From 7cf7ffe025adf43ee8ed90e48fdd7c080bd9f4b4 Mon Sep 17 00:00:00 2001 From: Laan Tungir Date: Thu, 14 Aug 2025 18:30:16 -0400 Subject: [PATCH] . --- .gitignore | 7 +- Makefile | 45 +- VERSION | 2 +- openssl-install/bin/c_rehash | 4 +- .../include/openssl/configuration.h | 3 + openssl-install/lib64/pkgconfig/libcrypto.pc | 2 +- openssl-install/lib64/pkgconfig/libssl.pc | 2 +- openssl-install/lib64/pkgconfig/openssl.pc | 2 +- .../share/doc/openssl/html/man1/CA.pl.html | 175 -- .../openssl/html/man1/openssl-asn1parse.html | 229 -- .../doc/openssl/html/man1/openssl-ca.html | 753 ------ .../openssl/html/man1/openssl-ciphers.html | 857 ------- .../doc/openssl/html/man1/openssl-cmds.html | 71 - .../doc/openssl/html/man1/openssl-cmp.html | 1299 ---------- .../doc/openssl/html/man1/openssl-cms.html | 892 ------- .../doc/openssl/html/man1/openssl-crl.html | 225 -- .../openssl/html/man1/openssl-crl2pkcs7.html | 133 - .../doc/openssl/html/man1/openssl-dgst.html | 297 --- .../openssl/html/man1/openssl-dhparam.html | 170 -- .../doc/openssl/html/man1/openssl-dsa.html | 202 -- .../openssl/html/man1/openssl-dsaparam.html | 165 -- .../doc/openssl/html/man1/openssl-ec.html | 212 -- .../openssl/html/man1/openssl-ecparam.html | 214 -- .../doc/openssl/html/man1/openssl-enc.html | 467 ---- .../doc/openssl/html/man1/openssl-engine.html | 148 -- .../doc/openssl/html/man1/openssl-errstr.html | 72 - .../html/man1/openssl-fipsinstall.html | 434 ---- .../html/man1/openssl-format-options.html | 161 -- .../doc/openssl/html/man1/openssl-gendsa.html | 136 - .../openssl/html/man1/openssl-genpkey.html | 576 ----- .../doc/openssl/html/man1/openssl-genrsa.html | 149 -- .../doc/openssl/html/man1/openssl-info.html | 120 - .../doc/openssl/html/man1/openssl-kdf.html | 254 -- .../doc/openssl/html/man1/openssl-list.html | 340 --- .../doc/openssl/html/man1/openssl-mac.html | 205 -- .../man1/openssl-namedisplay-options.html | 187 -- .../doc/openssl/html/man1/openssl-nseq.html | 102 - .../doc/openssl/html/man1/openssl-ocsp.html | 478 ---- .../html/man1/openssl-passphrase-options.html | 95 - .../doc/openssl/html/man1/openssl-passwd.html | 164 -- .../doc/openssl/html/man1/openssl-pkcs12.html | 459 ---- .../doc/openssl/html/man1/openssl-pkcs7.html | 148 -- .../doc/openssl/html/man1/openssl-pkcs8.html | 286 --- .../doc/openssl/html/man1/openssl-pkey.html | 254 -- .../openssl/html/man1/openssl-pkeyparam.html | 129 - .../openssl/html/man1/openssl-pkeyutl.html | 467 ---- .../doc/openssl/html/man1/openssl-prime.html | 103 - .../doc/openssl/html/man1/openssl-rand.html | 115 - .../doc/openssl/html/man1/openssl-rehash.html | 146 -- .../doc/openssl/html/man1/openssl-req.html | 738 ------ .../doc/openssl/html/man1/openssl-rsa.html | 228 -- .../doc/openssl/html/man1/openssl-rsautl.html | 275 --- .../openssl/html/man1/openssl-s_client.html | 1013 -------- .../openssl/html/man1/openssl-s_server.html | 976 -------- .../doc/openssl/html/man1/openssl-s_time.html | 193 -- .../openssl/html/man1/openssl-sess_id.html | 188 -- .../doc/openssl/html/man1/openssl-smime.html | 479 ---- .../doc/openssl/html/man1/openssl-speed.html | 221 -- .../doc/openssl/html/man1/openssl-spkac.html | 194 -- .../doc/openssl/html/man1/openssl-srp.html | 158 -- .../openssl/html/man1/openssl-storeutl.html | 177 -- .../doc/openssl/html/man1/openssl-ts.html | 602 ----- .../man1/openssl-verification-options.html | 589 ----- .../doc/openssl/html/man1/openssl-verify.html | 179 -- .../openssl/html/man1/openssl-version.html | 139 -- .../doc/openssl/html/man1/openssl-x509.html | 822 ------- .../share/doc/openssl/html/man1/openssl.html | 884 ------- .../share/doc/openssl/html/man1/tsget.html | 190 -- .../doc/openssl/html/man3/ADMISSIONS.html | 120 - .../openssl/html/man3/ASN1_EXTERN_FUNCS.html | 169 -- .../html/man3/ASN1_INTEGER_get_int64.html | 116 - .../openssl/html/man3/ASN1_INTEGER_new.html | 63 - .../openssl/html/man3/ASN1_ITEM_lookup.html | 59 - .../openssl/html/man3/ASN1_OBJECT_new.html | 68 - .../html/man3/ASN1_STRING_TABLE_add.html | 82 - .../openssl/html/man3/ASN1_STRING_length.html | 107 - .../openssl/html/man3/ASN1_STRING_new.html | 69 - .../html/man3/ASN1_STRING_print_ex.html | 103 - .../doc/openssl/html/man3/ASN1_TIME_set.html | 205 -- .../doc/openssl/html/man3/ASN1_TYPE_get.html | 89 - .../doc/openssl/html/man3/ASN1_aux_cb.html | 307 --- .../html/man3/ASN1_generate_nconf.html | 274 --- .../openssl/html/man3/ASN1_item_d2i_bio.html | 101 - .../doc/openssl/html/man3/ASN1_item_new.html | 60 - .../doc/openssl/html/man3/ASN1_item_sign.html | 212 -- .../openssl/html/man3/ASYNC_WAIT_CTX_new.html | 153 -- .../openssl/html/man3/ASYNC_start_job.html | 303 --- .../doc/openssl/html/man3/BF_encrypt.html | 104 - .../share/doc/openssl/html/man3/BIO_ADDR.html | 109 - .../doc/openssl/html/man3/BIO_ADDRINFO.html | 101 - .../doc/openssl/html/man3/BIO_connect.html | 127 - .../share/doc/openssl/html/man3/BIO_ctrl.html | 151 -- .../doc/openssl/html/man3/BIO_f_base64.html | 119 - .../doc/openssl/html/man3/BIO_f_buffer.html | 89 - .../doc/openssl/html/man3/BIO_f_cipher.html | 81 - .../share/doc/openssl/html/man3/BIO_f_md.html | 156 -- .../doc/openssl/html/man3/BIO_f_null.html | 58 - .../doc/openssl/html/man3/BIO_f_prefix.html | 80 - .../openssl/html/man3/BIO_f_readbuffer.html | 69 - .../doc/openssl/html/man3/BIO_f_ssl.html | 258 -- .../doc/openssl/html/man3/BIO_find_type.html | 83 - .../doc/openssl/html/man3/BIO_get_data.html | 76 - .../html/man3/BIO_get_ex_new_index.html | 114 - .../html/man3/BIO_get_rpoll_descriptor.html | 111 - .../doc/openssl/html/man3/BIO_meth_new.html | 150 -- .../share/doc/openssl/html/man3/BIO_new.html | 89 - .../doc/openssl/html/man3/BIO_new_CMS.html | 81 - .../openssl/html/man3/BIO_parse_hostserv.html | 91 - .../doc/openssl/html/man3/BIO_printf.html | 66 - .../share/doc/openssl/html/man3/BIO_push.html | 100 - .../share/doc/openssl/html/man3/BIO_read.html | 103 - .../doc/openssl/html/man3/BIO_s_accept.html | 187 -- .../doc/openssl/html/man3/BIO_s_bio.html | 157 -- .../doc/openssl/html/man3/BIO_s_connect.html | 183 -- .../doc/openssl/html/man3/BIO_s_core.html | 83 - .../doc/openssl/html/man3/BIO_s_datagram.html | 228 -- .../openssl/html/man3/BIO_s_dgram_pair.html | 163 -- .../share/doc/openssl/html/man3/BIO_s_fd.html | 103 - .../doc/openssl/html/man3/BIO_s_file.html | 159 -- .../doc/openssl/html/man3/BIO_s_mem.html | 162 -- .../doc/openssl/html/man3/BIO_s_null.html | 60 - .../doc/openssl/html/man3/BIO_s_socket.html | 68 - .../doc/openssl/html/man3/BIO_sendmmsg.html | 168 -- .../openssl/html/man3/BIO_set_callback.html | 298 --- .../openssl/html/man3/BIO_should_retry.html | 115 - .../openssl/html/man3/BIO_socket_wait.html | 69 - .../openssl/html/man3/BN_BLINDING_new.html | 112 - .../doc/openssl/html/man3/BN_CTX_new.html | 91 - .../doc/openssl/html/man3/BN_CTX_start.html | 66 - .../share/doc/openssl/html/man3/BN_add.html | 128 - .../doc/openssl/html/man3/BN_add_word.html | 78 - .../doc/openssl/html/man3/BN_bn2bin.html | 120 - .../share/doc/openssl/html/man3/BN_cmp.html | 75 - .../share/doc/openssl/html/man3/BN_copy.html | 75 - .../openssl/html/man3/BN_generate_prime.html | 200 -- .../openssl/html/man3/BN_mod_exp_mont.html | 72 - .../doc/openssl/html/man3/BN_mod_inverse.html | 64 - .../html/man3/BN_mod_mul_montgomery.html | 99 - .../html/man3/BN_mod_mul_reciprocal.html | 84 - .../share/doc/openssl/html/man3/BN_new.html | 75 - .../doc/openssl/html/man3/BN_num_bytes.html | 71 - .../share/doc/openssl/html/man3/BN_rand.html | 104 - .../openssl/html/man3/BN_security_bits.html | 66 - .../doc/openssl/html/man3/BN_set_bit.html | 81 - .../share/doc/openssl/html/man3/BN_swap.html | 51 - .../share/doc/openssl/html/man3/BN_zero.html | 82 - .../doc/openssl/html/man3/BUF_MEM_new.html | 86 - .../share/doc/openssl/html/man3/CMAC_CTX.html | 119 - .../html/man3/CMS_EncryptedData_decrypt.html | 76 - .../html/man3/CMS_EncryptedData_encrypt.html | 79 - .../html/man3/CMS_EnvelopedData_create.html | 84 - .../doc/openssl/html/man3/CMS_add0_cert.html | 82 - .../html/man3/CMS_add1_recipient_cert.html | 88 - .../openssl/html/man3/CMS_add1_signer.html | 91 - .../doc/openssl/html/man3/CMS_compress.html | 79 - .../openssl/html/man3/CMS_data_create.html | 67 - .../doc/openssl/html/man3/CMS_decrypt.html | 95 - .../openssl/html/man3/CMS_digest_create.html | 70 - .../doc/openssl/html/man3/CMS_encrypt.html | 99 - .../doc/openssl/html/man3/CMS_final.html | 72 - .../html/man3/CMS_get0_RecipientInfos.html | 121 - .../html/man3/CMS_get0_SignerInfos.html | 89 - .../doc/openssl/html/man3/CMS_get0_type.html | 87 - .../html/man3/CMS_get1_ReceiptRequest.html | 92 - .../share/doc/openssl/html/man3/CMS_sign.html | 114 - .../openssl/html/man3/CMS_sign_receipt.html | 65 - .../html/man3/CMS_signed_get_attr.html | 170 -- .../doc/openssl/html/man3/CMS_uncompress.html | 74 - .../doc/openssl/html/man3/CMS_verify.html | 128 - .../openssl/html/man3/CMS_verify_receipt.html | 67 - .../doc/openssl/html/man3/COMP_CTX_new.html | 151 -- .../openssl/html/man3/CONF_modules_free.html | 70 - .../html/man3/CONF_modules_load_file.html | 144 -- .../html/man3/CRYPTO_THREAD_run_once.html | 210 -- .../html/man3/CRYPTO_get_ex_new_index.html | 142 -- .../doc/openssl/html/man3/CRYPTO_memcmp.html | 56 - .../html/man3/CTLOG_STORE_get0_log_by_id.html | 65 - .../openssl/html/man3/CTLOG_STORE_new.html | 91 - .../doc/openssl/html/man3/CTLOG_new.html | 90 - .../html/man3/CT_POLICY_EVAL_CTX_new.html | 132 - .../openssl/html/man3/DEFINE_STACK_OF.html | 206 -- .../doc/openssl/html/man3/DES_random_key.html | 225 -- .../openssl/html/man3/DH_generate_key.html | 83 - .../html/man3/DH_generate_parameters.html | 173 -- .../doc/openssl/html/man3/DH_get0_pqg.html | 114 - .../openssl/html/man3/DH_get_1024_160.html | 81 - .../doc/openssl/html/man3/DH_meth_new.html | 141 -- .../share/doc/openssl/html/man3/DH_new.html | 71 - .../doc/openssl/html/man3/DH_new_by_nid.html | 64 - .../doc/openssl/html/man3/DH_set_method.html | 91 - .../share/doc/openssl/html/man3/DH_size.html | 79 - .../doc/openssl/html/man3/DSA_SIG_new.html | 69 - .../doc/openssl/html/man3/DSA_do_sign.html | 72 - .../doc/openssl/html/man3/DSA_dup_DH.html | 70 - .../openssl/html/man3/DSA_generate_key.html | 67 - .../html/man3/DSA_generate_parameters.html | 118 - .../doc/openssl/html/man3/DSA_get0_pqg.html | 102 - .../doc/openssl/html/man3/DSA_meth_new.html | 177 -- .../share/doc/openssl/html/man3/DSA_new.html | 71 - .../doc/openssl/html/man3/DSA_set_method.html | 89 - .../share/doc/openssl/html/man3/DSA_sign.html | 84 - .../share/doc/openssl/html/man3/DSA_size.html | 77 - .../openssl/html/man3/DTLS_get_data_mtu.html | 56 - .../openssl/html/man3/DTLS_set_timer_cb.html | 64 - .../openssl/html/man3/DTLSv1_get_timeout.html | 68 - .../html/man3/DTLSv1_handle_timeout.html | 66 - .../doc/openssl/html/man3/DTLSv1_listen.html | 101 - .../doc/openssl/html/man3/ECDSA_SIG_new.html | 142 -- .../doc/openssl/html/man3/ECDSA_sign.html | 165 -- .../html/man3/ECPKParameters_print.html | 68 - .../html/man3/EC_GFp_simple_method.html | 84 - .../doc/openssl/html/man3/EC_GROUP_copy.html | 200 -- .../doc/openssl/html/man3/EC_GROUP_new.html | 170 -- .../html/man3/EC_KEY_get_enc_flags.html | 61 - .../doc/openssl/html/man3/EC_KEY_new.html | 168 -- .../doc/openssl/html/man3/EC_POINT_add.html | 103 - .../doc/openssl/html/man3/EC_POINT_new.html | 179 -- .../doc/openssl/html/man3/ENGINE_add.html | 426 ---- .../doc/openssl/html/man3/ERR_GET_LIB.html | 82 - .../openssl/html/man3/ERR_clear_error.html | 56 - .../openssl/html/man3/ERR_error_string.html | 87 - .../doc/openssl/html/man3/ERR_get_error.html | 116 - .../html/man3/ERR_load_crypto_strings.html | 70 - .../openssl/html/man3/ERR_load_strings.html | 74 - .../share/doc/openssl/html/man3/ERR_new.html | 76 - .../openssl/html/man3/ERR_print_errors.html | 71 - .../doc/openssl/html/man3/ERR_put_error.html | 155 -- .../openssl/html/man3/ERR_remove_state.html | 65 - .../doc/openssl/html/man3/ERR_set_mark.html | 74 - .../html/man3/EVP_ASYM_CIPHER_free.html | 103 - .../doc/openssl/html/man3/EVP_BytesToKey.html | 81 - .../man3/EVP_CIPHER_CTX_get_cipher_data.html | 61 - .../man3/EVP_CIPHER_CTX_get_original_iv.html | 69 - .../html/man3/EVP_CIPHER_meth_new.html | 229 -- .../doc/openssl/html/man3/EVP_DigestInit.html | 782 ------ .../openssl/html/man3/EVP_DigestSignInit.html | 179 -- .../html/man3/EVP_DigestVerifyInit.html | 174 -- .../doc/openssl/html/man3/EVP_EncodeInit.html | 114 - .../openssl/html/man3/EVP_EncryptInit.html | 1557 ------------ .../share/doc/openssl/html/man3/EVP_KDF.html | 266 -- .../doc/openssl/html/man3/EVP_KEM_free.html | 100 - .../openssl/html/man3/EVP_KEYEXCH_free.html | 104 - .../doc/openssl/html/man3/EVP_KEYMGMT.html | 124 - .../share/doc/openssl/html/man3/EVP_MAC.html | 399 --- .../openssl/html/man3/EVP_MD_meth_new.html | 169 -- .../doc/openssl/html/man3/EVP_OpenInit.html | 75 - .../openssl/html/man3/EVP_PBE_CipherInit.html | 119 - .../doc/openssl/html/man3/EVP_PKEY2PKCS8.html | 65 - .../html/man3/EVP_PKEY_ASN1_METHOD.html | 353 --- .../openssl/html/man3/EVP_PKEY_CTX_ctrl.html | 416 ---- .../html/man3/EVP_PKEY_CTX_get0_libctx.html | 67 - .../html/man3/EVP_PKEY_CTX_get0_pkey.html | 65 - .../html/man3/EVP_PKEY_CTX_get_algor.html | 57 - .../openssl/html/man3/EVP_PKEY_CTX_new.html | 131 - .../html/man3/EVP_PKEY_CTX_set1_pbe_pass.html | 69 - .../html/man3/EVP_PKEY_CTX_set_hkdf_md.html | 156 -- .../html/man3/EVP_PKEY_CTX_set_params.html | 80 - .../EVP_PKEY_CTX_set_rsa_pss_keygen_md.html | 98 - .../html/man3/EVP_PKEY_CTX_set_scrypt_N.html | 89 - .../man3/EVP_PKEY_CTX_set_tls1_prf_md.html | 112 - .../html/man3/EVP_PKEY_asn1_get_count.html | 78 - .../doc/openssl/html/man3/EVP_PKEY_check.html | 90 - .../html/man3/EVP_PKEY_copy_parameters.html | 103 - .../html/man3/EVP_PKEY_decapsulate.html | 115 - .../openssl/html/man3/EVP_PKEY_decrypt.html | 125 - .../openssl/html/man3/EVP_PKEY_derive.html | 120 - .../EVP_PKEY_digestsign_supports_digest.html | 61 - .../html/man3/EVP_PKEY_encapsulate.html | 116 - .../openssl/html/man3/EVP_PKEY_encrypt.html | 117 - .../openssl/html/man3/EVP_PKEY_fromdata.html | 272 -- .../openssl/html/man3/EVP_PKEY_get_attr.html | 102 - .../man3/EVP_PKEY_get_default_digest_nid.html | 70 - .../html/man3/EVP_PKEY_get_field_type.html | 71 - .../html/man3/EVP_PKEY_get_group_name.html | 62 - .../openssl/html/man3/EVP_PKEY_get_size.html | 80 - .../html/man3/EVP_PKEY_gettable_params.html | 125 - .../doc/openssl/html/man3/EVP_PKEY_is_a.html | 118 - .../openssl/html/man3/EVP_PKEY_keygen.html | 187 -- .../html/man3/EVP_PKEY_meth_get_count.html | 76 - .../openssl/html/man3/EVP_PKEY_meth_new.html | 405 --- .../doc/openssl/html/man3/EVP_PKEY_new.html | 146 -- .../html/man3/EVP_PKEY_print_private.html | 85 - .../openssl/html/man3/EVP_PKEY_set1_RSA.html | 157 -- .../EVP_PKEY_set1_encoded_public_key.html | 139 -- .../openssl/html/man3/EVP_PKEY_set_type.html | 66 - .../html/man3/EVP_PKEY_settable_params.html | 91 - .../doc/openssl/html/man3/EVP_PKEY_sign.html | 304 --- .../openssl/html/man3/EVP_PKEY_todata.html | 72 - .../openssl/html/man3/EVP_PKEY_verify.html | 291 --- .../html/man3/EVP_PKEY_verify_recover.html | 130 - .../share/doc/openssl/html/man3/EVP_RAND.html | 347 --- .../doc/openssl/html/man3/EVP_SIGNATURE.html | 106 - .../doc/openssl/html/man3/EVP_SealInit.html | 82 - .../doc/openssl/html/man3/EVP_SignInit.html | 104 - .../doc/openssl/html/man3/EVP_VerifyInit.html | 105 - .../openssl/html/man3/EVP_aes_128_gcm.html | 113 - .../openssl/html/man3/EVP_aria_128_gcm.html | 79 - .../doc/openssl/html/man3/EVP_bf_cbc.html | 77 - .../doc/openssl/html/man3/EVP_blake2b512.html | 85 - .../html/man3/EVP_camellia_128_ecb.html | 73 - .../doc/openssl/html/man3/EVP_cast5_cbc.html | 77 - .../doc/openssl/html/man3/EVP_chacha20.html | 86 - .../doc/openssl/html/man3/EVP_des_cbc.html | 93 - .../doc/openssl/html/man3/EVP_desx_cbc.html | 72 - .../doc/openssl/html/man3/EVP_idea_cbc.html | 75 - .../share/doc/openssl/html/man3/EVP_md2.html | 76 - .../share/doc/openssl/html/man3/EVP_md4.html | 76 - .../share/doc/openssl/html/man3/EVP_md5.html | 87 - .../share/doc/openssl/html/man3/EVP_mdc2.html | 76 - .../doc/openssl/html/man3/EVP_rc2_cbc.html | 85 - .../share/doc/openssl/html/man3/EVP_rc4.html | 89 - .../html/man3/EVP_rc5_32_12_16_cbc.html | 93 - .../doc/openssl/html/man3/EVP_ripemd160.html | 76 - .../doc/openssl/html/man3/EVP_seed_cbc.html | 77 - .../html/man3/EVP_set_default_properties.html | 78 - .../share/doc/openssl/html/man3/EVP_sha1.html | 76 - .../doc/openssl/html/man3/EVP_sha224.html | 83 - .../doc/openssl/html/man3/EVP_sha3_224.html | 90 - .../share/doc/openssl/html/man3/EVP_sm3.html | 76 - .../doc/openssl/html/man3/EVP_sm4_cbc.html | 78 - .../doc/openssl/html/man3/EVP_whirlpool.html | 76 - .../doc/openssl/html/man3/GENERAL_NAME.html | 58 - .../share/doc/openssl/html/man3/HMAC.html | 143 -- .../share/doc/openssl/html/man3/MD5.html | 115 - .../doc/openssl/html/man3/MDC2_Init.html | 90 - .../doc/openssl/html/man3/NCONF_new_ex.html | 91 - .../doc/openssl/html/man3/OBJ_nid2obj.html | 168 -- .../openssl/html/man3/OCSP_REQUEST_new.html | 117 - .../openssl/html/man3/OCSP_cert_to_id.html | 94 - .../html/man3/OCSP_request_add1_nonce.html | 82 - .../html/man3/OCSP_resp_find_status.html | 156 -- .../html/man3/OCSP_response_status.html | 115 - .../openssl/html/man3/OCSP_sendreq_new.html | 96 - .../openssl/html/man3/OPENSSL_Applink.html | 49 - .../doc/openssl/html/man3/OPENSSL_FILE.html | 70 - .../html/man3/OPENSSL_LH_COMPFUNC.html | 232 -- .../openssl/html/man3/OPENSSL_LH_stats.html | 85 - .../doc/openssl/html/man3/OPENSSL_config.html | 88 - .../html/man3/OPENSSL_fork_prepare.html | 71 - .../doc/openssl/html/man3/OPENSSL_gmtime.html | 74 - .../html/man3/OPENSSL_hexchar2int.html | 70 - .../openssl/html/man3/OPENSSL_ia32cap.html | 189 -- .../html/man3/OPENSSL_init_crypto.html | 228 -- .../openssl/html/man3/OPENSSL_init_ssl.html | 87 - .../html/man3/OPENSSL_instrument_bus.html | 58 - .../man3/OPENSSL_load_builtin_modules.html | 76 - .../doc/openssl/html/man3/OPENSSL_malloc.html | 172 -- .../openssl/html/man3/OPENSSL_riscvcap.html | 269 -- .../openssl/html/man3/OPENSSL_s390xcap.html | 220 -- .../html/man3/OPENSSL_secure_malloc.html | 116 - .../openssl/html/man3/OPENSSL_strcasecmp.html | 66 - .../doc/openssl/html/man3/OSSL_ALGORITHM.html | 146 -- .../doc/openssl/html/man3/OSSL_CALLBACK.html | 79 - .../openssl/html/man3/OSSL_CMP_ATAV_set0.html | 108 - .../openssl/html/man3/OSSL_CMP_CTX_new.html | 599 ----- .../man3/OSSL_CMP_HDR_get0_transactionID.html | 72 - .../html/man3/OSSL_CMP_ITAV_new_caCerts.html | 158 -- .../openssl/html/man3/OSSL_CMP_ITAV_set0.html | 127 - .../html/man3/OSSL_CMP_MSG_get0_header.html | 155 -- .../html/man3/OSSL_CMP_MSG_http_perform.html | 69 - .../html/man3/OSSL_CMP_SRV_CTX_new.html | 157 -- .../html/man3/OSSL_CMP_STATUSINFO_new.html | 74 - .../html/man3/OSSL_CMP_exec_certreq.html | 141 -- .../openssl/html/man3/OSSL_CMP_log_open.html | 100 - .../html/man3/OSSL_CMP_validate_msg.html | 77 - .../html/man3/OSSL_CORE_MAKE_FUNC.html | 60 - .../html/man3/OSSL_CRMF_MSG_get0_tmpl.html | 104 - .../man3/OSSL_CRMF_MSG_set0_validity.html | 115 - .../OSSL_CRMF_MSG_set1_regCtrl_regToken.html | 116 - .../OSSL_CRMF_MSG_set1_regInfo_certReq.html | 81 - .../openssl/html/man3/OSSL_CRMF_pbmp_new.html | 96 - .../doc/openssl/html/man3/OSSL_DECODER.html | 166 -- .../openssl/html/man3/OSSL_DECODER_CTX.html | 204 -- .../man3/OSSL_DECODER_CTX_new_for_pkey.html | 119 - .../html/man3/OSSL_DECODER_from_bio.html | 134 - .../doc/openssl/html/man3/OSSL_DISPATCH.html | 90 - .../doc/openssl/html/man3/OSSL_ENCODER.html | 119 - .../openssl/html/man3/OSSL_ENCODER_CTX.html | 186 -- .../man3/OSSL_ENCODER_CTX_new_for_pkey.html | 131 - .../html/man3/OSSL_ENCODER_to_bio.html | 138 -- .../html/man3/OSSL_ERR_STATE_save.html | 84 - .../man3/OSSL_ESS_check_signing_certs.html | 83 - .../html/man3/OSSL_GENERAL_NAMES_print.html | 56 - .../openssl/html/man3/OSSL_HPKE_CTX_new.html | 456 ---- .../openssl/html/man3/OSSL_HTTP_REQ_CTX.html | 171 -- .../html/man3/OSSL_HTTP_parse_url.html | 83 - .../openssl/html/man3/OSSL_HTTP_transfer.html | 167 -- .../html/man3/OSSL_IETF_ATTR_SYNTAX.html | 103 - .../man3/OSSL_IETF_ATTR_SYNTAX_print.html | 62 - .../man3/OSSL_INDICATOR_set_callback.html | 91 - .../doc/openssl/html/man3/OSSL_ITEM.html | 62 - .../doc/openssl/html/man3/OSSL_LIB_CTX.html | 103 - .../OSSL_LIB_CTX_set_conf_diagnostics.html | 64 - .../doc/openssl/html/man3/OSSL_PARAM.html | 314 --- .../doc/openssl/html/man3/OSSL_PARAM_BLD.html | 169 -- .../man3/OSSL_PARAM_allocate_from_text.html | 207 -- .../doc/openssl/html/man3/OSSL_PARAM_dup.html | 69 - .../doc/openssl/html/man3/OSSL_PARAM_int.html | 307 --- .../doc/openssl/html/man3/OSSL_PROVIDER.html | 188 -- .../html/man3/OSSL_QUIC_client_method.html | 64 - .../openssl/html/man3/OSSL_SELF_TEST_new.html | 176 -- .../man3/OSSL_SELF_TEST_set_callback.html | 62 - .../openssl/html/man3/OSSL_STORE_INFO.html | 187 -- .../openssl/html/man3/OSSL_STORE_LOADER.html | 293 --- .../openssl/html/man3/OSSL_STORE_SEARCH.html | 151 -- .../openssl/html/man3/OSSL_STORE_attach.html | 66 - .../openssl/html/man3/OSSL_STORE_expect.html | 82 - .../openssl/html/man3/OSSL_STORE_open.html | 153 -- .../doc/openssl/html/man3/OSSL_sleep.html | 58 - .../openssl/html/man3/OSSL_trace_enabled.html | 278 --- .../man3/OSSL_trace_get_category_num.html | 61 - .../html/man3/OSSL_trace_set_channel.html | 350 --- .../html/man3/OpenSSL_add_all_algorithms.html | 75 - .../openssl/html/man3/OpenSSL_version.html | 272 -- .../html/man3/PBMAC1_get1_pbkdf2_param.html | 66 - .../html/man3/PEM_X509_INFO_read_bio_ex.html | 87 - .../openssl/html/man3/PEM_bytes_read_bio.html | 81 - .../share/doc/openssl/html/man3/PEM_read.html | 98 - .../doc/openssl/html/man3/PEM_read_CMS.html | 110 - .../html/man3/PEM_read_bio_PrivateKey.html | 439 ---- .../openssl/html/man3/PEM_read_bio_ex.html | 80 - .../html/man3/PEM_write_bio_CMS_stream.html | 68 - .../html/man3/PEM_write_bio_PKCS7_stream.html | 68 - .../html/man3/PKCS12_PBE_keyivgen.html | 108 - .../html/man3/PKCS12_SAFEBAG_create_cert.html | 105 - .../html/man3/PKCS12_SAFEBAG_get0_attrs.html | 65 - .../html/man3/PKCS12_SAFEBAG_get1_cert.html | 90 - .../html/man3/PKCS12_SAFEBAG_set0_attrs.html | 51 - .../html/man3/PKCS12_add1_attr_by_NID.html | 70 - .../html/man3/PKCS12_add_CSPName_asc.html | 58 - .../openssl/html/man3/PKCS12_add_cert.html | 91 - .../man3/PKCS12_add_friendlyname_asc.html | 69 - .../html/man3/PKCS12_add_localkeyid.html | 59 - .../openssl/html/man3/PKCS12_add_safe.html | 100 - .../doc/openssl/html/man3/PKCS12_create.html | 115 - .../html/man3/PKCS12_decrypt_skey.html | 73 - .../doc/openssl/html/man3/PKCS12_gen_mac.html | 102 - .../html/man3/PKCS12_get_friendlyname.html | 60 - .../doc/openssl/html/man3/PKCS12_init.html | 64 - .../html/man3/PKCS12_item_decrypt_d2i.html | 84 - .../html/man3/PKCS12_key_gen_utf8_ex.html | 133 - .../doc/openssl/html/man3/PKCS12_newpass.html | 119 - .../html/man3/PKCS12_pack_p7encdata.html | 74 - .../doc/openssl/html/man3/PKCS12_parse.html | 81 - .../openssl/html/man3/PKCS5_PBE_keyivgen.html | 173 -- .../openssl/html/man3/PKCS5_PBKDF2_HMAC.html | 82 - .../doc/openssl/html/man3/PKCS7_decrypt.html | 72 - .../doc/openssl/html/man3/PKCS7_encrypt.html | 91 - .../html/man3/PKCS7_get_octet_string.html | 61 - .../doc/openssl/html/man3/PKCS7_sign.html | 110 - .../html/man3/PKCS7_sign_add_signer.html | 95 - .../html/man3/PKCS7_type_is_other.html | 58 - .../doc/openssl/html/man3/PKCS7_verify.html | 110 - .../doc/openssl/html/man3/PKCS8_encrypt.html | 90 - .../html/man3/PKCS8_pkey_add1_attr.html | 71 - .../share/doc/openssl/html/man3/RAND_add.html | 92 - .../doc/openssl/html/man3/RAND_bytes.html | 95 - .../doc/openssl/html/man3/RAND_cleanup.html | 63 - .../share/doc/openssl/html/man3/RAND_egd.html | 67 - .../openssl/html/man3/RAND_get0_primary.html | 92 - .../doc/openssl/html/man3/RAND_load_file.html | 94 - .../openssl/html/man3/RAND_set_DRBG_type.html | 82 - .../html/man3/RAND_set_rand_method.html | 91 - .../doc/openssl/html/man3/RC4_set_key.html | 85 - .../doc/openssl/html/man3/RIPEMD160_Init.html | 92 - .../openssl/html/man3/RSA_blinding_on.html | 68 - .../doc/openssl/html/man3/RSA_check_key.html | 87 - .../openssl/html/man3/RSA_generate_key.html | 113 - .../doc/openssl/html/man3/RSA_get0_key.html | 144 -- .../doc/openssl/html/man3/RSA_meth_new.html | 208 -- .../share/doc/openssl/html/man3/RSA_new.html | 69 - .../man3/RSA_padding_add_PKCS1_type_1.html | 148 -- .../doc/openssl/html/man3/RSA_print.html | 88 - .../html/man3/RSA_private_encrypt.html | 93 - .../openssl/html/man3/RSA_public_encrypt.html | 111 - .../doc/openssl/html/man3/RSA_set_method.html | 167 -- .../share/doc/openssl/html/man3/RSA_sign.html | 80 - .../html/man3/RSA_sign_ASN1_OCTET_STRING.html | 84 - .../share/doc/openssl/html/man3/RSA_size.html | 81 - .../share/doc/openssl/html/man3/SCT_new.html | 203 -- .../doc/openssl/html/man3/SCT_print.html | 68 - .../doc/openssl/html/man3/SCT_validate.html | 108 - .../doc/openssl/html/man3/SHA256_Init.html | 110 - .../openssl/html/man3/SMIME_read_ASN1.html | 86 - .../doc/openssl/html/man3/SMIME_read_CMS.html | 94 - .../openssl/html/man3/SMIME_read_PKCS7.html | 93 - .../openssl/html/man3/SMIME_write_ASN1.html | 82 - .../openssl/html/man3/SMIME_write_CMS.html | 78 - .../openssl/html/man3/SMIME_write_PKCS7.html | 78 - .../doc/openssl/html/man3/SRP_Calc_B.html | 92 - .../doc/openssl/html/man3/SRP_VBASE_new.html | 86 - .../html/man3/SRP_create_verifier.html | 122 - .../openssl/html/man3/SRP_user_pwd_new.html | 80 - .../html/man3/SSL_CIPHER_get_name.html | 181 -- .../man3/SSL_COMP_add_compression_method.html | 133 - .../openssl/html/man3/SSL_CONF_CTX_new.html | 66 - .../html/man3/SSL_CONF_CTX_set1_prefix.html | 70 - .../html/man3/SSL_CONF_CTX_set_flags.html | 105 - .../html/man3/SSL_CONF_CTX_set_ssl_ctx.html | 74 - .../doc/openssl/html/man3/SSL_CONF_cmd.html | 652 ----- .../openssl/html/man3/SSL_CONF_cmd_argv.html | 65 - .../html/man3/SSL_CTX_add1_chain_cert.html | 122 - .../man3/SSL_CTX_add_extra_chain_cert.html | 81 - .../html/man3/SSL_CTX_add_session.html | 83 - .../doc/openssl/html/man3/SSL_CTX_config.html | 102 - .../doc/openssl/html/man3/SSL_CTX_ctrl.html | 60 - .../html/man3/SSL_CTX_dane_enable.html | 255 -- .../html/man3/SSL_CTX_flush_sessions.html | 76 - .../doc/openssl/html/man3/SSL_CTX_free.html | 65 - .../openssl/html/man3/SSL_CTX_get0_param.html | 91 - .../html/man3/SSL_CTX_get_verify_mode.html | 71 - .../man3/SSL_CTX_has_client_custom_ext.html | 56 - .../man3/SSL_CTX_load_verify_locations.html | 141 -- .../doc/openssl/html/man3/SSL_CTX_new.html | 221 -- .../html/man3/SSL_CTX_sess_number.html | 89 - .../man3/SSL_CTX_sess_set_cache_size.html | 70 - .../html/man3/SSL_CTX_sess_set_get_cb.html | 93 - .../openssl/html/man3/SSL_CTX_sessions.html | 61 - .../html/man3/SSL_CTX_set0_CA_list.html | 130 - .../SSL_CTX_set1_cert_comp_preference.html | 133 - .../html/man3/SSL_CTX_set1_curves.html | 132 - .../html/man3/SSL_CTX_set1_sigalgs.html | 111 - .../man3/SSL_CTX_set1_verify_cert_store.html | 96 - .../html/man3/SSL_CTX_set_alpn_select_cb.html | 171 -- .../html/man3/SSL_CTX_set_cert_cb.html | 75 - .../html/man3/SSL_CTX_set_cert_store.html | 84 - .../SSL_CTX_set_cert_verify_callback.html | 83 - .../html/man3/SSL_CTX_set_cipher_list.html | 129 - .../html/man3/SSL_CTX_set_client_cert_cb.html | 82 - .../man3/SSL_CTX_set_client_hello_cb.html | 103 - .../SSL_CTX_set_ct_validation_callback.html | 101 - .../man3/SSL_CTX_set_ctlog_list_file.html | 66 - .../man3/SSL_CTX_set_default_passwd_cb.html | 100 - .../man3/SSL_CTX_set_generate_session_id.html | 116 - .../html/man3/SSL_CTX_set_info_callback.html | 190 -- .../man3/SSL_CTX_set_keylog_callback.html | 63 - .../html/man3/SSL_CTX_set_max_cert_list.html | 81 - .../man3/SSL_CTX_set_min_proto_version.html | 82 - .../openssl/html/man3/SSL_CTX_set_mode.html | 138 -- .../html/man3/SSL_CTX_set_msg_callback.html | 183 -- .../html/man3/SSL_CTX_set_num_tickets.html | 75 - .../html/man3/SSL_CTX_set_options.html | 503 ---- .../man3/SSL_CTX_set_psk_client_callback.html | 143 -- .../html/man3/SSL_CTX_set_quiet_shutdown.html | 79 - .../html/man3/SSL_CTX_set_read_ahead.html | 74 - .../SSL_CTX_set_record_padding_callback.html | 106 - .../html/man3/SSL_CTX_set_security_level.html | 170 -- .../man3/SSL_CTX_set_session_cache_mode.html | 134 - .../man3/SSL_CTX_set_session_id_context.html | 95 - .../man3/SSL_CTX_set_session_ticket_cb.html | 169 -- .../man3/SSL_CTX_set_split_send_fragment.html | 152 -- .../html/man3/SSL_CTX_set_srp_password.html | 177 -- .../html/man3/SSL_CTX_set_ssl_version.html | 100 - ..._CTX_set_stateless_cookie_generate_cb.html | 89 - .../html/man3/SSL_CTX_set_timeout.html | 80 - ...SL_CTX_set_tlsext_servername_callback.html | 167 -- .../man3/SSL_CTX_set_tlsext_status_cb.html | 92 - .../SSL_CTX_set_tlsext_ticket_key_cb.html | 213 -- .../man3/SSL_CTX_set_tlsext_use_srtp.html | 156 -- .../man3/SSL_CTX_set_tmp_dh_callback.html | 91 - .../html/man3/SSL_CTX_set_tmp_ecdh.html | 64 - .../openssl/html/man3/SSL_CTX_set_verify.html | 270 -- .../html/man3/SSL_CTX_use_certificate.html | 121 - .../man3/SSL_CTX_use_psk_identity_hint.html | 123 - .../html/man3/SSL_CTX_use_serverinfo.html | 78 - .../openssl/html/man3/SSL_SESSION_free.html | 81 - .../html/man3/SSL_SESSION_get0_cipher.html | 68 - .../html/man3/SSL_SESSION_get0_hostname.html | 80 - .../man3/SSL_SESSION_get0_id_context.html | 70 - .../html/man3/SSL_SESSION_get0_peer.html | 56 - .../man3/SSL_SESSION_get_compress_id.html | 56 - .../SSL_SESSION_get_protocol_version.html | 68 - .../html/man3/SSL_SESSION_get_time.html | 101 - .../html/man3/SSL_SESSION_has_ticket.html | 70 - .../html/man3/SSL_SESSION_is_resumable.html | 61 - .../openssl/html/man3/SSL_SESSION_print.html | 62 - .../html/man3/SSL_SESSION_set1_id.html | 66 - .../doc/openssl/html/man3/SSL_accept.html | 87 - .../openssl/html/man3/SSL_accept_stream.html | 81 - .../html/man3/SSL_alert_type_string.html | 255 -- .../openssl/html/man3/SSL_alloc_buffers.html | 79 - .../openssl/html/man3/SSL_check_chain.html | 89 - .../doc/openssl/html/man3/SSL_clear.html | 83 - .../doc/openssl/html/man3/SSL_connect.html | 91 - .../openssl/html/man3/SSL_do_handshake.html | 87 - .../html/man3/SSL_export_keying_material.html | 83 - .../html/man3/SSL_extension_supported.html | 266 -- .../share/doc/openssl/html/man3/SSL_free.html | 74 - .../html/man3/SSL_get0_connection.html | 70 - .../html/man3/SSL_get0_group_name.html | 63 - .../openssl/html/man3/SSL_get0_peer_rpk.html | 98 - .../openssl/html/man3/SSL_get0_peer_scts.html | 61 - .../html/man3/SSL_get1_builtin_sigalgs.html | 61 - .../openssl/html/man3/SSL_get_SSL_CTX.html | 56 - .../html/man3/SSL_get_all_async_fds.html | 76 - .../html/man3/SSL_get_certificate.html | 75 - .../openssl/html/man3/SSL_get_ciphers.html | 89 - .../html/man3/SSL_get_client_random.html | 84 - .../html/man3/SSL_get_conn_close_info.html | 157 -- .../html/man3/SSL_get_current_cipher.html | 73 - .../html/man3/SSL_get_default_timeout.html | 63 - .../doc/openssl/html/man3/SSL_get_error.html | 154 -- .../html/man3/SSL_get_event_timeout.html | 90 - .../html/man3/SSL_get_extms_support.html | 58 - .../doc/openssl/html/man3/SSL_get_fd.html | 74 - .../html/man3/SSL_get_handshake_rtt.html | 69 - .../html/man3/SSL_get_peer_cert_chain.html | 84 - .../html/man3/SSL_get_peer_certificate.html | 95 - .../html/man3/SSL_get_peer_signature_nid.html | 63 - .../html/man3/SSL_get_peer_tmp_key.html | 67 - .../html/man3/SSL_get_psk_identity.html | 59 - .../doc/openssl/html/man3/SSL_get_rbio.html | 73 - .../html/man3/SSL_get_rpoll_descriptor.html | 91 - .../openssl/html/man3/SSL_get_session.html | 97 - .../html/man3/SSL_get_shared_sigalgs.html | 83 - .../openssl/html/man3/SSL_get_stream_id.html | 112 - .../html/man3/SSL_get_stream_read_state.html | 144 -- .../openssl/html/man3/SSL_get_value_uint.html | 280 --- .../html/man3/SSL_get_verify_result.html | 86 - .../openssl/html/man3/SSL_get_version.html | 201 -- .../openssl/html/man3/SSL_group_to_name.html | 58 - .../openssl/html/man3/SSL_handle_events.html | 93 - .../doc/openssl/html/man3/SSL_in_init.html | 117 - .../html/man3/SSL_inject_net_dgram.html | 68 - .../doc/openssl/html/man3/SSL_key_update.html | 95 - .../openssl/html/man3/SSL_library_init.html | 75 - .../html/man3/SSL_load_client_CA_file.html | 134 - .../share/doc/openssl/html/man3/SSL_new.html | 182 -- .../doc/openssl/html/man3/SSL_new_stream.html | 84 - .../doc/openssl/html/man3/SSL_pending.html | 68 - .../share/doc/openssl/html/man3/SSL_poll.html | 298 --- .../share/doc/openssl/html/man3/SSL_read.html | 108 - .../html/man3/SSL_read_early_data.html | 186 -- .../openssl/html/man3/SSL_rstate_string.html | 90 - .../openssl/html/man3/SSL_session_reused.html | 77 - .../doc/openssl/html/man3/SSL_set1_host.html | 100 - .../html/man3/SSL_set1_initial_peer_addr.html | 67 - .../html/man3/SSL_set1_server_cert_type.html | 183 -- .../html/man3/SSL_set_async_callback.html | 107 - .../doc/openssl/html/man3/SSL_set_bio.html | 100 - .../html/man3/SSL_set_blocking_mode.html | 76 - .../html/man3/SSL_set_connect_state.html | 77 - .../man3/SSL_set_default_stream_mode.html | 107 - .../doc/openssl/html/man3/SSL_set_fd.html | 87 - .../man3/SSL_set_incoming_stream_policy.html | 106 - .../html/man3/SSL_set_retry_verify.html | 86 - .../openssl/html/man3/SSL_set_session.html | 79 - .../html/man3/SSL_set_session_secret_cb.html | 72 - .../openssl/html/man3/SSL_set_shutdown.html | 99 - .../html/man3/SSL_set_verify_result.html | 63 - .../doc/openssl/html/man3/SSL_shutdown.html | 296 --- .../openssl/html/man3/SSL_state_string.html | 68 - .../html/man3/SSL_stream_conclude.html | 73 - .../openssl/html/man3/SSL_stream_reset.html | 88 - .../share/doc/openssl/html/man3/SSL_want.html | 137 -- .../doc/openssl/html/man3/SSL_write.html | 154 -- .../openssl/html/man3/TS_RESP_CTX_new.html | 64 - .../doc/openssl/html/man3/TS_VERIFY_CTX.html | 133 - .../doc/openssl/html/man3/UI_STRING.html | 113 - .../openssl/html/man3/UI_UTIL_read_pw.html | 73 - .../openssl/html/man3/UI_create_method.html | 178 -- .../share/doc/openssl/html/man3/UI_new.html | 178 -- .../doc/openssl/html/man3/X509V3_get_d2i.html | 223 -- .../doc/openssl/html/man3/X509V3_set_ctx.html | 67 - .../html/man3/X509_ACERT_add1_attr.html | 76 - .../html/man3/X509_ACERT_add_attr_nconf.html | 78 - .../X509_ACERT_get0_holder_baseCertId.html | 115 - .../html/man3/X509_ACERT_get_attr.html | 66 - .../html/man3/X509_ACERT_print_ex.html | 110 - .../doc/openssl/html/man3/X509_ALGOR_dup.html | 78 - .../doc/openssl/html/man3/X509_ATTRIBUTE.html | 184 -- .../html/man3/X509_CRL_get0_by_serial.html | 99 - .../html/man3/X509_EXTENSION_set_object.html | 96 - .../doc/openssl/html/man3/X509_LOOKUP.html | 186 -- .../html/man3/X509_LOOKUP_hash_dir.html | 123 - .../html/man3/X509_LOOKUP_meth_new.html | 158 -- .../html/man3/X509_NAME_ENTRY_get_object.html | 94 - .../html/man3/X509_NAME_add_entry_by_txt.html | 119 - .../openssl/html/man3/X509_NAME_get0_der.html | 57 - .../html/man3/X509_NAME_get_index_by_NID.html | 115 - .../openssl/html/man3/X509_NAME_print_ex.html | 108 - .../openssl/html/man3/X509_PUBKEY_new.html | 147 -- .../openssl/html/man3/X509_REQ_get_attr.html | 102 - .../html/man3/X509_REQ_get_extensions.html | 60 - .../doc/openssl/html/man3/X509_SIG_get0.html | 59 - .../man3/X509_STORE_CTX_get_by_subject.html | 65 - .../html/man3/X509_STORE_CTX_get_error.html | 565 ----- .../openssl/html/man3/X509_STORE_CTX_new.html | 181 -- .../man3/X509_STORE_CTX_set_verify_cb.html | 200 -- .../html/man3/X509_STORE_add_cert.html | 119 - .../html/man3/X509_STORE_get0_param.html | 81 - .../doc/openssl/html/man3/X509_STORE_new.html | 75 - .../man3/X509_STORE_set_verify_cb_func.html | 181 -- .../man3/X509_VERIFY_PARAM_set_flags.html | 246 -- .../doc/openssl/html/man3/X509_add_cert.html | 83 - .../doc/openssl/html/man3/X509_check_ca.html | 60 - .../openssl/html/man3/X509_check_host.html | 128 - .../openssl/html/man3/X509_check_issued.html | 56 - .../html/man3/X509_check_private_key.html | 67 - .../openssl/html/man3/X509_check_purpose.html | 114 - .../share/doc/openssl/html/man3/X509_cmp.html | 81 - .../doc/openssl/html/man3/X509_cmp_time.html | 86 - .../doc/openssl/html/man3/X509_digest.html | 90 - .../share/doc/openssl/html/man3/X509_dup.html | 96 - .../man3/X509_get0_distinguishing_id.html | 79 - .../html/man3/X509_get0_notBefore.html | 103 - .../html/man3/X509_get0_signature.html | 125 - .../doc/openssl/html/man3/X509_get0_uids.html | 75 - .../html/man3/X509_get_default_cert_file.html | 71 - .../html/man3/X509_get_extension_flags.html | 190 -- .../openssl/html/man3/X509_get_pubkey.html | 77 - .../html/man3/X509_get_serialNumber.html | 78 - .../html/man3/X509_get_subject_name.html | 112 - .../openssl/html/man3/X509_get_version.html | 84 - .../doc/openssl/html/man3/X509_load_http.html | 75 - .../share/doc/openssl/html/man3/X509_new.html | 93 - .../doc/openssl/html/man3/X509_sign.html | 86 - .../doc/openssl/html/man3/X509_verify.html | 80 - .../openssl/html/man3/X509_verify_cert.html | 83 - .../html/man3/X509v3_get_ext_by_NID.html | 140 -- .../doc/openssl/html/man3/b2i_PVK_bio_ex.html | 76 - .../html/man3/d2i_PKCS8PrivateKey_bio.html | 86 - .../doc/openssl/html/man3/d2i_PrivateKey.html | 114 - .../openssl/html/man3/d2i_RSAPrivateKey.html | 231 -- .../openssl/html/man3/d2i_SSL_SESSION.html | 70 - .../share/doc/openssl/html/man3/d2i_X509.html | 242 -- .../openssl/html/man3/i2d_CMS_bio_stream.html | 73 - .../html/man3/i2d_PKCS7_bio_stream.html | 73 - .../openssl/html/man3/i2d_re_X509_tbs.html | 74 - .../doc/openssl/html/man3/o2i_SCT_LIST.html | 65 - .../openssl/html/man3/s2i_ASN1_IA5STRING.html | 97 - .../share/doc/openssl/html/man5/config.html | 501 ---- .../doc/openssl/html/man5/fips_config.html | 307 --- .../doc/openssl/html/man5/x509v3_config.html | 540 ---- .../html/man7/EVP_ASYM_CIPHER-RSA.html | 168 -- .../html/man7/EVP_ASYM_CIPHER-SM2.html | 64 - .../doc/openssl/html/man7/EVP_CIPHER-AES.html | 135 - .../openssl/html/man7/EVP_CIPHER-ARIA.html | 93 - .../html/man7/EVP_CIPHER-BLOWFISH.html | 77 - .../html/man7/EVP_CIPHER-CAMELLIA.html | 85 - .../openssl/html/man7/EVP_CIPHER-CAST.html | 77 - .../openssl/html/man7/EVP_CIPHER-CHACHA.html | 69 - .../doc/openssl/html/man7/EVP_CIPHER-DES.html | 125 - .../openssl/html/man7/EVP_CIPHER-IDEA.html | 77 - .../openssl/html/man7/EVP_CIPHER-NULL.html | 112 - .../doc/openssl/html/man7/EVP_CIPHER-RC2.html | 85 - .../doc/openssl/html/man7/EVP_CIPHER-RC4.html | 73 - .../doc/openssl/html/man7/EVP_CIPHER-RC5.html | 79 - .../openssl/html/man7/EVP_CIPHER-SEED.html | 77 - .../doc/openssl/html/man7/EVP_CIPHER-SM4.html | 98 - .../doc/openssl/html/man7/EVP_KDF-ARGON2.html | 216 -- .../doc/openssl/html/man7/EVP_KDF-HKDF.html | 190 -- .../openssl/html/man7/EVP_KDF-HMAC-DRBG.html | 101 - .../doc/openssl/html/man7/EVP_KDF-KB.html | 232 -- .../openssl/html/man7/EVP_KDF-KRB5KDF.html | 133 - .../doc/openssl/html/man7/EVP_KDF-PBKDF1.html | 108 - .../doc/openssl/html/man7/EVP_KDF-PBKDF2.html | 142 -- .../openssl/html/man7/EVP_KDF-PKCS12KDF.html | 112 - .../doc/openssl/html/man7/EVP_KDF-PVKKDF.html | 95 - .../doc/openssl/html/man7/EVP_KDF-SCRYPT.html | 164 -- .../doc/openssl/html/man7/EVP_KDF-SS.html | 242 -- .../doc/openssl/html/man7/EVP_KDF-SSHKDF.html | 214 -- .../openssl/html/man7/EVP_KDF-TLS13_KDF.html | 177 -- .../openssl/html/man7/EVP_KDF-TLS1_PRF.html | 169 -- .../openssl/html/man7/EVP_KDF-X942-ASN1.html | 198 -- .../html/man7/EVP_KDF-X942-CONCAT.html | 56 - .../doc/openssl/html/man7/EVP_KDF-X963.html | 160 -- .../doc/openssl/html/man7/EVP_KEM-EC.html | 94 - .../doc/openssl/html/man7/EVP_KEM-RSA.html | 100 - .../doc/openssl/html/man7/EVP_KEM-X25519.html | 94 - .../doc/openssl/html/man7/EVP_KEYEXCH-DH.html | 156 -- .../openssl/html/man7/EVP_KEYEXCH-ECDH.html | 157 -- .../openssl/html/man7/EVP_KEYEXCH-X25519.html | 73 - .../doc/openssl/html/man7/EVP_MAC-BLAKE2.html | 110 - .../doc/openssl/html/man7/EVP_MAC-CMAC.html | 125 - .../doc/openssl/html/man7/EVP_MAC-GMAC.html | 111 - .../doc/openssl/html/man7/EVP_MAC-HMAC.html | 137 -- .../doc/openssl/html/man7/EVP_MAC-KMAC.html | 191 -- .../openssl/html/man7/EVP_MAC-Poly1305.html | 98 - .../openssl/html/man7/EVP_MAC-Siphash.html | 95 - .../doc/openssl/html/man7/EVP_MD-BLAKE2.html | 108 - .../doc/openssl/html/man7/EVP_MD-KECCAK.html | 77 - .../doc/openssl/html/man7/EVP_MD-MD2.html | 57 - .../doc/openssl/html/man7/EVP_MD-MD4.html | 57 - .../openssl/html/man7/EVP_MD-MD5-SHA1.html | 74 - .../doc/openssl/html/man7/EVP_MD-MD5.html | 57 - .../doc/openssl/html/man7/EVP_MD-MDC2.html | 72 - .../doc/openssl/html/man7/EVP_MD-NULL.html | 65 - .../openssl/html/man7/EVP_MD-RIPEMD160.html | 62 - .../doc/openssl/html/man7/EVP_MD-SHA1.html | 72 - .../doc/openssl/html/man7/EVP_MD-SHA2.html | 117 - .../doc/openssl/html/man7/EVP_MD-SHA3.html | 77 - .../doc/openssl/html/man7/EVP_MD-SHAKE.html | 121 - .../doc/openssl/html/man7/EVP_MD-SM3.html | 57 - .../openssl/html/man7/EVP_MD-WHIRLPOOL.html | 57 - .../doc/openssl/html/man7/EVP_MD-common.html | 74 - .../doc/openssl/html/man7/EVP_PKEY-DH.html | 337 --- .../doc/openssl/html/man7/EVP_PKEY-DSA.html | 156 -- .../doc/openssl/html/man7/EVP_PKEY-EC.html | 322 --- .../doc/openssl/html/man7/EVP_PKEY-FFC.html | 266 -- .../doc/openssl/html/man7/EVP_PKEY-HMAC.html | 121 - .../doc/openssl/html/man7/EVP_PKEY-RSA.html | 364 --- .../doc/openssl/html/man7/EVP_PKEY-SM2.html | 105 - .../openssl/html/man7/EVP_PKEY-X25519.html | 154 -- .../openssl/html/man7/EVP_RAND-CRNG-TEST.html | 99 - .../openssl/html/man7/EVP_RAND-CTR-DRBG.html | 160 -- .../openssl/html/man7/EVP_RAND-HASH-DRBG.html | 194 -- .../openssl/html/man7/EVP_RAND-HMAC-DRBG.html | 199 -- .../openssl/html/man7/EVP_RAND-JITTER.html | 120 - .../openssl/html/man7/EVP_RAND-SEED-SRC.html | 116 - .../openssl/html/man7/EVP_RAND-TEST-RAND.html | 175 -- .../share/doc/openssl/html/man7/EVP_RAND.html | 234 -- .../openssl/html/man7/EVP_SIGNATURE-DSA.html | 170 -- .../html/man7/EVP_SIGNATURE-ECDSA.html | 163 -- .../html/man7/EVP_SIGNATURE-ED25519.html | 161 -- .../openssl/html/man7/EVP_SIGNATURE-HMAC.html | 50 - .../openssl/html/man7/EVP_SIGNATURE-RSA.html | 273 -- .../openssl/html/man7/OSSL_PROVIDER-FIPS.html | 730 ------ .../openssl/html/man7/OSSL_PROVIDER-base.html | 257 -- .../html/man7/OSSL_PROVIDER-default.html | 638 ----- .../html/man7/OSSL_PROVIDER-legacy.html | 168 -- .../openssl/html/man7/OSSL_PROVIDER-null.html | 64 - .../html/man7/OSSL_STORE-winstore.html | 101 - .../share/doc/openssl/html/man7/RAND.html | 59 - .../share/doc/openssl/html/man7/RSA-PSS.html | 73 - .../share/doc/openssl/html/man7/X25519.html | 80 - .../share/doc/openssl/html/man7/bio.html | 101 - .../share/doc/openssl/html/man7/ct.html | 58 - .../doc/openssl/html/man7/des_modes.html | 214 -- .../share/doc/openssl/html/man7/evp.html | 83 - .../doc/openssl/html/man7/fips_module.html | 503 ---- .../doc/openssl/html/man7/img/cipher.png | Bin 81349 -> 0 bytes .../doc/openssl/html/man7/img/digest.png | Bin 84676 -> 0 bytes .../share/doc/openssl/html/man7/img/kdf.png | Bin 22285 -> 0 bytes .../share/doc/openssl/html/man7/img/mac.png | Bin 42741 -> 0 bytes .../share/doc/openssl/html/man7/img/pkey.png | Bin 148963 -> 0 bytes .../share/doc/openssl/html/man7/img/rand.png | Bin 30526 -> 0 bytes .../openssl/html/man7/life_cycle-cipher.html | 312 --- .../openssl/html/man7/life_cycle-digest.html | 227 -- .../doc/openssl/html/man7/life_cycle-kdf.html | 147 -- .../doc/openssl/html/man7/life_cycle-mac.html | 191 -- .../openssl/html/man7/life_cycle-pkey.html | 637 ----- .../openssl/html/man7/life_cycle-rand.html | 168 -- .../doc/openssl/html/man7/openssl-core.h.html | 84 - .../html/man7/openssl-core_dispatch.h.html | 76 - .../html/man7/openssl-core_names.h.html | 63 - .../doc/openssl/html/man7/openssl-env.html | 255 -- .../openssl/html/man7/openssl-glossary.html | 245 -- .../doc/openssl/html/man7/openssl-qlog.html | 266 -- .../doc/openssl/html/man7/openssl-quic.html | 574 ----- .../openssl/html/man7/openssl-threads.html | 69 - .../html/man7/openssl_user_macros.html | 123 - .../html/man7/ossl-guide-introduction.html | 113 - .../ossl-guide-libcrypto-introduction.html | 336 --- .../ossl-guide-libraries-introduction.html | 211 -- .../man7/ossl-guide-libssl-introduction.html | 96 - .../html/man7/ossl-guide-migration.html | 1744 ------------- .../man7/ossl-guide-quic-client-block.html | 295 --- .../ossl-guide-quic-client-non-block.html | 330 --- .../man7/ossl-guide-quic-introduction.html | 136 - .../man7/ossl-guide-quic-multi-stream.html | 277 --- .../man7/ossl-guide-tls-client-block.html | 465 ---- .../man7/ossl-guide-tls-client-non-block.html | 286 --- .../man7/ossl-guide-tls-introduction.html | 163 -- .../man7/ossl-guide-tls-server-block.html | 275 --- .../openssl/html/man7/ossl_store-file.html | 60 - .../doc/openssl/html/man7/ossl_store.html | 110 - .../html/man7/passphrase-encoding.html | 124 - .../share/doc/openssl/html/man7/property.html | 134 - .../html/man7/provider-asym_cipher.html | 255 -- .../doc/openssl/html/man7/provider-base.html | 830 ------- .../openssl/html/man7/provider-cipher.html | 177 -- .../openssl/html/man7/provider-decoder.html | 293 --- .../openssl/html/man7/provider-digest.html | 241 -- .../openssl/html/man7/provider-encoder.html | 288 --- .../doc/openssl/html/man7/provider-kdf.html | 384 --- .../doc/openssl/html/man7/provider-kem.html | 199 -- .../openssl/html/man7/provider-keyexch.html | 224 -- .../openssl/html/man7/provider-keymgmt.html | 397 --- .../doc/openssl/html/man7/provider-mac.html | 230 -- .../openssl/html/man7/provider-object.html | 181 -- .../doc/openssl/html/man7/provider-rand.html | 303 --- .../openssl/html/man7/provider-signature.html | 466 ---- .../openssl/html/man7/provider-storemgmt.html | 205 -- .../share/doc/openssl/html/man7/provider.html | 229 -- .../openssl/html/man7/proxy-certificates.html | 343 --- .../share/doc/openssl/html/man7/x509.html | 67 - openssl-install/share/man/man1/CA.pl.1ossl | 317 --- .../share/man/man1/asn1parse.1ossl | 1 - openssl-install/share/man/man1/c_rehash.1ossl | 1 - openssl-install/share/man/man1/ca.1ossl | 1 - openssl-install/share/man/man1/ciphers.1ossl | 1 - openssl-install/share/man/man1/cmp.1ossl | 1 - openssl-install/share/man/man1/cms.1ossl | 1 - openssl-install/share/man/man1/crl.1ossl | 1 - .../share/man/man1/crl2pkcs7.1ossl | 1 - openssl-install/share/man/man1/dgst.1ossl | 1 - openssl-install/share/man/man1/dhparam.1ossl | 1 - openssl-install/share/man/man1/dsa.1ossl | 1 - openssl-install/share/man/man1/dsaparam.1ossl | 1 - openssl-install/share/man/man1/ec.1ossl | 1 - openssl-install/share/man/man1/ecparam.1ossl | 1 - openssl-install/share/man/man1/enc.1ossl | 1 - openssl-install/share/man/man1/engine.1ossl | 1 - openssl-install/share/man/man1/errstr.1ossl | 1 - openssl-install/share/man/man1/gendsa.1ossl | 1 - openssl-install/share/man/man1/genpkey.1ossl | 1 - openssl-install/share/man/man1/genrsa.1ossl | 1 - openssl-install/share/man/man1/info.1ossl | 1 - openssl-install/share/man/man1/kdf.1ossl | 1 - openssl-install/share/man/man1/mac.1ossl | 1 - openssl-install/share/man/man1/nseq.1ossl | 1 - openssl-install/share/man/man1/ocsp.1ossl | 1 - .../share/man/man1/openssl-asn1parse.1ossl | 344 --- .../share/man/man1/openssl-ca.1ossl | 937 ------- .../share/man/man1/openssl-ciphers.1ossl | 926 ------- .../share/man/man1/openssl-cmds.1ossl | 277 --- .../share/man/man1/openssl-cmp.1ossl | 1538 ------------ .../share/man/man1/openssl-cms.1ossl | 1000 -------- .../share/man/man1/openssl-crl.1ossl | 305 --- .../share/man/man1/openssl-crl2pkcs7.1ossl | 238 -- .../share/man/man1/openssl-dgst.1ossl | 402 --- .../share/man/man1/openssl-dhparam.1ossl | 273 -- .../share/man/man1/openssl-dsa.1ossl | 323 --- .../share/man/man1/openssl-dsaparam.1ossl | 259 -- .../share/man/man1/openssl-ec.1ossl | 337 --- .../share/man/man1/openssl-ecparam.1ossl | 321 --- .../share/man/man1/openssl-enc.1ossl | 619 ----- .../share/man/man1/openssl-engine.1ossl | 251 -- .../share/man/man1/openssl-errstr.1ossl | 185 -- .../share/man/man1/openssl-fipsinstall.1ossl | 578 ----- .../man/man1/openssl-format-options.1ossl | 265 -- .../share/man/man1/openssl-gendsa.1ossl | 244 -- .../share/man/man1/openssl-genpkey.1ossl | 634 ----- .../share/man/man1/openssl-genrsa.1ossl | 262 -- .../share/man/man1/openssl-info.1ossl | 214 -- .../share/man/man1/openssl-kdf.1ossl | 358 --- .../share/man/man1/openssl-list.1ossl | 388 --- .../share/man/man1/openssl-mac.1ossl | 305 --- .../man1/openssl-namedisplay-options.1ossl | 286 --- .../share/man/man1/openssl-nseq.1ossl | 211 -- .../share/man/man1/openssl-ocsp.1ossl | 665 ----- .../man/man1/openssl-passphrase-options.1ossl | 203 -- .../share/man/man1/openssl-passwd.1ossl | 250 -- .../share/man/man1/openssl-pkcs12.1ossl | 601 ----- .../share/man/man1/openssl-pkcs7.1ossl | 243 -- .../share/man/man1/openssl-pkcs8.1ossl | 424 ---- .../share/man/man1/openssl-pkey.1ossl | 361 --- .../share/man/man1/openssl-pkeyparam.1ossl | 225 -- .../share/man/man1/openssl-pkeyutl.1ossl | 615 ----- .../share/man/man1/openssl-prime.1ossl | 200 -- .../share/man/man1/openssl-rand.1ossl | 221 -- .../share/man/man1/openssl-rehash.1ossl | 281 --- .../share/man/man1/openssl-req.1ossl | 941 ------- .../share/man/man1/openssl-rsa.1ossl | 341 --- .../share/man/man1/openssl-rsautl.1ossl | 387 --- .../share/man/man1/openssl-s_client.1ossl | 1219 --------- .../share/man/man1/openssl-s_server.1ossl | 1124 --------- .../share/man/man1/openssl-s_time.1ossl | 327 --- .../share/man/man1/openssl-sess_id.1ossl | 267 -- .../share/man/man1/openssl-smime.1ossl | 642 ----- .../share/man/man1/openssl-speed.1ossl | 297 --- .../share/man/man1/openssl-spkac.1ossl | 295 --- .../share/man/man1/openssl-srp.1ossl | 249 -- .../share/man/man1/openssl-storeutl.1ossl | 274 --- .../share/man/man1/openssl-ts.1ossl | 766 ------ .../man1/openssl-verification-options.1ossl | 768 ------ .../share/man/man1/openssl-verify.1ossl | 316 --- .../share/man/man1/openssl-version.1ossl | 231 -- .../share/man/man1/openssl-x509.1ossl | 891 ------- openssl-install/share/man/man1/openssl.1ossl | 775 ------ openssl-install/share/man/man1/passwd.1ossl | 1 - openssl-install/share/man/man1/pkcs12.1ossl | 1 - openssl-install/share/man/man1/pkcs7.1ossl | 1 - openssl-install/share/man/man1/pkcs8.1ossl | 1 - openssl-install/share/man/man1/pkey.1ossl | 1 - .../share/man/man1/pkeyparam.1ossl | 1 - openssl-install/share/man/man1/pkeyutl.1ossl | 1 - openssl-install/share/man/man1/prime.1ossl | 1 - openssl-install/share/man/man1/rand.1ossl | 1 - openssl-install/share/man/man1/rehash.1ossl | 1 - openssl-install/share/man/man1/req.1ossl | 1 - openssl-install/share/man/man1/rsa.1ossl | 1 - openssl-install/share/man/man1/rsautl.1ossl | 1 - openssl-install/share/man/man1/s_client.1ossl | 1 - openssl-install/share/man/man1/s_server.1ossl | 1 - openssl-install/share/man/man1/s_time.1ossl | 1 - openssl-install/share/man/man1/sess_id.1ossl | 1 - openssl-install/share/man/man1/smime.1ossl | 1 - openssl-install/share/man/man1/speed.1ossl | 1 - openssl-install/share/man/man1/spkac.1ossl | 1 - openssl-install/share/man/man1/srp.1ossl | 1 - openssl-install/share/man/man1/storeutl.1ossl | 1 - openssl-install/share/man/man1/ts.1ossl | 1 - openssl-install/share/man/man1/tsget.1ossl | 324 --- openssl-install/share/man/man1/verify.1ossl | 1 - openssl-install/share/man/man1/version.1ossl | 1 - openssl-install/share/man/man1/x509.1ossl | 1 - .../man/man3/ACCESS_DESCRIPTION_free.3ossl | 1 - .../man/man3/ACCESS_DESCRIPTION_new.3ossl | 1 - .../share/man/man3/ADMISSIONS.3ossl | 311 --- .../share/man/man3/ADMISSIONS_free.3ossl | 1 - .../ADMISSIONS_get0_admissionAuthority.3ossl | 1 - .../ADMISSIONS_get0_namingAuthority.3ossl | 1 - .../ADMISSIONS_get0_professionInfos.3ossl | 1 - .../share/man/man3/ADMISSIONS_new.3ossl | 1 - .../ADMISSIONS_set0_admissionAuthority.3ossl | 1 - .../ADMISSIONS_set0_namingAuthority.3ossl | 1 - .../ADMISSIONS_set0_professionInfos.3ossl | 1 - .../share/man/man3/ADMISSION_SYNTAX.3ossl | 1 - .../man/man3/ADMISSION_SYNTAX_free.3ossl | 1 - ...SSION_SYNTAX_get0_admissionAuthority.3ossl | 1 - ...ION_SYNTAX_get0_contentsOfAdmissions.3ossl | 1 - .../share/man/man3/ADMISSION_SYNTAX_new.3ossl | 1 - ...SSION_SYNTAX_set0_admissionAuthority.3ossl | 1 - ...ION_SYNTAX_set0_contentsOfAdmissions.3ossl | 1 - .../share/man/man3/ASIdOrRange_free.3ossl | 1 - .../share/man/man3/ASIdOrRange_new.3ossl | 1 - .../man/man3/ASIdentifierChoice_free.3ossl | 1 - .../man/man3/ASIdentifierChoice_new.3ossl | 1 - .../share/man/man3/ASIdentifiers_free.3ossl | 1 - .../share/man/man3/ASIdentifiers_new.3ossl | 1 - openssl-install/share/man/man3/ASN1_AUX.3ossl | 1 - .../share/man/man3/ASN1_ENUMERATED_get.3ossl | 1 - .../man/man3/ASN1_ENUMERATED_get_int64.3ossl | 1 - .../share/man/man3/ASN1_ENUMERATED_set.3ossl | 1 - .../man/man3/ASN1_ENUMERATED_set_int64.3ossl | 1 - .../man/man3/ASN1_ENUMERATED_to_BN.3ossl | 1 - .../share/man/man3/ASN1_EXTERN_FUNCS.3ossl | 299 --- .../man/man3/ASN1_GENERALIZEDTIME_adj.3ossl | 1 - .../man/man3/ASN1_GENERALIZEDTIME_check.3ossl | 1 - .../man/man3/ASN1_GENERALIZEDTIME_dup.3ossl | 1 - .../man/man3/ASN1_GENERALIZEDTIME_print.3ossl | 1 - .../man/man3/ASN1_GENERALIZEDTIME_set.3ossl | 1 - .../ASN1_GENERALIZEDTIME_set_string.3ossl | 1 - .../share/man/man3/ASN1_INTEGER_free.3ossl | 1 - .../share/man/man3/ASN1_INTEGER_get.3ossl | 1 - .../man/man3/ASN1_INTEGER_get_int64.3ossl | 262 -- .../man/man3/ASN1_INTEGER_get_uint64.3ossl | 1 - .../share/man/man3/ASN1_INTEGER_new.3ossl | 175 -- .../share/man/man3/ASN1_INTEGER_set.3ossl | 1 - .../man/man3/ASN1_INTEGER_set_int64.3ossl | 1 - .../man/man3/ASN1_INTEGER_set_uint64.3ossl | 1 - .../share/man/man3/ASN1_INTEGER_to_BN.3ossl | 1 - .../share/man/man3/ASN1_ITEM.3ossl | 1 - .../share/man/man3/ASN1_ITEM_get.3ossl | 1 - .../share/man/man3/ASN1_ITEM_lookup.3ossl | 171 -- .../share/man/man3/ASN1_OBJECT_free.3ossl | 1 - .../share/man/man3/ASN1_OBJECT_new.3ossl | 182 -- .../share/man/man3/ASN1_PRINT_ARG.3ossl | 1 - .../share/man/man3/ASN1_STREAM_ARG.3ossl | 1 - .../share/man/man3/ASN1_STRING_TABLE.3ossl | 1 - .../man/man3/ASN1_STRING_TABLE_add.3ossl | 196 -- .../man/man3/ASN1_STRING_TABLE_cleanup.3ossl | 1 - .../man/man3/ASN1_STRING_TABLE_get.3ossl | 1 - .../share/man/man3/ASN1_STRING_cmp.3ossl | 1 - .../share/man/man3/ASN1_STRING_data.3ossl | 1 - .../share/man/man3/ASN1_STRING_dup.3ossl | 1 - .../share/man/man3/ASN1_STRING_free.3ossl | 1 - .../man/man3/ASN1_STRING_get0_data.3ossl | 1 - .../share/man/man3/ASN1_STRING_length.3ossl | 244 -- .../share/man/man3/ASN1_STRING_new.3ossl | 183 -- .../share/man/man3/ASN1_STRING_print.3ossl | 1 - .../share/man/man3/ASN1_STRING_print_ex.3ossl | 246 -- .../man/man3/ASN1_STRING_print_ex_fp.3ossl | 1 - .../share/man/man3/ASN1_STRING_set.3ossl | 1 - .../share/man/man3/ASN1_STRING_to_UTF8.3ossl | 1 - .../share/man/man3/ASN1_STRING_type.3ossl | 1 - .../share/man/man3/ASN1_STRING_type_new.3ossl | 1 - .../share/man/man3/ASN1_TIME_adj.3ossl | 1 - .../share/man/man3/ASN1_TIME_check.3ossl | 1 - .../share/man/man3/ASN1_TIME_cmp_time_t.3ossl | 1 - .../share/man/man3/ASN1_TIME_compare.3ossl | 1 - .../share/man/man3/ASN1_TIME_diff.3ossl | 1 - .../share/man/man3/ASN1_TIME_dup.3ossl | 1 - .../share/man/man3/ASN1_TIME_normalize.3ossl | 1 - .../share/man/man3/ASN1_TIME_print.3ossl | 1 - .../share/man/man3/ASN1_TIME_print_ex.3ossl | 1 - .../share/man/man3/ASN1_TIME_set.3ossl | 419 ---- .../share/man/man3/ASN1_TIME_set_string.3ossl | 1 - .../man/man3/ASN1_TIME_set_string_X509.3ossl | 1 - .../man3/ASN1_TIME_to_generalizedtime.3ossl | 1 - .../share/man/man3/ASN1_TIME_to_tm.3ossl | 1 - .../share/man/man3/ASN1_TYPE_cmp.3ossl | 1 - .../share/man/man3/ASN1_TYPE_get.3ossl | 233 -- .../man/man3/ASN1_TYPE_pack_sequence.3ossl | 1 - .../share/man/man3/ASN1_TYPE_set.3ossl | 1 - .../share/man/man3/ASN1_TYPE_set1.3ossl | 1 - .../man/man3/ASN1_TYPE_unpack_sequence.3ossl | 1 - .../share/man/man3/ASN1_UTCTIME_adj.3ossl | 1 - .../share/man/man3/ASN1_UTCTIME_check.3ossl | 1 - .../man/man3/ASN1_UTCTIME_cmp_time_t.3ossl | 1 - .../share/man/man3/ASN1_UTCTIME_dup.3ossl | 1 - .../share/man/man3/ASN1_UTCTIME_print.3ossl | 1 - .../share/man/man3/ASN1_UTCTIME_set.3ossl | 1 - .../man/man3/ASN1_UTCTIME_set_string.3ossl | 1 - .../share/man/man3/ASN1_add_oid_module.3ossl | 1 - .../share/man/man3/ASN1_aux_cb.3ossl | 368 --- .../share/man/man3/ASN1_aux_const_cb.3ossl | 1 - .../share/man/man3/ASN1_ex_d2i.3ossl | 1 - .../share/man/man3/ASN1_ex_d2i_ex.3ossl | 1 - .../share/man/man3/ASN1_ex_free_func.3ossl | 1 - .../share/man/man3/ASN1_ex_i2d.3ossl | 1 - .../share/man/man3/ASN1_ex_new_ex_func.3ossl | 1 - .../share/man/man3/ASN1_ex_new_func.3ossl | 1 - .../share/man/man3/ASN1_ex_print_func.3ossl | 1 - .../share/man/man3/ASN1_generate_nconf.3ossl | 382 --- .../share/man/man3/ASN1_generate_v3.3ossl | 1 - .../share/man/man3/ASN1_item_d2i.3ossl | 1 - .../share/man/man3/ASN1_item_d2i_bio.3ossl | 247 -- .../share/man/man3/ASN1_item_d2i_bio_ex.3ossl | 1 - .../share/man/man3/ASN1_item_d2i_ex.3ossl | 1 - .../share/man/man3/ASN1_item_d2i_fp.3ossl | 1 - .../share/man/man3/ASN1_item_d2i_fp_ex.3ossl | 1 - .../man/man3/ASN1_item_i2d_mem_bio.3ossl | 1 - .../share/man/man3/ASN1_item_new.3ossl | 177 -- .../share/man/man3/ASN1_item_new_ex.3ossl | 1 - .../share/man/man3/ASN1_item_pack.3ossl | 1 - .../share/man/man3/ASN1_item_sign.3ossl | 357 --- .../share/man/man3/ASN1_item_sign_ctx.3ossl | 1 - .../share/man/man3/ASN1_item_sign_ex.3ossl | 1 - .../share/man/man3/ASN1_item_unpack.3ossl | 1 - .../share/man/man3/ASN1_item_unpack_ex.3ossl | 1 - .../share/man/man3/ASN1_item_verify.3ossl | 1 - .../share/man/man3/ASN1_item_verify_ctx.3ossl | 1 - .../share/man/man3/ASN1_item_verify_ex.3ossl | 1 - .../share/man/man3/ASN1_tag2str.3ossl | 1 - .../share/man/man3/ASRange_free.3ossl | 1 - .../share/man/man3/ASRange_new.3ossl | 1 - .../share/man/man3/ASYNC_STATUS_EAGAIN.3ossl | 1 - .../share/man/man3/ASYNC_STATUS_ERR.3ossl | 1 - .../share/man/man3/ASYNC_STATUS_OK.3ossl | 1 - .../man/man3/ASYNC_STATUS_UNSUPPORTED.3ossl | 1 - .../man/man3/ASYNC_WAIT_CTX_clear_fd.3ossl | 1 - .../share/man/man3/ASYNC_WAIT_CTX_free.3ossl | 1 - .../man/man3/ASYNC_WAIT_CTX_get_all_fds.3ossl | 1 - .../man3/ASYNC_WAIT_CTX_get_callback.3ossl | 1 - .../man3/ASYNC_WAIT_CTX_get_changed_fds.3ossl | 1 - .../man/man3/ASYNC_WAIT_CTX_get_fd.3ossl | 1 - .../man/man3/ASYNC_WAIT_CTX_get_status.3ossl | 1 - .../share/man/man3/ASYNC_WAIT_CTX_new.3ossl | 349 --- .../man3/ASYNC_WAIT_CTX_set_callback.3ossl | 1 - .../man/man3/ASYNC_WAIT_CTX_set_status.3ossl | 1 - .../man/man3/ASYNC_WAIT_CTX_set_wait_fd.3ossl | 1 - .../share/man/man3/ASYNC_block_pause.3ossl | 1 - .../share/man/man3/ASYNC_callback_fn.3ossl | 1 - .../share/man/man3/ASYNC_cleanup_thread.3ossl | 1 - .../man/man3/ASYNC_get_current_job.3ossl | 1 - .../man/man3/ASYNC_get_mem_functions.3ossl | 1 - .../share/man/man3/ASYNC_get_wait_ctx.3ossl | 1 - .../share/man/man3/ASYNC_init_thread.3ossl | 1 - .../share/man/man3/ASYNC_is_capable.3ossl | 1 - .../share/man/man3/ASYNC_pause_job.3ossl | 1 - .../man/man3/ASYNC_set_mem_functions.3ossl | 1 - .../share/man/man3/ASYNC_stack_alloc_fn.3ossl | 1 - .../share/man/man3/ASYNC_stack_free_fn.3ossl | 1 - .../share/man/man3/ASYNC_start_job.3ossl | 501 ---- .../share/man/man3/ASYNC_unblock_pause.3ossl | 1 - .../man/man3/AUTHORITY_INFO_ACCESS_free.3ossl | 1 - .../man/man3/AUTHORITY_INFO_ACCESS_new.3ossl | 1 - .../share/man/man3/AUTHORITY_KEYID_free.3ossl | 1 - .../share/man/man3/AUTHORITY_KEYID_new.3ossl | 1 - .../man/man3/BASIC_CONSTRAINTS_free.3ossl | 1 - .../man/man3/BASIC_CONSTRAINTS_new.3ossl | 1 - .../share/man/man3/BF_cbc_encrypt.3ossl | 1 - .../share/man/man3/BF_cfb64_encrypt.3ossl | 1 - .../share/man/man3/BF_decrypt.3ossl | 1 - .../share/man/man3/BF_ecb_encrypt.3ossl | 1 - .../share/man/man3/BF_encrypt.3ossl | 263 -- .../share/man/man3/BF_ofb64_encrypt.3ossl | 1 - .../share/man/man3/BF_options.3ossl | 1 - .../share/man/man3/BF_set_key.3ossl | 1 - openssl-install/share/man/man3/BIO_ADDR.3ossl | 271 -- .../share/man/man3/BIO_ADDRINFO.3ossl | 244 -- .../share/man/man3/BIO_ADDRINFO_address.3ossl | 1 - .../share/man/man3/BIO_ADDRINFO_family.3ossl | 1 - .../share/man/man3/BIO_ADDRINFO_free.3ossl | 1 - .../share/man/man3/BIO_ADDRINFO_next.3ossl | 1 - .../man/man3/BIO_ADDRINFO_protocol.3ossl | 1 - .../man/man3/BIO_ADDRINFO_socktype.3ossl | 1 - .../share/man/man3/BIO_ADDR_clear.3ossl | 1 - .../share/man/man3/BIO_ADDR_copy.3ossl | 1 - .../share/man/man3/BIO_ADDR_dup.3ossl | 1 - .../share/man/man3/BIO_ADDR_family.3ossl | 1 - .../share/man/man3/BIO_ADDR_free.3ossl | 1 - .../man/man3/BIO_ADDR_hostname_string.3ossl | 1 - .../share/man/man3/BIO_ADDR_new.3ossl | 1 - .../share/man/man3/BIO_ADDR_path_string.3ossl | 1 - .../share/man/man3/BIO_ADDR_rawaddress.3ossl | 1 - .../share/man/man3/BIO_ADDR_rawmake.3ossl | 1 - .../share/man/man3/BIO_ADDR_rawport.3ossl | 1 - .../man/man3/BIO_ADDR_service_string.3ossl | 1 - .../share/man/man3/BIO_accept_ex.3ossl | 1 - .../share/man/man3/BIO_append_filename.3ossl | 1 - openssl-install/share/man/man3/BIO_bind.3ossl | 1 - .../share/man/man3/BIO_callback_ctrl.3ossl | 1 - .../share/man/man3/BIO_callback_fn.3ossl | 1 - .../share/man/man3/BIO_callback_fn_ex.3ossl | 1 - .../share/man/man3/BIO_closesocket.3ossl | 1 - .../share/man/man3/BIO_connect.3ossl | 249 -- openssl-install/share/man/man3/BIO_ctrl.3ossl | 321 --- .../man/man3/BIO_ctrl_dgram_connect.3ossl | 1 - .../man/man3/BIO_ctrl_get_read_request.3ossl | 1 - .../man3/BIO_ctrl_get_write_guarantee.3ossl | 1 - .../share/man/man3/BIO_ctrl_pending.3ossl | 1 - .../man3/BIO_ctrl_reset_read_request.3ossl | 1 - .../man/man3/BIO_ctrl_set_connected.3ossl | 1 - .../share/man/man3/BIO_ctrl_wpending.3ossl | 1 - .../share/man/man3/BIO_debug_callback.3ossl | 1 - .../man/man3/BIO_debug_callback_ex.3ossl | 1 - .../share/man/man3/BIO_destroy_bio_pair.3ossl | 1 - .../man/man3/BIO_dgram_detect_peer_addr.3ossl | 1 - .../share/man/man3/BIO_dgram_get_caps.3ossl | 1 - .../man3/BIO_dgram_get_effective_caps.3ossl | 1 - .../man3/BIO_dgram_get_local_addr_cap.3ossl | 1 - .../BIO_dgram_get_local_addr_enable.3ossl | 1 - .../share/man/man3/BIO_dgram_get_mtu.3ossl | 1 - .../man/man3/BIO_dgram_get_mtu_overhead.3ossl | 1 - .../man/man3/BIO_dgram_get_no_trunc.3ossl | 1 - .../share/man/man3/BIO_dgram_get_peer.3ossl | 1 - .../man/man3/BIO_dgram_recv_timedout.3ossl | 1 - .../man/man3/BIO_dgram_send_timedout.3ossl | 1 - .../share/man/man3/BIO_dgram_set_caps.3ossl | 1 - .../BIO_dgram_set_local_addr_enable.3ossl | 1 - .../share/man/man3/BIO_dgram_set_mtu.3ossl | 1 - .../man/man3/BIO_dgram_set_no_trunc.3ossl | 1 - .../share/man/man3/BIO_dgram_set_peer.3ossl | 1 - .../share/man/man3/BIO_do_accept.3ossl | 1 - .../share/man/man3/BIO_do_connect.3ossl | 1 - .../share/man/man3/BIO_do_connect_retry.3ossl | 1 - .../share/man/man3/BIO_do_handshake.3ossl | 1 - openssl-install/share/man/man3/BIO_eof.3ossl | 1 - .../share/man/man3/BIO_err_is_non_fatal.3ossl | 1 - .../share/man/man3/BIO_f_base64.3ossl | 267 -- .../share/man/man3/BIO_f_brotli.3ossl | 1 - .../share/man/man3/BIO_f_buffer.3ossl | 234 -- .../share/man/man3/BIO_f_cipher.3ossl | 211 -- openssl-install/share/man/man3/BIO_f_md.3ossl | 295 --- .../share/man/man3/BIO_f_null.3ossl | 171 -- .../share/man/man3/BIO_f_prefix.3ossl | 201 -- .../share/man/man3/BIO_f_readbuffer.3ossl | 192 -- .../share/man/man3/BIO_f_ssl.3ossl | 446 ---- .../share/man/man3/BIO_f_zlib.3ossl | 1 - .../share/man/man3/BIO_f_zstd.3ossl | 1 - .../share/man/man3/BIO_find_type.3ossl | 203 -- .../share/man/man3/BIO_flush.3ossl | 1 - openssl-install/share/man/man3/BIO_free.3ossl | 1 - .../share/man/man3/BIO_free_all.3ossl | 1 - .../share/man/man3/BIO_get0_dgram_bio.3ossl | 1 - .../man/man3/BIO_get_accept_ip_family.3ossl | 1 - .../share/man/man3/BIO_get_accept_name.3ossl | 1 - .../share/man/man3/BIO_get_accept_port.3ossl | 1 - .../share/man/man3/BIO_get_app_data.3ossl | 1 - .../share/man/man3/BIO_get_bind_mode.3ossl | 1 - .../man/man3/BIO_get_buffer_num_lines.3ossl | 1 - .../share/man/man3/BIO_get_callback.3ossl | 1 - .../share/man/man3/BIO_get_callback_arg.3ossl | 1 - .../share/man/man3/BIO_get_callback_ex.3ossl | 1 - .../share/man/man3/BIO_get_cipher_ctx.3ossl | 1 - .../man/man3/BIO_get_cipher_status.3ossl | 1 - .../share/man/man3/BIO_get_close.3ossl | 1 - .../share/man/man3/BIO_get_conn_address.3ossl | 1 - .../man/man3/BIO_get_conn_hostname.3ossl | 1 - .../man/man3/BIO_get_conn_ip_family.3ossl | 1 - .../share/man/man3/BIO_get_conn_mode.3ossl | 1 - .../share/man/man3/BIO_get_conn_port.3ossl | 1 - .../share/man/man3/BIO_get_data.3ossl | 196 -- .../share/man/man3/BIO_get_ex_data.3ossl | 1 - .../share/man/man3/BIO_get_ex_new_index.3ossl | 266 -- .../share/man/man3/BIO_get_fd.3ossl | 1 - .../share/man/man3/BIO_get_fp.3ossl | 1 - .../share/man/man3/BIO_get_indent.3ossl | 1 - .../man/man3/BIO_get_info_callback.3ossl | 1 - .../share/man/man3/BIO_get_init.3ossl | 1 - .../share/man/man3/BIO_get_ktls_recv.3ossl | 1 - .../share/man/man3/BIO_get_ktls_send.3ossl | 1 - .../share/man/man3/BIO_get_line.3ossl | 1 - .../share/man/man3/BIO_get_md.3ossl | 1 - .../share/man/man3/BIO_get_md_ctx.3ossl | 1 - .../share/man/man3/BIO_get_mem_data.3ossl | 1 - .../share/man/man3/BIO_get_mem_ptr.3ossl | 1 - .../share/man/man3/BIO_get_new_index.3ossl | 1 - .../man/man3/BIO_get_num_renegotiates.3ossl | 1 - .../share/man/man3/BIO_get_peer_name.3ossl | 1 - .../share/man/man3/BIO_get_peer_port.3ossl | 1 - .../share/man/man3/BIO_get_read_request.3ossl | 1 - .../share/man/man3/BIO_get_retry_BIO.3ossl | 1 - .../share/man/man3/BIO_get_retry_reason.3ossl | 1 - .../man/man3/BIO_get_rpoll_descriptor.3ossl | 236 -- .../share/man/man3/BIO_get_shutdown.3ossl | 1 - .../share/man/man3/BIO_get_sock_type.3ossl | 1 - .../share/man/man3/BIO_get_ssl.3ossl | 1 - .../man/man3/BIO_get_wpoll_descriptor.3ossl | 1 - .../man/man3/BIO_get_write_buf_size.3ossl | 1 - .../man/man3/BIO_get_write_guarantee.3ossl | 1 - openssl-install/share/man/man3/BIO_gets.3ossl | 1 - .../man/man3/BIO_hostserv_priorities.3ossl | 1 - .../share/man/man3/BIO_info_cb.3ossl | 1 - .../share/man/man3/BIO_int_ctrl.3ossl | 1 - .../share/man/man3/BIO_listen.3ossl | 1 - .../share/man/man3/BIO_lookup.3ossl | 1 - .../share/man/man3/BIO_lookup_ex.3ossl | 1 - .../share/man/man3/BIO_lookup_type.3ossl | 1 - .../share/man/man3/BIO_make_bio_pair.3ossl | 1 - .../share/man/man3/BIO_meth_free.3ossl | 1 - .../man/man3/BIO_meth_get_callback_ctrl.3ossl | 1 - .../share/man/man3/BIO_meth_get_create.3ossl | 1 - .../share/man/man3/BIO_meth_get_ctrl.3ossl | 1 - .../share/man/man3/BIO_meth_get_destroy.3ossl | 1 - .../share/man/man3/BIO_meth_get_gets.3ossl | 1 - .../share/man/man3/BIO_meth_get_puts.3ossl | 1 - .../share/man/man3/BIO_meth_get_read.3ossl | 1 - .../share/man/man3/BIO_meth_get_read_ex.3ossl | 1 - .../man/man3/BIO_meth_get_recvmmsg.3ossl | 1 - .../man/man3/BIO_meth_get_sendmmsg.3ossl | 1 - .../share/man/man3/BIO_meth_get_write.3ossl | 1 - .../man/man3/BIO_meth_get_write_ex.3ossl | 1 - .../share/man/man3/BIO_meth_new.3ossl | 326 --- .../man/man3/BIO_meth_set_callback_ctrl.3ossl | 1 - .../share/man/man3/BIO_meth_set_create.3ossl | 1 - .../share/man/man3/BIO_meth_set_ctrl.3ossl | 1 - .../share/man/man3/BIO_meth_set_destroy.3ossl | 1 - .../share/man/man3/BIO_meth_set_gets.3ossl | 1 - .../share/man/man3/BIO_meth_set_puts.3ossl | 1 - .../share/man/man3/BIO_meth_set_read.3ossl | 1 - .../share/man/man3/BIO_meth_set_read_ex.3ossl | 1 - .../man/man3/BIO_meth_set_recvmmsg.3ossl | 1 - .../man/man3/BIO_meth_set_sendmmsg.3ossl | 1 - .../share/man/man3/BIO_meth_set_write.3ossl | 1 - .../man/man3/BIO_meth_set_write_ex.3ossl | 1 - .../share/man/man3/BIO_method_type.3ossl | 1 - openssl-install/share/man/man3/BIO_new.3ossl | 211 -- .../share/man/man3/BIO_new_CMS.3ossl | 204 -- .../share/man/man3/BIO_new_accept.3ossl | 1 - .../man/man3/BIO_new_bio_dgram_pair.3ossl | 1 - .../share/man/man3/BIO_new_bio_pair.3ossl | 1 - .../man/man3/BIO_new_buffer_ssl_connect.3ossl | 1 - .../share/man/man3/BIO_new_connect.3ossl | 1 - .../share/man/man3/BIO_new_dgram.3ossl | 1 - .../share/man/man3/BIO_new_ex.3ossl | 1 - .../share/man/man3/BIO_new_fd.3ossl | 1 - .../share/man/man3/BIO_new_file.3ossl | 1 - .../share/man/man3/BIO_new_fp.3ossl | 1 - .../man/man3/BIO_new_from_core_bio.3ossl | 1 - .../share/man/man3/BIO_new_mem_buf.3ossl | 1 - .../share/man/man3/BIO_new_socket.3ossl | 1 - .../share/man/man3/BIO_new_ssl.3ossl | 1 - .../share/man/man3/BIO_new_ssl_connect.3ossl | 1 - openssl-install/share/man/man3/BIO_next.3ossl | 1 - .../share/man/man3/BIO_parse_hostserv.3ossl | 215 -- .../share/man/man3/BIO_pending.3ossl | 1 - openssl-install/share/man/man3/BIO_pop.3ossl | 1 - .../share/man/man3/BIO_printf.3ossl | 189 -- .../share/man/man3/BIO_ptr_ctrl.3ossl | 1 - openssl-install/share/man/man3/BIO_push.3ossl | 233 -- openssl-install/share/man/man3/BIO_puts.3ossl | 1 - openssl-install/share/man/man3/BIO_read.3ossl | 259 -- .../share/man/man3/BIO_read_ex.3ossl | 1 - .../share/man/man3/BIO_read_filename.3ossl | 1 - .../share/man/man3/BIO_recvmmsg.3ossl | 1 - .../share/man/man3/BIO_reset.3ossl | 1 - .../share/man/man3/BIO_retry_type.3ossl | 1 - .../share/man/man3/BIO_rw_filename.3ossl | 1 - .../share/man/man3/BIO_s_accept.3ossl | 388 --- .../share/man/man3/BIO_s_bio.3ossl | 332 --- .../share/man/man3/BIO_s_connect.3ossl | 366 --- .../share/man/man3/BIO_s_core.3ossl | 205 -- .../share/man/man3/BIO_s_datagram.3ossl | 367 --- .../share/man/man3/BIO_s_dgram_mem.3ossl | 1 - .../share/man/man3/BIO_s_dgram_pair.3ossl | 343 --- openssl-install/share/man/man3/BIO_s_fd.3ossl | 230 -- .../share/man/man3/BIO_s_file.3ossl | 304 --- .../share/man/man3/BIO_s_mem.3ossl | 351 --- .../share/man/man3/BIO_s_null.3ossl | 176 -- .../share/man/man3/BIO_s_secmem.3ossl | 1 - .../share/man/man3/BIO_s_socket.3ossl | 186 -- openssl-install/share/man/man3/BIO_seek.3ossl | 1 - .../share/man/man3/BIO_sendmmsg.3ossl | 350 --- .../share/man/man3/BIO_set_accept_bios.3ossl | 1 - .../man/man3/BIO_set_accept_ip_family.3ossl | 1 - .../share/man/man3/BIO_set_accept_name.3ossl | 1 - .../share/man/man3/BIO_set_accept_port.3ossl | 1 - .../share/man/man3/BIO_set_app_data.3ossl | 1 - .../share/man/man3/BIO_set_bind_mode.3ossl | 1 - .../man/man3/BIO_set_buffer_read_data.3ossl | 1 - .../share/man/man3/BIO_set_buffer_size.3ossl | 1 - .../share/man/man3/BIO_set_callback.3ossl | 453 ---- .../share/man/man3/BIO_set_callback_arg.3ossl | 1 - .../share/man/man3/BIO_set_callback_ex.3ossl | 1 - .../share/man/man3/BIO_set_cipher.3ossl | 1 - .../share/man/man3/BIO_set_close.3ossl | 1 - .../share/man/man3/BIO_set_conn_address.3ossl | 1 - .../man/man3/BIO_set_conn_hostname.3ossl | 1 - .../man/man3/BIO_set_conn_ip_family.3ossl | 1 - .../share/man/man3/BIO_set_conn_mode.3ossl | 1 - .../share/man/man3/BIO_set_conn_port.3ossl | 1 - .../share/man/man3/BIO_set_data.3ossl | 1 - .../share/man/man3/BIO_set_ex_data.3ossl | 1 - .../share/man/man3/BIO_set_fd.3ossl | 1 - .../share/man/man3/BIO_set_fp.3ossl | 1 - .../share/man/man3/BIO_set_indent.3ossl | 1 - .../man/man3/BIO_set_info_callback.3ossl | 1 - .../share/man/man3/BIO_set_init.3ossl | 1 - .../share/man/man3/BIO_set_md.3ossl | 1 - .../share/man/man3/BIO_set_mem_buf.3ossl | 1 - .../man/man3/BIO_set_mem_eof_return.3ossl | 1 - .../share/man/man3/BIO_set_nbio.3ossl | 1 - .../share/man/man3/BIO_set_nbio_accept.3ossl | 1 - .../share/man/man3/BIO_set_next.3ossl | 1 - .../share/man/man3/BIO_set_prefix.3ossl | 1 - .../man/man3/BIO_set_read_buffer_size.3ossl | 1 - .../share/man/man3/BIO_set_retry_reason.3ossl | 1 - .../share/man/man3/BIO_set_shutdown.3ossl | 1 - .../share/man/man3/BIO_set_sock_type.3ossl | 1 - .../share/man/man3/BIO_set_ssl.3ossl | 1 - .../share/man/man3/BIO_set_ssl_mode.3ossl | 1 - .../man3/BIO_set_ssl_renegotiate_bytes.3ossl | 1 - .../BIO_set_ssl_renegotiate_timeout.3ossl | 1 - .../share/man/man3/BIO_set_tfo.3ossl | 1 - .../share/man/man3/BIO_set_tfo_accept.3ossl | 1 - .../man/man3/BIO_set_write_buf_size.3ossl | 1 - .../man/man3/BIO_set_write_buffer_size.3ossl | 1 - .../man/man3/BIO_should_io_special.3ossl | 1 - .../share/man/man3/BIO_should_read.3ossl | 1 - .../share/man/man3/BIO_should_retry.3ossl | 276 --- .../share/man/man3/BIO_should_write.3ossl | 1 - .../share/man/man3/BIO_shutdown_wr.3ossl | 1 - .../share/man/man3/BIO_snprintf.3ossl | 1 - .../share/man/man3/BIO_socket.3ossl | 1 - .../share/man/man3/BIO_socket_wait.3ossl | 200 -- .../man/man3/BIO_ssl_copy_session_id.3ossl | 1 - .../share/man/man3/BIO_ssl_shutdown.3ossl | 1 - openssl-install/share/man/man3/BIO_tell.3ossl | 1 - .../share/man/man3/BIO_up_ref.3ossl | 1 - .../share/man/man3/BIO_vfree.3ossl | 1 - .../share/man/man3/BIO_vprintf.3ossl | 1 - .../share/man/man3/BIO_vsnprintf.3ossl | 1 - openssl-install/share/man/man3/BIO_wait.3ossl | 1 - .../share/man/man3/BIO_wpending.3ossl | 1 - .../share/man/man3/BIO_write.3ossl | 1 - .../share/man/man3/BIO_write_ex.3ossl | 1 - .../share/man/man3/BIO_write_filename.3ossl | 1 - .../share/man/man3/BN_BLINDING_convert.3ossl | 1 - .../man/man3/BN_BLINDING_convert_ex.3ossl | 1 - .../man/man3/BN_BLINDING_create_param.3ossl | 1 - .../share/man/man3/BN_BLINDING_free.3ossl | 1 - .../man/man3/BN_BLINDING_get_flags.3ossl | 1 - .../share/man/man3/BN_BLINDING_invert.3ossl | 1 - .../man/man3/BN_BLINDING_invert_ex.3ossl | 1 - .../man3/BN_BLINDING_is_current_thread.3ossl | 1 - .../share/man/man3/BN_BLINDING_lock.3ossl | 1 - .../share/man/man3/BN_BLINDING_new.3ossl | 258 -- .../man3/BN_BLINDING_set_current_thread.3ossl | 1 - .../man/man3/BN_BLINDING_set_flags.3ossl | 1 - .../share/man/man3/BN_BLINDING_unlock.3ossl | 1 - .../share/man/man3/BN_BLINDING_update.3ossl | 1 - .../share/man/man3/BN_CTX_end.3ossl | 1 - .../share/man/man3/BN_CTX_free.3ossl | 1 - .../share/man/man3/BN_CTX_get.3ossl | 1 - .../share/man/man3/BN_CTX_new.3ossl | 223 -- .../share/man/man3/BN_CTX_new_ex.3ossl | 1 - .../share/man/man3/BN_CTX_secure_new.3ossl | 1 - .../share/man/man3/BN_CTX_secure_new_ex.3ossl | 1 - .../share/man/man3/BN_CTX_start.3ossl | 189 -- .../share/man/man3/BN_GENCB_call.3ossl | 1 - .../share/man/man3/BN_GENCB_free.3ossl | 1 - .../share/man/man3/BN_GENCB_get_arg.3ossl | 1 - .../share/man/man3/BN_GENCB_new.3ossl | 1 - .../share/man/man3/BN_GENCB_set.3ossl | 1 - .../share/man/man3/BN_GENCB_set_old.3ossl | 1 - .../share/man/man3/BN_MONT_CTX_copy.3ossl | 1 - .../share/man/man3/BN_MONT_CTX_free.3ossl | 1 - .../share/man/man3/BN_MONT_CTX_new.3ossl | 1 - .../share/man/man3/BN_MONT_CTX_set.3ossl | 1 - .../share/man/man3/BN_RECP_CTX_free.3ossl | 1 - .../share/man/man3/BN_RECP_CTX_new.3ossl | 1 - .../share/man/man3/BN_RECP_CTX_set.3ossl | 1 - .../share/man/man3/BN_abs_is_word.3ossl | 1 - openssl-install/share/man/man3/BN_add.3ossl | 276 --- .../share/man/man3/BN_add_word.3ossl | 193 -- .../share/man/man3/BN_are_coprime.3ossl | 1 - .../share/man/man3/BN_bin2bn.3ossl | 1 - .../share/man/man3/BN_bn2bin.3ossl | 281 --- .../share/man/man3/BN_bn2binpad.3ossl | 1 - .../share/man/man3/BN_bn2dec.3ossl | 1 - .../share/man/man3/BN_bn2hex.3ossl | 1 - .../share/man/man3/BN_bn2lebinpad.3ossl | 1 - .../share/man/man3/BN_bn2mpi.3ossl | 1 - .../share/man/man3/BN_bn2nativepad.3ossl | 1 - .../share/man/man3/BN_check_prime.3ossl | 1 - openssl-install/share/man/man3/BN_clear.3ossl | 1 - .../share/man/man3/BN_clear_bit.3ossl | 1 - .../share/man/man3/BN_clear_free.3ossl | 1 - openssl-install/share/man/man3/BN_cmp.3ossl | 196 -- openssl-install/share/man/man3/BN_copy.3ossl | 191 -- .../share/man/man3/BN_dec2bn.3ossl | 1 - openssl-install/share/man/man3/BN_div.3ossl | 1 - .../share/man/man3/BN_div_recp.3ossl | 1 - .../share/man/man3/BN_div_word.3ossl | 1 - openssl-install/share/man/man3/BN_dup.3ossl | 1 - openssl-install/share/man/man3/BN_exp.3ossl | 1 - openssl-install/share/man/man3/BN_free.3ossl | 1 - .../share/man/man3/BN_from_montgomery.3ossl | 1 - openssl-install/share/man/man3/BN_gcd.3ossl | 1 - .../share/man/man3/BN_generate_prime.3ossl | 382 --- .../share/man/man3/BN_generate_prime_ex.3ossl | 1 - .../man/man3/BN_generate_prime_ex2.3ossl | 1 - .../man/man3/BN_get0_nist_prime_192.3ossl | 1 - .../man/man3/BN_get0_nist_prime_224.3ossl | 1 - .../man/man3/BN_get0_nist_prime_256.3ossl | 1 - .../man/man3/BN_get0_nist_prime_384.3ossl | 1 - .../man/man3/BN_get0_nist_prime_521.3ossl | 1 - .../man/man3/BN_get_rfc2409_prime_1024.3ossl | 1 - .../man/man3/BN_get_rfc2409_prime_768.3ossl | 1 - .../man/man3/BN_get_rfc3526_prime_1536.3ossl | 1 - .../man/man3/BN_get_rfc3526_prime_2048.3ossl | 1 - .../man/man3/BN_get_rfc3526_prime_3072.3ossl | 1 - .../man/man3/BN_get_rfc3526_prime_4096.3ossl | 1 - .../man/man3/BN_get_rfc3526_prime_6144.3ossl | 1 - .../man/man3/BN_get_rfc3526_prime_8192.3ossl | 1 - .../share/man/man3/BN_get_word.3ossl | 1 - .../share/man/man3/BN_hex2bn.3ossl | 1 - .../share/man/man3/BN_is_bit_set.3ossl | 1 - .../share/man/man3/BN_is_odd.3ossl | 1 - .../share/man/man3/BN_is_one.3ossl | 1 - .../share/man/man3/BN_is_prime.3ossl | 1 - .../share/man/man3/BN_is_prime_ex.3ossl | 1 - .../share/man/man3/BN_is_prime_fasttest.3ossl | 1 - .../man/man3/BN_is_prime_fasttest_ex.3ossl | 1 - .../share/man/man3/BN_is_word.3ossl | 1 - .../share/man/man3/BN_is_zero.3ossl | 1 - .../share/man/man3/BN_lebin2bn.3ossl | 1 - .../share/man/man3/BN_lshift.3ossl | 1 - .../share/man/man3/BN_lshift1.3ossl | 1 - .../share/man/man3/BN_mask_bits.3ossl | 1 - openssl-install/share/man/man3/BN_mod.3ossl | 1 - .../share/man/man3/BN_mod_add.3ossl | 1 - .../share/man/man3/BN_mod_exp.3ossl | 1 - .../share/man/man3/BN_mod_exp_mont.3ossl | 197 -- .../man/man3/BN_mod_exp_mont_consttime.3ossl | 1 - .../man3/BN_mod_exp_mont_consttime_x2.3ossl | 1 - .../share/man/man3/BN_mod_inverse.3ossl | 176 -- .../share/man/man3/BN_mod_mul.3ossl | 1 - .../man/man3/BN_mod_mul_montgomery.3ossl | 220 -- .../man/man3/BN_mod_mul_reciprocal.3ossl | 207 -- .../share/man/man3/BN_mod_sqr.3ossl | 1 - .../share/man/man3/BN_mod_sqrt.3ossl | 1 - .../share/man/man3/BN_mod_sub.3ossl | 1 - .../share/man/man3/BN_mod_word.3ossl | 1 - .../share/man/man3/BN_mpi2bn.3ossl | 1 - openssl-install/share/man/man3/BN_mul.3ossl | 1 - .../share/man/man3/BN_mul_word.3ossl | 1 - .../share/man/man3/BN_native2bn.3ossl | 1 - openssl-install/share/man/man3/BN_new.3ossl | 195 -- openssl-install/share/man/man3/BN_nnmod.3ossl | 1 - .../share/man/man3/BN_num_bits.3ossl | 1 - .../share/man/man3/BN_num_bits_word.3ossl | 1 - .../share/man/man3/BN_num_bytes.3ossl | 192 -- openssl-install/share/man/man3/BN_one.3ossl | 1 - openssl-install/share/man/man3/BN_print.3ossl | 1 - .../share/man/man3/BN_print_fp.3ossl | 1 - .../share/man/man3/BN_priv_rand.3ossl | 1 - .../share/man/man3/BN_priv_rand_ex.3ossl | 1 - .../share/man/man3/BN_priv_rand_range.3ossl | 1 - .../man/man3/BN_priv_rand_range_ex.3ossl | 1 - .../share/man/man3/BN_pseudo_rand.3ossl | 1 - .../share/man/man3/BN_pseudo_rand_range.3ossl | 1 - openssl-install/share/man/man3/BN_rand.3ossl | 252 -- .../share/man/man3/BN_rand_ex.3ossl | 1 - .../share/man/man3/BN_rand_range.3ossl | 1 - .../share/man/man3/BN_rand_range_ex.3ossl | 1 - .../share/man/man3/BN_rshift.3ossl | 1 - .../share/man/man3/BN_rshift1.3ossl | 1 - .../share/man/man3/BN_secure_new.3ossl | 1 - .../share/man/man3/BN_security_bits.3ossl | 181 -- .../share/man/man3/BN_set_bit.3ossl | 204 -- .../share/man/man3/BN_set_word.3ossl | 1 - .../share/man/man3/BN_signed_bin2bn.3ossl | 1 - .../share/man/man3/BN_signed_bn2bin.3ossl | 1 - .../share/man/man3/BN_signed_bn2lebin.3ossl | 1 - .../share/man/man3/BN_signed_bn2native.3ossl | 1 - .../share/man/man3/BN_signed_lebin2bn.3ossl | 1 - .../share/man/man3/BN_signed_native2bn.3ossl | 1 - openssl-install/share/man/man3/BN_sqr.3ossl | 1 - openssl-install/share/man/man3/BN_sub.3ossl | 1 - .../share/man/man3/BN_sub_word.3ossl | 1 - openssl-install/share/man/man3/BN_swap.3ossl | 163 -- .../man/man3/BN_to_ASN1_ENUMERATED.3ossl | 1 - .../share/man/man3/BN_to_ASN1_INTEGER.3ossl | 1 - .../share/man/man3/BN_to_montgomery.3ossl | 1 - openssl-install/share/man/man3/BN_ucmp.3ossl | 1 - .../share/man/man3/BN_value_one.3ossl | 1 - .../share/man/man3/BN_with_flags.3ossl | 1 - openssl-install/share/man/man3/BN_zero.3ossl | 198 -- .../share/man/man3/BUF_MEM_free.3ossl | 1 - .../share/man/man3/BUF_MEM_grow.3ossl | 1 - .../share/man/man3/BUF_MEM_grow_clean.3ossl | 1 - .../share/man/man3/BUF_MEM_new.3ossl | 207 -- .../share/man/man3/BUF_MEM_new_ex.3ossl | 1 - .../share/man/man3/BUF_reverse.3ossl | 1 - .../man/man3/CERTIFICATEPOLICIES_free.3ossl | 1 - .../man/man3/CERTIFICATEPOLICIES_new.3ossl | 1 - openssl-install/share/man/man3/CMAC_CTX.3ossl | 246 -- .../share/man/man3/CMAC_CTX_cleanup.3ossl | 1 - .../share/man/man3/CMAC_CTX_copy.3ossl | 1 - .../share/man/man3/CMAC_CTX_free.3ossl | 1 - .../man/man3/CMAC_CTX_get0_cipher_ctx.3ossl | 1 - .../share/man/man3/CMAC_CTX_new.3ossl | 1 - .../share/man/man3/CMAC_Final.3ossl | 1 - .../share/man/man3/CMAC_Init.3ossl | 1 - .../share/man/man3/CMAC_Update.3ossl | 1 - .../share/man/man3/CMAC_resume.3ossl | 1 - .../man3/CMS_AuthEnvelopedData_create.3ossl | 1 - .../CMS_AuthEnvelopedData_create_ex.3ossl | 1 - .../share/man/man3/CMS_ContentInfo_free.3ossl | 1 - .../share/man/man3/CMS_ContentInfo_new.3ossl | 1 - .../man/man3/CMS_ContentInfo_new_ex.3ossl | 1 - .../man/man3/CMS_ContentInfo_print_ctx.3ossl | 1 - .../man/man3/CMS_EncryptedData_decrypt.3ossl | 199 -- .../man/man3/CMS_EncryptedData_encrypt.3ossl | 200 -- .../man3/CMS_EncryptedData_encrypt_ex.3ossl | 1 - .../man/man3/CMS_EnvelopedData_create.3ossl | 212 -- .../man3/CMS_EnvelopedData_create_ex.3ossl | 1 - .../man/man3/CMS_EnvelopedData_decrypt.3ossl | 1 - .../share/man/man3/CMS_EnvelopedData_it.3ossl | 1 - .../man/man3/CMS_ReceiptRequest_create0.3ossl | 1 - .../man3/CMS_ReceiptRequest_create0_ex.3ossl | 1 - .../man/man3/CMS_ReceiptRequest_free.3ossl | 1 - .../man3/CMS_ReceiptRequest_get0_values.3ossl | 1 - .../man/man3/CMS_ReceiptRequest_new.3ossl | 1 - .../man/man3/CMS_RecipientInfo_decrypt.3ossl | 1 - .../man/man3/CMS_RecipientInfo_encrypt.3ossl | 1 - .../CMS_RecipientInfo_kari_set0_pkey.3ossl | 1 - ...ecipientInfo_kari_set0_pkey_and_peer.3ossl | 1 - .../CMS_RecipientInfo_kekri_get0_id.3ossl | 1 - .../man3/CMS_RecipientInfo_kekri_id_cmp.3ossl | 1 - .../CMS_RecipientInfo_ktri_cert_cmp.3ossl | 1 - ...MS_RecipientInfo_ktri_get0_signer_id.3ossl | 1 - .../man/man3/CMS_RecipientInfo_set0_key.3ossl | 1 - .../man3/CMS_RecipientInfo_set0_pkey.3ossl | 1 - .../man/man3/CMS_RecipientInfo_type.3ossl | 1 - .../share/man/man3/CMS_SignedData_free.3ossl | 1 - .../share/man/man3/CMS_SignedData_new.3ossl | 1 - .../man/man3/CMS_SignedData_verify.3ossl | 1 - .../man/man3/CMS_SignerInfo_cert_cmp.3ossl | 1 - .../man3/CMS_SignerInfo_get0_signature.3ossl | 1 - .../man3/CMS_SignerInfo_get0_signer_id.3ossl | 1 - .../CMS_SignerInfo_set1_signer_cert.3ossl | 1 - .../share/man/man3/CMS_SignerInfo_sign.3ossl | 1 - .../share/man/man3/CMS_add0_cert.3ossl | 215 -- .../share/man/man3/CMS_add0_crl.3ossl | 1 - .../man/man3/CMS_add0_recipient_key.3ossl | 1 - .../man/man3/CMS_add1_ReceiptRequest.3ossl | 1 - .../share/man/man3/CMS_add1_cert.3ossl | 1 - .../share/man/man3/CMS_add1_crl.3ossl | 1 - .../share/man/man3/CMS_add1_recipient.3ossl | 1 - .../man/man3/CMS_add1_recipient_cert.3ossl | 216 -- .../share/man/man3/CMS_add1_signer.3ossl | 240 -- .../share/man/man3/CMS_compress.3ossl | 208 -- .../share/man/man3/CMS_data_create.3ossl | 185 -- .../share/man/man3/CMS_data_create_ex.3ossl | 1 - .../share/man/man3/CMS_decrypt.3ossl | 251 -- .../man/man3/CMS_decrypt_set1_password.3ossl | 1 - .../man/man3/CMS_decrypt_set1_pkey.3ossl | 1 - .../man3/CMS_decrypt_set1_pkey_and_peer.3ossl | 1 - .../share/man/man3/CMS_digest_create.3ossl | 188 -- .../share/man/man3/CMS_digest_create_ex.3ossl | 1 - .../share/man/man3/CMS_encrypt.3ossl | 245 -- .../share/man/man3/CMS_encrypt_ex.3ossl | 1 - .../share/man/man3/CMS_final.3ossl | 191 -- .../share/man/man3/CMS_final_digest.3ossl | 1 - .../man/man3/CMS_get0_RecipientInfos.3ossl | 285 --- .../share/man/man3/CMS_get0_SignerInfos.3ossl | 221 -- .../share/man/man3/CMS_get0_content.3ossl | 1 - .../man/man3/CMS_get0_eContentType.3ossl | 1 - .../share/man/man3/CMS_get0_signers.3ossl | 1 - .../share/man/man3/CMS_get0_type.3ossl | 218 -- .../man/man3/CMS_get1_ReceiptRequest.3ossl | 222 -- .../share/man/man3/CMS_get1_certs.3ossl | 1 - .../share/man/man3/CMS_get1_crls.3ossl | 1 - .../man/man3/CMS_set1_eContentType.3ossl | 1 - openssl-install/share/man/man3/CMS_sign.3ossl | 274 --- .../share/man/man3/CMS_sign_ex.3ossl | 1 - .../share/man/man3/CMS_sign_receipt.3ossl | 183 -- .../share/man/man3/CMS_signed_add1_attr.3ossl | 1 - .../man3/CMS_signed_add1_attr_by_NID.3ossl | 1 - .../man3/CMS_signed_add1_attr_by_OBJ.3ossl | 1 - .../man3/CMS_signed_add1_attr_by_txt.3ossl | 1 - .../man/man3/CMS_signed_delete_attr.3ossl | 1 - .../man3/CMS_signed_get0_data_by_OBJ.3ossl | 1 - .../share/man/man3/CMS_signed_get_attr.3ossl | 338 --- .../man/man3/CMS_signed_get_attr_by_NID.3ossl | 1 - .../man/man3/CMS_signed_get_attr_by_OBJ.3ossl | 1 - .../man/man3/CMS_signed_get_attr_count.3ossl | 1 - .../share/man/man3/CMS_uncompress.3ossl | 189 -- .../man/man3/CMS_unsigned_add1_attr.3ossl | 1 - .../man3/CMS_unsigned_add1_attr_by_NID.3ossl | 1 - .../man3/CMS_unsigned_add1_attr_by_OBJ.3ossl | 1 - .../man3/CMS_unsigned_add1_attr_by_txt.3ossl | 1 - .../man/man3/CMS_unsigned_delete_attr.3ossl | 1 - .../man3/CMS_unsigned_get0_data_by_OBJ.3ossl | 1 - .../man/man3/CMS_unsigned_get_attr.3ossl | 1 - .../man3/CMS_unsigned_get_attr_by_NID.3ossl | 1 - .../man3/CMS_unsigned_get_attr_by_OBJ.3ossl | 1 - .../man3/CMS_unsigned_get_attr_count.3ossl | 1 - .../share/man/man3/CMS_verify.3ossl | 300 --- .../share/man/man3/CMS_verify_receipt.3ossl | 185 -- .../share/man/man3/COMP_CTX_free.3ossl | 1 - .../share/man/man3/COMP_CTX_get_method.3ossl | 1 - .../share/man/man3/COMP_CTX_get_type.3ossl | 1 - .../share/man/man3/COMP_CTX_new.3ossl | 298 --- .../share/man/man3/COMP_brotli.3ossl | 1 - .../share/man/man3/COMP_brotli_oneshot.3ossl | 1 - .../share/man/man3/COMP_compress_block.3ossl | 1 - .../share/man/man3/COMP_expand_block.3ossl | 1 - .../share/man/man3/COMP_get_name.3ossl | 1 - .../share/man/man3/COMP_get_type.3ossl | 1 - .../share/man/man3/COMP_zlib.3ossl | 1 - .../share/man/man3/COMP_zlib_oneshot.3ossl | 1 - .../share/man/man3/COMP_zstd.3ossl | 1 - .../share/man/man3/COMP_zstd_oneshot.3ossl | 1 - .../man3/CONF_get1_default_config_file.3ossl | 1 - .../share/man/man3/CONF_modules_finish.3ossl | 1 - .../share/man/man3/CONF_modules_free.3ossl | 191 -- .../share/man/man3/CONF_modules_load.3ossl | 1 - .../man/man3/CONF_modules_load_file.3ossl | 302 --- .../man/man3/CONF_modules_load_file_ex.3ossl | 1 - .../share/man/man3/CONF_modules_unload.3ossl | 1 - .../share/man/man3/CRL_DIST_POINTS_free.3ossl | 1 - .../share/man/man3/CRL_DIST_POINTS_new.3ossl | 1 - .../share/man/man3/CRYPTO_EX_dup.3ossl | 1 - .../share/man/man3/CRYPTO_EX_free.3ossl | 1 - .../share/man/man3/CRYPTO_EX_new.3ossl | 1 - .../man/man3/CRYPTO_THREAD_lock_free.3ossl | 1 - .../man/man3/CRYPTO_THREAD_lock_new.3ossl | 1 - .../man/man3/CRYPTO_THREAD_read_lock.3ossl | 1 - .../man/man3/CRYPTO_THREAD_run_once.3ossl | 380 --- .../share/man/man3/CRYPTO_THREAD_unlock.3ossl | 1 - .../man/man3/CRYPTO_THREAD_write_lock.3ossl | 1 - .../share/man/man3/CRYPTO_aligned_alloc.3ossl | 1 - .../share/man/man3/CRYPTO_alloc_ex_data.3ossl | 1 - .../share/man/man3/CRYPTO_atomic_add.3ossl | 1 - .../share/man/man3/CRYPTO_atomic_add64.3ossl | 1 - .../share/man/man3/CRYPTO_atomic_and.3ossl | 1 - .../share/man/man3/CRYPTO_atomic_load.3ossl | 1 - .../man/man3/CRYPTO_atomic_load_int.3ossl | 1 - .../share/man/man3/CRYPTO_atomic_or.3ossl | 1 - .../share/man/man3/CRYPTO_atomic_store.3ossl | 1 - .../share/man/man3/CRYPTO_clear_free.3ossl | 1 - .../share/man/man3/CRYPTO_clear_realloc.3ossl | 1 - .../share/man/man3/CRYPTO_free.3ossl | 1 - .../share/man/man3/CRYPTO_free_ex_data.3ossl | 1 - .../share/man/man3/CRYPTO_free_ex_index.3ossl | 1 - .../share/man/man3/CRYPTO_free_fn.3ossl | 1 - .../man/man3/CRYPTO_get_alloc_counts.3ossl | 1 - .../share/man/man3/CRYPTO_get_ex_data.3ossl | 1 - .../man/man3/CRYPTO_get_ex_new_index.3ossl | 313 --- .../man/man3/CRYPTO_get_mem_functions.3ossl | 1 - .../share/man/man3/CRYPTO_malloc.3ossl | 1 - .../share/man/man3/CRYPTO_malloc_fn.3ossl | 1 - .../share/man/man3/CRYPTO_mem_ctrl.3ossl | 1 - .../share/man/man3/CRYPTO_mem_debug_pop.3ossl | 1 - .../man/man3/CRYPTO_mem_debug_push.3ossl | 1 - .../share/man/man3/CRYPTO_mem_leaks.3ossl | 1 - .../share/man/man3/CRYPTO_mem_leaks_cb.3ossl | 1 - .../share/man/man3/CRYPTO_mem_leaks_fp.3ossl | 1 - .../share/man/man3/CRYPTO_memcmp.3ossl | 171 -- .../share/man/man3/CRYPTO_new_ex_data.3ossl | 1 - .../share/man/man3/CRYPTO_realloc.3ossl | 1 - .../share/man/man3/CRYPTO_realloc_fn.3ossl | 1 - .../man/man3/CRYPTO_secure_allocated.3ossl | 1 - .../man/man3/CRYPTO_secure_clear_free.3ossl | 1 - .../share/man/man3/CRYPTO_secure_free.3ossl | 1 - .../share/man/man3/CRYPTO_secure_malloc.3ossl | 1 - .../man/man3/CRYPTO_secure_malloc_done.3ossl | 1 - .../man/man3/CRYPTO_secure_malloc_init.3ossl | 1 - .../CRYPTO_secure_malloc_initialized.3ossl | 1 - .../share/man/man3/CRYPTO_secure_used.3ossl | 1 - .../share/man/man3/CRYPTO_secure_zalloc.3ossl | 1 - .../share/man/man3/CRYPTO_set_ex_data.3ossl | 1 - .../share/man/man3/CRYPTO_set_mem_debug.3ossl | 1 - .../man/man3/CRYPTO_set_mem_functions.3ossl | 1 - .../share/man/man3/CRYPTO_strdup.3ossl | 1 - .../share/man/man3/CRYPTO_strndup.3ossl | 1 - .../share/man/man3/CRYPTO_zalloc.3ossl | 1 - .../share/man/man3/CTLOG_STORE_free.3ossl | 1 - .../man/man3/CTLOG_STORE_get0_log_by_id.3ossl | 180 -- .../man3/CTLOG_STORE_load_default_file.3ossl | 1 - .../man/man3/CTLOG_STORE_load_file.3ossl | 1 - .../share/man/man3/CTLOG_STORE_new.3ossl | 220 -- .../share/man/man3/CTLOG_STORE_new_ex.3ossl | 1 - .../share/man/man3/CTLOG_free.3ossl | 1 - .../share/man/man3/CTLOG_get0_log_id.3ossl | 1 - .../share/man/man3/CTLOG_get0_name.3ossl | 1 - .../man/man3/CTLOG_get0_public_key.3ossl | 1 - .../share/man/man3/CTLOG_new.3ossl | 221 -- .../share/man/man3/CTLOG_new_ex.3ossl | 1 - .../man/man3/CTLOG_new_from_base64.3ossl | 1 - .../man/man3/CTLOG_new_from_base64_ex.3ossl | 1 - .../man/man3/CT_POLICY_EVAL_CTX_free.3ossl | 1 - .../man3/CT_POLICY_EVAL_CTX_get0_cert.3ossl | 1 - .../man3/CT_POLICY_EVAL_CTX_get0_issuer.3ossl | 1 - .../CT_POLICY_EVAL_CTX_get0_log_store.3ossl | 1 - .../man3/CT_POLICY_EVAL_CTX_get_time.3ossl | 1 - .../man/man3/CT_POLICY_EVAL_CTX_new.3ossl | 247 -- .../man/man3/CT_POLICY_EVAL_CTX_new_ex.3ossl | 1 - .../man3/CT_POLICY_EVAL_CTX_set1_cert.3ossl | 1 - .../man3/CT_POLICY_EVAL_CTX_set1_issuer.3ossl | 1 - ...LICY_EVAL_CTX_set_shared_CTLOG_STORE.3ossl | 1 - .../man3/CT_POLICY_EVAL_CTX_set_time.3ossl | 1 - .../man/man3/DECLARE_ASN1_FUNCTIONS.3ossl | 1 - .../share/man/man3/DECLARE_PEM_rw.3ossl | 1 - .../share/man/man3/DEFINE_LHASH_OF.3ossl | 1 - .../share/man/man3/DEFINE_LHASH_OF_EX.3ossl | 1 - .../man/man3/DEFINE_SPECIAL_STACK_OF.3ossl | 1 - .../man3/DEFINE_SPECIAL_STACK_OF_CONST.3ossl | 1 - .../share/man/man3/DEFINE_STACK_OF.3ossl | 448 ---- .../man/man3/DEFINE_STACK_OF_CONST.3ossl | 1 - .../share/man/man3/DES_cbc_cksum.3ossl | 1 - .../share/man/man3/DES_cfb64_encrypt.3ossl | 1 - .../share/man/man3/DES_cfb_encrypt.3ossl | 1 - .../share/man/man3/DES_crypt.3ossl | 1 - .../share/man/man3/DES_ecb2_encrypt.3ossl | 1 - .../share/man/man3/DES_ecb3_encrypt.3ossl | 1 - .../share/man/man3/DES_ecb_encrypt.3ossl | 1 - .../share/man/man3/DES_ede2_cbc_encrypt.3ossl | 1 - .../man/man3/DES_ede2_cfb64_encrypt.3ossl | 1 - .../man/man3/DES_ede2_ofb64_encrypt.3ossl | 1 - .../share/man/man3/DES_ede3_cbc_encrypt.3ossl | 1 - .../man/man3/DES_ede3_cfb64_encrypt.3ossl | 1 - .../man/man3/DES_ede3_ofb64_encrypt.3ossl | 1 - .../share/man/man3/DES_fcrypt.3ossl | 1 - .../share/man/man3/DES_is_weak_key.3ossl | 1 - .../share/man/man3/DES_key_sched.3ossl | 1 - .../share/man/man3/DES_ncbc_encrypt.3ossl | 1 - .../share/man/man3/DES_ofb64_encrypt.3ossl | 1 - .../share/man/man3/DES_ofb_encrypt.3ossl | 1 - .../share/man/man3/DES_pcbc_encrypt.3ossl | 1 - .../share/man/man3/DES_quad_cksum.3ossl | 1 - .../share/man/man3/DES_random_key.3ossl | 464 ---- .../share/man/man3/DES_set_key.3ossl | 1 - .../share/man/man3/DES_set_key_checked.3ossl | 1 - .../man/man3/DES_set_key_unchecked.3ossl | 1 - .../share/man/man3/DES_set_odd_parity.3ossl | 1 - .../share/man/man3/DES_string_to_2keys.3ossl | 1 - .../share/man/man3/DES_string_to_key.3ossl | 1 - .../share/man/man3/DES_xcbc_encrypt.3ossl | 1 - .../share/man/man3/DH_OpenSSL.3ossl | 1 - openssl-install/share/man/man3/DH_bits.3ossl | 1 - openssl-install/share/man/man3/DH_check.3ossl | 1 - .../share/man/man3/DH_check_ex.3ossl | 1 - .../share/man/man3/DH_check_params.3ossl | 1 - .../share/man/man3/DH_check_params_ex.3ossl | 1 - .../share/man/man3/DH_check_pub_key_ex.3ossl | 1 - .../share/man/man3/DH_clear_flags.3ossl | 1 - .../share/man/man3/DH_compute_key.3ossl | 1 - .../man/man3/DH_compute_key_padded.3ossl | 1 - openssl-install/share/man/man3/DH_free.3ossl | 1 - .../share/man/man3/DH_generate_key.3ossl | 215 -- .../man/man3/DH_generate_parameters.3ossl | 290 --- .../man/man3/DH_generate_parameters_ex.3ossl | 1 - .../share/man/man3/DH_get0_engine.3ossl | 1 - .../share/man/man3/DH_get0_g.3ossl | 1 - .../share/man/man3/DH_get0_key.3ossl | 1 - .../share/man/man3/DH_get0_p.3ossl | 1 - .../share/man/man3/DH_get0_pqg.3ossl | 283 --- .../share/man/man3/DH_get0_priv_key.3ossl | 1 - .../share/man/man3/DH_get0_pub_key.3ossl | 1 - .../share/man/man3/DH_get0_q.3ossl | 1 - .../share/man/man3/DH_get_1024_160.3ossl | 225 -- .../share/man/man3/DH_get_2048_224.3ossl | 1 - .../share/man/man3/DH_get_2048_256.3ossl | 1 - .../man/man3/DH_get_default_method.3ossl | 1 - .../share/man/man3/DH_get_ex_data.3ossl | 1 - .../share/man/man3/DH_get_ex_new_index.3ossl | 1 - .../share/man/man3/DH_get_length.3ossl | 1 - .../share/man/man3/DH_get_nid.3ossl | 1 - .../share/man/man3/DH_meth_dup.3ossl | 1 - .../share/man/man3/DH_meth_free.3ossl | 1 - .../man/man3/DH_meth_get0_app_data.3ossl | 1 - .../share/man/man3/DH_meth_get0_name.3ossl | 1 - .../man/man3/DH_meth_get_bn_mod_exp.3ossl | 1 - .../man/man3/DH_meth_get_compute_key.3ossl | 1 - .../share/man/man3/DH_meth_get_finish.3ossl | 1 - .../share/man/man3/DH_meth_get_flags.3ossl | 1 - .../man/man3/DH_meth_get_generate_key.3ossl | 1 - .../man3/DH_meth_get_generate_params.3ossl | 1 - .../share/man/man3/DH_meth_get_init.3ossl | 1 - .../share/man/man3/DH_meth_new.3ossl | 311 --- .../man/man3/DH_meth_set0_app_data.3ossl | 1 - .../share/man/man3/DH_meth_set1_name.3ossl | 1 - .../man/man3/DH_meth_set_bn_mod_exp.3ossl | 1 - .../man/man3/DH_meth_set_compute_key.3ossl | 1 - .../share/man/man3/DH_meth_set_finish.3ossl | 1 - .../share/man/man3/DH_meth_set_flags.3ossl | 1 - .../man/man3/DH_meth_set_generate_key.3ossl | 1 - .../man3/DH_meth_set_generate_params.3ossl | 1 - .../share/man/man3/DH_meth_set_init.3ossl | 1 - openssl-install/share/man/man3/DH_new.3ossl | 190 -- .../share/man/man3/DH_new_by_nid.3ossl | 186 -- .../share/man/man3/DH_new_method.3ossl | 1 - .../share/man/man3/DH_security_bits.3ossl | 1 - .../share/man/man3/DH_set0_key.3ossl | 1 - .../share/man/man3/DH_set0_pqg.3ossl | 1 - .../man/man3/DH_set_default_method.3ossl | 1 - .../share/man/man3/DH_set_ex_data.3ossl | 1 - .../share/man/man3/DH_set_flags.3ossl | 1 - .../share/man/man3/DH_set_length.3ossl | 1 - .../share/man/man3/DH_set_method.3ossl | 232 -- openssl-install/share/man/man3/DH_size.3ossl | 202 -- .../share/man/man3/DH_test_flags.3ossl | 1 - .../share/man/man3/DHparams_print.3ossl | 1 - .../share/man/man3/DHparams_print_fp.3ossl | 1 - .../share/man/man3/DIRECTORYSTRING_free.3ossl | 1 - .../share/man/man3/DIRECTORYSTRING_new.3ossl | 1 - .../share/man/man3/DISPLAYTEXT_free.3ossl | 1 - .../share/man/man3/DISPLAYTEXT_new.3ossl | 1 - .../share/man/man3/DIST_POINT_NAME_dup.3ossl | 1 - .../share/man/man3/DIST_POINT_NAME_free.3ossl | 1 - .../share/man/man3/DIST_POINT_NAME_new.3ossl | 1 - .../share/man/man3/DIST_POINT_free.3ossl | 1 - .../share/man/man3/DIST_POINT_new.3ossl | 1 - .../share/man/man3/DSA_OpenSSL.3ossl | 1 - .../share/man/man3/DSA_SIG_free.3ossl | 1 - .../share/man/man3/DSA_SIG_get0.3ossl | 1 - .../share/man/man3/DSA_SIG_new.3ossl | 191 -- .../share/man/man3/DSA_SIG_set0.3ossl | 1 - openssl-install/share/man/man3/DSA_bits.3ossl | 1 - .../share/man/man3/DSA_clear_flags.3ossl | 1 - .../share/man/man3/DSA_do_sign.3ossl | 197 -- .../share/man/man3/DSA_do_verify.3ossl | 1 - .../share/man/man3/DSA_dup_DH.3ossl | 185 -- openssl-install/share/man/man3/DSA_free.3ossl | 1 - .../share/man/man3/DSA_generate_key.3ossl | 186 -- .../man/man3/DSA_generate_parameters.3ossl | 252 -- .../man/man3/DSA_generate_parameters_ex.3ossl | 1 - .../share/man/man3/DSA_get0_engine.3ossl | 1 - .../share/man/man3/DSA_get0_g.3ossl | 1 - .../share/man/man3/DSA_get0_key.3ossl | 1 - .../share/man/man3/DSA_get0_p.3ossl | 1 - .../share/man/man3/DSA_get0_pqg.3ossl | 255 -- .../share/man/man3/DSA_get0_priv_key.3ossl | 1 - .../share/man/man3/DSA_get0_pub_key.3ossl | 1 - .../share/man/man3/DSA_get0_q.3ossl | 1 - .../man/man3/DSA_get_default_method.3ossl | 1 - .../share/man/man3/DSA_get_ex_data.3ossl | 1 - .../share/man/man3/DSA_get_ex_new_index.3ossl | 1 - .../share/man/man3/DSA_meth_dup.3ossl | 1 - .../share/man/man3/DSA_meth_free.3ossl | 1 - .../man/man3/DSA_meth_get0_app_data.3ossl | 1 - .../share/man/man3/DSA_meth_get0_name.3ossl | 1 - .../man/man3/DSA_meth_get_bn_mod_exp.3ossl | 1 - .../share/man/man3/DSA_meth_get_finish.3ossl | 1 - .../share/man/man3/DSA_meth_get_flags.3ossl | 1 - .../share/man/man3/DSA_meth_get_init.3ossl | 1 - .../share/man/man3/DSA_meth_get_keygen.3ossl | 1 - .../share/man/man3/DSA_meth_get_mod_exp.3ossl | 1 - .../man/man3/DSA_meth_get_paramgen.3ossl | 1 - .../share/man/man3/DSA_meth_get_sign.3ossl | 1 - .../man/man3/DSA_meth_get_sign_setup.3ossl | 1 - .../share/man/man3/DSA_meth_get_verify.3ossl | 1 - .../share/man/man3/DSA_meth_new.3ossl | 361 --- .../man/man3/DSA_meth_set0_app_data.3ossl | 1 - .../share/man/man3/DSA_meth_set1_name.3ossl | 1 - .../man/man3/DSA_meth_set_bn_mod_exp.3ossl | 1 - .../share/man/man3/DSA_meth_set_finish.3ossl | 1 - .../share/man/man3/DSA_meth_set_flags.3ossl | 1 - .../share/man/man3/DSA_meth_set_init.3ossl | 1 - .../share/man/man3/DSA_meth_set_keygen.3ossl | 1 - .../share/man/man3/DSA_meth_set_mod_exp.3ossl | 1 - .../man/man3/DSA_meth_set_paramgen.3ossl | 1 - .../share/man/man3/DSA_meth_set_sign.3ossl | 1 - .../man/man3/DSA_meth_set_sign_setup.3ossl | 1 - .../share/man/man3/DSA_meth_set_verify.3ossl | 1 - openssl-install/share/man/man3/DSA_new.3ossl | 193 -- .../share/man/man3/DSA_new_method.3ossl | 1 - .../share/man/man3/DSA_print.3ossl | 1 - .../share/man/man3/DSA_print_fp.3ossl | 1 - .../share/man/man3/DSA_security_bits.3ossl | 1 - .../share/man/man3/DSA_set0_key.3ossl | 1 - .../share/man/man3/DSA_set0_pqg.3ossl | 1 - .../man/man3/DSA_set_default_method.3ossl | 1 - .../share/man/man3/DSA_set_ex_data.3ossl | 1 - .../share/man/man3/DSA_set_flags.3ossl | 1 - .../share/man/man3/DSA_set_method.3ossl | 232 -- openssl-install/share/man/man3/DSA_sign.3ossl | 215 -- .../share/man/man3/DSA_sign_setup.3ossl | 1 - openssl-install/share/man/man3/DSA_size.3ossl | 201 -- .../share/man/man3/DSA_test_flags.3ossl | 1 - .../share/man/man3/DSA_verify.3ossl | 1 - .../share/man/man3/DSAparams_dup.3ossl | 1 - .../share/man/man3/DSAparams_print.3ossl | 1 - .../share/man/man3/DSAparams_print_fp.3ossl | 1 - .../share/man/man3/DTLS_client_method.3ossl | 1 - .../share/man/man3/DTLS_get_data_mtu.3ossl | 168 -- .../share/man/man3/DTLS_method.3ossl | 1 - .../share/man/man3/DTLS_server_method.3ossl | 1 - .../share/man/man3/DTLS_set_timer_cb.3ossl | 183 -- .../share/man/man3/DTLS_timer_cb.3ossl | 1 - .../man/man3/DTLSv1_2_client_method.3ossl | 1 - .../share/man/man3/DTLSv1_2_method.3ossl | 1 - .../man/man3/DTLSv1_2_server_method.3ossl | 1 - .../share/man/man3/DTLSv1_client_method.3ossl | 1 - .../share/man/man3/DTLSv1_get_timeout.3ossl | 190 -- .../man/man3/DTLSv1_handle_timeout.3ossl | 183 -- .../share/man/man3/DTLSv1_listen.3ossl | 286 --- .../share/man/man3/DTLSv1_method.3ossl | 1 - .../share/man/man3/DTLSv1_server_method.3ossl | 1 - .../share/man/man3/ECDSA_SIG_free.3ossl | 1 - .../share/man/man3/ECDSA_SIG_get0.3ossl | 1 - .../share/man/man3/ECDSA_SIG_get0_r.3ossl | 1 - .../share/man/man3/ECDSA_SIG_get0_s.3ossl | 1 - .../share/man/man3/ECDSA_SIG_new.3ossl | 281 --- .../share/man/man3/ECDSA_SIG_set0.3ossl | 1 - .../share/man/man3/ECDSA_do_sign.3ossl | 1 - .../share/man/man3/ECDSA_do_sign_ex.3ossl | 1 - .../share/man/man3/ECDSA_do_verify.3ossl | 1 - .../share/man/man3/ECDSA_sign.3ossl | 329 --- .../share/man/man3/ECDSA_sign_ex.3ossl | 1 - .../share/man/man3/ECDSA_sign_setup.3ossl | 1 - .../share/man/man3/ECDSA_size.3ossl | 1 - .../share/man/man3/ECDSA_verify.3ossl | 1 - .../share/man/man3/ECPARAMETERS_free.3ossl | 1 - .../share/man/man3/ECPARAMETERS_new.3ossl | 1 - .../share/man/man3/ECPKPARAMETERS_free.3ossl | 1 - .../share/man/man3/ECPKPARAMETERS_new.3ossl | 1 - .../share/man/man3/ECPKParameters_print.3ossl | 188 -- .../man/man3/ECPKParameters_print_fp.3ossl | 1 - .../man/man3/EC_GF2m_simple_method.3ossl | 1 - .../share/man/man3/EC_GFp_mont_method.3ossl | 1 - .../share/man/man3/EC_GFp_nist_method.3ossl | 1 - .../man/man3/EC_GFp_nistp224_method.3ossl | 1 - .../man/man3/EC_GFp_nistp256_method.3ossl | 1 - .../man/man3/EC_GFp_nistp521_method.3ossl | 1 - .../share/man/man3/EC_GFp_simple_method.3ossl | 215 -- .../share/man/man3/EC_GROUP_check.3ossl | 1 - .../man3/EC_GROUP_check_discriminant.3ossl | 1 - .../man/man3/EC_GROUP_check_named_curve.3ossl | 1 - .../share/man/man3/EC_GROUP_clear_free.3ossl | 1 - .../share/man/man3/EC_GROUP_cmp.3ossl | 1 - .../share/man/man3/EC_GROUP_copy.3ossl | 397 --- .../share/man/man3/EC_GROUP_dup.3ossl | 1 - .../share/man/man3/EC_GROUP_free.3ossl | 1 - .../man/man3/EC_GROUP_get0_cofactor.3ossl | 1 - .../share/man/man3/EC_GROUP_get0_field.3ossl | 1 - .../man/man3/EC_GROUP_get0_generator.3ossl | 1 - .../share/man/man3/EC_GROUP_get0_order.3ossl | 1 - .../share/man/man3/EC_GROUP_get0_seed.3ossl | 1 - .../man/man3/EC_GROUP_get_asn1_flag.3ossl | 1 - .../man/man3/EC_GROUP_get_basis_type.3ossl | 1 - .../man/man3/EC_GROUP_get_cofactor.3ossl | 1 - .../share/man/man3/EC_GROUP_get_curve.3ossl | 1 - .../man/man3/EC_GROUP_get_curve_GF2m.3ossl | 1 - .../man/man3/EC_GROUP_get_curve_GFp.3ossl | 1 - .../man/man3/EC_GROUP_get_curve_name.3ossl | 1 - .../share/man/man3/EC_GROUP_get_degree.3ossl | 1 - .../man/man3/EC_GROUP_get_ecparameters.3ossl | 1 - .../man3/EC_GROUP_get_ecpkparameters.3ossl | 1 - .../man/man3/EC_GROUP_get_field_type.3ossl | 1 - .../share/man/man3/EC_GROUP_get_order.3ossl | 1 - .../man3/EC_GROUP_get_pentanomial_basis.3ossl | 1 - .../EC_GROUP_get_point_conversion_form.3ossl | 1 - .../man/man3/EC_GROUP_get_seed_len.3ossl | 1 - .../man3/EC_GROUP_get_trinomial_basis.3ossl | 1 - .../man3/EC_GROUP_have_precompute_mult.3ossl | 1 - .../share/man/man3/EC_GROUP_method_of.3ossl | 1 - .../share/man/man3/EC_GROUP_new.3ossl | 376 --- .../man/man3/EC_GROUP_new_by_curve_name.3ossl | 1 - .../man3/EC_GROUP_new_by_curve_name_ex.3ossl | 1 - .../man/man3/EC_GROUP_new_curve_GF2m.3ossl | 1 - .../man/man3/EC_GROUP_new_curve_GFp.3ossl | 1 - .../man3/EC_GROUP_new_from_ecparameters.3ossl | 1 - .../EC_GROUP_new_from_ecpkparameters.3ossl | 1 - .../man/man3/EC_GROUP_new_from_params.3ossl | 1 - .../share/man/man3/EC_GROUP_order_bits.3ossl | 1 - .../man/man3/EC_GROUP_precompute_mult.3ossl | 1 - .../man/man3/EC_GROUP_set_asn1_flag.3ossl | 1 - .../share/man/man3/EC_GROUP_set_curve.3ossl | 1 - .../man/man3/EC_GROUP_set_curve_GF2m.3ossl | 1 - .../man/man3/EC_GROUP_set_curve_GFp.3ossl | 1 - .../man/man3/EC_GROUP_set_curve_name.3ossl | 1 - .../man/man3/EC_GROUP_set_generator.3ossl | 1 - .../EC_GROUP_set_point_conversion_form.3ossl | 1 - .../share/man/man3/EC_GROUP_set_seed.3ossl | 1 - .../share/man/man3/EC_GROUP_to_params.3ossl | 1 - .../share/man/man3/EC_KEY_check_key.3ossl | 1 - .../share/man/man3/EC_KEY_clear_flags.3ossl | 1 - .../share/man/man3/EC_KEY_copy.3ossl | 1 - .../EC_KEY_decoded_from_explicit_params.3ossl | 1 - .../share/man/man3/EC_KEY_dup.3ossl | 1 - .../share/man/man3/EC_KEY_free.3ossl | 1 - .../share/man/man3/EC_KEY_generate_key.3ossl | 1 - .../share/man/man3/EC_KEY_get0_engine.3ossl | 1 - .../share/man/man3/EC_KEY_get0_group.3ossl | 1 - .../man/man3/EC_KEY_get0_private_key.3ossl | 1 - .../man/man3/EC_KEY_get0_public_key.3ossl | 1 - .../share/man/man3/EC_KEY_get_conv_form.3ossl | 1 - .../share/man/man3/EC_KEY_get_enc_flags.3ossl | 191 -- .../share/man/man3/EC_KEY_get_ex_data.3ossl | 1 - .../man/man3/EC_KEY_get_ex_new_index.3ossl | 1 - .../share/man/man3/EC_KEY_get_flags.3ossl | 1 - .../share/man/man3/EC_KEY_get_method.3ossl | 1 - .../share/man/man3/EC_KEY_key2buf.3ossl | 1 - .../share/man/man3/EC_KEY_new.3ossl | 378 --- .../man/man3/EC_KEY_new_by_curve_name.3ossl | 1 - .../man3/EC_KEY_new_by_curve_name_ex.3ossl | 1 - .../share/man/man3/EC_KEY_new_ex.3ossl | 1 - .../share/man/man3/EC_KEY_oct2key.3ossl | 1 - .../share/man/man3/EC_KEY_oct2priv.3ossl | 1 - .../man/man3/EC_KEY_precompute_mult.3ossl | 1 - .../share/man/man3/EC_KEY_priv2buf.3ossl | 1 - .../share/man/man3/EC_KEY_priv2oct.3ossl | 1 - .../share/man/man3/EC_KEY_set_asn1_flag.3ossl | 1 - .../share/man/man3/EC_KEY_set_conv_form.3ossl | 1 - .../share/man/man3/EC_KEY_set_enc_flags.3ossl | 1 - .../share/man/man3/EC_KEY_set_ex_data.3ossl | 1 - .../share/man/man3/EC_KEY_set_flags.3ossl | 1 - .../share/man/man3/EC_KEY_set_group.3ossl | 1 - .../share/man/man3/EC_KEY_set_method.3ossl | 1 - .../man/man3/EC_KEY_set_private_key.3ossl | 1 - .../man/man3/EC_KEY_set_public_key.3ossl | 1 - ...EY_set_public_key_affine_coordinates.3ossl | 1 - .../share/man/man3/EC_KEY_up_ref.3ossl | 1 - .../man/man3/EC_METHOD_get_field_type.3ossl | 1 - .../share/man/man3/EC_POINT_add.3ossl | 233 -- .../share/man/man3/EC_POINT_bn2point.3ossl | 1 - .../share/man/man3/EC_POINT_clear_free.3ossl | 1 - .../share/man/man3/EC_POINT_cmp.3ossl | 1 - .../share/man/man3/EC_POINT_copy.3ossl | 1 - .../share/man/man3/EC_POINT_dbl.3ossl | 1 - .../share/man/man3/EC_POINT_dup.3ossl | 1 - .../share/man/man3/EC_POINT_free.3ossl | 1 - ...OINT_get_Jprojective_coordinates_GFp.3ossl | 1 - .../EC_POINT_get_affine_coordinates.3ossl | 1 - ...EC_POINT_get_affine_coordinates_GF2m.3ossl | 1 - .../EC_POINT_get_affine_coordinates_GFp.3ossl | 1 - .../share/man/man3/EC_POINT_hex2point.3ossl | 1 - .../share/man/man3/EC_POINT_invert.3ossl | 1 - .../man/man3/EC_POINT_is_at_infinity.3ossl | 1 - .../share/man/man3/EC_POINT_is_on_curve.3ossl | 1 - .../share/man/man3/EC_POINT_make_affine.3ossl | 1 - .../share/man/man3/EC_POINT_method_of.3ossl | 1 - .../share/man/man3/EC_POINT_mul.3ossl | 1 - .../share/man/man3/EC_POINT_new.3ossl | 411 ---- .../share/man/man3/EC_POINT_oct2point.3ossl | 1 - .../share/man/man3/EC_POINT_point2bn.3ossl | 1 - .../share/man/man3/EC_POINT_point2buf.3ossl | 1 - .../share/man/man3/EC_POINT_point2hex.3ossl | 1 - .../share/man/man3/EC_POINT_point2oct.3ossl | 1 - ...OINT_set_Jprojective_coordinates_GFp.3ossl | 1 - .../EC_POINT_set_affine_coordinates.3ossl | 1 - ...EC_POINT_set_affine_coordinates_GF2m.3ossl | 1 - .../EC_POINT_set_affine_coordinates_GFp.3ossl | 1 - .../EC_POINT_set_compressed_coordinates.3ossl | 1 - ...OINT_set_compressed_coordinates_GF2m.3ossl | 1 - ...POINT_set_compressed_coordinates_GFp.3ossl | 1 - .../man/man3/EC_POINT_set_to_infinity.3ossl | 1 - .../man/man3/EC_POINTs_make_affine.3ossl | 1 - .../share/man/man3/EC_POINTs_mul.3ossl | 1 - .../man/man3/EC_get_builtin_curves.3ossl | 1 - .../share/man/man3/EDIPARTYNAME_free.3ossl | 1 - .../share/man/man3/EDIPARTYNAME_new.3ossl | 1 - .../share/man/man3/ENGINE_add.3ossl | 816 ------ .../man/man3/ENGINE_add_conf_module.3ossl | 1 - .../share/man/man3/ENGINE_by_id.3ossl | 1 - .../share/man/man3/ENGINE_cleanup.3ossl | 1 - .../man/man3/ENGINE_cmd_is_executable.3ossl | 1 - .../share/man/man3/ENGINE_ctrl.3ossl | 1 - .../share/man/man3/ENGINE_ctrl_cmd.3ossl | 1 - .../man/man3/ENGINE_ctrl_cmd_string.3ossl | 1 - .../share/man/man3/ENGINE_finish.3ossl | 1 - .../share/man/man3/ENGINE_free.3ossl | 1 - .../share/man/man3/ENGINE_get_DH.3ossl | 1 - .../share/man/man3/ENGINE_get_DSA.3ossl | 1 - .../share/man/man3/ENGINE_get_RAND.3ossl | 1 - .../share/man/man3/ENGINE_get_RSA.3ossl | 1 - .../share/man/man3/ENGINE_get_cipher.3ossl | 1 - .../man/man3/ENGINE_get_cipher_engine.3ossl | 1 - .../share/man/man3/ENGINE_get_ciphers.3ossl | 1 - .../share/man/man3/ENGINE_get_cmd_defns.3ossl | 1 - .../man/man3/ENGINE_get_ctrl_function.3ossl | 1 - .../man/man3/ENGINE_get_default_DH.3ossl | 1 - .../man/man3/ENGINE_get_default_DSA.3ossl | 1 - .../man/man3/ENGINE_get_default_RAND.3ossl | 1 - .../man/man3/ENGINE_get_default_RSA.3ossl | 1 - .../man3/ENGINE_get_destroy_function.3ossl | 1 - .../share/man/man3/ENGINE_get_digest.3ossl | 1 - .../man/man3/ENGINE_get_digest_engine.3ossl | 1 - .../share/man/man3/ENGINE_get_digests.3ossl | 1 - .../share/man/man3/ENGINE_get_ex_data.3ossl | 1 - .../man/man3/ENGINE_get_ex_new_index.3ossl | 1 - .../man/man3/ENGINE_get_finish_function.3ossl | 1 - .../share/man/man3/ENGINE_get_first.3ossl | 1 - .../share/man/man3/ENGINE_get_flags.3ossl | 1 - .../share/man/man3/ENGINE_get_id.3ossl | 1 - .../man/man3/ENGINE_get_init_function.3ossl | 1 - .../share/man/man3/ENGINE_get_last.3ossl | 1 - .../ENGINE_get_load_privkey_function.3ossl | 1 - .../ENGINE_get_load_pubkey_function.3ossl | 1 - .../share/man/man3/ENGINE_get_name.3ossl | 1 - .../share/man/man3/ENGINE_get_next.3ossl | 1 - .../share/man/man3/ENGINE_get_prev.3ossl | 1 - .../man/man3/ENGINE_get_table_flags.3ossl | 1 - .../share/man/man3/ENGINE_init.3ossl | 1 - .../man3/ENGINE_load_builtin_engines.3ossl | 1 - .../man/man3/ENGINE_load_private_key.3ossl | 1 - .../man/man3/ENGINE_load_public_key.3ossl | 1 - .../share/man/man3/ENGINE_new.3ossl | 1 - .../share/man/man3/ENGINE_register_DH.3ossl | 1 - .../share/man/man3/ENGINE_register_DSA.3ossl | 1 - .../share/man/man3/ENGINE_register_RAND.3ossl | 1 - .../share/man/man3/ENGINE_register_RSA.3ossl | 1 - .../man/man3/ENGINE_register_all_DH.3ossl | 1 - .../man/man3/ENGINE_register_all_DSA.3ossl | 1 - .../man/man3/ENGINE_register_all_RAND.3ossl | 1 - .../man/man3/ENGINE_register_all_RSA.3ossl | 1 - .../man3/ENGINE_register_all_ciphers.3ossl | 1 - .../man3/ENGINE_register_all_complete.3ossl | 1 - .../man3/ENGINE_register_all_digests.3ossl | 1 - .../man/man3/ENGINE_register_ciphers.3ossl | 1 - .../man/man3/ENGINE_register_complete.3ossl | 1 - .../man/man3/ENGINE_register_digests.3ossl | 1 - .../share/man/man3/ENGINE_remove.3ossl | 1 - .../share/man/man3/ENGINE_set_DH.3ossl | 1 - .../share/man/man3/ENGINE_set_DSA.3ossl | 1 - .../share/man/man3/ENGINE_set_RAND.3ossl | 1 - .../share/man/man3/ENGINE_set_RSA.3ossl | 1 - .../share/man/man3/ENGINE_set_ciphers.3ossl | 1 - .../share/man/man3/ENGINE_set_cmd_defns.3ossl | 1 - .../man/man3/ENGINE_set_ctrl_function.3ossl | 1 - .../share/man/man3/ENGINE_set_default.3ossl | 1 - .../man/man3/ENGINE_set_default_DH.3ossl | 1 - .../man/man3/ENGINE_set_default_DSA.3ossl | 1 - .../man/man3/ENGINE_set_default_RAND.3ossl | 1 - .../man/man3/ENGINE_set_default_RSA.3ossl | 1 - .../man/man3/ENGINE_set_default_ciphers.3ossl | 1 - .../man/man3/ENGINE_set_default_digests.3ossl | 1 - .../man/man3/ENGINE_set_default_string.3ossl | 1 - .../man3/ENGINE_set_destroy_function.3ossl | 1 - .../share/man/man3/ENGINE_set_digests.3ossl | 1 - .../share/man/man3/ENGINE_set_ex_data.3ossl | 1 - .../man/man3/ENGINE_set_finish_function.3ossl | 1 - .../share/man/man3/ENGINE_set_flags.3ossl | 1 - .../share/man/man3/ENGINE_set_id.3ossl | 1 - .../man/man3/ENGINE_set_init_function.3ossl | 1 - .../ENGINE_set_load_privkey_function.3ossl | 1 - .../ENGINE_set_load_pubkey_function.3ossl | 1 - .../share/man/man3/ENGINE_set_name.3ossl | 1 - .../man/man3/ENGINE_set_table_flags.3ossl | 1 - .../share/man/man3/ENGINE_unregister_DH.3ossl | 1 - .../man/man3/ENGINE_unregister_DSA.3ossl | 1 - .../man/man3/ENGINE_unregister_RAND.3ossl | 1 - .../man/man3/ENGINE_unregister_RSA.3ossl | 1 - .../man/man3/ENGINE_unregister_ciphers.3ossl | 1 - .../man/man3/ENGINE_unregister_digests.3ossl | 1 - .../share/man/man3/ENGINE_up_ref.3ossl | 1 - .../share/man/man3/ERR_FATAL_ERROR.3ossl | 1 - .../share/man/man3/ERR_GET_LIB.3ossl | 202 -- .../share/man/man3/ERR_GET_REASON.3ossl | 1 - openssl-install/share/man/man3/ERR_PACK.3ossl | 1 - .../share/man/man3/ERR_add_error_data.3ossl | 1 - .../man/man3/ERR_add_error_mem_bio.3ossl | 1 - .../share/man/man3/ERR_add_error_txt.3ossl | 1 - .../share/man/man3/ERR_add_error_vdata.3ossl | 1 - .../share/man/man3/ERR_clear_error.3ossl | 166 -- .../share/man/man3/ERR_clear_last_mark.3ossl | 1 - .../share/man/man3/ERR_count_to_mark.3ossl | 1 - .../share/man/man3/ERR_error_string.3ossl | 216 -- .../share/man/man3/ERR_error_string_n.3ossl | 1 - .../share/man/man3/ERR_free_strings.3ossl | 1 - .../man/man3/ERR_func_error_string.3ossl | 1 - .../share/man/man3/ERR_get_error.3ossl | 274 --- .../share/man/man3/ERR_get_error_all.3ossl | 1 - .../share/man/man3/ERR_get_error_line.3ossl | 1 - .../man/man3/ERR_get_error_line_data.3ossl | 1 - .../man/man3/ERR_get_next_error_library.3ossl | 1 - .../share/man/man3/ERR_lib_error_string.3ossl | 1 - .../man/man3/ERR_load_crypto_strings.3ossl | 187 -- .../share/man/man3/ERR_load_strings.3ossl | 192 -- openssl-install/share/man/man3/ERR_new.3ossl | 209 -- .../share/man/man3/ERR_peek_error.3ossl | 1 - .../share/man/man3/ERR_peek_error_all.3ossl | 1 - .../share/man/man3/ERR_peek_error_data.3ossl | 1 - .../share/man/man3/ERR_peek_error_func.3ossl | 1 - .../share/man/man3/ERR_peek_error_line.3ossl | 1 - .../man/man3/ERR_peek_error_line_data.3ossl | 1 - .../share/man/man3/ERR_peek_last_error.3ossl | 1 - .../man/man3/ERR_peek_last_error_all.3ossl | 1 - .../man/man3/ERR_peek_last_error_data.3ossl | 1 - .../man/man3/ERR_peek_last_error_func.3ossl | 1 - .../man/man3/ERR_peek_last_error_line.3ossl | 1 - .../man3/ERR_peek_last_error_line_data.3ossl | 1 - openssl-install/share/man/man3/ERR_pop.3ossl | 1 - .../share/man/man3/ERR_pop_to_mark.3ossl | 1 - .../share/man/man3/ERR_print_errors.3ossl | 193 -- .../share/man/man3/ERR_print_errors_cb.3ossl | 1 - .../share/man/man3/ERR_print_errors_fp.3ossl | 1 - .../share/man/man3/ERR_put_error.3ossl | 299 --- .../share/man/man3/ERR_raise.3ossl | 1 - .../share/man/man3/ERR_raise_data.3ossl | 1 - .../man/man3/ERR_reason_error_string.3ossl | 1 - .../share/man/man3/ERR_remove_state.3ossl | 184 -- .../man/man3/ERR_remove_thread_state.3ossl | 1 - .../share/man/man3/ERR_set_debug.3ossl | 1 - .../share/man/man3/ERR_set_error.3ossl | 1 - .../share/man/man3/ERR_set_mark.3ossl | 192 -- .../share/man/man3/ERR_vset_error.3ossl | 1 - .../share/man/man3/ESS_CERT_ID_V2_dup.3ossl | 1 - .../share/man/man3/ESS_CERT_ID_V2_free.3ossl | 1 - .../share/man/man3/ESS_CERT_ID_V2_new.3ossl | 1 - .../share/man/man3/ESS_CERT_ID_dup.3ossl | 1 - .../share/man/man3/ESS_CERT_ID_free.3ossl | 1 - .../share/man/man3/ESS_CERT_ID_new.3ossl | 1 - .../man/man3/ESS_ISSUER_SERIAL_dup.3ossl | 1 - .../man/man3/ESS_ISSUER_SERIAL_free.3ossl | 1 - .../man/man3/ESS_ISSUER_SERIAL_new.3ossl | 1 - .../man/man3/ESS_SIGNING_CERT_V2_dup.3ossl | 1 - .../man/man3/ESS_SIGNING_CERT_V2_free.3ossl | 1 - .../man/man3/ESS_SIGNING_CERT_V2_it.3ossl | 1 - .../man/man3/ESS_SIGNING_CERT_V2_new.3ossl | 1 - .../share/man/man3/ESS_SIGNING_CERT_dup.3ossl | 1 - .../man/man3/ESS_SIGNING_CERT_free.3ossl | 1 - .../share/man/man3/ESS_SIGNING_CERT_it.3ossl | 1 - .../share/man/man3/ESS_SIGNING_CERT_new.3ossl | 1 - .../EVP_ASYM_CIPHER_do_all_provided.3ossl | 1 - .../man/man3/EVP_ASYM_CIPHER_fetch.3ossl | 1 - .../share/man/man3/EVP_ASYM_CIPHER_free.3ossl | 243 -- .../EVP_ASYM_CIPHER_get0_description.3ossl | 1 - .../man/man3/EVP_ASYM_CIPHER_get0_name.3ossl | 1 - .../man3/EVP_ASYM_CIPHER_get0_provider.3ossl | 1 - .../EVP_ASYM_CIPHER_gettable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_ASYM_CIPHER_is_a.3ossl | 1 - .../man3/EVP_ASYM_CIPHER_names_do_all.3ossl | 1 - .../EVP_ASYM_CIPHER_settable_ctx_params.3ossl | 1 - .../man/man3/EVP_ASYM_CIPHER_up_ref.3ossl | 1 - .../share/man/man3/EVP_BytesToKey.3ossl | 210 -- .../man/man3/EVP_CIPHER_CTX_block_size.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_cipher.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_clear_flags.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_copy.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_ctrl.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_dup.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_encrypting.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_flags.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_free.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get0_cipher.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get0_name.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get1_cipher.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get_algor.3ossl | 1 - .../EVP_CIPHER_CTX_get_algor_params.3ossl | 1 - .../man3/EVP_CIPHER_CTX_get_app_data.3ossl | 1 - .../man3/EVP_CIPHER_CTX_get_block_size.3ossl | 1 - .../man3/EVP_CIPHER_CTX_get_cipher_data.3ossl | 183 -- .../man3/EVP_CIPHER_CTX_get_iv_length.3ossl | 1 - .../man3/EVP_CIPHER_CTX_get_key_length.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get_mode.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get_nid.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get_num.3ossl | 1 - .../man3/EVP_CIPHER_CTX_get_original_iv.3ossl | 208 -- .../man/man3/EVP_CIPHER_CTX_get_params.3ossl | 1 - .../man3/EVP_CIPHER_CTX_get_tag_length.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_get_type.3ossl | 1 - .../man3/EVP_CIPHER_CTX_get_updated_iv.3ossl | 1 - .../man3/EVP_CIPHER_CTX_gettable_params.3ossl | 1 - .../man3/EVP_CIPHER_CTX_is_encrypting.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_iv.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_iv_length.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_iv_noconst.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_key_length.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_mode.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_new.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_nid.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_num.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_original_iv.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_reset.3ossl | 1 - .../EVP_CIPHER_CTX_set_algor_params.3ossl | 1 - .../man3/EVP_CIPHER_CTX_set_app_data.3ossl | 1 - .../man3/EVP_CIPHER_CTX_set_cipher_data.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_set_flags.3ossl | 1 - .../man3/EVP_CIPHER_CTX_set_key_length.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_set_num.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_set_padding.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_set_params.3ossl | 1 - .../man3/EVP_CIPHER_CTX_settable_params.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_tag_length.3ossl | 1 - .../man/man3/EVP_CIPHER_CTX_test_flags.3ossl | 1 - .../share/man/man3/EVP_CIPHER_CTX_type.3ossl | 1 - .../man/man3/EVP_CIPHER_asn1_to_param.3ossl | 1 - .../man/man3/EVP_CIPHER_block_size.3ossl | 1 - .../man/man3/EVP_CIPHER_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_CIPHER_fetch.3ossl | 1 - .../share/man/man3/EVP_CIPHER_flags.3ossl | 1 - .../share/man/man3/EVP_CIPHER_free.3ossl | 1 - .../man3/EVP_CIPHER_get0_description.3ossl | 1 - .../share/man/man3/EVP_CIPHER_get0_name.3ossl | 1 - .../man/man3/EVP_CIPHER_get0_provider.3ossl | 1 - .../man/man3/EVP_CIPHER_get_block_size.3ossl | 1 - .../share/man/man3/EVP_CIPHER_get_flags.3ossl | 1 - .../man/man3/EVP_CIPHER_get_iv_length.3ossl | 1 - .../man/man3/EVP_CIPHER_get_key_length.3ossl | 1 - .../share/man/man3/EVP_CIPHER_get_mode.3ossl | 1 - .../share/man/man3/EVP_CIPHER_get_nid.3ossl | 1 - .../man/man3/EVP_CIPHER_get_params.3ossl | 1 - .../share/man/man3/EVP_CIPHER_get_type.3ossl | 1 - .../man3/EVP_CIPHER_gettable_ctx_params.3ossl | 1 - .../man/man3/EVP_CIPHER_gettable_params.3ossl | 1 - .../share/man/man3/EVP_CIPHER_is_a.3ossl | 1 - .../share/man/man3/EVP_CIPHER_iv_length.3ossl | 1 - .../man/man3/EVP_CIPHER_key_length.3ossl | 1 - .../share/man/man3/EVP_CIPHER_meth_dup.3ossl | 1 - .../share/man/man3/EVP_CIPHER_meth_free.3ossl | 1 - .../man3/EVP_CIPHER_meth_get_cleanup.3ossl | 1 - .../man/man3/EVP_CIPHER_meth_get_ctrl.3ossl | 1 - .../man3/EVP_CIPHER_meth_get_do_cipher.3ossl | 1 - .../EVP_CIPHER_meth_get_get_asn1_params.3ossl | 1 - .../man/man3/EVP_CIPHER_meth_get_init.3ossl | 1 - .../EVP_CIPHER_meth_get_set_asn1_params.3ossl | 1 - .../share/man/man3/EVP_CIPHER_meth_new.3ossl | 371 --- .../man3/EVP_CIPHER_meth_set_cleanup.3ossl | 1 - .../man/man3/EVP_CIPHER_meth_set_ctrl.3ossl | 1 - .../man3/EVP_CIPHER_meth_set_do_cipher.3ossl | 1 - .../man/man3/EVP_CIPHER_meth_set_flags.3ossl | 1 - .../EVP_CIPHER_meth_set_get_asn1_params.3ossl | 1 - .../EVP_CIPHER_meth_set_impl_ctx_size.3ossl | 1 - .../man/man3/EVP_CIPHER_meth_set_init.3ossl | 1 - .../man3/EVP_CIPHER_meth_set_iv_length.3ossl | 1 - .../EVP_CIPHER_meth_set_set_asn1_params.3ossl | 1 - .../share/man/man3/EVP_CIPHER_mode.3ossl | 1 - .../share/man/man3/EVP_CIPHER_name.3ossl | 1 - .../man/man3/EVP_CIPHER_names_do_all.3ossl | 1 - .../share/man/man3/EVP_CIPHER_nid.3ossl | 1 - .../man/man3/EVP_CIPHER_param_to_asn1.3ossl | 1 - .../man3/EVP_CIPHER_settable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_CIPHER_type.3ossl | 1 - .../share/man/man3/EVP_CIPHER_up_ref.3ossl | 1 - .../share/man/man3/EVP_Cipher.3ossl | 1 - .../share/man/man3/EVP_CipherFinal.3ossl | 1 - .../share/man/man3/EVP_CipherFinal_ex.3ossl | 1 - .../share/man/man3/EVP_CipherInit.3ossl | 1 - .../share/man/man3/EVP_CipherInit_ex.3ossl | 1 - .../share/man/man3/EVP_CipherInit_ex2.3ossl | 1 - .../share/man/man3/EVP_CipherUpdate.3ossl | 1 - .../share/man/man3/EVP_DecodeBlock.3ossl | 1 - .../share/man/man3/EVP_DecodeFinal.3ossl | 1 - .../share/man/man3/EVP_DecodeInit.3ossl | 1 - .../share/man/man3/EVP_DecodeUpdate.3ossl | 1 - .../share/man/man3/EVP_DecryptFinal.3ossl | 1 - .../share/man/man3/EVP_DecryptFinal_ex.3ossl | 1 - .../share/man/man3/EVP_DecryptInit.3ossl | 1 - .../share/man/man3/EVP_DecryptInit_ex.3ossl | 1 - .../share/man/man3/EVP_DecryptInit_ex2.3ossl | 1 - .../share/man/man3/EVP_DecryptUpdate.3ossl | 1 - .../share/man/man3/EVP_Digest.3ossl | 1 - .../share/man/man3/EVP_DigestFinal.3ossl | 1 - .../share/man/man3/EVP_DigestFinalXOF.3ossl | 1 - .../share/man/man3/EVP_DigestFinal_ex.3ossl | 1 - .../share/man/man3/EVP_DigestInit.3ossl | 880 ------- .../share/man/man3/EVP_DigestInit_ex.3ossl | 1 - .../share/man/man3/EVP_DigestInit_ex2.3ossl | 1 - .../share/man/man3/EVP_DigestSign.3ossl | 1 - .../share/man/man3/EVP_DigestSignFinal.3ossl | 1 - .../share/man/man3/EVP_DigestSignInit.3ossl | 339 --- .../man/man3/EVP_DigestSignInit_ex.3ossl | 1 - .../share/man/man3/EVP_DigestSignUpdate.3ossl | 1 - .../share/man/man3/EVP_DigestSqueeze.3ossl | 1 - .../share/man/man3/EVP_DigestUpdate.3ossl | 1 - .../share/man/man3/EVP_DigestVerify.3ossl | 1 - .../man/man3/EVP_DigestVerifyFinal.3ossl | 1 - .../share/man/man3/EVP_DigestVerifyInit.3ossl | 324 --- .../man/man3/EVP_DigestVerifyInit_ex.3ossl | 1 - .../man/man3/EVP_DigestVerifyUpdate.3ossl | 1 - .../share/man/man3/EVP_EC_gen.3ossl | 1 - .../share/man/man3/EVP_ENCODE_CTX_copy.3ossl | 1 - .../share/man/man3/EVP_ENCODE_CTX_free.3ossl | 1 - .../share/man/man3/EVP_ENCODE_CTX_new.3ossl | 1 - .../share/man/man3/EVP_ENCODE_CTX_num.3ossl | 1 - .../share/man/man3/EVP_EncodeBlock.3ossl | 1 - .../share/man/man3/EVP_EncodeFinal.3ossl | 1 - .../share/man/man3/EVP_EncodeInit.3ossl | 320 --- .../share/man/man3/EVP_EncodeUpdate.3ossl | 1 - .../share/man/man3/EVP_EncryptFinal.3ossl | 1 - .../share/man/man3/EVP_EncryptFinal_ex.3ossl | 1 - .../share/man/man3/EVP_EncryptInit.3ossl | 1852 -------------- .../share/man/man3/EVP_EncryptInit_ex.3ossl | 1 - .../share/man/man3/EVP_EncryptInit_ex2.3ossl | 1 - .../share/man/man3/EVP_EncryptUpdate.3ossl | 1 - openssl-install/share/man/man3/EVP_KDF.3ossl | 439 ---- .../share/man/man3/EVP_KDF_CTX.3ossl | 1 - .../share/man/man3/EVP_KDF_CTX_dup.3ossl | 1 - .../share/man/man3/EVP_KDF_CTX_free.3ossl | 1 - .../man/man3/EVP_KDF_CTX_get_kdf_size.3ossl | 1 - .../man/man3/EVP_KDF_CTX_get_params.3ossl | 1 - .../man3/EVP_KDF_CTX_gettable_params.3ossl | 1 - .../share/man/man3/EVP_KDF_CTX_kdf.3ossl | 1 - .../share/man/man3/EVP_KDF_CTX_new.3ossl | 1 - .../share/man/man3/EVP_KDF_CTX_reset.3ossl | 1 - .../man/man3/EVP_KDF_CTX_set_params.3ossl | 1 - .../man3/EVP_KDF_CTX_settable_params.3ossl | 1 - .../share/man/man3/EVP_KDF_derive.3ossl | 1 - .../man/man3/EVP_KDF_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_KDF_fetch.3ossl | 1 - .../share/man/man3/EVP_KDF_free.3ossl | 1 - .../man/man3/EVP_KDF_get0_description.3ossl | 1 - .../share/man/man3/EVP_KDF_get0_name.3ossl | 1 - .../man/man3/EVP_KDF_get0_provider.3ossl | 1 - .../share/man/man3/EVP_KDF_get_params.3ossl | 1 - .../man3/EVP_KDF_gettable_ctx_params.3ossl | 1 - .../man/man3/EVP_KDF_gettable_params.3ossl | 1 - .../share/man/man3/EVP_KDF_is_a.3ossl | 1 - .../share/man/man3/EVP_KDF_names_do_all.3ossl | 1 - .../man3/EVP_KDF_settable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_KDF_up_ref.3ossl | 1 - .../man/man3/EVP_KEM_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_KEM_fetch.3ossl | 1 - .../share/man/man3/EVP_KEM_free.3ossl | 237 -- .../man/man3/EVP_KEM_get0_description.3ossl | 1 - .../share/man/man3/EVP_KEM_get0_name.3ossl | 1 - .../man/man3/EVP_KEM_get0_provider.3ossl | 1 - .../man3/EVP_KEM_gettable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_KEM_is_a.3ossl | 1 - .../share/man/man3/EVP_KEM_names_do_all.3ossl | 1 - .../man3/EVP_KEM_settable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_KEM_up_ref.3ossl | 1 - .../man3/EVP_KEYEXCH_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_KEYEXCH_fetch.3ossl | 1 - .../share/man/man3/EVP_KEYEXCH_free.3ossl | 242 -- .../man3/EVP_KEYEXCH_get0_description.3ossl | 1 - .../man/man3/EVP_KEYEXCH_get0_name.3ossl | 1 - .../man/man3/EVP_KEYEXCH_get0_provider.3ossl | 1 - .../EVP_KEYEXCH_gettable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_KEYEXCH_is_a.3ossl | 1 - .../man/man3/EVP_KEYEXCH_names_do_all.3ossl | 1 - .../EVP_KEYEXCH_settable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_KEYEXCH_up_ref.3ossl | 1 - .../share/man/man3/EVP_KEYMGMT.3ossl | 285 --- .../man3/EVP_KEYMGMT_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_KEYMGMT_fetch.3ossl | 1 - .../share/man/man3/EVP_KEYMGMT_free.3ossl | 1 - .../EVP_KEYMGMT_gen_gettable_params.3ossl | 1 - .../EVP_KEYMGMT_gen_settable_params.3ossl | 1 - .../man3/EVP_KEYMGMT_get0_description.3ossl | 1 - .../man/man3/EVP_KEYMGMT_get0_name.3ossl | 1 - .../man/man3/EVP_KEYMGMT_get0_provider.3ossl | 1 - .../man3/EVP_KEYMGMT_gettable_params.3ossl | 1 - .../share/man/man3/EVP_KEYMGMT_is_a.3ossl | 1 - .../man/man3/EVP_KEYMGMT_names_do_all.3ossl | 1 - .../man3/EVP_KEYMGMT_settable_params.3ossl | 1 - .../share/man/man3/EVP_KEYMGMT_up_ref.3ossl | 1 - openssl-install/share/man/man3/EVP_MAC.3ossl | 630 ----- .../share/man/man3/EVP_MAC_CTX.3ossl | 1 - .../share/man/man3/EVP_MAC_CTX_dup.3ossl | 1 - .../share/man/man3/EVP_MAC_CTX_free.3ossl | 1 - .../share/man/man3/EVP_MAC_CTX_get0_mac.3ossl | 1 - .../man/man3/EVP_MAC_CTX_get_block_size.3ossl | 1 - .../man/man3/EVP_MAC_CTX_get_mac_size.3ossl | 1 - .../man/man3/EVP_MAC_CTX_get_params.3ossl | 1 - .../man3/EVP_MAC_CTX_gettable_params.3ossl | 1 - .../share/man/man3/EVP_MAC_CTX_new.3ossl | 1 - .../man/man3/EVP_MAC_CTX_set_params.3ossl | 1 - .../man3/EVP_MAC_CTX_settable_params.3ossl | 1 - .../man/man3/EVP_MAC_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_MAC_fetch.3ossl | 1 - .../share/man/man3/EVP_MAC_final.3ossl | 1 - .../share/man/man3/EVP_MAC_finalXOF.3ossl | 1 - .../share/man/man3/EVP_MAC_free.3ossl | 1 - .../man/man3/EVP_MAC_get0_description.3ossl | 1 - .../share/man/man3/EVP_MAC_get0_name.3ossl | 1 - .../man/man3/EVP_MAC_get0_provider.3ossl | 1 - .../share/man/man3/EVP_MAC_get_params.3ossl | 1 - .../man3/EVP_MAC_gettable_ctx_params.3ossl | 1 - .../man/man3/EVP_MAC_gettable_params.3ossl | 1 - .../share/man/man3/EVP_MAC_init.3ossl | 1 - .../share/man/man3/EVP_MAC_is_a.3ossl | 1 - .../share/man/man3/EVP_MAC_names_do_all.3ossl | 1 - .../man3/EVP_MAC_settable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_MAC_up_ref.3ossl | 1 - .../share/man/man3/EVP_MAC_update.3ossl | 1 - .../man/man3/EVP_MD_CTX_block_size.3ossl | 1 - .../man/man3/EVP_MD_CTX_clear_flags.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_copy.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_copy_ex.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_ctrl.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_dup.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_free.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_get0_md.3ossl | 1 - .../man/man3/EVP_MD_CTX_get0_md_data.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_get0_name.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_get1_md.3ossl | 1 - .../man/man3/EVP_MD_CTX_get_block_size.3ossl | 1 - .../man/man3/EVP_MD_CTX_get_params.3ossl | 1 - .../man/man3/EVP_MD_CTX_get_pkey_ctx.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_get_size.3ossl | 1 - .../man/man3/EVP_MD_CTX_get_size_ex.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_get_type.3ossl | 1 - .../man/man3/EVP_MD_CTX_gettable_params.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_md.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_md_data.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_new.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_pkey_ctx.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_reset.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_set_flags.3ossl | 1 - .../man/man3/EVP_MD_CTX_set_params.3ossl | 1 - .../man/man3/EVP_MD_CTX_set_pkey_ctx.3ossl | 1 - .../man/man3/EVP_MD_CTX_set_update_fn.3ossl | 1 - .../man/man3/EVP_MD_CTX_settable_params.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_size.3ossl | 1 - .../man/man3/EVP_MD_CTX_test_flags.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_type.3ossl | 1 - .../share/man/man3/EVP_MD_CTX_update_fn.3ossl | 1 - .../share/man/man3/EVP_MD_block_size.3ossl | 1 - .../man/man3/EVP_MD_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_MD_fetch.3ossl | 1 - .../share/man/man3/EVP_MD_flags.3ossl | 1 - .../share/man/man3/EVP_MD_free.3ossl | 1 - .../man/man3/EVP_MD_get0_description.3ossl | 1 - .../share/man/man3/EVP_MD_get0_name.3ossl | 1 - .../share/man/man3/EVP_MD_get0_provider.3ossl | 1 - .../man/man3/EVP_MD_get_block_size.3ossl | 1 - .../share/man/man3/EVP_MD_get_flags.3ossl | 1 - .../share/man/man3/EVP_MD_get_params.3ossl | 1 - .../share/man/man3/EVP_MD_get_pkey_type.3ossl | 1 - .../share/man/man3/EVP_MD_get_size.3ossl | 1 - .../share/man/man3/EVP_MD_get_type.3ossl | 1 - .../man/man3/EVP_MD_gettable_ctx_params.3ossl | 1 - .../man/man3/EVP_MD_gettable_params.3ossl | 1 - .../share/man/man3/EVP_MD_is_a.3ossl | 1 - .../share/man/man3/EVP_MD_meth_dup.3ossl | 1 - .../share/man/man3/EVP_MD_meth_free.3ossl | 1 - .../man3/EVP_MD_meth_get_app_datasize.3ossl | 1 - .../man/man3/EVP_MD_meth_get_cleanup.3ossl | 1 - .../share/man/man3/EVP_MD_meth_get_copy.3ossl | 1 - .../share/man/man3/EVP_MD_meth_get_ctrl.3ossl | 1 - .../man/man3/EVP_MD_meth_get_final.3ossl | 1 - .../man/man3/EVP_MD_meth_get_flags.3ossl | 1 - .../share/man/man3/EVP_MD_meth_get_init.3ossl | 1 - .../EVP_MD_meth_get_input_blocksize.3ossl | 1 - .../man3/EVP_MD_meth_get_result_size.3ossl | 1 - .../man/man3/EVP_MD_meth_get_update.3ossl | 1 - .../share/man/man3/EVP_MD_meth_new.3ossl | 328 --- .../man3/EVP_MD_meth_set_app_datasize.3ossl | 1 - .../man/man3/EVP_MD_meth_set_cleanup.3ossl | 1 - .../share/man/man3/EVP_MD_meth_set_copy.3ossl | 1 - .../share/man/man3/EVP_MD_meth_set_ctrl.3ossl | 1 - .../man/man3/EVP_MD_meth_set_final.3ossl | 1 - .../man/man3/EVP_MD_meth_set_flags.3ossl | 1 - .../share/man/man3/EVP_MD_meth_set_init.3ossl | 1 - .../EVP_MD_meth_set_input_blocksize.3ossl | 1 - .../man3/EVP_MD_meth_set_result_size.3ossl | 1 - .../man/man3/EVP_MD_meth_set_update.3ossl | 1 - .../share/man/man3/EVP_MD_name.3ossl | 1 - .../share/man/man3/EVP_MD_names_do_all.3ossl | 1 - .../share/man/man3/EVP_MD_nid.3ossl | 1 - .../share/man/man3/EVP_MD_pkey_type.3ossl | 1 - .../man/man3/EVP_MD_settable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_MD_size.3ossl | 1 - .../share/man/man3/EVP_MD_type.3ossl | 1 - .../share/man/man3/EVP_MD_up_ref.3ossl | 1 - .../share/man/man3/EVP_MD_xof.3ossl | 1 - .../share/man/man3/EVP_OpenFinal.3ossl | 1 - .../share/man/man3/EVP_OpenInit.3ossl | 200 -- .../share/man/man3/EVP_OpenUpdate.3ossl | 1 - .../share/man/man3/EVP_PBE_CipherInit.3ossl | 229 -- .../man/man3/EVP_PBE_CipherInit_ex.3ossl | 1 - .../share/man/man3/EVP_PBE_alg_add.3ossl | 1 - .../share/man/man3/EVP_PBE_alg_add_type.3ossl | 1 - .../share/man/man3/EVP_PBE_find.3ossl | 1 - .../share/man/man3/EVP_PBE_find_ex.3ossl | 1 - .../share/man/man3/EVP_PBE_scrypt.3ossl | 1 - .../share/man/man3/EVP_PBE_scrypt_ex.3ossl | 1 - .../share/man/man3/EVP_PKCS82PKEY.3ossl | 1 - .../share/man/man3/EVP_PKCS82PKEY_ex.3ossl | 1 - openssl-install/share/man/man3/EVP_PKEY.3ossl | 1 - .../share/man/man3/EVP_PKEY2PKCS8.3ossl | 179 -- .../share/man/man3/EVP_PKEY_ASN1_METHOD.3ossl | 592 ----- .../man3/EVP_PKEY_CTX_add1_hkdf_info.3ossl | 1 - .../EVP_PKEY_CTX_add1_tls1_prf_seed.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_ctrl.3ossl | 818 ------ .../man/man3/EVP_PKEY_CTX_ctrl_str.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_ctrl_uint64.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_dup.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_free.3ossl | 1 - .../man3/EVP_PKEY_CTX_get0_dh_kdf_oid.3ossl | 1 - .../man3/EVP_PKEY_CTX_get0_dh_kdf_ukm.3ossl | 1 - .../man3/EVP_PKEY_CTX_get0_ecdh_kdf_ukm.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get0_libctx.3ossl | 185 -- .../man/man3/EVP_PKEY_CTX_get0_peerkey.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get0_pkey.3ossl | 188 -- .../man/man3/EVP_PKEY_CTX_get0_propq.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get0_provider.3ossl | 1 - .../EVP_PKEY_CTX_get0_rsa_oaep_label.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_get1_id.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get1_id_len.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get_algor.3ossl | 195 -- .../man3/EVP_PKEY_CTX_get_algor_params.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get_app_data.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_get_cb.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get_dh_kdf_md.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_dh_kdf_outlen.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_dh_kdf_type.3ossl | 1 - .../EVP_PKEY_CTX_get_ecdh_cofactor_mode.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_ecdh_kdf_md.3ossl | 1 - .../EVP_PKEY_CTX_get_ecdh_kdf_outlen.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_ecdh_kdf_type.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_group_name.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_keygen_info.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_get_params.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_rsa_mgf1_md.3ossl | 1 - .../EVP_PKEY_CTX_get_rsa_mgf1_md_name.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_rsa_oaep_md.3ossl | 1 - .../EVP_PKEY_CTX_get_rsa_oaep_md_name.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_rsa_padding.3ossl | 1 - .../EVP_PKEY_CTX_get_rsa_pss_saltlen.3ossl | 1 - .../man3/EVP_PKEY_CTX_get_signature_md.3ossl | 1 - .../man3/EVP_PKEY_CTX_gettable_params.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_is_a.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_md.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_new.3ossl | 258 -- .../man/man3/EVP_PKEY_CTX_new_from_name.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_new_from_pkey.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_new_id.3ossl | 1 - .../man3/EVP_PKEY_CTX_set0_dh_kdf_oid.3ossl | 1 - .../man3/EVP_PKEY_CTX_set0_dh_kdf_ukm.3ossl | 1 - .../man3/EVP_PKEY_CTX_set0_ecdh_kdf_ukm.3ossl | 1 - .../EVP_PKEY_CTX_set0_rsa_oaep_label.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set1_hkdf_key.3ossl | 1 - .../man3/EVP_PKEY_CTX_set1_hkdf_salt.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_set1_id.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set1_pbe_pass.3ossl | 185 -- .../EVP_PKEY_CTX_set1_rsa_keygen_pubexp.3ossl | 1 - .../man3/EVP_PKEY_CTX_set1_scrypt_salt.3ossl | 1 - .../EVP_PKEY_CTX_set1_tls1_prf_secret.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_algor_params.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_app_data.3ossl | 1 - .../share/man/man3/EVP_PKEY_CTX_set_cb.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_dh_kdf_md.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_dh_kdf_outlen.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_dh_kdf_type.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_dh_nid.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_dh_pad.3ossl | 1 - ...P_PKEY_CTX_set_dh_paramgen_generator.3ossl | 1 - .../EVP_PKEY_CTX_set_dh_paramgen_gindex.3ossl | 1 - ...P_PKEY_CTX_set_dh_paramgen_prime_len.3ossl | 1 - .../EVP_PKEY_CTX_set_dh_paramgen_seed.3ossl | 1 - ...KEY_CTX_set_dh_paramgen_subprime_len.3ossl | 1 - .../EVP_PKEY_CTX_set_dh_paramgen_type.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_dh_rfc5114.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_dhx_rfc5114.3ossl | 1 - .../EVP_PKEY_CTX_set_dsa_paramgen_bits.3ossl | 1 - ...EVP_PKEY_CTX_set_dsa_paramgen_gindex.3ossl | 1 - .../EVP_PKEY_CTX_set_dsa_paramgen_md.3ossl | 1 - ...P_PKEY_CTX_set_dsa_paramgen_md_props.3ossl | 1 - ...EVP_PKEY_CTX_set_dsa_paramgen_q_bits.3ossl | 1 - .../EVP_PKEY_CTX_set_dsa_paramgen_seed.3ossl | 1 - .../EVP_PKEY_CTX_set_dsa_paramgen_type.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_ec_param_enc.3ossl | 1 - ...P_PKEY_CTX_set_ec_paramgen_curve_nid.3ossl | 1 - .../EVP_PKEY_CTX_set_ecdh_cofactor_mode.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_ecdh_kdf_md.3ossl | 1 - .../EVP_PKEY_CTX_set_ecdh_kdf_outlen.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_ecdh_kdf_type.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_group_name.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_hkdf_md.3ossl | 293 --- .../man/man3/EVP_PKEY_CTX_set_hkdf_mode.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_kem_op.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_mac_key.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_params.3ossl | 226 -- .../EVP_PKEY_CTX_set_rsa_keygen_bits.3ossl | 1 - .../EVP_PKEY_CTX_set_rsa_keygen_primes.3ossl | 1 - .../EVP_PKEY_CTX_set_rsa_keygen_pubexp.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_rsa_mgf1_md.3ossl | 1 - .../EVP_PKEY_CTX_set_rsa_mgf1_md_name.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_rsa_oaep_md.3ossl | 1 - .../EVP_PKEY_CTX_set_rsa_oaep_md_name.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_rsa_padding.3ossl | 1 - .../EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl | 236 -- ..._PKEY_CTX_set_rsa_pss_keygen_md_name.3ossl | 1 - ..._PKEY_CTX_set_rsa_pss_keygen_mgf1_md.3ossl | 1 - ..._CTX_set_rsa_pss_keygen_mgf1_md_name.3ossl | 1 - ..._PKEY_CTX_set_rsa_pss_keygen_saltlen.3ossl | 1 - .../EVP_PKEY_CTX_set_rsa_pss_saltlen.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_scrypt_N.3ossl | 221 -- ...EVP_PKEY_CTX_set_scrypt_maxmem_bytes.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_scrypt_p.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_scrypt_r.3ossl | 1 - .../man/man3/EVP_PKEY_CTX_set_signature.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_signature_md.3ossl | 1 - .../man3/EVP_PKEY_CTX_set_tls1_prf_md.3ossl | 244 -- .../man3/EVP_PKEY_CTX_settable_params.3ossl | 1 - .../share/man/man3/EVP_PKEY_METHOD.3ossl | 1 - .../share/man/man3/EVP_PKEY_Q_keygen.3ossl | 1 - .../share/man/man3/EVP_PKEY_add1_attr.3ossl | 1 - .../man/man3/EVP_PKEY_add1_attr_by_NID.3ossl | 1 - .../man/man3/EVP_PKEY_add1_attr_by_OBJ.3ossl | 1 - .../man/man3/EVP_PKEY_add1_attr_by_txt.3ossl | 1 - .../share/man/man3/EVP_PKEY_asn1_add0.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_add_alias.3ossl | 1 - .../share/man/man3/EVP_PKEY_asn1_copy.3ossl | 1 - .../share/man/man3/EVP_PKEY_asn1_find.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_find_str.3ossl | 1 - .../share/man/man3/EVP_PKEY_asn1_free.3ossl | 1 - .../share/man/man3/EVP_PKEY_asn1_get0.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_get0_info.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_get_count.3ossl | 212 -- .../share/man/man3/EVP_PKEY_asn1_new.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_check.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_ctrl.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_free.3ossl | 1 - .../man3/EVP_PKEY_asn1_set_get_priv_key.3ossl | 1 - .../man3/EVP_PKEY_asn1_set_get_pub_key.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_item.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_param.3ossl | 1 - .../man3/EVP_PKEY_asn1_set_param_check.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_private.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_public.3ossl | 1 - .../man3/EVP_PKEY_asn1_set_public_check.3ossl | 1 - .../EVP_PKEY_asn1_set_security_bits.3ossl | 1 - .../man3/EVP_PKEY_asn1_set_set_priv_key.3ossl | 1 - .../man3/EVP_PKEY_asn1_set_set_pub_key.3ossl | 1 - .../man/man3/EVP_PKEY_asn1_set_siginf.3ossl | 1 - .../share/man/man3/EVP_PKEY_assign_DH.3ossl | 1 - .../share/man/man3/EVP_PKEY_assign_DSA.3ossl | 1 - .../man/man3/EVP_PKEY_assign_EC_KEY.3ossl | 1 - .../man/man3/EVP_PKEY_assign_POLY1305.3ossl | 1 - .../share/man/man3/EVP_PKEY_assign_RSA.3ossl | 1 - .../man/man3/EVP_PKEY_assign_SIPHASH.3ossl | 1 - .../man3/EVP_PKEY_auth_decapsulate_init.3ossl | 1 - .../man3/EVP_PKEY_auth_encapsulate_init.3ossl | 1 - .../share/man/man3/EVP_PKEY_base_id.3ossl | 1 - .../share/man/man3/EVP_PKEY_bits.3ossl | 1 - .../share/man/man3/EVP_PKEY_can_sign.3ossl | 1 - .../share/man/man3/EVP_PKEY_check.3ossl | 231 -- .../share/man/man3/EVP_PKEY_cmp.3ossl | 1 - .../man/man3/EVP_PKEY_cmp_parameters.3ossl | 1 - .../man/man3/EVP_PKEY_copy_parameters.3ossl | 236 -- .../share/man/man3/EVP_PKEY_decapsulate.3ossl | 244 -- .../man/man3/EVP_PKEY_decapsulate_init.3ossl | 1 - .../share/man/man3/EVP_PKEY_decrypt.3ossl | 266 -- .../man/man3/EVP_PKEY_decrypt_init.3ossl | 1 - .../man/man3/EVP_PKEY_decrypt_init_ex.3ossl | 1 - .../share/man/man3/EVP_PKEY_delete_attr.3ossl | 1 - .../share/man/man3/EVP_PKEY_derive.3ossl | 255 -- .../share/man/man3/EVP_PKEY_derive_init.3ossl | 1 - .../man/man3/EVP_PKEY_derive_init_ex.3ossl | 1 - .../man/man3/EVP_PKEY_derive_set_peer.3ossl | 1 - .../man3/EVP_PKEY_derive_set_peer_ex.3ossl | 1 - .../EVP_PKEY_digestsign_supports_digest.3ossl | 175 -- .../share/man/man3/EVP_PKEY_dup.3ossl | 1 - .../share/man/man3/EVP_PKEY_encapsulate.3ossl | 253 -- .../man/man3/EVP_PKEY_encapsulate_init.3ossl | 1 - .../share/man/man3/EVP_PKEY_encrypt.3ossl | 249 -- .../man/man3/EVP_PKEY_encrypt_init.3ossl | 1 - .../man/man3/EVP_PKEY_encrypt_init_ex.3ossl | 1 - .../share/man/man3/EVP_PKEY_eq.3ossl | 1 - .../share/man/man3/EVP_PKEY_export.3ossl | 1 - .../share/man/man3/EVP_PKEY_free.3ossl | 1 - .../share/man/man3/EVP_PKEY_fromdata.3ossl | 392 --- .../man/man3/EVP_PKEY_fromdata_init.3ossl | 1 - .../man/man3/EVP_PKEY_fromdata_settable.3ossl | 1 - .../share/man/man3/EVP_PKEY_gen_cb.3ossl | 1 - .../share/man/man3/EVP_PKEY_generate.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0_DH.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0_DSA.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0_EC_KEY.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0_RSA.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0_asn1.3ossl | 1 - .../man/man3/EVP_PKEY_get0_description.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0_engine.3ossl | 1 - .../share/man/man3/EVP_PKEY_get0_hmac.3ossl | 1 - .../man/man3/EVP_PKEY_get0_poly1305.3ossl | 1 - .../man/man3/EVP_PKEY_get0_provider.3ossl | 1 - .../man/man3/EVP_PKEY_get0_siphash.3ossl | 1 - .../man/man3/EVP_PKEY_get0_type_name.3ossl | 1 - .../share/man/man3/EVP_PKEY_get1_DH.3ossl | 1 - .../share/man/man3/EVP_PKEY_get1_DSA.3ossl | 1 - .../share/man/man3/EVP_PKEY_get1_EC_KEY.3ossl | 1 - .../share/man/man3/EVP_PKEY_get1_RSA.3ossl | 1 - .../EVP_PKEY_get1_encoded_public_key.3ossl | 1 - .../man3/EVP_PKEY_get1_tls_encodedpoint.3ossl | 1 - .../share/man/man3/EVP_PKEY_get_attr.3ossl | 244 -- .../man/man3/EVP_PKEY_get_attr_by_NID.3ossl | 1 - .../man/man3/EVP_PKEY_get_attr_by_OBJ.3ossl | 1 - .../man/man3/EVP_PKEY_get_attr_count.3ossl | 1 - .../share/man/man3/EVP_PKEY_get_base_id.3ossl | 1 - .../share/man/man3/EVP_PKEY_get_bits.3ossl | 1 - .../man/man3/EVP_PKEY_get_bn_param.3ossl | 1 - .../EVP_PKEY_get_default_digest_name.3ossl | 1 - .../EVP_PKEY_get_default_digest_nid.3ossl | 197 -- .../EVP_PKEY_get_ec_point_conv_form.3ossl | 1 - .../share/man/man3/EVP_PKEY_get_ex_data.3ossl | 1 - .../man/man3/EVP_PKEY_get_ex_new_index.3ossl | 1 - .../man/man3/EVP_PKEY_get_field_type.3ossl | 185 -- .../man/man3/EVP_PKEY_get_group_name.3ossl | 177 -- .../share/man/man3/EVP_PKEY_get_id.3ossl | 1 - .../man/man3/EVP_PKEY_get_int_param.3ossl | 1 - .../EVP_PKEY_get_octet_string_param.3ossl | 1 - .../share/man/man3/EVP_PKEY_get_params.3ossl | 1 - .../man3/EVP_PKEY_get_raw_private_key.3ossl | 1 - .../man3/EVP_PKEY_get_raw_public_key.3ossl | 1 - .../man/man3/EVP_PKEY_get_security_bits.3ossl | 1 - .../share/man/man3/EVP_PKEY_get_size.3ossl | 225 -- .../man/man3/EVP_PKEY_get_size_t_param.3ossl | 1 - .../man3/EVP_PKEY_get_utf8_string_param.3ossl | 1 - .../man/man3/EVP_PKEY_gettable_params.3ossl | 266 -- .../share/man/man3/EVP_PKEY_id.3ossl | 1 - .../share/man/man3/EVP_PKEY_is_a.3ossl | 247 -- .../share/man/man3/EVP_PKEY_keygen.3ossl | 371 --- .../share/man/man3/EVP_PKEY_keygen_init.3ossl | 1 - .../share/man/man3/EVP_PKEY_meth_add0.3ossl | 1 - .../share/man/man3/EVP_PKEY_meth_copy.3ossl | 1 - .../share/man/man3/EVP_PKEY_meth_find.3ossl | 1 - .../share/man/man3/EVP_PKEY_meth_free.3ossl | 1 - .../share/man/man3/EVP_PKEY_meth_get0.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get0_info.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_check.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_cleanup.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_copy.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_count.3ossl | 194 -- .../man/man3/EVP_PKEY_meth_get_ctrl.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_decrypt.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_derive.3ossl | 1 - .../EVP_PKEY_meth_get_digest_custom.3ossl | 1 - .../man3/EVP_PKEY_meth_get_digestsign.3ossl | 1 - .../man3/EVP_PKEY_meth_get_digestverify.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_encrypt.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_init.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_keygen.3ossl | 1 - .../man3/EVP_PKEY_meth_get_param_check.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_paramgen.3ossl | 1 - .../man3/EVP_PKEY_meth_get_public_check.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_sign.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_signctx.3ossl | 1 - .../man/man3/EVP_PKEY_meth_get_verify.3ossl | 1 - .../EVP_PKEY_meth_get_verify_recover.3ossl | 1 - .../man3/EVP_PKEY_meth_get_verifyctx.3ossl | 1 - .../share/man/man3/EVP_PKEY_meth_new.3ossl | 630 ----- .../share/man/man3/EVP_PKEY_meth_remove.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_check.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_cleanup.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_copy.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_ctrl.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_decrypt.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_derive.3ossl | 1 - .../EVP_PKEY_meth_set_digest_custom.3ossl | 1 - .../man3/EVP_PKEY_meth_set_digestsign.3ossl | 1 - .../man3/EVP_PKEY_meth_set_digestverify.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_encrypt.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_init.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_keygen.3ossl | 1 - .../man3/EVP_PKEY_meth_set_param_check.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_paramgen.3ossl | 1 - .../man3/EVP_PKEY_meth_set_public_check.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_sign.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_signctx.3ossl | 1 - .../man/man3/EVP_PKEY_meth_set_verify.3ossl | 1 - .../EVP_PKEY_meth_set_verify_recover.3ossl | 1 - .../man3/EVP_PKEY_meth_set_verifyctx.3ossl | 1 - .../man3/EVP_PKEY_missing_parameters.3ossl | 1 - .../share/man/man3/EVP_PKEY_new.3ossl | 350 --- .../man/man3/EVP_PKEY_new_CMAC_key.3ossl | 1 - .../share/man/man3/EVP_PKEY_new_mac_key.3ossl | 1 - .../man3/EVP_PKEY_new_raw_private_key.3ossl | 1 - .../EVP_PKEY_new_raw_private_key_ex.3ossl | 1 - .../man3/EVP_PKEY_new_raw_public_key.3ossl | 1 - .../man3/EVP_PKEY_new_raw_public_key_ex.3ossl | 1 - .../man/man3/EVP_PKEY_pairwise_check.3ossl | 1 - .../share/man/man3/EVP_PKEY_param_check.3ossl | 1 - .../man/man3/EVP_PKEY_param_check_quick.3ossl | 1 - .../man/man3/EVP_PKEY_parameters_eq.3ossl | 1 - .../share/man/man3/EVP_PKEY_paramgen.3ossl | 1 - .../man/man3/EVP_PKEY_paramgen_init.3ossl | 1 - .../man/man3/EVP_PKEY_print_params.3ossl | 1 - .../man/man3/EVP_PKEY_print_params_fp.3ossl | 1 - .../man/man3/EVP_PKEY_print_private.3ossl | 207 -- .../man/man3/EVP_PKEY_print_private_fp.3ossl | 1 - .../man/man3/EVP_PKEY_print_public.3ossl | 1 - .../man/man3/EVP_PKEY_print_public_fp.3ossl | 1 - .../man/man3/EVP_PKEY_private_check.3ossl | 1 - .../man/man3/EVP_PKEY_public_check.3ossl | 1 - .../man3/EVP_PKEY_public_check_quick.3ossl | 1 - .../man/man3/EVP_PKEY_security_bits.3ossl | 1 - .../share/man/man3/EVP_PKEY_set1_DH.3ossl | 1 - .../share/man/man3/EVP_PKEY_set1_DSA.3ossl | 1 - .../share/man/man3/EVP_PKEY_set1_EC_KEY.3ossl | 1 - .../share/man/man3/EVP_PKEY_set1_RSA.3ossl | 369 --- .../EVP_PKEY_set1_encoded_public_key.3ossl | 274 --- .../share/man/man3/EVP_PKEY_set1_engine.3ossl | 1 - .../man3/EVP_PKEY_set1_tls_encodedpoint.3ossl | 1 - .../man/man3/EVP_PKEY_set_bn_param.3ossl | 1 - .../share/man/man3/EVP_PKEY_set_ex_data.3ossl | 1 - .../man/man3/EVP_PKEY_set_int_param.3ossl | 1 - .../EVP_PKEY_set_octet_string_param.3ossl | 1 - .../share/man/man3/EVP_PKEY_set_params.3ossl | 1 - .../man/man3/EVP_PKEY_set_size_t_param.3ossl | 1 - .../share/man/man3/EVP_PKEY_set_type.3ossl | 200 -- .../man3/EVP_PKEY_set_type_by_keymgmt.3ossl | 1 - .../man/man3/EVP_PKEY_set_type_str.3ossl | 1 - .../man3/EVP_PKEY_set_utf8_string_param.3ossl | 1 - .../man/man3/EVP_PKEY_settable_params.3ossl | 211 -- .../share/man/man3/EVP_PKEY_sign.3ossl | 484 ---- .../share/man/man3/EVP_PKEY_sign_init.3ossl | 1 - .../man/man3/EVP_PKEY_sign_init_ex.3ossl | 1 - .../man/man3/EVP_PKEY_sign_init_ex2.3ossl | 1 - .../man3/EVP_PKEY_sign_message_final.3ossl | 1 - .../man/man3/EVP_PKEY_sign_message_init.3ossl | 1 - .../man3/EVP_PKEY_sign_message_update.3ossl | 1 - .../share/man/man3/EVP_PKEY_size.3ossl | 1 - .../share/man/man3/EVP_PKEY_todata.3ossl | 193 -- .../share/man/man3/EVP_PKEY_type.3ossl | 1 - .../man/man3/EVP_PKEY_type_names_do_all.3ossl | 1 - .../share/man/man3/EVP_PKEY_up_ref.3ossl | 1 - .../share/man/man3/EVP_PKEY_verify.3ossl | 473 ---- .../share/man/man3/EVP_PKEY_verify_init.3ossl | 1 - .../man/man3/EVP_PKEY_verify_init_ex.3ossl | 1 - .../man/man3/EVP_PKEY_verify_init_ex2.3ossl | 1 - .../man3/EVP_PKEY_verify_message_final.3ossl | 1 - .../man3/EVP_PKEY_verify_message_init.3ossl | 1 - .../man3/EVP_PKEY_verify_message_update.3ossl | 1 - .../man/man3/EVP_PKEY_verify_recover.3ossl | 273 -- .../man3/EVP_PKEY_verify_recover_init.3ossl | 1 - .../EVP_PKEY_verify_recover_init_ex.3ossl | 1 - .../EVP_PKEY_verify_recover_init_ex2.3ossl | 1 - .../share/man/man3/EVP_Q_digest.3ossl | 1 - .../share/man/man3/EVP_Q_mac.3ossl | 1 - openssl-install/share/man/man3/EVP_RAND.3ossl | 544 ---- .../share/man/man3/EVP_RAND_CTX.3ossl | 1 - .../share/man/man3/EVP_RAND_CTX_free.3ossl | 1 - .../man/man3/EVP_RAND_CTX_get0_rand.3ossl | 1 - .../man/man3/EVP_RAND_CTX_get_params.3ossl | 1 - .../man3/EVP_RAND_CTX_gettable_params.3ossl | 1 - .../share/man/man3/EVP_RAND_CTX_new.3ossl | 1 - .../man/man3/EVP_RAND_CTX_set_params.3ossl | 1 - .../man3/EVP_RAND_CTX_settable_params.3ossl | 1 - .../share/man/man3/EVP_RAND_CTX_up_ref.3ossl | 1 - .../share/man/man3/EVP_RAND_STATE_ERROR.3ossl | 1 - .../share/man/man3/EVP_RAND_STATE_READY.3ossl | 1 - .../man3/EVP_RAND_STATE_UNINITIALISED.3ossl | 1 - .../man/man3/EVP_RAND_do_all_provided.3ossl | 1 - .../man/man3/EVP_RAND_enable_locking.3ossl | 1 - .../share/man/man3/EVP_RAND_fetch.3ossl | 1 - .../share/man/man3/EVP_RAND_free.3ossl | 1 - .../share/man/man3/EVP_RAND_generate.3ossl | 1 - .../man/man3/EVP_RAND_get0_description.3ossl | 1 - .../share/man/man3/EVP_RAND_get0_name.3ossl | 1 - .../man/man3/EVP_RAND_get0_provider.3ossl | 1 - .../share/man/man3/EVP_RAND_get_params.3ossl | 1 - .../share/man/man3/EVP_RAND_get_state.3ossl | 1 - .../man/man3/EVP_RAND_get_strength.3ossl | 1 - .../man3/EVP_RAND_gettable_ctx_params.3ossl | 1 - .../man/man3/EVP_RAND_gettable_params.3ossl | 1 - .../share/man/man3/EVP_RAND_instantiate.3ossl | 1 - .../share/man/man3/EVP_RAND_is_a.3ossl | 1 - .../man/man3/EVP_RAND_names_do_all.3ossl | 1 - .../share/man/man3/EVP_RAND_nonce.3ossl | 1 - .../share/man/man3/EVP_RAND_reseed.3ossl | 1 - .../man3/EVP_RAND_settable_ctx_params.3ossl | 1 - .../man/man3/EVP_RAND_uninstantiate.3ossl | 1 - .../share/man/man3/EVP_RAND_up_ref.3ossl | 1 - .../man3/EVP_RAND_verify_zeroization.3ossl | 1 - .../share/man/man3/EVP_RSA_gen.3ossl | 1 - .../share/man/man3/EVP_SIGNATURE.3ossl | 247 -- .../man3/EVP_SIGNATURE_do_all_provided.3ossl | 1 - .../share/man/man3/EVP_SIGNATURE_fetch.3ossl | 1 - .../share/man/man3/EVP_SIGNATURE_free.3ossl | 1 - .../man3/EVP_SIGNATURE_get0_description.3ossl | 1 - .../man/man3/EVP_SIGNATURE_get0_name.3ossl | 1 - .../man3/EVP_SIGNATURE_get0_provider.3ossl | 1 - .../EVP_SIGNATURE_gettable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_SIGNATURE_is_a.3ossl | 1 - .../man/man3/EVP_SIGNATURE_names_do_all.3ossl | 1 - .../EVP_SIGNATURE_settable_ctx_params.3ossl | 1 - .../share/man/man3/EVP_SIGNATURE_up_ref.3ossl | 1 - .../share/man/man3/EVP_SealFinal.3ossl | 1 - .../share/man/man3/EVP_SealInit.3ossl | 223 -- .../share/man/man3/EVP_SealUpdate.3ossl | 1 - .../share/man/man3/EVP_SignFinal.3ossl | 1 - .../share/man/man3/EVP_SignFinal_ex.3ossl | 1 - .../share/man/man3/EVP_SignInit.3ossl | 248 -- .../share/man/man3/EVP_SignInit_ex.3ossl | 1 - .../share/man/man3/EVP_SignUpdate.3ossl | 1 - .../share/man/man3/EVP_VerifyFinal.3ossl | 1 - .../share/man/man3/EVP_VerifyFinal_ex.3ossl | 1 - .../share/man/man3/EVP_VerifyInit.3ossl | 243 -- .../share/man/man3/EVP_VerifyInit_ex.3ossl | 1 - .../share/man/man3/EVP_VerifyUpdate.3ossl | 1 - .../share/man/man3/EVP_aes_128_cbc.3ossl | 1 - .../man/man3/EVP_aes_128_cbc_hmac_sha1.3ossl | 1 - .../man3/EVP_aes_128_cbc_hmac_sha256.3ossl | 1 - .../share/man/man3/EVP_aes_128_ccm.3ossl | 1 - .../share/man/man3/EVP_aes_128_cfb.3ossl | 1 - .../share/man/man3/EVP_aes_128_cfb1.3ossl | 1 - .../share/man/man3/EVP_aes_128_cfb128.3ossl | 1 - .../share/man/man3/EVP_aes_128_cfb8.3ossl | 1 - .../share/man/man3/EVP_aes_128_ctr.3ossl | 1 - .../share/man/man3/EVP_aes_128_ecb.3ossl | 1 - .../share/man/man3/EVP_aes_128_gcm.3ossl | 274 --- .../share/man/man3/EVP_aes_128_ocb.3ossl | 1 - .../share/man/man3/EVP_aes_128_ofb.3ossl | 1 - .../share/man/man3/EVP_aes_128_wrap.3ossl | 1 - .../share/man/man3/EVP_aes_128_wrap_pad.3ossl | 1 - .../share/man/man3/EVP_aes_128_xts.3ossl | 1 - .../share/man/man3/EVP_aes_192_cbc.3ossl | 1 - .../share/man/man3/EVP_aes_192_ccm.3ossl | 1 - .../share/man/man3/EVP_aes_192_cfb.3ossl | 1 - .../share/man/man3/EVP_aes_192_cfb1.3ossl | 1 - .../share/man/man3/EVP_aes_192_cfb128.3ossl | 1 - .../share/man/man3/EVP_aes_192_cfb8.3ossl | 1 - .../share/man/man3/EVP_aes_192_ctr.3ossl | 1 - .../share/man/man3/EVP_aes_192_ecb.3ossl | 1 - .../share/man/man3/EVP_aes_192_gcm.3ossl | 1 - .../share/man/man3/EVP_aes_192_ocb.3ossl | 1 - .../share/man/man3/EVP_aes_192_ofb.3ossl | 1 - .../share/man/man3/EVP_aes_192_wrap.3ossl | 1 - .../share/man/man3/EVP_aes_192_wrap_pad.3ossl | 1 - .../share/man/man3/EVP_aes_256_cbc.3ossl | 1 - .../man/man3/EVP_aes_256_cbc_hmac_sha1.3ossl | 1 - .../man3/EVP_aes_256_cbc_hmac_sha256.3ossl | 1 - .../share/man/man3/EVP_aes_256_ccm.3ossl | 1 - .../share/man/man3/EVP_aes_256_cfb.3ossl | 1 - .../share/man/man3/EVP_aes_256_cfb1.3ossl | 1 - .../share/man/man3/EVP_aes_256_cfb128.3ossl | 1 - .../share/man/man3/EVP_aes_256_cfb8.3ossl | 1 - .../share/man/man3/EVP_aes_256_ctr.3ossl | 1 - .../share/man/man3/EVP_aes_256_ecb.3ossl | 1 - .../share/man/man3/EVP_aes_256_gcm.3ossl | 1 - .../share/man/man3/EVP_aes_256_ocb.3ossl | 1 - .../share/man/man3/EVP_aes_256_ofb.3ossl | 1 - .../share/man/man3/EVP_aes_256_wrap.3ossl | 1 - .../share/man/man3/EVP_aes_256_wrap_pad.3ossl | 1 - .../share/man/man3/EVP_aes_256_xts.3ossl | 1 - .../share/man/man3/EVP_aria_128_cbc.3ossl | 1 - .../share/man/man3/EVP_aria_128_ccm.3ossl | 1 - .../share/man/man3/EVP_aria_128_cfb.3ossl | 1 - .../share/man/man3/EVP_aria_128_cfb1.3ossl | 1 - .../share/man/man3/EVP_aria_128_cfb128.3ossl | 1 - .../share/man/man3/EVP_aria_128_cfb8.3ossl | 1 - .../share/man/man3/EVP_aria_128_ctr.3ossl | 1 - .../share/man/man3/EVP_aria_128_ecb.3ossl | 1 - .../share/man/man3/EVP_aria_128_gcm.3ossl | 218 -- .../share/man/man3/EVP_aria_128_ofb.3ossl | 1 - .../share/man/man3/EVP_aria_192_cbc.3ossl | 1 - .../share/man/man3/EVP_aria_192_ccm.3ossl | 1 - .../share/man/man3/EVP_aria_192_cfb.3ossl | 1 - .../share/man/man3/EVP_aria_192_cfb1.3ossl | 1 - .../share/man/man3/EVP_aria_192_cfb128.3ossl | 1 - .../share/man/man3/EVP_aria_192_cfb8.3ossl | 1 - .../share/man/man3/EVP_aria_192_ctr.3ossl | 1 - .../share/man/man3/EVP_aria_192_ecb.3ossl | 1 - .../share/man/man3/EVP_aria_192_gcm.3ossl | 1 - .../share/man/man3/EVP_aria_192_ofb.3ossl | 1 - .../share/man/man3/EVP_aria_256_cbc.3ossl | 1 - .../share/man/man3/EVP_aria_256_ccm.3ossl | 1 - .../share/man/man3/EVP_aria_256_cfb.3ossl | 1 - .../share/man/man3/EVP_aria_256_cfb1.3ossl | 1 - .../share/man/man3/EVP_aria_256_cfb128.3ossl | 1 - .../share/man/man3/EVP_aria_256_cfb8.3ossl | 1 - .../share/man/man3/EVP_aria_256_ctr.3ossl | 1 - .../share/man/man3/EVP_aria_256_ecb.3ossl | 1 - .../share/man/man3/EVP_aria_256_gcm.3ossl | 1 - .../share/man/man3/EVP_aria_256_ofb.3ossl | 1 - .../share/man/man3/EVP_bf_cbc.3ossl | 190 -- .../share/man/man3/EVP_bf_cfb.3ossl | 1 - .../share/man/man3/EVP_bf_cfb64.3ossl | 1 - .../share/man/man3/EVP_bf_ecb.3ossl | 1 - .../share/man/man3/EVP_bf_ofb.3ossl | 1 - .../share/man/man3/EVP_blake2b512.3ossl | 192 -- .../share/man/man3/EVP_blake2s256.3ossl | 1 - .../share/man/man3/EVP_camellia_128_cbc.3ossl | 1 - .../share/man/man3/EVP_camellia_128_cfb.3ossl | 1 - .../man/man3/EVP_camellia_128_cfb1.3ossl | 1 - .../man/man3/EVP_camellia_128_cfb128.3ossl | 1 - .../man/man3/EVP_camellia_128_cfb8.3ossl | 1 - .../share/man/man3/EVP_camellia_128_ctr.3ossl | 1 - .../share/man/man3/EVP_camellia_128_ecb.3ossl | 207 -- .../share/man/man3/EVP_camellia_128_ofb.3ossl | 1 - .../share/man/man3/EVP_camellia_192_cbc.3ossl | 1 - .../share/man/man3/EVP_camellia_192_cfb.3ossl | 1 - .../man/man3/EVP_camellia_192_cfb1.3ossl | 1 - .../man/man3/EVP_camellia_192_cfb128.3ossl | 1 - .../man/man3/EVP_camellia_192_cfb8.3ossl | 1 - .../share/man/man3/EVP_camellia_192_ctr.3ossl | 1 - .../share/man/man3/EVP_camellia_192_ecb.3ossl | 1 - .../share/man/man3/EVP_camellia_192_ofb.3ossl | 1 - .../share/man/man3/EVP_camellia_256_cbc.3ossl | 1 - .../share/man/man3/EVP_camellia_256_cfb.3ossl | 1 - .../man/man3/EVP_camellia_256_cfb1.3ossl | 1 - .../man/man3/EVP_camellia_256_cfb128.3ossl | 1 - .../man/man3/EVP_camellia_256_cfb8.3ossl | 1 - .../share/man/man3/EVP_camellia_256_ctr.3ossl | 1 - .../share/man/man3/EVP_camellia_256_ecb.3ossl | 1 - .../share/man/man3/EVP_camellia_256_ofb.3ossl | 1 - .../share/man/man3/EVP_cast5_cbc.3ossl | 190 -- .../share/man/man3/EVP_cast5_cfb.3ossl | 1 - .../share/man/man3/EVP_cast5_cfb64.3ossl | 1 - .../share/man/man3/EVP_cast5_ecb.3ossl | 1 - .../share/man/man3/EVP_cast5_ofb.3ossl | 1 - .../share/man/man3/EVP_chacha20.3ossl | 199 -- .../man/man3/EVP_chacha20_poly1305.3ossl | 1 - .../share/man/man3/EVP_cleanup.3ossl | 1 - .../EVP_default_properties_enable_fips.3ossl | 1 - ...P_default_properties_is_fips_enabled.3ossl | 1 - .../share/man/man3/EVP_des_cbc.3ossl | 219 -- .../share/man/man3/EVP_des_cfb.3ossl | 1 - .../share/man/man3/EVP_des_cfb1.3ossl | 1 - .../share/man/man3/EVP_des_cfb64.3ossl | 1 - .../share/man/man3/EVP_des_cfb8.3ossl | 1 - .../share/man/man3/EVP_des_ecb.3ossl | 1 - .../share/man/man3/EVP_des_ede.3ossl | 1 - .../share/man/man3/EVP_des_ede3.3ossl | 1 - .../share/man/man3/EVP_des_ede3_cbc.3ossl | 1 - .../share/man/man3/EVP_des_ede3_cfb.3ossl | 1 - .../share/man/man3/EVP_des_ede3_cfb1.3ossl | 1 - .../share/man/man3/EVP_des_ede3_cfb64.3ossl | 1 - .../share/man/man3/EVP_des_ede3_cfb8.3ossl | 1 - .../share/man/man3/EVP_des_ede3_ecb.3ossl | 1 - .../share/man/man3/EVP_des_ede3_ofb.3ossl | 1 - .../share/man/man3/EVP_des_ede3_wrap.3ossl | 1 - .../share/man/man3/EVP_des_ede_cbc.3ossl | 1 - .../share/man/man3/EVP_des_ede_cfb.3ossl | 1 - .../share/man/man3/EVP_des_ede_cfb64.3ossl | 1 - .../share/man/man3/EVP_des_ede_ecb.3ossl | 1 - .../share/man/man3/EVP_des_ede_ofb.3ossl | 1 - .../share/man/man3/EVP_des_ofb.3ossl | 1 - .../share/man/man3/EVP_desx_cbc.3ossl | 185 -- .../share/man/man3/EVP_enc_null.3ossl | 1 - .../share/man/man3/EVP_get_cipherbyname.3ossl | 1 - .../share/man/man3/EVP_get_cipherbynid.3ossl | 1 - .../share/man/man3/EVP_get_cipherbyobj.3ossl | 1 - .../share/man/man3/EVP_get_digestbyname.3ossl | 1 - .../share/man/man3/EVP_get_digestbynid.3ossl | 1 - .../share/man/man3/EVP_get_digestbyobj.3ossl | 1 - .../share/man/man3/EVP_idea_cbc.3ossl | 188 -- .../share/man/man3/EVP_idea_cfb.3ossl | 1 - .../share/man/man3/EVP_idea_cfb64.3ossl | 1 - .../share/man/man3/EVP_idea_ecb.3ossl | 1 - .../share/man/man3/EVP_idea_ofb.3ossl | 1 - openssl-install/share/man/man3/EVP_md2.3ossl | 184 -- openssl-install/share/man/man3/EVP_md4.3ossl | 185 -- openssl-install/share/man/man3/EVP_md5.3ossl | 194 -- .../share/man/man3/EVP_md5_sha1.3ossl | 1 - .../share/man/man3/EVP_md_null.3ossl | 1 - openssl-install/share/man/man3/EVP_mdc2.3ossl | 186 -- .../share/man/man3/EVP_rc2_40_cbc.3ossl | 1 - .../share/man/man3/EVP_rc2_64_cbc.3ossl | 1 - .../share/man/man3/EVP_rc2_cbc.3ossl | 202 -- .../share/man/man3/EVP_rc2_cfb.3ossl | 1 - .../share/man/man3/EVP_rc2_cfb64.3ossl | 1 - .../share/man/man3/EVP_rc2_ecb.3ossl | 1 - .../share/man/man3/EVP_rc2_ofb.3ossl | 1 - openssl-install/share/man/man3/EVP_rc4.3ossl | 198 -- .../share/man/man3/EVP_rc4_40.3ossl | 1 - .../share/man/man3/EVP_rc4_hmac_md5.3ossl | 1 - .../share/man/man3/EVP_rc5_32_12_16_cbc.3ossl | 207 -- .../share/man/man3/EVP_rc5_32_12_16_cfb.3ossl | 1 - .../man/man3/EVP_rc5_32_12_16_cfb64.3ossl | 1 - .../share/man/man3/EVP_rc5_32_12_16_ecb.3ossl | 1 - .../share/man/man3/EVP_rc5_32_12_16_ofb.3ossl | 1 - .../share/man/man3/EVP_ripemd160.3ossl | 185 -- .../share/man/man3/EVP_seed_cbc.3ossl | 190 -- .../share/man/man3/EVP_seed_cfb.3ossl | 1 - .../share/man/man3/EVP_seed_cfb128.3ossl | 1 - .../share/man/man3/EVP_seed_ecb.3ossl | 1 - .../share/man/man3/EVP_seed_ofb.3ossl | 1 - .../man/man3/EVP_set_default_properties.3ossl | 201 -- openssl-install/share/man/man3/EVP_sha1.3ossl | 184 -- .../share/man/man3/EVP_sha224.3ossl | 199 -- .../share/man/man3/EVP_sha256.3ossl | 1 - .../share/man/man3/EVP_sha384.3ossl | 1 - .../share/man/man3/EVP_sha3_224.3ossl | 204 -- .../share/man/man3/EVP_sha3_256.3ossl | 1 - .../share/man/man3/EVP_sha3_384.3ossl | 1 - .../share/man/man3/EVP_sha3_512.3ossl | 1 - .../share/man/man3/EVP_sha512.3ossl | 1 - .../share/man/man3/EVP_sha512_224.3ossl | 1 - .../share/man/man3/EVP_sha512_256.3ossl | 1 - .../share/man/man3/EVP_shake128.3ossl | 1 - .../share/man/man3/EVP_shake256.3ossl | 1 - openssl-install/share/man/man3/EVP_sm3.3ossl | 184 -- .../share/man/man3/EVP_sm4_cbc.3ossl | 194 -- .../share/man/man3/EVP_sm4_cfb.3ossl | 1 - .../share/man/man3/EVP_sm4_cfb128.3ossl | 1 - .../share/man/man3/EVP_sm4_ctr.3ossl | 1 - .../share/man/man3/EVP_sm4_ecb.3ossl | 1 - .../share/man/man3/EVP_sm4_ofb.3ossl | 1 - .../share/man/man3/EVP_whirlpool.3ossl | 186 -- .../man/man3/EXTENDED_KEY_USAGE_free.3ossl | 1 - .../man/man3/EXTENDED_KEY_USAGE_new.3ossl | 1 - .../share/man/man3/EXT_UTF8STRING.3ossl | 1 - .../share/man/man3/GENERAL_NAME.3ossl | 173 -- .../share/man/man3/GENERAL_NAMES_free.3ossl | 1 - .../share/man/man3/GENERAL_NAMES_new.3ossl | 1 - .../share/man/man3/GENERAL_NAME_dup.3ossl | 1 - .../share/man/man3/GENERAL_NAME_free.3ossl | 1 - .../share/man/man3/GENERAL_NAME_new.3ossl | 1 - .../man3/GENERAL_NAME_set1_X509_NAME.3ossl | 1 - .../share/man/man3/GENERAL_SUBTREE_free.3ossl | 1 - .../share/man/man3/GENERAL_SUBTREE_new.3ossl | 1 - .../share/man/man3/GEN_SESSION_CB.3ossl | 1 - openssl-install/share/man/man3/HMAC.3ossl | 307 --- .../share/man/man3/HMAC_CTX_copy.3ossl | 1 - .../share/man/man3/HMAC_CTX_free.3ossl | 1 - .../share/man/man3/HMAC_CTX_get_md.3ossl | 1 - .../share/man/man3/HMAC_CTX_new.3ossl | 1 - .../share/man/man3/HMAC_CTX_reset.3ossl | 1 - .../share/man/man3/HMAC_CTX_set_flags.3ossl | 1 - .../share/man/man3/HMAC_Final.3ossl | 1 - .../share/man/man3/HMAC_Init.3ossl | 1 - .../share/man/man3/HMAC_Init_ex.3ossl | 1 - .../share/man/man3/HMAC_Update.3ossl | 1 - .../share/man/man3/HMAC_size.3ossl | 1 - .../man/man3/IMPLEMENT_ASN1_FUNCTIONS.3ossl | 1 - .../man/man3/IMPLEMENT_EXTERN_ASN1.3ossl | 1 - .../man/man3/IMPLEMENT_LHASH_COMP_FN.3ossl | 1 - .../man/man3/IMPLEMENT_LHASH_HASH_FN.3ossl | 1 - .../share/man/man3/IPAddressChoice_free.3ossl | 1 - .../share/man/man3/IPAddressChoice_new.3ossl | 1 - .../share/man/man3/IPAddressFamily_free.3ossl | 1 - .../share/man/man3/IPAddressFamily_new.3ossl | 1 - .../man/man3/IPAddressOrRange_free.3ossl | 1 - .../share/man/man3/IPAddressOrRange_new.3ossl | 1 - .../share/man/man3/IPAddressRange_free.3ossl | 1 - .../share/man/man3/IPAddressRange_new.3ossl | 1 - .../man/man3/ISSUER_SIGN_TOOL_free.3ossl | 1 - .../share/man/man3/ISSUER_SIGN_TOOL_it.3ossl | 1 - .../share/man/man3/ISSUER_SIGN_TOOL_new.3ossl | 1 - .../man/man3/ISSUING_DIST_POINT_free.3ossl | 1 - .../man/man3/ISSUING_DIST_POINT_it.3ossl | 1 - .../man/man3/ISSUING_DIST_POINT_new.3ossl | 1 - openssl-install/share/man/man3/LHASH.3ossl | 1 - .../man/man3/LHASH_DOALL_ARG_FN_TYPE.3ossl | 1 - openssl-install/share/man/man3/LHASH_OF.3ossl | 1 - openssl-install/share/man/man3/MD2.3ossl | 1 - .../share/man/man3/MD2_Final.3ossl | 1 - openssl-install/share/man/man3/MD2_Init.3ossl | 1 - .../share/man/man3/MD2_Update.3ossl | 1 - openssl-install/share/man/man3/MD4.3ossl | 1 - .../share/man/man3/MD4_Final.3ossl | 1 - openssl-install/share/man/man3/MD4_Init.3ossl | 1 - .../share/man/man3/MD4_Update.3ossl | 1 - openssl-install/share/man/man3/MD5.3ossl | 246 -- .../share/man/man3/MD5_Final.3ossl | 1 - openssl-install/share/man/man3/MD5_Init.3ossl | 1 - .../share/man/man3/MD5_Update.3ossl | 1 - openssl-install/share/man/man3/MDC2.3ossl | 1 - .../share/man/man3/MDC2_Final.3ossl | 1 - .../share/man/man3/MDC2_Init.3ossl | 212 -- .../share/man/man3/MDC2_Update.3ossl | 1 - .../man/man3/NAME_CONSTRAINTS_free.3ossl | 1 - .../share/man/man3/NAME_CONSTRAINTS_new.3ossl | 1 - .../share/man/man3/NAMING_AUTHORITY.3ossl | 1 - .../man/man3/NAMING_AUTHORITY_free.3ossl | 1 - .../NAMING_AUTHORITY_get0_authorityId.3ossl | 1 - .../NAMING_AUTHORITY_get0_authorityText.3ossl | 1 - .../NAMING_AUTHORITY_get0_authorityURL.3ossl | 1 - .../share/man/man3/NAMING_AUTHORITY_new.3ossl | 1 - .../NAMING_AUTHORITY_set0_authorityId.3ossl | 1 - .../NAMING_AUTHORITY_set0_authorityText.3ossl | 1 - .../NAMING_AUTHORITY_set0_authorityURL.3ossl | 1 - .../share/man/man3/NCONF_default.3ossl | 1 - .../share/man/man3/NCONF_free.3ossl | 1 - .../share/man/man3/NCONF_get0_libctx.3ossl | 1 - .../share/man/man3/NCONF_get_section.3ossl | 1 - .../man/man3/NCONF_get_section_names.3ossl | 1 - .../share/man/man3/NCONF_load.3ossl | 1 - .../share/man/man3/NCONF_new.3ossl | 1 - .../share/man/man3/NCONF_new_ex.3ossl | 215 -- .../man3/NETSCAPE_CERT_SEQUENCE_free.3ossl | 1 - .../man/man3/NETSCAPE_CERT_SEQUENCE_new.3ossl | 1 - .../share/man/man3/NETSCAPE_SPKAC_free.3ossl | 1 - .../share/man/man3/NETSCAPE_SPKAC_new.3ossl | 1 - .../share/man/man3/NETSCAPE_SPKI_free.3ossl | 1 - .../share/man/man3/NETSCAPE_SPKI_new.3ossl | 1 - .../share/man/man3/NOTICEREF_free.3ossl | 1 - .../share/man/man3/NOTICEREF_new.3ossl | 1 - .../share/man/man3/OBJ_add_sigid.3ossl | 1 - .../share/man/man3/OBJ_cleanup.3ossl | 1 - openssl-install/share/man/man3/OBJ_cmp.3ossl | 1 - .../share/man/man3/OBJ_create.3ossl | 1 - openssl-install/share/man/man3/OBJ_dup.3ossl | 1 - .../share/man/man3/OBJ_get0_data.3ossl | 1 - .../share/man/man3/OBJ_length.3ossl | 1 - .../share/man/man3/OBJ_ln2nid.3ossl | 1 - .../share/man/man3/OBJ_nid2ln.3ossl | 1 - .../share/man/man3/OBJ_nid2obj.3ossl | 345 --- .../share/man/man3/OBJ_nid2sn.3ossl | 1 - .../share/man/man3/OBJ_obj2nid.3ossl | 1 - .../share/man/man3/OBJ_obj2txt.3ossl | 1 - .../share/man/man3/OBJ_sn2nid.3ossl | 1 - .../share/man/man3/OBJ_txt2nid.3ossl | 1 - .../share/man/man3/OBJ_txt2obj.3ossl | 1 - .../share/man/man3/OCSP_BASICRESP_free.3ossl | 1 - .../share/man/man3/OCSP_BASICRESP_new.3ossl | 1 - .../share/man/man3/OCSP_CERTID_dup.3ossl | 1 - .../share/man/man3/OCSP_CERTID_free.3ossl | 1 - .../share/man/man3/OCSP_CERTID_new.3ossl | 1 - .../share/man/man3/OCSP_CERTSTATUS_free.3ossl | 1 - .../share/man/man3/OCSP_CERTSTATUS_new.3ossl | 1 - .../share/man/man3/OCSP_CRLID_free.3ossl | 1 - .../share/man/man3/OCSP_CRLID_new.3ossl | 1 - .../share/man/man3/OCSP_ONEREQ_free.3ossl | 1 - .../share/man/man3/OCSP_ONEREQ_new.3ossl | 1 - .../share/man/man3/OCSP_REQINFO_free.3ossl | 1 - .../share/man/man3/OCSP_REQINFO_new.3ossl | 1 - .../share/man/man3/OCSP_REQUEST_free.3ossl | 1 - .../share/man/man3/OCSP_REQUEST_new.3ossl | 251 -- .../share/man/man3/OCSP_REQ_CTX.3ossl | 1 - .../man/man3/OCSP_REQ_CTX_add1_header.3ossl | 1 - .../share/man/man3/OCSP_REQ_CTX_free.3ossl | 1 - .../share/man/man3/OCSP_REQ_CTX_i2d.3ossl | 1 - .../man/man3/OCSP_REQ_CTX_set1_req.3ossl | 1 - .../share/man/man3/OCSP_RESPBYTES_free.3ossl | 1 - .../share/man/man3/OCSP_RESPBYTES_new.3ossl | 1 - .../share/man/man3/OCSP_RESPDATA_free.3ossl | 1 - .../share/man/man3/OCSP_RESPDATA_new.3ossl | 1 - .../share/man/man3/OCSP_RESPID_free.3ossl | 1 - .../share/man/man3/OCSP_RESPID_match.3ossl | 1 - .../share/man/man3/OCSP_RESPID_match_ex.3ossl | 1 - .../share/man/man3/OCSP_RESPID_new.3ossl | 1 - .../man/man3/OCSP_RESPID_set_by_key.3ossl | 1 - .../man/man3/OCSP_RESPID_set_by_key_ex.3ossl | 1 - .../man/man3/OCSP_RESPID_set_by_name.3ossl | 1 - .../share/man/man3/OCSP_RESPONSE_free.3ossl | 1 - .../share/man/man3/OCSP_RESPONSE_new.3ossl | 1 - .../man/man3/OCSP_REVOKEDINFO_free.3ossl | 1 - .../share/man/man3/OCSP_REVOKEDINFO_new.3ossl | 1 - .../share/man/man3/OCSP_SERVICELOC_free.3ossl | 1 - .../share/man/man3/OCSP_SERVICELOC_new.3ossl | 1 - .../share/man/man3/OCSP_SIGNATURE_free.3ossl | 1 - .../share/man/man3/OCSP_SIGNATURE_new.3ossl | 1 - .../share/man/man3/OCSP_SINGLERESP_free.3ossl | 1 - .../share/man/man3/OCSP_SINGLERESP_new.3ossl | 1 - .../man/man3/OCSP_basic_add1_nonce.3ossl | 1 - .../share/man/man3/OCSP_basic_sign.3ossl | 1 - .../share/man/man3/OCSP_basic_sign_ctx.3ossl | 1 - .../share/man/man3/OCSP_basic_verify.3ossl | 1 - .../share/man/man3/OCSP_cert_id_new.3ossl | 1 - .../share/man/man3/OCSP_cert_to_id.3ossl | 220 -- .../share/man/man3/OCSP_check_nonce.3ossl | 1 - .../share/man/man3/OCSP_check_validity.3ossl | 1 - .../share/man/man3/OCSP_copy_nonce.3ossl | 1 - .../share/man/man3/OCSP_id_cmp.3ossl | 1 - .../share/man/man3/OCSP_id_get0_info.3ossl | 1 - .../share/man/man3/OCSP_id_issuer_cmp.3ossl | 1 - .../share/man/man3/OCSP_parse_url.3ossl | 1 - .../share/man/man3/OCSP_request_add0_id.3ossl | 1 - .../man/man3/OCSP_request_add1_cert.3ossl | 1 - .../man/man3/OCSP_request_add1_nonce.3ossl | 215 -- .../man/man3/OCSP_request_onereq_count.3ossl | 1 - .../man/man3/OCSP_request_onereq_get0.3ossl | 1 - .../share/man/man3/OCSP_request_sign.3ossl | 1 - .../share/man/man3/OCSP_resp_count.3ossl | 1 - .../share/man/man3/OCSP_resp_find.3ossl | 1 - .../man/man3/OCSP_resp_find_status.3ossl | 351 --- .../share/man/man3/OCSP_resp_get0.3ossl | 1 - .../share/man/man3/OCSP_resp_get0_certs.3ossl | 1 - .../share/man/man3/OCSP_resp_get0_id.3ossl | 1 - .../man/man3/OCSP_resp_get0_produced_at.3ossl | 1 - .../man/man3/OCSP_resp_get0_respdata.3ossl | 1 - .../man/man3/OCSP_resp_get0_signature.3ossl | 1 - .../man/man3/OCSP_resp_get0_signer.3ossl | 1 - .../man/man3/OCSP_resp_get0_tbs_sigalg.3ossl | 1 - .../share/man/man3/OCSP_resp_get1_id.3ossl | 1 - .../share/man/man3/OCSP_response_create.3ossl | 1 - .../man/man3/OCSP_response_get1_basic.3ossl | 1 - .../share/man/man3/OCSP_response_status.3ossl | 264 -- .../share/man/man3/OCSP_sendreq_bio.3ossl | 1 - .../share/man/man3/OCSP_sendreq_nbio.3ossl | 1 - .../share/man/man3/OCSP_sendreq_new.3ossl | 262 -- .../man3/OCSP_set_max_response_length.3ossl | 1 - .../man/man3/OCSP_single_get0_status.3ossl | 1 - .../share/man/man3/OPENSSL_Applink.3ossl | 168 -- .../share/man/man3/OPENSSL_FILE.3ossl | 187 -- .../share/man/man3/OPENSSL_FUNC.3ossl | 1 - .../share/man/man3/OPENSSL_INIT_free.3ossl | 1 - .../share/man/man3/OPENSSL_INIT_new.3ossl | 1 - .../OPENSSL_INIT_set_config_appname.3ossl | 1 - .../OPENSSL_INIT_set_config_file_flags.3ossl | 1 - .../OPENSSL_INIT_set_config_filename.3ossl | 1 - .../share/man/man3/OPENSSL_LH_COMPFUNC.3ossl | 475 ---- .../man/man3/OPENSSL_LH_DOALL_FUNC.3ossl | 1 - .../share/man/man3/OPENSSL_LH_HASHFUNC.3ossl | 1 - .../share/man/man3/OPENSSL_LH_delete.3ossl | 1 - .../share/man/man3/OPENSSL_LH_doall.3ossl | 1 - .../share/man/man3/OPENSSL_LH_doall_arg.3ossl | 1 - .../man/man3/OPENSSL_LH_doall_arg_thunk.3ossl | 1 - .../share/man/man3/OPENSSL_LH_error.3ossl | 1 - .../share/man/man3/OPENSSL_LH_flush.3ossl | 1 - .../share/man/man3/OPENSSL_LH_free.3ossl | 1 - .../man/man3/OPENSSL_LH_get_down_load.3ossl | 1 - .../share/man/man3/OPENSSL_LH_insert.3ossl | 1 - .../share/man/man3/OPENSSL_LH_new.3ossl | 1 - .../man/man3/OPENSSL_LH_node_stats.3ossl | 1 - .../man/man3/OPENSSL_LH_node_stats_bio.3ossl | 1 - .../man3/OPENSSL_LH_node_usage_stats.3ossl | 1 - .../OPENSSL_LH_node_usage_stats_bio.3ossl | 1 - .../share/man/man3/OPENSSL_LH_num_items.3ossl | 1 - .../share/man/man3/OPENSSL_LH_retrieve.3ossl | 1 - .../man/man3/OPENSSL_LH_set_down_load.3ossl | 1 - .../man/man3/OPENSSL_LH_set_thunks.3ossl | 1 - .../share/man/man3/OPENSSL_LH_stats.3ossl | 212 -- .../share/man/man3/OPENSSL_LH_stats_bio.3ossl | 1 - .../share/man/man3/OPENSSL_LINE.3ossl | 1 - .../man/man3/OPENSSL_MALLOC_FAILURES.3ossl | 1 - .../share/man/man3/OPENSSL_MALLOC_FD.3ossl | 1 - .../share/man/man3/OPENSSL_MSTR.3ossl | 1 - .../share/man/man3/OPENSSL_MSTR_HELPER.3ossl | 1 - .../man3/OPENSSL_VERSION_BUILD_METADATA.3ossl | 1 - .../man/man3/OPENSSL_VERSION_MAJOR.3ossl | 1 - .../man/man3/OPENSSL_VERSION_MINOR.3ossl | 1 - .../man/man3/OPENSSL_VERSION_NUMBER.3ossl | 1 - .../man/man3/OPENSSL_VERSION_PATCH.3ossl | 1 - .../man/man3/OPENSSL_VERSION_PREREQ.3ossl | 1 - .../man3/OPENSSL_VERSION_PRE_RELEASE.3ossl | 1 - .../share/man/man3/OPENSSL_VERSION_TEXT.3ossl | 1 - .../man/man3/OPENSSL_aligned_alloc.3ossl | 1 - .../share/man/man3/OPENSSL_atexit.3ossl | 1 - .../share/man/man3/OPENSSL_buf2hexstr.3ossl | 1 - .../man/man3/OPENSSL_buf2hexstr_ex.3ossl | 1 - .../share/man/man3/OPENSSL_cipher_name.3ossl | 1 - .../share/man/man3/OPENSSL_cleanse.3ossl | 1 - .../share/man/man3/OPENSSL_cleanup.3ossl | 1 - .../share/man/man3/OPENSSL_clear_free.3ossl | 1 - .../man/man3/OPENSSL_clear_realloc.3ossl | 1 - .../share/man/man3/OPENSSL_config.3ossl | 214 -- .../share/man/man3/OPENSSL_fork_child.3ossl | 1 - .../share/man/man3/OPENSSL_fork_parent.3ossl | 1 - .../share/man/man3/OPENSSL_fork_prepare.3ossl | 203 -- .../share/man/man3/OPENSSL_free.3ossl | 1 - .../share/man/man3/OPENSSL_gmtime.3ossl | 193 -- .../share/man/man3/OPENSSL_gmtime_adj.3ossl | 1 - .../share/man/man3/OPENSSL_gmtime_diff.3ossl | 1 - .../share/man/man3/OPENSSL_hexchar2int.3ossl | 214 -- .../share/man/man3/OPENSSL_hexstr2buf.3ossl | 1 - .../man/man3/OPENSSL_hexstr2buf_ex.3ossl | 1 - .../share/man/man3/OPENSSL_ia32cap.3ossl | 264 -- .../share/man/man3/OPENSSL_info.3ossl | 1 - .../share/man/man3/OPENSSL_init_crypto.3ossl | 409 --- .../share/man/man3/OPENSSL_init_ssl.3ossl | 209 -- .../man/man3/OPENSSL_instrument_bus.3ossl | 186 -- .../man/man3/OPENSSL_instrument_bus2.3ossl | 1 - .../man3/OPENSSL_load_builtin_modules.3ossl | 190 -- .../share/man/man3/OPENSSL_malloc.3ossl | 390 --- .../share/man/man3/OPENSSL_malloc_init.3ossl | 1 - .../man/man3/OPENSSL_mem_debug_pop.3ossl | 1 - .../man/man3/OPENSSL_mem_debug_push.3ossl | 1 - .../share/man/man3/OPENSSL_memdup.3ossl | 1 - .../share/man/man3/OPENSSL_no_config.3ossl | 1 - .../share/man/man3/OPENSSL_realloc.3ossl | 1 - .../share/man/man3/OPENSSL_riscvcap.3ossl | 323 --- .../share/man/man3/OPENSSL_s390xcap.3ossl | 344 --- .../man/man3/OPENSSL_secure_actual_size.3ossl | 1 - .../man/man3/OPENSSL_secure_clear_free.3ossl | 1 - .../share/man/man3/OPENSSL_secure_free.3ossl | 1 - .../man/man3/OPENSSL_secure_malloc.3ossl | 276 --- .../man/man3/OPENSSL_secure_zalloc.3ossl | 1 - .../share/man/man3/OPENSSL_sk_deep_copy.3ossl | 1 - .../share/man/man3/OPENSSL_sk_delete.3ossl | 1 - .../man/man3/OPENSSL_sk_delete_ptr.3ossl | 1 - .../share/man/man3/OPENSSL_sk_dup.3ossl | 1 - .../share/man/man3/OPENSSL_sk_find.3ossl | 1 - .../share/man/man3/OPENSSL_sk_find_all.3ossl | 1 - .../share/man/man3/OPENSSL_sk_find_ex.3ossl | 1 - .../share/man/man3/OPENSSL_sk_free.3ossl | 1 - .../share/man/man3/OPENSSL_sk_insert.3ossl | 1 - .../share/man/man3/OPENSSL_sk_is_sorted.3ossl | 1 - .../share/man/man3/OPENSSL_sk_new.3ossl | 1 - .../share/man/man3/OPENSSL_sk_new_null.3ossl | 1 - .../man/man3/OPENSSL_sk_new_reserve.3ossl | 1 - .../share/man/man3/OPENSSL_sk_num.3ossl | 1 - .../share/man/man3/OPENSSL_sk_pop.3ossl | 1 - .../share/man/man3/OPENSSL_sk_pop_free.3ossl | 1 - .../share/man/man3/OPENSSL_sk_push.3ossl | 1 - .../share/man/man3/OPENSSL_sk_reserve.3ossl | 1 - .../share/man/man3/OPENSSL_sk_set.3ossl | 1 - .../man/man3/OPENSSL_sk_set_cmp_func.3ossl | 1 - .../share/man/man3/OPENSSL_sk_shift.3ossl | 1 - .../share/man/man3/OPENSSL_sk_sort.3ossl | 1 - .../share/man/man3/OPENSSL_sk_unshift.3ossl | 1 - .../share/man/man3/OPENSSL_sk_value.3ossl | 1 - .../share/man/man3/OPENSSL_sk_zero.3ossl | 1 - .../share/man/man3/OPENSSL_strcasecmp.3ossl | 182 -- .../share/man/man3/OPENSSL_strdup.3ossl | 1 - .../share/man/man3/OPENSSL_strlcat.3ossl | 1 - .../share/man/man3/OPENSSL_strlcpy.3ossl | 1 - .../share/man/man3/OPENSSL_strncasecmp.3ossl | 1 - .../share/man/man3/OPENSSL_strndup.3ossl | 1 - .../share/man/man3/OPENSSL_strtoul.3ossl | 1 - .../share/man/man3/OPENSSL_thread_stop.3ossl | 1 - .../man/man3/OPENSSL_thread_stop_ex.3ossl | 1 - .../man3/OPENSSL_version_build_metadata.3ossl | 1 - .../man/man3/OPENSSL_version_major.3ossl | 1 - .../man/man3/OPENSSL_version_minor.3ossl | 1 - .../man/man3/OPENSSL_version_patch.3ossl | 1 - .../man3/OPENSSL_version_pre_release.3ossl | 1 - .../share/man/man3/OPENSSL_zalloc.3ossl | 1 - .../share/man/man3/OSSL_ALGORITHM.3ossl | 260 -- .../man3/OSSL_ATTRIBUTES_SYNTAX_free.3ossl | 1 - .../man/man3/OSSL_ATTRIBUTES_SYNTAX_it.3ossl | 1 - .../man/man3/OSSL_ATTRIBUTES_SYNTAX_new.3ossl | 1 - .../OSSL_BASIC_ATTR_CONSTRAINTS_free.3ossl | 1 - .../man3/OSSL_BASIC_ATTR_CONSTRAINTS_it.3ossl | 1 - .../OSSL_BASIC_ATTR_CONSTRAINTS_new.3ossl | 1 - .../share/man/man3/OSSL_CALLBACK.3ossl | 193 -- .../share/man/man3/OSSL_CMP_ATAV.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAVS.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAVS_free.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAVS_it.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAVS_new.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAV_create.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAV_free.3ossl | 1 - .../man/man3/OSSL_CMP_ATAV_get0_algId.3ossl | 1 - .../man/man3/OSSL_CMP_ATAV_get0_type.3ossl | 1 - .../man/man3/OSSL_CMP_ATAV_get0_value.3ossl | 1 - .../man3/OSSL_CMP_ATAV_get_rsaKeyLen.3ossl | 1 - .../man/man3/OSSL_CMP_ATAV_new_algId.3ossl | 1 - .../man3/OSSL_CMP_ATAV_new_rsaKeyLen.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAV_push1.3ossl | 1 - .../share/man/man3/OSSL_CMP_ATAV_set0.3ossl | 248 -- .../share/man/man3/OSSL_CMP_CR.3ossl | 1 - .../man/man3/OSSL_CMP_CRLSTATUS_create.3ossl | 1 - .../man/man3/OSSL_CMP_CRLSTATUS_free.3ossl | 1 - .../man/man3/OSSL_CMP_CRLSTATUS_get0.3ossl | 1 - .../man/man3/OSSL_CMP_CRLSTATUS_new1.3ossl | 1 - .../man3/OSSL_CMP_CTX_build_cert_chain.3ossl | 1 - .../share/man/man3/OSSL_CMP_CTX_free.3ossl | 1 - .../OSSL_CMP_CTX_get0_geninfo_ITAVs.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get0_libctx.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get0_newCert.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get0_newPkey.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get0_propq.3ossl | 1 - .../man3/OSSL_CMP_CTX_get0_statusString.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get0_trusted.3ossl | 1 - .../man3/OSSL_CMP_CTX_get0_trustedStore.3ossl | 1 - .../man3/OSSL_CMP_CTX_get0_untrusted.3ossl | 1 - .../OSSL_CMP_CTX_get0_validatedSrvCert.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get1_caPubs.3ossl | 1 - .../man3/OSSL_CMP_CTX_get1_extraCertsIn.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get1_newChain.3ossl | 1 - .../OSSL_CMP_CTX_get_certConf_cb_arg.3ossl | 1 - .../man3/OSSL_CMP_CTX_get_failInfoCode.3ossl | 1 - .../man3/OSSL_CMP_CTX_get_http_cb_arg.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get_option.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_get_status.3ossl | 1 - .../OSSL_CMP_CTX_get_transfer_cb_arg.3ossl | 1 - .../share/man/man3/OSSL_CMP_CTX_new.3ossl | 1039 -------- .../man/man3/OSSL_CMP_CTX_print_errors.3ossl | 1 - .../OSSL_CMP_CTX_push0_geninfo_ITAV.3ossl | 1 - .../man3/OSSL_CMP_CTX_push0_genm_ITAV.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_push0_policy.3ossl | 1 - .../OSSL_CMP_CTX_push1_subjectAltName.3ossl | 1 - .../share/man/man3/OSSL_CMP_CTX_reinit.3ossl | 1 - .../OSSL_CMP_CTX_reqExtensions_have_SAN.3ossl | 1 - .../OSSL_CMP_CTX_reset_geninfo_ITAVs.3ossl | 1 - .../man3/OSSL_CMP_CTX_server_perform.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set0_newPkey.3ossl | 1 - .../OSSL_CMP_CTX_set0_reqExtensions.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set0_trusted.3ossl | 1 - .../man3/OSSL_CMP_CTX_set0_trustedStore.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_cert.3ossl | 1 - .../OSSL_CMP_CTX_set1_expected_sender.3ossl | 1 - .../OSSL_CMP_CTX_set1_extraCertsOut.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_issuer.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_no_proxy.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_oldCert.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_p10CSR.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_pkey.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_proxy.3ossl | 1 - .../man3/OSSL_CMP_CTX_set1_recipient.3ossl | 1 - .../OSSL_CMP_CTX_set1_referenceValue.3ossl | 1 - .../man3/OSSL_CMP_CTX_set1_secretValue.3ossl | 1 - .../man3/OSSL_CMP_CTX_set1_senderNonce.3ossl | 1 - .../man3/OSSL_CMP_CTX_set1_serialNumber.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_server.3ossl | 1 - .../man3/OSSL_CMP_CTX_set1_serverPath.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set1_srvCert.3ossl | 1 - .../man3/OSSL_CMP_CTX_set1_subjectName.3ossl | 1 - .../OSSL_CMP_CTX_set1_transactionID.3ossl | 1 - .../man3/OSSL_CMP_CTX_set1_untrusted.3ossl | 1 - .../man3/OSSL_CMP_CTX_set_certConf_cb.3ossl | 1 - .../OSSL_CMP_CTX_set_certConf_cb_arg.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set_http_cb.3ossl | 1 - .../man3/OSSL_CMP_CTX_set_http_cb_arg.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set_log_cb.3ossl | 1 - .../man3/OSSL_CMP_CTX_set_log_verbosity.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_set_option.3ossl | 1 - .../man3/OSSL_CMP_CTX_set_serverPort.3ossl | 1 - .../man3/OSSL_CMP_CTX_set_transfer_cb.3ossl | 1 - .../OSSL_CMP_CTX_set_transfer_cb_arg.3ossl | 1 - .../man/man3/OSSL_CMP_CTX_setup_CRM.3ossl | 1 - .../man3/OSSL_CMP_CTX_snprint_PKIStatus.3ossl | 1 - .../OSSL_CMP_HDR_get0_geninfo_ITAVs.3ossl | 1 - .../man3/OSSL_CMP_HDR_get0_recipNonce.3ossl | 1 - .../OSSL_CMP_HDR_get0_transactionID.3ossl | 186 -- .../share/man/man3/OSSL_CMP_IR.3ossl | 1 - .../share/man/man3/OSSL_CMP_ITAV_create.3ossl | 1 - .../share/man/man3/OSSL_CMP_ITAV_dup.3ossl | 1 - .../share/man/man3/OSSL_CMP_ITAV_free.3ossl | 1 - .../man/man3/OSSL_CMP_ITAV_get0_caCerts.3ossl | 1 - .../man3/OSSL_CMP_ITAV_get0_certProfile.3ossl | 1 - .../OSSL_CMP_ITAV_get0_crlStatusList.3ossl | 1 - .../man/man3/OSSL_CMP_ITAV_get0_crls.3ossl | 1 - .../man3/OSSL_CMP_ITAV_get0_rootCaCert.3ossl | 1 - .../OSSL_CMP_ITAV_get0_rootCaKeyUpdate.3ossl | 1 - .../man/man3/OSSL_CMP_ITAV_get0_type.3ossl | 1 - .../man/man3/OSSL_CMP_ITAV_get0_value.3ossl | 1 - .../OSSL_CMP_ITAV_get1_certReqTemplate.3ossl | 1 - .../man3/OSSL_CMP_ITAV_new0_certProfile.3ossl | 1 - .../OSSL_CMP_ITAV_new0_certReqTemplate.3ossl | 1 - .../OSSL_CMP_ITAV_new0_crlStatusList.3ossl | 1 - .../man/man3/OSSL_CMP_ITAV_new_caCerts.3ossl | 345 --- .../man/man3/OSSL_CMP_ITAV_new_crls.3ossl | 1 - .../man3/OSSL_CMP_ITAV_new_rootCaCert.3ossl | 1 - .../OSSL_CMP_ITAV_new_rootCaKeyUpdate.3ossl | 1 - .../man3/OSSL_CMP_ITAV_push0_stack_item.3ossl | 1 - .../share/man/man3/OSSL_CMP_ITAV_set0.3ossl | 264 -- .../share/man/man3/OSSL_CMP_KUR.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_ALERT.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_CRIT.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_DEBUG.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_EMERG.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_ERR.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_INFO.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_NOTICE.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_TRACE.3ossl | 1 - .../share/man/man3/OSSL_CMP_LOG_WARNING.3ossl | 1 - .../share/man/man3/OSSL_CMP_MSG_dup.3ossl | 1 - .../share/man/man3/OSSL_CMP_MSG_free.3ossl | 1 - .../OSSL_CMP_MSG_get0_certreq_publickey.3ossl | 1 - .../man/man3/OSSL_CMP_MSG_get0_header.3ossl | 287 --- .../man/man3/OSSL_CMP_MSG_get_bodytype.3ossl | 1 - .../man/man3/OSSL_CMP_MSG_http_perform.3ossl | 190 -- .../share/man/man3/OSSL_CMP_MSG_it.3ossl | 1 - .../share/man/man3/OSSL_CMP_MSG_read.3ossl | 1 - .../man3/OSSL_CMP_MSG_update_recipNonce.3ossl | 1 - .../OSSL_CMP_MSG_update_transactionID.3ossl | 1 - .../share/man/man3/OSSL_CMP_MSG_write.3ossl | 1 - .../share/man/man3/OSSL_CMP_P10CR.3ossl | 1 - .../man/man3/OSSL_CMP_PKIHEADER_free.3ossl | 1 - .../man/man3/OSSL_CMP_PKIHEADER_it.3ossl | 1 - .../man/man3/OSSL_CMP_PKIHEADER_new.3ossl | 1 - .../share/man/man3/OSSL_CMP_PKISI_dup.3ossl | 1 - .../share/man/man3/OSSL_CMP_PKISI_free.3ossl | 1 - .../share/man/man3/OSSL_CMP_PKISI_it.3ossl | 1 - .../share/man/man3/OSSL_CMP_PKISI_new.3ossl | 1 - .../man/man3/OSSL_CMP_PKISTATUS_it.3ossl | 1 - .../man/man3/OSSL_CMP_SRV_CTX_free.3ossl | 1 - .../man3/OSSL_CMP_SRV_CTX_get0_cmp_ctx.3ossl | 1 - .../OSSL_CMP_SRV_CTX_get0_custom_ctx.3ossl | 1 - .../man/man3/OSSL_CMP_SRV_CTX_init.3ossl | 1 - .../man3/OSSL_CMP_SRV_CTX_init_trans.3ossl | 1 - .../share/man/man3/OSSL_CMP_SRV_CTX_new.3ossl | 328 --- ...SL_CMP_SRV_CTX_set_accept_raverified.3ossl | 1 - ...L_CMP_SRV_CTX_set_accept_unprotected.3ossl | 1 - ...P_SRV_CTX_set_grant_implicit_confirm.3ossl | 1 - ..._SRV_CTX_set_send_unprotected_errors.3ossl | 1 - .../man/man3/OSSL_CMP_SRV_certConf_cb_t.3ossl | 1 - .../man3/OSSL_CMP_SRV_cert_request_cb_t.3ossl | 1 - .../OSSL_CMP_SRV_clean_transaction_cb_t.3ossl | 1 - .../OSSL_CMP_SRV_delayed_delivery_cb_t.3ossl | 1 - .../man/man3/OSSL_CMP_SRV_error_cb_t.3ossl | 1 - .../man/man3/OSSL_CMP_SRV_genm_cb_t.3ossl | 1 - .../man/man3/OSSL_CMP_SRV_pollReq_cb_t.3ossl | 1 - .../man3/OSSL_CMP_SRV_process_request.3ossl | 1 - .../share/man/man3/OSSL_CMP_SRV_rr_cb_t.3ossl | 1 - .../man/man3/OSSL_CMP_STATUSINFO_new.3ossl | 197 -- .../share/man/man3/OSSL_CMP_certConf_cb.3ossl | 1 - .../man/man3/OSSL_CMP_certConf_cb_t.3ossl | 1 - .../share/man/man3/OSSL_CMP_exec_CR_ses.3ossl | 1 - .../man/man3/OSSL_CMP_exec_GENM_ses.3ossl | 1 - .../share/man/man3/OSSL_CMP_exec_IR_ses.3ossl | 1 - .../man/man3/OSSL_CMP_exec_KUR_ses.3ossl | 1 - .../man/man3/OSSL_CMP_exec_P10CR_ses.3ossl | 1 - .../share/man/man3/OSSL_CMP_exec_RR_ses.3ossl | 1 - .../man/man3/OSSL_CMP_exec_certreq.3ossl | 393 --- .../man/man3/OSSL_CMP_get1_caCerts.3ossl | 1 - .../man3/OSSL_CMP_get1_certReqTemplate.3ossl | 1 - .../man/man3/OSSL_CMP_get1_crlUpdate.3ossl | 1 - .../man3/OSSL_CMP_get1_rootCaKeyUpdate.3ossl | 1 - .../share/man/man3/OSSL_CMP_log_cb_t.3ossl | 1 - .../share/man/man3/OSSL_CMP_log_close.3ossl | 1 - .../share/man/man3/OSSL_CMP_log_open.3ossl | 258 -- .../man/man3/OSSL_CMP_print_errors_cb.3ossl | 1 - .../man/man3/OSSL_CMP_print_to_bio.3ossl | 1 - .../share/man/man3/OSSL_CMP_severity.3ossl | 1 - .../man3/OSSL_CMP_snprint_PKIStatusInfo.3ossl | 1 - .../man/man3/OSSL_CMP_transfer_cb_t.3ossl | 1 - .../share/man/man3/OSSL_CMP_try_certreq.3ossl | 1 - .../man3/OSSL_CMP_validate_cert_path.3ossl | 1 - .../man/man3/OSSL_CMP_validate_msg.3ossl | 219 -- .../share/man/man3/OSSL_CORE_MAKE_FUNC.3ossl | 175 -- .../OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup.3ossl | 1 - ...OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free.3ossl | 1 - .../share/man/man3/OSSL_CRMF_CERTID_dup.3ossl | 1 - .../man/man3/OSSL_CRMF_CERTID_free.3ossl | 1 - .../share/man/man3/OSSL_CRMF_CERTID_gen.3ossl | 1 - .../man3/OSSL_CRMF_CERTID_get0_issuer.3ossl | 1 - .../OSSL_CRMF_CERTID_get0_serialNumber.3ossl | 1 - .../share/man/man3/OSSL_CRMF_CERTID_it.3ossl | 1 - .../share/man/man3/OSSL_CRMF_CERTID_new.3ossl | 1 - .../man/man3/OSSL_CRMF_CERTTEMPLATE_dup.3ossl | 1 - .../man3/OSSL_CRMF_CERTTEMPLATE_fill.3ossl | 1 - .../man3/OSSL_CRMF_CERTTEMPLATE_free.3ossl | 1 - ...SL_CRMF_CERTTEMPLATE_get0_extensions.3ossl | 1 - .../OSSL_CRMF_CERTTEMPLATE_get0_issuer.3ossl | 1 - ...SSL_CRMF_CERTTEMPLATE_get0_publicKey.3ossl | 1 - ..._CRMF_CERTTEMPLATE_get0_serialNumber.3ossl | 1 - .../OSSL_CRMF_CERTTEMPLATE_get0_subject.3ossl | 1 - .../man/man3/OSSL_CRMF_CERTTEMPLATE_it.3ossl | 1 - .../man/man3/OSSL_CRMF_CERTTEMPLATE_new.3ossl | 1 - .../man3/OSSL_CRMF_ENCRYPTEDVALUE_free.3ossl | 1 - ...SSL_CRMF_ENCRYPTEDVALUE_get1_encCert.3ossl | 1 - .../man3/OSSL_CRMF_ENCRYPTEDVALUE_it.3ossl | 1 - .../man3/OSSL_CRMF_ENCRYPTEDVALUE_new.3ossl | 1 - .../share/man/man3/OSSL_CRMF_MSGS_free.3ossl | 1 - .../share/man/man3/OSSL_CRMF_MSGS_it.3ossl | 1 - .../share/man/man3/OSSL_CRMF_MSGS_new.3ossl | 1 - .../man/man3/OSSL_CRMF_MSGS_verify_popo.3ossl | 1 - ...IPublicationInfo_push0_SinglePubInfo.3ossl | 1 - .../man/man3/OSSL_CRMF_MSG_create_popo.3ossl | 1 - .../share/man/man3/OSSL_CRMF_MSG_dup.3ossl | 1 - .../share/man/man3/OSSL_CRMF_MSG_free.3ossl | 1 - ..._CRMF_MSG_get0_regCtrl_authenticator.3ossl | 1 - ...OSSL_CRMF_MSG_get0_regCtrl_oldCertID.3ossl | 1 - ..._MSG_get0_regCtrl_pkiPublicationInfo.3ossl | 1 - ...RMF_MSG_get0_regCtrl_protocolEncrKey.3ossl | 1 - .../OSSL_CRMF_MSG_get0_regCtrl_regToken.3ossl | 1 - .../OSSL_CRMF_MSG_get0_regInfo_certReq.3ossl | 1 - ...OSSL_CRMF_MSG_get0_regInfo_utf8Pairs.3ossl | 1 - .../man/man3/OSSL_CRMF_MSG_get0_tmpl.3ossl | 235 -- .../man3/OSSL_CRMF_MSG_get_certReqId.3ossl | 1 - .../share/man/man3/OSSL_CRMF_MSG_it.3ossl | 1 - .../share/man/man3/OSSL_CRMF_MSG_new.3ossl | 1 - .../man3/OSSL_CRMF_MSG_push0_extension.3ossl | 1 - .../OSSL_CRMF_MSG_set0_SinglePubInfo.3ossl | 1 - .../man3/OSSL_CRMF_MSG_set0_extensions.3ossl | 1 - .../man3/OSSL_CRMF_MSG_set0_validity.3ossl | 247 -- ..._CRMF_MSG_set1_regCtrl_authenticator.3ossl | 1 - ...OSSL_CRMF_MSG_set1_regCtrl_oldCertID.3ossl | 1 - ..._MSG_set1_regCtrl_pkiPublicationInfo.3ossl | 1 - ...RMF_MSG_set1_regCtrl_protocolEncrKey.3ossl | 1 - .../OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl | 261 -- .../OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl | 198 -- ...OSSL_CRMF_MSG_set1_regInfo_utf8Pairs.3ossl | 1 - ...MF_MSG_set_PKIPublicationInfo_action.3ossl | 1 - .../man3/OSSL_CRMF_MSG_set_certReqId.3ossl | 1 - .../man3/OSSL_CRMF_PBMPARAMETER_free.3ossl | 1 - .../man/man3/OSSL_CRMF_PBMPARAMETER_it.3ossl | 1 - .../man/man3/OSSL_CRMF_PBMPARAMETER_new.3ossl | 1 - .../OSSL_CRMF_PKIPUBLICATIONINFO_free.3ossl | 1 - .../OSSL_CRMF_PKIPUBLICATIONINFO_it.3ossl | 1 - .../OSSL_CRMF_PKIPUBLICATIONINFO_new.3ossl | 1 - .../man3/OSSL_CRMF_SINGLEPUBINFO_free.3ossl | 1 - .../man/man3/OSSL_CRMF_SINGLEPUBINFO_it.3ossl | 1 - .../man3/OSSL_CRMF_SINGLEPUBINFO_new.3ossl | 1 - .../share/man/man3/OSSL_CRMF_pbm_new.3ossl | 1 - .../share/man/man3/OSSL_CRMF_pbmp_new.3ossl | 223 -- .../share/man/man3/OSSL_DECODER.3ossl | 322 --- .../share/man/man3/OSSL_DECODER_CLEANUP.3ossl | 1 - .../man/man3/OSSL_DECODER_CONSTRUCT.3ossl | 1 - .../share/man/man3/OSSL_DECODER_CTX.3ossl | 382 --- .../man3/OSSL_DECODER_CTX_add_decoder.3ossl | 1 - .../man/man3/OSSL_DECODER_CTX_add_extra.3ossl | 1 - .../man/man3/OSSL_DECODER_CTX_free.3ossl | 1 - .../man3/OSSL_DECODER_CTX_get_cleanup.3ossl | 1 - .../man3/OSSL_DECODER_CTX_get_construct.3ossl | 1 - .../OSSL_DECODER_CTX_get_construct_data.3ossl | 1 - .../OSSL_DECODER_CTX_get_num_decoders.3ossl | 1 - .../share/man/man3/OSSL_DECODER_CTX_new.3ossl | 1 - .../man3/OSSL_DECODER_CTX_new_for_pkey.3ossl | 273 -- .../man3/OSSL_DECODER_CTX_set_cleanup.3ossl | 1 - .../man3/OSSL_DECODER_CTX_set_construct.3ossl | 1 - .../OSSL_DECODER_CTX_set_construct_data.3ossl | 1 - ...OSSL_DECODER_CTX_set_input_structure.3ossl | 1 - .../OSSL_DECODER_CTX_set_input_type.3ossl | 1 - .../man3/OSSL_DECODER_CTX_set_params.3ossl | 1 - .../OSSL_DECODER_CTX_set_passphrase.3ossl | 1 - .../OSSL_DECODER_CTX_set_passphrase_cb.3ossl | 1 - .../OSSL_DECODER_CTX_set_passphrase_ui.3ossl | 1 - ...OSSL_DECODER_CTX_set_pem_password_cb.3ossl | 1 - .../man3/OSSL_DECODER_CTX_set_selection.3ossl | 1 - .../man/man3/OSSL_DECODER_INSTANCE.3ossl | 1 - .../OSSL_DECODER_INSTANCE_get_decoder.3ossl | 1 - ...SSL_DECODER_INSTANCE_get_decoder_ctx.3ossl | 1 - ...DECODER_INSTANCE_get_input_structure.3ossl | 1 - ...OSSL_DECODER_INSTANCE_get_input_type.3ossl | 1 - .../man3/OSSL_DECODER_do_all_provided.3ossl | 1 - .../share/man/man3/OSSL_DECODER_export.3ossl | 1 - .../share/man/man3/OSSL_DECODER_fetch.3ossl | 1 - .../share/man/man3/OSSL_DECODER_free.3ossl | 1 - .../man/man3/OSSL_DECODER_from_bio.3ossl | 249 -- .../man/man3/OSSL_DECODER_from_data.3ossl | 1 - .../share/man/man3/OSSL_DECODER_from_fp.3ossl | 1 - .../man3/OSSL_DECODER_get0_description.3ossl | 1 - .../man/man3/OSSL_DECODER_get0_name.3ossl | 1 - .../man3/OSSL_DECODER_get0_properties.3ossl | 1 - .../man/man3/OSSL_DECODER_get0_provider.3ossl | 1 - .../man/man3/OSSL_DECODER_get_params.3ossl | 1 - .../man3/OSSL_DECODER_gettable_params.3ossl | 1 - .../share/man/man3/OSSL_DECODER_is_a.3ossl | 1 - .../man/man3/OSSL_DECODER_names_do_all.3ossl | 1 - .../OSSL_DECODER_settable_ctx_params.3ossl | 1 - .../share/man/man3/OSSL_DECODER_up_ref.3ossl | 1 - .../share/man/man3/OSSL_DISPATCH.3ossl | 198 -- .../share/man/man3/OSSL_DISPATCH_END.3ossl | 1 - .../man/man3/OSSL_EC_curve_nid2name.3ossl | 1 - .../share/man/man3/OSSL_ENCODER.3ossl | 276 --- .../share/man/man3/OSSL_ENCODER_CLEANUP.3ossl | 1 - .../man/man3/OSSL_ENCODER_CONSTRUCT.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_CTX.3ossl | 345 --- .../man3/OSSL_ENCODER_CTX_add_encoder.3ossl | 1 - .../man/man3/OSSL_ENCODER_CTX_add_extra.3ossl | 1 - .../man/man3/OSSL_ENCODER_CTX_free.3ossl | 1 - .../OSSL_ENCODER_CTX_get_num_encoders.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_CTX_new.3ossl | 1 - .../man3/OSSL_ENCODER_CTX_new_for_pkey.3ossl | 271 -- .../man3/OSSL_ENCODER_CTX_set_cipher.3ossl | 1 - .../man3/OSSL_ENCODER_CTX_set_cleanup.3ossl | 1 - .../man3/OSSL_ENCODER_CTX_set_construct.3ossl | 1 - .../OSSL_ENCODER_CTX_set_construct_data.3ossl | 1 - ...SSL_ENCODER_CTX_set_output_structure.3ossl | 1 - .../OSSL_ENCODER_CTX_set_output_type.3ossl | 1 - .../man3/OSSL_ENCODER_CTX_set_params.3ossl | 1 - .../OSSL_ENCODER_CTX_set_passphrase.3ossl | 1 - .../OSSL_ENCODER_CTX_set_passphrase_cb.3ossl | 1 - .../OSSL_ENCODER_CTX_set_passphrase_ui.3ossl | 1 - ...OSSL_ENCODER_CTX_set_pem_password_cb.3ossl | 1 - .../man3/OSSL_ENCODER_CTX_set_selection.3ossl | 1 - .../man/man3/OSSL_ENCODER_INSTANCE.3ossl | 1 - .../OSSL_ENCODER_INSTANCE_get_encoder.3ossl | 1 - ...SSL_ENCODER_INSTANCE_get_encoder_ctx.3ossl | 1 - ...NCODER_INSTANCE_get_output_structure.3ossl | 1 - ...SSL_ENCODER_INSTANCE_get_output_type.3ossl | 1 - .../man3/OSSL_ENCODER_do_all_provided.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_fetch.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_free.3ossl | 1 - .../man3/OSSL_ENCODER_get0_description.3ossl | 1 - .../man/man3/OSSL_ENCODER_get0_name.3ossl | 1 - .../man3/OSSL_ENCODER_get0_properties.3ossl | 1 - .../man/man3/OSSL_ENCODER_get0_provider.3ossl | 1 - .../man/man3/OSSL_ENCODER_get_params.3ossl | 1 - .../man3/OSSL_ENCODER_gettable_params.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_is_a.3ossl | 1 - .../man/man3/OSSL_ENCODER_names_do_all.3ossl | 1 - .../OSSL_ENCODER_settable_ctx_params.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_to_bio.3ossl | 260 -- .../share/man/man3/OSSL_ENCODER_to_data.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_to_fp.3ossl | 1 - .../share/man/man3/OSSL_ENCODER_up_ref.3ossl | 1 - .../share/man/man3/OSSL_ERR_STATE_free.3ossl | 1 - .../share/man/man3/OSSL_ERR_STATE_new.3ossl | 1 - .../man/man3/OSSL_ERR_STATE_restore.3ossl | 1 - .../share/man/man3/OSSL_ERR_STATE_save.3ossl | 217 -- .../man3/OSSL_ERR_STATE_save_to_mark.3ossl | 1 - .../man3/OSSL_ESS_check_signing_certs.3ossl | 218 -- .../man3/OSSL_ESS_signing_cert_new_init.3ossl | 1 - .../OSSL_ESS_signing_cert_v2_new_init.3ossl | 1 - .../man/man3/OSSL_GENERAL_NAMES_print.3ossl | 168 -- .../share/man/man3/OSSL_HPKE_CTX_free.3ossl | 1 - .../man/man3/OSSL_HPKE_CTX_get_seq.3ossl | 1 - .../share/man/man3/OSSL_HPKE_CTX_new.3ossl | 672 ----- .../man3/OSSL_HPKE_CTX_set1_authpriv.3ossl | 1 - .../man/man3/OSSL_HPKE_CTX_set1_authpub.3ossl | 1 - .../man/man3/OSSL_HPKE_CTX_set1_ikme.3ossl | 1 - .../man/man3/OSSL_HPKE_CTX_set1_psk.3ossl | 1 - .../man/man3/OSSL_HPKE_CTX_set_seq.3ossl | 1 - .../share/man/man3/OSSL_HPKE_decap.3ossl | 1 - .../share/man/man3/OSSL_HPKE_encap.3ossl | 1 - .../share/man/man3/OSSL_HPKE_export.3ossl | 1 - .../man3/OSSL_HPKE_get_ciphertext_size.3ossl | 1 - .../man/man3/OSSL_HPKE_get_grease_value.3ossl | 1 - .../OSSL_HPKE_get_public_encap_size.3ossl | 1 - .../OSSL_HPKE_get_recommended_ikmelen.3ossl | 1 - .../share/man/man3/OSSL_HPKE_keygen.3ossl | 1 - .../share/man/man3/OSSL_HPKE_open.3ossl | 1 - .../share/man/man3/OSSL_HPKE_seal.3ossl | 1 - .../share/man/man3/OSSL_HPKE_str2suite.3ossl | 1 - .../man/man3/OSSL_HPKE_suite_check.3ossl | 1 - .../share/man/man3/OSSL_HTTP_REQ_CTX.3ossl | 418 ---- .../man3/OSSL_HTTP_REQ_CTX_add1_header.3ossl | 1 - .../man/man3/OSSL_HTTP_REQ_CTX_exchange.3ossl | 1 - .../man/man3/OSSL_HTTP_REQ_CTX_free.3ossl | 1 - .../man3/OSSL_HTTP_REQ_CTX_get0_mem_bio.3ossl | 1 - .../man3/OSSL_HTTP_REQ_CTX_get_resp_len.3ossl | 1 - .../man/man3/OSSL_HTTP_REQ_CTX_nbio.3ossl | 1 - .../man/man3/OSSL_HTTP_REQ_CTX_nbio_d2i.3ossl | 1 - .../man/man3/OSSL_HTTP_REQ_CTX_new.3ossl | 1 - .../man/man3/OSSL_HTTP_REQ_CTX_set1_req.3ossl | 1 - .../man3/OSSL_HTTP_REQ_CTX_set_expected.3ossl | 1 - ...P_REQ_CTX_set_max_response_hdr_lines.3ossl | 1 - ...HTTP_REQ_CTX_set_max_response_length.3ossl | 1 - .../OSSL_HTTP_REQ_CTX_set_request_line.3ossl | 1 - .../man/man3/OSSL_HTTP_adapt_proxy.3ossl | 1 - .../share/man/man3/OSSL_HTTP_bio_cb_t.3ossl | 1 - .../share/man/man3/OSSL_HTTP_close.3ossl | 1 - .../share/man/man3/OSSL_HTTP_exchange.3ossl | 1 - .../share/man/man3/OSSL_HTTP_get.3ossl | 1 - .../share/man/man3/OSSL_HTTP_is_alive.3ossl | 1 - .../share/man/man3/OSSL_HTTP_open.3ossl | 1 - .../share/man/man3/OSSL_HTTP_parse_url.3ossl | 245 -- .../man/man3/OSSL_HTTP_proxy_connect.3ossl | 1 - .../man/man3/OSSL_HTTP_set1_request.3ossl | 1 - .../share/man/man3/OSSL_HTTP_transfer.3ossl | 440 ---- .../man/man3/OSSL_IETF_ATTR_SYNTAX.3ossl | 222 -- .../OSSL_IETF_ATTR_SYNTAX_VALUE_free.3ossl | 1 - .../man3/OSSL_IETF_ATTR_SYNTAX_VALUE_it.3ossl | 1 - .../OSSL_IETF_ATTR_SYNTAX_VALUE_new.3ossl | 1 - .../OSSL_IETF_ATTR_SYNTAX_add1_value.3ossl | 1 - .../man/man3/OSSL_IETF_ATTR_SYNTAX_free.3ossl | 1 - ...ETF_ATTR_SYNTAX_get0_policyAuthority.3ossl | 1 - .../OSSL_IETF_ATTR_SYNTAX_get0_value.3ossl | 1 - .../OSSL_IETF_ATTR_SYNTAX_get_value_num.3ossl | 1 - .../man/man3/OSSL_IETF_ATTR_SYNTAX_it.3ossl | 1 - .../man/man3/OSSL_IETF_ATTR_SYNTAX_new.3ossl | 1 - .../man3/OSSL_IETF_ATTR_SYNTAX_print.3ossl | 172 -- ...ETF_ATTR_SYNTAX_set0_policyAuthority.3ossl | 1 - .../man3/OSSL_INDICATOR_get_callback.3ossl | 1 - .../man3/OSSL_INDICATOR_set_callback.3ossl | 214 -- .../man/man3/OSSL_ISSUER_SERIAL_free.3ossl | 1 - .../man3/OSSL_ISSUER_SERIAL_get0_issuer.3ossl | 1 - .../OSSL_ISSUER_SERIAL_get0_issuerUID.3ossl | 1 - .../man3/OSSL_ISSUER_SERIAL_get0_serial.3ossl | 1 - .../man/man3/OSSL_ISSUER_SERIAL_new.3ossl | 1 - .../man3/OSSL_ISSUER_SERIAL_set1_issuer.3ossl | 1 - .../OSSL_ISSUER_SERIAL_set1_issuerUID.3ossl | 1 - .../man3/OSSL_ISSUER_SERIAL_set1_serial.3ossl | 1 - .../share/man/man3/OSSL_ITEM.3ossl | 178 -- .../share/man/man3/OSSL_LIB_CTX.3ossl | 284 --- .../share/man/man3/OSSL_LIB_CTX_free.3ossl | 1 - .../OSSL_LIB_CTX_get0_global_default.3ossl | 1 - .../OSSL_LIB_CTX_get_conf_diagnostics.3ossl | 1 - .../man/man3/OSSL_LIB_CTX_get_data.3ossl | 1 - .../man/man3/OSSL_LIB_CTX_load_config.3ossl | 1 - .../share/man/man3/OSSL_LIB_CTX_new.3ossl | 1 - .../man/man3/OSSL_LIB_CTX_new_child.3ossl | 1 - .../man3/OSSL_LIB_CTX_new_from_dispatch.3ossl | 1 - .../man/man3/OSSL_LIB_CTX_set0_default.3ossl | 1 - .../OSSL_LIB_CTX_set_conf_diagnostics.3ossl | 184 -- .../man3/OSSL_OBJECT_DIGEST_INFO_free.3ossl | 1 - .../OSSL_OBJECT_DIGEST_INFO_get0_digest.3ossl | 1 - .../man3/OSSL_OBJECT_DIGEST_INFO_new.3ossl | 1 - .../OSSL_OBJECT_DIGEST_INFO_set1_digest.3ossl | 1 - .../share/man/man3/OSSL_PARAM.3ossl | 466 ---- .../share/man/man3/OSSL_PARAM_BLD.3ossl | 339 --- .../share/man/man3/OSSL_PARAM_BLD_free.3ossl | 1 - .../share/man/man3/OSSL_PARAM_BLD_new.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_BN.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_BN_pad.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_double.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_int.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_int32.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_int64.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_long.3ossl | 1 - .../man3/OSSL_PARAM_BLD_push_octet_ptr.3ossl | 1 - .../OSSL_PARAM_BLD_push_octet_string.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_size_t.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_time_t.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_uint.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_uint32.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_uint64.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_push_ulong.3ossl | 1 - .../man3/OSSL_PARAM_BLD_push_utf8_ptr.3ossl | 1 - .../OSSL_PARAM_BLD_push_utf8_string.3ossl | 1 - .../man/man3/OSSL_PARAM_BLD_to_param.3ossl | 1 - .../share/man/man3/OSSL_PARAM_BN.3ossl | 1 - .../share/man/man3/OSSL_PARAM_DEFN.3ossl | 1 - .../share/man/man3/OSSL_PARAM_END.3ossl | 1 - .../man/man3/OSSL_PARAM_UNMODIFIED.3ossl | 1 - .../man3/OSSL_PARAM_allocate_from_text.3ossl | 330 --- .../man/man3/OSSL_PARAM_construct_BN.3ossl | 1 - .../man3/OSSL_PARAM_construct_double.3ossl | 1 - .../man/man3/OSSL_PARAM_construct_end.3ossl | 1 - .../man/man3/OSSL_PARAM_construct_int.3ossl | 1 - .../man/man3/OSSL_PARAM_construct_int32.3ossl | 1 - .../man/man3/OSSL_PARAM_construct_int64.3ossl | 1 - .../man/man3/OSSL_PARAM_construct_long.3ossl | 1 - .../man3/OSSL_PARAM_construct_octet_ptr.3ossl | 1 - .../OSSL_PARAM_construct_octet_string.3ossl | 1 - .../man3/OSSL_PARAM_construct_size_t.3ossl | 1 - .../man3/OSSL_PARAM_construct_time_t.3ossl | 1 - .../man/man3/OSSL_PARAM_construct_uint.3ossl | 1 - .../man3/OSSL_PARAM_construct_uint32.3ossl | 1 - .../man3/OSSL_PARAM_construct_uint64.3ossl | 1 - .../man/man3/OSSL_PARAM_construct_ulong.3ossl | 1 - .../man3/OSSL_PARAM_construct_utf8_ptr.3ossl | 1 - .../OSSL_PARAM_construct_utf8_string.3ossl | 1 - .../share/man/man3/OSSL_PARAM_double.3ossl | 1 - .../share/man/man3/OSSL_PARAM_dup.3ossl | 191 -- .../share/man/man3/OSSL_PARAM_free.3ossl | 1 - .../share/man/man3/OSSL_PARAM_get_BN.3ossl | 1 - .../man/man3/OSSL_PARAM_get_double.3ossl | 1 - .../share/man/man3/OSSL_PARAM_get_int.3ossl | 1 - .../share/man/man3/OSSL_PARAM_get_int32.3ossl | 1 - .../share/man/man3/OSSL_PARAM_get_int64.3ossl | 1 - .../share/man/man3/OSSL_PARAM_get_long.3ossl | 1 - .../man/man3/OSSL_PARAM_get_octet_ptr.3ossl | 1 - .../man3/OSSL_PARAM_get_octet_string.3ossl | 1 - .../OSSL_PARAM_get_octet_string_ptr.3ossl | 1 - .../man/man3/OSSL_PARAM_get_size_t.3ossl | 1 - .../man/man3/OSSL_PARAM_get_time_t.3ossl | 1 - .../share/man/man3/OSSL_PARAM_get_uint.3ossl | 1 - .../man/man3/OSSL_PARAM_get_uint32.3ossl | 1 - .../man/man3/OSSL_PARAM_get_uint64.3ossl | 1 - .../share/man/man3/OSSL_PARAM_get_ulong.3ossl | 1 - .../man/man3/OSSL_PARAM_get_utf8_ptr.3ossl | 1 - .../man/man3/OSSL_PARAM_get_utf8_string.3ossl | 1 - .../man3/OSSL_PARAM_get_utf8_string_ptr.3ossl | 1 - .../share/man/man3/OSSL_PARAM_int.3ossl | 543 ---- .../share/man/man3/OSSL_PARAM_int32.3ossl | 1 - .../share/man/man3/OSSL_PARAM_int64.3ossl | 1 - .../share/man/man3/OSSL_PARAM_locate.3ossl | 1 - .../man/man3/OSSL_PARAM_locate_const.3ossl | 1 - .../share/man/man3/OSSL_PARAM_long.3ossl | 1 - .../share/man/man3/OSSL_PARAM_merge.3ossl | 1 - .../share/man/man3/OSSL_PARAM_modified.3ossl | 1 - .../share/man/man3/OSSL_PARAM_octet_ptr.3ossl | 1 - .../man/man3/OSSL_PARAM_octet_string.3ossl | 1 - .../share/man/man3/OSSL_PARAM_set_BN.3ossl | 1 - .../man3/OSSL_PARAM_set_all_unmodified.3ossl | 1 - .../man/man3/OSSL_PARAM_set_double.3ossl | 1 - .../share/man/man3/OSSL_PARAM_set_int.3ossl | 1 - .../share/man/man3/OSSL_PARAM_set_int32.3ossl | 1 - .../share/man/man3/OSSL_PARAM_set_int64.3ossl | 1 - .../share/man/man3/OSSL_PARAM_set_long.3ossl | 1 - .../man/man3/OSSL_PARAM_set_octet_ptr.3ossl | 1 - .../man3/OSSL_PARAM_set_octet_string.3ossl | 1 - .../man/man3/OSSL_PARAM_set_size_t.3ossl | 1 - .../man/man3/OSSL_PARAM_set_time_t.3ossl | 1 - .../share/man/man3/OSSL_PARAM_set_uint.3ossl | 1 - .../man/man3/OSSL_PARAM_set_uint32.3ossl | 1 - .../man/man3/OSSL_PARAM_set_uint64.3ossl | 1 - .../share/man/man3/OSSL_PARAM_set_ulong.3ossl | 1 - .../man/man3/OSSL_PARAM_set_utf8_ptr.3ossl | 1 - .../man/man3/OSSL_PARAM_set_utf8_string.3ossl | 1 - .../share/man/man3/OSSL_PARAM_size_t.3ossl | 1 - .../share/man/man3/OSSL_PARAM_time_t.3ossl | 1 - .../share/man/man3/OSSL_PARAM_uint.3ossl | 1 - .../share/man/man3/OSSL_PARAM_uint32.3ossl | 1 - .../share/man/man3/OSSL_PARAM_uint64.3ossl | 1 - .../share/man/man3/OSSL_PARAM_ulong.3ossl | 1 - .../share/man/man3/OSSL_PARAM_utf8_ptr.3ossl | 1 - .../man/man3/OSSL_PARAM_utf8_string.3ossl | 1 - .../man/man3/OSSL_PASSPHRASE_CALLBACK.3ossl | 1 - .../share/man/man3/OSSL_PROVIDER.3ossl | 380 --- .../man/man3/OSSL_PROVIDER_add_builtin.3ossl | 1 - .../man/man3/OSSL_PROVIDER_available.3ossl | 1 - .../share/man/man3/OSSL_PROVIDER_do_all.3ossl | 1 - ...SL_PROVIDER_get0_default_search_path.3ossl | 1 - .../man3/OSSL_PROVIDER_get0_dispatch.3ossl | 1 - .../man/man3/OSSL_PROVIDER_get0_name.3ossl | 1 - .../OSSL_PROVIDER_get0_provider_ctx.3ossl | 1 - .../man3/OSSL_PROVIDER_get_capabilities.3ossl | 1 - .../man/man3/OSSL_PROVIDER_get_params.3ossl | 1 - .../man3/OSSL_PROVIDER_gettable_params.3ossl | 1 - .../share/man/man3/OSSL_PROVIDER_load.3ossl | 1 - .../man/man3/OSSL_PROVIDER_load_ex.3ossl | 1 - .../man3/OSSL_PROVIDER_query_operation.3ossl | 1 - .../man/man3/OSSL_PROVIDER_self_test.3ossl | 1 - ...SSL_PROVIDER_set_default_search_path.3ossl | 1 - .../man/man3/OSSL_PROVIDER_try_load.3ossl | 1 - .../man/man3/OSSL_PROVIDER_try_load_ex.3ossl | 1 - .../share/man/man3/OSSL_PROVIDER_unload.3ossl | 1 - .../OSSL_PROVIDER_unquery_operation.3ossl | 1 - .../OSSL_QUIC_ERR_AEAD_LIMIT_REACHED.3ossl | 1 - .../OSSL_QUIC_ERR_APPLICATION_ERROR.3ossl | 1 - ...L_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR.3ossl | 1 - .../OSSL_QUIC_ERR_CONNECTION_REFUSED.3ossl | 1 - ...OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED.3ossl | 1 - .../man/man3/OSSL_QUIC_ERR_CRYPTO_ERR.3ossl | 1 - .../man3/OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN.3ossl | 1 - .../man3/OSSL_QUIC_ERR_CRYPTO_ERR_END.3ossl | 1 - .../man3/OSSL_QUIC_ERR_FINAL_SIZE_ERROR.3ossl | 1 - .../OSSL_QUIC_ERR_FLOW_CONTROL_ERROR.3ossl | 1 - .../OSSL_QUIC_ERR_FRAME_ENCODING_ERROR.3ossl | 1 - .../man3/OSSL_QUIC_ERR_INTERNAL_ERROR.3ossl | 1 - .../man3/OSSL_QUIC_ERR_INVALID_TOKEN.3ossl | 1 - .../man3/OSSL_QUIC_ERR_KEY_UPDATE_ERROR.3ossl | 1 - .../man/man3/OSSL_QUIC_ERR_NO_ERROR.3ossl | 1 - .../man3/OSSL_QUIC_ERR_NO_VIABLE_PATH.3ossl | 1 - .../OSSL_QUIC_ERR_PROTOCOL_VIOLATION.3ossl | 1 - .../OSSL_QUIC_ERR_STREAM_LIMIT_ERROR.3ossl | 1 - .../OSSL_QUIC_ERR_STREAM_STATE_ERROR.3ossl | 1 - ...L_QUIC_ERR_TRANSPORT_PARAMETER_ERROR.3ossl | 1 - .../OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT.3ossl | 1 - .../man/man3/OSSL_QUIC_client_method.3ossl | 181 -- .../man3/OSSL_QUIC_client_thread_method.3ossl | 1 - .../share/man/man3/OSSL_SELF_TEST_free.3ossl | 1 - .../man3/OSSL_SELF_TEST_get_callback.3ossl | 1 - .../share/man/man3/OSSL_SELF_TEST_new.3ossl | 292 --- .../man/man3/OSSL_SELF_TEST_onbegin.3ossl | 1 - .../man3/OSSL_SELF_TEST_oncorrupt_byte.3ossl | 1 - .../share/man/man3/OSSL_SELF_TEST_onend.3ossl | 1 - .../man3/OSSL_SELF_TEST_set_callback.3ossl | 183 -- .../man/man3/OSSL_STACK_OF_X509_free.3ossl | 1 - .../share/man/man3/OSSL_STORE_CTX.3ossl | 1 - .../share/man/man3/OSSL_STORE_INFO.3ossl | 350 --- .../share/man/man3/OSSL_STORE_INFO_free.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get0_CERT.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get0_CRL.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get0_NAME.3ossl | 1 - ...SSL_STORE_INFO_get0_NAME_description.3ossl | 1 - .../man3/OSSL_STORE_INFO_get0_PARAMS.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get0_PKEY.3ossl | 1 - .../man3/OSSL_STORE_INFO_get0_PUBKEY.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get0_data.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get1_CERT.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get1_CRL.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get1_NAME.3ossl | 1 - ...SSL_STORE_INFO_get1_NAME_description.3ossl | 1 - .../man3/OSSL_STORE_INFO_get1_PARAMS.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get1_PKEY.3ossl | 1 - .../man3/OSSL_STORE_INFO_get1_PUBKEY.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_get_type.3ossl | 1 - .../share/man/man3/OSSL_STORE_INFO_new.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_new_CERT.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_new_CRL.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_new_NAME.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_new_PARAMS.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_new_PKEY.3ossl | 1 - .../man/man3/OSSL_STORE_INFO_new_PUBKEY.3ossl | 1 - ...SSL_STORE_INFO_set0_NAME_description.3ossl | 1 - .../man3/OSSL_STORE_INFO_type_string.3ossl | 1 - .../share/man/man3/OSSL_STORE_LOADER.3ossl | 507 ---- .../man/man3/OSSL_STORE_LOADER_CTX.3ossl | 1 - .../OSSL_STORE_LOADER_do_all_provided.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_fetch.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_free.3ossl | 1 - .../OSSL_STORE_LOADER_get0_description.3ossl | 1 - .../man3/OSSL_STORE_LOADER_get0_engine.3ossl | 1 - .../OSSL_STORE_LOADER_get0_properties.3ossl | 1 - .../OSSL_STORE_LOADER_get0_provider.3ossl | 1 - .../man3/OSSL_STORE_LOADER_get0_scheme.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_is_a.3ossl | 1 - .../man3/OSSL_STORE_LOADER_names_do_all.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_new.3ossl | 1 - .../man3/OSSL_STORE_LOADER_set_attach.3ossl | 1 - .../man3/OSSL_STORE_LOADER_set_close.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_set_ctrl.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_set_eof.3ossl | 1 - .../man3/OSSL_STORE_LOADER_set_error.3ossl | 1 - .../man3/OSSL_STORE_LOADER_set_expect.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_set_find.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_set_load.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_set_open.3ossl | 1 - .../man3/OSSL_STORE_LOADER_set_open_ex.3ossl | 1 - .../man/man3/OSSL_STORE_LOADER_up_ref.3ossl | 1 - .../share/man/man3/OSSL_STORE_SEARCH.3ossl | 313 --- .../man/man3/OSSL_STORE_SEARCH_by_alias.3ossl | 1 - .../OSSL_STORE_SEARCH_by_issuer_serial.3ossl | 1 - ...OSSL_STORE_SEARCH_by_key_fingerprint.3ossl | 1 - .../man/man3/OSSL_STORE_SEARCH_by_name.3ossl | 1 - .../man/man3/OSSL_STORE_SEARCH_free.3ossl | 1 - .../man3/OSSL_STORE_SEARCH_get0_bytes.3ossl | 1 - .../man3/OSSL_STORE_SEARCH_get0_digest.3ossl | 1 - .../man3/OSSL_STORE_SEARCH_get0_name.3ossl | 1 - .../man3/OSSL_STORE_SEARCH_get0_serial.3ossl | 1 - .../man3/OSSL_STORE_SEARCH_get0_string.3ossl | 1 - .../man/man3/OSSL_STORE_SEARCH_get_type.3ossl | 1 - .../share/man/man3/OSSL_STORE_attach.3ossl | 178 -- .../share/man/man3/OSSL_STORE_attach_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_close.3ossl | 1 - .../share/man/man3/OSSL_STORE_close_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_ctrl.3ossl | 1 - .../share/man/man3/OSSL_STORE_ctrl_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_delete.3ossl | 1 - .../share/man/man3/OSSL_STORE_eof.3ossl | 1 - .../share/man/man3/OSSL_STORE_eof_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_error.3ossl | 1 - .../share/man/man3/OSSL_STORE_error_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_expect.3ossl | 211 -- .../share/man/man3/OSSL_STORE_expect_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_find.3ossl | 1 - .../share/man/man3/OSSL_STORE_find_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_load.3ossl | 1 - .../share/man/man3/OSSL_STORE_load_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_open.3ossl | 317 --- .../share/man/man3/OSSL_STORE_open_ex.3ossl | 1 - .../man/man3/OSSL_STORE_open_ex_fn.3ossl | 1 - .../share/man/man3/OSSL_STORE_open_fn.3ossl | 1 - .../OSSL_STORE_post_process_info_fn.3ossl | 1 - .../man/man3/OSSL_STORE_register_loader.3ossl | 1 - .../man/man3/OSSL_STORE_supports_search.3ossl | 1 - .../man3/OSSL_STORE_unregister_loader.3ossl | 1 - .../OSSL_TARGETING_INFORMATION_free.3ossl | 1 - .../man3/OSSL_TARGETING_INFORMATION_it.3ossl | 1 - .../man3/OSSL_TARGETING_INFORMATION_new.3ossl | 1 - .../share/man/man3/OSSL_TARGETS_free.3ossl | 1 - .../share/man/man3/OSSL_TARGETS_it.3ossl | 1 - .../share/man/man3/OSSL_TARGETS_new.3ossl | 1 - .../man/man3/OSSL_TARGET_CERT_free.3ossl | 1 - .../share/man/man3/OSSL_TARGET_CERT_it.3ossl | 1 - .../share/man/man3/OSSL_TARGET_CERT_new.3ossl | 1 - .../share/man/man3/OSSL_TARGET_free.3ossl | 1 - .../share/man/man3/OSSL_TARGET_it.3ossl | 1 - .../share/man/man3/OSSL_TARGET_new.3ossl | 1 - ...SL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN.3ossl | 1 - ...OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL.3ossl | 1 - .../share/man/man3/OSSL_TRACE.3ossl | 1 - .../share/man/man3/OSSL_TRACE1.3ossl | 1 - .../share/man/man3/OSSL_TRACE2.3ossl | 1 - .../share/man/man3/OSSL_TRACE3.3ossl | 1 - .../share/man/man3/OSSL_TRACE4.3ossl | 1 - .../share/man/man3/OSSL_TRACE5.3ossl | 1 - .../share/man/man3/OSSL_TRACE6.3ossl | 1 - .../share/man/man3/OSSL_TRACE7.3ossl | 1 - .../share/man/man3/OSSL_TRACE8.3ossl | 1 - .../share/man/man3/OSSL_TRACE9.3ossl | 1 - .../share/man/man3/OSSL_TRACEV.3ossl | 1 - .../share/man/man3/OSSL_TRACE_BEGIN.3ossl | 1 - .../share/man/man3/OSSL_TRACE_CANCEL.3ossl | 1 - .../share/man/man3/OSSL_TRACE_ENABLED.3ossl | 1 - .../share/man/man3/OSSL_TRACE_END.3ossl | 1 - .../share/man/man3/OSSL_TRACE_STRING.3ossl | 1 - .../man/man3/OSSL_TRACE_STRING_MAX.3ossl | 1 - .../man3/OSSL_USER_NOTICE_SYNTAX_free.3ossl | 1 - .../man/man3/OSSL_USER_NOTICE_SYNTAX_it.3ossl | 1 - .../man3/OSSL_USER_NOTICE_SYNTAX_new.3ossl | 1 - .../man/man3/OSSL_default_cipher_list.3ossl | 1 - .../man/man3/OSSL_default_ciphersuites.3ossl | 1 - .../share/man/man3/OSSL_get_max_threads.3ossl | 1 - .../man3/OSSL_get_thread_support_flags.3ossl | 1 - .../share/man/man3/OSSL_parse_url.3ossl | 1 - .../share/man/man3/OSSL_set_max_threads.3ossl | 1 - .../share/man/man3/OSSL_sleep.3ossl | 174 -- .../share/man/man3/OSSL_trace_begin.3ossl | 1 - .../share/man/man3/OSSL_trace_cb.3ossl | 1 - .../share/man/man3/OSSL_trace_enabled.3ossl | 466 ---- .../share/man/man3/OSSL_trace_end.3ossl | 1 - .../man3/OSSL_trace_get_category_name.3ossl | 1 - .../man3/OSSL_trace_get_category_num.3ossl | 176 -- .../man/man3/OSSL_trace_set_callback.3ossl | 1 - .../man/man3/OSSL_trace_set_channel.3ossl | 449 ---- .../man/man3/OSSL_trace_set_prefix.3ossl | 1 - .../man/man3/OSSL_trace_set_suffix.3ossl | 1 - .../share/man/man3/OSSL_trace_string.3ossl | 1 - .../share/man/man3/OTHERNAME_free.3ossl | 1 - .../share/man/man3/OTHERNAME_new.3ossl | 1 - .../man/man3/OpenSSL_add_all_algorithms.3ossl | 196 -- .../man/man3/OpenSSL_add_all_ciphers.3ossl | 1 - .../man/man3/OpenSSL_add_all_digests.3ossl | 1 - .../man/man3/OpenSSL_add_ssl_algorithms.3ossl | 1 - .../share/man/man3/OpenSSL_version.3ossl | 364 --- .../share/man/man3/OpenSSL_version_num.3ossl | 1 - .../share/man/man3/PBE2PARAM_free.3ossl | 1 - .../share/man/man3/PBE2PARAM_new.3ossl | 1 - .../share/man/man3/PBEPARAM_free.3ossl | 1 - .../share/man/man3/PBEPARAM_new.3ossl | 1 - .../share/man/man3/PBKDF2PARAM_free.3ossl | 1 - .../share/man/man3/PBKDF2PARAM_new.3ossl | 1 - .../share/man/man3/PBMAC1PARAM_free.3ossl | 1 - .../share/man/man3/PBMAC1PARAM_it.3ossl | 1 - .../share/man/man3/PBMAC1PARAM_new.3ossl | 1 - .../man/man3/PBMAC1_get1_pbkdf2_param.3ossl | 176 -- .../man/man3/PEM_FLAG_EAY_COMPATIBLE.3ossl | 1 - .../share/man/man3/PEM_FLAG_ONLY_B64.3ossl | 1 - .../share/man/man3/PEM_FLAG_SECURE.3ossl | 1 - .../share/man/man3/PEM_X509_INFO_read.3ossl | 1 - .../man/man3/PEM_X509_INFO_read_bio.3ossl | 1 - .../man/man3/PEM_X509_INFO_read_bio_ex.3ossl | 214 -- .../man/man3/PEM_X509_INFO_read_ex.3ossl | 1 - .../share/man/man3/PEM_bytes_read_bio.3ossl | 216 -- .../man/man3/PEM_bytes_read_bio_secmem.3ossl | 1 - .../share/man/man3/PEM_do_header.3ossl | 1 - .../man/man3/PEM_get_EVP_CIPHER_INFO.3ossl | 1 - openssl-install/share/man/man3/PEM_read.3ossl | 265 -- .../share/man/man3/PEM_read_CMS.3ossl | 282 --- .../share/man/man3/PEM_read_DHparams.3ossl | 1 - .../man/man3/PEM_read_DSAPrivateKey.3ossl | 1 - .../share/man/man3/PEM_read_DSA_PUBKEY.3ossl | 1 - .../share/man/man3/PEM_read_DSAparams.3ossl | 1 - .../man/man3/PEM_read_ECPKParameters.3ossl | 1 - .../man/man3/PEM_read_ECPrivateKey.3ossl | 1 - .../share/man/man3/PEM_read_EC_PUBKEY.3ossl | 1 - .../PEM_read_NETSCAPE_CERT_SEQUENCE.3ossl | 1 - .../share/man/man3/PEM_read_PKCS7.3ossl | 1 - .../share/man/man3/PEM_read_PKCS8.3ossl | 1 - .../man3/PEM_read_PKCS8_PRIV_KEY_INFO.3ossl | 1 - .../share/man/man3/PEM_read_PUBKEY.3ossl | 1 - .../share/man/man3/PEM_read_PUBKEY_ex.3ossl | 1 - .../share/man/man3/PEM_read_PrivateKey.3ossl | 1 - .../man/man3/PEM_read_PrivateKey_ex.3ossl | 1 - .../man/man3/PEM_read_RSAPrivateKey.3ossl | 1 - .../man/man3/PEM_read_RSAPublicKey.3ossl | 1 - .../share/man/man3/PEM_read_RSA_PUBKEY.3ossl | 1 - .../share/man/man3/PEM_read_SSL_SESSION.3ossl | 1 - .../share/man/man3/PEM_read_X509.3ossl | 1 - .../share/man/man3/PEM_read_X509_ACERT.3ossl | 1 - .../share/man/man3/PEM_read_X509_AUX.3ossl | 1 - .../share/man/man3/PEM_read_X509_CRL.3ossl | 1 - .../share/man/man3/PEM_read_X509_PUBKEY.3ossl | 1 - .../share/man/man3/PEM_read_X509_REQ.3ossl | 1 - .../share/man/man3/PEM_read_bio.3ossl | 1 - .../share/man/man3/PEM_read_bio_CMS.3ossl | 1 - .../man/man3/PEM_read_bio_DHparams.3ossl | 1 - .../man/man3/PEM_read_bio_DSAPrivateKey.3ossl | 1 - .../man/man3/PEM_read_bio_DSA_PUBKEY.3ossl | 1 - .../man/man3/PEM_read_bio_DSAparams.3ossl | 1 - .../man3/PEM_read_bio_ECPKParameters.3ossl | 1 - .../man/man3/PEM_read_bio_EC_PUBKEY.3ossl | 1 - .../PEM_read_bio_NETSCAPE_CERT_SEQUENCE.3ossl | 1 - .../share/man/man3/PEM_read_bio_PKCS7.3ossl | 1 - .../share/man/man3/PEM_read_bio_PKCS8.3ossl | 1 - .../PEM_read_bio_PKCS8_PRIV_KEY_INFO.3ossl | 1 - .../share/man/man3/PEM_read_bio_PUBKEY.3ossl | 1 - .../man/man3/PEM_read_bio_PUBKEY_ex.3ossl | 1 - .../man/man3/PEM_read_bio_Parameters.3ossl | 1 - .../man/man3/PEM_read_bio_Parameters_ex.3ossl | 1 - .../man/man3/PEM_read_bio_PrivateKey.3ossl | 753 ------ .../man/man3/PEM_read_bio_PrivateKey_ex.3ossl | 1 - .../man/man3/PEM_read_bio_RSAPrivateKey.3ossl | 1 - .../man/man3/PEM_read_bio_RSAPublicKey.3ossl | 1 - .../man/man3/PEM_read_bio_RSA_PUBKEY.3ossl | 1 - .../man/man3/PEM_read_bio_SSL_SESSION.3ossl | 1 - .../share/man/man3/PEM_read_bio_X509.3ossl | 1 - .../man/man3/PEM_read_bio_X509_ACERT.3ossl | 1 - .../man/man3/PEM_read_bio_X509_AUX.3ossl | 1 - .../man/man3/PEM_read_bio_X509_CRL.3ossl | 1 - .../man/man3/PEM_read_bio_X509_PUBKEY.3ossl | 1 - .../man/man3/PEM_read_bio_X509_REQ.3ossl | 1 - .../share/man/man3/PEM_read_bio_ex.3ossl | 200 -- .../share/man/man3/PEM_write.3ossl | 1 - .../share/man/man3/PEM_write_CMS.3ossl | 1 - .../share/man/man3/PEM_write_DHparams.3ossl | 1 - .../share/man/man3/PEM_write_DHxparams.3ossl | 1 - .../man/man3/PEM_write_DSAPrivateKey.3ossl | 1 - .../share/man/man3/PEM_write_DSA_PUBKEY.3ossl | 1 - .../share/man/man3/PEM_write_DSAparams.3ossl | 1 - .../man/man3/PEM_write_ECPKParameters.3ossl | 1 - .../man/man3/PEM_write_ECPrivateKey.3ossl | 1 - .../share/man/man3/PEM_write_EC_PUBKEY.3ossl | 1 - .../PEM_write_NETSCAPE_CERT_SEQUENCE.3ossl | 1 - .../share/man/man3/PEM_write_PKCS7.3ossl | 1 - .../share/man/man3/PEM_write_PKCS8.3ossl | 1 - .../man/man3/PEM_write_PKCS8PrivateKey.3ossl | 1 - .../man3/PEM_write_PKCS8PrivateKey_nid.3ossl | 1 - .../man3/PEM_write_PKCS8_PRIV_KEY_INFO.3ossl | 1 - .../share/man/man3/PEM_write_PUBKEY.3ossl | 1 - .../share/man/man3/PEM_write_PUBKEY_ex.3ossl | 1 - .../share/man/man3/PEM_write_PrivateKey.3ossl | 1 - .../man/man3/PEM_write_PrivateKey_ex.3ossl | 1 - .../man/man3/PEM_write_RSAPrivateKey.3ossl | 1 - .../man/man3/PEM_write_RSAPublicKey.3ossl | 1 - .../share/man/man3/PEM_write_RSA_PUBKEY.3ossl | 1 - .../man/man3/PEM_write_SSL_SESSION.3ossl | 1 - .../share/man/man3/PEM_write_X509.3ossl | 1 - .../share/man/man3/PEM_write_X509_ACERT.3ossl | 1 - .../share/man/man3/PEM_write_X509_AUX.3ossl | 1 - .../share/man/man3/PEM_write_X509_CRL.3ossl | 1 - .../man/man3/PEM_write_X509_PUBKEY.3ossl | 1 - .../share/man/man3/PEM_write_X509_REQ.3ossl | 1 - .../man/man3/PEM_write_X509_REQ_NEW.3ossl | 1 - .../share/man/man3/PEM_write_bio.3ossl | 1 - .../share/man/man3/PEM_write_bio_CMS.3ossl | 1 - .../man/man3/PEM_write_bio_CMS_stream.3ossl | 180 -- .../man/man3/PEM_write_bio_DHparams.3ossl | 1 - .../man/man3/PEM_write_bio_DHxparams.3ossl | 1 - .../man3/PEM_write_bio_DSAPrivateKey.3ossl | 1 - .../man/man3/PEM_write_bio_DSA_PUBKEY.3ossl | 1 - .../man/man3/PEM_write_bio_DSAparams.3ossl | 1 - .../man3/PEM_write_bio_ECPKParameters.3ossl | 1 - .../man/man3/PEM_write_bio_ECPrivateKey.3ossl | 1 - .../man/man3/PEM_write_bio_EC_PUBKEY.3ossl | 1 - ...PEM_write_bio_NETSCAPE_CERT_SEQUENCE.3ossl | 1 - .../share/man/man3/PEM_write_bio_PKCS7.3ossl | 1 - .../man/man3/PEM_write_bio_PKCS7_stream.3ossl | 179 -- .../share/man/man3/PEM_write_bio_PKCS8.3ossl | 1 - .../man3/PEM_write_bio_PKCS8PrivateKey.3ossl | 1 - .../PEM_write_bio_PKCS8PrivateKey_nid.3ossl | 1 - .../PEM_write_bio_PKCS8_PRIV_KEY_INFO.3ossl | 1 - .../share/man/man3/PEM_write_bio_PUBKEY.3ossl | 1 - .../man/man3/PEM_write_bio_PUBKEY_ex.3ossl | 1 - .../man/man3/PEM_write_bio_Parameters.3ossl | 1 - .../man/man3/PEM_write_bio_PrivateKey.3ossl | 1 - .../man3/PEM_write_bio_PrivateKey_ex.3ossl | 1 - ...PEM_write_bio_PrivateKey_traditional.3ossl | 1 - .../man3/PEM_write_bio_RSAPrivateKey.3ossl | 1 - .../man/man3/PEM_write_bio_RSAPublicKey.3ossl | 1 - .../man/man3/PEM_write_bio_RSA_PUBKEY.3ossl | 1 - .../man/man3/PEM_write_bio_SSL_SESSION.3ossl | 1 - .../share/man/man3/PEM_write_bio_X509.3ossl | 1 - .../man/man3/PEM_write_bio_X509_ACERT.3ossl | 1 - .../man/man3/PEM_write_bio_X509_AUX.3ossl | 1 - .../man/man3/PEM_write_bio_X509_CRL.3ossl | 1 - .../man/man3/PEM_write_bio_X509_PUBKEY.3ossl | 1 - .../man/man3/PEM_write_bio_X509_REQ.3ossl | 1 - .../man/man3/PEM_write_bio_X509_REQ_NEW.3ossl | 1 - .../share/man/man3/PKCS12_BAGS_free.3ossl | 1 - .../share/man/man3/PKCS12_BAGS_new.3ossl | 1 - .../share/man/man3/PKCS12_MAC_DATA_free.3ossl | 1 - .../share/man/man3/PKCS12_MAC_DATA_new.3ossl | 1 - .../share/man/man3/PKCS12_PBE_keyivgen.3ossl | 237 -- .../man/man3/PKCS12_PBE_keyivgen_ex.3ossl | 1 - .../man3/PKCS12_SAFEBAG_create0_p8inf.3ossl | 1 - .../man3/PKCS12_SAFEBAG_create0_pkcs8.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_create_cert.3ossl | 229 -- .../man/man3/PKCS12_SAFEBAG_create_crl.3ossl | 1 - .../PKCS12_SAFEBAG_create_pkcs8_encrypt.3ossl | 1 - ...CS12_SAFEBAG_create_pkcs8_encrypt_ex.3ossl | 1 - .../man3/PKCS12_SAFEBAG_create_secret.3ossl | 1 - .../share/man/man3/PKCS12_SAFEBAG_free.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get0_attr.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get0_attrs.3ossl | 182 -- .../man3/PKCS12_SAFEBAG_get0_bag_obj.3ossl | 1 - .../man3/PKCS12_SAFEBAG_get0_bag_type.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get0_p8inf.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get0_pkcs8.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get0_safes.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get0_type.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get1_cert.3ossl | 220 -- .../man3/PKCS12_SAFEBAG_get1_cert_ex.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get1_crl.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get1_crl_ex.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get_bag_nid.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_get_nid.3ossl | 1 - .../share/man/man3/PKCS12_SAFEBAG_new.3ossl | 1 - .../man/man3/PKCS12_SAFEBAG_set0_attrs.3ossl | 165 -- .../man/man3/PKCS12_add1_attr_by_NID.3ossl | 183 -- .../man/man3/PKCS12_add1_attr_by_txt.3ossl | 1 - .../man/man3/PKCS12_add_CSPName_asc.3ossl | 168 -- .../share/man/man3/PKCS12_add_cert.3ossl | 210 -- .../man3/PKCS12_add_friendlyname_asc.3ossl | 184 -- .../man3/PKCS12_add_friendlyname_uni.3ossl | 1 - .../man3/PKCS12_add_friendlyname_utf8.3ossl | 1 - .../share/man/man3/PKCS12_add_key.3ossl | 1 - .../share/man/man3/PKCS12_add_key_ex.3ossl | 1 - .../man/man3/PKCS12_add_localkeyid.3ossl | 170 -- .../share/man/man3/PKCS12_add_safe.3ossl | 212 -- .../share/man/man3/PKCS12_add_safe_ex.3ossl | 1 - .../share/man/man3/PKCS12_add_safes.3ossl | 1 - .../share/man/man3/PKCS12_add_safes_ex.3ossl | 1 - .../share/man/man3/PKCS12_add_secret.3ossl | 1 - .../share/man/man3/PKCS12_create.3ossl | 266 -- .../share/man/man3/PKCS12_create_cb.3ossl | 1 - .../share/man/man3/PKCS12_create_ex.3ossl | 1 - .../share/man/man3/PKCS12_create_ex2.3ossl | 1 - .../share/man/man3/PKCS12_decrypt_skey.3ossl | 185 -- .../man/man3/PKCS12_decrypt_skey_ex.3ossl | 1 - .../share/man/man3/PKCS12_free.3ossl | 1 - .../share/man/man3/PKCS12_gen_mac.3ossl | 224 -- .../share/man/man3/PKCS12_get0_mac.3ossl | 1 - .../share/man/man3/PKCS12_get_attr_gen.3ossl | 1 - .../man/man3/PKCS12_get_friendlyname.3ossl | 171 -- .../share/man/man3/PKCS12_init.3ossl | 179 -- .../share/man/man3/PKCS12_init_ex.3ossl | 1 - .../man/man3/PKCS12_item_decrypt_d2i.3ossl | 204 -- .../man/man3/PKCS12_item_decrypt_d2i_ex.3ossl | 1 - .../man/man3/PKCS12_item_i2d_encrypt.3ossl | 1 - .../man/man3/PKCS12_item_i2d_encrypt_ex.3ossl | 1 - .../share/man/man3/PKCS12_key_gen_asc.3ossl | 1 - .../man/man3/PKCS12_key_gen_asc_ex.3ossl | 1 - .../share/man/man3/PKCS12_key_gen_uni.3ossl | 1 - .../man/man3/PKCS12_key_gen_uni_ex.3ossl | 1 - .../share/man/man3/PKCS12_key_gen_utf8.3ossl | 1 - .../man/man3/PKCS12_key_gen_utf8_ex.3ossl | 247 -- .../share/man/man3/PKCS12_new.3ossl | 1 - .../share/man/man3/PKCS12_newpass.3ossl | 244 -- .../man/man3/PKCS12_pack_p7encdata.3ossl | 189 -- .../man/man3/PKCS12_pack_p7encdata_ex.3ossl | 1 - .../share/man/man3/PKCS12_parse.3ossl | 207 -- .../share/man/man3/PKCS12_pbe_crypt.3ossl | 1 - .../share/man/man3/PKCS12_pbe_crypt_ex.3ossl | 1 - .../share/man/man3/PKCS12_set_mac.3ossl | 1 - .../man/man3/PKCS12_set_pbmac1_pbkdf2.3ossl | 1 - .../share/man/man3/PKCS12_setup_mac.3ossl | 1 - .../share/man/man3/PKCS12_verify_mac.3ossl | 1 - .../share/man/man3/PKCS5_PBE_keyivgen.3ossl | 315 --- .../man/man3/PKCS5_PBE_keyivgen_ex.3ossl | 1 - .../share/man/man3/PKCS5_PBKDF2_HMAC.3ossl | 208 -- .../man/man3/PKCS5_PBKDF2_HMAC_SHA1.3ossl | 1 - .../share/man/man3/PKCS5_pbe2_set.3ossl | 1 - .../share/man/man3/PKCS5_pbe2_set_iv.3ossl | 1 - .../share/man/man3/PKCS5_pbe2_set_iv_ex.3ossl | 1 - .../man/man3/PKCS5_pbe2_set_scrypt.3ossl | 1 - .../share/man/man3/PKCS5_pbe_set.3ossl | 1 - .../share/man/man3/PKCS5_pbe_set0_algor.3ossl | 1 - .../man/man3/PKCS5_pbe_set0_algor_ex.3ossl | 1 - .../share/man/man3/PKCS5_pbe_set_ex.3ossl | 1 - .../share/man/man3/PKCS5_pbkdf2_set.3ossl | 1 - .../share/man/man3/PKCS5_pbkdf2_set_ex.3ossl | 1 - .../man/man3/PKCS5_v2_PBE_keyivgen.3ossl | 1 - .../man/man3/PKCS5_v2_PBE_keyivgen_ex.3ossl | 1 - .../man/man3/PKCS5_v2_scrypt_keyivgen.3ossl | 1 - .../man3/PKCS5_v2_scrypt_keyivgen_ex.3ossl | 1 - .../share/man/man3/PKCS7_DIGEST_free.3ossl | 1 - .../share/man/man3/PKCS7_DIGEST_new.3ossl | 1 - .../share/man/man3/PKCS7_ENCRYPT_free.3ossl | 1 - .../share/man/man3/PKCS7_ENCRYPT_new.3ossl | 1 - .../man/man3/PKCS7_ENC_CONTENT_free.3ossl | 1 - .../man/man3/PKCS7_ENC_CONTENT_new.3ossl | 1 - .../share/man/man3/PKCS7_ENVELOPE_free.3ossl | 1 - .../share/man/man3/PKCS7_ENVELOPE_new.3ossl | 1 - .../man3/PKCS7_ISSUER_AND_SERIAL_digest.3ossl | 1 - .../man3/PKCS7_ISSUER_AND_SERIAL_free.3ossl | 1 - .../man3/PKCS7_ISSUER_AND_SERIAL_new.3ossl | 1 - .../man/man3/PKCS7_RECIP_INFO_free.3ossl | 1 - .../share/man/man3/PKCS7_RECIP_INFO_new.3ossl | 1 - .../share/man/man3/PKCS7_SIGNED_free.3ossl | 1 - .../share/man/man3/PKCS7_SIGNED_new.3ossl | 1 - .../man/man3/PKCS7_SIGNER_INFO_free.3ossl | 1 - .../man/man3/PKCS7_SIGNER_INFO_new.3ossl | 1 - .../man/man3/PKCS7_SIGN_ENVELOPE_free.3ossl | 1 - .../man/man3/PKCS7_SIGN_ENVELOPE_new.3ossl | 1 - .../man/man3/PKCS7_add_certificate.3ossl | 1 - .../share/man/man3/PKCS7_add_crl.3ossl | 1 - .../share/man/man3/PKCS7_decrypt.3ossl | 187 -- .../share/man/man3/PKCS7_dup.3ossl | 1 - .../share/man/man3/PKCS7_encrypt.3ossl | 227 -- .../share/man/man3/PKCS7_encrypt_ex.3ossl | 1 - .../share/man/man3/PKCS7_free.3ossl | 1 - .../share/man/man3/PKCS7_get0_signers.3ossl | 1 - .../man/man3/PKCS7_get_octet_string.3ossl | 171 -- .../share/man/man3/PKCS7_new.3ossl | 1 - .../share/man/man3/PKCS7_new_ex.3ossl | 1 - .../share/man/man3/PKCS7_print_ctx.3ossl | 1 - .../share/man/man3/PKCS7_sign.3ossl | 262 -- .../man/man3/PKCS7_sign_add_signer.3ossl | 239 -- .../share/man/man3/PKCS7_sign_ex.3ossl | 1 - .../share/man/man3/PKCS7_type_is_other.3ossl | 174 -- .../share/man/man3/PKCS7_verify.3ossl | 272 -- .../man/man3/PKCS8_PRIV_KEY_INFO_free.3ossl | 1 - .../man/man3/PKCS8_PRIV_KEY_INFO_new.3ossl | 1 - .../share/man/man3/PKCS8_decrypt.3ossl | 1 - .../share/man/man3/PKCS8_decrypt_ex.3ossl | 1 - .../share/man/man3/PKCS8_encrypt.3ossl | 208 -- .../share/man/man3/PKCS8_encrypt_ex.3ossl | 1 - .../share/man/man3/PKCS8_pkey_add1_attr.3ossl | 185 -- .../man3/PKCS8_pkey_add1_attr_by_NID.3ossl | 1 - .../man3/PKCS8_pkey_add1_attr_by_OBJ.3ossl | 1 - .../man/man3/PKCS8_pkey_get0_attrs.3ossl | 1 - .../share/man/man3/PKCS8_set0_pbe.3ossl | 1 - .../share/man/man3/PKCS8_set0_pbe_ex.3ossl | 1 - .../man/man3/PKEY_USAGE_PERIOD_free.3ossl | 1 - .../man/man3/PKEY_USAGE_PERIOD_new.3ossl | 1 - .../share/man/man3/POLICYINFO_free.3ossl | 1 - .../share/man/man3/POLICYINFO_new.3ossl | 1 - .../share/man/man3/POLICYQUALINFO_free.3ossl | 1 - .../share/man/man3/POLICYQUALINFO_new.3ossl | 1 - .../man/man3/POLICY_CONSTRAINTS_free.3ossl | 1 - .../man/man3/POLICY_CONSTRAINTS_new.3ossl | 1 - .../share/man/man3/POLICY_MAPPING_free.3ossl | 1 - .../share/man/man3/POLICY_MAPPING_new.3ossl | 1 - .../share/man/man3/PROFESSION_INFO.3ossl | 1 - .../share/man/man3/PROFESSION_INFOS.3ossl | 1 - .../man/man3/PROFESSION_INFOS_free.3ossl | 1 - .../share/man/man3/PROFESSION_INFOS_new.3ossl | 1 - .../share/man/man3/PROFESSION_INFO_free.3ossl | 1 - ...OFESSION_INFO_get0_addProfessionInfo.3ossl | 1 - ...PROFESSION_INFO_get0_namingAuthority.3ossl | 1 - ...PROFESSION_INFO_get0_professionItems.3ossl | 1 - .../PROFESSION_INFO_get0_professionOIDs.3ossl | 1 - ...FESSION_INFO_get0_registrationNumber.3ossl | 1 - .../share/man/man3/PROFESSION_INFO_new.3ossl | 1 - ...OFESSION_INFO_set0_addProfessionInfo.3ossl | 1 - ...PROFESSION_INFO_set0_namingAuthority.3ossl | 1 - ...PROFESSION_INFO_set0_professionItems.3ossl | 1 - .../PROFESSION_INFO_set0_professionOIDs.3ossl | 1 - ...FESSION_INFO_set0_registrationNumber.3ossl | 1 - .../man3/PROXY_CERT_INFO_EXTENSION_free.3ossl | 1 - .../man3/PROXY_CERT_INFO_EXTENSION_new.3ossl | 1 - .../share/man/man3/PROXY_POLICY_free.3ossl | 1 - .../share/man/man3/PROXY_POLICY_new.3ossl | 1 - .../share/man/man3/RAND_OpenSSL.3ossl | 1 - openssl-install/share/man/man3/RAND_add.3ossl | 244 -- .../share/man/man3/RAND_bytes.3ossl | 234 -- .../share/man/man3/RAND_bytes_ex.3ossl | 1 - .../share/man/man3/RAND_cleanup.3ossl | 179 -- openssl-install/share/man/man3/RAND_egd.3ossl | 193 -- .../share/man/man3/RAND_egd_bytes.3ossl | 1 - .../share/man/man3/RAND_event.3ossl | 1 - .../share/man/man3/RAND_file_name.3ossl | 1 - .../share/man/man3/RAND_get0_primary.3ossl | 225 -- .../share/man/man3/RAND_get0_private.3ossl | 1 - .../share/man/man3/RAND_get0_public.3ossl | 1 - .../share/man/man3/RAND_get_rand_method.3ossl | 1 - .../man3/RAND_keep_random_devices_open.3ossl | 1 - .../share/man/man3/RAND_load_file.3ossl | 218 -- .../share/man/man3/RAND_poll.3ossl | 1 - .../share/man/man3/RAND_priv_bytes.3ossl | 1 - .../share/man/man3/RAND_priv_bytes_ex.3ossl | 1 - .../share/man/man3/RAND_pseudo_bytes.3ossl | 1 - .../share/man/man3/RAND_query_egd_bytes.3ossl | 1 - .../share/man/man3/RAND_screen.3ossl | 1 - .../share/man/man3/RAND_seed.3ossl | 1 - .../share/man/man3/RAND_set0_private.3ossl | 1 - .../share/man/man3/RAND_set0_public.3ossl | 1 - .../share/man/man3/RAND_set_DRBG_type.3ossl | 203 -- .../share/man/man3/RAND_set_rand_method.3ossl | 220 -- .../man/man3/RAND_set_seed_source_type.3ossl | 1 - .../share/man/man3/RAND_status.3ossl | 1 - .../share/man/man3/RAND_write_file.3ossl | 1 - openssl-install/share/man/man3/RC4.3ossl | 1 - .../share/man/man3/RC4_set_key.3ossl | 210 -- .../share/man/man3/RIPEMD160.3ossl | 1 - .../share/man/man3/RIPEMD160_Final.3ossl | 1 - .../share/man/man3/RIPEMD160_Init.3ossl | 214 -- .../share/man/man3/RIPEMD160_Update.3ossl | 1 - .../share/man/man3/RSAPrivateKey_dup.3ossl | 1 - .../share/man/man3/RSAPublicKey_dup.3ossl | 1 - .../share/man/man3/RSA_OAEP_PARAMS_free.3ossl | 1 - .../share/man/man3/RSA_OAEP_PARAMS_new.3ossl | 1 - .../share/man/man3/RSA_PKCS1_OpenSSL.3ossl | 1 - .../share/man/man3/RSA_PSS_PARAMS_dup.3ossl | 1 - .../share/man/man3/RSA_PSS_PARAMS_free.3ossl | 1 - .../share/man/man3/RSA_PSS_PARAMS_new.3ossl | 1 - openssl-install/share/man/man3/RSA_bits.3ossl | 1 - .../share/man/man3/RSA_blinding_off.3ossl | 1 - .../share/man/man3/RSA_blinding_on.3ossl | 187 -- .../share/man/man3/RSA_check_key.3ossl | 225 -- .../share/man/man3/RSA_check_key_ex.3ossl | 1 - .../share/man/man3/RSA_clear_flags.3ossl | 1 - .../share/man/man3/RSA_flags.3ossl | 1 - openssl-install/share/man/man3/RSA_free.3ossl | 1 - .../share/man/man3/RSA_generate_key.3ossl | 251 -- .../share/man/man3/RSA_generate_key_ex.3ossl | 1 - .../man3/RSA_generate_multi_prime_key.3ossl | 1 - .../share/man/man3/RSA_get0_crt_params.3ossl | 1 - .../share/man/man3/RSA_get0_d.3ossl | 1 - .../share/man/man3/RSA_get0_dmp1.3ossl | 1 - .../share/man/man3/RSA_get0_dmq1.3ossl | 1 - .../share/man/man3/RSA_get0_e.3ossl | 1 - .../share/man/man3/RSA_get0_engine.3ossl | 1 - .../share/man/man3/RSA_get0_factors.3ossl | 1 - .../share/man/man3/RSA_get0_iqmp.3ossl | 1 - .../share/man/man3/RSA_get0_key.3ossl | 326 --- .../RSA_get0_multi_prime_crt_params.3ossl | 1 - .../man3/RSA_get0_multi_prime_factors.3ossl | 1 - .../share/man/man3/RSA_get0_n.3ossl | 1 - .../share/man/man3/RSA_get0_p.3ossl | 1 - .../share/man/man3/RSA_get0_pss_params.3ossl | 1 - .../share/man/man3/RSA_get0_q.3ossl | 1 - .../share/man/man3/RSA_get_app_data.3ossl | 1 - .../man/man3/RSA_get_default_method.3ossl | 1 - .../share/man/man3/RSA_get_ex_data.3ossl | 1 - .../share/man/man3/RSA_get_ex_new_index.3ossl | 1 - .../share/man/man3/RSA_get_method.3ossl | 1 - .../RSA_get_multi_prime_extra_count.3ossl | 1 - .../share/man/man3/RSA_get_version.3ossl | 1 - .../share/man/man3/RSA_meth_dup.3ossl | 1 - .../share/man/man3/RSA_meth_free.3ossl | 1 - .../man/man3/RSA_meth_get0_app_data.3ossl | 1 - .../share/man/man3/RSA_meth_get0_name.3ossl | 1 - .../man/man3/RSA_meth_get_bn_mod_exp.3ossl | 1 - .../share/man/man3/RSA_meth_get_finish.3ossl | 1 - .../share/man/man3/RSA_meth_get_flags.3ossl | 1 - .../share/man/man3/RSA_meth_get_init.3ossl | 1 - .../share/man/man3/RSA_meth_get_keygen.3ossl | 1 - .../share/man/man3/RSA_meth_get_mod_exp.3ossl | 1 - .../RSA_meth_get_multi_prime_keygen.3ossl | 1 - .../man/man3/RSA_meth_get_priv_dec.3ossl | 1 - .../man/man3/RSA_meth_get_priv_enc.3ossl | 1 - .../share/man/man3/RSA_meth_get_pub_dec.3ossl | 1 - .../share/man/man3/RSA_meth_get_pub_enc.3ossl | 1 - .../share/man/man3/RSA_meth_get_sign.3ossl | 1 - .../share/man/man3/RSA_meth_get_verify.3ossl | 1 - .../share/man/man3/RSA_meth_new.3ossl | 404 --- .../man/man3/RSA_meth_set0_app_data.3ossl | 1 - .../share/man/man3/RSA_meth_set1_name.3ossl | 1 - .../man/man3/RSA_meth_set_bn_mod_exp.3ossl | 1 - .../share/man/man3/RSA_meth_set_finish.3ossl | 1 - .../share/man/man3/RSA_meth_set_flags.3ossl | 1 - .../share/man/man3/RSA_meth_set_init.3ossl | 1 - .../share/man/man3/RSA_meth_set_keygen.3ossl | 1 - .../share/man/man3/RSA_meth_set_mod_exp.3ossl | 1 - .../RSA_meth_set_multi_prime_keygen.3ossl | 1 - .../man/man3/RSA_meth_set_priv_dec.3ossl | 1 - .../man/man3/RSA_meth_set_priv_enc.3ossl | 1 - .../share/man/man3/RSA_meth_set_pub_dec.3ossl | 1 - .../share/man/man3/RSA_meth_set_pub_enc.3ossl | 1 - .../share/man/man3/RSA_meth_set_sign.3ossl | 1 - .../share/man/man3/RSA_meth_set_verify.3ossl | 1 - openssl-install/share/man/man3/RSA_new.3ossl | 189 -- .../share/man/man3/RSA_new_method.3ossl | 1 - .../man/man3/RSA_padding_add_PKCS1_OAEP.3ossl | 1 - .../RSA_padding_add_PKCS1_OAEP_mgf1.3ossl | 1 - .../man3/RSA_padding_add_PKCS1_type_1.3ossl | 287 --- .../man3/RSA_padding_add_PKCS1_type_2.3ossl | 1 - .../share/man/man3/RSA_padding_add_none.3ossl | 1 - .../man3/RSA_padding_check_PKCS1_OAEP.3ossl | 1 - .../RSA_padding_check_PKCS1_OAEP_mgf1.3ossl | 1 - .../man3/RSA_padding_check_PKCS1_type_1.3ossl | 1 - .../man3/RSA_padding_check_PKCS1_type_2.3ossl | 1 - .../man/man3/RSA_padding_check_none.3ossl | 1 - .../share/man/man3/RSA_print.3ossl | 216 -- .../share/man/man3/RSA_print_fp.3ossl | 1 - .../share/man/man3/RSA_private_decrypt.3ossl | 1 - .../share/man/man3/RSA_private_encrypt.3ossl | 215 -- .../share/man/man3/RSA_public_decrypt.3ossl | 1 - .../share/man/man3/RSA_public_encrypt.3ossl | 255 -- .../share/man/man3/RSA_security_bits.3ossl | 1 - .../share/man/man3/RSA_set0_crt_params.3ossl | 1 - .../share/man/man3/RSA_set0_factors.3ossl | 1 - .../share/man/man3/RSA_set0_key.3ossl | 1 - .../man3/RSA_set0_multi_prime_params.3ossl | 1 - .../share/man/man3/RSA_set_app_data.3ossl | 1 - .../man/man3/RSA_set_default_method.3ossl | 1 - .../share/man/man3/RSA_set_ex_data.3ossl | 1 - .../share/man/man3/RSA_set_flags.3ossl | 1 - .../share/man/man3/RSA_set_method.3ossl | 328 --- openssl-install/share/man/man3/RSA_sign.3ossl | 209 -- .../man/man3/RSA_sign_ASN1_OCTET_STRING.3ossl | 210 -- openssl-install/share/man/man3/RSA_size.3ossl | 198 -- .../share/man/man3/RSA_test_flags.3ossl | 1 - .../share/man/man3/RSA_verify.3ossl | 1 - .../man3/RSA_verify_ASN1_OCTET_STRING.3ossl | 1 - .../share/man/man3/SCRYPT_PARAMS_free.3ossl | 1 - .../share/man/man3/SCRYPT_PARAMS_new.3ossl | 1 - .../share/man/man3/SCT_LIST_free.3ossl | 1 - .../share/man/man3/SCT_LIST_print.3ossl | 1 - .../share/man/man3/SCT_LIST_validate.3ossl | 1 - openssl-install/share/man/man3/SCT_free.3ossl | 1 - .../share/man/man3/SCT_get0_extensions.3ossl | 1 - .../share/man/man3/SCT_get0_log_id.3ossl | 1 - .../share/man/man3/SCT_get0_signature.3ossl | 1 - .../man/man3/SCT_get_log_entry_type.3ossl | 1 - .../man/man3/SCT_get_signature_nid.3ossl | 1 - .../share/man/man3/SCT_get_source.3ossl | 1 - .../share/man/man3/SCT_get_timestamp.3ossl | 1 - .../man/man3/SCT_get_validation_status.3ossl | 1 - .../share/man/man3/SCT_get_version.3ossl | 1 - openssl-install/share/man/man3/SCT_new.3ossl | 322 --- .../share/man/man3/SCT_new_from_base64.3ossl | 1 - .../share/man/man3/SCT_print.3ossl | 188 -- .../share/man/man3/SCT_set0_extensions.3ossl | 1 - .../share/man/man3/SCT_set0_log_id.3ossl | 1 - .../share/man/man3/SCT_set0_signature.3ossl | 1 - .../share/man/man3/SCT_set1_extensions.3ossl | 1 - .../share/man/man3/SCT_set1_log_id.3ossl | 1 - .../share/man/man3/SCT_set1_signature.3ossl | 1 - .../man/man3/SCT_set_log_entry_type.3ossl | 1 - .../man/man3/SCT_set_signature_nid.3ossl | 1 - .../share/man/man3/SCT_set_source.3ossl | 1 - .../share/man/man3/SCT_set_timestamp.3ossl | 1 - .../share/man/man3/SCT_set_version.3ossl | 1 - .../share/man/man3/SCT_validate.3ossl | 224 -- .../man3/SCT_validation_status_string.3ossl | 1 - openssl-install/share/man/man3/SHA1.3ossl | 1 - .../share/man/man3/SHA1_Final.3ossl | 1 - .../share/man/man3/SHA1_Init.3ossl | 1 - .../share/man/man3/SHA1_Update.3ossl | 1 - openssl-install/share/man/man3/SHA224.3ossl | 1 - .../share/man/man3/SHA224_Final.3ossl | 1 - .../share/man/man3/SHA224_Init.3ossl | 1 - .../share/man/man3/SHA224_Update.3ossl | 1 - openssl-install/share/man/man3/SHA256.3ossl | 1 - .../share/man/man3/SHA256_Final.3ossl | 1 - .../share/man/man3/SHA256_Init.3ossl | 249 -- .../share/man/man3/SHA256_Update.3ossl | 1 - openssl-install/share/man/man3/SHA384.3ossl | 1 - .../share/man/man3/SHA384_Final.3ossl | 1 - .../share/man/man3/SHA384_Init.3ossl | 1 - .../share/man/man3/SHA384_Update.3ossl | 1 - openssl-install/share/man/man3/SHA512.3ossl | 1 - .../share/man/man3/SHA512_Final.3ossl | 1 - .../share/man/man3/SHA512_Init.3ossl | 1 - .../share/man/man3/SHA512_Update.3ossl | 1 - .../share/man/man3/SMIME_read_ASN1.3ossl | 215 -- .../share/man/man3/SMIME_read_ASN1_ex.3ossl | 1 - .../share/man/man3/SMIME_read_CMS.3ossl | 223 -- .../share/man/man3/SMIME_read_CMS_ex.3ossl | 1 - .../share/man/man3/SMIME_read_PKCS7.3ossl | 219 -- .../share/man/man3/SMIME_read_PKCS7_ex.3ossl | 1 - .../share/man/man3/SMIME_write_ASN1.3ossl | 213 -- .../share/man/man3/SMIME_write_ASN1_ex.3ossl | 1 - .../share/man/man3/SMIME_write_CMS.3ossl | 199 -- .../share/man/man3/SMIME_write_PKCS7.3ossl | 200 -- .../share/man/man3/SRP_Calc_A.3ossl | 1 - .../share/man/man3/SRP_Calc_B.3ossl | 233 -- .../share/man/man3/SRP_Calc_B_ex.3ossl | 1 - .../share/man/man3/SRP_Calc_client_key.3ossl | 1 - .../man/man3/SRP_Calc_client_key_ex.3ossl | 1 - .../share/man/man3/SRP_Calc_server_key.3ossl | 1 - .../share/man/man3/SRP_Calc_u.3ossl | 1 - .../share/man/man3/SRP_Calc_u_ex.3ossl | 1 - .../share/man/man3/SRP_Calc_x.3ossl | 1 - .../share/man/man3/SRP_Calc_x_ex.3ossl | 1 - .../share/man/man3/SRP_VBASE_add0_user.3ossl | 1 - .../share/man/man3/SRP_VBASE_free.3ossl | 1 - .../man/man3/SRP_VBASE_get1_by_user.3ossl | 1 - .../man/man3/SRP_VBASE_get_by_user.3ossl | 1 - .../share/man/man3/SRP_VBASE_init.3ossl | 1 - .../share/man/man3/SRP_VBASE_new.3ossl | 241 -- .../man/man3/SRP_check_known_gN_param.3ossl | 1 - .../share/man/man3/SRP_create_verifier.3ossl | 273 -- .../man/man3/SRP_create_verifier_BN.3ossl | 1 - .../man/man3/SRP_create_verifier_BN_ex.3ossl | 1 - .../man/man3/SRP_create_verifier_ex.3ossl | 1 - .../share/man/man3/SRP_get_default_gN.3ossl | 1 - .../share/man/man3/SRP_user_pwd_free.3ossl | 1 - .../share/man/man3/SRP_user_pwd_new.3ossl | 210 -- .../share/man/man3/SRP_user_pwd_set0_sv.3ossl | 1 - .../man/man3/SRP_user_pwd_set1_ids.3ossl | 1 - .../share/man/man3/SRP_user_pwd_set_gN.3ossl | 1 - .../man/man3/SSL_ACCEPT_STREAM_NO_BLOCK.3ossl | 1 - .../man/man3/SSL_CIPHER_description.3ossl | 1 - .../share/man/man3/SSL_CIPHER_find.3ossl | 1 - .../man/man3/SSL_CIPHER_get_auth_nid.3ossl | 1 - .../share/man/man3/SSL_CIPHER_get_bits.3ossl | 1 - .../man/man3/SSL_CIPHER_get_cipher_nid.3ossl | 1 - .../man/man3/SSL_CIPHER_get_digest_nid.3ossl | 1 - .../SSL_CIPHER_get_handshake_digest.3ossl | 1 - .../share/man/man3/SSL_CIPHER_get_id.3ossl | 1 - .../man/man3/SSL_CIPHER_get_kx_nid.3ossl | 1 - .../share/man/man3/SSL_CIPHER_get_name.3ossl | 340 --- .../man/man3/SSL_CIPHER_get_protocol_id.3ossl | 1 - .../man/man3/SSL_CIPHER_get_version.3ossl | 1 - .../share/man/man3/SSL_CIPHER_is_aead.3ossl | 1 - .../man/man3/SSL_CIPHER_standard_name.3ossl | 1 - .../SSL_COMP_add_compression_method.3ossl | 243 -- .../SSL_COMP_free_compression_methods.3ossl | 1 - .../share/man/man3/SSL_COMP_get0_name.3ossl | 1 - .../SSL_COMP_get_compression_methods.3ossl | 1 - .../share/man/man3/SSL_COMP_get_id.3ossl | 1 - .../man/man3/SSL_CONF_CTX_clear_flags.3ossl | 1 - .../share/man/man3/SSL_CONF_CTX_finish.3ossl | 1 - .../share/man/man3/SSL_CONF_CTX_free.3ossl | 1 - .../share/man/man3/SSL_CONF_CTX_new.3ossl | 182 -- .../man/man3/SSL_CONF_CTX_set1_prefix.3ossl | 189 -- .../man/man3/SSL_CONF_CTX_set_flags.3ossl | 206 -- .../share/man/man3/SSL_CONF_CTX_set_ssl.3ossl | 1 - .../man/man3/SSL_CONF_CTX_set_ssl_ctx.3ossl | 195 -- .../share/man/man3/SSL_CONF_cmd.3ossl | 896 ------- .../share/man/man3/SSL_CONF_cmd_argv.3ossl | 183 -- .../man/man3/SSL_CONF_cmd_value_type.3ossl | 1 - .../man/man3/SSL_CONN_CLOSE_FLAG_LOCAL.3ossl | 1 - .../man3/SSL_CONN_CLOSE_FLAG_TRANSPORT.3ossl | 1 - .../man/man3/SSL_CTX_add0_chain_cert.3ossl | 1 - .../man/man3/SSL_CTX_add1_chain_cert.3ossl | 292 --- .../man/man3/SSL_CTX_add1_to_CA_list.3ossl | 1 - .../man/man3/SSL_CTX_add_client_CA.3ossl | 1 - .../man3/SSL_CTX_add_client_custom_ext.3ossl | 1 - .../man/man3/SSL_CTX_add_custom_ext.3ossl | 1 - .../man3/SSL_CTX_add_extra_chain_cert.3ossl | 224 -- .../man3/SSL_CTX_add_server_custom_ext.3ossl | 1 - .../share/man/man3/SSL_CTX_add_session.3ossl | 200 -- .../man/man3/SSL_CTX_build_cert_chain.3ossl | 1 - .../man/man3/SSL_CTX_callback_ctrl.3ossl | 1 - .../man/man3/SSL_CTX_check_private_key.3ossl | 1 - .../man/man3/SSL_CTX_clear_chain_certs.3ossl | 1 - .../SSL_CTX_clear_extra_chain_certs.3ossl | 1 - .../share/man/man3/SSL_CTX_clear_mode.3ossl | 1 - .../man/man3/SSL_CTX_clear_options.3ossl | 1 - .../man/man3/SSL_CTX_compress_certs.3ossl | 1 - .../share/man/man3/SSL_CTX_config.3ossl | 224 -- .../man/man3/SSL_CTX_ct_is_enabled.3ossl | 1 - .../share/man/man3/SSL_CTX_ctrl.3ossl | 175 -- .../man/man3/SSL_CTX_dane_clear_flags.3ossl | 1 - .../share/man/man3/SSL_CTX_dane_enable.3ossl | 517 ---- .../man/man3/SSL_CTX_dane_mtype_set.3ossl | 1 - .../man/man3/SSL_CTX_dane_set_flags.3ossl | 1 - .../SSL_CTX_decrypt_session_ticket_fn.3ossl | 1 - .../share/man/man3/SSL_CTX_disable_ct.3ossl | 1 - .../share/man/man3/SSL_CTX_enable_ct.3ossl | 1 - .../man/man3/SSL_CTX_flush_sessions.3ossl | 202 -- .../man/man3/SSL_CTX_flush_sessions_ex.3ossl | 1 - .../share/man/man3/SSL_CTX_free.3ossl | 182 -- .../SSL_CTX_generate_session_ticket_fn.3ossl | 1 - .../share/man/man3/SSL_CTX_get0_CA_list.3ossl | 1 - .../man3/SSL_CTX_get0_chain_cert_store.3ossl | 1 - .../man/man3/SSL_CTX_get0_chain_certs.3ossl | 1 - .../man3/SSL_CTX_get0_client_cert_type.3ossl | 1 - .../share/man/man3/SSL_CTX_get0_param.3ossl | 212 -- .../man3/SSL_CTX_get0_security_ex_data.3ossl | 1 - .../man3/SSL_CTX_get0_server_cert_type.3ossl | 1 - .../man3/SSL_CTX_get0_verify_cert_store.3ossl | 1 - .../man3/SSL_CTX_get1_compressed_cert.3ossl | 1 - .../share/man/man3/SSL_CTX_get_app_data.3ossl | 1 - .../man/man3/SSL_CTX_get_cert_store.3ossl | 1 - .../share/man/man3/SSL_CTX_get_ciphers.3ossl | 1 - .../man/man3/SSL_CTX_get_client_CA_list.3ossl | 1 - .../man/man3/SSL_CTX_get_client_cert_cb.3ossl | 1 - .../man3/SSL_CTX_get_default_passwd_cb.3ossl | 1 - ...L_CTX_get_default_passwd_cb_userdata.3ossl | 1 - .../man3/SSL_CTX_get_default_read_ahead.3ossl | 1 - .../share/man/man3/SSL_CTX_get_ex_data.3ossl | 1 - .../man/man3/SSL_CTX_get_ex_new_index.3ossl | 1 - .../man3/SSL_CTX_get_extra_chain_certs.3ossl | 1 - .../SSL_CTX_get_extra_chain_certs_only.3ossl | 1 - .../man/man3/SSL_CTX_get_info_callback.3ossl | 1 - .../man3/SSL_CTX_get_keylog_callback.3ossl | 1 - .../man/man3/SSL_CTX_get_max_cert_list.3ossl | 1 - .../man/man3/SSL_CTX_get_max_early_data.3ossl | 1 - .../man3/SSL_CTX_get_max_proto_version.3ossl | 1 - .../man3/SSL_CTX_get_min_proto_version.3ossl | 1 - .../share/man/man3/SSL_CTX_get_mode.3ossl | 1 - .../man/man3/SSL_CTX_get_num_tickets.3ossl | 1 - .../share/man/man3/SSL_CTX_get_options.3ossl | 1 - .../man/man3/SSL_CTX_get_quiet_shutdown.3ossl | 1 - .../man/man3/SSL_CTX_get_read_ahead.3ossl | 1 - ..._CTX_get_record_padding_callback_arg.3ossl | 1 - .../SSL_CTX_get_recv_max_early_data.3ossl | 1 - .../man3/SSL_CTX_get_security_callback.3ossl | 1 - .../man/man3/SSL_CTX_get_security_level.3ossl | 1 - .../man3/SSL_CTX_get_session_cache_mode.3ossl | 1 - .../man/man3/SSL_CTX_get_ssl_method.3ossl | 1 - .../share/man/man3/SSL_CTX_get_timeout.3ossl | 1 - .../man3/SSL_CTX_get_tlsext_status_arg.3ossl | 1 - .../man3/SSL_CTX_get_tlsext_status_cb.3ossl | 1 - .../man3/SSL_CTX_get_tlsext_status_type.3ossl | 1 - .../man3/SSL_CTX_get_verify_callback.3ossl | 1 - .../man/man3/SSL_CTX_get_verify_depth.3ossl | 1 - .../man/man3/SSL_CTX_get_verify_mode.3ossl | 191 -- .../man3/SSL_CTX_has_client_custom_ext.3ossl | 169 -- .../man/man3/SSL_CTX_keylog_cb_func.3ossl | 1 - .../man/man3/SSL_CTX_load_verify_dir.3ossl | 1 - .../man/man3/SSL_CTX_load_verify_file.3ossl | 1 - .../man3/SSL_CTX_load_verify_locations.3ossl | 309 --- .../man/man3/SSL_CTX_load_verify_store.3ossl | 1 - .../share/man/man3/SSL_CTX_new.3ossl | 372 --- .../share/man/man3/SSL_CTX_new_ex.3ossl | 1 - .../man/man3/SSL_CTX_remove_session.3ossl | 1 - .../man3/SSL_CTX_select_current_cert.3ossl | 1 - .../share/man/man3/SSL_CTX_sess_accept.3ossl | 1 - .../man/man3/SSL_CTX_sess_accept_good.3ossl | 1 - .../SSL_CTX_sess_accept_renegotiate.3ossl | 1 - .../man/man3/SSL_CTX_sess_cache_full.3ossl | 1 - .../share/man/man3/SSL_CTX_sess_cb_hits.3ossl | 1 - .../share/man/man3/SSL_CTX_sess_connect.3ossl | 1 - .../man/man3/SSL_CTX_sess_connect_good.3ossl | 1 - .../SSL_CTX_sess_connect_renegotiate.3ossl | 1 - .../man3/SSL_CTX_sess_get_cache_size.3ossl | 1 - .../man/man3/SSL_CTX_sess_get_get_cb.3ossl | 1 - .../man/man3/SSL_CTX_sess_get_new_cb.3ossl | 1 - .../man/man3/SSL_CTX_sess_get_remove_cb.3ossl | 1 - .../share/man/man3/SSL_CTX_sess_hits.3ossl | 1 - .../share/man/man3/SSL_CTX_sess_misses.3ossl | 1 - .../share/man/man3/SSL_CTX_sess_number.3ossl | 217 -- .../man3/SSL_CTX_sess_set_cache_size.3ossl | 193 -- .../man/man3/SSL_CTX_sess_set_get_cb.3ossl | 254 -- .../man/man3/SSL_CTX_sess_set_new_cb.3ossl | 1 - .../man/man3/SSL_CTX_sess_set_remove_cb.3ossl | 1 - .../man/man3/SSL_CTX_sess_timeouts.3ossl | 1 - .../share/man/man3/SSL_CTX_sessions.3ossl | 178 -- .../share/man/man3/SSL_CTX_set0_CA_list.3ossl | 320 --- .../share/man/man3/SSL_CTX_set0_chain.3ossl | 1 - .../man3/SSL_CTX_set0_chain_cert_store.3ossl | 1 - .../man3/SSL_CTX_set0_security_ex_data.3ossl | 1 - .../man/man3/SSL_CTX_set0_tmp_dh_pkey.3ossl | 1 - .../man3/SSL_CTX_set0_verify_cert_store.3ossl | 1 - .../SSL_CTX_set1_cert_comp_preference.3ossl | 281 --- .../man/man3/SSL_CTX_set1_cert_store.3ossl | 1 - .../share/man/man3/SSL_CTX_set1_chain.3ossl | 1 - .../man3/SSL_CTX_set1_chain_cert_store.3ossl | 1 - .../man3/SSL_CTX_set1_client_cert_type.3ossl | 1 - .../man3/SSL_CTX_set1_client_sigalgs.3ossl | 1 - .../SSL_CTX_set1_client_sigalgs_list.3ossl | 1 - .../man3/SSL_CTX_set1_compressed_cert.3ossl | 1 - .../share/man/man3/SSL_CTX_set1_curves.3ossl | 304 --- .../man/man3/SSL_CTX_set1_curves_list.3ossl | 1 - .../share/man/man3/SSL_CTX_set1_groups.3ossl | 1 - .../man/man3/SSL_CTX_set1_groups_list.3ossl | 1 - .../share/man/man3/SSL_CTX_set1_param.3ossl | 1 - .../man3/SSL_CTX_set1_server_cert_type.3ossl | 1 - .../share/man/man3/SSL_CTX_set1_sigalgs.3ossl | 259 -- .../man/man3/SSL_CTX_set1_sigalgs_list.3ossl | 1 - .../man3/SSL_CTX_set1_verify_cert_store.3ossl | 245 -- .../SSL_CTX_set_allow_early_data_cb.3ossl | 1 - .../man/man3/SSL_CTX_set_alpn_protos.3ossl | 1 - .../man/man3/SSL_CTX_set_alpn_select_cb.3ossl | 332 --- .../share/man/man3/SSL_CTX_set_app_data.3ossl | 1 - .../man/man3/SSL_CTX_set_async_callback.3ossl | 1 - .../man3/SSL_CTX_set_async_callback_arg.3ossl | 1 - .../man/man3/SSL_CTX_set_block_padding.3ossl | 1 - .../man3/SSL_CTX_set_block_padding_ex.3ossl | 1 - .../share/man/man3/SSL_CTX_set_cert_cb.3ossl | 211 -- .../man/man3/SSL_CTX_set_cert_store.3ossl | 221 -- .../SSL_CTX_set_cert_verify_callback.3ossl | 235 -- .../man/man3/SSL_CTX_set_cipher_list.3ossl | 261 -- .../man/man3/SSL_CTX_set_ciphersuites.3ossl | 1 - .../man/man3/SSL_CTX_set_client_CA_list.3ossl | 1 - .../man/man3/SSL_CTX_set_client_cert_cb.3ossl | 240 -- .../man3/SSL_CTX_set_client_hello_cb.3ossl | 281 --- .../man3/SSL_CTX_set_cookie_generate_cb.3ossl | 1 - .../man3/SSL_CTX_set_cookie_verify_cb.3ossl | 1 - .../SSL_CTX_set_ct_validation_callback.3ossl | 275 --- .../man3/SSL_CTX_set_ctlog_list_file.3ossl | 184 -- .../man/man3/SSL_CTX_set_current_cert.3ossl | 1 - .../SSL_CTX_set_default_ctlog_list_file.3ossl | 1 - .../man3/SSL_CTX_set_default_passwd_cb.3ossl | 244 -- ...L_CTX_set_default_passwd_cb_userdata.3ossl | 1 - .../SSL_CTX_set_default_read_buffer_len.3ossl | 1 - .../man3/SSL_CTX_set_default_verify_dir.3ossl | 1 - .../SSL_CTX_set_default_verify_file.3ossl | 1 - .../SSL_CTX_set_default_verify_paths.3ossl | 1 - .../SSL_CTX_set_default_verify_store.3ossl | 1 - .../share/man/man3/SSL_CTX_set_dh_auto.3ossl | 1 - .../man/man3/SSL_CTX_set_ecdh_auto.3ossl | 1 - .../share/man/man3/SSL_CTX_set_ex_data.3ossl | 1 - .../SSL_CTX_set_generate_session_id.3ossl | 269 -- .../man/man3/SSL_CTX_set_info_callback.3ossl | 293 --- .../man3/SSL_CTX_set_keylog_callback.3ossl | 184 -- .../man/man3/SSL_CTX_set_max_cert_list.3ossl | 213 -- .../man/man3/SSL_CTX_set_max_early_data.3ossl | 1 - .../man/man3/SSL_CTX_set_max_pipelines.3ossl | 1 - .../man3/SSL_CTX_set_max_proto_version.3ossl | 1 - .../man3/SSL_CTX_set_max_send_fragment.3ossl | 1 - .../man3/SSL_CTX_set_min_proto_version.3ossl | 208 -- .../share/man/man3/SSL_CTX_set_mode.3ossl | 269 -- .../man/man3/SSL_CTX_set_msg_callback.3ossl | 300 --- .../man3/SSL_CTX_set_msg_callback_arg.3ossl | 1 - .../SSL_CTX_set_next_proto_select_cb.3ossl | 1 - ...SL_CTX_set_next_protos_advertised_cb.3ossl | 1 - .../man/man3/SSL_CTX_set_num_tickets.3ossl | 227 -- .../share/man/man3/SSL_CTX_set_options.3ossl | 627 ----- .../SSL_CTX_set_post_handshake_auth.3ossl | 1 - .../SSL_CTX_set_psk_client_callback.3ossl | 301 --- ...SL_CTX_set_psk_find_session_callback.3ossl | 1 - .../SSL_CTX_set_psk_server_callback.3ossl | 1 - ...SSL_CTX_set_psk_use_session_callback.3ossl | 1 - .../share/man/man3/SSL_CTX_set_purpose.3ossl | 1 - .../man/man3/SSL_CTX_set_quiet_shutdown.3ossl | 207 -- .../man/man3/SSL_CTX_set_read_ahead.3ossl | 208 -- .../SSL_CTX_set_record_padding_callback.3ossl | 249 -- ..._CTX_set_record_padding_callback_arg.3ossl | 1 - .../SSL_CTX_set_recv_max_early_data.3ossl | 1 - .../man3/SSL_CTX_set_security_callback.3ossl | 1 - .../man/man3/SSL_CTX_set_security_level.3ossl | 307 --- .../man3/SSL_CTX_set_session_cache_mode.3ossl | 263 -- .../man3/SSL_CTX_set_session_id_context.3ossl | 215 -- .../man3/SSL_CTX_set_session_ticket_cb.3ossl | 305 --- .../SSL_CTX_set_split_send_fragment.3ossl | 318 --- .../man/man3/SSL_CTX_set_srp_cb_arg.3ossl | 1 - .../SSL_CTX_set_srp_client_pwd_callback.3ossl | 1 - .../man/man3/SSL_CTX_set_srp_password.3ossl | 360 --- .../man/man3/SSL_CTX_set_srp_strength.3ossl | 1 - .../man/man3/SSL_CTX_set_srp_username.3ossl | 1 - .../SSL_CTX_set_srp_username_callback.3ossl | 1 - ...SL_CTX_set_srp_verify_param_callback.3ossl | 1 - .../man/man3/SSL_CTX_set_ssl_version.3ossl | 216 -- ...CTX_set_stateless_cookie_generate_cb.3ossl | 227 -- ...L_CTX_set_stateless_cookie_verify_cb.3ossl | 1 - .../share/man/man3/SSL_CTX_set_timeout.3ossl | 209 -- ...L_CTX_set_tlsext_max_fragment_length.3ossl | 1 - .../SSL_CTX_set_tlsext_servername_arg.3ossl | 1 - ...L_CTX_set_tlsext_servername_callback.3ossl | 287 --- .../man3/SSL_CTX_set_tlsext_status_arg.3ossl | 1 - .../man3/SSL_CTX_set_tlsext_status_cb.3ossl | 258 -- .../man3/SSL_CTX_set_tlsext_status_type.3ossl | 1 - .../SSL_CTX_set_tlsext_ticket_key_cb.3ossl | 375 --- ...SSL_CTX_set_tlsext_ticket_key_evp_cb.3ossl | 1 - .../man3/SSL_CTX_set_tlsext_use_srtp.3ossl | 264 -- .../share/man/man3/SSL_CTX_set_tmp_dh.3ossl | 1 - .../man3/SSL_CTX_set_tmp_dh_callback.3ossl | 256 -- .../share/man/man3/SSL_CTX_set_tmp_ecdh.3ossl | 182 -- .../share/man/man3/SSL_CTX_set_trust.3ossl | 1 - .../share/man/man3/SSL_CTX_set_verify.3ossl | 500 ---- .../man/man3/SSL_CTX_set_verify_depth.3ossl | 1 - .../share/man/man3/SSL_CTX_up_ref.3ossl | 1 - .../man/man3/SSL_CTX_use_PrivateKey.3ossl | 1 - .../man3/SSL_CTX_use_PrivateKey_ASN1.3ossl | 1 - .../man3/SSL_CTX_use_PrivateKey_file.3ossl | 1 - .../man/man3/SSL_CTX_use_RSAPrivateKey.3ossl | 1 - .../man3/SSL_CTX_use_RSAPrivateKey_ASN1.3ossl | 1 - .../man3/SSL_CTX_use_RSAPrivateKey_file.3ossl | 1 - .../man/man3/SSL_CTX_use_cert_and_key.3ossl | 1 - .../man/man3/SSL_CTX_use_certificate.3ossl | 337 --- .../man3/SSL_CTX_use_certificate_ASN1.3ossl | 1 - .../SSL_CTX_use_certificate_chain_file.3ossl | 1 - .../man3/SSL_CTX_use_certificate_file.3ossl | 1 - .../man3/SSL_CTX_use_psk_identity_hint.3ossl | 279 --- .../man/man3/SSL_CTX_use_serverinfo.3ossl | 221 -- .../man/man3/SSL_CTX_use_serverinfo_ex.3ossl | 1 - .../man3/SSL_CTX_use_serverinfo_file.3ossl | 1 - .../SSL_DEFAULT_STREAM_MODE_AUTO_BIDI.3ossl | 1 - .../SSL_DEFAULT_STREAM_MODE_AUTO_UNI.3ossl | 1 - .../man3/SSL_DEFAULT_STREAM_MODE_NONE.3ossl | 1 - .../SSL_INCOMING_STREAM_POLICY_ACCEPT.3ossl | 1 - .../SSL_INCOMING_STREAM_POLICY_AUTO.3ossl | 1 - .../SSL_INCOMING_STREAM_POLICY_REJECT.3ossl | 1 - .../share/man/man3/SSL_OP_BIT.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_E.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_EC.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_ECD.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_ER.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_EW.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_F.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_I.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_IS.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_ISB.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_ISE.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_ISU.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_NONE.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_OS.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_OSB.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_OSE.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_OSU.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_R.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_RE.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_RW.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_RWE.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_W.3ossl | 1 - .../share/man/man3/SSL_POLL_EVENT_WE.3ossl | 1 - .../man3/SSL_POLL_FLAG_NO_HANDLE_EVENTS.3ossl | 1 - .../share/man/man3/SSL_SESSION_dup.3ossl | 1 - .../share/man/man3/SSL_SESSION_free.3ossl | 219 -- .../man3/SSL_SESSION_get0_alpn_selected.3ossl | 1 - .../man/man3/SSL_SESSION_get0_cipher.3ossl | 189 -- .../man/man3/SSL_SESSION_get0_hostname.3ossl | 206 -- .../man3/SSL_SESSION_get0_id_context.3ossl | 187 -- .../man/man3/SSL_SESSION_get0_peer.3ossl | 170 -- .../man/man3/SSL_SESSION_get0_peer_rpk.3ossl | 1 - .../man/man3/SSL_SESSION_get0_ticket.3ossl | 1 - .../SSL_SESSION_get0_ticket_appdata.3ossl | 1 - .../man/man3/SSL_SESSION_get_app_data.3ossl | 1 - .../man3/SSL_SESSION_get_compress_id.3ossl | 171 -- .../man/man3/SSL_SESSION_get_ex_data.3ossl | 1 - .../man3/SSL_SESSION_get_ex_new_index.3ossl | 1 - .../share/man/man3/SSL_SESSION_get_id.3ossl | 1 - .../man/man3/SSL_SESSION_get_master_key.3ossl | 1 - .../man3/SSL_SESSION_get_max_early_data.3ossl | 1 - .../SSL_SESSION_get_max_fragment_length.3ossl | 1 - .../SSL_SESSION_get_protocol_version.3ossl | 187 -- ...SSL_SESSION_get_ticket_lifetime_hint.3ossl | 1 - .../share/man/man3/SSL_SESSION_get_time.3ossl | 233 -- .../man/man3/SSL_SESSION_get_time_ex.3ossl | 1 - .../man/man3/SSL_SESSION_get_timeout.3ossl | 1 - .../man/man3/SSL_SESSION_has_ticket.3ossl | 190 -- .../man/man3/SSL_SESSION_is_resumable.3ossl | 175 -- .../share/man/man3/SSL_SESSION_new.3ossl | 1 - .../share/man/man3/SSL_SESSION_print.3ossl | 179 -- .../share/man/man3/SSL_SESSION_print_fp.3ossl | 1 - .../man/man3/SSL_SESSION_print_keylog.3ossl | 1 - .../man3/SSL_SESSION_set1_alpn_selected.3ossl | 1 - .../man/man3/SSL_SESSION_set1_hostname.3ossl | 1 - .../share/man/man3/SSL_SESSION_set1_id.3ossl | 181 -- .../man3/SSL_SESSION_set1_id_context.3ossl | 1 - .../man3/SSL_SESSION_set1_master_key.3ossl | 1 - .../SSL_SESSION_set1_ticket_appdata.3ossl | 1 - .../man/man3/SSL_SESSION_set_app_data.3ossl | 1 - .../man/man3/SSL_SESSION_set_cipher.3ossl | 1 - .../man/man3/SSL_SESSION_set_ex_data.3ossl | 1 - .../man3/SSL_SESSION_set_max_early_data.3ossl | 1 - .../SSL_SESSION_set_protocol_version.3ossl | 1 - .../share/man/man3/SSL_SESSION_set_time.3ossl | 1 - .../man/man3/SSL_SESSION_set_time_ex.3ossl | 1 - .../man/man3/SSL_SESSION_set_timeout.3ossl | 1 - .../share/man/man3/SSL_SESSION_up_ref.3ossl | 1 - .../man/man3/SSL_STREAM_FLAG_ADVANCE.3ossl | 1 - .../man/man3/SSL_STREAM_FLAG_NO_BLOCK.3ossl | 1 - .../share/man/man3/SSL_STREAM_FLAG_UNI.3ossl | 1 - .../man3/SSL_STREAM_STATE_CONN_CLOSED.3ossl | 1 - .../man/man3/SSL_STREAM_STATE_FINISHED.3ossl | 1 - .../man/man3/SSL_STREAM_STATE_NONE.3ossl | 1 - .../share/man/man3/SSL_STREAM_STATE_OK.3ossl | 1 - .../man3/SSL_STREAM_STATE_RESET_LOCAL.3ossl | 1 - .../man3/SSL_STREAM_STATE_RESET_REMOTE.3ossl | 1 - .../man/man3/SSL_STREAM_STATE_WRONG_DIR.3ossl | 1 - .../share/man/man3/SSL_STREAM_TYPE_BIDI.3ossl | 1 - .../share/man/man3/SSL_STREAM_TYPE_NONE.3ossl | 1 - .../share/man/man3/SSL_STREAM_TYPE_READ.3ossl | 1 - .../man/man3/SSL_STREAM_TYPE_WRITE.3ossl | 1 - .../SSL_VALUE_CLASS_FEATURE_NEGOTIATED.3ossl | 1 - ...SSL_VALUE_CLASS_FEATURE_PEER_REQUEST.3ossl | 1 - .../SSL_VALUE_CLASS_FEATURE_REQUEST.3ossl | 1 - .../man/man3/SSL_VALUE_CLASS_GENERIC.3ossl | 1 - .../man3/SSL_VALUE_EVENT_HANDLING_MODE.3ossl | 1 - ...L_VALUE_EVENT_HANDLING_MODE_EXPLICIT.3ossl | 1 - ...L_VALUE_EVENT_HANDLING_MODE_IMPLICIT.3ossl | 1 - ...SL_VALUE_EVENT_HANDLING_MODE_INHERIT.3ossl | 1 - .../man3/SSL_VALUE_QUIC_IDLE_TIMEOUT.3ossl | 1 - ...L_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL.3ossl | 1 - ..._VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL.3ossl | 1 - ...SL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL.3ossl | 1 - ...L_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL.3ossl | 1 - .../SSL_VALUE_STREAM_WRITE_BUF_AVAIL.3ossl | 1 - .../SSL_VALUE_STREAM_WRITE_BUF_SIZE.3ossl | 1 - .../SSL_VALUE_STREAM_WRITE_BUF_USED.3ossl | 1 - .../man/man3/SSL_WRITE_FLAG_CONCLUDE.3ossl | 1 - .../share/man/man3/SSL_accept.3ossl | 205 -- .../share/man/man3/SSL_accept_stream.3ossl | 212 -- .../share/man/man3/SSL_add0_chain_cert.3ossl | 1 - .../share/man/man3/SSL_add1_chain_cert.3ossl | 1 - .../share/man/man3/SSL_add1_host.3ossl | 1 - .../share/man/man3/SSL_add1_to_CA_list.3ossl | 1 - .../share/man/man3/SSL_add_client_CA.3ossl | 1 - .../SSL_add_dir_cert_subjects_to_stack.3ossl | 1 - .../share/man/man3/SSL_add_expected_rpk.3ossl | 1 - .../SSL_add_file_cert_subjects_to_stack.3ossl | 1 - ...SSL_add_store_cert_subjects_to_stack.3ossl | 1 - .../man/man3/SSL_alert_desc_string.3ossl | 1 - .../man/man3/SSL_alert_desc_string_long.3ossl | 1 - .../man/man3/SSL_alert_type_string.3ossl | 369 --- .../man/man3/SSL_alert_type_string_long.3ossl | 1 - .../share/man/man3/SSL_alloc_buffers.3ossl | 197 -- .../man/man3/SSL_allow_early_data_cb_fn.3ossl | 1 - .../man/man3/SSL_async_callback_fn.3ossl | 1 - .../share/man/man3/SSL_build_cert_chain.3ossl | 1 - .../man/man3/SSL_bytes_to_cipher_list.3ossl | 1 - .../share/man/man3/SSL_callback_ctrl.3ossl | 1 - .../share/man/man3/SSL_check_chain.3ossl | 225 -- .../man/man3/SSL_check_private_key.3ossl | 1 - .../share/man/man3/SSL_clear.3ossl | 211 -- .../man/man3/SSL_clear_chain_certs.3ossl | 1 - .../share/man/man3/SSL_clear_mode.3ossl | 1 - .../share/man/man3/SSL_clear_options.3ossl | 1 - .../man/man3/SSL_client_hello_cb_fn.3ossl | 1 - .../man3/SSL_client_hello_get0_ciphers.3ossl | 1 - ...lient_hello_get0_compression_methods.3ossl | 1 - .../man/man3/SSL_client_hello_get0_ext.3ossl | 1 - ...SSL_client_hello_get0_legacy_version.3ossl | 1 - .../man3/SSL_client_hello_get0_random.3ossl | 1 - .../SSL_client_hello_get0_session_id.3ossl | 1 - ...client_hello_get1_extensions_present.3ossl | 1 - ...SSL_client_hello_get_extension_order.3ossl | 1 - .../man/man3/SSL_client_hello_isv2.3ossl | 1 - .../share/man/man3/SSL_client_version.3ossl | 1 - .../share/man/man3/SSL_compress_certs.3ossl | 1 - .../share/man/man3/SSL_config.3ossl | 1 - .../share/man/man3/SSL_connect.3ossl | 220 -- .../share/man/man3/SSL_ct_is_enabled.3ossl | 1 - openssl-install/share/man/man3/SSL_ctrl.3ossl | 1 - .../man/man3/SSL_custom_ext_add_cb_ex.3ossl | 1 - .../man/man3/SSL_custom_ext_free_cb_ex.3ossl | 1 - .../man/man3/SSL_custom_ext_parse_cb_ex.3ossl | 1 - .../share/man/man3/SSL_dane_clear_flags.3ossl | 1 - .../share/man/man3/SSL_dane_enable.3ossl | 1 - .../share/man/man3/SSL_dane_set_flags.3ossl | 1 - .../share/man/man3/SSL_dane_tlsa_add.3ossl | 1 - .../share/man/man3/SSL_disable_ct.3ossl | 1 - .../share/man/man3/SSL_do_handshake.3ossl | 204 -- openssl-install/share/man/man3/SSL_dup.3ossl | 1 - .../share/man/man3/SSL_enable_ct.3ossl | 1 - .../man/man3/SSL_export_keying_material.3ossl | 222 -- .../SSL_export_keying_material_early.3ossl | 1 - .../man/man3/SSL_extension_supported.3ossl | 409 --- openssl-install/share/man/man3/SSL_free.3ossl | 210 -- .../share/man/man3/SSL_free_buffers.3ossl | 1 - .../share/man/man3/SSL_get0_CA_list.3ossl | 1 - .../man/man3/SSL_get0_alpn_selected.3ossl | 1 - .../man/man3/SSL_get0_chain_cert_store.3ossl | 1 - .../share/man/man3/SSL_get0_chain_certs.3ossl | 1 - .../man/man3/SSL_get0_client_cert_type.3ossl | 1 - .../share/man/man3/SSL_get0_connection.3ossl | 185 -- .../man/man3/SSL_get0_dane_authority.3ossl | 1 - .../share/man/man3/SSL_get0_dane_tlsa.3ossl | 1 - .../share/man/man3/SSL_get0_group_name.3ossl | 178 -- .../share/man/man3/SSL_get0_iana_groups.3ossl | 1 - .../man3/SSL_get0_next_proto_negotiated.3ossl | 1 - .../share/man/man3/SSL_get0_param.3ossl | 1 - .../man/man3/SSL_get0_peer_CA_list.3ossl | 1 - .../man/man3/SSL_get0_peer_certificate.3ossl | 1 - .../share/man/man3/SSL_get0_peer_rpk.3ossl | 227 -- .../share/man/man3/SSL_get0_peer_scts.3ossl | 176 -- .../share/man/man3/SSL_get0_peername.3ossl | 1 - .../man/man3/SSL_get0_security_ex_data.3ossl | 1 - .../man/man3/SSL_get0_server_cert_type.3ossl | 1 - .../share/man/man3/SSL_get0_session.3ossl | 1 - .../man/man3/SSL_get0_verified_chain.3ossl | 1 - .../man/man3/SSL_get0_verify_cert_store.3ossl | 1 - .../man/man3/SSL_get1_builtin_sigalgs.3ossl | 173 -- .../man/man3/SSL_get1_compressed_cert.3ossl | 1 - .../share/man/man3/SSL_get1_curves.3ossl | 1 - .../share/man/man3/SSL_get1_groups.3ossl | 1 - .../man/man3/SSL_get1_peer_certificate.3ossl | 1 - .../share/man/man3/SSL_get1_session.3ossl | 1 - .../man/man3/SSL_get1_supported_ciphers.3ossl | 1 - .../share/man/man3/SSL_get_SSL_CTX.3ossl | 167 -- .../SSL_get_accept_stream_queue_len.3ossl | 1 - .../man/man3/SSL_get_all_async_fds.3ossl | 217 -- .../share/man/man3/SSL_get_app_data.3ossl | 1 - .../share/man/man3/SSL_get_async_status.3ossl | 1 - .../man/man3/SSL_get_blocking_mode.3ossl | 1 - .../share/man/man3/SSL_get_certificate.3ossl | 196 -- .../man/man3/SSL_get_changed_async_fds.3ossl | 1 - .../share/man/man3/SSL_get_cipher.3ossl | 1 - .../share/man/man3/SSL_get_cipher_bits.3ossl | 1 - .../share/man/man3/SSL_get_cipher_list.3ossl | 1 - .../share/man/man3/SSL_get_cipher_name.3ossl | 1 - .../man/man3/SSL_get_cipher_version.3ossl | 1 - .../share/man/man3/SSL_get_ciphers.3ossl | 248 -- .../man/man3/SSL_get_client_CA_list.3ossl | 1 - .../man/man3/SSL_get_client_ciphers.3ossl | 1 - .../man/man3/SSL_get_client_random.3ossl | 233 -- .../man/man3/SSL_get_conn_close_info.3ossl | 293 --- .../man/man3/SSL_get_current_cipher.3ossl | 202 -- .../man/man3/SSL_get_default_passwd_cb.3ossl | 1 - .../SSL_get_default_passwd_cb_userdata.3ossl | 1 - .../man/man3/SSL_get_default_timeout.3ossl | 181 -- .../man/man3/SSL_get_early_data_status.3ossl | 1 - .../share/man/man3/SSL_get_error.3ossl | 318 --- .../man3/SSL_get_event_handling_mode.3ossl | 1 - .../man/man3/SSL_get_event_timeout.3ossl | 209 -- .../share/man/man3/SSL_get_ex_data.3ossl | 1 - .../SSL_get_ex_data_X509_STORE_CTX_idx.3ossl | 1 - .../share/man/man3/SSL_get_ex_new_index.3ossl | 1 - .../man/man3/SSL_get_extms_support.3ossl | 172 -- .../share/man/man3/SSL_get_fd.3ossl | 179 -- .../SSL_get_feature_negotiated_uint.3ossl | 1 - .../SSL_get_feature_peer_request_uint.3ossl | 1 - .../man3/SSL_get_feature_request_uint.3ossl | 1 - .../man/man3/SSL_get_generic_value_uint.3ossl | 1 - .../man/man3/SSL_get_handshake_rtt.3ossl | 192 -- .../man/man3/SSL_get_info_callback.3ossl | 1 - .../man/man3/SSL_get_key_update_type.3ossl | 1 - .../man/man3/SSL_get_max_cert_list.3ossl | 1 - .../man/man3/SSL_get_max_early_data.3ossl | 1 - .../man/man3/SSL_get_max_proto_version.3ossl | 1 - .../man/man3/SSL_get_min_proto_version.3ossl | 1 - .../share/man/man3/SSL_get_mode.3ossl | 1 - .../SSL_get_negotiated_client_cert_type.3ossl | 1 - .../man/man3/SSL_get_negotiated_group.3ossl | 1 - .../SSL_get_negotiated_server_cert_type.3ossl | 1 - .../share/man/man3/SSL_get_num_tickets.3ossl | 1 - .../share/man/man3/SSL_get_options.3ossl | 1 - .../man/man3/SSL_get_peer_cert_chain.3ossl | 202 -- .../man/man3/SSL_get_peer_certificate.3ossl | 210 -- .../man/man3/SSL_get_peer_signature_nid.3ossl | 185 -- .../SSL_get_peer_signature_type_nid.3ossl | 1 - .../share/man/man3/SSL_get_peer_tmp_key.3ossl | 184 -- .../man/man3/SSL_get_pending_cipher.3ossl | 1 - .../share/man/man3/SSL_get_privatekey.3ossl | 1 - .../share/man/man3/SSL_get_psk_identity.3ossl | 176 -- .../man/man3/SSL_get_psk_identity_hint.3ossl | 1 - ...SSL_get_quic_stream_bidi_local_avail.3ossl | 1 - ...SL_get_quic_stream_bidi_remote_avail.3ossl | 1 - .../SSL_get_quic_stream_uni_local_avail.3ossl | 1 - ...SSL_get_quic_stream_uni_remote_avail.3ossl | 1 - .../man/man3/SSL_get_quiet_shutdown.3ossl | 1 - .../share/man/man3/SSL_get_rbio.3ossl | 175 -- .../share/man/man3/SSL_get_read_ahead.3ossl | 1 - .../SSL_get_record_padding_callback_arg.3ossl | 1 - .../man3/SSL_get_recv_max_early_data.3ossl | 1 - .../share/man/man3/SSL_get_rfd.3ossl | 1 - .../man/man3/SSL_get_rpoll_descriptor.3ossl | 221 -- ...SSL_get_secure_renegotiation_support.3ossl | 1 - .../man/man3/SSL_get_security_callback.3ossl | 1 - .../man/man3/SSL_get_security_level.3ossl | 1 - .../man3/SSL_get_selected_srtp_profile.3ossl | 1 - .../man/man3/SSL_get_server_random.3ossl | 1 - .../man/man3/SSL_get_server_tmp_key.3ossl | 1 - .../share/man/man3/SSL_get_servername.3ossl | 1 - .../man/man3/SSL_get_servername_type.3ossl | 1 - .../share/man/man3/SSL_get_session.3ossl | 238 -- .../man/man3/SSL_get_shared_ciphers.3ossl | 1 - .../share/man/man3/SSL_get_shared_curve.3ossl | 1 - .../share/man/man3/SSL_get_shared_group.3ossl | 1 - .../man/man3/SSL_get_shared_sigalgs.3ossl | 219 -- .../share/man/man3/SSL_get_shutdown.3ossl | 1 - .../share/man/man3/SSL_get_sigalgs.3ossl | 1 - .../man/man3/SSL_get_signature_nid.3ossl | 1 - .../man/man3/SSL_get_signature_type_nid.3ossl | 1 - .../share/man/man3/SSL_get_srp_N.3ossl | 1 - .../share/man/man3/SSL_get_srp_g.3ossl | 1 - .../share/man/man3/SSL_get_srp_userinfo.3ossl | 1 - .../share/man/man3/SSL_get_srp_username.3ossl | 1 - .../man/man3/SSL_get_srtp_profiles.3ossl | 1 - .../share/man/man3/SSL_get_ssl_method.3ossl | 1 - .../share/man/man3/SSL_get_state.3ossl | 1 - .../share/man/man3/SSL_get_stream_id.3ossl | 232 -- .../man3/SSL_get_stream_read_error_code.3ossl | 1 - .../man/man3/SSL_get_stream_read_state.3ossl | 281 --- .../share/man/man3/SSL_get_stream_type.3ossl | 1 - .../man3/SSL_get_stream_write_buf_avail.3ossl | 1 - .../man3/SSL_get_stream_write_buf_size.3ossl | 1 - .../man3/SSL_get_stream_write_buf_used.3ossl | 1 - .../SSL_get_stream_write_error_code.3ossl | 1 - .../man/man3/SSL_get_stream_write_state.3ossl | 1 - .../share/man/man3/SSL_get_time.3ossl | 1 - .../share/man/man3/SSL_get_timeout.3ossl | 1 - .../SSL_get_tlsext_status_ocsp_resp.3ossl | 1 - .../man/man3/SSL_get_tlsext_status_type.3ossl | 1 - .../share/man/man3/SSL_get_tmp_key.3ossl | 1 - .../share/man/man3/SSL_get_value_uint.3ossl | 449 ---- .../man/man3/SSL_get_verify_callback.3ossl | 1 - .../share/man/man3/SSL_get_verify_depth.3ossl | 1 - .../share/man/man3/SSL_get_verify_mode.3ossl | 1 - .../man/man3/SSL_get_verify_result.3ossl | 197 -- .../share/man/man3/SSL_get_version.3ossl | 255 -- .../share/man/man3/SSL_get_wbio.3ossl | 1 - .../share/man/man3/SSL_get_wfd.3ossl | 1 - .../man/man3/SSL_get_wpoll_descriptor.3ossl | 1 - .../share/man/man3/SSL_group_to_name.3ossl | 175 -- .../share/man/man3/SSL_handle_events.3ossl | 225 -- .../man3/SSL_has_matching_session_id.3ossl | 1 - .../share/man/man3/SSL_has_pending.3ossl | 1 - .../share/man/man3/SSL_in_accept_init.3ossl | 1 - .../share/man/man3/SSL_in_before.3ossl | 1 - .../share/man/man3/SSL_in_connect_init.3ossl | 1 - .../share/man/man3/SSL_in_init.3ossl | 233 -- .../share/man/man3/SSL_inject_net_dgram.3ossl | 186 -- .../share/man/man3/SSL_is_connection.3ossl | 1 - .../share/man/man3/SSL_is_dtls.3ossl | 1 - .../share/man/man3/SSL_is_init_finished.3ossl | 1 - .../share/man/man3/SSL_is_quic.3ossl | 1 - .../share/man/man3/SSL_is_server.3ossl | 1 - .../share/man/man3/SSL_is_stream_local.3ossl | 1 - .../share/man/man3/SSL_is_tls.3ossl | 1 - .../share/man/man3/SSL_key_update.3ossl | 260 -- .../share/man/man3/SSL_library_init.3ossl | 186 -- .../man/man3/SSL_load_client_CA_file.3ossl | 241 -- .../man/man3/SSL_load_client_CA_file_ex.3ossl | 1 - .../man/man3/SSL_load_error_strings.3ossl | 1 - .../share/man/man3/SSL_net_read_desired.3ossl | 1 - .../man/man3/SSL_net_write_desired.3ossl | 1 - openssl-install/share/man/man3/SSL_new.3ossl | 255 -- .../man/man3/SSL_new_session_ticket.3ossl | 1 - .../share/man/man3/SSL_new_stream.3ossl | 220 -- openssl-install/share/man/man3/SSL_peek.3ossl | 1 - .../share/man/man3/SSL_peek_ex.3ossl | 1 - .../share/man/man3/SSL_pending.3ossl | 200 -- openssl-install/share/man/man3/SSL_poll.3ossl | 471 ---- .../man/man3/SSL_psk_client_cb_func.3ossl | 1 - .../man3/SSL_psk_find_session_cb_func.3ossl | 1 - .../man/man3/SSL_psk_server_cb_func.3ossl | 1 - .../man3/SSL_psk_use_session_cb_func.3ossl | 1 - openssl-install/share/man/man3/SSL_read.3ossl | 284 --- .../share/man/man3/SSL_read_early_data.3ossl | 502 ---- .../share/man/man3/SSL_read_ex.3ossl | 1 - .../share/man/man3/SSL_renegotiate.3ossl | 1 - .../man3/SSL_renegotiate_abbreviated.3ossl | 1 - .../man/man3/SSL_renegotiate_pending.3ossl | 1 - .../share/man/man3/SSL_rstate_string.3ossl | 194 -- .../man/man3/SSL_rstate_string_long.3ossl | 1 - .../man/man3/SSL_select_current_cert.3ossl | 1 - .../man/man3/SSL_select_next_proto.3ossl | 1 - .../share/man/man3/SSL_sendfile.3ossl | 1 - .../share/man/man3/SSL_session_reused.3ossl | 178 -- .../share/man/man3/SSL_set0_CA_list.3ossl | 1 - .../share/man/man3/SSL_set0_chain.3ossl | 1 - .../man/man3/SSL_set0_chain_cert_store.3ossl | 1 - .../share/man/man3/SSL_set0_rbio.3ossl | 1 - .../man/man3/SSL_set0_security_ex_data.3ossl | 1 - .../share/man/man3/SSL_set0_tmp_dh_pkey.3ossl | 1 - .../man/man3/SSL_set0_verify_cert_store.3ossl | 1 - .../share/man/man3/SSL_set0_wbio.3ossl | 1 - .../man3/SSL_set1_cert_comp_preference.3ossl | 1 - .../share/man/man3/SSL_set1_chain.3ossl | 1 - .../man/man3/SSL_set1_chain_cert_store.3ossl | 1 - .../man/man3/SSL_set1_client_cert_type.3ossl | 1 - .../man/man3/SSL_set1_client_sigalgs.3ossl | 1 - .../man3/SSL_set1_client_sigalgs_list.3ossl | 1 - .../man/man3/SSL_set1_compressed_cert.3ossl | 1 - .../share/man/man3/SSL_set1_curves.3ossl | 1 - .../share/man/man3/SSL_set1_curves_list.3ossl | 1 - .../share/man/man3/SSL_set1_groups.3ossl | 1 - .../share/man/man3/SSL_set1_groups_list.3ossl | 1 - .../share/man/man3/SSL_set1_host.3ossl | 259 -- .../man/man3/SSL_set1_initial_peer_addr.3ossl | 192 -- .../share/man/man3/SSL_set1_param.3ossl | 1 - .../man/man3/SSL_set1_server_cert_type.3ossl | 323 --- .../share/man/man3/SSL_set1_sigalgs.3ossl | 1 - .../man/man3/SSL_set1_sigalgs_list.3ossl | 1 - .../man/man3/SSL_set1_verify_cert_store.3ossl | 1 - .../share/man/man3/SSL_set_accept_state.3ossl | 1 - .../man3/SSL_set_allow_early_data_cb.3ossl | 1 - .../share/man/man3/SSL_set_alpn_protos.3ossl | 1 - .../share/man/man3/SSL_set_app_data.3ossl | 1 - .../man/man3/SSL_set_async_callback.3ossl | 238 -- .../man/man3/SSL_set_async_callback_arg.3ossl | 1 - .../share/man/man3/SSL_set_bio.3ossl | 240 -- .../man/man3/SSL_set_block_padding.3ossl | 1 - .../man/man3/SSL_set_block_padding_ex.3ossl | 1 - .../man/man3/SSL_set_blocking_mode.3ossl | 205 -- .../share/man/man3/SSL_set_cert_cb.3ossl | 1 - .../share/man/man3/SSL_set_cipher_list.3ossl | 1 - .../share/man/man3/SSL_set_ciphersuites.3ossl | 1 - .../man/man3/SSL_set_client_CA_list.3ossl | 1 - .../man/man3/SSL_set_connect_state.3ossl | 208 -- .../man3/SSL_set_ct_validation_callback.3ossl | 1 - .../share/man/man3/SSL_set_current_cert.3ossl | 1 - .../man/man3/SSL_set_default_passwd_cb.3ossl | 1 - .../SSL_set_default_passwd_cb_userdata.3ossl | 1 - .../SSL_set_default_read_buffer_len.3ossl | 1 - .../man3/SSL_set_default_stream_mode.3ossl | 251 -- .../share/man/man3/SSL_set_dh_auto.3ossl | 1 - .../share/man/man3/SSL_set_ecdh_auto.3ossl | 1 - .../man3/SSL_set_event_handling_mode.3ossl | 1 - .../share/man/man3/SSL_set_ex_data.3ossl | 1 - .../share/man/man3/SSL_set_fd.3ossl | 201 -- .../man3/SSL_set_feature_request_uint.3ossl | 1 - .../man3/SSL_set_generate_session_id.3ossl | 1 - .../man/man3/SSL_set_generic_value_uint.3ossl | 1 - .../share/man/man3/SSL_set_hostflags.3ossl | 1 - .../man3/SSL_set_incoming_stream_policy.3ossl | 219 -- .../man/man3/SSL_set_info_callback.3ossl | 1 - .../man/man3/SSL_set_max_cert_list.3ossl | 1 - .../man/man3/SSL_set_max_early_data.3ossl | 1 - .../man/man3/SSL_set_max_pipelines.3ossl | 1 - .../man/man3/SSL_set_max_proto_version.3ossl | 1 - .../man/man3/SSL_set_max_send_fragment.3ossl | 1 - .../man/man3/SSL_set_min_proto_version.3ossl | 1 - .../share/man/man3/SSL_set_mode.3ossl | 1 - .../share/man/man3/SSL_set_msg_callback.3ossl | 1 - .../man/man3/SSL_set_msg_callback_arg.3ossl | 1 - .../share/man/man3/SSL_set_num_tickets.3ossl | 1 - .../share/man/man3/SSL_set_options.3ossl | 1 - .../man3/SSL_set_post_handshake_auth.3ossl | 1 - .../man3/SSL_set_psk_client_callback.3ossl | 1 - .../SSL_set_psk_find_session_callback.3ossl | 1 - .../man3/SSL_set_psk_server_callback.3ossl | 1 - .../SSL_set_psk_use_session_callback.3ossl | 1 - .../share/man/man3/SSL_set_purpose.3ossl | 1 - .../man/man3/SSL_set_quiet_shutdown.3ossl | 1 - .../share/man/man3/SSL_set_read_ahead.3ossl | 1 - .../SSL_set_record_padding_callback.3ossl | 1 - .../SSL_set_record_padding_callback_arg.3ossl | 1 - .../man3/SSL_set_recv_max_early_data.3ossl | 1 - .../share/man/man3/SSL_set_retry_verify.3ossl | 201 -- .../share/man/man3/SSL_set_rfd.3ossl | 1 - .../man/man3/SSL_set_security_callback.3ossl | 1 - .../man/man3/SSL_set_security_level.3ossl | 1 - .../share/man/man3/SSL_set_session.3ossl | 195 -- .../man/man3/SSL_set_session_id_context.3ossl | 1 - .../man/man3/SSL_set_session_secret_cb.3ossl | 201 -- .../share/man/man3/SSL_set_shutdown.3ossl | 214 -- .../man3/SSL_set_split_send_fragment.3ossl | 1 - .../man/man3/SSL_set_srp_server_param.3ossl | 1 - .../man3/SSL_set_srp_server_param_pw.3ossl | 1 - .../share/man/man3/SSL_set_ssl_method.3ossl | 1 - .../share/man/man3/SSL_set_time.3ossl | 1 - .../share/man/man3/SSL_set_timeout.3ossl | 1 - .../man/man3/SSL_set_tlsext_host_name.3ossl | 1 - .../SSL_set_tlsext_max_fragment_length.3ossl | 1 - .../SSL_set_tlsext_status_ocsp_resp.3ossl | 1 - .../man/man3/SSL_set_tlsext_status_type.3ossl | 1 - .../man/man3/SSL_set_tlsext_use_srtp.3ossl | 1 - .../share/man/man3/SSL_set_tmp_dh.3ossl | 1 - .../man/man3/SSL_set_tmp_dh_callback.3ossl | 1 - .../share/man/man3/SSL_set_tmp_ecdh.3ossl | 1 - .../share/man/man3/SSL_set_trust.3ossl | 1 - .../share/man/man3/SSL_set_value_uint.3ossl | 1 - .../share/man/man3/SSL_set_verify.3ossl | 1 - .../share/man/man3/SSL_set_verify_depth.3ossl | 1 - .../man/man3/SSL_set_verify_result.3ossl | 178 -- .../share/man/man3/SSL_set_wfd.3ossl | 1 - .../share/man/man3/SSL_shutdown.3ossl | 528 ---- .../share/man/man3/SSL_shutdown_ex.3ossl | 1 - .../share/man/man3/SSL_state_string.3ossl | 185 -- .../man/man3/SSL_state_string_long.3ossl | 1 - .../share/man/man3/SSL_stateless.3ossl | 1 - .../share/man/man3/SSL_stream_conclude.3ossl | 191 -- .../share/man/man3/SSL_stream_reset.3ossl | 209 -- .../share/man/man3/SSL_trace.3ossl | 1 - .../share/man/man3/SSL_up_ref.3ossl | 1 - .../share/man/man3/SSL_use_PrivateKey.3ossl | 1 - .../man/man3/SSL_use_PrivateKey_ASN1.3ossl | 1 - .../man/man3/SSL_use_PrivateKey_file.3ossl | 1 - .../man/man3/SSL_use_RSAPrivateKey.3ossl | 1 - .../man/man3/SSL_use_RSAPrivateKey_ASN1.3ossl | 1 - .../man/man3/SSL_use_RSAPrivateKey_file.3ossl | 1 - .../share/man/man3/SSL_use_cert_and_key.3ossl | 1 - .../share/man/man3/SSL_use_certificate.3ossl | 1 - .../man/man3/SSL_use_certificate_ASN1.3ossl | 1 - .../man3/SSL_use_certificate_chain_file.3ossl | 1 - .../man/man3/SSL_use_certificate_file.3ossl | 1 - .../man/man3/SSL_use_psk_identity_hint.3ossl | 1 - .../share/man/man3/SSL_verify_cb.3ossl | 1 - .../SSL_verify_client_post_handshake.3ossl | 1 - .../share/man/man3/SSL_version.3ossl | 1 - .../man/man3/SSL_waiting_for_async.3ossl | 1 - openssl-install/share/man/man3/SSL_want.3ossl | 241 -- .../share/man/man3/SSL_want_async.3ossl | 1 - .../share/man/man3/SSL_want_async_job.3ossl | 1 - .../man/man3/SSL_want_client_hello_cb.3ossl | 1 - .../share/man/man3/SSL_want_nothing.3ossl | 1 - .../share/man/man3/SSL_want_read.3ossl | 1 - .../man/man3/SSL_want_retry_verify.3ossl | 1 - .../share/man/man3/SSL_want_write.3ossl | 1 - .../share/man/man3/SSL_want_x509_lookup.3ossl | 1 - .../share/man/man3/SSL_write.3ossl | 321 --- .../share/man/man3/SSL_write_early_data.3ossl | 1 - .../share/man/man3/SSL_write_ex.3ossl | 1 - .../share/man/man3/SSL_write_ex2.3ossl | 1 - .../share/man/man3/SSLv23_client_method.3ossl | 1 - .../share/man/man3/SSLv23_method.3ossl | 1 - .../share/man/man3/SSLv23_server_method.3ossl | 1 - .../share/man/man3/SSLv3_client_method.3ossl | 1 - .../share/man/man3/SSLv3_method.3ossl | 1 - .../share/man/man3/SSLv3_server_method.3ossl | 1 - .../share/man/man3/SXNETID_free.3ossl | 1 - .../share/man/man3/SXNETID_new.3ossl | 1 - .../share/man/man3/SXNET_free.3ossl | 1 - .../share/man/man3/SXNET_new.3ossl | 1 - .../share/man/man3/TLS_FEATURE_free.3ossl | 1 - .../share/man/man3/TLS_FEATURE_new.3ossl | 1 - .../share/man/man3/TLS_client_method.3ossl | 1 - .../share/man/man3/TLS_method.3ossl | 1 - .../share/man/man3/TLS_server_method.3ossl | 1 - .../man/man3/TLSv1_1_client_method.3ossl | 1 - .../share/man/man3/TLSv1_1_method.3ossl | 1 - .../man/man3/TLSv1_1_server_method.3ossl | 1 - .../man/man3/TLSv1_2_client_method.3ossl | 1 - .../share/man/man3/TLSv1_2_method.3ossl | 1 - .../man/man3/TLSv1_2_server_method.3ossl | 1 - .../share/man/man3/TLSv1_client_method.3ossl | 1 - .../share/man/man3/TLSv1_method.3ossl | 1 - .../share/man/man3/TLSv1_server_method.3ossl | 1 - .../share/man/man3/TS_ACCURACY_dup.3ossl | 1 - .../share/man/man3/TS_ACCURACY_free.3ossl | 1 - .../share/man/man3/TS_ACCURACY_new.3ossl | 1 - .../share/man/man3/TS_MSG_IMPRINT_dup.3ossl | 1 - .../share/man/man3/TS_MSG_IMPRINT_free.3ossl | 1 - .../share/man/man3/TS_MSG_IMPRINT_new.3ossl | 1 - .../share/man/man3/TS_REQ_dup.3ossl | 1 - .../share/man/man3/TS_REQ_free.3ossl | 1 - .../share/man/man3/TS_REQ_new.3ossl | 1 - .../share/man/man3/TS_RESP_CTX_free.3ossl | 1 - .../share/man/man3/TS_RESP_CTX_new.3ossl | 182 -- .../share/man/man3/TS_RESP_CTX_new_ex.3ossl | 1 - .../share/man/man3/TS_RESP_dup.3ossl | 1 - .../share/man/man3/TS_RESP_free.3ossl | 1 - .../share/man/man3/TS_RESP_new.3ossl | 1 - .../share/man/man3/TS_STATUS_INFO_dup.3ossl | 1 - .../share/man/man3/TS_STATUS_INFO_free.3ossl | 1 - .../share/man/man3/TS_STATUS_INFO_new.3ossl | 1 - .../share/man/man3/TS_TST_INFO_dup.3ossl | 1 - .../share/man/man3/TS_TST_INFO_free.3ossl | 1 - .../share/man/man3/TS_TST_INFO_new.3ossl | 1 - .../man/man3/TS_VERIFY_CTS_set_certs.3ossl | 1 - .../share/man/man3/TS_VERIFY_CTX.3ossl | 289 --- .../man/man3/TS_VERIFY_CTX_add_flags.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_cleanup.3ossl | 1 - .../share/man/man3/TS_VERIFY_CTX_free.3ossl | 1 - .../share/man/man3/TS_VERIFY_CTX_init.3ossl | 1 - .../share/man/man3/TS_VERIFY_CTX_new.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set0_certs.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set0_data.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set0_imprint.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set0_store.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set_certs.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set_data.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set_flags.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set_imprint.3ossl | 1 - .../man/man3/TS_VERIFY_CTX_set_store.3ossl | 1 - openssl-install/share/man/man3/UI.3ossl | 1 - .../share/man/man3/UI_METHOD.3ossl | 1 - .../share/man/man3/UI_OpenSSL.3ossl | 1 - .../share/man/man3/UI_STRING.3ossl | 279 --- .../share/man/man3/UI_UTIL_read_pw.3ossl | 203 -- .../man/man3/UI_UTIL_read_pw_string.3ossl | 1 - .../man3/UI_UTIL_wrap_read_pem_callback.3ossl | 1 - .../share/man/man3/UI_add_error_string.3ossl | 1 - .../share/man/man3/UI_add_info_string.3ossl | 1 - .../share/man/man3/UI_add_input_boolean.3ossl | 1 - .../share/man/man3/UI_add_input_string.3ossl | 1 - .../share/man/man3/UI_add_user_data.3ossl | 1 - .../share/man/man3/UI_add_verify_string.3ossl | 1 - .../share/man/man3/UI_construct_prompt.3ossl | 1 - .../share/man/man3/UI_create_method.3ossl | 328 --- openssl-install/share/man/man3/UI_ctrl.3ossl | 1 - .../share/man/man3/UI_destroy_method.3ossl | 1 - .../share/man/man3/UI_dup_error_string.3ossl | 1 - .../share/man/man3/UI_dup_info_string.3ossl | 1 - .../share/man/man3/UI_dup_input_boolean.3ossl | 1 - .../share/man/man3/UI_dup_input_string.3ossl | 1 - .../share/man/man3/UI_dup_user_data.3ossl | 1 - .../share/man/man3/UI_dup_verify_string.3ossl | 1 - openssl-install/share/man/man3/UI_free.3ossl | 1 - .../man/man3/UI_get0_action_string.3ossl | 1 - .../man/man3/UI_get0_output_string.3ossl | 1 - .../share/man/man3/UI_get0_result.3ossl | 1 - .../man/man3/UI_get0_result_string.3ossl | 1 - .../share/man/man3/UI_get0_test_string.3ossl | 1 - .../share/man/man3/UI_get0_user_data.3ossl | 1 - .../share/man/man3/UI_get_app_data.3ossl | 1 - .../man/man3/UI_get_default_method.3ossl | 1 - .../share/man/man3/UI_get_ex_data.3ossl | 1 - .../share/man/man3/UI_get_ex_new_index.3ossl | 1 - .../share/man/man3/UI_get_input_flags.3ossl | 1 - .../share/man/man3/UI_get_method.3ossl | 1 - .../share/man/man3/UI_get_result_length.3ossl | 1 - .../man/man3/UI_get_result_maxsize.3ossl | 1 - .../man/man3/UI_get_result_minsize.3ossl | 1 - .../man3/UI_get_result_string_length.3ossl | 1 - .../share/man/man3/UI_get_string_type.3ossl | 1 - .../share/man/man3/UI_method_get_closer.3ossl | 1 - .../man3/UI_method_get_data_destructor.3ossl | 1 - .../man3/UI_method_get_data_duplicator.3ossl | 1 - .../man/man3/UI_method_get_ex_data.3ossl | 1 - .../man/man3/UI_method_get_flusher.3ossl | 1 - .../share/man/man3/UI_method_get_opener.3ossl | 1 - .../UI_method_get_prompt_constructor.3ossl | 1 - .../share/man/man3/UI_method_get_reader.3ossl | 1 - .../share/man/man3/UI_method_get_writer.3ossl | 1 - .../share/man/man3/UI_method_set_closer.3ossl | 1 - .../man3/UI_method_set_data_duplicator.3ossl | 1 - .../man/man3/UI_method_set_ex_data.3ossl | 1 - .../man/man3/UI_method_set_flusher.3ossl | 1 - .../share/man/man3/UI_method_set_opener.3ossl | 1 - .../UI_method_set_prompt_constructor.3ossl | 1 - .../share/man/man3/UI_method_set_reader.3ossl | 1 - .../share/man/man3/UI_method_set_writer.3ossl | 1 - openssl-install/share/man/man3/UI_new.3ossl | 386 --- .../share/man/man3/UI_new_method.3ossl | 1 - openssl-install/share/man/man3/UI_null.3ossl | 1 - .../share/man/man3/UI_process.3ossl | 1 - .../share/man/man3/UI_set_app_data.3ossl | 1 - .../man/man3/UI_set_default_method.3ossl | 1 - .../share/man/man3/UI_set_ex_data.3ossl | 1 - .../share/man/man3/UI_set_method.3ossl | 1 - .../share/man/man3/UI_set_result.3ossl | 1 - .../share/man/man3/UI_set_result_ex.3ossl | 1 - .../share/man/man3/UI_string_types.3ossl | 1 - .../share/man/man3/USERNOTICE_free.3ossl | 1 - .../share/man/man3/USERNOTICE_new.3ossl | 1 - .../share/man/man3/X509V3_EXT_d2i.3ossl | 1 - .../share/man/man3/X509V3_EXT_i2d.3ossl | 1 - .../share/man/man3/X509V3_add1_i2d.3ossl | 1 - .../share/man/man3/X509V3_get_d2i.3ossl | 396 --- .../share/man/man3/X509V3_set_ctx.3ossl | 200 -- .../man/man3/X509V3_set_issuer_pkey.3ossl | 1 - .../share/man/man3/X509_ACERT_INFO_free.3ossl | 1 - .../share/man/man3/X509_ACERT_INFO_it.3ossl | 1 - .../share/man/man3/X509_ACERT_INFO_new.3ossl | 1 - .../man3/X509_ACERT_ISSUER_V2FORM_free.3ossl | 1 - .../man3/X509_ACERT_ISSUER_V2FORM_new.3ossl | 1 - .../share/man/man3/X509_ACERT_add1_attr.3ossl | 198 -- .../man3/X509_ACERT_add1_attr_by_NID.3ossl | 1 - .../man3/X509_ACERT_add1_attr_by_OBJ.3ossl | 1 - .../man3/X509_ACERT_add1_attr_by_txt.3ossl | 1 - .../man/man3/X509_ACERT_add1_ext_i2d.3ossl | 1 - .../man/man3/X509_ACERT_add_attr_nconf.3ossl | 198 -- .../man/man3/X509_ACERT_delete_attr.3ossl | 1 - .../share/man/man3/X509_ACERT_dup.3ossl | 1 - .../share/man/man3/X509_ACERT_free.3ossl | 1 - .../man/man3/X509_ACERT_get0_extensions.3ossl | 1 - .../X509_ACERT_get0_holder_baseCertId.3ossl | 246 -- .../man3/X509_ACERT_get0_holder_digest.3ossl | 1 - .../X509_ACERT_get0_holder_entityName.3ossl | 1 - .../man3/X509_ACERT_get0_info_sigalg.3ossl | 1 - .../man/man3/X509_ACERT_get0_issuerName.3ossl | 1 - .../man/man3/X509_ACERT_get0_issuerUID.3ossl | 1 - .../man/man3/X509_ACERT_get0_notAfter.3ossl | 1 - .../man/man3/X509_ACERT_get0_notBefore.3ossl | 1 - .../man3/X509_ACERT_get0_serialNumber.3ossl | 1 - .../man/man3/X509_ACERT_get0_signature.3ossl | 1 - .../share/man/man3/X509_ACERT_get_attr.3ossl | 191 -- .../man/man3/X509_ACERT_get_attr_by_NID.3ossl | 1 - .../man/man3/X509_ACERT_get_attr_by_OBJ.3ossl | 1 - .../man/man3/X509_ACERT_get_attr_count.3ossl | 1 - .../man/man3/X509_ACERT_get_ext_d2i.3ossl | 1 - .../man3/X509_ACERT_get_signature_nid.3ossl | 1 - .../man/man3/X509_ACERT_get_version.3ossl | 1 - .../share/man/man3/X509_ACERT_it.3ossl | 1 - .../share/man/man3/X509_ACERT_new.3ossl | 1 - .../share/man/man3/X509_ACERT_print.3ossl | 1 - .../share/man/man3/X509_ACERT_print_ex.3ossl | 237 -- .../X509_ACERT_set0_holder_baseCertId.3ossl | 1 - .../man3/X509_ACERT_set0_holder_digest.3ossl | 1 - .../X509_ACERT_set0_holder_entityName.3ossl | 1 - .../man/man3/X509_ACERT_set1_issuerName.3ossl | 1 - .../man/man3/X509_ACERT_set1_notAfter.3ossl | 1 - .../man/man3/X509_ACERT_set1_notBefore.3ossl | 1 - .../man3/X509_ACERT_set1_serialNumber.3ossl | 1 - .../man/man3/X509_ACERT_set_version.3ossl | 1 - .../share/man/man3/X509_ACERT_sign.3ossl | 1 - .../share/man/man3/X509_ACERT_sign_ctx.3ossl | 1 - .../share/man/man3/X509_ACERT_verify.3ossl | 1 - .../share/man/man3/X509_ALGOR_cmp.3ossl | 1 - .../share/man/man3/X509_ALGOR_copy.3ossl | 1 - .../share/man/man3/X509_ALGOR_dup.3ossl | 204 -- .../share/man/man3/X509_ALGOR_free.3ossl | 1 - .../share/man/man3/X509_ALGOR_get0.3ossl | 1 - .../share/man/man3/X509_ALGOR_it.3ossl | 1 - .../share/man/man3/X509_ALGOR_new.3ossl | 1 - .../share/man/man3/X509_ALGOR_set0.3ossl | 1 - .../share/man/man3/X509_ALGOR_set_md.3ossl | 1 - .../share/man/man3/X509_ATTRIBUTE.3ossl | 399 --- .../share/man/man3/X509_ATTRIBUTE_count.3ossl | 1 - .../man/man3/X509_ATTRIBUTE_create.3ossl | 1 - .../man3/X509_ATTRIBUTE_create_by_NID.3ossl | 1 - .../man3/X509_ATTRIBUTE_create_by_OBJ.3ossl | 1 - .../man3/X509_ATTRIBUTE_create_by_txt.3ossl | 1 - .../share/man/man3/X509_ATTRIBUTE_dup.3ossl | 1 - .../share/man/man3/X509_ATTRIBUTE_free.3ossl | 1 - .../man/man3/X509_ATTRIBUTE_get0_data.3ossl | 1 - .../man/man3/X509_ATTRIBUTE_get0_object.3ossl | 1 - .../man/man3/X509_ATTRIBUTE_get0_type.3ossl | 1 - .../share/man/man3/X509_ATTRIBUTE_new.3ossl | 1 - .../man/man3/X509_ATTRIBUTE_set1_data.3ossl | 1 - .../man/man3/X509_ATTRIBUTE_set1_object.3ossl | 1 - .../share/man/man3/X509_CERT_AUX_free.3ossl | 1 - .../share/man/man3/X509_CERT_AUX_new.3ossl | 1 - .../share/man/man3/X509_CINF_free.3ossl | 1 - .../share/man/man3/X509_CINF_new.3ossl | 1 - .../share/man/man3/X509_CRL_INFO_free.3ossl | 1 - .../share/man/man3/X509_CRL_INFO_new.3ossl | 1 - .../man/man3/X509_CRL_add0_revoked.3ossl | 1 - .../man/man3/X509_CRL_add1_ext_i2d.3ossl | 1 - .../share/man/man3/X509_CRL_add_ext.3ossl | 1 - .../share/man/man3/X509_CRL_cmp.3ossl | 1 - .../share/man/man3/X509_CRL_delete_ext.3ossl | 1 - .../share/man/man3/X509_CRL_digest.3ossl | 1 - .../share/man/man3/X509_CRL_dup.3ossl | 1 - .../share/man/man3/X509_CRL_free.3ossl | 1 - .../man/man3/X509_CRL_get0_by_cert.3ossl | 1 - .../man/man3/X509_CRL_get0_by_serial.3ossl | 246 -- .../man/man3/X509_CRL_get0_extensions.3ossl | 1 - .../man/man3/X509_CRL_get0_lastUpdate.3ossl | 1 - .../man/man3/X509_CRL_get0_nextUpdate.3ossl | 1 - .../man/man3/X509_CRL_get0_signature.3ossl | 1 - .../share/man/man3/X509_CRL_get_REVOKED.3ossl | 1 - .../share/man/man3/X509_CRL_get_ext.3ossl | 1 - .../man/man3/X509_CRL_get_ext_by_NID.3ossl | 1 - .../man/man3/X509_CRL_get_ext_by_OBJ.3ossl | 1 - .../man3/X509_CRL_get_ext_by_critical.3ossl | 1 - .../man/man3/X509_CRL_get_ext_count.3ossl | 1 - .../share/man/man3/X509_CRL_get_ext_d2i.3ossl | 1 - .../share/man/man3/X509_CRL_get_issuer.3ossl | 1 - .../man/man3/X509_CRL_get_signature_nid.3ossl | 1 - .../share/man/man3/X509_CRL_get_version.3ossl | 1 - .../share/man/man3/X509_CRL_http_nbio.3ossl | 1 - .../share/man/man3/X509_CRL_load_http.3ossl | 1 - .../share/man/man3/X509_CRL_match.3ossl | 1 - .../share/man/man3/X509_CRL_new.3ossl | 1 - .../share/man/man3/X509_CRL_new_ex.3ossl | 1 - .../man/man3/X509_CRL_set1_lastUpdate.3ossl | 1 - .../man/man3/X509_CRL_set1_nextUpdate.3ossl | 1 - .../man/man3/X509_CRL_set_issuer_name.3ossl | 1 - .../share/man/man3/X509_CRL_set_version.3ossl | 1 - .../share/man/man3/X509_CRL_sign.3ossl | 1 - .../share/man/man3/X509_CRL_sign_ctx.3ossl | 1 - .../share/man/man3/X509_CRL_sort.3ossl | 1 - .../share/man/man3/X509_CRL_verify.3ossl | 1 - .../man3/X509_EXTENSION_create_by_NID.3ossl | 1 - .../man3/X509_EXTENSION_create_by_OBJ.3ossl | 1 - .../share/man/man3/X509_EXTENSION_dup.3ossl | 1 - .../share/man/man3/X509_EXTENSION_free.3ossl | 1 - .../man3/X509_EXTENSION_get_critical.3ossl | 1 - .../man/man3/X509_EXTENSION_get_data.3ossl | 1 - .../man/man3/X509_EXTENSION_get_object.3ossl | 1 - .../share/man/man3/X509_EXTENSION_new.3ossl | 1 - .../man3/X509_EXTENSION_set_critical.3ossl | 1 - .../man/man3/X509_EXTENSION_set_data.3ossl | 1 - .../man/man3/X509_EXTENSION_set_object.3ossl | 227 -- .../share/man/man3/X509_LOOKUP.3ossl | 371 --- .../share/man/man3/X509_LOOKUP_METHOD.3ossl | 1 - .../share/man/man3/X509_LOOKUP_TYPE.3ossl | 1 - .../share/man/man3/X509_LOOKUP_add_dir.3ossl | 1 - .../man/man3/X509_LOOKUP_add_store.3ossl | 1 - .../man/man3/X509_LOOKUP_add_store_ex.3ossl | 1 - .../share/man/man3/X509_LOOKUP_by_alias.3ossl | 1 - .../man/man3/X509_LOOKUP_by_fingerprint.3ossl | 1 - .../man3/X509_LOOKUP_by_issuer_serial.3ossl | 1 - .../man/man3/X509_LOOKUP_by_subject.3ossl | 1 - .../man/man3/X509_LOOKUP_by_subject_ex.3ossl | 1 - .../share/man/man3/X509_LOOKUP_ctrl.3ossl | 1 - .../share/man/man3/X509_LOOKUP_ctrl_ex.3ossl | 1 - .../share/man/man3/X509_LOOKUP_ctrl_fn.3ossl | 1 - .../share/man/man3/X509_LOOKUP_file.3ossl | 1 - .../share/man/man3/X509_LOOKUP_free.3ossl | 1 - .../man3/X509_LOOKUP_get_by_alias_fn.3ossl | 1 - .../X509_LOOKUP_get_by_fingerprint_fn.3ossl | 1 - .../X509_LOOKUP_get_by_issuer_serial_fn.3ossl | 1 - .../man3/X509_LOOKUP_get_by_subject_fn.3ossl | 1 - .../man3/X509_LOOKUP_get_method_data.3ossl | 1 - .../man/man3/X509_LOOKUP_get_store.3ossl | 1 - .../share/man/man3/X509_LOOKUP_hash_dir.3ossl | 291 --- .../share/man/man3/X509_LOOKUP_init.3ossl | 1 - .../man/man3/X509_LOOKUP_load_file.3ossl | 1 - .../man/man3/X509_LOOKUP_load_file_ex.3ossl | 1 - .../man/man3/X509_LOOKUP_load_store.3ossl | 1 - .../man/man3/X509_LOOKUP_load_store_ex.3ossl | 1 - .../man/man3/X509_LOOKUP_meth_free.3ossl | 1 - .../man/man3/X509_LOOKUP_meth_get_ctrl.3ossl | 1 - .../man/man3/X509_LOOKUP_meth_get_free.3ossl | 1 - .../X509_LOOKUP_meth_get_get_by_alias.3ossl | 1 - ...9_LOOKUP_meth_get_get_by_fingerprint.3ossl | 1 - ...LOOKUP_meth_get_get_by_issuer_serial.3ossl | 1 - .../X509_LOOKUP_meth_get_get_by_subject.3ossl | 1 - .../man/man3/X509_LOOKUP_meth_get_init.3ossl | 1 - .../man3/X509_LOOKUP_meth_get_new_item.3ossl | 1 - .../man3/X509_LOOKUP_meth_get_shutdown.3ossl | 1 - .../share/man/man3/X509_LOOKUP_meth_new.3ossl | 328 --- .../man/man3/X509_LOOKUP_meth_set_ctrl.3ossl | 1 - .../man/man3/X509_LOOKUP_meth_set_free.3ossl | 1 - .../X509_LOOKUP_meth_set_get_by_alias.3ossl | 1 - ...9_LOOKUP_meth_set_get_by_fingerprint.3ossl | 1 - ...LOOKUP_meth_set_get_by_issuer_serial.3ossl | 1 - .../X509_LOOKUP_meth_set_get_by_subject.3ossl | 1 - .../man/man3/X509_LOOKUP_meth_set_init.3ossl | 1 - .../man3/X509_LOOKUP_meth_set_new_item.3ossl | 1 - .../man3/X509_LOOKUP_meth_set_shutdown.3ossl | 1 - .../share/man/man3/X509_LOOKUP_new.3ossl | 1 - .../man3/X509_LOOKUP_set_method_data.3ossl | 1 - .../share/man/man3/X509_LOOKUP_shutdown.3ossl | 1 - .../share/man/man3/X509_LOOKUP_store.3ossl | 1 - .../man3/X509_NAME_ENTRY_create_by_NID.3ossl | 1 - .../man3/X509_NAME_ENTRY_create_by_OBJ.3ossl | 1 - .../man3/X509_NAME_ENTRY_create_by_txt.3ossl | 1 - .../share/man/man3/X509_NAME_ENTRY_dup.3ossl | 1 - .../share/man/man3/X509_NAME_ENTRY_free.3ossl | 1 - .../man/man3/X509_NAME_ENTRY_get_data.3ossl | 1 - .../man/man3/X509_NAME_ENTRY_get_object.3ossl | 227 -- .../share/man/man3/X509_NAME_ENTRY_new.3ossl | 1 - .../man/man3/X509_NAME_ENTRY_set_data.3ossl | 1 - .../man/man3/X509_NAME_ENTRY_set_object.3ossl | 1 - .../share/man/man3/X509_NAME_add_entry.3ossl | 1 - .../man/man3/X509_NAME_add_entry_by_NID.3ossl | 1 - .../man/man3/X509_NAME_add_entry_by_OBJ.3ossl | 1 - .../man/man3/X509_NAME_add_entry_by_txt.3ossl | 258 -- .../share/man/man3/X509_NAME_cmp.3ossl | 1 - .../man/man3/X509_NAME_delete_entry.3ossl | 1 - .../share/man/man3/X509_NAME_digest.3ossl | 1 - .../share/man/man3/X509_NAME_dup.3ossl | 1 - .../man/man3/X509_NAME_entry_count.3ossl | 1 - .../share/man/man3/X509_NAME_free.3ossl | 1 - .../share/man/man3/X509_NAME_get0_der.3ossl | 171 -- .../share/man/man3/X509_NAME_get_entry.3ossl | 1 - .../man/man3/X509_NAME_get_index_by_NID.3ossl | 260 -- .../man/man3/X509_NAME_get_index_by_OBJ.3ossl | 1 - .../man/man3/X509_NAME_get_text_by_NID.3ossl | 1 - .../man/man3/X509_NAME_get_text_by_OBJ.3ossl | 1 - .../share/man/man3/X509_NAME_hash.3ossl | 1 - .../share/man/man3/X509_NAME_hash_ex.3ossl | 1 - .../share/man/man3/X509_NAME_new.3ossl | 1 - .../share/man/man3/X509_NAME_oneline.3ossl | 1 - .../share/man/man3/X509_NAME_print.3ossl | 1 - .../share/man/man3/X509_NAME_print_ex.3ossl | 263 -- .../man/man3/X509_NAME_print_ex_fp.3ossl | 1 - .../man/man3/X509_OBJECT_set1_X509.3ossl | 1 - .../man/man3/X509_OBJECT_set1_X509_CRL.3ossl | 1 - .../share/man/man3/X509_PUBKEY_dup.3ossl | 1 - .../share/man/man3/X509_PUBKEY_eq.3ossl | 1 - .../share/man/man3/X509_PUBKEY_free.3ossl | 1 - .../share/man/man3/X509_PUBKEY_get.3ossl | 1 - .../share/man/man3/X509_PUBKEY_get0.3ossl | 1 - .../man/man3/X509_PUBKEY_get0_param.3ossl | 1 - .../share/man/man3/X509_PUBKEY_new.3ossl | 310 --- .../share/man/man3/X509_PUBKEY_new_ex.3ossl | 1 - .../share/man/man3/X509_PUBKEY_set.3ossl | 1 - .../man/man3/X509_PUBKEY_set0_param.3ossl | 1 - .../man3/X509_PUBKEY_set0_public_key.3ossl | 1 - .../share/man/man3/X509_REQ_INFO_free.3ossl | 1 - .../share/man/man3/X509_REQ_INFO_new.3ossl | 1 - .../share/man/man3/X509_REQ_add1_attr.3ossl | 1 - .../man/man3/X509_REQ_add1_attr_by_NID.3ossl | 1 - .../man/man3/X509_REQ_add1_attr_by_OBJ.3ossl | 1 - .../man/man3/X509_REQ_add1_attr_by_txt.3ossl | 1 - .../man/man3/X509_REQ_add_extensions.3ossl | 1 - .../man3/X509_REQ_add_extensions_nid.3ossl | 1 - .../man/man3/X509_REQ_check_private_key.3ossl | 1 - .../share/man/man3/X509_REQ_delete_attr.3ossl | 1 - .../share/man/man3/X509_REQ_digest.3ossl | 1 - .../share/man/man3/X509_REQ_dup.3ossl | 1 - .../share/man/man3/X509_REQ_free.3ossl | 1 - .../X509_REQ_get0_distinguishing_id.3ossl | 1 - .../share/man/man3/X509_REQ_get0_pubkey.3ossl | 1 - .../man/man3/X509_REQ_get0_signature.3ossl | 1 - .../man/man3/X509_REQ_get_X509_PUBKEY.3ossl | 1 - .../share/man/man3/X509_REQ_get_attr.3ossl | 242 -- .../man/man3/X509_REQ_get_attr_by_NID.3ossl | 1 - .../man/man3/X509_REQ_get_attr_by_OBJ.3ossl | 1 - .../man/man3/X509_REQ_get_attr_count.3ossl | 1 - .../man/man3/X509_REQ_get_extensions.3ossl | 185 -- .../share/man/man3/X509_REQ_get_pubkey.3ossl | 1 - .../man/man3/X509_REQ_get_signature_nid.3ossl | 1 - .../man/man3/X509_REQ_get_subject_name.3ossl | 1 - .../share/man/man3/X509_REQ_get_version.3ossl | 1 - .../share/man/man3/X509_REQ_new.3ossl | 1 - .../share/man/man3/X509_REQ_new_ex.3ossl | 1 - .../X509_REQ_set0_distinguishing_id.3ossl | 1 - .../man/man3/X509_REQ_set0_signature.3ossl | 1 - .../man3/X509_REQ_set1_signature_algo.3ossl | 1 - .../share/man/man3/X509_REQ_set_pubkey.3ossl | 1 - .../man/man3/X509_REQ_set_subject_name.3ossl | 1 - .../share/man/man3/X509_REQ_set_version.3ossl | 1 - .../share/man/man3/X509_REQ_sign.3ossl | 1 - .../share/man/man3/X509_REQ_sign_ctx.3ossl | 1 - .../share/man/man3/X509_REQ_verify.3ossl | 1 - .../share/man/man3/X509_REQ_verify_ex.3ossl | 1 - .../man/man3/X509_REVOKED_add1_ext_i2d.3ossl | 1 - .../share/man/man3/X509_REVOKED_add_ext.3ossl | 1 - .../man/man3/X509_REVOKED_delete_ext.3ossl | 1 - .../share/man/man3/X509_REVOKED_dup.3ossl | 1 - .../share/man/man3/X509_REVOKED_free.3ossl | 1 - .../man3/X509_REVOKED_get0_extensions.3ossl | 1 - .../X509_REVOKED_get0_revocationDate.3ossl | 1 - .../man3/X509_REVOKED_get0_serialNumber.3ossl | 1 - .../share/man/man3/X509_REVOKED_get_ext.3ossl | 1 - .../man3/X509_REVOKED_get_ext_by_NID.3ossl | 1 - .../man3/X509_REVOKED_get_ext_by_OBJ.3ossl | 1 - .../X509_REVOKED_get_ext_by_critical.3ossl | 1 - .../man/man3/X509_REVOKED_get_ext_count.3ossl | 1 - .../man/man3/X509_REVOKED_get_ext_d2i.3ossl | 1 - .../share/man/man3/X509_REVOKED_new.3ossl | 1 - .../X509_REVOKED_set_revocationDate.3ossl | 1 - .../man3/X509_REVOKED_set_serialNumber.3ossl | 1 - .../share/man/man3/X509_SIG_INFO_get.3ossl | 1 - .../share/man/man3/X509_SIG_INFO_set.3ossl | 1 - .../share/man/man3/X509_SIG_free.3ossl | 1 - .../share/man/man3/X509_SIG_get0.3ossl | 172 -- .../share/man/man3/X509_SIG_getm.3ossl | 1 - .../share/man/man3/X509_SIG_new.3ossl | 1 - .../share/man/man3/X509_STORE.3ossl | 1 - .../man/man3/X509_STORE_CTX_cert_crl_fn.3ossl | 1 - .../man3/X509_STORE_CTX_check_crl_fn.3ossl | 1 - .../man3/X509_STORE_CTX_check_issued_fn.3ossl | 1 - .../man3/X509_STORE_CTX_check_policy_fn.3ossl | 1 - .../X509_STORE_CTX_check_revocation_fn.3ossl | 1 - .../man/man3/X509_STORE_CTX_cleanup.3ossl | 1 - .../man/man3/X509_STORE_CTX_cleanup_fn.3ossl | 1 - .../share/man/man3/X509_STORE_CTX_free.3ossl | 1 - .../man/man3/X509_STORE_CTX_get0_cert.3ossl | 1 - .../man/man3/X509_STORE_CTX_get0_chain.3ossl | 1 - .../man/man3/X509_STORE_CTX_get0_param.3ossl | 1 - .../man/man3/X509_STORE_CTX_get0_rpk.3ossl | 1 - .../man3/X509_STORE_CTX_get0_untrusted.3ossl | 1 - .../man/man3/X509_STORE_CTX_get1_chain.3ossl | 1 - .../man/man3/X509_STORE_CTX_get1_issuer.3ossl | 1 - .../man3/X509_STORE_CTX_get_app_data.3ossl | 1 - .../man3/X509_STORE_CTX_get_by_subject.3ossl | 183 -- .../man3/X509_STORE_CTX_get_cert_crl.3ossl | 1 - .../man3/X509_STORE_CTX_get_check_crl.3ossl | 1 - .../X509_STORE_CTX_get_check_issued.3ossl | 1 - .../X509_STORE_CTX_get_check_policy.3ossl | 1 - .../X509_STORE_CTX_get_check_revocation.3ossl | 1 - .../man/man3/X509_STORE_CTX_get_cleanup.3ossl | 1 - .../man/man3/X509_STORE_CTX_get_crl_fn.3ossl | 1 - .../X509_STORE_CTX_get_current_cert.3ossl | 1 - .../man/man3/X509_STORE_CTX_get_error.3ossl | 532 ---- .../man3/X509_STORE_CTX_get_error_depth.3ossl | 1 - .../man/man3/X509_STORE_CTX_get_ex_data.3ossl | 1 - .../X509_STORE_CTX_get_ex_new_index.3ossl | 1 - .../man/man3/X509_STORE_CTX_get_get_crl.3ossl | 1 - .../man3/X509_STORE_CTX_get_get_issuer.3ossl | 1 - .../man3/X509_STORE_CTX_get_issuer_fn.3ossl | 1 - .../X509_STORE_CTX_get_lookup_certs.3ossl | 1 - .../man3/X509_STORE_CTX_get_lookup_crls.3ossl | 1 - .../X509_STORE_CTX_get_num_untrusted.3ossl | 1 - .../X509_STORE_CTX_get_obj_by_subject.3ossl | 1 - .../man/man3/X509_STORE_CTX_get_verify.3ossl | 1 - .../man3/X509_STORE_CTX_get_verify_cb.3ossl | 1 - .../share/man/man3/X509_STORE_CTX_init.3ossl | 1 - .../man/man3/X509_STORE_CTX_init_rpk.3ossl | 1 - .../man3/X509_STORE_CTX_lookup_certs_fn.3ossl | 1 - .../man3/X509_STORE_CTX_lookup_crls_fn.3ossl | 1 - .../share/man/man3/X509_STORE_CTX_new.3ossl | 460 ---- .../man/man3/X509_STORE_CTX_new_ex.3ossl | 1 - .../man3/X509_STORE_CTX_print_verify_cb.3ossl | 1 - .../man3/X509_STORE_CTX_purpose_inherit.3ossl | 1 - .../man/man3/X509_STORE_CTX_set0_crls.3ossl | 1 - .../man/man3/X509_STORE_CTX_set0_param.3ossl | 1 - .../man/man3/X509_STORE_CTX_set0_rpk.3ossl | 1 - .../X509_STORE_CTX_set0_trusted_stack.3ossl | 1 - .../man3/X509_STORE_CTX_set0_untrusted.3ossl | 1 - .../X509_STORE_CTX_set0_verified_chain.3ossl | 1 - .../man3/X509_STORE_CTX_set_app_data.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_cert.3ossl | 1 - .../X509_STORE_CTX_set_current_cert.3ossl | 1 - .../X509_STORE_CTX_set_current_reasons.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_default.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_error.3ossl | 1 - .../man3/X509_STORE_CTX_set_error_depth.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_ex_data.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_get_crl.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_purpose.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_trust.3ossl | 1 - .../man/man3/X509_STORE_CTX_set_verify.3ossl | 1 - .../man3/X509_STORE_CTX_set_verify_cb.3ossl | 377 --- .../man/man3/X509_STORE_CTX_verify.3ossl | 1 - .../man/man3/X509_STORE_CTX_verify_cb.3ossl | 1 - .../man/man3/X509_STORE_CTX_verify_fn.3ossl | 1 - .../share/man/man3/X509_STORE_add_cert.3ossl | 303 --- .../share/man/man3/X509_STORE_add_crl.3ossl | 1 - .../man/man3/X509_STORE_add_lookup.3ossl | 1 - .../share/man/man3/X509_STORE_free.3ossl | 1 - .../man/man3/X509_STORE_get0_objects.3ossl | 1 - .../man/man3/X509_STORE_get0_param.3ossl | 206 -- .../man/man3/X509_STORE_get1_all_certs.3ossl | 1 - .../man/man3/X509_STORE_get1_objects.3ossl | 1 - .../man/man3/X509_STORE_get_cert_crl.3ossl | 1 - .../man/man3/X509_STORE_get_check_crl.3ossl | 1 - .../man3/X509_STORE_get_check_issued.3ossl | 1 - .../man3/X509_STORE_get_check_policy.3ossl | 1 - .../X509_STORE_get_check_revocation.3ossl | 1 - .../man/man3/X509_STORE_get_cleanup.3ossl | 1 - .../man/man3/X509_STORE_get_ex_data.3ossl | 1 - .../man3/X509_STORE_get_ex_new_index.3ossl | 1 - .../man/man3/X509_STORE_get_get_crl.3ossl | 1 - .../man/man3/X509_STORE_get_get_issuer.3ossl | 1 - .../man3/X509_STORE_get_lookup_certs.3ossl | 1 - .../man/man3/X509_STORE_get_lookup_crls.3ossl | 1 - .../man/man3/X509_STORE_get_verify_cb.3ossl | 1 - .../share/man/man3/X509_STORE_load_file.3ossl | 1 - .../man/man3/X509_STORE_load_file_ex.3ossl | 1 - .../man/man3/X509_STORE_load_locations.3ossl | 1 - .../man3/X509_STORE_load_locations_ex.3ossl | 1 - .../share/man/man3/X509_STORE_load_path.3ossl | 1 - .../man/man3/X509_STORE_load_store.3ossl | 1 - .../man/man3/X509_STORE_load_store_ex.3ossl | 1 - .../share/man/man3/X509_STORE_lock.3ossl | 1 - .../share/man/man3/X509_STORE_new.3ossl | 191 -- .../man/man3/X509_STORE_set1_param.3ossl | 1 - .../man/man3/X509_STORE_set_cert_crl.3ossl | 1 - .../man/man3/X509_STORE_set_check_crl.3ossl | 1 - .../man3/X509_STORE_set_check_issued.3ossl | 1 - .../man3/X509_STORE_set_check_policy.3ossl | 1 - .../X509_STORE_set_check_revocation.3ossl | 1 - .../man/man3/X509_STORE_set_cleanup.3ossl | 1 - .../man3/X509_STORE_set_default_paths.3ossl | 1 - .../X509_STORE_set_default_paths_ex.3ossl | 1 - .../share/man/man3/X509_STORE_set_depth.3ossl | 1 - .../man/man3/X509_STORE_set_ex_data.3ossl | 1 - .../share/man/man3/X509_STORE_set_flags.3ossl | 1 - .../man/man3/X509_STORE_set_get_crl.3ossl | 1 - .../man/man3/X509_STORE_set_get_issuer.3ossl | 1 - .../man3/X509_STORE_set_lookup_certs.3ossl | 1 - .../man/man3/X509_STORE_set_lookup_crls.3ossl | 1 - .../man3/X509_STORE_set_lookup_crls_cb.3ossl | 1 - .../man/man3/X509_STORE_set_purpose.3ossl | 1 - .../share/man/man3/X509_STORE_set_trust.3ossl | 1 - .../man/man3/X509_STORE_set_verify.3ossl | 1 - .../man/man3/X509_STORE_set_verify_cb.3ossl | 1 - .../man3/X509_STORE_set_verify_cb_func.3ossl | 416 ---- .../man/man3/X509_STORE_set_verify_func.3ossl | 1 - .../share/man/man3/X509_STORE_unlock.3ossl | 1 - .../share/man/man3/X509_STORE_up_ref.3ossl | 1 - .../share/man/man3/X509_VAL_free.3ossl | 1 - .../share/man/man3/X509_VAL_new.3ossl | 1 - .../man3/X509_VERIFY_PARAM_add0_policy.3ossl | 1 - .../man3/X509_VERIFY_PARAM_add1_host.3ossl | 1 - .../man3/X509_VERIFY_PARAM_clear_flags.3ossl | 1 - .../man3/X509_VERIFY_PARAM_get0_email.3ossl | 1 - .../man3/X509_VERIFY_PARAM_get0_host.3ossl | 1 - .../X509_VERIFY_PARAM_get0_peername.3ossl | 1 - .../man3/X509_VERIFY_PARAM_get1_ip_asc.3ossl | 1 - .../X509_VERIFY_PARAM_get_auth_level.3ossl | 1 - .../man3/X509_VERIFY_PARAM_get_depth.3ossl | 1 - .../man3/X509_VERIFY_PARAM_get_flags.3ossl | 1 - .../X509_VERIFY_PARAM_get_hostflags.3ossl | 1 - .../X509_VERIFY_PARAM_get_inh_flags.3ossl | 1 - .../man/man3/X509_VERIFY_PARAM_get_time.3ossl | 1 - .../man3/X509_VERIFY_PARAM_set1_email.3ossl | 1 - .../man3/X509_VERIFY_PARAM_set1_host.3ossl | 1 - .../man/man3/X509_VERIFY_PARAM_set1_ip.3ossl | 1 - .../man3/X509_VERIFY_PARAM_set1_ip_asc.3ossl | 1 - .../X509_VERIFY_PARAM_set1_policies.3ossl | 1 - .../X509_VERIFY_PARAM_set_auth_level.3ossl | 1 - .../man3/X509_VERIFY_PARAM_set_depth.3ossl | 1 - .../man3/X509_VERIFY_PARAM_set_flags.3ossl | 545 ---- .../X509_VERIFY_PARAM_set_hostflags.3ossl | 1 - .../X509_VERIFY_PARAM_set_inh_flags.3ossl | 1 - .../man3/X509_VERIFY_PARAM_set_purpose.3ossl | 1 - .../man/man3/X509_VERIFY_PARAM_set_time.3ossl | 1 - .../man3/X509_VERIFY_PARAM_set_trust.3ossl | 1 - .../share/man/man3/X509_add1_ext_i2d.3ossl | 1 - .../share/man/man3/X509_add_cert.3ossl | 207 -- .../share/man/man3/X509_add_certs.3ossl | 1 - .../share/man/man3/X509_add_ext.3ossl | 1 - .../share/man/man3/X509_build_chain.3ossl | 1 - .../share/man/man3/X509_chain_up_ref.3ossl | 1 - .../share/man/man3/X509_check_ca.3ossl | 180 -- .../share/man/man3/X509_check_email.3ossl | 1 - .../share/man/man3/X509_check_host.3ossl | 292 --- .../share/man/man3/X509_check_ip.3ossl | 1 - .../share/man/man3/X509_check_ip_asc.3ossl | 1 - .../share/man/man3/X509_check_issued.3ossl | 177 -- .../man/man3/X509_check_private_key.3ossl | 185 -- .../share/man/man3/X509_check_purpose.3ossl | 209 -- openssl-install/share/man/man3/X509_cmp.3ossl | 217 -- .../man/man3/X509_cmp_current_time.3ossl | 1 - .../share/man/man3/X509_cmp_time.3ossl | 219 -- .../share/man/man3/X509_cmp_timeframe.3ossl | 1 - .../share/man/man3/X509_delete_ext.3ossl | 1 - .../share/man/man3/X509_digest.3ossl | 222 -- .../share/man/man3/X509_digest_sig.3ossl | 1 - openssl-install/share/man/man3/X509_dup.3ossl | 590 ----- .../share/man/man3/X509_free.3ossl | 1 - .../man/man3/X509_get0_authority_issuer.3ossl | 1 - .../man/man3/X509_get0_authority_key_id.3ossl | 1 - .../man/man3/X509_get0_authority_serial.3ossl | 1 - .../man3/X509_get0_distinguishing_id.3ossl | 200 -- .../share/man/man3/X509_get0_extensions.3ossl | 1 - .../share/man/man3/X509_get0_notAfter.3ossl | 1 - .../share/man/man3/X509_get0_notBefore.3ossl | 260 -- .../share/man/man3/X509_get0_pubkey.3ossl | 1 - .../man/man3/X509_get0_serialNumber.3ossl | 1 - .../share/man/man3/X509_get0_signature.3ossl | 290 --- .../man/man3/X509_get0_subject_key_id.3ossl | 1 - .../share/man/man3/X509_get0_tbs_sigalg.3ossl | 1 - .../share/man/man3/X509_get0_uids.3ossl | 204 -- .../share/man/man3/X509_get_X509_PUBKEY.3ossl | 1 - .../man/man3/X509_get_default_cert_dir.3ossl | 1 - .../man3/X509_get_default_cert_dir_env.3ossl | 1 - .../man/man3/X509_get_default_cert_file.3ossl | 217 -- .../man3/X509_get_default_cert_file_env.3ossl | 1 - .../share/man/man3/X509_get_ex_data.3ossl | 1 - .../man/man3/X509_get_ex_new_index.3ossl | 1 - .../share/man/man3/X509_get_ext.3ossl | 1 - .../share/man/man3/X509_get_ext_by_NID.3ossl | 1 - .../share/man/man3/X509_get_ext_by_OBJ.3ossl | 1 - .../man/man3/X509_get_ext_by_critical.3ossl | 1 - .../share/man/man3/X509_get_ext_count.3ossl | 1 - .../share/man/man3/X509_get_ext_d2i.3ossl | 1 - .../man3/X509_get_extended_key_usage.3ossl | 1 - .../man/man3/X509_get_extension_flags.3ossl | 322 --- .../share/man/man3/X509_get_issuer_name.3ossl | 1 - .../share/man/man3/X509_get_key_usage.3ossl | 1 - .../share/man/man3/X509_get_pathlen.3ossl | 1 - .../man/man3/X509_get_proxy_pathlen.3ossl | 1 - .../share/man/man3/X509_get_pubkey.3ossl | 218 -- .../man/man3/X509_get_serialNumber.3ossl | 219 -- .../man/man3/X509_get_signature_info.3ossl | 1 - .../man/man3/X509_get_signature_nid.3ossl | 1 - .../man/man3/X509_get_subject_name.3ossl | 271 -- .../share/man/man3/X509_get_version.3ossl | 223 -- .../share/man/man3/X509_getm_notAfter.3ossl | 1 - .../share/man/man3/X509_getm_notBefore.3ossl | 1 - .../share/man/man3/X509_gmtime_adj.3ossl | 1 - .../share/man/man3/X509_http_nbio.3ossl | 1 - .../man/man3/X509_issuer_and_serial_cmp.3ossl | 1 - .../share/man/man3/X509_issuer_name_cmp.3ossl | 1 - .../man/man3/X509_issuer_name_hash.3ossl | 1 - .../man/man3/X509_load_cert_crl_file.3ossl | 1 - .../man/man3/X509_load_cert_crl_file_ex.3ossl | 1 - .../share/man/man3/X509_load_cert_file.3ossl | 1 - .../man/man3/X509_load_cert_file_ex.3ossl | 1 - .../share/man/man3/X509_load_crl_file.3ossl | 1 - .../share/man/man3/X509_load_http.3ossl | 204 -- openssl-install/share/man/man3/X509_new.3ossl | 238 -- .../share/man/man3/X509_new_ex.3ossl | 1 - .../share/man/man3/X509_pubkey_digest.3ossl | 1 - .../share/man/man3/X509_self_signed.3ossl | 1 - .../man3/X509_set0_distinguishing_id.3ossl | 1 - .../share/man/man3/X509_set1_notAfter.3ossl | 1 - .../share/man/man3/X509_set1_notBefore.3ossl | 1 - .../share/man/man3/X509_set_ex_data.3ossl | 1 - .../share/man/man3/X509_set_issuer_name.3ossl | 1 - .../share/man/man3/X509_set_proxy_flag.3ossl | 1 - .../man/man3/X509_set_proxy_pathlen.3ossl | 1 - .../share/man/man3/X509_set_pubkey.3ossl | 1 - .../man/man3/X509_set_serialNumber.3ossl | 1 - .../man/man3/X509_set_subject_name.3ossl | 1 - .../share/man/man3/X509_set_version.3ossl | 1 - .../share/man/man3/X509_sign.3ossl | 220 -- .../share/man/man3/X509_sign_ctx.3ossl | 1 - .../man/man3/X509_subject_name_cmp.3ossl | 1 - .../man/man3/X509_subject_name_hash.3ossl | 1 - .../share/man/man3/X509_time_adj.3ossl | 1 - .../share/man/man3/X509_time_adj_ex.3ossl | 1 - .../share/man/man3/X509_up_ref.3ossl | 1 - .../share/man/man3/X509_verify.3ossl | 220 -- .../share/man/man3/X509_verify_cert.3ossl | 243 -- .../man3/X509_verify_cert_error_string.3ossl | 1 - .../share/man/man3/X509at_add1_attr.3ossl | 1 - .../man/man3/X509at_add1_attr_by_NID.3ossl | 1 - .../man/man3/X509at_add1_attr_by_OBJ.3ossl | 1 - .../man/man3/X509at_add1_attr_by_txt.3ossl | 1 - .../share/man/man3/X509at_delete_attr.3ossl | 1 - .../man/man3/X509at_get0_data_by_OBJ.3ossl | 1 - .../share/man/man3/X509at_get_attr.3ossl | 1 - .../man/man3/X509at_get_attr_by_NID.3ossl | 1 - .../man/man3/X509at_get_attr_by_OBJ.3ossl | 1 - .../man/man3/X509at_get_attr_count.3ossl | 1 - .../share/man/man3/X509v3_add_ext.3ossl | 1 - .../man/man3/X509v3_add_extensions.3ossl | 1 - .../share/man/man3/X509v3_delete_ext.3ossl | 1 - .../share/man/man3/X509v3_get_ext.3ossl | 1 - .../man/man3/X509v3_get_ext_by_NID.3ossl | 298 --- .../man/man3/X509v3_get_ext_by_OBJ.3ossl | 1 - .../man/man3/X509v3_get_ext_by_critical.3ossl | 1 - .../share/man/man3/X509v3_get_ext_count.3ossl | 1 - .../share/man/man3/b2i_PVK_bio.3ossl | 1 - .../share/man/man3/b2i_PVK_bio_ex.3ossl | 200 -- .../share/man/man3/custom_ext_add_cb.3ossl | 1 - .../share/man/man3/custom_ext_free_cb.3ossl | 1 - .../share/man/man3/custom_ext_parse_cb.3ossl | 1 - .../man/man3/d2i_ACCESS_DESCRIPTION.3ossl | 1 - .../share/man/man3/d2i_ADMISSIONS.3ossl | 1 - .../share/man/man3/d2i_ADMISSION_SYNTAX.3ossl | 1 - .../share/man/man3/d2i_ASIdOrRange.3ossl | 1 - .../man/man3/d2i_ASIdentifierChoice.3ossl | 1 - .../share/man/man3/d2i_ASIdentifiers.3ossl | 1 - .../share/man/man3/d2i_ASN1_BIT_STRING.3ossl | 1 - .../share/man/man3/d2i_ASN1_BMPSTRING.3ossl | 1 - .../share/man/man3/d2i_ASN1_ENUMERATED.3ossl | 1 - .../man/man3/d2i_ASN1_GENERALIZEDTIME.3ossl | 1 - .../man/man3/d2i_ASN1_GENERALSTRING.3ossl | 1 - .../share/man/man3/d2i_ASN1_IA5STRING.3ossl | 1 - .../share/man/man3/d2i_ASN1_INTEGER.3ossl | 1 - .../share/man/man3/d2i_ASN1_NULL.3ossl | 1 - .../share/man/man3/d2i_ASN1_OBJECT.3ossl | 1 - .../man/man3/d2i_ASN1_OCTET_STRING.3ossl | 1 - .../share/man/man3/d2i_ASN1_PRINTABLE.3ossl | 1 - .../man/man3/d2i_ASN1_PRINTABLESTRING.3ossl | 1 - .../man/man3/d2i_ASN1_SEQUENCE_ANY.3ossl | 1 - .../share/man/man3/d2i_ASN1_SET_ANY.3ossl | 1 - .../share/man/man3/d2i_ASN1_T61STRING.3ossl | 1 - .../share/man/man3/d2i_ASN1_TIME.3ossl | 1 - .../share/man/man3/d2i_ASN1_TYPE.3ossl | 1 - .../share/man/man3/d2i_ASN1_UINTEGER.3ossl | 1 - .../man/man3/d2i_ASN1_UNIVERSALSTRING.3ossl | 1 - .../share/man/man3/d2i_ASN1_UTCTIME.3ossl | 1 - .../share/man/man3/d2i_ASN1_UTF8STRING.3ossl | 1 - .../man/man3/d2i_ASN1_VISIBLESTRING.3ossl | 1 - .../share/man/man3/d2i_ASRange.3ossl | 1 - .../man/man3/d2i_AUTHORITY_INFO_ACCESS.3ossl | 1 - .../share/man/man3/d2i_AUTHORITY_KEYID.3ossl | 1 - .../share/man/man3/d2i_AutoPrivateKey.3ossl | 1 - .../man/man3/d2i_AutoPrivateKey_ex.3ossl | 1 - .../man/man3/d2i_BASIC_CONSTRAINTS.3ossl | 1 - .../man/man3/d2i_CERTIFICATEPOLICIES.3ossl | 1 - .../share/man/man3/d2i_CMS_ContentInfo.3ossl | 1 - .../man/man3/d2i_CMS_ReceiptRequest.3ossl | 1 - .../share/man/man3/d2i_CMS_bio.3ossl | 1 - .../share/man/man3/d2i_CRL_DIST_POINTS.3ossl | 1 - .../share/man/man3/d2i_DHparams.3ossl | 1 - .../share/man/man3/d2i_DHparams_bio.3ossl | 1 - .../share/man/man3/d2i_DHparams_fp.3ossl | 1 - .../share/man/man3/d2i_DHxparams.3ossl | 1 - .../share/man/man3/d2i_DIRECTORYSTRING.3ossl | 1 - .../share/man/man3/d2i_DISPLAYTEXT.3ossl | 1 - .../share/man/man3/d2i_DIST_POINT.3ossl | 1 - .../share/man/man3/d2i_DIST_POINT_NAME.3ossl | 1 - .../share/man/man3/d2i_DSAPrivateKey.3ossl | 1 - .../man/man3/d2i_DSAPrivateKey_bio.3ossl | 1 - .../share/man/man3/d2i_DSAPrivateKey_fp.3ossl | 1 - .../share/man/man3/d2i_DSAPublicKey.3ossl | 1 - .../share/man/man3/d2i_DSA_PUBKEY.3ossl | 1 - .../share/man/man3/d2i_DSA_PUBKEY_bio.3ossl | 1 - .../share/man/man3/d2i_DSA_PUBKEY_fp.3ossl | 1 - .../share/man/man3/d2i_DSA_SIG.3ossl | 1 - .../share/man/man3/d2i_DSAparams.3ossl | 1 - .../share/man/man3/d2i_ECDSA_SIG.3ossl | 1 - .../share/man/man3/d2i_ECPKParameters.3ossl | 1 - .../share/man/man3/d2i_ECParameters.3ossl | 1 - .../share/man/man3/d2i_ECPrivateKey.3ossl | 1 - .../share/man/man3/d2i_ECPrivateKey_bio.3ossl | 1 - .../share/man/man3/d2i_ECPrivateKey_fp.3ossl | 1 - .../share/man/man3/d2i_EC_PUBKEY.3ossl | 1 - .../share/man/man3/d2i_EC_PUBKEY_bio.3ossl | 1 - .../share/man/man3/d2i_EC_PUBKEY_fp.3ossl | 1 - .../share/man/man3/d2i_EDIPARTYNAME.3ossl | 1 - .../share/man/man3/d2i_ESS_CERT_ID.3ossl | 1 - .../share/man/man3/d2i_ESS_CERT_ID_V2.3ossl | 1 - .../man/man3/d2i_ESS_ISSUER_SERIAL.3ossl | 1 - .../share/man/man3/d2i_ESS_SIGNING_CERT.3ossl | 1 - .../man/man3/d2i_ESS_SIGNING_CERT_V2.3ossl | 1 - .../man/man3/d2i_EXTENDED_KEY_USAGE.3ossl | 1 - .../share/man/man3/d2i_GENERAL_NAME.3ossl | 1 - .../share/man/man3/d2i_GENERAL_NAMES.3ossl | 1 - .../share/man/man3/d2i_IPAddressChoice.3ossl | 1 - .../share/man/man3/d2i_IPAddressFamily.3ossl | 1 - .../share/man/man3/d2i_IPAddressOrRange.3ossl | 1 - .../share/man/man3/d2i_IPAddressRange.3ossl | 1 - .../share/man/man3/d2i_ISSUER_SIGN_TOOL.3ossl | 1 - .../man/man3/d2i_ISSUING_DIST_POINT.3ossl | 1 - .../share/man/man3/d2i_KeyParams.3ossl | 1 - .../share/man/man3/d2i_KeyParams_bio.3ossl | 1 - .../share/man/man3/d2i_NAMING_AUTHORITY.3ossl | 1 - .../man/man3/d2i_NETSCAPE_CERT_SEQUENCE.3ossl | 1 - .../share/man/man3/d2i_NETSCAPE_SPKAC.3ossl | 1 - .../share/man/man3/d2i_NETSCAPE_SPKI.3ossl | 1 - .../share/man/man3/d2i_NOTICEREF.3ossl | 1 - .../share/man/man3/d2i_OCSP_BASICRESP.3ossl | 1 - .../share/man/man3/d2i_OCSP_CERTID.3ossl | 1 - .../share/man/man3/d2i_OCSP_CERTSTATUS.3ossl | 1 - .../share/man/man3/d2i_OCSP_CRLID.3ossl | 1 - .../share/man/man3/d2i_OCSP_ONEREQ.3ossl | 1 - .../share/man/man3/d2i_OCSP_REQINFO.3ossl | 1 - .../share/man/man3/d2i_OCSP_REQUEST.3ossl | 1 - .../share/man/man3/d2i_OCSP_RESPBYTES.3ossl | 1 - .../share/man/man3/d2i_OCSP_RESPDATA.3ossl | 1 - .../share/man/man3/d2i_OCSP_RESPID.3ossl | 1 - .../share/man/man3/d2i_OCSP_RESPONSE.3ossl | 1 - .../share/man/man3/d2i_OCSP_REVOKEDINFO.3ossl | 1 - .../share/man/man3/d2i_OCSP_SERVICELOC.3ossl | 1 - .../share/man/man3/d2i_OCSP_SIGNATURE.3ossl | 1 - .../share/man/man3/d2i_OCSP_SINGLERESP.3ossl | 1 - .../man/man3/d2i_OSSL_ATTRIBUTES_SYNTAX.3ossl | 1 - .../d2i_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl | 1 - .../share/man/man3/d2i_OSSL_CMP_ATAVS.3ossl | 1 - .../share/man/man3/d2i_OSSL_CMP_MSG.3ossl | 1 - .../share/man/man3/d2i_OSSL_CMP_MSG_bio.3ossl | 1 - .../man/man3/d2i_OSSL_CMP_PKIHEADER.3ossl | 1 - .../share/man/man3/d2i_OSSL_CMP_PKISI.3ossl | 1 - .../share/man/man3/d2i_OSSL_CRMF_CERTID.3ossl | 1 - .../man/man3/d2i_OSSL_CRMF_CERTTEMPLATE.3ossl | 1 - .../man3/d2i_OSSL_CRMF_ENCRYPTEDVALUE.3ossl | 1 - .../share/man/man3/d2i_OSSL_CRMF_MSG.3ossl | 1 - .../share/man/man3/d2i_OSSL_CRMF_MSGS.3ossl | 1 - .../man/man3/d2i_OSSL_CRMF_PBMPARAMETER.3ossl | 1 - .../d2i_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl | 1 - .../man3/d2i_OSSL_CRMF_SINGLEPUBINFO.3ossl | 1 - .../man/man3/d2i_OSSL_IETF_ATTR_SYNTAX.3ossl | 1 - .../man/man3/d2i_OSSL_ISSUER_SERIAL.3ossl | 1 - .../man3/d2i_OSSL_OBJECT_DIGEST_INFO.3ossl | 1 - .../share/man/man3/d2i_OSSL_TARGET.3ossl | 1 - .../man3/d2i_OSSL_TARGETING_INFORMATION.3ossl | 1 - .../share/man/man3/d2i_OSSL_TARGETS.3ossl | 1 - .../share/man/man3/d2i_OSSL_TARGET_CERT.3ossl | 1 - .../man3/d2i_OSSL_USER_NOTICE_SYNTAX.3ossl | 1 - .../share/man/man3/d2i_OTHERNAME.3ossl | 1 - .../share/man/man3/d2i_PBE2PARAM.3ossl | 1 - .../share/man/man3/d2i_PBEPARAM.3ossl | 1 - .../share/man/man3/d2i_PBKDF2PARAM.3ossl | 1 - .../share/man/man3/d2i_PBMAC1PARAM.3ossl | 1 - .../share/man/man3/d2i_PKCS12.3ossl | 1 - .../share/man/man3/d2i_PKCS12_BAGS.3ossl | 1 - .../share/man/man3/d2i_PKCS12_MAC_DATA.3ossl | 1 - .../share/man/man3/d2i_PKCS12_SAFEBAG.3ossl | 1 - .../share/man/man3/d2i_PKCS12_bio.3ossl | 1 - .../share/man/man3/d2i_PKCS12_fp.3ossl | 1 - .../share/man/man3/d2i_PKCS7.3ossl | 1 - .../share/man/man3/d2i_PKCS7_DIGEST.3ossl | 1 - .../share/man/man3/d2i_PKCS7_ENCRYPT.3ossl | 1 - .../man/man3/d2i_PKCS7_ENC_CONTENT.3ossl | 1 - .../share/man/man3/d2i_PKCS7_ENVELOPE.3ossl | 1 - .../man3/d2i_PKCS7_ISSUER_AND_SERIAL.3ossl | 1 - .../share/man/man3/d2i_PKCS7_RECIP_INFO.3ossl | 1 - .../share/man/man3/d2i_PKCS7_SIGNED.3ossl | 1 - .../man/man3/d2i_PKCS7_SIGNER_INFO.3ossl | 1 - .../man/man3/d2i_PKCS7_SIGN_ENVELOPE.3ossl | 1 - .../share/man/man3/d2i_PKCS7_bio.3ossl | 1 - .../share/man/man3/d2i_PKCS7_fp.3ossl | 1 - .../man/man3/d2i_PKCS8PrivateKey_bio.3ossl | 205 -- .../man/man3/d2i_PKCS8PrivateKey_fp.3ossl | 1 - .../man/man3/d2i_PKCS8_PRIV_KEY_INFO.3ossl | 1 - .../man3/d2i_PKCS8_PRIV_KEY_INFO_bio.3ossl | 1 - .../man/man3/d2i_PKCS8_PRIV_KEY_INFO_fp.3ossl | 1 - .../share/man/man3/d2i_PKCS8_bio.3ossl | 1 - .../share/man/man3/d2i_PKCS8_fp.3ossl | 1 - .../man/man3/d2i_PKEY_USAGE_PERIOD.3ossl | 1 - .../share/man/man3/d2i_POLICYINFO.3ossl | 1 - .../share/man/man3/d2i_POLICYQUALINFO.3ossl | 1 - .../share/man/man3/d2i_PROFESSION_INFO.3ossl | 1 - .../man3/d2i_PROXY_CERT_INFO_EXTENSION.3ossl | 1 - .../share/man/man3/d2i_PROXY_POLICY.3ossl | 1 - .../share/man/man3/d2i_PUBKEY.3ossl | 1 - .../share/man/man3/d2i_PUBKEY_bio.3ossl | 1 - .../share/man/man3/d2i_PUBKEY_ex.3ossl | 1 - .../share/man/man3/d2i_PUBKEY_ex_bio.3ossl | 1 - .../share/man/man3/d2i_PUBKEY_ex_fp.3ossl | 1 - .../share/man/man3/d2i_PUBKEY_fp.3ossl | 1 - .../share/man/man3/d2i_PrivateKey.3ossl | 265 -- .../share/man/man3/d2i_PrivateKey_bio.3ossl | 1 - .../share/man/man3/d2i_PrivateKey_ex.3ossl | 1 - .../man/man3/d2i_PrivateKey_ex_bio.3ossl | 1 - .../share/man/man3/d2i_PrivateKey_ex_fp.3ossl | 1 - .../share/man/man3/d2i_PrivateKey_fp.3ossl | 1 - .../share/man/man3/d2i_PublicKey.3ossl | 1 - .../share/man/man3/d2i_RSAPrivateKey.3ossl | 426 ---- .../man/man3/d2i_RSAPrivateKey_bio.3ossl | 1 - .../share/man/man3/d2i_RSAPrivateKey_fp.3ossl | 1 - .../share/man/man3/d2i_RSAPublicKey.3ossl | 1 - .../share/man/man3/d2i_RSAPublicKey_bio.3ossl | 1 - .../share/man/man3/d2i_RSAPublicKey_fp.3ossl | 1 - .../share/man/man3/d2i_RSA_OAEP_PARAMS.3ossl | 1 - .../share/man/man3/d2i_RSA_PSS_PARAMS.3ossl | 1 - .../share/man/man3/d2i_RSA_PUBKEY.3ossl | 1 - .../share/man/man3/d2i_RSA_PUBKEY_bio.3ossl | 1 - .../share/man/man3/d2i_RSA_PUBKEY_fp.3ossl | 1 - .../share/man/man3/d2i_SCRYPT_PARAMS.3ossl | 1 - .../share/man/man3/d2i_SCT_LIST.3ossl | 1 - .../share/man/man3/d2i_SSL_SESSION.3ossl | 189 -- .../share/man/man3/d2i_SSL_SESSION_ex.3ossl | 1 - .../share/man/man3/d2i_SXNET.3ossl | 1 - .../share/man/man3/d2i_SXNETID.3ossl | 1 - .../share/man/man3/d2i_TS_ACCURACY.3ossl | 1 - .../share/man/man3/d2i_TS_MSG_IMPRINT.3ossl | 1 - .../man/man3/d2i_TS_MSG_IMPRINT_bio.3ossl | 1 - .../man/man3/d2i_TS_MSG_IMPRINT_fp.3ossl | 1 - .../share/man/man3/d2i_TS_REQ.3ossl | 1 - .../share/man/man3/d2i_TS_REQ_bio.3ossl | 1 - .../share/man/man3/d2i_TS_REQ_fp.3ossl | 1 - .../share/man/man3/d2i_TS_RESP.3ossl | 1 - .../share/man/man3/d2i_TS_RESP_bio.3ossl | 1 - .../share/man/man3/d2i_TS_RESP_fp.3ossl | 1 - .../share/man/man3/d2i_TS_STATUS_INFO.3ossl | 1 - .../share/man/man3/d2i_TS_TST_INFO.3ossl | 1 - .../share/man/man3/d2i_TS_TST_INFO_bio.3ossl | 1 - .../share/man/man3/d2i_TS_TST_INFO_fp.3ossl | 1 - .../share/man/man3/d2i_USERNOTICE.3ossl | 1 - openssl-install/share/man/man3/d2i_X509.3ossl | 777 ------ .../share/man/man3/d2i_X509_ACERT.3ossl | 1 - .../share/man/man3/d2i_X509_ACERT_bio.3ossl | 1 - .../share/man/man3/d2i_X509_ACERT_fp.3ossl | 1 - .../share/man/man3/d2i_X509_ALGOR.3ossl | 1 - .../share/man/man3/d2i_X509_ALGORS.3ossl | 1 - .../share/man/man3/d2i_X509_ATTRIBUTE.3ossl | 1 - .../share/man/man3/d2i_X509_AUX.3ossl | 1 - .../share/man/man3/d2i_X509_CERT_AUX.3ossl | 1 - .../share/man/man3/d2i_X509_CINF.3ossl | 1 - .../share/man/man3/d2i_X509_CRL.3ossl | 1 - .../share/man/man3/d2i_X509_CRL_INFO.3ossl | 1 - .../share/man/man3/d2i_X509_CRL_bio.3ossl | 1 - .../share/man/man3/d2i_X509_CRL_fp.3ossl | 1 - .../share/man/man3/d2i_X509_EXTENSION.3ossl | 1 - .../share/man/man3/d2i_X509_EXTENSIONS.3ossl | 1 - .../share/man/man3/d2i_X509_NAME.3ossl | 1 - .../share/man/man3/d2i_X509_NAME_ENTRY.3ossl | 1 - .../share/man/man3/d2i_X509_PUBKEY.3ossl | 1 - .../share/man/man3/d2i_X509_PUBKEY_bio.3ossl | 1 - .../share/man/man3/d2i_X509_PUBKEY_fp.3ossl | 1 - .../share/man/man3/d2i_X509_REQ.3ossl | 1 - .../share/man/man3/d2i_X509_REQ_INFO.3ossl | 1 - .../share/man/man3/d2i_X509_REQ_bio.3ossl | 1 - .../share/man/man3/d2i_X509_REQ_fp.3ossl | 1 - .../share/man/man3/d2i_X509_REVOKED.3ossl | 1 - .../share/man/man3/d2i_X509_SIG.3ossl | 1 - .../share/man/man3/d2i_X509_VAL.3ossl | 1 - .../share/man/man3/d2i_X509_bio.3ossl | 1 - .../share/man/man3/d2i_X509_fp.3ossl | 1 - .../share/man/man3/i2b_PVK_bio.3ossl | 1 - .../share/man/man3/i2b_PVK_bio_ex.3ossl | 1 - .../man/man3/i2d_ACCESS_DESCRIPTION.3ossl | 1 - .../share/man/man3/i2d_ADMISSIONS.3ossl | 1 - .../share/man/man3/i2d_ADMISSION_SYNTAX.3ossl | 1 - .../share/man/man3/i2d_ASIdOrRange.3ossl | 1 - .../man/man3/i2d_ASIdentifierChoice.3ossl | 1 - .../share/man/man3/i2d_ASIdentifiers.3ossl | 1 - .../share/man/man3/i2d_ASN1_BIT_STRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_BMPSTRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_ENUMERATED.3ossl | 1 - .../man/man3/i2d_ASN1_GENERALIZEDTIME.3ossl | 1 - .../man/man3/i2d_ASN1_GENERALSTRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_IA5STRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_INTEGER.3ossl | 1 - .../share/man/man3/i2d_ASN1_NULL.3ossl | 1 - .../share/man/man3/i2d_ASN1_OBJECT.3ossl | 1 - .../man/man3/i2d_ASN1_OCTET_STRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_PRINTABLE.3ossl | 1 - .../man/man3/i2d_ASN1_PRINTABLESTRING.3ossl | 1 - .../man/man3/i2d_ASN1_SEQUENCE_ANY.3ossl | 1 - .../share/man/man3/i2d_ASN1_SET_ANY.3ossl | 1 - .../share/man/man3/i2d_ASN1_T61STRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_TIME.3ossl | 1 - .../share/man/man3/i2d_ASN1_TYPE.3ossl | 1 - .../man/man3/i2d_ASN1_UNIVERSALSTRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_UTCTIME.3ossl | 1 - .../share/man/man3/i2d_ASN1_UTF8STRING.3ossl | 1 - .../man/man3/i2d_ASN1_VISIBLESTRING.3ossl | 1 - .../share/man/man3/i2d_ASN1_bio_stream.3ossl | 1 - .../share/man/man3/i2d_ASRange.3ossl | 1 - .../man/man3/i2d_AUTHORITY_INFO_ACCESS.3ossl | 1 - .../share/man/man3/i2d_AUTHORITY_KEYID.3ossl | 1 - .../man/man3/i2d_BASIC_CONSTRAINTS.3ossl | 1 - .../man/man3/i2d_CERTIFICATEPOLICIES.3ossl | 1 - .../share/man/man3/i2d_CMS_ContentInfo.3ossl | 1 - .../man/man3/i2d_CMS_ReceiptRequest.3ossl | 1 - .../share/man/man3/i2d_CMS_bio.3ossl | 1 - .../share/man/man3/i2d_CMS_bio_stream.3ossl | 182 -- .../share/man/man3/i2d_CRL_DIST_POINTS.3ossl | 1 - .../share/man/man3/i2d_DHparams.3ossl | 1 - .../share/man/man3/i2d_DHparams_bio.3ossl | 1 - .../share/man/man3/i2d_DHparams_fp.3ossl | 1 - .../share/man/man3/i2d_DHxparams.3ossl | 1 - .../share/man/man3/i2d_DIRECTORYSTRING.3ossl | 1 - .../share/man/man3/i2d_DISPLAYTEXT.3ossl | 1 - .../share/man/man3/i2d_DIST_POINT.3ossl | 1 - .../share/man/man3/i2d_DIST_POINT_NAME.3ossl | 1 - .../share/man/man3/i2d_DSAPrivateKey.3ossl | 1 - .../man/man3/i2d_DSAPrivateKey_bio.3ossl | 1 - .../share/man/man3/i2d_DSAPrivateKey_fp.3ossl | 1 - .../share/man/man3/i2d_DSAPublicKey.3ossl | 1 - .../share/man/man3/i2d_DSA_PUBKEY.3ossl | 1 - .../share/man/man3/i2d_DSA_PUBKEY_bio.3ossl | 1 - .../share/man/man3/i2d_DSA_PUBKEY_fp.3ossl | 1 - .../share/man/man3/i2d_DSA_SIG.3ossl | 1 - .../share/man/man3/i2d_DSAparams.3ossl | 1 - .../share/man/man3/i2d_ECDSA_SIG.3ossl | 1 - .../share/man/man3/i2d_ECPKParameters.3ossl | 1 - .../share/man/man3/i2d_ECParameters.3ossl | 1 - .../share/man/man3/i2d_ECPrivateKey.3ossl | 1 - .../share/man/man3/i2d_ECPrivateKey_bio.3ossl | 1 - .../share/man/man3/i2d_ECPrivateKey_fp.3ossl | 1 - .../share/man/man3/i2d_EC_PUBKEY.3ossl | 1 - .../share/man/man3/i2d_EC_PUBKEY_bio.3ossl | 1 - .../share/man/man3/i2d_EC_PUBKEY_fp.3ossl | 1 - .../share/man/man3/i2d_EDIPARTYNAME.3ossl | 1 - .../share/man/man3/i2d_ESS_CERT_ID.3ossl | 1 - .../share/man/man3/i2d_ESS_CERT_ID_V2.3ossl | 1 - .../man/man3/i2d_ESS_ISSUER_SERIAL.3ossl | 1 - .../share/man/man3/i2d_ESS_SIGNING_CERT.3ossl | 1 - .../man/man3/i2d_ESS_SIGNING_CERT_V2.3ossl | 1 - .../man/man3/i2d_EXTENDED_KEY_USAGE.3ossl | 1 - .../share/man/man3/i2d_GENERAL_NAME.3ossl | 1 - .../share/man/man3/i2d_GENERAL_NAMES.3ossl | 1 - .../share/man/man3/i2d_IPAddressChoice.3ossl | 1 - .../share/man/man3/i2d_IPAddressFamily.3ossl | 1 - .../share/man/man3/i2d_IPAddressOrRange.3ossl | 1 - .../share/man/man3/i2d_IPAddressRange.3ossl | 1 - .../share/man/man3/i2d_ISSUER_SIGN_TOOL.3ossl | 1 - .../man/man3/i2d_ISSUING_DIST_POINT.3ossl | 1 - .../share/man/man3/i2d_KeyParams.3ossl | 1 - .../share/man/man3/i2d_KeyParams_bio.3ossl | 1 - .../share/man/man3/i2d_NAMING_AUTHORITY.3ossl | 1 - .../man/man3/i2d_NETSCAPE_CERT_SEQUENCE.3ossl | 1 - .../share/man/man3/i2d_NETSCAPE_SPKAC.3ossl | 1 - .../share/man/man3/i2d_NETSCAPE_SPKI.3ossl | 1 - .../share/man/man3/i2d_NOTICEREF.3ossl | 1 - .../share/man/man3/i2d_OCSP_BASICRESP.3ossl | 1 - .../share/man/man3/i2d_OCSP_CERTID.3ossl | 1 - .../share/man/man3/i2d_OCSP_CERTSTATUS.3ossl | 1 - .../share/man/man3/i2d_OCSP_CRLID.3ossl | 1 - .../share/man/man3/i2d_OCSP_ONEREQ.3ossl | 1 - .../share/man/man3/i2d_OCSP_REQINFO.3ossl | 1 - .../share/man/man3/i2d_OCSP_REQUEST.3ossl | 1 - .../share/man/man3/i2d_OCSP_RESPBYTES.3ossl | 1 - .../share/man/man3/i2d_OCSP_RESPDATA.3ossl | 1 - .../share/man/man3/i2d_OCSP_RESPID.3ossl | 1 - .../share/man/man3/i2d_OCSP_RESPONSE.3ossl | 1 - .../share/man/man3/i2d_OCSP_REVOKEDINFO.3ossl | 1 - .../share/man/man3/i2d_OCSP_SERVICELOC.3ossl | 1 - .../share/man/man3/i2d_OCSP_SIGNATURE.3ossl | 1 - .../share/man/man3/i2d_OCSP_SINGLERESP.3ossl | 1 - .../man/man3/i2d_OSSL_ATTRIBUTES_SYNTAX.3ossl | 1 - .../i2d_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl | 1 - .../share/man/man3/i2d_OSSL_CMP_ATAVS.3ossl | 1 - .../share/man/man3/i2d_OSSL_CMP_MSG.3ossl | 1 - .../share/man/man3/i2d_OSSL_CMP_MSG_bio.3ossl | 1 - .../man/man3/i2d_OSSL_CMP_PKIHEADER.3ossl | 1 - .../share/man/man3/i2d_OSSL_CMP_PKISI.3ossl | 1 - .../share/man/man3/i2d_OSSL_CRMF_CERTID.3ossl | 1 - .../man/man3/i2d_OSSL_CRMF_CERTTEMPLATE.3ossl | 1 - .../man3/i2d_OSSL_CRMF_ENCRYPTEDVALUE.3ossl | 1 - .../share/man/man3/i2d_OSSL_CRMF_MSG.3ossl | 1 - .../share/man/man3/i2d_OSSL_CRMF_MSGS.3ossl | 1 - .../man/man3/i2d_OSSL_CRMF_PBMPARAMETER.3ossl | 1 - .../i2d_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl | 1 - .../man3/i2d_OSSL_CRMF_SINGLEPUBINFO.3ossl | 1 - .../man/man3/i2d_OSSL_IETF_ATTR_SYNTAX.3ossl | 1 - .../man/man3/i2d_OSSL_ISSUER_SERIAL.3ossl | 1 - .../man3/i2d_OSSL_OBJECT_DIGEST_INFO.3ossl | 1 - .../share/man/man3/i2d_OSSL_TARGET.3ossl | 1 - .../man3/i2d_OSSL_TARGETING_INFORMATION.3ossl | 1 - .../share/man/man3/i2d_OSSL_TARGETS.3ossl | 1 - .../share/man/man3/i2d_OSSL_TARGET_CERT.3ossl | 1 - .../man3/i2d_OSSL_USER_NOTICE_SYNTAX.3ossl | 1 - .../share/man/man3/i2d_OTHERNAME.3ossl | 1 - .../share/man/man3/i2d_PBE2PARAM.3ossl | 1 - .../share/man/man3/i2d_PBEPARAM.3ossl | 1 - .../share/man/man3/i2d_PBKDF2PARAM.3ossl | 1 - .../share/man/man3/i2d_PBMAC1PARAM.3ossl | 1 - .../share/man/man3/i2d_PKCS12.3ossl | 1 - .../share/man/man3/i2d_PKCS12_BAGS.3ossl | 1 - .../share/man/man3/i2d_PKCS12_MAC_DATA.3ossl | 1 - .../share/man/man3/i2d_PKCS12_SAFEBAG.3ossl | 1 - .../share/man/man3/i2d_PKCS12_bio.3ossl | 1 - .../share/man/man3/i2d_PKCS12_fp.3ossl | 1 - .../share/man/man3/i2d_PKCS7.3ossl | 1 - .../share/man/man3/i2d_PKCS7_DIGEST.3ossl | 1 - .../share/man/man3/i2d_PKCS7_ENCRYPT.3ossl | 1 - .../man/man3/i2d_PKCS7_ENC_CONTENT.3ossl | 1 - .../share/man/man3/i2d_PKCS7_ENVELOPE.3ossl | 1 - .../man3/i2d_PKCS7_ISSUER_AND_SERIAL.3ossl | 1 - .../share/man/man3/i2d_PKCS7_NDEF.3ossl | 1 - .../share/man/man3/i2d_PKCS7_RECIP_INFO.3ossl | 1 - .../share/man/man3/i2d_PKCS7_SIGNED.3ossl | 1 - .../man/man3/i2d_PKCS7_SIGNER_INFO.3ossl | 1 - .../man/man3/i2d_PKCS7_SIGN_ENVELOPE.3ossl | 1 - .../share/man/man3/i2d_PKCS7_bio.3ossl | 1 - .../share/man/man3/i2d_PKCS7_bio_stream.3ossl | 182 -- .../share/man/man3/i2d_PKCS7_fp.3ossl | 1 - .../man3/i2d_PKCS8PrivateKeyInfo_bio.3ossl | 1 - .../man/man3/i2d_PKCS8PrivateKeyInfo_fp.3ossl | 1 - .../man/man3/i2d_PKCS8PrivateKey_bio.3ossl | 1 - .../man/man3/i2d_PKCS8PrivateKey_fp.3ossl | 1 - .../man3/i2d_PKCS8PrivateKey_nid_bio.3ossl | 1 - .../man/man3/i2d_PKCS8PrivateKey_nid_fp.3ossl | 1 - .../man/man3/i2d_PKCS8_PRIV_KEY_INFO.3ossl | 1 - .../man3/i2d_PKCS8_PRIV_KEY_INFO_bio.3ossl | 1 - .../man/man3/i2d_PKCS8_PRIV_KEY_INFO_fp.3ossl | 1 - .../share/man/man3/i2d_PKCS8_bio.3ossl | 1 - .../share/man/man3/i2d_PKCS8_fp.3ossl | 1 - .../man/man3/i2d_PKEY_USAGE_PERIOD.3ossl | 1 - .../share/man/man3/i2d_POLICYINFO.3ossl | 1 - .../share/man/man3/i2d_POLICYQUALINFO.3ossl | 1 - .../share/man/man3/i2d_PROFESSION_INFO.3ossl | 1 - .../man3/i2d_PROXY_CERT_INFO_EXTENSION.3ossl | 1 - .../share/man/man3/i2d_PROXY_POLICY.3ossl | 1 - .../share/man/man3/i2d_PUBKEY.3ossl | 1 - .../share/man/man3/i2d_PUBKEY_bio.3ossl | 1 - .../share/man/man3/i2d_PUBKEY_fp.3ossl | 1 - .../share/man/man3/i2d_PrivateKey.3ossl | 1 - .../share/man/man3/i2d_PrivateKey_bio.3ossl | 1 - .../share/man/man3/i2d_PrivateKey_fp.3ossl | 1 - .../share/man/man3/i2d_PublicKey.3ossl | 1 - .../share/man/man3/i2d_RSAPrivateKey.3ossl | 1 - .../man/man3/i2d_RSAPrivateKey_bio.3ossl | 1 - .../share/man/man3/i2d_RSAPrivateKey_fp.3ossl | 1 - .../share/man/man3/i2d_RSAPublicKey.3ossl | 1 - .../share/man/man3/i2d_RSAPublicKey_bio.3ossl | 1 - .../share/man/man3/i2d_RSAPublicKey_fp.3ossl | 1 - .../share/man/man3/i2d_RSA_OAEP_PARAMS.3ossl | 1 - .../share/man/man3/i2d_RSA_PSS_PARAMS.3ossl | 1 - .../share/man/man3/i2d_RSA_PUBKEY.3ossl | 1 - .../share/man/man3/i2d_RSA_PUBKEY_bio.3ossl | 1 - .../share/man/man3/i2d_RSA_PUBKEY_fp.3ossl | 1 - .../share/man/man3/i2d_SCRYPT_PARAMS.3ossl | 1 - .../share/man/man3/i2d_SCT_LIST.3ossl | 1 - .../share/man/man3/i2d_SSL_SESSION.3ossl | 1 - .../share/man/man3/i2d_SXNET.3ossl | 1 - .../share/man/man3/i2d_SXNETID.3ossl | 1 - .../share/man/man3/i2d_TS_ACCURACY.3ossl | 1 - .../share/man/man3/i2d_TS_MSG_IMPRINT.3ossl | 1 - .../man/man3/i2d_TS_MSG_IMPRINT_bio.3ossl | 1 - .../man/man3/i2d_TS_MSG_IMPRINT_fp.3ossl | 1 - .../share/man/man3/i2d_TS_REQ.3ossl | 1 - .../share/man/man3/i2d_TS_REQ_bio.3ossl | 1 - .../share/man/man3/i2d_TS_REQ_fp.3ossl | 1 - .../share/man/man3/i2d_TS_RESP.3ossl | 1 - .../share/man/man3/i2d_TS_RESP_bio.3ossl | 1 - .../share/man/man3/i2d_TS_RESP_fp.3ossl | 1 - .../share/man/man3/i2d_TS_STATUS_INFO.3ossl | 1 - .../share/man/man3/i2d_TS_TST_INFO.3ossl | 1 - .../share/man/man3/i2d_TS_TST_INFO_bio.3ossl | 1 - .../share/man/man3/i2d_TS_TST_INFO_fp.3ossl | 1 - .../share/man/man3/i2d_USERNOTICE.3ossl | 1 - openssl-install/share/man/man3/i2d_X509.3ossl | 1 - .../share/man/man3/i2d_X509_ACERT.3ossl | 1 - .../share/man/man3/i2d_X509_ACERT_bio.3ossl | 1 - .../share/man/man3/i2d_X509_ACERT_fp.3ossl | 1 - .../share/man/man3/i2d_X509_ALGOR.3ossl | 1 - .../share/man/man3/i2d_X509_ALGORS.3ossl | 1 - .../share/man/man3/i2d_X509_ATTRIBUTE.3ossl | 1 - .../share/man/man3/i2d_X509_AUX.3ossl | 1 - .../share/man/man3/i2d_X509_CERT_AUX.3ossl | 1 - .../share/man/man3/i2d_X509_CINF.3ossl | 1 - .../share/man/man3/i2d_X509_CRL.3ossl | 1 - .../share/man/man3/i2d_X509_CRL_INFO.3ossl | 1 - .../share/man/man3/i2d_X509_CRL_bio.3ossl | 1 - .../share/man/man3/i2d_X509_CRL_fp.3ossl | 1 - .../share/man/man3/i2d_X509_EXTENSION.3ossl | 1 - .../share/man/man3/i2d_X509_EXTENSIONS.3ossl | 1 - .../share/man/man3/i2d_X509_NAME.3ossl | 1 - .../share/man/man3/i2d_X509_NAME_ENTRY.3ossl | 1 - .../share/man/man3/i2d_X509_PUBKEY.3ossl | 1 - .../share/man/man3/i2d_X509_PUBKEY_bio.3ossl | 1 - .../share/man/man3/i2d_X509_PUBKEY_fp.3ossl | 1 - .../share/man/man3/i2d_X509_REQ.3ossl | 1 - .../share/man/man3/i2d_X509_REQ_INFO.3ossl | 1 - .../share/man/man3/i2d_X509_REQ_bio.3ossl | 1 - .../share/man/man3/i2d_X509_REQ_fp.3ossl | 1 - .../share/man/man3/i2d_X509_REVOKED.3ossl | 1 - .../share/man/man3/i2d_X509_SIG.3ossl | 1 - .../share/man/man3/i2d_X509_VAL.3ossl | 1 - .../share/man/man3/i2d_X509_bio.3ossl | 1 - .../share/man/man3/i2d_X509_fp.3ossl | 1 - .../share/man/man3/i2d_re_X509_CRL_tbs.3ossl | 1 - .../share/man/man3/i2d_re_X509_REQ_tbs.3ossl | 1 - .../share/man/man3/i2d_re_X509_tbs.3ossl | 220 -- openssl-install/share/man/man3/i2o_SCT.3ossl | 1 - .../share/man/man3/i2o_SCT_LIST.3ossl | 1 - .../share/man/man3/i2s_ASN1_ENUMERATED.3ossl | 1 - .../man/man3/i2s_ASN1_ENUMERATED_TABLE.3ossl | 1 - .../share/man/man3/i2s_ASN1_IA5STRING.3ossl | 1 - .../share/man/man3/i2s_ASN1_INTEGER.3ossl | 1 - .../man/man3/i2s_ASN1_OCTET_STRING.3ossl | 1 - .../share/man/man3/i2s_ASN1_UTF8STRING.3ossl | 1 - .../share/man/man3/i2t_ASN1_OBJECT.3ossl | 1 - .../share/man/man3/lh_TYPE_delete.3ossl | 1 - .../share/man/man3/lh_TYPE_doall.3ossl | 1 - .../share/man/man3/lh_TYPE_doall_arg.3ossl | 1 - .../share/man/man3/lh_TYPE_error.3ossl | 1 - .../share/man/man3/lh_TYPE_flush.3ossl | 1 - .../share/man/man3/lh_TYPE_free.3ossl | 1 - .../man/man3/lh_TYPE_get_down_load.3ossl | 1 - .../share/man/man3/lh_TYPE_insert.3ossl | 1 - .../share/man/man3/lh_TYPE_new.3ossl | 1 - .../share/man/man3/lh_TYPE_num_items.3ossl | 1 - .../share/man/man3/lh_TYPE_retrieve.3ossl | 1 - .../man/man3/lh_TYPE_set_down_load.3ossl | 1 - openssl-install/share/man/man3/o2i_SCT.3ossl | 1 - .../share/man/man3/o2i_SCT_LIST.3ossl | 180 -- .../share/man/man3/pem_password_cb.3ossl | 1 - .../share/man/man3/s2i_ASN1_IA5STRING.3ossl | 230 -- .../share/man/man3/s2i_ASN1_INTEGER.3ossl | 1 - .../man/man3/s2i_ASN1_OCTET_STRING.3ossl | 1 - .../share/man/man3/s2i_ASN1_UTF8STRING.3ossl | 1 - .../share/man/man3/sk_TYPE_deep_copy.3ossl | 1 - .../share/man/man3/sk_TYPE_delete.3ossl | 1 - .../share/man/man3/sk_TYPE_delete_ptr.3ossl | 1 - .../share/man/man3/sk_TYPE_dup.3ossl | 1 - .../share/man/man3/sk_TYPE_find.3ossl | 1 - .../share/man/man3/sk_TYPE_find_all.3ossl | 1 - .../share/man/man3/sk_TYPE_find_ex.3ossl | 1 - .../share/man/man3/sk_TYPE_free.3ossl | 1 - .../share/man/man3/sk_TYPE_insert.3ossl | 1 - .../share/man/man3/sk_TYPE_is_sorted.3ossl | 1 - .../share/man/man3/sk_TYPE_new.3ossl | 1 - .../share/man/man3/sk_TYPE_new_null.3ossl | 1 - .../share/man/man3/sk_TYPE_new_reserve.3ossl | 1 - .../share/man/man3/sk_TYPE_num.3ossl | 1 - .../share/man/man3/sk_TYPE_pop.3ossl | 1 - .../share/man/man3/sk_TYPE_pop_free.3ossl | 1 - .../share/man/man3/sk_TYPE_push.3ossl | 1 - .../share/man/man3/sk_TYPE_reserve.3ossl | 1 - .../share/man/man3/sk_TYPE_set.3ossl | 1 - .../share/man/man3/sk_TYPE_set_cmp_func.3ossl | 1 - .../share/man/man3/sk_TYPE_shift.3ossl | 1 - .../share/man/man3/sk_TYPE_sort.3ossl | 1 - .../share/man/man3/sk_TYPE_unshift.3ossl | 1 - .../share/man/man3/sk_TYPE_value.3ossl | 1 - .../share/man/man3/sk_TYPE_zero.3ossl | 1 - .../share/man/man3/ssl_ct_validation_cb.3ossl | 1 - .../man/man3/tls_session_secret_cb_fn.3ossl | 1 - openssl-install/share/man/man5/config.5ossl | 721 ------ .../share/man/man5/fips_config.5ossl | 326 --- .../share/man/man5/x509v3_config.5ossl | 771 ------ .../share/man/man7/EVP_ASYM_CIPHER-RSA.7ossl | 261 -- .../share/man/man7/EVP_ASYM_CIPHER-SM2.7ossl | 172 -- .../share/man/man7/EVP_CIPHER-AES.7ossl | 228 -- .../share/man/man7/EVP_CIPHER-ARIA.7ossl | 189 -- .../share/man/man7/EVP_CIPHER-BLOWFISH.7ossl | 177 -- .../share/man/man7/EVP_CIPHER-CAMELLIA.7ossl | 183 -- .../share/man/man7/EVP_CIPHER-CAST.7ossl | 177 -- .../share/man/man7/EVP_CIPHER-CHACHA.7ossl | 171 -- .../share/man/man7/EVP_CIPHER-DES.7ossl | 215 -- .../share/man/man7/EVP_CIPHER-IDEA.7ossl | 177 -- .../share/man/man7/EVP_CIPHER-NULL.7ossl | 199 -- .../share/man/man7/EVP_CIPHER-RC2.7ossl | 183 -- .../share/man/man7/EVP_CIPHER-RC4.7ossl | 174 -- .../share/man/man7/EVP_CIPHER-RC5.7ossl | 179 -- .../share/man/man7/EVP_CIPHER-SEED.7ossl | 177 -- .../share/man/man7/EVP_CIPHER-SM4.7ossl | 197 -- .../share/man/man7/EVP_KDF-ARGON2.7ossl | 326 --- .../share/man/man7/EVP_KDF-HKDF.7ossl | 307 --- .../share/man/man7/EVP_KDF-HMAC-DRBG.7ossl | 199 -- .../share/man/man7/EVP_KDF-KB.7ossl | 336 --- .../share/man/man7/EVP_KDF-KRB5KDF.7ossl | 244 -- .../share/man/man7/EVP_KDF-PBKDF1.7ossl | 215 -- .../share/man/man7/EVP_KDF-PBKDF2.7ossl | 247 -- .../share/man/man7/EVP_KDF-PKCS12KDF.7ossl | 219 -- .../share/man/man7/EVP_KDF-PVKKDF.7ossl | 200 -- .../share/man/man7/EVP_KDF-SCRYPT.7ossl | 284 --- .../share/man/man7/EVP_KDF-SS.7ossl | 343 --- .../share/man/man7/EVP_KDF-SSHKDF.7ossl | 318 --- .../share/man/man7/EVP_KDF-TLS13_KDF.7ossl | 294 --- .../share/man/man7/EVP_KDF-TLS1_PRF.7ossl | 283 --- .../share/man/man7/EVP_KDF-X942-ASN1.7ossl | 300 --- .../share/man/man7/EVP_KDF-X942-CONCAT.7ossl | 166 -- .../share/man/man7/EVP_KDF-X963.7ossl | 270 -- .../share/man/man7/EVP_KEM-EC.7ossl | 205 -- .../share/man/man7/EVP_KEM-RSA.7ossl | 200 -- .../share/man/man7/EVP_KEM-X25519.7ossl | 204 -- .../share/man/man7/EVP_KEM-X448.7ossl | 1 - .../share/man/man7/EVP_KEYEXCH-DH.7ossl | 277 --- .../share/man/man7/EVP_KEYEXCH-ECDH.7ossl | 269 -- .../share/man/man7/EVP_KEYEXCH-X25519.7ossl | 185 -- .../share/man/man7/EVP_KEYEXCH-X448.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-CMAC.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-DH.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-DHX.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-DSA.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-EC.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-ED25519.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-ED448.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-HMAC.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-Poly1305.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-RSA.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-SM2.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-Siphash.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-X25519.7ossl | 1 - .../share/man/man7/EVP_KEYMGMT-X448.7ossl | 1 - .../share/man/man7/EVP_MAC-BLAKE2.7ossl | 216 -- .../share/man/man7/EVP_MAC-BLAKE2BMAC.7ossl | 1 - .../share/man/man7/EVP_MAC-BLAKE2SMAC.7ossl | 1 - .../share/man/man7/EVP_MAC-CMAC.7ossl | 222 -- .../share/man/man7/EVP_MAC-GMAC.7ossl | 202 -- .../share/man/man7/EVP_MAC-HMAC.7ossl | 228 -- .../share/man/man7/EVP_MAC-KMAC.7ossl | 296 --- .../share/man/man7/EVP_MAC-KMAC128.7ossl | 1 - .../share/man/man7/EVP_MAC-KMAC256.7ossl | 1 - .../share/man/man7/EVP_MAC-Poly1305.7ossl | 191 -- .../share/man/man7/EVP_MAC-Siphash.7ossl | 190 -- .../share/man/man7/EVP_MD-BLAKE2.7ossl | 198 -- .../share/man/man7/EVP_MD-KECCAK-KMAC.7ossl | 1 - .../share/man/man7/EVP_MD-KECCAK.7ossl | 178 -- .../share/man/man7/EVP_MD-MD2.7ossl | 164 -- .../share/man/man7/EVP_MD-MD4.7ossl | 164 -- .../share/man/man7/EVP_MD-MD5-SHA1.7ossl | 181 -- .../share/man/man7/EVP_MD-MD5.7ossl | 164 -- .../share/man/man7/EVP_MD-MDC2.7ossl | 175 -- .../share/man/man7/EVP_MD-NULL.7ossl | 169 -- .../share/man/man7/EVP_MD-RIPEMD160.7ossl | 168 -- .../share/man/man7/EVP_MD-SHA1.7ossl | 180 -- .../share/man/man7/EVP_MD-SHA2.7ossl | 196 -- .../share/man/man7/EVP_MD-SHA3.7ossl | 178 -- .../share/man/man7/EVP_MD-SHAKE.7ossl | 217 -- .../share/man/man7/EVP_MD-SM3.7ossl | 164 -- .../share/man/man7/EVP_MD-WHIRLPOOL.7ossl | 164 -- .../share/man/man7/EVP_MD-common.7ossl | 183 -- .../share/man/man7/EVP_PKEY-CMAC.7ossl | 1 - .../share/man/man7/EVP_PKEY-DH.7ossl | 459 ---- .../share/man/man7/EVP_PKEY-DHX.7ossl | 1 - .../share/man/man7/EVP_PKEY-DSA.7ossl | 271 -- .../share/man/man7/EVP_PKEY-EC.7ossl | 447 ---- .../share/man/man7/EVP_PKEY-ED25519.7ossl | 1 - .../share/man/man7/EVP_PKEY-ED448.7ossl | 1 - .../share/man/man7/EVP_PKEY-FFC.7ossl | 346 --- .../share/man/man7/EVP_PKEY-HMAC.7ossl | 207 -- .../share/man/man7/EVP_PKEY-Poly1305.7ossl | 1 - .../share/man/man7/EVP_PKEY-RSA.7ossl | 438 ---- .../share/man/man7/EVP_PKEY-SM2.7ossl | 227 -- .../share/man/man7/EVP_PKEY-Siphash.7ossl | 1 - .../share/man/man7/EVP_PKEY-X25519.7ossl | 246 -- .../share/man/man7/EVP_PKEY-X448.7ossl | 1 - .../share/man/man7/EVP_RAND-CRNG-TEST.7ossl | 202 -- .../share/man/man7/EVP_RAND-CTR-DRBG.7ossl | 249 -- .../share/man/man7/EVP_RAND-HASH-DRBG.7ossl | 274 --- .../share/man/man7/EVP_RAND-HMAC-DRBG.7ossl | 277 --- .../share/man/man7/EVP_RAND-JITTER.7ossl | 225 -- .../share/man/man7/EVP_RAND-SEED-SRC.7ossl | 220 -- .../share/man/man7/EVP_RAND-TEST-RAND.7ossl | 267 -- openssl-install/share/man/man7/EVP_RAND.7ossl | 407 --- .../share/man/man7/EVP_SIGNATURE-CMAC.7ossl | 1 - .../share/man/man7/EVP_SIGNATURE-DSA.7ossl | 266 -- .../share/man/man7/EVP_SIGNATURE-ECDSA.7ossl | 255 -- .../man/man7/EVP_SIGNATURE-ED25519.7ossl | 304 --- .../share/man/man7/EVP_SIGNATURE-ED448.7ossl | 1 - .../share/man/man7/EVP_SIGNATURE-HMAC.7ossl | 183 -- .../man/man7/EVP_SIGNATURE-Poly1305.7ossl | 1 - .../share/man/man7/EVP_SIGNATURE-RSA.7ossl | 352 --- .../man/man7/EVP_SIGNATURE-Siphash.7ossl | 1 - openssl-install/share/man/man7/Ed25519.7ossl | 1 - openssl-install/share/man/man7/Ed448.7ossl | 1 - .../share/man/man7/OPENSSL_API_COMPAT.7ossl | 1 - .../man/man7/OPENSSL_NO_DEPRECATED.7ossl | 1 - .../share/man/man7/OSSL_PROVIDER-FIPS.7ossl | 665 ----- .../share/man/man7/OSSL_PROVIDER-base.7ossl | 290 --- .../man/man7/OSSL_PROVIDER-default.7ossl | 490 ---- .../share/man/man7/OSSL_PROVIDER-legacy.7ossl | 234 -- .../share/man/man7/OSSL_PROVIDER-null.7ossl | 168 -- .../share/man/man7/OSSL_STORE-winstore.7ossl | 201 -- openssl-install/share/man/man7/RAND.7ossl | 212 -- openssl-install/share/man/man7/RSA-PSS.7ossl | 189 -- openssl-install/share/man/man7/RSA.7ossl | 1 - openssl-install/share/man/man7/SM2.7ossl | 1 - openssl-install/share/man/man7/X25519.7ossl | 210 -- openssl-install/share/man/man7/X448.7ossl | 1 - openssl-install/share/man/man7/bio.7ossl | 241 -- openssl-install/share/man/man7/crypto.7ossl | 1 - openssl-install/share/man/man7/ct.7ossl | 185 -- .../share/man/man7/des_modes.7ossl | 295 --- openssl-install/share/man/man7/evp.7ossl | 238 -- .../share/man/man7/fips_module.7ossl | 721 ------ .../share/man/man7/life_cycle-cipher.7ossl | 283 --- .../share/man/man7/life_cycle-digest.7ossl | 262 -- .../share/man/man7/life_cycle-kdf.7ossl | 219 -- .../share/man/man7/life_cycle-mac.7ossl | 238 -- .../share/man/man7/life_cycle-pkey.7ossl | 322 --- .../share/man/man7/life_cycle-rand.7ossl | 231 -- .../share/man/man7/migration_guide.7ossl | 1 - .../share/man/man7/openssl-core.h.7ossl | 184 -- .../man/man7/openssl-core_dispatch.h.7ossl | 182 -- .../share/man/man7/openssl-core_names.h.7ossl | 180 -- .../share/man/man7/openssl-env.7ossl | 297 --- .../share/man/man7/openssl-glossary.7ossl | 339 --- .../share/man/man7/openssl-qlog.7ossl | 352 --- .../share/man/man7/openssl-quic.7ossl | 791 ------ .../share/man/man7/openssl-threads.7ossl | 236 -- .../share/man/man7/openssl_user_macros.7ossl | 233 -- .../man/man7/ossl-guide-introduction.7ossl | 234 -- .../ossl-guide-libcrypto-introduction.7ossl | 521 ---- .../ossl-guide-libraries-introduction.7ossl | 450 ---- .../man7/ossl-guide-libssl-introduction.7ossl | 238 -- .../share/man/man7/ossl-guide-migration.7ossl | 2186 ----------------- .../man7/ossl-guide-quic-client-block.7ossl | 514 ---- .../ossl-guide-quic-client-non-block.7ossl | 599 ----- .../man7/ossl-guide-quic-introduction.7ossl | 304 --- .../man7/ossl-guide-quic-multi-stream.7ossl | 531 ---- .../man7/ossl-guide-tls-client-block.7ossl | 730 ------ .../ossl-guide-tls-client-non-block.7ossl | 513 ---- .../man7/ossl-guide-tls-introduction.7ossl | 454 ---- .../man7/ossl-guide-tls-server-block.7ossl | 483 ---- .../share/man/man7/ossl_store-file.7ossl | 191 -- .../share/man/man7/ossl_store.7ossl | 220 -- .../share/man/man7/passphrase-encoding.7ossl | 288 --- openssl-install/share/man/man7/property.7ossl | 289 --- .../share/man/man7/provider-asym_cipher.7ossl | 422 ---- .../share/man/man7/provider-base.7ossl | 1104 --------- .../share/man/man7/provider-cipher.7ossl | 381 --- .../share/man/man7/provider-decoder.7ossl | 423 ---- .../share/man/man7/provider-digest.7ossl | 405 --- .../share/man/man7/provider-encoder.7ossl | 432 ---- .../share/man/man7/provider-kdf.7ossl | 482 ---- .../share/man/man7/provider-kem.7ossl | 384 --- .../share/man/man7/provider-keyexch.7ossl | 392 --- .../share/man/man7/provider-keymgmt.7ossl | 628 ----- .../share/man/man7/provider-mac.7ossl | 390 --- .../share/man/man7/provider-object.7ossl | 292 --- .../share/man/man7/provider-rand.7ossl | 454 ---- .../share/man/man7/provider-signature.7ossl | 738 ------ .../share/man/man7/provider-storemgmt.7ossl | 356 --- openssl-install/share/man/man7/provider.7ossl | 400 --- .../share/man/man7/proxy-certificates.7ossl | 476 ---- openssl-install/share/man/man7/ssl.7ossl | 1 - openssl-install/share/man/man7/x509.7ossl | 206 -- openssl-install/ssl/ct_log_list.cnf | 9 - openssl-install/ssl/ct_log_list.cnf.dist | 9 - openssl-install/ssl/misc/CA.pl | 383 --- openssl-install/ssl/misc/tsget | 1 - openssl-install/ssl/misc/tsget.pl | 200 -- openssl-install/ssl/openssl.cnf | 390 --- openssl-install/ssl/openssl.cnf.dist | 390 --- 7085 files changed, 53 insertions(+), 380453 deletions(-) delete mode 100644 openssl-install/share/doc/openssl/html/man1/CA.pl.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-asn1parse.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-ca.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-ciphers.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-cmds.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-cmp.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-cms.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-crl.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-crl2pkcs7.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-dgst.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-dhparam.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-dsa.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-dsaparam.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-ec.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-ecparam.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-enc.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-engine.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-errstr.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-fipsinstall.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-format-options.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-gendsa.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-genpkey.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-genrsa.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-info.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-kdf.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-list.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-mac.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-namedisplay-options.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-nseq.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-ocsp.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-passphrase-options.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-passwd.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-pkcs12.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-pkcs7.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-pkcs8.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-pkey.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-pkeyparam.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-pkeyutl.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-prime.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-rand.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-rehash.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-req.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-rsa.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-rsautl.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-s_client.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-s_server.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-s_time.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-sess_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-smime.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-speed.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-spkac.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-srp.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-storeutl.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-ts.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-verification-options.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-verify.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-version.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl-x509.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/openssl.html delete mode 100644 openssl-install/share/doc/openssl/html/man1/tsget.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ADMISSIONS.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_EXTERN_FUNCS.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_get_int64.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_ITEM_lookup.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_OBJECT_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_STRING_TABLE_add.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_STRING_length.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_STRING_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_STRING_print_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_TIME_set.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_TYPE_get.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_aux_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_generate_nconf.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_item_d2i_bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_item_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASN1_item_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASYNC_WAIT_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ASYNC_start_job.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BF_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_ADDR.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_ADDRINFO.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_connect.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_ctrl.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_base64.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_buffer.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_cipher.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_md.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_null.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_prefix.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_readbuffer.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_f_ssl.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_find_type.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_get_data.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_get_ex_new_index.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_get_rpoll_descriptor.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_new_CMS.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_parse_hostserv.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_printf.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_push.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_read.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_accept.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_connect.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_core.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_datagram.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_dgram_pair.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_fd.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_file.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_mem.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_null.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_s_socket.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_sendmmsg.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_set_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_should_retry.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BIO_socket_wait.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_BLINDING_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_CTX_start.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_add.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_add_word.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_bn2bin.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_cmp.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_copy.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_generate_prime.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_mod_exp_mont.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_mod_inverse.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_mod_mul_montgomery.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_mod_mul_reciprocal.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_num_bytes.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_rand.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_security_bits.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_set_bit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_swap.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BN_zero.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/BUF_MEM_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMAC_CTX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_decrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_EnvelopedData_create.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_add0_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_add1_recipient_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_add1_signer.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_compress.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_data_create.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_decrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_digest_create.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_final.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_get0_RecipientInfos.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_get0_SignerInfos.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_get0_type.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_get1_ReceiptRequest.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_sign_receipt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_signed_get_attr.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_uncompress.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_verify.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CMS_verify_receipt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/COMP_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CONF_modules_free.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CONF_modules_load_file.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CRYPTO_THREAD_run_once.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CRYPTO_get_ex_new_index.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CRYPTO_memcmp.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_get0_log_by_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CTLOG_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/CT_POLICY_EVAL_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DEFINE_STACK_OF.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DES_random_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_generate_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_generate_parameters.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_get0_pqg.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_get_1024_160.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_new_by_nid.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_set_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DH_size.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_SIG_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_do_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_dup_DH.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_generate_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_generate_parameters.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_get0_pqg.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_set_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DSA_size.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DTLS_get_data_mtu.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DTLS_set_timer_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DTLSv1_get_timeout.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DTLSv1_handle_timeout.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/DTLSv1_listen.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ECDSA_SIG_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ECDSA_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ECPKParameters_print.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EC_GFp_simple_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EC_GROUP_copy.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EC_GROUP_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EC_KEY_get_enc_flags.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EC_KEY_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EC_POINT_add.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EC_POINT_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ENGINE_add.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_GET_LIB.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_clear_error.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_error_string.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_get_error.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_load_crypto_strings.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_load_strings.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_print_errors.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_put_error.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_remove_state.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/ERR_set_mark.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_ASYM_CIPHER_free.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_BytesToKey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_cipher_data.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_original_iv.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_DigestInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_DigestSignInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_DigestVerifyInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_EncodeInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_EncryptInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_KDF.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_KEM_free.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_KEYEXCH_free.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_KEYMGMT.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_MAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_MD_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_OpenInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PBE_CipherInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY2PKCS8.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_ASN1_METHOD.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_ctrl.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_libctx.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_pkey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get_algor.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set1_pbe_pass.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_hkdf_md.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_params.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_scrypt_N.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_tls1_prf_md.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_asn1_get_count.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_check.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_copy_parameters.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decapsulate.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_derive.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_digestsign_supports_digest.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encapsulate.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_fromdata.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_attr.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_default_digest_nid.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_field_type.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_group_name.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_size.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_gettable_params.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_is_a.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_keygen.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_get_count.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_print_private.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_RSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_encoded_public_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set_type.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_settable_params.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_todata.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify_recover.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_RAND.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_SIGNATURE.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_SealInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_SignInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_VerifyInit.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_aes_128_gcm.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_aria_128_gcm.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_bf_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_blake2b512.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_camellia_128_ecb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_cast5_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_chacha20.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_des_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_desx_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_idea_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_md2.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_md4.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_md5.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_mdc2.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_rc2_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_rc4.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_rc5_32_12_16_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_ripemd160.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_seed_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_set_default_properties.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_sha1.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_sha224.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_sha3_224.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_sm3.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_sm4_cbc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/EVP_whirlpool.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/GENERAL_NAME.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/HMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/MD5.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/MDC2_Init.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/NCONF_new_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OBJ_nid2obj.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OCSP_REQUEST_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OCSP_cert_to_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OCSP_request_add1_nonce.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OCSP_resp_find_status.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OCSP_response_status.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OCSP_sendreq_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_Applink.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_FILE.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_COMPFUNC.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_stats.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_config.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_fork_prepare.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_gmtime.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_hexchar2int.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_ia32cap.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_init_crypto.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_init_ssl.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_instrument_bus.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_load_builtin_modules.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_malloc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_riscvcap.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_s390xcap.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_secure_malloc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OPENSSL_strcasecmp.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ALGORITHM.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CALLBACK.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ATAV_set0.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_HDR_get0_transactionID.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_new_caCerts.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_set0.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_get0_header.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_http_perform.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_SRV_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_STATUSINFO_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_exec_certreq.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_log_open.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CMP_validate_msg.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CORE_MAKE_FUNC.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_get0_tmpl.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set0_validity.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_pbmp_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_DECODER.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX_new_for_pkey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_from_bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_DISPATCH.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX_new_for_pkey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_to_bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ERR_STATE_save.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ESS_check_signing_certs.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_GENERAL_NAMES_print.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_HPKE_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_REQ_CTX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_parse_url.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_transfer.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX_print.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_INDICATOR_set_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_ITEM.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX_set_conf_diagnostics.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_PARAM.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_BLD.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_allocate_from_text.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_dup.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_int.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_PROVIDER.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_QUIC_client_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_set_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_STORE_INFO.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_STORE_LOADER.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_STORE_SEARCH.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_STORE_attach.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_STORE_expect.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_STORE_open.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_sleep.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_trace_enabled.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_trace_get_category_num.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OSSL_trace_set_channel.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OpenSSL_add_all_algorithms.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/OpenSSL_version.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PBMAC1_get1_pbkdf2_param.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_X509_INFO_read_bio_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_bytes_read_bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_read.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_read_CMS.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_read_bio_PrivateKey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_read_bio_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_write_bio_CMS_stream.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PEM_write_bio_PKCS7_stream.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_PBE_keyivgen.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_create_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get0_attrs.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get1_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_set0_attrs.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_add1_attr_by_NID.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_add_CSPName_asc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_add_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_add_friendlyname_asc.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_add_localkeyid.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_add_safe.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_create.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_decrypt_skey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_gen_mac.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_get_friendlyname.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_init.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_item_decrypt_d2i.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_key_gen_utf8_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_newpass.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_pack_p7encdata.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS12_parse.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS5_PBE_keyivgen.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS5_PBKDF2_HMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS7_decrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS7_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS7_get_octet_string.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS7_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS7_sign_add_signer.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS7_type_is_other.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS7_verify.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS8_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/PKCS8_pkey_add1_attr.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_add.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_bytes.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_cleanup.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_egd.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_get0_primary.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_load_file.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_set_DRBG_type.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RAND_set_rand_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RC4_set_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RIPEMD160_Init.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_blinding_on.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_check_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_generate_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_get0_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_padding_add_PKCS1_type_1.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_print.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_private_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_public_encrypt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_set_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_sign_ASN1_OCTET_STRING.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/RSA_size.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SCT_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SCT_print.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SCT_validate.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SHA256_Init.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SMIME_read_ASN1.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SMIME_read_CMS.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SMIME_read_PKCS7.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SMIME_write_ASN1.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SMIME_write_CMS.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SMIME_write_PKCS7.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SRP_Calc_B.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SRP_VBASE_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SRP_create_verifier.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SRP_user_pwd_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CIPHER_get_name.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_COMP_add_compression_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set1_prefix.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_flags.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_ssl_ctx.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd_argv.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_add1_chain_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_extra_chain_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_session.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_config.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_ctrl.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_dane_enable.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_flush_sessions.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_free.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_get0_param.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_get_verify_mode.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_has_client_custom_ext.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_load_verify_locations.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_number.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_cache_size.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_get_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_sessions.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set0_CA_list.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_cert_comp_preference.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_curves.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_sigalgs.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_verify_cert_store.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_alpn_select_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_store.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_verify_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cipher_list.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_cert_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_hello_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ct_validation_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ctlog_list_file.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_default_passwd_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_generate_session_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_info_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_keylog_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_max_cert_list.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_min_proto_version.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_mode.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_msg_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_num_tickets.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_options.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_psk_client_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_quiet_shutdown.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_read_ahead.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_record_padding_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_security_level.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_cache_mode.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_id_context.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_ticket_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_split_send_fragment.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_srp_password.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ssl_version.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_stateless_cookie_generate_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_timeout.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_servername_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_status_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_ticket_key_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_use_srtp.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_dh_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_ecdh.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_verify.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_certificate.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_psk_identity_hint.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_serverinfo.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_free.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_cipher.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_hostname.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_id_context.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_peer.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_compress_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_protocol_version.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_time.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_has_ticket.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_is_resumable.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_print.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_SESSION_set1_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_accept.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_accept_stream.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_alert_type_string.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_alloc_buffers.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_check_chain.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_clear.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_connect.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_do_handshake.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_export_keying_material.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_extension_supported.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_free.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get0_connection.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get0_group_name.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_rpk.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_scts.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get1_builtin_sigalgs.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_SSL_CTX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_all_async_fds.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_certificate.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_ciphers.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_client_random.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_conn_close_info.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_current_cipher.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_default_timeout.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_error.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_event_timeout.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_extms_support.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_fd.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_handshake_rtt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_peer_cert_chain.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_peer_certificate.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_peer_signature_nid.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_peer_tmp_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_psk_identity.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_rbio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_rpoll_descriptor.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_session.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_shared_sigalgs.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_stream_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_stream_read_state.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_value_uint.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_verify_result.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_get_version.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_group_to_name.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_handle_events.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_in_init.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_inject_net_dgram.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_key_update.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_library_init.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_load_client_CA_file.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_new_stream.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_pending.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_poll.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_read.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_read_early_data.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_rstate_string.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_session_reused.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set1_host.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set1_initial_peer_addr.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set1_server_cert_type.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_async_callback.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_blocking_mode.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_connect_state.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_default_stream_mode.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_fd.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_incoming_stream_policy.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_retry_verify.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_session.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_session_secret_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_shutdown.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_set_verify_result.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_shutdown.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_state_string.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_stream_conclude.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_stream_reset.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_want.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/SSL_write.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/TS_RESP_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/TS_VERIFY_CTX.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/UI_STRING.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/UI_UTIL_read_pw.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/UI_create_method.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/UI_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509V3_get_d2i.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509V3_set_ctx.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_ACERT_add1_attr.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_ACERT_add_attr_nconf.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_ACERT_get0_holder_baseCertId.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_ACERT_get_attr.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_ACERT_print_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_ALGOR_dup.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_ATTRIBUTE.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_CRL_get0_by_serial.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_EXTENSION_set_object.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_LOOKUP.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_hash_dir.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_meth_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_NAME_ENTRY_get_object.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_NAME_add_entry_by_txt.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_NAME_get0_der.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_NAME_get_index_by_NID.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_NAME_print_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_PUBKEY_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_REQ_get_attr.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_REQ_get_extensions.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_SIG_get0.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_by_subject.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_error.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_set_verify_cb.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_add_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_get0_param.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_STORE_set_verify_cb_func.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_VERIFY_PARAM_set_flags.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_add_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_check_ca.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_check_host.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_check_issued.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_check_private_key.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_check_purpose.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_cmp.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_cmp_time.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_digest.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_dup.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get0_distinguishing_id.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get0_notBefore.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get0_signature.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get0_uids.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get_default_cert_file.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get_extension_flags.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get_pubkey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get_serialNumber.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get_subject_name.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_get_version.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_load_http.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_new.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_sign.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_verify.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509_verify_cert.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/X509v3_get_ext_by_NID.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/b2i_PVK_bio_ex.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/d2i_PKCS8PrivateKey_bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/d2i_PrivateKey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/d2i_RSAPrivateKey.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/d2i_SSL_SESSION.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/d2i_X509.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/i2d_CMS_bio_stream.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/i2d_PKCS7_bio_stream.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/i2d_re_X509_tbs.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/o2i_SCT_LIST.html delete mode 100644 openssl-install/share/doc/openssl/html/man3/s2i_ASN1_IA5STRING.html delete mode 100644 openssl-install/share/doc/openssl/html/man5/config.html delete mode 100644 openssl-install/share/doc/openssl/html/man5/fips_config.html delete mode 100644 openssl-install/share/doc/openssl/html/man5/x509v3_config.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-RSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-SM2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-AES.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-ARIA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-BLOWFISH.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAMELLIA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAST.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CHACHA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-DES.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-IDEA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-NULL.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC4.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC5.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SEED.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SM4.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-ARGON2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-HKDF.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-HMAC-DRBG.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-KB.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-KRB5KDF.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF1.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-PKCS12KDF.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-PVKKDF.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-SCRYPT.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-SS.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-SSHKDF.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS13_KDF.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS1_PRF.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-ASN1.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-CONCAT.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KDF-X963.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KEM-EC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KEM-RSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KEM-X25519.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-DH.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-ECDH.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-X25519.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MAC-BLAKE2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MAC-CMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MAC-GMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MAC-HMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MAC-KMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MAC-Poly1305.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MAC-Siphash.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-BLAKE2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-KECCAK.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-MD2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-MD4.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5-SHA1.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-MDC2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-NULL.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-RIPEMD160.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA1.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA3.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-SHAKE.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-SM3.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-WHIRLPOOL.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_MD-common.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DH.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-EC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-FFC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-HMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-RSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-SM2.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_PKEY-X25519.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND-CRNG-TEST.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND-CTR-DRBG.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND-HASH-DRBG.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND-HMAC-DRBG.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND-JITTER.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND-SEED-SRC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND-TEST-RAND.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_RAND.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-DSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ECDSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ED25519.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-HMAC.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-RSA.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-FIPS.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-base.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-default.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-legacy.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-null.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/OSSL_STORE-winstore.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/RAND.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/RSA-PSS.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/X25519.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/bio.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ct.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/des_modes.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/evp.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/fips_module.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/img/cipher.png delete mode 100644 openssl-install/share/doc/openssl/html/man7/img/digest.png delete mode 100644 openssl-install/share/doc/openssl/html/man7/img/kdf.png delete mode 100644 openssl-install/share/doc/openssl/html/man7/img/mac.png delete mode 100644 openssl-install/share/doc/openssl/html/man7/img/pkey.png delete mode 100644 openssl-install/share/doc/openssl/html/man7/img/rand.png delete mode 100644 openssl-install/share/doc/openssl/html/man7/life_cycle-cipher.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/life_cycle-digest.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/life_cycle-kdf.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/life_cycle-mac.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/life_cycle-pkey.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/life_cycle-rand.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-core.h.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-core_dispatch.h.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-core_names.h.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-env.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-glossary.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-qlog.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-quic.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl-threads.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/openssl_user_macros.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-introduction.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-libcrypto-introduction.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-libraries-introduction.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-libssl-introduction.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-migration.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-block.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-non-block.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-introduction.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-multi-stream.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-block.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-non-block.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-introduction.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-server-block.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl_store-file.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/ossl_store.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/passphrase-encoding.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/property.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-asym_cipher.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-base.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-cipher.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-decoder.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-digest.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-encoder.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-kdf.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-kem.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-keyexch.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-keymgmt.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-mac.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-object.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-rand.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-signature.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider-storemgmt.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/provider.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/proxy-certificates.html delete mode 100644 openssl-install/share/doc/openssl/html/man7/x509.html delete mode 100644 openssl-install/share/man/man1/CA.pl.1ossl delete mode 120000 openssl-install/share/man/man1/asn1parse.1ossl delete mode 120000 openssl-install/share/man/man1/c_rehash.1ossl delete mode 120000 openssl-install/share/man/man1/ca.1ossl delete mode 120000 openssl-install/share/man/man1/ciphers.1ossl delete mode 120000 openssl-install/share/man/man1/cmp.1ossl delete mode 120000 openssl-install/share/man/man1/cms.1ossl delete mode 120000 openssl-install/share/man/man1/crl.1ossl delete mode 120000 openssl-install/share/man/man1/crl2pkcs7.1ossl delete mode 120000 openssl-install/share/man/man1/dgst.1ossl delete mode 120000 openssl-install/share/man/man1/dhparam.1ossl delete mode 120000 openssl-install/share/man/man1/dsa.1ossl delete mode 120000 openssl-install/share/man/man1/dsaparam.1ossl delete mode 120000 openssl-install/share/man/man1/ec.1ossl delete mode 120000 openssl-install/share/man/man1/ecparam.1ossl delete mode 120000 openssl-install/share/man/man1/enc.1ossl delete mode 120000 openssl-install/share/man/man1/engine.1ossl delete mode 120000 openssl-install/share/man/man1/errstr.1ossl delete mode 120000 openssl-install/share/man/man1/gendsa.1ossl delete mode 120000 openssl-install/share/man/man1/genpkey.1ossl delete mode 120000 openssl-install/share/man/man1/genrsa.1ossl delete mode 120000 openssl-install/share/man/man1/info.1ossl delete mode 120000 openssl-install/share/man/man1/kdf.1ossl delete mode 120000 openssl-install/share/man/man1/mac.1ossl delete mode 120000 openssl-install/share/man/man1/nseq.1ossl delete mode 120000 openssl-install/share/man/man1/ocsp.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-asn1parse.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-ca.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-ciphers.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-cmds.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-cmp.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-cms.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-crl.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-crl2pkcs7.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-dgst.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-dhparam.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-dsa.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-dsaparam.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-ec.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-ecparam.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-enc.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-engine.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-errstr.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-fipsinstall.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-format-options.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-gendsa.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-genpkey.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-genrsa.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-info.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-kdf.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-list.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-mac.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-namedisplay-options.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-nseq.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-ocsp.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-passphrase-options.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-passwd.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-pkcs12.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-pkcs7.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-pkcs8.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-pkey.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-pkeyparam.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-pkeyutl.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-prime.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-rand.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-rehash.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-req.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-rsa.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-rsautl.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-s_client.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-s_server.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-s_time.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-sess_id.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-smime.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-speed.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-spkac.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-srp.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-storeutl.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-ts.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-verification-options.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-verify.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-version.1ossl delete mode 100644 openssl-install/share/man/man1/openssl-x509.1ossl delete mode 100644 openssl-install/share/man/man1/openssl.1ossl delete mode 120000 openssl-install/share/man/man1/passwd.1ossl delete mode 120000 openssl-install/share/man/man1/pkcs12.1ossl delete mode 120000 openssl-install/share/man/man1/pkcs7.1ossl delete mode 120000 openssl-install/share/man/man1/pkcs8.1ossl delete mode 120000 openssl-install/share/man/man1/pkey.1ossl delete mode 120000 openssl-install/share/man/man1/pkeyparam.1ossl delete mode 120000 openssl-install/share/man/man1/pkeyutl.1ossl delete mode 120000 openssl-install/share/man/man1/prime.1ossl delete mode 120000 openssl-install/share/man/man1/rand.1ossl delete mode 120000 openssl-install/share/man/man1/rehash.1ossl delete mode 120000 openssl-install/share/man/man1/req.1ossl delete mode 120000 openssl-install/share/man/man1/rsa.1ossl delete mode 120000 openssl-install/share/man/man1/rsautl.1ossl delete mode 120000 openssl-install/share/man/man1/s_client.1ossl delete mode 120000 openssl-install/share/man/man1/s_server.1ossl delete mode 120000 openssl-install/share/man/man1/s_time.1ossl delete mode 120000 openssl-install/share/man/man1/sess_id.1ossl delete mode 120000 openssl-install/share/man/man1/smime.1ossl delete mode 120000 openssl-install/share/man/man1/speed.1ossl delete mode 120000 openssl-install/share/man/man1/spkac.1ossl delete mode 120000 openssl-install/share/man/man1/srp.1ossl delete mode 120000 openssl-install/share/man/man1/storeutl.1ossl delete mode 120000 openssl-install/share/man/man1/ts.1ossl delete mode 100644 openssl-install/share/man/man1/tsget.1ossl delete mode 120000 openssl-install/share/man/man1/verify.1ossl delete mode 120000 openssl-install/share/man/man1/version.1ossl delete mode 120000 openssl-install/share/man/man1/x509.1ossl delete mode 120000 openssl-install/share/man/man3/ACCESS_DESCRIPTION_free.3ossl delete mode 120000 openssl-install/share/man/man3/ACCESS_DESCRIPTION_new.3ossl delete mode 100644 openssl-install/share/man/man3/ADMISSIONS.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_free.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_get0_admissionAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_get0_namingAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_get0_professionInfos.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_new.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_set0_admissionAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_set0_namingAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSIONS_set0_professionInfos.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSION_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSION_SYNTAX_free.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_admissionAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_contentsOfAdmissions.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSION_SYNTAX_new.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_admissionAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_contentsOfAdmissions.3ossl delete mode 120000 openssl-install/share/man/man3/ASIdOrRange_free.3ossl delete mode 120000 openssl-install/share/man/man3/ASIdOrRange_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASIdentifierChoice_free.3ossl delete mode 120000 openssl-install/share/man/man3/ASIdentifierChoice_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASIdentifiers_free.3ossl delete mode 120000 openssl-install/share/man/man3/ASIdentifiers_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ENUMERATED_get.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ENUMERATED_get_int64.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ENUMERATED_set.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ENUMERATED_set_int64.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ENUMERATED_to_BN.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_EXTERN_FUNCS.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_adj.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_check.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_print.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set_string.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_INTEGER_free.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_INTEGER_get.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_INTEGER_get_int64.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_INTEGER_get_uint64.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_INTEGER_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_INTEGER_set.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_INTEGER_set_int64.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_INTEGER_set_uint64.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_INTEGER_to_BN.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ITEM.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ITEM_get.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_ITEM_lookup.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_OBJECT_free.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_OBJECT_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_PRINT_ARG.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STREAM_ARG.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_TABLE.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_STRING_TABLE_add.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_TABLE_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_TABLE_get.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_data.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_free.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_get0_data.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_STRING_length.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_STRING_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_print.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_STRING_print_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_print_ex_fp.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_set.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_to_UTF8.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_type.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_STRING_type_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_adj.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_check.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_cmp_time_t.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_compare.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_diff.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_normalize.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_print.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_print_ex.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_TIME_set.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_set_string.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_set_string_X509.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_to_generalizedtime.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TIME_to_tm.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TYPE_cmp.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_TYPE_get.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TYPE_pack_sequence.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TYPE_set.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TYPE_set1.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_TYPE_unpack_sequence.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_UTCTIME_adj.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_UTCTIME_check.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_UTCTIME_cmp_time_t.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_UTCTIME_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_UTCTIME_print.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_UTCTIME_set.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_UTCTIME_set_string.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_add_oid_module.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_aux_cb.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_aux_const_cb.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ex_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ex_d2i_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ex_free_func.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ex_i2d.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ex_new_ex_func.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ex_new_func.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_ex_print_func.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_generate_nconf.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_generate_v3.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_d2i.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_item_d2i_bio.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_d2i_bio_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_d2i_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_d2i_fp.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_d2i_fp_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_i2d_mem_bio.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_item_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_pack.3ossl delete mode 100644 openssl-install/share/man/man3/ASN1_item_sign.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_sign_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_sign_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_unpack.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_unpack_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_verify.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_verify_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_item_verify_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ASN1_tag2str.3ossl delete mode 120000 openssl-install/share/man/man3/ASRange_free.3ossl delete mode 120000 openssl-install/share/man/man3/ASRange_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_STATUS_EAGAIN.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_STATUS_ERR.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_STATUS_OK.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_STATUS_UNSUPPORTED.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_clear_fd.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_all_fds.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_callback.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_changed_fds.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_fd.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_status.3ossl delete mode 100644 openssl-install/share/man/man3/ASYNC_WAIT_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_callback.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_status.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_wait_fd.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_block_pause.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_callback_fn.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_cleanup_thread.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_get_current_job.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_get_mem_functions.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_get_wait_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_init_thread.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_is_capable.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_pause_job.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_set_mem_functions.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_stack_alloc_fn.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_stack_free_fn.3ossl delete mode 100644 openssl-install/share/man/man3/ASYNC_start_job.3ossl delete mode 120000 openssl-install/share/man/man3/ASYNC_unblock_pause.3ossl delete mode 120000 openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_free.3ossl delete mode 120000 openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_new.3ossl delete mode 120000 openssl-install/share/man/man3/AUTHORITY_KEYID_free.3ossl delete mode 120000 openssl-install/share/man/man3/AUTHORITY_KEYID_new.3ossl delete mode 120000 openssl-install/share/man/man3/BASIC_CONSTRAINTS_free.3ossl delete mode 120000 openssl-install/share/man/man3/BASIC_CONSTRAINTS_new.3ossl delete mode 120000 openssl-install/share/man/man3/BF_cbc_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/BF_cfb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/BF_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/BF_ecb_encrypt.3ossl delete mode 100644 openssl-install/share/man/man3/BF_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/BF_ofb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/BF_options.3ossl delete mode 120000 openssl-install/share/man/man3/BF_set_key.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_ADDR.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_ADDRINFO.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDRINFO_address.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDRINFO_family.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDRINFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDRINFO_next.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDRINFO_protocol.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDRINFO_socktype.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_clear.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_copy.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_dup.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_family.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_free.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_hostname_string.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_new.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_path_string.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_rawaddress.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_rawmake.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_rawport.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ADDR_service_string.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_accept_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_append_filename.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_bind.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_callback_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_callback_fn.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_callback_fn_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_closesocket.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_connect.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ctrl_dgram_connect.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ctrl_get_read_request.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ctrl_get_write_guarantee.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ctrl_pending.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ctrl_reset_read_request.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ctrl_set_connected.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ctrl_wpending.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_debug_callback.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_debug_callback_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_destroy_bio_pair.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_detect_peer_addr.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_caps.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_effective_caps.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_local_addr_cap.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_local_addr_enable.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_mtu.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_mtu_overhead.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_no_trunc.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_get_peer.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_recv_timedout.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_send_timedout.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_set_caps.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_set_local_addr_enable.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_set_mtu.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_set_no_trunc.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_dgram_set_peer.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_do_accept.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_do_connect.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_do_connect_retry.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_do_handshake.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_eof.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_err_is_non_fatal.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_base64.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_f_brotli.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_buffer.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_cipher.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_md.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_null.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_prefix.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_readbuffer.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_f_ssl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_f_zlib.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_f_zstd.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_find_type.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_flush.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_free.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_free_all.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get0_dgram_bio.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_accept_ip_family.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_accept_name.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_accept_port.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_bind_mode.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_buffer_num_lines.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_callback.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_callback_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_cipher_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_cipher_status.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_close.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_conn_address.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_conn_hostname.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_conn_ip_family.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_conn_mode.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_conn_port.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_get_data.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_ex_data.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_fd.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_fp.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_indent.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_info_callback.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_init.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_ktls_recv.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_ktls_send.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_line.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_md.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_md_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_mem_data.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_mem_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_num_renegotiates.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_peer_name.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_peer_port.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_read_request.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_retry_BIO.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_retry_reason.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_get_rpoll_descriptor.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_sock_type.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_ssl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_wpoll_descriptor.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_write_buf_size.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_get_write_guarantee.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_gets.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_hostserv_priorities.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_info_cb.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_int_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_listen.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_lookup.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_lookup_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_lookup_type.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_make_bio_pair.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_callback_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_create.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_destroy.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_gets.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_puts.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_read.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_read_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_recvmmsg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_sendmmsg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_write.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_get_write_ex.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_callback_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_create.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_destroy.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_gets.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_puts.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_read.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_read_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_recvmmsg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_sendmmsg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_write.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_meth_set_write_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_method_type.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_new.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_new_CMS.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_accept.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_bio_dgram_pair.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_bio_pair.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_buffer_ssl_connect.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_connect.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_dgram.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_fd.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_file.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_fp.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_from_core_bio.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_mem_buf.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_socket.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_ssl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_new_ssl_connect.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_next.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_parse_hostserv.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_pending.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_pop.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_printf.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ptr_ctrl.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_push.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_puts.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_read.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_read_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_read_filename.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_recvmmsg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_reset.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_retry_type.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_rw_filename.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_accept.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_bio.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_connect.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_core.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_datagram.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_s_dgram_mem.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_dgram_pair.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_fd.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_file.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_mem.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_null.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_s_secmem.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_s_socket.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_seek.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_sendmmsg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_accept_bios.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_accept_ip_family.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_accept_name.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_accept_port.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_bind_mode.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_buffer_read_data.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_buffer_size.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_set_callback.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_callback_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_close.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_conn_address.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_conn_hostname.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_conn_ip_family.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_conn_mode.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_conn_port.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_data.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_fd.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_fp.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_indent.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_info_callback.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_init.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_md.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_mem_buf.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_mem_eof_return.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_nbio.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_nbio_accept.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_next.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_prefix.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_read_buffer_size.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_retry_reason.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_sock_type.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_ssl.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_ssl_mode.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_ssl_renegotiate_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_ssl_renegotiate_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_tfo.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_tfo_accept.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_write_buf_size.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_set_write_buffer_size.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_should_io_special.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_should_read.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_should_retry.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_should_write.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_shutdown_wr.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_snprintf.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_socket.3ossl delete mode 100644 openssl-install/share/man/man3/BIO_socket_wait.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ssl_copy_session_id.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_ssl_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_tell.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_vfree.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_vprintf.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_vsnprintf.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_wait.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_wpending.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_write.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_write_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BIO_write_filename.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_convert.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_convert_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_create_param.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_free.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_invert.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_invert_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_is_current_thread.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_lock.3ossl delete mode 100644 openssl-install/share/man/man3/BN_BLINDING_new.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_set_current_thread.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_unlock.3ossl delete mode 120000 openssl-install/share/man/man3/BN_BLINDING_update.3ossl delete mode 120000 openssl-install/share/man/man3/BN_CTX_end.3ossl delete mode 120000 openssl-install/share/man/man3/BN_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/BN_CTX_get.3ossl delete mode 100644 openssl-install/share/man/man3/BN_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/BN_CTX_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_CTX_secure_new.3ossl delete mode 120000 openssl-install/share/man/man3/BN_CTX_secure_new_ex.3ossl delete mode 100644 openssl-install/share/man/man3/BN_CTX_start.3ossl delete mode 120000 openssl-install/share/man/man3/BN_GENCB_call.3ossl delete mode 120000 openssl-install/share/man/man3/BN_GENCB_free.3ossl delete mode 120000 openssl-install/share/man/man3/BN_GENCB_get_arg.3ossl delete mode 120000 openssl-install/share/man/man3/BN_GENCB_new.3ossl delete mode 120000 openssl-install/share/man/man3/BN_GENCB_set.3ossl delete mode 120000 openssl-install/share/man/man3/BN_GENCB_set_old.3ossl delete mode 120000 openssl-install/share/man/man3/BN_MONT_CTX_copy.3ossl delete mode 120000 openssl-install/share/man/man3/BN_MONT_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/BN_MONT_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/BN_MONT_CTX_set.3ossl delete mode 120000 openssl-install/share/man/man3/BN_RECP_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/BN_RECP_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/BN_RECP_CTX_set.3ossl delete mode 120000 openssl-install/share/man/man3/BN_abs_is_word.3ossl delete mode 100644 openssl-install/share/man/man3/BN_add.3ossl delete mode 100644 openssl-install/share/man/man3/BN_add_word.3ossl delete mode 120000 openssl-install/share/man/man3/BN_are_coprime.3ossl delete mode 120000 openssl-install/share/man/man3/BN_bin2bn.3ossl delete mode 100644 openssl-install/share/man/man3/BN_bn2bin.3ossl delete mode 120000 openssl-install/share/man/man3/BN_bn2binpad.3ossl delete mode 120000 openssl-install/share/man/man3/BN_bn2dec.3ossl delete mode 120000 openssl-install/share/man/man3/BN_bn2hex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_bn2lebinpad.3ossl delete mode 120000 openssl-install/share/man/man3/BN_bn2mpi.3ossl delete mode 120000 openssl-install/share/man/man3/BN_bn2nativepad.3ossl delete mode 120000 openssl-install/share/man/man3/BN_check_prime.3ossl delete mode 120000 openssl-install/share/man/man3/BN_clear.3ossl delete mode 120000 openssl-install/share/man/man3/BN_clear_bit.3ossl delete mode 120000 openssl-install/share/man/man3/BN_clear_free.3ossl delete mode 100644 openssl-install/share/man/man3/BN_cmp.3ossl delete mode 100644 openssl-install/share/man/man3/BN_copy.3ossl delete mode 120000 openssl-install/share/man/man3/BN_dec2bn.3ossl delete mode 120000 openssl-install/share/man/man3/BN_div.3ossl delete mode 120000 openssl-install/share/man/man3/BN_div_recp.3ossl delete mode 120000 openssl-install/share/man/man3/BN_div_word.3ossl delete mode 120000 openssl-install/share/man/man3/BN_dup.3ossl delete mode 120000 openssl-install/share/man/man3/BN_exp.3ossl delete mode 120000 openssl-install/share/man/man3/BN_free.3ossl delete mode 120000 openssl-install/share/man/man3/BN_from_montgomery.3ossl delete mode 120000 openssl-install/share/man/man3/BN_gcd.3ossl delete mode 100644 openssl-install/share/man/man3/BN_generate_prime.3ossl delete mode 120000 openssl-install/share/man/man3/BN_generate_prime_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_generate_prime_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get0_nist_prime_192.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get0_nist_prime_224.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get0_nist_prime_256.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get0_nist_prime_384.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get0_nist_prime_521.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc2409_prime_1024.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc2409_prime_768.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc3526_prime_1536.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc3526_prime_2048.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc3526_prime_3072.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc3526_prime_4096.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc3526_prime_6144.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_rfc3526_prime_8192.3ossl delete mode 120000 openssl-install/share/man/man3/BN_get_word.3ossl delete mode 120000 openssl-install/share/man/man3/BN_hex2bn.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_bit_set.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_odd.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_one.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_prime.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_prime_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_prime_fasttest.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_prime_fasttest_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_word.3ossl delete mode 120000 openssl-install/share/man/man3/BN_is_zero.3ossl delete mode 120000 openssl-install/share/man/man3/BN_lebin2bn.3ossl delete mode 120000 openssl-install/share/man/man3/BN_lshift.3ossl delete mode 120000 openssl-install/share/man/man3/BN_lshift1.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mask_bits.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_add.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_exp.3ossl delete mode 100644 openssl-install/share/man/man3/BN_mod_exp_mont.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_exp_mont_consttime.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_exp_mont_consttime_x2.3ossl delete mode 100644 openssl-install/share/man/man3/BN_mod_inverse.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_mul.3ossl delete mode 100644 openssl-install/share/man/man3/BN_mod_mul_montgomery.3ossl delete mode 100644 openssl-install/share/man/man3/BN_mod_mul_reciprocal.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_sqr.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_sqrt.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_sub.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mod_word.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mpi2bn.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mul.3ossl delete mode 120000 openssl-install/share/man/man3/BN_mul_word.3ossl delete mode 120000 openssl-install/share/man/man3/BN_native2bn.3ossl delete mode 100644 openssl-install/share/man/man3/BN_new.3ossl delete mode 120000 openssl-install/share/man/man3/BN_nnmod.3ossl delete mode 120000 openssl-install/share/man/man3/BN_num_bits.3ossl delete mode 120000 openssl-install/share/man/man3/BN_num_bits_word.3ossl delete mode 100644 openssl-install/share/man/man3/BN_num_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/BN_one.3ossl delete mode 120000 openssl-install/share/man/man3/BN_print.3ossl delete mode 120000 openssl-install/share/man/man3/BN_print_fp.3ossl delete mode 120000 openssl-install/share/man/man3/BN_priv_rand.3ossl delete mode 120000 openssl-install/share/man/man3/BN_priv_rand_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_priv_rand_range.3ossl delete mode 120000 openssl-install/share/man/man3/BN_priv_rand_range_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_pseudo_rand.3ossl delete mode 120000 openssl-install/share/man/man3/BN_pseudo_rand_range.3ossl delete mode 100644 openssl-install/share/man/man3/BN_rand.3ossl delete mode 120000 openssl-install/share/man/man3/BN_rand_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_rand_range.3ossl delete mode 120000 openssl-install/share/man/man3/BN_rand_range_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BN_rshift.3ossl delete mode 120000 openssl-install/share/man/man3/BN_rshift1.3ossl delete mode 120000 openssl-install/share/man/man3/BN_secure_new.3ossl delete mode 100644 openssl-install/share/man/man3/BN_security_bits.3ossl delete mode 100644 openssl-install/share/man/man3/BN_set_bit.3ossl delete mode 120000 openssl-install/share/man/man3/BN_set_word.3ossl delete mode 120000 openssl-install/share/man/man3/BN_signed_bin2bn.3ossl delete mode 120000 openssl-install/share/man/man3/BN_signed_bn2bin.3ossl delete mode 120000 openssl-install/share/man/man3/BN_signed_bn2lebin.3ossl delete mode 120000 openssl-install/share/man/man3/BN_signed_bn2native.3ossl delete mode 120000 openssl-install/share/man/man3/BN_signed_lebin2bn.3ossl delete mode 120000 openssl-install/share/man/man3/BN_signed_native2bn.3ossl delete mode 120000 openssl-install/share/man/man3/BN_sqr.3ossl delete mode 120000 openssl-install/share/man/man3/BN_sub.3ossl delete mode 120000 openssl-install/share/man/man3/BN_sub_word.3ossl delete mode 100644 openssl-install/share/man/man3/BN_swap.3ossl delete mode 120000 openssl-install/share/man/man3/BN_to_ASN1_ENUMERATED.3ossl delete mode 120000 openssl-install/share/man/man3/BN_to_ASN1_INTEGER.3ossl delete mode 120000 openssl-install/share/man/man3/BN_to_montgomery.3ossl delete mode 120000 openssl-install/share/man/man3/BN_ucmp.3ossl delete mode 120000 openssl-install/share/man/man3/BN_value_one.3ossl delete mode 120000 openssl-install/share/man/man3/BN_with_flags.3ossl delete mode 100644 openssl-install/share/man/man3/BN_zero.3ossl delete mode 120000 openssl-install/share/man/man3/BUF_MEM_free.3ossl delete mode 120000 openssl-install/share/man/man3/BUF_MEM_grow.3ossl delete mode 120000 openssl-install/share/man/man3/BUF_MEM_grow_clean.3ossl delete mode 100644 openssl-install/share/man/man3/BUF_MEM_new.3ossl delete mode 120000 openssl-install/share/man/man3/BUF_MEM_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/BUF_reverse.3ossl delete mode 120000 openssl-install/share/man/man3/CERTIFICATEPOLICIES_free.3ossl delete mode 120000 openssl-install/share/man/man3/CERTIFICATEPOLICIES_new.3ossl delete mode 100644 openssl-install/share/man/man3/CMAC_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_CTX_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_CTX_copy.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_CTX_get0_cipher_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_Final.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_Init.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_Update.3ossl delete mode 120000 openssl-install/share/man/man3/CMAC_resume.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_AuthEnvelopedData_create.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_AuthEnvelopedData_create_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ContentInfo_free.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ContentInfo_new.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ContentInfo_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ContentInfo_print_ctx.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_EncryptedData_decrypt.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_EncryptedData_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_EncryptedData_encrypt_ex.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_EnvelopedData_create.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_EnvelopedData_create_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_EnvelopedData_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_EnvelopedData_it.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ReceiptRequest_create0.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ReceiptRequest_create0_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ReceiptRequest_free.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ReceiptRequest_get0_values.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_ReceiptRequest_new.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey_and_peer.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_kekri_get0_id.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_kekri_id_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_ktri_cert_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_ktri_get0_signer_id.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_set0_key.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_set0_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_RecipientInfo_type.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignedData_free.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignedData_new.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignedData_verify.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignerInfo_cert_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignerInfo_get0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignerInfo_get0_signer_id.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignerInfo_set1_signer_cert.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_SignerInfo_sign.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_add0_cert.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_add0_crl.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_add0_recipient_key.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_add1_ReceiptRequest.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_add1_cert.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_add1_crl.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_add1_recipient.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_add1_recipient_cert.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_add1_signer.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_compress.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_data_create.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_data_create_ex.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_decrypt_set1_password.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_decrypt_set1_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_decrypt_set1_pkey_and_peer.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_digest_create.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_digest_create_ex.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_encrypt_ex.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_final.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_final_digest.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_get0_RecipientInfos.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_get0_SignerInfos.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_get0_content.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_get0_eContentType.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_get0_signers.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_get0_type.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_get1_ReceiptRequest.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_get1_certs.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_get1_crls.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_set1_eContentType.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_sign.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_sign_ex.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_sign_receipt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_add1_attr.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_add1_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_add1_attr_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_delete_attr.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_get0_data_by_OBJ.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_signed_get_attr.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_get_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_get_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_signed_get_attr_count.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_uncompress.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_add1_attr.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_delete_attr.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_get0_data_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_get_attr.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_get_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_get_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/CMS_unsigned_get_attr_count.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_verify.3ossl delete mode 100644 openssl-install/share/man/man3/CMS_verify_receipt.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_CTX_get_method.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_CTX_get_type.3ossl delete mode 100644 openssl-install/share/man/man3/COMP_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_brotli.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_brotli_oneshot.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_compress_block.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_expand_block.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_get_name.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_get_type.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_zlib.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_zlib_oneshot.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_zstd.3ossl delete mode 120000 openssl-install/share/man/man3/COMP_zstd_oneshot.3ossl delete mode 120000 openssl-install/share/man/man3/CONF_get1_default_config_file.3ossl delete mode 120000 openssl-install/share/man/man3/CONF_modules_finish.3ossl delete mode 100644 openssl-install/share/man/man3/CONF_modules_free.3ossl delete mode 120000 openssl-install/share/man/man3/CONF_modules_load.3ossl delete mode 100644 openssl-install/share/man/man3/CONF_modules_load_file.3ossl delete mode 120000 openssl-install/share/man/man3/CONF_modules_load_file_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CONF_modules_unload.3ossl delete mode 120000 openssl-install/share/man/man3/CRL_DIST_POINTS_free.3ossl delete mode 120000 openssl-install/share/man/man3/CRL_DIST_POINTS_new.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_EX_dup.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_EX_free.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_EX_new.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_THREAD_lock_free.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_THREAD_lock_new.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_THREAD_read_lock.3ossl delete mode 100644 openssl-install/share/man/man3/CRYPTO_THREAD_run_once.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_THREAD_unlock.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_THREAD_write_lock.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_aligned_alloc.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_alloc_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_atomic_add.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_atomic_add64.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_atomic_and.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_atomic_load.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_atomic_load_int.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_atomic_or.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_atomic_store.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_clear_free.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_clear_realloc.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_free.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_free_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_free_ex_index.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_free_fn.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_get_alloc_counts.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_get_ex_data.3ossl delete mode 100644 openssl-install/share/man/man3/CRYPTO_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_get_mem_functions.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_malloc.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_malloc_fn.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_mem_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_mem_debug_pop.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_mem_debug_push.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_mem_leaks.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_mem_leaks_cb.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_mem_leaks_fp.3ossl delete mode 100644 openssl-install/share/man/man3/CRYPTO_memcmp.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_new_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_realloc.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_realloc_fn.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_allocated.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_clear_free.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_free.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_malloc.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_malloc_done.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_malloc_init.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_malloc_initialized.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_used.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_secure_zalloc.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_set_mem_debug.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_set_mem_functions.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_strdup.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_strndup.3ossl delete mode 120000 openssl-install/share/man/man3/CRYPTO_zalloc.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_STORE_free.3ossl delete mode 100644 openssl-install/share/man/man3/CTLOG_STORE_get0_log_by_id.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_STORE_load_default_file.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_STORE_load_file.3ossl delete mode 100644 openssl-install/share/man/man3/CTLOG_STORE_new.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_STORE_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_free.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_get0_log_id.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_get0_public_key.3ossl delete mode 100644 openssl-install/share/man/man3/CTLOG_new.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_new_from_base64.3ossl delete mode 120000 openssl-install/share/man/man3/CTLOG_new_from_base64_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_cert.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_log_store.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get_time.3ossl delete mode 100644 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_cert.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE.3ossl delete mode 120000 openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_time.3ossl delete mode 120000 openssl-install/share/man/man3/DECLARE_ASN1_FUNCTIONS.3ossl delete mode 120000 openssl-install/share/man/man3/DECLARE_PEM_rw.3ossl delete mode 120000 openssl-install/share/man/man3/DEFINE_LHASH_OF.3ossl delete mode 120000 openssl-install/share/man/man3/DEFINE_LHASH_OF_EX.3ossl delete mode 120000 openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF.3ossl delete mode 120000 openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF_CONST.3ossl delete mode 100644 openssl-install/share/man/man3/DEFINE_STACK_OF.3ossl delete mode 120000 openssl-install/share/man/man3/DEFINE_STACK_OF_CONST.3ossl delete mode 120000 openssl-install/share/man/man3/DES_cbc_cksum.3ossl delete mode 120000 openssl-install/share/man/man3/DES_cfb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_cfb_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_crypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ecb2_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ecb3_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ecb_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ede2_cbc_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ede2_cfb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ede2_ofb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ede3_cbc_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ede3_cfb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ede3_ofb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_fcrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_is_weak_key.3ossl delete mode 120000 openssl-install/share/man/man3/DES_key_sched.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ncbc_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ofb64_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_ofb_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_pcbc_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DES_quad_cksum.3ossl delete mode 100644 openssl-install/share/man/man3/DES_random_key.3ossl delete mode 120000 openssl-install/share/man/man3/DES_set_key.3ossl delete mode 120000 openssl-install/share/man/man3/DES_set_key_checked.3ossl delete mode 120000 openssl-install/share/man/man3/DES_set_key_unchecked.3ossl delete mode 120000 openssl-install/share/man/man3/DES_set_odd_parity.3ossl delete mode 120000 openssl-install/share/man/man3/DES_string_to_2keys.3ossl delete mode 120000 openssl-install/share/man/man3/DES_string_to_key.3ossl delete mode 120000 openssl-install/share/man/man3/DES_xcbc_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/DH_OpenSSL.3ossl delete mode 120000 openssl-install/share/man/man3/DH_bits.3ossl delete mode 120000 openssl-install/share/man/man3/DH_check.3ossl delete mode 120000 openssl-install/share/man/man3/DH_check_ex.3ossl delete mode 120000 openssl-install/share/man/man3/DH_check_params.3ossl delete mode 120000 openssl-install/share/man/man3/DH_check_params_ex.3ossl delete mode 120000 openssl-install/share/man/man3/DH_check_pub_key_ex.3ossl delete mode 120000 openssl-install/share/man/man3/DH_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DH_compute_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_compute_key_padded.3ossl delete mode 120000 openssl-install/share/man/man3/DH_free.3ossl delete mode 100644 openssl-install/share/man/man3/DH_generate_key.3ossl delete mode 100644 openssl-install/share/man/man3/DH_generate_parameters.3ossl delete mode 120000 openssl-install/share/man/man3/DH_generate_parameters_ex.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get0_engine.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get0_g.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get0_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get0_p.3ossl delete mode 100644 openssl-install/share/man/man3/DH_get0_pqg.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get0_priv_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get0_pub_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get0_q.3ossl delete mode 100644 openssl-install/share/man/man3/DH_get_1024_160.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get_2048_224.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get_2048_256.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get_length.3ossl delete mode 120000 openssl-install/share/man/man3/DH_get_nid.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_dup.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get0_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get_bn_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get_compute_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get_finish.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get_generate_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get_generate_params.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_get_init.3ossl delete mode 100644 openssl-install/share/man/man3/DH_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set0_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set1_name.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set_bn_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set_compute_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set_finish.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set_generate_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set_generate_params.3ossl delete mode 120000 openssl-install/share/man/man3/DH_meth_set_init.3ossl delete mode 100644 openssl-install/share/man/man3/DH_new.3ossl delete mode 100644 openssl-install/share/man/man3/DH_new_by_nid.3ossl delete mode 120000 openssl-install/share/man/man3/DH_new_method.3ossl delete mode 120000 openssl-install/share/man/man3/DH_security_bits.3ossl delete mode 120000 openssl-install/share/man/man3/DH_set0_key.3ossl delete mode 120000 openssl-install/share/man/man3/DH_set0_pqg.3ossl delete mode 120000 openssl-install/share/man/man3/DH_set_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/DH_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/DH_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DH_set_length.3ossl delete mode 100644 openssl-install/share/man/man3/DH_set_method.3ossl delete mode 100644 openssl-install/share/man/man3/DH_size.3ossl delete mode 120000 openssl-install/share/man/man3/DH_test_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DHparams_print.3ossl delete mode 120000 openssl-install/share/man/man3/DHparams_print_fp.3ossl delete mode 120000 openssl-install/share/man/man3/DIRECTORYSTRING_free.3ossl delete mode 120000 openssl-install/share/man/man3/DIRECTORYSTRING_new.3ossl delete mode 120000 openssl-install/share/man/man3/DISPLAYTEXT_free.3ossl delete mode 120000 openssl-install/share/man/man3/DISPLAYTEXT_new.3ossl delete mode 120000 openssl-install/share/man/man3/DIST_POINT_NAME_dup.3ossl delete mode 120000 openssl-install/share/man/man3/DIST_POINT_NAME_free.3ossl delete mode 120000 openssl-install/share/man/man3/DIST_POINT_NAME_new.3ossl delete mode 120000 openssl-install/share/man/man3/DIST_POINT_free.3ossl delete mode 120000 openssl-install/share/man/man3/DIST_POINT_new.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_OpenSSL.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_SIG_free.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_SIG_get0.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_SIG_new.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_SIG_set0.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_bits.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_clear_flags.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_do_sign.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_do_verify.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_dup_DH.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_free.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_generate_key.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_generate_parameters.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_generate_parameters_ex.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get0_engine.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get0_g.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get0_key.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get0_p.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_get0_pqg.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get0_priv_key.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get0_pub_key.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get0_q.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_dup.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get0_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_bn_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_finish.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_init.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_paramgen.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_sign.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_sign_setup.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_get_verify.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set0_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set1_name.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_bn_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_finish.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_init.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_paramgen.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_sign.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_sign_setup.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_meth_set_verify.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_new.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_new_method.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_print.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_print_fp.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_security_bits.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_set0_key.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_set0_pqg.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_set_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_set_flags.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_set_method.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_sign.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_sign_setup.3ossl delete mode 100644 openssl-install/share/man/man3/DSA_size.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_test_flags.3ossl delete mode 120000 openssl-install/share/man/man3/DSA_verify.3ossl delete mode 120000 openssl-install/share/man/man3/DSAparams_dup.3ossl delete mode 120000 openssl-install/share/man/man3/DSAparams_print.3ossl delete mode 120000 openssl-install/share/man/man3/DSAparams_print_fp.3ossl delete mode 120000 openssl-install/share/man/man3/DTLS_client_method.3ossl delete mode 100644 openssl-install/share/man/man3/DTLS_get_data_mtu.3ossl delete mode 120000 openssl-install/share/man/man3/DTLS_method.3ossl delete mode 120000 openssl-install/share/man/man3/DTLS_server_method.3ossl delete mode 100644 openssl-install/share/man/man3/DTLS_set_timer_cb.3ossl delete mode 120000 openssl-install/share/man/man3/DTLS_timer_cb.3ossl delete mode 120000 openssl-install/share/man/man3/DTLSv1_2_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/DTLSv1_2_method.3ossl delete mode 120000 openssl-install/share/man/man3/DTLSv1_2_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/DTLSv1_client_method.3ossl delete mode 100644 openssl-install/share/man/man3/DTLSv1_get_timeout.3ossl delete mode 100644 openssl-install/share/man/man3/DTLSv1_handle_timeout.3ossl delete mode 100644 openssl-install/share/man/man3/DTLSv1_listen.3ossl delete mode 120000 openssl-install/share/man/man3/DTLSv1_method.3ossl delete mode 120000 openssl-install/share/man/man3/DTLSv1_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_SIG_free.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_SIG_get0.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_SIG_get0_r.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_SIG_get0_s.3ossl delete mode 100644 openssl-install/share/man/man3/ECDSA_SIG_new.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_SIG_set0.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_do_sign.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_do_sign_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_do_verify.3ossl delete mode 100644 openssl-install/share/man/man3/ECDSA_sign.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_sign_ex.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_sign_setup.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_size.3ossl delete mode 120000 openssl-install/share/man/man3/ECDSA_verify.3ossl delete mode 120000 openssl-install/share/man/man3/ECPARAMETERS_free.3ossl delete mode 120000 openssl-install/share/man/man3/ECPARAMETERS_new.3ossl delete mode 120000 openssl-install/share/man/man3/ECPKPARAMETERS_free.3ossl delete mode 120000 openssl-install/share/man/man3/ECPKPARAMETERS_new.3ossl delete mode 100644 openssl-install/share/man/man3/ECPKParameters_print.3ossl delete mode 120000 openssl-install/share/man/man3/ECPKParameters_print_fp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GF2m_simple_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GFp_mont_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GFp_nist_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GFp_nistp224_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GFp_nistp256_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GFp_nistp521_method.3ossl delete mode 100644 openssl-install/share/man/man3/EC_GFp_simple_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_check.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_check_discriminant.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_check_named_curve.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_clear_free.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_cmp.3ossl delete mode 100644 openssl-install/share/man/man3/EC_GROUP_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_free.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get0_cofactor.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get0_field.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get0_generator.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get0_order.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get0_seed.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_asn1_flag.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_basis_type.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_cofactor.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_curve.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_curve_GF2m.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_curve_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_curve_name.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_degree.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_ecparameters.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_ecpkparameters.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_field_type.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_order.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_pentanomial_basis.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_point_conversion_form.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_seed_len.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_get_trinomial_basis.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_have_precompute_mult.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_method_of.3ossl delete mode 100644 openssl-install/share/man/man3/EC_GROUP_new.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_new_by_curve_name.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_new_by_curve_name_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_new_curve_GF2m.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_new_curve_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_new_from_ecparameters.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_new_from_ecpkparameters.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_new_from_params.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_order_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_precompute_mult.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_asn1_flag.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_curve.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_curve_GF2m.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_curve_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_curve_name.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_generator.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_point_conversion_form.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_set_seed.3ossl delete mode 120000 openssl-install/share/man/man3/EC_GROUP_to_params.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_check_key.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_decoded_from_explicit_params.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_free.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_generate_key.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get0_engine.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get0_group.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get0_private_key.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get0_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get_conv_form.3ossl delete mode 100644 openssl-install/share/man/man3/EC_KEY_get_enc_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_get_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_key2buf.3ossl delete mode 100644 openssl-install/share/man/man3/EC_KEY_new.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_new_by_curve_name.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_new_by_curve_name_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_oct2key.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_oct2priv.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_precompute_mult.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_priv2buf.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_priv2oct.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_asn1_flag.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_conv_form.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_enc_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_group.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_method.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_private_key.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_set_public_key_affine_coordinates.3ossl delete mode 120000 openssl-install/share/man/man3/EC_KEY_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EC_METHOD_get_field_type.3ossl delete mode 100644 openssl-install/share/man/man3/EC_POINT_add.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_bn2point.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_clear_free.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_dbl.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_free.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_get_Jprojective_coordinates_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_get_affine_coordinates.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GF2m.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_hex2point.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_invert.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_is_at_infinity.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_is_on_curve.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_make_affine.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_method_of.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_mul.3ossl delete mode 100644 openssl-install/share/man/man3/EC_POINT_new.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_oct2point.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_point2bn.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_point2buf.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_point2hex.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_point2oct.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_Jprojective_coordinates_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_affine_coordinates.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GF2m.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GF2m.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GFp.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINT_set_to_infinity.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINTs_make_affine.3ossl delete mode 120000 openssl-install/share/man/man3/EC_POINTs_mul.3ossl delete mode 120000 openssl-install/share/man/man3/EC_get_builtin_curves.3ossl delete mode 120000 openssl-install/share/man/man3/EDIPARTYNAME_free.3ossl delete mode 120000 openssl-install/share/man/man3/EDIPARTYNAME_new.3ossl delete mode 100644 openssl-install/share/man/man3/ENGINE_add.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_add_conf_module.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_by_id.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_cmd_is_executable.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_ctrl_cmd.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_ctrl_cmd_string.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_finish.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_free.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_DH.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_cipher_engine.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_cmd_defns.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_ctrl_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_default_DH.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_default_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_default_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_default_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_destroy_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_digest.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_digest_engine.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_digests.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_finish_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_first.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_id.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_init_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_last.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_load_privkey_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_load_pubkey_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_name.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_next.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_prev.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_get_table_flags.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_init.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_load_builtin_engines.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_load_private_key.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_load_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_new.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_DH.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_all_DH.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_all_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_all_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_all_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_all_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_all_complete.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_all_digests.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_complete.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_register_digests.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_remove.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_DH.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_cmd_defns.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_ctrl_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default_DH.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default_digests.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_default_string.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_destroy_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_digests.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_finish_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_id.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_init_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_load_privkey_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_load_pubkey_function.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_name.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_set_table_flags.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_unregister_DH.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_unregister_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_unregister_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_unregister_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_unregister_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_unregister_digests.3ossl delete mode 120000 openssl-install/share/man/man3/ENGINE_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_FATAL_ERROR.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_GET_LIB.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_GET_REASON.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_PACK.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_add_error_data.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_add_error_mem_bio.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_add_error_txt.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_add_error_vdata.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_clear_error.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_clear_last_mark.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_count_to_mark.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_error_string.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_error_string_n.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_free_strings.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_func_error_string.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_get_error.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_get_error_all.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_get_error_line.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_get_error_line_data.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_get_next_error_library.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_lib_error_string.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_load_crypto_strings.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_load_strings.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_new.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_error.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_error_all.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_error_data.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_error_func.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_error_line.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_error_line_data.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_last_error.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_last_error_all.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_last_error_data.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_last_error_func.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_last_error_line.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_peek_last_error_line_data.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_pop.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_pop_to_mark.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_print_errors.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_print_errors_cb.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_print_errors_fp.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_put_error.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_raise.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_raise_data.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_reason_error_string.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_remove_state.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_remove_thread_state.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_set_debug.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_set_error.3ossl delete mode 100644 openssl-install/share/man/man3/ERR_set_mark.3ossl delete mode 120000 openssl-install/share/man/man3/ERR_vset_error.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_CERT_ID_V2_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_CERT_ID_V2_free.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_CERT_ID_V2_new.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_CERT_ID_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_CERT_ID_free.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_CERT_ID_new.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_ISSUER_SERIAL_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_ISSUER_SERIAL_free.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_ISSUER_SERIAL_new.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_free.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_it.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_new.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_dup.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_free.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_it.3ossl delete mode 120000 openssl-install/share/man/man3/ESS_SIGNING_CERT_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_fetch.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_ASYM_CIPHER_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ASYM_CIPHER_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_BytesToKey.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_encrypting.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get1_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_block_size.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_cipher_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_iv_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_key_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_mode.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_num.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_original_iv.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_tag_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_get_updated_iv.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_is_encrypting.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_iv.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_noconst.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_key_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_mode.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_num.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_original_iv.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_reset.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_algor_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_cipher_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_key_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_num.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_padding.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_tag_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_test_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_CTX_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_asn1_to_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_iv_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_key_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_mode.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_get_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_iv_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_key_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_get_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_get_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_get_do_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_get_get_asn1_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_get_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_get_set_asn1_params.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_CIPHER_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_do_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_get_asn1_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_impl_ctx_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_iv_length.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_meth_set_set_asn1_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_mode.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_param_to_asn1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CIPHER_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_Cipher.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CipherFinal.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CipherFinal_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CipherInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CipherInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CipherInit_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_CipherUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecodeBlock.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecodeFinal.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecodeInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecodeUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecryptFinal.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecryptFinal_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecryptInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecryptInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecryptInit_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DecryptUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_Digest.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestFinal.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestFinalXOF.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestFinal_ex.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_DigestInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestInit_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestSign.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestSignFinal.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_DigestSignInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestSignInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestSignUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestSqueeze.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestVerify.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestVerifyFinal.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_DigestVerifyInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestVerifyInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_DigestVerifyUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EC_gen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ENCODE_CTX_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ENCODE_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ENCODE_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_ENCODE_CTX_num.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncodeBlock.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncodeFinal.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_EncodeInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncodeUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncryptFinal.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncryptFinal_ex.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_EncryptInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncryptInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncryptInit_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_EncryptUpdate.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_KDF.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_get_kdf_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_kdf.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_reset.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_CTX_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_derive.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KDF_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_fetch.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_KEM_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEM_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_fetch.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_KEYEXCH_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYEXCH_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_KEYMGMT.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_gen_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_gen_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_KEYMGMT_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_MAC.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_get0_mac.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_get_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_get_mac_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_CTX_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_final.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_finalXOF.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MAC_update.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_copy_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get0_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get0_md_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get1_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get_pkey_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get_size_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_get_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_md_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_pkey_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_reset.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_set_pkey_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_set_update_fn.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_test_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_CTX_update_fn.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get_block_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get_pkey_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_get_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_app_datasize.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_final.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_input_blocksize.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_result_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_get_update.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_MD_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_app_datasize.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_final.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_input_blocksize.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_result_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_meth_set_update.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_pkey_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_MD_xof.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_OpenFinal.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_OpenInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_OpenUpdate.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PBE_CipherInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PBE_CipherInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PBE_alg_add.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PBE_alg_add_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PBE_find.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PBE_find_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PBE_scrypt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PBE_scrypt_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKCS82PKEY.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKCS82PKEY_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY2PKCS8.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_ASN1_METHOD.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_add1_hkdf_info.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_add1_tls1_prf_seed.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_str.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_uint64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_dup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_oid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_ukm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_ecdh_kdf_ukm.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_libctx.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_peerkey.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_propq.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get0_rsa_oaep_label.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id_len.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_cb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_outlen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_cofactor_mode.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_outlen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_group_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_keygen_info.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_padding.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_pss_saltlen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_get_signature_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_md.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_new_id.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_oid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_ukm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set0_ecdh_kdf_ukm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set0_rsa_oaep_label.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_salt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set1_id.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_set1_pbe_pass.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set1_rsa_keygen_pubexp.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set1_scrypt_salt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set1_tls1_prf_secret.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_algor_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_cb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_outlen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_pad.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_generator.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_gindex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_prime_len.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_seed.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_subprime_len.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_rfc5114.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dhx_rfc5114.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_gindex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md_props.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_q_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_seed.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_param_enc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_paramgen_curve_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_cofactor_mode.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_outlen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_group_name.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_mode.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_kem_op.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_mac_key.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_primes.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_pubexp.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_padding.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_saltlen.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_N.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_maxmem_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_p.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_r.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature_md.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_CTX_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_METHOD.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_Q_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_add1_attr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_add0.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_add_alias.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_find.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_find_str.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_get0.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_get0_info.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_asn1_get_count.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_priv_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_pub_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_item.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_param_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_private.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_public.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_public_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_security_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_priv_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_pub_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_asn1_set_siginf.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_assign_DH.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_assign_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_assign_EC_KEY.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_assign_POLY1305.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_assign_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_assign_SIPHASH.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_auth_decapsulate_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_auth_encapsulate_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_base_id.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_can_sign.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_cmp_parameters.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_copy_parameters.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_decapsulate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_decapsulate_init.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_decrypt_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_decrypt_init_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_delete_attr.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_derive.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_derive_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_derive_init_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_derive_set_peer.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_derive_set_peer_ex.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_digestsign_supports_digest.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_dup.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_encapsulate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_encapsulate_init.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_encrypt_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_encrypt_init_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_eq.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_export.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_free.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_fromdata.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_fromdata_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_fromdata_settable.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_gen_cb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_generate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_DH.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_EC_KEY.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_asn1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_engine.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_hmac.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_poly1305.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_siphash.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get0_type_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get1_DH.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get1_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get1_EC_KEY.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get1_RSA.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get1_encoded_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get1_tls_encodedpoint.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_get_attr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_attr_count.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_base_id.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_bn_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_default_digest_name.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_get_default_digest_nid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_ec_point_conv_form.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_ex_new_index.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_get_field_type.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_get_group_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_id.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_int_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_octet_string_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_raw_private_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_raw_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_security_bits.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_get_size.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_size_t_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_get_utf8_string_param.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_id.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_is_a.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_keygen_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_add0.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_find.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get0.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get0_info.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_copy.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_meth_get_count.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_derive.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_digest_custom.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_digestsign.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_digestverify.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_param_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_paramgen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_public_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_sign.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_signctx.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_verify.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_verify_recover.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_get_verifyctx.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_remove.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_copy.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_derive.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_digest_custom.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_digestsign.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_digestverify.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_param_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_paramgen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_public_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_sign.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_signctx.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_verify.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_verify_recover.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_meth_set_verifyctx.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_missing_parameters.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_new_CMAC_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_new_mac_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_pairwise_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_param_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_param_check_quick.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_parameters_eq.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_paramgen.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_paramgen_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_print_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_print_params_fp.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_print_private.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_print_private_fp.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_print_public.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_print_public_fp.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_private_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_public_check.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_public_check_quick.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_security_bits.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set1_DH.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set1_DSA.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set1_EC_KEY.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_set1_RSA.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_set1_encoded_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set1_engine.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set1_tls_encodedpoint.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_bn_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_int_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_octet_string_param.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_size_t_param.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_set_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_type_by_keymgmt.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_type_str.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_set_utf8_string_param.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_settable_params.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_sign.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_sign_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_sign_init_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_sign_init_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_sign_message_final.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_sign_message_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_sign_message_update.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_size.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_todata.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_type.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_type_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_verify.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_init_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_init_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_message_final.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_message_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_message_update.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_PKEY_verify_recover.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_recover_init.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_Q_digest.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_Q_mac.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_RAND.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_get0_rand.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_settable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_CTX_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_STATE_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_STATE_READY.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_STATE_UNINITIALISED.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_enable_locking.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_generate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_get_state.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_get_strength.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_instantiate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_nonce.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_reseed.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_uninstantiate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RAND_verify_zeroization.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_RSA_gen.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_SIGNATURE.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_free.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_gettable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SIGNATURE_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SealFinal.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_SealInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SealUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SignFinal.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SignFinal_ex.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_SignInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SignInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_SignUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_VerifyFinal.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_VerifyFinal_ex.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_VerifyInit.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_VerifyInit_ex.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_VerifyUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha256.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_ccm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_ecb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_aes_128_gcm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_ocb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_wrap.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_wrap_pad.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_128_xts.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_ccm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_gcm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_ocb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_wrap.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_192_wrap_pad.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha256.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_ccm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_gcm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_ocb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_wrap.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_wrap_pad.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aes_256_xts.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_ccm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_ecb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_aria_128_gcm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_128_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_ccm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_gcm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_192_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_ccm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_gcm.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_aria_256_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_bf_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_bf_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_bf_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_bf_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_bf_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_blake2b512.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_blake2s256.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_128_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_128_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_128_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_128_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_128_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_128_ctr.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_camellia_128_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_128_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_192_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_camellia_256_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_cast5_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_cast5_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_cast5_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_cast5_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_cast5_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_chacha20.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_chacha20_poly1305.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_default_properties_enable_fips.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_default_properties_is_fips_enabled.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_des_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_cfb1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_cfb8.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede3_wrap.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ede_ofb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_des_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_desx_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_enc_null.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_get_cipherbyname.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_get_cipherbynid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_get_cipherbyobj.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_get_digestbyname.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_get_digestbynid.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_get_digestbyobj.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_idea_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_idea_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_idea_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_idea_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_idea_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_md2.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_md4.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_md5.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_md5_sha1.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_md_null.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_mdc2.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc2_40_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc2_64_cbc.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_rc2_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc2_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc2_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc2_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc2_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_rc4.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc4_40.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc4_hmac_md5.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_rc5_32_12_16_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb64.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc5_32_12_16_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_rc5_32_12_16_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_ripemd160.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_seed_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_seed_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_seed_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_seed_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_seed_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_set_default_properties.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_sha1.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_sha224.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha256.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha384.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_sha3_224.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha3_256.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha3_384.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha3_512.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha512.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha512_224.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sha512_256.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_shake128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_shake256.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_sm3.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_sm4_cbc.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sm4_cfb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sm4_cfb128.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sm4_ctr.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sm4_ecb.3ossl delete mode 120000 openssl-install/share/man/man3/EVP_sm4_ofb.3ossl delete mode 100644 openssl-install/share/man/man3/EVP_whirlpool.3ossl delete mode 120000 openssl-install/share/man/man3/EXTENDED_KEY_USAGE_free.3ossl delete mode 120000 openssl-install/share/man/man3/EXTENDED_KEY_USAGE_new.3ossl delete mode 120000 openssl-install/share/man/man3/EXT_UTF8STRING.3ossl delete mode 100644 openssl-install/share/man/man3/GENERAL_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_NAMES_free.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_NAMES_new.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_NAME_dup.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_NAME_free.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_NAME_new.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_NAME_set1_X509_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_SUBTREE_free.3ossl delete mode 120000 openssl-install/share/man/man3/GENERAL_SUBTREE_new.3ossl delete mode 120000 openssl-install/share/man/man3/GEN_SESSION_CB.3ossl delete mode 100644 openssl-install/share/man/man3/HMAC.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_CTX_copy.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_CTX_get_md.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_CTX_reset.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_CTX_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_Final.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_Init.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_Init_ex.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_Update.3ossl delete mode 120000 openssl-install/share/man/man3/HMAC_size.3ossl delete mode 120000 openssl-install/share/man/man3/IMPLEMENT_ASN1_FUNCTIONS.3ossl delete mode 120000 openssl-install/share/man/man3/IMPLEMENT_EXTERN_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/IMPLEMENT_LHASH_COMP_FN.3ossl delete mode 120000 openssl-install/share/man/man3/IMPLEMENT_LHASH_HASH_FN.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressChoice_free.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressChoice_new.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressFamily_free.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressFamily_new.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressOrRange_free.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressOrRange_new.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressRange_free.3ossl delete mode 120000 openssl-install/share/man/man3/IPAddressRange_new.3ossl delete mode 120000 openssl-install/share/man/man3/ISSUER_SIGN_TOOL_free.3ossl delete mode 120000 openssl-install/share/man/man3/ISSUER_SIGN_TOOL_it.3ossl delete mode 120000 openssl-install/share/man/man3/ISSUER_SIGN_TOOL_new.3ossl delete mode 120000 openssl-install/share/man/man3/ISSUING_DIST_POINT_free.3ossl delete mode 120000 openssl-install/share/man/man3/ISSUING_DIST_POINT_it.3ossl delete mode 120000 openssl-install/share/man/man3/ISSUING_DIST_POINT_new.3ossl delete mode 120000 openssl-install/share/man/man3/LHASH.3ossl delete mode 120000 openssl-install/share/man/man3/LHASH_DOALL_ARG_FN_TYPE.3ossl delete mode 120000 openssl-install/share/man/man3/LHASH_OF.3ossl delete mode 120000 openssl-install/share/man/man3/MD2.3ossl delete mode 120000 openssl-install/share/man/man3/MD2_Final.3ossl delete mode 120000 openssl-install/share/man/man3/MD2_Init.3ossl delete mode 120000 openssl-install/share/man/man3/MD2_Update.3ossl delete mode 120000 openssl-install/share/man/man3/MD4.3ossl delete mode 120000 openssl-install/share/man/man3/MD4_Final.3ossl delete mode 120000 openssl-install/share/man/man3/MD4_Init.3ossl delete mode 120000 openssl-install/share/man/man3/MD4_Update.3ossl delete mode 100644 openssl-install/share/man/man3/MD5.3ossl delete mode 120000 openssl-install/share/man/man3/MD5_Final.3ossl delete mode 120000 openssl-install/share/man/man3/MD5_Init.3ossl delete mode 120000 openssl-install/share/man/man3/MD5_Update.3ossl delete mode 120000 openssl-install/share/man/man3/MDC2.3ossl delete mode 120000 openssl-install/share/man/man3/MDC2_Final.3ossl delete mode 100644 openssl-install/share/man/man3/MDC2_Init.3ossl delete mode 120000 openssl-install/share/man/man3/MDC2_Update.3ossl delete mode 120000 openssl-install/share/man/man3/NAME_CONSTRAINTS_free.3ossl delete mode 120000 openssl-install/share/man/man3/NAME_CONSTRAINTS_new.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_free.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityId.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityText.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityURL.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_new.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityId.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityText.3ossl delete mode 120000 openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityURL.3ossl delete mode 120000 openssl-install/share/man/man3/NCONF_default.3ossl delete mode 120000 openssl-install/share/man/man3/NCONF_free.3ossl delete mode 120000 openssl-install/share/man/man3/NCONF_get0_libctx.3ossl delete mode 120000 openssl-install/share/man/man3/NCONF_get_section.3ossl delete mode 120000 openssl-install/share/man/man3/NCONF_get_section_names.3ossl delete mode 120000 openssl-install/share/man/man3/NCONF_load.3ossl delete mode 120000 openssl-install/share/man/man3/NCONF_new.3ossl delete mode 100644 openssl-install/share/man/man3/NCONF_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_free.3ossl delete mode 120000 openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_new.3ossl delete mode 120000 openssl-install/share/man/man3/NETSCAPE_SPKAC_free.3ossl delete mode 120000 openssl-install/share/man/man3/NETSCAPE_SPKAC_new.3ossl delete mode 120000 openssl-install/share/man/man3/NETSCAPE_SPKI_free.3ossl delete mode 120000 openssl-install/share/man/man3/NETSCAPE_SPKI_new.3ossl delete mode 120000 openssl-install/share/man/man3/NOTICEREF_free.3ossl delete mode 120000 openssl-install/share/man/man3/NOTICEREF_new.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_add_sigid.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_create.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_get0_data.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_length.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_ln2nid.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_nid2ln.3ossl delete mode 100644 openssl-install/share/man/man3/OBJ_nid2obj.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_nid2sn.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_obj2nid.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_obj2txt.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_sn2nid.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_txt2nid.3ossl delete mode 120000 openssl-install/share/man/man3/OBJ_txt2obj.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_BASICRESP_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_BASICRESP_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_CERTID_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_CERTID_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_CERTID_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_CERTSTATUS_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_CERTSTATUS_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_CRLID_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_CRLID_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_ONEREQ_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_ONEREQ_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQINFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQINFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQUEST_free.3ossl delete mode 100644 openssl-install/share/man/man3/OCSP_REQUEST_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQ_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQ_CTX_add1_header.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQ_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQ_CTX_i2d.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REQ_CTX_set1_req.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPBYTES_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPBYTES_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPDATA_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPDATA_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPID_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPID_match.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPID_match_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPID_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPID_set_by_key.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPID_set_by_key_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPID_set_by_name.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPONSE_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_RESPONSE_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REVOKEDINFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_REVOKEDINFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_SERVICELOC_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_SERVICELOC_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_SIGNATURE_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_SIGNATURE_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_SINGLERESP_free.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_SINGLERESP_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_basic_add1_nonce.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_basic_sign.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_basic_sign_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_basic_verify.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_cert_id_new.3ossl delete mode 100644 openssl-install/share/man/man3/OCSP_cert_to_id.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_check_nonce.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_check_validity.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_copy_nonce.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_id_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_id_get0_info.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_id_issuer_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_parse_url.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_request_add0_id.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_request_add1_cert.3ossl delete mode 100644 openssl-install/share/man/man3/OCSP_request_add1_nonce.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_request_onereq_count.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_request_onereq_get0.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_request_sign.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_count.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_find.3ossl delete mode 100644 openssl-install/share/man/man3/OCSP_resp_find_status.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0_certs.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0_id.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0_produced_at.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0_respdata.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0_signer.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get0_tbs_sigalg.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_resp_get1_id.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_response_create.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_response_get1_basic.3ossl delete mode 100644 openssl-install/share/man/man3/OCSP_response_status.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_sendreq_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_sendreq_nbio.3ossl delete mode 100644 openssl-install/share/man/man3/OCSP_sendreq_new.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_set_max_response_length.3ossl delete mode 120000 openssl-install/share/man/man3/OCSP_single_get0_status.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_Applink.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_FILE.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_FUNC.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_INIT_free.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_INIT_new.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_INIT_set_config_appname.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_INIT_set_config_file_flags.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_INIT_set_config_filename.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_LH_COMPFUNC.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_DOALL_FUNC.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_HASHFUNC.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_delete.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_doall.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_doall_arg.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_doall_arg_thunk.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_error.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_flush.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_free.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_get_down_load.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_insert.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_new.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_node_stats.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_node_stats_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_num_items.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_retrieve.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_set_down_load.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_set_thunks.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_LH_stats.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LH_stats_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_LINE.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_MALLOC_FAILURES.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_MALLOC_FD.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_MSTR.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_MSTR_HELPER.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_BUILD_METADATA.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_MAJOR.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_MINOR.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_NUMBER.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_PATCH.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_PREREQ.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_PRE_RELEASE.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_VERSION_TEXT.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_aligned_alloc.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_atexit.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_buf2hexstr.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_buf2hexstr_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_cipher_name.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_cleanse.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_clear_free.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_clear_realloc.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_config.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_fork_child.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_fork_parent.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_fork_prepare.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_free.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_gmtime.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_gmtime_adj.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_gmtime_diff.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_hexchar2int.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_hexstr2buf.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_hexstr2buf_ex.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_ia32cap.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_info.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_init_crypto.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_init_ssl.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_instrument_bus.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_instrument_bus2.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_load_builtin_modules.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_malloc.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_malloc_init.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_mem_debug_pop.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_mem_debug_push.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_memdup.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_no_config.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_realloc.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_riscvcap.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_s390xcap.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_secure_actual_size.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_secure_clear_free.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_secure_free.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_secure_malloc.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_secure_zalloc.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_deep_copy.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_delete.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_delete_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_find.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_find_all.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_find_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_free.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_insert.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_is_sorted.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_new.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_new_null.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_new_reserve.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_num.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_pop.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_pop_free.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_push.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_reserve.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_set.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_set_cmp_func.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_shift.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_sort.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_unshift.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_value.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_sk_zero.3ossl delete mode 100644 openssl-install/share/man/man3/OPENSSL_strcasecmp.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_strdup.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_strlcat.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_strlcpy.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_strncasecmp.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_strndup.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_strtoul.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_thread_stop.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_thread_stop_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_version_build_metadata.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_version_major.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_version_minor.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_version_patch.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_version_pre_release.3ossl delete mode 120000 openssl-install/share/man/man3/OPENSSL_zalloc.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ALGORITHM.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_new.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CALLBACK.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAVS.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAVS_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAVS_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAVS_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_create.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_algId.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_type.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_value.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_get_rsaKeyLen.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_new_algId.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_new_rsaKeyLen.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ATAV_push1.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_ATAV_set0.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_create.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_get0.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_new1.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_build_cert_chain.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_geninfo_ITAVs.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_libctx.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newCert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newPkey.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_propq.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_statusString.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trusted.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trustedStore.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_untrusted.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get0_validatedSrvCert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get1_caPubs.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get1_extraCertsIn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get1_newChain.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get_certConf_cb_arg.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get_failInfoCode.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get_http_cb_arg.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get_option.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get_status.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_get_transfer_cb_arg.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_print_errors.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_push0_geninfo_ITAV.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_push0_genm_ITAV.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_push0_policy.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_push1_subjectAltName.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_reinit.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_reqExtensions_have_SAN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_reset_geninfo_ITAVs.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_server_perform.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set0_newPkey.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set0_reqExtensions.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trusted.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trustedStore.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_cert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_expected_sender.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_extraCertsOut.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_no_proxy.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_oldCert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_p10CSR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_proxy.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_recipient.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_referenceValue.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_secretValue.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_senderNonce.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_server.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serverPath.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_srvCert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_subjectName.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_transactionID.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set1_untrusted.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb_arg.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb_arg.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_verbosity.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_option.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_serverPort.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb_arg.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_setup_CRM.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_CTX_snprint_PKIStatus.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_HDR_get0_geninfo_ITAVs.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_HDR_get0_recipNonce.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_HDR_get0_transactionID.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_IR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_create.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_caCerts.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_certProfile.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crlStatusList.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crls.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaCert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaKeyUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_type.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_value.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_get1_certReqTemplate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certProfile.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certReqTemplate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_crlStatusList.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_ITAV_new_caCerts.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_new_crls.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaCert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaKeyUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_ITAV_push0_stack_item.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_ITAV_set0.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_KUR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_ALERT.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_CRIT.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_DEBUG.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_EMERG.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_ERR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_NOTICE.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_TRACE.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_LOG_WARNING.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_get0_certreq_publickey.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_MSG_get0_header.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_get_bodytype.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_MSG_http_perform.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_read.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_update_recipNonce.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_update_transactionID.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_MSG_write.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_P10CR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKISI_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKISI_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKISI_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKISI_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_PKISTATUS_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_cmp_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_custom_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init_trans.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_raverified.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_unprotected.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_grant_implicit_confirm.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_send_unprotected_errors.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_certConf_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_cert_request_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_clean_transaction_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_delayed_delivery_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_error_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_genm_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_pollReq_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_process_request.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_SRV_rr_cb_t.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_STATUSINFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_certConf_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_certConf_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_exec_CR_ses.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_exec_GENM_ses.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_exec_IR_ses.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_exec_KUR_ses.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_exec_P10CR_ses.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_exec_RR_ses.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_exec_certreq.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_get1_caCerts.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_get1_certReqTemplate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_get1_crlUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_get1_rootCaKeyUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_log_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_log_close.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_log_open.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_print_errors_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_print_to_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_severity.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_snprint_PKIStatusInfo.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_transfer_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_try_certreq.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CMP_validate_cert_path.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CMP_validate_msg.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CORE_MAKE_FUNC.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTID_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTID_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTID_gen.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTID_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTID_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_fill.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_publicKey.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_subject.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSGS_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSGS_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSGS_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSGS_verify_popo.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_create_popo.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_authenticator.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_oldCertID.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_regToken.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_certReq.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_utf8Pairs.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_tmpl.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_get_certReqId.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_push0_extension.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_SinglePubInfo.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_extensions.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_validity.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_authenticator.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_oldCertID.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_utf8Pairs.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set_PKIPublicationInfo_action.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_MSG_set_certReqId.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_CRMF_pbm_new.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_CRMF_pbmp_new.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_DECODER.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CLEANUP.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CONSTRUCT.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_DECODER_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_add_decoder.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_add_extra.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_get_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct_data.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_get_num_decoders.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_new.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_DECODER_CTX_new_for_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct_data.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_structure.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_type.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_ui.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_pem_password_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_CTX_set_selection.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_INSTANCE.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_structure.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_type.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_export.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_free.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_DECODER_from_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_from_data.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_from_fp.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_get0_properties.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_settable_ctx_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DECODER_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_DISPATCH.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_DISPATCH_END.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_EC_curve_nid2name.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ENCODER.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CLEANUP.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CONSTRUCT.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ENCODER_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_encoder.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_extra.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_get_num_encoders.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_new.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ENCODER_CTX_new_for_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct_data.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_structure.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_type.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_ui.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_pem_password_cb.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_selection.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_structure.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_type.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_get0_properties.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_settable_ctx_params.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ENCODER_to_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_to_data.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_to_fp.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ENCODER_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ERR_STATE_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ERR_STATE_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ERR_STATE_restore.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ERR_STATE_save.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ERR_STATE_save_to_mark.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ESS_check_signing_certs.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ESS_signing_cert_new_init.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ESS_signing_cert_v2_new_init.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_GENERAL_NAMES_print.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_CTX_get_seq.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_HPKE_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpriv.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpub.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_ikme.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_psk.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_CTX_set_seq.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_decap.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_encap.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_export.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_get_ciphertext_size.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_get_grease_value.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_get_public_encap_size.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_get_recommended_ikmelen.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_open.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_seal.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_str2suite.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HPKE_suite_check.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_add1_header.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_exchange.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get0_mem_bio.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get_resp_len.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set1_req.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_expected.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_length.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_request_line.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_adapt_proxy.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_bio_cb_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_close.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_exchange.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_get.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_is_alive.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_open.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_HTTP_parse_url.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_proxy_connect.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_HTTP_set1_request.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_HTTP_transfer.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_add1_value.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_value.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get_value_num.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_new.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_print.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_INDICATOR_get_callback.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_INDICATOR_set_callback.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuerUID.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_serial.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuerUID.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_serial.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_ITEM.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_LIB_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_get0_global_default.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_get_conf_diagnostics.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_get_data.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_load_config.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_new_child.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_new_from_dispatch.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_LIB_CTX_set0_default.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_LIB_CTX_set_conf_diagnostics.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_get0_digest.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_set1_digest.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_PARAM.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_PARAM_BLD.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN_pad.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_double.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_long.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_size_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_time_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_ulong.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BLD_to_param.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_BN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_DEFN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_END.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_UNMODIFIED.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_PARAM_allocate_from_text.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_BN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_double.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_end.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_int.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_int32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_int64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_long.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_octet_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_octet_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_size_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_time_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_uint.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_uint32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_uint64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_ulong.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_double.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_PARAM_dup.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_BN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_double.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_int.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_int32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_int64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_long.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_octet_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_octet_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_octet_string_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_size_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_time_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_uint.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_uint32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_uint64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_ulong.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_utf8_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string_ptr.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_PARAM_int.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_int32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_int64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_locate.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_locate_const.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_long.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_merge.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_modified.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_octet_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_octet_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_BN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_all_unmodified.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_double.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_int.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_int32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_int64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_long.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_octet_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_octet_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_size_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_time_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_uint.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_uint32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_uint64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_ulong.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_utf8_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_set_utf8_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_size_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_time_t.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_uint.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_uint32.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_uint64.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_ulong.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_utf8_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PARAM_utf8_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PASSPHRASE_CALLBACK.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_PROVIDER.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_add_builtin.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_available.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_get0_default_search_path.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_get0_dispatch.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_get0_provider_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_get_capabilities.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_get_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_gettable_params.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_load.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_load_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_query_operation.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_self_test.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_set_default_search_path.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_try_load.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_try_load_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_unload.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_PROVIDER_unquery_operation.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_AEAD_LIMIT_REACHED.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_APPLICATION_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_REFUSED.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_END.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_FINAL_SIZE_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_FLOW_CONTROL_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_FRAME_ENCODING_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_INTERNAL_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_INVALID_TOKEN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_KEY_UPDATE_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_VIABLE_PATH.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_PROTOCOL_VIOLATION.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_LIMIT_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_STATE_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_QUIC_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_QUIC_client_thread_method.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_SELF_TEST_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_SELF_TEST_get_callback.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_SELF_TEST_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_SELF_TEST_onbegin.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_SELF_TEST_oncorrupt_byte.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_SELF_TEST_onend.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_SELF_TEST_set_callback.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STACK_OF_X509_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_CTX.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_STORE_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CERT.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME_description.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PKEY.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get0_data.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CERT.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME_description.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PKEY.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_get_type.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_new_CERT.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_new_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_new_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_new_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_new_PKEY.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_new_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_set0_NAME_description.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_INFO_type_string.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_STORE_LOADER.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_do_all_provided.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_fetch.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_description.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_engine.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_properties.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_provider.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_scheme.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_is_a.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_names_do_all.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_attach.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_close.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_eof.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_error.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_expect.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_find.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_load.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_LOADER_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_STORE_SEARCH.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_alias.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_issuer_serial.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_key_fingerprint.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_name.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_digest.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_serial.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_string.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_SEARCH_get_type.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_STORE_attach.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_attach_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_close.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_close_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_ctrl_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_delete.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_eof.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_eof_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_error.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_error_fn.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_STORE_expect.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_expect_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_find.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_find_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_load.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_load_fn.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_STORE_open.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_open_ex.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_open_ex_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_open_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_post_process_info_fn.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_register_loader.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_supports_search.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_STORE_unregister_loader.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGETS_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGETS_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGETS_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGET_CERT_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGET_CERT_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGET_CERT_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGET_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGET_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TARGET_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE1.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE2.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE3.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE4.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE5.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE6.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE7.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE8.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE9.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACEV.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE_BEGIN.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE_CANCEL.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE_ENABLED.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE_END.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_TRACE_STRING_MAX.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_free.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_it.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_new.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_default_cipher_list.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_default_ciphersuites.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_get_max_threads.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_get_thread_support_flags.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_parse_url.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_set_max_threads.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_sleep.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_begin.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_cb.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_trace_enabled.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_end.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_get_category_name.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_trace_get_category_num.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_set_callback.3ossl delete mode 100644 openssl-install/share/man/man3/OSSL_trace_set_channel.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_set_prefix.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_set_suffix.3ossl delete mode 120000 openssl-install/share/man/man3/OSSL_trace_string.3ossl delete mode 120000 openssl-install/share/man/man3/OTHERNAME_free.3ossl delete mode 120000 openssl-install/share/man/man3/OTHERNAME_new.3ossl delete mode 100644 openssl-install/share/man/man3/OpenSSL_add_all_algorithms.3ossl delete mode 120000 openssl-install/share/man/man3/OpenSSL_add_all_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/OpenSSL_add_all_digests.3ossl delete mode 120000 openssl-install/share/man/man3/OpenSSL_add_ssl_algorithms.3ossl delete mode 100644 openssl-install/share/man/man3/OpenSSL_version.3ossl delete mode 120000 openssl-install/share/man/man3/OpenSSL_version_num.3ossl delete mode 120000 openssl-install/share/man/man3/PBE2PARAM_free.3ossl delete mode 120000 openssl-install/share/man/man3/PBE2PARAM_new.3ossl delete mode 120000 openssl-install/share/man/man3/PBEPARAM_free.3ossl delete mode 120000 openssl-install/share/man/man3/PBEPARAM_new.3ossl delete mode 120000 openssl-install/share/man/man3/PBKDF2PARAM_free.3ossl delete mode 120000 openssl-install/share/man/man3/PBKDF2PARAM_new.3ossl delete mode 120000 openssl-install/share/man/man3/PBMAC1PARAM_free.3ossl delete mode 120000 openssl-install/share/man/man3/PBMAC1PARAM_it.3ossl delete mode 120000 openssl-install/share/man/man3/PBMAC1PARAM_new.3ossl delete mode 100644 openssl-install/share/man/man3/PBMAC1_get1_pbkdf2_param.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_FLAG_EAY_COMPATIBLE.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_FLAG_ONLY_B64.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_FLAG_SECURE.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_X509_INFO_read.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_X509_INFO_read_bio.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_X509_INFO_read_bio_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_X509_INFO_read_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_bytes_read_bio.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_bytes_read_bio_secmem.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_do_header.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_get_EVP_CIPHER_INFO.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_read.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_read_CMS.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_DHparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_DSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_DSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_DSAparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_ECPKParameters.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_ECPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_EC_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_NETSCAPE_CERT_SEQUENCE.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_PKCS7.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_PKCS8.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_PKCS8_PRIV_KEY_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_PUBKEY_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_PrivateKey_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_RSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_RSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_SSL_SESSION.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_X509.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_X509_ACERT.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_X509_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_X509_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_X509_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_X509_REQ.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_CMS.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_DHparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_DSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_DSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_DSAparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_ECPKParameters.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_EC_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_NETSCAPE_CERT_SEQUENCE.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_PKCS7.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_PKCS8.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_PKCS8_PRIV_KEY_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_PUBKEY_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_Parameters.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_Parameters_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_read_bio_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_PrivateKey_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_RSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_RSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_SSL_SESSION.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_X509.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_X509_ACERT.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_X509_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_X509_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_X509_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_read_bio_X509_REQ.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_read_bio_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_CMS.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_DHparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_DHxparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_DSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_DSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_DSAparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_ECPKParameters.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_ECPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_EC_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_NETSCAPE_CERT_SEQUENCE.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PKCS7.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PKCS8.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey_nid.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PKCS8_PRIV_KEY_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PUBKEY_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_PrivateKey_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_RSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_RSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_SSL_SESSION.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_X509.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_X509_ACERT.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_X509_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_X509_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_X509_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_X509_REQ.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_X509_REQ_NEW.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_CMS.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_write_bio_CMS_stream.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_DHparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_DHxparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_DSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_DSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_DSAparams.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_ECPKParameters.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_ECPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_EC_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_NETSCAPE_CERT_SEQUENCE.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PKCS7.3ossl delete mode 100644 openssl-install/share/man/man3/PEM_write_bio_PKCS7_stream.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PKCS8.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey_nid.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PKCS8_PRIV_KEY_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PUBKEY_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_Parameters.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PrivateKey_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_PrivateKey_traditional.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_RSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_RSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_SSL_SESSION.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_X509.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_X509_ACERT.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_X509_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_X509_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_X509_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_X509_REQ.3ossl delete mode 120000 openssl-install/share/man/man3/PEM_write_bio_X509_REQ_NEW.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_BAGS_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_BAGS_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_MAC_DATA_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_MAC_DATA_new.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_PBE_keyivgen.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_PBE_keyivgen_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_p8inf.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_pkcs8.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_SAFEBAG_create_cert.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_create_crl.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_create_secret.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attr.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attrs.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_obj.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_type.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_p8inf.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_pkcs8.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_safes.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_type.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get_bag_nid.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_get_nid.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_SAFEBAG_new.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_SAFEBAG_set0_attrs.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add1_attr_by_txt.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_add_CSPName_asc.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_add_cert.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_add_friendlyname_asc.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_friendlyname_uni.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_friendlyname_utf8.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_key.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_key_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_add_localkeyid.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_add_safe.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_safe_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_safes.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_safes_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_add_secret.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_create.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_create_cb.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_create_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_create_ex2.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_decrypt_skey.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_decrypt_skey_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_free.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_gen_mac.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_get0_mac.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_get_attr_gen.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_get_friendlyname.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_init.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_init_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_item_decrypt_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_item_decrypt_d2i_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_item_i2d_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_item_i2d_encrypt_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_key_gen_asc.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_key_gen_asc_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_key_gen_uni.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_key_gen_uni_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_key_gen_utf8.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_key_gen_utf8_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_new.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_newpass.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_pack_p7encdata.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_pack_p7encdata_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS12_parse.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_pbe_crypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_pbe_crypt_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_set_mac.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_set_pbmac1_pbkdf2.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_setup_mac.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS12_verify_mac.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS5_PBE_keyivgen.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_PBE_keyivgen_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC_SHA1.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe2_set.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe2_set_iv.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe2_set_iv_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe2_set_scrypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe_set.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe_set0_algor.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe_set0_algor_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbe_set_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbkdf2_set.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_pbkdf2_set_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_DIGEST_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_DIGEST_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ENCRYPT_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ENCRYPT_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ENC_CONTENT_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ENC_CONTENT_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ENVELOPE_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ENVELOPE_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_digest.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_RECIP_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_RECIP_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_SIGNED_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_SIGNED_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_SIGNER_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_SIGNER_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_add_certificate.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_add_crl.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS7_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_dup.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS7_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_encrypt_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_get0_signers.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS7_get_octet_string.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_print_ctx.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS7_sign.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS7_sign_add_signer.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS7_sign_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS7_type_is_other.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS7_verify.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_decrypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_decrypt_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS8_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_encrypt_ex.3ossl delete mode 100644 openssl-install/share/man/man3/PKCS8_pkey_add1_attr.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_pkey_get0_attrs.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_set0_pbe.3ossl delete mode 120000 openssl-install/share/man/man3/PKCS8_set0_pbe_ex.3ossl delete mode 120000 openssl-install/share/man/man3/PKEY_USAGE_PERIOD_free.3ossl delete mode 120000 openssl-install/share/man/man3/PKEY_USAGE_PERIOD_new.3ossl delete mode 120000 openssl-install/share/man/man3/POLICYINFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/POLICYINFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/POLICYQUALINFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/POLICYQUALINFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/POLICY_CONSTRAINTS_free.3ossl delete mode 120000 openssl-install/share/man/man3/POLICY_CONSTRAINTS_new.3ossl delete mode 120000 openssl-install/share/man/man3/POLICY_MAPPING_free.3ossl delete mode 120000 openssl-install/share/man/man3/POLICY_MAPPING_new.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFOS.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFOS_free.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFOS_new.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_get0_addProfessionInfo.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_get0_namingAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_get0_professionItems.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_get0_professionOIDs.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_get0_registrationNumber.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_set0_addProfessionInfo.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_set0_namingAuthority.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_set0_professionItems.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_set0_professionOIDs.3ossl delete mode 120000 openssl-install/share/man/man3/PROFESSION_INFO_set0_registrationNumber.3ossl delete mode 120000 openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_free.3ossl delete mode 120000 openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_new.3ossl delete mode 120000 openssl-install/share/man/man3/PROXY_POLICY_free.3ossl delete mode 120000 openssl-install/share/man/man3/PROXY_POLICY_new.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_OpenSSL.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_add.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_bytes_ex.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_cleanup.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_egd.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_egd_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_event.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_file_name.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_get0_primary.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_get0_private.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_get0_public.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_get_rand_method.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_keep_random_devices_open.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_load_file.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_poll.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_priv_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_priv_bytes_ex.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_pseudo_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_query_egd_bytes.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_screen.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_seed.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_set0_private.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_set0_public.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_set_DRBG_type.3ossl delete mode 100644 openssl-install/share/man/man3/RAND_set_rand_method.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_set_seed_source_type.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_status.3ossl delete mode 120000 openssl-install/share/man/man3/RAND_write_file.3ossl delete mode 120000 openssl-install/share/man/man3/RC4.3ossl delete mode 100644 openssl-install/share/man/man3/RC4_set_key.3ossl delete mode 120000 openssl-install/share/man/man3/RIPEMD160.3ossl delete mode 120000 openssl-install/share/man/man3/RIPEMD160_Final.3ossl delete mode 100644 openssl-install/share/man/man3/RIPEMD160_Init.3ossl delete mode 120000 openssl-install/share/man/man3/RIPEMD160_Update.3ossl delete mode 120000 openssl-install/share/man/man3/RSAPrivateKey_dup.3ossl delete mode 120000 openssl-install/share/man/man3/RSAPublicKey_dup.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_OAEP_PARAMS_free.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_OAEP_PARAMS_new.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_PKCS1_OpenSSL.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_PSS_PARAMS_dup.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_PSS_PARAMS_free.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_PSS_PARAMS_new.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_bits.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_blinding_off.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_blinding_on.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_check_key.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_check_key_ex.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_flags.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_free.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_generate_key.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_generate_key_ex.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_generate_multi_prime_key.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_crt_params.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_d.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_dmp1.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_dmq1.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_e.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_engine.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_factors.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_iqmp.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_get0_key.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_multi_prime_crt_params.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_multi_prime_factors.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_n.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_p.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_pss_params.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get0_q.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get_method.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get_multi_prime_extra_count.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_get_version.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_dup.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get0_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_bn_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_finish.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_init.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_multi_prime_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_priv_dec.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_priv_enc.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_pub_dec.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_pub_enc.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_sign.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_get_verify.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set0_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set1_name.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_bn_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_finish.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_init.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_mod_exp.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_multi_prime_keygen.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_priv_dec.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_priv_enc.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_pub_dec.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_pub_enc.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_sign.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_meth_set_verify.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_new.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_new_method.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP_mgf1.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_1.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_2.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_add_none.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP_mgf1.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_1.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_2.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_padding_check_none.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_print.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_print_fp.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_private_decrypt.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_private_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_public_decrypt.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_public_encrypt.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_security_bits.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set0_crt_params.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set0_factors.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set0_key.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set0_multi_prime_params.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_set_flags.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_set_method.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_sign.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_sign_ASN1_OCTET_STRING.3ossl delete mode 100644 openssl-install/share/man/man3/RSA_size.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_test_flags.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_verify.3ossl delete mode 120000 openssl-install/share/man/man3/RSA_verify_ASN1_OCTET_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/SCRYPT_PARAMS_free.3ossl delete mode 120000 openssl-install/share/man/man3/SCRYPT_PARAMS_new.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_LIST_free.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_LIST_print.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_LIST_validate.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_free.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get0_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get0_log_id.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get_log_entry_type.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get_signature_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get_source.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get_timestamp.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get_validation_status.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_get_version.3ossl delete mode 100644 openssl-install/share/man/man3/SCT_new.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_new_from_base64.3ossl delete mode 100644 openssl-install/share/man/man3/SCT_print.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set0_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set0_log_id.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set1_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set1_log_id.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set1_signature.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set_log_entry_type.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set_signature_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set_source.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set_timestamp.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_set_version.3ossl delete mode 100644 openssl-install/share/man/man3/SCT_validate.3ossl delete mode 120000 openssl-install/share/man/man3/SCT_validation_status_string.3ossl delete mode 120000 openssl-install/share/man/man3/SHA1.3ossl delete mode 120000 openssl-install/share/man/man3/SHA1_Final.3ossl delete mode 120000 openssl-install/share/man/man3/SHA1_Init.3ossl delete mode 120000 openssl-install/share/man/man3/SHA1_Update.3ossl delete mode 120000 openssl-install/share/man/man3/SHA224.3ossl delete mode 120000 openssl-install/share/man/man3/SHA224_Final.3ossl delete mode 120000 openssl-install/share/man/man3/SHA224_Init.3ossl delete mode 120000 openssl-install/share/man/man3/SHA224_Update.3ossl delete mode 120000 openssl-install/share/man/man3/SHA256.3ossl delete mode 120000 openssl-install/share/man/man3/SHA256_Final.3ossl delete mode 100644 openssl-install/share/man/man3/SHA256_Init.3ossl delete mode 120000 openssl-install/share/man/man3/SHA256_Update.3ossl delete mode 120000 openssl-install/share/man/man3/SHA384.3ossl delete mode 120000 openssl-install/share/man/man3/SHA384_Final.3ossl delete mode 120000 openssl-install/share/man/man3/SHA384_Init.3ossl delete mode 120000 openssl-install/share/man/man3/SHA384_Update.3ossl delete mode 120000 openssl-install/share/man/man3/SHA512.3ossl delete mode 120000 openssl-install/share/man/man3/SHA512_Final.3ossl delete mode 120000 openssl-install/share/man/man3/SHA512_Init.3ossl delete mode 120000 openssl-install/share/man/man3/SHA512_Update.3ossl delete mode 100644 openssl-install/share/man/man3/SMIME_read_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SMIME_read_ASN1_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SMIME_read_CMS.3ossl delete mode 120000 openssl-install/share/man/man3/SMIME_read_CMS_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SMIME_read_PKCS7.3ossl delete mode 120000 openssl-install/share/man/man3/SMIME_read_PKCS7_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SMIME_write_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SMIME_write_ASN1_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SMIME_write_CMS.3ossl delete mode 100644 openssl-install/share/man/man3/SMIME_write_PKCS7.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_A.3ossl delete mode 100644 openssl-install/share/man/man3/SRP_Calc_B.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_B_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_client_key.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_client_key_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_server_key.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_u.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_u_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_x.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_Calc_x_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_VBASE_add0_user.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_VBASE_free.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_VBASE_get1_by_user.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_VBASE_get_by_user.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_VBASE_init.3ossl delete mode 100644 openssl-install/share/man/man3/SRP_VBASE_new.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_check_known_gN_param.3ossl delete mode 100644 openssl-install/share/man/man3/SRP_create_verifier.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_create_verifier_BN.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_create_verifier_BN_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_create_verifier_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_get_default_gN.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_user_pwd_free.3ossl delete mode 100644 openssl-install/share/man/man3/SRP_user_pwd_new.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_user_pwd_set0_sv.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_user_pwd_set1_ids.3ossl delete mode 120000 openssl-install/share/man/man3/SRP_user_pwd_set_gN.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_ACCEPT_STREAM_NO_BLOCK.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_description.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_find.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_auth_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_bits.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_cipher_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_digest_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_handshake_digest.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_kx_nid.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CIPHER_get_name.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_protocol_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_get_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_is_aead.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CIPHER_standard_name.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_COMP_add_compression_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_COMP_free_compression_methods.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_COMP_get0_name.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_COMP_get_compression_methods.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_COMP_get_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CONF_CTX_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CONF_CTX_finish.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CONF_CTX_free.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CONF_CTX_new.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CONF_CTX_set1_prefix.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CONF_CTX_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl_ctx.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CONF_cmd.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CONF_cmd_argv.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CONF_cmd_value_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_LOCAL.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_TRANSPORT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_add0_chain_cert.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_add1_chain_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_add1_to_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_add_client_CA.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_add_client_custom_ext.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_add_custom_ext.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_add_extra_chain_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_add_server_custom_ext.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_add_session.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_build_cert_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_callback_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_check_private_key.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_clear_chain_certs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_clear_extra_chain_certs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_clear_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_clear_options.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_compress_certs.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_config.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_ct_is_enabled.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_dane_clear_flags.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_dane_enable.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_dane_mtype_set.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_dane_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_decrypt_session_ticket_fn.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_disable_ct.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_enable_ct.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_flush_sessions.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_flush_sessions_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_generate_session_ticket_fn.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get0_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get0_chain_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get0_chain_certs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get0_client_cert_type.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_get0_param.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get0_security_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get0_server_cert_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get0_verify_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get1_compressed_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_client_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_client_cert_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb_userdata.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_default_read_ahead.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs_only.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_info_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_keylog_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_max_cert_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_max_proto_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_min_proto_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_num_tickets.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_options.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_quiet_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_read_ahead.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_record_padding_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_recv_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_security_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_security_level.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_session_cache_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_ssl_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_verify_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_get_verify_depth.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_get_verify_mode.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_has_client_custom_ext.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_keylog_cb_func.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_load_verify_dir.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_load_verify_file.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_load_verify_locations.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_load_verify_store.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_remove_session.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_select_current_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_accept.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_accept_good.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_accept_renegotiate.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_cache_full.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_cb_hits.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_connect.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_connect_good.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_connect_renegotiate.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_get_cache_size.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_get_get_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_get_new_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_get_remove_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_hits.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_misses.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_sess_number.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_sess_set_cache_size.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_sess_set_get_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_set_new_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_set_remove_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_sess_timeouts.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_sessions.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set0_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set0_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set0_chain_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set0_security_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set0_tmp_dh_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set0_verify_cert_store.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set1_cert_comp_preference.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_chain_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_client_cert_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_compressed_cert.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set1_curves.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_curves_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_groups.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_groups_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_param.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_server_cert_type.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set1_sigalgs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set1_sigalgs_list.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set1_verify_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_allow_early_data_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_alpn_protos.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_alpn_select_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_async_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_async_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_block_padding.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_block_padding_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_cert_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_cert_store.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_cert_verify_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_cipher_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_ciphersuites.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_client_CA_list.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_client_cert_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_client_hello_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_cookie_generate_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_cookie_verify_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_ct_validation_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_ctlog_list_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_current_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_default_ctlog_list_file.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb_userdata.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_default_read_buffer_len.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_default_verify_dir.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_default_verify_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_default_verify_paths.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_default_verify_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_dh_auto.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_ecdh_auto.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_ex_data.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_generate_session_id.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_info_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_keylog_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_max_cert_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_max_pipelines.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_max_proto_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_max_send_fragment.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_min_proto_version.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_mode.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_msg_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_msg_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_next_proto_select_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_next_protos_advertised_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_num_tickets.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_options.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_post_handshake_auth.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_psk_client_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_psk_find_session_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_psk_server_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_psk_use_session_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_purpose.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_quiet_shutdown.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_read_ahead.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_recv_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_security_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_security_level.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_session_cache_mode.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_session_id_context.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_session_ticket_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_split_send_fragment.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_srp_cb_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_srp_client_pwd_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_srp_password.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_srp_strength.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_srp_username.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_srp_username_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_srp_verify_param_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_ssl_version.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_generate_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_verify_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_tlsext_max_fragment_length.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_arg.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_arg.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_type.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_evp_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_tlsext_use_srtp.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_tmp_dh.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_tmp_dh_callback.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_tmp_ecdh.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_trust.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_set_verify.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_set_verify_depth.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_cert_and_key.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_use_certificate.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_certificate_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_certificate_chain_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_certificate_file.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_use_psk_identity_hint.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_CTX_use_serverinfo.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_serverinfo_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_CTX_use_serverinfo_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_BIDI.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_UNI.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_NONE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_ACCEPT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_AUTO.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_REJECT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_OP_BIT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_E.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_EC.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_ECD.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_ER.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_EW.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_F.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_I.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_IS.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_ISB.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_ISE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_ISU.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_NONE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_OS.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_OSB.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_OSE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_OSU.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_R.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_RE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_RW.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_RWE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_W.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_EVENT_WE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_POLL_FLAG_NO_HANDLE_EVENTS.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_dup.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_free.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get0_alpn_selected.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_get0_cipher.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_get0_hostname.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_get0_id_context.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_get0_peer.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get0_peer_rpk.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get0_ticket.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get0_ticket_appdata.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_app_data.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_get_compress_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_master_key.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_max_fragment_length.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_get_protocol_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_ticket_lifetime_hint.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_get_time.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_time_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_get_timeout.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_has_ticket.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_is_resumable.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_new.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_print.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_print_fp.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_print_keylog.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set1_alpn_selected.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set1_hostname.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_SESSION_set1_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set1_id_context.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set1_master_key.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set1_ticket_appdata.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_protocol_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_time.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_time_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_set_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_SESSION_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_FLAG_ADVANCE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_FLAG_NO_BLOCK.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_FLAG_UNI.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_STATE_CONN_CLOSED.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_STATE_FINISHED.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_STATE_NONE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_STATE_OK.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_LOCAL.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_REMOTE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_STATE_WRONG_DIR.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_TYPE_BIDI.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_TYPE_NONE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_TYPE_READ.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_STREAM_TYPE_WRITE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_NEGOTIATED.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_PEER_REQUEST.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_REQUEST.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_CLASS_GENERIC.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_INHERIT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_QUIC_IDLE_TIMEOUT.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_AVAIL.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_SIZE.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_USED.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_WRITE_FLAG_CONCLUDE.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_accept.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_accept_stream.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add0_chain_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add1_chain_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add1_host.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add1_to_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add_client_CA.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add_dir_cert_subjects_to_stack.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add_expected_rpk.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add_file_cert_subjects_to_stack.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_add_store_cert_subjects_to_stack.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_alert_desc_string.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_alert_desc_string_long.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_alert_type_string.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_alert_type_string_long.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_alloc_buffers.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_allow_early_data_cb_fn.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_async_callback_fn.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_build_cert_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_bytes_to_cipher_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_callback_ctrl.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_check_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_check_private_key.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_clear.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_clear_chain_certs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_clear_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_clear_options.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_cb_fn.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get0_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get0_compression_methods.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get0_ext.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get0_legacy_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get0_random.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get0_session_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get1_extensions_present.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_get_extension_order.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_hello_isv2.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_client_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_compress_certs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_config.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_connect.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_ct_is_enabled.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_custom_ext_add_cb_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_custom_ext_free_cb_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_custom_ext_parse_cb_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_dane_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_dane_enable.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_dane_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_dane_tlsa_add.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_disable_ct.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_do_handshake.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_dup.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_enable_ct.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_export_keying_material.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_export_keying_material_early.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_extension_supported.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_free.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_free_buffers.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_alpn_selected.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_chain_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_chain_certs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_client_cert_type.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get0_connection.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_dane_authority.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_dane_tlsa.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get0_group_name.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_iana_groups.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_next_proto_negotiated.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_param.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_peer_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_peer_certificate.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get0_peer_rpk.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get0_peer_scts.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_peername.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_security_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_server_cert_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_session.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_verified_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get0_verify_cert_store.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get1_builtin_sigalgs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get1_compressed_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get1_curves.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get1_groups.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get1_peer_certificate.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get1_session.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get1_supported_ciphers.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_SSL_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_accept_stream_queue_len.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_all_async_fds.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_async_status.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_blocking_mode.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_certificate.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_changed_async_fds.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_cipher_bits.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_cipher_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_cipher_name.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_cipher_version.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_client_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_client_ciphers.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_client_random.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_conn_close_info.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_current_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_default_passwd_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_default_passwd_cb_userdata.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_default_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_early_data_status.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_error.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_event_handling_mode.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_event_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_ex_data_X509_STORE_CTX_idx.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_ex_new_index.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_extms_support.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_fd.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_feature_negotiated_uint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_feature_peer_request_uint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_feature_request_uint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_generic_value_uint.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_handshake_rtt.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_info_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_key_update_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_max_cert_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_max_proto_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_min_proto_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_negotiated_client_cert_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_negotiated_group.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_negotiated_server_cert_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_num_tickets.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_options.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_peer_cert_chain.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_peer_certificate.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_peer_signature_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_peer_signature_type_nid.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_peer_tmp_key.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_pending_cipher.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_privatekey.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_psk_identity.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_psk_identity_hint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_quic_stream_bidi_local_avail.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_quic_stream_bidi_remote_avail.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_quic_stream_uni_local_avail.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_quic_stream_uni_remote_avail.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_quiet_shutdown.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_rbio.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_read_ahead.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_record_padding_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_recv_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_rfd.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_rpoll_descriptor.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_secure_renegotiation_support.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_security_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_security_level.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_selected_srtp_profile.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_server_random.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_server_tmp_key.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_servername.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_servername_type.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_session.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_shared_ciphers.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_shared_curve.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_shared_group.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_shared_sigalgs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_sigalgs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_signature_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_signature_type_nid.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_srp_N.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_srp_g.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_srp_userinfo.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_srp_username.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_srtp_profiles.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_ssl_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_state.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_stream_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_stream_read_error_code.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_stream_read_state.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_stream_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_stream_write_buf_avail.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_stream_write_buf_size.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_stream_write_buf_used.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_stream_write_error_code.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_stream_write_state.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_time.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_tlsext_status_ocsp_resp.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_tlsext_status_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_tmp_key.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_value_uint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_verify_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_verify_depth.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_verify_mode.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_verify_result.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_get_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_wbio.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_wfd.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_get_wpoll_descriptor.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_group_to_name.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_handle_events.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_has_matching_session_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_has_pending.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_in_accept_init.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_in_before.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_in_connect_init.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_in_init.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_inject_net_dgram.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_is_connection.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_is_dtls.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_is_init_finished.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_is_quic.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_is_server.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_is_stream_local.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_is_tls.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_key_update.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_library_init.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_load_client_CA_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_load_client_CA_file_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_load_error_strings.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_net_read_desired.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_net_write_desired.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_new.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_new_session_ticket.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_new_stream.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_peek.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_peek_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_pending.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_poll.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_psk_client_cb_func.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_psk_find_session_cb_func.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_psk_server_cb_func.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_psk_use_session_cb_func.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_read.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_read_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_read_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_renegotiate.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_renegotiate_abbreviated.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_renegotiate_pending.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_rstate_string.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_rstate_string_long.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_select_current_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_select_next_proto.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_sendfile.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_session_reused.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_CA_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_chain_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_rbio.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_security_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_tmp_dh_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_verify_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set0_wbio.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_cert_comp_preference.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_chain.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_chain_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_client_cert_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_client_sigalgs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_client_sigalgs_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_compressed_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_curves.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_curves_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_groups.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_groups_list.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set1_host.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set1_initial_peer_addr.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_param.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set1_server_cert_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_sigalgs.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_sigalgs_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set1_verify_cert_store.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_accept_state.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_allow_early_data_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_alpn_protos.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_app_data.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_async_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_async_callback_arg.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_bio.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_block_padding.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_block_padding_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_blocking_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_cert_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_cipher_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_ciphersuites.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_client_CA_list.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_connect_state.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_ct_validation_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_current_cert.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_default_passwd_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_default_passwd_cb_userdata.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_default_read_buffer_len.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_default_stream_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_dh_auto.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_ecdh_auto.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_event_handling_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_ex_data.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_fd.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_feature_request_uint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_generate_session_id.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_generic_value_uint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_hostflags.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_incoming_stream_policy.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_info_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_max_cert_list.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_max_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_max_pipelines.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_max_proto_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_max_send_fragment.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_min_proto_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_mode.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_msg_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_msg_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_num_tickets.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_options.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_post_handshake_auth.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_psk_client_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_psk_find_session_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_psk_server_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_psk_use_session_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_purpose.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_quiet_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_read_ahead.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_record_padding_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_record_padding_callback_arg.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_recv_max_early_data.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_retry_verify.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_rfd.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_security_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_security_level.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_session.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_session_id_context.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_session_secret_cb.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_split_send_fragment.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_srp_server_param.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_srp_server_param_pw.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_ssl_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_time.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_timeout.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tlsext_host_name.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tlsext_max_fragment_length.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tlsext_status_ocsp_resp.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tlsext_status_type.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tlsext_use_srtp.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tmp_dh.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tmp_dh_callback.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_tmp_ecdh.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_trust.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_value_uint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_verify.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_verify_depth.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_set_verify_result.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_set_wfd.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_shutdown_ex.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_state_string.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_state_string_long.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_stateless.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_stream_conclude.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_stream_reset.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_trace.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_PrivateKey_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_PrivateKey_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_RSAPrivateKey_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_RSAPrivateKey_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_cert_and_key.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_certificate.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_certificate_ASN1.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_certificate_chain_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_certificate_file.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_use_psk_identity_hint.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_verify_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_verify_client_post_handshake.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_version.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_waiting_for_async.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_want.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_async.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_async_job.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_client_hello_cb.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_nothing.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_read.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_retry_verify.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_write.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_want_x509_lookup.3ossl delete mode 100644 openssl-install/share/man/man3/SSL_write.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_write_early_data.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_write_ex.3ossl delete mode 120000 openssl-install/share/man/man3/SSL_write_ex2.3ossl delete mode 120000 openssl-install/share/man/man3/SSLv23_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSLv23_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSLv23_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSLv3_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSLv3_method.3ossl delete mode 120000 openssl-install/share/man/man3/SSLv3_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/SXNETID_free.3ossl delete mode 120000 openssl-install/share/man/man3/SXNETID_new.3ossl delete mode 120000 openssl-install/share/man/man3/SXNET_free.3ossl delete mode 120000 openssl-install/share/man/man3/SXNET_new.3ossl delete mode 120000 openssl-install/share/man/man3/TLS_FEATURE_free.3ossl delete mode 120000 openssl-install/share/man/man3/TLS_FEATURE_new.3ossl delete mode 120000 openssl-install/share/man/man3/TLS_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLS_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLS_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_1_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_1_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_1_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_2_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_2_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_2_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_client_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_method.3ossl delete mode 120000 openssl-install/share/man/man3/TLSv1_server_method.3ossl delete mode 120000 openssl-install/share/man/man3/TS_ACCURACY_dup.3ossl delete mode 120000 openssl-install/share/man/man3/TS_ACCURACY_free.3ossl delete mode 120000 openssl-install/share/man/man3/TS_ACCURACY_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_MSG_IMPRINT_dup.3ossl delete mode 120000 openssl-install/share/man/man3/TS_MSG_IMPRINT_free.3ossl delete mode 120000 openssl-install/share/man/man3/TS_MSG_IMPRINT_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_REQ_dup.3ossl delete mode 120000 openssl-install/share/man/man3/TS_REQ_free.3ossl delete mode 120000 openssl-install/share/man/man3/TS_REQ_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_RESP_CTX_free.3ossl delete mode 100644 openssl-install/share/man/man3/TS_RESP_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_RESP_CTX_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/TS_RESP_dup.3ossl delete mode 120000 openssl-install/share/man/man3/TS_RESP_free.3ossl delete mode 120000 openssl-install/share/man/man3/TS_RESP_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_STATUS_INFO_dup.3ossl delete mode 120000 openssl-install/share/man/man3/TS_STATUS_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/TS_STATUS_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_TST_INFO_dup.3ossl delete mode 120000 openssl-install/share/man/man3/TS_TST_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/TS_TST_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTS_set_certs.3ossl delete mode 100644 openssl-install/share/man/man3/TS_VERIFY_CTX.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_add_flags.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_init.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set0_certs.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set0_data.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set0_imprint.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set0_store.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set_certs.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set_data.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set_imprint.3ossl delete mode 120000 openssl-install/share/man/man3/TS_VERIFY_CTX_set_store.3ossl delete mode 120000 openssl-install/share/man/man3/UI.3ossl delete mode 120000 openssl-install/share/man/man3/UI_METHOD.3ossl delete mode 120000 openssl-install/share/man/man3/UI_OpenSSL.3ossl delete mode 100644 openssl-install/share/man/man3/UI_STRING.3ossl delete mode 100644 openssl-install/share/man/man3/UI_UTIL_read_pw.3ossl delete mode 120000 openssl-install/share/man/man3/UI_UTIL_read_pw_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_UTIL_wrap_read_pem_callback.3ossl delete mode 120000 openssl-install/share/man/man3/UI_add_error_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_add_info_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_add_input_boolean.3ossl delete mode 120000 openssl-install/share/man/man3/UI_add_input_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_add_user_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_add_verify_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_construct_prompt.3ossl delete mode 100644 openssl-install/share/man/man3/UI_create_method.3ossl delete mode 120000 openssl-install/share/man/man3/UI_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/UI_destroy_method.3ossl delete mode 120000 openssl-install/share/man/man3/UI_dup_error_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_dup_info_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_dup_input_boolean.3ossl delete mode 120000 openssl-install/share/man/man3/UI_dup_input_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_dup_user_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_dup_verify_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_free.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get0_action_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get0_output_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get0_result.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get0_result_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get0_test_string.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get0_user_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_input_flags.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_method.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_result_length.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_result_maxsize.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_result_minsize.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_result_string_length.3ossl delete mode 120000 openssl-install/share/man/man3/UI_get_string_type.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_closer.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_data_destructor.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_data_duplicator.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_flusher.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_opener.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_prompt_constructor.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_reader.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_get_writer.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_closer.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_data_duplicator.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_flusher.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_opener.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_prompt_constructor.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_reader.3ossl delete mode 120000 openssl-install/share/man/man3/UI_method_set_writer.3ossl delete mode 100644 openssl-install/share/man/man3/UI_new.3ossl delete mode 120000 openssl-install/share/man/man3/UI_new_method.3ossl delete mode 120000 openssl-install/share/man/man3/UI_null.3ossl delete mode 120000 openssl-install/share/man/man3/UI_process.3ossl delete mode 120000 openssl-install/share/man/man3/UI_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_set_default_method.3ossl delete mode 120000 openssl-install/share/man/man3/UI_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/UI_set_method.3ossl delete mode 120000 openssl-install/share/man/man3/UI_set_result.3ossl delete mode 120000 openssl-install/share/man/man3/UI_set_result_ex.3ossl delete mode 120000 openssl-install/share/man/man3/UI_string_types.3ossl delete mode 120000 openssl-install/share/man/man3/USERNOTICE_free.3ossl delete mode 120000 openssl-install/share/man/man3/USERNOTICE_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509V3_EXT_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/X509V3_EXT_i2d.3ossl delete mode 120000 openssl-install/share/man/man3/X509V3_add1_i2d.3ossl delete mode 100644 openssl-install/share/man/man3/X509V3_get_d2i.3ossl delete mode 100644 openssl-install/share/man/man3/X509V3_set_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/X509V3_set_issuer_pkey.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_INFO_it.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_new.3ossl delete mode 100644 openssl-install/share/man/man3/X509_ACERT_add1_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_add1_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_add1_attr_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_add1_ext_i2d.3ossl delete mode 100644 openssl-install/share/man/man3/X509_ACERT_add_attr_nconf.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_delete_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_extensions.3ossl delete mode 100644 openssl-install/share/man/man3/X509_ACERT_get0_holder_baseCertId.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_holder_digest.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_holder_entityName.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_info_sigalg.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_issuerName.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_issuerUID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_notAfter.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_notBefore.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get0_signature.3ossl delete mode 100644 openssl-install/share/man/man3/X509_ACERT_get_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get_attr_count.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get_ext_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get_signature_nid.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_get_version.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_it.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_print.3ossl delete mode 100644 openssl-install/share/man/man3/X509_ACERT_print_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set0_holder_baseCertId.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set0_holder_digest.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set0_holder_entityName.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set1_issuerName.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set1_notAfter.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set1_notBefore.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set1_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_set_version.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_sign.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_sign_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ACERT_verify.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_copy.3ossl delete mode 100644 openssl-install/share/man/man3/X509_ALGOR_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_get0.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_it.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_set0.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ALGOR_set_md.3ossl delete mode 100644 openssl-install/share/man/man3/X509_ATTRIBUTE.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_count.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_create.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_get0_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_get0_object.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_get0_type.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_set1_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_ATTRIBUTE_set1_object.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CERT_AUX_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CERT_AUX_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CINF_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CINF_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_add0_revoked.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_add1_ext_i2d.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_add_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_delete_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_digest.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get0_by_cert.3ossl delete mode 100644 openssl-install/share/man/man3/X509_CRL_get0_by_serial.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get0_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get0_lastUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get0_nextUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_REVOKED.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_ext_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_ext_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_ext_by_critical.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_ext_count.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_ext_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_signature_nid.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_get_version.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_http_nbio.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_load_http.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_match.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_set1_lastUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_set1_nextUpdate.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_set_issuer_name.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_set_version.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_sign.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_sign_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_sort.3ossl delete mode 120000 openssl-install/share/man/man3/X509_CRL_verify.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_create_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_create_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_get_critical.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_get_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_get_object.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_set_critical.3ossl delete mode 120000 openssl-install/share/man/man3/X509_EXTENSION_set_data.3ossl delete mode 100644 openssl-install/share/man/man3/X509_EXTENSION_set_object.3ossl delete mode 100644 openssl-install/share/man/man3/X509_LOOKUP.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_METHOD.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_TYPE.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_add_dir.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_add_store.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_add_store_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_by_alias.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_by_fingerprint.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_by_issuer_serial.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_by_subject.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_by_subject_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_ctrl_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_ctrl_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_file.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_get_by_alias_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_get_by_fingerprint_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_get_by_issuer_serial_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_get_by_subject_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_get_method_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_get_store.3ossl delete mode 100644 openssl-install/share/man/man3/X509_LOOKUP_hash_dir.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_init.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_load_file.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_load_file_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_load_store.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_load_store_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_alias.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_fingerprint.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_issuer_serial.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_subject.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_init.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_new_item.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_get_shutdown.3ossl delete mode 100644 openssl-install/share/man/man3/X509_LOOKUP_meth_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_ctrl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_alias.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_fingerprint.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_issuer_serial.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_subject.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_init.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_new_item.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_meth_set_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_set_method_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_shutdown.3ossl delete mode 120000 openssl-install/share/man/man3/X509_LOOKUP_store.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_get_data.3ossl delete mode 100644 openssl-install/share/man/man3/X509_NAME_ENTRY_get_object.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_set_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_ENTRY_set_object.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_add_entry.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_add_entry_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_add_entry_by_OBJ.3ossl delete mode 100644 openssl-install/share/man/man3/X509_NAME_add_entry_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_delete_entry.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_digest.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_entry_count.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_free.3ossl delete mode 100644 openssl-install/share/man/man3/X509_NAME_get0_der.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_get_entry.3ossl delete mode 100644 openssl-install/share/man/man3/X509_NAME_get_index_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_get_index_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_get_text_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_get_text_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_hash.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_hash_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_oneline.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_print.3ossl delete mode 100644 openssl-install/share/man/man3/X509_NAME_print_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_NAME_print_ex_fp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_OBJECT_set1_X509.3ossl delete mode 120000 openssl-install/share/man/man3/X509_OBJECT_set1_X509_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_eq.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_get.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_get0.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_get0_param.3ossl delete mode 100644 openssl-install/share/man/man3/X509_PUBKEY_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_set.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_set0_param.3ossl delete mode 120000 openssl-install/share/man/man3/X509_PUBKEY_set0_public_key.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_INFO_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_INFO_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_add1_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_add1_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_add1_attr_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_add_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_add_extensions_nid.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_check_private_key.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_delete_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_digest.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get0_distinguishing_id.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get0_pubkey.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_X509_PUBKEY.3ossl delete mode 100644 openssl-install/share/man/man3/X509_REQ_get_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_attr_count.3ossl delete mode 100644 openssl-install/share/man/man3/X509_REQ_get_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_pubkey.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_signature_nid.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_subject_name.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_get_version.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_set0_distinguishing_id.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_set0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_set1_signature_algo.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_set_pubkey.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_set_subject_name.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_set_version.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_sign.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_sign_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_verify.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REQ_verify_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_add1_ext_i2d.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_add_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_delete_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get0_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get0_revocationDate.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get0_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get_ext_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get_ext_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get_ext_by_critical.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get_ext_count.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_get_ext_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_set_revocationDate.3ossl delete mode 120000 openssl-install/share/man/man3/X509_REVOKED_set_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/X509_SIG_INFO_get.3ossl delete mode 120000 openssl-install/share/man/man3/X509_SIG_INFO_set.3ossl delete mode 120000 openssl-install/share/man/man3/X509_SIG_free.3ossl delete mode 100644 openssl-install/share/man/man3/X509_SIG_get0.3ossl delete mode 120000 openssl-install/share/man/man3/X509_SIG_getm.3ossl delete mode 120000 openssl-install/share/man/man3/X509_SIG_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_cert_crl_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_check_crl_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_check_issued_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_check_policy_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_check_revocation_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_cleanup_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get0_cert.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get0_chain.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get0_param.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get0_rpk.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get0_untrusted.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get1_chain.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get1_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_app_data.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_CTX_get_by_subject.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_cert_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_check_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_check_issued.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_check_policy.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_check_revocation.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_crl_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_current_cert.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_CTX_get_error.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_error_depth.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_get_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_get_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_issuer_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_certs.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_crls.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_num_untrusted.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_obj_by_subject.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_verify.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_get_verify_cb.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_init.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_init_rpk.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_lookup_certs_fn.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_lookup_crls_fn.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_CTX_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_print_verify_cb.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_purpose_inherit.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set0_crls.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set0_param.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set0_rpk.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set0_trusted_stack.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set0_untrusted.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set0_verified_chain.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_app_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_cert.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_current_cert.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_current_reasons.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_default.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_error.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_error_depth.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_get_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_purpose.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_trust.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_set_verify.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_CTX_set_verify_cb.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_verify.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_verify_cb.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_CTX_verify_fn.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_add_cert.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_add_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_add_lookup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get0_objects.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_get0_param.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get1_all_certs.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get1_objects.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_cert_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_check_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_check_issued.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_check_policy.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_check_revocation.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_get_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_get_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_lookup_certs.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_lookup_crls.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_get_verify_cb.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_load_file.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_load_file_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_load_locations.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_load_locations_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_load_path.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_load_store.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_load_store_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_lock.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set1_param.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_cert_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_check_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_check_issued.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_check_policy.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_check_revocation.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_cleanup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_default_paths.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_default_paths_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_depth.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_get_crl.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_get_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_lookup_certs.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_lookup_crls.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_lookup_crls_cb.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_purpose.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_trust.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_verify.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_verify_cb.3ossl delete mode 100644 openssl-install/share/man/man3/X509_STORE_set_verify_cb_func.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_set_verify_func.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_unlock.3ossl delete mode 120000 openssl-install/share/man/man3/X509_STORE_up_ref.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VAL_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VAL_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_add0_policy.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_add1_host.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_clear_flags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_email.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_host.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_peername.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get1_ip_asc.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get_auth_level.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get_depth.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get_flags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get_hostflags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get_inh_flags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_get_time.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_email.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_host.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip_asc.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_policies.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_auth_level.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_depth.3ossl delete mode 100644 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_flags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_hostflags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_inh_flags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_purpose.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_time.3ossl delete mode 120000 openssl-install/share/man/man3/X509_VERIFY_PARAM_set_trust.3ossl delete mode 120000 openssl-install/share/man/man3/X509_add1_ext_i2d.3ossl delete mode 100644 openssl-install/share/man/man3/X509_add_cert.3ossl delete mode 120000 openssl-install/share/man/man3/X509_add_certs.3ossl delete mode 120000 openssl-install/share/man/man3/X509_add_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_build_chain.3ossl delete mode 120000 openssl-install/share/man/man3/X509_chain_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/X509_check_ca.3ossl delete mode 120000 openssl-install/share/man/man3/X509_check_email.3ossl delete mode 100644 openssl-install/share/man/man3/X509_check_host.3ossl delete mode 120000 openssl-install/share/man/man3/X509_check_ip.3ossl delete mode 120000 openssl-install/share/man/man3/X509_check_ip_asc.3ossl delete mode 100644 openssl-install/share/man/man3/X509_check_issued.3ossl delete mode 100644 openssl-install/share/man/man3/X509_check_private_key.3ossl delete mode 100644 openssl-install/share/man/man3/X509_check_purpose.3ossl delete mode 100644 openssl-install/share/man/man3/X509_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_cmp_current_time.3ossl delete mode 100644 openssl-install/share/man/man3/X509_cmp_time.3ossl delete mode 120000 openssl-install/share/man/man3/X509_cmp_timeframe.3ossl delete mode 120000 openssl-install/share/man/man3/X509_delete_ext.3ossl delete mode 100644 openssl-install/share/man/man3/X509_digest.3ossl delete mode 120000 openssl-install/share/man/man3/X509_digest_sig.3ossl delete mode 100644 openssl-install/share/man/man3/X509_dup.3ossl delete mode 120000 openssl-install/share/man/man3/X509_free.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_authority_issuer.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_authority_key_id.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_authority_serial.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get0_distinguishing_id.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_notAfter.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get0_notBefore.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_pubkey.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_serialNumber.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get0_signature.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_subject_key_id.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get0_tbs_sigalg.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get0_uids.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_X509_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_default_cert_dir.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_default_cert_dir_env.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get_default_cert_file.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_default_cert_file_env.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ex_new_index.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ext_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ext_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ext_by_critical.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ext_count.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_ext_d2i.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_extended_key_usage.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get_extension_flags.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_issuer_name.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_key_usage.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_pathlen.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_proxy_pathlen.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get_pubkey.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_signature_info.3ossl delete mode 120000 openssl-install/share/man/man3/X509_get_signature_nid.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get_subject_name.3ossl delete mode 100644 openssl-install/share/man/man3/X509_get_version.3ossl delete mode 120000 openssl-install/share/man/man3/X509_getm_notAfter.3ossl delete mode 120000 openssl-install/share/man/man3/X509_getm_notBefore.3ossl delete mode 120000 openssl-install/share/man/man3/X509_gmtime_adj.3ossl delete mode 120000 openssl-install/share/man/man3/X509_http_nbio.3ossl delete mode 120000 openssl-install/share/man/man3/X509_issuer_and_serial_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_issuer_name_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_issuer_name_hash.3ossl delete mode 120000 openssl-install/share/man/man3/X509_load_cert_crl_file.3ossl delete mode 120000 openssl-install/share/man/man3/X509_load_cert_crl_file_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_load_cert_file.3ossl delete mode 120000 openssl-install/share/man/man3/X509_load_cert_file_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_load_crl_file.3ossl delete mode 100644 openssl-install/share/man/man3/X509_load_http.3ossl delete mode 100644 openssl-install/share/man/man3/X509_new.3ossl delete mode 120000 openssl-install/share/man/man3/X509_new_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_pubkey_digest.3ossl delete mode 120000 openssl-install/share/man/man3/X509_self_signed.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set0_distinguishing_id.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set1_notAfter.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set1_notBefore.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_ex_data.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_issuer_name.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_proxy_flag.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_proxy_pathlen.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_pubkey.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_serialNumber.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_subject_name.3ossl delete mode 120000 openssl-install/share/man/man3/X509_set_version.3ossl delete mode 100644 openssl-install/share/man/man3/X509_sign.3ossl delete mode 120000 openssl-install/share/man/man3/X509_sign_ctx.3ossl delete mode 120000 openssl-install/share/man/man3/X509_subject_name_cmp.3ossl delete mode 120000 openssl-install/share/man/man3/X509_subject_name_hash.3ossl delete mode 120000 openssl-install/share/man/man3/X509_time_adj.3ossl delete mode 120000 openssl-install/share/man/man3/X509_time_adj_ex.3ossl delete mode 120000 openssl-install/share/man/man3/X509_up_ref.3ossl delete mode 100644 openssl-install/share/man/man3/X509_verify.3ossl delete mode 100644 openssl-install/share/man/man3/X509_verify_cert.3ossl delete mode 120000 openssl-install/share/man/man3/X509_verify_cert_error_string.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_add1_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_add1_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_add1_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_add1_attr_by_txt.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_delete_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_get0_data_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_get_attr.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_get_attr_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_get_attr_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509at_get_attr_count.3ossl delete mode 120000 openssl-install/share/man/man3/X509v3_add_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509v3_add_extensions.3ossl delete mode 120000 openssl-install/share/man/man3/X509v3_delete_ext.3ossl delete mode 120000 openssl-install/share/man/man3/X509v3_get_ext.3ossl delete mode 100644 openssl-install/share/man/man3/X509v3_get_ext_by_NID.3ossl delete mode 120000 openssl-install/share/man/man3/X509v3_get_ext_by_OBJ.3ossl delete mode 120000 openssl-install/share/man/man3/X509v3_get_ext_by_critical.3ossl delete mode 120000 openssl-install/share/man/man3/X509v3_get_ext_count.3ossl delete mode 120000 openssl-install/share/man/man3/b2i_PVK_bio.3ossl delete mode 100644 openssl-install/share/man/man3/b2i_PVK_bio_ex.3ossl delete mode 120000 openssl-install/share/man/man3/custom_ext_add_cb.3ossl delete mode 120000 openssl-install/share/man/man3/custom_ext_free_cb.3ossl delete mode 120000 openssl-install/share/man/man3/custom_ext_parse_cb.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ACCESS_DESCRIPTION.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ADMISSIONS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ADMISSION_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASIdOrRange.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASIdentifierChoice.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASIdentifiers.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_BIT_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_BMPSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_ENUMERATED.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_GENERALIZEDTIME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_GENERALSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_IA5STRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_INTEGER.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_NULL.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_OBJECT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_OCTET_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_PRINTABLE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_PRINTABLESTRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_SEQUENCE_ANY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_SET_ANY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_T61STRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_TIME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_TYPE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_UINTEGER.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_UNIVERSALSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_UTCTIME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_UTF8STRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASN1_VISIBLESTRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ASRange.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_AUTHORITY_INFO_ACCESS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_AUTHORITY_KEYID.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_AutoPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_AutoPrivateKey_ex.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_BASIC_CONSTRAINTS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_CERTIFICATEPOLICIES.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_CMS_ContentInfo.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_CMS_ReceiptRequest.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_CMS_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_CRL_DIST_POINTS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DHparams.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DHparams_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DHparams_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DHxparams.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DIRECTORYSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DISPLAYTEXT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DIST_POINT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DIST_POINT_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSAPrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSAPrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSA_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSA_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSA_SIG.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_DSAparams.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ECDSA_SIG.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ECPKParameters.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ECParameters.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ECPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ECPrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ECPrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_EC_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_EC_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_EC_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_EDIPARTYNAME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ESS_CERT_ID.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ESS_CERT_ID_V2.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ESS_ISSUER_SERIAL.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT_V2.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_EXTENDED_KEY_USAGE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_GENERAL_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_GENERAL_NAMES.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_IPAddressChoice.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_IPAddressFamily.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_IPAddressOrRange.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_IPAddressRange.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ISSUER_SIGN_TOOL.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_ISSUING_DIST_POINT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_KeyParams.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_KeyParams_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_NAMING_AUTHORITY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_NETSCAPE_CERT_SEQUENCE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_NETSCAPE_SPKAC.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_NETSCAPE_SPKI.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_NOTICEREF.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_BASICRESP.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_CERTID.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_CERTSTATUS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_CRLID.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_ONEREQ.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_REQINFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_REQUEST.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_RESPBYTES.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_RESPDATA.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_RESPID.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_RESPONSE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_REVOKEDINFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_SERVICELOC.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_SIGNATURE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OCSP_SINGLERESP.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_ATTRIBUTES_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CMP_ATAVS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CMP_MSG.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CMP_MSG_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CMP_PKIHEADER.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CMP_PKISI.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTID.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTTEMPLATE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_ENCRYPTEDVALUE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_MSG.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_MSGS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_PBMPARAMETER.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_CRMF_SINGLEPUBINFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_IETF_ATTR_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_ISSUER_SERIAL.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_OBJECT_DIGEST_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_TARGET.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_TARGETING_INFORMATION.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_TARGETS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_TARGET_CERT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OSSL_USER_NOTICE_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_OTHERNAME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PBE2PARAM.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PBEPARAM.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PBKDF2PARAM.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PBMAC1PARAM.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS12.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS12_BAGS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS12_MAC_DATA.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS12_SAFEBAG.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS12_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS12_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_DIGEST.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_ENCRYPT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_ENC_CONTENT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_ENVELOPE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_ISSUER_AND_SERIAL.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_RECIP_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_SIGNED.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_SIGNER_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_SIGN_ENVELOPE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS7_fp.3ossl delete mode 100644 openssl-install/share/man/man3/d2i_PKCS8PrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS8PrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS8_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKCS8_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PKEY_USAGE_PERIOD.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_POLICYINFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_POLICYQUALINFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PROFESSION_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PROXY_CERT_INFO_EXTENSION.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PROXY_POLICY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PUBKEY_ex.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PUBKEY_ex_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PUBKEY_ex_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PUBKEY_fp.3ossl delete mode 100644 openssl-install/share/man/man3/d2i_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PrivateKey_ex.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PrivateKey_ex_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PrivateKey_ex_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_PublicKey.3ossl delete mode 100644 openssl-install/share/man/man3/d2i_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSAPrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSAPrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSAPublicKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSAPublicKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSA_OAEP_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSA_PSS_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSA_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_RSA_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_SCRYPT_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_SCT_LIST.3ossl delete mode 100644 openssl-install/share/man/man3/d2i_SSL_SESSION.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_SSL_SESSION_ex.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_SXNET.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_SXNETID.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_ACCURACY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_REQ.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_REQ_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_REQ_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_RESP.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_RESP_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_RESP_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_STATUS_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_TST_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_TST_INFO_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_TS_TST_INFO_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_USERNOTICE.3ossl delete mode 100644 openssl-install/share/man/man3/d2i_X509.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_ACERT.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_ACERT_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_ACERT_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_ALGOR.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_ALGORS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_ATTRIBUTE.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_CERT_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_CINF.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_CRL_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_CRL_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_CRL_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_EXTENSION.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_EXTENSIONS.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_NAME_ENTRY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_REQ.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_REQ_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_REQ_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_REQ_fp.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_REVOKED.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_SIG.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_VAL.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_bio.3ossl delete mode 120000 openssl-install/share/man/man3/d2i_X509_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2b_PVK_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2b_PVK_bio_ex.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ACCESS_DESCRIPTION.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ADMISSIONS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ADMISSION_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASIdOrRange.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASIdentifierChoice.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASIdentifiers.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_BIT_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_BMPSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_ENUMERATED.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_GENERALIZEDTIME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_GENERALSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_IA5STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_INTEGER.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_NULL.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_OBJECT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_OCTET_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_PRINTABLE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_PRINTABLESTRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_SEQUENCE_ANY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_SET_ANY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_T61STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_TIME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_TYPE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_UNIVERSALSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_UTCTIME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_UTF8STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_VISIBLESTRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASN1_bio_stream.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ASRange.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_AUTHORITY_INFO_ACCESS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_AUTHORITY_KEYID.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_BASIC_CONSTRAINTS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_CERTIFICATEPOLICIES.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_CMS_ContentInfo.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_CMS_ReceiptRequest.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_CMS_bio.3ossl delete mode 100644 openssl-install/share/man/man3/i2d_CMS_bio_stream.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_CRL_DIST_POINTS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DHparams.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DHparams_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DHparams_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DHxparams.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DIRECTORYSTRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DISPLAYTEXT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DIST_POINT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DIST_POINT_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSAPrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSAPrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSA_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSA_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSA_SIG.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_DSAparams.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ECDSA_SIG.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ECPKParameters.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ECParameters.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ECPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ECPrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ECPrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_EC_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_EC_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_EC_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_EDIPARTYNAME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ESS_CERT_ID.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ESS_CERT_ID_V2.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ESS_ISSUER_SERIAL.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT_V2.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_EXTENDED_KEY_USAGE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_GENERAL_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_GENERAL_NAMES.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_IPAddressChoice.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_IPAddressFamily.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_IPAddressOrRange.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_IPAddressRange.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ISSUER_SIGN_TOOL.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_ISSUING_DIST_POINT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_KeyParams.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_KeyParams_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_NAMING_AUTHORITY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_NETSCAPE_CERT_SEQUENCE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_NETSCAPE_SPKAC.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_NETSCAPE_SPKI.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_NOTICEREF.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_BASICRESP.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_CERTID.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_CERTSTATUS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_CRLID.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_ONEREQ.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_REQINFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_REQUEST.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_RESPBYTES.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_RESPDATA.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_RESPID.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_RESPONSE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_REVOKEDINFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_SERVICELOC.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_SIGNATURE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OCSP_SINGLERESP.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_ATTRIBUTES_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CMP_ATAVS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CMP_MSG.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CMP_MSG_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CMP_PKIHEADER.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CMP_PKISI.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTID.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTTEMPLATE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_ENCRYPTEDVALUE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_MSG.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_MSGS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_PBMPARAMETER.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_CRMF_SINGLEPUBINFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_IETF_ATTR_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_ISSUER_SERIAL.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_OBJECT_DIGEST_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_TARGET.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_TARGETING_INFORMATION.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_TARGETS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_TARGET_CERT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OSSL_USER_NOTICE_SYNTAX.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_OTHERNAME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PBE2PARAM.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PBEPARAM.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PBKDF2PARAM.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PBMAC1PARAM.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS12.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS12_BAGS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS12_MAC_DATA.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS12_SAFEBAG.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS12_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS12_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_DIGEST.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_ENCRYPT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_ENC_CONTENT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_ENVELOPE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_ISSUER_AND_SERIAL.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_NDEF.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_RECIP_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_SIGNED.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_SIGNER_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_SIGN_ENVELOPE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_bio.3ossl delete mode 100644 openssl-install/share/man/man3/i2d_PKCS7_bio_stream.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS7_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8PrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8PrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKCS8_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PKEY_USAGE_PERIOD.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_POLICYINFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_POLICYQUALINFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PROFESSION_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PROXY_CERT_INFO_EXTENSION.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PROXY_POLICY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_PublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSAPrivateKey.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSAPrivateKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSAPrivateKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSAPublicKey.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSAPublicKey_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSAPublicKey_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSA_OAEP_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSA_PSS_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSA_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSA_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_RSA_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_SCRYPT_PARAMS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_SCT_LIST.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_SSL_SESSION.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_SXNET.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_SXNETID.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_ACCURACY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_REQ.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_REQ_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_REQ_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_RESP.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_RESP_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_RESP_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_STATUS_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_TST_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_TST_INFO_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_TS_TST_INFO_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_USERNOTICE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_ACERT.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_ACERT_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_ACERT_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_ALGOR.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_ALGORS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_ATTRIBUTE.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_CERT_AUX.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_CINF.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_CRL.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_CRL_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_CRL_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_CRL_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_EXTENSION.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_EXTENSIONS.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_NAME.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_NAME_ENTRY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_PUBKEY.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_PUBKEY_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_PUBKEY_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_REQ.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_REQ_INFO.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_REQ_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_REQ_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_REVOKED.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_SIG.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_VAL.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_bio.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_X509_fp.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_re_X509_CRL_tbs.3ossl delete mode 120000 openssl-install/share/man/man3/i2d_re_X509_REQ_tbs.3ossl delete mode 100644 openssl-install/share/man/man3/i2d_re_X509_tbs.3ossl delete mode 120000 openssl-install/share/man/man3/i2o_SCT.3ossl delete mode 120000 openssl-install/share/man/man3/i2o_SCT_LIST.3ossl delete mode 120000 openssl-install/share/man/man3/i2s_ASN1_ENUMERATED.3ossl delete mode 120000 openssl-install/share/man/man3/i2s_ASN1_ENUMERATED_TABLE.3ossl delete mode 120000 openssl-install/share/man/man3/i2s_ASN1_IA5STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2s_ASN1_INTEGER.3ossl delete mode 120000 openssl-install/share/man/man3/i2s_ASN1_OCTET_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2s_ASN1_UTF8STRING.3ossl delete mode 120000 openssl-install/share/man/man3/i2t_ASN1_OBJECT.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_delete.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_doall.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_doall_arg.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_error.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_flush.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_free.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_get_down_load.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_insert.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_new.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_num_items.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_retrieve.3ossl delete mode 120000 openssl-install/share/man/man3/lh_TYPE_set_down_load.3ossl delete mode 120000 openssl-install/share/man/man3/o2i_SCT.3ossl delete mode 100644 openssl-install/share/man/man3/o2i_SCT_LIST.3ossl delete mode 120000 openssl-install/share/man/man3/pem_password_cb.3ossl delete mode 100644 openssl-install/share/man/man3/s2i_ASN1_IA5STRING.3ossl delete mode 120000 openssl-install/share/man/man3/s2i_ASN1_INTEGER.3ossl delete mode 120000 openssl-install/share/man/man3/s2i_ASN1_OCTET_STRING.3ossl delete mode 120000 openssl-install/share/man/man3/s2i_ASN1_UTF8STRING.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_deep_copy.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_delete.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_delete_ptr.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_dup.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_find.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_find_all.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_find_ex.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_free.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_insert.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_is_sorted.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_new.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_new_null.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_new_reserve.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_num.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_pop.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_pop_free.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_push.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_reserve.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_set.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_set_cmp_func.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_shift.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_sort.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_unshift.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_value.3ossl delete mode 120000 openssl-install/share/man/man3/sk_TYPE_zero.3ossl delete mode 120000 openssl-install/share/man/man3/ssl_ct_validation_cb.3ossl delete mode 120000 openssl-install/share/man/man3/tls_session_secret_cb_fn.3ossl delete mode 100644 openssl-install/share/man/man5/config.5ossl delete mode 100644 openssl-install/share/man/man5/fips_config.5ossl delete mode 100644 openssl-install/share/man/man5/x509v3_config.5ossl delete mode 100644 openssl-install/share/man/man7/EVP_ASYM_CIPHER-RSA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_ASYM_CIPHER-SM2.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-AES.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-ARIA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-BLOWFISH.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-CAMELLIA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-CAST.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-CHACHA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-DES.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-IDEA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-NULL.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-RC2.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-RC4.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-RC5.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-SEED.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_CIPHER-SM4.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-ARGON2.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-HKDF.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-HMAC-DRBG.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-KB.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-KRB5KDF.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-PBKDF1.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-PBKDF2.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-PKCS12KDF.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-PVKKDF.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-SCRYPT.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-SS.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-SSHKDF.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-TLS13_KDF.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-TLS1_PRF.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-X942-ASN1.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-X942-CONCAT.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KDF-X963.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KEM-EC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KEM-RSA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KEM-X25519.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEM-X448.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KEYEXCH-DH.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KEYEXCH-ECDH.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_KEYEXCH-X25519.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYEXCH-X448.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-CMAC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-DH.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-DHX.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-DSA.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-EC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-ED25519.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-ED448.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-HMAC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-Poly1305.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-RSA.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-SM2.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-Siphash.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-X25519.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_KEYMGMT-X448.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MAC-BLAKE2.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_MAC-BLAKE2BMAC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_MAC-BLAKE2SMAC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MAC-CMAC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MAC-GMAC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MAC-HMAC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MAC-KMAC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_MAC-KMAC128.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_MAC-KMAC256.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MAC-Poly1305.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MAC-Siphash.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-BLAKE2.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_MD-KECCAK-KMAC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-KECCAK.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-MD2.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-MD4.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-MD5-SHA1.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-MD5.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-MDC2.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-NULL.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-RIPEMD160.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-SHA1.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-SHA2.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-SHA3.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-SHAKE.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-SM3.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-WHIRLPOOL.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_MD-common.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_PKEY-CMAC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-DH.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_PKEY-DHX.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-DSA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-EC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_PKEY-ED25519.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_PKEY-ED448.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-FFC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-HMAC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_PKEY-Poly1305.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-RSA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-SM2.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_PKEY-Siphash.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_PKEY-X25519.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_PKEY-X448.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND-CRNG-TEST.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND-CTR-DRBG.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND-HASH-DRBG.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND-HMAC-DRBG.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND-JITTER.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND-SEED-SRC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND-TEST-RAND.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_RAND.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_SIGNATURE-CMAC.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_SIGNATURE-DSA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_SIGNATURE-ECDSA.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_SIGNATURE-ED25519.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_SIGNATURE-ED448.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_SIGNATURE-HMAC.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_SIGNATURE-Poly1305.7ossl delete mode 100644 openssl-install/share/man/man7/EVP_SIGNATURE-RSA.7ossl delete mode 120000 openssl-install/share/man/man7/EVP_SIGNATURE-Siphash.7ossl delete mode 120000 openssl-install/share/man/man7/Ed25519.7ossl delete mode 120000 openssl-install/share/man/man7/Ed448.7ossl delete mode 120000 openssl-install/share/man/man7/OPENSSL_API_COMPAT.7ossl delete mode 120000 openssl-install/share/man/man7/OPENSSL_NO_DEPRECATED.7ossl delete mode 100644 openssl-install/share/man/man7/OSSL_PROVIDER-FIPS.7ossl delete mode 100644 openssl-install/share/man/man7/OSSL_PROVIDER-base.7ossl delete mode 100644 openssl-install/share/man/man7/OSSL_PROVIDER-default.7ossl delete mode 100644 openssl-install/share/man/man7/OSSL_PROVIDER-legacy.7ossl delete mode 100644 openssl-install/share/man/man7/OSSL_PROVIDER-null.7ossl delete mode 100644 openssl-install/share/man/man7/OSSL_STORE-winstore.7ossl delete mode 100644 openssl-install/share/man/man7/RAND.7ossl delete mode 100644 openssl-install/share/man/man7/RSA-PSS.7ossl delete mode 120000 openssl-install/share/man/man7/RSA.7ossl delete mode 120000 openssl-install/share/man/man7/SM2.7ossl delete mode 100644 openssl-install/share/man/man7/X25519.7ossl delete mode 120000 openssl-install/share/man/man7/X448.7ossl delete mode 100644 openssl-install/share/man/man7/bio.7ossl delete mode 120000 openssl-install/share/man/man7/crypto.7ossl delete mode 100644 openssl-install/share/man/man7/ct.7ossl delete mode 100644 openssl-install/share/man/man7/des_modes.7ossl delete mode 100644 openssl-install/share/man/man7/evp.7ossl delete mode 100644 openssl-install/share/man/man7/fips_module.7ossl delete mode 100644 openssl-install/share/man/man7/life_cycle-cipher.7ossl delete mode 100644 openssl-install/share/man/man7/life_cycle-digest.7ossl delete mode 100644 openssl-install/share/man/man7/life_cycle-kdf.7ossl delete mode 100644 openssl-install/share/man/man7/life_cycle-mac.7ossl delete mode 100644 openssl-install/share/man/man7/life_cycle-pkey.7ossl delete mode 100644 openssl-install/share/man/man7/life_cycle-rand.7ossl delete mode 120000 openssl-install/share/man/man7/migration_guide.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-core.h.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-core_dispatch.h.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-core_names.h.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-env.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-glossary.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-qlog.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-quic.7ossl delete mode 100644 openssl-install/share/man/man7/openssl-threads.7ossl delete mode 100644 openssl-install/share/man/man7/openssl_user_macros.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-introduction.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-libcrypto-introduction.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-libraries-introduction.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-libssl-introduction.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-migration.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-quic-client-block.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-quic-client-non-block.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-quic-introduction.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-quic-multi-stream.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-tls-client-block.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-tls-client-non-block.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-tls-introduction.7ossl delete mode 100644 openssl-install/share/man/man7/ossl-guide-tls-server-block.7ossl delete mode 100644 openssl-install/share/man/man7/ossl_store-file.7ossl delete mode 100644 openssl-install/share/man/man7/ossl_store.7ossl delete mode 100644 openssl-install/share/man/man7/passphrase-encoding.7ossl delete mode 100644 openssl-install/share/man/man7/property.7ossl delete mode 100644 openssl-install/share/man/man7/provider-asym_cipher.7ossl delete mode 100644 openssl-install/share/man/man7/provider-base.7ossl delete mode 100644 openssl-install/share/man/man7/provider-cipher.7ossl delete mode 100644 openssl-install/share/man/man7/provider-decoder.7ossl delete mode 100644 openssl-install/share/man/man7/provider-digest.7ossl delete mode 100644 openssl-install/share/man/man7/provider-encoder.7ossl delete mode 100644 openssl-install/share/man/man7/provider-kdf.7ossl delete mode 100644 openssl-install/share/man/man7/provider-kem.7ossl delete mode 100644 openssl-install/share/man/man7/provider-keyexch.7ossl delete mode 100644 openssl-install/share/man/man7/provider-keymgmt.7ossl delete mode 100644 openssl-install/share/man/man7/provider-mac.7ossl delete mode 100644 openssl-install/share/man/man7/provider-object.7ossl delete mode 100644 openssl-install/share/man/man7/provider-rand.7ossl delete mode 100644 openssl-install/share/man/man7/provider-signature.7ossl delete mode 100644 openssl-install/share/man/man7/provider-storemgmt.7ossl delete mode 100644 openssl-install/share/man/man7/provider.7ossl delete mode 100644 openssl-install/share/man/man7/proxy-certificates.7ossl delete mode 120000 openssl-install/share/man/man7/ssl.7ossl delete mode 100644 openssl-install/share/man/man7/x509.7ossl delete mode 100644 openssl-install/ssl/ct_log_list.cnf delete mode 100644 openssl-install/ssl/ct_log_list.cnf.dist delete mode 100755 openssl-install/ssl/misc/CA.pl delete mode 120000 openssl-install/ssl/misc/tsget delete mode 100755 openssl-install/ssl/misc/tsget.pl delete mode 100644 openssl-install/ssl/openssl.cnf delete mode 100644 openssl-install/ssl/openssl.cnf.dist diff --git a/.gitignore b/.gitignore index 771fc6b1..06e29c73 100644 --- a/.gitignore +++ b/.gitignore @@ -7,11 +7,9 @@ nips/ node_modules/ nostr-tools/ tiny-AES-c/ -mbedtls/ -mbedtls-arm64-install/ -mbedtls-install/ + secp256k1/ Trash/debug_tests/ node_modules/ @@ -22,5 +20,4 @@ node_modules/ *.dylib *.dll build/ -mbedtls-install/ -mbedtls-arm64-install/ + diff --git a/Makefile b/Makefile index 5399faac..7d0579f9 100644 --- a/Makefile +++ b/Makefile @@ -29,6 +29,13 @@ SECP256K1_PRECOMPUTED_LIB = ./secp256k1/.libs/libsecp256k1_precomputed.a SECP256K1_ARM64_LIB = ./secp256k1/.libs/libsecp256k1_arm64.a SECP256K1_ARM64_PRECOMPUTED_LIB = ./secp256k1/.libs/libsecp256k1_precomputed_arm64.a +# OpenSSL library paths +OPENSSL_LIB_SSL = ./openssl-install/lib64/libssl.a +OPENSSL_LIB_CRYPTO = ./openssl-install/lib64/libcrypto.a + +# curl library paths +CURL_LIB = ./curl-install/lib/libcurl.a + # Library outputs (static only) STATIC_LIB = libnostr_core.a ARM64_STATIC_LIB = libnostr_core_arm64.a @@ -58,8 +65,40 @@ $(SECP256K1_LIB): secp256k1/configure fi @echo "x86_64 secp256k1 library built successfully" +# Build OpenSSL for x86_64 +$(OPENSSL_LIB_SSL) $(OPENSSL_LIB_CRYPTO): openssl-3.4.2/Configure + @echo "Building OpenSSL for x86_64..." + @cd openssl-3.4.2 && \ + if [ ! -f ../openssl-install/lib64/libssl.a ] || [ ! -f ../openssl-install/lib64/libcrypto.a ]; then \ + echo "Configuring OpenSSL..."; \ + make distclean >/dev/null 2>&1 || true; \ + ./Configure linux-x86_64 --prefix=$(PWD)/openssl-install --openssldir=$(PWD)/openssl-install/ssl no-shared no-dso; \ + echo "Building OpenSSL libraries..."; \ + make -j$(shell nproc 2>/dev/null || echo 4); \ + make install_sw >/dev/null 2>&1; \ + else \ + echo "OpenSSL libraries already exist, skipping build"; \ + fi + @echo "x86_64 OpenSSL libraries built successfully" + +# Build curl for x86_64 +$(CURL_LIB): curl-8.15.0/curl-8.15.0/configure $(OPENSSL_LIB_SSL) + @echo "Building curl for x86_64..." + @cd curl-8.15.0/curl-8.15.0 && \ + if [ ! -f ../../curl-install/lib/libcurl.a ]; then \ + echo "Configuring curl..."; \ + make distclean >/dev/null 2>&1 || true; \ + ./configure --prefix=$(PWD)/curl-install --with-openssl=$(PWD)/openssl-install --disable-shared --enable-static --without-libpsl --without-nghttp2 --without-brotli --without-zstd; \ + echo "Building curl library..."; \ + make -j$(shell nproc 2>/dev/null || echo 4); \ + make install >/dev/null 2>&1; \ + else \ + echo "curl library already exists, skipping build"; \ + fi + @echo "x86_64 curl library built successfully" + # Static library - includes secp256k1 and OpenSSL objects for self-contained library -$(STATIC_LIB): $(LIB_OBJECTS) $(SECP256K1_LIB) +$(STATIC_LIB): $(LIB_OBJECTS) $(SECP256K1_LIB) $(OPENSSL_LIB_SSL) $(OPENSSL_LIB_CRYPTO) @echo "Creating self-contained static library: $@" @echo "Extracting secp256k1 objects..." @mkdir -p .tmp_secp256k1 @@ -70,8 +109,8 @@ $(STATIC_LIB): $(LIB_OBJECTS) $(SECP256K1_LIB) fi @echo "Extracting OpenSSL objects..." @mkdir -p .tmp_openssl - @cd .tmp_openssl && $(AR) x ../openssl-install/lib64/libssl.a - @cd .tmp_openssl && $(AR) x ../openssl-install/lib64/libcrypto.a + @cd .tmp_openssl && $(AR) x ../$(OPENSSL_LIB_SSL) + @cd .tmp_openssl && $(AR) x ../$(OPENSSL_LIB_CRYPTO) @echo "Combining all objects into $@..." $(AR) rcs $@ $(LIB_OBJECTS) .tmp_secp256k1/*.o .tmp_openssl/*.o @rm -rf .tmp_secp256k1 .tmp_openssl diff --git a/VERSION b/VERSION index 7db26729..a2e1aa9d 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -0.1.26 +0.1.27 diff --git a/openssl-install/bin/c_rehash b/openssl-install/bin/c_rehash index 633c0dd2..551b9e01 100755 --- a/openssl-install/bin/c_rehash +++ b/openssl-install/bin/c_rehash @@ -12,8 +12,8 @@ # Perl c_rehash script, scan all files in a directory # and add symbolic links to their hash values. -my $dir = "/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-3.4.2/../openssl-install/ssl"; -my $prefix = "/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-3.4.2/../openssl-install"; +my $dir = "/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-install/ssl"; +my $prefix = "/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-install"; my $errorcount = 0; my $openssl = $ENV{OPENSSL} || "openssl"; diff --git a/openssl-install/include/openssl/configuration.h b/openssl-install/include/openssl/configuration.h index 19bbcc42..3f76e24f 100644 --- a/openssl-install/include/openssl/configuration.h +++ b/openssl-install/include/openssl/configuration.h @@ -58,6 +58,9 @@ extern "C" { # ifndef OPENSSL_NO_DEVCRYPTOENG # define OPENSSL_NO_DEVCRYPTOENG # endif +# ifndef OPENSSL_NO_DSO +# define OPENSSL_NO_DSO +# endif # ifndef OPENSSL_NO_EC_NISTP_64_GCC_128 # define OPENSSL_NO_EC_NISTP_64_GCC_128 # endif diff --git a/openssl-install/lib64/pkgconfig/libcrypto.pc b/openssl-install/lib64/pkgconfig/libcrypto.pc index 1a5b731b..9688d6b6 100644 --- a/openssl-install/lib64/pkgconfig/libcrypto.pc +++ b/openssl-install/lib64/pkgconfig/libcrypto.pc @@ -1,4 +1,4 @@ -prefix=/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-3.4.2/../openssl-install +prefix=/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-install exec_prefix=${prefix} libdir=${exec_prefix}/lib64 includedir=${prefix}/include diff --git a/openssl-install/lib64/pkgconfig/libssl.pc b/openssl-install/lib64/pkgconfig/libssl.pc index a53f63d3..c79924aa 100644 --- a/openssl-install/lib64/pkgconfig/libssl.pc +++ b/openssl-install/lib64/pkgconfig/libssl.pc @@ -1,4 +1,4 @@ -prefix=/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-3.4.2/../openssl-install +prefix=/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-install exec_prefix=${prefix} libdir=${exec_prefix}/lib64 includedir=${prefix}/include diff --git a/openssl-install/lib64/pkgconfig/openssl.pc b/openssl-install/lib64/pkgconfig/openssl.pc index 73afd9bd..02d0848c 100644 --- a/openssl-install/lib64/pkgconfig/openssl.pc +++ b/openssl-install/lib64/pkgconfig/openssl.pc @@ -1,4 +1,4 @@ -prefix=/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-3.4.2/../openssl-install +prefix=/home/teknari/Sync/Programming/VibeCoding/nostr_core_lib/openssl-install exec_prefix=${prefix} libdir=${exec_prefix}/lib64 includedir=${prefix}/include diff --git a/openssl-install/share/doc/openssl/html/man1/CA.pl.html b/openssl-install/share/doc/openssl/html/man1/CA.pl.html deleted file mode 100644 index 4557cbdb..00000000 --- a/openssl-install/share/doc/openssl/html/man1/CA.pl.html +++ /dev/null @@ -1,175 +0,0 @@ - - - - -CA.pl - - - - - - - - - - -

NAME

- -

CA.pl - friendlier interface for OpenSSL certificate programs

- -

SYNOPSIS

- -

CA.pl -? | -h | -help

- -

CA.pl -newcert | -newreq | -newreq-nodes | -xsign | -sign | -signCA | -signcert | -crl | -newca [-extra-cmd parameter]

- -

CA.pl -pkcs12 [certname]

- -

CA.pl -verify certfile ...

- -

CA.pl -revoke certfile [reason]

- -

DESCRIPTION

- -

The CA.pl script is a perl script that supplies the relevant command line arguments to the openssl(1) command for some common certificate operations. It is intended to simplify the process of certificate creation and management by the use of some simple options.

- -

The script is intended as a simple front end for the openssl(1) program for use by a beginner. Its behaviour isn't always what is wanted. For more control over the behaviour of the certificate commands call the openssl(1) command directly.

- -

Most of the filenames mentioned below can be modified by editing the CA.pl script.

- -

Under some environments it may not be possible to run the CA.pl script directly (for example Win32) and the default configuration file location may be wrong. In this case the command:

- -
perl -S CA.pl
- -

can be used and the OPENSSL_CONF environment variable can be set to point to the correct path of the configuration file.

- -

OPTIONS

- -
- -
-?, -h, -help
-
- -

Prints a usage message.

- -
-
-newcert
-
- -

Creates a new self signed certificate. The private key is written to the file newkey.pem and the request written to the file newreq.pem. Invokes openssl-req(1).

- -
-
-newreq
-
- -

Creates a new certificate request. The private key is written to the file newkey.pem and the request written to the file newreq.pem. Executes openssl-req(1) under the hood.

- -
-
-newreq-nodes
-
- -

Is like -newreq except that the private key will not be encrypted. Uses openssl-req(1).

- -
-
-newca
-
- -

Creates a new CA hierarchy for use with the ca program (or the -signcert and -xsign options). The user is prompted to enter the filename of the CA certificates (which should also contain the private key) or by hitting ENTER details of the CA will be prompted for. The relevant files and directories are created in a directory called demoCA in the current directory. Uses openssl-req(1) and openssl-ca(1).

- -

If the demoCA directory already exists then the -newca command will not overwrite it and will do nothing. This can happen if a previous call using the -newca option terminated abnormally. To get the correct behaviour delete the directory if it already exists.

- -
-
-pkcs12
-
- -

Create a PKCS#12 file containing the user certificate, private key and CA certificate. It expects the user certificate and private key to be in the file newcert.pem and the CA certificate to be in the file demoCA/cacert.pem, it creates a file newcert.p12. This command can thus be called after the -sign option. The PKCS#12 file can be imported directly into a browser. If there is an additional argument on the command line it will be used as the "friendly name" for the certificate (which is typically displayed in the browser list box), otherwise the name "My Certificate" is used. Delegates work to openssl-pkcs12(1).

- -
-
-sign, -signcert, -xsign
-
- -

Calls the openssl-ca(1) command to sign a certificate request. It expects the request to be in the file newreq.pem. The new certificate is written to the file newcert.pem except in the case of the -xsign option when it is written to standard output.

- -
-
-signCA
-
- -

This option is the same as the -sign option except it uses the configuration file section v3_ca and so makes the signed request a valid CA certificate. This is useful when creating intermediate CA from a root CA. Extra params are passed to openssl-ca(1).

- -
-
-signcert
-
- -

This option is the same as -sign except it expects a self signed certificate to be present in the file newreq.pem. Extra params are passed to openssl-x509(1) and openssl-ca(1).

- -
-
-crl
-
- -

Generate a CRL. Executes openssl-ca(1).

- -
-
-revoke certfile [reason]
-
- -

Revoke the certificate contained in the specified certfile. An optional reason may be specified, and must be one of: unspecified, keyCompromise, CACompromise, affiliationChanged, superseded, cessationOfOperation, certificateHold, or removeFromCRL. Leverages openssl-ca(1).

- -
-
-verify
-
- -

Verifies certificates against the CA certificate for demoCA. If no certificates are specified on the command line it tries to verify the file newcert.pem. Invokes openssl-verify(1).

- -
-
-extra-cmd parameter
-
- -

For each option extra-cmd, pass parameter to the openssl(1) sub-command with the same name as cmd, if that sub-command is invoked. For example, if openssl-req(1) is invoked, the parameter given with -extra-req will be passed to it. For multi-word parameters, either repeat the option or quote the parameters so it looks like one word to your shell. See the individual command documentation for more information.

- -
-
- -

EXAMPLES

- -

Create a CA hierarchy:

- -
CA.pl -newca
- -

Complete certificate creation example: create a CA, create a request, sign the request and finally create a PKCS#12 file containing it.

- -
CA.pl -newca
-CA.pl -newreq
-CA.pl -sign
-CA.pl -pkcs12 "My Test Certificate"
- -

ENVIRONMENT

- -

The environment variable OPENSSL may be used to specify the name of the OpenSSL program. It can be a full pathname, or a relative one.

- -

The environment variable OPENSSL_CONFIG may be used to specify a configuration option and value to the req and ca commands invoked by this script. It's value should be the option and pathname, as in -config /path/to/conf-file.

- -

SEE ALSO

- -

openssl(1), openssl-x509(1), openssl-ca(1), openssl-req(1), openssl-pkcs12(1), config(5)

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-asn1parse.html b/openssl-install/share/doc/openssl/html/man1/openssl-asn1parse.html deleted file mode 100644 index dba03591..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-asn1parse.html +++ /dev/null @@ -1,229 +0,0 @@ - - - - -openssl-asn1parse - - - - - - - - - - -

NAME

- -

openssl-asn1parse - ASN.1 parsing command

- -

SYNOPSIS

- -

openssl asn1parse [-help] [-inform DER|PEM|B64] [-in filename] [-out filename] [-noout] [-offset number] [-length number] [-i] [-oid filename] [-dump] [-dlimit num] [-strparse offset] [-genstr string] [-genconf file] [-strictpem] [-item name]

- -

DESCRIPTION

- -

This command is a diagnostic utility that can parse ASN.1 structures. It can also be used to extract data from ASN.1 formatted data.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM|B64
-
- -

The input format; the default is PEM. See openssl-format-options(1) for details.

- -
-
-in filename
-
- -

The input file, default is standard input.

- -
-
-out filename
-
- -

Output file to place the DER encoded data into. If this option is not present then no data will be output. This is most useful when combined with the -strparse option.

- -
-
-noout
-
- -

Don't output the parsed version of the input file.

- -
-
-offset number
-
- -

Starting offset to begin parsing, default is start of file.

- -
-
-length number
-
- -

Number of bytes to parse, default is until end of file.

- -
-
-i
-
- -

Indents the output according to the "depth" of the structures.

- -
-
-oid filename
-
- -

A file containing additional OBJECT IDENTIFIERs (OIDs). The format of this file is described in the NOTES section below.

- -
-
-dump
-
- -

Dump unknown data in hex format.

- -
-
-dlimit num
-
- -

Like -dump, but only the first num bytes are output.

- -
-
-strparse offset
-
- -

Parse the contents octets of the ASN.1 object starting at offset. This option can be used multiple times to "drill down" into a nested structure.

- -
-
-genstr string, -genconf file
-
- -

Generate encoded data based on string, file or both using ASN1_generate_nconf(3) format. If file only is present then the string is obtained from the default section using the name asn1. The encoded data is passed through the ASN1 parser and printed out as though it came from a file, the contents can thus be examined and written to a file using the -out option.

- -
-
-strictpem
-
- -

If this option is used then -inform will be ignored. Without this option any data in a PEM format input file will be treated as being base64 encoded and processed whether it has the normal PEM BEGIN and END markers or not. This option will ignore any data prior to the start of the BEGIN marker, or after an END marker in a PEM file.

- -
-
-item name
-
- -

Attempt to decode and print the data as an ASN1_ITEM name. This can be used to print out the fields of any supported ASN.1 structure if the type is known.

- -
-
- -

Output

- -

The output will typically contain lines like this:

- -
0:d=0  hl=4 l= 681 cons: SEQUENCE
- -

.....

- -
229:d=3  hl=3 l= 141 prim: BIT STRING
-373:d=2  hl=3 l= 162 cons: cont [ 3 ]
-376:d=3  hl=3 l= 159 cons: SEQUENCE
-379:d=4  hl=2 l=  29 cons: SEQUENCE
-381:d=5  hl=2 l=   3 prim: OBJECT            :X509v3 Subject Key Identifier
-386:d=5  hl=2 l=  22 prim: OCTET STRING
-410:d=4  hl=2 l= 112 cons: SEQUENCE
-412:d=5  hl=2 l=   3 prim: OBJECT            :X509v3 Authority Key Identifier
-417:d=5  hl=2 l= 105 prim: OCTET STRING
-524:d=4  hl=2 l=  12 cons: SEQUENCE
- -

.....

- -

This example is part of a self-signed certificate. Each line starts with the offset in decimal. d=XX specifies the current depth. The depth is increased within the scope of any SET or SEQUENCE. hl=XX gives the header length (tag and length octets) of the current type. l=XX gives the length of the contents octets.

- -

The -i option can be used to make the output more readable.

- -

Some knowledge of the ASN.1 structure is needed to interpret the output.

- -

In this example the BIT STRING at offset 229 is the certificate public key. The contents octets of this will contain the public key information. This can be examined using the option -strparse 229 to yield:

- -
  0:d=0  hl=3 l= 137 cons: SEQUENCE
-  3:d=1  hl=3 l= 129 prim: INTEGER           :E5D21E1F5C8D208EA7A2166C7FAF9F6BDF2059669C60876DDB70840F1A5AAFA59699FE471F379F1DD6A487E7D5409AB6A88D4A9746E24B91D8CF55DB3521015460C8EDE44EE8A4189F7A7BE77D6CD3A9AF2696F486855CF58BF0EDF2B4068058C7A947F52548DDF7E15E96B385F86422BEA9064A3EE9E1158A56E4A6F47E5897
-135:d=1  hl=2 l=   3 prim: INTEGER           :010001
- -

NOTES

- -

If an OID is not part of OpenSSL's internal table it will be represented in numerical form (for example 1.2.3.4). The file passed to the -oid option allows additional OIDs to be included. Each line consists of three columns, the first column is the OID in numerical format and should be followed by white space. The second column is the "short name" which is a single word followed by whitespace. The final column is the rest of the line and is the "long name". Example:

- -

1.2.3.4 shortName A long name

- -

For any OID with an associated short and long name, this command will display the long name.

- -

EXAMPLES

- -

Parse a file:

- -
openssl asn1parse -in file.pem
- -

Parse a DER file:

- -
openssl asn1parse -inform DER -in file.der
- -

Generate a simple UTF8String:

- -
openssl asn1parse -genstr 'UTF8:Hello World'
- -

Generate and write out a UTF8String, don't print parsed output:

- -
openssl asn1parse -genstr 'UTF8:Hello World' -noout -out utf8.der
- -

Generate using a config file:

- -
openssl asn1parse -genconf asn1.cnf -noout -out asn1.der
- -

Example config file:

- -
asn1=SEQUENCE:seq_sect
-
-[seq_sect]
-
-field1=BOOL:TRUE
-field2=EXP:0, UTF8:some random string
- -

BUGS

- -

There should be options to change the format of output lines. The output of some ASN.1 types is not well handled (if at all).

- -

SEE ALSO

- -

openssl(1), ASN1_generate_nconf(3)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-ca.html b/openssl-install/share/doc/openssl/html/man1/openssl-ca.html deleted file mode 100644 index e890f282..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-ca.html +++ /dev/null @@ -1,753 +0,0 @@ - - - - -openssl-ca - - - - - - - - - - -

NAME

- -

openssl-ca - sample minimal CA application

- -

SYNOPSIS

- -

openssl ca [-help] [-verbose] [-quiet] [-config filename] [-name section] [-section section] [-gencrl] [-revoke file] [-valid file] [-status serial] [-updatedb] [-crl_reason reason] [-crl_hold instruction] [-crl_compromise time] [-crl_CA_compromise time] [-crl_lastupdate date] [-crl_nextupdate date] [-crldays days] [-crlhours hours] [-crlsec seconds] [-crlexts section] [-startdate date] [-not_before date] [-enddate date] [-not_after date] [-days arg] [-md arg] [-policy arg] [-keyfile filename|uri] [-keyform DER|PEM|P12|ENGINE] [-key arg] [-passin arg] [-cert file] [-certform DER|PEM|P12] [-selfsign] [-in file] [-inform DER|<PEM>] [-out file] [-notext] [-dateopt] [-outdir dir] [-infiles] [-spkac file] [-ss_cert file] [-preserveDN] [-noemailDN] [-batch] [-msie_hack] [-extensions section] [-extfile section] [-subj arg] [-utf8] [-sigopt nm:v] [-vfyopt nm:v] [-create_serial] [-rand_serial] [-multivalue-rdn] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [certreq...]

- -

DESCRIPTION

- -

This command emulates a CA application. See the WARNINGS especially when considering to use it productively.

- -

It generates certificates bearing X.509 version 3. Unless specified otherwise, key identifier extensions are included as described in x509v3_config(5).

- -

It can be used to sign certificate requests (CSRs) in a variety of forms and generate certificate revocation lists (CRLs). It also maintains a text database of issued certificates and their status. When signing certificates, a single request can be specified with the -in option, or multiple requests can be processed by specifying a set of certreq files after all options.

- -

Note that there are also very lean ways of generating certificates: the req and x509 commands can be used for directly creating certificates. See openssl-req(1) and openssl-x509(1) for details.

- -

The descriptions of the ca command options are divided into each purpose.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-verbose
-
- -

This prints extra details about the operations being performed.

- -
-
-quiet
-
- -

This prints fewer details about the operations being performed, which may be handy during batch scripts or pipelines.

- -
-
-config filename
-
- -

Specifies the configuration file to use. Optional; for a description of the default value, see "COMMAND SUMMARY" in openssl(1).

- -
-
-name section, -section section
-
- -

Specifies the configuration file section to use (overrides default_ca in the ca section).

- -
-
-in filename
-
- -

An input filename containing a single certificate request (CSR) to be signed by the CA.

- -
-
-inform DER|PEM
-
- -

The format to use when loading certificate request (CSR) input files; by default PEM is tried first. See openssl-format-options(1) for details.

- -
-
-ss_cert filename
-
- -

A single self-signed certificate to be signed by the CA.

- -
-
-spkac filename
-
- -

A file containing a single Netscape signed public key and challenge and additional field values to be signed by the CA. See the SPKAC FORMAT section for information on the required input and output format.

- -
-
-infiles
-
- -

If present this should be the last option, all subsequent arguments are taken as the names of files containing certificate requests.

- -
-
-out filename
-
- -

The output file to output certificates to. The default is standard output. The certificate details will also be printed out to this file in PEM format (except that -spkac outputs DER format).

- -
-
-outdir directory
-
- -

The directory to output certificates to. The certificate will be written to a filename consisting of the serial number in hex with .pem appended.

- -
-
-cert filename
-
- -

The CA certificate, which must match with -keyfile.

- -
-
-certform DER|PEM|P12
-
- -

The format of the data in certificate input files; unspecified by default. See openssl-format-options(1) for details.

- -
-
-keyfile filename|uri
-
- -

The CA private key to sign certificate requests with. This must match with -cert.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The format of the private key input file; unspecified by default. See openssl-format-options(1) for details.

- -
-
-sigopt nm:v
-
- -

Pass options to the signature algorithm during sign operations. Names and values of these options are algorithm-specific and documented in "Signature parameters" in provider-signature(7).

- -
-
-vfyopt nm:v
-
- -

Pass options to the signature algorithm during verify operations. Names and values of these options are algorithm-specific.

- -

This often needs to be given while signing too, because the self-signature of a certificate signing request (CSR) is verified against the included public key, and that verification may need its own set of options.

- -
-
-key password
-
- -

The password used to encrypt the private key. Since on some systems the command line arguments are visible (e.g., when using ps(1) on Unix), this option should be used with caution. Better use -passin.

- -
-
-passin arg
-
- -

The key password source for key files and certificate PKCS#12 files. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-selfsign
-
- -

Indicates the issued certificates are to be signed with the key the certificate requests were signed with (given with -keyfile). Certificate requests signed with a different key are ignored. If -spkac, -ss_cert or -gencrl are given, -selfsign is ignored.

- -

A consequence of using -selfsign is that the self-signed certificate appears among the entries in the certificate database (see the configuration option database), and uses the same serial number counter as all other certificates sign with the self-signed certificate.

- -
-
-notext
-
- -

Don't output the text form of a certificate to the output file.

- -
-
-dateopt
-
- -

Specify the date output format. Values are: rfc_822 and iso_8601. Defaults to rfc_822.

- -
-
-startdate date, -not_before date
-
- -

This allows the start date to be explicitly set. The format of the date is YYMMDDHHMMSSZ (the same as an ASN1 UTCTime structure), or YYYYMMDDHHMMSSZ (the same as an ASN1 GeneralizedTime structure). In both formats, seconds SS and timezone Z must be present. Alternatively, you can also use "today".

- -
-
-enddate date, -not_after date
-
- -

This allows the expiry date to be explicitly set. The format of the date is YYMMDDHHMMSSZ (the same as an ASN1 UTCTime structure), or YYYYMMDDHHMMSSZ (the same as an ASN1 GeneralizedTime structure). In both formats, seconds SS and timezone Z must be present. Alternatively, you can also use "today".

- -

This overrides the -days option.

- -
-
-days arg
-
- -

The number of days from today to certify the certificate for.

- -

Regardless of the option -not_before, the days are always counted from today. When used together with the option -not_after/-startdate, the explicit expiry date takes precedence.

- -
-
-md alg
-
- -

The message digest to use. Any digest supported by the openssl-dgst(1) command can be used. For signing algorithms that do not support a digest (i.e. Ed25519 and Ed448) any message digest that is set is ignored. This option also applies to CRLs.

- -
-
-policy arg
-
- -

This option defines the CA "policy" to use. This is a section in the configuration file which decides which fields should be mandatory or match the CA certificate. Check out the POLICY FORMAT section for more information.

- -
-
-msie_hack
-
- -

This is a deprecated option to make this command work with very old versions of the IE certificate enrollment control "certenr3". It used UniversalStrings for almost everything. Since the old control has various security bugs its use is strongly discouraged.

- -
-
-preserveDN
-
- -

Normally the DN order of a certificate is the same as the order of the fields in the relevant policy section. When this option is set the order is the same as the request. This is largely for compatibility with the older IE enrollment control which would only accept certificates if their DNs match the order of the request. This is not needed for Xenroll.

- -
-
-noemailDN
-
- -

The DN of a certificate can contain the EMAIL field if present in the request DN, however, it is good policy just having the e-mail set into the altName extension of the certificate. When this option is set the EMAIL field is removed from the certificate' subject and set only in the, eventually present, extensions. The email_in_dn keyword can be used in the configuration file to enable this behaviour.

- -
-
-batch
-
- -

This sets the batch mode. In this mode no questions will be asked and all certificates will be certified automatically.

- -
-
-extensions section
-
- -

The section of the configuration file containing certificate extensions to be added when a certificate is issued (defaults to x509_extensions unless the -extfile option is used).

- -

See the x509v3_config(5) manual page for details of the extension section format.

- -
-
-extfile file
-
- -

An additional configuration file to read certificate extensions from (using the default section unless the -extensions option is also used).

- -
-
-subj arg
-
- -

Supersedes subject name given in the request.

- -

The arg must be formatted as /type0=value0/type1=value1/type2=.... Special characters may be escaped by \ (backslash), whitespace is retained. Empty values are permitted, but the corresponding type will not be included in the resulting certificate. Giving a single / will lead to an empty sequence of RDNs (a NULL-DN). Multi-valued RDNs can be formed by placing a + character instead of a / between the AttributeValueAssertions (AVAs) that specify the members of the set. Example:

- -

/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe

- -
-
-utf8
-
- -

This option causes field values to be interpreted as UTF8 strings, by default they are interpreted as ASCII. This means that the field values, whether prompted from a terminal or obtained from a configuration file, must be valid UTF8 strings.

- -
-
-create_serial
-
- -

If reading serial from the text file as specified in the configuration fails, specifying this option creates a new random serial to be used as next serial number. To get random serial numbers, use the -rand_serial flag instead; this should only be used for simple error-recovery.

- -
-
-rand_serial
-
- -

Generate a large random number to use as the serial number. This overrides any option or configuration to use a serial number file.

- -
-
-multivalue-rdn
-
- -

This option has been deprecated and has no effect.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

CRL OPTIONS

- -
- -
-gencrl
-
- -

This option generates a CRL based on information in the index file.

- -
-
-crl_lastupdate time
-
- -

Allows the value of the CRL's lastUpdate field to be explicitly set; if this option is not present, the current time is used. Accepts times in YYMMDDHHMMSSZ format (the same as an ASN1 UTCTime structure) or YYYYMMDDHHMMSSZ format (the same as an ASN1 GeneralizedTime structure).

- -
-
-crl_nextupdate time
-
- -

Allows the value of the CRL's nextUpdate field to be explicitly set; if this option is present, any values given for -crldays, -crlhours and -crlsec are ignored. Accepts times in the same formats as -crl_lastupdate.

- -
-
-crldays num
-
- -

The number of days before the next CRL is due. That is the days from now to place in the CRL nextUpdate field.

- -
-
-crlhours num
-
- -

The number of hours before the next CRL is due.

- -
-
-crlsec num
-
- -

The number of seconds before the next CRL is due.

- -
-
-revoke filename
-
- -

A filename containing a certificate to revoke.

- -
-
-valid filename
-
- -

A filename containing a certificate to add a Valid certificate entry.

- -
-
-status serial
-
- -

Displays the revocation status of the certificate with the specified serial number and exits.

- -
-
-updatedb
-
- -

Updates the database index to purge expired certificates.

- -
-
-crl_reason reason
-
- -

Revocation reason, where reason is one of: unspecified, keyCompromise, CACompromise, affiliationChanged, superseded, cessationOfOperation, certificateHold or removeFromCRL. The matching of reason is case insensitive. Setting any revocation reason will make the CRL v2.

- -

In practice removeFromCRL is not particularly useful because it is only used in delta CRLs which are not currently implemented.

- -
-
-crl_hold instruction
-
- -

This sets the CRL revocation reason code to certificateHold and the hold instruction to instruction which must be an OID. Although any OID can be used only holdInstructionNone (the use of which is discouraged by RFC2459) holdInstructionCallIssuer or holdInstructionReject will normally be used.

- -
-
-crl_compromise time
-
- -

This sets the revocation reason to keyCompromise and the compromise time to time. time should be in GeneralizedTime format that is YYYYMMDDHHMMSSZ.

- -
-
-crl_CA_compromise time
-
- -

This is the same as crl_compromise except the revocation reason is set to CACompromise.

- -
-
-crlexts section
-
- -

The section of the configuration file containing CRL extensions to include. If no CRL extension section is present then a V1 CRL is created, if the CRL extension section is present (even if it is empty) then a V2 CRL is created. The CRL extensions specified are CRL extensions and not CRL entry extensions. It should be noted that some software (for example Netscape) can't handle V2 CRLs. See x509v3_config(5) manual page for details of the extension section format.

- -
-
- -

CONFIGURATION FILE OPTIONS

- -

The section of the configuration file containing options for this command is found as follows: If the -name command line option is used, then it names the section to be used. Otherwise the section to be used must be named in the default_ca option of the ca section of the configuration file (or in the default section of the configuration file). Besides default_ca, the following options are read directly from the ca section: RANDFILE preserve msie_hack With the exception of RANDFILE, this is probably a bug and may change in future releases.

- -

Many of the configuration file options are identical to command line options. Where the option is present in the configuration file and the command line the command line value is used. Where an option is described as mandatory then it must be present in the configuration file or the command line equivalent (if any) used.

- -
- -
oid_file
-
- -

This specifies a file containing additional OBJECT IDENTIFIERS. Each line of the file should consist of the numerical form of the object identifier followed by whitespace then the short name followed by whitespace and finally the long name.

- -
-
oid_section
-
- -

This specifies a section in the configuration file containing extra object identifiers. Each line should consist of the short name of the object identifier followed by = and the numerical form. The short and long names are the same when this option is used.

- -
-
new_certs_dir
-
- -

The same as the -outdir command line option. It specifies the directory where new certificates will be placed. Mandatory.

- -
-
certificate
-
- -

The same as -cert. It gives the file containing the CA certificate. Mandatory.

- -
-
private_key
-
- -

Same as the -keyfile option. The file containing the CA private key. Mandatory.

- -
-
RANDFILE
-
- -

At startup the specified file is loaded into the random number generator, and at exit 256 bytes will be written to it. (Note: Using a RANDFILE is not necessary anymore, see the "HISTORY" section.

- -
-
default_days
-
- -

The same as the -days option. The number of days from today to certify a certificate for.

- -
-
default_startdate
-
- -

The same as the -startdate option. The start date to certify a certificate for. If not set the current time is used.

- -
-
default_enddate
-
- -

The same as the -enddate option. Either this option or default_days (or the command line equivalents) must be present.

- -
-
default_crl_hours default_crl_days
-
- -

The same as the -crlhours and the -crldays options. These will only be used if neither command line option is present. At least one of these must be present to generate a CRL.

- -
-
default_md
-
- -

The same as the -md option. Mandatory except where the signing algorithm does not require a digest (i.e. Ed25519 and Ed448).

- -
-
database
-
- -

The text database file to use. Mandatory. This file must be present though initially it will be empty.

- -
-
unique_subject
-
- -

If the value yes is given, the valid certificate entries in the database must have unique subjects. if the value no is given, several valid certificate entries may have the exact same subject. The default value is yes, to be compatible with older (pre 0.9.8) versions of OpenSSL. However, to make CA certificate roll-over easier, it's recommended to use the value no, especially if combined with the -selfsign command line option.

- -

Note that it is valid in some circumstances for certificates to be created without any subject. In the case where there are multiple certificates without subjects this does not count as a duplicate.

- -
-
serial
-
- -

A text file containing the next serial number to use in hex. Mandatory. This file must be present and contain a valid serial number.

- -
-
crlnumber
-
- -

A text file containing the next CRL number to use in hex. The crl number will be inserted in the CRLs only if this file exists. If this file is present, it must contain a valid CRL number.

- -
-
x509_extensions
-
- -

A fallback to the -extensions option.

- -
-
crl_extensions
-
- -

A fallback to the -crlexts option.

- -
-
preserve
-
- -

The same as -preserveDN

- -
-
email_in_dn
-
- -

The same as -noemailDN. If you want the EMAIL field to be removed from the DN of the certificate simply set this to 'no'. If not present the default is to allow for the EMAIL filed in the certificate's DN.

- -
-
msie_hack
-
- -

The same as -msie_hack

- -
-
policy
-
- -

The same as -policy. Mandatory. See the POLICY FORMAT section for more information.

- -
-
name_opt, cert_opt
-
- -

These options allow the format used to display the certificate details when asking the user to confirm signing. All the options supported by the x509 utilities -nameopt and -certopt switches can be used here, except the no_signame and no_sigdump are permanently set and cannot be disabled (this is because the certificate signature cannot be displayed because the certificate has not been signed at this point).

- -

For convenience the values ca_default are accepted by both to produce a reasonable output.

- -

If neither option is present the format used in earlier versions of OpenSSL is used. Use of the old format is strongly discouraged because it only displays fields mentioned in the policy section, mishandles multicharacter string types and does not display extensions.

- -
-
copy_extensions
-
- -

Determines how extensions in certificate requests should be handled. If set to none or this option is not present then extensions are ignored and not copied to the certificate. If set to copy then any extensions present in the request that are not already present are copied to the certificate. If set to copyall then all extensions in the request are copied to the certificate: if the extension is already present in the certificate it is deleted first. See the WARNINGS section before using this option.

- -

The main use of this option is to allow a certificate request to supply values for certain extensions such as subjectAltName.

- -
-
- -

POLICY FORMAT

- -

The policy section consists of a set of variables corresponding to certificate DN fields. If the value is "match" then the field value must match the same field in the CA certificate. If the value is "supplied" then it must be present. If the value is "optional" then it may be present. Any fields not mentioned in the policy section are silently deleted, unless the -preserveDN option is set but this can be regarded more of a quirk than intended behaviour.

- -

SPKAC FORMAT

- -

The input to the -spkac command line option is a Netscape signed public key and challenge. This will usually come from the KEYGEN tag in an HTML form to create a new private key. It is however possible to create SPKACs using openssl-spkac(1).

- -

The file should contain the variable SPKAC set to the value of the SPKAC and also the required DN components as name value pairs. If you need to include the same component twice then it can be preceded by a number and a '.'.

- -

When processing SPKAC format, the output is DER if the -out flag is used, but PEM format if sending to stdout or the -outdir flag is used.

- -

EXAMPLES

- -

Note: these examples assume that the directory structure this command assumes is already set up and the relevant files already exist. This usually involves creating a CA certificate and private key with openssl-req(1), a serial number file and an empty index file and placing them in the relevant directories.

- -

To use the sample configuration file below the directories demoCA, demoCA/private and demoCA/newcerts would be created. The CA certificate would be copied to demoCA/cacert.pem and its private key to demoCA/private/cakey.pem. A file demoCA/serial would be created containing for example "01" and the empty index file demoCA/index.txt.

- -

Sign a certificate request:

- -
openssl ca -in req.pem -out newcert.pem
- -

Sign an SM2 certificate request:

- -
openssl ca -in sm2.csr -out sm2.crt -md sm3 \
-        -sigopt "distid:1234567812345678" \
-        -vfyopt "distid:1234567812345678"
- -

Sign a certificate request, using CA extensions:

- -
openssl ca -in req.pem -extensions v3_ca -out newcert.pem
- -

Generate a CRL

- -
openssl ca -gencrl -out crl.pem
- -

Sign several requests:

- -
openssl ca -infiles req1.pem req2.pem req3.pem
- -

Certify a Netscape SPKAC:

- -
openssl ca -spkac spkac.txt
- -

A sample SPKAC file (the SPKAC line has been truncated for clarity):

- -
SPKAC=MIG0MGAwXDANBgkqhkiG9w0BAQEFAANLADBIAkEAn7PDhCeV/xIxUg8V70YRxK2A5
-CN=Steve Test
-emailAddress=steve@openssl.org
-0.OU=OpenSSL Group
-1.OU=Another Group
- -

A sample configuration file with the relevant sections for this command:

- -
[ ca ]
-default_ca      = CA_default            # The default ca section
-
-[ CA_default ]
-
-dir            = ./demoCA              # top dir
-database       = $dir/index.txt        # index file.
-new_certs_dir  = $dir/newcerts         # new certs dir
-
-certificate    = $dir/cacert.pem       # The CA cert
-serial         = $dir/serial           # serial no file
-#rand_serial    = yes                  # for random serial#'s
-private_key    = $dir/private/cakey.pem# CA private key
-
-default_days   = 365                   # how long to certify for
-default_crl_days= 30                   # how long before next CRL
-default_md     = sha256                # md to use
-
-policy         = policy_any            # default policy
-email_in_dn    = no                    # Don't add the email into cert DN
-
-name_opt       = ca_default            # Subject name display option
-cert_opt       = ca_default            # Certificate display option
-copy_extensions = none                 # Don't copy extensions from request
-
-[ policy_any ]
-countryName            = supplied
-stateOrProvinceName    = optional
-organizationName       = optional
-organizationalUnitName = optional
-commonName             = supplied
-emailAddress           = optional
- -

FILES

- -

Note: the location of all files can change either by compile time options, configuration file entries, environment variables or command line options. The values below reflect the default values.

- -
/usr/local/ssl/lib/openssl.cnf - master configuration file
-./demoCA                       - main CA directory
-./demoCA/cacert.pem            - CA certificate
-./demoCA/private/cakey.pem     - CA private key
-./demoCA/serial                - CA serial number file
-./demoCA/serial.old            - CA serial number backup file
-./demoCA/index.txt             - CA text database file
-./demoCA/index.txt.old         - CA text database backup file
-./demoCA/certs                 - certificate output file
- -

RESTRICTIONS

- -

The text database index file is a critical part of the process and if corrupted it can be difficult to fix. It is theoretically possible to rebuild the index file from all the issued certificates and a current CRL: however there is no option to do this.

- -

V2 CRL features like delta CRLs are not currently supported.

- -

Although several requests can be input and handled at once it is only possible to include one SPKAC or self-signed certificate.

- -

BUGS

- -

This command is quirky and at times downright unfriendly.

- -

The use of an in-memory text database can cause problems when large numbers of certificates are present because, as the name implies the database has to be kept in memory.

- -

This command really needs rewriting or the required functionality exposed at either a command or interface level so that a more user-friendly replacement could handle things properly. The script CA.pl helps a little but not very much.

- -

Any fields in a request that are not present in a policy are silently deleted. This does not happen if the -preserveDN option is used. To enforce the absence of the EMAIL field within the DN, as suggested by RFCs, regardless the contents of the request' subject the -noemailDN option can be used. The behaviour should be more friendly and configurable.

- -

Canceling some commands by refusing to certify a certificate can create an empty file.

- -

WARNINGS

- -

This command was originally meant as an example of how to do things in a CA. Its code does not have production quality. It was not supposed to be used as a full blown CA itself, nevertheless some people are using it for this purpose at least internally. When doing so, specific care should be taken to properly secure the private key(s) used for signing certificates. It is advisable to keep them in a secure HW storage such as a smart card or HSM and access them via a suitable engine or crypto provider.

- -

This command is effectively a single user command: no locking is done on the various files and attempts to run more than one openssl ca command on the same database can have unpredictable results.

- -

The copy_extensions option should be used with caution. If care is not taken then it can be a security risk. For example if a certificate request contains a basicConstraints extension with CA:TRUE and the copy_extensions value is set to copyall and the user does not spot this when the certificate is displayed then this will hand the requester a valid CA certificate. This situation can be avoided by setting copy_extensions to copy and including basicConstraints with CA:FALSE in the configuration file. Then if the request contains a basicConstraints extension it will be ignored.

- -

It is advisable to also include values for other extensions such as keyUsage to prevent a request supplying its own values.

- -

Additional restrictions can be placed on the CA certificate itself. For example if the CA certificate has:

- -
basicConstraints = CA:TRUE, pathlen:0
- -

then even if a certificate is issued with CA:TRUE it will not be valid.

- -

HISTORY

- -

Since OpenSSL 1.1.1, the program follows RFC5280. Specifically, certificate validity period (specified by any of -startdate, -enddate and -days) and CRL last/next update time (specified by any of -crl_lastupdate, -crl_nextupdate, -crldays, -crlhours and -crlsec) will be encoded as UTCTime if the dates are earlier than year 2049 (included), and as GeneralizedTime if the dates are in year 2050 or later.

- -

OpenSSL 1.1.1 introduced a new random generator (CSPRNG) with an improved seeding mechanism. The new seeding mechanism makes it unnecessary to define a RANDFILE for saving and restoring randomness. This option is retained mainly for compatibility reasons.

- -

The -section option was added in OpenSSL 3.0.0.

- -

The -multivalue-rdn option has become obsolete in OpenSSL 3.0.0 and has no effect.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

Since OpenSSL 3.2, generated certificates bear X.509 version 3, and key identifier extensions are included by default.

- -

SEE ALSO

- -

openssl(1), openssl-req(1), openssl-spkac(1), openssl-x509(1), CA.pl(1), config(5), x509v3_config(5)

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-ciphers.html b/openssl-install/share/doc/openssl/html/man1/openssl-ciphers.html deleted file mode 100644 index c586013a..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-ciphers.html +++ /dev/null @@ -1,857 +0,0 @@ - - - - -openssl-ciphers - - - - - - - - - - -

NAME

- -

openssl-ciphers - SSL cipher display and cipher list command

- -

SYNOPSIS

- -

openssl ciphers [-help] [-s] [-v] [-V] [-ssl3] [-tls1] [-tls1_1] [-tls1_2] [-tls1_3] [-s] [-psk] [-srp] [-stdname] [-convert name] [-ciphersuites val] [-provider name] [-provider-path path] [-propquery propq] [cipherlist]

- -

DESCRIPTION

- -

This command converts textual OpenSSL cipher lists into ordered SSL cipher preference lists. It can be used to determine the appropriate cipherlist.

- -

OPTIONS

- -
- -
-help
-
- -

Print a usage message.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-s
-
- -

Only list supported ciphers: those consistent with the security level, and minimum and maximum protocol version. This is closer to the actual cipher list an application will support.

- -

PSK and SRP ciphers are not enabled by default: they require -psk or -srp to enable them.

- -

It also does not change the default list of supported signature algorithms.

- -

On a server the list of supported ciphers might also exclude other ciphers depending on the configured certificates and presence of DH parameters.

- -

If this option is not used then all ciphers that match the cipherlist will be listed.

- -
-
-psk
-
- -

When combined with -s includes cipher suites which require PSK.

- -
-
-srp
-
- -

When combined with -s includes cipher suites which require SRP. This option is deprecated.

- -
-
-v
-
- -

Verbose output: For each cipher suite, list details as provided by SSL_CIPHER_description(3).

- -
-
-V
-
- -

Like -v, but include the official cipher suite values in hex.

- -
-
-tls1_3, -tls1_2, -tls1_1, -tls1, -ssl3
-
- -

In combination with the -s option, list the ciphers which could be used if the specified protocol were negotiated. Note that not all protocols and flags may be available, depending on how OpenSSL was built.

- -
-
-stdname
-
- -

Precede each cipher suite by its standard name.

- -
-
-convert name
-
- -

Convert a standard cipher name to its OpenSSL name.

- -
-
-ciphersuites val
-
- -

Sets the list of TLSv1.3 ciphersuites. This list will be combined with any TLSv1.2 and below ciphersuites that have been configured. The format for this list is a simple colon (":") separated list of TLSv1.3 ciphersuite names. By default this value is:

- -
TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256
- -
-
cipherlist
-
- -

A cipher list of TLSv1.2 and below ciphersuites to convert to a cipher preference list. This list will be combined with any TLSv1.3 ciphersuites that have been configured. If it is not included then the default cipher list will be used. The format is described below.

- -
-
- -

CIPHER LIST FORMAT

- -

The cipher list consists of one or more cipher strings separated by colons. Commas or spaces are also acceptable separators but colons are normally used.

- -

The cipher string may reference a cipher using its standard name from the IANA TLS Cipher Suites Registry (https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-parameters-4).

- -

The actual cipher string can take several different forms.

- -

It can consist of a single cipher suite such as RC4-SHA.

- -

It can represent a list of cipher suites containing a certain algorithm, or cipher suites of a certain type. For example SHA1 represents all ciphers suites using the digest algorithm SHA1 and SSLv3 represents all SSL v3 algorithms.

- -

Lists of cipher suites can be combined in a single cipher string using the + character. This is used as a logical and operation. For example SHA1+DES represents all cipher suites containing the SHA1 and the DES algorithms.

- -

Each cipher string can be optionally preceded by the characters !, - or +.

- -

If ! is used then the ciphers are permanently deleted from the list. The ciphers deleted can never reappear in the list even if they are explicitly stated.

- -

If - is used then the ciphers are deleted from the list, but some or all of the ciphers can be added again by later options.

- -

If + is used then the ciphers are moved to the end of the list. This option doesn't add any new ciphers it just moves matching existing ones.

- -

If none of these characters is present then the string is just interpreted as a list of ciphers to be appended to the current preference list. If the list includes any ciphers already present they will be ignored: that is they will not moved to the end of the list.

- -

The cipher string @STRENGTH can be used at any point to sort the current cipher list in order of encryption algorithm key length.

- -

The cipher string @SECLEVEL=n can be used at any point to set the security level to n, which should be a number between zero and five, inclusive. See SSL_CTX_set_security_level(3) for a description of what each level means.

- -

The cipher list can be prefixed with the DEFAULT keyword, which enables the default cipher list as defined below. Unlike cipher strings, this prefix may not be combined with other strings using + character. For example, DEFAULT+DES is not valid.

- -

The content of the default list is determined at compile time and normally corresponds to ALL:!COMPLEMENTOFDEFAULT:!eNULL.

- -

CIPHER STRINGS

- -

The following is a list of all permitted cipher strings and their meanings.

- -
- -
COMPLEMENTOFDEFAULT
-
- -

The ciphers included in ALL, but not enabled by default. Currently this includes all RC4 and anonymous ciphers. Note that this rule does not cover eNULL, which is not included by ALL (use COMPLEMENTOFALL if necessary). Note that RC4 based cipher suites are not built into OpenSSL by default (see the enable-weak-ssl-ciphers option to Configure).

- -
-
ALL
-
- -

All cipher suites except the eNULL ciphers (which must be explicitly enabled if needed). As of OpenSSL 1.0.0, the ALL cipher suites are sensibly ordered by default.

- -
-
COMPLEMENTOFALL
-
- -

The cipher suites not enabled by ALL, currently eNULL.

- -
-
HIGH
-
- -

"High" encryption cipher suites. This currently means those with key lengths larger than 128 bits, and some cipher suites with 128-bit keys.

- -
-
MEDIUM
-
- -

"Medium" encryption cipher suites, currently some of those using 128 bit encryption.

- -
-
LOW
-
- -

"Low" encryption cipher suites, currently those using 64 or 56 bit encryption algorithms but excluding export cipher suites. All these cipher suites have been removed as of OpenSSL 1.1.0.

- -
-
eNULL, NULL
-
- -

The "NULL" ciphers that is those offering no encryption. Because these offer no encryption at all and are a security risk they are not enabled via either the DEFAULT or ALL cipher strings. Be careful when building cipherlists out of lower-level primitives such as kRSA or aECDSA as these do overlap with the eNULL ciphers. When in doubt, include !eNULL in your cipherlist.

- -
-
aNULL
-
- -

The cipher suites offering no authentication. This is currently the anonymous DH algorithms and anonymous ECDH algorithms. These cipher suites are vulnerable to "man in the middle" attacks and so their use is discouraged. These are excluded from the DEFAULT ciphers, but included in the ALL ciphers. Be careful when building cipherlists out of lower-level primitives such as kDHE or AES as these do overlap with the aNULL ciphers. When in doubt, include !aNULL in your cipherlist.

- -
-
kRSA, aRSA, RSA
-
- -

Cipher suites using RSA key exchange or authentication. RSA is an alias for kRSA.

- -
-
kDHr, kDHd, kDH
-
- -

Cipher suites using static DH key agreement and DH certificates signed by CAs with RSA and DSS keys or either respectively. All these cipher suites have been removed in OpenSSL 1.1.0.

- -
-
kDHE, kEDH, DH
-
- -

Cipher suites using ephemeral DH key agreement, including anonymous cipher suites.

- -
-
DHE, EDH
-
- -

Cipher suites using authenticated ephemeral DH key agreement.

- -
-
ADH
-
- -

Anonymous DH cipher suites, note that this does not include anonymous Elliptic Curve DH (ECDH) cipher suites.

- -
-
kEECDH, kECDHE, ECDH
-
- -

Cipher suites using ephemeral ECDH key agreement, including anonymous cipher suites.

- -
-
ECDHE, EECDH
-
- -

Cipher suites using authenticated ephemeral ECDH key agreement.

- -
-
AECDH
-
- -

Anonymous Elliptic Curve Diffie-Hellman cipher suites.

- -
-
aDSS, DSS
-
- -

Cipher suites using DSS authentication, i.e. the certificates carry DSS keys.

- -
-
aDH
-
- -

Cipher suites effectively using DH authentication, i.e. the certificates carry DH keys. All these cipher suites have been removed in OpenSSL 1.1.0.

- -
-
aECDSA, ECDSA
-
- -

Cipher suites using ECDSA authentication, i.e. the certificates carry ECDSA keys.

- -
-
TLSv1.2, TLSv1.0, SSLv3
-
- -

Lists cipher suites which are only supported in at least TLS v1.2, TLS v1.0 or SSL v3.0 respectively. Note: there are no cipher suites specific to TLS v1.1. Since this is only the minimum version, if, for example, TLSv1.0 is negotiated then both TLSv1.0 and SSLv3.0 cipher suites are available.

- -

Note: these cipher strings do not change the negotiated version of SSL or TLS, they only affect the list of available cipher suites.

- -
-
AES128, AES256, AES
-
- -

cipher suites using 128 bit AES, 256 bit AES or either 128 or 256 bit AES.

- -
-
AESGCM
-
- -

AES in Galois Counter Mode (GCM): these cipher suites are only supported in TLS v1.2.

- -
-
AESCCM, AESCCM8
-
- -

AES in Cipher Block Chaining - Message Authentication Mode (CCM): these cipher suites are only supported in TLS v1.2. AESCCM references CCM cipher suites using both 16 and 8 octet Integrity Check Value (ICV) while AESCCM8 only references 8 octet ICV.

- -
-
ARIA128, ARIA256, ARIA
-
- -

Cipher suites using 128 bit ARIA, 256 bit ARIA or either 128 or 256 bit ARIA.

- -
-
CAMELLIA128, CAMELLIA256, CAMELLIA
-
- -

Cipher suites using 128 bit CAMELLIA, 256 bit CAMELLIA or either 128 or 256 bit CAMELLIA.

- -
-
CHACHA20
-
- -

Cipher suites using ChaCha20.

- -
-
3DES
-
- -

Cipher suites using triple DES.

- -
-
DES
-
- -

Cipher suites using DES (not triple DES). All these cipher suites have been removed in OpenSSL 1.1.0.

- -
-
RC4
-
- -

Cipher suites using RC4.

- -
-
RC2
-
- -

Cipher suites using RC2.

- -
-
IDEA
-
- -

Cipher suites using IDEA.

- -
-
SEED
-
- -

Cipher suites using SEED.

- -
-
MD5
-
- -

Cipher suites using MD5.

- -
-
SHA1, SHA
-
- -

Cipher suites using SHA1.

- -
-
SHA256, SHA384
-
- -

Cipher suites using SHA256 or SHA384.

- -
-
aGOST
-
- -

Cipher suites using GOST R 34.10 (either 2001 or 94) for authentication (needs an engine supporting GOST algorithms).

- -
-
aGOST01
-
- -

Cipher suites using GOST R 34.10-2001 authentication.

- -
-
kGOST
-
- -

Cipher suites, using VKO 34.10 key exchange, specified in the RFC 4357.

- -
-
GOST94
-
- -

Cipher suites, using HMAC based on GOST R 34.11-94.

- -
-
GOST89MAC
-
- -

Cipher suites using GOST 28147-89 MAC instead of HMAC.

- -
-
PSK
-
- -

All cipher suites using pre-shared keys (PSK).

- -
-
kPSK, kECDHEPSK, kDHEPSK, kRSAPSK
-
- -

Cipher suites using PSK key exchange, ECDHE_PSK, DHE_PSK or RSA_PSK.

- -
-
aPSK
-
- -

Cipher suites using PSK authentication (currently all PSK modes apart from RSA_PSK).

- -
-
SUITEB128, SUITEB128ONLY, SUITEB192
-
- -

Enables suite B mode of operation using 128 (permitting 192 bit mode by peer) 128 bit (not permitting 192 bit by peer) or 192 bit level of security respectively. If used these cipherstrings should appear first in the cipher list and anything after them is ignored. Setting Suite B mode has additional consequences required to comply with RFC6460. In particular the supported signature algorithms is reduced to support only ECDSA and SHA256 or SHA384, only the elliptic curves P-256 and P-384 can be used and only the two suite B compliant cipher suites (ECDHE-ECDSA-AES128-GCM-SHA256 and ECDHE-ECDSA-AES256-GCM-SHA384) are permissible.

- -
-
CBC
-
- -

All cipher suites using encryption algorithm in Cipher Block Chaining (CBC) mode. These cipher suites are only supported in TLS v1.2 and earlier. Currently it's an alias for the following cipherstrings: SSL_DES, SSL_3DES, SSL_RC2, SSL_IDEA, SSL_AES128, SSL_AES256, SSL_CAMELLIA128, SSL_CAMELLIA256, SSL_SEED.

- -
-
- -

CIPHER SUITE NAMES

- -

The following lists give the standard SSL or TLS cipher suites names from the relevant specification and their OpenSSL equivalents. You can use either standard names or OpenSSL names in cipher lists, or a mix of both.

- -

It should be noted, that several cipher suite names do not include the authentication used, e.g. DES-CBC3-SHA. In these cases, RSA authentication is used.

- -

SSL v3.0 cipher suites

- -
SSL_RSA_WITH_NULL_MD5                   NULL-MD5
-SSL_RSA_WITH_NULL_SHA                   NULL-SHA
-SSL_RSA_WITH_RC4_128_MD5                RC4-MD5
-SSL_RSA_WITH_RC4_128_SHA                RC4-SHA
-SSL_RSA_WITH_IDEA_CBC_SHA               IDEA-CBC-SHA
-SSL_RSA_WITH_3DES_EDE_CBC_SHA           DES-CBC3-SHA
-
-SSL_DH_DSS_WITH_3DES_EDE_CBC_SHA        DH-DSS-DES-CBC3-SHA
-SSL_DH_RSA_WITH_3DES_EDE_CBC_SHA        DH-RSA-DES-CBC3-SHA
-SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA       DHE-DSS-DES-CBC3-SHA
-SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA       DHE-RSA-DES-CBC3-SHA
-
-SSL_DH_anon_WITH_RC4_128_MD5            ADH-RC4-MD5
-SSL_DH_anon_WITH_3DES_EDE_CBC_SHA       ADH-DES-CBC3-SHA
-
-SSL_FORTEZZA_KEA_WITH_NULL_SHA          Not implemented.
-SSL_FORTEZZA_KEA_WITH_FORTEZZA_CBC_SHA  Not implemented.
-SSL_FORTEZZA_KEA_WITH_RC4_128_SHA       Not implemented.
- -

TLS v1.0 cipher suites

- -
TLS_RSA_WITH_NULL_MD5                   NULL-MD5
-TLS_RSA_WITH_NULL_SHA                   NULL-SHA
-TLS_RSA_WITH_RC4_128_MD5                RC4-MD5
-TLS_RSA_WITH_RC4_128_SHA                RC4-SHA
-TLS_RSA_WITH_IDEA_CBC_SHA               IDEA-CBC-SHA
-TLS_RSA_WITH_3DES_EDE_CBC_SHA           DES-CBC3-SHA
-
-TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA        Not implemented.
-TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA        Not implemented.
-TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA       DHE-DSS-DES-CBC3-SHA
-TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA       DHE-RSA-DES-CBC3-SHA
-
-TLS_DH_anon_WITH_RC4_128_MD5            ADH-RC4-MD5
-TLS_DH_anon_WITH_3DES_EDE_CBC_SHA       ADH-DES-CBC3-SHA
- -

AES cipher suites from RFC3268, extending TLS v1.0

- -
TLS_RSA_WITH_AES_128_CBC_SHA            AES128-SHA
-TLS_RSA_WITH_AES_256_CBC_SHA            AES256-SHA
-
-TLS_DH_DSS_WITH_AES_128_CBC_SHA         DH-DSS-AES128-SHA
-TLS_DH_DSS_WITH_AES_256_CBC_SHA         DH-DSS-AES256-SHA
-TLS_DH_RSA_WITH_AES_128_CBC_SHA         DH-RSA-AES128-SHA
-TLS_DH_RSA_WITH_AES_256_CBC_SHA         DH-RSA-AES256-SHA
-
-TLS_DHE_DSS_WITH_AES_128_CBC_SHA        DHE-DSS-AES128-SHA
-TLS_DHE_DSS_WITH_AES_256_CBC_SHA        DHE-DSS-AES256-SHA
-TLS_DHE_RSA_WITH_AES_128_CBC_SHA        DHE-RSA-AES128-SHA
-TLS_DHE_RSA_WITH_AES_256_CBC_SHA        DHE-RSA-AES256-SHA
-
-TLS_DH_anon_WITH_AES_128_CBC_SHA        ADH-AES128-SHA
-TLS_DH_anon_WITH_AES_256_CBC_SHA        ADH-AES256-SHA
- -

Camellia cipher suites from RFC4132, extending TLS v1.0

- -
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA      CAMELLIA128-SHA
-TLS_RSA_WITH_CAMELLIA_256_CBC_SHA      CAMELLIA256-SHA
-
-TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA   DH-DSS-CAMELLIA128-SHA
-TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA   DH-DSS-CAMELLIA256-SHA
-TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA   DH-RSA-CAMELLIA128-SHA
-TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA   DH-RSA-CAMELLIA256-SHA
-
-TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA  DHE-DSS-CAMELLIA128-SHA
-TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA  DHE-DSS-CAMELLIA256-SHA
-TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA  DHE-RSA-CAMELLIA128-SHA
-TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA  DHE-RSA-CAMELLIA256-SHA
-
-TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA  ADH-CAMELLIA128-SHA
-TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA  ADH-CAMELLIA256-SHA
- -

SEED cipher suites from RFC4162, extending TLS v1.0

- -
TLS_RSA_WITH_SEED_CBC_SHA              SEED-SHA
-
-TLS_DH_DSS_WITH_SEED_CBC_SHA           DH-DSS-SEED-SHA
-TLS_DH_RSA_WITH_SEED_CBC_SHA           DH-RSA-SEED-SHA
-
-TLS_DHE_DSS_WITH_SEED_CBC_SHA          DHE-DSS-SEED-SHA
-TLS_DHE_RSA_WITH_SEED_CBC_SHA          DHE-RSA-SEED-SHA
-
-TLS_DH_anon_WITH_SEED_CBC_SHA          ADH-SEED-SHA
- -

GOST cipher suites from draft-chudov-cryptopro-cptls, extending TLS v1.0

- -

Note: these ciphers require an engine which including GOST cryptographic algorithms, such as the gost engine, which isn't part of the OpenSSL distribution.

- -
TLS_GOSTR341094_WITH_28147_CNT_IMIT GOST94-GOST89-GOST89
-TLS_GOSTR341001_WITH_28147_CNT_IMIT GOST2001-GOST89-GOST89
-TLS_GOSTR341094_WITH_NULL_GOSTR3411 GOST94-NULL-GOST94
-TLS_GOSTR341001_WITH_NULL_GOSTR3411 GOST2001-NULL-GOST94
- -

GOST cipher suites, extending TLS v1.2

- -

Note: these ciphers require an engine which including GOST cryptographic algorithms, such as the gost engine, which isn't part of the OpenSSL distribution.

- -
TLS_GOSTR341112_256_WITH_28147_CNT_IMIT GOST2012-GOST8912-GOST8912
-TLS_GOSTR341112_256_WITH_NULL_GOSTR3411 GOST2012-NULL-GOST12
- -

Note: GOST2012-GOST8912-GOST8912 is an alias for two ciphers ID old LEGACY-GOST2012-GOST8912-GOST8912 and new IANA-GOST2012-GOST8912-GOST8912

- -

Additional Export 1024 and other cipher suites

- -

Note: these ciphers can also be used in SSL v3.

- -
TLS_DHE_DSS_WITH_RC4_128_SHA            DHE-DSS-RC4-SHA
- -

Elliptic curve cipher suites

- -
TLS_ECDHE_RSA_WITH_NULL_SHA             ECDHE-RSA-NULL-SHA
-TLS_ECDHE_RSA_WITH_RC4_128_SHA          ECDHE-RSA-RC4-SHA
-TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA     ECDHE-RSA-DES-CBC3-SHA
-TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA      ECDHE-RSA-AES128-SHA
-TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA      ECDHE-RSA-AES256-SHA
-
-TLS_ECDHE_ECDSA_WITH_NULL_SHA           ECDHE-ECDSA-NULL-SHA
-TLS_ECDHE_ECDSA_WITH_RC4_128_SHA        ECDHE-ECDSA-RC4-SHA
-TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA   ECDHE-ECDSA-DES-CBC3-SHA
-TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA    ECDHE-ECDSA-AES128-SHA
-TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA    ECDHE-ECDSA-AES256-SHA
-
-TLS_ECDH_anon_WITH_NULL_SHA             AECDH-NULL-SHA
-TLS_ECDH_anon_WITH_RC4_128_SHA          AECDH-RC4-SHA
-TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA     AECDH-DES-CBC3-SHA
-TLS_ECDH_anon_WITH_AES_128_CBC_SHA      AECDH-AES128-SHA
-TLS_ECDH_anon_WITH_AES_256_CBC_SHA      AECDH-AES256-SHA
- -

TLS v1.2 cipher suites

- -
TLS_RSA_WITH_NULL_SHA256                  NULL-SHA256
-
-TLS_RSA_WITH_AES_128_CBC_SHA256           AES128-SHA256
-TLS_RSA_WITH_AES_256_CBC_SHA256           AES256-SHA256
-TLS_RSA_WITH_AES_128_GCM_SHA256           AES128-GCM-SHA256
-TLS_RSA_WITH_AES_256_GCM_SHA384           AES256-GCM-SHA384
-
-TLS_DH_RSA_WITH_AES_128_CBC_SHA256        DH-RSA-AES128-SHA256
-TLS_DH_RSA_WITH_AES_256_CBC_SHA256        DH-RSA-AES256-SHA256
-TLS_DH_RSA_WITH_AES_128_GCM_SHA256        DH-RSA-AES128-GCM-SHA256
-TLS_DH_RSA_WITH_AES_256_GCM_SHA384        DH-RSA-AES256-GCM-SHA384
-
-TLS_DH_DSS_WITH_AES_128_CBC_SHA256        DH-DSS-AES128-SHA256
-TLS_DH_DSS_WITH_AES_256_CBC_SHA256        DH-DSS-AES256-SHA256
-TLS_DH_DSS_WITH_AES_128_GCM_SHA256        DH-DSS-AES128-GCM-SHA256
-TLS_DH_DSS_WITH_AES_256_GCM_SHA384        DH-DSS-AES256-GCM-SHA384
-
-TLS_DHE_RSA_WITH_AES_128_CBC_SHA256       DHE-RSA-AES128-SHA256
-TLS_DHE_RSA_WITH_AES_256_CBC_SHA256       DHE-RSA-AES256-SHA256
-TLS_DHE_RSA_WITH_AES_128_GCM_SHA256       DHE-RSA-AES128-GCM-SHA256
-TLS_DHE_RSA_WITH_AES_256_GCM_SHA384       DHE-RSA-AES256-GCM-SHA384
-
-TLS_DHE_DSS_WITH_AES_128_CBC_SHA256       DHE-DSS-AES128-SHA256
-TLS_DHE_DSS_WITH_AES_256_CBC_SHA256       DHE-DSS-AES256-SHA256
-TLS_DHE_DSS_WITH_AES_128_GCM_SHA256       DHE-DSS-AES128-GCM-SHA256
-TLS_DHE_DSS_WITH_AES_256_GCM_SHA384       DHE-DSS-AES256-GCM-SHA384
-
-TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256     ECDHE-RSA-AES128-SHA256
-TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384     ECDHE-RSA-AES256-SHA384
-TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256     ECDHE-RSA-AES128-GCM-SHA256
-TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384     ECDHE-RSA-AES256-GCM-SHA384
-
-TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256   ECDHE-ECDSA-AES128-SHA256
-TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384   ECDHE-ECDSA-AES256-SHA384
-TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256   ECDHE-ECDSA-AES128-GCM-SHA256
-TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384   ECDHE-ECDSA-AES256-GCM-SHA384
-
-TLS_DH_anon_WITH_AES_128_CBC_SHA256       ADH-AES128-SHA256
-TLS_DH_anon_WITH_AES_256_CBC_SHA256       ADH-AES256-SHA256
-TLS_DH_anon_WITH_AES_128_GCM_SHA256       ADH-AES128-GCM-SHA256
-TLS_DH_anon_WITH_AES_256_GCM_SHA384       ADH-AES256-GCM-SHA384
-
-RSA_WITH_AES_128_CCM                      AES128-CCM
-RSA_WITH_AES_256_CCM                      AES256-CCM
-DHE_RSA_WITH_AES_128_CCM                  DHE-RSA-AES128-CCM
-DHE_RSA_WITH_AES_256_CCM                  DHE-RSA-AES256-CCM
-RSA_WITH_AES_128_CCM_8                    AES128-CCM8
-RSA_WITH_AES_256_CCM_8                    AES256-CCM8
-DHE_RSA_WITH_AES_128_CCM_8                DHE-RSA-AES128-CCM8
-DHE_RSA_WITH_AES_256_CCM_8                DHE-RSA-AES256-CCM8
-ECDHE_ECDSA_WITH_AES_128_CCM              ECDHE-ECDSA-AES128-CCM
-ECDHE_ECDSA_WITH_AES_256_CCM              ECDHE-ECDSA-AES256-CCM
-ECDHE_ECDSA_WITH_AES_128_CCM_8            ECDHE-ECDSA-AES128-CCM8
-ECDHE_ECDSA_WITH_AES_256_CCM_8            ECDHE-ECDSA-AES256-CCM8
- -

ARIA cipher suites from RFC6209, extending TLS v1.2

- -

Note: the CBC modes mentioned in this RFC are not supported.

- -
TLS_RSA_WITH_ARIA_128_GCM_SHA256          ARIA128-GCM-SHA256
-TLS_RSA_WITH_ARIA_256_GCM_SHA384          ARIA256-GCM-SHA384
-TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256      DHE-RSA-ARIA128-GCM-SHA256
-TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384      DHE-RSA-ARIA256-GCM-SHA384
-TLS_DHE_DSS_WITH_ARIA_128_GCM_SHA256      DHE-DSS-ARIA128-GCM-SHA256
-TLS_DHE_DSS_WITH_ARIA_256_GCM_SHA384      DHE-DSS-ARIA256-GCM-SHA384
-TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256  ECDHE-ECDSA-ARIA128-GCM-SHA256
-TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384  ECDHE-ECDSA-ARIA256-GCM-SHA384
-TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256    ECDHE-ARIA128-GCM-SHA256
-TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384    ECDHE-ARIA256-GCM-SHA384
-TLS_PSK_WITH_ARIA_128_GCM_SHA256          PSK-ARIA128-GCM-SHA256
-TLS_PSK_WITH_ARIA_256_GCM_SHA384          PSK-ARIA256-GCM-SHA384
-TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256      DHE-PSK-ARIA128-GCM-SHA256
-TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384      DHE-PSK-ARIA256-GCM-SHA384
-TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256      RSA-PSK-ARIA128-GCM-SHA256
-TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384      RSA-PSK-ARIA256-GCM-SHA384
- -

Camellia HMAC-Based cipher suites from RFC6367, extending TLS v1.2

- -
TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-ECDSA-CAMELLIA128-SHA256
-TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-ECDSA-CAMELLIA256-SHA384
-TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256   ECDHE-RSA-CAMELLIA128-SHA256
-TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384   ECDHE-RSA-CAMELLIA256-SHA384
- -

Pre-shared keying (PSK) cipher suites

- -
PSK_WITH_NULL_SHA                         PSK-NULL-SHA
-DHE_PSK_WITH_NULL_SHA                     DHE-PSK-NULL-SHA
-RSA_PSK_WITH_NULL_SHA                     RSA-PSK-NULL-SHA
-
-PSK_WITH_RC4_128_SHA                      PSK-RC4-SHA
-PSK_WITH_3DES_EDE_CBC_SHA                 PSK-3DES-EDE-CBC-SHA
-PSK_WITH_AES_128_CBC_SHA                  PSK-AES128-CBC-SHA
-PSK_WITH_AES_256_CBC_SHA                  PSK-AES256-CBC-SHA
-
-DHE_PSK_WITH_RC4_128_SHA                  DHE-PSK-RC4-SHA
-DHE_PSK_WITH_3DES_EDE_CBC_SHA             DHE-PSK-3DES-EDE-CBC-SHA
-DHE_PSK_WITH_AES_128_CBC_SHA              DHE-PSK-AES128-CBC-SHA
-DHE_PSK_WITH_AES_256_CBC_SHA              DHE-PSK-AES256-CBC-SHA
-
-RSA_PSK_WITH_RC4_128_SHA                  RSA-PSK-RC4-SHA
-RSA_PSK_WITH_3DES_EDE_CBC_SHA             RSA-PSK-3DES-EDE-CBC-SHA
-RSA_PSK_WITH_AES_128_CBC_SHA              RSA-PSK-AES128-CBC-SHA
-RSA_PSK_WITH_AES_256_CBC_SHA              RSA-PSK-AES256-CBC-SHA
-
-PSK_WITH_AES_128_GCM_SHA256               PSK-AES128-GCM-SHA256
-PSK_WITH_AES_256_GCM_SHA384               PSK-AES256-GCM-SHA384
-DHE_PSK_WITH_AES_128_GCM_SHA256           DHE-PSK-AES128-GCM-SHA256
-DHE_PSK_WITH_AES_256_GCM_SHA384           DHE-PSK-AES256-GCM-SHA384
-RSA_PSK_WITH_AES_128_GCM_SHA256           RSA-PSK-AES128-GCM-SHA256
-RSA_PSK_WITH_AES_256_GCM_SHA384           RSA-PSK-AES256-GCM-SHA384
-
-PSK_WITH_AES_128_CBC_SHA256               PSK-AES128-CBC-SHA256
-PSK_WITH_AES_256_CBC_SHA384               PSK-AES256-CBC-SHA384
-PSK_WITH_NULL_SHA256                      PSK-NULL-SHA256
-PSK_WITH_NULL_SHA384                      PSK-NULL-SHA384
-DHE_PSK_WITH_AES_128_CBC_SHA256           DHE-PSK-AES128-CBC-SHA256
-DHE_PSK_WITH_AES_256_CBC_SHA384           DHE-PSK-AES256-CBC-SHA384
-DHE_PSK_WITH_NULL_SHA256                  DHE-PSK-NULL-SHA256
-DHE_PSK_WITH_NULL_SHA384                  DHE-PSK-NULL-SHA384
-RSA_PSK_WITH_AES_128_CBC_SHA256           RSA-PSK-AES128-CBC-SHA256
-RSA_PSK_WITH_AES_256_CBC_SHA384           RSA-PSK-AES256-CBC-SHA384
-RSA_PSK_WITH_NULL_SHA256                  RSA-PSK-NULL-SHA256
-RSA_PSK_WITH_NULL_SHA384                  RSA-PSK-NULL-SHA384
-PSK_WITH_AES_128_GCM_SHA256               PSK-AES128-GCM-SHA256
-PSK_WITH_AES_256_GCM_SHA384               PSK-AES256-GCM-SHA384
-
-ECDHE_PSK_WITH_RC4_128_SHA                ECDHE-PSK-RC4-SHA
-ECDHE_PSK_WITH_3DES_EDE_CBC_SHA           ECDHE-PSK-3DES-EDE-CBC-SHA
-ECDHE_PSK_WITH_AES_128_CBC_SHA            ECDHE-PSK-AES128-CBC-SHA
-ECDHE_PSK_WITH_AES_256_CBC_SHA            ECDHE-PSK-AES256-CBC-SHA
-ECDHE_PSK_WITH_AES_128_CBC_SHA256         ECDHE-PSK-AES128-CBC-SHA256
-ECDHE_PSK_WITH_AES_256_CBC_SHA384         ECDHE-PSK-AES256-CBC-SHA384
-ECDHE_PSK_WITH_NULL_SHA                   ECDHE-PSK-NULL-SHA
-ECDHE_PSK_WITH_NULL_SHA256                ECDHE-PSK-NULL-SHA256
-ECDHE_PSK_WITH_NULL_SHA384                ECDHE-PSK-NULL-SHA384
-
-PSK_WITH_CAMELLIA_128_CBC_SHA256          PSK-CAMELLIA128-SHA256
-PSK_WITH_CAMELLIA_256_CBC_SHA384          PSK-CAMELLIA256-SHA384
-
-DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256      DHE-PSK-CAMELLIA128-SHA256
-DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384      DHE-PSK-CAMELLIA256-SHA384
-
-RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256      RSA-PSK-CAMELLIA128-SHA256
-RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384      RSA-PSK-CAMELLIA256-SHA384
-
-ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256    ECDHE-PSK-CAMELLIA128-SHA256
-ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384    ECDHE-PSK-CAMELLIA256-SHA384
-
-PSK_WITH_AES_128_CCM                      PSK-AES128-CCM
-PSK_WITH_AES_256_CCM                      PSK-AES256-CCM
-DHE_PSK_WITH_AES_128_CCM                  DHE-PSK-AES128-CCM
-DHE_PSK_WITH_AES_256_CCM                  DHE-PSK-AES256-CCM
-PSK_WITH_AES_128_CCM_8                    PSK-AES128-CCM8
-PSK_WITH_AES_256_CCM_8                    PSK-AES256-CCM8
-DHE_PSK_WITH_AES_128_CCM_8                DHE-PSK-AES128-CCM8
-DHE_PSK_WITH_AES_256_CCM_8                DHE-PSK-AES256-CCM8
- -

ChaCha20-Poly1305 cipher suites, extending TLS v1.2

- -
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256      ECDHE-RSA-CHACHA20-POLY1305
-TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256    ECDHE-ECDSA-CHACHA20-POLY1305
-TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256        DHE-RSA-CHACHA20-POLY1305
-TLS_PSK_WITH_CHACHA20_POLY1305_SHA256            PSK-CHACHA20-POLY1305
-TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256      ECDHE-PSK-CHACHA20-POLY1305
-TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256        DHE-PSK-CHACHA20-POLY1305
-TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256        RSA-PSK-CHACHA20-POLY1305
- -

TLS v1.3 cipher suites

- -
TLS_AES_128_GCM_SHA256                     TLS_AES_128_GCM_SHA256
-TLS_AES_256_GCM_SHA384                     TLS_AES_256_GCM_SHA384
-TLS_CHACHA20_POLY1305_SHA256               TLS_CHACHA20_POLY1305_SHA256
-TLS_AES_128_CCM_SHA256                     TLS_AES_128_CCM_SHA256
-TLS_AES_128_CCM_8_SHA256                   TLS_AES_128_CCM_8_SHA256
- -

TLS v1.3 integrity-only cipher suites according to RFC 9150

- -
TLS_SHA256_SHA256          TLS_SHA256_SHA256
-TLS_SHA384_SHA384          TLS_SHA384_SHA384
- -

Note: these ciphers are purely HMAC based and do not provide any confidentiality and thus are disabled by default. These ciphers are only available at security level 0.

- -

Older names used by OpenSSL

- -

The following names are accepted by older releases:

- -
SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA    EDH-RSA-DES-CBC3-SHA (DHE-RSA-DES-CBC3-SHA)
-SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA    EDH-DSS-DES-CBC3-SHA (DHE-DSS-DES-CBC3-SHA)
- -

NOTES

- -

Some compiled versions of OpenSSL may not include all the ciphers listed here because some ciphers were excluded at compile time.

- -

EXAMPLES

- -

Verbose listing of all OpenSSL ciphers including NULL ciphers:

- -
openssl ciphers -v 'ALL:eNULL'
- -

Include all ciphers except NULL and anonymous DH then sort by strength:

- -
openssl ciphers -v 'ALL:!ADH:@STRENGTH'
- -

Include all ciphers except ones with no encryption (eNULL) or no authentication (aNULL):

- -
openssl ciphers -v 'ALL:!aNULL'
- -

Include only 3DES ciphers and then place RSA ciphers last:

- -
openssl ciphers -v '3DES:+RSA'
- -

Include all RC4 ciphers but leave out those without authentication:

- -
openssl ciphers -v 'RC4:!COMPLEMENTOFDEFAULT'
- -

Include all ciphers with RSA authentication but leave out ciphers without encryption.

- -
openssl ciphers -v 'RSA:!COMPLEMENTOFALL'
- -

Set security level to 2 and display all ciphers consistent with level 2:

- -
openssl ciphers -s -v 'ALL:@SECLEVEL=2'
- -

SEE ALSO

- -

openssl(1), openssl-s_client(1), openssl-s_server(1), ssl(7)

- -

HISTORY

- -

The -V option was added in OpenSSL 1.0.0.

- -

The -stdname is only available if OpenSSL is built with tracing enabled (enable-ssl-trace argument to Configure) before OpenSSL 1.1.1.

- -

The -convert option was added in OpenSSL 1.1.1.

- -

Support for standard IANA names in cipher lists was added in OpenSSL 3.2.0.

- -

The support for TLS v1.3 integrity-only cipher suites was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-cmds.html b/openssl-install/share/doc/openssl/html/man1/openssl-cmds.html deleted file mode 100644 index cf8b8c70..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-cmds.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -openssl-cmds - - - - - - - - - - -

NAME

- -

asn1parse, ca, ciphers, cmp, cms, crl, crl2pkcs7, dgst, dhparam, dsa, dsaparam, ec, ecparam, enc, engine, errstr, gendsa, genpkey, genrsa, info, kdf, mac, nseq, ocsp, passwd, pkcs12, pkcs7, pkcs8, pkey, pkeyparam, pkeyutl, prime, rand, rehash, req, rsa, rsautl, s_client, s_server, s_time, sess_id, smime, speed, spkac, srp, storeutl, ts, verify, version, x509 - OpenSSL application commands

- -

SYNOPSIS

- -

openssl cmd -help | [-option | -option arg] ... [arg] ...

- -

DESCRIPTION

- -

Every cmd listed above is a (sub-)command of the openssl(1) application. It has its own detailed manual page at openssl-cmd(1). For example, to view the manual page for the openssl dgst command, type man openssl-dgst.

- -

OPTIONS

- -

Among others, every subcommand has a help option.

- -
- -
-help
-
- -

Print out a usage message for the subcommand.

- -
-
- -

SEE ALSO

- -

openssl(1), openssl-asn1parse(1), openssl-ca(1), openssl-ciphers(1), openssl-cmp(1), openssl-cms(1), openssl-crl(1), openssl-crl2pkcs7(1), openssl-dgst(1), openssl-dhparam(1), openssl-dsa(1), openssl-dsaparam(1), openssl-ec(1), openssl-ecparam(1), openssl-enc(1), openssl-engine(1), openssl-errstr(1), openssl-gendsa(1), openssl-genpkey(1), openssl-genrsa(1), openssl-info(1), openssl-kdf(1), openssl-mac(1), openssl-nseq(1), openssl-ocsp(1), openssl-passwd(1), openssl-pkcs12(1), openssl-pkcs7(1), openssl-pkcs8(1), openssl-pkey(1), openssl-pkeyparam(1), openssl-pkeyutl(1), openssl-prime(1), openssl-rand(1), openssl-rehash(1), openssl-req(1), openssl-rsa(1), openssl-rsautl(1), openssl-s_client(1), openssl-s_server(1), openssl-s_time(1), openssl-sess_id(1), openssl-smime(1), openssl-speed(1), openssl-spkac(1), openssl-srp(1), openssl-storeutl(1), openssl-ts(1), openssl-verify(1), openssl-version(1), openssl-x509(1),

- -

HISTORY

- -

Initially, the manual page entry for the openssl cmd command used to be available at cmd(1). Later, the alias openssl-cmd(1) was introduced, which made it easier to group the openssl commands using the apropos(1) command or the shell's tab completion.

- -

In order to reduce cluttering of the global manual page namespace, the manual page entries without the 'openssl-' prefix have been deprecated in OpenSSL 3.0 and will be removed in OpenSSL 4.0.

- -

COPYRIGHT

- -

Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-cmp.html b/openssl-install/share/doc/openssl/html/man1/openssl-cmp.html deleted file mode 100644 index 0b18e2c2..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-cmp.html +++ /dev/null @@ -1,1299 +0,0 @@ - - - - -openssl-cmp - - - - - - - - - - -

NAME

- -

openssl-cmp - Certificate Management Protocol (CMP, RFC 4210) application

- -

SYNOPSIS

- -

openssl cmp [-help] [-config filename] [-section names] [-verbosity level]

- -

Generic message options:

- -

[-cmd ir|cr|kur|p10cr|rr|genm] [-infotype name] [-profile name] [-geninfo values] [-template filename] [-keyspec filename]

- -

Certificate enrollment options:

- -

[-newkey filename|uri] [-newkeypass arg] [-subject name] [-days number] [-reqexts name] [-sans spec] [-san_nodefault] [-policies name] [-policy_oids names] [-policy_oids_critical] [-popo number] [-csr filename] [-out_trusted filenames|uris] [-implicit_confirm] [-disable_confirm] [-certout filename] [-chainout filename]

- -

Certificate enrollment and revocation options:

- -

[-oldcert filename|uri] [-issuer name] [-serial number] [-revreason number]

- -

Message transfer options:

- -

[-server [http[s]://][userinfo@]host[:port][/path][?query][#fragment]] [-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]] [-no_proxy addresses] [-recipient name] [-path remote_path] [-keep_alive value] [-msg_timeout seconds] [-total_timeout seconds]

- -

Server authentication options:

- -

[-trusted filenames|uris] [-untrusted filenames|uris] [-srvcert filename|uri] [-expect_sender name] [-ignore_keyusage] [-unprotected_errors] [-no_cache_extracerts] [-srvcertout filename] [-extracertsout filename] [-cacertsout filename] [-oldwithold filename] [-newwithnew filename] [-newwithold filename] [-oldwithnew filename] [-crlcert filename] [-oldcrl filename] [-crlout filename]

- -

Client authentication and protection options:

- -

[-ref value] [-secret arg] [-cert filename|uri] [-own_trusted filenames|uris] [-key filename|uri] [-keypass arg] [-digest name] [-mac name] [-extracerts filenames|uris] [-unprotected_requests]

- -

Credentials format options:

- -

[-certform PEM|DER] [-crlform PEM|DER] [-keyform PEM|DER|P12|ENGINE] [-otherpass arg] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

Random state options:

- -

[-rand files] [-writerand file]

- -

TLS connection options:

- -

[-tls_used] [-tls_cert filename|uri] [-tls_key filename|uri] [-tls_keypass arg] [-tls_extra filenames|uris] [-tls_trusted filenames|uris] [-tls_host name]

- -

Client-side debugging options:

- -

[-batch] [-repeat number] [-reqin filenames] [-reqin_new_tid] [-reqout filenames] [-reqout_only filename] [-rspin filenames] [-rspout filenames] [-use_mock_srv]

- -

Mock server options:

- -

[-port number] [-max_msgs number] [-srv_ref value] [-srv_secret arg] [-srv_cert filename|uri] [-srv_key filename|uri] [-srv_keypass arg] [-srv_trusted filenames|uris] [-srv_untrusted filenames|uris] [-ref_cert filename|uri] [-rsp_cert filename|uri] [-rsp_crl filename|uri] [-rsp_extracerts filenames|uris] [-rsp_capubs filenames|uris] [-rsp_newwithnew filename|uri] [-rsp_newwithold filename|uri] [-rsp_oldwithnew filename|uri] [-poll_count number] [-check_after number] [-grant_implicitconf] [-pkistatus number] [-failure number] [-failurebits number] [-statusstring arg] [-send_error] [-send_unprotected] [-send_unprot_err] [-accept_unprotected] [-accept_unprot_err] [-accept_raverified]

- -

Certificate verification options, for both CMP and TLS:

- -

[-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks]

- -

DESCRIPTION

- -

The cmp command is a client implementation for the Certificate Management Protocol (CMP) as defined in RFC4210. It can be used to request certificates from a CA server, update their certificates, request certificates to be revoked, and perform other types of CMP requests.

- -

OPTIONS

- -
- -
-help
-
- -

Display a summary of all options

- -
-
-config filename
-
- -

Configuration file to use. An empty string "" means none. Default filename is from the environment variable OPENSSL_CONF.

- -
-
-section names
-
- -

Section(s) to use within config file defining CMP options. An empty string "" means no specific section. Default is cmp.

- -

Multiple section names may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Contents of sections named later may override contents of sections named before. In any case, as usual, the [default] section and finally the unnamed section (as far as present) can provide per-option fallback values.

- -
-
-verbosity level
-
- -

Level of verbosity for logging, error output, etc. 0 = EMERG, 1 = ALERT, 2 = CRIT, 3 = ERR, 4 = WARN, 5 = NOTE, 6 = INFO, 7 = DEBUG, 8 = TRACE. Defaults to 6 = INFO.

- -
-
- -

Generic message options

- -
- -
-cmd ir|cr|kur|p10cr|rr|genm
-
- -

CMP command to execute. Currently implemented commands are:

- -
- -
ir   - Initialization Request
-
- -
-
cr   - Certificate Request
-
- -
-
p10cr - PKCS#10 Certification Request (for legacy support)
-
- -
-
kur   - Key Update Request
-
- -
-
rr   - Revocation Request
-
- -
-
genm - General Message
-
- -
-
- -

ir requests initialization of an end entity into a PKI hierarchy by issuing a first certificate.

- -

cr requests issuing an additional certificate for an end entity already initialized to the PKI hierarchy.

- -

p10cr requests issuing an additional certificate similarly to cr but using legacy PKCS#10 CSR format.

- -

kur requests a (key) update for an existing certificate.

- -

rr requests revocation of an existing certificate.

- -

genm requests information using a General Message, where optionally included InfoTypeAndValues may be used to state which info is of interest. Upon receipt of the General Response, information about all received ITAV infoTypes is printed to stdout.

- -
-
-infotype name
-
- -

Set InfoType name to use for requesting specific info in genm, e.g., signKeyPairTypes. There is specific support for caCerts, rootCaCert, certReqTemplate, and crlStatusList (CRL update retrieval).

- -
-
-profile name
-
- -

Name of a certificate profile to place in the PKIHeader generalInfo field of request messages.

- -
-
-geninfo values
-
- -

A comma-separated list of InfoTypeAndValue to place in the generalInfo field of the PKIHeader of requests messages. Each InfoTypeAndValue gives an OID and an integer or string value of the form OID:int:number or OID:str:text, e.g., '1.2.3.4:int:56789, id-kp:str:name'.

- -
-
-template filename
-
- -

The file to save any CRMF certTemplate in DER format received in a genp message with id-it-certReqTemplate.

- -
-
-keyspec filename
-
- -

It is optional and used to specify the file to save any keySpec if present in a genp message with id-it-keyGenParameters.

- -

Note: any keySpec field contents received are logged as INFO.

- -
-
- -

Certificate enrollment options

- -
- -
-newkey filename|uri
-
- -

The source of the private or public key for the certificate being requested. Defaults to the public key in the PKCS#10 CSR given with the -csr option, the public key of the reference certificate, or the current client key.

- -

The public portion of the key is placed in the certification request.

- -

Unless -cmd p10cr, -popo -1, or -popo 0 is given, the private key will be needed as well to provide the proof of possession (POPO), where the -key option may provide a fallback.

- -
-
-newkeypass arg
-
- -

Pass phrase source for the key given with the -newkey option. If not given here, the password will be prompted for if needed.

- -

For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-subject name
-
- -

X.509 Distinguished Name (DN) to use as subject field in the requested certificate template in IR/CR/KUR messages. If the NULL-DN (/) is given then no subject is placed in the template. Default is the subject DN of any PKCS#10 CSR given with the -csr option. For KUR, a further fallback is the subject DN of the reference certificate (see -oldcert) if provided. This fallback is used for IR and CR only if no SANs are set.

- -

If provided and neither of -cert, -oldcert, or -csr is given, the subject DN is used as fallback sender of outgoing CMP messages.

- -

The argument must be formatted as /type0=value0/type1=value1/type2=.... Special characters may be escaped by \ (backslash); whitespace is retained. Empty values are permitted, but the corresponding type will not be included. Giving a single / will lead to an empty sequence of RDNs (a NULL-DN). Multi-valued RDNs can be formed by placing a + character instead of a / between the AttributeValueAssertions (AVAs) that specify the members of the set. Example:

- -

/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe

- -
-
-days number
-
- -

Number of days the new certificate is requested to be valid for, counting from the current time of the host. Also triggers the explicit request that the validity period starts from the current time (as seen by the host).

- -
-
-reqexts name
-
- -

Name of section in OpenSSL config file defining certificate request extensions. If the -csr option is present, these extensions augment the extensions contained the given PKCS#10 CSR, overriding any extensions with same OIDs.

- -
-
-sans spec
-
- -

One or more IP addresses, email addresses, DNS names, or URIs separated by commas or whitespace (where in the latter case the whole argument must be enclosed in "...") to add as Subject Alternative Name(s) (SAN) certificate request extension. If the special element "critical" is given the SANs are flagged as critical. Cannot be used if any Subject Alternative Name extension is set via -reqexts.

- -
-
-san_nodefault
-
- -

When Subject Alternative Names are not given via -sans nor defined via -reqexts, they are copied by default from the reference certificate (see -oldcert). This can be disabled by giving the -san_nodefault option.

- -
-
-policies name
-
- -

Name of section in OpenSSL config file defining policies to be set as certificate request extension. This option cannot be used together with -policy_oids.

- -
-
-policy_oids names
-
- -

One or more OID(s), separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "...") to add as certificate policies request extension. This option cannot be used together with -policies.

- -
-
-policy_oids_critical
-
- -

Flag the policies given with -policy_oids as critical.

- -
-
-popo number
-
- -

Proof-of-possession (POPO) method to use for IR/CR/KUR; values: -1..<2> where -1 = NONE, 0 = RAVERIFIED, 1 = SIGNATURE (default), 2 = KEYENC.

- -

Note that a signature-based POPO can only be produced if a private key is provided via the -newkey or -key options.

- -
-
-csr filename
-
- -

PKCS#10 CSR in PEM or DER format containing a certificate request. With -cmd p10cr it is used directly in a legacy P10CR message.

- -

When used with -cmd ir, cr, or kur, it is transformed into the respective regular CMP request. In this case, a private key must be provided (with -newkey or -key) for the proof of possession (unless -popo -1 or -popo 0 is used) and the respective public key is placed in the certification request (rather than taking over the public key contained in the PKCS#10 CSR).

- -

PKCS#10 CSR input may also be used with -cmd rr to specify the certificate to be revoked via the included subject name and public key. Its subject is used as fallback sender in CMP message headers if -cert and -oldcert are not given.

- -
-
-out_trusted filenames|uris
-
- -

Trusted certificate(s) to use for validating the newly enrolled certificate. During this verification, any certificate status checking is disabled.

- -

Multiple sources may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Each source may contain multiple certificates.

- -

The certificate verification options -verify_hostname, -verify_ip, and -verify_email only affect the certificate verification enabled via this option.

- -
-
-implicit_confirm
-
- -

Request implicit confirmation of newly enrolled certificates.

- -
-
-disable_confirm
-
- -

Do not send certificate confirmation message for newly enrolled certificate without requesting implicit confirmation to cope with broken servers not supporting implicit confirmation correctly. WARNING: This leads to behavior violating RFC 4210.

- -
-
-certout filename
-
- -

The file where any newly enrolled certificate should be saved.

- -
-
-chainout filename
-
- -

The file where the chain of any newly enrolled certificate should be saved. This chain excludes the leaf certificate, i.e., the newly enrolled certificate. Also the trust anchor (the root certificate) is not included.

- -

If the -certout option is given, too, with equal filename argument, then the file produced contains both outputs concatenated: the newly enrolled certificate followed by its chain.

- -
-
- -

Certificate enrollment and revocation options

- -
- -
-oldcert filename|uri
-
- -

The certificate to be updated (i.e., renewed or re-keyed) in Key Update Request (KUR) messages or to be revoked in Revocation Request (RR) messages. For KUR the certificate to be updated defaults to -cert, and the resulting certificate is called reference certificate. For RR the certificate to be revoked can also be specified using -csr. -oldcert and -csr is ignored if -issuer and -serial is provided.

- -

The reference certificate, if any, is also used for deriving default subject DN and Subject Alternative Names and the default issuer entry in the requested certificate template of an IR/CR/KUR. Its public key is used as a fallback in the template of certification requests. Its subject is used as sender of outgoing messages if -cert is not given. Its issuer is used as default recipient in CMP message headers if neither -recipient, -srvcert, nor -issuer is given.

- -
-
-issuer name
-
- -

X.509 Distinguished Name (DN) to place as the issuer field in the requested certificate template in IR/CR/KUR/RR messages. If the NULL-DN (/) is given then no issuer is placed in the template.

- -

If provided and neither -recipient nor -srvcert is given, the issuer DN is used as fallback recipient of outgoing CMP messages.

- -

The argument must be formatted as /type0=value0/type1=value1/type2=.... For details see the description of the -subject option.

- -
-
-serial number
-
- -

Specify the Serial number of certificate to be revoked in revocation request. The serial number can be decimal or hex (if preceded by 0x)

- -
-
-revreason number
-
- -

Set CRLReason to be included in revocation request (RR); values: 0..10 or -1 for none (which is the default).

- -

Reason numbers defined in RFC 5280 are:

- -
CRLReason ::= ENUMERATED {
-     unspecified             (0),
-     keyCompromise           (1),
-     cACompromise            (2),
-     affiliationChanged      (3),
-     superseded              (4),
-     cessationOfOperation    (5),
-     certificateHold         (6),
-     -- value 7 is not used
-     removeFromCRL           (8),
-     privilegeWithdrawn      (9),
-     aACompromise           (10)
- }
- -
-
- -

Message transfer options

- -
- -
-server [http[s]://][userinfo@]host[:port][/path][?query][#fragment]
-
- -

The host domain name or IP address and optionally port of the CMP server to connect to using HTTP(S). IP address may be for v4 or v6, such as 127.0.0.1 or [::1] for localhost. If the host string is an IPv6 address, it must be enclosed in [ and ].

- -

This option excludes -port and -use_mock_srv. It is ignored if -rspin is given with enough filename arguments.

- -

If the scheme https is given, the -tls_used option is implied. When TLS is used, the default port is 443, otherwise 80. The optional userinfo and fragment components are ignored. Any given query component is handled as part of the path component. If a path is included it provides the default value for the -path option.

- -
-
-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]
-
- -

The HTTP(S) proxy server to use for reaching the CMP server unless -no_proxy applies, see below. If the host string is an IPv6 address, it must be enclosed in [ and ]. The proxy port defaults to 80 or 443 if the scheme is https; apart from that the optional http:// or https:// prefix is ignored (note that using TLS may be required by -tls_used or -server with the prefix https), as well as any path, userinfo, and query, and fragment components. Defaults to the environment variable http_proxy if set, else HTTP_PROXY in case no TLS is used, otherwise https_proxy if set, else HTTPS_PROXY. This option is ignored if -server is not given.

- -
-
-no_proxy addresses
-
- -

List of IP addresses and/or DNS names of servers not to use an HTTP(S) proxy for, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Default is from the environment variable no_proxy if set, else NO_PROXY. This option is ignored if -server is not given.

- -
-
-recipient name
-
- -

Distinguished Name (DN) to use in the recipient field of CMP request message headers, i.e., the CMP server (usually the addressed CA).

- -

The recipient field in the header of a CMP message is mandatory. If not given explicitly the recipient is determined in the following order: the subject of the CMP server certificate given with the -srvcert option, the -issuer option, the issuer of the certificate given with the -oldcert option, the issuer of the CMP client certificate (-cert option), as far as any of those is present, else the NULL-DN as last resort.

- -

The argument must be formatted as /type0=value0/type1=value1/type2=.... For details see the description of the -subject option.

- -
-
-path remote_path
-
- -

HTTP path at the CMP server (aka CMP alias) to use for POST requests. Defaults to any path given with -server, else "/".

- -
-
-keep_alive value
-
- -

If the given value is 0 then HTTP connections are closed after each response (which would be the default behavior of HTTP 1.0) even if a CMP transaction needs more than one round trip. If the value is 1 or 2 then for each transaction a persistent connection is requested. If the value is 2 then a persistent connection is required, i.e., an error occurs if the server does not grant it. The default value is 1, which means preferring to keep the connection open.

- -
-
-msg_timeout seconds
-
- -

Number of seconds a CMP request-response message round trip is allowed to take before a timeout error is returned. A value <= 0 means no limitation (waiting indefinitely). Default is to use the -total_timeout setting.

- -
-
-total_timeout seconds
-
- -

Maximum total number of seconds a transaction may take, including polling etc. A value <= 0 means no limitation (waiting indefinitely). Default is 0.

- -
-
- -

Server authentication options

- -
- -
-trusted filenames|uris
-
- -

The certificate(s), typically of root CAs, the client shall use as trust anchors when validating signature-based protection of CMP response messages. This option is ignored if the -srvcert option is given as well. It provides more flexibility than -srvcert because the CMP protection certificate of the server is not pinned but may be any certificate from which a chain to one of the given trust anchors can be constructed.

- -

If none of -trusted, -srvcert, and -secret is given, message validation errors will be thrown unless -unprotected_errors permits an exception.

- -

Multiple sources may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Each source may contain multiple certificates.

- -

The certificate verification options -verify_hostname, -verify_ip, and -verify_email have no effect on the certificate verification enabled via this option.

- -
-
-untrusted filenames|uris
-
- -

Non-trusted intermediate CA certificate(s). Any extra certificates given with the -cert option are appended to it. All these certificates may be useful for cert path construction for the own CMP signer certificate (to include in the extraCerts field of request messages) and for the TLS client certificate (if TLS is used) as well as for chain building when validating server certificates (checking signature-based CMP message protection) and when validating newly enrolled certificates.

- -

Multiple sources may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Each source may contain multiple certificates.

- -
-
-srvcert filename|uri
-
- -

The specific CMP server certificate to expect and directly trust (even if it is expired) when verifying signature-based protection of CMP response messages. This pins the accepted server and results in ignoring the -trusted option.

- -

If set, the subject of the certificate is also used as default value for the recipient of CMP requests and as default value for the expected sender of CMP responses.

- -
-
-expect_sender name
-
- -

Distinguished Name (DN) expected in the sender field of incoming CMP messages. Defaults to the subject DN of the pinned -srvcert, if any.

- -

This can be used to make sure that only a particular entity is accepted as CMP message signer, and attackers are not able to use arbitrary certificates of a trusted PKI hierarchy to fraudulently pose as a CMP server. Note that this option gives slightly more freedom than setting the -srvcert, which pins the server to the holder of a particular certificate, while the expected sender name will continue to match after updates of the server cert.

- -

The argument must be formatted as /type0=value0/type1=value1/type2=.... For details see the description of the -subject option.

- -
-
-ignore_keyusage
-
- -

Ignore key usage restrictions in CMP signer certificates when validating signature-based protection of incoming CMP messages. By default, digitalSignature must be allowed by CMP signer certificates. This option applies to both CMP clients and the mock server.

- -
-
-unprotected_errors
-
- -

Accept missing or invalid protection of negative responses from the server. This applies to the following message types and contents:

- -
    - -
  • error messages

    - -
  • -
  • negative certificate responses (IP/CP/KUP)

    - -
  • -
  • negative revocation responses (RP)

    - -
  • -
  • negative PKIConf messages

    - -
  • -
- -

WARNING: This setting leads to unspecified behavior and it is meant exclusively to allow interoperability with server implementations violating RFC 4210, e.g.:

- -
    - -
  • section 5.1.3.1 allows exceptions from protecting only for special cases: "There MAY be cases in which the PKIProtection BIT STRING is deliberately not used to protect a message [...] because other protection, external to PKIX, will be applied instead."

    - -
  • -
  • section 5.3.21 is clear on ErrMsgContent: "The CA MUST always sign it with a signature key."

    - -
  • -
  • appendix D.4 shows PKIConf message having protection

    - -
  • -
- -
-
-no_cache_extracerts
-
- -

Do not cache certificates in the extraCerts field of CMP messages received. By default, they are kept as they may be helful for validating further messages. This option applies to both CMP clients and the mock server.

- -
-
-srvcertout filename
-
- -

The file where to save the successfully validated certificate, if any, that the CMP server used for signature-based response message protection. If there is no such certificate, typically because the protection was MAC-based, this is indicated by deleting the file (if it existed).

- -
-
-extracertsout filename
-
- -

The file where to save the list of certificates contained in the extraCerts field of the last received response message that is not a pollRep nor PKIConf.

- -
-
-cacertsout filename
-
- -

The file where to save the list of CA certificates contained in the caPubs field if a positive certificate response (i.e., IP, CP, or KUP) message was received or contained in a general response (genp) message with infoType caCerts.

- -
-
-oldwithold filename
-
- -

The root CA certificate to include in a genm request of infoType rootCaCert. If present and the optional oldWithNew certificate is received, it is verified using the newWithNew certificate as the (only) trust anchor.

- -
-
-newwithnew filename
-
- -

This option must be provided when -infotype rootCaCert is given. It specifies the file to save the newWithNew certificate received in a genp message of type rootCaKeyUpdate. If on success no such cert was received, this file (if present) is deleted to indicate that the requested root CA certificate update is not available.

- -

Any received newWithNew certificate is verified using any received newWithOld certificate as untrusted intermediate certificate and the certificate provided with -oldwithold as the (only) trust anchor, or if not provided, using the certificates given with the -trusted option.

- -

WARNING: The newWithNew certificate is meant to be a certificate that will be trusted. The trust placed in it cannot be stronger than the trust placed in the -oldwithold certificate if present, otherwise it cannot be stronger than the weakest trust placed in any of the -trusted certificates.

- -
-
-newwithold filename
-
- -

The file to save any newWithOld certificate received in a genp message of infoType rootCaKeyUpdate. If on success no such cert was received, this is indicated by deleting the file.

- -
-
-oldwithnew filename
-
- -

The file to save any oldWithNew certificate received in a genp message of infoType rootCaKeyUpdate. If on success no such cert was received, this is indicated by deleting the file.

- -
-
-crlcert filename
-
- -

Certificate to derive CRL issuer data for the source field when obtaining a CRL in a genm request with infoType crlStatusList. Any available distribution point name is preferred over issuer names.

- -
-
-oldcrl filename
-
- -

The CRL to obtain an update for in a genm request with infoType crlStatusList. Unless the -crlcert option is provided as well, the given CRL is used for deriving CRL issuer data for the source field. Any available distribution point name is preferred over issuer names. If the CRL contains a thisUpdate field, its value is copied to the request.

- -
-
-crlout filename
-
- -

The file to save any CRL received in a genp message of infoType crls. If on success no such CRL was received, this is indicated by deleting the file.

- -
-
- -

Client authentication options

- -
- -
-ref value
-
- -

Reference number/string/value to use as fallback senderKID; this is required if no sender name can be determined from the -cert or <-subject> options and is typically used when authenticating with pre-shared key (password-based MAC).

- -
-
-secret arg
-
- -

Provides the source of a secret value to use with MAC-based message protection. This takes precedence over the -cert and -key options. The secret is used for creating MAC-based protection of outgoing messages and for validating incoming messages that have MAC-based protection. The algorithm used by default is Password-Based Message Authentication Code (PBM) as defined in RFC 4210 section 5.1.3.1.

- -

For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-cert filename|uri
-
- -

The client's current CMP signer certificate. Requires the corresponding key to be given with -key.

- -

The subject and the public key contained in this certificate serve as fallback values in the certificate template of IR/CR/KUR messages.

- -

The subject of this certificate will be used as sender of outgoing CMP messages, while the subject of -oldcert or -subjectName may provide fallback values.

- -

The issuer of this certificate is used as one of the recipient fallback values and as fallback issuer entry in the certificate template of IR/CR/KUR messages.

- -

When performing signature-based message protection, this "protection certificate", also called "signer certificate", will be included first in the extraCerts field of outgoing messages and the signature is done with the corresponding key. In Initialization Request (IR) messages this can be used for authenticating using an external entity certificate as defined in appendix E.7 of RFC 4210.

- -

For Key Update Request (KUR) messages this is also used as the certificate to be updated if the -oldcert option is not given.

- -

If the file includes further certs, they are appended to the untrusted certs because they typically constitute the chain of the client certificate, which is included in the extraCerts field in signature-protected request messages.

- -
-
-own_trusted filenames|uris
-
- -

If this list of certificates is provided then the chain built for the client-side CMP signer certificate given with the -cert option is verified using the given certificates as trust anchors.

- -

Multiple sources may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Each source may contain multiple certificates.

- -

The certificate verification options -verify_hostname, -verify_ip, and -verify_email have no effect on the certificate verification enabled via this option.

- -
-
-key filename|uri
-
- -

The corresponding private key file for the client's current certificate given in the -cert option. This will be used for signature-based message protection unless the -secret option indicating MAC-based protection or -unprotected_requests is given.

- -

It is also used as a fallback for the -newkey option with IR/CR/KUR messages.

- -
-
-keypass arg
-
- -

Pass phrase source for the private key given with the -key option. Also used for -cert and -oldcert in case it is an encrypted PKCS#12 file. If not given here, the password will be prompted for if needed.

- -

For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-digest name
-
- -

Specifies name of supported digest to use in RFC 4210's MSG_SIG_ALG and as the one-way function (OWF) in MSG_MAC_ALG. If applicable, this is used for message protection and proof-of-possession (POPO) signatures. To see the list of supported digests, use openssl list -digest-commands. Defaults to sha256.

- -
-
-mac name
-
- -

Specifies the name of the MAC algorithm in MSG_MAC_ALG. To get the names of supported MAC algorithms use openssl list -mac-algorithms and possibly combine such a name with the name of a supported digest algorithm, e.g., hmacWithSHA256. Defaults to hmac-sha1 as per RFC 4210.

- -
-
-extracerts filenames|uris
-
- -

Certificates to append in the extraCerts field when sending messages. They can be used as the default CMP signer certificate chain to include.

- -

Multiple sources may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Each source may contain multiple certificates.

- -
-
-unprotected_requests
-
- -

Send request messages without CMP-level protection.

- -
-
- -

Credentials format options

- -
- -
-certform PEM|DER
-
- -

File format to use when saving a certificate to a file. Default value is PEM.

- -
-
-crlform PEM|DER
-
- -

File format to use when saving a CRL to a file. Default value is DER. DER format is preferred because it enables more efficient storage of large CRLs.

- -
-
-keyform PEM|DER|P12|ENGINE
-
- -

The format of the key input; unspecified by default. See "Format Options" in openssl(1) for details.

- -
-
-otherpass arg
-
- -

Pass phrase source for certificate given with the -trusted, -untrusted, -own_trusted, -srvcert, -crlcert, -out_trusted, -extracerts, -srv_trusted, -srv_untrusted, -ref_cert, -rsp_cert, -rsp_extracerts, -rsp_capubs, -rsp_newwithnew, -rsp_newwithold, -rsp_oldwithnew, -tls_extra, and -tls_trusted options. If not given here, the password will be prompted for if needed.

- -

For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -

As an alternative to using this combination:

- -
-engine {engineid} -key {keyid} -keyform ENGINE
- -

... it's also possible to just give the key ID in URI form to -key, like this:

- -
-key org.openssl.engine:{engineid}:{keyid}
- -

This applies to all options specifying keys: -key, -newkey, and -tls_key.

- -
-
- -

Provider options

- -
- -
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

Random state options

- -
- -
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
- -

TLS connection options

- -
- -
-tls_used
-
- -

Make the CMP client use TLS (regardless if other TLS-related options are set) for message exchange with the server via HTTP. This option is not supported with the -port option. It is implied if the -server option is given with the scheme https. It is ignored if the -server option is not given or -use_mock_srv is given or -rspin is given with enough filename arguments.

- -

The following TLS-related options are ignored if TLS is not used.

- -
-
-tls_cert filename|uri
-
- -

Client's TLS certificate to use for authenticating to the TLS server. If the source includes further certs they are used (along with -untrusted certs) for constructing the client cert chain provided to the TLS server.

- -
-
-tls_key filename|uri
-
- -

Private key for the client's TLS certificate.

- -
-
-tls_keypass arg
-
- -

Pass phrase source for client's private TLS key -tls_key. Also used for -tls_cert in case it is an encrypted PKCS#12 file. If not given here, the password will be prompted for if needed.

- -

For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-tls_extra filenames|uris
-
- -

Extra certificates to provide to the TLS server during handshake.

- -
-
-tls_trusted filenames|uris
-
- -

Trusted certificate(s) to use for validating the TLS server certificate. This implies hostname validation.

- -

Multiple sources may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Each source may contain multiple certificates.

- -

The certificate verification options -verify_hostname, -verify_ip, and -verify_email have no effect on the certificate verification enabled via this option.

- -
-
-tls_host name
-
- -

Address to be checked during hostname validation. This may be a DNS name or an IP address. If not given it defaults to the -server address.

- -
-
- -

Client-side options for debugging and offline scenarios

- -
- -
-batch
-
- -

Do not interactively prompt for input, for instance when a password is needed. This can be useful for batch processing and testing.

- -
-
-repeat number
-
- -

Invoke the command the given positive number of times with the same parameters. Default is one invocation.

- -
-
-reqin filenames
-
- -

Take the sequence of CMP requests to send to the server from the given file(s) rather than from the sequence of requests produced internally.

- -

This option is useful for supporting offline scenarios where the certificate request (or any other CMP request) is produced beforehand and sent out later.

- -

This option is ignored if the -rspin option is given because in the latter case no requests are actually sent.

- -

Note that in any case the client produces internally its sequence of CMP request messages. Thus, all options required for doing this (such as -cmd and all options providing the required parameters) need to be given also when the -reqin option is present.

- -

If the -reqin option is given for a certificate request and no -newkey, -key, -oldcert, or -csr option is given, a fallback public key is taken from the request message file (if it is included in the certificate template).

- -

Hint: In case the -reqin option is given for a certificate request, there are situations where the client has access to the public key to be certified but not to the private key that by default will be needed for proof of possession. In this case the POPO is not actually needed (because the internally produced certificate request message will not be sent), and its generation can be disabled using the options -popo -1 or -popo 0.

- -

Multiple filenames may be given, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "...").

- -

The files are read as far as needed to complete the transaction and filenames have been provided. If more requests are needed, the remaining ones are taken from the items at the respective position in the sequence of requests produced internally.

- -

The client needs to update the recipNonce field in the given requests (except for the first one) in order to satisfy the checks to be performed by the server. This causes re-protection (if protecting requests is required).

- -
-
-reqin_new_tid
-
- -

Use a fresh transactionID for CMP request messages read using -reqin, which causes their reprotection (if protecting requests is required). This may be needed in case the sequence of requests is reused and the CMP server complains that the transaction ID has already been used.

- -
-
-reqout filenames
-
- -

Save the sequence of CMP requests created by the client to the given file(s). These requests are not sent to the server if the -reqin option is used, too.

- -

Multiple filenames may be given, separated by commas and/or whitespace.

- -

Files are written as far as needed to save the transaction and filenames have been provided. If the transaction contains more requests, the remaining ones are not saved.

- -
-
-reqout_only filename
-
- -

Save the first CMP requests created by the client to the given file and exit. Any options related to CMP servers and their responses are ignored.

- -

This option is useful for supporting offline scenarios where the certificate request (or any other CMP request) is produced beforehand and sent out later.

- -
-
-rspin filenames
-
- -

Process the sequence of CMP responses provided in the given file(s), not contacting any given server, as long as enough filenames are provided to complete the transaction.

- -

Multiple filenames may be given, separated by commas and/or whitespace.

- -

Any server specified via the -server or -use_mock_srv options is contacted only if more responses are needed to complete the transaction. In this case the transaction will fail unless the server has been prepared to continue the already started transaction.

- -
-
-rspout filenames
-
- -

Save the sequence of actually used CMP responses to the given file(s). These have been received from the server unless -rspin takes effect.

- -

Multiple filenames may be given, separated by commas and/or whitespace.

- -

Files are written as far as needed to save the responses contained in the transaction and filenames have been provided. If the transaction contains more responses, the remaining ones are not saved.

- -
-
-use_mock_srv
-
- -

Test the client using the internal CMP server mock-up at API level, bypassing socket-based transfer via HTTP. This excludes the -server and -port options.

- -
-
- -

Mock server options

- -
- -
-port number
-
- -

Act as HTTP-based CMP server mock-up listening on the given local port. The client may address the server via, e.g., 127.0.0.1 or [::1]. This option excludes the -server and -use_mock_srv options. The -rspin, -rspout, -reqin, and -reqout options so far are not supported in this mode.

- -
-
-max_msgs number
-
- -

Maximum number of CMP (request) messages the CMP HTTP server mock-up should handle, which must be nonnegative. The default value is 0, which means that no limit is imposed. In any case the server terminates on internal errors, but not when it detects a CMP-level error that it can successfully answer with an error message.

- -
-
-srv_ref value
-
- -

Reference value to use as senderKID of server in case no -srv_cert is given.

- -
-
-srv_secret arg
-
- -

Password source for server authentication with a pre-shared key (secret).

- -
-
-srv_cert filename|uri
-
- -

Certificate of the server.

- -
-
-srv_key filename|uri
-
- -

Private key used by the server for signing messages.

- -
-
-srv_keypass arg
-
- -

Server private key (and cert) file pass phrase source.

- -
-
-srv_trusted filenames|uris
-
- -

Trusted certificates for client authentication.

- -

The certificate verification options -verify_hostname, -verify_ip, and -verify_email have no effect on the certificate verification enabled via this option.

- -
-
-srv_untrusted filenames|uris
-
- -

Intermediate CA certs that may be useful when validating client certificates.

- -
-
-ref_cert filename|uri
-
- -

Certificate to be expected for RR messages and any oldCertID in KUR messages.

- -
-
-rsp_cert filename|uri
-
- -

Certificate to be returned as mock enrollment result.

- -
-
-rsp_crl filename|uri
-
- -

CRL to be returned in genp of type crls.

- -
-
-rsp_extracerts filenames|uris
-
- -

Extra certificates to be included in mock certification responses.

- -
-
-rsp_capubs filenames|uris
-
- -

CA certificates to be included in mock Initialization Response (IP) message.

- -
-
-rsp_newwithnew filename|uri
-
- -

Certificate to be returned in newWithNew field of genp of type rootCaKeyUpdate.

- -
-
-rsp_newwithold filename|uri
-
- -

Certificate to be returned in newWithOld field of genp of type rootCaKeyUpdate.

- -
-
-rsp_oldwithnew filename|uri
-
- -

Certificate to be returned in oldWithNew field of genp of type rootCaKeyUpdate.

- -
-
-poll_count number
-
- -

Number of times the client must poll before receiving a certificate.

- -
-
-check_after number
-
- -

The checkAfter value (number of seconds to wait) to include in poll response.

- -
-
-grant_implicitconf
-
- -

Grant implicit confirmation of newly enrolled certificate.

- -
-
-pkistatus number
-
- -

PKIStatus to be included in server response. Valid range is 0 (accepted) .. 6 (keyUpdateWarning).

- -
-
-failure number
-
- -

A single failure info bit number to be included in server response. Valid range is 0 (badAlg) .. 26 (duplicateCertReq).

- -
-
-failurebits number Number representing failure bits to be included in server response. Valid range is 0 .. 2^27 - 1.
-
- -
-
-statusstring arg
-
- -

Text to be included as status string in server response.

- -
-
-send_error
-
- -

Force server to reply with error message.

- -
-
-send_unprotected
-
- -

Send response messages without CMP-level protection.

- -
-
-send_unprot_err
-
- -

In case of negative responses, server shall send unprotected error messages, certificate responses (IP/CP/KUP), and revocation responses (RP). WARNING: This setting leads to behavior violating RFC 4210.

- -
-
-accept_unprotected
-
- -

Accept missing or invalid protection of requests.

- -
-
-accept_unprot_err
-
- -

Accept unprotected error messages from client. So far this has no effect because the server does not accept any error messages.

- -
-
-accept_raverified
-
- -

Accept RAVERIFED as proof of possession (POPO).

- -
-
- -

Certificate verification options, for both CMP and TLS

- -
- -
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -

The certificate verification options -verify_hostname, -verify_ip, and -verify_email only affect the certificate verification enabled via the -out_trusted option.

- -
-
- -

NOTES

- -

When a client obtains, from a CMP server, CA certificates that it is going to trust, for instance via the caPubs field of a certificate response or using general messages with infoType caCerts or rootCaCert, authentication of the CMP server is particularly critical. So special care must be taken setting up server authentication using -trusted and related options for certificate-based authentication or -secret for MAC-based protection. If authentication is certificate-based, the -srvcertout option should be used to obtain the validated server certificate and perform an authorization check based on it.

- -

When setting up CMP configurations and experimenting with enrollment options typically various errors occur until the configuration is correct and complete. When the CMP server reports an error the client will by default check the protection of the CMP response message. Yet some CMP services tend not to protect negative responses. In this case the client will reject them, and thus their contents are not shown although they usually contain hints that would be helpful for diagnostics. For assisting in such cases the CMP client offers a workaround via the -unprotected_errors option, which allows accepting such negative messages.

- -

If OpenSSL was built with trace support enabled (e.g., ./config enable-trace) and the environment variable OPENSSL_TRACE includes HTTP, the requests and the response headers transferred via HTTP are printed.

- -

EXAMPLES

- -

Simple examples using the default OpenSSL configuration file

- -

This CMP client implementation comes with demonstrative CMP sections in the example configuration file openssl/apps/openssl.cnf, which can be used to interact conveniently with the Insta Demo CA.

- -

In order to enroll an initial certificate from that CA it is sufficient to issue the following shell commands.

- -
export OPENSSL_CONF=/path/to/openssl/apps/openssl.cnf
- -
openssl genrsa -out insta.priv.pem
-openssl cmp -section insta
- -

This should produce the file insta.cert.pem containing a new certificate for the private key held in insta.priv.pem. It can be viewed using, e.g.,

- -
openssl x509 -noout -text -in insta.cert.pem
- -

In case the network setup requires using an HTTP proxy it may be given as usual via the environment variable http_proxy or via the -proxy option in the configuration file or the CMP command-line argument -proxy, for example

- -
-proxy http://192.168.1.1:8080
- -

In the Insta Demo CA scenario both clients and the server may use the pre-shared secret insta and the reference value 3078 to authenticate to each other.

- -

Alternatively, CMP messages may be protected in signature-based manner, where the trust anchor in this case is insta.ca.crt and the client may use any certificate already obtained from that CA, as specified in the [signature] section of the example configuration. This can be used in combination with the [insta] section simply by

- -
openssl cmp -section insta,signature
- -

By default the CMP IR message type is used, yet CR works equally here. This may be specified directly at the command line:

- -
openssl cmp -section insta -cmd cr
- -

or by referencing in addition the [cr] section of the example configuration:

- -
openssl cmp -section insta,cr
- -

In order to update the enrolled certificate one may call

- -
openssl cmp -section insta,kur,signature
- -

using signature-based protection with the certificate that is to be updated. For certificate updates, MAC-based protection should generally not be used.

- -

In a similar way any previously enrolled certificate may be revoked by

- -
openssl cmp -section insta,rr -trusted insta.ca.crt
- -

or

- -
openssl cmp -section insta,rr,signature
- -

Many more options can be given in the configuration file and/or on the command line. For instance, the -reqexts CLI option may refer to a section in the configuration file defining X.509 extensions to use in certificate requests, such as v3_req in openssl/apps/openssl.cnf:

- -
openssl cmp -section insta,cr -reqexts v3_req
- -

Certificate enrollment

- -

The following examples do not make use of a configuration file at first. They assume that a CMP server can be contacted on the local TCP port 80 and accepts requests under the alias /pkix/.

- -

For enrolling its very first certificate the client generates a client key and sends an initial request message to the local CMP server using a pre-shared secret key for mutual authentication. In this example the client does not have the CA certificate yet, so we specify the name of the CA with the -recipient option and save any CA certificates that we may receive in the capubs.pem file.

- -

In below command line usage examples the \ at line ends is used just for formatting; each of the command invocations should be on a single line.

- -
openssl genrsa -out cl_key.pem
-openssl cmp -cmd ir -server 127.0.0.1:80/pkix/ -recipient "/CN=CMPserver" \
-  -ref 1234 -secret pass:1234-5678 \
-  -newkey cl_key.pem -subject "/CN=MyName" \
-  -cacertsout capubs.pem -certout cl_cert.pem
- -

Certificate update

- -

Then, when the client certificate and its related key pair needs to be updated, the client can send a key update request taking the certs in capubs.pem as trusted for authenticating the server and using the previous cert and key for its own authentication. Then it can start using the new cert and key.

- -
openssl genrsa -out cl_key_new.pem
-openssl cmp -cmd kur -server 127.0.0.1:80/pkix/ \
-  -trusted capubs.pem \
-  -cert cl_cert.pem -key cl_key.pem \
-  -newkey cl_key_new.pem -certout cl_cert.pem
-cp cl_key_new.pem cl_key.pem
- -

This command sequence can be repeated as often as needed.

- -

Requesting information from CMP server

- -

Requesting "all relevant information" with an empty General Message. This prints information about all received ITAV infoTypes to stdout.

- -
openssl cmp -cmd genm -server 127.0.0.1/pkix/ -recipient "/CN=CMPserver" \
-  -ref 1234 -secret pass:1234-5678
- -

Using a custom configuration file

- -

For CMP client invocations, in particular for certificate enrollment, usually many parameters need to be set, which is tedious and error-prone to do on the command line. Therefore, the client offers the possibility to read options from sections of the OpenSSL config file, usually called openssl.cnf. The values found there can still be extended and even overridden by any subsequently loaded sections and on the command line.

- -

After including in the configuration file the following sections:

- -
[cmp]
-server = 127.0.0.1
-path = pkix/
-trusted = capubs.pem
-cert = cl_cert.pem
-key = cl_key.pem
-newkey = cl_key.pem
-certout = cl_cert.pem
-
-[init]
-recipient = "/CN=CMPserver"
-trusted =
-cert =
-key =
-ref = 1234
-secret = pass:1234-5678-1234-567
-subject = "/CN=MyName"
-cacertsout = capubs.pem
- -

the above enrollment transactions reduce to

- -
openssl cmp -section cmp,init
-openssl cmp -cmd kur -newkey cl_key_new.pem
- -

and the above transaction using a general message reduces to

- -
openssl cmp -section cmp,init -cmd genm
- -

SEE ALSO

- -

openssl-genrsa(1), openssl-ecparam(1), openssl-list(1), openssl-req(1), openssl-x509(1), x509v3_config(5)

- -

HISTORY

- -

The cmp application was added in OpenSSL 3.0.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -profile option was added in OpenSSL 3.3.

- -

-crlcert, -oldcrl, -crlout, -crlform and -rsp_crl options were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-cms.html b/openssl-install/share/doc/openssl/html/man1/openssl-cms.html deleted file mode 100644 index 652514df..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-cms.html +++ /dev/null @@ -1,892 +0,0 @@ - - - - -openssl-cms - - - - - - - - - - -

NAME

- -

openssl-cms - CMS command

- -

SYNOPSIS

- -

openssl cms [-help]

- -

General options:

- -

[-in filename] [-out filename] [-config configfile]

- -

Operation options:

- -

[-encrypt] [-decrypt] [-sign] [-verify] [-resign] [-sign_receipt] [-verify_receipt receipt] [-digest digest] [-digest_create] [-digest_verify] [-compress] [-uncompress] [-EncryptedData_encrypt] [-EncryptedData_decrypt] [-data_create] [-data_out] [-cmsout]

- -

File format options:

- -

[-inform DER|PEM|SMIME] [-outform DER|PEM|SMIME] [-rctform DER|PEM|SMIME] [-stream] [-indef] [-noindef] [-binary] [-crlfeol] [-asciicrlf]

- -

Keys and password options:

- -

[-pwri_password password] [-secretkey key] [-secretkeyid id] [-inkey filename|uri] [-passin arg] [-keyopt name:parameter] [-keyform DER|PEM|P12|ENGINE] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [-rand files] [-writerand file]

- -

Encryption options:

- -

[-originator file] [-recip file] [recipient-cert ...] [-cipher] [-wrap cipher] [-aes128-wrap] [-aes192-wrap] [-aes256-wrap] [-des3-wrap] [-debug_decrypt]

- -

Signing options:

- -

[-md digest] [-signer file] [-certfile file] [-cades] [-nodetach] [-nocerts] [-noattr] [-nosmimecap] [-receipt_request_all] [-receipt_request_first] [-receipt_request_from emailaddress] [-receipt_request_to emailaddress]

- -

Verification options:

- -

[-signer file] [-content filename] [-no_content_verify] [-no_attr_verify] [-nosigs] [-noverify] [-nointern] [-cades] [-verify_retcode] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore]

- -

Output options:

- -

[-keyid] [-econtent_type type] [-text] [-certsout file] [-to addr] [-from addr] [-subject subj]

- -

Printing options:

- -

[-noout] [-print] [-nameopt option] [-receipt_request_print]

- -

Validation options:

- -

[-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks]

- -

DESCRIPTION

- -

This command handles data in CMS format such as S/MIME v3.1 email messages. It can encrypt, decrypt, sign, verify, compress, uncompress, and print messages.

- -

OPTIONS

- -

There are a number of operation options that set the type of operation to be performed: encrypt, decrypt, sign, verify, resign, sign_receipt, verify_receipt, digest_create, digest_verify, compress, uncompress, EncryptedData_encrypt, EncryptedData_decrypt, data_create, data_out, or cmsout. The relevance of the other options depends on the operation type and their meaning may vary according to it.

- -
- -
-help
-
- -

Print out a usage message.

- -
-
- -

General options

- -
- -
-in filename
-
- -

The input message to be encrypted or signed or the message to be decrypted or verified.

- -
-
-out filename
-
- -

The message text that has been decrypted or verified or the output MIME format message that has been signed or verified.

- -
-
-config configfile
-
- -

See "Configuration Option" in openssl(1).

- -
-
- -

Operation options

- -
- -
-encrypt
-
- -

Encrypt data for the given recipient certificates. Input file is the message to be encrypted. The output file is the encrypted data in MIME format. The actual CMS type is EnvelopedData.

- -

Note that no revocation check is done for the recipient cert, so if that key has been compromised, others may be able to decrypt the text.

- -
-
-decrypt
-
- -

Decrypt data using the supplied certificate and private key. Expects encrypted datain MIME format for the input file. The decrypted data is written to the output file.

- -
-
-sign
-
- -

Sign data using the supplied certificate and private key. Input file is the message to be signed. The signed data in MIME format is written to the output file.

- -
-
-verify
-
- -

Verify signed data. Expects a signed data on input and outputs the signed data. Both clear text and opaque signing is supported.

- -

By default, validation of signer certificates and their chain is done w.r.t. the S/MIME signing (smimesign) purpose. For details see "Certificate Extensions" in openssl-verification-options(1).

- -
-
-resign
-
- -

Resign a message: take an existing message and one or more new signers.

- -
-
-sign_receipt
-
- -

Generate and output a signed receipt for the supplied message. The input message must contain a signed receipt request. Functionality is otherwise similar to the -sign operation.

- -
-
-verify_receipt receipt
-
- -

Verify a signed receipt in filename receipt. The input message must contain the original receipt request. Functionality is otherwise similar to the -verify operation.

- -
-
-digest digest
-
- -

When used with -sign, provides the digest in hexadecimal form instead of computing it from the original message content. Cannot be combined with -in or -nodetach.

- -

This operation is the CMS equivalent of openssl-pkeyutl(1) signing. When signing a pre-computed digest, the security relies on the digest and its computation from the original message being trusted.

- -
-
-digest_create
-
- -

Create a CMS DigestedData type.

- -
-
-digest_verify
-
- -

Verify a CMS DigestedData type and output the content.

- -
-
-compress
-
- -

Create a CMS CompressedData type. OpenSSL must be compiled with zlib support for this option to work, otherwise it will output an error.

- -
-
-uncompress
-
- -

Uncompress a CMS CompressedData type and output the content. OpenSSL must be compiled with zlib support for this option to work, otherwise it will output an error.

- -
-
-EncryptedData_encrypt
-
- -

Encrypt content using supplied symmetric key and algorithm using a CMS EncryptedData type and output the content.

- -
-
-EncryptedData_decrypt
-
- -

Decrypt content using supplied symmetric key and algorithm using a CMS EncryptedData type and output the content.

- -
-
-data_create
-
- -

Create a CMS Data type.

- -
-
-data_out
-
- -

Data type and output the content.

- -
-
-cmsout
-
- -

Takes an input message and writes out a PEM encoded CMS structure.

- -
-
- -

File format options

- -
- -
-inform DER|PEM|SMIME
-
- -

The input format of the CMS structure (if one is being read); the default is SMIME. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM|SMIME
-
- -

The output format of the CMS structure (if one is being written); the default is SMIME. See openssl-format-options(1) for details.

- -
-
-rctform DER|PEM|SMIME
-
- -

The signed receipt format for use with the -receipt_verify; the default is SMIME. See openssl-format-options(1) for details.

- -
-
-stream, -indef
-
- -

The -stream and -indef options are equivalent and enable streaming I/O for encoding operations. This permits single pass processing of data without the need to hold the entire contents in memory, potentially supporting very large files. Streaming is automatically set for S/MIME signing with detached data if the output format is SMIME it is currently off by default for all other operations.

- -
-
-noindef
-
- -

Disable streaming I/O where it would produce and indefinite length constructed encoding. This option currently has no effect. In future streaming will be enabled by default on all relevant operations and this option will disable it.

- -
-
-binary
-
- -

Normally the input message is converted to "canonical" format which is effectively using CR and LF as end of line: as required by the S/MIME specification. When this option is present no translation occurs. This is useful when handling binary data which may not be in MIME format.

- -
-
-crlfeol
-
- -

Normally the output file uses a single LF as end of line. When this option is present CRLF is used instead.

- -
-
-asciicrlf
-
- -

When signing use ASCII CRLF format canonicalisation. This strips trailing whitespace from all lines, deletes trailing blank lines at EOF and sets the encapsulated content type. This option is normally used with detached content and an output signature format of DER. This option is not normally needed when verifying as it is enabled automatically if the encapsulated content format is detected.

- -
-
- -

Keys and password options

- -
- -
-pwri_password password
-
- -

Specify password for recipient.

- -
-
-secretkey key
-
- -

Specify symmetric key to use. The key must be supplied in hex format and be consistent with the algorithm used. Supported by the -EncryptedData_encrypt -EncryptedData_decrypt, -encrypt and -decrypt options. When used with -encrypt or -decrypt the supplied key is used to wrap or unwrap the content encryption key using an AES key in the KEKRecipientInfo type.

- -
-
-secretkeyid id
-
- -

The key identifier for the supplied symmetric key for KEKRecipientInfo type. This option must be present if the -secretkey option is used with -encrypt. With -decrypt operations the id is used to locate the relevant key if it is not supplied then an attempt is used to decrypt any KEKRecipientInfo structures.

- -
-
-inkey filename|uri
-
- -

The private key to use when signing or decrypting. This must match the corresponding certificate. If this option is not specified then the private key must be included in the certificate file specified with the -recip or -signer file. When signing this option can be used multiple times to specify successive keys.

- -
-
-passin arg
-
- -

The private key password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-keyopt name:parameter
-
- -

For signing and encryption this option can be used multiple times to set customised parameters for the preceding key or certificate. It can currently be used to set RSA-PSS for signing, RSA-OAEP for encryption or to modify default parameters for ECDH.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The format of the private key file; unspecified by default. See openssl-format-options(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
- -

Encryption and decryption options

- -
- -
-originator file
-
- -

A certificate of the originator of the encrypted message. Necessary for decryption when Key Agreement is in use for a shared key. Currently, not allowed for encryption.

- -
-
-recip file
-
- -

When decrypting a message this specifies the certificate of the recipient. The certificate must match one of the recipients of the message.

- -

When encrypting a message this option may be used multiple times to specify each recipient. This form must be used if customised parameters are required (for example to specify RSA-OAEP).

- -

Only certificates carrying RSA, Diffie-Hellman or EC keys are supported by this option.

- -
-
recipient-cert ...
-
- -

This is an alternative to using the -recip option when encrypting a message. One or more certificate filenames may be given.

- -
-
-cipher
-
- -

The encryption algorithm to use. For example triple DES (168 bits) - -des3 or 256 bit AES - -aes256. Any standard algorithm name (as used by the EVP_get_cipherbyname() function) can also be used preceded by a dash, for example -aes-128-cbc. See openssl-enc(1) for a list of ciphers supported by your version of OpenSSL.

- -

Currently the AES variants with GCM mode are the only supported AEAD algorithms.

- -

If not specified triple DES is used. Only used with -encrypt and -EncryptedData_create commands.

- -
-
-wrap cipher
-
- -

Cipher algorithm to use for key wrap when encrypting the message using Key Agreement for key transport. The algorithm specified should be suitable for key wrap.

- -
-
-aes128-wrap, -aes192-wrap, -aes256-wrap, -des3-wrap
-
- -

Use AES128, AES192, AES256, or 3DES-EDE, respectively, to wrap key. Depending on the OpenSSL build options used, -des3-wrap may not be supported.

- -
-
-debug_decrypt
-
- -

This option sets the CMS_DEBUG_DECRYPT flag. This option should be used with caution: see the notes section below.

- -
-
- -

Signing options

- -
- -
-md digest
-
- -

Digest algorithm to use when signing or resigning. If not present then the default digest algorithm for the signing key will be used (usually SHA1).

- -
-
-signer file
-
- -

A signing certificate. When signing or resigning a message, this option can be used multiple times if more than one signer is required.

- -
-
-certfile file
-
- -

Allows additional certificates to be specified. When signing these will be included with the message. When verifying, these will be searched for signer certificates and will be used for chain building.

- -

The input can be in PEM, DER, or PKCS#12 format.

- -
-
-cades
-
- -

When used with -sign, add an ESS signingCertificate or ESS signingCertificateV2 signed-attribute to the SignerInfo, in order to make the signature comply with the requirements for a CAdES Basic Electronic Signature (CAdES-BES).

- -
-
-nodetach
-
- -

When signing a message use opaque signing: this form is more resistant to translation by mail relays but it cannot be read by mail agents that do not support S/MIME. Without this option cleartext signing with the MIME type multipart/signed is used.

- -
-
-nocerts
-
- -

When signing a message the signer's certificate is normally included with this option it is excluded. This will reduce the size of the signed message but the verifier must have a copy of the signers certificate available locally (passed using the -certfile option for example).

- -
-
-noattr
-
- -

Normally when a message is signed a set of attributes are included which include the signing time and supported symmetric algorithms. With this option they are not included.

- -
-
-nosmimecap
-
- -

Exclude the list of supported algorithms from signed attributes, other options such as signing time and content type are still included.

- -
-
-receipt_request_all, -receipt_request_first
-
- -

For -sign option include a signed receipt request. Indicate requests should be provided by all recipient or first tier recipients (those mailed directly and not from a mailing list). Ignored it -receipt_request_from is included.

- -
-
-receipt_request_from emailaddress
-
- -

For -sign option include a signed receipt request. Add an explicit email address where receipts should be supplied.

- -
-
-receipt_request_to emailaddress
-
- -

Add an explicit email address where signed receipts should be sent to. This option must but supplied if a signed receipt is requested.

- -
-
- -

Verification options

- -
- -
-signer file
-
- -

If a message has been verified successfully then the signers certificate(s) will be written to this file if the verification was successful.

- -
-
-content filename
-
- -

This specifies a file containing the detached content for operations taking S/MIME input, such as the -verify command. This is only usable if the CMS structure is using the detached signature form where the content is not included. This option will override any content if the input format is S/MIME and it uses the multipart/signed MIME content type.

- -
-
-no_content_verify
-
- -

Do not verify signed content signatures.

- -
-
-no_attr_verify
-
- -

Do not verify signed attribute signatures.

- -
-
-nosigs
-
- -

Don't verify message signature.

- -
-
-noverify
-
- -

Do not verify the signers certificate of a signed message.

- -
-
-nointern
-
- -

When verifying a message normally certificates (if any) included in the message are searched for the signing certificate. With this option only the certificates specified in the -certfile option are used. The supplied certificates can still be used as untrusted CAs however.

- -
-
-cades
-
- -

When used with -verify, require and check signer certificate digest. See the NOTES section for more details.

- -
-
-verify_retcode
-
- -

Exit nonzero on verification failure.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
- -

Output options

- -
- -
-keyid
-
- -

Use subject key identifier to identify certificates instead of issuer name and serial number. The supplied certificate must include a subject key identifier extension. Supported by -sign and -encrypt options.

- -
-
-econtent_type type
-
- -

Set the encapsulated content type to type if not supplied the Data type is used. The type argument can be any valid OID name in either text or numerical format.

- -
-
-text
-
- -

This option adds plain text (text/plain) MIME headers to the supplied message if encrypting or signing. If decrypting or verifying it strips off text headers: if the decrypted or verified message is not of MIME type text/plain then an error occurs.

- -
-
-certsout file
-
- -

Any certificates contained in the input message are written to file.

- -
-
-to, -from, -subject
-
- -

The relevant email headers. These are included outside the signed portion of a message so they may be included manually. If signing then many S/MIME mail clients check the signers certificate's email address matches that specified in the From: address.

- -
-
- -

Printing options

- -
- -
-noout
-
- -

For the -cmsout operation do not output the parsed CMS structure. This is useful if the syntax of the CMS structure is being checked.

- -
-
-print
-
- -

For the -cmsout operation print out all fields of the CMS structure. This implies -noout. This is mainly useful for testing purposes.

- -
-
-nameopt option
-
- -

For the -cmsout operation when -print option is in use, specifies printing options for string fields. For most cases utf8 is reasonable value. See openssl-namedisplay-options(1) for details.

- -
-
-receipt_request_print
-
- -

For the -verify operation print out the contents of any signed receipt requests.

- -
-
- -

Validation options

- -
- -
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -

Any validation errors cause the command to exit.

- -
-
- -

NOTES

- -

The MIME message must be sent without any blank lines between the headers and the output. Some mail programs will automatically add a blank line. Piping the mail directly to sendmail is one way to achieve the correct format.

- -

The supplied message to be signed or encrypted must include the necessary MIME headers or many S/MIME clients won't display it properly (if at all). You can use the -text option to automatically add plain text headers.

- -

A "signed and encrypted" message is one where a signed message is then encrypted. This can be produced by encrypting an already signed message: see the examples section.

- -

This version of the program only allows one signer per message but it will verify multiple signers on received messages. Some S/MIME clients choke if a message contains multiple signers. It is possible to sign messages "in parallel" by signing an already signed message.

- -

The options -encrypt and -decrypt reflect common usage in S/MIME clients. Strictly speaking these process CMS enveloped data: CMS encrypted data is used for other purposes.

- -

The -resign option uses an existing message digest when adding a new signer. This means that attributes must be present in at least one existing signer using the same message digest or this operation will fail.

- -

The -stream and -indef options enable streaming I/O support. As a result the encoding is BER using indefinite length constructed encoding and no longer DER. Streaming is supported for the -encrypt operation and the -sign operation if the content is not detached.

- -

Streaming is always used for the -sign operation with detached data but since the content is no longer part of the CMS structure the encoding remains DER.

- -

If the -decrypt option is used without a recipient certificate then an attempt is made to locate the recipient by trying each potential recipient in turn using the supplied private key. To thwart the MMA attack (Bleichenbacher's attack on PKCS #1 v1.5 RSA padding) all recipients are tried whether they succeed or not and if no recipients match the message is "decrypted" using a random key which will typically output garbage. The -debug_decrypt option can be used to disable the MMA attack protection and return an error if no recipient can be found: this option should be used with caution. For a fuller description see CMS_decrypt(3)).

- -

CADES BASIC ELECTRONIC SIGNATURE (CADES-BES)

- -

A CAdES Basic Electronic Signature (CAdES-BES), as defined in the European Standard ETSI EN 319 122-1 V1.1.1, contains:

- - - -

EXIT CODES

- -
- -
0
-
- -

The operation was completely successfully.

- -
-
1
-
- -

An error occurred parsing the command options.

- -
-
2
-
- -

One of the input files could not be read.

- -
-
3
-
- -

An error occurred creating the CMS file or when reading the MIME message.

- -
-
4
-
- -

An error occurred decrypting or verifying the message.

- -
-
5
-
- -

The message was verified correctly but an error occurred writing out the signers certificates.

- -
-
- -

COMPATIBILITY WITH PKCS#7 FORMAT

- -

openssl-smime(1) can only process the older PKCS#7 format. openssl cms supports Cryptographic Message Syntax format. Use of some features will result in messages which cannot be processed by applications which only support the older format. These are detailed below.

- -

The use of the -keyid option with -sign or -encrypt.

- -

The -outform PEM option uses different headers.

- -

The -compress option.

- -

The -secretkey option when used with -encrypt.

- -

The use of PSS with -sign.

- -

The use of OAEP or non-RSA keys with -encrypt.

- -

Additionally the -EncryptedData_create and -data_create type cannot be processed by the older openssl-smime(1) command.

- -

EXAMPLES

- -

Create a cleartext signed message:

- -
openssl cms -sign -in message.txt -text -out mail.msg \
-       -signer mycert.pem
- -

Create an opaque signed message

- -
openssl cms -sign -in message.txt -text -out mail.msg -nodetach \
-       -signer mycert.pem
- -

Create a signed message, include some additional certificates and read the private key from another file:

- -
openssl cms -sign -in in.txt -text -out mail.msg \
-       -signer mycert.pem -inkey mykey.pem -certfile mycerts.pem
- -

Create a signed message with two signers, use key identifier:

- -
openssl cms -sign -in message.txt -text -out mail.msg \
-       -signer mycert.pem -signer othercert.pem -keyid
- -

Send a signed message under Unix directly to sendmail, including headers:

- -
openssl cms -sign -in in.txt -text -signer mycert.pem \
-       -from steve@openssl.org -to someone@somewhere \
-       -subject "Signed message" | sendmail someone@somewhere
- -

Verify a message and extract the signer's certificate if successful:

- -
openssl cms -verify -in mail.msg -signer user.pem -out signedtext.txt
- -

Send encrypted mail using triple DES:

- -
openssl cms -encrypt -in in.txt -from steve@openssl.org \
-       -to someone@somewhere -subject "Encrypted message" \
-       -des3 user.pem -out mail.msg
- -

Sign and encrypt mail:

- -
openssl cms -sign -in ml.txt -signer my.pem -text \
-       | openssl cms -encrypt -out mail.msg \
-       -from steve@openssl.org -to someone@somewhere \
-       -subject "Signed and Encrypted message" -des3 user.pem
- -

Note: the encryption command does not include the -text option because the message being encrypted already has MIME headers.

- -

Decrypt a message:

- -
openssl cms -decrypt -in mail.msg -recip mycert.pem -inkey key.pem
- -

The output from Netscape form signing is a PKCS#7 structure with the detached signature format. You can use this program to verify the signature by line wrapping the base64 encoded structure and surrounding it with:

- -
-----BEGIN PKCS7-----
------END PKCS7-----
- -

and using the command,

- -
openssl cms -verify -inform PEM -in signature.pem -content content.txt
- -

alternatively you can base64 decode the signature and use

- -
openssl cms -verify -inform DER -in signature.der -content content.txt
- -

Create an encrypted message using 128 bit Camellia:

- -
openssl cms -encrypt -in plain.txt -camellia128 -out mail.msg cert.pem
- -

Add a signer to an existing message:

- -
openssl cms -resign -in mail.msg -signer newsign.pem -out mail2.msg
- -

Sign a message using RSA-PSS:

- -
openssl cms -sign -in message.txt -text -out mail.msg \
-       -signer mycert.pem -keyopt rsa_padding_mode:pss
- -

Create an encrypted message using RSA-OAEP:

- -
openssl cms -encrypt -in plain.txt -out mail.msg \
-       -recip cert.pem -keyopt rsa_padding_mode:oaep
- -

Use SHA256 KDF with an ECDH certificate:

- -
openssl cms -encrypt -in plain.txt -out mail.msg \
-       -recip ecdhcert.pem -keyopt ecdh_kdf_md:sha256
- -

Print CMS signed binary data in human-readable form:

- -

openssl cms -in signed.cms -binary -inform DER -cmsout -print

- -

BUGS

- -

The MIME parser isn't very clever: it seems to handle most messages that I've thrown at it but it may choke on others.

- -

The code currently will only write out the signer's certificate to a file: if the signer has a separate encryption certificate this must be manually extracted. There should be some heuristic that determines the correct encryption certificate.

- -

Ideally a database should be maintained of a certificates for each email address.

- -

The code doesn't currently take note of the permitted symmetric encryption algorithms as supplied in the SMIMECapabilities signed attribute. this means the user has to manually include the correct encryption algorithm. It should store the list of permitted ciphers in a database and only use those.

- -

No revocation checking is done on the signer's certificate.

- -

SEE ALSO

- -

ossl_store-file(7)

- -

HISTORY

- -

The use of multiple -signer options and the -resign command were first added in OpenSSL 1.0.0.

- -

The -keyopt option was added in OpenSSL 1.0.2.

- -

Support for RSA-OAEP and RSA-PSS was added in OpenSSL 1.0.2.

- -

The use of non-RSA keys with -encrypt and -decrypt was added in OpenSSL 1.0.2.

- -

The -no_alt_chains option was added in OpenSSL 1.0.2b.

- -

The -nameopt option was added in OpenSSL 3.0.0.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -digest option was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-crl.html b/openssl-install/share/doc/openssl/html/man1/openssl-crl.html deleted file mode 100644 index 2c07510b..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-crl.html +++ /dev/null @@ -1,225 +0,0 @@ - - - - -openssl-crl - - - - - - - - - - -

NAME

- -

openssl-crl - CRL command

- -

SYNOPSIS

- -

openssl crl [-help] [-inform DER|PEM] [-outform DER|PEM] [-key filename] [-keyform DER|PEM|P12] [-dateopt] [-text] [-in filename] [-out filename] [-gendelta filename] [-badsig] [-verify] [-noout] [-hash] [-hash_old] [-fingerprint] [-crlnumber] [-issuer] [-lastupdate] [-nextupdate] [-nameopt option] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command processes CRL files in DER or PEM format.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM
-
- -

The CRL input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The CRL output format; the default is PEM. See openssl-format-options(1) for details.

- -
-
-key filename
-
- -

The private key to be used to sign the CRL.

- -
-
-keyform DER|PEM|P12
-
- -

The format of the private key file; unspecified by default. See openssl-format-options(1) for details.

- -
-
-in filename
-
- -

This specifies the input filename to read from or standard input if this option is not specified.

- -
-
-out filename
-
- -

Specifies the output filename to write to or standard output by default.

- -
-
-gendelta filename
-
- -

Output a comparison of the main CRL and the one specified here.

- -
-
-badsig
-
- -

Corrupt the signature before writing it; this can be useful for testing.

- -
-
-dateopt
-
- -

Specify the date output format. Values are: rfc_822 and iso_8601. Defaults to rfc_822.

- -
-
-text
-
- -

Print out the CRL in text form.

- -
-
-verify
-
- -

Verify the signature in the CRL. If the verification fails, the program will immediately exit, i.e. further option processing (e.g. -gendelta) is skipped.

- -

This option is implicitly enabled if any of -CApath, -CAfile or -CAstore is specified.

- -
-
-noout
-
- -

Don't output the encoded version of the CRL.

- -
-
-fingerprint
-
- -

Output the fingerprint of the CRL.

- -
-
-crlnumber
-
- -

Output the number of the CRL.

- -
-
-hash
-
- -

Output a hash of the issuer name. This can be use to lookup CRLs in a directory by issuer name.

- -
-
-hash_old
-
- -

Outputs the "hash" of the CRL issuer name using the older algorithm as used by OpenSSL before version 1.0.0.

- -
-
-issuer
-
- -

Output the issuer name.

- -
-
-lastupdate
-
- -

Output the lastUpdate field.

- -
-
-nextupdate
-
- -

Output the nextUpdate field.

- -
-
-nameopt option
-
- -

This specifies how the subject or issuer names are displayed. See openssl-namedisplay-options(1) for details.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

EXAMPLES

- -

Convert a CRL file from PEM to DER:

- -
openssl crl -in crl.pem -outform DER -out crl.der
- -

Output the text form of a DER encoded certificate:

- -
openssl crl -in crl.der -text -noout
- -

BUGS

- -

Ideally it should be possible to create a CRL using appropriate options and files too.

- -

SEE ALSO

- -

openssl(1), openssl-crl2pkcs7(1), openssl-ca(1), openssl-x509(1), ossl_store-file(7)

- -

HISTORY

- -

Since OpenSSL 3.3, the -verify option will exit with 1 on failure.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-crl2pkcs7.html b/openssl-install/share/doc/openssl/html/man1/openssl-crl2pkcs7.html deleted file mode 100644 index 6364653c..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-crl2pkcs7.html +++ /dev/null @@ -1,133 +0,0 @@ - - - - -openssl-crl2pkcs7 - - - - - - - - - - -

NAME

- -

openssl-crl2pkcs7 - Create a PKCS#7 structure from a CRL and certificates

- -

SYNOPSIS

- -

openssl crl2pkcs7 [-help] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-out filename] [-certfile filename] [-nocrl] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command takes an optional CRL and one or more certificates and converts them into a PKCS#7 degenerate "certificates only" structure.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM
-
- -

The input format of the CRL; the default is PEM. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The output format of the PKCS#7 object; the default is PEM. See openssl-format-options(1) for details.

- -
-
-in filename
-
- -

This specifies the input filename to read a CRL from or standard input if this option is not specified.

- -
-
-out filename
-
- -

Specifies the output filename to write the PKCS#7 structure to or standard output by default.

- -
-
-certfile filename
-
- -

Specifies a filename containing one or more certificates in PEM format. All certificates in the file will be added to the PKCS#7 structure. This option can be used more than once to read certificates from multiple files.

- -
-
-nocrl
-
- -

Normally a CRL is included in the output file. With this option no CRL is included in the output file and a CRL is not read from the input file.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

EXAMPLES

- -

Create a PKCS#7 structure from a certificate and CRL:

- -
openssl crl2pkcs7 -in crl.pem -certfile cert.pem -out p7.pem
- -

Creates a PKCS#7 structure in DER format with no CRL from several different certificates:

- -
openssl crl2pkcs7 -nocrl -certfile newcert.pem
-       -certfile demoCA/cacert.pem -outform DER -out p7.der
- -

NOTES

- -

The output file is a PKCS#7 signed data structure containing no signers and just certificates and an optional CRL.

- -

This command can be used to send certificates and CAs to Netscape as part of the certificate enrollment process. This involves sending the DER encoded output as MIME type application/x-x509-user-cert.

- -

The PEM encoded form with the header and footer lines removed can be used to install user certificates and CAs in MSIE using the Xenroll control.

- -

SEE ALSO

- -

openssl(1), openssl-pkcs7(1)

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-dgst.html b/openssl-install/share/doc/openssl/html/man1/openssl-dgst.html deleted file mode 100644 index 96153c5a..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-dgst.html +++ /dev/null @@ -1,297 +0,0 @@ - - - - -openssl-dgst - - - - - - - - - - -

NAME

- -

openssl-dgst - perform digest operations

- -

SYNOPSIS

- -

openssl dgst|digest [-digest] [-list] [-help] [-c] [-d] [-debug] [-hex] [-binary] [-xoflen length] [-r] [-out filename] [-sign filename|uri] [-keyform DER|PEM|P12|ENGINE] [-passin arg] [-verify filename] [-prverify filename] [-signature filename] [-sigopt nm:v] [-hmac key] [-mac alg] [-macopt nm:v] [-fips-fingerprint] [-engine id] [-engine_impl id] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq] [file ...]

- -

DESCRIPTION

- -

This command output the message digest of a supplied file or files in hexadecimal, and also generates and verifies digital signatures using message digests.

- -

The generic name, openssl dgst, may be used with an option specifying the algorithm to be used. The default digest is sha256. A supported digest name may also be used as the sub-command name. To see the list of supported algorithms, use openssl list -digest-algorithms

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-digest
-
- -

Specifies name of a supported digest to be used. See option -list below :

- -
-
-list
-
- -

Prints out a list of supported message digests.

- -
-
-c
-
- -

Print out the digest in two digit groups separated by colons, only relevant if the -hex option is given as well.

- -
-
-d, -debug
-
- -

Print out BIO debugging information.

- -
-
-hex
-
- -

Digest is to be output as a hex dump. This is the default case for a "normal" digest as opposed to a digital signature. See NOTES below for digital signatures using -hex.

- -
-
-binary
-
- -

Output the digest or signature in binary form.

- -
-
-xoflen length
-
- -

Set the output length for XOF algorithms, such as shake128 and shake256. This option is not supported for signing operations.

- -

For OpenSSL providers it is required to set this value for shake algorithms, since the previous default values were only set to supply half of the maximum security strength.

- -

To ensure the maximum security strength of 128 bits, the xoflen for shake128 should be set to at least 32 (bytes). For compatibility with previous versions of OpenSSL, it may be set to 16, resulting in a security strength of only 64 bits.

- -

To ensure the maximum security strength of 256 bits, the xoflen for shake256 should be set to at least 64 (bytes). For compatibility with previous versions of OpenSSL, it may be set to 32, resulting in a security strength of only 128 bits.

- -
-
-r
-
- -

Output the digest in the "coreutils" format, including newlines. Used by programs like sha1sum(1).

- -
-
-out filename
-
- -

Filename to output to, or standard output by default.

- -
-
-sign filename|uri
-
- -

Digitally sign the digest using the given private key. Note this option does not support Ed25519 or Ed448 private keys. Use the openssl-pkeyutl(1) command instead for this.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The format of the key to sign with; unspecified by default. See openssl-format-options(1) for details.

- -
-
-sigopt nm:v
-
- -

Pass options to the signature algorithm during sign or verify operations. Names and values of these options are algorithm-specific and documented in "Signature parameters" in provider-signature(7).

- -
-
-passin arg
-
- -

The private key password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-verify filename
-
- -

Verify the signature using the public key in "filename". The output is either "Verified OK" or "Verification Failure".

- -
-
-prverify filename
-
- -

Verify the signature using the private key in "filename".

- -
-
-signature filename
-
- -

The actual signature to verify.

- -
-
-hmac key
-
- -

Create a hashed MAC using "key".

- -

The openssl-mac(1) command should be preferred to using this command line option.

- -
-
-mac alg
-
- -

Create MAC (keyed Message Authentication Code). The most popular MAC algorithm is HMAC (hash-based MAC), but there are other MAC algorithms which are not based on hash, for instance gost-mac algorithm, supported by the gost engine. MAC keys and other options should be set via -macopt parameter.

- -

The openssl-mac(1) command should be preferred to using this command line option.

- -
-
-macopt nm:v
-
- -

Passes options to MAC algorithm, specified by -mac key. Following options are supported by both by HMAC and gost-mac:

- -
- -
key:string
-
- -

Specifies MAC key as alphanumeric string (use if key contain printable characters only). String length must conform to any restrictions of the MAC algorithm for example exactly 32 chars for gost-mac.

- -
-
hexkey:string
-
- -

Specifies MAC key in hexadecimal form (two hex digits per byte). Key length must conform to any restrictions of the MAC algorithm for example exactly 32 chars for gost-mac.

- -
-
- -

The openssl-mac(1) command should be preferred to using this command line option.

- -
-
-fips-fingerprint
-
- -

Compute HMAC using a specific key for certain OpenSSL-FIPS operations.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -

The engine is not used for digests unless the -engine_impl option is used or it is configured to do so, see "Engine Configuration Module" in config(5).

- -
-
-engine_impl id
-
- -

When used with the -engine option, it specifies to also use engine id for digest operations.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
file ...
-
- -

File or files to digest. If no files are specified then standard input is used.

- -
-
- -

EXAMPLES

- -

To create a hex-encoded message digest of a file:

- -
openssl dgst -md5 -hex file.txt
-or
-openssl md5 file.txt
- -

To sign a file using SHA-256 with binary file output:

- -
openssl dgst -sha256 -sign privatekey.pem -out signature.sign file.txt
-or
-openssl sha256 -sign privatekey.pem -out signature.sign file.txt
- -

To verify a signature:

- -
openssl dgst -sha256 -verify publickey.pem \
--signature signature.sign \
-file.txt
- -

NOTES

- -

The digest mechanisms that are available will depend on the options used when building OpenSSL. The openssl list -digest-algorithms command can be used to list them.

- -

New or agile applications should use probably use SHA-256. Other digests, particularly SHA-1 and MD5, are still widely used for interoperating with existing formats and protocols.

- -

When signing a file, this command will automatically determine the algorithm (RSA, ECC, etc) to use for signing based on the private key's ASN.1 info. When verifying signatures, it only handles the RSA, DSA, or ECDSA signature itself, not the related data to identify the signer and algorithm used in formats such as x.509, CMS, and S/MIME.

- -

A source of random numbers is required for certain signing algorithms, in particular ECDSA and DSA.

- -

The signing and verify options should only be used if a single file is being signed or verified.

- -

Hex signatures cannot be verified using openssl. Instead, use "xxd -r" or similar program to transform the hex signature into a binary signature prior to verification.

- -

The openssl-mac(1) command is preferred over the -hmac, -mac and -macopt command line options.

- -

SEE ALSO

- -

openssl-mac(1)

- -

HISTORY

- -

The default digest was changed from MD5 to SHA256 in OpenSSL 1.1.0. The FIPS-related options were removed in OpenSSL 1.1.0.

- -

The -engine and -engine_impl options were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-dhparam.html b/openssl-install/share/doc/openssl/html/man1/openssl-dhparam.html deleted file mode 100644 index 2e251833..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-dhparam.html +++ /dev/null @@ -1,170 +0,0 @@ - - - - -openssl-dhparam - - - - - - - - - - -

NAME

- -

openssl-dhparam - DH parameter manipulation and generation

- -

SYNOPSIS

- -

openssl dhparam [-help] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-out filename] [-dsaparam] [-check] [-noout] [-text] [-verbose] [-quiet] [-2] [-3] [-5] [-engine id] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq] [numbits]

- -

DESCRIPTION

- -

This command is used to manipulate DH parameter files.

- -

See "EXAMPLES" in openssl-genpkey(1) for examples on how to generate a key using a named safe prime group without generating intermediate parameters.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM, -outform DER|PEM
-
- -

The input format and output format; the default is PEM. The object is compatible with the PKCS#3 DHparameter structure. See openssl-format-options(1) for details.

- -
-
-in filename
-
- -

This specifies the input filename to read parameters from or standard input if this option is not specified.

- -
-
-out filename
-
- -

This specifies the output filename parameters to. Standard output is used if this option is not present. The output filename should not be the same as the input filename.

- -
-
-dsaparam
-
- -

If this option is used, DSA rather than DH parameters are read or created; they are converted to DH format. Otherwise, safe primes (such that (p-1)/2 is also prime) will be used for DH parameter generation.

- -

DH parameter generation with the -dsaparam option is much faster. Beware that with such DSA-style DH parameters, a fresh DH key should be created for each use to avoid small-subgroup attacks that may be possible otherwise.

- -
-
-check
-
- -

Performs numerous checks to see if the supplied parameters are valid and displays a warning if not.

- -
-
-2, -3, -5
-
- -

The generator to use, either 2, 3 or 5. If present then the input file is ignored and parameters are generated instead. If not present but numbits is present, parameters are generated with the default generator 2.

- -
-
numbits
-
- -

This option specifies that a parameter set should be generated of size numbits. It must be the last option. If this option is present then the input file is ignored and parameters are generated instead. If this option is not present but a generator (-2, -3 or -5) is present, parameters are generated with a default length of 2048 bits. The minimum length is 512 bits. The maximum length is 10000 bits.

- -
-
-noout
-
- -

This option inhibits the output of the encoded version of the parameters.

- -
-
-text
-
- -

This option prints out the DH parameters in human readable form.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-verbose
-
- -

This option enables the output of progress messages, which is handy when running commands interactively that may take a long time to execute.

- -
-
-quiet
-
- -

This option suppresses the output of progress messages, which may be undesirable in batch scripts or pipelines.

- -
-
- -

NOTES

- -

This command replaces the dh and gendh commands of previous releases.

- -

SEE ALSO

- -

openssl(1), openssl-pkeyparam(1), openssl-dsaparam(1), openssl-genpkey(1).

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -C option was removed in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-dsa.html b/openssl-install/share/doc/openssl/html/man1/openssl-dsa.html deleted file mode 100644 index 156c4fbd..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-dsa.html +++ /dev/null @@ -1,202 +0,0 @@ - - - - -openssl-dsa - - - - - - - - - - -

NAME

- -

openssl-dsa - DSA key processing

- -

SYNOPSIS

- -

openssl dsa [-help] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-passin arg] [-out filename] [-passout arg] [-aes128] [-aes192] [-aes256] [-aria128] [-aria192] [-aria256] [-camellia128] [-camellia192] [-camellia256] [-des] [-des3] [-idea] [-text] [-noout] [-modulus] [-pubin] [-pubout] [-pvk-strong] [-pvk-weak] [-pvk-none] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command processes DSA keys. They can be converted between various forms and their components printed out. Note This command uses the traditional SSLeay compatible format for private key encryption: newer applications should use the more secure PKCS#8 format using the pkcs8

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM
-
- -

The key input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The key output format; the default is PEM. See openssl-format-options(1) for details.

- -

Private keys are a sequence of ASN.1 INTEGERS: the version (zero), p, q, g, and the public and private key components. Public keys are a SubjectPublicKeyInfo structure with the DSA type.

- -

The PEM format also accepts PKCS#8 data.

- -
-
-in filename
-
- -

This specifies the input filename to read a key from or standard input if this option is not specified. If the key is encrypted a pass phrase will be prompted for.

- -
-
-out filename
-
- -

This specifies the output filename to write a key to or standard output by is not specified. If any encryption options are set then a pass phrase will be prompted for. The output filename should not be the same as the input filename.

- -
-
-passin arg, -passout arg
-
- -

The password source for the input and output file. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea
-
- -

These options encrypt the private key with the specified cipher before outputting it. A pass phrase is prompted for. If none of these options is specified the key is written in plain text. This means that this command can be used to remove the pass phrase from a key by not giving any encryption option is given, or to add or change the pass phrase by setting them. These options can only be used with PEM format output files.

- -
-
-text
-
- -

Prints out the public, private key components and parameters.

- -
-
-noout
-
- -

This option prevents output of the encoded version of the key.

- -
-
-modulus
-
- -

This option prints out the value of the public key component of the key.

- -
-
-pubin
-
- -

By default, a private key is read from the input. With this option a public key is read instead. If the input contains no public key but a private key, its public part is used.

- -
-
-pubout
-
- -

By default, a private key is output. With this option a public key will be output instead. This option is automatically set if the input is a public key.

- -
-
-pvk-strong
-
- -

Enable 'Strong' PVK encoding level (default).

- -
-
-pvk-weak
-
- -

Enable 'Weak' PVK encoding level.

- -
-
-pvk-none
-
- -

Don't enforce PVK encoding.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

The openssl-pkey(1) command is capable of performing all the operations this command can, as well as supporting other public key types.

- -

EXAMPLES

- -

The documentation for the openssl-pkey(1) command contains examples equivalent to the ones listed here.

- -

To remove the pass phrase on a DSA private key:

- -
openssl dsa -in key.pem -out keyout.pem
- -

To encrypt a private key using triple DES:

- -
openssl dsa -in key.pem -des3 -out keyout.pem
- -

To convert a private key from PEM to DER format:

- -
openssl dsa -in key.pem -outform DER -out keyout.der
- -

To print out the components of a private key to standard output:

- -
openssl dsa -in key.pem -text -noout
- -

To just output the public part of a private key:

- -
openssl dsa -in key.pem -pubout -out pubkey.pem
- -

SEE ALSO

- -

openssl(1), openssl-pkey(1), openssl-dsaparam(1), openssl-gendsa(1), openssl-rsa(1), openssl-genrsa(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-dsaparam.html b/openssl-install/share/doc/openssl/html/man1/openssl-dsaparam.html deleted file mode 100644 index 14e34c95..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-dsaparam.html +++ /dev/null @@ -1,165 +0,0 @@ - - - - -openssl-dsaparam - - - - - - - - - - -

NAME

- -

openssl-dsaparam - DSA parameter manipulation and generation

- -

SYNOPSIS

- -

openssl dsaparam [-help] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-out filename] [-noout] [-text] [-genkey] [-verbose] [-quiet] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [numbits] [numqbits]

- -

DESCRIPTION

- -

This command is used to manipulate or generate DSA parameter files.

- -

DSA parameter generation can be a slow process and as a result the same set of DSA parameters is often used to generate several distinct keys.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM
-
- -

The DSA parameters input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The DSA parameters output format; the default is PEM. See openssl-format-options(1) for details.

- -

Parameters are a sequence of ASN.1 INTEGERs: p, q, and g. This is compatible with RFC 2459 DSS-Parms structure.

- -
-
-in filename
-
- -

This specifies the input filename to read parameters from or standard input if this option is not specified. If the numbits parameter is included then this option will be ignored.

- -
-
-out filename
-
- -

This specifies the output filename parameters to. Standard output is used if this option is not present. The output filename should not be the same as the input filename.

- -
-
-noout
-
- -

This option inhibits the output of the encoded version of the parameters.

- -
-
-text
-
- -

This option prints out the DSA parameters in human readable form.

- -
-
-genkey
-
- -

This option will generate a DSA either using the specified or generated parameters.

- -
-
-verbose
-
- -

Print extra details about the operations being performed.

- -
-
-quiet
-
- -

Print fewer details about the operations being performed, which may be handy during batch scripts and pipelines.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
numbits
-
- -

This optional argument specifies that a parameter set should be generated of size numbits. If this argument is included then the input file (if any) is ignored.

- -
-
numqbits
-
- -

This optional argument specifies that a parameter set should be generated with a subprime parameter q of size numqbits. It must be the last argument. If this argument is included then the input file (if any) is ignored.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

SEE ALSO

- -

openssl(1), openssl-pkeyparam(1), openssl-gendsa(1), openssl-dsa(1), openssl-genrsa(1), openssl-rsa(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -C option was removed in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-ec.html b/openssl-install/share/doc/openssl/html/man1/openssl-ec.html deleted file mode 100644 index 558743b2..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-ec.html +++ /dev/null @@ -1,212 +0,0 @@ - - - - -openssl-ec - - - - - - - - - - -

NAME

- -

openssl-ec - EC key processing

- -

SYNOPSIS

- -

openssl ec [-help] [-inform DER|PEM|P12|ENGINE] [-outform DER|PEM] [-in filename|uri] [-passin arg] [-out filename] [-passout arg] [-des] [-des3] [-idea] [-text] [-noout] [-param_out] [-pubin] [-pubout] [-conv_form arg] [-param_enc arg] [-no_public] [-check] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

The openssl-ec(1) command processes EC keys. They can be converted between various forms and their components printed out. Note OpenSSL uses the private key format specified in 'SEC 1: Elliptic Curve Cryptography' (http://www.secg.org/). To convert an OpenSSL EC private key into the PKCS#8 private key format use the openssl-pkcs8(1) command.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM|P12|ENGINE
-
- -

The key input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The key output format; the default is PEM. See openssl-format-options(1) for details.

- -

Private keys are an SEC1 private key or PKCS#8 format. Public keys are a SubjectPublicKeyInfo as specified in IETF RFC 3280.

- -
-
-in filename|uri
-
- -

This specifies the input to read a key from or standard input if this option is not specified. If the key is encrypted a pass phrase will be prompted for.

- -
-
-out filename
-
- -

This specifies the output filename to write a key to or standard output by is not specified. If any encryption options are set then a pass phrase will be prompted for. The output filename should not be the same as the input filename.

- -
-
-passin arg, -passout arg
-
- -

The password source for the input and output file. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-des|-des3|-idea
-
- -

These options encrypt the private key with the DES, triple DES, IDEA or any other cipher supported by OpenSSL before outputting it. A pass phrase is prompted for. If none of these options is specified the key is written in plain text. This means that using this command to read in an encrypted key with no encryption option can be used to remove the pass phrase from a key, or by setting the encryption options it can be use to add or change the pass phrase. These options can only be used with PEM format output files.

- -
-
-text
-
- -

Prints out the public, private key components and parameters.

- -
-
-noout
-
- -

This option prevents output of the encoded version of the key.

- -
-
-param_out
-
- -

Print the elliptic curve parameters.

- -
-
-pubin
-
- -

By default a private key is read from the input. With this option a public key is read instead. If the input contains no public key but a private key, its public part is used.

- -
-
-pubout
-
- -

By default a private key is output. With this option a public key will be output instead. This option is automatically set if the input is a public key.

- -
-
-conv_form arg
-
- -

This specifies how the points on the elliptic curve are converted into octet strings. Possible values are: compressed, uncompressed (the default value) and hybrid. For more information regarding the point conversion forms please read the X9.62 standard. Note Due to patent issues the compressed option is disabled by default for binary curves and can be enabled by defining the preprocessor macro OPENSSL_EC_BIN_PT_COMP at compile time.

- -
-
-param_enc arg
-
- -

This specifies how the elliptic curve parameters are encoded. Possible value are: named_curve, i.e. the ec parameters are specified by an OID, or explicit where the ec parameters are explicitly given (see RFC 3279 for the definition of the EC parameters structures). The default value is named_curve. Note the implicitlyCA alternative, as specified in RFC 3279, is currently not implemented in OpenSSL.

- -
-
-no_public
-
- -

This option omits the public key components from the private key output.

- -
-
-check
-
- -

This option checks the consistency of an EC private or public key.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

The openssl-pkey(1) command is capable of performing all the operations this command can, as well as supporting other public key types.

- -

EXAMPLES

- -

The documentation for the openssl-pkey(1) command contains examples equivalent to the ones listed here.

- -

To encrypt a private key using triple DES:

- -
openssl ec -in key.pem -des3 -out keyout.pem
- -

To convert a private key from PEM to DER format:

- -
openssl ec -in key.pem -outform DER -out keyout.der
- -

To print out the components of a private key to standard output:

- -
openssl ec -in key.pem -text -noout
- -

To just output the public part of a private key:

- -
openssl ec -in key.pem -pubout -out pubkey.pem
- -

To change the parameters encoding to explicit:

- -
openssl ec -in key.pem -param_enc explicit -out keyout.pem
- -

To change the point conversion form to compressed:

- -
openssl ec -in key.pem -conv_form compressed -out keyout.pem
- -

SEE ALSO

- -

openssl(1), openssl-pkey(1), openssl-ecparam(1), openssl-dsa(1), openssl-rsa(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -conv_form and -no_public options are no longer supported with keys loaded from an engine in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2003-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-ecparam.html b/openssl-install/share/doc/openssl/html/man1/openssl-ecparam.html deleted file mode 100644 index fae08c71..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-ecparam.html +++ /dev/null @@ -1,214 +0,0 @@ - - - - -openssl-ecparam - - - - - - - - - - -

NAME

- -

openssl-ecparam - EC parameter manipulation and generation

- -

SYNOPSIS

- -

openssl ecparam [-help] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-out filename] [-noout] [-text] [-check] [-check_named] [-name arg] [-list_curves] [-conv_form arg] [-param_enc arg] [-no_seed] [-genkey] [-engine id] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command is used to manipulate or generate EC parameter files.

- -

OpenSSL is currently not able to generate new groups and therefore this command can only create EC parameters from known (named) curves.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM
-
- -

The EC parameters input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The EC parameters output format; the default is PEM. See openssl-format-options(1) for details.

- -

Parameters are encoded as EcpkParameters as specified in IETF RFC 3279.

- -
-
-in filename
-
- -

This specifies the input filename to read parameters from or standard input if this option is not specified.

- -
-
-out filename
-
- -

This specifies the output filename parameters to. Standard output is used if this option is not present. The output filename should not be the same as the input filename.

- -
-
-noout
-
- -

This option inhibits the output of the encoded version of the parameters.

- -
-
-text
-
- -

This option prints out the EC parameters in human readable form.

- -
-
-check
-
- -

Validate the elliptic curve parameters.

- -
-
-check_named
-
- -

Validate the elliptic name curve parameters by checking if the curve parameters match any built-in curves.

- -
-
-name arg
-
- -

Use the EC parameters with the specified 'short' name. Use -list_curves to get a list of all currently implemented EC parameters.

- -
-
-list_curves
-
- -

Print out a list of all currently implemented EC parameters names and exit.

- -
-
-conv_form arg
-
- -

This specifies how the points on the elliptic curve are converted into octet strings. Possible values are: compressed, uncompressed (the default value) and hybrid. For more information regarding the point conversion forms please read the X9.62 standard. Note Due to patent issues the compressed option is disabled by default for binary curves and can be enabled by defining the preprocessor macro OPENSSL_EC_BIN_PT_COMP at compile time.

- -
-
-param_enc arg
-
- -

This specifies how the elliptic curve parameters are encoded. Possible value are: named_curve, i.e. the ec parameters are specified by an OID, or explicit where the ec parameters are explicitly given (see RFC 3279 for the definition of the EC parameters structures). The default value is named_curve. Note the implicitlyCA alternative, as specified in RFC 3279, is currently not implemented in OpenSSL.

- -
-
-no_seed
-
- -

This option inhibits that the 'seed' for the parameter generation is included in the ECParameters structure (see RFC 3279).

- -
-
-genkey
-
- -

This option will generate an EC private key using the specified parameters.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

The openssl-genpkey(1) and openssl-pkeyparam(1) commands are capable of performing all the operations this command can, as well as supporting other public key types.

- -

EXAMPLES

- -

The documentation for the openssl-genpkey(1) and openssl-pkeyparam(1) commands contains examples equivalent to the ones listed here.

- -

To create EC parameters with the group 'prime192v1':

- -
openssl ecparam -out ec_param.pem -name prime192v1
- -

To create EC parameters with explicit parameters:

- -
openssl ecparam -out ec_param.pem -name prime192v1 -param_enc explicit
- -

To validate given EC parameters:

- -
openssl ecparam -in ec_param.pem -check
- -

To create EC parameters and a private key:

- -
openssl ecparam -out ec_key.pem -name prime192v1 -genkey
- -

To change the point encoding to 'compressed':

- -
openssl ecparam -in ec_in.pem -out ec_out.pem -conv_form compressed
- -

To print out the EC parameters to standard output:

- -
openssl ecparam -in ec_param.pem -noout -text
- -

SEE ALSO

- -

openssl(1), openssl-pkeyparam(1), openssl-genpkey(1), openssl-ec(1), openssl-dsaparam(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -C option was removed in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2003-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-enc.html b/openssl-install/share/doc/openssl/html/man1/openssl-enc.html deleted file mode 100644 index c8e2fff8..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-enc.html +++ /dev/null @@ -1,467 +0,0 @@ - - - - -openssl-enc - - - - - - - - - - -

NAME

- -

openssl-enc - symmetric cipher routines

- -

SYNOPSIS

- -

openssl enc|cipher [-cipher] [-help] [-list] [-ciphers] [-in filename] [-out filename] [-pass arg] [-e] [-d] [-a] [-base64] [-A] [-k password] [-kfile filename] [-K key] [-iv IV] [-S salt] [-salt] [-nosalt] [-z] [-md digest] [-iter count] [-pbkdf2] [-saltlen size] [-p] [-P] [-bufsize number] [-nopad] [-v] [-debug] [-none] [-engine id] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq]

- -

openssl cipher [...]

- -

DESCRIPTION

- -

The symmetric cipher commands allow data to be encrypted or decrypted using various block and stream ciphers using keys based on passwords or explicitly provided. Base64 encoding or decoding can also be performed either by itself or in addition to the encryption or decryption.

- -

OPTIONS

- -
- -
-cipher
-
- -

The cipher to use.

- -
-
-help
-
- -

Print out a usage message.

- -
-
-list
-
- -

List all supported ciphers.

- -
-
-ciphers
-
- -

Alias of -list to display all supported ciphers.

- -
-
-in filename
-
- -

The input filename, standard input by default.

- -
-
-out filename
-
- -

The output filename, standard output by default.

- -
-
-pass arg
-
- -

The password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-e
-
- -

Encrypt the input data: this is the default.

- -
-
-d
-
- -

Decrypt the input data.

- -
-
-a
-
- -

Base64 process the data. This means that if encryption is taking place the data is base64 encoded after encryption. If decryption is set then the input data is base64 decoded before being decrypted.

- -

When the -A option not given, on encoding a newline is inserted after each 64 characters, and on decoding a newline is expected among the first 1024 bytes of input.

- -
-
-base64
-
- -

Same as -a

- -
-
-A
-
- -

If the -a option is set then base64 encoding produces output without any newline character, and base64 decoding does not require any newlines. Therefore it can be helpful to use the -A option when decoding unknown input.

- -
-
-k password
-
- -

The password to derive the key from. This is for compatibility with previous versions of OpenSSL. Superseded by the -pass argument.

- -
-
-kfile filename
-
- -

Read the password to derive the key from the first line of filename. This is for compatibility with previous versions of OpenSSL. Superseded by the -pass argument.

- -
-
-md digest
-
- -

Use the specified digest to create the key from the passphrase. The default algorithm is sha-256.

- -
-
-iter count
-
- -

Use a given number of iterations on the password in deriving the encryption key. High values increase the time required to brute-force the resulting file. This option enables the use of PBKDF2 algorithm to derive the key.

- -
-
-pbkdf2
-
- -

Use PBKDF2 algorithm with a default iteration count of 10000 unless otherwise specified by the -iter command line option.

- -
-
-saltlen
-
- -

Set the salt length to use when using the -pbkdf2 option. For compatibility reasons, the default is 8 bytes. The maximum value is currently 16 bytes. If the -pbkdf2 option is not used, then this option is ignored and a fixed salt length of 8 is used. The salt length used when encrypting must also be used when decrypting.

- -
-
-nosalt
-
- -

Don't use a salt in the key derivation routines. This option SHOULD NOT be used except for test purposes or compatibility with ancient versions of OpenSSL.

- -
-
-salt
-
- -

Use salt (randomly generated or provide with -S option) when encrypting, this is the default.

- -
-
-S salt
-
- -

The actual salt to use: this must be represented as a string of hex digits. If this option is used while encrypting, the same exact value will be needed again during decryption. This salt may be truncated or zero padded to match the salt length (See -saltlen).

- -
-
-K key
-
- -

The actual key to use: this must be represented as a string comprised only of hex digits. If only the key is specified, the IV must additionally specified using the -iv option. When both a key and a password are specified, the key given with the -K option will be used and the IV generated from the password will be taken. It does not make much sense to specify both key and password.

- -
-
-iv IV
-
- -

The actual IV to use: this must be represented as a string comprised only of hex digits. When only the key is specified using the -K option, the IV must explicitly be defined. When a password is being specified using one of the other options, the IV is generated from this password.

- -
-
-p
-
- -

Print out the key and IV used.

- -
-
-P
-
- -

Print out the key and IV used then immediately exit: don't do any encryption or decryption.

- -
-
-bufsize number
-
- -

Set the buffer size for I/O.

- -
-
-nopad
-
- -

Disable standard block padding.

- -
-
-v
-
- -

Verbose print; display some statistics about I/O and buffer sizes.

- -
-
-debug
-
- -

Debug the BIOs used for I/O.

- -
-
-z
-
- -

Compress or decompress encrypted data using zlib after encryption or before decryption. This option exists only if OpenSSL was compiled with the zlib or zlib-dynamic option.

- -
-
-none
-
- -

Use NULL cipher (no encryption or decryption of input).

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
- -

NOTES

- -

The program can be called either as openssl cipher or openssl enc -cipher. The first form doesn't work with engine-provided ciphers, because this form is processed before the configuration file is read and any ENGINEs loaded. Use the openssl-list(1) command to get a list of supported ciphers.

- -

Engines which provide entirely new encryption algorithms (such as the ccgost engine which provides gost89 algorithm) should be configured in the configuration file. Engines specified on the command line using -engine option can only be used for hardware-assisted implementations of ciphers which are supported by the OpenSSL core or another engine specified in the configuration file.

- -

When the enc command lists supported ciphers, ciphers provided by engines, specified in the configuration files are listed too.

- -

A password will be prompted for to derive the key and IV if necessary.

- -

The -salt option should ALWAYS be used if the key is being derived from a password unless you want compatibility with previous versions of OpenSSL.

- -

Without the -salt option it is possible to perform efficient dictionary attacks on the password and to attack stream cipher encrypted data. The reason for this is that without the salt the same password always generates the same encryption key.

- -

When the salt is generated at random (that means when encrypting using a passphrase without explicit salt given using -S option), the first bytes of the encrypted data are reserved to store the salt for later decrypting.

- -

Some of the ciphers do not have large keys and others have security implications if not used correctly. A beginner is advised to just use a strong block cipher, such as AES, in CBC mode.

- -

All the block ciphers normally use PKCS#5 padding, also known as standard block padding. This allows a rudimentary integrity or password check to be performed. However, since the chance of random data passing the test is better than 1 in 256 it isn't a very good test.

- -

If padding is disabled then the input data must be a multiple of the cipher block length.

- -

All RC2 ciphers have the same key and effective key length.

- -

Blowfish and RC5 algorithms use a 128 bit key.

- -

Please note that OpenSSL 3.0 changed the effect of the -S option. Any explicit salt value specified via this option is no longer prepended to the ciphertext when encrypting, and must again be explicitly provided when decrypting. Conversely, when the -S option is used during decryption, the ciphertext is expected to not have a prepended salt value.

- -

When using OpenSSL 3.0 or later to decrypt data that was encrypted with an explicit salt under OpenSSL 1.1.1 do not use the -S option, the salt will then be read from the ciphertext. To generate ciphertext that can be decrypted with OpenSSL 1.1.1 do not use the -S option, the salt will be then be generated randomly and prepended to the output.

- -

SUPPORTED CIPHERS

- -

Note that some of these ciphers can be disabled at compile time and some are available only if an appropriate engine is configured in the configuration file. The output when invoking this command with the -list option (that is openssl enc -list) is a list of ciphers, supported by your version of OpenSSL, including ones provided by configured engines.

- -

This command does not support authenticated encryption modes like CCM and GCM, and will not support such modes in the future. This is due to having to begin streaming output (e.g., to standard output when -out is not used) before the authentication tag could be validated. When this command is used in a pipeline, the receiving end will not be able to roll back upon authentication failure. The AEAD modes currently in common use also suffer from catastrophic failure of confidentiality and/or integrity upon reuse of key/iv/nonce, and since openssl enc places the entire burden of key/iv/nonce management upon the user, the risk of exposing AEAD modes is too great to allow. These key/iv/nonce management issues also affect other modes currently exposed in this command, but the failure modes are less extreme in these cases, and the functionality cannot be removed with a stable release branch. For bulk encryption of data, whether using authenticated encryption modes or other modes, openssl-cms(1) is recommended, as it provides a standard data format and performs the needed key/iv/nonce management.

- -

When enc is used with key wrapping modes the input data cannot be streamed, meaning it must be processed in a single pass. Consequently, the input data size must be less than the buffer size (-bufsize arg, default to 8*1024 bytes). The '*-wrap' ciphers require the input to be a multiple of 8 bytes long, because no padding is involved. The '*-wrap-pad' ciphers allow any input length. In both cases, no IV is needed. See example below.

- -
base64             Base 64
-
-bf-cbc             Blowfish in CBC mode
-bf                 Alias for bf-cbc
-blowfish           Alias for bf-cbc
-bf-cfb             Blowfish in CFB mode
-bf-ecb             Blowfish in ECB mode
-bf-ofb             Blowfish in OFB mode
-
-cast-cbc           CAST in CBC mode
-cast               Alias for cast-cbc
-cast5-cbc          CAST5 in CBC mode
-cast5-cfb          CAST5 in CFB mode
-cast5-ecb          CAST5 in ECB mode
-cast5-ofb          CAST5 in OFB mode
-
-chacha20           ChaCha20 algorithm
-
-des-cbc            DES in CBC mode
-des                Alias for des-cbc
-des-cfb            DES in CFB mode
-des-ofb            DES in OFB mode
-des-ecb            DES in ECB mode
-
-des-ede-cbc        Two key triple DES EDE in CBC mode
-des-ede            Two key triple DES EDE in ECB mode
-des-ede-cfb        Two key triple DES EDE in CFB mode
-des-ede-ofb        Two key triple DES EDE in OFB mode
-
-des-ede3-cbc       Three key triple DES EDE in CBC mode
-des-ede3           Three key triple DES EDE in ECB mode
-des3               Alias for des-ede3-cbc
-des-ede3-cfb       Three key triple DES EDE CFB mode
-des-ede3-ofb       Three key triple DES EDE in OFB mode
-
-desx               DESX algorithm.
-
-gost89             GOST 28147-89 in CFB mode (provided by ccgost engine)
-gost89-cnt         GOST 28147-89 in CNT mode (provided by ccgost engine)
-
-idea-cbc           IDEA algorithm in CBC mode
-idea               same as idea-cbc
-idea-cfb           IDEA in CFB mode
-idea-ecb           IDEA in ECB mode
-idea-ofb           IDEA in OFB mode
-
-rc2-cbc            128 bit RC2 in CBC mode
-rc2                Alias for rc2-cbc
-rc2-cfb            128 bit RC2 in CFB mode
-rc2-ecb            128 bit RC2 in ECB mode
-rc2-ofb            128 bit RC2 in OFB mode
-rc2-64-cbc         64 bit RC2 in CBC mode
-rc2-40-cbc         40 bit RC2 in CBC mode
-
-rc4                128 bit RC4
-rc4-64             64 bit RC4
-rc4-40             40 bit RC4
-
-rc5-cbc            RC5 cipher in CBC mode
-rc5                Alias for rc5-cbc
-rc5-cfb            RC5 cipher in CFB mode
-rc5-ecb            RC5 cipher in ECB mode
-rc5-ofb            RC5 cipher in OFB mode
-
-seed-cbc           SEED cipher in CBC mode
-seed               Alias for seed-cbc
-seed-cfb           SEED cipher in CFB mode
-seed-ecb           SEED cipher in ECB mode
-seed-ofb           SEED cipher in OFB mode
-
-sm4-cbc            SM4 cipher in CBC mode
-sm4                Alias for sm4-cbc
-sm4-cfb            SM4 cipher in CFB mode
-sm4-ctr            SM4 cipher in CTR mode
-sm4-ecb            SM4 cipher in ECB mode
-sm4-ofb            SM4 cipher in OFB mode
-
-aes-[128|192|256]-cbc  128/192/256 bit AES in CBC mode
-aes[128|192|256]       Alias for aes-[128|192|256]-cbc
-aes-[128|192|256]-cfb  128/192/256 bit AES in 128 bit CFB mode
-aes-[128|192|256]-cfb1 128/192/256 bit AES in 1 bit CFB mode
-aes-[128|192|256]-cfb8 128/192/256 bit AES in 8 bit CFB mode
-aes-[128|192|256]-ctr  128/192/256 bit AES in CTR mode
-aes-[128|192|256]-ecb  128/192/256 bit AES in ECB mode
-aes-[128|192|256]-ofb  128/192/256 bit AES in OFB mode
-
-aes-[128|192|256]-wrap     key wrapping using 128/192/256 bit AES
-aes-[128|192|256]-wrap-pad key wrapping with padding using 128/192/256 bit AES
-
-aria-[128|192|256]-cbc  128/192/256 bit ARIA in CBC mode
-aria[128|192|256]       Alias for aria-[128|192|256]-cbc
-aria-[128|192|256]-cfb  128/192/256 bit ARIA in 128 bit CFB mode
-aria-[128|192|256]-cfb1 128/192/256 bit ARIA in 1 bit CFB mode
-aria-[128|192|256]-cfb8 128/192/256 bit ARIA in 8 bit CFB mode
-aria-[128|192|256]-ctr  128/192/256 bit ARIA in CTR mode
-aria-[128|192|256]-ecb  128/192/256 bit ARIA in ECB mode
-aria-[128|192|256]-ofb  128/192/256 bit ARIA in OFB mode
-
-camellia-[128|192|256]-cbc  128/192/256 bit Camellia in CBC mode
-camellia[128|192|256]       Alias for camellia-[128|192|256]-cbc
-camellia-[128|192|256]-cfb  128/192/256 bit Camellia in 128 bit CFB mode
-camellia-[128|192|256]-cfb1 128/192/256 bit Camellia in 1 bit CFB mode
-camellia-[128|192|256]-cfb8 128/192/256 bit Camellia in 8 bit CFB mode
-camellia-[128|192|256]-ctr  128/192/256 bit Camellia in CTR mode
-camellia-[128|192|256]-ecb  128/192/256 bit Camellia in ECB mode
-camellia-[128|192|256]-ofb  128/192/256 bit Camellia in OFB mode
- -

EXAMPLES

- -

Just base64 encode a binary file:

- -
openssl base64 -in file.bin -out file.b64
- -

Decode the same file

- -
openssl base64 -d -in file.b64 -out file.bin
- -

Encrypt a file using AES-128 using a prompted password and PBKDF2 key derivation:

- -
openssl enc -aes128 -pbkdf2 -in file.txt -out file.aes128
- -

Decrypt a file using a supplied password:

- -
openssl enc -aes128 -pbkdf2 -d -in file.aes128 -out file.txt \
-   -pass pass:<password>
- -

Encrypt a file then base64 encode it (so it can be sent via mail for example) using AES-256 in CTR mode and PBKDF2 key derivation:

- -
openssl enc -aes-256-ctr -pbkdf2 -a -in file.txt -out file.aes256
- -

Base64 decode a file then decrypt it using a password supplied in a file:

- -
openssl enc -aes-256-ctr -pbkdf2 -d -a -in file.aes256 -out file.txt \
-   -pass file:<passfile>
- -

AES key wrapping:

- -
 openssl enc -e -a -id-aes128-wrap-pad -K 000102030405060708090A0B0C0D0E0F -in file.bin
-or
- openssl aes128-wrap-pad -e -a -K 000102030405060708090A0B0C0D0E0F -in file.bin
- -

BUGS

- -

The -A option when used with large files doesn't work properly. On the other hand, when base64 decoding without the -A option, if the first 1024 bytes of input do not include a newline character the first two lines of input are ignored.

- -

The openssl enc command only supports a fixed number of algorithms with certain parameters. So if, for example, you want to use RC2 with a 76 bit key or RC4 with an 84 bit key you can't use this program.

- -

HISTORY

- -

The default digest was changed from MD5 to SHA256 in OpenSSL 1.1.0.

- -

The -list option was added in OpenSSL 1.1.1e.

- -

The -ciphers and -engine options were deprecated in OpenSSL 3.0.

- -

The -saltlen option was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-engine.html b/openssl-install/share/doc/openssl/html/man1/openssl-engine.html deleted file mode 100644 index 80e08716..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-engine.html +++ /dev/null @@ -1,148 +0,0 @@ - - - - -openssl-engine - - - - - - - - - - -

NAME

- -

openssl-engine - load and query engines

- -

SYNOPSIS

- -

openssl engine [-help] [-v] [-vv] [-vvv] [-vvvv] [-c] [-t] [-tt] [-pre command] ... [-post command] ... [engine ...]

- -

DESCRIPTION

- -

This command has been deprecated. Providers should be used instead of engines.

- -

This command is used to query the status and capabilities of the specified engines. Engines may be specified before and after all other command-line flags. Only those specified are queried.

- -

OPTIONS

- -
- -
-help
-
- -

Display an option summary.

- -
-
-v -vv -vvv -vvvv
-
- -

Provides information about each specified engine. The first flag lists all the possible run-time control commands; the second adds a description of each command; the third adds the input flags, and the final option adds the internal input flags.

- -
-
-c
-
- -

Lists the capabilities of each engine.

- -
-
-t
-
- -

Tests if each specified engine is available, and displays the answer.

- -
-
-tt
-
- -

Displays an error trace for any unavailable engine.

- -
-
-pre command
-
- -
-
-post command
-
- -

Command-line configuration of engines. The -pre command is given to the engine before it is loaded and the -post command is given after the engine is loaded. The command is of the form cmd:val where cmd is the command, and val is the value for the command. See the example below.

- -

These two options are cumulative, so they may be given more than once in the same command.

- -
-
- -

EXAMPLES

- -

To list all the commands available to a dynamic engine:

- -
$ openssl engine -t -tt -vvvv dynamic
-(dynamic) Dynamic engine loading support
-     [ unavailable ]
-     SO_PATH: Specifies the path to the new ENGINE shared library
-          (input flags): STRING
-     NO_VCHECK: Specifies to continue even if version checking fails (boolean)
-          (input flags): NUMERIC
-     ID: Specifies an ENGINE id name for loading
-          (input flags): STRING
-     LIST_ADD: Whether to add a loaded ENGINE to the internal list (0=no,1=yes,2=mandatory)
-          (input flags): NUMERIC
-     DIR_LOAD: Specifies whether to load from 'DIR_ADD' directories (0=no,1=yes,2=mandatory)
-          (input flags): NUMERIC
-     DIR_ADD: Adds a directory from which ENGINEs can be loaded
-          (input flags): STRING
-     LOAD: Load up the ENGINE specified by other settings
-          (input flags): NO_INPUT
- -

To list the capabilities of the rsax engine:

- -
$ openssl engine -c
-(rsax) RSAX engine support
- [RSA]
-(dynamic) Dynamic engine loading support
- -

ENVIRONMENT

- -
- -
OPENSSL_ENGINES
-
- -

The path to the engines directory.

- -
-
- -

SEE ALSO

- -

openssl(1), config(5)

- -

HISTORY

- -

This command was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-errstr.html b/openssl-install/share/doc/openssl/html/man1/openssl-errstr.html deleted file mode 100644 index 811fdae4..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-errstr.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -openssl-errstr - - - - - - - - - - -

NAME

- -

openssl-errstr - lookup error codes

- -

SYNOPSIS

- -

openssl errstr [-help] error_code...

- -

DESCRIPTION

- -

Sometimes an application will not load error message texts and only numerical forms will be available. This command can be used to display the meaning of the hex code. The hex code is the hex digits after the second colon.

- -

OPTIONS

- -
- -
-help
-
- -

Display a usage message.

- -
-
- -

EXAMPLES

- -

The error code:

- -
27594:error:2006D080:lib(32)::reason(128)::107:
- -

can be displayed with:

- -
openssl errstr 2006D080
- -

to produce the error message:

- -
error:2006D080:BIO routines::no such file
- -

COPYRIGHT

- -

Copyright 2004-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-fipsinstall.html b/openssl-install/share/doc/openssl/html/man1/openssl-fipsinstall.html deleted file mode 100644 index 6ad460f7..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-fipsinstall.html +++ /dev/null @@ -1,434 +0,0 @@ - - - - -openssl-fipsinstall - - - - - - - - - - -

NAME

- -

openssl-fipsinstall - perform FIPS configuration installation

- -

SYNOPSIS

- -

openssl fipsinstall [-help] [-in configfilename] [-out configfilename] [-module modulefilename] [-provider_name providername] [-section_name sectionname] [-verify] [-mac_name macname] [-macopt nm:v] [-noout] [-quiet] [-pedantic] [-no_conditional_errors] [-no_security_checks] [-hmac_key_check] [-kmac_key_check] [-ems_check] [-no_drbg_truncated_digests] [-signature_digest_check] [-hkdf_digest_check] [-tls13_kdf_digest_check] [-tls1_prf_digest_check] [-sshkdf_digest_check] [-sskdf_digest_check] [-x963kdf_digest_check] [-dsa_sign_disabled] [-no_pbkdf2_lower_bound_check] [-no_short_mac] [-tdes_encrypt_disabled] [-rsa_pkcs15_padding_disabled] [-rsa_pss_saltlen_check] [-rsa_sign_x931_disabled] [-hkdf_key_check] [-kbkdf_key_check] [-tls13_kdf_key_check] [-tls1_prf_key_check] [-sshkdf_key_check] [-sskdf_key_check] [-x963kdf_key_check] [-x942kdf_key_check] [-ecdh_cofactor_check] [-self_test_onload] [-self_test_oninstall] [-corrupt_desc selftest_description] [-corrupt_type selftest_type] [-config parent_config]

- -

DESCRIPTION

- -

This command is used to generate a FIPS module configuration file. This configuration file can be used each time a FIPS module is loaded in order to pass data to the FIPS module self tests. The FIPS module always verifies its MAC, but optionally only needs to run the KAT's once, at installation.

- -

The generated configuration file consists of:

- -
- -
- A MAC of the FIPS module file.
-
- -
-
- A test status indicator.
-
- -

This indicates if the Known Answer Self Tests (KAT's) have successfully run.

- -
-
- A MAC of the status indicator.
-
- -
-
- A control for conditional self tests errors.
-
- -

By default if a continuous test (e.g a key pair test) fails then the FIPS module will enter an error state, and no services or cryptographic algorithms will be able to be accessed after this point. The default value of '1' will cause the fips module error state to be entered. If the value is '0' then the module error state will not be entered. Regardless of whether the error state is entered or not, the current operation (e.g. key generation) will return an error. The user is responsible for retrying the operation if the module error state is not entered.

- -
-
- A control to indicate whether run-time security checks are done.
-
- -

This indicates if run-time checks related to enforcement of security parameters such as minimum security strength of keys and approved curve names are used. The default value of '1' will perform the checks. If the value is '0' the checks are not performed and FIPS compliance must be done by procedures documented in the relevant Security Policy.

- -
-
- -

This file is described in fips_config(5).

- -

OPTIONS

- -
- -
-help
-
- -

Print a usage message.

- -
-
-module filename
-
- -

Filename of the FIPS module to perform an integrity check on. The path provided in the filename is used to load the module when it is activated, and this overrides the environment variable OPENSSL_MODULES.

- -
-
-out configfilename
-
- -

Filename to output the configuration data to; the default is standard output.

- -
-
-in configfilename
-
- -

Input filename to load configuration data from. Must be used if the -verify option is specified.

- -
-
-verify
-
- -

Verify that the input configuration file contains the correct information.

- -
-
-provider_name providername
-
- -

Name of the provider inside the configuration file. The default value is fips.

- -
-
-section_name sectionname
-
- -

Name of the section inside the configuration file. The default value is fips_sect.

- -
-
-mac_name name
-
- -

Specifies the name of a supported MAC algorithm which will be used. The MAC mechanisms that are available will depend on the options used when building OpenSSL. To see the list of supported MAC's use the command openssl list -mac-algorithms. The default is HMAC.

- -
-
-macopt nm:v
-
- -

Passes options to the MAC algorithm. A comprehensive list of controls can be found in the EVP_MAC implementation documentation. Common control strings used for this command are:

- -
- -
key:string
-
- -

Specifies the MAC key as an alphanumeric string (use if the key contains printable characters only). The string length must conform to any restrictions of the MAC algorithm. A key must be specified for every MAC algorithm. If no key is provided, the default that was specified when OpenSSL was configured is used.

- -
-
hexkey:string
-
- -

Specifies the MAC key in hexadecimal form (two hex digits per byte). The key length must conform to any restrictions of the MAC algorithm. A key must be specified for every MAC algorithm. If no key is provided, the default that was specified when OpenSSL was configured is used.

- -
-
digest:string
-
- -

Used by HMAC as an alphanumeric string (use if the key contains printable characters only). The string length must conform to any restrictions of the MAC algorithm. To see the list of supported digests, use the command openssl list -digest-commands. The default digest is SHA-256.

- -
-
- -
-
-noout
-
- -

Disable logging of the self tests.

- -
-
-pedantic
-
- -

Configure the module so that it is strictly FIPS compliant rather than being backwards compatible. This enables conditional errors, security checks etc. Note that any previous configuration options will be overwritten and any subsequent configuration options that violate FIPS compliance will result in an error.

- -
-
-no_conditional_errors
-
- -

Configure the module to not enter an error state if a conditional self test fails as described above.

- -
-
-no_security_checks
-
- -

Configure the module to not perform run-time security checks as described above.

- -

Enabling the configuration option "no-fips-securitychecks" provides another way to turn off the check at compile time.

- -
-
-ems_check
-
- -

Configure the module to enable a run-time Extended Master Secret (EMS) check when using the TLS1_PRF KDF algorithm. This check is disabled by default. See RFC 7627 for information related to EMS.

- -
-
-no_short_mac
-
- -

Configure the module to not allow short MAC outputs. See SP 800-185 8.4.2 and FIPS 140-3 ID C.D for details.

- -
-
-hmac_key_check
-
- -

Configure the module to not allow small keys sizes when using HMAC. See SP 800-131Ar2 for details.

- -
-
-kmac_key_check
-
- -

Configure the module to not allow small keys sizes when using KMAC. See SP 800-131Ar2 for details.

- -
-
-no_drbg_truncated_digests
-
- -

Configure the module to not allow truncated digests to be used with Hash and HMAC DRBGs. See FIPS 140-3 IG D.R for details.

- -
-
-signature_digest_check
-
- -

Configure the module to enforce signature algorithms to use digests that are explicitly permitted by the various standards.

- -
-
-hkdf_digest_check
-
- -

Configure the module to enable a run-time digest check when deriving a key by HKDF. See NIST SP 800-56Cr2 for details.

- -
-
-tls13_kdf_digest_check
-
- -

Configure the module to enable a run-time digest check when deriving a key by TLS13 KDF. See RFC 8446 for details.

- -
-
-tls1_prf_digest_check
-
- -

Configure the module to enable a run-time digest check when deriving a key by TLS_PRF. See NIST SP 800-135r1 for details.

- -
-
-sshkdf_digest_check
-
- -

Configure the module to enable a run-time digest check when deriving a key by SSHKDF. See NIST SP 800-135r1 for details.

- -
-
-sskdf_digest_check
-
- -

Configure the module to enable a run-time digest check when deriving a key by SSKDF. See NIST SP 800-56Cr2 for details.

- -
-
-x963kdf_digest_check
-
- -

Configure the module to enable a run-time digest check when deriving a key by X963KDF. See NIST SP 800-131Ar2 for details.

- -
-
-dsa_sign_disabled
-
- -

Configure the module to not allow DSA signing (DSA signature verification is still allowed). See FIPS 140-3 IG C.K for details.

- -
-
-tdes_encrypt_disabled
-
- -

Configure the module to not allow Triple-DES encryption. Triple-DES decryption is still allowed for legacy purposes. See SP800-131Ar2 for details.

- -
-
-rsa_pkcs15_padding_disabled
-
- -

Configure the module to not allow PKCS#1 version 1.5 padding to be used with RSA for key transport and key agreement. See NIST's SP 800-131A Revision 2 for details.

- -
-
-rsa_pss_saltlen_check
-
- -

Configure the module to enable a run-time salt length check when generating or verifying a RSA-PSS signature. See FIPS 186-5 5.4 (g) for details.

- -
-
-rsa_sign_x931_disabled
-
- -

Configure the module to not allow X9.31 padding to be used when signing with RSA. See FIPS 140-3 IG C.K for details.

- -
-
-hkdf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by HKDF. See NIST SP 800-131Ar2 for details.

- -
-
-kbkdf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by KBKDF. See NIST SP 800-131Ar2 for details.

- -
-
-tls13_kdf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by TLS13 KDF. See NIST SP 800-131Ar2 for details.

- -
-
-tls1_prf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by TLS_PRF. See NIST SP 800-131Ar2 for details.

- -
-
-sshkdf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by SSHKDF. See NIST SP 800-131Ar2 for details.

- -
-
-sskdf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by SSKDF. See NIST SP 800-131Ar2 for details.

- -
-
-x963kdf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by X963KDF. See NIST SP 800-131Ar2 for details.

- -
-
-x942kdf_key_check
-
- -

Configure the module to enable a run-time short key-derivation key check when deriving a key by X942KDF. See NIST SP 800-131Ar2 for details.

- -
-
-no_pbkdf2_lower_bound_check
-
- -

Configure the module to not perform run-time lower bound check for PBKDF2. See NIST SP 800-132 for details.

- -
-
-ecdh_cofactor_check
-
- -

Configure the module to enable a run-time check that ECDH uses the EC curves cofactor value when deriving a key. This only affects the 'B' and 'K' curves. See SP 800-56A r3 Section 5.7.1.2 for details.

- -
-
-self_test_onload
-
- -

Do not write the two fields related to the "test status indicator" and "MAC status indicator" to the output configuration file. Without these fields the self tests KATS will run each time the module is loaded. This option could be used for cross compiling, since the self tests need to run at least once on each target machine. Once the self tests have run on the target machine the user could possibly then add the 2 fields into the configuration using some other mechanism.

- -

This is the default.

- -
-
-self_test_oninstall
-
- -

The converse of -self_test_oninstall. The two fields related to the "test status indicator" and "MAC status indicator" are written to the output configuration file.

- -
-
-quiet
-
- -

Do not output pass/fail messages. Implies -noout.

- -
-
-corrupt_desc selftest_description, -corrupt_type selftest_type
-
- -

The corrupt options can be used to test failure of one or more self tests by name. Either option or both may be used to select the tests to corrupt. Refer to the entries for st-desc and st-type in OSSL_PROVIDER-FIPS(7) for values that can be used.

- -
-
-config parent_config
-
- -

Test that a FIPS provider can be loaded from the specified configuration file. A previous call to this application needs to generate the extra configuration data that is included by the base parent_config configuration file. See config(5) for further information on how to set up a provider section. All other options are ignored if '-config' is used.

- -
-
- -

NOTES

- -

Self tests results are logged by default if the options -quiet and -noout are not specified, or if either of the options -corrupt_desc or -corrupt_type are used. If the base configuration file is set up to autoload the fips module, then the fips module will be loaded and self tested BEFORE the fipsinstall application has a chance to set up its own self test callback. As a result of this the self test output and the options -corrupt_desc and -corrupt_type will be ignored. For normal usage the base configuration file should use the default provider when generating the fips configuration file.

- -

The -self_test_oninstall option was added and the -self_test_onload option was made the default in OpenSSL 3.1.

- -

The command and all remaining options were added in OpenSSL 3.0.

- -

EXAMPLES

- -

Calculate the mac of a FIPS module fips.so and run a FIPS self test for the module, and save the fips.cnf configuration file:

- -
openssl fipsinstall -module ./fips.so -out fips.cnf -provider_name fips
- -

Verify that the configuration file fips.cnf contains the correct info:

- -
openssl fipsinstall -module ./fips.so -in fips.cnf  -provider_name fips -verify
- -

Corrupt any self tests which have the description SHA1:

- -
openssl fipsinstall -module ./fips.so -out fips.cnf -provider_name fips \
-        -corrupt_desc 'SHA1'
- -

Validate that the fips module can be loaded from a base configuration file:

- -
export OPENSSL_CONF_INCLUDE=<path of configuration files>
-export OPENSSL_MODULES=<provider-path>
-openssl fipsinstall -config' 'default.cnf'
- -

SEE ALSO

- -

config(5), fips_config(5), OSSL_PROVIDER-FIPS(7), EVP_MAC(3)

- -

HISTORY

- -

The openssl-fipsinstall application was added in OpenSSL 3.0.

- -

The following options were added in OpenSSL 3.1:

- -

-ems_check, -self_test_oninstall

- -

The following options were added in OpenSSL 3.2:

- -

-pedantic, -no_drbg_truncated_digests

- -

The following options were added in OpenSSL 3.4:

- -

-hmac_key_check, -kmac_key_check, -signature_digest_check, -hkdf_digest_check, -tls13_kdf_digest_check, -tls1_prf_digest_check, -sshkdf_digest_check, -sskdf_digest_check, -x963kdf_digest_check, -dsa_sign_disabled, -no_pbkdf2_lower_bound_check, -no_short_mac, -tdes_encrypt_disabled, -rsa_pkcs15_padding_disabled, -rsa_pss_saltlen_check, -rsa_sign_x931_disabled, -hkdf_key_check, -kbkdf_key_check, -tls13_kdf_key_check, -tls1_prf_key_check, -sshkdf_key_check, -sskdf_key_check, -x963kdf_key_check, -x942kdf_key_check, -ecdh_cofactor_check

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-format-options.html b/openssl-install/share/doc/openssl/html/man1/openssl-format-options.html deleted file mode 100644 index 9f951413..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-format-options.html +++ /dev/null @@ -1,161 +0,0 @@ - - - - -openssl-format-options - - - - - - - - - - -

NAME

- -

openssl-format-options - OpenSSL command input and output format options

- -

SYNOPSIS

- -

openssl command [ options ... ] [ parameters ... ]

- -

DESCRIPTION

- -

Several OpenSSL commands can take input or generate output in a variety of formats.

- -

Since OpenSSL 3.0 keys, single certificates, and CRLs can be read from files in any of the DER, PEM or P12 formats. Specifying their input format is no more needed and the openssl commands will automatically try all the possible formats. However if the DER or PEM input format is specified it will be enforced.

- -

In order to access a key via an engine the input format ENGINE may be used; alternatively the key identifier in the <uri> argument of the respective key option may be preceded by org.openssl.engine:. See "Engine Options" in openssl(1) for an example usage of the latter.

- -

OPTIONS

- -

Format Options

- -

The options to specify the format are as follows. Refer to the individual man page to see which options are accepted.

- -
- -
-inform format, -outform format
-
- -

The format of the input or output streams.

- -
-
-keyform format
-
- -

Format of a private key input source.

- -
-
-CRLform format
-
- -

Format of a CRL input source.

- -
-
- -

Format Option Arguments

- -

The possible format arguments are described below. Both uppercase and lowercase are accepted.

- -

The list of acceptable format arguments, and the default, is described in each command documentation.

- -
- -
DER
-
- -

A binary format, encoded or parsed according to Distinguished Encoding Rules (DER) of the ASN.1 data language.

- -
-
ENGINE
-
- -

Used to specify that the cryptographic material is in an OpenSSL engine. An engine must be configured or specified using the -engine option. A password or PIN may be supplied to the engine using the -passin option.

- -
-
P12
-
- -

A DER-encoded file containing a PKCS#12 object. It might be necessary to provide a decryption password to retrieve the private key.

- -
-
PEM
-
- -

A text format defined in IETF RFC 1421 and IETF RFC 7468. Briefly, this is a block of base-64 encoding (defined in IETF RFC 4648), with specific lines used to mark the start and end:

- -
Text before the BEGIN line is ignored.
------ BEGIN object-type -----
-OT43gQKBgQC/2OHZoko6iRlNOAQ/tMVFNq7fL81GivoQ9F1U0Qr+DH3ZfaH8eIkX
-xT0ToMPJUzWAn8pZv0snA0um6SIgvkCuxO84OkANCVbttzXImIsL7pFzfcwV/ERK
-UM6j0ZuSMFOCr/lGPAoOQU0fskidGEHi1/kW+suSr28TqsyYZpwBDQ==
------ END object-type -----
-Text after the END line is also ignored
- -

The object-type must match the type of object that is expected. For example a BEGIN X509 CERTIFICATE will not match if the command is trying to read a private key. The types supported include:

- -
ANY PRIVATE KEY
-CERTIFICATE
-CERTIFICATE REQUEST
-CMS
-DH PARAMETERS
-DSA PARAMETERS
-DSA PUBLIC KEY
-EC PARAMETERS
-EC PRIVATE KEY
-ECDSA PUBLIC KEY
-ENCRYPTED PRIVATE KEY
-PARAMETERS
-PKCS #7 SIGNED DATA
-PKCS7
-PRIVATE KEY
-PUBLIC KEY
-RSA PRIVATE KEY
-SSL SESSION PARAMETERS
-TRUSTED CERTIFICATE
-X509 CRL
-X9.42 DH PARAMETERS
- -

The following legacy object-type's are also supported for compatibility with earlier releases:

- -
DSA PRIVATE KEY
-NEW CERTIFICATE REQUEST
-RSA PUBLIC KEY
-X509 CERTIFICATE
- -
-
SMIME
-
- -

An S/MIME object as described in IETF RFC 8551. Earlier versions were known as CMS and are compatible. Note that the parsing is simple and might fail to parse some legal data.

- -
-
- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-gendsa.html b/openssl-install/share/doc/openssl/html/man1/openssl-gendsa.html deleted file mode 100644 index 8f5ca504..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-gendsa.html +++ /dev/null @@ -1,136 +0,0 @@ - - - - -openssl-gendsa - - - - - - - - - - -

NAME

- -

openssl-gendsa - generate a DSA private key from a set of parameters

- -

SYNOPSIS

- -

openssl gendsa [-help] [-out filename] [-passout arg] [-aes128] [-aes192] [-aes256] [-aria128] [-aria192] [-aria256] [-camellia128] [-camellia192] [-camellia256] [-des] [-des3] [-idea] [-verbose] [-quiet] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [paramfile]

- -

DESCRIPTION

- -

This command generates a DSA private key from a DSA parameter file (which will be typically generated by the openssl-dsaparam(1) command).

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-out filename
-
- -

Output the key to the specified file. If this argument is not specified then standard output is used.

- -
-
-passout arg
-
- -

The passphrase used for the output file. See openssl-passphrase-options(1).

- -
-
-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea
-
- -

These options encrypt the private key with specified cipher before outputting it. A pass phrase is prompted for. If none of these options is specified no encryption is used.

- -

Note that all options must be given before the paramfile argument.

- -
-
-verbose
-
- -

Print extra details about the operations being performed.

- -
-
-quiet
-
- -

Print fewer details about the operations being performed, which may be handy during batch scripts and pipelines.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
paramfile
-
- -

The DSA parameter file to use. The parameters in this file determine the size of the private key. DSA parameters can be generated and examined using the openssl-dsaparam(1) command.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

NOTES

- -

DSA key generation is little more than random number generation so it is much quicker that RSA key generation for example.

- -

SEE ALSO

- -

openssl(1), openssl-genpkey(1), openssl-dsaparam(1), openssl-dsa(1), openssl-genrsa(1), openssl-rsa(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-genpkey.html b/openssl-install/share/doc/openssl/html/man1/openssl-genpkey.html deleted file mode 100644 index 266eb501..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-genpkey.html +++ /dev/null @@ -1,576 +0,0 @@ - - - - -openssl-genpkey - - - - - - - - - - -

NAME

- -

openssl-genpkey - generate a private key or key pair

- -

SYNOPSIS

- -

openssl genpkey [-help] [-out filename] [-outpubkey filename] [-outform DER|PEM] [-verbose] [-quiet] [-pass arg] [-cipher] [-paramfile file] [-algorithm alg] [-pkeyopt opt:value] [-genparam] [-text] [-rand files] [-writerand file] [-engine id]

- -

[-provider name] [-provider-path path] [-propquery propq] [-config configfile]

- -

DESCRIPTION

- -

This command generates a private key or key pair.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-out filename
-
- -

Output the private key to the specified file. If this argument is not specified then standard output is used.

- -
-
-outpubkey filename
-
- -

Output the public key to the specified file. If this argument is not specified then the public key is not output.

- -
-
-outform DER|PEM
-
- -

The output format, except when -genparam is given; the default is PEM. See openssl-format-options(1) for details.

- -

When -genparam is given, -outform is ignored.

- -
-
-verbose
-
- -

Output "status dots" while generating keys.

- -
-
-quiet
-
- -

Do not output "status dots" while generating keys.

- -
-
-pass arg
-
- -

The output file password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-cipher
-
- -

This option encrypts the private key with the supplied cipher. Any algorithm name accepted by EVP_get_cipherbyname() is acceptable such as des3.

- -
-
-algorithm alg
-
- -

Public key algorithm to use such as RSA, DSA, DH or DHX. If used this option must precede any -pkeyopt options. The options -paramfile and -algorithm are mutually exclusive. Engines or providers may add algorithms in addition to the standard built-in ones.

- -

Valid built-in algorithm names for private key generation are RSA, RSA-PSS, EC, X25519, X448, ED25519 and ED448.

- -

Valid built-in algorithm names for parameter generation (see the -genparam option) are DH, DSA and EC.

- -

Note that the algorithm name X9.42 DH may be used as a synonym for DHX keys and PKCS#3 refers to DH Keys. Some options are not shared between DH and DHX keys.

- -
-
-pkeyopt opt:value
-
- -

Set the public key algorithm option opt to value. The precise set of options supported depends on the public key algorithm used and its implementation. See "KEY GENERATION OPTIONS" and "PARAMETER GENERATION OPTIONS" below for more details.

- -

To list the possible opt values for an algorithm use: openssl genpkey -algorithm XXX -help

- -
-
-genparam
-
- -

Generate a set of parameters instead of a private key. If used this option must precede any -algorithm, -paramfile or -pkeyopt options.

- -
-
-paramfile filename
-
- -

Some public key algorithms generate a private key based on a set of parameters. They can be supplied using this option. If this option is used the public key algorithm used is determined by the parameters. If used this option must precede any -pkeyopt options. The options -paramfile and -algorithm are mutually exclusive.

- -
-
-text
-
- -

Print an (unencrypted) text representation of private and public keys and parameters along with the PEM or DER structure.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-config configfile
-
- -

See "Configuration Option" in openssl(1).

- -
-
- -

KEY GENERATION OPTIONS

- -

The options supported by each algorithm and indeed each implementation of an algorithm can vary. The options for the OpenSSL implementations are detailed below. There are no key generation options defined for the X25519, X448, ED25519 or ED448 algorithms.

- -

RSA Key Generation Options

- -
- -
rsa_keygen_bits:numbits
-
- -

The number of bits in the generated key. If not specified 2048 is used.

- -
-
rsa_keygen_primes:numprimes
-
- -

The number of primes in the generated key. If not specified 2 is used.

- -
-
rsa_keygen_pubexp:value
-
- -

The RSA public exponent value. This can be a large decimal or hexadecimal value if preceded by 0x. Default value is 65537.

- -
-
- -

RSA-PSS Key Generation Options

- -

Note: by default an RSA-PSS key has no parameter restrictions.

- -
- -
rsa_keygen_bits:numbits, rsa_keygen_primes:numprimes, rsa_keygen_pubexp:value
-
- -

These options have the same meaning as the RSA algorithm.

- -
-
rsa_pss_keygen_md:digest
-
- -

If set the key is restricted and can only use digest for signing.

- -
-
rsa_pss_keygen_mgf1_md:digest
-
- -

If set the key is restricted and can only use digest as it's MGF1 parameter.

- -
-
rsa_pss_keygen_saltlen:len
-
- -

If set the key is restricted and len specifies the minimum salt length.

- -
-
- -

EC Key Generation Options

- -

The EC key generation options can also be used for parameter generation.

- -
- -
ec_paramgen_curve:curve
-
- -

The EC curve to use. OpenSSL supports NIST curve names such as "P-256".

- -
-
ec_param_enc:encoding
-
- -

The encoding to use for parameters. The encoding parameter must be either named_curve or explicit. The default value is named_curve.

- -
-
- -

DH Key Generation Options

- -
- -
group:name
-
- -

The paramfile option is not required if a named group is used here. See the "DH Parameter Generation Options" section below.

- -
-
- -

PARAMETER GENERATION OPTIONS

- -

The options supported by each algorithm and indeed each implementation of an algorithm can vary. The options for the OpenSSL implementations are detailed below.

- -

DSA Parameter Generation Options

- -
- -
dsa_paramgen_bits:numbits
-
- -

The number of bits in the generated prime. If not specified 2048 is used.

- -
-
dsa_paramgen_q_bits:numbits
-
- -
-
qbits:numbits
-
- -

The number of bits in the q parameter. Must be one of 160, 224 or 256. If not specified 224 is used.

- -
-
dsa_paramgen_md:digest
-
- -
-
digest:digest
-
- -

The digest to use during parameter generation. Must be one of sha1, sha224 or sha256. If set, then the number of bits in q will match the output size of the specified digest and the dsa_paramgen_q_bits parameter will be ignored. If not set, then a digest will be used that gives an output matching the number of bits in q, i.e. sha1 if q length is 160, sha224 if it 224 or sha256 if it is 256.

- -
-
properties:query
-
- -

The digest property query string to use when fetching a digest from a provider.

- -
-
type:type
-
- -

The type of generation to use. Set this to 1 to use legacy FIPS186-2 parameter generation. The default of 0 uses FIPS186-4 parameter generation.

- -
-
gindex:index
-
- -

The index to use for canonical generation and verification of the generator g. Set this to a positive value ranging from 0..255 to use this mode. Larger values will only use the bottom byte. This index must then be reused during key validation to verify the value of g. If this value is not set then g is not verifiable. The default value is -1.

- -
-
hexseed:seed
-
- -

The seed seed data to use instead of generating a random seed internally. This should be used for testing purposes only. This will either produced fixed values for the generated parameters OR it will fail if the seed did not generate valid primes.

- -
-
- -

DH Parameter Generation Options

- -

For most use cases it is recommended to use the group option rather than the type options. Note that the group option is not used by default if no parameter generation options are specified.

- -
- -
group:name
-
- -
-
dh_param:name
-
- -

Use a named DH group to select constant values for the DH parameters. All other options will be ignored if this value is set.

- -

Valid values that are associated with the algorithm of "DH" are: "ffdhe2048", "ffdhe3072", "ffdhe4096", "ffdhe6144", "ffdhe8192", "modp_1536", "modp_2048", "modp_3072", "modp_4096", "modp_6144", "modp_8192".

- -

Valid values that are associated with the algorithm of "DHX" are the RFC5114 names "dh_1024_160", "dh_2048_224", "dh_2048_256".

- -
-
dh_rfc5114:num
-
- -

If this option is set, then the appropriate RFC5114 parameters are used instead of generating new parameters. The value num can be one of 1, 2 or 3 that are equivalent to using the option group with one of "dh_1024_160", "dh_2048_224" or "dh_2048_256". All other options will be ignored if this value is set.

- -
-
pbits:numbits
-
- -
-
dh_paramgen_prime_len:numbits
-
- -

The number of bits in the prime parameter p. The default is 2048.

- -
-
qbits:numbits
-
- -
-
dh_paramgen_subprime_len:numbits
-
- -

The number of bits in the sub prime parameter q. The default is 224. Only relevant if used in conjunction with the dh_paramgen_type option to generate DHX parameters.

- -
-
safeprime-generator:value
-
- -
-
dh_paramgen_generator:value
-
- -

The value to use for the generator g. The default is 2. The algorithm option must be "DH" for this parameter to be used.

- -
-
type:string
-
- -

The type name of DH parameters to generate. Valid values are:

- -
- -
"generator"
-
- -

Use a safe prime generator with the option safeprime_generator The algorithm option must be "DH".

- -
-
"fips186_4"
-
- -

FIPS186-4 parameter generation. The algorithm option must be "DHX".

- -
-
"fips186_2"
-
- -

FIPS186-4 parameter generation. The algorithm option must be "DHX".

- -
-
"group"
-
- -

Can be used with the option pbits to select one of "ffdhe2048", "ffdhe3072", "ffdhe4096", "ffdhe6144" or "ffdhe8192". The algorithm option must be "DH".

- -
-
"default"
-
- -

Selects a default type based on the algorithm. This is used by the OpenSSL default provider to set the type for backwards compatibility. If algorithm is "DH" then "generator" is used. If algorithm is "DHX" then "fips186_2" is used.

- -
-
- -
-
dh_paramgen_type:value
-
- -

The type of DH parameters to generate. Valid values are 0, 1, 2 or 3 which correspond to setting the option type to "generator", "fips186_2", "fips186_4" or "group".

- -
-
digest:digest
-
- -

The digest to use during parameter generation. Must be one of sha1, sha224 or sha256. If set, then the number of bits in qbits will match the output size of the specified digest and the qbits parameter will be ignored. If not set, then a digest will be used that gives an output matching the number of bits in q, i.e. sha1 if q length is 160, sha224 if it is 224 or sha256 if it is 256. This is only used by "fips186_4" and "fips186_2" key generation.

- -
-
properties:query
-
- -

The digest property query string to use when fetching a digest from a provider. This is only used by "fips186_4" and "fips186_2" key generation.

- -
-
gindex:index
-
- -

The index to use for canonical generation and verification of the generator g. Set this to a positive value ranging from 0..255 to use this mode. Larger values will only use the bottom byte. This index must then be reused during key validation to verify the value of g. If this value is not set then g is not verifiable. The default value is -1. This is only used by "fips186_4" and "fips186_2" key generation.

- -
-
hexseed:seed
-
- -

The seed seed data to use instead of generating a random seed internally. This should be used for testing purposes only. This will either produced fixed values for the generated parameters OR it will fail if the seed did not generate valid primes. This is only used by "fips186_4" and "fips186_2" key generation.

- -
-
- -

EC Parameter Generation Options

- -

The EC parameter generation options are the same as for key generation. See "EC Key Generation Options" above.

- -

NOTES

- -

The use of the genpkey program is encouraged over the algorithm specific utilities because additional algorithm options and ENGINE provided algorithms can be used.

- -

EXAMPLES

- -

Generate an RSA private key using default parameters:

- -
openssl genpkey -algorithm RSA -out key.pem
- -

Encrypt output private key using 128 bit AES and the passphrase "hello":

- -
openssl genpkey -algorithm RSA -out key.pem -aes-128-cbc -pass pass:hello
- -

Generate a 2048 bit RSA key using 3 as the public exponent:

- -
openssl genpkey -algorithm RSA -out key.pem \
-    -pkeyopt rsa_keygen_bits:2048 -pkeyopt rsa_keygen_pubexp:3
- -

Generate 2048 bit DSA parameters that can be validated: The output values for gindex and seed are required for key validation purposes and are not saved to the output pem file).

- -
openssl genpkey -genparam -algorithm DSA -out dsap.pem -pkeyopt pbits:2048 \
-    -pkeyopt qbits:224 -pkeyopt digest:SHA256 -pkeyopt gindex:1 -text
- -

Generate DSA key from parameters:

- -
openssl genpkey -paramfile dsap.pem -out dsakey.pem
- -

Generate 4096 bit DH Key using safe prime group ffdhe4096:

- -
openssl genpkey -algorithm DH -out dhkey.pem -pkeyopt group:ffdhe4096
- -

Generate 2048 bit X9.42 DH key with 256 bit subgroup using RFC5114 group3:

- -
openssl genpkey -algorithm DHX -out dhkey.pem -pkeyopt dh_rfc5114:3
- -

Generate a DH key using a DH parameters file:

- -
openssl genpkey -paramfile dhp.pem -out dhkey.pem
- -

Output DH parameters for safe prime group ffdhe2048:

- -
openssl genpkey -genparam -algorithm DH -out dhp.pem -pkeyopt group:ffdhe2048
- -

Output 2048 bit X9.42 DH parameters with 224 bit subgroup using RFC5114 group2:

- -
openssl genpkey -genparam -algorithm DHX -out dhp.pem -pkeyopt dh_rfc5114:2
- -

Output 2048 bit X9.42 DH parameters with 224 bit subgroup using FIP186-4 keygen:

- -
openssl genpkey -genparam -algorithm DHX -out dhp.pem -text \
-    -pkeyopt pbits:2048 -pkeyopt qbits:224 -pkeyopt digest:SHA256 \
-    -pkeyopt gindex:1 -pkeyopt dh_paramgen_type:2
- -

Output 1024 bit X9.42 DH parameters with 160 bit subgroup using FIP186-2 keygen:

- -
openssl genpkey -genparam -algorithm DHX -out dhp.pem -text \
-    -pkeyopt pbits:1024 -pkeyopt qbits:160 -pkeyopt digest:SHA1 \
-    -pkeyopt gindex:1 -pkeyopt dh_paramgen_type:1
- -

Output 2048 bit DH parameters:

- -
openssl genpkey -genparam -algorithm DH -out dhp.pem \
-    -pkeyopt dh_paramgen_prime_len:2048
- -

Output 2048 bit DH parameters using a generator:

- -
openssl genpkey -genparam -algorithm DH -out dhpx.pem \
-    -pkeyopt dh_paramgen_prime_len:2048 \
-    -pkeyopt dh_paramgen_type:1
- -

Generate EC parameters:

- -
openssl genpkey -genparam -algorithm EC -out ecp.pem \
-       -pkeyopt ec_paramgen_curve:secp384r1 \
-       -pkeyopt ec_param_enc:named_curve
- -

Generate EC key from parameters:

- -
openssl genpkey -paramfile ecp.pem -out eckey.pem
- -

Generate EC key directly:

- -
openssl genpkey -algorithm EC -out eckey.pem \
-       -pkeyopt ec_paramgen_curve:P-384 \
-       -pkeyopt ec_param_enc:named_curve
- -

Generate an X25519 private key:

- -
openssl genpkey -algorithm X25519 -out xkey.pem
- -

Generate an ED448 private key:

- -
openssl genpkey -algorithm ED448 -out xkey.pem
- -

HISTORY

- -

The ability to use NIST curve names, and to generate an EC key directly, were added in OpenSSL 1.0.2. The ability to generate X25519 keys was added in OpenSSL 1.1.0. The ability to generate X448, ED25519 and ED448 keys was added in OpenSSL 1.1.1.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-genrsa.html b/openssl-install/share/doc/openssl/html/man1/openssl-genrsa.html deleted file mode 100644 index 14aca693..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-genrsa.html +++ /dev/null @@ -1,149 +0,0 @@ - - - - -openssl-genrsa - - - - - - - - - - -

NAME

- -

openssl-genrsa - generate an RSA private key

- -

SYNOPSIS

- -

openssl genrsa [-help] [-out filename] [-passout arg] [-aes128] [-aes192] [-aes256] [-aria128] [-aria192] [-aria256] [-camellia128] [-camellia192] [-camellia256] [-des] [-des3] [-idea] [-F4] [-f4] [-3] [-primes num] [-verbose] [-quiet] [-traditional] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [numbits]

- -

DESCRIPTION

- -

This command generates an RSA private key.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-out filename
-
- -

Output the key to the specified file. If this argument is not specified then standard output is used.

- -
-
-passout arg
-
- -

The output file password source. For more information about the format see openssl-passphrase-options(1).

- -
-
-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea
-
- -

These options encrypt the private key with specified cipher before outputting it. If none of these options is specified no encryption is used. If encryption is used a pass phrase is prompted for if it is not supplied via the -passout argument.

- -
-
-F4, -f4, -3
-
- -

The public exponent to use, either 65537 or 3. The default is 65537. The -3 option has been deprecated.

- -
-
-primes num
-
- -

Specify the number of primes to use while generating the RSA key. The num parameter must be a positive integer that is greater than 1 and less than 16. If num is greater than 2, then the generated key is called a 'multi-prime' RSA key, which is defined in RFC 8017.

- -
-
-verbose
-
- -

Print extra details about the operations being performed.

- -
-
-quiet
-
- -

Print fewer details about the operations being performed, which may be handy during batch scripts and pipelines.

- -
-
-traditional
-
- -

Write the key using the traditional PKCS#1 format instead of the PKCS#8 format.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
numbits
-
- -

The size of the private key to generate in bits. This must be the last option specified. The default is 2048 and values less than 512 are not allowed.

- -
-
- -

NOTES

- -

RSA private key generation essentially involves the generation of two or more prime numbers. When generating a private key various symbols will be output to indicate the progress of the generation. A . represents each number which has passed an initial sieve test, + means a number has passed a single round of the Miller-Rabin primality test, * means the current prime starts a regenerating progress due to some failed tests. A newline means that the number has passed all the prime tests (the actual number depends on the key size).

- -

Because key generation is a random process the time taken to generate a key may vary somewhat. But in general, more primes lead to less generation time of a key.

- -

SEE ALSO

- -

openssl(1), openssl-genpkey(1), openssl-gendsa(1)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-info.html b/openssl-install/share/doc/openssl/html/man1/openssl-info.html deleted file mode 100644 index 979409c6..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-info.html +++ /dev/null @@ -1,120 +0,0 @@ - - - - -openssl-info - - - - - - - - - - -

NAME

- -

openssl-info - print OpenSSL built-in information

- -

SYNOPSIS

- -

openssl info [-help] [-configdir] [-enginesdir] [-modulesdir ] [-dsoext] [-dirnamesep] [-listsep] [-seeds] [-cpusettings] [-windowscontext]

- -

DESCRIPTION

- -

This command is used to print out information about OpenSSL. The information is written exactly as it is with no extra text, which makes useful for scripts.

- -

As a consequence, only one item may be chosen for each run of this command.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-configdir
-
- -

Outputs the default directory for OpenSSL configuration files.

- -
-
-enginesdir
-
- -

Outputs the default directory for OpenSSL engine modules.

- -
-
-modulesdir
-
- -

Outputs the default directory for OpenSSL dynamically loadable modules other than engine modules.

- -
-
-dsoext
-
- -

Outputs the DSO extension OpenSSL uses.

- -
-
-dirnamesep
-
- -

Outputs the separator character between a directory specification and a filename. Note that on some operating systems, this is not the same as the separator between directory elements.

- -
-
-listsep
-
- -

Outputs the OpenSSL list separator character. This is typically used to construct $PATH (%PATH% on Windows) style lists.

- -
-
-seeds
-
- -

Outputs the randomness seed sources.

- -
-
-cpusettings
-
- -

Outputs the OpenSSL CPU settings info.

- -
-
-windowscontext
-
- -

Outputs the Windows install context.

- -
-
- -

HISTORY

- -

This command was added in OpenSSL 3.0.

- -

The -windowscontext option was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-kdf.html b/openssl-install/share/doc/openssl/html/man1/openssl-kdf.html deleted file mode 100644 index eb7be97a..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-kdf.html +++ /dev/null @@ -1,254 +0,0 @@ - - - - -openssl-kdf - - - - - - - - - - -

NAME

- -

openssl-kdf - perform Key Derivation Function operations

- -

SYNOPSIS

- -

openssl kdf [-help] [-cipher] [-digest] [-mac] [-kdfopt nm:v] [-keylen num] [-out filename] [-binary] [-provider name] [-provider-path path] [-propquery propq] kdf_name

- -

DESCRIPTION

- -

The key derivation functions generate a derived key from either a secret or password.

- -

OPTIONS

- -
- -
-help
-
- -

Print a usage message.

- -
-
-keylen num
-
- -

The output size of the derived key. This field is required.

- -
-
-out filename
-
- -

Filename to output to, or standard output by default.

- -
-
-binary
-
- -

Output the derived key in binary form. Uses hexadecimal text format if not specified.

- -
-
-cipher name
-
- -

Specify the cipher to be used by the KDF. Not all KDFs require a cipher and it is an error to use this option in such cases.

- -
-
-digest name
-
- -

Specify the digest to be used by the KDF. Not all KDFs require a digest and it is an error to use this option in such cases. To see the list of supported digests, use openssl list -digest-commands.

- -
-
-mac name
-
- -

Specify the MAC to be used by the KDF. Not all KDFs require a MAC and it is an error to use this option in such cases.

- -
-
-kdfopt nm:v
-
- -

Passes options to the KDF algorithm. A comprehensive list of parameters can be found in "PARAMETERS" in EVP_KDF(3). Common parameter names used by EVP_KDF_CTX_set_params() are:

- -
- -
key:string
-
- -

Specifies the secret key as an alphanumeric string (use if the key contains printable characters only). The string length must conform to any restrictions of the KDF algorithm. A key must be specified for most KDF algorithms.

- -
-
hexkey:string
-
- -

Alternative to the key: option where the secret key is specified in hexadecimal form (two hex digits per byte).

- -
-
pass:string
-
- -

Specifies the password as an alphanumeric string (use if the password contains printable characters only). The password must be specified for PBKDF2 and scrypt.

- -
-
hexpass:string
-
- -

Alternative to the pass: option where the password is specified in hexadecimal form (two hex digits per byte).

- -
-
salt:string
-
- -

Specifies a non-secret unique cryptographic salt as an alphanumeric string (use if it contains printable characters only). The length must conform to any restrictions of the KDF algorithm. A salt parameter is required for several KDF algorithms, such as EVP_KDF-PBKDF2(7).

- -
-
hexsalt:string
-
- -

Alternative to the salt: option where the salt is specified in hexadecimal form (two hex digits per byte).

- -
-
info:string
-
- -

Some KDF implementations, such as EVP_KDF-HKDF(7), take an 'info' parameter for binding the derived key material to application- and context-specific information. Specifies the info, fixed info, other info or shared info argument as an alphanumeric string (use if it contains printable characters only). The length must conform to any restrictions of the KDF algorithm.

- -
-
hexinfo:string
-
- -

Alternative to the info: option where the info is specified in hexadecimal form (two hex digits per byte).

- -
-
digest:string
-
- -

This option is identical to the -digest option.

- -
-
cipher:string
-
- -

This option is identical to the -cipher option.

- -
-
mac:string
-
- -

This option is identical to the -mac option.

- -
-
- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
kdf_name
-
- -

Specifies the name of a supported KDF algorithm which will be used. The supported algorithms names include TLS1-PRF, HKDF, SSKDF, PBKDF2, SSHKDF, X942KDF-ASN1, X942KDF-CONCAT, X963KDF and SCRYPT.

- -
-
- -

EXAMPLES

- -

Use TLS1-PRF to create a hex-encoded derived key from a secret key and seed:

- -
openssl kdf -keylen 16 -kdfopt digest:SHA2-256 -kdfopt key:secret \
-            -kdfopt seed:seed TLS1-PRF
- -

Use HKDF to create a hex-encoded derived key from a secret key, salt and info:

- -
openssl kdf -keylen 10 -kdfopt digest:SHA2-256 -kdfopt key:secret \
-            -kdfopt salt:salt -kdfopt info:label HKDF
- -

Use SSKDF with KMAC to create a hex-encoded derived key from a secret key, salt and info:

- -
openssl kdf -keylen 64 -kdfopt mac:KMAC-128 -kdfopt maclen:20 \
-            -kdfopt hexkey:b74a149a161545 -kdfopt hexinfo:348a37a2 \
-            -kdfopt hexsalt:3638271ccd68a2 SSKDF
- -

Use SSKDF with HMAC to create a hex-encoded derived key from a secret key, salt and info:

- -
openssl kdf -keylen 16 -kdfopt mac:HMAC -kdfopt digest:SHA2-256 \
-            -kdfopt hexkey:b74a149a -kdfopt hexinfo:348a37a2 \
-            -kdfopt hexsalt:3638271c SSKDF
- -

Use SSKDF with Hash to create a hex-encoded derived key from a secret key, salt and info:

- -
openssl kdf -keylen 14 -kdfopt digest:SHA2-256 \
-            -kdfopt hexkey:6dbdc23f045488 \
-            -kdfopt hexinfo:a1b2c3d4 SSKDF
- -

Use SSHKDF to create a hex-encoded derived key from a secret key, hash and session_id:

- -
openssl kdf -keylen 16 -kdfopt digest:SHA2-256 \
-            -kdfopt hexkey:0102030405 \
-            -kdfopt hexxcghash:06090A \
-            -kdfopt hexsession_id:01020304 \
-            -kdfopt type:A SSHKDF
- -

Use PBKDF2 to create a hex-encoded derived key from a password and salt:

- -
openssl kdf -keylen 32 -kdfopt digest:SHA256 -kdfopt pass:password \
-            -kdfopt salt:salt -kdfopt iter:2 PBKDF2
- -

Use scrypt to create a hex-encoded derived key from a password and salt:

- -
openssl kdf -keylen 64 -kdfopt pass:password -kdfopt salt:NaCl \
-            -kdfopt n:1024 -kdfopt r:8 -kdfopt p:16 \
-            -kdfopt maxmem_bytes:10485760 SCRYPT
- -

NOTES

- -

The KDF mechanisms that are available will depend on the options used when building OpenSSL.

- -

SEE ALSO

- -

openssl(1), openssl-pkeyutl(1), EVP_KDF(3), EVP_KDF-SCRYPT(7), EVP_KDF-TLS1_PRF(7), EVP_KDF-PBKDF2(7), EVP_KDF-HKDF(7), EVP_KDF-SS(7), EVP_KDF-SSHKDF(7), EVP_KDF-X942-ASN1(7), EVP_KDF-X942-CONCAT(7), EVP_KDF-X963(7)

- -

HISTORY

- -

Added in OpenSSL 3.0

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-list.html b/openssl-install/share/doc/openssl/html/man1/openssl-list.html deleted file mode 100644 index ea9ffb65..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-list.html +++ /dev/null @@ -1,340 +0,0 @@ - - - - -openssl-list - - - - - - - - - - -

NAME

- -

openssl-list - list algorithms and features

- -

SYNOPSIS

- -

openssl list [-help] [-verbose] [-select name] [-1] [-all-algorithms] [-commands] [-standard-commands] [-digest-algorithms] [-digest-commands] [-kdf-algorithms] [-mac-algorithms] [-random-instances] [-random-generators] [-cipher-algorithms] [-cipher-commands] [-encoders] [-decoders] [-key-managers] [-key-exchange-algorithms] [-kem-algorithms] [-signature-algorithms] [-tls-signature-algorithms] [-asymcipher-algorithms] [-public-key-algorithms] [-public-key-methods] [-store-loaders] [-providers] [-engines] [-disabled] [-objects] [-options command] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command is used to generate list of algorithms or disabled features.

- -

OPTIONS

- -
- -
-help
-
- -

Display a usage message.

- -
-
-verbose
-
- -

Displays extra information. The options below where verbosity applies say a bit more about what that means.

- -
-
-select name
-
- -

Only list algorithms that match this name.

- -
-
-1
-
- -

List the commands, digest-commands, or cipher-commands in a single column. If used, this option must be given first.

- -
-
-all-algorithms
-
- -

Display lists of all algorithms. These include:

- -
- -
Asymmetric ciphers
-
- -
-
Decoders
-
- -
-
Digests
-
- -
-
Encoders
-
- -
-
Key derivation algorithms (KDF)
-
- -
-
Key encapsulation methods (KEM)
-
- -
-
Key exchange algorithms (KEX)
-
- -
-
Key managers
-
- -
-
Message authentication code algorithms (MAC)
-
- -
-
Random number generators (RNG, DRBG)
-
- -
-
Signature algorithms
-
- -
-
Store loaders
-
- -
-
Symmetric ciphers
-
- -
-
- -
-
-commands
-
- -

Display a list of standard commands.

- -
-
-standard-commands
-
- -

List of standard commands.

- -
-
-digest-commands
-
- -

This option is deprecated. Use digest-algorithms instead.

- -

Display a list of message digest commands, which are typically used as input to the openssl-dgst(1) or openssl-speed(1) commands.

- -
-
-cipher-commands
-
- -

This option is deprecated. Use cipher-algorithms instead.

- -

Display a list of cipher commands, which are typically used as input to the openssl-enc(1) or openssl-speed(1) commands.

- -
-
-cipher-algorithms, -digest-algorithms, -kdf-algorithms, -mac-algorithms,
-
- -

Display a list of symmetric cipher, digest, kdf and mac algorithms. See "Display of algorithm names" for a description of how names are displayed.

- -

In verbose mode, the algorithms provided by a provider will get additional information on what parameters each implementation supports.

- -
-
-random-instances
-
- -

List the primary, public and private random number generator details.

- -
-
-random-generators
-
- -

Display a list of random number generators. See "Display of algorithm names" for a description of how names are displayed.

- -
-
-encoders
-
- -

Display a list of encoders. See "Display of algorithm names" for a description of how names are displayed.

- -

In verbose mode, the algorithms provided by a provider will get additional information on what parameters each implementation supports.

- -
-
-decoders
-
- -

Display a list of decoders. See "Display of algorithm names" for a description of how names are displayed.

- -

In verbose mode, the algorithms provided by a provider will get additional information on what parameters each implementation supports.

- -
-
-public-key-algorithms
-
- -

Display a list of public key algorithms, with each algorithm as a block of multiple lines, all but the first are indented. The options key-exchange-algorithms, kem-algorithms, signature-algorithms, and asymcipher-algorithms will display similar info.

- -
-
-public-key-methods
-
- -

Display a list of public key methods.

- -
-
-key-managers
-
- -

Display a list of key managers.

- -
-
-key-exchange-algorithms
-
- -

Display a list of key exchange algorithms.

- -
-
-kem-algorithms
-
- -

Display a list of key encapsulation algorithms.

- -
-
-signature-algorithms
-
- -

Display a list of signature algorithms.

- -
-
-tls-signature-algorithms
-
- -

Display the list of signature algorithms available for TLS handshakes made available by all currently active providers. The output format is colon delimited in a form directly usable in SSL_CONF_cmd(3) specifying SignatureAlgorithms.

- -
-
-asymcipher-algorithms
-
- -

Display a list of asymmetric cipher algorithms.

- -
-
-store-loaders
-
- -

Display a list of store loaders.

- -
-
-providers
-
- -

Display a list of all loaded providers with their names, version and status.

- -

In verbose mode, the full version and all provider parameters will additionally be displayed.

- -
-
-engines
-
- -

This option is deprecated.

- -

Display a list of loaded engines.

- -
-
-disabled
-
- -

Display a list of disabled features, those that were compiled out of the installation.

- -
-
-objects
-
- -

Display a list of built in objects, i.e. OIDs with names. They're listed in the format described in "ASN1 Object Configuration Module" in config(5).

- -
-
-options command
-
- -

Output a two-column list of the options accepted by the specified command. The first is the option name, and the second is a one-character indication of what type of parameter it takes, if any. This is an internal option, used for checking that the documentation is complete.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

Display of algorithm names

- -

Algorithm names may be displayed in one of two manners:

- -
- -
Legacy implementations
-
- -

Legacy implementations will simply display the main name of the algorithm on a line of its own, or in the form <foo bar>> to show that foo is an alias for the main name, bar

- -
-
Provided implementations
-
- -

Implementations from a provider are displayed like this if the implementation is labeled with a single name:

- -
foo @ bar
- -

or like this if it's labeled with multiple names:

- -
{ foo1, foo2 } @bar
- -

In both cases, bar is the name of the provider.

- -
-
- -

HISTORY

- -

The -engines, -digest-commands, and -cipher-commands options were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-mac.html b/openssl-install/share/doc/openssl/html/man1/openssl-mac.html deleted file mode 100644 index f5432e2c..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-mac.html +++ /dev/null @@ -1,205 +0,0 @@ - - - - -openssl-mac - - - - - - - - - - -

NAME

- -

openssl-mac - perform Message Authentication Code operations

- -

SYNOPSIS

- -

openssl mac [-help] [-cipher] [-digest] [-macopt] [-in filename] [-out filename] [-binary] [-provider name] [-provider-path path] [-propquery propq] mac_name

- -

DESCRIPTION

- -

The message authentication code functions output the MAC of a supplied input file.

- -

OPTIONS

- -
- -
-help
-
- -

Print a usage message.

- -
-
-in filename
-
- -

Input filename to calculate a MAC for, or standard input by default. Standard input is used if the filename is '-'. Files and standard input are expected to be in binary format.

- -
-
-out filename
-
- -

Filename to output to, or standard output by default.

- -
-
-binary
-
- -

Output the MAC in binary form. Uses hexadecimal text format if not specified.

- -
-
-cipher name
-
- -

Used by CMAC and GMAC to specify the cipher algorithm. For CMAC it should be a CBC mode cipher e.g. AES-128-CBC. For GMAC it should be a GCM mode cipher e.g. AES-128-GCM.

- -
-
-digest name
-
- -

Used by HMAC as an alphanumeric string (use if the key contains printable characters only). The string length must conform to any restrictions of the MAC algorithm. To see the list of supported digests, use openssl list -digest-commands.

- -
-
-macopt nm:v
-
- -

Passes options to the MAC algorithm. A comprehensive list of controls can be found in the EVP_MAC implementation documentation. Common parameter names used by EVP_MAC_CTX_get_params() are:

- -
- -
key:string
-
- -

Specifies the MAC key as an alphanumeric string (use if the key contains printable characters only). The string length must conform to any restrictions of the MAC algorithm. A key must be specified for every MAC algorithm.

- -
-
hexkey:string
-
- -

Specifies the MAC key in hexadecimal form (two hex digits per byte). The key length must conform to any restrictions of the MAC algorithm. A key must be specified for every MAC algorithm.

- -
-
iv:string
-
- -

Used by GMAC to specify an IV as an alphanumeric string (use if the IV contains printable characters only).

- -
-
hexiv:string
-
- -

Used by GMAC to specify an IV in hexadecimal form (two hex digits per byte).

- -
-
size:int
-
- -

Used by KMAC128 or KMAC256 to specify an output length. The default sizes are 32 or 64 bytes respectively.

- -
-
custom:string
-
- -

Used by KMAC128 or KMAC256 to specify a customization string. The default is the empty string "".

- -
-
digest:string
-
- -

This option is identical to the -digest option.

- -
-
cipher:string
-
- -

This option is identical to the -cipher option.

- -
-
- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
mac_name
-
- -

Specifies the name of a supported MAC algorithm which will be used. To see the list of supported MAC's use the command openssl list -mac-algorithms.

- -
-
- -

EXAMPLES

- -

To create a hex-encoded HMAC-SHA1 MAC of a file and write to stdout:

- -
openssl mac -digest SHA1 \
-        -macopt hexkey:000102030405060708090A0B0C0D0E0F10111213 \
-        -in msg.bin HMAC
- -

To create a SipHash MAC from a file with a binary file output:

- -
openssl mac -macopt hexkey:000102030405060708090A0B0C0D0E0F \
-        -in msg.bin -out out.bin -binary SipHash
- -

To create a hex-encoded CMAC-AES-128-CBC MAC from a file:

- -
openssl mac -cipher AES-128-CBC \
-        -macopt hexkey:77A77FAF290C1FA30C683DF16BA7A77B \
-        -in msg.bin CMAC
- -

To create a hex-encoded KMAC128 MAC from a file with a Customisation String 'Tag' and output length of 16:

- -
openssl mac -macopt custom:Tag -macopt hexkey:40414243444546 \
-        -macopt size:16 -in msg.bin KMAC128
- -

To create a hex-encoded GMAC-AES-128-GCM with a IV from a file:

- -
openssl mac -cipher AES-128-GCM -macopt hexiv:E0E00F19FED7BA0136A797F3 \
-        -macopt hexkey:77A77FAF290C1FA30C683DF16BA7A77B -in msg.bin GMAC
- -

NOTES

- -

The MAC mechanisms that are available will depend on the options used when building OpenSSL. Use openssl list -mac-algorithms to list them.

- -

SEE ALSO

- -

openssl(1), EVP_MAC(3), EVP_MAC-CMAC(7), EVP_MAC-GMAC(7), EVP_MAC-HMAC(7), EVP_MAC-KMAC(7), EVP_MAC-Siphash(7), EVP_MAC-Poly1305(7)

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-namedisplay-options.html b/openssl-install/share/doc/openssl/html/man1/openssl-namedisplay-options.html deleted file mode 100644 index 7c1e79b0..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-namedisplay-options.html +++ /dev/null @@ -1,187 +0,0 @@ - - - - -openssl-namedisplay-options - - - - - - - - - - -

NAME

- -

openssl-namedisplay-options - Distinguished name display options

- -

SYNOPSIS

- -

openssl command [ options ... ] [ parameters ... ]

- -

DESCRIPTION

- -

OpenSSL provides fine-grain control over how the subject and issuer DN's are displayed. This is specified by using the -nameopt option, which takes a comma-separated list of options from the following set. An option may be preceded by a minus sign, -, to turn it off. The first four option arguments are the most commonly used.

- -

The default value is esc_ctrl,utf8,dump_unknown,dump_der,sep_comma_plus_space,sname.

- -

OPTIONS

- -

Name Format Option Arguments

- -

The DN output format can be fine tuned with the following flags.

- -
- -
compat
-
- -

Display the name using an old format from previous OpenSSL versions.

- -
-
RFC2253
-
- -

Display the name using the format defined in RFC 2253. It is equivalent to esc_2253, esc_ctrl, esc_msb, utf8, dump_nostr, dump_unknown, dump_der, sep_comma_plus, dn_rev and sname.

- -
-
oneline
-
- -

Display the name in one line, using a format that is more readable RFC 2253. It is equivalent to esc_2253, esc_ctrl, esc_msb, utf8, dump_nostr, dump_der, use_quote, sep_comma_plus_space, space_eq and sname options.

- -
-
multiline
-
- -

Display the name using multiple lines. It is equivalent to esc_ctrl, esc_msb, sep_multiline, space_eq, lname and align.

- -
-
esc_2253
-
- -

Escape the "special" characters in a field, as required by RFC 2253. That is, any of the characters ,+"<>;, # at the beginning of a string and leading or trailing spaces.

- -
-
esc_2254
-
- -

Escape the "special" characters in a field as required by RFC 2254 in a field. That is, the NUL character and of ()*.

- -
-
esc_ctrl
-
- -

Escape non-printable ASCII characters, codes less than 0x20 (space) or greater than 0x7F (DELETE). They are displayed using RFC 2253 \XX notation where XX are the two hex digits representing the character value.

- -
-
esc_msb
-
- -

Escape any characters with the most significant bit set, that is with values larger than 127, as described in esc_ctrl.

- -
-
use_quote
-
- -

Escapes some characters by surrounding the entire string with quotation marks, ". Without this option, individual special characters are preceded with a backslash character, \.

- -
-
utf8
-
- -

Convert all strings to UTF-8 format first as required by RFC 2253. If the output device is UTF-8 compatible, then using this option (and not setting esc_msb) may give the correct display of multibyte characters. If this option is not set, then multibyte characters larger than 0xFF will be output as \UXXXX for 16 bits or \WXXXXXXXX for 32 bits. In addition, any UTF8Strings will be converted to their character form first.

- -
-
ignore_type
-
- -

This option does not attempt to interpret multibyte characters in any way. That is, the content octets are merely dumped as though one octet represents each character. This is useful for diagnostic purposes but will result in rather odd looking output.

- -
-
show_type
-
- -

Display the type of the ASN1 character string before the value, such as BMPSTRING: Hello World.

- -
-
dump_der
-
- -

Any fields that would be output in hex format are displayed using the DER encoding of the field. If not set, just the content octets are displayed. Either way, the #XXXX... format of RFC 2253 is used.

- -
-
dump_nostr
-
- -

Dump non-character strings, such as ASN.1 OCTET STRING. If this option is not set, then non character string types will be displayed as though each content octet represents a single character.

- -
-
dump_all
-
- -

Dump all fields. When this used with dump_der, this allows the DER encoding of the structure to be unambiguously determined.

- -
-
dump_unknown
-
- -

Dump any field whose OID is not recognised by OpenSSL.

- -
-
sep_comma_plus, sep_comma_plus_space, sep_semi_plus_space, sep_multiline
-
- -

Specify the field separators. The first word is used between the Relative Distinguished Names (RDNs) and the second is between multiple Attribute Value Assertions (AVAs). Multiple AVAs are very rare and their use is discouraged. The options ending in "space" additionally place a space after the separator to make it more readable. The sep_multiline starts each field on its own line, and uses "plus space" for the AVA separator. It also indents the fields by four characters. The default value is sep_comma_plus_space.

- -
-
dn_rev
-
- -

Reverse the fields of the DN as required by RFC 2253. This also reverses the order of multiple AVAs in a field, but this is permissible as there is no ordering on values.

- -
-
nofname, sname, lname, oid
-
- -

Specify how the field name is displayed. nofname does not display the field at all. sname uses the "short name" form (CN for commonName for example). lname uses the long form. oid represents the OID in numerical form and is useful for diagnostic purpose.

- -
-
align
-
- -

Align field values for a more readable output. Only usable with sep_multiline.

- -
-
space_eq
-
- -

Places spaces round the equal sign, =, character which follows the field name.

- -
-
- -

COPYRIGHT

- -

Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-nseq.html b/openssl-install/share/doc/openssl/html/man1/openssl-nseq.html deleted file mode 100644 index 2920bcaa..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-nseq.html +++ /dev/null @@ -1,102 +0,0 @@ - - - - -openssl-nseq - - - - - - - - - - -

NAME

- -

openssl-nseq - create or examine a Netscape certificate sequence

- -

SYNOPSIS

- -

openssl nseq [-help] [-in filename] [-out filename] [-toseq] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command takes a file containing a Netscape certificate sequence and prints out the certificates contained in it or takes a file of certificates and converts it into a Netscape certificate sequence.

- -

A Netscape certificate sequence is an old Netscape-specific format that can be sometimes be sent to browsers as an alternative to the standard PKCS#7 format when several certificates are sent to the browser, for example during certificate enrollment. It was also used by Netscape certificate server.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-in filename
-
- -

This specifies the input filename to read or standard input if this option is not specified.

- -
-
-out filename
-
- -

Specifies the output filename or standard output by default.

- -
-
-toseq
-
- -

Normally a Netscape certificate sequence will be input and the output is the certificates contained in it. With the -toseq option the situation is reversed: a Netscape certificate sequence is created from a file of certificates.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

EXAMPLES

- -

Output the certificates in a Netscape certificate sequence

- -
openssl nseq -in nseq.pem -out certs.pem
- -

Create a Netscape certificate sequence

- -
openssl nseq -in certs.pem -toseq -out nseq.pem
- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-ocsp.html b/openssl-install/share/doc/openssl/html/man1/openssl-ocsp.html deleted file mode 100644 index 7d678184..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-ocsp.html +++ /dev/null @@ -1,478 +0,0 @@ - - - - -openssl-ocsp - - - - - - - - - - -

NAME

- -

openssl-ocsp - Online Certificate Status Protocol command

- -

SYNOPSIS

- -

OCSP Client

- -

openssl ocsp [-help] [-out file] [-issuer file] [-cert file] [-no_certs] [-serial n] [-signer file] [-signkey file] [-sign_other file] [-nonce] [-no_nonce] [-req_text] [-resp_text] [-text] [-reqout file] [-respout file] [-reqin file] [-respin file] [-url URL] [-host host:port] [-path pathname] [-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]] [-no_proxy addresses] [-header] [-timeout seconds] [-VAfile file] [-validity_period n] [-status_age n] [-noverify] [-verify_other file] [-trust_other] [-no_intern] [-no_signature_verify] [-no_cert_verify] [-no_chain] [-no_cert_checks] [-no_explicit] [-port num] [-ignore_err]

- -

OCSP Server

- -

openssl ocsp [-index file] [-CA file] [-rsigner file] [-rkey file] [-passin arg] [-rother file] [-rsigopt nm:v] [-rmd digest] [-badsig] [-resp_no_certs] [-nmin n] [-ndays n] [-resp_key_id] [-nrequest n] [-multi process-count] [-rcid digest] [-digest] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

The Online Certificate Status Protocol (OCSP) enables applications to determine the (revocation) state of an identified certificate (RFC 2560).

- -

This command performs many common OCSP tasks. It can be used to print out requests and responses, create requests and send queries to an OCSP responder and behave like a mini OCSP server itself.

- -

OPTIONS

- -

This command operates as either a client or a server. The options are described below, divided into those two modes.

- -

OCSP Client Options

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-out filename
-
- -

specify output filename, default is standard output.

- -
-
-issuer filename
-
- -

This specifies the current issuer certificate. The input can be in PEM, DER, or PKCS#12 format.

- -

This option can be used multiple times. This option MUST come before any -cert options.

- -
-
-cert filename
-
- -

Add the certificate filename to the request. The input can be in PEM, DER, or PKCS#12 format.

- -

This option can be used multiple times. The issuer certificate is taken from the previous -issuer option, or an error occurs if no issuer certificate is specified.

- -
-
-no_certs
-
- -

Don't include any certificates in signed request.

- -
-
-serial num
-
- -

Same as the -cert option except the certificate with serial number num is added to the request. The serial number is interpreted as a decimal integer unless preceded by 0x. Negative integers can also be specified by preceding the value by a - sign.

- -
-
-signer filename, -signkey filename
-
- -

Sign the OCSP request using the certificate specified in the -signer option and the private key specified by the -signkey option. The input can be in PEM, DER, or PKCS#12 format.

- -

If the -signkey option is not present then the private key is read from the same file as the certificate. If neither option is specified then the OCSP request is not signed.

- -
-
-sign_other filename
-
- -

Additional certificates to include in the signed request. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-nonce, -no_nonce
-
- -

Add an OCSP nonce extension to a request or disable OCSP nonce addition. Normally if an OCSP request is input using the -reqin option no nonce is added: using the -nonce option will force addition of a nonce. If an OCSP request is being created (using -cert and -serial options) a nonce is automatically added specifying -no_nonce overrides this.

- -
-
-req_text, -resp_text, -text
-
- -

Print out the text form of the OCSP request, response or both respectively.

- -
-
-reqout file, -respout file
-
- -

Write out the DER encoded certificate request or response to file.

- -
-
-reqin file, -respin file
-
- -

Read OCSP request or response file from file. These option are ignored if OCSP request or response creation is implied by other options (for example with -serial, -cert and -host options).

- -
-
-url responder_url
-
- -

Specify the responder host and optionally port and path via a URL. Both HTTP and HTTPS (SSL/TLS) URLs can be specified. The optional userinfo and fragment components are ignored. Any given query component is handled as part of the path component. For details, see the -host and -path options described next.

- -
-
-host host:port, -path pathname
-
- -

If the -host option is present then the OCSP request is sent to the host host on port port. The host may be a domain name or an IP (v4 or v6) address, such as 127.0.0.1 or [::1] for localhost. If it is an IPv6 address, it must be enclosed in [ and ].

- -

The -path option specifies the HTTP pathname to use or "/" by default. This is equivalent to specifying -url with scheme http:// and the given host, port, and optional pathname.

- -
-
-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]
-
- -

The HTTP(S) proxy server to use for reaching the OCSP server unless -no_proxy applies, see below. If the host string is an IPv6 address, it must be enclosed in [ and ]. The proxy port defaults to 80 or 443 if the scheme is https; apart from that the optional http:// or https:// prefix is ignored, as well as any userinfo, path, query, and fragment components. Defaults to the environment variable http_proxy if set, else HTTP_PROXY in case no TLS is used, otherwise https_proxy if set, else HTTPS_PROXY.

- -
-
-no_proxy addresses
-
- -

List of IP addresses and/or DNS names of servers not to use an HTTP(S) proxy for, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Default is from the environment variable no_proxy if set, else NO_PROXY.

- -
-
-header name=value
-
- -

Adds the header name with the specified value to the OCSP request that is sent to the responder. This may be repeated.

- -
-
-timeout seconds
-
- -

Connection timeout to the OCSP responder in seconds. On POSIX systems, when running as an OCSP responder, this option also limits the time that the responder is willing to wait for the client request. This time is measured from the time the responder accepts the connection until the complete request is received.

- -
-
-verify_other file
-
- -

File or URI containing additional certificates to search when attempting to locate the OCSP response signing certificate. Some responders omit the actual signer's certificate from the response: this option can be used to supply the necessary certificate in such cases. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-trust_other
-
- -

The certificates specified by the -verify_other option should be explicitly trusted and no additional checks will be performed on them. This is useful when the complete responder certificate chain is not available or trusting a root CA is not appropriate.

- -
-
-VAfile file
-
- -

File or URI containing explicitly trusted responder certificates. Equivalent to the -verify_other and -trust_other options. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-noverify
-
- -

Don't attempt to verify the OCSP response signature or the nonce values. This option will normally only be used for debugging since it disables all verification of the responders certificate.

- -
-
-no_intern
-
- -

Ignore certificates contained in the OCSP response when searching for the signers certificate. With this option the signers certificate must be specified with either the -verify_other or -VAfile options.

- -
-
-no_signature_verify
-
- -

Don't check the signature on the OCSP response. Since this option tolerates invalid signatures on OCSP responses it will normally only be used for testing purposes.

- -
-
-no_cert_verify
-
- -

Don't verify the OCSP response signers certificate at all. Since this option allows the OCSP response to be signed by any certificate it should only be used for testing purposes.

- -
-
-no_chain
-
- -

Do not use certificates in the response as additional untrusted CA certificates.

- -
-
-no_explicit
-
- -

Do not explicitly trust the root CA if it is set to be trusted for OCSP signing.

- -
-
-no_cert_checks
-
- -

Don't perform any additional checks on the OCSP response signers certificate. That is do not make any checks to see if the signers certificate is authorised to provide the necessary status information: as a result this option should only be used for testing purposes.

- -
-
-validity_period nsec, -status_age age
-
- -

These options specify the range of times, in seconds, which will be tolerated in an OCSP response. Each certificate status response includes a notBefore time and an optional notAfter time. The current time should fall between these two values, but the interval between the two times may be only a few seconds. In practice the OCSP responder and clients clocks may not be precisely synchronised and so such a check may fail. To avoid this the -validity_period option can be used to specify an acceptable error range in seconds, the default value is 5 minutes.

- -

If the notAfter time is omitted from a response then this means that new status information is immediately available. In this case the age of the notBefore field is checked to see it is not older than age seconds old. By default this additional check is not performed.

- -
-
-rcid digest
-
- -

This option sets the digest algorithm to use for certificate identification in the OCSP response. Any digest supported by the openssl-dgst(1) command can be used. The default is the same digest algorithm used in the request.

- -
-
-digest
-
- -

This option sets digest algorithm to use for certificate identification in the OCSP request. Any digest supported by the OpenSSL dgst command can be used. The default is SHA-1. This option may be used multiple times to specify the digest used by subsequent certificate identifiers.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

OCSP Server Options

- -
- -
-index indexfile
-
- -

The indexfile parameter is the name of a text index file in ca format containing certificate revocation information.

- -

If the -index option is specified then this command switches to responder mode, otherwise it is in client mode. The request(s) the responder processes can be either specified on the command line (using -issuer and -serial options), supplied in a file (using the -reqin option) or via external OCSP clients (if -port or -url is specified).

- -

If the -index option is present then the -CA and -rsigner options must also be present.

- -
-
-CA file
-
- -

CA certificates corresponding to the revocation information in the index file given with -index. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-rsigner file
-
- -

The certificate to sign OCSP responses with. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-rkey file
-
- -

The private key to sign OCSP responses with: if not present the file specified in the -rsigner option is used.

- -
-
-passin arg
-
- -

The private key password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-rother file
-
- -

Additional certificates to include in the OCSP response. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-rsigopt nm:v
-
- -

Pass options to the signature algorithm when signing OCSP responses. Names and values of these options are algorithm-specific.

- -
-
-rmd digest
-
- -

The digest to use when signing the response.

- -
-
-badsig
-
- -

Corrupt the response signature before writing it; this can be useful for testing.

- -
-
-resp_no_certs
-
- -

Don't include any certificates in the OCSP response.

- -
-
-resp_key_id
-
- -

Identify the signer certificate using the key ID, default is to use the subject name.

- -
-
-port portnum
-
- -

Port to listen for OCSP requests on. Both IPv4 and IPv6 are possible. The port may also be specified using the -url option. A 0 argument indicates that any available port shall be chosen automatically.

- -
-
-ignore_err
-
- -

Ignore malformed requests or responses: When acting as an OCSP client, retry if a malformed response is received. When acting as an OCSP responder, continue running instead of terminating upon receiving a malformed request.

- -
-
-nrequest number
-
- -

The OCSP server will exit after receiving number requests, default unlimited.

- -
-
-multi process-count
-
- -

Run the specified number of OCSP responder child processes, with the parent process respawning child processes as needed. Child processes will detect changes in the CA index file and automatically reload it. When running as a responder -timeout option is recommended to limit the time each child is willing to wait for the client's OCSP response. This option is available on POSIX systems (that support the fork() and other required unix system-calls).

- -
-
-nmin minutes, -ndays days
-
- -

Number of minutes or days when fresh revocation information is available: used in the nextUpdate field. If neither option is present then the nextUpdate field is omitted meaning fresh revocation information is immediately available.

- -
-
- -

OCSP RESPONSE VERIFICATION

- -

OCSP Response follows the rules specified in RFC2560.

- -

Initially the OCSP responder certificate is located and the signature on the OCSP request checked using the responder certificate's public key.

- -

Then a normal certificate verify is performed on the OCSP responder certificate building up a certificate chain in the process. The locations of the trusted certificates used to build the chain can be specified by the -CAfile, -CApath or -CAstore options or they will be looked for in the standard OpenSSL certificates directory.

- -

If the initial verify fails then the OCSP verify process halts with an error.

- -

Otherwise the issuing CA certificate in the request is compared to the OCSP responder certificate: if there is a match then the OCSP verify succeeds.

- -

Otherwise the OCSP responder certificate's CA is checked against the issuing CA certificate in the request. If there is a match and the OCSPSigning extended key usage is present in the OCSP responder certificate then the OCSP verify succeeds.

- -

Otherwise, if -no_explicit is not set the root CA of the OCSP responders CA is checked to see if it is trusted for OCSP signing. If it is the OCSP verify succeeds.

- -

If none of these checks is successful then the OCSP verify fails.

- -

What this effectively means if that if the OCSP responder certificate is authorised directly by the CA it is issuing revocation information about (and it is correctly configured) then verification will succeed.

- -

If the OCSP responder is a "global responder" which can give details about multiple CAs and has its own separate certificate chain then its root CA can be trusted for OCSP signing. For example:

- -
openssl x509 -in ocspCA.pem -addtrust OCSPSigning -out trustedCA.pem
- -

Alternatively the responder certificate itself can be explicitly trusted with the -VAfile option.

- -

NOTES

- -

As noted, most of the verify options are for testing or debugging purposes. Normally only the -CApath, -CAfile, -CAstore and (if the responder is a 'global VA') -VAfile options need to be used.

- -

The OCSP server is only useful for test and demonstration purposes: it is not really usable as a full OCSP responder. It contains only a very simple HTTP request handling and can only handle the POST form of OCSP queries. It also handles requests serially meaning it cannot respond to new requests until it has processed the current one. The text index file format of revocation is also inefficient for large quantities of revocation data.

- -

It is possible to run this command in responder mode via a CGI script using the -reqin and -respout options.

- -

EXAMPLES

- -

Create an OCSP request and write it to a file:

- -
openssl ocsp -issuer issuer.pem -cert c1.pem -cert c2.pem -reqout req.der
- -

Send a query to an OCSP responder with URL http://ocsp.myhost.com/ save the response to a file, print it out in text form, and verify the response:

- -
openssl ocsp -issuer issuer.pem -cert c1.pem -cert c2.pem \
-    -url http://ocsp.myhost.com/ -resp_text -respout resp.der
- -

Read in an OCSP response and print out text form:

- -
openssl ocsp -respin resp.der -text -noverify
- -

OCSP server on port 8888 using a standard ca configuration, and a separate responder certificate. All requests and responses are printed to a file.

- -
openssl ocsp -index demoCA/index.txt -port 8888 -rsigner rcert.pem -CA demoCA/cacert.pem
-       -text -out log.txt
- -

As above but exit after processing one request:

- -
openssl ocsp -index demoCA/index.txt -port 8888 -rsigner rcert.pem -CA demoCA/cacert.pem
-    -nrequest 1
- -

Query status information using an internally generated request:

- -
openssl ocsp -index demoCA/index.txt -rsigner rcert.pem -CA demoCA/cacert.pem
-    -issuer demoCA/cacert.pem -serial 1
- -

Query status information using request read from a file, and write the response to a second file.

- -
openssl ocsp -index demoCA/index.txt -rsigner rcert.pem -CA demoCA/cacert.pem
-    -reqin req.der -respout resp.der
- -

HISTORY

- -

The -no_alt_chains option was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-passphrase-options.html b/openssl-install/share/doc/openssl/html/man1/openssl-passphrase-options.html deleted file mode 100644 index b795582a..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-passphrase-options.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -openssl-passphrase-options - - - - - - - - - - -

NAME

- -

openssl-passphrase-options - Pass phrase options

- -

SYNOPSIS

- -

openssl command [ options ... ] [ parameters ... ]

- -

DESCRIPTION

- -

Several OpenSSL commands accept password arguments, typically using -passin and -passout for input and output passwords respectively. These allow the password to be obtained from a variety of sources. Both of these options take a single argument whose format is described below. If no password argument is given and a password is required then the user is prompted to enter one: this will typically be read from the current terminal with echoing turned off.

- -

Note that character encoding may be relevant, please see passphrase-encoding(7).

- -

OPTIONS

- -

Pass Phrase Option Arguments

- -

Pass phrase arguments can be formatted as follows.

- -
- -
pass:password
-
- -

The actual password is password. Since the password is visible to utilities (like 'ps' under Unix) this form should only be used where security is not important.

- -
-
env:var
-
- -

Obtain the password from the environment variable var. Since the environment of other processes is visible on certain platforms (e.g. ps under certain Unix OSes) this option should be used with caution.

- -
-
file:pathname
-
- -

Reads the password from the specified file pathname, which can be a regular file, device, or named pipe. Only the first line, up to the newline character, is read from the stream.

- -

If the same pathname argument is supplied to both -passin and -passout arguments, the first line will be used for the input password, and the next line will be used for the output password.

- -
-
fd:number
-
- -

Reads the password from the file descriptor number. This can be useful for sending data via a pipe, for example. The same line handling as described for file: applies to passwords read from file descriptors.

- -

fd: is not supported on Windows.

- -
-
stdin
-
- -

Reads the password from standard input. The same line handling as described for file: applies to passwords read from standard input.

- -
-
- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-passwd.html b/openssl-install/share/doc/openssl/html/man1/openssl-passwd.html deleted file mode 100644 index 20bc275f..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-passwd.html +++ /dev/null @@ -1,164 +0,0 @@ - - - - -openssl-passwd - - - - - - - - - - -

NAME

- -

openssl-passwd - compute password hashes

- -

SYNOPSIS

- -

openssl passwd [-help] [-1] [-apr1] [-aixmd5] [-5] [-6] [-salt string] [-in file] [-stdin] [-noverify] [-quiet] [-table] [-reverse] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq] [password]

- -

DESCRIPTION

- -

This command computes the hash of a password typed at run-time or the hash of each password in a list. The password list is taken from the named file for option -in, from stdin for option -stdin, or from the command line, or from the terminal otherwise.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-1
-
- -

Use the MD5 based BSD password algorithm 1 (default).

- -
-
-apr1
-
- -

Use the apr1 algorithm (Apache variant of the BSD algorithm).

- -
-
-aixmd5
-
- -

Use the AIX MD5 algorithm (AIX variant of the BSD algorithm).

- -
-
-5
-
- -
-
-6
-
- -

Use the SHA256 / SHA512 based algorithms defined by Ulrich Drepper. See https://www.akkadia.org/drepper/SHA-crypt.txt.

- -
-
-salt string
-
- -

Use the specified salt. When reading a password from the terminal, this implies -noverify.

- -
-
-in file
-
- -

Read passwords from file.

- -
-
-stdin
-
- -

Read passwords from stdin.

- -
-
-noverify
-
- -

Don't verify when reading a password from the terminal.

- -
-
-quiet
-
- -

Don't output warnings when passwords given at the command line are truncated.

- -
-
-table
-
- -

In the output list, prepend the cleartext password and a TAB character to each password hash.

- -
-
-reverse
-
- -

When the -table option is used, reverse the order of cleartext and hash.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

EXAMPLES

- -
% openssl passwd -1 -salt xxxxxxxx password
-$1$xxxxxxxx$UYCIxa628.9qXjpQCjM4a.
-
-% openssl passwd -apr1 -salt xxxxxxxx password
-$apr1$xxxxxxxx$dxHfLAsjHkDRmG83UXe8K0
-
-% openssl passwd -aixmd5 -salt xxxxxxxx password
-xxxxxxxx$8Oaipk/GPKhC64w/YVeFD/
- -

HISTORY

- -

The -crypt option was removed in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-pkcs12.html b/openssl-install/share/doc/openssl/html/man1/openssl-pkcs12.html deleted file mode 100644 index 87288568..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-pkcs12.html +++ /dev/null @@ -1,459 +0,0 @@ - - - - -openssl-pkcs12 - - - - - - - - - - -

NAME

- -

openssl-pkcs12 - PKCS#12 file command

- -

SYNOPSIS

- -

openssl pkcs12 [-help] [-passin arg] [-passout arg] [-password arg] [-twopass] [-in filename|uri] [-out filename] [-nokeys] [-nocerts] [-noout] [-legacy] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [-rand files] [-writerand file]

- -

PKCS#12 input (parsing) options: [-info] [-nomacver] [-clcerts] [-cacerts]

- -

[-aes128] [-aes192] [-aes256] [-aria128] [-aria192] [-aria256] [-camellia128] [-camellia192] [-camellia256] [-des] [-des3] [-idea] [-noenc] [-nodes]

- -

PKCS#12 output (export) options:

- -

[-export] [-inkey filename|uri] [-certfile filename] [-passcerts arg] [-chain] [-untrusted filename] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-name name] [-caname name] [-CSP name] [-LMK] [-keyex] [-keysig] [-keypbe cipher] [-certpbe cipher] [-descert] [-macalg digest] [-pbmac1_pbkdf2] [-pbmac1_pbkdf2_md digest] [-iter count] [-noiter] [-nomaciter] [-maciter] [-macsaltlen] [-nomac] [-jdktrust usage]

- -

DESCRIPTION

- -

This command allows PKCS#12 files (sometimes referred to as PFX files) to be created and parsed. PKCS#12 files are used by several programs including Netscape, MSIE and MS Outlook.

- -

OPTIONS

- -

There are a lot of options the meaning of some depends of whether a PKCS#12 file is being created or parsed. By default a PKCS#12 file is parsed. A PKCS#12 file can be created by using the -export option (see below). The PKCS#12 export encryption and MAC options such as -certpbe and -iter and many further options such as -chain are relevant only with -export. Conversely, the options regarding encryption of private keys when outputting PKCS#12 input are relevant only when the -export option is not given.

- -

The default encryption algorithm is AES-256-CBC with PBKDF2 for key derivation.

- -

When encountering problems loading legacy PKCS#12 files that involve, for example, RC2-40-CBC, try using the -legacy option and, if needed, the -provider-path option.

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-passin arg
-
- -

The password source for the input, and for encrypting any private keys that are output. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-passout arg
-
- -

The password source for output files.

- -
-
-password arg
-
- -

With -export, -password is equivalent to -passout, otherwise it is equivalent to -passin.

- -
-
-twopass
-
- -

Prompt for separate integrity and encryption passwords: most software always assumes these are the same so this option will render such PKCS#12 files unreadable. Cannot be used in combination with the options -password, -passin if importing from PKCS#12, or -passout if exporting.

- -
-
-nokeys
-
- -

No private keys will be output.

- -
-
-nocerts
-
- -

No certificates will be output.

- -
-
-noout
-
- -

This option inhibits all credentials output, and so the input is just verified.

- -
-
-legacy
-
- -

Use legacy mode of operation and automatically load the legacy provider. If OpenSSL is not installed system-wide, it is necessary to also use, for example, -provider-path ./providers or to set the environment variable OPENSSL_MODULES to point to the directory where the providers can be found.

- -

In the legacy mode, the default algorithm for certificate encryption is RC2_CBC or 3DES_CBC depending on whether the RC2 cipher is enabled in the build. The default algorithm for private key encryption is 3DES_CBC. If the legacy option is not specified, then the legacy provider is not loaded and the default encryption algorithm for both certificates and private keys is AES_256_CBC with PBKDF2 for key derivation.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
- -

PKCS#12 input (parsing) options

- -
- -
-in filename|uri
-
- -

This specifies the input filename or URI. Standard input is used by default. Without the -export option this must be PKCS#12 file to be parsed. For use with the -export option see the "PKCS#12 output (export) options" section.

- -
-
-out filename
-
- -

The filename to write certificates and private keys to, standard output by default. They are all written in PEM format.

- -
-
-info
-
- -

Output additional information about the PKCS#12 file structure, algorithms used and iteration counts.

- -
-
-nomacver
-
- -

Don't attempt to verify the integrity MAC.

- -
-
-clcerts
-
- -

Only output client certificates (not CA certificates).

- -
-
-cacerts
-
- -

Only output CA certificates (not client certificates).

- -
-
-aes128, -aes192, -aes256
-
- -

Use AES to encrypt private keys before outputting.

- -
-
-aria128, -aria192, -aria256
-
- -

Use ARIA to encrypt private keys before outputting.

- -
-
-camellia128, -camellia192, -camellia256
-
- -

Use Camellia to encrypt private keys before outputting.

- -
-
-des
-
- -

Use DES to encrypt private keys before outputting.

- -
-
-des3
-
- -

Use triple DES to encrypt private keys before outputting.

- -
-
-idea
-
- -

Use IDEA to encrypt private keys before outputting.

- -
-
-noenc
-
- -

Don't encrypt private keys at all.

- -
-
-nodes
-
- -

This option is deprecated since OpenSSL 3.0; use -noenc instead.

- -
-
- -

PKCS#12 output (export) options

- -
- -
-export
-
- -

This option specifies that a PKCS#12 file will be created rather than parsed.

- -
-
-out filename
-
- -

This specifies filename to write the PKCS#12 file to. Standard output is used by default.

- -
-
-in filename|uri
-
- -

This specifies the input filename or URI. Standard input is used by default. With the -export option this is a file with certificates and a key, or a URI that refers to a key accessed via an engine. The order of credentials in a file doesn't matter but one private key and its corresponding certificate should be present. If additional certificates are present they will also be included in the PKCS#12 output file.

- -
-
-inkey filename|uri
-
- -

The private key input for PKCS12 output. If this option is not specified then the input file (-in argument) must contain a private key. If no engine is used, the argument is taken as a file. If the -engine option is used or the URI has prefix org.openssl.engine: then the rest of the URI is taken as key identifier for the given engine.

- -
-
-certfile filename
-
- -

An input file with extra certificates to be added to the PKCS#12 output if the -export option is given.

- -
-
-passcerts arg
-
- -

The password source for certificate input such as -certfile and -untrusted. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-chain
-
- -

If this option is present then the certificate chain of the end entity certificate is built and included in the PKCS#12 output file. The end entity certificate is the first one read from the -in file if no key is given, else the first certificate matching the given key. The standard CA trust store is used for chain building, as well as any untrusted CA certificates given with the -untrusted option.

- -
-
-untrusted filename
-
- -

An input file of untrusted certificates that may be used for chain building, which is relevant only when a PKCS#12 file is created with the -export option and the -chain option is given as well. Any certificates that are actually part of the chain are added to the output.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-name friendlyname
-
- -

This specifies the "friendly name" for the certificates and private key. This name is typically displayed in list boxes by software importing the file.

- -
-
-caname friendlyname
-
- -

This specifies the "friendly name" for other certificates. This option may be used multiple times to specify names for all certificates in the order they appear. Netscape ignores friendly names on other certificates whereas MSIE displays them.

- -
-
-CSP name
-
- -

Write name as a Microsoft CSP name. The password source for the input, and for encrypting any private keys that are output. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-LMK
-
- -

Add the "Local Key Set" identifier to the attributes.

- -
-
-keyex|-keysig
-
- -

Specifies that the private key is to be used for key exchange or just signing. This option is only interpreted by MSIE and similar MS software. Normally "export grade" software will only allow 512 bit RSA keys to be used for encryption purposes but arbitrary length keys for signing. The -keysig option marks the key for signing only. Signing only keys can be used for S/MIME signing, authenticode (ActiveX control signing) and SSL client authentication, however, due to a bug only MSIE 5.0 and later support the use of signing only keys for SSL client authentication.

- -
-
-keypbe alg, -certpbe alg
-
- -

These options allow the algorithm used to encrypt the private key and certificates to be selected. Any PKCS#5 v1.5 or PKCS#12 PBE algorithm name can be used (see "NOTES" section for more information). If a cipher name (as output by openssl list -cipher-algorithms) is specified then it is used with PKCS#5 v2.0. For interoperability reasons it is advisable to only use PKCS#12 algorithms.

- -

Special value NONE disables encryption of the private key and certificates.

- -
-
-descert
-
- -

Encrypt the certificates using triple DES. By default the private key and the certificates are encrypted using AES-256-CBC unless the '-legacy' option is used. If '-descert' is used with the '-legacy' then both, the private key and the certificates are encrypted using triple DES.

- -
-
-macalg digest
-
- -

Specify the MAC digest algorithm. If not included SHA256 will be used.

- -
-
-pbmac1_pbkdf2
-
- -

Use PBMAC1 with PBKDF2 for MAC protection of the PKCS#12 file.

- -
-
-pbmac1_pbkdf2_md digest
-
- -

Specify the PBKDF2 KDF digest algorithm. If not specified, SHA256 will be used. Unless -pbmac1_pbkdf2 is specified, this parameter is ignored.

- -
-
-iter count
-
- -

This option specifies the iteration count for the encryption key and MAC. The default value is 2048.

- -

To discourage attacks by using large dictionaries of common passwords the algorithm that derives keys from passwords can have an iteration count applied to it: this causes a certain part of the algorithm to be repeated and slows it down. The MAC is used to check the file integrity but since it will normally have the same password as the keys and certificates it could also be attacked.

- -
-
-noiter, -nomaciter
-
- -

By default both encryption and MAC iteration counts are set to 2048, using these options the MAC and encryption iteration counts can be set to 1, since this reduces the file security you should not use these options unless you really have to. Most software supports both MAC and encryption iteration counts. MSIE 4.0 doesn't support MAC iteration counts so it needs the -nomaciter option.

- -
-
-maciter
-
- -

This option is included for compatibility with previous versions, it used to be needed to use MAC iterations counts but they are now used by default.

- -
-
-macsaltlen
-
- -

This option specifies the salt length in bytes for the MAC. The salt length should be at least 16 bytes as per NIST SP 800-132. The default value is 8 bytes for backwards compatibility.

- -
-
-nomac
-
- -

Do not attempt to provide the MAC integrity. This can be useful with the FIPS provider as the PKCS12 MAC requires PKCS12KDF which is not an approved FIPS algorithm and cannot be supported by the FIPS provider.

- -
-
-jdktrust
-
- -

Export pkcs12 file in a format compatible with Java keystore usage. This option accepts a string parameter indicating the trust oid name to be granted to the certificate it is associated with. Currently only "anyExtendedKeyUsage" is defined. Note that, as Java keystores do not accept PKCS12 files with both trusted certificates and keypairs, use of this option implies the setting of the -nokeys option

- -
-
- -

NOTES

- -

Although there are a large number of options most of them are very rarely used. For PKCS#12 file parsing only -in and -out need to be used for PKCS#12 file creation -export and -name are also used.

- -

If none of the -clcerts, -cacerts or -nocerts options are present then all certificates will be output in the order they appear in the input PKCS#12 files. There is no guarantee that the first certificate present is the one corresponding to the private key. Certain software which tries to get a private key and the corresponding certificate might assume that the first certificate in the file is the one corresponding to the private key, but that may not always be the case. Using the -clcerts option will solve this problem by only outputting the certificate corresponding to the private key. If the CA certificates are required then they can be output to a separate file using the -nokeys -cacerts options to just output CA certificates.

- -

The -keypbe and -certpbe algorithms allow the precise encryption algorithms for private keys and certificates to be specified. Normally the defaults are fine but occasionally software can't handle triple DES encrypted private keys, then the option -keypbe PBE-SHA1-RC2-40 can be used to reduce the private key encryption to 40 bit RC2. A complete description of all algorithms is contained in openssl-pkcs8(1).

- -

Prior 1.1 release passwords containing non-ASCII characters were encoded in non-compliant manner, which limited interoperability, in first hand with Windows. But switching to standard-compliant password encoding poses problem accessing old data protected with broken encoding. For this reason even legacy encodings is attempted when reading the data. If you use PKCS#12 files in production application you are advised to convert the data, because implemented heuristic approach is not MT-safe, its sole goal is to facilitate the data upgrade with this command.

- -

EXAMPLES

- -

Parse a PKCS#12 file and output it to a PEM file:

- -
openssl pkcs12 -in file.p12 -out file.pem
- -

Output only client certificates to a file:

- -
openssl pkcs12 -in file.p12 -clcerts -out file.pem
- -

Don't encrypt the private key:

- -
openssl pkcs12 -in file.p12 -out file.pem -noenc
- -

Print some info about a PKCS#12 file:

- -
openssl pkcs12 -in file.p12 -info -noout
- -

Print some info about a PKCS#12 file in legacy mode:

- -
openssl pkcs12 -in file.p12 -info -noout -legacy
- -

Create a PKCS#12 file from a PEM file that may contain a key and certificates:

- -
openssl pkcs12 -export -in file.pem -out file.p12 -name "My PSE"
- -

Include some extra certificates:

- -
openssl pkcs12 -export -in file.pem -out file.p12 -name "My PSE" \
- -certfile othercerts.pem
- -

Export a PKCS#12 file with data from a certificate PEM file and from a further PEM file containing a key, with default algorithms as in the legacy provider:

- -
openssl pkcs12 -export -in cert.pem -inkey key.pem -out file.p12 -legacy
- -

SEE ALSO

- -

openssl(1), openssl-pkcs8(1), ossl_store-file(7)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0. The -nodes option was deprecated in OpenSSL 3.0, too; use -noenc instead.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-pkcs7.html b/openssl-install/share/doc/openssl/html/man1/openssl-pkcs7.html deleted file mode 100644 index 3341e47c..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-pkcs7.html +++ /dev/null @@ -1,148 +0,0 @@ - - - - -openssl-pkcs7 - - - - - - - - - - -

NAME

- -

openssl-pkcs7 - PKCS#7 command

- -

SYNOPSIS

- -

openssl pkcs7 [-help] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-out filename] [-print] [-print_certs] [-quiet] [-text] [-noout] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command processes PKCS#7 files. Note that it only understands PKCS#7 v 1.5 as specified in IETF RFC 2315. It cannot currently parse CMS as described in IETF RFC 2630.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM, -outform DER|PEM
-
- -

The input and formats; the default is PEM. See openssl-format-options(1) for details.

- -

The data is a PKCS#7 Version 1.5 structure.

- -
-
-in filename
-
- -

This specifies the input filename to read from or standard input if this option is not specified.

- -
-
-out filename
-
- -

Specifies the output filename to write to or standard output by default.

- -
-
-print
-
- -

Print out the full PKCS7 object.

- -
- -
- -

Prints out any certificates or CRLs contained in the file. They are preceded by their subject and issuer names in one line format.

- -
-
-quiet
-
- -

When used with -print_certs, prints out just the PEM-encoded certificates without any other output.

- -
-
-text
-
- -

Prints out certificate details in full rather than just subject and issuer names.

- -
-
-noout
-
- -

Don't output the encoded version of the PKCS#7 structure (or certificates if -print_certs is set).

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

EXAMPLES

- -

Convert a PKCS#7 file from PEM to DER:

- -
openssl pkcs7 -in file.pem -outform DER -out file.der
- -

Output all certificates in a file:

- -
openssl pkcs7 -in file.pem -print_certs -out certs.pem
- -

SEE ALSO

- -

openssl(1), openssl-crl2pkcs7(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-pkcs8.html b/openssl-install/share/doc/openssl/html/man1/openssl-pkcs8.html deleted file mode 100644 index cfe87eac..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-pkcs8.html +++ /dev/null @@ -1,286 +0,0 @@ - - - - -openssl-pkcs8 - - - - - - - - - - -

NAME

- -

openssl-pkcs8 - PKCS#8 format private key conversion command

- -

SYNOPSIS

- -

openssl pkcs8 [-help] [-topk8] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-passin arg] [-out filename] [-passout arg] [-iter count] [-noiter] [-nocrypt] [-traditional] [-v2 alg] [-v2prf alg] [-v1 alg] [-scrypt] [-scrypt_N N] [-scrypt_r r] [-scrypt_p p] [-saltlen size] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command processes private keys in PKCS#8 format. It can handle both unencrypted PKCS#8 PrivateKeyInfo format and EncryptedPrivateKeyInfo format with a variety of PKCS#5 (v1.5 and v2.0) and PKCS#12 algorithms.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-topk8
-
- -

Normally a PKCS#8 private key is expected on input and a private key will be written to the output file. With the -topk8 option the situation is reversed: it reads a private key and writes a PKCS#8 format key.

- -
-
-inform DER|PEM, -outform DER|PEM
-
- -

The input and formats; the default is PEM. See openssl-format-options(1) for details.

- -

If a key is being converted from PKCS#8 form (i.e. the -topk8 option is not used) then the input file must be in PKCS#8 format. An encrypted key is expected unless -nocrypt is included.

- -

If -topk8 is not used and PEM mode is set the output file will be an unencrypted private key in PKCS#8 format. If the -traditional option is used then a traditional format private key is written instead.

- -

If -topk8 is not used and DER mode is set the output file will be an unencrypted private key in traditional DER format.

- -

If -topk8 is used then any supported private key can be used for the input file in a format specified by -inform. The output file will be encrypted PKCS#8 format using the specified encryption parameters unless -nocrypt is included.

- -
-
-traditional
-
- -

When this option is present and -topk8 is not a traditional format private key is written.

- -
-
-in filename
-
- -

This specifies the input filename to read a key from or standard input if this option is not specified. If the key is encrypted a pass phrase will be prompted for.

- -
-
-passin arg, -passout arg
-
- -

The password source for the input and output file. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-out filename
-
- -

This specifies the output filename to write a key to or standard output by default. If any encryption options are set then a pass phrase will be prompted for. The output filename should not be the same as the input filename.

- -
-
-iter count
-
- -

When creating new PKCS#8 containers, use a given number of iterations on the password in deriving the encryption key for the PKCS#8 output. High values increase the time required to brute-force a PKCS#8 container.

- -
-
-noiter
-
- -

When creating new PKCS#8 containers, use 1 as iteration count.

- -
-
-nocrypt
-
- -

PKCS#8 keys generated or input are normally PKCS#8 EncryptedPrivateKeyInfo structures using an appropriate password based encryption algorithm. With this option an unencrypted PrivateKeyInfo structure is expected or output. This option does not encrypt private keys at all and should only be used when absolutely necessary. Certain software such as some versions of Java code signing software used unencrypted private keys.

- -
-
-v2 alg
-
- -

This option sets the PKCS#5 v2.0 algorithm.

- -

The alg argument is the encryption algorithm to use, valid values include aes128, aes256 and des3. If this option isn't specified then aes256 is used.

- -
-
-v2prf alg
-
- -

This option sets the PRF algorithm to use with PKCS#5 v2.0. A typical value value would be hmacWithSHA256. If this option isn't set then the default for the cipher is used or hmacWithSHA256 if there is no default.

- -

Some implementations may not support custom PRF algorithms and may require the hmacWithSHA1 option to work.

- -
-
-v1 alg
-
- -

This option indicates a PKCS#5 v1.5 or PKCS#12 algorithm should be used. Some older implementations may not support PKCS#5 v2.0 and may require this option. If not specified PKCS#5 v2.0 form is used.

- -
-
-scrypt
-
- -

Uses the scrypt algorithm for private key encryption using default parameters: currently N=16384, r=8 and p=1 and AES in CBC mode with a 256 bit key. These parameters can be modified using the -scrypt_N, -scrypt_r, -scrypt_p and -v2 options.

- -
-
-scrypt_N N, -scrypt_r r, -scrypt_p p
-
- -

Sets the scrypt N, r or p parameters.

- -
-
-saltlen
-
- -

Sets the length (in bytes) of the salt to use for the PBE algorithm. If this value is not specified, the default for PBES2 is 16 (128 bits) and 8 (64 bits) for PBES1.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

NOTES

- -

By default, when converting a key to PKCS#8 format, PKCS#5 v2.0 using 256 bit AES with HMAC and SHA256 is used.

- -

Some older implementations do not support PKCS#5 v2.0 format and require the older PKCS#5 v1.5 form instead, possibly also requiring insecure weak encryption algorithms such as 56 bit DES.

- -

Private keys encrypted using PKCS#5 v2.0 algorithms and high iteration counts are more secure that those encrypted using the traditional SSLeay compatible formats. So if additional security is considered important the keys should be converted.

- -

It is possible to write out DER encoded encrypted private keys in PKCS#8 format because the encryption details are included at an ASN1 level whereas the traditional format includes them at a PEM level.

- -

PKCS#5 V1.5 AND PKCS#12 ALGORITHMS

- -

Various algorithms can be used with the -v1 command line option, including PKCS#5 v1.5 and PKCS#12. These are described in more detail below.

- -
- -
PBE-MD2-DES PBE-MD5-DES
-
- -

These algorithms were included in the original PKCS#5 v1.5 specification. They only offer 56 bits of protection since they both use DES.

- -
-
PBE-SHA1-RC2-64, PBE-MD2-RC2-64, PBE-MD5-RC2-64, PBE-SHA1-DES
-
- -

These algorithms are not mentioned in the original PKCS#5 v1.5 specification but they use the same key derivation algorithm and are supported by some software. They are mentioned in PKCS#5 v2.0. They use either 64 bit RC2 or 56 bit DES.

- -
-
PBE-SHA1-RC4-128, PBE-SHA1-RC4-40, PBE-SHA1-3DES, PBE-SHA1-2DES, PBE-SHA1-RC2-128, PBE-SHA1-RC2-40
-
- -

These algorithms use the PKCS#12 password based encryption algorithm and allow strong encryption algorithms like triple DES or 128 bit RC2 to be used.

- -
-
- -

EXAMPLES

- -

Convert a private key to PKCS#8 format using default parameters (AES with 256 bit key and hmacWithSHA256):

- -
openssl pkcs8 -in key.pem -topk8 -out enckey.pem
- -

Convert a private key to PKCS#8 unencrypted format:

- -
openssl pkcs8 -in key.pem -topk8 -nocrypt -out enckey.pem
- -

Convert a private key to PKCS#5 v2.0 format using triple DES:

- -
openssl pkcs8 -in key.pem -topk8 -v2 des3 -out enckey.pem
- -

Convert a private key to PKCS#5 v2.0 format using AES with 256 bits in CBC mode and hmacWithSHA512 PRF:

- -
openssl pkcs8 -in key.pem -topk8 -v2 aes-256-cbc -v2prf hmacWithSHA512 -out enckey.pem
- -

Convert a private key to PKCS#8 using a PKCS#5 1.5 compatible algorithm (DES):

- -
openssl pkcs8 -in key.pem -topk8 -v1 PBE-MD5-DES -out enckey.pem
- -

Convert a private key to PKCS#8 using a PKCS#12 compatible algorithm (3DES):

- -
openssl pkcs8 -in key.pem -topk8 -out enckey.pem -v1 PBE-SHA1-3DES
- -

Read a DER unencrypted PKCS#8 format private key:

- -
openssl pkcs8 -inform DER -nocrypt -in key.der -out key.pem
- -

Convert a private key from any PKCS#8 encrypted format to traditional format:

- -
openssl pkcs8 -in pk8.pem -traditional -out key.pem
- -

Convert a private key to PKCS#8 format, encrypting with AES-256 and with one million iterations of the password:

- -
openssl pkcs8 -in key.pem -topk8 -v2 aes-256-cbc -iter 1000000 -out pk8.pem
- -

STANDARDS

- -

Test vectors from this PKCS#5 v2.0 implementation were posted to the pkcs-tng mailing list using triple DES, DES and RC2 with high iteration counts, several people confirmed that they could decrypt the private keys produced and therefore, it can be assumed that the PKCS#5 v2.0 implementation is reasonably accurate at least as far as these algorithms are concerned.

- -

The format of PKCS#8 DSA (and other) private keys is not well documented: it is hidden away in PKCS#11 v2.01, section 11.9. OpenSSL's default DSA PKCS#8 private key format complies with this standard.

- -

BUGS

- -

There should be an option that prints out the encryption algorithm in use and other details such as the iteration count.

- -

SEE ALSO

- -

openssl(1), openssl-dsa(1), openssl-rsa(1), openssl-genrsa(1), openssl-gendsa(1)

- -

HISTORY

- -

The -iter option was added in OpenSSL 1.1.0.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-pkey.html b/openssl-install/share/doc/openssl/html/man1/openssl-pkey.html deleted file mode 100644 index 932bcf6a..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-pkey.html +++ /dev/null @@ -1,254 +0,0 @@ - - - - -openssl-pkey - - - - - - - - - - -

NAME

- -

openssl-pkey - public or private key processing command

- -

SYNOPSIS

- -

openssl pkey [-help] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [-check] [-pubcheck] [-in filename|uri] [-inform DER|PEM|P12|ENGINE] [-passin arg] [-pubin] [-out filename] [-outform DER|PEM] [-cipher] [-passout arg] [-traditional] [-pubout] [-noout] [-text] [-text_pub] [-ec_conv_form arg] [-ec_param_enc arg]

- -

DESCRIPTION

- -

This command processes public or private keys. They can be converted between various forms and their components printed.

- -

OPTIONS

- -

General options

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-check
-
- -

This option checks the consistency of a key pair for both public and private components.

- -
-
-pubcheck
-
- -

This option checks the correctness of either a public key or the public component of a key pair.

- -
-
- -

Input options

- -
- -
-in filename|uri
-
- -

This specifies the input to read a key from or standard input if this option is not specified. If the key input is encrypted and -passin is not given a pass phrase will be prompted for.

- -
-
-inform DER|PEM|P12|ENGINE
-
- -

The key input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-passin arg
-
- -

The password source for the key input.

- -

For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-pubin
-
- -

By default a private key is read from the input. With this option a public key is read instead. If the input contains no public key but a private key, its public part is used.

- -
-
- -

Output options

- -
- -
-out filename
-
- -

This specifies the output filename to save the encoded and/or text output of key or standard output if this option is not specified. If any cipher option is set but no -passout is given then a pass phrase will be prompted for. The output filename should not be the same as the input filename.

- -
-
-outform DER|PEM
-
- -

The key output format; the default is PEM. See openssl-format-options(1) for details.

- -
-
-cipher
-
- -

Encrypt the PEM encoded private key with the supplied cipher. Any algorithm name accepted by EVP_get_cipherbyname() is acceptable such as aes128. Encryption is not supported for DER output.

- -
-
-passout arg
-
- -

The password source for the output file.

- -

For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-traditional
-
- -

Normally a private key is written using standard format: this is PKCS#8 form with the appropriate encryption algorithm (if any). If the -traditional option is specified then the older "traditional" format is used instead.

- -
-
-pubout
-
- -

By default the private and public key is output; this option restricts the output to the public components. This option is automatically set if the input is a public key.

- -

When combined with -text, this is equivalent to -text_pub.

- -
-
-noout
-
- -

Do not output the key in encoded form.

- -
-
-text
-
- -

Output the various key components in plain text (possibly in addition to the PEM encoded form). This cannot be combined with encoded output in DER format.

- -
-
-text_pub
-
- -

Output in text form only the public key components (also for private keys). This cannot be combined with encoded output in DER format.

- -
-
-ec_conv_form arg
-
- -

This option only applies to elliptic-curve based keys.

- -

This specifies how the points on the elliptic curve are converted into octet strings. Possible values are: compressed (the default value), uncompressed and hybrid. For more information regarding the point conversion forms please read the X9.62 standard. Note Due to patent issues the compressed option is disabled by default for binary curves and can be enabled by defining the preprocessor macro OPENSSL_EC_BIN_PT_COMP at compile time.

- -
-
-ec_param_enc arg
-
- -

This option only applies to elliptic curve based public and private keys.

- -

This specifies how the elliptic curve parameters are encoded. Possible value are: named_curve, i.e. the ec parameters are specified by an OID, or explicit where the ec parameters are explicitly given (see RFC 3279 for the definition of the EC parameters structures). The default value is named_curve. Note the implicitlyCA alternative, as specified in RFC 3279, is currently not implemented in OpenSSL.

- -
-
- -

EXAMPLES

- -

To remove the pass phrase on a private key:

- -
openssl pkey -in key.pem -out keyout.pem
- -

To encrypt a private key using triple DES:

- -
openssl pkey -in key.pem -des3 -out keyout.pem
- -

To convert a private key from PEM to DER format:

- -
openssl pkey -in key.pem -outform DER -out keyout.der
- -

To print out the components of a private key to standard output:

- -
openssl pkey -in key.pem -text -noout
- -

To print out the public components of a private key to standard output:

- -
openssl pkey -in key.pem -text_pub -noout
- -

To just output the public part of a private key:

- -
openssl pkey -in key.pem -pubout -out pubkey.pem
- -

To change the EC parameters encoding to explicit:

- -
openssl pkey -in key.pem -ec_param_enc explicit -out keyout.pem
- -

To change the EC point conversion form to compressed:

- -
openssl pkey -in key.pem -ec_conv_form compressed -out keyout.pem
- -

SEE ALSO

- -

openssl(1), openssl-genpkey(1), openssl-rsa(1), openssl-pkcs8(1), openssl-dsa(1), openssl-genrsa(1), openssl-gendsa(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-pkeyparam.html b/openssl-install/share/doc/openssl/html/man1/openssl-pkeyparam.html deleted file mode 100644 index 6cbacf1f..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-pkeyparam.html +++ /dev/null @@ -1,129 +0,0 @@ - - - - -openssl-pkeyparam - - - - - - - - - - -

NAME

- -

openssl-pkeyparam - public key algorithm parameter processing command

- -

SYNOPSIS

- -

openssl pkeyparam [-help] [-in filename] [-out filename] [-text] [-noout] [-check] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command processes public key algorithm parameters. They can be checked for correctness and their components printed out.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-in filename
-
- -

This specifies the input filename to read parameters from or standard input if this option is not specified.

- -
-
-out filename
-
- -

This specifies the output filename to write parameters to or standard output if this option is not specified.

- -
-
-text
-
- -

Prints out the parameters in plain text in addition to the encoded version.

- -
-
-noout
-
- -

Do not output the encoded version of the parameters.

- -
-
-check
-
- -

This option checks the correctness of parameters.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

EXAMPLES

- -

Print out text version of parameters:

- -
openssl pkeyparam -in param.pem -text
- -

NOTES

- -

There are no -inform or -outform options for this command because only PEM format is supported because the key type is determined by the PEM headers.

- -

SEE ALSO

- -

openssl(1), openssl-genpkey(1), openssl-rsa(1), openssl-pkcs8(1), openssl-dsa(1), openssl-genrsa(1), openssl-gendsa(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-pkeyutl.html b/openssl-install/share/doc/openssl/html/man1/openssl-pkeyutl.html deleted file mode 100644 index 53d457ef..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-pkeyutl.html +++ /dev/null @@ -1,467 +0,0 @@ - - - - -openssl-pkeyutl - - - - - - - - - - -

NAME

- -

openssl-pkeyutl - asymmetric key command

- -

SYNOPSIS

- -

openssl pkeyutl [-help] [-in file] [-rawin] [-digest algorithm] [-out file] [-secret file] [-sigfile file] [-inkey filename|uri] [-keyform DER|PEM|P12|ENGINE] [-passin arg] [-pubin] [-certin] [-rev] [-sign] [-verify] [-verifyrecover] [-encrypt] [-decrypt] [-derive] [-peerkey file] [-peerform DER|PEM|P12|ENGINE] [-encap] [-decap] [-kdf algorithm] [-kdflen length] [-kemop operation] [-pkeyopt opt:value] [-pkeyopt_passin opt[:passarg]] [-hexdump] [-asn1parse] [-engine id] [-engine_impl] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq] [-config configfile]

- -

DESCRIPTION

- -

This command can be used to perform low-level operations on asymmetric (public or private) keys using any supported algorithm.

- -

By default the signing operation (see -sign option) is assumed.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-in filename
-
- -

This specifies the input filename to read data from or standard input if this option is not specified.

- -
-
-rawin
-
- -

This indicates that the signature or verification input data is raw data, which is not hashed by any message digest algorithm. Except with EdDSA, the user can specify a digest algorithm by using the -digest option. For signature algorithms like RSA, DSA and ECDSA, the default digest algorithm is SHA256. For SM2, it is SM3.

- -

This option can only be used with -sign and -verify. For EdDSA (the Ed25519 and Ed448 algorithms) this option is required.

- -
-
-digest algorithm
-
- -

This option can only be used with -sign and -verify. It specifies the digest algorithm that is used to hash the input data before signing or verifying it with the input key. This option could be omitted if the signature algorithm does not require preprocessing the input through a pluggable hash function before signing (for instance, EdDSA). If this option is omitted but the signature algorithm requires one and the -rawin option is given, a default value will be used (see -rawin for details). If this option is present, then the -rawin option is required.

- -

At this time, HashEdDSA (the ph or "prehash" variant of EdDSA) is not supported, so the -digest option cannot be used with EdDSA.

- -
-
-out filename
-
- -

Specifies the output filename to write to or standard output by default.

- -
-
-secret filename
-
- -

Specifies the output filename to write the secret to on -encap.

- -
-
-sigfile file
-
- -

Signature file, required and allowed for -verify operations only.

- -
-
-inkey filename|uri
-
- -

The input key, by default it should be a private key.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The key format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-passin arg
-
- -

The input key password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-pubin
-
- -

By default a private key is read from the key input. With this option a public key is read instead. If the input contains no public key but a private key, its public part is used.

- -
-
-certin
-
- -

The input is a certificate containing a public key.

- -
-
-rev
-
- -

Reverse the order of the input buffer. This is useful for some libraries (such as CryptoAPI) which represent the buffer in little-endian format. This cannot be used in conjunction with -rawin.

- -
-
-sign
-
- -

Sign the input data and output the signed result. This requires a private key. Using a message digest operation along with this is recommended, when applicable, see the -rawin and -digest options for details. Otherwise, the input data given with the -in option is assumed to already be a digest, but this may then require an additional -pkeyopt digest:md in some cases (e.g., RSA with the default PKCS#1 padding mode). Even for other algorithms like ECDSA, where the additional -pkeyopt option does not affect signature output, it is recommended, as it enables checking that the input length is consistent with the intended digest.

- -
-
-verify
-
- -

Verify the input data against the signature given with the -sigfile option and indicate if the verification succeeded or failed. The input data given with the -in option is assumed to be a hash value unless the -rawin option is specified or implied. With raw data, when a digest algorithm is applicable, though it may be inferred from the signature or take a default value, it should also be specified.

- -
-
-verifyrecover
-
- -

Verify the given signature and output the recovered data (signature payload). For example, in case of RSA PKCS#1 the recovered data is the EMSA-PKCS-v1_5 DER encoding of the digest algorithm OID and value as specified in RFC8017 Section 9.2.

- -

Note that here the input given with the -in option is not a signature input (as with the -sign and -verify options) but a signature output value, typically produced using the -sign option.

- -

This option is available only for use with RSA keys.

- -
-
-encrypt
-
- -

Encrypt the input data using a public key.

- -
-
-decrypt
-
- -

Decrypt the input data using a private key.

- -
-
-derive
-
- -

Derive a shared secret using own private (EC)DH key and peer key.

- -
-
-peerkey file
-
- -

File containing the peer public or private (EC)DH key to use with the key derivation (agreement) operation. Its type must match the type of the own private key given with -inkey.

- -
-
-peerform DER|PEM|P12|ENGINE
-
- -

The peer key format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-encap
-
- -

Encapsulate a generated secret using a private key. The encapsulated result (binary data) is written to standard output by default, or else to the file specified with -out. The -secret option must also be provided to specify the output file for the secret value generated in the encapsulation process.

- -
-
-decap
-
- -

Decapsulate the secret using a private key. The result (binary data) is written to standard output by default, or else to the file specified with -out.

- -
-
-kemop operation
-
- -

This option is used for -encap/-decap commands and specifies the KEM operation specific for the key algorithm when there is no default KEM operation. If the algorithm has the default KEM operation, this option can be omitted.

- -

See EVP_PKEY_CTX_set_kem_op(3) and algorithm-specific KEM documentation e.g. EVP_KEM-RSA(7), EVP_KEM-EC(7), EVP_KEM-X25519(7), and EVP_KEM-X448(7).

- -
-
-kdf algorithm
-
- -

Use key derivation function algorithm. The supported algorithms are at present TLS1-PRF and HKDF. Note: additional parameters and the KDF output length will normally have to be set for this to work. See EVP_PKEY_CTX_set_hkdf_md(3) and EVP_PKEY_CTX_set_tls1_prf_md(3) for the supported string parameters of each algorithm.

- -
-
-kdflen length
-
- -

Set the output length for KDF.

- -
-
-pkeyopt opt:value
-
- -

Public key options specified as opt:value. See NOTES below for more details.

- -
-
-pkeyopt_passin opt[:passarg]
-
- -

Allows reading a public key option opt from stdin or a password source. If only opt is specified, the user will be prompted to enter a password on stdin. Alternatively, passarg can be specified which can be any value supported by openssl-passphrase-options(1).

- -
-
-hexdump
-
- -

hex dump the output data.

- -
-
-asn1parse
-
- -

Parse the ASN.1 output data to check its DER encoding and print any errors. When combined with the -verifyrecover option, this may be useful in case an ASN.1 DER-encoded structure had been signed directly (without hashing it) and when checking a signature in PKCS#1 v1.5 format, which has a DER encoding.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-engine_impl
-
- -

When used with the -engine option, it specifies to also use engine id for crypto operations.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-config configfile
-
- -

See "Configuration Option" in openssl(1).

- -
-
- -

NOTES

- -

The operations and options supported vary according to the key algorithm and its implementation. The OpenSSL operations and options are indicated below.

- -

Unless otherwise mentioned, the -pkeyopt option supports for all public-key types the digest:alg argument, which specifies the digest in use for the signing and verification operations. The value alg should represent a digest name as used in the EVP_get_digestbyname() function for example sha256. This value is not used to hash the input data. It is used (by some algorithms) for sanity-checking the lengths of data passed in and for creating the structures that make up the signature (e.g., DigestInfo in RSASSA PKCS#1 v1.5 signatures).

- -

For instance, if the value of the -pkeyopt option digest argument is sha256, the signature or verification input should be the 32 bytes long binary value of the SHA256 hash function output.

- -

Unless -rawin is used or implied, this command does not hash the input data but rather it will use the data directly as input to the signature algorithm. Depending on the key type, signature type, and mode of padding, the maximum sensible lengths of input data differ. With RSA the signed data cannot be longer than the key modulus. In case of ECDSA and DSA the data should not be longer than the field size, otherwise it will be silently truncated to the field size. In any event the input size must not be larger than the largest supported digest output size EVP_MAX_MD_SIZE, which currently is 64 bytes.

- -

RSA ALGORITHM

- -

The RSA algorithm generally supports the encrypt, decrypt, sign, verify and verifyrecover operations. However, some padding modes support only a subset of these operations. The following additional pkeyopt values are supported:

- -
- -
rsa_padding_mode:mode
-
- -

This sets the RSA padding mode. Acceptable values for mode are pkcs1 for PKCS#1 padding, none for no padding, oaep for OAEP mode, x931 for X9.31 mode and pss for PSS.

- -

In PKCS#1 padding, if the message digest is not set, then the supplied data is signed or verified directly instead of using a DigestInfo structure. If a digest is set, then the DigestInfo structure is used and its length must correspond to the digest type.

- -

Note, for pkcs1 padding, as a protection against the Bleichenbacher attack, the decryption will not fail in case of padding check failures. Use none and manual inspection of the decrypted message to verify if the decrypted value has correct PKCS#1 v1.5 padding.

- -

For oaep mode only encryption and decryption is supported.

- -

For x931 if the digest type is set it is used to format the block data otherwise the first byte is used to specify the X9.31 digest ID. Sign, verify and verifyrecover are can be performed in this mode.

- -

For pss mode only sign and verify are supported and the digest type must be specified.

- -
-
rsa_pss_saltlen:len
-
- -

For pss mode only this option specifies the salt length. Three special values are supported: digest sets the salt length to the digest length, max sets the salt length to the maximum permissible value. When verifying auto causes the salt length to be automatically determined based on the PSS block structure.

- -
-
rsa_mgf1_md:digest
-
- -

For PSS and OAEP padding sets the MGF1 digest. If the MGF1 digest is not explicitly set in PSS mode then the signing digest is used.

- -
-
rsa_oaep_md:digest
-
- -

Sets the digest used for the OAEP hash function. If not explicitly set then SHA256 is used.

- -
-
rsa_pkcs1_implicit_rejection:flag
-
- -

Disables (when set to 0) or enables (when set to 1) the use of implicit rejection with PKCS#1 v1.5 decryption. When enabled (the default), as a protection against Bleichenbacher attack, the library will generate a deterministic random plaintext that it will return to the caller in case of padding check failure. When disabled, it's the callers' responsibility to handle the returned errors in a side-channel free manner.

- -
-
- -

RSA-PSS ALGORITHM

- -

The RSA-PSS algorithm is a restricted version of the RSA algorithm which only supports the sign and verify operations with PSS padding. The following additional -pkeyopt values are supported:

- -
- -
rsa_padding_mode:mode, rsa_pss_saltlen:len, rsa_mgf1_md:digest
-
- -

These have the same meaning as the RSA algorithm with some additional restrictions. The padding mode can only be set to pss which is the default value.

- -

If the key has parameter restrictions then the digest, MGF1 digest and salt length are set to the values specified in the parameters. The digest and MG cannot be changed and the salt length cannot be set to a value less than the minimum restriction.

- -
-
- -

DSA ALGORITHM

- -

The DSA algorithm supports signing and verification operations only. Currently there are no additional -pkeyopt options other than digest. The SHA256 digest is assumed by default.

- -

DH ALGORITHM

- -

The DH algorithm only supports the derivation operation and no additional -pkeyopt options.

- -

EC ALGORITHM

- -

The EC algorithm supports sign, verify and derive operations. The sign and verify operations use ECDSA and derive uses ECDH. SHA256 is assumed by default for the -pkeyopt digest option.

- -

X25519 AND X448 ALGORITHMS

- -

The X25519 and X448 algorithms support key derivation only. Currently there are no additional options.

- -

ED25519 AND ED448 ALGORITHMS

- -

These algorithms only support signing and verifying. OpenSSL only implements the "pure" variants of these algorithms so raw data can be passed directly to them without hashing them first. OpenSSL only supports "oneshot" operation with these algorithms. This means that the entire file to be signed/verified must be read into memory before processing it. Signing or Verifying very large files should be avoided. Additionally the size of the file must be known for this to work. If the size of the file cannot be determined (for example if the input is stdin) then the sign or verify operation will fail.

- -

SM2

- -

The SM2 algorithm supports sign, verify, encrypt and decrypt operations. For the sign and verify operations, SM2 requires an Distinguishing ID string to be passed in. The following -pkeyopt value is supported:

- -
- -
distid:string
-
- -

This sets the ID string used in SM2 sign or verify operations. While verifying an SM2 signature, the ID string must be the same one used when signing the data. Otherwise the verification will fail.

- -
-
hexdistid:hex_string
-
- -

This sets the ID string used in SM2 sign or verify operations. While verifying an SM2 signature, the ID string must be the same one used when signing the data. Otherwise the verification will fail. The ID string provided with this option should be a valid hexadecimal value.

- -
-
- -

EXAMPLES

- -

Sign some data using a private key:

- -
openssl pkeyutl -sign -in file -inkey key.pem -out sig
- -

Recover the signed data (e.g. if an RSA key is used):

- -
openssl pkeyutl -verifyrecover -in sig -inkey key.pem
- -

Verify the signature (e.g. a DSA key):

- -
openssl pkeyutl -verify -in file -sigfile sig -inkey key.pem
- -

Sign data using a message digest value (this is currently only valid for RSA):

- -
openssl pkeyutl -sign -in file -inkey key.pem -out sig -pkeyopt digest:sha256
- -

Derive a shared secret value:

- -
openssl pkeyutl -derive -inkey key.pem -peerkey pubkey.pem -out secret
- -

Hexdump 48 bytes of TLS1 PRF using digest SHA256 and shared secret and seed consisting of the single byte 0xFF:

- -
openssl pkeyutl -kdf TLS1-PRF -kdflen 48 -pkeyopt md:SHA256 \
-   -pkeyopt hexsecret:ff -pkeyopt hexseed:ff -hexdump
- -

Derive a key using scrypt where the password is read from command line:

- -
openssl pkeyutl -kdf scrypt -kdflen 16 -pkeyopt_passin pass \
-   -pkeyopt hexsalt:aabbcc -pkeyopt N:16384 -pkeyopt r:8 -pkeyopt p:1
- -

Derive using the same algorithm, but read key from environment variable MYPASS:

- -
openssl pkeyutl -kdf scrypt -kdflen 16 -pkeyopt_passin pass:env:MYPASS \
-   -pkeyopt hexsalt:aabbcc -pkeyopt N:16384 -pkeyopt r:8 -pkeyopt p:1
- -

Sign some data using an SM2(7) private key and a specific ID:

- -
openssl pkeyutl -sign -in file -inkey sm2.key -out sig -rawin -digest sm3 \
-   -pkeyopt distid:someid
- -

Verify some data using an SM2(7) certificate and a specific ID:

- -
openssl pkeyutl -verify -certin -in file -inkey sm2.cert -sigfile sig \
-   -rawin -digest sm3 -pkeyopt distid:someid
- -

Decrypt some data using a private key with OAEP padding using SHA256:

- -
openssl pkeyutl -decrypt -in file -inkey key.pem -out secret \
-   -pkeyopt rsa_padding_mode:oaep -pkeyopt rsa_oaep_md:sha256
- -

SEE ALSO

- -

openssl(1), openssl-genpkey(1), openssl-pkey(1), openssl-rsautl(1) openssl-dgst(1), openssl-rsa(1), openssl-genrsa(1), openssl-kdf(1) EVP_PKEY_CTX_set_hkdf_md(3), EVP_PKEY_CTX_set_tls1_prf_md(3),

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-prime.html b/openssl-install/share/doc/openssl/html/man1/openssl-prime.html deleted file mode 100644 index a6ef305a..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-prime.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -openssl-prime - - - - - - - - - - -

NAME

- -

openssl-prime - compute prime numbers

- -

SYNOPSIS

- -

openssl prime [-help] [-hex] [-generate] [-bits num] [-safe] [-provider name] [-provider-path path] [-propquery propq] [-checks num] [number ...]

- -

DESCRIPTION

- -

This command checks if the specified numbers are prime.

- -

If no numbers are given on the command line, the -generate flag should be used to generate primes according to the requirements specified by the rest of the flags.

- -

OPTIONS

- -
- -
-help
-
- -

Display an option summary.

- -
-
-hex
-
- -

Generate hex output.

- -
-
-generate
-
- -

Generate a prime number.

- -
-
-bits num
-
- -

Generate a prime with num bits.

- -
-
-safe
-
- -

When used with -generate, generates a "safe" prime. If the number generated is n, then check that (n-1)/2 is also prime.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-checks num
-
- -

This parameter is ignored.

- -
-
- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-rand.html b/openssl-install/share/doc/openssl/html/man1/openssl-rand.html deleted file mode 100644 index 0fd83b07..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-rand.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -openssl-rand - - - - - - - - - - -

NAME

- -

openssl-rand - generate pseudo-random bytes

- -

SYNOPSIS

- -

openssl rand [-help] [-out file] [-base64] [-hex] [-engine id] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq] num[K|M|G|T]

- -

DESCRIPTION

- -

This command generates num random bytes using a cryptographically secure pseudo random number generator (CSPRNG). A suffix [K|M|G|T] may be appended to the num value to indicate the requested value be scaled as a multiple of KiB/MiB/GiB/TiB respectively. Note that suffixes are case sensitive, and that the suffixes represent binary multiples (K = 1024 bytes, M = 1024*1024 bytes, etc).

- -

The string 'max' may be substituted for a numerical value in num, to request the maximum number of bytes the CSPRNG can produce per instantiation. Currently, this is restricted to 2^61 bytes as per NIST SP 800-90C.

- -

The random bytes are generated using the RAND_bytes(3) function, which provides a security level of 256 bits, provided it managed to seed itself successfully from a trusted operating system entropy source. Otherwise, the command will fail with a nonzero error code. For more details, see RAND_bytes(3), RAND(7), and EVP_RAND(7).

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-out file
-
- -

Write to file instead of standard output.

- -
-
-base64
-
- -

Perform base64 encoding on the output.

- -
-
-hex
-
- -

Show the output as a hex string.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

SEE ALSO

- -

openssl(1), RAND_bytes(3), RAND(7), EVP_RAND(7)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-rehash.html b/openssl-install/share/doc/openssl/html/man1/openssl-rehash.html deleted file mode 100644 index e6c71fe6..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-rehash.html +++ /dev/null @@ -1,146 +0,0 @@ - - - - -openssl-rehash - - - - - - - - - - -

NAME

- -

openssl-rehash, c_rehash - Create symbolic links to files named by the hash values

- -

SYNOPSIS

- -

openssl rehash [-h] [-help] [-old] [-compat] [-n] [-v] [-provider name] [-provider-path path] [-propquery propq] [directory] ...

- -

c_rehash [-h] [-help] [-old] [-n] [-v] [-provider name] [-provider-path path] [-propquery propq] [directory] ...

- -

DESCRIPTION

- -

This command is generally equivalent to the external script c_rehash, except for minor differences noted below.

- -

openssl rehash scans directories and calculates a hash value of each .pem, .crt, .cer, or .crl file in the specified directory list and creates symbolic links for each file, where the name of the link is the hash value. (If the platform does not support symbolic links, a copy is made.) This command is useful as many programs that use OpenSSL require directories to be set up like this in order to find certificates.

- -

If any directories are named on the command line, then those are processed in turn. If not, then the SSL_CERT_DIR environment variable is consulted; this should be a colon-separated list of directories, like the Unix PATH variable. If that is not set then the default directory (installation-specific but often /usr/local/ssl/certs) is processed.

- -

In order for a directory to be processed, the user must have write permissions on that directory, otherwise an error will be generated.

- -

The links created are of the form HHHHHHHH.D, where each H is a hexadecimal character and D is a single decimal digit. When a directory is processed, all links in it that have a name in that syntax are first removed, even if they are being used for some other purpose. To skip the removal step, use the -n flag. Hashes for CRL's look similar except the letter r appears after the period, like this: HHHHHHHH.rD.

- -

Multiple objects may have the same hash; they will be indicated by incrementing the D value. Duplicates are found by comparing the full SHA-1 fingerprint. A warning will be displayed if a duplicate is found.

- -

A warning will also be displayed if there are files that cannot be parsed as either a certificate or a CRL or if more than one such object appears in the file.

- -

Script Configuration

- -

The c_rehash script uses the openssl program to compute the hashes and fingerprints. If not found in the user's PATH, then set the OPENSSL environment variable to the full pathname. Any program can be used, it will be invoked as follows for either a certificate or CRL:

- -
$OPENSSL x509 -hash -fingerprint -noout -in FILENAME
-$OPENSSL crl -hash -fingerprint -noout -in FILENAME
- -

where FILENAME is the filename. It must output the hash of the file on the first line, and the fingerprint on the second, optionally prefixed with some text and an equals sign.

- -

OPTIONS

- -
- -
-help -h
-
- -

Display a brief usage message.

- -
-
-old
-
- -

Use old-style hashing (MD5, as opposed to SHA-1) for generating links to be used for releases before 1.0.0. Note that current versions will not use the old style.

- -
-
-n
-
- -

Do not remove existing links. This is needed when keeping new and old-style links in the same directory.

- -
-
-compat
-
- -

Generate links for both old-style (MD5) and new-style (SHA1) hashing. This allows releases before 1.0.0 to use these links along-side newer releases.

- -
-
-v
-
- -

Print messages about old links removed and new links created. By default, this command only lists each directory as it is processed.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

ENVIRONMENT

- -
- -
OPENSSL
-
- -

The path to an executable to use to generate hashes and fingerprints (see above).

- -
-
SSL_CERT_DIR
-
- -

Colon separated list of directories to operate on. Ignored if directories are listed on the command line.

- -
-
- -

SEE ALSO

- -

openssl(1), openssl-crl(1), openssl-x509(1)

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-req.html b/openssl-install/share/doc/openssl/html/man1/openssl-req.html deleted file mode 100644 index 89e04f96..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-req.html +++ /dev/null @@ -1,738 +0,0 @@ - - - - -openssl-req - - - - - - - - - - -

NAME

- -

openssl-req - PKCS#10 certificate request and certificate generating command

- -

SYNOPSIS

- -

openssl req [-help] [-inform DER|PEM] [-outform DER|PEM] [-in filename] [-passin arg] [-out filename] [-passout arg] [-text] [-pubkey] [-noout] [-verify] [-modulus] [-new] [-newkey arg] [-pkeyopt opt:value] [-noenc] [-nodes] [-key filename|uri] [-keyform DER|PEM|P12|ENGINE] [-keyout filename] [-keygen_engine id] [-digest] [-config filename] [-section name] [-x509] [-x509v1] [-CA filename|uri] [-CAkey filename|uri] [-not_before date] [-not_after date] [-days n] [-set_serial n] [-newhdr] [-copy_extensions arg] [-extensions section] [-reqexts section] [-addext ext] [-precert] [-utf8] [-reqopt] [-subject] [-subj arg] [-multivalue-rdn] [-sigopt nm:v] [-vfyopt nm:v] [-batch] [-verbose] [-quiet] [-nameopt option] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command primarily creates and processes certificate requests (CSRs) in PKCS#10 format. It can additionally create self-signed certificates for use as root CAs for example.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM
-
- -

The CSR input file format to use; by default PEM is tried first. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The output format; unspecified by default. See openssl-format-options(1) for details.

- -

The data is a PKCS#10 object.

- -
-
-in filename
-
- -

This specifies the input filename to read a request from. This defaults to standard input unless -x509 or -CA is specified. A request is only read if the creation options (-new or -newkey or -precert) are not specified.

- -
-
-sigopt nm:v
-
- -

Pass options to the signature algorithm during sign operations. Names and values of these options are algorithm-specific.

- -
-
-vfyopt nm:v
-
- -

Pass options to the signature algorithm during verify operations. Names and values of these options are algorithm-specific.

- -
-
-passin arg
-
- -

The password source for private key and certificate input. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-passout arg
-
- -

The password source for the output file. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-out filename
-
- -

This specifies the output filename to write to or standard output by default.

- -
-
-text
-
- -

Prints out the certificate request in text form.

- -
-
-subject
-
- -

Prints out the certificate request subject (or certificate subject if -x509 is in use).

- -
-
-pubkey
-
- -

Prints out the public key.

- -
-
-noout
-
- -

This option prevents output of the encoded version of the certificate request.

- -
-
-modulus
-
- -

Prints out the value of the modulus of the public key contained in the request.

- -
-
-verify
-
- -

Verifies the self-signature on the request. If the verification fails, the program will immediately exit, i.e. further option processing (e.g. -text) is skipped.

- -
-
-new
-
- -

This option generates a new certificate request. It will prompt the user for the relevant field values. The actual fields prompted for and their maximum and minimum sizes are specified in the configuration file and any requested extensions.

- -

If the -key option is not given it will generate a new private key using information specified in the configuration file or given with the -newkey and -pkeyopt options, else by default an RSA key with 2048 bits length.

- -
-
-newkey arg
-
- -

This option is used to generate a new private key unless -key is given. It is subsequently used as if it was given using the -key option.

- -

This option implies the -new flag to create a new certificate request or a new certificate in case -x509 is used.

- -

The argument takes one of several forms.

- -

[rsa:]nbits generates an RSA key nbits in size. If nbits is omitted, i.e., -newkey rsa is specified, the default key size specified in the configuration file with the default_bits option is used if present, else 2048.

- -

All other algorithms support the -newkey algname:file form, where file is an algorithm parameter file, created with openssl genpkey -genparam or an X.509 certificate for a key with appropriate algorithm.

- -

param:file generates a key using the parameter file or certificate file, the algorithm is determined by the parameters.

- -

algname[:file] generates a key using the given algorithm algname. If a parameter file file is given then the parameters specified there are used, where the algorithm parameters must match algname. If algorithm parameters are not given, any necessary parameters should be specified via the -pkeyopt option.

- -

dsa:filename generates a DSA key using the parameters in the file filename. ec:filename generates EC key (usable both with ECDSA or ECDH algorithms), gost2001:filename generates GOST R 34.10-2001 key (requires gost engine configured in the configuration file). If just gost2001 is specified a parameter set should be specified by -pkeyopt paramset:X

- -
-
-pkeyopt opt:value
-
- -

Set the public key algorithm option opt to value. The precise set of options supported depends on the public key algorithm used and its implementation. See "KEY GENERATION OPTIONS" in openssl-genpkey(1) for more details.

- -
-
-key filename|uri
-
- -

This option provides the private key for signing a new certificate or certificate request. Unless -in is given, the corresponding public key is placed in the new certificate or certificate request, resulting in a self-signature.

- -

For certificate signing this option is overridden by the -CA option.

- -

This option also accepts PKCS#8 format private keys for PEM format files.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The format of the private key; unspecified by default. See openssl-format-options(1) for details.

- -
-
-keyout filename
-
- -

This gives the filename to write any private key to that has been newly created or read from -key. If neither the -keyout option nor the -key option are given then the filename specified in the configuration file with the default_keyfile option is used, if present. Thus, if you want to write the private key and the -key option is provided, you should provide the -keyout option explicitly. If a new key is generated and no filename is specified the key is written to standard output.

- -
-
-noenc
-
- -

If this option is specified then if a private key is created it will not be encrypted.

- -
-
-nodes
-
- -

This option is deprecated since OpenSSL 3.0; use -noenc instead.

- -
-
-digest
-
- -

This specifies the message digest to sign the request. Any digest supported by the OpenSSL dgst command can be used. This overrides the digest algorithm specified in the configuration file.

- -

Some public key algorithms may override this choice. For instance, DSA signatures always use SHA1, GOST R 34.10 signatures always use GOST R 34.11-94 (-md_gost94), Ed25519 and Ed448 never use any digest.

- -
-
-config filename
-
- -

This allows an alternative configuration file to be specified. Optional; for a description of the default value, see "COMMAND SUMMARY" in openssl(1).

- -
-
-section name
-
- -

Specifies the name of the section to use; the default is req.

- -
-
-subj arg
-
- -

Sets subject name for new request or supersedes the subject name when processing a certificate request.

- -

The arg must be formatted as /type0=value0/type1=value1/type2=.... Special characters may be escaped by \ (backslash), whitespace is retained. Empty values are permitted, but the corresponding type will not be included in the request. Giving a single / will lead to an empty sequence of RDNs (a NULL-DN). Multi-valued RDNs can be formed by placing a + character instead of a / between the AttributeValueAssertions (AVAs) that specify the members of the set. Example:

- -

/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe

- -
-
-multivalue-rdn
-
- -

This option has been deprecated and has no effect.

- -
-
-x509
-
- -

This option outputs a certificate instead of a certificate request. This is typically used to generate test certificates. It is implied by the -CA option.

- -

This option implies the -new flag if -in is not given.

- -

If an existing request is specified with the -in option, it is converted to a certificate; otherwise a request is created from scratch.

- -

Unless specified using the -set_serial option, a large random number will be used for the serial number.

- -

Unless the -copy_extensions option is used, X.509 extensions are not copied from any provided request input file.

- -

X.509 extensions to be added can be specified in the configuration file, possibly using the -config and -extensions options, and/or using the -addext option.

- -

Unless -x509v1 is given, generated certificates bear X.509 version 3. Unless specified otherwise, key identifier extensions are included as described in x509v3_config(5).

- -
-
-x509v1
-
- -

Request generation of certificates with X.509 version 1. This implies -x509. If X.509 extensions are given, anyway X.509 version 3 is set.

- -
-
-CA filename|uri
-
- -

Specifies the "CA" certificate to be used for signing a new certificate and implies use of -x509. When present, this behaves like a "micro CA" as follows: The subject name of the "CA" certificate is placed as issuer name in the new certificate, which is then signed using the "CA" key given as specified below.

- -
-
-CAkey filename|uri
-
- -

Sets the "CA" private key to sign a certificate with. The private key must match the public key of the certificate given with -CA. If this option is not provided then the key must be present in the -CA input.

- -
-
-not_before date
-
- -

When -x509 is in use this allows the start date to be explicitly set, otherwise it is ignored. The format of date is YYMMDDHHMMSSZ (the same as an ASN1 UTCTime structure), or YYYYMMDDHHMMSSZ (the same as an ASN1 GeneralizedTime structure). In both formats, seconds SS and timezone Z must be present. Alternatively, you can also use "today".

- -
-
-not_after date
-
- -

When -x509 is in use this allows the expiry date to be explicitly set, otherwise it is ignored. The format of date is YYMMDDHHMMSSZ (the same as an ASN1 UTCTime structure), or YYYYMMDDHHMMSSZ (the same as an ASN1 GeneralizedTime structure). In both formats, seconds SS and timezone Z must be present. Alternatively, you can also use "today".

- -

This overrides the -days option.

- -
-
-days n
-
- -

When -x509 is in use this specifies the number of days from today to certify the certificate for, otherwise it is ignored. n should be a positive integer. The default is 30 days.

- -

Regardless of the option -not_before, the days are always counted from today. When used together with the option -not_after, the explicit expiry date takes precedence.

- -
-
-set_serial n
-
- -

Serial number to use when outputting a self-signed certificate. This may be specified as a decimal value or a hex value if preceded by 0x. If not given, a large random number will be used.

- -
-
-copy_extensions arg
-
- -

Determines how X.509 extensions in certificate requests should be handled when -x509 is in use. If arg is none or this option is not present then extensions are ignored. If arg is copy or copyall then all extensions in the request are copied to the certificate.

- -

The main use of this option is to allow a certificate request to supply values for certain extensions such as subjectAltName.

- -
-
-extensions section, -reqexts section
-
- -

Can be used to override the name of the configuration file section from which X.509 extensions are included in the certificate (when -x509 is in use) or certificate request. This allows several different sections to be used in the same configuration file to specify requests for a variety of purposes.

- -
-
-addext ext
-
- -

Add a specific extension to the certificate (if -x509 is in use) or certificate request. The argument must have the form of a key=value pair as it would appear in a config file.

- -

If an extension is added using this option that has the same OID as one defined in the extension section of the config file, it overrides that one.

- -

This option can be given multiple times. Doing so, the same key most not be given more than once.

- -
-
-precert
-
- -

A poison extension will be added to the certificate, making it a "pre-certificate" (see RFC6962). This can be submitted to Certificate Transparency logs in order to obtain signed certificate timestamps (SCTs). These SCTs can then be embedded into the pre-certificate as an extension, before removing the poison and signing the certificate.

- -

This implies the -new flag.

- -
-
-utf8
-
- -

This option causes field values to be interpreted as UTF8 strings, by default they are interpreted as ASCII. This means that the field values, whether prompted from a terminal or obtained from a configuration file, must be valid UTF8 strings.

- -
-
-reqopt option
-
- -

Customise the printing format used with -text. The option argument can be a single option or multiple options separated by commas.

- -

See discussion of the -certopt parameter in the openssl-x509(1) command.

- -
-
-newhdr
-
- -

Adds the word NEW to the PEM file header and footer lines on the outputted request. Some software (Netscape certificate server) and some CAs need this.

- -
-
-batch
-
- -

Non-interactive mode.

- -
-
-verbose
-
- -

Print extra details about the operations being performed.

- -
-
-quiet
-
- -

Print fewer details about the operations being performed, which may be handy during batch scripts or pipelines (specifically "progress dots" during key generation are suppressed).

- -
-
-keygen_engine id
-
- -

Specifies an engine (by its unique id string) which would be used for key generation operations.

- -
-
-nameopt option
-
- -

This specifies how the subject or issuer names are displayed. See openssl-namedisplay-options(1) for details.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

CONFIGURATION FILE FORMAT

- -

The configuration options are specified in the req section of the configuration file. An alternate name be specified by using the -section option. As with all configuration files, if no value is specified in the specific section then the initial unnamed or default section is searched too.

- -

The options available are described in detail below.

- -
- -
input_password, output_password
-
- -

The passwords for the input private key file (if present) and the output private key file (if one will be created). The command line options passin and passout override the configuration file values.

- -
-
default_bits
-
- -

Specifies the default key size in bits.

- -

This option is used in conjunction with the -new option to generate a new key. It can be overridden by specifying an explicit key size in the -newkey option. The smallest accepted key size is 512 bits. If no key size is specified then 2048 bits is used.

- -
-
default_keyfile
-
- -

This is the default filename to write a private key to. If not specified the key is written to standard output. This can be overridden by the -keyout option.

- -
-
oid_file
-
- -

This specifies a file containing additional OBJECT IDENTIFIERS. Each line of the file should consist of the numerical form of the object identifier followed by whitespace then the short name followed by whitespace and finally the long name.

- -
-
oid_section
-
- -

This specifies a section in the configuration file containing extra object identifiers. Each line should consist of the short name of the object identifier followed by = and the numerical form. The short and long names are the same when this option is used.

- -
-
RANDFILE
-
- -

At startup the specified file is loaded into the random number generator, and at exit 256 bytes will be written to it. It is used for private key generation.

- -
-
encrypt_key
-
- -

If this is set to no then if a private key is generated it is not encrypted. This is equivalent to the -noenc command line option. For compatibility encrypt_rsa_key is an equivalent option.

- -
-
default_md
-
- -

This option specifies the digest algorithm to use. Any digest supported by the OpenSSL dgst command can be used. This option can be overridden on the command line. Certain signing algorithms (i.e. Ed25519 and Ed448) will ignore any digest that has been set.

- -
-
string_mask
-
- -

This option masks out the use of certain string types in certain fields. Most users will not need to change this option. It can be set to several values:

- -
- -
utf8only - only UTF8Strings are used (this is the default value)
-
- -
-
pkix - any string type except T61Strings
-
- -
-
nombstr - any string type except BMPStrings and UTF8Strings
-
- -
-
default - any kind of string type
-
- -
-
- -

Note that utf8only is the PKIX recommendation in RFC2459 after 2003, and the default string_mask; default is not the default option. The nombstr value is a workaround for some software that has problems with variable-sized BMPStrings and UTF8Strings.

- -
-
req_extensions
-
- -

This specifies the configuration file section containing a list of extensions to add to the certificate request. It can be overridden by the -reqexts (or -extensions) command line switch. See the x509v3_config(5) manual page for details of the extension section format.

- -
-
x509_extensions
-
- -

This specifies the configuration file section containing a list of extensions to add to certificate generated when -x509 is in use. It can be overridden by the -extensions command line switch.

- -
-
prompt
-
- -

If set to the value no this disables prompting of certificate fields and just takes values from the config file directly. It also changes the expected format of the distinguished_name and attributes sections.

- -
-
utf8
-
- -

If set to the value yes then field values to be interpreted as UTF8 strings, by default they are interpreted as ASCII. This means that the field values, whether prompted from a terminal or obtained from a configuration file, must be valid UTF8 strings.

- -
-
attributes
-
- -

This specifies the section containing any request attributes: its format is the same as distinguished_name. Typically these may contain the challengePassword or unstructuredName types. They are currently ignored by OpenSSL's request signing utilities but some CAs might want them.

- -
-
distinguished_name
-
- -

This specifies the section containing the distinguished name fields to prompt for when generating a certificate or certificate request. The format is described in the next section.

- -
-
- -

DISTINGUISHED NAME AND ATTRIBUTE SECTION FORMAT

- -

There are two separate formats for the distinguished name and attribute sections. If the prompt option is set to no then these sections just consist of field names and values: for example,

- -
CN=My Name
-OU=My Organization
-emailAddress=someone@somewhere.org
- -

This allows external programs (e.g. GUI based) to generate a template file with all the field names and values and just pass it to this command. An example of this kind of configuration file is contained in the EXAMPLES section.

- -

Alternatively if the prompt option is absent or not set to no then the file contains field prompting information. It consists of lines of the form:

- -
fieldName="prompt"
-fieldName_default="default field value"
-fieldName_min= 2
-fieldName_max= 4
- -

"fieldName" is the field name being used, for example commonName (or CN). The "prompt" string is used to ask the user to enter the relevant details. If the user enters nothing then the default value is used if no default value is present then the field is omitted. A field can still be omitted if a default value is present if the user just enters the '.' character.

- -

The number of characters entered must be between the fieldName_min and fieldName_max limits: there may be additional restrictions based on the field being used (for example countryName can only ever be two characters long and must fit in a PrintableString).

- -

Some fields (such as organizationName) can be used more than once in a DN. This presents a problem because configuration files will not recognize the same name occurring twice. To avoid this problem if the fieldName contains some characters followed by a full stop they will be ignored. So for example a second organizationName can be input by calling it "1.organizationName".

- -

The actual permitted field names are any object identifier short or long names. These are compiled into OpenSSL and include the usual values such as commonName, countryName, localityName, organizationName, organizationalUnitName, stateOrProvinceName. Additionally emailAddress is included as well as name, surname, givenName, initials, and dnQualifier.

- -

Additional object identifiers can be defined with the oid_file or oid_section options in the configuration file. Any additional fields will be treated as though they were a DirectoryString.

- -

EXAMPLES

- -

Examine and verify certificate request:

- -
openssl req -in req.pem -text -verify -noout
- -

Create a private key and then generate a certificate request from it:

- -
openssl genrsa -out key.pem 2048
-openssl req -new -key key.pem -out req.pem
- -

The same but just using req:

- -
openssl req -newkey rsa:2048 -keyout key.pem -out req.pem
- -

Generate a self-signed root certificate:

- -
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out req.pem
- -

Create an SM2 private key and then generate a certificate request from it:

- -
openssl ecparam -genkey -name SM2 -out sm2.key
-openssl req -new -key sm2.key -out sm2.csr -sm3 -sigopt "distid:1234567812345678"
- -

Examine and verify an SM2 certificate request:

- -
openssl req -verify -in sm2.csr -sm3 -vfyopt "distid:1234567812345678"
- -

Example of a file pointed to by the oid_file option:

- -
1.2.3.4        shortName       A longer Name
-1.2.3.6        otherName       Other longer Name
- -

Example of a section pointed to by oid_section making use of variable expansion:

- -
testoid1=1.2.3.5
-testoid2=${testoid1}.6
- -

Sample configuration file prompting for field values:

- -
[ req ]
-default_bits           = 2048
-default_keyfile        = privkey.pem
-distinguished_name     = req_distinguished_name
-attributes             = req_attributes
-req_extensions         = v3_ca
-
-dirstring_type = nombstr
-
-[ req_distinguished_name ]
-countryName                    = Country Name (2 letter code)
-countryName_default            = AU
-countryName_min                = 2
-countryName_max                = 2
-
-localityName                   = Locality Name (eg, city)
-
-organizationalUnitName         = Organizational Unit Name (eg, section)
-
-commonName                     = Common Name (eg, YOUR name)
-commonName_max                 = 64
-
-emailAddress                   = Email Address
-emailAddress_max               = 40
-
-[ req_attributes ]
-challengePassword              = A challenge password
-challengePassword_min          = 4
-challengePassword_max          = 20
-
-[ v3_ca ]
-
-subjectKeyIdentifier=hash
-authorityKeyIdentifier=keyid:always,issuer:always
-basicConstraints = critical, CA:true
- -

Sample configuration containing all field values:

- -
[ req ]
-default_bits           = 2048
-default_keyfile        = keyfile.pem
-distinguished_name     = req_distinguished_name
-attributes             = req_attributes
-prompt                 = no
-output_password        = mypass
-
-[ req_distinguished_name ]
-C                      = GB
-ST                     = Test State or Province
-L                      = Test Locality
-O                      = Organization Name
-OU                     = Organizational Unit Name
-CN                     = Common Name
-emailAddress           = test@email.address
-
-[ req_attributes ]
-challengePassword              = A challenge password
- -

Example of giving the most common attributes (subject and extensions) on the command line:

- -
openssl req -new -subj "/C=GB/CN=foo" \
-                 -addext "subjectAltName = DNS:foo.co.uk" \
-                 -addext "certificatePolicies = 1.2.3.4" \
-                 -newkey rsa:2048 -keyout key.pem -out req.pem
- -

NOTES

- -

The certificate requests generated by Xenroll with MSIE have extensions added. It includes the keyUsage extension which determines the type of key (signature only or general purpose) and any additional OIDs entered by the script in an extendedKeyUsage extension.

- -

DIAGNOSTICS

- -

The following messages are frequently asked about:

- -
Using configuration from /some/path/openssl.cnf
-Unable to load config info
- -

This is followed some time later by:

- -
unable to find 'distinguished_name' in config
-problems making Certificate Request
- -

The first error message is the clue: it can't find the configuration file! Certain operations (like examining a certificate request) don't need a configuration file so its use isn't enforced. Generation of certificates or requests however does need a configuration file. This could be regarded as a bug.

- -

Another puzzling message is this:

- -
Attributes:
-    a0:00
- -

this is displayed when no attributes are present and the request includes the correct empty SET OF structure (the DER encoding of which is 0xa0 0x00). If you just see:

- -
Attributes:
- -

then the SET OF is missing and the encoding is technically invalid (but it is tolerated). See the description of the command line option -asn1-kludge for more information.

- -

BUGS

- -

OpenSSL's handling of T61Strings (aka TeletexStrings) is broken: it effectively treats them as ISO-8859-1 (Latin 1), Netscape and MSIE have similar behaviour. This can cause problems if you need characters that aren't available in PrintableStrings and you don't want to or can't use BMPStrings.

- -

As a consequence of the T61String handling the only correct way to represent accented characters in OpenSSL is to use a BMPString: unfortunately Netscape currently chokes on these. If you have to use accented characters with Netscape and MSIE then you currently need to use the invalid T61String form.

- -

The current prompting is not very friendly. It doesn't allow you to confirm what you've just entered. Other things like extensions in certificate requests are statically defined in the configuration file. Some of these: like an email address in subjectAltName should be input by the user.

- -

SEE ALSO

- -

openssl(1), openssl-x509(1), openssl-ca(1), openssl-genrsa(1), openssl-gendsa(1), config(5), x509v3_config(5)

- -

HISTORY

- -

The -section option was added in OpenSSL 3.0.0.

- -

The -multivalue-rdn option has become obsolete in OpenSSL 3.0.0 and has no effect.

- -

The -engine option was deprecated in OpenSSL 3.0. The <-nodes> option was deprecated in OpenSSL 3.0, too; use -noenc instead.

- -

The -reqexts option has been made an alias of -extensions in OpenSSL 3.2.

- -

Since OpenSSL 3.2, generated certificates bear X.509 version 3 unless -x509v1 is given, and key identifier extensions are included by default.

- -

Since OpenSSL 3.3, the -verify option will exit with 1 on failure.

- -

COPYRIGHT

- -

Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-rsa.html b/openssl-install/share/doc/openssl/html/man1/openssl-rsa.html deleted file mode 100644 index 49df8a6a..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-rsa.html +++ /dev/null @@ -1,228 +0,0 @@ - - - - -openssl-rsa - - - - - - - - - - -

NAME

- -

openssl-rsa - RSA key processing command

- -

SYNOPSIS

- -

openssl rsa [-help] [-inform DER|PEM|P12|ENGINE] [-outform DER|PEM] [-in filename|uri] [-passin arg] [-out filename] [-passout arg] [-aes128] [-aes192] [-aes256] [-aria128] [-aria192] [-aria256] [-camellia128] [-camellia192] [-camellia256] [-des] [-des3] [-idea] [-text] [-noout] [-modulus] [-traditional] [-check] [-pubin] [-pubout] [-RSAPublicKey_in] [-RSAPublicKey_out] [-pvk-strong] [-pvk-weak] [-pvk-none] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command processes RSA keys. They can be converted between various forms and their components printed out.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM|P12|ENGINE
-
- -

The key input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM
-
- -

The key output format; the default is PEM. See openssl-format-options(1) for details.

- -
-
-traditional
-
- -

When writing a private key, use the traditional PKCS#1 format instead of the PKCS#8 format.

- -
-
-in filename|uri
-
- -

This specifies the input to read a key from or standard input if this option is not specified. If the key is encrypted a pass phrase will be prompted for.

- -
-
-passin arg, -passout arg
-
- -

The password source for the input and output file. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-out filename
-
- -

This specifies the output filename to write a key to or standard output if this option is not specified. If any encryption options are set then a pass phrase will be prompted for. The output filename should not be the same as the input filename.

- -
-
-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea
-
- -

These options encrypt the private key with the specified cipher before outputting it. A pass phrase is prompted for. If none of these options is specified the key is written in plain text. This means that this command can be used to remove the pass phrase from a key by not giving any encryption option is given, or to add or change the pass phrase by setting them. These options can only be used with PEM format output files.

- -
-
-text
-
- -

Prints out the various public or private key components in plain text in addition to the encoded version.

- -
-
-noout
-
- -

This option prevents output of the encoded version of the key.

- -
-
-modulus
-
- -

This option prints out the value of the modulus of the key.

- -
-
-check
-
- -

This option checks the consistency of an RSA private key.

- -
-
-pubin
-
- -

By default a private key is read from the input. With this option a public key is read instead. If the input contains no public key but a private key, its public part is used.

- -
-
-pubout
-
- -

By default a private key is output: with this option a public key will be output instead. This option is automatically set if the input is a public key.

- -
-
-RSAPublicKey_in, -RSAPublicKey_out
-
- -

Like -pubin and -pubout except RSAPublicKey format is used instead.

- -
-
-pvk-strong
-
- -

Enable 'Strong' PVK encoding level (default).

- -
-
-pvk-weak
-
- -

Enable 'Weak' PVK encoding level.

- -
-
-pvk-none
-
- -

Don't enforce PVK encoding.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

NOTES

- -

The openssl-pkey(1) command is capable of performing all the operations this command can, as well as supporting other public key types.

- -

EXAMPLES

- -

The documentation for the openssl-pkey(1) command contains examples equivalent to the ones listed here.

- -

To remove the pass phrase on an RSA private key:

- -
openssl rsa -in key.pem -out keyout.pem
- -

To encrypt a private key using triple DES:

- -
openssl rsa -in key.pem -des3 -out keyout.pem
- -

To convert a private key from PEM to DER format:

- -
openssl rsa -in key.pem -outform DER -out keyout.der
- -

To print out the components of a private key to standard output:

- -
openssl rsa -in key.pem -text -noout
- -

To just output the public part of a private key:

- -
openssl rsa -in key.pem -pubout -out pubkey.pem
- -

Output the public part of a private key in RSAPublicKey format:

- -
openssl rsa -in key.pem -RSAPublicKey_out -out pubkey.pem
- -

BUGS

- -

There should be an option that automatically handles .key files, without having to manually edit them.

- -

SEE ALSO

- -

openssl(1), openssl-pkey(1), openssl-pkcs8(1), openssl-dsa(1), openssl-genrsa(1), openssl-gendsa(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-rsautl.html b/openssl-install/share/doc/openssl/html/man1/openssl-rsautl.html deleted file mode 100644 index e51f99f2..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-rsautl.html +++ /dev/null @@ -1,275 +0,0 @@ - - - - -openssl-rsautl - - - - - - - - - - -

NAME

- -

openssl-rsautl - RSA command

- -

SYNOPSIS

- -

openssl rsautl [-help] [-in file] [-passin arg] [-rev] [-out file] [-inkey filename|uri] [-keyform DER|PEM|P12|ENGINE] [-pubin] [-certin] [-sign] [-verify] [-encrypt] [-decrypt] [-pkcs] [-x931] [-oaep] [-raw] [-hexdump] [-asn1parse] [-engine id] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command has been deprecated. The openssl-pkeyutl(1) command should be used instead.

- -

This command can be used to sign, verify, encrypt and decrypt data using the RSA algorithm.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-in filename
-
- -

This specifies the input filename to read data from or standard input if this option is not specified.

- -
-
-passin arg
-
- -

The passphrase used in the output file. See see openssl-passphrase-options(1).

- -
-
-rev
-
- -

Reverse the order of the input.

- -
-
-out filename
-
- -

Specifies the output filename to write to or standard output by default.

- -
-
-inkey filename|uri
-
- -

The input key, by default it should be an RSA private key.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The key format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-pubin
-
- -

By default a private key is read from the key input. With this option a public key is read instead. If the input contains no public key but a private key, its public part is used.

- -
-
-certin
-
- -

The input is a certificate containing an RSA public key.

- -
-
-sign
-
- -

Sign the input data and output the signed result. This requires an RSA private key.

- -
-
-verify
-
- -

Verify the input data and output the recovered data.

- -
-
-encrypt
-
- -

Encrypt the input data using an RSA public key.

- -
-
-decrypt
-
- -

Decrypt the input data using an RSA private key.

- -
-
-pkcs, -oaep, -x931, -raw
-
- -

The padding to use: PKCS#1 v1.5 (the default), PKCS#1 OAEP, ANSI X9.31, or no padding, respectively. For signatures, only -pkcs and -raw can be used.

- -

Note: because of protection against Bleichenbacher attacks, decryption using PKCS#1 v1.5 mode will not return errors in case padding check failed. Use -raw and inspect the returned value manually to check if the padding is correct.

- -
-
-hexdump
-
- -

Hex dump the output data.

- -
-
-asn1parse
-
- -

Parse the ASN.1 output data, this is useful when combined with the -verify option.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

NOTES

- -

Since this command uses the RSA algorithm directly, it can only be used to sign or verify small pieces of data.

- -

EXAMPLES

- -

Examples equivalent to these can be found in the documentation for the non-deprecated openssl-pkeyutl(1) command.

- -

Sign some data using a private key:

- -
openssl rsautl -sign -in file -inkey key.pem -out sig
- -

Recover the signed data

- -
openssl rsautl -verify -in sig -inkey key.pem
- -

Examine the raw signed data:

- -
openssl rsautl -verify -in sig -inkey key.pem -raw -hexdump
-
-0000 - 00 01 ff ff ff ff ff ff-ff ff ff ff ff ff ff ff   ................
-0010 - ff ff ff ff ff ff ff ff-ff ff ff ff ff ff ff ff   ................
-0020 - ff ff ff ff ff ff ff ff-ff ff ff ff ff ff ff ff   ................
-0030 - ff ff ff ff ff ff ff ff-ff ff ff ff ff ff ff ff   ................
-0040 - ff ff ff ff ff ff ff ff-ff ff ff ff ff ff ff ff   ................
-0050 - ff ff ff ff ff ff ff ff-ff ff ff ff ff ff ff ff   ................
-0060 - ff ff ff ff ff ff ff ff-ff ff ff ff ff ff ff ff   ................
-0070 - ff ff ff ff 00 68 65 6c-6c 6f 20 77 6f 72 6c 64   .....hello world
- -

The PKCS#1 block formatting is evident from this. If this was done using encrypt and decrypt the block would have been of type 2 (the second byte) and random padding data visible instead of the 0xff bytes.

- -

It is possible to analyse the signature of certificates using this command in conjunction with openssl-asn1parse(1). Consider the self signed example in certs/pca-cert.pem. Running openssl-asn1parse(1) as follows yields:

- -
openssl asn1parse -in pca-cert.pem
-
-   0:d=0  hl=4 l= 742 cons: SEQUENCE
-   4:d=1  hl=4 l= 591 cons:  SEQUENCE
-   8:d=2  hl=2 l=   3 cons:   cont [ 0 ]
-  10:d=3  hl=2 l=   1 prim:    INTEGER           :02
-  13:d=2  hl=2 l=   1 prim:   INTEGER           :00
-  16:d=2  hl=2 l=  13 cons:   SEQUENCE
-  18:d=3  hl=2 l=   9 prim:    OBJECT            :md5WithRSAEncryption
-  29:d=3  hl=2 l=   0 prim:    NULL
-  31:d=2  hl=2 l=  92 cons:   SEQUENCE
-  33:d=3  hl=2 l=  11 cons:    SET
-  35:d=4  hl=2 l=   9 cons:     SEQUENCE
-  37:d=5  hl=2 l=   3 prim:      OBJECT            :countryName
-  42:d=5  hl=2 l=   2 prim:      PRINTABLESTRING   :AU
- ....
- 599:d=1  hl=2 l=  13 cons:  SEQUENCE
- 601:d=2  hl=2 l=   9 prim:   OBJECT            :md5WithRSAEncryption
- 612:d=2  hl=2 l=   0 prim:   NULL
- 614:d=1  hl=3 l= 129 prim:  BIT STRING
- -

The final BIT STRING contains the actual signature. It can be extracted with:

- -
openssl asn1parse -in pca-cert.pem -out sig -noout -strparse 614
- -

The certificate public key can be extracted with:

- -
openssl x509 -in test/testx509.pem -pubkey -noout >pubkey.pem
- -

The signature can be analysed with:

- -
openssl rsautl -in sig -verify -asn1parse -inkey pubkey.pem -pubin
-
-   0:d=0  hl=2 l=  32 cons: SEQUENCE
-   2:d=1  hl=2 l=  12 cons:  SEQUENCE
-   4:d=2  hl=2 l=   8 prim:   OBJECT            :md5
-  14:d=2  hl=2 l=   0 prim:   NULL
-  16:d=1  hl=2 l=  16 prim:  OCTET STRING
-     0000 - f3 46 9e aa 1a 4a 73 c9-37 ea 93 00 48 25 08 b5   .F...Js.7...H%..
- -

This is the parsed version of an ASN1 DigestInfo structure. It can be seen that the digest used was md5. The actual part of the certificate that was signed can be extracted with:

- -
openssl asn1parse -in pca-cert.pem -out tbs -noout -strparse 4
- -

and its digest computed with:

- -
openssl md5 -c tbs
-MD5(tbs)= f3:46:9e:aa:1a:4a:73:c9:37:ea:93:00:48:25:08:b5
- -

which it can be seen agrees with the recovered value above.

- -

SEE ALSO

- -

openssl(1), openssl-pkeyutl(1), openssl-dgst(1), openssl-rsa(1), openssl-genrsa(1)

- -

HISTORY

- -

This command was deprecated in OpenSSL 3.0.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-s_client.html b/openssl-install/share/doc/openssl/html/man1/openssl-s_client.html deleted file mode 100644 index 7ac89ba9..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-s_client.html +++ /dev/null @@ -1,1013 +0,0 @@ - - - - -openssl-s_client - - - - - - - - - - -

NAME

- -

openssl-s_client - SSL/TLS client program

- -

SYNOPSIS

- -

openssl s_client [-help] [-ssl_config section] [-connect host:port] [-host hostname] [-port port] [-bind host:port] [-proxy host:port] [-proxy_user userid] [-proxy_pass arg] [-unix path] [-4] [-6] [-quic] [-servername name] [-noservername] [-verify depth] [-verify_return_error] [-verify_quiet] [-verifyCAfile filename] [-verifyCApath dir] [-verifyCAstore uri] [-cert filename] [-certform DER|PEM|P12] [-cert_chain filename] [-build_chain] [-CRL filename] [-CRLform DER|PEM] [-crl_download] [-key filename|uri] [-keyform DER|PEM|P12|ENGINE] [-pass arg] [-chainCAfile filename] [-chainCApath directory] [-chainCAstore uri] [-requestCAfile filename] [-dane_tlsa_domain domain] [-dane_tlsa_rrdata rrdata] [-dane_ee_no_namechecks] [-reconnect] [-showcerts] [-prexit] [-no-interactive] [-debug] [-trace] [-nocommands] [-adv] [-security_debug] [-security_debug_verbose] [-msg] [-timeout] [-mtu size] [-no_etm] [-no_ems] [-keymatexport label] [-keymatexportlen len] [-msgfile filename] [-nbio_test] [-state] [-nbio] [-crlf] [-ign_eof] [-no_ign_eof] [-psk_identity identity] [-psk key] [-psk_session file] [-quiet] [-sctp] [-sctp_label_bug] [-fallback_scsv] [-async] [-maxfraglen len] [-max_send_frag] [-split_send_frag] [-max_pipelines] [-read_buf] [-ignore_unexpected_eof] [-bugs] [-no_tx_cert_comp] [-no_rx_cert_comp] [-comp] [-no_comp] [-brief] [-legacy_server_connect] [-no_legacy_server_connect] [-allow_no_dhe_kex] [-prefer_no_dhe_kex] [-sigalgs sigalglist] [-curves curvelist] [-cipher cipherlist] [-ciphersuites val] [-serverpref] [-starttls protocol] [-name hostname] [-xmpphost hostname] [-name hostname] [-tlsextdebug] [-no_ticket] [-sess_out filename] [-serverinfo types] [-sess_in filename] [-serverinfo types] [-status] [-alpn protocols] [-nextprotoneg protocols] [-ct] [-noct] [-ctlogfile] [-keylogfile file] [-early_data file] [-enable_pha] [-use_srtp value] [-srpuser value] [-srppass value] [-srp_lateuser] [-srp_moregroups] [-srp_strength number] [-ktls] [-tfo] [-nameopt option] [-no_ssl3] [-no_tls1] [-no_tls1_1] [-no_tls1_2] [-no_tls1_3] [-ssl3] [-tls1] [-tls1_1] [-tls1_2] [-tls1_3] [-dtls] [-dtls1] [-dtls1_2] [-xkey infile] [-xcert file] [-xchain file] [-xchain_build file] [-xcertform DER|PEM]> [-xkeyform DER|PEM]> [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-bugs] [-no_comp] [-comp] [-no_ticket] [-serverpref] [-client_renegotiation] [-legacy_renegotiation] [-no_renegotiation] [-no_resumption_on_reneg] [-legacy_server_connect] [-no_legacy_server_connect] [-no_etm] [-allow_no_dhe_kex] [-prefer_no_dhe_kex] [-prioritize_chacha] [-strict] [-sigalgs algs] [-client_sigalgs algs] [-groups groups] [-curves curves] [-named_curve curve] [-cipher ciphers] [-ciphersuites 1.3ciphers] [-min_protocol minprot] [-max_protocol maxprot] [-record_padding padding] [-debug_broken_protocol] [-no_middlebox] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq] [-engine id] [-ssl_client_engine id] [-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks] [-enable_server_rpk] [-enable_client_rpk] [host:port]

- -

DESCRIPTION

- -

This command implements a generic SSL/TLS client which connects to a remote host using SSL/TLS. It is a very useful diagnostic tool for SSL servers.

- -

OPTIONS

- -

In addition to the options below, this command also supports the common and client only options documented in the "Supported Command Line Commands" section of the SSL_CONF_cmd(3) manual page.

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-ssl_config section
-
- -

Use the specified section of the configuration file to configure the SSL_CTX object.

- -
-
-connect host:port
-
- -

This specifies the host and optional port to connect to. It is possible to select the host and port using the optional target positional argument instead. If neither this nor the target positional argument are specified then an attempt is made to connect to the local host on port 4433. If the host string is an IPv6 address, it must be enclosed in [ and ].

- -
-
-host hostname
-
- -

Host to connect to; use -connect instead.

- -
-
-port port
-
- -

Connect to the specified port; use -connect instead.

- -
-
-bind host:port
-
- -

This specifies the host address and or port to bind as the source for the connection. For Unix-domain sockets the port is ignored and the host is used as the source socket address. If the host string is an IPv6 address, it must be enclosed in [ and ].

- -
-
-proxy host:port
-
- -

When used with the -connect flag, the program uses the host and port specified with this flag and issues an HTTP CONNECT command to connect to the desired server. If the host string is an IPv6 address, it must be enclosed in [ and ].

- -
-
-proxy_user userid
-
- -

When used with the -proxy flag, the program will attempt to authenticate with the specified proxy using basic (base64) authentication. NB: Basic authentication is insecure; the credentials are sent to the proxy in easily reversible base64 encoding before any TLS/SSL session is established. Therefore, these credentials are easily recovered by anyone able to sniff/trace the network. Use with caution.

- -
-
-proxy_pass arg
-
- -

The proxy password source, used with the -proxy_user flag. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-unix path
-
- -

Connect over the specified Unix-domain socket.

- -
-
-4
-
- -

Use IPv4 only.

- -
-
-6
-
- -

Use IPv6 only.

- -
-
-quic
-
- -

Connect using the QUIC protocol. If specified then the -alpn option must also be provided.

- -
-
-servername name
-
- -

Set the TLS SNI (Server Name Indication) extension in the ClientHello message to the given value. If -servername is not provided, the TLS SNI extension will be populated with the name given to -connect if it follows a DNS name format. If -connect is not provided either, the SNI is set to "localhost". This is the default since OpenSSL 1.1.1.

- -

Even though SNI should normally be a DNS name and not an IP address, if -servername is provided then that name will be sent, regardless of whether it is a DNS name or not.

- -

This option cannot be used in conjunction with -noservername.

- -
-
-noservername
-
- -

Suppresses sending of the SNI (Server Name Indication) extension in the ClientHello message. Cannot be used in conjunction with the -servername or -dane_tlsa_domain options.

- -
-
-cert filename
-
- -

The client certificate to use, if one is requested by the server. The default is not to use a certificate.

- -

The chain for the client certificate may be specified using -cert_chain.

- -
-
-certform DER|PEM|P12
-
- -

The client certificate file format to use; unspecified by default. See openssl-format-options(1) for details.

- -
-
-cert_chain
-
- -

A file or URI of untrusted certificates to use when attempting to build the certificate chain related to the certificate specified via the -cert option. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-build_chain
-
- -

Specify whether the application should build the client certificate chain to be provided to the server.

- -
-
-CRL filename
-
- -

CRL file to use to check the server's certificate.

- -
-
-CRLform DER|PEM
-
- -

The CRL file format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-crl_download
-
- -

Download CRL from distribution points in the certificate. Note that this option is ignored if -crl_check option is not provided. Note that the maximum size of CRL is limited by X509_CRL_load_http(3) function.

- -
-
-key filename|uri
-
- -

The client private key to use. If not specified then the certificate file will be used to read also the key.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The key format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-pass arg
-
- -

the private key and certificate file password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-verify depth
-
- -

The verify depth to use. This specifies the maximum length of the server certificate chain and turns on server certificate verification. Unless the -verify_return_error option is given, the verify operation continues after errors so all the problems with a certificate chain can be seen. As a side effect the connection will never fail due to a server certificate verify failure.

- -

By default, validation of server certificates and their chain is done w.r.t. the (D)TLS Server (sslserver) purpose. For details see "Certificate Extensions" in openssl-verification-options(1).

- -
-
-verify_return_error
-
- -

Turns on server certificate verification, like with -verify, but returns verification errors instead of continuing. This will typically abort the handshake with a fatal error.

- -
-
-verify_quiet
-
- -

Limit verify output to only errors.

- -
-
-verifyCAfile filename
-
- -

A file in PEM format containing trusted certificates to use for verifying the server's certificate.

- -
-
-verifyCApath dir
-
- -

A directory containing trusted certificates to use for verifying the server's certificate. This directory must be in "hash format", see openssl-verify(1) for more information.

- -
-
-verifyCAstore uri
-
- -

The URI of a store containing trusted certificates to use for verifying the server's certificate.

- -
-
-chainCAfile file
-
- -

A file in PEM format containing trusted certificates to use when attempting to build the client certificate chain.

- -
-
-chainCApath directory
-
- -

A directory containing trusted certificates to use for building the client certificate chain provided to the server. This directory must be in "hash format", see openssl-verify(1) for more information.

- -
-
-chainCAstore uri
-
- -

The URI of a store containing trusted certificates to use when attempting to build the client certificate chain. The URI may indicate a single certificate, as well as a collection of them. With URIs in the file: scheme, this acts as -chainCAfile or -chainCApath, depending on if the URI indicates a directory or a single file. See ossl_store-file(7) for more information on the file: scheme.

- -
-
-requestCAfile file
-
- -

A file containing a list of certificates whose subject names will be sent to the server in the certificate_authorities extension. Only supported for TLS 1.3

- -
-
-dane_tlsa_domain domain
-
- -

Enable RFC6698/RFC7671 DANE TLSA authentication and specify the TLSA base domain which becomes the default SNI hint and the primary reference identifier for hostname checks. This must be used in combination with at least one instance of the -dane_tlsa_rrdata option below.

- -

When DANE authentication succeeds, the diagnostic output will include the lowest (closest to 0) depth at which a TLSA record authenticated a chain certificate. When that TLSA record is a "2 1 0" trust anchor public key that signed (rather than matched) the top-most certificate of the chain, the result is reported as "TA public key verified". Otherwise, either the TLSA record "matched TA certificate" at a positive depth or else "matched EE certificate" at depth 0.

- -
-
-dane_tlsa_rrdata rrdata
-
- -

Use one or more times to specify the RRDATA fields of the DANE TLSA RRset associated with the target service. The rrdata value is specified in "presentation form", that is four whitespace separated fields that specify the usage, selector, matching type and associated data, with the last of these encoded in hexadecimal. Optional whitespace is ignored in the associated data field. For example:

- -
$ openssl s_client -brief -starttls smtp \
-  -connect smtp.example.com:25 \
-  -dane_tlsa_domain smtp.example.com \
-  -dane_tlsa_rrdata "2 1 1
-    B111DD8A1C2091A89BD4FD60C57F0716CCE50FEEFF8137CDBEE0326E 02CF362B" \
-  -dane_tlsa_rrdata "2 1 1
-    60B87575447DCBA2A36B7D11AC09FB24A9DB406FEE12D2CC90180517 616E8A18"
-...
-Verification: OK
-Verified peername: smtp.example.com
-DANE TLSA 2 1 1 ...ee12d2cc90180517616e8a18 matched TA certificate at depth 1
-...
- -
-
-dane_ee_no_namechecks
-
- -

This disables server name checks when authenticating via DANE-EE(3) TLSA records. For some applications, primarily web browsers, it is not safe to disable name checks due to "unknown key share" attacks, in which a malicious server can convince a client that a connection to a victim server is instead a secure connection to the malicious server. The malicious server may then be able to violate cross-origin scripting restrictions. Thus, despite the text of RFC7671, name checks are by default enabled for DANE-EE(3) TLSA records, and can be disabled in applications where it is safe to do so. In particular, SMTP and XMPP clients should set this option as SRV and MX records already make it possible for a remote domain to redirect client connections to any server of its choice, and in any case SMTP and XMPP clients do not execute scripts downloaded from remote servers.

- -
-
-reconnect
-
- -

Reconnects to the same server 5 times using the same session ID, this can be used as a test that session caching is working.

- -
-
-showcerts
-
- -

Displays the server certificate list as sent by the server: it only consists of certificates the server has sent (in the order the server has sent them). It is not a verified chain.

- -
-
-prexit
-
- -

Print session information when the program exits. This will always attempt to print out information even if the connection fails. Normally information will only be printed out once if the connection succeeds. This option is useful because the cipher in use may be renegotiated or the connection may fail because a client certificate is required or is requested only after an attempt is made to access a certain URL. Note: the output produced by this option is not always accurate because a connection might never have been established.

- -
-
-no-interactive
-
- -

This flag can be used to run the client in a non-interactive mode.

- -
-
-state
-
- -

Prints out the SSL session states.

- -
-
-debug
-
- -

Print extensive debugging information including a hex dump of all traffic.

- -
-
-nocommands
-
- -

Do not use interactive command letters.

- -
-
-adv
-
- -

Use advanced command mode.

- -
-
-security_debug
-
- -

Enable security debug messages.

- -
-
-security_debug_verbose
-
- -

Output more security debug output.

- -
-
-msg
-
- -

Show protocol messages.

- -
-
-timeout
-
- -

Enable send/receive timeout on DTLS connections.

- -
-
-mtu size
-
- -

Set MTU of the link layer to the specified size.

- -
-
-no_etm
-
- -

Disable Encrypt-then-MAC negotiation.

- -
-
-no_ems
-
- -

Disable Extended master secret negotiation.

- -
-
-keymatexport label
-
- -

Export keying material using the specified label.

- -
-
-keymatexportlen len
-
- -

Export the specified number of bytes of keying material; default is 20.

- -

Show all protocol messages with hex dump.

- -
-
-trace
-
- -

Show verbose trace output of protocol messages.

- -
-
-msgfile filename
-
- -

File to send output of -msg or -trace to, default standard output.

- -
-
-nbio_test
-
- -

Tests nonblocking I/O

- -
-
-nbio
-
- -

Turns on nonblocking I/O

- -
-
-crlf
-
- -

This option translated a line feed from the terminal into CR+LF as required by some servers.

- -
-
-ign_eof
-
- -

Inhibit shutting down the connection when end of file is reached in the input. This implicitly turns on -nocommands as well.

- -
-
-quiet
-
- -

Inhibit printing of session and certificate information. This implicitly turns on -ign_eof and -nocommands as well.

- -
-
-no_ign_eof
-
- -

Shut down the connection when end of file is reached in the input. Can be used to override the implicit -ign_eof after -quiet.

- -
-
-psk_identity identity
-
- -

Use the PSK identity identity when using a PSK cipher suite. The default value is "Client_identity" (without the quotes).

- -
-
-psk key
-
- -

Use the PSK key key when using a PSK cipher suite. The key is given as a hexadecimal number without leading 0x, for example -psk 1a2b3c4d. This option must be provided in order to use a PSK cipher.

- -
-
-psk_session file
-
- -

Use the pem encoded SSL_SESSION data stored in file as the basis of a PSK. Note that this will only work if TLSv1.3 is negotiated.

- -
-
-sctp
-
- -

Use SCTP for the transport protocol instead of UDP in DTLS. Must be used in conjunction with -dtls, -dtls1 or -dtls1_2. This option is only available where OpenSSL has support for SCTP enabled.

- -
-
-sctp_label_bug
-
- -

Use the incorrect behaviour of older OpenSSL implementations when computing endpoint-pair shared secrets for DTLS/SCTP. This allows communication with older broken implementations but breaks interoperability with correct implementations. Must be used in conjunction with -sctp. This option is only available where OpenSSL has support for SCTP enabled.

- -
-
-fallback_scsv
-
- -

Send TLS_FALLBACK_SCSV in the ClientHello.

- -
-
-async
-
- -

Switch on asynchronous mode. Cryptographic operations will be performed asynchronously. This will only have an effect if an asynchronous capable engine is also used via the -engine option. For test purposes the dummy async engine (dasync) can be used (if available).

- -
-
-maxfraglen len
-
- -

Enable Maximum Fragment Length Negotiation; allowed values are 512, 1024, 2048, and 4096.

- -
-
-max_send_frag int
-
- -

The maximum size of data fragment to send. See SSL_CTX_set_max_send_fragment(3) for further information.

- -
-
-split_send_frag int
-
- -

The size used to split data for encrypt pipelines. If more data is written in one go than this value then it will be split into multiple pipelines, up to the maximum number of pipelines defined by max_pipelines. This only has an effect if a suitable cipher suite has been negotiated, an engine that supports pipelining has been loaded, and max_pipelines is greater than 1. See SSL_CTX_set_split_send_fragment(3) for further information.

- -
-
-max_pipelines int
-
- -

The maximum number of encrypt/decrypt pipelines to be used. This will only have an effect if an engine has been loaded that supports pipelining (e.g. the dasync engine) and a suitable cipher suite has been negotiated. The default value is 1. See SSL_CTX_set_max_pipelines(3) for further information.

- -
-
-read_buf int
-
- -

The default read buffer size to be used for connections. This will only have an effect if the buffer size is larger than the size that would otherwise be used and pipelining is in use (see SSL_CTX_set_default_read_buffer_len(3) for further information).

- -
-
-ignore_unexpected_eof
-
- -

Some TLS implementations do not send the mandatory close_notify alert on shutdown. If the application tries to wait for the close_notify alert but the peer closes the connection without sending it, an error is generated. When this option is enabled the peer does not need to send the close_notify alert and a closed connection will be treated as if the close_notify alert was received. For more information on shutting down a connection, see SSL_shutdown(3).

- -
-
-bugs
-
- -

There are several known bugs in SSL and TLS implementations. Adding this option enables various workarounds.

- -
-
-no_tx_cert_comp
-
- -

Disables support for sending TLSv1.3 compressed certificates.

- -
-
-no_rx_cert_comp
-
- -

Disables support for receiving TLSv1.3 compressed certificate.

- -
-
-comp
-
- -

Enables support for SSL/TLS compression. This option was introduced in OpenSSL 1.1.0. TLS compression is not recommended and is off by default as of OpenSSL 1.1.0. TLS compression can only be used in security level 1 or lower. From OpenSSL 3.2.0 and above the default security level is 2, so this option will have no effect without also changing the security level. Use the -cipher option to change the security level. See openssl-ciphers(1) for more information.

- -
-
-no_comp
-
- -

Disables support for SSL/TLS compression. TLS compression is not recommended and is off by default as of OpenSSL 1.1.0.

- -
-
-brief
-
- -

Only provide a brief summary of connection parameters instead of the normal verbose output.

- -
-
-sigalgs sigalglist
-
- -

Specifies the list of signature algorithms that are sent by the client. The server selects one entry in the list based on its preferences. For example strings, see SSL_CTX_set1_sigalgs(3)

- -
-
-curves curvelist
-
- -

Specifies the list of supported curves to be sent by the client. The curve is ultimately selected by the server.

- -

The list of all supported groups includes named EC parameters as well as X25519 and X448 or FFDHE groups, and may also include groups implemented in 3rd-party providers. For a list of named EC parameters, use:

- -
$ openssl ecparam -list_curves
- -
-
-cipher cipherlist
-
- -

This allows the TLSv1.2 and below cipher list sent by the client to be modified. This list will be combined with any TLSv1.3 ciphersuites that have been configured. Although the server determines which ciphersuite is used it should take the first supported cipher in the list sent by the client. See openssl-ciphers(1) for more information.

- -
-
-ciphersuites val
-
- -

This allows the TLSv1.3 ciphersuites sent by the client to be modified. This list will be combined with any TLSv1.2 and below ciphersuites that have been configured. Although the server determines which cipher suite is used it should take the first supported cipher in the list sent by the client. See openssl-ciphers(1) for more information. The format for this list is a simple colon (":") separated list of TLSv1.3 ciphersuite names.

- -
-
-starttls protocol
-
- -

Send the protocol-specific message(s) to switch to TLS for communication. protocol is a keyword for the intended protocol. Currently, the only supported keywords are "smtp", "pop3", "imap", "ftp", "xmpp", "xmpp-server", "irc", "postgres", "mysql", "lmtp", "nntp", "sieve" and "ldap".

- -
-
-xmpphost hostname
-
- -

This option, when used with "-starttls xmpp" or "-starttls xmpp-server", specifies the host for the "to" attribute of the stream element. If this option is not specified, then the host specified with "-connect" will be used.

- -

This option is an alias of the -name option for "xmpp" and "xmpp-server".

- -
-
-name hostname
-
- -

This option is used to specify hostname information for various protocols used with -starttls option. Currently only "xmpp", "xmpp-server", "smtp" and "lmtp" can utilize this -name option.

- -

If this option is used with "-starttls xmpp" or "-starttls xmpp-server", if specifies the host for the "to" attribute of the stream element. If this option is not specified, then the host specified with "-connect" will be used.

- -

If this option is used with "-starttls lmtp" or "-starttls smtp", it specifies the name to use in the "LMTP LHLO" or "SMTP EHLO" message, respectively. If this option is not specified, then "mail.example.com" will be used.

- -
-
-tlsextdebug
-
- -

Print out a hex dump of any TLS extensions received from the server.

- -
-
-no_ticket
-
- -

Disable RFC4507bis session ticket support.

- -
-
-sess_out filename
-
- -

Output SSL session to filename.

- -
-
-sess_in filename
-
- -

Load SSL session from filename. The client will attempt to resume a connection from this session.

- -
-
-serverinfo types
-
- -

A list of comma-separated TLS Extension Types (numbers between 0 and 65535). Each type will be sent as an empty ClientHello TLS Extension. The server's response (if any) will be encoded and displayed as a PEM file.

- -
-
-status
-
- -

Sends a certificate status request to the server (OCSP stapling). The server response (if any) is printed out.

- -
-
-alpn protocols, -nextprotoneg protocols
-
- -

These flags enable the Enable the Application-Layer Protocol Negotiation or Next Protocol Negotiation (NPN) extension, respectively. ALPN is the IETF standard and replaces NPN. The protocols list is a comma-separated list of protocol names that the client should advertise support for. The list should contain the most desirable protocols first. Protocol names are printable ASCII strings, for example "http/1.1" or "spdy/3". An empty list of protocols is treated specially and will cause the client to advertise support for the TLS extension but disconnect just after receiving ServerHello with a list of server supported protocols. The flag -nextprotoneg cannot be specified if -tls1_3 is used.

- -
-
-ct, -noct
-
- -

Use one of these two options to control whether Certificate Transparency (CT) is enabled (-ct) or disabled (-noct). If CT is enabled, signed certificate timestamps (SCTs) will be requested from the server and reported at handshake completion.

- -

Enabling CT also enables OCSP stapling, as this is one possible delivery method for SCTs.

- -
-
-ctlogfile
-
- -

A file containing a list of known Certificate Transparency logs. See SSL_CTX_set_ctlog_list_file(3) for the expected file format.

- -
-
-keylogfile file
-
- -

Appends TLS secrets to the specified keylog file such that external programs (like Wireshark) can decrypt TLS connections.

- -
-
-early_data file
-
- -

Reads the contents of the specified file and attempts to send it as early data to the server. This will only work with resumed sessions that support early data and when the server accepts the early data.

- -
-
-enable_pha
-
- -

For TLSv1.3 only, send the Post-Handshake Authentication extension. This will happen whether or not a certificate has been provided via -cert.

- -
-
-use_srtp value
-
- -

Offer SRTP key management, where value is a colon-separated profile list.

- -
-
-srpuser value
-
- -

Set the SRP username to the specified value. This option is deprecated.

- -
-
-srppass value
-
- -

Set the SRP password to the specified value. This option is deprecated.

- -
-
-srp_lateuser
-
- -

SRP username for the second ClientHello message. This option is deprecated.

- -
-
-srp_moregroups This option is deprecated.
-
- -

Tolerate other than the known g and N values.

- -
-
-srp_strength number
-
- -

Set the minimal acceptable length, in bits, for N. This option is deprecated.

- -
-
-ktls
-
- -

Enable Kernel TLS for sending and receiving. This option was introduced in OpenSSL 3.2.0. Kernel TLS is off by default as of OpenSSL 3.2.0.

- -
-
-tfo
-
- -

Enable creation of connections via TCP fast open (RFC7413).

- -
-
-no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3, -ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3
-
- -

See "TLS Version Options" in openssl(1).

- -
-
-dtls, -dtls1, -dtls1_2
-
- -

These specify the use of DTLS instead of TLS. See "TLS Version Options" in openssl(1).

- -
-
-nameopt option
-
- -

This specifies how the subject or issuer names are displayed. See openssl-namedisplay-options(1) for details.

- -
-
-xkey infile, -xcert file, -xchain file, -xchain_build file, -xcertform DER|PEM, -xkeyform DER|PEM
-
- -

Set extended certificate verification options. See "Extended Verification Options" in openssl-verification-options(1) for details.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-bugs, -comp, -no_comp, -no_ticket, -serverpref, -client_renegotiation, -legacy_renegotiation, -no_renegotiation, -no_resumption_on_reneg, -legacy_server_connect, -no_legacy_server_connect, -no_etm -allow_no_dhe_kex, -prefer_no_dhe_kex, -prioritize_chacha, -strict, -sigalgs algs, -client_sigalgs algs, -groups groups, -curves curves, -named_curve curve, -cipher ciphers, -ciphersuites 1.3ciphers, -min_protocol minprot, -max_protocol maxprot, -record_padding padding, -debug_broken_protocol, -no_middlebox
-
- -

See "SUPPORTED COMMAND LINE COMMANDS" in SSL_CONF_cmd(3) for details.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-ssl_client_engine id
-
- -

Specify engine to be used for client certificate operations.

- -
-
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -

Verification errors are displayed, for debugging, but the command will proceed unless the -verify_return_error option is used.

- -
-
-enable_server_rpk
-
- -

Enable support for receiving raw public keys (RFC7250) from the server. Use of X.509 certificates by the server becomes optional, and servers that support raw public keys may elect to use them. Servers that don't support raw public keys or prefer to use X.509 certificates can still elect to send X.509 certificates as usual.

- -
-
-enable_client_rpk
-
- -

Enable support for sending raw public keys (RFC7250) to the server. A raw public key will be sent by the client, if solicited by the server, provided a suitable key and public certificate pair is configured. Some servers may nevertheless not request any client credentials, or may request a certificate.

- -
-
host:port
-
- -

Rather than providing -connect, the target host and optional port may be provided as a single positional argument after all options. If neither this nor -connect are provided, falls back to attempting to connect to localhost on port 4433. If the host string is an IPv6 address, it must be enclosed in [ and ].

- -
-
- -

CONNECTED COMMANDS (BASIC)

- -

If a connection is established with an SSL/TLS server then any data received from the server is displayed and any key presses will be sent to the server. If end of file is reached then the connection will be closed down.

- -

When used interactively (which means neither -quiet nor -ign_eof have been given), and neither of -adv or -nocommands are given then "Basic" command mode is entered. In this mode certain commands are recognized which perform special operations. These commands are a letter which must appear at the start of a line. All further data after the initial letter on the line is ignored. The commands are listed below.

- -
- -
Q
-
- -

End the current SSL connection and exit.

- -
-
R
-
- -

Renegotiate the SSL session (TLSv1.2 and below only).

- -
-
C
-
- -

Attempt to reconnect to the server using a resumption handshake.

- -
-
k
-
- -

Send a key update message to the server (TLSv1.3 only)

- -
-
K
-
- -

Send a key update message to the server and request one back (TLSv1.3 only)

- -
-
- -

CONNECTED COMMANDS (ADVANCED)

- -

If -adv has been given then "advanced" command mode is entered. As with basic mode, if a connection is established with an SSL/TLS server then any data received from the server is displayed and any key presses will be sent to the server. If end of file is reached then the connection will be closed down.

- -

Special commands can be supplied by enclosing them in braces, e.g. "{help}" or "{quit}". These commands can appear anywhere in the text entered into s_client, but they are not sent to the server. Some commands can take an argument by ending the command name with ":" and then providing the argument, e.g. "{keyup:req}". Some commands are only available when certain protocol versions have been negotiated.

- -

If a newline appears at the end of a line entered into s_client then this is also sent to the server. If a command appears on a line on its own with no other text on the same line, then the newline is suppressed and not sent to the server.

- -

The following commands are recognised.

- -
- -
help
-
- -

Prints out summary help text about the available commands.

- -
-
quit
-
- -

Close the connection to the peer

- -
-
reconnect
-
- -

Reconnect to the peer and attempt a resumption handshake

- -
-
keyup
-
- -

Send a Key Update message. TLSv1.3 only. This command takes an optional argument. If the argument "req" is supplied then the peer is also requested to update its keys. Otherwise if "noreq" is supplied the peer is not requested to update its keys. The default is "req".

- -
-
reneg
-
- -

Initiate a renegotiation with the server. (D)TLSv1.2 or below only.

- -
-
fin
-
- -

Indicate FIN on the current stream. QUIC only. Once FIN has been sent any further text entered for this stream is ignored.

- -
-
- -

NOTES

- -

This command can be used to debug SSL servers. To connect to an SSL HTTP server the command:

- -
openssl s_client -connect servername:443
- -

would typically be used (https uses port 443). If the connection succeeds then an HTTP command can be given such as "GET /" to retrieve a web page.

- -

If the handshake fails then there are several possible causes, if it is nothing obvious like no client certificate then the -bugs, -ssl3, -tls1, -no_ssl3, -no_tls1 options can be tried in case it is a buggy server. In particular you should play with these options before submitting a bug report to an OpenSSL mailing list.

- -

A frequent problem when attempting to get client certificates working is that a web client complains it has no certificates or gives an empty list to choose from. This is normally because the server is not sending the clients certificate authority in its "acceptable CA list" when it requests a certificate. By using this command, the CA list can be viewed and checked. However, some servers only request client authentication after a specific URL is requested. To obtain the list in this case it is necessary to use the -prexit option and send an HTTP request for an appropriate page.

- -

If a certificate is specified on the command line using the -cert option it will not be used unless the server specifically requests a client certificate. Therefore, merely including a client certificate on the command line is no guarantee that the certificate works.

- -

If there are problems verifying a server certificate then the -showcerts option can be used to show all the certificates sent by the server.

- -

This command is a test tool and is designed to continue the handshake after any certificate verification errors. As a result it will accept any certificate chain (trusted or not) sent by the peer. Non-test applications should not do this as it makes them vulnerable to a MITM attack. This behaviour can be changed by with the -verify_return_error option: any verify errors are then returned aborting the handshake.

- -

The -bind option may be useful if the server or a firewall requires connections to come from some particular address and or port.

- -

Note on Non-Interactive Use

- -

When s_client is run in a non-interactive environment (e.g., a cron job or a script without a valid stdin), it may close the connection prematurely, especially with TLS 1.3. To prevent this, you can use the -ign_eof flag, which keeps s_client running even after reaching EOF from stdin.

- -

For example:

- -
openssl s_client -connect <server address>:443 -tls1_3
-                 -sess_out /path/to/tls_session_params_file
-                 -ign_eof </dev/null
- -

However, relying solely on -ign_eof can lead to issues if the server keeps the connection open, expecting the client to close first. In such cases, the client may hang indefinitely. This behavior is not uncommon, particularly with protocols where the server waits for a graceful disconnect from the client.

- -

For example, when connecting to an SMTP server, the session may pause if the server expects a QUIT command before closing:

- -
$ openssl s_client -brief -ign_eof -starttls smtp
-                   -connect <server address>:25 </dev/null
-CONNECTION ESTABLISHED
-Protocol version: TLSv1.3
-Ciphersuite: TLS_AES_256_GCM_SHA384
-...
-250 CHUNKING
-[long pause]
- -

To avoid such hangs, it's better to use an application-level command to initiate a clean disconnect. For SMTP, you can send a QUIT command:

- -
printf 'QUIT\r\n' | openssl s_client -connect <server address>:25
-                                     -starttls smtp -brief -ign_eof
- -

Similarly, for HTTP/1.1 connections, including a `Connection: close` header ensures the server closes the connection after responding:

- -
printf 'GET / HTTP/1.1\r\nHost: <server address>\r\nConnection: close\r\n\r\n'
-    | openssl s_client -connect <server address>:443 -brief
- -

These approaches help manage the connection closure gracefully and prevent hangs caused by the server waiting for the client to initiate the disconnect.

- -

BUGS

- -

Because this program has a lot of options and also because some of the techniques used are rather old, the C source for this command is rather hard to read and not a model of how things should be done. A typical SSL client program would be much simpler.

- -

The -prexit option is a bit of a hack. We should really report information whenever a session is renegotiated.

- -

SEE ALSO

- -

openssl(1), openssl-sess_id(1), openssl-s_server(1), openssl-ciphers(1), SSL_CONF_cmd(3), SSL_CTX_set_max_send_fragment(3), SSL_CTX_set_split_send_fragment(3), SSL_CTX_set_max_pipelines(3), ossl_store-file(7)

- -

HISTORY

- -

The -no_alt_chains option was added in OpenSSL 1.1.0. The -name option was added in OpenSSL 1.1.1.

- -

The -certform option has become obsolete in OpenSSL 3.0.0 and has no effect.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -enable_client_rpk, -enable_server_rpk, -no_rx_cert_comp, -no_tx_cert_comp, and -tfo options were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-s_server.html b/openssl-install/share/doc/openssl/html/man1/openssl-s_server.html deleted file mode 100644 index da393fef..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-s_server.html +++ /dev/null @@ -1,976 +0,0 @@ - - - - -openssl-s_server - - - - - - - - - - -

NAME

- -

openssl-s_server - SSL/TLS server program

- -

SYNOPSIS

- -

openssl s_server [-help] [-port +int] [-accept val] [-unix val] [-4] [-6] [-unlink] [-context val] [-verify int] [-Verify int] [-cert infile] [-cert2 infile] [-certform DER|PEM|P12] [-cert_chain infile] [-build_chain] [-serverinfo val] [-key filename|uri] [-key2 filename|uri] [-keyform DER|PEM|P12|ENGINE] [-pass val] [-dcert infile] [-dcertform DER|PEM|P12] [-dcert_chain infile] [-dkey filename|uri] [-dkeyform DER|PEM|P12|ENGINE] [-dpass val] [-nbio_test] [-crlf] [-debug] [-msg] [-msgfile outfile] [-state] [-nocert] [-quiet] [-no_resume_ephemeral] [-www] [-WWW] [-http_server_binmode] [-no_ca_names] [-ignore_unexpected_eof] [-servername] [-servername_fatal] [-tlsextdebug] [-HTTP] [-id_prefix val] [-keymatexport val] [-keymatexportlen +int] [-CRL infile] [-CRLform DER|PEM] [-crl_download] [-chainCAfile infile] [-chainCApath dir] [-chainCAstore uri] [-verifyCAfile infile] [-verifyCApath dir] [-verifyCAstore uri] [-no_cache] [-ext_cache] [-verify_return_error] [-verify_quiet] [-ign_eof] [-no_ign_eof] [-no_etm] [-no_ems] [-status] [-status_verbose] [-status_timeout int] [-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]] [-no_proxy addresses] [-status_url val] [-status_file infile] [-ssl_config val] [-trace] [-security_debug] [-security_debug_verbose] [-brief] [-rev] [-async] [-max_send_frag +int] [-split_send_frag +int] [-max_pipelines +int] [-naccept +int] [-read_buf +int] [-bugs] [-no_tx_cert_comp] [-no_rx_cert_comp] [-no_comp] [-comp] [-no_ticket] [-serverpref] [-legacy_renegotiation] [-no_renegotiation] [-no_resumption_on_reneg] [-allow_no_dhe_kex] [-prefer_no_dhe_kex] [-prioritize_chacha] [-strict] [-sigalgs val] [-client_sigalgs val] [-groups val] [-curves val] [-named_curve val] [-cipher val] [-ciphersuites val] [-dhparam infile] [-record_padding val] [-debug_broken_protocol] [-nbio] [-psk_identity val] [-psk_hint val] [-psk val] [-psk_session file] [-srpvfile infile] [-srpuserseed val] [-timeout] [-mtu +int] [-listen] [-sctp] [-sctp_label_bug] [-use_srtp val] [-no_dhe] [-nextprotoneg val] [-alpn val] [-ktls] [-sendfile] [-zerocopy_sendfile] [-keylogfile outfile] [-recv_max_early_data int] [-max_early_data int] [-early_data] [-stateless] [-anti_replay] [-no_anti_replay] [-num_tickets] [-tfo] [-cert_comp] [-nameopt option] [-no_ssl3] [-no_tls1] [-no_tls1_1] [-no_tls1_2] [-no_tls1_3] [-ssl3] [-tls1] [-tls1_1] [-tls1_2] [-tls1_3] [-dtls] [-dtls1] [-dtls1_2] [-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks] [-bugs] [-no_comp] [-comp] [-no_ticket] [-serverpref] [-client_renegotiation] [-legacy_renegotiation] [-no_renegotiation] [-no_resumption_on_reneg] [-legacy_server_connect] [-no_legacy_server_connect] [-no_etm] [-allow_no_dhe_kex] [-prefer_no_dhe_kex] [-prioritize_chacha] [-strict] [-sigalgs algs] [-client_sigalgs algs] [-groups groups] [-curves curves] [-named_curve curve] [-cipher ciphers] [-ciphersuites 1.3ciphers] [-min_protocol minprot] [-max_protocol maxprot] [-record_padding padding] [-debug_broken_protocol] [-no_middlebox] [-xkey infile] [-xcert file] [-xchain file] [-xchain_build file] [-xcertform DER|PEM]> [-xkeyform DER|PEM]> [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [-enable_server_rpk] [-enable_client_rpk]

- -

DESCRIPTION

- -

This command implements a generic SSL/TLS server which listens for connections on a given port using SSL/TLS.

- -

OPTIONS

- -

In addition to the options below, this command also supports the common and server only options documented "Supported Command Line Commands" in SSL_CONF_cmd(3)

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-port +int
-
- -

The TCP port to listen on for connections. If not specified 4433 is used.

- -
-
-accept val
-
- -

The optional TCP host and port to listen on for connections. If not specified, *:4433 is used.

- -
-
-unix val
-
- -

Unix domain socket to accept on.

- -
-
-4
-
- -

Use IPv4 only.

- -
-
-6
-
- -

Use IPv6 only.

- -
- -
- -

For -unix, unlink any existing socket first.

- -
-
-context val
-
- -

Sets the SSL context id. It can be given any string value. If this option is not present a default value will be used.

- -
-
-verify int, -Verify int
-
- -

The verify depth to use. This specifies the maximum length of the client certificate chain and makes the server request a certificate from the client. With the -verify option a certificate is requested but the client does not have to send one, with the -Verify option the client must supply a certificate or an error occurs.

- -

If the cipher suite cannot request a client certificate (for example an anonymous cipher suite or PSK) this option has no effect.

- -

By default, validation of any supplied client certificate and its chain is done w.r.t. the (D)TLS Client (sslclient) purpose. For details see "Certificate Extensions" in openssl-verification-options(1).

- -
-
-cert infile
-
- -

The certificate to use, most servers cipher suites require the use of a certificate and some require a certificate with a certain public key type: for example the DSS cipher suites require a certificate containing a DSS (DSA) key. If not specified then the filename server.pem will be used.

- -
-
-cert2 infile
-
- -

The certificate file to use for servername; default is server2.pem.

- -
-
-certform DER|PEM|P12
-
- -

The server certificate file format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-cert_chain
-
- -

A file or URI of untrusted certificates to use when attempting to build the certificate chain related to the certificate specified via the -cert option. These untrusted certificates are sent to clients and used for generating certificate status (aka OCSP stapling) requests. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-build_chain
-
- -

Specify whether the application should build the server certificate chain to be provided to the client.

- -
-
-serverinfo val
-
- -

A file containing one or more blocks of PEM data. Each PEM block must encode a TLS ServerHello extension (2 bytes type, 2 bytes length, followed by "length" bytes of extension data). If the client sends an empty TLS ClientHello extension matching the type, the corresponding ServerHello extension will be returned.

- -
-
-key filename|uri
-
- -

The private key to use. If not specified then the certificate file will be used.

- -
-
-key2 filename|uri
-
- -

The private Key file to use for servername if not given via -cert2.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The key format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-pass val
-
- -

The private key and certificate file password source. For more information about the format of val, see openssl-passphrase-options(1).

- -
-
-dcert infile, -dkey filename|uri
-
- -

Specify an additional certificate and private key, these behave in the same manner as the -cert and -key options except there is no default if they are not specified (no additional certificate and key is used). As noted above some cipher suites require a certificate containing a key of a certain type. Some cipher suites need a certificate carrying an RSA key and some a DSS (DSA) key. By using RSA and DSS certificates and keys a server can support clients which only support RSA or DSS cipher suites by using an appropriate certificate.

- -
-
-dcert_chain
-
- -

A file or URI of untrusted certificates to use when attempting to build the server certificate chain when a certificate specified via the -dcert option is in use. The input can be in PEM, DER, or PKCS#12 format.

- -
-
-dcertform DER|PEM|P12
-
- -

The format of the additional certificate file; unspecified by default. See openssl-format-options(1) for details.

- -
-
-dkeyform DER|PEM|P12|ENGINE
-
- -

The format of the additional private key; unspecified by default. See openssl-format-options(1) for details.

- -
-
-dpass val
-
- -

The passphrase for the additional private key and certificate. For more information about the format of val, see openssl-passphrase-options(1).

- -
-
-nbio_test
-
- -

Tests non blocking I/O.

- -
-
-crlf
-
- -

This option translated a line feed from the terminal into CR+LF.

- -
-
-debug
-
- -

Print extensive debugging information including a hex dump of all traffic.

- -
-
-security_debug
-
- -

Print output from SSL/TLS security framework.

- -
-
-security_debug_verbose
-
- -

Print more output from SSL/TLS security framework

- -
-
-msg
-
- -

Show all protocol messages with hex dump.

- -
-
-msgfile outfile
-
- -

File to send output of -msg or -trace to, default standard output.

- -
-
-state
-
- -

Prints the SSL session states.

- -
-
-CRL infile
-
- -

The CRL file to use.

- -
-
-CRLform DER|PEM
-
- -

The CRL file format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-crl_download
-
- -

Download CRLs from distribution points given in CDP extensions of certificates

- -
-
-verifyCAfile filename
-
- -

A file in PEM format CA containing trusted certificates to use for verifying client certificates.

- -
-
-verifyCApath dir
-
- -

A directory containing trusted certificates to use for verifying client certificates. This directory must be in "hash format", see openssl-verify(1) for more information.

- -
-
-verifyCAstore uri
-
- -

The URI of a store containing trusted certificates to use for verifying client certificates.

- -
-
-chainCAfile file
-
- -

A file in PEM format containing trusted certificates to use when attempting to build the server certificate chain.

- -
-
-chainCApath dir
-
- -

A directory containing trusted certificates to use for building the server certificate chain provided to the client. This directory must be in "hash format", see openssl-verify(1) for more information.

- -
-
-chainCAstore uri
-
- -

The URI of a store containing trusted certificates to use for building the server certificate chain provided to the client. The URI may indicate a single certificate, as well as a collection of them. With URIs in the file: scheme, this acts as -chainCAfile or -chainCApath, depending on if the URI indicates a directory or a single file. See ossl_store-file(7) for more information on the file: scheme.

- -
-
-nocert
-
- -

If this option is set then no certificate is used. This restricts the cipher suites available to the anonymous ones (currently just anonymous DH).

- -
-
-quiet
-
- -

Inhibit printing of session and certificate information.

- -
-
-no_resume_ephemeral
-
- -

Disable caching and tickets if ephemeral (EC)DH is used.

- -
-
-tlsextdebug
-
- -

Print a hex dump of any TLS extensions received from the server.

- -
-
-www
-
- -

Sends a status message back to the client when it connects. This includes information about the ciphers used and various session parameters. The output is in HTML format so this option can be used with a web browser. The special URL /renegcert turns on client cert validation, and /reneg tells the server to request renegotiation. The -early_data option cannot be used with this option.

- -
-
-WWW, -HTTP
-
- -

Emulates a simple web server. Pages will be resolved relative to the current directory, for example if the URL https://myhost/page.html is requested the file ./page.html will be sent. If the -HTTP flag is used, the files are sent directly, and should contain any HTTP response headers (including status response line). If the -WWW option is used, the response headers are generated by the server, and the file extension is examined to determine the Content-Type header. Extensions of html, htm, and php are text/html and all others are text/plain. In addition, the special URL /stats will return status information like the -www option. Neither of these options can be used in conjunction with -early_data.

- -
-
-http_server_binmode
-
- -

When acting as web-server (using option -WWW or -HTTP) open files requested by the client in binary mode.

- -
-
-no_ca_names
-
- -

Disable TLS Extension CA Names. You may want to disable it for security reasons or for compatibility with some Windows TLS implementations crashing when this extension is larger than 1024 bytes.

- -
-
-ignore_unexpected_eof
-
- -

Some TLS implementations do not send the mandatory close_notify alert on shutdown. If the application tries to wait for the close_notify alert but the peer closes the connection without sending it, an error is generated. When this option is enabled the peer does not need to send the close_notify alert and a closed connection will be treated as if the close_notify alert was received. For more information on shutting down a connection, see SSL_shutdown(3).

- -
-
-servername
-
- -

Servername for HostName TLS extension.

- -
-
-servername_fatal
-
- -

On servername mismatch send fatal alert (default: warning alert).

- -
-
-id_prefix val
-
- -

Generate SSL/TLS session IDs prefixed by val. This is mostly useful for testing any SSL/TLS code (e.g. proxies) that wish to deal with multiple servers, when each of which might be generating a unique range of session IDs (e.g. with a certain prefix).

- -
-
-keymatexport
-
- -

Export keying material using label.

- -
-
-keymatexportlen
-
- -

Export the given number of bytes of keying material; default 20.

- -
-
-no_cache
-
- -

Disable session cache.

- -
-
-ext_cache.
-
- -

Disable internal cache, set up and use external cache.

- -
-
-verify_return_error
-
- -

Verification errors normally just print a message but allow the connection to continue, for debugging purposes. If this option is used, then verification errors close the connection.

- -
-
-verify_quiet
-
- -

No verify output except verify errors.

- -
-
-ign_eof
-
- -

Ignore input EOF (default: when -quiet).

- -
-
-no_ign_eof
-
- -

Do not ignore input EOF.

- -
-
-no_etm
-
- -

Disable Encrypt-then-MAC negotiation.

- -
-
-no_ems
-
- -

Disable Extended master secret negotiation.

- -
-
-status
-
- -

Enables certificate status request support (aka OCSP stapling).

- -
-
-status_verbose
-
- -

Enables certificate status request support (aka OCSP stapling) and gives a verbose printout of the OCSP response. Use the -cert_chain option to specify the certificate of the server's certificate signer that is required for certificate status requests.

- -
-
-status_timeout int
-
- -

Sets the timeout for OCSP response to int seconds.

- -
-
-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]
-
- -

The HTTP(S) proxy server to use for reaching the OCSP server unless -no_proxy applies, see below. If the host string is an IPv6 address, it must be enclosed in [ and ]. The proxy port defaults to 80 or 443 if the scheme is https; apart from that the optional http:// or https:// prefix is ignored, as well as any userinfo, path, query, and fragment components. Defaults to the environment variable http_proxy if set, else HTTP_PROXY in case no TLS is used, otherwise https_proxy if set, else HTTPS_PROXY.

- -
-
-no_proxy addresses
-
- -

List of IP addresses and/or DNS names of servers not to use an HTTP(S) proxy for, separated by commas and/or whitespace (where in the latter case the whole argument must be enclosed in "..."). Default is from the environment variable no_proxy if set, else NO_PROXY.

- -
-
-status_url val
-
- -

Sets a fallback responder URL to use if no responder URL is present in the server certificate. Without this option an error is returned if the server certificate does not contain a responder address. The optional userinfo and fragment URL components are ignored. Any given query component is handled as part of the path component.

- -
-
-status_file infile
-
- -

Overrides any OCSP responder URLs from the certificate and always provides the OCSP Response stored in the file. The file must be in DER format.

- -
-
-ssl_config val
-
- -

Configure SSL_CTX using the given configuration value.

- -
-
-trace
-
- -

Show verbose trace output of protocol messages.

- -
-
-brief
-
- -

Provide a brief summary of connection parameters instead of the normal verbose output.

- -
-
-rev
-
- -

Simple echo server that sends back received text reversed. Also sets -brief. Cannot be used in conjunction with -early_data.

- -
-
-async
-
- -

Switch on asynchronous mode. Cryptographic operations will be performed asynchronously. This will only have an effect if an asynchronous capable engine is also used via the -engine option. For test purposes the dummy async engine (dasync) can be used (if available).

- -
-
-max_send_frag +int
-
- -

The maximum size of data fragment to send. See SSL_CTX_set_max_send_fragment(3) for further information.

- -
-
-split_send_frag +int
-
- -

The size used to split data for encrypt pipelines. If more data is written in one go than this value then it will be split into multiple pipelines, up to the maximum number of pipelines defined by max_pipelines. This only has an effect if a suitable cipher suite has been negotiated, an engine that supports pipelining has been loaded, and max_pipelines is greater than 1. See SSL_CTX_set_split_send_fragment(3) for further information.

- -
-
-max_pipelines +int
-
- -

The maximum number of encrypt/decrypt pipelines to be used. This will only have an effect if an engine has been loaded that supports pipelining (e.g. the dasync engine) and a suitable cipher suite has been negotiated. The default value is 1. See SSL_CTX_set_max_pipelines(3) for further information.

- -
-
-naccept +int
-
- -

The server will exit after receiving the specified number of connections, default unlimited.

- -
-
-read_buf +int
-
- -

The default read buffer size to be used for connections. This will only have an effect if the buffer size is larger than the size that would otherwise be used and pipelining is in use (see SSL_CTX_set_default_read_buffer_len(3) for further information).

- -
-
-bugs
-
- -

There are several known bugs in SSL and TLS implementations. Adding this option enables various workarounds.

- -
-
-no_tx_cert_comp
-
- -

Disables support for sending TLSv1.3 compressed certificates.

- -
-
-no_rx_cert_comp
-
- -

Disables support for receiving TLSv1.3 compressed certificates.

- -
-
-no_comp
-
- -

Disable negotiation of TLS compression. TLS compression is not recommended and is off by default as of OpenSSL 1.1.0.

- -
-
-comp
-
- -

Enables support for SSL/TLS compression. This option was introduced in OpenSSL 1.1.0. TLS compression is not recommended and is off by default as of OpenSSL 1.1.0. TLS compression can only be used in security level 1 or lower. From OpenSSL 3.2.0 and above the default security level is 2, so this option will have no effect without also changing the security level. Use the -cipher option to change the security level. See openssl-ciphers(1) for more information.

- -
-
-no_ticket
-
- -

Disable RFC4507bis session ticket support. This option has no effect if TLSv1.3 is negotiated. See -num_tickets.

- -
-
-num_tickets
-
- -

Control the number of tickets that will be sent to the client after a full handshake in TLSv1.3. The default number of tickets is 2. This option does not affect the number of tickets sent after a resumption handshake.

- -
-
-serverpref
-
- -

Use the server's cipher preferences, rather than the client's preferences.

- -
-
-prioritize_chacha
-
- -

Prioritize ChaCha ciphers when preferred by clients. Requires -serverpref.

- -
-
-no_resumption_on_reneg
-
- -

Set the SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION option.

- -
-
-client_sigalgs val
-
- -

Signature algorithms to support for client certificate authentication (colon-separated list).

- -
-
-named_curve val
-
- -

Specifies the elliptic curve to use. NOTE: this is single curve, not a list.

- -

The list of all supported groups includes named EC parameters as well as X25519 and X448 or FFDHE groups, and may also include groups implemented in 3rd-party providers. For a list of named EC parameters, use:

- -
$ openssl ecparam -list_curves
- -
-
-cipher val
-
- -

This allows the list of TLSv1.2 and below ciphersuites used by the server to be modified. This list is combined with any TLSv1.3 ciphersuites that have been configured. When the client sends a list of supported ciphers the first client cipher also included in the server list is used. Because the client specifies the preference order, the order of the server cipherlist is irrelevant. See openssl-ciphers(1) for more information.

- -
-
-ciphersuites val
-
- -

This allows the list of TLSv1.3 ciphersuites used by the server to be modified. This list is combined with any TLSv1.2 and below ciphersuites that have been configured. When the client sends a list of supported ciphers the first client cipher also included in the server list is used. Because the client specifies the preference order, the order of the server cipherlist is irrelevant. See openssl-ciphers(1) command for more information. The format for this list is a simple colon (":") separated list of TLSv1.3 ciphersuite names.

- -
-
-dhparam infile
-
- -

The DH parameter file to use. The ephemeral DH cipher suites generate keys using a set of DH parameters. If not specified then an attempt is made to load the parameters from the server certificate file. If this fails then a static set of parameters hard coded into this command will be used.

- -
-
-nbio
-
- -

Turns on non blocking I/O.

- -
-
-timeout
-
- -

Enable timeouts.

- -
-
-mtu
-
- -

Set link-layer MTU.

- -
-
-psk_identity val
-
- -

Expect the client to send PSK identity val when using a PSK cipher suite, and warn if they do not. By default, the expected PSK identity is the string "Client_identity".

- -
-
-psk_hint val
-
- -

Use the PSK identity hint val when using a PSK cipher suite.

- -
-
-psk val
-
- -

Use the PSK key val when using a PSK cipher suite. The key is given as a hexadecimal number without leading 0x, for example -psk 1a2b3c4d. This option must be provided in order to use a PSK cipher.

- -
-
-psk_session file
-
- -

Use the pem encoded SSL_SESSION data stored in file as the basis of a PSK. Note that this will only work if TLSv1.3 is negotiated.

- -
-
-srpvfile
-
- -

The verifier file for SRP. This option is deprecated.

- -
-
-srpuserseed
-
- -

A seed string for a default user salt. This option is deprecated.

- -
-
-listen
-
- -

This option can only be used in conjunction with one of the DTLS options above. With this option, this command will listen on a UDP port for incoming connections. Any ClientHellos that arrive will be checked to see if they have a cookie in them or not. Any without a cookie will be responded to with a HelloVerifyRequest. If a ClientHello with a cookie is received then this command will connect to that peer and complete the handshake.

- -
-
-sctp
-
- -

Use SCTP for the transport protocol instead of UDP in DTLS. Must be used in conjunction with -dtls, -dtls1 or -dtls1_2. This option is only available where OpenSSL has support for SCTP enabled.

- -
-
-sctp_label_bug
-
- -

Use the incorrect behaviour of older OpenSSL implementations when computing endpoint-pair shared secrets for DTLS/SCTP. This allows communication with older broken implementations but breaks interoperability with correct implementations. Must be used in conjunction with -sctp. This option is only available where OpenSSL has support for SCTP enabled.

- -
-
-use_srtp
-
- -

Offer SRTP key management with a colon-separated profile list.

- -
-
-no_dhe
-
- -

If this option is set then no DH parameters will be loaded effectively disabling the ephemeral DH cipher suites.

- -
-
-alpn val, -nextprotoneg val
-
- -

These flags enable the Application-Layer Protocol Negotiation or Next Protocol Negotiation (NPN) extension, respectively. ALPN is the IETF standard and replaces NPN. The val list is a comma-separated list of supported protocol names. The list should contain the most desirable protocols first. Protocol names are printable ASCII strings, for example "http/1.1" or "spdy/3". The flag -nextprotoneg cannot be specified if -tls1_3 is used.

- -
-
-ktls
-
- -

Enable Kernel TLS for sending and receiving. This option was introduced in OpenSSL 3.2.0. Kernel TLS is off by default as of OpenSSL 3.2.0.

- -
-
-sendfile
-
- -

If this option is set and KTLS is enabled, SSL_sendfile() will be used instead of BIO_write() to send the HTTP response requested by a client. This option is only valid when -ktls along with -WWW or -HTTP are specified.

- -
-
-zerocopy_sendfile
-
- -

If this option is set, SSL_sendfile() will use the zerocopy TX mode, which gives a performance boost when used with KTLS hardware offload. Note that invalid TLS records might be transmitted if the file is changed while being sent. This option depends on -sendfile; when used alone, -sendfile is implied, and a warning is shown. Note that KTLS sendfile on FreeBSD always runs in the zerocopy mode.

- -
-
-keylogfile outfile
-
- -

Appends TLS secrets to the specified keylog file such that external programs (like Wireshark) can decrypt TLS connections.

- -
-
-max_early_data int
-
- -

Change the default maximum early data bytes that are specified for new sessions and any incoming early data (when used in conjunction with the -early_data flag). The default value is approximately 16k. The argument must be an integer greater than or equal to 0.

- -
-
-recv_max_early_data int
-
- -

Specify the hard limit on the maximum number of early data bytes that will be accepted.

- -
-
-early_data
-
- -

Accept early data where possible. Cannot be used in conjunction with -www, -WWW, -HTTP or -rev.

- -
-
-stateless
-
- -

Require TLSv1.3 cookies.

- -
-
-anti_replay, -no_anti_replay
-
- -

Switches replay protection on or off, respectively. Replay protection is on by default unless overridden by a configuration file. When it is on, OpenSSL will automatically detect if a session ticket has been used more than once, TLSv1.3 has been negotiated, and early data is enabled on the server. A full handshake is forced if a session ticket is used a second or subsequent time. Any early data that was sent will be rejected.

- -
-
-tfo
-
- -

Enable acceptance of TCP Fast Open (RFC7413) connections.

- -
-
-cert_comp
-
- -

Pre-compresses certificates (RFC8879) that will be sent during the handshake.

- -
-
-nameopt option
-
- -

This specifies how the subject or issuer names are displayed. See openssl-namedisplay-options(1) for details.

- -
-
-no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3, -ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3
-
- -

See "TLS Version Options" in openssl(1).

- -
-
-dtls, -dtls1, -dtls1_2
-
- -

These specify the use of DTLS instead of TLS. See "TLS Version Options" in openssl(1).

- -
-
-bugs, -comp, -no_comp, -no_ticket, -serverpref, -client_renegotiation, -legacy_renegotiation, -no_renegotiation, -no_resumption_on_reneg, -legacy_server_connect, -no_legacy_server_connect, -no_etm -allow_no_dhe_kex, -prefer_no_dhe_kex, -prioritize_chacha, -strict, -sigalgs algs, -client_sigalgs algs, -groups groups, -curves curves, -named_curve curve, -cipher ciphers, -ciphersuites 1.3ciphers, -min_protocol minprot, -max_protocol maxprot, -record_padding padding, -debug_broken_protocol, -no_middlebox
-
- -

See "SUPPORTED COMMAND LINE COMMANDS" in SSL_CONF_cmd(3) for details.

- -
-
-xkey infile, -xcert file, -xchain file, -xchain_build file, -xcertform DER|PEM, -xkeyform DER|PEM
-
- -

Set extended certificate verification options. See "Extended Verification Options" in openssl-verification-options(1) for details.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -

If the server requests a client certificate, then verification errors are displayed, for debugging, but the command will proceed unless the -verify_return_error option is used.

- -
-
-enable_server_rpk
-
- -

Enable support for sending raw public keys (RFC7250) to the client. A raw public key will be sent by the server, if solicited by the client, provided a suitable key and public certificate pair is configured. Clients that don't support raw public keys or prefer to use X.509 certificates can still elect to receive X.509 certificates as usual.

- -

Raw public keys are extracted from the configured certificate/private key.

- -
-
-enable_client_rpk
-
- -

Enable support for receiving raw public keys (RFC7250) from the client. Use of X.509 certificates by the client becomes optional, and clients that support raw public keys may elect to use them. Clients that don't support raw public keys or prefer to use X.509 certificates can still elect to send X.509 certificates as usual.

- -

Raw public keys are extracted from the configured certificate/private key.

- -
-
- -

CONNECTED COMMANDS

- -

If a connection request is established with an SSL client and neither the -www nor the -WWW option has been used then normally any data received from the client is displayed and any key presses will be sent to the client.

- -

Certain commands are also recognized which perform special operations. These commands are a letter which must appear at the start of a line. They are listed below.

- -
- -
q
-
- -

End the current SSL connection but still accept new connections.

- -
-
Q
-
- -

End the current SSL connection and exit.

- -
-
r
-
- -

Renegotiate the SSL session (TLSv1.2 and below only).

- -
-
R
-
- -

Renegotiate the SSL session and request a client certificate (TLSv1.2 and below only).

- -
-
P
-
- -

Send some plain text down the underlying TCP connection: this should cause the client to disconnect due to a protocol violation.

- -
-
S
-
- -

Print out some session cache status information.

- -
-
k
-
- -

Send a key update message to the client (TLSv1.3 only)

- -
-
K
-
- -

Send a key update message to the client and request one back (TLSv1.3 only)

- -
-
c
-
- -

Send a certificate request to the client (TLSv1.3 only)

- -
-
- -

NOTES

- -

This command can be used to debug SSL clients. To accept connections from a web browser the command:

- -
openssl s_server -accept 443 -www
- -

can be used for example.

- -

Although specifying an empty list of CAs when requesting a client certificate is strictly speaking a protocol violation, some SSL clients interpret this to mean any CA is acceptable. This is useful for debugging purposes.

- -

The session parameters can printed out using the openssl-sess_id(1) command.

- -

BUGS

- -

Because this program has a lot of options and also because some of the techniques used are rather old, the C source for this command is rather hard to read and not a model of how things should be done. A typical SSL server program would be much simpler.

- -

The output of common ciphers is wrong: it just gives the list of ciphers that OpenSSL recognizes and the client supports.

- -

There should be a way for this command to print out details of any unknown cipher suites a client says it supports.

- -

SEE ALSO

- -

openssl(1), openssl-sess_id(1), openssl-s_client(1), openssl-ciphers(1), SSL_CONF_cmd(3), SSL_CTX_set_max_send_fragment(3), SSL_CTX_set_split_send_fragment(3), SSL_CTX_set_max_pipelines(3), ossl_store-file(7)

- -

HISTORY

- -

The -no_alt_chains option was added in OpenSSL 1.1.0.

- -

The -allow-no-dhe-kex and -prioritize_chacha options were added in OpenSSL 1.1.1.

- -

The -srpvfile, -srpuserseed, and -engine option were deprecated in OpenSSL 3.0.

- -

The -enable_client_rpk, -enable_server_rpk, -no_rx_cert_comp, -no_tx_cert_comp, and -tfo options were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-s_time.html b/openssl-install/share/doc/openssl/html/man1/openssl-s_time.html deleted file mode 100644 index af9156f3..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-s_time.html +++ /dev/null @@ -1,193 +0,0 @@ - - - - -openssl-s_time - - - - - - - - - - -

NAME

- -

openssl-s_time - SSL/TLS performance timing program

- -

SYNOPSIS

- -

openssl s_time [-help] [-connect host:port] [-www page] [-cert filename] [-key filename] [-reuse] [-new] [-verify depth] [-time seconds] [-ssl3] [-tls1] [-tls1_1] [-tls1_2] [-tls1_3] [-bugs] [-cipher cipherlist] [-ciphersuites val] [-nameopt option] [-cafile file] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command implements a generic SSL/TLS client which connects to a remote host using SSL/TLS. It can request a page from the server and includes the time to transfer the payload data in its timing measurements. It measures the number of connections within a given timeframe, the amount of data transferred (if any), and calculates the average time spent for one connection.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-connect host:port
-
- -

This specifies the host and optional port to connect to. If the host string is an IPv6 address, it must be enclosed in [ and ].

- -
-
-www page
-
- -

This specifies the page to GET from the server. A value of '/' gets the index.html page. If this parameter is not specified, then this command will only perform the handshake to establish SSL connections but not transfer any payload data.

- -
-
-cert certname
-
- -

The certificate to use, if one is requested by the server. The default is not to use a certificate. The file is in PEM format.

- -
-
-key keyfile
-
- -

The private key to use. If not specified then the certificate file will be used. The file is in PEM format.

- -
-
-verify depth
-
- -

The verify depth to use. This specifies the maximum length of the server certificate chain and turns on server certificate verification. Currently the verify operation continues after errors so all the problems with a certificate chain can be seen. As a side effect the connection will never fail due to a server certificate verify failure.

- -
-
-new
-
- -

Performs the timing test using a new session ID for each connection. If neither -new nor -reuse are specified, they are both on by default and executed in sequence.

- -
-
-reuse
-
- -

Performs the timing test using the same session ID; this can be used as a test that session caching is working. If neither -new nor -reuse are specified, they are both on by default and executed in sequence.

- -
-
-bugs
-
- -

There are several known bugs in SSL and TLS implementations. Adding this option enables various workarounds.

- -
-
-cipher cipherlist
-
- -

This allows the TLSv1.2 and below cipher list sent by the client to be modified. This list will be combined with any TLSv1.3 ciphersuites that have been configured. Although the server determines which cipher suite is used it should take the first supported cipher in the list sent by the client. See openssl-ciphers(1) for more information.

- -
-
-ciphersuites val
-
- -

This allows the TLSv1.3 ciphersuites sent by the client to be modified. This list will be combined with any TLSv1.2 and below ciphersuites that have been configured. Although the server determines which cipher suite is used it should take the first supported cipher in the list sent by the client. See openssl-ciphers(1) for more information. The format for this list is a simple colon (":") separated list of TLSv1.3 ciphersuite names.

- -
-
-time length
-
- -

Specifies how long (in seconds) this command should establish connections and optionally transfer payload data from a server. Server and client performance and the link speed determine how many connections it can establish.

- -
-
-nameopt option
-
- -

This specifies how the subject or issuer names are displayed. See openssl-namedisplay-options(1) for details.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-cafile file
-
- -

This is an obsolete synonym for -CAfile.

- -
-
-ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3
-
- -

See "TLS Version Options" in openssl(1).

- -
-
- -

NOTES

- -

This command can be used to measure the performance of an SSL connection. To connect to an SSL HTTP server and get the default page the command

- -
openssl s_time -connect servername:443 -www / -CApath yourdir -CAfile yourfile.pem -cipher commoncipher [-ssl3]
- -

would typically be used (https uses port 443). commoncipher is a cipher to which both client and server can agree, see the openssl-ciphers(1) command for details.

- -

If the handshake fails then there are several possible causes, if it is nothing obvious like no client certificate then the -bugs and -ssl3 options can be tried in case it is a buggy server. In particular you should play with these options before submitting a bug report to an OpenSSL mailing list.

- -

A frequent problem when attempting to get client certificates working is that a web client complains it has no certificates or gives an empty list to choose from. This is normally because the server is not sending the clients certificate authority in its "acceptable CA list" when it requests a certificate. By using openssl-s_client(1) the CA list can be viewed and checked. However, some servers only request client authentication after a specific URL is requested. To obtain the list in this case it is necessary to use the -prexit option of openssl-s_client(1) and send an HTTP request for an appropriate page.

- -

If a certificate is specified on the command line using the -cert option it will not be used unless the server specifically requests a client certificate. Therefore, merely including a client certificate on the command line is no guarantee that the certificate works.

- -

BUGS

- -

Because this program does not have all the options of the openssl-s_client(1) program to turn protocols on and off, you may not be able to measure the performance of all protocols with all servers.

- -

The -verify option should really exit if the server verification fails.

- -

HISTORY

- -

The -cafile option was deprecated in OpenSSL 3.0.

- -

SEE ALSO

- -

openssl(1), openssl-s_client(1), openssl-s_server(1), openssl-ciphers(1), ossl_store-file(7)

- -

COPYRIGHT

- -

Copyright 2004-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-sess_id.html b/openssl-install/share/doc/openssl/html/man1/openssl-sess_id.html deleted file mode 100644 index a1d1e779..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-sess_id.html +++ /dev/null @@ -1,188 +0,0 @@ - - - - -openssl-sess_id - - - - - - - - - - -

NAME

- -

openssl-sess_id - SSL/TLS session handling command

- -

SYNOPSIS

- -

openssl sess_id [-help] [-inform DER|PEM] [-outform DER|PEM|NSS] [-in filename] [-out filename] [-text] [-cert] [-noout] [-context ID]

- -

DESCRIPTION

- -

This command processes the encoded version of the SSL session structure and optionally prints out SSL session details (for example the SSL session master key) in human readable format. Since this is a diagnostic tool that needs some knowledge of the SSL protocol to use properly, most users will not need to use it.

- -

The precise format of the data can vary across OpenSSL versions and is not documented.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-inform DER|PEM, -outform DER|PEM|NSS
-
- -

The input and output formats; the default is PEM. See openssl-format-options(1) for details.

- -

For NSS output, the session ID and master key are reported in NSS "keylog" format.

- -
-
-in filename
-
- -

This specifies the input filename to read session information from or standard input by default.

- -
-
-out filename
-
- -

This specifies the output filename to write session information to or standard output if this option is not specified.

- -
-
-text
-
- -

Prints out the various public or private key components in plain text in addition to the encoded version.

- -
-
-cert
-
- -

If a certificate is present in the session it will be output using this option, if the -text option is also present then it will be printed out in text form.

- -
-
-noout
-
- -

This option prevents output of the encoded version of the session.

- -
-
-context ID
-
- -

This option can set the session id so the output session information uses the supplied ID. The ID can be any string of characters. This option won't normally be used.

- -
-
- -

OUTPUT

- -

Typical output:

- -
SSL-Session:
-    Protocol  : TLSv1
-    Cipher    : 0016
-    Session-ID: 871E62626C554CE95488823752CBD5F3673A3EF3DCE9C67BD916C809914B40ED
-    Session-ID-ctx: 01000000
-    Master-Key: A7CEFC571974BE02CAC305269DC59F76EA9F0B180CB6642697A68251F2D2BB57E51DBBB4C7885573192AE9AEE220FACD
-    Key-Arg   : None
-    Start Time: 948459261
-    Timeout   : 300 (sec)
-    Verify return code 0 (ok)
- -

These are described below in more detail.

- -
- -
Protocol
-
- -

This is the protocol in use TLSv1.3, TLSv1.2, TLSv1.1, TLSv1 or SSLv3.

- -
-
Cipher
-
- -

The cipher used this is the actual raw SSL or TLS cipher code, see the SSL or TLS specifications for more information.

- -
-
Session-ID
-
- -

The SSL session ID in hex format.

- -
-
Session-ID-ctx
-
- -

The session ID context in hex format.

- -
-
Master-Key
-
- -

This is the SSL session master key.

- -
-
Start Time
-
- -

This is the session start time represented as an integer in standard Unix format.

- -
-
Timeout
-
- -

The timeout in seconds.

- -
-
Verify return code
-
- -

This is the return code when an SSL client certificate is verified.

- -
-
- -

NOTES

- -

Since the SSL session output contains the master key it is possible to read the contents of an encrypted session using this information. Therefore, appropriate security precautions should be taken if the information is being output by a "real" application. This is however strongly discouraged and should only be used for debugging purposes.

- -

BUGS

- -

The cipher and start time should be printed out in human readable form.

- -

SEE ALSO

- -

openssl(1), openssl-ciphers(1), openssl-s_server(1)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-smime.html b/openssl-install/share/doc/openssl/html/man1/openssl-smime.html deleted file mode 100644 index d227467c..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-smime.html +++ /dev/null @@ -1,479 +0,0 @@ - - - - -openssl-smime - - - - - - - - - - -

NAME

- -

openssl-smime - S/MIME command

- -

SYNOPSIS

- -

openssl smime [-help] [-encrypt] [-decrypt] [-sign] [-resign] [-verify] [-pk7out] [-binary] [-crlfeol] [-cipher] [-in file] [-certfile file] [-signer file] [-nointern] [-noverify] [-nochain] [-nosigs] [-nocerts] [-noattr] [-nodetach] [-nosmimecap] [-recip file] [-inform DER|PEM|SMIME] [-outform DER|PEM|SMIME] [-keyform DER|PEM|P12|ENGINE] [-passin arg] [-inkey filename|uri] [-out file] [-content file] [-to addr] [-from ad] [-subject s] [-text] [-indef] [-noindef] [-stream] [-md digest] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-engine id] [-rand files] [-writerand file] [-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks] [-provider name] [-provider-path path] [-propquery propq] [-config configfile] recipcert ...

- -

DESCRIPTION

- -

This command handles S/MIME mail. It can encrypt, decrypt, sign and verify S/MIME messages.

- -

OPTIONS

- -

There are six operation options that set the type of operation to be performed: -encrypt, -decrypt, -sign, -resign, -verify, and -pk7out. These are mutually exclusive. The meaning of the other options varies according to the operation type.

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-encrypt
-
- -

Encrypt mail for the given recipient certificates. Input file is the message to be encrypted. The output file is the encrypted mail in MIME format.

- -

Note that no revocation check is done for the recipient cert, so if that key has been compromised, others may be able to decrypt the text.

- -
-
-decrypt
-
- -

Decrypt mail using the supplied certificate and private key. Expects an encrypted mail message in MIME format for the input file. The decrypted mail is written to the output file.

- -
-
-sign
-
- -

Sign mail using the supplied certificate and private key. Input file is the message to be signed. The signed message in MIME format is written to the output file.

- -
-
-resign
-
- -

Resign a message: take an existing message and one or more new signers.

- -
-
-verify
-
- -

Verify signed mail. Expects a signed mail message on input and outputs the signed data. Both clear text and opaque signing is supported.

- -
-
-pk7out
-
- -

Takes an input message and writes out a PEM encoded PKCS#7 structure.

- -
-
-in filename
-
- -

The input message to be encrypted or signed or the MIME message to be decrypted or verified.

- -
-
-out filename
-
- -

The message text that has been decrypted or verified or the output MIME format message that has been signed or verified.

- -
-
-inform DER|PEM|SMIME
-
- -

The input format of the PKCS#7 (S/MIME) structure (if one is being read); the default is SMIME. See openssl-format-options(1) for details.

- -
-
-outform DER|PEM|SMIME
-
- -

The output format of the PKCS#7 (S/MIME) structure (if one is being written); the default is SMIME. See openssl-format-options(1) for details.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The key format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-stream, -indef, -noindef
-
- -

The -stream and -indef options are equivalent and enable streaming I/O for encoding operations. This permits single pass processing of data without the need to hold the entire contents in memory, potentially supporting very large files. Streaming is automatically set for S/MIME signing with detached data if the output format is SMIME it is currently off by default for all other operations.

- -
-
-noindef
-
- -

Disable streaming I/O where it would produce and indefinite length constructed encoding. This option currently has no effect. In future streaming will be enabled by default on all relevant operations and this option will disable it.

- -
-
-content filename
-
- -

This specifies a file containing the detached content, this is only useful with the -verify command. This is only usable if the PKCS#7 structure is using the detached signature form where the content is not included. This option will override any content if the input format is S/MIME and it uses the multipart/signed MIME content type.

- -
-
-text
-
- -

This option adds plain text (text/plain) MIME headers to the supplied message if encrypting or signing. If decrypting or verifying it strips off text headers: if the decrypted or verified message is not of MIME type text/plain then an error occurs.

- -
-
-md digest
-
- -

Digest algorithm to use when signing or resigning. If not present then the default digest algorithm for the signing key will be used (usually SHA1).

- -
-
-cipher
-
- -

The encryption algorithm to use. For example DES (56 bits) - -des, triple DES (168 bits) - -des3, EVP_get_cipherbyname() function) can also be used preceded by a dash, for example -aes-128-cbc. See openssl-enc(1) for list of ciphers supported by your version of OpenSSL.

- -

If not specified triple DES is used. Only used with -encrypt.

- -
-
-nointern
-
- -

When verifying a message normally certificates (if any) included in the message are searched for the signing certificate. With this option only the certificates specified in the -certfile option are used. The supplied certificates can still be used as untrusted CAs however.

- -
-
-noverify
-
- -

Do not verify the signers certificate of a signed message.

- -
-
-nochain
-
- -

Do not do chain verification of signers certificates; that is, do not use the certificates in the signed message as untrusted CAs.

- -
-
-nosigs
-
- -

Don't try to verify the signatures on the message.

- -
-
-nocerts
-
- -

When signing a message, the signer's certificate is normally included. With this option it is excluded. This will reduce the size of the signed message, but the verifier must have a copy of the signers certificate available locally (passed using the -certfile option for example).

- -
-
-noattr
-
- -

Normally, when a message is signed, a set of attributes are included which include the signing time and supported symmetric algorithms. With this option they are not included.

- -
-
-nodetach
-
- -

When signing a message use opaque signing. This form is more resistant to translation by mail relays but it cannot be read by mail agents that do not support S/MIME. Without this option cleartext signing with the MIME type multipart/signed is used.

- -
-
-nosmimecap
-
- -

When signing a message, do not include the SMIMECapabilities attribute.

- -
-
-binary
-
- -

Normally the input message is converted to "canonical" format which is effectively using CR and LF as end of line: as required by the S/MIME specification. When this option is present no translation occurs. This is useful when handling binary data which may not be in MIME format.

- -
-
-crlfeol
-
- -

Normally the output file uses a single LF as end of line. When this option is present CRLF is used instead.

- -
-
-certfile file
-
- -

Allows additional certificates to be specified. When signing these will be included with the message. When verifying, these will be searched for signer certificates and will be used for chain building.

- -

The input can be in PEM, DER, or PKCS#12 format.

- -
-
-signer file
-
- -

A signing certificate when signing or resigning a message, this option can be used multiple times if more than one signer is required. If a message is being verified then the signers certificates will be written to this file if the verification was successful.

- -
-
-recip file
-
- -

The recipients certificate when decrypting a message. This certificate must match one of the recipients of the message or an error occurs.

- -
-
-inkey filename|uri
-
- -

The private key to use when signing or decrypting. This must match the corresponding certificate. If this option is not specified then the private key must be included in the certificate file specified with the -recip or -signer file. When signing this option can be used multiple times to specify successive keys.

- -
-
-passin arg
-
- -

The private key password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-to, -from, -subject
-
- -

The relevant mail headers. These are included outside the signed portion of a message so they may be included manually. If signing then many S/MIME mail clients check the signers certificate's email address matches that specified in the From: address.

- -
-
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -

Any verification errors cause the command to exit.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-config configfile
-
- -

See "Configuration Option" in openssl(1).

- -
-
recipcert ...
-
- -

One or more certificates of message recipients, used when encrypting a message.

- -
-
- -

NOTES

- -

The MIME message must be sent without any blank lines between the headers and the output. Some mail programs will automatically add a blank line. Piping the mail directly to sendmail is one way to achieve the correct format.

- -

The supplied message to be signed or encrypted must include the necessary MIME headers or many S/MIME clients won't display it properly (if at all). You can use the -text option to automatically add plain text headers.

- -

A "signed and encrypted" message is one where a signed message is then encrypted. This can be produced by encrypting an already signed message: see the examples section.

- -

This version of the program only allows one signer per message but it will verify multiple signers on received messages. Some S/MIME clients choke if a message contains multiple signers. It is possible to sign messages "in parallel" by signing an already signed message.

- -

The options -encrypt and -decrypt reflect common usage in S/MIME clients. Strictly speaking these process PKCS#7 enveloped data: PKCS#7 encrypted data is used for other purposes.

- -

The -resign option uses an existing message digest when adding a new signer. This means that attributes must be present in at least one existing signer using the same message digest or this operation will fail.

- -

The -stream and -indef options enable streaming I/O support. As a result the encoding is BER using indefinite length constructed encoding and no longer DER. Streaming is supported for the -encrypt operation and the -sign operation if the content is not detached.

- -

Streaming is always used for the -sign operation with detached data but since the content is no longer part of the PKCS#7 structure the encoding remains DER.

- -

EXIT CODES

- -
- -
0
-
- -

The operation was completely successfully.

- -
-
1
-
- -

An error occurred parsing the command options.

- -
-
2
-
- -

One of the input files could not be read.

- -
-
3
-
- -

An error occurred creating the PKCS#7 file or when reading the MIME message.

- -
-
4
-
- -

An error occurred decrypting or verifying the message.

- -
-
5
-
- -

The message was verified correctly but an error occurred writing out the signers certificates.

- -
-
- -

EXAMPLES

- -

Create a cleartext signed message:

- -
openssl smime -sign -in message.txt -text -out mail.msg \
-       -signer mycert.pem
- -

Create an opaque signed message:

- -
openssl smime -sign -in message.txt -text -out mail.msg -nodetach \
-       -signer mycert.pem
- -

Create a signed message, include some additional certificates and read the private key from another file:

- -
openssl smime -sign -in in.txt -text -out mail.msg \
-       -signer mycert.pem -inkey mykey.pem -certfile mycerts.pem
- -

Create a signed message with two signers:

- -
openssl smime -sign -in message.txt -text -out mail.msg \
-       -signer mycert.pem -signer othercert.pem
- -

Send a signed message under Unix directly to sendmail, including headers:

- -
openssl smime -sign -in in.txt -text -signer mycert.pem \
-       -from steve@openssl.org -to someone@somewhere \
-       -subject "Signed message" | sendmail someone@somewhere
- -

Verify a message and extract the signer's certificate if successful:

- -
openssl smime -verify -in mail.msg -signer user.pem -out signedtext.txt
- -

Send encrypted mail using triple DES:

- -
openssl smime -encrypt -in in.txt -out mail.msg -from steve@openssl.org \
-       -to someone@somewhere -subject "Encrypted message" \
-       -des3 user.pem
- -

Sign and encrypt mail:

- -
openssl smime -sign -in ml.txt -signer my.pem -text \
-       | openssl smime -encrypt -out mail.msg \
-       -from steve@openssl.org -to someone@somewhere \
-       -subject "Signed and Encrypted message" -des3 user.pem
- -

Note: the encryption command does not include the -text option because the message being encrypted already has MIME headers.

- -

Decrypt mail:

- -
openssl smime -decrypt -in mail.msg -recip mycert.pem -inkey key.pem
- -

The output from Netscape form signing is a PKCS#7 structure with the detached signature format. You can use this program to verify the signature by line wrapping the base64 encoded structure and surrounding it with:

- -
-----BEGIN PKCS7-----
------END PKCS7-----
- -

and using the command:

- -
openssl smime -verify -inform PEM -in signature.pem -content content.txt
- -

Alternatively you can base64 decode the signature and use:

- -
openssl smime -verify -inform DER -in signature.der -content content.txt
- -

Create an encrypted message using 128 bit Camellia:

- -
openssl smime -encrypt -in plain.txt -camellia128 -out mail.msg cert.pem
- -

Add a signer to an existing message:

- -
openssl smime -resign -in mail.msg -signer newsign.pem -out mail2.msg
- -

BUGS

- -

The MIME parser isn't very clever: it seems to handle most messages that I've thrown at it but it may choke on others.

- -

The code currently will only write out the signer's certificate to a file: if the signer has a separate encryption certificate this must be manually extracted. There should be some heuristic that determines the correct encryption certificate.

- -

Ideally a database should be maintained of a certificates for each email address.

- -

The code doesn't currently take note of the permitted symmetric encryption algorithms as supplied in the SMIMECapabilities signed attribute. This means the user has to manually include the correct encryption algorithm. It should store the list of permitted ciphers in a database and only use those.

- -

No revocation checking is done on the signer's certificate.

- -

The current code can only handle S/MIME v2 messages, the more complex S/MIME v3 structures may cause parsing errors.

- -

SEE ALSO

- -

ossl_store-file(7)

- -

HISTORY

- -

The use of multiple -signer options and the -resign command were first added in OpenSSL 1.0.0

- -

The -no_alt_chains option was added in OpenSSL 1.1.0.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-speed.html b/openssl-install/share/doc/openssl/html/man1/openssl-speed.html deleted file mode 100644 index 660b7b9e..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-speed.html +++ /dev/null @@ -1,221 +0,0 @@ - - - - -openssl-speed - - - - - - - - - - -

NAME

- -

openssl-speed - test library performance

- -

SYNOPSIS

- -

openssl speed [-help] [-config filename] [-elapsed] [-evp algo] [-hmac algo] [-cmac algo] [-mb] [-aead] [-kem-algorithms] [-signature-algorithms] [-multi num] [-async_jobs num] [-misalign num] [-decrypt] [-primes num] [-seconds num] [-bytes num] [-mr] [-mlock] [-testmode] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq] [algorithm ...]

- -

DESCRIPTION

- -

This command is used to test the performance of cryptographic algorithms.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-config filename
-
- -

Specifies the configuration file to use. Optional; for a description of the default value, see "COMMAND SUMMARY" in openssl(1).

- -
-
-elapsed
-
- -

When calculating operations- or bytes-per-second, use wall-clock time instead of CPU user time as divisor. It can be useful when testing speed of hardware engines.

- -
-
-evp algo
-
- -

Use the specified cipher or message digest algorithm via the EVP interface. If algo is an AEAD cipher, then you can pass -aead to benchmark a TLS-like sequence. And if algo is a multi-buffer capable cipher, e.g. aes-128-cbc-hmac-sha1, then -mb will time multi-buffer operation.

- -

To see the algorithms supported with this option, use openssl list -digest-algorithms or openssl list -cipher-algorithms command.

- -
-
-multi num
-
- -

Run multiple operations in parallel.

- -
-
-async_jobs num
-
- -

Enable async mode and start specified number of jobs.

- -
-
-misalign num
-
- -

Misalign the buffers by the specified number of bytes.

- -
-
-hmac digest
-
- -

Time the HMAC algorithm using the specified message digest.

- -
-
-cmac cipher
-
- -

Time the CMAC algorithm using the specified cipher e.g. openssl speed -cmac aes128.

- -
-
-decrypt
-
- -

Time the decryption instead of encryption. Affects only the EVP testing.

- -
-
-mb
-
- -

Enable multi-block mode on EVP-named cipher.

- -
-
-aead
-
- -

Benchmark EVP-named AEAD cipher in TLS-like sequence.

- -
-
-kem-algorithms
-
- -

Benchmark KEM algorithms: key generation, encapsulation, decapsulation.

- -
-
-signature-algorithms
-
- -

Benchmark signature algorithms: key generation, signature, verification.

- -
-
-primes num
-
- -

Generate a num-prime RSA key and use it to run the benchmarks. This option is only effective if RSA algorithm is specified to test.

- -
-
-seconds num
-
- -

Run benchmarks for num seconds.

- -
-
-bytes num
-
- -

Run benchmarks on num-byte buffers. Affects ciphers, digests and the CSPRNG. The limit on the size of the buffer is INT_MAX - 64 bytes, which for a 32-bit int would be 2147483583 bytes.

- -
-
-mr
-
- -

Produce the summary in a mechanical, machine-readable, format.

- -
-
-mlock
-
- -

Lock memory into RAM for more deterministic measurements.

- -
-
-testmode
-
- -

Runs the speed command in testmode. Runs only 1 iteration of each algorithm test regardless of any -seconds value. In the event that any operation fails then the speed command will return with a failure result.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
algorithm ...
-
- -

If any algorithm is given, then those algorithms are tested, otherwise a pre-compiled grand selection is tested.

- -
-
- -

BUGS

- -

The algorithm can be selected only from a pre-compiled subset of things that the openssl speed command knows about. To test any additional digest or cipher algorithm supported by OpenSSL use the -evp option.

- -

There is no way to test the speed of any additional public key algorithms supported by third party providers with the openssl speed command.

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

DSA512 was removed in OpenSSL 3.2.

- -

The -testmode option was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-spkac.html b/openssl-install/share/doc/openssl/html/man1/openssl-spkac.html deleted file mode 100644 index d939cf2f..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-spkac.html +++ /dev/null @@ -1,194 +0,0 @@ - - - - -openssl-spkac - - - - - - - - - - -

NAME

- -

openssl-spkac - SPKAC printing and generating command

- -

SYNOPSIS

- -

openssl spkac [-help] [-in filename] [-out filename] [-digest digest] [-key filename|uri] [-keyform DER|PEM|P12|ENGINE] [-passin arg] [-challenge string] [-pubkey] [-spkac spkacname] [-spksect section] [-noout] [-verify] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command processes Netscape signed public key and challenge (SPKAC) files. It can print out their contents, verify the signature and produce its own SPKACs from a supplied private key.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-in filename
-
- -

This specifies the input filename to read from or standard input if this option is not specified. Ignored if the -key option is used.

- -
-
-out filename
-
- -

Specifies the output filename to write to or standard output by default.

- -
-
-digest digest
-
- -

Use the specified digest to sign a created SPKAC file. The default digest algorithm is MD5.

- -
-
-key filename|uri
-
- -

Create an SPKAC file using the private key specified by filename or uri. The -in, -noout, -spksect and -verify options are ignored if present.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The key format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-passin arg
-
- -

The input file password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-challenge string
-
- -

Specifies the challenge string if an SPKAC is being created.

- -
-
-spkac spkacname
-
- -

Allows an alternative name form the variable containing the SPKAC. The default is "SPKAC". This option affects both generated and input SPKAC files.

- -
-
-spksect section
-
- -

Allows an alternative name form the section containing the SPKAC. The default is the default section.

- -
-
-noout
-
- -

Don't output the text version of the SPKAC (not used if an SPKAC is being created).

- -
-
-pubkey
-
- -

Output the public key of an SPKAC (not used if an SPKAC is being created).

- -
-
-verify
-
- -

Verifies the digital signature on the supplied SPKAC.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

EXAMPLES

- -

Print out the contents of an SPKAC:

- -
openssl spkac -in spkac.cnf
- -

Verify the signature of an SPKAC:

- -
openssl spkac -in spkac.cnf -noout -verify
- -

Create an SPKAC using the challenge string "hello":

- -
openssl spkac -key key.pem -challenge hello -out spkac.cnf
- -

Example of an SPKAC, (long lines split up for clarity):

- -
SPKAC=MIG5MGUwXDANBgkqhkiG9w0BAQEFAANLADBIAkEA\
-1cCoq2Wa3Ixs47uI7FPVwHVIPDx5yso105Y6zpozam135a\
-8R0CpoRvkkigIyXfcCjiVi5oWk+6FfPaD03uPFoQIDAQAB\
-FgVoZWxsbzANBgkqhkiG9w0BAQQFAANBAFpQtY/FojdwkJ\
-h1bEIYuc2EeM2KHTWPEepWYeawvHD0gQ3DngSC75YCWnnD\
-dq+NQ3F+X4deMx9AaEglZtULwV4=
- -

NOTES

- -

A created SPKAC with suitable DN components appended can be fed to openssl-ca(1).

- -

SPKACs are typically generated by Netscape when a form is submitted containing the KEYGEN tag as part of the certificate enrollment process.

- -

The challenge string permits a primitive form of proof of possession of private key. By checking the SPKAC signature and a random challenge string some guarantee is given that the user knows the private key corresponding to the public key being certified. This is important in some applications. Without this it is possible for a previous SPKAC to be used in a "replay attack".

- -

SEE ALSO

- -

openssl(1), openssl-ca(1)

- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -digest option was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-srp.html b/openssl-install/share/doc/openssl/html/man1/openssl-srp.html deleted file mode 100644 index 190d75bd..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-srp.html +++ /dev/null @@ -1,158 +0,0 @@ - - - - -openssl-srp - - - - - - - - - - -

NAME

- -

openssl-srp - maintain SRP password file

- -

SYNOPSIS

- -

openssl srp [-help] [-verbose] [-add] [-modify] [-delete] [-list] [-name section] [-srpvfile file] [-gn identifier] [-userinfo text] [-passin arg] [-passout arg] [-engine id] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq] [-config configfile] [user ...]

- -

DESCRIPTION

- -

This command is deprecated. It is used to maintain an SRP (secure remote password) file. At most one of the -add, -modify, -delete, and -list options can be specified. These options take zero or more usernames as parameters and perform the appropriate operation on the SRP file. For -list, if no user is given then all users are displayed.

- -

The configuration file to use, and the section within the file, can be specified with the -config and -name flags, respectively.

- -

OPTIONS

- -
- -
-help
-
- -

Display an option summary.

- -
-
-verbose
-
- -

Generate verbose output while processing.

- -
-
-add
-
- -

Add a user and SRP verifier.

- -
-
-modify
-
- -

Modify the SRP verifier of an existing user.

- -
-
-delete
-
- -

Delete user from verifier file.

- -
-
-list
-
- -

List users.

- -
-
-name
-
- -

The particular SRP definition to use.

- -
-
-srpvfile file
-
- -

If the config file is not specified, -srpvfile can be used to specify the file to operate on.

- -
-
-gn
-
- -

Specifies the g and N values, using one of the strengths defined in IETF RFC 5054.

- -
-
-userinfo
-
- -

specifies additional information to add when adding or modifying a user.

- -
-
-passin arg, -passout arg
-
- -

The password source for the input and output file. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
-config configfile
-
- -

See "Configuration Option" in openssl(1).

- -

[-rand files] [-writerand file]

- -
-
- -

HISTORY

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-storeutl.html b/openssl-install/share/doc/openssl/html/man1/openssl-storeutl.html deleted file mode 100644 index 424137c3..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-storeutl.html +++ /dev/null @@ -1,177 +0,0 @@ - - - - -openssl-storeutl - - - - - - - - - - -

NAME

- -

openssl-storeutl - STORE command

- -

SYNOPSIS

- -

openssl storeutl [-help] [-out file] [-noout] [-passin arg] [-text arg] [-r] [-certs] [-keys] [-crls] [-subject arg] [-issuer arg] [-serial arg] [-alias arg] [-fingerprint arg] [-digest] [-engine id] [-provider name] [-provider-path path] [-propquery propq] uri

- -

DESCRIPTION

- -

This command can be used to display the contents (after decryption as the case may be) fetched from the given URI.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-out filename
-
- -

specifies the output filename to write to or standard output by default.

- -
-
-noout
-
- -

this option prevents output of the PEM data.

- -
-
-passin arg
-
- -

the key password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-text
-
- -

Prints out the objects in text form, similarly to the -text output from openssl-x509(1), openssl-pkey(1), etc.

- -
-
-r
-
- -

Fetch objects recursively when possible.

- -
-
-certs
-
- -
-
-keys
-
- -
-
-crls
-
- -

Only select the certificates, keys or CRLs from the given URI. However, if this URI would return a set of names (URIs), those are always returned.

- -

Note that all options must be given before the uri argument.

- -

Note -keys selects exclusively private keys, there is no selector for public keys only.

- -
-
-subject arg
-
- -

Search for an object having the subject name arg.

- -

The arg must be formatted as /type0=value0/type1=value1/type2=.... Special characters may be escaped by \ (backslash), whitespace is retained. Empty values are permitted but are ignored for the search. That is, a search with an empty value will have the same effect as not specifying the type at all. Giving a single / will lead to an empty sequence of RDNs (a NULL-DN). Multi-valued RDNs can be formed by placing a + character instead of a / between the AttributeValueAssertions (AVAs) that specify the members of the set.

- -

Example:

- -

/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe

- -
-
-issuer arg
-
- -
-
-serial arg
-
- -

Search for an object having the given issuer name and serial number. These two options must be used together. The issuer arg must be formatted as /type0=value0/type1=value1/type2=..., characters may be escaped by \ (backslash), no spaces are skipped. The serial arg may be specified as a decimal value or a hex value if preceded by 0x.

- -
-
-alias arg
-
- -

Search for an object having the given alias.

- -
-
-fingerprint arg
-
- -

Search for an object having the given fingerprint.

- -
-
-digest
-
- -

The digest that was used to compute the fingerprint given with -fingerprint.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

SEE ALSO

- -

openssl(1)

- -

HISTORY

- -

This command was added in OpenSSL 1.1.1.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-ts.html b/openssl-install/share/doc/openssl/html/man1/openssl-ts.html deleted file mode 100644 index c61c2485..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-ts.html +++ /dev/null @@ -1,602 +0,0 @@ - - - - -openssl-ts - - - - - - - - - - -

NAME

- -

openssl-ts - Time Stamping Authority command

- -

SYNOPSIS

- -

openssl ts -help

- -

openssl ts -query [-config configfile] [-data file_to_hash] [-digest digest_bytes] [-digest] [-tspolicy object_id] [-no_nonce] [-cert] [-in request.tsq] [-out request.tsq] [-text] [-rand files] [-writerand file] [-provider name] [-provider-path path] [-propquery propq]

- -

openssl ts -reply [-config configfile] [-section tsa_section] [-queryfile request.tsq] [-passin password_src] [-signer tsa_cert.pem] [-inkey filename|uri] [-digest] [-chain certs_file.pem] [-tspolicy object_id] [-in response.tsr] [-token_in] [-out response.tsr] [-token_out] [-text] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

openssl ts -verify [-data file_to_hash] [-digest digest_bytes] [-queryfile request.tsq] [-in response.tsr] [-token_in] [-untrusted files|uris] [-CAfile file] [-CApath dir] [-CAstore uri] [-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command is a basic Time Stamping Authority (TSA) client and server application as specified in RFC 3161 (Time-Stamp Protocol, TSP). A TSA can be part of a PKI deployment and its role is to provide long term proof of the existence of a certain datum before a particular time. Here is a brief description of the protocol:

- -
    - -
  1. The TSA client computes a one-way hash value for a data file and sends the hash to the TSA.

    - -
  2. -
  3. The TSA attaches the current date and time to the received hash value, signs them and sends the timestamp token back to the client. By creating this token the TSA certifies the existence of the original data file at the time of response generation.

    - -
  4. -
  5. The TSA client receives the timestamp token and verifies the signature on it. It also checks if the token contains the same hash value that it had sent to the TSA.

    - -
  6. -
- -

There is one DER encoded protocol data unit defined for transporting a timestamp request to the TSA and one for sending the timestamp response back to the client. This command has three main functions: creating a timestamp request based on a data file, creating a timestamp response based on a request, verifying if a response corresponds to a particular request or a data file.

- -

There is no support for sending the requests/responses automatically over HTTP or TCP yet as suggested in RFC 3161. The users must send the requests either by ftp or e-mail.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-query
-
- -

Generate a TS query. For details see "Timestamp Request generation".

- -
-
-reply
-
- -

Generate a TS reply. For details see "Timestamp Response generation".

- -
-
-verify
-
- -

Verify a TS response. For details see "Timestamp Response verification".

- -
-
- -

Timestamp Request generation

- -

The -query command can be used for creating and printing a timestamp request with the following options:

- -
- -
-config configfile
-
- -

The configuration file to use. Optional; for a description of the default value, see "COMMAND SUMMARY" in openssl(1).

- -
-
-data file_to_hash
-
- -

The data file for which the timestamp request needs to be created. stdin is the default if neither the -data nor the -digest parameter is specified. (Optional)

- -
-
-digest digest_bytes
-
- -

It is possible to specify the message imprint explicitly without the data file. The imprint must be specified in a hexadecimal format, two characters per byte, the bytes optionally separated by colons (e.g. 1A:F6:01:... or 1AF601...). The number of bytes must match the message digest algorithm in use. (Optional)

- -
-
-digest
-
- -

The message digest to apply to the data file. Any digest supported by the openssl-dgst(1) command can be used. The default is SHA-256. (Optional)

- -
-
-tspolicy object_id
-
- -

The policy that the client expects the TSA to use for creating the timestamp token. Either the dotted OID notation or OID names defined in the config file can be used. If no policy is requested the TSA will use its own default policy. (Optional)

- -
-
-no_nonce
-
- -

No nonce is specified in the request if this option is given. Otherwise, a 64-bit long pseudo-random nonce is included in the request. It is recommended to use a nonce to protect against replay attacks. (Optional)

- -
-
-cert
-
- -

The TSA is expected to include its signing certificate in the response. (Optional)

- -
-
-in request.tsq
-
- -

This option specifies a previously created timestamp request in DER format that will be printed into the output file. Useful when you need to examine the content of a request in human-readable format. (Optional)

- -
-
-out request.tsq
-
- -

Name of the output file to which the request will be written. Default is stdout. (Optional)

- -
-
-text
-
- -

If this option is specified the output is human-readable text format instead of DER. (Optional)

- -
-
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
- -

Timestamp Response generation

- -

A timestamp response (TimeStampResp) consists of a response status and the timestamp token itself (ContentInfo), if the token generation was successful. The -reply command is for creating a timestamp response or timestamp token based on a request and printing the response/token in human-readable format. If -token_out is not specified the output is always a timestamp response (TimeStampResp), otherwise it is a timestamp token (ContentInfo).

- -
- -
-config configfile
-
- -

The configuration file to use. Optional; for a description of the default value, see "COMMAND SUMMARY" in openssl(1). See "CONFIGURATION FILE OPTIONS" for configurable variables.

- -
-
-section tsa_section
-
- -

The name of the config file section containing the settings for the response generation. If not specified the default TSA section is used, see "CONFIGURATION FILE OPTIONS" for details. (Optional)

- -
-
-queryfile request.tsq
-
- -

The name of the file containing a DER encoded timestamp request. (Optional)

- -
-
-passin password_src
-
- -

Specifies the password source for the private key of the TSA. See description in openssl(1). (Optional)

- -
-
-signer tsa_cert.pem
-
- -

The signer certificate of the TSA in PEM format. The TSA signing certificate must have exactly one extended key usage assigned to it: timeStamping. The extended key usage must also be critical, otherwise the certificate is going to be refused. Overrides the signer_cert variable of the config file. (Optional)

- -
-
-inkey filename|uri
-
- -

The signer private key of the TSA in PEM format. Overrides the signer_key config file option. (Optional)

- -
-
-digest
-
- -

Signing digest to use. Overrides the signer_digest config file option. (Mandatory unless specified in the config file)

- -
-
-chain certs_file.pem
-
- -

The collection of certificates in PEM format that will all be included in the response in addition to the signer certificate if the -cert option was used for the request. This file is supposed to contain the certificate chain for the signer certificate from its issuer upwards. The -reply command does not build a certificate chain automatically. (Optional)

- -
-
-tspolicy object_id
-
- -

The default policy to use for the response unless the client explicitly requires a particular TSA policy. The OID can be specified either in dotted notation or with its name. Overrides the default_policy config file option. (Optional)

- -
-
-in response.tsr
-
- -

Specifies a previously created timestamp response or timestamp token (if -token_in is also specified) in DER format that will be written to the output file. This option does not require a request, it is useful e.g. when you need to examine the content of a response or token or you want to extract the timestamp token from a response. If the input is a token and the output is a timestamp response a default 'granted' status info is added to the token. (Optional)

- -
-
-token_in
-
- -

This flag can be used together with the -in option and indicates that the input is a DER encoded timestamp token (ContentInfo) instead of a timestamp response (TimeStampResp). (Optional)

- -
-
-out response.tsr
-
- -

The response is written to this file. The format and content of the file depends on other options (see -text, -token_out). The default is stdout. (Optional)

- -
-
-token_out
-
- -

The output is a timestamp token (ContentInfo) instead of timestamp response (TimeStampResp). (Optional)

- -
-
-text
-
- -

If this option is specified the output is human-readable text format instead of DER. (Optional)

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

Timestamp Response verification

- -

The -verify command is for verifying if a timestamp response or timestamp token is valid and matches a particular timestamp request or data file. The -verify command does not use the configuration file.

- -
- -
-data file_to_hash
-
- -

The response or token must be verified against file_to_hash. The file is hashed with the message digest algorithm specified in the token. The -digest and -queryfile options must not be specified with this one. (Optional)

- -
-
-digest digest_bytes
-
- -

The response or token must be verified against the message digest specified with this option. The number of bytes must match the message digest algorithm specified in the token. The -data and -queryfile options must not be specified with this one. (Optional)

- -
-
-queryfile request.tsq
-
- -

The original timestamp request in DER format. The -data and -digest options must not be specified with this one. (Optional)

- -
-
-in response.tsr
-
- -

The timestamp response that needs to be verified in DER format. (Mandatory)

- -
-
-token_in
-
- -

This flag can be used together with the -in option and indicates that the input is a DER encoded timestamp token (ContentInfo) instead of a timestamp response (TimeStampResp). (Optional)

- -
-
-untrusted files|uris
-
- -

A set of additional untrusted certificates which may be needed when building the certificate chain for the TSA's signing certificate. These do not need to contain the TSA signing certificate and intermediate CA certificates as far as the response already includes them. (Optional)

- -

Multiple sources may be given, separated by commas and/or whitespace. Each file may contain multiple certificates.

- -
-
-CAfile file, -CApath dir, -CAstore uri
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details. At least one of -CAfile, -CApath or -CAstore must be specified.

- -
-
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -

Any verification errors cause the command to exit.

- -
-
- -

CONFIGURATION FILE OPTIONS

- -

The -query and -reply commands make use of a configuration file. See config(5) for a general description of the syntax of the config file. The -query command uses only the symbolic OID names section and it can work without it. However, the -reply command needs the config file for its operation.

- -

When there is a command line switch equivalent of a variable the switch always overrides the settings in the config file.

- -
- -
tsa section, default_tsa
-
- -

This is the main section and it specifies the name of another section that contains all the options for the -reply command. This default section can be overridden with the -section command line switch. (Optional)

- -
-
oid_file
-
- -

This specifies a file containing additional OBJECT IDENTIFIERS. Each line of the file should consist of the numerical form of the object identifier followed by whitespace then the short name followed by whitespace and finally the long name. (Optional)

- -
-
oid_section
-
- -

This specifies a section in the configuration file containing extra object identifiers. Each line should consist of the short name of the object identifier followed by = and the numerical form. The short and long names are the same when this option is used. (Optional)

- -
-
RANDFILE
-
- -

At startup the specified file is loaded into the random number generator, and at exit 256 bytes will be written to it. (Note: Using a RANDFILE is not necessary anymore, see the "HISTORY" section.

- -
-
serial
-
- -

The name of the file containing the hexadecimal serial number of the last timestamp response created. This number is incremented by 1 for each response. If the file does not exist at the time of response generation a new file is created with serial number 1. (Mandatory)

- -
-
crypto_device
-
- -

Specifies the OpenSSL engine that will be set as the default for all available algorithms. The default value is built-in, you can specify any other engines supported by OpenSSL (e.g. use chil for the NCipher HSM). (Optional)

- -
-
signer_cert
-
- -

TSA signing certificate in PEM format. The same as the -signer command line option. (Optional)

- -
-
certs
-
- -

A file containing a set of PEM encoded certificates that need to be included in the response. The same as the -chain command line option. (Optional)

- -
-
signer_key
-
- -

The private key of the TSA in PEM format. The same as the -inkey command line option. (Optional)

- -
-
signer_digest
-
- -

Signing digest to use. The same as the -digest command line option. (Mandatory unless specified on the command line)

- -
-
default_policy
-
- -

The default policy to use when the request does not mandate any policy. The same as the -tspolicy command line option. (Optional)

- -
-
other_policies
-
- -

Comma separated list of policies that are also acceptable by the TSA and used only if the request explicitly specifies one of them. (Optional)

- -
-
digests
-
- -

The list of message digest algorithms that the TSA accepts. At least one algorithm must be specified. (Mandatory)

- -
-
accuracy
-
- -

The accuracy of the time source of the TSA in seconds, milliseconds and microseconds. E.g. secs:1, millisecs:500, microsecs:100. If any of the components is missing zero is assumed for that field. (Optional)

- -
-
clock_precision_digits
-
- -

Specifies the maximum number of digits, which represent the fraction of seconds, that need to be included in the time field. The trailing zeros must be removed from the time, so there might actually be fewer digits, or no fraction of seconds at all. Supported only on UNIX platforms. The maximum value is 6, default is 0. (Optional)

- -
-
ordering
-
- -

If this option is yes the responses generated by this TSA can always be ordered, even if the time difference between two responses is less than the sum of their accuracies. Default is no. (Optional)

- -
-
tsa_name
-
- -

Set this option to yes if the subject name of the TSA must be included in the TSA name field of the response. Default is no. (Optional)

- -
-
ess_cert_id_chain
-
- -

The SignedData objects created by the TSA always contain the certificate identifier of the signing certificate in a signed attribute (see RFC 2634, Enhanced Security Services). If this variable is set to no, only this signing certificate identifier is included in the SigningCertificate signed attribute. If this variable is set to yes and the certs variable or the -chain option is specified then the certificate identifiers of the chain will also be included, where the -chain option overrides the certs variable. Default is no. (Optional)

- -
-
ess_cert_id_alg
-
- -

This option specifies the hash function to be used to calculate the TSA's public key certificate identifier. Default is sha256. (Optional)

- -
-
- -

EXAMPLES

- -

All the examples below presume that OPENSSL_CONF is set to a proper configuration file, e.g. the example configuration file openssl/apps/openssl.cnf will do.

- -

Timestamp Request

- -

To create a timestamp request for design1.txt with SHA-256 digest, without nonce and policy, and without requirement for a certificate in the response:

- -
openssl ts -query -data design1.txt -no_nonce \
-      -out design1.tsq
- -

To create a similar timestamp request with specifying the message imprint explicitly:

- -
openssl ts -query -digest b7e5d3f93198b38379852f2c04e78d73abdd0f4b \
-       -no_nonce -out design1.tsq
- -

To print the content of the previous request in human readable format:

- -
openssl ts -query -in design1.tsq -text
- -

To create a timestamp request which includes the SHA-512 digest of design2.txt, requests the signer certificate and nonce, and specifies a policy id (assuming the tsa_policy1 name is defined in the OID section of the config file):

- -
openssl ts -query -data design2.txt -sha512 \
-      -tspolicy tsa_policy1 -cert -out design2.tsq
- -

Timestamp Response

- -

Before generating a response a signing certificate must be created for the TSA that contains the timeStamping critical extended key usage extension without any other key usage extensions. You can add this line to the user certificate section of the config file to generate a proper certificate;

- -
extendedKeyUsage = critical,timeStamping
- -

See openssl-req(1), openssl-ca(1), and openssl-x509(1) for instructions. The examples below assume that cacert.pem contains the certificate of the CA, tsacert.pem is the signing certificate issued by cacert.pem and tsakey.pem is the private key of the TSA.

- -

To create a timestamp response for a request:

- -
openssl ts -reply -queryfile design1.tsq -inkey tsakey.pem \
-      -signer tsacert.pem -out design1.tsr
- -

If you want to use the settings in the config file you could just write:

- -
openssl ts -reply -queryfile design1.tsq -out design1.tsr
- -

To print a timestamp reply to stdout in human readable format:

- -
openssl ts -reply -in design1.tsr -text
- -

To create a timestamp token instead of timestamp response:

- -
openssl ts -reply -queryfile design1.tsq -out design1_token.der -token_out
- -

To print a timestamp token to stdout in human readable format:

- -
openssl ts -reply -in design1_token.der -token_in -text -token_out
- -

To extract the timestamp token from a response:

- -
openssl ts -reply -in design1.tsr -out design1_token.der -token_out
- -

To add 'granted' status info to a timestamp token thereby creating a valid response:

- -
openssl ts -reply -in design1_token.der -token_in -out design1.tsr
- -

Timestamp Verification

- -

To verify a timestamp reply against a request:

- -
openssl ts -verify -queryfile design1.tsq -in design1.tsr \
-      -CAfile cacert.pem -untrusted tsacert.pem
- -

To verify a timestamp reply that includes the certificate chain:

- -
openssl ts -verify -queryfile design2.tsq -in design2.tsr \
-      -CAfile cacert.pem
- -

To verify a timestamp token against the original data file:

- -
openssl ts -verify -data design2.txt -in design2.tsr \
-      -CAfile cacert.pem
- -

To verify a timestamp token against a message imprint:

- -
openssl ts -verify -digest b7e5d3f93198b38379852f2c04e78d73abdd0f4b \
-       -in design2.tsr -CAfile cacert.pem
- -

You could also look at the 'test' directory for more examples.

- -

BUGS

- - - -

HISTORY

- -

OpenSSL 1.1.1 introduced a new random generator (CSPRNG) with an improved seeding mechanism. The new seeding mechanism makes it unnecessary to define a RANDFILE for saving and restoring randomness. This option is retained mainly for compatibility reasons.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

SEE ALSO

- -

openssl(1), tsget(1), openssl-req(1), openssl-x509(1), openssl-ca(1), openssl-genrsa(1), config(5), ossl_store-file(7)

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-verification-options.html b/openssl-install/share/doc/openssl/html/man1/openssl-verification-options.html deleted file mode 100644 index f5779e98..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-verification-options.html +++ /dev/null @@ -1,589 +0,0 @@ - - - - -openssl-verification-options - - - - - - - - - - -

NAME

- -

openssl-verification-options - generic X.509 certificate verification options

- -

SYNOPSIS

- -

openssl command [ options ... ] [ parameters ... ]

- -

DESCRIPTION

- -

There are many situations where X.509 certificates are verified within the OpenSSL libraries and in various OpenSSL commands.

- -

Certificate verification is implemented by X509_verify_cert(3). It is a complicated process consisting of a number of steps and depending on numerous options. The most important of them are detailed in the following sections.

- -

In a nutshell, a valid chain of certificates needs to be built up and verified starting from the target certificate that is to be verified and ending in a certificate that due to some policy is trusted. Certificate validation can be performed in the context of a purpose, which is a high-level specification of the intended use of the target certificate, such as sslserver for TLS servers, or (by default) for any purpose.

- -

The details of how each OpenSSL command handles errors are documented on the specific command page.

- -

DANE support is documented in openssl-s_client(1), SSL_CTX_dane_enable(3), SSL_set1_host(3), X509_VERIFY_PARAM_set_flags(3), and X509_check_host(3).

- -

Trust Anchors

- -

In general, according to RFC 4158 and RFC 5280, a trust anchor is any public key and related subject distinguished name (DN) that for some reason is considered trusted and thus is acceptable as the root of a chain of certificates.

- -

In practice, trust anchors are given in the form of certificates, where their essential fields are the public key and the subject DN. In addition to the requirements in RFC 5280, OpenSSL checks the validity period of such certificates and makes use of some further fields. In particular, the subject key identifier extension, if present, is used for matching trust anchors during chain building.

- -

In the most simple and common case, trust anchors are by default all self-signed "root" CA certificates that are placed in the trust store, which is a collection of certificates that are trusted for certain uses. This is akin to what is used in the trust stores of Mozilla Firefox, or Apple's and Microsoft's certificate stores, ...

- -

From the OpenSSL perspective, a trust anchor is a certificate that should be augmented with an explicit designation for which uses of a target certificate the certificate may serve as a trust anchor. In PEM encoding, this is indicated by the TRUSTED CERTIFICATE string. Such a designation provides a set of positive trust attributes explicitly stating trust for the listed purposes and/or a set of negative trust attributes explicitly rejecting the use for the listed purposes. The purposes are encoded using the values defined for the extended key usages (EKUs) that may be given in X.509 extensions of end-entity certificates. See also the "Extended Key Usage" section below.

- -

The currently recognized uses are clientAuth (SSL client use), serverAuth (SSL server use), emailProtection (S/MIME email use), codeSigning (object signer use), OCSPSigning (OCSP responder use), OCSP (OCSP request use), timeStamping (TSA server use), and anyExtendedKeyUsage. As of OpenSSL 1.1.0, the last of these blocks all uses when rejected or enables all uses when trusted.

- -

A certificate, which may be CA certificate or an end-entity certificate, is considered a trust anchor for the given use if and only if all the following conditions hold:

- - - -

Certification Path Building

- -

First, a certificate chain is built up starting from the target certificate and ending in a trust anchor.

- -

The chain is built up iteratively, looking up in turn a certificate with suitable key usage that matches as an issuer of the current "subject" certificate as described below. If there is such a certificate, the first one found that is currently valid is taken, otherwise the one that expired most recently of all such certificates. For efficiency, no backtracking is performed, thus any further candidate issuer certificates that would match equally are ignored.

- -

When a self-signed certificate has been added, chain construction stops. In this case it must fully match a trust anchor, otherwise chain building fails.

- -

A candidate issuer certificate matches a subject certificate if all of the following conditions hold:

- - - -

The lookup first searches for issuer certificates in the trust store. If it does not find a match there it consults the list of untrusted ("intermediate" CA) certificates, if provided.

- -

Certification Path Validation

- -

When the certificate chain building process was successful the chain components and their links are checked thoroughly.

- -

The first step is to check that each certificate is well-formed. Part of these checks are enabled only if the -x509_strict option is given.

- -

The second step is to check the X.509v3 extensions of every certificate for consistency with the intended specific purpose, if any. If the -purpose option is not given then no such checks are done except for CMS signature checking, where by default smimesign is checked, and SSL/(D)TLS connection setup, where by default sslserver or sslclient are checked. The X.509v3 extensions of the target or "leaf" certificate must be compatible with the specified purpose. All other certificates down the chain are checked to be valid CA certificates, and possibly also further non-standard checks are performed. The precise extensions required are described in detail in the "Certificate Extensions" section below.

- -

The third step is to check the trust settings on the last certificate (which typically is a self-signed root CA certificate). It must be trusted for the given use. For compatibility with previous versions of OpenSSL, a self-signed certificate with no trust attributes is considered to be valid for all uses.

- -

The fourth, and final, step is to check the validity of the certificate chain. For each element in the chain, including the root CA certificate, the validity period as specified by the notBefore and notAfter fields is checked against the current system time. The -attime flag may be used to use a reference time other than "now." The certificate signature is checked as well (except for the signature of the typically self-signed root CA certificate, which is verified only if the -check_ss_sig option is given). When verifying a certificate signature the keyUsage extension (if present) of the candidate issuer certificate is checked to permit digitalSignature for signing proxy certificates or to permit keyCertSign for signing other certificates, respectively. If all operations complete successfully then certificate is considered valid. If any operation fails then the certificate is not valid.

- -

OPTIONS

- -

Trusted Certificate Options

- -

The following options specify how to supply the certificates that can be used as trust anchors for certain uses. As mentioned, a collection of such certificates is called a trust store.

- -

Note that OpenSSL does not provide a default set of trust anchors. Many Linux distributions include a system default and configure OpenSSL to point to that. Mozilla maintains an influential trust store that can be found at https://www.mozilla.org/en-US/about/governance/policies/security-group/certs/.

- -

The certificates to add to the trust store can be specified using following options.

- -
- -
-CAfile file
-
- -

Load the specified file which contains a trusted certificate in DER format or potentially several of them in case the input is in PEM format. PEM-encoded certificates may also have trust attributes set.

- -
-
-no-CAfile
-
- -

Do not load the default file of trusted certificates.

- -
-
-CApath dir
-
- -

Use the specified directory as a collection of trusted certificates, i.e., a trust store. Files should be named with the hash value of the X.509 SubjectName of each certificate. This is so that the library can extract the IssuerName, hash it, and directly lookup the file to get the issuer certificate. See openssl-rehash(1) for information on creating this type of directory.

- -
-
-no-CApath
-
- -

Do not use the default directory of trusted certificates.

- -
-
-CAstore uri
-
- -

Use uri as a store of CA certificates. The URI may indicate a single certificate, as well as a collection of them. With URIs in the file: scheme, this acts as -CAfile or -CApath, depending on if the URI indicates a single file or directory. See ossl_store-file(7) for more information on the file: scheme.

- -

These certificates are also used when building the server certificate chain (for example with openssl-s_server(1)) or client certificate chain (for example with openssl-s_time(1)).

- -
-
-no-CAstore
-
- -

Do not use the default store of trusted CA certificates.

- -
-
- -

Verification Options

- -

The certificate verification can be fine-tuned with the following flags.

- -
- -
-verbose
-
- -

Print extra information about the operations being performed.

- -
-
-attime timestamp
-
- -

Perform validation checks using time specified by timestamp and not current system time. timestamp is the number of seconds since January 1, 1970 (i.e., the Unix Epoch).

- -
-
-no_check_time
-
- -

This option suppresses checking the validity period of certificates and CRLs against the current time. If option -attime is used to specify a verification time, the check is not suppressed.

- -
-
-x509_strict
-
- -

This disables non-compliant workarounds for broken certificates. Thus errors are thrown on certificates not compliant with RFC 5280.

- -

When this option is set, among others, the following certificate well-formedness conditions are checked:

- -
    - -
  • The basicConstraints of CA certificates must be marked critical.

    - -
  • -
  • CA certificates must explicitly include the keyUsage extension.

    - -
  • -
  • If a pathlenConstraint is given the key usage keyCertSign must be allowed.

    - -
  • -
  • The pathlenConstraint must not be given for non-CA certificates.

    - -
  • -
  • The issuer name of any certificate must not be empty.

    - -
  • -
  • The subject name of CA certs, certs with keyUsage crlSign, and certs without subjectAlternativeName must not be empty.

    - -
  • -
  • If a subjectAlternativeName extension is given it must not be empty.

    - -
  • -
  • The signatureAlgorithm field and the cert signature must be consistent.

    - -
  • -
  • Any given authorityKeyIdentifier and any given subjectKeyIdentifier must not be marked critical.

    - -
  • -
  • The authorityKeyIdentifier must be given for X.509v3 certs unless they are self-signed.

    - -
  • -
  • The subjectKeyIdentifier must be given for all X.509v3 CA certs.

    - -
  • -
- -
-
-ignore_critical
-
- -

Normally if an unhandled critical extension is present that is not supported by OpenSSL the certificate is rejected (as required by RFC5280). If this option is set critical extensions are ignored.

- -
-
-issuer_checks
-
- -

Ignored.

- -
-
-crl_check
-
- -

Checks end entity certificate validity by attempting to look up a valid CRL. If a valid CRL cannot be found an error occurs.

- -
-
-crl_check_all
-
- -

Checks the validity of all certificates in the chain by attempting to look up valid CRLs.

- -
-
-use_deltas
-
- -

Enable support for delta CRLs.

- -
-
-extended_crl
-
- -

Enable extended CRL features such as indirect CRLs and alternate CRL signing keys.

- -
-
-suiteB_128_only, -suiteB_128, -suiteB_192
-
- -

Enable the Suite B mode operation at 128 bit Level of Security, 128 bit or 192 bit, or only 192 bit Level of Security respectively. See RFC6460 for details. In particular the supported signature algorithms are reduced to support only ECDSA and SHA256 or SHA384 and only the elliptic curves P-256 and P-384.

- -
-
-auth_level level
-
- -

Set the certificate chain authentication security level to level. The authentication security level determines the acceptable signature and public key strength when verifying certificate chains. For a certificate chain to validate, the public keys of all the certificates must meet the specified security level. The signature algorithm security level is enforced for all the certificates in the chain except for the chain's trust anchor, which is either directly trusted or validated by means other than its signature. See SSL_CTX_set_security_level(3) for the definitions of the available levels. The default security level is -1, or "not set". At security level 0 or lower all algorithms are acceptable. Security level 1 requires at least 80-bit-equivalent security and is broadly interoperable, though it will, for example, reject MD5 signatures or RSA keys shorter than 1024 bits.

- -
-
-partial_chain
-
- -

Allow verification to succeed if an incomplete chain can be built. That is, a chain ending in a certificate that normally would not be trusted (because it has no matching positive trust attributes and is not self-signed) but is an element of the trust store. This certificate may be self-issued or belong to an intermediate CA.

- -
-
-check_ss_sig
-
- -

Verify the signature of the last certificate in a chain if the certificate is supposedly self-signed. This is prohibited and will result in an error if it is a non-conforming CA certificate with key usage restrictions not including the keyCertSign bit. This verification is disabled by default because it doesn't add any security.

- -
-
-allow_proxy_certs
-
- -

Allow the verification of proxy certificates.

- -
-
-trusted_first
-
- -

As of OpenSSL 1.1.0 this option is on by default and cannot be disabled.

- -

When constructing the certificate chain, the trusted certificates specified via -CAfile, -CApath, -CAstore or -trusted are always used before any certificates specified via -untrusted.

- -
-
-no_alt_chains
-
- -

As of OpenSSL 1.1.0, since -trusted_first always on, this option has no effect.

- -
-
-trusted file
-
- -

Parse file as a set of one or more certificates. Each of them qualifies as trusted if has a suitable positive trust attribute or it is self-signed or the -partial_chain option is specified. This option implies the -no-CAfile, -no-CApath, and -no-CAstore options and it cannot be used with the -CAfile, -CApath or -CAstore options, so only certificates specified using the -trusted option are trust anchors. This option may be used multiple times.

- -
-
-untrusted file
-
- -

Parse file as a set of one or more certificates. All certificates (typically of intermediate CAs) are considered untrusted and may be used to construct a certificate chain from the target certificate to a trust anchor. This option may be used multiple times.

- -
-
-policy arg
-
- -

Enable policy processing and add arg to the user-initial-policy-set (see RFC5280). The policy arg can be an object name or an OID in numeric form. This argument can appear more than once.

- -
-
-explicit_policy
-
- -

Set policy variable require-explicit-policy (see RFC5280).

- -
-
-policy_check
-
- -

Enables certificate policy processing.

- -
-
-policy_print
-
- -

Print out diagnostics related to policy processing.

- -
-
-inhibit_any
-
- -

Set policy variable inhibit-any-policy (see RFC5280).

- -
-
-inhibit_map
-
- -

Set policy variable inhibit-policy-mapping (see RFC5280).

- -
-
-purpose purpose
-
- -

A high-level specification of the intended use of the target certificate. Currently predefined purposes are sslclient, sslserver, nssslserver, smimesign, smimeencrypt, crlsign, ocsphelper, timestampsign, codesign and any. If peer certificate verification is enabled, by default the TLS implementation and thus the commands openssl-s_client(1) and openssl-s_server(1) check for consistency with TLS server (sslserver) or TLS client use (sslclient), respectively. By default, CMS signature validation, which can be done via openssl-cms(1), checks for consistency with S/MIME signing use (smimesign).

- -

While IETF RFC 5280 says that id-kp-serverAuth and id-kp-clientAuth are only for WWW use, in practice they are used for all kinds of TLS clients and servers, and this is what OpenSSL assumes as well.

- -
-
-verify_depth num
-
- -

Limit the certificate chain to num intermediate CA certificates. A maximal depth chain can have up to num+2 certificates, since neither the end-entity certificate nor the trust-anchor certificate count against the -verify_depth limit.

- -
-
-verify_email email
-
- -

Verify if email matches the email address in Subject Alternative Name or the email in the subject Distinguished Name.

- -
-
-verify_hostname hostname
-
- -

Verify if hostname matches DNS name in Subject Alternative Name or Common Name in the subject certificate.

- -
-
-verify_ip ip
-
- -

Verify if ip matches the IP address in Subject Alternative Name of the subject certificate.

- -
-
-verify_name name
-
- -

Use a set of verification parameters, also known as verification method, identified by name. The currently predefined methods are named ssl_client, ssl_server, smime_sign with alias pkcs7, code_sign, and default. These mimic the combinations of purpose and trust settings used in SSL/(D)TLS, CMS/PKCS7 (including S/MIME), and code signing.

- -

The verification parameters include the trust model, various flags that can partly be set also via other command-line options, and the verification purpose, which in turn implies certificate key usage and extended key usage requirements.

- -

The trust model determines which auxiliary trust or reject OIDs are applicable to verifying the given certificate chain. They can be given using the -addtrust and -addreject options for openssl-x509(1).

- -
-
- -

Extended Verification Options

- -

Sometimes there may be more than one certificate chain leading to an end-entity certificate. This usually happens when a root or intermediate CA signs a certificate for another a CA in other organization. Another reason is when a CA might have intermediates that use two different signature formats, such as a SHA-1 and a SHA-256 digest.

- -

The following options can be used to provide data that will allow the OpenSSL command to generate an alternative chain.

- -
- -
-xkey infile, -xcert infile, -xchain
-
- -

Specify an extra certificate, private key and certificate chain. These behave in the same manner as the -cert, -key and -cert_chain options. When specified, the callback returning the first valid chain will be in use by the client.

- -
-
-xchain_build
-
- -

Specify whether the application should build the certificate chain to be provided to the server for the extra certificates via the -xkey, -xcert, and -xchain options.

- -
-
-xcertform DER|PEM|P12
-
- -

The input format for the extra certificate. This option has no effect and is retained for backward compatibility only.

- -
-
-xkeyform DER|PEM|P12
-
- -

The input format for the extra key. This option has no effect and is retained for backward compatibility only.

- -
-
- -

Certificate Extensions

- -

Options like -purpose and -verify_name trigger the processing of specific certificate extensions, which determine what certificates can be used for.

- -

Basic Constraints

- -

The basicConstraints extension CA flag is used to determine whether the certificate can be used as a CA. If the CA flag is true then it is a CA, if the CA flag is false then it is not a CA. All CAs should have the CA flag set to true.

- -

If the basicConstraints extension is absent, which includes the case that it is an X.509v1 certificate, then the certificate is considered to be a "possible CA" and other extensions are checked according to the intended use of the certificate. The treatment of certificates without basicConstraints as a CA is presently supported, but this could change in the future.

- -

Key Usage

- -

If the keyUsage extension is present then additional restraints are made on the uses of the certificate. A CA certificate must have the keyCertSign bit set if the keyUsage extension is present.

- -

Extended Key Usage

- -

The extKeyUsage (EKU) extension places additional restrictions on certificate use. If this extension is present (whether critical or not) in an end-entity certficiate, the key is allowed only for the uses specified, while the special EKU anyExtendedKeyUsage allows for all uses.

- -

Note that according to RFC 5280 section 4.2.1.12, the Extended Key Usage extension will appear only in end-entity certificates, and consequently the standard certification path validation described in its section 6 does not include EKU checks for CA certificates. The CA/Browser Forum requires for TLS server, S/MIME, and code signing use the presence of respective EKUs in subordinate CA certificates (while excluding them for root CA certificates), while taking over from RFC 5280 the certificate validity concept and certificate path validation.

- -

For historic reasons, OpenSSL has its own way of interpreting and checking EKU extensions on CA certificates, which may change in the future. It does not require the presence of EKU extensions in CA certificates, but in case the verification purpose is sslclient, nssslserver, sslserver, smimesign, or smimeencrypt, it checks that any present EKU extension (that does not contain anyExtendedKeyUsage) contains the respective EKU as detailed below. Moreover, it does these checks even for trust anchor certificates.

- -

Checks Implied by Specific Predefined Policies

- -

A specific description of each check is given below. The comments about basicConstraints and keyUsage and X.509v1 certificates above apply to all CA certificates.

- -
- -
(D)TLS Client (sslclient)
-
- -

Any given extended key usage extension must allow for clientAuth ("TLS WWW client authentication").

- -

For target certificates, the key usage must allow for digitalSignature and/or keyAgreement. The Netscape certificate type must be absent or have the SSL client bit set.

- -

For all other certificates the normal CA checks apply. In addition, the Netscape certificate type must be absent or have the SSL CA bit set. This is used as a workaround if the basicConstraints extension is absent.

- -
-
(D)TLS Server (sslserver)
-
- -

Any given extended key usage extension must allow for serverAuth ("TLS WWW server authentication") and/or include one of the SGC OIDs.

- -

For target certificates, the key usage must allow for digitalSignature, keyEncipherment, and/or keyAgreement. The Netscape certificate type must be absent or have the SSL server bit set.

- -

For all other certificates the normal CA checks apply. In addition, the Netscape certificate type must be absent or have the SSL CA bit set. This is used as a workaround if the basicConstraints extension is absent.

- -
-
Netscape SSL Server (nssslserver)
-
- -

In addition to what has been described for sslserver, for a Netscape SSL client to connect to an SSL server, its EE certficate must have the keyEncipherment bit set if the keyUsage extension is present. This isn't always valid because some cipher suites use the key for digital signing. Otherwise it is the same as a normal SSL server.

- -
-
Common S/MIME Checks
-
- -

Any given extended key usage extension must allow for emailProtection.

- -

For target certificates, the Netscape certificate type must be absent or should have the S/MIME bit set. If the S/MIME bit is not set in the Netscape certificate type then the SSL client bit is tolerated as an alternative but a warning is shown. This is because some Verisign certificates don't set the S/MIME bit.

- -

For all other certificates the normal CA checks apply. In addition, the Netscape certificate type must be absent or have the S/MIME CA bit set. This is used as a workaround if the basicConstraints extension is absent.

- -
-
S/MIME Signing (smimesign)
-
- -

In addition to the common S/MIME checks, for target certficiates the key usage must allow for digitalSignature and/or nonRepudiation.

- -
-
S/MIME Encryption (smimeencrypt)
-
- -

In addition to the common S/MIME checks, for target certficiates the key usage must allow for keyEncipherment.

- -
-
CRL Signing (crlsign)
-
- -

For target certificates, the key usage must allow for cRLSign.

- -

For all other certifcates the normal CA checks apply. Except in this case the basicConstraints extension must be present.

- -
-
OCSP Helper (ocsphelper)
-
- -

For target certificates, no checks are performed at this stage, but special checks apply; see OCSP_basic_verify(3).

- -

For all other certifcates the normal CA checks apply.

- -
-
Timestamp Signing (timestampsign)
-
- -

For target certificates, if the key usage extension is present, it must include digitalSignature and/or nonRepudiation and must not include other bits. The EKU extension must be present and contain timeStamping only. Moreover, it must be marked as critical.

- -

For all other certifcates the normal CA checks apply.

- -
-
Code Signing (codesign)
-
- -

For target certificates, the key usage extension must be present and marked critical and include <digitalSignature>, but must not include keyCertSign nor cRLSign. The EKU extension must be present and contain codeSign, but must not include anyExtendedKeyUsage nor serverAuth.

- -

For all other certifcates the normal CA checks apply.

- -
-
- -

BUGS

- -

The issuer checks still suffer from limitations in the underlying X509_LOOKUP API. One consequence of this is that trusted certificates with matching subject name must appear in a file (as specified by the -CAfile option), a directory (as specified by -CApath), or a store (as specified by -CAstore). If there are multiple such matches, possibly in multiple locations, only the first one (in the mentioned order of locations) is recognised.

- -

SEE ALSO

- -

X509_verify_cert(3), OCSP_basic_verify(3), openssl-verify(1), openssl-ocsp(1), openssl-ts(1), openssl-s_client(1), openssl-s_server(1), openssl-smime(1), openssl-cmp(1), openssl-cms(1)

- -

HISTORY

- -

The checks enabled by -x509_strict have been extended in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-verify.html b/openssl-install/share/doc/openssl/html/man1/openssl-verify.html deleted file mode 100644 index 631b6a26..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-verify.html +++ /dev/null @@ -1,179 +0,0 @@ - - - - -openssl-verify - - - - - - - - - - -

NAME

- -

openssl-verify - certificate verification command

- -

SYNOPSIS

- -

openssl verify [-help] [-CRLfile filename|uri] [-crl_download] [-show_chain] [-verbose] [-trusted filename|uri] [-untrusted filename|uri] [-vfyopt nm:v] [-nameopt option] [-CAfile file] [-no-CAfile] [-CApath dir] [-no-CApath] [-CAstore uri] [-no-CAstore] [-engine id] [-allow_proxy_certs] [-attime timestamp] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy arg] [-policy_check] [-policy_print] [-purpose purpose] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level num] [-verify_depth num] [-verify_email email] [-verify_hostname hostname] [-verify_ip ip] [-verify_name name] [-x509_strict] [-issuer_checks] [-provider name] [-provider-path path] [-propquery propq] [--] [certificate ...]

- -

DESCRIPTION

- -

This command verifies certificate chains. If a certificate chain has multiple problems, this program attempts to display all of them.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-CRLfile filename|uri
-
- -

The file or URI should contain one or more CRLs in PEM or DER format. This option can be specified more than once to include CRLs from multiple sources.

- -
-
-crl_download
-
- -

Attempt to download CRL information for certificates via their CDP entries.

- -
-
-show_chain
-
- -

Display information about the certificate chain that has been built (if successful). Certificates in the chain that came from the untrusted list will be flagged as "untrusted".

- -
-
-verbose
-
- -

Print extra information about the operations being performed.

- -
-
-trusted filename|uri
-
- -

A file or URI of (more or less) trusted certificates. See openssl-verification-options(1) for more information on trust settings.

- -

This option can be specified more than once to load certificates from multiple sources.

- -
-
-untrusted filename|uri
-
- -

A file or URI of untrusted certificates to use for chain building. This option can be specified more than once to load certificates from multiple sources.

- -
-
-vfyopt nm:v
-
- -

Pass options to the signature algorithm during verify operations. Names and values of these options are algorithm-specific.

- -
-
-nameopt option
-
- -

This specifies how the subject or issuer names are displayed. See openssl-namedisplay-options(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -

To load certificates or CRLs that require engine support, specify the -engine option before any of the -trusted, -untrusted or -CRLfile options.

- -
-
-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore
-
- -

See "Trusted Certificate Options" in openssl-verification-options(1) for details.

- -
-
-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks
-
- -

Set various options of certificate chain verification. See "Verification Options" in openssl-verification-options(1) for details.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
--
-
- -

Indicates the last option. All arguments following this are assumed to be certificate files. This is useful if the first certificate filename begins with a -.

- -
-
certificate ...
-
- -

One or more target certificates to verify, one per file. If no certificates are given, this command will attempt to read a single certificate from standard input.

- -
-
- -

DIAGNOSTICS

- -

When a verify operation fails the output messages can be somewhat cryptic. The general form of the error message is:

- -
server.pem: /C=AU/ST=Queensland/O=CryptSoft Pty Ltd/CN=Test CA (1024 bit)
-error 24 at 1 depth lookup:invalid CA certificate
- -

The first line contains the name of the certificate being verified followed by the subject name of the certificate. The second line contains the error number and the depth. The depth is number of the certificate being verified when a problem was detected starting with zero for the target ("leaf") certificate itself then 1 for the CA that signed the target certificate and so on. Finally a textual version of the error number is presented.

- -

A list of the error codes and messages can be found in X509_STORE_CTX_get_error(3); the full list is defined in the header file <openssl/x509_vfy.h>.

- -

This command ignores many errors, in order to allow all the problems with a certificate chain to be determined.

- -

SEE ALSO

- -

openssl-verification-options(1), openssl-x509(1), ossl_store-file(7)

- -

HISTORY

- -

The -show_chain option was added in OpenSSL 1.1.0.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-version.html b/openssl-install/share/doc/openssl/html/man1/openssl-version.html deleted file mode 100644 index 2bbf7812..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-version.html +++ /dev/null @@ -1,139 +0,0 @@ - - - - -openssl-version - - - - - - - - - - -

NAME

- -

openssl-version - print OpenSSL version information

- -

SYNOPSIS

- -

openssl version [-help] [-a] [-v] [-b] [-o] [-f] [-p] [-d] [-e] [-m] [-r] [-c] [-w]

- -

DESCRIPTION

- -

This command is used to print out version information about OpenSSL.

- -

OPTIONS

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-a
-
- -

All information, this is the same as setting all the other flags.

- -
-
-v
-
- -

The current OpenSSL version.

- -
-
-b
-
- -

The date the current version of OpenSSL was built.

- -
-
-o
-
- -

Option information: various options set when the library was built.

- -
-
-f
-
- -

Compilation flags.

- -
-
-p
-
- -

Platform setting.

- -
-
-d
-
- -

OPENSSLDIR setting.

- -
-
-e
-
- -

ENGINESDIR settings.

- -
-
-m
-
- -

MODULESDIR settings.

- -
-
-r
-
- -

The random number generator source settings.

- -
-
-c
-
- -

The OpenSSL CPU settings info.

- -
-
-w
-
- -

The OpenSSL OSSL_WINCTX build time variable, if set. Used for computing Windows registry key names. This option is unavailable on non-Windows platforms.

- -
-
- -

HISTORY

- -

In OpenSSL versions prior to 3.4, OpenSSL had a limitation regarding the OPENSSLDIR, MODULESDIR and ENGINESDIR build time macros. These macros were defined at build time, and represented filesystem paths. This is common practice on unix like systems, as there was an expectation that a given build would be installed to a pre-determined location. On Windows however, there is no such expectation, as libraries can be installed to arbitrary locations. OSSL_WINCTX was introduced as a new build time variable to define a set of registry keys identified by the name openssl-<version>-<ctx>, in which the <version> value is derived from the version string in the openssl source, and the <ctx> extension is derived from the OSSL_WINCTX variable. The values of OPENSSLDIR, ENGINESDIR and MODULESDIR can be set to various paths underneath this key to break the requirement to predict the installation path at build time.

- -

NOTES

- -

The output of openssl version -a would typically be used when sending in a bug report.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl-x509.html b/openssl-install/share/doc/openssl/html/man1/openssl-x509.html deleted file mode 100644 index f82e753b..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl-x509.html +++ /dev/null @@ -1,822 +0,0 @@ - - - - -openssl-x509 - - - - - - - - - - -

NAME

- -

openssl-x509 - Certificate display and signing command

- -

SYNOPSIS

- -

openssl x509 [-help] [-in filename|uri] [-passin arg] [-new] [-x509toreq] [-req] [-copy_extensions arg] [-inform DER|PEM] [-vfyopt nm:v] [-key filename|uri] [-keyform DER|PEM|P12|ENGINE] [-signkey filename|uri] [-out filename] [-outform DER|PEM] [-nocert] [-noout] [-dateopt] [-text] [-certopt option] [-fingerprint] [-alias] [-serial] [-startdate] [-enddate] [-dates] [-subject] [-issuer] [-nameopt option] [-email] [-hash] [-subject_hash] [-subject_hash_old] [-issuer_hash] [-issuer_hash_old] [-ext extensions] [-ocspid] [-ocsp_uri] [-purpose] [-pubkey] [-modulus] [-checkend num] [-checkhost host] [-checkemail host] [-checkip ipaddr] [-set_serial n] [-next_serial] [-not_before date] [-not_after date] [-days arg] [-preserve_dates] [-set_issuer arg] [-set_subject arg] [-subj arg] [-force_pubkey filename] [-clrext] [-extfile filename] [-extensions section] [-sigopt nm:v] [-badsig] [-digest] [-CA filename|uri] [-CAform DER|PEM|P12] [-CAkey filename|uri] [-CAkeyform DER|PEM|P12|ENGINE] [-CAserial filename] [-CAcreateserial] [-trustout] [-setalias arg] [-clrtrust] [-addtrust arg] [-clrreject] [-addreject arg] [-rand files] [-writerand file] [-engine id] [-provider name] [-provider-path path] [-propquery propq]

- -

DESCRIPTION

- -

This command is a multi-purposes certificate handling command. It can be used to print certificate information, convert certificates to various forms, edit certificate trust settings, generate certificates from scratch or from certification requests and then self-signing them or signing them like a "micro CA".

- -

Generated certificates bear X.509 version 3. Unless specified otherwise, key identifier extensions are included as described in x509v3_config(5).

- -

Since there are a large number of options they will split up into various sections.

- -

OPTIONS

- -

Input, Output, and General Purpose Options

- -
- -
-help
-
- -

Print out a usage message.

- -
-
-in filename|uri
-
- -

This specifies the input to read a certificate from or the input file for reading a certificate request if the -req flag is used. In both cases this defaults to standard input.

- -

This option cannot be combined with the -new flag.

- -
-
-passin arg
-
- -

The key and certificate file password source. For more information about the format of arg see openssl-passphrase-options(1).

- -
-
-new
-
- -

Generate a certificate from scratch, not using an input certificate or certificate request. So this excludes the -in and -req options. Instead, the -set_subject option needs to be given. The public key to include can be given with the -force_pubkey option and defaults to the key given with the -key (or -signkey) option, which implies self-signature.

- -
-
-x509toreq
-
- -

Output a PKCS#10 certificate request (rather than a certificate). The -key (or -signkey) option must be used to provide the private key for self-signing; the corresponding public key is placed in the subjectPKInfo field.

- -

X.509 extensions included in a certificate input are not copied by default. X.509 extensions to be added can be specified using the -extfile option.

- -
-
-req
-
- -

By default a certificate is expected on input. With this option a PKCS#10 certificate request is expected instead, which must be correctly self-signed.

- -

X.509 extensions included in the request are not copied by default. X.509 extensions to be added can be specified using the -extfile option.

- -
-
-copy_extensions arg
-
- -

Determines how to handle X.509 extensions when converting from a certificate to a request using the -x509toreq option or converting from a request to a certificate using the -req option. If arg is none or this option is not present then extensions are ignored. If arg is copy or copyall then all extensions are copied, except that subject identifier and authority key identifier extensions are not taken over when producing a certificate request.

- -

The -ext option can be used to further restrict which extensions to copy.

- -
-
-inform DER|PEM
-
- -

The input file format to use; by default PEM is tried first. See openssl-format-options(1) for details.

- -
-
-vfyopt nm:v
-
- -

Pass options to the signature algorithm during verify operations. Names and values of these options are algorithm-specific.

- -
-
-key filename|uri
-
- -

This option provides the private key for signing a new certificate or certificate request. Unless -force_pubkey is given, the corresponding public key is placed in the new certificate or certificate request, resulting in a self-signature.

- -

This option cannot be used in conjunction with the -CA option.

- -

It sets the issuer name to the subject name (i.e., makes it self-issued). Unless the -preserve_dates option is supplied, it sets the validity start date to the current time and the end date to a value determined by the -days option. Start date and end date can also be explicitly supplied with options -not_before and -not_after.

- -
-
-signkey filename|uri
-
- -

This option is an alias of -key.

- -
-
-keyform DER|PEM|P12|ENGINE
-
- -

The key input format; unspecified by default. See openssl-format-options(1) for details.

- -
-
-out filename
-
- -

This specifies the output filename to write to or standard output by default.

- -
-
-outform DER|PEM
-
- -

The output format; the default is PEM. See openssl-format-options(1) for details.

- -
-
-nocert
-
- -

Do not output a certificate (except for printing as requested by below options).

- -
-
-noout
-
- -

This option prevents output except for printing as requested by below options.

- -
-
- -

Certificate Printing Options

- -

Note: the -alias and -purpose options are also printing options but are described in the "Trust Settings" section.

- -
- -
-dateopt
-
- -

Specify the date output format. Values are: rfc_822 and iso_8601. Defaults to rfc_822.

- -
-
-text
-
- -

Prints out the certificate in text form. Full details are printed including the public key, signature algorithms, issuer and subject names, serial number any extensions present and any trust settings.

- -
-
-certopt option
-
- -

Customise the print format used with -text. The option argument can be a single option or multiple options separated by commas. The -certopt switch may be also be used more than once to set multiple options. See the "Text Printing Flags" section for more information.

- -
-
-fingerprint
-
- -

Calculates and prints the digest of the DER encoded version of the entire certificate (see digest options). This is commonly called a "fingerprint". Because of the nature of message digests, the fingerprint of a certificate is unique to that certificate and two certificates with the same fingerprint can be considered to be the same.

- -
-
-alias
-
- -

Prints the certificate "alias" (nickname), if any.

- -
-
-serial
-
- -

Prints the certificate serial number.

- -
-
-startdate
-
- -

Prints out the start date of the certificate, that is the notBefore date.

- -
-
-enddate
-
- -

Prints out the expiry date of the certificate, that is the notAfter date.

- -
-
-dates
-
- -

Prints out the start and expiry dates of a certificate.

- -
-
-subject
-
- -

Prints the subject name.

- -
-
-issuer
-
- -

Prints the issuer name.

- -
-
-nameopt option
-
- -

This specifies how the subject or issuer names are displayed. See openssl-namedisplay-options(1) for details.

- -
-
-email
-
- -

Prints the email address(es) if any.

- -
-
-hash
-
- -

Synonym for "-subject_hash" for backward compatibility reasons.

- -
-
-subject_hash
-
- -

Prints the "hash" of the certificate subject name. This is used in OpenSSL to form an index to allow certificates in a directory to be looked up by subject name.

- -
-
-subject_hash_old
-
- -

Prints the "hash" of the certificate subject name using the older algorithm as used by OpenSSL before version 1.0.0.

- -
-
-issuer_hash
-
- -

Prints the "hash" of the certificate issuer name.

- -
-
-issuer_hash_old
-
- -

Prints the "hash" of the certificate issuer name using the older algorithm as used by OpenSSL before version 1.0.0.

- -
-
-ext extensions
-
- -

Prints out the certificate extensions in text form. Can also be used to restrict which extensions to copy. Extensions are specified with a comma separated string, e.g., "subjectAltName, subjectKeyIdentifier". See the x509v3_config(5) manual page for the extension names.

- -
-
-ocspid
-
- -

Prints the OCSP hash values for the subject name and public key.

- -
-
-ocsp_uri
-
- -

Prints the OCSP responder address(es) if any.

- -
-
-purpose
-
- -

This option performs tests on the certificate extensions and outputs the results. For a more complete description see "Certificate Extensions" in openssl-verification-options(1).

- -
-
-pubkey
-
- -

Prints the certificate's SubjectPublicKeyInfo block in PEM format.

- -
-
-modulus
-
- -

This option prints out the value of the modulus of the public key contained in the certificate.

- -
-
- -

Certificate Checking Options

- -
- -
-checkend arg
-
- -

Checks if the certificate expires within the next arg seconds and exits nonzero if yes it will expire or zero if not.

- -
-
-checkhost host
-
- -

Check that the certificate matches the specified host.

- -
-
-checkemail email
-
- -

Check that the certificate matches the specified email address.

- -
-
-checkip ipaddr
-
- -

Check that the certificate matches the specified IP address.

- -
-
- -

Certificate Output Options

- -
- -
-set_serial n
-
- -

Specifies the serial number to use. This option can be used with the -key, -signkey, or -CA options. If used in conjunction with the -CA option the serial number file (as specified by the -CAserial option) is not used.

- -

The serial number can be decimal or hex (if preceded by 0x).

- -
-
-next_serial
-
- -

Set the serial to be one more than the number in the certificate.

- -
-
-not_before date
-
- -

This allows the start date to be explicitly set. The format of the date is YYMMDDHHMMSSZ (the same as an ASN1 UTCTime structure), or YYYYMMDDHHMMSSZ (the same as an ASN1 GeneralizedTime structure). In both formats, seconds SS and timezone Z must be present. Alternatively, you can also use "today".

- -

Cannot be used together with the -preserve_dates option.

- -
-
-not_after date
-
- -

This allows the expiry date to be explicitly set. The format of the date is YYMMDDHHMMSSZ (the same as an ASN1 UTCTime structure), or YYYYMMDDHHMMSSZ (the same as an ASN1 GeneralizedTime structure). In both formats, seconds SS and timezone Z must be present. Alternatively, you can also use "today".

- -

Cannot be used together with the -preserve_dates option. This overrides the option -days.

- -
-
-days arg
-
- -

Specifies the number of days from today until a newly generated certificate expires. The default is 30.

- -

Cannot be used together with the option -preserve_dates. If option -not_after is set, the explicit expiry date takes precedence.

- -
-
-preserve_dates
-
- -

When signing a certificate, preserve "notBefore" and "notAfter" dates of any input certificate instead of adjusting them to current time and duration. Cannot be used together with the options -days, -not_before and -not_after.

- -
-
-set_issuer arg
-
- -

When a certificate is created set its issuer name to the given value.

- -

See -set_subject on how the arg must be formatted.

- -
-
-set_subject arg
-
- -

When a certificate is created set its subject name to the given value. When the certificate is self-signed the issuer name is set to the same value, unless the -set_issuer option is given.

- -

The arg must be formatted as /type0=value0/type1=value1/type2=.... Special characters may be escaped by \ (backslash), whitespace is retained. Empty values are permitted, but the corresponding type will not be included in the certificate. Giving a single / will lead to an empty sequence of RDNs (a NULL-DN). Multi-valued RDNs can be formed by placing a + character instead of a / between the AttributeValueAssertions (AVAs) that specify the members of the set. Example:

- -

/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe

- -

This option can be used with the -new and -force_pubkey options to create a new certificate without providing an input certificate or certificate request.

- -
-
-subj arg
-
- -

This option is an alias of -set_subject.

- -
-
-force_pubkey filename
-
- -

When a new certificate or certificate request is created set its public key to the given key instead of the key contained in the input or given with the -key (or -signkey) option. If the input contains no public key but a private key, its public part is used.

- -

This option can be used in conjunction with b<-new> and -set_subject to directly generate a certificate containing any desired public key.

- -

This option is also useful for creating self-issued certificates that are not self-signed, for instance when the key cannot be used for signing, such as DH.

- -
-
-clrext
-
- -

When transforming a certificate to a new certificate by default all certificate extensions are retained.

- -

When transforming a certificate or certificate request, the -clrext option prevents taking over any extensions from the source. In any case, when producing a certificate request, neither subject identifier nor authority key identifier extensions are included.

- -
-
-extfile filename
-
- -

Configuration file containing certificate and request X.509 extensions to add.

- -
-
-extensions section
-
- -

The section in the extfile to add X.509 extensions from. If this option is not specified then the extensions should either be contained in the unnamed (default) section or the default section should contain a variable called "extensions" which contains the section to use.

- -

See the x509v3_config(5) manual page for details of the extension section format.

- -

Unless specified otherwise, key identifier extensions are included as described in x509v3_config(5).

- -
-
-sigopt nm:v
-
- -

Pass options to the signature algorithm during sign operations. This option may be given multiple times. Names and values provided using this option are algorithm-specific.

- -
-
-badsig
-
- -

Corrupt the signature before writing it; this can be useful for testing.

- -
-
-digest
-
- -

The digest to use. This affects any signing or printing option that uses a message digest, such as the -fingerprint, -key, and -CA options. Any digest supported by the openssl-dgst(1) command can be used. If not specified then SHA1 is used with -fingerprint or the default digest for the signing algorithm is used, typically SHA256.

- -
-
- -

Micro-CA Options

- -
- -
-CA filename|uri
-
- -

Specifies the "CA" certificate to be used for signing. When present, this behaves like a "micro CA" as follows: The subject name of the "CA" certificate is placed as issuer name in the new certificate, which is then signed using the "CA" key given as detailed below.

- -

This option cannot be used in conjunction with -key (or -signkey). This option is normally combined with the -req option referencing a CSR. Without the -req option the input must be an existing certificate unless the -new option is given, which generates a certificate from scratch.

- -
-
-CAform DER|PEM|P12,
-
- -

The format for the CA certificate; unspecified by default. See openssl-format-options(1) for details.

- -
-
-CAkey filename|uri
-
- -

Sets the CA private key to sign a certificate with. The private key must match the public key of the certificate given with -CA. If this option is not provided then the key must be present in the -CA input.

- -
-
-CAkeyform DER|PEM|P12|ENGINE
-
- -

The format for the CA key; unspecified by default. See openssl-format-options(1) for details.

- -
-
-CAserial filename
-
- -

Sets the CA serial number file to use.

- -

When creating a certificate with this option and with the -CA option, the certificate serial number is stored in the given file. This file consists of one line containing an even number of hex digits with the serial number used last time. After reading this number, it is incremented and used, and the file is updated.

- -

The default filename consists of the CA certificate file base name with .srl appended. For example if the CA certificate file is called mycacert.pem it expects to find a serial number file called mycacert.srl.

- -

If the -CA option is specified and neither <-CAserial> or <-CAcreateserial> is given and the default serial number file does not exist, a random number is generated; this is the recommended practice.

- -
-
-CAcreateserial
-
- -

With this option and the -CA option the CA serial number file is created if it does not exist. A random number is generated, used for the certificate, and saved into the serial number file determined as described above.

- -
-
- -

Trust Settings

- -

A trusted certificate is an ordinary certificate which has several additional pieces of information attached to it such as the permitted and prohibited uses of the certificate and possibly an "alias" (nickname).

- -

Normally when a certificate is being verified at least one certificate must be "trusted". By default a trusted certificate must be stored locally and must be a root CA: any certificate chain ending in this CA is then usable for any purpose.

- -

Trust settings currently are only used with a root CA. They allow a finer control over the purposes the root CA can be used for. For example, a CA may be trusted for SSL client but not SSL server use.

- -

See openssl-verification-options(1) for more information on the meaning of trust settings.

- -

Future versions of OpenSSL will recognize trust settings on any certificate: not just root CAs.

- -
- -
-trustout
-
- -

Mark any certificate PEM output as <trusted> certificate rather than ordinary. An ordinary or trusted certificate can be input but by default an ordinary certificate is output and any trust settings are discarded. With the -trustout option a trusted certificate is output. A trusted certificate is automatically output if any trust settings are modified.

- -
-
-setalias arg
-
- -

Sets the "alias" of the certificate. This will allow the certificate to be referred to using a nickname for example "Steve's Certificate".

- -
-
-clrtrust
-
- -

Clears all the permitted or trusted uses of the certificate.

- -
-
-addtrust arg
-
- -

Adds a trusted certificate use. Any object name can be used here but currently only clientAuth, serverAuth, emailProtection, and anyExtendedKeyUsage are defined. As of OpenSSL 1.1.0, the last of these blocks all purposes when rejected or enables all purposes when trusted. Other OpenSSL applications may define additional uses.

- -
-
-clrreject
-
- -

Clears all the prohibited or rejected uses of the certificate.

- -
-
-addreject arg
-
- -

Adds a prohibited trust anchor purpose. It accepts the same values as the -addtrust option.

- -
-
- -

Generic options

- -
- -
-rand files, -writerand file
-
- -

See "Random State Options" in openssl(1) for details.

- -
-
-engine id
-
- -

See "Engine Options" in openssl(1). This option is deprecated.

- -
-
-provider name
-
- -
-
-provider-path path
-
- -
-
-propquery propq
-
- -

See "Provider Options" in openssl(1), provider(7), and property(7).

- -
-
- -

Text Printing Flags

- -

As well as customising the name printing format, it is also possible to customise the actual fields printed using the certopt option when the text option is present. The default behaviour is to print all fields.

- -
- -
compatible
-
- -

Use the old format. This is equivalent to specifying no printing options at all.

- -
-
no_header
-
- -

Don't print header information: that is the lines saying "Certificate" and "Data".

- -
-
no_version
-
- -

Don't print out the version number.

- -
-
no_serial
-
- -

Don't print out the serial number.

- -
-
no_signame
-
- -

Don't print out the signature algorithm used.

- -
-
no_validity
-
- -

Don't print the validity, that is the notBefore and notAfter fields.

- -
-
no_subject
-
- -

Don't print out the subject name.

- -
-
no_issuer
-
- -

Don't print out the issuer name.

- -
-
no_pubkey
-
- -

Don't print out the public key.

- -
-
no_sigdump
-
- -

Don't give a hexadecimal dump of the certificate signature.

- -
-
no_aux
-
- -

Don't print out certificate trust information.

- -
-
no_extensions
-
- -

Don't print out any X509V3 extensions.

- -
-
ext_default
-
- -

Retain default extension behaviour: attempt to print out unsupported certificate extensions.

- -
-
ext_error
-
- -

Print an error message for unsupported certificate extensions.

- -
-
ext_parse
-
- -

ASN1 parse unsupported extensions.

- -
-
ext_dump
-
- -

Hex dump unsupported extensions.

- -
-
ca_default
-
- -

The value used by openssl-ca(1), equivalent to no_issuer, no_pubkey, no_header, and no_version.

- -
-
- -

EXAMPLES

- -

Note: in these examples the '\' means the example should be all on one line.

- -

Print the contents of a certificate:

- -
openssl x509 -in cert.pem -noout -text
- -

Print the "Subject Alternative Name" extension of a certificate:

- -
openssl x509 -in cert.pem -noout -ext subjectAltName
- -

Print more extensions of a certificate:

- -
openssl x509 -in cert.pem -noout -ext subjectAltName,nsCertType
- -

Print the certificate serial number:

- -
openssl x509 -in cert.pem -noout -serial
- -

Print the certificate subject name:

- -
openssl x509 -in cert.pem -noout -subject
- -

Print the certificate subject name in RFC2253 form:

- -
openssl x509 -in cert.pem -noout -subject -nameopt RFC2253
- -

Print the certificate subject name in oneline form on a terminal supporting UTF8:

- -
openssl x509 -in cert.pem -noout -subject -nameopt oneline,-esc_msb
- -

Print the certificate SHA1 fingerprint:

- -
openssl x509 -sha1 -in cert.pem -noout -fingerprint
- -

Convert a certificate from PEM to DER format:

- -
openssl x509 -in cert.pem -inform PEM -out cert.der -outform DER
- -

Convert a certificate to a certificate request:

- -
openssl x509 -x509toreq -in cert.pem -out req.pem -key key.pem
- -

Convert a certificate request into a self-signed certificate using extensions for a CA:

- -
openssl x509 -req -in careq.pem -extfile openssl.cnf -extensions v3_ca \
-       -key key.pem -out cacert.pem
- -

Sign a certificate request using the CA certificate above and add user certificate extensions:

- -
openssl x509 -req -in req.pem -extfile openssl.cnf -extensions v3_usr \
-       -CA cacert.pem -CAkey key.pem -CAcreateserial
- -

Set a certificate to be trusted for SSL client use and change set its alias to "Steve's Class 1 CA"

- -
openssl x509 -in cert.pem -addtrust clientAuth \
-       -setalias "Steve's Class 1 CA" -out trust.pem
- -

NOTES

- -

The conversion to UTF8 format used with the name options assumes that T61Strings use the ISO8859-1 character set. This is wrong but Netscape and MSIE do this as do many certificates. So although this is incorrect it is more likely to print the majority of certificates correctly.

- -

The -email option searches the subject name and the subject alternative name extension. Only unique email addresses will be printed out: it will not print the same address more than once.

- -

BUGS

- -

It is possible to produce invalid certificates or requests by specifying the wrong private key, using unsuitable X.509 extensions, or using inconsistent options in some cases: these should be checked.

- -

There should be options to explicitly set such things as start and end dates rather than an offset from the current time.

- -

SEE ALSO

- -

openssl(1), openssl-req(1), openssl-ca(1), openssl-genrsa(1), openssl-gendsa(1), openssl-verify(1), x509v3_config(5)

- -

HISTORY

- -

The hash algorithm used in the -subject_hash and -issuer_hash options before OpenSSL 1.0.0 was based on the deprecated MD5 algorithm and the encoding of the distinguished name. In OpenSSL 1.0.0 and later it is based on a canonical version of the DN using SHA1. This means that any directories using the old form must have their links rebuilt using openssl-rehash(1) or similar.

- -

The -signkey option has been renamed to -key in OpenSSL 3.0, keeping the old name as an alias.

- -

The -engine option was deprecated in OpenSSL 3.0.

- -

The -C option was removed in OpenSSL 3.0.

- -

Since OpenSSL 3.2, generated certificates bear X.509 version 3, and key identifier extensions are included by default.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/openssl.html b/openssl-install/share/doc/openssl/html/man1/openssl.html deleted file mode 100644 index 8210a47f..00000000 --- a/openssl-install/share/doc/openssl/html/man1/openssl.html +++ /dev/null @@ -1,884 +0,0 @@ - - - - -openssl - - - - - - - - - - -

NAME

- -

openssl - OpenSSL command line program

- -

SYNOPSIS

- -

openssl command [ options ... ] [ parameters ... ]

- -

openssl no-XXX [ options ]

- -

openssl -help | -version

- -

DESCRIPTION

- -

OpenSSL is a cryptography toolkit implementing the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) network protocols and related cryptography standards required by them.

- -

The openssl program is a command line program for using the various cryptography functions of OpenSSL's crypto library from the shell. It can be used for

- -
o  Creation and management of private keys, public keys and parameters
-o  Public key cryptographic operations
-o  Creation of X.509 certificates, CSRs and CRLs
-o  Calculation of Message Digests and Message Authentication Codes
-o  Encryption and Decryption with Ciphers
-o  SSL/TLS Client and Server Tests
-o  Handling of S/MIME signed or encrypted mail
-o  Timestamp requests, generation and verification
- -

COMMAND SUMMARY

- -

The openssl program provides a rich variety of commands (command in the "SYNOPSIS" above). Each command can have many options and argument parameters, shown above as options and parameters.

- -

Detailed documentation and use cases for most standard subcommands are available (e.g., openssl-x509(1)). The subcommand openssl-list(1) may be used to list subcommands.

- -

The command no-XXX tests whether a command of the specified name is available. If no command named XXX exists, it returns 0 (success) and prints no-XXX; otherwise it returns 1 and prints XXX. In both cases, the output goes to stdout and nothing is printed to stderr. Additional command line arguments are always ignored. Since for each cipher there is a command of the same name, this provides an easy way for shell scripts to test for the availability of ciphers in the openssl program. (no-XXX is not able to detect pseudo-commands such as quit, list, or no-XXX itself.)

- -

Configuration Option

- -

Many commands use an external configuration file for some or all of their arguments and have a -config option to specify that file. The default name of the file is openssl.cnf in the default certificate storage area, which can be determined from the openssl-version(1) command using the -d or -a option. The environment variable OPENSSL_CONF can be used to specify a different file location or to disable loading a configuration (using the empty string).

- -

Among others, the configuration file can be used to load modules and to specify parameters for generating certificates and random numbers. See config(5) for details.

- -

Standard Commands

- -
- -
asn1parse
-
- -

Parse an ASN.1 sequence.

- -
-
ca
-
- -

Certificate Authority (CA) Management.

- -
-
ciphers
-
- -

Cipher Suite Description Determination.

- -
-
cms
-
- -

CMS (Cryptographic Message Syntax) command.

- -
-
crl
-
- -

Certificate Revocation List (CRL) Management.

- -
-
crl2pkcs7
-
- -

CRL to PKCS#7 Conversion.

- -
-
dgst
-
- -

Message Digest calculation. MAC calculations are superseded by openssl-mac(1).

- -
-
dhparam
-
- -

Generation and Management of Diffie-Hellman Parameters. Superseded by openssl-genpkey(1) and openssl-pkeyparam(1).

- -
-
dsa
-
- -

DSA Data Management.

- -
-
dsaparam
-
- -

DSA Parameter Generation and Management. Superseded by openssl-genpkey(1) and openssl-pkeyparam(1).

- -
-
ec
-
- -

EC (Elliptic curve) key processing.

- -
-
ecparam
-
- -

EC parameter manipulation and generation.

- -
-
enc
-
- -

Encryption, decryption, and encoding.

- -
-
engine
-
- -

Engine (loadable module) information and manipulation.

- -
-
errstr
-
- -

Error Number to Error String Conversion.

- -
-
fipsinstall
-
- -

FIPS configuration installation.

- -
-
gendsa
-
- -

Generation of DSA Private Key from Parameters. Superseded by openssl-genpkey(1) and openssl-pkey(1).

- -
-
genpkey
-
- -

Generation of Private Key or Parameters.

- -
-
genrsa
-
- -

Generation of RSA Private Key. Superseded by openssl-genpkey(1).

- -
-
help
-
- -

Display information about a command's options.

- -
-
info
-
- -

Display diverse information built into the OpenSSL libraries.

- -
-
kdf
-
- -

Key Derivation Functions.

- -
-
list
-
- -

List algorithms and features.

- -
-
mac
-
- -

Message Authentication Code Calculation.

- -
-
nseq
-
- -

Create or examine a Netscape certificate sequence.

- -
-
ocsp
-
- -

Online Certificate Status Protocol command.

- -
-
passwd
-
- -

Generation of hashed passwords.

- -
-
pkcs12
-
- -

PKCS#12 Data Management.

- -
-
pkcs7
-
- -

PKCS#7 Data Management.

- -
-
pkcs8
-
- -

PKCS#8 format private key conversion command.

- -
-
pkey
-
- -

Public and private key management.

- -
-
pkeyparam
-
- -

Public key algorithm parameter management.

- -
-
pkeyutl
-
- -

Public key algorithm cryptographic operation command.

- -
-
prime
-
- -

Compute prime numbers.

- -
-
rand
-
- -

Generate pseudo-random bytes.

- -
-
rehash
-
- -

Create symbolic links to certificate and CRL files named by the hash values.

- -
-
req
-
- -

PKCS#10 X.509 Certificate Signing Request (CSR) Management.

- -
-
rsa
-
- -

RSA key management.

- -
-
rsautl
-
- -

RSA command for signing, verification, encryption, and decryption. Superseded by openssl-pkeyutl(1).

- -
-
s_client
-
- -

This implements a generic SSL/TLS client which can establish a transparent connection to a remote server speaking SSL/TLS. It's intended for testing purposes only and provides only rudimentary interface functionality but internally uses mostly all functionality of the OpenSSL ssl library.

- -
-
s_server
-
- -

This implements a generic SSL/TLS server which accepts connections from remote clients speaking SSL/TLS. It's intended for testing purposes only and provides only rudimentary interface functionality but internally uses mostly all functionality of the OpenSSL ssl library. It provides both an own command line oriented protocol for testing SSL functions and a simple HTTP response facility to emulate an SSL/TLS-aware webserver.

- -
-
s_time
-
- -

SSL Connection Timer.

- -
-
sess_id
-
- -

SSL Session Data Management.

- -
-
smime
-
- -

S/MIME mail processing.

- -
-
speed
-
- -

Algorithm Speed Measurement.

- -
-
spkac
-
- -

SPKAC printing and generating command.

- -
-
srp
-
- -

Maintain SRP password file. This command is deprecated.

- -
-
storeutl
-
- -

Command to list and display certificates, keys, CRLs, etc.

- -
-
ts
-
- -

Time Stamping Authority command.

- -
-
verify
-
- -

X.509 Certificate Verification. See also the openssl-verification-options(1) manual page.

- -
-
version
-
- -

OpenSSL Version Information.

- -
-
x509
-
- -

X.509 Certificate Data Management.

- -
-
- -

Message Digest Commands

- -
- -
blake2b512
-
- -

BLAKE2b-512 Digest

- -
-
blake2s256
-
- -

BLAKE2s-256 Digest

- -
-
md2
-
- -

MD2 Digest

- -
-
md4
-
- -

MD4 Digest

- -
-
md5
-
- -

MD5 Digest

- -
-
mdc2
-
- -

MDC2 Digest

- -
-
rmd160
-
- -

RMD-160 Digest

- -
-
sha1
-
- -

SHA-1 Digest

- -
-
sha224
-
- -

SHA-2 224 Digest

- -
-
sha256
-
- -

SHA-2 256 Digest

- -
-
sha384
-
- -

SHA-2 384 Digest

- -
-
sha512
-
- -

SHA-2 512 Digest

- -
-
sha3-224
-
- -

SHA-3 224 Digest

- -
-
sha3-256
-
- -

SHA-3 256 Digest

- -
-
sha3-384
-
- -

SHA-3 384 Digest

- -
-
sha3-512
-
- -

SHA-3 512 Digest

- -
-
keccak-224
-
- -

KECCAK 224 Digest

- -
-
keccak-256
-
- -

KECCAK 256 Digest

- -
-
keccak-384
-
- -

KECCAK 384 Digest

- -
-
keccak-512
-
- -

KECCAK 512 Digest

- -
-
shake128
-
- -

SHA-3 SHAKE128 Digest

- -
-
shake256
-
- -

SHA-3 SHAKE256 Digest

- -
-
sm3
-
- -

SM3 Digest

- -
-
- -

Encryption, Decryption, and Encoding Commands

- -

The following aliases provide convenient access to the most used encodings and ciphers.

- -

Depending on how OpenSSL was configured and built, not all ciphers listed here may be present. See openssl-enc(1) for more information.

- -
- -
aes128, aes-128-cbc, aes-128-cfb, aes-128-ctr, aes-128-ecb, aes-128-ofb
-
- -

AES-128 Cipher

- -
-
aes192, aes-192-cbc, aes-192-cfb, aes-192-ctr, aes-192-ecb, aes-192-ofb
-
- -

AES-192 Cipher

- -
-
aes256, aes-256-cbc, aes-256-cfb, aes-256-ctr, aes-256-ecb, aes-256-ofb
-
- -

AES-256 Cipher

- -
-
aria128, aria-128-cbc, aria-128-cfb, aria-128-ctr, aria-128-ecb, aria-128-ofb
-
- -

Aria-128 Cipher

- -
-
aria192, aria-192-cbc, aria-192-cfb, aria-192-ctr, aria-192-ecb, aria-192-ofb
-
- -

Aria-192 Cipher

- -
-
aria256, aria-256-cbc, aria-256-cfb, aria-256-ctr, aria-256-ecb, aria-256-ofb
-
- -

Aria-256 Cipher

- -
-
base64
-
- -

Base64 Encoding

- -
-
bf, bf-cbc, bf-cfb, bf-ecb, bf-ofb
-
- -

Blowfish Cipher

- -
-
camellia128, camellia-128-cbc, camellia-128-cfb, camellia-128-ctr, camellia-128-ecb, camellia-128-ofb
-
- -

Camellia-128 Cipher

- -
-
camellia192, camellia-192-cbc, camellia-192-cfb, camellia-192-ctr, camellia-192-ecb, camellia-192-ofb
-
- -

Camellia-192 Cipher

- -
-
camellia256, camellia-256-cbc, camellia-256-cfb, camellia-256-ctr, camellia-256-ecb, camellia-256-ofb
-
- -

Camellia-256 Cipher

- -
-
cast, cast-cbc
-
- -

CAST Cipher

- -
-
cast5-cbc, cast5-cfb, cast5-ecb, cast5-ofb
-
- -

CAST5 Cipher

- -
-
chacha20
-
- -

Chacha20 Cipher

- -
-
des, des-cbc, des-cfb, des-ecb, des-ede, des-ede-cbc, des-ede-cfb, des-ede-ofb, des-ofb
-
- -

DES Cipher

- -
-
des3, desx, des-ede3, des-ede3-cbc, des-ede3-cfb, des-ede3-ofb
-
- -

Triple-DES Cipher

- -
-
idea, idea-cbc, idea-cfb, idea-ecb, idea-ofb
-
- -

IDEA Cipher

- -
-
rc2, rc2-cbc, rc2-cfb, rc2-ecb, rc2-ofb
-
- -

RC2 Cipher

- -
-
rc4
-
- -

RC4 Cipher

- -
-
rc5, rc5-cbc, rc5-cfb, rc5-ecb, rc5-ofb
-
- -

RC5 Cipher

- -
-
seed, seed-cbc, seed-cfb, seed-ecb, seed-ofb
-
- -

SEED Cipher

- -
-
sm4, sm4-cbc, sm4-cfb, sm4-ctr, sm4-ecb, sm4-ofb
-
- -

SM4 Cipher

- -
-
- -

OPTIONS

- -

Details of which options are available depend on the specific command. This section describes some common options with common behavior.

- -

Program Options

- -

These options can be specified without a command specified to get help or version information.

- -
- -
-help
-
- -

Provides a terse summary of all options. For more detailed information, each command supports a -help option. Accepts --help as well.

- -
-
-version
-
- -

Provides a terse summary of the openssl program version. For more detailed information see openssl-version(1). Accepts --version as well.

- -
-
- -

Common Options

- -
- -
-help
-
- -

If an option takes an argument, the "type" of argument is also given.

- -
-
--
-
- -

This terminates the list of options. It is mostly useful if any filename parameters start with a minus sign:

- -
openssl verify [flags...] -- -cert1.pem...
- -
-
- -

Format Options

- -

See openssl-format-options(1) for manual page.

- -

Pass Phrase Options

- -

See the openssl-passphrase-options(1) manual page.

- -

Random State Options

- -

Prior to OpenSSL 1.1.1, it was common for applications to store information about the state of the random-number generator in a file that was loaded at startup and rewritten upon exit. On modern operating systems, this is generally no longer necessary as OpenSSL will seed itself from a trusted entropy source provided by the operating system. These flags are still supported for special platforms or circumstances that might require them.

- -

It is generally an error to use the same seed file more than once and every use of -rand should be paired with -writerand.

- -
- -
-rand files
-
- -

A file or files containing random data used to seed the random number generator. Multiple files can be specified separated by an OS-dependent character. The separator is ; for MS-Windows, , for OpenVMS, and : for all others. Another way to specify multiple files is to repeat this flag with different filenames.

- -
-
-writerand file
-
- -

Writes the seed data to the specified file upon exit. This file can be used in a subsequent command invocation.

- -
-
- -

Certificate Verification Options

- -

See the openssl-verification-options(1) manual page.

- -

Name Format Options

- -

See the openssl-namedisplay-options(1) manual page.

- -

TLS Version Options

- -

Several commands use SSL, TLS, or DTLS. By default, the commands use TLS and clients will offer the lowest and highest protocol version they support, and servers will pick the highest version that the client offers that is also supported by the server.

- -

The options below can be used to limit which protocol versions are used, and whether TCP (SSL and TLS) or UDP (DTLS) is used. Note that not all protocols and flags may be available, depending on how OpenSSL was built.

- -
- -
-ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3, -no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3
-
- -

These options require or disable the use of the specified SSL or TLS protocols. When a specific TLS version is required, only that version will be offered or accepted. Only one specific protocol can be given and it cannot be combined with any of the no_ options. The no_* options do not work with s_time and ciphers commands but work with s_client and s_server commands.

- -
-
-dtls, -dtls1, -dtls1_2
-
- -

These options specify to use DTLS instead of TLS. With -dtls, clients will negotiate any supported DTLS protocol version. Use the -dtls1 or -dtls1_2 options to support only DTLS1.0 or DTLS1.2, respectively.

- -
-
- -

Engine Options

- -
- -
-engine id
-
- -

Load the engine identified by id and use all the methods it implements (algorithms, key storage, etc.), unless specified otherwise in the command-specific documentation or it is configured to do so, as described in "Engine Configuration" in config(5).

- -

The engine will be used for key ids specified with -key and similar options when an option like -keyform engine is given.

- -

A special case is the loader_attic engine, which is meant just for internal OpenSSL testing purposes and supports loading keys, parameters, certificates, and CRLs from files. When this engine is used, files with such credentials are read via this engine. Using the file: schema is optional; a plain file (path) name will do.

- -
-
- -

Options specifying keys, like -key and similar, can use the generic OpenSSL engine key loading URI scheme org.openssl.engine: to retrieve private keys and public keys. The URI syntax is as follows, in simplified form:

- -
org.openssl.engine:{engineid}:{keyid}
- -

Where {engineid} is the identity/name of the engine, and {keyid} is a key identifier that's acceptable by that engine. For example, when using an engine that interfaces against a PKCS#11 implementation, the generic key URI would be something like this (this happens to be an example for the PKCS#11 engine that's part of OpenSC):

- -
-key org.openssl.engine:pkcs11:label_some-private-key
- -

As a third possibility, for engines and providers that have implemented their own OSSL_STORE_LOADER(3), org.openssl.engine: should not be necessary. For a PKCS#11 implementation that has implemented such a loader, the PKCS#11 URI as defined in RFC 7512 should be possible to use directly:

- -
-key pkcs11:object=some-private-key;pin-value=1234
- -

Provider Options

- -
- -
-provider name
-
- -

Load and initialize the provider identified by name. The name can be also a path to the provider module. In that case the provider name will be the specified path and not just the provider module name. Interpretation of relative paths is platform specific. The configured "MODULESDIR" path, OPENSSL_MODULES environment variable, or the path specified by -provider-path is prepended to relative paths. See provider(7) for a more detailed description.

- -
-
-provider-path path
-
- -

Specifies the search path that is to be used for looking for providers. Equivalently, the OPENSSL_MODULES environment variable may be set.

- -
-
-propquery propq
-
- -

Specifies the property query clause to be used when fetching algorithms from the loaded providers. See property(7) for a more detailed description.

- -
-
- -

ENVIRONMENT

- -

The OpenSSL libraries can take some configuration parameters from the environment.

- -

For information about all environment variables used by the OpenSSL libraries, such as OPENSSL_CONF, OPENSSL_MODULES, and OPENSSL_TRACE, see openssl-env(7).

- -

For information about the use of environment variables in configuration, see "ENVIRONMENT" in config(5).

- -

For information about specific commands, see openssl-engine(1), openssl-rehash(1), and tsget(1).

- -

For information about querying or specifying CPU architecture flags, see OPENSSL_ia32cap(3), OPENSSL_s390xcap(3) and OPENSSL_riscvcap(3).

- -

SEE ALSO

- -

openssl-asn1parse(1), openssl-ca(1), openssl-ciphers(1), openssl-cms(1), openssl-crl(1), openssl-crl2pkcs7(1), openssl-dgst(1), openssl-dhparam(1), openssl-dsa(1), openssl-dsaparam(1), openssl-ec(1), openssl-ecparam(1), openssl-enc(1), openssl-engine(1), openssl-errstr(1), openssl-gendsa(1), openssl-genpkey(1), openssl-genrsa(1), openssl-kdf(1), openssl-list(1), openssl-mac(1), openssl-nseq(1), openssl-ocsp(1), openssl-passwd(1), openssl-pkcs12(1), openssl-pkcs7(1), openssl-pkcs8(1), openssl-pkey(1), openssl-pkeyparam(1), openssl-pkeyutl(1), openssl-prime(1), openssl-rand(1), openssl-rehash(1), openssl-req(1), openssl-rsa(1), openssl-rsautl(1), openssl-s_client(1), openssl-s_server(1), openssl-s_time(1), openssl-sess_id(1), openssl-smime(1), openssl-speed(1), openssl-spkac(1), openssl-srp(1), openssl-storeutl(1), openssl-ts(1), openssl-verify(1), openssl-version(1), openssl-x509(1), config(5), crypto(7), openssl-env(7). ssl(7), x509v3_config(5)

- -

HISTORY

- -

The list -XXX-algorithms options were added in OpenSSL 1.0.0; For notes on the availability of other commands, see their individual manual pages.

- -

The -issuer_checks option is deprecated as of OpenSSL 1.1.0 and is silently ignored.

- -

The -xcertform and -xkeyform options are obsolete since OpenSSL 3.0 and have no effect.

- -

The interactive mode, which could be invoked by running openssl with no further arguments, was removed in OpenSSL 3.0, and running that program with no arguments is now equivalent to openssl help.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man1/tsget.html b/openssl-install/share/doc/openssl/html/man1/tsget.html deleted file mode 100644 index 2723c219..00000000 --- a/openssl-install/share/doc/openssl/html/man1/tsget.html +++ /dev/null @@ -1,190 +0,0 @@ - - - - -tsget - - - - - - - - - - -

NAME

- -

tsget - Time Stamping HTTP/HTTPS client

- -

SYNOPSIS

- -

tsget -h server_url [-e extension] [-o output] [-v] [-d] [-k private_key.pem] [-p key_password] [-c client_cert.pem] [-C CA_certs.pem] [-P CA_path] [-r files] [-g EGD_socket] [request ...]

- -

DESCRIPTION

- -

This command can be used for sending a timestamp request, as specified in RFC 3161, to a timestamp server over HTTP or HTTPS and storing the timestamp response in a file. It cannot be used for creating the requests and verifying responses, you have to use openssl-ts(1) to do that. This command can send several requests to the server without closing the TCP connection if more than one requests are specified on the command line.

- -

This command sends the following HTTP request for each timestamp request:

- -
POST url HTTP/1.1
-User-Agent: OpenTSA tsget.pl/<version>
-Host: <host>:<port>
-Pragma: no-cache
-Content-Type: application/timestamp-query
-Accept: application/timestamp-reply
-Content-Length: length of body
-
-...binary request specified by the user...
- -

It expects a response of type application/timestamp-reply, which is written to a file without any interpretation.

- -

OPTIONS

- -
- -
-h server_url
-
- -

The URL of the HTTP/HTTPS server listening for timestamp requests.

- -
-
-e extension
-
- -

If the -o option is not given this argument specifies the extension of the output files. The base name of the output file will be the same as those of the input files. Default extension is .tsr. (Optional)

- -
-
-o output
-
- -

This option can be specified only when just one request is sent to the server. The timestamp response will be written to the given output file. '-' means standard output. In case of multiple timestamp requests or the absence of this argument the names of the output files will be derived from the names of the input files and the default or specified extension argument. (Optional)

- -
-
-v
-
- -

The name of the currently processed request is printed on standard error. (Optional)

- -
-
-d
-
- -

Switches on verbose mode for the underlying perl module WWW::Curl::Easy. You can see detailed debug messages for the connection. (Optional)

- -
-
-k private_key.pem
-
- -

(HTTPS) In case of certificate-based client authentication over HTTPS private_key.pem must contain the private key of the user. The private key file can optionally be protected by a passphrase. The -c option must also be specified. (Optional)

- -
-
-p key_password
-
- -

(HTTPS) Specifies the passphrase for the private key specified by the -k argument. If this option is omitted and the key is passphrase protected, it will be prompted for. (Optional)

- -
-
-c client_cert.pem
-
- -

(HTTPS) In case of certificate-based client authentication over HTTPS client_cert.pem must contain the X.509 certificate of the user. The -k option must also be specified. If this option is not specified no certificate-based client authentication will take place. (Optional)

- -
-
-C CA_certs.pem
-
- -

(HTTPS) The trusted CA certificate store. The certificate chain of the peer's certificate must include one of the CA certificates specified in this file. Either option -C or option -P must be given in case of HTTPS. (Optional)

- -
-
-P CA_path
-
- -

(HTTPS) The path containing the trusted CA certificates to verify the peer's certificate. The directory must be prepared with openssl-rehash(1). Either option -C or option -P must be given in case of HTTPS. (Optional)

- -
-
-r files
-
- -

See "Random State Options" in openssl(1) for more information.

- -
-
-g EGD_socket
-
- -

The name of an EGD socket to get random data from. (Optional)

- -
-
request ...
-
- -

List of files containing RFC 3161 DER-encoded timestamp requests. If no requests are specified only one request will be sent to the server and it will be read from the standard input. (Optional)

- -
-
- -

ENVIRONMENT VARIABLES

- -

The TSGET environment variable can optionally contain default arguments. The content of this variable is added to the list of command line arguments.

- -

EXAMPLES

- -

The examples below presume that file1.tsq and file2.tsq contain valid timestamp requests, tsa.opentsa.org listens at port 8080 for HTTP requests and at port 8443 for HTTPS requests, the TSA service is available at the /tsa absolute path.

- -

Get a timestamp response for file1.tsq over HTTP, output is written to file1.tsr:

- -
tsget -h http://tsa.opentsa.org:8080/tsa file1.tsq
- -

Get a timestamp response for file1.tsq and file2.tsq over HTTP showing progress, output is written to file1.reply and file2.reply respectively:

- -
tsget -h http://tsa.opentsa.org:8080/tsa -v -e .reply \
-      file1.tsq file2.tsq
- -

Create a timestamp request, write it to file3.tsq, send it to the server and write the response to file3.tsr:

- -
openssl ts -query -data file3.txt -cert | tee file3.tsq \
-      | tsget -h http://tsa.opentsa.org:8080/tsa \
-      -o file3.tsr
- -

Get a timestamp response for file1.tsq over HTTPS without client authentication:

- -
tsget -h https://tsa.opentsa.org:8443/tsa \
-      -C cacerts.pem file1.tsq
- -

Get a timestamp response for file1.tsq over HTTPS with certificate-based client authentication (it will ask for the passphrase if client_key.pem is protected):

- -
tsget -h https://tsa.opentsa.org:8443/tsa -C cacerts.pem \
-      -k client_key.pem -c client_cert.pem file1.tsq
- -

You can shorten the previous command line if you make use of the TSGET environment variable. The following commands do the same as the previous example:

- -
TSGET='-h https://tsa.opentsa.org:8443/tsa -C cacerts.pem \
-      -k client_key.pem -c client_cert.pem'
-export TSGET
-tsget file1.tsq
- -

SEE ALSO

- -

openssl(1), openssl-ts(1), WWW::Curl::Easy, https://www.rfc-editor.org/rfc/rfc3161.html

- -

COPYRIGHT

- -

Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ADMISSIONS.html b/openssl-install/share/doc/openssl/html/man3/ADMISSIONS.html deleted file mode 100644 index 46e60813..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ADMISSIONS.html +++ /dev/null @@ -1,120 +0,0 @@ - - - - -ADMISSIONS - - - - - - - - - - -

NAME

- -

ADMISSIONS, ADMISSIONS_get0_admissionAuthority, ADMISSIONS_get0_namingAuthority, ADMISSIONS_get0_professionInfos, ADMISSIONS_set0_admissionAuthority, ADMISSIONS_set0_namingAuthority, ADMISSIONS_set0_professionInfos, ADMISSION_SYNTAX, ADMISSION_SYNTAX_get0_admissionAuthority, ADMISSION_SYNTAX_get0_contentsOfAdmissions, ADMISSION_SYNTAX_set0_admissionAuthority, ADMISSION_SYNTAX_set0_contentsOfAdmissions, NAMING_AUTHORITY, NAMING_AUTHORITY_get0_authorityId, NAMING_AUTHORITY_get0_authorityURL, NAMING_AUTHORITY_get0_authorityText, NAMING_AUTHORITY_set0_authorityId, NAMING_AUTHORITY_set0_authorityURL, NAMING_AUTHORITY_set0_authorityText, PROFESSION_INFO, PROFESSION_INFOS, PROFESSION_INFO_get0_addProfessionInfo, PROFESSION_INFO_get0_namingAuthority, PROFESSION_INFO_get0_professionItems, PROFESSION_INFO_get0_professionOIDs, PROFESSION_INFO_get0_registrationNumber, PROFESSION_INFO_set0_addProfessionInfo, PROFESSION_INFO_set0_namingAuthority, PROFESSION_INFO_set0_professionItems, PROFESSION_INFO_set0_professionOIDs, PROFESSION_INFO_set0_registrationNumber - Accessors and settors for ADMISSION_SYNTAX

- -

SYNOPSIS

- -
typedef struct NamingAuthority_st NAMING_AUTHORITY;
-typedef struct ProfessionInfo_st PROFESSION_INFO;
-typedef STACK_OF(PROFESSION_INFO) PROFESSION_INFOS;
-typedef struct Admissions_st ADMISSIONS;
-typedef struct AdmissionSyntax_st ADMISSION_SYNTAX;
-
-const ASN1_OBJECT *NAMING_AUTHORITY_get0_authorityId(
-    const NAMING_AUTHORITY *n);
-void NAMING_AUTHORITY_set0_authorityId(NAMING_AUTHORITY *n,
-    ASN1_OBJECT* namingAuthorityId);
-const ASN1_IA5STRING *NAMING_AUTHORITY_get0_authorityURL(
-    const NAMING_AUTHORITY *n);
-void NAMING_AUTHORITY_set0_authorityURL(NAMING_AUTHORITY *n,
-    ASN1_IA5STRING* namingAuthorityUrl);
-const ASN1_STRING *NAMING_AUTHORITY_get0_authorityText(
-    const NAMING_AUTHORITY *n);
-void NAMING_AUTHORITY_set0_authorityText(NAMING_AUTHORITY *n,
-    ASN1_STRING* namingAuthorityText);
-
-const GENERAL_NAME *ADMISSION_SYNTAX_get0_admissionAuthority(
-    const ADMISSION_SYNTAX *as);
-void ADMISSION_SYNTAX_set0_admissionAuthority(
-    ADMISSION_SYNTAX *as, GENERAL_NAME *aa);
-const STACK_OF(ADMISSIONS) *ADMISSION_SYNTAX_get0_contentsOfAdmissions(
-    const ADMISSION_SYNTAX *as);
-void ADMISSION_SYNTAX_set0_contentsOfAdmissions(
-    ADMISSION_SYNTAX *as, STACK_OF(ADMISSIONS) *a);
-
-const GENERAL_NAME *ADMISSIONS_get0_admissionAuthority(const ADMISSIONS *a);
-void ADMISSIONS_set0_admissionAuthority(ADMISSIONS *a, GENERAL_NAME *aa);
-const NAMING_AUTHORITY *ADMISSIONS_get0_namingAuthority(const ADMISSIONS *a);
-void ADMISSIONS_set0_namingAuthority(ADMISSIONS *a, NAMING_AUTHORITY *na);
-const PROFESSION_INFOS *ADMISSIONS_get0_professionInfos(const ADMISSIONS *a);
-void ADMISSIONS_set0_professionInfos(ADMISSIONS *a, PROFESSION_INFOS *pi);
-
-const ASN1_OCTET_STRING *PROFESSION_INFO_get0_addProfessionInfo(
-    const PROFESSION_INFO *pi);
-void PROFESSION_INFO_set0_addProfessionInfo(
-    PROFESSION_INFO *pi, ASN1_OCTET_STRING *aos);
-const NAMING_AUTHORITY *PROFESSION_INFO_get0_namingAuthority(
-    const PROFESSION_INFO *pi);
-void PROFESSION_INFO_set0_namingAuthority(
-    PROFESSION_INFO *pi, NAMING_AUTHORITY *na);
-const STACK_OF(ASN1_STRING) *PROFESSION_INFO_get0_professionItems(
-    const PROFESSION_INFO *pi);
-void PROFESSION_INFO_set0_professionItems(
-    PROFESSION_INFO *pi, STACK_OF(ASN1_STRING) *as);
-const STACK_OF(ASN1_OBJECT) *PROFESSION_INFO_get0_professionOIDs(
-    const PROFESSION_INFO *pi);
-void PROFESSION_INFO_set0_professionOIDs(
-    PROFESSION_INFO *pi, STACK_OF(ASN1_OBJECT) *po);
-const ASN1_PRINTABLESTRING *PROFESSION_INFO_get0_registrationNumber(
-    const PROFESSION_INFO *pi);
-void PROFESSION_INFO_set0_registrationNumber(
-    PROFESSION_INFO *pi, ASN1_PRINTABLESTRING *rn);
- -

DESCRIPTION

- -

The PROFESSION_INFOS, ADMISSION_SYNTAX, ADMISSIONS, and PROFESSION_INFO types are opaque structures representing the analogous types defined in the Common PKI Specification published by https://www.t7ev.org. Knowledge of those structures and their semantics is assumed.

- -

The conventional routines to convert between DER and the local format are described in d2i_X509(3). The conventional routines to allocate and free the types are defined in X509_dup(3).

- -

The PROFESSION_INFOS type is a stack of PROFESSION_INFO; see DEFINE_STACK_OF(3) for details.

- -

The NAMING_AUTHORITY type has an authority ID and URL, and text fields. The NAMING_AUTHORITY_get0_authorityId(), NAMING_AUTHORITY_get0_get0_authorityURL(), and NAMING_AUTHORITY_get0_get0_authorityText(), functions return pointers to those values within the object. The NAMING_AUTHORITY_set0_authorityId(), NAMING_AUTHORITY_set0_get0_authorityURL(), and NAMING_AUTHORITY_set0_get0_authorityText(), functions free any existing value and set the pointer to the specified value.

- -

The ADMISSION_SYNTAX type has an authority name and a stack of ADMISSION objects. The ADMISSION_SYNTAX_get0_admissionAuthority() and ADMISSION_SYNTAX_get0_contentsOfAdmissions() functions return pointers to those values within the object. The ADMISSION_SYNTAX_set0_admissionAuthority() and ADMISSION_SYNTAX_set0_contentsOfAdmissions() functions free any existing value and set the pointer to the specified value.

- -

The ADMISSION type has an authority name, authority object, and a stack of PROFESSION_INFO items. The ADMISSIONS_get0_admissionAuthority(), ADMISSIONS_get0_namingAuthority(), and ADMISSIONS_get0_professionInfos() functions return pointers to those values within the object. The ADMISSIONS_set0_admissionAuthority(), ADMISSIONS_set0_namingAuthority(), and ADMISSIONS_set0_professionInfos() functions free any existing value and set the pointer to the specified value.

- -

The PROFESSION_INFO type has a name authority, stacks of profession Items and OIDs, a registration number, and additional profession info. The functions PROFESSION_INFO_get0_addProfessionInfo(), PROFESSION_INFO_get0_namingAuthority(), PROFESSION_INFO_get0_professionItems(), PROFESSION_INFO_get0_professionOIDs(), and PROFESSION_INFO_get0_registrationNumber() functions return pointers to those values within the object. The PROFESSION_INFO_set0_addProfessionInfo(), PROFESSION_INFO_set0_namingAuthority(), PROFESSION_INFO_set0_professionItems(), PROFESSION_INFO_set0_professionOIDs(), and PROFESSION_INFO_set0_registrationNumber() functions free any existing value and set the pointer to the specified value.

- -

RETURN VALUES

- -

Described above. Note that all of the get0 functions return a pointer to the internal data structure and must not be freed.

- -

SEE ALSO

- -

X509_dup(3), d2i_X509(3),

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_EXTERN_FUNCS.html b/openssl-install/share/doc/openssl/html/man3/ASN1_EXTERN_FUNCS.html deleted file mode 100644 index 98c66b4d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_EXTERN_FUNCS.html +++ /dev/null @@ -1,169 +0,0 @@ - - - - -ASN1_EXTERN_FUNCS - - - - - - - - - - -

NAME

- -

ASN1_EXTERN_FUNCS, ASN1_ex_d2i, ASN1_ex_d2i_ex, ASN1_ex_i2d, ASN1_ex_new_func, ASN1_ex_new_ex_func, ASN1_ex_free_func, ASN1_ex_print_func, IMPLEMENT_EXTERN_ASN1 - ASN.1 external function support

- -

SYNOPSIS

- -
#include <openssl/asn1t.h>
-
-typedef int ASN1_ex_d2i(ASN1_VALUE **pval, const unsigned char **in, long len,
-                        const ASN1_ITEM *it, int tag, int aclass, char opt,
-                        ASN1_TLC *ctx);
-typedef int ASN1_ex_d2i_ex(ASN1_VALUE **pval, const unsigned char **in, long len,
-                           const ASN1_ITEM *it, int tag, int aclass, char opt,
-                           ASN1_TLC *ctx, OSSL_LIB_CTX *libctx,
-                           const char *propq);
-typedef int ASN1_ex_i2d(const ASN1_VALUE **pval, unsigned char **out,
-                        const ASN1_ITEM *it, int tag, int aclass);
-typedef int ASN1_ex_new_func(ASN1_VALUE **pval, const ASN1_ITEM *it);
-typedef int ASN1_ex_new_ex_func(ASN1_VALUE **pval, const ASN1_ITEM *it,
-                                OSSL_LIB_CTX *libctx, const char *propq);
-typedef void ASN1_ex_free_func(ASN1_VALUE **pval, const ASN1_ITEM *it);
-typedef int ASN1_ex_print_func(BIO *out, const ASN1_VALUE **pval,
-                               int indent, const char *fname,
-                               const ASN1_PCTX *pctx);
-
-struct ASN1_EXTERN_FUNCS_st {
-   void *app_data;
-   ASN1_ex_new_func *asn1_ex_new;
-   ASN1_ex_free_func *asn1_ex_free;
-   ASN1_ex_free_func *asn1_ex_clear;
-   ASN1_ex_d2i *asn1_ex_d2i;
-   ASN1_ex_i2d *asn1_ex_i2d;
-   ASN1_ex_print_func *asn1_ex_print;
-   ASN1_ex_new_ex_func *asn1_ex_new_ex;
-   ASN1_ex_d2i_ex *asn1_ex_d2i_ex;
-};
-typedef struct ASN1_EXTERN_FUNCS_st ASN1_EXTERN_FUNCS;
-
-#define IMPLEMENT_EXTERN_ASN1(sname, tag, fptrs)
- -

DESCRIPTION

- -

ASN.1 data structures templates are typically defined in OpenSSL using a series of macros such as ASN1_SEQUENCE(), ASN1_SEQUENCE_END() and so on. Instead templates can also be defined based entirely on external functions. These external functions are called to perform operations such as creating a new ASN1_VALUE or converting an ASN1_VALUE to or from DER encoding.

- -

The macro IMPLEMENT_EXTERN_ASN1() can be used to create such an externally defined structure. The name of the structure should be supplied in the sname parameter. The tag for the structure (e.g. typically V_ASN1_SEQUENCE) should be supplied in the tag parameter. Finally a pointer to an ASN1_EXTERN_FUNCS structure should be supplied in the fptrs parameter.

- -

The ASN1_EXTERN_FUNCS structure has the following entries.

- -
- -
app_data
-
- -

A pointer to arbitrary application specific data.

- -
-
asn1_ex_new
-
- -

A "new" function responsible for constructing a new ASN1_VALUE object. The newly constructed value should be stored in *pval. The it parameter is a pointer to the ASN1_ITEM template object created via the IMPLEMENT_EXTERN_ASN1() macro.

- -

Returns a positive value on success or 0 on error.

- -
-
asn1_ex_free
-
- -

A "free" function responsible for freeing the ASN1_VALUE passed in *pval that was previously allocated via a "new" function. The it parameter is a pointer to the ASN1_ITEM template object created via the IMPLEMENT_EXTERN_ASN1() macro.

- -
-
asn1_ex_clear
-
- -

A "clear" function responsible for clearing any data in the ASN1_VALUE passed in *pval and making it suitable for reuse. The it parameter is a pointer to the ASN1_ITEM template object created via the IMPLEMENT_EXTERN_ASN1() macro.

- -
-
asn1_ex_d2i
-
- -

A "d2i" function responsible for converting DER data with the tag tag and class class into an ASN1_VALUE. If *pval is non-NULL then the ASN_VALUE it points to should be reused. Otherwise a new ASN1_VALUE should be allocated and stored in *pval. *in points to the DER data to be decoded and len is the length of that data. After decoding *in should be updated to point at the next byte after the decoded data. If the ASN1_VALUE is considered optional in this context then opt will be nonzero. Otherwise it will be zero. The it parameter is a pointer to the ASN1_ITEM template object created via the IMPLEMENT_EXTERN_ASN1() macro. A pointer to the current ASN1_TLC context (which may be required for other ASN1 function calls) is passed in the ctx parameter.

- -

The asn1_ex_d2i entry may be NULL if asn1_ex_d2i_ex has been specified instead.

- -

Returns <= 0 on error or a positive value on success.

- -
-
asn1_ex_i2d
-
- -

An "i2d" function responsible for converting an ASN1_VALUE into DER encoding. On entry *pval will contain the ASN1_VALUE to be encoded. If default tagging is to be used then tag will be -1 on entry. Otherwise if implicit tagging should be used then tag and aclass will be the tag and associated class.

- -

If out is not NULL then this function should write the DER encoded data to the buffer in *out, and then increment *out to point to immediately after the data just written.

- -

If out is NULL then no data should be written but the length calculated and returned as if it were.

- -

The asn1_ex_i2d entry may be NULL if asn1_ex_i2d_ex has been specified instead.

- -

The return value should be negative if a fatal error occurred, or 0 if a non-fatal error occurred. Otherwise it should return the length of the encoded data.

- -
-
asn1_ex_print
-
- -

A "print" function. out is the BIO to print the output to. *pval is the ASN1_VALUE to be printed. indent is the number of spaces of indenting to be printed before any data is printed. fname is currently unused and is always "". pctx is a pointer to the ASN1_PCTX for the print operation.

- -

Returns 0 on error or a positive value on success. If the return value is 2 then an additional newline will be printed after the data printed by this function.

- -
-
asn1_ex_new_ex
-
- -

This is the same as asn1_ex_new except that it is additionally passed the OSSL_LIB_CTX to be used in libctx and any property query string to be used for algorithm fetching in the propq parameter. See "ALGORITHM FETCHING" in crypto(7) for further details. If asn1_ex_new_ex is non NULL, then it will always be called in preference to asn1_ex_new.

- -
-
asn1_ex_d2i_ex
-
- -

This is the same as asn1_ex_d2i except that it is additionally passed the OSSL_LIB_CTX to be used in libctx and any property query string to be used for algorithm fetching in the propq parameter. See "ALGORITHM FETCHING" in crypto(7) for further details. If asn1_ex_d2i_ex is non NULL, then it will always be called in preference to asn1_ex_d2i.

- -
-
- -

RETURN VALUES

- -

Return values for the various callbacks are as described above.

- -

SEE ALSO

- -

ASN1_item_new_ex(3)

- -

HISTORY

- -

The asn1_ex_new_ex and asn1_ex_d2i_ex callbacks were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_get_int64.html b/openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_get_int64.html deleted file mode 100644 index 96b65ef1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_get_int64.html +++ /dev/null @@ -1,116 +0,0 @@ - - - - -ASN1_INTEGER_get_int64 - - - - - - - - - - -

NAME

- -

ASN1_INTEGER_get_uint64, ASN1_INTEGER_set_uint64, ASN1_INTEGER_get_int64, ASN1_INTEGER_get, ASN1_INTEGER_set_int64, ASN1_INTEGER_set, BN_to_ASN1_INTEGER, ASN1_INTEGER_to_BN, ASN1_ENUMERATED_get_int64, ASN1_ENUMERATED_get, ASN1_ENUMERATED_set_int64, ASN1_ENUMERATED_set, BN_to_ASN1_ENUMERATED, ASN1_ENUMERATED_to_BN - ASN.1 INTEGER and ENUMERATED utilities

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-int ASN1_INTEGER_get_int64(int64_t *pr, const ASN1_INTEGER *a);
-long ASN1_INTEGER_get(const ASN1_INTEGER *a);
-
-int ASN1_INTEGER_set_int64(ASN1_INTEGER *a, int64_t r);
-int ASN1_INTEGER_set(ASN1_INTEGER *a, long v);
-
-int ASN1_INTEGER_get_uint64(uint64_t *pr, const ASN1_INTEGER *a);
-int ASN1_INTEGER_set_uint64(ASN1_INTEGER *a, uint64_t r);
-
-ASN1_INTEGER *BN_to_ASN1_INTEGER(const BIGNUM *bn, ASN1_INTEGER *ai);
-BIGNUM *ASN1_INTEGER_to_BN(const ASN1_INTEGER *ai, BIGNUM *bn);
-
-int ASN1_ENUMERATED_get_int64(int64_t *pr, const ASN1_ENUMERATED *a);
-long ASN1_ENUMERATED_get(const ASN1_ENUMERATED *a);
-
-int ASN1_ENUMERATED_set_int64(ASN1_ENUMERATED *a, int64_t r);
-int ASN1_ENUMERATED_set(ASN1_ENUMERATED *a, long v);
-
-ASN1_ENUMERATED *BN_to_ASN1_ENUMERATED(const BIGNUM *bn, ASN1_ENUMERATED *ai);
-BIGNUM *ASN1_ENUMERATED_to_BN(const ASN1_ENUMERATED *ai, BIGNUM *bn);
- -

DESCRIPTION

- -

These functions convert to and from ASN1_INTEGER and ASN1_ENUMERATED structures.

- -

ASN1_INTEGER_get_int64() converts an ASN1_INTEGER into an int64_t type If successful it returns 1 and sets *pr to the value of a. If it fails (due to invalid type or the value being too big to fit into an int64_t type) it returns 0.

- -

ASN1_INTEGER_get_uint64() is similar to ASN1_INTEGER_get_int64_t() except it converts to a uint64_t type and an error is returned if the passed integer is negative.

- -

ASN1_INTEGER_get() also returns the value of a but it returns 0 if a is NULL and -1 on error (which is ambiguous because -1 is a legitimate value for an ASN1_INTEGER). New applications should use ASN1_INTEGER_get_int64() instead.

- -

ASN1_INTEGER_set_int64() sets the value of ASN1_INTEGER a to the int64_t value r.

- -

ASN1_INTEGER_set_uint64() sets the value of ASN1_INTEGER a to the uint64_t value r.

- -

ASN1_INTEGER_set() sets the value of ASN1_INTEGER a to the long value v.

- -

BN_to_ASN1_INTEGER() converts BIGNUM bn to an ASN1_INTEGER. If ai is NULL a new ASN1_INTEGER structure is returned. If ai is not NULL then the existing structure will be used instead.

- -

ASN1_INTEGER_to_BN() converts ASN1_INTEGER ai into a BIGNUM. If bn is NULL a new BIGNUM structure is returned. If bn is not NULL then the existing structure will be used instead.

- -

ASN1_ENUMERATED_get_int64(), ASN1_ENUMERATED_set_int64(), ASN1_ENUMERATED_set(), BN_to_ASN1_ENUMERATED() and ASN1_ENUMERATED_to_BN() behave in an identical way to their ASN1_INTEGER counterparts except they operate on an ASN1_ENUMERATED value.

- -

ASN1_ENUMERATED_get() returns the value of a in a similar way to ASN1_INTEGER_get() but it returns 0xffffffffL if the value of a will not fit in a long type. New applications should use ASN1_ENUMERATED_get_int64() instead.

- -

NOTES

- -

In general an ASN1_INTEGER or ASN1_ENUMERATED type can contain an integer of almost arbitrary size and so cannot always be represented by a C int64_t type. However, in many cases (for example version numbers) they represent small integers which can be more easily manipulated if converted to an appropriate C integer type.

- -

BUGS

- -

The ambiguous return values of ASN1_INTEGER_get() and ASN1_ENUMERATED_get() mean these functions should be avoided if possible. They are retained for compatibility. Normally the ambiguous return values are not legitimate values for the fields they represent.

- -

RETURN VALUES

- -

ASN1_INTEGER_set_int64(), ASN1_INTEGER_set(), ASN1_ENUMERATED_set_int64() and ASN1_ENUMERATED_set() return 1 for success and 0 for failure. They will only fail if a memory allocation error occurs.

- -

ASN1_INTEGER_get_int64() and ASN1_ENUMERATED_get_int64() return 1 for success and 0 for failure. They will fail if the passed type is incorrect (this will only happen if there is a programming error) or if the value exceeds the range of an int64_t type.

- -

BN_to_ASN1_INTEGER() and BN_to_ASN1_ENUMERATED() return an ASN1_INTEGER or ASN1_ENUMERATED structure respectively or NULL if an error occurs. They will only fail due to a memory allocation error.

- -

ASN1_INTEGER_to_BN() and ASN1_ENUMERATED_to_BN() return a BIGNUM structure of NULL if an error occurs. They can fail if the passed type is incorrect (due to programming error) or due to a memory allocation failure.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

HISTORY

- -

ASN1_INTEGER_set_int64(), ASN1_INTEGER_get_int64(), ASN1_ENUMERATED_set_int64() and ASN1_ENUMERATED_get_int64() were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_new.html b/openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_new.html deleted file mode 100644 index b441806e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_INTEGER_new.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -ASN1_INTEGER_new - - - - - - - - - - -

NAME

- -

ASN1_INTEGER_new, ASN1_INTEGER_free - ASN1_INTEGER allocation functions

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-ASN1_INTEGER *ASN1_INTEGER_new(void);
-void ASN1_INTEGER_free(ASN1_INTEGER *a);
- -

DESCRIPTION

- -

ASN1_INTEGER_new() returns an allocated ASN1_INTEGER structure.

- -

ASN1_INTEGER_free() frees up a single ASN1_INTEGER object. If the argument is NULL, nothing is done.

- -

ASN1_INTEGER structure representing the ASN.1 INTEGER type

- -

RETURN VALUES

- -

ASN1_INTEGER_new() return a valid ASN1_INTEGER structure or NULL if an error occurred.

- -

ASN1_INTEGER_free() does not return a value.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_ITEM_lookup.html b/openssl-install/share/doc/openssl/html/man3/ASN1_ITEM_lookup.html deleted file mode 100644 index a767f029..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_ITEM_lookup.html +++ /dev/null @@ -1,59 +0,0 @@ - - - - -ASN1_ITEM_lookup - - - - - - - - - - -

NAME

- -

ASN1_ITEM_lookup, ASN1_ITEM_get - lookup ASN.1 structures

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-const ASN1_ITEM *ASN1_ITEM_lookup(const char *name);
-const ASN1_ITEM *ASN1_ITEM_get(size_t i);
- -

DESCRIPTION

- -

ASN1_ITEM_lookup() returns the ASN1_ITEM named name.

- -

ASN1_ITEM_get() returns the ASN1_ITEM with index i. This function returns NULL if the index i is out of range.

- -

RETURN VALUES

- -

ASN1_ITEM_lookup() and ASN1_ITEM_get() return a valid ASN1_ITEM structure or NULL if an error occurred.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_OBJECT_new.html b/openssl-install/share/doc/openssl/html/man3/ASN1_OBJECT_new.html deleted file mode 100644 index e75881dd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_OBJECT_new.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -ASN1_OBJECT_new - - - - - - - - - - -

NAME

- -

ASN1_OBJECT_new, ASN1_OBJECT_free - object allocation functions

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-ASN1_OBJECT *ASN1_OBJECT_new(void);
-void ASN1_OBJECT_free(ASN1_OBJECT *a);
- -

DESCRIPTION

- -

The ASN1_OBJECT allocation routines, allocate and free an ASN1_OBJECT structure, which represents an ASN1 OBJECT IDENTIFIER.

- -

ASN1_OBJECT_new() allocates and initializes an ASN1_OBJECT structure.

- -

ASN1_OBJECT_free() frees up the ASN1_OBJECT structure a. If a is NULL, nothing is done.

- -

NOTES

- -

Although ASN1_OBJECT_new() allocates a new ASN1_OBJECT structure it is almost never used in applications. The ASN1 object utility functions such as OBJ_nid2obj() are used instead.

- -

RETURN VALUES

- -

If the allocation fails, ASN1_OBJECT_new() returns NULL and sets an error code that can be obtained by ERR_get_error(3). Otherwise it returns a pointer to the newly allocated structure.

- -

ASN1_OBJECT_free() returns no value.

- -

SEE ALSO

- -

ERR_get_error(3), d2i_ASN1_OBJECT(3)

- -

COPYRIGHT

- -

Copyright 2002-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_TABLE_add.html b/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_TABLE_add.html deleted file mode 100644 index 47cafa5c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_TABLE_add.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -ASN1_STRING_TABLE_add - - - - - - - - - - -

NAME

- -

ASN1_STRING_TABLE, ASN1_STRING_TABLE_add, ASN1_STRING_TABLE_get, ASN1_STRING_TABLE_cleanup - ASN1_STRING_TABLE manipulation functions

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-typedef struct asn1_string_table_st ASN1_STRING_TABLE;
-
-int ASN1_STRING_TABLE_add(int nid, long minsize, long maxsize,
-                          unsigned long mask, unsigned long flags);
-ASN1_STRING_TABLE *ASN1_STRING_TABLE_get(int nid);
-void ASN1_STRING_TABLE_cleanup(void);
- -

DESCRIPTION

- -

Types

- -

ASN1_STRING_TABLE is a table which holds string information (basically minimum size, maximum size, type and etc) for a NID object.

- -

Functions

- -

ASN1_STRING_TABLE_add() adds a new ASN1_STRING_TABLE item into the local ASN1 string table based on the nid along with other parameters.

- -

If the item is already in the table, fields of ASN1_STRING_TABLE are updated (depending on the values of those parameters, e.g., minsize and maxsize >= 0, mask and flags != 0). If the nid is standard, a copy of the standard ASN1_STRING_TABLE is created and updated with other parameters.

- -

ASN1_STRING_TABLE_get() searches for an ASN1_STRING_TABLE item based on nid. It will search the local table first, then the standard one.

- -

ASN1_STRING_TABLE_cleanup() frees all ASN1_STRING_TABLE items added by ASN1_STRING_TABLE_add().

- -

RETURN VALUES

- -

ASN1_STRING_TABLE_add() returns 1 on success, 0 if an error occurred.

- -

ASN1_STRING_TABLE_get() returns a valid ASN1_STRING_TABLE structure or NULL if nothing is found.

- -

ASN1_STRING_TABLE_cleanup() does not return a value.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_length.html b/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_length.html deleted file mode 100644 index 7721b0b1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_length.html +++ /dev/null @@ -1,107 +0,0 @@ - - - - -ASN1_STRING_length - - - - - - - - - - -

NAME

- -

ASN1_STRING_dup, ASN1_STRING_cmp, ASN1_STRING_set, ASN1_STRING_length, ASN1_STRING_type, ASN1_STRING_get0_data, ASN1_STRING_data, ASN1_STRING_to_UTF8 - ASN1_STRING utility functions

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-int ASN1_STRING_length(ASN1_STRING *x);
-const unsigned char *ASN1_STRING_get0_data(const ASN1_STRING *x);
-unsigned char *ASN1_STRING_data(ASN1_STRING *x);
-
-ASN1_STRING *ASN1_STRING_dup(const ASN1_STRING *a);
-
-int ASN1_STRING_cmp(ASN1_STRING *a, ASN1_STRING *b);
-
-int ASN1_STRING_set(ASN1_STRING *str, const void *data, int len);
-
-int ASN1_STRING_type(const ASN1_STRING *x);
-
-int ASN1_STRING_to_UTF8(unsigned char **out, const ASN1_STRING *in);
- -

DESCRIPTION

- -

These functions allow an ASN1_STRING structure to be manipulated.

- -

ASN1_STRING_length() returns the length of the content of x.

- -

ASN1_STRING_get0_data() returns an internal pointer to the data of x. Since this is an internal pointer it should not be freed or modified in any way.

- -

ASN1_STRING_data() is similar to ASN1_STRING_get0_data() except the returned value is not constant. This function is deprecated: applications should use ASN1_STRING_get0_data() instead.

- -

ASN1_STRING_dup() returns a copy of the structure a.

- -

ASN1_STRING_cmp() compares a and b returning 0 if the two are identical. The string types and content are compared.

- -

ASN1_STRING_set() sets the data of string str to the buffer data or length len. The supplied data is copied. If len is -1 then the length is determined by strlen(data).

- -

ASN1_STRING_type() returns the type of x, using standard constants such as V_ASN1_OCTET_STRING.

- -

ASN1_STRING_to_UTF8() converts the string in to UTF8 format, the converted data is allocated in a buffer in *out. The length of out is returned or a negative error code. The buffer *out should be freed using OPENSSL_free().

- -

NOTES

- -

Almost all ASN1 types in OpenSSL are represented as an ASN1_STRING structure. Other types such as ASN1_OCTET_STRING are simply typedef'ed to ASN1_STRING and the functions call the ASN1_STRING equivalents. ASN1_STRING is also used for some CHOICE types which consist entirely of primitive string types such as DirectoryString and Time.

- -

These functions should not be used to examine or modify ASN1_INTEGER or ASN1_ENUMERATED types: the relevant INTEGER or ENUMERATED utility functions should be used instead.

- -

In general it cannot be assumed that the data returned by ASN1_STRING_data() is null terminated or does not contain embedded nulls. The actual format of the data will depend on the actual string type itself: for example for an IA5String the data will be ASCII, for a BMPString two bytes per character in big endian format, and for a UTF8String it will be in UTF8 format.

- -

Similar care should be take to ensure the data is in the correct format when calling ASN1_STRING_set().

- -

RETURN VALUES

- -

ASN1_STRING_length() returns the length of the content of x.

- -

ASN1_STRING_get0_data() and ASN1_STRING_data() return an internal pointer to the data of x.

- -

ASN1_STRING_dup() returns a valid ASN1_STRING structure or NULL if an error occurred.

- -

ASN1_STRING_cmp() returns an integer greater than, equal to, or less than 0, according to whether a is greater than, equal to, or less than b.

- -

ASN1_STRING_set() returns 1 on success or 0 on error.

- -

ASN1_STRING_type() returns the type of x.

- -

ASN1_STRING_to_UTF8() returns the number of bytes in output string out or a negative value if an error occurred.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_new.html b/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_new.html deleted file mode 100644 index 9c16bcf4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_new.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -ASN1_STRING_new - - - - - - - - - - -

NAME

- -

ASN1_STRING_new, ASN1_STRING_type_new, ASN1_STRING_free - ASN1_STRING allocation functions

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-ASN1_STRING *ASN1_STRING_new(void);
-ASN1_STRING *ASN1_STRING_type_new(int type);
-void ASN1_STRING_free(ASN1_STRING *a);
- -

DESCRIPTION

- -

ASN1_STRING_new() returns an allocated ASN1_STRING structure. Its type is undefined.

- -

ASN1_STRING_type_new() returns an allocated ASN1_STRING structure of type type.

- -

ASN1_STRING_free() frees up a. If a is NULL nothing is done.

- -

NOTES

- -

Other string types call the ASN1_STRING functions. For example ASN1_OCTET_STRING_new() calls ASN1_STRING_type_new(V_ASN1_OCTET_STRING).

- -

RETURN VALUES

- -

ASN1_STRING_new() and ASN1_STRING_type_new() return a valid ASN1_STRING structure or NULL if an error occurred.

- -

ASN1_STRING_free() does not return a value.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_print_ex.html b/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_print_ex.html deleted file mode 100644 index 288c9725..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_STRING_print_ex.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -ASN1_STRING_print_ex - - - - - - - - - - -

NAME

- -

ASN1_tag2str, ASN1_STRING_print_ex, ASN1_STRING_print_ex_fp, ASN1_STRING_print - ASN1_STRING output routines

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-int ASN1_STRING_print_ex(BIO *out, const ASN1_STRING *str, unsigned long flags);
-int ASN1_STRING_print_ex_fp(FILE *fp, const ASN1_STRING *str, unsigned long flags);
-int ASN1_STRING_print(BIO *out, const ASN1_STRING *str);
-
-const char *ASN1_tag2str(int tag);
- -

DESCRIPTION

- -

These functions output an ASN1_STRING structure. ASN1_STRING is used to represent all the ASN1 string types.

- -

ASN1_STRING_print_ex() outputs str to out, the format is determined by the options flags. ASN1_STRING_print_ex_fp() is identical except it outputs to fp instead.

- -

ASN1_STRING_print() prints str to out but using a different format to ASN1_STRING_print_ex(). It replaces unprintable characters (other than CR, LF) with '.'.

- -

ASN1_tag2str() returns a human-readable name of the specified ASN.1 tag.

- -

NOTES

- -

ASN1_STRING_print() is a deprecated function which should be avoided; use ASN1_STRING_print_ex() instead.

- -

Although there are a large number of options frequently ASN1_STRFLGS_RFC2253 is suitable, or on UTF8 terminals ASN1_STRFLGS_RFC2253 & ~ASN1_STRFLGS_ESC_MSB.

- -

The complete set of supported options for flags is listed below.

- -

Various characters can be escaped. If ASN1_STRFLGS_ESC_2253 is set the characters determined by RFC2253 are escaped. If ASN1_STRFLGS_ESC_CTRL is set control characters are escaped. If ASN1_STRFLGS_ESC_MSB is set characters with the MSB set are escaped: this option should not be used if the terminal correctly interprets UTF8 sequences.

- -

Escaping takes several forms.

- -

If the character being escaped is a 16 bit character then the form "\UXXXX" is used using exactly four characters for the hex representation. If it is 32 bits then "\WXXXXXXXX" is used using eight characters of its hex representation. These forms will only be used if UTF8 conversion is not set (see below).

- -

Printable characters are normally escaped using the backslash '\' character. If ASN1_STRFLGS_ESC_QUOTE is set then the whole string is instead surrounded by double quote characters: this is arguably more readable than the backslash notation. Other characters use the "\XX" using exactly two characters of the hex representation.

- -

If ASN1_STRFLGS_UTF8_CONVERT is set then characters are converted to UTF8 format first. If the terminal supports the display of UTF8 sequences then this option will correctly display multi byte characters.

- -

If ASN1_STRFLGS_IGNORE_TYPE is set then the string type is not interpreted at all: everything is assumed to be one byte per character. This is primarily for debugging purposes and can result in confusing output in multi character strings.

- -

If ASN1_STRFLGS_SHOW_TYPE is set then the string type itself is printed out before its value (for example "BMPSTRING"), this actually uses ASN1_tag2str().

- -

The content of a string instead of being interpreted can be "dumped": this just outputs the value of the string using the form #XXXX using hex format for each octet.

- -

If ASN1_STRFLGS_DUMP_ALL is set then any type is dumped.

- -

Normally non character string types (such as OCTET STRING) are assumed to be one byte per character, if ASN1_STRFLGS_DUMP_UNKNOWN is set then they will be dumped instead.

- -

When a type is dumped normally just the content octets are printed, if ASN1_STRFLGS_DUMP_DER is set then the complete encoding is dumped instead (including tag and length octets).

- -

ASN1_STRFLGS_RFC2253 includes all the flags required by RFC2253. It is equivalent to: ASN1_STRFLGS_ESC_2253 | ASN1_STRFLGS_ESC_CTRL | ASN1_STRFLGS_ESC_MSB | ASN1_STRFLGS_UTF8_CONVERT | ASN1_STRFLGS_DUMP_UNKNOWN ASN1_STRFLGS_DUMP_DER

- -

RETURN VALUES

- -

ASN1_STRING_print_ex() and ASN1_STRING_print_ex_fp() return the number of characters written or -1 if an error occurred.

- -

ASN1_STRING_print() returns 1 on success or 0 on error.

- -

ASN1_tag2str() returns a human-readable name of the specified ASN.1 tag.

- -

SEE ALSO

- -

X509_NAME_print_ex(3), ASN1_tag2str(3)

- -

COPYRIGHT

- -

Copyright 2002-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_TIME_set.html b/openssl-install/share/doc/openssl/html/man3/ASN1_TIME_set.html deleted file mode 100644 index e0f92201..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_TIME_set.html +++ /dev/null @@ -1,205 +0,0 @@ - - - - -ASN1_TIME_set - - - - - - - - - - -

NAME

- -

ASN1_TIME_set, ASN1_UTCTIME_set, ASN1_GENERALIZEDTIME_set, ASN1_TIME_adj, ASN1_UTCTIME_adj, ASN1_GENERALIZEDTIME_adj, ASN1_TIME_check, ASN1_UTCTIME_check, ASN1_GENERALIZEDTIME_check, ASN1_TIME_set_string, ASN1_UTCTIME_set_string, ASN1_GENERALIZEDTIME_set_string, ASN1_TIME_set_string_X509, ASN1_TIME_normalize, ASN1_TIME_to_tm, ASN1_TIME_print, ASN1_TIME_print_ex, ASN1_UTCTIME_print, ASN1_GENERALIZEDTIME_print, ASN1_TIME_diff, ASN1_TIME_cmp_time_t, ASN1_UTCTIME_cmp_time_t, ASN1_TIME_compare, ASN1_TIME_to_generalizedtime, ASN1_TIME_dup, ASN1_UTCTIME_dup, ASN1_GENERALIZEDTIME_dup - ASN.1 Time functions

- -

SYNOPSIS

- -
ASN1_TIME *ASN1_TIME_set(ASN1_TIME *s, time_t t);
-ASN1_UTCTIME *ASN1_UTCTIME_set(ASN1_UTCTIME *s, time_t t);
-ASN1_GENERALIZEDTIME *ASN1_GENERALIZEDTIME_set(ASN1_GENERALIZEDTIME *s,
-                                               time_t t);
-
-ASN1_TIME *ASN1_TIME_adj(ASN1_TIME *s, time_t t, int offset_day,
-                         long offset_sec);
-ASN1_UTCTIME *ASN1_UTCTIME_adj(ASN1_UTCTIME *s, time_t t,
-                               int offset_day, long offset_sec);
-ASN1_GENERALIZEDTIME *ASN1_GENERALIZEDTIME_adj(ASN1_GENERALIZEDTIME *s,
-                                               time_t t, int offset_day,
-                                               long offset_sec);
-
-int ASN1_TIME_set_string(ASN1_TIME *s, const char *str);
-int ASN1_TIME_set_string_X509(ASN1_TIME *s, const char *str);
-int ASN1_UTCTIME_set_string(ASN1_UTCTIME *s, const char *str);
-int ASN1_GENERALIZEDTIME_set_string(ASN1_GENERALIZEDTIME *s,
-                                    const char *str);
-
-int ASN1_TIME_normalize(ASN1_TIME *s);
-
-int ASN1_TIME_check(const ASN1_TIME *t);
-int ASN1_UTCTIME_check(const ASN1_UTCTIME *t);
-int ASN1_GENERALIZEDTIME_check(const ASN1_GENERALIZEDTIME *t);
-
-int ASN1_TIME_print(BIO *b, const ASN1_TIME *s);
-int ASN1_TIME_print_ex(BIO *bp, const ASN1_TIME *tm, unsigned long flags);
-int ASN1_UTCTIME_print(BIO *b, const ASN1_UTCTIME *s);
-int ASN1_GENERALIZEDTIME_print(BIO *b, const ASN1_GENERALIZEDTIME *s);
-
-int ASN1_TIME_to_tm(const ASN1_TIME *s, struct tm *tm);
-int ASN1_TIME_diff(int *pday, int *psec, const ASN1_TIME *from,
-                   const ASN1_TIME *to);
-
-int ASN1_TIME_cmp_time_t(const ASN1_TIME *s, time_t t);
-int ASN1_UTCTIME_cmp_time_t(const ASN1_UTCTIME *s, time_t t);
-
-int ASN1_TIME_compare(const ASN1_TIME *a, const ASN1_TIME *b);
-
-ASN1_GENERALIZEDTIME *ASN1_TIME_to_generalizedtime(ASN1_TIME *t,
-                                                   ASN1_GENERALIZEDTIME **out);
-
-ASN1_TIME *ASN1_TIME_dup(const ASN1_TIME *t);
-ASN1_UTCTIME *ASN1_UTCTIME_dup(const ASN1_UTCTIME *t);
-ASN1_GENERALIZEDTIME *ASN1_GENERALIZEDTIME_dup(const ASN1_GENERALIZEDTIME *t);
- -

DESCRIPTION

- -

The ASN1_TIME_set(), ASN1_UTCTIME_set() and ASN1_GENERALIZEDTIME_set() functions set the structure s to the time represented by the time_t value t. If s is NULL a new time structure is allocated and returned.

- -

The ASN1_TIME_adj(), ASN1_UTCTIME_adj() and ASN1_GENERALIZEDTIME_adj() functions set the time structure s to the time represented by the time offset_day and offset_sec after the time_t value t. The values of offset_day or offset_sec can be negative to set a time before t. The offset_sec value can also exceed the number of seconds in a day. If s is NULL a new structure is allocated and returned.

- -

The ASN1_TIME_set_string(), ASN1_UTCTIME_set_string() and ASN1_GENERALIZEDTIME_set_string() functions set the time structure s to the time represented by string str which must be in appropriate ASN.1 time format (for example YYMMDDHHMMSSZ or YYYYMMDDHHMMSSZ). If s is NULL this function performs a format check on str only. The string str is copied into s.

- -

ASN1_TIME_set_string_X509() sets ASN1_TIME structure s to the time represented by string str which must be in appropriate time format that RFC 5280 requires, which means it only allows YYMMDDHHMMSSZ and YYYYMMDDHHMMSSZ (leap second is rejected), all other ASN.1 time format are not allowed. If s is NULL this function performs a format check on str only.

- -

The ASN1_TIME_normalize() function converts an ASN1_GENERALIZEDTIME or ASN1_UTCTIME into a time value that can be used in a certificate. It should be used after the ASN1_TIME_set_string() functions and before ASN1_TIME_print() functions to get consistent (i.e. GMT) results.

- -

The ASN1_TIME_check(), ASN1_UTCTIME_check() and ASN1_GENERALIZEDTIME_check() functions check the syntax of the time structure s.

- -

The ASN1_TIME_print(), ASN1_UTCTIME_print() and ASN1_GENERALIZEDTIME_print() functions print the time structure s to BIO b in human readable format. It will be of the format MMM DD HH:MM:SS[.s*] YYYY GMT, for example "Feb 3 00:55:52 2015 GMT", which does not include a newline. If the time structure has invalid format it prints out "Bad time value" and returns an error. The output for generalized time may include a fractional part following the second.

- -

ASN1_TIME_print_ex() provides flags to specify the output format of the datetime. This can be either ASN1_DTFLGS_RFC822 or ASN1_DTFLGS_ISO8601.

- -

ASN1_TIME_to_tm() converts the time s to the standard tm structure. If s is NULL, then the current time is converted. The output time is GMT. The tm_sec, tm_min, tm_hour, tm_mday, tm_wday, tm_yday, tm_mon and tm_year fields of tm structure are set to proper values, whereas all other fields are set to 0. If tm is NULL this function performs a format check on s only. If s is in Generalized format with fractional seconds, e.g. YYYYMMDDHHMMSS.SSSZ, the fractional seconds will be lost while converting s to tm structure.

- -

ASN1_TIME_diff() sets *pday and *psec to the time difference between from and to. If to represents a time later than from then one or both (depending on the time difference) of *pday and *psec will be positive. If to represents a time earlier than from then one or both of *pday and *psec will be negative. If to and from represent the same time then *pday and *psec will both be zero. If both *pday and *psec are nonzero they will always have the same sign. The value of *psec will always be less than the number of seconds in a day. If from or to is NULL the current time is used.

- -

The ASN1_TIME_cmp_time_t() and ASN1_UTCTIME_cmp_time_t() functions compare the two times represented by the time structure s and the time_t t.

- -

The ASN1_TIME_compare() function compares the two times represented by the time structures a and b.

- -

The ASN1_TIME_to_generalizedtime() function converts an ASN1_TIME to an ASN1_GENERALIZEDTIME, regardless of year. If either out or *out are NULL, then a new object is allocated and must be freed after use.

- -

The ASN1_TIME_dup(), ASN1_UTCTIME_dup() and ASN1_GENERALIZEDTIME_dup() functions duplicate the time structure t and return the duplicated result correspondingly.

- -

NOTES

- -

The ASN1_TIME structure corresponds to the ASN.1 structure Time defined in RFC5280 et al. The time setting functions obey the rules outlined in RFC5280: if the date can be represented by UTCTime it is used, else GeneralizedTime is used.

- -

The ASN1_TIME, ASN1_UTCTIME and ASN1_GENERALIZEDTIME structures are represented as an ASN1_STRING internally and can be freed up using ASN1_STRING_free().

- -

The ASN1_TIME structure can represent years from 0000 to 9999 but no attempt is made to correct ancient calendar changes (for example from Julian to Gregorian calendars).

- -

ASN1_UTCTIME is limited to a year range of 1950 through 2049.

- -

Some applications add offset times directly to a time_t value and pass the results to ASN1_TIME_set() (or equivalent). This can cause problems as the time_t value can overflow on some systems resulting in unexpected results. New applications should use ASN1_TIME_adj() instead and pass the offset value in the offset_sec and offset_day parameters instead of directly manipulating a time_t value.

- -

ASN1_TIME_adj() may change the type from ASN1_GENERALIZEDTIME to ASN1_UTCTIME, or vice versa, based on the resulting year. ASN1_GENERALIZEDTIME_adj() and ASN1_UTCTIME_adj() will not modify the type of the return structure.

- -

It is recommended that functions starting with ASN1_TIME be used instead of those starting with ASN1_UTCTIME or ASN1_GENERALIZEDTIME. The functions starting with ASN1_UTCTIME and ASN1_GENERALIZEDTIME act only on that specific time format. The functions starting with ASN1_TIME will operate on either format.

- -

Users familiar with RFC822 should note that when specifying the flag ASN1_DTFLGS_RFC822 the year will be formatted as documented above, i.e., using 4 digits, not 2 as specified in RFC822.

- -

BUGS

- -

ASN1_TIME_print(), ASN1_UTCTIME_print() and ASN1_GENERALIZEDTIME_print() do not print out the timezone: it either prints out "GMT" or nothing. But all certificates complying with RFC5280 et al use GMT anyway.

- -

ASN1_TIME_print(), ASN1_TIME_print_ex(), ASN1_UTCTIME_print() and ASN1_GENERALIZEDTIME_print() do not distinguish if they fail because of an I/O error or invalid time format.

- -

Use the ASN1_TIME_normalize() function to normalize the time value before printing to get GMT results.

- -

RETURN VALUES

- -

ASN1_TIME_set(), ASN1_UTCTIME_set(), ASN1_GENERALIZEDTIME_set(), ASN1_TIME_adj(), ASN1_UTCTIME_adj() and ASN1_GENERALIZEDTIME_set() return a pointer to a time structure or NULL if an error occurred.

- -

ASN1_TIME_set_string(), ASN1_UTCTIME_set_string(), ASN1_GENERALIZEDTIME_set_string() and ASN1_TIME_set_string_X509() return 1 if the time value is successfully set and 0 otherwise.

- -

ASN1_TIME_normalize() returns 1 on success, and 0 on error.

- -

ASN1_TIME_check(), ASN1_UTCTIME_check and ASN1_GENERALIZEDTIME_check() return 1 if the structure is syntactically correct and 0 otherwise.

- -

ASN1_TIME_print(), ASN1_UTCTIME_print() and ASN1_GENERALIZEDTIME_print() return 1 if the time is successfully printed out and 0 if an I/O error occurred an error occurred (I/O error or invalid time format).

- -

ASN1_TIME_to_tm() returns 1 if the time is successfully parsed and 0 if an error occurred (invalid time format).

- -

ASN1_TIME_diff() returns 1 for success and 0 for failure. It can fail if the passed-in time structure has invalid syntax, for example.

- -

ASN1_TIME_cmp_time_t() and ASN1_UTCTIME_cmp_time_t() return -1 if s is before t, 0 if s equals t, or 1 if s is after t. -2 is returned on error.

- -

ASN1_TIME_compare() returns -1 if a is before b, 0 if a equals b, or 1 if a is after b. -2 is returned on error.

- -

ASN1_TIME_to_generalizedtime() returns a pointer to the appropriate time structure on success or NULL if an error occurred.

- -

ASN1_TIME_dup(), ASN1_UTCTIME_dup() and ASN1_GENERALIZEDTIME_dup() return a pointer to a time structure or NULL if an error occurred.

- -

EXAMPLES

- -

Set a time structure to one hour after the current time and print it out:

- -
#include <time.h>
-#include <openssl/asn1.h>
-
-ASN1_TIME *tm;
-time_t t;
-BIO *b;
-
-t = time(NULL);
-tm = ASN1_TIME_adj(NULL, t, 0, 60 * 60);
-b = BIO_new_fp(stdout, BIO_NOCLOSE);
-ASN1_TIME_print(b, tm);
-ASN1_STRING_free(tm);
-BIO_free(b);
- -

Determine if one time is later or sooner than the current time:

- -
int day, sec;
-
-if (!ASN1_TIME_diff(&day, &sec, NULL, to))
-    /* Invalid time format */
-
-if (day > 0 || sec > 0)
-    printf("Later\n");
-else if (day < 0 || sec < 0)
-    printf("Sooner\n");
-else
-    printf("Same\n");
- -

HISTORY

- -

The ASN1_TIME_to_tm() function was added in OpenSSL 1.1.1. The ASN1_TIME_set_string_X509() function was added in OpenSSL 1.1.1. The ASN1_TIME_normalize() function was added in OpenSSL 1.1.1. The ASN1_TIME_cmp_time_t() function was added in OpenSSL 1.1.1. The ASN1_TIME_compare() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_TYPE_get.html b/openssl-install/share/doc/openssl/html/man3/ASN1_TYPE_get.html deleted file mode 100644 index f5b5de80..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_TYPE_get.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -ASN1_TYPE_get - - - - - - - - - - -

NAME

- -

ASN1_TYPE_get, ASN1_TYPE_set, ASN1_TYPE_set1, ASN1_TYPE_cmp, ASN1_TYPE_unpack_sequence, ASN1_TYPE_pack_sequence - ASN1_TYPE utility functions

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-int ASN1_TYPE_get(const ASN1_TYPE *a);
-void ASN1_TYPE_set(ASN1_TYPE *a, int type, void *value);
-int ASN1_TYPE_set1(ASN1_TYPE *a, int type, const void *value);
-int ASN1_TYPE_cmp(const ASN1_TYPE *a, const ASN1_TYPE *b);
-
-void *ASN1_TYPE_unpack_sequence(const ASN1_ITEM *it, const ASN1_TYPE *t);
-ASN1_TYPE *ASN1_TYPE_pack_sequence(const ASN1_ITEM *it, void *s,
-                                   ASN1_TYPE **t);
- -

DESCRIPTION

- -

These functions allow an ASN1_TYPE structure to be manipulated. The ASN1_TYPE structure can contain any ASN.1 type or constructed type such as a SEQUENCE: it is effectively equivalent to the ASN.1 ANY type.

- -

ASN1_TYPE_get() returns the type of a or 0 if it fails.

- -

ASN1_TYPE_set() sets the value of a to type and value. This function uses the pointer value internally so it must not be freed up after the call.

- -

ASN1_TYPE_set1() sets the value of a to type a copy of value.

- -

ASN1_TYPE_cmp() compares ASN.1 types a and b and returns 0 if they are identical and nonzero otherwise.

- -

ASN1_TYPE_unpack_sequence() attempts to parse the SEQUENCE present in t using the ASN.1 structure it. If successful it returns a pointer to the ASN.1 structure corresponding to it which must be freed by the caller. If it fails it return NULL.

- -

ASN1_TYPE_pack_sequence() attempts to encode the ASN.1 structure s corresponding to it into an ASN1_TYPE. If successful the encoded ASN1_TYPE is returned. If t and *t are not NULL the encoded type is written to t overwriting any existing data. If t is not NULL but *t is NULL the returned ASN1_TYPE is written to *t.

- -

NOTES

- -

The type and meaning of the value parameter for ASN1_TYPE_set() and ASN1_TYPE_set1() is determined by the type parameter. If type is V_ASN1_NULL value is ignored. If type is V_ASN1_BOOLEAN then the boolean is set to TRUE if value is not NULL. If type is V_ASN1_OBJECT then value is an ASN1_OBJECT structure. Otherwise type is and ASN1_STRING structure. If type corresponds to a primitive type (or a string type) then the contents of the ASN1_STRING contain the content octets of the type. If type corresponds to a constructed type or a tagged type (V_ASN1_SEQUENCE, V_ASN1_SET or V_ASN1_OTHER) then the ASN1_STRING contains the entire ASN.1 encoding verbatim (including tag and length octets).

- -

ASN1_TYPE_cmp() may not return zero if two types are equivalent but have different encodings. For example the single content octet of the boolean TRUE value under BER can have any nonzero encoding but ASN1_TYPE_cmp() will only return zero if the values are the same.

- -

If either or both of the parameters passed to ASN1_TYPE_cmp() is NULL the return value is nonzero. Technically if both parameters are NULL the two types could be absent OPTIONAL fields and so should match, however, passing NULL values could also indicate a programming error (for example an unparsable type which returns NULL) for types which do not match. So applications should handle the case of two absent values separately.

- -

RETURN VALUES

- -

ASN1_TYPE_get() returns the type of the ASN1_TYPE argument.

- -

ASN1_TYPE_set() does not return a value.

- -

ASN1_TYPE_set1() returns 1 for success and 0 for failure.

- -

ASN1_TYPE_cmp() returns 0 if the types are identical and nonzero otherwise.

- -

ASN1_TYPE_unpack_sequence() returns a pointer to an ASN.1 structure or NULL on failure.

- -

ASN1_TYPE_pack_sequence() return an ASN1_TYPE structure if it succeeds or NULL on failure.

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_aux_cb.html b/openssl-install/share/doc/openssl/html/man3/ASN1_aux_cb.html deleted file mode 100644 index c166d899..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_aux_cb.html +++ /dev/null @@ -1,307 +0,0 @@ - - - - -ASN1_aux_cb - - - - - - - - - - -

NAME

- -

ASN1_AUX, ASN1_PRINT_ARG, ASN1_STREAM_ARG, ASN1_aux_cb, ASN1_aux_const_cb - ASN.1 auxiliary data

- -

SYNOPSIS

- -
#include <openssl/asn1t.h>
-
-struct ASN1_AUX_st {
-    void *app_data;
-    int flags;
-    int ref_offset;             /* Offset of reference value */
-    int ref_lock;               /* Offset to an CRYPTO_RWLOCK */
-    ASN1_aux_cb *asn1_cb;
-    int enc_offset;             /* Offset of ASN1_ENCODING structure */
-    ASN1_aux_const_cb *asn1_const_cb; /* for ASN1_OP_I2D_ and ASN1_OP_PRINT_ */
-};
-typedef struct ASN1_AUX_st ASN1_AUX;
-
-struct ASN1_PRINT_ARG_st {
-    BIO *out;
-    int indent;
-    const ASN1_PCTX *pctx;
-};
-typedef struct ASN1_PRINT_ARG_st ASN1_PRINT_ARG;
-
-struct ASN1_STREAM_ARG_st {
-    BIO *out;
-    BIO *ndef_bio;
-    unsigned char **boundary;
-};
-typedef struct ASN1_STREAM_ARG_st ASN1_STREAM_ARG;
-
-typedef int ASN1_aux_cb(int operation, ASN1_VALUE **in, const ASN1_ITEM *it,
-                        void *exarg);
-typedef int ASN1_aux_const_cb(int operation, const ASN1_VALUE **in,
-                              const ASN1_ITEM *it, void *exarg);
- -

DESCRIPTION

- -

ASN.1 data structures can be associated with an ASN1_AUX object to supply additional information about the ASN.1 structure. An ASN1_AUX structure is associated with the structure during the definition of the ASN.1 template. For example an ASN1_AUX structure will be associated by using one of the various ASN.1 template definition macros that supply auxiliary information such as ASN1_SEQUENCE_enc(), ASN1_SEQUENCE_ref(), ASN1_SEQUENCE_cb_const_cb(), ASN1_SEQUENCE_const_cb(), ASN1_SEQUENCE_cb() or ASN1_NDEF_SEQUENCE_cb().

- -

An ASN1_AUX structure contains the following information.

- -
- -
app_data
-
- -

Arbitrary application data

- -
-
flags
-
- -

Flags which indicate the auxiliarly functionality supported.

- -

The ASN1_AFLG_REFCOUNT flag indicates that objects support reference counting.

- -

The ASN1_AFLG_ENCODING flag indicates that the original encoding of the object will be saved.

- -

The ASN1_AFLG_BROKEN flag is a work around for broken encoders where the sequence length value may not be correct. This should generally not be used.

- -

The ASN1_AFLG_CONST_CB flag indicates that the "const" form of the ASN1_AUX callback should be used in preference to the non-const form.

- -
-
ref_offset
-
- -

If the ASN1_AFLG_REFCOUNT flag is set then this value is assumed to be an offset into the ASN1_VALUE structure where a CRYPTO_REF_COUNT may be found for the purposes of reference counting.

- -
-
ref_lock
-
- -

If the ASN1_AFLG_REFCOUNT flag is set then this value is assumed to be an offset into the ASN1_VALUE structure where a CRYPTO_RWLOCK may be found for the purposes of reference counting.

- -
-
asn1_cb
-
- -

A callback that will be invoked at various points during the processing of the ASN1_VALUE. See below for further details.

- -
-
enc_offset
-
- -

Offset into the ASN1_VALUE object where the original encoding of the object will be saved if the ASN1_AFLG_ENCODING flag has been set.

- -
-
asn1_const_cb
-
- -

A callback that will be invoked at various points during the processing of the ASN1_VALUE. This is used in preference to the asn1_cb callback if the ASN1_AFLG_CONST_CB flag is set. See below for further details.

- -
-
- -

During the processing of an ASN1_VALUE object the callbacks set via asn1_cb or asn1_const_cb will be invoked as a result of various events indicated via the operation parameter. The value of *in will be the ASN1_VALUE object being processed based on the template in it. An additional operation specific parameter may be passed in exarg. The currently supported operations are as follows. The callbacks should return a positive value on success or zero on error, unless otherwise noted below.

- -
- -
ASN1_OP_NEW_PRE
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure prior to an ASN1_VALUE object being allocated. The callback may allocate the ASN1_VALUE itself and store it in *pval. If it does so it should return 2 from the callback. On error it should return 0.

- -
-
ASN1_OP_NEW_POST
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure after an ASN1_VALUE object has been allocated. The allocated object is in *pval.

- -
-
ASN1_OP_FREE_PRE
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure immediately before an ASN1_VALUE is freed. If the callback originally constructed the ASN1_VALUE via ASN1_OP_NEW_PRE then it should free it at this point and return 2 from the callback. Otherwise it should return 1 for success or 0 on error.

- -
-
ASN1_OP_FREE_POST
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure immediately after ASN1_VALUE sub-structures are freed.

- -
-
ASN1_OP_D2I_PRE
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure immediately before a "d2i" operation for the ASN1_VALUE.

- -
-
ASN1_OP_D2I_POST
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure immediately after a "d2i" operation for the ASN1_VALUE.

- -
-
ASN1_OP_I2D_PRE
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure immediately before a "i2d" operation for the ASN1_VALUE.

- -
-
ASN1_OP_I2D_POST
-
- -

Invoked when processing a CHOICE, SEQUENCE or NDEF_SEQUENCE structure immediately after a "i2d" operation for the ASN1_VALUE.

- -
-
ASN1_OP_PRINT_PRE
-
- -

Invoked when processing a SEQUENCE or NDEF_SEQUENCE structure immediately before printing the ASN1_VALUE. The exarg argument will be a pointer to an ASN1_PRINT_ARG structure (see below).

- -
-
ASN1_OP_PRINT_POST
-
- -

Invoked when processing a SEQUENCE or NDEF_SEQUENCE structure immediately after printing the ASN1_VALUE. The exarg argument will be a pointer to an ASN1_PRINT_ARG structure (see below).

- -
-
ASN1_OP_STREAM_PRE
-
- -

Invoked immediately prior to streaming the ASN1_VALUE data using indefinite length encoding. The exarg argument will be a pointer to a ASN1_STREAM_ARG structure (see below).

- -
-
ASN1_OP_STREAM_POST
-
- -

Invoked immediately after streaming the ASN1_VALUE data using indefinite length encoding. The exarg argument will be a pointer to a ASN1_STREAM_ARG structure (see below).

- -
-
ASN1_OP_DETACHED_PRE
-
- -

Invoked immediately prior to processing the ASN1_VALUE data as a "detached" value (as used in CMS and PKCS7). The exarg argument will be a pointer to a ASN1_STREAM_ARG structure (see below).

- -
-
ASN1_OP_DETACHED_POST
-
- -

Invoked immediately after processing the ASN1_VALUE data as a "detached" value (as used in CMS and PKCS7). The exarg argument will be a pointer to a ASN1_STREAM_ARG structure (see below).

- -
-
ASN1_OP_DUP_PRE
-
- -

Invoked immediate prior to an ASN1_VALUE being duplicated via a call to ASN1_item_dup().

- -
-
ASN1_OP_DUP_POST
-
- -

Invoked immediate after to an ASN1_VALUE has been duplicated via a call to ASN1_item_dup().

- -
-
ASN1_OP_GET0_LIBCTX
-
- -

Invoked in order to obtain the OSSL_LIB_CTX associated with an ASN1_VALUE if any. A pointer to an OSSL_LIB_CTX should be stored in *exarg if such a value exists.

- -
-
ASN1_OP_GET0_PROPQ
-
- -

Invoked in order to obtain the property query string associated with an ASN1_VALUE if any. A pointer to the property query string should be stored in *exarg if such a value exists.

- -
-
- -

An ASN1_PRINT_ARG object is used during processing of ASN1_OP_PRINT_PRE and ASN1_OP_PRINT_POST callback operations. It contains the following information.

- -
- -
out
-
- -

The BIO being used to print the data out.

- -
-
ndef_bio
-
- -

The current number of indent spaces that should be used for printing this data.

- -
-
pctx
-
- -

The context for the ASN1_PCTX operation.

- -
-
- -

An ASN1_STREAM_ARG object is used during processing of ASN1_OP_STREAM_PRE, ASN1_OP_STREAM_POST, ASN1_OP_DETACHED_PRE and ASN1_OP_DETACHED_POST callback operations. It contains the following information.

- -
- -
out
-
- -

The BIO to stream through

- -
-
ndef_bio
-
- -

The BIO with filters appended

- -
-
boundary
-
- -

The streaming I/O boundary.

- -
-
- -

RETURN VALUES

- -

The callbacks return 0 on error and a positive value on success. Some operations require specific positive success values as noted above.

- -

SEE ALSO

- -

ASN1_item_new_ex(3)

- -

HISTORY

- -

The ASN1_aux_const_cb() callback and the ASN1_OP_GET0_LIBCTX and ASN1_OP_GET0_PROPQ operation types were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_generate_nconf.html b/openssl-install/share/doc/openssl/html/man3/ASN1_generate_nconf.html deleted file mode 100644 index 47d3a8e1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_generate_nconf.html +++ /dev/null @@ -1,274 +0,0 @@ - - - - -ASN1_generate_nconf - - - - - - - - - - -

NAME

- -

ASN1_generate_nconf, ASN1_generate_v3 - ASN1 string generation functions

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-ASN1_TYPE *ASN1_generate_nconf(const char *str, CONF *nconf);
-ASN1_TYPE *ASN1_generate_v3(const char *str, X509V3_CTX *cnf);
- -

DESCRIPTION

- -

These functions generate the ASN1 encoding of a string in an ASN1_TYPE structure.

- -

str contains the string to encode. nconf or cnf contains the optional configuration information where additional strings will be read from. nconf will typically come from a config file whereas cnf is obtained from an X509V3_CTX structure, which will typically be used by X509 v3 certificate extension functions. cnf or nconf can be set to NULL if no additional configuration will be used.

- -

GENERATION STRING FORMAT

- -

The actual data encoded is determined by the string str and the configuration information. The general format of the string is:

- -
- -
[modifier,]type[:value]
-
- -
-
- -

That is zero or more comma separated modifiers followed by a type followed by an optional colon and a value. The formats of type, value and modifier are explained below.

- -

Supported Types

- -

The supported types are listed below. Case is not significant in the type names. Unless otherwise specified only the ASCII format is permissible.

- -
- -
BOOLEAN, BOOL
-
- -

This encodes a boolean type. The value string is mandatory and should be TRUE or FALSE. Additionally TRUE, true, Y, y, YES, yes, FALSE, false, N, n, NO and no are acceptable.

- -
-
NULL
-
- -

Encode the NULL type, the value string must not be present.

- -
-
INTEGER, INT
-
- -

Encodes an ASN1 INTEGER type. The value string represents the value of the integer, it can be prefaced by a minus sign and is normally interpreted as a decimal value unless the prefix 0x is included.

- -
-
ENUMERATED, ENUM
-
- -

Encodes the ASN1 ENUMERATED type, it is otherwise identical to INTEGER.

- -
-
OBJECT, OID
-
- -

Encodes an ASN1 OBJECT IDENTIFIER, the value string can be a short name, a long name or numerical format.

- -
-
UTCTIME, UTC
-
- -

Encodes an ASN1 UTCTime structure, the value should be in the format YYMMDDHHMMSSZ.

- -
-
GENERALIZEDTIME, GENTIME
-
- -

Encodes an ASN1 GeneralizedTime structure, the value should be in the format YYYYMMDDHHMMSSZ.

- -
-
OCTETSTRING, OCT
-
- -

Encodes an ASN1 OCTET STRING. value represents the contents of this structure, the format strings ASCII and HEX can be used to specify the format of value.

- -
-
BITSTRING, BITSTR
-
- -

Encodes an ASN1 BIT STRING. value represents the contents of this structure, the format strings ASCII, HEX and BITLIST can be used to specify the format of value.

- -

If the format is anything other than BITLIST the number of unused bits is set to zero.

- -
-
UNIVERSALSTRING, UNIV, IA5, IA5STRING, UTF8, UTF8String, BMP, BMPSTRING, VISIBLESTRING, VISIBLE, PRINTABLESTRING, PRINTABLE, T61, T61STRING, TELETEXSTRING, GeneralString, NUMERICSTRING, NUMERIC
-
- -

These encode the corresponding string types. value represents the contents of this structure. The format can be ASCII or UTF8.

- -
-
SEQUENCE, SEQ, SET
-
- -

Formats the result as an ASN1 SEQUENCE or SET type. value should be a section name which will contain the contents. The field names in the section are ignored and the values are in the generated string format. If value is absent then an empty SEQUENCE will be encoded.

- -
-
- -

Modifiers

- -

Modifiers affect the following structure, they can be used to add EXPLICIT or IMPLICIT tagging, add wrappers or to change the string format of the final type and value. The supported formats are documented below.

- -
- -
EXPLICIT, EXP
-
- -

Add an explicit tag to the following structure. This string should be followed by a colon and the tag value to use as a decimal value.

- -

By following the number with U, A, P or C UNIVERSAL, APPLICATION, PRIVATE or CONTEXT SPECIFIC tagging can be used, the default is CONTEXT SPECIFIC.

- -
-
IMPLICIT, IMP
-
- -

This is the same as EXPLICIT except IMPLICIT tagging is used instead.

- -
-
OCTWRAP, SEQWRAP, SETWRAP, BITWRAP
-
- -

The following structure is surrounded by an OCTET STRING, a SEQUENCE, a SET or a BIT STRING respectively. For a BIT STRING the number of unused bits is set to zero.

- -
-
FORMAT
-
- -

This specifies the format of the ultimate value. It should be followed by a colon and one of the strings ASCII, UTF8, HEX or BITLIST.

- -

If no format specifier is included then ASCII is used. If UTF8 is specified then the value string must be a valid UTF8 string. For HEX the output must be a set of hex digits. BITLIST (which is only valid for a BIT STRING) is a comma separated list of the indices of the set bits, all other bits are zero.

- -
-
- -

RETURN VALUES

- -

ASN1_generate_nconf() and ASN1_generate_v3() return the encoded data as an ASN1_TYPE structure or NULL if an error occurred.

- -

The error codes that can be obtained by ERR_get_error(3).

- -

EXAMPLES

- -

A simple IA5String:

- -
IA5STRING:Hello World
- -

An IA5String explicitly tagged:

- -
EXPLICIT:0,IA5STRING:Hello World
- -

An IA5String explicitly tagged using APPLICATION tagging:

- -
EXPLICIT:0A,IA5STRING:Hello World
- -

A BITSTRING with bits 1 and 5 set and all others zero:

- -
FORMAT:BITLIST,BITSTRING:1,5
- -

A more complex example using a config file to produce a SEQUENCE consisting of a BOOL an OID and a UTF8String:

- -
asn1 = SEQUENCE:seq_section
-
-[seq_section]
-
-field1 = BOOLEAN:TRUE
-field2 = OID:commonName
-field3 = UTF8:Third field
- -

This example produces an RSAPrivateKey structure, this is the key contained in the file client.pem in all OpenSSL distributions (note: the field names such as 'coeff' are ignored and are present just for clarity):

- -
asn1=SEQUENCE:private_key
-[private_key]
-version=INTEGER:0
-
-n=INTEGER:0xBB6FE79432CC6EA2D8F970675A5A87BFBE1AFF0BE63E879F2AFFB93644\
-D4D2C6D000430DEC66ABF47829E74B8C5108623A1C0EE8BE217B3AD8D36D5EB4FCA1D9
-
-e=INTEGER:0x010001
-
-d=INTEGER:0x6F05EAD2F27FFAEC84BEC360C4B928FD5F3A9865D0FCAAD291E2A52F4A\
-F810DC6373278C006A0ABBA27DC8C63BF97F7E666E27C5284D7D3B1FFFE16B7A87B51D
-
-p=INTEGER:0xF3929B9435608F8A22C208D86795271D54EBDFB09DDEF539AB083DA912\
-D4BD57
-
-q=INTEGER:0xC50016F89DFF2561347ED1186A46E150E28BF2D0F539A1594BBD7FE467\
-46EC4F
-
-exp1=INTEGER:0x9E7D4326C924AFC1DEA40B45650134966D6F9DFA3A7F9D698CD4ABEA\
-9C0A39B9
-
-exp2=INTEGER:0xBA84003BB95355AFB7C50DF140C60513D0BA51D637272E355E397779\
-E7B2458F
-
-coeff=INTEGER:0x30B9E4F2AFA5AC679F920FC83F1F2DF1BAF1779CF989447FABC2F5\
-628657053A
- -

This example is the corresponding public key in a SubjectPublicKeyInfo structure:

- -
# Start with a SEQUENCE
-asn1=SEQUENCE:pubkeyinfo
-
-# pubkeyinfo contains an algorithm identifier and the public key wrapped
-# in a BIT STRING
-[pubkeyinfo]
-algorithm=SEQUENCE:rsa_alg
-pubkey=BITWRAP,SEQUENCE:rsapubkey
-
-# algorithm ID for RSA is just an OID and a NULL
-[rsa_alg]
-algorithm=OID:rsaEncryption
-parameter=NULL
-
-# Actual public key: modulus and exponent
-[rsapubkey]
-n=INTEGER:0xBB6FE79432CC6EA2D8F970675A5A87BFBE1AFF0BE63E879F2AFFB93644\
-D4D2C6D000430DEC66ABF47829E74B8C5108623A1C0EE8BE217B3AD8D36D5EB4FCA1D9
-
-e=INTEGER:0x010001
- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2002-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_item_d2i_bio.html b/openssl-install/share/doc/openssl/html/man3/ASN1_item_d2i_bio.html deleted file mode 100644 index ef4a1932..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_item_d2i_bio.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -ASN1_item_d2i_bio - - - - - - - - - - -

NAME

- -

ASN1_item_d2i_ex, ASN1_item_d2i, ASN1_item_d2i_bio_ex, ASN1_item_d2i_bio, ASN1_item_d2i_fp_ex, ASN1_item_d2i_fp, ASN1_item_i2d_mem_bio, ASN1_item_pack, ASN1_item_unpack_ex, ASN1_item_unpack - decode and encode DER-encoded ASN.1 structures

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-ASN1_VALUE *ASN1_item_d2i_ex(ASN1_VALUE **pval, const unsigned char **in,
-                             long len, const ASN1_ITEM *it,
-                             OSSL_LIB_CTX *libctx, const char *propq);
-ASN1_VALUE *ASN1_item_d2i(ASN1_VALUE **pval, const unsigned char **in,
-                          long len, const ASN1_ITEM *it);
-
-void *ASN1_item_d2i_bio_ex(const ASN1_ITEM *it, BIO *in, void *x,
-                           OSSL_LIB_CTX *libctx, const char *propq);
-void *ASN1_item_d2i_bio(const ASN1_ITEM *it, BIO *in, void *x);
-
-void *ASN1_item_d2i_fp_ex(const ASN1_ITEM *it, FILE *in, void *x,
-                          OSSL_LIB_CTX *libctx, const char *propq);
-void *ASN1_item_d2i_fp(const ASN1_ITEM *it, FILE *in, void *x);
-
-BIO *ASN1_item_i2d_mem_bio(const ASN1_ITEM *it, const ASN1_VALUE *val);
-
-ASN1_STRING *ASN1_item_pack(void *obj, const ASN1_ITEM *it, ASN1_STRING **oct);
-
-void *ASN1_item_unpack(const ASN1_STRING *oct, const ASN1_ITEM *it);
-
-void *ASN1_item_unpack_ex(const ASN1_STRING *oct, const ASN1_ITEM *it,
-                         OSSL_LIB_CTX *libctx, const char *propq);
- -

DESCRIPTION

- -

ASN1_item_d2i_ex() decodes the contents of the data stored in *in of length len which must be a DER-encoded ASN.1 structure, using the ASN.1 template it. It places the result in *pval unless pval is NULL. If *pval is non-NULL on entry then the ASN1_VALUE present there will be reused. Otherwise a new ASN1_VALUE will be allocated. If any algorithm fetches are required during the process then they will use the OSSL_LIB_CTXprovided in the libctx parameter and the property query string in propq. See "ALGORITHM FETCHING" in crypto(7) for more information about algorithm fetching. On exit *in will be updated to point to the next byte in the buffer after the decoded structure.

- -

ASN1_item_d2i() is the same as ASN1_item_d2i_ex() except that the default OSSL_LIB_CTX is used (i.e. NULL) and with a NULL property query string.

- -

ASN1_item_d2i_bio_ex() decodes the contents of its input BIO in, which must be a DER-encoded ASN.1 structure, using the ASN.1 template it and places the result in *pval unless pval is NULL. If in is NULL it returns NULL, else a pointer to the parsed structure. If any algorithm fetches are required during the process then they will use the OSSL_LIB_CTX provided in the libctx parameter and the property query string in propq. See "ALGORITHM FETCHING" in crypto(7) for more information about algorithm fetching.

- -

ASN1_item_d2i_bio() is the same as ASN1_item_d2i_bio_ex() except that the default OSSL_LIB_CTX is used (i.e. NULL) and with a NULL property query string.

- -

ASN1_item_d2i_fp_ex() is the same as ASN1_item_d2i_bio_ex() except that a FILE pointer is provided instead of a BIO.

- -

ASN1_item_d2i_fp() is the same as ASN1_item_d2i_fp_ex() except that the default OSSL_LIB_CTX is used (i.e. NULL) and with a NULL property query string.

- -

ASN1_item_i2d_mem_bio() encodes the given ASN.1 value val using the ASN.1 template it and returns the result in a memory BIO.

- -

ASN1_item_pack() encodes the given ASN.1 value in obj using the ASN.1 template it and returns an ASN1_STRING object. If the passed in *oct is not NULL then this is used to store the returned result, otherwise a new ASN1_STRING object is created. If oct is not NULL and *oct is NULL then the returned return is also set into *oct. If there is an error the optional passed in ASN1_STRING will not be freed, but the previous value may be cleared when ASN1_STRING_set0(*oct, NULL, 0) is called internally.

- -

ASN1_item_unpack() uses ASN1_item_d2i() to decode the DER-encoded ASN1_STRING oct using the ASN.1 template it.

- -

ASN1_item_unpack_ex() is similar to ASN1_item_unpack(), but uses ASN1_item_d2i_ex() so that the libctx and propq can be used when doing algorithm fetching.

- -

RETURN VALUES

- -

ASN1_item_d2i_bio(), ASN1_item_unpack_ex() and ASN1_item_unpack() return a pointer to an ASN1_VALUE or NULL on error.

- -

ASN1_item_i2d_mem_bio() returns a pointer to a memory BIO or NULL on error.

- -

ASN1_item_pack() returns a pointer to an ASN1_STRING or NULL on error.

- -

HISTORY

- -

The functions ASN1_item_d2i_ex(), ASN1_item_d2i_bio_ex(), ASN1_item_d2i_fp_ex() and ASN1_item_i2d_mem_bio() were added in OpenSSL 3.0.

- -

The function ASN1_item_unpack_ex() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2021-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_item_new.html b/openssl-install/share/doc/openssl/html/man3/ASN1_item_new.html deleted file mode 100644 index d342e7c4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_item_new.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -ASN1_item_new - - - - - - - - - - -

NAME

- -

ASN1_item_new_ex, ASN1_item_new - create new ASN.1 values

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-ASN1_VALUE *ASN1_item_new_ex(const ASN1_ITEM *it, OSSL_LIB_CTX *libctx,
-                             const char *propq);
-ASN1_VALUE *ASN1_item_new(const ASN1_ITEM *it);
- -

DESCRIPTION

- -

ASN1_item_new_ex() creates a new ASN1_VALUE structure based on the ASN1_ITEM template given in the it parameter. If any algorithm fetches are required during the process then they will use the OSSL_LIB_CTX provided in the libctx parameter and the property query string in propq. See "ALGORITHM FETCHING" in crypto(7) for more information about algorithm fetching.

- -

ASN1_item_new() is the same as ASN1_item_new_ex() except that the default OSSL_LIB_CTX is used (i.e. NULL) and with a NULL property query string.

- -

RETURN VALUES

- -

ASN1_item_new_ex() and ASN1_item_new() return a pointer to the newly created ASN1_VALUE or NULL on error.

- -

HISTORY

- -

The function ASN1_item_new_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASN1_item_sign.html b/openssl-install/share/doc/openssl/html/man3/ASN1_item_sign.html deleted file mode 100644 index f52de282..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASN1_item_sign.html +++ /dev/null @@ -1,212 +0,0 @@ - - - - -ASN1_item_sign - - - - - - - - - - -

NAME

- -

ASN1_item_sign, ASN1_item_sign_ex, ASN1_item_sign_ctx, ASN1_item_verify, ASN1_item_verify_ex, ASN1_item_verify_ctx - ASN1 sign and verify

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int ASN1_item_sign_ex(const ASN1_ITEM *it, X509_ALGOR *algor1,
-                      X509_ALGOR *algor2, ASN1_BIT_STRING *signature,
-                      const void *data, const ASN1_OCTET_STRING *id,
-                      EVP_PKEY *pkey, const EVP_MD *md, OSSL_LIB_CTX *libctx,
-                      const char *propq);
-
-int ASN1_item_sign(const ASN1_ITEM *it, X509_ALGOR *algor1, X509_ALGOR *algor2,
-                   ASN1_BIT_STRING *signature, const void *data,
-                   EVP_PKEY *pkey, const EVP_MD *md);
-
-int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1,
-                       X509_ALGOR *algor2, ASN1_BIT_STRING *signature,
-                       const void *data, EVP_MD_CTX *ctx);
-
-int ASN1_item_verify_ex(const ASN1_ITEM *it, const X509_ALGOR *alg,
-                        const ASN1_BIT_STRING *signature, const void *data,
-                        const ASN1_OCTET_STRING *id, EVP_PKEY *pkey,
-                        OSSL_LIB_CTX *libctx, const char *propq);
-
-int ASN1_item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
-                     const ASN1_BIT_STRING *signature, const void *data,
-                     EVP_PKEY *pkey);
-
-int ASN1_item_verify_ctx(const ASN1_ITEM *it, const X509_ALGOR *alg,
-                         const ASN1_BIT_STRING *signature, const void *data,
-                         EVP_MD_CTX *ctx);
- -

DESCRIPTION

- -

ASN1_item_sign_ex() is used to sign arbitrary ASN1 data using a data object data, the ASN.1 structure it, private key pkey and message digest md. The data that is signed is formed by taking the data object in data and converting it to der format using the ASN.1 structure it. The data that will be signed, and a structure containing the signature may both have a copy of the X509_ALGOR. The ASN1_item_sign_ex() function will write the correct X509_ALGOR to the structs based on the algorithms and parameters that have been set up. If one of algor1 or algor2 points to the X509_ALGOR of the data to be signed, then that X509_ALGOR will first be written before the signature is generated. Examples of valid values that can be used by the ASN.1 structure it are ASN1_ITEM_rptr(X509_CINF), ASN1_ITEM_rptr(X509_REQ_INFO) and ASN1_ITEM_rptr(X509_CRL_INFO). The OSSL_LIB_CTX specified in libctx and the property query string specified in props are used when searching for algorithms in providers. The generated signature is set into signature. The optional parameter id can be NULL, but can be set for special key types. See EVP_PKEY_CTX_set1_id() for further info. The output parameters <algor1> and algor2 are ignored if they are NULL.

- -

ASN1_item_sign() is similar to ASN1_item_sign_ex() but uses default values of NULL for the id, libctx and propq.

- -

ASN1_item_sign_ctx() is similar to ASN1_item_sign() but uses the parameters contained in digest context ctx.

- -

ASN1_item_verify_ex() is used to verify the signature signature of internal data data using the public key pkey and algorithm identifier alg. The data that is verified is formed by taking the data object in data and converting it to der format using the ASN.1 structure it. The OSSL_LIB_CTX specified in libctx and the property query string specified in props are used when searching for algorithms in providers. The optional parameter id can be NULL, but can be set for special key types. See EVP_PKEY_CTX_set1_id() for further info.

- -

ASN1_item_verify() is similar to ASN1_item_verify_ex() but uses default values of NULL for the id, libctx and propq.

- -

ASN1_item_verify_ctx() is similar to ASN1_item_verify() but uses the parameters contained in digest context ctx.

- -

RETURN VALUES

- -

All sign functions return the size of the signature in bytes for success and zero for failure.

- -

All verify functions return 1 if the signature is valid and 0 if the signature check fails. If the signature could not be checked at all because it was ill-formed or some other error occurred then -1 is returned.

- -

EXAMPLES

- -

In the following example a 'MyObject' object is signed using the key contained in an EVP_MD_CTX. The signature is written to MyObject.signature. The object is then output in DER format and then loaded back in and verified.

- -
 #include <openssl/x509.h>
- #include <openssl/asn1t.h>
-
- /* An object used to store the ASN1 data fields that will be signed */
- typedef struct MySignInfoObject_st
- {
-     ASN1_INTEGER *version;
-     X509_ALGOR sig_alg;
- } MySignInfoObject;
-
- DECLARE_ASN1_FUNCTIONS(MySignInfoObject)
- /*
-  * A higher level object containing the ASN1 fields, signature alg and
-  * output signature.
-  */
- typedef struct MyObject_st
- {
-     MySignInfoObject info;
-     X509_ALGOR sig_alg;
-     ASN1_BIT_STRING *signature;
- } MyObject;
-
- DECLARE_ASN1_FUNCTIONS(MyObject)
-
- /* The ASN1 definition of MySignInfoObject */
- ASN1_SEQUENCE_cb(MySignInfoObject, NULL) = {
-     ASN1_SIMPLE(MySignInfoObject, version, ASN1_INTEGER)
-     ASN1_EMBED(MySignInfoObject, sig_alg, X509_ALGOR),
- } ASN1_SEQUENCE_END_cb(MySignInfoObject, MySignInfoObject)
-
- /* new, free, d2i & i2d functions for MySignInfoObject */
- IMPLEMENT_ASN1_FUNCTIONS(MySignInfoObject)
-
- /* The ASN1 definition of MyObject */
- ASN1_SEQUENCE_cb(MyObject, NULL) = {
-     ASN1_EMBED(MyObject, info, MySignInfoObject),
-     ASN1_EMBED(MyObject, sig_alg, X509_ALGOR),
-     ASN1_SIMPLE(MyObject, signature, ASN1_BIT_STRING)
- } ASN1_SEQUENCE_END_cb(MyObject, MyObject)
-
- /* new, free, d2i & i2d functions for MyObject */
- IMPLEMENT_ASN1_FUNCTIONS(MyObject)
-
- int test_asn1_item_sign_verify(const char *mdname, EVP_PKEY *pkey, long version)
- {
-    int ret = 0;
-    unsigned char *obj_der = NULL;
-    const unsigned char *p = NULL;
-    MyObject *obj = NULL, *loaded_obj = NULL;
-    const ASN1_ITEM *it = ASN1_ITEM_rptr(MySignInfoObject);
-    EVP_MD_CTX *sctx = NULL, *vctx = NULL;
-    int len;
-
-    /* Create MyObject and set its version */
-    obj = MyObject_new();
-    if (obj == NULL)
-        goto err;
-    if (!ASN1_INTEGER_set(obj->info.version, version))
-        goto err;
-
-    /* Set the key and digest used for signing */
-    sctx = EVP_MD_CTX_new();
-    if (sctx == NULL
-        || !EVP_DigestSignInit_ex(sctx, NULL, mdname, NULL, NULL, pkey))
-        goto err;
-
-    /*
-     * it contains the mapping between ASN.1 data and an object MySignInfoObject
-     * obj->info is the 'MySignInfoObject' object that will be
-     *   converted into DER data and then signed.
-     * obj->signature will contain the output signature.
-     * obj->sig_alg is filled with the private key's signing algorithm id.
-     * obj->info.sig_alg is another copy of the signing algorithm id that sits
-     * within MyObject.
-     */
-    len = ASN1_item_sign_ctx(it, &obj->sig_alg, &obj->info.sig_alg,
-                             obj->signature, &obj->info, sctx);
-    if (len <= 0
-        || X509_ALGOR_cmp(&obj->sig_alg, &obj->info.sig_alg) != 0)
-        goto err;
-
-    /* Output MyObject in der form */
-    len = i2d_MyObject(obj, &obj_der);
-    if (len <= 0)
-        goto err;
-
-    /* Set the key and digest used for verifying */
-    vctx = EVP_MD_CTX_new();
-    if (vctx == NULL
-        || !EVP_DigestVerifyInit_ex(vctx, NULL, mdname, NULL, NULL, pkey))
-        goto err;
-
-    /* Load the der data back into an object */
-    p = obj_der;
-    loaded_obj = d2i_MyObject(NULL, &p, len);
-    if (loaded_obj == NULL)
-        goto err;
-    /* Verify the loaded object */
-    ret = ASN1_item_verify_ctx(it, &loaded_obj->sig_alg, loaded_obj->signature,
-                               &loaded_obj->info, vctx);
-err:
-    OPENSSL_free(obj_der);
-    MyObject_free(loaded_obj);
-    MyObject_free(obj);
-    EVP_MD_CTX_free(sctx);
-    EVP_MD_CTX_free(vctx);
-    return ret;
- }
- -

SEE ALSO

- -

X509_sign(3), X509_verify(3)

- -

HISTORY

- -

ASN1_item_sign_ex() and ASN1_item_verify_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASYNC_WAIT_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/ASYNC_WAIT_CTX_new.html deleted file mode 100644 index df7e5abe..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASYNC_WAIT_CTX_new.html +++ /dev/null @@ -1,153 +0,0 @@ - - - - -ASYNC_WAIT_CTX_new - - - - - - - - - - -

NAME

- -

ASYNC_WAIT_CTX_new, ASYNC_WAIT_CTX_free, ASYNC_WAIT_CTX_set_wait_fd, ASYNC_WAIT_CTX_get_fd, ASYNC_WAIT_CTX_get_all_fds, ASYNC_WAIT_CTX_get_changed_fds, ASYNC_WAIT_CTX_clear_fd, ASYNC_WAIT_CTX_set_callback, ASYNC_WAIT_CTX_get_callback, ASYNC_WAIT_CTX_set_status, ASYNC_WAIT_CTX_get_status, ASYNC_callback_fn, ASYNC_STATUS_UNSUPPORTED, ASYNC_STATUS_ERR, ASYNC_STATUS_OK, ASYNC_STATUS_EAGAIN - functions to manage waiting for asynchronous jobs to complete

- -

SYNOPSIS

- -
#include <openssl/async.h>
-
-#define ASYNC_STATUS_UNSUPPORTED    0
-#define ASYNC_STATUS_ERR            1
-#define ASYNC_STATUS_OK             2
-#define ASYNC_STATUS_EAGAIN         3
-typedef int (*ASYNC_callback_fn)(void *arg);
-ASYNC_WAIT_CTX *ASYNC_WAIT_CTX_new(void);
-void ASYNC_WAIT_CTX_free(ASYNC_WAIT_CTX *ctx);
-int ASYNC_WAIT_CTX_set_wait_fd(ASYNC_WAIT_CTX *ctx, const void *key,
-                               OSSL_ASYNC_FD fd,
-                               void *custom_data,
-                               void (*cleanup)(ASYNC_WAIT_CTX *, const void *,
-                                               OSSL_ASYNC_FD, void *));
-int ASYNC_WAIT_CTX_get_fd(ASYNC_WAIT_CTX *ctx, const void *key,
-                          OSSL_ASYNC_FD *fd, void **custom_data);
-int ASYNC_WAIT_CTX_get_all_fds(ASYNC_WAIT_CTX *ctx, OSSL_ASYNC_FD *fd,
-                               size_t *numfds);
-int ASYNC_WAIT_CTX_get_changed_fds(ASYNC_WAIT_CTX *ctx, OSSL_ASYNC_FD *addfd,
-                                   size_t *numaddfds, OSSL_ASYNC_FD *delfd,
-                                   size_t *numdelfds);
-int ASYNC_WAIT_CTX_clear_fd(ASYNC_WAIT_CTX *ctx, const void *key);
-int ASYNC_WAIT_CTX_set_callback(ASYNC_WAIT_CTX *ctx,
-                                ASYNC_callback_fn callback,
-                                void *callback_arg);
-int ASYNC_WAIT_CTX_get_callback(ASYNC_WAIT_CTX *ctx,
-                                ASYNC_callback_fn *callback,
-                                void **callback_arg);
-int ASYNC_WAIT_CTX_set_status(ASYNC_WAIT_CTX *ctx, int status);
-int ASYNC_WAIT_CTX_get_status(ASYNC_WAIT_CTX *ctx);
- -

DESCRIPTION

- -

For an overview of how asynchronous operations are implemented in OpenSSL see ASYNC_start_job(3). An ASYNC_WAIT_CTX object represents an asynchronous "session", i.e. a related set of crypto operations. For example in SSL terms this would have a one-to-one correspondence with an SSL connection.

- -

Application code must create an ASYNC_WAIT_CTX using the ASYNC_WAIT_CTX_new() function prior to calling ASYNC_start_job() (see ASYNC_start_job(3)). When the job is started it is associated with the ASYNC_WAIT_CTX for the duration of that job. An ASYNC_WAIT_CTX should only be used for one ASYNC_JOB at any one time, but can be reused after an ASYNC_JOB has finished for a subsequent ASYNC_JOB. When the session is complete (e.g. the SSL connection is closed), application code cleans up with ASYNC_WAIT_CTX_free().

- -

ASYNC_WAIT_CTXs can have "wait" file descriptors associated with them. Calling ASYNC_WAIT_CTX_get_all_fds() and passing in a pointer to an ASYNC_WAIT_CTX in the ctx parameter will return the wait file descriptors associated with that job in *fd. The number of file descriptors returned will be stored in *numfds. It is the caller's responsibility to ensure that sufficient memory has been allocated in *fd to receive all the file descriptors. Calling ASYNC_WAIT_CTX_get_all_fds() with a NULL fd value will return no file descriptors but will still populate *numfds. Therefore, application code is typically expected to call this function twice: once to get the number of fds, and then again when sufficient memory has been allocated. If only one asynchronous engine is being used then normally this call will only ever return one fd. If multiple asynchronous engines are being used then more could be returned.

- -

The function ASYNC_WAIT_CTX_get_changed_fds() can be used to detect if any fds have changed since the last call time ASYNC_start_job() returned ASYNC_PAUSE (or since the ASYNC_WAIT_CTX was created if no ASYNC_PAUSE result has been received). The numaddfds and numdelfds parameters will be populated with the number of fds added or deleted respectively. *addfd and *delfd will be populated with the list of added and deleted fds respectively. Similarly to ASYNC_WAIT_CTX_get_all_fds() either of these can be NULL, but if they are not NULL then the caller is responsible for ensuring sufficient memory is allocated.

- -

Implementers of async aware code (e.g. engines) are encouraged to return a stable fd for the lifetime of the ASYNC_WAIT_CTX in order to reduce the "churn" of regularly changing fds - although no guarantees of this are provided to applications.

- -

Applications can wait for the file descriptor to be ready for "read" using a system function call such as select or poll (being ready for "read" indicates that the job should be resumed). If no file descriptor is made available then an application will have to periodically "poll" the job by attempting to restart it to see if it is ready to continue.

- -

Async aware code (e.g. engines) can get the current ASYNC_WAIT_CTX from the job via ASYNC_get_wait_ctx(3) and provide a file descriptor to use for waiting on by calling ASYNC_WAIT_CTX_set_wait_fd(). Typically this would be done by an engine immediately prior to calling ASYNC_pause_job() and not by end user code. An existing association with a file descriptor can be obtained using ASYNC_WAIT_CTX_get_fd() and cleared using ASYNC_WAIT_CTX_clear_fd(). Both of these functions requires a key value which is unique to the async aware code. This could be any unique value but a good candidate might be the ENGINE * for the engine. The custom_data parameter can be any value, and will be returned in a subsequent call to ASYNC_WAIT_CTX_get_fd(). The ASYNC_WAIT_CTX_set_wait_fd() function also expects a pointer to a "cleanup" routine. This can be NULL but if provided will automatically get called when the ASYNC_WAIT_CTX is freed, and gives the engine the opportunity to close the fd or any other resources. Note: The "cleanup" routine does not get called if the fd is cleared directly via a call to ASYNC_WAIT_CTX_clear_fd().

- -

An example of typical usage might be an async capable engine. User code would initiate cryptographic operations. The engine would initiate those operations asynchronously and then call ASYNC_WAIT_CTX_set_wait_fd() followed by ASYNC_pause_job() to return control to the user code. The user code can then perform other tasks or wait for the job to be ready by calling "select" or other similar function on the wait file descriptor. The engine can signal to the user code that the job should be resumed by making the wait file descriptor "readable". Once resumed the engine should clear the wake signal on the wait file descriptor.

- -

As well as a file descriptor, user code may also be notified via a callback. The callback and data pointers are stored within the ASYNC_WAIT_CTX along with an additional status field that can be used for the notification of retries from an engine. This additional method can be used when the user thinks that a file descriptor is too costly in terms of CPU cycles or in some context where a file descriptor is not appropriate.

- -

ASYNC_WAIT_CTX_set_callback() sets the callback and the callback argument. The callback will be called to notify user code when an engine completes a cryptography operation. It is a requirement that the callback function is small and nonblocking as it will be run in the context of a polling mechanism or an interrupt.

- -

ASYNC_WAIT_CTX_get_callback() returns the callback set in the ASYNC_WAIT_CTX structure.

- -

ASYNC_WAIT_CTX_set_status() allows an engine to set the current engine status. The possible status values are the following:

- -
- -
ASYNC_STATUS_UNSUPPORTED
-
- -

The engine does not support the callback mechanism. This is the default value. The engine must call ASYNC_WAIT_CTX_set_status() to set the status to some value other than ASYNC_STATUS_UNSUPPORTED if it intends to enable the callback mechanism.

- -
-
ASYNC_STATUS_ERR
-
- -

The engine has a fatal problem with this request. The user code should clean up this session.

- -
-
ASYNC_STATUS_OK
-
- -

The request has been successfully submitted.

- -
-
ASYNC_STATUS_EAGAIN
-
- -

The engine has some problem which will be recovered soon, such as a buffer is full, so user code should resume the job.

- -
-
- -

ASYNC_WAIT_CTX_get_status() allows user code to obtain the current status value. If the status is any value other than ASYNC_STATUS_OK then the user code should not expect to receive a callback from the engine even if one has been set.

- -

An example of the usage of the callback method might be the following. User code would initiate cryptographic operations, and the engine code would dispatch this operation to hardware, and if the dispatch is successful, then the engine code would call ASYNC_pause_job() to return control to the user code. After that, user code can perform other tasks. When the hardware completes the operation, normally it is detected by a polling function or an interrupt, as the user code set a callback by calling ASYNC_WAIT_CTX_set_callback() previously, then the registered callback will be called.

- -

ASYNC_WAIT_CTX_free() frees up a single ASYNC_WAIT_CTX object. If the argument is NULL, nothing is done.

- -

RETURN VALUES

- -

ASYNC_WAIT_CTX_new() returns a pointer to the newly allocated ASYNC_WAIT_CTX or NULL on error.

- -

ASYNC_WAIT_CTX_set_wait_fd, ASYNC_WAIT_CTX_get_fd, ASYNC_WAIT_CTX_get_all_fds, ASYNC_WAIT_CTX_get_changed_fds, ASYNC_WAIT_CTX_clear_fd, ASYNC_WAIT_CTX_set_callback, ASYNC_WAIT_CTX_get_callback and ASYNC_WAIT_CTX_set_status all return 1 on success or 0 on error. ASYNC_WAIT_CTX_get_status() returns the engine status.

- -

NOTES

- -

On Windows platforms the <openssl/async.h> header is dependent on some of the types customarily made available by including <windows.h>. The application developer is likely to require control over when the latter is included, commonly as one of the first included headers. Therefore, it is defined as an application developer's responsibility to include <windows.h> prior to <openssl/async.h>.

- -

SEE ALSO

- -

crypto(7), ASYNC_start_job(3)

- -

HISTORY

- -

ASYNC_WAIT_CTX_new(), ASYNC_WAIT_CTX_free(), ASYNC_WAIT_CTX_set_wait_fd(), ASYNC_WAIT_CTX_get_fd(), ASYNC_WAIT_CTX_get_all_fds(), ASYNC_WAIT_CTX_get_changed_fds() and ASYNC_WAIT_CTX_clear_fd() were added in OpenSSL 1.1.0.

- -

ASYNC_WAIT_CTX_set_callback(), ASYNC_WAIT_CTX_get_callback(), ASYNC_WAIT_CTX_set_status(), and ASYNC_WAIT_CTX_get_status() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ASYNC_start_job.html b/openssl-install/share/doc/openssl/html/man3/ASYNC_start_job.html deleted file mode 100644 index 5db318e5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ASYNC_start_job.html +++ /dev/null @@ -1,303 +0,0 @@ - - - - -ASYNC_start_job - - - - - - - - - - -

NAME

- -

ASYNC_get_wait_ctx, ASYNC_init_thread, ASYNC_cleanup_thread, ASYNC_start_job, ASYNC_pause_job, ASYNC_get_current_job, ASYNC_block_pause, ASYNC_unblock_pause, ASYNC_is_capable, ASYNC_stack_alloc_fn, ASYNC_stack_free_fn, ASYNC_set_mem_functions, ASYNC_get_mem_functions - asynchronous job management functions

- -

SYNOPSIS

- -
#include <openssl/async.h>
-
-int ASYNC_init_thread(size_t max_size, size_t init_size);
-void ASYNC_cleanup_thread(void);
-
-int ASYNC_start_job(ASYNC_JOB **job, ASYNC_WAIT_CTX *ctx, int *ret,
-                    int (*func)(void *), void *args, size_t size);
-int ASYNC_pause_job(void);
-
-ASYNC_JOB *ASYNC_get_current_job(void);
-ASYNC_WAIT_CTX *ASYNC_get_wait_ctx(ASYNC_JOB *job);
-void ASYNC_block_pause(void);
-void ASYNC_unblock_pause(void);
-
-int ASYNC_is_capable(void);
-
-typedef void *(*ASYNC_stack_alloc_fn)(size_t *num);
-typedef void (*ASYNC_stack_free_fn)(void *addr);
-int ASYNC_set_mem_functions(ASYNC_stack_alloc_fn alloc_fn,
-                            ASYNC_stack_free_fn free_fn);
-void ASYNC_get_mem_functions(ASYNC_stack_alloc_fn *alloc_fn,
-                             ASYNC_stack_free_fn *free_fn);
- -

DESCRIPTION

- -

OpenSSL implements asynchronous capabilities through an ASYNC_JOB. This represents code that can be started and executes until some event occurs. At that point the code can be paused and control returns to user code until some subsequent event indicates that the job can be resumed. It's OpenSSL specific implementation of cooperative multitasking.

- -

The creation of an ASYNC_JOB is a relatively expensive operation. Therefore, for efficiency reasons, jobs can be created up front and reused many times. They are held in a pool until they are needed, at which point they are removed from the pool, used, and then returned to the pool when the job completes. If the user application is multi-threaded, then ASYNC_init_thread() may be called for each thread that will initiate asynchronous jobs. Before user code exits per-thread resources need to be cleaned up. This will normally occur automatically (see OPENSSL_init_crypto(3)) but may be explicitly initiated by using ASYNC_cleanup_thread(). No asynchronous jobs must be outstanding for the thread when ASYNC_cleanup_thread() is called. Failing to ensure this will result in memory leaks.

- -

The max_size argument limits the number of ASYNC_JOBs that will be held in the pool. If max_size is set to 0 then no upper limit is set. When an ASYNC_JOB is needed but there are none available in the pool already then one will be automatically created, as long as the total of ASYNC_JOBs managed by the pool does not exceed max_size. When the pool is first initialised init_size ASYNC_JOBs will be created immediately. If ASYNC_init_thread() is not called before the pool is first used then it will be called automatically with a max_size of 0 (no upper limit) and an init_size of 0 (no ASYNC_JOBs created up front).

- -

An asynchronous job is started by calling the ASYNC_start_job() function. Initially *job should be NULL. ctx should point to an ASYNC_WAIT_CTX object created through the ASYNC_WAIT_CTX_new(3) function. ret should point to a location where the return value of the asynchronous function should be stored on completion of the job. func represents the function that should be started asynchronously. The data pointed to by args and of size size will be copied and then passed as an argument to func when the job starts. ASYNC_start_job will return one of the following values:

- -
- -
ASYNC_ERR
-
- -

An error occurred trying to start the job. Check the OpenSSL error queue (e.g. see ERR_print_errors(3)) for more details.

- -
-
ASYNC_NO_JOBS
-
- -

There are no jobs currently available in the pool. This call can be retried again at a later time.

- -
-
ASYNC_PAUSE
-
- -

The job was successfully started but was "paused" before it completed (see ASYNC_pause_job() below). A handle to the job is placed in *job. Other work can be performed (if desired) and the job restarted at a later time. To restart a job call ASYNC_start_job() again passing the job handle in *job. The func, args and size parameters will be ignored when restarting a job. When restarting a job ASYNC_start_job() must be called from the same thread that the job was originally started from. ASYNC_WAIT_CTX is used to know when a job is ready to be restarted.

- -
-
ASYNC_FINISH
-
- -

The job completed. *job will be NULL and the return value from func will be placed in *ret.

- -
-
- -

At any one time there can be a maximum of one job actively running per thread (you can have many that are paused). ASYNC_get_current_job() can be used to get a pointer to the currently executing ASYNC_JOB. If no job is currently executing then this will return NULL.

- -

If executing within the context of a job (i.e. having been called directly or indirectly by the function "func" passed as an argument to ASYNC_start_job()) then ASYNC_pause_job() will immediately return control to the calling application with ASYNC_PAUSE returned from the ASYNC_start_job() call. A subsequent call to ASYNC_start_job passing in the relevant ASYNC_JOB in the *job parameter will resume execution from the ASYNC_pause_job() call. If ASYNC_pause_job() is called whilst not within the context of a job then no action is taken and ASYNC_pause_job() returns immediately.

- -

ASYNC_get_wait_ctx() can be used to get a pointer to the ASYNC_WAIT_CTX for the job (see ASYNC_WAIT_CTX_new(3)). ASYNC_WAIT_CTXs contain two different ways to notify applications that a job is ready to be resumed. One is a "wait" file descriptor, and the other is a "callback" mechanism.

- -

The "wait" file descriptor associated with ASYNC_WAIT_CTX is used for applications to wait for the file descriptor to be ready for "read" using a system function call such as select(2) or poll(2) (being ready for "read" indicates that the job should be resumed). If no file descriptor is made available then an application will have to periodically "poll" the job by attempting to restart it to see if it is ready to continue.

- -

ASYNC_WAIT_CTXs also have a "callback" mechanism to notify applications. The callback is set by an application, and it will be automatically called when an engine completes a cryptography operation, so that the application can resume the paused work flow without polling. An engine could be written to look whether the callback has been set. If it has then it would use the callback mechanism in preference to the file descriptor notifications. If a callback is not set then the engine may use file descriptor based notifications. Please note that not all engines may support the callback mechanism, so the callback may not be used even if it has been set. See ASYNC_WAIT_CTX_new() for more details.

- -

The ASYNC_block_pause() function will prevent the currently active job from pausing. The block will remain in place until a subsequent call to ASYNC_unblock_pause(). These functions can be nested, e.g. if you call ASYNC_block_pause() twice then you must call ASYNC_unblock_pause() twice in order to re-enable pausing. If these functions are called while there is no currently active job then they have no effect. This functionality can be useful to avoid deadlock scenarios. For example during the execution of an ASYNC_JOB an application acquires a lock. It then calls some cryptographic function which invokes ASYNC_pause_job(). This returns control back to the code that created the ASYNC_JOB. If that code then attempts to acquire the same lock before resuming the original job then a deadlock can occur. By calling ASYNC_block_pause() immediately after acquiring the lock and ASYNC_unblock_pause() immediately before releasing it then this situation cannot occur.

- -

Some platforms cannot support async operations. The ASYNC_is_capable() function can be used to detect whether the current platform is async capable or not.

- -

Custom memory allocation functions are supported for the POSIX platform. Custom memory allocation functions allow alternative methods of allocating stack memory such as mmap, or using stack memory from the current thread. Using an ASYNC_stack_alloc_fn callback also allows manipulation of the stack size, which defaults to 32k. The stack size can be altered by allocating a stack of a size different to the requested size, and passing back the new stack size in the callback's *num parameter.

- -

RETURN VALUES

- -

ASYNC_init_thread returns 1 on success or 0 otherwise.

- -

ASYNC_start_job returns one of ASYNC_ERR, ASYNC_NO_JOBS, ASYNC_PAUSE or ASYNC_FINISH as described above.

- -

ASYNC_pause_job returns 0 if an error occurred or 1 on success. If called when not within the context of an ASYNC_JOB then this is counted as success so 1 is returned.

- -

ASYNC_get_current_job returns a pointer to the currently executing ASYNC_JOB or NULL if not within the context of a job.

- -

ASYNC_get_wait_ctx() returns a pointer to the ASYNC_WAIT_CTX for the job.

- -

ASYNC_is_capable() returns 1 if the current platform is async capable or 0 otherwise.

- -

ASYNC_set_mem_functions returns 1 if custom stack allocators are supported by the current platform and no allocations have already occurred or 0 otherwise.

- -

NOTES

- -

On Windows platforms the <openssl/async.h> header is dependent on some of the types customarily made available by including <windows.h>. The application developer is likely to require control over when the latter is included, commonly as one of the first included headers. Therefore, it is defined as an application developer's responsibility to include <windows.h> prior to <openssl/async.h>.

- -

EXAMPLES

- -

The following example demonstrates how to use most of the core async APIs:

- -
#ifdef _WIN32
-# include <windows.h>
-#endif
-#include <stdio.h>
-#include <unistd.h>
-#include <openssl/async.h>
-#include <openssl/crypto.h>
-
-int unique = 0;
-
-void cleanup(ASYNC_WAIT_CTX *ctx, const void *key, OSSL_ASYNC_FD r, void *vw)
-{
-    OSSL_ASYNC_FD *w = (OSSL_ASYNC_FD *)vw;
-
-    close(r);
-    close(*w);
-    OPENSSL_free(w);
-}
-
-int jobfunc(void *arg)
-{
-    ASYNC_JOB *currjob;
-    unsigned char *msg;
-    int pipefds[2] = {0, 0};
-    OSSL_ASYNC_FD *wptr;
-    char buf = 'X';
-
-    currjob = ASYNC_get_current_job();
-    if (currjob != NULL) {
-        printf("Executing within a job\n");
-    } else {
-        printf("Not executing within a job - should not happen\n");
-        return 0;
-    }
-
-    msg = (unsigned char *)arg;
-    printf("Passed in message is: %s\n", msg);
-
-    /*
-     * Create a way to inform the calling thread when this job is ready
-     * to resume, in this example we're using file descriptors.
-     * For offloading the task to an asynchronous ENGINE it's not necessary,
-     * the ENGINE should handle that internally.
-     */
-
-    if (pipe(pipefds) != 0) {
-        printf("Failed to create pipe\n");
-        return 0;
-    }
-    wptr = OPENSSL_malloc(sizeof(OSSL_ASYNC_FD));
-    if (wptr == NULL) {
-        printf("Failed to malloc\n");
-        return 0;
-    }
-    *wptr = pipefds[1];
-    ASYNC_WAIT_CTX_set_wait_fd(ASYNC_get_wait_ctx(currjob), &unique,
-                               pipefds[0], wptr, cleanup);
-
-    /*
-     * Normally some external event (like a network read being ready,
-     * disk access being finished, or some hardware offload operation
-     * completing) would cause this to happen at some
-     * later point - but we do it here for demo purposes, i.e.
-     * immediately signalling that the job is ready to be woken up after
-     * we return to main via ASYNC_pause_job().
-     */
-    write(pipefds[1], &buf, 1);
-
-    /*
-     * Return control back to main just before calling a blocking
-     * method. The main thread will wait until pipefds[0] is ready
-     * for reading before returning control to this thread.
-     */
-    ASYNC_pause_job();
-
-    /* Perform the blocking call (it won't block with this example code) */
-    read(pipefds[0], &buf, 1);
-
-    printf ("Resumed the job after a pause\n");
-
-    return 1;
-}
-
-int main(void)
-{
-    ASYNC_JOB *job = NULL;
-    ASYNC_WAIT_CTX *ctx = NULL;
-    int ret;
-    OSSL_ASYNC_FD waitfd;
-    fd_set waitfdset;
-    size_t numfds;
-    unsigned char msg[13] = "Hello world!";
-
-    printf("Starting...\n");
-
-    ctx = ASYNC_WAIT_CTX_new();
-    if (ctx == NULL) {
-        printf("Failed to create ASYNC_WAIT_CTX\n");
-        abort();
-    }
-
-    for (;;) {
-        switch (ASYNC_start_job(&job, ctx, &ret, jobfunc, msg, sizeof(msg))) {
-        case ASYNC_ERR:
-        case ASYNC_NO_JOBS:
-            printf("An error occurred\n");
-            goto end;
-        case ASYNC_PAUSE:
-            printf("Job was paused\n");
-            break;
-        case ASYNC_FINISH:
-            printf("Job finished with return value %d\n", ret);
-            goto end;
-        }
-
-        /* Get the file descriptor we can use to wait for the job
-         * to be ready to be woken up
-         */
-        printf("Waiting for the job to be woken up\n");
-
-        if (!ASYNC_WAIT_CTX_get_all_fds(ctx, NULL, &numfds)
-                || numfds > 1) {
-            printf("Unexpected number of fds\n");
-            abort();
-        }
-        ASYNC_WAIT_CTX_get_all_fds(ctx, &waitfd, &numfds);
-        FD_ZERO(&waitfdset);
-        FD_SET(waitfd, &waitfdset);
-
-        /* Wait for the job to be ready for wakeup */
-        select(waitfd + 1, &waitfdset, NULL, NULL, NULL);
-    }
-
-end:
-    ASYNC_WAIT_CTX_free(ctx);
-    printf("Finishing\n");
-
-    return 0;
-}
- -

The expected output from executing the above example program is:

- -
Starting...
-Executing within a job
-Passed in message is: Hello world!
-Job was paused
-Waiting for the job to be woken up
-Resumed the job after a pause
-Job finished with return value 1
-Finishing
- -

SEE ALSO

- -

crypto(7), ERR_print_errors(3)

- -

HISTORY

- -

ASYNC_init_thread, ASYNC_cleanup_thread, ASYNC_start_job, ASYNC_pause_job, ASYNC_get_current_job, ASYNC_get_wait_ctx(), ASYNC_block_pause(), ASYNC_unblock_pause() and ASYNC_is_capable() were first added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BF_encrypt.html b/openssl-install/share/doc/openssl/html/man3/BF_encrypt.html deleted file mode 100644 index f5984d5d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BF_encrypt.html +++ /dev/null @@ -1,104 +0,0 @@ - - - - -BF_encrypt - - - - - - - - - - -

NAME

- -

BF_set_key, BF_encrypt, BF_decrypt, BF_ecb_encrypt, BF_cbc_encrypt, BF_cfb64_encrypt, BF_ofb64_encrypt, BF_options - Blowfish encryption

- -

SYNOPSIS

- -
#include <openssl/blowfish.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void BF_set_key(BF_KEY *key, int len, const unsigned char *data);
-
-void BF_ecb_encrypt(const unsigned char *in, unsigned char *out,
-                    BF_KEY *key, int enc);
-void BF_cbc_encrypt(const unsigned char *in, unsigned char *out,
-                    long length, BF_KEY *schedule,
-                    unsigned char *ivec, int enc);
-void BF_cfb64_encrypt(const unsigned char *in, unsigned char *out,
-                      long length, BF_KEY *schedule,
-                      unsigned char *ivec, int *num, int enc);
-void BF_ofb64_encrypt(const unsigned char *in, unsigned char *out,
-                      long length, BF_KEY *schedule,
-                      unsigned char *ivec, int *num);
-const char *BF_options(void);
-
-void BF_encrypt(BF_LONG *data, const BF_KEY *key);
-void BF_decrypt(BF_LONG *data, const BF_KEY *key);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_EncryptInit_ex(3), EVP_EncryptUpdate(3) and EVP_EncryptFinal_ex(3) or the equivalently named decrypt functions.

- -

This library implements the Blowfish cipher, which was invented and described by Counterpane (see http://www.counterpane.com/blowfish.html ).

- -

Blowfish is a block cipher that operates on 64 bit (8 byte) blocks of data. It uses a variable size key, but typically, 128 bit (16 byte) keys are considered good for strong encryption. Blowfish can be used in the same modes as DES (see des_modes(7)). Blowfish is currently one of the faster block ciphers. It is quite a bit faster than DES, and much faster than IDEA or RC2.

- -

Blowfish consists of a key setup phase and the actual encryption or decryption phase.

- -

BF_set_key() sets up the BF_KEY key using the len bytes long key at data.

- -

BF_ecb_encrypt() is the basic Blowfish encryption and decryption function. It encrypts or decrypts the first 64 bits of in using the key key, putting the result in out. enc decides if encryption (BF_ENCRYPT) or decryption (BF_DECRYPT) shall be performed. The vector pointed at by in and out must be 64 bits in length, no less. If they are larger, everything after the first 64 bits is ignored.

- -

The mode functions BF_cbc_encrypt(), BF_cfb64_encrypt() and BF_ofb64_encrypt() all operate on variable length data. They all take an initialization vector ivec which needs to be passed along into the next call of the same function for the same message. ivec may be initialized with anything, but the recipient needs to know what it was initialized with, or it won't be able to decrypt. Some programs and protocols simplify this, like SSH, where ivec is simply initialized to zero. BF_cbc_encrypt() operates on data that is a multiple of 8 bytes long, while BF_cfb64_encrypt() and BF_ofb64_encrypt() are used to encrypt a variable number of bytes (the amount does not have to be an exact multiple of 8). The purpose of the latter two is to simulate stream ciphers, and therefore, they need the parameter num, which is a pointer to an integer where the current offset in ivec is stored between calls. This integer must be initialized to zero when ivec is initialized.

- -

BF_cbc_encrypt() is the Cipher Block Chaining function for Blowfish. It encrypts or decrypts the 64 bits chunks of in using the key schedule, putting the result in out. enc decides if encryption (BF_ENCRYPT) or decryption (BF_DECRYPT) shall be performed. ivec must point at an 8 byte long initialization vector.

- -

BF_cfb64_encrypt() is the CFB mode for Blowfish with 64 bit feedback. It encrypts or decrypts the bytes in in using the key schedule, putting the result in out. enc decides if encryption (BF_ENCRYPT) or decryption (BF_DECRYPT) shall be performed. ivec must point at an 8 byte long initialization vector. num must point at an integer which must be initially zero.

- -

BF_ofb64_encrypt() is the OFB mode for Blowfish with 64 bit feedback. It uses the same parameters as BF_cfb64_encrypt(), which must be initialized the same way.

- -

BF_encrypt() and BF_decrypt() are the lowest level functions for Blowfish encryption. They encrypt/decrypt the first 64 bits of the vector pointed by data, using the key key. These functions should not be used unless you implement 'modes' of Blowfish. The alternative is to use BF_ecb_encrypt(). If you still want to use these functions, you should be aware that they take each 32-bit chunk in host-byte order, which is little-endian on little-endian platforms and big-endian on big-endian ones.

- -

RETURN VALUES

- -

None of the functions presented here return any value.

- -

NOTE

- -

Applications should use the higher level functions EVP_EncryptInit(3) etc. instead of calling these functions directly.

- -

SEE ALSO

- -

EVP_EncryptInit(3), des_modes(7)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_ADDR.html b/openssl-install/share/doc/openssl/html/man3/BIO_ADDR.html deleted file mode 100644 index bde47b12..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_ADDR.html +++ /dev/null @@ -1,109 +0,0 @@ - - - - -BIO_ADDR - - - - - - - - - - -

NAME

- -

BIO_ADDR, BIO_ADDR_new, BIO_ADDR_copy, BIO_ADDR_dup, BIO_ADDR_clear, BIO_ADDR_free, BIO_ADDR_rawmake, BIO_ADDR_family, BIO_ADDR_rawaddress, BIO_ADDR_rawport, BIO_ADDR_hostname_string, BIO_ADDR_service_string, BIO_ADDR_path_string - BIO_ADDR routines

- -

SYNOPSIS

- -
#include <sys/types.h>
-#include <openssl/bio.h>
-
-typedef union bio_addr_st BIO_ADDR;
-
-BIO_ADDR *BIO_ADDR_new(void);
-int BIO_ADDR_copy(BIO_ADDR *dst, const BIO_ADDR *src);
-BIO_ADDR *BIO_ADDR_dup(const BIO_ADDR *ap);
-void BIO_ADDR_free(BIO_ADDR *ap);
-void BIO_ADDR_clear(BIO_ADDR *ap);
-int BIO_ADDR_rawmake(BIO_ADDR *ap, int family,
-                     const void *where, size_t wherelen, unsigned short port);
-int BIO_ADDR_family(const BIO_ADDR *ap);
-int BIO_ADDR_rawaddress(const BIO_ADDR *ap, void *p, size_t *l);
-unsigned short BIO_ADDR_rawport(const BIO_ADDR *ap);
-char *BIO_ADDR_hostname_string(const BIO_ADDR *ap, int numeric);
-char *BIO_ADDR_service_string(const BIO_ADDR *ap, int numeric);
-char *BIO_ADDR_path_string(const BIO_ADDR *ap);
- -

DESCRIPTION

- -

The BIO_ADDR type is a wrapper around all types of socket addresses that OpenSSL deals with, currently transparently supporting AF_INET, AF_INET6 and AF_UNIX according to what's available on the platform at hand.

- -

BIO_ADDR_new() creates a new unfilled BIO_ADDR, to be used with routines that will fill it with information, such as BIO_accept_ex().

- -

BIO_ADDR_copy() copies the contents of src into dst. Neither src or dst can be NULL.

- -

BIO_ADDR_dup() creates a new BIO_ADDR, with a copy of the address data in ap.

- -

BIO_ADDR_free() frees a BIO_ADDR created with BIO_ADDR_new() or BIO_ADDR_dup(). If the argument is NULL, nothing is done.

- -

BIO_ADDR_clear() clears any data held within the provided BIO_ADDR and sets it back to an uninitialised state.

- -

BIO_ADDR_rawmake() takes a protocol family, a byte array of size wherelen with an address in network byte order pointed at by where and a port number in network byte order in port (except for the AF_UNIX protocol family, where port is meaningless and therefore ignored) and populates the given BIO_ADDR with them. In case this creates a AF_UNIX BIO_ADDR, wherelen is expected to be the length of the path string (not including the terminating NUL, such as the result of a call to strlen()). Read on about the addresses in "RAW ADDRESSES" below.

- -

BIO_ADDR_family() returns the protocol family of the given BIO_ADDR. The possible non-error results are one of the constants AF_INET, AF_INET6 and AF_UNIX. It will also return AF_UNSPEC if the BIO_ADDR has not been initialised.

- -

BIO_ADDR_rawaddress() will write the raw address of the given BIO_ADDR in the area pointed at by p if p is non-NULL, and will set *l to be the amount of bytes the raw address takes up if l is non-NULL. A technique to only find out the size of the address is a call with p set to NULL. The raw address will be in network byte order, most significant byte first. In case this is a AF_UNIX BIO_ADDR, l gets the length of the path string (not including the terminating NUL, such as the result of a call to strlen()). Read on about the addresses in "RAW ADDRESSES" below.

- -

BIO_ADDR_rawport() returns the raw port of the given BIO_ADDR. The raw port will be in network byte order.

- -

BIO_ADDR_hostname_string() returns a character string with the hostname of the given BIO_ADDR. If numeric is 1, the string will contain the numerical form of the address. This only works for BIO_ADDR of the protocol families AF_INET and AF_INET6. The returned string has been allocated on the heap and must be freed with OPENSSL_free().

- -

BIO_ADDR_service_string() returns a character string with the service name of the port of the given BIO_ADDR. If numeric is 1, the string will contain the port number. This only works for BIO_ADDR of the protocol families AF_INET and AF_INET6. The returned string has been allocated on the heap and must be freed with OPENSSL_free().

- -

BIO_ADDR_path_string() returns a character string with the path of the given BIO_ADDR. This only works for BIO_ADDR of the protocol family AF_UNIX. The returned string has been allocated on the heap and must be freed with OPENSSL_free().

- -

RAW ADDRESSES

- -

Both BIO_ADDR_rawmake() and BIO_ADDR_rawaddress() take a pointer to a network byte order address of a specific site. Internally, those are treated as a pointer to struct in_addr (for AF_INET), struct in6_addr (for AF_INET6) or char * (for AF_UNIX), all depending on the protocol family the address is for.

- -

RETURN VALUES

- -

The string producing functions BIO_ADDR_hostname_string(), BIO_ADDR_service_string() and BIO_ADDR_path_string() will return NULL on error and leave an error indication on the OpenSSL error stack.

- -

BIO_ADDR_copy() returns 1 on success or 0 on error.

- -

All other functions described here return 0 or NULL when the information they should return isn't available.

- -

SEE ALSO

- -

BIO_connect(3), BIO_s_connect(3)

- -

HISTORY

- -

BIO_ADDR_copy() and BIO_ADDR_dup() were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_ADDRINFO.html b/openssl-install/share/doc/openssl/html/man3/BIO_ADDRINFO.html deleted file mode 100644 index 1f807906..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_ADDRINFO.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -BIO_ADDRINFO - - - - - - - - - - -

NAME

- -

BIO_lookup_type, BIO_ADDRINFO, BIO_ADDRINFO_next, BIO_ADDRINFO_free, BIO_ADDRINFO_family, BIO_ADDRINFO_socktype, BIO_ADDRINFO_protocol, BIO_ADDRINFO_address, BIO_lookup_ex, BIO_lookup - BIO_ADDRINFO type and routines

- -

SYNOPSIS

- -
#include <sys/types.h>
-#include <openssl/bio.h>
-
-typedef union bio_addrinfo_st BIO_ADDRINFO;
-
-enum BIO_lookup_type {
-    BIO_LOOKUP_CLIENT, BIO_LOOKUP_SERVER
-};
-
-int BIO_lookup_ex(const char *host, const char *service, int lookup_type,
-                  int family, int socktype, int protocol, BIO_ADDRINFO **res);
-int BIO_lookup(const char *host, const char *service,
-               enum BIO_lookup_type lookup_type,
-               int family, int socktype, BIO_ADDRINFO **res);
-
-const BIO_ADDRINFO *BIO_ADDRINFO_next(const BIO_ADDRINFO *bai);
-int BIO_ADDRINFO_family(const BIO_ADDRINFO *bai);
-int BIO_ADDRINFO_socktype(const BIO_ADDRINFO *bai);
-int BIO_ADDRINFO_protocol(const BIO_ADDRINFO *bai);
-const BIO_ADDR *BIO_ADDRINFO_address(const BIO_ADDRINFO *bai);
-void BIO_ADDRINFO_free(BIO_ADDRINFO *bai);
- -

DESCRIPTION

- -

The BIO_ADDRINFO type is a wrapper for address information types provided on your platform.

- -

BIO_ADDRINFO normally forms a chain of several that can be picked at one by one.

- -

BIO_lookup_ex() looks up a specified host and service, and uses lookup_type to determine what the default address should be if host is NULL. family, socktype and protocol are used to determine what protocol family, socket type and protocol should be used for the lookup. family can be any of AF_INET, AF_INET6, AF_UNIX and AF_UNSPEC. socktype can be SOCK_STREAM, SOCK_DGRAM or 0. Specifying 0 indicates that any type can be used. protocol specifies a protocol such as IPPROTO_TCP, IPPROTO_UDP or IPPORTO_SCTP. If set to 0 than any protocol can be used. res points at a pointer to hold the start of a BIO_ADDRINFO chain.

- -

For the family AF_UNIX, BIO_lookup_ex() will ignore the service parameter and expects the host parameter to hold the path to the socket file.

- -

BIO_lookup() does the same as BIO_lookup_ex() but does not provide the ability to select based on the protocol (any protocol may be returned).

- -

BIO_ADDRINFO_family() returns the family of the given BIO_ADDRINFO. The result will be one of the constants AF_INET, AF_INET6 and AF_UNIX.

- -

BIO_ADDRINFO_socktype() returns the socket type of the given BIO_ADDRINFO. The result will be one of the constants SOCK_STREAM and SOCK_DGRAM.

- -

BIO_ADDRINFO_protocol() returns the protocol id of the given BIO_ADDRINFO. The result will be one of the constants IPPROTO_TCP and IPPROTO_UDP.

- -

BIO_ADDRINFO_address() returns the underlying BIO_ADDR of the given BIO_ADDRINFO.

- -

BIO_ADDRINFO_next() returns the next BIO_ADDRINFO in the chain from the given one.

- -

BIO_ADDRINFO_free() frees the chain of BIO_ADDRINFO starting with the given one. If the argument is NULL, nothing is done.

- -

RETURN VALUES

- -

BIO_lookup_ex() and BIO_lookup() return 1 on success and 0 when an error occurred, and will leave an error indication on the OpenSSL error stack in that case.

- -

All other functions described here return 0 or NULL when the information they should return isn't available.

- -

NOTES

- -

The BIO_lookup_ex() implementation uses the platform provided getaddrinfo() function. On Linux it is known that specifying 0 for the protocol will not return any SCTP based addresses when calling getaddrinfo(). Therefore, if an SCTP address is required then the protocol parameter to BIO_lookup_ex() should be explicitly set to IPPROTO_SCTP. The same may be true on other platforms.

- -

HISTORY

- -

The BIO_lookup_ex() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_connect.html b/openssl-install/share/doc/openssl/html/man3/BIO_connect.html deleted file mode 100644 index 136a246e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_connect.html +++ /dev/null @@ -1,127 +0,0 @@ - - - - -BIO_connect - - - - - - - - - - -

NAME

- -

BIO_socket, BIO_bind, BIO_connect, BIO_listen, BIO_accept_ex, BIO_closesocket - BIO socket communication setup routines

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-int BIO_socket(int domain, int socktype, int protocol, int options);
-int BIO_bind(int sock, const BIO_ADDR *addr, int options);
-int BIO_connect(int sock, const BIO_ADDR *addr, int options);
-int BIO_listen(int sock, const BIO_ADDR *addr, int options);
-int BIO_accept_ex(int accept_sock, BIO_ADDR *peer, int options);
-int BIO_closesocket(int sock);
- -

DESCRIPTION

- -

BIO_socket() creates a socket in the domain domain, of type socktype and protocol. Socket options are currently unused, but is present for future use.

- -

BIO_bind() binds the source address and service to a socket and may be useful before calling BIO_connect(). The options may include BIO_SOCK_REUSEADDR, which is described in "FLAGS" below.

- -

BIO_connect() connects sock to the address and service given by addr. Connection options may be zero or any combination of BIO_SOCK_KEEPALIVE, BIO_SOCK_NONBLOCK and BIO_SOCK_NODELAY. The flags are described in "FLAGS" below.

- -

BIO_listen() has sock start listening on the address and service given by addr. Connection options may be zero or any combination of BIO_SOCK_KEEPALIVE, BIO_SOCK_NONBLOCK, BIO_SOCK_NODELAY, BIO_SOCK_REUSEADDR and BIO_SOCK_V6_ONLY. The flags are described in "FLAGS" below.

- -

BIO_accept_ex() waits for an incoming connections on the given socket accept_sock. When it gets a connection, the address and port of the peer gets stored in peer if that one is non-NULL. Accept options may be zero or BIO_SOCK_NONBLOCK, and is applied on the accepted socket. The flags are described in "FLAGS" below.

- -

BIO_closesocket() closes sock.

- -

FLAGS

- -
- -
BIO_SOCK_KEEPALIVE
-
- -

Enables regular sending of keep-alive messages.

- -
-
BIO_SOCK_NONBLOCK
-
- -

Sets the socket to nonblocking mode.

- -
-
BIO_SOCK_NODELAY
-
- -

Corresponds to TCP_NODELAY, and disables the Nagle algorithm. With this set, any data will be sent as soon as possible instead of being buffered until there's enough for the socket to send out in one go.

- -
-
BIO_SOCK_REUSEADDR
-
- -

Try to reuse the address and port combination for a recently closed port.

- -
-
BIO_SOCK_V6_ONLY
-
- -

When creating an IPv6 socket, make it only listen for IPv6 addresses and not IPv4 addresses mapped to IPv6.

- -
-
BIO_SOCK_TFO
-
- -

Enables TCP Fast Open on the socket. Uses appropriate APIs on supported operating systems, including Linux, macOS and FreeBSD. Can be used with BIO_connect(), BIO_set_conn_mode(), BIO_set_bind_mode(), and BIO_listen(). On Linux kernels before 4.14, use BIO_set_conn_address() to specify the peer address before starting the TLS handshake.

- -
-
- -

These flags are bit flags, so they are to be combined with the | operator, for example:

- -
BIO_connect(sock, addr, BIO_SOCK_KEEPALIVE | BIO_SOCK_NONBLOCK);
- -

RETURN VALUES

- -

BIO_socket() returns the socket number on success or INVALID_SOCKET (-1) on error. When an error has occurred, the OpenSSL error stack will hold the error data and errno has the system error.

- -

BIO_bind(), BIO_connect() and BIO_listen() return 1 on success or 0 on error. When an error has occurred, the OpenSSL error stack will hold the error data and errno has the system error.

- -

BIO_accept_ex() returns the accepted socket on success or INVALID_SOCKET (-1) on error. When an error has occurred, the OpenSSL error stack will hold the error data and errno has the system error.

- -

SEE ALSO

- -

BIO_ADDR(3)

- -

HISTORY

- -

BIO_gethostname(), BIO_get_port(), BIO_get_host_ip(), BIO_get_accept_socket() and BIO_accept() were deprecated in OpenSSL 1.1.0. Use the functions described above instead.

- -

COPYRIGHT

- -

Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_ctrl.html b/openssl-install/share/doc/openssl/html/man3/BIO_ctrl.html deleted file mode 100644 index bee213db..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_ctrl.html +++ /dev/null @@ -1,151 +0,0 @@ - - - - -BIO_ctrl - - - - - - - - - - -

NAME

- -

BIO_ctrl, BIO_callback_ctrl, BIO_ptr_ctrl, BIO_int_ctrl, BIO_reset, BIO_seek, BIO_tell, BIO_flush, BIO_eof, BIO_set_close, BIO_get_close, BIO_pending, BIO_wpending, BIO_ctrl_pending, BIO_ctrl_wpending, BIO_get_info_callback, BIO_set_info_callback, BIO_info_cb, BIO_get_ktls_send, BIO_get_ktls_recv, BIO_set_conn_mode, BIO_get_conn_mode, BIO_set_tfo - BIO control operations

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-typedef int BIO_info_cb(BIO *b, int state, int res);
-
-long BIO_ctrl(BIO *bp, int cmd, long larg, void *parg);
-long BIO_callback_ctrl(BIO *b, int cmd, BIO_info_cb *cb);
-void *BIO_ptr_ctrl(BIO *bp, int cmd, long larg);
-long BIO_int_ctrl(BIO *bp, int cmd, long larg, int iarg);
-
-int BIO_reset(BIO *b);
-int BIO_seek(BIO *b, int ofs);
-int BIO_tell(BIO *b);
-int BIO_flush(BIO *b);
-int BIO_eof(BIO *b);
-int BIO_set_close(BIO *b, long flag);
-int BIO_get_close(BIO *b);
-int BIO_pending(BIO *b);
-int BIO_wpending(BIO *b);
-size_t BIO_ctrl_pending(BIO *b);
-size_t BIO_ctrl_wpending(BIO *b);
-
-int BIO_get_info_callback(BIO *b, BIO_info_cb **cbp);
-int BIO_set_info_callback(BIO *b, BIO_info_cb *cb);
-
-int BIO_get_ktls_send(BIO *b);
-int BIO_get_ktls_recv(BIO *b);
-
-int BIO_set_conn_mode(BIO *b, int mode);
-int BIO_get_conn_mode(BIO *b);
-
-int BIO_set_tfo(BIO *b, int onoff);
- -

DESCRIPTION

- -

BIO_ctrl(), BIO_callback_ctrl(), BIO_ptr_ctrl() and BIO_int_ctrl() are BIO "control" operations taking arguments of various types. These functions are not normally called directly, various macros are used instead. The standard macros are described below, macros specific to a particular type of BIO are described in the specific BIOs manual page as well as any special features of the standard calls.

- -

BIO_reset() typically resets a BIO to some initial state, in the case of file related BIOs for example it rewinds the file pointer to the start of the file.

- -

BIO_seek() resets a file related BIO's (that is file descriptor and FILE BIOs) file position pointer to ofs bytes from start of file.

- -

BIO_tell() returns the current file position of a file related BIO.

- -

BIO_flush() normally writes out any internally buffered data, in some cases it is used to signal EOF and that no more data will be written.

- -

BIO_eof() returns 1 if the BIO has read EOF, the precise meaning of "EOF" varies according to the BIO type.

- -

BIO_set_close() sets the BIO b close flag to flag. flag can take the value BIO_CLOSE or BIO_NOCLOSE. Typically BIO_CLOSE is used in a source/sink BIO to indicate that the underlying I/O stream should be closed when the BIO is freed.

- -

BIO_get_close() returns the BIOs close flag.

- -

BIO_pending(), BIO_ctrl_pending(), BIO_wpending() and BIO_ctrl_wpending() return the number of pending characters in the BIOs read and write buffers. Not all BIOs support these calls. BIO_ctrl_pending() and BIO_ctrl_wpending() return a size_t type and are functions, BIO_pending() and BIO_wpending() are macros which call BIO_ctrl().

- -

BIO_get_ktls_send() returns 1 if the BIO is using the Kernel TLS data-path for sending. Otherwise, it returns zero. BIO_get_ktls_recv() returns 1 if the BIO is using the Kernel TLS data-path for receiving. Otherwise, it returns zero.

- -

BIO_get_conn_mode() returns the BIO connection mode. BIO_set_conn_mode() sets the BIO connection mode.

- -

BIO_set_tfo() disables TCP Fast Open when onoff is 0, and enables TCP Fast Open when onoff is nonzero. Setting the value to 1 is equivalent to setting BIO_SOCK_TFO in BIO_set_conn_mode().

- -

RETURN VALUES

- -

BIO_reset() normally returns 1 for success and <=0 for failure. File BIOs are an exception, they return 0 for success and -1 for failure.

- -

BIO_seek() and BIO_tell() both return the current file position on success and -1 for failure, except file BIOs which for BIO_seek() always return 0 for success and -1 for failure.

- -

BIO_flush() returns 1 for success and <=0 for failure.

- -

BIO_eof() returns 1 if EOF has been reached, 0 if not, or negative values for failure.

- -

BIO_set_close() returns 1 on success or <=0 for failure.

- -

BIO_get_close() returns the close flag value: BIO_CLOSE or BIO_NOCLOSE. It also returns other negative values if an error occurs.

- -

BIO_pending(), BIO_ctrl_pending(), BIO_wpending() and BIO_ctrl_wpending() return the amount of pending data. BIO_pending() and BIO_wpending() return negative value or 0 on error. BIO_ctrl_pending() and BIO_ctrl_wpending() return 0 on error.

- -

BIO_get_ktls_send() returns 1 if the BIO is using the Kernel TLS data-path for sending. Otherwise, it returns zero. BIO_get_ktls_recv() returns 1 if the BIO is using the Kernel TLS data-path for receiving. Otherwise, it returns zero.

- -

BIO_set_conn_mode() returns 1 for success and 0 for failure. BIO_get_conn_mode() returns the current connection mode. Which may contain the bitwise-or of the following flags:

- -
BIO_SOCK_REUSEADDR
-BIO_SOCK_V6_ONLY
-BIO_SOCK_KEEPALIVE
-BIO_SOCK_NONBLOCK
-BIO_SOCK_NODELAY
-BIO_SOCK_TFO
- -

BIO_set_tfo() returns 1 for success, and 0 for failure.

- -

NOTES

- -

BIO_flush(), because it can write data may return 0 or -1 indicating that the call should be retried later in a similar manner to BIO_write_ex(). The BIO_should_retry() call should be used and appropriate action taken is the call fails.

- -

The return values of BIO_pending() and BIO_wpending() may not reliably determine the amount of pending data in all cases. For example in the case of a file BIO some data may be available in the FILE structures internal buffers but it is not possible to determine this in a portably way. For other types of BIO they may not be supported.

- -

Filter BIOs if they do not internally handle a particular BIO_ctrl() operation usually pass the operation to the next BIO in the chain. This often means there is no need to locate the required BIO for a particular operation, it can be called on a chain and it will be automatically passed to the relevant BIO. However, this can cause unexpected results: for example no current filter BIOs implement BIO_seek(), but this may still succeed if the chain ends in a FILE or file descriptor BIO.

- -

Source/sink BIOs return an 0 if they do not recognize the BIO_ctrl() operation.

- -

BUGS

- -

Some of the return values are ambiguous and care should be taken. In particular a return value of 0 can be returned if an operation is not supported, if an error occurred, if EOF has not been reached and in the case of BIO_seek() on a file BIO for a successful operation.

- -

In older versions of OpenSSL the BIO_ctrl_pending() and BIO_ctrl_wpending() could return values greater than INT_MAX on error.

- -

HISTORY

- -

The BIO_get_ktls_send() and BIO_get_ktls_recv() macros were added in OpenSSL 3.0. They were modified to never return -1 in OpenSSL 3.0.4.

- -

The BIO_get_conn_mode(), BIO_set_conn_mode() and BIO_set_tfo() functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_base64.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_base64.html deleted file mode 100644 index e0e16781..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_base64.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -BIO_f_base64 - - - - - - - - - - -

NAME

- -

BIO_f_base64 - base64 BIO filter

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-#include <openssl/evp.h>
-
-const BIO_METHOD *BIO_f_base64(void);
- -

DESCRIPTION

- -

BIO_f_base64() returns the base64 BIO method. This is a filter BIO that base64 encodes any data written through it and decodes any data read through it.

- -

Base64 BIOs do not support BIO_gets() or BIO_puts().

- -

For writing, by default output is divided to lines of length 64 characters and there is a newline at the end of output. This behavior can be changed with BIO_FLAGS_BASE64_NO_NL flag.

- -

For reading, the first line of base64 content should be at most 1024 bytes long including newline unless the flag BIO_FLAGS_BASE64_NO_NL is set. Subsequent input lines can be of any length (i.e., newlines may appear anywhere in the input) and a newline at the end of input is not needed.

- -

Also when reading, unless the flag BIO_FLAGS_BASE64_NO_NL is set, initial lines that contain non-base64 content (whitespace is tolerated and ignored) are skipped, as are lines longer than 1024 bytes. Decoding starts with the first line that is shorter than 1024 bytes (including the newline) and consists of only (at least one) valid base64 characters plus optional whitespace. Decoding stops when base64 padding is encountered, a soft end-of-input character (-, see EVP_DecodeUpdate(3)) occurs as the first byte after a complete group of 4 valid base64 characters is decoded, or when an error occurs (e.g. due to input characters other than valid base64 or whitespace).

- -

If decoding stops as a result of an error, the first BIO_read(3) that returns no decoded data will typically return a negative result, rather than 0 (which indicates normal end of input). However, a negative return value can also occur if the underlying BIO supports retries, see BIO_should_read(3) and BIO_set_mem_eof_return(3).

- -

BIO_flush() on a base64 BIO that is being written through is used to signal that no more data is to be encoded: this is used to flush the final block through the BIO.

- -

The flag BIO_FLAGS_BASE64_NO_NL can be set with BIO_set_flags(). For writing, it causes all data to be written on one line without newline at the end. For reading, it removes all expectations on newlines in the input data.

- -

NOTES

- -

Because of the format of base64 encoding the end of the encoded block cannot always be reliably determined.

- -

RETURN VALUES

- -

BIO_f_base64() returns the base64 BIO method.

- -

EXAMPLES

- -

Base64 encode the string "Hello World\n" and write the result to standard output:

- -
BIO *bio, *b64;
-char message[] = "Hello World \n";
-
-b64 = BIO_new(BIO_f_base64());
-bio = BIO_new_fp(stdout, BIO_NOCLOSE);
-BIO_push(b64, bio);
-BIO_write(b64, message, strlen(message));
-BIO_flush(b64);
-
-BIO_free_all(b64);
- -

Read base64 encoded data from standard input and write the decoded data to standard output:

- -
BIO *bio, *b64, *bio_out;
-char inbuf[512];
-int inlen;
-
-b64 = BIO_new(BIO_f_base64());
-bio = BIO_new_fp(stdin, BIO_NOCLOSE);
-bio_out = BIO_new_fp(stdout, BIO_NOCLOSE);
-BIO_push(b64, bio);
-while ((inlen = BIO_read(b64, inbuf, 512)) > 0)
-    BIO_write(bio_out, inbuf, inlen);
-
-BIO_flush(bio_out);
-BIO_free_all(b64);
- -

BUGS

- -

The hyphen character (-) is treated as an ad hoc soft end-of-input character when it occurs at the start of a base64 group of 4 encoded characters.

- -

This heuristic works to detect the ends of base64 blocks in PEM or multi-part MIME, provided there are no stray hyphens in the middle input. But it is just a heuristic, and sufficiently unusual input could produce unexpected results.

- -

There should perhaps be some way of specifying a test that the BIO can perform to reliably determine EOF (for example a MIME boundary).

- -

It may be possible for BIO_read(3) to return zero, rather than -1, even if an error has been detected, more tests are needed to cover all the potential error paths.

- -

SEE ALSO

- -

BIO_read(3), BIO_should_read(3), BIO_set_mem_eof_return(3), EVP_DecodeUpdate(3).

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_buffer.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_buffer.html deleted file mode 100644 index d77b0cae..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_buffer.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -BIO_f_buffer - - - - - - - - - - -

NAME

- -

BIO_get_buffer_num_lines, BIO_set_read_buffer_size, BIO_set_write_buffer_size, BIO_set_buffer_size, BIO_set_buffer_read_data, BIO_f_buffer - buffering BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_f_buffer(void);
-
-long BIO_get_buffer_num_lines(BIO *b);
-long BIO_set_read_buffer_size(BIO *b, long size);
-long BIO_set_write_buffer_size(BIO *b, long size);
-long BIO_set_buffer_size(BIO *b, long size);
-long BIO_set_buffer_read_data(BIO *b, void *buf, long num);
- -

DESCRIPTION

- -

BIO_f_buffer() returns the buffering BIO method.

- -

Data written to a buffering BIO is buffered and periodically written to the next BIO in the chain. Data read from a buffering BIO comes from an internal buffer which is filled from the next BIO in the chain. Both BIO_gets() and BIO_puts() are supported.

- -

Calling BIO_reset() on a buffering BIO clears any buffered data.

- -

BIO_get_buffer_num_lines() returns the number of lines currently buffered.

- -

BIO_set_read_buffer_size(), BIO_set_write_buffer_size() and BIO_set_buffer_size() set the read, write or both read and write buffer sizes to size. The initial buffer size is DEFAULT_BUFFER_SIZE, currently 4096. Any attempt to reduce the buffer size below DEFAULT_BUFFER_SIZE is ignored. Any buffered data is cleared when the buffer is resized.

- -

BIO_set_buffer_read_data() clears the read buffer and fills it with num bytes of buf. If num is larger than the current buffer size the buffer is expanded.

- -

NOTES

- -

These functions, other than BIO_f_buffer(), are implemented as macros.

- -

Buffering BIOs implement BIO_read_ex() and BIO_gets() by using BIO_read_ex() operations on the next BIO in the chain and storing the result in an internal buffer, from which bytes are given back to the caller as appropriate for the call; a BIO_gets() is guaranteed to give the caller a whole line, and BIO_read_ex() is guaranteed to give the caller the number of bytes it asks for, unless there's an error or end of communication is reached in the next BIO. By prepending a buffering BIO to a chain it is therefore possible to provide BIO_gets() or exact size BIO_read_ex() functionality if the following BIOs do not support it.

- -

Do not add more than one BIO_f_buffer() to a BIO chain. The result of doing so will force a full read of the size of the internal buffer of the top BIO_f_buffer(), which is 4 KiB at a minimum.

- -

Data is only written to the next BIO in the chain when the write buffer fills or when BIO_flush() is called. It is therefore important to call BIO_flush() whenever any pending data should be written such as when removing a buffering BIO using BIO_pop(). BIO_flush() may need to be retried if the ultimate source/sink BIO is non blocking.

- -

RETURN VALUES

- -

BIO_f_buffer() returns the buffering BIO method.

- -

BIO_get_buffer_num_lines() returns the number of lines buffered (may be 0) or a negative value in case of errors.

- -

BIO_set_read_buffer_size(), BIO_set_write_buffer_size() and BIO_set_buffer_size() return 1 if the buffer was successfully resized or <=0 for failure.

- -

BIO_set_buffer_read_data() returns 1 if the data was set correctly or <=0 if there was an error.

- -

SEE ALSO

- -

bio(7), BIO_reset(3), BIO_flush(3), BIO_pop(3), BIO_ctrl(3).

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_cipher.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_cipher.html deleted file mode 100644 index 2a140a19..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_cipher.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -BIO_f_cipher - - - - - - - - - - -

NAME

- -

BIO_f_cipher, BIO_set_cipher, BIO_get_cipher_status, BIO_get_cipher_ctx - cipher BIO filter

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-#include <openssl/evp.h>
-
-const BIO_METHOD *BIO_f_cipher(void);
-int BIO_set_cipher(BIO *b, const EVP_CIPHER *cipher,
-                   const unsigned char *key, const unsigned char *iv, int enc);
-int BIO_get_cipher_status(BIO *b);
-int BIO_get_cipher_ctx(BIO *b, EVP_CIPHER_CTX **pctx);
- -

DESCRIPTION

- -

BIO_f_cipher() returns the cipher BIO method. This is a filter BIO that encrypts any data written through it, and decrypts any data read from it. It is a BIO wrapper for the cipher routines EVP_CipherInit(), EVP_CipherUpdate() and EVP_CipherFinal().

- -

Cipher BIOs do not support BIO_gets() or BIO_puts().

- -

BIO_flush() on an encryption BIO that is being written through is used to signal that no more data is to be encrypted: this is used to flush and possibly pad the final block through the BIO.

- -

BIO_set_cipher() sets the cipher of BIO b to cipher using key key and IV iv. enc should be set to 1 for encryption and zero for decryption.

- -

When reading from an encryption BIO the final block is automatically decrypted and checked when EOF is detected. BIO_get_cipher_status() is a BIO_ctrl() macro which can be called to determine whether the decryption operation was successful.

- -

BIO_get_cipher_ctx() is a BIO_ctrl() macro which retrieves the internal BIO cipher context. The retrieved context can be used in conjunction with the standard cipher routines to set it up. This is useful when BIO_set_cipher() is not flexible enough for the applications needs.

- -

NOTES

- -

When encrypting BIO_flush() must be called to flush the final block through the BIO. If it is not then the final block will fail a subsequent decrypt.

- -

When decrypting an error on the final block is signaled by a zero return value from the read operation. A successful decrypt followed by EOF will also return zero for the final read. BIO_get_cipher_status() should be called to determine if the decrypt was successful.

- -

As always, if BIO_gets() or BIO_puts() support is needed then it can be achieved by preceding the cipher BIO with a buffering BIO.

- -

RETURN VALUES

- -

BIO_f_cipher() returns the cipher BIO method.

- -

BIO_set_cipher() returns 1 for success and 0 for failure.

- -

BIO_get_cipher_status() returns 1 for a successful decrypt and <=0 for failure.

- -

BIO_get_cipher_ctx() returns 1 for success and <=0 for failure.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_md.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_md.html deleted file mode 100644 index 5370bbb0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_md.html +++ /dev/null @@ -1,156 +0,0 @@ - - - - -BIO_f_md - - - - - - - - - - -

NAME

- -

BIO_f_md, BIO_set_md, BIO_get_md, BIO_get_md_ctx - message digest BIO filter

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-#include <openssl/evp.h>
-
-const BIO_METHOD *BIO_f_md(void);
-int BIO_set_md(BIO *b, EVP_MD *md);
-int BIO_get_md(BIO *b, EVP_MD **mdp);
-int BIO_get_md_ctx(BIO *b, EVP_MD_CTX **mdcp);
- -

DESCRIPTION

- -

BIO_f_md() returns the message digest BIO method. This is a filter BIO that digests any data passed through it. It is a BIO wrapper for the digest routines EVP_DigestInit(), EVP_DigestUpdate() and EVP_DigestFinal().

- -

Any data written or read through a digest BIO using BIO_read_ex() and BIO_write_ex() is digested.

- -

BIO_gets(), if its size parameter is large enough finishes the digest calculation and returns the digest value. BIO_puts() is not supported.

- -

BIO_reset() reinitialises a digest BIO.

- -

BIO_set_md() sets the message digest of BIO b to md: this must be called to initialize a digest BIO before any data is passed through it. It is a BIO_ctrl() macro.

- -

BIO_get_md() places a pointer to the digest BIOs digest method in mdp. It is a BIO_ctrl() macro.

- -

BIO_get_md_ctx() returns the digest BIOs context into mdcp.

- -

NOTES

- -

The context returned by BIO_get_md_ctx() can be used in calls to EVP_DigestFinal() and also the signature routines EVP_SignFinal() and EVP_VerifyFinal().

- -

The context returned by BIO_get_md_ctx() is an internal context structure. Changes made to this context will affect the digest BIO itself and the context pointer will become invalid when the digest BIO is freed.

- -

After the digest has been retrieved from a digest BIO it must be reinitialized by calling BIO_reset(), or BIO_set_md() before any more data is passed through it.

- -

If an application needs to call BIO_gets() or BIO_puts() through a chain containing digest BIOs then this can be done by prepending a buffering BIO.

- -

Calling BIO_get_md_ctx() will return the context and initialize the BIO state. This allows applications to initialize the context externally if the standard calls such as BIO_set_md() are not sufficiently flexible.

- -

RETURN VALUES

- -

BIO_f_md() returns the digest BIO method.

- -

BIO_set_md(), BIO_get_md() and BIO_md_ctx() return 1 for success and <=0 for failure.

- -

EXAMPLES

- -

The following example creates a BIO chain containing an SHA1 and MD5 digest BIO and passes the string "Hello World" through it. Error checking has been omitted for clarity.

- -
BIO *bio, *mdtmp;
-char message[] = "Hello World";
-
-bio = BIO_new(BIO_s_null());
-mdtmp = BIO_new(BIO_f_md());
-BIO_set_md(mdtmp, EVP_sha1());
-/*
- * For BIO_push() we want to append the sink BIO and keep a note of
- * the start of the chain.
- */
-bio = BIO_push(mdtmp, bio);
-mdtmp = BIO_new(BIO_f_md());
-BIO_set_md(mdtmp, EVP_md5());
-bio = BIO_push(mdtmp, bio);
-/* Note: mdtmp can now be discarded */
-BIO_write(bio, message, strlen(message));
- -

The next example digests data by reading through a chain instead:

- -
BIO *bio, *mdtmp;
-char buf[1024];
-int rdlen;
-
-bio = BIO_new_file(file, "rb");
-mdtmp = BIO_new(BIO_f_md());
-BIO_set_md(mdtmp, EVP_sha1());
-bio = BIO_push(mdtmp, bio);
-mdtmp = BIO_new(BIO_f_md());
-BIO_set_md(mdtmp, EVP_md5());
-bio = BIO_push(mdtmp, bio);
-do {
-    rdlen = BIO_read(bio, buf, sizeof(buf));
-    /* Might want to do something with the data here */
-} while (rdlen > 0);
- -

This next example retrieves the message digests from a BIO chain and outputs them. This could be used with the examples above.

- -
BIO *mdtmp;
-unsigned char mdbuf[EVP_MAX_MD_SIZE];
-int mdlen;
-int i;
-
-mdtmp = bio;   /* Assume bio has previously been set up */
-do {
-    EVP_MD *md;
-
-    mdtmp = BIO_find_type(mdtmp, BIO_TYPE_MD);
-    if (!mdtmp)
-        break;
-    BIO_get_md(mdtmp, &md);
-    printf("%s digest", OBJ_nid2sn(EVP_MD_get_type(md)));
-    mdlen = BIO_gets(mdtmp, mdbuf, EVP_MAX_MD_SIZE);
-    for (i = 0; i < mdlen; i++) printf(":%02X", mdbuf[i]);
-    printf("\n");
-    mdtmp = BIO_next(mdtmp);
-} while (mdtmp);
-
-BIO_free_all(bio);
- -

BUGS

- -

The lack of support for BIO_puts() and the non standard behaviour of BIO_gets() could be regarded as anomalous. It could be argued that BIO_gets() and BIO_puts() should be passed to the next BIO in the chain and digest the data passed through and that digests should be retrieved using a separate BIO_ctrl() call.

- -

HISTORY

- -

Before OpenSSL 1.0.0., the call to BIO_get_md_ctx() would only work if the BIO was initialized first.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_null.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_null.html deleted file mode 100644 index e716affd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_null.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -BIO_f_null - - - - - - - - - - -

NAME

- -

BIO_f_null - null filter

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_f_null(void);
- -

DESCRIPTION

- -

BIO_f_null() returns the null filter BIO method. This is a filter BIO that does nothing.

- -

All requests to a null filter BIO are passed through to the next BIO in the chain: this means that a BIO chain containing a null filter BIO behaves just as though the BIO was not there.

- -

NOTES

- -

As may be apparent a null filter BIO is not particularly useful.

- -

RETURN VALUES

- -

BIO_f_null() returns the null filter BIO method.

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_prefix.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_prefix.html deleted file mode 100644 index 332416b7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_prefix.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -BIO_f_prefix - - - - - - - - - - -

NAME

- -

BIO_f_prefix, BIO_set_prefix, BIO_set_indent, BIO_get_indent - prefix BIO filter

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_f_prefix(void);
-long BIO_set_prefix(BIO *b, const char *prefix);
-long BIO_set_indent(BIO *b, long indent);
-long BIO_get_indent(BIO *b);
- -

DESCRIPTION

- -

BIO_f_cipher() returns the prefix BIO method. This is a filter for text output, where each line gets automatically prefixed and indented according to user input.

- -

The prefix and the indentation are combined. For each line of output going through this filter, the prefix is output first, then the amount of additional spaces indicated by the indentation, and then the line itself.

- -

By default, there is no prefix, and indentation is set to 0.

- -

BIO_set_prefix() sets the prefix to be used for future lines of text, using prefix. prefix may be NULL, signifying that there should be no prefix. If prefix isn't NULL, this function makes a copy of it.

- -

BIO_set_indent() sets the indentation to be used for future lines of text, using indent. Negative values are not allowed.

- -

BIO_get_indent() gets the current indentation.

- -

NOTES

- -

BIO_set_prefix(), BIO_set_indent() and BIO_get_indent() are implemented as macros.

- -

RETURN VALUES

- -

BIO_f_prefix() returns the prefix BIO method.

- -

BIO_set_prefix() returns 1 if the prefix was correctly set, or <=0 on failure.

- -

BIO_set_indent() returns 1 if the prefix was correctly set, or <=0 on failure.

- -

BIO_get_indent() returns the current indentation, or a negative value for failure.

- -

SEE ALSO

- -

bio(7)

- -

COPYRIGHT

- -

Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_readbuffer.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_readbuffer.html deleted file mode 100644 index 0b7e0b35..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_readbuffer.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -BIO_f_readbuffer - - - - - - - - - - -

NAME

- -

BIO_f_readbuffer - read only buffering BIO that supports BIO_tell() and BIO_seek()

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_f_readbuffer(void);
- -

DESCRIPTION

- -

BIO_f_readbuffer() returns the read buffering BIO method.

- -

This BIO filter can be inserted on top of BIO's that do not support BIO_tell() or BIO_seek() (e.g. A file BIO that uses stdin).

- -

Data read from a read buffering BIO comes from an internal buffer which is filled from the next BIO in the chain.

- -

BIO_gets() is supported for read buffering BIOs. Writing data to a read buffering BIO is not supported.

- -

Calling BIO_reset() on a read buffering BIO does not clear any buffered data.

- -

NOTES

- -

Read buffering BIOs implement BIO_read_ex() by using BIO_read_ex() operations on the next BIO (e.g. a file BIO) in the chain and storing the result in an internal buffer, from which bytes are given back to the caller as appropriate for the call. BIO_read_ex() is guaranteed to give the caller the number of bytes it asks for, unless there's an error or end of communication is reached in the next BIO. The internal buffer can grow to cache the entire contents of the next BIO in the chain. BIO_seek() uses the internal buffer, so that it can only seek into data that is already read.

- -

RETURN VALUES

- -

BIO_f_readbuffer() returns the read buffering BIO method.

- -

SEE ALSO

- -

bio(7), BIO_read(3), BIO_gets(3), BIO_reset(3), BIO_ctrl(3).

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_f_ssl.html b/openssl-install/share/doc/openssl/html/man3/BIO_f_ssl.html deleted file mode 100644 index eb8b8c5d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_f_ssl.html +++ /dev/null @@ -1,258 +0,0 @@ - - - - -BIO_f_ssl - - - - - - - - - - -

NAME

- -

BIO_do_handshake, BIO_f_ssl, BIO_set_ssl, BIO_get_ssl, BIO_set_ssl_mode, BIO_set_ssl_renegotiate_bytes, BIO_get_num_renegotiates, BIO_set_ssl_renegotiate_timeout, BIO_new_ssl, BIO_new_ssl_connect, BIO_new_buffer_ssl_connect, BIO_ssl_copy_session_id, BIO_ssl_shutdown - SSL BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-#include <openssl/ssl.h>
-
-const BIO_METHOD *BIO_f_ssl(void);
-
-long BIO_set_ssl(BIO *b, SSL *ssl, long c);
-long BIO_get_ssl(BIO *b, SSL **sslp);
-long BIO_set_ssl_mode(BIO *b, long client);
-long BIO_set_ssl_renegotiate_bytes(BIO *b, long num);
-long BIO_set_ssl_renegotiate_timeout(BIO *b, long seconds);
-long BIO_get_num_renegotiates(BIO *b);
-
-BIO *BIO_new_ssl(SSL_CTX *ctx, int client);
-BIO *BIO_new_ssl_connect(SSL_CTX *ctx);
-BIO *BIO_new_buffer_ssl_connect(SSL_CTX *ctx);
-int BIO_ssl_copy_session_id(BIO *to, BIO *from);
-void BIO_ssl_shutdown(BIO *bio);
-
-long BIO_do_handshake(BIO *b);
- -

DESCRIPTION

- -

BIO_f_ssl() returns the SSL BIO method. This is a filter BIO which is a wrapper round the OpenSSL SSL routines adding a BIO "flavour" to SSL I/O.

- -

I/O performed on an SSL BIO communicates using the SSL protocol with the SSLs read and write BIOs. If an SSL connection is not established then an attempt is made to establish one on the first I/O call.

- -

If a BIO is appended to an SSL BIO using BIO_push() it is automatically used as the SSL BIOs read and write BIOs.

- -

Calling BIO_reset() on an SSL BIO closes down any current SSL connection by calling SSL_shutdown(). BIO_reset() is then sent to the next BIO in the chain: this will typically disconnect the underlying transport. The SSL BIO is then reset to the initial accept or connect state.

- -

If the close flag is set when an SSL BIO is freed then the internal SSL structure is also freed using SSL_free().

- -

BIO_set_ssl() sets the internal SSL pointer of SSL BIO b to ssl using the close flag c.

- -

BIO_get_ssl() retrieves the SSL pointer of SSL BIO b, it can then be manipulated using the standard SSL library functions.

- -

BIO_set_ssl_mode() sets the SSL BIO mode to client. If client is 1 client mode is set. If client is 0 server mode is set.

- -

BIO_set_ssl_renegotiate_bytes() sets the renegotiate byte count of SSL BIO b to num. When set after every num bytes of I/O (read and write) the SSL session is automatically renegotiated. num must be at least 512 bytes.

- -

BIO_set_ssl_renegotiate_timeout() sets the renegotiate timeout of SSL BIO b to seconds. When the renegotiate timeout elapses the session is automatically renegotiated.

- -

BIO_get_num_renegotiates() returns the total number of session renegotiations due to I/O or timeout of SSL BIO b.

- -

BIO_new_ssl() allocates an SSL BIO using SSL_CTX ctx and using client mode if client is non zero.

- -

BIO_new_ssl_connect() creates a new BIO chain consisting of an SSL BIO (using ctx) followed by a connect BIO.

- -

BIO_new_buffer_ssl_connect() creates a new BIO chain consisting of a buffering BIO, an SSL BIO (using ctx), and a connect BIO.

- -

BIO_ssl_copy_session_id() copies an SSL session id between BIO chains from and to. It does this by locating the SSL BIOs in each chain and calling SSL_copy_session_id() on the internal SSL pointer.

- -

BIO_ssl_shutdown() closes down an SSL connection on BIO chain bio. It does this by locating the SSL BIO in the chain and calling SSL_shutdown() on its internal SSL pointer.

- -

BIO_do_handshake() attempts to complete an SSL handshake on the supplied BIO and establish the SSL connection. For non-SSL BIOs the connection is done typically at TCP level. If domain name resolution yields multiple IP addresses all of them are tried after connect() failures. The function returns 1 if the connection was established successfully. A zero or negative value is returned if the connection could not be established. The call BIO_should_retry() should be used for nonblocking connect BIOs to determine if the call should be retried. If a connection has already been established this call has no effect.

- -

NOTES

- -

SSL BIOs are exceptional in that if the underlying transport is non blocking they can still request a retry in exceptional circumstances. Specifically this will happen if a session renegotiation takes place during a BIO_read_ex() operation, one case where this happens is when step up occurs.

- -

The SSL flag SSL_AUTO_RETRY can be set to disable this behaviour. That is when this flag is set an SSL BIO using a blocking transport will never request a retry.

- -

Since unknown BIO_ctrl() operations are sent through filter BIOs the servers name and port can be set using BIO_set_host() on the BIO returned by BIO_new_ssl_connect() without having to locate the connect BIO first.

- -

Applications do not have to call BIO_do_handshake() but may wish to do so to separate the handshake process from other I/O processing.

- -

BIO_set_ssl(), BIO_get_ssl(), BIO_set_ssl_mode(), BIO_set_ssl_renegotiate_bytes(), BIO_set_ssl_renegotiate_timeout(), BIO_get_num_renegotiates(), and BIO_do_handshake() are implemented as macros.

- -

BIO_ssl_copy_session_id() is not currently supported on QUIC SSL objects and fails if called on such an object.

- -

RETURN VALUES

- -

BIO_f_ssl() returns the SSL BIO_METHOD structure.

- -

BIO_set_ssl(), BIO_get_ssl(), BIO_set_ssl_mode(), BIO_set_ssl_renegotiate_bytes(), BIO_set_ssl_renegotiate_timeout() and BIO_get_num_renegotiates() return 1 on success or a value which is less than or equal to 0 if an error occurred.

- -

BIO_new_ssl(), BIO_new_ssl_connect() and BIO_new_buffer_ssl_connect() return a valid BIO structure on success or NULL if an error occurred.

- -

BIO_ssl_copy_session_id() returns 1 on success or 0 on error, or if called on a QUIC SSL object.

- -

BIO_do_handshake() returns 1 if the connection was established successfully. A zero or negative value is returned if the connection could not be established.

- -

EXAMPLES

- -

This SSL/TLS client example attempts to retrieve a page from an SSL/TLS web server. The I/O routines are identical to those of the unencrypted example in BIO_s_connect(3).

- -
BIO *sbio, *out;
-int len;
-char tmpbuf[1024];
-SSL_CTX *ctx;
-SSL *ssl;
-
-/* XXX Seed the PRNG if needed. */
-
-ctx = SSL_CTX_new(TLS_client_method());
-
-/* XXX Set verify paths and mode here. */
-
-sbio = BIO_new_ssl_connect(ctx);
-BIO_get_ssl(sbio, &ssl);
-if (ssl == NULL) {
-    fprintf(stderr, "Can't locate SSL pointer\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-
-/* XXX We might want to do other things with ssl here */
-
-/* An empty host part means the loopback address */
-BIO_set_conn_hostname(sbio, ":https");
-
-out = BIO_new_fp(stdout, BIO_NOCLOSE);
-if (BIO_do_connect(sbio) <= 0) {
-    fprintf(stderr, "Error connecting to server\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-
-/* XXX Could examine ssl here to get connection info */
-
-BIO_puts(sbio, "GET / HTTP/1.0\n\n");
-for (;;) {
-    len = BIO_read(sbio, tmpbuf, 1024);
-    if (len <= 0)
-        break;
-    BIO_write(out, tmpbuf, len);
-}
-BIO_free_all(sbio);
-BIO_free(out);
- -

Here is a simple server example. It makes use of a buffering BIO to allow lines to be read from the SSL BIO using BIO_gets. It creates a pseudo web page containing the actual request from a client and also echoes the request to standard output.

- -
BIO *sbio, *bbio, *acpt, *out;
-int len;
-char tmpbuf[1024];
-SSL_CTX *ctx;
-SSL *ssl;
-
-/* XXX Seed the PRNG if needed. */
-
-ctx = SSL_CTX_new(TLS_server_method());
-if (!SSL_CTX_use_certificate_file(ctx, "server.pem", SSL_FILETYPE_PEM)
-        || !SSL_CTX_use_PrivateKey_file(ctx, "server.pem", SSL_FILETYPE_PEM)
-        || !SSL_CTX_check_private_key(ctx)) {
-    fprintf(stderr, "Error setting up SSL_CTX\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-
-/* XXX Other things like set verify locations, EDH temp callbacks. */
-
-/* New SSL BIO setup as server */
-sbio = BIO_new_ssl(ctx, 0);
-BIO_get_ssl(sbio, &ssl);
-if (ssl == NULL) {
-    fprintf(stderr, "Can't locate SSL pointer\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-
-bbio = BIO_new(BIO_f_buffer());
-sbio = BIO_push(bbio, sbio);
-acpt = BIO_new_accept("4433");
-
-/*
- * By doing this when a new connection is established
- * we automatically have sbio inserted into it. The
- * BIO chain is now 'swallowed' by the accept BIO and
- * will be freed when the accept BIO is freed.
- */
-BIO_set_accept_bios(acpt, sbio);
-out = BIO_new_fp(stdout, BIO_NOCLOSE);
-
-/* First call to BIO_do_accept() sets up accept BIO */
-if (BIO_do_accept(acpt) <= 0) {
-    fprintf(stderr, "Error setting up accept BIO\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
- -

/* Second call to BIO_do_accept() waits for incoming connection */ if (BIO_do_accept(acpt) <= 0) { fprintf(stderr, "Error accepting connection\n"); ERR_print_errors_fp(stderr); exit(1); }

- -
/* We only want one connection so remove and free accept BIO */
-sbio = BIO_pop(acpt);
-BIO_free_all(acpt);
-
-if (BIO_do_handshake(sbio) <= 0) {
-    fprintf(stderr, "Error in SSL handshake\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-
-BIO_puts(sbio, "HTTP/1.0 200 OK\r\nContent-type: text/plain\r\n\r\n");
-BIO_puts(sbio, "\r\nConnection Established\r\nRequest headers:\r\n");
-BIO_puts(sbio, "--------------------------------------------------\r\n");
-
-for (;;) {
-    len = BIO_gets(sbio, tmpbuf, 1024);
-    if (len <= 0)
-        break;
-    BIO_write(sbio, tmpbuf, len);
-    BIO_write(out, tmpbuf, len);
-    /* Look for blank line signifying end of headers*/
-    if (tmpbuf[0] == '\r' || tmpbuf[0] == '\n')
-        break;
-}
-
-BIO_puts(sbio, "--------------------------------------------------\r\n");
-BIO_puts(sbio, "\r\n");
-BIO_flush(sbio);
-BIO_free_all(sbio);
- -

HISTORY

- -

In OpenSSL before 1.0.0 the BIO_pop() call was handled incorrectly, the I/O BIO reference count was incorrectly incremented (instead of decremented) and dissociated with the SSL BIO even if the SSL BIO was not explicitly being popped (e.g. a pop higher up the chain). Applications which included workarounds for this bug (e.g. freeing BIOs more than once) should be modified to handle this fix or they may free up an already freed BIO.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_find_type.html b/openssl-install/share/doc/openssl/html/man3/BIO_find_type.html deleted file mode 100644 index 99efc6cc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_find_type.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -BIO_find_type - - - - - - - - - - -

NAME

- -

BIO_find_type, BIO_next, BIO_method_type - BIO chain traversal

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-BIO *BIO_find_type(BIO *b, int bio_type);
-BIO *BIO_next(BIO *b);
-int BIO_method_type(const BIO *b);
- -

DESCRIPTION

- -

The BIO_find_type() searches for a BIO of a given type in a chain, starting at BIO b. If type is a specific type (such as BIO_TYPE_MEM) then a search is made for a BIO of that type. If type is a general type (such as BIO_TYPE_SOURCE_SINK) then the next matching BIO of the given general type is searched for. BIO_find_type() returns the next matching BIO or NULL if none is found. If type is BIO_TYPE_NONE it will not find a match.

- -

The following general types are defined: BIO_TYPE_DESCRIPTOR, BIO_TYPE_FILTER, and BIO_TYPE_SOURCE_SINK.

- -

For a list of the specific types, see the <openssl/bio.h> header file.

- -

BIO_next() returns the next BIO in a chain. It can be used to traverse all BIOs in a chain or used in conjunction with BIO_find_type() to find all BIOs of a certain type.

- -

BIO_method_type() returns the type of a BIO.

- -

RETURN VALUES

- -

BIO_find_type() returns a matching BIO or NULL for no match.

- -

BIO_next() returns the next BIO in a chain.

- -

BIO_method_type() returns the type of the BIO b.

- -

EXAMPLES

- -

Traverse a chain looking for digest BIOs:

- -
BIO *btmp;
-
-btmp = in_bio; /* in_bio is chain to search through */
-do {
-    btmp = BIO_find_type(btmp, BIO_TYPE_MD);
-    if (btmp == NULL)
-        break; /* Not found */
-    /* btmp is a digest BIO, do something with it ...*/
-    ...
-
-    btmp = BIO_next(btmp);
-} while (btmp);
- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_get_data.html b/openssl-install/share/doc/openssl/html/man3/BIO_get_data.html deleted file mode 100644 index e0855162..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_get_data.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -BIO_get_data - - - - - - - - - - -

NAME

- -

BIO_set_data, BIO_get_data, BIO_set_init, BIO_get_init, BIO_set_shutdown, BIO_get_shutdown - functions for managing BIO state information

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-void BIO_set_data(BIO *a, void *ptr);
-void *BIO_get_data(BIO *a);
-void BIO_set_init(BIO *a, int init);
-int BIO_get_init(BIO *a);
-void BIO_set_shutdown(BIO *a, int shut);
-int BIO_get_shutdown(BIO *a);
- -

DESCRIPTION

- -

These functions are mainly useful when implementing a custom BIO.

- -

The BIO_set_data() function associates the custom data pointed to by ptr with the BIO. This data can subsequently be retrieved via a call to BIO_get_data(). This can be used by custom BIOs for storing implementation specific information.

- -

The BIO_set_init() function sets the value of the BIO's "init" flag to indicate whether initialisation has been completed for this BIO or not. A nonzero value indicates that initialisation is complete, whilst zero indicates that it is not. Often initialisation will complete during initial construction of the BIO. For some BIOs however, initialisation may not complete until after additional steps have occurred (for example through calling custom ctrls). The BIO_get_init() function returns the value of the "init" flag.

- -

The BIO_set_shutdown() and BIO_get_shutdown() functions set and get the state of this BIO's shutdown (i.e. BIO_CLOSE) flag. If set then the underlying resource is also closed when the BIO is freed.

- -

RETURN VALUES

- -

BIO_get_data() returns a pointer to the implementation specific custom data associated with this BIO, or NULL if none has been set.

- -

BIO_get_init() returns the state of the BIO's init flag.

- -

BIO_get_shutdown() returns the stat of the BIO's shutdown (i.e. BIO_CLOSE) flag.

- -

SEE ALSO

- -

bio(7), BIO_meth_new(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_get_ex_new_index.html b/openssl-install/share/doc/openssl/html/man3/BIO_get_ex_new_index.html deleted file mode 100644 index 979f69fc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_get_ex_new_index.html +++ /dev/null @@ -1,114 +0,0 @@ - - - - -BIO_get_ex_new_index - - - - - - - - - - -

NAME

- -

BIO_get_ex_new_index, BIO_set_ex_data, BIO_get_ex_data, BIO_set_app_data, BIO_get_app_data, DH_get_ex_new_index, DH_set_ex_data, DH_get_ex_data, DSA_get_ex_new_index, DSA_set_ex_data, DSA_get_ex_data, EC_KEY_get_ex_new_index, EC_KEY_set_ex_data, EC_KEY_get_ex_data, ENGINE_get_ex_new_index, ENGINE_set_ex_data, ENGINE_get_ex_data, EVP_PKEY_get_ex_new_index, EVP_PKEY_set_ex_data, EVP_PKEY_get_ex_data, RSA_get_ex_new_index, RSA_set_ex_data, RSA_get_ex_data, RSA_set_app_data, RSA_get_app_data, SSL_get_ex_new_index, SSL_set_ex_data, SSL_get_ex_data, SSL_set_app_data, SSL_get_app_data, SSL_CTX_get_ex_new_index, SSL_CTX_set_ex_data, SSL_CTX_get_ex_data, SSL_CTX_set_app_data, SSL_CTX_get_app_data, SSL_SESSION_get_ex_new_index, SSL_SESSION_set_ex_data, SSL_SESSION_get_ex_data, SSL_SESSION_set_app_data, SSL_SESSION_get_app_data, UI_get_ex_new_index, UI_set_ex_data, UI_get_ex_data, UI_set_app_data, UI_get_app_data, X509_STORE_CTX_get_ex_new_index, X509_STORE_CTX_set_ex_data, X509_STORE_CTX_get_ex_data, X509_STORE_CTX_set_app_data, X509_STORE_CTX_get_app_data, X509_STORE_get_ex_new_index, X509_STORE_set_ex_data, X509_STORE_get_ex_data, X509_get_ex_new_index, X509_set_ex_data, X509_get_ex_data - application-specific data

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int TYPE_get_ex_new_index(long argl, void *argp,
-                          CRYPTO_EX_new *new_func,
-                          CRYPTO_EX_dup *dup_func,
-                          CRYPTO_EX_free *free_func);
-
-int TYPE_set_ex_data(TYPE *d, int idx, void *arg);
-
-void *TYPE_get_ex_data(const TYPE *d, int idx);
-
-#define TYPE_set_app_data(TYPE *d, void *arg)
-#define TYPE_get_app_data(TYPE *d)
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DH_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func,
-                        CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func);
-int DH_set_ex_data(DH *type, int idx, void *arg);
-void *DH_get_ex_data(DH *type, int idx);
-int DSA_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func,
-                         CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func);
-int DSA_set_ex_data(DSA *type, int idx, void *arg);
-void *DSA_get_ex_data(DSA *type, int idx);
-int EC_KEY_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func,
-                            CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func);
-int EC_KEY_set_ex_data(EC_KEY *type, int idx, void *arg);
-void *EC_KEY_get_ex_data(EC_KEY *type, int idx);
-int RSA_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func,
-                         CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func);
-int RSA_set_ex_data(RSA *type, int idx, void *arg);
-void *RSA_get_ex_data(RSA *type, int idx);
-int RSA_set_app_data(RSA *type, void *arg);
-void *RSA_get_app_data(RSA *type);
-int ENGINE_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func,
-                            CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func);
-int ENGINE_set_ex_data(ENGINE *type, int idx, void *arg);
-void *ENGINE_get_ex_data(ENGINE *type, int idx);
- -

DESCRIPTION

- -

In the description here, TYPE is used a placeholder for any of the OpenSSL datatypes listed in CRYPTO_get_ex_new_index(3).

- -

All functions with a TYPE of DH, DSA, RSA and EC_KEY are deprecated. Applications should instead use EVP_PKEY_set_ex_data(), EVP_PKEY_get_ex_data() and EVP_PKEY_get_ex_new_index().

- -

All functions with a TYPE of ENGINE are deprecated. Applications using engines should be replaced by providers.

- -

These functions handle application-specific data for OpenSSL data structures.

- -

TYPE_get_ex_new_index() is a macro that calls CRYPTO_get_ex_new_index() with the correct index value.

- -

TYPE_set_ex_data() is a function that calls CRYPTO_set_ex_data() with an offset into the opaque exdata part of the TYPE object.

- -

TYPE_get_ex_data() is a function that calls CRYPTO_get_ex_data() with an offset into the opaque exdata part of the TYPE object.

- -

For compatibility with previous releases, the exdata index of zero is reserved for "application data." There are two convenience functions for this. TYPE_set_app_data() is a macro that invokes TYPE_set_ex_data() with idx set to zero. TYPE_get_app_data() is a macro that invokes TYPE_get_ex_data() with idx set to zero.

- -

RETURN VALUES

- -

TYPE_get_ex_new_index() returns a new index on success or -1 on error.

- -

TYPE_set_ex_data() returns 1 on success or 0 on error.

- -

TYPE_get_ex_data() returns the application data or NULL if an error occurred.

- -

SEE ALSO

- -

CRYPTO_get_ex_new_index(3).

- -

HISTORY

- -

The functions DH_get_ex_new_index(), DH_set_ex_data(), DH_get_ex_data(), DSA_get_ex_new_index(), DSA_set_ex_data(), DSA_get_ex_data(), EC_KEY_get_ex_new_index(), EC_KEY_set_ex_data(), EC_KEY_get_ex_data(), ENGINE_get_ex_new_index(), ENGINE_set_ex_data(), ENGINE_get_ex_data(), RSA_get_ex_new_index(), RSA_set_ex_data(), RSA_get_ex_data(), RSA_set_app_data() and RSA_get_app_data() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_get_rpoll_descriptor.html b/openssl-install/share/doc/openssl/html/man3/BIO_get_rpoll_descriptor.html deleted file mode 100644 index cb6037d1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_get_rpoll_descriptor.html +++ /dev/null @@ -1,111 +0,0 @@ - - - - -BIO_get_rpoll_descriptor - - - - - - - - - - -

NAME

- -

BIO_get_rpoll_descriptor, BIO_get_wpoll_descriptor - obtain a structure which can be used to determine when a BIO object can next be read or written

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-typedef struct bio_poll_descriptor_st {
-    uint32_t type;
-    union {
-        int        fd;
-        void       *custom;
-        uintptr_t  custom_ui;
-    } value;
-} BIO_POLL_DESCRIPTOR;
-
-int BIO_get_rpoll_descriptor(BIO *b, BIO_POLL_DESCRIPTOR *desc);
-int BIO_get_wpoll_descriptor(BIO *b, BIO_POLL_DESCRIPTOR *desc);
- -

DESCRIPTION

- -

BIO_get_rpoll_descriptor() and BIO_get_wpoll_descriptor(), on success, fill *desc with a poll descriptor. A poll descriptor is a tagged union structure which represents some kind of OS or non-OS resource which can be used to synchronise on I/O availability events.

- -

BIO_get_rpoll_descriptor() outputs a descriptor which can be used to determine when the BIO can (potentially) next be read, and BIO_get_wpoll_descriptor() outputs a descriptor which can be used to determine when the BIO can (potentially) next be written.

- -

It is permissible for BIO_get_rpoll_descriptor() and BIO_get_wpoll_descriptor() to output the same descriptor.

- -

Poll descriptors can represent different kinds of information. A typical kind of resource which might be represented by a poll descriptor is an OS file descriptor which can be used with APIs such as select().

- -

The kinds of poll descriptor defined by OpenSSL are:

- -
- -
BIO_POLL_DESCRIPTOR_TYPE_NONE
-
- -

Represents the absence of a valid poll descriptor. It may be used by BIO_get_rpoll_descriptor() or BIO_get_wpoll_descriptor() to indicate that the BIO is not pollable for readability or writeability respectively.

- -

For this type, no field within the value field of the BIO_POLL_DESCRIPTOR is valid.

- -
-
BIO_POLL_DESCRIPTOR_TYPE_SOCK_FD
-
- -

The poll descriptor represents an OS socket resource. The field value.fd in the BIO_POLL_DESCRIPTOR is valid if it is not set to -1.

- -

The resource is whatever kind of handle is used by a given OS to represent sockets, which may vary by OS. For example, on Windows, the value is a SOCKET for use with the Winsock API. On POSIX-like platforms, it is a file descriptor.

- -

Where a poll descriptor of this type is output by BIO_get_rpoll_descriptor(), it should be polled for readability to determine when the BIO might next be able to successfully complete a BIO_read() operation; likewise, where a poll descriptor of this type is output by BIO_get_wpoll_descriptor(), it should be polled for writeability to determine when the BIO might next be able to successfully complete a BIO_write() operation.

- -
-
BIO_POLL_DESCRIPTOR_CUSTOM_START
-
- -

Type values beginning with this value (inclusive) are reserved for application allocation for custom poll descriptor types. Any of the definitions in the union field value can be used by the application arbitrarily as opaque values.

- -
-
- -

Because poll descriptors are a tagged union structure, they can represent different kinds of information. New types of poll descriptor may be defined, including by applications, according to their needs.

- -

RETURN VALUES

- -

The functions BIO_get_rpoll_descriptor() and BIO_get_wpoll_descriptor() return 1 on success and 0 on failure.

- -

These functions are permitted to succeed and initialise *desc with a poll descriptor of type BIO_POLL_DESCRIPTOR_TYPE_NONE to indicate that the BIO is not pollable for readability or writeability respectively.

- -

SEE ALSO

- -

SSL_handle_events(3), SSL_get_event_timeout(3), SSL_get_rpoll_descriptor(3), SSL_get_wpoll_descriptor(3), bio(7)

- -

HISTORY

- -

The SSL_get_rpoll_descriptor() and SSL_get_wpoll_descriptor() functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_meth_new.html b/openssl-install/share/doc/openssl/html/man3/BIO_meth_new.html deleted file mode 100644 index bebe290b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_meth_new.html +++ /dev/null @@ -1,150 +0,0 @@ - - - - -BIO_meth_new - - - - - - - - - - -

NAME

- -

BIO_get_new_index, BIO_meth_new, BIO_meth_free, BIO_meth_get_read_ex, BIO_meth_set_read_ex, BIO_meth_get_write_ex, BIO_meth_set_write_ex, BIO_meth_get_write, BIO_meth_set_write, BIO_meth_get_read, BIO_meth_set_read, BIO_meth_get_puts, BIO_meth_set_puts, BIO_meth_get_gets, BIO_meth_set_gets, BIO_meth_get_ctrl, BIO_meth_set_ctrl, BIO_meth_get_create, BIO_meth_set_create, BIO_meth_get_destroy, BIO_meth_set_destroy, BIO_meth_get_callback_ctrl, BIO_meth_set_callback_ctrl, BIO_meth_set_sendmmsg, BIO_meth_get_sendmmsg, BIO_meth_set_recvmmsg, BIO_meth_get_recvmmsg - Routines to build up BIO methods

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-int BIO_get_new_index(void);
-
-BIO_METHOD *BIO_meth_new(int type, const char *name);
-
-void BIO_meth_free(BIO_METHOD *biom);
-
-int (*BIO_meth_get_write_ex(const BIO_METHOD *biom))(BIO *, const char *, size_t,
-                                               size_t *);
-int (*BIO_meth_get_write(const BIO_METHOD *biom))(BIO *, const char *, int);
-int BIO_meth_set_write_ex(BIO_METHOD *biom,
-                          int (*bwrite)(BIO *, const char *, size_t, size_t *));
-int BIO_meth_set_write(BIO_METHOD *biom,
-                       int (*write)(BIO *, const char *, int));
-
-int (*BIO_meth_get_read_ex(const BIO_METHOD *biom))(BIO *, char *, size_t, size_t *);
-int (*BIO_meth_get_read(const BIO_METHOD *biom))(BIO *, char *, int);
-int BIO_meth_set_read_ex(BIO_METHOD *biom,
-                         int (*bread)(BIO *, char *, size_t, size_t *));
-int BIO_meth_set_read(BIO_METHOD *biom, int (*read)(BIO *, char *, int));
-
-int (*BIO_meth_get_puts(const BIO_METHOD *biom))(BIO *, const char *);
-int BIO_meth_set_puts(BIO_METHOD *biom, int (*puts)(BIO *, const char *));
-
-int (*BIO_meth_get_gets(const BIO_METHOD *biom))(BIO *, char *, int);
-int BIO_meth_set_gets(BIO_METHOD *biom,
-                      int (*gets)(BIO *, char *, int));
-
-long (*BIO_meth_get_ctrl(const BIO_METHOD *biom))(BIO *, int, long, void *);
-int BIO_meth_set_ctrl(BIO_METHOD *biom,
-                      long (*ctrl)(BIO *, int, long, void *));
-
-int (*BIO_meth_get_create(const BIO_METHOD *bion))(BIO *);
-int BIO_meth_set_create(BIO_METHOD *biom, int (*create)(BIO *));
-
-int (*BIO_meth_get_destroy(const BIO_METHOD *biom))(BIO *);
-int BIO_meth_set_destroy(BIO_METHOD *biom, int (*destroy)(BIO *));
-
-long (*BIO_meth_get_callback_ctrl(const BIO_METHOD *biom))(BIO *, int, BIO_info_cb *);
-int BIO_meth_set_callback_ctrl(BIO_METHOD *biom,
-                               long (*callback_ctrl)(BIO *, int, BIO_info_cb *));
-
-ossl_ssize_t (*BIO_meth_get_sendmmsg(const BIO_METHOD *biom))(BIO *,
-                                                              BIO_MSG *,
-                                                              size_t,
-                                                              size_t,
-                                                              uint64_t);
-int BIO_meth_set_sendmmsg(BIO_METHOD *biom,
-                          ossl_ssize_t (*f) (BIO *, BIO_MSG *, size_t,
-                                             size_t, uint64_t));
-
-ossl_ssize_t (*BIO_meth_get_recvmmsg(const BIO_METHOD *biom))(BIO *,
-                                                              BIO_MSG *,
-                                                              size_t,
-                                                              size_t,
-                                                              uint64_t);
-int BIO_meth_set_recvmmsg(BIO_METHOD *biom,
-                          ossl_ssize_t (*f) (BIO *, BIO_MSG *, size_t,
-                                             size_t, uint64_t));
- -

DESCRIPTION

- -

The BIO_METHOD type is a structure used for the implementation of new BIO types. It provides a set of functions used by OpenSSL for the implementation of the various BIO capabilities. See the bio(7) page for more information.

- -

BIO_meth_new() creates a new BIO_METHOD structure that contains a type identifier type and a string that represents its name. type can be set to either BIO_TYPE_NONE or via BIO_get_new_index() if a unique type is required for searching (See BIO_find_type(3))

- -

Note that BIO_get_new_index() can only be used 127 times before it returns an error.

- -

The set of standard OpenSSL provided BIO types is provided in <openssl/bio.h>. Some examples include BIO_TYPE_BUFFER and BIO_TYPE_CIPHER. Filter BIOs should have a type which have the "filter" bit set (BIO_TYPE_FILTER). Source/sink BIOs should have the "source/sink" bit set (BIO_TYPE_SOURCE_SINK). File descriptor based BIOs (e.g. socket, fd, connect, accept etc) should additionally have the "descriptor" bit set (BIO_TYPE_DESCRIPTOR). See the BIO_find_type(3) page for more information.

- -

BIO_meth_free() destroys a BIO_METHOD structure and frees up any memory associated with it. If the argument is NULL, nothing is done.

- -

BIO_meth_get_write_ex() and BIO_meth_set_write_ex() get and set the function used for writing arbitrary length data to the BIO respectively. This function will be called in response to the application calling BIO_write_ex() or BIO_write(). The parameters for the function have the same meaning as for BIO_write_ex(). Older code may call BIO_meth_get_write() and BIO_meth_set_write() instead. Applications should not call both BIO_meth_set_write_ex() and BIO_meth_set_write() or call BIO_meth_get_write() when the function was set with BIO_meth_set_write_ex().

- -

BIO_meth_get_read_ex() and BIO_meth_set_read_ex() get and set the function used for reading arbitrary length data from the BIO respectively. This function will be called in response to the application calling BIO_read_ex() or BIO_read(). The parameters for the function have the same meaning as for BIO_read_ex(). Older code may call BIO_meth_get_read() and BIO_meth_set_read() instead. Applications should not call both BIO_meth_set_read_ex() and BIO_meth_set_read() or call BIO_meth_get_read() when the function was set with BIO_meth_set_read_ex().

- -

BIO_meth_get_puts() and BIO_meth_set_puts() get and set the function used for writing a NULL terminated string to the BIO respectively. This function will be called in response to the application calling BIO_puts(). The parameters for the function have the same meaning as for BIO_puts().

- -

BIO_meth_get_gets() and BIO_meth_set_gets() get and set the function typically used for reading a line of data from the BIO respectively (see the BIO_gets(3) page for more information). This function will be called in response to the application calling BIO_gets(). The parameters for the function have the same meaning as for BIO_gets().

- -

BIO_meth_get_ctrl() and BIO_meth_set_ctrl() get and set the function used for processing ctrl messages in the BIO respectively. See the BIO_ctrl(3) page for more information. This function will be called in response to the application calling BIO_ctrl(). The parameters for the function have the same meaning as for BIO_ctrl().

- -

BIO_meth_get_create() and BIO_meth_set_create() get and set the function used for creating a new instance of the BIO respectively. This function will be called in response to the application calling BIO_new() and passing in a pointer to the current BIO_METHOD. The BIO_new() function will allocate the memory for the new BIO, and a pointer to this newly allocated structure will be passed as a parameter to the function. If a create function is set, BIO_new() will not mark the BIO as initialised on allocation. BIO_set_init(3) must then be called either by the create function, or later, by a BIO ctrl function, once BIO initialisation is complete.

- -

BIO_meth_get_destroy() and BIO_meth_set_destroy() get and set the function used for destroying an instance of a BIO respectively. This function will be called in response to the application calling BIO_free(). A pointer to the BIO to be destroyed is passed as a parameter. The destroy function should be used for BIO specific clean up. The memory for the BIO itself should not be freed by this function.

- -

BIO_meth_get_callback_ctrl() and BIO_meth_set_callback_ctrl() get and set the function used for processing callback ctrl messages in the BIO respectively. See the BIO_callback_ctrl(3) page for more information. This function will be called in response to the application calling BIO_callback_ctrl(). The parameters for the function have the same meaning as for BIO_callback_ctrl().

- -

BIO_meth_get_sendmmsg(), BIO_meth_set_sendmmsg(), BIO_meth_get_recvmmsg() and BIO_meth_set_recvmmsg() get and set the functions used for handling BIO_sendmmsg() and BIO_recvmmsg() calls respectively. See BIO_sendmmsg(3) for more information.

- -

RETURN VALUES

- -

BIO_get_new_index() returns the new BIO type value or -1 if an error occurred.

- -

BIO_meth_new(int type, const char *name) returns a valid BIO_METHOD or NULL if an error occurred.

- -

The BIO_meth_set functions return 1 on success or 0 on error.

- -

The BIO_meth_get functions return the corresponding function pointers.

- -

SEE ALSO

- -

bio(7), BIO_find_type(3), BIO_ctrl(3), BIO_read_ex(3), BIO_new(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_new.html b/openssl-install/share/doc/openssl/html/man3/BIO_new.html deleted file mode 100644 index ce31b64b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_new.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -BIO_new - - - - - - - - - - -

NAME

- -

BIO_new_ex, BIO_new, BIO_up_ref, BIO_free, BIO_vfree, BIO_free_all - BIO allocation and freeing functions

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-BIO *BIO_new_ex(OSSL_LIB_CTX *libctx, const BIO_METHOD *type);
-BIO *BIO_new(const BIO_METHOD *type);
-int BIO_up_ref(BIO *a);
-int BIO_free(BIO *a);
-void BIO_vfree(BIO *a);
-void BIO_free_all(BIO *a);
- -

DESCRIPTION

- -

The BIO_new_ex() function returns a new BIO using method type associated with the library context libctx (see OSSL_LIB_CTX(3)). The library context may be NULL to indicate the default library context.

- -

The BIO_new() is the same as BIO_new_ex() except the default library context is always used.

- -

BIO_up_ref() increments the reference count associated with the BIO object.

- -

BIO_free() frees up a single BIO, BIO_vfree() also frees up a single BIO but it does not return a value. If a is NULL nothing is done. Calling BIO_free() may also have some effect on the underlying I/O structure, for example it may close the file being referred to under certain circumstances. For more details see the individual BIO_METHOD descriptions.

- -

BIO_free_all() frees up an entire BIO chain, it does not halt if an error occurs freeing up an individual BIO in the chain. If a is NULL nothing is done.

- -

RETURN VALUES

- -

BIO_new_ex() and BIO_new() return a newly created BIO or NULL if the call fails.

- -

BIO_up_ref() and BIO_free() return 1 for success and 0 for failure.

- -

BIO_free_all() and BIO_vfree() do not return values.

- -

NOTES

- -

If BIO_free() is called on a BIO chain it will only free one BIO resulting in a memory leak.

- -

Calling BIO_free_all() on a single BIO has the same effect as calling BIO_free() on it other than the discarded return value.

- -

HISTORY

- -

BIO_set() was removed in OpenSSL 1.1.0 as BIO type is now opaque.

- -

BIO_new_ex() was added in OpenSSL 3.0.

- -

EXAMPLES

- -

Create a memory BIO:

- -
BIO *mem = BIO_new(BIO_s_mem());
- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_new_CMS.html b/openssl-install/share/doc/openssl/html/man3/BIO_new_CMS.html deleted file mode 100644 index 9389e928..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_new_CMS.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -BIO_new_CMS - - - - - - - - - - -

NAME

- -

BIO_new_CMS - CMS streaming filter BIO

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-BIO *BIO_new_CMS(BIO *out, CMS_ContentInfo *cms);
- -

DESCRIPTION

- -

BIO_new_CMS() returns a streaming filter BIO chain based on cms. The output of the filter is written to out. Any data written to the chain is automatically translated to a BER format CMS structure of the appropriate type.

- -

NOTES

- -

The chain returned by this function behaves like a standard filter BIO. It supports non blocking I/O. Content is processed and streamed on the fly and not all held in memory at once: so it is possible to encode very large structures. After all content has been written through the chain BIO_flush() must be called to finalise the structure.

- -

The CMS_STREAM flag must be included in the corresponding flags parameter of the cms creation function.

- -

If an application wishes to write additional data to out BIOs should be removed from the chain using BIO_pop() and freed with BIO_free() until out is reached. If no additional data needs to be written BIO_free_all() can be called to free up the whole chain.

- -

Any content written through the filter is used verbatim: no canonical translation is performed.

- -

It is possible to chain multiple BIOs to, for example, create a triple wrapped signed, enveloped, signed structure. In this case it is the applications responsibility to set the inner content type of any outer CMS_ContentInfo structures.

- -

Large numbers of small writes through the chain should be avoided as this will produce an output consisting of lots of OCTET STRING structures. Prepending a BIO_f_buffer() buffering BIO will prevent this.

- -

BUGS

- -

There is currently no corresponding inverse BIO: i.e. one which can decode a CMS structure on the fly.

- -

RETURN VALUES

- -

BIO_new_CMS() returns a BIO chain when successful or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_encrypt(3)

- -

HISTORY

- -

The BIO_new_CMS() function was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_parse_hostserv.html b/openssl-install/share/doc/openssl/html/man3/BIO_parse_hostserv.html deleted file mode 100644 index e9665c29..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_parse_hostserv.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -BIO_parse_hostserv - - - - - - - - - - -

NAME

- -

BIO_hostserv_priorities, BIO_parse_hostserv - utility routines to parse a standard host and service string

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-enum BIO_hostserv_priorities {
-    BIO_PARSE_PRIO_HOST, BIO_PARSE_PRIO_SERV
-};
-int BIO_parse_hostserv(const char *hostserv, char **host, char **service,
-                       enum BIO_hostserv_priorities hostserv_prio);
- -

DESCRIPTION

- -

BIO_parse_hostserv() will parse the information given in hostserv, create strings with the hostname and service name and give those back via host and service. Those will need to be freed after they are used. hostserv_prio helps determine if hostserv shall be interpreted primarily as a hostname or a service name in ambiguous cases.

- -

The syntax the BIO_parse_hostserv() recognises is:

- -
host + ':' + service
-host + ':' + '*'
-host + ':'
-       ':' + service
-'*'  + ':' + service
-host
-service
- -

The host part can be a name or an IP address. If it's a IPv6 address, it MUST be enclosed in brackets, such as '[::1]'.

- -

The service part can be a service name or its port number. A service name will be mapped to a port number using the system function getservbyname().

- -

The returned values will depend on the given hostserv string and hostserv_prio, as follows:

- -
host + ':' + service  => *host = "host", *service = "service"
-host + ':' + '*'      => *host = "host", *service = NULL
-host + ':'            => *host = "host", *service = NULL
-       ':' + service  => *host = NULL, *service = "service"
- '*' + ':' + service  => *host = NULL, *service = "service"
-
-in case no ':' is present in the string, the result depends on
-hostserv_prio, as follows:
-
-when hostserv_prio == BIO_PARSE_PRIO_HOST
-host                 => *host = "host", *service untouched
-
-when hostserv_prio == BIO_PARSE_PRIO_SERV
-service              => *host untouched, *service = "service"
- -

RETURN VALUES

- -

BIO_parse_hostserv() returns 1 on success or 0 on error.

- -

SEE ALSO

- -

BIO_ADDRINFO(3)

- -

COPYRIGHT

- -

Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_printf.html b/openssl-install/share/doc/openssl/html/man3/BIO_printf.html deleted file mode 100644 index ecac50e8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_printf.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -BIO_printf - - - - - - - - - - -

NAME

- -

BIO_printf, BIO_vprintf, BIO_snprintf, BIO_vsnprintf - formatted output to a BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-int BIO_printf(BIO *bio, const char *format, ...);
-int BIO_vprintf(BIO *bio, const char *format, va_list args);
-
-int BIO_snprintf(char *buf, size_t n, const char *format, ...);
-int BIO_vsnprintf(char *buf, size_t n, const char *format, va_list args);
- -

DESCRIPTION

- -

BIO_printf() is similar to the standard C printf() function, except that the output is sent to the specified BIO, bio, rather than standard output. All common format specifiers are supported.

- -

BIO_vprintf() is similar to the vprintf() function found on many platforms, the output is sent to the specified BIO, bio, rather than standard output. All common format specifiers are supported. The argument list args is a stdarg argument list.

- -

BIO_snprintf() is for platforms that do not have the common snprintf() function. It is like sprintf() except that the size parameter, n, specifies the size of the output buffer.

- -

BIO_vsnprintf() is to BIO_snprintf() as BIO_vprintf() is to BIO_printf().

- -

RETURN VALUES

- -

All functions return the number of bytes written, or -1 on error. For BIO_snprintf() and BIO_vsnprintf() this includes when the output buffer is too small.

- -

NOTES

- -

Except when n is 0, both BIO_snprintf() and BIO_vsnprintf() always terminate their output with '\0'. This includes cases where -1 is returned, such as when there is insufficient space to output the whole string.

- -

COPYRIGHT

- -

Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_push.html b/openssl-install/share/doc/openssl/html/man3/BIO_push.html deleted file mode 100644 index 07a090da..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_push.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -BIO_push - - - - - - - - - - -

NAME

- -

BIO_push, BIO_pop, BIO_set_next - add and remove BIOs from a chain

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-BIO *BIO_push(BIO *b, BIO *next);
-BIO *BIO_pop(BIO *b);
-void BIO_set_next(BIO *b, BIO *next);
- -

DESCRIPTION

- -

BIO_push() pushes b on next. If b is NULL the function does nothing and returns next. Otherwise it prepends b, which may be a single BIO or a chain of BIOs, to next (unless next is NULL). It then makes a control call on b and returns b.

- -

BIO_pop() removes the BIO b from any chain is is part of. If b is NULL the function does nothing and returns NULL. Otherwise it makes a control call on b and returns the next BIO in the chain, or NULL if there is no next BIO. The removed BIO becomes a single BIO with no association with the original chain, it can thus be freed or be made part of a different chain.

- -

BIO_set_next() replaces the existing next BIO in a chain with the BIO pointed to by next. The new chain may include some of the same BIOs from the old chain or it may be completely different.

- -

NOTES

- -

The names of these functions are perhaps a little misleading. BIO_push() joins two BIO chains whereas BIO_pop() deletes a single BIO from a chain, the deleted BIO does not need to be at the end of a chain.

- -

The process of calling BIO_push() and BIO_pop() on a BIO may have additional consequences (a control call is made to the affected BIOs). Any effects will be noted in the descriptions of individual BIOs.

- -

RETURN VALUES

- -

BIO_push() returns the head of the chain, which usually is b, or next if b is NULL.

- -

BIO_pop() returns the next BIO in the chain, or NULL if there is no next BIO.

- -

EXAMPLES

- -

For these examples suppose md1 and md2 are digest BIOs, b64 is a base64 BIO and f is a file BIO.

- -

If the call:

- -
BIO_push(b64, f);
- -

is made then the new chain will be b64-f. After making the calls

- -
BIO_push(md2, b64);
-BIO_push(md1, md2);
- -

the new chain is md1-md2-b64-f. Data written to md1 will be digested by md1 and md2, base64 encoded, and finally written to f.

- -

It should be noted that reading causes data to pass in the reverse direction, that is data is read from f, base64 decoded, and digested by md2 and then md1.

- -

The call:

- -
BIO_pop(md2);
- -

will return b64 and the new chain will be md1-b64-f. Data can be written to and read from md1 as before, except that md2 will no more be applied.

- -

SEE ALSO

- -

bio(7)

- -

HISTORY

- -

The BIO_set_next() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_read.html b/openssl-install/share/doc/openssl/html/man3/BIO_read.html deleted file mode 100644 index f0240bee..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_read.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -BIO_read - - - - - - - - - - -

NAME

- -

BIO_read_ex, BIO_write_ex, BIO_read, BIO_write, BIO_gets, BIO_get_line, BIO_puts - BIO I/O functions

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-int BIO_read_ex(BIO *b, void *data, size_t dlen, size_t *readbytes);
-int BIO_write_ex(BIO *b, const void *data, size_t dlen, size_t *written);
-
-int BIO_read(BIO *b, void *data, int dlen);
-int BIO_gets(BIO *b, char *buf, int size);
-int BIO_get_line(BIO *b, char *buf, int size);
-int BIO_write(BIO *b, const void *data, int dlen);
-int BIO_puts(BIO *b, const char *buf);
- -

DESCRIPTION

- -

BIO_read_ex() attempts to read dlen bytes from BIO b and places the data in data. If any bytes were successfully read then the number of bytes read is stored in *readbytes.

- -

BIO_write_ex() attempts to write dlen bytes from data to BIO b. If successful then the number of bytes written is stored in *written unless written is NULL.

- -

BIO_read() attempts to read len bytes from BIO b and places the data in buf.

- -

BIO_gets() performs the BIOs "gets" operation and places the data in buf. Usually this operation will attempt to read a line of data from the BIO of maximum length size-1. There are exceptions to this, however; for example, BIO_gets() on a digest BIO will calculate and return the digest and other BIOs may not support BIO_gets() at all. The returned string is always NUL-terminated and the '\n' is preserved if present in the input data. On binary input there may be NUL characters within the string; in this case the return value (if nonnegative) may give an incorrect length.

- -

BIO_get_line() attempts to read from BIO b a line of data up to the next '\n' or the maximum length size-1 is reached and places the data in buf. The returned string is always NUL-terminated and the '\n' is preserved if present in the input data. On binary input there may be NUL characters within the string; in this case the return value (if nonnegative) gives the actual length read. For implementing this, unfortunately the data needs to be read byte-by-byte.

- -

BIO_write() attempts to write len bytes from buf to BIO b.

- -

BIO_puts() attempts to write a NUL-terminated string buf to BIO b.

- -

RETURN VALUES

- -

BIO_read_ex() returns 1 if data was successfully read, and 0 otherwise.

- -

BIO_write_ex() returns 1 if no error was encountered writing data, 0 otherwise. Requesting to write 0 bytes is not considered an error.

- -

BIO_write() returns -2 if the "write" operation is not implemented by the BIO or -1 on other errors. Otherwise it returns the number of bytes written. This may be 0 if the BIO b is NULL or dlen <= 0.

- -

BIO_gets() returns -2 if the "gets" operation is not implemented by the BIO or -1 on other errors. Otherwise it typically returns the amount of data read, but depending on the implementation it may return only the length up to the first NUL character contained in the data read. In any case the trailing NUL that is added after the data read is not included in the length returned.

- -

All other functions return either the amount of data successfully read or written (if the return value is positive) or that no data was successfully read or written if the result is 0 or -1. If the return value is -2 then the operation is not implemented in the specific BIO type.

- -

NOTES

- -

A 0 or -1 return is not necessarily an indication of an error. In particular when the source/sink is nonblocking or of a certain type it may merely be an indication that no data is currently available and that the application should retry the operation later.

- -

One technique sometimes used with blocking sockets is to use a system call (such as select(), poll() or equivalent) to determine when data is available and then call read() to read the data. The equivalent with BIOs (that is call select() on the underlying I/O structure and then call BIO_read() to read the data) should not be used because a single call to BIO_read() can cause several reads (and writes in the case of SSL BIOs) on the underlying I/O structure and may block as a result. Instead select() (or equivalent) should be combined with non blocking I/O so successive reads will request a retry instead of blocking.

- -

See BIO_should_retry(3) for details of how to determine the cause of a retry and other I/O issues.

- -

If the "gets" method is not supported by a BIO then BIO_get_line() can be used. It is also possible to make BIO_gets() usable even if the "gets" method is not supported by adding a buffering BIO BIO_f_buffer(3) to the chain.

- -

SEE ALSO

- -

BIO_should_retry(3)

- -

HISTORY

- -

BIO_gets() on 1.1.0 and older when called on BIO_fd() based BIO did not keep the '\n' at the end of the line in the buffer.

- -

BIO_get_line() was added in OpenSSL 3.0.

- -

BIO_write_ex() returns 1 if the size of the data to write is 0 and the written parameter of the function can be NULL since OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_accept.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_accept.html deleted file mode 100644 index be0f8cac..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_accept.html +++ /dev/null @@ -1,187 +0,0 @@ - - - - -BIO_s_accept - - - - - - - - - - -

NAME

- -

BIO_s_accept, BIO_set_accept_name, BIO_set_accept_port, BIO_get_accept_name, BIO_get_accept_port, BIO_new_accept, BIO_set_nbio_accept, BIO_set_tfo_accept, BIO_set_accept_bios, BIO_get_peer_name, BIO_get_peer_port, BIO_get_accept_ip_family, BIO_set_accept_ip_family, BIO_set_bind_mode, BIO_get_bind_mode, BIO_do_accept - accept BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_accept(void);
-
-long BIO_set_accept_name(BIO *b, char *name);
-char *BIO_get_accept_name(BIO *b);
-
-long BIO_set_accept_port(BIO *b, char *port);
-char *BIO_get_accept_port(BIO *b);
-
-BIO *BIO_new_accept(char *host_port);
-
-long BIO_set_nbio_accept(BIO *b, int n);
-long BIO_set_tfo_accept(BIO *b, int n);
-long BIO_set_accept_bios(BIO *b, char *bio);
-
-char *BIO_get_peer_name(BIO *b);
-char *BIO_get_peer_port(BIO *b);
-long BIO_get_accept_ip_family(BIO *b);
-long BIO_set_accept_ip_family(BIO *b, long family);
-
-long BIO_set_bind_mode(BIO *b, long mode);
-long BIO_get_bind_mode(BIO *b);
-
-int BIO_do_accept(BIO *b);
- -

DESCRIPTION

- -

BIO_s_accept() returns the accept BIO method. This is a wrapper round the platform's TCP/IP socket accept routines.

- -

Using accept BIOs, TCP/IP connections can be accepted and data transferred using only BIO routines. In this way any platform specific operations are hidden by the BIO abstraction.

- -

Read and write operations on an accept BIO will perform I/O on the underlying connection. If no connection is established and the port (see below) is set up properly then the BIO waits for an incoming connection.

- -

Accept BIOs support BIO_puts() but not BIO_gets().

- -

If the close flag is set on an accept BIO then any active connection on that chain is shutdown and the socket closed when the BIO is freed.

- -

Calling BIO_reset() on an accept BIO will close any active connection and reset the BIO into a state where it awaits another incoming connection.

- -

BIO_get_fd() and BIO_set_fd() can be called to retrieve or set the accept socket. See BIO_s_fd(3)

- -

BIO_set_accept_name() uses the string name to set the accept name. The name is represented as a string of the form "host:port", where "host" is the interface to use and "port" is the port. The host can be "*" or empty which is interpreted as meaning any interface. If the host is an IPv6 address, it has to be enclosed in brackets, for example "[::1]:https". "port" has the same syntax as the port specified in BIO_set_conn_port() for connect BIOs, that is it can be a numerical port string or a string to lookup using getservbyname() and a string table.

- -

BIO_set_accept_port() uses the string port to set the accept port of BIO b. "port" has the same syntax as the port specified in BIO_set_conn_port() for connect BIOs, that is it can be a numerical port string or a string to lookup using getservbyname() and a string table. If the given port is 0 then a random available port is chosen. It may be queried using BIO_sock_info() and BIO_ADDR_service_string(3).

- -

BIO_new_accept() combines BIO_new() and BIO_set_accept_name() into a single call: that is it creates a new accept BIO with port host_port.

- -

BIO_set_nbio_accept() sets the accept socket to blocking mode (the default) if n is 0 or non blocking mode if n is 1.

- -

BIO_set_tfo_accept() enables TCP Fast Open on the accept socket if n is 1 or disables TCP Fast Open if n is 0 (the default). Setting the value to 1 is equivalent to setting BIO_SOCK_TFO in BIO_set_bind_mode().

- -

BIO_set_accept_bios() can be used to set a chain of BIOs which will be duplicated and prepended to the chain when an incoming connection is received. This is useful if, for example, a buffering or SSL BIO is required for each connection. The chain of BIOs must not be freed after this call, they will be automatically freed when the accept BIO is freed.

- -

BIO_get_accept_ip_family() returns the IP family accepted by the BIO b, which may be BIO_FAMILY_IPV4, BIO_FAMILY_IPV6, or BIO_FAMILY_IPANY.

- -

BIO_set_accept_ip_family() sets the IP family family accepted by BIO b. The default is BIO_FAMILY_IPANY.

- -

BIO_set_bind_mode() and BIO_get_bind_mode() set and retrieve the current bind mode. If BIO_BIND_NORMAL (the default) is set then another socket cannot be bound to the same port. If BIO_BIND_REUSEADDR is set then other sockets can bind to the same port. If BIO_BIND_REUSEADDR_IF_UNUSED is set then and attempt is first made to use BIO_BIN_NORMAL, if this fails and the port is not in use then a second attempt is made using BIO_BIND_REUSEADDR. If BIO_SOCK_TFO is set, then the socket will be configured to accept TCP Fast Open connections.

- -

BIO_do_accept() serves two functions. When it is first called, after the accept BIO has been setup, it will attempt to create the accept socket and bind an address to it. Second and subsequent calls to BIO_do_accept() will await an incoming connection, or request a retry in non blocking mode.

- -

NOTES

- -

When an accept BIO is at the end of a chain it will await an incoming connection before processing I/O calls. When an accept BIO is not at then end of a chain it passes I/O calls to the next BIO in the chain.

- -

When a connection is established a new socket BIO is created for the connection and appended to the chain. That is the chain is now accept->socket. This effectively means that attempting I/O on an initial accept socket will await an incoming connection then perform I/O on it.

- -

If any additional BIOs have been set using BIO_set_accept_bios() then they are placed between the socket and the accept BIO, that is the chain will be accept->otherbios->socket.

- -

If a server wishes to process multiple connections (as is normally the case) then the accept BIO must be made available for further incoming connections. This can be done by waiting for a connection and then calling:

- -
connection = BIO_pop(accept);
- -

After this call connection will contain a BIO for the recently established connection and accept will now be a single BIO again which can be used to await further incoming connections. If no further connections will be accepted the accept can be freed using BIO_free().

- -

If only a single connection will be processed it is possible to perform I/O using the accept BIO itself. This is often undesirable however because the accept BIO will still accept additional incoming connections. This can be resolved by using BIO_pop() (see above) and freeing up the accept BIO after the initial connection.

- -

If the underlying accept socket is nonblocking and BIO_do_accept() is called to await an incoming connection it is possible for BIO_should_io_special() with the reason BIO_RR_ACCEPT. If this happens then it is an indication that an accept attempt would block: the application should take appropriate action to wait until the underlying socket has accepted a connection and retry the call.

- -

BIO_set_accept_name(), BIO_get_accept_name(), BIO_set_accept_port(), BIO_get_accept_port(), BIO_set_nbio_accept(), BIO_set_accept_bios(), BIO_get_peer_name(), BIO_get_peer_port(), BIO_get_accept_ip_family(), BIO_set_accept_ip_family(), BIO_set_bind_mode(), BIO_get_bind_mode() and BIO_do_accept() are macros.

- -

RETURN VALUES

- -

BIO_do_accept(), BIO_set_accept_name(), BIO_set_accept_port(), BIO_set_nbio_accept(), BIO_set_accept_bios(), BIO_set_accept_ip_family(), and BIO_set_bind_mode() return 1 for success and <= 0 for failure.

- -

BIO_get_accept_name() returns the accept name or NULL on error. BIO_get_peer_name() returns the peer name or NULL on error.

- -

BIO_get_accept_port() returns the accept port as a string or NULL on error. BIO_get_peer_port() returns the peer port as a string or NULL on error. BIO_get_accept_ip_family() returns the IP family or <= 0 on error.

- -

BIO_get_bind_mode() returns the set of BIO_BIND flags, or <= 0 on failure.

- -

BIO_new_accept() returns a BIO or NULL on error.

- -

EXAMPLES

- -

This example accepts two connections on port 4444, sends messages down each and finally closes both down.

- -
BIO *abio, *cbio, *cbio2;
-
-/* First call to BIO_do_accept() sets up accept BIO */
-abio = BIO_new_accept("4444");
-if (BIO_do_accept(abio) <= 0) {
-    fprintf(stderr, "Error setting up accept\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-
-/* Wait for incoming connection */
-if (BIO_do_accept(abio) <= 0) {
-    fprintf(stderr, "Error accepting connection\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-fprintf(stderr, "Connection 1 established\n");
-
-/* Retrieve BIO for connection */
-cbio = BIO_pop(abio);
-BIO_puts(cbio, "Connection 1: Sending out Data on initial connection\n");
-fprintf(stderr, "Sent out data on connection 1\n");
-
-/* Wait for another connection */
-if (BIO_do_accept(abio) <= 0) {
-    fprintf(stderr, "Error accepting connection\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-fprintf(stderr, "Connection 2 established\n");
-
-/* Close accept BIO to refuse further connections */
-cbio2 = BIO_pop(abio);
-BIO_free(abio);
-BIO_puts(cbio2, "Connection 2: Sending out Data on second\n");
-fprintf(stderr, "Sent out data on connection 2\n");
-
-BIO_puts(cbio, "Connection 1: Second connection established\n");
-
-/* Close the two established connections */
-BIO_free(cbio);
-BIO_free(cbio2);
- -

HISTORY

- -

BIO_set_tfo_accept() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_bio.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_bio.html deleted file mode 100644 index e6f72e2d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_bio.html +++ /dev/null @@ -1,157 +0,0 @@ - - - - -BIO_s_bio - - - - - - - - - - -

NAME

- -

BIO_s_bio, BIO_make_bio_pair, BIO_destroy_bio_pair, BIO_shutdown_wr, BIO_set_write_buf_size, BIO_get_write_buf_size, BIO_new_bio_pair, BIO_get_write_guarantee, BIO_ctrl_get_write_guarantee, BIO_get_read_request, BIO_ctrl_get_read_request, BIO_ctrl_reset_read_request - BIO pair BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_bio(void);
-
-int BIO_make_bio_pair(BIO *b1, BIO *b2);
-int BIO_destroy_bio_pair(BIO *b);
-int BIO_shutdown_wr(BIO *b);
-
-int BIO_set_write_buf_size(BIO *b, long size);
-size_t BIO_get_write_buf_size(BIO *b, long size);
-
-int BIO_new_bio_pair(BIO **bio1, size_t writebuf1, BIO **bio2, size_t writebuf2);
-
-int BIO_get_write_guarantee(BIO *b);
-size_t BIO_ctrl_get_write_guarantee(BIO *b);
-int BIO_get_read_request(BIO *b);
-size_t BIO_ctrl_get_read_request(BIO *b);
-int BIO_ctrl_reset_read_request(BIO *b);
- -

DESCRIPTION

- -

BIO_s_bio() returns the method for a BIO pair. A BIO pair is a pair of source/sink BIOs where data written to either half of the pair is buffered and can be read from the other half. Both halves must usually by handled by the same application thread since no locking is done on the internal data structures.

- -

Since BIO chains typically end in a source/sink BIO it is possible to make this one half of a BIO pair and have all the data processed by the chain under application control.

- -

One typical use of BIO pairs is to place TLS/SSL I/O under application control, this can be used when the application wishes to use a non standard transport for TLS/SSL or the normal socket routines are inappropriate.

- -

Calls to BIO_read_ex() will read data from the buffer or request a retry if no data is available.

- -

Calls to BIO_write_ex() will place data in the buffer or request a retry if the buffer is full.

- -

The standard calls BIO_ctrl_pending() and BIO_ctrl_wpending() can be used to determine the amount of pending data in the read or write buffer.

- -

BIO_reset() clears any data in the write buffer.

- -

BIO_make_bio_pair() joins two separate BIOs into a connected pair.

- -

BIO_destroy_pair() destroys the association between two connected BIOs. Freeing up any half of the pair will automatically destroy the association.

- -

BIO_shutdown_wr() is used to close down a BIO b. After this call no further writes on BIO b are allowed (they will return an error). Reads on the other half of the pair will return any pending data or EOF when all pending data has been read.

- -

BIO_set_write_buf_size() sets the write buffer size of BIO b to size. If the size is not initialized a default value is used. This is currently 17K, sufficient for a maximum size TLS record.

- -

BIO_get_write_buf_size() returns the size of the write buffer.

- -

BIO_new_bio_pair() combines the calls to BIO_new(), BIO_make_bio_pair() and BIO_set_write_buf_size() to create a connected pair of BIOs bio1, bio2 with write buffer sizes writebuf1 and writebuf2. If either size is zero then the default size is used. BIO_new_bio_pair() does not check whether bio1 or bio2 do point to some other BIO, the values are overwritten, BIO_free() is not called.

- -

BIO_get_write_guarantee() and BIO_ctrl_get_write_guarantee() return the maximum length of data that can be currently written to the BIO. Writes larger than this value will return a value from BIO_write_ex() less than the amount requested or if the buffer is full request a retry. BIO_ctrl_get_write_guarantee() is a function whereas BIO_get_write_guarantee() is a macro.

- -

BIO_get_read_request() and BIO_ctrl_get_read_request() return the amount of data requested, or the buffer size if it is less, if the last read attempt at the other half of the BIO pair failed due to an empty buffer. This can be used to determine how much data should be written to the BIO so the next read will succeed: this is most useful in TLS/SSL applications where the amount of data read is usually meaningful rather than just a buffer size. After a successful read this call will return zero. It also will return zero once new data has been written satisfying the read request or part of it. Note that BIO_get_read_request() never returns an amount larger than that returned by BIO_get_write_guarantee().

- -

BIO_ctrl_reset_read_request() can also be used to reset the value returned by BIO_get_read_request() to zero.

- -

NOTES

- -

Both halves of a BIO pair should be freed. That is even if one half is implicit freed due to a BIO_free_all() or SSL_free() call the other half needs to be freed.

- -

When used in bidirectional applications (such as TLS/SSL) care should be taken to flush any data in the write buffer. This can be done by calling BIO_pending() on the other half of the pair and, if any data is pending, reading it and sending it to the underlying transport. This must be done before any normal processing (such as calling select() ) due to a request and BIO_should_read() being true.

- -

To see why this is important consider a case where a request is sent using BIO_write_ex() and a response read with BIO_read_ex(), this can occur during an TLS/SSL handshake for example. BIO_write_ex() will succeed and place data in the write buffer. BIO_read_ex() will initially fail and BIO_should_read() will be true. If the application then waits for data to be available on the underlying transport before flushing the write buffer it will never succeed because the request was never sent!

- -

BIO_eof() is true if no data is in the peer BIO and the peer BIO has been shutdown.

- -

BIO_make_bio_pair(), BIO_destroy_bio_pair(), BIO_shutdown_wr(), BIO_set_write_buf_size(), BIO_get_write_buf_size(), BIO_get_write_guarantee(), and BIO_get_read_request() are implemented as macros.

- -

RETURN VALUES

- -

BIO_new_bio_pair() returns 1 on success, with the new BIOs available in bio1 and bio2, or 0 on failure, with NULL pointers stored into the locations for bio1 and bio2. Check the error stack for more information.

- -

[XXXXX: More return values need to be added here]

- -

EXAMPLES

- -

The BIO pair can be used to have full control over the network access of an application. The application can call select() on the socket as required without having to go through the SSL-interface.

- -
BIO *internal_bio, *network_bio;
-
-...
-BIO_new_bio_pair(&internal_bio, 0, &network_bio, 0);
-SSL_set_bio(ssl, internal_bio, internal_bio);
-SSL_operations(); /* e.g. SSL_read and SSL_write */
-...
-
-application |   TLS-engine
-   |        |
-   +----------> SSL_operations()
-            |     /\    ||
-            |     ||    \/
-            |   BIO-pair (internal_bio)
-            |   BIO-pair (network_bio)
-            |     ||     /\
-            |     \/     ||
-   +-----------< BIO_operations()
-   |        |
-   |        |
-  socket
-
- ...
- SSL_free(ssl);                /* implicitly frees internal_bio */
- BIO_free(network_bio);
- ...
- -

As the BIO pair will only buffer the data and never directly access the connection, it behaves nonblocking and will return as soon as the write buffer is full or the read buffer is drained. Then the application has to flush the write buffer and/or fill the read buffer.

- -

Use the BIO_ctrl_pending(), to find out whether data is buffered in the BIO and must be transferred to the network. Use BIO_ctrl_get_read_request() to find out, how many bytes must be written into the buffer before the SSL_operation() can successfully be continued.

- -

WARNINGS

- -

As the data is buffered, SSL_operation() may return with an ERROR_SSL_WANT_READ condition, but there is still data in the write buffer. An application must not rely on the error value of SSL_operation() but must assure that the write buffer is always flushed first. Otherwise a deadlock may occur as the peer might be waiting for the data before being able to continue.

- -

SEE ALSO

- -

SSL_set_bio(3), ssl(7), bio(7), BIO_should_retry(3), BIO_read_ex(3)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_connect.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_connect.html deleted file mode 100644 index 53d2cf96..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_connect.html +++ /dev/null @@ -1,183 +0,0 @@ - - - - -BIO_s_connect - - - - - - - - - - -

NAME

- -

BIO_s_connect, BIO_new_connect, BIO_set_conn_hostname, BIO_set_conn_port, BIO_set_conn_address, BIO_set_conn_ip_family, BIO_get_conn_hostname, BIO_get_conn_port, BIO_get_conn_address, BIO_get_conn_ip_family, BIO_set_nbio, BIO_set_sock_type, BIO_get_sock_type, BIO_get0_dgram_bio, BIO_do_connect - connect BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_connect(void);
-
-BIO *BIO_new_connect(const char *name);
-
-long BIO_set_conn_hostname(BIO *b, char *name);
-long BIO_set_conn_port(BIO *b, char *port);
-long BIO_set_conn_address(BIO *b, BIO_ADDR *addr);
-long BIO_set_conn_ip_family(BIO *b, long family);
-const char *BIO_get_conn_hostname(BIO *b);
-const char *BIO_get_conn_port(BIO *b);
-const BIO_ADDR *BIO_get_conn_address(BIO *b);
-const long BIO_get_conn_ip_family(BIO *b);
-
-long BIO_set_nbio(BIO *b, long n);
-
-int BIO_set_sock_type(BIO *b, int sock_type);
-int BIO_get_sock_type(BIO *b);
-int BIO_get0_dgram_bio(BIO *B, BIO **dgram_bio);
-
-long BIO_do_connect(BIO *b);
- -

DESCRIPTION

- -

BIO_s_connect() returns the connect BIO method. This is a wrapper round the platform's TCP/IP socket connection routines.

- -

Using connect BIOs, TCP/IP connections can be made and data transferred using only BIO routines. In this way any platform specific operations are hidden by the BIO abstraction.

- -

Read and write operations on a connect BIO will perform I/O on the underlying connection. If no connection is established and the port and hostname (see below) is set up properly then a connection is established first.

- -

Connect BIOs support BIO_puts() and BIO_gets().

- -

If the close flag is set on a connect BIO then any active connection is shutdown and the socket closed when the BIO is freed.

- -

Calling BIO_reset() on a connect BIO will close any active connection and reset the BIO into a state where it can connect to the same host again.

- -

BIO_new_connect() combines BIO_new() and BIO_set_conn_hostname() into a single call: that is it creates a new connect BIO with hostname name.

- -

BIO_set_conn_hostname() uses the string name to set the hostname. The hostname can be an IP address; if the address is an IPv6 one, it must be enclosed in brackets [ and ]. The hostname can also include the port in the form hostname:port; see BIO_parse_hostserv(3) and BIO_set_conn_port() for details.

- -

BIO_set_conn_port() sets the port to port. port can be the numerical form or a service string such as "http", which will be mapped to a port number using the system function getservbyname().

- -

BIO_set_conn_address() sets the address and port information using a BIO_ADDR(3ssl).

- -

BIO_set_conn_ip_family() sets the IP family.

- -

BIO_get_conn_hostname() returns the hostname of the connect BIO or NULL if the BIO is initialized but no hostname is set. This return value is an internal pointer which should not be modified.

- -

BIO_get_conn_port() returns the port as a string. This return value is an internal pointer which should not be modified.

- -

BIO_get_conn_address() returns the address information as a BIO_ADDR. This return value is an internal pointer which should not be modified.

- -

BIO_get_conn_ip_family() returns the IP family of the connect BIO.

- -

BIO_set_nbio() sets the non blocking I/O flag to n. If n is zero then blocking I/O is set. If n is 1 then non blocking I/O is set. Blocking I/O is the default. The call to BIO_set_nbio() should be made before the connection is established because non blocking I/O is set during the connect process.

- -

BIO_do_connect() attempts to connect the supplied BIO. This performs an SSL/TLS handshake as far as supported by the BIO. For non-SSL BIOs the connection is done typically at TCP level. If domain name resolution yields multiple IP addresses all of them are tried after connect() failures. The function returns 1 if the connection was established successfully. A zero or negative value is returned if the connection could not be established. The call BIO_should_retry() should be used for non blocking connect BIOs to determine if the call should be retried. If a connection has already been established this call has no effect.

- -

BIO_set_sock_type() can be used to set a socket type value as would be passed in a call to socket(2). The only currently supported values are SOCK_STREAM (the default) and SOCK_DGRAM. If SOCK_DGRAM is configured, the connection created is a UDP datagram socket handled via BIO_s_datagram(3). I/O calls such as BIO_read(3) and BIO_write(3) are forwarded transparently to an internal BIO_s_datagram(3) instance. The created BIO_s_datagram(3) instance can be retrieved using BIO_get0_dgram_bio() if desired, which writes a pointer to the BIO_s_datagram(3) instance to *dgram_bio. The lifetime of the internal BIO_s_datagram(3) is managed by BIO_s_connect() and does not need to be freed by the caller.

- -

BIO_get_sock_type() retrieves the value set using BIO_set_sock_type().

- -

NOTES

- -

If blocking I/O is set then a non positive return value from any I/O call is caused by an error condition, although a zero return will normally mean that the connection was closed.

- -

If the port name is supplied as part of the hostname then this will override any value set with BIO_set_conn_port(). This may be undesirable if the application does not wish to allow connection to arbitrary ports. This can be avoided by checking for the presence of the ':' character in the passed hostname and either indicating an error or truncating the string at that point.

- -

The values returned by BIO_get_conn_hostname(), BIO_get_conn_address(), and BIO_get_conn_port() are updated when a connection attempt is made. Before any connection attempt the values returned are those set by the application itself.

- -

Applications do not have to call BIO_do_connect() but may wish to do so to separate the connection process from other I/O processing.

- -

If non blocking I/O is set then retries will be requested as appropriate.

- -

It addition to BIO_should_read() and BIO_should_write() it is also possible for BIO_should_io_special() to be true during the initial connection process with the reason BIO_RR_CONNECT. If this is returned then this is an indication that a connection attempt would block, the application should then take appropriate action to wait until the underlying socket has connected and retry the call.

- -

BIO_set_conn_hostname(), BIO_set_conn_port(), BIO_get_conn_hostname(), BIO_set_conn_address(), BIO_get_conn_port(), BIO_get_conn_address(), BIO_set_conn_ip_family(), BIO_get_conn_ip_family(), BIO_set_nbio(), and BIO_do_connect() are macros.

- -

RETURN VALUES

- -

BIO_s_connect() returns the connect BIO method.

- -

BIO_set_conn_address(), BIO_set_conn_port(), and BIO_set_conn_ip_family() return 1 or <=0 if an error occurs.

- -

BIO_set_conn_hostname() returns 1 on success and <=0 on failure.

- -

BIO_get_conn_address() returns the address information or NULL if none was set.

- -

BIO_get_conn_hostname() returns the connected hostname or NULL if none was set.

- -

BIO_get_conn_ip_family() returns the address family or -1 if none was set.

- -

BIO_get_conn_port() returns a string representing the connected port or NULL if not set.

- -

BIO_set_nbio() returns 1 or <=0 if an error occurs.

- -

BIO_do_connect() returns 1 if the connection was successfully established and <=0 if the connection failed.

- -

BIO_set_sock_type() returns 1 on success or 0 on failure.

- -

BIO_get_sock_type() returns a socket type or 0 if the call is not supported.

- -

BIO_get0_dgram_bio() returns 1 on success or 0 on failure.

- -

EXAMPLES

- -

This is example connects to a webserver on the local host and attempts to retrieve a page and copy the result to standard output.

- -
BIO *cbio, *out;
-int len;
-char tmpbuf[1024];
-
-cbio = BIO_new_connect("localhost:http");
-out = BIO_new_fp(stdout, BIO_NOCLOSE);
-if (BIO_do_connect(cbio) <= 0) {
-    fprintf(stderr, "Error connecting to server\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
-BIO_puts(cbio, "GET / HTTP/1.0\n\n");
-for (;;) {
-    len = BIO_read(cbio, tmpbuf, 1024);
-    if (len <= 0)
-        break;
-    BIO_write(out, tmpbuf, len);
-}
-BIO_free(cbio);
-BIO_free(out);
- -

SEE ALSO

- -

BIO_ADDR(3), BIO_parse_hostserv(3)

- -

HISTORY

- -

BIO_set_conn_int_port(), BIO_get_conn_int_port(), BIO_set_conn_ip(), and BIO_get_conn_ip() were removed in OpenSSL 1.1.0. Use BIO_set_conn_address() and BIO_get_conn_address() instead.

- -

Connect BIOs support BIO_gets() since OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_core.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_core.html deleted file mode 100644 index b5df0cd5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_core.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -BIO_s_core - - - - - - - - - - -

NAME

- -

BIO_s_core, BIO_new_from_core_bio - OSSL_CORE_BIO functions

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_core(void);
-
-BIO *BIO_new_from_core_bio(OSSL_LIB_CTX *libctx, OSSL_CORE_BIO *corebio);
- -

DESCRIPTION

- -

BIO_s_core() returns the core BIO method function.

- -

A core BIO is treated as source/sink BIO which communicates to some external BIO. This is primarily useful to provider authors. A number of calls from libcrypto into a provider supply an OSSL_CORE_BIO parameter. This represents a BIO within libcrypto, but cannot be used directly by a provider. Instead it should be wrapped using a BIO_s_core().

- -

Once a BIO is constructed based on BIO_s_core(), the associated OSSL_CORE_BIO object should be set on it using BIO_set_data(3). Note that the BIO will only operate correctly if it is associated with a library context constructed using OSSL_LIB_CTX_new_from_dispatch(3). To associate the BIO with a library context construct it using BIO_new_ex(3).

- -

BIO_new_from_core_bio() is a convenience function that constructs a new BIO based on BIO_s_core() and that is associated with the given library context. It then also sets the OSSL_CORE_BIO object on the BIO using BIO_set_data(3).

- -

RETURN VALUES

- -

BIO_s_core() return a core BIO BIO_METHOD structure.

- -

BIO_new_from_core_bio() returns a BIO structure on success or NULL on failure. A failure will most commonly be because the library context was not constructed using OSSL_LIB_CTX_new_from_dispatch(3).

- -

HISTORY

- -

BIO_s_core() and BIO_new_from_core_bio() were added in OpenSSL 3.0.

- -

EXAMPLES

- -

Create a core BIO and write some data to it:

- -
int some_function(OSSL_LIB_CTX *libctx, OSSL_CORE_BIO *corebio) {
-    BIO *cbio = BIO_new_from_core_bio(libctx, corebio);
-
-    if (cbio == NULL)
-        return 0;
-
-    BIO_puts(cbio, "Hello World\n");
-
-    BIO_free(cbio);
-    return 1;
-}
- -

COPYRIGHT

- -

Copyright 2021-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_datagram.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_datagram.html deleted file mode 100644 index bd90ea0c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_datagram.html +++ /dev/null @@ -1,228 +0,0 @@ - - - - -BIO_s_datagram - - - - - - - - - - -

NAME

- -

BIO_s_datagram, BIO_new_dgram, BIO_ctrl_dgram_connect, BIO_ctrl_set_connected, BIO_dgram_recv_timedout, BIO_dgram_send_timedout, BIO_dgram_get_peer, BIO_dgram_set_peer, BIO_dgram_detect_peer_addr, BIO_dgram_get_mtu_overhead - Network BIO with datagram semantics

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-BIO_METHOD *BIO_s_datagram(void);
-BIO *BIO_new_dgram(int fd, int close_flag);
-
-int BIO_ctrl_dgram_connect(BIO *bio, const BIO_ADDR *peer);
-int BIO_ctrl_set_connected(BIO *bio, const BIO_ADDR *peer);
-int BIO_dgram_recv_timedout(BIO *bio);
-int BIO_dgram_send_timedout(BIO *bio);
-int BIO_dgram_get_peer(BIO *bio, BIO_ADDR *peer);
-int BIO_dgram_set_peer(BIO *bio, const BIO_ADDR *peer);
-int BIO_dgram_get_mtu_overhead(BIO *bio);
-int BIO_dgram_detect_peer_addr(BIO *bio, BIO_ADDR *peer);
- -

DESCRIPTION

- -

BIO_s_datagram() is a BIO implementation designed for use with network sockets which provide datagram semantics, such as UDP sockets. It is suitable for use with DTLSv1 or QUIC.

- -

Because BIO_s_datagram() has datagram semantics, a single BIO_write() call sends a single datagram and a single BIO_read() call receives a single datagram. If the size of the buffer passed to BIO_read() is inadequate, the datagram is silently truncated.

- -

For a memory-based BIO which provides datagram semantics identical to those of BIO_s_datagram(), see BIO_s_dgram_pair(3).

- -

This BIO supports the BIO_sendmmsg(3) and BIO_recvmmsg(3) functions.

- -

When using BIO_s_datagram(), it is important to note that:

- - - -

Various controls are available for configuring the BIO_s_datagram() using BIO_ctrl(3):

- -
- -
BIO_ctrl_dgram_connect (BIO_CTRL_DGRAM_CONNECT)
-
- -

This is equivalent to calling BIO_dgram_set_peer(3).

- -

Despite its name, this function does not cause the underlying socket to become connected.

- -
-
BIO_ctrl_set_connected (BIO_CTRL_SET_CONNECTED)
-
- -

This informs the BIO_s_datagram() whether the underlying socket has been connected, and therefore how the BIO_s_datagram() should attempt to use the socket.

- -

If the peer argument is non-NULL, BIO_s_datagram() assumes that the underlying socket has been connected and will attempt to use the socket using OS APIs which do not specify peer addresses (for example, send(3) and recv(3) or similar). The peer argument should specify the peer address to which the socket is connected.

- -

If the peer argument is NULL, BIO_s_datagram() assumes that the underlying socket is not connected and will attempt to use the socket using an OS APIs which specify peer addresses (for example, sendto(3) and recvfrom(3)).

- -

This control does not affect the operation of BIO_sendmmsg(3) or BIO_recvmmsg(3).

- -
-
BIO_dgram_get_peer (BIO_CTRL_DGRAM_GET_PEER)
-
- -

This outputs a BIO_ADDR which specifies one of the following values, whichever happened most recently:

- -
    - -
  • The peer address last passed to BIO_dgram_set_peer(), BIO_ctrl_dgram_connect() or BIO_ctrl_set_connected().

    - -
  • -
  • The peer address of the datagram last received by a call to BIO_read().

    - -
  • -
- -
-
BIO_dgram_set_peer (BIO_CTRL_DGRAM_SET_PEER)
-
- -

Sets the peer address to be used for subsequent writes to this BIO.

- -

Warning: When used with an unconnected network socket, the value set may be modified by future calls to BIO_read(3), making use of BIO_s_datagram() hazardous when used with unconnected network sockets; see above.

- -

This does not affect the operation of BIO_sendmmsg(3). BIO_recvmmsg(3) does not affect the value set by BIO_dgram_set_peer().

- -
-
BIO_dgram_detect_peer_addr (BIO_CTRL_DGRAM_DETECT_PEER_ADDR)
-
- -

This is similar to BIO_dgram_get_peer() except that if the peer address has not been set on the BIO object, an OS call such as getpeername(2) will be attempted to try and autodetect the peer address to which the underlying socket is connected. Other BIOs may also implement this control if they are capable of sensing a peer address, without necessarily also implementing BIO_dgram_set_peer() and BIO_dgram_get_peer().

- -
-
BIO_dgram_recv_timeout (BIO_CTRL_DGRAM_GET_RECV_TIMER_EXP)
-
- -

Returns 1 if the last I/O operation performed on the BIO (for example, via a call to BIO_read(3)) may have been caused by a receive timeout.

- -
-
BIO_dgram_send_timedout (BIO_CTRL_DGRAM_GET_SEND_TIMER_EXP)
-
- -

Returns 1 if the last I/O operation performed on the BIO (for example, via a call to BIO_write(3)) may have been caused by a send timeout.

- -
-
BIO_dgram_get_mtu_overhead (BIO_CTRL_DGRAM_GET_MTU_OVERHEAD)
-
- -

Returns a quantity in bytes which is a rough estimate of the number of bytes of overhead which should typically be added to a datagram payload size in order to estimate the final size of the Layer 3 (e.g. IP) packet which will contain the datagram. In most cases, the maximum datagram payload size which can be transmitted can be determined by determining the link MTU in bytes and subtracting the value returned by this call.

- -

The value returned by this call depends on the network layer protocol being used.

- -

The value returned is not fully reliable because datagram overheads can be higher in atypical network configurations, for example where IPv6 extension headers or IPv4 options are used.

- -
-
BIO_CTRL_DGRAM_SET_DONT_FRAG
-
- -

If num is nonzero, configures the underlying network socket to enable Don't Fragment mode, in which datagrams will be set with the IP Don't Fragment (DF) bit set. If num is zero, Don't Fragment mode is disabled.

- -
-
BIO_CTRL_DGRAM_QUERY_MTU
-
- -

Queries the OS for its assessment of the Path MTU for the destination to which the underlying network socket, and returns that Path MTU in bytes. This control can only be used with a connected socket.

- -

This is not supported on all platforms and depends on OS support being available. Returns 0 on failure.

- -
-
BIO_CTRL_DGRAM_MTU_DISCOVER
-
- -

This control requests that Path MTU discovery be enabled on the underlying network socket.

- -
-
BIO_CTRL_DGRAM_GET_FALLBACK_MTU
-
- -

Returns the estimated minimum size of datagram payload which should always be supported on the BIO. This size is determined by the minimum MTU required to be supported by the applicable underlying network layer. Use of datagrams of this size may lead to suboptimal performance, but should be routable in all circumstances. The value returned is the datagram payload size in bytes and does not include the size of layer 3 or layer 4 protocol headers.

- -
-
BIO_CTRL_DGRAM_MTU_EXCEEDED
-
- -

Returns 1 if the last attempted write to the BIO failed due to the size of the attempted write exceeding the applicable MTU.

- -
-
BIO_CTRL_DGRAM_SET_NEXT_TIMEOUT
-
- -

Accepts a pointer to a struct timeval. If the time specified is zero, disables receive timeouts. Otherwise, configures the specified time interval as the receive timeout for the socket for the purposes of future BIO_read(3) calls.

- -
-
BIO_CTRL_DGRAM_SET_PEEK_MODE
-
- -

If num is nonzero, enables peek mode; otherwise, disables peek mode. Where peek mode is enabled, calls to BIO_read(3) read datagrams from the underlying network socket in peek mode, meaning that a future call to BIO_read(3) will yield the same datagram until peek mode is disabled.

- -

BIO_recvmmsg(3) is not affected by this control.

- -
-
- -

BIO_new_dgram() is a helper function which instantiates a BIO_s_datagram() and sets the BIO to use the socket given in fd by calling BIO_set_fd().

- -

RETURN VALUES

- -

BIO_s_datagram() returns a BIO method.

- -

BIO_new_dgram() returns a BIO on success and NULL on failure.

- -

BIO_ctrl_dgram_connect(), BIO_ctrl_set_connected() and BIO_dgram_set_peer() return 1 on success and 0 on failure.

- -

BIO_dgram_get_peer() and BIO_dgram_detect_peer_addr() return 0 on failure and the number of bytes for the outputted address representation (a positive value) on success.

- -

BIO_dgram_recv_timedout() and BIO_dgram_send_timedout() return 0 or 1 depending on the circumstance; see discussion above.

- -

BIO_dgram_get_mtu_overhead() returns a value in bytes.

- -

SEE ALSO

- -

BIO_sendmmsg(3), BIO_s_dgram_pair(3), DTLSv1_listen(3), bio(7)

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_dgram_pair.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_dgram_pair.html deleted file mode 100644 index e7de8b1f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_dgram_pair.html +++ /dev/null @@ -1,163 +0,0 @@ - - - - -BIO_s_dgram_pair - - - - - - - - - - -

NAME

- -

BIO_s_dgram_pair, BIO_new_bio_dgram_pair, BIO_dgram_set_no_trunc, BIO_dgram_get_no_trunc, BIO_dgram_get_effective_caps, BIO_dgram_get_caps, BIO_dgram_set_caps, BIO_dgram_set_mtu, BIO_dgram_get_mtu - datagram pair BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_dgram_pair(void);
-
-int BIO_new_bio_dgram_pair(BIO **bio1, size_t writebuf1,
-                           BIO **bio2, size_t writebuf2);
-int BIO_dgram_set_no_trunc(BIO *bio, int enable);
-int BIO_dgram_get_no_trunc(BIO *bio);
-uint32_t BIO_dgram_get_effective_caps(BIO *bio);
-uint32_t BIO_dgram_get_caps(BIO *bio);
-int BIO_dgram_set_caps(BIO *bio, uint32_t caps);
-int BIO_dgram_set_mtu(BIO *bio, unsigned int mtu);
-unsigned int BIO_dgram_get_mtu(BIO *bio);
- -

DESCRIPTION

- -

BIO_s_dgram_pair() returns the method for a BIO datagram pair. A BIO datagram pair is similar to a BIO pair (see BIO_s_bio(3)) but has datagram semantics. Broadly, this means that the length of the buffer passed to a write call will match that retrieved by a read call. If the buffer passed to a read call is too short, the datagram is truncated or the read fails, depending on how the BIO is configured.

- -

The BIO datagram pair attaches certain metadata to each write, such as source and destination addresses. This information may be retrieved on read.

- -

A typical application of a BIO datagram pair is to allow an application to keep all datagram network I/O requested by libssl under application control.

- -

The BIO datagram pair is designed to support multithreaded use where certain restrictions are observed; see THREADING.

- -

The BIO datagram pair allows each half of a pair to signal to the other half whether they support certain capabilities; see CAPABILITY INDICATION.

- -

BIO_new_bio_dgram_pair() combines the calls to BIO_new(3), BIO_make_bio_pair(3) and BIO_set_write_buf_size(3) to create a connected pair of BIOs bio1, bio2 with write buffer sizes writebuf1 and writebuf2. If either size is zero then the default size is used.

- -

BIO_make_bio_pair(3) may be used to join two datagram pair BIOs into a pair. The two BIOs must both use the method returned by BIO_s_dgram_pair() and neither of the BIOs may currently be associated in a pair.

- -

BIO_destroy_bio_pair(3) destroys the association between two connected BIOs. Freeing either half of the pair will automatically destroy the association.

- -

BIO_reset(3) clears any data in the write buffer of the given BIO. This means that the opposite BIO in the pair will no longer have any data waiting to be read.

- -

The BIO maintains a fixed size internal write buffer. When the buffer is full, further writes will fail until the buffer is drained via calls to BIO_read(3). The size of the buffer can be changed using BIO_set_write_buf_size(3) and queried using BIO_get_write_buf_size(3).

- -

Note that the write buffer is partially consumed by metadata stored internally which is attached to each datagram, such as source and destination addresses. The size of this overhead is undefined and may change between releases.

- -

The standard BIO_ctrl_pending(3) call has modified behaviour and returns the size of the next datagram waiting to be read in bytes. An application can use this function to ensure it provides an adequate buffer to a subsequent read call. If no datagram is waiting to be read, zero is returned.

- -

This BIO does not support sending or receiving zero-length datagrams. Passing a zero-length buffer to BIO_write is treated as a no-op.

- -

BIO_eof(3) returns 1 only if the given BIO datagram pair BIO is not currently connected to a peer BIO.

- -

BIO_get_write_guarantee(3) and BIO_ctrl_get_write_guarantee(3) return how large a datagram the next call to BIO_write(3) can accept. If there is not enough space in the write buffer to accept another datagram equal in size to the configured MTU, zero is returned (see below). This is intended to avoid a situation where an application attempts to read a datagram from a network intending to write it to a BIO datagram pair, but where the received datagram ends up being too large to write to the BIO datagram pair.

- -

BIO_dgram_set_no_trunc() and BIO_ctrl_get_no_trunc() set and retrieve the truncation mode for the given half of a BIO datagram pair. When no-truncate mode is enabled, BIO_read() will fail if the buffer provided is inadequate to hold the next datagram to be read. If no-truncate mode is disabled (the default), the datagram will be silently truncated. This default behaviour maintains compatibility with the semantics of the Berkeley sockets API.

- -

BIO_dgram_set_mtu() and BIO_dgram_get_mtu() may be used to set an informational MTU value on the BIO datagram pair. If BIO_dgram_set_mtu() is used on a BIO which is currently part of a BIO datagram pair, the MTU value is set on both halves of the pair. The value does not affect the operation of the BIO datagram pair (except for BIO_get_write_guarantee(); see above) but may be used by other code to determine a requested MTU. When a BIO datagram pair BIO is created, the MTU is set to an unspecified but valid value.

- -

BIO_flush(3) is a no-op.

- -

NOTES

- -

The halves of a BIO datagram pair have independent lifetimes and must be separately freed.

- -

THREADING

- -

BIO_recvmmsg(3), BIO_sendmmsg(3), BIO_read(3), BIO_write(3), BIO_pending(3), BIO_get_write_guarantee(3) and BIO_flush(3) may be used by multiple threads simultaneously on the same BIO datagram pair. Specific BIO_ctrl(3) operations (namely BIO_CTRL_PENDING, BIO_CTRL_FLUSH and BIO_C_GET_WRITE_GUARANTEE) may also be used. Invoking any other BIO call, or any other BIO_ctrl(3) operation, on either half of a BIO datagram pair while any other BIO call is also in progress to either half of the same BIO datagram pair results in undefined behaviour.

- -

CAPABILITY INDICATION

- -

The BIO datagram pair can be used to enqueue datagrams which have source and destination addresses attached. It is important that the component consuming one side of a BIO datagram pair understand whether the other side of the pair will honour any source and destination addresses it attaches to each datagram. For example, if datagrams are queued with destination addresses set but simply read by simple calls to BIO_read(3), the destination addresses will be discarded.

- -

Each half of a BIO datagram pair can have capability flags set on it which indicate whether source and destination addresses will be honoured by the reader and whether they will be provided by the writer. These capability flags should be set via a call to BIO_dgram_set_caps(), and these capabilities will be reflected in the value returned by BIO_dgram_get_effective_caps() on the opposite BIO. If necessary, the capability value previously set can be retrieved using BIO_dgram_get_caps(). Note that BIO_dgram_set_caps() on a given BIO controls the capabilities advertised to the peer, and BIO_dgram_get_effective_caps() on a given BIO determines the capabilities advertised by the peer of that BIO.

- -

The following capabilities are available:

- -
- -
BIO_DGRAM_CAP_HANDLES_SRC_ADDR
-
- -

The user of the datagram pair BIO promises to honour source addresses provided with datagrams written to the BIO pair.

- -
-
BIO_DGRAM_CAP_HANDLES_DST_ADDR
-
- -

The user of the datagram pair BIO promises to honour destination addresses provided with datagrams written to the BIO pair.

- -
-
BIO_DGRAM_CAP_PROVIDES_SRC_ADDR
-
- -

The user of the datagram pair BIO advertises the fact that it will provide source addressing information with future writes to the BIO pair, where available.

- -
-
BIO_DGRAM_CAP_PROVIDES_DST_ADDR
-
- -

The user of the datagram pair BIO advertises the fact that it will provide destination addressing information with future writes to the BIO pair, where available.

- -
-
- -

If a caller attempts to specify a destination address (for example, using BIO_sendmmsg(3)) and the peer has not advertised the BIO_DGRAM_CAP_HANDLES_DST_ADDR capability, the operation fails. Thus, capability negotiation is mandatory.

- -

If a caller attempts to specify a source address when writing, or requests a destination address when receiving, and local address support has not been enabled, the operation fails; see BIO_dgram_set_local_addr_enable(3).

- -

If a caller attempts to enable local address support using BIO_dgram_set_local_addr_enable(3) and BIO_dgram_get_local_addr_cap(3) does not return 1 (meaning that the peer has not advertised both the BIO_DGRAM_CAP_HANDLES_SRC_ADDR and the BIO_DGRAM_CAP_PROVIDES_DST_ADDR capability), the operation fails.

- -

BIO_DGRAM_CAP_PROVIDES_SRC_ADDR and BIO_DGRAM_CAP_PROVIDES_DST_ADDR indicate that the application using that half of a BIO datagram pair promises to provide source and destination addresses respectively when writing datagrams to that half of the BIO datagram pair. However, these capability flags do not affect the behaviour of the BIO datagram pair.

- -

RETURN VALUES

- -

BIO_new_bio_dgram_pair() returns 1 on success, with the new BIOs available in bio1 and bio2, or 0 on failure, with NULL pointers stored into the locations for bio1 and bio2. Check the error stack for more information.

- -

BIO_dgram_set_no_trunc(), BIO_dgram_set_caps() and BIO_dgram_set_mtu() return 1 on success and 0 on failure.

- -

BIO_dgram_get_no_trunc() returns 1 if no-truncate mode is enabled on a BIO, or 0 if no-truncate mode is not enabled or not supported on a given BIO.

- -

BIO_dgram_get_effective_caps() and BIO_dgram_get_caps() return zero if no capabilities are supported.

- -

BIO_dgram_get_mtu() returns the MTU value configured on the BIO, or zero if the operation is not supported.

- -

SEE ALSO

- -

BIO_s_bio(3), bio(7)

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_fd.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_fd.html deleted file mode 100644 index f8a475c1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_fd.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -BIO_s_fd - - - - - - - - - - -

NAME

- -

BIO_s_fd, BIO_set_fd, BIO_get_fd, BIO_new_fd - file descriptor BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_fd(void);
-
-int BIO_set_fd(BIO *b, int fd, int c);
-int BIO_get_fd(BIO *b, int *c);
-
-BIO *BIO_new_fd(int fd, int close_flag);
- -

DESCRIPTION

- -

BIO_s_fd() returns the file descriptor BIO method. This is a wrapper round the platforms file descriptor routines such as read() and write().

- -

BIO_read_ex() and BIO_write_ex() read or write the underlying descriptor. BIO_puts() is supported but BIO_gets() is not.

- -

If the close flag is set then close() is called on the underlying file descriptor when the BIO is freed.

- -

BIO_reset() attempts to change the file pointer to the start of file such as by using lseek(fd, 0, 0).

- -

BIO_seek() sets the file pointer to position ofs from start of file such as by using lseek(fd, ofs, 0).

- -

BIO_tell() returns the current file position such as by calling lseek(fd, 0, 1).

- -

BIO_set_fd() sets the file descriptor of BIO b to fd and the close flag to c.

- -

BIO_get_fd() places the file descriptor of BIO b in c if it is not NULL. It also returns the file descriptor.

- -

BIO_new_fd() returns a file descriptor BIO using fd and close_flag.

- -

NOTES

- -

The behaviour of BIO_read_ex() and BIO_write_ex() depends on the behavior of the platforms read() and write() calls on the descriptor. If the underlying file descriptor is in a non blocking mode then the BIO will behave in the manner described in the BIO_read_ex(3) and BIO_should_retry(3) manual pages.

- -

File descriptor BIOs should not be used for socket I/O. Use socket BIOs instead.

- -

BIO_set_fd() and BIO_get_fd() are implemented as macros.

- -

RETURN VALUES

- -

BIO_s_fd() returns the file descriptor BIO method.

- -

BIO_set_fd() returns 1 on success or <=0 for failure.

- -

BIO_get_fd() returns the file descriptor or -1 if the BIO has not been initialized. It also returns zero and negative values if other error occurs.

- -

BIO_new_fd() returns the newly allocated BIO or NULL is an error occurred.

- -

EXAMPLES

- -

This is a file descriptor BIO version of "Hello World":

- -
BIO *out;
-
-out = BIO_new_fd(fileno(stdout), BIO_NOCLOSE);
-BIO_printf(out, "Hello World\n");
-BIO_free(out);
- -

SEE ALSO

- -

BIO_seek(3), BIO_tell(3), BIO_reset(3), BIO_read_ex(3), BIO_write_ex(3), BIO_puts(3), BIO_gets(3), BIO_printf(3), BIO_set_close(3), BIO_get_close(3)

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_file.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_file.html deleted file mode 100644 index c5bb2c85..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_file.html +++ /dev/null @@ -1,159 +0,0 @@ - - - - -BIO_s_file - - - - - - - - - - -

NAME

- -

BIO_s_file, BIO_new_file, BIO_new_fp, BIO_set_fp, BIO_get_fp, BIO_read_filename, BIO_write_filename, BIO_append_filename, BIO_rw_filename - FILE bio

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_file(void);
-BIO *BIO_new_file(const char *filename, const char *mode);
-BIO *BIO_new_fp(FILE *stream, int flags);
-
-BIO_set_fp(BIO *b, FILE *fp, int flags);
-BIO_get_fp(BIO *b, FILE **fpp);
-
-int BIO_read_filename(BIO *b, char *name);
-int BIO_write_filename(BIO *b, char *name);
-int BIO_append_filename(BIO *b, char *name);
-int BIO_rw_filename(BIO *b, char *name);
- -

DESCRIPTION

- -

BIO_s_file() returns the BIO file method. As its name implies it is a wrapper round the stdio FILE structure and it is a source/sink BIO.

- -

Calls to BIO_read_ex() and BIO_write_ex() read and write data to the underlying stream. BIO_gets() and BIO_puts() are supported on file BIOs.

- -

BIO_flush() on a file BIO calls the fflush() function on the wrapped stream.

- -

BIO_reset() attempts to change the file pointer to the start of file using fseek(stream, 0, 0).

- -

BIO_seek() sets the file pointer to position ofs from start of file using fseek(stream, ofs, 0).

- -

BIO_eof() calls feof().

- -

Setting the BIO_CLOSE flag calls fclose() on the stream when the BIO is freed.

- -

BIO_new_file() creates a new file BIO with mode mode the meaning of mode is the same as the stdio function fopen(). The BIO_CLOSE flag is set on the returned BIO.

- -

BIO_new_fp() creates a file BIO wrapping stream. Flags can be: BIO_CLOSE, BIO_NOCLOSE (the close flag) BIO_FP_TEXT (sets the underlying stream to text mode, default is binary: this only has any effect under Win32).

- -

BIO_set_fp() sets the fp of a file BIO to fp. flags has the same meaning as in BIO_new_fp(), it is a macro.

- -

BIO_get_fp() retrieves the fp of a file BIO, it is a macro.

- -

BIO_seek() is a macro that sets the position pointer to offset bytes from the start of file.

- -

BIO_tell() returns the value of the position pointer.

- -

BIO_read_filename(), BIO_write_filename(), BIO_append_filename() and BIO_rw_filename() set the file BIO b to use file name for reading, writing, append or read write respectively.

- -

NOTES

- -

When wrapping stdout, stdin or stderr the underlying stream should not normally be closed so the BIO_NOCLOSE flag should be set.

- -

Because the file BIO calls the underlying stdio functions any quirks in stdio behaviour will be mirrored by the corresponding BIO.

- -

On Windows BIO_new_files reserves for the filename argument to be UTF-8 encoded. In other words if you have to make it work in multi- lingual environment, encode filenames in UTF-8.

- -

RETURN VALUES

- -

BIO_s_file() returns the file BIO method.

- -

BIO_new_file() and BIO_new_fp() return a file BIO or NULL if an error occurred.

- -

BIO_set_fp() and BIO_get_fp() return 1 for success or <=0 for failure (although the current implementation never return 0).

- -

BIO_seek() returns 0 for success or negative values for failure.

- -

BIO_tell() returns the current file position or negative values for failure.

- -

BIO_read_filename(), BIO_write_filename(), BIO_append_filename() and BIO_rw_filename() return 1 for success or <=0 for failure.

- -

EXAMPLES

- -

File BIO "hello world":

- -
BIO *bio_out;
-
-bio_out = BIO_new_fp(stdout, BIO_NOCLOSE);
-BIO_printf(bio_out, "Hello World\n");
- -

Alternative technique:

- -
BIO *bio_out;
-
-bio_out = BIO_new(BIO_s_file());
-if (bio_out == NULL)
-    /* Error */
-if (BIO_set_fp(bio_out, stdout, BIO_NOCLOSE) <= 0)
-    /* Error */
-BIO_printf(bio_out, "Hello World\n");
- -

Write to a file:

- -
BIO *out;
-
-out = BIO_new_file("filename.txt", "w");
-if (!out)
-    /* Error */
-BIO_printf(out, "Hello World\n");
-BIO_free(out);
- -

Alternative technique:

- -
BIO *out;
-
-out = BIO_new(BIO_s_file());
-if (out == NULL)
-    /* Error */
-if (BIO_write_filename(out, "filename.txt") <= 0)
-    /* Error */
-BIO_printf(out, "Hello World\n");
-BIO_free(out);
- -

BUGS

- -

BIO_reset() and BIO_seek() are implemented using fseek() on the underlying stream. The return value for fseek() is 0 for success or -1 if an error occurred this differs from other types of BIO which will typically return 1 for success and a non positive value if an error occurred.

- -

SEE ALSO

- -

BIO_seek(3), BIO_tell(3), BIO_reset(3), BIO_flush(3), BIO_read_ex(3), BIO_write_ex(3), BIO_puts(3), BIO_gets(3), BIO_printf(3), BIO_set_close(3), BIO_get_close(3)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_mem.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_mem.html deleted file mode 100644 index e4124f3a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_mem.html +++ /dev/null @@ -1,162 +0,0 @@ - - - - -BIO_s_mem - - - - - - - - - - -

NAME

- -

BIO_s_secmem, BIO_s_dgram_mem, BIO_s_mem, BIO_set_mem_eof_return, BIO_get_mem_data, BIO_set_mem_buf, BIO_get_mem_ptr, BIO_new_mem_buf - memory BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_mem(void);
-const BIO_METHOD *BIO_s_dgram_mem(void);
-const BIO_METHOD *BIO_s_secmem(void);
-
-BIO_set_mem_eof_return(BIO *b, int v);
-long BIO_get_mem_data(BIO *b, char **pp);
-BIO_set_mem_buf(BIO *b, BUF_MEM *bm, int c);
-BIO_get_mem_ptr(BIO *b, BUF_MEM **pp);
-
-BIO *BIO_new_mem_buf(const void *buf, int len);
- -

DESCRIPTION

- -

BIO_s_mem() returns the memory BIO method function.

- -

A memory BIO is a source/sink BIO which uses memory for its I/O. Data written to a memory BIO is stored in a BUF_MEM structure which is extended as appropriate to accommodate the stored data.

- -

BIO_s_secmem() is like BIO_s_mem() except that the secure heap is used for buffer storage.

- -

BIO_s_dgram_mem() is a memory BIO that respects datagram semantics. A single call to BIO_write(3) will write a single datagram to the memory BIO. A subsequent call to BIO_read(3) will read the data in that datagram. The BIO_read(3) call will never return more data than was written in the original BIO_write(3) call even if there were subsequent BIO_write(3) calls that wrote more datagrams. Each successive call to BIO_read(3) will read the next datagram. If a BIO_read(3) call supplies a read buffer that is smaller than the size of the datagram, then the read buffer will be completely filled and the remaining data from the datagram will be discarded.

- -

It is not possible to write a zero length datagram. Calling BIO_write(3) in this case will return 0 and no datagrams will be written. Calling BIO_read(3) when there are no datagrams in the BIO to read will return a negative result and the "retry" flags will be set (i.e. calling BIO_should_retry(3) will return true). A datagram mem BIO will never return true from BIO_eof(3).

- -

Any data written to a memory BIO can be recalled by reading from it. Unless the memory BIO is read only any data read from it is deleted from the BIO.

- -

Memory BIOs except BIO_s_dgram_mem() support BIO_gets() and BIO_puts().

- -

BIO_s_dgram_mem() supports BIO_sendmmsg(3) and BIO_recvmmsg(3) calls and calls related to BIO_ADDR and MTU handling similarly to the BIO_s_dgram_pair(3).

- -

If the BIO_CLOSE flag is set when a memory BIO is freed then the underlying BUF_MEM structure is also freed.

- -

Calling BIO_reset() on a read write memory BIO clears any data in it if the flag BIO_FLAGS_NONCLEAR_RST is not set, otherwise it just restores the read pointer to the state it was just after the last write was performed and the data can be read again. On a read only BIO it similarly restores the BIO to its original state and the read only data can be read again.

- -

BIO_eof() is true if no data is in the BIO.

- -

BIO_ctrl_pending() returns the number of bytes currently stored.

- -

BIO_set_mem_eof_return() sets the behaviour of memory BIO b when it is empty. If the v is zero then an empty memory BIO will return EOF (that is it will return zero and BIO_should_retry(b) will be false. If v is non zero then it will return v when it is empty and it will set the read retry flag (that is BIO_read_retry(b) is true). To avoid ambiguity with a normal positive return value v should be set to a negative value, typically -1. Calling this macro will fail for datagram mem BIOs.

- -

BIO_get_mem_data() sets *pp to a pointer to the start of the memory BIOs data and returns the total amount of data available. It is implemented as a macro. Note the pointer returned by this call is informative, no transfer of ownership of this memory is implied. See notes on BIO_set_close().

- -

BIO_set_mem_buf() sets the internal BUF_MEM structure to bm and sets the close flag to c, that is c should be either BIO_CLOSE or BIO_NOCLOSE. It is a macro.

- -

BIO_get_mem_ptr() places the underlying BUF_MEM structure in *pp. It is a macro.

- -

BIO_new_mem_buf() creates a memory BIO using len bytes of data at buf, if len is -1 then the buf is assumed to be nul terminated and its length is determined by strlen. The BIO is set to a read only state and as a result cannot be written to. This is useful when some data needs to be made available from a static area of memory in the form of a BIO. The supplied data is read directly from the supplied buffer: it is not copied first, so the supplied area of memory must be unchanged until the BIO is freed.

- -

All of the five functions described above return an error with BIO_s_dgram_mem().

- -

NOTES

- -

Writes to memory BIOs will always succeed if memory is available: that is their size can grow indefinitely. An exception is BIO_s_dgram_mem() when BIO_set_write_buf_size(3) is called on it. In such case the write buffer size will be fixed and any writes that would overflow the buffer will return an error.

- -

Every write after partial read (not all data in the memory buffer was read) to a read write memory BIO will have to move the unread data with an internal copy operation, if a BIO contains a lot of data and it is read in small chunks intertwined with writes the operation can be very slow. Adding a buffering BIO to the chain can speed up the process.

- -

Calling BIO_set_mem_buf() on a secmem or dgram BIO will give undefined results, including perhaps a program crash.

- -

Switching a memory BIO from read write to read only is not supported and can give undefined results including a program crash. There are two notable exceptions to the rule. The first one is to assign a static memory buffer immediately after BIO creation and set the BIO as read only.

- -

The other supported sequence is to start with a read write BIO then temporarily switch it to read only and call BIO_reset() on the read only BIO immediately before switching it back to read write. Before the BIO is freed it must be switched back to the read write mode.

- -

Calling BIO_get_mem_ptr() on read only BIO will return a BUF_MEM that contains only the remaining data to be read. If the close status of the BIO is set to BIO_NOCLOSE, before freeing the BUF_MEM the data pointer in it must be set to NULL as the data pointer does not point to an allocated memory.

- -

Calling BIO_reset() on a read write memory BIO with BIO_FLAGS_NONCLEAR_RST flag set can have unexpected outcome when the reads and writes to the BIO are intertwined. As documented above the BIO will be reset to the state after the last completed write operation. The effects of reads preceding that write operation cannot be undone.

- -

Calling BIO_get_mem_ptr() prior to a BIO_reset() call with BIO_FLAGS_NONCLEAR_RST set has the same effect as a write operation.

- -

Calling BIO_set_close() with BIO_NOCLOSE orphans the BUF_MEM internal to the BIO, _not_ its actual data buffer. See the examples section for the proper method for claiming ownership of the data pointer for a deferred free operation.

- -

RETURN VALUES

- -

BIO_s_mem(), BIO_s_dgram_mem() and BIO_s_secmem() return a valid memory BIO_METHOD structure.

- -

BIO_set_mem_eof_return(), BIO_set_mem_buf() and BIO_get_mem_ptr() return 1 on success or a value which is less than or equal to 0 if an error occurred.

- -

BIO_get_mem_data() returns the total number of bytes available on success, 0 if b is NULL, or a negative value in case of other errors.

- -

BIO_new_mem_buf() returns a valid BIO structure on success or NULL on error.

- -

EXAMPLES

- -

Create a memory BIO and write some data to it:

- -
BIO *mem = BIO_new(BIO_s_mem());
-
-BIO_puts(mem, "Hello World\n");
- -

Create a read only memory BIO:

- -
char data[] = "Hello World";
-BIO *mem = BIO_new_mem_buf(data, -1);
- -

Extract the BUF_MEM structure from a memory BIO and then free up the BIO:

- -
BUF_MEM *bptr;
-
-BIO_get_mem_ptr(mem, &bptr);
-BIO_set_close(mem, BIO_NOCLOSE); /* So BIO_free() leaves BUF_MEM alone */
-BIO_free(mem);
- -

Extract the BUF_MEM ptr, claim ownership of the internal data and free the BIO and BUF_MEM structure:

- -
BUF_MEM *bptr;
-char *data;
-
-BIO_get_mem_data(bio, &data);
-BIO_get_mem_ptr(bio, &bptr);
-BIO_set_close(mem, BIO_NOCLOSE); /* So BIO_free orphans BUF_MEM */
-BIO_free(bio);
-bptr->data = NULL; /* Tell BUF_MEM to orphan data */
-BUF_MEM_free(bptr);
-...
-free(data);
- -

HISTORY

- -

BIO_s_dgram_mem() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_null.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_null.html deleted file mode 100644 index ad30eaa3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_null.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -BIO_s_null - - - - - - - - - - -

NAME

- -

BIO_s_null - null data sink

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_null(void);
- -

DESCRIPTION

- -

BIO_s_null() returns the null sink BIO method. Data written to the null sink is discarded, reads return EOF.

- -

NOTES

- -

A null sink BIO behaves in a similar manner to the Unix /dev/null device.

- -

A null bio can be placed on the end of a chain to discard any data passed through it.

- -

A null sink is useful if, for example, an application wishes to digest some data by writing through a digest bio but not send the digested data anywhere. Since a BIO chain must normally include a source/sink BIO this can be achieved by adding a null sink BIO to the end of the chain

- -

RETURN VALUES

- -

BIO_s_null() returns the null sink BIO method.

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_s_socket.html b/openssl-install/share/doc/openssl/html/man3/BIO_s_socket.html deleted file mode 100644 index 5ee9f1f3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_s_socket.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -BIO_s_socket - - - - - - - - - - -

NAME

- -

BIO_s_socket, BIO_new_socket - socket BIO

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-const BIO_METHOD *BIO_s_socket(void);
-
-BIO *BIO_new_socket(int sock, int close_flag);
- -

DESCRIPTION

- -

BIO_s_socket() returns the socket BIO method. This is a wrapper round the platform's socket routines.

- -

BIO_read_ex() and BIO_write_ex() read or write the underlying socket. BIO_puts() is supported but BIO_gets() is not.

- -

If the close flag is set then the socket is shut down and closed when the BIO is freed.

- -

BIO_new_socket() returns a socket BIO using sock and close_flag.

- -

NOTES

- -

Socket BIOs also support any relevant functionality of file descriptor BIOs.

- -

The reason for having separate file descriptor and socket BIOs is that on some platforms sockets are not file descriptors and use distinct I/O routines, Windows is one such platform. Any code mixing the two will not work on all platforms.

- -

RETURN VALUES

- -

BIO_s_socket() returns the socket BIO method.

- -

BIO_new_socket() returns the newly allocated BIO or NULL is an error occurred.

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_sendmmsg.html b/openssl-install/share/doc/openssl/html/man3/BIO_sendmmsg.html deleted file mode 100644 index 17a886c4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_sendmmsg.html +++ /dev/null @@ -1,168 +0,0 @@ - - - - -BIO_sendmmsg - - - - - - - - - - -

NAME

- -

BIO_sendmmsg, BIO_recvmmsg, BIO_dgram_set_local_addr_enable, BIO_dgram_get_local_addr_enable, BIO_dgram_get_local_addr_cap, BIO_err_is_non_fatal - send and receive multiple datagrams in a single call

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-typedef struct bio_msg_st {
-    void *data;
-    size_t data_len;
-    BIO_ADDR *peer, *local;
-    uint64_t flags;
-} BIO_MSG;
-
-int BIO_sendmmsg(BIO *b, BIO_MSG *msg,
-                 size_t stride, size_t num_msg, uint64_t flags,
-                 size_t *msgs_processed);
-int BIO_recvmmsg(BIO *b, BIO_MSG *msg,
-                 size_t stride, size_t num_msg, uint64_t flags,
-                 size_t *msgs_processed);
-
-int BIO_dgram_set_local_addr_enable(BIO *b, int enable);
-int BIO_dgram_get_local_addr_enable(BIO *b, int *enable);
-int BIO_dgram_get_local_addr_cap(BIO *b);
-int BIO_err_is_non_fatal(unsigned int errcode);
- -

DESCRIPTION

- -

BIO_sendmmsg() and BIO_recvmmsg() functions can be used to send and receive multiple messages in a single call to a BIO. They are analogous to sendmmsg(2) and recvmmsg(2) on operating systems which provide those functions.

- -

The BIO_MSG structure provides a subset of the functionality of the struct msghdr structure defined by POSIX. These functions accept an array of BIO_MSG structures. On any particular invocation, these functions may process all of the passed structures, some of them, or none of them. This is indicated by the value stored in *msgs_processed, which expresses the number of messages processed.

- -

The caller should set the data member of a BIO_MSG to a buffer containing the data to send, or to be filled with a received message. data_len should be set to the size of the buffer in bytes. If the given BIO_MSG is processed (in other words, if the integer returned by the function is greater than or equal to that BIO_MSG's array index), data_len will be modified to specify the actual amount of data sent or received.

- -

The flags field of a BIO_MSG provides input per-message flags to the invocation. If the invocation processes that BIO_MSG, the flags field is written with output per-message flags, or zero if no such flags are applicable.

- -

Currently, no input or output per-message flags are defined and this field should be set to zero before calling BIO_sendmmsg() or BIO_recvmmsg().

- -

The flags argument to BIO_sendmmsg() and BIO_recvmmsg() provides global flags which affect the entire invocation. No global flags are currently defined and this argument should be set to zero.

- -

When these functions are used to send and receive datagrams, the peer field of a BIO_MSG allows the destination address of sent datagrams to be specified on a per-datagram basis, and the source address of received datagrams to be determined. The peer field should be set to point to a BIO_ADDR, which will be read by BIO_sendmmsg() and used as the destination address for sent datagrams, and written by BIO_recvmmsg() with the source address of received datagrams.

- -

Similarly, the local field of a BIO_MSG allows the source address of sent datagrams to be specified on a per-datagram basis, and the destination address of received datagrams to be determined. Unlike peer, support for local must be explicitly enabled on a BIO before it can be used; see BIO_dgram_set_local_addr_enable(). If local is non-NULL in a BIO_MSG and support for local has not been enabled, processing of that BIO_MSG fails.

- -

peer and local should be set to NULL if they are not required. Support for local may not be available on all platforms; on these platforms, these functions always fail if local is non-NULL.

- -

If local is specified and local address support is enabled, but the operating system does not report a local address for a specific received message, the BIO_ADDR it points to will be cleared (address family set to AF_UNSPEC). This is known to happen on Windows when a packet is received which was sent by the local system, regardless of whether the packet's destination address was the loopback address or the IP address of a local non-loopback interface. This is also known to happen on macOS in some circumstances, such as for packets sent before local address support was enabled for a receiving socket. These are OS-specific limitations. As such, users of this API using local address support should expect to sometimes receive a cleared local BIO_ADDR instead of the correct value.

- -

The stride argument must be set to sizeof(BIO_MSG). This argument facilitates backwards compatibility if fields are added to BIO_MSG. Callers must zero-initialize BIO_MSG.

- -

num_msg should be sent to the maximum number of messages to send or receive, which is also the length of the array pointed to by msg.

- -

msgs_processed must be non-NULL and points to an integer written with the number of messages successfully processed; see the RETURN VALUES section for further discussion.

- -

Unlike most BIO functions, these functions explicitly support multi-threaded use. Multiple concurrent writers and multiple concurrent readers of the same BIO are permitted in any combination. As such, these functions do not clear, set, or otherwise modify BIO retry flags. The return value must be used to determine whether an operation should be retried; see below.

- -

The support for concurrent use extends to BIO_sendmmsg() and BIO_recvmmsg() only, and no other function may be called on a given BIO while any call to BIO_sendmmsg() or BIO_recvmmsg() is in progress, or vice versa.

- -

BIO_dgram_set_local_addr_enable() and BIO_dgram_get_local_addr_enable() control whether local address support is enabled. To enable local address support, call BIO_dgram_set_local_addr_enable() with an argument of 1. The call will fail if local address support is not available for the platform. BIO_dgram_get_local_addr_enable() retrieves the value set by BIO_dgram_set_local_addr_enable().

- -

BIO_dgram_get_local_addr_cap() determines if the BIO is capable of supporting local addresses.

- -

BIO_err_is_non_fatal() determines if a packed error code represents an error which is transient in nature.

- -

NOTES

- -

Some implementations of the BIO_sendmmsg() and BIO_recvmmsg() BIO methods might always process at most one message at a time, for example when OS-level functionality to transmit or receive multiple messages at a time is not available.

- -

RETURN VALUES

- -

On success, the functions BIO_sendmmsg() and BIO_recvmmsg() return 1 and write the number of messages successfully processed (which need not be nonzero) to msgs_processed. Where a positive value n is written to msgs_processed, all entries in the BIO_MSG array from 0 through n-1 inclusive have their data_len and flags fields updated with the results of the operation on that message. If the call was to BIO_recvmmsg() and the peer or local fields of that message are non-NULL, the BIO_ADDR structures they point to are written with the relevant address.

- -

On failure, the functions BIO_sendmmsg() and BIO_recvmmsg() return 0 and write zero to msgs_processed. Thus msgs_processed is always written regardless of the outcome of the function call.

- -

If BIO_sendmmsg() and BIO_recvmmsg() fail, they always raise an ERR_LIB_BIO error using ERR_raise(3). Any error may be raised, but the following in particular may be noted:

- -
- -
BIO_R_LOCAL_ADDR_NOT_AVAILABLE
-
- -

The local field was set to a non-NULL value, but local address support is not available or not enabled on the BIO.

- -
-
BIO_R_PEER_ADDR_NOT_AVAILABLE
-
- -

The peer field was set to a non-NULL value, but peer address support is not available on the BIO.

- -
-
BIO_R_UNSUPPORTED_METHOD
-
- -

The BIO_sendmmsg() or BIO_recvmmsg() method is not supported on the BIO.

- -
-
BIO_R_NON_FATAL
-
- -

The call failed due to a transient, non-fatal error (for example, because the BIO is in nonblocking mode and the call would otherwise have blocked).

- -

Implementations of this interface which do not make system calls and thereby pass through system error codes using ERR_LIB_SYS (for example, memory-based implementations) should issue this reason code to indicate a transient failure. However, users of this interface should not test for this reason code directly, as there are multiple possible packed error codes representing a transient failure; use BIO_err_is_non_fatal() instead (discussed below).

- -
-
Socket errors
-
- -

OS-level socket errors are reported using an error with library code ERR_LIB_SYS; for a packed error code errcode where ERR_SYSTEM_ERROR(errcode) == 1, the OS-level socket error code can be retrieved using ERR_GET_REASON(errcode). The packed error code can be retrieved by calling ERR_peek_last_error(3) after the call to BIO_sendmmsg() or BIO_recvmmsg() returns 0.

- -
-
Non-fatal errors
-
- -

Whether an error is transient can be determined by passing the packed error code to BIO_err_is_non_fatal(). Callers should do this instead of testing the reason code directly, as there are many possible error codes which can indicate a transient error, many of which are system specific.

- -
-
- -

Third parties implementing custom BIOs supporting the BIO_sendmmsg() or BIO_recvmmsg() methods should note that it is a required part of the API contract that an error is always raised when either of these functions return 0.

- -

BIO_dgram_set_local_addr_enable() returns 1 if local address support was successfully enabled or disabled and 0 otherwise.

- -

BIO_dgram_get_local_addr_enable() returns 1 if the local address support enable flag was successfully retrieved.

- -

BIO_dgram_get_local_addr_cap() returns 1 if the BIO can support local addresses.

- -

BIO_err_is_non_fatal() returns 1 if the passed packed error code represents an error which is transient in nature.

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_set_callback.html b/openssl-install/share/doc/openssl/html/man3/BIO_set_callback.html deleted file mode 100644 index 942d318c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_set_callback.html +++ /dev/null @@ -1,298 +0,0 @@ - - - - -BIO_set_callback - - - - - - - - - - -

NAME

- -

BIO_set_callback_ex, BIO_get_callback_ex, BIO_set_callback, BIO_get_callback, BIO_set_callback_arg, BIO_get_callback_arg, BIO_debug_callback, BIO_debug_callback_ex, BIO_callback_fn_ex, BIO_callback_fn - BIO callback functions

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-typedef long (*BIO_callback_fn_ex)(BIO *b, int oper, const char *argp,
-                                   size_t len, int argi,
-                                   long argl, int ret, size_t *processed);
-
-void BIO_set_callback_ex(BIO *b, BIO_callback_fn_ex callback);
-BIO_callback_fn_ex BIO_get_callback_ex(const BIO *b);
-
-void BIO_set_callback_arg(BIO *b, char *arg);
-char *BIO_get_callback_arg(const BIO *b);
-
-long BIO_debug_callback_ex(BIO *bio, int oper, const char *argp, size_t len,
-                           int argi, long argl, int ret, size_t *processed);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
typedef long (*BIO_callback_fn)(BIO *b, int oper, const char *argp, int argi,
-                                long argl, long ret);
-void BIO_set_callback(BIO *b, BIO_callback_fn cb);
-BIO_callback_fn BIO_get_callback(const BIO *b);
-long BIO_debug_callback(BIO *bio, int cmd, const char *argp, int argi,
-                        long argl, long ret);
-
-typedef struct bio_mmsg_cb_args_st {
-    BIO_MSG    *msg;
-    size_t      stride, num_msg;
-    uint64_t    flags;
-    size_t     *msgs_processed;
-} BIO_MMSG_CB_ARGS;
- -

DESCRIPTION

- -

BIO_set_callback_ex() and BIO_get_callback_ex() set and retrieve the BIO callback. The callback is called during most high-level BIO operations. It can be used for debugging purposes to trace operations on a BIO or to modify its operation.

- -

BIO_set_callback() and BIO_get_callback() set and retrieve the old format BIO callback. New code should not use these functions, but they are retained for backwards compatibility. Any callback set via BIO_set_callback_ex() will get called in preference to any set by BIO_set_callback().

- -

BIO_set_callback_arg() and BIO_get_callback_arg() are macros which can be used to set and retrieve an argument for use in the callback.

- -

BIO_debug_callback_ex() is a standard debugging callback which prints out information relating to each BIO operation. If the callback argument is set it is interpreted as a BIO to send the information to, otherwise stderr is used. The BIO_debug_callback() function is the deprecated version of the same callback for use with the old callback format BIO_set_callback() function.

- -

BIO_callback_fn_ex is the type of the callback function and BIO_callback_fn is the type of the old format callback function. The meaning of each argument is described below:

- -
- -
b
-
- -

The BIO the callback is attached to is passed in b.

- -
-
oper
-
- -

oper is set to the operation being performed. For some operations the callback is called twice, once before and once after the actual operation, the latter case has oper or'ed with BIO_CB_RETURN.

- -
-
len
-
- -

The length of the data requested to be read or written. This is only useful if oper is BIO_CB_READ, BIO_CB_WRITE or BIO_CB_GETS.

- -
-
argp argi argl
-
- -

The meaning of the arguments argp, argi and argl depends on the value of oper, that is the operation being performed.

- -
-
processed
-
- -

processed is a pointer to a location which will be updated with the amount of data that was actually read or written. Only used for BIO_CB_READ, BIO_CB_WRITE, BIO_CB_GETS and BIO_CB_PUTS.

- -
-
ret
-
- -

ret is the return value that would be returned to the application if no callback were present. The actual value returned is the return value of the callback itself. In the case of callbacks called before the actual BIO operation 1 is placed in ret, if the return value is not positive it will be immediately returned to the application and the BIO operation will not be performed.

- -
-
- -

The callback should normally simply return ret when it has finished processing, unless it specifically wishes to modify the value returned to the application.

- -

CALLBACK OPERATIONS

- -

In the notes below, callback defers to the actual callback function that is called.

- -
- -
BIO_free(b)
-
- -
callback_ex(b, BIO_CB_FREE, NULL, 0, 0, 0L, 1L, NULL)
- -

or

- -
callback(b, BIO_CB_FREE, NULL, 0L, 0L, 1L)
- -

is called before the free operation.

- -
-
BIO_read_ex(b, data, dlen, readbytes)
-
- -
callback_ex(b, BIO_CB_READ, data, dlen, 0, 0L, 1L, NULL)
- -

or

- -
callback(b, BIO_CB_READ, data, dlen, 0L, 1L)
- -

is called before the read and

- -
callback_ex(b, BIO_CB_READ | BIO_CB_RETURN, data, dlen, 0, 0L, retvalue,
-            &readbytes)
- -

or

- -
callback(b, BIO_CB_READ|BIO_CB_RETURN, data, dlen, 0L, retvalue)
- -

after.

- -
-
BIO_write(b, data, dlen, written)
-
- -
callback_ex(b, BIO_CB_WRITE, data, dlen, 0, 0L, 1L, NULL)
- -

or

- -
callback(b, BIO_CB_WRITE, datat, dlen, 0L, 1L)
- -

is called before the write and

- -
callback_ex(b, BIO_CB_WRITE | BIO_CB_RETURN, data, dlen, 0, 0L, retvalue,
-            &written)
- -

or

- -
callback(b, BIO_CB_WRITE|BIO_CB_RETURN, data, dlen, 0L, retvalue)
- -

after.

- -
-
BIO_gets(b, buf, size)
-
- -
callback_ex(b, BIO_CB_GETS, buf, size, 0, 0L, 1, NULL, NULL)
- -

or

- -
callback(b, BIO_CB_GETS, buf, size, 0L, 1L)
- -

is called before the operation and

- -
callback_ex(b, BIO_CB_GETS | BIO_CB_RETURN, buf, size, 0, 0L, retvalue,
-            &readbytes)
- -

or

- -
callback(b, BIO_CB_GETS|BIO_CB_RETURN, buf, size, 0L, retvalue)
- -

after.

- -
-
BIO_puts(b, buf)
-
- -
callback_ex(b, BIO_CB_PUTS, buf, 0, 0, 0L, 1L, NULL);
- -

or

- -
callback(b, BIO_CB_PUTS, buf, 0, 0L, 1L)
- -

is called before the operation and

- -
callback_ex(b, BIO_CB_PUTS | BIO_CB_RETURN, buf, 0, 0, 0L, retvalue, &written)
- -

or

- -
callback(b, BIO_CB_PUTS|BIO_CB_RETURN, buf, 0, 0L, retvalue)
- -

after.

- -
-
BIO_ctrl(BIO *b, int cmd, long larg, void *parg)
-
- -
callback_ex(b, BIO_CB_CTRL, parg, 0, cmd, larg, 1L, NULL)
- -

or

- -
callback(b, BIO_CB_CTRL, parg, cmd, larg, 1L)
- -

is called before the call and

- -
callback_ex(b, BIO_CB_CTRL | BIO_CB_RETURN, parg, 0, cmd, larg, ret, NULL)
- -

or

- -
callback(b, BIO_CB_CTRL|BIO_CB_RETURN, parg, cmd, larg, ret)
- -

after.

- -

Note: cmd == BIO_CTRL_SET_CALLBACK is special, because parg is not the argument of type BIO_info_cb itself. In this case parg is a pointer to the actual call parameter, see BIO_callback_ctrl.

- -
-
BIO_sendmmsg(BIO *b, BIO_MSG *msg, size_t stride, size_t num_msg, uint64_t flags, size_t *msgs_processed)
-
- -
callback_ex(b, BIO_CB_SENDMMSG, args, 0, 0, 0, 1, NULL)
- -

or

- -
callback(b, BIO_CB_SENDMMSG, args, 0, 0, 1)
- -

is called before the call and

- -
callback_ex(b, BIO_CB_SENDMMSG | BIO_CB_RETURN, args, ret, 0, 0, ret, NULL)
- -

or

- -
callback(b, BIO_CB_SENDMMSG | BIO_CB_RETURN, args, ret, 0, 0, ret)
- -

after.

- -

args is a pointer to a BIO_MMSG_CB_ARGS structure containing the arguments passed to BIO_sendmmsg(). ret is the return value of the BIO_sendmmsg() call. The return value of BIO_sendmmsg() is altered to the value returned by the BIO_CB_SENDMMSG | BIO_CB_RETURN call.

- -
-
BIO_recvmmsg(BIO *b, BIO_MSG *msg, size_t stride, size_t num_msg, uint64_t flags, size_t *msgs_processed)
-
- -

See the documentation for BIO_sendmmsg(). BIO_recvmmsg() works identically except that BIO_CB_RECVMMSG is used instead of BIO_CB_SENDMMSG.

- -
-
- -

RETURN VALUES

- -

BIO_get_callback_ex() and BIO_get_callback() return the callback function previously set by a call to BIO_set_callback_ex() and BIO_set_callback() respectively.

- -

BIO_get_callback_arg() returns a char pointer to the value previously set via a call to BIO_set_callback_arg().

- -

BIO_debug_callback() returns 1 or ret if it's called after specific BIO operations.

- -

EXAMPLES

- -

The BIO_debug_callback_ex() function is an example, its source is in crypto/bio/bio_cb.c

- -

HISTORY

- -

The BIO_debug_callback_ex() function was added in OpenSSL 3.0.

- -

BIO_set_callback(), BIO_get_callback(), and BIO_debug_callback() were deprecated in OpenSSL 3.0. Use the non-deprecated _ex functions instead.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_should_retry.html b/openssl-install/share/doc/openssl/html/man3/BIO_should_retry.html deleted file mode 100644 index 851695b5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_should_retry.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -BIO_should_retry - - - - - - - - - - -

NAME

- -

BIO_should_read, BIO_should_write, BIO_should_io_special, BIO_retry_type, BIO_should_retry, BIO_get_retry_BIO, BIO_get_retry_reason, BIO_set_retry_reason - BIO retry functions

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-int BIO_should_read(BIO *b);
-int BIO_should_write(BIO *b);
-int BIO_should_io_special(iBIO *b);
-int BIO_retry_type(BIO *b);
-int BIO_should_retry(BIO *b);
-
-BIO *BIO_get_retry_BIO(BIO *bio, int *reason);
-int BIO_get_retry_reason(BIO *bio);
-void BIO_set_retry_reason(BIO *bio, int reason);
- -

DESCRIPTION

- -

These functions determine why a BIO is not able to read or write data. They will typically be called after a failed BIO_read_ex() or BIO_write_ex() call.

- -

BIO_should_retry() is true if the call that produced this condition should then be retried at a later time.

- -

If BIO_should_retry() is false then the cause is an error condition.

- -

BIO_should_read() is true if the cause of the condition is that the BIO has insufficient data to return. Check for readability and/or retry the last operation.

- -

BIO_should_write() is true if the cause of the condition is that the BIO has pending data to write. Check for writability and/or retry the last operation.

- -

BIO_should_io_special() is true if some "special" condition, that is a reason other than reading or writing is the cause of the condition.

- -

BIO_retry_type() returns a mask of the cause of a retry condition consisting of the values BIO_FLAGS_READ, BIO_FLAGS_WRITE, BIO_FLAGS_IO_SPECIAL though current BIO types will only set one of these.

- -

BIO_get_retry_BIO() determines the precise reason for the special condition, it returns the BIO that caused this condition and if reason is not NULL it contains the reason code. The meaning of the reason code and the action that should be taken depends on the type of BIO that resulted in this condition.

- -

BIO_get_retry_reason() returns the reason for a special condition if passed the relevant BIO, for example as returned by BIO_get_retry_BIO().

- -

BIO_set_retry_reason() sets the retry reason for a special condition for a given BIO. This would usually only be called by BIO implementations.

- -

NOTES

- -

BIO_should_read(), BIO_should_write(), BIO_should_io_special(), BIO_retry_type(), and BIO_should_retry(), are implemented as macros.

- -

If BIO_should_retry() returns false then the precise "error condition" depends on the BIO type that caused it and the return code of the BIO operation. For example if a call to BIO_read_ex() on a socket BIO returns 0 and BIO_should_retry() is false then the cause will be that the connection closed. A similar condition on a file BIO will mean that it has reached EOF. Some BIO types may place additional information on the error queue. For more details see the individual BIO type manual pages.

- -

If the underlying I/O structure is in a blocking mode almost all current BIO types will not request a retry, because the underlying I/O calls will not. If the application knows that the BIO type will never signal a retry then it need not call BIO_should_retry() after a failed BIO I/O call. This is typically done with file BIOs.

- -

SSL BIOs are the only current exception to this rule: they can request a retry even if the underlying I/O structure is blocking, if a handshake occurs during a call to BIO_read(). An application can retry the failed call immediately or avoid this situation by setting SSL_MODE_AUTO_RETRY on the underlying SSL structure.

- -

While an application may retry a failed non blocking call immediately this is likely to be very inefficient because the call will fail repeatedly until data can be processed or is available. An application will normally wait until the necessary condition is satisfied. How this is done depends on the underlying I/O structure.

- -

For example if the cause is ultimately a socket and BIO_should_read() is true then a call to select() may be made to wait until data is available and then retry the BIO operation. By combining the retry conditions of several non blocking BIOs in a single select() call it is possible to service several BIOs in a single thread, though the performance may be poor if SSL BIOs are present because long delays can occur during the initial handshake process.

- -

It is possible for a BIO to block indefinitely if the underlying I/O structure cannot process or return any data. This depends on the behaviour of the platforms I/O functions. This is often not desirable: one solution is to use non blocking I/O and use a timeout on the select() (or equivalent) call.

- -

BUGS

- -

The OpenSSL ASN1 functions cannot gracefully deal with non blocking I/O: that is they cannot retry after a partial read or write. This is usually worked around by only passing the relevant data to ASN1 functions when the entire structure can be read or written.

- -

RETURN VALUES

- -

BIO_should_read(), BIO_should_write(), BIO_should_io_special(), and BIO_should_retry() return either 1 or 0 based on the actual conditions of the BIO.

- -

BIO_retry_type() returns a flag combination presenting the cause of a retry condition or false if there is no retry condition.

- -

BIO_get_retry_BIO() returns a valid BIO structure.

- -

BIO_get_retry_reason() returns the reason for a special condition.

- -

SEE ALSO

- -

bio(7)

- -

HISTORY

- -

The BIO_get_retry_reason() and BIO_set_retry_reason() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BIO_socket_wait.html b/openssl-install/share/doc/openssl/html/man3/BIO_socket_wait.html deleted file mode 100644 index 40c43abb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BIO_socket_wait.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -BIO_socket_wait - - - - - - - - - - -

NAME

- -

BIO_socket_wait, BIO_wait, BIO_do_connect_retry - BIO connection utility functions

- -

SYNOPSIS

- -
#include <openssl/bio.h>
-
-#ifndef OPENSSL_NO_SOCK
-int BIO_socket_wait(int fd, int for_read, time_t max_time);
-#endif
-int BIO_wait(BIO *bio, time_t max_time, unsigned int nap_milliseconds);
-int BIO_do_connect_retry(BIO *bio, int timeout, int nap_milliseconds);
- -

DESCRIPTION

- -

BIO_socket_wait() waits on the socket fd for reading if for_read is not 0, else for writing, at most until max_time. It succeeds immediately if max_time == 0 (which means no timeout given).

- -

BIO_wait() waits at most until max_time on the given (typically socket-based) bio, for reading if bio is supposed to read, else for writing. It is used by BIO_do_connect_retry() and can be used together BIO_read(3). It succeeds immediately if max_time == 0 (which means no timeout given). If sockets are not available it supports polling by succeeding after sleeping at most the given nap_milliseconds in order to avoid a tight busy loop. Via nap_milliseconds the caller determines the polling granularity.

- -

BIO_do_connect_retry() connects via the given bio. It retries BIO_do_connect() as far as needed to reach a definite outcome, i.e., connection succeeded, timeout has been reached, or an error occurred. For nonblocking and potentially even non-socket BIOs it polls every nap_milliseconds and sleeps in between using BIO_wait(). If nap_milliseconds is < 0 then a default value of 100 ms is used. If the timeout parameter is > 0 this indicates the maximum number of seconds to wait until the connection is established or a definite error occurred. A value of 0 enables waiting indefinitely (i.e, no timeout), while a value < 0 means that BIO_do_connect() is tried only once. The function may, directly or indirectly, invoke ERR_clear_error().

- -

RETURN VALUES

- -

BIO_socket_wait(), BIO_wait(), and BIO_do_connect_retry() return -1 on error, 0 on timeout, and 1 on success.

- -

SEE ALSO

- -

BIO_do_connect(3), BIO_read(3)

- -

HISTORY

- -

BIO_socket_wait(), BIO_wait(), and BIO_do_connect_retry() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_BLINDING_new.html b/openssl-install/share/doc/openssl/html/man3/BN_BLINDING_new.html deleted file mode 100644 index f067def5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_BLINDING_new.html +++ /dev/null @@ -1,112 +0,0 @@ - - - - -BN_BLINDING_new - - - - - - - - - - -

NAME

- -

BN_BLINDING_new, BN_BLINDING_free, BN_BLINDING_update, BN_BLINDING_convert, BN_BLINDING_invert, BN_BLINDING_convert_ex, BN_BLINDING_invert_ex, BN_BLINDING_is_current_thread, BN_BLINDING_set_current_thread, BN_BLINDING_lock, BN_BLINDING_unlock, BN_BLINDING_get_flags, BN_BLINDING_set_flags, BN_BLINDING_create_param - blinding related BIGNUM functions

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-BN_BLINDING *BN_BLINDING_new(const BIGNUM *A, const BIGNUM *Ai,
-                             BIGNUM *mod);
-void BN_BLINDING_free(BN_BLINDING *b);
-int BN_BLINDING_update(BN_BLINDING *b, BN_CTX *ctx);
-int BN_BLINDING_convert(BIGNUM *n, BN_BLINDING *b, BN_CTX *ctx);
-int BN_BLINDING_invert(BIGNUM *n, BN_BLINDING *b, BN_CTX *ctx);
-int BN_BLINDING_convert_ex(BIGNUM *n, BIGNUM *r, BN_BLINDING *b,
-                           BN_CTX *ctx);
-int BN_BLINDING_invert_ex(BIGNUM *n, const BIGNUM *r, BN_BLINDING *b,
-                          BN_CTX *ctx);
-int BN_BLINDING_is_current_thread(BN_BLINDING *b);
-void BN_BLINDING_set_current_thread(BN_BLINDING *b);
-int BN_BLINDING_lock(BN_BLINDING *b);
-int BN_BLINDING_unlock(BN_BLINDING *b);
-unsigned long BN_BLINDING_get_flags(const BN_BLINDING *b);
-void BN_BLINDING_set_flags(BN_BLINDING *b, unsigned long flags);
-BN_BLINDING *BN_BLINDING_create_param(BN_BLINDING *b,
-                                      const BIGNUM *e, BIGNUM *m, BN_CTX *ctx,
-                                      int (*bn_mod_exp)(BIGNUM *r,
-                                                        const BIGNUM *a,
-                                                        const BIGNUM *p,
-                                                        const BIGNUM *m,
-                                                        BN_CTX *ctx,
-                                                        BN_MONT_CTX *m_ctx),
-                                      BN_MONT_CTX *m_ctx);
- -

DESCRIPTION

- -

BN_BLINDING_new() allocates a new BN_BLINDING structure and copies the A and Ai values into the newly created BN_BLINDING object.

- -

BN_BLINDING_free() frees the BN_BLINDING structure. If b is NULL, nothing is done.

- -

BN_BLINDING_update() updates the BN_BLINDING parameters by squaring the A and Ai or, after specific number of uses and if the necessary parameters are set, by re-creating the blinding parameters.

- -

BN_BLINDING_convert_ex() multiplies n with the blinding factor A. If r is not NULL a copy the inverse blinding factor Ai will be returned in r (this is useful if a RSA object is shared among several threads). BN_BLINDING_invert_ex() multiplies n with the inverse blinding factor Ai. If r is not NULL it will be used as the inverse blinding.

- -

BN_BLINDING_convert() and BN_BLINDING_invert() are wrapper functions for BN_BLINDING_convert_ex() and BN_BLINDING_invert_ex() with r set to NULL.

- -

BN_BLINDING_is_current_thread() returns whether the BN_BLINDING structure is owned by the current thread. This is to help users provide proper locking if needed for multi-threaded use.

- -

BN_BLINDING_set_current_thread() sets the current thread as the owner of the BN_BLINDING structure.

- -

BN_BLINDING_lock() locks the BN_BLINDING structure.

- -

BN_BLINDING_unlock() unlocks the BN_BLINDING structure.

- -

BN_BLINDING_get_flags() returns the BN_BLINDING flags. Currently there are two supported flags: BN_BLINDING_NO_UPDATE and BN_BLINDING_NO_RECREATE. BN_BLINDING_NO_UPDATE inhibits the automatic update of the BN_BLINDING parameters after each use and BN_BLINDING_NO_RECREATE inhibits the automatic re-creation of the BN_BLINDING parameters after a fixed number of uses (currently 32). In newly allocated BN_BLINDING objects no flags are set. BN_BLINDING_set_flags() sets the BN_BLINDING parameters flags.

- -

BN_BLINDING_create_param() creates new BN_BLINDING parameters using the exponent e and the modulus m. bn_mod_exp and m_ctx can be used to pass special functions for exponentiation (normally BN_mod_exp_mont() and BN_MONT_CTX).

- -

RETURN VALUES

- -

BN_BLINDING_new() returns the newly allocated BN_BLINDING structure or NULL in case of an error.

- -

BN_BLINDING_update(), BN_BLINDING_convert(), BN_BLINDING_invert(), BN_BLINDING_convert_ex() and BN_BLINDING_invert_ex() return 1 on success and 0 if an error occurred.

- -

BN_BLINDING_is_current_thread() returns 1 if the current thread owns the BN_BLINDING object, 0 otherwise.

- -

BN_BLINDING_set_current_thread() doesn't return anything.

- -

BN_BLINDING_lock(), BN_BLINDING_unlock() return 1 if the operation succeeded or 0 on error.

- -

BN_BLINDING_get_flags() returns the currently set BN_BLINDING flags (a unsigned long value).

- -

BN_BLINDING_create_param() returns the newly created BN_BLINDING parameters or NULL on error.

- -

HISTORY

- -

BN_BLINDING_thread_id() was first introduced in OpenSSL 1.0.0, and it deprecates BN_BLINDING_set_thread_id() and BN_BLINDING_get_thread_id().

- -

COPYRIGHT

- -

Copyright 2005-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/BN_CTX_new.html deleted file mode 100644 index ac62b5f1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_CTX_new.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -BN_CTX_new - - - - - - - - - - -

NAME

- -

BN_CTX_new_ex, BN_CTX_new, BN_CTX_secure_new_ex, BN_CTX_secure_new, BN_CTX_free - allocate and free BN_CTX structures

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-BN_CTX *BN_CTX_new_ex(OSSL_LIB_CTX *ctx);
-BN_CTX *BN_CTX_new(void);
-
-BN_CTX *BN_CTX_secure_new_ex(OSSL_LIB_CTX *ctx);
-BN_CTX *BN_CTX_secure_new(void);
-
-void BN_CTX_free(BN_CTX *c);
- -

DESCRIPTION

- -

A BN_CTX is a structure that holds BIGNUM temporary variables used by library functions. Since dynamic memory allocation to create BIGNUMs is rather expensive when used in conjunction with repeated subroutine calls, the BN_CTX structure is used.

- -

BN_CTX_new_ex() allocates and initializes a BN_CTX structure for the given library context ctx. The <ctx> value may be NULL in which case the default library context will be used. BN_CTX_new() is the same as BN_CTX_new_ex() except that the default library context is always used.

- -

BN_CTX_secure_new_ex() allocates and initializes a BN_CTX structure but uses the secure heap (see CRYPTO_secure_malloc(3)) to hold the BIGNUMs for the given library context ctx. The <ctx> value may be NULL in which case the default library context will be used. BN_CTX_secure_new() is the same as BN_CTX_secure_new_ex() except that the default library context is always used.

- -

BN_CTX_free() frees the components of the BN_CTX and the structure itself. Since BN_CTX_start() is required in order to obtain BIGNUMs from the BN_CTX, in most cases BN_CTX_end() must be called before the BN_CTX may be freed by BN_CTX_free(). If c is NULL, nothing is done.

- -

A given BN_CTX must only be used by a single thread of execution. No locking is performed, and the internal pool allocator will not properly handle multiple threads of execution.

- -

RETURN VALUES

- -

BN_CTX_new() and BN_CTX_secure_new() return a pointer to the BN_CTX. If the allocation fails, they return NULL and sets an error code that can be obtained by ERR_get_error(3).

- -

BN_CTX_free() has no return values.

- -

REMOVED FUNCTIONALITY

- -
void BN_CTX_init(BN_CTX *c);
- -

BN_CTX_init() is no longer available as of OpenSSL 1.1.0. Applications should replace use of BN_CTX_init with BN_CTX_new instead:

- -
BN_CTX *ctx;
-ctx = BN_CTX_new();
-if (!ctx)
-    /* error */
-...
-BN_CTX_free(ctx);
- -

SEE ALSO

- -

ERR_get_error(3), BN_add(3), BN_CTX_start(3)

- -

HISTORY

- -

BN_CTX_init() was removed in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_CTX_start.html b/openssl-install/share/doc/openssl/html/man3/BN_CTX_start.html deleted file mode 100644 index 52791e75..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_CTX_start.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -BN_CTX_start - - - - - - - - - - -

NAME

- -

BN_CTX_start, BN_CTX_get, BN_CTX_end - use temporary BIGNUM variables

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-void BN_CTX_start(BN_CTX *ctx);
-
-BIGNUM *BN_CTX_get(BN_CTX *ctx);
-
-void BN_CTX_end(BN_CTX *ctx);
- -

DESCRIPTION

- -

These functions are used to obtain temporary BIGNUM variables from a BN_CTX (which can been created by using BN_CTX_new(3)) in order to save the overhead of repeatedly creating and freeing BIGNUMs in functions that are called from inside a loop.

- -

A function must call BN_CTX_start() first. Then, BN_CTX_get() may be called repeatedly to obtain temporary BIGNUMs. All BN_CTX_get() calls must be made before calling any other functions that use the ctx as an argument.

- -

Finally, BN_CTX_end() must be called before returning from the function. If ctx is NULL, nothing is done. When BN_CTX_end() is called, the BIGNUM pointers obtained from BN_CTX_get() become invalid.

- -

RETURN VALUES

- -

BN_CTX_start() and BN_CTX_end() return no values.

- -

BN_CTX_get() returns a pointer to the BIGNUM, or NULL on error. Once BN_CTX_get() has failed, the subsequent calls will return NULL as well, so it is sufficient to check the return value of the last BN_CTX_get() call. In case of an error, an error code is set, which can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

BN_CTX_new(3)

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_add.html b/openssl-install/share/doc/openssl/html/man3/BN_add.html deleted file mode 100644 index 0d818e4a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_add.html +++ /dev/null @@ -1,128 +0,0 @@ - - - - -BN_add - - - - - - - - - - -

NAME

- -

BN_add, BN_sub, BN_mul, BN_sqr, BN_div, BN_mod, BN_nnmod, BN_mod_add, BN_mod_sub, BN_mod_mul, BN_mod_sqr, BN_mod_sqrt, BN_exp, BN_mod_exp, BN_gcd - arithmetic operations on BIGNUMs

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b);
-
-int BN_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b);
-
-int BN_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx);
-
-int BN_sqr(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx);
-
-int BN_div(BIGNUM *dv, BIGNUM *rem, const BIGNUM *a, const BIGNUM *d,
-           BN_CTX *ctx);
-
-int BN_mod(BIGNUM *rem, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx);
-
-int BN_nnmod(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx);
-
-int BN_mod_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m,
-               BN_CTX *ctx);
-
-int BN_mod_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m,
-               BN_CTX *ctx);
-
-int BN_mod_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m,
-               BN_CTX *ctx);
-
-int BN_mod_sqr(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx);
-
-BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);
-
-int BN_exp(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx);
-
-int BN_mod_exp(BIGNUM *r, const BIGNUM *a, const BIGNUM *p,
-               const BIGNUM *m, BN_CTX *ctx);
-
-int BN_gcd(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx);
- -

DESCRIPTION

- -

BN_add() adds a and b and places the result in r (r=a+b). r may be the same BIGNUM as a or b.

- -

BN_sub() subtracts b from a and places the result in r (r=a-b). r may be the same BIGNUM as a or b.

- -

BN_mul() multiplies a and b and places the result in r (r=a*b). r may be the same BIGNUM as a or b. For multiplication by powers of 2, use BN_lshift(3).

- -

BN_sqr() takes the square of a and places the result in r (r=a^2). r and a may be the same BIGNUM. This function is faster than BN_mul(r,a,a).

- -

BN_div() divides a by d and places the result in dv and the remainder in rem (dv=a/d, rem=a%d). Either of dv and rem may be NULL, in which case the respective value is not returned. The result is rounded towards zero; thus if a is negative, the remainder will be zero or negative. For division by powers of 2, use BN_rshift(3).

- -

BN_mod() corresponds to BN_div() with dv set to NULL.

- -

BN_nnmod() reduces a modulo m and places the nonnegative remainder in r.

- -

BN_mod_add() adds a to b modulo m and places the nonnegative result in r.

- -

BN_mod_sub() subtracts b from a modulo m and places the nonnegative result in r.

- -

BN_mod_mul() multiplies a by b and finds the nonnegative remainder respective to modulus m (r=(a*b) mod m). r may be the same BIGNUM as a or b. For more efficient algorithms for repeated computations using the same modulus, see BN_mod_mul_montgomery(3) and BN_mod_mul_reciprocal(3).

- -

BN_mod_sqr() takes the square of a modulo m and places the result in r.

- -

BN_mod_sqrt() returns the modular square root of a such that in^2 = a (mod p). The modulus p must be a prime, otherwise an error or an incorrect "result" will be returned. The result is stored into in which can be NULL. The result will be newly allocated in that case.

- -

BN_exp() raises a to the p-th power and places the result in r (r=a^p). This function is faster than repeated applications of BN_mul().

- -

BN_mod_exp() computes a to the p-th power modulo m (r=a^p % m). This function uses less time and space than BN_exp(). Do not call this function when m is even and any of the parameters have the BN_FLG_CONSTTIME flag set.

- -

BN_gcd() computes the greatest common divisor of a and b and places the result in r. r may be the same BIGNUM as a or b.

- -

For all functions, ctx is a previously allocated BN_CTX used for temporary variables; see BN_CTX_new(3).

- -

Unless noted otherwise, the result BIGNUM must be different from the arguments.

- -

NOTES

- -

For modular operations such as BN_nnmod() or BN_mod_exp() it is an error to use the same BIGNUM object for the modulus as for the output.

- -

RETURN VALUES

- -

The BN_mod_sqrt() returns the result (possibly incorrect if p is not a prime), or NULL.

- -

For all remaining functions, 1 is returned for success, 0 on error. The return value should always be checked (e.g., if (!BN_add(r,a,b)) goto err;). The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), BN_CTX_new(3), BN_add_word(3), BN_set_bit(3)

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_add_word.html b/openssl-install/share/doc/openssl/html/man3/BN_add_word.html deleted file mode 100644 index 32bf5b09..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_add_word.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -BN_add_word - - - - - - - - - - -

NAME

- -

BN_add_word, BN_sub_word, BN_mul_word, BN_div_word, BN_mod_word - arithmetic functions on BIGNUMs with integers

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_add_word(BIGNUM *a, BN_ULONG w);
-
-int BN_sub_word(BIGNUM *a, BN_ULONG w);
-
-int BN_mul_word(BIGNUM *a, BN_ULONG w);
-
-BN_ULONG BN_div_word(BIGNUM *a, BN_ULONG w);
-
-BN_ULONG BN_mod_word(const BIGNUM *a, BN_ULONG w);
- -

DESCRIPTION

- -

These functions perform arithmetic operations on BIGNUMs with unsigned integers. They are much more efficient than the normal BIGNUM arithmetic operations.

- -

BN_add_word() adds w to a (a+=w).

- -

BN_sub_word() subtracts w from a (a-=w).

- -

BN_mul_word() multiplies a and w (a*=w).

- -

BN_div_word() divides a by w (a/=w) and returns the remainder.

- -

BN_mod_word() returns the remainder of a divided by w (a%w).

- -

For BN_div_word() and BN_mod_word(), w must not be 0.

- -

RETURN VALUES

- -

BN_add_word(), BN_sub_word() and BN_mul_word() return 1 for success, 0 on error. The error codes can be obtained by ERR_get_error(3).

- -

BN_mod_word() and BN_div_word() return a%w on success and (BN_ULONG)-1 if an error occurred.

- -

SEE ALSO

- -

ERR_get_error(3), BN_add(3)

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_bn2bin.html b/openssl-install/share/doc/openssl/html/man3/BN_bn2bin.html deleted file mode 100644 index c58c6a2b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_bn2bin.html +++ /dev/null @@ -1,120 +0,0 @@ - - - - -BN_bn2bin - - - - - - - - - - -

NAME

- -

BN_bn2binpad, BN_signed_bn2bin, BN_bn2bin, BN_bin2bn, BN_signed_bin2bn, BN_bn2lebinpad, BN_signed_bn2lebin, BN_lebin2bn, BN_signed_lebin2bn, BN_bn2nativepad, BN_signed_bn2native, BN_native2bn, BN_signed_native2bn, BN_bn2hex, BN_bn2dec, BN_hex2bn, BN_dec2bn, BN_print, BN_print_fp, BN_bn2mpi, BN_mpi2bn - format conversions

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_bn2bin(const BIGNUM *a, unsigned char *to);
-int BN_bn2binpad(const BIGNUM *a, unsigned char *to, int tolen);
-int BN_signed_bn2bin(const BIGNUM *a, unsigned char *to, int tolen);
-BIGNUM *BN_bin2bn(const unsigned char *s, int len, BIGNUM *ret);
-BIGNUM *BN_signed_bin2bn(const unsigned char *s, int len, BIGNUM *ret);
-
-int BN_bn2lebinpad(const BIGNUM *a, unsigned char *to, int tolen);
-int BN_signed_bn2lebin(const BIGNUM *a, unsigned char *to, int tolen);
-BIGNUM *BN_lebin2bn(const unsigned char *s, int len, BIGNUM *ret);
-BIGNUM *BN_signed_lebin2bn(const unsigned char *s, int len, BIGNUM *ret);
-
-int BN_bn2nativepad(const BIGNUM *a, unsigned char *to, int tolen);
-int BN_signed_bn2native(const BIGNUM *a, unsigned char *to, int tolen);
-BIGNUM *BN_native2bn(const unsigned char *s, int len, BIGNUM *ret);
-BIGNUM *BN_signed_native2bn(const unsigned char *s, int len, BIGNUM *ret);
-
-char *BN_bn2hex(const BIGNUM *a);
-char *BN_bn2dec(const BIGNUM *a);
-int BN_hex2bn(BIGNUM **a, const char *str);
-int BN_dec2bn(BIGNUM **a, const char *str);
-
-int BN_print(BIO *fp, const BIGNUM *a);
-int BN_print_fp(FILE *fp, const BIGNUM *a);
-
-int BN_bn2mpi(const BIGNUM *a, unsigned char *to);
-BIGNUM *BN_mpi2bn(unsigned char *s, int len, BIGNUM *ret);
- -

DESCRIPTION

- -

BN_bn2bin() converts the absolute value of a into big-endian form and stores it at to. to must point to BN_num_bytes(a) bytes of memory.

- -

BN_bn2binpad() also converts the absolute value of a into big-endian form and stores it at to. tolen indicates the length of the output buffer to. The result is padded with zeros if necessary. If tolen is less than BN_num_bytes(a) an error is returned.

- -

BN_signed_bn2bin() converts the value of a into big-endian signed 2's complements form and stores it at to. tolen indicates the length of the output buffer to. The result is signed extended (padded with 0x00 for positive numbers or with 0xff for negative numbers) if necessary. If tolen is smaller than the necessary size (which may be <BN_num_bytes(a) + 1>), an error is returned.

- -

BN_bin2bn() converts the positive integer in big-endian form of length len at s into a BIGNUM and places it in ret. If ret is NULL, a new BIGNUM is created.

- -

BN_signed_bin2bn() converts the integer in big-endian signed 2's complement form of length len at s into a BIGNUM and places it in ret. If ret is NULL, a new BIGNUM is created.

- -

BN_bn2lebinpad(), BN_signed_bn2lebin() and BN_lebin2bn() are identical to BN_bn2binpad(), BN_signed_bn2bin() and BN_bin2bn() except the buffer is in little-endian format.

- -

BN_bn2nativepad(), BN_signed_bn2native() and BN_native2bn() are identical to BN_bn2binpad(), BN_signed_bn2bin() and BN_bin2bn() except the buffer is in native format, i.e. most significant byte first on big-endian platforms, and least significant byte first on little-endian platforms.

- -

BN_bn2hex() and BN_bn2dec() return printable strings containing the hexadecimal and decimal encoding of a respectively. For negative numbers, the string is prefaced with a leading '-'. The string must be freed later using OPENSSL_free().

- -

BN_hex2bn() takes as many characters as possible from the string str, including the leading character '-' which means negative, to form a valid hexadecimal number representation and converts them to a BIGNUM and stores it in **a. If *a is NULL, a new BIGNUM is created. If a is NULL, it only computes the length of valid representation. A "negative zero" is converted to zero. BN_dec2bn() is the same using the decimal system.

- -

BN_print() and BN_print_fp() write the hexadecimal encoding of a, with a leading '-' for negative numbers, to the BIO or FILE fp.

- -

BN_bn2mpi() and BN_mpi2bn() convert BIGNUMs from and to a format that consists of the number's length in bytes represented as a 4-byte big-endian number, and the number itself in big-endian format, where the most significant bit signals a negative number (the representation of numbers with the MSB set is prefixed with null byte).

- -

BN_bn2mpi() stores the representation of a at to, where to must be large enough to hold the result. The size can be determined by calling BN_bn2mpi(a, NULL).

- -

BN_mpi2bn() converts the len bytes long representation at s to a BIGNUM and stores it at ret, or in a newly allocated BIGNUM if ret is NULL.

- -

RETURN VALUES

- -

BN_bn2bin() returns the length of the big-endian number placed at to. BN_bin2bn() returns the BIGNUM, NULL on error.

- -

BN_bn2binpad(), BN_signed_bn2bin(), BN_bn2lebinpad(), BN_signed_bn2lebin(), BN_bn2nativepad(), and_signed BN_bn2native() return the number of bytes written or -1 if the supplied buffer is too small.

- -

BN_bn2hex() and BN_bn2dec() return a NUL-terminated string, or NULL on error. BN_hex2bn() and BN_dec2bn() return the number of characters used in parsing, or 0 on error, in which case no new BIGNUM will be created.

- -

BN_print_fp() and BN_print() return 1 on success, 0 on write errors.

- -

BN_bn2mpi() returns the length of the representation. BN_mpi2bn() returns the BIGNUM, and NULL on error.

- -

The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), BN_zero(3), ASN1_INTEGER_to_BN(3), BN_num_bytes(3)

- -

HISTORY

- -

The functions BN_signed_bin2bn(), BN_signed_bn2bin(), BN_signed_lebin2bn(), BN_signed_bn2lebin(), BN_signed_native2bn(), BN_signed_bn2native() were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_cmp.html b/openssl-install/share/doc/openssl/html/man3/BN_cmp.html deleted file mode 100644 index d37d6980..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_cmp.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -BN_cmp - - - - - - - - - - -

NAME

- -

BN_cmp, BN_ucmp, BN_is_zero, BN_is_one, BN_is_word, BN_abs_is_word, BN_is_odd, BN_are_coprime - BIGNUM comparison and test functions

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_cmp(const BIGNUM *a, const BIGNUM *b);
-int BN_ucmp(const BIGNUM *a, const BIGNUM *b);
-
-int BN_is_zero(const BIGNUM *a);
-int BN_is_one(const BIGNUM *a);
-int BN_is_word(const BIGNUM *a, const BN_ULONG w);
-int BN_abs_is_word(const BIGNUM *a, const BN_ULONG w);
-int BN_is_odd(const BIGNUM *a);
-
-int BN_are_coprime(BIGNUM *a, const BIGNUM *b, BN_CTX *ctx);
- -

DESCRIPTION

- -

BN_cmp() compares the numbers a and b. BN_ucmp() compares their absolute values.

- -

BN_is_zero(), BN_is_one(), BN_is_word() and BN_abs_is_word() test if a equals 0, 1, w, or |w| respectively. BN_is_odd() tests if a is odd.

- -

BN_are_coprime() determines if a and b are coprime. ctx is used internally for storing temporary variables. The values of a and b and ctx must not be NULL.

- -

RETURN VALUES

- -

BN_cmp() returns -1 if a < b, 0 if a == b and 1 if a > b. BN_ucmp() is the same using the absolute values of a and b.

- -

BN_is_zero(), BN_is_one() BN_is_word(), BN_abs_is_word() and BN_is_odd() return 1 if the condition is true, 0 otherwise.

- -

BN_are_coprime() returns 1 if the BIGNUM's are coprime, otherwise it returns 0.

- -

HISTORY

- -

Prior to OpenSSL 1.1.0, BN_is_zero(), BN_is_one(), BN_is_word(), BN_abs_is_word() and BN_is_odd() were macros.

- -

The function BN_are_coprime() was added in OpenSSL 3.1.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_copy.html b/openssl-install/share/doc/openssl/html/man3/BN_copy.html deleted file mode 100644 index 182e3909..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_copy.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -BN_copy - - - - - - - - - - -

NAME

- -

BN_copy, BN_dup, BN_with_flags - copy BIGNUMs

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-BIGNUM *BN_copy(BIGNUM *to, const BIGNUM *from);
-
-BIGNUM *BN_dup(const BIGNUM *from);
-
-void BN_with_flags(BIGNUM *dest, const BIGNUM *b, int flags);
- -

DESCRIPTION

- -

BN_copy() copies from to to. BN_dup() creates a new BIGNUM containing the value from.

- -

BN_with_flags creates a temporary shallow copy of b in dest. It places significant restrictions on the copied data. Applications that do no adhere to these restrictions may encounter unexpected side effects or crashes. For that reason use of this function is discouraged. Any flags provided in flags will be set in dest in addition to any flags already set in b. For example this might commonly be used to create a temporary copy of a BIGNUM with the BN_FLG_CONSTTIME flag set for constant time operations. The temporary copy in dest will share some internal state with b. For this reason the following restrictions apply to the use of dest:

- - - -

RETURN VALUES

- -

BN_copy() returns to on success, NULL on error. BN_dup() returns the new BIGNUM, and NULL on error. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_generate_prime.html b/openssl-install/share/doc/openssl/html/man3/BN_generate_prime.html deleted file mode 100644 index c1ebbf0e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_generate_prime.html +++ /dev/null @@ -1,200 +0,0 @@ - - - - -BN_generate_prime - - - - - - - - - - -

NAME

- -

BN_generate_prime_ex2, BN_generate_prime_ex, BN_is_prime_ex, BN_check_prime, BN_is_prime_fasttest_ex, BN_GENCB_call, BN_GENCB_new, BN_GENCB_free, BN_GENCB_set_old, BN_GENCB_set, BN_GENCB_get_arg, BN_generate_prime, BN_is_prime, BN_is_prime_fasttest - generate primes and test for primality

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_generate_prime_ex2(BIGNUM *ret, int bits, int safe,
-                          const BIGNUM *add, const BIGNUM *rem, BN_GENCB *cb,
-                          BN_CTX *ctx);
-
-int BN_generate_prime_ex(BIGNUM *ret, int bits, int safe, const BIGNUM *add,
-                         const BIGNUM *rem, BN_GENCB *cb);
-
-int BN_check_prime(const BIGNUM *p, BN_CTX *ctx, BN_GENCB *cb);
-
-int BN_GENCB_call(BN_GENCB *cb, int a, int b);
-
-BN_GENCB *BN_GENCB_new(void);
-
-void BN_GENCB_free(BN_GENCB *cb);
-
-void BN_GENCB_set_old(BN_GENCB *gencb,
-                      void (*callback)(int, int, void *), void *cb_arg);
-
-void BN_GENCB_set(BN_GENCB *gencb,
-                  int (*callback)(int, int, BN_GENCB *), void *cb_arg);
-
-void *BN_GENCB_get_arg(BN_GENCB *cb);
- -

The following functions have been deprecated since OpenSSL 0.9.8, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
BIGNUM *BN_generate_prime(BIGNUM *ret, int num, int safe, BIGNUM *add,
-                          BIGNUM *rem, void (*callback)(int, int, void *),
-                          void *cb_arg);
-
-int BN_is_prime(const BIGNUM *p, int nchecks,
-                void (*callback)(int, int, void *), BN_CTX *ctx, void *cb_arg);
-
-int BN_is_prime_fasttest(const BIGNUM *p, int nchecks,
-                         void (*callback)(int, int, void *), BN_CTX *ctx,
-                         void *cb_arg, int do_trial_division);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int BN_is_prime_ex(const BIGNUM *p, int nchecks, BN_CTX *ctx, BN_GENCB *cb);
-
-int BN_is_prime_fasttest_ex(const BIGNUM *p, int nchecks, BN_CTX *ctx,
-                            int do_trial_division, BN_GENCB *cb);
- -

DESCRIPTION

- -

BN_generate_prime_ex2() generates a pseudo-random prime number of at least bit length bits using the BN_CTX provided in ctx. The value of ctx must not be NULL.

- -

The returned number is probably prime with a negligible error. The maximum error rate is 2^-128. It's 2^-287 for a 512 bit prime, 2^-435 for a 1024 bit prime, 2^-648 for a 2048 bit prime, and lower than 2^-882 for primes larger than 2048 bit.

- -

If add is NULL the returned prime number will have exact bit length bits with the top most two bits set.

- -

If ret is not NULL, it will be used to store the number.

- -

If cb is not NULL, it is used as follows:

- - - -

The prime may have to fulfill additional requirements for use in Diffie-Hellman key exchange:

- -

If add is not NULL, the prime will fulfill the condition p % add == rem (p % add == 1 if rem == NULL) in order to suit a given generator.

- -

If safe is true, it will be a safe prime (i.e. a prime p so that (p-1)/2 is also prime). If safe is true, and rem == NULL the condition will be p % add == 3. It is recommended that add is a multiple of 4.

- -

The random generator must be seeded prior to calling BN_generate_prime_ex(). If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail. The random number generator configured for the OSSL_LIB_CTX associated with ctx will be used.

- -

BN_generate_prime_ex() is the same as BN_generate_prime_ex2() except that no ctx parameter is passed. In this case the random number generator associated with the default OSSL_LIB_CTX will be used.

- -

BN_check_prime(), BN_is_prime_ex(), BN_is_prime_fasttest_ex(), BN_is_prime() and BN_is_prime_fasttest() test if the number p is prime. The functions tests until one of the tests shows that p is composite, or all the tests passed. If p passes all these tests, it is considered a probable prime.

- -

The test performed on p are trial division by a number of small primes and rounds of the of the Miller-Rabin probabilistic primality test.

- -

The functions do at least 64 rounds of the Miller-Rabin test giving a maximum false positive rate of 2^-128. If the size of p is more than 2048 bits, they do at least 128 rounds giving a maximum false positive rate of 2^-256.

- -

If nchecks is larger than the minimum above (64 or 128), nchecks rounds of the Miller-Rabin test will be done.

- -

If do_trial_division set to 0, the trial division will be skipped. BN_is_prime_ex() and BN_is_prime() always skip the trial division.

- -

BN_is_prime_ex(), BN_is_prime_fasttest_ex(), BN_is_prime() and BN_is_prime_fasttest() are deprecated.

- -

BN_is_prime_fasttest() and BN_is_prime() behave just like BN_is_prime_fasttest_ex() and BN_is_prime_ex() respectively, but with the old style call back.

- -

ctx is a preallocated BN_CTX (to save the overhead of allocating and freeing the structure in a loop), or NULL.

- -

If the trial division is done, and no divisors are found and cb is not NULL, BN_GENCB_call(cb, 1, -1) is called.

- -

After each round of the Miller-Rabin probabilistic primality test, if cb is not NULL, BN_GENCB_call(cb, 1, j) is called with j the iteration (j = 0, 1, ...).

- -

BN_GENCB_call() calls the callback function held in the BN_GENCB structure and passes the ints a and b as arguments. There are two types of BN_GENCB structure that are supported: "new" style and "old" style. New programs should prefer the "new" style, whilst the "old" style is provided for backwards compatibility purposes.

- -

A BN_GENCB structure should be created through a call to BN_GENCB_new(), and freed through a call to BN_GENCB_free(). If the argument is NULL, nothing is done.

- -

For "new" style callbacks a BN_GENCB structure should be initialised with a call to BN_GENCB_set(), where gencb is a BN_GENCB *, callback is of type int (*callback)(int, int, BN_GENCB *) and cb_arg is a void *. "Old" style callbacks are the same except they are initialised with a call to BN_GENCB_set_old() and callback is of type void (*callback)(int, int, void *).

- -

A callback is invoked through a call to BN_GENCB_call. This will check the type of the callback and will invoke callback(a, b, gencb) for new style callbacks or callback(a, b, cb_arg) for old style.

- -

It is possible to obtain the argument associated with a BN_GENCB structure (set via a call to BN_GENCB_set or BN_GENCB_set_old) using BN_GENCB_get_arg.

- -

BN_generate_prime() (deprecated) works in the same way as BN_generate_prime_ex() but expects an old-style callback function directly in the callback parameter, and an argument to pass to it in the cb_arg. BN_is_prime() and BN_is_prime_fasttest() can similarly be compared to BN_is_prime_ex() and BN_is_prime_fasttest_ex(), respectively.

- -

RETURN VALUES

- -

BN_generate_prime_ex() return 1 on success or 0 on error.

- -

BN_is_prime_ex(), BN_is_prime_fasttest_ex(), BN_is_prime(), BN_is_prime_fasttest() and BN_check_prime return 0 if the number is composite, 1 if it is prime with an error probability of less than 0.25^nchecks, and -1 on error.

- -

BN_generate_prime() returns the prime number on success, NULL otherwise.

- -

BN_GENCB_new returns a pointer to a BN_GENCB structure on success, or NULL otherwise.

- -

BN_GENCB_get_arg returns the argument previously associated with a BN_GENCB structure.

- -

Callback functions should return 1 on success or 0 on error.

- -

The error codes can be obtained by ERR_get_error(3).

- -

REMOVED FUNCTIONALITY

- -

As of OpenSSL 1.1.0 it is no longer possible to create a BN_GENCB structure directly, as in:

- -
BN_GENCB callback;
- -

Instead applications should create a BN_GENCB structure using BN_GENCB_new:

- -
BN_GENCB *callback;
-callback = BN_GENCB_new();
-if (!callback)
-    /* error */
-...
-BN_GENCB_free(callback);
- -

SEE ALSO

- -

DH_generate_parameters(3), DSA_generate_parameters(3), RSA_generate_key(3), ERR_get_error(3), RAND_bytes(3), RAND(7)

- -

HISTORY

- -

The BN_is_prime_ex() and BN_is_prime_fasttest_ex() functions were deprecated in OpenSSL 3.0.

- -

The BN_GENCB_new(), BN_GENCB_free(), and BN_GENCB_get_arg() functions were added in OpenSSL 1.1.0.

- -

BN_check_prime() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_mod_exp_mont.html b/openssl-install/share/doc/openssl/html/man3/BN_mod_exp_mont.html deleted file mode 100644 index b56bde3d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_mod_exp_mont.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -BN_mod_exp_mont - - - - - - - - - - -

NAME

- -

BN_mod_exp_mont, BN_mod_exp_mont_consttime, BN_mod_exp_mont_consttime_x2 - Montgomery exponentiation

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_mod_exp_mont(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p,
-                    const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *in_mont);
-
-int BN_mod_exp_mont_consttime(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p,
-                              const BIGNUM *m, BN_CTX *ctx,
-                              BN_MONT_CTX *in_mont);
-
-int BN_mod_exp_mont_consttime_x2(BIGNUM *rr1, const BIGNUM *a1,
-                                 const BIGNUM *p1, const BIGNUM *m1,
-                                 BN_MONT_CTX *in_mont1, BIGNUM *rr2,
-                                 const BIGNUM *a2, const BIGNUM *p2,
-                                 const BIGNUM *m2, BN_MONT_CTX *in_mont2,
-                                 BN_CTX *ctx);
- -

DESCRIPTION

- -

BN_mod_exp_mont() computes a to the p-th power modulo m (rr=a^p % m) using Montgomery multiplication. in_mont is a Montgomery context and can be NULL. In the case in_mont is NULL, it will be initialized within the function, so you can save time on initialization if you provide it in advance.

- -

BN_mod_exp_mont_consttime() computes a to the p-th power modulo m (rr=a^p % m) using Montgomery multiplication. It is a variant of BN_mod_exp_mont(3) that uses fixed windows and the special precomputation memory layout to limit data-dependency to a minimum to protect secret exponents. It is called automatically when BN_mod_exp_mont(3) is called with parameters a, p, m, any of which have BN_FLG_CONSTTIME flag.

- -

BN_mod_exp_mont_consttime_x2() computes two independent exponentiations a1 to the p1-th power modulo m1 (rr1=a1^p1 % m1) and a2 to the p2-th power modulo m2 (rr2=a2^p2 % m2) using Montgomery multiplication. For some fixed and equal modulus sizes m1 and m2 it uses optimizations that allow to speedup two exponentiations. In all other cases the function reduces to two calls of BN_mod_exp_mont_consttime(3).

- -

RETURN VALUES

- -

For all functions 1 is returned for success, 0 on error. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), BN_mod_exp_mont(3)

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_mod_inverse.html b/openssl-install/share/doc/openssl/html/man3/BN_mod_inverse.html deleted file mode 100644 index 4b5692c2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_mod_inverse.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -BN_mod_inverse - - - - - - - - - - -

NAME

- -

BN_mod_inverse - compute inverse modulo n

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-BIGNUM *BN_mod_inverse(BIGNUM *r, BIGNUM *a, const BIGNUM *n,
-                       BN_CTX *ctx);
- -

DESCRIPTION

- -

BN_mod_inverse() computes the inverse of a modulo n places the result in r ((a*r)%n==1). If r is NULL, a new BIGNUM is created.

- -

ctx is a previously allocated BN_CTX used for temporary variables. r may be the same BIGNUM as a.

- -

NOTES

- -

It is an error to use the same BIGNUM as n.

- -

RETURN VALUES

- -

BN_mod_inverse() returns the BIGNUM containing the inverse, and NULL on error. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), BN_add(3)

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_mod_mul_montgomery.html b/openssl-install/share/doc/openssl/html/man3/BN_mod_mul_montgomery.html deleted file mode 100644 index 212aa765..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_mod_mul_montgomery.html +++ /dev/null @@ -1,99 +0,0 @@ - - - - -BN_mod_mul_montgomery - - - - - - - - - - -

NAME

- -

BN_mod_mul_montgomery, BN_MONT_CTX_new, BN_MONT_CTX_free, BN_MONT_CTX_set, BN_MONT_CTX_copy, BN_from_montgomery, BN_to_montgomery - Montgomery multiplication

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-BN_MONT_CTX *BN_MONT_CTX_new(void);
-void BN_MONT_CTX_free(BN_MONT_CTX *mont);
-
-int BN_MONT_CTX_set(BN_MONT_CTX *mont, const BIGNUM *m, BN_CTX *ctx);
-BN_MONT_CTX *BN_MONT_CTX_copy(BN_MONT_CTX *to, BN_MONT_CTX *from);
-
-int BN_mod_mul_montgomery(BIGNUM *r, BIGNUM *a, BIGNUM *b,
-                          BN_MONT_CTX *mont, BN_CTX *ctx);
-
-int BN_from_montgomery(BIGNUM *r, BIGNUM *a, BN_MONT_CTX *mont,
-                       BN_CTX *ctx);
-
-int BN_to_montgomery(BIGNUM *r, BIGNUM *a, BN_MONT_CTX *mont,
-                     BN_CTX *ctx);
- -

DESCRIPTION

- -

These functions implement Montgomery multiplication. They are used automatically when BN_mod_exp(3) is called with suitable input, but they may be useful when several operations are to be performed using the same modulus.

- -

BN_MONT_CTX_new() allocates and initializes a BN_MONT_CTX structure.

- -

BN_MONT_CTX_set() sets up the mont structure from the modulus m by precomputing its inverse and a value R.

- -

BN_MONT_CTX_copy() copies the BN_MONT_CTX from to to.

- -

BN_MONT_CTX_free() frees the components of the BN_MONT_CTX, and, if it was created by BN_MONT_CTX_new(), also the structure itself. If mont is NULL, nothing is done.

- -

BN_mod_mul_montgomery() computes Mont(a,b):=a*b*R^-1 and places the result in r.

- -

BN_from_montgomery() performs the Montgomery reduction r = a*R^-1.

- -

BN_to_montgomery() computes Mont(a,R^2), i.e. a*R. Note that a must be nonnegative and smaller than the modulus.

- -

For all functions, ctx is a previously allocated BN_CTX used for temporary variables.

- -

RETURN VALUES

- -

BN_MONT_CTX_new() returns the newly allocated BN_MONT_CTX, and NULL on error.

- -

BN_MONT_CTX_free() has no return value.

- -

For the other functions, 1 is returned for success, 0 on error. The error codes can be obtained by ERR_get_error(3).

- -

WARNINGS

- -

The inputs must be reduced modulo m, otherwise the result will be outside the expected range.

- -

SEE ALSO

- -

ERR_get_error(3), BN_add(3), BN_CTX_new(3)

- -

HISTORY

- -

BN_MONT_CTX_init() was removed in OpenSSL 1.1.0

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_mod_mul_reciprocal.html b/openssl-install/share/doc/openssl/html/man3/BN_mod_mul_reciprocal.html deleted file mode 100644 index 5e456fa0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_mod_mul_reciprocal.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -BN_mod_mul_reciprocal - - - - - - - - - - -

NAME

- -

BN_mod_mul_reciprocal, BN_div_recp, BN_RECP_CTX_new, BN_RECP_CTX_free, BN_RECP_CTX_set - modular multiplication using reciprocal

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-BN_RECP_CTX *BN_RECP_CTX_new(void);
-void BN_RECP_CTX_free(BN_RECP_CTX *recp);
-
-int BN_RECP_CTX_set(BN_RECP_CTX *recp, const BIGNUM *m, BN_CTX *ctx);
-
-int BN_div_recp(BIGNUM *dv, BIGNUM *rem, const BIGNUM *a, BN_RECP_CTX *recp,
-                BN_CTX *ctx);
-
-int BN_mod_mul_reciprocal(BIGNUM *r, const BIGNUM *a, const BIGNUM *b,
-                          BN_RECP_CTX *recp, BN_CTX *ctx);
- -

DESCRIPTION

- -

BN_mod_mul_reciprocal() can be used to perform an efficient BN_mod_mul(3) operation when the operation will be performed repeatedly with the same modulus. It computes r=(a*b)%m using recp=1/m, which is set as described below. ctx is a previously allocated BN_CTX used for temporary variables.

- -

BN_RECP_CTX_new() allocates and initializes a BN_RECP structure.

- -

BN_RECP_CTX_free() frees the components of the BN_RECP, and, if it was created by BN_RECP_CTX_new(), also the structure itself. If recp is NULL, nothing is done.

- -

BN_RECP_CTX_set() stores m in recp and sets it up for computing 1/m and shifting it left by BN_num_bits(m)+1 to make it an integer. The result and the number of bits it was shifted left will later be stored in recp.

- -

BN_div_recp() divides a by m using recp. It places the quotient in dv and the remainder in rem.

- -

The BN_RECP_CTX structure cannot be shared between threads.

- -

RETURN VALUES

- -

BN_RECP_CTX_new() returns the newly allocated BN_RECP_CTX, and NULL on error.

- -

BN_RECP_CTX_free() has no return value.

- -

For the other functions, 1 is returned for success, 0 on error. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), BN_add(3), BN_CTX_new(3)

- -

HISTORY

- -

BN_RECP_CTX_init() was removed in OpenSSL 1.1.0

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_new.html b/openssl-install/share/doc/openssl/html/man3/BN_new.html deleted file mode 100644 index 323b98f6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_new.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -BN_new - - - - - - - - - - -

NAME

- -

BN_new, BN_secure_new, BN_clear, BN_free, BN_clear_free - allocate and free BIGNUMs

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-BIGNUM *BN_new(void);
-
-BIGNUM *BN_secure_new(void);
-
-void BN_clear(BIGNUM *a);
-
-void BN_free(BIGNUM *a);
-
-void BN_clear_free(BIGNUM *a);
- -

DESCRIPTION

- -

BN_new() allocates and initializes a BIGNUM structure. BN_secure_new() does the same except that the secure heap OPENSSL_secure_malloc(3) is used to store the value.

- -

BN_clear() is used to destroy sensitive data such as keys when they are no longer needed. It erases the memory used by a and sets it to the value 0. If a is NULL, nothing is done.

- -

BN_free() frees the components of the BIGNUM, and if it was created by BN_new(), also the structure itself. BN_clear_free() additionally overwrites the data before the memory is returned to the system. If a is NULL, nothing is done.

- -

RETURN VALUES

- -

BN_new() and BN_secure_new() return a pointer to the BIGNUM initialised to the value 0. If the allocation fails, they return NULL and set an error code that can be obtained by ERR_get_error(3).

- -

BN_clear(), BN_free() and BN_clear_free() have no return values.

- -

SEE ALSO

- -

ERR_get_error(3), OPENSSL_secure_malloc(3)

- -

HISTORY

- -

BN_init() was removed in OpenSSL 1.1.0; use BN_new() instead.

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_num_bytes.html b/openssl-install/share/doc/openssl/html/man3/BN_num_bytes.html deleted file mode 100644 index 5dd20edd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_num_bytes.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -BN_num_bytes - - - - - - - - - - -

NAME

- -

BN_num_bits, BN_num_bytes, BN_num_bits_word - get BIGNUM size

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_num_bytes(const BIGNUM *a);
-
-int BN_num_bits(const BIGNUM *a);
-
-int BN_num_bits_word(BN_ULONG w);
- -

DESCRIPTION

- -

BN_num_bytes() returns the size of a BIGNUM in bytes.

- -

BN_num_bits_word() returns the number of significant bits in a word. If we take 0x00000432 as an example, it returns 11, not 16, not 32. Basically, except for a zero, it returns floor(log2(w))+1.

- -

BN_num_bits() returns the number of significant bits in a BIGNUM, following the same principle as BN_num_bits_word().

- -

BN_num_bytes() is a macro.

- -

RETURN VALUES

- -

The size.

- -

NOTES

- -

Some have tried using BN_num_bits() on individual numbers in RSA keys, DH keys and DSA keys, and found that they don't always come up with the number of bits they expected (something like 512, 1024, 2048, ...). This is because generating a number with some specific number of bits doesn't always set the highest bits, thereby making the number of significant bits a little lower. If you want to know the "key size" of such a key, either use functions like RSA_size(), DH_size() and DSA_size(), or use BN_num_bytes() and multiply with 8 (although there's no real guarantee that will match the "key size", just a lot more probability).

- -

SEE ALSO

- -

DH_size(3), DSA_size(3), RSA_size(3)

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_rand.html b/openssl-install/share/doc/openssl/html/man3/BN_rand.html deleted file mode 100644 index 52596f27..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_rand.html +++ /dev/null @@ -1,104 +0,0 @@ - - - - -BN_rand - - - - - - - - - - -

NAME

- -

BN_rand_ex, BN_rand, BN_priv_rand_ex, BN_priv_rand, BN_pseudo_rand, BN_rand_range_ex, BN_rand_range, BN_priv_rand_range_ex, BN_priv_rand_range, BN_pseudo_rand_range - generate pseudo-random number

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_rand_ex(BIGNUM *rnd, int bits, int top, int bottom,
-               unsigned int strength, BN_CTX *ctx);
-int BN_rand(BIGNUM *rnd, int bits, int top, int bottom);
-
-int BN_priv_rand_ex(BIGNUM *rnd, int bits, int top, int bottom,
-                    unsigned int strength, BN_CTX *ctx);
-int BN_priv_rand(BIGNUM *rnd, int bits, int top, int bottom);
-
-int BN_rand_range_ex(BIGNUM *rnd, const BIGNUM *range, unsigned int strength,
-                     BN_CTX *ctx);
-int BN_rand_range(BIGNUM *rnd, const BIGNUM *range);
-
-int BN_priv_rand_range_ex(BIGNUM *rnd, const BIGNUM *range, unsigned int strength,
-                          BN_CTX *ctx);
-int BN_priv_rand_range(BIGNUM *rnd, const BIGNUM *range);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int BN_pseudo_rand(BIGNUM *rnd, int bits, int top, int bottom);
-int BN_pseudo_rand_range(BIGNUM *rnd, const BIGNUM *range);
- -

DESCRIPTION

- -

BN_rand_ex() generates a cryptographically strong pseudo-random number of bits in length and security strength at least strength bits using the random number generator for the library context associated with ctx. The function stores the generated data in rnd. The parameter ctx may be NULL in which case the default library context is used. If bits is less than zero, or too small to accommodate the requirements specified by the top and bottom parameters, an error is returned. The top parameters specifies requirements on the most significant bit of the generated number. If it is BN_RAND_TOP_ANY, there is no constraint. If it is BN_RAND_TOP_ONE, the top bit must be one. If it is BN_RAND_TOP_TWO, the two most significant bits of the number will be set to 1, so that the product of two such random numbers will always have 2*bits length. If bottom is BN_RAND_BOTTOM_ODD, the number will be odd; if it is BN_RAND_BOTTOM_ANY it can be odd or even. If bits is 1 then top cannot also be BN_RAND_TOP_TWO.

- -

BN_rand() is the same as BN_rand_ex() except that the default library context is always used.

- -

BN_rand_range_ex() generates a cryptographically strong pseudo-random number rnd, of security strength at least strength bits, in the range 0 <= rnd < range using the random number generator for the library context associated with ctx. The parameter ctx may be NULL in which case the default library context is used.

- -

BN_rand_range() is the same as BN_rand_range_ex() except that the default library context is always used.

- -

BN_priv_rand_ex(), BN_priv_rand(), BN_priv_rand_rand_ex() and BN_priv_rand_range() have the same semantics as BN_rand_ex(), BN_rand(), BN_rand_range_ex() and BN_rand_range() respectively. They are intended to be used for generating values that should remain private, and mirror the same difference between RAND_bytes(3) and RAND_priv_bytes(3).

- -

NOTES

- -

Always check the error return value of these functions and do not take randomness for granted: an error occurs if the CSPRNG has not been seeded with enough randomness to ensure an unpredictable byte sequence.

- -

RETURN VALUES

- -

The functions return 1 on success, 0 on error. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), RAND_add(3), RAND_bytes(3), RAND_priv_bytes(3), RAND(7), EVP_RAND(7)

- -

HISTORY

- - - -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_security_bits.html b/openssl-install/share/doc/openssl/html/man3/BN_security_bits.html deleted file mode 100644 index c1b51ed6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_security_bits.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -BN_security_bits - - - - - - - - - - -

NAME

- -

BN_security_bits - returns bits of security based on given numbers

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_security_bits(int L, int N);
- -

DESCRIPTION

- -

BN_security_bits() returns the number of bits of security provided by a specific algorithm and a particular key size. The bits of security is defined in NIST SP800-57. Currently, BN_security_bits() support two types of asymmetric algorithms: the FFC (Finite Field Cryptography) and IFC (Integer Factorization Cryptography). For FFC, e.g., DSA and DH, both parameters L and N are used to decide the bits of security, where L is the size of the public key and N is the size of the private key. For IFC, e.g., RSA, only L is used and it's commonly considered to be the key size (modulus).

- -

RETURN VALUES

- -

Number of security bits.

- -

NOTES

- -

ECC (Elliptic Curve Cryptography) is not covered by the BN_security_bits() function. The symmetric algorithms are not covered neither.

- -

SEE ALSO

- -

DH_security_bits(3), DSA_security_bits(3), RSA_security_bits(3)

- -

HISTORY

- -

The BN_security_bits() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2017-2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_set_bit.html b/openssl-install/share/doc/openssl/html/man3/BN_set_bit.html deleted file mode 100644 index ca376204..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_set_bit.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -BN_set_bit - - - - - - - - - - -

NAME

- -

BN_set_bit, BN_clear_bit, BN_is_bit_set, BN_mask_bits, BN_lshift, BN_lshift1, BN_rshift, BN_rshift1 - bit operations on BIGNUMs

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-int BN_set_bit(BIGNUM *a, int n);
-int BN_clear_bit(BIGNUM *a, int n);
-
-int BN_is_bit_set(const BIGNUM *a, int n);
-
-int BN_mask_bits(BIGNUM *a, int n);
-
-int BN_lshift(BIGNUM *r, const BIGNUM *a, int n);
-int BN_lshift1(BIGNUM *r, BIGNUM *a);
-
-int BN_rshift(BIGNUM *r, BIGNUM *a, int n);
-int BN_rshift1(BIGNUM *r, BIGNUM *a);
- -

DESCRIPTION

- -

BN_set_bit() sets bit n in a to 1 (a|=(1<<n)). The number is expanded if necessary.

- -

BN_clear_bit() sets bit n in a to 0 (a&=~(1<<n)). An error occurs if a is shorter than n bits.

- -

BN_is_bit_set() tests if bit n in a is set.

- -

BN_mask_bits() truncates a to an n bit number (a&=~((~0)<<n)). An error occurs if n is negative. An error is also returned if the internal representation of a is already shorter than n bits. The internal representation depends on the platform's word size, and this error can be safely ignored. Use BN_num_bits(3) to determine the exact number of bits if needed.

- -

BN_lshift() shifts a left by n bits and places the result in r (r=a*2^n). Note that n must be nonnegative. BN_lshift1() shifts a left by one and places the result in r (r=2*a).

- -

BN_rshift() shifts a right by n bits and places the result in r (r=a/2^n). Note that n must be nonnegative. BN_rshift1() shifts a right by one and places the result in r (r=a/2).

- -

For the shift functions, r and a may be the same variable.

- -

RETURN VALUES

- -

BN_is_bit_set() returns 1 if the bit is set, 0 otherwise.

- -

All other functions return 1 for success, 0 on error. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

BN_num_bytes(3), BN_add(3)

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_swap.html b/openssl-install/share/doc/openssl/html/man3/BN_swap.html deleted file mode 100644 index 82db7d43..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_swap.html +++ /dev/null @@ -1,51 +0,0 @@ - - - - -BN_swap - - - - - - - - - - -

NAME

- -

BN_swap - exchange BIGNUMs

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-void BN_swap(BIGNUM *a, BIGNUM *b);
- -

DESCRIPTION

- -

BN_swap() exchanges the values of a and b.

- -

RETURN VALUES

- -

BN_swap() does not return a value.

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BN_zero.html b/openssl-install/share/doc/openssl/html/man3/BN_zero.html deleted file mode 100644 index 5979f42b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BN_zero.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -BN_zero - - - - - - - - - - -

NAME

- -

BN_zero, BN_one, BN_value_one, BN_set_word, BN_get_word - BIGNUM assignment operations

- -

SYNOPSIS

- -
#include <openssl/bn.h>
-
-void BN_zero(BIGNUM *a);
-int BN_one(BIGNUM *a);
-
-const BIGNUM *BN_value_one(void);
-
-int BN_set_word(BIGNUM *a, BN_ULONG w);
-unsigned BN_ULONG BN_get_word(BIGNUM *a);
- -

DESCRIPTION

- -

BN_ULONG is a macro that will be an unsigned integral type optimized for the most efficient implementation on the local platform.

- -

BN_zero(), BN_one() and BN_set_word() set a to the values 0, 1 and w respectively. BN_zero() and BN_one() are macros.

- -

BN_value_one() returns a BIGNUM constant of value 1. This constant is useful for use in comparisons and assignment.

- -

BN_get_word() returns a, if it can be represented as a BN_ULONG.

- -

RETURN VALUES

- -

BN_get_word() returns the value a, or all-bits-set if a cannot be represented as a single integer.

- -

BN_one() and BN_set_word() return 1 on success, 0 otherwise. BN_value_one() returns the constant. BN_zero() never fails and returns no value.

- -

BUGS

- -

If a BIGNUM is equal to the value of all-bits-set, it will collide with the error condition returned by BN_get_word() which uses that as an error value.

- -

BN_ULONG should probably be a typedef.

- -

SEE ALSO

- -

BN_bn2bin(3)

- -

HISTORY

- -

In OpenSSL 0.9.8, BN_zero() was changed to not return a value; previous versions returned an int.

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/BUF_MEM_new.html b/openssl-install/share/doc/openssl/html/man3/BUF_MEM_new.html deleted file mode 100644 index 1d97c022..00000000 --- a/openssl-install/share/doc/openssl/html/man3/BUF_MEM_new.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -BUF_MEM_new - - - - - - - - - - -

NAME

- -

BUF_MEM_new, BUF_MEM_new_ex, BUF_MEM_free, BUF_MEM_grow, BUF_MEM_grow_clean, BUF_reverse - simple character array structure

- -

SYNOPSIS

- -
#include <openssl/buffer.h>
-
-BUF_MEM *BUF_MEM_new(void);
-
-BUF_MEM *BUF_MEM_new_ex(unsigned long flags);
-
-void BUF_MEM_free(BUF_MEM *a);
-
-int BUF_MEM_grow(BUF_MEM *str, int len);
-size_t BUF_MEM_grow_clean(BUF_MEM *str, size_t len);
-
-void BUF_reverse(unsigned char *out, const unsigned char *in, size_t size);
- -

DESCRIPTION

- -

The buffer library handles simple character arrays. Buffers are used for various purposes in the library, most notably memory BIOs.

- -

BUF_MEM_new() allocates a new buffer of zero size.

- -

BUF_MEM_new_ex() allocates a buffer with the specified flags. The flag BUF_MEM_FLAG_SECURE specifies that the data pointer should be allocated on the secure heap; see CRYPTO_secure_malloc(3).

- -

BUF_MEM_free() frees up an already existing buffer. The data is zeroed before freeing up in case the buffer contains sensitive data. If the argument is NULL, nothing is done.

- -

BUF_MEM_grow() changes the size of an already existing buffer to len. Any data already in the buffer is preserved if it increases in size.

- -

BUF_MEM_grow_clean() is similar to BUF_MEM_grow() but it sets any free'd or additionally-allocated memory to zero.

- -

BUF_reverse() reverses size bytes at in into out. If in is NULL, the array is reversed in-place.

- -

RETURN VALUES

- -

BUF_MEM_new() returns the buffer or NULL on error.

- -

BUF_MEM_free() has no return value.

- -

BUF_MEM_grow() and BUF_MEM_grow_clean() return zero on error or the new size (i.e., len).

- -

SEE ALSO

- -

bio(7), CRYPTO_secure_malloc(3).

- -

HISTORY

- -

The BUF_MEM_new_ex() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMAC_CTX.html b/openssl-install/share/doc/openssl/html/man3/CMAC_CTX.html deleted file mode 100644 index a1a8783b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMAC_CTX.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -CMAC_CTX - - - - - - - - - - -

NAME

- -

CMAC_CTX, CMAC_CTX_new, CMAC_CTX_cleanup, CMAC_CTX_free, CMAC_CTX_get0_cipher_ctx, CMAC_CTX_copy, CMAC_Init, CMAC_Update, CMAC_Final, CMAC_resume - create cipher-based message authentication codes

- -

SYNOPSIS

- -
#include <openssl/cmac.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be disabled entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7).

- -
typedef struct CMAC_CTX_st CMAC_CTX;
-
-CMAC_CTX *CMAC_CTX_new(void);
-void CMAC_CTX_cleanup(CMAC_CTX *ctx);
-void CMAC_CTX_free(CMAC_CTX *ctx);
-EVP_CIPHER_CTX *CMAC_CTX_get0_cipher_ctx(CMAC_CTX *ctx);
-int CMAC_CTX_copy(CMAC_CTX *out, const CMAC_CTX *in);
-int CMAC_Init(CMAC_CTX *ctx, const void *key, size_t keylen,
-              const EVP_CIPHER *cipher, ENGINE *impl);
-int CMAC_Update(CMAC_CTX *ctx, const void *data, size_t dlen);
-int CMAC_Final(CMAC_CTX *ctx, unsigned char *out, size_t *poutlen);
-int CMAC_resume(CMAC_CTX *ctx);
- -

DESCRIPTION

- -

The low-level MAC functions documented on this page are deprecated. Applications should use the new EVP_MAC(3) interface. Specifically, utilize the following functions for MAC operations:

- -
- -
EVP_MAC_CTX_new(3) to create a new MAC context.
-
- -
-
EVP_MAC_CTX_free(3) to free the MAC context.
-
- -
-
EVP_MAC_init(3) to initialize the MAC context.
-
- -
-
EVP_MAC_update(3) to update the MAC with data.
-
- -
-
EVP_MAC_final(3) to finalize the MAC and retrieve the output.
-
- -
-
- -

Alternatively, for a single-step MAC computation, use the EVP_Q_mac(3) function.

- -

The CMAC_CTX type is a structure used for the provision of CMAC (Cipher-based Message Authentication Code) operations.

- -

CMAC_CTX_new() creates a new CMAC_CTX structure and returns a pointer to it.

- -

CMAC_CTX_cleanup() resets the CMAC_CTX structure, clearing any internal data but not freeing the structure itself.

- -

CMAC_CTX_free() frees the CMAC_CTX structure and any associated resources. If the argument is NULL, no action is taken.

- -

CMAC_CTX_get0_cipher_ctx() returns a pointer to the internal EVP_CIPHER_CTX structure within the CMAC_CTX.

- -

CMAC_CTX_copy() copies the state from one CMAC_CTX structure to another.

- -

CMAC_Init() initializes the CMAC_CTX structure for a new CMAC calculation with the specified key, key length, and cipher type. Optionally, an ENGINE can be provided.

- -

CMAC_Update() processes data to be included in the CMAC calculation. This function can be called multiple times to update the context with additional data.

- -

CMAC_Final() finalizes the CMAC calculation and retrieves the resulting MAC value. The output is stored in the provided buffer, and the length is stored in the variable pointed to by poutlen. To determine the required buffer size, call with out set to NULL, which stores only the length in poutlen. Allocate a buffer of this size and call CMAC_Final() again with the allocated buffer to retrieve the MAC.

- -

CMAC_resume() resumes a previously finalized CMAC calculation, allowing additional data to be processed and a new MAC to be generated.

- -

RETURN VALUES

- -

CMAC_CTX_new() returns a pointer to a new CMAC_CTX structure or NULL if an error occurs.

- -

CMAC_CTX_get0_cipher_ctx() returns a pointer to the internal EVP_CIPHER_CTX structure, or NULL if an error occurs.

- -

CMAC_CTX_copy(), CMAC_Init(), CMAC_Update(), CMAC_Final() and CMAC_resume() return 1 for success or 0 if an error occurs.

- -

HISTORY

- -

All functions described here were deprecated in OpenSSL 3.0. For replacements, see EVP_MAC_CTX_new(3), EVP_MAC_CTX_free(3), EVP_MAC_init(3), EVP_MAC_update(3), and EVP_MAC_final(3).

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_decrypt.html b/openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_decrypt.html deleted file mode 100644 index a31d23f0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_decrypt.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -CMS_EncryptedData_decrypt - - - - - - - - - - -

NAME

- -

CMS_EncryptedData_decrypt, CMS_EnvelopedData_decrypt - Decrypt CMS EncryptedData or EnvelopedData

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_EncryptedData_decrypt(CMS_ContentInfo *cms,
-                              const unsigned char *key, size_t keylen,
-                              BIO *dcont, BIO *out, unsigned int flags);
-
-BIO *CMS_EnvelopedData_decrypt(CMS_EnvelopedData *env, BIO *detached_data,
-                               EVP_PKEY *pkey, X509 *cert,
-                               ASN1_OCTET_STRING *secret, unsigned int flags,
-                               OSSL_LIB_CTX *libctx, const char *propq);
- -

DESCRIPTION

- -

CMS_EncryptedData_decrypt() decrypts a cms EncryptedData object using the symmetric key of size keylen bytes. out is a BIO to write the content to and flags is an optional set of flags. dcont is used in the rare case where the encrypted content is detached. It will normally be set to NULL.

- -

The following flags can be passed in the flags parameter.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are deleted from the content. If the content is not of type text/plain then an error is returned.

- -

CMS_EnvelopedData_decrypt() decrypts, similarly to CMS_decrypt(3), a CMS EnvelopedData object env using the symmetric key secret if it is not NULL, otherwise the private key of the recipient pkey. If pkey is given, it is recommended to provide also the associated certificate in cert - see CMS_decrypt(3) and the NOTES on cert there. The optional parameters flags and dcont are used as described above. The optional parameters library context libctx and property query propq are used when retrieving algorithms from providers.

- -

RETURN VALUES

- -

CMS_EncryptedData_decrypt() returns 0 if an error occurred otherwise returns 1.

- -

CMS_EnvelopedData_decrypt() returns NULL if an error occurred, otherwise a BIO containing the decypted content.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_EncryptedData_encrypt(3), CMS_decrypt(3)

- -

HISTORY

- -

CMS_EnvelopedData_decrypt() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_encrypt.html b/openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_encrypt.html deleted file mode 100644 index adb0263e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_EncryptedData_encrypt.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -CMS_EncryptedData_encrypt - - - - - - - - - - -

NAME

- -

CMS_EncryptedData_encrypt_ex, CMS_EncryptedData_encrypt - Create CMS EncryptedData

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *CMS_EncryptedData_encrypt_ex(BIO *in,
-                                              const EVP_CIPHER *cipher,
-                                              const unsigned char *key,
-                                              size_t keylen,
-                                              unsigned int flags,
-                                              OSSL_LIB_CTX *ctx,
-                                              const char *propq);
-
-CMS_ContentInfo *CMS_EncryptedData_encrypt(BIO *in,
-    const EVP_CIPHER *cipher, const unsigned char *key, size_t keylen,
-    unsigned int flags);
- -

DESCRIPTION

- -

CMS_EncryptedData_encrypt_ex() creates a CMS_ContentInfo structure with a type NID_pkcs7_encrypted. in is a BIO containing the data to encrypt using cipher and the encryption key key of size keylen bytes. The library context libctx and the property query propq are used when retrieving algorithms from providers. flags is a set of optional flags.

- -

The flags field supports the options CMS_DETACHED, CMS_STREAM and CMS_PARTIAL. Internally CMS_final() is called unless CMS_STREAM and/or CMS_PARTIAL is specified.

- -

The algorithm passed in the cipher parameter must support ASN1 encoding of its parameters.

- -

The CMS_ContentInfo structure can be freed using CMS_ContentInfo_free(3).

- -

CMS_EncryptedData_encrypt() is similar to CMS_EncryptedData_encrypt_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

RETURN VALUES

- -

If the allocation fails, CMS_EncryptedData_encrypt_ex() and CMS_EncryptedData_encrypt() return NULL and set an error code that can be obtained by ERR_get_error(3). Otherwise they return a pointer to the newly allocated structure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_final(3), CMS_EncryptedData_decrypt(3)

- -

HISTORY

- -

The CMS_EncryptedData_encrypt_ex() method was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_EnvelopedData_create.html b/openssl-install/share/doc/openssl/html/man3/CMS_EnvelopedData_create.html deleted file mode 100644 index 06d36504..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_EnvelopedData_create.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -CMS_EnvelopedData_create - - - - - - - - - - -

NAME

- -

CMS_EnvelopedData_create_ex, CMS_EnvelopedData_create, CMS_AuthEnvelopedData_create, CMS_AuthEnvelopedData_create_ex - Create CMS envelope

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *
-CMS_EnvelopedData_create_ex(const EVP_CIPHER *cipher, OSSL_LIB_CTX *libctx,
-                            const char *propq);
-CMS_ContentInfo *CMS_EnvelopedData_create(const EVP_CIPHER *cipher);
-
-CMS_ContentInfo *
-CMS_AuthEnvelopedData_create_ex(const EVP_CIPHER *cipher, OSSL_LIB_CTX *libctx,
-                                const char *propq);
-CMS_ContentInfo *CMS_AuthEnvelopedData_create(const EVP_CIPHER *cipher);
- -

DESCRIPTION

- -

CMS_EnvelopedData_create_ex() creates a CMS_ContentInfo structure with a type NID_pkcs7_enveloped. cipher is the symmetric cipher to use. The library context libctx and the property query propq are used when retrieving algorithms from providers.

- -

CMS_AuthEnvelopedData_create_ex() creates a CMS_ContentInfo structure with a type NID_id_smime_ct_authEnvelopedData. cipher is the symmetric AEAD cipher to use. Currently only AES variants with GCM mode are supported. The library context libctx and the property query propq are used when retrieving algorithms from providers.

- -

The algorithm passed in the cipher parameter must support ASN1 encoding of its parameters.

- -

The recipients can be added later using CMS_add1_recipient_cert(3) or CMS_add0_recipient_key(3).

- -

The CMS_ContentInfo structure needs to be finalized using CMS_final(3) and then freed using CMS_ContentInfo_free(3).

- -

CMS_EnvelopedData_create() and CMS_AuthEnvelopedData_create() are similar to CMS_EnvelopedData_create_ex() and CMS_AuthEnvelopedData_create_ex() but use default values of NULL for the library context libctx and the property query propq.

- -

NOTES

- -

Although CMS_EnvelopedData_create_ex(), and CMS_EnvelopedData_create(), CMS_AuthEnvelopedData_create_ex(), and CMS_AuthEnvelopedData_create() allocate a new CMS_ContentInfo structure, they are not usually used in applications. The wrappers CMS_encrypt(3) and CMS_decrypt(3) are often used instead.

- -

RETURN VALUES

- -

If the allocation fails, CMS_EnvelopedData_create_ex(), CMS_EnvelopedData_create(), CMS_AuthEnvelopedData_create_ex(), and CMS_AuthEnvelopedData_create() return NULL and set an error code that can be obtained by ERR_get_error(3). Otherwise they return a pointer to the newly allocated structure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_encrypt(3), CMS_decrypt(3), CMS_final(3)

- -

HISTORY

- -

The CMS_EnvelopedData_create_ex() method was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_add0_cert.html b/openssl-install/share/doc/openssl/html/man3/CMS_add0_cert.html deleted file mode 100644 index 51deabd4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_add0_cert.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -CMS_add0_cert - - - - - - - - - - -

NAME

- -

CMS_add0_cert, CMS_add1_cert, CMS_get1_certs, CMS_add0_crl, CMS_add1_crl, CMS_get1_crls - CMS certificate and CRL utility functions

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_add0_cert(CMS_ContentInfo *cms, X509 *cert);
-int CMS_add1_cert(CMS_ContentInfo *cms, X509 *cert);
-STACK_OF(X509) *CMS_get1_certs(CMS_ContentInfo *cms);
-
-int CMS_add0_crl(CMS_ContentInfo *cms, X509_CRL *crl);
-int CMS_add1_crl(CMS_ContentInfo *cms, X509_CRL *crl);
-STACK_OF(X509_CRL) *CMS_get1_crls(CMS_ContentInfo *cms);
- -

DESCRIPTION

- -

CMS_add0_cert() and CMS_add1_cert() add certificate cert to cms unless it is already present. This is used by CMS_sign_ex(3) and CMS_sign(3) and may be used before calling CMS_verify(3) to help chain building in certificate validation. As the 0 implies, CMS_add0_cert() adds cert internally to cms and on success it must not be freed up by the caller. In contrast, the caller of CMS_add1_cert() must free cert. cms must be of type signed data or (authenticated) enveloped data. For signed data, such a certificate can be used when signing or verifying to fill in the signer certificate or to provide an extra CA certificate that may be needed for chain building in certificate validation.

- -

CMS_get1_certs() returns all certificates in cms.

- -

CMS_add0_crl() and CMS_add1_crl() add CRL crl to cms. cms must be of type signed data or (authenticated) enveloped data. For signed data, such a CRL may be used in certificate validation with CMS_verify(3). It may be given both for inclusion when signing a CMS message and when verifying a signed CMS message.

- -

CMS_get1_crls() returns all CRLs in cms.

- -

NOTES

- -

The CMS_ContentInfo structure cms must be of type signed data or enveloped data or authenticated enveloped data or an error will be returned.

- -

For signed data, certificates and CRLs are added to the certificates and crls fields of SignedData structure. For enveloped data they are added to OriginatorInfo.

- -

RETURN VALUES

- -

CMS_add0_cert(), CMS_add1_cert() and CMS_add0_crl() and CMS_add1_crl() return 1 for success and 0 for failure.

- -

CMS_get1_certs() and CMS_get1_crls() return the STACK of certificates or CRLs or NULL if there are none or an error occurs. Besides out-of-memory, the only error which will occur in practice is if the cms type is invalid.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_sign_ex(3), CMS_verify(3), CMS_encrypt(3)

- -

HISTORY

- -

CMS_add0_cert() and CMS_add1_cert() have been changed in OpenSSL 3.2 not to throw an error if a certificate to be added is already present.

- -

COPYRIGHT

- -

Copyright 2008-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_add1_recipient_cert.html b/openssl-install/share/doc/openssl/html/man3/CMS_add1_recipient_cert.html deleted file mode 100644 index ffb4a08d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_add1_recipient_cert.html +++ /dev/null @@ -1,88 +0,0 @@ - - - - -CMS_add1_recipient_cert - - - - - - - - - - -

NAME

- -

CMS_add1_recipient, CMS_add1_recipient_cert, CMS_add0_recipient_key - add recipients to a CMS enveloped data structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_RecipientInfo *CMS_add1_recipient(CMS_ContentInfo *cms, X509 *recip,
-                                      EVP_PKEY *originatorPrivKey,
-                                      X509 *originator, unsigned int flags);
-
-CMS_RecipientInfo *CMS_add1_recipient_cert(CMS_ContentInfo *cms,
-                                           X509 *recip, unsigned int flags);
-
-CMS_RecipientInfo *CMS_add0_recipient_key(CMS_ContentInfo *cms, int nid,
-                                          unsigned char *key, size_t keylen,
-                                          unsigned char *id, size_t idlen,
-                                          ASN1_GENERALIZEDTIME *date,
-                                          ASN1_OBJECT *otherTypeId,
-                                          ASN1_TYPE *otherType);
- -

DESCRIPTION

- -

CMS_add1_recipient() adds recipient recip and provides the originator pkey originatorPrivKey and originator certificate originator to CMS_ContentInfo. The originator-related fields are relevant only in case when the keyAgreement method of providing of the shared key is in use.

- -

CMS_add1_recipient_cert() adds recipient recip to CMS_ContentInfo enveloped data structure cms as a KeyTransRecipientInfo structure.

- -

CMS_add0_recipient_key() adds symmetric key key of length keylen using wrapping algorithm nid, identifier id of length idlen and optional values date, otherTypeId and otherType to CMS_ContentInfo enveloped data structure cms as a KEKRecipientInfo structure.

- -

The CMS_ContentInfo structure should be obtained from an initial call to CMS_encrypt() with the flag CMS_PARTIAL set.

- -

NOTES

- -

The main purpose of this function is to provide finer control over a CMS enveloped data structure where the simpler CMS_encrypt() function defaults are not appropriate. For example if one or more KEKRecipientInfo structures need to be added. New attributes can also be added using the returned CMS_RecipientInfo structure and the CMS attribute utility functions.

- -

OpenSSL will by default identify recipient certificates using issuer name and serial number. If CMS_USE_KEYID is set it will use the subject key identifier value instead. An error occurs if all recipient certificates do not have a subject key identifier extension.

- -

Currently only AES based key wrapping algorithms are supported for nid, specifically: NID_id_aes128_wrap, NID_id_aes192_wrap and NID_id_aes256_wrap. If nid is set to NID_undef then an AES wrap algorithm will be used consistent with keylen.

- -

RETURN VALUES

- -

CMS_add1_recipient_cert() and CMS_add0_recipient_key() return an internal pointer to the CMS_RecipientInfo structure just added or NULL if an error occurs.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_decrypt(3), CMS_final(3),

- -

HISTORY

- -

CMS_add1_recipient_cert and CMS_add0_recipient_key were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2008-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_add1_signer.html b/openssl-install/share/doc/openssl/html/man3/CMS_add1_signer.html deleted file mode 100644 index fb54dd64..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_add1_signer.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -CMS_add1_signer - - - - - - - - - - -

NAME

- -

CMS_add1_signer, CMS_SignerInfo_sign - add a signer to a CMS_ContentInfo signed data structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_SignerInfo *CMS_add1_signer(CMS_ContentInfo *cms, X509 *signcert,
-                                EVP_PKEY *pkey, const EVP_MD *md,
-                                unsigned int flags);
-
-int CMS_SignerInfo_sign(CMS_SignerInfo *si);
- -

DESCRIPTION

- -

CMS_add1_signer() adds a signer with certificate signcert and private key pkey using message digest md to CMS_ContentInfo SignedData structure cms.

- -

The CMS_ContentInfo structure should be obtained from an initial call to CMS_sign() with the flag CMS_PARTIAL set or in the case or re-signing a valid CMS_ContentInfo SignedData structure.

- -

If the md parameter is NULL then the default digest for the public key algorithm will be used.

- -

Unless the CMS_REUSE_DIGEST flag is set the returned CMS_ContentInfo structure is not complete and must be finalized either by streaming (if applicable) or a call to CMS_final().

- -

The CMS_SignerInfo_sign() function explicitly signs a CMS_SignerInfo structure, its main use is when the CMS_REUSE_DIGEST and CMS_PARTIAL flags are both set.

- -

NOTES

- -

The main purpose of CMS_add1_signer() is to provide finer control over a CMS signed data structure where the simpler CMS_sign() function defaults are not appropriate. For example if multiple signers or non default digest algorithms are needed. New attributes can also be added using the returned CMS_SignerInfo structure and the CMS attribute utility functions or the CMS signed receipt request functions.

- -

Any of the following flags (ored together) can be passed in the flags parameter.

- -

If CMS_REUSE_DIGEST is set then an attempt is made to copy the content digest value from the CMS_ContentInfo structure: to add a signer to an existing structure. An error occurs if a matching digest value cannot be found to copy. The returned CMS_ContentInfo structure will be valid and finalized when this flag is set.

- -

If CMS_PARTIAL is set in addition to CMS_REUSE_DIGEST then the CMS_SignerInfo structure will not be finalized so additional attributes can be added. In this case an explicit call to CMS_SignerInfo_sign() is needed to finalize it.

- -

If CMS_NOCERTS is set the signer's certificate will not be included in the CMS_ContentInfo structure, the signer's certificate must still be supplied in the signcert parameter though. This can reduce the size of the signature if the signers certificate can be obtained by other means: for example a previously signed message.

- -

The SignedData structure includes several CMS signedAttributes including the signing time, the CMS content type and the supported list of ciphers in an SMIMECapabilities attribute. If CMS_NOATTR is set then no signedAttributes will be used. If CMS_NOSMIMECAP is set then just the SMIMECapabilities are omitted.

- -

OpenSSL will by default identify signing certificates using issuer name and serial number. If CMS_USE_KEYID is set it will use the subject key identifier value instead. An error occurs if the signing certificate does not have a subject key identifier extension.

- -

If present the SMIMECapabilities attribute indicates support for the following algorithms in preference order: 256 bit AES, Gost R3411-94, Gost 28147-89, 192 bit AES, 128 bit AES, triple DES, 128 bit RC2, 64 bit RC2, DES and 40 bit RC2. If any of these algorithms is not available then it will not be included: for example the GOST algorithms will not be included if the GOST ENGINE is not loaded.

- -

CMS_add1_signer() returns an internal pointer to the CMS_SignerInfo structure just added, this can be used to set additional attributes before it is finalized.

- -

RETURN VALUES

- -

CMS_add1_signer() returns an internal pointer to the CMS_SignerInfo structure just added or NULL if an error occurs.

- -

CMS_SignerInfo_sign() returns 1 on success, 0 on failure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_final(3),

- -

COPYRIGHT

- -

Copyright 2014-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_compress.html b/openssl-install/share/doc/openssl/html/man3/CMS_compress.html deleted file mode 100644 index f4c9fe38..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_compress.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -CMS_compress - - - - - - - - - - -

NAME

- -

CMS_compress - create a CMS CompressedData structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *CMS_compress(BIO *in, int comp_nid, unsigned int flags);
- -

DESCRIPTION

- -

CMS_compress() creates and returns a CMS CompressedData structure. comp_nid is the compression algorithm to use or NID_undef to use the default algorithm (zlib compression). in is the content to be compressed. flags is an optional set of flags.

- -

The only currently supported compression algorithm is zlib using the NID NID_zlib_compression.

- -

If zlib support is not compiled into OpenSSL then CMS_compress() will return an error.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are prepended to the data.

- -

Normally the supplied content is translated into MIME canonical format (as required by the S/MIME specifications) if CMS_BINARY is set no translation occurs. This option should be used if the supplied data is in binary format otherwise the translation will corrupt it. If CMS_BINARY is set then CMS_TEXT is ignored.

- -

If the CMS_STREAM flag is set a partial CMS_ContentInfo structure is returned suitable for streaming I/O: no data is read from the BIO in.

- -

The compressed data is included in the CMS_ContentInfo structure, unless CMS_DETACHED is set in which case it is omitted. This is rarely used in practice and is not supported by SMIME_write_CMS().

- -

If the flag CMS_STREAM is set the returned CMS_ContentInfo structure is not complete and outputting its contents via a function that does not properly finalize the CMS_ContentInfo structure will give unpredictable results.

- -

Several functions including SMIME_write_CMS(), i2d_CMS_bio_stream(), PEM_write_bio_CMS_stream() finalize the structure. Alternatively finalization can be performed by obtaining the streaming ASN1 BIO directly using BIO_new_CMS().

- -

Additional compression parameters such as the zlib compression level cannot currently be set.

- -

RETURN VALUES

- -

CMS_compress() returns either a CMS_ContentInfo structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), CMS_uncompress(3)

- -

HISTORY

- -

The CMS_STREAM flag was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_data_create.html b/openssl-install/share/doc/openssl/html/man3/CMS_data_create.html deleted file mode 100644 index 155983c7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_data_create.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -CMS_data_create - - - - - - - - - - -

NAME

- -

CMS_data_create_ex, CMS_data_create - Create CMS Data object

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *CMS_data_create_ex(BIO *in, unsigned int flags,
-                                    OSSL_LIB_CTX *libctx, const char *propq);
-CMS_ContentInfo *CMS_data_create(BIO *in, unsigned int flags);
- -

DESCRIPTION

- -

CMS_data_create_ex() creates a CMS_ContentInfo structure with a type NID_pkcs7_data. The data is supplied via the in BIO. The library context libctx and the property query propq are used when retrieving algorithms from providers. The flags field supports the CMS_STREAM flag. Internally CMS_final() is called unless CMS_STREAM is specified.

- -

The CMS_ContentInfo structure can be freed using CMS_ContentInfo_free(3).

- -

CMS_data_create() is similar to CMS_data_create_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

RETURN VALUES

- -

If the allocation fails, CMS_data_create_ex() and CMS_data_create() return NULL and set an error code that can be obtained by ERR_get_error(3). Otherwise they return a pointer to the newly allocated structure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_final(3)

- -

HISTORY

- -

The CMS_data_create_ex() method was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_decrypt.html b/openssl-install/share/doc/openssl/html/man3/CMS_decrypt.html deleted file mode 100644 index 4a6783bf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_decrypt.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -CMS_decrypt - - - - - - - - - - -

NAME

- -

CMS_decrypt, CMS_decrypt_set1_pkey_and_peer, CMS_decrypt_set1_pkey, CMS_decrypt_set1_password - decrypt content from a CMS envelopedData structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_decrypt(CMS_ContentInfo *cms, EVP_PKEY *pkey, X509 *cert,
-                BIO *dcont, BIO *out, unsigned int flags);
-int CMS_decrypt_set1_pkey_and_peer(CMS_ContentInfo *cms,
-                EVP_PKEY *pk, X509 *cert, X509 *peer);
-int CMS_decrypt_set1_pkey(CMS_ContentInfo *cms, EVP_PKEY *pk, X509 *cert);
-int CMS_decrypt_set1_password(CMS_ContentInfo *cms,
-                              unsigned char *pass, ossl_ssize_t passlen);
- -

DESCRIPTION

- -

CMS_decrypt() extracts the decrypted content from a CMS EnvelopedData or AuthEnvelopedData structure. It uses CMS_decrypt_set1_pkey() to decrypt the content with the recipient private key pkey if pkey is not NULL. In this case, the associated certificate is recommended to provide in cert - see the NOTES below. out is a BIO to write the content to and flags is an optional set of flags. If pkey is NULL the function assumes that decryption was already done (e.g., using CMS_decrypt_set1_pkey() or CMS_decrypt_set1_password()) and just provides the content unless cert, dcont, and out are NULL as well. The dcont parameter is used in the rare case where the encrypted content is detached. It will normally be set to NULL.

- -

CMS_decrypt_set1_pkey_and_peer() decrypts the CMS_ContentInfo structure cms using the private key pkey, the corresponding certificate cert, which is recommended but may be NULL, and the (optional) originator certificate peer. On success, it also records in cms the decryption key pkey, and then should be followed by CMS_decrypt(cms, NULL, NULL, dcont, out, flags). This call deallocates any decryption key stored in cms.

- -

CMS_decrypt_set1_pkey() is the same as CMS_decrypt_set1_pkey_and_peer() with peer being NULL.

- -

CMS_decrypt_set1_password() decrypts the CMS_ContentInfo structure cms using the secret pass of length passlen. On success, it also records in cms the decryption key used, and then should be followed by CMS_decrypt(cms, NULL, NULL, dcont, out, flags). This call deallocates any decryption key stored in cms.

- -

NOTES

- -

Although the recipients certificate is not needed to decrypt the data it is needed to locate the appropriate (of possible several) recipients in the CMS structure.

- -

If cert is set to NULL all possible recipients are tried. This case however is problematic. To thwart the MMA attack (Bleichenbacher's attack on PKCS #1 v1.5 RSA padding) all recipients are tried whether they succeed or not. If no recipient succeeds then a random symmetric key is used to decrypt the content: this will typically output garbage and may (but is not guaranteed to) ultimately return a padding error only. If CMS_decrypt() just returned an error when all recipient encrypted keys failed to decrypt an attacker could use this in a timing attack. If the special flag CMS_DEBUG_DECRYPT is set then the above behaviour is modified and an error is returned if no recipient encrypted key can be decrypted without generating a random content encryption key. Applications should use this flag with extreme caution especially in automated gateways as it can leave them open to attack.

- -

It is possible to determine the correct recipient key by other means (for example looking them up in a database) and setting them in the CMS structure in advance using the CMS utility functions such as CMS_set1_pkey(), or use CMS_decrypt_set1_password() if the recipient has a symmetric key. In these cases both cert and pkey should be set to NULL.

- -

To process KEKRecipientInfo types CMS_set1_key() or CMS_RecipientInfo_set0_key() and CMS_RecipientInfo_decrypt() should be called before CMS_decrypt() and cert and pkey set to NULL.

- -

The following flags can be passed in the flags parameter.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are deleted from the content. If the content is not of type text/plain then an error is returned.

- -

RETURN VALUES

- -

CMS_decrypt(), CMS_decrypt_set1_pkey_and_peer(), CMS_decrypt_set1_pkey(), and CMS_decrypt_set1_password() return either 1 for success or 0 for failure. The error can be obtained from ERR_get_error(3).

- -

BUGS

- -

The set1_ part of these function names is misleading and should better read: with_.

- -

The lack of single pass processing and the need to hold all data in memory as mentioned in CMS_verify() also applies to CMS_decrypt().

- -

SEE ALSO

- -

ERR_get_error(3), CMS_encrypt(3)

- -

HISTORY

- -

CMS_decrypt_set1_pkey_and_peer() and CMS_decrypt_set1_password() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2008-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_digest_create.html b/openssl-install/share/doc/openssl/html/man3/CMS_digest_create.html deleted file mode 100644 index c187b8b4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_digest_create.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -CMS_digest_create - - - - - - - - - - -

NAME

- -

CMS_digest_create_ex, CMS_digest_create - Create CMS DigestedData object

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *CMS_digest_create_ex(BIO *in, const EVP_MD *md,
-                                      unsigned int flags, OSSL_LIB_CTX *ctx,
-                                      const char *propq);
-
-CMS_ContentInfo *CMS_digest_create(BIO *in, const EVP_MD *md,
-                                   unsigned int flags);
- -

DESCRIPTION

- -

CMS_digest_create_ex() creates a CMS_ContentInfo structure with a type NID_pkcs7_digest. The data supplied via the in BIO is digested using md. The library context libctx and the property query propq are used when retrieving algorithms from providers. The flags field supports the CMS_DETACHED and CMS_STREAM flags, Internally CMS_final() is called unless CMS_STREAM is specified.

- -

The CMS_ContentInfo structure can be freed using CMS_ContentInfo_free(3).

- -

CMS_digest_create() is similar to CMS_digest_create_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

RETURN VALUES

- -

If the allocation fails, CMS_digest_create_ex() and CMS_digest_create() return NULL and set an error code that can be obtained by ERR_get_error(3). Otherwise they return a pointer to the newly allocated structure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_final(3)>

- -

HISTORY

- -

The CMS_digest_create_ex() method was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_encrypt.html b/openssl-install/share/doc/openssl/html/man3/CMS_encrypt.html deleted file mode 100644 index f1561c24..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_encrypt.html +++ /dev/null @@ -1,99 +0,0 @@ - - - - -CMS_encrypt - - - - - - - - - - -

NAME

- -

CMS_encrypt_ex, CMS_encrypt - create a CMS envelopedData structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *CMS_encrypt_ex(STACK_OF(X509) *certs, BIO *in,
-                                const EVP_CIPHER *cipher, unsigned int flags,
-                                OSSL_LIB_CTX *libctx, const char *propq);
-CMS_ContentInfo *CMS_encrypt(STACK_OF(X509) *certs, BIO *in,
-                             const EVP_CIPHER *cipher, unsigned int flags);
- -

DESCRIPTION

- -

CMS_encrypt_ex() creates and returns a CMS EnvelopedData or AuthEnvelopedData structure. certs is a list of recipient certificates. in is the content to be encrypted. cipher is the symmetric cipher to use. flags is an optional set of flags. The library context libctx and the property query propq are used internally when retrieving algorithms from providers.

- -

Only certificates carrying RSA, Diffie-Hellman or EC keys are supported by this function.

- -

EVP_des_ede3_cbc() (triple DES) is the algorithm of choice for S/MIME use because most clients will support it.

- -

The algorithm passed in the cipher parameter must support ASN1 encoding of its parameters. If the cipher mode is GCM, then an AuthEnvelopedData structure containing MAC is used. Otherwise an EnvelopedData structure is used. Currently the AES variants with GCM mode are the only supported AEAD algorithms.

- -

Many browsers implement a "sign and encrypt" option which is simply an S/MIME envelopedData containing an S/MIME signed message. This can be readily produced by storing the S/MIME signed message in a memory BIO and passing it to CMS_encrypt().

- -

The following flags can be passed in the flags parameter.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are prepended to the data.

- -

Normally the supplied content is translated into MIME canonical format (as required by the S/MIME specifications) if CMS_BINARY is set no translation occurs. This option should be used if the supplied data is in binary format otherwise the translation will corrupt it. If CMS_BINARY is set then CMS_TEXT is ignored.

- -

OpenSSL will by default identify recipient certificates using issuer name and serial number. If CMS_USE_KEYID is set it will use the subject key identifier value instead. An error occurs if all recipient certificates do not have a subject key identifier extension.

- -

If the CMS_STREAM flag is set a partial CMS_ContentInfo structure is returned suitable for streaming I/O: no data is read from the BIO in.

- -

If the CMS_PARTIAL flag is set a partial CMS_ContentInfo structure is returned to which additional recipients and attributes can be added before finalization.

- -

The data being encrypted is included in the CMS_ContentInfo structure, unless CMS_DETACHED is set in which case it is omitted. This is rarely used in practice and is not supported by SMIME_write_CMS().

- -

If the flag CMS_STREAM is set the returned CMS_ContentInfo structure is not complete and outputting its contents via a function that does not properly finalize the CMS_ContentInfo structure will give unpredictable results.

- -

Several functions including SMIME_write_CMS(), i2d_CMS_bio_stream(), PEM_write_bio_CMS_stream() finalize the structure. Alternatively finalization can be performed by obtaining the streaming ASN1 BIO directly using BIO_new_CMS().

- -

The recipients specified in certs use a CMS KeyTransRecipientInfo info structure. KEKRecipientInfo is also supported using the flag CMS_PARTIAL and CMS_add0_recipient_key().

- -

The parameter certs may be NULL if CMS_PARTIAL is set and recipients added later using CMS_add1_recipient_cert() or CMS_add0_recipient_key().

- -

CMS_encrypt() is similar to CMS_encrypt_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

RETURN VALUES

- -

CMS_encrypt_ex() and CMS_encrypt() return either a CMS_ContentInfo structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), CMS_decrypt(3)

- -

HISTORY

- -

The function CMS_encrypt_ex() was added in OpenSSL 3.0.

- -

The CMS_STREAM flag was first supported in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2008-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_final.html b/openssl-install/share/doc/openssl/html/man3/CMS_final.html deleted file mode 100644 index 76d765c3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_final.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -CMS_final - - - - - - - - - - -

NAME

- -

CMS_final, CMS_final_digest - finalise a CMS_ContentInfo structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_final(CMS_ContentInfo *cms, BIO *data, BIO *dcont, unsigned int flags);
-int CMS_final_digest(CMS_ContentInfo *cms, const unsigned char *md,
-                     unsigned int mdlen, BIO *dcont, unsigned int flags);
- -

DESCRIPTION

- -

CMS_final() finalises the structure cms. Its purpose is to perform any operations necessary on cms (digest computation for example) and set the appropriate fields. The parameter data contains the content to be processed. The dcont parameter contains a BIO to write content to after processing: this is only used with detached data and will usually be set to NULL.

- -

CMS_final_digest() finalises the structure cms using a pre-computed digest, rather than computing the digest from the original data.

- -

NOTES

- -

These functions will normally be called when the CMS_PARTIAL flag is used. It should only be used when streaming is not performed because the streaming I/O functions perform finalisation operations internally.

- -

To sign a pre-computed digest, CMS_sign(3) or CMS_sign_ex() is called with the data parameter set to NULL before the CMS structure is finalised with the digest provided to CMS_final_digest() in binary form. When signing a pre-computed digest, the security relies on the digest and its computation from the original message being trusted.

- -

RETURN VALUES

- -

CMS_final() and CMS_final_digest() return 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_encrypt(3)

- -

HISTORY

- -

CMS_final_digest() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2008-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_get0_RecipientInfos.html b/openssl-install/share/doc/openssl/html/man3/CMS_get0_RecipientInfos.html deleted file mode 100644 index 4d8113da..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_get0_RecipientInfos.html +++ /dev/null @@ -1,121 +0,0 @@ - - - - -CMS_get0_RecipientInfos - - - - - - - - - - -

NAME

- -

CMS_get0_RecipientInfos, CMS_RecipientInfo_type, CMS_RecipientInfo_ktri_get0_signer_id, CMS_RecipientInfo_ktri_cert_cmp, CMS_RecipientInfo_set0_pkey, CMS_RecipientInfo_kekri_get0_id, CMS_RecipientInfo_kari_set0_pkey_and_peer, CMS_RecipientInfo_kari_set0_pkey, CMS_RecipientInfo_kekri_id_cmp, CMS_RecipientInfo_set0_key, CMS_RecipientInfo_decrypt, CMS_RecipientInfo_encrypt - CMS envelopedData RecipientInfo routines

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-STACK_OF(CMS_RecipientInfo) *CMS_get0_RecipientInfos(CMS_ContentInfo *cms);
-int CMS_RecipientInfo_type(CMS_RecipientInfo *ri);
-
-int CMS_RecipientInfo_ktri_get0_signer_id(CMS_RecipientInfo *ri,
-                                          ASN1_OCTET_STRING **keyid,
-                                          X509_NAME **issuer,
-                                          ASN1_INTEGER **sno);
-int CMS_RecipientInfo_ktri_cert_cmp(CMS_RecipientInfo *ri, X509 *cert);
-int CMS_RecipientInfo_set0_pkey(CMS_RecipientInfo *ri, EVP_PKEY *pkey);
-int CMS_RecipientInfo_kari_set0_pkey_and_peer(CMS_RecipientInfo *ri,
-                                              EVP_PKEY *pk, X509 *peer);
-int CMS_RecipientInfo_kari_set0_pkey(CMS_RecipientInfo *ri, EVP_PKEY *pk);
-int CMS_RecipientInfo_kekri_get0_id(CMS_RecipientInfo *ri, X509_ALGOR **palg,
-                                    ASN1_OCTET_STRING **pid,
-                                    ASN1_GENERALIZEDTIME **pdate,
-                                    ASN1_OBJECT **potherid,
-                                    ASN1_TYPE **pothertype);
-int CMS_RecipientInfo_kekri_id_cmp(CMS_RecipientInfo *ri,
-                                   const unsigned char *id, size_t idlen);
-int CMS_RecipientInfo_set0_key(CMS_RecipientInfo *ri,
-                               unsigned char *key, size_t keylen);
-
-int CMS_RecipientInfo_decrypt(CMS_ContentInfo *cms, CMS_RecipientInfo *ri);
-int CMS_RecipientInfo_encrypt(CMS_ContentInfo *cms, CMS_RecipientInfo *ri);
- -

DESCRIPTION

- -

The function CMS_get0_RecipientInfos() returns all the CMS_RecipientInfo structures associated with a CMS EnvelopedData structure.

- -

CMS_RecipientInfo_type() returns the type of CMS_RecipientInfo structure ri. It will currently return CMS_RECIPINFO_TRANS, CMS_RECIPINFO_AGREE, CMS_RECIPINFO_KEK, CMS_RECIPINFO_PASS, or CMS_RECIPINFO_OTHER.

- -

CMS_RecipientInfo_ktri_get0_signer_id() retrieves the certificate recipient identifier associated with a specific CMS_RecipientInfo structure ri, which must be of type CMS_RECIPINFO_TRANS. Either the keyidentifier will be set in keyid or both issuer name and serial number in issuer and sno.

- -

CMS_RecipientInfo_ktri_cert_cmp() compares the certificate cert against the CMS_RecipientInfo structure ri, which must be of type CMS_RECIPINFO_TRANS. It returns zero if the comparison is successful and non zero if not.

- -

CMS_RecipientInfo_set0_pkey() associates the private key pkey with the CMS_RecipientInfo structure ri, which must be of type CMS_RECIPINFO_TRANS.

- -

CMS_RecipientInfo_kari_set0_pkey_and_peer() associates the private key pkey and peer certificate peer with the CMS_RecipientInfo structure ri, which must be of type CMS_RECIPINFO_AGREE.

- -

CMS_RecipientInfo_kari_set0_pkey() associates the private key pkey with the CMS_RecipientInfo structure ri, which must be of type CMS_RECIPINFO_AGREE.

- -

CMS_RecipientInfo_kekri_get0_id() retrieves the key information from the CMS_RecipientInfo structure ri which must be of type CMS_RECIPINFO_KEK. Any of the remaining parameters can be NULL if the application is not interested in the value of a field. Where a field is optional and absent NULL will be written to the corresponding parameter. The keyEncryptionAlgorithm field is written to palg, the keyIdentifier field is written to pid, the date field if present is written to pdate, if the other field is present the components keyAttrId and keyAttr are written to parameters potherid and pothertype.

- -

CMS_RecipientInfo_kekri_id_cmp() compares the ID in the id and idlen parameters against the keyIdentifier CMS_RecipientInfo structure ri, which must be of type CMS_RECIPINFO_KEK. It returns zero if the comparison is successful and non zero if not.

- -

CMS_RecipientInfo_set0_key() associates the symmetric key key of length keylen with the CMS_RecipientInfo structure ri, which must be of type CMS_RECIPINFO_KEK.

- -

CMS_RecipientInfo_decrypt() attempts to decrypt CMS_RecipientInfo structure ri in structure cms. A key must have been associated with the structure first.

- -

CMS_RecipientInfo_encrypt() attempts to encrypt CMS_RecipientInfo structure ri in structure cms. A key must have been associated with the structure first and the content encryption key must be available: for example by a previous call to CMS_RecipientInfo_decrypt().

- -

NOTES

- -

The main purpose of these functions is to enable an application to lookup recipient keys using any appropriate technique when the simpler method of CMS_decrypt() is not appropriate.

- -

In typical usage and application will retrieve all CMS_RecipientInfo structures using CMS_get0_RecipientInfos() and check the type of each using CMS_RecipientInfo_type(). Depending on the type the CMS_RecipientInfo structure can be ignored or its key identifier data retrieved using an appropriate function. Then if the corresponding secret or private key can be obtained by any appropriate means it can then associated with the structure and CMS_RecipientInfo_decrypt() called. If successful CMS_decrypt() can be called with a NULL key to decrypt the enveloped content.

- -

The CMS_RecipientInfo_encrypt() can be used to add a new recipient to an existing enveloped data structure. Typically an application will first decrypt an appropriate CMS_RecipientInfo structure to make the content encrypt key available, it will then add a new recipient using a function such as CMS_add1_recipient_cert() and finally encrypt the content encryption key using CMS_RecipientInfo_encrypt().

- -

RETURN VALUES

- -

CMS_get0_RecipientInfos() returns all CMS_RecipientInfo structures, or NULL if an error occurs.

- -

CMS_RecipientInfo_ktri_get0_signer_id(), CMS_RecipientInfo_set0_pkey(), CMS_RecipientInfo_kekri_get0_id(), CMS_RecipientInfo_set0_key() and CMS_RecipientInfo_decrypt() return 1 for success or 0 if an error occurs. CMS_RecipientInfo_encrypt() return 1 for success or 0 if an error occurs.

- -

CMS_RecipientInfo_ktri_cert_cmp() and CMS_RecipientInfo_kekri_cmp() return 0 for a successful comparison and non zero otherwise.

- -

Any error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), CMS_decrypt(3)

- -

HISTORY

- -

CMS_RecipientInfo_kari_set0_pkey_and_peer and CMS_RecipientInfo_kari_set0_pkey were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2008-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_get0_SignerInfos.html b/openssl-install/share/doc/openssl/html/man3/CMS_get0_SignerInfos.html deleted file mode 100644 index dad949ea..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_get0_SignerInfos.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -CMS_get0_SignerInfos - - - - - - - - - - -

NAME

- -

CMS_SignerInfo_set1_signer_cert, CMS_get0_SignerInfos, CMS_SignerInfo_get0_signer_id, CMS_SignerInfo_get0_signature, CMS_SignerInfo_cert_cmp - CMS signedData signer functions

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-STACK_OF(CMS_SignerInfo) *CMS_get0_SignerInfos(CMS_ContentInfo *cms);
-
-int CMS_SignerInfo_get0_signer_id(CMS_SignerInfo *si, ASN1_OCTET_STRING **keyid,
-                                  X509_NAME **issuer, ASN1_INTEGER **sno);
-ASN1_OCTET_STRING *CMS_SignerInfo_get0_signature(CMS_SignerInfo *si);
-int CMS_SignerInfo_cert_cmp(CMS_SignerInfo *si, X509 *cert);
-void CMS_SignerInfo_set1_signer_cert(CMS_SignerInfo *si, X509 *signer);
- -

DESCRIPTION

- -

The function CMS_get0_SignerInfos() returns all the CMS_SignerInfo structures associated with a CMS signedData structure.

- -

CMS_SignerInfo_get0_signer_id() retrieves the certificate signer identifier associated with a specific CMS_SignerInfo structure si. Either the keyidentifier will be set in keyid or both issuer name and serial number in issuer and sno.

- -

CMS_SignerInfo_get0_signature() retrieves the signature associated with si in a pointer to an ASN1_OCTET_STRING structure. This pointer returned corresponds to the internal signature value if si so it may be read or modified.

- -

CMS_SignerInfo_cert_cmp() compares the certificate cert against the signer identifier si. It returns zero if the comparison is successful and non zero if not.

- -

CMS_SignerInfo_set1_signer_cert() sets the signers certificate of si to signer.

- -

NOTES

- -

The main purpose of these functions is to enable an application to lookup signers certificates using any appropriate technique when the simpler method of CMS_verify() is not appropriate.

- -

In typical usage and application will retrieve all CMS_SignerInfo structures using CMS_get0_SignerInfo() and retrieve the identifier information using CMS. It will then obtain the signer certificate by some unspecified means (or return and error if it cannot be found) and set it using CMS_SignerInfo_set1_signer_cert().

- -

Once all signer certificates have been set CMS_verify() can be used.

- -

Although CMS_get0_SignerInfos() can return NULL if an error occurs or if there are no signers this is not a problem in practice because the only error which can occur is if the cms structure is not of type signedData due to application error.

- -

RETURN VALUES

- -

CMS_get0_SignerInfos() returns all CMS_SignerInfo structures, or NULL there are no signers or an error occurs.

- -

CMS_SignerInfo_get0_signer_id() returns 1 for success and 0 for failure.

- -

CMS_SignerInfo_cert_cmp() returns 0 for a successful comparison and non zero otherwise.

- -

CMS_SignerInfo_set1_signer_cert() does not return a value.

- -

Any error can be obtained from ERR_get_error(3)

- -

SEE ALSO

- -

ERR_get_error(3), CMS_verify(3)

- -

COPYRIGHT

- -

Copyright 2008-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_get0_type.html b/openssl-install/share/doc/openssl/html/man3/CMS_get0_type.html deleted file mode 100644 index 3bac4fc3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_get0_type.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -CMS_get0_type - - - - - - - - - - -

NAME

- -

CMS_get0_type, CMS_set1_eContentType, CMS_get0_eContentType, CMS_get0_content - get and set CMS content types and content

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-const ASN1_OBJECT *CMS_get0_type(const CMS_ContentInfo *cms);
-int CMS_set1_eContentType(CMS_ContentInfo *cms, const ASN1_OBJECT *oid);
-const ASN1_OBJECT *CMS_get0_eContentType(CMS_ContentInfo *cms);
-ASN1_OCTET_STRING **CMS_get0_content(CMS_ContentInfo *cms);
- -

DESCRIPTION

- -

CMS_get0_type() returns the content type of a CMS_ContentInfo structure as an ASN1_OBJECT pointer. An application can then decide how to process the CMS_ContentInfo structure based on this value.

- -

CMS_set1_eContentType() sets the embedded content type of a CMS_ContentInfo structure. It should be called with CMS functions (such as CMS_sign(3), CMS_encrypt(3)) with the CMS_PARTIAL flag and before the structure is finalised, otherwise the results are undefined.

- -

ASN1_OBJECT *CMS_get0_eContentType() returns a pointer to the embedded content type.

- -

CMS_get0_content() returns a pointer to the ASN1_OCTET_STRING pointer containing the embedded content.

- -

NOTES

- -

As the 0 implies CMS_get0_type(), CMS_get0_eContentType() and CMS_get0_content() return internal pointers which should not be freed up. CMS_set1_eContentType() copies the supplied OID and it should be freed up after use.

- -

The ASN1_OBJECT values returned can be converted to an integer NID value using OBJ_obj2nid(). For the currently supported content types the following values are returned:

- -
NID_pkcs7_data
-NID_pkcs7_signed
-NID_pkcs7_digest
-NID_id_smime_ct_compressedData:
-NID_pkcs7_encrypted
-NID_pkcs7_enveloped
- -

The return value of CMS_get0_content() is a pointer to the ASN1_OCTET_STRING content pointer. That means that for example:

- -
ASN1_OCTET_STRING **pconf = CMS_get0_content(cms);
- -

*pconf could be NULL if there is no embedded content. Applications can access, modify or create the embedded content in a CMS_ContentInfo structure using this function. Applications usually will not need to modify the embedded content as it is normally set by higher level functions.

- -

RETURN VALUES

- -

CMS_get0_type() and CMS_get0_eContentType() return an ASN1_OBJECT structure.

- -

CMS_set1_eContentType() returns 1 for success or 0 if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_get1_ReceiptRequest.html b/openssl-install/share/doc/openssl/html/man3/CMS_get1_ReceiptRequest.html deleted file mode 100644 index 5707ee20..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_get1_ReceiptRequest.html +++ /dev/null @@ -1,92 +0,0 @@ - - - - -CMS_get1_ReceiptRequest - - - - - - - - - - -

NAME

- -

CMS_ReceiptRequest_create0_ex, CMS_ReceiptRequest_create0, CMS_add1_ReceiptRequest, CMS_get1_ReceiptRequest, CMS_ReceiptRequest_get0_values - CMS signed receipt request functions

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ReceiptRequest *CMS_ReceiptRequest_create0_ex(
-    unsigned char *id, int idlen, int allorfirst,
-    STACK_OF(GENERAL_NAMES) *receiptList, STACK_OF(GENERAL_NAMES) *receiptsTo,
-    OSSL_LIB_CTX *libctx);
-CMS_ReceiptRequest *CMS_ReceiptRequest_create0(
-    unsigned char *id, int idlen, int allorfirst,
-    STACK_OF(GENERAL_NAMES) *receiptList, STACK_OF(GENERAL_NAMES) *receiptsTo);
-int CMS_add1_ReceiptRequest(CMS_SignerInfo *si, CMS_ReceiptRequest *rr);
-int CMS_get1_ReceiptRequest(CMS_SignerInfo *si, CMS_ReceiptRequest **prr);
-void CMS_ReceiptRequest_get0_values(CMS_ReceiptRequest *rr, ASN1_STRING **pcid,
-                                    int *pallorfirst,
-                                    STACK_OF(GENERAL_NAMES) **plist,
-                                    STACK_OF(GENERAL_NAMES) **prto);
- -

DESCRIPTION

- -

CMS_ReceiptRequest_create0_ex() creates a signed receipt request structure. The signedContentIdentifier field is set using id and idlen, or it is set to 32 bytes of pseudo random data if id is NULL. If receiptList is NULL the allOrFirstTier option in receiptsFrom is used and set to the value of the allorfirst parameter. If receiptList is not NULL the receiptList option in receiptsFrom is used. The receiptsTo parameter specifies the receiptsTo field value. The library context libctx is used to find the public random generator.

- -

CMS_ReceiptRequest_create0() is similar to CMS_ReceiptRequest_create0_ex() but uses default values of NULL for the library context libctx.

- -

The CMS_add1_ReceiptRequest() function adds a signed receipt request rr to SignerInfo structure si.

- -

int CMS_get1_ReceiptRequest() looks for a signed receipt request in si, if any is found it is decoded and written to prr.

- -

CMS_ReceiptRequest_get0_values() retrieves the values of a receipt request. The signedContentIdentifier is copied to pcid. If the allOrFirstTier option of receiptsFrom is used its value is copied to pallorfirst otherwise the receiptList field is copied to plist. The receiptsTo parameter is copied to prto.

- -

NOTES

- -

For more details of the meaning of the fields see RFC2634.

- -

The contents of a signed receipt should only be considered meaningful if the corresponding CMS_ContentInfo structure can be successfully verified using CMS_verify().

- -

RETURN VALUES

- -

CMS_ReceiptRequest_create0_ex() and CMS_ReceiptRequest_create0() return a signed receipt request structure or NULL if an error occurred.

- -

CMS_add1_ReceiptRequest() returns 1 for success or 0 if an error occurred.

- -

CMS_get1_ReceiptRequest() returns 1 is a signed receipt request is found and decoded. It returns 0 if a signed receipt request is not present and -1 if it is present but malformed.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_sign_receipt(3), CMS_verify(3) CMS_verify_receipt(3)

- -

HISTORY

- -

The function CMS_ReceiptRequest_create0_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2008-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_sign.html b/openssl-install/share/doc/openssl/html/man3/CMS_sign.html deleted file mode 100644 index 4af1cc0b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_sign.html +++ /dev/null @@ -1,114 +0,0 @@ - - - - -CMS_sign - - - - - - - - - - -

NAME

- -

CMS_sign, CMS_sign_ex - create a CMS SignedData structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *CMS_sign_ex(X509 *signcert, EVP_PKEY *pkey,
-                             STACK_OF(X509) *certs, BIO *data,
-                             unsigned int flags, OSSL_LIB_CTX *ctx,
-                             const char *propq);
-CMS_ContentInfo *CMS_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
-                          BIO *data, unsigned int flags);
- -

DESCRIPTION

- -

CMS_sign_ex() creates and returns a CMS SignedData structure. signcert is the certificate to sign with, pkey is the corresponding private key. certs is an optional additional set of certificates to include in the CMS structure (for example any intermediate CAs in the chain). The library context libctx and the property query propq are used when retrieving algorithms from providers. Any or all of these parameters can be NULL, see NOTES below.

- -

The data to be signed is read from BIO data.

- -

flags is an optional set of flags.

- -

CMS_sign() is similar to CMS_sign_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

NOTES

- -

Any of the following flags (ored together) can be passed in the flags parameter.

- -

Many S/MIME clients expect the signed content to include valid MIME headers. If the CMS_TEXT flag is set MIME headers for type text/plain are prepended to the data.

- -

If CMS_NOCERTS is set the signer's certificate will not be included in the CMS_ContentInfo structure, the signer's certificate must still be supplied in the signcert parameter though. This can reduce the size of the signature if the signers certificate can be obtained by other means: for example a previously signed message.

- -

The data being signed is included in the CMS_ContentInfo structure, unless CMS_DETACHED is set in which case it is omitted. This is used for CMS_ContentInfo detached signatures which are used in S/MIME plaintext signed messages for example.

- -

Normally the supplied content is translated into MIME canonical format (as required by the S/MIME specifications) if CMS_BINARY is set no translation occurs. This option should be used if the supplied data is in binary format otherwise the translation will corrupt it.

- -

The SignedData structure includes several CMS signedAttributes including the signing time, the CMS content type and the supported list of ciphers in an SMIMECapabilities attribute. If CMS_NOATTR is set then no signedAttributes will be used. If CMS_NOSMIMECAP is set then just the SMIMECapabilities are omitted.

- -

If present the SMIMECapabilities attribute indicates support for the following algorithms in preference order: 256 bit AES, Gost R3411-94, Gost 28147-89, 192 bit AES, 128 bit AES, triple DES, 128 bit RC2, 64 bit RC2, DES and 40 bit RC2. If any of these algorithms is not available then it will not be included: for example the GOST algorithms will not be included if the GOST ENGINE is not loaded.

- -

OpenSSL will by default identify signing certificates using issuer name and serial number. If CMS_USE_KEYID is set it will use the subject key identifier value instead. An error occurs if the signing certificate does not have a subject key identifier extension.

- -

If the flags CMS_STREAM is set then the returned CMS_ContentInfo structure is just initialized ready to perform the signing operation. The signing is however not performed and the data to be signed is not read from the data parameter. Signing is deferred until after the data has been written. In this way data can be signed in a single pass.

- -

If the CMS_PARTIAL flag is set a partial CMS_ContentInfo structure is output to which additional signers and capabilities can be added before finalization.

- -

If the flag CMS_STREAM is set the returned CMS_ContentInfo structure is not complete and outputting its contents via a function that does not properly finalize the CMS_ContentInfo structure will give unpredictable results.

- -

Several functions including SMIME_write_CMS(), i2d_CMS_bio_stream(), PEM_write_bio_CMS_stream() finalize the structure. Alternatively finalization can be performed by obtaining the streaming ASN1 BIO directly using BIO_new_CMS().

- -

If a signer is specified it will use the default digest for the signing algorithm. This is SHA256 for both RSA and DSA keys.

- -

If signcert and pkey are NULL then a certificates only CMS structure is output.

- -

The function CMS_sign() is a basic CMS signing function whose output will be suitable for many purposes. For finer control of the output format the certs, signcert and pkey parameters can all be NULL and the CMS_PARTIAL flag set. Then one or more signers can be added using the function CMS_add1_signer(), non default digests can be used and custom attributes added. CMS_final() must then be called to finalize the structure if streaming is not enabled.

- -

BUGS

- -

Some attributes such as counter signatures are not supported.

- -

RETURN VALUES

- -

CMS_sign_ex() and CMS_sign() return either a valid CMS_ContentInfo structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), CMS_verify(3)

- -

HISTORY

- -

The CMS_STREAM flag is only supported for detached data in OpenSSL 0.9.8, it is supported for embedded data in OpenSSL 1.0.0 and later.

- -

The CMS_sign_ex() method was added in OpenSSL 3.0.

- -

Since OpenSSL 3.2, CMS_sign_ex() and CMS_sign() ignore any duplicate certificates in their certs argument and no longer throw an error for them.

- -

COPYRIGHT

- -

Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_sign_receipt.html b/openssl-install/share/doc/openssl/html/man3/CMS_sign_receipt.html deleted file mode 100644 index 8481a2d2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_sign_receipt.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -CMS_sign_receipt - - - - - - - - - - -

NAME

- -

CMS_sign_receipt - create a CMS signed receipt

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, X509 *signcert,
-                                  EVP_PKEY *pkey, STACK_OF(X509) *certs,
-                                  unsigned int flags);
- -

DESCRIPTION

- -

CMS_sign_receipt() creates and returns a CMS signed receipt structure. si is the CMS_SignerInfo structure containing the signed receipt request. signcert is the certificate to sign with, pkey is the corresponding private key. certs is an optional additional set of certificates to include in the CMS structure (for example any intermediate CAs in the chain).

- -

flags is an optional set of flags.

- -

NOTES

- -

This functions behaves in a similar way to CMS_sign() except the flag values CMS_DETACHED, CMS_BINARY, CMS_NOATTR, CMS_TEXT and CMS_STREAM are not supported since they do not make sense in the context of signed receipts.

- -

RETURN VALUES

- -

CMS_sign_receipt() returns either a valid CMS_ContentInfo structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), CMS_verify_receipt(3), CMS_sign(3)

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_signed_get_attr.html b/openssl-install/share/doc/openssl/html/man3/CMS_signed_get_attr.html deleted file mode 100644 index 55643ef7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_signed_get_attr.html +++ /dev/null @@ -1,170 +0,0 @@ - - - - -CMS_signed_get_attr - - - - - - - - - - -

NAME

- -

CMS_signed_get_attr_count, CMS_signed_get_attr_by_NID, CMS_signed_get_attr_by_OBJ, CMS_signed_get_attr, CMS_signed_delete_attr, CMS_signed_add1_attr, CMS_signed_add1_attr_by_OBJ, CMS_signed_add1_attr_by_NID, CMS_signed_add1_attr_by_txt, CMS_signed_get0_data_by_OBJ, CMS_unsigned_get_attr_count, CMS_unsigned_get_attr_by_NID, CMS_unsigned_get_attr_by_OBJ, CMS_unsigned_get_attr, CMS_unsigned_delete_attr, CMS_unsigned_add1_attr, CMS_unsigned_add1_attr_by_OBJ, CMS_unsigned_add1_attr_by_NID, CMS_unsigned_add1_attr_by_txt, CMS_unsigned_get0_data_by_OBJ - CMS signed and unsigned attribute functions

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_signed_get_attr_count(const CMS_SignerInfo *si);
-int CMS_signed_get_attr_by_NID(const CMS_SignerInfo *si, int nid,
-                               int lastpos);
-int CMS_signed_get_attr_by_OBJ(const CMS_SignerInfo *si, const ASN1_OBJECT *obj,
-                               int lastpos);
-X509_ATTRIBUTE *CMS_signed_get_attr(const CMS_SignerInfo *si, int loc);
-X509_ATTRIBUTE *CMS_signed_delete_attr(CMS_SignerInfo *si, int loc);
-int CMS_signed_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr);
-int CMS_signed_add1_attr_by_OBJ(CMS_SignerInfo *si,
-                                const ASN1_OBJECT *obj, int type,
-                                const void *bytes, int len);
-int CMS_signed_add1_attr_by_NID(CMS_SignerInfo *si,
-                                int nid, int type,
-                                const void *bytes, int len);
-int CMS_signed_add1_attr_by_txt(CMS_SignerInfo *si,
-                                const char *attrname, int type,
-                                const void *bytes, int len);
-void *CMS_signed_get0_data_by_OBJ(const CMS_SignerInfo *si,
-                                  const ASN1_OBJECT *oid,
-                                  int lastpos, int type);
-
-int CMS_unsigned_get_attr_count(const CMS_SignerInfo *si);
-int CMS_unsigned_get_attr_by_NID(const CMS_SignerInfo *si, int nid,
-                                 int lastpos);
-int CMS_unsigned_get_attr_by_OBJ(const CMS_SignerInfo *si,
-                                 const ASN1_OBJECT *obj, int lastpos);
-X509_ATTRIBUTE *CMS_unsigned_get_attr(const CMS_SignerInfo *si, int loc);
-X509_ATTRIBUTE *CMS_unsigned_delete_attr(CMS_SignerInfo *si, int loc);
-int CMS_unsigned_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr);
-int CMS_unsigned_add1_attr_by_OBJ(CMS_SignerInfo *si,
-                                  const ASN1_OBJECT *obj, int type,
-                                  const void *bytes, int len);
-int CMS_unsigned_add1_attr_by_NID(CMS_SignerInfo *si,
-                                  int nid, int type,
-                                  const void *bytes, int len);
-int CMS_unsigned_add1_attr_by_txt(CMS_SignerInfo *si,
-                                  const char *attrname, int type,
-                                  const void *bytes, int len);
-void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid,
-                                    int lastpos, int type);
- -

DESCRIPTION

- -

CMS_signerInfo contains separate attribute lists for signed and unsigned attributes. Each CMS_signed_XXX() function is used for signed attributes, and each CMS_unsigned_XXX() function is used for unsigned attributes. Since the CMS_unsigned_XXX() functions work in the same way as the CMS_signed_XXX() equivalents, only the CMS_signed_XXX() functions are described below.

- -

CMS_signed_get_attr_by_OBJ() finds the location of the first matching object obj in the SignerInfo's si signed attribute list. The search starts at the position after lastpos. If the returned value is positive then it can be used on the next call to CMS_signed_get_attr_by_OBJ() as the value of lastpos in order to iterate through the remaining attributes. lastpos can be set to any negative value on the first call, in order to start searching from the start of the signed attribute list.

- -

CMS_signed_get_attr_by_NID() is similar to CMS_signed_get_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

CMS_signed_get_attr() returns the X509_ATTRIBUTE object at index loc in the si signed attribute list. loc should be in the range from 0 to CMS_signed_get_attr_count() - 1.

- -

CMS_signed_delete_attr() removes the X509_ATTRIBUTE object at index loc in the si signed attribute list. An error occurs if the si attribute list is NULL.

- -

CMS_signed_add1_attr() pushes a copy of the passed in X509_ATTRIBUTE object to the si signed attribute list. A new signed attribute list is created if required. An error occurs if attr is NULL.

- -

CMS_signed_add1_attr_by_OBJ() creates a new signed X509_ATTRIBUTE using X509_ATTRIBUTE_set1_object() and X509_ATTRIBUTE_set1_data() to assign a new obj with type type and data bytes of length len and then pushes it to the key object's attribute list.

- -

CMS_signed_add1_attr_by_NID() is similar to CMS_signed_add1_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

CMS_signed_add1_attr_by_txt() is similar to CMS_signed_add1_attr_by_OBJ() except that it passes a name attrname associated with the object. See <openssl/obj_mac.h> for a list of SN_* names.

- -

CMS_signed_get0_data_by_OBJ() finds the first attribute in a si signed attributes list that matches the obj starting at index lastpos and returns the data retrieved from the found attributes first ASN1_TYPE object. An error will occur if the attribute type type does not match the type of the ASN1_TYPE object OR if type is either V_ASN1_BOOLEAN or V_ASN1_NULL OR the attribute is not found. If lastpos is less than -1 then an error will occur if there are multiple objects in the signed attribute list that match obj. If lastpos is less than -2 then an error will occur if there is more than one ASN1_TYPE object in the found signed attribute.

- -

Refer to X509_ATTRIBUTE(3) for information related to attributes.

- -

RETURN VALUES

- -

The CMS_unsigned_XXX() functions return values are similar to those of the equivalent CMS_signed_XXX() functions.

- -

CMS_signed_get_attr_count() returns the number of signed attributes in the SignerInfo si, or -1 if the signed attribute list is NULL.

- -

CMS_signed_get_attr_by_OBJ() returns -1 if either the signed attribute list of si is empty OR if obj is not found, otherwise it returns the location of the obj in the SignerInfo's si signed attribute list.

- -

CMS_signed_get_attr_by_NID() is similar to CMS_signed_get_attr_by_OBJ() except that it returns -2 if the nid is not known by OpenSSL.

- -

CMS_signed_get_attr() returns either a signed X509_ATTRIBUTE or NULL on error.

- -

CMS_signed_delete_attr() returns either the removed signed X509_ATTRIBUTE or NULL if there is a error.

- -

CMS_signed_add1_attr(), CMS_signed_add1_attr_by_OBJ(), CMS_signed_add1_attr_by_NID(), CMS_signed_add1_attr_by_txt(), return 1 on success or 0 on error.

- -

CMS_signed_get0_data_by_OBJ() returns the data retrieved from the found signed attributes first ASN1_TYPE object, or NULL if an error occurs.

- -

NOTES

- -

Some attributes are added automatically during the signing process.

- -

Calling CMS_SignerInfo_sign() adds the NID_pkcs9_signingTime signed attribute.

- -

Calling CMS_final(), CMS_final_digest() or CMS_dataFinal() adds the NID_pkcs9_messageDigest signed attribute.

- -

The NID_pkcs9_contentType signed attribute is always added if the NID_pkcs9_signingTime attribute is added.

- -

Calling CMS_sign_ex(), CMS_sign_receipt() or CMS_add1_signer() may add attributes depending on the flags parameter. See CMS_add1_signer(3) for more information.

- -

OpenSSL applies special rules for the following attribute NIDs:

- -
- -
CMS Signed Attributes
-
- -

NID_pkcs9_contentType NID_pkcs9_messageDigest NID_pkcs9_signingTime

- -
-
ESS Signed Attributes
-
- -

NID_id_smime_aa_signingCertificate NID_id_smime_aa_signingCertificateV2 NID_id_smime_aa_receiptRequest

- -
-
CMS Unsigned Attributes
-
- -

NID_pkcs9_countersignature

- -
-
- -

CMS_signed_add1_attr(), CMS_signed_add1_attr_by_OBJ(), CMS_signed_add1_attr_by_NID(), CMS_signed_add1_attr_by_txt() and the equivalent CMS_unsigned_add1_attrXXX() functions allow duplicate attributes to be added. The attribute rules are not checked during these function calls, and are deferred until the sign or verify process (i.e. during calls to any of CMS_sign_ex(), CMS_sign(), CMS_sign_receipt(), CMS_add1_signer(), CMS_Final(), CMS_dataFinal(), CMS_final_digest(), CMS_verify(), CMS_verify_receipt() or CMS_SignedData_verify()).

- -

For CMS attribute rules see RFC 5652 Section 11. For ESS attribute rules see RFC 2634 Section 1.3.4 and RFC 5035 Section 5.4.

- -

SEE ALSO

- -

X509_ATTRIBUTE(3)

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_uncompress.html b/openssl-install/share/doc/openssl/html/man3/CMS_uncompress.html deleted file mode 100644 index e0df32e7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_uncompress.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -CMS_uncompress - - - - - - - - - - -

NAME

- -

CMS_uncompress - uncompress a CMS CompressedData structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_uncompress(CMS_ContentInfo *cms, BIO *dcont, BIO *out, unsigned int flags);
- -

DESCRIPTION

- -

CMS_uncompress() extracts and uncompresses the content from a CMS CompressedData structure cms. data is a BIO to write the content to and flags is an optional set of flags.

- -

The dcont parameter is used in the rare case where the compressed content is detached. It will normally be set to NULL.

- -

NOTES

- -

The only currently supported compression algorithm is zlib: if the structure indicates the use of any other algorithm an error is returned.

- -

If zlib support is not compiled into OpenSSL then CMS_uncompress() will always return an error.

- -

The following flags can be passed in the flags parameter.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are deleted from the content. If the content is not of type text/plain then an error is returned.

- -

RETURN VALUES

- -

CMS_uncompress() returns either 1 for success or 0 for failure. The error can be obtained from ERR_get_error(3)

- -

BUGS

- -

The lack of single pass processing and the need to hold all data in memory as mentioned in CMS_verify() also applies to CMS_decompress().

- -

SEE ALSO

- -

ERR_get_error(3), CMS_compress(3)

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_verify.html b/openssl-install/share/doc/openssl/html/man3/CMS_verify.html deleted file mode 100644 index b3cb3440..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_verify.html +++ /dev/null @@ -1,128 +0,0 @@ - - - - -CMS_verify - - - - - - - - - - -

NAME

- -

CMS_verify, CMS_SignedData_verify, CMS_get0_signers - verify a CMS SignedData structure

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, X509_STORE *store,
-               BIO *detached_data, BIO *out, unsigned int flags);
-BIO *CMS_SignedData_verify(CMS_SignedData *sd, BIO *detached_data,
-                           STACK_OF(X509) *scerts, X509_STORE *store,
-                           STACK_OF(X509) *extra, STACK_OF(X509_CRL) *crls,
-                           unsigned int flags,
-                           OSSL_LIB_CTX *libctx, const char *propq);
-
-STACK_OF(X509) *CMS_get0_signers(CMS_ContentInfo *cms);
- -

DESCRIPTION

- -

CMS_verify() is very similar to PKCS7_verify(3). It verifies a CMS SignedData structure contained in a structure of type CMS_ContentInfo. cms points to the CMS_ContentInfo structure to verify. The optional certs parameter refers to a set of certificates in which to search for signing certificates. It is also used as a source of untrusted intermediate CA certificates for chain building. cms may contain extra untrusted CA certificates that may be used for chain building as well as CRLs that may be used for certificate validation. store may be NULL or point to the trusted certificate store to use for chain verification. detached_data refers to the signed data if the content is detached from cms. Otherwise detached_data should be NULL and the signed data must be in cms. The content is written to the BIO out unless it is NULL. flags is an optional set of flags, which can be used to modify the operation.

- -

CMS_SignedData_verify() is like CMS_verify() except that it operates on CMS SignedData input in the sd argument, it has some additional parameters described next, and on success it returns the verified content as a memory BIO. The optional extra parameter may be used to provide untrusted CA certificates that may be helpful for chain building in certificate validation. This list of certificates must not contain duplicates. The optional crls parameter may be used to provide extra CRLs. Also the list of CRLs must not contain duplicates. The optional parameters library context libctx and property query propq are used when retrieving algorithms from providers.

- -

CMS_get0_signers() retrieves the signing certificate(s) from cms; it may only be called after a successful CMS_verify() or CMS_SignedData_verify() operation.

- -

VERIFY PROCESS

- -

Normally the verify process proceeds as follows.

- -

Initially some sanity checks are performed on cms. The type of cms must be SignedData. There must be at least one signature on the data and if the content is detached detached_data cannot be NULL.

- -

An attempt is made to locate all the signing certificate(s), first looking in the certs parameter (if it is not NULL) and then looking in any certificates contained in the cms structure unless CMS_NOINTERN is set. If any signing certificate cannot be located the operation fails.

- -

Each signing certificate is chain verified using the smimesign purpose and using the trusted certificate store store if supplied. Any internal certificates in the message, which may have been added using CMS_add1_cert(3), are used as untrusted CAs. If CRL checking is enabled in store and CMS_NOCRL is not set, any internal CRLs, which may have been added using CMS_add1_crl(3), are used in addition to attempting to look them up in store. If store is not NULL and any chain verify fails an error code is returned.

- -

Finally the signed content is read (and written to out unless it is NULL) and the signature is checked.

- -

If all signatures verify correctly then the function is successful.

- -

Any of the following flags (ored together) can be passed in the flags parameter to change the default verify behaviour.

- -

If CMS_NOINTERN is set the certificates in the message itself are not searched when locating the signing certificate(s). This means that all the signing certificates must be in the certs parameter.

- -

If CMS_NOCRL is set and CRL checking is enabled in store then any CRLs in the message itself and provided via the crls parameter are ignored.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are deleted from the content. If the content is not of type text/plain then an error is returned.

- -

If CMS_NO_SIGNER_CERT_VERIFY is set the signing certificates are not chain verified, unless CMS_CADES flag is also set.

- -

If CMS_NO_ATTR_VERIFY is set the signed attributes signature is not verified, unless CMS_CADES flag is also set.

- -

If CMS_CADES is set, each signer certificate is checked against the ESS signingCertificate or ESS signingCertificateV2 extension that is required in the signed attributes of the signature.

- -

If CMS_NO_CONTENT_VERIFY is set then the content digest is not checked.

- -

NOTES

- -

One application of CMS_NOINTERN is to only accept messages signed by a small number of certificates. The acceptable certificates would be passed in the certs parameter. In this case if the signer certificate is not one of the certificates supplied in certs then the verify will fail because the signer cannot be found.

- -

In some cases the standard techniques for looking up and validating certificates are not appropriate: for example an application may wish to lookup certificates in a database or perform customised verification. This can be achieved by setting and verifying the signer certificates manually using the signed data utility functions.

- -

Care should be taken when modifying the default verify behaviour, for example setting CMS_NO_CONTENT_VERIFY will totally disable all content verification and any modified content will be considered valid. This combination is however useful if one merely wishes to write the content to out and its validity is not considered important.

- -

Chain verification should arguably be performed using the signing time rather than the current time. However, since the signing time is supplied by the signer it cannot be trusted without additional evidence (such as a trusted timestamp).

- -

RETURN VALUES

- -

CMS_verify() returns 1 for a successful verification and 0 if an error occurred.

- -

CMS_SignedData_verify() returns a memory BIO containing the verified content, or NULL on error.

- -

CMS_get0_signers() returns all signers or NULL if an error occurred.

- -

The error can be obtained from ERR_get_error(3).

- -

BUGS

- -

The trusted certificate store is not searched for the signing certificate. This is primarily due to the inadequacies of the current X509_STORE functionality.

- -

The lack of single pass processing means that the signed content must all be held in memory if it is not detached.

- -

SEE ALSO

- -

PKCS7_verify(3), CMS_add1_cert(3), CMS_add1_crl(3), OSSL_ESS_check_signing_certs(3), ERR_get_error(3), CMS_sign(3)

- -

HISTORY

- -

CMS_SignedData_verify() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2008-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CMS_verify_receipt.html b/openssl-install/share/doc/openssl/html/man3/CMS_verify_receipt.html deleted file mode 100644 index cf3ca128..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CMS_verify_receipt.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -CMS_verify_receipt - - - - - - - - - - -

NAME

- -

CMS_verify_receipt - verify a CMS signed receipt

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms,
-                       STACK_OF(X509) *certs, X509_STORE *store,
-                       unsigned int flags);
- -

DESCRIPTION

- -

CMS_verify_receipt() verifies a CMS signed receipt. rcms is the signed receipt to verify. ocms is the original SignedData structure containing the receipt request. certs is a set of certificates in which to search for the signing certificate. store is a trusted certificate store (used for chain verification).

- -

flags is an optional set of flags, which can be used to modify the verify operation.

- -

NOTES

- -

This functions behaves in a similar way to CMS_verify() except the flag values CMS_DETACHED, CMS_BINARY, CMS_TEXT and CMS_STREAM are not supported since they do not make sense in the context of signed receipts.

- -

RETURN VALUES

- -

CMS_verify_receipt() returns 1 for a successful verification and zero if an error occurred.

- -

The error can be obtained from ERR_get_error(3)

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign_receipt(3), CMS_verify(3),

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/COMP_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/COMP_CTX_new.html deleted file mode 100644 index 14f2b55e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/COMP_CTX_new.html +++ /dev/null @@ -1,151 +0,0 @@ - - - - -COMP_CTX_new - - - - - - - - - - -

NAME

- -

COMP_CTX_new, COMP_CTX_get_method, COMP_CTX_get_type, COMP_get_type, COMP_get_name, COMP_CTX_free, COMP_compress_block, COMP_expand_block, COMP_zlib, COMP_zlib_oneshot, COMP_brotli, COMP_brotli_oneshot, COMP_zstd, COMP_zstd_oneshot, BIO_f_zlib, BIO_f_brotli, BIO_f_zstd - Compression support

- -

SYNOPSIS

- -
#include <openssl/comp.h>
-
-COMP_CTX *COMP_CTX_new(COMP_METHOD *meth);
-void COMP_CTX_free(COMP_CTX *ctx);
-const COMP_METHOD *COMP_CTX_get_method(const COMP_CTX *ctx);
-int COMP_CTX_get_type(const COMP_CTX* comp);
-int COMP_get_type(const COMP_METHOD *meth);
-const char *COMP_get_name(const COMP_METHOD *meth);
-
-int COMP_compress_block(COMP_CTX *ctx, unsigned char *out, int olen,
-                        unsigned char *in, int ilen);
-int COMP_expand_block(COMP_CTX *ctx, unsigned char *out, int olen,
-                      unsigned char *in, int ilen);
-
-COMP_METHOD *COMP_zlib(void);
-COMP_METHOD *COMP_zlib_oneshot(void);
-COMP_METHOD *COMP_brotli(void);
-COMP_METHOD *COMP_brotli_oneshot(void);
-COMP_METHOD *COMP_zstd(void);
-COMP_METHOD *COMP_zstd_oneshot(void);
-
-const BIO_METHOD *BIO_f_zlib(void);
-const BIO_METHOD *BIO_f_brotli(void);
-const BIO_METHOD *BIO_f_zstd(void);
- -

DESCRIPTION

- -

These functions provide compression support for OpenSSL. Compression is used within the OpenSSL library to support TLS record and certificate compression.

- -

COMP_CTX_new() is used to create a new COMP_CTX structure used to compress data.

- -

COMP_CTX_free() is used to free the returned COMP_CTX. If the argument is NULL, nothing is done.

- -

COMP_CTX_get_method() returns the COMP_METHOD of the given ctx.

- -

COMP_CTX_get_type() and COMP_get_type() return the NID for the COMP_CTX and COMP_METHOD, respectively. COMP_get_name() returns the name of the algorithm of the given COMP_METHOD.

- -

COMP_compress_block() compresses b<ilen> bytes from the buffer in into the buffer b<out> of size olen using the algorithm specified by ctx.

- -

COMP_expand_block() expands ilen bytes from the buffer in into the buffer out of size olen using the algorithm specified by ctx.

- -

Methods (COMP_METHOD) may be specified by one of these functions. These functions will be available even if their corresponding compression algorithm is not configured into the OpenSSL library. In such a case, NULL will be returned.

- - - -

BIO_f_zlib(), BIO_f_brotli() BIO_f_zstd() each return a BIO_METHOD that may be used to create a BIO via BIO_new(3) to read and write compressed files or streams. The functions are only available if the corresponding algorithm is compiled into the OpenSSL library. NULL may be returned if the algorithm fails to load dynamically.

- -

NOTES

- -

While compressing non-compressible data, the output may be larger than the input. Care should be taken to size output buffers appropriate for both compression and expansion.

- -

Compression support and compression algorithms must be enabled and built into the library before use. Refer to the INSTALL.md file when configuring OpenSSL.

- -

ZLIB may be found at https://zlib.net

- -

Brotli may be found at https://github.com/google/brotli.

- -

Zstandard may be found at https://github.com/facebook/zstd.

- -

Compression of SSL/TLS records is not recommended, as it has been shown to lead to the CRIME attack https://en.wikipedia.org/wiki/CRIME. It is disabled by default, and may be enabled by clearing the SSL_OP_NO_COMPRESSION option and setting the security level as appropriate. See the documentation for the SSL_CTX_set_options(3) and SSL_set_options(3) functions.

- -

Compression is also used to support certificate compression as described in RFC8879 https://datatracker.ietf.org/doc/html/rfc8879. It may be disabled via the SSL_OP_NO_TX_CERTIFICATE_COMPRESSION and SSL_OP_NO_RX_CERTIFICATE_COMPRESSION options of the SSL_CTX_set_options(3) or SSL_set_options(3) functions.

- -

COMP_zlib(), COMP_brotli() and COMP_zstd() are stream-based compression methods. Internal state (including compression dictionary) is maintained between calls. If an error is returned, the stream is corrupted, and should be closed.

- -

COMP_zlib_oneshot(), COMP_brotli_oneshot() and COMP_zstd_oneshot() are not stream-based. These methods do not maintain state between calls. An error in one call does not affect future calls.

- -

RETURN VALUES

- -

COMP_CTX_new() returns a COMP_CTX on success, or NULL on failure.

- -

COMP_CTX_get_method(), COMP_zlib(), COMP_zlib_oneshot(), COMP_brotli(), COMP_brotli_oneshot(), COMP_zstd(), and COMP_zstd_oneshot() return a COMP_METHOD on success, or NULL on failure.

- -

COMP_CTX_get_type() and COMP_get_type() return a NID value. On failure, NID_undef is returned.

- -

COMP_compress_block() and COMP_expand_block() return the number of bytes stored in the output buffer out. This may be 0. On failure, -1 is returned.

- -

COMP_get_name() returns a const char * that must not be freed on success, or NULL on failure.

- -

BIO_f_zlib(), BIO_f_brotli() and BIO_f_zstd() return NULL on error, and a BIO_METHOD on success.

- -

SEE ALSO

- -

BIO_new(3), SSL_CTX_set_options(3), SSL_set_options(3)

- -

HISTORY

- -

Brotli and Zstandard functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CONF_modules_free.html b/openssl-install/share/doc/openssl/html/man3/CONF_modules_free.html deleted file mode 100644 index 73c9aa07..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CONF_modules_free.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -CONF_modules_free - - - - - - - - - - -

NAME

- -

CONF_modules_free, CONF_modules_finish, CONF_modules_unload - OpenSSL configuration cleanup functions

- -

SYNOPSIS

- -
#include <openssl/conf.h>
-
-void CONF_modules_finish(void);
-void CONF_modules_unload(int all);
- -

The following functions have been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void CONF_modules_free(void);
- -

DESCRIPTION

- -

CONF_modules_free() closes down and frees up all memory allocated by all configuration modules. Normally, in versions of OpenSSL prior to 1.1.0, applications called CONF_modules_free() at exit to tidy up any configuration performed.

- -

CONF_modules_finish() calls each configuration modules finish handler to free up any configuration that module may have performed.

- -

CONF_modules_unload() finishes and unloads configuration modules. If all is set to 0 only modules loaded from DSOs will be unloads. If all is 1 all modules, including built-in modules will be unloaded.

- -

RETURN VALUES

- -

None of the functions return a value.

- -

SEE ALSO

- -

config(5), OPENSSL_config(3), CONF_modules_load_file_ex(3)

- -

HISTORY

- -

CONF_modules_free() was deprecated in OpenSSL 1.1.0; do not use it. For more information see OPENSSL_init_crypto(3).

- -

COPYRIGHT

- -

Copyright 2004-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CONF_modules_load_file.html b/openssl-install/share/doc/openssl/html/man3/CONF_modules_load_file.html deleted file mode 100644 index a0a34e20..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CONF_modules_load_file.html +++ /dev/null @@ -1,144 +0,0 @@ - - - - -CONF_modules_load_file - - - - - - - - - - -

NAME

- -

CONF_get1_default_config_file, CONF_modules_load_file_ex, CONF_modules_load_file, CONF_modules_load - OpenSSL configuration functions

- -

SYNOPSIS

- -
#include <openssl/conf.h>
-
-char *CONF_get1_default_config_file(void);
-int CONF_modules_load_file_ex(OSSL_LIB_CTX *libctx, const char *filename,
-                              const char *appname, unsigned long flags);
-int CONF_modules_load_file(const char *filename, const char *appname,
-                           unsigned long flags);
-int CONF_modules_load(const CONF *cnf, const char *appname,
-                      unsigned long flags);
- -

DESCRIPTION

- -

The function CONF_get1_default_config_file() determines the default configuration file pathname as follows. If the OPENSSL_CONF environment variable is set its value is returned. Else the function returns the path obtained using X509_get_default_cert_area(3) with the filename "openssl.cnf" appended. The caller is responsible for freeing any string returned.

- -

The function CONF_modules_load_file_ex() configures OpenSSL using library context libctx file filename and application name appname. If filename is NULL the standard OpenSSL configuration file is used as determined by calling CONF_get1_default_config_file(). If appname is NULL the standard OpenSSL application name openssl_conf is used. The behaviour can be customized using flags. Note that, the error suppressing can be overridden by config_diagnostics as described in config(5).

- -

CONF_modules_load_file() is the same as CONF_modules_load_file_ex() but has a NULL library context.

- -

CONF_modules_load() is identical to CONF_modules_load_file() except it reads configuration information from cnf.

- -

NOTES

- -

The following flags are currently recognized:

- -

If CONF_MFLAGS_IGNORE_ERRORS is set errors returned by individual configuration modules are ignored. If not set the first module error is considered fatal and no further modules are loaded.

- -

Normally any modules errors will add error information to the error queue. If CONF_MFLAGS_SILENT is set no error information is added.

- -

If CONF_MFLAGS_IGNORE_RETURN_CODES is set the function unconditionally returns success. This is used by default in OPENSSL_init_crypto(3) to ignore any errors in the default system-wide configuration file, as having all OpenSSL applications fail to start when there are potentially minor issues in the file is too risky. Applications calling CONF_modules_load_file_ex explicitly should not generally set this flag.

- -

If CONF_MFLAGS_NO_DSO is set configuration module loading from DSOs is disabled.

- -

CONF_MFLAGS_IGNORE_MISSING_FILE if set will make CONF_load_modules_file() ignore missing configuration files. Normally a missing configuration file return an error.

- -

CONF_MFLAGS_DEFAULT_SECTION if set and appname is not NULL will use the default section pointed to by openssl_conf if appname does not exist.

- -

By using CONF_modules_load_file_ex() with appropriate flags an application can customise application configuration to best suit its needs. In some cases the use of a configuration file is optional and its absence is not an error: in this case CONF_MFLAGS_IGNORE_MISSING_FILE would be set.

- -

Errors during configuration may also be handled differently by different applications. For example in some cases an error may simply print out a warning message and the application continue. In other cases an application might consider a configuration file error as fatal and exit immediately.

- -

Applications can use the CONF_modules_load() function if they wish to load a configuration file themselves and have finer control over how errors are treated.

- -

RETURN VALUES

- -

These functions return 1 for success and a zero or negative value for failure. If module errors are not ignored the return code will reflect the return value of the failing module (this will always be zero or negative).

- -

EXAMPLES

- -

Load a configuration file and print out any errors and exit (missing file considered fatal):

- -
if (CONF_modules_load_file_ex(libctx, NULL, NULL, 0) <= 0) {
-    fprintf(stderr, "FATAL: error loading configuration file\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
- -

Load default configuration file using the section indicated by "myapp", tolerate missing files, but exit on other errors:

- -
if (CONF_modules_load_file_ex(NULL, NULL, "myapp",
-                              CONF_MFLAGS_IGNORE_MISSING_FILE) <= 0) {
-    fprintf(stderr, "FATAL: error loading configuration file\n");
-    ERR_print_errors_fp(stderr);
-    exit(1);
-}
- -

Load custom configuration file and section, only print warnings on error, missing configuration file ignored:

- -
if (CONF_modules_load_file_ex(NULL, "/something/app.cnf", "myapp",
-                              CONF_MFLAGS_IGNORE_MISSING_FILE) <= 0) {
-    fprintf(stderr, "WARNING: error loading configuration file\n");
-    ERR_print_errors_fp(stderr);
-}
- -

Load and parse configuration file manually, custom error handling:

- -
FILE *fp;
-CONF *cnf = NULL;
-long eline;
-
-fp = fopen("/somepath/app.cnf", "r");
-if (fp == NULL) {
-    fprintf(stderr, "Error opening configuration file\n");
-    /* Other missing configuration file behaviour */
-} else {
-    cnf = NCONF_new_ex(libctx, NULL);
-    if (NCONF_load_fp(cnf, fp, &eline) == 0) {
-        fprintf(stderr, "Error on line %ld of configuration file\n", eline);
-        ERR_print_errors_fp(stderr);
-        /* Other malformed configuration file behaviour */
-    } else if (CONF_modules_load(cnf, "appname", 0) <= 0) {
-        fprintf(stderr, "Error configuring application\n");
-        ERR_print_errors_fp(stderr);
-        /* Other configuration error behaviour */
-    }
-    fclose(fp);
-    NCONF_free(cnf);
-}
- -

SEE ALSO

- -

config(5), OPENSSL_config(3), NCONF_new_ex(3)

- -

COPYRIGHT

- -

Copyright 2004-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CRYPTO_THREAD_run_once.html b/openssl-install/share/doc/openssl/html/man3/CRYPTO_THREAD_run_once.html deleted file mode 100644 index e10de971..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CRYPTO_THREAD_run_once.html +++ /dev/null @@ -1,210 +0,0 @@ - - - - -CRYPTO_THREAD_run_once - - - - - - - - - - -

NAME

- -

CRYPTO_THREAD_run_once, CRYPTO_THREAD_lock_new, CRYPTO_THREAD_read_lock, CRYPTO_THREAD_write_lock, CRYPTO_THREAD_unlock, CRYPTO_THREAD_lock_free, CRYPTO_atomic_add, CRYPTO_atomic_add64, CRYPTO_atomic_and, CRYPTO_atomic_or, CRYPTO_atomic_load, CRYPTO_atomic_store, CRYPTO_atomic_load_int, OSSL_set_max_threads, OSSL_get_max_threads, OSSL_get_thread_support_flags, OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL, OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN - OpenSSL thread support

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-CRYPTO_ONCE CRYPTO_ONCE_STATIC_INIT;
-int CRYPTO_THREAD_run_once(CRYPTO_ONCE *once, void (*init)(void));
-
-CRYPTO_RWLOCK *CRYPTO_THREAD_lock_new(void);
-int CRYPTO_THREAD_read_lock(CRYPTO_RWLOCK *lock);
-int CRYPTO_THREAD_write_lock(CRYPTO_RWLOCK *lock);
-int CRYPTO_THREAD_unlock(CRYPTO_RWLOCK *lock);
-void CRYPTO_THREAD_lock_free(CRYPTO_RWLOCK *lock);
-
-int CRYPTO_atomic_add(int *val, int amount, int *ret, CRYPTO_RWLOCK *lock);
-int CRYPTO_atomic_add64(uint64_t *val, uint64_t op, uint64_t *ret,
-                        CRYPTO_RWLOCK *lock);
-int CRYPTO_atomic_and(uint64_t *val, uint64_t op, uint64_t *ret,
-                      CRYPTO_RWLOCK *lock);
-int CRYPTO_atomic_or(uint64_t *val, uint64_t op, uint64_t *ret,
-                     CRYPTO_RWLOCK *lock);
-int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock);
-int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock);
-int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock);
-
-int OSSL_set_max_threads(OSSL_LIB_CTX *ctx, uint64_t max_threads);
-uint64_t OSSL_get_max_threads(OSSL_LIB_CTX *ctx);
-uint32_t OSSL_get_thread_support_flags(void);
-
-#define OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL
-#define OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN
- -

DESCRIPTION

- -

OpenSSL can be safely used in multi-threaded applications provided that support for the underlying OS threading API is built-in. Currently, OpenSSL supports the pthread and Windows APIs. OpenSSL can also be built without any multi-threading support, for example on platforms that don't provide any threading support or that provide a threading API that is not yet supported by OpenSSL.

- -

The following multi-threading function are provided:

- - - -

RETURN VALUES

- -

CRYPTO_THREAD_run_once() returns 1 on success, or 0 on error.

- -

CRYPTO_THREAD_lock_new() returns the allocated lock, or NULL on error.

- -

CRYPTO_THREAD_lock_free() returns no value.

- -

OSSL_set_max_threads() returns 1 on success and 0 on failure. Returns failure if OpenSSL-managed thread pooling is not supported (for example, if it is not supported on the current platform, or because OpenSSL is not built with the necessary support).

- -

OSSL_get_max_threads() returns the maximum number of threads currently allowed to be used by the thread pool. If thread pooling is disabled or not available, returns 0.

- -

OSSL_get_thread_support_flags() returns zero or more OSSL_THREAD_SUPPORT_FLAG values.

- -

The other functions return 1 on success, or 0 on error.

- -

NOTES

- -

On Windows platforms the CRYPTO_THREAD_* types and functions in the <openssl/crypto.h> header are dependent on some of the types customarily made available by including <windows.h>. The application developer is likely to require control over when the latter is included, commonly as one of the first included headers. Therefore, it is defined as an application developer's responsibility to include <windows.h> prior to <openssl/crypto.h> where use of CRYPTO_THREAD_* types and functions is required.

- -

EXAMPLES

- -

You can find out if OpenSSL was configured with thread support:

- -
#include <openssl/opensslconf.h>
-#if defined(OPENSSL_THREADS)
-    /* thread support enabled */
-#else
-    /* no thread support */
-#endif
- -

This example safely initializes and uses a lock.

- -
#ifdef _WIN32
-# include <windows.h>
-#endif
-#include <openssl/crypto.h>
-
-static CRYPTO_ONCE once = CRYPTO_ONCE_STATIC_INIT;
-static CRYPTO_RWLOCK *lock;
-
-static void myinit(void)
-{
-    lock = CRYPTO_THREAD_lock_new();
-}
-
-static int mylock(void)
-{
-    if (!CRYPTO_THREAD_run_once(&once, void init) || lock == NULL)
-        return 0;
-    return CRYPTO_THREAD_write_lock(lock);
-}
-
-static int myunlock(void)
-{
-    return CRYPTO_THREAD_unlock(lock);
-}
-
-int serialized(void)
-{
-    int ret = 0;
-
-    if (!mylock()) {
-       /* Do not unlock unless the lock was successfully acquired. */
-       return 0;
-    }
-
-    /* Your code here, do not return without releasing the lock! */
-    ret = ... ;
-    myunlock();
-    return ret;
-}
- -

Finalization of locks is an advanced topic, not covered in this example. This can only be done at process exit or when a dynamically loaded library is no longer in use and is unloaded. The simplest solution is to just "leak" the lock in applications and not repeatedly load/unload shared libraries that allocate locks.

- -

SEE ALSO

- -

crypto(7), openssl-threads(7).

- -

HISTORY

- -

CRYPTO_atomic_store() was added in OpenSSL 3.4.0

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CRYPTO_get_ex_new_index.html b/openssl-install/share/doc/openssl/html/man3/CRYPTO_get_ex_new_index.html deleted file mode 100644 index 3430ebed..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CRYPTO_get_ex_new_index.html +++ /dev/null @@ -1,142 +0,0 @@ - - - - -CRYPTO_get_ex_new_index - - - - - - - - - - -

NAME

- -

CRYPTO_EX_new, CRYPTO_EX_free, CRYPTO_EX_dup, CRYPTO_free_ex_index, CRYPTO_get_ex_new_index, CRYPTO_alloc_ex_data, CRYPTO_set_ex_data, CRYPTO_get_ex_data, CRYPTO_free_ex_data, CRYPTO_new_ex_data - functions supporting application-specific data

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-int CRYPTO_get_ex_new_index(int class_index,
-                            long argl, void *argp,
-                            CRYPTO_EX_new *new_func,
-                            CRYPTO_EX_dup *dup_func,
-                            CRYPTO_EX_free *free_func);
-
-typedef void CRYPTO_EX_new(void *parent, void *ptr, CRYPTO_EX_DATA *ad,
-                           int idx, long argl, void *argp);
-typedef void CRYPTO_EX_free(void *parent, void *ptr, CRYPTO_EX_DATA *ad,
-                            int idx, long argl, void *argp);
-typedef int CRYPTO_EX_dup(CRYPTO_EX_DATA *to, const CRYPTO_EX_DATA *from,
-                          void **from_d, int idx, long argl, void *argp);
-
-int CRYPTO_new_ex_data(int class_index, void *obj, CRYPTO_EX_DATA *ad);
-
-int CRYPTO_alloc_ex_data(int class_index, void *obj, CRYPTO_EX_DATA *ad,
-                         int idx);
-
-int CRYPTO_set_ex_data(CRYPTO_EX_DATA *r, int idx, void *arg);
-
-void *CRYPTO_get_ex_data(const CRYPTO_EX_DATA *r, int idx);
-
-void CRYPTO_free_ex_data(int class_index, void *obj, CRYPTO_EX_DATA *r);
-
-int CRYPTO_free_ex_index(int class_index, int idx);
- -

DESCRIPTION

- -

Several OpenSSL structures can have application-specific data attached to them, known as "exdata." The specific structures are:

- -
BIO
-DH
-DSA
-EC_KEY
-ENGINE
-EVP_PKEY
-RSA
-SSL
-SSL_CTX
-SSL_SESSION
-UI
-UI_METHOD
-X509
-X509_STORE
-X509_STORE_CTX
- -

In addition, the APP name is reserved for use by application code.

- -

Each is identified by an CRYPTO_EX_INDEX_xxx define in the header file <openssl/crypto.h>. In addition, CRYPTO_EX_INDEX_APP is reserved for applications to use this facility for their own structures.

- -

The API described here is used by OpenSSL to manipulate exdata for specific structures. Since the application data can be anything at all it is passed and retrieved as a void * type.

- -

The CRYPTO_EX_DATA type is opaque. To initialize the exdata part of a structure, call CRYPTO_new_ex_data(). This is only necessary for CRYPTO_EX_INDEX_APP objects.

- -

Exdata types are identified by an index, an integer guaranteed to be unique within structures for the lifetime of the program. Applications using exdata typically call CRYPTO_get_ex_new_index at startup, and store the result in a global variable, or write a wrapper function to provide lazy evaluation. The class_index should be one of the CRYPTO_EX_INDEX_xxx values. The argl and argp parameters are saved to be passed to the callbacks but are otherwise not used. In order to transparently manipulate exdata, three callbacks must be provided. The semantics of those callbacks are described below.

- -

When copying or releasing objects with exdata, the callback functions are called in increasing order of their index value.

- -

If a dynamic library can be unloaded, it should call CRYPTO_free_ex_index() when this is done. This will replace the callbacks with no-ops so that applications don't crash. Any existing exdata will be leaked.

- -

To set or get the exdata on an object, the appropriate type-specific routine must be used. This is because the containing structure is opaque and the CRYPTO_EX_DATA field is not accessible. In both API's, the idx parameter should be an already-created index value.

- -

When setting exdata, the pointer specified with a particular index is saved, and returned on a subsequent "get" call. If the application is going to release the data, it must make sure to set a NULL value at the index, to avoid likely double-free crashes.

- -

The function CRYPTO_free_ex_data is used to free all exdata attached to a structure. The appropriate type-specific routine must be used. The class_index identifies the structure type, the obj is a pointer to the actual structure, and r is a pointer to the structure's exdata field.

- -

Callback Functions

- -

This section describes how the callback functions are used. Applications that are defining their own exdata using CYPRTO_EX_INDEX_APP must call them as described here.

- -

When a structure is initially allocated (such as RSA_new()) then the new_func() is called for every defined index. There is no requirement that the entire parent, or containing, structure has been set up. The new_func() is typically used only to allocate memory to store the exdata, and perhaps an "initialized" flag within that memory. The exdata value may be allocated later on with CRYPTO_alloc_ex_data(), or may be set by calling CRYPTO_set_ex_data().

- -

When a structure is free'd (such as SSL_CTX_free()) then the free_func() is called for every defined index. Again, the state of the parent structure is not guaranteed. The free_func() may be called with a NULL pointer.

- -

Both new_func() and free_func() take the same parameters. The parent is the pointer to the structure that contains the exdata. The ptr is the current exdata item; for new_func() this will typically be NULL. The r parameter is a pointer to the exdata field of the object. The idx is the index and is the value returned when the callbacks were initially registered via CRYPTO_get_ex_new_index() and can be used if the same callback handles different types of exdata.

- -

dup_func() is called when a structure is being copied. This is only done for SSL, SSL_SESSION, EC_KEY objects and BIO chains via BIO_dup_chain(). The to and from parameters are pointers to the destination and source CRYPTO_EX_DATA structures, respectively. The *from_d parameter is a pointer to the source exdata. When the dup_func() returns, the value in *from_d is copied to the destination ex_data. If the pointer contained in *pptr is not modified by the dup_func(), then both to and from will point to the same data. The idx, argl and argp parameters are as described for the other two callbacks. If the dup_func() returns 0 the whole CRYPTO_dup_ex_data() will fail.

- -

RETURN VALUES

- -

CRYPTO_get_ex_new_index() returns a new index or -1 on failure.

- -

CRYPTO_free_ex_index(), CRYPTO_alloc_ex_data() and CRYPTO_set_ex_data() return 1 on success or 0 on failure.

- -

CRYPTO_get_ex_data() returns the application data or NULL on failure; note that NULL may be a valid value.

- -

dup_func() should return 0 for failure and 1 for success.

- -

HISTORY

- -

CRYPTO_alloc_ex_data() was added in OpenSSL 3.0.

- -

The signature of the dup_func() callback was changed in OpenSSL 3.0 to use the type void ** for from_d. Previously this parameter was of type void *.

- -

Support for ENGINE "exdata" was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CRYPTO_memcmp.html b/openssl-install/share/doc/openssl/html/man3/CRYPTO_memcmp.html deleted file mode 100644 index 29120cec..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CRYPTO_memcmp.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -CRYPTO_memcmp - - - - - - - - - - -

NAME

- -

CRYPTO_memcmp - Constant time memory comparison

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-int CRYPTO_memcmp(const void *a, const void *b, size_t len);
- -

DESCRIPTION

- -

The CRYPTO_memcmp function compares the len bytes pointed to by a and b for equality. It takes an amount of time dependent on len, but independent of the contents of the memory regions pointed to by a and b.

- -

RETURN VALUES

- -

CRYPTO_memcmp() returns 0 if the memory regions are equal and nonzero otherwise.

- -

NOTES

- -

Unlike memcmp(2), this function cannot be used to order the two memory regions as the return value when they differ is undefined, other than being nonzero.

- -

COPYRIGHT

- -

Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_get0_log_by_id.html b/openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_get0_log_by_id.html deleted file mode 100644 index 5f80176e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_get0_log_by_id.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -CTLOG_STORE_get0_log_by_id - - - - - - - - - - -

NAME

- -

CTLOG_STORE_get0_log_by_id - Get a Certificate Transparency log from a CTLOG_STORE

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-const CTLOG *CTLOG_STORE_get0_log_by_id(const CTLOG_STORE *store,
-                                        const uint8_t *log_id,
-                                        size_t log_id_len);
- -

DESCRIPTION

- -

A Signed Certificate Timestamp (SCT) identifies the Certificate Transparency (CT) log that issued it using the log's LogID (see RFC 6962, Section 3.2). Therefore, it is useful to be able to look up more information about a log (e.g. its public key) using this LogID.

- -

CTLOG_STORE_get0_log_by_id() provides a way to do this. It will find a CTLOG in a CTLOG_STORE that has a given LogID.

- -

RETURN VALUES

- -

CTLOG_STORE_get0_log_by_id returns a CTLOG with the given LogID, if it exists in the given CTLOG_STORE, otherwise it returns NULL.

- -

SEE ALSO

- -

ct(7), CTLOG_STORE_new(3)

- -

HISTORY

- -

The CTLOG_STORE_get0_log_by_id() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_new.html b/openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_new.html deleted file mode 100644 index 3c0827ba..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CTLOG_STORE_new.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -CTLOG_STORE_new - - - - - - - - - - -

NAME

- -

CTLOG_STORE_new_ex, CTLOG_STORE_new, CTLOG_STORE_free, CTLOG_STORE_load_default_file, CTLOG_STORE_load_file - Create and populate a Certificate Transparency log list

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-CTLOG_STORE *CTLOG_STORE_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
-CTLOG_STORE *CTLOG_STORE_new(void);
-void CTLOG_STORE_free(CTLOG_STORE *store);
-
-int CTLOG_STORE_load_default_file(CTLOG_STORE *store);
-int CTLOG_STORE_load_file(CTLOG_STORE *store, const char *file);
- -

DESCRIPTION

- -

A CTLOG_STORE is a container for a list of CTLOGs (Certificate Transparency logs). The list can be loaded from one or more files and then searched by LogID (see RFC 6962, Section 3.2, for the definition of a LogID).

- -

CTLOG_STORE_new_ex() creates an empty list of CT logs associated with the library context libctx and the property query string propq.

- -

CTLOG_STORE_new() does the same thing as CTLOG_STORE_new_ex() but with the default library context and property query string.

- -

The CTLOG_STORE is then populated by CTLOG_STORE_load_default_file() or CTLOG_STORE_load_file(). CTLOG_STORE_load_default_file() loads from the default file, which is named ct_log_list.cnf in OPENSSLDIR (see the output of openssl-version(1)). This can be overridden using an environment variable named CTLOG_FILE. CTLOG_STORE_load_file() loads from a caller-specified file path instead. Both of these functions append any loaded CT logs to the CTLOG_STORE.

- -

The expected format of the file is:

- -
enabled_logs=foo,bar
-
-[foo]
-description = Log 1
-key = <base64-encoded DER SubjectPublicKeyInfo here>
-
-[bar]
-description = Log 2
-key = <base64-encoded DER SubjectPublicKeyInfo here>
- -

Once a CTLOG_STORE is no longer required, it should be passed to CTLOG_STORE_free(). This will delete all of the CTLOGs stored within, along with the CTLOG_STORE itself. If the argument is NULL, nothing is done.

- -

NOTES

- -

If there are any invalid CT logs in a file, they are skipped and the remaining valid logs will still be added to the CTLOG_STORE. A CT log will be considered invalid if it is missing a "key" or "description" field.

- -

RETURN VALUES

- -

Both CTLOG_STORE_load_default_file and CTLOG_STORE_load_file return 1 if all CT logs in the file are successfully parsed and loaded, 0 otherwise.

- -

SEE ALSO

- -

ct(7), CTLOG_STORE_get0_log_by_id(3), SSL_CTX_set_ctlog_list_file(3)

- -

HISTORY

- -

CTLOG_STORE_new_ex was added in OpenSSL 3.0. All other functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CTLOG_new.html b/openssl-install/share/doc/openssl/html/man3/CTLOG_new.html deleted file mode 100644 index 9b43494b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CTLOG_new.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -CTLOG_new - - - - - - - - - - -

NAME

- -

CTLOG_new_ex, CTLOG_new, CTLOG_new_from_base64, CTLOG_new_from_base64_ex, CTLOG_free, CTLOG_get0_name, CTLOG_get0_log_id, CTLOG_get0_public_key - encapsulates information about a Certificate Transparency log

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-CTLOG *CTLOG_new_ex(EVP_PKEY *public_key, const char *name,
-                    OSSL_LIB_CTX *libctx, const char *propq);
-CTLOG *CTLOG_new(EVP_PKEY *public_key, const char *name);
-
-int CTLOG_new_from_base64_ex(CTLOG **ct_log, const char *pkey_base64,
-                             const char *name, OSSL_LIB_CTX *libctx,
-                             const char *propq);
-int CTLOG_new_from_base64(CTLOG ** ct_log,
-                          const char *pkey_base64, const char *name);
-void CTLOG_free(CTLOG *log);
-const char *CTLOG_get0_name(const CTLOG *log);
-void CTLOG_get0_log_id(const CTLOG *log, const uint8_t **log_id,
-                       size_t *log_id_len);
-EVP_PKEY *CTLOG_get0_public_key(const CTLOG *log);
- -

DESCRIPTION

- -

CTLOG_new_ex() returns a new CTLOG that represents the Certificate Transparency (CT) log with the given public key and associates it with the library context libctx and property query string propq. A name must also be provided that can be used to help users identify this log. Ownership of the public key is transferred.

- -

CTLOG_new() does the same thing as CTLOG_new_ex() but with the default library context and the default property query string.

- -

CTLOG_new_from_base64_ex() also creates a new CTLOG, but takes the public key in base64-encoded DER form and sets the ct_log pointer to point to the new CTLOG. The base64 will be decoded and the public key parsed. The CTLOG will be associated with the given library context libctx and property query string propq.

- -

CTLOG_new_from_base64() does the same thing as CTLOG_new_from_base64_ex() except that the default library context and property query string are used.

- -

Regardless of whether CTLOG_new() or CTLOG_new_from_base64() is used, it is the caller's responsibility to pass the CTLOG to CTLOG_free() once it is no longer needed. This will delete it and, if created by CTLOG_new(), the EVP_PKEY that was passed to it. If the argument to CTLOG_free() is NULL, nothing is done.

- -

CTLOG_get0_name() returns the name of the log, as provided when the CTLOG was created. Ownership of the string remains with the CTLOG.

- -

CTLOG_get0_log_id() sets *log_id to point to a string containing that log's LogID (see RFC 6962). It sets *log_id_len to the length of that LogID. For a v1 CT log, the LogID will be a SHA-256 hash (i.e. 32 bytes long). Ownership of the string remains with the CTLOG.

- -

CTLOG_get0_public_key() returns the public key of the CT log. Ownership of the EVP_PKEY remains with the CTLOG.

- -

RETURN VALUES

- -

CTLOG_new() will return NULL if an error occurs.

- -

CTLOG_new_from_base64() will return 1 on success, 0 otherwise.

- -

SEE ALSO

- -

ct(7)

- -

HISTORY

- -

The functions CTLOG_new_ex() and CTLOG_new_from_base64_ex() were added in OpenSSL 3.0. All other functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/CT_POLICY_EVAL_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/CT_POLICY_EVAL_CTX_new.html deleted file mode 100644 index 5b2b9b55..00000000 --- a/openssl-install/share/doc/openssl/html/man3/CT_POLICY_EVAL_CTX_new.html +++ /dev/null @@ -1,132 +0,0 @@ - - - - -CT_POLICY_EVAL_CTX_new - - - - - - - - - - -

NAME

- -

CT_POLICY_EVAL_CTX_new_ex, CT_POLICY_EVAL_CTX_new, CT_POLICY_EVAL_CTX_free, CT_POLICY_EVAL_CTX_get0_cert, CT_POLICY_EVAL_CTX_set1_cert, CT_POLICY_EVAL_CTX_get0_issuer, CT_POLICY_EVAL_CTX_set1_issuer, CT_POLICY_EVAL_CTX_get0_log_store, CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE, CT_POLICY_EVAL_CTX_get_time, CT_POLICY_EVAL_CTX_set_time - Encapsulates the data required to evaluate whether SCTs meet a Certificate Transparency policy

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-CT_POLICY_EVAL_CTX *CT_POLICY_EVAL_CTX_new_ex(OSSL_LIB_CTX *libctx,
-                                              const char *propq);
-CT_POLICY_EVAL_CTX *CT_POLICY_EVAL_CTX_new(void);
-void CT_POLICY_EVAL_CTX_free(CT_POLICY_EVAL_CTX *ctx);
-X509* CT_POLICY_EVAL_CTX_get0_cert(const CT_POLICY_EVAL_CTX *ctx);
-int CT_POLICY_EVAL_CTX_set1_cert(CT_POLICY_EVAL_CTX *ctx, X509 *cert);
-X509* CT_POLICY_EVAL_CTX_get0_issuer(const CT_POLICY_EVAL_CTX *ctx);
-int CT_POLICY_EVAL_CTX_set1_issuer(CT_POLICY_EVAL_CTX *ctx, X509 *issuer);
-const CTLOG_STORE *CT_POLICY_EVAL_CTX_get0_log_store(const CT_POLICY_EVAL_CTX *ctx);
-void CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE(CT_POLICY_EVAL_CTX *ctx,
-                                               CTLOG_STORE *log_store);
-uint64_t CT_POLICY_EVAL_CTX_get_time(const CT_POLICY_EVAL_CTX *ctx);
-void CT_POLICY_EVAL_CTX_set_time(CT_POLICY_EVAL_CTX *ctx, uint64_t time_in_ms);
- -

DESCRIPTION

- -

A CT_POLICY_EVAL_CTX is used by functions that evaluate whether Signed Certificate Timestamps (SCTs) fulfil a Certificate Transparency (CT) policy. This policy may be, for example, that at least one valid SCT is available. To determine this, an SCT's timestamp and signature must be verified. This requires:

- - - -

The above requirements are met using the setters described below.

- -

CT_POLICY_EVAL_CTX_new_ex() creates an empty policy evaluation context and associates it with the given library context libctx and property query string propq.

- -

CT_POLICY_EVAL_CTX_new() does the same thing as CT_POLICY_EVAL_CTX_new_ex() except that it uses the default library context and property query string.

- -

The CT_POLICY_EVAL_CTX should then be populated using:

- - - -

Each setter has a matching getter for accessing the current value.

- -

When no longer required, the CT_POLICY_EVAL_CTX should be passed to CT_POLICY_EVAL_CTX_free() to delete it. If the argument to CT_POLICY_EVAL_CTX_free() is NULL, nothing is done.

- -

NOTES

- -

The issuer certificate only needs to be provided if at least one of the SCTs was issued for a pre-certificate. This will be the case for SCTs embedded in a certificate (i.e. those in an X.509 extension), but may not be the case for SCTs found in the TLS SCT extension or OCSP response.

- -

RETURN VALUES

- -

CT_POLICY_EVAL_CTX_new_ex() and CT_POLICY_EVAL_CTX_new() will return NULL if malloc fails.

- -

SEE ALSO

- -

ct(7)

- -

HISTORY

- -

CT_POLICY_EVAL_CTX_new_ex was added in OpenSSL 3.0. All other functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DEFINE_STACK_OF.html b/openssl-install/share/doc/openssl/html/man3/DEFINE_STACK_OF.html deleted file mode 100644 index a9332493..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DEFINE_STACK_OF.html +++ /dev/null @@ -1,206 +0,0 @@ - - - - -DEFINE_STACK_OF - - - - - - - - - - -

NAME

- -

DEFINE_STACK_OF, DEFINE_STACK_OF_CONST, DEFINE_SPECIAL_STACK_OF, DEFINE_SPECIAL_STACK_OF_CONST, sk_TYPE_num, sk_TYPE_value, sk_TYPE_new, sk_TYPE_new_null, sk_TYPE_reserve, sk_TYPE_free, sk_TYPE_zero, sk_TYPE_delete, sk_TYPE_delete_ptr, sk_TYPE_push, sk_TYPE_unshift, sk_TYPE_pop, sk_TYPE_shift, sk_TYPE_pop_free, sk_TYPE_insert, sk_TYPE_set, sk_TYPE_find, sk_TYPE_find_ex, sk_TYPE_find_all, sk_TYPE_sort, sk_TYPE_is_sorted, sk_TYPE_dup, sk_TYPE_deep_copy, sk_TYPE_set_cmp_func, sk_TYPE_new_reserve, OPENSSL_sk_deep_copy, OPENSSL_sk_delete, OPENSSL_sk_delete_ptr, OPENSSL_sk_dup, OPENSSL_sk_find, OPENSSL_sk_find_ex, OPENSSL_sk_find_all, OPENSSL_sk_free, OPENSSL_sk_insert, OPENSSL_sk_is_sorted, OPENSSL_sk_new, OPENSSL_sk_new_null, OPENSSL_sk_new_reserve, OPENSSL_sk_num, OPENSSL_sk_pop, OPENSSL_sk_pop_free, OPENSSL_sk_push, OPENSSL_sk_reserve, OPENSSL_sk_set, OPENSSL_sk_set_cmp_func, OPENSSL_sk_shift, OPENSSL_sk_sort, OPENSSL_sk_unshift, OPENSSL_sk_value, OPENSSL_sk_zero - stack container

- -

SYNOPSIS

- -
#include <openssl/safestack.h>
-
-STACK_OF(TYPE)
-DEFINE_STACK_OF(TYPE)
-DEFINE_STACK_OF_CONST(TYPE)
-DEFINE_SPECIAL_STACK_OF(FUNCTYPE, TYPE)
-DEFINE_SPECIAL_STACK_OF_CONST(FUNCTYPE, TYPE)
-
-typedef int (*sk_TYPE_compfunc)(const TYPE *const *a, const TYPE *const *b);
-typedef TYPE * (*sk_TYPE_copyfunc)(const TYPE *a);
-typedef void (*sk_TYPE_freefunc)(TYPE *a);
-
-int sk_TYPE_num(const STACK_OF(TYPE) *sk);
-TYPE *sk_TYPE_value(const STACK_OF(TYPE) *sk, int idx);
-STACK_OF(TYPE) *sk_TYPE_new(sk_TYPE_compfunc compare);
-STACK_OF(TYPE) *sk_TYPE_new_null(void);
-int sk_TYPE_reserve(STACK_OF(TYPE) *sk, int n);
-void sk_TYPE_free(STACK_OF(TYPE) *sk);
-void sk_TYPE_zero(STACK_OF(TYPE) *sk);
-TYPE *sk_TYPE_delete(STACK_OF(TYPE) *sk, int i);
-TYPE *sk_TYPE_delete_ptr(STACK_OF(TYPE) *sk, TYPE *ptr);
-int sk_TYPE_push(STACK_OF(TYPE) *sk, const TYPE *ptr);
-int sk_TYPE_unshift(STACK_OF(TYPE) *sk, const TYPE *ptr);
-TYPE *sk_TYPE_pop(STACK_OF(TYPE) *sk);
-TYPE *sk_TYPE_shift(STACK_OF(TYPE) *sk);
-void sk_TYPE_pop_free(STACK_OF(TYPE) *sk, sk_TYPE_freefunc freefunc);
-int sk_TYPE_insert(STACK_OF(TYPE) *sk, TYPE *ptr, int idx);
-TYPE *sk_TYPE_set(STACK_OF(TYPE) *sk, int idx, const TYPE *ptr);
-int sk_TYPE_find(STACK_OF(TYPE) *sk, TYPE *ptr);
-int sk_TYPE_find_ex(STACK_OF(TYPE) *sk, TYPE *ptr);
-int sk_TYPE_find_all(STACK_OF(TYPE) *sk, TYPE *ptr, int *pnum);
-void sk_TYPE_sort(const STACK_OF(TYPE) *sk);
-int sk_TYPE_is_sorted(const STACK_OF(TYPE) *sk);
-STACK_OF(TYPE) *sk_TYPE_dup(const STACK_OF(TYPE) *sk);
-STACK_OF(TYPE) *sk_TYPE_deep_copy(const STACK_OF(TYPE) *sk,
-                                  sk_TYPE_copyfunc copyfunc,
-                                  sk_TYPE_freefunc freefunc);
-sk_TYPE_compfunc (*sk_TYPE_set_cmp_func(STACK_OF(TYPE) *sk,
-                                        sk_TYPE_compfunc compare));
-STACK_OF(TYPE) *sk_TYPE_new_reserve(sk_TYPE_compfunc compare, int n);
- -

DESCRIPTION

- -

Applications can create and use their own stacks by placing any of the macros described below in a header file. These macros define typesafe inline functions that wrap around the utility OPENSSL_sk_ API. In the description here, TYPE is used as a placeholder for any of the OpenSSL datatypes, such as X509.

- -

The STACK_OF() macro returns the name for a stack of the specified TYPE. This is an opaque pointer to a structure declaration. This can be used in every header file that references the stack. There are several DEFINE... macros that create static inline functions for all of the functions described on this page. This should normally be used in one source file, and the stack manipulation is wrapped with application-specific functions.

- -

DEFINE_STACK_OF() creates set of functions for a stack of TYPE elements. The type is referenced by STACK_OF(TYPE) and each function name begins with sk_TYPE_. DEFINE_STACK_OF_CONST() is identical to DEFINE_STACK_OF() except each element is constant.

- -
/* DEFINE_STACK_OF(TYPE) */
-TYPE *sk_TYPE_value(STACK_OF(TYPE) *sk, int idx);
-/* DEFINE_STACK_OF_CONST(TYPE) */
-const TYPE *sk_TYPE_value(STACK_OF(TYPE) *sk, int idx);
- -

DEFINE_SPECIAL_STACK_OF() and DEFINE_SPECIAL_STACK_OF_CONST() are similar except FUNCNAME is used in the function names:

- -
/* DEFINE_SPECIAL_STACK_OF(TYPE, FUNCNAME) */
-TYPE *sk_FUNCNAME_value(STACK_OF(TYPE) *sk, int idx);
-/* DEFINE_SPECIAL_STACK_OF(TYPE, FUNCNAME) */
-const TYPE *sk_FUNCNAME_value(STACK_OF(TYPE) *sk, int idx);
- -

sk_TYPE_num() returns the number of elements in sk or -1 if sk is NULL.

- -

sk_TYPE_value() returns element idx in sk, where idx starts at zero. If idx is out of range then NULL is returned.

- -

sk_TYPE_new() allocates a new empty stack using comparison function compare. If compare is NULL then no comparison function is used. This function is equivalent to sk_TYPE_new_reserve(compare, 0).

- -

sk_TYPE_new_null() allocates a new empty stack with no comparison function. This function is equivalent to sk_TYPE_new_reserve(NULL, 0).

- -

sk_TYPE_reserve() allocates additional memory in the sk structure such that the next n calls to sk_TYPE_insert(), sk_TYPE_push() or sk_TYPE_unshift() will not fail or cause memory to be allocated or reallocated. If n is zero, any excess space allocated in the sk structure is freed. On error sk is unchanged.

- -

sk_TYPE_new_reserve() allocates a new stack. The new stack will have additional memory allocated to hold n elements if n is positive. The next n calls to sk_TYPE_insert(), sk_TYPE_push() or sk_TYPE_unshift() will not fail or cause memory to be allocated or reallocated. If n is zero or less than zero, no memory is allocated. sk_TYPE_new_reserve() also sets the comparison function compare to the newly created stack. If compare is NULL then no comparison function is used.

- -

sk_TYPE_set_cmp_func() sets the comparison function of sk to compare. The previous comparison function is returned or NULL if there was no previous comparison function.

- -

sk_TYPE_free() frees up the sk structure. It does not free up any elements of sk. After this call sk is no longer valid.

- -

sk_TYPE_zero() sets the number of elements in sk to zero. It does not free sk so after this call sk is still valid.

- -

sk_TYPE_pop_free() frees up all elements of sk and sk itself. The free function freefunc() is called on each element to free it.

- -

sk_TYPE_delete() deletes element i from sk. It returns the deleted element or NULL if i is out of range.

- -

sk_TYPE_delete_ptr() deletes element matching ptr from sk. It returns the deleted element or NULL if no element matching ptr was found.

- -

sk_TYPE_insert() inserts ptr into sk at position idx. Any existing elements at or after idx are moved downwards. If idx is out of range the new element is appended to sk. sk_TYPE_insert() either returns the number of elements in sk after the new element is inserted or zero if an error (such as memory allocation failure) occurred.

- -

sk_TYPE_push() appends ptr to sk it is equivalent to:

- -
sk_TYPE_insert(sk, ptr, -1);
- -

sk_TYPE_unshift() inserts ptr at the start of sk it is equivalent to:

- -
sk_TYPE_insert(sk, ptr, 0);
- -

sk_TYPE_pop() returns and removes the last element from sk.

- -

sk_TYPE_shift() returns and removes the first element from sk.

- -

sk_TYPE_set() sets element idx of sk to ptr replacing the current element. The new element value is returned or NULL if an error occurred: this will only happen if sk is NULL or idx is out of range.

- -

sk_TYPE_find() searches sk for the element ptr. In the case where no comparison function has been specified, the function performs a linear search for a pointer equal to ptr. The index of the first matching element is returned or -1 if there is no match. In the case where a comparison function has been specified, sk is sorted and sk_TYPE_find() returns the index of a matching element or -1 if there is no match. Note that, in this case the comparison function will usually compare the values pointed to rather than the pointers themselves and the order of elements in sk can change.

- -

sk_TYPE_find_ex() operates like sk_TYPE_find() except when a comparison function has been specified and no matching element is found. Instead of returning -1, sk_TYPE_find_ex() returns the index of the element either before or after the location where ptr would be if it were present in sk. The function also does not guarantee that the first matching element in the sorted stack is returned.

- -

sk_TYPE_find_all() operates like sk_TYPE_find() but it also sets the *pnum to number of matching elements in the stack. In case no comparison function has been specified the *pnum will be always set to 1 if matching element was found, 0 otherwise.

- -

sk_TYPE_sort() sorts sk using the supplied comparison function.

- -

sk_TYPE_is_sorted() returns 1 if sk is sorted and 0 otherwise.

- -

sk_TYPE_dup() returns a shallow copy of sk or an empty stack if the passed stack is NULL. Note the pointers in the copy are identical to the original.

- -

sk_TYPE_deep_copy() returns a new stack where each element has been copied or an empty stack if the passed stack is NULL. Copying is performed by the supplied copyfunc() and freeing by freefunc(). The function freefunc() is only called if an error occurs.

- -

NOTES

- -

Care should be taken when accessing stacks in multi-threaded environments. Any operation which increases the size of a stack such as sk_TYPE_insert() or sk_TYPE_push() can "grow" the size of an internal array and cause race conditions if the same stack is accessed in a different thread. Operations such as sk_TYPE_find() and sk_TYPE_sort() can also reorder the stack.

- -

Any comparison function supplied should use a metric suitable for use in a binary search operation. That is it should return zero, a positive or negative value if a is equal to, greater than or less than b respectively.

- -

Care should be taken when checking the return values of the functions sk_TYPE_find() and sk_TYPE_find_ex(). They return an index to the matching element. In particular 0 indicates a matching first element. A failed search is indicated by a -1 return value.

- -

STACK_OF(), DEFINE_STACK_OF(), DEFINE_STACK_OF_CONST(), and DEFINE_SPECIAL_STACK_OF() are implemented as macros.

- -

It is not an error to call sk_TYPE_num(), sk_TYPE_value(), sk_TYPE_free(), sk_TYPE_zero(), sk_TYPE_pop_free(), sk_TYPE_delete(), sk_TYPE_delete_ptr(), sk_TYPE_pop(), sk_TYPE_shift(), sk_TYPE_find(), sk_TYPE_find_ex(), and sk_TYPE_find_all() on a NULL stack, empty stack, or with an invalid index. An error is not raised in these conditions.

- -

The underlying utility OPENSSL_sk_ API should not be used directly. It defines these functions: OPENSSL_sk_deep_copy(), OPENSSL_sk_delete(), OPENSSL_sk_delete_ptr(), OPENSSL_sk_dup(), OPENSSL_sk_find(), OPENSSL_sk_find_ex(), OPENSSL_sk_find_all(), OPENSSL_sk_free(), OPENSSL_sk_insert(), OPENSSL_sk_is_sorted(), OPENSSL_sk_new(), OPENSSL_sk_new_null(), OPENSSL_sk_new_reserve(), OPENSSL_sk_num(), OPENSSL_sk_pop(), OPENSSL_sk_pop_free(), OPENSSL_sk_push(), OPENSSL_sk_reserve(), OPENSSL_sk_set(), OPENSSL_sk_set_cmp_func(), OPENSSL_sk_shift(), OPENSSL_sk_sort(), OPENSSL_sk_unshift(), OPENSSL_sk_value(), OPENSSL_sk_zero().

- -

RETURN VALUES

- -

sk_TYPE_num() returns the number of elements in the stack or -1 if the passed stack is NULL.

- -

sk_TYPE_value() returns a pointer to a stack element or NULL if the index is out of range.

- -

sk_TYPE_new(), sk_TYPE_new_null() and sk_TYPE_new_reserve() return an empty stack or NULL if an error occurs.

- -

sk_TYPE_reserve() returns 1 on successful allocation of the required memory or 0 on error.

- -

sk_TYPE_set_cmp_func() returns the old comparison function or NULL if there was no old comparison function.

- -

sk_TYPE_free(), sk_TYPE_zero(), sk_TYPE_pop_free() and sk_TYPE_sort() do not return values.

- -

sk_TYPE_pop(), sk_TYPE_shift(), sk_TYPE_delete() and sk_TYPE_delete_ptr() return a pointer to the deleted element or NULL on error.

- -

sk_TYPE_insert(), sk_TYPE_push() and sk_TYPE_unshift() return the total number of elements in the stack and 0 if an error occurred.

- -

sk_TYPE_set() returns a pointer to the replacement element or NULL on error.

- -

sk_TYPE_find() and sk_TYPE_find_ex() return an index to the found element or -1 on error.

- -

sk_TYPE_is_sorted() returns 1 if the stack is sorted and 0 if it is not.

- -

sk_TYPE_dup() and sk_TYPE_deep_copy() return a pointer to the copy of the stack or NULL on error.

- -

HISTORY

- -

Before OpenSSL 1.1.0, this was implemented via macros and not inline functions and was not a public API.

- -

sk_TYPE_reserve() and sk_TYPE_new_reserve() were added in OpenSSL 1.1.1.

- -

From OpenSSL 3.2.0, the sk_TYPE_find(), sk_TYPE_find_ex() and sk_TYPE_find_all() calls are read-only and do not sort the stack. To avoid any performance implications this change introduces, sk_TYPE_sort() should be called before these find operations.

- -

Before OpenSSL 3.3.0 sk_TYPE_push() returned -1 if sk was NULL. It was changed to return 0 in this condition as for other errors.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DES_random_key.html b/openssl-install/share/doc/openssl/html/man3/DES_random_key.html deleted file mode 100644 index 30fcc594..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DES_random_key.html +++ /dev/null @@ -1,225 +0,0 @@ - - - - -DES_random_key - - - - - - - - - - -

NAME

- -

DES_random_key, DES_set_key, DES_key_sched, DES_set_key_checked, DES_set_key_unchecked, DES_set_odd_parity, DES_is_weak_key, DES_ecb_encrypt, DES_ecb2_encrypt, DES_ecb3_encrypt, DES_ncbc_encrypt, DES_cfb_encrypt, DES_ofb_encrypt, DES_pcbc_encrypt, DES_cfb64_encrypt, DES_ofb64_encrypt, DES_xcbc_encrypt, DES_ede2_cbc_encrypt, DES_ede2_cfb64_encrypt, DES_ede2_ofb64_encrypt, DES_ede3_cbc_encrypt, DES_ede3_cfb64_encrypt, DES_ede3_ofb64_encrypt, DES_cbc_cksum, DES_quad_cksum, DES_string_to_key, DES_string_to_2keys, DES_fcrypt, DES_crypt - DES encryption

- -

SYNOPSIS

- -
#include <openssl/des.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void DES_random_key(DES_cblock *ret);
-
-int DES_set_key(const_DES_cblock *key, DES_key_schedule *schedule);
-int DES_key_sched(const_DES_cblock *key, DES_key_schedule *schedule);
-int DES_set_key_checked(const_DES_cblock *key, DES_key_schedule *schedule);
-void DES_set_key_unchecked(const_DES_cblock *key, DES_key_schedule *schedule);
-
-void DES_set_odd_parity(DES_cblock *key);
-int DES_is_weak_key(const_DES_cblock *key);
-
-void DES_ecb_encrypt(const_DES_cblock *input, DES_cblock *output,
-                     DES_key_schedule *ks, int enc);
-void DES_ecb2_encrypt(const_DES_cblock *input, DES_cblock *output,
-                      DES_key_schedule *ks1, DES_key_schedule *ks2, int enc);
-void DES_ecb3_encrypt(const_DES_cblock *input, DES_cblock *output,
-                      DES_key_schedule *ks1, DES_key_schedule *ks2,
-                      DES_key_schedule *ks3, int enc);
-
-void DES_ncbc_encrypt(const unsigned char *input, unsigned char *output,
-                      long length, DES_key_schedule *schedule, DES_cblock *ivec,
-                      int enc);
-void DES_cfb_encrypt(const unsigned char *in, unsigned char *out,
-                     int numbits, long length, DES_key_schedule *schedule,
-                     DES_cblock *ivec, int enc);
-void DES_ofb_encrypt(const unsigned char *in, unsigned char *out,
-                     int numbits, long length, DES_key_schedule *schedule,
-                     DES_cblock *ivec);
-void DES_pcbc_encrypt(const unsigned char *input, unsigned char *output,
-                      long length, DES_key_schedule *schedule, DES_cblock *ivec,
-                      int enc);
-void DES_cfb64_encrypt(const unsigned char *in, unsigned char *out,
-                       long length, DES_key_schedule *schedule, DES_cblock *ivec,
-                       int *num, int enc);
-void DES_ofb64_encrypt(const unsigned char *in, unsigned char *out,
-                       long length, DES_key_schedule *schedule, DES_cblock *ivec,
-                       int *num);
-
-void DES_xcbc_encrypt(const unsigned char *input, unsigned char *output,
-                      long length, DES_key_schedule *schedule, DES_cblock *ivec,
-                      const_DES_cblock *inw, const_DES_cblock *outw, int enc);
-
-void DES_ede2_cbc_encrypt(const unsigned char *input, unsigned char *output,
-                          long length, DES_key_schedule *ks1,
-                          DES_key_schedule *ks2, DES_cblock *ivec, int enc);
-void DES_ede2_cfb64_encrypt(const unsigned char *in, unsigned char *out,
-                            long length, DES_key_schedule *ks1,
-                            DES_key_schedule *ks2, DES_cblock *ivec,
-                            int *num, int enc);
-void DES_ede2_ofb64_encrypt(const unsigned char *in, unsigned char *out,
-                            long length, DES_key_schedule *ks1,
-                            DES_key_schedule *ks2, DES_cblock *ivec, int *num);
-
-void DES_ede3_cbc_encrypt(const unsigned char *input, unsigned char *output,
-                          long length, DES_key_schedule *ks1,
-                          DES_key_schedule *ks2, DES_key_schedule *ks3,
-                          DES_cblock *ivec, int enc);
-void DES_ede3_cfb64_encrypt(const unsigned char *in, unsigned char *out,
-                            long length, DES_key_schedule *ks1,
-                            DES_key_schedule *ks2, DES_key_schedule *ks3,
-                            DES_cblock *ivec, int *num, int enc);
-void DES_ede3_ofb64_encrypt(const unsigned char *in, unsigned char *out,
-                            long length, DES_key_schedule *ks1,
-                            DES_key_schedule *ks2, DES_key_schedule *ks3,
-                            DES_cblock *ivec, int *num);
-
-DES_LONG DES_cbc_cksum(const unsigned char *input, DES_cblock *output,
-                       long length, DES_key_schedule *schedule,
-                       const_DES_cblock *ivec);
-DES_LONG DES_quad_cksum(const unsigned char *input, DES_cblock output[],
-                        long length, int out_count, DES_cblock *seed);
-void DES_string_to_key(const char *str, DES_cblock *key);
-void DES_string_to_2keys(const char *str, DES_cblock *key1, DES_cblock *key2);
-
-char *DES_fcrypt(const char *buf, const char *salt, char *ret);
-char *DES_crypt(const char *buf, const char *salt);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_EncryptInit_ex(3), EVP_EncryptUpdate(3) and EVP_EncryptFinal_ex(3) or the equivalently named decrypt functions.

- -

This library contains a fast implementation of the DES encryption algorithm.

- -

There are two phases to the use of DES encryption. The first is the generation of a DES_key_schedule from a key, the second is the actual encryption. A DES key is of type DES_cblock. This type consists of 8 bytes with odd parity. The least significant bit in each byte is the parity bit. The key schedule is an expanded form of the key; it is used to speed the encryption process.

- -

DES_random_key() generates a random key. The random generator must be seeded when calling this function. If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail. If the function fails, 0 is returned.

- -

Before a DES key can be used, it must be converted into the architecture dependent DES_key_schedule via the DES_set_key_checked() or DES_set_key_unchecked() function.

- -

DES_set_key_checked() will check that the key passed is of odd parity and is not a weak or semi-weak key. If the parity is wrong, then -1 is returned. If the key is a weak key, then -2 is returned. If an error is returned, the key schedule is not generated.

- -

DES_set_key() works like DES_set_key_checked() and remains for backward compatibility.

- -

DES_set_odd_parity() sets the parity of the passed key to odd.

- -

DES_is_weak_key() returns 1 if the passed key is a weak key, 0 if it is ok.

- -

The following routines mostly operate on an input and output stream of DES_cblocks.

- -

DES_ecb_encrypt() is the basic DES encryption routine that encrypts or decrypts a single 8-byte DES_cblock in electronic code book (ECB) mode. It always transforms the input data, pointed to by input, into the output data, pointed to by the output argument. If the encrypt argument is nonzero (DES_ENCRYPT), the input (cleartext) is encrypted in to the output (ciphertext) using the key_schedule specified by the schedule argument, previously set via DES_set_key. If encrypt is zero (DES_DECRYPT), the input (now ciphertext) is decrypted into the output (now cleartext). Input and output may overlap. DES_ecb_encrypt() does not return a value.

- -

DES_ecb3_encrypt() encrypts/decrypts the input block by using three-key Triple-DES encryption in ECB mode. This involves encrypting the input with ks1, decrypting with the key schedule ks2, and then encrypting with ks3. This routine greatly reduces the chances of brute force breaking of DES and has the advantage of if ks1, ks2 and ks3 are the same, it is equivalent to just encryption using ECB mode and ks1 as the key.

- -

The macro DES_ecb2_encrypt() is provided to perform two-key Triple-DES encryption by using ks1 for the final encryption.

- -

DES_ncbc_encrypt() encrypts/decrypts using the cipher-block-chaining (CBC) mode of DES. If the encrypt argument is nonzero, the routine cipher-block-chain encrypts the cleartext data pointed to by the input argument into the ciphertext pointed to by the output argument, using the key schedule provided by the schedule argument, and initialization vector provided by the ivec argument. If the length argument is not an integral multiple of eight bytes, the last block is copied to a temporary area and zero filled. The output is always an integral multiple of eight bytes.

- -

DES_xcbc_encrypt() is RSA's DESX mode of DES. It uses inw and outw to 'whiten' the encryption. inw and outw are secret (unlike the iv) and are as such, part of the key. So the key is sort of 24 bytes. This is much better than CBC DES.

- -

DES_ede3_cbc_encrypt() implements outer triple CBC DES encryption with three keys. This means that each DES operation inside the CBC mode is C=E(ks3,D(ks2,E(ks1,M))). This mode is used by SSL.

- -

The DES_ede2_cbc_encrypt() macro implements two-key Triple-DES by reusing ks1 for the final encryption. C=E(ks1,D(ks2,E(ks1,M))). This form of Triple-DES is used by the RSAREF library.

- -

DES_pcbc_encrypt() encrypts/decrypts using the propagating cipher block chaining mode used by Kerberos v4. Its parameters are the same as DES_ncbc_encrypt().

- -

DES_cfb_encrypt() encrypts/decrypts using cipher feedback mode. This method takes an array of characters as input and outputs an array of characters. It does not require any padding to 8 character groups. Note: the ivec variable is changed and the new changed value needs to be passed to the next call to this function. Since this function runs a complete DES ECB encryption per numbits, this function is only suggested for use when sending a small number of characters.

- -

DES_cfb64_encrypt() implements CFB mode of DES with 64-bit feedback. Why is this useful you ask? Because this routine will allow you to encrypt an arbitrary number of bytes, without 8 byte padding. Each call to this routine will encrypt the input bytes to output and then update ivec and num. num contains 'how far' we are though ivec. If this does not make much sense, read more about CFB mode of DES.

- -

DES_ede3_cfb64_encrypt() and DES_ede2_cfb64_encrypt() is the same as DES_cfb64_encrypt() except that Triple-DES is used.

- -

DES_ofb_encrypt() encrypts using output feedback mode. This method takes an array of characters as input and outputs an array of characters. It does not require any padding to 8 character groups. Note: the ivec variable is changed and the new changed value needs to be passed to the next call to this function. Since this function runs a complete DES ECB encryption per numbits, this function is only suggested for use when sending a small number of characters.

- -

DES_ofb64_encrypt() is the same as DES_cfb64_encrypt() using Output Feed Back mode.

- -

DES_ede3_ofb64_encrypt() and DES_ede2_ofb64_encrypt() is the same as DES_ofb64_encrypt(), using Triple-DES.

- -

The following functions are included in the DES library for compatibility with the MIT Kerberos library.

- -

DES_cbc_cksum() produces an 8 byte checksum based on the input stream (via CBC encryption). The last 4 bytes of the checksum are returned and the complete 8 bytes are placed in output. This function is used by Kerberos v4. Other applications should use EVP_DigestInit(3) etc. instead.

- -

DES_quad_cksum() is a Kerberos v4 function. It returns a 4 byte checksum from the input bytes. The algorithm can be iterated over the input, depending on out_count, 1, 2, 3 or 4 times. If output is non-NULL, the 8 bytes generated by each pass are written into output.

- -

The following are DES-based transformations:

- -

DES_fcrypt() is a fast version of the Unix crypt(3) function. This version takes only a small amount of space relative to other fast crypt() implementations. This is different to the normal crypt() in that the third parameter is the buffer that the return value is written into. It needs to be at least 14 bytes long. This function is thread safe, unlike the normal crypt().

- -

DES_crypt() is a faster replacement for the normal system crypt(). This function calls DES_fcrypt() with a static array passed as the third parameter. This mostly emulates the normal non-thread-safe semantics of crypt(3). The salt must be two ASCII characters.

- -

The values returned by DES_fcrypt() and DES_crypt() are terminated by NUL character.

- -

DES_enc_write() writes len bytes to file descriptor fd from buffer buf. The data is encrypted via pcbc_encrypt (default) using sched for the key and iv as a starting vector. The actual data send down fd consists of 4 bytes (in network byte order) containing the length of the following encrypted data. The encrypted data then follows, padded with random data out to a multiple of 8 bytes.

- -

BUGS

- -

DES_cbc_encrypt() does not modify ivec; use DES_ncbc_encrypt() instead.

- -

DES_cfb_encrypt() and DES_ofb_encrypt() operates on input of 8 bits. What this means is that if you set numbits to 12, and length to 2, the first 12 bits will come from the 1st input byte and the low half of the second input byte. The second 12 bits will have the low 8 bits taken from the 3rd input byte and the top 4 bits taken from the 4th input byte. The same holds for output. This function has been implemented this way because most people will be using a multiple of 8 and because once you get into pulling bytes input bytes apart things get ugly!

- -

DES_string_to_key() is available for backward compatibility with the MIT library. New applications should use a cryptographic hash function. The same applies for DES_string_to_2key().

- -

NOTES

- -

The des library was written to be source code compatible with the MIT Kerberos library.

- -

Applications should use the higher level functions EVP_EncryptInit(3) etc. instead of calling these functions directly.

- -

Single-key DES is insecure due to its short key size. ECB mode is not suitable for most applications; see des_modes(7).

- -

RETURN VALUES

- -

DES_set_key(), DES_key_sched(), and DES_set_key_checked() return 0 on success or negative values on error.

- -

DES_is_weak_key() returns 1 if the passed key is a weak key, 0 if it is ok.

- -

DES_cbc_cksum() and DES_quad_cksum() return 4-byte integer representing the last 4 bytes of the checksum of the input.

- -

DES_fcrypt() returns a pointer to the caller-provided buffer and DES_crypt() - to a static buffer on success; otherwise they return NULL.

- -

SEE ALSO

- -

des_modes(7), EVP_EncryptInit(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

The requirement that the salt parameter to DES_crypt() and DES_fcrypt() be two ASCII characters was first enforced in OpenSSL 1.1.0. Previous versions tried to use the letter uppercase A if both character were not present, and could crash when given non-ASCII on some platforms.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_generate_key.html b/openssl-install/share/doc/openssl/html/man3/DH_generate_key.html deleted file mode 100644 index b88c29e5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_generate_key.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -DH_generate_key - - - - - - - - - - -

NAME

- -

DH_generate_key, DH_compute_key, DH_compute_key_padded - perform Diffie-Hellman key exchange

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DH_generate_key(DH *dh);
-
-int DH_compute_key(unsigned char *key, const BIGNUM *pub_key, DH *dh);
-
-int DH_compute_key_padded(unsigned char *key, const BIGNUM *pub_key, DH *dh);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_derive_init(3) and EVP_PKEY_derive(3).

- -

DH_generate_key() performs the first step of a Diffie-Hellman key exchange by generating private and public DH values. By calling DH_compute_key() or DH_compute_key_padded(), these are combined with the other party's public value to compute the shared key.

- -

DH_generate_key() expects dh to contain the shared parameters dh->p and dh->g. It generates a random private DH value unless dh->priv_key is already set, and computes the corresponding public value dh->pub_key, which can then be published.

- -

DH_compute_key() computes the shared secret from the private DH value in dh and the other party's public value in pub_key and stores it in key. key must point to DH_size(dh) bytes of memory. The padding style is RFC 5246 (8.1.2) that strips leading zero bytes. It is not constant time due to the leading zero bytes being stripped. The return value should be considered public.

- -

DH_compute_key_padded() is similar but stores a fixed number of bytes. The padding style is NIST SP 800-56A (C.1) that retains leading zero bytes. It is constant time due to the leading zero bytes being retained. The return value should be considered public.

- -

RETURN VALUES

- -

DH_generate_key() returns 1 on success, 0 otherwise.

- -

DH_compute_key() returns the size of the shared secret on success, -1 on error.

- -

DH_compute_key_padded() returns DH_size(dh) on success, -1 on error.

- -

The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

EVP_PKEY_derive(3), DH_new(3), ERR_get_error(3), RAND_bytes(3), DH_size(3)

- -

HISTORY

- -

DH_compute_key_padded() was added in OpenSSL 1.0.2.

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_generate_parameters.html b/openssl-install/share/doc/openssl/html/man3/DH_generate_parameters.html deleted file mode 100644 index d9a79637..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_generate_parameters.html +++ /dev/null @@ -1,173 +0,0 @@ - - - - -DH_generate_parameters - - - - - - - - - - -

NAME

- -

DH_generate_parameters_ex, DH_generate_parameters, DH_check, DH_check_params, DH_check_ex, DH_check_params_ex, DH_check_pub_key_ex - generate and check Diffie-Hellman parameters

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DH_generate_parameters_ex(DH *dh, int prime_len, int generator, BN_GENCB *cb);
-
-int DH_check(DH *dh, int *codes);
-int DH_check_params(DH *dh, int *codes);
-
-int DH_check_ex(const DH *dh);
-int DH_check_params_ex(const DH *dh);
-int DH_check_pub_key_ex(const DH *dh, const BIGNUM *pub_key);
- -

The following functions have been deprecated since OpenSSL 0.9.8, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DH *DH_generate_parameters(int prime_len, int generator,
-                           void (*callback)(int, int, void *), void *cb_arg);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_check(3), EVP_PKEY_public_check(3), EVP_PKEY_private_check(3) and EVP_PKEY_param_check(3).

- -

DH_generate_parameters_ex() generates Diffie-Hellman parameters that can be shared among a group of users, and stores them in the provided DH structure. The pseudo-random number generator must be seeded before calling it. The parameters generated by DH_generate_parameters_ex() should not be used in signature schemes.

- -

prime_len is the length in bits of the safe prime to be generated. generator is a small number > 1, typically 2 or 5.

- -

A callback function may be used to provide feedback about the progress of the key generation. If cb is not NULL, it will be called as described in BN_generate_prime(3) while a random prime number is generated, and when a prime has been found, BN_GENCB_call(cb, 3, 0) is called. See BN_generate_prime_ex(3) for information on the BN_GENCB_call() function.

- -

DH_generate_parameters() is similar to DH_generate_prime_ex() but expects an old-style callback function; see BN_generate_prime(3) for information on the old-style callback.

- -

DH_check_params() confirms that the p and g are likely enough to be valid. This is a lightweight check, if a more thorough check is needed, use DH_check(). The value of *codes is updated with any problems found. If *codes is zero then no problems were found, otherwise the following bits may be set:

- -
- -
DH_CHECK_P_NOT_PRIME
-
- -

The parameter p has been determined to not being an odd prime. Note that the lack of this bit doesn't guarantee that p is a prime.

- -
-
DH_NOT_SUITABLE_GENERATOR
-
- -

The generator g is not suitable. Note that the lack of this bit doesn't guarantee that g is suitable, unless p is known to be a strong prime.

- -
-
DH_MODULUS_TOO_SMALL
-
- -

The modulus is too small.

- -
-
DH_MODULUS_TOO_LARGE
-
- -

The modulus is too large.

- -
-
- -

DH_check() confirms that the Diffie-Hellman parameters dh are valid. The value of *codes is updated with any problems found. If *codes is zero then no problems were found, otherwise the following bits may be set:

- -
- -
DH_CHECK_P_NOT_PRIME
-
- -

The parameter p is not prime.

- -
-
DH_CHECK_P_NOT_SAFE_PRIME
-
- -

The parameter p is not a safe prime and no q value is present.

- -
-
DH_UNABLE_TO_CHECK_GENERATOR
-
- -

The generator g cannot be checked for suitability.

- -
-
DH_NOT_SUITABLE_GENERATOR
-
- -

The generator g is not suitable.

- -
-
DH_CHECK_Q_NOT_PRIME
-
- -

The parameter q is not prime.

- -
-
DH_CHECK_INVALID_Q_VALUE
-
- -

The parameter q is invalid.

- -
-
DH_CHECK_INVALID_J_VALUE
-
- -

The parameter j is invalid.

- -
-
- -

If 0 is returned or *codes is set to a nonzero value the supplied parameters should not be used for Diffie-Hellman operations otherwise the security properties of the key exchange are not guaranteed.

- -

DH_check_ex(), DH_check_params() and DH_check_pub_key_ex() are similar to DH_check() and DH_check_params() respectively, but the error reasons are added to the thread's error queue instead of provided as return values from the function.

- -

RETURN VALUES

- -

DH_generate_parameters_ex(), DH_check() and DH_check_params() return 1 if the check could be performed, 0 otherwise.

- -

DH_generate_parameters() returns a pointer to the DH structure or NULL if the parameter generation fails.

- -

DH_check_ex(), DH_check_params() and DH_check_pub_key_ex() return 1 if the check is successful, 0 for failed.

- -

The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

DH_new(3), ERR_get_error(3), RAND_bytes(3), DH_free(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

DH_generate_parameters() was deprecated in OpenSSL 0.9.8; use DH_generate_parameters_ex() instead.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_get0_pqg.html b/openssl-install/share/doc/openssl/html/man3/DH_get0_pqg.html deleted file mode 100644 index 9e821c2f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_get0_pqg.html +++ /dev/null @@ -1,114 +0,0 @@ - - - - -DH_get0_pqg - - - - - - - - - - -

NAME

- -

DH_get0_pqg, DH_set0_pqg, DH_get0_key, DH_set0_key, DH_get0_p, DH_get0_q, DH_get0_g, DH_get0_priv_key, DH_get0_pub_key, DH_clear_flags, DH_test_flags, DH_set_flags, DH_get0_engine, DH_get_length, DH_set_length - Routines for getting and setting data in a DH object

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void DH_get0_pqg(const DH *dh,
-                 const BIGNUM **p, const BIGNUM **q, const BIGNUM **g);
-int DH_set0_pqg(DH *dh, BIGNUM *p, BIGNUM *q, BIGNUM *g);
-void DH_get0_key(const DH *dh,
-                 const BIGNUM **pub_key, const BIGNUM **priv_key);
-int DH_set0_key(DH *dh, BIGNUM *pub_key, BIGNUM *priv_key);
-const BIGNUM *DH_get0_p(const DH *dh);
-const BIGNUM *DH_get0_q(const DH *dh);
-const BIGNUM *DH_get0_g(const DH *dh);
-const BIGNUM *DH_get0_priv_key(const DH *dh);
-const BIGNUM *DH_get0_pub_key(const DH *dh);
-void DH_clear_flags(DH *dh, int flags);
-int DH_test_flags(const DH *dh, int flags);
-void DH_set_flags(DH *dh, int flags);
-
-long DH_get_length(const DH *dh);
-int DH_set_length(DH *dh, long length);
-
-ENGINE *DH_get0_engine(DH *d);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_get_bn_param(3) for any methods that return a BIGNUM. Refer to EVP_PKEY-DH(7) for more information.

- -

A DH object contains the parameters p, q and g. Note that the q parameter is optional. It also contains a public key (pub_key) and (optionally) a private key (priv_key).

- -

The p, q and g parameters can be obtained by calling DH_get0_pqg(). If the parameters have not yet been set then *p, *q and *g will be set to NULL. Otherwise they are set to pointers to their respective values. These point directly to the internal representations of the values and therefore should not be freed directly. Any of the out parameters p, q, and g can be NULL, in which case no value will be returned for that parameter.

- -

The p, q and g values can be set by calling DH_set0_pqg() and passing the new values for p, q and g as parameters to the function. Calling this function transfers the memory management of the values to the DH object, and therefore the values that have been passed in should not be freed directly after this function has been called. The q parameter may be NULL. DH_set0_pqg() also checks if the parameters associated with p and g and optionally q are associated with known safe prime groups. If it is a safe prime group then the value of q will be set to q = (p - 1) / 2 if q is NULL. The optional length parameter will be set to BN_num_bits(q) if q is not NULL.

- -

To get the public and private key values use the DH_get0_key() function. A pointer to the public key will be stored in *pub_key, and a pointer to the private key will be stored in *priv_key. Either may be NULL if they have not been set yet, although if the private key has been set then the public key must be. The values point to the internal representation of the public key and private key values. This memory should not be freed directly. Any of the out parameters pub_key and priv_key can be NULL, in which case no value will be returned for that parameter.

- -

The public and private key values can be set using DH_set0_key(). Either parameter may be NULL, which means the corresponding DH field is left untouched. As with DH_set0_pqg() this function transfers the memory management of the key values to the DH object, and therefore they should not be freed directly after this function has been called.

- -

Any of the values p, q, g, priv_key, and pub_key can also be retrieved separately by the corresponding function DH_get0_p(), DH_get0_q(), DH_get0_g(), DH_get0_priv_key(), and DH_get0_pub_key(), respectively.

- -

DH_set_flags() sets the flags in the flags parameter on the DH object. Multiple flags can be passed in one go (bitwise ORed together). Any flags that are already set are left set. DH_test_flags() tests to see whether the flags passed in the flags parameter are currently set in the DH object. Multiple flags can be tested in one go. All flags that are currently set are returned, or zero if none of the flags are set. DH_clear_flags() clears the specified flags within the DH object.

- -

DH_get0_engine() returns a handle to the ENGINE that has been set for this DH object, or NULL if no such ENGINE has been set. This function is deprecated. All engines should be replaced by providers.

- -

The DH_get_length() and DH_set_length() functions get and set the optional length parameter associated with this DH object. If the length is nonzero then it is used, otherwise it is ignored. The length parameter indicates the length of the secret exponent (private key) in bits. For safe prime groups the optional length parameter length can be set to a value greater or equal to 2 * maximum_target_security_strength(BN_num_bits(p)) as listed in SP800-56Ar3 Table(s) 25 & 26. These functions are deprecated and should be replaced with EVP_PKEY_CTX_set_params() and EVP_PKEY_get_int_param() using the parameter key OSSL_PKEY_PARAM_DH_PRIV_LEN as described in EVP_PKEY-DH(7).

- -

NOTES

- -

Values retrieved with DH_get0_key() are owned by the DH object used in the call and may therefore not be passed to DH_set0_key(). If needed, duplicate the received value using BN_dup() and pass the duplicate. The same applies to DH_get0_pqg() and DH_set0_pqg().

- -

RETURN VALUES

- -

DH_set0_pqg() and DH_set0_key() return 1 on success or 0 on failure.

- -

DH_get0_p(), DH_get0_q(), DH_get0_g(), DH_get0_priv_key(), and DH_get0_pub_key() return the respective value, or NULL if it is unset.

- -

DH_test_flags() returns the current state of the flags in the DH object.

- -

DH_get0_engine() returns the ENGINE set for the DH object or NULL if no ENGINE has been set.

- -

DH_get_length() returns the length of the secret exponent (private key) in bits, or zero if no such length has been explicitly set.

- -

SEE ALSO

- -

DH_new(3), DH_new(3), DH_generate_parameters(3), DH_generate_key(3), DH_set_method(3), DH_size(3), DH_meth_new(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 1.1.0.

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_get_1024_160.html b/openssl-install/share/doc/openssl/html/man3/DH_get_1024_160.html deleted file mode 100644 index 6535bc1f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_get_1024_160.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -DH_get_1024_160 - - - - - - - - - - -

NAME

- -

DH_get_1024_160, DH_get_2048_224, DH_get_2048_256, BN_get0_nist_prime_192, BN_get0_nist_prime_224, BN_get0_nist_prime_256, BN_get0_nist_prime_384, BN_get0_nist_prime_521, BN_get_rfc2409_prime_768, BN_get_rfc2409_prime_1024, BN_get_rfc3526_prime_1536, BN_get_rfc3526_prime_2048, BN_get_rfc3526_prime_3072, BN_get_rfc3526_prime_4096, BN_get_rfc3526_prime_6144, BN_get_rfc3526_prime_8192 - Create standardized public primes or DH pairs

- -

SYNOPSIS

- -
#include <openssl/dh.h>
-
-const BIGNUM *BN_get0_nist_prime_192(void);
-const BIGNUM *BN_get0_nist_prime_224(void);
-const BIGNUM *BN_get0_nist_prime_256(void);
-const BIGNUM *BN_get0_nist_prime_384(void);
-const BIGNUM *BN_get0_nist_prime_521(void);
-
-BIGNUM *BN_get_rfc2409_prime_768(BIGNUM *bn);
-BIGNUM *BN_get_rfc2409_prime_1024(BIGNUM *bn);
-BIGNUM *BN_get_rfc3526_prime_1536(BIGNUM *bn);
-BIGNUM *BN_get_rfc3526_prime_2048(BIGNUM *bn);
-BIGNUM *BN_get_rfc3526_prime_3072(BIGNUM *bn);
-BIGNUM *BN_get_rfc3526_prime_4096(BIGNUM *bn);
-BIGNUM *BN_get_rfc3526_prime_6144(BIGNUM *bn);
-BIGNUM *BN_get_rfc3526_prime_8192(BIGNUM *bn);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#include <openssl/dh.h>
-
-DH *DH_get_1024_160(void);
-DH *DH_get_2048_224(void);
-DH *DH_get_2048_256(void);
- -

DESCRIPTION

- -

DH_get_1024_160(), DH_get_2048_224(), and DH_get_2048_256() each return a DH object for the IETF RFC 5114 value. These functions are deprecated. Applications should instead use EVP_PKEY_CTX_set_dh_rfc5114() and EVP_PKEY_CTX_set_dhx_rfc5114() as described in EVP_PKEY_CTX_ctrl(3) or by setting the OSSL_PKEY_PARAM_GROUP_NAME as specified in "DH parameters" in EVP_PKEY-DH(7)) to one of "dh_1024_160", "dh_2048_224" or "dh_2048_256".

- -

BN_get0_nist_prime_192(), BN_get0_nist_prime_224(), BN_get0_nist_prime_256(), BN_get0_nist_prime_384(), and BN_get0_nist_prime_521() functions return a BIGNUM for the specific NIST prime curve (e.g., P-256).

- -

BN_get_rfc2409_prime_768(), BN_get_rfc2409_prime_1024(), BN_get_rfc3526_prime_1536(), BN_get_rfc3526_prime_2048(), BN_get_rfc3526_prime_3072(), BN_get_rfc3526_prime_4096(), BN_get_rfc3526_prime_6144(), and BN_get_rfc3526_prime_8192() functions return a BIGNUM for the specified size from IETF RFC 2409. If bn is not NULL, the BIGNUM will be set into that location as well.

- -

RETURN VALUES

- -

Defined above.

- -

HISTORY

- -

The functions DH_get_1024_160(), DH_get_2048_224() and DH_get_2048_256() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_meth_new.html b/openssl-install/share/doc/openssl/html/man3/DH_meth_new.html deleted file mode 100644 index 5bcd2392..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_meth_new.html +++ /dev/null @@ -1,141 +0,0 @@ - - - - -DH_meth_new - - - - - - - - - - -

NAME

- -

DH_meth_new, DH_meth_free, DH_meth_dup, DH_meth_get0_name, DH_meth_set1_name, DH_meth_get_flags, DH_meth_set_flags, DH_meth_get0_app_data, DH_meth_set0_app_data, DH_meth_get_generate_key, DH_meth_set_generate_key, DH_meth_get_compute_key, DH_meth_set_compute_key, DH_meth_get_bn_mod_exp, DH_meth_set_bn_mod_exp, DH_meth_get_init, DH_meth_set_init, DH_meth_get_finish, DH_meth_set_finish, DH_meth_get_generate_params, DH_meth_set_generate_params - Routines to build up DH methods

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DH_METHOD *DH_meth_new(const char *name, int flags);
-
-void DH_meth_free(DH_METHOD *dhm);
-
-DH_METHOD *DH_meth_dup(const DH_METHOD *dhm);
-
-const char *DH_meth_get0_name(const DH_METHOD *dhm);
-int DH_meth_set1_name(DH_METHOD *dhm, const char *name);
-
-int DH_meth_get_flags(const DH_METHOD *dhm);
-int DH_meth_set_flags(DH_METHOD *dhm, int flags);
-
-void *DH_meth_get0_app_data(const DH_METHOD *dhm);
-int DH_meth_set0_app_data(DH_METHOD *dhm, void *app_data);
-
-int (*DH_meth_get_generate_key(const DH_METHOD *dhm))(DH *);
-int DH_meth_set_generate_key(DH_METHOD *dhm, int (*generate_key)(DH *));
-
-int (*DH_meth_get_compute_key(const DH_METHOD *dhm))
-    (unsigned char *key, const BIGNUM *pub_key, DH *dh);
-int DH_meth_set_compute_key(DH_METHOD *dhm,
-    int (*compute_key)(unsigned char *key, const BIGNUM *pub_key, DH *dh));
-
-int (*DH_meth_get_bn_mod_exp(const DH_METHOD *dhm))
-    (const DH *dh, BIGNUM *r, const BIGNUM *a, const BIGNUM *p,
-     const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *m_ctx);
-int DH_meth_set_bn_mod_exp(DH_METHOD *dhm,
-    int (*bn_mod_exp)(const DH *dh, BIGNUM *r, const BIGNUM *a,
-                      const BIGNUM *p, const BIGNUM *m, BN_CTX *ctx,
-                      BN_MONT_CTX *m_ctx));
-
-int (*DH_meth_get_init(const DH_METHOD *dhm))(DH *);
-int DH_meth_set_init(DH_METHOD *dhm, int (*init)(DH *));
-
-int (*DH_meth_get_finish(const DH_METHOD *dhm))(DH *);
-int DH_meth_set_finish(DH_METHOD *dhm, int (*finish)(DH *));
-
-int (*DH_meth_get_generate_params(const DH_METHOD *dhm))
-    (DH *, int, int, BN_GENCB *);
-int DH_meth_set_generate_params(DH_METHOD *dhm,
-    int (*generate_params)(DH *, int, int, BN_GENCB *));
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the provider APIs.

- -

The DH_METHOD type is a structure used for the provision of custom DH implementations. It provides a set of functions used by OpenSSL for the implementation of the various DH capabilities.

- -

DH_meth_new() creates a new DH_METHOD structure. It should be given a unique name and a set of flags. The name should be a NULL terminated string, which will be duplicated and stored in the DH_METHOD object. It is the callers responsibility to free the original string. The flags will be used during the construction of a new DH object based on this DH_METHOD. Any new DH object will have those flags set by default.

- -

DH_meth_dup() creates a duplicate copy of the DH_METHOD object passed as a parameter. This might be useful for creating a new DH_METHOD based on an existing one, but with some differences.

- -

DH_meth_free() destroys a DH_METHOD structure and frees up any memory associated with it. If the argument is NULL, nothing is done.

- -

DH_meth_get0_name() will return a pointer to the name of this DH_METHOD. This is a pointer to the internal name string and so should not be freed by the caller. DH_meth_set1_name() sets the name of the DH_METHOD to name. The string is duplicated and the copy is stored in the DH_METHOD structure, so the caller remains responsible for freeing the memory associated with the name.

- -

DH_meth_get_flags() returns the current value of the flags associated with this DH_METHOD. DH_meth_set_flags() provides the ability to set these flags.

- -

The functions DH_meth_get0_app_data() and DH_meth_set0_app_data() provide the ability to associate implementation specific data with the DH_METHOD. It is the application's responsibility to free this data before the DH_METHOD is freed via a call to DH_meth_free().

- -

DH_meth_get_generate_key() and DH_meth_set_generate_key() get and set the function used for generating a new DH key pair respectively. This function will be called in response to the application calling DH_generate_key(). The parameter for the function has the same meaning as for DH_generate_key().

- -

DH_meth_get_compute_key() and DH_meth_set_compute_key() get and set the function used for computing a new DH shared secret respectively. This function will be called in response to the application calling DH_compute_key(). The parameters for the function have the same meaning as for DH_compute_key().

- -

DH_meth_get_bn_mod_exp() and DH_meth_set_bn_mod_exp() get and set the function used for computing the following value:

- -
r = a ^ p mod m
- -

This function will be called by the default OpenSSL function for DH_generate_key(). The result is stored in the r parameter. This function may be NULL unless using the default generate key function, in which case it must be present.

- -

DH_meth_get_init() and DH_meth_set_init() get and set the function used for creating a new DH instance respectively. This function will be called in response to the application calling DH_new() (if the current default DH_METHOD is this one) or DH_new_method(). The DH_new() and DH_new_method() functions will allocate the memory for the new DH object, and a pointer to this newly allocated structure will be passed as a parameter to the function. This function may be NULL.

- -

DH_meth_get_finish() and DH_meth_set_finish() get and set the function used for destroying an instance of a DH object respectively. This function will be called in response to the application calling DH_free(). A pointer to the DH to be destroyed is passed as a parameter. The destroy function should be used for DH implementation specific clean up. The memory for the DH itself should not be freed by this function. This function may be NULL.

- -

DH_meth_get_generate_params() and DH_meth_set_generate_params() get and set the function used for generating DH parameters respectively. This function will be called in response to the application calling DH_generate_parameters_ex() (or DH_generate_parameters()). The parameters for the function have the same meaning as for DH_generate_parameters_ex(). This function may be NULL.

- -

RETURN VALUES

- -

DH_meth_new() and DH_meth_dup() return the newly allocated DH_METHOD object or NULL on failure.

- -

DH_meth_get0_name() and DH_meth_get_flags() return the name and flags associated with the DH_METHOD respectively.

- -

All other DH_meth_get_*() functions return the appropriate function pointer that has been set in the DH_METHOD, or NULL if no such pointer has yet been set.

- -

DH_meth_set1_name() and all DH_meth_set_*() functions return 1 on success or 0 on failure.

- -

SEE ALSO

- -

DH_new(3), DH_new(3), DH_generate_parameters(3), DH_generate_key(3), DH_set_method(3), DH_size(3), DH_get0_pqg(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

The functions described here were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_new.html b/openssl-install/share/doc/openssl/html/man3/DH_new.html deleted file mode 100644 index 5abe62eb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_new.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -DH_new - - - - - - - - - - -

NAME

- -

DH_new, DH_free - allocate and free DH objects

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DH* DH_new(void);
-
-void DH_free(DH *dh);
- -

DESCRIPTION

- -

DH_new() allocates and initializes a DH structure.

- -

DH_free() frees the DH structure and its components. The values are erased before the memory is returned to the system. If dh is NULL nothing is done.

- -

RETURN VALUES

- -

If the allocation fails, DH_new() returns NULL and sets an error code that can be obtained by ERR_get_error(3). Otherwise it returns a pointer to the newly allocated structure.

- -

DH_free() returns no value.

- -

SEE ALSO

- -

DH_new(3), ERR_get_error(3), DH_generate_parameters(3), DH_generate_key(3), EVP_PKEY-DH(7)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

For replacement see EVP_PKEY-DH(7).

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_new_by_nid.html b/openssl-install/share/doc/openssl/html/man3/DH_new_by_nid.html deleted file mode 100644 index c1eb0801..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_new_by_nid.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -DH_new_by_nid - - - - - - - - - - -

NAME

- -

DH_new_by_nid, DH_get_nid - create or get DH named parameters

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DH *DH_new_by_nid(int nid);
-
-int DH_get_nid(const DH *dh);
- -

DESCRIPTION

- -

DH_new_by_nid() creates and returns a DH structure containing named parameters nid. Currently nid must be NID_ffdhe2048, NID_ffdhe3072, NID_ffdhe4096, NID_ffdhe6144, NID_ffdhe8192, NID_modp_1536, NID_modp_2048, NID_modp_3072, NID_modp_4096, NID_modp_6144 or NID_modp_8192.

- -

DH_get_nid() determines if the parameters contained in dh match any named safe prime group. It returns the NID corresponding to the matching parameters or NID_undef if there is no match. This function is deprecated.

- -

RETURN VALUES

- -

DH_new_by_nid() returns a set of DH parameters or NULL if an error occurred.

- -

DH_get_nid() returns the NID of the matching set of parameters for p and g and optionally q, otherwise it returns NID_undef if there is no match.

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_set_method.html b/openssl-install/share/doc/openssl/html/man3/DH_set_method.html deleted file mode 100644 index e96d553a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_set_method.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -DH_set_method - - - - - - - - - - -

NAME

- -

DH_set_default_method, DH_get_default_method, DH_set_method, DH_new_method, DH_OpenSSL - select DH method

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void DH_set_default_method(const DH_METHOD *meth);
-
-const DH_METHOD *DH_get_default_method(void);
-
-int DH_set_method(DH *dh, const DH_METHOD *meth);
-
-DH *DH_new_method(ENGINE *engine);
-
-const DH_METHOD *DH_OpenSSL(void);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the provider APIs.

- -

A DH_METHOD specifies the functions that OpenSSL uses for Diffie-Hellman operations. By modifying the method, alternative implementations such as hardware accelerators may be used. IMPORTANT: See the NOTES section for important information about how these DH API functions are affected by the use of ENGINE API calls.

- -

Initially, the default DH_METHOD is the OpenSSL internal implementation, as returned by DH_OpenSSL().

- -

DH_set_default_method() makes meth the default method for all DH structures created later. NB: This is true only whilst no ENGINE has been set as a default for DH, so this function is no longer recommended. This function is not thread-safe and should not be called at the same time as other OpenSSL functions.

- -

DH_get_default_method() returns a pointer to the current default DH_METHOD. However, the meaningfulness of this result is dependent on whether the ENGINE API is being used, so this function is no longer recommended.

- -

DH_set_method() selects meth to perform all operations using the key dh. This will replace the DH_METHOD used by the DH key and if the previous method was supplied by an ENGINE, the handle to that ENGINE will be released during the change. It is possible to have DH keys that only work with certain DH_METHOD implementations (e.g. from an ENGINE module that supports embedded hardware-protected keys), and in such cases attempting to change the DH_METHOD for the key can have unexpected results.

- -

DH_new_method() allocates and initializes a DH structure so that engine will be used for the DH operations. If engine is NULL, the default ENGINE for DH operations is used, and if no default ENGINE is set, the DH_METHOD controlled by DH_set_default_method() is used.

- -

A new DH_METHOD object may be constructed using DH_meth_new() (see DH_meth_new(3)).

- -

RETURN VALUES

- -

DH_OpenSSL() and DH_get_default_method() return pointers to the respective DH_METHODs.

- -

DH_set_default_method() returns no value.

- -

DH_set_method() returns nonzero if the provided meth was successfully set as the method for dh (including unloading the ENGINE handle if the previous method was supplied by an ENGINE).

- -

DH_new_method() returns NULL and sets an error code that can be obtained by ERR_get_error(3) if the allocation fails. Otherwise it returns a pointer to the newly allocated structure.

- -

SEE ALSO

- -

DH_new(3), DH_new(3), DH_meth_new(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DH_size.html b/openssl-install/share/doc/openssl/html/man3/DH_size.html deleted file mode 100644 index 60bfbb98..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DH_size.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -DH_size - - - - - - - - - - -

NAME

- -

DH_size, DH_bits, DH_security_bits - get Diffie-Hellman prime size and security bits

- -

SYNOPSIS

- -
#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DH_bits(const DH *dh);
-
-int DH_size(const DH *dh);
-
-int DH_security_bits(const DH *dh);
- -

DESCRIPTION

- -

The functions described on this page are deprecated. Applications should instead use EVP_PKEY_get_bits(3), EVP_PKEY_get_security_bits(3) and EVP_PKEY_get_size(3).

- -

DH_bits() returns the number of significant bits.

- -

dh and dh->p must not be NULL.

- -

DH_size() returns the Diffie-Hellman prime size in bytes. It can be used to determine how much memory must be allocated for the shared secret computed by DH_compute_key(3).

- -

DH_security_bits() returns the number of security bits of the given dh key. See BN_security_bits(3).

- -

RETURN VALUES

- -

DH_bits() returns the number of bits in the key, or -1 if dh doesn't hold any key parameters.

- -

DH_size() returns the prime size of Diffie-Hellman in bytes, or -1 if dh doesn't hold any key parameters.

- -

DH_security_bits() returns the number of security bits, or -1 if dh doesn't hold any key parameters.

- -

SEE ALSO

- -

EVP_PKEY_get_bits(3), DH_new(3), DH_generate_key(3), BN_num_bits(3)

- -

HISTORY

- -

All functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_SIG_new.html b/openssl-install/share/doc/openssl/html/man3/DSA_SIG_new.html deleted file mode 100644 index 6e7eaad6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_SIG_new.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -DSA_SIG_new - - - - - - - - - - -

NAME

- -

DSA_SIG_get0, DSA_SIG_set0, DSA_SIG_new, DSA_SIG_free - allocate and free DSA signature objects

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
-
-DSA_SIG *DSA_SIG_new(void);
-void DSA_SIG_free(DSA_SIG *a);
-void DSA_SIG_get0(const DSA_SIG *sig, const BIGNUM **pr, const BIGNUM **ps);
-int DSA_SIG_set0(DSA_SIG *sig, BIGNUM *r, BIGNUM *s);
- -

DESCRIPTION

- -

DSA_SIG_new() allocates an empty DSA_SIG structure.

- -

DSA_SIG_free() frees the DSA_SIG structure and its components. The values are erased before the memory is returned to the system. If the argument is NULL, nothing is done.

- -

DSA_SIG_get0() returns internal pointers to the r and s values contained in sig.

- -

The r and s values can be set by calling DSA_SIG_set0() and passing the new values for r and s as parameters to the function. Calling this function transfers the memory management of the values to the DSA_SIG object, and therefore the values that have been passed in should not be freed directly after this function has been called.

- -

RETURN VALUES

- -

If the allocation fails, DSA_SIG_new() returns NULL and sets an error code that can be obtained by ERR_get_error(3). Otherwise it returns a pointer to the newly allocated structure.

- -

DSA_SIG_free() returns no value.

- -

DSA_SIG_set0() returns 1 on success or 0 on failure.

- -

SEE ALSO

- -

EVP_PKEY_new(3), EVP_PKEY_free(3), EVP_PKEY_get_bn_param(3), ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_do_sign.html b/openssl-install/share/doc/openssl/html/man3/DSA_do_sign.html deleted file mode 100644 index 2a740f9c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_do_sign.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -DSA_do_sign - - - - - - - - - - -

NAME

- -

DSA_do_sign, DSA_do_verify - raw DSA signature operations

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DSA_SIG *DSA_do_sign(const unsigned char *dgst, int dlen, DSA *dsa);
-
-int DSA_do_verify(const unsigned char *dgst, int dgst_len,
-                  DSA_SIG *sig, DSA *dsa);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_sign_init(3), EVP_PKEY_sign(3), EVP_PKEY_verify_init(3) and EVP_PKEY_verify(3).

- -

DSA_do_sign() computes a digital signature on the len byte message digest dgst using the private key dsa and returns it in a newly allocated DSA_SIG structure.

- -

DSA_sign_setup(3) may be used to precompute part of the signing operation in case signature generation is time-critical.

- -

DSA_do_verify() verifies that the signature sig matches a given message digest dgst of size len. dsa is the signer's public key.

- -

RETURN VALUES

- -

DSA_do_sign() returns the signature, NULL on error. DSA_do_verify() returns 1 for a valid signature, 0 for an incorrect signature and -1 on error. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

DSA_new(3), ERR_get_error(3), RAND_bytes(3), DSA_SIG_new(3), DSA_sign(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_dup_DH.html b/openssl-install/share/doc/openssl/html/man3/DSA_dup_DH.html deleted file mode 100644 index 16be36d5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_dup_DH.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -DSA_dup_DH - - - - - - - - - - -

NAME

- -

DSA_dup_DH - create a DH structure out of DSA structure

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DH *DSA_dup_DH(const DSA *r);
- -

DESCRIPTION

- -

The function described on this page is deprecated. There is no direct replacement, applications should use the EVP_PKEY APIs for Diffie-Hellman operations.

- -

DSA_dup_DH() duplicates DSA parameters/keys as DH parameters/keys. q is lost during that conversion, but the resulting DH parameters contain its length.

- -

RETURN VALUES

- -

DSA_dup_DH() returns the new DH structure, and NULL on error. The error codes can be obtained by ERR_get_error(3).

- -

NOTE

- -

Be careful to avoid small subgroup attacks when using this.

- -

SEE ALSO

- -

DH_new(3), DSA_new(3), ERR_get_error(3)

- -

HISTORY

- -

This function was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_generate_key.html b/openssl-install/share/doc/openssl/html/man3/DSA_generate_key.html deleted file mode 100644 index 38361711..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_generate_key.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -DSA_generate_key - - - - - - - - - - -

NAME

- -

DSA_generate_key - generate DSA key pair

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DSA_generate_key(DSA *a);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_keygen_init(3) and EVP_PKEY_keygen(3) as described in EVP_PKEY-DSA(7).

- -

DSA_generate_key() expects a to contain DSA parameters. It generates a new key pair and stores it in a->pub_key and a->priv_key.

- -

The random generator must be seeded prior to calling DSA_generate_key(). If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

RETURN VALUES

- -

DSA_generate_key() returns 1 on success, 0 otherwise. The error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

DSA_new(3), ERR_get_error(3), RAND_bytes(3), DSA_generate_parameters_ex(3)

- -

HISTORY

- -

This function was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_generate_parameters.html b/openssl-install/share/doc/openssl/html/man3/DSA_generate_parameters.html deleted file mode 100644 index be80c6e3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_generate_parameters.html +++ /dev/null @@ -1,118 +0,0 @@ - - - - -DSA_generate_parameters - - - - - - - - - - -

NAME

- -

DSA_generate_parameters_ex, DSA_generate_parameters - generate DSA parameters

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DSA_generate_parameters_ex(DSA *dsa, int bits,
-                               const unsigned char *seed, int seed_len,
-                               int *counter_ret, unsigned long *h_ret,
-                               BN_GENCB *cb);
- -

The following functions have been deprecated since OpenSSL 0.9.8, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DSA *DSA_generate_parameters(int bits, unsigned char *seed, int seed_len,
-                             int *counter_ret, unsigned long *h_ret,
-                             void (*callback)(int, int, void *), void *cb_arg);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_paramgen_init(3) and EVP_PKEY_keygen(3) as described in EVP_PKEY-DSA(7).

- -

DSA_generate_parameters_ex() generates primes p and q and a generator g for use in the DSA and stores the result in dsa.

- -

bits is the length of the prime p to be generated. For lengths under 2048 bits, the length of q is 160 bits; for lengths greater than or equal to 2048 bits, the length of q is set to 256 bits.

- -

If seed is NULL, the primes will be generated at random. If seed_len is less than the length of q, an error is returned.

- -

DSA_generate_parameters_ex() places the iteration count in *counter_ret and a counter used for finding a generator in *h_ret, unless these are NULL.

- -

A callback function may be used to provide feedback about the progress of the key generation. If cb is not NULL, it will be called as shown below. For information on the BN_GENCB structure and the BN_GENCB_call function discussed below, refer to BN_generate_prime(3).

- -

DSA_generate_parameters() is similar to DSA_generate_parameters_ex() but expects an old-style callback function; see BN_generate_prime(3) for information on the old-style callback.

- - - -

RETURN VALUES

- -

DSA_generate_parameters_ex() returns a 1 on success, or 0 otherwise. The error codes can be obtained by ERR_get_error(3).

- -

DSA_generate_parameters() returns a pointer to the DSA structure or NULL if the parameter generation fails.

- -

BUGS

- -

Seed lengths greater than 20 are not supported.

- -

SEE ALSO

- -

DSA_new(3), ERR_get_error(3), RAND_bytes(3), DSA_free(3), BN_generate_prime(3)

- -

HISTORY

- -

DSA_generate_parameters_ex() was deprecated in OpenSSL 3.0.

- -

DSA_generate_parameters() was deprecated in OpenSSL 0.9.8; use DSA_generate_parameters_ex() instead.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_get0_pqg.html b/openssl-install/share/doc/openssl/html/man3/DSA_get0_pqg.html deleted file mode 100644 index 6d1dd7cd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_get0_pqg.html +++ /dev/null @@ -1,102 +0,0 @@ - - - - -DSA_get0_pqg - - - - - - - - - - -

NAME

- -

DSA_get0_pqg, DSA_set0_pqg, DSA_get0_key, DSA_set0_key, DSA_get0_p, DSA_get0_q, DSA_get0_g, DSA_get0_pub_key, DSA_get0_priv_key, DSA_clear_flags, DSA_test_flags, DSA_set_flags, DSA_get0_engine - Routines for getting and setting data in a DSA object

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void DSA_get0_pqg(const DSA *d,
-                  const BIGNUM **p, const BIGNUM **q, const BIGNUM **g);
-int DSA_set0_pqg(DSA *d, BIGNUM *p, BIGNUM *q, BIGNUM *g);
-void DSA_get0_key(const DSA *d,
-                  const BIGNUM **pub_key, const BIGNUM **priv_key);
-int DSA_set0_key(DSA *d, BIGNUM *pub_key, BIGNUM *priv_key);
-const BIGNUM *DSA_get0_p(const DSA *d);
-const BIGNUM *DSA_get0_q(const DSA *d);
-const BIGNUM *DSA_get0_g(const DSA *d);
-const BIGNUM *DSA_get0_pub_key(const DSA *d);
-const BIGNUM *DSA_get0_priv_key(const DSA *d);
-void DSA_clear_flags(DSA *d, int flags);
-int DSA_test_flags(const DSA *d, int flags);
-void DSA_set_flags(DSA *d, int flags);
-ENGINE *DSA_get0_engine(DSA *d);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_get_bn_param(3).

- -

A DSA object contains the parameters p, q and g. It also contains a public key (pub_key) and (optionally) a private key (priv_key).

- -

The p, q and g parameters can be obtained by calling DSA_get0_pqg(). If the parameters have not yet been set then *p, *q and *g will be set to NULL. Otherwise they are set to pointers to their respective values. These point directly to the internal representations of the values and therefore should not be freed directly.

- -

The p, q and g values can be set by calling DSA_set0_pqg() and passing the new values for p, q and g as parameters to the function. Calling this function transfers the memory management of the values to the DSA object, and therefore the values that have been passed in should not be freed directly after this function has been called.

- -

To get the public and private key values use the DSA_get0_key() function. A pointer to the public key will be stored in *pub_key, and a pointer to the private key will be stored in *priv_key. Either may be NULL if they have not been set yet, although if the private key has been set then the public key must be. The values point to the internal representation of the public key and private key values. This memory should not be freed directly.

- -

The public and private key values can be set using DSA_set0_key(). The public key must be non-NULL the first time this function is called on a given DSA object. The private key may be NULL. On subsequent calls, either may be NULL, which means the corresponding DSA field is left untouched. As for DSA_set0_pqg() this function transfers the memory management of the key values to the DSA object, and therefore they should not be freed directly after this function has been called.

- -

Any of the values p, q, g, priv_key, and pub_key can also be retrieved separately by the corresponding function DSA_get0_p(), DSA_get0_q(), DSA_get0_g(), DSA_get0_priv_key(), and DSA_get0_pub_key(), respectively.

- -

DSA_set_flags() sets the flags in the flags parameter on the DSA object. Multiple flags can be passed in one go (bitwise ORed together). Any flags that are already set are left set. DSA_test_flags() tests to see whether the flags passed in the flags parameter are currently set in the DSA object. Multiple flags can be tested in one go. All flags that are currently set are returned, or zero if none of the flags are set. DSA_clear_flags() clears the specified flags within the DSA object.

- -

DSA_get0_engine() returns a handle to the ENGINE that has been set for this DSA object, or NULL if no such ENGINE has been set.

- -

NOTES

- -

Values retrieved with DSA_get0_key() are owned by the DSA object used in the call and may therefore not be passed to DSA_set0_key(). If needed, duplicate the received value using BN_dup() and pass the duplicate. The same applies to DSA_get0_pqg() and DSA_set0_pqg().

- -

RETURN VALUES

- -

DSA_set0_pqg() and DSA_set0_key() return 1 on success or 0 on failure.

- -

DSA_test_flags() returns the current state of the flags in the DSA object.

- -

DSA_get0_engine() returns the ENGINE set for the DSA object or NULL if no ENGINE has been set.

- -

SEE ALSO

- -

EVP_PKEY_get_bn_param(3), DSA_new(3), DSA_new(3), DSA_generate_parameters(3), DSA_generate_key(3), DSA_dup_DH(3), DSA_do_sign(3), DSA_set_method(3), DSA_SIG_new(3), DSA_sign(3), DSA_size(3), DSA_meth_new(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 1.1.0 and deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_meth_new.html b/openssl-install/share/doc/openssl/html/man3/DSA_meth_new.html deleted file mode 100644 index 1399b2f5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_meth_new.html +++ /dev/null @@ -1,177 +0,0 @@ - - - - -DSA_meth_new - - - - - - - - - - -

NAME

- -

DSA_meth_new, DSA_meth_free, DSA_meth_dup, DSA_meth_get0_name, DSA_meth_set1_name, DSA_meth_get_flags, DSA_meth_set_flags, DSA_meth_get0_app_data, DSA_meth_set0_app_data, DSA_meth_get_sign, DSA_meth_set_sign, DSA_meth_get_sign_setup, DSA_meth_set_sign_setup, DSA_meth_get_verify, DSA_meth_set_verify, DSA_meth_get_mod_exp, DSA_meth_set_mod_exp, DSA_meth_get_bn_mod_exp, DSA_meth_set_bn_mod_exp, DSA_meth_get_init, DSA_meth_set_init, DSA_meth_get_finish, DSA_meth_set_finish, DSA_meth_get_paramgen, DSA_meth_set_paramgen, DSA_meth_get_keygen, DSA_meth_set_keygen - Routines to build up DSA methods

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DSA_METHOD *DSA_meth_new(const char *name, int flags);
-
-void DSA_meth_free(DSA_METHOD *dsam);
-
-DSA_METHOD *DSA_meth_dup(const DSA_METHOD *meth);
-
-const char *DSA_meth_get0_name(const DSA_METHOD *dsam);
-int DSA_meth_set1_name(DSA_METHOD *dsam, const char *name);
-
-int DSA_meth_get_flags(const DSA_METHOD *dsam);
-int DSA_meth_set_flags(DSA_METHOD *dsam, int flags);
-
-void *DSA_meth_get0_app_data(const DSA_METHOD *dsam);
-int DSA_meth_set0_app_data(DSA_METHOD *dsam, void *app_data);
-
-DSA_SIG *(*DSA_meth_get_sign(const DSA_METHOD *dsam))(const unsigned char *,
-                                                      int, DSA *);
-int DSA_meth_set_sign(DSA_METHOD *dsam, DSA_SIG *(*sign)(const unsigned char *,
-                                                         int, DSA *));
-
-int (*DSA_meth_get_sign_setup(const DSA_METHOD *dsam))(DSA *, BN_CTX *,$
-                                                       BIGNUM **, BIGNUM **);
-int DSA_meth_set_sign_setup(DSA_METHOD *dsam, int (*sign_setup)(DSA *, BN_CTX *,
-                                                                BIGNUM **, BIGNUM **));
-
-int (*DSA_meth_get_verify(const DSA_METHOD *dsam))(const unsigned char *,
-                                                   int, DSA_SIG *, DSA *);
-int DSA_meth_set_verify(DSA_METHOD *dsam, int (*verify)(const unsigned char *,
-                                                        int, DSA_SIG *, DSA *));
-
-int (*DSA_meth_get_mod_exp(const DSA_METHOD *dsam))(DSA *dsa, BIGNUM *rr, BIGNUM *a1,
-                                                    BIGNUM *p1, BIGNUM *a2, BIGNUM *p2,
-                                                    BIGNUM *m, BN_CTX *ctx,
-                                                    BN_MONT_CTX *in_mont);
-int DSA_meth_set_mod_exp(DSA_METHOD *dsam, int (*mod_exp)(DSA *dsa, BIGNUM *rr,
-                                                          BIGNUM *a1, BIGNUM *p1,
-                                                          BIGNUM *a2, BIGNUM *p2,
-                                                          BIGNUM *m, BN_CTX *ctx,
-                                                          BN_MONT_CTX *mont));
-
-int (*DSA_meth_get_bn_mod_exp(const DSA_METHOD *dsam))(DSA *dsa, BIGNUM *r, BIGNUM *a,
-                                                       const BIGNUM *p, const BIGNUM *m,
-                                                       BN_CTX *ctx, BN_MONT_CTX *mont);
-int DSA_meth_set_bn_mod_exp(DSA_METHOD *dsam, int (*bn_mod_exp)(DSA *dsa,
-                                                                BIGNUM *r,
-                                                                BIGNUM *a,
-                                                                const BIGNUM *p,
-                                                                const BIGNUM *m,
-                                                                BN_CTX *ctx,
-                                                                BN_MONT_CTX *mont));
-
-int (*DSA_meth_get_init(const DSA_METHOD *dsam))(DSA *);
-int DSA_meth_set_init(DSA_METHOD *dsam, int (*init)(DSA *));
-
-int (*DSA_meth_get_finish(const DSA_METHOD *dsam))(DSA *);
-int DSA_meth_set_finish(DSA_METHOD *dsam, int (*finish)(DSA *));
-
-int (*DSA_meth_get_paramgen(const DSA_METHOD *dsam))(DSA *, int,
-                                                     const unsigned char *,
-                                                     int, int *, unsigned long *,
-                                                     BN_GENCB *);
-int DSA_meth_set_paramgen(DSA_METHOD *dsam,
-                          int (*paramgen)(DSA *, int, const unsigned char *,
-                                          int, int *, unsigned long *, BN_GENCB *));
-
-int (*DSA_meth_get_keygen(const DSA_METHOD *dsam))(DSA *);
-int DSA_meth_set_keygen(DSA_METHOD *dsam, int (*keygen)(DSA *));
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications and extension implementations should instead use the OSSL_PROVIDER APIs.

- -

The DSA_METHOD type is a structure used for the provision of custom DSA implementations. It provides a set of functions used by OpenSSL for the implementation of the various DSA capabilities.

- -

DSA_meth_new() creates a new DSA_METHOD structure. It should be given a unique name and a set of flags. The name should be a NULL terminated string, which will be duplicated and stored in the DSA_METHOD object. It is the callers responsibility to free the original string. The flags will be used during the construction of a new DSA object based on this DSA_METHOD. Any new DSA object will have those flags set by default.

- -

DSA_meth_dup() creates a duplicate copy of the DSA_METHOD object passed as a parameter. This might be useful for creating a new DSA_METHOD based on an existing one, but with some differences.

- -

DSA_meth_free() destroys a DSA_METHOD structure and frees up any memory associated with it. If the argument is NULL, nothing is done.

- -

DSA_meth_get0_name() will return a pointer to the name of this DSA_METHOD. This is a pointer to the internal name string and so should not be freed by the caller. DSA_meth_set1_name() sets the name of the DSA_METHOD to name. The string is duplicated and the copy is stored in the DSA_METHOD structure, so the caller remains responsible for freeing the memory associated with the name.

- -

DSA_meth_get_flags() returns the current value of the flags associated with this DSA_METHOD. DSA_meth_set_flags() provides the ability to set these flags.

- -

The functions DSA_meth_get0_app_data() and DSA_meth_set0_app_data() provide the ability to associate implementation specific data with the DSA_METHOD. It is the application's responsibility to free this data before the DSA_METHOD is freed via a call to DSA_meth_free().

- -

DSA_meth_get_sign() and DSA_meth_set_sign() get and set the function used for creating a DSA signature respectively. This function will be called in response to the application calling DSA_do_sign() (or DSA_sign()). The parameters for the function have the same meaning as for DSA_do_sign().

- -

DSA_meth_get_sign_setup() and DSA_meth_set_sign_setup() get and set the function used for precalculating the DSA signature values k^-1 and r. This function will be called in response to the application calling DSA_sign_setup(). The parameters for the function have the same meaning as for DSA_sign_setup().

- -

DSA_meth_get_verify() and DSA_meth_set_verify() get and set the function used for verifying a DSA signature respectively. This function will be called in response to the application calling DSA_do_verify() (or DSA_verify()). The parameters for the function have the same meaning as for DSA_do_verify().

- -

DSA_meth_get_mod_exp() and DSA_meth_set_mod_exp() get and set the function used for computing the following value:

- -
rr = a1^p1 * a2^p2 mod m
- -

This function will be called by the default OpenSSL method during verification of a DSA signature. The result is stored in the rr parameter. This function may be NULL.

- -

DSA_meth_get_bn_mod_exp() and DSA_meth_set_bn_mod_exp() get and set the function used for computing the following value:

- -
r = a ^ p mod m
- -

This function will be called by the default OpenSSL function for DSA_sign_setup(). The result is stored in the r parameter. This function may be NULL.

- -

DSA_meth_get_init() and DSA_meth_set_init() get and set the function used for creating a new DSA instance respectively. This function will be called in response to the application calling DSA_new() (if the current default DSA_METHOD is this one) or DSA_new_method(). The DSA_new() and DSA_new_method() functions will allocate the memory for the new DSA object, and a pointer to this newly allocated structure will be passed as a parameter to the function. This function may be NULL.

- -

DSA_meth_get_finish() and DSA_meth_set_finish() get and set the function used for destroying an instance of a DSA object respectively. This function will be called in response to the application calling DSA_free(). A pointer to the DSA to be destroyed is passed as a parameter. The destroy function should be used for DSA implementation specific clean up. The memory for the DSA itself should not be freed by this function. This function may be NULL.

- -

DSA_meth_get_paramgen() and DSA_meth_set_paramgen() get and set the function used for generating DSA parameters respectively. This function will be called in response to the application calling DSA_generate_parameters_ex() (or DSA_generate_parameters()). The parameters for the function have the same meaning as for DSA_generate_parameters_ex().

- -

DSA_meth_get_keygen() and DSA_meth_set_keygen() get and set the function used for generating a new DSA key pair respectively. This function will be called in response to the application calling DSA_generate_key(). The parameter for the function has the same meaning as for DSA_generate_key().

- -

RETURN VALUES

- -

DSA_meth_new() and DSA_meth_dup() return the newly allocated DSA_METHOD object or NULL on failure.

- -

DSA_meth_get0_name() and DSA_meth_get_flags() return the name and flags associated with the DSA_METHOD respectively.

- -

All other DSA_meth_get_*() functions return the appropriate function pointer that has been set in the DSA_METHOD, or NULL if no such pointer has yet been set.

- -

DSA_meth_set1_name() and all DSA_meth_set_*() functions return 1 on success or 0 on failure.

- -

SEE ALSO

- -

DSA_new(3), DSA_new(3), DSA_generate_parameters(3), DSA_generate_key(3), DSA_dup_DH(3), DSA_do_sign(3), DSA_set_method(3), DSA_SIG_new(3), DSA_sign(3), DSA_size(3), DSA_get0_pqg(3)

- -

HISTORY

- -

The functions described here were deprecated in OpenSSL 3.0.

- -

The functions described here were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_new.html b/openssl-install/share/doc/openssl/html/man3/DSA_new.html deleted file mode 100644 index d5bc6e03..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_new.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -DSA_new - - - - - - - - - - -

NAME

- -

DSA_new, DSA_free - allocate and free DSA objects

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DSA* DSA_new(void);
-
-void DSA_free(DSA *dsa);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_new(3) and EVP_PKEY_free(3).

- -

DSA_new() allocates and initializes a DSA structure. It is equivalent to calling DSA_new_method(NULL).

- -

DSA_free() frees the DSA structure and its components. The values are erased before the memory is returned to the system. If dsa is NULL nothing is done.

- -

RETURN VALUES

- -

If the allocation fails, DSA_new() returns NULL and sets an error code that can be obtained by ERR_get_error(3). Otherwise it returns a pointer to the newly allocated structure.

- -

DSA_free() returns no value.

- -

SEE ALSO

- -

EVP_PKEY_new(3), EVP_PKEY_free(3), DSA_new(3), ERR_get_error(3), DSA_generate_parameters(3), DSA_generate_key(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_set_method.html b/openssl-install/share/doc/openssl/html/man3/DSA_set_method.html deleted file mode 100644 index 9781d4ce..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_set_method.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -DSA_set_method - - - - - - - - - - -

NAME

- -

DSA_set_default_method, DSA_get_default_method, DSA_set_method, DSA_new_method, DSA_OpenSSL - select DSA method

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void DSA_set_default_method(const DSA_METHOD *meth);
-
-const DSA_METHOD *DSA_get_default_method(void);
-
-int DSA_set_method(DSA *dsa, const DSA_METHOD *meth);
-
-DSA *DSA_new_method(ENGINE *engine);
-
-const DSA_METHOD *DSA_OpenSSL(void);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should providers instead of method overrides.

- -

A DSA_METHOD specifies the functions that OpenSSL uses for DSA operations. By modifying the method, alternative implementations such as hardware accelerators may be used. IMPORTANT: See the NOTES section for important information about how these DSA API functions are affected by the use of ENGINE API calls.

- -

Initially, the default DSA_METHOD is the OpenSSL internal implementation, as returned by DSA_OpenSSL().

- -

DSA_set_default_method() makes meth the default method for all DSA structures created later. NB: This is true only whilst no ENGINE has been set as a default for DSA, so this function is no longer recommended. This function is not thread-safe and should not be called at the same time as other OpenSSL functions.

- -

DSA_get_default_method() returns a pointer to the current default DSA_METHOD. However, the meaningfulness of this result is dependent on whether the ENGINE API is being used, so this function is no longer recommended.

- -

DSA_set_method() selects meth to perform all operations using the key rsa. This will replace the DSA_METHOD used by the DSA key and if the previous method was supplied by an ENGINE, the handle to that ENGINE will be released during the change. It is possible to have DSA keys that only work with certain DSA_METHOD implementations (e.g. from an ENGINE module that supports embedded hardware-protected keys), and in such cases attempting to change the DSA_METHOD for the key can have unexpected results. See DSA_meth_new(3) for information on constructing custom DSA_METHOD objects;

- -

DSA_new_method() allocates and initializes a DSA structure so that engine will be used for the DSA operations. If engine is NULL, the default engine for DSA operations is used, and if no default ENGINE is set, the DSA_METHOD controlled by DSA_set_default_method() is used.

- -

RETURN VALUES

- -

DSA_OpenSSL() and DSA_get_default_method() return pointers to the respective DSA_METHODs.

- -

DSA_set_default_method() returns no value.

- -

DSA_set_method() returns nonzero if the provided meth was successfully set as the method for dsa (including unloading the ENGINE handle if the previous method was supplied by an ENGINE).

- -

DSA_new_method() returns NULL and sets an error code that can be obtained by ERR_get_error(3) if the allocation fails. Otherwise it returns a pointer to the newly allocated structure.

- -

SEE ALSO

- -

DSA_new(3), DSA_new(3), DSA_meth_new(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_sign.html b/openssl-install/share/doc/openssl/html/man3/DSA_sign.html deleted file mode 100644 index c14a945a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_sign.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -DSA_sign - - - - - - - - - - -

NAME

- -

DSA_sign, DSA_sign_setup, DSA_verify - DSA signatures

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DSA_sign(int type, const unsigned char *dgst, int len,
-             unsigned char *sigret, unsigned int *siglen, DSA *dsa);
-
-int DSA_sign_setup(DSA *dsa, BN_CTX *ctx, BIGNUM **kinvp, BIGNUM **rp);
-
-int DSA_verify(int type, const unsigned char *dgst, int len,
-               unsigned char *sigbuf, int siglen, DSA *dsa);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_sign_init(3), EVP_PKEY_sign(3), EVP_PKEY_verify_init(3) and EVP_PKEY_verify(3).

- -

DSA_sign() computes a digital signature on the len byte message digest dgst using the private key dsa and places its ASN.1 DER encoding at sigret. The length of the signature is places in *siglen. sigret must point to DSA_size(dsa) bytes of memory.

- -

DSA_sign_setup() is defined only for backward binary compatibility and should not be used. Since OpenSSL 1.1.0 the DSA type is opaque and the output of DSA_sign_setup() cannot be used anyway: calling this function will only cause overhead, and does not affect the actual signature (pre-)computation.

- -

DSA_verify() verifies that the signature sigbuf of size siglen matches a given message digest dgst of size len. dsa is the signer's public key.

- -

The type parameter is ignored.

- -

The random generator must be seeded when DSA_sign() (or DSA_sign_setup()) is called. If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

RETURN VALUES

- -

DSA_sign() and DSA_sign_setup() return 1 on success, 0 on error. DSA_verify() returns 1 for a valid signature, 0 for an incorrect signature and -1 on error. The error codes can be obtained by ERR_get_error(3).

- -

CONFORMING TO

- -

US Federal Information Processing Standard FIPS186-4 (Digital Signature Standard, DSS), ANSI X9.30

- -

SEE ALSO

- -

DSA_new(3), ERR_get_error(3), RAND_bytes(3), DSA_do_sign(3), RAND(7)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DSA_size.html b/openssl-install/share/doc/openssl/html/man3/DSA_size.html deleted file mode 100644 index 919ac657..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DSA_size.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -DSA_size - - - - - - - - - - -

NAME

- -

DSA_size, DSA_bits, DSA_security_bits - get DSA signature size, key bits or security bits

- -

SYNOPSIS

- -
#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DSA_bits(const DSA *dsa);
-
-int DSA_size(const DSA *dsa);
-
-int DSA_security_bits(const DSA *dsa);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_get_bits(3), EVP_PKEY_get_security_bits(3) and EVP_PKEY_get_size(3).

- -

DSA_bits() returns the number of bits in key dsa: this is the number of bits in the p parameter.

- -

DSA_size() returns the maximum size of an ASN.1 encoded DSA signature for key dsa in bytes. It can be used to determine how much memory must be allocated for a DSA signature.

- -

DSA_security_bits() returns the number of security bits of the given dsa key. See BN_security_bits(3).

- -

RETURN VALUES

- -

DSA_security_bits() returns the number of security bits in the key, or -1 if dsa doesn't hold any key parameters.

- -

DSA_bits() returns the number of bits in the key, or -1 if dsa doesn't hold any key parameters.

- -

DSA_size() returns the signature size in bytes, or -1 if dsa doesn't hold any key parameters.

- -

SEE ALSO

- -

EVP_PKEY_get_bits(3), EVP_PKEY_get_security_bits(3), EVP_PKEY_get_size(3), DSA_new(3), DSA_sign(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DTLS_get_data_mtu.html b/openssl-install/share/doc/openssl/html/man3/DTLS_get_data_mtu.html deleted file mode 100644 index ea863025..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DTLS_get_data_mtu.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -DTLS_get_data_mtu - - - - - - - - - - -

NAME

- -

DTLS_get_data_mtu - Get maximum data payload size

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-size_t DTLS_get_data_mtu(const SSL *ssl);
- -

DESCRIPTION

- -

This function obtains the maximum data payload size for the established DTLS connection ssl, based on the DTLS record MTU and the overhead of the DTLS record header, encryption and authentication currently in use.

- -

RETURN VALUES

- -

Returns the maximum data payload size on success, or 0 on failure.

- -

HISTORY

- -

The DTLS_get_data_mtu() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DTLS_set_timer_cb.html b/openssl-install/share/doc/openssl/html/man3/DTLS_set_timer_cb.html deleted file mode 100644 index 001ab09f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DTLS_set_timer_cb.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -DTLS_set_timer_cb - - - - - - - - - - -

NAME

- -

DTLS_timer_cb, DTLS_set_timer_cb - Set callback for controlling DTLS timer duration

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef unsigned int (*DTLS_timer_cb)(SSL *s, unsigned int timer_us);
-
-void DTLS_set_timer_cb(SSL *s, DTLS_timer_cb cb);
- -

DESCRIPTION

- -

This function sets an optional callback function for controlling the timeout interval on the DTLS protocol. The callback function will be called by DTLS for every new DTLS packet that is sent.

- -

The callback should return the timeout interval in micro seconds.

- -

The timer_us parameter of the callback is the last set timeout interval returned. On the first invocation of the callback, this value will be 0.

- -

At the beginning of the connection, if no timeout callback has been set via DTLS_set_timer_cb(), the default timeout value is 1 second. For all subsequent timeouts, the default behavior is to double the duration up to a maximum of 1 minute.

- -

RETURN VALUES

- -

Returns void.

- -

HISTORY

- -

The DTLS_set_timer_cb() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DTLSv1_get_timeout.html b/openssl-install/share/doc/openssl/html/man3/DTLSv1_get_timeout.html deleted file mode 100644 index 11dbacf8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DTLSv1_get_timeout.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -DTLSv1_get_timeout - - - - - - - - - - -

NAME

- -

DTLSv1_get_timeout - determine when a DTLS or QUIC SSL object next needs a timeout event to be handled

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int DTLSv1_get_timeout(SSL *s, struct timeval *tv);
- -

DESCRIPTION

- -

DTLSv1_get_timeout() can be used on a DTLS or QUIC SSL object to determine when the SSL object next needs to perform internal processing due to the passage of time.

- -

Calling DTLSv1_get_timeout() results in *tv being written with an amount of time left before the SSL object needs have DTLSv1_handle_timeout() called on it. If the SSL object needs to be ticked immediately, *tv is zeroed and the function succeeds, returning 1. If no timeout is currently active, this function returns 0.

- -

This function is only applicable to DTLS and QUIC objects. It fails if called on any other kind of SSL object.

- -

Note that the value output by a call to DTLSv1_get_timeout() may change as a result of other calls to the SSL object.

- -

Once the timeout expires, DTLSv1_handle_timeout() should be called to handle any internal processing which is due; for more information, see DTLSv1_handle_timeout(3).

- -

SSL_get_event_timeout(3) supersedes all use cases for this this function and may be used instead of it.

- -

RETURN VALUES

- -

On success, writes a duration to *tv and returns 1.

- -

Returns 0 on failure, or if no timeout is currently active.

- -

SEE ALSO

- -

DTLSv1_handle_timeout(3), SSL_get_event_timeout(3), ssl(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DTLSv1_handle_timeout.html b/openssl-install/share/doc/openssl/html/man3/DTLSv1_handle_timeout.html deleted file mode 100644 index cedaf16d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DTLSv1_handle_timeout.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -DTLSv1_handle_timeout - - - - - - - - - - -

NAME

- -

DTLSv1_handle_timeout - handle a pending timeout event for a DTLS or QUIC SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int DTLSv1_handle_timeout(SSL *ssl);
- -

DESCRIPTION

- -

DTLSv1_handle_timeout() handles any timeout events which have become pending on a DTLS or QUIC SSL object.

- -

Use DTLSv1_get_timeout(3) or SSL_get_event_timeout(3) to determine when to call DTLSv1_handle_timeout().

- -

This function is only applicable to DTLS or QUIC SSL objects. It returns 0 if called on any other kind of SSL object.

- -

SSL_handle_events(3) supersedes all use cases for this function and may be used instead of it.

- -

RETURN VALUES

- -

Returns 1 if there was a pending timeout event and it was handled successfully.

- -

Returns 0 if there was no pending timeout event, or if the SSL object is not a DTLS or QUIC object.

- -

Returns -1 if there was a pending timeout event but it could not be handled successfully.

- -

SEE ALSO

- -

DTLSv1_get_timeout(3), SSL_handle_events(3), ssl(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/DTLSv1_listen.html b/openssl-install/share/doc/openssl/html/man3/DTLSv1_listen.html deleted file mode 100644 index 34b73d67..00000000 --- a/openssl-install/share/doc/openssl/html/man3/DTLSv1_listen.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -DTLSv1_listen - - - - - - - - - - -

NAME

- -

SSL_stateless, DTLSv1_listen - Statelessly listen for incoming connections

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_stateless(SSL *s);
-int DTLSv1_listen(SSL *ssl, BIO_ADDR *peer);
- -

DESCRIPTION

- -

SSL_stateless() statelessly listens for new incoming TLSv1.3 connections. DTLSv1_listen() statelessly listens for new incoming DTLS connections. If a ClientHello is received that does not contain a cookie, then they respond with a request for a new ClientHello that does contain a cookie. If a ClientHello is received with a cookie that is verified then the function returns in order to enable the handshake to be completed (for example by using SSL_accept()).

- -

NOTES

- -

Some transport protocols (such as UDP) can be susceptible to amplification attacks. Unlike TCP there is no initial connection setup in UDP that validates that the client can actually receive messages on its advertised source address. An attacker could forge its source IP address and then send handshake initiation messages to the server. The server would then send its response to the forged source IP. If the response messages are larger than the original message then the amplification attack has succeeded.

- -

If DTLS is used over UDP (or any datagram based protocol that does not validate the source IP) then it is susceptible to this type of attack. TLSv1.3 is designed to operate over a stream-based transport protocol (such as TCP). If TCP is being used then there is no need to use SSL_stateless(). However, some stream-based transport protocols (e.g. QUIC) may not validate the source address. In this case a TLSv1.3 application would be susceptible to this attack.

- -

As a countermeasure to this issue TLSv1.3 and DTLS include a stateless cookie mechanism. The idea is that when a client attempts to connect to a server it sends a ClientHello message. The server responds with a HelloRetryRequest (in TLSv1.3) or a HelloVerifyRequest (in DTLS) which contains a unique cookie. The client then resends the ClientHello, but this time includes the cookie in the message thus proving that the client is capable of receiving messages sent to that address. All of this can be done by the server without allocating any state, and thus without consuming expensive resources.

- -

OpenSSL implements this capability via the SSL_stateless() and DTLSv1_listen() functions. The ssl parameter should be a newly allocated SSL object with its read and write BIOs set, in the same way as might be done for a call to SSL_accept(). Typically, for DTLS, the read BIO will be in an "unconnected" state and thus capable of receiving messages from any peer.

- -

When a ClientHello is received that contains a cookie that has been verified, then these functions will return with the ssl parameter updated into a state where the handshake can be continued by a call to (for example) SSL_accept(). Additionally, for DTLSv1_listen(), the BIO_ADDR pointed to by peer will be filled in with details of the peer that sent the ClientHello. If the underlying BIO is unable to obtain the BIO_ADDR of the peer (for example because the BIO does not support this), then *peer will be cleared and the family set to AF_UNSPEC. Typically user code is expected to "connect" the underlying socket to the peer and continue the handshake in a connected state.

- -

Warning: It is essential that the calling code connects the underlying socket to the peer after making use of DTLSv1_listen(). In the typical case where BIO_s_datagram(3) is used, the peer address is updated when receiving a datagram on an unconnected socket. If the socket is not connected, it can receive datagrams from any host on the network, which will cause subsequent outgoing datagrams transmitted by DTLS to be transmitted to that host. In other words, failing to call BIO_connect() or a similar OS-specific function on a socket means that any host on the network can cause outgoing DTLS traffic to be redirected to it by sending a datagram to the socket in question. This does not break the cryptographic protections of DTLS but may facilitate a denial-of-service attack or allow unencrypted information in the DTLS handshake to be learned by an attacker. This is due to the historical design of BIO_s_datagram(3); see BIO_s_datagram(3) for details on this issue.

- -

Once a socket has been connected, BIO_ctrl_set_connected(3) should be used to inform the BIO that the socket is to be used in connected mode.

- -

Prior to calling DTLSv1_listen() user code must ensure that cookie generation and verification callbacks have been set up using SSL_CTX_set_cookie_generate_cb(3) and SSL_CTX_set_cookie_verify_cb(3) respectively. For SSL_stateless(), SSL_CTX_set_stateless_cookie_generate_cb(3) and SSL_CTX_set_stateless_cookie_verify_cb(3) must be used instead.

- -

Since DTLSv1_listen() operates entirely statelessly whilst processing incoming ClientHellos it is unable to process fragmented messages (since this would require the allocation of state). An implication of this is that DTLSv1_listen() only supports ClientHellos that fit inside a single datagram.

- -

For SSL_stateless() if an entire ClientHello message cannot be read without the "read" BIO becoming empty then the SSL_stateless() call will fail. It is the application's responsibility to ensure that data read from the "read" BIO during a single SSL_stateless() call is all from the same peer.

- -

SSL_stateless() will fail (with a 0 return value) if some TLS version less than TLSv1.3 is used.

- -

Both SSL_stateless() and DTLSv1_listen() will clear the error queue when they start.

- -

SSL_stateless() cannot be used with QUIC SSL objects and returns an error if called on such an object.

- -

RETURN VALUES

- -

For SSL_stateless() a return value of 1 indicates success and the ssl object will be set up ready to continue the handshake. A return value of 0 or -1 indicates failure. If the value is 0 then a HelloRetryRequest was sent. A value of -1 indicates any other error. User code may retry the SSL_stateless() call.

- -

For DTLSv1_listen() a return value of >= 1 indicates success. The ssl object will be set up ready to continue the handshake. the peer value will also be filled in.

- -

A return value of 0 indicates a non-fatal error. This could (for example) be because of nonblocking IO, or some invalid message having been received from a peer. Errors may be placed on the OpenSSL error queue with further information if appropriate. Typically user code is expected to retry the call to DTLSv1_listen() in the event of a non-fatal error.

- -

A return value of <0 indicates a fatal error. This could (for example) be because of a failure to allocate sufficient memory for the operation.

- -

For DTLSv1_listen(), prior to OpenSSL 1.1.0, fatal and non-fatal errors both produce return codes <= 0 (in typical implementations user code treats all errors as non-fatal), whilst return codes >0 indicate success.

- -

SEE ALSO

- -

SSL_CTX_set_cookie_generate_cb(3), SSL_CTX_set_cookie_verify_cb(3), SSL_CTX_set_stateless_cookie_generate_cb(3), SSL_CTX_set_stateless_cookie_verify_cb(3), SSL_get_error(3), SSL_accept(3), ssl(7), bio(7)

- -

HISTORY

- -

The SSL_stateless() function was added in OpenSSL 1.1.1.

- -

The DTLSv1_listen() return codes were clarified in OpenSSL 1.1.0. The type of "peer" also changed in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ECDSA_SIG_new.html b/openssl-install/share/doc/openssl/html/man3/ECDSA_SIG_new.html deleted file mode 100644 index 6226d2b8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ECDSA_SIG_new.html +++ /dev/null @@ -1,142 +0,0 @@ - - - - -ECDSA_SIG_new - - - - - - - - - - -

NAME

- -

ECDSA_SIG_new, ECDSA_SIG_free, ECDSA_SIG_get0, ECDSA_SIG_get0_r, ECDSA_SIG_get0_s, ECDSA_SIG_set0 - Functions for creating, destroying and manipulating ECDSA_SIG objects

- -

SYNOPSIS

- -
#include <openssl/ecdsa.h>
-
-ECDSA_SIG *ECDSA_SIG_new(void);
-void ECDSA_SIG_free(ECDSA_SIG *sig);
-void ECDSA_SIG_get0(const ECDSA_SIG *sig, const BIGNUM **pr, const BIGNUM **ps);
-const BIGNUM *ECDSA_SIG_get0_r(const ECDSA_SIG *sig);
-const BIGNUM *ECDSA_SIG_get0_s(const ECDSA_SIG *sig);
-int ECDSA_SIG_set0(ECDSA_SIG *sig, BIGNUM *r, BIGNUM *s);
- -

DESCRIPTION

- -

ECDSA_SIG is an opaque structure consisting of two BIGNUMs for the r and s value of an Elliptic Curve Digital Signature Algorithm (ECDSA) signature (see FIPS186-4 or X9.62). The ECDSA_SIG object was mainly used by the deprecated low level functions described in ECDSA_sign(3), it is still required in order to be able to set or get the values of r and s into or from a signature. This is mainly used for testing purposes as shown in the "EXAMPLES".

- -

ECDSA_SIG_new() allocates an empty ECDSA_SIG structure. Note: before OpenSSL 1.1.0, the r and s components were initialised.

- -

ECDSA_SIG_free() frees the ECDSA_SIG structure sig. If the argument is NULL, nothing is done.

- -

ECDSA_SIG_get0() returns internal pointers the r and s values contained in sig and stores them in *pr and *ps, respectively. The pointer pr or ps can be NULL, in which case the corresponding value is not returned.

- -

The values r, s can also be retrieved separately by the corresponding function ECDSA_SIG_get0_r() and ECDSA_SIG_get0_s(), respectively.

- -

Non-NULL r and s values can be set on the sig by calling ECDSA_SIG_set0(). Calling this function transfers the memory management of the values to the ECDSA_SIG object, and therefore the values that have been passed in should not be freed by the caller.

- -

See i2d_ECDSA_SIG(3) and d2i_ECDSA_SIG(3) for information about encoding and decoding ECDSA signatures to/from DER.

- -

RETURN VALUES

- -

ECDSA_SIG_new() returns NULL if the allocation fails.

- -

ECDSA_SIG_set0() returns 1 on success or 0 on failure.

- -

ECDSA_SIG_get0_r() and ECDSA_SIG_get0_s() return the corresponding value, or NULL if it is unset.

- -

EXAMPLES

- -

Extract signature r and s values from a ECDSA signature of size signaturelen:

- -
ECDSA_SIG *obj;
-const BIGNUM *r, *s;
-
-/* Load a signature into the ECDSA_SIG object */
-obj = d2i_ECDSA_SIG(NULL, &signature, signaturelen);
-if (obj == NULL)
-    /* error */
-
-r = ECDSA_SIG_get0_r(obj);
-s = ECDSA_SIG_get0_s(obj);
-if (r == NULL || s == NULL)
-    /* error */
-
-/* Use BN_bn2binpad() here to convert to r and s into byte arrays */
-
-/*
- * Do not try to access I<r> or I<s> after calling ECDSA_SIG_free(),
- * as they are both freed by this call.
- */
-ECDSA_SIG_free(obj);
- -

Convert r and s byte arrays into an ECDSA_SIG signature of size signaturelen:

- -
ECDSA_SIG *obj = NULL;
-unsigned char *signature = NULL;
-size_t signaturelen;
-BIGNUM *rbn = NULL, *sbn = NULL;
-
-obj = ECDSA_SIG_new();
-if (obj == NULL)
-    /* error */
-rbn = BN_bin2bn(r, rlen, NULL);
-sbn = BN_bin2bn(s, slen, NULL);
-if (rbn == NULL || sbn == NULL)
-    /* error */
-
-if (!ECDSA_SIG_set0(obj, rbn, sbn))
-    /* error */
-/* Set these to NULL since they are now owned by obj */
-rbn = sbn = NULL;
-
-signaturelen = i2d_ECDSA_SIG(obj, &signature);
-if (signaturelen <= 0)
-    /* error */
-
-/*
- * This signature could now be passed to L<EVP_DigestVerify(3)>
- * or L<EVP_DigestVerifyFinal(3)>
- */
-
-BN_free(rbn);
-BN_free(sbn);
-OPENSSL_free(signature);
-ECDSA_SIG_free(obj);
- -

CONFORMING TO

- -

ANSI X9.62, US Federal Information Processing Standard FIPS186-4 (Digital Signature Standard, DSS)

- -

SEE ALSO

- -

EC_KEY_new(3), EVP_DigestSignInit(3), EVP_DigestVerifyInit(3), EVP_PKEY_sign(3) i2d_ECDSA_SIG(3), d2i_ECDSA_SIG(3), ECDSA_sign(3)

- -

COPYRIGHT

- -

Copyright 2004-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ECDSA_sign.html b/openssl-install/share/doc/openssl/html/man3/ECDSA_sign.html deleted file mode 100644 index cf8870d8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ECDSA_sign.html +++ /dev/null @@ -1,165 +0,0 @@ - - - - -ECDSA_sign - - - - - - - - - - -

NAME

- -

ECDSA_size, ECDSA_sign, ECDSA_do_sign, ECDSA_verify, ECDSA_do_verify, ECDSA_sign_setup, ECDSA_sign_ex, ECDSA_do_sign_ex - deprecated low-level elliptic curve digital signature algorithm (ECDSA) functions

- -

SYNOPSIS

- -
#include <openssl/ecdsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int ECDSA_size(const EC_KEY *eckey);
-
-int ECDSA_sign(int type, const unsigned char *dgst, int dgstlen,
-               unsigned char *sig, unsigned int *siglen, EC_KEY *eckey);
-ECDSA_SIG *ECDSA_do_sign(const unsigned char *dgst, int dgst_len,
-                         EC_KEY *eckey);
-
-int ECDSA_verify(int type, const unsigned char *dgst, int dgstlen,
-                 const unsigned char *sig, int siglen, EC_KEY *eckey);
-int ECDSA_do_verify(const unsigned char *dgst, int dgst_len,
-                    const ECDSA_SIG *sig, EC_KEY* eckey);
-
-ECDSA_SIG *ECDSA_do_sign_ex(const unsigned char *dgst, int dgstlen,
-                            const BIGNUM *kinv, const BIGNUM *rp,
-                            EC_KEY *eckey);
-int ECDSA_sign_setup(EC_KEY *eckey, BN_CTX *ctx, BIGNUM **kinv, BIGNUM **rp);
-int ECDSA_sign_ex(int type, const unsigned char *dgst, int dgstlen,
-                  unsigned char *sig, unsigned int *siglen,
-                  const BIGNUM *kinv, const BIGNUM *rp, EC_KEY *eckey);
- -

DESCRIPTION

- -

See ECDSA_SIG_new(3) for a description of the ECDSA_SIG object.

- -

See i2d_ECDSA_SIG(3) and d2i_ECDSA_SIG(3) for information about encoding and decoding ECDSA signatures to/from DER.

- -

All of the functions described below are deprecated. Applications should use the higher level EVP interface such as EVP_DigestSignInit(3) or EVP_DigestVerifyInit(3) instead.

- -

ECDSA_size() returns the maximum length of a DER encoded ECDSA signature created with the private EC key eckey. To obtain the actual signature size use EVP_PKEY_sign(3) with a NULL sig parameter.

- -

ECDSA_sign() computes a digital signature of the dgstlen bytes hash value dgst using the private EC key eckey. The DER encoded signatures is stored in sig and its length is returned in siglen. Note: sig must point to ECDSA_size(eckey) bytes of memory. The parameter type is currently ignored. ECDSA_sign() is wrapper function for ECDSA_sign_ex() with kinv and rp set to NULL.

- -

ECDSA_do_sign() is similar to ECDSA_sign() except the signature is returned as a newly allocated ECDSA_SIG structure (or NULL on error). ECDSA_do_sign() is a wrapper function for ECDSA_do_sign_ex() with kinv and rp set to NULL.

- -

ECDSA_verify() verifies that the signature in sig of size siglen is a valid ECDSA signature of the hash value dgst of size dgstlen using the public key eckey. The parameter type is ignored.

- -

ECDSA_do_verify() is similar to ECDSA_verify() except the signature is presented in the form of a pointer to an ECDSA_SIG structure.

- -

The remaining functions utilise the internal kinv and r values used during signature computation. Most applications will never need to call these and some external ECDSA ENGINE implementations may not support them at all if either kinv or r is not NULL.

- -

ECDSA_sign_setup() may be used to precompute parts of the signing operation. eckey is the private EC key and ctx is a pointer to BN_CTX structure (or NULL). The precomputed values or returned in kinv and rp and can be used in a later call to ECDSA_sign_ex() or ECDSA_do_sign_ex().

- -

ECDSA_sign_ex() computes a digital signature of the dgstlen bytes hash value dgst using the private EC key eckey and the optional pre-computed values kinv and rp. The DER encoded signature is stored in sig and its length is returned in siglen. Note: sig must point to ECDSA_size(eckey) bytes of memory. The parameter type is ignored.

- -

ECDSA_do_sign_ex() is similar to ECDSA_sign_ex() except the signature is returned as a newly allocated ECDSA_SIG structure (or NULL on error).

- -

RETURN VALUES

- -

ECDSA_size() returns the maximum length signature or 0 on error.

- -

ECDSA_sign(), ECDSA_sign_ex() and ECDSA_sign_setup() return 1 if successful or 0 on error.

- -

ECDSA_do_sign() and ECDSA_do_sign_ex() return a pointer to an allocated ECDSA_SIG structure or NULL on error.

- -

ECDSA_verify() and ECDSA_do_verify() return 1 for a valid signature, 0 for an invalid signature and -1 on error. The error codes can be obtained by ERR_get_error(3).

- -

EXAMPLES

- -

Creating an ECDSA signature of a given SHA-256 hash value using the named curve prime256v1 (aka P-256). This example uses deprecated functionality. See "DESCRIPTION".

- -

First step: create an EC_KEY object (note: this part is not ECDSA specific)

- -
int ret;
-ECDSA_SIG *sig;
-EC_KEY *eckey;
-
-eckey = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1);
-if (eckey == NULL)
-    /* error */
-if (EC_KEY_generate_key(eckey) == 0)
-    /* error */
- -

Second step: compute the ECDSA signature of a SHA-256 hash value using ECDSA_do_sign():

- -
sig = ECDSA_do_sign(digest, 32, eckey);
-if (sig == NULL)
-    /* error */
- -

or using ECDSA_sign():

- -
unsigned char *buffer, *pp;
-int buf_len;
-
-buf_len = ECDSA_size(eckey);
-buffer = OPENSSL_malloc(buf_len);
-pp = buffer;
-if (ECDSA_sign(0, dgst, dgstlen, pp, &buf_len, eckey) == 0)
-    /* error */
- -

Third step: verify the created ECDSA signature using ECDSA_do_verify():

- -
ret = ECDSA_do_verify(digest, 32, sig, eckey);
- -

or using ECDSA_verify():

- -
ret = ECDSA_verify(0, digest, 32, buffer, buf_len, eckey);
- -

and finally evaluate the return value:

- -
if (ret == 1)
-    /* signature ok */
-else if (ret == 0)
-    /* incorrect signature */
-else
-    /* error */
- -

CONFORMING TO

- -

ANSI X9.62, US Federal Information Processing Standard FIPS186-2 (Digital Signature Standard, DSS)

- -

SEE ALSO

- -

EC_KEY_new(3), EVP_DigestSignInit(3), EVP_DigestVerifyInit(3), EVP_PKEY_sign(3) i2d_ECDSA_SIG(3), d2i_ECDSA_SIG(3)

- -

HISTORY

- -

All functionality described here was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2004-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ECPKParameters_print.html b/openssl-install/share/doc/openssl/html/man3/ECPKParameters_print.html deleted file mode 100644 index 81cbd599..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ECPKParameters_print.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -ECPKParameters_print - - - - - - - - - - -

NAME

- -

ECPKParameters_print, ECPKParameters_print_fp - Functions for decoding and encoding ASN1 representations of elliptic curve entities

- -

SYNOPSIS

- -
#include <openssl/ec.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int ECPKParameters_print(BIO *bp, const EC_GROUP *x, int off);
-int ECPKParameters_print_fp(FILE *fp, const EC_GROUP *x, int off);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_print_params(3)

- -

The ECPKParameters represent the public parameters for an EC_GROUP structure, which represents a curve.

- -

The ECPKParameters_print() and ECPKParameters_print_fp() functions print a human-readable output of the public parameters of the EC_GROUP to bp or fp. The output lines are indented by off spaces.

- -

RETURN VALUES

- -

ECPKParameters_print() and ECPKParameters_print_fp() return 1 for success and 0 if an error occurs.

- -

SEE ALSO

- -

crypto(7), EC_GROUP_new(3), EC_GROUP_copy(3), EC_POINT_new(3), EC_POINT_add(3), EC_KEY_new(3), EC_GFp_simple_method(3),

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2013-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EC_GFp_simple_method.html b/openssl-install/share/doc/openssl/html/man3/EC_GFp_simple_method.html deleted file mode 100644 index 7897cc2e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EC_GFp_simple_method.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -EC_GFp_simple_method - - - - - - - - - - -

NAME

- -

EC_GFp_simple_method, EC_GFp_mont_method, EC_GFp_nist_method, EC_GFp_nistp224_method, EC_GFp_nistp256_method, EC_GFp_nistp521_method, EC_GF2m_simple_method, EC_METHOD_get_field_type - Functions for obtaining EC_METHOD objects

- -

SYNOPSIS

- -
#include <openssl/ec.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
const EC_METHOD *EC_GFp_simple_method(void);
-const EC_METHOD *EC_GFp_mont_method(void);
-const EC_METHOD *EC_GFp_nist_method(void);
-const EC_METHOD *EC_GFp_nistp224_method(void);
-const EC_METHOD *EC_GFp_nistp256_method(void);
-const EC_METHOD *EC_GFp_nistp521_method(void);
-
-const EC_METHOD *EC_GF2m_simple_method(void);
-
-int EC_METHOD_get_field_type(const EC_METHOD *meth);
- -

DESCRIPTION

- -

All const EC_METHOD *EC_GF* functions were deprecated in OpenSSL 3.0, since EC_METHOD is no longer a public concept.

- -

The Elliptic Curve library provides a number of different implementations through a single common interface. When constructing a curve using EC_GROUP_new (see EC_GROUP_new(3)) an implementation method must be provided. The functions described here all return a const pointer to an EC_METHOD structure that can be passed to EC_GROUP_NEW. It is important that the correct implementation type for the form of curve selected is used.

- -

For F2^m curves there is only one implementation choice, i.e. EC_GF2_simple_method.

- -

For Fp curves the lowest common denominator implementation is the EC_GFp_simple_method implementation. All other implementations are based on this one. EC_GFp_mont_method builds on EC_GFp_simple_method but adds the use of montgomery multiplication (see BN_mod_mul_montgomery(3)). EC_GFp_nist_method offers an implementation optimised for use with NIST recommended curves (NIST curves are available through EC_GROUP_new_by_curve_name as described in EC_GROUP_new(3)).

- -

The functions EC_GFp_nistp224_method, EC_GFp_nistp256_method and EC_GFp_nistp521_method offer 64 bit optimised implementations for the NIST P224, P256 and P521 curves respectively. Note, however, that these implementations are not available on all platforms.

- -

EC_METHOD_get_field_type() was deprecated in OpenSSL 3.0. Applications should use EC_GROUP_get_field_type() as a replacement (see EC_GROUP_copy(3)).

- -

RETURN VALUES

- -

All EC_GFp* functions and EC_GF2m_simple_method always return a const pointer to an EC_METHOD structure.

- -

EC_METHOD_get_field_type returns an integer that identifies the type of field the EC_METHOD structure supports.

- -

SEE ALSO

- -

crypto(7), EC_GROUP_new(3), EC_GROUP_copy(3), EC_POINT_new(3), EC_POINT_add(3), EC_KEY_new(3), d2i_ECPKParameters(3), BN_mod_mul_montgomery(3)

- -

HISTORY

- -

EC_GFp_simple_method(), EC_GFp_mont_method(void), EC_GFp_nist_method(), EC_GFp_nistp224_method(), EC_GFp_nistp256_method(), EC_GFp_nistp521_method(), EC_GF2m_simple_method(), and EC_METHOD_get_field_type() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2013-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EC_GROUP_copy.html b/openssl-install/share/doc/openssl/html/man3/EC_GROUP_copy.html deleted file mode 100644 index e4aff7bf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EC_GROUP_copy.html +++ /dev/null @@ -1,200 +0,0 @@ - - - - -EC_GROUP_copy - - - - - - - - - - -

NAME

- -

EC_GROUP_get0_order, EC_GROUP_order_bits, EC_GROUP_get0_cofactor, EC_GROUP_copy, EC_GROUP_dup, EC_GROUP_method_of, EC_GROUP_set_generator, EC_GROUP_get0_generator, EC_GROUP_get_order, EC_GROUP_get_cofactor, EC_GROUP_set_curve_name, EC_GROUP_get_curve_name, EC_GROUP_set_asn1_flag, EC_GROUP_get_asn1_flag, EC_GROUP_set_point_conversion_form, EC_GROUP_get_point_conversion_form, EC_GROUP_get0_seed, EC_GROUP_get_seed_len, EC_GROUP_set_seed, EC_GROUP_get_degree, EC_GROUP_check, EC_GROUP_check_named_curve, EC_GROUP_check_discriminant, EC_GROUP_cmp, EC_GROUP_get_basis_type, EC_GROUP_get_trinomial_basis, EC_GROUP_get_pentanomial_basis, EC_GROUP_get0_field, EC_GROUP_get_field_type - Functions for manipulating EC_GROUP objects

- -

SYNOPSIS

- -
#include <openssl/ec.h>
-
-int EC_GROUP_copy(EC_GROUP *dst, const EC_GROUP *src);
-EC_GROUP *EC_GROUP_dup(const EC_GROUP *src);
-
-int EC_GROUP_set_generator(EC_GROUP *group, const EC_POINT *generator,
-                           const BIGNUM *order, const BIGNUM *cofactor);
-const EC_POINT *EC_GROUP_get0_generator(const EC_GROUP *group);
-
-int EC_GROUP_get_order(const EC_GROUP *group, BIGNUM *order, BN_CTX *ctx);
-const BIGNUM *EC_GROUP_get0_order(const EC_GROUP *group);
-int EC_GROUP_order_bits(const EC_GROUP *group);
-int EC_GROUP_get_cofactor(const EC_GROUP *group, BIGNUM *cofactor, BN_CTX *ctx);
-const BIGNUM *EC_GROUP_get0_cofactor(const EC_GROUP *group);
-const BIGNUM *EC_GROUP_get0_field(const EC_GROUP *group);
-
-void EC_GROUP_set_curve_name(EC_GROUP *group, int nid);
-int EC_GROUP_get_curve_name(const EC_GROUP *group);
-
-void EC_GROUP_set_asn1_flag(EC_GROUP *group, int flag);
-int EC_GROUP_get_asn1_flag(const EC_GROUP *group);
-
-void EC_GROUP_set_point_conversion_form(EC_GROUP *group, point_conversion_form_t form);
-point_conversion_form_t EC_GROUP_get_point_conversion_form(const EC_GROUP *group);
-
-unsigned char *EC_GROUP_get0_seed(const EC_GROUP *group);
-size_t EC_GROUP_get_seed_len(const EC_GROUP *group);
-size_t EC_GROUP_set_seed(EC_GROUP *group, const unsigned char *, size_t len);
-
-int EC_GROUP_get_degree(const EC_GROUP *group);
-
-int EC_GROUP_check(const EC_GROUP *group, BN_CTX *ctx);
-int EC_GROUP_check_named_curve(const EC_GROUP *group, int nist_only,
-                               BN_CTX *ctx);
-
-int EC_GROUP_check_discriminant(const EC_GROUP *group, BN_CTX *ctx);
-
-int EC_GROUP_cmp(const EC_GROUP *a, const EC_GROUP *b, BN_CTX *ctx);
-
-int EC_GROUP_get_basis_type(const EC_GROUP *group);
-int EC_GROUP_get_trinomial_basis(const EC_GROUP *group, unsigned int *k);
-int EC_GROUP_get_pentanomial_basis(const EC_GROUP *group, unsigned int *k1,
-                                   unsigned int *k2, unsigned int *k3);
-
-int EC_GROUP_get_field_type(const EC_GROUP *group);
- -

The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
const EC_METHOD *EC_GROUP_method_of(const EC_GROUP *group);
- -

DESCRIPTION

- -

EC_GROUP_copy() copies the curve src into dst. Both src and dst must use the same EC_METHOD.

- -

EC_GROUP_dup() creates a new EC_GROUP object and copies the content from src to the newly created EC_GROUP object.

- -

EC_GROUP_method_of() obtains the EC_METHOD of group. This function was deprecated in OpenSSL 3.0, since EC_METHOD is no longer a public concept.

- -

EC_GROUP_set_generator() sets curve parameters that must be agreed by all participants using the curve. These parameters include the generator, the order and the cofactor. The generator is a well defined point on the curve chosen for cryptographic operations. Integers used for point multiplications will be between 0 and n-1 where n is the order. The order multiplied by the cofactor gives the number of points on the curve.

- -

EC_GROUP_get0_generator() returns the generator for the identified group.

- -

EC_GROUP_get_order() retrieves the order of group and copies its value into order. It fails in case group is not fully initialized (i.e., its order is not set or set to zero).

- -

EC_GROUP_get_cofactor() retrieves the cofactor of group and copies its value into cofactor. It fails in case group is not fully initialized or if the cofactor is not set (or set to zero).

- -

The functions EC_GROUP_set_curve_name() and EC_GROUP_get_curve_name(), set and get the NID for the curve respectively (see EC_GROUP_new(3)). If a curve does not have a NID associated with it, then EC_GROUP_get_curve_name will return NID_undef.

- -

The asn1_flag value is used to determine whether the curve encoding uses explicit parameters or a named curve using an ASN1 OID: many applications only support the latter form. If asn1_flag is OPENSSL_EC_NAMED_CURVE then the named curve form is used and the parameters must have a corresponding named curve NID set. If asn1_flags is OPENSSL_EC_EXPLICIT_CURVE the parameters are explicitly encoded. The functions EC_GROUP_get_asn1_flag() and EC_GROUP_set_asn1_flag() get and set the status of the asn1_flag for the curve. Note: OPENSSL_EC_EXPLICIT_CURVE was added in OpenSSL 1.1.0, for previous versions of OpenSSL the value 0 must be used instead. Before OpenSSL 1.1.0 the default form was to use explicit parameters (meaning that applications would have to explicitly set the named curve form) in OpenSSL 1.1.0 and later the named curve form is the default.

- -

The point_conversion_form for a curve controls how EC_POINT data is encoded as ASN1 as defined in X9.62 (ECDSA). point_conversion_form_t is an enum defined as follows:

- -
typedef enum {
-       /** the point is encoded as z||x, where the octet z specifies
-        *   which solution of the quadratic equation y is  */
-       POINT_CONVERSION_COMPRESSED = 2,
-       /** the point is encoded as z||x||y, where z is the octet 0x04  */
-       POINT_CONVERSION_UNCOMPRESSED = 4,
-       /** the point is encoded as z||x||y, where the octet z specifies
-        *  which solution of the quadratic equation y is  */
-       POINT_CONVERSION_HYBRID = 6
-} point_conversion_form_t;
- -

For POINT_CONVERSION_UNCOMPRESSED the point is encoded as an octet signifying the UNCOMPRESSED form has been used followed by the octets for x, followed by the octets for y.

- -

For any given x coordinate for a point on a curve it is possible to derive two possible y values. For POINT_CONVERSION_COMPRESSED the point is encoded as an octet signifying that the COMPRESSED form has been used AND which of the two possible solutions for y has been used, followed by the octets for x.

- -

For POINT_CONVERSION_HYBRID the point is encoded as an octet signifying the HYBRID form has been used AND which of the two possible solutions for y has been used, followed by the octets for x, followed by the octets for y.

- -

The functions EC_GROUP_set_point_conversion_form() and EC_GROUP_get_point_conversion_form(), set and get the point_conversion_form for the curve respectively.

- -

ANSI X9.62 (ECDSA standard) defines a method of generating the curve parameter b from a random number. This provides advantages in that a parameter obtained in this way is highly unlikely to be susceptible to special purpose attacks, or have any trapdoors in it. If the seed is present for a curve then the b parameter was generated in a verifiable fashion using that seed. The OpenSSL EC library does not use this seed value but does enable you to inspect it using EC_GROUP_get0_seed(). This returns a pointer to a memory block containing the seed that was used. The length of the memory block can be obtained using EC_GROUP_get_seed_len(). A number of the built-in curves within the library provide seed values that can be obtained. It is also possible to set a custom seed using EC_GROUP_set_seed() and passing a pointer to a memory block, along with the length of the seed. Again, the EC library will not use this seed value, although it will be preserved in any ASN1 based communications.

- -

EC_GROUP_get_degree() gets the degree of the field. For Fp fields this will be the number of bits in p. For F2^m fields this will be the value m.

- -

EC_GROUP_get_field_type() identifies what type of field the EC_GROUP structure supports, which will be either F2^m or Fp.

- -

The function EC_GROUP_check_discriminant() calculates the discriminant for the curve and verifies that it is valid. For a curve defined over Fp the discriminant is given by the formula 4*a^3 + 27*b^2 whilst for F2^m curves the discriminant is simply b. In either case for the curve to be valid the discriminant must be non zero.

- -

The function EC_GROUP_check() behaves in the following way: For the OpenSSL default provider it performs a number of checks on a curve to verify that it is valid. Checks performed include verifying that the discriminant is non zero; that a generator has been defined; that the generator is on the curve and has the correct order. For the OpenSSL FIPS provider it uses EC_GROUP_check_named_curve() to conform to SP800-56Ar3.

- -

The function EC_GROUP_check_named_curve() determines if the group's domain parameters match one of the built-in curves supported by the library. The curve name is returned as a NID if it matches. If the group's domain parameters have been modified then no match will be found. If the curve name of the given group is NID_undef (e.g. it has been created by using explicit parameters with no curve name), then this method can be used to lookup the name of the curve that matches the group domain parameters. The built-in curves contain aliases, so that multiple NID's can map to the same domain parameters. For such curves it is unspecified which of the aliases will be returned if the curve name of the given group is NID_undef. If nist_only is 1 it will only look for NIST approved curves, otherwise it searches all built-in curves. This function may be passed a BN_CTX object in the ctx parameter. The ctx parameter may be NULL.

- -

EC_GROUP_cmp() compares a and b to determine whether they represent the same curve or not.

- -

The functions EC_GROUP_get_basis_type(), EC_GROUP_get_trinomial_basis() and EC_GROUP_get_pentanomial_basis() should only be called for curves defined over an F2^m field. Addition and multiplication operations within an F2^m field are performed using an irreducible polynomial function f(x). This function is either a trinomial of the form:

- -

f(x) = x^m + x^k + 1 with m > k >= 1

- -

or a pentanomial of the form:

- -

f(x) = x^m + x^k3 + x^k2 + x^k1 + 1 with m > k3 > k2 > k1 >= 1

- -

The function EC_GROUP_get_basis_type() returns a NID identifying whether a trinomial or pentanomial is in use for the field. The function EC_GROUP_get_trinomial_basis() must only be called where f(x) is of the trinomial form, and returns the value of k. Similarly the function EC_GROUP_get_pentanomial_basis() must only be called where f(x) is of the pentanomial form, and returns the values of k1, k2 and k3 respectively.

- -

RETURN VALUES

- -

The following functions return 1 on success or 0 on error: EC_GROUP_copy(), EC_GROUP_set_generator(), EC_GROUP_check(), EC_GROUP_check_discriminant(), EC_GROUP_get_trinomial_basis() and EC_GROUP_get_pentanomial_basis().

- -

EC_GROUP_dup() returns a pointer to the duplicated curve, or NULL on error.

- -

EC_GROUP_method_of() returns the EC_METHOD implementation in use for the given curve or NULL on error.

- -

EC_GROUP_get0_generator() returns the generator for the given curve or NULL on error.

- -

EC_GROUP_get_order() returns 0 if the order is not set (or set to zero) for group or if copying into order fails, 1 otherwise.

- -

EC_GROUP_get_cofactor() returns 0 if the cofactor is not set (or is set to zero) for group or if copying into cofactor fails, 1 otherwise.

- -

EC_GROUP_get_curve_name() returns the curve name (NID) for group or will return NID_undef if no curve name is associated.

- -

EC_GROUP_get_asn1_flag() returns the ASN1 flag for the specified group .

- -

EC_GROUP_get_point_conversion_form() returns the point_conversion_form for group.

- -

EC_GROUP_get_degree() returns the degree for group or 0 if the operation is not supported by the underlying group implementation.

- -

EC_GROUP_get_field_type() returns either NID_X9_62_prime_field for prime curves or NID_X9_62_characteristic_two_field for binary curves; these values are defined in the <openssl/obj_mac.h> header file.

- -

EC_GROUP_check_named_curve() returns the nid of the matching named curve, otherwise it returns 0 for no match, or -1 on error.

- -

EC_GROUP_get0_order() returns an internal pointer to the group order. EC_GROUP_order_bits() returns the number of bits in the group order. EC_GROUP_get0_cofactor() returns an internal pointer to the group cofactor. EC_GROUP_get0_field() returns an internal pointer to the group field. For curves over GF(p), this is the modulus; for curves over GF(2^m), this is the irreducible polynomial defining the field.

- -

EC_GROUP_get0_seed() returns a pointer to the seed that was used to generate the parameter b, or NULL if the seed is not specified. EC_GROUP_get_seed_len() returns the length of the seed or 0 if the seed is not specified.

- -

EC_GROUP_set_seed() returns the length of the seed that has been set. If the supplied seed is NULL, or the supplied seed length is 0, the return value will be 1. On error 0 is returned.

- -

EC_GROUP_cmp() returns 0 if the curves are equal, 1 if they are not equal, or -1 on error.

- -

EC_GROUP_get_basis_type() returns the values NID_X9_62_tpBasis or NID_X9_62_ppBasis (as defined in <openssl/obj_mac.h>) for a trinomial or pentanomial respectively. Alternatively in the event of an error a 0 is returned.

- -

SEE ALSO

- -

crypto(7), EC_GROUP_new(3), EC_POINT_new(3), EC_POINT_add(3), EC_KEY_new(3), EC_GFp_simple_method(3), d2i_ECPKParameters(3)

- -

HISTORY

- -

EC_GROUP_method_of() was deprecated in OpenSSL 3.0. EC_GROUP_get0_field(), EC_GROUP_check_named_curve() and EC_GROUP_get_field_type() were added in OpenSSL 3.0. EC_GROUP_get0_order(), EC_GROUP_order_bits() and EC_GROUP_get0_cofactor() were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2013-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EC_GROUP_new.html b/openssl-install/share/doc/openssl/html/man3/EC_GROUP_new.html deleted file mode 100644 index 91c95961..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EC_GROUP_new.html +++ /dev/null @@ -1,170 +0,0 @@ - - - - -EC_GROUP_new - - - - - - - - - - -

NAME

- -

EC_GROUP_get_ecparameters, EC_GROUP_get_ecpkparameters, EC_GROUP_new_from_params, EC_GROUP_to_params, EC_GROUP_new_from_ecparameters, EC_GROUP_new_from_ecpkparameters, EC_GROUP_new, EC_GROUP_free, EC_GROUP_clear_free, EC_GROUP_new_curve_GFp, EC_GROUP_new_curve_GF2m, EC_GROUP_new_by_curve_name_ex, EC_GROUP_new_by_curve_name, EC_GROUP_set_curve, EC_GROUP_get_curve, EC_GROUP_set_curve_GFp, EC_GROUP_get_curve_GFp, EC_GROUP_set_curve_GF2m, EC_GROUP_get_curve_GF2m, EC_get_builtin_curves, OSSL_EC_curve_nid2name - Functions for creating and destroying EC_GROUP objects

- -

SYNOPSIS

- -
#include <openssl/ec.h>
-
-EC_GROUP *EC_GROUP_new_from_params(const OSSL_PARAM params[],
-                                   OSSL_LIB_CTX *libctx, const char *propq);
-OSSL_PARAM *EC_GROUP_to_params(const EC_GROUP *group, OSSL_LIB_CTX *libctx,
-                               const char *propq, BN_CTX *bnctx);
-EC_GROUP *EC_GROUP_new_from_ecparameters(const ECPARAMETERS *params);
-EC_GROUP *EC_GROUP_new_from_ecpkparameters(const ECPKPARAMETERS *params);
-void EC_GROUP_free(EC_GROUP *group);
-
-EC_GROUP *EC_GROUP_new_curve_GFp(const BIGNUM *p, const BIGNUM *a,
-                                 const BIGNUM *b, BN_CTX *ctx);
-EC_GROUP *EC_GROUP_new_curve_GF2m(const BIGNUM *p, const BIGNUM *a,
-                                  const BIGNUM *b, BN_CTX *ctx);
-EC_GROUP *EC_GROUP_new_by_curve_name_ex(OSSL_LIB_CTX *libctx, const char *propq,
-                                        int nid);
-EC_GROUP *EC_GROUP_new_by_curve_name(int nid);
-
-int EC_GROUP_set_curve(EC_GROUP *group, const BIGNUM *p, const BIGNUM *a,
-                       const BIGNUM *b, BN_CTX *ctx);
-int EC_GROUP_get_curve(const EC_GROUP *group, BIGNUM *p, BIGNUM *a, BIGNUM *b,
-                       BN_CTX *ctx);
-
-ECPARAMETERS *EC_GROUP_get_ecparameters(const EC_GROUP *group,
-                                        ECPARAMETERS *params);
-ECPKPARAMETERS *EC_GROUP_get_ecpkparameters(const EC_GROUP *group,
-                                            ECPKPARAMETERS *params);
-
-size_t EC_get_builtin_curves(EC_builtin_curve *r, size_t nitems);
-const char *OSSL_EC_curve_nid2name(int nid);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
EC_GROUP *EC_GROUP_new(const EC_METHOD *meth);
-void EC_GROUP_clear_free(EC_GROUP *group);
-
-int EC_GROUP_set_curve_GFp(EC_GROUP *group, const BIGNUM *p,
-                           const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx);
-int EC_GROUP_get_curve_GFp(const EC_GROUP *group, BIGNUM *p,
-                           BIGNUM *a, BIGNUM *b, BN_CTX *ctx);
-int EC_GROUP_set_curve_GF2m(EC_GROUP *group, const BIGNUM *p,
-                            const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx);
-int EC_GROUP_get_curve_GF2m(const EC_GROUP *group, BIGNUM *p,
-                            BIGNUM *a, BIGNUM *b, BN_CTX *ctx);
- -

DESCRIPTION

- -

Within the library there are two forms of elliptic curve that are of interest. The first form is those defined over the prime field Fp. The elements of Fp are the integers 0 to p-1, where p is a prime number. This gives us a revised elliptic curve equation as follows:

- -

y^2 mod p = x^3 +ax + b mod p

- -

The second form is those defined over a binary field F2^m where the elements of the field are integers of length at most m bits. For this form the elliptic curve equation is modified to:

- -

y^2 + xy = x^3 + ax^2 + b (where b != 0)

- -

Operations in a binary field are performed relative to an irreducible polynomial. All such curves with OpenSSL use a trinomial or a pentanomial for this parameter.

- -

Although deprecated since OpenSSL 3.0 and should no longer be used, a new curve can be constructed by calling EC_GROUP_new(), using the implementation provided by meth (see EC_GFp_simple_method(3)) and associated with the library context ctx (see OSSL_LIB_CTX(3)). The ctx parameter may be NULL in which case the default library context is used. It is then necessary to call EC_GROUP_set_curve() to set the curve parameters. Applications should instead use one of the other EC_GROUP_new_* constructors.

- -

EC_GROUP_new_from_params() creates a group with parameters specified by params. The library context libctx (see OSSL_LIB_CTX(3)) and property query string propq are used to fetch algorithms from providers. params may be either a list of explicit params or a named group, The values for ctx and propq may be NULL. The params that can be used are described in EVP_PKEY-EC(7).

- -

EC_GROUP_to_params creates an OSSL_PARAM array with the corresponding parameters describing the given EC_GROUP. The resulting parameters may contain parameters describing a named or explicit curve depending on the EC_GROUP. The library context libctx (see OSSL_LIB_CTX(3)) and property query string propq are used to fetch algorithms from providers. bnctx is an optional preallocated BN_CTX (to save the overhead of allocating and freeing the structure in a loop). The values for libctx, propq and bnctx may be NULL. The caller is responsible for freeing the OSSL_PARAM pointer returned.

- -

EC_GROUP_new_from_ecparameters() will create a group from the specified params and EC_GROUP_new_from_ecpkparameters() will create a group from the specific PK params.

- -

EC_GROUP_set_curve() sets the curve parameters p, a and b. For a curve over Fp p is the prime for the field. For a curve over F2^m p represents the irreducible polynomial - each bit represents a term in the polynomial. Therefore, there will either be three or five bits set dependent on whether the polynomial is a trinomial or a pentanomial. In either case, a and b represents the coefficients a and b from the relevant equation introduced above.

- -

EC_group_get_curve() obtains the previously set curve parameters.

- -

EC_GROUP_set_curve_GFp() and EC_GROUP_set_curve_GF2m() are synonyms for EC_GROUP_set_curve(). They are defined for backwards compatibility only and should not be used.

- -

EC_GROUP_get_curve_GFp() and EC_GROUP_get_curve_GF2m() are synonyms for EC_GROUP_get_curve(). They are defined for backwards compatibility only and should not be used.

- -

The functions EC_GROUP_new_curve_GFp() and EC_GROUP_new_curve_GF2m() are shortcuts for calling EC_GROUP_new() and then the EC_GROUP_set_curve() function. An appropriate default implementation method will be used.

- -

Whilst the library can be used to create any curve using the functions described above, there are also a number of predefined curves that are available. In order to obtain a list of all of the predefined curves, call the function EC_get_builtin_curves(). The parameter r should be an array of EC_builtin_curve structures of size nitems. The function will populate the r array with information about the built-in curves. If nitems is less than the total number of curves available, then the first nitems curves will be returned. Otherwise the total number of curves will be provided. The return value is the total number of curves available (whether that number has been populated in r or not). Passing a NULL r, or setting nitems to 0 will do nothing other than return the total number of curves available. The EC_builtin_curve structure is defined as follows:

- -
typedef struct {
-       int nid;
-       const char *comment;
-       } EC_builtin_curve;
- -

Each EC_builtin_curve item has a unique integer id (nid), and a human readable comment string describing the curve.

- -

In order to construct a built-in curve use the function EC_GROUP_new_by_curve_name_ex() and provide the nid of the curve to be constructed, the associated library context to be used in ctx (see OSSL_LIB_CTX(3)) and any property query string in propq. The ctx value may be NULL in which case the default library context is used. The propq value may also be NULL.

- -

EC_GROUP_new_by_curve_name() is the same as EC_GROUP_new_by_curve_name_ex() except that the default library context is always used along with a NULL property query string.

- -

EC_GROUP_free() frees the memory associated with the EC_GROUP. If group is NULL nothing is done.

- -

EC_GROUP_clear_free() is deprecated: it was meant to destroy any sensitive data held within the EC_GROUP and then free its memory, but since all the data stored in the EC_GROUP is public anyway, this function is unnecessary. Its use can be safely replaced with EC_GROUP_free(). If group is NULL nothing is done.

- -

OSSL_EC_curve_nid2name() converts a curve nid into the corresponding name.

- -

RETURN VALUES

- -

All EC_GROUP_new* functions return a pointer to the newly constructed group, or NULL on error.

- -

EC_get_builtin_curves() returns the number of built-in curves that are available.

- -

EC_GROUP_set_curve_GFp(), EC_GROUP_get_curve_GFp(), EC_GROUP_set_curve_GF2m(), EC_GROUP_get_curve_GF2m() return 1 on success or 0 on error.

- -

OSSL_EC_curve_nid2name() returns a character string constant, or NULL on error.

- -

SEE ALSO

- -

crypto(7), EC_GROUP_copy(3), EC_POINT_new(3), EC_POINT_add(3), EC_KEY_new(3), EC_GFp_simple_method(3), d2i_ECPKParameters(3), OSSL_LIB_CTX(3), EVP_PKEY-EC(7)

- -

HISTORY

- - - -

COPYRIGHT

- -

Copyright 2013-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EC_KEY_get_enc_flags.html b/openssl-install/share/doc/openssl/html/man3/EC_KEY_get_enc_flags.html deleted file mode 100644 index e4f78ca6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EC_KEY_get_enc_flags.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -EC_KEY_get_enc_flags - - - - - - - - - - -

NAME

- -

EC_KEY_get_enc_flags, EC_KEY_set_enc_flags - Get and set flags for encoding EC_KEY structures

- -

SYNOPSIS

- -
#include <openssl/ec.h>
-
-unsigned int EC_KEY_get_enc_flags(const EC_KEY *key);
-void EC_KEY_set_enc_flags(EC_KEY *eckey, unsigned int flags);
- -

DESCRIPTION

- -

The format of the external representation of the public key written by i2d_ECPrivateKey() (such as whether it is stored in a compressed form or not) is described by the point_conversion_form. See EC_GROUP_copy(3) for a description of point_conversion_form.

- -

When reading a private key encoded without an associated public key (e.g. if EC_PKEY_NO_PUBKEY has been used - see below), then d2i_ECPrivateKey() generates the missing public key automatically. Private keys encoded without parameters (e.g. if EC_PKEY_NO_PARAMETERS has been used - see below) cannot be loaded using d2i_ECPrivateKey().

- -

The functions EC_KEY_get_enc_flags() and EC_KEY_set_enc_flags() get and set the value of the encoding flags for the key. There are two encoding flags currently defined - EC_PKEY_NO_PARAMETERS and EC_PKEY_NO_PUBKEY. These flags define the behaviour of how the key is converted into ASN1 in a call to i2d_ECPrivateKey(). If EC_PKEY_NO_PARAMETERS is set then the public parameters for the curve are not encoded along with the private key. If EC_PKEY_NO_PUBKEY is set then the public key is not encoded along with the private key.

- -

RETURN VALUES

- -

EC_KEY_get_enc_flags() returns the value of the current encoding flags for the EC_KEY.

- -

SEE ALSO

- -

crypto(7), EC_GROUP_new(3), EC_GROUP_copy(3), EC_POINT_new(3), EC_POINT_add(3), EC_GFp_simple_method(3), d2i_ECPKParameters(3), d2i_ECPrivateKey(3)

- -

COPYRIGHT

- -

Copyright 2015-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EC_KEY_new.html b/openssl-install/share/doc/openssl/html/man3/EC_KEY_new.html deleted file mode 100644 index 2cdd9c2d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EC_KEY_new.html +++ /dev/null @@ -1,168 +0,0 @@ - - - - -EC_KEY_new - - - - - - - - - - -

NAME

- -

EVP_EC_gen, EC_KEY_get_method, EC_KEY_set_method, EC_KEY_new_ex, EC_KEY_new, EC_KEY_get_flags, EC_KEY_set_flags, EC_KEY_clear_flags, EC_KEY_new_by_curve_name_ex, EC_KEY_new_by_curve_name, EC_KEY_free, EC_KEY_copy, EC_KEY_dup, EC_KEY_up_ref, EC_KEY_get0_engine, EC_KEY_get0_group, EC_KEY_set_group, EC_KEY_get0_private_key, EC_KEY_set_private_key, EC_KEY_get0_public_key, EC_KEY_set_public_key, EC_KEY_get_conv_form, EC_KEY_set_conv_form, EC_KEY_set_asn1_flag, EC_KEY_decoded_from_explicit_params, EC_KEY_precompute_mult, EC_KEY_generate_key, EC_KEY_check_key, EC_KEY_set_public_key_affine_coordinates, EC_KEY_oct2key, EC_KEY_key2buf, EC_KEY_oct2priv, EC_KEY_priv2oct, EC_KEY_priv2buf - Functions for creating, destroying and manipulating EC_KEY objects

- -

SYNOPSIS

- -
#include <openssl/ec.h>
-
-EVP_PKEY *EVP_EC_gen(const char *curve);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
EC_KEY *EC_KEY_new_ex(OSSL_LIB_CTX *ctx, const char *propq);
-EC_KEY *EC_KEY_new(void);
-int EC_KEY_get_flags(const EC_KEY *key);
-void EC_KEY_set_flags(EC_KEY *key, int flags);
-void EC_KEY_clear_flags(EC_KEY *key, int flags);
-EC_KEY *EC_KEY_new_by_curve_name_ex(OSSL_LIB_CTX *ctx, const char *propq,
-                                    int nid);
-EC_KEY *EC_KEY_new_by_curve_name(int nid);
-void EC_KEY_free(EC_KEY *key);
-EC_KEY *EC_KEY_copy(EC_KEY *dst, const EC_KEY *src);
-EC_KEY *EC_KEY_dup(const EC_KEY *src);
-int EC_KEY_up_ref(EC_KEY *key);
-ENGINE *EC_KEY_get0_engine(const EC_KEY *eckey);
-const EC_GROUP *EC_KEY_get0_group(const EC_KEY *key);
-int EC_KEY_set_group(EC_KEY *key, const EC_GROUP *group);
-const BIGNUM *EC_KEY_get0_private_key(const EC_KEY *key);
-int EC_KEY_set_private_key(EC_KEY *key, const BIGNUM *priv_key);
-const EC_POINT *EC_KEY_get0_public_key(const EC_KEY *key);
-int EC_KEY_set_public_key(EC_KEY *key, const EC_POINT *pub);
-point_conversion_form_t EC_KEY_get_conv_form(const EC_KEY *key);
-void EC_KEY_set_conv_form(EC_KEY *eckey, point_conversion_form_t cform);
-void EC_KEY_set_asn1_flag(EC_KEY *eckey, int asn1_flag);
-int EC_KEY_decoded_from_explicit_params(const EC_KEY *key);
-int EC_KEY_generate_key(EC_KEY *key);
-int EC_KEY_check_key(const EC_KEY *key);
-int EC_KEY_set_public_key_affine_coordinates(EC_KEY *key, BIGNUM *x, BIGNUM *y);
-const EC_KEY_METHOD *EC_KEY_get_method(const EC_KEY *key);
-int EC_KEY_set_method(EC_KEY *key, const EC_KEY_METHOD *meth);
-
-int EC_KEY_oct2key(EC_KEY *eckey, const unsigned char *buf, size_t len, BN_CTX *ctx);
-size_t EC_KEY_key2buf(const EC_KEY *eckey, point_conversion_form_t form,
-                      unsigned char **pbuf, BN_CTX *ctx);
-
-int EC_KEY_oct2priv(EC_KEY *eckey, const unsigned char *buf, size_t len);
-size_t EC_KEY_priv2oct(const EC_KEY *eckey, unsigned char *buf, size_t len);
-
-size_t EC_KEY_priv2buf(const EC_KEY *eckey, unsigned char **pbuf);
-int EC_KEY_precompute_mult(EC_KEY *key, BN_CTX *ctx);
- -

DESCRIPTION

- -

EVP_EC_gen() generates a new EC key pair on the given curve.

- -

All of the functions described below are deprecated. Applications should instead use EVP_EC_gen(), EVP_PKEY_Q_keygen(3), or EVP_PKEY_keygen_init(3) and EVP_PKEY_keygen(3).

- -

An EC_KEY represents a public key and, optionally, the associated private key. A new EC_KEY with no associated curve can be constructed by calling EC_KEY_new_ex() and specifying the associated library context in ctx (see OSSL_LIB_CTX(3)) and property query string propq. The ctx parameter may be NULL in which case the default library context is used. The reference count for the newly created EC_KEY is initially set to 1. A curve can be associated with the EC_KEY by calling EC_KEY_set_group().

- -

EC_KEY_new() is the same as EC_KEY_new_ex() except that the default library context is always used.

- -

Alternatively a new EC_KEY can be constructed by calling EC_KEY_new_by_curve_name_ex() and supplying the nid of the associated curve, the library context to be used ctx (see OSSL_LIB_CTX(3)) and any property query string propq. The ctx parameter may be NULL in which case the default library context is used. The propq value may also be NULL. See EC_GROUP_new(3) for a description of curve names. This function simply wraps calls to EC_KEY_new_ex() and EC_GROUP_new_by_curve_name_ex().

- -

EC_KEY_new_by_curve_name() is the same as EC_KEY_new_by_curve_name_ex() except that the default library context is always used and a NULL property query string.

- -

Calling EC_KEY_free() decrements the reference count for the EC_KEY object, and if it has dropped to zero then frees the memory associated with it. If key is NULL nothing is done.

- -

EC_KEY_copy() copies the contents of the EC_KEY in src into dest.

- -

EC_KEY_dup() creates a new EC_KEY object and copies ec_key into it.

- -

EC_KEY_up_ref() increments the reference count associated with the EC_KEY object.

- -

EC_KEY_get0_engine() returns a handle to the ENGINE that has been set for this EC_KEY object.

- -

EC_KEY_generate_key() generates a new public and private key for the supplied eckey object. eckey must have an EC_GROUP object associated with it before calling this function. The private key is a random integer (0 < priv_key < order, where order is the order of the EC_GROUP object). The public key is an EC_POINT on the curve calculated by multiplying the generator for the curve by the private key.

- -

EC_KEY_check_key() performs various sanity checks on the EC_KEY object to confirm that it is valid.

- -

EC_KEY_set_public_key_affine_coordinates() sets the public key for key based on its affine coordinates; i.e., it constructs an EC_POINT object based on the supplied x and y values and sets the public key to be this EC_POINT. It also performs certain sanity checks on the key to confirm that it is valid.

- -

The functions EC_KEY_get0_group(), EC_KEY_set_group(), EC_KEY_get0_private_key(), EC_KEY_set_private_key(), EC_KEY_get0_public_key(), and EC_KEY_set_public_key() get and set the EC_GROUP object, the private key, and the EC_POINT public key for the key respectively. The function EC_KEY_set_private_key() accepts NULL as the priv_key argument to securely clear the private key component from the EC_KEY.

- -

The functions EC_KEY_get_conv_form() and EC_KEY_set_conv_form() get and set the point_conversion_form for the key. For a description of point_conversion_forms please see EC_POINT_new(3).

- -

EC_KEY_set_flags() sets the flags in the flags parameter on the EC_KEY object. Any flags that are already set are left set. The flags currently defined are EC_FLAG_NON_FIPS_ALLOW and EC_FLAG_FIPS_CHECKED. In addition there is the flag EC_FLAG_COFACTOR_ECDH which is specific to ECDH. EC_KEY_get_flags() returns the current flags that are set for this EC_KEY. EC_KEY_clear_flags() clears the flags indicated by the flags parameter; all other flags are left in their existing state.

- -

EC_KEY_set_asn1_flag() sets the asn1_flag on the underlying EC_GROUP object (if set). Refer to EC_GROUP_copy(3) for further information on the asn1_flag.

- -

EC_KEY_decoded_from_explicit_params() returns 1 if the group of the key was decoded from data with explicitly encoded group parameters, -1 if the key is NULL or the group parameters are missing, and 0 otherwise.

- -

EC_KEY_precompute_mult() stores multiples of the underlying EC_GROUP generator for faster point multiplication. See also EC_POINT_add(3). Modern versions should instead switch to named curves which OpenSSL has hardcoded lookup tables for.

- -

EC_KEY_oct2key() and EC_KEY_key2buf() are identical to the functions EC_POINT_oct2point() and EC_POINT_point2buf() except they use the public key EC_POINT in eckey.

- -

EC_KEY_oct2priv() and EC_KEY_priv2oct() convert between the private key component of eckey and octet form. The octet form consists of the content octets of the privateKey OCTET STRING in an ECPrivateKey ASN.1 structure.

- -

The function EC_KEY_priv2oct() must be supplied with a buffer long enough to store the octet form. The return value provides the number of octets stored. Calling the function with a NULL buffer will not perform the conversion but will just return the required buffer length.

- -

The function EC_KEY_priv2buf() allocates a buffer of suitable length and writes an EC_KEY to it in octet format. The allocated buffer is written to *pbuf and its length is returned. The caller must free up the allocated buffer with a call to OPENSSL_free(). Since the allocated buffer value is written to *pbuf the pbuf parameter MUST NOT be NULL.

- -

EC_KEY_priv2buf() converts an EC_KEY private key into an allocated buffer.

- -

RETURN VALUES

- -

EC_KEY_new_ex(), EC_KEY_new(), EC_KEY_new_by_curve_name_ex(), EC_KEY_new_by_curve_name() and EC_KEY_dup() return a pointer to the newly created EC_KEY object, or NULL on error.

- -

EC_KEY_get_flags() returns the flags associated with the EC_KEY object as an integer.

- -

EC_KEY_copy() returns a pointer to the destination key, or NULL on error.

- -

EC_KEY_get0_engine() returns a pointer to an ENGINE, or NULL if it wasn't set.

- -

EC_KEY_up_ref(), EC_KEY_set_group(), EC_KEY_set_public_key(), EC_KEY_precompute_mult(), EC_KEY_generate_key(), EC_KEY_check_key(), EC_KEY_set_public_key_affine_coordinates(), EC_KEY_oct2key() and EC_KEY_oct2priv() return 1 on success or 0 on error.

- -

EC_KEY_set_private_key() returns 1 on success or 0 on error except when the priv_key argument is NULL, in that case it returns 0, for legacy compatibility, and should not be treated as an error.

- -

EC_KEY_get0_group() returns the EC_GROUP associated with the EC_KEY.

- -

EC_KEY_get0_private_key() returns the private key associated with the EC_KEY.

- -

EC_KEY_get_conv_form() return the point_conversion_form for the EC_KEY.

- -

EC_KEY_key2buf(), EC_KEY_priv2oct() and EC_KEY_priv2buf() return the length of the buffer or 0 on error.

- -

SEE ALSO

- -

EVP_PKEY_Q_keygen(3) crypto(7), EC_GROUP_new(3), EC_GROUP_copy(3), EC_POINT_new(3), EC_POINT_add(3), EC_GFp_simple_method(3), d2i_ECPKParameters(3), OSSL_LIB_CTX(3)

- -

HISTORY

- -

EVP_EC_gen() was added in OpenSSL 3.0. All other functions described here were deprecated in OpenSSL 3.0. For replacement see EVP_PKEY-EC(7).

- -

COPYRIGHT

- -

Copyright 2013-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EC_POINT_add.html b/openssl-install/share/doc/openssl/html/man3/EC_POINT_add.html deleted file mode 100644 index cee33c07..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EC_POINT_add.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -EC_POINT_add - - - - - - - - - - -

NAME

- -

EC_POINT_add, EC_POINT_dbl, EC_POINT_invert, EC_POINT_is_at_infinity, EC_POINT_is_on_curve, EC_POINT_cmp, EC_POINT_make_affine, EC_POINTs_make_affine, EC_POINTs_mul, EC_POINT_mul, EC_GROUP_precompute_mult, EC_GROUP_have_precompute_mult - Functions for performing mathematical operations and tests on EC_POINT objects

- -

SYNOPSIS

- -
#include <openssl/ec.h>
-
-int EC_POINT_add(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a,
-                 const EC_POINT *b, BN_CTX *ctx);
-int EC_POINT_dbl(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a, BN_CTX *ctx);
-int EC_POINT_invert(const EC_GROUP *group, EC_POINT *a, BN_CTX *ctx);
-int EC_POINT_is_at_infinity(const EC_GROUP *group, const EC_POINT *p);
-int EC_POINT_is_on_curve(const EC_GROUP *group, const EC_POINT *point, BN_CTX *ctx);
-int EC_POINT_cmp(const EC_GROUP *group, const EC_POINT *a, const EC_POINT *b, BN_CTX *ctx);
-int EC_POINT_mul(const EC_GROUP *group, EC_POINT *r, const BIGNUM *n,
-                 const EC_POINT *q, const BIGNUM *m, BN_CTX *ctx);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int EC_POINT_make_affine(const EC_GROUP *group, EC_POINT *point, BN_CTX *ctx);
-int EC_POINTs_make_affine(const EC_GROUP *group, size_t num,
-                          EC_POINT *points[], BN_CTX *ctx);
-int EC_POINTs_mul(const EC_GROUP *group, EC_POINT *r, const BIGNUM *n, size_t num,
-                  const EC_POINT *p[], const BIGNUM *m[], BN_CTX *ctx);
-int EC_GROUP_precompute_mult(EC_GROUP *group, BN_CTX *ctx);
-int EC_GROUP_have_precompute_mult(const EC_GROUP *group);
- -

DESCRIPTION

- -

EC_POINT_add adds the two points a and b and places the result in r. Similarly EC_POINT_dbl doubles the point a and places the result in r. In both cases it is valid for r to be one of a or b.

- -

EC_POINT_invert calculates the inverse of the supplied point a. The result is placed back in a.

- -

The function EC_POINT_is_at_infinity tests whether the supplied point is at infinity or not.

- -

EC_POINT_is_on_curve tests whether the supplied point is on the curve or not.

- -

EC_POINT_cmp compares the two supplied points and tests whether or not they are equal.

- -

The functions EC_POINT_make_affine and EC_POINTs_make_affine force the internal representation of the EC_POINT(s) into the affine coordinate system. In the case of EC_POINTs_make_affine the value num provides the number of points in the array points to be forced. These functions were deprecated in OpenSSL 3.0 and should no longer be used. Modern versions automatically perform this conversion when needed.

- -

EC_POINT_mul calculates the value generator * n + q * m and stores the result in r. The value n may be NULL in which case the result is just q * m (variable point multiplication). Alternatively, both q and m may be NULL, and n non-NULL, in which case the result is just generator * n (fixed point multiplication). When performing a single fixed or variable point multiplication, the underlying implementation uses a constant time algorithm, when the input scalar (either n or m) is in the range [0, ec_group_order).

- -

Although deprecated in OpenSSL 3.0 and should no longer be used, EC_POINTs_mul calculates the value generator * n + q[0] * m[0] + ... + q[num-1] * m[num-1]. As for EC_POINT_mul the value n may be NULL or num may be zero. When performing a fixed point multiplication (n is non-NULL and num is 0) or a variable point multiplication (n is NULL and num is 1), the underlying implementation uses a constant time algorithm, when the input scalar (either n or m[0]) is in the range [0, ec_group_order). Modern versions should instead use EC_POINT_mul(), combined (if needed) with EC_POINT_add() in such rare circumstances.

- -

The function EC_GROUP_precompute_mult stores multiples of the generator for faster point multiplication, whilst EC_GROUP_have_precompute_mult tests whether precomputation has already been done. See EC_GROUP_copy(3) for information about the generator. Precomputation functionality was deprecated in OpenSSL 3.0. Users of EC_GROUP_precompute_mult() and EC_GROUP_have_precompute_mult() should switch to named curves which OpenSSL has hardcoded lookup tables for.

- -

RETURN VALUES

- -

The following functions return 1 on success or 0 on error: EC_POINT_add, EC_POINT_dbl, EC_POINT_invert, EC_POINT_make_affine, EC_POINTs_make_affine, EC_POINTs_make_affine, EC_POINT_mul, EC_POINTs_mul and EC_GROUP_precompute_mult.

- -

EC_POINT_is_at_infinity returns 1 if the point is at infinity, or 0 otherwise.

- -

EC_POINT_is_on_curve returns 1 if the point is on the curve, 0 if not, or -1 on error.

- -

EC_POINT_cmp returns 1 if the points are not equal, 0 if they are, or -1 on error.

- -

EC_GROUP_have_precompute_mult return 1 if a precomputation has been done, or 0 if not.

- -

SEE ALSO

- -

crypto(7), EC_GROUP_new(3), EC_GROUP_copy(3), EC_POINT_new(3), EC_KEY_new(3), EC_GFp_simple_method(3), d2i_ECPKParameters(3)

- -

HISTORY

- -

EC_POINT_make_affine(), EC_POINTs_make_affine(), EC_POINTs_mul(), EC_GROUP_precompute_mult(), and EC_GROUP_have_precompute_mult() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2013-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EC_POINT_new.html b/openssl-install/share/doc/openssl/html/man3/EC_POINT_new.html deleted file mode 100644 index 92e04be0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EC_POINT_new.html +++ /dev/null @@ -1,179 +0,0 @@ - - - - -EC_POINT_new - - - - - - - - - - -

NAME

- -

EC_POINT_set_Jprojective_coordinates_GFp, EC_POINT_point2buf, EC_POINT_new, EC_POINT_free, EC_POINT_clear_free, EC_POINT_copy, EC_POINT_dup, EC_POINT_method_of, EC_POINT_set_to_infinity, EC_POINT_get_Jprojective_coordinates_GFp, EC_POINT_set_affine_coordinates, EC_POINT_get_affine_coordinates, EC_POINT_set_compressed_coordinates, EC_POINT_set_affine_coordinates_GFp, EC_POINT_get_affine_coordinates_GFp, EC_POINT_set_compressed_coordinates_GFp, EC_POINT_set_affine_coordinates_GF2m, EC_POINT_get_affine_coordinates_GF2m, EC_POINT_set_compressed_coordinates_GF2m, EC_POINT_point2oct, EC_POINT_oct2point, EC_POINT_point2bn, EC_POINT_bn2point, EC_POINT_point2hex, EC_POINT_hex2point - Functions for creating, destroying and manipulating EC_POINT objects

- -

SYNOPSIS

- -
#include <openssl/ec.h>
-
-EC_POINT *EC_POINT_new(const EC_GROUP *group);
-void EC_POINT_free(EC_POINT *point);
-void EC_POINT_clear_free(EC_POINT *point);
-int EC_POINT_copy(EC_POINT *dst, const EC_POINT *src);
-EC_POINT *EC_POINT_dup(const EC_POINT *src, const EC_GROUP *group);
-int EC_POINT_set_to_infinity(const EC_GROUP *group, EC_POINT *point);
-int EC_POINT_set_affine_coordinates(const EC_GROUP *group, EC_POINT *p,
-                                    const BIGNUM *x, const BIGNUM *y,
-                                    BN_CTX *ctx);
-int EC_POINT_get_affine_coordinates(const EC_GROUP *group, const EC_POINT *p,
-                                    BIGNUM *x, BIGNUM *y, BN_CTX *ctx);
-int EC_POINT_set_compressed_coordinates(const EC_GROUP *group, EC_POINT *p,
-                                        const BIGNUM *x, int y_bit,
-                                        BN_CTX *ctx);
-size_t EC_POINT_point2oct(const EC_GROUP *group, const EC_POINT *p,
-                          point_conversion_form_t form,
-                          unsigned char *buf, size_t len, BN_CTX *ctx);
-size_t EC_POINT_point2buf(const EC_GROUP *group, const EC_POINT *point,
-                          point_conversion_form_t form,
-                          unsigned char **pbuf, BN_CTX *ctx);
-int EC_POINT_oct2point(const EC_GROUP *group, EC_POINT *p,
-                       const unsigned char *buf, size_t len, BN_CTX *ctx);
-char *EC_POINT_point2hex(const EC_GROUP *group, const EC_POINT *p,
-                         point_conversion_form_t form, BN_CTX *ctx);
-EC_POINT *EC_POINT_hex2point(const EC_GROUP *group, const char *hex,
-                             EC_POINT *p, BN_CTX *ctx);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
const EC_METHOD *EC_POINT_method_of(const EC_POINT *point);
-int EC_POINT_set_Jprojective_coordinates_GFp(const EC_GROUP *group,
-                                             EC_POINT *p,
-                                             const BIGNUM *x, const BIGNUM *y,
-                                             const BIGNUM *z, BN_CTX *ctx);
-int EC_POINT_get_Jprojective_coordinates_GFp(const EC_GROUP *group,
-                                             const EC_POINT *p,
-                                             BIGNUM *x, BIGNUM *y, BIGNUM *z,
-                                             BN_CTX *ctx);
-int EC_POINT_set_affine_coordinates_GFp(const EC_GROUP *group, EC_POINT *p,
-                                        const BIGNUM *x, const BIGNUM *y,
-                                        BN_CTX *ctx);
-int EC_POINT_get_affine_coordinates_GFp(const EC_GROUP *group,
-                                        const EC_POINT *p,
-                                        BIGNUM *x, BIGNUM *y, BN_CTX *ctx);
-int EC_POINT_set_compressed_coordinates_GFp(const EC_GROUP *group,
-                                            EC_POINT *p,
-                                            const BIGNUM *x, int y_bit,
-                                            BN_CTX *ctx);
-int EC_POINT_set_affine_coordinates_GF2m(const EC_GROUP *group, EC_POINT *p,
-                                         const BIGNUM *x, const BIGNUM *y,
-                                         BN_CTX *ctx);
-int EC_POINT_get_affine_coordinates_GF2m(const EC_GROUP *group,
-                                         const EC_POINT *p,
-                                         BIGNUM *x, BIGNUM *y, BN_CTX *ctx);
-int EC_POINT_set_compressed_coordinates_GF2m(const EC_GROUP *group,
-                                             EC_POINT *p,
-                                             const BIGNUM *x, int y_bit,
-                                             BN_CTX *ctx);
-BIGNUM *EC_POINT_point2bn(const EC_GROUP *group, const EC_POINT *p,
-                          point_conversion_form_t form, BIGNUM *bn,
-                          BN_CTX *ctx);
-EC_POINT *EC_POINT_bn2point(const EC_GROUP *group, const BIGNUM *bn,
-                            EC_POINT *p, BN_CTX *ctx);
- -

DESCRIPTION

- -

An EC_POINT structure represents a point on a curve. A new point is constructed by calling the function EC_POINT_new() and providing the group object that the point relates to.

- -

EC_POINT_free() frees the memory associated with the EC_POINT. if point is NULL nothing is done.

- -

EC_POINT_clear_free() destroys any sensitive data held within the EC_POINT and then frees its memory. If point is NULL nothing is done.

- -

EC_POINT_copy() copies the point src into dst. Both src and dst must use the same EC_METHOD.

- -

EC_POINT_dup() creates a new EC_POINT object and copies the content from src to the newly created EC_POINT object.

- -

EC_POINT_method_of() obtains the EC_METHOD associated with point. This function was deprecated in OpenSSL 3.0, since EC_METHOD is no longer a public concept.

- -

A valid point on a curve is the special point at infinity. A point is set to be at infinity by calling EC_POINT_set_to_infinity().

- -

The affine coordinates for a point describe a point in terms of its x and y position. The function EC_POINT_set_affine_coordinates() sets the x and y coordinates for the point p defined over the curve given in group. The function EC_POINT_get_affine_coordinates() sets x and y, either of which may be NULL, to the corresponding coordinates of p.

- -

The functions EC_POINT_set_affine_coordinates_GFp() and EC_POINT_set_affine_coordinates_GF2m() are synonyms for EC_POINT_set_affine_coordinates(). They are defined for backwards compatibility only and should not be used.

- -

The functions EC_POINT_get_affine_coordinates_GFp() and EC_POINT_get_affine_coordinates_GF2m() are synonyms for EC_POINT_get_affine_coordinates(). They are defined for backwards compatibility only and should not be used.

- -

As well as the affine coordinates, a point can alternatively be described in terms of its Jacobian projective coordinates (for Fp curves only). Jacobian projective coordinates are expressed as three values x, y and z. Working in this coordinate system provides more efficient point multiplication operations. A mapping exists between Jacobian projective coordinates and affine coordinates. A Jacobian projective coordinate (x, y, z) can be written as an affine coordinate as (x/(z^2), y/(z^3)). Conversion to Jacobian projective from affine coordinates is simple. The coordinate (x, y) is mapped to (x, y, 1). Although deprecated in OpenSSL 3.0 and should no longer be used, to set or get the projective coordinates in older versions use EC_POINT_set_Jprojective_coordinates_GFp() and EC_POINT_get_Jprojective_coordinates_GFp() respectively. Modern versions should instead use EC_POINT_set_affine_coordinates() and EC_POINT_get_affine_coordinates(), performing the conversion manually using the above maps in such rare circumstances.

- -

Points can also be described in terms of their compressed coordinates. For a point (x, y), for any given value for x such that the point is on the curve there will only ever be two possible values for y. Therefore, a point can be set using the EC_POINT_set_compressed_coordinates() function where x is the x coordinate and y_bit is a value 0 or 1 to identify which of the two possible values for y should be used.

- -

The functions EC_POINT_set_compressed_coordinates_GFp() and EC_POINT_set_compressed_coordinates_GF2m() are synonyms for EC_POINT_set_compressed_coordinates(). They are defined for backwards compatibility only and should not be used.

- -

In addition EC_POINT can be converted to and from various external representations. The octet form is the binary encoding of the ECPoint structure (as defined in RFC5480 and used in certificates and TLS records): only the content octets are present, the OCTET STRING tag and length are not included. BIGNUM form is the octet form interpreted as a big endian integer converted to a BIGNUM structure. Hexadecimal form is the octet form converted to a NULL terminated character string where each character is one of the printable values 0-9 or A-F (or a-f).

- -

The functions EC_POINT_point2oct(), EC_POINT_oct2point(), EC_POINT_point2bn(), EC_POINT_bn2point(), EC_POINT_point2hex() and EC_POINT_hex2point() convert from and to EC_POINTs for the formats: octet, BIGNUM and hexadecimal respectively.

- -

The function EC_POINT_point2oct() encodes the given curve point p as an octet string into the buffer buf of size len, using the specified conversion form form. The encoding conforms with Sec. 2.3.3 of the SECG SEC 1 ("Elliptic Curve Cryptography") standard. Similarly the function EC_POINT_oct2point() decodes a curve point into p from the octet string contained in the given buffer buf of size len, conforming to Sec. 2.3.4 of the SECG SEC 1 ("Elliptic Curve Cryptography") standard.

- -

The functions EC_POINT_point2hex() and EC_POINT_point2bn() convert a point p, respectively, to the hexadecimal or BIGNUM representation of the same encoding of the function EC_POINT_point2oct(). Vice versa, similarly to the function EC_POINT_oct2point(), the functions EC_POINT_hex2point() and EC_POINT_point2bn() decode the hexadecimal or BIGNUM representation into the EC_POINT p.

- -

Notice that, according to the standard, the octet string encoding of the point at infinity for a given curve is fixed to a single octet of value zero and that, vice versa, a single octet of size zero is decoded as the point at infinity.

- -

The function EC_POINT_point2oct() must be supplied with a buffer long enough to store the octet form. The return value provides the number of octets stored. Calling the function with a NULL buffer will not perform the conversion but will still return the required buffer length.

- -

The function EC_POINT_point2buf() allocates a buffer of suitable length and writes an EC_POINT to it in octet format. The allocated buffer is written to *pbuf and its length is returned. The caller must free up the allocated buffer with a call to OPENSSL_free(). Since the allocated buffer value is written to *pbuf the pbuf parameter MUST NOT be NULL.

- -

The function EC_POINT_point2hex() will allocate sufficient memory to store the hexadecimal string. It is the caller's responsibility to free this memory with a subsequent call to OPENSSL_free().

- -

RETURN VALUES

- -

EC_POINT_new() and EC_POINT_dup() return the newly allocated EC_POINT or NULL on error.

- -

The following functions return 1 on success or 0 on error: EC_POINT_copy(), EC_POINT_set_to_infinity(), EC_POINT_set_Jprojective_coordinates_GFp(), EC_POINT_get_Jprojective_coordinates_GFp(), EC_POINT_set_affine_coordinates_GFp(), EC_POINT_get_affine_coordinates_GFp(), EC_POINT_set_compressed_coordinates_GFp(), EC_POINT_set_affine_coordinates_GF2m(), EC_POINT_get_affine_coordinates_GF2m(), EC_POINT_set_compressed_coordinates_GF2m() and EC_POINT_oct2point().

- -

EC_POINT_method_of returns the EC_METHOD associated with the supplied EC_POINT.

- -

EC_POINT_point2oct() and EC_POINT_point2buf() return the length of the required buffer or 0 on error.

- -

EC_POINT_point2bn() returns the pointer to the BIGNUM supplied, or NULL on error.

- -

EC_POINT_bn2point() returns the pointer to the EC_POINT supplied, or NULL on error.

- -

EC_POINT_point2hex() returns a pointer to the hex string, or NULL on error.

- -

EC_POINT_hex2point() returns the pointer to the EC_POINT supplied, or NULL on error.

- -

SEE ALSO

- -

crypto(7), EC_GROUP_new(3), EC_GROUP_copy(3), EC_POINT_add(3), EC_KEY_new(3), EC_GFp_simple_method(3), d2i_ECPKParameters(3)

- -

HISTORY

- -

EC_POINT_method_of(), EC_POINT_set_Jprojective_coordinates_GFp(), EC_POINT_get_Jprojective_coordinates_GFp(), EC_POINT_set_affine_coordinates_GFp(), EC_POINT_get_affine_coordinates_GFp(), EC_POINT_set_compressed_coordinates_GFp(), EC_POINT_set_affine_coordinates_GF2m(), EC_POINT_get_affine_coordinates_GF2m(), EC_POINT_set_compressed_coordinates_GF2m(), EC_POINT_point2bn(), and EC_POINT_bn2point() were deprecated in OpenSSL 3.0.

- -

EC_POINT_set_affine_coordinates, EC_POINT_get_affine_coordinates, and EC_POINT_set_compressed_coordinates were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2013-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ENGINE_add.html b/openssl-install/share/doc/openssl/html/man3/ENGINE_add.html deleted file mode 100644 index 4f9c2b37..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ENGINE_add.html +++ /dev/null @@ -1,426 +0,0 @@ - - - - -ENGINE_add - - - - - - - - - - -

NAME

- -

ENGINE_get_DH, ENGINE_get_DSA, ENGINE_by_id, ENGINE_get_cipher_engine, ENGINE_get_default_DH, ENGINE_get_default_DSA, ENGINE_get_default_RAND, ENGINE_get_default_RSA, ENGINE_get_digest_engine, ENGINE_get_first, ENGINE_get_last, ENGINE_get_next, ENGINE_get_prev, ENGINE_new, ENGINE_get_ciphers, ENGINE_get_ctrl_function, ENGINE_get_digests, ENGINE_get_destroy_function, ENGINE_get_finish_function, ENGINE_get_init_function, ENGINE_get_load_privkey_function, ENGINE_get_load_pubkey_function, ENGINE_load_private_key, ENGINE_load_public_key, ENGINE_get_RAND, ENGINE_get_RSA, ENGINE_get_id, ENGINE_get_name, ENGINE_get_cmd_defns, ENGINE_get_cipher, ENGINE_get_digest, ENGINE_add, ENGINE_cmd_is_executable, ENGINE_ctrl, ENGINE_ctrl_cmd, ENGINE_ctrl_cmd_string, ENGINE_finish, ENGINE_free, ENGINE_get_flags, ENGINE_init, ENGINE_register_DH, ENGINE_register_DSA, ENGINE_register_RAND, ENGINE_register_RSA, ENGINE_register_all_complete, ENGINE_register_ciphers, ENGINE_register_complete, ENGINE_register_digests, ENGINE_remove, ENGINE_set_DH, ENGINE_set_DSA, ENGINE_set_RAND, ENGINE_set_RSA, ENGINE_set_ciphers, ENGINE_set_cmd_defns, ENGINE_set_ctrl_function, ENGINE_set_default, ENGINE_set_default_DH, ENGINE_set_default_DSA, ENGINE_set_default_RAND, ENGINE_set_default_RSA, ENGINE_set_default_ciphers, ENGINE_set_default_digests, ENGINE_set_default_string, ENGINE_set_destroy_function, ENGINE_set_digests, ENGINE_set_finish_function, ENGINE_set_flags, ENGINE_set_id, ENGINE_set_init_function, ENGINE_set_load_privkey_function, ENGINE_set_load_pubkey_function, ENGINE_set_name, ENGINE_up_ref, ENGINE_get_table_flags, ENGINE_cleanup, ENGINE_load_builtin_engines, ENGINE_register_all_DH, ENGINE_register_all_DSA, ENGINE_register_all_RAND, ENGINE_register_all_RSA, ENGINE_register_all_ciphers, ENGINE_register_all_digests, ENGINE_set_table_flags, ENGINE_unregister_DH, ENGINE_unregister_DSA, ENGINE_unregister_RAND, ENGINE_unregister_RSA, ENGINE_unregister_ciphers, ENGINE_unregister_digests - ENGINE cryptographic module support

- -

SYNOPSIS

- -
#include <openssl/engine.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
ENGINE *ENGINE_get_first(void);
-ENGINE *ENGINE_get_last(void);
-ENGINE *ENGINE_get_next(ENGINE *e);
-ENGINE *ENGINE_get_prev(ENGINE *e);
-
-int ENGINE_add(ENGINE *e);
-int ENGINE_remove(ENGINE *e);
-
-ENGINE *ENGINE_by_id(const char *id);
-
-int ENGINE_init(ENGINE *e);
-int ENGINE_finish(ENGINE *e);
-
-void ENGINE_load_builtin_engines(void);
-
-ENGINE *ENGINE_get_default_RSA(void);
-ENGINE *ENGINE_get_default_DSA(void);
-ENGINE *ENGINE_get_default_DH(void);
-ENGINE *ENGINE_get_default_RAND(void);
-ENGINE *ENGINE_get_cipher_engine(int nid);
-ENGINE *ENGINE_get_digest_engine(int nid);
-
-int ENGINE_set_default_RSA(ENGINE *e);
-int ENGINE_set_default_DSA(ENGINE *e);
-int ENGINE_set_default_DH(ENGINE *e);
-int ENGINE_set_default_RAND(ENGINE *e);
-int ENGINE_set_default_ciphers(ENGINE *e);
-int ENGINE_set_default_digests(ENGINE *e);
-int ENGINE_set_default_string(ENGINE *e, const char *list);
-
-int ENGINE_set_default(ENGINE *e, unsigned int flags);
-
-unsigned int ENGINE_get_table_flags(void);
-void ENGINE_set_table_flags(unsigned int flags);
-
-int ENGINE_register_RSA(ENGINE *e);
-void ENGINE_unregister_RSA(ENGINE *e);
-void ENGINE_register_all_RSA(void);
-int ENGINE_register_DSA(ENGINE *e);
-void ENGINE_unregister_DSA(ENGINE *e);
-void ENGINE_register_all_DSA(void);
-int ENGINE_register_DH(ENGINE *e);
-void ENGINE_unregister_DH(ENGINE *e);
-void ENGINE_register_all_DH(void);
-int ENGINE_register_RAND(ENGINE *e);
-void ENGINE_unregister_RAND(ENGINE *e);
-void ENGINE_register_all_RAND(void);
-int ENGINE_register_ciphers(ENGINE *e);
-void ENGINE_unregister_ciphers(ENGINE *e);
-void ENGINE_register_all_ciphers(void);
-int ENGINE_register_digests(ENGINE *e);
-void ENGINE_unregister_digests(ENGINE *e);
-void ENGINE_register_all_digests(void);
-int ENGINE_register_complete(ENGINE *e);
-int ENGINE_register_all_complete(void);
-
-int ENGINE_ctrl(ENGINE *e, int cmd, long i, void *p, void (*f)(void));
-int ENGINE_cmd_is_executable(ENGINE *e, int cmd);
-int ENGINE_ctrl_cmd(ENGINE *e, const char *cmd_name,
-                    long i, void *p, void (*f)(void), int cmd_optional);
-int ENGINE_ctrl_cmd_string(ENGINE *e, const char *cmd_name, const char *arg,
-                           int cmd_optional);
-
-ENGINE *ENGINE_new(void);
-int ENGINE_free(ENGINE *e);
-int ENGINE_up_ref(ENGINE *e);
-
-int ENGINE_set_id(ENGINE *e, const char *id);
-int ENGINE_set_name(ENGINE *e, const char *name);
-int ENGINE_set_RSA(ENGINE *e, const RSA_METHOD *rsa_meth);
-int ENGINE_set_DSA(ENGINE *e, const DSA_METHOD *dsa_meth);
-int ENGINE_set_DH(ENGINE *e, const DH_METHOD *dh_meth);
-int ENGINE_set_RAND(ENGINE *e, const RAND_METHOD *rand_meth);
-int ENGINE_set_destroy_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR destroy_f);
-int ENGINE_set_init_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR init_f);
-int ENGINE_set_finish_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR finish_f);
-int ENGINE_set_ctrl_function(ENGINE *e, ENGINE_CTRL_FUNC_PTR ctrl_f);
-int ENGINE_set_load_privkey_function(ENGINE *e, ENGINE_LOAD_KEY_PTR loadpriv_f);
-int ENGINE_set_load_pubkey_function(ENGINE *e, ENGINE_LOAD_KEY_PTR loadpub_f);
-int ENGINE_set_ciphers(ENGINE *e, ENGINE_CIPHERS_PTR f);
-int ENGINE_set_digests(ENGINE *e, ENGINE_DIGESTS_PTR f);
-int ENGINE_set_flags(ENGINE *e, int flags);
-int ENGINE_set_cmd_defns(ENGINE *e, const ENGINE_CMD_DEFN *defns);
-
-const char *ENGINE_get_id(const ENGINE *e);
-const char *ENGINE_get_name(const ENGINE *e);
-const RSA_METHOD *ENGINE_get_RSA(const ENGINE *e);
-const DSA_METHOD *ENGINE_get_DSA(const ENGINE *e);
-const DH_METHOD *ENGINE_get_DH(const ENGINE *e);
-const RAND_METHOD *ENGINE_get_RAND(const ENGINE *e);
-ENGINE_GEN_INT_FUNC_PTR ENGINE_get_destroy_function(const ENGINE *e);
-ENGINE_GEN_INT_FUNC_PTR ENGINE_get_init_function(const ENGINE *e);
-ENGINE_GEN_INT_FUNC_PTR ENGINE_get_finish_function(const ENGINE *e);
-ENGINE_CTRL_FUNC_PTR ENGINE_get_ctrl_function(const ENGINE *e);
-ENGINE_LOAD_KEY_PTR ENGINE_get_load_privkey_function(const ENGINE *e);
-ENGINE_LOAD_KEY_PTR ENGINE_get_load_pubkey_function(const ENGINE *e);
-ENGINE_CIPHERS_PTR ENGINE_get_ciphers(const ENGINE *e);
-ENGINE_DIGESTS_PTR ENGINE_get_digests(const ENGINE *e);
-const EVP_CIPHER *ENGINE_get_cipher(ENGINE *e, int nid);
-const EVP_MD *ENGINE_get_digest(ENGINE *e, int nid);
-int ENGINE_get_flags(const ENGINE *e);
-const ENGINE_CMD_DEFN *ENGINE_get_cmd_defns(const ENGINE *e);
-
-EVP_PKEY *ENGINE_load_private_key(ENGINE *e, const char *key_id,
-                                  UI_METHOD *ui_method, void *callback_data);
-EVP_PKEY *ENGINE_load_public_key(ENGINE *e, const char *key_id,
-                                 UI_METHOD *ui_method, void *callback_data);
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void ENGINE_cleanup(void);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the provider APIs.

- -

These functions create, manipulate, and use cryptographic modules in the form of ENGINE objects. These objects act as containers for implementations of cryptographic algorithms, and support a reference-counted mechanism to allow them to be dynamically loaded in and out of the running application.

- -

The cryptographic functionality that can be provided by an ENGINE implementation includes the following abstractions;

- -
RSA_METHOD - for providing alternative RSA implementations
-DSA_METHOD, DH_METHOD, RAND_METHOD, ECDH_METHOD, ECDSA_METHOD,
-      - similarly for other OpenSSL APIs
-EVP_CIPHER - potentially multiple cipher algorithms (indexed by 'nid')
-EVP_DIGEST - potentially multiple hash algorithms (indexed by 'nid')
-key-loading - loading public and/or private EVP_PKEY keys
- -

Reference counting and handles

- -

Due to the modular nature of the ENGINE API, pointers to ENGINEs need to be treated as handles - i.e. not only as pointers, but also as references to the underlying ENGINE object. Ie. one should obtain a new reference when making copies of an ENGINE pointer if the copies will be used (and released) independently.

- -

ENGINE objects have two levels of reference-counting to match the way in which the objects are used. At the most basic level, each ENGINE pointer is inherently a structural reference - a structural reference is required to use the pointer value at all, as this kind of reference is a guarantee that the structure can not be deallocated until the reference is released.

- -

However, a structural reference provides no guarantee that the ENGINE is initialised and able to use any of its cryptographic implementations. Indeed it's quite possible that most ENGINEs will not initialise at all in typical environments, as ENGINEs are typically used to support specialised hardware. To use an ENGINE's functionality, you need a functional reference. This kind of reference can be considered a specialised form of structural reference, because each functional reference implicitly contains a structural reference as well - however to avoid difficult-to-find programming bugs, it is recommended to treat the two kinds of reference independently. If you have a functional reference to an ENGINE, you have a guarantee that the ENGINE has been initialised and is ready to perform cryptographic operations, and will remain initialised until after you have released your reference.

- -

Structural references

- -

This basic type of reference is used for instantiating new ENGINEs, iterating across OpenSSL's internal linked-list of loaded ENGINEs, reading information about an ENGINE, etc. Essentially a structural reference is sufficient if you only need to query or manipulate the data of an ENGINE implementation rather than use its functionality.

- -

The ENGINE_new() function returns a structural reference to a new (empty) ENGINE object. There are other ENGINE API functions that return structural references such as; ENGINE_by_id(), ENGINE_get_first(), ENGINE_get_last(), ENGINE_get_next(), ENGINE_get_prev(). All structural references should be released by a corresponding to call to the ENGINE_free() function - the ENGINE object itself will only actually be cleaned up and deallocated when the last structural reference is released. If the argument to ENGINE_free() is NULL, nothing is done.

- -

It should also be noted that many ENGINE API function calls that accept a structural reference will internally obtain another reference - typically this happens whenever the supplied ENGINE will be needed by OpenSSL after the function has returned. Eg. the function to add a new ENGINE to OpenSSL's internal list is ENGINE_add() - if this function returns success, then OpenSSL will have stored a new structural reference internally so the caller is still responsible for freeing their own reference with ENGINE_free() when they are finished with it. In a similar way, some functions will automatically release the structural reference passed to it if part of the function's job is to do so. Eg. the ENGINE_get_next() and ENGINE_get_prev() functions are used for iterating across the internal ENGINE list - they will return a new structural reference to the next (or previous) ENGINE in the list or NULL if at the end (or beginning) of the list, but in either case the structural reference passed to the function is released on behalf of the caller.

- -

To clarify a particular function's handling of references, one should always consult that function's documentation "man" page, or failing that the <openssl/engine.h> header file includes some hints.

- -

Functional references

- -

As mentioned, functional references exist when the cryptographic functionality of an ENGINE is required to be available. A functional reference can be obtained in one of two ways; from an existing structural reference to the required ENGINE, or by asking OpenSSL for the default operational ENGINE for a given cryptographic purpose.

- -

To obtain a functional reference from an existing structural reference, call the ENGINE_init() function. This returns zero if the ENGINE was not already operational and couldn't be successfully initialised (e.g. lack of system drivers, no special hardware attached, etc), otherwise it will return nonzero to indicate that the ENGINE is now operational and will have allocated a new functional reference to the ENGINE. All functional references are released by calling ENGINE_finish() (which removes the implicit structural reference as well).

- -

The second way to get a functional reference is by asking OpenSSL for a default implementation for a given task, e.g. by ENGINE_get_default_RSA(), ENGINE_get_default_cipher_engine(), etc. These are discussed in the next section, though they are not usually required by application programmers as they are used automatically when creating and using the relevant algorithm-specific types in OpenSSL, such as RSA, DSA, EVP_CIPHER_CTX, etc.

- -

Default implementations

- -

For each supported abstraction, the ENGINE code maintains an internal table of state to control which implementations are available for a given abstraction and which should be used by default. These implementations are registered in the tables and indexed by an 'nid' value, because abstractions like EVP_CIPHER and EVP_DIGEST support many distinct algorithms and modes, and ENGINEs can support arbitrarily many of them. In the case of other abstractions like RSA, DSA, etc, there is only one "algorithm" so all implementations implicitly register using the same 'nid' index.

- -

When a default ENGINE is requested for a given abstraction/algorithm/mode, (e.g. when calling RSA_new_method(NULL)), a "get_default" call will be made to the ENGINE subsystem to process the corresponding state table and return a functional reference to an initialised ENGINE whose implementation should be used. If no ENGINE should (or can) be used, it will return NULL and the caller will operate with a NULL ENGINE handle - this usually equates to using the conventional software implementation. In the latter case, OpenSSL will from then on behave the way it used to before the ENGINE API existed.

- -

Each state table has a flag to note whether it has processed this "get_default" query since the table was last modified, because to process this question it must iterate across all the registered ENGINEs in the table trying to initialise each of them in turn, in case one of them is operational. If it returns a functional reference to an ENGINE, it will also cache another reference to speed up processing future queries (without needing to iterate across the table). Likewise, it will cache a NULL response if no ENGINE was available so that future queries won't repeat the same iteration unless the state table changes. This behaviour can also be changed; if the ENGINE_TABLE_FLAG_NOINIT flag is set (using ENGINE_set_table_flags()), no attempted initialisations will take place, instead the only way for the state table to return a non-NULL ENGINE to the "get_default" query will be if one is expressly set in the table. Eg. ENGINE_set_default_RSA() does the same job as ENGINE_register_RSA() except that it also sets the state table's cached response for the "get_default" query. In the case of abstractions like EVP_CIPHER, where implementations are indexed by 'nid', these flags and cached-responses are distinct for each 'nid' value.

- -

Application requirements

- -

This section will explain the basic things an application programmer should support to make the most useful elements of the ENGINE functionality available to the user. The first thing to consider is whether the programmer wishes to make alternative ENGINE modules available to the application and user. OpenSSL maintains an internal linked list of "visible" ENGINEs from which it has to operate - at start-up, this list is empty and in fact if an application does not call any ENGINE API calls and it uses static linking against openssl, then the resulting application binary will not contain any alternative ENGINE code at all. So the first consideration is whether any/all available ENGINE implementations should be made visible to OpenSSL - this is controlled by calling the various "load" functions.

- -

The fact that ENGINEs are made visible to OpenSSL (and thus are linked into the program and loaded into memory at run-time) does not mean they are "registered" or called into use by OpenSSL automatically - that behaviour is something for the application to control. Some applications will want to allow the user to specify exactly which ENGINE they want used if any is to be used at all. Others may prefer to load all support and have OpenSSL automatically use at run-time any ENGINE that is able to successfully initialise - i.e. to assume that this corresponds to acceleration hardware attached to the machine or some such thing. There are probably numerous other ways in which applications may prefer to handle things, so we will simply illustrate the consequences as they apply to a couple of simple cases and leave developers to consider these and the source code to openssl's built-in utilities as guides.

- -

If no ENGINE API functions are called within an application, then OpenSSL will not allocate any internal resources. Prior to OpenSSL 1.1.0, however, if any ENGINEs are loaded, even if not registered or used, it was necessary to call ENGINE_cleanup() before the program exits.

- -

Using a specific ENGINE implementation

- -

Here we'll assume an application has been configured by its user or admin to want to use the "ACME" ENGINE if it is available in the version of OpenSSL the application was compiled with. If it is available, it should be used by default for all RSA, DSA, and symmetric cipher operations, otherwise OpenSSL should use its built-in software as per usual. The following code illustrates how to approach this;

- -
ENGINE *e;
-const char *engine_id = "ACME";
-ENGINE_load_builtin_engines();
-e = ENGINE_by_id(engine_id);
-if (!e)
-    /* the engine isn't available */
-    return;
-if (!ENGINE_init(e)) {
-    /* the engine couldn't initialise, release 'e' */
-    ENGINE_free(e);
-    return;
-}
-if (!ENGINE_set_default_RSA(e))
-    /*
-     * This should only happen when 'e' can't initialise, but the previous
-     * statement suggests it did.
-     */
-    abort();
-ENGINE_set_default_DSA(e);
-ENGINE_set_default_ciphers(e);
-/* Release the functional reference from ENGINE_init() */
-ENGINE_finish(e);
-/* Release the structural reference from ENGINE_by_id() */
-ENGINE_free(e);
- -

Automatically using built-in ENGINE implementations

- -

Here we'll assume we want to load and register all ENGINE implementations bundled with OpenSSL, such that for any cryptographic algorithm required by OpenSSL - if there is an ENGINE that implements it and can be initialised, it should be used. The following code illustrates how this can work;

- -
/* Load all bundled ENGINEs into memory and make them visible */
-ENGINE_load_builtin_engines();
-/* Register all of them for every algorithm they collectively implement */
-ENGINE_register_all_complete();
- -

That's all that's required. Eg. the next time OpenSSL tries to set up an RSA key, any bundled ENGINEs that implement RSA_METHOD will be passed to ENGINE_init() and if any of those succeed, that ENGINE will be set as the default for RSA use from then on.

- -

Advanced configuration support

- -

There is a mechanism supported by the ENGINE framework that allows each ENGINE implementation to define an arbitrary set of configuration "commands" and expose them to OpenSSL and any applications based on OpenSSL. This mechanism is entirely based on the use of name-value pairs and assumes ASCII input (no unicode or UTF for now!), so it is ideal if applications want to provide a transparent way for users to provide arbitrary configuration "directives" directly to such ENGINEs. It is also possible for the application to dynamically interrogate the loaded ENGINE implementations for the names, descriptions, and input flags of their available "control commands", providing a more flexible configuration scheme. However, if the user is expected to know which ENGINE device he/she is using (in the case of specialised hardware, this goes without saying) then applications may not need to concern themselves with discovering the supported control commands and simply prefer to pass settings into ENGINEs exactly as they are provided by the user.

- -

Before illustrating how control commands work, it is worth mentioning what they are typically used for. Broadly speaking there are two uses for control commands; the first is to provide the necessary details to the implementation (which may know nothing at all specific to the host system) so that it can be initialised for use. This could include the path to any driver or config files it needs to load, required network addresses, smart-card identifiers, passwords to initialise protected devices, logging information, etc etc. This class of commands typically needs to be passed to an ENGINE before attempting to initialise it, i.e. before calling ENGINE_init(). The other class of commands consist of settings or operations that tweak certain behaviour or cause certain operations to take place, and these commands may work either before or after ENGINE_init(), or in some cases both. ENGINE implementations should provide indications of this in the descriptions attached to built-in control commands and/or in external product documentation.

- -

Issuing control commands to an ENGINE

- -

Let's illustrate by example; a function for which the caller supplies the name of the ENGINE it wishes to use, a table of string-pairs for use before initialisation, and another table for use after initialisation. Note that the string-pairs used for control commands consist of a command "name" followed by the command "parameter" - the parameter could be NULL in some cases but the name can not. This function should initialise the ENGINE (issuing the "pre" commands beforehand and the "post" commands afterwards) and set it as the default for everything except RAND and then return a boolean success or failure.

- -
int generic_load_engine_fn(const char *engine_id,
-                           const char **pre_cmds, int pre_num,
-                           const char **post_cmds, int post_num)
-{
-    ENGINE *e = ENGINE_by_id(engine_id);
-    if (!e) return 0;
-    while (pre_num--) {
-        if (!ENGINE_ctrl_cmd_string(e, pre_cmds[0], pre_cmds[1], 0)) {
-            fprintf(stderr, "Failed command (%s - %s:%s)\n", engine_id,
-                    pre_cmds[0], pre_cmds[1] ? pre_cmds[1] : "(NULL)");
-            ENGINE_free(e);
-            return 0;
-        }
-        pre_cmds += 2;
-    }
-    if (!ENGINE_init(e)) {
-        fprintf(stderr, "Failed initialisation\n");
-        ENGINE_free(e);
-        return 0;
-    }
-    /*
-     * ENGINE_init() returned a functional reference, so free the structural
-     * reference from ENGINE_by_id().
-     */
-    ENGINE_free(e);
-    while (post_num--) {
-        if (!ENGINE_ctrl_cmd_string(e, post_cmds[0], post_cmds[1], 0)) {
-            fprintf(stderr, "Failed command (%s - %s:%s)\n", engine_id,
-                    post_cmds[0], post_cmds[1] ? post_cmds[1] : "(NULL)");
-            ENGINE_finish(e);
-            return 0;
-        }
-        post_cmds += 2;
-    }
-    ENGINE_set_default(e, ENGINE_METHOD_ALL & ~ENGINE_METHOD_RAND);
-    /* Success */
-    return 1;
-}
- -

Note that ENGINE_ctrl_cmd_string() accepts a boolean argument that can relax the semantics of the function - if set nonzero it will only return failure if the ENGINE supported the given command name but failed while executing it, if the ENGINE doesn't support the command name it will simply return success without doing anything. In this case we assume the user is only supplying commands specific to the given ENGINE so we set this to FALSE.

- -

Discovering supported control commands

- -

It is possible to discover at run-time the names, numerical-ids, descriptions and input parameters of the control commands supported by an ENGINE using a structural reference. Note that some control commands are defined by OpenSSL itself and it will intercept and handle these control commands on behalf of the ENGINE, i.e. the ENGINE's ctrl() handler is not used for the control command. <openssl/engine.h> defines an index, ENGINE_CMD_BASE, that all control commands implemented by ENGINEs should be numbered from. Any command value lower than this symbol is considered a "generic" command is handled directly by the OpenSSL core routines.

- -

It is using these "core" control commands that one can discover the control commands implemented by a given ENGINE, specifically the commands:

- -
ENGINE_HAS_CTRL_FUNCTION
-ENGINE_CTRL_GET_FIRST_CMD_TYPE
-ENGINE_CTRL_GET_NEXT_CMD_TYPE
-ENGINE_CTRL_GET_CMD_FROM_NAME
-ENGINE_CTRL_GET_NAME_LEN_FROM_CMD
-ENGINE_CTRL_GET_NAME_FROM_CMD
-ENGINE_CTRL_GET_DESC_LEN_FROM_CMD
-ENGINE_CTRL_GET_DESC_FROM_CMD
-ENGINE_CTRL_GET_CMD_FLAGS
- -

Whilst these commands are automatically processed by the OpenSSL framework code, they use various properties exposed by each ENGINE to process these queries. An ENGINE has 3 properties it exposes that can affect how this behaves; it can supply a ctrl() handler, it can specify ENGINE_FLAGS_MANUAL_CMD_CTRL in the ENGINE's flags, and it can expose an array of control command descriptions. If an ENGINE specifies the ENGINE_FLAGS_MANUAL_CMD_CTRL flag, then it will simply pass all these "core" control commands directly to the ENGINE's ctrl() handler (and thus, it must have supplied one), so it is up to the ENGINE to reply to these "discovery" commands itself. If that flag is not set, then the OpenSSL framework code will work with the following rules:

- -
if no ctrl() handler supplied;
-    ENGINE_HAS_CTRL_FUNCTION returns FALSE (zero),
-    all other commands fail.
-if a ctrl() handler was supplied but no array of control commands;
-    ENGINE_HAS_CTRL_FUNCTION returns TRUE,
-    all other commands fail.
-if a ctrl() handler and array of control commands was supplied;
-    ENGINE_HAS_CTRL_FUNCTION returns TRUE,
-    all other commands proceed processing ...
- -

If the ENGINE's array of control commands is empty then all other commands will fail, otherwise; ENGINE_CTRL_GET_FIRST_CMD_TYPE returns the identifier of the first command supported by the ENGINE, ENGINE_GET_NEXT_CMD_TYPE takes the identifier of a command supported by the ENGINE and returns the next command identifier or fails if there are no more, ENGINE_CMD_FROM_NAME takes a string name for a command and returns the corresponding identifier or fails if no such command name exists, and the remaining commands take a command identifier and return properties of the corresponding commands. All except ENGINE_CTRL_GET_FLAGS return the string length of a command name or description, or populate a supplied character buffer with a copy of the command name or description. ENGINE_CTRL_GET_FLAGS returns a bitwise-OR'd mask of the following possible values:

- -
ENGINE_CMD_FLAG_NUMERIC
-ENGINE_CMD_FLAG_STRING
-ENGINE_CMD_FLAG_NO_INPUT
-ENGINE_CMD_FLAG_INTERNAL
- -

If the ENGINE_CMD_FLAG_INTERNAL flag is set, then any other flags are purely informational to the caller - this flag will prevent the command being usable for any higher-level ENGINE functions such as ENGINE_ctrl_cmd_string(). "INTERNAL" commands are not intended to be exposed to text-based configuration by applications, administrations, users, etc. These can support arbitrary operations via ENGINE_ctrl(), including passing to and/or from the control commands data of any arbitrary type. These commands are supported in the discovery mechanisms simply to allow applications to determine if an ENGINE supports certain specific commands it might want to use (e.g. application "foo" might query various ENGINEs to see if they implement "FOO_GET_VENDOR_LOGO_GIF" - and ENGINE could therefore decide whether or not to support this "foo"-specific extension).

- -

ENVIRONMENT

- -
- -
OPENSSL_ENGINES
-
- -

The path to the engines directory. Ignored in set-user-ID and set-group-ID programs.

- -
-
- -

RETURN VALUES

- -

ENGINE_get_first(), ENGINE_get_last(), ENGINE_get_next() and ENGINE_get_prev() return a valid ENGINE structure or NULL if an error occurred.

- -

ENGINE_add() and ENGINE_remove() return 1 on success or 0 on error.

- -

ENGINE_by_id() returns a valid ENGINE structure or NULL if an error occurred.

- -

ENGINE_init() and ENGINE_finish() return 1 on success or 0 on error.

- -

All ENGINE_get_default_TYPE() functions, ENGINE_get_cipher_engine() and ENGINE_get_digest_engine() return a valid ENGINE structure on success or NULL if an error occurred.

- -

All ENGINE_set_default_TYPE() functions return 1 on success or 0 on error.

- -

ENGINE_set_default() returns 1 on success or 0 on error.

- -

ENGINE_get_table_flags() returns an unsigned integer value representing the global table flags which are used to control the registration behaviour of ENGINE implementations.

- -

All ENGINE_register_TYPE() functions return 1 on success or 0 on error.

- -

ENGINE_register_complete() and ENGINE_register_all_complete() always return 1.

- -

ENGINE_ctrl() returns a positive value on success or others on error.

- -

ENGINE_cmd_is_executable() returns 1 if cmd is executable or 0 otherwise.

- -

ENGINE_ctrl_cmd() and ENGINE_ctrl_cmd_string() return 1 on success or 0 on error.

- -

ENGINE_new() returns a valid ENGINE structure on success or NULL if an error occurred.

- -

ENGINE_free() always returns 1.

- -

ENGINE_up_ref() returns 1 on success or 0 on error.

- -

ENGINE_set_id() and ENGINE_set_name() return 1 on success or 0 on error.

- -

All other ENGINE_set_* functions return 1 on success or 0 on error.

- -

ENGINE_get_id() and ENGINE_get_name() return a string representing the identifier and the name of the ENGINE e respectively.

- -

ENGINE_get_RSA(), ENGINE_get_DSA(), ENGINE_get_DH() and ENGINE_get_RAND() return corresponding method structures for each algorithms.

- -

ENGINE_get_destroy_function(), ENGINE_get_init_function(), ENGINE_get_finish_function(), ENGINE_get_ctrl_function(), ENGINE_get_load_privkey_function(), ENGINE_get_load_pubkey_function(), ENGINE_get_ciphers() and ENGINE_get_digests() return corresponding function pointers of the callbacks.

- -

ENGINE_get_cipher() returns a valid EVP_CIPHER structure on success or NULL if an error occurred.

- -

ENGINE_get_digest() returns a valid EVP_MD structure on success or NULL if an error occurred.

- -

ENGINE_get_flags() returns an integer representing the ENGINE flags which are used to control various behaviours of an ENGINE.

- -

ENGINE_get_cmd_defns() returns an ENGINE_CMD_DEFN structure or NULL if it's not set.

- -

ENGINE_load_private_key() and ENGINE_load_public_key() return a valid EVP_PKEY structure on success or NULL if an error occurred.

- -

SEE ALSO

- -

OPENSSL_init_crypto(3), RSA_new_method(3), DSA_new(3), DH_new(3), RAND_bytes(3), config(5)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

ENGINE_cleanup() was deprecated in OpenSSL 1.1.0 by the automatic cleanup done by OPENSSL_cleanup() and should not be used.

- -

COPYRIGHT

- -

Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_GET_LIB.html b/openssl-install/share/doc/openssl/html/man3/ERR_GET_LIB.html deleted file mode 100644 index 68bf46ea..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_GET_LIB.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -ERR_GET_LIB - - - - - - - - - - -

NAME

- -

ERR_GET_LIB, ERR_GET_REASON, ERR_FATAL_ERROR - get information from error codes

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-int ERR_GET_LIB(unsigned long e);
-
-int ERR_GET_REASON(unsigned long e);
-
-int ERR_FATAL_ERROR(unsigned long e);
- -

DESCRIPTION

- -

The error code returned by ERR_get_error() consists of a library number and reason code. ERR_GET_LIB() and ERR_GET_REASON() can be used to extract these.

- -

ERR_FATAL_ERROR() indicates whether a given error code is a fatal error.

- -

The library number describes where the error occurred, the reason code is the information about what went wrong.

- -

Each sub-library of OpenSSL has a unique library number; the reason code is unique within each sub-library. Note that different libraries may use the same value to signal different reasons.

- -

ERR_R_... reason codes such as ERR_R_MALLOC_FAILURE are globally unique. However, when checking for sub-library specific reason codes, be sure to also compare the library number.

- -

ERR_GET_LIB(), ERR_GET_REASON(), and ERR_FATAL_ERROR() are macros.

- -

RETURN VALUES

- -

The library number, reason code, and whether the error is fatal, respectively. Starting with OpenSSL 3.0.0, the function code is always set to zero.

- -

NOTES

- -

Applications should not make control flow decisions based on specific error codes. Error codes are subject to change at any time (even in patch releases of OpenSSL). A particular error code can only be considered meaningful for control flow decisions if it is explicitly documented as such. New failure codes may still appear at any time.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

HISTORY

- -

ERR_GET_LIB() and ERR_GET_REASON() are available in all versions of OpenSSL.

- -

ERR_GET_FUNC() was removed in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_clear_error.html b/openssl-install/share/doc/openssl/html/man3/ERR_clear_error.html deleted file mode 100644 index 9aff2281..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_clear_error.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -ERR_clear_error - - - - - - - - - - -

NAME

- -

ERR_clear_error - clear the error queue

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-void ERR_clear_error(void);
- -

DESCRIPTION

- -

ERR_clear_error() empties the current thread's error queue.

- -

RETURN VALUES

- -

ERR_clear_error() has no return value.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_error_string.html b/openssl-install/share/doc/openssl/html/man3/ERR_error_string.html deleted file mode 100644 index f63d83dc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_error_string.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -ERR_error_string - - - - - - - - - - -

NAME

- -

ERR_error_string, ERR_error_string_n, ERR_lib_error_string, ERR_func_error_string, ERR_reason_error_string - obtain human-readable error message

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-char *ERR_error_string(unsigned long e, char *buf);
-void ERR_error_string_n(unsigned long e, char *buf, size_t len);
-
-const char *ERR_lib_error_string(unsigned long e);
-const char *ERR_reason_error_string(unsigned long e);
- -

Deprecated in OpenSSL 3.0:

- -
const char *ERR_func_error_string(unsigned long e);
- -

DESCRIPTION

- -

ERR_error_string() generates a human-readable string representing the error code e, and places it at buf. buf must be at least 256 bytes long. If buf is NULL, the error string is placed in a static buffer. Note that this function is not thread-safe and does no checks on the size of the buffer; use ERR_error_string_n() instead.

- -

ERR_error_string_n() is a variant of ERR_error_string() that writes at most len characters (including the terminating 0) and truncates the string if necessary. For ERR_error_string_n(), buf may not be NULL.

- -

The string will have the following format:

- -
error:[error code]:[library name]::[reason string]
- -

error code is an 8 digit hexadecimal number, library name and reason string are ASCII text.

- -

ERR_lib_error_string() and ERR_reason_error_string() return the library name and reason string respectively.

- -

If there is no text string registered for the given error code, the error string will contain the numeric code.

- -

ERR_print_errors(3) can be used to print all error codes currently in the queue.

- -

RETURN VALUES

- -

ERR_error_string() returns a pointer to a static buffer containing the string if buf == NULL, buf otherwise.

- -

ERR_lib_error_string() and ERR_reason_error_string() return the strings, and NULL if none is registered for the error code.

- -

ERR_func_error_string() returns NULL.

- -

SEE ALSO

- -

ERR_get_error(3), ERR_print_errors(3)

- -

HISTORY

- -

ERR_func_error_string() became deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_get_error.html b/openssl-install/share/doc/openssl/html/man3/ERR_get_error.html deleted file mode 100644 index ea2dea84..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_get_error.html +++ /dev/null @@ -1,116 +0,0 @@ - - - - -ERR_get_error - - - - - - - - - - -

NAME

- -

ERR_get_error, ERR_peek_error, ERR_peek_last_error, ERR_get_error_line, ERR_peek_error_line, ERR_peek_last_error_line, ERR_peek_error_func, ERR_peek_last_error_func, ERR_peek_error_data, ERR_peek_last_error_data, ERR_get_error_all, ERR_peek_error_all, ERR_peek_last_error_all, ERR_get_error_line_data, ERR_peek_error_line_data, ERR_peek_last_error_line_data - obtain error code and data

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-unsigned long ERR_get_error(void);
-unsigned long ERR_peek_error(void);
-unsigned long ERR_peek_last_error(void);
-
-unsigned long ERR_peek_error_line(const char **file, int *line);
-unsigned long ERR_peek_last_error_line(const char **file, int *line);
-
-unsigned long ERR_peek_error_func(const char **func);
-unsigned long ERR_peek_last_error_func(const char **func);
-
-unsigned long ERR_peek_error_data(const char **data, int *flags);
-unsigned long ERR_peek_last_error_data(const char **data, int *flags);
-
-unsigned long ERR_get_error_all(const char **file, int *line,
-                                const char **func,
-                                const char **data, int *flags);
-unsigned long ERR_peek_error_all(const char **file, int *line,
-                                 const char **func,
-                                 const char **data, int *flags);
-unsigned long ERR_peek_last_error_all(const char **file, int *line,
-                                      const char *func,
-                                      const char **data, int *flags);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
unsigned long ERR_get_error_line(const char **file, int *line);
-unsigned long ERR_get_error_line_data(const char **file, int *line,
-                                      const char **data, int *flags);
-unsigned long ERR_peek_error_line_data(const char **file, int *line,
-                                       const char **data, int *flags);
-unsigned long ERR_peek_last_error_line_data(const char **file, int *line,
-                                            const char **data, int *flags);
- -

DESCRIPTION

- -

ERR_get_error() returns the earliest error code from the thread's error queue and removes the entry. This function can be called repeatedly until there are no more error codes to return.

- -

ERR_peek_error() returns the earliest error code from the thread's error queue without modifying it.

- -

ERR_peek_last_error() returns the latest error code from the thread's error queue without modifying it.

- -

See ERR_GET_LIB(3) for obtaining further specific information such as the reason of the error, and ERR_error_string(3) for human-readable error messages.

- -

ERR_get_error_all() is the same as ERR_get_error(), but on success it additionally stores the filename, line number and function where the error occurred in *file, *line and *func, and also extra text and flags in *data, *flags. If any of those parameters are NULL, it will not be changed. An unset filename is indicated as "", i.e. an empty string. An unset line number is indicated as 0. An unset function name is indicated as "", i.e. an empty string.

- -

A pointer returned this way by these functions and the ones below is valid until the respective entry is overwritten in the error queue.

- -

ERR_peek_error_line() and ERR_peek_last_error_line() are the same as ERR_peek_error() and ERR_peek_last_error(), but on success they additionally store the filename and line number where the error occurred in *file and *line, as far as they are not NULL. An unset filename is indicated as "", i.e., an empty string. An unset line number is indicated as 0.

- -

ERR_peek_error_func() and ERR_peek_last_error_func() are the same as ERR_peek_error() and ERR_peek_last_error(), but on success they additionally store the name of the function where the error occurred in *func, unless it is NULL. An unset function name is indicated as "".

- -

ERR_peek_error_data() and ERR_peek_last_error_data() are the same as ERR_peek_error() and ERR_peek_last_error(), but on success they additionally store additional data and flags associated with the error code in *data and *flags, as far as they are not NULL. Unset data is indicated as "". In this case the value given for the flag is irrelevant (and equals 0). *data contains a string if *flags&ERR_TXT_STRING is true.

- -

ERR_peek_error_all() and ERR_peek_last_error_all() are combinations of all of the above.

- -

ERR_get_error_line(), ERR_get_error_line_data(), ERR_peek_error_line_data() and ERR_peek_last_error_line_data() are older variants of ERR_get_error_all(), ERR_peek_error_all() and ERR_peek_last_error_all(), and may give confusing results. They should no longer be used and are therefore deprecated.

- -

An application MUST NOT free the *data pointer (or any other pointers returned by these functions) with OPENSSL_free() as freeing is handled automatically by the error library.

- -

RETURN VALUES

- -

The error code, or 0 if there is no error in the queue.

- -

SEE ALSO

- -

ERR_error_string(3), ERR_GET_LIB(3)

- -

HISTORY

- -

ERR_peek_error_func(), ERR_peek_last_error_func(), ERR_peek_error_data(), ERR_peek_last_error_data(), ERR_peek_error_all() and ERR_peek_last_error_all() were added in OpenSSL 3.0.

- -

ERR_get_error_line(), ERR_get_error_line_data(), ERR_peek_error_line_data() and ERR_peek_last_error_line_data() became deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_load_crypto_strings.html b/openssl-install/share/doc/openssl/html/man3/ERR_load_crypto_strings.html deleted file mode 100644 index 49d0a341..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_load_crypto_strings.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -ERR_load_crypto_strings - - - - - - - - - - -

NAME

- -

ERR_load_crypto_strings, SSL_load_error_strings, ERR_free_strings - load and free error strings

- -

SYNOPSIS

- -

The following functions have been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#include <openssl/err.h>
-
-void ERR_load_crypto_strings(void);
-void ERR_free_strings(void);
-
-#include <openssl/ssl.h>
-
-void SSL_load_error_strings(void);
- -

DESCRIPTION

- -

ERR_load_crypto_strings() registers the error strings for all libcrypto functions. SSL_load_error_strings() does the same, but also registers the libssl error strings.

- -

In versions prior to OpenSSL 1.1.0, ERR_free_strings() releases any resources created by the above functions.

- -

RETURN VALUES

- -

ERR_load_crypto_strings(), SSL_load_error_strings() and ERR_free_strings() return no values.

- -

SEE ALSO

- -

ERR_error_string(3)

- -

HISTORY

- -

The ERR_load_crypto_strings(), SSL_load_error_strings(), and ERR_free_strings() functions were deprecated in OpenSSL 1.1.0 by OPENSSL_init_crypto() and OPENSSL_init_ssl() and should not be used.

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_load_strings.html b/openssl-install/share/doc/openssl/html/man3/ERR_load_strings.html deleted file mode 100644 index 408edcab..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_load_strings.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -ERR_load_strings - - - - - - - - - - -

NAME

- -

ERR_load_strings, ERR_PACK, ERR_get_next_error_library - load arbitrary error strings

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-int ERR_load_strings(int lib, ERR_STRING_DATA *str);
-
-int ERR_get_next_error_library(void);
-
-unsigned long ERR_PACK(int lib, int func, int reason);
- -

DESCRIPTION

- -

ERR_load_strings() registers error strings for library number lib.

- -

str is an array of error string data:

- -
typedef struct ERR_string_data_st
-{
-    unsigned long error;
-    char *string;
-} ERR_STRING_DATA;
- -

The error code is generated from the library number and a function and reason code: error = ERR_PACK(lib, func, reason). ERR_PACK() is a macro.

- -

The last entry in the array is {0,0}.

- -

ERR_get_next_error_library() can be used to assign library numbers to user libraries at run time.

- -

RETURN VALUES

- -

ERR_load_strings() returns 1 for success and 0 for failure. ERR_PACK() returns the error code. ERR_get_next_error_library() returns zero on failure, otherwise a new library number.

- -

SEE ALSO

- -

ERR_load_strings(3)

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_new.html b/openssl-install/share/doc/openssl/html/man3/ERR_new.html deleted file mode 100644 index f2f39f18..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_new.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -ERR_new - - - - - - - - - - -

NAME

- -

ERR_new, ERR_set_debug, ERR_set_error, ERR_vset_error - Error recording building blocks

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-void ERR_new(void);
-void ERR_set_debug(const char *file, int line, const char *func);
-void ERR_set_error(int lib, int reason, const char *fmt, ...);
-void ERR_vset_error(int lib, int reason, const char *fmt, va_list args);
- -

DESCRIPTION

- -

The functions described here are generally not used directly, but rather through macros such as ERR_raise(3). They can still be useful for anyone that wants to make their own macros.

- -

ERR_new() allocates a new slot in the thread's error queue.

- -

ERR_set_debug() sets the debug information related to the current error in the thread's error queue. The values that can be given are the filename file, line in the file line and the name of the function func where the error occurred. The names must be constant, this function will only save away the pointers, not copy the strings.

- -

ERR_set_error() sets the error information, which are the library number lib and the reason code reason, and additional data as a format string fmt and an arbitrary number of arguments. The additional data is processed with BIO_snprintf(3) to form the additional data string, which is allocated and store in the error record.

- -

ERR_vset_error() works like ERR_set_error(), but takes a va_list argument instead of a variable number of arguments.

- -

RETURN VALUES

- -

ERR_new, ERR_set_debug, ERR_set_error and ERR_vset_error do not return any values.

- -

NOTES

- -

The library number is unique to each unit that records errors. OpenSSL has a number of preallocated ones for its own uses, but others may allocate their own library number dynamically with ERR_get_next_error_library(3).

- -

Reason codes are unique within each library, and may have an associated set of strings as a short description of the reason. For dynamically allocated library numbers, reason strings are recorded with ERR_load_strings(3).

- -

Provider authors are supplied with core versions of these functions, see provider-base(7).

- -

SEE ALSO

- -

ERR_raise(3), ERR_get_next_error_library(3), ERR_load_strings(3), BIO_snprintf(3), provider-base(7)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_print_errors.html b/openssl-install/share/doc/openssl/html/man3/ERR_print_errors.html deleted file mode 100644 index e00e7e35..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_print_errors.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -ERR_print_errors - - - - - - - - - - -

NAME

- -

ERR_print_errors, ERR_print_errors_fp, ERR_print_errors_cb - print error messages

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-void ERR_print_errors(BIO *bp);
-void ERR_print_errors_fp(FILE *fp);
-void ERR_print_errors_cb(int (*cb)(const char *str, size_t len, void *u),
-                         void *u);
- -

DESCRIPTION

- -

ERR_print_errors() is a convenience function that prints the error strings for all errors that OpenSSL has recorded to bp, thus emptying the error queue.

- -

ERR_print_errors_fp() is the same, except that the output goes to a FILE.

- -

ERR_print_errors_cb() is the same, except that the callback function, cb, is called for each error line with the string, length, and userdata u as the callback parameters.

- -

The error strings will have the following format:

- -
[pid]:error:[error code]:[library name]:[function name]:[reason string]:[filename]:[line]:[optional text message]
- -

error code is an 8 digit hexadecimal number. library name, function name and reason string are ASCII text, as is optional text message if one was set for the respective error code.

- -

If there is no text string registered for the given error code, the error string will contain the numeric code.

- -

RETURN VALUES

- -

ERR_print_errors() and ERR_print_errors_fp() return no values.

- -

SEE ALSO

- -

ERR_error_string(3), ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_put_error.html b/openssl-install/share/doc/openssl/html/man3/ERR_put_error.html deleted file mode 100644 index 2fdcead6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_put_error.html +++ /dev/null @@ -1,155 +0,0 @@ - - - - -ERR_put_error - - - - - - - - - - -

NAME

- -

ERR_raise, ERR_raise_data, ERR_put_error, ERR_add_error_data, ERR_add_error_vdata, ERR_add_error_txt, ERR_add_error_mem_bio - record an error

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-void ERR_raise(int lib, int reason);
-void ERR_raise_data(int lib, int reason, const char *fmt, ...);
-
-void ERR_add_error_data(int num, ...);
-void ERR_add_error_vdata(int num, va_list arg);
-void ERR_add_error_txt(const char *sep, const char *txt);
-void ERR_add_error_mem_bio(const char *sep, BIO *bio);
- -

The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void ERR_put_error(int lib, int func, int reason, const char *file, int line);
- -

DESCRIPTION

- -

ERR_raise() adds a new error to the thread's error queue. The error occurred in the library lib for the reason given by the reason code. Furthermore, the name of the file, the line, and name of the function where the error occurred is saved with the error record.

- -

ERR_raise_data() does the same thing as ERR_raise(), but also lets the caller specify additional information as a format string fmt and an arbitrary number of values, which are processed with BIO_snprintf(3).

- -

ERR_put_error() adds an error code to the thread's error queue. It signals that the error of reason code reason occurred in function func of library lib, in line number line of file. This function is usually called by a macro.

- -

ERR_add_error_data() associates the concatenation of its num string arguments as additional data with the error code added last. ERR_add_error_vdata() is similar except the argument is a va_list. Multiple calls to these functions append to the current top of the error queue. The total length of the string data per error is limited to 4096 characters.

- -

ERR_add_error_txt() appends the given text string as additional data to the last error queue entry, after inserting the optional separator string if it is not NULL and the top error entry does not yet have additional data. In case the separator is at the end of the text it is not appended to the data. The sep argument may be for instance "\n" to insert a line break when needed. If the associated data would become more than 4096 characters long (which is the limit given above) it is split over sufficiently many new copies of the last error queue entry.

- -

ERR_add_error_mem_bio() is the same as ERR_add_error_txt() except that the text string is taken from the given memory BIO. It appends '\0' to the BIO contents if not already NUL-terminated.

- -

ERR_load_strings(3) can be used to register error strings so that the application can a generate human-readable error messages for the error code.

- -

Reporting errors

- -

OpenSSL library reports

- -

Each OpenSSL sub-library has library code ERR_LIB_XXX and has its own set of reason codes XXX_R_.... These are both passed in combination to ERR_raise() and ERR_raise_data(), and the combination ultimately produces the correct error text for the reported error.

- -

All these macros and the numbers they have as values are specific to OpenSSL's libraries. OpenSSL reason codes normally consist of textual error descriptions. For example, the function ssl3_read_bytes() reports a "handshake failure" as follows:

- -
ERR_raise(ERR_LIB_SSL, SSL_R_SSL_HANDSHAKE_FAILURE);
- -

There are two exceptions:

- -
- -
ERR_LIB_SYS
-
- -

This "library code" indicates that a system error is being reported. In this case, the reason code given to ERR_raise() and ERR_raise_data() must be errno(3).

- -
ERR_raise(ERR_LIB_SYS, errno);
- -
-
ERR_R_XXX
-
- -

This set of error codes is considered global, and may be used in combination with any sub-library code.

- -
ERR_raise(ERR_LIB_RSA, ERR_R_PASSED_INVALID_ARGUMENT);
- -
-
- -

Other pieces of software

- -

Other pieces of software that may want to use OpenSSL's error reporting system, such as engines or applications, must normally get their own numbers.

- - - -

The exceptions mentioned in "OpenSSL library reports" above are valid for other pieces of software, i.e. they may use ERR_LIB_SYS to report system errors:

- -
ERR_raise(ERR_LIB_SYS, errno);
- -

... and they may use ERR_R_XXX macros together with their own "library" code.

- -
int app_lib_code = ERR_get_next_error_library();
-
-/* ... */
-
-ERR_raise(app_lib_code, ERR_R_PASSED_INVALID_ARGUMENT);
- -

RETURN VALUES

- -

ERR_raise(), ERR_raise_data(), ERR_put_error(), ERR_add_error_data(), ERR_add_error_vdata() ERR_add_error_txt(), and ERR_add_error_mem_bio() return no values.

- -

NOTES

- -

ERR_raise(), ERR_raise() and ERR_put_error() are implemented as macros.

- -

SEE ALSO

- -

ERR_load_strings(3), ERR_get_next_error_library(3)

- -

HISTORY

- -

ERR_raise, ERR_raise_data, ERR_add_error_txt() and ERR_add_error_mem_bio() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_remove_state.html b/openssl-install/share/doc/openssl/html/man3/ERR_remove_state.html deleted file mode 100644 index 81a80b4b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_remove_state.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -ERR_remove_state - - - - - - - - - - -

NAME

- -

ERR_remove_thread_state, ERR_remove_state - DEPRECATED

- -

SYNOPSIS

- -

The following function has been deprecated since OpenSSL 1.0.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void ERR_remove_state(unsigned long tid);
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void ERR_remove_thread_state(void *tid);
- -

DESCRIPTION

- -

ERR_remove_state() frees the error queue associated with the specified thread, identified by tid. ERR_remove_thread_state() does the same thing, except the identifier is an opaque pointer.

- -

RETURN VALUES

- -

ERR_remove_state() and ERR_remove_thread_state() return no value.

- -

SEE ALSO

- -

LOPENSSL_init_crypto(3)

- -

HISTORY

- -

ERR_remove_state() was deprecated in OpenSSL 1.0.0 and ERR_remove_thread_state() was deprecated in OpenSSL 1.1.0; these functions and should not be used.

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/ERR_set_mark.html b/openssl-install/share/doc/openssl/html/man3/ERR_set_mark.html deleted file mode 100644 index 7b3a5487..00000000 --- a/openssl-install/share/doc/openssl/html/man3/ERR_set_mark.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -ERR_set_mark - - - - - - - - - - -

NAME

- -

ERR_set_mark, ERR_clear_last_mark, ERR_pop_to_mark, ERR_count_to_mark, ERR_pop - set mark, clear mark, pop errors until mark and pop last error

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-int ERR_set_mark(void);
-int ERR_pop_to_mark(void);
-int ERR_clear_last_mark(void);
-int ERR_count_to_mark(void);
-int ERR_pop(void);
- -

DESCRIPTION

- -

ERR_set_mark() sets a mark on the current topmost error record if there is one.

- -

ERR_pop_to_mark() will pop the top of the error stack until a mark is found. The mark is then removed. If there is no mark, the whole stack is removed.

- -

ERR_clear_last_mark() removes the last mark added if there is one.

- -

ERR_count_to_mark() returns the number of entries on the error stack above the most recently marked entry, not including that entry. If there is no mark in the error stack, the number of entries in the error stack is returned.

- -

ERR_pop() unconditionally pops a single error entry from the top of the error stack (which is the entry obtainable via ERR_peek_last_error(3)).

- -

RETURN VALUES

- -

ERR_set_mark() returns 0 if the error stack is empty, otherwise 1.

- -

ERR_clear_last_mark() and ERR_pop_to_mark() return 0 if there was no mark in the error stack, which implies that the stack became empty, otherwise 1.

- -

ERR_count_to_mark() returns the number of error stack entries found above the most recent mark, if any, or the total number of error stack entries.

- -

ERR_pop() returns 1 if an error was popped or 0 if the error stack was empty.

- -

HISTORY

- -

ERR_pop() was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2003-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_ASYM_CIPHER_free.html b/openssl-install/share/doc/openssl/html/man3/EVP_ASYM_CIPHER_free.html deleted file mode 100644 index 1f2c736b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_ASYM_CIPHER_free.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -EVP_ASYM_CIPHER_free - - - - - - - - - - -

NAME

- -

EVP_ASYM_CIPHER_fetch, EVP_ASYM_CIPHER_free, EVP_ASYM_CIPHER_up_ref, EVP_ASYM_CIPHER_is_a, EVP_ASYM_CIPHER_get0_provider, EVP_ASYM_CIPHER_do_all_provided, EVP_ASYM_CIPHER_names_do_all, EVP_ASYM_CIPHER_get0_name, EVP_ASYM_CIPHER_get0_description, EVP_ASYM_CIPHER_gettable_ctx_params, EVP_ASYM_CIPHER_settable_ctx_params - Functions to manage EVP_ASYM_CIPHER algorithm objects

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_ASYM_CIPHER *EVP_ASYM_CIPHER_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-                                       const char *properties);
-void EVP_ASYM_CIPHER_free(EVP_ASYM_CIPHER *cipher);
-int EVP_ASYM_CIPHER_up_ref(EVP_ASYM_CIPHER *cipher);
-const char *EVP_ASYM_CIPHER_get0_name(const EVP_ASYM_CIPHER *cipher);
-int EVP_ASYM_CIPHER_is_a(const EVP_ASYM_CIPHER *cipher, const char *name);
-OSSL_PROVIDER *EVP_ASYM_CIPHER_get0_provider(const EVP_ASYM_CIPHER *cipher);
-void EVP_ASYM_CIPHER_do_all_provided(OSSL_LIB_CTX *libctx,
-                                     void (*fn)(EVP_ASYM_CIPHER *cipher,
-                                                void *arg),
-                                     void *arg);
-int EVP_ASYM_CIPHER_names_do_all(const EVP_ASYM_CIPHER *cipher,
-                                 void (*fn)(const char *name, void *data),
-                                 void *data);
-const char *EVP_ASYM_CIPHER_get0_description(const EVP_ASYM_CIPHER *cipher);
-const OSSL_PARAM *EVP_ASYM_CIPHER_gettable_ctx_params(const EVP_ASYM_CIPHER *cip);
-const OSSL_PARAM *EVP_ASYM_CIPHER_settable_ctx_params(const EVP_ASYM_CIPHER *cip);
- -

DESCRIPTION

- -

EVP_ASYM_CIPHER_fetch() fetches the implementation for the given algorithm from any provider offering it, within the criteria given by the properties and in the scope of the given library context ctx (see OSSL_LIB_CTX(3)). The algorithm will be one offering functions for performing asymmetric cipher related tasks such as asymmetric encryption and decryption. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

The returned value must eventually be freed with EVP_ASYM_CIPHER_free().

- -

EVP_ASYM_CIPHER_free() decrements the reference count for the EVP_ASYM_CIPHER structure. Typically this structure will have been obtained from an earlier call to EVP_ASYM_CIPHER_fetch(). If the reference count drops to 0 then the structure is freed. If the argument is NULL, nothing is done.

- -

EVP_ASYM_CIPHER_up_ref() increments the reference count for an EVP_ASYM_CIPHER structure.

- -

EVP_ASYM_CIPHER_is_a() returns 1 if cipher is an implementation of an algorithm that's identifiable with name, otherwise 0.

- -

EVP_ASYM_CIPHER_get0_provider() returns the provider that cipher was fetched from.

- -

EVP_ASYM_CIPHER_do_all_provided() traverses all EVP_ASYM_CIPHERs implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -

EVP_ASYM_CIPHER_get0_name() returns the algorithm name from the provided implementation for the given cipher. Note that the cipher may have multiple synonyms associated with it. In this case the first name from the algorithm definition is returned. Ownership of the returned string is retained by the cipher object and should not be freed by the caller.

- -

EVP_ASYM_CIPHER_names_do_all() traverses all names for cipher, and calls fn with each name and data.

- -

EVP_ASYM_CIPHER_get0_description() returns a description of the cipher, meant for display and human consumption. The description is at the discretion of the cipher implementation.

- -

EVP_ASYM_CIPHER_gettable_ctx_params() and EVP_ASYM_CIPHER_settable_ctx_params() return a constant OSSL_PARAM(3) array that describes the names and types of key parameters that can be retrieved or set by a key encryption algorithm using EVP_PKEY_CTX_get_params(3) and EVP_PKEY_CTX_set_params(3).

- -

RETURN VALUES

- -

EVP_ASYM_CIPHER_fetch() returns a pointer to an EVP_ASYM_CIPHER for success or NULL for failure.

- -

EVP_ASYM_CIPHER_up_ref() returns 1 for success or 0 otherwise.

- -

EVP_ASYM_CIPHER_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EVP_ASYM_CIPHER_gettable_ctx_params() and EVP_ASYM_CIPHER_settable_ctx_params() return a constant OSSL_PARAM(3) array or NULL on error.

- -

SEE ALSO

- -

"ALGORITHM FETCHING" in crypto(7), OSSL_PROVIDER(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_BytesToKey.html b/openssl-install/share/doc/openssl/html/man3/EVP_BytesToKey.html deleted file mode 100644 index 9c63d365..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_BytesToKey.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -EVP_BytesToKey - - - - - - - - - - -

NAME

- -

EVP_BytesToKey - password based encryption routine

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_BytesToKey(const EVP_CIPHER *type, const EVP_MD *md,
-                   const unsigned char *salt,
-                   const unsigned char *data, int datal, int count,
-                   unsigned char *key, unsigned char *iv);
- -

DESCRIPTION

- -

EVP_BytesToKey() derives a key and IV from various parameters. type is the cipher to derive the key and IV for. md is the message digest to use. The salt parameter is used as a salt in the derivation: it should point to an 8 byte buffer or NULL if no salt is used. data is a buffer containing datal bytes which is used to derive the keying data. count is the iteration count to use. The derived key and IV will be written to key and iv respectively.

- -

NOTES

- -

A typical application of this function is to derive keying material for an encryption algorithm from a password in the data parameter.

- -

Increasing the count parameter slows down the algorithm which makes it harder for an attacker to perform a brute force attack using a large number of candidate passwords.

- -

If the total key and IV length is less than the digest length and MD5 is used then the derivation algorithm is compatible with PKCS#5 v1.5 otherwise a non standard extension is used to derive the extra data.

- -

Newer applications should use a more modern algorithm such as PBKDF2 as defined in PKCS#5v2.1 and provided by PKCS5_PBKDF2_HMAC.

- -

KEY DERIVATION ALGORITHM

- -

The key and IV is derived by concatenating D_1, D_2, etc until enough data is available for the key and IV. D_i is defined as:

- -
D_i = HASH^count(D_(i-1) || data || salt)
- -

where || denotes concatenation, D_0 is empty, HASH is the digest algorithm in use, HASH^1(data) is simply HASH(data), HASH^2(data) is HASH(HASH(data)) and so on.

- -

The initial bytes are used for the key and the subsequent bytes for the IV.

- -

RETURN VALUES

- -

If data is NULL, then EVP_BytesToKey() returns the number of bytes needed to store the derived key. Otherwise, EVP_BytesToKey() returns the size of the derived key in bytes, or 0 on error.

- -

SEE ALSO

- -

evp(7), RAND_bytes(3), PKCS5_PBKDF2_HMAC(3), EVP_EncryptInit(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_cipher_data.html b/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_cipher_data.html deleted file mode 100644 index 9004b368..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_cipher_data.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -EVP_CIPHER_CTX_get_cipher_data - - - - - - - - - - -

NAME

- -

EVP_CIPHER_CTX_get_cipher_data, EVP_CIPHER_CTX_set_cipher_data - Routines to inspect and modify EVP_CIPHER_CTX objects

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-void *EVP_CIPHER_CTX_get_cipher_data(const EVP_CIPHER_CTX *ctx);
-void *EVP_CIPHER_CTX_set_cipher_data(EVP_CIPHER_CTX *ctx, void *cipher_data);
- -

DESCRIPTION

- -

The EVP_CIPHER_CTX_get_cipher_data() function returns a pointer to the cipher data relevant to EVP_CIPHER_CTX. The contents of this data is specific to the particular implementation of the cipher. For example this data can be used by engines to store engine specific information. The data is automatically allocated and freed by OpenSSL, so applications and engines should not normally free this directly (but see below).

- -

The EVP_CIPHER_CTX_set_cipher_data() function allows an application or engine to replace the cipher data with new data. A pointer to any existing cipher data is returned from this function. If the old data is no longer required then it should be freed through a call to OPENSSL_free().

- -

RETURN VALUES

- -

The EVP_CIPHER_CTX_get_cipher_data() function returns a pointer to the current cipher data for the EVP_CIPHER_CTX.

- -

The EVP_CIPHER_CTX_set_cipher_data() function returns a pointer to the old cipher data for the EVP_CIPHER_CTX.

- -

HISTORY

- -

The EVP_CIPHER_CTX_get_cipher_data() and EVP_CIPHER_CTX_set_cipher_data() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_original_iv.html b/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_original_iv.html deleted file mode 100644 index 34c13391..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_CTX_get_original_iv.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -EVP_CIPHER_CTX_get_original_iv - - - - - - - - - - -

NAME

- -

EVP_CIPHER_CTX_get_original_iv, EVP_CIPHER_CTX_get_updated_iv, EVP_CIPHER_CTX_iv, EVP_CIPHER_CTX_original_iv, EVP_CIPHER_CTX_iv_noconst - Routines to inspect EVP_CIPHER_CTX IV data

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_CIPHER_CTX_get_original_iv(EVP_CIPHER_CTX *ctx, void *buf, size_t len);
-int EVP_CIPHER_CTX_get_updated_iv(EVP_CIPHER_CTX *ctx, void *buf, size_t len);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
const unsigned char *EVP_CIPHER_CTX_iv(const EVP_CIPHER_CTX *ctx);
-const unsigned char *EVP_CIPHER_CTX_original_iv(const EVP_CIPHER_CTX *ctx);
-unsigned char *EVP_CIPHER_CTX_iv_noconst(EVP_CIPHER_CTX *ctx);
- -

DESCRIPTION

- -

EVP_CIPHER_CTX_get_original_iv() and EVP_CIPHER_CTX_get_updated_iv() copy initialization vector (IV) information from the EVP_CIPHER_CTX into the caller-supplied buffer. EVP_CIPHER_CTX_get_iv_length(3) can be used to determine an appropriate buffer size, and if the supplied buffer is too small, an error will be returned (and no data copied). EVP_CIPHER_CTX_get_original_iv() accesses the ("original") IV that was supplied when the EVP_CIPHER_CTX was initialized, and EVP_CIPHER_CTX_get_updated_iv() accesses the current "IV state" of the cipher, which is updated during cipher operation for certain cipher modes (e.g., CBC and OFB).

- -

The functions EVP_CIPHER_CTX_iv(), EVP_CIPHER_CTX_original_iv(), and EVP_CIPHER_CTX_iv_noconst() are deprecated functions that provide similar (at a conceptual level) functionality. EVP_CIPHER_CTX_iv() returns a pointer to the beginning of the "IV state" as maintained internally in the EVP_CIPHER_CTX; EVP_CIPHER_CTX_original_iv() returns a pointer to the beginning of the ("original") IV, as maintained by the EVP_CIPHER_CTX, that was provided when the EVP_CIPHER_CTX was initialized; and EVP_CIPHER_CTX_get_iv_noconst() is the same as EVP_CIPHER_CTX_iv() but has a different return type for the pointer.

- -

RETURN VALUES

- -

EVP_CIPHER_CTX_get_original_iv() and EVP_CIPHER_CTX_get_updated_iv() return 1 on success and 0 on failure.

- -

The functions EVP_CIPHER_CTX_iv(), EVP_CIPHER_CTX_original_iv(), and EVP_CIPHER_CTX_iv_noconst() return a pointer to an IV as an array of bytes on success, and NULL on failure.

- -

HISTORY

- -

EVP_CIPHER_CTX_get_original_iv() and EVP_CIPHER_CTX_get_updated_iv() were added in OpenSSL 3.0.0.

- -

EVP_CIPHER_CTX_iv(), EVP_CIPHER_CTX_original_iv(), and EVP_CIPHER_CTX_iv_noconst() were added in OpenSSL 1.1.0, and were deprecated in OpenSSL 3.0.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_meth_new.html b/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_meth_new.html deleted file mode 100644 index 3470ed81..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_CIPHER_meth_new.html +++ /dev/null @@ -1,229 +0,0 @@ - - - - -EVP_CIPHER_meth_new - - - - - - - - - - -

NAME

- -

EVP_CIPHER_meth_new, EVP_CIPHER_meth_dup, EVP_CIPHER_meth_free, EVP_CIPHER_meth_set_iv_length, EVP_CIPHER_meth_set_flags, EVP_CIPHER_meth_set_impl_ctx_size, EVP_CIPHER_meth_set_init, EVP_CIPHER_meth_set_do_cipher, EVP_CIPHER_meth_set_cleanup, EVP_CIPHER_meth_set_set_asn1_params, EVP_CIPHER_meth_set_get_asn1_params, EVP_CIPHER_meth_set_ctrl, EVP_CIPHER_meth_get_init, EVP_CIPHER_meth_get_do_cipher, EVP_CIPHER_meth_get_cleanup, EVP_CIPHER_meth_get_set_asn1_params, EVP_CIPHER_meth_get_get_asn1_params, EVP_CIPHER_meth_get_ctrl - Routines to build up EVP_CIPHER methods

- -

SYNOPSIS

- -
#include <openssl/evp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
EVP_CIPHER *EVP_CIPHER_meth_new(int cipher_type, int block_size, int key_len);
-EVP_CIPHER *EVP_CIPHER_meth_dup(const EVP_CIPHER *cipher);
-void EVP_CIPHER_meth_free(EVP_CIPHER *cipher);
-
-int EVP_CIPHER_meth_set_iv_length(EVP_CIPHER *cipher, int iv_len);
-int EVP_CIPHER_meth_set_flags(EVP_CIPHER *cipher, unsigned long flags);
-int EVP_CIPHER_meth_set_impl_ctx_size(EVP_CIPHER *cipher, int ctx_size);
-int EVP_CIPHER_meth_set_init(EVP_CIPHER *cipher,
-                             int (*init)(EVP_CIPHER_CTX *ctx,
-                                         const unsigned char *key,
-                                         const unsigned char *iv,
-                                         int enc));
-int EVP_CIPHER_meth_set_do_cipher(EVP_CIPHER *cipher,
-                                  int (*do_cipher)(EVP_CIPHER_CTX *ctx,
-                                                   unsigned char *out,
-                                                   const unsigned char *in,
-                                                   size_t inl));
-int EVP_CIPHER_meth_set_cleanup(EVP_CIPHER *cipher,
-                                int (*cleanup)(EVP_CIPHER_CTX *));
-int EVP_CIPHER_meth_set_set_asn1_params(EVP_CIPHER *cipher,
-                                        int (*set_asn1_parameters)(EVP_CIPHER_CTX *,
-                                                                   ASN1_TYPE *));
-int EVP_CIPHER_meth_set_get_asn1_params(EVP_CIPHER *cipher,
-                                        int (*get_asn1_parameters)(EVP_CIPHER_CTX *,
-                                                                   ASN1_TYPE *));
-int EVP_CIPHER_meth_set_ctrl(EVP_CIPHER *cipher,
-                             int (*ctrl)(EVP_CIPHER_CTX *, int type,
-                                         int arg, void *ptr));
-
-int (*EVP_CIPHER_meth_get_init(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx,
-                                                          const unsigned char *key,
-                                                          const unsigned char *iv,
-                                                          int enc);
-int (*EVP_CIPHER_meth_get_do_cipher(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx,
-                                                               unsigned char *out,
-                                                               const unsigned char *in,
-                                                               size_t inl);
-int (*EVP_CIPHER_meth_get_cleanup(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *);
-int (*EVP_CIPHER_meth_get_set_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *,
-                                                                     ASN1_TYPE *);
-int (*EVP_CIPHER_meth_get_get_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *,
-                                                                     ASN1_TYPE *);
-int (*EVP_CIPHER_meth_get_ctrl(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *,
-                                                          int type, int arg,
-                                                          void *ptr);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the OSSL_PROVIDER APIs.

- -

The EVP_CIPHER type is a structure for symmetric cipher method implementation.

- -

EVP_CIPHER_meth_new() creates a new EVP_CIPHER structure.

- -

EVP_CIPHER_meth_dup() creates a copy of cipher.

- -

EVP_CIPHER_meth_free() destroys a EVP_CIPHER structure. If the argument is NULL, nothing is done.

- -

EVP_CIPHER_meth_set_iv_length() sets the length of the IV. This is only needed when the implemented cipher mode requires it.

- -

EVP_CIPHER_meth_set_flags() sets the flags to describe optional behaviours in the particular cipher. With the exception of cipher modes, of which only one may be present, several flags can be or'd together. The available flags are:

- -
- -
EVP_CIPH_STREAM_CIPHER, EVP_CIPH_ECB_MODE EVP_CIPH_CBC_MODE, EVP_CIPH_CFB_MODE, EVP_CIPH_OFB_MODE, EVP_CIPH_CTR_MODE, EVP_CIPH_GCM_MODE, EVP_CIPH_CCM_MODE, EVP_CIPH_XTS_MODE, EVP_CIPH_WRAP_MODE, EVP_CIPH_OCB_MODE, EVP_CIPH_SIV_MODE
-
- -

The cipher mode.

- -
-
EVP_CIPH_VARIABLE_LENGTH
-
- -

This cipher is of variable length.

- -
-
EVP_CIPH_CUSTOM_IV
-
- -

Storing and initialising the IV is left entirely to the implementation.

- -
-
EVP_CIPH_ALWAYS_CALL_INIT
-
- -

Set this if the implementation's init() function should be called even if key is NULL.

- -
-
EVP_CIPH_CTRL_INIT
-
- -

Set this to have the implementation's ctrl() function called with command code EVP_CTRL_INIT early in its setup.

- -
-
EVP_CIPH_CUSTOM_KEY_LENGTH
-
- -

Checking and setting the key length after creating the EVP_CIPHER is left to the implementation. Whenever someone uses EVP_CIPHER_CTX_set_key_length() on a EVP_CIPHER with this flag set, the implementation's ctrl() function will be called with the control code EVP_CTRL_SET_KEY_LENGTH and the key length in arg.

- -
-
EVP_CIPH_NO_PADDING
-
- -

Don't use standard block padding.

- -
-
EVP_CIPH_RAND_KEY
-
- -

Making a key with random content is left to the implementation. This is done by calling the implementation's ctrl() function with the control code EVP_CTRL_RAND_KEY and the pointer to the key memory storage in ptr.

- -
-
EVP_CIPH_CUSTOM_COPY
-
- -

Set this to have the implementation's ctrl() function called with command code EVP_CTRL_COPY at the end of EVP_CIPHER_CTX_copy(). The intended use is for further things to deal with after the implementation specific data block has been copied. The destination EVP_CIPHER_CTX is passed to the control with the ptr parameter. The implementation specific data block is reached with EVP_CIPHER_CTX_get_cipher_data().

- -
-
EVP_CIPH_FLAG_DEFAULT_ASN1
-
- -

Use the default EVP routines to pass IV to and from ASN.1.

- -
-
EVP_CIPH_FLAG_LENGTH_BITS
-
- -

Signals that the length of the input buffer for encryption / decryption is to be understood as the number of bits instead of bytes for this implementation. This is only useful for CFB1 ciphers.

- -
-
EVP_CIPH_FLAG_CTS
-
- -

Indicates that the cipher uses ciphertext stealing. This is currently used to indicate that the cipher is a one shot that only allows a single call to EVP_CipherUpdate().

- -
-
EVP_CIPH_FLAG_CUSTOM_CIPHER
-
- -

This indicates that the implementation takes care of everything, including padding, buffering and finalization. The EVP routines will simply give them control and do nothing more.

- -
-
EVP_CIPH_FLAG_AEAD_CIPHER
-
- -

This indicates that this is an AEAD cipher implementation.

- -
-
EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK
-
- -

Allow interleaving of crypto blocks, a particular optimization only applicable to certain TLS ciphers.

- -
-
- -

EVP_CIPHER_meth_set_impl_ctx_size() sets the size of the EVP_CIPHER's implementation context so that it can be automatically allocated.

- -

EVP_CIPHER_meth_set_init() sets the cipher init function for cipher. The cipher init function is called by EVP_CipherInit(), EVP_CipherInit_ex(), EVP_EncryptInit(), EVP_EncryptInit_ex(), EVP_DecryptInit(), EVP_DecryptInit_ex().

- -

EVP_CIPHER_meth_set_do_cipher() sets the cipher function for cipher. The cipher function is called by EVP_CipherUpdate(), EVP_EncryptUpdate(), EVP_DecryptUpdate(), EVP_CipherFinal(), EVP_EncryptFinal(), EVP_EncryptFinal_ex(), EVP_DecryptFinal() and EVP_DecryptFinal_ex().

- -

EVP_CIPHER_meth_set_cleanup() sets the function for cipher to do extra cleanup before the method's private data structure is cleaned out and freed. Note that the cleanup function is passed a EVP_CIPHER_CTX *, the private data structure is then available with EVP_CIPHER_CTX_get_cipher_data(). This cleanup function is called by EVP_CIPHER_CTX_reset() and EVP_CIPHER_CTX_free().

- -

EVP_CIPHER_meth_set_set_asn1_params() sets the function for cipher to set the AlgorithmIdentifier "parameter" based on the passed cipher. This function is called by EVP_CIPHER_param_to_asn1(). EVP_CIPHER_meth_set_get_asn1_params() sets the function for cipher that sets the cipher parameters based on an ASN.1 AlgorithmIdentifier "parameter". Both these functions are needed when there is a need for custom data (more or other than the cipher IV). They are called by EVP_CIPHER_param_to_asn1() and EVP_CIPHER_asn1_to_param() respectively if defined.

- -

EVP_CIPHER_meth_set_ctrl() sets the control function for cipher.

- -

EVP_CIPHER_meth_get_init(), EVP_CIPHER_meth_get_do_cipher(), EVP_CIPHER_meth_get_cleanup(), EVP_CIPHER_meth_get_set_asn1_params(), EVP_CIPHER_meth_get_get_asn1_params() and EVP_CIPHER_meth_get_ctrl() are all used to retrieve the method data given with the EVP_CIPHER_meth_set_*() functions above.

- -

RETURN VALUES

- -

EVP_CIPHER_meth_new() and EVP_CIPHER_meth_dup() return a pointer to a newly created EVP_CIPHER, or NULL on failure. All EVP_CIPHER_meth_set_*() functions return 1. All EVP_CIPHER_meth_get_*() functions return pointers to their respective cipher function.

- -

SEE ALSO

- -

EVP_EncryptInit(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

The functions described here were added in OpenSSL 1.1.0. The EVP_CIPHER structure created with these functions became reference counted in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_DigestInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_DigestInit.html deleted file mode 100644 index 32422bf3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_DigestInit.html +++ /dev/null @@ -1,782 +0,0 @@ - - - - -EVP_DigestInit - - - - - - - - - - -

NAME

- -

EVP_MD_fetch, EVP_MD_up_ref, EVP_MD_free, EVP_MD_get_params, EVP_MD_gettable_params, EVP_MD_CTX_new, EVP_MD_CTX_reset, EVP_MD_CTX_free, EVP_MD_CTX_dup, EVP_MD_CTX_copy, EVP_MD_CTX_copy_ex, EVP_MD_CTX_ctrl, EVP_MD_CTX_set_params, EVP_MD_CTX_get_params, EVP_MD_settable_ctx_params, EVP_MD_gettable_ctx_params, EVP_MD_CTX_settable_params, EVP_MD_CTX_gettable_params, EVP_MD_CTX_set_flags, EVP_MD_CTX_clear_flags, EVP_MD_CTX_test_flags, EVP_Q_digest, EVP_Digest, EVP_DigestInit_ex2, EVP_DigestInit_ex, EVP_DigestInit, EVP_DigestUpdate, EVP_DigestFinal_ex, EVP_DigestFinalXOF, EVP_DigestFinal, EVP_DigestSqueeze, EVP_MD_is_a, EVP_MD_get0_name, EVP_MD_get0_description, EVP_MD_names_do_all, EVP_MD_get0_provider, EVP_MD_get_type, EVP_MD_get_pkey_type, EVP_MD_get_size, EVP_MD_get_block_size, EVP_MD_get_flags, EVP_MD_CTX_get0_name, EVP_MD_CTX_md, EVP_MD_CTX_get0_md, EVP_MD_CTX_get1_md, EVP_MD_CTX_get_type, EVP_MD_CTX_get_size_ex, EVP_MD_CTX_get_block_size, EVP_MD_CTX_get0_md_data, EVP_MD_CTX_update_fn, EVP_MD_CTX_set_update_fn, EVP_md_null, EVP_get_digestbyname, EVP_get_digestbynid, EVP_get_digestbyobj, EVP_MD_CTX_get_pkey_ctx, EVP_MD_CTX_set_pkey_ctx, EVP_MD_do_all_provided, EVP_MD_type, EVP_MD_nid, EVP_MD_name, EVP_MD_pkey_type, EVP_MD_size, EVP_MD_block_size, EVP_MD_flags, EVP_MD_xof, EVP_MD_CTX_size, EVP_MD_CTX_get_size, EVP_MD_CTX_block_size, EVP_MD_CTX_type, EVP_MD_CTX_pkey_ctx, EVP_MD_CTX_md_data - EVP digest routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_MD *EVP_MD_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-                     const char *properties);
-int EVP_MD_up_ref(EVP_MD *md);
-void EVP_MD_free(EVP_MD *md);
-int EVP_MD_get_params(const EVP_MD *digest, OSSL_PARAM params[]);
-const OSSL_PARAM *EVP_MD_gettable_params(const EVP_MD *digest);
-EVP_MD_CTX *EVP_MD_CTX_new(void);
-int EVP_MD_CTX_reset(EVP_MD_CTX *ctx);
-void EVP_MD_CTX_free(EVP_MD_CTX *ctx);
-void EVP_MD_CTX_ctrl(EVP_MD_CTX *ctx, int cmd, int p1, void* p2);
-int EVP_MD_CTX_get_params(EVP_MD_CTX *ctx, OSSL_PARAM params[]);
-int EVP_MD_CTX_set_params(EVP_MD_CTX *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *EVP_MD_settable_ctx_params(const EVP_MD *md);
-const OSSL_PARAM *EVP_MD_gettable_ctx_params(const EVP_MD *md);
-const OSSL_PARAM *EVP_MD_CTX_settable_params(EVP_MD_CTX *ctx);
-const OSSL_PARAM *EVP_MD_CTX_gettable_params(EVP_MD_CTX *ctx);
-void EVP_MD_CTX_set_flags(EVP_MD_CTX *ctx, int flags);
-void EVP_MD_CTX_clear_flags(EVP_MD_CTX *ctx, int flags);
-int EVP_MD_CTX_test_flags(const EVP_MD_CTX *ctx, int flags);
-
-int EVP_Q_digest(OSSL_LIB_CTX *libctx, const char *name, const char *propq,
-                 const void *data, size_t datalen,
-                 unsigned char *md, size_t *mdlen);
-int EVP_Digest(const void *data, size_t count, unsigned char *md,
-               unsigned int *size, const EVP_MD *type, ENGINE *impl);
-int EVP_DigestInit_ex2(EVP_MD_CTX *ctx, const EVP_MD *type,
-                       const OSSL_PARAM params[]);
-int EVP_DigestInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl);
-int EVP_DigestUpdate(EVP_MD_CTX *ctx, const void *d, size_t cnt);
-int EVP_DigestFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s);
-int EVP_DigestFinalXOF(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen);
-int EVP_DigestSqueeze(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen);
-
-EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in);
-int EVP_MD_CTX_copy_ex(EVP_MD_CTX *out, const EVP_MD_CTX *in);
-
-int EVP_DigestInit(EVP_MD_CTX *ctx, const EVP_MD *type);
-int EVP_DigestFinal(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s);
-
-int EVP_MD_CTX_copy(EVP_MD_CTX *out, EVP_MD_CTX *in);
-
-const char *EVP_MD_get0_name(const EVP_MD *md);
-const char *EVP_MD_get0_description(const EVP_MD *md);
-int EVP_MD_is_a(const EVP_MD *md, const char *name);
-int EVP_MD_names_do_all(const EVP_MD *md,
-                        void (*fn)(const char *name, void *data),
-                        void *data);
-const OSSL_PROVIDER *EVP_MD_get0_provider(const EVP_MD *md);
-int EVP_MD_get_type(const EVP_MD *md);
-int EVP_MD_get_pkey_type(const EVP_MD *md);
-int EVP_MD_get_size(const EVP_MD *md);
-int EVP_MD_get_block_size(const EVP_MD *md);
-unsigned long EVP_MD_get_flags(const EVP_MD *md);
-int EVP_MD_xof(const EVP_MD *md);
-
-const EVP_MD *EVP_MD_CTX_get0_md(const EVP_MD_CTX *ctx);
-EVP_MD *EVP_MD_CTX_get1_md(EVP_MD_CTX *ctx);
-const char *EVP_MD_CTX_get0_name(const EVP_MD_CTX *ctx);
-int EVP_MD_CTX_get_size_ex(const EVP_MD_CTX *ctx);
-int EVP_MD_CTX_get_block_size(const EVP_MD_CTX *ctx);
-int EVP_MD_CTX_get_type(const EVP_MD_CTX *ctx);
-void *EVP_MD_CTX_get0_md_data(const EVP_MD_CTX *ctx);
-
-const EVP_MD *EVP_md_null(void);
-
-const EVP_MD *EVP_get_digestbyname(const char *name);
-const EVP_MD *EVP_get_digestbynid(int type);
-const EVP_MD *EVP_get_digestbyobj(const ASN1_OBJECT *o);
-
-EVP_PKEY_CTX *EVP_MD_CTX_get_pkey_ctx(const EVP_MD_CTX *ctx);
-void EVP_MD_CTX_set_pkey_ctx(EVP_MD_CTX *ctx, EVP_PKEY_CTX *pctx);
-
-void EVP_MD_do_all_provided(OSSL_LIB_CTX *libctx,
-                            void (*fn)(EVP_MD *mac, void *arg),
-                            void *arg);
-
-#define EVP_MD_type EVP_MD_get_type
-#define EVP_MD_nid EVP_MD_get_type
-#define EVP_MD_name EVP_MD_get0_name
-#define EVP_MD_pkey_type EVP_MD_get_pkey_type
-#define EVP_MD_size EVP_MD_get_size
-#define EVP_MD_block_size EVP_MD_get_block_size
-#define EVP_MD_flags EVP_MD_get_flags
-#define EVP_MD_CTX_get_size EVP_MD_CTX_get_size_ex
-#define EVP_MD_CTX_size EVP_MD_CTX_get_size_ex
-#define EVP_MD_CTX_block_size EVP_MD_CTX_get_block_size
-#define EVP_MD_CTX_type EVP_MD_CTX_get_type
-#define EVP_MD_CTX_pkey_ctx EVP_MD_CTX_get_pkey_ctx
-#define EVP_MD_CTX_md_data EVP_MD_CTX_get0_md_data
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
const EVP_MD *EVP_MD_CTX_md(const EVP_MD_CTX *ctx);
-
-int (*EVP_MD_CTX_update_fn(EVP_MD_CTX *ctx))(EVP_MD_CTX *ctx,
-                                             const void *data, size_t count);
-
-void EVP_MD_CTX_set_update_fn(EVP_MD_CTX *ctx,
-                              int (*update)(EVP_MD_CTX *ctx,
-                                            const void *data, size_t count));
- -

DESCRIPTION

- -

The EVP digest routines are a high-level interface to message digests, and Extendable Output Functions (XOF).

- -

The EVP_MD type is a structure for digest method implementation.

- -

Each Message digest algorithm (such as SHA256) produces a fixed size output length which is returned when EVP_DigestFinal_ex() is called. Extendable Output Functions (XOF) such as SHAKE256 have a variable sized output length outlen which can be used with either EVP_DigestFinalXOF() or EVP_DigestSqueeze(). EVP_DigestFinal_ex() may also be used for an XOF, but the "xoflen" must be set beforehand (See "PARAMETERS"). Note that EVP_MD_get_size() and EVP_MD_CTX_get_size_ex() behave differently for an XOF.

- -
- -
EVP_MD_fetch()
-
- -

Fetches the digest implementation for the given algorithm from any provider offering it, within the criteria given by the properties. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

The returned value must eventually be freed with EVP_MD_free().

- -

Fetched EVP_MD structures are reference counted.

- -
-
EVP_MD_up_ref()
-
- -

Increments the reference count for an EVP_MD structure.

- -
-
EVP_MD_free()
-
- -

Decrements the reference count for the fetched EVP_MD structure. If the reference count drops to 0 then the structure is freed. If the argument is NULL, nothing is done.

- -
-
EVP_MD_CTX_new()
-
- -

Allocates and returns a digest context.

- -
-
EVP_MD_CTX_reset()
-
- -

Resets the digest context ctx. This can be used to reuse an already existing context.

- -
-
EVP_MD_CTX_free()
-
- -

Cleans up digest context ctx and frees up the space allocated to it. If the argument is NULL, nothing is done.

- -
-
EVP_MD_CTX_ctrl()
-
- -

This is a legacy method. EVP_MD_CTX_set_params() and EVP_MD_CTX_get_params() is the mechanism that should be used to set and get parameters that are used by providers.

- -

Performs digest-specific control actions on context ctx. The control command is indicated in cmd and any additional arguments in p1 and p2. EVP_MD_CTX_ctrl() must be called after EVP_DigestInit_ex2(). Other restrictions may apply depending on the control type and digest implementation.

- -

If this function happens to be used with a fetched EVP_MD, it will translate the controls that are known to OpenSSL into OSSL_PARAM(3) parameters with keys defined by OpenSSL and call EVP_MD_CTX_get_params() or EVP_MD_CTX_set_params() as is appropriate for each control command.

- -

See "CONTROLS" below for more information, including what translations are being done.

- -
-
EVP_MD_get_params()
-
- -

Retrieves the requested list of params from a MD md. See "PARAMETERS" below for more information.

- -
-
EVP_MD_CTX_get_params()
-
- -

Retrieves the requested list of params from a MD context ctx. See "PARAMETERS" below for more information.

- -
-
EVP_MD_CTX_set_params()
-
- -

Sets the list of params into a MD context ctx. See "PARAMETERS" below for more information.

- -
-
EVP_MD_gettable_params()
-
- -

Get a constant OSSL_PARAM(3) array that describes the retrievable parameters that can be used with EVP_MD_get_params().

- -
-
EVP_MD_gettable_ctx_params(), EVP_MD_CTX_gettable_params()
-
- -

Get a constant OSSL_PARAM(3) array that describes the retrievable parameters that can be used with EVP_MD_CTX_get_params(). EVP_MD_gettable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_MD_CTX_gettable_params() returns the parameters that can be retrieved in the context's current state.

- -
-
EVP_MD_settable_ctx_params(), EVP_MD_CTX_settable_params()
-
- -

Get a constant OSSL_PARAM(3) array that describes the settable parameters that can be used with EVP_MD_CTX_set_params(). EVP_MD_settable_ctx_params() returns the parameters that can be set from the algorithm, whereas EVP_MD_CTX_settable_params() returns the parameters that can be set in the context's current state.

- -
-
EVP_MD_CTX_set_flags(), EVP_MD_CTX_clear_flags(), EVP_MD_CTX_test_flags()
-
- -

Sets, clears and tests ctx flags. See "FLAGS" below for more information.

- -
-
EVP_Q_digest() is a quick one-shot digest function.
-
- -

It hashes datalen bytes of data at data using the digest algorithm name, which is fetched using the optional libctx and propq parameters. The digest value is placed in md and its length is written at mdlen if the pointer is not NULL. At most EVP_MAX_MD_SIZE bytes will be written.

- -
-
EVP_Digest()
-
- -

A wrapper around the Digest Init_ex, Update and Final_ex functions. Hashes count bytes of data at data using a digest type from ENGINE impl. The digest value is placed in md and its length is written at size if the pointer is not NULL. At most EVP_MAX_MD_SIZE bytes will be written. If impl is NULL the default implementation of digest type is used.

- -
-
EVP_DigestInit_ex2()
-
- -

Sets up digest context ctx to use a digest type. type is typically supplied by a function such as EVP_sha1(), or a value explicitly fetched with EVP_MD_fetch().

- -

The parameters params are set on the context after initialisation.

- -

The type parameter can be NULL if ctx has been already initialized with another EVP_DigestInit_ex() call and has not been reset with EVP_MD_CTX_reset().

- -
-
EVP_DigestInit_ex()
-
- -

Sets up digest context ctx to use a digest type. type is typically supplied by a function such as EVP_sha1(), or a value explicitly fetched with EVP_MD_fetch().

- -

If impl is non-NULL, its implementation of the digest type is used if there is one, and if not, the default implementation is used.

- -

The type parameter can be NULL if ctx has been already initialized with another EVP_DigestInit_ex() call and has not been reset with EVP_MD_CTX_reset().

- -
-
EVP_DigestUpdate()
-
- -

Hashes cnt bytes of data at d into the digest context ctx. This function can be called several times on the same ctx to hash additional data.

- -
-
EVP_DigestFinal_ex()
-
- -

Retrieves the digest value from ctx and places it in md. If the s parameter is not NULL then the number of bytes of data written (i.e. the length of the digest) will be written to the integer at s, at most EVP_MAX_MD_SIZE bytes will be written unless the digest implementation allows changing the digest size and it is set to a larger value by the application. After calling EVP_DigestFinal_ex() no additional calls to EVP_DigestUpdate() can be made, but EVP_DigestInit_ex2() can be called to initialize a new digest operation.

- -
-
EVP_DigestFinalXOF()
-
- -

Interfaces to extendable-output functions, XOFs, such as SHAKE128 and SHAKE256. It retrieves the digest value from ctx and places it in outlen-sized out. After calling this function no additional calls to EVP_DigestUpdate() can be made, but EVP_DigestInit_ex2() can be called to initialize a new operation. EVP_DigestFinalXOF() may only be called once

- -
-
EVP_DigestSqueeze()
-
- -

Similar to EVP_DigestFinalXOF() but allows multiple calls to be made to squeeze variable length output data. EVP_DigestFinalXOF() should not be called after this.

- -
-
EVP_MD_CTX_dup()
-
- -

Can be used to duplicate the message digest state from in. This is useful to avoid multiple EVP_MD_fetch() calls or if large amounts of data are to be hashed which only differ in the last few bytes.

- -
-
EVP_MD_CTX_copy_ex()
-
- -

Can be used to copy the message digest state from in to out. This is useful if large amounts of data are to be hashed which only differ in the last few bytes.

- -
-
EVP_DigestInit()
-
- -

Behaves in the same way as EVP_DigestInit_ex2() except it doesn't set any parameters and calls EVP_MD_CTX_reset() so it cannot be used with an type of NULL.

- -
-
EVP_DigestFinal()
-
- -

Similar to EVP_DigestFinal_ex() except after computing the digest the digest context ctx is automatically cleaned up with EVP_MD_CTX_reset().

- -
-
EVP_MD_CTX_copy()
-
- -

Similar to EVP_MD_CTX_copy_ex() except the destination out does not have to be initialized.

- -
-
EVP_MD_is_a()
-
- -

Returns 1 if md is an implementation of an algorithm that's identifiable with name, otherwise 0.

- -

If md is a legacy digest (it's the return value from the likes of EVP_sha256() rather than the result of an EVP_MD_fetch()), only cipher names registered with the default library context (see OSSL_LIB_CTX(3)) will be considered.

- -
-
EVP_MD_xof()
-
- -

Returns 1 if md is an Extendable-output Function (XOF) otherwise it returns 0. SHAKE128 and SHAKE256 are XOF functions. It returns 0 for BLAKE2B algorithms.

- -
-
EVP_MD_get0_name(), EVP_MD_CTX_get0_name()
-
- -

Return the name of the given message digest. For fetched message digests with multiple names, only one of them is returned; it's recommended to use EVP_MD_names_do_all() instead.

- -
-
EVP_MD_names_do_all()
-
- -

Traverses all names for the md, and calls fn with each name and data. This is only useful with fetched EVP_MDs.

- -
-
EVP_MD_get0_description()
-
- -

Returns a description of the digest, meant for display and human consumption. The description is at the discretion of the digest implementation.

- -
-
EVP_MD_get0_provider()
-
- -

Returns an OSSL_PROVIDER pointer to the provider that implements the given EVP_MD.

- -
-
EVP_MD_get_size()
-
- -

Return the size of the message digest when passed an EVP_MD, i.e. the size of the hash. A negative value or 0 can occur for invalid size. For an XOF with no default size this returns 0.

- -
-
EVP_MD_CTX_get_size_ex(), EVP_MD_CTX_get_size()
-
- -

For a normal digest this is the same as EVP_MD_get_size(). For an XOF this returns the "xoflen" if it has been set, otherwise it returns 0.

- -
-
EVP_MD_get_block_size(), EVP_MD_CTX_get_block_size()
-
- -

Return the block size of the message digest when passed an EVP_MD or an EVP_MD_CTX structure.

- -
-
EVP_MD_get_type(), EVP_MD_CTX_get_type()
-
- -

Return the NID of the OBJECT IDENTIFIER representing the given message digest when passed an EVP_MD structure. For example, EVP_MD_get_type(EVP_sha1()) returns NID_sha1. This function is normally used when setting ASN1 OIDs.

- -
-
EVP_MD_CTX_get0_md_data()
-
- -

Return the digest method private data for the passed EVP_MD_CTX. The space is allocated by OpenSSL and has the size originally set with EVP_MD_meth_set_app_datasize().

- -
-
EVP_MD_CTX_get0_md(), EVP_MD_CTX_get1_md()
-
- -

EVP_MD_CTX_get0_md() returns the EVP_MD structure corresponding to the passed EVP_MD_CTX. This will be the same EVP_MD object originally passed to EVP_DigestInit_ex2() (or other similar function) when the EVP_MD_CTX was first initialised. Note that where explicit fetch is in use (see EVP_MD_fetch(3)) the value returned from this function will not have its reference count incremented and therefore it should not be used after the EVP_MD_CTX is freed. EVP_MD_CTX_get1_md() is the same except the ownership is passed to the caller and is from the passed EVP_MD_CTX.

- -
-
EVP_MD_CTX_set_update_fn()
-
- -

Sets the update function for ctx to update. This is the function that is called by EVP_DigestUpdate(). If not set, the update function from the EVP_MD type specified at initialization is used.

- -
-
EVP_MD_CTX_update_fn()
-
- -

Returns the update function for ctx.

- -
-
EVP_MD_get_flags()
-
- -

Returns the md flags. Note that these are different from the EVP_MD_CTX ones. See EVP_MD_meth_set_flags(3) for more information.

- -
-
EVP_MD_get_pkey_type()
-
- -

Returns the NID of the public key signing algorithm associated with this digest. For example EVP_sha1() is associated with RSA so this will return NID_sha1WithRSAEncryption. Since digests and signature algorithms are no longer linked this function is only retained for compatibility reasons.

- -
-
EVP_md_null()
-
- -

A "null" message digest that does nothing: i.e. the hash it returns is of zero length.

- -
-
EVP_get_digestbyname(), EVP_get_digestbynid(), EVP_get_digestbyobj()
-
- -

Returns an EVP_MD structure when passed a digest name, a digest NID or an ASN1_OBJECT structure respectively.

- -

The EVP_get_digestbyname() function is present for backwards compatibility with OpenSSL prior to version 3 and is different to the EVP_MD_fetch() function since it does not attempt to "fetch" an implementation of the cipher. Additionally, it only knows about digests that are built-in to OpenSSL and have an associated NID. Similarly EVP_get_digestbynid() and EVP_get_digestbyobj() also return objects without an associated implementation.

- -

When the digest objects returned by these functions are used (such as in a call to EVP_DigestInit_ex()) an implementation of the digest will be implicitly fetched from the loaded providers. This fetch could fail if no suitable implementation is available. Use EVP_MD_fetch() instead to explicitly fetch the algorithm and an associated implementation from a provider.

- -

See "ALGORITHM FETCHING" in crypto(7) for more information about fetching.

- -

The digest objects returned from these functions do not need to be freed with EVP_MD_free().

- -
-
EVP_MD_CTX_get_pkey_ctx()
-
- -

Returns the EVP_PKEY_CTX assigned to ctx. The returned pointer should not be freed by the caller.

- -
-
EVP_MD_CTX_set_pkey_ctx()
-
- -

Assigns an EVP_PKEY_CTX to EVP_MD_CTX. This is usually used to provide a customized EVP_PKEY_CTX to EVP_DigestSignInit(3) or EVP_DigestVerifyInit(3). The pctx passed to this function should be freed by the caller. A NULL pctx pointer is also allowed to clear the EVP_PKEY_CTX assigned to ctx. In such case, freeing the cleared EVP_PKEY_CTX or not depends on how the EVP_PKEY_CTX is created.

- -
-
EVP_MD_do_all_provided()
-
- -

Traverses all messages digests implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -
-
- -

PARAMETERS

- -

See OSSL_PARAM(3) for information about passing parameters.

- -

EVP_MD_CTX_set_params() and EVP_MD_CTX_get_params() can be used with the following OSSL_PARAM keys:

- -
- -
"xoflen" (OSSL_DIGEST_PARAM_XOFLEN) <unsigned integer>
-
- -

Sets or gets the digest length for extendable output functions. The value should not exceed what can be given using a size_t. It may be used by SHAKE-128 and SHAKE-256 to set the output length used by EVP_DigestFinal_ex() and EVP_DigestFinal().

- -
-
"size" (OSSL_DIGEST_PARAM_SIZE) <unsigned integer>
-
- -

Sets or gets a fixed digest length. The value should not exceed what can be given using a size_t. It may be used by BLAKE2B-512 to set the output length used by EVP_DigestFinal_ex() and EVP_DigestFinal().

- -
-
- -

EVP_MD_CTX_set_params() can be used with the following OSSL_PARAM keys:

- -
- -
"pad-type" (OSSL_DIGEST_PARAM_PAD_TYPE) <unsigned integer>
-
- -

Sets the padding type. It is used by the MDC2 algorithm.

- -
-
- -

EVP_MD_CTX_get_params() can be used with the following OSSL_PARAM keys:

- -
- -
"micalg" (OSSL_DIGEST_PARAM_MICALG) <UTF8 string>.
-
- -

Gets the digest Message Integrity Check algorithm string. This is used when creating S/MIME multipart/signed messages, as specified in RFC 3851. It may be used by external engines or providers.

- -
-
- -

CONTROLS

- -

EVP_MD_CTX_ctrl() can be used to send the following standard controls:

- -
- -
EVP_MD_CTRL_MICALG
-
- -

Gets the digest Message Integrity Check algorithm string. This is used when creating S/MIME multipart/signed messages, as specified in RFC 3851. The string value is written to p2.

- -

When used with a fetched EVP_MD, EVP_MD_CTX_get_params() gets called with an OSSL_PARAM(3) item with the key "micalg" (OSSL_DIGEST_PARAM_MICALG).

- -
-
EVP_MD_CTRL_XOF_LEN
-
- -

This control sets the digest length for extendable output functions to p1. Sending this control directly should not be necessary, the use of EVP_DigestFinalXOF() is preferred. Currently used by SHAKE algorithms.

- -

When used with a fetched EVP_MD, EVP_MD_CTX_get_params() gets called with an OSSL_PARAM(3) item with the key "xoflen" (OSSL_DIGEST_PARAM_XOFLEN).

- -
-
- -

FLAGS

- -

EVP_MD_CTX_set_flags(), EVP_MD_CTX_clear_flags() and EVP_MD_CTX_test_flags() can be used the manipulate and test these EVP_MD_CTX flags:

- -
- -
EVP_MD_CTX_FLAG_ONESHOT
-
- -

This flag instructs the digest to optimize for one update only, if possible.

- -
-
EVP_MD_CTX_FLAG_CLEANED
-
- -

This flag is for internal use only and must not be used in user code.

- -
-
EVP_MD_CTX_FLAG_REUSE
-
- -

This flag is for internal use only and must not be used in user code.

- -
-
EVP_MD_CTX_FLAG_NO_INIT
-
- -

This flag instructs EVP_DigestInit() and similar not to initialise the implementation specific data.

- -
-
EVP_MD_CTX_FLAG_FINALISE
-
- -

Some functions such as EVP_DigestSign only finalise copies of internal contexts so additional data can be included after the finalisation call. This is inefficient if this functionality is not required, and can be disabled with this flag.

- -
-
- -

RETURN VALUES

- -
- -
EVP_MD_fetch()
-
- -

Returns a pointer to a EVP_MD for success or NULL for failure.

- -
-
EVP_MD_up_ref()
-
- -

Returns 1 for success or 0 for failure.

- -
-
EVP_Q_digest(), EVP_Digest(), EVP_DigestInit_ex2(), EVP_DigestInit_ex(), EVP_DigestInit(), EVP_DigestUpdate(), EVP_DigestFinal_ex(), EVP_DigestFinalXOF(), and EVP_DigestFinal()
-
- -

return 1 for success and 0 for failure.

- -
-
EVP_MD_CTX_ctrl()
-
- -

Returns 1 if successful or 0 for failure.

- -
-
EVP_MD_CTX_set_params(), EVP_MD_CTX_get_params()
-
- -

Returns 1 if successful or 0 for failure.

- -
-
EVP_MD_CTX_settable_params(), EVP_MD_CTX_gettable_params()
-
- -

Return an array of constant OSSL_PARAM(3)s, or NULL if there is none to get.

- -
-
EVP_MD_CTX_dup()
-
- -

Returns a new EVP_MD_CTX if successful or NULL on failure.

- -
-
EVP_MD_CTX_copy_ex()
-
- -

Returns 1 if successful or 0 for failure.

- -
-
EVP_MD_get_type(), EVP_MD_get_pkey_type()
-
- -

Returns the NID of the corresponding OBJECT IDENTIFIER or NID_undef if none exists.

- -
-
EVP_MD_get_size(), EVP_MD_get_block_size(), EVP_MD_CTX_get_size(), EVP_MD_CTX_get_block_size()
-
- -

Returns the digest or block size in bytes or -1 for failure.

- -
-
EVP_md_null()
-
- -

Returns a pointer to the EVP_MD structure of the "null" message digest.

- -
-
EVP_get_digestbyname(), EVP_get_digestbynid(), EVP_get_digestbyobj()
-
- -

Returns either an EVP_MD structure or NULL if an error occurs.

- -
-
EVP_MD_CTX_set_pkey_ctx()
-
- -

This function has no return value.

- -
-
EVP_MD_names_do_all()
-
- -

Returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -
-
- -

NOTES

- -

The EVP interface to message digests should almost always be used in preference to the low-level interfaces. This is because the code then becomes transparent to the digest used and much more flexible.

- -

New applications should use the SHA-2 (such as EVP_sha256(3)) or the SHA-3 digest algorithms (such as EVP_sha3_512(3)). The other digest algorithms are still in common use.

- -

For most applications the impl parameter to EVP_DigestInit_ex() will be set to NULL to use the default digest implementation.

- -

Ignoring failure returns of EVP_DigestInit_ex(), EVP_DigestInit_ex2(), or EVP_DigestInit() can lead to undefined behavior on subsequent calls updating or finalizing the EVP_MD_CTX such as the EVP_DigestUpdate() or EVP_DigestFinal() functions. The only valid calls on the EVP_MD_CTX when initialization fails are calls that attempt another initialization of the context or release the context.

- -

The functions EVP_DigestInit(), EVP_DigestFinal() and EVP_MD_CTX_copy() are obsolete but are retained to maintain compatibility with existing code. New applications should use EVP_DigestInit_ex(), EVP_DigestFinal_ex() and EVP_MD_CTX_copy_ex() because they can efficiently reuse a digest context instead of initializing and cleaning it up on each call and allow non default implementations of digests to be specified.

- -

If digest contexts are not cleaned up after use, memory leaks will occur.

- -

EVP_MD_CTX_get0_name(), EVP_MD_CTX_get_size(), EVP_MD_CTX_get_block_size(), EVP_MD_CTX_get_type(), EVP_get_digestbynid() and EVP_get_digestbyobj() are defined as macros.

- -

EVP_MD_CTX_ctrl() sends commands to message digests for additional configuration or control.

- -

EXAMPLES

- -

This example digests the data "Test Message\n" and "Hello World\n", using the digest name passed on the command line.

- -
#include <stdio.h>
-#include <string.h>
-#include <openssl/evp.h>
-
-int main(int argc, char *argv[])
-{
-    EVP_MD_CTX *mdctx;
-    const EVP_MD *md;
-    char mess1[] = "Test Message\n";
-    char mess2[] = "Hello World\n";
-    unsigned char md_value[EVP_MAX_MD_SIZE];
-    unsigned int md_len, i;
-
-    if (argv[1] == NULL) {
-        printf("Usage: mdtest digestname\n");
-        exit(1);
-    }
-
-    md = EVP_get_digestbyname(argv[1]);
-    if (md == NULL) {
-        printf("Unknown message digest %s\n", argv[1]);
-        exit(1);
-    }
-
-    mdctx = EVP_MD_CTX_new();
-    if (!EVP_DigestInit_ex2(mdctx, md, NULL)) {
-        printf("Message digest initialization failed.\n");
-        EVP_MD_CTX_free(mdctx);
-        exit(1);
-    }
-    if (!EVP_DigestUpdate(mdctx, mess1, strlen(mess1))) {
-        printf("Message digest update failed.\n");
-        EVP_MD_CTX_free(mdctx);
-        exit(1);
-    }
-    if (!EVP_DigestUpdate(mdctx, mess2, strlen(mess2))) {
-        printf("Message digest update failed.\n");
-        EVP_MD_CTX_free(mdctx);
-        exit(1);
-    }
-    if (!EVP_DigestFinal_ex(mdctx, md_value, &md_len)) {
-        printf("Message digest finalization failed.\n");
-        EVP_MD_CTX_free(mdctx);
-        exit(1);
-    }
-    EVP_MD_CTX_free(mdctx);
-
-    printf("Digest is: ");
-    for (i = 0; i < md_len; i++)
-        printf("%02x", md_value[i]);
-    printf("\n");
-
-    exit(0);
-}
- -

SEE ALSO

- -

EVP_MD_meth_new(3), openssl-dgst(1), evp(7), OSSL_PROVIDER(3), OSSL_PARAM(3), property(7), "ALGORITHM FETCHING" in crypto(7), provider-digest(7), life_cycle-digest(7)

- -

The full list of digest algorithms are provided below.

- -

EVP_blake2b512(3), EVP_md2(3), EVP_md4(3), EVP_md5(3), EVP_mdc2(3), EVP_ripemd160(3), EVP_sha1(3), EVP_sha224(3), EVP_sha3_224(3), EVP_sm3(3), EVP_whirlpool(3)

- -

HISTORY

- -

The EVP_MD_CTX_create() and EVP_MD_CTX_destroy() functions were renamed to EVP_MD_CTX_new() and EVP_MD_CTX_free() in OpenSSL 1.1.0, respectively.

- -

The link between digests and signing algorithms was fixed in OpenSSL 1.0 and later, so now EVP_sha1() can be used with RSA and DSA.

- -

The EVP_dss1() function was removed in OpenSSL 1.1.0.

- -

The EVP_MD_CTX_set_pkey_ctx() function was added in OpenSSL 1.1.1.

- -

The EVP_Q_digest(), EVP_DigestInit_ex2(), EVP_MD_fetch(), EVP_MD_free(), EVP_MD_up_ref(), EVP_MD_get_params(), EVP_MD_CTX_set_params(), EVP_MD_CTX_get_params(), EVP_MD_gettable_params(), EVP_MD_gettable_ctx_params(), EVP_MD_settable_ctx_params(), EVP_MD_CTX_settable_params() and EVP_MD_CTX_gettable_params() functions were added in OpenSSL 3.0.

- -

The EVP_MD_type(), EVP_MD_nid(), EVP_MD_name(), EVP_MD_pkey_type(), EVP_MD_size(), EVP_MD_block_size(), EVP_MD_flags(), EVP_MD_CTX_size(), EVP_MD_CTX_block_size(), EVP_MD_CTX_type(), and EVP_MD_CTX_md_data() functions were renamed to include get or get0 in their names in OpenSSL 3.0, respectively. The old names are kept as non-deprecated alias macros.

- -

The EVP_MD_CTX_md() function was deprecated in OpenSSL 3.0; use EVP_MD_CTX_get0_md() instead. EVP_MD_CTX_update_fn() and EVP_MD_CTX_set_update_fn() were deprecated in OpenSSL 3.0.

- -

The EVP_MD_CTX_dup() function was added in OpenSSL 3.1.

- -

The EVP_DigestSqueeze() function was added in OpenSSL 3.3.

- -

The EVP_MD_CTX_get_size_ex() and EVP_xof() functions were added in OpenSSL 3.4. The macros EVP_MD_CTX_get_size() and EVP_MD_CTX_size were changed in OpenSSL 3.4 to be aliases for EVP_MD_CTX_get_size_ex(), previously they were aliases for EVP_MD_get_size which returned a constant value. This is required for XOF digests since they do not have a fixed size.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_DigestSignInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_DigestSignInit.html deleted file mode 100644 index 2a07e06f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_DigestSignInit.html +++ /dev/null @@ -1,179 +0,0 @@ - - - - -EVP_DigestSignInit - - - - - - - - - - -

NAME

- -

EVP_DigestSignInit_ex, EVP_DigestSignInit, EVP_DigestSignUpdate, EVP_DigestSignFinal, EVP_DigestSign - EVP signing functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_DigestSignInit_ex(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
-                          const char *mdname, OSSL_LIB_CTX *libctx,
-                          const char *props, EVP_PKEY *pkey,
-                          const OSSL_PARAM params[]);
-int EVP_DigestSignInit(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
-                       const EVP_MD *type, ENGINE *e, EVP_PKEY *pkey);
-int EVP_DigestSignUpdate(EVP_MD_CTX *ctx, const void *d, size_t cnt);
-int EVP_DigestSignFinal(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen);
-
-int EVP_DigestSign(EVP_MD_CTX *ctx, unsigned char *sig,
-                   size_t *siglen, const unsigned char *tbs,
-                   size_t tbslen);
- -

DESCRIPTION

- -

The EVP signature routines are a high-level interface to digital signatures. Input data is digested first before the signing takes place.

- -

EVP_DigestSignInit_ex() sets up signing context ctx to use a digest with the name mdname and private key pkey. The name of the digest to be used is passed to the provider of the signature algorithm in use. How that provider interprets the digest name is provider specific. The provider may implement that digest directly itself or it may (optionally) choose to fetch it (which could result in a digest from a different provider being selected). If the provider supports fetching the digest then it may use the props argument for the properties to be used during the fetch. Finally, the passed parameters params, if not NULL, are set on the context before returning.

- -

The pkey algorithm is used to fetch a EVP_SIGNATURE method implicitly, to be used for the actual signing. See "Implicit fetch" in provider(7) for more information about implicit fetches.

- -

The OpenSSL default and legacy providers support fetching digests and can fetch those digests from any available provider. The OpenSSL FIPS provider also supports fetching digests but will only fetch digests that are themselves implemented inside the FIPS provider.

- -

ctx must be created with EVP_MD_CTX_new() before calling this function. If pctx is not NULL, the EVP_PKEY_CTX of the signing operation will be written to *pctx: this can be used to set alternative signing options. Note that any existing value in *pctx is overwritten. The EVP_PKEY_CTX value returned must not be freed directly by the application if ctx is not assigned an EVP_PKEY_CTX value before being passed to EVP_DigestSignInit_ex() (which means the EVP_PKEY_CTX is created inside EVP_DigestSignInit_ex() and it will be freed automatically when the EVP_MD_CTX is freed). If the EVP_PKEY_CTX to be used is created by EVP_DigestSignInit_ex then it will use the OSSL_LIB_CTX specified in libctx and the property query string specified in props.

- -

The digest mdname may be NULL if the signing algorithm supports it. The props argument can always be NULL.

- -

No EVP_PKEY_CTX will be created by EVP_DigestSignInit_ex() if the passed ctx has already been assigned one via EVP_MD_CTX_set_pkey_ctx(3). See also SM2(7).

- -

Only EVP_PKEY types that support signing can be used with these functions. This includes MAC algorithms where the MAC generation is considered as a form of "signing". Built-in EVP_PKEY types supported by these functions are CMAC, Poly1305, DSA, ECDSA, HMAC, RSA, SipHash, Ed25519 and Ed448.

- -

Not all digests can be used for all key types. The following combinations apply.

- -
- -
DSA
-
- -

Supports SHA1, SHA224, SHA256, SHA384 and SHA512

- -
-
ECDSA
-
- -

Supports SHA1, SHA224, SHA256, SHA384, SHA512 and SM3

- -
-
RSA with no padding
-
- -

Supports no digests (the digest type must be NULL)

- -
-
RSA with X931 padding
-
- -

Supports SHA1, SHA256, SHA384 and SHA512

- -
-
All other RSA padding types
-
- -

Support SHA1, SHA224, SHA256, SHA384, SHA512, MD5, MD5_SHA1, MD2, MD4, MDC2, SHA3-224, SHA3-256, SHA3-384, SHA3-512

- -
-
Ed25519 and Ed448
-
- -

Support no digests (the digest type must be NULL)

- -
-
HMAC
-
- -

Supports any digest

- -
-
CMAC, Poly1305 and SipHash
-
- -

Will ignore any digest provided.

- -
-
- -

If RSA-PSS is used and restrictions apply then the digest must match.

- -

EVP_DigestSignInit() works in the same way as EVP_DigestSignInit_ex() except that the mdname parameter will be inferred from the supplied digest type, and props will be NULL. Where supplied the ENGINE e will be used for the signing and digest algorithm implementations. e may be NULL.

- -

EVP_DigestSignUpdate() hashes cnt bytes of data at d into the signature context ctx. This function can be called several times on the same ctx to include additional data.

- -

Unless sig is NULL EVP_DigestSignFinal() signs the data in ctx and places the signature in sig. Otherwise the maximum necessary size of the output buffer is written to the siglen parameter. If sig is not NULL then before the call the siglen parameter should contain the length of the sig buffer. If the call is successful the signature is written to sig and the amount of data written to siglen.

- -

EVP_DigestSign() is similar to a single call to EVP_DigestSignUpdate() and EVP_DigestSignFinal(). Unless sig is NULL, EVP_DigestSign() signs the data tbs of length tbslen bytes and places the signature in a buffer sig of size siglen. If sig is NULL, the maximum necessary size of the signature buffer is written to the siglen parameter.

- -

RETURN VALUES

- -

EVP_DigestSignInit(), EVP_DigestSignUpdate(), EVP_DigestSignFinal() and EVP_DigestSign() return 1 for success and 0 for failure.

- -

The error codes can be obtained from ERR_get_error(3).

- -

NOTES

- -

The EVP interface to digital signatures should almost always be used in preference to the low-level interfaces. This is because the code then becomes transparent to the algorithm used and much more flexible.

- -

EVP_DigestSign() is a one shot operation which signs a single block of data in one function. For algorithms that support streaming it is equivalent to calling EVP_DigestSignUpdate() and EVP_DigestSignFinal(). For algorithms which do not support streaming (e.g. PureEdDSA) it is the only way to sign data.

- -

In previous versions of OpenSSL there was a link between message digest types and public key algorithms. This meant that "clone" digests such as EVP_dss1() needed to be used to sign using SHA1 and DSA. This is no longer necessary and the use of clone digest is now discouraged.

- -

For some key types and parameters the random number generator must be seeded. If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

The call to EVP_DigestSignFinal() internally finalizes a copy of the digest context. This means that calls to EVP_DigestSignUpdate() and EVP_DigestSignFinal() can be called later to digest and sign additional data. Applications may disable this behavior by setting the EVP_MD_CTX_FLAG_FINALISE context flag via EVP_MD_CTX_set_flags(3).

- -

Note that not all providers support continuation, in case the selected provider does not allow to duplicate contexts EVP_DigestSignFinal() will finalize the digest context and attempting to process additional data via EVP_DigestSignUpdate() will result in an error.

- -

EVP_DigestSignInit() and EVP_DigestSignInit_ex() functions can be called multiple times on a context and the parameters set by previous calls should be preserved if the pkey parameter is NULL. The call then just resets the state of the ctx.

- -

EVP_DigestSign() can not be called again, once a signature is generated (by passing sig as non NULL), unless the EVP_MD_CTX is reinitialised by calling EVP_DigestSignInit_ex().

- -

Ignoring failure returns of EVP_DigestSignInit() and EVP_DigestSignInit_ex() functions can lead to subsequent undefined behavior when calling EVP_DigestSignUpdate(), EVP_DigestSignFinal(), or EVP_DigestSign().

- -

The use of EVP_PKEY_get_size() with these functions is discouraged because some signature operations may have a signature length which depends on the parameters set. As a result EVP_PKEY_get_size() would have to return a value which indicates the maximum possible signature for any set of parameters.

- -

SEE ALSO

- -

EVP_DigestVerifyInit(3), EVP_DigestInit(3), evp(7), HMAC(3), MD2(3), MD5(3), MDC2(3), RIPEMD160(3), SHA1(3), openssl-dgst(1), RAND(7)

- -

HISTORY

- -

EVP_DigestSignInit(), EVP_DigestSignUpdate() and EVP_DigestSignFinal() were added in OpenSSL 1.0.0.

- -

EVP_DigestSignInit_ex() was added in OpenSSL 3.0.

- -

EVP_DigestSignUpdate() was converted from a macro to a function in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_DigestVerifyInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_DigestVerifyInit.html deleted file mode 100644 index da7fc0a5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_DigestVerifyInit.html +++ /dev/null @@ -1,174 +0,0 @@ - - - - -EVP_DigestVerifyInit - - - - - - - - - - -

NAME

- -

EVP_DigestVerifyInit_ex, EVP_DigestVerifyInit, EVP_DigestVerifyUpdate, EVP_DigestVerifyFinal, EVP_DigestVerify - EVP signature verification functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_DigestVerifyInit_ex(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
-                            const char *mdname, OSSL_LIB_CTX *libctx,
-                            const char *props, EVP_PKEY *pkey,
-                            const OSSL_PARAM params[]);
-int EVP_DigestVerifyInit(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
-                         const EVP_MD *type, ENGINE *e, EVP_PKEY *pkey);
-int EVP_DigestVerifyUpdate(EVP_MD_CTX *ctx, const void *d, size_t cnt);
-int EVP_DigestVerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sig,
-                          size_t siglen);
-int EVP_DigestVerify(EVP_MD_CTX *ctx, const unsigned char *sig,
-                     size_t siglen, const unsigned char *tbs, size_t tbslen);
- -

DESCRIPTION

- -

The EVP signature routines are a high-level interface to digital signatures. Input data is digested first before the signature verification takes place.

- -

EVP_DigestVerifyInit_ex() sets up verification context ctx to use a digest with the name mdname and public key pkey. The name of the digest to be used is passed to the provider of the signature algorithm in use. How that provider interprets the digest name is provider specific. The provider may implement that digest directly itself or it may (optionally) choose to fetch it (which could result in a digest from a different provider being selected). If the provider supports fetching the digest then it may use the props argument for the properties to be used during the fetch. Finally, the passed parameters params, if not NULL, are set on the context before returning.

- -

The pkey algorithm is used to fetch a EVP_SIGNATURE method implicitly, to be used for the actual signing. See "Implicit fetch" in provider(7) for more information about implicit fetches.

- -

The OpenSSL default and legacy providers support fetching digests and can fetch those digests from any available provider. The OpenSSL FIPS provider also supports fetching digests but will only fetch digests that are themselves implemented inside the FIPS provider.

- -

ctx must be created with EVP_MD_CTX_new() before calling this function. If pctx is not NULL, the EVP_PKEY_CTX of the verification operation will be written to *pctx: this can be used to set alternative verification options. Note that any existing value in *pctx is overwritten. The EVP_PKEY_CTX value returned must not be freed directly by the application if ctx is not assigned an EVP_PKEY_CTX value before being passed to EVP_DigestVerifyInit_ex() (which means the EVP_PKEY_CTX is created inside EVP_DigestVerifyInit_ex() and it will be freed automatically when the EVP_MD_CTX is freed). If the EVP_PKEY_CTX to be used is created by EVP_DigestVerifyInit_ex then it will use the OSSL_LIB_CTX specified in libctx and the property query string specified in props.

- -

No EVP_PKEY_CTX will be created by EVP_DigestVerifyInit_ex() if the passed ctx has already been assigned one via EVP_MD_CTX_set_pkey_ctx(3). See also SM2(7).

- -

Not all digests can be used for all key types. The following combinations apply.

- -
- -
DSA
-
- -

Supports SHA1, SHA224, SHA256, SHA384 and SHA512

- -
-
ECDSA
-
- -

Supports SHA1, SHA224, SHA256, SHA384, SHA512 and SM3

- -
-
RSA with no padding
-
- -

Supports no digests (the digest type must be NULL)

- -
-
RSA with X931 padding
-
- -

Supports SHA1, SHA256, SHA384 and SHA512

- -
-
All other RSA padding types
-
- -

Support SHA1, SHA224, SHA256, SHA384, SHA512, MD5, MD5_SHA1, MD2, MD4, MDC2, SHA3-224, SHA3-256, SHA3-384, SHA3-512

- -
-
Ed25519 and Ed448
-
- -

Support no digests (the digest type must be NULL)

- -
-
HMAC
-
- -

Supports any digest

- -
-
CMAC, Poly1305 and Siphash
-
- -

Will ignore any digest provided.

- -
-
- -

If RSA-PSS is used and restrictions apply then the digest must match.

- -

EVP_DigestVerifyInit() works in the same way as EVP_DigestVerifyInit_ex() except that the mdname parameter will be inferred from the supplied digest type, and props will be NULL. Where supplied the ENGINE e will be used for the signature verification and digest algorithm implementations. e may be NULL.

- -

EVP_DigestVerifyUpdate() hashes cnt bytes of data at d into the verification context ctx. This function can be called several times on the same ctx to include additional data.

- -

EVP_DigestVerifyFinal() verifies the data in ctx against the signature in sig of length siglen.

- -

EVP_DigestVerify() verifies tbslen bytes at tbs against the signature in sig of length siglen.

- -

RETURN VALUES

- -

EVP_DigestVerifyInit() and EVP_DigestVerifyUpdate() return 1 for success and 0 for failure.

- -

EVP_DigestVerifyFinal() and EVP_DigestVerify() return 1 for success; any other value indicates failure. A return value of zero indicates that the signature did not verify successfully (that is, tbs did not match the original data or the signature had an invalid form), while other values indicate a more serious error (and sometimes also indicate an invalid signature form).

- -

The error codes can be obtained from ERR_get_error(3).

- -

NOTES

- -

The EVP interface to digital signatures should almost always be used in preference to the low-level interfaces. This is because the code then becomes transparent to the algorithm used and much more flexible.

- -

EVP_DigestVerify() is a one shot operation which verifies a single block of data in one function. For algorithms that support streaming it is equivalent to calling EVP_DigestVerifyUpdate() and EVP_DigestVerifyFinal(). For algorithms which do not support streaming (e.g. PureEdDSA) it is the only way to verify data.

- -

In previous versions of OpenSSL there was a link between message digest types and public key algorithms. This meant that "clone" digests such as EVP_dss1() needed to be used to sign using SHA1 and DSA. This is no longer necessary and the use of clone digest is now discouraged.

- -

For some key types and parameters the random number generator must be seeded. If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

The call to EVP_DigestVerifyFinal() internally finalizes a copy of the digest context. This means that EVP_VerifyUpdate() and EVP_VerifyFinal() can be called later to digest and verify additional data. Applications may disable this behavior by setting the EVP_MD_CTX_FLAG_FINALISE context flag via EVP_MD_CTX_set_flags(3).

- -

Note that not all providers support continuation, in case the selected provider does not allow to duplicate contexts EVP_DigestVerifyFinal() will finalize the digest context and attempting to process additional data via EVP_DigestVerifyUpdate() will result in an error.

- -

EVP_DigestVerifyInit() and EVP_DigestVerifyInit_ex() functions can be called multiple times on a context and the parameters set by previous calls should be preserved if the pkey parameter is NULL. The call then just resets the state of the ctx.

- -

EVP_DigestVerify() can only be called once, and cannot be used again without reinitialising the EVP_MD_CTX by calling EVP_DigestVerifyInit_ex().

- -

Ignoring failure returns of EVP_DigestVerifyInit() and EVP_DigestVerifyInit_ex() functions can lead to subsequent undefined behavior when calling EVP_DigestVerifyUpdate(), EVP_DigestVerifyFinal(), or EVP_DigestVerify().

- -

SEE ALSO

- -

EVP_DigestSignInit(3), EVP_DigestInit(3), evp(7), HMAC(3), MD2(3), MD5(3), MDC2(3), RIPEMD160(3), SHA1(3), openssl-dgst(1), RAND(7)

- -

HISTORY

- -

EVP_DigestVerifyInit(), EVP_DigestVerifyUpdate() and EVP_DigestVerifyFinal() were added in OpenSSL 1.0.0.

- -

EVP_DigestVerifyInit_ex() was added in OpenSSL 3.0.

- -

EVP_DigestVerifyUpdate() was converted from a macro to a function in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_EncodeInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_EncodeInit.html deleted file mode 100644 index b933ccbb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_EncodeInit.html +++ /dev/null @@ -1,114 +0,0 @@ - - - - -EVP_EncodeInit - - - - - - - - - - -

NAME

- -

EVP_ENCODE_CTX_new, EVP_ENCODE_CTX_free, EVP_ENCODE_CTX_copy, EVP_ENCODE_CTX_num, EVP_EncodeInit, EVP_EncodeUpdate, EVP_EncodeFinal, EVP_EncodeBlock, EVP_DecodeInit, EVP_DecodeUpdate, EVP_DecodeFinal, EVP_DecodeBlock - EVP base64 encode/decode routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_ENCODE_CTX *EVP_ENCODE_CTX_new(void);
-void EVP_ENCODE_CTX_free(EVP_ENCODE_CTX *ctx);
-int EVP_ENCODE_CTX_copy(EVP_ENCODE_CTX *dctx, EVP_ENCODE_CTX *sctx);
-int EVP_ENCODE_CTX_num(EVP_ENCODE_CTX *ctx);
-void EVP_EncodeInit(EVP_ENCODE_CTX *ctx);
-int EVP_EncodeUpdate(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl,
-                     const unsigned char *in, int inl);
-void EVP_EncodeFinal(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl);
-int EVP_EncodeBlock(unsigned char *t, const unsigned char *f, int n);
-
-void EVP_DecodeInit(EVP_ENCODE_CTX *ctx);
-int EVP_DecodeUpdate(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl,
-                     const unsigned char *in, int inl);
-int EVP_DecodeFinal(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl);
-int EVP_DecodeBlock(unsigned char *t, const unsigned char *f, int n);
- -

DESCRIPTION

- -

The EVP encode routines provide a high-level interface to base64 encoding and decoding. Base64 encoding converts binary data into a printable form that uses the characters A-Z, a-z, 0-9, "+" and "/" to represent the data. For every 3 bytes of binary data provided 4 bytes of base64 encoded data will be produced plus some occasional newlines (see below). If the input data length is not a multiple of 3 then the output data will be padded at the end using the "=" character.

- -

EVP_ENCODE_CTX_new() allocates, initializes and returns a context to be used for the encode/decode functions.

- -

EVP_ENCODE_CTX_free() cleans up an encode/decode context ctx and frees up the space allocated to it. If the argument is NULL, nothing is done.

- -

Encoding of binary data is performed in blocks of 48 input bytes (or less for the final block). For each 48 byte input block encoded 64 bytes of base64 data is output plus an additional newline character (i.e. 65 bytes in total). The final block (which may be less than 48 bytes) will output 4 bytes for every 3 bytes of input. If the data length is not divisible by 3 then a full 4 bytes is still output for the final 1 or 2 bytes of input. Similarly a newline character will also be output.

- -

EVP_EncodeInit() initialises ctx for the start of a new encoding operation.

- -

EVP_EncodeUpdate() encode inl bytes of data found in the buffer pointed to by in. The output is stored in the buffer out and the number of bytes output is stored in *outl. It is the caller's responsibility to ensure that the buffer at out is sufficiently large to accommodate the output data. Only full blocks of data (48 bytes) will be immediately processed and output by this function. Any remainder is held in the ctx object and will be processed by a subsequent call to EVP_EncodeUpdate() or EVP_EncodeFinal(). To calculate the required size of the output buffer add together the value of inl with the amount of unprocessed data held in ctx and divide the result by 48 (ignore any remainder). This gives the number of blocks of data that will be processed. Ensure the output buffer contains 65 bytes of storage for each block, plus an additional byte for a NUL terminator. EVP_EncodeUpdate() may be called repeatedly to process large amounts of input data. In the event of an error EVP_EncodeUpdate() will set *outl to 0 and return 0. On success 1 will be returned.

- -

EVP_EncodeFinal() must be called at the end of an encoding operation. It will process any partial block of data remaining in the ctx object. The output data will be stored in out and the length of the data written will be stored in *outl. It is the caller's responsibility to ensure that out is sufficiently large to accommodate the output data which will never be more than 65 bytes plus an additional NUL terminator (i.e. 66 bytes in total).

- -

EVP_ENCODE_CTX_copy() can be used to copy a context sctx to a context dctx. dctx must be initialized before calling this function.

- -

EVP_ENCODE_CTX_num() will return the number of as yet unprocessed bytes still to be encoded or decoded that are pending in the ctx object.

- -

EVP_EncodeBlock() encodes a full block of input data in f and of length n and stores it in t. For every 3 bytes of input provided 4 bytes of output data will be produced. If n is not divisible by 3 then the block is encoded as a final block of data and the output is padded such that it is always divisible by 4. Additionally a NUL terminator character will be added. For example if 16 bytes of input data is provided then 24 bytes of encoded data is created plus 1 byte for a NUL terminator (i.e. 25 bytes in total). The length of the data generated without the NUL terminator is returned from the function.

- -

EVP_DecodeInit() initialises ctx for the start of a new decoding operation.

- -

EVP_DecodeUpdate() decodes inl characters of data found in the buffer pointed to by in. The output is stored in the buffer out and the number of bytes output is stored in *outl. It is the caller's responsibility to ensure that the buffer at out is sufficiently large to accommodate the output data. This function will attempt to decode as much data as possible in chunks of up to 80 base64 characters at a time. Residual input shorter than the internal chunk size will be buffered in ctx if its length is not a multiple of 4 (including any padding), to be processed in future calls to EVP_DecodeUpdate() or EVP_DecodeFinal(). If the final chunk length is a multiple of 4, it is decoded immediately and not buffered.

- -

Any whitespace, newline or carriage return characters are ignored. For compatibility with PEM, the - (hyphen) character is treated as a soft end-of-input, subsequent bytes are not buffered, and the return value will be 0 to indicate that the end of the base64 input has been detected. The soft end-of-input, if present, MUST occur after a multiple of 4 valid base64 input bytes. The soft end-of-input condition is not remembered in ctx, it is up to the caller to avoid further calls to EVP_DecodeUpdate() after a 0 or negative (error) return.

- -

If any invalid base64 characters are encountered or if the base64 padding character (=) is encountered in the middle of the data then EVP_DecodeUpdate() returns -1 to indicate an error. A return value of 0 or 1 indicates successful processing of the data. A return value of 0 additionally indicates that the last 4 bytes processed ended with base64 padding (=), or that the next 4 byte group starts with the soft end-of-input (-) character, and therefore no more input data is expected to be processed.

- -

For every 4 valid base64 bytes processed (ignoring whitespace, carriage returns and line feeds), 3 bytes of binary output data will be produced (except at the end of data terminated with one or two padding characters).

- -

EVP_DecodeFinal() should be called at the end of a decoding operation, but it will never decode additional data. If there is no residual data it will return 1 to indicate success. If there is residual data, its length is not a multiple of 4, i.e. it was not properly padded, -1 is is returned in that case to indicate an error.

- -

EVP_DecodeBlock() will decode the block of n characters of base64 data contained in f and store the result in t. Any leading whitespace will be trimmed as will any trailing whitespace, newlines, carriage returns or EOF characters. Internal whitespace MUST NOT be present. After trimming the data in f MUST consist entirely of valid base64 characters or padding (only at the tail of the input) and its length MUST be divisible by 4. For every 4 input bytes exactly 3 output bytes will be produced. Padding bytes (=) (even if internal) are decoded to 6 zero bits, the caller is responsible for taking trailing padding into account, by ignoring as many bytes at the tail of the returned output. EVP_DecodeBlock() will return the length of the data decoded or -1 on error.

- -

RETURN VALUES

- -

EVP_ENCODE_CTX_new() returns a pointer to the newly allocated EVP_ENCODE_CTX object or NULL on error.

- -

EVP_ENCODE_CTX_num() returns the number of bytes pending encoding or decoding in ctx.

- -

EVP_EncodeUpdate() returns 0 on error or 1 on success.

- -

EVP_EncodeBlock() returns the number of bytes encoded excluding the NUL terminator.

- -

EVP_DecodeUpdate() returns -1 on error and 0 or 1 on success. If 0 is returned then no more non-padding base64 characters are expected.

- -

EVP_DecodeFinal() returns -1 on error or 1 on success.

- -

EVP_DecodeBlock() returns the length of the data decoded or -1 on error.

- -

SEE ALSO

- -

evp(7)

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_EncryptInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_EncryptInit.html deleted file mode 100644 index 9a2da58c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_EncryptInit.html +++ /dev/null @@ -1,1557 +0,0 @@ - - - - -EVP_EncryptInit - - - - - - - - - - -

NAME

- -

EVP_CIPHER_fetch, EVP_CIPHER_up_ref, EVP_CIPHER_free, EVP_CIPHER_CTX_new, EVP_CIPHER_CTX_reset, EVP_CIPHER_CTX_free, EVP_CIPHER_CTX_dup, EVP_CIPHER_CTX_copy, EVP_EncryptInit_ex, EVP_EncryptInit_ex2, EVP_EncryptUpdate, EVP_EncryptFinal_ex, EVP_DecryptInit_ex, EVP_DecryptInit_ex2, EVP_DecryptUpdate, EVP_DecryptFinal_ex, EVP_CipherInit_ex, EVP_CipherInit_ex2, EVP_CipherUpdate, EVP_CipherFinal_ex, EVP_CIPHER_CTX_set_key_length, EVP_CIPHER_CTX_ctrl, EVP_EncryptInit, EVP_EncryptFinal, EVP_DecryptInit, EVP_DecryptFinal, EVP_CipherInit, EVP_CipherFinal, EVP_Cipher, EVP_get_cipherbyname, EVP_get_cipherbynid, EVP_get_cipherbyobj, EVP_CIPHER_is_a, EVP_CIPHER_get0_name, EVP_CIPHER_get0_description, EVP_CIPHER_names_do_all, EVP_CIPHER_get0_provider, EVP_CIPHER_get_nid, EVP_CIPHER_get_params, EVP_CIPHER_gettable_params, EVP_CIPHER_get_block_size, EVP_CIPHER_get_key_length, EVP_CIPHER_get_iv_length, EVP_CIPHER_get_flags, EVP_CIPHER_get_mode, EVP_CIPHER_get_type, EVP_CIPHER_CTX_cipher, EVP_CIPHER_CTX_get0_cipher, EVP_CIPHER_CTX_get1_cipher, EVP_CIPHER_CTX_get0_name, EVP_CIPHER_CTX_get_nid, EVP_CIPHER_CTX_get_params, EVP_CIPHER_gettable_ctx_params, EVP_CIPHER_CTX_gettable_params, EVP_CIPHER_CTX_set_params, EVP_CIPHER_settable_ctx_params, EVP_CIPHER_CTX_settable_params, EVP_CIPHER_CTX_get_block_size, EVP_CIPHER_CTX_get_key_length, EVP_CIPHER_CTX_get_iv_length, EVP_CIPHER_CTX_get_tag_length, EVP_CIPHER_CTX_get_app_data, EVP_CIPHER_CTX_set_app_data, EVP_CIPHER_CTX_flags, EVP_CIPHER_CTX_set_flags, EVP_CIPHER_CTX_clear_flags, EVP_CIPHER_CTX_test_flags, EVP_CIPHER_CTX_get_type, EVP_CIPHER_CTX_get_mode, EVP_CIPHER_CTX_get_num, EVP_CIPHER_CTX_set_num, EVP_CIPHER_CTX_is_encrypting, EVP_CIPHER_param_to_asn1, EVP_CIPHER_asn1_to_param, EVP_CIPHER_CTX_set_padding, EVP_enc_null, EVP_CIPHER_do_all_provided, EVP_CIPHER_nid, EVP_CIPHER_name, EVP_CIPHER_block_size, EVP_CIPHER_key_length, EVP_CIPHER_iv_length, EVP_CIPHER_flags, EVP_CIPHER_mode, EVP_CIPHER_type, EVP_CIPHER_CTX_encrypting, EVP_CIPHER_CTX_nid, EVP_CIPHER_CTX_block_size, EVP_CIPHER_CTX_key_length, EVP_CIPHER_CTX_iv_length, EVP_CIPHER_CTX_tag_length, EVP_CIPHER_CTX_num, EVP_CIPHER_CTX_type, EVP_CIPHER_CTX_mode - EVP cipher routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_CIPHER *EVP_CIPHER_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-                             const char *properties);
-int EVP_CIPHER_up_ref(EVP_CIPHER *cipher);
-void EVP_CIPHER_free(EVP_CIPHER *cipher);
-EVP_CIPHER_CTX *EVP_CIPHER_CTX_new(void);
-int EVP_CIPHER_CTX_reset(EVP_CIPHER_CTX *ctx);
-void EVP_CIPHER_CTX_free(EVP_CIPHER_CTX *ctx);
-EVP_CIPHER_CTX *EVP_CIPHER_CTX_dup(const EVP_CIPHER_CTX *in);
-int EVP_CIPHER_CTX_copy(EVP_CIPHER_CTX *out, const EVP_CIPHER_CTX *in);
-
-int EVP_EncryptInit_ex(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                       ENGINE *impl, const unsigned char *key, const unsigned char *iv);
-int EVP_EncryptInit_ex2(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                        const unsigned char *key, const unsigned char *iv,
-                        const OSSL_PARAM params[]);
-int EVP_EncryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out,
-                      int *outl, const unsigned char *in, int inl);
-int EVP_EncryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl);
-
-int EVP_DecryptInit_ex(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                       ENGINE *impl, const unsigned char *key, const unsigned char *iv);
-int EVP_DecryptInit_ex2(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                        const unsigned char *key, const unsigned char *iv,
-                        const OSSL_PARAM params[]);
-int EVP_DecryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out,
-                      int *outl, const unsigned char *in, int inl);
-int EVP_DecryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl);
-
-int EVP_CipherInit_ex(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                      ENGINE *impl, const unsigned char *key, const unsigned char *iv, int enc);
-int EVP_CipherInit_ex2(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                       const unsigned char *key, const unsigned char *iv,
-                       int enc, const OSSL_PARAM params[]);
-int EVP_CipherUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out,
-                     int *outl, const unsigned char *in, int inl);
-int EVP_CipherFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl);
-
-int EVP_EncryptInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                    const unsigned char *key, const unsigned char *iv);
-int EVP_EncryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl);
-
-int EVP_DecryptInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                    const unsigned char *key, const unsigned char *iv);
-int EVP_DecryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl);
-
-int EVP_CipherInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                   const unsigned char *key, const unsigned char *iv, int enc);
-int EVP_CipherFinal(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl);
-
-int EVP_Cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
-               const unsigned char *in, unsigned int inl);
-
-int EVP_CIPHER_CTX_set_padding(EVP_CIPHER_CTX *x, int padding);
-int EVP_CIPHER_CTX_set_key_length(EVP_CIPHER_CTX *x, int keylen);
-int EVP_CIPHER_CTX_ctrl(EVP_CIPHER_CTX *ctx, int cmd, int p1, void *p2);
-int EVP_CIPHER_CTX_rand_key(EVP_CIPHER_CTX *ctx, unsigned char *key);
-void EVP_CIPHER_CTX_set_flags(EVP_CIPHER_CTX *ctx, int flags);
-void EVP_CIPHER_CTX_clear_flags(EVP_CIPHER_CTX *ctx, int flags);
-int EVP_CIPHER_CTX_test_flags(const EVP_CIPHER_CTX *ctx, int flags);
-
-const EVP_CIPHER *EVP_get_cipherbyname(const char *name);
-const EVP_CIPHER *EVP_get_cipherbynid(int nid);
-const EVP_CIPHER *EVP_get_cipherbyobj(const ASN1_OBJECT *a);
-
-int EVP_CIPHER_get_nid(const EVP_CIPHER *e);
-int EVP_CIPHER_is_a(const EVP_CIPHER *cipher, const char *name);
-int EVP_CIPHER_names_do_all(const EVP_CIPHER *cipher,
-                            void (*fn)(const char *name, void *data),
-                            void *data);
-const char *EVP_CIPHER_get0_name(const EVP_CIPHER *cipher);
-const char *EVP_CIPHER_get0_description(const EVP_CIPHER *cipher);
-const OSSL_PROVIDER *EVP_CIPHER_get0_provider(const EVP_CIPHER *cipher);
-int EVP_CIPHER_get_block_size(const EVP_CIPHER *e);
-int EVP_CIPHER_get_key_length(const EVP_CIPHER *e);
-int EVP_CIPHER_get_iv_length(const EVP_CIPHER *e);
-unsigned long EVP_CIPHER_get_flags(const EVP_CIPHER *e);
-unsigned long EVP_CIPHER_get_mode(const EVP_CIPHER *e);
-int EVP_CIPHER_get_type(const EVP_CIPHER *cipher);
-
-const EVP_CIPHER *EVP_CIPHER_CTX_get0_cipher(const EVP_CIPHER_CTX *ctx);
-EVP_CIPHER *EVP_CIPHER_CTX_get1_cipher(const EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_get_nid(const EVP_CIPHER_CTX *ctx);
-const char *EVP_CIPHER_CTX_get0_name(const EVP_CIPHER_CTX *ctx);
-
-int EVP_CIPHER_get_params(EVP_CIPHER *cipher, OSSL_PARAM params[]);
-int EVP_CIPHER_CTX_set_params(EVP_CIPHER_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_CIPHER_CTX_get_params(EVP_CIPHER_CTX *ctx, OSSL_PARAM params[]);
-const OSSL_PARAM *EVP_CIPHER_gettable_params(const EVP_CIPHER *cipher);
-const OSSL_PARAM *EVP_CIPHER_settable_ctx_params(const EVP_CIPHER *cipher);
-const OSSL_PARAM *EVP_CIPHER_gettable_ctx_params(const EVP_CIPHER *cipher);
-const OSSL_PARAM *EVP_CIPHER_CTX_settable_params(EVP_CIPHER_CTX *ctx);
-const OSSL_PARAM *EVP_CIPHER_CTX_gettable_params(EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_get_block_size(const EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_get_key_length(const EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_get_iv_length(const EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_get_tag_length(const EVP_CIPHER_CTX *ctx);
-void *EVP_CIPHER_CTX_get_app_data(const EVP_CIPHER_CTX *ctx);
-void EVP_CIPHER_CTX_set_app_data(const EVP_CIPHER_CTX *ctx, void *data);
-int EVP_CIPHER_CTX_get_type(const EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_get_mode(const EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_get_num(const EVP_CIPHER_CTX *ctx);
-int EVP_CIPHER_CTX_set_num(EVP_CIPHER_CTX *ctx, int num);
-int EVP_CIPHER_CTX_is_encrypting(const EVP_CIPHER_CTX *ctx);
-
-int EVP_CIPHER_param_to_asn1(EVP_CIPHER_CTX *c, ASN1_TYPE *type);
-int EVP_CIPHER_asn1_to_param(EVP_CIPHER_CTX *c, ASN1_TYPE *type);
-
-void EVP_CIPHER_do_all_provided(OSSL_LIB_CTX *libctx,
-                                void (*fn)(EVP_CIPHER *cipher, void *arg),
-                                void *arg);
-
-#define EVP_CIPHER_nid EVP_CIPHER_get_nid
-#define EVP_CIPHER_name EVP_CIPHER_get0_name
-#define EVP_CIPHER_block_size EVP_CIPHER_get_block_size
-#define EVP_CIPHER_key_length EVP_CIPHER_get_key_length
-#define EVP_CIPHER_iv_length EVP_CIPHER_get_iv_length
-#define EVP_CIPHER_flags EVP_CIPHER_get_flags
-#define EVP_CIPHER_mode EVP_CIPHER_get_mode
-#define EVP_CIPHER_type EVP_CIPHER_get_type
-#define EVP_CIPHER_CTX_encrypting EVP_CIPHER_CTX_is_encrypting
-#define EVP_CIPHER_CTX_nid EVP_CIPHER_CTX_get_nid
-#define EVP_CIPHER_CTX_block_size EVP_CIPHER_CTX_get_block_size
-#define EVP_CIPHER_CTX_key_length EVP_CIPHER_CTX_get_key_length
-#define EVP_CIPHER_CTX_iv_length EVP_CIPHER_CTX_get_iv_length
-#define EVP_CIPHER_CTX_tag_length EVP_CIPHER_CTX_get_tag_length
-#define EVP_CIPHER_CTX_num EVP_CIPHER_CTX_get_num
-#define EVP_CIPHER_CTX_type EVP_CIPHER_CTX_get_type
-#define EVP_CIPHER_CTX_mode EVP_CIPHER_CTX_get_mode
- -

The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
const EVP_CIPHER *EVP_CIPHER_CTX_cipher(const EVP_CIPHER_CTX *ctx);
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int EVP_CIPHER_CTX_flags(const EVP_CIPHER_CTX *ctx);
- -

DESCRIPTION

- -

The EVP cipher routines are a high-level interface to certain symmetric ciphers.

- -

The EVP_CIPHER type is a structure for cipher method implementation.

- -
- -
EVP_CIPHER_fetch()
-
- -

Fetches the cipher implementation for the given algorithm from any provider offering it, within the criteria given by the properties. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

The returned value must eventually be freed with EVP_CIPHER_free().

- -

Fetched EVP_CIPHER structures are reference counted.

- -
-
EVP_CIPHER_up_ref()
-
- -

Increments the reference count for an EVP_CIPHER structure.

- -
-
EVP_CIPHER_free()
-
- -

Decrements the reference count for the fetched EVP_CIPHER structure. If the reference count drops to 0 then the structure is freed. If the argument is NULL, nothing is done.

- -
-
EVP_CIPHER_CTX_new()
-
- -

Allocates and returns a cipher context.

- -
-
EVP_CIPHER_CTX_free()
-
- -

Clears all information from a cipher context and frees any allocated memory associated with it, including ctx itself. This function should be called after all operations using a cipher are complete so sensitive information does not remain in memory. If the argument is NULL, nothing is done.

- -
-
EVP_CIPHER_CTX_dup()
-
- -

Can be used to duplicate the cipher state from in. This is useful to avoid multiple EVP_CIPHER_fetch() calls or if large amounts of data are to be fed which only differ in the last few bytes.

- -
-
EVP_CIPHER_CTX_copy()
-
- -

Can be used to copy the cipher state from in to out.

- -
-
EVP_CIPHER_CTX_ctrl()
-
- -

This is a legacy method. EVP_CIPHER_CTX_set_params() and EVP_CIPHER_CTX_get_params() is the mechanism that should be used to set and get parameters that are used by providers.

- -

Performs cipher-specific control actions on context ctx. The control command is indicated in cmd and any additional arguments in p1 and p2. EVP_CIPHER_CTX_ctrl() must be called after EVP_CipherInit_ex2(). Other restrictions may apply depending on the control type and cipher implementation.

- -

If this function happens to be used with a fetched EVP_CIPHER, it will translate the controls that are known to OpenSSL into OSSL_PARAM(3) parameters with keys defined by OpenSSL and call EVP_CIPHER_CTX_get_params() or EVP_CIPHER_CTX_set_params() as is appropriate for each control command.

- -

See "CONTROLS" below for more information, including what translations are being done.

- -
-
EVP_CIPHER_get_params()
-
- -

Retrieves the requested list of algorithm params from a CIPHER cipher. See "PARAMETERS" below for more information.

- -
-
EVP_CIPHER_CTX_get_params()
-
- -

Retrieves the requested list of params from CIPHER context ctx. See "PARAMETERS" below for more information.

- -
-
EVP_CIPHER_CTX_set_params()
-
- -

Sets the list of params into a CIPHER context ctx. See "PARAMETERS" below for more information.

- -
-
EVP_CIPHER_gettable_params()
-
- -

Get a constant OSSL_PARAM(3) array that describes the retrievable parameters that can be used with EVP_CIPHER_get_params().

- -
-
EVP_CIPHER_gettable_ctx_params() and EVP_CIPHER_CTX_gettable_params()
-
- -

Get a constant OSSL_PARAM(3) array that describes the retrievable parameters that can be used with EVP_CIPHER_CTX_get_params(). EVP_CIPHER_gettable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_CIPHER_CTX_gettable_params() returns the parameters that can be retrieved in the context's current state.

- -
-
EVP_CIPHER_settable_ctx_params() and EVP_CIPHER_CTX_settable_params()
-
- -

Get a constant OSSL_PARAM(3) array that describes the settable parameters that can be used with EVP_CIPHER_CTX_set_params(). EVP_CIPHER_settable_ctx_params() returns the parameters that can be set from the algorithm, whereas EVP_CIPHER_CTX_settable_params() returns the parameters that can be set in the context's current state.

- -
-
EVP_EncryptInit_ex2()
-
- -

Sets up cipher context ctx for encryption with cipher type. type is typically supplied by calling EVP_CIPHER_fetch(). type may also be set using legacy functions such as EVP_aes_256_cbc(), but this is not recommended for new applications. key is the symmetric key to use and iv is the IV to use (if necessary), the actual number of bytes used for the key and IV depends on the cipher. The parameters params will be set on the context after initialisation. It is possible to set all parameters to NULL except type in an initial call and supply the remaining parameters in subsequent calls, all of which have type set to NULL. This is done when the default cipher parameters are not appropriate. For EVP_CIPH_GCM_MODE the IV will be generated internally if it is not specified.

- -
-
EVP_EncryptInit_ex()
-
- -

This legacy function is similar to EVP_EncryptInit_ex2() when impl is NULL. The implementation of the type from the impl engine will be used if it exists.

- -
-
EVP_EncryptUpdate()
-
- -

Encrypts inl bytes from the buffer in and writes the encrypted version to out. The pointers out and in may point to the same location, in which case the encryption will be done in-place. However, in-place encryption is guaranteed to work only if the encryption context (ctx) has processed data in multiples of the block size. If the context contains an incomplete data block from previous operations, in-place encryption will fail.

- -

If out and in point to different locations, the two buffers must be disjoint, otherwise the operation might fail or the outcome might be undefined.

- -

This function can be called multiple times to encrypt successive blocks of data. The amount of data written depends on the block alignment of the encrypted data. For most ciphers and modes, the amount of data written can be anything from zero bytes to (inl + cipher_block_size - 1) bytes. For wrap cipher modes, the amount of data written can be anything from zero bytes to (inl + cipher_block_size) bytes. For stream ciphers, the amount of data written can be anything from zero bytes to inl bytes. Thus, the buffer pointed to by out must contain sufficient room for the operation being performed. The actual number of bytes written is placed in outl.

- -

If padding is enabled (the default) then EVP_EncryptFinal_ex() encrypts the "final" data, that is any data that remains in a partial block. It uses standard block padding (aka PKCS padding) as described in the NOTES section, below. The encrypted final data is written to out which should have sufficient space for one cipher block. The number of bytes written is placed in outl. After this function is called the encryption operation is finished and no further calls to EVP_EncryptUpdate() should be made.

- -

If padding is disabled then EVP_EncryptFinal_ex() will not encrypt any more data and it will return an error if any data remains in a partial block: that is if the total data length is not a multiple of the block size.

- -
-
EVP_DecryptInit_ex2(), EVP_DecryptInit_ex(), EVP_DecryptUpdate() and EVP_DecryptFinal_ex()
-
- -

These functions are the corresponding decryption operations. EVP_DecryptFinal() will return an error code if padding is enabled and the final block is not correctly formatted. The parameters and restrictions are identical to the encryption operations except that if padding is enabled the decrypted data buffer out passed to EVP_DecryptUpdate() should have sufficient room for (inl + cipher_block_size) bytes unless the cipher block size is 1 in which case inl bytes is sufficient.

- -
-
EVP_CipherInit_ex2(), EVP_CipherInit_ex(), EVP_CipherUpdate() and EVP_CipherFinal_ex()
-
- -

These functions can be used for decryption or encryption. The operation performed depends on the value of the enc parameter. It should be set to 1 for encryption, 0 for decryption and -1 to leave the value unchanged (the actual value of 'enc' being supplied in a previous call).

- -
-
EVP_CIPHER_CTX_reset()
-
- -

Clears all information from a cipher context and free up any allocated memory associated with it, except the ctx itself. This function should be called anytime ctx is reused by another EVP_CipherInit() / EVP_CipherUpdate() / EVP_CipherFinal() series of calls.

- -
-
EVP_EncryptInit(), EVP_DecryptInit() and EVP_CipherInit()
-
- -

Behave in a similar way to EVP_EncryptInit_ex(), EVP_DecryptInit_ex() and EVP_CipherInit_ex() except if the type is not a fetched cipher they use the default implementation of the type.

- -
-
EVP_EncryptFinal(), EVP_DecryptFinal() and EVP_CipherFinal()
-
- -

Identical to EVP_EncryptFinal_ex(), EVP_DecryptFinal_ex() and EVP_CipherFinal_ex(). In previous releases they also cleaned up the ctx, but this is no longer done and EVP_CIPHER_CTX_cleanup() must be called to free any context resources.

- -
-
EVP_Cipher()
-
- -

Encrypts or decrypts a maximum inl amount of bytes from in and leaves the result in out.

- -

For legacy ciphers - If the cipher doesn't have the flag EVP_CIPH_FLAG_CUSTOM_CIPHER set, then inl must be a multiple of EVP_CIPHER_get_block_size(). If it isn't, the result is undefined. If the cipher has that flag set, then inl can be any size.

- -

Due to the constraints of the API contract of this function it shouldn't be used in applications, please consider using EVP_CipherUpdate() and EVP_CipherFinal_ex() instead.

- -
-
EVP_get_cipherbyname(), EVP_get_cipherbynid() and EVP_get_cipherbyobj()
-
- -

Returns an EVP_CIPHER structure when passed a cipher name, a cipher NID or an ASN1_OBJECT structure respectively.

- -

EVP_get_cipherbyname() will return NULL for algorithms such as "AES-128-SIV", "AES-128-CBC-CTS" and "CAMELLIA-128-CBC-CTS" which were previously only accessible via low level interfaces.

- -

The EVP_get_cipherbyname() function is present for backwards compatibility with OpenSSL prior to version 3 and is different to the EVP_CIPHER_fetch() function since it does not attempt to "fetch" an implementation of the cipher. Additionally, it only knows about ciphers that are built-in to OpenSSL and have an associated NID. Similarly EVP_get_cipherbynid() and EVP_get_cipherbyobj() also return objects without an associated implementation.

- -

When the cipher objects returned by these functions are used (such as in a call to EVP_EncryptInit_ex()) an implementation of the cipher will be implicitly fetched from the loaded providers. This fetch could fail if no suitable implementation is available. Use EVP_CIPHER_fetch() instead to explicitly fetch the algorithm and an associated implementation from a provider.

- -

See "ALGORITHM FETCHING" in crypto(7) for more information about fetching.

- -

The cipher objects returned from these functions do not need to be freed with EVP_CIPHER_free().

- -
-
EVP_CIPHER_get_nid() and EVP_CIPHER_CTX_get_nid()
-
- -

Return the NID of a cipher when passed an EVP_CIPHER or EVP_CIPHER_CTX structure. The actual NID value is an internal value which may not have a corresponding OBJECT IDENTIFIER. NID_undef is returned in the event that the nid is unknown or if the cipher has not been properly initialized via a call to EVP_CipherInit.

- -
-
EVP_CIPHER_CTX_set_flags(), EVP_CIPHER_CTX_clear_flags() and EVP_CIPHER_CTX_test_flags()
-
- -

Sets, clears and tests ctx flags. See "FLAGS" below for more information.

- -

For provided ciphers EVP_CIPHER_CTX_set_flags() should be called only after the fetched cipher has been assigned to the ctx. It is recommended to use "PARAMETERS" instead.

- -
-
EVP_CIPHER_CTX_set_padding()
-
- -

Enables or disables padding. This function should be called after the context is set up for encryption or decryption with EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2() or EVP_CipherInit_ex2(). By default encryption operations are padded using standard block padding and the padding is checked and removed when decrypting. If the pad parameter is zero then no padding is performed, the total amount of data encrypted or decrypted must then be a multiple of the block size or an error will occur.

- -
-
EVP_CIPHER_get_key_length() and EVP_CIPHER_CTX_get_key_length()
-
- -

Return the key length of a cipher when passed an EVP_CIPHER or EVP_CIPHER_CTX structure. The constant EVP_MAX_KEY_LENGTH is the maximum key length for all ciphers. Note: although EVP_CIPHER_get_key_length() is fixed for a given cipher, the value of EVP_CIPHER_CTX_get_key_length() may be different for variable key length ciphers.

- -
-
EVP_CIPHER_CTX_set_key_length()
-
- -

Sets the key length of the cipher context. If the cipher is a fixed length cipher then attempting to set the key length to any value other than the fixed value is an error.

- -
-
EVP_CIPHER_get_iv_length() and EVP_CIPHER_CTX_get_iv_length()
-
- -

Return the IV length of a cipher when passed an EVP_CIPHER or EVP_CIPHER_CTX. It will return zero if the cipher does not use an IV, if the cipher has not yet been initialized within the EVP_CIPHER_CTX, or if the passed cipher is NULL. The constant EVP_MAX_IV_LENGTH is the maximum IV length for all ciphers.

- -
-
EVP_CIPHER_CTX_get_tag_length()
-
- -

Returns the tag length of an AEAD cipher when passed a EVP_CIPHER_CTX. It will return zero if the cipher does not support a tag. It returns a default value if the tag length has not been set.

- -
-
EVP_CIPHER_get_block_size() and EVP_CIPHER_CTX_get_block_size()
-
- -

Return the block size of a cipher when passed an EVP_CIPHER or EVP_CIPHER_CTX structure. The constant EVP_MAX_BLOCK_LENGTH is also the maximum block length for all ciphers. A value of 0 is returned if the cipher has not been properly initialized with a call to EVP_CipherInit.

- -
-
EVP_CIPHER_get_type() and EVP_CIPHER_CTX_get_type()
-
- -

Return the type of the passed cipher or context. This "type" is the actual NID of the cipher OBJECT IDENTIFIER and as such it ignores the cipher parameters (40 bit RC2 and 128 bit RC2 have the same NID). If the cipher does not have an object identifier or does not have ASN1 support this function will return NID_undef.

- -
-
EVP_CIPHER_is_a()
-
- -

Returns 1 if cipher is an implementation of an algorithm that's identifiable with name, otherwise 0. If cipher is a legacy cipher (it's the return value from the likes of EVP_aes128() rather than the result of an EVP_CIPHER_fetch()), only cipher names registered with the default library context (see OSSL_LIB_CTX(3)) will be considered.

- -
-
EVP_CIPHER_get0_name() and EVP_CIPHER_CTX_get0_name()
-
- -

Return the name of the passed cipher or context. For fetched ciphers with multiple names, only one of them is returned. See also EVP_CIPHER_names_do_all().

- -
-
EVP_CIPHER_names_do_all()
-
- -

Traverses all names for the cipher, and calls fn with each name and data. This is only useful with fetched EVP_CIPHERs.

- -
-
EVP_CIPHER_get0_description()
-
- -

Returns a description of the cipher, meant for display and human consumption. The description is at the discretion of the cipher implementation.

- -
-
EVP_CIPHER_get0_provider()
-
- -

Returns an OSSL_PROVIDER pointer to the provider that implements the given EVP_CIPHER.

- -
-
EVP_CIPHER_CTX_get0_cipher()
-
- -

Returns the EVP_CIPHER structure when passed an EVP_CIPHER_CTX structure. EVP_CIPHER_CTX_get1_cipher() is the same except the ownership is passed to the caller. Both functions return NULL on error.

- -
-
EVP_CIPHER_get_mode() and EVP_CIPHER_CTX_get_mode()
-
- -

Return the block cipher mode: EVP_CIPH_ECB_MODE, EVP_CIPH_CBC_MODE, EVP_CIPH_CFB_MODE, EVP_CIPH_OFB_MODE, EVP_CIPH_CTR_MODE, EVP_CIPH_GCM_MODE, EVP_CIPH_CCM_MODE, EVP_CIPH_XTS_MODE, EVP_CIPH_WRAP_MODE, EVP_CIPH_OCB_MODE or EVP_CIPH_SIV_MODE. If the cipher is a stream cipher then EVP_CIPH_STREAM_CIPHER is returned.

- -
-
EVP_CIPHER_get_flags()
-
- -

Returns any flags associated with the cipher. See "FLAGS" for a list of currently defined flags.

- -
-
EVP_CIPHER_CTX_get_num() and EVP_CIPHER_CTX_set_num()
-
- -

Gets or sets the cipher specific "num" parameter for the associated ctx. Built-in ciphers typically use this to track how much of the current underlying block has been "used" already.

- -
-
EVP_CIPHER_CTX_is_encrypting()
-
- -

Reports whether the ctx is being used for encryption or decryption.

- -
-
EVP_CIPHER_CTX_flags()
-
- -

A deprecated macro calling EVP_CIPHER_get_flags(EVP_CIPHER_CTX_get0_cipher(ctx)). Do not use.

- -
-
EVP_CIPHER_param_to_asn1()
-
- -

Sets the AlgorithmIdentifier "parameter" based on the passed cipher. This will typically include any parameters and an IV. The cipher IV (if any) must be set when this call is made. This call should be made before the cipher is actually "used" (before any EVP_EncryptUpdate(), EVP_DecryptUpdate() calls for example). This function may fail if the cipher does not have any ASN1 support, or if an uninitialized cipher is passed to it.

- -
-
EVP_CIPHER_asn1_to_param()
-
- -

Sets the cipher parameters based on an ASN1 AlgorithmIdentifier "parameter". The precise effect depends on the cipher. In the case of RC2, for example, it will set the IV and effective key length. This function should be called after the base cipher type is set but before the key is set. For example EVP_CipherInit() will be called with the IV and key set to NULL, EVP_CIPHER_asn1_to_param() will be called and finally EVP_CipherInit() again with all parameters except the key set to NULL. It is possible for this function to fail if the cipher does not have any ASN1 support or the parameters cannot be set (for example the RC2 effective key length is not supported.

- -
-
EVP_CIPHER_CTX_rand_key()
-
- -

Generates a random key of the appropriate length based on the cipher context. The EVP_CIPHER can provide its own random key generation routine to support keys of a specific form. key must point to a buffer at least as big as the value returned by EVP_CIPHER_CTX_get_key_length().

- -
-
EVP_CIPHER_do_all_provided()
-
- -

Traverses all ciphers implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -
-
- -

PARAMETERS

- -

See OSSL_PARAM(3) for information about passing parameters.

- -

Gettable EVP_CIPHER parameters

- -

When EVP_CIPHER_fetch() is called it internally calls EVP_CIPHER_get_params() and caches the results.

- -

EVP_CIPHER_get_params() can be used with the following OSSL_PARAM(3) keys:

- -
- -
"mode" (OSSL_CIPHER_PARAM_MODE) <unsigned integer>
-
- -

Gets the mode for the associated cipher algorithm cipher. See "EVP_CIPHER_get_mode() and EVP_CIPHER_CTX_get_mode()" for a list of valid modes. Use EVP_CIPHER_get_mode() to retrieve the cached value.

- -
-
"keylen" (OSSL_CIPHER_PARAM_KEYLEN) <unsigned integer>
-
- -

Gets the key length for the associated cipher algorithm cipher. Use EVP_CIPHER_get_key_length() to retrieve the cached value.

- -
-
"ivlen" (OSSL_CIPHER_PARAM_IVLEN) <unsigned integer>
-
- -

Gets the IV length for the associated cipher algorithm cipher. Use EVP_CIPHER_get_iv_length() to retrieve the cached value.

- -
-
"blocksize" (OSSL_CIPHER_PARAM_BLOCK_SIZE) <unsigned integer>
-
- -

Gets the block size for the associated cipher algorithm cipher. The block size should be 1 for stream ciphers. Note that the block size for a cipher may be different to the block size for the underlying encryption/decryption primitive. For example AES in CTR mode has a block size of 1 (because it operates like a stream cipher), even though AES has a block size of 16. Use EVP_CIPHER_get_block_size() to retrieve the cached value.

- -
-
"aead" (OSSL_CIPHER_PARAM_AEAD) <integer>
-
- -

Gets 1 if this is an AEAD cipher algorithm, otherwise it gets 0. Use (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) to retrieve the cached value.

- -
-
"custom-iv" (OSSL_CIPHER_PARAM_CUSTOM_IV) <integer>
-
- -

Gets 1 if the cipher algorithm cipher has a custom IV, otherwise it gets 0. Storing and initializing the IV is left entirely to the implementation, if a custom IV is used. Use (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_CUSTOM_IV) to retrieve the cached value.

- -
-
"cts" (OSSL_CIPHER_PARAM_CTS) <integer>
-
- -

Gets 1 if the cipher algorithm cipher uses ciphertext stealing, otherwise it gets 0. This is currently used to indicate that the cipher is a one shot that only allows a single call to EVP_CipherUpdate(). Use (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_CTS) to retrieve the cached value.

- -
-
"tls-multi" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK) <integer>
-
- -

Gets 1 if the cipher algorithm cipher supports interleaving of crypto blocks, otherwise it gets 0. The interleaving is an optimization only applicable to certain TLS ciphers. Use (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK) to retrieve the cached value.

- -
-
"has-randkey" (OSSL_CIPHER_PARAM_HAS_RANDKEY) <integer>
-
- -

Gets 1 if the cipher algorithm cipher supports the gettable EVP_CIPHER_CTX parameter OSSL_CIPHER_PARAM_RANDOM_KEY. Only DES and 3DES set this to 1, all other OpenSSL ciphers return 0.

- -
-
"decrypt-only" (OSSL_CIPHER_PARAM_DECRYPT_ONLY) <integer
-
- -

Gets 1 if the cipher algorithm cipher implementation supports only the decryption operation such as the 3DES ciphers in the fips provider. Otherwise gets 0 or the parameter might not be present at all.

- -
-
- -

Gettable and Settable EVP_CIPHER_CTX parameters

- -

The following OSSL_PARAM(3) keys can be used with both EVP_CIPHER_CTX_get_params() and EVP_CIPHER_CTX_set_params().

- -
- -
"padding" (OSSL_CIPHER_PARAM_PADDING) <unsigned integer>
-
- -

Gets or sets the padding mode for the cipher context ctx. Padding is enabled if the value is 1, and disabled if the value is 0. See also EVP_CIPHER_CTX_set_padding().

- -
-
"num" (OSSL_CIPHER_PARAM_NUM) <unsigned integer>
-
- -

Gets or sets the cipher specific "num" parameter for the cipher context ctx. Built-in ciphers typically use this to track how much of the current underlying block has been "used" already. See also EVP_CIPHER_CTX_get_num() and EVP_CIPHER_CTX_set_num().

- -
-
"keylen" (OSSL_CIPHER_PARAM_KEYLEN) <unsigned integer>
-
- -

Gets or sets the key length for the cipher context ctx. The length of the "keylen" parameter should not exceed that of a size_t. See also EVP_CIPHER_CTX_get_key_length() and EVP_CIPHER_CTX_set_key_length().

- -
-
"tag" (OSSL_CIPHER_PARAM_AEAD_TAG) <octet string>
-
- -

Gets or sets the AEAD tag for the associated cipher context ctx. See "AEAD Interface" in EVP_EncryptInit(3).

- -
-
"keybits" (OSSL_CIPHER_PARAM_RC2_KEYBITS) <unsigned integer>
-
- -

Gets or sets the effective keybits used for a RC2 cipher. The length of the "keybits" parameter should not exceed that of a size_t.

- -
-
"rounds" (OSSL_CIPHER_PARAM_ROUNDS) <unsigned integer>
-
- -

Gets or sets the number of rounds to be used for a cipher. This is used by the RC5 cipher.

- -
-
"algorithm-id" (OSSL_CIPHER_PARAM_ALGORITHM_ID) <octet string>
-
- -

Used to get the DER encoded AlgorithmIdentifier from the cipher implementation. Functions like EVP_PKEY_CTX_get_algor(3) use this parameter.

- -
-
"algorithm-id-params" (OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS) <octet string>
-
- -

Used to pass the DER encoded AlgorithmIdentifier parameter to or from the cipher implementation. Functions like EVP_CIPHER_CTX_set_algor_params(3) and EVP_CIPHER_CTX_get_algor_params(3) use this parameter.

- -
-
"alg_id_params" (OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS_OLD) <octet string>
-
- -

An deprecated alias for "algorithm-id-params", only used by EVP_CIPHER_param_to_asn1(3) and EVP_CIPHER_asn1_to_param(3).

- -
-
"cts_mode" (OSSL_CIPHER_PARAM_CTS_MODE) <UTF8 string>
-
- -

Gets or sets the cipher text stealing mode. For all modes the output size is the same as the input size. The input length must be greater than or equal to the block size. (The block size for AES and CAMELLIA is 16 bytes).

- -

Valid values for the mode are:

- -
- -
"CS1"
-
- -

The NIST variant of cipher text stealing. For input lengths that are multiples of the block size it is equivalent to using a "AES-XXX-CBC" or "CAMELLIA-XXX-CBC" cipher otherwise the second last cipher text block is a partial block.

- -
-
"CS2"
-
- -

For input lengths that are multiples of the block size it is equivalent to using a "AES-XXX-CBC" or "CAMELLIA-XXX-CBC" cipher, otherwise it is the same as "CS3" mode.

- -
-
"CS3"
-
- -

The Kerberos5 variant of cipher text stealing which always swaps the last cipher text block with the previous block (which may be a partial or full block depending on the input length). If the input length is exactly one full block then this is equivalent to using a "AES-XXX-CBC" or "CAMELLIA-XXX-CBC" cipher.

- -
-
- -

The default is "CS1". This is only supported for "AES-128-CBC-CTS", "AES-192-CBC-CTS", "AES-256-CBC-CTS", "CAMELLIA-128-CBC-CTS", "CAMELLIA-192-CBC-CTS" and "CAMELLIA-256-CBC-CTS".

- -
-
"tls1multi_interleave" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE) <unsigned integer>
-
- -

Sets or gets the number of records being sent in one go for a tls1 multiblock cipher operation (either 4 or 8 records).

- -
-
- -

Gettable EVP_CIPHER_CTX parameters

- -

The following OSSL_PARAM(3) keys can be used with EVP_CIPHER_CTX_get_params():

- -
- -
"ivlen" (OSSL_CIPHER_PARAM_IVLEN and <OSSL_CIPHER_PARAM_AEAD_IVLEN) <unsigned integer>
-
- -

Gets the IV length for the cipher context ctx. The length of the "ivlen" parameter should not exceed that of a size_t. See also EVP_CIPHER_CTX_get_iv_length().

- -
-
"iv" (OSSL_CIPHER_PARAM_IV) <octet string OR octet ptr>
-
- -

Gets the IV used to initialize the associated cipher context ctx. See also EVP_CIPHER_CTX_get_original_iv().

- -
-
"updated-iv" (OSSL_CIPHER_PARAM_UPDATED_IV) <octet string OR octet ptr>
-
- -

Gets the updated pseudo-IV state for the associated cipher context, e.g., the previous ciphertext block for CBC mode or the iteratively encrypted IV value for OFB mode. Note that octet pointer access is deprecated and is provided only for backwards compatibility with historical libcrypto APIs. See also EVP_CIPHER_CTX_get_updated_iv().

- -
-
"randkey" (OSSL_CIPHER_PARAM_RANDOM_KEY) <octet string>
-
- -

Gets an implementation specific randomly generated key for the associated cipher context ctx. This is currently only supported by DES and 3DES (which set the key to odd parity).

- -
-
"taglen" (OSSL_CIPHER_PARAM_AEAD_TAGLEN) <unsigned integer>
-
- -

Gets the tag length to be used for an AEAD cipher for the associated cipher context ctx. It gets a default value if it has not been set. The length of the "taglen" parameter should not exceed that of a size_t. See also EVP_CIPHER_CTX_get_tag_length().

- -
-
"tlsaadpad" (OSSL_CIPHER_PARAM_AEAD_TLS1_AAD_PAD) <unsigned integer>
-
- -

Gets the length of the tag that will be added to a TLS record for the AEAD tag for the associated cipher context ctx. The length of the "tlsaadpad" parameter should not exceed that of a size_t.

- -
-
"tlsivgen" (OSSL_CIPHER_PARAM_AEAD_TLS1_GET_IV_GEN) <octet string>
-
- -

Gets the invocation field generated for encryption. Can only be called after "tlsivfixed" is set. This is only used for GCM mode.

- -
-
"tls1multi_enclen" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_LEN) <unsigned integer>
-
- -

Get the total length of the record returned from the "tls1multi_enc" operation.

- -
-
"tls1multi_maxbufsz" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_BUFSIZE) <unsigned integer>
-
- -

Gets the maximum record length for a TLS1 multiblock cipher operation. The length of the "tls1multi_maxbufsz" parameter should not exceed that of a size_t.

- -
-
"tls1multi_aadpacklen" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD_PACKLEN) <unsigned integer>
-
- -

Gets the result of running the "tls1multi_aad" operation.

- -
-
"tls-mac" (OSSL_CIPHER_PARAM_TLS_MAC) <octet ptr>
-
- -

Used to pass the TLS MAC data.

- -
-
"fips-indicator" (OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

This option is used by the OpenSSL FIPS provider.

- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling a cipher final operation such as EVP_EncryptFinal_ex(). It may return 0 if the "encrypt-check" option is set to 0.

- -
-
"iv-generated" (OSSL_CIPHER_PARAM_AEAD_IV_GENERATED) <unsigned integer>
-
- -

An indicator that returns 1 if an IV was generated internally during encryption, or O otherwise. This may be used by GCM ciphers after calling a cipher final operation such as EVP_EncryptFinal_ex(). GCM should generate an IV internally if the IV is not specified during a cipher initialisation call such as EVP_CipherInit_ex(). See FIPS 140-3 IG C.H for information related to IV requirements.

- -
-
- -

Settable EVP_CIPHER_CTX parameters

- -

The following OSSL_PARAM(3) keys can be used with EVP_CIPHER_CTX_set_params():

- -
- -
"mackey" (OSSL_CIPHER_PARAM_AEAD_MAC_KEY) <octet string>
-
- -

Sets the MAC key used by composite AEAD ciphers such as AES-CBC-HMAC-SHA256.

- -
-
"speed" (OSSL_CIPHER_PARAM_SPEED) <unsigned integer>
-
- -

Sets the speed option for the associated cipher context. This is only supported by AES SIV ciphers which disallow multiple operations by default. Setting "speed" to 1 allows another encrypt or decrypt operation to be performed. This is used for performance testing.

- -
-
"use-bits" (OSSL_CIPHER_PARAM_USE_BITS) <unsigned integer>
-
- -

Determines if the input length inl passed to EVP_EncryptUpdate(), EVP_DecryptUpdate() and EVP_CipherUpdate() is the number of bits or number of bytes. Setting "use-bits" to 1 uses bits. The default is in bytes. This is only used for CFB1 ciphers.

- -

This can be set using EVP_CIPHER_CTX_set_flags(ctx, EVP_CIPH_FLAG_LENGTH_BITS).

- -
-
"tls-version" (OSSL_CIPHER_PARAM_TLS_VERSION) <integer>
-
- -

Sets the TLS version.

- -
-
"tls-mac-size" (OSSL_CIPHER_PARAM_TLS_MAC_SIZE) <unsigned integer>
-
- -

Set the TLS MAC size.

- -
-
"tlsaad" (OSSL_CIPHER_PARAM_AEAD_TLS1_AAD) <octet string>
-
- -

Sets TLSv1.2 AAD information for the associated cipher context ctx. TLSv1.2 AAD information is always 13 bytes in length and is as defined for the "additional_data" field described in section 6.2.3.3 of RFC5246.

- -
-
"tlsivfixed" (OSSL_CIPHER_PARAM_AEAD_TLS1_IV_FIXED) <octet string>
-
- -

Sets the fixed portion of an IV for an AEAD cipher used in a TLS record encryption/ decryption for the associated cipher context. TLS record encryption/decryption always occurs "in place" so that the input and output buffers are always the same memory location. AEAD IVs in TLSv1.2 consist of an implicit "fixed" part and an explicit part that varies with every record. Setting a TLS fixed IV changes a cipher to encrypt/decrypt TLS records. TLS records are encrypted/decrypted using a single OSSL_FUNC_cipher_cipher call per record. For a record decryption the first bytes of the input buffer will be the explicit part of the IV and the final bytes of the input buffer will be the AEAD tag. The length of the explicit part of the IV and the tag length will depend on the cipher in use and will be defined in the RFC for the relevant ciphersuite. In order to allow for "in place" decryption the plaintext output should be written to the same location in the output buffer that the ciphertext payload was read from, i.e. immediately after the explicit IV.

- -

When encrypting a record the first bytes of the input buffer should be empty to allow space for the explicit IV, as will the final bytes where the tag will be written. The length of the input buffer will include the length of the explicit IV, the payload, and the tag bytes. The cipher implementation should generate the explicit IV and write it to the beginning of the output buffer, do "in place" encryption of the payload and write that to the output buffer, and finally add the tag onto the end of the output buffer.

- -

Whether encrypting or decrypting the value written to *outl in the OSSL_FUNC_cipher_cipher call should be the length of the payload excluding the explicit IV length and the tag length.

- -
-
"tlsivinv" (OSSL_CIPHER_PARAM_AEAD_TLS1_SET_IV_INV) <octet string>
-
- -

Sets the invocation field used for decryption. Can only be called after "tlsivfixed" is set. This is only used for GCM mode.

- -
-
"tls1multi_enc" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC) <octet string>
-
- -

Triggers a multiblock TLS1 encrypt operation for a TLS1 aware cipher that supports sending 4 or 8 records in one go. The cipher performs both the MAC and encrypt stages and constructs the record headers itself. "tls1multi_enc" supplies the output buffer for the encrypt operation, "tls1multi_encin" & "tls1multi_interleave" must also be set in order to supply values to the encrypt operation.

- -
-
"tls1multi_encin" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_IN) <octet string>
-
- -

Supplies the data to encrypt for a TLS1 multiblock cipher operation.

- -
-
"tls1multi_maxsndfrag" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_SEND_FRAGMENT) <unsigned integer>
-
- -

Sets the maximum send fragment size for a TLS1 multiblock cipher operation. It must be set before using "tls1multi_maxbufsz". The length of the "tls1multi_maxsndfrag" parameter should not exceed that of a size_t.

- -
-
"tls1multi_aad" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD) <octet string>
-
- -

Sets the authenticated additional data used by a TLS1 multiblock cipher operation. The supplied data consists of 13 bytes of record data containing: Bytes 0-7: The sequence number of the first record Byte 8: The record type Byte 9-10: The protocol version Byte 11-12: Input length (Always 0)

- -

"tls1multi_interleave" must also be set for this operation.

- -
-
"xts_standard" (OSSL_CIPHER_PARAM_XTS_STANDARD) <UTF8 string>
-
- -

Sets the XTS standard to use with SM4-XTS algorithm. XTS mode has two implementations, one is standardized in IEEE Std. 1619-2007 and has been widely used (e.g., XTS AES), the other is proposed recently (GB/T 17964-2021 implemented in May 2022) and is currently only used in SM4.

- -

The main difference between them is the multiplication by the primitive element α to calculate the tweak values. The IEEE Std 1619-2007 noted that the multiplication "is a left shift of each byte by one bit with carry propagating from one byte to the next one", which means that in each byte, the leftmost bit is the most significant bit. But in GB/T 17964-2021, the rightmost bit is the most significant bit, thus the multiplication becomes a right shift of each byte by one bit with carry propagating from one byte to the next one.

- -

Valid values for the mode are:

- -
- -
"GB"
-
- -

The GB/T 17964-2021 variant of SM4-XTS algorithm.

- -
-
"IEEE"
-
- -

The IEEE Std. 1619-2007 variant of SM4-XTS algorithm.

- -
-
- -

The default value is "GB".

- -
-
"encrypt-check" (OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK) <integer>
-
- -

This option is used by the OpenSSL FIPS provider.

- -

If required this parameter should be set early via an cipher encrypt init function such as EVP_EncryptInit_ex2(). The default value of 1 causes an error when an encryption operation is triggered. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

CONTROLS

- -

The Mappings from EVP_CIPHER_CTX_ctrl() identifiers to PARAMETERS are listed in the following section. See the "PARAMETERS" section for more details.

- -

EVP_CIPHER_CTX_ctrl() can be used to send the following standard controls:

- -
- -
EVP_CTRL_AEAD_SET_IVLEN and EVP_CTRL_GET_IVLEN
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() and EVP_CIPHER_CTX_get_params() get called with an OSSL_PARAM(3) item with the key "ivlen" (OSSL_CIPHER_PARAM_IVLEN).

- -
-
EVP_CTRL_AEAD_SET_IV_FIXED
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key "tlsivfixed" (OSSL_CIPHER_PARAM_AEAD_TLS1_IV_FIXED).

- -
-
EVP_CTRL_AEAD_SET_MAC_KEY
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key "mackey" (OSSL_CIPHER_PARAM_AEAD_MAC_KEY).

- -
-
EVP_CTRL_AEAD_SET_TAG and EVP_CTRL_AEAD_GET_TAG
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() and EVP_CIPHER_CTX_get_params() get called with an OSSL_PARAM(3) item with the key "tag" (OSSL_CIPHER_PARAM_AEAD_TAG).

- -
-
EVP_CTRL_CCM_SET_L
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key "ivlen" (OSSL_CIPHER_PARAM_IVLEN) with a value of (15 - L)

- -
-
EVP_CTRL_COPY
-
- -

There is no OSSL_PARAM mapping for this. Use EVP_CIPHER_CTX_copy() instead.

- -
-
EVP_CTRL_GCM_SET_IV_INV
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key "tlsivinv" (OSSL_CIPHER_PARAM_AEAD_TLS1_SET_IV_INV).

- -
-
EVP_CTRL_RAND_KEY
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key "randkey" (OSSL_CIPHER_PARAM_RANDOM_KEY).

- -
-
EVP_CTRL_SET_KEY_LENGTH
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key "keylen" (OSSL_CIPHER_PARAM_KEYLEN).

- -
-
EVP_CTRL_SET_RC2_KEY_BITS and EVP_CTRL_GET_RC2_KEY_BITS
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() and EVP_CIPHER_CTX_get_params() get called with an OSSL_PARAM(3) item with the key "keybits" (OSSL_CIPHER_PARAM_RC2_KEYBITS).

- -
-
EVP_CTRL_SET_RC5_ROUNDS and EVP_CTRL_GET_RC5_ROUNDS
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() and EVP_CIPHER_CTX_get_params() get called with an OSSL_PARAM(3) item with the key "rounds" (OSSL_CIPHER_PARAM_ROUNDS).

- -
-
EVP_CTRL_SET_SPEED
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key "speed" (OSSL_CIPHER_PARAM_SPEED).

- -
-
EVP_CTRL_GCM_IV_GEN
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_get_params() gets called with an OSSL_PARAM(3) item with the key "tlsivgen" (OSSL_CIPHER_PARAM_AEAD_TLS1_GET_IV_GEN).

- -
-
EVP_CTRL_AEAD_TLS1_AAD
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() get called with an OSSL_PARAM(3) item with the key "tlsaad" (OSSL_CIPHER_PARAM_AEAD_TLS1_AAD) followed by EVP_CIPHER_CTX_get_params() with a key of "tlsaadpad" (OSSL_CIPHER_PARAM_AEAD_TLS1_AAD_PAD).

- -
-
EVP_CTRL_TLS1_1_MULTIBLOCK_MAX_BUFSIZE
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with an OSSL_PARAM(3) item with the key OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_SEND_FRAGMENT followed by EVP_CIPHER_CTX_get_params() with a key of "tls1multi_maxbufsz" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_BUFSIZE).

- -
-
EVP_CTRL_TLS1_1_MULTIBLOCK_AAD
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with OSSL_PARAM(3) items with the keys "tls1multi_aad" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD) and "tls1multi_interleave" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE) followed by EVP_CIPHER_CTX_get_params() with keys of "tls1multi_aadpacklen" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD_PACKLEN) and "tls1multi_interleave" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE).

- -
-
EVP_CTRL_TLS1_1_MULTIBLOCK_ENCRYPT
-
- -

When used with a fetched EVP_CIPHER, EVP_CIPHER_CTX_set_params() gets called with OSSL_PARAM(3) items with the keys "tls1multi_enc" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC), "tls1multi_encin" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_IN) and "tls1multi_interleave" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE), followed by EVP_CIPHER_CTX_get_params() with a key of "tls1multi_enclen" (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_LEN).

- -
-
- -

FLAGS

- -

EVP_CIPHER_CTX_set_flags(), EVP_CIPHER_CTX_clear_flags() and EVP_CIPHER_CTX_test_flags(). can be used to manipulate and test these EVP_CIPHER_CTX flags:

- -
- -
EVP_CIPH_NO_PADDING
-
- -

Used by EVP_CIPHER_CTX_set_padding().

- -

See also "Gettable and Settable EVP_CIPHER_CTX parameters" "padding"

- -
-
EVP_CIPH_FLAG_LENGTH_BITS
-
- -

See "Settable EVP_CIPHER_CTX parameters" "use-bits".

- -
-
EVP_CIPHER_CTX_FLAG_WRAP_ALLOW
-
- -

Used for Legacy purposes only. This flag needed to be set to indicate the cipher handled wrapping.

- -
-
- -

EVP_CIPHER_flags() uses the following flags that have mappings to "Gettable EVP_CIPHER parameters":

- -
- -
EVP_CIPH_FLAG_AEAD_CIPHER
-
- -

See "Gettable EVP_CIPHER parameters" "aead".

- -
-
EVP_CIPH_CUSTOM_IV
-
- -

See "Gettable EVP_CIPHER parameters" "custom-iv".

- -
-
EVP_CIPH_FLAG_CTS
-
- -

See "Gettable EVP_CIPHER parameters" "cts".

- -
-
EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK;
-
- -

See "Gettable EVP_CIPHER parameters" "tls-multi".

- -
-
EVP_CIPH_RAND_KEY
-
- -

See "Gettable EVP_CIPHER parameters" "has-randkey".

- -
-
- -

EVP_CIPHER_flags() uses the following flags for legacy purposes only:

- -
- -
EVP_CIPH_VARIABLE_LENGTH
-
- -
-
EVP_CIPH_FLAG_CUSTOM_CIPHER
-
- -
-
EVP_CIPH_ALWAYS_CALL_INIT
-
- -
-
EVP_CIPH_CTRL_INIT
-
- -
-
EVP_CIPH_CUSTOM_KEY_LENGTH
-
- -
-
EVP_CIPH_CUSTOM_COPY
-
- -
-
EVP_CIPH_FLAG_DEFAULT_ASN1
-
- -

See EVP_CIPHER_meth_set_flags(3) for further information related to the above flags.

- -
-
- -

RETURN VALUES

- -

EVP_CIPHER_fetch() returns a pointer to a EVP_CIPHER for success and NULL for failure.

- -

EVP_CIPHER_up_ref() returns 1 for success or 0 otherwise.

- -

EVP_CIPHER_CTX_new() returns a pointer to a newly created EVP_CIPHER_CTX for success and NULL for failure.

- -

EVP_CIPHER_CTX_dup() returns a new EVP_CIPHER_CTX if successful or NULL on failure.

- -

EVP_CIPHER_CTX_copy() returns 1 if successful or 0 for failure.

- -

EVP_EncryptInit_ex2(), EVP_EncryptUpdate() and EVP_EncryptFinal_ex() return 1 for success and 0 for failure.

- -

EVP_DecryptInit_ex2() and EVP_DecryptUpdate() return 1 for success and 0 for failure. EVP_DecryptFinal_ex() returns 0 if the decrypt failed or 1 for success.

- -

EVP_CipherInit_ex2() and EVP_CipherUpdate() return 1 for success and 0 for failure. EVP_CipherFinal_ex() returns 0 for an encryption/decryption failure or 1 for success.

- -

EVP_Cipher() returns 1 on success and <= 0 on failure, if the flag EVP_CIPH_FLAG_CUSTOM_CIPHER is not set for the cipher, or if the cipher has not been initialized via a call to EVP_CipherInit_ex2. EVP_Cipher() returns the number of bytes written to out for encryption/decryption, or the number of bytes authenticated in a call specifying AAD for an AEAD cipher, if the flag EVP_CIPH_FLAG_CUSTOM_CIPHER is set for the cipher.

- -

EVP_CIPHER_CTX_reset() returns 1 for success and 0 for failure.

- -

EVP_get_cipherbyname(), EVP_get_cipherbynid() and EVP_get_cipherbyobj() return an EVP_CIPHER structure or NULL on error.

- -

EVP_CIPHER_get_nid() and EVP_CIPHER_CTX_get_nid() return a NID.

- -

EVP_CIPHER_get_block_size() and EVP_CIPHER_CTX_get_block_size() return the block size, or 0 on error.

- -

EVP_CIPHER_get_key_length() and EVP_CIPHER_CTX_get_key_length() return the key length.

- -

EVP_CIPHER_CTX_set_padding() always returns 1.

- -

EVP_CIPHER_get_iv_length() and EVP_CIPHER_CTX_get_iv_length() return the IV length, zero if the cipher does not use an IV and a negative value on error.

- -

EVP_CIPHER_CTX_get_tag_length() return the tag length or zero if the cipher does not use a tag.

- -

EVP_CIPHER_get_type() and EVP_CIPHER_CTX_get_type() return the NID of the cipher's OBJECT IDENTIFIER or NID_undef if it has no defined OBJECT IDENTIFIER.

- -

EVP_CIPHER_CTX_cipher() returns an EVP_CIPHER structure.

- -

EVP_CIPHER_CTX_get_num() returns a nonnegative num value or EVP_CTRL_RET_UNSUPPORTED if the implementation does not support the call or on any other error.

- -

EVP_CIPHER_CTX_set_num() returns 1 on success and 0 if the implementation does not support the call or on any other error.

- -

EVP_CIPHER_CTX_is_encrypting() returns 1 if the ctx is set up for encryption 0 otherwise.

- -

EVP_CIPHER_param_to_asn1() and EVP_CIPHER_asn1_to_param() return greater than zero for success and zero or a negative number on failure.

- -

EVP_CIPHER_CTX_rand_key() returns 1 for success and zero or a negative number for failure.

- -

EVP_CIPHER_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

CIPHER LISTING

- -

All algorithms have a fixed key length unless otherwise stated.

- -

Refer to "SEE ALSO" for the full list of ciphers available through the EVP interface.

- -
- -
EVP_enc_null()
-
- -

Null cipher: does nothing.

- -
-
- -

AEAD INTERFACE

- -

The EVP interface for Authenticated Encryption with Associated Data (AEAD) modes are subtly altered and several additional ctrl operations are supported depending on the mode specified.

- -

To specify additional authenticated data (AAD), a call to EVP_CipherUpdate(), EVP_EncryptUpdate() or EVP_DecryptUpdate() should be made with the output parameter out set to NULL. In this case, on success, the parameter outl is set to the number of bytes authenticated.

- -

When decrypting, the return value of EVP_DecryptFinal() or EVP_CipherFinal() indicates whether the operation was successful. If it does not indicate success, the authentication operation has failed and any output data MUST NOT be used as it is corrupted.

- -

Please note that the number of authenticated bytes returned by EVP_CipherUpdate() depends on the cipher used. Stream ciphers, such as ChaCha20 or ciphers in GCM mode, can handle 1 byte at a time, resulting in an effective "block" size of 1. Conversely, ciphers in OCB mode must process data one block at a time, and the block size is returned.

- -

Regardless of the returned size, it is safe to pass unpadded data to an EVP_CipherUpdate() call in a single operation.

- -

GCM and OCB Modes

- -

The following ctrls are supported in GCM and OCB modes.

- -
- -
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, ivlen, NULL)
-
- -

Sets the IV length. This call can only be made before specifying an IV. If not called a default IV length is used.

- -

For GCM AES and OCB AES the default is 12 (i.e. 96 bits). For OCB mode the maximum is 15.

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, taglen, tag)
-
- -

Writes taglen bytes of the tag value to the buffer indicated by tag. This call can only be made when encrypting data and after all data has been processed (e.g. after an EVP_EncryptFinal() call).

- -

For OCB, taglen must either be 16 or the value previously set via EVP_CTRL_AEAD_SET_TAG.

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag)
-
- -

When decrypting, this call sets the expected tag to taglen bytes from tag. taglen must be between 1 and 16 inclusive. The tag must be set prior to any call to EVP_DecryptFinal() or EVP_DecryptFinal_ex().

- -

For GCM, this call is only valid when decrypting data.

- -

For OCB, this call is valid when decrypting data to set the expected tag, and when encrypting to set the desired tag length.

- -

In OCB mode, calling this with tag set to NULL sets the tag length. The tag length can only be set before specifying an IV. If this is not called prior to setting the IV, then a default tag length is used.

- -

For OCB AES, the default tag length is 16 (i.e. 128 bits). It is also the maximum tag length for OCB.

- -
-
- -

CCM Mode

- -

The EVP interface for CCM mode is similar to that of the GCM mode but with a few additional requirements and different ctrl values.

- -

For CCM mode, the total plaintext or ciphertext length MUST be passed to EVP_CipherUpdate(), EVP_EncryptUpdate() or EVP_DecryptUpdate() with the output and input parameters (in and out) set to NULL and the length passed in the inl parameter.

- -

The following ctrls are supported in CCM mode.

- -
- -
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag)
-
- -

This call is made to set the expected CCM tag value when decrypting or the length of the tag (with the tag parameter set to NULL) when encrypting. The tag length is often referred to as M. If not set a default value is used (12 for AES). When decrypting, the tag needs to be set before passing in data to be decrypted, but as in GCM and OCB mode, it can be set after passing additional authenticated data (see "AEAD INTERFACE").

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_CCM_SET_L, ivlen, NULL)
-
- -

Sets the CCM L value. If not set a default is used (8 for AES).

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, ivlen, NULL)
-
- -

Sets the CCM nonce (IV) length. This call can only be made before specifying a nonce value. The nonce length is given by 15 - L so it is 7 by default for AES.

- -
-
- -

SIV Mode

- -

Both the AES-SIV and AES-GCM-SIV ciphers fall under this mode.

- -

For SIV mode ciphers the behaviour of the EVP interface is subtly altered and several additional ctrl operations are supported.

- -

To specify any additional authenticated data (AAD) and/or a Nonce, a call to EVP_CipherUpdate(), EVP_EncryptUpdate() or EVP_DecryptUpdate() should be made with the output parameter out set to NULL.

- -

RFC5297 states that the Nonce is the last piece of AAD before the actual encrypt/decrypt takes place. The API does not differentiate the Nonce from other AAD.

- -

When decrypting the return value of EVP_DecryptFinal() or EVP_CipherFinal() indicates if the operation was successful. If it does not indicate success the authentication operation has failed and any output data MUST NOT be used as it is corrupted.

- -

The API does not store the SIV (Synthetic Initialization Vector) in the cipher text. Instead, it is stored as the tag within the EVP_CIPHER_CTX. The SIV must be retrieved from the context after encryption, and set into the context before decryption.

- -

This differs from RFC5297 in that the cipher output from encryption, and the cipher input to decryption, does not contain the SIV. This also means that the plain text and cipher text lengths are identical.

- -

The following ctrls are supported in SIV mode, and are used to get and set the Synthetic Initialization Vector:

- -
- -
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, taglen, tag);
-
- -

Writes taglen bytes of the tag value (the Synthetic Initialization Vector) to the buffer indicated by tag. This call can only be made when encrypting data and after all data has been processed (e.g. after an EVP_EncryptFinal() call). For SIV mode the taglen must be 16.

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag);
-
- -

Sets the expected tag (the Synthetic Initialization Vector) to taglen bytes from tag. This call is only legal when decrypting data and must be made before any data is processed (e.g. before any EVP_DecryptUpdate() calls). For SIV mode the taglen must be 16.

- -
-
- -

SIV mode makes two passes over the input data, thus, only one call to EVP_CipherUpdate(), EVP_EncryptUpdate() or EVP_DecryptUpdate() should be made with out set to a non-NULL value. A call to EVP_DecryptFinal() or EVP_CipherFinal() is not required, but will indicate if the update operation succeeded.

- -

ChaCha20-Poly1305

- -

The following ctrls are supported for the ChaCha20-Poly1305 AEAD algorithm.

- -
- -
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, ivlen, NULL)
-
- -

Sets the nonce length. This call is now redundant since the only valid value is the default length of 12 (i.e. 96 bits). Prior to OpenSSL 3.0 a nonce of less than 12 bytes could be used to automatically pad the iv with leading 0 bytes to make it 12 bytes in length.

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, taglen, tag)
-
- -

Writes taglen bytes of the tag value to the buffer indicated by tag. This call can only be made when encrypting data and after all data has been processed (e.g. after an EVP_EncryptFinal() call).

- -

taglen specified here must be 16 (POLY1305_BLOCK_SIZE, i.e. 128-bits) or less.

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag)
-
- -

Sets the expected tag to taglen bytes from tag. The tag length can only be set before specifying an IV. taglen must be between 1 and 16 (POLY1305_BLOCK_SIZE) inclusive. This call is only valid when decrypting data.

- -
-
- -

NOTES

- -

Where possible the EVP interface to symmetric ciphers should be used in preference to the low-level interfaces. This is because the code then becomes transparent to the cipher used and much more flexible. Additionally, the EVP interface will ensure the use of platform specific cryptographic acceleration such as AES-NI (the low-level interfaces do not provide the guarantee).

- -

PKCS padding works by adding n padding bytes of value n to make the total length of the encrypted data a multiple of the block size. Padding is always added so if the data is already a multiple of the block size n will equal the block size. For example if the block size is 8 and 11 bytes are to be encrypted then 5 padding bytes of value 5 will be added.

- -

When decrypting the final block is checked to see if it has the correct form.

- -

Although the decryption operation can produce an error if padding is enabled, it is not a strong test that the input data or key is correct. A random block has better than 1 in 256 chance of being of the correct format and problems with the input data earlier on will not produce a final decrypt error.

- -

If padding is disabled then the decryption operation will always succeed if the total amount of data decrypted is a multiple of the block size.

- -

The functions EVP_EncryptInit(), EVP_EncryptInit_ex(), EVP_EncryptFinal(), EVP_DecryptInit(), EVP_DecryptInit_ex(), EVP_CipherInit(), EVP_CipherInit_ex() and EVP_CipherFinal() are obsolete but are retained for compatibility with existing code. New code should use EVP_EncryptInit_ex2(), EVP_EncryptFinal_ex(), EVP_DecryptInit_ex2(), EVP_DecryptFinal_ex(), EVP_CipherInit_ex2() and EVP_CipherFinal_ex() because they can reuse an existing context without allocating and freeing it up on each call.

- -

There are some differences between functions EVP_CipherInit() and EVP_CipherInit_ex(), significant in some circumstances. EVP_CipherInit() fills the passed context object with zeros. As a consequence, EVP_CipherInit() does not allow step-by-step initialization of the ctx when the key and iv are passed in separate calls. It also means that the flags set for the CTX are removed, and it is especially important for the EVP_CIPHER_CTX_FLAG_WRAP_ALLOW flag treated specially in EVP_CipherInit_ex().

- -

Ignoring failure returns of the EVP_CIPHER_CTX initialization functions can lead to subsequent undefined behavior when calling the functions that update or finalize the context. The only valid calls on the EVP_CIPHER_CTX when initialization fails are calls that attempt another initialization of the context or release the context.

- -

EVP_get_cipherbynid(), and EVP_get_cipherbyobj() are implemented as macros.

- -

BUGS

- -

EVP_MAX_KEY_LENGTH and EVP_MAX_IV_LENGTH only refer to the internal ciphers with default key lengths. If custom ciphers exceed these values the results are unpredictable. This is because it has become standard practice to define a generic key as a fixed unsigned char array containing EVP_MAX_KEY_LENGTH bytes.

- -

The ASN1 code is incomplete (and sometimes inaccurate) it has only been tested for certain common S/MIME ciphers (RC2, DES, triple DES) in CBC mode.

- -

EXAMPLES

- -

Encrypt a string using IDEA:

- -
int do_crypt(char *outfile)
-{
-    unsigned char outbuf[1024];
-    int outlen, tmplen;
-    /*
-     * Bogus key and IV: we'd normally set these from
-     * another source.
-     */
-    unsigned char key[] = {0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15};
-    unsigned char iv[] = {1,2,3,4,5,6,7,8};
-    char intext[] = "Some Crypto Text";
-    EVP_CIPHER_CTX *ctx;
-    FILE *out;
-
-    ctx = EVP_CIPHER_CTX_new();
-    if (!EVP_EncryptInit_ex2(ctx, EVP_idea_cbc(), key, iv, NULL)) {
-        /* Error */
-        EVP_CIPHER_CTX_free(ctx);
-        return 0;
-    }
-
-    if (!EVP_EncryptUpdate(ctx, outbuf, &outlen, intext, strlen(intext))) {
-        /* Error */
-        EVP_CIPHER_CTX_free(ctx);
-        return 0;
-    }
-    /*
-     * Buffer passed to EVP_EncryptFinal() must be after data just
-     * encrypted to avoid overwriting it.
-     */
-    if (!EVP_EncryptFinal_ex(ctx, outbuf + outlen, &tmplen)) {
-        /* Error */
-        EVP_CIPHER_CTX_free(ctx);
-        return 0;
-    }
-    outlen += tmplen;
-    EVP_CIPHER_CTX_free(ctx);
-    /*
-     * Need binary mode for fopen because encrypted data is
-     * binary data. Also cannot use strlen() on it because
-     * it won't be NUL terminated and may contain embedded
-     * NULs.
-     */
-    out = fopen(outfile, "wb");
-    if (out == NULL) {
-        /* Error */
-        return 0;
-    }
-    fwrite(outbuf, 1, outlen, out);
-    fclose(out);
-    return 1;
-}
- -

The ciphertext from the above example can be decrypted using the openssl utility with the command line (shown on two lines for clarity):

- -
openssl idea -d \
-    -K 000102030405060708090A0B0C0D0E0F -iv 0102030405060708 <filename
- -

General encryption and decryption function example using FILE I/O and AES128 with a 128-bit key:

- -
int do_crypt(FILE *in, FILE *out, int do_encrypt)
-{
-    /* Allow enough space in output buffer for additional block */
-    unsigned char inbuf[1024], outbuf[1024 + EVP_MAX_BLOCK_LENGTH];
-    int inlen, outlen;
-    EVP_CIPHER_CTX *ctx;
-    /*
-     * Bogus key and IV: we'd normally set these from
-     * another source.
-     */
-    unsigned char key[] = "0123456789abcdeF";
-    unsigned char iv[] = "1234567887654321";
-
-    /* Don't set key or IV right away; we want to check lengths */
-    ctx = EVP_CIPHER_CTX_new();
-    if (!EVP_CipherInit_ex2(ctx, EVP_aes_128_cbc(), NULL, NULL,
-                            do_encrypt, NULL)) {
-        /* Error */
-        EVP_CIPHER_CTX_free(ctx);
-        return 0;
-    }
-    OPENSSL_assert(EVP_CIPHER_CTX_get_key_length(ctx) == 16);
-    OPENSSL_assert(EVP_CIPHER_CTX_get_iv_length(ctx) == 16);
-
-    /* Now we can set key and IV */
-    if (!EVP_CipherInit_ex2(ctx, NULL, key, iv, do_encrypt, NULL)) {
-        /* Error */
-        EVP_CIPHER_CTX_free(ctx);
-        return 0;
-    }
-
-    for (;;) {
-        inlen = fread(inbuf, 1, 1024, in);
-        if (inlen <= 0)
-            break;
-        if (!EVP_CipherUpdate(ctx, outbuf, &outlen, inbuf, inlen)) {
-            /* Error */
-            EVP_CIPHER_CTX_free(ctx);
-            return 0;
-        }
-        fwrite(outbuf, 1, outlen, out);
-    }
-    if (!EVP_CipherFinal_ex(ctx, outbuf, &outlen)) {
-        /* Error */
-        EVP_CIPHER_CTX_free(ctx);
-        return 0;
-    }
-    fwrite(outbuf, 1, outlen, out);
-
-    EVP_CIPHER_CTX_free(ctx);
-    return 1;
-}
- -

Encryption using AES-CBC with a 256-bit key with "CS1" ciphertext stealing.

- -
int encrypt(const unsigned char *key, const unsigned char *iv,
-            const unsigned char *msg, size_t msg_len, unsigned char *out)
-{
-   /*
-    * This assumes that key size is 32 bytes and the iv is 16 bytes.
-    * For ciphertext stealing mode the length of the ciphertext "out" will be
-    * the same size as the plaintext size "msg_len".
-    * The "msg_len" can be any size >= 16.
-    */
-    int ret = 0, encrypt = 1, outlen, len;
-    EVP_CIPHER_CTX *ctx = NULL;
-    EVP_CIPHER *cipher = NULL;
-    OSSL_PARAM params[2];
-
-    ctx = EVP_CIPHER_CTX_new();
-    cipher = EVP_CIPHER_fetch(NULL, "AES-256-CBC-CTS", NULL);
-    if (ctx == NULL || cipher == NULL)
-        goto err;
-
-    /*
-     * The default is "CS1" so this is not really needed,
-     * but would be needed to set either "CS2" or "CS3".
-     */
-    params[0] = OSSL_PARAM_construct_utf8_string(OSSL_CIPHER_PARAM_CTS_MODE,
-                                                 "CS1", 0);
-    params[1] = OSSL_PARAM_construct_end();
-
-    if (!EVP_CipherInit_ex2(ctx, cipher, key, iv, encrypt, params))
-        goto err;
-
-    /* NOTE: CTS mode does not support multiple calls to EVP_CipherUpdate() */
-    if (!EVP_CipherUpdate(ctx, out, &outlen, msg, msg_len))
-        goto err;
-     if (!EVP_CipherFinal_ex(ctx, out + outlen, &len))
-        goto err;
-    ret = 1;
-err:
-    EVP_CIPHER_free(cipher);
-    EVP_CIPHER_CTX_free(ctx);
-    return ret;
-}
- -

SEE ALSO

- -

evp(7), property(7), "ALGORITHM FETCHING" in crypto(7), provider-cipher(7), life_cycle-cipher(7)

- -

Supported ciphers are listed in:

- -

EVP_aes_128_gcm(3), EVP_aria_128_gcm(3), EVP_bf_cbc(3), EVP_camellia_128_ecb(3), EVP_cast5_cbc(3), EVP_chacha20(3), EVP_des_cbc(3), EVP_desx_cbc(3), EVP_idea_cbc(3), EVP_rc2_cbc(3), EVP_rc4(3), EVP_rc5_32_12_16_cbc(3), EVP_seed_cbc(3), EVP_sm4_cbc(3),

- -

HISTORY

- -

Support for OCB mode was added in OpenSSL 1.1.0.

- -

EVP_CIPHER_CTX was made opaque in OpenSSL 1.1.0. As a result, EVP_CIPHER_CTX_reset() appeared and EVP_CIPHER_CTX_cleanup() disappeared. EVP_CIPHER_CTX_init() remains as an alias for EVP_CIPHER_CTX_reset().

- -

The EVP_CIPHER_CTX_cipher() function was deprecated in OpenSSL 3.0; use EVP_CIPHER_CTX_get0_cipher() instead.

- -

The EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), EVP_CipherInit_ex2(), EVP_CIPHER_fetch(), EVP_CIPHER_free(), EVP_CIPHER_up_ref(), EVP_CIPHER_CTX_get0_cipher(), EVP_CIPHER_CTX_get1_cipher(), EVP_CIPHER_get_params(), EVP_CIPHER_CTX_set_params(), EVP_CIPHER_CTX_get_params(), EVP_CIPHER_gettable_params(), EVP_CIPHER_settable_ctx_params(), EVP_CIPHER_gettable_ctx_params(), EVP_CIPHER_CTX_settable_params() and EVP_CIPHER_CTX_gettable_params() functions were added in 3.0.

- -

The EVP_CIPHER_nid(), EVP_CIPHER_name(), EVP_CIPHER_block_size(), EVP_CIPHER_key_length(), EVP_CIPHER_iv_length(), EVP_CIPHER_flags(), EVP_CIPHER_mode(), EVP_CIPHER_type(), EVP_CIPHER_CTX_nid(), EVP_CIPHER_CTX_block_size(), EVP_CIPHER_CTX_key_length(), EVP_CIPHER_CTX_iv_length(), EVP_CIPHER_CTX_tag_length(), EVP_CIPHER_CTX_num(), EVP_CIPHER_CTX_type(), and EVP_CIPHER_CTX_mode() functions were renamed to include get or get0 in their names in OpenSSL 3.0, respectively. The old names are kept as non-deprecated alias macros.

- -

The EVP_CIPHER_CTX_encrypting() function was renamed to EVP_CIPHER_CTX_is_encrypting() in OpenSSL 3.0. The old name is kept as non-deprecated alias macro.

- -

The EVP_CIPHER_CTX_flags() macro was deprecated in OpenSSL 1.1.0.

- -

EVP_CIPHER_CTX_dup() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_KDF.html b/openssl-install/share/doc/openssl/html/man3/EVP_KDF.html deleted file mode 100644 index e3a86296..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_KDF.html +++ /dev/null @@ -1,266 +0,0 @@ - - - - -EVP_KDF - - - - - - - - - - -

NAME

- -

EVP_KDF, EVP_KDF_fetch, EVP_KDF_free, EVP_KDF_up_ref, EVP_KDF_CTX, EVP_KDF_CTX_new, EVP_KDF_CTX_free, EVP_KDF_CTX_dup, EVP_KDF_CTX_reset, EVP_KDF_derive, EVP_KDF_CTX_get_kdf_size, EVP_KDF_get0_provider, EVP_KDF_CTX_kdf, EVP_KDF_is_a, EVP_KDF_get0_name, EVP_KDF_names_do_all, EVP_KDF_get0_description, EVP_KDF_CTX_get_params, EVP_KDF_CTX_set_params, EVP_KDF_do_all_provided, EVP_KDF_get_params, EVP_KDF_gettable_params, EVP_KDF_gettable_ctx_params, EVP_KDF_settable_ctx_params, EVP_KDF_CTX_gettable_params, EVP_KDF_CTX_settable_params - EVP KDF routines

- -

SYNOPSIS

- -
#include <openssl/kdf.h>
-
-typedef struct evp_kdf_st EVP_KDF;
-typedef struct evp_kdf_ctx_st EVP_KDF_CTX;
-
-EVP_KDF_CTX *EVP_KDF_CTX_new(EVP_KDF *kdf);
-const EVP_KDF *EVP_KDF_CTX_kdf(EVP_KDF_CTX *ctx);
-void EVP_KDF_CTX_free(EVP_KDF_CTX *ctx);
-EVP_KDF_CTX *EVP_KDF_CTX_dup(const EVP_KDF_CTX *src);
-void EVP_KDF_CTX_reset(EVP_KDF_CTX *ctx);
-size_t EVP_KDF_CTX_get_kdf_size(EVP_KDF_CTX *ctx);
-int EVP_KDF_derive(EVP_KDF_CTX *ctx, unsigned char *key, size_t keylen,
-                   const OSSL_PARAM params[]);
-int EVP_KDF_up_ref(EVP_KDF *kdf);
-void EVP_KDF_free(EVP_KDF *kdf);
-EVP_KDF *EVP_KDF_fetch(OSSL_LIB_CTX *libctx, const char *algorithm,
-                       const char *properties);
-int EVP_KDF_is_a(const EVP_KDF *kdf, const char *name);
-const char *EVP_KDF_get0_name(const EVP_KDF *kdf);
-const char *EVP_KDF_get0_description(const EVP_KDF *kdf);
-const OSSL_PROVIDER *EVP_KDF_get0_provider(const EVP_KDF *kdf);
-void EVP_KDF_do_all_provided(OSSL_LIB_CTX *libctx,
-                             void (*fn)(EVP_KDF *kdf, void *arg),
-                             void *arg);
-int EVP_KDF_names_do_all(const EVP_KDF *kdf,
-                         void (*fn)(const char *name, void *data),
-                         void *data);
-int EVP_KDF_get_params(EVP_KDF *kdf, OSSL_PARAM params[]);
-int EVP_KDF_CTX_get_params(EVP_KDF_CTX *ctx, OSSL_PARAM params[]);
-int EVP_KDF_CTX_set_params(EVP_KDF_CTX *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *EVP_KDF_gettable_params(const EVP_KDF *kdf);
-const OSSL_PARAM *EVP_KDF_gettable_ctx_params(const EVP_KDF *kdf);
-const OSSL_PARAM *EVP_KDF_settable_ctx_params(const EVP_KDF *kdf);
-const OSSL_PARAM *EVP_KDF_CTX_gettable_params(const EVP_KDF *kdf);
-const OSSL_PARAM *EVP_KDF_CTX_settable_params(const EVP_KDF *kdf);
-const OSSL_PROVIDER *EVP_KDF_get0_provider(const EVP_KDF *kdf);
- -

DESCRIPTION

- -

The EVP KDF routines are a high-level interface to Key Derivation Function algorithms and should be used instead of algorithm-specific functions.

- -

After creating a EVP_KDF_CTX for the required algorithm using EVP_KDF_CTX_new(), inputs to the algorithm are supplied either by passing them as part of the EVP_KDF_derive() call or using calls to EVP_KDF_CTX_set_params() before calling EVP_KDF_derive() to derive the key.

- -

Types

- -

EVP_KDF is a type that holds the implementation of a KDF.

- -

EVP_KDF_CTX is a context type that holds the algorithm inputs.

- -

Algorithm implementation fetching

- -

EVP_KDF_fetch() fetches an implementation of a KDF algorithm, given a library context libctx and a set of properties. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

See "Key Derivation Function (KDF)" in OSSL_PROVIDER-default(7) for the lists of algorithms supported by the default provider.

- -

The returned value must eventually be freed with EVP_KDF_free(3).

- -

EVP_KDF_up_ref() increments the reference count of an already fetched KDF.

- -

EVP_KDF_free() frees a fetched algorithm. NULL is a valid parameter, for which this function is a no-op.

- -

Context manipulation functions

- -

EVP_KDF_CTX_new() creates a new context for the KDF implementation kdf.

- -

EVP_KDF_CTX_free() frees up the context ctx. If ctx is NULL, nothing is done.

- -

EVP_KDF_CTX_kdf() returns the EVP_KDF associated with the context ctx.

- -

Computing functions

- -

EVP_KDF_CTX_reset() resets the context to the default state as if the context had just been created.

- -

EVP_KDF_derive() processes any parameters in Params and then derives keylen bytes of key material and places it in the key buffer. If the algorithm produces a fixed amount of output then an error will occur unless the keylen parameter is equal to that output size, as returned by EVP_KDF_CTX_get_kdf_size().

- -

EVP_KDF_get_params() retrieves details about the implementation kdf. The set of parameters given with params determine exactly what parameters should be retrieved. Note that a parameter that is unknown in the underlying context is simply ignored.

- -

EVP_KDF_CTX_get_params() retrieves chosen parameters, given the context ctx and its underlying context. The set of parameters given with params determine exactly what parameters should be retrieved. Note that a parameter that is unknown in the underlying context is simply ignored.

- -

EVP_KDF_CTX_set_params() passes chosen parameters to the underlying context, given a context ctx. The set of parameters given with params determine exactly what parameters are passed down. Note that a parameter that is unknown in the underlying context is simply ignored. Also, what happens when a needed parameter isn't passed down is defined by the implementation.

- -

EVP_KDF_gettable_params() returns an OSSL_PARAM(3) array that describes the retrievable and settable parameters. EVP_KDF_gettable_params() returns parameters that can be used with EVP_KDF_get_params().

- -

EVP_KDF_gettable_ctx_params() and EVP_KDF_CTX_gettable_params() return constant OSSL_PARAM(3) arrays that describe the retrievable parameters that can be used with EVP_KDF_CTX_get_params(). EVP_KDF_gettable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_KDF_CTX_gettable_params() returns the parameters that can be retrieved in the context's current state.

- -

EVP_KDF_settable_ctx_params() and EVP_KDF_CTX_settable_params() return constant OSSL_PARAM(3) arrays that describe the settable parameters that can be used with EVP_KDF_CTX_set_params(). EVP_KDF_settable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_KDF_CTX_settable_params() returns the parameters that can be retrieved in the context's current state.

- -

Information functions

- -

EVP_KDF_CTX_get_kdf_size() returns the output size if the algorithm produces a fixed amount of output and SIZE_MAX otherwise. If an error occurs then 0 is returned. For some algorithms an error may result if input parameters necessary to calculate a fixed output size have not yet been supplied.

- -

EVP_KDF_is_a() returns 1 if kdf is an implementation of an algorithm that's identifiable with name, otherwise 0.

- -

EVP_KDF_get0_provider() returns the provider that holds the implementation of the given kdf.

- -

EVP_KDF_do_all_provided() traverses all KDF implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -

EVP_KDF_get0_name() return the name of the given KDF. For fetched KDFs with multiple names, only one of them is returned; it's recommended to use EVP_KDF_names_do_all() instead.

- -

EVP_KDF_names_do_all() traverses all names for kdf, and calls fn with each name and data.

- -

EVP_KDF_get0_description() returns a description of the kdf, meant for display and human consumption. The description is at the discretion of the kdf implementation.

- -

PARAMETERS

- -

The standard parameter names are:

- -
- -
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -

Some KDF implementations require a password. For those KDF implementations that support it, this parameter sets the password.

- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -

Some KDF implementations can take a non-secret unique cryptographic salt. For those KDF implementations that support it, this parameter sets the salt.

- -

The default value, if any, is implementation dependent.

- -
-
"iter" (OSSL_KDF_PARAM_ITER) <unsigned integer>
-
- -

Some KDF implementations require an iteration count. For those KDF implementations that support it, this parameter sets the iteration count.

- -

The default value, if any, is implementation dependent.

- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"mac" (OSSL_KDF_PARAM_MAC) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -
-
"cipher" (OSSL_KDF_PARAM_CIPHER) <UTF8 string>
-
- -

For KDF implementations that use an underlying computation MAC, digest or cipher, these parameters set what the algorithm should be.

- -

The value is always the name of the intended algorithm, or the properties.

- -

Note that not all algorithms may support all possible underlying implementations.

- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -

Some KDF implementations require a key. For those KDF implementations that support it, this octet string parameter sets the key.

- -
-
"info" (OSSL_KDF_PARAM_INFO) <octet string>
-
- -

Some KDF implementations, such as EVP_KDF-HKDF(7), take an 'info' parameter for binding the derived key material to application- and context-specific information. This parameter sets the info, fixed info, other info or shared info argument. You can specify this parameter multiple times, and each instance will be concatenated to form the final value.

- -
-
"maclen" (OSSL_KDF_PARAM_MAC_SIZE) <unsigned integer>
-
- -

Used by implementations that use a MAC with a variable output size (KMAC). For those KDF implementations that support it, this parameter sets the MAC output size.

- -

The default value, if any, is implementation dependent. The length must never exceed what can be given with a size_t.

- -
-
"maxmem_bytes" (OSSL_KDF_PARAM_SCRYPT_MAXMEM) <unsigned integer>
-
- -

Memory-hard password-based KDF algorithms, such as scrypt, use an amount of memory that depends on the load factors provided as input. For those KDF implementations that support it, this uint64_t parameter sets an upper limit on the amount of memory that may be consumed while performing a key derivation. If this memory usage limit is exceeded because the load factors are chosen too high, the key derivation will fail.

- -

The default value is implementation dependent. The memory size must never exceed what can be given with a size_t.

- -
-
- -

RETURN VALUES

- -

EVP_KDF_fetch() returns a pointer to a newly fetched EVP_KDF, or NULL if allocation failed.

- -

EVP_KDF_get0_provider() returns a pointer to the provider for the KDF, or NULL on error.

- -

EVP_KDF_up_ref() returns 1 on success, 0 on error.

- -

EVP_KDF_CTX_new() returns either the newly allocated EVP_KDF_CTX structure or NULL if an error occurred.

- -

EVP_KDF_CTX_free() and EVP_KDF_CTX_reset() do not return a value.

- -

EVP_KDF_CTX_get_kdf_size() returns the output size. SIZE_MAX is returned to indicate that the algorithm produces a variable amount of output; 0 to indicate failure.

- -

EVP_KDF_get0_name() returns the name of the KDF, or NULL on error.

- -

EVP_KDF_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

The remaining functions return 1 for success and 0 or a negative value for failure. In particular, a return value of -2 indicates the operation is not supported by the KDF algorithm.

- -

NOTES

- -

The KDF life-cycle is described in life_cycle-kdf(7). In the future, the transitions described there will be enforced. When this is done, it will not be considered a breaking change to the API.

- -

SEE ALSO

- -

"Key Derivation Function (KDF)" in OSSL_PROVIDER-default(7), life_cycle-kdf(7).

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_KEM_free.html b/openssl-install/share/doc/openssl/html/man3/EVP_KEM_free.html deleted file mode 100644 index 0317d2c1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_KEM_free.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -EVP_KEM_free - - - - - - - - - - -

NAME

- -

EVP_KEM_fetch, EVP_KEM_free, EVP_KEM_up_ref, EVP_KEM_get0_name, EVP_KEM_is_a, EVP_KEM_get0_provider, EVP_KEM_do_all_provided, EVP_KEM_names_do_all, EVP_KEM_get0_description, EVP_KEM_gettable_ctx_params, EVP_KEM_settable_ctx_params - Functions to manage EVP_KEM algorithm objects

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_KEM *EVP_KEM_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-                       const char *properties);
-void EVP_KEM_free(EVP_KEM *kem);
-int EVP_KEM_up_ref(EVP_KEM *kem);
-const char *EVP_KEM_get0_name(const EVP_KEM *kem);
-int EVP_KEM_is_a(const EVP_KEM *kem, const char *name);
-OSSL_PROVIDER *EVP_KEM_get0_provider(const EVP_KEM *kem);
-void EVP_KEM_do_all_provided(OSSL_LIB_CTX *libctx,
-                             void (*fn)(EVP_KEM *kem, void *arg), void *arg);
-int EVP_KEM_names_do_all(const EVP_KEM *kem,
-                         void (*fn)(const char *name, void *data), void *data);
-const char *EVP_KEM_get0_description(const EVP_KEM *kem);
-const OSSL_PARAM *EVP_KEM_gettable_ctx_params(const EVP_KEM *kem);
-const OSSL_PARAM *EVP_KEM_settable_ctx_params(const EVP_KEM *kem);
- -

DESCRIPTION

- -

EVP_KEM_fetch() fetches the implementation for the given algorithm from any provider offering it, within the criteria given by the properties and in the scope of the given library context ctx (see OSSL_LIB_CTX(3)). The algorithm will be one offering functions for performing asymmetric kem related tasks such as key encapsulation and decapsulation. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

The returned value must eventually be freed with EVP_KEM_free().

- -

EVP_KEM_free() decrements the reference count for the EVP_KEM structure. Typically this structure will have been obtained from an earlier call to EVP_KEM_fetch(). If the reference count drops to 0 then the structure is freed. If the argument is NULL, nothing is done.

- -

EVP_KEM_up_ref() increments the reference count for an EVP_KEM structure.

- -

EVP_KEM_is_a() returns 1 if kem is an implementation of an algorithm that's identifiable with name, otherwise 0.

- -

EVP_KEM_get0_provider() returns the provider that kem was fetched from.

- -

EVP_KEM_do_all_provided() traverses all EVP_KEMs implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -

EVP_KEM_get0_name() returns the algorithm name from the provided implementation for the given kem. Note that the kem may have multiple synonyms associated with it. In this case the first name from the algorithm definition is returned. Ownership of the returned string is retained by the kem object and should not be freed by the caller.

- -

EVP_KEM_names_do_all() traverses all names for kem, and calls fn with each name and data.

- -

EVP_KEM_get0_description() returns a description of the kem, meant for display and human consumption. The description is at the discretion of the kem implementation.

- -

EVP_KEM_gettable_ctx_params() and EVP_KEM_settable_ctx_params() return a constant OSSL_PARAM(3) array that describes the names and types of key parameters that can be retrieved or set by a key encapsulation algorithm using EVP_PKEY_CTX_get_params(3) and EVP_PKEY_CTX_set_params(3).

- -

RETURN VALUES

- -

EVP_KEM_fetch() returns a pointer to an EVP_KEM for success or NULL for failure.

- -

EVP_KEM_up_ref() returns 1 for success or 0 otherwise.

- -

EVP_KEM_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EVP_KEM_gettable_ctx_params() and EVP_KEM_settable_ctx_params() return a constant OSSL_PARAM(3) array or NULL on error.

- -

SEE ALSO

- -

"ALGORITHM FETCHING" in crypto(7), OSSL_PROVIDER(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_KEYEXCH_free.html b/openssl-install/share/doc/openssl/html/man3/EVP_KEYEXCH_free.html deleted file mode 100644 index 946fae75..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_KEYEXCH_free.html +++ /dev/null @@ -1,104 +0,0 @@ - - - - -EVP_KEYEXCH_free - - - - - - - - - - -

NAME

- -

EVP_KEYEXCH_fetch, EVP_KEYEXCH_free, EVP_KEYEXCH_up_ref, EVP_KEYEXCH_get0_provider, EVP_KEYEXCH_is_a, EVP_KEYEXCH_do_all_provided, EVP_KEYEXCH_names_do_all, EVP_KEYEXCH_get0_name, EVP_KEYEXCH_get0_description, EVP_KEYEXCH_gettable_ctx_params, EVP_KEYEXCH_settable_ctx_params - Functions to manage EVP_KEYEXCH algorithm objects

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_KEYEXCH *EVP_KEYEXCH_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-                               const char *properties);
-void EVP_KEYEXCH_free(EVP_KEYEXCH *exchange);
-int EVP_KEYEXCH_up_ref(EVP_KEYEXCH *exchange);
-OSSL_PROVIDER *EVP_KEYEXCH_get0_provider(const EVP_KEYEXCH *exchange);
-int EVP_KEYEXCH_is_a(const EVP_KEYEXCH *exchange, const char *name);
-const char *EVP_KEYEXCH_get0_name(const EVP_KEYEXCH *exchange);
-void EVP_KEYEXCH_do_all_provided(OSSL_LIB_CTX *libctx,
-                                 void (*fn)(EVP_KEYEXCH *exchange, void *arg),
-                                 void *arg);
-int EVP_KEYEXCH_names_do_all(const EVP_KEYEXCH *exchange,
-                             void (*fn)(const char *name, void *data),
-                             void *data);
-const char *EVP_KEYEXCH_get0_description(const EVP_KEYEXCH *keyexch);
-const OSSL_PARAM *EVP_KEYEXCH_gettable_ctx_params(const EVP_KEYEXCH *keyexch);
-const OSSL_PARAM *EVP_KEYEXCH_settable_ctx_params(const EVP_KEYEXCH *keyexch);
- -

DESCRIPTION

- -

EVP_KEYEXCH_fetch() fetches the key exchange implementation for the given algorithm from any provider offering it, within the criteria given by the properties. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

The returned value must eventually be freed with EVP_KEYEXCH_free().

- -

EVP_KEYEXCH_free() decrements the reference count for the EVP_KEYEXCH structure. Typically this structure will have been obtained from an earlier call to EVP_KEYEXCH_fetch(). If the reference count drops to 0 then the structure is freed. If the argument is NULL, nothing is done.

- -

EVP_KEYEXCH_up_ref() increments the reference count for an EVP_KEYEXCH structure.

- -

EVP_KEYEXCH_get0_provider() returns the provider that exchange was fetched from.

- -

EVP_KEYEXCH_is_a() checks if exchange is an implementation of an algorithm that's identifiable with name.

- -

EVP_KEYEXCH_get0_name() returns the algorithm name from the provided implementation for the given exchange. Note that the exchange may have multiple synonyms associated with it. In this case the first name from the algorithm definition is returned. Ownership of the returned string is retained by the exchange object and should not be freed by the caller.

- -

EVP_KEYEXCH_names_do_all() traverses all names for the exchange, and calls fn with each name and data.

- -

EVP_KEYEXCH_get0_description() returns a description of the keyexch, meant for display and human consumption. The description is at the discretion of the keyexch implementation.

- -

EVP_KEYEXCH_do_all_provided() traverses all key exchange implementations by all activated providers in the library context libctx, and for each of the implementations, calls fn with the implementation method and data as arguments.

- -

EVP_KEYEXCH_gettable_ctx_params() and EVP_KEYEXCH_settable_ctx_params() return a constant OSSL_PARAM(3) array that describes the names and types of key parameters that can be retrieved or set by a key exchange algorithm using EVP_PKEY_CTX_get_params(3) and EVP_PKEY_CTX_set_params(3).

- -

RETURN VALUES

- -

EVP_KEYEXCH_fetch() returns a pointer to a EVP_KEYEXCH for success or NULL for failure.

- -

EVP_KEYEXCH_up_ref() returns 1 for success or 0 otherwise.

- -

EVP_KEYEXCH_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EVP_KEYEXCH_is_a() returns 1 of exchange was identifiable, otherwise 0.

- -

EVP_KEYEXCH_gettable_ctx_params() and EVP_KEYEXCH_settable_ctx_params() return a constant OSSL_PARAM(3) array or NULL on error.

- -

SEE ALSO

- -

"ALGORITHM FETCHING" in crypto(7), OSSL_PROVIDER(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_KEYMGMT.html b/openssl-install/share/doc/openssl/html/man3/EVP_KEYMGMT.html deleted file mode 100644 index 6bd88d36..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_KEYMGMT.html +++ /dev/null @@ -1,124 +0,0 @@ - - - - -EVP_KEYMGMT - - - - - - - - - - -

NAME

- -

EVP_KEYMGMT, EVP_KEYMGMT_fetch, EVP_KEYMGMT_up_ref, EVP_KEYMGMT_free, EVP_KEYMGMT_get0_provider, EVP_KEYMGMT_is_a, EVP_KEYMGMT_get0_description, EVP_KEYMGMT_get0_name, EVP_KEYMGMT_do_all_provided, EVP_KEYMGMT_names_do_all, EVP_KEYMGMT_gettable_params, EVP_KEYMGMT_settable_params, EVP_KEYMGMT_gen_gettable_params, EVP_KEYMGMT_gen_settable_params - EVP key management routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-typedef struct evp_keymgmt_st EVP_KEYMGMT;
-
-EVP_KEYMGMT *EVP_KEYMGMT_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-                               const char *properties);
-int EVP_KEYMGMT_up_ref(EVP_KEYMGMT *keymgmt);
-void EVP_KEYMGMT_free(EVP_KEYMGMT *keymgmt);
-const OSSL_PROVIDER *EVP_KEYMGMT_get0_provider(const EVP_KEYMGMT *keymgmt);
-int EVP_KEYMGMT_is_a(const EVP_KEYMGMT *keymgmt, const char *name);
-const char *EVP_KEYMGMT_get0_name(const EVP_KEYMGMT *keymgmt);
-const char *EVP_KEYMGMT_get0_description(const EVP_KEYMGMT *keymgmt);
-
-void EVP_KEYMGMT_do_all_provided(OSSL_LIB_CTX *libctx,
-                                 void (*fn)(EVP_KEYMGMT *keymgmt, void *arg),
-                                 void *arg);
-int EVP_KEYMGMT_names_do_all(const EVP_KEYMGMT *keymgmt,
-                             void (*fn)(const char *name, void *data),
-                             void *data);
-const OSSL_PARAM *EVP_KEYMGMT_gettable_params(const EVP_KEYMGMT *keymgmt);
-const OSSL_PARAM *EVP_KEYMGMT_settable_params(const EVP_KEYMGMT *keymgmt);
-const OSSL_PARAM *EVP_KEYMGMT_gen_settable_params(const EVP_KEYMGMT *keymgmt);
-const OSSL_PARAM *EVP_KEYMGMT_gen_gettable_params(const EVP_KEYMGMT *keymgmt);
- -

DESCRIPTION

- -

EVP_KEYMGMT is a method object that represents key management implementations for different cryptographic algorithms. This method object provides functionality to have providers import key material from the outside, as well as export key material to the outside. Most of the functionality can only be used internally and has no public interface, this object is simply passed into other functions when needed.

- -

EVP_KEYMGMT_fetch() looks for an algorithm within the provider that has been loaded into the OSSL_LIB_CTX given by ctx, having the name given by algorithm and the properties given by properties.

- -

EVP_KEYMGMT_up_ref() increments the reference count for the given EVP_KEYMGMT keymgmt.

- -

EVP_KEYMGMT_free() decrements the reference count for the given EVP_KEYMGMT keymgmt, and when the count reaches zero, frees it. If the argument is NULL, nothing is done.

- -

EVP_KEYMGMT_get0_provider() returns the provider that has this particular implementation.

- -

EVP_KEYMGMT_is_a() checks if keymgmt is an implementation of an algorithm that's identifiable with name.

- -

EVP_KEYMGMT_get0_name() returns the algorithm name from the provided implementation for the given keymgmt. Note that the keymgmt may have multiple synonyms associated with it. In this case the first name from the algorithm definition is returned. Ownership of the returned string is retained by the keymgmt object and should not be freed by the caller.

- -

EVP_KEYMGMT_names_do_all() traverses all names for the keymgmt, and calls fn with each name and data.

- -

EVP_KEYMGMT_get0_description() returns a description of the keymgmt, meant for display and human consumption. The description is at the discretion of the keymgmt implementation.

- -

EVP_KEYMGMT_do_all_provided() traverses all key keymgmt implementations by all activated providers in the library context libctx, and for each of the implementations, calls fn with the implementation method and data as arguments.

- -

EVP_KEYMGMT_gettable_params() and EVP_KEYMGMT_settable_params() return a constant OSSL_PARAM(3) array that describes the names and types of key parameters that can be retrieved or set. EVP_KEYMGMT_gettable_params() is used by EVP_PKEY_gettable_params(3).

- -

EVP_KEYMGMT_gen_gettable_params() and EVP_KEYMGMT_gen_settable_params() return a constant OSSL_PARAM(3) array that describes the names and types of key generation parameters that can be retrieved or set via EVP_PKEY_CTX_get_params(3) or EVP_PKEY_CTX_set_params(3) respectively.

- -

NOTES

- -

EVP_KEYMGMT_fetch() may be called implicitly by other fetching functions, using the same library context and properties. Any other API that uses keys will typically do this.

- -

RETURN VALUES

- -

EVP_KEYMGMT_fetch() returns a pointer to the key management implementation represented by an EVP_KEYMGMT object, or NULL on error.

- -

EVP_KEYMGMT_up_ref() returns 1 on success, or 0 on error.

- -

EVP_KEYMGMT_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EVP_KEYMGMT_free() doesn't return any value.

- -

EVP_KEYMGMT_get0_provider() returns a pointer to a provider object, or NULL on error.

- -

EVP_KEYMGMT_is_a() returns 1 of keymgmt was identifiable, otherwise 0.

- -

EVP_KEYMGMT_get0_name() returns the algorithm name, or NULL on error.

- -

EVP_KEYMGMT_get0_description() returns a pointer to a description, or NULL if there isn't one.

- -

EVP_KEYMGMT_gettable_params(), EVP_KEYMGMT_settable_params(), EVP_KEYMGMT_gen_gettable_params() and EVP_KEYMGMT_gen_settable_params() return a constant OSSL_PARAM(3) array or NULL on error.

- -

SEE ALSO

- -

EVP_MD_fetch(3), OSSL_LIB_CTX(3)

- -

HISTORY

- -

The function EVP_KEYMGMT_gen_gettable_params() was added in OpenSSL 3.4.0 All other functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_MAC.html b/openssl-install/share/doc/openssl/html/man3/EVP_MAC.html deleted file mode 100644 index df4d508b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_MAC.html +++ /dev/null @@ -1,399 +0,0 @@ - - - - -EVP_MAC - - - - - - - - - - -

NAME

- -

EVP_MAC, EVP_MAC_fetch, EVP_MAC_up_ref, EVP_MAC_free, EVP_MAC_is_a, EVP_MAC_get0_name, EVP_MAC_names_do_all, EVP_MAC_get0_description, EVP_MAC_get0_provider, EVP_MAC_get_params, EVP_MAC_gettable_params, EVP_MAC_CTX, EVP_MAC_CTX_new, EVP_MAC_CTX_free, EVP_MAC_CTX_dup, EVP_MAC_CTX_get0_mac, EVP_MAC_CTX_get_params, EVP_MAC_CTX_set_params, EVP_MAC_CTX_get_mac_size, EVP_MAC_CTX_get_block_size, EVP_Q_mac, EVP_MAC_init, EVP_MAC_update, EVP_MAC_final, EVP_MAC_finalXOF, EVP_MAC_gettable_ctx_params, EVP_MAC_settable_ctx_params, EVP_MAC_CTX_gettable_params, EVP_MAC_CTX_settable_params, EVP_MAC_do_all_provided - EVP MAC routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-typedef struct evp_mac_st EVP_MAC;
-typedef struct evp_mac_ctx_st EVP_MAC_CTX;
-
-EVP_MAC *EVP_MAC_fetch(OSSL_LIB_CTX *libctx, const char *algorithm,
-                       const char *properties);
-int EVP_MAC_up_ref(EVP_MAC *mac);
-void EVP_MAC_free(EVP_MAC *mac);
-int EVP_MAC_is_a(const EVP_MAC *mac, const char *name);
-const char *EVP_MAC_get0_name(const EVP_MAC *mac);
-int EVP_MAC_names_do_all(const EVP_MAC *mac,
-                         void (*fn)(const char *name, void *data),
-                         void *data);
-const char *EVP_MAC_get0_description(const EVP_MAC *mac);
-const OSSL_PROVIDER *EVP_MAC_get0_provider(const EVP_MAC *mac);
-int EVP_MAC_get_params(EVP_MAC *mac, OSSL_PARAM params[]);
-
-EVP_MAC_CTX *EVP_MAC_CTX_new(EVP_MAC *mac);
-void EVP_MAC_CTX_free(EVP_MAC_CTX *ctx);
-EVP_MAC_CTX *EVP_MAC_CTX_dup(const EVP_MAC_CTX *src);
-EVP_MAC *EVP_MAC_CTX_get0_mac(EVP_MAC_CTX *ctx);
-int EVP_MAC_CTX_get_params(EVP_MAC_CTX *ctx, OSSL_PARAM params[]);
-int EVP_MAC_CTX_set_params(EVP_MAC_CTX *ctx, const OSSL_PARAM params[]);
-
-size_t EVP_MAC_CTX_get_mac_size(EVP_MAC_CTX *ctx);
-size_t EVP_MAC_CTX_get_block_size(EVP_MAC_CTX *ctx);
-unsigned char *EVP_Q_mac(OSSL_LIB_CTX *libctx, const char *name, const char *propq,
-                         const char *subalg, const OSSL_PARAM *params,
-                         const void *key, size_t keylen,
-                         const unsigned char *data, size_t datalen,
-                         unsigned char *out, size_t outsize, size_t *outlen);
-int EVP_MAC_init(EVP_MAC_CTX *ctx, const unsigned char *key, size_t keylen,
-                 const OSSL_PARAM params[]);
-int EVP_MAC_update(EVP_MAC_CTX *ctx, const unsigned char *data, size_t datalen);
-int EVP_MAC_final(EVP_MAC_CTX *ctx,
-                  unsigned char *out, size_t *outl, size_t outsize);
-int EVP_MAC_finalXOF(EVP_MAC_CTX *ctx, unsigned char *out, size_t outsize);
-
-const OSSL_PARAM *EVP_MAC_gettable_params(const EVP_MAC *mac);
-const OSSL_PARAM *EVP_MAC_gettable_ctx_params(const EVP_MAC *mac);
-const OSSL_PARAM *EVP_MAC_settable_ctx_params(const EVP_MAC *mac);
-const OSSL_PARAM *EVP_MAC_CTX_gettable_params(EVP_MAC_CTX *ctx);
-const OSSL_PARAM *EVP_MAC_CTX_settable_params(EVP_MAC_CTX *ctx);
-
-void EVP_MAC_do_all_provided(OSSL_LIB_CTX *libctx,
-                             void (*fn)(EVP_MAC *mac, void *arg),
-                             void *arg);
- -

DESCRIPTION

- -

These types and functions help the application to calculate MACs of different types and with different underlying algorithms if there are any.

- -

MACs are a bit complex insofar that some of them use other algorithms for actual computation. HMAC uses a digest, and CMAC uses a cipher. Therefore, there are sometimes two contexts to keep track of, one for the MAC algorithm itself and one for the underlying computation algorithm if there is one.

- -

To make things less ambiguous, this manual talks about a "context" or "MAC context", which is to denote the MAC level context, and about a "underlying context", or "computation context", which is to denote the context for the underlying computation algorithm if there is one.

- -

Types

- -

EVP_MAC is a type that holds the implementation of a MAC.

- -

EVP_MAC_CTX is a context type that holds internal MAC information as well as a reference to a computation context, for those MACs that rely on an underlying computation algorithm.

- -

Algorithm implementation fetching

- -

EVP_MAC_fetch() fetches an implementation of a MAC algorithm, given a library context libctx and a set of properties. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

See "Message Authentication Code (MAC)" in OSSL_PROVIDER-default(7) for the list of algorithms supported by the default provider.

- -

The returned value must eventually be freed with EVP_MAC_free(3).

- -

EVP_MAC_up_ref() increments the reference count of an already fetched MAC.

- -

EVP_MAC_free() frees a fetched algorithm. NULL is a valid parameter, for which this function is a no-op.

- -

Context manipulation functions

- -

EVP_MAC_CTX_new() creates a new context for the MAC type mac. The created context can then be used with most other functions described here.

- -

EVP_MAC_CTX_free() frees the contents of the context, including an underlying context if there is one, as well as the context itself. NULL is a valid parameter, for which this function is a no-op.

- -

EVP_MAC_CTX_dup() duplicates the src context and returns a newly allocated context.

- -

EVP_MAC_CTX_get0_mac() returns the EVP_MAC associated with the context ctx.

- -

Computing functions

- -

EVP_Q_mac() computes the message authentication code of data with length datalen using the MAC algorithm name and the key key with length keylen. The MAC algorithm is fetched using any given libctx and property query string propq. It takes parameters subalg and further params, both of which may be NULL if not needed. If out is not NULL, it places the result in the memory pointed at by out, but only if outsize is sufficient (otherwise no computation is made). If out is NULL, it allocates and uses a buffer of suitable length, which will be returned on success and must be freed by the caller. In either case, also on error, it assigns the number of bytes written to *outlen unless outlen is NULL.

- -

EVP_MAC_init() sets up the underlying context ctx with information given via the key and params arguments. The MAC key has a length of keylen and the parameters in params are processed before setting the key. If key is NULL, the key must be set via params either as part of this call or separately using EVP_MAC_CTX_set_params(). Providing non-NULL params to this function is equivalent to calling EVP_MAC_CTX_set_params() with those params for the same ctx beforehand. Note: There are additional requirements for some MAC algorithms during re-initalization (i.e. calling EVP_MAC_init() on an EVP_MAC after EVP_MAC_final() has been called on the same object). See the NOTES section below.

- -

EVP_MAC_init() should be called before EVP_MAC_update() and EVP_MAC_final().

- -

EVP_MAC_update() adds datalen bytes from data to the MAC input.

- -

EVP_MAC_final() does the final computation and stores the result in the memory pointed at by out of size outsize, and sets the number of bytes written in *outl at. If out is NULL or outsize is too small, then no computation is made. To figure out what the output length will be and allocate space for it dynamically, simply call with out being NULL and outl pointing at a valid location, then allocate space and make a second call with out pointing at the allocated space.

- -

EVP_MAC_finalXOF() does the final computation for an XOF based MAC and stores the result in the memory pointed at by out of size outsize.

- -

EVP_MAC_get_params() retrieves details about the implementation mac. The set of parameters given with params determine exactly what parameters should be retrieved. Note that a parameter that is unknown in the underlying context is simply ignored.

- -

EVP_MAC_CTX_get_params() retrieves chosen parameters, given the context ctx and its underlying context. The set of parameters given with params determine exactly what parameters should be retrieved. Note that a parameter that is unknown in the underlying context is simply ignored.

- -

EVP_MAC_CTX_set_params() passes chosen parameters to the underlying context, given a context ctx. The set of parameters given with params determine exactly what parameters are passed down. If params are NULL, the underlying context should do nothing and return 1. Note that a parameter that is unknown in the underlying context is simply ignored. Also, what happens when a needed parameter isn't passed down is defined by the implementation.

- -

EVP_MAC_gettable_params() returns an OSSL_PARAM(3) array that describes the retrievable and settable parameters. EVP_MAC_gettable_params() returns parameters that can be used with EVP_MAC_get_params().

- -

EVP_MAC_gettable_ctx_params() and EVP_MAC_CTX_gettable_params() return constant OSSL_PARAM(3) arrays that describe the retrievable parameters that can be used with EVP_MAC_CTX_get_params(). EVP_MAC_gettable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_MAC_CTX_gettable_params() returns the parameters that can be retrieved in the context's current state.

- -

EVP_MAC_settable_ctx_params() and EVP_MAC_CTX_settable_params() return constant OSSL_PARAM(3) arrays that describe the settable parameters that can be used with EVP_MAC_CTX_set_params(). EVP_MAC_settable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_MAC_CTX_settable_params() returns the parameters that can be retrieved in the context's current state.

- -

Information functions

- -

EVP_MAC_CTX_get_mac_size() returns the MAC output size for the given context.

- -

EVP_MAC_CTX_get_block_size() returns the MAC block size for the given context. Not all MAC algorithms support this.

- -

EVP_MAC_is_a() checks if the given mac is an implementation of an algorithm that's identifiable with name.

- -

EVP_MAC_get0_provider() returns the provider that holds the implementation of the given mac.

- -

EVP_MAC_do_all_provided() traverses all MAC implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -

EVP_MAC_get0_name() return the name of the given MAC. For fetched MACs with multiple names, only one of them is returned; it's recommended to use EVP_MAC_names_do_all() instead.

- -

EVP_MAC_names_do_all() traverses all names for mac, and calls fn with each name and data.

- -

EVP_MAC_get0_description() returns a description of the mac, meant for display and human consumption. The description is at the discretion of the mac implementation.

- -

PARAMETERS

- -

Parameters are identified by name as strings, and have an expected data type and maximum size. OpenSSL has a set of macros for parameter names it expects to see in its own MAC implementations. Here, we show all three, the OpenSSL macro for the parameter name, the name in string form, and a type description.

- -

The standard parameter names are:

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Its value is the MAC key as an array of bytes.

- -

For MACs that use an underlying computation algorithm, the algorithm must be set first, see parameter names "algorithm" below.

- -
-
"iv" (OSSL_MAC_PARAM_IV) <octet string>
-
- -

Some MAC implementations (GMAC) require an IV, this parameter sets the IV.

- -
-
"custom" (OSSL_MAC_PARAM_CUSTOM) <octet string>
-
- -

Some MAC implementations (KMAC, BLAKE2) accept a Customization String, this parameter sets the Customization String. The default value is the empty string.

- -
-
"salt" (OSSL_MAC_PARAM_SALT) <octet string>
-
- -

This option is used by BLAKE2 MAC.

- -
-
"xof" (OSSL_MAC_PARAM_XOF) <integer>
-
- -

It's a simple flag, the value 0 or 1 are expected.

- -

This option is used by KMAC.

- -
-
"digest-noinit" (OSSL_MAC_PARAM_DIGEST_NOINIT) <integer>
-
- -

A simple flag to set the MAC digest to not initialise the implementation specific data. The value 0 or 1 is expected.

- -

This option is deprecated and will be removed in a future release. The option may be set, but is ignored.

- -
-
"digest-oneshot" (OSSL_MAC_PARAM_DIGEST_ONESHOT) <integer>
-
- -

A simple flag to set the MAC digest to be a oneshot operation. The value 0 or 1 is expected.

- -

This option is deprecated and will be removed in a future release. The option may be set, but is ignored.

- -
-
"properties" (OSSL_MAC_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_MAC_PARAM_DIGEST) <UTF8 string>
-
- -
-
"cipher" (OSSL_MAC_PARAM_CIPHER) <UTF8 string>
-
- -

For MAC implementations that use an underlying computation cipher or digest, these parameters set what the algorithm should be.

- -

The value is always the name of the intended algorithm, or the properties.

- -

Note that not all algorithms may support all digests. HMAC does not support variable output length digests such as SHAKE128 or SHAKE256.

- -
-
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

For MAC implementations that support it, set the output size that EVP_MAC_final() should produce. The allowed sizes vary between MAC implementations, but must never exceed what can be given with a size_t.

- -
-
"tls-data-size" (OSSL_MAC_PARAM_TLS_DATA_SIZE) <unsigned integer>
-
- -

This parameter is only supported by HMAC. If set then special handling is activated for calculating the MAC of a received mac-then-encrypt TLS record where variable length record padding has been used (as in the case of CBC mode ciphersuites). The value represents the total length of the record that is having the MAC calculated including the received MAC and the record padding.

- -

When used EVP_MAC_update must be called precisely twice. The first time with the 13 bytes of TLS "header" data, and the second time with the entire record including the MAC itself and any padding. The entire record length must equal the value passed in the "tls-data-size" parameter. The length passed in the datalen parameter to EVP_MAC_update() should be equal to the length of the record after the MAC and any padding has been removed.

- -
-
- -

All these parameters should be used before the calls to any of EVP_MAC_init(), EVP_MAC_update() and EVP_MAC_final() for a full computation. Anything else may give undefined results.

- -

NOTES

- -

The MAC life-cycle is described in life_cycle-mac(7). In the future, the transitions described there will be enforced. When this is done, it will not be considered a breaking change to the API.

- -

The usage of the parameter names "custom", "iv" and "salt" correspond to the names used in the standard where the algorithm was defined.

- -

Some MAC algorithms store internal state that cannot be extracted during re-initalization. For example GMAC cannot extract an IV from the underlying CIPHER context, and so calling EVP_MAC_init() on an EVP_MAC object after EVP_MAC_final() has been called cannot reset its cipher state to what it was when the IV was initially generated. For such instances, an OSSL_MAC_PARAM_IV parameter must be passed with each call to EVP_MAC_init().

- -

RETURN VALUES

- -

EVP_MAC_fetch() returns a pointer to a newly fetched EVP_MAC, or NULL if allocation failed.

- -

EVP_MAC_up_ref() returns 1 on success, 0 on error.

- -

EVP_MAC_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EVP_MAC_free() returns nothing at all.

- -

EVP_MAC_is_a() returns 1 if the given method can be identified with the given name, otherwise 0.

- -

EVP_MAC_get0_name() returns a name of the MAC, or NULL on error.

- -

EVP_MAC_get0_provider() returns a pointer to the provider for the MAC, or NULL on error.

- -

EVP_MAC_CTX_new() and EVP_MAC_CTX_dup() return a pointer to a newly created EVP_MAC_CTX, or NULL if allocation failed.

- -

EVP_MAC_CTX_free() returns nothing at all.

- -

EVP_MAC_CTX_get_params() and EVP_MAC_CTX_set_params() return 1 on success, 0 on error.

- -

EVP_Q_mac() returns a pointer to the computed MAC value, or NULL on error.

- -

EVP_MAC_init(), EVP_MAC_update(), EVP_MAC_final(), and EVP_MAC_finalXOF() return 1 on success, 0 on error.

- -

EVP_MAC_CTX_get_mac_size() returns the expected output size, or 0 if it isn't set. If it isn't set, a call to EVP_MAC_init() will set it.

- -

EVP_MAC_CTX_get_block_size() returns the block size, or 0 if it isn't set. If it isn't set, a call to EVP_MAC_init() will set it.

- -

EVP_MAC_do_all_provided() returns nothing at all.

- -

EXAMPLES

- -
#include <stdlib.h>
-#include <stdio.h>
-#include <string.h>
-#include <stdarg.h>
-#include <unistd.h>
-
-#include <openssl/evp.h>
-#include <openssl/err.h>
-#include <openssl/params.h>
-
-int main() {
-    EVP_MAC *mac = EVP_MAC_fetch(NULL, getenv("MY_MAC"), NULL);
-    const char *cipher = getenv("MY_MAC_CIPHER");
-    const char *digest = getenv("MY_MAC_DIGEST");
-    const char *key = getenv("MY_KEY");
-    EVP_MAC_CTX *ctx = NULL;
-
-    unsigned char buf[4096];
-    size_t read_l;
-    size_t final_l;
-
-    size_t i;
-
-    OSSL_PARAM params[3];
-    size_t params_n = 0;
-
-    if (cipher != NULL)
-        params[params_n++] =
-            OSSL_PARAM_construct_utf8_string("cipher", (char*)cipher, 0);
-    if (digest != NULL)
-        params[params_n++] =
-            OSSL_PARAM_construct_utf8_string("digest", (char*)digest, 0);
-    params[params_n] = OSSL_PARAM_construct_end();
-
-    if (mac == NULL
-        || key == NULL
-        || (ctx = EVP_MAC_CTX_new(mac)) == NULL
-        || !EVP_MAC_init(ctx, (const unsigned char *)key, strlen(key),
-                         params))
-        goto err;
-
-    while ( (read_l = read(STDIN_FILENO, buf, sizeof(buf))) > 0) {
-        if (!EVP_MAC_update(ctx, buf, read_l))
-            goto err;
-    }
-
-    if (!EVP_MAC_final(ctx, buf, &final_l, sizeof(buf)))
-        goto err;
-
-    printf("Result: ");
-    for (i = 0; i < final_l; i++)
-        printf("%02X", buf[i]);
-    printf("\n");
-
-    EVP_MAC_CTX_free(ctx);
-    EVP_MAC_free(mac);
-    exit(0);
-
- err:
-    EVP_MAC_CTX_free(ctx);
-    EVP_MAC_free(mac);
-    fprintf(stderr, "Something went wrong\n");
-    ERR_print_errors_fp(stderr);
-    exit (1);
-}
- -

A run of this program, called with correct environment variables, can look like this:

- -
$ MY_MAC=cmac MY_KEY=secret0123456789 MY_MAC_CIPHER=aes-128-cbc \
-  LD_LIBRARY_PATH=. ./foo < foo.c
-Result: C5C06683CD9DDEF904D754505C560A4E
- -

(in this example, that program was stored in foo.c and compiled to ./foo)

- -

SEE ALSO

- -

property(7) OSSL_PARAM(3), EVP_MAC-BLAKE2(7), EVP_MAC-CMAC(7), EVP_MAC-GMAC(7), EVP_MAC-HMAC(7), EVP_MAC-KMAC(7), EVP_MAC-Siphash(7), EVP_MAC-Poly1305(7), provider-mac(7), life_cycle-mac(7)

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_MD_meth_new.html b/openssl-install/share/doc/openssl/html/man3/EVP_MD_meth_new.html deleted file mode 100644 index 4fd635ff..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_MD_meth_new.html +++ /dev/null @@ -1,169 +0,0 @@ - - - - -EVP_MD_meth_new - - - - - - - - - - -

NAME

- -

EVP_MD_meth_new, EVP_MD_meth_dup, EVP_MD_meth_free, EVP_MD_meth_set_input_blocksize, EVP_MD_meth_set_result_size, EVP_MD_meth_set_app_datasize, EVP_MD_meth_set_flags, EVP_MD_meth_set_init, EVP_MD_meth_set_update, EVP_MD_meth_set_final, EVP_MD_meth_set_copy, EVP_MD_meth_set_cleanup, EVP_MD_meth_set_ctrl, EVP_MD_meth_get_input_blocksize, EVP_MD_meth_get_result_size, EVP_MD_meth_get_app_datasize, EVP_MD_meth_get_flags, EVP_MD_meth_get_init, EVP_MD_meth_get_update, EVP_MD_meth_get_final, EVP_MD_meth_get_copy, EVP_MD_meth_get_cleanup, EVP_MD_meth_get_ctrl - Routines to build up legacy EVP_MD methods

- -

SYNOPSIS

- -
#include <openssl/evp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
EVP_MD *EVP_MD_meth_new(int md_type, int pkey_type);
-void EVP_MD_meth_free(EVP_MD *md);
-EVP_MD *EVP_MD_meth_dup(const EVP_MD *md);
-
-int EVP_MD_meth_set_input_blocksize(EVP_MD *md, int blocksize);
-int EVP_MD_meth_set_result_size(EVP_MD *md, int resultsize);
-int EVP_MD_meth_set_app_datasize(EVP_MD *md, int datasize);
-int EVP_MD_meth_set_flags(EVP_MD *md, unsigned long flags);
-int EVP_MD_meth_set_init(EVP_MD *md, int (*init)(EVP_MD_CTX *ctx));
-int EVP_MD_meth_set_update(EVP_MD *md, int (*update)(EVP_MD_CTX *ctx,
-                                                     const void *data,
-                                                     size_t count));
-int EVP_MD_meth_set_final(EVP_MD *md, int (*final)(EVP_MD_CTX *ctx,
-                                                   unsigned char *md));
-int EVP_MD_meth_set_copy(EVP_MD *md, int (*copy)(EVP_MD_CTX *to,
-                                                 const EVP_MD_CTX *from));
-int EVP_MD_meth_set_cleanup(EVP_MD *md, int (*cleanup)(EVP_MD_CTX *ctx));
-int EVP_MD_meth_set_ctrl(EVP_MD *md, int (*ctrl)(EVP_MD_CTX *ctx, int cmd,
-                                                 int p1, void *p2));
-
-int EVP_MD_meth_get_input_blocksize(const EVP_MD *md);
-int EVP_MD_meth_get_result_size(const EVP_MD *md);
-int EVP_MD_meth_get_app_datasize(const EVP_MD *md);
-unsigned long EVP_MD_meth_get_flags(const EVP_MD *md);
-int (*EVP_MD_meth_get_init(const EVP_MD *md))(EVP_MD_CTX *ctx);
-int (*EVP_MD_meth_get_update(const EVP_MD *md))(EVP_MD_CTX *ctx,
-                                                const void *data,
-                                                size_t count);
-int (*EVP_MD_meth_get_final(const EVP_MD *md))(EVP_MD_CTX *ctx,
-                                               unsigned char *md);
-int (*EVP_MD_meth_get_copy(const EVP_MD *md))(EVP_MD_CTX *to,
-                                              const EVP_MD_CTX *from);
-int (*EVP_MD_meth_get_cleanup(const EVP_MD *md))(EVP_MD_CTX *ctx);
-int (*EVP_MD_meth_get_ctrl(const EVP_MD *md))(EVP_MD_CTX *ctx, int cmd,
-                                              int p1, void *p2);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the OSSL_PROVIDER APIs.

- -

The EVP_MD type is a structure for digest method implementation. It can also have associated public/private key signing and verifying routines.

- -

EVP_MD_meth_new() creates a new EVP_MD structure. These EVP_MD structures are reference counted.

- -

EVP_MD_meth_dup() creates a copy of md.

- -

EVP_MD_meth_free() decrements the reference count for the EVP_MD structure. If the reference count drops to 0 then the structure is freed. If the argument is NULL, nothing is done.

- -

EVP_MD_meth_set_input_blocksize() sets the internal input block size for the method md to blocksize bytes.

- -

EVP_MD_meth_set_result_size() sets the size of the result that the digest method in md is expected to produce to resultsize bytes.

- -

The digest method may have its own private data, which OpenSSL will allocate for it. EVP_MD_meth_set_app_datasize() should be used to set the size for it to datasize.

- -

EVP_MD_meth_set_flags() sets the flags to describe optional behaviours in the particular md. Several flags can be or'd together. The available flags are:

- -
- -
EVP_MD_FLAG_ONESHOT
-
- -

This digest method can only handle one block of input.

- -
-
EVP_MD_FLAG_XOF
-
- -

This digest method is an extensible-output function (XOF) and supports the EVP_MD_CTRL_XOF_LEN control.

- -
-
EVP_MD_FLAG_DIGALGID_NULL
-
- -

When setting up a DigestAlgorithmIdentifier, this flag will have the parameter set to NULL by default. Use this for PKCS#1. Note: if combined with EVP_MD_FLAG_DIGALGID_ABSENT, the latter will override.

- -
-
EVP_MD_FLAG_DIGALGID_ABSENT
-
- -

When setting up a DigestAlgorithmIdentifier, this flag will have the parameter be left absent by default. Note: if combined with EVP_MD_FLAG_DIGALGID_NULL, the latter will be overridden.

- -
-
EVP_MD_FLAG_DIGALGID_CUSTOM
-
- -

Custom DigestAlgorithmIdentifier handling via ctrl, with EVP_MD_FLAG_DIGALGID_ABSENT as default. Note: if combined with EVP_MD_FLAG_DIGALGID_NULL, the latter will be overridden. Currently unused.

- -
-
EVP_MD_FLAG_FIPS
-
- -

This digest method is suitable for use in FIPS mode. Currently unused.

- -
-
- -

EVP_MD_meth_set_init() sets the digest init function for md. The digest init function is called by EVP_Digest(), EVP_DigestInit(), EVP_DigestInit_ex(), EVP_SignInit, EVP_SignInit_ex(), EVP_VerifyInit() and EVP_VerifyInit_ex().

- -

EVP_MD_meth_set_update() sets the digest update function for md. The digest update function is called by EVP_Digest(), EVP_DigestUpdate() and EVP_SignUpdate().

- -

EVP_MD_meth_set_final() sets the digest final function for md. The digest final function is called by EVP_Digest(), EVP_DigestFinal(), EVP_DigestFinal_ex(), EVP_SignFinal() and EVP_VerifyFinal().

- -

EVP_MD_meth_set_copy() sets the function for md to do extra computations after the method's private data structure has been copied from one EVP_MD_CTX to another. If all that's needed is to copy the data, there is no need for this copy function. Note that the copy function is passed two EVP_MD_CTX *, the private data structure is then available with EVP_MD_CTX_get0_md_data(). This copy function is called by EVP_MD_CTX_copy() and EVP_MD_CTX_copy_ex().

- -

EVP_MD_meth_set_cleanup() sets the function for md to do extra cleanup before the method's private data structure is cleaned out and freed. Note that the cleanup function is passed a EVP_MD_CTX *, the private data structure is then available with EVP_MD_CTX_get0_md_data(). This cleanup function is called by EVP_MD_CTX_reset() and EVP_MD_CTX_free().

- -

EVP_MD_meth_set_ctrl() sets the control function for md. See EVP_MD_CTX_ctrl(3) for the available controls.

- -

EVP_MD_meth_get_input_blocksize(), EVP_MD_meth_get_result_size(), EVP_MD_meth_get_app_datasize(), EVP_MD_meth_get_flags(), EVP_MD_meth_get_init(), EVP_MD_meth_get_update(), EVP_MD_meth_get_final(), EVP_MD_meth_get_copy(), EVP_MD_meth_get_cleanup() and EVP_MD_meth_get_ctrl() are all used to retrieve the method data given with the EVP_MD_meth_set_*() functions above.

- -

RETURN VALUES

- -

EVP_MD_meth_new() and EVP_MD_meth_dup() return a pointer to a newly created EVP_MD, or NULL on failure. All EVP_MD_meth_set_*() functions return 1. EVP_MD_get_input_blocksize(), EVP_MD_meth_get_result_size(), EVP_MD_meth_get_app_datasize() and EVP_MD_meth_get_flags() return the indicated sizes or flags. All other EVP_CIPHER_meth_get_*() functions return pointers to their respective md function.

- -

SEE ALSO

- -

EVP_DigestInit(3), EVP_SignInit(3), EVP_VerifyInit(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

The EVP_MD structure was openly available in OpenSSL before version 1.1. The functions described here were added in OpenSSL 1.1. The EVP_MD structure created with these functions became reference counted in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_OpenInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_OpenInit.html deleted file mode 100644 index 348d8485..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_OpenInit.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -EVP_OpenInit - - - - - - - - - - -

NAME

- -

EVP_OpenInit, EVP_OpenUpdate, EVP_OpenFinal - EVP envelope decryption

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_OpenInit(EVP_CIPHER_CTX *ctx, EVP_CIPHER *type, unsigned char *ek,
-                 int ekl, unsigned char *iv, EVP_PKEY *priv);
-int EVP_OpenUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out,
-                   int *outl, unsigned char *in, int inl);
-int EVP_OpenFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl);
- -

DESCRIPTION

- -

The EVP envelope routines are a high-level interface to envelope decryption. They decrypt a public key encrypted symmetric key and then decrypt data using it.

- -

EVP_OpenInit() initializes a cipher context ctx for decryption with cipher type. It decrypts the encrypted symmetric key of length ekl bytes passed in the ek parameter using the private key priv. The IV is supplied in the iv parameter.

- -

EVP_OpenUpdate() and EVP_OpenFinal() have exactly the same properties as the EVP_DecryptUpdate() and EVP_DecryptFinal() routines, as documented on the EVP_EncryptInit(3) manual page.

- -

NOTES

- -

It is possible to call EVP_OpenInit() twice in the same way as EVP_DecryptInit(). The first call should have priv set to NULL and (after setting any cipher parameters) it should be called again with type set to NULL.

- -

If the cipher passed in the type parameter is a variable length cipher then the key length will be set to the value of the recovered key length. If the cipher is a fixed length cipher then the recovered key length must match the fixed cipher length.

- -

RETURN VALUES

- -

EVP_OpenInit() returns 0 on error or a non zero integer (actually the recovered secret key size) if successful.

- -

EVP_OpenUpdate() returns 1 for success or 0 for failure.

- -

EVP_OpenFinal() returns 0 if the decrypt failed or 1 for success.

- -

SEE ALSO

- -

evp(7), RAND_bytes(3), EVP_EncryptInit(3), EVP_SealInit(3)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PBE_CipherInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_PBE_CipherInit.html deleted file mode 100644 index 8a45524f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PBE_CipherInit.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -EVP_PBE_CipherInit - - - - - - - - - - -

NAME

- -

EVP_PBE_CipherInit, EVP_PBE_CipherInit_ex, EVP_PBE_find, EVP_PBE_find_ex, EVP_PBE_alg_add_type, EVP_PBE_alg_add - Password based encryption routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PBE_CipherInit(ASN1_OBJECT *pbe_obj, const char *pass, int passlen,
-                       ASN1_TYPE *param, EVP_CIPHER_CTX *ctx, int en_de);
-int EVP_PBE_CipherInit_ex(ASN1_OBJECT *pbe_obj, const char *pass, int passlen,
-                          ASN1_TYPE *param, EVP_CIPHER_CTX *ctx, int en_de,
-                          OSSL_LIB_CTX *libctx, const char *propq);
-
-int EVP_PBE_find(int type, int pbe_nid, int *pcnid, int *pmnid,
-                 EVP_PBE_KEYGEN **pkeygen);
-int EVP_PBE_find_ex(int type, int pbe_nid, int *pcnid, int *pmnid,
-                    EVP_PBE_KEYGEN **pkeygen, EVP_PBE_KEYGEN_EX **keygen_ex);
-
-int EVP_PBE_alg_add_type(int pbe_type, int pbe_nid, int cipher_nid,
-                         int md_nid, EVP_PBE_KEYGEN *keygen);
-int EVP_PBE_alg_add(int nid, const EVP_CIPHER *cipher, const EVP_MD *md,
-                    EVP_PBE_KEYGEN *keygen);
- -

DESCRIPTION

- -

PBE operations

- -

EVP_PBE_CipherInit() and EVP_PBE_CipherInit_ex() initialise an EVP_CIPHER_CTX ctx for encryption (en_de=1) or decryption (en_de=0) using the password pass of length passlen. The PBE algorithm type and parameters are extracted from an OID pbe_obj and parameters param.

- -

EVP_PBE_CipherInit_ex() also allows the application to specify a library context libctx and property query propq to select appropriate algorithm implementations.

- - - -

EVP_PBE_find() and EVP_PBE_find_ex() search for a matching algorithm using two parameters:

- -

1. An algorithm type type which can be:

- - - -

2. A pbe_nid which can represent the algorithm identifier with parameters e.g. NID_pbeWithSHA1AndRC2_CBC or an algorithm class e.g. NID_pbes2.

- -

They return the algorithm's cipher ID pcnid, digest ID pmnid and a key generation function for the algorithm pkeygen. EVP_PBE_CipherInit_ex() also returns an extended key generation function keygen_ex which takes a library context and property query.

- -

If a NULL is supplied for any of pcnid, pmnid, pkeygen or pkeygen_ex then this parameter is not returned.

- -

PBE algorithm add

- -

EVP_PBE_alg_add_type() and EVP_PBE_alg_add() add an algorithm to the list of known algorithms. Their parameters have the same meaning as for EVP_PBE_find() and EVP_PBE_find_ex() functions.

- -

NOTES

- -

The arguments pbe_obj and param to EVP_PBE_CipherInit() and EVP_PBE_CipherInit_ex() together form an X509_ALGOR and can often be extracted directly from this structure.

- -

RETURN VALUES

- -

Return value is 1 for success and 0 if an error occurred.

- -

SEE ALSO

- -

PKCS5_PBE_keyivgen(3), PKCS12_PBE_keyivgen_ex(3), PKCS5_v2_PBE_keyivgen_ex(3), PKCS12_pbe_crypt_ex(3), PKCS12_create_ex(3)

- -

HISTORY

- -

EVP_PBE_CipherInit_ex() and EVP_PBE_find_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY2PKCS8.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY2PKCS8.html deleted file mode 100644 index 2af3d742..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY2PKCS8.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -EVP_PKEY2PKCS8 - - - - - - - - - - -

NAME

- -

EVP_PKEY2PKCS8, EVP_PKCS82PKEY_ex, EVP_PKCS82PKEY - Convert a private key to/from PKCS8

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-PKCS8_PRIV_KEY_INFO *EVP_PKEY2PKCS8(const EVP_PKEY *pkey);
-EVP_PKEY *EVP_PKCS82PKEY(const PKCS8_PRIV_KEY_INFO *p8);
-EVP_PKEY *EVP_PKCS82PKEY_ex(const PKCS8_PRIV_KEY_INFO *p8, OSSL_LIB_CTX *libctx,
-                            const char *propq);
- -

DESCRIPTION

- -

EVP_PKEY2PKCS8() converts a private key pkey into a returned PKCS8 object.

- -

EVP_PKCS82PKEY_ex() converts a PKCS8 object p8 into a returned private key. It uses libctx and propq when fetching algorithms.

- -

EVP_PKCS82PKEY() is similar to EVP_PKCS82PKEY_ex() but uses default values of NULL for the libctx and propq.

- -

RETURN VALUES

- -

EVP_PKEY2PKCS8() returns a PKCS8 object on success. EVP_PKCS82PKEY() and EVP_PKCS82PKEY_ex() return a private key on success.

- -

All functions return NULL if the operation fails.

- -

SEE ALSO

- -

PKCS8_pkey_add1_attr(3),

- -

COPYRIGHT

- -

Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_ASN1_METHOD.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_ASN1_METHOD.html deleted file mode 100644 index 660b6fee..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_ASN1_METHOD.html +++ /dev/null @@ -1,353 +0,0 @@ - - - - -EVP_PKEY_ASN1_METHOD - - - - - - - - - - -

NAME

- -

EVP_PKEY_ASN1_METHOD, EVP_PKEY_asn1_new, EVP_PKEY_asn1_copy, EVP_PKEY_asn1_free, EVP_PKEY_asn1_add0, EVP_PKEY_asn1_add_alias, EVP_PKEY_asn1_set_public, EVP_PKEY_asn1_set_private, EVP_PKEY_asn1_set_param, EVP_PKEY_asn1_set_free, EVP_PKEY_asn1_set_ctrl, EVP_PKEY_asn1_set_item, EVP_PKEY_asn1_set_siginf, EVP_PKEY_asn1_set_check, EVP_PKEY_asn1_set_public_check, EVP_PKEY_asn1_set_param_check, EVP_PKEY_asn1_set_security_bits, EVP_PKEY_asn1_set_set_priv_key, EVP_PKEY_asn1_set_set_pub_key, EVP_PKEY_asn1_set_get_priv_key, EVP_PKEY_asn1_set_get_pub_key, EVP_PKEY_get0_asn1 - manipulating and registering EVP_PKEY_ASN1_METHOD structure

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-typedef struct evp_pkey_asn1_method_st EVP_PKEY_ASN1_METHOD;
-
-EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_new(int id, int flags,
-                                        const char *pem_str,
-                                        const char *info);
-void EVP_PKEY_asn1_copy(EVP_PKEY_ASN1_METHOD *dst,
-                        const EVP_PKEY_ASN1_METHOD *src);
-void EVP_PKEY_asn1_free(EVP_PKEY_ASN1_METHOD *ameth);
-int EVP_PKEY_asn1_add0(const EVP_PKEY_ASN1_METHOD *ameth);
-int EVP_PKEY_asn1_add_alias(int to, int from);
-
-void EVP_PKEY_asn1_set_public(EVP_PKEY_ASN1_METHOD *ameth,
-                              int (*pub_decode) (EVP_PKEY *pk,
-                                                 const X509_PUBKEY *pub),
-                              int (*pub_encode) (X509_PUBKEY *pub,
-                                                 const EVP_PKEY *pk),
-                              int (*pub_cmp) (const EVP_PKEY *a,
-                                              const EVP_PKEY *b),
-                              int (*pub_print) (BIO *out,
-                                                const EVP_PKEY *pkey,
-                                                int indent, ASN1_PCTX *pctx),
-                              int (*pkey_size) (const EVP_PKEY *pk),
-                              int (*pkey_bits) (const EVP_PKEY *pk));
-void EVP_PKEY_asn1_set_private(EVP_PKEY_ASN1_METHOD *ameth,
-                               int (*priv_decode) (EVP_PKEY *pk,
-                                                   const PKCS8_PRIV_KEY_INFO
-                                                   *p8inf),
-                               int (*priv_encode) (PKCS8_PRIV_KEY_INFO *p8,
-                                                   const EVP_PKEY *pk),
-                               int (*priv_print) (BIO *out,
-                                                  const EVP_PKEY *pkey,
-                                                  int indent,
-                                                  ASN1_PCTX *pctx));
-void EVP_PKEY_asn1_set_param(EVP_PKEY_ASN1_METHOD *ameth,
-                             int (*param_decode) (EVP_PKEY *pkey,
-                                                  const unsigned char **pder,
-                                                  int derlen),
-                             int (*param_encode) (const EVP_PKEY *pkey,
-                                                  unsigned char **pder),
-                             int (*param_missing) (const EVP_PKEY *pk),
-                             int (*param_copy) (EVP_PKEY *to,
-                                                const EVP_PKEY *from),
-                             int (*param_cmp) (const EVP_PKEY *a,
-                                               const EVP_PKEY *b),
-                             int (*param_print) (BIO *out,
-                                                 const EVP_PKEY *pkey,
-                                                 int indent,
-                                                 ASN1_PCTX *pctx));
-
-void EVP_PKEY_asn1_set_free(EVP_PKEY_ASN1_METHOD *ameth,
-                            void (*pkey_free) (EVP_PKEY *pkey));
-void EVP_PKEY_asn1_set_ctrl(EVP_PKEY_ASN1_METHOD *ameth,
-                            int (*pkey_ctrl) (EVP_PKEY *pkey, int op,
-                                              long arg1, void *arg2));
-void EVP_PKEY_asn1_set_item(EVP_PKEY_ASN1_METHOD *ameth,
-                            int (*item_verify) (EVP_MD_CTX *ctx,
-                                                const ASN1_ITEM *it,
-                                                void *asn,
-                                                X509_ALGOR *a,
-                                                ASN1_BIT_STRING *sig,
-                                                EVP_PKEY *pkey),
-                            int (*item_sign) (EVP_MD_CTX *ctx,
-                                              const ASN1_ITEM *it,
-                                              void *asn,
-                                              X509_ALGOR *alg1,
-                                              X509_ALGOR *alg2,
-                                              ASN1_BIT_STRING *sig));
-
-void EVP_PKEY_asn1_set_siginf(EVP_PKEY_ASN1_METHOD *ameth,
-                              int (*siginf_set) (X509_SIG_INFO *siginf,
-                                                 const X509_ALGOR *alg,
-                                                 const ASN1_STRING *sig));
-
-void EVP_PKEY_asn1_set_check(EVP_PKEY_ASN1_METHOD *ameth,
-                             int (*pkey_check) (const EVP_PKEY *pk));
-
-void EVP_PKEY_asn1_set_public_check(EVP_PKEY_ASN1_METHOD *ameth,
-                                    int (*pkey_pub_check) (const EVP_PKEY *pk));
-
-void EVP_PKEY_asn1_set_param_check(EVP_PKEY_ASN1_METHOD *ameth,
-                                   int (*pkey_param_check) (const EVP_PKEY *pk));
-
-void EVP_PKEY_asn1_set_security_bits(EVP_PKEY_ASN1_METHOD *ameth,
-                                     int (*pkey_security_bits) (const EVP_PKEY
-                                                                *pk));
-
-void EVP_PKEY_asn1_set_set_priv_key(EVP_PKEY_ASN1_METHOD *ameth,
-                                    int (*set_priv_key) (EVP_PKEY *pk,
-                                                         const unsigned char
-                                                            *priv,
-                                                         size_t len));
-
-void EVP_PKEY_asn1_set_set_pub_key(EVP_PKEY_ASN1_METHOD *ameth,
-                                   int (*set_pub_key) (EVP_PKEY *pk,
-                                                       const unsigned char *pub,
-                                                       size_t len));
-
-void EVP_PKEY_asn1_set_get_priv_key(EVP_PKEY_ASN1_METHOD *ameth,
-                                    int (*get_priv_key) (const EVP_PKEY *pk,
-                                                         unsigned char *priv,
-                                                         size_t *len));
-
-void EVP_PKEY_asn1_set_get_pub_key(EVP_PKEY_ASN1_METHOD *ameth,
-                                   int (*get_pub_key) (const EVP_PKEY *pk,
-                                                       unsigned char *pub,
-                                                       size_t *len));
-
-const EVP_PKEY_ASN1_METHOD *EVP_PKEY_get0_asn1(const EVP_PKEY *pkey);
- -

DESCRIPTION

- -

EVP_PKEY_ASN1_METHOD is a structure which holds a set of ASN.1 conversion, printing and information methods for a specific public key algorithm.

- -

There are two places where the EVP_PKEY_ASN1_METHOD objects are stored: one is a built-in array representing the standard methods for different algorithms, and the other one is a stack of user-defined application-specific methods, which can be manipulated by using EVP_PKEY_asn1_add0(3).

- -

Methods

- -

The methods are the underlying implementations of a particular public key algorithm present by the EVP_PKEY object.

- -
int (*pub_decode) (EVP_PKEY *pk, const X509_PUBKEY *pub);
-int (*pub_encode) (X509_PUBKEY *pub, const EVP_PKEY *pk);
-int (*pub_cmp) (const EVP_PKEY *a, const EVP_PKEY *b);
-int (*pub_print) (BIO *out, const EVP_PKEY *pkey, int indent,
-                  ASN1_PCTX *pctx);
- -

The pub_decode() and pub_encode() methods are called to decode / encode X509_PUBKEY ASN.1 parameters to / from pk. They MUST return 0 on error, 1 on success. They're called by X509_PUBKEY_get0(3) and X509_PUBKEY_set(3).

- -

The pub_cmp() method is called when two public keys are to be compared. It MUST return 1 when the keys are equal, 0 otherwise. It's called by EVP_PKEY_eq(3).

- -

The pub_print() method is called to print a public key in humanly readable text to out, indented indent spaces. It MUST return 0 on error, 1 on success. It's called by EVP_PKEY_print_public(3).

- -
int (*priv_decode) (EVP_PKEY *pk, const PKCS8_PRIV_KEY_INFO *p8inf);
-int (*priv_encode) (PKCS8_PRIV_KEY_INFO *p8, const EVP_PKEY *pk);
-int (*priv_print) (BIO *out, const EVP_PKEY *pkey, int indent,
-                   ASN1_PCTX *pctx);
- -

The priv_decode() and priv_encode() methods are called to decode / encode PKCS8_PRIV_KEY_INFO form private key to / from pk. They MUST return 0 on error, 1 on success. They're called by EVP_PKCS82PKEY(3) and EVP_PKEY2PKCS8(3).

- -

The priv_print() method is called to print a private key in humanly readable text to out, indented indent spaces. It MUST return 0 on error, 1 on success. It's called by EVP_PKEY_print_private(3).

- -
int (*pkey_size) (const EVP_PKEY *pk);
-int (*pkey_bits) (const EVP_PKEY *pk);
-int (*pkey_security_bits) (const EVP_PKEY *pk);
- -

The pkey_size() method returns the key size in bytes. It's called by EVP_PKEY_get_size(3).

- -

The pkey_bits() method returns the key size in bits. It's called by EVP_PKEY_get_bits(3).

- -
int (*param_decode) (EVP_PKEY *pkey,
-                     const unsigned char **pder, int derlen);
-int (*param_encode) (const EVP_PKEY *pkey, unsigned char **pder);
-int (*param_missing) (const EVP_PKEY *pk);
-int (*param_copy) (EVP_PKEY *to, const EVP_PKEY *from);
-int (*param_cmp) (const EVP_PKEY *a, const EVP_PKEY *b);
-int (*param_print) (BIO *out, const EVP_PKEY *pkey, int indent,
-                    ASN1_PCTX *pctx);
- -

The param_decode() and param_encode() methods are called to decode / encode DER formatted parameters to / from pk. They MUST return 0 on error, 1 on success. They're called by PEM_read_bio_Parameters(3) and the file: OSSL_STORE_LOADER(3).

- -

The param_missing() method returns 0 if a key parameter is missing, otherwise 1. It's called by EVP_PKEY_missing_parameters(3).

- -

The param_copy() method copies key parameters from from to to. It MUST return 0 on error, 1 on success. It's called by EVP_PKEY_copy_parameters(3).

- -

The param_cmp() method compares the parameters of keys a and b. It MUST return 1 when the keys are equal, 0 when not equal, or a negative number on error. It's called by EVP_PKEY_parameters_eq(3).

- -

The param_print() method prints the private key parameters in humanly readable text to out, indented indent spaces. It MUST return 0 on error, 1 on success. It's called by EVP_PKEY_print_params(3).

- -
int (*sig_print) (BIO *out,
-                  const X509_ALGOR *sigalg, const ASN1_STRING *sig,
-                  int indent, ASN1_PCTX *pctx);
- -

The sig_print() method prints a signature in humanly readable text to out, indented indent spaces. sigalg contains the exact signature algorithm. If the signature in sig doesn't correspond to what this method expects, X509_signature_dump() must be used as a last resort. It MUST return 0 on error, 1 on success. It's called by X509_signature_print(3).

- -
void (*pkey_free) (EVP_PKEY *pkey);
- -

The pkey_free() method helps freeing the internals of pkey. It's called by EVP_PKEY_free(3), EVP_PKEY_set_type(3), EVP_PKEY_set_type_str(3), and EVP_PKEY_assign(3).

- -
int (*pkey_ctrl) (EVP_PKEY *pkey, int op, long arg1, void *arg2);
- -

The pkey_ctrl() method adds extra algorithm specific control. It's called by EVP_PKEY_get_default_digest_nid(3), EVP_PKEY_set1_encoded_public_key(3), EVP_PKEY_get1_encoded_public_key(3), PKCS7_SIGNER_INFO_set(3), PKCS7_RECIP_INFO_set(3), ...

- -
int (*old_priv_decode) (EVP_PKEY *pkey,
-                        const unsigned char **pder, int derlen);
-int (*old_priv_encode) (const EVP_PKEY *pkey, unsigned char **pder);
- -

The old_priv_decode() and old_priv_encode() methods decode / encode they private key pkey from / to a DER formatted array. These are exclusively used to help decoding / encoding older (pre PKCS#8) PEM formatted encrypted private keys. old_priv_decode() MUST return 0 on error, 1 on success. old_priv_encode() MUST the return same kind of values as i2d_PrivateKey(). They're called by d2i_PrivateKey(3) and i2d_PrivateKey(3).

- -
int (*item_verify) (EVP_MD_CTX *ctx, const ASN1_ITEM *it, void *asn,
-                    X509_ALGOR *a, ASN1_BIT_STRING *sig, EVP_PKEY *pkey);
-int (*item_sign) (EVP_MD_CTX *ctx, const ASN1_ITEM *it, void *asn,
-                  X509_ALGOR *alg1, X509_ALGOR *alg2,
-                  ASN1_BIT_STRING *sig);
- -

The item_sign() and item_verify() methods make it possible to have algorithm specific signatures and verification of them.

- -

item_sign() MUST return one of:

- -
- -
<=0
-
- -

error

- -
-
1
-
- -

item_sign() did everything, OpenSSL internals just needs to pass the signature length back.

- -
-
2
-
- -

item_sign() did nothing, OpenSSL internal standard routines are expected to continue with the default signature production.

- -
-
3
-
- -

item_sign() set the algorithm identifier algor1 and algor2, OpenSSL internals should just sign using those algorithms.

- -
-
- -

item_verify() MUST return one of:

- -
- -
<=0
-
- -

error

- -
-
1
-
- -

item_sign() did everything, OpenSSL internals just needs to pass the signature length back.

- -
-
2
-
- -

item_sign() did nothing, OpenSSL internal standard routines are expected to continue with the default signature production.

- -
-
- -

item_verify() and item_sign() are called by ASN1_item_verify(3) and ASN1_item_sign(3), and by extension, X509_verify(3), X509_REQ_verify(3), X509_sign(3), X509_REQ_sign(3), ...

- -
int (*siginf_set) (X509_SIG_INFO *siginf, const X509_ALGOR *alg,
-                   const ASN1_STRING *sig);
- -

The siginf_set() method is used to set custom X509_SIG_INFO parameters. It MUST return 0 on error, or 1 on success. It's called as part of X509_check_purpose(3), X509_check_ca(3) and X509_check_issued(3).

- -
int (*pkey_check) (const EVP_PKEY *pk);
-int (*pkey_public_check) (const EVP_PKEY *pk);
-int (*pkey_param_check) (const EVP_PKEY *pk);
- -

The pkey_check(), pkey_public_check() and pkey_param_check() methods are used to check the validity of pk for key-pair, public component and parameters, respectively. They MUST return 0 for an invalid key, or 1 for a valid key. They are called by EVP_PKEY_check(3), EVP_PKEY_public_check(3) and EVP_PKEY_param_check(3) respectively.

- -
int (*set_priv_key) (EVP_PKEY *pk, const unsigned char *priv, size_t len);
-int (*set_pub_key) (EVP_PKEY *pk, const unsigned char *pub, size_t len);
- -

The set_priv_key() and set_pub_key() methods are used to set the raw private and public key data for an EVP_PKEY. They MUST return 0 on error, or 1 on success. They are called by EVP_PKEY_new_raw_private_key(3), and EVP_PKEY_new_raw_public_key(3) respectively.

- -
size_t (*dirty) (const EVP_PKEY *pk);
-void *(*export_to) (const EVP_PKEY *pk, EVP_KEYMGMT *keymgmt);
- -

dirty_cnt() returns the internal key's dirty count. This can be used to synchronise different copies of the same keys.

- -

The export_to() method exports the key material from the given key to a provider, through the EVP_KEYMGMT(3) interface, if that provider supports importing key material.

- -

Functions

- -

EVP_PKEY_asn1_new() creates and returns a new EVP_PKEY_ASN1_METHOD object, and associates the given id, flags, pem_str and info. id is a NID, pem_str is the PEM type string, info is a descriptive string. The following flags are supported:

- -
ASN1_PKEY_SIGPARAM_NULL
- -

If ASN1_PKEY_SIGPARAM_NULL is set, then the signature algorithm parameters are given the type V_ASN1_NULL by default, otherwise they will be given the type V_ASN1_UNDEF (i.e. the parameter is omitted). See X509_ALGOR_set0(3) for more information.

- -

EVP_PKEY_asn1_copy() copies an EVP_PKEY_ASN1_METHOD object from src to dst. This function is not thread safe, it's recommended to only use this when initializing the application.

- -

EVP_PKEY_asn1_free() frees an existing EVP_PKEY_ASN1_METHOD pointed by ameth. If the argument is NULL, nothing is done.

- -

EVP_PKEY_asn1_add0() adds ameth to the user defined stack of methods unless another EVP_PKEY_ASN1_METHOD with the same NID is already there. This function is not thread safe, it's recommended to only use this when initializing the application.

- -

EVP_PKEY_asn1_add_alias() creates an alias with the NID to for the EVP_PKEY_ASN1_METHOD with NID from unless another EVP_PKEY_ASN1_METHOD with the same NID is already added. This function is not thread safe, it's recommended to only use this when initializing the application.

- -

EVP_PKEY_asn1_set_public(), EVP_PKEY_asn1_set_private(), EVP_PKEY_asn1_set_param(), EVP_PKEY_asn1_set_free(), EVP_PKEY_asn1_set_ctrl(), EVP_PKEY_asn1_set_item(), EVP_PKEY_asn1_set_siginf(), EVP_PKEY_asn1_set_check(), EVP_PKEY_asn1_set_public_check(), EVP_PKEY_asn1_set_param_check(), EVP_PKEY_asn1_set_security_bits(), EVP_PKEY_asn1_set_set_priv_key(), EVP_PKEY_asn1_set_set_pub_key(), EVP_PKEY_asn1_set_get_priv_key() and EVP_PKEY_asn1_set_get_pub_key() set the diverse methods of the given EVP_PKEY_ASN1_METHOD object.

- -

EVP_PKEY_get0_asn1() finds the EVP_PKEY_ASN1_METHOD associated with the key pkey.

- -

RETURN VALUES

- -

EVP_PKEY_asn1_new() returns NULL on error, or a pointer to an EVP_PKEY_ASN1_METHOD object otherwise.

- -

EVP_PKEY_asn1_add0() and EVP_PKEY_asn1_add_alias() return 0 on error, or 1 on success.

- -

EVP_PKEY_get0_asn1() returns NULL on error, or a pointer to a constant EVP_PKEY_ASN1_METHOD object otherwise.

- -

HISTORY

- -

The signature of the pub_decode functional argument of EVP_PKEY_asn1_set_public() has changed in OpenSSL 3.0 so its pub parameter is now constified.

- -

COPYRIGHT

- -

Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_ctrl.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_ctrl.html deleted file mode 100644 index 379801ab..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_ctrl.html +++ /dev/null @@ -1,416 +0,0 @@ - - - - -EVP_PKEY_CTX_ctrl - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_ctrl, EVP_PKEY_CTX_ctrl_str, EVP_PKEY_CTX_ctrl_uint64, EVP_PKEY_CTX_md, EVP_PKEY_CTX_set_signature_md, EVP_PKEY_CTX_get_signature_md, EVP_PKEY_CTX_set_mac_key, EVP_PKEY_CTX_set_group_name, EVP_PKEY_CTX_get_group_name, EVP_PKEY_CTX_set_rsa_padding, EVP_PKEY_CTX_get_rsa_padding, EVP_PKEY_CTX_set_rsa_pss_saltlen, EVP_PKEY_CTX_get_rsa_pss_saltlen, EVP_PKEY_CTX_set_rsa_keygen_bits, EVP_PKEY_CTX_set_rsa_keygen_pubexp, EVP_PKEY_CTX_set1_rsa_keygen_pubexp, EVP_PKEY_CTX_set_rsa_keygen_primes, EVP_PKEY_CTX_set_rsa_mgf1_md_name, EVP_PKEY_CTX_set_rsa_mgf1_md, EVP_PKEY_CTX_get_rsa_mgf1_md, EVP_PKEY_CTX_get_rsa_mgf1_md_name, EVP_PKEY_CTX_set_rsa_oaep_md_name, EVP_PKEY_CTX_set_rsa_oaep_md, EVP_PKEY_CTX_get_rsa_oaep_md, EVP_PKEY_CTX_get_rsa_oaep_md_name, EVP_PKEY_CTX_set0_rsa_oaep_label, EVP_PKEY_CTX_get0_rsa_oaep_label, EVP_PKEY_CTX_set_dsa_paramgen_bits, EVP_PKEY_CTX_set_dsa_paramgen_q_bits, EVP_PKEY_CTX_set_dsa_paramgen_md, EVP_PKEY_CTX_set_dsa_paramgen_md_props, EVP_PKEY_CTX_set_dsa_paramgen_gindex, EVP_PKEY_CTX_set_dsa_paramgen_type, EVP_PKEY_CTX_set_dsa_paramgen_seed, EVP_PKEY_CTX_set_dh_paramgen_prime_len, EVP_PKEY_CTX_set_dh_paramgen_subprime_len, EVP_PKEY_CTX_set_dh_paramgen_generator, EVP_PKEY_CTX_set_dh_paramgen_type, EVP_PKEY_CTX_set_dh_paramgen_gindex, EVP_PKEY_CTX_set_dh_paramgen_seed, EVP_PKEY_CTX_set_dh_rfc5114, EVP_PKEY_CTX_set_dhx_rfc5114, EVP_PKEY_CTX_set_dh_pad, EVP_PKEY_CTX_set_dh_nid, EVP_PKEY_CTX_set_dh_kdf_type, EVP_PKEY_CTX_get_dh_kdf_type, EVP_PKEY_CTX_set0_dh_kdf_oid, EVP_PKEY_CTX_get0_dh_kdf_oid, EVP_PKEY_CTX_set_dh_kdf_md, EVP_PKEY_CTX_get_dh_kdf_md, EVP_PKEY_CTX_set_dh_kdf_outlen, EVP_PKEY_CTX_get_dh_kdf_outlen, EVP_PKEY_CTX_set0_dh_kdf_ukm, EVP_PKEY_CTX_get0_dh_kdf_ukm, EVP_PKEY_CTX_set_ec_paramgen_curve_nid, EVP_PKEY_CTX_set_ec_param_enc, EVP_PKEY_CTX_set_ecdh_cofactor_mode, EVP_PKEY_CTX_get_ecdh_cofactor_mode, EVP_PKEY_CTX_set_ecdh_kdf_type, EVP_PKEY_CTX_get_ecdh_kdf_type, EVP_PKEY_CTX_set_ecdh_kdf_md, EVP_PKEY_CTX_get_ecdh_kdf_md, EVP_PKEY_CTX_set_ecdh_kdf_outlen, EVP_PKEY_CTX_get_ecdh_kdf_outlen, EVP_PKEY_CTX_set0_ecdh_kdf_ukm, EVP_PKEY_CTX_get0_ecdh_kdf_ukm, EVP_PKEY_CTX_set1_id, EVP_PKEY_CTX_get1_id, EVP_PKEY_CTX_get1_id_len, EVP_PKEY_CTX_set_kem_op - algorithm specific control operations

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_CTX_ctrl(EVP_PKEY_CTX *ctx, int keytype, int optype,
-                      int cmd, int p1, void *p2);
-int EVP_PKEY_CTX_ctrl_uint64(EVP_PKEY_CTX *ctx, int keytype, int optype,
-                             int cmd, uint64_t value);
-int EVP_PKEY_CTX_ctrl_str(EVP_PKEY_CTX *ctx, const char *type,
-                          const char *value);
-
-int EVP_PKEY_CTX_md(EVP_PKEY_CTX *ctx, int optype, int cmd, const char *md);
-
-int EVP_PKEY_CTX_set_signature_md(EVP_PKEY_CTX *ctx, const EVP_MD *md);
-int EVP_PKEY_CTX_get_signature_md(EVP_PKEY_CTX *ctx, const EVP_MD **pmd);
-
-int EVP_PKEY_CTX_set_mac_key(EVP_PKEY_CTX *ctx, const unsigned char *key,
-                             int len);
-int EVP_PKEY_CTX_set_group_name(EVP_PKEY_CTX *ctx, const char *name);
-int EVP_PKEY_CTX_get_group_name(EVP_PKEY_CTX *ctx, char *name, size_t namelen);
-
-int EVP_PKEY_CTX_set_kem_op(EVP_PKEY_CTX *ctx, const char *op);
-
-#include <openssl/rsa.h>
-
-int EVP_PKEY_CTX_set_rsa_padding(EVP_PKEY_CTX *ctx, int pad);
-int EVP_PKEY_CTX_get_rsa_padding(EVP_PKEY_CTX *ctx, int *pad);
-int EVP_PKEY_CTX_set_rsa_pss_saltlen(EVP_PKEY_CTX *ctx, int saltlen);
-int EVP_PKEY_CTX_get_rsa_pss_saltlen(EVP_PKEY_CTX *ctx, int *saltlen);
-int EVP_PKEY_CTX_set_rsa_keygen_bits(EVP_PKEY_CTX *ctx, int mbits);
-int EVP_PKEY_CTX_set1_rsa_keygen_pubexp(EVP_PKEY_CTX *ctx, BIGNUM *pubexp);
-int EVP_PKEY_CTX_set_rsa_keygen_primes(EVP_PKEY_CTX *ctx, int primes);
-int EVP_PKEY_CTX_set_rsa_mgf1_md_name(EVP_PKEY_CTX *ctx, const char *mdname,
-                                    const char *mdprops);
-int EVP_PKEY_CTX_set_rsa_mgf1_md(EVP_PKEY_CTX *ctx, const EVP_MD *md);
-int EVP_PKEY_CTX_get_rsa_mgf1_md(EVP_PKEY_CTX *ctx, const EVP_MD **md);
-int EVP_PKEY_CTX_get_rsa_mgf1_md_name(EVP_PKEY_CTX *ctx, char *name,
-                                      size_t namelen);
-int EVP_PKEY_CTX_set_rsa_oaep_md_name(EVP_PKEY_CTX *ctx, const char *mdname,
-                                      const char *mdprops);
-int EVP_PKEY_CTX_set_rsa_oaep_md(EVP_PKEY_CTX *ctx, const EVP_MD *md);
-int EVP_PKEY_CTX_get_rsa_oaep_md(EVP_PKEY_CTX *ctx, const EVP_MD **md);
-int EVP_PKEY_CTX_get_rsa_oaep_md_name(EVP_PKEY_CTX *ctx, char *name,
-                                      size_t namelen);
-int EVP_PKEY_CTX_set0_rsa_oaep_label(EVP_PKEY_CTX *ctx, void *label,
-                                     int len);
-int EVP_PKEY_CTX_get0_rsa_oaep_label(EVP_PKEY_CTX *ctx, unsigned char **label);
-
-#include <openssl/dsa.h>
-
-int EVP_PKEY_CTX_set_dsa_paramgen_bits(EVP_PKEY_CTX *ctx, int nbits);
-int EVP_PKEY_CTX_set_dsa_paramgen_q_bits(EVP_PKEY_CTX *ctx, int qbits);
-int EVP_PKEY_CTX_set_dsa_paramgen_md(EVP_PKEY_CTX *ctx, const EVP_MD *md);
-int EVP_PKEY_CTX_set_dsa_paramgen_md_props(EVP_PKEY_CTX *ctx,
-                                           const char *md_name,
-                                           const char *md_properties);
-int EVP_PKEY_CTX_set_dsa_paramgen_type(EVP_PKEY_CTX *ctx, const char *name);
-int EVP_PKEY_CTX_set_dsa_paramgen_gindex(EVP_PKEY_CTX *ctx, int gindex);
-int EVP_PKEY_CTX_set_dsa_paramgen_seed(EVP_PKEY_CTX *ctx,
-                                       const unsigned char *seed,
-                                       size_t seedlen);
-
-#include <openssl/dh.h>
-
-int EVP_PKEY_CTX_set_dh_paramgen_prime_len(EVP_PKEY_CTX *ctx, int len);
-int EVP_PKEY_CTX_set_dh_paramgen_subprime_len(EVP_PKEY_CTX *ctx, int len);
-int EVP_PKEY_CTX_set_dh_paramgen_generator(EVP_PKEY_CTX *ctx, int gen);
-int EVP_PKEY_CTX_set_dh_paramgen_type(EVP_PKEY_CTX *ctx, int type);
-int EVP_PKEY_CTX_set_dh_pad(EVP_PKEY_CTX *ctx, int pad);
-int EVP_PKEY_CTX_set_dh_nid(EVP_PKEY_CTX *ctx, int nid);
-int EVP_PKEY_CTX_set_dh_rfc5114(EVP_PKEY_CTX *ctx, int rfc5114);
-int EVP_PKEY_CTX_set_dhx_rfc5114(EVP_PKEY_CTX *ctx, int rfc5114);
-int EVP_PKEY_CTX_set_dh_paramgen_gindex(EVP_PKEY_CTX *ctx, int gindex);
-int EVP_PKEY_CTX_set_dh_paramgen_seed(EVP_PKEY_CTX *ctx,
-                                       const unsigned char *seed,
-                                       size_t seedlen);
-int EVP_PKEY_CTX_set_dh_kdf_type(EVP_PKEY_CTX *ctx, int kdf);
-int EVP_PKEY_CTX_get_dh_kdf_type(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_CTX_set0_dh_kdf_oid(EVP_PKEY_CTX *ctx, ASN1_OBJECT *oid);
-int EVP_PKEY_CTX_get0_dh_kdf_oid(EVP_PKEY_CTX *ctx, ASN1_OBJECT **oid);
-int EVP_PKEY_CTX_set_dh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD *md);
-int EVP_PKEY_CTX_get_dh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD **md);
-int EVP_PKEY_CTX_set_dh_kdf_outlen(EVP_PKEY_CTX *ctx, int len);
-int EVP_PKEY_CTX_get_dh_kdf_outlen(EVP_PKEY_CTX *ctx, int *len);
-int EVP_PKEY_CTX_set0_dh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char *ukm, int len);
-
-#include <openssl/ec.h>
-
-int EVP_PKEY_CTX_set_ec_paramgen_curve_nid(EVP_PKEY_CTX *ctx, int nid);
-int EVP_PKEY_CTX_set_ec_param_enc(EVP_PKEY_CTX *ctx, int param_enc);
-int EVP_PKEY_CTX_set_ecdh_cofactor_mode(EVP_PKEY_CTX *ctx, int cofactor_mode);
-int EVP_PKEY_CTX_get_ecdh_cofactor_mode(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_CTX_set_ecdh_kdf_type(EVP_PKEY_CTX *ctx, int kdf);
-int EVP_PKEY_CTX_get_ecdh_kdf_type(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_CTX_set_ecdh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD *md);
-int EVP_PKEY_CTX_get_ecdh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD **md);
-int EVP_PKEY_CTX_set_ecdh_kdf_outlen(EVP_PKEY_CTX *ctx, int len);
-int EVP_PKEY_CTX_get_ecdh_kdf_outlen(EVP_PKEY_CTX *ctx, int *len);
-int EVP_PKEY_CTX_set0_ecdh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char *ukm, int len);
-
-int EVP_PKEY_CTX_set1_id(EVP_PKEY_CTX *ctx, void *id, size_t id_len);
-int EVP_PKEY_CTX_get1_id(EVP_PKEY_CTX *ctx, void *id);
-int EVP_PKEY_CTX_get1_id_len(EVP_PKEY_CTX *ctx, size_t *id_len);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#include <openssl/rsa.h>
-
-int EVP_PKEY_CTX_set_rsa_keygen_pubexp(EVP_PKEY_CTX *ctx, BIGNUM *pubexp);
-
-#include <openssl/dh.h>
-
-int EVP_PKEY_CTX_get0_dh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char **ukm);
-
-#include <openssl/ec.h>
-
-int EVP_PKEY_CTX_get0_ecdh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char **ukm);
- -

DESCRIPTION

- -

EVP_PKEY_CTX_ctrl() sends a control operation to the context ctx. The key type used must match keytype if it is not -1. The parameter optype is a mask indicating which operations the control can be applied to. The control command is indicated in cmd and any additional arguments in p1 and p2.

- -

For cmd = EVP_PKEY_CTRL_SET_MAC_KEY, p1 is the length of the MAC key, and p2 is the MAC key. This is used by Poly1305, SipHash, HMAC and CMAC.

- -

Applications will not normally call EVP_PKEY_CTX_ctrl() directly but will instead call one of the algorithm specific functions below.

- -

EVP_PKEY_CTX_ctrl_uint64() is a wrapper that directly passes a uint64 value as p2 to EVP_PKEY_CTX_ctrl().

- -

EVP_PKEY_CTX_ctrl_str() allows an application to send an algorithm specific control operation to a context ctx in string form. This is intended to be used for options specified on the command line or in text files. The commands supported are documented in the openssl utility command line pages for the option -pkeyopt which is supported by the pkeyutl, genpkey and req commands.

- -

EVP_PKEY_CTX_md() sends a message digest control operation to the context ctx. The message digest is specified by its name md.

- -

EVP_PKEY_CTX_set_signature_md() sets the message digest type used in a signature. It can be used in the RSA, DSA and ECDSA algorithms.

- -

EVP_PKEY_CTX_get_signature_md()gets the message digest type used in a signature. It can be used in the RSA, DSA and ECDSA algorithms.

- -

Key generation typically involves setting up parameters to be used and generating the private and public key data. Some algorithm implementations allow private key data to be set explicitly using EVP_PKEY_CTX_set_mac_key(). In this case key generation is simply the process of setting up the parameters for the key and then setting the raw key data to the value explicitly. Normally applications would call EVP_PKEY_new_raw_private_key(3) or similar functions instead.

- -

EVP_PKEY_CTX_set_mac_key() can be used with any of the algorithms supported by the EVP_PKEY_new_raw_private_key(3) function.

- -

EVP_PKEY_CTX_set_group_name() sets the group name to name for parameter and key generation. For example for EC keys this will set the curve name and for DH keys it will set the name of the finite field group.

- -

EVP_PKEY_CTX_get_group_name() finds the group name that's currently set with ctx, and writes it to the location that name points at, as long as its size namelen is large enough to store that name, including a terminating NUL byte.

- -

RSA parameters

- -

EVP_PKEY_CTX_set_rsa_padding() sets the RSA padding mode for ctx. The pad parameter can take the value RSA_PKCS1_PADDING for PKCS#1 padding, RSA_NO_PADDING for no padding, RSA_PKCS1_OAEP_PADDING for OAEP padding (encrypt and decrypt only), RSA_X931_PADDING for X9.31 padding (signature operations only), RSA_PKCS1_PSS_PADDING (sign and verify only) and RSA_PKCS1_WITH_TLS_PADDING for TLS RSA ClientKeyExchange message padding (decryption only).

- -

Two RSA padding modes behave differently if EVP_PKEY_CTX_set_signature_md() is used. If this function is called for PKCS#1 padding the plaintext buffer is an actual digest value and is encapsulated in a DigestInfo structure according to PKCS#1 when signing and this structure is expected (and stripped off) when verifying. If this control is not used with RSA and PKCS#1 padding then the supplied data is used directly and not encapsulated. In the case of X9.31 padding for RSA the algorithm identifier byte is added or checked and removed if this control is called. If it is not called then the first byte of the plaintext buffer is expected to be the algorithm identifier byte.

- -

EVP_PKEY_CTX_get_rsa_padding() gets the RSA padding mode for ctx.

- -

EVP_PKEY_CTX_set_rsa_pss_saltlen() sets the RSA PSS salt length to saltlen. As its name implies it is only supported for PSS padding. If this function is not called then the salt length is maximized up to the digest length when signing and auto detection when verifying. Four special values are supported:

- -
- -
RSA_PSS_SALTLEN_DIGEST
-
- -

sets the salt length to the digest length.

- -
-
RSA_PSS_SALTLEN_MAX
-
- -

sets the salt length to the maximum permissible value.

- -
-
RSA_PSS_SALTLEN_AUTO
-
- -

causes the salt length to be automatically determined based on the PSS block structure when verifying. When signing, it has the same meaning as RSA_PSS_SALTLEN_MAX.

- -
-
RSA_PSS_SALTLEN_AUTO_DIGEST_MAX
-
- -

causes the salt length to be automatically determined based on the PSS block structure when verifying, like RSA_PSS_SALTLEN_AUTO. When signing, the salt length is maximized up to a maximum of the digest length to comply with FIPS 186-4 section 5.5.

- -
-
- -

EVP_PKEY_CTX_get_rsa_pss_saltlen() gets the RSA PSS salt length for ctx. The padding mode must already have been set to RSA_PKCS1_PSS_PADDING.

- -

EVP_PKEY_CTX_set_rsa_keygen_bits() sets the RSA key length for RSA key generation to bits. If not specified 2048 bits is used.

- -

EVP_PKEY_CTX_set1_rsa_keygen_pubexp() sets the public exponent value for RSA key generation to the value stored in pubexp. Currently it should be an odd integer. In accordance with the OpenSSL naming convention, the pubexp pointer must be freed independently of the EVP_PKEY_CTX (ie, it is internally copied). If not specified 65537 is used.

- -

EVP_PKEY_CTX_set_rsa_keygen_pubexp() does the same as EVP_PKEY_CTX_set1_rsa_keygen_pubexp() except that there is no internal copy and therefore pubexp should not be modified or freed after the call.

- -

EVP_PKEY_CTX_set_rsa_keygen_primes() sets the number of primes for RSA key generation to primes. If not specified 2 is used.

- -

EVP_PKEY_CTX_set_rsa_mgf1_md_name() sets the MGF1 digest for RSA padding schemes to the digest named mdname. If the RSA algorithm implementation for the selected provider supports it then the digest will be fetched using the properties mdprops. If not explicitly set the signing digest is used. The padding mode must have been set to RSA_PKCS1_OAEP_PADDING or RSA_PKCS1_PSS_PADDING.

- -

EVP_PKEY_CTX_set_rsa_mgf1_md() does the same as EVP_PKEY_CTX_set_rsa_mgf1_md_name() except that the name of the digest is inferred from the supplied md and it is not possible to specify any properties.

- -

EVP_PKEY_CTX_get_rsa_mgf1_md_name() gets the name of the MGF1 digest algorithm for ctx. If not explicitly set the signing digest is used. The padding mode must have been set to RSA_PKCS1_OAEP_PADDING or RSA_PKCS1_PSS_PADDING.

- -

EVP_PKEY_CTX_get_rsa_mgf1_md() does the same as EVP_PKEY_CTX_get_rsa_mgf1_md_name() except that it returns a pointer to an EVP_MD object instead. Note that only known, built-in EVP_MD objects will be returned. The EVP_MD object may be NULL if the digest is not one of these (such as a digest only implemented in a third party provider).

- -

EVP_PKEY_CTX_set_rsa_oaep_md_name() sets the message digest type used in RSA OAEP to the digest named mdname. If the RSA algorithm implementation for the selected provider supports it then the digest will be fetched using the properties mdprops. The padding mode must have been set to RSA_PKCS1_OAEP_PADDING.

- -

EVP_PKEY_CTX_set_rsa_oaep_md() does the same as EVP_PKEY_CTX_set_rsa_oaep_md_name() except that the name of the digest is inferred from the supplied md and it is not possible to specify any properties.

- -

EVP_PKEY_CTX_get_rsa_oaep_md_name() gets the message digest algorithm name used in RSA OAEP and stores it in the buffer name which is of size namelen. The padding mode must have been set to RSA_PKCS1_OAEP_PADDING. The buffer should be sufficiently large for any expected digest algorithm names or the function will fail.

- -

EVP_PKEY_CTX_get_rsa_oaep_md() does the same as EVP_PKEY_CTX_get_rsa_oaep_md_name() except that it returns a pointer to an EVP_MD object instead. Note that only known, built-in EVP_MD objects will be returned. The EVP_MD object may be NULL if the digest is not one of these (such as a digest only implemented in a third party provider).

- -

EVP_PKEY_CTX_set0_rsa_oaep_label() sets the RSA OAEP label to binary data label and its length in bytes to len. If label is NULL or len is 0, the label is cleared. The library takes ownership of the label so the caller should not free the original memory pointed to by label. The padding mode must have been set to RSA_PKCS1_OAEP_PADDING.

- -

EVP_PKEY_CTX_get0_rsa_oaep_label() gets the RSA OAEP label to label. The return value is the label length. The padding mode must have been set to RSA_PKCS1_OAEP_PADDING. The resulting pointer is owned by the library and should not be freed by the caller.

- -

RSA_PKCS1_WITH_TLS_PADDING is used when decrypting an RSA encrypted TLS pre-master secret in a TLS ClientKeyExchange message. It is the same as RSA_PKCS1_PADDING except that it additionally verifies that the result is the correct length and the first two bytes are the protocol version initially requested by the client. If the encrypted content is publicly invalid then the decryption will fail. However, if the padding checks fail then decryption will still appear to succeed but a random TLS premaster secret will be returned instead. This padding mode accepts two parameters which can be set using the EVP_PKEY_CTX_set_params(3) function. These are OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION and OSSL_ASYM_CIPHER_PARAM_TLS_NEGOTIATED_VERSION, both of which are expected to be unsigned integers. Normally only the first of these will be set and represents the TLS protocol version that was first requested by the client (e.g. 0x0303 for TLSv1.2, 0x0302 for TLSv1.1 etc). Historically some buggy clients would use the negotiated protocol version instead of the protocol version first requested. If this behaviour should be tolerated then OSSL_ASYM_CIPHER_PARAM_TLS_NEGOTIATED_VERSION should be set to the actual negotiated protocol version. Otherwise it should be left unset.

- -

Similarly to the RSA_PKCS1_WITH_TLS_PADDING above, since OpenSSL version 3.2.0, the use of RSA_PKCS1_PADDING will return a randomly generated message instead of padding errors in case padding checks fail. Applications that want to remain secure while using earlier versions of OpenSSL, or a provider that doesn't implement the implicit rejection mechanism, still need to handle both the error code from the RSA decryption operation and the returned message in a side channel secure manner. This protection against Bleichenbacher attacks can be disabled by setting OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION (an unsigned integer) to 0.

- -

DSA parameters

- -

EVP_PKEY_CTX_set_dsa_paramgen_bits() sets the number of bits used for DSA parameter generation to nbits. If not specified, 2048 is used.

- -

EVP_PKEY_CTX_set_dsa_paramgen_q_bits() sets the number of bits in the subprime parameter q for DSA parameter generation to qbits. If not specified, 224 is used. If a digest function is specified below, this parameter is ignored and instead, the number of bits in q matches the size of the digest.

- -

EVP_PKEY_CTX_set_dsa_paramgen_md() sets the digest function used for DSA parameter generation to md. If not specified, one of SHA-1, SHA-224, or SHA-256 is selected to match the bit length of q above.

- -

EVP_PKEY_CTX_set_dsa_paramgen_md_props() sets the digest function used for DSA parameter generation using md_name and md_properties to retrieve the digest from a provider. If not specified, md_name will be set to one of SHA-1, SHA-224, or SHA-256 depending on the bit length of q above. md_properties is a property query string that has a default value of '' if not specified.

- -

EVP_PKEY_CTX_set_dsa_paramgen_gindex() sets the gindex used by the generator G. The default value is -1 which uses unverifiable g, otherwise a positive value uses verifiable g. This value must be saved if key validation of g is required, since it is not part of a persisted key.

- -

EVP_PKEY_CTX_set_dsa_paramgen_seed() sets the seed to use for generation rather than using a randomly generated value for the seed. This is useful for testing purposes only and can fail if the seed does not produce primes for both p & q on its first iteration. This value must be saved if key validation of p, q, and verifiable g are required, since it is not part of a persisted key.

- -

EVP_PKEY_CTX_set_dsa_paramgen_type() sets the generation type to use FIPS186-4 generation if name is "fips186_4", or FIPS186-2 generation if name is "fips186_2". The default value for the default provider is "fips186_2". The default value for the FIPS provider is "fips186_4".

- -

DH parameters

- -

EVP_PKEY_CTX_set_dh_paramgen_prime_len() sets the length of the DH prime parameter p for DH parameter generation. If this function is not called then 2048 is used. Only accepts lengths greater than or equal to 256.

- -

EVP_PKEY_CTX_set_dh_paramgen_subprime_len() sets the length of the DH optional subprime parameter q for DH parameter generation. The default is 256 if the prime is at least 2048 bits long or 160 otherwise. The DH paramgen type must have been set to "fips186_4".

- -

EVP_PKEY_CTX_set_dh_paramgen_generator() sets DH generator to gen for DH parameter generation. If not specified 2 is used.

- -

EVP_PKEY_CTX_set_dh_paramgen_type() sets the key type for DH parameter generation. The supported parameters are:

- -
- -
DH_PARAMGEN_TYPE_GROUP
-
- -

Use a named group. If only the safe prime parameter p is set this can be used to select a ffdhe safe prime group of the correct size.

- -
-
DH_PARAMGEN_TYPE_FIPS_186_4
-
- -

FIPS186-4 FFC parameter generator.

- -
-
DH_PARAMGEN_TYPE_FIPS_186_2
-
- -

FIPS186-2 FFC parameter generator (X9.42 DH).

- -
-
DH_PARAMGEN_TYPE_GENERATOR
-
- -

Uses a safe prime generator g (PKCS#3 format).

- -
-
- -

The default in the default provider is DH_PARAMGEN_TYPE_GENERATOR for the "DH" keytype, and DH_PARAMGEN_TYPE_FIPS_186_2 for the "DHX" keytype. In the FIPS provider the default value is DH_PARAMGEN_TYPE_GROUP for the "DH" keytype and <DH_PARAMGEN_TYPE_FIPS_186_4 for the "DHX" keytype.

- -

EVP_PKEY_CTX_set_dh_paramgen_gindex() sets the gindex used by the generator G. The default value is -1 which uses unverifiable g, otherwise a positive value uses verifiable g. This value must be saved if key validation of g is required, since it is not part of a persisted key.

- -

EVP_PKEY_CTX_set_dh_paramgen_seed() sets the seed to use for generation rather than using a randomly generated value for the seed. This is useful for testing purposes only and can fail if the seed does not produce primes for both p & q on its first iteration. This value must be saved if key validation of p, q, and verifiable g are required, since it is not part of a persisted key.

- -

EVP_PKEY_CTX_set_dh_pad() sets the DH padding mode. If pad is 1 the shared secret is padded with zeros up to the size of the DH prime p. If pad is zero (the default) then no padding is performed.

- -

EVP_PKEY_CTX_set_dh_nid() sets the DH parameters to values corresponding to nid as defined in RFC7919 or RFC3526. The nid parameter must be NID_ffdhe2048, NID_ffdhe3072, NID_ffdhe4096, NID_ffdhe6144, NID_ffdhe8192, NID_modp_1536, NID_modp_2048, NID_modp_3072, NID_modp_4096, NID_modp_6144, NID_modp_8192 or NID_undef to clear the stored value. This function can be called during parameter or key generation. The nid parameter and the rfc5114 parameter are mutually exclusive.

- -

EVP_PKEY_CTX_set_dh_rfc5114() and EVP_PKEY_CTX_set_dhx_rfc5114() both set the DH parameters to the values defined in RFC5114. The rfc5114 parameter must be 1, 2 or 3 corresponding to RFC5114 sections 2.1, 2.2 and 2.3. or 0 to clear the stored value. This macro can be called during parameter generation. The ctx must have a key type of EVP_PKEY_DHX. The rfc5114 parameter and the nid parameter are mutually exclusive.

- -

DH key derivation function parameters

- -

Note that all of the following functions require that the ctx parameter has a private key type of EVP_PKEY_DHX. When using key derivation, the output of EVP_PKEY_derive() is the output of the KDF instead of the DH shared secret. The KDF output is typically used as a Key Encryption Key (KEK) that in turn encrypts a Content Encryption Key (CEK).

- -

EVP_PKEY_CTX_set_dh_kdf_type() sets the key derivation function type to kdf for DH key derivation. Possible values are EVP_PKEY_DH_KDF_NONE and EVP_PKEY_DH_KDF_X9_42 which uses the key derivation specified in RFC2631 (based on the keying algorithm described in X9.42). When using key derivation, the kdf_oid, kdf_md and kdf_outlen parameters must also be specified.

- -

EVP_PKEY_CTX_get_dh_kdf_type() gets the key derivation function type for ctx used for DH key derivation. Possible values are EVP_PKEY_DH_KDF_NONE and EVP_PKEY_DH_KDF_X9_42.

- -

EVP_PKEY_CTX_set0_dh_kdf_oid() sets the key derivation function object identifier to oid for DH key derivation. This OID should identify the algorithm to be used with the Content Encryption Key. The library takes ownership of the object identifier so the caller should not free the original memory pointed to by oid.

- -

EVP_PKEY_CTX_get0_dh_kdf_oid() gets the key derivation function oid for ctx used for DH key derivation. The resulting pointer is owned by the library and should not be freed by the caller.

- -

EVP_PKEY_CTX_set_dh_kdf_md() sets the key derivation function message digest to md for DH key derivation. Note that RFC2631 specifies that this digest should be SHA1 but OpenSSL tolerates other digests.

- -

EVP_PKEY_CTX_get_dh_kdf_md() gets the key derivation function message digest for ctx used for DH key derivation.

- -

EVP_PKEY_CTX_set_dh_kdf_outlen() sets the key derivation function output length to len for DH key derivation.

- -

EVP_PKEY_CTX_get_dh_kdf_outlen() gets the key derivation function output length for ctx used for DH key derivation.

- -

EVP_PKEY_CTX_set0_dh_kdf_ukm() sets the user key material to ukm and its length to len for DH key derivation. This parameter is optional and corresponds to the partyAInfo field in RFC2631 terms. The specification requires that it is 512 bits long but this is not enforced by OpenSSL. The library takes ownership of the user key material so the caller should not free the original memory pointed to by ukm.

- -

EVP_PKEY_CTX_get0_dh_kdf_ukm() gets the user key material for ctx. The return value is the user key material length. The resulting pointer is owned by the library and should not be freed by the caller.

- -

EC parameters

- -

Use EVP_PKEY_CTX_set_group_name() (described above) to set the curve name to name for parameter and key generation.

- -

EVP_PKEY_CTX_set_ec_paramgen_curve_nid() does the same as EVP_PKEY_CTX_set_group_name(), but is specific to EC and uses a nid rather than a name string.

- -

For EC parameter generation, one of EVP_PKEY_CTX_set_group_name() or EVP_PKEY_CTX_set_ec_paramgen_curve_nid() must be called or an error occurs because there is no default curve. These function can also be called to set the curve explicitly when generating an EC key.

- -

EVP_PKEY_CTX_get_group_name() (described above) can be used to obtain the curve name that's currently set with ctx.

- -

EVP_PKEY_CTX_set_ec_param_enc() sets the EC parameter encoding to param_enc when generating EC parameters or an EC key. The encoding can be OPENSSL_EC_EXPLICIT_CURVE for explicit parameters (the default in versions of OpenSSL before 1.1.0) or OPENSSL_EC_NAMED_CURVE to use named curve form. For maximum compatibility the named curve form should be used. Note: the OPENSSL_EC_NAMED_CURVE value was added in OpenSSL 1.1.0; previous versions should use 0 instead.

- -

ECDH parameters

- -

EVP_PKEY_CTX_set_ecdh_cofactor_mode() sets the cofactor mode to cofactor_mode for ECDH key derivation. Possible values are 1 to enable cofactor key derivation, 0 to disable it and -1 to clear the stored cofactor mode and fallback to the private key cofactor mode.

- -

EVP_PKEY_CTX_get_ecdh_cofactor_mode() returns the cofactor mode for ctx used for ECDH key derivation. Possible values are 1 when cofactor key derivation is enabled and 0 otherwise.

- -

ECDH key derivation function parameters

- -

EVP_PKEY_CTX_set_ecdh_kdf_type() sets the key derivation function type to kdf for ECDH key derivation. Possible values are EVP_PKEY_ECDH_KDF_NONE and EVP_PKEY_ECDH_KDF_X9_63 which uses the key derivation specified in X9.63. When using key derivation, the kdf_md and kdf_outlen parameters must also be specified.

- -

EVP_PKEY_CTX_get_ecdh_kdf_type() returns the key derivation function type for ctx used for ECDH key derivation. Possible values are EVP_PKEY_ECDH_KDF_NONE and EVP_PKEY_ECDH_KDF_X9_63.

- -

EVP_PKEY_CTX_set_ecdh_kdf_md() sets the key derivation function message digest to md for ECDH key derivation. Note that X9.63 specifies that this digest should be SHA1 but OpenSSL tolerates other digests.

- -

EVP_PKEY_CTX_get_ecdh_kdf_md() gets the key derivation function message digest for ctx used for ECDH key derivation.

- -

EVP_PKEY_CTX_set_ecdh_kdf_outlen() sets the key derivation function output length to len for ECDH key derivation.

- -

EVP_PKEY_CTX_get_ecdh_kdf_outlen() gets the key derivation function output length for ctx used for ECDH key derivation.

- -

EVP_PKEY_CTX_set0_ecdh_kdf_ukm() sets the user key material to ukm for ECDH key derivation. This parameter is optional and corresponds to the shared info in X9.63 terms. The library takes ownership of the user key material so the caller should not free the original memory pointed to by ukm.

- -

EVP_PKEY_CTX_get0_ecdh_kdf_ukm() gets the user key material for ctx. The return value is the user key material length. The resulting pointer is owned by the library and should not be freed by the caller.

- -

Other parameters

- -

EVP_PKEY_CTX_set1_id(), EVP_PKEY_CTX_get1_id() and EVP_PKEY_CTX_get1_id_len() are used to manipulate the special identifier field for specific signature algorithms such as SM2. The EVP_PKEY_CTX_set1_id() sets an ID pointed by id with the length id_len to the library. The library takes a copy of the id so that the caller can safely free the original memory pointed to by id. EVP_PKEY_CTX_get1_id_len() returns the length of the ID set via a previous call to EVP_PKEY_CTX_set1_id(). The length is usually used to allocate adequate memory for further calls to EVP_PKEY_CTX_get1_id(). EVP_PKEY_CTX_get1_id() returns the previously set ID value to caller in id. The caller should allocate adequate memory space for the id before calling EVP_PKEY_CTX_get1_id().

- -

EVP_PKEY_CTX_set_kem_op() sets the KEM operation to run. This can be set after EVP_PKEY_encapsulate_init() or EVP_PKEY_decapsulate_init() to select the kem operation. For the key types that support encapsulation and don't have the default operation, e.g. RSA, this function must be called before EVP_PKEY_encapsulate() or EVP_PKEY_decapsulate(). The supported values for the built-in algorithms are enumerated in EVP_KEM-RSA(7), EVP_KEM-EC(7), EVP_KEM-X25519(7), and EVP_KEM-X448(7).

- -

RETURN VALUES

- -

All other functions described on this page return a positive value for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

SEE ALSO

- -

EVP_PKEY_CTX_set_params(3), EVP_PKEY_CTX_new(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3), EVP_PKEY_keygen(3) EVP_PKEY_encapsulate(3) EVP_PKEY_decapsulate(3)

- -

HISTORY

- -

EVP_PKEY_CTX_get_rsa_oaep_md_name(), EVP_PKEY_CTX_get_rsa_mgf1_md_name(), EVP_PKEY_CTX_set_rsa_mgf1_md_name(), EVP_PKEY_CTX_set_rsa_oaep_md_name(), EVP_PKEY_CTX_set_dsa_paramgen_md_props(), EVP_PKEY_CTX_set_dsa_paramgen_gindex(), EVP_PKEY_CTX_set_dsa_paramgen_type(), EVP_PKEY_CTX_set_dsa_paramgen_seed(), EVP_PKEY_CTX_set_group_name() and EVP_PKEY_CTX_get_group_name() were added in OpenSSL 3.0.

- -

The EVP_PKEY_CTX_set1_id(), EVP_PKEY_CTX_get1_id() and EVP_PKEY_CTX_get1_id_len() macros were added in 1.1.1, other functions were added in OpenSSL 1.0.0.

- -

In OpenSSL 1.1.1 and below the functions were mostly macros. From OpenSSL 3.0 they are all functions.

- -

EVP_PKEY_CTX_set_rsa_keygen_pubexp(), EVP_PKEY_CTX_get0_dh_kdf_ukm(), and EVP_PKEY_CTX_get0_ecdh_kdf_ukm() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_libctx.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_libctx.html deleted file mode 100644 index 558d0e40..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_libctx.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -EVP_PKEY_CTX_get0_libctx - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_get0_libctx, EVP_PKEY_CTX_get0_propq, EVP_PKEY_CTX_get0_provider - functions for getting diverse information from an EVP_PKEY_CTX

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-OSSL_LIB_CTX *EVP_PKEY_CTX_get0_libctx(EVP_PKEY_CTX *ctx);
-const char *EVP_PKEY_CTX_get0_propq(const EVP_PKEY_CTX *ctx);
-const OSSL_PROVIDER *EVP_PKEY_CTX_get0_provider(const EVP_PKEY_CTX *ctx);
- -

DESCRIPTION

- -

EVP_PKEY_CTX_get0_libctx() and EVP_PKEY_CTX_get0_propq() obtain the OSSL_LIB_CTX and property query string values respectively that were associated with the EVP_PKEY_CTX when it was constructed.

- -

EVP_PKEY_CTX_get0_provider() returns the provider associated with the ongoing EVP_PKEY_CTX operation. If the operation is performed by en ENGINE, this function returns NULL.

- -

RETURN VALUES

- -

EVP_PKEY_CTX_get0_libctx() and EVP_PKEY_CTX_get0_propq() functions return the OSSL_LIB_CTX and property query string associated with the EVP_PKEY_CTX or NULL if they are not set. The returned values should not be freed by the caller.

- -

EVP_PKEY_CTX_get0_provider() returns a provider if an operation performed by a provider is ongoing, otherwise NULL.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3)

- -

HISTORY

- -

All functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_pkey.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_pkey.html deleted file mode 100644 index 49802642..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get0_pkey.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -EVP_PKEY_CTX_get0_pkey - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_get0_pkey, EVP_PKEY_CTX_get0_peerkey - functions for accessing the EVP_PKEY associated with an EVP_PKEY_CTX

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_PKEY *EVP_PKEY_CTX_get0_pkey(EVP_PKEY_CTX *ctx);
-EVP_PKEY *EVP_PKEY_CTX_get0_peerkey(EVP_PKEY_CTX *ctx);
- -

DESCRIPTION

- -

EVP_PKEY_CTX_get0_pkey() is used to access the EVP_PKEY associated with the given EVP_PKEY_CTX ctx. The EVP_PKEY obtained is the one used for creating the EVP_PKEY_CTX using either EVP_PKEY_CTX_new(3) or EVP_PKEY_CTX_new_from_pkey(3).

- -

EVP_PKEY_CTX_get0_peerkey() is used to access the peer EVP_PKEY associated with the given EVP_PKEY_CTX ctx. The peer EVP_PKEY obtained is the one set using either EVP_PKEY_derive_set_peer(3) or EVP_PKEY_derive_set_peer_ex(3).

- -

RETURN VALUES

- -

EVP_PKEY_CTX_get0_pkey() returns the EVP_PKEY associated with the EVP_PKEY_CTX or NULL if it is not set.

- -

EVP_PKEY_CTX_get0_peerkey() returns the peer EVP_PKEY associated with the EVP_PKEY_CTX or NULL if it is not set.

- -

The returned EVP_PKEY objects are owned by the EVP_PKEY_CTX, and therefore should not explicitly be freed by the caller.

- -

These functions do not affect the EVP_PKEY reference count. They merely act as getter functions, and should be treated as such.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_new_from_pkey(3), EVP_PKEY_derive_set_peer(3), EVP_PKEY_derive_set_peer_ex(3)

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get_algor.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get_algor.html deleted file mode 100644 index 6e466149..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_get_algor.html +++ /dev/null @@ -1,57 +0,0 @@ - - - - -EVP_PKEY_CTX_get_algor - - - - - - - - - - -

NAME

- -

EVP_CIPHER_CTX_get_algor, EVP_CIPHER_CTX_get_algor_params, EVP_CIPHER_CTX_set_algor_params, EVP_PKEY_CTX_get_algor, EVP_PKEY_CTX_get_algor_params, EVP_PKEY_CTX_set_algor_params - pass AlgorithmIdentifier and its params to/from algorithm implementations

- -

SYNOPSIS

- -
int EVP_TYPE_CTX_get_algor(EVP_TYPE_CTX *ctx, X509_ALGOR **alg);
-int EVP_TYPE_CTX_get_algor_params(EVP_TYPE_CTX *ctx, X509_ALGOR *alg);
-int EVP_TYPE_CTX_set_algor_params(EVP_TYPE_CTX *ctx, const X509_ALGOR *alg);
- -

DESCRIPTION

- -

In the description here and the "SYNOPSIS" above, TYPE is used as a placeholder for any EVP operation type.

- -

EVP_TYPE_CTX_get_algor() attempts to retrieve a complete AlgorithmIdentifier from the EVP_TYPE implementation, and populates *alg with it. If alg is NULL, calling this function will serve to see if calling this function is supported at all by the EVP_TYPE implementation. If *alg is NULL, space will be allocated automatically, and assigned to *alg.

- -

EVP_TYPE_CTX_get_algor_params() attempts to retrieve the parameters part of an AlgorithmIdentifier from the EVP_TYPE implementation, and populates alg-parameters> with it. If alg is NULL, calling this function will serve to see if calling this function is supported at all by the EVP_TYPE implementation. If alg->parameters is NULL, space will be allocated automatically, and assigned to alg->parameters. If alg->parameters is not NULL, its previous contents will be overwritten with the retrieved AlgorithmIdentifier parameters. Beware!

- -

EVP_TYPE_CTX_set_algor_params() attempts to pass alg->parameters to the EVP_TYPE implementation. If alg is NULL, calling this function will serve to see if calling this function is supported at all by the EVP_TYPE implementation.

- -

RETURN VALUES

- -

All functions return 1 for success, and 0 or a negative number if an error occurs. In particular, -2 is returned when the function isn't supported by the EVP_TYPE implementation.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_new.html deleted file mode 100644 index bcfc0a01..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_new.html +++ /dev/null @@ -1,131 +0,0 @@ - - - - -EVP_PKEY_CTX_new - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_new, EVP_PKEY_CTX_new_id, EVP_PKEY_CTX_new_from_name, EVP_PKEY_CTX_new_from_pkey, EVP_PKEY_CTX_dup, EVP_PKEY_CTX_free, EVP_PKEY_CTX_is_a - public key algorithm context functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_PKEY_CTX *EVP_PKEY_CTX_new(EVP_PKEY *pkey, ENGINE *e);
-EVP_PKEY_CTX *EVP_PKEY_CTX_new_id(int id, ENGINE *e);
-EVP_PKEY_CTX *EVP_PKEY_CTX_new_from_name(OSSL_LIB_CTX *libctx,
-                                         const char *name,
-                                         const char *propquery);
-EVP_PKEY_CTX *EVP_PKEY_CTX_new_from_pkey(OSSL_LIB_CTX *libctx,
-                                         EVP_PKEY *pkey,
-                                         const char *propquery);
-EVP_PKEY_CTX *EVP_PKEY_CTX_dup(const EVP_PKEY_CTX *ctx);
-void EVP_PKEY_CTX_free(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_CTX_is_a(EVP_PKEY_CTX *ctx, const char *keytype);
- -

DESCRIPTION

- -

The EVP_PKEY_CTX_new() function allocates public key algorithm context using the pkey key type and ENGINE e.

- -

The EVP_PKEY_CTX_new_id() function allocates public key algorithm context using the key type specified by id and ENGINE e.

- -

The EVP_PKEY_CTX_new_from_name() function allocates a public key algorithm context using the library context libctx (see OSSL_LIB_CTX(3)), the key type specified by name and the property query propquery. None of the arguments are duplicated, so they must remain unchanged for the lifetime of the returned EVP_PKEY_CTX or of any of its duplicates. Read further about the possible names in "NOTES" below.

- -

The EVP_PKEY_CTX_new_from_pkey() function allocates a public key algorithm context using the library context libctx (see OSSL_LIB_CTX(3)) and the algorithm specified by pkey and the property query propquery. None of the arguments are duplicated, so they must remain unchanged for the lifetime of the returned EVP_PKEY_CTX or any of its duplicates.

- -

EVP_PKEY_CTX_new_id() and EVP_PKEY_CTX_new_from_name() are normally used when no EVP_PKEY structure is associated with the operations, for example during parameter generation or key generation for some algorithms.

- -

EVP_PKEY_CTX_dup() duplicates the context ctx. It is not supported for a keygen operation. It is however possible to duplicate a context freshly created via any of the above new functions, provided EVP_PKEY_keygen_init(3) has not yet been called on the source context, and then use the copy for key generation.

- -

EVP_PKEY_CTX_free() frees up the context ctx. If ctx is NULL, nothing is done.

- -

EVP_PKEY_is_a() checks if the key type associated with ctx is keytype.

- -

NOTES

- -

On EVP_PKEY_CTX

- -

The EVP_PKEY_CTX structure is an opaque public key algorithm context used by the OpenSSL high-level public key API. Contexts MUST NOT be shared between threads: that is it is not permissible to use the same context simultaneously in two threads.

- -

On Key Types

- -

We mention "key type" in this manual, which is the same as "algorithm" in most cases, allowing either term to be used interchangeably. There are algorithms where the key type and the algorithm of the operations that use the keys are not the same, such as EC keys being used for ECDSA and ECDH operations.

- -

Key types are given in two different manners:

- -
- -
Legacy NID or EVP_PKEY type
-
- -

This is the id used with EVP_PKEY_CTX_new_id().

- -

These are EVP_PKEY_RSA, EVP_PKEY_RSA_PSS, EVP_PKEY_DSA, EVP_PKEY_DH, EVP_PKEY_EC, EVP_PKEY_SM2, EVP_PKEY_X25519, EVP_PKEY_X448, and are used by legacy methods.

- -
-
Name strings
-
- -

This is the name used with EVP_PKEY_CTX_new_from_name().

- -

These are names like "RSA", "DSA", and what's available depends on what providers are currently accessible.

- -

The OpenSSL providers offer a set of key types available this way, please see OSSL_PROVIDER-FIPS(7) and OSSL_PROVIDER-default(7) and related documentation for more information.

- -
-
- -

RETURN VALUES

- -

EVP_PKEY_CTX_new(), EVP_PKEY_CTX_new_id() and EVP_PKEY_CTX_dup() return either the newly allocated EVP_PKEY_CTX structure or NULL if an error occurred.

- -

EVP_PKEY_CTX_free() does not return a value.

- -

EVP_PKEY_CTX_is_a() returns 1 for true and 0 for false.

- -

SEE ALSO

- -

EVP_PKEY_new(3)

- -

HISTORY

- -

The EVP_PKEY_CTX_new(), EVP_PKEY_CTX_new_id(), EVP_PKEY_CTX_dup() and EVP_PKEY_CTX_free() functions were added in OpenSSL 1.0.0.

- -

The EVP_PKEY_CTX_new_from_name() and EVP_PKEY_CTX_new_from_pkey() functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set1_pbe_pass.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set1_pbe_pass.html deleted file mode 100644 index eff0f684..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set1_pbe_pass.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -EVP_PKEY_CTX_set1_pbe_pass - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_set1_pbe_pass - generic KDF support functions

- -

SYNOPSIS

- -
#include <openssl/kdf.h>
-
-int EVP_PKEY_CTX_set1_pbe_pass(EVP_PKEY_CTX *pctx, unsigned char *pass,
-                               int passlen);
- -

DESCRIPTION

- -

These functions are generic support functions for all KDF algorithms.

- -

EVP_PKEY_CTX_set1_pbe_pass() sets the password to the passlen first bytes from pass.

- -

STRING CTRLS

- -

There is also support for string based control operations via EVP_PKEY_CTX_ctrl_str(3). The password can be directly specified using the type parameter "pass" or given in hex encoding using the "hexpass" parameter.

- -

RETURN VALUES

- -

All these functions return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_ctrl_str(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

EVP_PKEY_CTX_set1_pbe_pass() was converted from a macro to a function in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_hkdf_md.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_hkdf_md.html deleted file mode 100644 index e7a80b04..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_hkdf_md.html +++ /dev/null @@ -1,156 +0,0 @@ - - - - -EVP_PKEY_CTX_set_hkdf_md - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_set_hkdf_md, EVP_PKEY_CTX_set1_hkdf_salt, EVP_PKEY_CTX_set1_hkdf_key, EVP_PKEY_CTX_add1_hkdf_info, EVP_PKEY_CTX_set_hkdf_mode - HMAC-based Extract-and-Expand key derivation algorithm

- -

SYNOPSIS

- -
#include <openssl/kdf.h>
-
-int EVP_PKEY_CTX_set_hkdf_mode(EVP_PKEY_CTX *pctx, int mode);
-
-int EVP_PKEY_CTX_set_hkdf_md(EVP_PKEY_CTX *pctx, const EVP_MD *md);
-
-int EVP_PKEY_CTX_set1_hkdf_salt(EVP_PKEY_CTX *pctx, unsigned char *salt,
-                                int saltlen);
-
-int EVP_PKEY_CTX_set1_hkdf_key(EVP_PKEY_CTX *pctx, unsigned char *key,
-                               int keylen);
-
-int EVP_PKEY_CTX_add1_hkdf_info(EVP_PKEY_CTX *pctx, unsigned char *info,
-                                int infolen);
- -

DESCRIPTION

- -

The EVP_PKEY_HKDF algorithm implements the HKDF key derivation function. HKDF follows the "extract-then-expand" paradigm, where the KDF logically consists of two modules. The first stage takes the input keying material and "extracts" from it a fixed-length pseudorandom key K. The second stage "expands" the key K into several additional pseudorandom keys (the output of the KDF).

- -

EVP_PKEY_CTX_set_hkdf_mode() sets the mode for the HKDF operation. There are three modes that are currently defined:

- -
- -
EVP_PKEY_HKDEF_MODE_EXTRACT_AND_EXPAND
-
- -

This is the default mode. Calling EVP_PKEY_derive(3) on an EVP_PKEY_CTX set up for HKDF will perform an extract followed by an expand operation in one go. The derived key returned will be the result after the expand operation. The intermediate fixed-length pseudorandom key K is not returned.

- -

In this mode the digest, key, salt and info values must be set before a key is derived or an error occurs.

- -
-
EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY
-
- -

In this mode calling EVP_PKEY_derive(3) will just perform the extract operation. The value returned will be the intermediate fixed-length pseudorandom key K.

- -

The digest, key and salt values must be set before a key is derived or an error occurs.

- -
-
EVP_PKEY_HKDEF_MODE_EXPAND_ONLY
-
- -

In this mode calling EVP_PKEY_derive(3) will just perform the expand operation. The input key should be set to the intermediate fixed-length pseudorandom key K returned from a previous extract operation.

- -

The digest, key and info values must be set before a key is derived or an error occurs.

- -
-
- -

EVP_PKEY_CTX_set_hkdf_md() sets the message digest associated with the HKDF.

- -

EVP_PKEY_CTX_set1_hkdf_salt() sets the salt to saltlen bytes of the buffer salt. Any existing value is replaced.

- -

EVP_PKEY_CTX_set1_hkdf_key() sets the key to keylen bytes of the buffer key. Any existing value is replaced.

- -

EVP_PKEY_CTX_add1_hkdf_info() sets the info value to infolen bytes of the buffer info. If a value is already set, it is appended to the existing value.

- -

STRING CTRLS

- -

HKDF also supports string based control operations via EVP_PKEY_CTX_ctrl_str(3). The type parameter "md" uses the supplied value as the name of the digest algorithm to use. The type parameter "mode" uses the values "EXTRACT_AND_EXPAND", "EXTRACT_ONLY" and "EXPAND_ONLY" to determine the mode to use. The type parameters "salt", "key" and "info" use the supplied value parameter as a seed, key or info value. The names "hexsalt", "hexkey" and "hexinfo" are similar except they take a hex string which is converted to binary.

- -

NOTES

- -

A context for HKDF can be obtained by calling:

- -
EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL);
- -

The total length of the info buffer cannot exceed 2048 bytes in length: this should be more than enough for any normal use of HKDF.

- -

The output length of an HKDF expand operation is specified via the length parameter to the EVP_PKEY_derive(3) function. Since the HKDF output length is variable, passing a NULL buffer as a means to obtain the requisite length is not meaningful with HKDF in any mode that performs an expand operation. Instead, the caller must allocate a buffer of the desired length, and pass that buffer to EVP_PKEY_derive(3) along with (a pointer initialized to) the desired length. Passing a NULL buffer to obtain the length is allowed when using EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY.

- -

Optimised versions of HKDF can be implemented in an ENGINE.

- -

RETURN VALUES

- -

All these functions return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

This example derives 10 bytes using SHA-256 with the secret key "secret", salt value "salt" and info value "label":

- -
EVP_PKEY_CTX *pctx;
-unsigned char out[10];
-size_t outlen = sizeof(out);
-pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL);
-
-if (EVP_PKEY_derive_init(pctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_hkdf_md(pctx, EVP_sha256()) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set1_hkdf_salt(pctx, "salt", 4) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set1_hkdf_key(pctx, "secret", 6) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_add1_hkdf_info(pctx, "label", 5) <= 0)
-    /* Error */
-if (EVP_PKEY_derive(pctx, out, &outlen) <= 0)
-    /* Error */
- -

CONFORMING TO

- -

RFC 5869

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_ctrl_str(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

All of the functions described here were converted from macros to functions in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_params.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_params.html deleted file mode 100644 index be2e23d3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_params.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -EVP_PKEY_CTX_set_params - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_set_params, EVP_PKEY_CTX_settable_params, EVP_PKEY_CTX_get_params, EVP_PKEY_CTX_gettable_params - provider parameter passing operations

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_CTX_set_params(EVP_PKEY_CTX *ctx, const OSSL_PARAM *params);
-const OSSL_PARAM *EVP_PKEY_CTX_settable_params(const EVP_PKEY_CTX *ctx);
-int EVP_PKEY_CTX_get_params(EVP_PKEY_CTX *ctx, OSSL_PARAM *params);
-const OSSL_PARAM *EVP_PKEY_CTX_gettable_params(const EVP_PKEY_CTX *ctx);
- -

DESCRIPTION

- -

The EVP_PKEY_CTX_get_params() and EVP_PKEY_CTX_set_params() functions allow transfer of arbitrary key parameters to and from providers. Not all parameters may be supported by all providers. See OSSL_PROVIDER(3) for more information on providers. The params field is a pointer to a list of OSSL_PARAM structures, terminated with a OSSL_PARAM_END(3) struct. See OSSL_PARAM(3) for information about passing parameters. These functions must only be called after the EVP_PKEY_CTX has been initialised for use in an operation. These methods replace the EVP_PKEY_CTX_ctrl() mechanism. (EVP_PKEY_CTX_ctrl now calls these methods internally to interact with providers).

- -

EVP_PKEY_CTX_gettable_params() and EVP_PKEY_CTX_settable_params() get a constant OSSL_PARAM(3) array that describes the gettable and settable parameters for the current algorithm implementation, i.e. parameters that can be used with EVP_PKEY_CTX_get_params() and EVP_PKEY_CTX_set_params() respectively. These functions must only be called after the EVP_PKEY_CTX has been initialised for use in an operation.

- -

Parameters

- -

Examples of EVP_PKEY parameters include the following:

- -

"Common parameters" in provider-keymgmt(7) "Key Exchange parameters" in provider-keyexch(7) "Signature parameters" in provider-signature(7)

- -

"Common RSA parameters" in EVP_PKEY-RSA(7) "RSA key generation parameters" in EVP_PKEY-RSA(7) "FFC parameters" in EVP_PKEY-FFC(7) "FFC key generation parameters" in EVP_PKEY-FFC(7) "DSA parameters" in EVP_PKEY-DSA(7) "DSA key generation parameters" in EVP_PKEY-DSA(7) "DH parameters" in EVP_PKEY-DH(7) "DH key generation parameters" in EVP_PKEY-DH(7) "Common EC parameters" in EVP_PKEY-EC(7) "Common X25519, X448, ED25519 and ED448 parameters" in EVP_PKEY-X25519(7)

- -

RETURN VALUES

- -

EVP_PKEY_CTX_set_params() returns 1 for success or 0 otherwise. EVP_PKEY_CTX_settable_params() returns an OSSL_PARAM array on success or NULL on error. It may also return NULL if there are no settable parameters available.

- -

All other functions and macros described on this page return a positive value for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3), EVP_PKEY_keygen(3)

- -

HISTORY

- -

All functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.html deleted file mode 100644 index 1480f98e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.html +++ /dev/null @@ -1,98 +0,0 @@ - - - - -EVP_PKEY_CTX_set_rsa_pss_keygen_md - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_set_rsa_pss_keygen_md, EVP_PKEY_CTX_set_rsa_pss_keygen_md_name, EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md, EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name, EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen - EVP_PKEY RSA-PSS algorithm support functions

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
-
-int EVP_PKEY_CTX_set_rsa_pss_keygen_md(EVP_PKEY_CTX *pctx,
-                                       const EVP_MD *md);
-int EVP_PKEY_CTX_set_rsa_pss_keygen_md_name(EVP_PKEY_CTX *ctx,
-                                            const char *mdname,
-                                            const char *mdprops);
-int EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md(EVP_PKEY_CTX *pctx,
-                                            const EVP_MD *md);
-int EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name(EVP_PKEY_CTX *pctx,
-                                                 const char *mdname);
-int EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen(EVP_PKEY_CTX *pctx,
-                                            int saltlen);
- -

DESCRIPTION

- -

These are the functions that implement RSA-PSS(7).

- -

Signing and Verification

- -

The macro EVP_PKEY_CTX_set_rsa_padding() is supported but an error is returned if an attempt is made to set the padding mode to anything other than PSS. It is otherwise similar to the RSA version.

- -

The EVP_PKEY_CTX_set_rsa_pss_saltlen() macro is used to set the salt length. If the key has usage restrictions then an error is returned if an attempt is made to set the salt length below the minimum value. It is otherwise similar to the RSA operation except detection of the salt length (using RSA_PSS_SALTLEN_AUTO) is not supported for verification if the key has usage restrictions.

- -

The EVP_PKEY_CTX_set_signature_md(3) and EVP_PKEY_CTX_set_rsa_mgf1_md(3) functions are used to set the digest and MGF1 algorithms respectively. If the key has usage restrictions then an error is returned if an attempt is made to set the digest to anything other than the restricted value. Otherwise these are similar to the RSA versions.

- -

Key Generation

- -

As with RSA key generation the EVP_PKEY_CTX_set_rsa_keygen_bits() and EVP_PKEY_CTX_set_rsa_keygen_pubexp() macros are supported for RSA-PSS: they have exactly the same meaning as for the RSA algorithm.

- -

Optional parameter restrictions can be specified when generating a PSS key. If any restrictions are set (using the macros described below) then all parameters are restricted. For example, setting a minimum salt length also restricts the digest and MGF1 algorithms. If any restrictions are in place then they are reflected in the corresponding parameters of the public key when (for example) a certificate request is signed.

- -

EVP_PKEY_CTX_set_rsa_pss_keygen_md() restricts the digest algorithm the generated key can use to md. EVP_PKEY_CTX_set_rsa_pss_keygen_md_name() does the same thing, but passes the algorithm by name rather than by EVP_MD.

- -

EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md() restricts the MGF1 algorithm the generated key can use to md. EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name() does the same thing, but passes the algorithm by name rather than by EVP_MD.

- -

EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen() restricts the minimum salt length to saltlen.

- -

NOTES

- -

A context for the RSA-PSS algorithm can be obtained by calling:

- -
EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_RSA_PSS, NULL);
- -

RETURN VALUES

- -

All these functions return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

SEE ALSO

- -

RSA-PSS(7), EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_ctrl_str(3), EVP_PKEY_derive(3)

- -

COPYRIGHT

- -

Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_scrypt_N.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_scrypt_N.html deleted file mode 100644 index 208f8e77..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_scrypt_N.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -EVP_PKEY_CTX_set_scrypt_N - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_set1_scrypt_salt, EVP_PKEY_CTX_set_scrypt_N, EVP_PKEY_CTX_set_scrypt_r, EVP_PKEY_CTX_set_scrypt_p, EVP_PKEY_CTX_set_scrypt_maxmem_bytes - EVP_PKEY scrypt KDF support functions

- -

SYNOPSIS

- -
#include <openssl/kdf.h>
-
-int EVP_PKEY_CTX_set1_scrypt_salt(EVP_PKEY_CTX *pctx, unsigned char *salt,
-                                  int saltlen);
-
-int EVP_PKEY_CTX_set_scrypt_N(EVP_PKEY_CTX *pctx, uint64_t N);
-
-int EVP_PKEY_CTX_set_scrypt_r(EVP_PKEY_CTX *pctx, uint64_t r);
-
-int EVP_PKEY_CTX_set_scrypt_p(EVP_PKEY_CTX *pctx, uint64_t p);
-
-int EVP_PKEY_CTX_set_scrypt_maxmem_bytes(EVP_PKEY_CTX *pctx,
-                                         uint64_t maxmem);
- -

DESCRIPTION

- -

These functions are used to set up the necessary data to use the scrypt KDF. For more information on scrypt, see EVP_KDF-SCRYPT(7).

- -

EVP_PKEY_CTX_set1_scrypt_salt() sets the saltlen bytes long salt value.

- -

EVP_PKEY_CTX_set_scrypt_N(), EVP_PKEY_CTX_set_scrypt_r() and EVP_PKEY_CTX_set_scrypt_p() configure the work factors N, r and p.

- -

EVP_PKEY_CTX_set_scrypt_maxmem_bytes() sets how much RAM key derivation may maximally use, given in bytes. If RAM is exceeded because the load factors are chosen too high, the key derivation will fail.

- -

STRING CTRLS

- -

scrypt also supports string based control operations via EVP_PKEY_CTX_ctrl_str(3). Similarly, the salt can either be specified using the type parameter "salt" or in hex encoding by using the "hexsalt" parameter. The work factors N, r and p as well as maxmem_bytes can be set by using the parameters "N", "r", "p" and "maxmem_bytes", respectively.

- -

NOTES

- -

There is a newer generic API for KDFs, EVP_KDF(3), which is preferred over the EVP_PKEY method.

- -

The scrypt KDF also uses EVP_PKEY_CTX_set1_pbe_pass() as well as the value from the string controls "pass" and "hexpass". See EVP_PKEY_CTX_set1_pbe_pass(3).

- -

RETURN VALUES

- -

All these functions return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

SEE ALSO

- -

EVP_KDF(3) EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_ctrl_str(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

All of the functions described here were converted from macros to functions in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_tls1_prf_md.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_tls1_prf_md.html deleted file mode 100644 index cd3a5a15..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_CTX_set_tls1_prf_md.html +++ /dev/null @@ -1,112 +0,0 @@ - - - - -EVP_PKEY_CTX_set_tls1_prf_md - - - - - - - - - - -

NAME

- -

EVP_PKEY_CTX_set_tls1_prf_md, EVP_PKEY_CTX_set1_tls1_prf_secret, EVP_PKEY_CTX_add1_tls1_prf_seed - TLS PRF key derivation algorithm

- -

SYNOPSIS

- -
#include <openssl/kdf.h>
-
-int EVP_PKEY_CTX_set_tls1_prf_md(EVP_PKEY_CTX *pctx, const EVP_MD *md);
-int EVP_PKEY_CTX_set1_tls1_prf_secret(EVP_PKEY_CTX *pctx,
-                                      unsigned char *sec, int seclen);
-int EVP_PKEY_CTX_add1_tls1_prf_seed(EVP_PKEY_CTX *pctx,
-                                    unsigned char *seed, int seedlen);
- -

DESCRIPTION

- -

The EVP_PKEY_TLS1_PRF algorithm implements the PRF key derivation function for TLS. It has no associated private key and only implements key derivation using EVP_PKEY_derive(3).

- -

EVP_PKEY_set_tls1_prf_md() sets the message digest associated with the TLS PRF. EVP_md5_sha1() is treated as a special case which uses the PRF algorithm using both MD5 and SHA1 as used in TLS 1.0 and 1.1.

- -

EVP_PKEY_CTX_set_tls1_prf_secret() sets the secret value of the TLS PRF to seclen bytes of the buffer sec. Any existing secret value is replaced and any seed is reset.

- -

EVP_PKEY_CTX_add1_tls1_prf_seed() sets the seed to seedlen bytes of seed. If a seed is already set it is appended to the existing value.

- -

STRING CTRLS

- -

The TLS PRF also supports string based control operations using EVP_PKEY_CTX_ctrl_str(3). The type parameter "md" uses the supplied value as the name of the digest algorithm to use. The type parameters "secret" and "seed" use the supplied value parameter as a secret or seed value. The names "hexsecret" and "hexseed" are similar except they take a hex string which is converted to binary.

- -

NOTES

- -

A context for the TLS PRF can be obtained by calling:

- -
EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_TLS1_PRF, NULL);
- -

The digest, secret value and seed must be set before a key is derived or an error occurs.

- -

The total length of all seeds cannot exceed 1024 bytes in length: this should be more than enough for any normal use of the TLS PRF.

- -

The output length of the PRF is specified by the length parameter in the EVP_PKEY_derive() function. Since the output length is variable, setting the buffer to NULL is not meaningful for the TLS PRF.

- -

Optimised versions of the TLS PRF can be implemented in an ENGINE.

- -

RETURN VALUES

- -

All these functions return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

This example derives 10 bytes using SHA-256 with the secret key "secret" and seed value "seed":

- -
EVP_PKEY_CTX *pctx;
-unsigned char out[10];
-size_t outlen = sizeof(out);
-
-pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_TLS1_PRF, NULL);
-if (EVP_PKEY_derive_init(pctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_tls1_prf_md(pctx, EVP_sha256()) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set1_tls1_prf_secret(pctx, "secret", 6) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, "seed", 4) <= 0)
-    /* Error */
-if (EVP_PKEY_derive(pctx, out, &outlen) <= 0)
-    /* Error */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_ctrl_str(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

All of the functions described here were converted from macros to functions in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_asn1_get_count.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_asn1_get_count.html deleted file mode 100644 index 7c4538af..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_asn1_get_count.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -EVP_PKEY_asn1_get_count - - - - - - - - - - -

NAME

- -

EVP_PKEY_asn1_find, EVP_PKEY_asn1_find_str, EVP_PKEY_asn1_get_count, EVP_PKEY_asn1_get0, EVP_PKEY_asn1_get0_info - enumerate public key ASN.1 methods

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_asn1_get_count(void);
-const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_get0(int idx);
-const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find(ENGINE **pe, int type);
-const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find_str(ENGINE **pe,
-                                                   const char *str, int len);
-int EVP_PKEY_asn1_get0_info(int *ppkey_id, int *pkey_base_id,
-                            int *ppkey_flags, const char **pinfo,
-                            const char **ppem_str,
-                            const EVP_PKEY_ASN1_METHOD *ameth);
- -

DESCRIPTION

- -

EVP_PKEY_asn1_count() returns a count of the number of public key ASN.1 methods available: it includes standard methods and any methods added by the application.

- -

EVP_PKEY_asn1_get0() returns the public key ASN.1 method idx. The value of idx must be between zero and EVP_PKEY_asn1_get_count() - 1.

- -

EVP_PKEY_asn1_find() looks up the EVP_PKEY_ASN1_METHOD with NID type. If pe isn't NULL, then it will look up an engine implementing a EVP_PKEY_ASN1_METHOD for the NID type and return that instead, and also set *pe to point at the engine that implements it.

- -

EVP_PKEY_asn1_find_str() looks up the EVP_PKEY_ASN1_METHOD with PEM type string str. Just like EVP_PKEY_asn1_find(), if pe isn't NULL, then it will look up an engine implementing a EVP_PKEY_ASN1_METHOD for the NID type and return that instead, and also set *pe to point at the engine that implements it.

- -

EVP_PKEY_asn1_get0_info() returns the public key ID, base public key ID (both NIDs), any flags, the method description and PEM type string associated with the public key ASN.1 method *ameth.

- -

EVP_PKEY_asn1_count(), EVP_PKEY_asn1_get0(), EVP_PKEY_asn1_find() and EVP_PKEY_asn1_find_str() are not thread safe, but as long as all EVP_PKEY_ASN1_METHOD objects are added before the application gets threaded, using them is safe. See EVP_PKEY_asn1_add0(3).

- -

RETURN VALUES

- -

EVP_PKEY_asn1_count() returns the number of available public key methods.

- -

EVP_PKEY_asn1_get0() return a public key method or NULL if idx is out of range.

- -

EVP_PKEY_asn1_get0_info() returns 0 on failure, 1 on success.

- -

SEE ALSO

- -

EVP_PKEY_asn1_new(3), EVP_PKEY_asn1_add0(3)

- -

COPYRIGHT

- -

Copyright 2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_check.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_check.html deleted file mode 100644 index c31f264d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_check.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -EVP_PKEY_check - - - - - - - - - - -

NAME

- -

EVP_PKEY_check, EVP_PKEY_param_check, EVP_PKEY_param_check_quick, EVP_PKEY_public_check, EVP_PKEY_public_check_quick, EVP_PKEY_private_check, EVP_PKEY_pairwise_check - key and parameter validation functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_check(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_param_check(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_param_check_quick(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_public_check(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_public_check_quick(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_private_check(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_pairwise_check(EVP_PKEY_CTX *ctx);
- -

DESCRIPTION

- -

EVP_PKEY_param_check() validates the parameters component of the key given by ctx. This check will always succeed for key types that do not have parameters.

- -

EVP_PKEY_param_check_quick() validates the parameters component of the key given by ctx like EVP_PKEY_param_check() does. However some algorithm implementations may offer a quicker form of validation that omits some checks in order to perform a lightweight sanity check of the key. If a quicker form is not provided then this function call does the same thing as EVP_PKEY_param_check().

- -

EVP_PKEY_public_check() validates the public component of the key given by ctx.

- -

EVP_PKEY_public_check_quick() validates the public component of the key given by ctx like EVP_PKEY_public_check() does. However some algorithm implementations may offer a quicker form of validation that omits some checks in order to perform a lightweight sanity check of the key. If a quicker form is not provided then this function call does the same thing as EVP_PKEY_public_check().

- -

EVP_PKEY_private_check() validates the private component of the key given by ctx.

- -

EVP_PKEY_pairwise_check() validates that the public and private components have the correct mathematical relationship to each other for the key given by ctx.

- -

EVP_PKEY_check() is an alias for the EVP_PKEY_pairwise_check() function.

- -

NOTES

- -

Key validation used by the OpenSSL FIPS provider complies with the rules within SP800-56A and SP800-56B. For backwards compatibility reasons the OpenSSL default provider may use checks that are not as restrictive for certain key types. For further information see "DSA key validation" in EVP_PKEY-DSA(7), "DH key validation" in EVP_PKEY-DH(7), "EC key validation" in EVP_PKEY-EC(7) and "RSA key validation" in EVP_PKEY-RSA(7).

- -

Refer to SP800-56A and SP800-56B for rules relating to when these functions should be called during key establishment. It is not necessary to call these functions after locally calling an approved key generation method, but may be required for assurance purposes when receiving keys from a third party.

- -

The EVP_PKEY_pairwise_check() and EVP_PKEY_private_check() might not be bounded by any key size limits as private keys are not expected to be supplied by attackers. For that reason they might take an unbounded time if run on arbitrarily large keys.

- -

RETURN VALUES

- -

All functions return 1 for success or others for failure. They return -2 if the operation is not supported for the specific algorithm.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_fromdata(3), EVP_PKEY-DH(7), EVP_PKEY-FFC(7), EVP_PKEY-DSA(7), EVP_PKEY-EC(7), EVP_PKEY-RSA(7),

- -

HISTORY

- -

EVP_PKEY_check(), EVP_PKEY_public_check() and EVP_PKEY_param_check() were added in OpenSSL 1.1.1.

- -

EVP_PKEY_param_check_quick(), EVP_PKEY_public_check_quick(), EVP_PKEY_private_check() and EVP_PKEY_pairwise_check() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_copy_parameters.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_copy_parameters.html deleted file mode 100644 index 0d8f296d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_copy_parameters.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -EVP_PKEY_copy_parameters - - - - - - - - - - -

NAME

- -

EVP_PKEY_missing_parameters, EVP_PKEY_copy_parameters, EVP_PKEY_parameters_eq, EVP_PKEY_cmp_parameters, EVP_PKEY_eq, EVP_PKEY_cmp - public key parameter and comparison functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_missing_parameters(const EVP_PKEY *pkey);
-int EVP_PKEY_copy_parameters(EVP_PKEY *to, const EVP_PKEY *from);
-
-int EVP_PKEY_parameters_eq(const EVP_PKEY *a, const EVP_PKEY *b);
-int EVP_PKEY_eq(const EVP_PKEY *a, const EVP_PKEY *b);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int EVP_PKEY_cmp_parameters(const EVP_PKEY *a, const EVP_PKEY *b);
-int EVP_PKEY_cmp(const EVP_PKEY *a, const EVP_PKEY *b);
- -

DESCRIPTION

- -

The function EVP_PKEY_missing_parameters() returns 1 if the public key parameters of pkey are missing and 0 if they are present or the algorithm doesn't use parameters.

- -

The function EVP_PKEY_copy_parameters() copies the parameters from key from to key to. An error is returned if the parameters are missing in from or present in both from and to and mismatch. If the parameters in from and to are both present and match this function has no effect.

- -

The function EVP_PKEY_parameters_eq() checks the parameters of keys a and b for equality.

- -

The function EVP_PKEY_eq() checks the keys a and b for equality, including their parameters if they are available.

- -

NOTES

- -

The main purpose of the functions EVP_PKEY_missing_parameters() and EVP_PKEY_copy_parameters() is to handle public keys in certificates where the parameters are sometimes omitted from a public key if they are inherited from the CA that signed it.

- -

The deprecated functions EVP_PKEY_cmp() and EVP_PKEY_cmp_parameters() differ in their return values compared to other _cmp() functions. They are aliases for EVP_PKEY_eq() and EVP_PKEY_parameters_eq().

- -

The function EVP_PKEY_cmp() previously only checked the key parameters (if there are any) and the public key, assuming that there always was a public key and that private key equality could be derived from that. Because it's no longer assumed that the private key in an EVP_PKEY(3) is always accompanied by a public key, the comparison can not rely on public key comparison alone.

- -

Instead, EVP_PKEY_eq() (and therefore also EVP_PKEY_cmp()) now compares:

- -
    - -
  1. the key parameters (if there are any)

    - -
  2. -
  3. the public keys or the private keys of the two EVP_PKEYs, depending on what they both contain.

    - -
  4. -
- -

RETURN VALUES

- -

The function EVP_PKEY_missing_parameters() returns 1 if the public key parameters of pkey are missing and 0 if they are present or the algorithm doesn't use parameters.

- -

These functions EVP_PKEY_copy_parameters() returns 1 for success and 0 for failure.

- -

The functions EVP_PKEY_cmp_parameters(), EVP_PKEY_parameters_eq(), EVP_PKEY_cmp() and EVP_PKEY_eq() return 1 if their inputs match, 0 if they don't match, -1 if the key types are different and -2 if the operation is not supported.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_keygen(3)

- -

HISTORY

- -

The EVP_PKEY_cmp() and EVP_PKEY_cmp_parameters() functions were deprecated in OpenSSL 3.0.

- -

The EVP_PKEY_eq() and EVP_PKEY_parameters_eq() were added in OpenSSL 3.0 to replace EVP_PKEY_cmp() and EVP_PKEY_cmp_parameters().

- -

COPYRIGHT

- -

Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decapsulate.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decapsulate.html deleted file mode 100644 index a4feadc2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decapsulate.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -EVP_PKEY_decapsulate - - - - - - - - - - -

NAME

- -

EVP_PKEY_decapsulate_init, EVP_PKEY_auth_decapsulate_init, EVP_PKEY_decapsulate - Key decapsulation using a KEM algorithm with a private key

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_decapsulate_init(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_PKEY_auth_decapsulate_init(EVP_PKEY_CTX *ctx, EVP_PKEY *authpub,
-                                  const OSSL_PARAM params[]);
-int EVP_PKEY_decapsulate(EVP_PKEY_CTX *ctx,
-                         unsigned char *unwrapped, size_t *unwrappedlen,
-                         const unsigned char *wrapped, size_t wrappedlen);
- -

DESCRIPTION

- -

The EVP_PKEY_decapsulate_init() function initializes a private key algorithm context ctx for a decapsulation operation and then sets the params on the context in the same way as calling EVP_PKEY_CTX_set_params(3). Note that ctx usually is produced using EVP_PKEY_CTX_new_from_pkey(3), specifying the private key to use.

- -

The EVP_PKEY_auth_decapsulate_init() function is similar to EVP_PKEY_decapsulate_init() but also passes an authpub authentication public key that is used during decapsulation.

- -

The EVP_PKEY_decapsulate() function performs a private key decapsulation operation using ctx. The data to be decapsulated is specified using the wrapped and wrappedlen parameters. If unwrapped is NULL then the size of the output secret buffer is written to *unwrappedlen. If unwrapped is not NULL and the call is successful then the decapsulated secret data is written to unwrapped and the amount of data written to *unwrappedlen. Note that, if unwrappedlen is not NULL in this call, the value it points to must be initialised to the length of unwrapped, so that the call can validate it is of sufficient size to hold the result of the operation.

- -

NOTES

- -

After the call to EVP_PKEY_decapsulate_init() algorithm-specific parameters for the operation may be set or modified using EVP_PKEY_CTX_set_params(3).

- -

RETURN VALUES

- -

EVP_PKEY_decapsulate_init(), EVP_PKEY_auth_decapsulate_init() and EVP_PKEY_decapsulate() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the private key algorithm.

- -

EXAMPLES

- -

Decapsulate data using RSA:

- -
#include <openssl/evp.h>
-
-/*
- * NB: assumes rsa_priv_key is an RSA private key,
- * and that in, inlen are already set up to contain encapsulated data.
- */
-
-EVP_PKEY_CTX *ctx = NULL;
-size_t secretlen = 0;
-unsigned char *secret = NULL;;
-
-ctx = EVP_PKEY_CTX_new_from_pkey(libctx, rsa_priv_key, NULL);
-if (ctx == NULL)
-    /* Error */
-if (EVP_PKEY_decapsulate_init(ctx, NULL) <= 0)
-    /* Error */
-
-/* Set the mode - only 'RSASVE' is currently supported */
-if (EVP_PKEY_CTX_set_kem_op(ctx, "RSASVE") <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_decapsulate(ctx, NULL, &secretlen, in, inlen) <= 0)
-    /* Error */
-
-secret = OPENSSL_malloc(secretlen);
-if (secret == NULL)
-    /* malloc failure */
-
-/* Decapsulated secret data is secretlen bytes long */
-if (EVP_PKEY_decapsulate(ctx, secret, &secretlen, in, inlen) <= 0)
-    /* Error */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new_from_pkey(3), EVP_PKEY_encapsulate(3), EVP_KEM-RSA(7), EVP_KEM-X25519(7), EVP_KEM-EC(7)

- -

HISTORY

- -

The functions EVP_PKEY_decapsulate_init() and EVP_PKEY_decapsulate() were added in OpenSSL 3.0.

- -

The function EVP_PKEY_auth_decapsulate_init() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decrypt.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decrypt.html deleted file mode 100644 index 242e4821..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_decrypt.html +++ /dev/null @@ -1,125 +0,0 @@ - - - - -EVP_PKEY_decrypt - - - - - - - - - - -

NAME

- -

EVP_PKEY_decrypt_init, EVP_PKEY_decrypt_init_ex, EVP_PKEY_decrypt - decrypt using a public key algorithm

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_decrypt_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_decrypt_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_PKEY_decrypt(EVP_PKEY_CTX *ctx,
-                     unsigned char *out, size_t *outlen,
-                     const unsigned char *in, size_t inlen);
- -

DESCRIPTION

- -

The EVP_PKEY_decrypt_init() function initializes a public key algorithm context using key pkey for a decryption operation.

- -

The EVP_PKEY_decrypt_init_ex() function initializes a public key algorithm context using key pkey for a decryption operation and sets the algorithm specific params.

- -

The EVP_PKEY_decrypt() function performs a public key decryption operation using ctx. The data to be decrypted is specified using the in and inlen parameters. If out is NULL then the minimum required size of the output buffer is written to the *outlen parameter.

- -

If out is not NULL then before the call the *outlen parameter must contain the length of the out buffer. If the call is successful the decrypted data is written to out and the amount of the decrypted data written to *outlen, otherwise an error is returned.

- -

NOTES

- -

After the call to EVP_PKEY_decrypt_init() algorithm specific control operations can be performed to set any appropriate parameters for the operation. These operations can be included in the EVP_PKEY_decrypt_init_ex() call.

- -

The function EVP_PKEY_decrypt() can be called more than once on the same context if several operations are performed using the same parameters.

- -

RETURN VALUES

- -

EVP_PKEY_decrypt_init(), EVP_PKEY_decrypt_init_ex() and EVP_PKEY_decrypt() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

WARNINGS

- -

In OpenSSL versions before 3.2.0, when used in PKCS#1 v1.5 padding, both the return value from the EVP_PKEY_decrypt() and the outlen provided information useful in mounting a Bleichenbacher attack against the used private key. They had to be processed in a side-channel free way.

- -

Since version 3.2.0, the EVP_PKEY_decrypt() method when used with PKCS#1 v1.5 padding as implemented in the default provider implements the implicit rejection mechanism (see OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION in provider-asym_cipher(7)). That means it doesn't return an error when it detects an error in padding, instead it returns a pseudo-randomly generated message, removing the need of side-channel secure code from applications using OpenSSL. If OpenSSL is configured to use a provider that doesn't implement implicit rejection, the code still needs to handle the returned values using side-channel free code. Side-channel free handling of the error stack can be performed using either a pair of unconditional ERR_set_mark(3) and ERR_pop_to_mark(3) calls or by using the ERR_clear_error(3) call.

- -

EXAMPLES

- -

Decrypt data using OAEP (for RSA keys):

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-ENGINE *eng;
-unsigned char *out, *in;
-size_t outlen, inlen;
-EVP_PKEY *key;
-
-/*
- * NB: assumes key, eng, in, inlen are already set up
- * and that key is an RSA private key
- */
-ctx = EVP_PKEY_CTX_new(key, eng);
-if (!ctx)
-    /* Error occurred */
-if (EVP_PKEY_decrypt_init(ctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_OAEP_PADDING) <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_decrypt(ctx, NULL, &outlen, in, inlen) <= 0)
-    /* Error */
-
-out = OPENSSL_malloc(outlen);
-
-if (!out)
-    /* malloc failure */
-
-if (EVP_PKEY_decrypt(ctx, out, &outlen, in, inlen) <= 0)
-    /* Error */
-
-/* Decrypted data is outlen bytes written to buffer out */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_encrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_derive.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_derive.html deleted file mode 100644 index d3acbef8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_derive.html +++ /dev/null @@ -1,120 +0,0 @@ - - - - -EVP_PKEY_derive - - - - - - - - - - -

NAME

- -

EVP_PKEY_derive_init, EVP_PKEY_derive_init_ex, EVP_PKEY_derive_set_peer_ex, EVP_PKEY_derive_set_peer, EVP_PKEY_derive - derive public key algorithm shared secret

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_derive_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_derive_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_PKEY_derive_set_peer_ex(EVP_PKEY_CTX *ctx, EVP_PKEY *peer,
-                                int validate_peer);
-int EVP_PKEY_derive_set_peer(EVP_PKEY_CTX *ctx, EVP_PKEY *peer);
-int EVP_PKEY_derive(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen);
- -

DESCRIPTION

- -

EVP_PKEY_derive_init() initializes a public key algorithm context ctx for shared secret derivation using the algorithm given when the context was created using EVP_PKEY_CTX_new(3) or variants thereof. The algorithm is used to fetch a EVP_KEYEXCH method implicitly, see "Implicit fetch" in provider(7) for more information about implicit fetches.

- -

EVP_PKEY_derive_init_ex() is the same as EVP_PKEY_derive_init() but additionally sets the passed parameters params on the context before returning.

- -

EVP_PKEY_derive_set_peer_ex() sets the peer key: this will normally be a public key. The validate_peer will validate the public key if this value is non zero.

- -

EVP_PKEY_derive_set_peer() is similar to EVP_PKEY_derive_set_peer_ex() with validate_peer set to 1.

- -

EVP_PKEY_derive() derives a shared secret using ctx. If key is NULL then the maximum size of the output buffer is written to the keylen parameter. If key is not NULL then before the call the keylen parameter should contain the length of the key buffer, if the call is successful the shared secret is written to key and the amount of data written to keylen.

- -

NOTES

- -

After the call to EVP_PKEY_derive_init(), algorithm specific control operations can be performed to set any appropriate parameters for the operation.

- -

The function EVP_PKEY_derive() can be called more than once on the same context if several operations are performed using the same parameters.

- -

RETURN VALUES

- -

EVP_PKEY_derive_init() and EVP_PKEY_derive() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

Derive shared secret (for example DH or EC keys):

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-ENGINE *eng;
-unsigned char *skey;
-size_t skeylen;
-EVP_PKEY *pkey, *peerkey;
-/* NB: assumes pkey, eng, peerkey have been already set up */
-
-ctx = EVP_PKEY_CTX_new(pkey, eng);
-if (!ctx)
-    /* Error occurred */
-if (EVP_PKEY_derive_init(ctx) <= 0)
-    /* Error */
-if (EVP_PKEY_derive_set_peer(ctx, peerkey) <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_derive(ctx, NULL, &skeylen) <= 0)
-    /* Error */
-
-skey = OPENSSL_malloc(skeylen);
-
-if (!skey)
-    /* malloc failure */
-
-if (EVP_PKEY_derive(ctx, skey, &skeylen) <= 0)
-    /* Error */
-
-/* Shared secret is skey bytes written to buffer skey */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_KEYEXCH_fetch(3)

- -

HISTORY

- -

The EVP_PKEY_derive_init(), EVP_PKEY_derive_set_peer() and EVP_PKEY_derive() functions were originally added in OpenSSL 1.0.0.

- -

The EVP_PKEY_derive_init_ex() and EVP_PKEY_derive_set_peer_ex() functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_digestsign_supports_digest.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_digestsign_supports_digest.html deleted file mode 100644 index 99a6bee3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_digestsign_supports_digest.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -EVP_PKEY_digestsign_supports_digest - - - - - - - - - - -

NAME

- -

EVP_PKEY_digestsign_supports_digest - indicate support for signature digest

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-int EVP_PKEY_digestsign_supports_digest(EVP_PKEY *pkey, OSSL_LIB_CTX *libctx,
-                                        const char *name, const char *propq);
- -

DESCRIPTION

- -

The EVP_PKEY_digestsign_supports_digest() function queries whether the message digest name is supported for public key signature operations associated with key pkey. The query is done within an optional library context libctx and with an optional property query propq.

- -

RETURN VALUES

- -

The EVP_PKEY_digestsign_supports_digest() function returns 1 if the message digest algorithm identified by name can be used for public key signature operations associated with key pkey and 0 if it cannot be used. It returns a negative value for failure.

- -

SEE ALSO

- -

EVP_DigestSignInit_ex(3),

- -

HISTORY

- -

The EVP_PKEY_digestsign_supports_digest() function was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encapsulate.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encapsulate.html deleted file mode 100644 index ecb9e909..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encapsulate.html +++ /dev/null @@ -1,116 +0,0 @@ - - - - -EVP_PKEY_encapsulate - - - - - - - - - - -

NAME

- -

EVP_PKEY_encapsulate_init, EVP_PKEY_auth_encapsulate_init, EVP_PKEY_encapsulate - Key encapsulation using a KEM algorithm with a public key

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_encapsulate_init(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_PKEY_auth_encapsulate_init(EVP_PKEY_CTX *ctx, EVP_PKEY *authpriv,
-                                  const OSSL_PARAM params[]);
-int EVP_PKEY_encapsulate(EVP_PKEY_CTX *ctx,
-                         unsigned char *wrappedkey, size_t *wrappedkeylen,
-                         unsigned char *genkey, size_t *genkeylen);
- -

DESCRIPTION

- -

The EVP_PKEY_encapsulate_init() function initializes a public key algorithm context ctx for an encapsulation operation and then sets the params on the context in the same way as calling EVP_PKEY_CTX_set_params(3). Note that ctx is usually is produced using EVP_PKEY_CTX_new_from_pkey(3), specifying the public key to use.

- -

The EVP_PKEY_auth_encapsulate_init() function is similar to EVP_PKEY_encapsulate_init() but also passes an authpriv authentication private key that is used during encapsulation.

- -

The EVP_PKEY_encapsulate() function performs a public key encapsulation operation using ctx. The symmetric secret generated in genkey can be used as key material. The ciphertext in wrappedkey is its encapsulated form, which can be sent to another party, who can use EVP_PKEY_decapsulate(3) to retrieve it using their private key. If wrappedkey is NULL then the maximum size of the output buffer is written to the *wrappedkeylen parameter unless wrappedkeylen is NULL and the maximum size of the generated key buffer is written to *genkeylen unless genkeylen is NULL. If wrappedkey is not NULL and the call is successful then the internally generated key is written to genkey and its size is written to *genkeylen. The encapsulated version of the generated key is written to wrappedkey and its size is written to *wrappedkeylen. Note that if wrappedlen is not NULL, then the value it points to must initially hold the size of the unwrapped buffer so that its size can be validated by the call, ensuring it is large enough to hold the result written to wrapped.

- -

NOTES

- -

After the call to EVP_PKEY_encapsulate_init() algorithm-specific parameters for the operation may be set or modified using EVP_PKEY_CTX_set_params(3).

- -

RETURN VALUES

- -

EVP_PKEY_encapsulate_init(), EVP_PKEY_auth_encapsulate_init() and EVP_PKEY_encapsulate() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

Encapsulate an RSASVE key (for RSA keys).

- -
#include <openssl/evp.h>
-
-/*
- * NB: assumes rsa_pub_key is an public key of another party.
- */
-
-EVP_PKEY_CTX *ctx = NULL;
-size_t secretlen = 0, outlen = 0;
-unsigned char *out = NULL, *secret = NULL;
-
-ctx = EVP_PKEY_CTX_new_from_pkey(libctx, rsa_pub_key, NULL);
-if (ctx == NULL)
-    /* Error */
-if (EVP_PKEY_encapsulate_init(ctx, NULL) <= 0)
-    /* Error */
-
-/* Set the mode - only 'RSASVE' is currently supported */
- if (EVP_PKEY_CTX_set_kem_op(ctx, "RSASVE") <= 0)
-    /* Error */
-/* Determine buffer length */
-if (EVP_PKEY_encapsulate(ctx, NULL, &outlen, NULL, &secretlen) <= 0)
-    /* Error */
-
-out = OPENSSL_malloc(outlen);
-secret = OPENSSL_malloc(secretlen);
-if (out == NULL || secret == NULL)
-    /* malloc failure */
-
-/*
- * The generated 'secret' can be used as key material.
- * The encapsulated 'out' can be sent to another party who can
- * decapsulate it using their private key to retrieve the 'secret'.
- */
-if (EVP_PKEY_encapsulate(ctx, out, &outlen, secret, &secretlen) <= 0)
-    /* Error */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new_from_pkey(3), EVP_PKEY_decapsulate(3), EVP_KEM-RSA(7), EVP_KEM-X25519(7), EVP_KEM-EC(7)

- -

HISTORY

- -

These functions EVP_PKEY_encapsulate_init() and EVP_PKEY_encapsulate() were added in OpenSSL 3.0. The function EVP_PKEY_auth_encapsulate_init() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encrypt.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encrypt.html deleted file mode 100644 index 216a708b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_encrypt.html +++ /dev/null @@ -1,117 +0,0 @@ - - - - -EVP_PKEY_encrypt - - - - - - - - - - -

NAME

- -

EVP_PKEY_encrypt_init_ex, EVP_PKEY_encrypt_init, EVP_PKEY_encrypt - encrypt using a public key algorithm

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_encrypt_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_encrypt_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_PKEY_encrypt(EVP_PKEY_CTX *ctx,
-                     unsigned char *out, size_t *outlen,
-                     const unsigned char *in, size_t inlen);
- -

DESCRIPTION

- -

The EVP_PKEY_encrypt_init() function initializes a public key algorithm context using key pkey for an encryption operation.

- -

The EVP_PKEY_encrypt_init_ex() function initializes a public key algorithm context using key pkey for an encryption operation and sets the algorithm specific params.

- -

The EVP_PKEY_encrypt() function performs a public key encryption operation using ctx. The data to be encrypted is specified using the in and inlen parameters. If out is NULL then the maximum size of the output buffer is written to the outlen parameter. If out is not NULL then before the call the outlen parameter should contain the length of the out buffer, if the call is successful the encrypted data is written to out and the amount of data written to outlen.

- -

NOTES

- -

After the call to EVP_PKEY_encrypt_init() algorithm specific control operations can be performed to set any appropriate parameters for the operation. These operations can be included in the EVP_PKEY_encrypt_init_ex() call.

- -

The function EVP_PKEY_encrypt() can be called more than once on the same context if several operations are performed using the same parameters.

- -

RETURN VALUES

- -

EVP_PKEY_encrypt_init(), EVP_PKEY_encrypt_init_ex() and EVP_PKEY_encrypt() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

Encrypt data using OAEP (for RSA keys). See also PEM_read_PUBKEY(3) or d2i_X509(3) for means to load a public key. You may also simply set 'eng = NULL;' to start with the default OpenSSL RSA implementation:

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-#include <openssl/engine.h>
-
-EVP_PKEY_CTX *ctx;
-ENGINE *eng;
-unsigned char *out, *in;
-size_t outlen, inlen;
-EVP_PKEY *key;
-
-/*
- * NB: assumes eng, key, in, inlen are already set up,
- * and that key is an RSA public key
- */
-ctx = EVP_PKEY_CTX_new(key, eng);
-if (!ctx)
-    /* Error occurred */
-if (EVP_PKEY_encrypt_init(ctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_OAEP_PADDING) <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_encrypt(ctx, NULL, &outlen, in, inlen) <= 0)
-    /* Error */
-
-out = OPENSSL_malloc(outlen);
-
-if (!out)
-    /* malloc failure */
-
-if (EVP_PKEY_encrypt(ctx, out, &outlen, in, inlen) <= 0)
-    /* Error */
-
-/* Encrypted data is outlen bytes written to buffer out */
- -

SEE ALSO

- -

d2i_X509(3), ENGINE_by_id(3), EVP_PKEY_CTX_new(3), EVP_PKEY_decrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_fromdata.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_fromdata.html deleted file mode 100644 index 8875bc9e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_fromdata.html +++ /dev/null @@ -1,272 +0,0 @@ - - - - -EVP_PKEY_fromdata - - - - - - - - - - -

NAME

- -

EVP_PKEY_fromdata_init, EVP_PKEY_fromdata, EVP_PKEY_fromdata_settable - functions to create keys and key parameters from user data

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_fromdata_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_fromdata(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey, int selection,
-                      OSSL_PARAM params[]);
-const OSSL_PARAM *EVP_PKEY_fromdata_settable(EVP_PKEY_CTX *ctx, int selection);
- -

DESCRIPTION

- -

The functions described here are used to create new keys from user provided key data, such as n, e and d for a minimal RSA keypair.

- -

These functions use an EVP_PKEY_CTX context, which should primarily be created with EVP_PKEY_CTX_new_from_name(3) or EVP_PKEY_CTX_new_id(3).

- -

The exact key data that the user can pass depends on the key type. These are passed as an OSSL_PARAM(3) array.

- -

EVP_PKEY_fromdata_init() initializes a public key algorithm context for creating a key or key parameters from user data.

- -

EVP_PKEY_fromdata() creates the structure to store a key or key parameters, given data from params, selection and a context that's been initialized with EVP_PKEY_fromdata_init(). The result is written to *ppkey. selection is described in "Selections". The parameters that can be used for various types of key are as described by the diverse "Common parameters" sections of the EVP_PKEY-RSA(7), EVP_PKEY-DSA(7), EVP_PKEY-DH(7), EVP_PKEY-EC(7), EVP_PKEY-ED448(7), EVP_PKEY-X25519(7), EVP_PKEY-X448(7), and EVP_PKEY-ED25519(7) pages.

- -

EVP_PKEY_fromdata_settable() gets a constant OSSL_PARAM(3) array that describes the settable parameters that can be used with EVP_PKEY_fromdata(). selection is described in "Selections".

- -

Parameters in the params array that are not among the settable parameters for the given selection are ignored.

- -

Selections

- -

The following constants can be used for selection:

- -
- -
EVP_PKEY_KEY_PARAMETERS
-
- -

Only key parameters will be selected.

- -
-
EVP_PKEY_PUBLIC_KEY
-
- -

Only public key components will be selected. This includes optional key parameters.

- -
-
EVP_PKEY_KEYPAIR
-
- -

Any keypair components will be selected. This includes the private key, public key and key parameters.

- -
-
- -

NOTES

- -

These functions only work with key management methods coming from a provider. This is the mirror function to EVP_PKEY_todata(3).

- -

RETURN VALUES

- -

EVP_PKEY_fromdata_init() and EVP_PKEY_fromdata() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

These examples are very terse for the sake of staying on topic, which is the EVP_PKEY_fromdata() set of functions. In real applications, BIGNUMs would be handled and converted to byte arrays with BN_bn2nativepad(), but that's off topic here.

- -

Creating an RSA keypair using raw key data

- -
#include <openssl/evp.h>
-
-/*
- * These are extremely small to make this example simple.  A real
- * and secure application will not use such small numbers.  A real
- * and secure application is expected to use BIGNUMs, and to build
- * this array dynamically.
- */
-unsigned long rsa_n = 0xbc747fc5;
-unsigned long rsa_e = 0x10001;
-unsigned long rsa_d = 0x7b133399;
-OSSL_PARAM params[] = {
-    OSSL_PARAM_ulong("n", &rsa_n),
-    OSSL_PARAM_ulong("e", &rsa_e),
-    OSSL_PARAM_ulong("d", &rsa_d),
-    OSSL_PARAM_END
-};
-
-int main()
-{
-    EVP_PKEY_CTX *ctx = EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL);
-    EVP_PKEY *pkey = NULL;
-
-    if (ctx == NULL
-        || EVP_PKEY_fromdata_init(ctx) <= 0
-        || EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEYPAIR, params) <= 0)
-        exit(1);
-
-    /* Do what you want with |pkey| */
-}
- -

Creating an ECC keypair using raw key data

- -
#include <openssl/evp.h>
-#include <openssl/param_build.h>
-#include <openssl/ec.h>
-
-/*
- * Fixed data to represent the private and public key.
- */
-const unsigned char priv_data[] = {
-    0xb9, 0x2f, 0x3c, 0xe6, 0x2f, 0xfb, 0x45, 0x68,
-    0x39, 0x96, 0xf0, 0x2a, 0xaf, 0x6c, 0xda, 0xf2,
-    0x89, 0x8a, 0x27, 0xbf, 0x39, 0x9b, 0x7e, 0x54,
-    0x21, 0xc2, 0xa1, 0xe5, 0x36, 0x12, 0x48, 0x5d
-};
-/* UNCOMPRESSED FORMAT */
-const unsigned char pub_data[] = {
-    POINT_CONVERSION_UNCOMPRESSED,
-    0xcf, 0x20, 0xfb, 0x9a, 0x1d, 0x11, 0x6c, 0x5e,
-    0x9f, 0xec, 0x38, 0x87, 0x6c, 0x1d, 0x2f, 0x58,
-    0x47, 0xab, 0xa3, 0x9b, 0x79, 0x23, 0xe6, 0xeb,
-    0x94, 0x6f, 0x97, 0xdb, 0xa3, 0x7d, 0xbd, 0xe5,
-    0x26, 0xca, 0x07, 0x17, 0x8d, 0x26, 0x75, 0xff,
-    0xcb, 0x8e, 0xb6, 0x84, 0xd0, 0x24, 0x02, 0x25,
-    0x8f, 0xb9, 0x33, 0x6e, 0xcf, 0x12, 0x16, 0x2f,
-    0x5c, 0xcd, 0x86, 0x71, 0xa8, 0xbf, 0x1a, 0x47
-};
-
-int main()
-{
-    EVP_PKEY_CTX *ctx;
-    EVP_PKEY *pkey = NULL;
-    BIGNUM *priv;
-    OSSL_PARAM_BLD *param_bld;
-    OSSL_PARAM *params = NULL;
-    int exitcode = 0;
-
-    priv = BN_bin2bn(priv_data, sizeof(priv_data), NULL);
-
-    param_bld = OSSL_PARAM_BLD_new();
-    if (priv != NULL && param_bld != NULL
-        && OSSL_PARAM_BLD_push_utf8_string(param_bld, "group",
-                                           "prime256v1", 0)
-        && OSSL_PARAM_BLD_push_BN(param_bld, "priv", priv)
-        && OSSL_PARAM_BLD_push_octet_string(param_bld, "pub",
-                                            pub_data, sizeof(pub_data)))
-        params = OSSL_PARAM_BLD_to_param(param_bld);
-
-    ctx = EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL);
-    if (ctx == NULL
-        || params == NULL
-        || EVP_PKEY_fromdata_init(ctx) <= 0
-        || EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEYPAIR, params) <= 0) {
-        exitcode = 1;
-    } else {
-        /* Do what you want with |pkey| */
-    }
-
-    EVP_PKEY_free(pkey);
-    EVP_PKEY_CTX_free(ctx);
-    OSSL_PARAM_free(params);
-    OSSL_PARAM_BLD_free(param_bld);
-    BN_free(priv);
-
-    exit(exitcode);
-}
- -

Finding out params for an unknown key type

- -
#include <openssl/evp.h>
-#include <openssl/core.h>
-
-/* Program expects a key type as first argument */
-int main(int argc, char *argv[])
-{
-    EVP_PKEY_CTX *ctx = EVP_PKEY_CTX_new_from_name(NULL, argv[1], NULL);
-    const OSSL_PARAM *settable_params = NULL;
-
-    if (ctx == NULL)
-       exit(1);
-   settable_params = EVP_PKEY_fromdata_settable(ctx, EVP_PKEY_KEYPAIR);
-   if (settable_params == NULL)
-        exit(1);
-
-    for (; settable_params->key != NULL; settable_params++) {
-        const char *datatype = NULL;
-
-        switch (settable_params->data_type) {
-        case OSSL_PARAM_INTEGER:
-            datatype = "integer";
-            break;
-        case OSSL_PARAM_UNSIGNED_INTEGER:
-            datatype = "unsigned integer";
-            break;
-        case OSSL_PARAM_UTF8_STRING:
-            datatype = "printable string (utf-8 encoding expected)";
-            break;
-        case OSSL_PARAM_UTF8_PTR:
-            datatype = "printable string pointer (utf-8 encoding expected)";
-            break;
-        case OSSL_PARAM_OCTET_STRING:
-            datatype = "octet string";
-            break;
-        case OSSL_PARAM_OCTET_PTR:
-            datatype = "octet string pointer";
-            break;
-        }
-        printf("%s : %s ", settable_params->key, datatype);
-        if (settable_params->data_size == 0)
-            printf("(unlimited size)\n");
-        else
-            printf("(maximum size %zu)\n", settable_params->data_size);
-    }
-}
- -

The descriptor OSSL_PARAM(3) returned by EVP_PKEY_fromdata_settable() may also be used programmatically, for example with OSSL_PARAM_allocate_from_text(3).

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), provider(7), EVP_PKEY_gettable_params(3), OSSL_PARAM(3), EVP_PKEY_todata(3), EVP_PKEY-RSA(7), EVP_PKEY-DSA(7), EVP_PKEY-DH(7), EVP_PKEY-EC(7), EVP_PKEY-ED448(7), EVP_PKEY-X25519(7), EVP_PKEY-X448(7), EVP_PKEY-ED25519(7)

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_attr.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_attr.html deleted file mode 100644 index def5ae5f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_attr.html +++ /dev/null @@ -1,102 +0,0 @@ - - - - -EVP_PKEY_get_attr - - - - - - - - - - -

NAME

- -

EVP_PKEY_get_attr, EVP_PKEY_get_attr_count, EVP_PKEY_get_attr_by_NID, EVP_PKEY_get_attr_by_OBJ, EVP_PKEY_delete_attr, EVP_PKEY_add1_attr, EVP_PKEY_add1_attr_by_OBJ, EVP_PKEY_add1_attr_by_NID, EVP_PKEY_add1_attr_by_txt - EVP_PKEY X509_ATTRIBUTE functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int EVP_PKEY_get_attr_count(const EVP_PKEY *key);
-int EVP_PKEY_get_attr_by_NID(const EVP_PKEY *key, int nid, int lastpos);
-int EVP_PKEY_get_attr_by_OBJ(const EVP_PKEY *key, const ASN1_OBJECT *obj,
-                             int lastpos);
-X509_ATTRIBUTE *EVP_PKEY_get_attr(const EVP_PKEY *key, int loc);
-X509_ATTRIBUTE *EVP_PKEY_delete_attr(EVP_PKEY *key, int loc);
-int EVP_PKEY_add1_attr(EVP_PKEY *key, X509_ATTRIBUTE *attr);
-int EVP_PKEY_add1_attr_by_OBJ(EVP_PKEY *key,
-                              const ASN1_OBJECT *obj, int type,
-                              const unsigned char *bytes, int len);
-int EVP_PKEY_add1_attr_by_NID(EVP_PKEY *key,
-                              int nid, int type,
-                              const unsigned char *bytes, int len);
-int EVP_PKEY_add1_attr_by_txt(EVP_PKEY *key,
-                              const char *attrname, int type,
-                              const unsigned char *bytes, int len);
- -

DESCRIPTION

- -

These functions are used by PKCS12.

- -

EVP_PKEY_get_attr_by_OBJ() finds the location of the first matching object obj in the key attribute list. The search starts at the position after lastpos. If the returned value is positive then it can be used on the next call to EVP_PKEY_get_attr_by_OBJ() as the value of lastpos in order to iterate through the remaining attributes. lastpos can be set to any negative value on the first call, in order to start searching from the start of the attribute list.

- -

EVP_PKEY_get_attr_by_NID() is similar to EVP_PKEY_get_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

EVP_PKEY_get_attr() returns the X509_ATTRIBUTE object at index loc in the key attribute list. loc should be in the range from 0 to EVP_PKEY_get_attr_count() - 1.

- -

EVP_PKEY_delete_attr() removes the X509_ATTRIBUTE object at index loc in the key attribute list.

- -

EVP_PKEY_add1_attr() pushes a copy of the passed in X509_ATTRIBUTE object to the key attribute list. A new key attribute list is created if required. An error occurs if either attr is NULL, or the attribute already exists.

- -

EVP_PKEY_add1_attr_by_OBJ() creates a new X509_ATTRIBUTE using X509_ATTRIBUTE_set1_object() and X509_ATTRIBUTE_set1_data() to assign a new obj with type type and data bytes of length len and then pushes it to the key object's attribute list. If obj already exists in the attribute list then an error occurs.

- -

EVP_PKEY_add1_attr_by_NID() is similar to EVP_PKEY_add1_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

EVP_PKEY_add1_attr_by_txt() is similar to EVP_PKEY_add1_attr_by_OBJ() except that it passes a name attrname associated with the object. See <openssl/obj_mac.h> for a list of SN_* names.

- -

RETURN VALUES

- -

EVP_PKEY_get_attr_count() returns the number of attributes in the key object attribute list or -1 if the attribute list is NULL.

- -

EVP_PKEY_get_attr_by_OBJ() returns -1 if either the list is empty OR the object is not found, otherwise it returns the location of the object in the list.

- -

EVP_PKEY_get_attr_by_NID() is similar to EVP_PKEY_get_attr_by_OBJ(), except that it returns -2 if the nid is not known by OpenSSL.

- -

EVP_PKEY_get_attr() returns either a X509_ATTRIBUTE or NULL if there is a error.

- -

EVP_PKEY_delete_attr() returns either the removed X509_ATTRIBUTE or NULL if there is a error.

- -

EVP_PKEY_add1_attr(), EVP_PKEY_add1_attr_by_OBJ(), EVP_PKEY_add1_attr_by_NID() and EVP_PKEY_add1_attr_by_txt() return 1 on success or 0 otherwise.

- -

NOTES

- -

A EVP_PKEY object's attribute list is initially NULL. All the above functions listed will return an error unless EVP_PKEY_add1_attr() is called. All functions listed assume that the key is not NULL.

- -

SEE ALSO

- -

X509_ATTRIBUTE(3)

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_default_digest_nid.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_default_digest_nid.html deleted file mode 100644 index cc914d80..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_default_digest_nid.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -EVP_PKEY_get_default_digest_nid - - - - - - - - - - -

NAME

- -

EVP_PKEY_get_default_digest_nid, EVP_PKEY_get_default_digest_name - get default signature digest

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_get_default_digest_name(EVP_PKEY *pkey,
-                                     char *mdname, size_t mdname_sz);
-int EVP_PKEY_get_default_digest_nid(EVP_PKEY *pkey, int *pnid);
- -

DESCRIPTION

- -

EVP_PKEY_get_default_digest_name() fills in the default message digest name for the public key signature operations associated with key pkey into mdname, up to at most mdname_sz bytes including the ending NUL byte. The name could be "UNDEF", signifying that a digest must (for return value 2) or may (for return value 1) be left unspecified.

- -

EVP_PKEY_get_default_digest_nid() sets pnid to the default message digest NID for the public key signature operations associated with key pkey. Note that some signature algorithms (i.e. Ed25519 and Ed448) do not use a digest during signing. In this case pnid will be set to NID_undef. This function is only reliable for legacy keys, which are keys with a EVP_PKEY_ASN1_METHOD; these keys have typically been loaded from engines, or created with EVP_PKEY_assign_RSA(3) or similar.

- -

NOTES

- -

For all current standard OpenSSL public key algorithms SHA256 is returned.

- -

RETURN VALUES

- -

EVP_PKEY_get_default_digest_name() and EVP_PKEY_get_default_digest_nid() both return 1 if the message digest is advisory (that is other digests can be used) and 2 if it is mandatory (other digests can not be used). They return 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_sign(3), EVP_PKEY_digestsign_supports_digest(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3),

- -

HISTORY

- -

This function was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2006-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_field_type.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_field_type.html deleted file mode 100644 index eb6d7ee9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_field_type.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -EVP_PKEY_get_field_type - - - - - - - - - - -

NAME

- -

EVP_PKEY_get_field_type, EVP_PKEY_get_ec_point_conv_form - get field type or point conversion form of a key

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_get_field_type(const EVP_PKEY *pkey);
-int EVP_PKEY_get_ec_point_conv_form(const EVP_PKEY *pkey);
- -

DESCRIPTION

- -

EVP_PKEY_get_field_type() returns the field type NID of the pkey, if pkey's key type supports it. The types currently supported by the built-in OpenSSL providers are either NID_X9_62_prime_field for prime curves or NID_X9_62_characteristic_two_field for binary curves; these values are defined in the <openssl/obj_mac.h> header file.

- -

EVP_PKEY_get_ec_point_conv_form() returns the point conversion format of the pkey, if pkey's key type supports it.

- -

NOTES

- -

Among the standard OpenSSL key types, this is only supported for EC and SM2 keys. Other providers may support this for additional key types.

- -

RETURN VALUES

- -

EVP_PKEY_get_field_type() returns the field type NID or 0 on error.

- -

EVP_PKEY_get_ec_point_conv_form() returns the point conversion format number (see EC_GROUP_copy(3)) or 0 on error.

- -

SEE ALSO

- -

EC_GROUP_copy(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_group_name.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_group_name.html deleted file mode 100644 index e0c1b98d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_group_name.html +++ /dev/null @@ -1,62 +0,0 @@ - - - - -EVP_PKEY_get_group_name - - - - - - - - - - -

NAME

- -

EVP_PKEY_get_group_name - get group name of a key

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_get_group_name(EVP_PKEY *pkey, char *gname, size_t gname_sz,
-                            size_t *gname_len);
- -

DESCRIPTION

- -

EVP_PKEY_get_group_name() fills in the group name of the pkey into gname, up to at most gname_sz bytes including the ending NUL byte and assigns *gname_len the actual length of the name not including the NUL byte, if pkey's key type supports it. gname as well as gname_len may individually be NULL, and won't be filled in or assigned in that case.

- -

NOTES

- -

Among the standard OpenSSL key types, this is only supported for DH, EC and SM2 keys. Other providers may support this for additional key types.

- -

RETURN VALUES

- -

EVP_PKEY_get_group_name() returns 1 if the group name could be filled in, otherwise 0.

- -

HISTORY

- -

This function was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_size.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_size.html deleted file mode 100644 index b2c51707..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_get_size.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -EVP_PKEY_get_size - - - - - - - - - - -

NAME

- -

EVP_PKEY_get_size, EVP_PKEY_get_bits, EVP_PKEY_get_security_bits, EVP_PKEY_bits, EVP_PKEY_security_bits, EVP_PKEY_size - EVP_PKEY information functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_get_size(const EVP_PKEY *pkey);
-int EVP_PKEY_get_bits(const EVP_PKEY *pkey);
-int EVP_PKEY_get_security_bits(const EVP_PKEY *pkey);
-
-#define EVP_PKEY_bits EVP_PKEY_get_bits
-#define EVP_PKEY_security_bits EVP_PKEY_get_security_bits
-#define EVP_PKEY_size EVP_PKEY_get_size
- -

DESCRIPTION

- -

EVP_PKEY_get_size() returns the maximum suitable size for the output buffers for almost all operations that can be done with pkey. This corresponds to the provider parameter OSSL_PKEY_PARAM_MAX_SIZE. The primary documented use is with EVP_SignFinal(3) and EVP_SealInit(3), but it isn't limited there. The returned size is also large enough for the output buffer of EVP_PKEY_sign(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_derive(3).

- -

It must be stressed that, unless the documentation for the operation that's being performed says otherwise, the size returned by EVP_PKEY_get_size() is only preliminary and not exact, so the final contents of the target buffer may be smaller. It is therefore crucial to take note of the size given back by the function that performs the operation, such as EVP_PKEY_sign(3) (the siglen argument will receive that length), to avoid bugs.

- -

EVP_PKEY_get_bits() returns the cryptographic length of the cryptosystem to which the key in pkey belongs, in bits. Note that the definition of cryptographic length is specific to the key cryptosystem. This length corresponds to the provider parameter OSSL_PKEY_PARAM_BITS.

- -

EVP_PKEY_get_security_bits() returns the number of security bits of the given pkey, bits of security is defined in NIST SP800-57. This corresponds to the provider parameter OSSL_PKEY_PARAM_SECURITY_BITS.

- -

RETURN VALUES

- -

EVP_PKEY_get_size(), EVP_PKEY_get_bits() and EVP_PKEY_get_security_bits() return a positive number, or 0 if this size isn't available.

- -

NOTES

- -

Most functions that have an output buffer and are mentioned with EVP_PKEY_get_size() have a functionality where you can pass NULL for the buffer and still pass a pointer to an integer and get the exact size that this function call delivers in the context that it's called in. This allows those functions to be called twice, once to find out the exact buffer size, then allocate the buffer in between, and call that function again actually output the data. For those functions, it isn't strictly necessary to call EVP_PKEY_get_size() to find out the buffer size, but may be useful in cases where it's desirable to know the upper limit in advance.

- -

It should also be especially noted that EVP_PKEY_get_size() shouldn't be used to get the output size for EVP_DigestSignFinal(), according to "NOTES" in EVP_DigestSignFinal(3).

- -

SEE ALSO

- -

provider-keymgmt(7), EVP_SignFinal(3), EVP_SealInit(3), EVP_PKEY_sign(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

The EVP_PKEY_bits(), EVP_PKEY_security_bits(), and EVP_PKEY_size() functions were renamed to include get in their names in OpenSSL 3.0, respectively. The old names are kept as non-deprecated alias macros.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_gettable_params.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_gettable_params.html deleted file mode 100644 index a5af4871..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_gettable_params.html +++ /dev/null @@ -1,125 +0,0 @@ - - - - -EVP_PKEY_gettable_params - - - - - - - - - - -

NAME

- -

EVP_PKEY_gettable_params, EVP_PKEY_get_params, EVP_PKEY_get_int_param, EVP_PKEY_get_size_t_param, EVP_PKEY_get_bn_param, EVP_PKEY_get_utf8_string_param, EVP_PKEY_get_octet_string_param - retrieve key parameters from a key

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const OSSL_PARAM *EVP_PKEY_gettable_params(EVP_PKEY *pkey);
-int EVP_PKEY_get_params(const EVP_PKEY *pkey, OSSL_PARAM params[]);
-int EVP_PKEY_get_int_param(const EVP_PKEY *pkey, const char *key_name,
-                           int *out);
-int EVP_PKEY_get_size_t_param(const EVP_PKEY *pkey, const char *key_name,
-                              size_t *out);
-int EVP_PKEY_get_bn_param(const EVP_PKEY *pkey, const char *key_name,
-                          BIGNUM **bn);
-int EVP_PKEY_get_utf8_string_param(const EVP_PKEY *pkey, const char *key_name,
-                                   char *str, size_t max_buf_sz,
-                                   size_t *out_len);
-int EVP_PKEY_get_octet_string_param(const EVP_PKEY *pkey, const char *key_name,
-                                    unsigned char *buf, size_t max_buf_sz,
-                                    size_t *out_len);
- -

DESCRIPTION

- -

See OSSL_PARAM(3) for information about parameters.

- -

EVP_PKEY_get_params() retrieves parameters from the key pkey, according to the contents of params.

- -

EVP_PKEY_gettable_params() returns a constant list of params indicating the names and types of key parameters that can be retrieved.

- -

An OSSL_PARAM(3) of type OSSL_PARAM_INTEGER or OSSL_PARAM_UNSIGNED_INTEGER is of arbitrary length. Such a parameter can be obtained using any of the functions EVP_PKEY_get_int_param(), EVP_PKEY_get_size_t_param() or EVP_PKEY_get_bn_param(). Attempting to obtain an integer value that does not fit into a native C int type will cause EVP_PKEY_get_int_param() to fail. Similarly attempting to obtain an integer value that is negative or does not fit into a native C size_t type using EVP_PKEY_get_size_t_param() will also fail.

- -

EVP_PKEY_get_int_param() retrieves a key pkey integer value *out associated with a name of key_name if it fits into int type. For parameters that do not fit into int use EVP_PKEY_get_bn_param().

- -

EVP_PKEY_get_size_t_param() retrieves a key pkey size_t value *out associated with a name of key_name if it fits into size_t type. For parameters that do not fit into size_t use EVP_PKEY_get_bn_param().

- -

EVP_PKEY_get_bn_param() retrieves a key pkey BIGNUM value **bn associated with a name of key_name. If *bn is NULL then the BIGNUM is allocated by the method.

- -

EVP_PKEY_get_utf8_string_param() get a key pkey UTF8 string value into a buffer str of maximum size max_buf_sz associated with a name of key_name. The maximum size must be large enough to accommodate the string value including a terminating NUL byte, or this function will fail. If out_len is not NULL, *out_len is set to the length of the string not including the terminating NUL byte. The required buffer size not including the terminating NUL byte can be obtained from *out_len by calling the function with str set to NULL.

- -

EVP_PKEY_get_octet_string_param() get a key pkey's octet string value into a buffer buf of maximum size max_buf_sz associated with a name of key_name. If out_len is not NULL, *out_len is set to the length of the contents. The required buffer size can be obtained from *out_len by calling the function with buf set to NULL.

- -

NOTES

- -

These functions only work for EVP_PKEYs that contain a provider side key.

- -

RETURN VALUES

- -

EVP_PKEY_gettable_params() returns NULL on error or if it is not supported.

- -

All other methods return 1 if a value associated with the key's key_name was successfully returned, or 0 if there was an error. An error may be returned by methods EVP_PKEY_get_utf8_string_param() and EVP_PKEY_get_octet_string_param() if max_buf_sz is not big enough to hold the value. If out_len is not NULL, *out_len will be assigned the required buffer size to hold the value.

- -

EXAMPLES

- -
#include <openssl/evp.h>
-
-char curve_name[64];
-unsigned char pub[256];
-BIGNUM *bn_priv = NULL;
-
-/*
- * NB: assumes 'key' is set up before the next step. In this example the key
- * is an EC key.
- */
-
-if (!EVP_PKEY_get_utf8_string_param(key, OSSL_PKEY_PARAM_GROUP_NAME,
-                                    curve_name, sizeof(curve_name), &len)) {
-  /* Error */
-}
-if (!EVP_PKEY_get_octet_string_param(key, OSSL_PKEY_PARAM_PUB_KEY,
-                                     pub, sizeof(pub), &len)) {
-    /* Error */
-}
-if (!EVP_PKEY_get_bn_param(key, OSSL_PKEY_PARAM_PRIV_KEY, &bn_priv)) {
-    /* Error */
-}
-
-BN_clear_free(bn_priv);
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), provider-keymgmt(7), OSSL_PARAM(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_is_a.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_is_a.html deleted file mode 100644 index e1463518..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_is_a.html +++ /dev/null @@ -1,118 +0,0 @@ - - - - -EVP_PKEY_is_a - - - - - - - - - - -

NAME

- -

EVP_PKEY_is_a, EVP_PKEY_can_sign, EVP_PKEY_type_names_do_all, EVP_PKEY_get0_type_name, EVP_PKEY_get0_description, EVP_PKEY_get0_provider - key type and capabilities functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_is_a(const EVP_PKEY *pkey, const char *name);
-int EVP_PKEY_can_sign(const EVP_PKEY *pkey);
-int EVP_PKEY_type_names_do_all(const EVP_PKEY *pkey,
-                               void (*fn)(const char *name, void *data),
-                               void *data);
-const char *EVP_PKEY_get0_type_name(const EVP_PKEY *key);
-const char *EVP_PKEY_get0_description(const EVP_PKEY *key);
-const OSSL_PROVIDER *EVP_PKEY_get0_provider(const EVP_PKEY *key);
- -

DESCRIPTION

- -

EVP_PKEY_is_a() checks if the key type of pkey is name.

- -

EVP_PKEY_can_sign() checks if the functionality for the key type of pkey supports signing. No other check is done, such as whether pkey contains a private key.

- -

EVP_PKEY_type_names_do_all() traverses all names for pkey's key type, and calls fn with each name and data. For example, an RSA EVP_PKEY may be named both RSA and rsaEncryption. The order of the names depends on the provider implementation that holds the key.

- -

EVP_PKEY_get0_type_name() returns the first key type name that is found for the given pkey. Note that the pkey may have multiple synonyms associated with it. In this case it depends on the provider implementation that holds the key which one will be returned. Ownership of the returned string is retained by the pkey object and should not be freed by the caller.

- -

EVP_PKEY_get0_description() returns a description of the type of EVP_PKEY, meant for display and human consumption. The description is at the discretion of the key type implementation.

- -

EVP_PKEY_get0_provider() returns the provider of the EVP_PKEY's EVP_KEYMGMT(3).

- -

RETURN VALUES

- -

EVP_PKEY_is_a() returns 1 if pkey has the key type name, otherwise 0.

- -

EVP_PKEY_can_sign() returns 1 if the pkey key type functionality supports signing, otherwise 0.

- -

EVP_PKEY_get0_type_name() returns the name that is found or NULL on error.

- -

EVP_PKEY_get0_description() returns the description if found or NULL if not.

- -

EVP_PKEY_get0_provider() returns the provider if found or NULL if not.

- -

EVP_PKEY_type_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EXAMPLES

- -

EVP_PKEY_is_a()

- -

The loaded providers and what key types they support will ultimately determine what name is possible to use with EVP_PKEY_is_a(). We do know that the default provider supports RSA, DH, DSA and EC keys, so we can use this as an crude example:

- -
#include <openssl/evp.h>
-
-...
-    /* |pkey| is an EVP_PKEY* */
-    if (EVP_PKEY_is_a(pkey, "RSA")) {
-        BIGNUM *modulus = NULL;
-        if (EVP_PKEY_get_bn_param(pkey, "n", &modulus))
-            /* do whatever with the modulus */
-        BN_free(modulus);
-    }
- -

EVP_PKEY_can_sign()

- -
#include <openssl/evp.h>
-
-...
-    /* |pkey| is an EVP_PKEY* */
-    if (!EVP_PKEY_can_sign(pkey)) {
-        fprintf(stderr, "Not a signing key!");
-        exit(1);
-    }
-    /* Sign something... */
- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_keygen.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_keygen.html deleted file mode 100644 index 44cd3a4d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_keygen.html +++ /dev/null @@ -1,187 +0,0 @@ - - - - -EVP_PKEY_keygen - - - - - - - - - - -

NAME

- -

EVP_PKEY_Q_keygen, EVP_PKEY_keygen_init, EVP_PKEY_paramgen_init, EVP_PKEY_generate, EVP_PKEY_CTX_set_cb, EVP_PKEY_CTX_get_cb, EVP_PKEY_CTX_get_keygen_info, EVP_PKEY_CTX_set_app_data, EVP_PKEY_CTX_get_app_data, EVP_PKEY_gen_cb, EVP_PKEY_paramgen, EVP_PKEY_keygen - key and parameter generation and check functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_PKEY *EVP_PKEY_Q_keygen(OSSL_LIB_CTX *libctx, const char *propq,
-                            const char *type, ...);
-
-int EVP_PKEY_keygen_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_paramgen_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_generate(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey);
-int EVP_PKEY_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey);
-int EVP_PKEY_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey);
-
-typedef int EVP_PKEY_gen_cb(EVP_PKEY_CTX *ctx);
-
-void EVP_PKEY_CTX_set_cb(EVP_PKEY_CTX *ctx, EVP_PKEY_gen_cb *cb);
-EVP_PKEY_gen_cb *EVP_PKEY_CTX_get_cb(EVP_PKEY_CTX *ctx);
-
-int EVP_PKEY_CTX_get_keygen_info(EVP_PKEY_CTX *ctx, int idx);
-
-void EVP_PKEY_CTX_set_app_data(EVP_PKEY_CTX *ctx, void *data);
-void *EVP_PKEY_CTX_get_app_data(EVP_PKEY_CTX *ctx);
- -

DESCRIPTION

- -

Generating keys is sometimes straight forward, just generate the key's numbers and be done with it. However, there are certain key types that need key parameters, often called domain parameters but not necessarily limited to that, that also need to be generated. In addition to this, the caller may want to set user provided generation parameters that further affect key parameter or key generation, such as the desired key size.

- -

To flexibly allow all that's just been described, key parameter and key generation is divided into an initialization of a key algorithm context, functions to set user provided parameters, and finally the key parameter or key generation function itself.

- -

The key algorithm context must be created using EVP_PKEY_CTX_new(3) or variants thereof, see that manual for details.

- -

EVP_PKEY_keygen_init() initializes a public key algorithm context ctx for a key generation operation.

- -

EVP_PKEY_paramgen_init() is similar to EVP_PKEY_keygen_init() except key parameters are generated.

- -

After initialization, generation parameters may be provided with EVP_PKEY_CTX_ctrl(3) or EVP_PKEY_CTX_set_params(3), or any other function described in those manuals.

- -

EVP_PKEY_generate() performs the generation operation, the resulting key parameters or key are written to *ppkey. If *ppkey is NULL when this function is called, it will be allocated, and should be freed by the caller when no longer useful, using EVP_PKEY_free(3).

- -

EVP_PKEY_paramgen() and EVP_PKEY_keygen() do exactly the same thing as EVP_PKEY_generate(), after checking that the corresponding EVP_PKEY_paramgen_init() or EVP_PKEY_keygen_init() was used to initialize ctx. These are older functions that are kept for backward compatibility. It is safe to use EVP_PKEY_generate() instead.

- -

The function EVP_PKEY_set_cb() sets the key or parameter generation callback to cb. The function EVP_PKEY_CTX_get_cb() returns the key or parameter generation callback.

- -

The function EVP_PKEY_CTX_get_keygen_info() returns parameters associated with the generation operation. If idx is -1 the total number of parameters available is returned. Any non negative value returns the value of that parameter. EVP_PKEY_CTX_gen_keygen_info() with a nonnegative value for idx should only be called within the generation callback.

- -

If the callback returns 0 then the key generation operation is aborted and an error occurs. This might occur during a time consuming operation where a user clicks on a "cancel" button.

- -

The functions EVP_PKEY_CTX_set_app_data() and EVP_PKEY_CTX_get_app_data() set and retrieve an opaque pointer. This can be used to set some application defined value which can be retrieved in the callback: for example a handle which is used to update a "progress dialog".

- -

EVP_PKEY_Q_keygen() abstracts from the explicit use of EVP_PKEY_CTX while providing a 'quick' but limited way of generating a new asymmetric key pair. It provides shorthands for simple and common cases of key generation. As usual, the library context libctx and property query propq can be given for fetching algorithms from providers. If type is RSA, a size_t parameter must be given to specify the size of the RSA key. If type is EC, a string parameter must be given to specify the name of the EC curve. If type is X25519, X448, ED25519, ED448, or SM2 no further parameter is needed.

- -

RETURN VALUES

- -

EVP_PKEY_keygen_init(), EVP_PKEY_paramgen_init(), EVP_PKEY_keygen() and EVP_PKEY_paramgen() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EVP_PKEY_Q_keygen() returns an EVP_PKEY, or NULL on failure.

- -

NOTES

- -

After the call to EVP_PKEY_keygen_init() or EVP_PKEY_paramgen_init() algorithm specific control operations can be performed to set any appropriate parameters for the operation.

- -

The functions EVP_PKEY_keygen() and EVP_PKEY_paramgen() can be called more than once on the same context if several operations are performed using the same parameters.

- -

The meaning of the parameters passed to the callback will depend on the algorithm and the specific implementation of the algorithm. Some might not give any useful information at all during key or parameter generation. Others might not even call the callback.

- -

The operation performed by key or parameter generation depends on the algorithm used. In some cases (e.g. EC with a supplied named curve) the "generation" option merely sets the appropriate fields in an EVP_PKEY structure.

- -

In OpenSSL an EVP_PKEY structure containing a private key also contains the public key components and parameters (if any). An OpenSSL private key is equivalent to what some libraries call a "key pair". A private key can be used in functions which require the use of a public key or parameters.

- -

EXAMPLES

- -

Generate a 2048 bit RSA key:

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-EVP_PKEY *pkey = NULL;
-
-ctx = EVP_PKEY_CTX_new_id(EVP_PKEY_RSA, NULL);
-if (!ctx)
-    /* Error occurred */
-if (EVP_PKEY_keygen_init(ctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_rsa_keygen_bits(ctx, 2048) <= 0)
-    /* Error */
-
-/* Generate key */
-if (EVP_PKEY_keygen(ctx, &pkey) <= 0)
-    /* Error */
- -

Generate a key from a set of parameters:

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-ENGINE *eng;
-EVP_PKEY *pkey = NULL, *param;
-
-/* Assumed param, eng are set up already */
-ctx = EVP_PKEY_CTX_new(param, eng);
-if (!ctx)
-    /* Error occurred */
-if (EVP_PKEY_keygen_init(ctx) <= 0)
-    /* Error */
-
-/* Generate key */
-if (EVP_PKEY_keygen(ctx, &pkey) <= 0)
-    /* Error */
- -

Example of generation callback for OpenSSL public key implementations:

- -
/* Application data is a BIO to output status to */
-
-EVP_PKEY_CTX_set_app_data(ctx, status_bio);
-
-static int genpkey_cb(EVP_PKEY_CTX *ctx)
-{
-    char c = '*';
-    BIO *b = EVP_PKEY_CTX_get_app_data(ctx);
-    int p = EVP_PKEY_CTX_get_keygen_info(ctx, 0);
-
-    if (p == 0)
-        c = '.';
-    if (p == 1)
-        c = '+';
-    if (p == 2)
-        c = '*';
-    if (p == 3)
-        c = '\n';
-    BIO_write(b, &c, 1);
-    (void)BIO_flush(b);
-    return 1;
-}
- -

SEE ALSO

- -

EVP_RSA_gen(3), EVP_EC_gen(3), EVP_PKEY_CTX_new(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

EVP_PKEY_keygen_init(), int EVP_PKEY_paramgen_init(), EVP_PKEY_keygen(), EVP_PKEY_paramgen(), EVP_PKEY_gen_cb(), EVP_PKEY_CTX_set_cb(), EVP_PKEY_CTX_get_cb(), EVP_PKEY_CTX_get_keygen_info(), EVP_PKEY_CTX_set_app_data() and EVP_PKEY_CTX_get_app_data() were added in OpenSSL 1.0.0.

- -

EVP_PKEY_Q_keygen() and EVP_PKEY_generate() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_get_count.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_get_count.html deleted file mode 100644 index 60099e81..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_get_count.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_PKEY_meth_get_count - - - - - - - - - - -

NAME

- -

EVP_PKEY_meth_get_count, EVP_PKEY_meth_get0, EVP_PKEY_meth_get0_info - enumerate public key methods

- -

SYNOPSIS

- -
#include <openssl/evp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
size_t EVP_PKEY_meth_get_count(void);
-const EVP_PKEY_METHOD *EVP_PKEY_meth_get0(size_t idx);
-void EVP_PKEY_meth_get0_info(int *ppkey_id, int *pflags,
-                             const EVP_PKEY_METHOD *meth);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the OSSL_PROVIDER APIs.

- -

EVP_PKEY_meth_count() returns a count of the number of public key methods available: it includes standard methods and any methods added by the application.

- -

EVP_PKEY_meth_get0() returns the public key method idx. The value of idx must be between zero and EVP_PKEY_meth_get_count() - 1.

- -

EVP_PKEY_meth_get0_info() returns the public key ID (a NID) and any flags associated with the public key method *meth.

- -

RETURN VALUES

- -

EVP_PKEY_meth_count() returns the number of available public key methods.

- -

EVP_PKEY_meth_get0() return a public key method or NULL if idx is out of range.

- -

EVP_PKEY_meth_get0_info() does not return a value.

- -

SEE ALSO

- -

EVP_PKEY_new(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_new.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_new.html deleted file mode 100644 index 8e1c9f5a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_meth_new.html +++ /dev/null @@ -1,405 +0,0 @@ - - - - -EVP_PKEY_meth_new - - - - - - - - - - -

NAME

- -

EVP_PKEY_meth_new, EVP_PKEY_meth_free, EVP_PKEY_meth_copy, EVP_PKEY_meth_find, EVP_PKEY_meth_add0, EVP_PKEY_METHOD, EVP_PKEY_meth_set_init, EVP_PKEY_meth_set_copy, EVP_PKEY_meth_set_cleanup, EVP_PKEY_meth_set_paramgen, EVP_PKEY_meth_set_keygen, EVP_PKEY_meth_set_sign, EVP_PKEY_meth_set_verify, EVP_PKEY_meth_set_verify_recover, EVP_PKEY_meth_set_signctx, EVP_PKEY_meth_set_verifyctx, EVP_PKEY_meth_set_encrypt, EVP_PKEY_meth_set_decrypt, EVP_PKEY_meth_set_derive, EVP_PKEY_meth_set_ctrl, EVP_PKEY_meth_set_digestsign, EVP_PKEY_meth_set_digestverify, EVP_PKEY_meth_set_check, EVP_PKEY_meth_set_public_check, EVP_PKEY_meth_set_param_check, EVP_PKEY_meth_set_digest_custom, EVP_PKEY_meth_get_init, EVP_PKEY_meth_get_copy, EVP_PKEY_meth_get_cleanup, EVP_PKEY_meth_get_paramgen, EVP_PKEY_meth_get_keygen, EVP_PKEY_meth_get_sign, EVP_PKEY_meth_get_verify, EVP_PKEY_meth_get_verify_recover, EVP_PKEY_meth_get_signctx, EVP_PKEY_meth_get_verifyctx, EVP_PKEY_meth_get_encrypt, EVP_PKEY_meth_get_decrypt, EVP_PKEY_meth_get_derive, EVP_PKEY_meth_get_ctrl, EVP_PKEY_meth_get_digestsign, EVP_PKEY_meth_get_digestverify, EVP_PKEY_meth_get_check, EVP_PKEY_meth_get_public_check, EVP_PKEY_meth_get_param_check, EVP_PKEY_meth_get_digest_custom, EVP_PKEY_meth_remove - manipulating EVP_PKEY_METHOD structure

- -

SYNOPSIS

- -
#include <openssl/evp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
typedef struct evp_pkey_method_st EVP_PKEY_METHOD;
-
-EVP_PKEY_METHOD *EVP_PKEY_meth_new(int id, int flags);
-void EVP_PKEY_meth_free(EVP_PKEY_METHOD *pmeth);
-void EVP_PKEY_meth_copy(EVP_PKEY_METHOD *dst, const EVP_PKEY_METHOD *src);
-const EVP_PKEY_METHOD *EVP_PKEY_meth_find(int type);
-int EVP_PKEY_meth_add0(const EVP_PKEY_METHOD *pmeth);
-int EVP_PKEY_meth_remove(const EVP_PKEY_METHOD *pmeth);
-
-void EVP_PKEY_meth_set_init(EVP_PKEY_METHOD *pmeth,
-                            int (*init) (EVP_PKEY_CTX *ctx));
-void EVP_PKEY_meth_set_copy(EVP_PKEY_METHOD *pmeth,
-                            int (*copy) (EVP_PKEY_CTX *dst,
-                                         const EVP_PKEY_CTX *src));
-void EVP_PKEY_meth_set_cleanup(EVP_PKEY_METHOD *pmeth,
-                               void (*cleanup) (EVP_PKEY_CTX *ctx));
-void EVP_PKEY_meth_set_paramgen(EVP_PKEY_METHOD *pmeth,
-                                int (*paramgen_init) (EVP_PKEY_CTX *ctx),
-                                int (*paramgen) (EVP_PKEY_CTX *ctx,
-                                                 EVP_PKEY *pkey));
-void EVP_PKEY_meth_set_keygen(EVP_PKEY_METHOD *pmeth,
-                              int (*keygen_init) (EVP_PKEY_CTX *ctx),
-                              int (*keygen) (EVP_PKEY_CTX *ctx,
-                                             EVP_PKEY *pkey));
-void EVP_PKEY_meth_set_sign(EVP_PKEY_METHOD *pmeth,
-                            int (*sign_init) (EVP_PKEY_CTX *ctx),
-                            int (*sign) (EVP_PKEY_CTX *ctx,
-                                         unsigned char *sig, size_t *siglen,
-                                         const unsigned char *tbs,
-                                         size_t tbslen));
-void EVP_PKEY_meth_set_verify(EVP_PKEY_METHOD *pmeth,
-                              int (*verify_init) (EVP_PKEY_CTX *ctx),
-                              int (*verify) (EVP_PKEY_CTX *ctx,
-                                             const unsigned char *sig,
-                                             size_t siglen,
-                                             const unsigned char *tbs,
-                                             size_t tbslen));
-void EVP_PKEY_meth_set_verify_recover(EVP_PKEY_METHOD *pmeth,
-                                      int (*verify_recover_init) (EVP_PKEY_CTX
-                                                                  *ctx),
-                                      int (*verify_recover) (EVP_PKEY_CTX
-                                                             *ctx,
-                                                             unsigned char
-                                                             *sig,
-                                                             size_t *siglen,
-                                                             const unsigned
-                                                             char *tbs,
-                                                             size_t tbslen));
-void EVP_PKEY_meth_set_signctx(EVP_PKEY_METHOD *pmeth,
-                               int (*signctx_init) (EVP_PKEY_CTX *ctx,
-                                                    EVP_MD_CTX *mctx),
-                               int (*signctx) (EVP_PKEY_CTX *ctx,
-                                               unsigned char *sig,
-                                               size_t *siglen,
-                                               EVP_MD_CTX *mctx));
-void EVP_PKEY_meth_set_verifyctx(EVP_PKEY_METHOD *pmeth,
-                                 int (*verifyctx_init) (EVP_PKEY_CTX *ctx,
-                                                        EVP_MD_CTX *mctx),
-                                 int (*verifyctx) (EVP_PKEY_CTX *ctx,
-                                                   const unsigned char *sig,
-                                                   int siglen,
-                                                   EVP_MD_CTX *mctx));
-void EVP_PKEY_meth_set_encrypt(EVP_PKEY_METHOD *pmeth,
-                               int (*encrypt_init) (EVP_PKEY_CTX *ctx),
-                               int (*encryptfn) (EVP_PKEY_CTX *ctx,
-                                                 unsigned char *out,
-                                                 size_t *outlen,
-                                                 const unsigned char *in,
-                                                 size_t inlen));
-void EVP_PKEY_meth_set_decrypt(EVP_PKEY_METHOD *pmeth,
-                               int (*decrypt_init) (EVP_PKEY_CTX *ctx),
-                               int (*decrypt) (EVP_PKEY_CTX *ctx,
-                                               unsigned char *out,
-                                               size_t *outlen,
-                                               const unsigned char *in,
-                                               size_t inlen));
-void EVP_PKEY_meth_set_derive(EVP_PKEY_METHOD *pmeth,
-                              int (*derive_init) (EVP_PKEY_CTX *ctx),
-                              int (*derive) (EVP_PKEY_CTX *ctx,
-                                             unsigned char *key,
-                                             size_t *keylen));
-void EVP_PKEY_meth_set_ctrl(EVP_PKEY_METHOD *pmeth,
-                            int (*ctrl) (EVP_PKEY_CTX *ctx, int type, int p1,
-                                         void *p2),
-                            int (*ctrl_str) (EVP_PKEY_CTX *ctx,
-                                             const char *type,
-                                             const char *value));
-void EVP_PKEY_meth_set_digestsign(EVP_PKEY_METHOD *pmeth,
-                                  int (*digestsign) (EVP_MD_CTX *ctx,
-                                                     unsigned char *sig,
-                                                     size_t *siglen,
-                                                     const unsigned char *tbs,
-                                                     size_t tbslen));
-void EVP_PKEY_meth_set_digestverify(EVP_PKEY_METHOD *pmeth,
-                                    int (*digestverify) (EVP_MD_CTX *ctx,
-                                                         const unsigned char *sig,
-                                                         size_t siglen,
-                                                         const unsigned char *tbs,
-                                                         size_t tbslen));
-void EVP_PKEY_meth_set_check(EVP_PKEY_METHOD *pmeth,
-                             int (*check) (EVP_PKEY *pkey));
-void EVP_PKEY_meth_set_public_check(EVP_PKEY_METHOD *pmeth,
-                                    int (*check) (EVP_PKEY *pkey));
-void EVP_PKEY_meth_set_param_check(EVP_PKEY_METHOD *pmeth,
-                                   int (*check) (EVP_PKEY *pkey));
-void EVP_PKEY_meth_set_digest_custom(EVP_PKEY_METHOD *pmeth,
-                                    int (*digest_custom) (EVP_PKEY_CTX *ctx,
-                                                          EVP_MD_CTX *mctx));
-
-void EVP_PKEY_meth_get_init(const EVP_PKEY_METHOD *pmeth,
-                            int (**pinit) (EVP_PKEY_CTX *ctx));
-void EVP_PKEY_meth_get_copy(const EVP_PKEY_METHOD *pmeth,
-                            int (**pcopy) (EVP_PKEY_CTX *dst,
-                                           EVP_PKEY_CTX *src));
-void EVP_PKEY_meth_get_cleanup(const EVP_PKEY_METHOD *pmeth,
-                               void (**pcleanup) (EVP_PKEY_CTX *ctx));
-void EVP_PKEY_meth_get_paramgen(const EVP_PKEY_METHOD *pmeth,
-                                int (**pparamgen_init) (EVP_PKEY_CTX *ctx),
-                                int (**pparamgen) (EVP_PKEY_CTX *ctx,
-                                                   EVP_PKEY *pkey));
-void EVP_PKEY_meth_get_keygen(const EVP_PKEY_METHOD *pmeth,
-                              int (**pkeygen_init) (EVP_PKEY_CTX *ctx),
-                              int (**pkeygen) (EVP_PKEY_CTX *ctx,
-                                               EVP_PKEY *pkey));
-void EVP_PKEY_meth_get_sign(const EVP_PKEY_METHOD *pmeth,
-                            int (**psign_init) (EVP_PKEY_CTX *ctx),
-                            int (**psign) (EVP_PKEY_CTX *ctx,
-                                           unsigned char *sig, size_t *siglen,
-                                           const unsigned char *tbs,
-                                           size_t tbslen));
-void EVP_PKEY_meth_get_verify(const EVP_PKEY_METHOD *pmeth,
-                              int (**pverify_init) (EVP_PKEY_CTX *ctx),
-                              int (**pverify) (EVP_PKEY_CTX *ctx,
-                                               const unsigned char *sig,
-                                               size_t siglen,
-                                               const unsigned char *tbs,
-                                               size_t tbslen));
-void EVP_PKEY_meth_get_verify_recover(const EVP_PKEY_METHOD *pmeth,
-                                      int (**pverify_recover_init) (EVP_PKEY_CTX
-                                                                    *ctx),
-                                      int (**pverify_recover) (EVP_PKEY_CTX
-                                                               *ctx,
-                                                               unsigned char
-                                                               *sig,
-                                                               size_t *siglen,
-                                                               const unsigned
-                                                               char *tbs,
-                                                               size_t tbslen));
-void EVP_PKEY_meth_get_signctx(const EVP_PKEY_METHOD *pmeth,
-                               int (**psignctx_init) (EVP_PKEY_CTX *ctx,
-                                                      EVP_MD_CTX *mctx),
-                               int (**psignctx) (EVP_PKEY_CTX *ctx,
-                                                 unsigned char *sig,
-                                                 size_t *siglen,
-                                                 EVP_MD_CTX *mctx));
-void EVP_PKEY_meth_get_verifyctx(const EVP_PKEY_METHOD *pmeth,
-                                 int (**pverifyctx_init) (EVP_PKEY_CTX *ctx,
-                                                          EVP_MD_CTX *mctx),
-                                 int (**pverifyctx) (EVP_PKEY_CTX *ctx,
-                                                     const unsigned char *sig,
-                                                     int siglen,
-                                                     EVP_MD_CTX *mctx));
-void EVP_PKEY_meth_get_encrypt(const EVP_PKEY_METHOD *pmeth,
-                               int (**pencrypt_init) (EVP_PKEY_CTX *ctx),
-                               int (**pencryptfn) (EVP_PKEY_CTX *ctx,
-                                                   unsigned char *out,
-                                                   size_t *outlen,
-                                                   const unsigned char *in,
-                                                   size_t inlen));
-void EVP_PKEY_meth_get_decrypt(const EVP_PKEY_METHOD *pmeth,
-                               int (**pdecrypt_init) (EVP_PKEY_CTX *ctx),
-                               int (**pdecrypt) (EVP_PKEY_CTX *ctx,
-                                                 unsigned char *out,
-                                                 size_t *outlen,
-                                                 const unsigned char *in,
-                                                 size_t inlen));
-void EVP_PKEY_meth_get_derive(const EVP_PKEY_METHOD *pmeth,
-                              int (**pderive_init) (EVP_PKEY_CTX *ctx),
-                              int (**pderive) (EVP_PKEY_CTX *ctx,
-                                               unsigned char *key,
-                                               size_t *keylen));
-void EVP_PKEY_meth_get_ctrl(const EVP_PKEY_METHOD *pmeth,
-                            int (**pctrl) (EVP_PKEY_CTX *ctx, int type, int p1,
-                                           void *p2),
-                            int (**pctrl_str) (EVP_PKEY_CTX *ctx,
-                                               const char *type,
-                                               const char *value));
-void EVP_PKEY_meth_get_digestsign(const EVP_PKEY_METHOD *pmeth,
-                                  int (**digestsign) (EVP_MD_CTX *ctx,
-                                                      unsigned char *sig,
-                                                      size_t *siglen,
-                                                      const unsigned char *tbs,
-                                                      size_t tbslen));
-void EVP_PKEY_meth_get_digestverify(const EVP_PKEY_METHOD *pmeth,
-                                    int (**digestverify) (EVP_MD_CTX *ctx,
-                                                          const unsigned char *sig,
-                                                          size_t siglen,
-                                                          const unsigned char *tbs,
-                                                          size_t tbslen));
-void EVP_PKEY_meth_get_check(const EVP_PKEY_METHOD *pmeth,
-                             int (**pcheck) (EVP_PKEY *pkey));
-void EVP_PKEY_meth_get_public_check(const EVP_PKEY_METHOD *pmeth,
-                                    int (**pcheck) (EVP_PKEY *pkey));
-void EVP_PKEY_meth_get_param_check(const EVP_PKEY_METHOD *pmeth,
-                                   int (**pcheck) (EVP_PKEY *pkey));
-void EVP_PKEY_meth_get_digest_custom(const EVP_PKEY_METHOD *pmeth,
-                                    int (**pdigest_custom) (EVP_PKEY_CTX *ctx,
-                                                            EVP_MD_CTX *mctx));
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the OSSL_PROVIDER APIs.

- -

EVP_PKEY_METHOD is a structure which holds a set of methods for a specific public key cryptographic algorithm. Those methods are usually used to perform different jobs, such as generating a key, signing or verifying, encrypting or decrypting, etc.

- -

There are two places where the EVP_PKEY_METHOD objects are stored: one is a built-in static array representing the standard methods for different algorithms, and the other one is a stack of user-defined application-specific methods, which can be manipulated by using EVP_PKEY_meth_add0(3).

- -

The EVP_PKEY_METHOD objects are usually referenced by EVP_PKEY_CTX objects.

- -

Methods

- -

The methods are the underlying implementations of a particular public key algorithm present by the EVP_PKEY_CTX object.

- -
int (*init) (EVP_PKEY_CTX *ctx);
-int (*copy) (EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src);
-void (*cleanup) (EVP_PKEY_CTX *ctx);
- -

The init() method is called to initialize algorithm-specific data when a new EVP_PKEY_CTX is created. As opposed to init(), the cleanup() method is called when an EVP_PKEY_CTX is freed. The copy() method is called when an EVP_PKEY_CTX is being duplicated. Refer to EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_new_id(3), EVP_PKEY_CTX_free(3) and EVP_PKEY_CTX_dup(3).

- -
int (*paramgen_init) (EVP_PKEY_CTX *ctx);
-int (*paramgen) (EVP_PKEY_CTX *ctx, EVP_PKEY *pkey);
- -

The paramgen_init() and paramgen() methods deal with key parameter generation. They are called by EVP_PKEY_paramgen_init(3) and EVP_PKEY_paramgen(3) to handle the parameter generation process.

- -
int (*keygen_init) (EVP_PKEY_CTX *ctx);
-int (*keygen) (EVP_PKEY_CTX *ctx, EVP_PKEY *pkey);
- -

The keygen_init() and keygen() methods are used to generate the actual key for the specified algorithm. They are called by EVP_PKEY_keygen_init(3) and EVP_PKEY_keygen(3).

- -
int (*sign_init) (EVP_PKEY_CTX *ctx);
-int (*sign) (EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen,
-             const unsigned char *tbs, size_t tbslen);
- -

The sign_init() and sign() methods are used to generate the signature of a piece of data using a private key. They are called by EVP_PKEY_sign_init(3) and EVP_PKEY_sign(3).

- -
int (*verify_init) (EVP_PKEY_CTX *ctx);
-int (*verify) (EVP_PKEY_CTX *ctx,
-               const unsigned char *sig, size_t siglen,
-               const unsigned char *tbs, size_t tbslen);
- -

The verify_init() and verify() methods are used to verify whether a signature is valid. They are called by EVP_PKEY_verify_init(3) and EVP_PKEY_verify(3).

- -
int (*verify_recover_init) (EVP_PKEY_CTX *ctx);
-int (*verify_recover) (EVP_PKEY_CTX *ctx,
-                       unsigned char *rout, size_t *routlen,
-                       const unsigned char *sig, size_t siglen);
- -

The verify_recover_init() and verify_recover() methods are used to verify a signature and then recover the digest from the signature (for instance, a signature that was generated by RSA signing algorithm). They are called by EVP_PKEY_verify_recover_init(3) and EVP_PKEY_verify_recover(3).

- -
int (*signctx_init) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx);
-int (*signctx) (EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen,
-                EVP_MD_CTX *mctx);
- -

The signctx_init() and signctx() methods are used to sign a digest present by a EVP_MD_CTX object. They are called by the EVP_DigestSign functions. See EVP_DigestSignInit(3) for details.

- -
int (*verifyctx_init) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx);
-int (*verifyctx) (EVP_PKEY_CTX *ctx, const unsigned char *sig, int siglen,
-                  EVP_MD_CTX *mctx);
- -

The verifyctx_init() and verifyctx() methods are used to verify a signature against the data in a EVP_MD_CTX object. They are called by the various EVP_DigestVerify functions. See EVP_DigestVerifyInit(3) for details.

- -
int (*encrypt_init) (EVP_PKEY_CTX *ctx);
-int (*encrypt) (EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen,
-                const unsigned char *in, size_t inlen);
- -

The encrypt_init() and encrypt() methods are used to encrypt a piece of data. They are called by EVP_PKEY_encrypt_init(3) and EVP_PKEY_encrypt(3).

- -
int (*decrypt_init) (EVP_PKEY_CTX *ctx);
-int (*decrypt) (EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen,
-                const unsigned char *in, size_t inlen);
- -

The decrypt_init() and decrypt() methods are used to decrypt a piece of data. They are called by EVP_PKEY_decrypt_init(3) and EVP_PKEY_decrypt(3).

- -
int (*derive_init) (EVP_PKEY_CTX *ctx);
-int (*derive) (EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen);
- -

The derive_init() and derive() methods are used to derive the shared secret from a public key algorithm (for instance, the DH algorithm). They are called by EVP_PKEY_derive_init(3) and EVP_PKEY_derive(3).

- -
int (*ctrl) (EVP_PKEY_CTX *ctx, int type, int p1, void *p2);
-int (*ctrl_str) (EVP_PKEY_CTX *ctx, const char *type, const char *value);
- -

The ctrl() and ctrl_str() methods are used to adjust algorithm-specific settings. See EVP_PKEY_CTX_ctrl(3) and related functions for details.

- -
int (*digestsign) (EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen,
-                   const unsigned char *tbs, size_t tbslen);
-int (*digestverify) (EVP_MD_CTX *ctx, const unsigned char *sig,
-                     size_t siglen, const unsigned char *tbs,
-                     size_t tbslen);
- -

The digestsign() and digestverify() methods are used to generate or verify a signature in a one-shot mode. They could be called by EVP_DigestSign(3) and EVP_DigestVerify(3).

- -
int (*check) (EVP_PKEY *pkey);
-int (*public_check) (EVP_PKEY *pkey);
-int (*param_check) (EVP_PKEY *pkey);
- -

The check(), public_check() and param_check() methods are used to validate a key-pair, the public component and parameters respectively for a given pkey. They could be called by EVP_PKEY_check(3), EVP_PKEY_public_check(3) and EVP_PKEY_param_check(3) respectively.

- -
int (*digest_custom) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx);
- -

The digest_custom() method is used to generate customized digest content before the real message is passed to functions like EVP_DigestSignUpdate(3) or EVP_DigestVerifyInit(3). This is usually required by some public key signature algorithms like SM2 which requires a hashed prefix to the message to be signed. The digest_custom() function will be called by EVP_DigestSignInit(3) and EVP_DigestVerifyInit(3).

- -

Functions

- -

EVP_PKEY_meth_new() creates and returns a new EVP_PKEY_METHOD object, and associates the given id and flags. The following flags are supported:

- -
EVP_PKEY_FLAG_AUTOARGLEN
-EVP_PKEY_FLAG_SIGCTX_CUSTOM
- -

If an EVP_PKEY_METHOD is set with the EVP_PKEY_FLAG_AUTOARGLEN flag, the maximum size of the output buffer will be automatically calculated or checked in corresponding EVP methods by the EVP framework. Thus the implementations of these methods don't need to care about handling the case of returning output buffer size by themselves. For details on the output buffer size, refer to EVP_PKEY_sign(3).

- -

The EVP_PKEY_FLAG_SIGCTX_CUSTOM is used to indicate the signctx() method of an EVP_PKEY_METHOD is always called by the EVP framework while doing a digest signing operation by calling EVP_DigestSignFinal(3).

- -

EVP_PKEY_meth_free() frees an existing EVP_PKEY_METHOD pointed by pmeth. If the argument is NULL, nothing is done.

- -

EVP_PKEY_meth_copy() copies an EVP_PKEY_METHOD object from src to dst.

- -

EVP_PKEY_meth_find() finds an EVP_PKEY_METHOD object with the id. This function first searches through the user-defined method objects and then the built-in objects.

- -

EVP_PKEY_meth_add0() adds pmeth to the user defined stack of methods.

- -

EVP_PKEY_meth_remove() removes an EVP_PKEY_METHOD object added by EVP_PKEY_meth_add0().

- -

The EVP_PKEY_meth_set functions set the corresponding fields of EVP_PKEY_METHOD structure with the arguments passed.

- -

The EVP_PKEY_meth_get functions get the corresponding fields of EVP_PKEY_METHOD structure to the arguments provided.

- -

RETURN VALUES

- -

EVP_PKEY_meth_new() returns a pointer to a new EVP_PKEY_METHOD object or returns NULL on error.

- -

EVP_PKEY_meth_free() and EVP_PKEY_meth_copy() do not return values.

- -

EVP_PKEY_meth_find() returns a pointer to the found EVP_PKEY_METHOD object or returns NULL if not found.

- -

EVP_PKEY_meth_add0() returns 1 if method is added successfully or 0 if an error occurred.

- -

EVP_PKEY_meth_remove() returns 1 if method is removed successfully or 0 if an error occurred.

- -

All EVP_PKEY_meth_set and EVP_PKEY_meth_get functions have no return values. For the 'get' functions, function pointers are returned by arguments.

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

The signature of the copy functional argument of EVP_PKEY_meth_set_copy() has changed in OpenSSL 3.0 so its src parameter is now constified.

- -

COPYRIGHT

- -

Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_new.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_new.html deleted file mode 100644 index 716a28d5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_new.html +++ /dev/null @@ -1,146 +0,0 @@ - - - - -EVP_PKEY_new - - - - - - - - - - -

NAME

- -

EVP_PKEY, EVP_PKEY_new, EVP_PKEY_up_ref, EVP_PKEY_dup, EVP_PKEY_free, EVP_PKEY_new_raw_private_key_ex, EVP_PKEY_new_raw_private_key, EVP_PKEY_new_raw_public_key_ex, EVP_PKEY_new_raw_public_key, EVP_PKEY_new_CMAC_key, EVP_PKEY_new_mac_key, EVP_PKEY_get_raw_private_key, EVP_PKEY_get_raw_public_key - public/private key allocation and raw key handling functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-typedef evp_pkey_st EVP_PKEY;
-
-EVP_PKEY *EVP_PKEY_new(void);
-int EVP_PKEY_up_ref(EVP_PKEY *key);
-EVP_PKEY *EVP_PKEY_dup(EVP_PKEY *key);
-void EVP_PKEY_free(EVP_PKEY *key);
-
-EVP_PKEY *EVP_PKEY_new_raw_private_key_ex(OSSL_LIB_CTX *libctx,
-                                          const char *keytype,
-                                          const char *propq,
-                                          const unsigned char *key,
-                                          size_t keylen);
-EVP_PKEY *EVP_PKEY_new_raw_private_key(int type, ENGINE *e,
-                                       const unsigned char *key, size_t keylen);
-EVP_PKEY *EVP_PKEY_new_raw_public_key_ex(OSSL_LIB_CTX *libctx,
-                                         const char *keytype,
-                                         const char *propq,
-                                         const unsigned char *key,
-                                         size_t keylen);
-EVP_PKEY *EVP_PKEY_new_raw_public_key(int type, ENGINE *e,
-                                      const unsigned char *key, size_t keylen);
-EVP_PKEY *EVP_PKEY_new_mac_key(int type, ENGINE *e, const unsigned char *key,
-                               int keylen);
-
-int EVP_PKEY_get_raw_private_key(const EVP_PKEY *pkey, unsigned char *priv,
-                                 size_t *len);
-int EVP_PKEY_get_raw_public_key(const EVP_PKEY *pkey, unsigned char *pub,
-                                size_t *len);
- -

The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
EVP_PKEY *EVP_PKEY_new_CMAC_key(ENGINE *e, const unsigned char *priv,
-                                size_t len, const EVP_CIPHER *cipher);
- -

DESCRIPTION

- -

EVP_PKEY is a generic structure to hold diverse types of asymmetric keys (also known as "key pairs"), and can be used for diverse operations, like signing, verifying signatures, key derivation, etc. The asymmetric keys themselves are often referred to as the "internal key", and are handled by backends, such as providers (through EVP_KEYMGMT(3)) or ENGINEs.

- -

Conceptually, an EVP_PKEY internal key may hold a private key, a public key, or both (a keypair), and along with those, key parameters if the key type requires them. The presence of these components determine what operations can be made; for example, signing normally requires the presence of a private key, and verifying normally requires the presence of a public key.

- -

EVP_PKEY has also been used for MAC algorithm that were conceived as producing signatures, although not being public key algorithms; "POLY1305", "SIPHASH", "HMAC", "CMAC". This usage is considered legacy and is discouraged in favor of the EVP_MAC(3) API.

- -

The EVP_PKEY_new() function allocates an empty EVP_PKEY structure which is used by OpenSSL to store public and private keys. The reference count is set to 1.

- -

EVP_PKEY_up_ref() increments the reference count of key.

- -

EVP_PKEY_dup() duplicates the key. The key must not be ENGINE based or a raw key, otherwise the duplication will fail.

- -

EVP_PKEY_free() decrements the reference count of key and, if the reference count is zero, frees it up. If key is NULL, nothing is done.

- -

EVP_PKEY_new_raw_private_key_ex() allocates a new EVP_PKEY. Unless an engine should be used for the key type, a provider for the key is found using the library context libctx and the property query string propq. The keytype argument indicates what kind of key this is. The value should be a string for a public key algorithm that supports raw private keys, i.e one of "X25519", "ED25519", "X448" or "ED448". key points to the raw private key data for this EVP_PKEY which should be of length keylen. The length should be appropriate for the type of the key. The public key data will be automatically derived from the given private key data (if appropriate for the algorithm type).

- -

EVP_PKEY_new_raw_private_key() does the same as EVP_PKEY_new_raw_private_key_ex() except that the default library context and default property query are used instead. If e is non-NULL then the new EVP_PKEY structure is associated with the engine e. The type argument indicates what kind of key this is. The value should be a NID for a public key algorithm that supports raw private keys, i.e. one of EVP_PKEY_X25519, EVP_PKEY_ED25519, EVP_PKEY_X448 or EVP_PKEY_ED448.

- -

EVP_PKEY_new_raw_private_key_ex() and EVP_PKEY_new_raw_private_key() may also be used with most MACs implemented as public key algorithms, so key types such as "HMAC", "POLY1305", "SIPHASH", or their NID form EVP_PKEY_POLY1305, EVP_PKEY_SIPHASH, EVP_PKEY_HMAC are also accepted. This usage is, as mentioned above, discouraged in favor of the EVP_MAC(3) API.

- -

EVP_PKEY_new_raw_public_key_ex() works in the same way as EVP_PKEY_new_raw_private_key_ex() except that key points to the raw public key data. The EVP_PKEY structure will be initialised without any private key information. Algorithm types that support raw public keys are "X25519", "ED25519", "X448" or "ED448".

- -

EVP_PKEY_new_raw_public_key() works in the same way as EVP_PKEY_new_raw_private_key() except that key points to the raw public key data. The EVP_PKEY structure will be initialised without any private key information. Algorithm types that support raw public keys are EVP_PKEY_X25519, EVP_PKEY_ED25519, EVP_PKEY_X448 or EVP_PKEY_ED448.

- -

EVP_PKEY_new_mac_key() works in the same way as EVP_PKEY_new_raw_private_key(). New applications should use EVP_PKEY_new_raw_private_key() instead.

- -

EVP_PKEY_get_raw_private_key() fills the buffer provided by priv with raw private key data. The size of the priv buffer should be in *len on entry to the function, and on exit *len is updated with the number of bytes actually written. If the buffer priv is NULL then *len is populated with the number of bytes required to hold the key. The calling application is responsible for ensuring that the buffer is large enough to receive the private key data. This function only works for algorithms that support raw private keys. Currently this is: EVP_PKEY_HMAC, EVP_PKEY_POLY1305, EVP_PKEY_SIPHASH, EVP_PKEY_X25519, EVP_PKEY_ED25519, EVP_PKEY_X448 or EVP_PKEY_ED448.

- -

EVP_PKEY_get_raw_public_key() fills the buffer provided by pub with raw public key data. The size of the pub buffer should be in *len on entry to the function, and on exit *len is updated with the number of bytes actually written. If the buffer pub is NULL then *len is populated with the number of bytes required to hold the key. The calling application is responsible for ensuring that the buffer is large enough to receive the public key data. This function only works for algorithms that support raw public keys. Currently this is: EVP_PKEY_X25519, EVP_PKEY_ED25519, EVP_PKEY_X448 or EVP_PKEY_ED448.

- -

EVP_PKEY_new_CMAC_key() works in the same way as EVP_PKEY_new_raw_private_key() except it is only for the EVP_PKEY_CMAC algorithm type. In addition to the raw private key data, it also takes a cipher algorithm to be used during creation of a CMAC in the cipher argument. The cipher should be a standard encryption-only cipher. For example AEAD and XTS ciphers should not be used.

- -

Applications should use the EVP_MAC(3) API instead and set the OSSL_MAC_PARAM_CIPHER parameter on the EVP_MAC_CTX object with the name of the cipher being used.

- -

NOTES

- -

The EVP_PKEY structure is used by various OpenSSL functions which require a general private key without reference to any particular algorithm.

- -

The structure returned by EVP_PKEY_new() is empty. To add a private or public key to this empty structure use the appropriate functions described in EVP_PKEY_set1_RSA(3), EVP_PKEY_set1_DSA(3), EVP_PKEY_set1_DH(3) or EVP_PKEY_set1_EC_KEY(3).

- -

RETURN VALUES

- -

EVP_PKEY_new(), EVP_PKEY_new_raw_private_key(), EVP_PKEY_new_raw_public_key(), EVP_PKEY_new_CMAC_key() and EVP_PKEY_new_mac_key() return either the newly allocated EVP_PKEY structure or NULL if an error occurred.

- -

EVP_PKEY_dup() returns the key duplicate or NULL if an error occurred.

- -

EVP_PKEY_up_ref(), EVP_PKEY_get_raw_private_key() and EVP_PKEY_get_raw_public_key() return 1 for success and 0 for failure.

- -

SEE ALSO

- -

EVP_PKEY_set1_RSA(3), EVP_PKEY_set1_DSA(3), EVP_PKEY_set1_DH(3) or EVP_PKEY_set1_EC_KEY(3)

- -

HISTORY

- -

The EVP_PKEY_new() and EVP_PKEY_free() functions exist in all versions of OpenSSL.

- -

The EVP_PKEY_up_ref() function was added in OpenSSL 1.1.0.

- -

The EVP_PKEY_new_raw_private_key(), EVP_PKEY_new_raw_public_key(), EVP_PKEY_new_CMAC_key(), EVP_PKEY_new_raw_private_key() and EVP_PKEY_get_raw_public_key() functions were added in OpenSSL 1.1.1.

- -

The EVP_PKEY_dup(), EVP_PKEY_new_raw_private_key_ex(), and EVP_PKEY_new_raw_public_key_ex() functions were added in OpenSSL 3.0.

- -

The EVP_PKEY_new_CMAC_key() was deprecated in OpenSSL 3.0.

- -

The documentation of EVP_PKEY was amended in OpenSSL 3.0 to allow there to be the private part of the keypair without the public part, where this was previously implied to be disallowed.

- -

COPYRIGHT

- -

Copyright 2002-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_print_private.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_print_private.html deleted file mode 100644 index aac129c9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_print_private.html +++ /dev/null @@ -1,85 +0,0 @@ - - - - -EVP_PKEY_print_private - - - - - - - - - - -

NAME

- -

EVP_PKEY_print_public, EVP_PKEY_print_private, EVP_PKEY_print_params, EVP_PKEY_print_public_fp, EVP_PKEY_print_private_fp, EVP_PKEY_print_params_fp - public key algorithm printing routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_print_public(BIO *out, const EVP_PKEY *pkey,
-                          int indent, ASN1_PCTX *pctx);
-int EVP_PKEY_print_public_fp(FILE *fp, const EVP_PKEY *pkey,
-                             int indent, ASN1_PCTX *pctx);
-int EVP_PKEY_print_private(BIO *out, const EVP_PKEY *pkey,
-                           int indent, ASN1_PCTX *pctx);
-int EVP_PKEY_print_private_fp(FILE *fp, const EVP_PKEY *pkey,
-                              int indent, ASN1_PCTX *pctx);
-int EVP_PKEY_print_params(BIO *out, const EVP_PKEY *pkey,
-                          int indent, ASN1_PCTX *pctx);
-int EVP_PKEY_print_params_fp(FILE *fp, const EVP_PKEY *pkey,
-                             int indent, ASN1_PCTX *pctx);
- -

DESCRIPTION

- -

The functions EVP_PKEY_print_public(), EVP_PKEY_print_private() and EVP_PKEY_print_params() print out the public, private or parameter components of key pkey respectively. The key is sent to BIO out in human readable form. The parameter indent indicates how far the printout should be indented.

- -

The pctx parameter allows the print output to be finely tuned by using ASN1 printing options. If pctx is set to NULL then default values will be used.

- -

The functions EVP_PKEY_print_public_fp(), EVP_PKEY_print_private_fp() and EVP_PKEY_print_params_fp() do the same as the BIO based functions but use FILE fp instead.

- -

NOTES

- -

Currently no public key algorithms include any options in the pctx parameter.

- -

If the key does not include all the components indicated by the function then only those contained in the key will be printed. For example passing a public key to EVP_PKEY_print_private() will only print the public components.

- -

RETURN VALUES

- -

These functions all return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_keygen(3)

- -

HISTORY

- -

The functions EVP_PKEY_print_public(), EVP_PKEY_print_private(), and EVP_PKEY_print_params() were added in OpenSSL 1.0.0.

- -

The functions EVP_PKEY_print_public_fp(), EVP_PKEY_print_private_fp(), and EVP_PKEY_print_params_fp() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_RSA.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_RSA.html deleted file mode 100644 index 628448a2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_RSA.html +++ /dev/null @@ -1,157 +0,0 @@ - - - - -EVP_PKEY_set1_RSA - - - - - - - - - - -

NAME

- -

EVP_PKEY_set1_RSA, EVP_PKEY_set1_DSA, EVP_PKEY_set1_DH, EVP_PKEY_set1_EC_KEY, EVP_PKEY_get1_RSA, EVP_PKEY_get1_DSA, EVP_PKEY_get1_DH, EVP_PKEY_get1_EC_KEY, EVP_PKEY_get0_RSA, EVP_PKEY_get0_DSA, EVP_PKEY_get0_DH, EVP_PKEY_get0_EC_KEY, EVP_PKEY_assign_RSA, EVP_PKEY_assign_DSA, EVP_PKEY_assign_DH, EVP_PKEY_assign_EC_KEY, EVP_PKEY_assign_POLY1305, EVP_PKEY_assign_SIPHASH, EVP_PKEY_get0_hmac, EVP_PKEY_get0_poly1305, EVP_PKEY_get0_siphash, EVP_PKEY_get0, EVP_PKEY_type, EVP_PKEY_get_id, EVP_PKEY_get_base_id, EVP_PKEY_set1_engine, EVP_PKEY_get0_engine, EVP_PKEY_id, EVP_PKEY_base_id - EVP_PKEY assignment functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_get_id(const EVP_PKEY *pkey);
-int EVP_PKEY_get_base_id(const EVP_PKEY *pkey);
-int EVP_PKEY_type(int type);
-
-#define EVP_PKEY_id EVP_PKEY_get_id
-#define EVP_PKEY_base_id EVP_PKEY_get_base_id
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int EVP_PKEY_set1_RSA(EVP_PKEY *pkey, RSA *key);
-int EVP_PKEY_set1_DSA(EVP_PKEY *pkey, DSA *key);
-int EVP_PKEY_set1_DH(EVP_PKEY *pkey, DH *key);
-int EVP_PKEY_set1_EC_KEY(EVP_PKEY *pkey, EC_KEY *key);
-
-RSA *EVP_PKEY_get1_RSA(EVP_PKEY *pkey);
-DSA *EVP_PKEY_get1_DSA(EVP_PKEY *pkey);
-DH *EVP_PKEY_get1_DH(EVP_PKEY *pkey);
-EC_KEY *EVP_PKEY_get1_EC_KEY(EVP_PKEY *pkey);
-
-const unsigned char *EVP_PKEY_get0_hmac(const EVP_PKEY *pkey, size_t *len);
-const unsigned char *EVP_PKEY_get0_poly1305(const EVP_PKEY *pkey, size_t *len);
-const unsigned char *EVP_PKEY_get0_siphash(const EVP_PKEY *pkey, size_t *len);
-const RSA *EVP_PKEY_get0_RSA(const EVP_PKEY *pkey);
-const DSA *EVP_PKEY_get0_DSA(const EVP_PKEY *pkey);
-const DH *EVP_PKEY_get0_DH(const EVP_PKEY *pkey);
-const EC_KEY *EVP_PKEY_get0_EC_KEY(const EVP_PKEY *pkey);
-void *EVP_PKEY_get0(const EVP_PKEY *pkey);
-
-int EVP_PKEY_assign_RSA(EVP_PKEY *pkey, RSA *key);
-int EVP_PKEY_assign_DSA(EVP_PKEY *pkey, DSA *key);
-int EVP_PKEY_assign_DH(EVP_PKEY *pkey, DH *key);
-int EVP_PKEY_assign_EC_KEY(EVP_PKEY *pkey, EC_KEY *key);
-int EVP_PKEY_assign_POLY1305(EVP_PKEY *pkey, ASN1_OCTET_STRING *key);
-int EVP_PKEY_assign_SIPHASH(EVP_PKEY *pkey, ASN1_OCTET_STRING *key);
-
-ENGINE *EVP_PKEY_get0_engine(const EVP_PKEY *pkey);
-int EVP_PKEY_set1_engine(EVP_PKEY *pkey, ENGINE *engine);
- -

DESCRIPTION

- -

EVP_PKEY_get_base_id() returns the type of pkey. For example an RSA key will return EVP_PKEY_RSA.

- -

EVP_PKEY_get_id() returns the actual NID associated with pkey only if the pkey type isn't implemented just in a provider(7). Historically keys using the same algorithm could use different NIDs. For example an RSA key could use the NIDs corresponding to the NIDs NID_rsaEncryption (equivalent to EVP_PKEY_RSA) or NID_rsa (equivalent to EVP_PKEY_RSA2). The use of alternative non-standard NIDs is now rare so EVP_PKEY_RSA2 et al are not often seen in practice. EVP_PKEY_get_id() returns -1 (EVP_PKEY_KEYMGMT) if the pkey is only implemented in a provider(7).

- -

EVP_PKEY_type() returns the underlying type of the NID type. For example EVP_PKEY_type(EVP_PKEY_RSA2) will return EVP_PKEY_RSA.

- -

EVP_PKEY_set1_RSA(), EVP_PKEY_set1_DSA(), EVP_PKEY_set1_DH() and EVP_PKEY_set1_EC_KEY() set the key referenced by pkey to key. These functions are deprecated. Applications should instead use EVP_PKEY_fromdata(3).

- -

EVP_PKEY_assign_RSA(), EVP_PKEY_assign_DSA(), EVP_PKEY_assign_DH(), EVP_PKEY_assign_EC_KEY(), EVP_PKEY_assign_POLY1305() and EVP_PKEY_assign_SIPHASH() set the referenced key to key however these use the supplied key internally and so key will be freed when the parent pkey is freed. These macros are deprecated. Applications should instead read an EVP_PKEY directly using the OSSL_DECODER APIs (see OSSL_DECODER_CTX_new_for_pkey(3)), or construct an EVP_PKEY from data using EVP_PKEY_fromdata(3).

- -

EVP_PKEY_get1_RSA(), EVP_PKEY_get1_DSA(), EVP_PKEY_get1_DH() and EVP_PKEY_get1_EC_KEY() return the referenced key in pkey or NULL if the key is not of the correct type. The returned key must be freed after use. These functions are deprecated. Applications should instead use the EVP_PKEY directly where possible. If access to the low level key parameters is required then applications should use EVP_PKEY_get_params(3) and other similar functions. To write an EVP_PKEY out use the OSSL_ENCODER APIs (see OSSL_ENCODER_CTX_new_for_pkey(3)).

- -

EVP_PKEY_get0_hmac(), EVP_PKEY_get0_poly1305(), EVP_PKEY_get0_siphash(), EVP_PKEY_get0_RSA(), EVP_PKEY_get0_DSA(), EVP_PKEY_get0_DH() and EVP_PKEY_get0_EC_KEY() return the referenced key in pkey or NULL if the key is not of the correct type. The reference count of the returned key is not incremented and so the key must not be freed after use. These functions are deprecated. Applications should instead use the EVP_PKEY directly where possible. If access to the low level key parameters is required then applications should use EVP_PKEY_get_params(3) and other similar functions. To write an EVP_PKEY out use the OSSL_ENCODER APIs (see OSSL_ENCODER_CTX_new_for_pkey(3)). EVP_PKEY_get0() returns a pointer to the legacy key or NULL if the key is not legacy.

- -

Note that if an EVP_PKEY was not constructed using one of the deprecated functions such as EVP_PKEY_set1_RSA(), EVP_PKEY_set1_DSA(), EVP_PKEY_set1_DH() or EVP_PKEY_set1_EC_KEY(), or via the similarly named EVP_PKEY_assign macros described above then the internal key will be managed by a provider (see provider(7)). In that case the key returned by EVP_PKEY_get1_RSA(), EVP_PKEY_get1_DSA(), EVP_PKEY_get1_DH(), EVP_PKEY_get1_EC_KEY(), EVP_PKEY_get0_hmac(), EVP_PKEY_get0_poly1305(), EVP_PKEY_get0_siphash(), EVP_PKEY_get0_RSA(), EVP_PKEY_get0_DSA(), EVP_PKEY_get0_DH() or EVP_PKEY_get0_EC_KEY() will be a cached copy of the provider's key. Subsequent updates to the provider's key will not be reflected back in the cached copy, and updates made by an application to the returned key will not be reflected back in the provider's key. Subsequent calls to EVP_PKEY_get1_RSA(), EVP_PKEY_get1_DSA(), EVP_PKEY_get1_DH() and EVP_PKEY_get1_EC_KEY() will always return the cached copy returned by the first call.

- -

EVP_PKEY_get0_engine() returns a reference to the ENGINE handling pkey. This function is deprecated. Applications should use providers instead of engines (see provider(7) for details).

- -

EVP_PKEY_set1_engine() sets the ENGINE handling pkey to engine. It must be called after the key algorithm and components are set up. If engine does not include an EVP_PKEY_METHOD for pkey an error occurs. This function is deprecated. Applications should use providers instead of engines (see provider(7) for details).

- -

WARNINGS

- -

The following functions are only reliable with EVP_PKEYs that have been assigned an internal key with EVP_PKEY_assign_*():

- -

EVP_PKEY_get_id(), EVP_PKEY_get_base_id(), EVP_PKEY_type()

- -

For EVP_PKEY key type checking purposes, EVP_PKEY_is_a(3) is more generic.

- -

For purposes of retrieving the name of the EVP_PKEY the function EVP_PKEY_get0_type_name(3) is more generally useful.

- -

The keys returned from the functions EVP_PKEY_get0_RSA(), EVP_PKEY_get0_DSA(), EVP_PKEY_get0_DH() and EVP_PKEY_get0_EC_KEY() were changed to have a "const" return type in OpenSSL 3.0. As described above the keys returned may be cached copies of the key held in a provider. Due to this, and unlike in earlier versions of OpenSSL, they should be considered read-only copies of the key. Updates to these keys will not be reflected back in the provider side key. The EVP_PKEY_get1_RSA(), EVP_PKEY_get1_DSA(), EVP_PKEY_get1_DH() and EVP_PKEY_get1_EC_KEY() functions were not changed to have a "const" return type in order that applications can "free" the return value. However applications should still consider them as read-only copies.

- -

NOTES

- -

In accordance with the OpenSSL naming convention the key obtained from or assigned to the pkey using the 1 functions must be freed as well as pkey.

- -

EVP_PKEY_assign_RSA(), EVP_PKEY_assign_DSA(), EVP_PKEY_assign_DH(), EVP_PKEY_assign_EC_KEY(), EVP_PKEY_assign_POLY1305() and EVP_PKEY_assign_SIPHASH() are implemented as macros.

- -

EVP_PKEY_assign_EC_KEY() looks at the curve name id to determine if the passed EC_KEY is an SM2(7) key, and will set the EVP_PKEY type to EVP_PKEY_SM2 in that case, instead of EVP_PKEY_EC.

- -

Most applications wishing to know a key type will simply call EVP_PKEY_get_base_id() and will not care about the actual type: which will be identical in almost all cases.

- -

Previous versions of this document suggested using EVP_PKEY_type(pkey->type) to determine the type of a key. Since EVP_PKEY is now opaque this is no longer possible: the equivalent is EVP_PKEY_get_base_id(pkey).

- -

EVP_PKEY_set1_engine() is typically used by an ENGINE returning an HSM key as part of its routine to load a private key.

- -

RETURN VALUES

- -

EVP_PKEY_set1_RSA(), EVP_PKEY_set1_DSA(), EVP_PKEY_set1_DH() and EVP_PKEY_set1_EC_KEY() return 1 for success or 0 for failure.

- -

EVP_PKEY_get1_RSA(), EVP_PKEY_get1_DSA(), EVP_PKEY_get1_DH() and EVP_PKEY_get1_EC_KEY() return the referenced key or NULL if an error occurred.

- -

EVP_PKEY_assign_RSA(), EVP_PKEY_assign_DSA(), EVP_PKEY_assign_DH(), EVP_PKEY_assign_EC_KEY(), EVP_PKEY_assign_POLY1305() and EVP_PKEY_assign_SIPHASH() return 1 for success and 0 for failure.

- -

EVP_PKEY_get_base_id(), EVP_PKEY_get_id() and EVP_PKEY_type() return a key type or NID_undef (equivalently EVP_PKEY_NONE) on error.

- -

EVP_PKEY_set1_engine() returns 1 for success and 0 for failure.

- -

SEE ALSO

- -

EVP_PKEY_new(3), SM2(7)

- -

HISTORY

- -

The EVP_PKEY_id() and EVP_PKEY_base_id() functions were renamed to include get in their names in OpenSSL 3.0, respectively. The old names are kept as non-deprecated alias macros.

- -

EVP_PKEY_set1_RSA, EVP_PKEY_set1_DSA, EVP_PKEY_set1_DH, EVP_PKEY_set1_EC_KEY, EVP_PKEY_get1_RSA, EVP_PKEY_get1_DSA, EVP_PKEY_get1_DH, EVP_PKEY_get1_EC_KEY, EVP_PKEY_get0_RSA, EVP_PKEY_get0_DSA, EVP_PKEY_get0_DH, EVP_PKEY_get0_EC_KEY, EVP_PKEY_assign_RSA, EVP_PKEY_assign_DSA, EVP_PKEY_assign_DH, EVP_PKEY_assign_EC_KEY, EVP_PKEY_assign_POLY1305, EVP_PKEY_assign_SIPHASH, EVP_PKEY_get0_hmac, EVP_PKEY_get0_poly1305, EVP_PKEY_get0_siphash, EVP_PKEY_set1_engine and EVP_PKEY_get0_engine were deprecated in OpenSSL 3.0.

- -

The return value from EVP_PKEY_get0_RSA, EVP_PKEY_get0_DSA, EVP_PKEY_get0_DH, EVP_PKEY_get0_EC_KEY were made const in OpenSSL 3.0.

- -

The function EVP_PKEY_set_alias_type() was previously documented on this page. It was removed in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_encoded_public_key.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_encoded_public_key.html deleted file mode 100644 index 777656fe..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set1_encoded_public_key.html +++ /dev/null @@ -1,139 +0,0 @@ - - - - -EVP_PKEY_set1_encoded_public_key - - - - - - - - - - -

NAME

- -

EVP_PKEY_set1_encoded_public_key, EVP_PKEY_get1_encoded_public_key, EVP_PKEY_set1_tls_encodedpoint, EVP_PKEY_get1_tls_encodedpoint - functions to set and get public key data within an EVP_PKEY

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_set1_encoded_public_key(EVP_PKEY *pkey,
-                                     const unsigned char *pub, size_t publen);
-
-size_t EVP_PKEY_get1_encoded_public_key(EVP_PKEY *pkey, unsigned char **ppub);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int EVP_PKEY_set1_tls_encodedpoint(EVP_PKEY *pkey,
-                                   const unsigned char *pt, size_t ptlen);
-
-size_t EVP_PKEY_get1_tls_encodedpoint(EVP_PKEY *pkey, unsigned char **ppt);
- -

DESCRIPTION

- -

EVP_PKEY_set1_encoded_public_key() can be used to set the public key value within an existing EVP_PKEY object. For the built-in OpenSSL algorithms this currently only works for those that support key exchange. Parameters are not set as part of this operation, so typically an application will create an EVP_PKEY first, set the parameters on it, and then call this function. For example setting the parameters might be done using EVP_PKEY_copy_parameters(3).

- -

The format for the encoded public key will depend on the algorithm in use. For DH it should be encoded as a positive integer in big-endian form. For EC is should be a point conforming to Sec. 2.3.4 of the SECG SEC 1 ("Elliptic Curve Cryptography") standard. For X25519 and X448 it should be encoded in a format as defined by RFC7748.

- -

The key to be updated is supplied in pkey. The buffer containing the encoded key is pointed to be pub. The length of the buffer is supplied in publen.

- -

EVP_PKEY_get1_encoded_public_key() does the equivalent operation except that the encoded public key is returned to the application. The key containing the public key data is supplied in pkey. A buffer containing the encoded key will be allocated and stored in *ppub. The length of the encoded public key is returned by the function. The application is responsible for freeing the allocated buffer.

- -

The macro EVP_PKEY_set1_tls_encodedpoint() is deprecated and simply calls EVP_PKEY_set1_encoded_public_key() with all the same arguments. New applications should use EVP_PKEY_set1_encoded_public_key() instead.

- -

The macro EVP_PKEY_get1_tls_encodedpoint() is deprecated and simply calls EVP_PKEY_get1_encoded_public_key() with all the same arguments. New applications should use EVP_PKEY_get1_encoded_public_key() instead.

- -

RETURN VALUES

- -

EVP_PKEY_set1_encoded_public_key() returns 1 for success and 0 or a negative value for failure.

- -

EVP_PKEY_get1_encoded_public_key() returns the length of the encoded key or 0 for failure.

- -

EXAMPLES

- -

See EVP_PKEY_derive_init(3) and EVP_PKEY_derive(3) for information about performing a key exchange operation.

- -

Set up a peer's EVP_PKEY ready for a key exchange operation

- -
#include <openssl/evp.h>
-
-int exchange(EVP_PKEY *ourkey, unsigned char *peer_pub, size_t peer_pub_len)
-{
-    EVP_PKEY *peerkey = EVP_PKEY_new();
-
-    if (peerkey == NULL || EVP_PKEY_copy_parameters(peerkey, ourkey) <= 0)
-        return 0;
-
-    if (EVP_PKEY_set1_encoded_public_key(peerkey, peer_pub,
-                                         peer_pub_len) <= 0)
-        return 0;
-
-    /* Do the key exchange here */
-
-    EVP_PKEY_free(peerkey);
-
-    return 1;
-}
- -

Get an encoded public key to send to a peer

- -
#include <openssl/evp.h>
-
-int get_encoded_pub_key(EVP_PKEY *ourkey)
-{
-    unsigned char *pubkey;
-    size_t pubkey_len;
-
-   pubkey_len = EVP_PKEY_get1_encoded_public_key(ourkey, &pubkey);
-   if (pubkey_len == 0)
-       return 0;
-
-   /*
-    * Send the encoded public key stored in the buffer at "pubkey" and of
-    * length pubkey_len, to the peer.
-    */
-
-   OPENSSL_free(pubkey);
-   return 1;
-}
- -

SEE ALSO

- -

EVP_PKEY_new(3), EVP_PKEY_copy_parameters(3), EVP_PKEY_derive_init(3), EVP_PKEY_derive(3), EVP_PKEY-DH(7), EVP_PKEY-EC(7), EVP_PKEY-X25519(7), EVP_PKEY-X448(7)

- -

HISTORY

- -

EVP_PKEY_set1_encoded_public_key() and EVP_PKEY_get1_encoded_public_key() were added in OpenSSL 3.0.

- -

EVP_PKEY_set1_tls_encodedpoint() and EVP_PKEY_get1_tls_encodedpoint() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set_type.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set_type.html deleted file mode 100644 index 9a8e0674..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_set_type.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -EVP_PKEY_set_type - - - - - - - - - - -

NAME

- -

EVP_PKEY_set_type, EVP_PKEY_set_type_str, EVP_PKEY_set_type_by_keymgmt - functions to change the EVP_PKEY type

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_set_type(EVP_PKEY *pkey, int type);
-int EVP_PKEY_set_type_str(EVP_PKEY *pkey, const char *str, int len);
-int EVP_PKEY_set_type_by_keymgmt(EVP_PKEY *pkey, EVP_KEYMGMT *keymgmt);
- -

DESCRIPTION

- -

All the functions described here behave the same in so far that they clear all the previous key data and methods from pkey, and reset it to be of the type of key given by the different arguments. If pkey is NULL, these functions will still return the same return values as if it wasn't.

- -

EVP_PKEY_set_type() initialises pkey to contain an internal legacy key. When doing this, it finds a EVP_PKEY_ASN1_METHOD(3) corresponding to type, and associates pkey with the findings. It is an error if no EVP_PKEY_ASN1_METHOD(3) could be found for type.

- -

EVP_PKEY_set_type_str() initialises pkey to contain an internal legacy key. When doing this, it finds a EVP_PKEY_ASN1_METHOD(3) corresponding to str that has then length len, and associates pkey with the findings. It is an error if no EVP_PKEY_ASN1_METHOD(3) could be found for type.

- -

For both EVP_PKEY_set_type() and EVP_PKEY_set_type_str(), pkey gets a numeric type, which can be retrieved with EVP_PKEY_get_id(3). This numeric type is taken from the EVP_PKEY_ASN1_METHOD(3) that was found, and is equal to or closely related to type in the case of EVP_PKEY_set_type(), or related to str in the case of EVP_PKEY_set_type_str().

- -

EVP_PKEY_set_type_by_keymgmt() initialises pkey to contain an internal provider side key. When doing this, it associates pkey with keymgmt. For keys initialised like this, the numeric type retrieved with EVP_PKEY_get_id(3) will always be EVP_PKEY_NONE.

- -

RETURN VALUES

- -

All functions described here return 1 if successful, or 0 on error.

- -

SEE ALSO

- -

EVP_PKEY_assign(3), EVP_PKEY_get_id(3), EVP_PKEY_get0_RSA(3), EVP_PKEY_copy_parameters(3), EVP_PKEY_ASN1_METHOD(3), EVP_KEYMGMT(3)

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_settable_params.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_settable_params.html deleted file mode 100644 index 37bd0ac3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_settable_params.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -EVP_PKEY_settable_params - - - - - - - - - - -

NAME

- -

EVP_PKEY_settable_params, EVP_PKEY_set_params, EVP_PKEY_set_int_param, EVP_PKEY_set_size_t_param, EVP_PKEY_set_bn_param, EVP_PKEY_set_utf8_string_param, EVP_PKEY_set_octet_string_param - set key parameters into a key

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const OSSL_PARAM *EVP_PKEY_settable_params(const EVP_PKEY *pkey);
-int EVP_PKEY_set_params(EVP_PKEY *pkey, OSSL_PARAM params[]);
-int EVP_PKEY_set_int_param(EVP_PKEY *pkey, const char *key_name, int in);
-int EVP_PKEY_set_size_t_param(EVP_PKEY *pkey, const char *key_name, size_t in);
-int EVP_PKEY_set_bn_param(EVP_PKEY *pkey, const char *key_name,
-                          const BIGNUM *bn);
-int EVP_PKEY_set_utf8_string_param(EVP_PKEY *pkey, const char *key_name,
-                                   const char *str);
-int EVP_PKEY_set_octet_string_param(EVP_PKEY *pkey, const char *key_name,
-                                    const unsigned char *buf, size_t bsize);
- -

DESCRIPTION

- -

These functions can be used to set additional parameters into an existing EVP_PKEY.

- -

EVP_PKEY_set_params() sets one or more params into a pkey. See OSSL_PARAM(3) for information about parameters.

- -

EVP_PKEY_settable_params() returns a constant list of params indicating the names and types of key parameters that can be set. See OSSL_PARAM(3) for information about parameters.

- -

EVP_PKEY_set_int_param() sets an integer value in into a key pkey for the associated field key_name.

- -

EVP_PKEY_set_size_t_param() sets an size_t value in into a key pkey for the associated field key_name.

- -

EVP_PKEY_set_bn_param() sets the BIGNUM value bn into a key pkey for the associated field key_name.

- -

EVP_PKEY_set_utf8_string_param() sets the UTF8 string str into a key pkey for the associated field key_name.

- -

EVP_PKEY_set_octet_string_param() sets the octet string value buf with a size bsize into a key pkey for the associated field key_name.

- -

NOTES

- -

These functions only work for EVP_PKEYs that contain a provider side key.

- -

RETURN VALUES

- -

EVP_PKEY_settable_params() returns NULL on error or if it is not supported,

- -

All other methods return 1 if a value was successfully set, or 0 if there was an error.

- -

SEE ALSO

- -

EVP_PKEY_gettable_params(3), EVP_PKEY_CTX_new(3), provider-keymgmt(7), OSSL_PARAM(3),

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_sign.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_sign.html deleted file mode 100644 index 0a2a8ca6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_sign.html +++ /dev/null @@ -1,304 +0,0 @@ - - - - -EVP_PKEY_sign - - - - - - - - - - -

NAME

- -

EVP_PKEY_sign_init, EVP_PKEY_sign_init_ex, EVP_PKEY_sign_init_ex2, EVP_PKEY_sign, EVP_PKEY_sign_message_init, EVP_PKEY_sign_message_update, EVP_PKEY_sign_message_final - sign using a public key algorithm

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_sign_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_sign_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_PKEY_sign_init_ex2(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo,
-                           const OSSL_PARAM params[]);
-int EVP_PKEY_sign_message_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo,
-                               const OSSL_PARAM params[]);
-int EVP_PKEY_sign_message_update(EVP_PKEY_CTX *ctx,
-                                 unsigned char *in, size_t inlen);
-int EVP_PKEY_sign_message_final(EVP_PKEY_CTX *ctx, unsigned char *sig,
-                                size_t *siglen, size_t sigsize);
-int EVP_PKEY_sign(EVP_PKEY_CTX *ctx,
-                  unsigned char *sig, size_t *siglen,
-                  const unsigned char *tbs, size_t tbslen);
- -

DESCRIPTION

- -

EVP_PKEY_sign_init() initializes a public key algorithm context ctx for signing using the algorithm given when the context was created using EVP_PKEY_CTX_new(3) or variants thereof. The algorithm is used to fetch a EVP_SIGNATURE method implicitly, see "Implicit fetch" in provider(7) for more information about implicit fetches.

- -

EVP_PKEY_sign_init_ex() is the same as EVP_PKEY_sign_init() but additionally sets the passed parameters params on the context before returning.

- -

EVP_PKEY_sign_init_ex2() initializes a public key algorithm context ctx for signing a pre-computed message digest using the algorithm given by algo and the key given through EVP_PKEY_CTX_new(3) or EVP_PKEY_CTX_new_from_pkey(3). A context ctx without a pre-loaded key cannot be used with this function. This function provides almost the same functionality as EVP_PKEY_sign_init_ex(), but is uniquely intended to be used with a pre-computed messsage digest, and allows pre-determining the exact conditions for that message digest, if a composite signature algorithm (such as RSA-SHA256) was fetched. Following a call to this function, setting parameters that modifies the digest implementation or padding is not normally supported.

- -

EVP_PKEY_sign_message_init() initializes a public key algorithm context ctx for signing an unlimited size message using the algorithm given by algo and the key given through EVP_PKEY_CTX_new(3) or EVP_PKEY_CTX_new_from_pkey(3). Passing the message is supported both in a one-shot fashion using EVP_PKEY_sign(), and through the combination of EVP_PKEY_sign_message_update() and EVP_PKEY_sign_message_final(). This function enables using algorithms that can process input of arbitrary length, such as ED25519, RSA-SHA256 and similar.

- -

EVP_PKEY_sign_message_update() adds inlen bytes from in to the data to be processed for signature. The signature algorithm specification and implementation determine how the input bytes are processed and if there's a limit on the total size of the input. See "NOTES" below for a deeper explanation.

- -

EVP_PKEY_sign_message_final() signs the processed data and places the data in sig, and the number of signature bytes in *siglen, if the number of bytes doesn't surpass the size given by sigsize. sig may be NULL, and in that case, only *siglen is updated with the number of signature bytes.

- -

EVP_PKEY_sign() is a one-shot function that can be used with all the init functions above. When initialization was done with EVP_PKEY_sign_init(), EVP_PKEY_sign_init_ex() or EVP_PKEY_sign_init_ex2(), the data specified by tbs and tbslen is signed after appropriate padding. When initialization was done with EVP_PKEY_sign_message_init(), the data specified by tbs and tbslen is digested by the implied message digest algorithm, and the result is signed after appropriate padding. If sig is NULL then the maximum size of the output buffer is written to the siglen parameter. If sig is not NULL, then before the call the siglen parameter should contain the length of the sig buffer, and if the call is successful the signature is written to sig and the amount of data written to siglen.

- -

NOTES

- -

General

- -

Some signature implementations only accumulate the input data and do no further processing before signing it (they expect the input to be a digest), while others compress the data, typically by internally producing a digest, and signing the result. Some of them support both modes of operation at the same time. The caller is expected to know how the chosen algorithm is supposed to behave and under what conditions.

- -

For example, an RSA implementation can be expected to only expect a message digest as input, while ED25519 can be expected to process the input with a hash, i.e. to produce the message digest internally, and while RSA-SHA256 can be expected to handle either mode of operation, depending on if the operation was initialized with EVP_PKEY_sign_init_ex2() or with EVP_PKEY_sign_message_init().

- -

Similarly, an RSA implementation usually expects additional details to be set, like the message digest algorithm that the input is supposed to be digested with, as well as the padding mode (see EVP_PKEY_CTX_set_signature_md(3) and EVP_PKEY_CTX_set_rsa_padding(3) and similar others), while an RSA-SHA256 implementation usually has these details pre-set and immutable.

- -

The functions described here can't be used to combine separate algorithms. In particular, neither EVP_PKEY_CTX_set_signature_md(3) nor the OSSL_PARAM parameter "digest" (OSSL_SIGNATURE_PARAM_DIGEST) can be used to combine a signature algorithm with a hash algorithm to process the input. In other words, it's not possible to specify a ctx pre-loaded with an RSA pkey, or an algo that fetched RSA and try to specify SHA256 separately to get the functionality of RSA-SHA256. If combining algorithms in that manner is desired, please use EVP_DigestSignInit(3) and associated functions.

- -

Performing multiple signatures

- -

When initialized using EVP_PKEY_sign_init_ex() or EVP_PKEY_sign_init_ex2(), EVP_PKEY_sign() can be called more than once on the same context to have several one-shot operations performed using the same parameters.

- -

When initialized using EVP_PKEY_sign_message_init(), it's not possible to call EVP_PKEY_sign() multiple times.

- -

RETURN VALUES

- -

All functions return 1 for success and 0 or a negative value for failure.

- -

In particular, EVP_PKEY_sign_init() and its other variants may return -2 to indicate that the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

RSA with PKCS#1 padding for SHA256

- -

Sign data using RSA with PKCS#1 padding and a SHA256 digest as input:

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-/* md is a SHA-256 digest in this example. */
-unsigned char *md, *sig;
-size_t mdlen = 32, siglen;
-EVP_PKEY *signing_key;
-
-/*
- * NB: assumes signing_key and md are set up before the next
- * step. signing_key must be an RSA private key and md must
- * point to the SHA-256 digest to be signed.
- */
-ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */);
-if (ctx == NULL)
-    /* Error occurred */
-if (EVP_PKEY_sign_init(ctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_PADDING) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_signature_md(ctx, EVP_sha256()) <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_sign(ctx, NULL, &siglen, md, mdlen) <= 0)
-    /* Error */
-
-sig = OPENSSL_malloc(siglen);
-
-if (sig == NULL)
-    /* malloc failure */
-
-if (EVP_PKEY_sign(ctx, sig, &siglen, md, mdlen) <= 0)
-    /* Error */
-
-/* Signature is siglen bytes written to buffer sig */
- -

RSA-SHA256 with a pre-computed digest

- -

Sign a digest with RSA-SHA256 using one-shot functions. To be noted is that RSA-SHA256 is assumed to be an implementation of sha256WithRSAEncryption, for which the padding is pre-determined to be RSA_PKCS1_PADDING, and the input digest is assumed to have been computed using SHA256.

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-/* md is a SHA-256 digest in this example. */
-unsigned char *md, *sig;
-size_t mdlen = 32, siglen;
-EVP_PKEY *signing_key;
-
-/*
- * NB: assumes signing_key and md are set up before the next
- * step. signing_key must be an RSA private key and md must
- * point to the SHA-256 digest to be signed.
- */
-ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */);
-alg = EVP_SIGNATURE_fetch(NULL, "RSA-SHA256", NULL);
-
-if (ctx == NULL)
-    /* Error occurred */
-if (EVP_PKEY_sign_init_ex2(ctx, alg, NULL) <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_sign(ctx, NULL, &siglen, md, mdlen) <= 0)
-    /* Error */
-
-sig = OPENSSL_malloc(siglen);
-
-if (sig == NULL)
-    /* malloc failure */
-
-if (EVP_PKEY_sign(ctx, sig, &siglen, md, mdlen) <= 0)
-    /* Error */
-
-/* Signature is siglen bytes written to buffer sig */
- -

RSA-SHA256, one-shot

- -

Sign a document with RSA-SHA256 using one-shot functions. To be noted is that RSA-SHA256 is assumed to be an implementation of sha256WithRSAEncryption, for which the padding is pre-determined to be RSA_PKCS1_PADDING.

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-/* in is the input in this example. */
-unsigned char *in, *sig;
-/* inlen is the length of the input in this example. */
-size_t inlen, siglen;
-EVP_PKEY *signing_key;
-EVP_SIGNATURE *alg;
-
-/*
- * NB: assumes signing_key, in and inlen are set up before
- * the next step. signing_key must be an RSA private key,
- * in must point to data to be digested and signed, and
- * inlen must be the size of the data in bytes.
- */
-ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */);
-alg = EVP_SIGNATURE_fetch(NULL, "RSA-SHA256", NULL);
-
-if (ctx == NULL || alg == NULL)
-    /* Error occurred */
-if (EVP_PKEY_sign_message_init(ctx, alg, NULL) <= 0)
-    /* Error */
-
-/* Determine sig buffer length */
-if (EVP_PKEY_sign(ctx, NULL, &siglen, in, inlen) <= 0)
-    /* Error */
-
-sig = OPENSSL_malloc(siglen);
-
-if (sig == NULL)
-    /* malloc failure */
-
-if (EVP_PKEY_sign(ctx, sig, &siglen, in, inlen) <= 0)
-    /* Error */
-
-/* Signature is siglen bytes written to buffer sig */
- -

RSA-SHA256, using update and final

- -

This is the same as the previous example, but allowing stream-like functionality.

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-/* in is the input in this example. */
-unsigned char *in, *sig;
-/* inlen is the length of the input in this example. */
-size_t inlen, siglen;
-EVP_PKEY *signing_key;
-EVP_SIGNATURE *alg;
-
-/*
- * NB: assumes signing_key, in and inlen are set up before
- * the next step. signing_key must be an RSA private key,
- * in must point to data to be digested and signed, and
- * inlen must be the size of the data in bytes.
- */
-ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */);
-alg = EVP_SIGNATURE_fetch(NULL, "RSA-SHA256", NULL);
-
-if (ctx == NULL || alg == NULL)
-    /* Error occurred */
-if (EVP_PKEY_sign_message_init(ctx, alg, NULL) <= 0)
-    /* Error */
-
-while (inlen > 0) {
-    if (EVP_PKEY_sign_message_update(ctx, in, inlen)) <= 0)
-        /* Error */
-    if (inlen > 256) {
-        inlen -= 256;
-        in += 256;
-    } else {
-        inlen = 0;
-    }
-}
-
-/* Determine sig buffer length */
-if (EVP_PKEY_sign_message_final(ctx, NULL, &siglen) <= 0)
-    /* Error */
-
-sig = OPENSSL_malloc(siglen);
-
-if (sig == NULL)
-    /* malloc failure */
-
-if (EVP_PKEY_sign_message_final(ctx, sig, &siglen) <= 0)
-    /* Error */
-
-/* Signature is siglen bytes written to buffer sig */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_ctrl(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

The EVP_PKEY_sign_init() and EVP_PKEY_sign() functions were added in OpenSSL 1.0.0.

- -

The EVP_PKEY_sign_init_ex() function was added in OpenSSL 3.0.

- -

The EVP_PKEY_sign_init_ex2(), EVP_PKEY_sign_message_init(), EVP_PKEY_sign_message_update() and EVP_PKEY_sign_message_final() functions where added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_todata.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_todata.html deleted file mode 100644 index 7c6dfe17..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_todata.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -EVP_PKEY_todata - - - - - - - - - - -

NAME

- -

EVP_PKEY_todata, EVP_PKEY_export - functions to return keys as an array of key parameters

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_todata(const EVP_PKEY *pkey, int selection, OSSL_PARAM **params);
-int EVP_PKEY_export(const EVP_PKEY *pkey, int selection,
-                    OSSL_CALLBACK *export_cb, void *export_cbarg);
- -

DESCRIPTION

- -

The functions described here are used to extract EVP_PKEY key values as an array of OSSL_PARAM(3).

- -

EVP_PKEY_todata() extracts values from a key pkey using the selection. selection is described in "Selections" in EVP_PKEY_fromdata(3). OSSL_PARAM_free(3) should be used to free the returned parameters in *params.

- -

EVP_PKEY_export() is similar to EVP_PKEY_todata() but uses a callback export_cb that gets passed the value of export_cbarg. See openssl-core.h(7) for more information about the callback. Note that the OSSL_PARAM(3) array that is passed to the callback is not persistent after the callback returns. The user must preserve the items of interest, or use EVP_PKEY_todata() if persistence is required.

- -

NOTES

- -

These functions only work with key management methods coming from a provider. This is the mirror function to EVP_PKEY_fromdata(3).

- -

RETURN VALUES

- -

EVP_PKEY_todata() and EVP_PKEY_export() return 1 for success and 0 for failure.

- -

SEE ALSO

- -

OSSL_PARAM(3), openssl-core.h(7), EVP_PKEY_fromdata(3), EVP_PKEY-RSA(7), EVP_PKEY-DSA(7), EVP_PKEY-DH(7), EVP_PKEY-EC(7), EVP_PKEY-ED448(7), EVP_PKEY-X25519(7), EVP_PKEY-X448(7), EVP_PKEY-ED25519(7)

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify.html deleted file mode 100644 index 040dbfc1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify.html +++ /dev/null @@ -1,291 +0,0 @@ - - - - -EVP_PKEY_verify - - - - - - - - - - -

NAME

- -

EVP_PKEY_verify_init, EVP_PKEY_verify_init_ex, EVP_PKEY_verify_init_ex2, EVP_PKEY_verify, EVP_PKEY_verify_message_init, EVP_PKEY_verify_message_update, EVP_PKEY_verify_message_final, EVP_PKEY_CTX_set_signature - signature verification using a public key algorithm

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_verify_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_verify_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]);
-int EVP_PKEY_verify_init_ex2(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo,
-                             const OSSL_PARAM params[]);
-int EVP_PKEY_verify_message_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo,
-                                 const OSSL_PARAM params[]);
-int EVP_PKEY_CTX_set_signature(EVP_PKEY_CTX *pctx,
-                               const unsigned char *sig, size_t siglen);
-int EVP_PKEY_verify_message_update(EVP_PKEY_CTX *ctx,
-                                   unsigned char *in, size_t inlen);
-int EVP_PKEY_verify_message_final(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_verify(EVP_PKEY_CTX *ctx,
-                    const unsigned char *sig, size_t siglen,
-                    const unsigned char *tbs, size_t tbslen);
- -

DESCRIPTION

- -

EVP_PKEY_verify_init() initializes a public key algorithm context ctx for verification using the algorithm given when the context was created using EVP_PKEY_CTX_new(3) or variants thereof. The algorithm is used to fetch a EVP_SIGNATURE method implicitly, see "Implicit fetch" in provider(7) for more information about implicit fetches.

- -

EVP_PKEY_verify_init_ex() is the same as EVP_PKEY_verify_init() but additionally sets the passed parameters params on the context before returning.

- -

EVP_PKEY_verify_init_ex2() is the same as EVP_PKEY_verify_init_ex(), but works with an explicitly fetched EVP_SIGNATURE algo. A context ctx without a pre-loaded key cannot be used with this function. Depending on what algorithm was fetched, certain details revolving around the treatment of the input to EVP_PKEY_verify() may be pre-determined, and in that case, those details may normally not be changed. See "NOTES" below for a deeper explanation.

- -

EVP_PKEY_verify_message_init() initializes a public key algorithm context ctx for verifying an unlimited size message using the algorithm given by algo and the key given through EVP_PKEY_CTX_new(3) or EVP_PKEY_CTX_new_from_pkey(3). Passing the message is supported both in a one-shot fashion using EVP_PKEY_verify(), and through the combination of EVP_PKEY_verify_update() and EVP_PKEY_verify_final(). This function enables using algorithms that can process input of arbitrary length, such as ED25519, RSA-SHA256 and similar.

- -

EVP_PKEY_CTX_set_signature() specifies the siglen bytes long signature sig to be verified against by EVP_PKEY_verify_final(). It must be used together with EVP_PKEY_verify_update() and EVP_PKEY_verify_final(). See "NOTES" below for a deeper explanation.

- -

EVP_PKEY_verify_update() adds inlen bytes from in to the data to be processed for verification. The signature algorithm specification and implementation determine how the input bytes are processed and if there's a limit on the total size of the input. See "NOTES" below for a deeper explanation.

- -

EVP_PKEY_verify_final() verifies the processed data, given only ctx. The signature to verify against must have been given with EVP_PKEY_CTX_set_signature().

- -

EVP_PKEY_verify() is a one-shot function that performs the same thing as EVP_PKEY_CTX_set_signature() call with sig and siglen as parameters, followed by a single EVP_PKEY_verify_update() call with tbs and tbslen, followed by EVP_PKEY_verify_final() call.

- -

NOTES

- -

General

- -

Some signature implementations only accumulate the input data and do no further processing before verifying it (they expect the input to be a digest), while others compress the data, typically by internally producing a digest, and signing the result, which is then verified against a given signature. Some of them support both modes of operation at the same time. The caller is expected to know how the chosen algorithm is supposed to behave and under what conditions.

- -

For example, an RSA implementation can be expected to only expect a digest as input, while ED25519 can be expected to process the input with a hash, i.e. to produce the digest internally, and while RSA-SHA256 can be expected to handle either mode of operation, depending on if the operation was initialized with EVP_PKEY_verify_init_ex2() or with EVP_PKEY_verify_message_init().

- -

Similarly, an RSA implementation usually expects additional details to be set, like the message digest algorithm that the input is supposed to be digested with, as well as the padding mode (see EVP_PKEY_CTX_set_signature_md(3) and EVP_PKEY_CTX_set_rsa_padding(3) and similar others), while an RSA-SHA256 implementation usually has these details pre-set and immutable.

- -

The functions described here can't be used to combine separate algorithms. In particular, neither EVP_PKEY_CTX_set_signature_md(3) nor the OSSL_PARAM parameter "digest" (OSSL_SIGNATURE_PARAM_DIGEST) can be used to combine a signature algorithm with a hash algorithm to process the input. In other words, it's not possible to specify a ctx pre-loaded with an RSA pkey, or an algo that fetched RSA and try to specify SHA256 separately to get the functionality of RSA-SHA256. If combining algorithms in that manner is desired, please use EVP_DigestVerifyInit(3) and associated functions, or EVP_VerifyInit(3) and associated functions.

- -

Performing multiple verifications

- -

When initialized using EVP_PKEY_verify_init_ex() or EVP_PKEY_verify_init_ex2(), EVP_PKEY_verify() can be called more than once on the same context to have several one-shot operations performed using the same parameters.

- -

When initialized using EVP_PKEY_verify_message_init(), it's not possible to call EVP_PKEY_verify() multiple times.

- -

On EVP_PKEY_CTX_set_signature()

- -

Some signature algorithms (such as LMS) require the signature verification data be specified before verifying the message. Other algorithms allow the signature to be specified late. To allow either way (which may depend on the application's flow of input), the signature to be verified against must be specified using this function when using EVP_PKEY_verify_message_update() and EVP_PKEY_verify_message_final() to perform the verification.

- -

RETURN VALUES

- -

All functions return 1 for success and 0 or a negative value for failure. However, unlike other functions, the return value 0 from EVP_PKEY_verify(), EVP_PKEY_verify_recover() and EVP_PKEY_verify_message_final() only indicates that the signature did not verify successfully (that is tbs did not match the original data or the signature was of invalid form) it is not an indication of a more serious error.

- -

A negative value indicates an error other that signature verification failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

RSA with PKCS#1 padding for SHA256

- -

Verify signature using PKCS#1 padding and a SHA256 digest as input:

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-unsigned char *md, *sig;
-size_t mdlen, siglen;
-EVP_PKEY *verify_key;
-
-/*
- * NB: assumes verify_key, sig, siglen md and mdlen are already set up
- * and that verify_key is an RSA public key
- */
-ctx = EVP_PKEY_CTX_new(verify_key, NULL /* no engine */);
-if (ctx == NULL)
-    /* Error occurred */
-if (EVP_PKEY_verify_init(ctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_PADDING) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_signature_md(ctx, EVP_sha256()) <= 0)
-    /* Error */
-
-/* Perform operation */
-ret = EVP_PKEY_verify(ctx, sig, siglen, md, mdlen);
-
-/*
- * ret == 1 indicates success, 0 verify failure and < 0 for some
- * other error.
- */
- -

RSA-SHA256 with a pre-computed digest

- -

Verify a digest with RSA-SHA256 using one-shot functions. To be noted is that RSA-SHA256 is assumed to be an implementation of sha256WithRSAEncryption, for which the padding is pre-determined to be RSA_PKCS1_PADDING, and the input digest is assumed to have been computed using SHA256.

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-/* md is a SHA-256 digest in this example. */
-unsigned char *md, *sig;
-size_t mdlen = 32, siglen;
-EVP_PKEY *signing_key;
-
-/*
- * NB: assumes verify_key, sig, siglen, md and mdlen are already set up
- * and that verify_key is an RSA public key
- */
-ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */);
-alg = EVP_SIGNATURE_fetch(NULL, "RSA-SHA256", NULL);
-
-if (ctx == NULL)
-    /* Error occurred */
-if (EVP_PKEY_verify_init_ex2(ctx, alg, NULL) <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_verify(ctx, sig, siglen, md, mdlen) <= 0)
-    /* Error or signature doesn't verify */
-
-/* Perform operation */
-ret = EVP_PKEY_verify(ctx, sig, siglen, md, mdlen);
-
-/*
- * ret == 1 indicates success, 0 verify failure and < 0 for some
- * other error.
- */
- -

RSA-SHA256, one-shot

- -

Verify a document with RSA-SHA256 using one-shot functions. To be noted is that RSA-SHA256 is assumed to be an implementation of sha256WithRSAEncryption, for which the padding is pre-determined to be RSA_PKCS1_PADDING.

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-/* in the input in this example. */
-unsigned char *in, *sig;
-/* inlen is the length of the input in this example. */
-size_t inlen, siglen;
-EVP_PKEY *signing_key;
-EVP_SIGNATURE *alg;
-
-/*
- * NB: assumes signing_key, in and inlen are set up before
- * the next step. signing_key must be an RSA private key,
- * in must point to data to be digested and signed, and
- * inlen must be the size of the data in bytes.
- */
-ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */);
-alg = EVP_SIGNATURE_fetch(NULL, "RSA-SHA256", NULL);
-
-if (ctx == NULL || alg == NULL)
-    /* Error occurred */
-if (EVP_PKEY_verify_message_init(ctx, alg, NULL) <= 0)
-    /* Error */
-
-/* Perform operation */
-ret = EVP_PKEY_verify(ctx, sig, siglen, in, inlen);
-
-/*
- * ret == 1 indicates success, 0 verify failure and < 0 for some
- * other error.
- */
- -

RSA-SHA256, using update and final

- -

This is the same as the previous example, but allowing stream-like functionality.

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-/* in is the input in this example. */
-unsigned char *in, *sig;
-/* inlen is the length of the input in this example. */
-size_t inlen, siglen;
-EVP_PKEY *signing_key;
-EVP_SIGNATURE *alg;
-
-/*
- * NB: assumes signing_key, in and inlen are set up before
- * the next step. signing_key must be an RSA private key,
- * in must point to data to be digested and signed, and
- * inlen must be the size of the data in bytes.
- */
-ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */);
-alg = EVP_SIGNATURE_fetch(NULL, "RSA-SHA256", NULL);
-
-if (ctx == NULL || alg == NULL)
-    /* Error occurred */
-if (EVP_PKEY_verify_message_init(ctx, alg, NULL) <= 0)
-    /* Error */
-
-/* We have the signature, specify it early */
-EVP_PKEY_CTX_set_signature(ctx, sig, siglen);
-
-/* Perform operation */
-while (inlen > 0) {
-    if (EVP_PKEY_verify_message_update(ctx, in, inlen)) <= 0)
-        /* Error */
-    if (inlen > 256) {
-        inlen -= 256;
-        in += 256;
-    } else {
-        inlen = 0;
-    }
-}
-ret = EVP_PKEY_verify_message_final(ctx);
-
-/*
- * ret == 1 indicates success, 0 verify failure and < 0 for some
- * other error.
- */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

The EVP_PKEY_verify_init() and EVP_PKEY_verify() functions were added in OpenSSL 1.0.0.

- -

The EVP_PKEY_verify_init_ex() function was added in OpenSSL 3.0.

- -

The EVP_PKEY_verify_init_ex2(), EVP_PKEY_verify_message_init(), EVP_PKEY_verify_message_update(), EVP_PKEY_verify_message_final() and EVP_PKEY_CTX_set_signature() functions where added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify_recover.html b/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify_recover.html deleted file mode 100644 index ee042c11..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_PKEY_verify_recover.html +++ /dev/null @@ -1,130 +0,0 @@ - - - - -EVP_PKEY_verify_recover - - - - - - - - - - -

NAME

- -

EVP_PKEY_verify_recover_init, EVP_PKEY_verify_recover_init_ex, EVP_PKEY_verify_recover_init_ex2, EVP_PKEY_verify_recover - recover signature using a public key algorithm

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_PKEY_verify_recover_init(EVP_PKEY_CTX *ctx);
-int EVP_PKEY_verify_recover_init_ex(EVP_PKEY_CTX *ctx,
-                                    const OSSL_PARAM params[]);
-int EVP_PKEY_verify_recover_init_ex2(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo,
-                                     const OSSL_PARAM params[]);
-int EVP_PKEY_verify_recover(EVP_PKEY_CTX *ctx,
-                            unsigned char *rout, size_t *routlen,
-                            const unsigned char *sig, size_t siglen);
- -

DESCRIPTION

- -

EVP_PKEY_verify_recover_init() initializes a public key algorithm context ctx for signing using the algorithm given when the context was created using EVP_PKEY_CTX_new(3) or variants thereof. The algorithm is used to fetch a EVP_SIGNATURE method implicitly, see "Implicit fetch" in provider(7) for more information about implicit fetches.

- -

EVP_PKEY_verify_recover_init_ex() is the same as EVP_PKEY_verify_recover_init() but additionally sets the passed parameters params on the context before returning.

- -

EVP_PKEY_verify_recover_init_ex2() is the same as EVP_PKEY_verify_recover_init_ex(), but works with an explicitly fetched EVP_SIGNATURE algo. A context ctx without a pre-loaded key cannot be used with this function. Depending on what algorithm was fetched, certain details revolving around the treatment of the input to EVP_PKEY_verify() may be pre-determined, and in that case, those details may normally not be changed. See "NOTES" below for a deeper explanation.

- -

The EVP_PKEY_verify_recover() function recovers signed data using ctx. The signature is specified using the sig and siglen parameters. If rout is NULL then the maximum size of the output buffer is written to the routlen parameter. If rout is not NULL then before the call the routlen parameter should contain the length of the rout buffer, if the call is successful recovered data is written to rout and the amount of data written to routlen.

- -

NOTES

- -

Normally an application is only interested in whether a signature verification operation is successful in those cases the EVP_verify() function should be used.

- -

Sometimes however it is useful to obtain the data originally signed using a signing operation. Only certain public key algorithms can recover a signature in this way (for example RSA in PKCS padding mode).

- -

After the call to EVP_PKEY_verify_recover_init() algorithm specific control operations can be performed to set any appropriate parameters for the operation.

- -

After the call to EVP_PKEY_verify_recover_init_ex2(), algorithm specific control operations may not be needed if the chosen algorithm implies that those controls pre-set (and immutable).

- -

The function EVP_PKEY_verify_recover() can be called more than once on the same context if several operations are performed using the same parameters.

- -

RETURN VALUES

- -

EVP_PKEY_verify_recover_init() and EVP_PKEY_verify_recover() return 1 for success and 0 or a negative value for failure. In particular a return value of -2 indicates the operation is not supported by the public key algorithm.

- -

EXAMPLES

- -

Recover digest originally signed using PKCS#1 and SHA256 digest:

- -
#include <openssl/evp.h>
-#include <openssl/rsa.h>
-
-EVP_PKEY_CTX *ctx;
-unsigned char *rout, *sig;
-size_t routlen, siglen;
-EVP_PKEY *verify_key;
-
-/*
- * NB: assumes verify_key, sig and siglen are already set up
- * and that verify_key is an RSA public key
- */
-ctx = EVP_PKEY_CTX_new(verify_key, NULL /* no engine */);
-if (!ctx)
-    /* Error occurred */
-if (EVP_PKEY_verify_recover_init(ctx) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_PADDING) <= 0)
-    /* Error */
-if (EVP_PKEY_CTX_set_signature_md(ctx, EVP_sha256()) <= 0)
-    /* Error */
-
-/* Determine buffer length */
-if (EVP_PKEY_verify_recover(ctx, NULL, &routlen, sig, siglen) <= 0)
-    /* Error */
-
-rout = OPENSSL_malloc(routlen);
-
-if (!rout)
-    /* malloc failure */
-
-if (EVP_PKEY_verify_recover(ctx, rout, &routlen, sig, siglen) <= 0)
-    /* Error */
-
-/* Recovered data is routlen bytes written to buffer rout */
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_derive(3)

- -

HISTORY

- -

The EVP_PKEY_verify_recover_init() and EVP_PKEY_verify_recover() functions were added in OpenSSL 1.0.0.

- -

The EVP_PKEY_verify_recover_init_ex() function was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2013-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_RAND.html b/openssl-install/share/doc/openssl/html/man3/EVP_RAND.html deleted file mode 100644 index 4663b364..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_RAND.html +++ /dev/null @@ -1,347 +0,0 @@ - - - - -EVP_RAND - - - - - - - - - - -

NAME

- -

EVP_RAND, EVP_RAND_fetch, EVP_RAND_free, EVP_RAND_up_ref, EVP_RAND_CTX, EVP_RAND_CTX_new, EVP_RAND_CTX_free, EVP_RAND_CTX_up_ref, EVP_RAND_instantiate, EVP_RAND_uninstantiate, EVP_RAND_generate, EVP_RAND_reseed, EVP_RAND_nonce, EVP_RAND_enable_locking, EVP_RAND_verify_zeroization, EVP_RAND_get_strength, EVP_RAND_get_state, EVP_RAND_get0_provider, EVP_RAND_CTX_get0_rand, EVP_RAND_is_a, EVP_RAND_get0_name, EVP_RAND_names_do_all, EVP_RAND_get0_description, EVP_RAND_CTX_get_params, EVP_RAND_CTX_set_params, EVP_RAND_do_all_provided, EVP_RAND_get_params, EVP_RAND_gettable_ctx_params, EVP_RAND_settable_ctx_params, EVP_RAND_CTX_gettable_params, EVP_RAND_CTX_settable_params, EVP_RAND_gettable_params, EVP_RAND_STATE_UNINITIALISED, EVP_RAND_STATE_READY, EVP_RAND_STATE_ERROR - EVP RAND routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-typedef struct evp_rand_st EVP_RAND;
-typedef struct evp_rand_ctx_st EVP_RAND_CTX;
-
-EVP_RAND *EVP_RAND_fetch(OSSL_LIB_CTX *libctx, const char *algorithm,
-                       const char *properties);
-int EVP_RAND_up_ref(EVP_RAND *rand);
-void EVP_RAND_free(EVP_RAND *rand);
-EVP_RAND_CTX *EVP_RAND_CTX_new(EVP_RAND *rand, EVP_RAND_CTX *parent);
-void EVP_RAND_CTX_free(EVP_RAND_CTX *ctx);
-int EVP_RAND_CTX_up_ref(EVP_RAND_CTX *ctx);
-EVP_RAND *EVP_RAND_CTX_get0_rand(EVP_RAND_CTX *ctx);
-int EVP_RAND_get_params(EVP_RAND *rand, OSSL_PARAM params[]);
-int EVP_RAND_CTX_get_params(EVP_RAND_CTX *ctx, OSSL_PARAM params[]);
-int EVP_RAND_CTX_set_params(EVP_RAND_CTX *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *EVP_RAND_gettable_params(const EVP_RAND *rand);
-const OSSL_PARAM *EVP_RAND_gettable_ctx_params(const EVP_RAND *rand);
-const OSSL_PARAM *EVP_RAND_settable_ctx_params(const EVP_RAND *rand);
-const OSSL_PARAM *EVP_RAND_CTX_gettable_params(EVP_RAND_CTX *ctx);
-const OSSL_PARAM *EVP_RAND_CTX_settable_params(EVP_RAND_CTX *ctx);
-const char *EVP_RAND_get0_name(const EVP_RAND *rand);
-const char *EVP_RAND_get0_description(const EVP_RAND *rand);
-int EVP_RAND_is_a(const EVP_RAND *rand, const char *name);
-const OSSL_PROVIDER *EVP_RAND_get0_provider(const EVP_RAND *rand);
-void EVP_RAND_do_all_provided(OSSL_LIB_CTX *libctx,
-                              void (*fn)(EVP_RAND *rand, void *arg),
-                              void *arg);
-int EVP_RAND_names_do_all(const EVP_RAND *rand,
-                          void (*fn)(const char *name, void *data),
-                          void *data);
-
-int EVP_RAND_instantiate(EVP_RAND_CTX *ctx, unsigned int strength,
-                         int prediction_resistance,
-                         const unsigned char *pstr, size_t pstr_len,
-                         const OSSL_PARAM params[]);
-int EVP_RAND_uninstantiate(EVP_RAND_CTX *ctx);
-int EVP_RAND_generate(EVP_RAND_CTX *ctx, unsigned char *out, size_t outlen,
-                      unsigned int strength, int prediction_resistance,
-                      const unsigned char *addin, size_t addin_len);
-int EVP_RAND_reseed(EVP_RAND_CTX *ctx, int prediction_resistance,
-                    const unsigned char *ent, size_t ent_len,
-                    const unsigned char *addin, size_t addin_len);
-int EVP_RAND_nonce(EVP_RAND_CTX *ctx, unsigned char *out, size_t outlen);
-int EVP_RAND_enable_locking(EVP_RAND_CTX *ctx);
-int EVP_RAND_verify_zeroization(EVP_RAND_CTX *ctx);
-unsigned int EVP_RAND_get_strength(EVP_RAND_CTX *ctx);
-int EVP_RAND_get_state(EVP_RAND_CTX *ctx);
-
-#define EVP_RAND_STATE_UNINITIALISED    0
-#define EVP_RAND_STATE_READY            1
-#define EVP_RAND_STATE_ERROR            2
- -

DESCRIPTION

- -

The EVP RAND routines are a high-level interface to random number generators both deterministic and not. If you just want to generate random bytes then you don't need to use these functions: just call RAND_bytes() or RAND_priv_bytes(). If you want to do more, these calls should be used instead of the older RAND and RAND_DRBG functions.

- -

After creating a EVP_RAND_CTX for the required algorithm using EVP_RAND_CTX_new(), inputs to the algorithm are supplied either by passing them as part of the EVP_RAND_instantiate() call or using calls to EVP_RAND_CTX_set_params() before calling EVP_RAND_instantiate(). Finally, call EVP_RAND_generate() to produce cryptographically secure random bytes.

- -

Types

- -

EVP_RAND is a type that holds the implementation of a RAND.

- -

EVP_RAND_CTX is a context type that holds the algorithm inputs. EVP_RAND_CTX structures are reference counted.

- -

Algorithm implementation fetching

- -

EVP_RAND_fetch() fetches an implementation of a RAND algorithm, given a library context libctx and a set of properties. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

The returned value must eventually be freed with EVP_RAND_free(3).

- -

EVP_RAND_up_ref() increments the reference count of an already fetched RAND.

- -

EVP_RAND_free() frees a fetched algorithm. NULL is a valid parameter, for which this function is a no-op.

- -

Context manipulation functions

- -

EVP_RAND_CTX_new() creates a new context for the RAND implementation rand. If not NULL, parent specifies the seed source for this implementation. Not all random number generators need to have a seed source specified. If a parent is required, a NULL parent will utilise the operating system entropy sources. It is recommended to minimise the number of random number generators that rely on the operating system for their randomness because this is often scarce.

- -

EVP_RAND_CTX_free() frees up the context ctx. If ctx is NULL, nothing is done.

- -

EVP_RAND_CTX_get0_rand() returns the EVP_RAND associated with the context ctx.

- -

Random Number Generator Functions

- -

EVP_RAND_instantiate() processes any parameters in params and then instantiates the RAND ctx with a minimum security strength of <strength> and personalisation string pstr of length <pstr_len>. If prediction_resistance is specified, fresh entropy from a live source will be sought. This call operates as per NIST SP 800-90A and SP 800-90C.

- -

EVP_RAND_uninstantiate() uninstantiates the RAND ctx as per NIST SP 800-90A and SP 800-90C. Subsequent to this call, the RAND cannot be used to generate bytes. It can only be freed or instantiated again.

- -

EVP_RAND_generate() produces random bytes from the RAND ctx with the additional input addin of length addin_len. The bytes produced will meet the security strength. If prediction_resistance is specified, fresh entropy from a live source will be sought. This call operates as per NIST SP 800-90A and SP 800-90C.

- -

EVP_RAND_reseed() reseeds the RAND with new entropy. Entropy ent of length ent_len bytes can be supplied as can additional input addin of length addin_len bytes. In the FIPS provider, both are treated as additional input as per NIST SP-800-90Ar1, Sections 9.1 and 9.2. Additional seed material is also drawn from the RAND's parent or the operating system. If prediction_resistance is specified, fresh entropy from a live source will be sought. This call operates as per NIST SP 800-90A and SP 800-90C.

- -

EVP_RAND_nonce() creates a nonce in out of length outlen bytes from the RAND ctx.

- -

EVP_RAND_enable_locking() enables locking for the RAND ctx and all of its parents. After this ctx will operate in a thread safe manner, albeit more slowly. This function is not itself thread safe if called with the same ctx from multiple threads. Typically locking should be enabled before a ctx is shared across multiple threads.

- -

EVP_RAND_get_params() retrieves details about the implementation rand. The set of parameters given with params determine exactly what parameters should be retrieved. Note that a parameter that is unknown in the underlying context is simply ignored.

- -

EVP_RAND_CTX_get_params() retrieves chosen parameters, given the context ctx and its underlying context. The set of parameters given with params determine exactly what parameters should be retrieved. Note that a parameter that is unknown in the underlying context is simply ignored.

- -

EVP_RAND_CTX_set_params() passes chosen parameters to the underlying context, given a context ctx. The set of parameters given with params determine exactly what parameters are passed down. Note that a parameter that is unknown in the underlying context is simply ignored. Also, what happens when a needed parameter isn't passed down is defined by the implementation.

- -

EVP_RAND_gettable_params() returns an OSSL_PARAM(3) array that describes the retrievable and settable parameters. EVP_RAND_gettable_params() returns parameters that can be used with EVP_RAND_get_params().

- -

EVP_RAND_gettable_ctx_params() and EVP_RAND_CTX_gettable_params() return constant OSSL_PARAM(3) arrays that describe the retrievable parameters that can be used with EVP_RAND_CTX_get_params(). EVP_RAND_gettable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_RAND_CTX_gettable_params() returns the parameters that can be retrieved in the context's current state.

- -

EVP_RAND_settable_ctx_params() and EVP_RAND_CTX_settable_params() return constant OSSL_PARAM(3) arrays that describe the settable parameters that can be used with EVP_RAND_CTX_set_params(). EVP_RAND_settable_ctx_params() returns the parameters that can be retrieved from the algorithm, whereas EVP_RAND_CTX_settable_params() returns the parameters that can be retrieved in the context's current state.

- -

Information functions

- -

EVP_RAND_get_strength() returns the security strength of the RAND ctx.

- -

EVP_RAND_get_state() returns the current state of the RAND ctx. States defined by the OpenSSL RNGs are:

- - - -

EVP_RAND_is_a() returns 1 if rand is an implementation of an algorithm that's identifiable with name, otherwise 0.

- -

EVP_RAND_get0_provider() returns the provider that holds the implementation of the given rand.

- -

EVP_RAND_do_all_provided() traverses all RAND implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -

EVP_RAND_get0_name() returns the canonical name of rand.

- -

EVP_RAND_names_do_all() traverses all names for rand, and calls fn with each name and data.

- -

EVP_RAND_get0_description() returns a description of the rand, meant for display and human consumption. The description is at the discretion of the rand implementation.

- -

EVP_RAND_verify_zeroization() confirms if the internal DRBG state is currently zeroed. This is used by the FIPS provider to support the mandatory self tests.

- -

PARAMETERS

- -

The standard parameter names are:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -

Returns the state of the random number generator.

- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -

Returns the bit strength of the random number generator.

- -
-
"fips-indicator" (OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This option is used by the OpenSSL FIPS provider and is not supported by all EVP_RAND sources.

- -
-
- -

For rands that are also deterministic random bit generators (DRBGs), these additional parameters are recognised. Not all parameters are relevant to, or are understood by all DRBG rands:

- -
- -
"reseed_requests" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -

Reads or set the number of generate requests before reseeding the associated RAND ctx.

- -
-
"reseed_time_interval" (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) <integer>
-
- -

Reads or set the number of elapsed seconds before reseeding the associated RAND ctx.

- -
-
"max_request" (OSSL_RAND_PARAM_MAX_REQUEST) <unsigned integer>
-
- -

Specifies the maximum number of bytes that can be generated in a single call to OSSL_FUNC_rand_generate.

- -
-
"min_entropylen" (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) <unsigned integer>
-
- -
-
"max_entropylen" (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) <unsigned integer>
-
- -

Specify the minimum and maximum number of bytes of random material that can be used to seed the DRBG.

- -
-
"min_noncelen" (OSSL_DRBG_PARAM_MIN_NONCELEN) <unsigned integer>
-
- -
-
"max_noncelen" (OSSL_DRBG_PARAM_MAX_NONCELEN) <unsigned integer>
-
- -

Specify the minimum and maximum number of bytes of nonce that can be used to seed the DRBG.

- -
-
"max_perslen" (OSSL_DRBG_PARAM_MAX_PERSLEN) <unsigned integer>
-
- -
-
"max_adinlen" (OSSL_DRBG_PARAM_MAX_ADINLEN) <unsigned integer>
-
- -

Specify the minimum and maximum number of bytes of personalisation string that can be used with the DRBG.

- -
-
"reseed_counter" (OSSL_DRBG_PARAM_RESEED_COUNTER) <unsigned integer>
-
- -

Specifies the number of times the DRBG has been seeded or reseeded.

- -
-
"properties" (OSSL_RAND_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"mac" (OSSL_RAND_PARAM_MAC) <UTF8 string>
-
- -
-
"digest" (OSSL_RAND_PARAM_DIGEST) <UTF8 string>
-
- -
-
"cipher" (OSSL_RAND_PARAM_CIPHER) <UTF8 string>
-
- -

For RAND implementations that use an underlying computation MAC, digest or cipher, these parameters set what the algorithm should be.

- -

The value is always the name of the intended algorithm, or the properties in the case of OSSL_RAND_PARAM_PROPERTIES.

- -
-
- -

NOTES

- -

The use of a nonzero value for the prediction_resistance argument to EVP_RAND_instantiate(), EVP_RAND_generate() or EVP_RAND_reseed() should be used sparingly. In the default setup, this will cause all public and private DRBGs to be reseeded on next use. Since, by default, public and private DRBGs are allocated on a per thread basis, this can result in significant overhead for highly multi-threaded applications. For normal use-cases, the default "reseed_requests" and "reseed_time_interval" thresholds ensure sufficient prediction resistance over time and you can reduce those values if you think they are too high. Explicitly requesting prediction resistance is intended for more special use-cases like generating long-term secrets.

- -

An EVP_RAND_CTX needs to have locking enabled if it acts as the parent of more than one child and the children can be accessed concurrently. This must be done by explicitly calling EVP_RAND_enable_locking().

- -

The RAND life-cycle is described in life_cycle-rand(7). In the future, the transitions described there will be enforced. When this is done, it will not be considered a breaking change to the API.

- -

RETURN VALUES

- -

EVP_RAND_fetch() returns a pointer to a newly fetched EVP_RAND, or NULL if allocation failed.

- -

EVP_RAND_get0_provider() returns a pointer to the provider for the RAND, or NULL on error.

- -

EVP_RAND_CTX_get0_rand() returns a pointer to the EVP_RAND associated with the context.

- -

EVP_RAND_get0_name() returns the name of the random number generation algorithm.

- -

EVP_RAND_up_ref() returns 1 on success, 0 on error.

- -

EVP_RAND_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EVP_RAND_CTX_new() returns either the newly allocated EVP_RAND_CTX structure or NULL if an error occurred.

- -

EVP_RAND_CTX_free() does not return a value.

- -

EVP_RAND_CTX_up_ref() returns 1 on success, 0 on error.

- -

EVP_RAND_nonce() returns 1 on success, 0 on error.

- -

EVP_RAND_get_strength() returns the strength of the random number generator in bits.

- -

EVP_RAND_gettable_params(), EVP_RAND_gettable_ctx_params() and EVP_RAND_settable_ctx_params() return an array of OSSL_PARAMs.

- -

EVP_RAND_verify_zeroization() returns 1 if the internal DRBG state is currently zeroed, and 0 if not.

- -

The remaining functions return 1 for success and 0 or a negative value for failure.

- -

SEE ALSO

- -

RAND_bytes(3), EVP_RAND-CTR-DRBG(7), EVP_RAND-HASH-DRBG(7), EVP_RAND-HMAC-DRBG(7), EVP_RAND-TEST-RAND(7), provider-rand(7), life_cycle-rand(7)

- -

HISTORY

- -

EVP_RAND_CTX_up_ref() was added in OpenSSL 3.1.

- -

The remaining functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_SIGNATURE.html b/openssl-install/share/doc/openssl/html/man3/EVP_SIGNATURE.html deleted file mode 100644 index 3f1b1cb7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_SIGNATURE.html +++ /dev/null @@ -1,106 +0,0 @@ - - - - -EVP_SIGNATURE - - - - - - - - - - -

NAME

- -

EVP_SIGNATURE, EVP_SIGNATURE_fetch, EVP_SIGNATURE_free, EVP_SIGNATURE_up_ref, EVP_SIGNATURE_is_a, EVP_SIGNATURE_get0_provider, EVP_SIGNATURE_do_all_provided, EVP_SIGNATURE_names_do_all, EVP_SIGNATURE_get0_name, EVP_SIGNATURE_get0_description, EVP_SIGNATURE_gettable_ctx_params, EVP_SIGNATURE_settable_ctx_params - Functions to manage EVP_SIGNATURE algorithm objects

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-typedef struct evp_signature_st EVP_SIGNATURE;
-
-EVP_SIGNATURE *EVP_SIGNATURE_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-                                   const char *properties);
-void EVP_SIGNATURE_free(EVP_SIGNATURE *signature);
-int EVP_SIGNATURE_up_ref(EVP_SIGNATURE *signature);
-const char *EVP_SIGNATURE_get0_name(const EVP_SIGNATURE *signature);
-int EVP_SIGNATURE_is_a(const EVP_SIGNATURE *signature, const char *name);
-OSSL_PROVIDER *EVP_SIGNATURE_get0_provider(const EVP_SIGNATURE *signature);
-void EVP_SIGNATURE_do_all_provided(OSSL_LIB_CTX *libctx,
-                                   void (*fn)(EVP_SIGNATURE *signature,
-                                              void *arg),
-                                   void *arg);
-int EVP_SIGNATURE_names_do_all(const EVP_SIGNATURE *signature,
-                               void (*fn)(const char *name, void *data),
-                               void *data);
-const char *EVP_SIGNATURE_get0_name(const EVP_SIGNATURE *signature);
-const char *EVP_SIGNATURE_get0_description(const EVP_SIGNATURE *signature);
-const OSSL_PARAM *EVP_SIGNATURE_gettable_ctx_params(const EVP_SIGNATURE *sig);
-const OSSL_PARAM *EVP_SIGNATURE_settable_ctx_params(const EVP_SIGNATURE *sig);
- -

DESCRIPTION

- -

EVP_SIGNATURE_fetch() fetches the implementation for the given algorithm from any provider offering it, within the criteria given by the properties. The algorithm will be one offering functions for performing signature related tasks such as signing and verifying. See "ALGORITHM FETCHING" in crypto(7) for further information.

- -

The returned value must eventually be freed with EVP_SIGNATURE_free().

- -

EVP_SIGNATURE_free() decrements the reference count for the EVP_SIGNATURE structure. Typically this structure will have been obtained from an earlier call to EVP_SIGNATURE_fetch(). If the reference count drops to 0 then the structure is freed. If the argument is NULL, nothing is done.

- -

EVP_SIGNATURE_up_ref() increments the reference count for an EVP_SIGNATURE structure.

- -

EVP_SIGNATURE_is_a() returns 1 if signature is an implementation of an algorithm that's identifiable with name, otherwise 0.

- -

EVP_SIGNATURE_get0_provider() returns the provider that signature was fetched from.

- -

EVP_SIGNATURE_do_all_provided() traverses all SIGNATURE implemented by all activated providers in the given library context libctx, and for each of the implementations, calls the given function fn with the implementation method and the given arg as argument.

- -

EVP_SIGNATURE_get0_name() returns the algorithm name from the provided implementation for the given signature. Note that the signature may have multiple synonyms associated with it. In this case the first name from the algorithm definition is returned. Ownership of the returned string is retained by the signature object and should not be freed by the caller.

- -

EVP_SIGNATURE_names_do_all() traverses all names for signature, and calls fn with each name and data.

- -

EVP_SIGNATURE_get0_description() returns a description of the signature, meant for display and human consumption. The description is at the discretion of the signature implementation.

- -

EVP_SIGNATURE_gettable_ctx_params() and EVP_SIGNATURE_settable_ctx_params() return a constant OSSL_PARAM(3) array that describes the names and types of key parameters that can be retrieved or set by a signature algorithm using EVP_PKEY_CTX_get_params(3) and EVP_PKEY_CTX_set_params(3).

- -

RETURN VALUES

- -

EVP_SIGNATURE_fetch() returns a pointer to an EVP_SIGNATURE for success or NULL for failure.

- -

EVP_SIGNATURE_up_ref() returns 1 for success or 0 otherwise.

- -

EVP_SIGNATURE_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

EVP_SIGNATURE_gettable_ctx_params() and EVP_SIGNATURE_settable_ctx_params() return a constant OSSL_PARAM(3) array or NULL on error.

- -

SEE ALSO

- -

"ALGORITHM FETCHING" in crypto(7), OSSL_PROVIDER(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_SealInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_SealInit.html deleted file mode 100644 index 31b82f0d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_SealInit.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -EVP_SealInit - - - - - - - - - - -

NAME

- -

EVP_SealInit, EVP_SealUpdate, EVP_SealFinal - EVP envelope encryption

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_SealInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type,
-                 unsigned char **ek, int *ekl, unsigned char *iv,
-                 EVP_PKEY **pubk, int npubk);
-int EVP_SealUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out,
-                   int *outl, unsigned char *in, int inl);
-int EVP_SealFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl);
- -

DESCRIPTION

- -

The EVP envelope routines are a high-level interface to envelope encryption. They generate a random key and IV (if required) then "envelope" it by using public key encryption. Data can then be encrypted using this key.

- -

EVP_SealInit() initializes a cipher context ctx for encryption with cipher type using a random secret key and IV. type is normally supplied by a function such as EVP_aes_256_cbc(). The secret key is encrypted using one or more public keys, this allows the same encrypted data to be decrypted using any of the corresponding private keys. ek is an array of buffers where the public key encrypted secret key will be written, each buffer must contain enough room for the corresponding encrypted key: that is ek[i] must have room for EVP_PKEY_get_size(pubk[i]) bytes. The actual size of each encrypted secret key is written to the array ekl. pubk is an array of npubk public keys.

- -

The iv parameter is a buffer where the generated IV is written to. It must contain enough room for the corresponding cipher's IV, as determined by (for example) EVP_CIPHER_get_iv_length(type).

- -

If the cipher does not require an IV then the iv parameter is ignored and can be NULL.

- -

EVP_SealUpdate() and EVP_SealFinal() have exactly the same properties as the EVP_EncryptUpdate() and EVP_EncryptFinal() routines, as documented on the EVP_EncryptInit(3) manual page.

- -

RETURN VALUES

- -

EVP_SealInit() returns 0 on error or npubk if successful.

- -

EVP_SealUpdate() and EVP_SealFinal() return 1 for success and 0 for failure.

- -

NOTES

- -

Because a random secret key is generated the random number generator must be seeded when EVP_SealInit() is called. If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

The public key must be RSA because it is the only OpenSSL public key algorithm that supports key transport.

- -

Envelope encryption is the usual method of using public key encryption on large amounts of data, this is because public key encryption is slow but symmetric encryption is fast. So symmetric encryption is used for bulk encryption and the small random symmetric key used is transferred using public key encryption.

- -

It is possible to call EVP_SealInit() twice in the same way as EVP_EncryptInit(). The first call should have npubk set to 0 and (after setting any cipher parameters) it should be called again with type set to NULL.

- -

SEE ALSO

- -

evp(7), RAND_bytes(3), EVP_EncryptInit(3), EVP_OpenInit(3), RAND(7)

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_SignInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_SignInit.html deleted file mode 100644 index 529f76c9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_SignInit.html +++ /dev/null @@ -1,104 +0,0 @@ - - - - -EVP_SignInit - - - - - - - - - - -

NAME

- -

EVP_SignInit, EVP_SignInit_ex, EVP_SignUpdate, EVP_SignFinal_ex, EVP_SignFinal - EVP signing functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_SignInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl);
-int EVP_SignUpdate(EVP_MD_CTX *ctx, const void *d, unsigned int cnt);
-int EVP_SignFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s,
-                     EVP_PKEY *pkey, OSSL_LIB_CTX *libctx, const char *propq);
-int EVP_SignFinal(EVP_MD_CTX *ctx, unsigned char *sig, unsigned int *s,
-                  EVP_PKEY *pkey);
-
-void EVP_SignInit(EVP_MD_CTX *ctx, const EVP_MD *type);
- -

DESCRIPTION

- -

The EVP signature routines are a high-level interface to digital signatures.

- -

EVP_SignInit_ex() sets up signing context ctx to use digest type from ENGINE impl. ctx must be created with EVP_MD_CTX_new() before calling this function.

- -

EVP_SignUpdate() hashes cnt bytes of data at d into the signature context ctx. This function can be called several times on the same ctx to include additional data.

- -

EVP_SignFinal_ex() signs the data in ctx using the private key pkey and places the signature in sig. The library context libctx and property query propq are used when creating a context to use with the key pkey. sig must be at least EVP_PKEY_get_size(pkey) bytes in size. s is an OUT parameter, and not used as an IN parameter. The number of bytes of data written (i.e. the length of the signature) will be written to the integer at s, at most EVP_PKEY_get_size(pkey) bytes will be written.

- -

EVP_SignFinal() is similar to EVP_SignFinal_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

EVP_SignInit() initializes a signing context ctx to use the default implementation of digest type.

- -

RETURN VALUES

- -

EVP_SignInit_ex(), EVP_SignUpdate(), EVP_SignFinal_ex() and EVP_SignFinal() return 1 for success and 0 for failure.

- -

The error codes can be obtained by ERR_get_error(3).

- -

NOTES

- -

The EVP interface to digital signatures should almost always be used in preference to the low-level interfaces. This is because the code then becomes transparent to the algorithm used and much more flexible.

- -

When signing with some private key types the random number generator must be seeded. If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

The call to EVP_SignFinal() internally finalizes a copy of the digest context. This means that calls to EVP_SignUpdate() and EVP_SignFinal() can be called later to digest and sign additional data.cApplications may disable this behavior by setting the EVP_MD_CTX_FLAG_FINALISE context flag via EVP_MD_CTX_set_flags(3).

- -

Since only a copy of the digest context is ever finalized the context must be cleaned up after use by calling EVP_MD_CTX_free() or a memory leak will occur.

- -

Note that not all providers support continuation, in case the selected provider does not allow to duplicate contexts EVP_SignFinal() will finalize the digest context and attempting to process additional data via EVP_SignUpdate() will result in an error.

- -

BUGS

- -

Older versions of this documentation wrongly stated that calls to EVP_SignUpdate() could not be made after calling EVP_SignFinal().

- -

Since the private key is passed in the call to EVP_SignFinal() any error relating to the private key (for example an unsuitable key and digest combination) will not be indicated until after potentially large amounts of data have been passed through EVP_SignUpdate().

- -

It is not possible to change the signing parameters using these function.

- -

The previous two bugs are fixed in the newer EVP_DigestSign*() functions.

- -

SEE ALSO

- -

EVP_PKEY_get_size(3), EVP_PKEY_get_bits(3), EVP_PKEY_get_security_bits(3), EVP_VerifyInit(3), EVP_DigestInit(3), evp(7), HMAC(3), MD2(3), MD5(3), MDC2(3), RIPEMD160(3), SHA1(3), openssl-dgst(1)

- -

HISTORY

- -

The function EVP_SignFinal_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_VerifyInit.html b/openssl-install/share/doc/openssl/html/man3/EVP_VerifyInit.html deleted file mode 100644 index eaf736cb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_VerifyInit.html +++ /dev/null @@ -1,105 +0,0 @@ - - - - -EVP_VerifyInit - - - - - - - - - - -

NAME

- -

EVP_VerifyInit_ex, EVP_VerifyInit, EVP_VerifyUpdate, EVP_VerifyFinal_ex, EVP_VerifyFinal - EVP signature verification functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_VerifyInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl);
-int EVP_VerifyUpdate(EVP_MD_CTX *ctx, const void *d, unsigned int cnt);
-int EVP_VerifyFinal_ex(EVP_MD_CTX *ctx, const unsigned char *sigbuf,
-                       unsigned int siglen, EVP_PKEY *pkey,
-                       OSSL_LIB_CTX *libctx, const char *propq);
-int EVP_VerifyFinal(EVP_MD_CTX *ctx, unsigned char *sigbuf, unsigned int siglen,
-                    EVP_PKEY *pkey);
-
-int EVP_VerifyInit(EVP_MD_CTX *ctx, const EVP_MD *type);
- -

DESCRIPTION

- -

The EVP signature verification routines are a high-level interface to digital signatures.

- -

EVP_VerifyInit_ex() sets up verification context ctx to use digest type from ENGINE impl. ctx must be created by calling EVP_MD_CTX_new() before calling this function.

- -

EVP_VerifyUpdate() hashes cnt bytes of data at d into the verification context ctx. This function can be called several times on the same ctx to include additional data.

- -

EVP_VerifyFinal_ex() verifies the data in ctx using the public key pkey and siglen bytes in sigbuf. The library context libctx and property query propq are used when creating a context to use with the key pkey.

- -

EVP_VerifyFinal() is similar to EVP_VerifyFinal_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

EVP_VerifyInit() initializes verification context ctx to use the default implementation of digest type.

- -

RETURN VALUES

- -

EVP_VerifyInit_ex() and EVP_VerifyUpdate() return 1 for success and 0 for failure.

- -

EVP_VerifyFinal_ex() and EVP_VerifyFinal() return 1 for a correct signature, 0 for failure and a negative value if some other error occurred.

- -

The error codes can be obtained by ERR_get_error(3).

- -

NOTES

- -

The EVP interface to digital signatures should almost always be used in preference to the low-level interfaces. This is because the code then becomes transparent to the algorithm used and much more flexible.

- -

The call to EVP_VerifyFinal() internally finalizes a copy of the digest context. This means that calls to EVP_VerifyUpdate() and EVP_VerifyFinal() can be called later to digest and verify additional data. Applications may disable this behavior by setting the EVP_MD_CTX_FLAG_FINALISE context flag via EVP_MD_CTX_set_flags(3).

- -

Since only a copy of the digest context is ever finalized the context must be cleaned up after use by calling EVP_MD_CTX_free() or a memory leak will occur.

- -

Note that not all providers support continuation, in case the selected provider does not allow to duplicate contexts EVP_VerifyFinal() will finalize the digest context and attempting to process additional data via EVP_VerifyUpdate() will result in an error.

- -

BUGS

- -

Older versions of this documentation wrongly stated that calls to EVP_VerifyUpdate() could not be made after calling EVP_VerifyFinal().

- -

Since the public key is passed in the call to EVP_SignFinal() any error relating to the private key (for example an unsuitable key and digest combination) will not be indicated until after potentially large amounts of data have been passed through EVP_SignUpdate().

- -

It is not possible to change the signing parameters using these function.

- -

The previous two bugs are fixed in the newer EVP_DigestVerify*() function.

- -

SEE ALSO

- -

evp(7), EVP_SignInit(3), EVP_DigestInit(3), evp(7), HMAC(3), MD2(3), MD5(3), MDC2(3), RIPEMD160(3), SHA1(3), openssl-dgst(1)

- -

HISTORY

- -

The function EVP_VerifyFinal_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_aes_128_gcm.html b/openssl-install/share/doc/openssl/html/man3/EVP_aes_128_gcm.html deleted file mode 100644 index be808dd6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_aes_128_gcm.html +++ /dev/null @@ -1,113 +0,0 @@ - - - - -EVP_aes_128_gcm - - - - - - - - - - -

NAME

- -

EVP_aes_128_cbc, EVP_aes_192_cbc, EVP_aes_256_cbc, EVP_aes_128_cfb, EVP_aes_192_cfb, EVP_aes_256_cfb, EVP_aes_128_cfb1, EVP_aes_192_cfb1, EVP_aes_256_cfb1, EVP_aes_128_cfb8, EVP_aes_192_cfb8, EVP_aes_256_cfb8, EVP_aes_128_cfb128, EVP_aes_192_cfb128, EVP_aes_256_cfb128, EVP_aes_128_ctr, EVP_aes_192_ctr, EVP_aes_256_ctr, EVP_aes_128_ecb, EVP_aes_192_ecb, EVP_aes_256_ecb, EVP_aes_128_ofb, EVP_aes_192_ofb, EVP_aes_256_ofb, EVP_aes_128_cbc_hmac_sha1, EVP_aes_256_cbc_hmac_sha1, EVP_aes_128_cbc_hmac_sha256, EVP_aes_256_cbc_hmac_sha256, EVP_aes_128_ccm, EVP_aes_192_ccm, EVP_aes_256_ccm, EVP_aes_128_gcm, EVP_aes_192_gcm, EVP_aes_256_gcm, EVP_aes_128_ocb, EVP_aes_192_ocb, EVP_aes_256_ocb, EVP_aes_128_wrap, EVP_aes_192_wrap, EVP_aes_256_wrap, EVP_aes_128_wrap_pad, EVP_aes_192_wrap_pad, EVP_aes_256_wrap_pad, EVP_aes_128_xts, EVP_aes_256_xts - EVP AES cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_ciphername(void)
- -

EVP_ciphername is used a placeholder for any of the described cipher functions, such as EVP_aes_128_cbc.

- -

DESCRIPTION

- -

The AES encryption algorithm for EVP.

- -
- -
EVP_aes_128_cbc(), EVP_aes_192_cbc(), EVP_aes_256_cbc(), EVP_aes_128_cfb(), EVP_aes_192_cfb(), EVP_aes_256_cfb(), EVP_aes_128_cfb1(), EVP_aes_192_cfb1(), EVP_aes_256_cfb1(), EVP_aes_128_cfb8(), EVP_aes_192_cfb8(), EVP_aes_256_cfb8(), EVP_aes_128_cfb128(), EVP_aes_192_cfb128(), EVP_aes_256_cfb128(), EVP_aes_128_ctr(), EVP_aes_192_ctr(), EVP_aes_256_ctr(), EVP_aes_128_ecb(), EVP_aes_192_ecb(), EVP_aes_256_ecb(), EVP_aes_128_ofb(), EVP_aes_192_ofb(), EVP_aes_256_ofb()
-
- -

AES for 128, 192 and 256 bit keys in the following modes: CBC, CFB with 128-bit shift, CFB with 1-bit shift, CFB with 8-bit shift, CTR, ECB, and OFB.

- -
-
EVP_aes_128_cbc_hmac_sha1(), EVP_aes_256_cbc_hmac_sha1()
-
- -

Authenticated encryption with AES in CBC mode using SHA-1 as HMAC, with keys of 128 and 256 bits length respectively. The authentication tag is 160 bits long.

- -

WARNING: this is not intended for usage outside of TLS and requires calling of some undocumented ctrl functions. These ciphers do not conform to the EVP AEAD interface.

- -
-
EVP_aes_128_cbc_hmac_sha256(), EVP_aes_256_cbc_hmac_sha256()
-
- -

Authenticated encryption with AES in CBC mode using SHA256 (SHA-2, 256-bits) as HMAC, with keys of 128 and 256 bits length respectively. The authentication tag is 256 bits long.

- -

WARNING: this is not intended for usage outside of TLS and requires calling of some undocumented ctrl functions. These ciphers do not conform to the EVP AEAD interface.

- -
-
EVP_aes_128_ccm(), EVP_aes_192_ccm(), EVP_aes_256_ccm(), EVP_aes_128_gcm(), EVP_aes_192_gcm(), EVP_aes_256_gcm(), EVP_aes_128_ocb(), EVP_aes_192_ocb(), EVP_aes_256_ocb()
-
- -

AES for 128, 192 and 256 bit keys in CBC-MAC Mode (CCM), Galois Counter Mode (GCM) and OCB Mode respectively. These ciphers require additional control operations to function correctly, see the "AEAD Interface" in EVP_EncryptInit(3) section for details.

- -
-
EVP_aes_128_wrap(), EVP_aes_192_wrap(), EVP_aes_256_wrap(), EVP_aes_128_wrap_pad(), EVP_aes_192_wrap_pad(), EVP_aes_256_wrap_pad()
-
- -

AES key wrap with 128, 192 and 256 bit keys, as according to RFC 3394 section 2.2.1 ("wrap") and RFC 5649 section 4.1 ("wrap with padding") respectively.

- -
-
EVP_aes_128_xts(), EVP_aes_256_xts()
-
- -

AES XTS mode (XTS-AES) is standardized in IEEE Std. 1619-2007 and described in NIST SP 800-38E. The XTS (XEX-based tweaked-codebook mode with ciphertext stealing) mode was designed by Prof. Phillip Rogaway of University of California, Davis, intended for encrypting data on a storage device.

- -

XTS-AES provides confidentiality but not authentication of data. It also requires a key of double-length for protection of a certain key size. In particular, XTS-AES-128 (EVP_aes_128_xts) takes input of a 256-bit key to achieve AES 128-bit security, and XTS-AES-256 (EVP_aes_256_xts) takes input of a 512-bit key to achieve AES 256-bit security.

- -

The XTS implementation in OpenSSL does not support streaming. That is there must only be one EVP_EncryptUpdate(3) call per EVP_EncryptInit_ex(3) call (and similarly with the "Decrypt" functions).

- -

The iv parameter to EVP_EncryptInit_ex(3) or EVP_DecryptInit_ex(3) is the XTS "tweak" value.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-AES(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_aria_128_gcm.html b/openssl-install/share/doc/openssl/html/man3/EVP_aria_128_gcm.html deleted file mode 100644 index f433482b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_aria_128_gcm.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -EVP_aria_128_gcm - - - - - - - - - - -

NAME

- -

EVP_aria_128_cbc, EVP_aria_192_cbc, EVP_aria_256_cbc, EVP_aria_128_cfb, EVP_aria_192_cfb, EVP_aria_256_cfb, EVP_aria_128_cfb1, EVP_aria_192_cfb1, EVP_aria_256_cfb1, EVP_aria_128_cfb8, EVP_aria_192_cfb8, EVP_aria_256_cfb8, EVP_aria_128_cfb128, EVP_aria_192_cfb128, EVP_aria_256_cfb128, EVP_aria_128_ctr, EVP_aria_192_ctr, EVP_aria_256_ctr, EVP_aria_128_ecb, EVP_aria_192_ecb, EVP_aria_256_ecb, EVP_aria_128_ofb, EVP_aria_192_ofb, EVP_aria_256_ofb, EVP_aria_128_ccm, EVP_aria_192_ccm, EVP_aria_256_ccm, EVP_aria_128_gcm, EVP_aria_192_gcm, EVP_aria_256_gcm, - EVP ARIA cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_ciphername(void)
- -

EVP_ciphername is used a placeholder for any of the described cipher functions, such as EVP_aria_128_cbc.

- -

DESCRIPTION

- -

The ARIA encryption algorithm for EVP.

- -
- -
EVP_aria_128_cbc(), EVP_aria_192_cbc(), EVP_aria_256_cbc(), EVP_aria_128_cfb(), EVP_aria_192_cfb(), EVP_aria_256_cfb(), EVP_aria_128_cfb1(), EVP_aria_192_cfb1(), EVP_aria_256_cfb1(), EVP_aria_128_cfb8(), EVP_aria_192_cfb8(), EVP_aria_256_cfb8(), EVP_aria_128_cfb128(), EVP_aria_192_cfb128(), EVP_aria_256_cfb128(), EVP_aria_128_ctr(), EVP_aria_192_ctr(), EVP_aria_256_ctr(), EVP_aria_128_ecb(), EVP_aria_192_ecb(), EVP_aria_256_ecb(), EVP_aria_128_ofb(), EVP_aria_192_ofb(), EVP_aria_256_ofb()
-
- -

ARIA for 128, 192 and 256 bit keys in the following modes: CBC, CFB with 128-bit shift, CFB with 1-bit shift, CFB with 8-bit shift, CTR, ECB and OFB.

- -
-
EVP_aria_128_ccm(), EVP_aria_192_ccm(), EVP_aria_256_ccm(), EVP_aria_128_gcm(), EVP_aria_192_gcm(), EVP_aria_256_gcm(),
-
- -

ARIA for 128, 192 and 256 bit keys in CBC-MAC Mode (CCM) and Galois Counter Mode (GCM). These ciphers require additional control operations to function correctly, see the "AEAD Interface" in EVP_EncryptInit(3) section for details.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-ARIA(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_bf_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_bf_cbc.html deleted file mode 100644 index 4578a57f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_bf_cbc.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_bf_cbc - - - - - - - - - - -

NAME

- -

EVP_bf_cbc, EVP_bf_cfb, EVP_bf_cfb64, EVP_bf_ecb, EVP_bf_ofb - EVP Blowfish cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_bf_cbc(void);
-const EVP_CIPHER *EVP_bf_cfb(void);
-const EVP_CIPHER *EVP_bf_cfb64(void);
-const EVP_CIPHER *EVP_bf_ecb(void);
-const EVP_CIPHER *EVP_bf_ofb(void);
- -

DESCRIPTION

- -

The Blowfish encryption algorithm for EVP.

- -

This is a variable key length cipher.

- -
- -
EVP_bf_cbc(), EVP_bf_cfb(), EVP_bf_cfb64(), EVP_bf_ecb(), EVP_bf_ofb()
-
- -

Blowfish encryption algorithm in CBC, CFB, ECB and OFB modes respectively.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-BLOWFISH(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_blake2b512.html b/openssl-install/share/doc/openssl/html/man3/EVP_blake2b512.html deleted file mode 100644 index 09b49a77..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_blake2b512.html +++ /dev/null @@ -1,85 +0,0 @@ - - - - -EVP_blake2b512 - - - - - - - - - - -

NAME

- -

EVP_blake2b512, EVP_blake2s256 - BLAKE2 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_blake2b512(void);
-const EVP_MD *EVP_blake2s256(void);
- -

DESCRIPTION

- -

BLAKE2 is an improved version of BLAKE, which was submitted to the NIST SHA-3 algorithm competition. The BLAKE2s and BLAKE2b algorithms are described in RFC 7693.

- -
- -
EVP_blake2s256()
-
- -

The BLAKE2s algorithm that produces a 256-bit output from a given input.

- -
-
EVP_blake2b512()
-
- -

The BLAKE2b algorithm that produces a 512-bit output from a given input.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-BLAKE2(7) instead. See "Performance" in crypto(7) for further information.

- -

Both algorithms support a variable-length digest, but this is only available through EVP_MD-BLAKE2(7).

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

RFC 7693.

- -

SEE ALSO

- -

evp(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_camellia_128_ecb.html b/openssl-install/share/doc/openssl/html/man3/EVP_camellia_128_ecb.html deleted file mode 100644 index 7fa99dc2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_camellia_128_ecb.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -EVP_camellia_128_ecb - - - - - - - - - - -

NAME

- -

EVP_camellia_128_cbc, EVP_camellia_192_cbc, EVP_camellia_256_cbc, EVP_camellia_128_cfb, EVP_camellia_192_cfb, EVP_camellia_256_cfb, EVP_camellia_128_cfb1, EVP_camellia_192_cfb1, EVP_camellia_256_cfb1, EVP_camellia_128_cfb8, EVP_camellia_192_cfb8, EVP_camellia_256_cfb8, EVP_camellia_128_cfb128, EVP_camellia_192_cfb128, EVP_camellia_256_cfb128, EVP_camellia_128_ctr, EVP_camellia_192_ctr, EVP_camellia_256_ctr, EVP_camellia_128_ecb, EVP_camellia_192_ecb, EVP_camellia_256_ecb, EVP_camellia_128_ofb, EVP_camellia_192_ofb, EVP_camellia_256_ofb - EVP Camellia cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_ciphername(void)
- -

EVP_ciphername is used a placeholder for any of the described cipher functions, such as EVP_camellia_128_cbc.

- -

DESCRIPTION

- -

The Camellia encryption algorithm for EVP.

- -
- -
EVP_camellia_128_cbc(), EVP_camellia_192_cbc(), EVP_camellia_256_cbc(), EVP_camellia_128_cfb(), EVP_camellia_192_cfb(), EVP_camellia_256_cfb(), EVP_camellia_128_cfb1(), EVP_camellia_192_cfb1(), EVP_camellia_256_cfb1(), EVP_camellia_128_cfb8(), EVP_camellia_192_cfb8(), EVP_camellia_256_cfb8(), EVP_camellia_128_cfb128(), EVP_camellia_192_cfb128(), EVP_camellia_256_cfb128(), EVP_camellia_128_ctr(), EVP_camellia_192_ctr(), EVP_camellia_256_ctr(), EVP_camellia_128_ecb(), EVP_camellia_192_ecb(), EVP_camellia_256_ecb(), EVP_camellia_128_ofb(), EVP_camellia_192_ofb(), EVP_camellia_256_ofb()
-
- -

Camellia for 128, 192 and 256 bit keys in the following modes: CBC, CFB with 128-bit shift, CFB with 1-bit shift, CFB with 8-bit shift, CTR, ECB and OFB.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-CAMELLIA(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_cast5_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_cast5_cbc.html deleted file mode 100644 index efab0c12..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_cast5_cbc.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_cast5_cbc - - - - - - - - - - -

NAME

- -

EVP_cast5_cbc, EVP_cast5_cfb, EVP_cast5_cfb64, EVP_cast5_ecb, EVP_cast5_ofb - EVP CAST cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_cast5_cbc(void);
-const EVP_CIPHER *EVP_cast5_cfb(void);
-const EVP_CIPHER *EVP_cast5_cfb64(void);
-const EVP_CIPHER *EVP_cast5_ecb(void);
-const EVP_CIPHER *EVP_cast5_ofb(void);
- -

DESCRIPTION

- -

The CAST encryption algorithm for EVP.

- -

This is a variable key length cipher.

- -
- -
EVP_cast5_cbc(), EVP_cast5_ecb(), EVP_cast5_cfb(), EVP_cast5_cfb64(), EVP_cast5_ofb()
-
- -

CAST encryption algorithm in CBC, ECB, CFB and OFB modes respectively.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-CAST(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_chacha20.html b/openssl-install/share/doc/openssl/html/man3/EVP_chacha20.html deleted file mode 100644 index 095fa63d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_chacha20.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -EVP_chacha20 - - - - - - - - - - -

NAME

- -

EVP_chacha20, EVP_chacha20_poly1305 - EVP ChaCha20 stream cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_chacha20(void);
-const EVP_CIPHER *EVP_chacha20_poly1305(void);
- -

DESCRIPTION

- -

The ChaCha20 stream cipher for EVP.

- -
- -
EVP_chacha20()
-
- -

The ChaCha20 stream cipher. The key length is 256 bits, the IV is 128 bits long. The first 64 bits consists of a counter in little-endian order followed by a 64 bit nonce. For example a nonce of:

- -

0000000000000002

- -

With an initial counter of 42 (2a in hex) would be expressed as:

- -

2a000000000000000000000000000002

- -
-
EVP_chacha20_poly1305()
-
- -

Authenticated encryption with ChaCha20-Poly1305. Like EVP_chacha20(), the key is 256 bits and the IV is 96 bits. This supports additional authenticated data (AAD) and produces a 128-bit authentication tag. See the "AEAD Interface" in EVP_EncryptInit(3) section for more information.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-CHACHA(7) instead. See "Performance" in crypto(7) for further information.

- -

RFC 7539 uses a 32 bit counter and a 96 bit nonce for the IV.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_des_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_des_cbc.html deleted file mode 100644 index 7c8ce63f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_des_cbc.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -EVP_des_cbc - - - - - - - - - - -

NAME

- -

EVP_des_cbc, EVP_des_cfb, EVP_des_cfb1, EVP_des_cfb8, EVP_des_cfb64, EVP_des_ecb, EVP_des_ofb, EVP_des_ede, EVP_des_ede_cbc, EVP_des_ede_cfb, EVP_des_ede_cfb64, EVP_des_ede_ecb, EVP_des_ede_ofb, EVP_des_ede3, EVP_des_ede3_cbc, EVP_des_ede3_cfb, EVP_des_ede3_cfb1, EVP_des_ede3_cfb8, EVP_des_ede3_cfb64, EVP_des_ede3_ecb, EVP_des_ede3_ofb, EVP_des_ede3_wrap - EVP DES cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_ciphername(void)
- -

EVP_ciphername is used a placeholder for any of the described cipher functions, such as EVP_des_cbc.

- -

DESCRIPTION

- -

The DES encryption algorithm for EVP.

- -
- -
EVP_des_cbc(), EVP_des_ecb(), EVP_des_cfb(), EVP_des_cfb1(), EVP_des_cfb8(), EVP_des_cfb64(), EVP_des_ofb()
-
- -

DES in CBC, ECB, CFB with 64-bit shift, CFB with 1-bit shift, CFB with 8-bit shift and OFB modes.

- -

None of these algorithms are provided by the OpenSSL default provider. To use them it is necessary to load either the OpenSSL legacy provider or another implementation.

- -
-
EVP_des_ede(), EVP_des_ede_cbc(), EVP_des_ede_cfb(), EVP_des_ede_cfb64(), EVP_des_ede_ecb(), EVP_des_ede_ofb()
-
- -

Two key triple DES in ECB, CBC, CFB with 64-bit shift and OFB modes.

- -
-
EVP_des_ede3(), EVP_des_ede3_cbc(), EVP_des_ede3_cfb(), EVP_des_ede3_cfb1(), EVP_des_ede3_cfb8(), EVP_des_ede3_cfb64(), EVP_des_ede3_ecb(), EVP_des_ede3_ofb()
-
- -

Three-key triple DES in ECB, CBC, CFB with 64-bit shift, CFB with 1-bit shift, CFB with 8-bit shift and OFB modes.

- -
-
EVP_des_ede3_wrap()
-
- -

Triple-DES key wrap according to RFC 3217 Section 3.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-DES(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_desx_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_desx_cbc.html deleted file mode 100644 index be2063c2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_desx_cbc.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -EVP_desx_cbc - - - - - - - - - - -

NAME

- -

EVP_desx_cbc - EVP DES-X cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_desx_cbc(void);
- -

DESCRIPTION

- -

The DES-X encryption algorithm for EVP.

- -

All modes below use a key length of 128 bits and acts on blocks of 128-bits.

- -
- -
EVP_desx_cbc()
-
- -

The DES-X algorithm in CBC mode.

- -

This algorithm is not provided by the OpenSSL default provider. To use it is necessary to load either the OpenSSL legacy provider or another implementation.

- -
-
- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-DES(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_idea_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_idea_cbc.html deleted file mode 100644 index e90dd1c0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_idea_cbc.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -EVP_idea_cbc - - - - - - - - - - -

NAME

- -

EVP_idea_cbc, EVP_idea_cfb, EVP_idea_cfb64, EVP_idea_ecb, EVP_idea_ofb - EVP IDEA cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_idea_cbc(void);
-const EVP_CIPHER *EVP_idea_cfb(void);
-const EVP_CIPHER *EVP_idea_cfb64(void);
-const EVP_CIPHER *EVP_idea_ecb(void);
-const EVP_CIPHER *EVP_idea_ofb(void);
- -

DESCRIPTION

- -

The IDEA encryption algorithm for EVP.

- -
- -
EVP_idea_cbc(), EVP_idea_cfb(), EVP_idea_cfb64(), EVP_idea_ecb(), EVP_idea_ofb()
-
- -

The IDEA encryption algorithm in CBC, CFB, ECB and OFB modes respectively.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-IDEA(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_md2.html b/openssl-install/share/doc/openssl/html/man3/EVP_md2.html deleted file mode 100644 index fe32742a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_md2.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_md2 - - - - - - - - - - -

NAME

- -

EVP_md2 - MD2 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_md2(void);
- -

DESCRIPTION

- -

MD2 is a cryptographic hash function standardized in RFC 1319 and designed by Ronald Rivest. This implementation is only available with the legacy provider.

- -
- -
EVP_md2()
-
- -

The MD2 algorithm which produces a 128-bit output from a given input.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-MD2(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

IETF RFC 1319.

- -

SEE ALSO

- -

evp(7), provider(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_md4.html b/openssl-install/share/doc/openssl/html/man3/EVP_md4.html deleted file mode 100644 index 4074db21..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_md4.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_md4 - - - - - - - - - - -

NAME

- -

EVP_md4 - MD4 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_md4(void);
- -

DESCRIPTION

- -

MD4 is a cryptographic hash function standardized in RFC 1320 and designed by Ronald Rivest, first published in 1990. This implementation is only available with the legacy provider.

- -
- -
EVP_md4()
-
- -

The MD4 algorithm which produces a 128-bit output from a given input.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-MD4(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

IETF RFC 1320.

- -

SEE ALSO

- -

evp(7), provider(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_md5.html b/openssl-install/share/doc/openssl/html/man3/EVP_md5.html deleted file mode 100644 index a18b4b00..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_md5.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -EVP_md5 - - - - - - - - - - -

NAME

- -

EVP_md5, EVP_md5_sha1 - MD5 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_md5(void);
-const EVP_MD *EVP_md5_sha1(void);
- -

DESCRIPTION

- -

MD5 is a cryptographic hash function standardized in RFC 1321 and designed by Ronald Rivest.

- -

The CMU Software Engineering Institute considers MD5 unsuitable for further use since its security has been severely compromised.

- -
- -
EVP_md5()
-
- -

The MD5 algorithm which produces a 128-bit output from a given input.

- -
-
EVP_md5_sha1()
-
- -

A hash algorithm of SSL v3 that combines MD5 with SHA-1 as described in RFC 6101.

- -

WARNING: this algorithm is not intended for non-SSL usage.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-MD5(7) or EVP_MD-MD5-SHA1(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

IETF RFC 1321.

- -

SEE ALSO

- -

evp(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_mdc2.html b/openssl-install/share/doc/openssl/html/man3/EVP_mdc2.html deleted file mode 100644 index 4db8847b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_mdc2.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_mdc2 - - - - - - - - - - -

NAME

- -

EVP_mdc2 - MDC-2 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_mdc2(void);
- -

DESCRIPTION

- -

MDC-2 (Modification Detection Code 2 or Meyer-Schilling) is a cryptographic hash function based on a block cipher. This implementation is only available with the legacy provider.

- -
- -
EVP_mdc2()
-
- -

The MDC-2DES algorithm of using MDC-2 with the DES block cipher. It produces a 128-bit output from a given input.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-MDC2(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

ISO/IEC 10118-2:2000 Hash-Function 2, with DES as the underlying block cipher.

- -

SEE ALSO

- -

evp(7), provider(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_rc2_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_rc2_cbc.html deleted file mode 100644 index 72f9c2a5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_rc2_cbc.html +++ /dev/null @@ -1,85 +0,0 @@ - - - - -EVP_rc2_cbc - - - - - - - - - - -

NAME

- -

EVP_rc2_cbc, EVP_rc2_cfb, EVP_rc2_cfb64, EVP_rc2_ecb, EVP_rc2_ofb, EVP_rc2_40_cbc, EVP_rc2_64_cbc - EVP RC2 cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_rc2_cbc(void);
-const EVP_CIPHER *EVP_rc2_cfb(void);
-const EVP_CIPHER *EVP_rc2_cfb64(void);
-const EVP_CIPHER *EVP_rc2_ecb(void);
-const EVP_CIPHER *EVP_rc2_ofb(void);
-const EVP_CIPHER *EVP_rc2_40_cbc(void);
-const EVP_CIPHER *EVP_rc2_64_cbc(void);
- -

DESCRIPTION

- -

The RC2 encryption algorithm for EVP.

- -
- -
EVP_rc2_cbc(), EVP_rc2_cfb(), EVP_rc2_cfb64(), EVP_rc2_ecb(), EVP_rc2_ofb()
-
- -

RC2 encryption algorithm in CBC, CFB, ECB and OFB modes respectively. This is a variable key length cipher with an additional parameter called "effective key bits" or "effective key length". By default both are set to 128 bits.

- -
-
EVP_rc2_40_cbc(), EVP_rc2_64_cbc()
-
- -

RC2 algorithm in CBC mode with a default key length and effective key length of 40 and 64 bits.

- -

WARNING: these functions are obsolete. Their usage should be replaced with the EVP_rc2_cbc(), EVP_CIPHER_CTX_set_key_length() and EVP_CIPHER_CTX_ctrl() functions to set the key length and effective key length.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-RC2(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_rc4.html b/openssl-install/share/doc/openssl/html/man3/EVP_rc4.html deleted file mode 100644 index bc6dd7db..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_rc4.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -EVP_rc4 - - - - - - - - - - -

NAME

- -

EVP_rc4, EVP_rc4_40, EVP_rc4_hmac_md5 - EVP RC4 stream cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_rc4(void);
-const EVP_CIPHER *EVP_rc4_40(void);
-const EVP_CIPHER *EVP_rc4_hmac_md5(void);
- -

DESCRIPTION

- -

The RC4 stream cipher for EVP.

- -
- -
EVP_rc4()
-
- -

RC4 stream cipher. This is a variable key length cipher with a default key length of 128 bits.

- -
-
EVP_rc4_40()
-
- -

RC4 stream cipher with 40 bit key length.

- -

WARNING: this function is obsolete. Its usage should be replaced with the EVP_rc4() and the EVP_CIPHER_CTX_set_key_length() functions.

- -
-
EVP_rc4_hmac_md5()
-
- -

Authenticated encryption with the RC4 stream cipher with MD5 as HMAC.

- -

WARNING: this is not intended for usage outside of TLS and requires calling of some undocumented ctrl functions. These ciphers do not conform to the EVP AEAD interface.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-RC4(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_rc5_32_12_16_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_rc5_32_12_16_cbc.html deleted file mode 100644 index ba0a5e9f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_rc5_32_12_16_cbc.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -EVP_rc5_32_12_16_cbc - - - - - - - - - - -

NAME

- -

EVP_rc5_32_12_16_cbc, EVP_rc5_32_12_16_cfb, EVP_rc5_32_12_16_cfb64, EVP_rc5_32_12_16_ecb, EVP_rc5_32_12_16_ofb - EVP RC5 cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_rc5_32_12_16_cbc(void);
-const EVP_CIPHER *EVP_rc5_32_12_16_cfb(void);
-const EVP_CIPHER *EVP_rc5_32_12_16_cfb64(void);
-const EVP_CIPHER *EVP_rc5_32_12_16_ecb(void);
-const EVP_CIPHER *EVP_rc5_32_12_16_ofb(void);
- -

DESCRIPTION

- -

The RC5 encryption algorithm for EVP.

- -
- -
EVP_rc5_32_12_16_cbc(), EVP_rc5_32_12_16_cfb(), EVP_rc5_32_12_16_cfb64(), EVP_rc5_32_12_16_ecb(), EVP_rc5_32_12_16_ofb()
-
- -

RC5 encryption algorithm in CBC, CFB, ECB and OFB modes respectively. This is a variable key length cipher with an additional "number of rounds" parameter. By default the key length is set to 128 bits and 12 rounds. Alternative key lengths can be set using EVP_CIPHER_CTX_set_key_length(3). The maximum key length is 2040 bits.

- -

The following rc5 specific ctrls are supported (see EVP_CIPHER_CTX_ctrl(3)).

- -
- -
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_SET_RC5_ROUNDS, rounds, NULL)
-
- -

Sets the number of rounds to rounds. This must be one of RC5_8_ROUNDS, RC5_12_ROUNDS or RC5_16_ROUNDS.

- -
-
EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GET_RC5_ROUNDS, 0, &rounds)
-
- -

Stores the number of rounds currently configured in *rounds where *rounds is an int.

- -
-
- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-RC5(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_ripemd160.html b/openssl-install/share/doc/openssl/html/man3/EVP_ripemd160.html deleted file mode 100644 index 3975e29f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_ripemd160.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_ripemd160 - - - - - - - - - - -

NAME

- -

EVP_ripemd160 - RIPEMD160 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_ripemd160(void);
- -

DESCRIPTION

- -

RIPEMD-160 is a cryptographic hash function first published in 1996 belonging to the RIPEMD family (RACE Integrity Primitives Evaluation Message Digest). This implementation is only available with the legacy provider.

- -
- -
EVP_ripemd160()
-
- -

The RIPEMD-160 algorithm which produces a 160-bit output from a given input.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-RIPEMD160(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

ISO/IEC 10118-3:2016 Dedicated Hash-Function 1 (RIPEMD-160).

- -

SEE ALSO

- -

evp(7), provider(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_seed_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_seed_cbc.html deleted file mode 100644 index 5b250e26..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_seed_cbc.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_seed_cbc - - - - - - - - - - -

NAME

- -

EVP_seed_cbc, EVP_seed_cfb, EVP_seed_cfb128, EVP_seed_ecb, EVP_seed_ofb - EVP SEED cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_seed_cbc(void);
-const EVP_CIPHER *EVP_seed_cfb(void);
-const EVP_CIPHER *EVP_seed_cfb128(void);
-const EVP_CIPHER *EVP_seed_ecb(void);
-const EVP_CIPHER *EVP_seed_ofb(void);
- -

DESCRIPTION

- -

The SEED encryption algorithm for EVP.

- -

All modes below use a key length of 128 bits and acts on blocks of 128-bits.

- -
- -
EVP_seed_cbc(), EVP_seed_cfb(), EVP_seed_cfb128(), EVP_seed_ecb(), EVP_seed_ofb()
-
- -

The SEED encryption algorithm in CBC, CFB, ECB and OFB modes respectively.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-SEED(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return an EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_set_default_properties.html b/openssl-install/share/doc/openssl/html/man3/EVP_set_default_properties.html deleted file mode 100644 index 3978d481..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_set_default_properties.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -EVP_set_default_properties - - - - - - - - - - -

NAME

- -

EVP_set_default_properties, EVP_default_properties_enable_fips, EVP_default_properties_is_fips_enabled - Set default properties for future algorithm fetches

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int EVP_set_default_properties(OSSL_LIB_CTX *libctx, const char *propq);
-int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable);
-int EVP_default_properties_is_fips_enabled(OSSL_LIB_CTX *libctx);
- -

DESCRIPTION

- -

EVP_set_default_properties() sets the default properties for all future EVP algorithm fetches, implicit as well as explicit. See "ALGORITHM FETCHING" in crypto(7) for information about implicit and explicit fetching.

- -

EVP_set_default_properties stores the properties given with the string propq among the EVP data that's been stored in the library context given with libctx (NULL signifies the default library context).

- -

Any previous default property for the specified library context will be dropped.

- -

EVP_default_properties_enable_fips() sets the 'fips=yes' to be a default property if enable is non zero, otherwise it clears 'fips' from the default property query for the given libctx. It merges the fips default property query with any existing query strings that have been set via EVP_set_default_properties().

- -

EVP_default_properties_is_fips_enabled() indicates if 'fips=yes' is a default property for the given libctx.

- -

NOTES

- -

EVP_set_default_properties() and EVP_default_properties_enable_fips() are not thread safe. They are intended to be called only during the initialisation phase of a libctx.

- -

RETURN VALUES

- -

EVP_set_default_properties() and EVP_default_properties_enable_fips() return 1 on success, or 0 on failure. An error is placed on the error stack if a failure occurs.

- -

EVP_default_properties_is_fips_enabled() returns 1 if the 'fips=yes' default property is set for the given libctx, otherwise it returns 0.

- -

SEE ALSO

- -

EVP_MD_fetch(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_sha1.html b/openssl-install/share/doc/openssl/html/man3/EVP_sha1.html deleted file mode 100644 index 9b752068..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_sha1.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_sha1 - - - - - - - - - - -

NAME

- -

EVP_sha1 - SHA-1 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_sha1(void);
- -

DESCRIPTION

- -

SHA-1 (Secure Hash Algorithm 1) is a cryptographic hash function standardized in NIST FIPS 180-4. The algorithm was designed by the United States National Security Agency and initially published in 1995.

- -
- -
EVP_sha1()
-
- -

The SHA-1 algorithm which produces a 160-bit output from a given input.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-SHA1(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

NIST FIPS 180-4.

- -

SEE ALSO

- -

evp(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_sha224.html b/openssl-install/share/doc/openssl/html/man3/EVP_sha224.html deleted file mode 100644 index d476645f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_sha224.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -EVP_sha224 - - - - - - - - - - -

NAME

- -

EVP_sha224, EVP_sha256, EVP_sha512_224, EVP_sha512_256, EVP_sha384, EVP_sha512 - SHA-2 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_sha224(void);
-const EVP_MD *EVP_sha256(void);
-const EVP_MD *EVP_sha512_224(void);
-const EVP_MD *EVP_sha512_256(void);
-const EVP_MD *EVP_sha384(void);
-const EVP_MD *EVP_sha512(void);
- -

DESCRIPTION

- -

SHA-2 (Secure Hash Algorithm 2) is a family of cryptographic hash functions standardized in NIST FIPS 180-4, first published in 2001.

- -
- -
EVP_sha224(), EVP_sha256(), EVP_sha512_224, EVP_sha512_256, EVP_sha384(), EVP_sha512()
-
- -

The SHA-2 SHA-224, SHA-256, SHA-512/224, SHA512/256, SHA-384 and SHA-512 algorithms, which generate 224, 256, 224, 256, 384 and 512 bits respectively of output from a given input.

- -

The two algorithms: SHA-512/224 and SHA512/256 are truncated forms of the SHA-512 algorithm. They are distinct from SHA-224 and SHA-256 even though their outputs are of the same size.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-SHA2(7)instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

NIST FIPS 180-4.

- -

SEE ALSO

- -

evp(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_sha3_224.html b/openssl-install/share/doc/openssl/html/man3/EVP_sha3_224.html deleted file mode 100644 index 301f5856..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_sha3_224.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -EVP_sha3_224 - - - - - - - - - - -

NAME

- -

EVP_sha3_224, EVP_sha3_256, EVP_sha3_384, EVP_sha3_512, EVP_shake128, EVP_shake256 - SHA-3 For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_sha3_224(void);
-const EVP_MD *EVP_sha3_256(void);
-const EVP_MD *EVP_sha3_384(void);
-const EVP_MD *EVP_sha3_512(void);
-
-const EVP_MD *EVP_shake128(void);
-const EVP_MD *EVP_shake256(void);
- -

DESCRIPTION

- -

SHA-3 (Secure Hash Algorithm 3) is a family of cryptographic hash functions standardized in NIST FIPS 202, first published in 2015. It is based on the Keccak algorithm.

- -
- -
EVP_sha3_224(), EVP_sha3_256(), EVP_sha3_384(), EVP_sha3_512()
-
- -

The SHA-3 SHA-3-224, SHA-3-256, SHA-3-384, and SHA-3-512 algorithms respectively. They produce 224, 256, 384 and 512 bits of output from a given input.

- -
-
EVP_shake128(), EVP_shake256()
-
- -

The SHAKE-128 and SHAKE-256 Extendable Output Functions (XOF) that can generate a variable hash length.

- -

Specifically, EVP_shake128 provides an overall security of 128 bits, while EVP_shake256 provides that of 256 bits.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-SHA3(7) or EVP_MD-SHAKE(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

NIST FIPS 202.

- -

SEE ALSO

- -

evp(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_sm3.html b/openssl-install/share/doc/openssl/html/man3/EVP_sm3.html deleted file mode 100644 index d01ff4cd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_sm3.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_sm3 - - - - - - - - - - -

NAME

- -

EVP_sm3 - SM3 for EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_sm3(void);
- -

DESCRIPTION

- -

SM3 is a cryptographic hash function with a 256-bit output, defined in GB/T 32905-2016.

- -
- -
EVP_sm3()
-
- -

The SM3 hash function.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-SM3(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

GB/T 32905-2016 and GM/T 0004-2012.

- -

SEE ALSO

- -

evp(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved. Copyright 2017 Ribose Inc. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_sm4_cbc.html b/openssl-install/share/doc/openssl/html/man3/EVP_sm4_cbc.html deleted file mode 100644 index b9ebb8b6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_sm4_cbc.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -EVP_sm4_cbc - - - - - - - - - - -

NAME

- -

EVP_sm4_cbc, EVP_sm4_ecb, EVP_sm4_cfb, EVP_sm4_cfb128, EVP_sm4_ofb, EVP_sm4_ctr - EVP SM4 cipher

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_CIPHER *EVP_sm4_cbc(void);
-const EVP_CIPHER *EVP_sm4_ecb(void);
-const EVP_CIPHER *EVP_sm4_cfb(void);
-const EVP_CIPHER *EVP_sm4_cfb128(void);
-const EVP_CIPHER *EVP_sm4_ofb(void);
-const EVP_CIPHER *EVP_sm4_ctr(void);
- -

DESCRIPTION

- -

The SM4 blockcipher (GB/T 32907-2016) for EVP.

- -

All modes below use a key length of 128 bits and acts on blocks of 128 bits.

- -
- -
EVP_sm4_cbc(), EVP_sm4_ecb(), EVP_sm4_cfb(), EVP_sm4_cfb128(), EVP_sm4_ofb(), EVP_sm4_ctr()
-
- -

The SM4 blockcipher with a 128-bit key in CBC, ECB, CFB, OFB and CTR modes respectively.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling these functions multiple times and should consider using EVP_CIPHER_fetch(3) with EVP_CIPHER-SM4(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_CIPHER structure that contains the implementation of the symmetric cipher. See EVP_CIPHER_meth_new(3) for details of the EVP_CIPHER structure.

- -

SEE ALSO

- -

evp(7), EVP_EncryptInit(3), EVP_CIPHER_meth_new(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved. Copyright 2017 Ribose Inc. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/EVP_whirlpool.html b/openssl-install/share/doc/openssl/html/man3/EVP_whirlpool.html deleted file mode 100644 index 9c69963e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/EVP_whirlpool.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -EVP_whirlpool - - - - - - - - - - -

NAME

- -

EVP_whirlpool - WHIRLPOOL For EVP

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-const EVP_MD *EVP_whirlpool(void);
- -

DESCRIPTION

- -

WHIRLPOOL is a cryptographic hash function standardized in ISO/IEC 10118-3:2004 designed by Vincent Rijmen and Paulo S. L. M. Barreto. This implementation is only available with the legacy provider.

- -
- -
EVP_whirlpool()
-
- -

The WHIRLPOOL algorithm that produces a message digest of 512-bits from a given input.

- -
-
- -

NOTES

- -

Developers should be aware of the negative performance implications of calling this function multiple times and should consider using EVP_MD_fetch(3) with EVP_MD-WHIRLPOOL(7) instead. See "Performance" in crypto(7) for further information.

- -

RETURN VALUES

- -

These functions return a EVP_MD structure that contains the implementation of the message digest. See EVP_MD_meth_new(3) for details of the EVP_MD structure.

- -

CONFORMING TO

- -

ISO/IEC 10118-3:2004.

- -

SEE ALSO

- -

evp(7), provider(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/GENERAL_NAME.html b/openssl-install/share/doc/openssl/html/man3/GENERAL_NAME.html deleted file mode 100644 index 1600cc27..00000000 --- a/openssl-install/share/doc/openssl/html/man3/GENERAL_NAME.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -GENERAL_NAME - - - - - - - - - - -

NAME

- -

GENERAL_NAME, GENERAL_NAME_set1_X509_NAME - GENERAL_NAME method routines

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-typedef struct GENERAL_NAME_st GENERAL_NAME;
-
-int GENERAL_NAME_set1_X509_NAME(GENERAL_NAME **tgt, const X509_NAME *src);
- -

DESCRIPTION

- -

GENERAL_NAME_set1_X509_NAME() creates a new GENERAL_NAME of type GEN_DIRNAME and populates it based on provided X509_NAME src which can be NULL. tgt must not be NULL. If successful, *tgt will be set to point to the newly created GENERAL_NAME.

- -

RETURN VALUES

- -

GENERAL_NAME_set1_X509_NAME() return 1 on success, 0 on error.

- -

HISTORY

- -

GENERAL_NAME_set1_X509_NAME() was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/HMAC.html b/openssl-install/share/doc/openssl/html/man3/HMAC.html deleted file mode 100644 index 136615b7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/HMAC.html +++ /dev/null @@ -1,143 +0,0 @@ - - - - -HMAC - - - - - - - - - - -

NAME

- -

HMAC, HMAC_CTX_new, HMAC_CTX_reset, HMAC_CTX_free, HMAC_Init, HMAC_Init_ex, HMAC_Update, HMAC_Final, HMAC_CTX_copy, HMAC_CTX_set_flags, HMAC_CTX_get_md, HMAC_size - HMAC message authentication code

- -

SYNOPSIS

- -
#include <openssl/hmac.h>
-
-unsigned char *HMAC(const EVP_MD *evp_md, const void *key, int key_len,
-                    const unsigned char *data, size_t data_len,
-                    unsigned char *md, unsigned int *md_len);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
HMAC_CTX *HMAC_CTX_new(void);
-int HMAC_CTX_reset(HMAC_CTX *ctx);
-
-int HMAC_Init_ex(HMAC_CTX *ctx, const void *key, int key_len,
-                 const EVP_MD *md, ENGINE *impl);
-int HMAC_Update(HMAC_CTX *ctx, const unsigned char *data, size_t len);
-int HMAC_Final(HMAC_CTX *ctx, unsigned char *md, unsigned int *len);
-
-void HMAC_CTX_free(HMAC_CTX *ctx);
-
-int HMAC_CTX_copy(HMAC_CTX *dctx, HMAC_CTX *sctx);
-void HMAC_CTX_set_flags(HMAC_CTX *ctx, unsigned long flags);
-const EVP_MD *HMAC_CTX_get_md(const HMAC_CTX *ctx);
-
-size_t HMAC_size(const HMAC_CTX *e);
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int HMAC_Init(HMAC_CTX *ctx, const void *key, int key_len,
-              const EVP_MD *md);
- -

DESCRIPTION

- -

HMAC is a MAC (message authentication code), i.e. a keyed hash function used for message authentication, which is based on a hash function.

- -

HMAC() computes the message authentication code of the data_len bytes at data using the hash function evp_md and the key key which is key_len bytes long. The key may also be NULL with key_len being 0.

- -

It places the result in md (which must have space for the output of the hash function, which is no more than EVP_MAX_MD_SIZE bytes). If md is NULL, the digest is placed in a static array. The size of the output is placed in md_len, unless it is NULL. Note: passing a NULL value for md to use the static array is not thread safe.

- -

evp_md is a message digest such as EVP_sha1(), EVP_ripemd160() etc. HMAC does not support variable output length digests such as EVP_shake128() and EVP_shake256().

- -

HMAC() uses the default OSSL_LIB_CTX. Use EVP_Q_mac(3) instead if a library context is required.

- -

All of the functions described below are deprecated. Applications should instead use EVP_MAC_CTX_new(3), EVP_MAC_CTX_free(3), EVP_MAC_init(3), EVP_MAC_update(3) and EVP_MAC_final(3) or the 'quick' single-shot MAC function EVP_Q_mac(3).

- -

HMAC_CTX_new() creates a new HMAC_CTX in heap memory.

- -

HMAC_CTX_reset() clears an existing HMAC_CTX and associated resources, making it suitable for new computations as if it was newly created with HMAC_CTX_new().

- -

HMAC_CTX_free() erases the key and other data from the HMAC_CTX, releases any associated resources and finally frees the HMAC_CTX itself. If the argument is NULL, nothing is done.

- -

The following functions may be used if the message is not completely stored in memory:

- -

HMAC_Init_ex() initializes or reuses a HMAC_CTX structure to use the hash function evp_md and key key. If both are NULL, or if key is NULL and evp_md is the same as the previous call, then the existing key is reused. ctx must have been created with HMAC_CTX_new() before the first use of an HMAC_CTX in this function.

- -

If HMAC_Init_ex() is called with key NULL and evp_md is not the same as the previous digest used by ctx then an error is returned because reuse of an existing key with a different digest is not supported.

- -

HMAC_Init() initializes a HMAC_CTX structure to use the hash function evp_md and the key key which is key_len bytes long.

- -

HMAC_Update() can be called repeatedly with chunks of the message to be authenticated (len bytes at data).

- -

HMAC_Final() places the message authentication code in md, which must have space for the hash function output.

- -

HMAC_CTX_copy() copies all of the internal state from sctx into dctx.

- -

HMAC_CTX_set_flags() applies the specified flags to the internal EVP_MD_CTXs. These flags have the same meaning as for EVP_MD_CTX_set_flags(3).

- -

HMAC_CTX_get_md() returns the EVP_MD that has previously been set for the supplied HMAC_CTX.

- -

HMAC_size() returns the length in bytes of the underlying hash function output.

- -

RETURN VALUES

- -

HMAC() returns a pointer to the message authentication code or NULL if an error occurred.

- -

HMAC_CTX_new() returns a pointer to a new HMAC_CTX on success or NULL if an error occurred.

- -

HMAC_CTX_reset(), HMAC_Init_ex(), HMAC_Update(), HMAC_Final() and HMAC_CTX_copy() return 1 for success or 0 if an error occurred.

- -

HMAC_CTX_get_md() return the EVP_MD previously set for the supplied HMAC_CTX or NULL if no EVP_MD has been set.

- -

HMAC_size() returns the length in bytes of the underlying hash function output or zero on error.

- -

CONFORMING TO

- -

RFC 2104

- -

SEE ALSO

- -

SHA1(3), EVP_Q_mac(3), evp(7)

- -

HISTORY

- -

All functions except for HMAC() were deprecated in OpenSSL 3.0.

- -

HMAC_CTX_init() was replaced with HMAC_CTX_reset() in OpenSSL 1.1.0.

- -

HMAC_CTX_cleanup() existed in OpenSSL before version 1.1.0.

- -

HMAC_CTX_new(), HMAC_CTX_free() and HMAC_CTX_get_md() are new in OpenSSL 1.1.0.

- -

HMAC_Init_ex(), HMAC_Update() and HMAC_Final() did not return values in OpenSSL before version 1.0.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/MD5.html b/openssl-install/share/doc/openssl/html/man3/MD5.html deleted file mode 100644 index cf94230b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/MD5.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -MD5 - - - - - - - - - - -

NAME

- -

MD2, MD4, MD5, MD2_Init, MD2_Update, MD2_Final, MD4_Init, MD4_Update, MD4_Final, MD5_Init, MD5_Update, MD5_Final - MD2, MD4, and MD5 hash functions

- -

SYNOPSIS

- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#include <openssl/md2.h>
-
-unsigned char *MD2(const unsigned char *d, unsigned long n, unsigned char *md);
-
-int MD2_Init(MD2_CTX *c);
-int MD2_Update(MD2_CTX *c, const unsigned char *data, unsigned long len);
-int MD2_Final(unsigned char *md, MD2_CTX *c);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#include <openssl/md4.h>
-
-unsigned char *MD4(const unsigned char *d, unsigned long n, unsigned char *md);
-
-int MD4_Init(MD4_CTX *c);
-int MD4_Update(MD4_CTX *c, const void *data, unsigned long len);
-int MD4_Final(unsigned char *md, MD4_CTX *c);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#include <openssl/md5.h>
-
-unsigned char *MD5(const unsigned char *d, unsigned long n, unsigned char *md);
-
-int MD5_Init(MD5_CTX *c);
-int MD5_Update(MD5_CTX *c, const void *data, unsigned long len);
-int MD5_Final(unsigned char *md, MD5_CTX *c);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_DigestInit_ex(3), EVP_DigestUpdate(3) and EVP_DigestFinal_ex(3).

- -

MD2, MD4, and MD5 are cryptographic hash functions with a 128 bit output.

- -

MD2(), MD4(), and MD5() compute the MD2, MD4, and MD5 message digest of the n bytes at d and place it in md (which must have space for MD2_DIGEST_LENGTH == MD4_DIGEST_LENGTH == MD5_DIGEST_LENGTH == 16 bytes of output). If md is NULL, the digest is placed in a static array.

- -

The following functions may be used if the message is not completely stored in memory:

- -

MD2_Init() initializes a MD2_CTX structure.

- -

MD2_Update() can be called repeatedly with chunks of the message to be hashed (len bytes at data).

- -

MD2_Final() places the message digest in md, which must have space for MD2_DIGEST_LENGTH == 16 bytes of output, and erases the MD2_CTX.

- -

MD4_Init(), MD4_Update(), MD4_Final(), MD5_Init(), MD5_Update(), and MD5_Final() are analogous using an MD4_CTX and MD5_CTX structure.

- -

Applications should use the higher level functions EVP_DigestInit(3) etc. instead of calling the hash functions directly.

- -

NOTE

- -

MD2, MD4, and MD5 are recommended only for compatibility with existing applications. In new applications, hashes from the SHA-2 or SHA-3 family should be preferred.

- -

RETURN VALUES

- -

MD2(), MD4(), and MD5() return pointers to the hash value.

- -

MD2_Init(), MD2_Update(), MD2_Final(), MD4_Init(), MD4_Update(), MD4_Final(), MD5_Init(), MD5_Update(), and MD5_Final() return 1 for success, 0 otherwise.

- -

CONFORMING TO

- -

RFC 1319, RFC 1320, RFC 1321

- -

SEE ALSO

- -

EVP_DigestInit(3), EVP_MD-SHA2(7), EVP_MD-SHA3(7)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/MDC2_Init.html b/openssl-install/share/doc/openssl/html/man3/MDC2_Init.html deleted file mode 100644 index 8a1ebf6b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/MDC2_Init.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -MDC2_Init - - - - - - - - - - -

NAME

- -

MDC2, MDC2_Init, MDC2_Update, MDC2_Final - MDC2 hash function

- -

SYNOPSIS

- -
#include <openssl/mdc2.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
unsigned char *MDC2(const unsigned char *d, unsigned long n,
-                    unsigned char *md);
-
-int MDC2_Init(MDC2_CTX *c);
-int MDC2_Update(MDC2_CTX *c, const unsigned char *data,
-                unsigned long len);
-int MDC2_Final(unsigned char *md, MDC2_CTX *c);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_DigestInit_ex(3), EVP_DigestUpdate(3) and EVP_DigestFinal_ex(3).

- -

MDC2 is a method to construct hash functions with 128 bit output from block ciphers. These functions are an implementation of MDC2 with DES.

- -

MDC2() computes the MDC2 message digest of the n bytes at d and places it in md (which must have space for MDC2_DIGEST_LENGTH == 16 bytes of output). If md is NULL, the digest is placed in a static array.

- -

The following functions may be used if the message is not completely stored in memory:

- -

MDC2_Init() initializes a MDC2_CTX structure.

- -

MDC2_Update() can be called repeatedly with chunks of the message to be hashed (len bytes at data).

- -

MDC2_Final() places the message digest in md, which must have space for MDC2_DIGEST_LENGTH == 16 bytes of output, and erases the MDC2_CTX.

- -

Applications should use the higher level functions EVP_DigestInit(3) etc. instead of calling the hash functions directly.

- -

RETURN VALUES

- -

MDC2() returns a pointer to the hash value.

- -

MDC2_Init(), MDC2_Update() and MDC2_Final() return 1 for success, 0 otherwise.

- -

CONFORMING TO

- -

ISO/IEC 10118-2:2000 Hash-Function 2, with DES as the underlying block cipher.

- -

SEE ALSO

- -

EVP_DigestInit(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/NCONF_new_ex.html b/openssl-install/share/doc/openssl/html/man3/NCONF_new_ex.html deleted file mode 100644 index f4063cb2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/NCONF_new_ex.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -NCONF_new_ex - - - - - - - - - - -

NAME

- -

NCONF_new_ex, NCONF_new, NCONF_free, NCONF_default, NCONF_load, NCONF_get0_libctx, NCONF_get_section, NCONF_get_section_names - functionality to Load and parse configuration files manually

- -

SYNOPSIS

- -
#include <openssl/conf.h>
-
-typedef struct {
-    char *section;
-    char *name;
-    char *value;
-} CONF_VALUE;
-
-CONF *NCONF_new_ex(OSSL_LIB_CTX *libctx, CONF_METHOD *meth);
-CONF *NCONF_new(CONF_METHOD *meth);
-void NCONF_free(CONF *conf);
-CONF_METHOD *NCONF_default(void);
-int NCONF_load(CONF *conf, const char *file, long *eline);
-OSSL_LIB_CTX *NCONF_get0_libctx(const CONF *conf);
-
-STACK_OF(CONF_VALUE) *NCONF_get_section(const CONF *conf, const char *name);
-STACK_OF(OPENSSL_CSTRING) *NCONF_get_section_names(const CONF *conf);
- -

DESCRIPTION

- -

NCONF_new_ex() creates a new CONF object in heap memory and assigns to it a context libctx that can be used during loading. If the method table meth is set to NULL then the default value of NCONF_default() is used.

- -

NCONF_new() is similar to NCONF_new_ex() but sets the libctx to NULL.

- -

NCONF_free() frees the data associated with conf and then frees the conf object. If the argument is NULL, nothing is done.

- -

NCONF_load() parses the file named filename and adds the values found to conf. If an error occurs file and eline list the file and line that the load failed on if they are not NULL.

- -

NCONF_default() gets the default method table for processing a configuration file.

- -

NCONF_get0_libctx() gets the library context associated with the conf parameter.

- -

NCONF_get_section_names() gets the names of the sections associated with the conf as STACK_OF(OPENSSL_CSTRING) strings. The individual strings are associated with the conf and will be invalid after conf is freed. The returned stack must be freed with sk_OPENSSL_CSTRING_free().

- -

NCONF_get_section() gets the config values associated with the conf from the config section name as STACK_OF(CONF_VALUE) structures. The returned stack is associated with the conf and will be invalid after conf is freed. It must not be freed by the caller.

- -

RETURN VALUES

- -

NCONF_load() returns 1 on success or 0 on error.

- -

NCONF_new_ex() and NCONF_new() return a newly created CONF object or NULL if an error occurs.

- -

SEE ALSO

- -

CONF_modules_load_file(3),

- -

HISTORY

- -

NCONF_new_ex(), NCONF_get0_libctx(), and NCONF_get_section_names() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OBJ_nid2obj.html b/openssl-install/share/doc/openssl/html/man3/OBJ_nid2obj.html deleted file mode 100644 index 3258ce68..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OBJ_nid2obj.html +++ /dev/null @@ -1,168 +0,0 @@ - - - - -OBJ_nid2obj - - - - - - - - - - -

NAME

- -

i2t_ASN1_OBJECT, OBJ_length, OBJ_get0_data, OBJ_nid2obj, OBJ_nid2ln, OBJ_nid2sn, OBJ_obj2nid, OBJ_txt2nid, OBJ_ln2nid, OBJ_sn2nid, OBJ_cmp, OBJ_dup, OBJ_txt2obj, OBJ_obj2txt, OBJ_create, OBJ_cleanup, OBJ_add_sigid - ASN1 object utility functions

- -

SYNOPSIS

- -
#include <openssl/objects.h>
-
-ASN1_OBJECT *OBJ_nid2obj(int n);
-const char *OBJ_nid2ln(int n);
-const char *OBJ_nid2sn(int n);
-
-int OBJ_obj2nid(const ASN1_OBJECT *o);
-int OBJ_ln2nid(const char *ln);
-int OBJ_sn2nid(const char *sn);
-
-int OBJ_txt2nid(const char *s);
-
-ASN1_OBJECT *OBJ_txt2obj(const char *s, int no_name);
-int OBJ_obj2txt(char *buf, int buf_len, const ASN1_OBJECT *a, int no_name);
-
-int i2t_ASN1_OBJECT(char *buf, int buf_len, const ASN1_OBJECT *a);
-
-int OBJ_cmp(const ASN1_OBJECT *a, const ASN1_OBJECT *b);
-ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o);
-
-int OBJ_create(const char *oid, const char *sn, const char *ln);
-
-size_t OBJ_length(const ASN1_OBJECT *obj);
-const unsigned char *OBJ_get0_data(const ASN1_OBJECT *obj);
-
-int OBJ_add_sigid(int signid, int dig_id, int pkey_id);
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void OBJ_cleanup(void);
- -

DESCRIPTION

- -

The ASN1 object utility functions process ASN1_OBJECT structures which are a representation of the ASN1 OBJECT IDENTIFIER (OID) type. For convenience, OIDs are usually represented in source code as numeric identifiers, or NIDs. OpenSSL has an internal table of OIDs that are generated when the library is built, and their corresponding NIDs are available as defined constants. For the functions below, application code should treat all returned values -- OIDs, NIDs, or names -- as constants.

- -

OBJ_nid2obj(), OBJ_nid2ln() and OBJ_nid2sn() convert the NID n to an ASN1_OBJECT structure, its long name and its short name respectively, or NULL if an error occurred.

- -

OBJ_obj2nid(), OBJ_ln2nid(), OBJ_sn2nid() return the corresponding NID for the object o, the long name ln or the short name sn respectively or NID_undef if an error occurred.

- -

OBJ_txt2nid() returns NID corresponding to text string s. s can be a long name, a short name or the numerical representation of an object.

- -

OBJ_txt2obj() converts the text string s into an ASN1_OBJECT structure. If no_name is 0 then long names and short names will be interpreted as well as numerical forms. If no_name is 1 only the numerical form is acceptable.

- -

OBJ_obj2txt() converts the ASN1_OBJECT a into a textual representation. Unless buf is NULL, the representation is written as a NUL-terminated string to buf, where at most buf_len bytes are written, truncating the result if necessary. In any case it returns the total string length, excluding the NUL character, required for non-truncated representation, or -1 on error. If no_name is 0 then if the object has a long or short name then that will be used, otherwise the numerical form will be used. If no_name is 1 then the numerical form will always be used.

- -

i2t_ASN1_OBJECT() is the same as OBJ_obj2txt() with the no_name set to zero.

- -

OBJ_cmp() compares a to b. If the two are identical 0 is returned.

- -

OBJ_dup() returns a copy of o.

- -

OBJ_create() adds a new object to the internal table. oid is the numerical form of the object, sn the short name and ln the long name. A new NID is returned for the created object in case of success and NID_undef in case of failure. Any of oid, sn and ln may be NULL, but not all at once.

- -

OBJ_length() returns the size of the content octets of obj.

- -

OBJ_get0_data() returns a pointer to the content octets of obj. The returned pointer is an internal pointer which must not be freed.

- -

OBJ_add_sigid() creates a new composite "Signature Algorithm" that associates a given NID with two other NIDs - one representing the underlying signature algorithm and the other representing a digest algorithm to be used in conjunction with it. signid represents the NID for the composite "Signature Algorithm", dig_id is the NID for the digest algorithm and pkey_id is the NID for the underlying signature algorithm. As there are signature algorithms that do not require a digest, NID_undef is a valid dig_id.

- -

OBJ_cleanup() releases any resources allocated by creating new objects.

- -

NOTES

- -

Objects in OpenSSL can have a short name, a long name and a numerical identifier (NID) associated with them. A standard set of objects is represented in an internal table. The appropriate values are defined in the header file objects.h.

- -

For example the OID for commonName has the following definitions:

- -
#define SN_commonName                   "CN"
-#define LN_commonName                   "commonName"
-#define NID_commonName                  13
- -

New objects can be added by calling OBJ_create().

- -

Table objects have certain advantages over other objects: for example their NIDs can be used in a C language switch statement. They are also static constant structures which are shared: that is there is only a single constant structure for each table object.

- -

Objects which are not in the table have the NID value NID_undef.

- -

Objects do not need to be in the internal tables to be processed, the functions OBJ_txt2obj() and OBJ_obj2txt() can process the numerical form of an OID.

- -

Some objects are used to represent algorithms which do not have a corresponding ASN.1 OBJECT IDENTIFIER encoding (for example no OID currently exists for a particular algorithm). As a result they cannot be encoded or decoded as part of ASN.1 structures. Applications can determine if there is a corresponding OBJECT IDENTIFIER by checking OBJ_length() is not zero.

- -

These functions cannot return const because an ASN1_OBJECT can represent both an internal, constant, OID and a dynamically-created one. The latter cannot be constant because it needs to be freed after use.

- -

These functions were not thread safe in OpenSSL 3.0 and before.

- -

RETURN VALUES

- -

OBJ_nid2obj() returns an ASN1_OBJECT structure or NULL is an error occurred.

- -

OBJ_nid2ln() and OBJ_nid2sn() returns a valid string or NULL on error.

- -

OBJ_obj2nid(), OBJ_ln2nid(), OBJ_sn2nid() and OBJ_txt2nid() return a NID or NID_undef on error.

- -

OBJ_add_sigid() returns 1 on success or 0 on error.

- -

i2t_ASN1_OBJECT() an OBJ_obj2txt() return -1 on error. On success, they return the length of the string written to buf if buf is not NULL and buf_len is big enough, otherwise the total string length. Note that this does not count the trailing NUL character.

- -

EXAMPLES

- -

Create an object for commonName:

- -
ASN1_OBJECT *o = OBJ_nid2obj(NID_commonName);
- -

Check if an object is commonName

- -
if (OBJ_obj2nid(obj) == NID_commonName)
-    /* Do something */
- -

Create a new NID and initialize an object from it:

- -
int new_nid = OBJ_create("1.2.3.4", "NewOID", "New Object Identifier");
-ASN1_OBJECT *obj = OBJ_nid2obj(new_nid);
- -

Create a new object directly:

- -
obj = OBJ_txt2obj("1.2.3.4", 1);
- -

SEE ALSO

- -

ERR_get_error(3)

- -

HISTORY

- -

OBJ_cleanup() was deprecated in OpenSSL 1.1.0 by OPENSSL_init_crypto(3) and should not be used.

- -

COPYRIGHT

- -

Copyright 2002-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OCSP_REQUEST_new.html b/openssl-install/share/doc/openssl/html/man3/OCSP_REQUEST_new.html deleted file mode 100644 index ebbfa8d4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OCSP_REQUEST_new.html +++ /dev/null @@ -1,117 +0,0 @@ - - - - -OCSP_REQUEST_new - - - - - - - - - - -

NAME

- -

OCSP_REQUEST_new, OCSP_REQUEST_free, OCSP_request_add0_id, OCSP_request_sign, OCSP_request_add1_cert, OCSP_request_onereq_count, OCSP_request_onereq_get0 - OCSP request functions

- -

SYNOPSIS

- -
#include <openssl/ocsp.h>
-
-OCSP_REQUEST *OCSP_REQUEST_new(void);
-void OCSP_REQUEST_free(OCSP_REQUEST *req);
-
-OCSP_ONEREQ *OCSP_request_add0_id(OCSP_REQUEST *req, OCSP_CERTID *cid);
-
-int OCSP_request_sign(OCSP_REQUEST *req,
-                      X509 *signer, EVP_PKEY *key, const EVP_MD *dgst,
-                      STACK_OF(X509) *certs, unsigned long flags);
-
-int OCSP_request_add1_cert(OCSP_REQUEST *req, X509 *cert);
-
-int OCSP_request_onereq_count(OCSP_REQUEST *req);
-OCSP_ONEREQ *OCSP_request_onereq_get0(OCSP_REQUEST *req, int i);
- -

DESCRIPTION

- -

OCSP_REQUEST_new() allocates and returns an empty OCSP_REQUEST structure.

- -

OCSP_REQUEST_free() frees up the request structure req. If the argument is NULL, nothing is done.

- -

OCSP_request_add0_id() adds certificate ID cid to req. It returns the OCSP_ONEREQ structure added so an application can add additional extensions to the request. The id parameter MUST NOT be freed up after the operation.

- -

OCSP_request_sign() signs OCSP request req using certificate signer, private key key, digest dgst and additional certificates certs. If the flags option OCSP_NOCERTS is set then no certificates will be included in the request.

- -

OCSP_request_add1_cert() adds certificate cert to request req. The application is responsible for freeing up cert after use.

- -

OCSP_request_onereq_count() returns the total number of OCSP_ONEREQ structures in req.

- -

OCSP_request_onereq_get0() returns an internal pointer to the OCSP_ONEREQ contained in req of index i. The index value i runs from 0 to OCSP_request_onereq_count(req) - 1.

- -

RETURN VALUES

- -

OCSP_REQUEST_new() returns an empty OCSP_REQUEST structure or NULL if an error occurred.

- -

OCSP_request_add0_id() returns the OCSP_ONEREQ structure containing cid or NULL if an error occurred.

- -

OCSP_request_sign() and OCSP_request_add1_cert() return 1 for success and 0 for failure.

- -

OCSP_request_onereq_count() returns the total number of OCSP_ONEREQ structures in req and -1 on error.

- -

OCSP_request_onereq_get0() returns a pointer to an OCSP_ONEREQ structure or NULL if the index value is out or range.

- -

NOTES

- -

An OCSP request structure contains one or more OCSP_ONEREQ structures corresponding to each certificate.

- -

OCSP_request_onereq_count() and OCSP_request_onereq_get0() are mainly used by OCSP responders.

- -

EXAMPLES

- -

Create an OCSP_REQUEST structure for certificate cert with issuer issuer:

- -
OCSP_REQUEST *req;
-OCSP_ID *cid;
-
-req = OCSP_REQUEST_new();
-if (req == NULL)
-   /* error */
-cid = OCSP_cert_to_id(EVP_sha1(), cert, issuer);
-if (cid == NULL)
-   /* error */
-
-if (OCSP_REQUEST_add0_id(req, cid) == NULL)
-   /* error */
-
-/* Do something with req, e.g. query responder */
-
-OCSP_REQUEST_free(req);
- -

SEE ALSO

- -

crypto(7), OCSP_cert_to_id(3), OCSP_request_add1_nonce(3), OCSP_resp_find_status(3), OCSP_response_status(3), OCSP_sendreq_new(3)

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OCSP_cert_to_id.html b/openssl-install/share/doc/openssl/html/man3/OCSP_cert_to_id.html deleted file mode 100644 index ec7728a9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OCSP_cert_to_id.html +++ /dev/null @@ -1,94 +0,0 @@ - - - - -OCSP_cert_to_id - - - - - - - - - - -

NAME

- -

OCSP_cert_to_id, OCSP_cert_id_new, OCSP_CERTID_free, OCSP_id_issuer_cmp, OCSP_id_cmp, OCSP_id_get0_info - OCSP certificate ID utility functions

- -

SYNOPSIS

- -
#include <openssl/ocsp.h>
-
-OCSP_CERTID *OCSP_cert_to_id(const EVP_MD *dgst,
-                             X509 *subject, X509 *issuer);
-
-OCSP_CERTID *OCSP_cert_id_new(const EVP_MD *dgst,
-                              X509_NAME *issuerName,
-                              ASN1_BIT_STRING *issuerKey,
-                              ASN1_INTEGER *serialNumber);
-
-void OCSP_CERTID_free(OCSP_CERTID *id);
-
-int OCSP_id_issuer_cmp(const OCSP_CERTID *a, const OCSP_CERTID *b);
-int OCSP_id_cmp(const OCSP_CERTID *a, const OCSP_CERTID *b);
-
-int OCSP_id_get0_info(ASN1_OCTET_STRING **piNameHash, ASN1_OBJECT **pmd,
-                      ASN1_OCTET_STRING **pikeyHash,
-                      ASN1_INTEGER **pserial, OCSP_CERTID *cid);
- -

DESCRIPTION

- -

OCSP_cert_to_id() creates and returns a new OCSP_CERTID structure using message digest dgst for certificate subject with issuer issuer. If dgst is NULL then SHA1 is used.

- -

OCSP_cert_id_new() creates and returns a new OCSP_CERTID using dgst and issuer name issuerName, issuer key hash issuerKey and serial number serialNumber.

- -

OCSP_CERTID_free() frees up id. If the argument is NULL, nothing is done.

- -

OCSP_id_cmp() compares OCSP_CERTID a and b.

- -

OCSP_id_issuer_cmp() compares only the issuer name of OCSP_CERTID a and b.

- -

OCSP_id_get0_info() returns the issuer name hash, hash OID, issuer key hash and serial number contained in cid. If any of the values are not required the corresponding parameter can be set to NULL.

- -

RETURN VALUES

- -

OCSP_cert_to_id() and OCSP_cert_id_new() return either a pointer to a valid OCSP_CERTID structure or NULL if an error occurred.

- -

OCSP_id_cmp() and OCSP_id_issuer_cmp() returns zero for a match and nonzero otherwise.

- -

OCSP_CERTID_free() does not return a value.

- -

OCSP_id_get0_info() returns 1 for success and 0 for failure.

- -

NOTES

- -

OCSP clients will typically only use OCSP_cert_to_id() or OCSP_cert_id_new(): the other functions are used by responder applications.

- -

The values returned by OCSP_id_get0_info() are internal pointers and MUST NOT be freed up by an application: they will be freed when the corresponding OCSP_CERTID structure is freed.

- -

SEE ALSO

- -

crypto(7), OCSP_request_add1_nonce(3), OCSP_REQUEST_new(3), OCSP_resp_find_status(3), OCSP_response_status(3), OCSP_sendreq_new(3)

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OCSP_request_add1_nonce.html b/openssl-install/share/doc/openssl/html/man3/OCSP_request_add1_nonce.html deleted file mode 100644 index 421407ec..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OCSP_request_add1_nonce.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -OCSP_request_add1_nonce - - - - - - - - - - -

NAME

- -

OCSP_request_add1_nonce, OCSP_basic_add1_nonce, OCSP_check_nonce, OCSP_copy_nonce - OCSP nonce functions

- -

SYNOPSIS

- -
#include <openssl/ocsp.h>
-
-int OCSP_request_add1_nonce(OCSP_REQUEST *req, unsigned char *val, int len);
-int OCSP_basic_add1_nonce(OCSP_BASICRESP *resp, unsigned char *val, int len);
-int OCSP_copy_nonce(OCSP_BASICRESP *resp, OCSP_REQUEST *req);
-int OCSP_check_nonce(OCSP_REQUEST *req, OCSP_BASICRESP *resp);
- -

DESCRIPTION

- -

OCSP_request_add1_nonce() adds a nonce of value val and length len to OCSP request req. If val is NULL a random nonce is used. If len is zero or negative a default length will be used (currently 16 bytes).

- -

OCSP_basic_add1_nonce() is identical to OCSP_request_add1_nonce() except it adds a nonce to OCSP basic response resp.

- -

OCSP_check_nonce() compares the nonce value in req and resp.

- -

OCSP_copy_nonce() copies any nonce value present in req to resp.

- -

RETURN VALUES

- -

OCSP_request_add1_nonce() and OCSP_basic_add1_nonce() return 1 for success and 0 for failure.

- -

OCSP_copy_nonce() returns 1 if a nonce was successfully copied, 2 if no nonce was present in req and 0 if an error occurred.

- -

OCSP_check_nonce() returns the result of the nonce comparison between req and resp. The return value indicates the result of the comparison. If nonces are present and equal 1 is returned. If the nonces are absent 2 is returned. If a nonce is present in the response only 3 is returned. If nonces are present and unequal 0 is returned. If the nonce is present in the request only then -1 is returned.

- -

NOTES

- -

For most purposes the nonce value in a request is set to a random value so the val parameter in OCSP_request_add1_nonce() is usually NULL.

- -

An OCSP nonce is typically added to an OCSP request to thwart replay attacks by checking the same nonce value appears in the response.

- -

Some responders may include a nonce in all responses even if one is not supplied.

- -

Some responders cache OCSP responses and do not sign each response for performance reasons. As a result they do not support nonces.

- -

The return values of OCSP_check_nonce() can be checked to cover each case. A positive return value effectively indicates success: nonces are both present and match, both absent or present in the response only. A nonzero return additionally covers the case where the nonce is present in the request only: this will happen if the responder doesn't support nonces. A zero return value indicates present and mismatched nonces: this should be treated as an error condition.

- -

SEE ALSO

- -

crypto(7), OCSP_cert_to_id(3), OCSP_REQUEST_new(3), OCSP_resp_find_status(3), OCSP_response_status(3), OCSP_sendreq_new(3)

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OCSP_resp_find_status.html b/openssl-install/share/doc/openssl/html/man3/OCSP_resp_find_status.html deleted file mode 100644 index fe09bb81..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OCSP_resp_find_status.html +++ /dev/null @@ -1,156 +0,0 @@ - - - - -OCSP_resp_find_status - - - - - - - - - - -

NAME

- -

OCSP_resp_find_status, OCSP_resp_count, OCSP_resp_get0, OCSP_resp_find, OCSP_single_get0_status, OCSP_resp_get0_produced_at, OCSP_resp_get0_signature, OCSP_resp_get0_tbs_sigalg, OCSP_resp_get0_respdata, OCSP_resp_get0_certs, OCSP_resp_get0_signer, OCSP_resp_get0_id, OCSP_resp_get1_id, OCSP_check_validity, OCSP_basic_verify - OCSP response utility functions

- -

SYNOPSIS

- -
#include <openssl/ocsp.h>
-
-int OCSP_resp_find_status(OCSP_BASICRESP *bs, OCSP_CERTID *id, int *status,
-                          int *reason,
-                          ASN1_GENERALIZEDTIME **revtime,
-                          ASN1_GENERALIZEDTIME **thisupd,
-                          ASN1_GENERALIZEDTIME **nextupd);
-
-int OCSP_resp_count(OCSP_BASICRESP *bs);
-OCSP_SINGLERESP *OCSP_resp_get0(OCSP_BASICRESP *bs, int idx);
-int OCSP_resp_find(OCSP_BASICRESP *bs, OCSP_CERTID *id, int last);
-int OCSP_single_get0_status(OCSP_SINGLERESP *single, int *reason,
-                            ASN1_GENERALIZEDTIME **revtime,
-                            ASN1_GENERALIZEDTIME **thisupd,
-                            ASN1_GENERALIZEDTIME **nextupd);
-
-const ASN1_GENERALIZEDTIME *OCSP_resp_get0_produced_at(
-                            const OCSP_BASICRESP* single);
-
-const ASN1_OCTET_STRING *OCSP_resp_get0_signature(const OCSP_BASICRESP *bs);
-const X509_ALGOR *OCSP_resp_get0_tbs_sigalg(const OCSP_BASICRESP *bs);
-const OCSP_RESPDATA *OCSP_resp_get0_respdata(const OCSP_BASICRESP *bs);
-const STACK_OF(X509) *OCSP_resp_get0_certs(const OCSP_BASICRESP *bs);
-
-int OCSP_resp_get0_signer(OCSP_BASICRESP *bs, X509 **signer,
-                          STACK_OF(X509) *extra_certs);
-
-int OCSP_resp_get0_id(const OCSP_BASICRESP *bs,
-                      const ASN1_OCTET_STRING **pid,
-                      const X509_NAME **pname);
-int OCSP_resp_get1_id(const OCSP_BASICRESP *bs,
-                      ASN1_OCTET_STRING **pid,
-                      X509_NAME **pname);
-
-int OCSP_check_validity(ASN1_GENERALIZEDTIME *thisupd,
-                        ASN1_GENERALIZEDTIME *nextupd,
-                        long sec, long maxsec);
-
-int OCSP_basic_verify(OCSP_BASICRESP *bs, STACK_OF(X509) *certs,
-                     X509_STORE *st, unsigned long flags);
- -

DESCRIPTION

- -

OCSP_resp_find_status() searches bs for an OCSP response for id. If it is successful the fields of the response are returned in *status, *reason, *revtime, *thisupd and *nextupd. The *status value will be one of V_OCSP_CERTSTATUS_GOOD, V_OCSP_CERTSTATUS_REVOKED or V_OCSP_CERTSTATUS_UNKNOWN. The *reason and *revtime fields are only set if the status is V_OCSP_CERTSTATUS_REVOKED. If set the *reason field will be set to the revocation reason which will be one of OCSP_REVOKED_STATUS_NOSTATUS, OCSP_REVOKED_STATUS_UNSPECIFIED, OCSP_REVOKED_STATUS_KEYCOMPROMISE, OCSP_REVOKED_STATUS_CACOMPROMISE, OCSP_REVOKED_STATUS_AFFILIATIONCHANGED, OCSP_REVOKED_STATUS_SUPERSEDED, OCSP_REVOKED_STATUS_CESSATIONOFOPERATION, OCSP_REVOKED_STATUS_CERTIFICATEHOLD or OCSP_REVOKED_STATUS_REMOVEFROMCRL.

- -

OCSP_resp_count() returns the number of OCSP_SINGLERESP structures in bs.

- -

OCSP_resp_get0() returns the OCSP_SINGLERESP structure in bs corresponding to index idx, where idx runs from 0 to OCSP_resp_count(bs) - 1.

- -

OCSP_resp_find() searches bs for id and returns the index of the first matching entry after last or starting from the beginning if last is -1.

- -

OCSP_single_get0_status() extracts the fields of single in *reason, *revtime, *thisupd and *nextupd.

- -

OCSP_resp_get0_produced_at() extracts the producedAt field from the single response bs.

- -

OCSP_resp_get0_signature() returns the signature from bs.

- -

OCSP_resp_get0_tbs_sigalg() returns the signatureAlgorithm from bs.

- -

OCSP_resp_get0_respdata() returns the tbsResponseData from bs.

- -

OCSP_resp_get0_certs() returns any certificates included in bs.

- -

OCSP_resp_get0_signer() attempts to retrieve the certificate that directly signed bs. The OCSP protocol does not require that this certificate is included in the certs field of the response, so additional certificates can be supplied via the extra_certs if the certificates that may have signed the response are known via some out-of-band mechanism.

- -

OCSP_resp_get0_id() gets the responder id of bs. If the responder ID is a name then <*pname> is set to the name and *pid is set to NULL. If the responder ID is by key ID then *pid is set to the key ID and *pname is set to NULL.

- -

OCSP_resp_get1_id() is the same as OCSP_resp_get0_id() but leaves ownership of *pid and *pname with the caller, who is responsible for freeing them unless the function returns 0.

- -

OCSP_check_validity() checks the validity of its thisupd and nextupd arguments, which will be typically obtained from OCSP_resp_find_status() or OCSP_single_get0_status(). If sec is nonzero it indicates how many seconds leeway should be allowed in the check. If maxsec is positive it indicates the maximum age of thisupd in seconds.

- -

OCSP_basic_verify() checks that the basic response message bs is correctly signed and that the signer certificate can be validated. It takes st as the trusted store and certs as a set of untrusted intermediate certificates. The function first tries to find the signer certificate of the response in certs. It then searches the certificates the responder may have included in bs unless flags contains OCSP_NOINTERN. It fails if the signer certificate cannot be found. Next, unless flags contains OCSP_NOSIGS, the function checks the signature of bs and fails on error. Then the function already returns success if flags contains OCSP_NOVERIFY or if the signer certificate was found in certs and flags contains OCSP_TRUSTOTHER. Otherwise the function continues by validating the signer certificate. If flags contains OCSP_PARTIAL_CHAIN it takes intermediate CA certificates in st as trust anchors. For more details, see the description of X509_V_FLAG_PARTIAL_CHAIN in "VERIFICATION FLAGS" in X509_VERIFY_PARAM_set_flags(3). If flags contains OCSP_NOCHAIN it ignores all certificates in certs and in bs, else it takes them as untrusted intermediate CA certificates and uses them for constructing the validation path for the signer certificate. Certificate revocation status checks using CRLs is disabled during path validation if the signer certificate contains the id-pkix-ocsp-no-check extension. After successful path validation the function returns success if the OCSP_NOCHECKS flag is set. Otherwise it verifies that the signer certificate meets the OCSP issuer criteria including potential delegation. If this does not succeed and the OCSP_NOEXPLICIT flag is not set the function checks for explicit trust for OCSP signing in the root CA certificate.

- -

RETURN VALUES

- -

OCSP_resp_find_status() returns 1 if id is found in bs and 0 otherwise.

- -

OCSP_resp_count() returns the total number of OCSP_SINGLERESP fields in bs or -1 on error.

- -

OCSP_resp_get0() returns a pointer to an OCSP_SINGLERESP structure or NULL on error, such as idx being out of range.

- -

OCSP_resp_find() returns the index of id in bs (which may be 0) or -1 on error, such as when id was not found.

- -

OCSP_single_get0_status() returns the status of single or -1 if an error occurred.

- -

OCSP_resp_get0_produced_at() returns the producedAt field from bs.

- -

OCSP_resp_get0_signature() returns the signature from bs.

- -

OCSP_resp_get0_tbs_sigalg() returns the signatureAlgorithm field from bs.

- -

OCSP_resp_get0_respdata() returns the tbsResponseData field from bs.

- -

OCSP_resp_get0_certs() returns any certificates included in bs.

- -

OCSP_resp_get0_signer() returns 1 if the signing certificate was located, or 0 if not found or on error.

- -

OCSP_resp_get0_id() and OCSP_resp_get1_id() return 1 on success, 0 on failure.

- -

OCSP_check_validity() returns 1 if thisupd and nextupd are valid time values and the current time + sec is not before thisupd and, if maxsec >= 0, the current time - maxsec is not past nextupd. Otherwise it returns 0 to indicate an error.

- -

OCSP_basic_verify() returns 1 on success, 0 on verification not successful, or -1 on a fatal error such as malloc failure.

- -

NOTES

- -

Applications will typically call OCSP_resp_find_status() using the certificate ID of interest and then check its validity using OCSP_check_validity(). They can then take appropriate action based on the status of the certificate.

- -

An OCSP response for a certificate contains thisUpdate and nextUpdate fields. Normally the current time should be between these two values. To account for clock skew the maxsec field can be set to nonzero in OCSP_check_validity(). Some responders do not set the nextUpdate field, this would otherwise mean an ancient response would be considered valid: the maxsec parameter to OCSP_check_validity() can be used to limit the permitted age of responses.

- -

The values written to *revtime, *thisupd and *nextupd by OCSP_resp_find_status() and OCSP_single_get0_status() are internal pointers which MUST NOT be freed up by the calling application. Any or all of these parameters can be set to NULL if their value is not required.

- -

SEE ALSO

- -

crypto(7), OCSP_cert_to_id(3), OCSP_request_add1_nonce(3), OCSP_REQUEST_new(3), OCSP_response_status(3), OCSP_sendreq_new(3), X509_VERIFY_PARAM_set_flags(3)

- -

COPYRIGHT

- -

Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OCSP_response_status.html b/openssl-install/share/doc/openssl/html/man3/OCSP_response_status.html deleted file mode 100644 index bb2f3945..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OCSP_response_status.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -OCSP_response_status - - - - - - - - - - -

NAME

- -

OCSP_response_status, OCSP_response_get1_basic, OCSP_response_create, OCSP_RESPONSE_free, OCSP_RESPID_set_by_name, OCSP_RESPID_set_by_key_ex, OCSP_RESPID_set_by_key, OCSP_RESPID_match_ex, OCSP_RESPID_match, OCSP_basic_sign, OCSP_basic_sign_ctx - OCSP response functions

- -

SYNOPSIS

- -
#include <openssl/ocsp.h>
-
-int OCSP_response_status(OCSP_RESPONSE *resp);
-OCSP_BASICRESP *OCSP_response_get1_basic(OCSP_RESPONSE *resp);
-OCSP_RESPONSE *OCSP_response_create(int status, OCSP_BASICRESP *bs);
-void OCSP_RESPONSE_free(OCSP_RESPONSE *resp);
-
-int OCSP_RESPID_set_by_name(OCSP_RESPID *respid, X509 *cert);
-int OCSP_RESPID_set_by_key_ex(OCSP_RESPID *respid, X509 *cert,
-                              OSSL_LIB_CTX *libctx, const char *propq);
-int OCSP_RESPID_set_by_key(OCSP_RESPID *respid, X509 *cert);
-int OCSP_RESPID_match_ex(OCSP_RESPID *respid, X509 *cert, OSSL_LIB_CTX *libctx,
-                         const char *propq);
-int OCSP_RESPID_match(OCSP_RESPID *respid, X509 *cert);
-
-int OCSP_basic_sign(OCSP_BASICRESP *brsp, X509 *signer, EVP_PKEY *key,
-                    const EVP_MD *dgst, STACK_OF(X509) *certs,
-                    unsigned long flags);
-int OCSP_basic_sign_ctx(OCSP_BASICRESP *brsp, X509 *signer, EVP_MD_CTX *ctx,
-                        STACK_OF(X509) *certs, unsigned long flags);
- -

DESCRIPTION

- -

OCSP_response_status() returns the OCSP response status of resp. It returns one of the values: OCSP_RESPONSE_STATUS_SUCCESSFUL, OCSP_RESPONSE_STATUS_MALFORMEDREQUEST, OCSP_RESPONSE_STATUS_INTERNALERROR, OCSP_RESPONSE_STATUS_TRYLATER OCSP_RESPONSE_STATUS_SIGREQUIRED, or OCSP_RESPONSE_STATUS_UNAUTHORIZED.

- -

OCSP_response_get1_basic() decodes and returns the OCSP_BASICRESP structure contained in resp.

- -

OCSP_response_create() creates and returns an OCSP_RESPONSE structure for status and optionally including basic response bs.

- -

OCSP_RESPONSE_free() frees up OCSP response resp. If the argument is NULL, nothing is done.

- -

OCSP_RESPID_set_by_name() sets the name of the OCSP_RESPID to be the same as the subject name in the supplied X509 certificate cert for the OCSP responder.

- -

OCSP_RESPID_set_by_key_ex() sets the key of the OCSP_RESPID to be the same as the key in the supplied X509 certificate cert for the OCSP responder. The key is stored as a SHA1 hash. To calculate the hash the SHA1 algorithm is fetched using the library ctx libctx and the property query string propq (see "ALGORITHM FETCHING" in crypto(7) for further information).

- -

OCSP_RESPID_set_by_key() does the same as OCSP_RESPID_set_by_key_ex() except that the default library context is used with an empty property query string.

- -

Note that an OCSP_RESPID can only have one of the name, or the key set. Calling OCSP_RESPID_set_by_name() or OCSP_RESPID_set_by_key() will clear any existing setting.

- -

OCSP_RESPID_match_ex() tests whether the OCSP_RESPID given in respid matches with the X509 certificate cert based on the SHA1 hash. To calculate the hash the SHA1 algorithm is fetched using the library ctx libctx and the property query string propq (see "ALGORITHM FETCHING" in crypto(7) for further information).

- -

OCSP_RESPID_match() does the same as OCSP_RESPID_match_ex() except that the default library context is used with an empty property query string.

- -

OCSP_basic_sign() signs OCSP response brsp using certificate signer, private key key, digest dgst and additional certificates certs. If the flags option OCSP_NOCERTS is set then no certificates will be included in the response. If the flags option OCSP_RESPID_KEY is set then the responder is identified by key ID rather than by name. OCSP_basic_sign_ctx() also signs OCSP response brsp but uses the parameters contained in digest context ctx.

- -

RETURN VALUES

- -

OCSP_RESPONSE_status() returns a status value.

- -

OCSP_response_get1_basic() returns an OCSP_BASICRESP structure pointer or NULL if an error occurred.

- -

OCSP_response_create() returns an OCSP_RESPONSE structure pointer or NULL if an error occurred.

- -

OCSP_RESPONSE_free() does not return a value.

- -

OCSP_RESPID_set_by_name(), OCSP_RESPID_set_by_key(), OCSP_basic_sign(), and OCSP_basic_sign_ctx() return 1 on success or 0 on failure.

- -

OCSP_RESPID_match() returns 1 if the OCSP_RESPID and the X509 certificate match or 0 otherwise.

- -

NOTES

- -

OCSP_response_get1_basic() is only called if the status of a response is OCSP_RESPONSE_STATUS_SUCCESSFUL.

- -

SEE ALSO

- -

crypto(7) OCSP_cert_to_id(3) OCSP_request_add1_nonce(3) OCSP_REQUEST_new(3) OCSP_resp_find_status(3) OCSP_sendreq_new(3) OCSP_RESPID_new(3) OCSP_RESPID_free(3)

- -

HISTORY

- -

The OCSP_RESPID_set_by_name(), OCSP_RESPID_set_by_key() and OCSP_RESPID_match() functions were added in OpenSSL 1.1.0a.

- -

The OCSP_basic_sign_ctx() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OCSP_sendreq_new.html b/openssl-install/share/doc/openssl/html/man3/OCSP_sendreq_new.html deleted file mode 100644 index 646bd658..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OCSP_sendreq_new.html +++ /dev/null @@ -1,96 +0,0 @@ - - - - -OCSP_sendreq_new - - - - - - - - - - -

NAME

- -

OCSP_REQ_CTX, OCSP_sendreq_new, OCSP_sendreq_nbio, OCSP_sendreq_bio, OCSP_REQ_CTX_i2d, OCSP_REQ_CTX_add1_header, OCSP_REQ_CTX_free, OCSP_set_max_response_length, OCSP_REQ_CTX_set1_req - OCSP responder query functions

- -

SYNOPSIS

- -
#include <openssl/ocsp.h>
-
-OSSL_HTTP_REQ_CTX *OCSP_sendreq_new(BIO *io, const char *path,
-                                    const OCSP_REQUEST *req, int buf_size);
-OCSP_RESPONSE *OCSP_sendreq_bio(BIO *io, const char *path, OCSP_REQUEST *req);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
typedef OSSL_HTTP_REQ_CTX OCSP_REQ_CTX;
-int OCSP_sendreq_nbio(OCSP_RESPONSE **presp, OSSL_HTTP_REQ_CTX *rctx);
-int OCSP_REQ_CTX_i2d(OCSP_REQ_CT *rctx, const ASN1_ITEM *it, ASN1_VALUE *req);
-int OCSP_REQ_CTX_add1_header(OCSP_REQ_CT *rctx,
-                             const char *name, const char *value);
-void OCSP_REQ_CTX_free(OCSP_REQ_CTX *rctx);
-void OCSP_set_max_response_length(OCSP_REQ_CT *rctx, unsigned long len);
-int OCSP_REQ_CTX_set1_req(OCSP_REQ_CTX *rctx, const OCSP_REQUEST *req);
- -

DESCRIPTION

- -

These functions perform an OCSP POST request / response transfer over HTTP, using the HTTP request functions described in OSSL_HTTP_REQ_CTX(3).

- -

The function OCSP_sendreq_new() builds a complete OSSL_HTTP_REQ_CTX structure with the BIO io to be used for requests and response, the URL path path, optionally the OCSP request req, and a response header maximum line length of buf_size. If buf_size is zero a default value of 4KiB is used. The req may be set to NULL and provided later using OCSP_REQ_CTX_set1_req() or OSSL_HTTP_REQ_CTX_set1_req(3). The io and path arguments to OCSP_sendreq_new() correspond to the components of the URL. For example if the responder URL is http://example.com/ocspreq the BIO io should haven been connected to host example.com on port 80 and path should be set to /ocspreq.

- -

OCSP_sendreq_nbio() attempts to send the request prepared in rctx and to gather the response via HTTP, using the BIO io and path that were given when calling OCSP_sendreq_new(). If the operation gets completed it assigns the response, a pointer to a OCSP_RESPONSE structure, in *presp. The function may need to be called again if its result is -1, which indicates BIO_should_retry(3). In such a case it is advisable to sleep a little in between, using BIO_wait(3) on the read BIO to prevent a busy loop.

- -

OCSP_sendreq_bio() combines OCSP_sendreq_new() with as many calls of OCSP_sendreq_nbio() as needed and then OCSP_REQ_CTX_free(), with a response header maximum line length 4k. It waits indefinitely on a response. It does not support setting a timeout or adding headers and is retained for compatibility; use OSSL_HTTP_transfer(3) instead.

- -

OCSP_REQ_CTX_i2d(rctx, it, req) is equivalent to the following:

- -
OSSL_HTTP_REQ_CTX_set1_req(rctx, "application/ocsp-request", it, req)
- -

OCSP_REQ_CTX_set1_req(rctx, req) is equivalent to the following:

- -
OSSL_HTTP_REQ_CTX_set1_req(rctx, "application/ocsp-request",
-                           ASN1_ITEM_rptr(OCSP_REQUEST),
-                           (const ASN1_VALUE *)req)
- -

The deprecated type and the remaining deprecated functions have been superseded by the following equivalents: OCSP_REQ_CTX by OSSL_HTTP_REQ_CTX(3), OCSP_REQ_CTX_add1_header() by OSSL_HTTP_REQ_CTX_add1_header(3), OCSP_REQ_CTX_free() by OSSL_HTTP_REQ_CTX_free(3), and OCSP_set_max_response_length() by OSSL_HTTP_REQ_CTX_set_max_response_length(3).

- -

RETURN VALUES

- -

OCSP_sendreq_new() returns a valid OSSL_HTTP_REQ_CTX structure or NULL if an error occurred.

- -

OCSP_sendreq_nbio() returns 1 for success, 0 on error, -1 if retry is needed.

- -

OCSP_sendreq_bio() returns the OCSP_RESPONSE structure sent by the responder or NULL if an error occurred.

- -

SEE ALSO

- -

OSSL_HTTP_REQ_CTX(3), OSSL_HTTP_transfer(3), OCSP_cert_to_id(3), OCSP_request_add1_nonce(3), OCSP_REQUEST_new(3), OCSP_resp_find_status(3), OCSP_response_status(3)

- -

HISTORY

- -

OCSP_REQ_CTX, OCSP_REQ_CTX_i2d(), OCSP_REQ_CTX_add1_header(), OCSP_REQ_CTX_free(), OCSP_set_max_response_length(), and OCSP_REQ_CTX_set1_req() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_Applink.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_Applink.html deleted file mode 100644 index 1eadf1c9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_Applink.html +++ /dev/null @@ -1,49 +0,0 @@ - - - - -OPENSSL_Applink - - - - - - - - - - -

NAME

- -

OPENSSL_Applink - glue between OpenSSL BIO and Win32 compiler run-time

- -

SYNOPSIS

- -
__declspec(dllexport) void **OPENSSL_Applink();
- -

DESCRIPTION

- -

OPENSSL_Applink is application-side interface which provides a glue between OpenSSL BIO layer and Win32 compiler run-time environment. Even though it appears at application side, it's essentially OpenSSL private interface. For this reason application developers are not expected to implement it, but to compile provided module with compiler of their choice and link it into the target application. The referred module is available as applink.c, located alongside the public header files (only on the platforms where applicable).

- -

RETURN VALUES

- -

Not available.

- -

COPYRIGHT

- -

Copyright 2004-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_FILE.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_FILE.html deleted file mode 100644 index 024d2f03..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_FILE.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -OPENSSL_FILE - - - - - - - - - - -

NAME

- -

OPENSSL_FILE, OPENSSL_LINE, OPENSSL_FUNC, OPENSSL_MSTR, OPENSSL_MSTR_HELPER - generic C programming utility macros

- -

SYNOPSIS

- -
#include <openssl/macros.h>
-
-#define OPENSSL_FILE /* typically: __FILE__ */
-#define OPENSSL_LINE /* typically: __LINE__ */
-#define OPENSSL_FUNC /* typically: __func__ */
-
-#define OPENSSL_MSTR_HELPER(x) #x
-#define OPENSSL_MSTR(x) OPENSSL_MSTR_HELPER(x)
- -

DESCRIPTION

- -

The macros OPENSSL_FILE and OPENSSL_LINE typically yield the current filename and line number during C compilation. When OPENSSL_NO_FILENAMES is defined they yield "" and 0, respectively.

- -

The macro OPENSSL_FUNC attempts to yield the name of the C function currently being compiled, as far as language and compiler versions allow. Otherwise, it yields "(unknown function)".

- -

The macro OPENSSL_MSTR yields the expansion of the macro given as argument, which is useful for concatenation with string constants. The macro OPENSSL_MSTR_HELPER is an auxiliary macro for this purpose.

- -

RETURN VALUES

- -

see above

- -

SEE ALSO

- -

crypto(7)

- -

HISTORY

- -

OPENSSL_FUNC, OPENSSL_MSTR, and OPENSSL_MSTR_HELPER were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_COMPFUNC.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_COMPFUNC.html deleted file mode 100644 index bc582c97..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_COMPFUNC.html +++ /dev/null @@ -1,232 +0,0 @@ - - - - -OPENSSL_LH_COMPFUNC - - - - - - - - - - -

NAME

- -

LHASH, LHASH_OF, DEFINE_LHASH_OF_EX, DEFINE_LHASH_OF, OPENSSL_LH_COMPFUNC, OPENSSL_LH_HASHFUNC, OPENSSL_LH_DOALL_FUNC, LHASH_DOALL_ARG_FN_TYPE, IMPLEMENT_LHASH_HASH_FN, IMPLEMENT_LHASH_COMP_FN, lh_TYPE_new, lh_TYPE_free, lh_TYPE_flush, lh_TYPE_insert, lh_TYPE_delete, lh_TYPE_retrieve, lh_TYPE_doall, lh_TYPE_doall_arg, lh_TYPE_num_items, lh_TYPE_get_down_load, lh_TYPE_set_down_load, lh_TYPE_error, OPENSSL_LH_new, OPENSSL_LH_free, OPENSSL_LH_flush, OPENSSL_LH_insert, OPENSSL_LH_delete, OPENSSL_LH_retrieve, OPENSSL_LH_doall, OPENSSL_LH_doall_arg, OPENSSL_LH_doall_arg_thunk, OPENSSL_LH_set_thunks, OPENSSL_LH_num_items, OPENSSL_LH_get_down_load, OPENSSL_LH_set_down_load, OPENSSL_LH_error - dynamic hash table

- -

SYNOPSIS

- -
#include <openssl/lhash.h>
-
-LHASH_OF(TYPE)
-
-DEFINE_LHASH_OF_EX(TYPE);
-
-LHASH_OF(TYPE) *lh_TYPE_new(OPENSSL_LH_HASHFUNC hash, OPENSSL_LH_COMPFUNC compare);
-void lh_TYPE_free(LHASH_OF(TYPE) *table);
-void lh_TYPE_flush(LHASH_OF(TYPE) *table);
-OPENSSL_LHASH *OPENSSL_LH_set_thunks(OPENSSL_LHASH *lh,
-                                     OPENSSL_LH_HASHFUNCTHUNK hw,
-                                     OPENSSL_LH_COMPFUNCTHUNK cw,
-                                     OPENSSL_LH_DOALL_FUNC_THUNK daw,
-                                     OPENSSL_LH_DOALL_FUNCARG_THUNK daaw)
-
-TYPE *lh_TYPE_insert(LHASH_OF(TYPE) *table, TYPE *data);
-TYPE *lh_TYPE_delete(LHASH_OF(TYPE) *table, TYPE *data);
-TYPE *lh_TYPE_retrieve(LHASH_OF(TYPE) *table, TYPE *data);
-
-void lh_TYPE_doall(LHASH_OF(TYPE) *table, OPENSSL_LH_DOALL_FUNC func);
-void lh_TYPE_doall_arg(LHASH_OF(TYPE) *table, OPENSSL_LH_DOALL_FUNCARG func,
-                       TYPE *arg);
-void OPENSSL_LH_doall_arg_thunk(OPENSSL_LHASH *lh,
-                                OPENSSL_LH_DOALL_FUNCARG_THUNK daaw,
-                                OPENSSL_LH_DOALL_FUNCARG fn, void *arg)
-
-unsigned long lh_TYPE_num_items(OPENSSL_LHASH *lh);
-unsigned long lh_TYPE_get_down_load(OPENSSL_LHASH *lh);
-void lh_TYPE_set_down_load(OPENSSL_LHASH *lh, unsigned long dl);
-
-int lh_TYPE_error(LHASH_OF(TYPE) *table);
-
-typedef int (*OPENSSL_LH_COMPFUNC)(const void *, const void *);
-typedef unsigned long (*OPENSSL_LH_HASHFUNC)(const void *);
-typedef void (*OPENSSL_LH_DOALL_FUNC)(const void *);
-typedef void (*LHASH_DOALL_ARG_FN_TYPE)(const void *, const void *);
-
-OPENSSL_LHASH *OPENSSL_LH_new(OPENSSL_LH_HASHFUNC h, OPENSSL_LH_COMPFUNC c);
-void OPENSSL_LH_free(OPENSSL_LHASH *lh);
-void OPENSSL_LH_flush(OPENSSL_LHASH *lh);
-
-void *OPENSSL_LH_insert(OPENSSL_LHASH *lh, void *data);
-void *OPENSSL_LH_delete(OPENSSL_LHASH *lh, const void *data);
-void *OPENSSL_LH_retrieve(OPENSSL_LHASH *lh, const void *data);
-
-void OPENSSL_LH_doall(OPENSSL_LHASH *lh, OPENSSL_LH_DOALL_FUNC func);
-void OPENSSL_LH_doall_arg(OPENSSL_LHASH *lh, OPENSSL_LH_DOALL_FUNCARG func, void *arg);
-
-unsigned long OPENSSL_LH_num_items(OPENSSL_LHASH *lh);
-unsigned long OPENSSL_LH_get_down_load(OPENSSL_LHASH *lh);
-void OPENSSL_LH_set_down_load(OPENSSL_LHASH *lh, unsigned long dl);
-
-int OPENSSL_LH_error(OPENSSL_LHASH *lh);
-
-#define LH_LOAD_MULT   /* integer constant */
- -

The following macro is deprecated:

- -
DEFINE_LHASH_OF(TYPE);
- -

DESCRIPTION

- -

This library implements type-checked dynamic hash tables. The hash table entries can be arbitrary structures. Usually they consist of key and value fields. In the description here, TYPE is used a placeholder for any of the OpenSSL datatypes, such as SSL_SESSION.

- -

To define a new type-checked dynamic hash table, use DEFINE_LHASH_OF_EX(). DEFINE_LHASH_OF() was previously used for this purpose, but is now deprecated. The DEFINE_LHASH_OF_EX() macro provides all functionality of DEFINE_LHASH_OF() except for certain deprecated statistics functions (see OPENSSL_LH_stats(3)).

- -

lh_TYPE_new() creates a new LHASH_OF(TYPE) structure to store arbitrary data entries, and specifies the 'hash' and 'compare' callbacks to be used in organising the table's entries. The hash callback takes a pointer to a table entry as its argument and returns an unsigned long hash value for its key field. The hash value is normally truncated to a power of 2, so make sure that your hash function returns well mixed low order bits. The compare callback takes two arguments (pointers to two hash table entries), and returns 0 if their keys are equal, nonzero otherwise.

- -

If your hash table will contain items of some particular type and the hash and compare callbacks hash/compare these types, then the IMPLEMENT_LHASH_HASH_FN and IMPLEMENT_LHASH_COMP_FN macros can be used to create callback wrappers of the prototypes required by lh_TYPE_new() as shown in this example:

- -
/*
- * Implement the hash and compare functions; "stuff" can be any word.
- */
-static unsigned long stuff_hash(const TYPE *a)
-{
-    ...
-}
-static int stuff_cmp(const TYPE *a, const TYPE *b)
-{
-    ...
-}
-
-/*
- * Implement the wrapper functions.
- */
-static IMPLEMENT_LHASH_HASH_FN(stuff, TYPE)
-static IMPLEMENT_LHASH_COMP_FN(stuff, TYPE)
- -

If the type is going to be used in several places, the following macros can be used in a common header file to declare the function wrappers:

- -
DECLARE_LHASH_HASH_FN(stuff, TYPE)
-DECLARE_LHASH_COMP_FN(stuff, TYPE)
- -

Then a hash table of TYPE objects can be created using this:

- -
LHASH_OF(TYPE) *htable;
-
-htable = B<lh_I<TYPE>_new>(LHASH_HASH_FN(stuff), LHASH_COMP_FN(stuff));
- -

lh_TYPE_free() frees the LHASH_OF(TYPE) structure table. Allocated hash table entries will not be freed; consider using lh_TYPE_doall() to deallocate any remaining entries in the hash table (see below). If the argument is NULL, nothing is done.

- -

lh_TYPE_flush() empties the LHASH_OF(TYPE) structure table. New entries can be added to the flushed table. Allocated hash table entries will not be freed; consider using lh_TYPE_doall() to deallocate any remaining entries in the hash table (see below).

- -

lh_TYPE_insert() inserts the structure pointed to by data into table. If there already is an entry with the same key, the old value is replaced. Note that lh_TYPE_insert() stores pointers, the data are not copied.

- -

lh_TYPE_delete() deletes an entry from table.

- -

lh_TYPE_retrieve() looks up an entry in table. Normally, data is a structure with the key field(s) set; the function will return a pointer to a fully populated structure.

- -

lh_TYPE_doall() will, for every entry in the hash table, call func with the data item as its parameter. For example:

- -
/* Cleans up resources belonging to 'a' (this is implemented elsewhere) */
-void TYPE_cleanup_doall(TYPE *a);
-
-/* Implement a prototype-compatible wrapper for "TYPE_cleanup" */
-IMPLEMENT_LHASH_DOALL_FN(TYPE_cleanup, TYPE)
-
-/* Call "TYPE_cleanup" against all items in a hash table. */
-lh_TYPE_doall(hashtable, LHASH_DOALL_FN(TYPE_cleanup));
-
-/* Then the hash table itself can be deallocated */
-lh_TYPE_free(hashtable);
- -

lh_TYPE_doall_arg() is the same as lh_TYPE_doall() except that func will be called with arg as the second argument and func should be of type LHASH_DOALL_ARG_FN(TYPE) (a callback prototype that is passed both the table entry and an extra argument). As with lh_doall(), you can instead choose to declare your callback with a prototype matching the types you are dealing with and use the declare/implement macros to create compatible wrappers that cast variables before calling your type-specific callbacks. An example of this is demonstrated here (printing all hash table entries to a BIO that is provided by the caller):

- -
/* Prints item 'a' to 'output_bio' (this is implemented elsewhere) */
-void TYPE_print_doall_arg(const TYPE *a, BIO *output_bio);
-
-/* Implement a prototype-compatible wrapper for "TYPE_print" */
-static IMPLEMENT_LHASH_DOALL_ARG_FN(TYPE, const TYPE, BIO)
-
-/* Print out the entire hashtable to a particular BIO */
-lh_TYPE_doall_arg(hashtable, LHASH_DOALL_ARG_FN(TYPE_print), BIO,
-                  logging_bio);
- -

Note that it is by default not safe to use lh_TYPE_delete() inside a callback passed to lh_TYPE_doall() or lh_TYPE_doall_arg(). The reason for this is that deleting an item from the hash table may result in the hash table being contracted to a smaller size and rehashed. lh_TYPE_doall() and lh_TYPE_doall_arg() are unsafe and will exhibit undefined behaviour under these conditions, as these functions assume the hash table size and bucket pointers do not change during the call.

- -

If it is desired to use lh_TYPE_doall() or lh_TYPE_doall_arg() with lh_TYPE_delete(), it is essential that you call lh_TYPE_set_down_load() with a down_load argument of 0 first. This disables hash table contraction and guarantees that it will be safe to delete items from a hash table during a call to lh_TYPE_doall() or lh_TYPE_doall_arg().

- -

It is never safe to call lh_TYPE_insert() during a call to lh_TYPE_doall() or lh_TYPE_doall_arg().

- -

lh_TYPE_error() can be used to determine if an error occurred in the last operation.

- -

lh_TYPE_num_items() returns the number of items in the hash table.

- -

lh_TYPE_get_down_load() and lh_TYPE_set_down_load() get and set the factor used to determine when the hash table is contracted. The factor is the load factor at or below which hash table contraction will occur, multiplied by LH_LOAD_MULT, where the load factor is the number of items divided by the number of nodes. Setting this value to 0 disables hash table contraction.

- -

OPENSSL_LH_new() is the same as the lh_TYPE_new() except that it is not type specific. So instead of returning an LHASH_OF(TYPE) value it returns a void *. In the same way the functions OPENSSL_LH_free(), OPENSSL_LH_flush(), OPENSSL_LH_insert(), OPENSSL_LH_delete(), OPENSSL_LH_retrieve(), OPENSSL_LH_doall(), OPENSSL_LH_doall_arg(), OPENSSL_LH_num_items(), OPENSSL_LH_get_down_load(), OPENSSL_LH_set_down_load() and OPENSSL_LH_error() are equivalent to the similarly named lh_TYPE functions except that they return or use a void * where the equivalent lh_TYPE function returns or uses a TYPE * or LHASH_OF(TYPE) *. lh_TYPE functions are implemented as type checked wrappers around the OPENSSL_LH functions. Most applications should not call the OPENSSL_LH functions directly.

- -

OPENSSL_LH_set_thunks() and OPENSSL_LH_doall_arg_thunk(), while public by necessity, are actually internal functions and should not be used.

- -

RETURN VALUES

- -

lh_TYPE_new() and OPENSSL_LH_new() return NULL on error, otherwise a pointer to the new LHASH structure.

- -

When a hash table entry is replaced, lh_TYPE_insert() or OPENSSL_LH_insert() return the value being replaced. NULL is returned on normal operation and on error.

- -

lh_TYPE_delete() and OPENSSL_LH_delete() return the entry being deleted. NULL is returned if there is no such value in the hash table.

- -

lh_TYPE_retrieve() and OPENSSL_LH_retrieve() return the hash table entry if it has been found, NULL otherwise.

- -

lh_TYPE_error() and OPENSSL_LH_error() return 1 if an error occurred in the last operation, 0 otherwise. It's meaningful only after non-retrieve operations.

- -

lh_TYPE_free(), OPENSSL_LH_free(), lh_TYPE_flush(), OPENSSL_LH_flush(), lh_TYPE_doall() OPENSSL_LH_doall(), lh_TYPE_doall_arg() and OPENSSL_LH_doall_arg() return no values.

- -

NOTE

- -

The LHASH code is not thread safe. All updating operations, as well as lh_TYPE_error() or OPENSSL_LH_error() calls must be performed under a write lock. All retrieve operations should be performed under a read lock, unless accurate usage statistics are desired. In which case, a write lock should be used for retrieve operations as well. For output of the usage statistics, using the functions from OPENSSL_LH_stats(3), a read lock suffices.

- -

The LHASH code regards table entries as constant data. As such, it internally represents lh_insert()'d items with a "const void *" pointer type. This is why callbacks such as those used by lh_doall() and lh_doall_arg() declare their prototypes with "const", even for the parameters that pass back the table items' data pointers - for consistency, user-provided data is "const" at all times as far as the LHASH code is concerned. However, as callers are themselves providing these pointers, they can choose whether they too should be treating all such parameters as constant.

- -

As an example, a hash table may be maintained by code that, for reasons of encapsulation, has only "const" access to the data being indexed in the hash table (i.e. it is returned as "const" from elsewhere in their code) - in this case the LHASH prototypes are appropriate as-is. Conversely, if the caller is responsible for the life-time of the data in question, then they may well wish to make modifications to table item passed back in the lh_doall() or lh_doall_arg() callbacks (see the "TYPE_cleanup" example above). If so, the caller can either cast the "const" away (if they're providing the raw callbacks themselves) or use the macros to declare/implement the wrapper functions without "const" types.

- -

Callers that only have "const" access to data they're indexing in a table, yet declare callbacks without constant types (or cast the "const" away themselves), are therefore creating their own risks/bugs without being encouraged to do so by the API. On a related note, those auditing code should pay special attention to any instances of DECLARE/IMPLEMENT_LHASH_DOALL_[ARG_]_FN macros that provide types without any "const" qualifiers.

- -

BUGS

- -

lh_TYPE_insert() and OPENSSL_LH_insert() return NULL both for success and error.

- -

SEE ALSO

- -

OPENSSL_LH_stats(3)

- -

HISTORY

- -

In OpenSSL 1.0.0, the lhash interface was revamped for better type checking.

- -

In OpenSSL 3.1, DEFINE_LHASH_OF_EX() was introduced and DEFINE_LHASH_OF() was deprecated.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_stats.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_stats.html deleted file mode 100644 index 4a143d43..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_LH_stats.html +++ /dev/null @@ -1,85 +0,0 @@ - - - - -OPENSSL_LH_stats - - - - - - - - - - -

NAME

- -

OPENSSL_LH_stats, OPENSSL_LH_node_stats, OPENSSL_LH_node_usage_stats, OPENSSL_LH_stats_bio, OPENSSL_LH_node_stats_bio, OPENSSL_LH_node_usage_stats_bio - LHASH statistics

- -

SYNOPSIS

- -
#include <openssl/lhash.h>
- -

The following functions have been deprecated since OpenSSL 3.1, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void OPENSSL_LH_node_stats(LHASH *table, FILE *out);
-void OPENSSL_LH_node_usage_stats(LHASH *table, FILE *out);
-
-void OPENSSL_LH_node_stats_bio(LHASH *table, BIO *out);
-void OPENSSL_LH_node_usage_stats_bio(LHASH *table, BIO *out);
-
-void OPENSSL_LH_stats(LHASH *table, FILE *out);
-void OPENSSL_LH_stats_bio(LHASH *table, BIO *out);
- -

DESCRIPTION

- -

The LHASH structure records statistics about most aspects of accessing the hash table.

- -

OPENSSL_LH_stats() prints out statistics on the size of the hash table and how many entries are in it. For historical reasons, this function also outputs a number of additional statistics, but the tracking of these statistics is no longer supported and these statistics are always reported as zero.

- -

OPENSSL_LH_node_stats() prints the number of entries for each 'bucket' in the hash table.

- -

OPENSSL_LH_node_usage_stats() prints out a short summary of the state of the hash table. It prints the 'load' and the 'actual load'. The load is the average number of data items per 'bucket' in the hash table. The 'actual load' is the average number of items per 'bucket', but only for buckets which contain entries. So the 'actual load' is the average number of searches that will need to find an item in the hash table, while the 'load' is the average number that will be done to record a miss.

- -

OPENSSL_LH_stats_bio(), OPENSSL_LH_node_stats_bio() and OPENSSL_LH_node_usage_stats_bio() are the same as the above, except that the output goes to a BIO.

- -

These functions are deprecated and should no longer be used.

- -

RETURN VALUES

- -

These functions do not return values.

- -

NOTE

- -

These calls should be made under a read lock. Refer to "NOTE" in OPENSSL_LH_COMPFUNC(3) for more details about the locks required when using the LHASH data structure.

- -

SEE ALSO

- -

bio(7), OPENSSL_LH_COMPFUNC(3)

- -

HISTORY

- -

These functions were deprecated in version 3.1.

- -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_config.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_config.html deleted file mode 100644 index 96ea5af7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_config.html +++ /dev/null @@ -1,88 +0,0 @@ - - - - -OPENSSL_config - - - - - - - - - - -

NAME

- -

OPENSSL_config, OPENSSL_no_config - simple OpenSSL configuration functions

- -

SYNOPSIS

- -
#include <openssl/conf.h>
- -

The following functions have been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void OPENSSL_config(const char *appname);
-void OPENSSL_no_config(void);
- -

DESCRIPTION

- -

OPENSSL_config() configures OpenSSL using the standard openssl.cnf and reads from the application section appname. If appname is NULL then the default section, openssl_conf, will be used. Errors are silently ignored. Multiple calls have no effect.

- -

OPENSSL_no_config() disables configuration. If called before OPENSSL_config() no configuration takes place.

- -

If the application is built with OPENSSL_LOAD_CONF defined, then a call to OpenSSL_add_all_algorithms() will implicitly call OPENSSL_config() first.

- -

NOTES

- -

The OPENSSL_config() function is designed to be a very simple "call it and forget it" function. It is however much better than nothing. Applications which need finer control over their configuration functionality should use the configuration functions such as CONF_modules_load() directly. This function is deprecated and its use should be avoided. Applications should instead call CONF_modules_load() during initialization (that is before starting any threads).

- -

There are several reasons why calling the OpenSSL configuration routines is advisable. For example, to load dynamic ENGINEs from shared libraries (DSOs). However, very few applications currently support the control interface and so very few can load and use dynamic ENGINEs. Equally in future more sophisticated ENGINEs will require certain control operations to customize them. If an application calls OPENSSL_config() it doesn't need to know or care about ENGINE control operations because they can be performed by editing a configuration file.

- -

ENVIRONMENT

- -
- -
OPENSSL_CONF
-
- -

The path to the config file. Ignored in set-user-ID and set-group-ID programs.

- -
-
- -

RETURN VALUES

- -

Neither OPENSSL_config() nor OPENSSL_no_config() return a value.

- -

SEE ALSO

- -

config(5), CONF_modules_load_file(3)

- -

HISTORY

- -

The OPENSSL_no_config() and OPENSSL_config() functions were deprecated in OpenSSL 1.1.0 by OPENSSL_init_crypto().

- -

COPYRIGHT

- -

Copyright 2004-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_fork_prepare.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_fork_prepare.html deleted file mode 100644 index 8bfc7fc9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_fork_prepare.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -OPENSSL_fork_prepare - - - - - - - - - - -

NAME

- -

OPENSSL_fork_prepare, OPENSSL_fork_parent, OPENSSL_fork_child - OpenSSL fork handlers

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void OPENSSL_fork_prepare(void);
-void OPENSSL_fork_parent(void);
-void OPENSSL_fork_child(void);
- -

DESCRIPTION

- -

These methods are currently unused, and as such, no replacement methods are required or planned.

- -

OpenSSL has state that should be reset when a process forks. For example, the entropy pool used to generate random numbers (and therefore encryption keys) should not be shared across multiple programs. The OPENSSL_fork_prepare(), OPENSSL_fork_parent(), and OPENSSL_fork_child() functions are used to reset this internal state.

- -

Platforms without fork(2) will probably not need to use these functions. Platforms with fork(2) but without pthread_atfork(3) will probably need to call them manually, as described in the following paragraph. Platforms such as Linux that have both functions will normally not need to call these functions as the OpenSSL library will do so automatically.

- -

OPENSSL_init_crypto(3) will register these functions with the appropriate handler, when the OPENSSL_INIT_ATFORK flag is used. For other applications, these functions can be called directly. They should be used according to the calling sequence described by the pthread_atfork(3) documentation, which is summarized here. OPENSSL_fork_prepare() should be called before a fork() is done. After the fork() returns, the parent process should call OPENSSL_fork_parent() and the child process should call OPENSSL_fork_child().

- -

RETURN VALUES

- -

OPENSSL_fork_prepare(), OPENSSL_fork_parent() and OPENSSL_fork_child() do not return values.

- -

SEE ALSO

- -

OPENSSL_init_crypto(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_gmtime.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_gmtime.html deleted file mode 100644 index b4393ce3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_gmtime.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -OPENSSL_gmtime - - - - - - - - - - -

NAME

- -

OPENSSL_gmtime, OPENSSL_gmtime_adj, OPENSSL_gmtime_diff - platform-agnostic OpenSSL time routines

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-struct tm *OPENSSL_gmtime(const time_t *timer, struct tm *result);
-int OPENSSL_gmtime_adj(struct tm *tm, int offset_day, long offset_sec);
-int OPENSSL_gmtime_diff(int *pday, int *psec,
-                       const struct tm *from, const struct tm *to);
- -

DESCRIPTION

- -

OPENSSL_gmtime() returns the UTC time specified by timer into the provided result argument.

- -

OPENSSL_gmtime_adj() adds the offsets in offset_day and offset_sec to tm.

- -

OPENSSL_gmtime_diff() calculates the difference between from and to.

- -

NOTES

- -

It is an error to call OPENSSL_gmtime() with result equal to NULL. The contents of the time_t given by timer are stored into the result. Calling with timer equal to NULL means use the current time.

- -

OPENSSL_gmtime_adj() converts tm into a days and seconds value, adds the offsets, then converts back into a struct tm specified by tm. Leap seconds are not considered.

- -

OPENSSL_gmtime_diff() calculates the difference between the two struct tm structures from and to. The difference in days is placed into *pday, the remaining seconds are placed to *psec. The value in *psec will be less than the number of seconds per day (3600). Leap seconds are not considered.

- -

RETURN VALUES

- -

OPENSSL_gmtime() returns NULL on error, or result on success.

- -

OPENSSL_gmtime_adj() and OPENSSL_gmtime_diff() return 0 on error, and 1 on success.

- -

HISTORY

- -

OPENSSL_gmtime(), OPENSSL_gmtime_adj() and OPENSSL_gmtime_diff() have been in OpenSSL since 1.0.0.

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_hexchar2int.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_hexchar2int.html deleted file mode 100644 index eba09e4f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_hexchar2int.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -OPENSSL_hexchar2int - - - - - - - - - - -

NAME

- -

OPENSSL_hexchar2int, OPENSSL_hexstr2buf_ex, OPENSSL_hexstr2buf, OPENSSL_buf2hexstr_ex, OPENSSL_buf2hexstr - Hex encoding and decoding functions

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-int OPENSSL_hexchar2int(unsigned char c);
-int OPENSSL_hexstr2buf_ex(unsigned char *buf, size_t buf_n, long *buflen,
-                          const char *str, const char sep);
-unsigned char *OPENSSL_hexstr2buf(const char *str, long *len);
-int OPENSSL_buf2hexstr_ex(char *str, size_t str_n, size_t *strlength,
-                          const unsigned char *buf, long buflen,
-                          const char sep);
-char *OPENSSL_buf2hexstr(const unsigned char *buf, long buflen);
- -

DESCRIPTION

- -

OPENSSL_hexchar2int() converts a hexadecimal character to its numeric equivalent.

- -

OPENSSL_hexstr2buf_ex() decodes the hex string str and places the resulting string of bytes in the given buf. The character sep is the separator between the bytes, setting this to '\0' means that there is no separator. buf_n gives the size of the buffer. If buflen is not NULL, it is filled in with the result length. To find out how large the result will be, call this function with NULL for buf. Colons between two-character hex "bytes" are accepted and ignored. An odd number of hex digits is an error.

- -

OPENSSL_hexstr2buf() does the same thing as OPENSSL_hexstr2buf_ex(), but allocates the space for the result, and returns the result. It uses a default separator of ':'. The memory is allocated by calling OPENSSL_malloc() and should be released by calling OPENSSL_free().

- -

OPENSSL_buf2hexstr_ex() encodes the contents of the given buf with length buflen and places the resulting hexadecimal character string in the given str. The character sep is the separator between the bytes, setting this to '\0' means that there is no separator. str_n gives the size of the of the string buffer. If strlength is not NULL, it is filled in with the result length. To find out how large the result will be, call this function with NULL for str.

- -

OPENSSL_buf2hexstr() does the same thing as OPENSSL_buf2hexstr_ex(), but allocates the space for the result, and returns the result. It uses a default separator of ':'. The memory is allocated by calling OPENSSL_malloc() and should be released by calling OPENSSL_free().

- -

RETURN VALUES

- -

OPENSSL_hexchar2int returns the value of a decoded hex character, or -1 on error.

- -

OPENSSL_buf2hexstr() and OPENSSL_hexstr2buf() return a pointer to allocated memory, or NULL on error.

- -

OPENSSL_buf2hexstr_ex() and OPENSSL_hexstr2buf_ex() return 1 on success, or 0 on error.

- -

COPYRIGHT

- -

Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_ia32cap.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_ia32cap.html deleted file mode 100644 index 8eff3177..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_ia32cap.html +++ /dev/null @@ -1,189 +0,0 @@ - - - - -OPENSSL_ia32cap - - - - - - - - - - -

NAME

- -

OPENSSL_ia32cap - the x86[_64] processor capabilities vector

- -

SYNOPSIS

- -
env OPENSSL_ia32cap=... <application>
- -

DESCRIPTION

- -

OpenSSL supports a range of x86[_64] instruction set extensions. These extensions are denoted by individual bits in capability vector returned by processor in EDX:ECX register pair after executing CPUID instruction with EAX=1 input value (see Intel Application Note #241618). This vector is copied to memory upon toolkit initialization and used to choose between different code paths to provide optimal performance across wide range of processors. For the moment of this writing following bits are significant:

- -
- -
bit #4 denoting presence of Time-Stamp Counter.
-
- -
-
bit #19 denoting availability of CLFLUSH instruction;
-
- -
-
bit #20, reserved by Intel, is used to choose among RC4 code paths;
-
- -
-
bit #23 denoting MMX support;
-
- -
-
bit #24, FXSR bit, denoting availability of XMM registers;
-
- -
-
bit #25 denoting SSE support;
-
- -
-
bit #26 denoting SSE2 support;
-
- -
-
bit #28 denoting Hyperthreading, which is used to distinguish cores with shared cache;
-
- -
-
bit #30, reserved by Intel, denotes specifically Intel CPUs;
-
- -
-
bit #33 denoting availability of PCLMULQDQ instruction;
-
- -
-
bit #41 denoting SSSE3, Supplemental SSE3, support;
-
- -
-
bit #43 denoting AMD XOP support (forced to zero on non-AMD CPUs);
-
- -
-
bit #54 denoting availability of MOVBE instruction;
-
- -
-
bit #57 denoting AES-NI instruction set extension;
-
- -
-
bit #58, XSAVE bit, lack of which in combination with MOVBE is used to identify Atom Silvermont core;
-
- -
-
bit #59, OSXSAVE bit, denoting availability of YMM registers;
-
- -
-
bit #60 denoting AVX extension;
-
- -
-
bit #62 denoting availability of RDRAND instruction;
-
- -
-
- -

For example, in 32-bit application context clearing bit #26 at run-time disables high-performance SSE2 code present in the crypto library, while clearing bit #24 disables SSE2 code operating on 128-bit XMM register bank. You might have to do the latter if target OpenSSL application is executed on SSE2 capable CPU, but under control of OS that does not enable XMM registers. Historically address of the capability vector copy was exposed to application through OPENSSL_ia32cap_loc(), but not anymore. Now the only way to affect the capability detection is to set OPENSSL_ia32cap environment variable prior target application start. To give a specific example, on Intel P4 processor env OPENSSL_ia32cap=0x16980010 apps/openssl, or better yet env OPENSSL_ia32cap=~0x1000000 apps/openssl would achieve the desired effect. Alternatively you can reconfigure the toolkit with no-sse2 option and recompile.

- -

Less intuitive is clearing bit #28, or ~0x10000000 in the "environment variable" terms. The truth is that it's not copied from CPUID output verbatim, but is adjusted to reflect whether or not the data cache is actually shared between logical cores. This in turn affects the decision on whether or not expensive countermeasures against cache-timing attacks are applied, most notably in AES assembler module.

- -

The capability vector is further extended with EBX value returned by CPUID with EAX=7 and ECX=0 as input. Following bits are significant:

- -
- -
bit #64+3 denoting availability of BMI1 instructions, e.g. ANDN;
-
- -
-
bit #64+5 denoting availability of AVX2 instructions;
-
- -
-
bit #64+8 denoting availability of BMI2 instructions, e.g. MULX and RORX;
-
- -
-
bit #64+16 denoting availability of AVX512F extension;
-
- -
-
bit #64+17 denoting availability of AVX512DQ extension;
-
- -
-
bit #64+18 denoting availability of RDSEED instruction;
-
- -
-
bit #64+19 denoting availability of ADCX and ADOX instructions;
-
- -
-
bit #64+21 denoting availability of VPMADD52[LH]UQ instructions, aka AVX512IFMA extension;
-
- -
-
bit #64+29 denoting availability of SHA extension;
-
- -
-
bit #64+30 denoting availability of AVX512BW extension;
-
- -
-
bit #64+31 denoting availability of AVX512VL extension;
-
- -
-
bit #64+41 denoting availability of VAES extension;
-
- -
-
bit #64+42 denoting availability of VPCLMULQDQ extension;
-
- -
-
- -

To control this extended capability word use : as delimiter when setting up OPENSSL_ia32cap environment variable. For example assigning :~0x20 would disable AVX2 code paths, and :0 - all post-AVX extensions.

- -

RETURN VALUES

- -

Not available.

- -

COPYRIGHT

- -

Copyright 2004-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_init_crypto.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_init_crypto.html deleted file mode 100644 index de4c9047..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_init_crypto.html +++ /dev/null @@ -1,228 +0,0 @@ - - - - -OPENSSL_init_crypto - - - - - - - - - - -

NAME

- -

OPENSSL_INIT_new, OPENSSL_INIT_set_config_filename, OPENSSL_INIT_set_config_appname, OPENSSL_INIT_set_config_file_flags, OPENSSL_INIT_free, OPENSSL_init_crypto, OPENSSL_cleanup, OPENSSL_atexit, OPENSSL_thread_stop_ex, OPENSSL_thread_stop - OpenSSL initialisation and deinitialisation functions

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-void OPENSSL_cleanup(void);
-int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings);
-int OPENSSL_atexit(void (*handler)(void));
-void OPENSSL_thread_stop_ex(OSSL_LIB_CTX *ctx);
-void OPENSSL_thread_stop(void);
-
-OPENSSL_INIT_SETTINGS *OPENSSL_INIT_new(void);
-int OPENSSL_INIT_set_config_filename(OPENSSL_INIT_SETTINGS *init,
-                                     const char* filename);
-int OPENSSL_INIT_set_config_file_flags(OPENSSL_INIT_SETTINGS *init,
-                                       unsigned long flags);
-int OPENSSL_INIT_set_config_appname(OPENSSL_INIT_SETTINGS *init,
-                                    const char* name);
-void OPENSSL_INIT_free(OPENSSL_INIT_SETTINGS *init);
- -

DESCRIPTION

- -

During normal operation OpenSSL (libcrypto) will allocate various resources at start up that must, subsequently, be freed on close down of the library. Additionally some resources are allocated on a per thread basis (if the application is multi-threaded), and these resources must be freed prior to the thread closing.

- -

As of version 1.1.0 OpenSSL will automatically allocate all resources that it needs so no explicit initialisation is required. Similarly it will also automatically deinitialise as required.

- -

However, there may be situations when explicit initialisation is desirable or needed, for example when some nondefault initialisation is required. The function OPENSSL_init_crypto() can be used for this purpose for libcrypto (see also OPENSSL_init_ssl(3) for the libssl equivalent).

- -

Numerous internal OpenSSL functions call OPENSSL_init_crypto(). Therefore, in order to perform nondefault initialisation, OPENSSL_init_crypto() MUST be called by application code prior to any other OpenSSL function calls.

- -

The opts parameter specifies which aspects of libcrypto should be initialised. Valid options are:

- -
- -
OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS
-
- -

Suppress automatic loading of the libcrypto error strings. This option is not a default option. Once selected subsequent calls to OPENSSL_init_crypto() with the option OPENSSL_INIT_LOAD_CRYPTO_STRINGS will be ignored.

- -
-
OPENSSL_INIT_LOAD_CRYPTO_STRINGS
-
- -

Automatic loading of the libcrypto error strings. With this option the library will automatically load the libcrypto error strings. This option is a default option. Once selected subsequent calls to OPENSSL_init_crypto() with the option OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS will be ignored.

- -
-
OPENSSL_INIT_ADD_ALL_CIPHERS
-
- -

With this option the library will automatically load and make available all libcrypto ciphers. This option is a default option. Once selected subsequent calls to OPENSSL_init_crypto() with the option OPENSSL_INIT_NO_ADD_ALL_CIPHERS will be ignored.

- -
-
OPENSSL_INIT_ADD_ALL_DIGESTS
-
- -

With this option the library will automatically load and make available all libcrypto digests. This option is a default option. Once selected subsequent calls to OPENSSL_init_crypto() with the option OPENSSL_INIT_NO_ADD_ALL_DIGESTS will be ignored.

- -
-
OPENSSL_INIT_NO_ADD_ALL_CIPHERS
-
- -

With this option the library will suppress automatic loading of libcrypto ciphers. This option is not a default option. Once selected subsequent calls to OPENSSL_init_crypto() with the option OPENSSL_INIT_ADD_ALL_CIPHERS will be ignored.

- -
-
OPENSSL_INIT_NO_ADD_ALL_DIGESTS
-
- -

With this option the library will suppress automatic loading of libcrypto digests. This option is not a default option. Once selected subsequent calls to OPENSSL_init_crypto() with the option OPENSSL_INIT_ADD_ALL_DIGESTS will be ignored.

- -
-
OPENSSL_INIT_LOAD_CONFIG
-
- -

With this option an OpenSSL configuration file will be automatically loaded and used by calling OPENSSL_config(). This is a default option. Note that in OpenSSL 1.1.1 this was the default for libssl but not for libcrypto (see OPENSSL_init_ssl(3) for further details about libssl initialisation). In OpenSSL 1.1.0 this was a nondefault option for both libssl and libcrypto. See the description of OPENSSL_INIT_new(), below.

- -
-
OPENSSL_INIT_NO_LOAD_CONFIG
-
- -

With this option the loading of OpenSSL configuration files will be suppressed. It is the equivalent of calling OPENSSL_no_config(). This is not a default option.

- -
-
OPENSSL_INIT_ASYNC
-
- -

With this option the library with automatically initialise the libcrypto async sub-library (see ASYNC_start_job(3)). This is a default option.

- -
-
OPENSSL_INIT_ENGINE_RDRAND
-
- -

With this option the library will automatically load and initialise the RDRAND engine (if available). This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ENGINE_DYNAMIC
-
- -

With this option the library will automatically load and initialise the dynamic engine. This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ENGINE_OPENSSL
-
- -

With this option the library will automatically load and initialise the openssl engine. This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ENGINE_CRYPTODEV
-
- -

With this option the library will automatically load and initialise the cryptodev engine (if available). This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ENGINE_CAPI
-
- -

With this option the library will automatically load and initialise the CAPI engine (if available). This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ENGINE_PADLOCK
-
- -

With this option the library will automatically load and initialise the padlock engine (if available). This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ENGINE_AFALG
-
- -

With this option the library will automatically load and initialise the AFALG engine. This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ENGINE_ALL_BUILTIN
-
- -

With this option the library will automatically load and initialise all the built in engines listed above with the exception of the openssl and afalg engines. This not a default option and is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_INIT_ATFORK
-
- -

With this option the library will register its fork handlers. See OPENSSL_fork_prepare(3) for details.

- -
-
OPENSSL_INIT_NO_ATEXIT
-
- -

By default OpenSSL will attempt to clean itself up when the process exits via an "atexit" handler. Using this option suppresses that behaviour. This means that the application will have to clean up OpenSSL explicitly using OPENSSL_cleanup().

- -
-
- -

Multiple options may be combined together in a single call to OPENSSL_init_crypto(). For example:

- -
OPENSSL_init_crypto(OPENSSL_INIT_NO_ADD_ALL_CIPHERS
-                    | OPENSSL_INIT_NO_ADD_ALL_DIGESTS, NULL);
- -

The OPENSSL_cleanup() function deinitialises OpenSSL (both libcrypto and libssl). All resources allocated by OpenSSL are freed. Typically there should be no need to call this function directly as it is initiated automatically on application exit. This is done via the standard C library atexit() function. In the event that the application will close in a manner that will not call the registered atexit() handlers then the application should call OPENSSL_cleanup() directly. Developers of libraries using OpenSSL are discouraged from calling this function and should instead, typically, rely on auto-deinitialisation. This is to avoid error conditions where both an application and a library it depends on both use OpenSSL, and the library deinitialises it before the application has finished using it.

- -

Once OPENSSL_cleanup() has been called the library cannot be reinitialised. Attempts to call OPENSSL_init_crypto() will fail and an ERR_R_INIT_FAIL error will be added to the error stack. Note that because initialisation has failed OpenSSL error strings will not be available, only an error code. This code can be put through the openssl errstr command line application to produce a human readable error (see openssl-errstr(1)).

- -

The OPENSSL_atexit() function enables the registration of a function to be called during OPENSSL_cleanup(). Stop handlers are called after deinitialisation of resources local to a thread, but before other process wide resources are freed. In the event that multiple stop handlers are registered, no guarantees are made about the order of execution.

- -

The OPENSSL_thread_stop_ex() function deallocates resources associated with the current thread for the given OSSL_LIB_CTX ctx. The ctx parameter can be NULL in which case the default OSSL_LIB_CTX is used.

- -

Typically, this function will be called automatically by the library when the thread exits as long as the OSSL_LIB_CTX has not been freed before the thread exits. If OSSL_LIB_CTX_free() is called OPENSSL_thread_stop_ex will be called automatically for the current thread (but not any other threads that may have used this OSSL_LIB_CTX).

- -

OPENSSL_thread_stop_ex should be called on all threads that will exit after the OSSL_LIB_CTX is freed. Typically this is not necessary for the default OSSL_LIB_CTX (because all resources are cleaned up on library exit) except if thread local resources should be freed before library exit, or under the circumstances described in the NOTES section below.

- -

OPENSSL_thread_stop() is the same as OPENSSL_thread_stop_ex() except that the default OSSL_LIB_CTX is always used.

- -

The OPENSSL_INIT_LOAD_CONFIG flag will load a configuration file, as with CONF_modules_load_file(3) with NULL filename and application name and the CONF_MFLAGS_IGNORE_MISSING_FILE, CONF_MFLAGS_IGNORE_RETURN_CODES and CONF_MFLAGS_DEFAULT_SECTION flags. The filename, application name, and flags can be customized by providing a non-null OPENSSL_INIT_SETTINGS object. The object can be allocated via OPENSSL_INIT_new(). The OPENSSL_INIT_set_config_filename() function can be used to specify a nondefault filename, which is copied and need not refer to persistent storage. Similarly, OPENSSL_INIT_set_config_appname() can be used to specify a nondefault application name. Finally, OPENSSL_INIT_set_file_flags can be used to specify nondefault flags. If the CONF_MFLAGS_IGNORE_RETURN_CODES flag is not included, any errors in the configuration file will cause an error return from OPENSSL_init_crypto or indirectly OPENSSL_init_ssl(3). The object can be released with OPENSSL_INIT_free() when done. If the argument to OPENSSL_INIT_free() is NULL, nothing is done.

- -

NOTES

- -

Resources local to a thread are deallocated automatically when the thread exits (e.g. in a pthreads environment, when pthread_exit() is called). On Windows platforms this is done in response to a DLL_THREAD_DETACH message being sent to the libcrypto32.dll entry point. Some windows functions may cause threads to exit without sending this message (for example ExitProcess()). If the application uses such functions, then the application must free up OpenSSL resources directly via a call to OPENSSL_thread_stop() on each thread. Similarly this message will also not be sent if OpenSSL is linked statically, and therefore applications using static linking should also call OPENSSL_thread_stop() on each thread. Additionally if OpenSSL is loaded dynamically via LoadLibrary() and the threads are not destroyed until after FreeLibrary() is called then each thread should call OPENSSL_thread_stop() prior to the FreeLibrary() call.

- -

On Linux/Unix where OpenSSL has been loaded via dlopen() and the application is multi-threaded and if dlclose() is subsequently called prior to the threads being destroyed then OpenSSL will not be able to deallocate resources associated with those threads. The application should either call OPENSSL_thread_stop() on each thread prior to the dlclose() call, or alternatively the original dlopen() call should use the RTLD_NODELETE flag (where available on the platform).

- -

RETURN VALUES

- -

The functions OPENSSL_init_crypto, OPENSSL_atexit() and OPENSSL_INIT_set_config_appname() return 1 on success or 0 on error.

- -

SEE ALSO

- -

OPENSSL_init_ssl(3)

- -

HISTORY

- -

The OPENSSL_init_crypto(), OPENSSL_cleanup(), OPENSSL_atexit(), OPENSSL_thread_stop(), OPENSSL_INIT_new(), OPENSSL_INIT_set_config_appname() and OPENSSL_INIT_free() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_init_ssl.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_init_ssl.html deleted file mode 100644 index ffbf63c6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_init_ssl.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -OPENSSL_init_ssl - - - - - - - - - - -

NAME

- -

OPENSSL_init_ssl - OpenSSL (libssl and libcrypto) initialisation

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int OPENSSL_init_ssl(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings);
- -

DESCRIPTION

- -

During normal operation OpenSSL (libssl and libcrypto) will allocate various resources at start up that must, subsequently, be freed on close down of the library. Additionally some resources are allocated on a per thread basis (if the application is multi-threaded), and these resources must be freed prior to the thread closing.

- -

As of version 1.1.0 OpenSSL will automatically allocate all resources that it needs so no explicit initialisation is required. Similarly it will also automatically deinitialise as required.

- -

However, there may be situations when explicit initialisation is desirable or needed, for example when some nondefault initialisation is required. The function OPENSSL_init_ssl() can be used for this purpose. Calling this function will explicitly initialise BOTH libcrypto and libssl. To explicitly initialise ONLY libcrypto see the OPENSSL_init_crypto(3) function.

- -

Numerous internal OpenSSL functions call OPENSSL_init_ssl(). Therefore, in order to perform nondefault initialisation, OPENSSL_init_ssl() MUST be called by application code prior to any other OpenSSL function calls.

- -

The opts parameter specifies which aspects of libssl and libcrypto should be initialised. Valid options for libcrypto are described on the OPENSSL_init_crypto(3) page. In addition to any libcrypto specific option the following libssl options can also be used:

- -
- -
OPENSSL_INIT_NO_LOAD_SSL_STRINGS
-
- -

Suppress automatic loading of the libssl error strings. This option is not a default option. Once selected subsequent calls to OPENSSL_init_ssl() with the option OPENSSL_INIT_LOAD_SSL_STRINGS will be ignored.

- -
-
OPENSSL_INIT_LOAD_SSL_STRINGS
-
- -

Automatic loading of the libssl error strings. This option is a default option. Once selected subsequent calls to OPENSSL_init_ssl() with the option OPENSSL_INIT_LOAD_SSL_STRINGS will be ignored.

- -
-
- -

OPENSSL_init_ssl() takes a settings parameter which can be used to set parameter values. See OPENSSL_init_crypto(3) for details.

- -

RETURN VALUES

- -

The function OPENSSL_init_ssl() returns 1 on success or 0 on error.

- -

SEE ALSO

- -

OPENSSL_init_crypto(3)

- -

HISTORY

- -

The OPENSSL_init_ssl() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_instrument_bus.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_instrument_bus.html deleted file mode 100644 index 79d2c8db..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_instrument_bus.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -OPENSSL_instrument_bus - - - - - - - - - - -

NAME

- -

OPENSSL_instrument_bus, OPENSSL_instrument_bus2 - instrument references to memory bus

- -

SYNOPSIS

- -
#ifdef OPENSSL_CPUID_OBJ
-size_t OPENSSL_instrument_bus(unsigned int *vector, size_t num);
-size_t OPENSSL_instrument_bus2(unsigned int *vector, size_t num, size_t max);
-#endif
- -

DESCRIPTION

- -

It was empirically found that timings of references to primary memory are subject to irregular, apparently non-deterministic variations. The subroutines in question instrument these references for purposes of gathering randomness for random number generator. In order to make it bus-bound a 'flush cache line' instruction is used between probes. In addition probes are added to vector elements in atomic or interlocked manner, which should contribute additional noise on multi-processor systems. This also means that vector[num] should be zeroed upon invocation (if you want to retrieve actual probe values).

- -

OPENSSL_instrument_bus() performs num probes and records the number of oscillator cycles every probe took.

- -

OPENSSL_instrument_bus2() on the other hand accumulates consecutive probes with the same value, i.e. in a way it records duration of periods when probe values appeared deterministic. The subroutine performs at most max probes in attempt to fill the vector[num], with max value of 0 meaning "as many as it takes."

- -

RETURN VALUES

- -

Return value of 0 indicates that CPU is not capable of performing the benchmark, either because oscillator counter or 'flush cache line' is not available on current platform. For reference, on x86 'flush cache line' was introduced with the SSE2 extensions.

- -

Otherwise number of recorded values is returned.

- -

COPYRIGHT

- -

Copyright 2011-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_load_builtin_modules.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_load_builtin_modules.html deleted file mode 100644 index 7f2a4a02..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_load_builtin_modules.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -OPENSSL_load_builtin_modules - - - - - - - - - - -

NAME

- -

OPENSSL_load_builtin_modules, ASN1_add_oid_module, ENGINE_add_conf_module - add standard configuration modules

- -

SYNOPSIS

- -
#include <openssl/conf.h>
-
-void OPENSSL_load_builtin_modules(void);
-void ASN1_add_oid_module(void);
-void ENGINE_add_conf_module(void);
- -

DESCRIPTION

- -

The function OPENSSL_load_builtin_modules() adds all the standard OpenSSL configuration modules to the internal list. They can then be used by the OpenSSL configuration code.

- -

ASN1_add_oid_module() adds just the ASN1 OBJECT module.

- -

ENGINE_add_conf_module() adds just the ENGINE configuration module.

- -

NOTES

- -

If the simple configuration function OPENSSL_config() is called then OPENSSL_load_builtin_modules() is called automatically.

- -

Applications which use the configuration functions directly will need to call OPENSSL_load_builtin_modules() themselves before any other configuration code.

- -

Applications should call OPENSSL_load_builtin_modules() to load all configuration modules instead of adding modules selectively: otherwise functionality may be missing from the application if an when new modules are added.

- -

RETURN VALUES

- -

None of the functions return a value.

- -

SEE ALSO

- -

config(5), OPENSSL_config(3)

- -

HISTORY

- -

ENGINE_add_conf_module() was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2004-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_malloc.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_malloc.html deleted file mode 100644 index ab897634..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_malloc.html +++ /dev/null @@ -1,172 +0,0 @@ - - - - -OPENSSL_malloc - - - - - - - - - - -

NAME

- -

OPENSSL_malloc_init, OPENSSL_malloc, OPENSSL_aligned_alloc, OPENSSL_zalloc, OPENSSL_realloc, OPENSSL_free, OPENSSL_clear_realloc, OPENSSL_clear_free, OPENSSL_cleanse, CRYPTO_malloc, CRYPTO_aligned_alloc, CRYPTO_zalloc, CRYPTO_realloc, CRYPTO_free, OPENSSL_strdup, OPENSSL_strndup, OPENSSL_memdup, OPENSSL_strlcpy, OPENSSL_strlcat, OPENSSL_strtoul, CRYPTO_strdup, CRYPTO_strndup, OPENSSL_mem_debug_push, OPENSSL_mem_debug_pop, CRYPTO_mem_debug_push, CRYPTO_mem_debug_pop, CRYPTO_clear_realloc, CRYPTO_clear_free, CRYPTO_malloc_fn, CRYPTO_realloc_fn, CRYPTO_free_fn, CRYPTO_get_mem_functions, CRYPTO_set_mem_functions, CRYPTO_get_alloc_counts, CRYPTO_set_mem_debug, CRYPTO_mem_ctrl, CRYPTO_mem_leaks, CRYPTO_mem_leaks_fp, CRYPTO_mem_leaks_cb, OPENSSL_MALLOC_FAILURES, OPENSSL_MALLOC_FD - Memory allocation functions

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-int OPENSSL_malloc_init(void);
-
-void *OPENSSL_malloc(size_t num);
-void *OPENSSL_aligned_alloc(size_t num, size_t alignment, void **freeptr);
-void *OPENSSL_zalloc(size_t num);
-void *OPENSSL_realloc(void *addr, size_t num);
-void OPENSSL_free(void *addr);
-char *OPENSSL_strdup(const char *str);
-char *OPENSSL_strndup(const char *str, size_t s);
-size_t OPENSSL_strlcat(char *dst, const char *src, size_t size);
-size_t OPENSSL_strlcpy(char *dst, const char *src, size_t size);
-int OPENSSL_strtoul(char *src, char **endptr, int base, unsigned long *num);
-void *OPENSSL_memdup(void *data, size_t s);
-void *OPENSSL_clear_realloc(void *p, size_t old_len, size_t num);
-void OPENSSL_clear_free(void *str, size_t num);
-void OPENSSL_cleanse(void *ptr, size_t len);
-
-void *CRYPTO_malloc(size_t num, const char *file, int line);
-void *CRYPTO_aligned_alloc(size_t num, size_t align, void **freeptr, 
-                           const char *file, int line);
-void *CRYPTO_zalloc(size_t num, const char *file, int line);
-void *CRYPTO_realloc(void *p, size_t num, const char *file, int line);
-void CRYPTO_free(void *str, const char *, int);
-char *CRYPTO_strdup(const char *p, const char *file, int line);
-char *CRYPTO_strndup(const char *p, size_t num, const char *file, int line);
-void *CRYPTO_clear_realloc(void *p, size_t old_len, size_t num,
-                           const char *file, int line);
-void CRYPTO_clear_free(void *str, size_t num, const char *, int);
-
-typedef void *(*CRYPTO_malloc_fn)(size_t num, const char *file, int line);
-typedef void *(*CRYPTO_realloc_fn)(void *addr, size_t num, const char *file,
-                                   int line);
-typedef void (*CRYPTO_free_fn)(void *addr, const char *file, int line);
-void CRYPTO_get_mem_functions(CRYPTO_malloc_fn *malloc_fn,
-                              CRYPTO_realloc_fn *realloc_fn,
-                              CRYPTO_free_fn *free_fn);
-int CRYPTO_set_mem_functions(CRYPTO_malloc_fn malloc_fn,
-                             CRYPTO_realloc_fn realloc_fn,
-                             CRYPTO_free_fn free_fn);
-
-void CRYPTO_get_alloc_counts(int *mcount, int *rcount, int *fcount);
-
-env OPENSSL_MALLOC_FAILURES=... <application>
-env OPENSSL_MALLOC_FD=... <application>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int CRYPTO_mem_leaks(BIO *b);
-int CRYPTO_mem_leaks_fp(FILE *fp);
-int CRYPTO_mem_leaks_cb(int (*cb)(const char *str, size_t len, void *u),
-                        void *u);
-
-int CRYPTO_set_mem_debug(int onoff);
-int CRYPTO_mem_ctrl(int mode);
-int OPENSSL_mem_debug_push(const char *info);
-int OPENSSL_mem_debug_pop(void);
-int CRYPTO_mem_debug_push(const char *info, const char *file, int line);
-int CRYPTO_mem_debug_pop(void);
- -

DESCRIPTION

- -

OpenSSL memory allocation is handled by the OPENSSL_xxx API. These are generally macro's that add the standard C __FILE__ and __LINE__ parameters and call a lower-level CRYPTO_xxx API. Some functions do not add those parameters, but exist for consistency.

- -

OPENSSL_malloc_init() does nothing and does not need to be called. It is included for compatibility with older versions of OpenSSL.

- -

OPENSSL_malloc(), OPENSSL_realloc(), and OPENSSL_free() are like the C malloc(), realloc(), and free() functions. OPENSSL_zalloc() calls memset() to zero the memory before returning.

- -

OPENSSL_aligned_alloc() operates just as OPENSSL_malloc does, but it allows for the caller to specify an alignment value, for instances in which the default alignment of malloc is insufficient for the callers needs. Note, the alignment value must be a power of 2, and the size specified must be a multiple of the alignment. NOTE: The call to OPENSSL_aligned_alloc() accepts a 3rd argument, freeptr which must point to a void pointer. On some platforms, there is no available library call to obtain memory allocations greater than what malloc provides. In this case, OPENSSL_aligned_alloc implements its own alignment routine, allocating additional memory and offsetting the returned pointer to be on the requested alignment boundary. In order to safely free allocations made by this method, the caller must return the value in the freeptr variable, rather than the returned pointer.

- -

OPENSSL_clear_realloc() and OPENSSL_clear_free() should be used when the buffer at addr holds sensitive information. The old buffer is filled with zero's by calling OPENSSL_cleanse() before ultimately calling OPENSSL_free(). If the argument to OPENSSL_free() is NULL, nothing is done.

- -

OPENSSL_cleanse() fills ptr of size len with a string of 0's. Use OPENSSL_cleanse() with care if the memory is a mapping of a file. If the storage controller uses write compression, then it's possible that sensitive tail bytes will survive zeroization because the block of zeros will be compressed. If the storage controller uses wear leveling, then the old sensitive data will not be overwritten; rather, a block of 0's will be written at a new physical location.

- -

OPENSSL_strdup(), OPENSSL_strndup() and OPENSSL_memdup() are like the equivalent C functions, except that memory is allocated by calling the OPENSSL_malloc() and should be released by calling OPENSSL_free().

- -

OPENSSL_strlcpy(), OPENSSL_strlcat() and OPENSSL_strnlen() are equivalents of the common C library functions and are provided for portability.

- -

OPENSSL_strtoul() is a wrapper around the POSIX function strtoul, with the same behaviors listed in the POSIX documentation, with the additional behavior that it validates the input str and num parameters for not being NULL, and confirms that at least a single byte of input has been consumed in the translation, returning an error in the event that no bytes were consumed.

- -

If no allocations have been done, it is possible to "swap out" the default implementations for OPENSSL_malloc(), OPENSSL_realloc() and OPENSSL_free() and replace them with alternate versions. CRYPTO_get_mem_functions() function fills in the given arguments with the function pointers for the current implementations. With CRYPTO_set_mem_functions(), you can specify a different set of functions. If any of malloc_fn, realloc_fn, or free_fn are NULL, then the function is not changed. While it's permitted to swap out only a few and not all the functions with CRYPTO_set_mem_functions(), it's recommended to swap them all out at once.

- -

If the library is built with the crypto-mdebug option, then one function, CRYPTO_get_alloc_counts(), and two additional environment variables, OPENSSL_MALLOC_FAILURES and OPENSSL_MALLOC_FD, are available.

- -

The function CRYPTO_get_alloc_counts() fills in the number of times each of CRYPTO_malloc(), CRYPTO_realloc(), and CRYPTO_free() have been called, into the values pointed to by mcount, rcount, and fcount, respectively. If a pointer is NULL, then the corresponding count is not stored.

- -

The variable OPENSSL_MALLOC_FAILURES controls how often allocations should fail. It is a set of fields separated by semicolons, which each field is a count (defaulting to zero) and an optional atsign and percentage (defaulting to 100). If the count is zero, then it lasts forever. For example, 100;@25 or 100@0;0@25 means the first 100 allocations pass, then all other allocations (until the program exits or crashes) have a 25% chance of failing.

- -

If the variable OPENSSL_MALLOC_FD is parsed as a positive integer, then it is taken as an open file descriptor. This is used in conjunction with OPENSSL_MALLOC_FAILURES described above. For every allocation it will log details about how many allocations there have been so far, what percentage chance there is for this allocation failing, and whether it has actually failed. The following example in classic shell syntax shows how to use this (will not work on all platforms):

- -
OPENSSL_MALLOC_FAILURES='200;@10'
-export OPENSSL_MALLOC_FAILURES
-OPENSSL_MALLOC_FD=3
-export OPENSSL_MALLOC_FD
-...app invocation... 3>/tmp/log$$
- -

RETURN VALUES

- -

OPENSSL_malloc_init(), OPENSSL_free(), OPENSSL_clear_free() CRYPTO_free(), CRYPTO_clear_free() and CRYPTO_get_mem_functions() return no value.

- -

OPENSSL_malloc(), OPENSSL_aligned_alloc(), OPENSSL_zalloc(), OPENSSL_realloc(), OPENSSL_clear_realloc(), CRYPTO_malloc(), CRYPTO_zalloc(), CRYPTO_realloc(), CRYPTO_clear_realloc(), OPENSSL_strdup(), and OPENSSL_strndup() return a pointer to allocated memory or NULL on error.

- -

CRYPTO_set_mem_functions() returns 1 on success or 0 on failure (almost always because allocations have already happened).

- -

CRYPTO_mem_leaks(), CRYPTO_mem_leaks_fp(), CRYPTO_mem_leaks_cb(), CRYPTO_set_mem_debug(), and CRYPTO_mem_ctrl() are deprecated and are no-ops that always return -1. OPENSSL_mem_debug_push(), OPENSSL_mem_debug_pop(), CRYPTO_mem_debug_push(), and CRYPTO_mem_debug_pop() are deprecated and are no-ops that always return 0.

- -

OPENSSL_strtoul() returns 1 on success and 0 in the event that an error has occurred. Specifically, 0 is returned in the following events:

- - - -

Note that a success condition does not imply that the expected translation has been performed. For instance calling

- -
OPENSSL_strtoul("0x12345", &endptr, 10, &num);
- -

will result in a successful translation with num having the value 0, and *endptr = 'x'. Be sure to validate how much data was consumed when calling this function.

- -

HISTORY

- -

OPENSSL_mem_debug_push(), OPENSSL_mem_debug_pop(), CRYPTO_mem_debug_push(), CRYPTO_mem_debug_pop(), CRYPTO_mem_leaks(), CRYPTO_mem_leaks_fp(), CRYPTO_mem_leaks_cb(), CRYPTO_set_mem_debug(), CRYPTO_mem_ctrl() were deprecated in OpenSSL 3.0. The memory-leak checking has been deprecated in OpenSSL 3.0 in favor of clang's memory and leak sanitizer. OPENSSL_aligned_alloc(), CRYPTO_aligned_alloc() were added in OpenSSL 3.4.0

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_riscvcap.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_riscvcap.html deleted file mode 100644 index 6b248c2b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_riscvcap.html +++ /dev/null @@ -1,269 +0,0 @@ - - - - -OPENSSL_riscvcap - - - - - - - - - - -

NAME

- -

OPENSSL_riscvcap - the RISC-V processor capabilities vector

- -

SYNOPSIS

- -
env OPENSSL_riscvcap=... <application>
- -

DESCRIPTION

- -

libcrypto supports RISC-V instruction set extensions. These extensions are denoted by individual extension names in the capabilities vector. For Linux platform, when libcrypto is initialized, the results returned by the RISC-V Hardware Probing syscall (hwprobe) are stored in the vector. Otherwise all capabilities are disabled.

- -

To override the set of instructions available to an application, you can set the OPENSSL_riscvcap environment variable before you start the application.

- -

The environment variable is similar to the RISC-V ISA string defined in the RISC-V Instruction Set Manual. It is case insensitive. Though due to the limit of the environment variable parser inside libcrypto, an extension must be prefixed with an underscore to make it recognizable. This also applies to the Vector extension.

- -
OPENSSL_riscvcap="rv64gc_v_zba_zbb_zbs..."
- -

Note that extension implication is currently not implemented. For example, when "rv64gc_b" is provided as the environment variable, zba/zbb/zbs would not be implied in the capability vector.

- -

Currently only these extensions are recognized:

- -
- -
ZBA
-
- -

Address Generation

- -

Could be detected using hwprobe for Linux kernel >= 6.5

- -
-
ZBB
-
- -

Basic bit-manipulation

- -

Could be detected using hwprobe for Linux kernel >= 6.5

- -
-
ZBC
-
- -

Carry-less multiplication

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZBS
-
- -

Single-bit instructions

- -

Could be detected using hwprobe for Linux kernel >= 6.5

- -
-
ZBKB
-
- -

Bit-manipulation for Cryptography

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZBKC
-
- -

Carry-less multiplication for Cryptography

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZBKX
-
- -

Crossbar permutations

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZKND
-
- -

NIST Suite: AES Decryption

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZKNE
-
- -

NIST Suite: AES Encryption

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZKNH
-
- -

NIST Suite: Hash Function Instructions

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZKSED
-
- -

ShangMi Suite: SM4 Block Cipher Instructions

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZKSH
-
- -

ShangMi Suite: SM3 Hash Function Instructions

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZKR
-
- -

Entropy Source Extension

- -
-
ZKT
-
- -

Data Independent Execution Latency

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
V
-
- -

Vector Extension for Application Processors

- -

Could be detected using hwprobe for Linux kernel >= 6.5

- -
-
ZVBB
-
- -

Vector Basic Bit-manipulation

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVBC
-
- -

Vector Carryless Multiplication

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVKB
-
- -

Vector Cryptography Bit-manipulation

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVKG
-
- -

Vector GCM/GMAC

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVKNED
-
- -

NIST Suite: Vector AES Block Cipher

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVKNHA
-
- -

NIST Suite: Vector SHA-2 Secure Hash

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVKNHB
-
- -

NIST Suite: Vector SHA-2 Secure Hash

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVKSED
-
- -

ShangMi Suite: SM4 Block Cipher

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
ZVKSH
-
- -

ShangMi Suite: SM3 Secure Hash

- -

Could be detected using hwprobe for Linux kernel >= 6.8

- -
-
- -

RETURN VALUES

- -

Not available.

- -

EXAMPLES

- -

Check currently detected capabilities

- -
$ openssl info -cpusettings
-OPENSSL_riscvcap=ZBA_ZBB_ZBC_ZBS_V
- -

Disables all instruction set extensions:

- -
OPENSSL_riscvcap="rv64gc"
- -

Only enable the vector extension:

- -
OPENSSL_riscvcap="rv64gc_v"
- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_s390xcap.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_s390xcap.html deleted file mode 100644 index d49f0070..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_s390xcap.html +++ /dev/null @@ -1,220 +0,0 @@ - - - - -OPENSSL_s390xcap - - - - - - - - - - -

NAME

- -

OPENSSL_s390xcap - the IBM z processor capabilities vector

- -

SYNOPSIS

- -
env OPENSSL_s390xcap=... <application>
- -

DESCRIPTION

- -

libcrypto supports z/Architecture instruction set extensions. These extensions are denoted by individual bits in the capabilities vector. When libcrypto is initialized, the bits returned by the STFLE instruction and by the QUERY functions are stored in the vector.

- -

To change the set of instructions available to an application, you can set the OPENSSL_s390xcap environment variable before you start the application. After initialization, the capability vector is ANDed bitwise with a mask which is derived from the environment variable.

- -

The environment variable is a semicolon-separated list of tokens which is processed from left to right (whitespace is ignored):

- -
OPENSSL_s390xcap="<tok1>;<tok2>;..."
- -

There are four types of tokens:

- -
- -
<string>
-
- -

The name of a processor generation. A bit in the environment variable's mask is set to one if and only if the specified processor generation implements the corresponding instruction set extension. Possible values are z900, z990, z9, z10, z196, zEC12, z13, z14, z15, and z16.

- -
-
<string>:<mask>:<mask>
-
- -

The name of an instruction followed by two 64-bit masks. The part of the environment variable's mask corresponding to the specified instruction is set to the specified 128-bit mask. Possible values are kimd, klmd, km, kmc, kmac, kmctr, kmo, kmf, prno, kma, pcc and kdsa.

- -
-
stfle:<mask>:<mask>:<mask>
-
- -

Store-facility-list-extended (stfle) followed by three 64-bit masks. The part of the environment variable's mask corresponding to the stfle instruction is set to the specified 192-bit mask.

- -
-
nocex
-
- -

Deactivate modular exponentiation and CRT operation offloading to Crypto Express Adapters.

- -
-
- -

The 64-bit masks are specified in hexadecimal notation. The 0x prefix is optional. Prefix a mask with a tilde, ~, to denote a bitwise NOT operation.

- -

The following is a list of significant bits for each instruction. Colon rows separate the individual 64-bit masks. The bit numbers in the first column are consistent with [1], that is, 0 denotes the leftmost bit and the numbering is continuous across 64-bit mask boundaries.

- -
     Bit     Mask     Facility/Function
-
-stfle:
-     # 17    1<<46    message-security assist
-     # 25    1<<38    store-clock-fast facility
-     :
-     # 76    1<<51    message-security assist extension 3
-     # 77    1<<50    message-security assist extension 4
-     # 86    1<<41    message-security-assist extension 12
-     :
-     #129    1<<62    vector facility
-     #134    1<<57    vector packed decimal facility
-     #135    1<<56    vector enhancements facility 1
-     #146    1<<45    message-security assist extension 8
-     #155    1<<36    message-security assist extension 9
-
-kimd :
-     #  1    1<<62    KIMD-SHA-1
-     #  2    1<<61    KIMD-SHA-256
-     #  3    1<<60    KIMD-SHA-512
-     # 32    1<<31    KIMD-SHA3-224
-     # 33    1<<30    KIMD-SHA3-256
-     # 34    1<<29    KIMD-SHA3-384
-     # 35    1<<28    KIMD-SHA3-512
-     # 36    1<<27    KIMD-SHAKE-128
-     # 37    1<<26    KIMD-SHAKE-256
-     :
-     # 65    1<<62    KIMD-GHASH
-
-klmd :
-     # 32    1<<31    KLMD-SHA3-224
-     # 33    1<<30    KLMD-SHA3-256
-     # 34    1<<29    KLMD-SHA3-384
-     # 35    1<<28    KLMD-SHA3-512
-     # 36    1<<27    KLMD-SHAKE-128
-     # 37    1<<26    KLMD-SHAKE-256
-     :
-
-km   :
-     # 18    1<<45    KM-AES-128
-     # 19    1<<44    KM-AES-192
-     # 20    1<<43    KM-AES-256
-     # 50    1<<13    KM-XTS-AES-128
-     # 52    1<<11    KM-XTS-AES-256
-     :
-     # 82    1<<45    KM-XTS-AES-128-MSA10
-     # 84    1<<43    KM-XTS-AES-256-MSA10
-
-kmc  :
-     # 18    1<<45    KMC-AES-128
-     # 19    1<<44    KMC-AES-192
-     # 20    1<<43    KMC-AES-256
-     :
-
-kmac :
-     # 18    1<<45    KMAC-AES-128
-     # 19    1<<44    KMAC-AES-192
-     # 20    1<<43    KMAC-AES-256
-     :
-     # 112   1<<15    KMAC-SHA-224
-     # 113   1<<14    KMAC-SHA-256
-     # 114   1<<13    KMAC-SHA-384
-     # 115   1<<12    KMAC-SHA-512
-
-kmctr:
-     :
-
-kmo  :
-     # 18    1<<45    KMO-AES-128
-     # 19    1<<44    KMO-AES-192
-     # 20    1<<43    KMO-AES-256
-     :
-
-kmf  :
-     # 18    1<<45    KMF-AES-128
-     # 19    1<<44    KMF-AES-192
-     # 20    1<<43    KMF-AES-256
-     :
-
-prno :
-     :
-
-kma  :
-     # 18    1<<45    KMA-GCM-AES-128
-     # 19    1<<44    KMA-GCM-AES-192
-     # 20    1<<43    KMA-GCM-AES-256
-     :
-
-pcc  :
-     :
-     # 64    1<<63    PCC-Scalar-Multiply-P256
-     # 65    1<<62    PCC-Scalar-Multiply-P384
-     # 66    1<<61    PCC-Scalar-Multiply-P521
-     # 72    1<<55    PCC-Scalar-Multiply-Ed25519
-     # 73    1<<54    PCC-Scalar-Multiply-Ed448
-     # 80    1<<47    PCC-Scalar-Multiply-X25519
-     # 81    1<<46    PCC-Scalar-Multiply-X448
-
-kdsa :
-     #  1    1<<62    KDSA-ECDSA-Verify-P256
-     #  2    1<<61    KDSA-ECDSA-Verify-P384
-     #  3    1<<60    KDSA-ECDSA-Verify-P521
-     #  9    1<<54    KDSA-ECDSA-Sign-P256
-     # 10    1<<53    KDSA-ECDSA-Sign-P384
-     # 11    1<<52    KDSA-ECDSA-Sign-P521
-     # 32    1<<31    KDSA-EdDSA-Verify-Ed25519
-     # 36    1<<27    KDSA-EdDSA-Verify-Ed448
-     # 40    1<<23    KDSA-EdDSA-Sign-Ed25519
-     # 44    1<<19    KDSA-EdDSA-Sign-Ed448
-     :
- -

RETURN VALUES

- -

Not available.

- -

EXAMPLES

- -

Disables all instruction set extensions which the z196 processor does not implement:

- -
OPENSSL_s390xcap="z196"
- -

Disables the vector facility:

- -
OPENSSL_s390xcap="stfle:~0:~0:~0x4000000000000000"
- -

Disables the KM-XTS-AES and the KIMD-SHAKE function codes:

- -
OPENSSL_s390xcap="km:~0x2800:~0;kimd:~0xc000000:~0"
- -

SEE ALSO

- -

[1] z/Architecture Principles of Operation, SA22-7832-12

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_secure_malloc.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_secure_malloc.html deleted file mode 100644 index 4beb1a6e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_secure_malloc.html +++ /dev/null @@ -1,116 +0,0 @@ - - - - -OPENSSL_secure_malloc - - - - - - - - - - -

NAME

- -

CRYPTO_secure_malloc_init, CRYPTO_secure_malloc_initialized, CRYPTO_secure_malloc_done, OPENSSL_secure_malloc, CRYPTO_secure_malloc, OPENSSL_secure_zalloc, CRYPTO_secure_zalloc, OPENSSL_secure_free, CRYPTO_secure_free, OPENSSL_secure_clear_free, CRYPTO_secure_clear_free, OPENSSL_secure_actual_size, CRYPTO_secure_allocated, CRYPTO_secure_used - secure heap storage

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-int CRYPTO_secure_malloc_init(size_t size, size_t minsize);
-
-int CRYPTO_secure_malloc_initialized();
-
-int CRYPTO_secure_malloc_done();
-
-void *OPENSSL_secure_malloc(size_t num);
-void *CRYPTO_secure_malloc(size_t num, const char *file, int line);
-
-void *OPENSSL_secure_zalloc(size_t num);
-void *CRYPTO_secure_zalloc(size_t num, const char *file, int line);
-
-void OPENSSL_secure_free(void* ptr);
-void CRYPTO_secure_free(void *ptr, const char *, int);
-
-void OPENSSL_secure_clear_free(void* ptr, size_t num);
-void CRYPTO_secure_clear_free(void *ptr, size_t num, const char *, int);
-
-size_t OPENSSL_secure_actual_size(const void *ptr);
-
-int CRYPTO_secure_allocated(const void *ptr);
-size_t CRYPTO_secure_used();
- -

DESCRIPTION

- -

In order to help protect applications (particularly long-running servers) from pointer overruns or underruns that could return arbitrary data from the program's dynamic memory area, where keys and other sensitive information might be stored, OpenSSL supports the concept of a "secure heap." The level and type of security guarantees depend on the operating system. It is a good idea to review the code and see if it addresses your threat model and concerns.

- -

If a secure heap is used, then private key BIGNUM values are stored there. This protects long-term storage of private keys, but will not necessarily put all intermediate values and computations there.

- -

CRYPTO_secure_malloc_init() creates the secure heap, with the specified size in bytes. The minsize parameter is the minimum size to allocate from the heap or zero to use a reasonable default value. Both size and, if specified, minsize must be a power of two and minsize should generally be small, for example 16 or 32. minsize must be less than a quarter of size in any case.

- -

CRYPTO_secure_malloc_initialized() indicates whether or not the secure heap as been initialized and is available.

- -

CRYPTO_secure_malloc_done() releases the heap and makes the memory unavailable to the process if all secure memory has been freed. It can take noticeably long to complete.

- -

OPENSSL_secure_malloc() allocates num bytes from the heap. If CRYPTO_secure_malloc_init() is not called, this is equivalent to calling OPENSSL_malloc(). It is a macro that expands to CRYPTO_secure_malloc() and adds the __FILE__ and __LINE__ parameters.

- -

OPENSSL_secure_zalloc() and CRYPTO_secure_zalloc() are like OPENSSL_secure_malloc() and CRYPTO_secure_malloc(), respectively, except that they call memset() to zero the memory before returning.

- -

OPENSSL_secure_free() releases the memory at ptr back to the heap. It must be called with a value previously obtained from OPENSSL_secure_malloc(). If CRYPTO_secure_malloc_init() is not called, this is equivalent to calling OPENSSL_free(). It exists for consistency with OPENSSL_secure_malloc() , and is a macro that expands to CRYPTO_secure_free() and adds the __FILE__ and __LINE__ parameters.. If the argument to OPENSSL_secure_free() is NULL, nothing is done.

- -

OPENSSL_secure_clear_free() is similar to OPENSSL_secure_free() except that it has an additional num parameter which is used to clear the memory if it was not allocated from the secure heap. If CRYPTO_secure_malloc_init() is not called, this is equivalent to calling OPENSSL_clear_free(). If the argument to OPENSSL_secure_clear_free() is NULL, nothing is done.

- -

OPENSSL_secure_actual_size() tells the actual size allocated to the pointer; implementations may allocate more space than initially requested, in order to "round up" and reduce secure heap fragmentation.

- -

OPENSSL_secure_allocated() tells if a pointer is allocated in the secure heap.

- -

CRYPTO_secure_used() returns the number of bytes allocated in the secure heap.

- -

RETURN VALUES

- -

CRYPTO_secure_malloc_init() returns 0 on failure, 1 if successful, and 2 if successful but the heap could not be protected by memory mapping.

- -

CRYPTO_secure_malloc_initialized() returns 1 if the secure heap is available (that is, if CRYPTO_secure_malloc_init() has been called, but CRYPTO_secure_malloc_done() has not been called or failed) or 0 if not.

- -

OPENSSL_secure_malloc() and OPENSSL_secure_zalloc() return a pointer into the secure heap of the requested size, or NULL if memory could not be allocated.

- -

CRYPTO_secure_allocated() returns 1 if the pointer is in the secure heap, or 0 if not.

- -

CRYPTO_secure_malloc_done() returns 1 if the secure memory area is released, or 0 if not.

- -

OPENSSL_secure_free() and OPENSSL_secure_clear_free() return no values.

- -

SEE ALSO

- -

OPENSSL_malloc(3), BN_new(3)

- -

HISTORY

- -

The OPENSSL_secure_clear_free() function was added in OpenSSL 1.1.0g.

- -

The second argument to CRYPTO_secure_malloc_init() was changed from an int to a size_t in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OPENSSL_strcasecmp.html b/openssl-install/share/doc/openssl/html/man3/OPENSSL_strcasecmp.html deleted file mode 100644 index 7ca1f41f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OPENSSL_strcasecmp.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -OPENSSL_strcasecmp - - - - - - - - - - -

NAME

- -

OPENSSL_strcasecmp, OPENSSL_strncasecmp - compare two strings ignoring case

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-int OPENSSL_strcasecmp(const char *s1, const char *s2);
-int OPENSSL_strncasecmp(const char *s1, const char *s2, size_t n);
- -

DESCRIPTION

- -

The OPENSSL_strcasecmp function performs a byte-by-byte comparison of the strings s1 and s2, ignoring the case of the characters.

- -

The OPENSSL_strncasecmp function is similar, except that it compares no more than n bytes of s1 and s2.

- -

In POSIX-compatible system and on Windows these functions use "C" locale for case insensitive. Otherwise the comparison is done in current locale.

- -

RETURN VALUES

- -

Both functions return an integer less than, equal to, or greater than zero if s1 is found, respectively, to be less than, to match, or be greater than s2.

- -

NOTES

- -

OpenSSL extensively uses case insensitive comparison of ASCII strings. Though OpenSSL itself is locale-agnostic, the applications using OpenSSL libraries may unpredictably suffer when they use localization (e.g. Turkish locale is well-known with a specific I/i cases). These functions use C locale for string comparison.

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.3.

- -

COPYRIGHT

- -

Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ALGORITHM.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ALGORITHM.html deleted file mode 100644 index e7d32a64..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ALGORITHM.html +++ /dev/null @@ -1,146 +0,0 @@ - - - - -OSSL_ALGORITHM - - - - - - - - - - -

NAME

- -

OSSL_ALGORITHM - OpenSSL Core type to define a fetchable algorithm

- -

SYNOPSIS

- -
#include <openssl/core.h>
-
-typedef struct ossl_algorithm_st OSSL_ALGORITHM;
-struct ossl_algorithm_st {
-    const char *algorithm_names;     /* key */
-    const char *property_definition; /* key */
-    const OSSL_DISPATCH *implementation;
-    const char *algorithm_description;
-};
- -

DESCRIPTION

- -

The OSSL_ALGORITHM type is a public structure that describes an algorithm that a provider(7) provides. Arrays of this type are returned by providers on demand from the OpenSSL libraries to describe what algorithms the providers provide implementations of, and with what properties.

- -

Arrays of this type must be terminated with a tuple where algorithm_names is NULL.

- -

This type of array is typically returned by the provider's operation querying function, further described in "Provider Functions" in provider-base(7).

- -

OSSL_ALGORITHM fields

- -
- -
algorithm_names
-
- -

This string is a colon separated set of names / identities, and is used by the appropriate fetching functionality (such as EVP_CIPHER_fetch(3), EVP_MD_fetch(3), etc) to find the desired algorithm.

- -

Multiple names / identities allow a specific algorithm implementation to be fetched multiple ways. For example, the RSA algorithm has the following known identities:

- -
    - -
  • RSA

    - -
  • -
  • rsaEncryption

    - -

    This is the name of the algorithm's OBJECT IDENTIFIER (OID), as given by the PKCS#1 RFC's ASN.1 module

    - -
  • -
  • 1.2.840.113549.1.1.1

    - -

    This is the OID itself for rsaEncryption, in canonical decimal text form.

    - -
  • -
- -

The resulting algorithm_names string would look like this:

- -
"RSA:rsaEncryption:1.2.840.113549.1.1.1"
- -

The OpenSSL libraries use the first of the algorithm names as the main or canonical name, on a per algorithm implementation basis.

- -

See the notes "On the subject of algorithm names" below for a more in depth discussion on algorithm_names and how that may interact with applications and libraries, including OpenSSL's.

- -
-
property_definition
-
- -

This string defines a set of properties associated with a particular algorithm implementation, and is used by the appropriate fetching functionality (such as EVP_CIPHER_fetch(3), EVP_MD_fetch(3), etc) for a finer grained lookup of an algorithm implementation, which is useful in case multiple implementations of the same algorithm are available.

- -

See property(7) for a further description of the contents of this string.

- -
-
implementation
-
- -

Pointer to an OSSL_DISPATCH(3) array, containing pointers to the functions of a particular algorithm implementation.

- -
-
algorithm_description
-
- -

A string with a short human-readable description of the algorithm.

- -
-
- -

NOTES

- -

On the subject of algorithm names

- -

Providers may find the need to register ASN.1 OIDs for algorithms using OBJ_create(3) (via the core_obj_create upcall described in provider-base(7), because some application or library -- possibly still the OpenSSL libraries, even -- use NIDs to look up algorithms.

- -

In that scenario, you must make sure that the corresponding OSSL_ALGORITHM's algorithm_names includes both the short and the long name.

- -

Most of the time, registering ASN.1 OIDs like this shouldn't be necessary, and applications and libraries are encouraged to use OBJ_obj2txt(3) to get a text representation of the OID, which may be a long or short name for OIDs that are registered, or the OID itself in canonical decimal text form if not (or if OBJ_obj2txt(3) is called with no_name = 1).

- -

It's recommended to make sure that the corresponding OSSL_ALGORITHM's algorithm_names include known names as well as the OID itself in canonical decimal text form. That should cover all scenarios.

- -

SEE ALSO

- -

crypto(7), provider-base(7), openssl-core.h(7), openssl-core_dispatch.h(7), OSSL_DISPATCH(3)

- -

HISTORY

- -

OSSL_ALGORITHM was added in OpenSSL 3.0

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CALLBACK.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CALLBACK.html deleted file mode 100644 index 6800e892..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CALLBACK.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -OSSL_CALLBACK - - - - - - - - - - -

NAME

- -

OSSL_CALLBACK, OSSL_PASSPHRASE_CALLBACK - OpenSSL Core type to define callbacks

- -

SYNOPSIS

- -
#include <openssl/core.h>
-typedef int (OSSL_CALLBACK)(const OSSL_PARAM params[], void *arg);
-typedef int (OSSL_PASSPHRASE_CALLBACK)(char *pass, size_t pass_size,
-                                       size_t *pass_len,
-                                       const OSSL_PARAM params[],
-                                       void *arg);
- -

DESCRIPTION

- -

For certain events or activities, provider functionality may need help from the application or the calling OpenSSL libraries themselves. For example, user input or direct (possibly optional) user output could be implemented this way.

- -

Callback functions themselves are always provided by or through the calling OpenSSL libraries, along with a generic pointer to data arg. As far as the function receiving the pointer to the function pointer and arg is concerned, the data that arg points at is opaque, and the pointer should simply be passed back to the callback function when it's called.

- -
- -
OSSL_CALLBACK
-
- -

This is a generic callback function. When calling this callback function, the caller is expected to build an OSSL_PARAM(3) array of data it wants or is expected to pass back, and pass that as params, as well as the opaque data pointer it received, as arg.

- -
-
OSSL_PASSPHRASE_CALLBACK
-
- -

This is a specialised callback function, used specifically to prompt the user for a passphrase. When calling this callback function, a buffer to store the pass phrase needs to be given with pass, and its size with pass_size. The length of the prompted pass phrase will be given back in *pass_len.

- -

Additional parameters can be passed with the OSSL_PARAM(3) array params,

- -
-
- -

SEE ALSO

- -

openssl-core.h(7)

- -

HISTORY

- -

The types described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ATAV_set0.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ATAV_set0.html deleted file mode 100644 index 02a26fac..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ATAV_set0.html +++ /dev/null @@ -1,108 +0,0 @@ - - - - -OSSL_CMP_ATAV_set0 - - - - - - - - - - -

NAME

- -

OSSL_CMP_ATAV, OSSL_CMP_ATAV_create, OSSL_CMP_ATAV_set0, OSSL_CMP_ATAV_get0_type, OSSL_CMP_ATAV_get0_value, OSSL_CMP_ATAV_new_algId, OSSL_CMP_ATAV_get0_algId, OSSL_CMP_ATAV_new_rsaKeyLen, OSSL_CMP_ATAV_get_rsaKeyLen, OSSL_CMP_ATAVS, OSSL_CMP_ATAV_push1, OSSL_CMP_ATAV_free - OSSL_CMP_ATAV utility functions

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-typedef OSSL_CRMF_ATTRIBUTETYPEANDVALUE OSSL_CMP_ATAV;
-OSSL_CMP_ATAV *OSSL_CMP_ATAV_create(ASN1_OBJECT *type, ASN1_TYPE *value);
-void OSSL_CMP_ATAV_set0(OSSL_CMP_ATAV *atav, ASN1_OBJECT *type,
-                        ASN1_TYPE *value);
-ASN1_OBJECT *OSSL_CMP_ATAV_get0_type(const OSSL_CMP_ATAV *atav);
-ASN1_TYPE *OSSL_CMP_ATAV_get0_value(const OSSL_CMP_ATAV *atav);
-
-OSSL_CMP_ATAV *OSSL_CMP_ATAV_new_algId(const X509_ALGOR *alg);
-X509_ALGOR *OSSL_CMP_ATAV_get0_algId(const OSSL_CMP_ATAV *atav);
-OSSL_CMP_ATAV *OSSL_CMP_ATAV_new_rsaKeyLen(int len);
-int OSSL_CMP_ATAV_get_rsaKeyLen(const OSSL_CMP_ATAV *atav);
-
-typedef STACK_OF(OSSL_CRMF_ATTRIBUTETYPEANDVALUE) OSSL_CMP_ATAVS;
-int OSSL_CMP_ATAV_push1(OSSL_CMP_ATAVS **sk_p, const OSSL_CMP_ATAV *atav);
-void OSSL_CMP_ATAV_free(OSSL_CMP_ATAV *atav);
- -

DESCRIPTION

- -

OSSL_CMP_ATAV is a short hand of OSSL_CRMF_ATTRIBUTETYPEANDVALUE, defined in RFC 4211 Appendix B. It is typically used in CertRequest structures, but also in CertReqTemplateContent structures for key specifications.

- -

OSSL_CMP_ATAV_create() creates a new OSSL_CMP_ATAV structure and fills it in. It combines OSSL_CMP_ATAV_new() and OSSL_CMP_ATAV_set0().

- -

OSSL_CMP_ATAV_set0() sets the atav with an infoType of type and an infoValue of value. The pointers type and value may be NULL, otherwise they must not be freed up after the call because their ownership is transferred to atav. The itav pointer must not be NULL.

- -

OSSL_CMP_ATAV_get0_type() returns a direct pointer to the infoType in the atav unless it is NULL.

- -

OSSL_CMP_ATAV_get0_value() returns a direct pointer to the infoValue in the atav as generic ASN1_TYPE pointer unless atav is NULL.

- -

OSSL_CMP_ATAV_new_algId() creates a new OSSL_CMP_ATAV structure of type algId and fills it in with a copy of the given alg.

- -

OSSL_CMP_ATAV_get0_algId() returns a direct pointer to the algId infoValue in the atav of type X509_ALGOR or NULL if atav is NULL or does not contain an algId.

- -

OSSL_CMP_ATAV_new_rsaKeyLen() creates a new OSSL_CMP_ATAV structure of type rsaKeyLen and fills it in with the given len, which must be positive.

- -

OSSL_CMP_ATAV_get_rsaKeyLen() returns the RSA key length in rsaKeyLen infoValue in the atav, -1 if atav is NULL or does not contain an rsaKeyLen or cannot be parsed, or -2 if the value is less than 1 or is greater than INT_MAX.

- -

OSSL_CMP_ATAV_push1() pushes a copy of atav to the stack of OSSL_CMP_ATAV pointed to by *sk_p. It creates a new stack if *sk_p points to NULL.

- -

OSSL_CMP_ATAV_free() deallocates atav. It is defined as a macro.

- -

NOTES

- -

CMP is defined in RFC 4210. CRMF is defined in RFC 4211.

- -

RETURN VALUES

- -

OSSL_CMP_ATAV_create(), OSSL_CMP_ATAV_new_algId(), and OSSL_CMP_ATAV_new_rsaKeyLen() return a pointer to the ATAV structure on success, or NULL on error.

- -

OSSL_CMP_ATAV_set0() and OSSL_CMP_ATAV_free() do not return a value.

- -

OSSL_CMP_ATAV_get0_type(), OSSL_CMP_ATAV_get0_value(), and OSSL_CMP_ATAV_get0_algId() return the respective pointer or NULL if their input is NULL.

- -

OSSL_CMP_ATAV_get_rsaKeyLen() return a key length in bits or < 0 on error.

- -

OSSL_CMP_ATAV_push1() returns 1 on success, 0 on error.

- -

SEE ALSO

- -

OSSL_CMP_ITAV_new0_certReqTemplate(3), ASN1_TYPE_set(3)

- -

HISTORY

- -

The OSSL_CMP_ATAV type and related functions were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_CTX_new.html deleted file mode 100644 index ae22eea0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_CTX_new.html +++ /dev/null @@ -1,599 +0,0 @@ - - - - -OSSL_CMP_CTX_new - - - - - - - - - - -

NAME

- -

OSSL_CMP_CTX_new, OSSL_CMP_CTX_free, OSSL_CMP_CTX_reinit, OSSL_CMP_CTX_get0_libctx, OSSL_CMP_CTX_get0_propq, OSSL_CMP_CTX_set_option, OSSL_CMP_CTX_get_option, OSSL_CMP_CTX_set_log_cb, OSSL_CMP_CTX_set_log_verbosity, OSSL_CMP_CTX_print_errors, OSSL_CMP_CTX_set1_serverPath, OSSL_CMP_CTX_set1_server, OSSL_CMP_CTX_set_serverPort, OSSL_CMP_CTX_set1_proxy, OSSL_CMP_CTX_set1_no_proxy, OSSL_CMP_CTX_set_http_cb, OSSL_CMP_CTX_set_http_cb_arg, OSSL_CMP_CTX_get_http_cb_arg, OSSL_CMP_transfer_cb_t, OSSL_CMP_CTX_set_transfer_cb, OSSL_CMP_CTX_set_transfer_cb_arg, OSSL_CMP_CTX_get_transfer_cb_arg, OSSL_CMP_CTX_set1_srvCert, OSSL_CMP_CTX_set1_expected_sender, OSSL_CMP_CTX_set0_trusted, OSSL_CMP_CTX_set0_trustedStore, OSSL_CMP_CTX_get0_trusted, OSSL_CMP_CTX_get0_trustedStore, OSSL_CMP_CTX_set1_untrusted, OSSL_CMP_CTX_get0_untrusted, OSSL_CMP_CTX_set1_cert, OSSL_CMP_CTX_build_cert_chain, OSSL_CMP_CTX_set1_pkey, OSSL_CMP_CTX_set1_referenceValue, OSSL_CMP_CTX_set1_secretValue, OSSL_CMP_CTX_set1_recipient, OSSL_CMP_CTX_push0_geninfo_ITAV, OSSL_CMP_CTX_reset_geninfo_ITAVs, OSSL_CMP_CTX_get0_geninfo_ITAVs, OSSL_CMP_CTX_set1_extraCertsOut, OSSL_CMP_CTX_set0_newPkey, OSSL_CMP_CTX_get0_newPkey, OSSL_CMP_CTX_set1_issuer, OSSL_CMP_CTX_set1_serialNumber, OSSL_CMP_CTX_set1_subjectName, OSSL_CMP_CTX_push1_subjectAltName, OSSL_CMP_CTX_set0_reqExtensions, OSSL_CMP_CTX_reqExtensions_have_SAN, OSSL_CMP_CTX_push0_policy, OSSL_CMP_CTX_set1_oldCert, OSSL_CMP_CTX_set1_p10CSR, OSSL_CMP_CTX_push0_genm_ITAV, OSSL_CMP_certConf_cb_t, OSSL_CMP_certConf_cb, OSSL_CMP_CTX_set_certConf_cb, OSSL_CMP_CTX_set_certConf_cb_arg, OSSL_CMP_CTX_get_certConf_cb_arg, OSSL_CMP_CTX_get_status, OSSL_CMP_CTX_get0_statusString, OSSL_CMP_CTX_get_failInfoCode, OSSL_CMP_CTX_get0_validatedSrvCert, OSSL_CMP_CTX_get0_newCert, OSSL_CMP_CTX_get1_newChain, OSSL_CMP_CTX_get1_caPubs, OSSL_CMP_CTX_get1_extraCertsIn, OSSL_CMP_CTX_set1_transactionID, OSSL_CMP_CTX_set1_senderNonce - functions for managing the CMP client context data structure

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-OSSL_CMP_CTX *OSSL_CMP_CTX_new(OSSL_LIB_CTX *libctx, const char *propq);
-void OSSL_CMP_CTX_free(OSSL_CMP_CTX *ctx);
-int OSSL_CMP_CTX_reinit(OSSL_CMP_CTX *ctx);
-OSSL_LIB_CTX *OSSL_CMP_CTX_get0_libctx(const OSSL_CMP_CTX *ctx);
-const char *OSSL_CMP_CTX_get0_propq(const OSSL_CMP_CTX *ctx);
-int OSSL_CMP_CTX_set_option(OSSL_CMP_CTX *ctx, int opt, int val);
-int OSSL_CMP_CTX_get_option(const OSSL_CMP_CTX *ctx, int opt);
-
-/* logging and error reporting: */
-int OSSL_CMP_CTX_set_log_cb(OSSL_CMP_CTX *ctx, OSSL_CMP_log_cb_t cb);
-#define OSSL_CMP_CTX_set_log_verbosity(ctx, level)
-void OSSL_CMP_CTX_print_errors(const OSSL_CMP_CTX *ctx);
-
-/* message transfer: */
-int OSSL_CMP_CTX_set1_serverPath(OSSL_CMP_CTX *ctx, const char *path);
-int OSSL_CMP_CTX_set1_server(OSSL_CMP_CTX *ctx, const char *address);
-int OSSL_CMP_CTX_set_serverPort(OSSL_CMP_CTX *ctx, int port);
-int OSSL_CMP_CTX_set1_proxy(OSSL_CMP_CTX *ctx, const char *name);
-int OSSL_CMP_CTX_set1_no_proxy(OSSL_CMP_CTX *ctx, const char *names);
-int OSSL_CMP_CTX_set_http_cb(OSSL_CMP_CTX *ctx, HTTP_bio_cb_t cb);
-int OSSL_CMP_CTX_set_http_cb_arg(OSSL_CMP_CTX *ctx, void *arg);
-void *OSSL_CMP_CTX_get_http_cb_arg(const OSSL_CMP_CTX *ctx);
-typedef OSSL_CMP_MSG *(*OSSL_CMP_transfer_cb_t)(OSSL_CMP_CTX *ctx,
-                                                const OSSL_CMP_MSG *req);
-int OSSL_CMP_CTX_set_transfer_cb(OSSL_CMP_CTX *ctx,
-                                 OSSL_CMP_transfer_cb_t cb);
-int OSSL_CMP_CTX_set_transfer_cb_arg(OSSL_CMP_CTX *ctx, void *arg);
-void *OSSL_CMP_CTX_get_transfer_cb_arg(const OSSL_CMP_CTX *ctx);
-
-/* server authentication: */
-int OSSL_CMP_CTX_set1_srvCert(OSSL_CMP_CTX *ctx, X509 *cert);
-int OSSL_CMP_CTX_set1_expected_sender(OSSL_CMP_CTX *ctx,
-                                     const X509_NAME *name);
-#define OSSL_CMP_CTX_set0_trusted OSSL_CMP_CTX_set0_trustedStore
-int OSSL_CMP_CTX_set0_trustedStore(OSSL_CMP_CTX *ctx, X509_STORE *store);
-#define OSSL_CMP_CTX_get0_trusted OSSL_CMP_CTX_get0_trustedStore
-X509_STORE *OSSL_CMP_CTX_get0_trustedStore(const OSSL_CMP_CTX *ctx);
-int OSSL_CMP_CTX_set1_untrusted(OSSL_CMP_CTX *ctx, STACK_OF(X509) *certs);
-STACK_OF(X509) *OSSL_CMP_CTX_get0_untrusted(const OSSL_CMP_CTX *ctx);
-
-/* client authentication: */
-int OSSL_CMP_CTX_set1_cert(OSSL_CMP_CTX *ctx, X509 *cert);
-int OSSL_CMP_CTX_build_cert_chain(OSSL_CMP_CTX *ctx, X509_STORE *own_trusted,
-                                  STACK_OF(X509) *candidates);
-int OSSL_CMP_CTX_set1_pkey(OSSL_CMP_CTX *ctx, EVP_PKEY *pkey);
-int OSSL_CMP_CTX_set1_referenceValue(OSSL_CMP_CTX *ctx,
-                                     const unsigned char *ref, int len);
-int OSSL_CMP_CTX_set1_secretValue(OSSL_CMP_CTX *ctx,
-                                  const unsigned char *sec, int len);
-
-/* CMP message header and extra certificates: */
-int OSSL_CMP_CTX_set1_recipient(OSSL_CMP_CTX *ctx, const X509_NAME *name);
-int OSSL_CMP_CTX_push0_geninfo_ITAV(OSSL_CMP_CTX *ctx, OSSL_CMP_ITAV *itav);
-int OSSL_CMP_CTX_reset_geninfo_ITAVs(OSSL_CMP_CTX *ctx);
-STACK_OF(OSSL_CMP_ITAV)
-    *OSSL_CMP_CTX_get0_geninfo_ITAVs(const OSSL_CMP_CTX *ctx);
-int OSSL_CMP_CTX_set1_extraCertsOut(OSSL_CMP_CTX *ctx,
-                                    STACK_OF(X509) *extraCertsOut);
-
-/* certificate template: */
-int OSSL_CMP_CTX_set0_newPkey(OSSL_CMP_CTX *ctx, int priv, EVP_PKEY *pkey);
-EVP_PKEY *OSSL_CMP_CTX_get0_newPkey(const OSSL_CMP_CTX *ctx, int priv);
-int OSSL_CMP_CTX_set1_issuer(OSSL_CMP_CTX *ctx, const X509_NAME *name);
-int OSSL_CMP_CTX_set1_serialNumber(OSSL_CMP_CTX *ctx, const ASN1_INTEGER *sn);
-int OSSL_CMP_CTX_set1_subjectName(OSSL_CMP_CTX *ctx, const X509_NAME *name);
-int OSSL_CMP_CTX_push1_subjectAltName(OSSL_CMP_CTX *ctx,
-                                      const GENERAL_NAME *name);
-int OSSL_CMP_CTX_set0_reqExtensions(OSSL_CMP_CTX *ctx, X509_EXTENSIONS *exts);
-int OSSL_CMP_CTX_reqExtensions_have_SAN(OSSL_CMP_CTX *ctx);
-int OSSL_CMP_CTX_push0_policy(OSSL_CMP_CTX *ctx, POLICYINFO *pinfo);
-int OSSL_CMP_CTX_set1_oldCert(OSSL_CMP_CTX *ctx, X509 *cert);
-int OSSL_CMP_CTX_set1_p10CSR(OSSL_CMP_CTX *ctx, const X509_REQ *csr);
-
-/* misc body contents: */
-int OSSL_CMP_CTX_push0_genm_ITAV(OSSL_CMP_CTX *ctx, OSSL_CMP_ITAV *itav);
-
-/* certificate confirmation: */
-typedef int (*OSSL_CMP_certConf_cb_t)(OSSL_CMP_CTX *ctx, X509 *cert,
-                                      int fail_info, const char **txt);
-int OSSL_CMP_certConf_cb(OSSL_CMP_CTX *ctx, X509 *cert, int fail_info,
-                         const char **text);
-int OSSL_CMP_CTX_set_certConf_cb(OSSL_CMP_CTX *ctx, OSSL_CMP_certConf_cb_t cb);
-int OSSL_CMP_CTX_set_certConf_cb_arg(OSSL_CMP_CTX *ctx, void *arg);
-void *OSSL_CMP_CTX_get_certConf_cb_arg(const OSSL_CMP_CTX *ctx);
-
-/* result fetching: */
-int OSSL_CMP_CTX_get_status(const OSSL_CMP_CTX *ctx);
-OSSL_CMP_PKIFREETEXT *OSSL_CMP_CTX_get0_statusString(const OSSL_CMP_CTX *ctx);
-int OSSL_CMP_CTX_get_failInfoCode(const OSSL_CMP_CTX *ctx);
-
-X509 *OSSL_CMP_CTX_get0_validatedSrvCert(const OSSL_CMP_CTX *ctx);
-X509 *OSSL_CMP_CTX_get0_newCert(const OSSL_CMP_CTX *ctx);
-STACK_OF(X509) *OSSL_CMP_CTX_get1_newChain(const OSSL_CMP_CTX *ctx);
-STACK_OF(X509) *OSSL_CMP_CTX_get1_caPubs(const OSSL_CMP_CTX *ctx);
-STACK_OF(X509) *OSSL_CMP_CTX_get1_extraCertsIn(const OSSL_CMP_CTX *ctx);
-
-/* for testing and debugging purposes: */
-int OSSL_CMP_CTX_set1_transactionID(OSSL_CMP_CTX *ctx,
-                                    const ASN1_OCTET_STRING *id);
-int OSSL_CMP_CTX_set1_senderNonce(OSSL_CMP_CTX *ctx,
-                                  const ASN1_OCTET_STRING *nonce);
- -

DESCRIPTION

- -

This is the context API for using CMP (Certificate Management Protocol) with OpenSSL.

- -

OSSL_CMP_CTX_new() allocates an OSSL_CMP_CTX structure associated with the library context libctx and property query string propq, both of which may be NULL to select the defaults. It initializes the remaining fields to their default values - for instance, the logging verbosity is set to OSSL_CMP_LOG_INFO, the message timeout is set to 120 seconds, and the proof-of-possession method is set to OSSL_CRMF_POPO_SIGNATURE.

- -

OSSL_CMP_CTX_free() deallocates an OSSL_CMP_CTX structure. If the argument is NULL, nothing is done.

- -

OSSL_CMP_CTX_reinit() prepares the given ctx for a further transaction by clearing the internal CMP transaction (aka session) status, PKIStatusInfo, and any previous results (newCert, newChain, caPubs, and extraCertsIn) from the last executed transaction. It also clears any ITAVs that were added by OSSL_CMP_CTX_push0_genm_ITAV(). All other field values (i.e., CMP options) are retained for potential reuse.

- -

OSSL_CMP_CTX_get0_libctx() returns the libctx argument that was used when constructing ctx with OSSL_CMP_CTX_new(), which may be NULL.

- -

OSSL_CMP_CTX_get0_propq() returns the propq argument that was used when constructing ctx with OSSL_CMP_CTX_new(), which may be NULL.

- -

OSSL_CMP_CTX_set_option() sets the given value for the given option (e.g., OSSL_CMP_OPT_IMPLICIT_CONFIRM) in the given OSSL_CMP_CTX structure.

- -

The following options can be set:

- -
- -
OSSL_CMP_OPT_LOG_VERBOSITY
-
- -
The level of severity needed for actually outputting log messages
-due to errors, warnings, general info, debugging, etc.
-Default is OSSL_CMP_LOG_INFO. See also L<OSSL_CMP_log_open(3)>.
- -
-
OSSL_CMP_OPT_KEEP_ALIVE
-
- -
If the given value is 0 then HTTP connections are not kept open
-after receiving a response, which is the default behavior for HTTP 1.0.
-If the value is 1 or 2 then persistent connections are requested.
-If the value is 2 then persistent connections are required,
-i.e., in case the server does not grant them an error occurs.
-The default value is 1: prefer to keep the connection open.
- -
-
OSSL_CMP_OPT_MSG_TIMEOUT
-
- -
Number of seconds a CMP request-response message round trip
-is allowed to take before a timeout error is returned.
-A value <= 0 means no limitation (waiting indefinitely).
-Default is to use the B<OSSL_CMP_OPT_TOTAL_TIMEOUT> setting.
- -
-
OSSL_CMP_OPT_TOTAL_TIMEOUT
-
- -
Maximum total number of seconds a transaction may take,
-including polling etc.
-A value <= 0 means no limitation (waiting indefinitely).
-Default is 0.
- -
-
OSSL_CMP_OPT_USE_TLS
-
- -
Use this option to indicate to the HTTP implementation
-whether TLS is going to be used for the connection (resulting in HTTPS).
-The value 1 indicates that TLS is used for client-side HTTP connections,
-which needs to be implemented via a callback function set by
-OSSL_CMP_CTX_set_http_cb().
-The value 0 indicates that TLS is not used.
-Default is -1 for backward compatibility: TLS is used by the client side
-if and only if OSSL_CMP_CTX_set_http_cb_arg() sets a non-NULL I<arg>.
- -
-
OSSL_CMP_OPT_VALIDITY_DAYS
-
- -
Number of days new certificates are asked to be valid for.
- -
-
OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT
-
- -
Do not take default Subject Alternative Names
-from the reference certificate.
- -
-
OSSL_CMP_OPT_SUBJECTALTNAME_CRITICAL
-
- -
Demand that the given Subject Alternative Names are flagged as critical.
- -
-
OSSL_CMP_OPT_POLICIES_CRITICAL
-
- -
Demand that the given policies are flagged as critical.
- -
-
OSSL_CMP_OPT_POPO_METHOD
-
- -
Select the proof of possession method to use. Possible values are:
-
-    OSSL_CRMF_POPO_NONE       - ProofOfPossession field omitted
-    OSSL_CRMF_POPO_RAVERIFIED - assert that the RA has already
-                                verified the PoPo
-    OSSL_CRMF_POPO_SIGNATURE  - sign a value with private key,
-                                which is the default.
-    OSSL_CRMF_POPO_KEYENC     - decrypt the encrypted certificate
-                                ("indirect method")
-
-Note that a signature-based POPO can only be produced if a private key
-is provided as the newPkey or client's pkey component of the CMP context.
- -
-
OSSL_CMP_OPT_DIGEST_ALGNID
-
- -
The NID of the digest algorithm to be used in RFC 4210's MSG_SIG_ALG
-for signature-based message protection and Proof-of-Possession (POPO).
-Default is SHA256.
- -
-
OSSL_CMP_OPT_OWF_ALGNID The NID of the digest algorithm to be used as one-way function (OWF) for MAC-based message protection with password-based MAC (PBM). See RFC 4210 section 5.1.3.1 for details. Default is SHA256.
-
- -
-
OSSL_CMP_OPT_MAC_ALGNID The NID of the MAC algorithm to be used for message protection with PBM. Default is HMAC-SHA1 as per RFC 4210.
-
- -
-
OSSL_CMP_OPT_REVOCATION_REASON
-
- -
The reason code to be included in a Revocation Request (RR);
-values: 0..10 (RFC 5210, 5.3.1) or -1 for none, which is the default.
- -
-
OSSL_CMP_OPT_IMPLICIT_CONFIRM
-
- -
Request server to enable implicit confirm mode, where the client
-does not need to send confirmation upon receiving the
-certificate. If the server does not enable implicit confirmation
-in the return message, then confirmation is sent anyway.
- -
-
OSSL_CMP_OPT_DISABLE_CONFIRM
-
- -
        Do not confirm enrolled certificates, to cope with broken servers
-        not supporting implicit confirmation correctly.
-B<WARNING:> This setting leads to unspecified behavior and it is meant
-exclusively to allow interoperability with server implementations violating
-RFC 4210.
- -
-
OSSL_CMP_OPT_UNPROTECTED_SEND
-
- -
Send request or response messages without CMP-level protection.
- -
-
OSSL_CMP_OPT_UNPROTECTED_ERRORS
-
- -
        Accept unprotected error responses which are either explicitly
-        unprotected or where protection verification failed. Applies to regular
-        error messages as well as certificate responses (IP/CP/KUP) and
-        revocation responses (RP) with rejection.
-B<WARNING:> This setting leads to unspecified behavior and it is meant
-exclusively to allow interoperability with server implementations violating
-RFC 4210.
- -
-
OSSL_CMP_OPT_IGNORE_KEYUSAGE
-
- -
Ignore key usage restrictions in the signer's certificate when
-validating signature-based protection in received CMP messages.
-Else, 'digitalSignature' must be allowed by CMP signer certificates.
- -
-
OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR
-
- -
Allow retrieving a trust anchor from extraCerts and using that
-to validate the certificate chain of an IP message.
-This is a quirk option added to support 3GPP TS 33.310.
-
-Note that using this option is dangerous as the certificate obtained
-this way has not been authenticated (at least not at CMP level).
-Taking it over as a trust anchor implements trust-on-first-use (TOFU).
- -
-
OSSL_CMP_OPT_NO_CACHE_EXTRACERTS
-
- -
Do not cache certificates received in the extraCerts CMP message field.
-Otherwise they are stored to potentially help validate further messages.
- -
-
- -

OSSL_CMP_CTX_get_option() reads the current value of the given option (e.g., OSSL_CMP_OPT_IMPLICIT_CONFIRM) from the given OSSL_CMP_CTX structure.

- -

OSSL_CMP_CTX_set_log_cb() sets in ctx the callback function cb for handling error queue entries and logging messages. When cb is NULL errors are printed to STDERR (if available, else ignored) any log messages are ignored. Alternatively, OSSL_CMP_log_open(3) may be used to direct logging to STDOUT.

- -

OSSL_CMP_CTX_set_log_verbosity() is a macro setting the OSSL_CMP_OPT_LOG_VERBOSITY context option to the given level.

- -

OSSL_CMP_CTX_print_errors() outputs any entries in the OpenSSL error queue. It is similar to ERR_print_errors_cb(3) but uses the CMP log callback function if set in the ctx for uniformity with CMP logging if given. Otherwise it uses ERR_print_errors(3) to print to STDERR (unless OPENSSL_NO_STDIO is defined).

- -

OSSL_CMP_CTX_set1_serverPath() sets the HTTP path of the CMP server on the host, also known as "CMP alias". The default is /.

- -

OSSL_CMP_CTX_set1_server() sets the given server address (which may be a hostname or IP address or NULL) in the given ctx.

- -

OSSL_CMP_CTX_set_serverPort() sets the port of the CMP server to connect to. If not used or the port argument is 0 the default port applies, which is 80 for HTTP and 443 for HTTPS.

- -

OSSL_CMP_CTX_set1_proxy() sets the HTTP proxy to be used for connecting to the given CMP server unless overruled by any "no_proxy" settings (see below). If TLS is not used this defaults to the value of the environment variable http_proxy if set, else HTTP_PROXY. Otherwise defaults to the value of https_proxy if set, else HTTPS_PROXY. An empty proxy string specifies not to use a proxy. Otherwise the format is [http[s]://][userinfo@]host[:port][/path][?query][#fragment], where any given userinfo, path, query, and fragment is ignored. If the host string is an IPv6 address, it must be enclosed in [ and ]. The default port number is 80, or 443 in case https: is given.

- -

OSSL_CMP_CTX_set1_no_proxy() sets the list of server hostnames not to use an HTTP proxy for. The names may be separated by commas and/or whitespace. Defaults to the environment variable no_proxy if set, else NO_PROXY.

- -

OSSL_CMP_CTX_set_http_cb() sets the optional BIO connect/disconnect callback function, which has the prototype

- -
typedef BIO *(*HTTP_bio_cb_t) (BIO *bio, void *arg, int connect, int detail);
- -

The callback may modify the bio provided by OSSL_CMP_MSG_http_perform(3) as described for the bio_update_fn parameter of OSSL_HTTP_open(3). The callback may make use of a custom defined argument arg, as described for the arg parameter of OSSL_HTTP_open(3). The argument is stored in the OSSL_CMP_CTX using OSSL_CMP_CTX_set_http_cb_arg(). See also the OSSL_CMP_OPT_USE_TLS option described above.

- -

OSSL_CMP_CTX_set_http_cb_arg() sets the argument, respectively a pointer to a structure containing arguments such as an SSL_CTX structure, optionally to be used by the http connect/disconnect callback function. arg is not consumed, and it must therefore explicitly be freed when not needed any more. arg may be NULL to clear the entry.

- -

OSSL_CMP_CTX_get_http_cb_arg() gets the argument, respectively the pointer to a structure containing arguments, previously set by OSSL_CMP_CTX_set_http_cb_arg() or NULL if unset.

- -

OSSL_CMP_CTX_set_transfer_cb() sets the message transfer callback function, which has the type

- -
typedef OSSL_CMP_MSG *(*OSSL_CMP_transfer_cb_t) (OSSL_CMP_CTX *ctx,
-                                                 const OSSL_CMP_MSG *req);
- -

Default is NULL, which implies the use of OSSL_CMP_MSG_http_perform(3). The callback should send the CMP request message it obtains via the req parameter and on success return the response, else it must return NULL. The transfer callback may make use of a custom defined argument stored in the ctx by means of OSSL_CMP_CTX_set_transfer_cb_arg(), which may be retrieved again through OSSL_CMP_CTX_get_transfer_cb_arg().

- -

OSSL_CMP_CTX_set_transfer_cb_arg() sets an argument, respectively a pointer to a structure containing arguments, optionally to be used by the transfer callback. arg is not consumed, and it must therefore explicitly be freed when not needed any more. arg may be NULL to clear the entry.

- -

OSSL_CMP_CTX_get_transfer_cb_arg() gets the argument, respectively the pointer to a structure containing arguments, previously set by OSSL_CMP_CTX_set_transfer_cb_arg() or NULL if unset.

- -

OSSL_CMP_CTX_set1_srvCert() sets the expected server cert in ctx and trusts it directly (even if it is expired) when verifying signed response messages. This pins the accepted CMP server and results in ignoring whatever may be set using OSSL_CMP_CTX_set0_trusted(). Any previously set value is freed. The cert argument may be NULL to clear the entry. If set, the subject of the certificate is also used as default value for the recipient of CMP requests and as default value for the expected sender of CMP responses.

- -

OSSL_CMP_CTX_set1_expected_sender() sets the Distinguished Name (DN) expected in the sender field of incoming CMP messages. Defaults to the subject of the pinned server certificate, if any. This can be used to make sure that only a particular entity is accepted as CMP message signer, and attackers are not able to use arbitrary certificates of a trusted PKI hierarchy to fraudulently pose as CMP server. Note that this gives slightly more freedom than OSSL_CMP_CTX_set1_srvCert(), which pins the server to the holder of a particular certificate, while the expected sender name will continue to match after updates of the server cert.

- -

OSSL_CMP_CTX_set0_trusted() is an alias of the original OSSL_CMP_CTX_set0_trustedStore(). It sets in the CMP context ctx the certificate store of type X509_STORE containing trusted certificates, typically of root CAs. This is ignored when a certificate is pinned using OSSL_CMP_CTX_set1_srvCert(). The store may also hold CRLs and a certificate verification callback function used for signature-based peer authentication. Any store entry already set before is freed. When given a NULL parameter the entry is cleared.

- -

OSSL_CMP_CTX_get0_trusted() is an alias of the original OSSL_CMP_CTX_get0_trustedStore(). It extracts from the CMP context ctx the pointer to the currently set certificate store containing trust anchors etc., or an empty store if unset.

- -

OSSL_CMP_CTX_set1_untrusted() sets up a list of non-trusted certificates of intermediate CAs that may be useful for path construction for the own CMP signer certificate, for the own TLS certificate (if any), when verifying peer CMP protection certificates, and when verifying newly enrolled certificates. The reference counts of those certificates handled successfully are increased. This list of untrusted certificates in ctx will get augmented by extraCerts in received CMP messages unless OSSL_CMP_OPT_NO_CACHE_EXTRACERTS is set.

- -

OSSL_CMP_CTX_get0_untrusted() returns a pointer to the list of untrusted certs in ctx, which may be empty if unset.

- -

OSSL_CMP_CTX_set1_cert() sets the CMP signer certificate, also called protection certificate, related to the private key used for signature-based CMP message protection. Therefore the public key of this cert must correspond to the private key set before or thereafter via OSSL_CMP_CTX_set1_pkey(). When using signature-based protection of CMP request messages this CMP signer certificate will be included first in the extraCerts field. It serves as fallback reference certificate, see OSSL_CMP_CTX_set1_oldCert(). The subject of this cert will be used as the sender field of outgoing messages, while the subject of any cert set via OSSL_CMP_CTX_set1_oldCert(), the subject of any PKCS#10 CSR set via OSSL_CMP_CTX_set1_p10CSR(), and any value set via OSSL_CMP_CTX_set1_subjectName() are used as fallback.

- -

The cert argument may be NULL to clear the entry.

- -

OSSL_CMP_CTX_build_cert_chain() builds a certificate chain for the CMP signer certificate previously set in the ctx. It adds the optional candidates, a list of intermediate CA certs that may already constitute the targeted chain, to the untrusted certs that may already exist in the ctx. Then the function uses this augmented set of certs for chain construction. If own_trusted is NULL it builds the chain as far down as possible and ignores any verification errors. Else the CMP signer certificate must be verifiable where the chain reaches a trust anchor contained in own_trusted. On success the function stores the resulting chain in ctx for inclusion in the extraCerts field of signature-protected messages. Calling this function is optional; by default a chain construction is performed on demand that is equivalent to calling this function with the candidates and own_trusted arguments being NULL.

- -

OSSL_CMP_CTX_set1_pkey() sets the client's private key corresponding to the CMP signer certificate set via OSSL_CMP_CTX_set1_cert(). This key is used create signature-based protection (protectionAlg = MSG_SIG_ALG) of outgoing messages unless a symmetric secret has been set via OSSL_CMP_CTX_set1_secretValue(). The pkey argument may be NULL to clear the entry.

- -

OSSL_CMP_CTX_set1_secretValue() sets in ctx the byte string sec of length len to use as pre-shared secret, or clears it if the sec argument is NULL. If present, this secret is used to create MAC-based authentication and integrity protection (rather than applying signature-based protection) of outgoing messages and to verify authenticity and integrity of incoming messages that have MAC-based protection (protectionAlg = MSG_MAC_ALG).

- -

OSSL_CMP_CTX_set1_referenceValue() sets the given referenceValue ref with length len in the given ctx or clears it if the ref argument is NULL. According to RFC 4210 section 5.1.1, if no value for the sender field in CMP message headers can be determined (i.e., no CMP signer certificate and no subject DN is set via OSSL_CMP_CTX_set1_subjectName() then the sender field will contain the NULL-DN and the senderKID field of the CMP message header must be set. When signature-based protection is used the senderKID will be set to the subjectKeyIdentifier of the CMP signer certificate as far as present. If not present or when MAC-based protection is used the ref value is taken as the fallback value for the senderKID.

- -

OSSL_CMP_CTX_set1_recipient() sets the recipient name that will be used in the PKIHeader of CMP request messages, i.e. the X509 name of the (CA) server.

- -

The recipient field in the header of a CMP message is mandatory. If not given explicitly the recipient is determined in the following order: the subject of the CMP server certificate set using OSSL_CMP_CTX_set1_srvCert(), the value set using OSSL_CMP_CTX_set1_issuer(), the issuer of the certificate set using OSSL_CMP_CTX_set1_oldCert(), the issuer of the CMP signer certificate, as far as any of those is present, else the NULL-DN as last resort.

- -

OSSL_CMP_CTX_push0_geninfo_ITAV() adds itav to the stack in the ctx to be added to the generalInfo field of the CMP PKIMessage header of a request message sent with this context.

- -

OSSL_CMP_CTX_reset_geninfo_ITAVs() clears any ITAVs that were added by OSSL_CMP_CTX_push0_geninfo_ITAV().

- -

OSSL_CMP_CTX_get0_geninfo_ITAVs() returns the list of ITAVs set in ctx for inclusion in the generalInfo field of the CMP PKIMessage header of requests or NULL if not set.

- -

OSSL_CMP_CTX_set1_extraCertsOut() sets the stack of extraCerts that will be sent to remote.

- -

OSSL_CMP_CTX_set0_newPkey() can be used to explicitly set the given EVP_PKEY structure as the private or public key to be certified in the CMP context. The priv parameter must be 0 if and only if the given key is a public key.

- -

OSSL_CMP_CTX_get0_newPkey() gives the key to use for certificate enrollment dependent on fields of the CMP context structure: the newPkey (which may be a private or public key) if present, else the public key in the p10CSR if present, else the client's private key. If the priv parameter is not 0 and the selected key does not have a private component then NULL is returned.

- -

OSSL_CMP_CTX_set1_issuer() sets the name of the intended issuer that will be set in the CertTemplate, i.e., the X509 name of the CA server.

- -

OSSL_CMP_CTX_set1_serialNumber() sets the serial number optionally used to select the certificate to be revoked in Revocation Requests (RR).

- -

OSSL_CMP_CTX_set1_subjectName() sets the subject DN that will be used in the CertTemplate structure when requesting a new cert. For Key Update Requests (KUR), it defaults to the subject DN of the reference certificate, see OSSL_CMP_CTX_set1_oldCert(). This default is used for Initialization Requests (IR) and Certification Requests (CR) only if no SANs are set. The subjectName is also used as fallback for the sender field of outgoing CMP messages if no reference certificate is available.

- -

OSSL_CMP_CTX_push1_subjectAltName() adds the given X509 name to the list of alternate names on the certificate template request. This cannot be used if any Subject Alternative Name extension is set via OSSL_CMP_CTX_set0_reqExtensions(). By default, unless OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT has been set, the Subject Alternative Names are copied from the reference certificate, see OSSL_CMP_CTX_set1_oldCert(). If set and the subject DN is not set with OSSL_CMP_CTX_set1_subjectName() then the certificate template of an IR and CR will not be filled with the default subject DN from the reference certificate. If a subject DN is desired it needs to be set explicitly with OSSL_CMP_CTX_set1_subjectName().

- -

OSSL_CMP_CTX_set0_reqExtensions() sets the X.509v3 extensions to be used in IR/CR/KUR.

- -

OSSL_CMP_CTX_reqExtensions_have_SAN() returns 1 if the context contains a Subject Alternative Name extension, else 0 or -1 on error.

- -

OSSL_CMP_CTX_push0_policy() adds the certificate policy info object to the X509_EXTENSIONS of the requested certificate template.

- -

OSSL_CMP_CTX_set1_oldCert() sets the old certificate to be updated in Key Update Requests (KUR) or to be revoked in Revocation Requests (RR). For RR, this is ignored if an issuer name and a serial number are provided using OSSL_CMP_CTX_set1_issuer() and OSSL_CMP_CTX_set1_serialNumber(), respectively. For IR/CR/KUR this sets the reference certificate, which otherwise defaults to the CMP signer certificate. The reference certificate determined this way, if any, is used for providing default public key, subject DN, Subject Alternative Names, and issuer DN entries in the requested certificate template of IR/CR/KUR messages.

- -

The subject of the reference certificate is used as the sender field value in CMP message headers. Its issuer is used as default recipient in CMP message headers.

- -

OSSL_CMP_CTX_set1_p10CSR() sets the PKCS#10 CSR to use in P10CR messages. If such a CSR is provided, its subject and public key fields are also used as fallback values for the certificate template of IR/CR/KUR/RR messages, and any extensions included are added to the template of IR/CR/KUR messages.

- -

OSSL_CMP_CTX_push0_genm_ITAV() adds itav to the stack in the ctx which will be the body of a General Message sent with this context.

- -

OSSL_CMP_certConf_cb() is the default certificate confirmation callback function. If the callback argument is not NULL it must point to a trust store. In this case the function checks that the newly enrolled certificate can be verified using this trust store and untrusted certificates from the ctx, which have been augmented by the list of extraCerts received. During this verification, any certificate status checking is disabled. If the callback argument is NULL the function tries building an approximate chain as far as possible using the same untrusted certificates from the ctx, and if this fails it takes the received extraCerts as fallback. The resulting cert chain can be retrieved using OSSL_CMP_CTX_get1_newChain(). This chain excludes the leaf certificate, i.e., the newly enrolled certificate. Also the trust anchor (the root certificate) is not included.

- -

OSSL_CMP_CTX_set_certConf_cb() sets the callback used for evaluating the newly enrolled certificate before the library sends, depending on its result, a positive or negative certConf message to the server. The callback has type

- -
typedef int (*OSSL_CMP_certConf_cb_t) (OSSL_CMP_CTX *ctx, X509 *cert,
-                                       int fail_info, const char **txt);
- -

and should inspect the certificate it obtains via the cert parameter and may overrule the pre-decision given in the fail_info and *txt parameters. If it accepts the certificate it must return 0, indicating success. Else it must return a bit field reflecting PKIFailureInfo with at least one failure bit and may set the *txt output parameter to point to a string constant with more detail. The transfer callback may make use of a custom defined argument stored in the ctx by means of OSSL_CMP_CTX_set_certConf_cb_arg(), which may be retrieved again through OSSL_CMP_CTX_get_certConf_cb_arg(). Typically, the callback will check at least that the certificate can be verified using a set of trusted certificates. It also could compare the subject DN and other fields of the newly enrolled certificate with the certificate template of the request.

- -

OSSL_CMP_CTX_set_certConf_cb_arg() sets an argument, respectively a pointer to a structure containing arguments, optionally to be used by the certConf callback. arg is not consumed, and it must therefore explicitly be freed when not needed any more. arg may be NULL to clear the entry.

- -

OSSL_CMP_CTX_get_certConf_cb_arg() gets the argument, respectively the pointer to a structure containing arguments, previously set by OSSL_CMP_CTX_set_certConf_cb_arg(), or NULL if unset.

- -

OSSL_CMP_CTX_get_status() returns for client contexts the PKIstatus from the last received CertRepMessage or Revocation Response or error message: =item OSSL_CMP_PKISTATUS_accepted on successful receipt of a GENP message:

- -
- -
OSSL_CMP_PKISTATUS_request
-
- -

if an IR/CR/KUR/RR/GENM request message could not be produced,

- -
-
OSSL_CMP_PKISTATUS_trans
-
- -

on a transmission error or transaction error for this type of request, and

- -
-
OSSL_CMP_PKISTATUS_unspecified
-
- -

if no such request was attempted or OSSL_CMP_CTX_reinit() has been called.

- -
-
- -

For server contexts it returns OSSL_CMP_PKISTATUS_trans if a transaction is open, otherwise OSSL_CMP_PKISTATUS_unspecified.

- -

OSSL_CMP_CTX_get0_statusString() returns the statusString from the last received CertRepMessage or Revocation Response or error message, or NULL if unset.

- -

OSSL_CMP_CTX_get_failInfoCode() returns the error code from the failInfo field of the last received CertRepMessage or Revocation Response or error message, or -1 if no such response was received or OSSL_CMP_CTX_reinit() has been called. This is a bit field and the flags for it are specified in the header file <openssl/cmp.h>. The flags start with OSSL_CMP_CTX_FAILINFO, for example: OSSL_CMP_CTX_FAILINFO_badAlg. Returns -1 if the failInfoCode field is unset.

- -

OSSL_CMP_CTX_get0_validatedSrvCert() returns the successfully validated certificate, if any, that the CMP server used in the current transaction for signature-based response message protection, or NULL if the server used MAC-based protection. The value is relevant only at the end of a successful transaction. It may be used to check the authorization of the server based on its cert.

- -

OSSL_CMP_CTX_get0_newCert() returns the pointer to the newly obtained certificate in case it is available, else NULL.

- -

OSSL_CMP_CTX_get1_newChain() returns a pointer to a duplicate of the stack of X.509 certificates computed by OSSL_CMP_certConf_cb() (if this function has been called) on the last received certificate response message IP/CP/KUP.

- -

OSSL_CMP_CTX_get1_caPubs() returns a pointer to a duplicate of the list of X.509 certificates in the caPubs field of the last received certificate response message (of type IP, CP, or KUP), or an empty stack if no caPubs have been received in the current transaction.

- -

OSSL_CMP_CTX_get1_extraCertsIn() returns a pointer to a duplicate of the list of X.509 certificates contained in the extraCerts field of the last received response message (except for pollRep and PKIConf), or an empty stack if no extraCerts have been received in the current transaction.

- -

OSSL_CMP_CTX_set1_transactionID() sets the given transaction ID in the given OSSL_CMP_CTX structure.

- -

OSSL_CMP_CTX_set1_senderNonce() stores the last sent sender nonce in the ctx. This will be used to validate the recipNonce in incoming messages.

- -

NOTES

- -

CMP is defined in RFC 4210 (and CRMF in RFC 4211).

- -

RETURN VALUES

- -

OSSL_CMP_CTX_free() and OSSL_CMP_CTX_print_errors() do not return anything.

- -

OSSL_CMP_CTX_new(), OSSL_CMP_CTX_get0_libctx(), OSSL_CMP_CTX_get0_propq(), OSSL_CMP_CTX_get_http_cb_arg(), OSSL_CMP_CTX_get_transfer_cb_arg(), OSSL_CMP_CTX_get0_trusted(), OSSL_CMP_CTX_get0_untrusted(), OSSL_CMP_CTX_get0_geninfo_ITAVs(), OSSL_CMP_CTX_get0_newPkey(), OSSL_CMP_CTX_get_certConf_cb_arg(), OSSL_CMP_CTX_get0_statusString(), OSSL_CMP_CTX_get0_validatedSrvCert(), OSSL_CMP_CTX_get0_newCert(), OSSL_CMP_CTX_get0_newChain(), OSSL_CMP_CTX_get1_caPubs(), and OSSL_CMP_CTX_get1_extraCertsIn() return the intended pointer value as described above or NULL on error.

- -

OSSL_CMP_CTX_get_option(), OSSL_CMP_CTX_reqExtensions_have_SAN(), OSSL_CMP_CTX_get_status(), and OSSL_CMP_CTX_get_failInfoCode() return the intended value as described above or -1 on error.

- -

OSSL_CMP_certConf_cb() returns fail_info if it is not equal to 0, else 0 on successful validation, or else a bit field with the OSSL_CMP_PKIFAILUREINFO_incorrectData bit set.

- -

All other functions, including OSSL_CMP_CTX_reinit() and OSSL_CMP_CTX_reset_geninfo_ITAVs(), return 1 on success, 0 on error.

- -

EXAMPLES

- -

The following code omits error handling.

- -

Set up a CMP client context for sending requests and verifying responses:

- -
cmp_ctx = OSSL_CMP_CTX_new();
-OSSL_CMP_CTX_set1_server(cmp_ctx, name_or_address);
-OSSL_CMP_CTX_set1_serverPort(cmp_ctx, port_string);
-OSSL_CMP_CTX_set1_serverPath(cmp_ctx, path_or_alias);
-OSSL_CMP_CTX_set0_trusted(cmp_ctx, ts);
- -

Set up symmetric credentials for MAC-based message protection such as PBM:

- -
OSSL_CMP_CTX_set1_referenceValue(cmp_ctx, ref, ref_len);
-OSSL_CMP_CTX_set1_secretValue(cmp_ctx, sec, sec_len);
- -

Set up the details for certificate requests:

- -
OSSL_CMP_CTX_set1_subjectName(cmp_ctx, name);
-OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, initialKey);
- -

Perform an Initialization Request transaction:

- -
initialCert = OSSL_CMP_exec_IR_ses(cmp_ctx);
- -

Reset the transaction state of the CMP context and the credentials:

- -
OSSL_CMP_CTX_reinit(cmp_ctx);
-OSSL_CMP_CTX_set1_referenceValue(cmp_ctx, NULL, 0);
-OSSL_CMP_CTX_set1_secretValue(cmp_ctx, NULL, 0);
- -

Perform a Certification Request transaction, making use of the new credentials:

- -
OSSL_CMP_CTX_set1_cert(cmp_ctx, initialCert);
-OSSL_CMP_CTX_set1_pkey(cmp_ctx, initialKey);
-OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, curentKey);
-currentCert = OSSL_CMP_exec_CR_ses(cmp_ctx);
- -

Perform a Key Update Request, signed using the cert (and key) to be updated:

- -
OSSL_CMP_CTX_reinit(cmp_ctx);
-OSSL_CMP_CTX_set1_cert(cmp_ctx, currentCert);
-OSSL_CMP_CTX_set1_pkey(cmp_ctx, currentKey);
-OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, updatedKey);
-currentCert = OSSL_CMP_exec_KUR_ses(cmp_ctx);
-currentKey = updatedKey;
- -

Perform a General Message transaction including, as an example, the id-it-signKeyPairTypes OID and prints info on the General Response contents:

- -
OSSL_CMP_CTX_reinit(cmp_ctx);
-
-ASN1_OBJECT *type = OBJ_txt2obj("1.3.6.1.5.5.7.4.2", 1);
-OSSL_CMP_ITAV *itav = OSSL_CMP_ITAV_create(type, NULL);
-OSSL_CMP_CTX_push0_genm_ITAV(cmp_ctx, itav);
-
-STACK_OF(OSSL_CMP_ITAV) *itavs;
-itavs = OSSL_CMP_exec_GENM_ses(cmp_ctx);
-print_itavs(itavs);
-sk_OSSL_CMP_ITAV_pop_free(itavs, OSSL_CMP_ITAV_free);
- -

SEE ALSO

- -

OSSL_CMP_exec_IR_ses(3), OSSL_CMP_exec_CR_ses(3), OSSL_CMP_exec_KUR_ses(3), OSSL_CMP_exec_GENM_ses(3), OSSL_CMP_exec_certreq(3), OSSL_CMP_MSG_http_perform(3), ERR_print_errors_cb(3), OSSL_HTTP_open(3)

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

OSSL_CMP_CTX_get0_trustedStore() was renamed to OSSL_CMP_CTX_get0_trusted() and OSSL_CMP_CTX_set0_trustedStore() was renamed to OSSL_CMP_CTX_set0_trusted(), using macros, while keeping the old names for backward compatibility, in OpenSSL 3.2.

- -

OSSL_CMP_CTX_reset_geninfo_ITAVs() was added in OpenSSL 3.0.8.

- -

OSSL_CMP_CTX_set1_serialNumber(), OSSL_CMP_CTX_get0_libctx(), OSSL_CMP_CTX_get0_propq(), and OSSL_CMP_CTX_get0_validatedSrvCert() were added in OpenSSL 3.2.

- -

OSSL_CMP_CTX_get0_geninfo_ITAVs() was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_HDR_get0_transactionID.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_HDR_get0_transactionID.html deleted file mode 100644 index c99412c6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_HDR_get0_transactionID.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -OSSL_CMP_HDR_get0_transactionID - - - - - - - - - - -

NAME

- -

OSSL_CMP_HDR_get0_transactionID, OSSL_CMP_HDR_get0_recipNonce, OSSL_CMP_HDR_get0_geninfo_ITAVs - functions manipulating CMP message headers

- -

SYNOPSIS

- -
 #include <openssl/cmp.h>
-
- ASN1_OCTET_STRING *OSSL_CMP_HDR_get0_transactionID(const
-                                                    OSSL_CMP_PKIHEADER *hdr);
- ASN1_OCTET_STRING *OSSL_CMP_HDR_get0_recipNonce(const
-                                                 OSSL_CMP_PKIHEADER *hdr);
-STACK_OF(OSSL_CMP_ITAV)
-    *OSSL_CMP_HDR_get0_geninfo_ITAVs(const OSSL_CMP_PKIHEADER *hdr);
- -

DESCRIPTION

- -

OSSL_CMP_HDR_get0_transactionID returns the transaction ID of the given PKIHeader.

- -

OSSL_CMP_HDR_get0_recipNonce returns the recipient nonce of the given PKIHeader.

- -

OSSL_CMP_HDR_get0_geninfo_ITAVs() returns the list of ITAVs in the generalInfo field of the given PKIHeader.

- -

NOTES

- -

CMP is defined in RFC 4210.

- -

RETURN VALUES

- -

The functions return the intended pointer value as described above or NULL if the respective entry does not exist and on error.

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

OSSL_CMP_HDR_get0_geninfo_ITAVs() was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2007-2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_new_caCerts.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_new_caCerts.html deleted file mode 100644 index 0b78051b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_new_caCerts.html +++ /dev/null @@ -1,158 +0,0 @@ - - - - -OSSL_CMP_ITAV_new_caCerts - - - - - - - - - - -

NAME

- -

OSSL_CMP_ITAV_new_caCerts, OSSL_CMP_ITAV_get0_caCerts, OSSL_CMP_ITAV_new_rootCaCert, OSSL_CMP_ITAV_get0_rootCaCert, OSSL_CMP_ITAV_new_rootCaKeyUpdate, OSSL_CMP_ITAV_get0_rootCaKeyUpdate, OSSL_CMP_CRLSTATUS_new1, OSSL_CMP_CRLSTATUS_create, OSSL_CMP_CRLSTATUS_get0, OSSL_CMP_ITAV_new0_crlStatusList, OSSL_CMP_ITAV_get0_crlStatusList, OSSL_CMP_ITAV_new_crls, OSSL_CMP_ITAV_get0_crls, OSSL_CMP_ITAV_new0_certReqTemplate, OSSL_CMP_ITAV_get1_certReqTemplate - CMP utility functions for handling specific genm and genp messages

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_caCerts(const STACK_OF(X509) *caCerts);
-int OSSL_CMP_ITAV_get0_caCerts(const OSSL_CMP_ITAV *itav, STACK_OF(X509) **out);
-
-OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_rootCaCert(const X509 *rootCaCert);
-int OSSL_CMP_ITAV_get0_rootCaCert(const OSSL_CMP_ITAV *itav, X509 **out);
-OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_rootCaKeyUpdate(const X509 *newWithNew,
-                                                 const X509 *newWithOld,
-                                                 const X509 *oldWithNew);
-int OSSL_CMP_ITAV_get0_rootCaKeyUpdate(const OSSL_CMP_ITAV *itav,
-                                       X509 **newWithNew,
-                                       X509 **newWithOld,
-                                       X509 **oldWithNew);
-
-OSSL_CMP_CRLSTATUS *OSSL_CMP_CRLSTATUS_new1(const DIST_POINT_NAME *dpn,
-                                            const GENERAL_NAMES *issuer,
-                                            const ASN1_TIME *thisUpdate);
-OSSL_CMP_CRLSTATUS *OSSL_CMP_CRLSTATUS_create(const X509_CRL *crl,
-                                              const X509 *cert, int only_DN);
-int OSSL_CMP_CRLSTATUS_get0(const OSSL_CMP_CRLSTATUS *crlstatus,
-                            DIST_POINT_NAME **dpn, GENERAL_NAMES **issuer,
-                            ASN1_TIME **thisUpdate);
-OSSL_CMP_ITAV
-*OSSL_CMP_ITAV_new0_crlStatusList(STACK_OF(OSSL_CMP_CRLSTATUS) *crlStatusList);
-int OSSL_CMP_ITAV_get0_crlStatusList(const OSSL_CMP_ITAV *itav,
-                                     STACK_OF(OSSL_CMP_CRLSTATUS) **out);
-OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_crls(const X509_CRL *crl);
-int OSSL_CMP_ITAV_get0_crls(const OSSL_CMP_ITAV *itav, STACK_OF(X509_CRL) **out);
-OSSL_CMP_ITAV
-*OSSL_CMP_ITAV_new0_certReqTemplate(OSSL_CRMF_CERTTEMPLATE *certTemplate,
-                                    OSSL_CMP_ATAVS *keySpec);
-int OSSL_CMP_ITAV_get1_certReqTemplate(const OSSL_CMP_ITAV *itav,
-                                       OSSL_CRMF_CERTTEMPLATE **certTemplate,
-                                       OSSL_CMP_ATAVS **keySpec);
- -

DESCRIPTION

- -

ITAV is short for InfoTypeAndValue.

- -

OSSL_CMP_ITAV_new_caCerts() creates an OSSL_CMP_ITAV structure of type caCerts and fills it with a copy of the provided list of certificates. The caCerts argument may be NULL or contain any number of certificates.

- -

OSSL_CMP_ITAV_get0_caCerts() requires that itav has type caCerts. It assigns NULL to *out if there are no CA certificates in itav, otherwise the internal pointer of type STACK_OF(X509) with the certificates present.

- -

OSSL_CMP_ITAV_new_rootCaCert() creates a new OSSL_CMP_ITAV structure of type rootCaCert that includes the optionally given certificate.

- -

OSSL_CMP_ITAV_get0_rootCaCert() requires that itav has type rootCaCert. It assigns NULL to *out if no certificate is included in itav, otherwise the internal pointer to the certificate contained in the infoValue field.

- -

OSSL_CMP_ITAV_new_rootCaKeyUpdate() creates a new OSSL_CMP_ITAV structure of type rootCaKeyUpdate that includes an RootCaKeyUpdateContent structure with the optional newWithNew, newWithOld, and oldWithNew certificates. An RootCaKeyUpdateContent structure is included only if newWithNew is not NULL.

- -

OSSL_CMP_ITAV_get0_rootCaKeyUpdate() requires that itav has infoType rootCaKeyUpdate. If an update of a root CA certificate is included, it assigns to *newWithNew the internal pointer to the certificate contained in the newWithNew infoValue sub-field of itav. If newWithOld is not NULL, it assigns to *newWithOld the internal pointer to the certificate contained in the newWithOld infoValue sub-field of itav. If oldWithNew is not NULL, it assigns to *oldWithNew the internal pointer to the certificate contained in the oldWithNew infoValue sub-field of itav. Each of these pointers will be set to NULL if no root CA certificate update is present or the respective sub-field is not included.

- -

OSSL_CMP_CRLSTATUS_new1() allocates a new OSSL_CMP_CRLSTATUS structure that contains either a copy of the distribution point name dpn or a copy of the certificate issuer issuer, while giving both is an error. If given, a copy of the CRL issuance time thisUpdate is also included.

- -

OSSL_CMP_CRLSTATUS_create() is a high-level variant of OSSL_CMP_CRLSTATUS_new1(). It fills the thisUpdate field with a copy of the thisUpdate field of crl if present. It fills the CRLSource field with a copy of the first data item found using the crl and/or cert parameters as follows. Any available distribution point name is preferred over issuer names. Data from cert, if present, is preferred over data from crl. If no distribution point names are available, candidate issuer names are taken from following sources, as far as present:

- -
- -
the list of distribution points in the first cRLDistributionPoints extension of cert,
-
- -
-
the issuer field of the authority key identifier of cert,
-
- -
-
the issuer DN of cert,
-
- -
-
the issuer field of the authority key identifier of crl, and
-
- -
-
the issuer DN of crl.
-
- -
-
- -

If <only_DN> is set, a candidate issuer name of type GENERAL_NAMES is accepted only if it contains exactly one general name of type directoryName.

- -

OSSL_CMP_CRLSTATUS_get0() reads the fields of crlstatus and assigns them to *dpn, *issuer, and *thisUpdate. *thisUpdate is assigned only if the thisUpdate argument is not NULL. Depending on the choice present, either *dpn or *issuer will be NULL. *thisUpdate can also be NULL if the field is not present.

- -

OSSL_CMP_ITAV_new0_crlStatusList() creates a new OSSL_CMP_ITAV structure of type crlStatusList that includes the optionally given list of CRL status data, each of which is of type OSSL_CMP_CRLSTATUS.

- -

OSSL_CMP_ITAV_get0_crlStatusList() on success assigns to *out an internal pointer to the list of CRL status data in the infoValue field of itav. The pointer may be NULL if no CRL status data is included. It is an error if the infoType of itav is not crlStatusList.

- -

OSSL_CMP_ITAV_new_crls() creates a new OSSL_CMP_ITAV structure of type crls including an empty list of CRLs if the crl argument is NULL or including a singleton list a with copy of the provided CRL otherwise.

- -

OSSL_CMP_ITAV_get0_crls() on success assigns to *out an internal pointer to the list of CRLs contained in the infoValue field of itav. The pointer may be NULL if no CRL is included. It is an error if the infoType of itav is not crls.

- -

OSSL_CMP_ITAV_new0_certReqTemplate() creates an OSSL_CMP_ITAV structure of type certReqTemplate. If certTemplate is NULL then also keySpec must be NULL, and the resulting ITAV can be used in a genm message to obtain the requirements a PKI has on the certificate template used to request certificates, or in a genp message stating that there are no such requirements. Otherwise the resulting ITAV includes a CertReqTemplateValue structure with certTemplate of type OSSL_CRMF_CERTTEMPLATE and an optional list of key specifications keySpec, each being of type OSSL_CMP_ATAV, and the resulting ATAV can be used in a genp message to provide requirements.

- -

OSSL_CMP_ITAV_get1_certReqTemplate() requires that itav has type certReqTemplate. If assigns NULL to *certTemplate if no OSSL_CRMF_CERTTEMPLATE structure with a certificate template value is in itav, otherwise a copy of the certTemplate field value. If keySpec is not NULL, it is assigned NULL if the structure is not present in itav or the keySpec field is absent. Otherwise, the function checks that all elements of keySpec field are of type algId or rsaKeyLen and assigns to *keySpec a copy of the keySpec field.

- -

NOTES

- -

CMP is defined in RFC 4210.

- -

RETURN VALUES

- -

OSSL_CMP_ITAV_new_caCerts(), OSSL_CMP_ITAV_new_rootCaCert(), OSSL_CMP_ITAV_new_rootCaKeyUpdate(), OSSL_CMP_CRLSTATUS_new1(), OSSL_CMP_CRLSTATUS_create(), OSSL_CMP_ITAV_new0_crlStatusList(), OSSL_CMP_ITAV_new_crls() and OSSL_CMP_ITAV_new0_certReqTemplate() return a pointer to the new ITAV structure on success, or NULL on error.

- -

OSSL_CMP_ITAV_get0_caCerts(), OSSL_CMP_ITAV_get0_rootCaCert(), OSSL_CMP_ITAV_get0_rootCaKeyUpdate(), OSSL_CMP_CRLSTATUS_get0(), OSSL_CMP_ITAV_get0_crlStatusList(), OSSL_CMP_ITAV_get0_crls() and OSSL_CMP_ITAV_get1_certReqTemplate() return 1 on success, 0 on error.

- -

SEE ALSO

- -

OSSL_CMP_ITAV_create(3) and OSSL_CMP_ITAV_get0_type(3)

- -

HISTORY

- -

OSSL_CMP_ITAV_new_caCerts(), OSSL_CMP_ITAV_get0_caCerts(), OSSL_CMP_ITAV_new_rootCaCert(), OSSL_CMP_ITAV_get0_rootCaCert(), OSSL_CMP_ITAV_new_rootCaKeyUpdate(), and OSSL_CMP_ITAV_get0_rootCaKeyUpdate() were added in OpenSSL 3.2.

- -

OSSL_CMP_CRLSTATUS_new1(), OSSL_CMP_CRLSTATUS_create(), OSSL_CMP_CRLSTATUS_get0(), OSSL_CMP_ITAV_new0_crlStatusList(), OSSL_CMP_ITAV_get0_crlStatusList(), OSSL_CMP_ITAV_new_crls(), OSSL_CMP_ITAV_get0_crls(), OSSL_CMP_ITAV_new0_certReqTemplate() and OSSL_CMP_ITAV_get1_certReqTemplate() were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_set0.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_set0.html deleted file mode 100644 index 5b20785a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_ITAV_set0.html +++ /dev/null @@ -1,127 +0,0 @@ - - - - -OSSL_CMP_ITAV_set0 - - - - - - - - - - -

NAME

- -

OSSL_CMP_ITAV_create, OSSL_CMP_ITAV_set0, OSSL_CMP_ITAV_get0_type, OSSL_CMP_ITAV_get0_value, OSSL_CMP_ITAV_push0_stack_item, OSSL_CMP_ITAV_new0_certProfile, OSSL_CMP_ITAV_get0_certProfile - OSSL_CMP_ITAV utility functions

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-OSSL_CMP_ITAV *OSSL_CMP_ITAV_create(ASN1_OBJECT *type, ASN1_TYPE *value);
-void OSSL_CMP_ITAV_set0(OSSL_CMP_ITAV *itav, ASN1_OBJECT *type,
-                        ASN1_TYPE *value);
-ASN1_OBJECT *OSSL_CMP_ITAV_get0_type(const OSSL_CMP_ITAV *itav);
-ASN1_TYPE *OSSL_CMP_ITAV_get0_value(const OSSL_CMP_ITAV *itav);
-int OSSL_CMP_ITAV_push0_stack_item(STACK_OF(OSSL_CMP_ITAV) **itav_sk_p,
-                                   OSSL_CMP_ITAV *itav);
-OSSL_CMP_ITAV
-*OSSL_CMP_ITAV_new0_certProfile(STACK_OF(ASN1_UTF8STRING) *certProfile);
-int OSSL_CMP_ITAV_get0_certProfile(const OSSL_CMP_ITAV *itav,
-                                   STACK_OF(ASN1_UTF8STRING) **out);
- -

DESCRIPTION

- -

ITAV is short for InfoTypeAndValue. This type is defined in RFC 4210 section 5.3.19 and Appendix F. It is used at various places in CMP messages, e.g., in the generalInfo PKIHeader field, to hold a key-value pair.

- -

OSSL_CMP_ITAV_create() creates a new OSSL_CMP_ITAV structure and fills it in. It combines OSSL_CMP_ITAV_new() and OSSL_CMP_ITAV_set0().

- -

OSSL_CMP_ITAV_set0() sets the itav with an infoType of type and an infoValue of value. This function uses the pointers type and value internally, so they must not be freed up after the call.

- -

OSSL_CMP_ITAV_get0_type() returns a direct pointer to the infoType in the itav.

- -

OSSL_CMP_ITAV_get0_value() returns a direct pointer to the infoValue in the itav as generic ASN1_TYPE pointer.

- -

OSSL_CMP_ITAV_push0_stack_item() pushes itav to the stack pointed to by *itav_sk_p. It creates a new stack if *itav_sk_p points to NULL.

- -

OSSL_CMP_ITAV_new0_certProfile() creates a new OSSL_CMP_ITAV structure of type certProfile that includes the optionally given list of profile names. On success, ownership of the list is with the new OSSL_CMP_ITAV structure.

- -

OSSL_CMP_ITAV_get0_certProfile() on success assigns to *out an internal pointer to the list of certificate profile names contained in the infoValue field of itav. The pointer may be NULL if no profile name is included. It is an error if the infoType of itav is not certProfile.

- -

NOTES

- -

CMP is defined in RFC 4210 and RFC 9480 (and CRMF in RFC 4211).

- -

OIDs to use as types in OSSL_CMP_ITAV can be found at https://datatracker.ietf.org/doc/html/rfc9480#section-4.2.2. The respective OpenSSL NIDs, such as NID_id_it_certProfile, are defined in the <openssl/obj_mac.h> header file.

- -

RETURN VALUES

- -

OSSL_CMP_ITAV_create() and OSSL_CMP_ITAV_new0_certProfile() return a pointer to an ITAV structure on success, or NULL on error.

- -

OSSL_CMP_ITAV_set0() does not return a value.

- -

OSSL_CMP_ITAV_get0_type() and OSSL_CMP_ITAV_get0_value() return the respective pointer or NULL if their input is NULL.

- -

OSSL_CMP_ITAV_push0_stack_item() and OSSL_CMP_ITAV_get0_certProfile() return 1 on success, 0 on error.

- -

EXAMPLES

- -

The following code creates and sets a structure representing a generic InfoTypeAndValue sequence, using an OID created from text as type, and an integer as value. Afterwards, it is pushed to the OSSL_CMP_CTX to be later included in the requests' PKIHeader's genInfo field.

- -
ASN1_OBJECT *type = OBJ_txt2obj("1.2.3.4.5", 1);
-if (type == NULL) ...
-
-ASN1_INTEGER *asn1int = ASN1_INTEGER_new();
-if (asn1int == NULL || !ASN1_INTEGER_set(asn1int, 12345)) ...
-
-ASN1_TYPE *val = ASN1_TYPE_new();
-if (val == NULL) ...
-ASN1_TYPE_set(val, V_ASN1_INTEGER, asn1int);
-
-OSSL_CMP_ITAV *itav = OSSL_CMP_ITAV_create(type, val);
-if (itav == NULL) ...
-
-if (!OSSL_CMP_CTX_push0_geninfo_ITAV(ctx, itav)) {
-    OSSL_CMP_ITAV_free(itav); /* also frees type and val */
-    ...
-}
-
-...
-
-OSSL_CMP_CTX_free(ctx); /* also frees itav */
- -

SEE ALSO

- -

OSSL_CMP_CTX_new(3), OSSL_CMP_CTX_free(3), ASN1_TYPE_set(3)

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

OSSL_CMP_ITAV_new0_certProfile() and OSSL_CMP_ITAV_get0_certProfile() were added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2007-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_get0_header.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_get0_header.html deleted file mode 100644 index 88039364..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_get0_header.html +++ /dev/null @@ -1,155 +0,0 @@ - - - - -OSSL_CMP_MSG_get0_header - - - - - - - - - - -

NAME

- -

OSSL_CMP_MSG_get0_header, OSSL_CMP_MSG_get_bodytype, OSSL_CMP_MSG_get0_certreq_publickey, OSSL_CMP_MSG_update_transactionID, OSSL_CMP_MSG_update_recipNonce, OSSL_CMP_CTX_setup_CRM, OSSL_CMP_MSG_read, OSSL_CMP_MSG_write, d2i_OSSL_CMP_MSG_bio, i2d_OSSL_CMP_MSG_bio - function(s) manipulating CMP messages

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-OSSL_CMP_PKIHEADER *OSSL_CMP_MSG_get0_header(const OSSL_CMP_MSG *msg);
-int OSSL_CMP_MSG_get_bodytype(const OSSL_CMP_MSG *msg);
-X509_PUBKEY *OSSL_CMP_MSG_get0_certreq_publickey(const OSSL_CMP_MSG *msg);
-int OSSL_CMP_MSG_update_transactionID(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg);
-int OSSL_CMP_MSG_update_recipNonce(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg);
-OSSL_CRMF_MSG *OSSL_CMP_CTX_setup_CRM(OSSL_CMP_CTX *ctx, int for_KUR, int rid);
-OSSL_CMP_MSG *OSSL_CMP_MSG_read(const char *file, OSSL_LIB_CTX *libctx, const char *propq);
-int OSSL_CMP_MSG_write(const char *file, const OSSL_CMP_MSG *msg);
-OSSL_CMP_MSG *d2i_OSSL_CMP_MSG_bio(BIO *bio, OSSL_CMP_MSG **msg);
-int i2d_OSSL_CMP_MSG_bio(BIO *bio, const OSSL_CMP_MSG *msg);
- -

DESCRIPTION

- -

OSSL_CMP_MSG_get0_header() returns the header of the given CMP message.

- -

OSSL_CMP_MSG_get_bodytype() returns the body type of the given CMP message.

- -

OSSL_CMP_MSG_get0_certreq_publickey() expects that msg is a certificate request message and returns the public key in its certificate template if present.

- -

OSSL_CMP_MSG_update_transactionID() updates the transactionID field in the header of the given message according to the CMP_CTX. If ctx does not contain a transaction ID, a fresh one is created before. The message gets re-protected (if protecting requests is required).

- -

OSSL_CMP_MSG_update_recipNonce() updates the recipNonce field in the header of the given message according to the CMP_CTX. The message gets re-protected (if protecting requests is required).

- -

OSSL_CMP_CTX_setup_CRM() creates a CRMF certificate request message from various information provided in the CMP context argument ctx for inclusion in a CMP request message based on details contained in ctx. The rid argument defines the request identifier to use, which typically is 0.

- -

The subject DN included in the certificate template is the first available value of these:

- -
- -
any subject name in ctx set via OSSL_CMP_CTX_set1_subjectName(3) - if it is the NULL-DN (i.e., any empty sequence of RDNs), no subject is included,
-
- -
-
the subject field of any PKCS#10 CSR set in ctx via OSSL_CMP_CTX_set1_p10CSR(3),
-
- -
-
the subject field of any reference certificate given in ctx (see OSSL_CMP_CTX_set1_oldCert(3)), but only if for_KUR is nonzero or the ctx does not include a Subject Alternative Name.
-
- -
-
- -

The public key included is the first available value of these:

- -
- -
the public key derived from any key set via OSSL_CMP_CTX_set0_newPkey(3),
-
- -
-
the public key of any PKCS#10 CSR given in ctx,
-
- -
-
the public key of any reference certificate given in ctx (see OSSL_CMP_CTX_set1_oldCert(3)),
-
- -
-
the public key derived from any client's private key set via OSSL_CMP_CTX_set1_pkey(3).
-
- -
-
- -

The set of X.509 extensions to include is computed as follows. If a PKCS#10 CSR is present in ctx, default extensions are taken from there, otherwise the empty set is taken as the initial value. If there is a reference certificate in ctx and contains Subject Alternative Names (SANs) and OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT is not set, these override any SANs from the PKCS#10 CSR. The extensions are further augmented or overridden by any extensions with the same OIDs included in the ctx via OSSL_CMP_CTX_set0_reqExtensions(3). The SANs are further overridden by any SANs included in ctx via OSSL_CMP_CTX_push1_subjectAltName(3). Finally, policies are overridden by any policies included in ctx via OSSL_CMP_CTX_push0_policy(3).

- -

OSSL_CMP_CTX_setup_CRM() also sets the sets the regToken control oldCertID for KUR messages using the issuer name and serial number of the reference certificate, if present.

- -

OSSL_CMP_MSG_read() loads a DER-encoded OSSL_CMP_MSG from file.

- -

OSSL_CMP_MSG_write() stores the given OSSL_CMP_MSG to file in DER encoding.

- -

d2i_OSSL_CMP_MSG_bio() parses an ASN.1-encoded OSSL_CMP_MSG from the BIO bio. It assigns a pointer to the new structure to *msg if msg is not NULL.

- -

i2d_OSSL_CMP_MSG_bio() writes the OSSL_CMP_MSG msg in ASN.1 encoding to BIO bio.

- -

NOTES

- -

CMP is defined in RFC 4210.

- -

RETURN VALUES

- -

OSSL_CMP_MSG_get0_header() returns the intended pointer value as described above or NULL if the respective entry does not exist and on error.

- -

OSSL_CMP_MSG_get_bodytype() returns the body type or -1 on error.

- -

OSSL_CMP_MSG_get0_certreq_publickey() returns a public key or NULL on error.

- -

OSSL_CMP_CTX_setup_CRM() returns a pointer to a OSSL_CRMF_MSG on success, NULL on error.

- -

d2i_OSSL_CMP_MSG_bio() returns the parsed message or NULL on error.

- -

OSSL_CMP_MSG_read() and d2i_OSSL_CMP_MSG_bio() return the parsed CMP message or NULL on error.

- -

OSSL_CMP_MSG_write() returns the number of bytes successfully encoded or a negative value if an error occurs.

- -

i2d_OSSL_CMP_MSG_bio(), OSSL_CMP_MSG_update_transactionID(), and OSSL_CMP_MSG_update_recipNonce() return 1 on success, 0 on error.

- -

SEE ALSO

- -

OSSL_CMP_CTX_set1_subjectName(3), OSSL_CMP_CTX_set1_p10CSR(3), OSSL_CMP_CTX_set1_oldCert(3), OSSL_CMP_CTX_set0_newPkey(3), OSSL_CMP_CTX_set1_pkey(3), OSSL_CMP_CTX_set0_reqExtensions(3), OSSL_CMP_CTX_push1_subjectAltName(3), OSSL_CMP_CTX_push0_policy(3)

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

OSSL_CMP_MSG_update_recipNonce() was added in OpenSSL 3.0.9.

- -

OSSL_CMP_MSG_get0_certreq_publickey() was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_http_perform.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_http_perform.html deleted file mode 100644 index a11bc738..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_MSG_http_perform.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -OSSL_CMP_MSG_http_perform - - - - - - - - - - -

NAME

- -

OSSL_CMP_MSG_http_perform - client-side HTTP(S) transfer of a CMP request-response pair

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-OSSL_CMP_MSG *OSSL_CMP_MSG_http_perform(OSSL_CMP_CTX *ctx,
-                                        const OSSL_CMP_MSG *req);
- -

DESCRIPTION

- -

OSSL_CMP_MSG_http_perform() sends the given PKIMessage req to the CMP server specified in ctx via OSSL_CMP_CTX_set1_server(3) and optionally OSSL_CMP_CTX_set_serverPort(3), using any "CMP alias" optionally specified via OSSL_CMP_CTX_set1_serverPath(3). The default port is 80 for HTTP and 443 for HTTPS; the default path is "/". On success the function returns the server's response PKIMessage.

- -

The function makes use of any HTTP callback function set via OSSL_CMP_CTX_set_http_cb(3). It respects any timeout value set via OSSL_CMP_CTX_set_option(3) with an OSSL_CMP_OPT_MSG_TIMEOUT argument. It also respects any HTTP(S) proxy options set via OSSL_CMP_CTX_set1_proxy(3) and OSSL_CMP_CTX_set1_no_proxy(3) and the respective environment variables. Proxying plain HTTP is supported directly, while using a proxy for HTTPS connections requires a suitable callback function such as OSSL_HTTP_proxy_connect(3).

- -

NOTES

- -

CMP is defined in RFC 4210. HTTP transfer for CMP is defined in RFC 6712.

- -

RETURN VALUES

- -

OSSL_CMP_MSG_http_perform() returns a CMP message on success, else NULL.

- -

SEE ALSO

- -

OSSL_CMP_CTX_new(3), OSSL_HTTP_proxy_connect(3).

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_SRV_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_SRV_CTX_new.html deleted file mode 100644 index 37174875..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_SRV_CTX_new.html +++ /dev/null @@ -1,157 +0,0 @@ - - - - -OSSL_CMP_SRV_CTX_new - - - - - - - - - - -

NAME

- -

OSSL_CMP_SRV_process_request, OSSL_CMP_CTX_server_perform, OSSL_CMP_SRV_CTX_new, OSSL_CMP_SRV_CTX_free, OSSL_CMP_SRV_cert_request_cb_t, OSSL_CMP_SRV_rr_cb_t, OSSL_CMP_SRV_certConf_cb_t, OSSL_CMP_SRV_genm_cb_t, OSSL_CMP_SRV_error_cb_t, OSSL_CMP_SRV_pollReq_cb_t, OSSL_CMP_SRV_CTX_init, OSSL_CMP_SRV_delayed_delivery_cb_t, OSSL_CMP_SRV_clean_transaction_cb_t, OSSL_CMP_SRV_CTX_init_trans, OSSL_CMP_SRV_CTX_get0_cmp_ctx, OSSL_CMP_SRV_CTX_get0_custom_ctx, OSSL_CMP_SRV_CTX_set_send_unprotected_errors, OSSL_CMP_SRV_CTX_set_accept_unprotected, OSSL_CMP_SRV_CTX_set_accept_raverified, OSSL_CMP_SRV_CTX_set_grant_implicit_confirm - generic functions to set up and control a CMP server

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-OSSL_CMP_MSG *OSSL_CMP_SRV_process_request(OSSL_CMP_SRV_CTX *srv_ctx,
-                                           const OSSL_CMP_MSG *req);
-OSSL_CMP_MSG *OSSL_CMP_CTX_server_perform(OSSL_CMP_CTX *client_ctx,
-                                          const OSSL_CMP_MSG *req);
-OSSL_CMP_SRV_CTX *OSSL_CMP_SRV_CTX_new(OSSL_LIB_CTX *libctx, const char *propq);
-void OSSL_CMP_SRV_CTX_free(OSSL_CMP_SRV_CTX *srv_ctx);
-
-typedef OSSL_CMP_PKISI *(*OSSL_CMP_SRV_cert_request_cb_t)(
-                                                OSSL_CMP_SRV_CTX *srv_ctx,
-                                                const OSSL_CMP_MSG *req,
-                                                int certReqId,
-                                                const OSSL_CRMF_MSG *crm,
-                                                const X509_REQ *p10cr,
-                                                X509 **certOut,
-                                                STACK_OF(X509) **chainOut,
-                                                STACK_OF(X509) **caPubs);
-typedef OSSL_CMP_PKISI *(*OSSL_CMP_SRV_rr_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx,
-                                                const OSSL_CMP_MSG *req,
-                                                const X509_NAME *issuer,
-                                                const ASN1_INTEGER *serial);
-typedef int (*OSSL_CMP_SRV_genm_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx,
-                                      const OSSL_CMP_MSG *req,
-                                      STACK_OF(OSSL_CMP_ITAV) *in,
-                                      STACK_OF(OSSL_CMP_ITAV) **out);
-typedef void (*OSSL_CMP_SRV_error_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx,
-                                        const OSSL_CMP_MSG *req,
-                                        const OSSL_CMP_PKISI *statusInfo,
-                                        const ASN1_INTEGER *errorCode,
-                                        const OSSL_CMP_PKIFREETEXT *errorDetails);
-typedef int (*OSSL_CMP_SRV_certConf_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx,
-                                          const OSSL_CMP_MSG *req,
-                                          int certReqId,
-                                          const ASN1_OCTET_STRING *certHash,
-                                          const OSSL_CMP_PKISI *si);
-typedef int (*OSSL_CMP_SRV_pollReq_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx,
-                                         const OSSL_CMP_MSG *req,
-                                         int certReqId,
-                                         OSSL_CMP_MSG **certReq,
-                                         int64_t *check_after);
-int OSSL_CMP_SRV_CTX_init(OSSL_CMP_SRV_CTX *srv_ctx, void *custom_ctx,
-                          OSSL_CMP_SRV_cert_request_cb_t process_cert_request,
-                          OSSL_CMP_SRV_rr_cb_t process_rr,
-                          OSSL_CMP_SRV_genm_cb_t process_genm,
-                          OSSL_CMP_SRV_error_cb_t process_error,
-                          OSSL_CMP_SRV_certConf_cb_t process_certConf,
-                          OSSL_CMP_SRV_pollReq_cb_t process_pollReq);
-typedef int (*OSSL_CMP_SRV_delayed_delivery_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx,
-                                                  const OSSL_CMP_MSG *req);
-typedef int (*OSSL_CMP_SRV_clean_transaction_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx,
-                                                   const ASN1_OCTET_STRING *id);
-int OSSL_CMP_SRV_CTX_init_trans(OSSL_CMP_SRV_CTX *srv_ctx,
-                                OSSL_CMP_SRV_delayed_delivery_cb_t delay,
-                                OSSL_CMP_SRV_clean_transaction_cb_t clean);
-
-OSSL_CMP_CTX *OSSL_CMP_SRV_CTX_get0_cmp_ctx(const OSSL_CMP_SRV_CTX *srv_ctx);
-void *OSSL_CMP_SRV_CTX_get0_custom_ctx(const OSSL_CMP_SRV_CTX *srv_ctx);
-
-int OSSL_CMP_SRV_CTX_set_send_unprotected_errors(OSSL_CMP_SRV_CTX *srv_ctx,
-                                                 int val);
-int OSSL_CMP_SRV_CTX_set_accept_unprotected(OSSL_CMP_SRV_CTX *srv_ctx, int val);
-int OSSL_CMP_SRV_CTX_set_accept_raverified(OSSL_CMP_SRV_CTX *srv_ctx, int val);
-int OSSL_CMP_SRV_CTX_set_grant_implicit_confirm(OSSL_CMP_SRV_CTX *srv_ctx,
-                                                int val);
- -

DESCRIPTION

- -

OSSL_CMP_SRV_process_request() implements the generic aspects of a CMP server. Its arguments are the OSSL_CMP_SRV_CTX srv_ctx and the CMP request message req. It does the typical generic checks on req, calls the respective callback function (if present) for more specific processing, and then assembles a result message, which may be a CMP error message. If after return of the function the expression OSSL_CMP_CTX_get_status(OSSL_CMP_SRV_CTX_get0_cmp_ctx(srv_ctx)) yields -1 then the function has closed the current transaction, which may be due to normal successful end of the transaction or due to an error.

- -

OSSL_CMP_CTX_server_perform() is an interface to OSSL_CMP_SRV_process_request() that can be used by a CMP client in the same way as OSSL_CMP_MSG_http_perform(3). The OSSL_CMP_SRV_CTX must be set as transfer_cb_arg of client_ctx.

- -

OSSL_CMP_SRV_CTX_new() creates and initializes an OSSL_CMP_SRV_CTX structure associated with the library context libctx and property query string propq, both of which may be NULL to select the defaults.

- -

OSSL_CMP_SRV_CTX_free() deletes the given srv_ctx. If the argument is NULL, nothing is done.

- -

OSSL_CMP_SRV_CTX_init() sets in the given srv_ctx a custom server context pointer as well as callback functions performing the specific processing of CMP certificate requests, revocation requests, certificate confirmation requests, general messages, error messages, and poll requests. All arguments except srv_ctx may be NULL. If a callback for some message type is not given this means that the respective type of CMP message is not supported by the server.

- -

OSSL_CMP_SRV_CTX_init_trans() sets in srv_ctx the optional callback functions for initiating delayed delivery and cleaning up a transaction. If the <delay> function is NULL then delivery of responses is never delayed. Otherwise delay takes a custom server context and a request message as input. It must return 1 if delivery of the respective response shall be delayed, 0 if not, and -1 on error. If the <clean> function is NULL then no specific cleanup is performed. Otherwise clean takes a custom server context and a transaction ID pointer as input, where the pointer is NULL in case a new transaction is being started and otherwise provides the ID of the transaction being terminated. The <clean> function should reset the respective portions of the state and free related memory. It must return 1 on success and 0 on error.

- -

OSSL_CMP_SRV_CTX_get0_cmp_ctx() returns the OSSL_CMP_CTX from the srv_ctx.

- -

OSSL_CMP_SRV_CTX_get0_custom_ctx() returns the custom server context from srv_ctx that has been set using OSSL_CMP_SRV_CTX_init().

- -

OSSL_CMP_SRV_CTX_set_send_unprotected_errors() enables sending error messages and other forms of negative responses unprotected.

- -

OSSL_CMP_SRV_CTX_set_accept_unprotected() enables acceptance of requests without protection of with invalid protection.

- -

OSSL_CMP_SRV_CTX_set_accept_raverified() enables acceptance of ir/cr/kur messages with POPO 'RAVerified'.

- -

OSSL_CMP_SRV_CTX_set_grant_implicit_confirm() enables granting implicit confirmation of newly enrolled certificates if requested.

- -

NOTES

- -

CMP is defined in RFC 4210 (and CRMF in RFC 4211).

- -

So far the CMP server implementation is limited to one request per CMP message (and consequently to at most one response component per CMP message).

- -

RETURN VALUES

- -

OSSL_CMP_SRV_CTX_new() returns a OSSL_CMP_SRV_CTX structure on success, NULL on error.

- -

OSSL_CMP_SRV_CTX_free() does not return a value.

- -

OSSL_CMP_SRV_CTX_get0_cmp_ctx() returns a OSSL_CMP_CTX structure on success, NULL on error.

- -

OSSL_CMP_SRV_CTX_get0_custom_ctx() returns the custom server context that has been set using OSSL_CMP_SRV_CTX_init().

- -

All other functions return 1 on success, 0 on error.

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

OSSL_CMP_SRV_CTX_init_trans() supporting delayed delivery of all types of response messages was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_STATUSINFO_new.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_STATUSINFO_new.html deleted file mode 100644 index 6183f4c2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_STATUSINFO_new.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -OSSL_CMP_STATUSINFO_new - - - - - - - - - - -

NAME

- -

OSSL_CMP_STATUSINFO_new, OSSL_CMP_snprint_PKIStatusInfo, OSSL_CMP_CTX_snprint_PKIStatus - function(s) for managing the CMP PKIStatus

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-
-OSSL_CMP_PKISI *OSSL_CMP_STATUSINFO_new(int status, int fail_info,
-                                        const char *text);
-char *OSSL_CMP_snprint_PKIStatusInfo(const OSSL_CMP_PKISI *statusInfo,
-                                     char *buf, size_t bufsize);
-char *OSSL_CMP_CTX_snprint_PKIStatus(const OSSL_CMP_CTX *ctx, char *buf,
-                                     size_t bufsize);
- -

DESCRIPTION

- -

This is the PKIStatus API for using CMP (Certificate Management Protocol) with OpenSSL.

- -

OSSL_CMP_STATUSINFO_new() creates a new PKIStatusInfo structure and fills in the given values. It sets the status field to status, copies text (unless it is NULL) to statusString, and interprets fail_info as bit pattern for the failInfo field.

- -

OSSL_CMP_snprint_PKIStatusInfo() places a human-readable string representing the given statusInfo in the given buffer, with the given maximal length.

- -

OSSL_CMP_CTX_snprint_PKIStatus() places a human-readable string representing the PKIStatusInfo components of the CMP context ctx in the given buffer, with the given maximal length.

- -

NOTES

- -

CMP is defined in RFC 4210 (and CRMF in RFC 4211).

- -

RETURN VALUES

- -

OSSL_CMP_STATUSINFO_new() returns a pointer to the structure on success, or NULL on error.

- -

OSSL_CMP_snprint_PKIStatusInfo() and OSSL_CMP_CTX_snprint_PKIStatus() return a copy of the buffer pointer containing the string or NULL on error.

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_exec_certreq.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_exec_certreq.html deleted file mode 100644 index c0869600..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_exec_certreq.html +++ /dev/null @@ -1,141 +0,0 @@ - - - - -OSSL_CMP_exec_certreq - - - - - - - - - - -

NAME

- -

OSSL_CMP_exec_certreq, OSSL_CMP_exec_IR_ses, OSSL_CMP_exec_CR_ses, OSSL_CMP_exec_P10CR_ses, OSSL_CMP_exec_KUR_ses, OSSL_CMP_IR, OSSL_CMP_CR, OSSL_CMP_P10CR, OSSL_CMP_KUR, OSSL_CMP_try_certreq, OSSL_CMP_exec_RR_ses, OSSL_CMP_exec_GENM_ses, OSSL_CMP_get1_caCerts, OSSL_CMP_get1_rootCaKeyUpdate, OSSL_CMP_get1_crlUpdate, OSSL_CMP_get1_certReqTemplate - functions implementing CMP client transactions

- -

SYNOPSIS

- -
 #include <openssl/cmp.h>
-
- X509 *OSSL_CMP_exec_certreq(OSSL_CMP_CTX *ctx, int req_type,
-                             const OSSL_CRMF_MSG *crm);
- X509 *OSSL_CMP_exec_IR_ses(OSSL_CMP_CTX *ctx);
- X509 *OSSL_CMP_exec_CR_ses(OSSL_CMP_CTX *ctx);
- X509 *OSSL_CMP_exec_P10CR_ses(OSSL_CMP_CTX *ctx);
- X509 *OSSL_CMP_exec_KUR_ses(OSSL_CMP_CTX *ctx);
- #define OSSL_CMP_IR
- #define OSSL_CMP_CR
- #define OSSL_CMP_P10CR
- #define OSSL_CMP_KUR
- int OSSL_CMP_try_certreq(OSSL_CMP_CTX *ctx, int req_type,
-                          const OSSL_CRMF_MSG *crm, int *checkAfter);
- int OSSL_CMP_exec_RR_ses(OSSL_CMP_CTX *ctx);
-
- STACK_OF(OSSL_CMP_ITAV) *OSSL_CMP_exec_GENM_ses(OSSL_CMP_CTX *ctx);
- int OSSL_CMP_get1_caCerts(OSSL_CMP_CTX *ctx, STACK_OF(X509) **out);
- int OSSL_CMP_get1_rootCaKeyUpdate(OSSL_CMP_CTX *ctx,
-                                   const X509 *oldWithOld, X509 **newWithNew,
-                                   X509 **newWithOld, X509 **oldWithNew);
- int OSSL_CMP_get1_crlUpdate(OSSL_CMP_CTX *ctx, const X509 *crlcert,
-                             const X509_CRL *last_crl,
-                             X509_CRL **crl);
- int OSSL_CMP_get1_certReqTemplate(OSSL_CMP_CTX *ctx,
-                                   OSSL_CRMF_CERTTEMPLATE **certTemplate,
-                                   OSSL_CMP_ATAVS **keySpec);
-=head1 DESCRIPTION
- -

This is the OpenSSL API for doing CMP (Certificate Management Protocol) client-server transactions, i.e., sequences of CMP requests and responses.

- -

All functions take a populated OSSL_CMP_CTX structure as their first argument. Usually the server name, port, and path ("CMP alias") need to be set, as well as credentials the client can use for authenticating itself to the server. In order to authenticate the server the client typically needs a trust store. The functions return their respective main results directly, while there are also accessor functions for retrieving various results and status information from the ctx. See OSSL_CMP_CTX_new(3) etc. for details.

- -

The default conveying protocol is HTTP. Timeout values may be given per request-response pair and per transaction. See OSSL_CMP_MSG_http_perform(3) for details.

- -

OSSL_CMP_exec_IR_ses() requests an initial certificate from the given PKI.

- -

OSSL_CMP_exec_CR_ses() requests an additional certificate.

- -

OSSL_CMP_exec_P10CR_ses() conveys a legacy PKCS#10 CSR requesting a certificate.

- -

OSSL_CMP_exec_KUR_ses() obtains an updated certificate.

- -

These four types of certificate enrollment are implemented as macros calling OSSL_CMP_exec_certreq().

- -

OSSL_CMP_exec_certreq() performs a certificate request of the type specified by the req_type parameter, which may be IR, CR, P10CR, or KUR. For IR, CR, and KUR, the certificate template to be used in the request may be supplied via the crm parameter pointing to a CRMF structure. Typically crm is NULL, then the template ingredients are taken from ctx and need to be filled in using OSSL_CMP_CTX_set1_subjectName(3), OSSL_CMP_CTX_set0_newPkey(3), OSSL_CMP_CTX_set1_oldCert(3), etc. For P10CR, OSSL_CMP_CTX_set1_p10CSR(3) needs to be used instead. The enrollment session may be blocked (with polling and sleeping in between) until the server side can fully process and ultimately answer the request.

- -

OSSL_CMP_try_certreq() is an alternative to the above functions that is more flexible regarding what to do after receiving a checkAfter value. When called for the first time (with no certificate request in progress for the given ctx) it starts a new transaction by sending a certificate request constructed as stated above using the req_type and optional crm parameter. Otherwise (when according to ctx a 'waiting' status has been received before) it continues polling for the pending request unless the req_type argument is < 0, which aborts the request. If the requested certificate is available the function returns 1 and the caller can use OSSL_CMP_CTX_get0_newCert(3) to retrieve the new certificate. If no error occurred but no certificate is available yet then OSSL_CMP_try_certreq() remembers in the CMP context that it should be retried and returns -1 after assigning the received checkAfter value via the output pointer argument (unless it is NULL). The checkAfter value indicates the number of seconds the caller should let pass before trying again. The caller is free to sleep for the given number of seconds or for some other time and/or to do anything else before retrying by calling OSSL_CMP_try_certreq() again with the same parameter values as before. OSSL_CMP_try_certreq() then polls to see whether meanwhile the requested certificate is available. If the caller decides to abort the pending certificate request and provides a negative value as the req_type argument then OSSL_CMP_try_certreq() aborts the CMP transaction by sending an error message to the server.

- -

OSSL_CMP_exec_RR_ses() requests the revocation of the certificate specified in the ctx using the issuer DN and serial number set by OSSL_CMP_CTX_set1_issuer(3) and OSSL_CMP_CTX_set1_serialNumber(3), respectively, otherwise the issuer DN and serial number of the certificate set by OSSL_CMP_CTX_set1_oldCert(3), otherwise the subject DN and public key of the certificate signing request set by OSSL_CMP_CTX_set1_p10CSR(3). RFC 4210 is vague in which PKIStatus should be returned by the server. We take "accepted" and "grantedWithMods" as clear success and handle "revocationWarning" and "revocationNotification" just as warnings because CAs typically return them as an indication that the certificate was already revoked. "rejection" is a clear error. The values "waiting" and "keyUpdateWarning" make no sense for revocation and thus are treated as an error as well. The revocation session may be blocked (with polling and sleeping in between) until the server can fully process and ultimately answer the request.

- -

OSSL_CMP_exec_GENM_ses() sends a genm general message containing the sequence of infoType and infoValue pairs (InfoTypeAndValue; short: ITAV) optionally provided in the ctx using OSSL_CMP_CTX_push0_genm_ITAV(3). The message exchange may be blocked (with polling and sleeping in between) until the server can fully process and ultimately answer the request. On success the function records in ctx status OSSL_CMP_PKISTATUS_accepted and returns the list of ITAVs received in a genp response message. This can be used, for instance, with infoType signKeyPairTypes to obtain the set of signature algorithm identifiers that the CA will certify for subject public keys. See RFC 4210 section 5.3.19 and appendix E.5 for details. Functions implementing more specific genm/genp exchanges are described next.

- -

OSSL_CMP_get1_caCerts() uses a genm/genp message exchange with infoType caCerts to obtain a list of CA certificates from the CMP server referenced by ctx. On success it assigns to *out the list of certificates received, which must be freed by the caller. NULL output means that no CA certificates were provided by the server.

- -

OSSL_CMP_get1_rootCaKeyUpdate() uses a genm request message with infoType rootCaCert to obtain from the CMP server referenced by ctx in a genp response message with infoType rootCaKeyUpdate any update of the given root CA certificate oldWithOld and verifies it as far as possible. See RFC 4210 section 4.4 for details. On success it assigns to *newWithNew the root certificate received. When the newWithOld and oldWithNew output parameters are not NULL, it assigns to them the corresponding transition certificates. NULL means that the respective certificate was not provided by the server. All certificates obtained this way must be freed by the caller.

- -

WARNING: The newWithNew certificate is meant to be a certificate that will be trusted. The trust placed in it cannot be stronger than the trust placed in the oldwithold certificate if present, otherwise it cannot be stronger than the weakest trust in any of the certificates in the trust store of ctx.

- -

OSSL_CMP_get1_crlUpdate() uses a genm request message with infoType crlStatusList to obtain CRL from the CMP server referenced by ctx in a genp response message with infoType crls. It uses last_crl and crlcert to create a request with a status field as described for OSSL_CMP_CRLSTATUS_create(3). On success it assigns to *crl the CRL received. NULL means that no CRL was provided by the server. The CRL obtained this way must be freed by the caller.

- -

OSSL_CMP_get1_certReqTemplate() uses a genm request message with infoType certReqTemplate to obtain a certificate request template from the CMP server referenced by ctx. On success it assigns to *certTemplate the certificate template received. NULL output means that no certificate request template was provided by the server. The optional keySpec output parameter is assigned the key specification if received, otherwise it set to NULL. Both must be freed by the caller.

- -

NOTES

- -

CMP is defined in RFC 4210 (and CRMF in RFC 4211).

- -

The CMP client implementation is limited to one request per CMP message (and consequently to at most one response component per CMP message).

- -

When a client obtains from a CMP server CA certificates that it is going to trust, for instance via the caPubs field of a certificate response or using functions like OSSL_CMP_get1_caCerts() and OSSL_CMP_get1_rootCaKeyUpdate(), authentication of the CMP server is particularly critical. So special care must be taken setting up server authentication in ctx using functions such as OSSL_CMP_CTX_set0_trusted(3) (for certificate-based authentication) or OSSL_CMP_CTX_set1_secretValue(3) (for MAC-based protection). If authentication is certificate-based, OSSL_CMP_CTX_get0_validatedSrvCert(3) should be used to obtain the server validated certificate and perform an authorization check based on it.

- -

RETURN VALUES

- -

OSSL_CMP_exec_certreq(), OSSL_CMP_exec_IR_ses(), OSSL_CMP_exec_CR_ses(), OSSL_CMP_exec_P10CR_ses(), and OSSL_CMP_exec_KUR_ses() return a pointer to the newly obtained X509 certificate on success, NULL on error. This pointer will be freed implicitly by OSSL_CMP_CTX_free() or CSSL_CMP_CTX_reinit().

- -

OSSL_CMP_try_certreq() returns 1 if the requested certificate is available via OSSL_CMP_CTX_get0_newCert(3) or on successfully aborting a pending certificate request, 0 on error, and -1 in case a 'waiting' status has been received and checkAfter value is available. In the latter case OSSL_CMP_CTX_get0_newCert(3) yields NULL and the output parameter checkAfter has been used to assign the received value unless checkAfter is NULL.

- -

OSSL_CMP_exec_RR_ses(), OSSL_CMP_get1_caCerts(), OSSL_CMP_get1_rootCaKeyUpdate(), OSSL_CMP_get1_crlUpdate() and OSSL_CMP_get1_certReqTemplate() return 1 on success, 0 on error.

- -

OSSL_CMP_exec_GENM_ses() returns NULL on error, otherwise a pointer to the sequence of ITAV received, which may be empty. This pointer must be freed by the caller.

- -

EXAMPLES

- -

See OSSL_CMP_CTX for examples on how to prepare the context for these functions.

- -

SEE ALSO

- -

OSSL_CMP_CTX_new(3), OSSL_CMP_CTX_free(3), OSSL_CMP_CTX_set1_subjectName(3), OSSL_CMP_CTX_set0_newPkey(3), OSSL_CMP_CTX_set1_p10CSR(3), OSSL_CMP_CTX_set1_oldCert(3), OSSL_CMP_CTX_get0_newCert(3), OSSL_CMP_CTX_push0_genm_ITAV(3), OSSL_CMP_MSG_http_perform(3), OSSL_CMP_CRLSTATUS_create(3)

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

OSSL_CMP_get1_caCerts() and OSSL_CMP_get1_rootCaKeyUpdate() were added in OpenSSL 3.2.

- -

Support for delayed delivery of all types of response messages was added in OpenSSL 3.3.

- -

OSSL_CMP_get1_crlUpdate() and OSSL_CMP_get1_certReqTemplate() were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_log_open.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_log_open.html deleted file mode 100644 index 5a46948d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_log_open.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -OSSL_CMP_log_open - - - - - - - - - - -

NAME

- -

OSSL_CMP_log_open, OSSL_CMP_log_close, OSSL_CMP_severity, OSSL_CMP_LOG_EMERG, OSSL_CMP_LOG_ALERT, OSSL_CMP_LOG_CRIT, OSSL_CMP_LOG_ERR, OSSL_CMP_LOG_WARNING, OSSL_CMP_LOG_NOTICE, OSSL_CMP_LOG_INFO, OSSL_CMP_LOG_DEBUG, OSSL_CMP_LOG_TRACE,

- -

OSSL_CMP_log_cb_t, OSSL_CMP_print_to_bio, OSSL_CMP_print_errors_cb - functions for logging and error reporting

- -

SYNOPSIS

- -
#include <openssl/cmp_util.h>
-
-int  OSSL_CMP_log_open(void);
-void OSSL_CMP_log_close(void);
-
-/* severity level declarations resemble those from syslog.h */
-typedef int OSSL_CMP_severity;
-#define OSSL_CMP_LOG_EMERG   0
-#define OSSL_CMP_LOG_ALERT   1
-#define OSSL_CMP_LOG_CRIT    2
-#define OSSL_CMP_LOG_ERR     3
-#define OSSL_CMP_LOG_WARNING 4
-#define OSSL_CMP_LOG_NOTICE  5
-#define OSSL_CMP_LOG_INFO    6
-#define OSSL_CMP_LOG_DEBUG   7
-#define OSSL_CMP_LOG_TRACE   8
-
-typedef int (*OSSL_CMP_log_cb_t)(const char *component,
-                                 const char *file, int line,
-                                 OSSL_CMP_severity level, const char *msg);
-int OSSL_CMP_print_to_bio(BIO *bio, const char *component, const char *file,
-                          int line, OSSL_CMP_severity level, const char *msg);
-void OSSL_CMP_print_errors_cb(OSSL_CMP_log_cb_t log_fn);
- -

DESCRIPTION

- -

The logging and error reporting facility described here contains convenience functions for CMP-specific logging, including a string prefix mirroring the severity levels of syslog.h, and enhancements of the error queue mechanism needed for large diagnostic messages produced by the CMP library in case of certificate validation failures.

- -

When an interesting activity is performed or an error occurs, some detail should be provided for user information, debugging, and auditing purposes. A CMP application can obtain this information by providing a callback function with the following type:

- -
typedef int (*OSSL_CMP_log_cb_t)(const char *component,
-                                 const char *file, int line,
-                                 OSSL_CMP_severity level, const char *msg);
- -

The parameters may provide some component info (which may be a module name and/or function name) or NULL, a file pathname or NULL, a line number or 0 indicating the source code location, a severity level, and a message string describing the nature of the event, terminated by '\n'.

- -

Even when an activity is successful some warnings may be useful and some degree of auditing may be required. Therefore, the logging facility supports a severity level and the callback function has a level parameter indicating such a level, such that error, warning, info, debug, etc. can be treated differently. The callback is activated only when the severity level is sufficient according to the current level of verbosity, which by default is OSSL_CMP_LOG_INFO.

- -

The callback function may itself do non-trivial tasks like writing to a log file or remote stream, which in turn may fail. Therefore, the function should return 1 on success and 0 on failure.

- -

OSSL_CMP_log_open() initializes the CMP-specific logging facility to output everything to STDOUT. It fails if the integrated tracing is disabled or STDIO is not available. It may be called during application startup. Alternatively, OSSL_CMP_CTX_set_log_cb(3) can be used for more flexibility. As long as neither if the two is used any logging output is ignored.

- -

OSSL_CMP_log_close() may be called when all activities are finished to flush any pending CMP-specific log output and deallocate related resources. It may be called multiple times. It does get called at OpenSSL shutdown.

- -

OSSL_CMP_print_to_bio() prints the given component info, filename, line number, severity level, and log message or error queue message to the given bio. component usually is a function or module name. If it is NULL, empty, or "(unknown function)" then "CMP" is used as fallback.

- -

OSSL_CMP_print_errors_cb() outputs any entries in the OpenSSL error queue. It is similar to ERR_print_errors_cb(3) but uses the CMP log callback function log_fn for uniformity with CMP logging if not NULL. Otherwise it prints to STDERR using OSSL_CMP_print_to_bio(3) (unless OPENSSL_NO_STDIO is defined).

- -

RETURN VALUES

- -

OSSL_CMP_log_close() and OSSL_CMP_print_errors_cb() do not return anything.

- -

All other functions return 1 on success, 0 on error.

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_validate_msg.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_validate_msg.html deleted file mode 100644 index 480f16ca..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CMP_validate_msg.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -OSSL_CMP_validate_msg - - - - - - - - - - -

NAME

- -

OSSL_CMP_validate_msg, OSSL_CMP_validate_cert_path - functions for verifying CMP message protection

- -

SYNOPSIS

- -
#include <openssl/cmp.h>
-int OSSL_CMP_validate_msg(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg);
-int OSSL_CMP_validate_cert_path(const OSSL_CMP_CTX *ctx,
-                                X509_STORE *trusted_store, X509 *cert);
- -

DESCRIPTION

- -

This is the API for validating the protection of CMP messages, which includes validating CMP message sender certificates and their paths while optionally checking the revocation status of the certificates(s).

- -

OSSL_CMP_validate_msg() validates the protection of the given msg, which must be signature-based or using password-based MAC (PBM). In the former case a suitable trust anchor must be given in the CMP context ctx, and in the latter case the matching secret must have been set there using OSSL_CMP_CTX_set1_secretValue(3).

- -

In case of signature algorithm, the certificate to use for the signature check is preferably the one provided by a call to OSSL_CMP_CTX_set1_srvCert(3). If no such sender cert has been pinned then candidate sender certificates are taken from the list of certificates received in the msg extraCerts, then any certificates provided before via OSSL_CMP_CTX_set1_untrusted(3), and then all trusted certificates provided via OSSL_CMP_CTX_set0_trusted(3). A candidate certificate is acceptable only if it is currently valid (or the trust store contains a verification callback that overrides the verdict that the certificate is expired or not yet valid), its subject DN matches the msg sender DN (as far as present), and its subject key identifier is present and matches the senderKID (as far as the latter is present). Each acceptable cert is tried in the given order to see if the message signature check succeeds and the cert and its path can be verified using any trust store set via OSSL_CMP_CTX_set0_trusted(3).

- -

If the option OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR was set by calling OSSL_CMP_CTX_set_option(3), for an Initialization Response (IP) message any self-issued certificate from the msg extraCerts field may be used as a trust anchor for the path verification of an 'acceptable' cert if it can be used also to validate the issued certificate returned in the IP message. This is according to TS 33.310 [Network Domain Security (NDS); Authentication Framework (AF)] document specified by The 3rd Generation Partnership Project (3GPP). Note that using this option is dangerous as the certificate obtained this way has not been authenticated (at least not at CMP level). Taking it over as a trust anchor implements trust-on-first-use (TOFU).

- -

Any cert that has been found as described above is cached and tried first when validating the signatures of subsequent messages in the same transaction.

- -

OSSL_CMP_validate_cert_path() attempts to validate the given certificate and its path using the given store of trusted certs (possibly including CRLs and a cert verification callback) and non-trusted intermediate certs from the ctx.

- -

NOTES

- -

CMP is defined in RFC 4210 (and CRMF in RFC 4211).

- -

RETURN VALUES

- -

OSSL_CMP_validate_msg() and OSSL_CMP_validate_cert_path() return 1 on success, 0 on error or validation failed.

- -

SEE ALSO

- -

OSSL_CMP_CTX_new(3), OSSL_CMP_exec_certreq(3), OSSL_CMP_CTX_set1_secretValue(3), OSSL_CMP_CTX_set1_srvCert(3), OSSL_CMP_CTX_set1_untrusted(3), OSSL_CMP_CTX_set0_trusted(3)

- -

HISTORY

- -

The OpenSSL CMP support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CORE_MAKE_FUNC.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CORE_MAKE_FUNC.html deleted file mode 100644 index ff867da4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CORE_MAKE_FUNC.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -OSSL_CORE_MAKE_FUNC - - - - - - - - - - -

NAME

- -

OSSL_CORE_MAKE_FUNC, SSL_OP_BIT, EXT_UTF8STRING - OpenSSL reserved symbols

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-
-#define OSSL_CORE_MAKE_FUNC(type,name,args)
-#define SSL_OP_BIT(n)
-#define EXT_UTF8STRING(nid)
- -

DESCRIPTION

- -

There are certain macros that may appear in OpenSSL header files that are reserved for internal use. They should not be used by applications or assumed to exist.

- -

All the macros listed in the synopsis above are reserved.

- -

RETURN VALUES

- -

Not applicable.

- -

HISTORY

- -

The macros described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_get0_tmpl.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_get0_tmpl.html deleted file mode 100644 index 5bbe9a4a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_get0_tmpl.html +++ /dev/null @@ -1,104 +0,0 @@ - - - - -OSSL_CRMF_MSG_get0_tmpl - - - - - - - - - - -

NAME

- -

OSSL_CRMF_MSG_get0_tmpl, OSSL_CRMF_CERTTEMPLATE_get0_publicKey, OSSL_CRMF_CERTTEMPLATE_get0_subject, OSSL_CRMF_CERTTEMPLATE_get0_issuer, OSSL_CRMF_CERTTEMPLATE_get0_serialNumber, OSSL_CRMF_CERTTEMPLATE_get0_extensions, OSSL_CRMF_CERTID_get0_serialNumber, OSSL_CRMF_CERTID_get0_issuer, OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert, OSSL_CRMF_MSG_get_certReqId - functions reading from CRMF CertReqMsg structures

- -

SYNOPSIS

- -
#include <openssl/crmf.h>
-
-OSSL_CRMF_CERTTEMPLATE *OSSL_CRMF_MSG_get0_tmpl(const OSSL_CRMF_MSG *crm);
-X509_PUBKEY
-*OSSL_CRMF_CERTTEMPLATE_get0_publicKey(const OSSL_CRMF_CERTTEMPLATE *tmpl);
-const X509_NAME
-*OSSL_CRMF_CERTTEMPLATE_get0_subject(const OSSL_CRMF_CERTTEMPLATE *tmpl);
-const X509_NAME
-*OSSL_CRMF_CERTTEMPLATE_get0_issuer(const OSSL_CRMF_CERTTEMPLATE *tmpl);
-const ASN1_INTEGER
-*OSSL_CRMF_CERTTEMPLATE_get0_serialNumber(const OSSL_CRMF_CERTTEMPLATE *tmpl);
-X509_EXTENSIONS
-*OSSL_CRMF_CERTTEMPLATE_get0_extensions(const OSSL_CRMF_CERTTEMPLATE *tmpl);
-
-const ASN1_INTEGER
-*OSSL_CRMF_CERTID_get0_serialNumber(const OSSL_CRMF_CERTID *cid);
-const X509_NAME *OSSL_CRMF_CERTID_get0_issuer(const OSSL_CRMF_CERTID *cid);
-
-X509
-*OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert(const OSSL_CRMF_ENCRYPTEDVALUE *ecert,
-                                       OSSL_LIB_CTX *libctx, const char *propq,
-                                       EVP_PKEY *pkey);
-
-int OSSL_CRMF_MSG_get_certReqId(const OSSL_CRMF_MSG *crm);
- -

DESCRIPTION

- -

OSSL_CRMF_MSG_get0_tmpl() retrieves the certificate template of crm.

- -

OSSL_CRMF_CERTTEMPLATE_get0_publicKey() retrieves the public key of the given certificate template tmpl.

- -

OSSL_CRMF_CERTTEMPLATE_get0_subject() retrieves the subject name of the given certificate template tmpl.

- -

OSSL_CRMF_CERTTEMPLATE_get0_issuer() retrieves the issuer name of the given certificate template tmpl.

- -

OSSL_CRMF_CERTTEMPLATE_get0_serialNumber() retrieves the serialNumber of the given certificate template tmpl.

- -

OSSL_CRMF_CERTTEMPLATE_get0_extensions() retrieves the X.509 extensions of the given certificate template tmpl, or NULL if not present.

- -

OSSL_CRMF_CERTID_get0_serialNumber retrieves the serialNumber of the given CertId cid.

- -

OSSL_CRMF_CERTID_get0_issuer retrieves the issuer name of the given CertId cid, which must be of ASN.1 type GEN_DIRNAME.

- -

OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert() decrypts the certificate in the given encryptedValue ecert, using the private key pkey, library context libctx and property query string propq (see OSSL_LIB_CTX(3)). This is needed for the indirect POPO method as in RFC 4210 section 5.2.8.2. The function returns the decrypted certificate as a copy, leaving its ownership with the caller, who is responsible for freeing it.

- -

OSSL_CRMF_MSG_get_certReqId() retrieves the certReqId of crm.

- -

RETURN VALUES

- -

OSSL_CRMF_MSG_get_certReqId() returns the certificate request ID as a nonnegative integer or -1 on error.

- -

All other functions return a pointer with the intended result or NULL on error.

- -

SEE ALSO

- -

RFC 4211

- -

HISTORY

- -

The OpenSSL CRMF support was added in OpenSSL 3.0.

- -

OSSL_CRMF_CERTTEMPLATE_get0_publicKey() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set0_validity.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set0_validity.html deleted file mode 100644 index 199ed84a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set0_validity.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -OSSL_CRMF_MSG_set0_validity - - - - - - - - - - -

NAME

- -

OSSL_CRMF_MSG_set0_validity, OSSL_CRMF_MSG_set_certReqId, OSSL_CRMF_CERTTEMPLATE_fill, OSSL_CRMF_MSG_set0_extensions, OSSL_CRMF_MSG_push0_extension, OSSL_CRMF_MSG_create_popo, OSSL_CRMF_MSGS_verify_popo - functions populating and verifying CRMF CertReqMsg structures

- -

SYNOPSIS

- -
#include <openssl/crmf.h>
-
-int OSSL_CRMF_MSG_set0_validity(OSSL_CRMF_MSG *crm,
-                                ASN1_TIME *notBefore, ASN1_TIME *notAfter);
-
-int OSSL_CRMF_MSG_set_certReqId(OSSL_CRMF_MSG *crm, int rid);
-
-int OSSL_CRMF_CERTTEMPLATE_fill(OSSL_CRMF_CERTTEMPLATE *tmpl,
-                                EVP_PKEY *pubkey,
-                                const X509_NAME *subject,
-                                const X509_NAME *issuer,
-                                const ASN1_INTEGER *serial);
-
-int OSSL_CRMF_MSG_set0_extensions(OSSL_CRMF_MSG *crm, X509_EXTENSIONS *exts);
-
-int OSSL_CRMF_MSG_push0_extension(OSSL_CRMF_MSG *crm, X509_EXTENSION *ext);
-
-int OSSL_CRMF_MSG_create_popo(int meth, OSSL_CRMF_MSG *crm,
-                              EVP_PKEY *pkey, const EVP_MD *digest,
-                              OSSL_LIB_CTX *libctx, const char *propq);
-
-int OSSL_CRMF_MSGS_verify_popo(const OSSL_CRMF_MSGS *reqs,
-                               int rid, int acceptRAVerified,
-                               OSSL_LIB_CTX *libctx, const char *propq);
- -

DESCRIPTION

- -

OSSL_CRMF_MSG_set0_validity() sets the notBefore and notAfter fields as validity constraints in the certTemplate of crm. Any of the notBefore and notAfter parameters may be NULL, which means no constraint for the respective field. On success ownership of notBefore and notAfter is transferred to crm.

- -

OSSL_CRMF_MSG_set_certReqId() sets rid as the certReqId of crm.

- -

OSSL_CRMF_CERTTEMPLATE_fill() sets those fields of the certTemplate tmpl for which non-NULL values are provided: pubkey, subject, issuer, and/or serial. X.509 extensions may be set using OSSL_CRMF_MSG_set0_extensions(). On success the reference counter of the pubkey (if given) is incremented, while the subject, issuer, and serial structures (if given) are copied.

- -

OSSL_CRMF_MSG_set0_extensions() sets exts as the extensions in the certTemplate of crm. Frees any pre-existing ones and consumes exts.

- -

OSSL_CRMF_MSG_push0_extension() pushes the X509 extension ext to the extensions in the certTemplate of crm. Consumes ext.

- -

OSSL_CRMF_MSG_create_popo() creates and sets the Proof-of-Possession (POPO) according to the method meth in crm. The library context libctx and property query string propq, may be NULL to select the defaults. In case the method is OSSL_CRMF_POPO_SIGNATURE the POPO is calculated using the private key pkey and the digest method digest, where the digest argument is ignored if pkey is of a type (such as Ed25519 and Ed448) that is implicitly associated with a digest algorithm.

- -

meth can be one of the following:

- - - -

OSSL_CRMF_MSGS_verify_popo verifies the Proof-of-Possession of the request with the given rid in the list of reqs. Optionally accepts RAVerified. It can make use of the library context libctx and property query string propq.

- -

RETURN VALUES

- -

All functions return 1 on success, 0 on error.

- -

SEE ALSO

- -

RFC 4211

- -

HISTORY

- -

The OpenSSL CRMF support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.html deleted file mode 100644 index 2a71ae7e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.html +++ /dev/null @@ -1,116 +0,0 @@ - - - - -OSSL_CRMF_MSG_set1_regCtrl_regToken - - - - - - - - - - -

NAME

- -

OSSL_CRMF_MSG_get0_regCtrl_regToken, OSSL_CRMF_MSG_set1_regCtrl_regToken, OSSL_CRMF_MSG_get0_regCtrl_authenticator, OSSL_CRMF_MSG_set1_regCtrl_authenticator, OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo, OSSL_CRMF_MSG_set0_SinglePubInfo, OSSL_CRMF_MSG_set_PKIPublicationInfo_action, OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo, OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo, OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey, OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey, OSSL_CRMF_MSG_get0_regCtrl_oldCertID, OSSL_CRMF_MSG_set1_regCtrl_oldCertID, OSSL_CRMF_CERTID_gen - functions getting or setting CRMF Registration Controls

- -

SYNOPSIS

- -
#include <openssl/crmf.h>
-
-ASN1_UTF8STRING
-   *OSSL_CRMF_MSG_get0_regCtrl_regToken(const OSSL_CRMF_MSG *msg);
-int OSSL_CRMF_MSG_set1_regCtrl_regToken(OSSL_CRMF_MSG *msg,
-                                        const ASN1_UTF8STRING *tok);
-ASN1_UTF8STRING
-   *OSSL_CRMF_MSG_get0_regCtrl_authenticator(const OSSL_CRMF_MSG *msg);
-int OSSL_CRMF_MSG_set1_regCtrl_authenticator(OSSL_CRMF_MSG *msg,
-                                             const ASN1_UTF8STRING *auth);
-int OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo(
-                                 OSSL_CRMF_PKIPUBLICATIONINFO *pi,
-                                 OSSL_CRMF_SINGLEPUBINFO *spi);
-int OSSL_CRMF_MSG_set0_SinglePubInfo(OSSL_CRMF_SINGLEPUBINFO *spi,
-                                     int method, GENERAL_NAME *nm);
-int OSSL_CRMF_MSG_set_PKIPublicationInfo_action(
-                                 OSSL_CRMF_PKIPUBLICATIONINFO *pi, int action);
-OSSL_CRMF_PKIPUBLICATIONINFO
-   *OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo(const OSSL_CRMF_MSG *msg);
-int OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo(OSSL_CRMF_MSG *msg,
-                                       const OSSL_CRMF_PKIPUBLICATIONINFO *pi);
-X509_PUBKEY
-   *OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey(const OSSL_CRMF_MSG *msg);
-int OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey(OSSL_CRMF_MSG *msg,
-                                               const X509_PUBKEY *pubkey);
-OSSL_CRMF_CERTID
-   *OSSL_CRMF_MSG_get0_regCtrl_oldCertID(const OSSL_CRMF_MSG *msg);
-int OSSL_CRMF_MSG_set1_regCtrl_oldCertID(OSSL_CRMF_MSG *msg,
-                                         const OSSL_CRMF_CERTID *cid);
-OSSL_CRMF_CERTID *OSSL_CRMF_CERTID_gen(const X509_NAME *issuer,
-                                       const ASN1_INTEGER *serial);
- -

DESCRIPTION

- -

Each of the OSSL_CRMF_MSG_get0_regCtrl_X() functions returns the respective control X in the given msg, if present.

- -

OSSL_CRMF_MSG_set1_regCtrl_regToken() sets the regToken control in the given msg copying the given tok as value. See RFC 4211, section 6.1.

- -

OSSL_CRMF_MSG_set1_regCtrl_authenticator() sets the authenticator control in the given msg copying the given auth as value. See RFC 4211, section 6.2.

- -

OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo() pushes the given spi to si. Consumes the spi pointer.

- -

OSSL_CRMF_MSG_set0_SinglePubInfo() sets in the given SinglePubInfo spi the method and publication location, in the form of a GeneralName, nm. The publication location is optional, and therefore nm may be NULL. The function consumes the nm pointer if present. Available methods are: # define OSSL_CRMF_PUB_METHOD_DONTCARE 0 # define OSSL_CRMF_PUB_METHOD_X500 1 # define OSSL_CRMF_PUB_METHOD_WEB 2 # define OSSL_CRMF_PUB_METHOD_LDAP 3

- -

OSSL_CRMF_MSG_set_PKIPublicationInfo_action() sets the action in the given pi using the given action as value. See RFC 4211, section 6.3. Available actions are: # define OSSL_CRMF_PUB_ACTION_DONTPUBLISH 0 # define OSSL_CRMF_PUB_ACTION_PLEASEPUBLISH 1

- -

OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo() sets the pkiPublicationInfo control in the given msg copying the given tok as value. See RFC 4211, section 6.3.

- -

OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey() sets the protocolEncrKey control in the given msg copying the given pubkey as value. See RFC 4211 section 6.6.

- -

OSSL_CRMF_MSG_set1_regCtrl_oldCertID() sets the oldCertID regToken control in the given msg copying the given cid as value. See RFC 4211, section 6.5.

- -

OSSL_CRMF_CERTID_gen produces an OSSL_CRMF_CERTID_gen structure copying the given issuer name and serial number.

- -

RETURN VALUES

- -

All OSSL_CRMF_MSG_get0_*() functions return the respective pointer value or NULL if not present and on error.

- -

All OSSL_CRMF_MSG_set1_*() functions return 1 on success, 0 on error.

- -

OSSL_CRMF_CERTID_gen() returns a pointer to the resulting structure or NULL on error.

- -

NOTES

- -

A function OSSL_CRMF_MSG_set1_regCtrl_pkiArchiveOptions() for setting an Archive Options Control is not yet implemented due to missing features to create the needed OSSL_CRMF_PKIARCHIVEOPTINS content.

- -

SEE ALSO

- -

RFC 4211

- -

HISTORY

- -

The OpenSSL CRMF support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.html deleted file mode 100644 index e8595524..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -OSSL_CRMF_MSG_set1_regInfo_certReq - - - - - - - - - - -

NAME

- -

OSSL_CRMF_MSG_get0_regInfo_utf8Pairs, OSSL_CRMF_MSG_set1_regInfo_utf8Pairs, OSSL_CRMF_MSG_get0_regInfo_certReq, OSSL_CRMF_MSG_set1_regInfo_certReq - functions getting or setting CRMF Registration Info

- -

SYNOPSIS

- -
#include <openssl/crmf.h>
-
-ASN1_UTF8STRING
-    *OSSL_CRMF_MSG_get0_regInfo_utf8Pairs(const OSSL_CRMF_MSG *msg);
-int OSSL_CRMF_MSG_set1_regInfo_utf8Pairs(OSSL_CRMF_MSG *msg,
-                                         const ASN1_UTF8STRING *utf8pairs);
-OSSL_CRMF_CERTREQUEST
-    *OSSL_CRMF_MSG_get0_regInfo_certReq(const OSSL_CRMF_MSG *msg);
-int OSSL_CRMF_MSG_set1_regInfo_certReq(OSSL_CRMF_MSG *msg,
-                                       const OSSL_CRMF_CERTREQUEST *cr);
- -

DESCRIPTION

- -

OSSL_CRMF_MSG_get0_regInfo_utf8Pairs() returns the first utf8Pairs regInfo in the given msg, if present.

- -

OSSL_CRMF_MSG_set1_regInfo_utf8Pairs() adds a copy of the given utf8pairs value as utf8Pairs regInfo to the given msg. See RFC 4211 section 7.1.

- -

OSSL_CRMF_MSG_get0_regInfo_certReq() returns the first certReq regInfo in the given msg, if present.

- -

OSSL_CRMF_MSG_set1_regInfo_certReq() adds a copy of the given cr value as certReq regInfo to the given msg. See RFC 4211 section 7.2.

- -

RETURN VALUES

- -

All get0_*() functions return the respective pointer value, NULL if not present.

- -

All set1_*() functions return 1 on success, 0 on error.

- -

NOTES

- -

Calling the set1_*() functions multiple times adds multiple instances of the respective control to the regInfo structure of the given msg. While RFC 4211 expects multiple utf8Pairs in one regInfo structure, it does not allow multiple certReq.

- -

SEE ALSO

- -

RFC 4211

- -

HISTORY

- -

The OpenSSL CRMF support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_pbmp_new.html b/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_pbmp_new.html deleted file mode 100644 index 5dd25a42..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_CRMF_pbmp_new.html +++ /dev/null @@ -1,96 +0,0 @@ - - - - -OSSL_CRMF_pbmp_new - - - - - - - - - - -

NAME

- -

OSSL_CRMF_pbm_new, OSSL_CRMF_pbmp_new - functions for producing Password-Based MAC (PBM)

- -

SYNOPSIS

- -
#include <openssl/crmf.h>
-
-int OSSL_CRMF_pbm_new(OSSL_LIB_CTX *libctx, const char *propq,
-                      const OSSL_CRMF_PBMPARAMETER *pbmp,
-                      const unsigned char *msg, size_t msglen,
-                      const unsigned char *sec, size_t seclen,
-                      unsigned char **mac, size_t *maclen);
-
-OSSL_CRMF_PBMPARAMETER *OSSL_CRMF_pbmp_new(OSSL_LIB_CTX *libctx, size_t saltlen,
-                                           int owfnid, size_t itercnt,
-                                           int macnid);
- -

DESCRIPTION

- -

OSSL_CRMF_pbm_new() generates a PBM (Password-Based MAC) based on given PBM parameters pbmp, message msg, and secret sec, along with the respective lengths msglen and seclen. The optional library context libctx and propq parameters may be used to influence the selection of the MAC algorithm referenced in the pbmp; see "ALGORITHM FETCHING" in crypto(7) for further information. On success writes the address of the newly allocated MAC via the mac reference parameter and writes the length via the maclen reference parameter unless it its NULL.

- -

OSSL_CRMF_pbmp_new() initializes and returns a new PBMParameter structure with a new random salt of given length saltlen, OWF (one-way function) NID owfnid, OWF iteration count itercnt, and MAC NID macnid. The library context libctx parameter may be used to select the provider for the random number generation (DRBG) and may be NULL for the default.

- -

NOTES

- -

The algorithms for the OWF (one-way function) and for the MAC (message authentication code) may be any with a NID defined in <openssl/objects.h>. As specified by RFC 4210, these should include NID_hmac_sha1.

- -

RFC 4210 recommends that the salt SHOULD be at least 8 bytes (64 bits) long, where 16 bytes is common.

- -

The iteration count must be at least 100, as stipulated by RFC 4211, and is limited to at most 100000 to avoid DoS through manipulated or otherwise malformed input.

- -

RETURN VALUES

- -

OSSL_CRMF_pbm_new() returns 1 on success, 0 on error.

- -

OSSL_CRMF_pbmp_new() returns a new and initialized OSSL_CRMF_PBMPARAMETER structure, or NULL on error.

- -

EXAMPLES

- -
OSSL_CRMF_PBMPARAMETER *pbm = NULL;
-unsigned char *msg = "Hello";
-unsigned char *sec = "SeCrEt";
-unsigned char *mac = NULL;
-size_t maclen;
-
-if ((pbm = OSSL_CRMF_pbmp_new(16, NID_sha256, 500, NID_hmac_sha1) == NULL))
-    goto err;
-if (!OSSL_CRMF_pbm_new(pbm, msg, 5, sec, 6, &mac, &maclen))
-    goto err;
- -

SEE ALSO

- -

RFC 4211 section 4.4

- -

HISTORY

- -

The OpenSSL CRMF support was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2007-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER.html b/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER.html deleted file mode 100644 index a2abac70..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER.html +++ /dev/null @@ -1,166 +0,0 @@ - - - - -OSSL_DECODER - - - - - - - - - - -

NAME

- -

OSSL_DECODER, OSSL_DECODER_fetch, OSSL_DECODER_up_ref, OSSL_DECODER_free, OSSL_DECODER_get0_provider, OSSL_DECODER_get0_properties, OSSL_DECODER_is_a, OSSL_DECODER_get0_name, OSSL_DECODER_get0_description, OSSL_DECODER_do_all_provided, OSSL_DECODER_names_do_all, OSSL_DECODER_gettable_params, OSSL_DECODER_get_params - Decoder method routines

- -

SYNOPSIS

- -
#include <openssl/decoder.h>
-
-typedef struct ossl_decoder_st OSSL_DECODER;
-
-OSSL_DECODER *OSSL_DECODER_fetch(OSSL_LIB_CTX *ctx, const char *name,
-                                 const char *properties);
-int OSSL_DECODER_up_ref(OSSL_DECODER *decoder);
-void OSSL_DECODER_free(OSSL_DECODER *decoder);
-const OSSL_PROVIDER *OSSL_DECODER_get0_provider(const OSSL_DECODER *decoder);
-const char *OSSL_DECODER_get0_properties(const OSSL_DECODER *decoder);
-int OSSL_DECODER_is_a(const OSSL_DECODER *decoder, const char *name);
-const char *OSSL_DECODER_get0_name(const OSSL_DECODER *decoder);
-const char *OSSL_DECODER_get0_description(const OSSL_DECODER *decoder);
-void OSSL_DECODER_do_all_provided(OSSL_LIB_CTX *libctx,
-                                  void (*fn)(OSSL_DECODER *decoder, void *arg),
-                                  void *arg);
-int OSSL_DECODER_names_do_all(const OSSL_DECODER *decoder,
-                              void (*fn)(const char *name, void *data),
-                              void *data);
-const OSSL_PARAM *OSSL_DECODER_gettable_params(OSSL_DECODER *decoder);
-int OSSL_DECODER_get_params(OSSL_DECODER_CTX *ctx, const OSSL_PARAM params[]);
- -

DESCRIPTION

- -

OSSL_DECODER is a method for decoders, which know how to decode encoded data into an object of some type that the rest of OpenSSL knows how to handle.

- -

OSSL_DECODER_fetch() looks for an algorithm within the provider that has been loaded into the OSSL_LIB_CTX given by ctx, having the name given by name and the properties given by properties. The name determines what type of object the fetched decoder method is expected to be able to decode, and the properties are used to determine the expected output type. For known properties and the values they may have, please have a look in "Names and properties" in provider-encoder(7).

- -

OSSL_DECODER_up_ref() increments the reference count for the given decoder.

- -

OSSL_DECODER_free() decrements the reference count for the given decoder, and when the count reaches zero, frees it. If the argument is NULL, nothing is done.

- -

OSSL_DECODER_get0_provider() returns the provider of the given decoder.

- -

OSSL_DECODER_get0_properties() returns the property definition associated with the given decoder.

- -

OSSL_DECODER_is_a() checks if decoder is an implementation of an algorithm that's identifiable with name.

- -

OSSL_DECODER_get0_name() returns the name used to fetch the given decoder.

- -

OSSL_DECODER_get0_description() returns a description of the decoder, meant for display and human consumption. The description is at the discretion of the decoder implementation.

- -

OSSL_DECODER_names_do_all() traverses all names for the given decoder, and calls fn with each name and data as arguments.

- -

OSSL_DECODER_do_all_provided() traverses all decoder implementations by all activated providers in the library context libctx, and for each of the implementations, calls fn with the implementation method and arg as arguments.

- -

OSSL_DECODER_gettable_params() returns an OSSL_PARAM(3) array of parameter descriptors.

- -

OSSL_DECODER_get_params() attempts to get parameters specified with an OSSL_PARAM(3) array params. Parameters that the implementation doesn't recognise should be ignored.

- -

RETURN VALUES

- -

OSSL_DECODER_fetch() returns a pointer to an OSSL_DECODER object, or NULL on error.

- -

OSSL_DECODER_up_ref() returns 1 on success, or 0 on error.

- -

OSSL_DECODER_free() doesn't return any value.

- -

OSSL_DECODER_get0_provider() returns a pointer to a provider object, or NULL on error.

- -

OSSL_DECODER_get0_properties() returns a pointer to a property definition string, or NULL on error.

- -

OSSL_DECODER_is_a() returns 1 if decoder was identifiable, otherwise 0.

- -

OSSL_DECODER_get0_name() returns the algorithm name from the provided implementation for the given decoder. Note that the decoder may have multiple synonyms associated with it. In this case the first name from the algorithm definition is returned. Ownership of the returned string is retained by the decoder object and should not be freed by the caller.

- -

OSSL_DECODER_get0_description() returns a pointer to a description, or NULL if there isn't one.

- -

OSSL_DECODER_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

NOTES

- -

OSSL_DECODER_fetch() may be called implicitly by other fetching functions, using the same library context and properties. Any other API that uses keys will typically do this.

- -

EXAMPLES

- -

To list all decoders in a provider to a bio_out:

- -
static void collect_decoders(OSSL_DECODER *decoder, void *stack)
-{
-    STACK_OF(OSSL_DECODER) *decoder_stack = stack;
-
-    sk_OSSL_DECODER_push(decoder_stack, decoder);
-    OSSL_DECODER_up_ref(decoder);
-}
-
-void print_name(const char *name, void *vdata)
-{
-    BIO *bio = vdata;
-
-    BIO_printf(bio, "%s ", name);
-}
-
-
-STACK_OF(OSSL_DECODER) *decoders;
-int i;
-
-decoders = sk_OSSL_DECODER_new_null();
-
-BIO_printf(bio_out, "DECODERs provided by %s:\n", provider);
-OSSL_DECODER_do_all_provided(NULL, collect_decoders,
-                             decoders);
-
-for (i = 0; i < sk_OSSL_DECODER_num(decoders); i++) {
-    OSSL_DECODER *decoder = sk_OSSL_DECODER_value(decoders, i);
-
-    if (strcmp(OSSL_PROVIDER_get0_name(OSSL_DECODER_get0_provider(decoder)),
-               provider) != 0)
-        continue;
-
-    if (OSSL_DECODER_names_do_all(decoder, print_name, bio_out))
-           BIO_printf(bio_out, "\n");
-}
-sk_OSSL_DECODER_pop_free(decoders, OSSL_DECODER_free);
- -

SEE ALSO

- -

provider(7), OSSL_DECODER_CTX(3), OSSL_DECODER_from_bio(3), OSSL_DECODER_CTX_new_for_pkey(3), OSSL_LIB_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX.html b/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX.html deleted file mode 100644 index f9cf0dd2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX.html +++ /dev/null @@ -1,204 +0,0 @@ - - - - -OSSL_DECODER_CTX - - - - - - - - - - -

NAME

- -

OSSL_DECODER_CTX, OSSL_DECODER_CTX_new, OSSL_DECODER_settable_ctx_params, OSSL_DECODER_CTX_set_params, OSSL_DECODER_CTX_free, OSSL_DECODER_CTX_set_selection, OSSL_DECODER_CTX_set_input_type, OSSL_DECODER_CTX_set_input_structure, OSSL_DECODER_CTX_add_decoder, OSSL_DECODER_CTX_add_extra, OSSL_DECODER_CTX_get_num_decoders, OSSL_DECODER_INSTANCE, OSSL_DECODER_CONSTRUCT, OSSL_DECODER_CLEANUP, OSSL_DECODER_CTX_set_construct, OSSL_DECODER_CTX_set_construct_data, OSSL_DECODER_CTX_set_cleanup, OSSL_DECODER_CTX_get_construct, OSSL_DECODER_CTX_get_construct_data, OSSL_DECODER_CTX_get_cleanup, OSSL_DECODER_export, OSSL_DECODER_INSTANCE_get_decoder, OSSL_DECODER_INSTANCE_get_decoder_ctx, OSSL_DECODER_INSTANCE_get_input_type, OSSL_DECODER_INSTANCE_get_input_structure - Decoder context routines

- -

SYNOPSIS

- -
#include <openssl/decoder.h>
-
-typedef struct ossl_decoder_ctx_st OSSL_DECODER_CTX;
-
-OSSL_DECODER_CTX *OSSL_DECODER_CTX_new(void);
-const OSSL_PARAM *OSSL_DECODER_settable_ctx_params(OSSL_DECODER *decoder);
-int OSSL_DECODER_CTX_set_params(OSSL_DECODER_CTX *ctx,
-                                const OSSL_PARAM params[]);
-void OSSL_DECODER_CTX_free(OSSL_DECODER_CTX *ctx);
-
-int OSSL_DECODER_CTX_set_selection(OSSL_DECODER_CTX *ctx, int selection);
-int OSSL_DECODER_CTX_set_input_type(OSSL_DECODER_CTX *ctx,
-                                    const char *input_type);
-int OSSL_DECODER_CTX_set_input_structure(OSSL_DECODER_CTX *ctx,
-                                         const char *input_structure);
-int OSSL_DECODER_CTX_add_decoder(OSSL_DECODER_CTX *ctx, OSSL_DECODER *decoder);
-int OSSL_DECODER_CTX_add_extra(OSSL_DECODER_CTX *ctx,
-                               OSSL_LIB_CTX *libctx,
-                               const char *propq);
-int OSSL_DECODER_CTX_get_num_decoders(OSSL_DECODER_CTX *ctx);
-
-typedef struct ossl_decoder_instance_st OSSL_DECODER_INSTANCE;
-OSSL_DECODER *
-OSSL_DECODER_INSTANCE_get_decoder(OSSL_DECODER_INSTANCE *decoder_inst);
-void *
-OSSL_DECODER_INSTANCE_get_decoder_ctx(OSSL_DECODER_INSTANCE *decoder_inst);
-const char *
-OSSL_DECODER_INSTANCE_get_input_type(OSSL_DECODER_INSTANCE *decoder_inst);
-OSSL_DECODER_INSTANCE_get_input_structure(OSSL_DECODER_INSTANCE *decoder_inst,
-                                          int *was_set);
-
-typedef int OSSL_DECODER_CONSTRUCT(OSSL_DECODER_INSTANCE *decoder_inst,
-                                   const OSSL_PARAM *object,
-                                   void *construct_data);
-typedef void OSSL_DECODER_CLEANUP(void *construct_data);
-
-int OSSL_DECODER_CTX_set_construct(OSSL_DECODER_CTX *ctx,
-                                   OSSL_DECODER_CONSTRUCT *construct);
-int OSSL_DECODER_CTX_set_construct_data(OSSL_DECODER_CTX *ctx,
-                                        void *construct_data);
-int OSSL_DECODER_CTX_set_cleanup(OSSL_DECODER_CTX *ctx,
-                                 OSSL_DECODER_CLEANUP *cleanup);
-OSSL_DECODER_CONSTRUCT *OSSL_DECODER_CTX_get_construct(OSSL_DECODER_CTX *ctx);
-void *OSSL_DECODER_CTX_get_construct_data(OSSL_DECODER_CTX *ctx);
-OSSL_DECODER_CLEANUP *OSSL_DECODER_CTX_get_cleanup(OSSL_DECODER_CTX *ctx);
-
-int OSSL_DECODER_export(OSSL_DECODER_INSTANCE *decoder_inst,
-                        void *reference, size_t reference_sz,
-                        OSSL_CALLBACK *export_cb, void *export_cbarg);
- -

DESCRIPTION

- -

The OSSL_DECODER_CTX holds data about multiple decoders, as needed to figure out what the input data is and to attempt to unpack it into one of several possible related results. This also includes chaining decoders, so the output from one can become the input for another. This allows having generic format decoders such as PEM to DER, as well as more specialized decoders like DER to RSA.

- -

The chains may be limited by specifying an input type, which is considered a starting point. This is both considered by OSSL_DECODER_CTX_add_extra(), which will stop adding one more decoder implementations when it has already added those that take the specified input type, and functions like OSSL_DECODER_from_bio(3), which will only start the decoding process with the decoder implementations that take that input type. For example, if the input type is set to DER, a PEM to DER decoder will be ignored.

- -

The input type can also be NULL, which means that the caller doesn't know what type of input they have. In this case, OSSL_DECODER_from_bio() will simply try with one decoder implementation after the other, and thereby discover what kind of input the caller gave it.

- -

For every decoding done, even an intermediary one, a constructor provided by the caller is called to attempt to construct an appropriate type / structure that the caller knows how to handle from the current decoding result. The constructor is set with OSSL_DECODER_CTX_set_construct().

- -

OSSL_DECODER_INSTANCE is an opaque structure that contains data about the decoder that was just used, and that may be useful for the constructor. There are some functions to extract data from this type, described further down.

- -

Functions

- -

OSSL_DECODER_CTX_new() creates a new empty OSSL_DECODER_CTX.

- -

OSSL_DECODER_settable_ctx_params() returns an OSSL_PARAM(3) array of parameter descriptors.

- -

OSSL_DECODER_CTX_set_params() attempts to set parameters specified with an OSSL_PARAM(3) array params. These parameters are passed to all decoders that have been added to the ctx so far. Parameters that an implementation doesn't recognise should be ignored by it.

- -

OSSL_DECODER_CTX_free() frees the given context ctx. If the argument is NULL, nothing is done.

- -

OSSL_DECODER_CTX_add_decoder() populates the OSSL_DECODER_CTX ctx with a decoder, to be used to attempt to decode some encoded input.

- -

OSSL_DECODER_CTX_add_extra() finds decoders that generate input for already added decoders, and adds them as well. This is used to build decoder chains.

- -

OSSL_DECODER_CTX_set_input_type() sets the starting input type. This limits the decoder chains to be considered, as explained in the general description above.

- -

OSSL_DECODER_CTX_set_input_structure() sets the name of the structure that the input is expected to have. This may be used to determines what decoder implementations may be used. NULL is a valid input structure, when it's not relevant, or when the decoder implementations are expected to figure it out.

- -

OSSL_DECODER_CTX_get_num_decoders() gets the number of decoders currently added to the context ctx.

- -

OSSL_DECODER_CTX_set_construct() sets the constructor construct.

- -

OSSL_DECODER_CTX_set_construct_data() sets the constructor data that is passed to the constructor every time it's called.

- -

OSSL_DECODER_CTX_set_cleanup() sets the constructor data cleanup function. This is called by OSSL_DECODER_CTX_free(3).

- -

OSSL_DECODER_CTX_get_construct(), OSSL_DECODER_CTX_get_construct_data() and OSSL_DECODER_CTX_get_cleanup() return the values that have been set by OSSL_DECODER_CTX_set_construct(), OSSL_DECODER_CTX_set_construct_data() and OSSL_DECODER_CTX_set_cleanup() respectively.

- -

OSSL_DECODER_export() is a fallback function for constructors that cannot use the data they get directly for diverse reasons. It takes the same decode instance decoder_inst that the constructor got and an object reference, unpacks the object which it refers to, and exports it by creating an OSSL_PARAM(3) array that it then passes to export_cb, along with export_arg.

- -

Constructor

- -

A OSSL_DECODER_CONSTRUCT gets the following arguments:

- -
- -
decoder_inst
-
- -

The OSSL_DECODER_INSTANCE for the decoder from which the constructor gets its data.

- -
-
object
-
- -

A provider-native object abstraction produced by the decoder. Further information on the provider-native object abstraction can be found in provider-object(7).

- -
-
construct_data
-
- -

The pointer that was set with OSSL_DECODE_CTX_set_construct_data().

- -
-
- -

The constructor is expected to return 1 when the data it receives can be constructed, otherwise 0.

- -

These utility functions may be used by a constructor:

- -

OSSL_DECODER_INSTANCE_get_decoder() can be used to get the decoder implementation from a decoder instance decoder_inst.

- -

OSSL_DECODER_INSTANCE_get_decoder_ctx() can be used to get the decoder implementation's provider context from a decoder instance decoder_inst.

- -

OSSL_DECODER_INSTANCE_get_input_type() can be used to get the decoder implementation's input type from a decoder instance decoder_inst.

- -

OSSL_DECODER_INSTANCE_get_input_structure() can be used to get the input structure for the decoder implementation from a decoder instance decoder_inst. This may be NULL.

- -

RETURN VALUES

- -

OSSL_DECODER_CTX_new() returns a pointer to a OSSL_DECODER_CTX, or NULL if the context structure couldn't be allocated.

- -

OSSL_DECODER_settable_ctx_params() returns an OSSL_PARAM(3) array, or NULL if none is available.

- -

OSSL_DECODER_CTX_set_params() returns 1 if all recognised parameters were valid, or 0 if one of them was invalid or caused some other failure in the implementation.

- -

OSSL_DECODER_CTX_add_decoder(), OSSL_DECODER_CTX_add_extra(), OSSL_DECODER_CTX_set_construct(), OSSL_DECODER_CTX_set_construct_data() and OSSL_DECODER_CTX_set_cleanup() return 1 on success, or 0 on failure.

- -

OSSL_DECODER_CTX_get_construct(), OSSL_DECODER_CTX_get_construct_data() and OSSL_DECODER_CTX_get_cleanup() return the current pointers to the constructor, the constructor data and the cleanup functions, respectively.

- -

OSSL_DECODER_CTX_num_decoders() returns the current number of decoders. It returns 0 if ctx is NULL.

- -

OSSL_DECODER_export() returns 1 on success, or 0 on failure.

- -

OSSL_DECODER_INSTANCE_decoder() returns an OSSL_DECODER pointer on success, or NULL on failure.

- -

OSSL_DECODER_INSTANCE_decoder_ctx() returns a provider context pointer on success, or NULL on failure.

- -

SEE ALSO

- -

provider(7), OSSL_DECODER(3), OSSL_DECODER_from_bio(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX_new_for_pkey.html b/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX_new_for_pkey.html deleted file mode 100644 index 0ab9e452..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_CTX_new_for_pkey.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -OSSL_DECODER_CTX_new_for_pkey - - - - - - - - - - -

NAME

- -

OSSL_DECODER_CTX_new_for_pkey, OSSL_DECODER_CTX_set_passphrase, OSSL_DECODER_CTX_set_pem_password_cb, OSSL_DECODER_CTX_set_passphrase_ui, OSSL_DECODER_CTX_set_passphrase_cb - Decoder routines to decode EVP_PKEYs

- -

SYNOPSIS

- -
#include <openssl/decoder.h>
-
-OSSL_DECODER_CTX *
-OSSL_DECODER_CTX_new_for_pkey(EVP_PKEY **pkey,
-                              const char *input_type,
-                              const char *input_struct,
-                              const char *keytype, int selection,
-                              OSSL_LIB_CTX *libctx, const char *propquery);
-
-int OSSL_DECODER_CTX_set_passphrase(OSSL_DECODER_CTX *ctx,
-                                    const unsigned char *kstr,
-                                    size_t klen);
-int OSSL_DECODER_CTX_set_pem_password_cb(OSSL_DECODER_CTX *ctx,
-                                         pem_password_cb *cb,
-                                         void *cbarg);
-int OSSL_DECODER_CTX_set_passphrase_ui(OSSL_DECODER_CTX *ctx,
-                                       const UI_METHOD *ui_method,
-                                       void *ui_data);
-int OSSL_DECODER_CTX_set_passphrase_cb(OSSL_DECODER_CTX *ctx,
-                                       OSSL_PASSPHRASE_CALLBACK *cb,
-                                       void *cbarg);
- -

DESCRIPTION

- -

OSSL_DECODER_CTX_new_for_pkey() is a utility function that creates a OSSL_DECODER_CTX, finds all applicable decoder implementations and sets them up, so all the caller has to do next is call functions like OSSL_DECODER_from_bio(3). The caller may use the optional input_type, input_struct, keytype and selection to specify what the input is expected to contain. The pkey must reference an EVP_PKEY * variable that will be set to the newly created EVP_PKEY on successful decoding. The referenced variable must be initialized to NULL before calling the function.

- -

Internally OSSL_DECODER_CTX_new_for_pkey() searches for all available EVP_KEYMGMT(3) implementations, and then builds a list of all potential decoder implementations that may be able to process the encoded input into data suitable for EVP_PKEYs. All these implementations are implicitly fetched using libctx and propquery.

- -

The search of decoder implementations can be limited with input_type and input_struct which specifies a starting input type and input structure. NULL is valid for both of them and signifies that the decoder implementations will find out the input type on their own. They are set with OSSL_DECODER_CTX_set_input_type(3) and OSSL_DECODER_CTX_set_input_structure(3). See "Input Types" and "Input Structures" below for further information.

- -

The search of decoder implementations can also be limited with keytype and selection, which specifies the expected resulting keytype and contents. NULL and zero are valid and signify that the decoder implementations will find out the keytype and key contents on their own from the input they get.

- -

If no suitable decoder implementation is found, OSSL_DECODER_CTX_new_for_pkey() still creates a OSSL_DECODER_CTX, but with no associated decoder (OSSL_DECODER_CTX_get_num_decoders(3) returns zero). This helps the caller to distinguish between an error when creating the OSSL_ENCODER_CTX and missing encoder implementation, and allows it to act accordingly.

- -

OSSL_DECODER_CTX_set_passphrase() gives the implementation a pass phrase to use when decrypting the encoded private key. Alternatively, a pass phrase callback may be specified with the following functions.

- -

OSSL_DECODER_CTX_set_pem_password_cb(), OSSL_DECODER_CTX_set_passphrase_ui() and OSSL_DECODER_CTX_set_passphrase_cb() set up a callback method that the implementation can use to prompt for a pass phrase, giving the caller the choice of preferred pass phrase callback form. These are called indirectly, through an internal OSSL_PASSPHRASE_CALLBACK(3) function.

- -

The internal OSSL_PASSPHRASE_CALLBACK(3) function caches the pass phrase, to be reused in all decodings that are performed in the same decoding run (for example, within one OSSL_DECODER_from_bio(3) call).

- -

Input Types

- -

Available input types depend on the implementations that available providers offer, and provider documentation should have the details.

- -

Among the known input types that OpenSSL decoder implementations offer for EVP_PKEYs are DER, PEM, MSBLOB and PVK. See openssl-glossary(7) for further information on what these input types mean.

- -

Input Structures

- -

Available input structures depend on the implementations that available providers offer, and provider documentation should have the details.

- -

Among the known input structures that OpenSSL decoder implementations offer for EVP_PKEYs are pkcs8 and SubjectPublicKeyInfo.

- -

OpenSSL decoder implementations also support the input structure type-specific. This is the structure used for keys encoded according to key type specific specifications. For example, RSA keys encoded according to PKCS#1.

- -

Selections

- -

selection can be any one of the values described in "Selections" in EVP_PKEY_fromdata(3). Additionally selection can also be set to 0 to indicate that the code will auto detect the selection.

- -

RETURN VALUES

- -

OSSL_DECODER_CTX_new_for_pkey() returns a pointer to a OSSL_DECODER_CTX, or NULL if it couldn't be created.

- -

OSSL_DECODER_CTX_set_passphrase(), OSSL_DECODER_CTX_set_pem_password_cb(), OSSL_DECODER_CTX_set_passphrase_ui() and OSSL_DECODER_CTX_set_passphrase_cb() all return 1 on success, or 0 on failure.

- -

SEE ALSO

- -

provider(7), OSSL_DECODER(3), OSSL_DECODER_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_from_bio.html b/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_from_bio.html deleted file mode 100644 index 8abb66ba..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_DECODER_from_bio.html +++ /dev/null @@ -1,134 +0,0 @@ - - - - -OSSL_DECODER_from_bio - - - - - - - - - - -

NAME

- -

OSSL_DECODER_from_data, OSSL_DECODER_from_bio, OSSL_DECODER_from_fp - Routines to perform a decoding

- -

SYNOPSIS

- -
#include <openssl/decoder.h>
-
-int OSSL_DECODER_from_bio(OSSL_DECODER_CTX *ctx, BIO *in);
-int OSSL_DECODER_from_fp(OSSL_DECODER_CTX *ctx, FILE *fp);
-int OSSL_DECODER_from_data(OSSL_DECODER_CTX *ctx, const unsigned char **pdata,
-                           size_t *pdata_len);
- -

Feature availability macros:

- -
- -
OSSL_DECODER_from_fp() is only available when OPENSSL_NO_STDIO is undefined.
-
- -
-
- -

DESCRIPTION

- -

OSSL_DECODER_from_data() runs the decoding process for the context ctx, with input coming from *pdata, *pdata_len bytes long. Both *pdata and *pdata_len must be non-NULL. When OSSL_DECODER_from_data() returns, *pdata is updated to point at the location after what has been decoded, and *pdata_len to have the number of remaining bytes.

- -

OSSL_DECODER_from_bio() runs the decoding process for the context ctx, with the input coming from the BIO in. Should it make a difference, it's recommended to have the BIO set in binary mode rather than text mode.

- -

OSSL_DECODER_from_fp() does the same thing as OSSL_DECODER_from_bio(), except that the input is coming from the FILE fp.

- -

RETURN VALUES

- -

OSSL_DECODER_from_bio(), OSSL_DECODER_from_data() and OSSL_DECODER_from_fp() return 1 on success, or 0 on failure.

- -

EXAMPLES

- -

To decode an RSA key encoded with PEM from a bio:

- -
OSSL_DECODER_CTX *dctx;
-EVP_PKEY *pkey = NULL;
-const char *format = "PEM";   /* NULL for any format */
-const char *structure = NULL; /* any structure */
-const char *keytype = "RSA";  /* NULL for any key */
-const unsigned char *pass = "my password";
-
-dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, format, structure,
-                                     keytype,
-                                     OSSL_KEYMGMT_SELECT_KEYPAIR,
-                                     NULL, NULL);
-if (dctx == NULL) {
-    /* error: no suitable potential decoders found */
-}
-if (pass != NULL)
-    OSSL_DECODER_CTX_set_passphrase(dctx, pass, strlen(pass));
-if (OSSL_DECODER_from_bio(dctx, bio)) {
-    /* pkey is created with the decoded data from the bio */
-} else {
-    /* decoding failure */
-}
-OSSL_DECODER_CTX_free(dctx);
- -

To decode an EC key encoded with DER from a buffer:

- -
OSSL_DECODER_CTX *dctx;
-EVP_PKEY *pkey = NULL;
-const char *format = "DER";   /* NULL for any format */
-const char *structure = NULL; /* any structure */
-const char *keytype = "EC";   /* NULL for any key */
-const unsigned char *pass = NULL
-const unsigned char *data = buffer;
-size_t datalen = sizeof(buffer);
-
-dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, format, structure,
-                                     keytype,
-                                     OSSL_KEYMGMT_SELECT_KEYPAIR
-                                     | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
-                                     NULL, NULL);
-if (dctx == NULL) {
-    /* error: no suitable potential decoders found */
-}
-if (pass != NULL)
-    OSSL_DECODER_CTX_set_passphrase(dctx, pass, strlen(pass));
-if (OSSL_DECODER_from_data(dctx, &data, &datalen)) {
-    /* pkey is created with the decoded data from the buffer */
-} else {
-    /* decoding failure */
-}
-OSSL_DECODER_CTX_free(dctx);
- -

SEE ALSO

- -

provider(7), OSSL_DECODER_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_DISPATCH.html b/openssl-install/share/doc/openssl/html/man3/OSSL_DISPATCH.html deleted file mode 100644 index 5d9ba203..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_DISPATCH.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -OSSL_DISPATCH - - - - - - - - - - -

NAME

- -

OSSL_DISPATCH, OSSL_DISPATCH_END - OpenSSL Core type to define a dispatchable function table

- -

SYNOPSIS

- -
#include <openssl/core.h>
-
-typedef struct ossl_dispatch_st OSSL_DISPATCH;
-struct ossl_dispatch_st {
-    int function_id;
-    void (*function)(void);
-};
-
-#define OSSL_DISPATCH_END
- -

DESCRIPTION

- -

This type is a tuple of function identity and function pointer. Arrays of this type are passed between the OpenSSL libraries and the providers to describe what functionality one side provides to the other.

- -

Arrays of this type must be terminated with the OSSL_DISPATCH_END macro.

- -

OSSL_DISPATCH fields

- -
- -
function_id
-
- -

OpenSSL defined function identity of the implemented function.

- -
-
function
-
- -

Pointer to the implemented function itself. Despite the generic definition of this field, the implemented function it points to must have a function signature that corresponds to the function_id

- -
-
- -

Available function identities and corresponding function signatures are defined in openssl-core_dispatch.h(7). Furthermore, the chosen function identities and associated function signature must be chosen specifically for the operation that it's intended for, as determined by the intended OSSL_ALGORITHM(3) array.

- -

Any function identity not recognised by the recipient of this type will be ignored. This ensures that providers built with one OpenSSL version in mind will work together with any other OpenSSL version that supports this mechanism.

- -

SEE ALSO

- -

crypto(7), openssl-core_dispatch.h(7), OSSL_ALGORITHM(3)

- -

HISTORY

- -

OSSL_DISPATCH was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER.html deleted file mode 100644 index 8c392047..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -OSSL_ENCODER - - - - - - - - - - -

NAME

- -

OSSL_ENCODER, OSSL_ENCODER_fetch, OSSL_ENCODER_up_ref, OSSL_ENCODER_free, OSSL_ENCODER_get0_provider, OSSL_ENCODER_get0_properties, OSSL_ENCODER_is_a, OSSL_ENCODER_get0_name, OSSL_ENCODER_get0_description, OSSL_ENCODER_do_all_provided, OSSL_ENCODER_names_do_all, OSSL_ENCODER_gettable_params, OSSL_ENCODER_get_params - Encoder method routines

- -

SYNOPSIS

- -
#include <openssl/encoder.h>
-
-typedef struct ossl_encoder_st OSSL_ENCODER;
-
-OSSL_ENCODER *OSSL_ENCODER_fetch(OSSL_LIB_CTX *ctx, const char *name,
-                                 const char *properties);
-int OSSL_ENCODER_up_ref(OSSL_ENCODER *encoder);
-void OSSL_ENCODER_free(OSSL_ENCODER *encoder);
-const OSSL_PROVIDER *OSSL_ENCODER_get0_provider(const OSSL_ENCODER *encoder);
-const char *OSSL_ENCODER_get0_properties(const OSSL_ENCODER *encoder);
-int OSSL_ENCODER_is_a(const OSSL_ENCODER *encoder, const char *name);
-const char *OSSL_ENCODER_get0_name(const OSSL_ENCODER *encoder);
-const char *OSSL_ENCODER_get0_description(const OSSL_ENCODER *encoder);
-void OSSL_ENCODER_do_all_provided(OSSL_LIB_CTX *libctx,
-                                  void (*fn)(OSSL_ENCODER *encoder, void *arg),
-                                  void *arg);
-int OSSL_ENCODER_names_do_all(const OSSL_ENCODER *encoder,
-                              void (*fn)(const char *name, void *data),
-                              void *data);
-const OSSL_PARAM *OSSL_ENCODER_gettable_params(OSSL_ENCODER *encoder);
-int OSSL_ENCODER_get_params(OSSL_ENCODER_CTX *ctx, const OSSL_PARAM params[]);
- -

DESCRIPTION

- -

OSSL_ENCODER is a method for encoders, which know how to encode an object of some kind to a encoded form, such as PEM, DER, or even human readable text.

- -

OSSL_ENCODER_fetch() looks for an algorithm within the provider that has been loaded into the OSSL_LIB_CTX given by ctx, having the name given by name and the properties given by properties. The name determines what type of object the fetched encoder method is expected to be able to encode, and the properties are used to determine the expected output type. For known properties and the values they may have, please have a look in "Names and properties" in provider-encoder(7).

- -

OSSL_ENCODER_up_ref() increments the reference count for the given encoder.

- -

OSSL_ENCODER_free() decrements the reference count for the given encoder, and when the count reaches zero, frees it. If the argument is NULL, nothing is done.

- -

OSSL_ENCODER_get0_provider() returns the provider of the given encoder.

- -

OSSL_ENCODER_get0_properties() returns the property definition associated with the given encoder.

- -

OSSL_ENCODER_is_a() checks if encoder is an implementation of an algorithm that's identifiable with name.

- -

OSSL_ENCODER_get0_name() returns the name used to fetch the given encoder.

- -

OSSL_ENCODER_get0_description() returns a description of the loader, meant for display and human consumption. The description is at the discretion of the loader implementation.

- -

OSSL_ENCODER_names_do_all() traverses all names for the given encoder, and calls fn with each name and data as arguments.

- -

OSSL_ENCODER_do_all_provided() traverses all encoder implementations by all activated providers in the library context libctx, and for each of the implementations, calls fn with the implementation method and arg as arguments.

- -

OSSL_ENCODER_gettable_params() returns an OSSL_PARAM(3) array of parameter descriptors.

- -

OSSL_ENCODER_get_params() attempts to get parameters specified with an OSSL_PARAM(3) array params. Parameters that the implementation doesn't recognise should be ignored.

- -

RETURN VALUES

- -

OSSL_ENCODER_fetch() returns a pointer to the key management implementation represented by an OSSL_ENCODER object, or NULL on error.

- -

OSSL_ENCODER_up_ref() returns 1 on success, or 0 on error.

- -

OSSL_ENCODER_free() doesn't return any value.

- -

OSSL_ENCODER_get0_provider() returns a pointer to a provider object, or NULL on error.

- -

OSSL_ENCODER_get0_properties() returns a pointer to a property definition string, or NULL on error.

- -

OSSL_ENCODER_is_a() returns 1 of encoder was identifiable, otherwise 0.

- -

OSSL_ENCODER_get0_name() returns the algorithm name from the provided implementation for the given encoder. Note that the encoder may have multiple synonyms associated with it. In this case the first name from the algorithm definition is returned. Ownership of the returned string is retained by the encoder object and should not be freed by the caller.

- -

OSSL_ENCODER_get0_description() returns a pointer to a description, or NULL if there isn't one.

- -

OSSL_ENCODER_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

SEE ALSO

- -

provider(7), OSSL_ENCODER_CTX(3), OSSL_ENCODER_to_bio(3), OSSL_ENCODER_CTX_new_for_pkey(3), OSSL_LIB_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX.html deleted file mode 100644 index 48342529..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX.html +++ /dev/null @@ -1,186 +0,0 @@ - - - - -OSSL_ENCODER_CTX - - - - - - - - - - -

NAME

- -

OSSL_ENCODER_CTX, OSSL_ENCODER_CTX_new, OSSL_ENCODER_settable_ctx_params, OSSL_ENCODER_CTX_set_params, OSSL_ENCODER_CTX_free, OSSL_ENCODER_CTX_set_selection, OSSL_ENCODER_CTX_set_output_type, OSSL_ENCODER_CTX_set_output_structure, OSSL_ENCODER_CTX_add_encoder, OSSL_ENCODER_CTX_add_extra, OSSL_ENCODER_CTX_get_num_encoders, OSSL_ENCODER_INSTANCE, OSSL_ENCODER_INSTANCE_get_encoder, OSSL_ENCODER_INSTANCE_get_encoder_ctx, OSSL_ENCODER_INSTANCE_get_output_type, OSSL_ENCODER_INSTANCE_get_output_structure, OSSL_ENCODER_CONSTRUCT, OSSL_ENCODER_CLEANUP, OSSL_ENCODER_CTX_set_construct, OSSL_ENCODER_CTX_set_construct_data, OSSL_ENCODER_CTX_set_cleanup - Encoder context routines

- -

SYNOPSIS

- -
#include <openssl/encoder.h>
-
-typedef struct ossl_encoder_ctx_st OSSL_ENCODER_CTX;
-
-OSSL_ENCODER_CTX *OSSL_ENCODER_CTX_new();
-const OSSL_PARAM *OSSL_ENCODER_settable_ctx_params(OSSL_ENCODER *encoder);
-int OSSL_ENCODER_CTX_set_params(OSSL_ENCODER_CTX *ctx,
-                                const OSSL_PARAM params[]);
-void OSSL_ENCODER_CTX_free(OSSL_ENCODER_CTX *ctx);
-
-int OSSL_ENCODER_CTX_set_selection(OSSL_ENCODER_CTX *ctx, int selection);
-int OSSL_ENCODER_CTX_set_output_type(OSSL_ENCODER_CTX *ctx,
-                                     const char *output_type);
-int OSSL_ENCODER_CTX_set_output_structure(OSSL_ENCODER_CTX *ctx,
-                                          const char *output_structure);
-
-int OSSL_ENCODER_CTX_add_encoder(OSSL_ENCODER_CTX *ctx, OSSL_ENCODER *encoder);
-int OSSL_ENCODER_CTX_add_extra(OSSL_ENCODER_CTX *ctx,
-                               OSSL_LIB_CTX *libctx, const char *propq);
-int OSSL_ENCODER_CTX_get_num_encoders(OSSL_ENCODER_CTX *ctx);
-
-typedef struct ossl_encoder_instance_st OSSL_ENCODER_INSTANCE;
-OSSL_ENCODER *
-OSSL_ENCODER_INSTANCE_get_encoder(OSSL_ENCODER_INSTANCE *encoder_inst);
-void *
-OSSL_ENCODER_INSTANCE_get_encoder_ctx(OSSL_ENCODER_INSTANCE *encoder_inst);
-const char *
-OSSL_ENCODER_INSTANCE_get_output_type(OSSL_ENCODER_INSTANCE *encoder_inst);
-const char *
-OSSL_ENCODER_INSTANCE_get_output_structure(OSSL_ENCODER_INSTANCE *encoder_inst);
-
-typedef const void *OSSL_ENCODER_CONSTRUCT(OSSL_ENCODER_INSTANCE *encoder_inst,
-                                           void *construct_data);
-typedef void OSSL_ENCODER_CLEANUP(void *construct_data);
-
-int OSSL_ENCODER_CTX_set_construct(OSSL_ENCODER_CTX *ctx,
-                                   OSSL_ENCODER_CONSTRUCT *construct);
-int OSSL_ENCODER_CTX_set_construct_data(OSSL_ENCODER_CTX *ctx,
-                                        void *construct_data);
-int OSSL_ENCODER_CTX_set_cleanup(OSSL_ENCODER_CTX *ctx,
-                                 OSSL_ENCODER_CLEANUP *cleanup);
- -

DESCRIPTION

- -

Encoding an input object to the desired encoding may be done with a chain of encoder implementations, which means that the output from one encoder may be the input for the next in the chain. The OSSL_ENCODER_CTX holds all the data about these encoders. This allows having generic format encoders such as DER to PEM, as well as more specialized encoders like RSA to DER.

- -

The final output type must be given, and a chain of encoders must end with an implementation that produces that output type.

- -

At the beginning of the encoding process, a constructor provided by the caller is called to ensure that there is an appropriate provider-side object to start with. The constructor is set with OSSL_ENCODER_CTX_set_construct().

- -

OSSL_ENCODER_INSTANCE is an opaque structure that contains data about the encoder that is going to be used, and that may be useful for the constructor. There are some functions to extract data from this type, described in "Constructor" below.

- -

Functions

- -

OSSL_ENCODER_CTX_new() creates a OSSL_ENCODER_CTX.

- -

OSSL_ENCODER_settable_ctx_params() returns an OSSL_PARAM(3) array of parameter descriptors.

- -

OSSL_ENCODER_CTX_set_params() attempts to set parameters specified with an OSSL_PARAM(3) array params. Parameters that the implementation doesn't recognise should be ignored.

- -

OSSL_ENCODER_CTX_free() frees the given context ctx. If the argument is NULL, nothing is done.

- -

OSSL_ENCODER_CTX_add_encoder() populates the OSSL_ENCODER_CTX ctx with a encoder, to be used to encode an input object.

- -

OSSL_ENCODER_CTX_add_extra() finds encoders that further encodes output from already added encoders, and adds them as well. This is used to build encoder chains.

- -

OSSL_ENCODER_CTX_set_output_type() sets the ending output type. This must be specified, and determines if a complete encoder chain is available.

- -

OSSL_ENCODER_CTX_set_output_structure() sets the desired output structure. This may be used to determines what encoder implementations may be used. Depending on the type of object being encoded, the output structure may not be relevant.

- -

OSSL_ENCODER_CTX_get_num_encoders() gets the number of encoders currently added to the context ctx.

- -

OSSL_ENCODER_CTX_set_construct() sets the constructor construct.

- -

OSSL_ENCODER_CTX_set_construct_data() sets the constructor data that is passed to the constructor every time it's called.

- -

OSSL_ENCODER_CTX_set_cleanup() sets the constructor data cleanup function. This is called by OSSL_ENCODER_CTX_free(3).

- -

Constructor

- -

A OSSL_ENCODER_CONSTRUCT gets the following arguments:

- -
- -
encoder_inst
-
- -

The OSSL_ENCODER_INSTANCE for the encoder from which the constructor gets its data.

- -
-
construct_data
-
- -

The pointer that was set with OSSL_ENCODE_CTX_set_construct_data().

- -
-
- -

The constructor is expected to return a valid (non-NULL) pointer to a provider-native object that can be used as first input of an encoding chain, or NULL to indicate that an error has occurred.

- -

These utility functions may be used by a constructor:

- -

OSSL_ENCODER_INSTANCE_get_encoder() can be used to get the encoder implementation of the encoder instance encoder_inst.

- -

OSSL_ENCODER_INSTANCE_get_encoder_ctx() can be used to get the encoder implementation's provider context of the encoder instance encoder_inst.

- -

OSSL_ENCODER_INSTANCE_get_output_type() can be used to get the output type for the encoder implementation of the encoder instance encoder_inst. This will never be NULL.

- -

OSSL_ENCODER_INSTANCE_get_output_structure() can be used to get the output structure for the encoder implementation of the encoder instance encoder_inst. This may be NULL.

- -

RETURN VALUES

- -

OSSL_ENCODER_CTX_new() returns a pointer to a OSSL_ENCODER_CTX, or NULL if the context structure couldn't be allocated.

- -

OSSL_ENCODER_settable_ctx_params() returns an OSSL_PARAM(3) array, or NULL if none is available.

- -

OSSL_ENCODER_CTX_set_params() returns 1 if all recognised parameters were valid, or 0 if one of them was invalid or caused some other failure in the implementation.

- -

OSSL_ENCODER_CTX_add_encoder(), OSSL_ENCODER_CTX_add_extra(), OSSL_ENCODER_CTX_set_construct(), OSSL_ENCODER_CTX_set_construct_data() and OSSL_ENCODER_CTX_set_cleanup() return 1 on success, or 0 on failure.

- -

OSSL_ENCODER_CTX_get_num_encoders() returns the current number of encoders. It returns 0 if ctx is NULL.

- -

OSSL_ENCODER_INSTANCE_get_encoder() returns an OSSL_ENCODER pointer on success, or NULL on failure.

- -

OSSL_ENCODER_INSTANCE_get_encoder_ctx() returns a provider context pointer on success, or NULL on failure.

- -

OSSL_ENCODER_INSTANCE_get_output_type() returns a string with the name of the input type, if relevant. NULL is a valid returned value.

- -

OSSL_ENCODER_INSTANCE_get_output_type() returns a string with the name of the output type.

- -

OSSL_ENCODER_INSTANCE_get_output_structure() returns a string with the name of the output structure.

- -

SEE ALSO

- -

provider(7), OSSL_ENCODER(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX_new_for_pkey.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX_new_for_pkey.html deleted file mode 100644 index 510a5dcf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_CTX_new_for_pkey.html +++ /dev/null @@ -1,131 +0,0 @@ - - - - -OSSL_ENCODER_CTX_new_for_pkey - - - - - - - - - - -

NAME

- -

OSSL_ENCODER_CTX_new_for_pkey, OSSL_ENCODER_CTX_set_cipher, OSSL_ENCODER_CTX_set_passphrase, OSSL_ENCODER_CTX_set_pem_password_cb, OSSL_ENCODER_CTX_set_passphrase_cb, OSSL_ENCODER_CTX_set_passphrase_ui - Encoder routines to encode EVP_PKEYs

- -

SYNOPSIS

- -
#include <openssl/encoder.h>
-
-OSSL_ENCODER_CTX *
-OSSL_ENCODER_CTX_new_for_pkey(const EVP_PKEY *pkey, int selection,
-                              const char *output_type,
-                              const char *output_structure,
-                              const char *propquery);
-
-int OSSL_ENCODER_CTX_set_cipher(OSSL_ENCODER_CTX *ctx,
-                                const char *cipher_name,
-                                const char *propquery);
-int OSSL_ENCODER_CTX_set_passphrase(OSSL_ENCODER_CTX *ctx,
-                                    const unsigned char *kstr,
-                                    size_t klen);
-int OSSL_ENCODER_CTX_set_pem_password_cb(OSSL_ENCODER_CTX *ctx,
-                                         pem_password_cb *cb, void *cbarg);
-int OSSL_ENCODER_CTX_set_passphrase_ui(OSSL_ENCODER_CTX *ctx,
-                                       const UI_METHOD *ui_method,
-                                       void *ui_data);
-int OSSL_ENCODER_CTX_set_passphrase_cb(OSSL_ENCODER_CTX *ctx,
-                                       OSSL_PASSPHRASE_CALLBACK *cb,
-                                       void *cbarg);
- -

DESCRIPTION

- -

OSSL_ENCODER_CTX_new_for_pkey() is a utility function that creates a OSSL_ENCODER_CTX, finds all applicable encoder implementations and sets them up, so almost all the caller has to do next is call functions like OSSL_ENCODER_to_bio(3). output_type determines the final output encoding, and selection can be used to select what parts of the pkey should be included in the output. output_type is further discussed in "Output types" below, and selection is further described in "Selections".

- -

Internally, OSSL_ENCODER_CTX_new_for_pkey() uses the names from the EVP_KEYMGMT(3) implementation associated with pkey to build a list of applicable encoder implementations that are used to process the pkey into the encoding named by output_type, with the outermost structure named by output_structure if that's relevant. All these implementations are implicitly fetched, with propquery for finer selection.

- -

If no suitable encoder implementation is found, OSSL_ENCODER_CTX_new_for_pkey() still creates a OSSL_ENCODER_CTX, but with no associated encoder (OSSL_ENCODER_CTX_get_num_encoders(3) returns zero). This helps the caller to distinguish between an error when creating the OSSL_ENCODER_CTX and missing encoder implementation, and allows it to act accordingly.

- -

OSSL_ENCODER_CTX_set_cipher() tells the implementation what cipher should be used to encrypt encoded keys. The cipher is given by name cipher_name. The interpretation of that cipher_name is implementation dependent. The implementation may implement the cipher directly itself or by other implementations, or it may choose to fetch it. If the implementation supports fetching the cipher, then it may use propquery as properties to be queried for when fetching. cipher_name may also be NULL, which will result in unencrypted encoding.

- -

OSSL_ENCODER_CTX_set_passphrase() gives the implementation a pass phrase to use when encrypting the encoded private key. Alternatively, a pass phrase callback may be specified with the following functions.

- -

OSSL_ENCODER_CTX_set_pem_password_cb(), OSSL_ENCODER_CTX_set_passphrase_ui() and OSSL_ENCODER_CTX_set_passphrase_cb() sets up a callback method that the implementation can use to prompt for a pass phrase, giving the caller the choice of preferred pass phrase callback form. These are called indirectly, through an internal OSSL_PASSPHRASE_CALLBACK(3) function.

- -

Output types

- -

The possible EVP_PKEY output types depends on the available implementations.

- -

OpenSSL has built in implementations for the following output types:

- -
- -
TEXT
-
- -

The output is a human readable description of the key. EVP_PKEY_print_private(3), EVP_PKEY_print_public(3) and EVP_PKEY_print_params(3) use this for their output.

- -
-
DER
-
- -

The output is the DER encoding of the selection of the pkey.

- -
-
PEM
-
- -

The output is the selection of the pkey in PEM format.

- -
-
- -

Selections

- -

selection can be any one of the values described in "Selections" in EVP_PKEY_fromdata(3).

- -

These are only 'hints' since the encoder implementations are free to determine what makes sense to include in the output, and this may depend on the desired output. For example, an EC key in a PKCS#8 structure doesn't usually include the public key.

- -

RETURN VALUES

- -

OSSL_ENCODER_CTX_new_for_pkey() returns a pointer to an OSSL_ENCODER_CTX, or NULL if it couldn't be created.

- -

OSSL_ENCODER_CTX_set_cipher(), OSSL_ENCODER_CTX_set_passphrase(), OSSL_ENCODER_CTX_set_pem_password_cb(), OSSL_ENCODER_CTX_set_passphrase_ui() and OSSL_ENCODER_CTX_set_passphrase_cb() all return 1 on success, or 0 on failure.

- -

SEE ALSO

- -

provider(7), OSSL_ENCODER(3), OSSL_ENCODER_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_to_bio.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_to_bio.html deleted file mode 100644 index 3578289e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ENCODER_to_bio.html +++ /dev/null @@ -1,138 +0,0 @@ - - - - -OSSL_ENCODER_to_bio - - - - - - - - - - -

NAME

- -

OSSL_ENCODER_to_data, OSSL_ENCODER_to_bio, OSSL_ENCODER_to_fp - Routines to perform an encoding

- -

SYNOPSIS

- -
#include <openssl/encoder.h>
-
-int OSSL_ENCODER_to_data(OSSL_ENCODER_CTX *ctx, unsigned char **pdata,
-                         size_t *pdata_len);
-int OSSL_ENCODER_to_bio(OSSL_ENCODER_CTX *ctx, BIO *out);
-int OSSL_ENCODER_to_fp(OSSL_ENCODER_CTX *ctx, FILE *fp);
- -

Feature availability macros:

- -
- -
OSSL_ENCODER_to_fp() is only available when OPENSSL_NO_STDIO is undefined.
-
- -
-
- -

DESCRIPTION

- -

OSSL_ENCODER_to_data() runs the encoding process for the context ctx, with the output going to the *pdata and *pdata_len. If *pdata is NULL when OSSL_ENCODER_to_data() is called, a buffer will be allocated using OPENSSL_zalloc(3), and *pdata will be set to point at the start of that buffer, and *pdata_len will be assigned its length when OSSL_ENCODER_to_data() returns. If *pdata is non-NULL when OSSL_ENCODER_to_data() is called, *pdata_len is assumed to have its size. In this case, *pdata will be set to point after the encoded bytes, and *pdata_len will be assigned the number of remaining bytes.

- -

OSSL_ENCODER_to_bio() runs the encoding process for the context ctx, with the output going to the BIO out.

- -

OSSL_ENCODER_to_fp() does the same thing as OSSL_ENCODER_to_bio(), except that the output is going to the FILE fp.

- -

For OSSL_ENCODER_to_bio() and OSSL_ENCODER_to_fp(), the application is required to set up the BIO or FILE properly, for example to have it in text or binary mode as is appropriate for the encoder output type.

- -

RETURN VALUES

- -

OSSL_ENCODER_to_bio(), OSSL_ENCODER_to_fp() and OSSL_ENCODER_to_data() return 1 on success, or 0 on failure.

- -

EXAMPLES

- -

To encode a pkey as PKCS#8 with PEM format into a bio:

- -
OSSL_ENCODER_CTX *ectx;
-const char *format = "PEM";
-const char *structure = "PrivateKeyInfo"; /* PKCS#8 structure */
-const unsigned char *pass = "my password";
-
-ectx = OSSL_ENCODER_CTX_new_for_pkey(pkey,
-                                     OSSL_KEYMGMT_SELECT_KEYPAIR
-                                     | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
-                                     format, structure,
-                                     NULL);
-if (ectx == NULL) {
-    /* error: no suitable potential encoders found */
-}
-if (pass != NULL)
-    OSSL_ENCODER_CTX_set_passphrase(ectx, pass, strlen(pass));
-if (OSSL_ENCODER_to_bio(ectx, bio)) {
-    /* pkey was successfully encoded into the bio */
-} else {
-    /* encoding failure */
-}
-OSSL_ENCODER_CTX_free(ectx);
- -

To encode a pkey as PKCS#8 with DER format encrypted with AES-256-CBC into a buffer:

- -
OSSL_ENCODER_CTX *ectx;
-const char *format = "DER";
-const char *structure = "PrivateKeyInfo"; /* PKCS#8 structure */
-const unsigned char *pass = "my password";
-unsigned char *data = NULL;
-size_t datalen;
-
-ectx = OSSL_ENCODER_CTX_new_for_pkey(pkey,
-                                     OSSL_KEYMGMT_SELECT_KEYPAIR
-                                     | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
-                                     format, structure,
-                                     NULL);
-if (ectx == NULL) {
-    /* error: no suitable potential encoders found */
-}
-if (pass != NULL) {
-    OSSL_ENCODER_CTX_set_passphrase(ectx, pass, strlen(pass));
-    OSSL_ENCODER_CTX_set_cipher(ctx, "AES-256-CBC", NULL);
-}
-if (OSSL_ENCODER_to_data(ectx, &data, &datalen)) {
-    /*
-     * pkey was successfully encoded into a newly allocated
-     * data buffer
-     */
-} else {
-    /* encoding failure */
-}
-OSSL_ENCODER_CTX_free(ectx);
- -

SEE ALSO

- -

provider(7), OSSL_ENCODER_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ERR_STATE_save.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ERR_STATE_save.html deleted file mode 100644 index d6f6b9b9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ERR_STATE_save.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -OSSL_ERR_STATE_save - - - - - - - - - - -

NAME

- -

OSSL_ERR_STATE_new, OSSL_ERR_STATE_save, OSSL_ERR_STATE_save_to_mark, OSSL_ERR_STATE_restore, OSSL_ERR_STATE_free - saving and restoring error state

- -

SYNOPSIS

- -
#include <openssl/err.h>
-
-ERR_STATE *OSSL_ERR_STATE_new(void);
-void OSSL_ERR_STATE_save(ERR_STATE *es);
-void OSSL_ERR_STATE_save_to_mark(ERR_STATE *es);
-void OSSL_ERR_STATE_restore(const ERR_STATE *es);
-void OSSL_ERR_STATE_free(ERR_STATE *es);
- -

DESCRIPTION

- -

These functions save and restore the error state from the thread local error state to a preallocated error state structure.

- -

OSSL_ERR_STATE_new() allocates an empty error state structure to be used when saving and restoring thread error state.

- -

OSSL_ERR_STATE_save() saves the thread error state to es. It subsequently clears the thread error state. Any previously saved state in es is cleared prior to saving the new state.

- -

OSSL_ERR_STATE_save_to_mark() is similar to OSSL_ERR_STATE_save() but only saves ERR entries up to the most recent mark on the ERR stack. These entries are moved to es and removed from the thread error state. However, the most recent marked ERR and any ERR state before it remains part of the thread error state and is not moved to the ERR_STATE. The mark is not cleared and must be cleared explicitly after a call to this function using ERR_pop_to_mark(3) or ERR_clear_last_mark(3). (Since a call to OSSL_ERR_STATE_save_to_mark() leaves the marked ERR as the top error, either of these functions will have the same effect.) If there is no marked ERR in the thread local error state, all ERR entries are copied and the effect is the same as for a call to OSSL_ERR_STATE_save().

- -

OSSL_ERR_STATE_restore() adds all the error entries from the saved state es to the thread error state. Existing entries in the thread error state are not affected if there is enough space for all the added entries. Any allocated data in the saved error entries is duplicated on adding to the thread state.

- -

OSSL_ERR_STATE_free() frees the saved error state es. If the argument is NULL, nothing is done.

- -

RETURN VALUES

- -

OSSL_ERR_STATE_new() returns a pointer to the allocated ERR_STATE structure or NULL on error.

- -

OSSL_ERR_STATE_save(), OSSL_ERR_STATE_save_to_mark(), OSSL_ERR_STATE_restore(), OSSL_ERR_STATE_free() do not return any values.

- -

NOTES

- -

OSSL_ERR_STATE_save() and OSSL_ERR_STATE_save_to_mark() cannot fail as it takes over any allocated data from the thread error state.

- -

OSSL_ERR_STATE_restore() is a best effort function. The only failure that can happen during its operation is when memory allocation fails. Because it manipulates the thread error state it avoids raising memory errors on such failure. At worst the restored error entries will be missing the auxiliary error data.

- -

SEE ALSO

- -

ERR_raise(3), ERR_get_error(3), ERR_clear_error(3)

- -

HISTORY

- -

All of these functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ESS_check_signing_certs.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ESS_check_signing_certs.html deleted file mode 100644 index 66bfaa3b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ESS_check_signing_certs.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -OSSL_ESS_check_signing_certs - - - - - - - - - - -

NAME

- -

OSSL_ESS_signing_cert_new_init, OSSL_ESS_signing_cert_v2_new_init, OSSL_ESS_check_signing_certs - Enhanced Security Services (ESS) functions

- -

SYNOPSIS

- -
#include <openssl/ess.h>
-
-ESS_SIGNING_CERT *OSSL_ESS_signing_cert_new_init(const X509 *signcert,
-                                                 const STACK_OF(X509) *certs,
-                                                 int set_issuer_serial);
-ESS_SIGNING_CERT_V2 *OSSL_ESS_signing_cert_v2_new_init(const EVP_MD *hash_alg,
-                                                       const X509 *signcert,
-                                                       const
-                                                       STACK_OF(X509) *certs,
-                                                       int set_issuer_serial);
-int OSSL_ESS_check_signing_certs(const ESS_SIGNING_CERT *ss,
-                                 const ESS_SIGNING_CERT_V2 *ssv2,
-                                 const STACK_OF(X509) *chain,
-                                 int require_signing_cert);
- -

DESCRIPTION

- -

OSSL_ESS_signing_cert_new_init() generates a new ESS_SIGNING_CERT structure referencing the given signcert and any given further certs using their SHA-1 fingerprints. If set_issuer_serial is nonzero then also the issuer and serial number of signcert are included in the ESS_CERT_ID as the issuerSerial field. For all members of certs the issuerSerial field is always included.

- -

OSSL_ESS_signing_cert_v2_new_init() is the same as OSSL_ESS_signing_cert_new_init() except that it uses the given hash_alg and generates a ESS_SIGNING_CERT_V2 structure with ESS_CERT_ID_V2 elements.

- -

OSSL_ESS_check_signing_certs() checks if the validation chain chain contains the certificates required by the identifiers given in ss and/or ssv2. If require_signing_cert is nonzero, ss or ssv2 must not be NULL. If both ss and ssv2 are not NULL, they are evaluated independently. The list of certificate identifiers in ss is of type ESS_CERT_ID, while the list contained in ssv2 is of type ESS_CERT_ID_V2. As far as these lists are present, they must be nonempty. The certificate identified by their first entry must be the first element of chain, i.e. the signer certificate. Any further certificates referenced in the list must also be found in chain. The matching is done using the given certificate hash algorithm and value. In addition to the checks required by RFCs 2624 and 5035, if the issuerSerial field is included in an ESSCertID or ESSCertIDv2 it must match the certificate issuer and serial number attributes.

- -

NOTES

- -

ESS has been defined in RFC 2634, which has been updated in RFC 5035 (ESS version 2) to support hash algorithms other than SHA-1. This is used for TSP (RFC 3161) and CAdES-BES (informational RFC 5126).

- -

RETURN VALUES

- -

OSSL_ESS_signing_cert_new_init() and OSSL_ESS_signing_cert_v2_new_init() return a pointer to the new structure or NULL on malloc failure.

- -

OSSL_ESS_check_signing_certs() returns 1 on success, 0 if a required certificate cannot be found, -1 on other error.

- -

SEE ALSO

- -

TS_VERIFY_CTX_set_certs(3), CMS_verify(3)

- -

HISTORY

- -

OSSL_ESS_signing_cert_new_init(), OSSL_ESS_signing_cert_v2_new_init(), and OSSL_ESS_check_signing_certs() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_GENERAL_NAMES_print.html b/openssl-install/share/doc/openssl/html/man3/OSSL_GENERAL_NAMES_print.html deleted file mode 100644 index 86d912ea..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_GENERAL_NAMES_print.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -OSSL_GENERAL_NAMES_print - - - - - - - - - - -

NAME

- -

OSSL_GENERAL_NAMES_print - print GeneralNames in a human-friendly, multi-line string

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-int OSSL_GENERAL_NAMES_print(BIO *out, GENERAL_NAMES *gens, int indent);
- -

DESCRIPTION

- -

OSSL_GENERAL_NAMES_print() prints a human readable version of the GeneralNames gens to BIO out. Each line is indented by indent spaces.

- -

RETURN VALUES

- -

OSSL_GENERAL_NAMES_print() always returns 1.

- -

HISTORY

- -

The functions described here were all added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_HPKE_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/OSSL_HPKE_CTX_new.html deleted file mode 100644 index c92f889c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_HPKE_CTX_new.html +++ /dev/null @@ -1,456 +0,0 @@ - - - - -OSSL_HPKE_CTX_new - - - - - - - - - - -

NAME

- -

OSSL_HPKE_CTX_new, OSSL_HPKE_CTX_free, OSSL_HPKE_encap, OSSL_HPKE_decap, OSSL_HPKE_seal, OSSL_HPKE_open, OSSL_HPKE_export, OSSL_HPKE_suite_check, OSSL_HPKE_str2suite, OSSL_HPKE_keygen, OSSL_HPKE_get_grease_value, OSSL_HPKE_get_ciphertext_size, OSSL_HPKE_get_public_encap_size, OSSL_HPKE_get_recommended_ikmelen, OSSL_HPKE_CTX_set1_psk, OSSL_HPKE_CTX_set1_ikme, OSSL_HPKE_CTX_set1_authpriv, OSSL_HPKE_CTX_set1_authpub, OSSL_HPKE_CTX_get_seq, OSSL_HPKE_CTX_set_seq - Hybrid Public Key Encryption (HPKE) functions

- -

SYNOPSIS

- -
#include <openssl/hpke.h>
-
-typedef struct {
-    uint16_t    kem_id;
-    uint16_t    kdf_id;
-    uint16_t    aead_id;
-} OSSL_HPKE_SUITE;
-
-OSSL_HPKE_CTX *OSSL_HPKE_CTX_new(int mode, OSSL_HPKE_SUITE suite, int role,
-                                 OSSL_LIB_CTX *libctx, const char *propq);
-void OSSL_HPKE_CTX_free(OSSL_HPKE_CTX *ctx);
-
-int OSSL_HPKE_encap(OSSL_HPKE_CTX *ctx,
-                    unsigned char *enc, size_t *enclen,
-                    const unsigned char *pub, size_t publen,
-                    const unsigned char *info, size_t infolen);
-int OSSL_HPKE_seal(OSSL_HPKE_CTX *ctx,
-                   unsigned char *ct, size_t *ctlen,
-                   const unsigned char *aad, size_t aadlen,
-                   const unsigned char *pt, size_t ptlen);
-
-int OSSL_HPKE_keygen(OSSL_HPKE_SUITE suite,
-                     unsigned char *pub, size_t *publen, EVP_PKEY **priv,
-                     const unsigned char *ikm, size_t ikmlen,
-                     OSSL_LIB_CTX *libctx, const char *propq);
-int OSSL_HPKE_decap(OSSL_HPKE_CTX *ctx,
-                    const unsigned char *enc, size_t enclen,
-                    EVP_PKEY *recippriv,
-                    const unsigned char *info, size_t infolen);
-int OSSL_HPKE_open(OSSL_HPKE_CTX *ctx,
-                   unsigned char *pt, size_t *ptlen,
-                   const unsigned char *aad, size_t aadlen,
-                   const unsigned char *ct, size_t ctlen);
-
-int OSSL_HPKE_export(OSSL_HPKE_CTX *ctx,
-                     unsigned char *secret, size_t secretlen,
-                     const unsigned char *label, size_t labellen);
-
-int OSSL_HPKE_CTX_set1_authpriv(OSSL_HPKE_CTX *ctx, EVP_PKEY *priv);
-int OSSL_HPKE_CTX_set1_authpub(OSSL_HPKE_CTX *ctx,
-                               unsigned char *pub, size_t publen);
-int OSSL_HPKE_CTX_set1_psk(OSSL_HPKE_CTX *ctx,
-                           const char *pskid,
-                           const unsigned char *psk, size_t psklen);
-
-int OSSL_HPKE_CTX_get_seq(OSSL_HPKE_CTX *ctx, uint64_t *seq);
-int OSSL_HPKE_CTX_set_seq(OSSL_HPKE_CTX *ctx, uint64_t seq);
-
-int OSSL_HPKE_CTX_set1_ikme(OSSL_HPKE_CTX *ctx,
-                            const unsigned char *ikme, size_t ikmelen);
-
-int OSSL_HPKE_suite_check(OSSL_HPKE_SUITE suite);
-int OSSL_HPKE_get_grease_value(const OSSL_HPKE_SUITE *suite_in,
-                               OSSL_HPKE_SUITE *suite,
-                               unsigned char *enc, size_t *enclen,
-                               unsigned char *ct, size_t ctlen,
-                               OSSL_LIB_CTX *libctx, const char *propq);
-
-int OSSL_HPKE_str2suite(const char *str, OSSL_HPKE_SUITE *suite);
-size_t OSSL_HPKE_get_ciphertext_size(OSSL_HPKE_SUITE suite, size_t clearlen);
-size_t OSSL_HPKE_get_public_encap_size(OSSL_HPKE_SUITE suite);
-size_t OSSL_HPKE_get_recommended_ikmelen(OSSL_HPKE_SUITE suite);
- -

DESCRIPTION

- -

These functions provide an API for using the form of Hybrid Public Key Encryption (HPKE) defined in RFC9180. Understanding the HPKE specification is likely required before using these APIs. HPKE is used by various other IETF specifications, including the TLS Encrypted Client Hello (ECH) specification and others.

- -

HPKE is a standardised, highly flexible construct for encrypting "to" a public key that supports combinations of a key encapsulation method (KEM), a key derivation function (KDF) and an authenticated encryption with additional data (AEAD) algorithm, with optional sender authentication.

- -

The sender and a receiver here will generally be using some application or protocol making use of HPKE. For example, with ECH, the sender will be a browser and the receiver will be a web server.

- -

Data Structures

- -

OSSL_HPKE_SUITE is a structure that holds identifiers for the algorithms used for KEM, KDF and AEAD operations.

- -

OSSL_HPKE_CTX is a context that maintains internal state as HPKE operations are carried out. Separate OSSL_HPKE_CTX objects must be used for the sender and receiver. Attempting to use a single context for both will result in errors.

- -

OSSL_HPKE_SUITE Identifiers

- -

The identifiers used by OSSL_HPKE_SUITE are:

- -

The KEM identifier kem_id is one of the following:

- -
- -
0x10 OSSL_HPKE_KEM_ID_P256
-
- -
-
0x11 OSSL_HPKE_KEM_ID_P384
-
- -
-
0x12 OSSL_HPKE_KEM_ID_P521
-
- -
-
0x20 OSSL_HPKE_KEM_ID_X25519
-
- -
-
0x21 OSSL_HPKE_KEM_ID_X448
-
- -
-
- -

The KDF identifier kdf_id is one of the following:

- -
- -
0x01 OSSL_HPKE_KDF_ID_HKDF_SHA256
-
- -
-
0x02 OSSL_HPKE_KDF_ID_HKDF_SHA384
-
- -
-
0x03 OSSL_HPKE_KDF_ID_HKDF_SHA512
-
- -
-
- -

The AEAD identifier aead_id is one of the following:

- -
- -
0x01 OSSL_HPKE_AEAD_ID_AES_GCM_128
-
- -
-
0x02 OSSL_HPKE_AEAD_ID_AES_GCM_256
-
- -
-
0x03 OSSL_HPKE_AEAD_ID_CHACHA_POLY1305
-
- -
-
0xFFFF OSSL_HPKE_AEAD_ID_EXPORTONLY
-
- -

The last identifier above indicates that AEAD operations are not needed. OSSL_HPKE_export() can be used, but OSSL_HPKE_open() and OSSL_HPKE_seal() will return an error if called with a context using that AEAD identifier.

- -
-
- -

HPKE Modes

- -

HPKE supports the following variants of Authentication using a mode Identifier:

- -
- -
OSSL_HPKE_MODE_BASE, 0x00
-
- -

Authentication is not used.

- -
-
OSSL_HPKE_MODE_PSK, 0x01
-
- -

Authenticates possession of a pre-shared key (PSK).

- -
-
OSSL_HPKE_MODE_AUTH, 0x02
-
- -

Authenticates possession of a KEM-based sender private key.

- -
-
OSSL_HPKE_MODE_PSKAUTH, 0x03
-
- -

A combination of OSSL_HPKE_MODE_PSK and OSSL_HPKE_MODE_AUTH. Both the PSK and the senders authentication public/private must be supplied before the encapsulation/decapsulation operation will work.

- -
-
- -

For further information related to authentication see "Pre-Shared Key HPKE modes" and "Sender-authenticated HPKE Modes".

- -

HPKE Roles

- -

HPKE contexts have a role - either sender or receiver. This is used to control which functions can be called and so that senders do not reuse a key and nonce with different plaintexts.

- -

OSSL_HPKE_CTX_free(), OSSL_HPKE_export(), OSSL_HPKE_CTX_set1_psk(), and OSSL_HPKE_CTX_get_seq() can be called regardless of role.

- -
- -
OSSL_HPKE_ROLE_SENDER, 0
-
- -

An OSSL_HPKE_CTX with this role can be used with OSSL_HPKE_encap(), OSSL_HPKE_seal(), OSSL_HPKE_CTX_set1_ikme() and OSSL_HPKE_CTX_set1_authpriv().

- -
-
OSSL_HPKE_ROLE_RECEIVER, 1
-
- -

An OSSL_HPKE_CTX with this role can be used with OSSL_HPKE_decap(), OSSL_HPKE_open(), OSSL_HPKE_CTX_set1_authpub() and OSSL_HPKE_CTX_set_seq().

- -
-
- -

Calling a function with an incorrect role set on OSSL_HPKE_CTX will result in an error.

- -

Parameter Size Limits

- -

In order to improve interoperability, RFC9180, section 7.2.1 suggests a RECOMMENDED maximum size of 64 octets for various input parameters. In this implementation we apply a limit of 66 octets for the ikmlen, psklen, and labellen parameters, and for the length of the string pskid for HPKE functions below. The constant OSSL_HPKE_MAX_PARMLEN is defined as the limit of this value. (We chose 66 octets so that we can validate all the test vectors present in RFC9180, Appendix A.)

- -

In accordance with RFC9180, section 9.5, we define a constant OSSL_HPKE_MIN_PSKLEN with a value of 32 for the minimum length of a pre-shared key, passed in psklen.

- -

While RFC9180 also RECOMMENDS a 64 octet limit for the infolen parameter, that is not sufficient for TLS Encrypted ClientHello (ECH) processing, so we enforce a limit of OSSL_HPKE_MAX_INFOLEN with a value of 1024 as the limit for the infolen parameter.

- -

Context Construct/Free

- -

OSSL_HPKE_CTX_new() creates a OSSL_HPKE_CTX context object used for subsequent HPKE operations, given a mode (See "HPKE Modes"), suite (see "OSSL_HPKE_SUITE Identifiers") and a role (see "HPKE Roles"). The libctx and propq are used when fetching algorithms from providers and may be set to NULL.

- -

OSSL_HPKE_CTX_free() frees the ctx OSSL_HPKE_CTX that was created previously by a call to OSSL_HPKE_CTX_new(). If the argument to OSSL_HPKE_CTX_free() is NULL, nothing is done.

- -

Sender APIs

- -

A sender's goal is to use HPKE to encrypt using a public key, via use of a KEM, then a KDF and finally an AEAD. The first step is to encapsulate (using OSSL_HPKE_encap()) the sender's public value using the recipient's public key, (pub) and to internally derive secrets. This produces the encapsulated public value (enc) to be sent to the recipient in whatever protocol is using HPKE. Having done the encapsulation step, the sender can then make one or more calls to OSSL_HPKE_seal() to encrypt plaintexts using the secret stored within ctx.

- -

OSSL_HPKE_encap() uses the HPKE context ctx, the recipient public value pub of size publen, and an optional info parameter of size infolen, to produce the encapsulated public value enc. On input enclen should contain the maximum size of the enc buffer, and returns the output size. An error will occur if the input enclen is smaller than the value returned from OSSL_HPKE_get_public_encap_size(). info may be used to bind other protocol or application artefacts such as identifiers. Generally, the encapsulated public value enc corresponds to a single-use ephemeral private value created as part of the encapsulation process. Only a single call to OSSL_HPKE_encap() is allowed for a given OSSL_HPKE_CTX.

- -

OSSL_HPKE_seal() takes the OSSL_HPKE_CTX context ctx, the plaintext buffer pt of size ptlen and optional additional authenticated data buffer aad of size aadlen, and returns the ciphertext ct of size ctlen. On input ctlen should contain the maximum size of the ct buffer, and returns the output size. An error will occur if the input ctlen is smaller than the value returned from OSSL_HPKE_get_public_encap_size().

- -

OSSL_HPKE_encap() must be called before the OSSL_HPKE_seal(). OSSL_HPKE_seal() may be called multiple times, with an internal "nonce" being incremented by one after each call.

- -

Recipient APIs

- -

Recipients using HPKE require a typically less ephemeral private value so that the public value can be distributed to potential senders via whatever protocol is using HPKE. For this reason, recipients will generally first generate a key pair and will need to manage their private key value using standard mechanisms outside the scope of this API. Private keys use normal EVP_PKEY(3) pointers so normal private key management mechanisms can be used for the relevant values.

- -

In order to enable encapsulation, the recipient needs to make it's public value available to the sender. There is no generic HPKE format defined for that - the relevant formatting is intended to be defined by the application/protocols that makes use of HPKE. ECH for example defines an ECHConfig data structure that combines the public value with other ECH data items. Normal library functions must therefore be used to extract the public value in the required format based on the EVP_PKEY(3) for the private value.

- -

OSSL_HPKE_keygen() provides a way for recipients to generate a key pair based on the HPKE suite to be used. It returns a EVP_PKEY(3) pointer for the private value priv and a encoded public key pub of size publen. On input publen should contain the maximum size of the pub buffer, and returns the output size. An error will occur if the input publen is too small. The libctx and propq are used when fetching algorithms from providers and may be set to NULL. The HPKE specification also defines a deterministic key generation scheme where the private value is derived from initial keying material (IKM), so OSSL_HPKE_keygen() also has an option to use that scheme, using the ikm parameter of size ikmlen. If either ikm is NULL or ikmlen is zero, then a randomly generated key for the relevant suite will be produced. If required ikmlen should be greater than or equal to OSSL_HPKE_get_recommended_ikmelen().

- -

OSSL_HPKE_decap() takes as input the sender's encapsulated public value produced by OSSL_HPKE_encap() (enc) and the recipient's EVP_PKEY(3) pointer (prov), and then re-generates the internal secret derived by the sender. As before, an optional info parameter allows binding that derived secret to other application/protocol artefacts. Only a single call to OSSL_HPKE_decap() is allowed for a given OSSL_HPKE_CTX.

- -

OSSL_HPKE_open() is used by the recipient to decrypt the ciphertext ct of size ctlen using the ctx and additional authenticated data aad of size aadlen, to produce the plaintext pt of size ptlen. On input ptlen should contain the maximum size of the pt buffer, and returns the output size. A pt buffer that is the same size as the ct buffer will suffice - generally the plaintext output will be a little smaller than the ciphertext input. An error will occur if the input ptlen is too small. OSSL_HPKE_open() may be called multiple times, but as with OSSL_HPKE_seal() there is an internally incrementing nonce value so ciphertexts need to be presented in the same order as used by the OSSL_HPKE_seal(). See "Re-sequencing" if you need to process multiple ciphertexts in a different order.

- -

Exporting Secrets

- -

HPKE defines a way to produce exported secrets for use by the application.

- -

OSSL_HPKE_export() takes as input the OSSL_HPKE_CTX, and an application supplied label label of size labellen, to produce a secret secret of size secretlen. The sender must first call OSSL_HPKE_encap(), and the receiver must call OSSL_HPKE_decap() in order to derive the same shared secret.

- -

Multiple calls to OSSL_HPKE_export() with the same inputs will produce the same secret. OSSL_HPKE_AEAD_ID_EXPORTONLY may be used as the OSSL_HPKE_SUITE aead_id that is passed to OSSL_HPKE_CTX_new() if the user needs to produce a shared secret, but does not wish to perform HPKE encryption.

- -

Sender-authenticated HPKE Modes

- -

HPKE defines modes that support KEM-based sender-authentication OSSL_HPKE_MODE_AUTH and OSSL_HPKE_MODE_PSKAUTH. This works by binding the sender's authentication private/public values into the encapsulation and decapsulation operations. The key used for such modes must also use the same KEM as used for the overall exchange. OSSL_HPKE_keygen() can be used to generate the private value required.

- -

OSSL_HPKE_CTX_set1_authpriv() can be used by the sender to set the senders private priv EVP_PKEY key into the OSSL_HPKE_CTX ctx before calling OSSL_HPKE_encap().

- -

OSSL_HPKE_CTX_set1_authpub() can be used by the receiver to set the senders encoded pub key pub of size publen into the OSSL_HPKE_CTX ctx before calling OSSL_HPKE_decap().

- -

Pre-Shared Key HPKE modes

- -

HPKE also defines a symmetric equivalent to the authentication described above using a pre-shared key (PSK) and a PSK identifier. PSKs can be used with the OSSL_HPKE_MODE_PSK and OSSL_HPKE_MODE_PSKAUTH modes.

- -

OSSL_HPKE_CTX_set1_psk() sets the PSK identifier pskid string, and PSK buffer psk of size psklen into the ctx. If required this must be called before OSSL_HPKE_encap() or OSSL_HPKE_decap(). As per RFC9180, if required, both psk and pskid must be set to non-NULL values. As PSKs are symmetric the same calls must happen on both sender and receiver sides.

- -

Deterministic key generation for senders

- -

Normally the senders ephemeral private key is generated randomly inside OSSL_HPKE_encap() and remains secret. OSSL_HPKE_CTX_set1_ikme() allows the user to override this behaviour by setting a deterministic input key material ikm of size ikmlen into the OSSL_HPKE_CTX ctx. If required OSSL_HPKE_CTX_set1_ikme() can optionally be called before OSSL_HPKE_encap(). ikmlen should be greater than or equal to OSSL_HPKE_get_recommended_ikmelen().

- -

It is generally undesirable to use OSSL_HPKE_CTX_set1_ikme(), since it exposes the relevant secret to the application rather then preserving it within the library, and is more likely to result in use of predictable values or values that leak.

- -

Re-sequencing

- -

Some protocols may have to deal with packet loss while still being able to decrypt arriving packets later. We provide a way to set the increment used for the nonce to the next subsequent call to OSSL_HPKE_open() (but not to OSSL_HPKE_seal() as explained below). The OSSL_HPKE_CTX_set_seq() API can be used for such purposes with the seq parameter value resetting the internal nonce increment to be used for the next call.

- -

A baseline nonce value is established based on the encapsulation or decapsulation operation and is then incremented by 1 for each call to seal or open. (In other words, the first seq increment defaults to zero.)

- -

If a caller needs to determine how many calls to seal or open have been made the OSSL_HPKE_CTX_get_seq() API can be used to retrieve the increment (in the seq output) that will be used in the next call to seal or open. That would return 0 before the first call a sender made to OSSL_HPKE_seal() and 1 after that first call.

- -

Note that reuse of the same nonce and key with different plaintexts would be very dangerous and could lead to loss of confidentiality and integrity. We therefore only support application control over seq for decryption (i.e. OSSL_HPKE_open()) operations.

- -

For compatibility with other implementations these seq increments are represented as uint64_t.

- -

Protocol Convenience Functions

- -

Additional convenience APIs allow the caller to access internal details of local HPKE support and/or algorithms, such as parameter lengths.

- -

OSSL_HPKE_suite_check() checks if a specific OSSL_HPKE_SUITE suite is supported locally.

- -

To assist with memory allocation, OSSL_HPKE_get_ciphertext_size() provides a way for the caller to know by how much ciphertext will be longer than a plaintext of length clearlen. (AEAD algorithms add a data integrity tag, so there is a small amount of ciphertext expansion.)

- -

OSSL_HPKE_get_public_encap_size() provides a way for senders to know how big the encapsulated public value will be for a given HPKE suite.

- -

OSSL_HPKE_get_recommended_ikmelen() returns the recommended Input Key Material size (in bytes) for a given suite. This is needed in cases where the same public value needs to be regenerated by a sender before calling OSSL_HPKE_seal(). ikmlen should be at least this size.

- -

OSSL_HPKE_get_grease_value() produces values of the appropriate length for a given suite_in value (or a random value if suite_in is NULL) so that a protocol using HPKE can send so-called GREASE (see RFC8701) values that are harder to distinguish from a real use of HPKE. The buffer sizes should be supplied on input. The output enc value will have an appropriate length for suite_out and a random value, and the ct output will be a random value. The relevant sizes for buffers can be found using OSSL_HPKE_get_ciphertext_size() and OSSL_HPKE_get_public_encap_size().

- -

OSSL_HPKE_str2suite() maps input str strings to an OSSL_HPKE_SUITE object. The input str should be a comma-separated string with a KEM, KDF and AEAD name in that order, for example "x25519,hkdf-sha256,aes128gcm". This can be used by command line tools that accept string form names for HPKE codepoints. Valid (case-insensitive) names are: "p-256", "p-384", "p-521", "x25519" and "x448" for KEM, "hkdf-sha256", "hkdf-sha384" and "hkdf-sha512" for KDF, and "aes-gcm-128", "aes-gcm-256", "chacha20-poly1305" and "exporter" for AEAD. String variants of the numbers listed in "OSSL_HPKE_SUITE Identifiers" can also be used.

- -

RETURN VALUES

- -

OSSL_HPKE_CTX_new() returns an OSSL_HPKE_CTX pointer or NULL on error.

- -

OSSL_HPKE_get_ciphertext_size(), OSSL_HPKE_get_public_encap_size(), OSSL_HPKE_get_recommended_ikmelen() all return a size_t with the relevant value or zero on error.

- -

All other functions return 1 for success or zero for error.

- -

EXAMPLES

- -

This example demonstrates a minimal round-trip using HPKE.

- -
#include <stddef.h>
-#include <string.h>
-#include <openssl/hpke.h>
-#include <openssl/evp.h>
-
-/*
- * this is big enough for this example, real code would need different
- * handling
- */
-#define LBUFSIZE 48
-
-/* Do a round-trip, generating a key, encrypting and decrypting */
-int main(int argc, char **argv)
-{
-    int ok = 0;
-    int hpke_mode = OSSL_HPKE_MODE_BASE;
-    OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT;
-    OSSL_HPKE_CTX *sctx = NULL, *rctx = NULL;
-    EVP_PKEY *priv = NULL;
-    unsigned char pub[LBUFSIZE];
-    size_t publen = sizeof(pub);
-    unsigned char enc[LBUFSIZE];
-    size_t enclen = sizeof(enc);
-    unsigned char ct[LBUFSIZE];
-    size_t ctlen = sizeof(ct);
-    unsigned char clear[LBUFSIZE];
-    size_t clearlen = sizeof(clear);
-    const unsigned char *pt = "a message not in a bottle";
-    size_t ptlen = strlen((char *)pt);
-    const unsigned char *info = "Some info";
-    size_t infolen = strlen((char *)info);
-    unsigned char aad[] = { 1, 2, 3, 4, 5, 6, 7, 8 };
-    size_t aadlen = sizeof(aad);
-
-    /*
-     * Generate receiver's key pair.
-     * The receiver gives this public key to the sender.
-     */
-    if (OSSL_HPKE_keygen(hpke_suite, pub, &publen, &priv,
-                         NULL, 0, NULL, NULL) != 1)
-        goto err;
-
-    /* sender's actions - encrypt data using the receivers public key */
-    if ((sctx = OSSL_HPKE_CTX_new(hpke_mode, hpke_suite,
-                                  OSSL_HPKE_ROLE_SENDER,
-                                  NULL, NULL)) == NULL)
-        goto err;
-    if (OSSL_HPKE_encap(sctx, enc, &enclen, pub, publen, info, infolen) != 1)
-        goto err;
-    if (OSSL_HPKE_seal(sctx, ct, &ctlen, aad, aadlen, pt, ptlen) != 1)
-        goto err;
-
-    /* receiver's actions - decrypt data using the receivers private key */
-    if ((rctx = OSSL_HPKE_CTX_new(hpke_mode, hpke_suite,
-                                  OSSL_HPKE_ROLE_RECEIVER,
-                                  NULL, NULL)) == NULL)
-        goto err;
-    if (OSSL_HPKE_decap(rctx, enc, enclen, priv, info, infolen) != 1)
-        goto err;
-    if (OSSL_HPKE_open(rctx, clear, &clearlen, aad, aadlen, ct, ctlen) != 1)
-        goto err;
-    ok = 1;
-err:
-    /* clean up */
-    printf(ok ? "All Good!\n" : "Error!\n");
-    OSSL_HPKE_CTX_free(rctx);
-    OSSL_HPKE_CTX_free(sctx);
-    EVP_PKEY_free(priv);
-    return 0;
-}
- -

WARNINGS

- -

Note that the OSSL_HPKE_CTX_set_seq() API could be dangerous - if used with GCM that could lead to nonce-reuse, which is a known danger. So avoid that entirely, or be very very careful when using that API.

- -

Use of an IKM value for deterministic key generation (via OSSL_HPKE_CTX_set1_ikme() or OSSL_HPKE_keygen()) creates the potential for leaking keys (or IKM values). Only use that if really needed and if you understand how keys or IKM values could be abused.

- -

SEE ALSO

- -

The RFC9180 specification: https://datatracker.ietf.org/doc/rfc9180/

- -

HISTORY

- -

This functionality described here was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_REQ_CTX.html b/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_REQ_CTX.html deleted file mode 100644 index c1eb35f3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_REQ_CTX.html +++ /dev/null @@ -1,171 +0,0 @@ - - - - -OSSL_HTTP_REQ_CTX - - - - - - - - - - -

NAME

- -

OSSL_HTTP_REQ_CTX, OSSL_HTTP_REQ_CTX_new, OSSL_HTTP_REQ_CTX_free, OSSL_HTTP_REQ_CTX_set_request_line, OSSL_HTTP_REQ_CTX_add1_header, OSSL_HTTP_REQ_CTX_set_expected, OSSL_HTTP_REQ_CTX_set1_req, OSSL_HTTP_REQ_CTX_nbio, OSSL_HTTP_REQ_CTX_nbio_d2i, OSSL_HTTP_REQ_CTX_exchange, OSSL_HTTP_REQ_CTX_get0_mem_bio, OSSL_HTTP_REQ_CTX_get_resp_len, OSSL_HTTP_REQ_CTX_set_max_response_length, OSSL_HTTP_is_alive, OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines - HTTP client low-level functions

- -

SYNOPSIS

- -
#include <openssl/http.h>
-
-typedef struct ossl_http_req_ctx_st OSSL_HTTP_REQ_CTX;
-
-OSSL_HTTP_REQ_CTX *OSSL_HTTP_REQ_CTX_new(BIO *wbio, BIO *rbio, int buf_size);
-void OSSL_HTTP_REQ_CTX_free(OSSL_HTTP_REQ_CTX *rctx);
-
-int OSSL_HTTP_REQ_CTX_set_request_line(OSSL_HTTP_REQ_CTX *rctx, int method_POST,
-                                       const char *server, const char *port,
-                                       const char *path);
-int OSSL_HTTP_REQ_CTX_add1_header(OSSL_HTTP_REQ_CTX *rctx,
-                                  const char *name, const char *value);
-
-int OSSL_HTTP_REQ_CTX_set_expected(OSSL_HTTP_REQ_CTX *rctx,
-                                   const char *content_type, int asn1,
-                                   int timeout, int keep_alive);
-int OSSL_HTTP_REQ_CTX_set1_req(OSSL_HTTP_REQ_CTX *rctx, const char *content_type,
-                               const ASN1_ITEM *it, const ASN1_VALUE *req);
-int OSSL_HTTP_REQ_CTX_nbio(OSSL_HTTP_REQ_CTX *rctx);
-int OSSL_HTTP_REQ_CTX_nbio_d2i(OSSL_HTTP_REQ_CTX *rctx,
-                               ASN1_VALUE **pval, const ASN1_ITEM *it);
-BIO *OSSL_HTTP_REQ_CTX_exchange(OSSL_HTTP_REQ_CTX *rctx);
-
-BIO *OSSL_HTTP_REQ_CTX_get0_mem_bio(const OSSL_HTTP_REQ_CTX *rctx);
-size_t OSSL_HTTP_REQ_CTX_get_resp_len(const OSSL_HTTP_REQ_CTX *rctx);
-void OSSL_HTTP_REQ_CTX_set_max_response_length(OSSL_HTTP_REQ_CTX *rctx,
-                                               unsigned long len);
-
-int OSSL_HTTP_is_alive(const OSSL_HTTP_REQ_CTX *rctx);
-
-void OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines(OSSL_HTTP_REQ_CTX *rctx,
-                                                  size_t count);
- -

DESCRIPTION

- -

OSSL_HTTP_REQ_CTX is a context structure for an HTTP request and response, used to collect all the necessary data to perform that request.

- -

This file documents low-level HTTP functions rarely used directly. High-level HTTP client functions like OSSL_HTTP_get(3) and OSSL_HTTP_transfer(3) should be preferred.

- -

OSSL_HTTP_REQ_CTX_new() allocates a new HTTP request context structure, which gets populated with the BIO to write/send the request to (wbio), the BIO to read/receive the response from (rbio, which may be equal to wbio), and the maximum expected response header line length buf_size. A value <= 0 indicates that the OSSL_HTTP_DEFAULT_MAX_LINE_LEN of 4KiB should be used. buf_size is also used as the number of content bytes that are read at a time. The allocated context structure includes an internal memory BIO, which collects the HTTP request header lines.

- -

OSSL_HTTP_REQ_CTX_free() frees up the HTTP request context rctx. The rbio is not free'd, wbio will be free'd if free_wbio is set. If the argument is NULL, nothing is done.

- -

OSSL_HTTP_REQ_CTX_set_request_line() adds the 1st HTTP request line to rctx. The HTTP method is determined by method_POST, which should be 1 to indicate POST or 0 to indicate GET. server and port may be set to give the server and the optional port that an HTTP proxy shall forward the request to, otherwise they must be left NULL. path provides the HTTP request path; if left NULL, / is used. For backward compatibility, path may begin with http:// and thus convey an absoluteURI. In this case it indicates HTTP proxy use and provides also the server (and optionally the port) that the proxy shall forward the request to. In this case the server and port arguments must be NULL.

- -

OSSL_HTTP_REQ_CTX_add1_header() adds header name with value value to the context rctx. It can be called more than once to add multiple header lines. For example, to add a Host header for example.com you would call:

- -
OSSL_HTTP_REQ_CTX_add1_header(ctx, "Host", "example.com");
- -

OSSL_HTTP_REQ_CTX_set_expected() optionally sets in rctx some expectations of the HTTP client on the response. Due to the structure of an HTTP request, if the keep_alive argument is nonzero the function must be used before calling OSSL_HTTP_REQ_CTX_set1_req().

- -

If the content_type argument is not NULL, the client will check that the specified content-type string is included in the HTTP header of the response and return an error if not. In the content-type header line the specified string should be present either as a whole, or in case the specified string does not include a ; character, it is sufficient that the specified string appears as a prefix in the header line, followed by a ; character and any further text. For instance, if the content_type argument specifies text/html, this is matched by text/html, text/html; charset=UTF-8, etc.

- -

If the asn1 parameter is nonzero a structure in ASN.1 encoding will be expected as the response content and input streaming is disabled. This means that an ASN.1 sequence header is required, its length field is checked, and OSSL_HTTP_REQ_CTX_get0_mem_bio() should be used to get the buffered response. Otherwise (by default) any input format is allowed without length checks. In this case the BIO given as rbio argument to OSSL_HTTP_REQ_CTX_new() should be used directly to read the response contents, which may support streaming. If the timeout parameter is > 0 this indicates the maximum number of seconds the subsequent HTTP transfer (sending the request and receiving a response) is allowed to take. timeout == 0 enables waiting indefinitely, i.e., no timeout can occur. This is the default. timeout < 0 takes over any value set via the overall_timeout argument of OSSL_HTTP_open(3) with the default being 0, which means no timeout. If the keep_alive parameter is 0, which is the default, the connection is not kept open after receiving a response. This is the default behavior for HTTP 1.0. If the value is 1 or 2 then a persistent connection is requested. If the value is 2 then a persistent connection is required, i.e., an error occurs in case the server does not grant it.

- -

OSSL_HTTP_REQ_CTX_set1_req() finalizes the HTTP request context. It is needed if the method_POST parameter in the OSSL_HTTP_REQ_CTX_set_request_line() call was 1 and an ASN.1-encoded request should be sent. It must also be used when requesting "keep-alive", even if a GET request is going to be sent, in which case req must be NULL. Unless req is NULL, the function adds the DER encoding of req using the ASN.1 template it to do the encoding (which does not support streaming). The HTTP header Content-Length is filled out with the length of the request. content_type must be NULL if req is NULL. If content_type isn't NULL, the HTTP header Content-Type is also added with the given string value. The header lines are added to the internal memory BIO for the request header.

- -

OSSL_HTTP_REQ_CTX_nbio() attempts to send the request prepared in rctx and to gather the response via HTTP, using the wbio and rbio that were given when calling OSSL_HTTP_REQ_CTX_new(). The function may need to be called again if its result is -1, which indicates BIO_should_retry(3). In such a case it is advisable to sleep a little in between, using BIO_wait(3) on the read BIO to prevent a busy loop.

- -

OSSL_HTTP_REQ_CTX_nbio_d2i() is like OSSL_HTTP_REQ_CTX_nbio() but on success in addition parses the response, which must be a DER-encoded ASN.1 structure, using the ASN.1 template it and places the result in *pval.

- -

OSSL_HTTP_REQ_CTX_exchange() calls OSSL_HTTP_REQ_CTX_nbio() as often as needed in order to exchange a request and response or until a timeout is reached. On success it returns a pointer to the BIO that can be used to read the result. If an ASN.1-encoded response was expected, this is the BIO returned by OSSL_HTTP_REQ_CTX_get0_mem_bio() when called after the exchange. This memory BIO does not support streaming. Otherwise the returned BIO is the rbio given to OSSL_HTTP_REQ_CTX_new(), which may support streaming. When this BIO is returned, it has been read past the end of the response header, such that the actual response body can be read from it. The returned BIO pointer MUST NOT be freed by the caller.

- -

OSSL_HTTP_REQ_CTX_get0_mem_bio() returns the internal memory BIO. Before the HTTP request is sent, this could be used to adapt its header lines. Use with caution! After receiving a response via HTTP, the BIO represents the current state of reading the response header. If the response was expected to be ASN.1 encoded, its contents can be read via this BIO, which does not support streaming. The returned BIO pointer must not be freed by the caller.

- -

OSSL_HTTP_REQ_CTX_get_resp_len() returns the size of the response contents in rctx if provided by the server as <Content-Length> header field, else 0.

- -

OSSL_HTTP_REQ_CTX_set_max_response_length() sets the maximum allowed response content length for rctx to len. If not set or len is 0 then the OSSL_HTTP_DEFAULT_MAX_RESP_LEN is used, which currently is 100 KiB. If the Content-Length header is present and exceeds this value or the content is an ASN.1 encoded structure with a length exceeding this value or both length indications are present but disagree then an error occurs.

- -

OSSL_HTTP_is_alive() can be used to query if the HTTP connection given by rctx is still alive, i.e., has not been closed. It returns 0 if rctx is NULL.

- -

If the client application requested or required a persistent connection and this was granted by the server, it can keep rctx as long as it wants to send further requests and OSSL_HTTP_is_alive() returns nonzero, else it should call OSSL_HTTP_REQ_CTX_free(rctx) or OSSL_HTTP_close(3). In case the client application keeps rctx but the connection then dies for any reason at the server side, it will notice this obtaining an I/O error when trying to send the next request via rctx.

- -

The OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines() function changes the limit for the number of HTTP headers which can be received in a response. The default value is 256. If the number of HTTP headers in a response exceeds the limit, then the HTTP_R_RESPONSE_TOO_MANY_HDRLINES error is indicated. Setting the limit to 0 disables the check.

- -

WARNINGS

- -

The server's response may be unexpected if the hostname that was used to create the wbio, any Host header, and the host specified in the request URL do not match.

- -

Many of these functions must be called in a certain order.

- -

First, the HTTP request context must be allocated: OSSL_HTTP_REQ_CTX_new().

- -

Then, the HTTP request must be prepared with request data:

- -
    - -
  1. Calling OSSL_HTTP_REQ_CTX_set_request_line().

    - -
  2. -
  3. Adding extra header lines with OSSL_HTTP_REQ_CTX_add1_header(). This is optional and may be done multiple times with different names.

    - -
  4. -
  5. Finalize the request using OSSL_HTTP_REQ_CTX_set1_req(). This may be omitted if the GET method is used and "keep-alive" is not requested.

    - -
  6. -
- -

When the request context is fully prepared, the HTTP exchange may be performed with OSSL_HTTP_REQ_CTX_nbio() or OSSL_HTTP_REQ_CTX_exchange().

- -

NOTES

- -

When built with tracing enabled, OSSL_HTTP_REQ_CTX_nbio() and all functions using it, such as OSSL_HTTP_REQ_CTX_exchange() and OSSL_HTTP_transfer(3), may be traced using OSSL_TRACE_CATEGORY_HTTP. See also OSSL_trace_enabled(3) and openssl-env(7).

- -

RETURN VALUES

- -

OSSL_HTTP_REQ_CTX_new() returns a pointer to a OSSL_HTTP_REQ_CTX, or NULL on error.

- -

OSSL_HTTP_REQ_CTX_free() and OSSL_HTTP_REQ_CTX_set_max_response_length() do not return values.

- -

OSSL_HTTP_REQ_CTX_set_request_line(), OSSL_HTTP_REQ_CTX_add1_header(), OSSL_HTTP_REQ_CTX_set1_req(), and OSSL_HTTP_REQ_CTX_set_expected() return 1 for success and 0 for failure.

- -

OSSL_HTTP_REQ_CTX_nbio() and OSSL_HTTP_REQ_CTX_nbio_d2i() return 1 for success, 0 on error or redirection, -1 if retry is needed.

- -

OSSL_HTTP_REQ_CTX_exchange() and OSSL_HTTP_REQ_CTX_get0_mem_bio() return a pointer to a BIO on success as described above or NULL on failure. The returned BIO must not be freed by the caller.

- -

OSSL_HTTP_REQ_CTX_get_resp_len() returns the size of the response contents or 0 if not available or an error occurred.

- -

OSSL_HTTP_is_alive() returns 1 if its argument is non-NULL and the client requested a persistent connection and the server did not disagree on keeping the connection open, else 0.

- -

SEE ALSO

- -

BIO_should_retry(3), BIO_wait(3), ASN1_item_d2i_bio(3), ASN1_item_i2d_mem_bio(3), OSSL_HTTP_open(3), OSSL_HTTP_get(3), OSSL_HTTP_transfer(3), OSSL_HTTP_close(3), OSSL_trace_enabled(3), and openssl-env(7).

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_parse_url.html b/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_parse_url.html deleted file mode 100644 index 6fcd754a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_parse_url.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -OSSL_HTTP_parse_url - - - - - - - - - - -

NAME

- -

OSSL_HTTP_adapt_proxy, OSSL_parse_url, OSSL_HTTP_parse_url, OCSP_parse_url - http utility functions

- -

SYNOPSIS

- -
#include <openssl/http.h>
-
-const char *OSSL_HTTP_adapt_proxy(const char *proxy, const char *no_proxy,
-                                  const char *server, int use_ssl);
-
-int OSSL_parse_url(const char *url, char **pscheme, char **puser, char **phost,
-                   char **pport, int *pport_num,
-                   char **ppath, char **pquery, char **pfrag);
-int OSSL_HTTP_parse_url(const char *url,
-                        int *pssl, char **puser, char **phost,
-                        char **pport, int *pport_num,
-                        char **ppath, char **pquery, char **pfrag);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int OCSP_parse_url(const char *url, char **phost, char **pport, char **ppath,
-                   int *pssl);
- -

DESCRIPTION

- -

OSSL_HTTP_adapt_proxy() takes an optional proxy hostname proxy and returns it transformed according to the optional no_proxy parameter, server, use_ssl, and the applicable environment variable, as follows. If proxy is NULL, take any default value from the http_proxy environment variable, or from https_proxy if use_ssl is nonzero. If this still does not yield a proxy hostname, take any further default value from the HTTP_PROXY environment variable, or from HTTPS_PROXY if use_ssl is nonzero. If no_proxy is NULL, take any default exclusion value from the no_proxy environment variable, or else from NO_PROXY. Return the determined proxy host unless the exclusion value, which is a list of proxy hosts separated by , and/or whitespace, contains server. Otherwise return NULL. When server is a string delimited by [ and ], which are used for IPv6 addresses, the enclosing [ and ] are stripped prior to comparison.

- -

OSSL_parse_url() parses its input string url as a URL of the form [scheme://][userinfo@]host[:port][/path][?query][#fragment] and splits it up into scheme, userinfo, host, port, path, query, and fragment components. The host (or server) component may be a DNS name or an IP address where IPv6 addresses must be enclosed in square brackets [ and ]. The port component is optional and defaults to 0. If given, it must be in decimal form. If the pport_num argument is not NULL the integer value of the port number is assigned to *pport_num on success. The path component is also optional and defaults to /. Each non-NULL result pointer argument pscheme, puser, phost, pport, ppath, pquery, and pfrag, is assigned the respective url component. Any IPv6 address in *phost is enclosed in [ and ]. On success, they are guaranteed to contain non-NULL string pointers, else NULL. It is the responsibility of the caller to free them using OPENSSL_free(3). If pquery is NULL, any given query component is handled as part of the path. A string returned via *ppath is guaranteed to begin with a / character. For absent scheme, userinfo, port, query, and fragment components an empty string is provided.

- -

OSSL_HTTP_parse_url() is a special form of OSSL_parse_url() where the scheme, if given, must be http or https. If pssl is not NULL, *pssl is assigned 1 in case parsing was successful and the scheme is https, else 0. The port component is optional and defaults to 443 if the scheme is https, else 80. Note that relative paths must be given with a leading /, otherwise the first path element is interpreted as the host.

- -

Calling the deprecated function OCSP_parse_url(url, host, port, path, ssl) is equivalent to OSSL_HTTP_parse_url(url, ssl, NULL, host, port, NULL, path, NULL, NULL).

- -

RETURN VALUES

- -

OSSL_HTTP_adapt_proxy() returns NULL if no proxy is to be used, otherwise a constant proxy hostname string, which is either the proxy name handed in or an environment variable value.

- -

OSSL_parse_url(), OSSL_HTTP_parse_url(), and OCSP_parse_url() return 1 on success, 0 on error.

- -

SEE ALSO

- -

OSSL_HTTP_transfer(3)

- -

HISTORY

- -

OSSL_HTTP_adapt_proxy(), OSSL_parse_url() and OSSL_HTTP_parse_url() were added in OpenSSL 3.0. OCSP_parse_url() was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_transfer.html b/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_transfer.html deleted file mode 100644 index 7385c553..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_HTTP_transfer.html +++ /dev/null @@ -1,167 +0,0 @@ - - - - -OSSL_HTTP_transfer - - - - - - - - - - -

NAME

- -

OSSL_HTTP_open, OSSL_HTTP_bio_cb_t, OSSL_HTTP_proxy_connect, OSSL_HTTP_set1_request, OSSL_HTTP_exchange, OSSL_HTTP_get, OSSL_HTTP_transfer, OSSL_HTTP_close - HTTP client high-level functions

- -

SYNOPSIS

- -
#include <openssl/http.h>
-
-typedef BIO *(*OSSL_HTTP_bio_cb_t)(BIO *bio, void *arg,
-                                   int connect, int detail);
-OSSL_HTTP_REQ_CTX *OSSL_HTTP_open(const char *server, const char *port,
-                                  const char *proxy, const char *no_proxy,
-                                  int use_ssl, BIO *bio, BIO *rbio,
-                                  OSSL_HTTP_bio_cb_t bio_update_fn, void *arg,
-                                  int buf_size, int overall_timeout);
-int OSSL_HTTP_proxy_connect(BIO *bio, const char *server, const char *port,
-                            const char *proxyuser, const char *proxypass,
-                            int timeout, BIO *bio_err, const char *prog);
-int OSSL_HTTP_set1_request(OSSL_HTTP_REQ_CTX *rctx, const char *path,
-                           const STACK_OF(CONF_VALUE) *headers,
-                           const char *content_type, BIO *req,
-                           const char *expected_content_type, int expect_asn1,
-                           size_t max_resp_len, int timeout, int keep_alive);
-BIO *OSSL_HTTP_exchange(OSSL_HTTP_REQ_CTX *rctx, char **redirection_url);
-BIO *OSSL_HTTP_get(const char *url, const char *proxy, const char *no_proxy,
-                   BIO *bio, BIO *rbio,
-                   OSSL_HTTP_bio_cb_t bio_update_fn, void *arg,
-                   int buf_size, const STACK_OF(CONF_VALUE) *headers,
-                   const char *expected_content_type, int expect_asn1,
-                   size_t max_resp_len, int timeout);
-BIO *OSSL_HTTP_transfer(OSSL_HTTP_REQ_CTX **prctx,
-                        const char *server, const char *port,
-                        const char *path, int use_ssl,
-                        const char *proxy, const char *no_proxy,
-                        BIO *bio, BIO *rbio,
-                        OSSL_HTTP_bio_cb_t bio_update_fn, void *arg,
-                        int buf_size, const STACK_OF(CONF_VALUE) *headers,
-                        const char *content_type, BIO *req,
-                        const char *expected_content_type, int expect_asn1,
-                        size_t max_resp_len, int timeout, int keep_alive);
-int OSSL_HTTP_close(OSSL_HTTP_REQ_CTX *rctx, int ok);
- -

DESCRIPTION

- -

OSSL_HTTP_open() initiates an HTTP session using the bio argument if not NULL, else by connecting to a given server optionally via a proxy.

- -

Typically the OpenSSL build supports sockets and the bio parameter is NULL. In this case rbio must be NULL as well and the server must be non-NULL. The function creates a network BIO internally using BIO_new_connect(3) for connecting to the given server and the optionally given port, defaulting to 80 for HTTP or 443 for HTTPS. Then this internal BIO is used for setting up a connection and for exchanging one or more request and response.

- -

If bio is given and rbio is NULL then this bio is used instead. If both bio and rbio are given (which may be memory BIOs for instance) then no explicit connection is set up, but bio is used for writing requests and rbio for reading responses. As soon as the client has flushed bio the server must be ready to provide a response or indicate a waiting condition via rbio.

- -

If bio is given, it is an error to provide non-NULL proxy or no_proxy arguments, while server and port arguments may be given to support diagnostic output. If bio is NULL the optional proxy parameter can be used to set an HTTP(S) proxy to use (unless overridden by "no_proxy" settings). If TLS is not used this defaults to the environment variable http_proxy if set, else HTTP_PROXY. If use_ssl != 0 it defaults to https_proxy if set, else HTTPS_PROXY. An empty proxy string "" forbids using a proxy. Otherwise, the format is [http[s]://][userinfo@]host[:port][/path][?query][#fragment], where any userinfo, path, query, and fragment given is ignored. If the host string is an IPv6 address, it must be enclosed in [ and ]. The default proxy port number is 80, or 443 in case "https:" is given. The HTTP client functions connect via the given proxy unless the server is found in the optional list no_proxy of proxy hostnames or IP addresses separated by , and/or whitespace (if not NULL; default is the environment variable no_proxy if set, else NO_PROXY). Proxying plain HTTP is supported directly, while using a proxy for HTTPS connections requires a suitable callback function such as OSSL_HTTP_proxy_connect(), described below.

- -

If use_ssl is nonzero a TLS connection is requested and the bio_update_fn parameter must be provided.

- -

The parameter bio_update_fn, which is optional if use_ssl is 0, may be used to modify the connection BIO used by the HTTP client, but cannot be used when both bio and rbio are given. bio_update_fn is a BIO connect/disconnect callback function with prototype

- -
BIO *(*OSSL_HTTP_bio_cb_t)(BIO *bio, void *arg, int connect, int detail)
- -

The callback function may modify the BIO provided in the bio argument, whereby it may use an optional custom defined argument arg, which can for instance point to an SSL_CTX structure. During connection establishment, just after calling BIO_do_connect_retry(), the callback function is invoked with the connect argument being 1 and detail being 1 if use_ssl is nonzero (i.e., HTTPS is requested), else 0. On disconnect connect is 0 and detail is 1 if no error occurred, else 0. For instance, on connect the callback may push an SSL BIO to implement HTTPS; after disconnect it may do some diagnostic output and pop and free the SSL BIO.

- -

The callback function must return either the potentially modified BIO bio or NULL to indicate failure, in which case it should not modify the BIO.

- -

Here is a simple example that supports TLS connections (but not via a proxy):

- -
BIO *http_tls_cb(BIO *bio, void *arg, int connect, int detail)
-{
-    if (connect && detail) { /* connecting with TLS */
-        SSL_CTX *ctx = (SSL_CTX *)arg;
-        BIO *sbio = BIO_new_ssl(ctx, 1);
-
-        bio = sbio != NULL ? BIO_push(sbio, bio) : NULL;
-    } else if (!connect) { /* disconnecting */
-        BIO *hbio;
-
-        if (!detail) { /* an error has occurred */
-            /* optionally add diagnostics here */
-        }
-        BIO_ssl_shutdown(bio);
-        hbio = BIO_pop(bio);
-        BIO_free(bio); /* SSL BIO */
-        bio = hbio;
-    }
-    return bio;
-}
- -

After disconnect the modified BIO will be deallocated using BIO_free_all(). The optional callback function argument arg is not consumed, so must be freed by the caller when not needed any more.

- -

The buf_size parameter specifies the response header maximum line length. A value <= 0 means that the OSSL_HTTP_DEFAULT_MAX_LINE_LEN (4KiB) is used. buf_size is also used as the number of content bytes that are read at a time.

- -

If the overall_timeout parameter is > 0 this indicates the maximum number of seconds the overall HTTP transfer (i.e., connection setup if needed, sending requests, and receiving responses) is allowed to take until completion. A value <= 0 enables waiting indefinitely, i.e., no timeout.

- -

OSSL_HTTP_proxy_connect() may be used by an above BIO connect callback function to set up an SSL/TLS connection via an HTTPS proxy. It promotes the given BIO bio representing a connection pre-established with a TLS proxy using the HTTP CONNECT method, optionally using proxy client credentials proxyuser and proxypass, to connect with TLS protection ultimately to server and port. If the port argument is NULL or the empty string it defaults to "443". If the timeout parameter is > 0 this indicates the maximum number of seconds the connection setup is allowed to take. A value <= 0 enables waiting indefinitely, i.e., no timeout. Since this function is typically called by applications such as openssl-s_client(1) it uses the bio_err and prog parameters (unless NULL) to print additional diagnostic information in a user-oriented way.

- -

OSSL_HTTP_set1_request() sets up in rctx the request header and content data and expectations on the response using the following parameters. If <rctx> indicates using a proxy for HTTP (but not HTTPS), the server host (and optionally port) needs to be placed in the header; thus it must be present in rctx. For backward compatibility, the server (and optional port) may also be given in the path argument beginning with http:// (thus giving an absoluteURI). If path is NULL it defaults to "/". If req is NULL the HTTP GET method will be used to send the request else HTTP POST with the contents of req and optional content_type, where the length of the data in req does not need to be determined in advance: the BIO will be read on-the-fly while sending the request, which supports streaming. The optional list headers may contain additional custom HTTP header lines.

- -

If the expected_content_type argument is not NULL, the client will check that the specified content-type string is included in the HTTP header of the response and return an error if not. In the content-type header line the specified string should be present either as a whole, or in case the specified string does not include a ; character, it is sufficient that the specified string appears as a prefix in the header line, followed by a ; character and any further text. For instance, if expected_content_type specifies text/html, this is matched by text/html, text/html; charset=UTF-8, etc.

- -

If the expect_asn1 parameter is nonzero, a structure in ASN.1 encoding will be expected as response content. The max_resp_len parameter specifies the maximum allowed response content length, where the value 0 indicates no limit. If the timeout parameter is > 0 this indicates the maximum number of seconds the subsequent HTTP transfer (sending the request and receiving a response) is allowed to take. A value of 0 enables waiting indefinitely, i.e., no timeout. A value < 0 indicates that the overall_timeout parameter value given when opening the HTTP transfer will be used instead. If keep_alive is 0 the connection is not kept open after receiving a response, which is the default behavior for HTTP 1.0. If the value is 1 or 2 then a persistent connection is requested. If the value is 2 then a persistent connection is required, i.e., an error occurs in case the server does not grant it.

- -

OSSL_HTTP_exchange() exchanges any form of HTTP request and response as specified by rctx, which must include both connection and request data, typically set up using OSSL_HTTP_open() and OSSL_HTTP_set1_request(). It implements the core of the functions described below. If the HTTP method is GET and redirection_url is not NULL the latter pointer is used to provide any new location that the server may return with HTTP code 301 (MOVED_PERMANENTLY) or 302 (FOUND). In this case the function returns NULL and the caller is responsible for deallocating the URL with OPENSSL_free(3). If the response header contains one or more "Content-Length" header lines and/or an ASN.1-encoded response is expected, which should include a total length, the length indications received are checked for consistency and for not exceeding any given maximum response length. If an ASN.1-encoded response is expected, the function returns on success the contents buffered in a memory BIO, which does not support streaming. Otherwise it returns directly the read BIO that holds the response contents, which allows a response of indefinite length and may support streaming. The caller is responsible for freeing the BIO pointer obtained.

- -

OSSL_HTTP_get() uses HTTP GET to obtain data from bio if non-NULL, else from the server contained in the url, and returns it as a BIO. It supports redirection via HTTP status code 301 or 302. It is meant for transfers with a single round trip, so does not support persistent connections. If bio is non-NULL, any host and port components in the url are not used for connecting but the hostname is used, as usual, for the Host header. Any userinfo and fragment components in the url are ignored. Any query component is handled as part of the path component. If the scheme component of the url is https a TLS connection is requested and the bio_update_fn, as described for OSSL_HTTP_open(), must be provided. Also the remaining parameters are interpreted as described for OSSL_HTTP_open() and OSSL_HTTP_set1_request(), respectively. The caller is responsible for freeing the BIO pointer obtained.

- -

OSSL_HTTP_transfer() exchanges an HTTP request and response over a connection managed via prctx without supporting redirection. It combines OSSL_HTTP_open(), OSSL_HTTP_set1_request(), OSSL_HTTP_exchange(), and OSSL_HTTP_close(). If prctx is not NULL it reuses any open connection represented by a non-NULL *prctx. It keeps the connection open if a persistent connection is requested or required and this was granted by the server, else it closes the connection and assigns NULL to *prctx. The remaining parameters are interpreted as described for OSSL_HTTP_open() and OSSL_HTTP_set1_request(), respectively. The caller is responsible for freeing the BIO pointer obtained.

- -

OSSL_HTTP_close() closes the connection and releases rctx. The ok parameter is passed to any BIO update function given during setup as described above for OSSL_HTTP_open(). It must be 1 if no error occurred during the HTTP transfer and 0 otherwise.

- -

NOTES

- -

The names of the environment variables used by this implementation: http_proxy, HTTP_PROXY, https_proxy, HTTPS_PROXY, no_proxy, and NO_PROXY, have been chosen for maximal compatibility with other HTTP client implementations such as wget, curl, and git.

- -

When built with tracing enabled, OSSL_HTTP_transfer() and all functions using it may be traced using OSSL_TRACE_CATEGORY_HTTP. See also OSSL_trace_enabled(3) and openssl-env(7).

- -

RETURN VALUES

- -

OSSL_HTTP_open() returns on success a OSSL_HTTP_REQ_CTX, else NULL.

- -

OSSL_HTTP_proxy_connect() and OSSL_HTTP_set1_request() return 1 on success, 0 on error.

- -

On success, OSSL_HTTP_exchange(), OSSL_HTTP_get(), and OSSL_HTTP_transfer() return a memory BIO that buffers all the data received if an ASN.1-encoded response is expected, otherwise a BIO that may support streaming. The BIO must be freed by the caller. On failure, they return NULL. Failure conditions include connection/transfer timeout, parse errors, etc. The caller is responsible for freeing the BIO pointer obtained.

- -

OSSL_HTTP_close() returns 0 if anything went wrong while disconnecting, else 1.

- -

SEE ALSO

- -

OSSL_HTTP_parse_url(3), BIO_new_connect(3), ASN1_item_i2d_mem_bio(3), ASN1_item_d2i_bio(3), OSSL_HTTP_is_alive(3), OSSL_trace_enabled(3), and openssl-env(7).

- -

HISTORY

- -

All the functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX.html b/openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX.html deleted file mode 100644 index 96853b4c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -OSSL_IETF_ATTR_SYNTAX - - - - - - - - - - -

NAME

- -

OSSL_IETF_ATTR_SYNTAX, OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority, OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority, OSSL_IETF_ATTR_SYNTAX_get_value_num, OSSL_IETF_ATTR_SYNTAX_get0_value, OSSL_IETF_ATTR_SYNTAX_add1_value - Accessors and setters for OSSL_IETF_ATTR_SYNTAX

- -

SYNOPSIS

- -
#include <openssl/x509_acert.h>
-
-typedef struct OSSL_IETF_ATTR_SYNTAX_st OSSL_IETF_ATTR_SYNTAX;
-
-const GENERAL_NAMES *
-OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority(const OSSL_IETF_ATTR_SYNTAX *a);
-void OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority(OSSL_IETF_ATTR_SYNTAX *a,
-                                                GENERAL_NAMES *names);
-
-int OSSL_IETF_ATTR_SYNTAX_get_value_num(const OSSL_IETF_ATTR_SYNTAX *a);
-void *OSSL_IETF_ATTR_SYNTAX_get0_value(const OSSL_IETF_ATTR_SYNTAX *a,
-                                       int ind, int *type);
-int OSSL_IETF_ATTR_SYNTAX_add1_value(OSSL_IETF_ATTR_SYNTAX *a, int type,
-                                     void *data);
- -

DESCRIPTION

- -

OSSL_IETF_ATTR_SYNTAX is an opaque structure that represents the IetfAttrSyntax type defined in RFC 5755 (Section 4.4) for use as an AttributeValue.

- -

OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority() and OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority() get and set the policyAuthority field of the structure. Both routines act on internal pointers of the structure and must not be freed by the application.

- -

An OSSL_IETF_ATTR_SYNTAX object also holds a sequence of values. OSSL_IETF_ATTR_SYNTAX_get_value_num() returns the number of values in the sequence. OSSL_IETF_ATTR_SYNTAX_add1_value(), adds a copy of data of a specified type to the sequence. The caller should free the data after use.

- -

OSSL_IETF_ATTR_SYNTAX_get0_value() will return the value and a specific index ind in the sequence or NULL on error. If type is not NULL, the type of the value will be written to this location.

- -

The type of the values stored in the OSSL_IETF_ATTR_SYNTAX value sequence is one of the following:

- -
- -
OSSL_IETFAS_OCTETS
-
- -

A pointer to an ASN1_OCTET_STRING

- -
-
OSSL_IETFAS_OID
-
- -

A pointer to an ASN1_OBJECT

- -
-
OSSL_IETFAS_STRING
-
- -

A pointer to an ASN1_UTF8STRING

- -
-
- -

RETURN VALUES

- -

OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority() returns an pointer to a GENERAL_NAMES structure or NULL if the policy authority has not been set.

- -

OSSL_IETF_ATTR_SYNTAX_get_value_num() returns the number of entries in the value sequence or -1 on error.

- -

OSSL_IETF_ATTR_SYNTAX_get0_value() returns a pointer to the value at the given index or NULL if the index is out of range.

- -

OSSL_IETF_ATTR_SYNTAX_add1_value() returns 1 on success and 0 on failure.

- -

HISTORY

- -

OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority(), OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority(), OSSL_IETF_ATTR_SYNTAX_get_value_num(), OSSL_IETF_ATTR_SYNTAX_get0_value(), and OSSL_IETF_ATTR_SYNTAX_add1_value() were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX_print.html b/openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX_print.html deleted file mode 100644 index 79f56ab0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_IETF_ATTR_SYNTAX_print.html +++ /dev/null @@ -1,62 +0,0 @@ - - - - -OSSL_IETF_ATTR_SYNTAX_print - - - - - - - - - - -

NAME

- -

OSSL_IETF_ATTR_SYNTAX_print - OSSL_IETF_ATTR_SYNTAX printing

- -

SYNOPSIS

- -
#include <openssl/x509_acert.h>
-
-int OSSL_IETF_ATTR_SYNTAX_print(BIO *bp, OSSL_IETF_ATTR_SYNTAX *a,
-                                int indent);
- -

DESCRIPTION

- -

OSSL_IETF_ATTR_SYNTAX_print() prints a human readable version of a to BIO bp. Each line of the output is indented by indent spaces.

- -

RETURN VALUES

- -

OSSL_IETF_ATTR_SYNTAX_print() return 1 on success or 0 on failure.

- -

SEE ALSO

- -

ASN1_STRING_print_ex(3)

- -

HISTORY

- -

OSSL_IETF_ATTR_SYNTAX_print() was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_INDICATOR_set_callback.html b/openssl-install/share/doc/openssl/html/man3/OSSL_INDICATOR_set_callback.html deleted file mode 100644 index 9a9d5f8c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_INDICATOR_set_callback.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -OSSL_INDICATOR_set_callback - - - - - - - - - - -

NAME

- -

OSSL_INDICATOR_set_callback, OSSL_INDICATOR_get_callback - specify a callback for FIPS indicators

- -

SYNOPSIS

- -
#include <openssl/indicator.h>
- -

typedef int (OSSL_INDICATOR_CALLBACK)(const char *type, const char *desc, const OSSL_PARAM params[]);

- -
void OSSL_INDICATOR_set_callback(OSSL_LIB_CTX *libctx,
-                                 OSSL_INDICATOR_CALLBACK *cb);
-void OSSL_INDICATOR_get_callback(OSSL_LIB_CTX *libctx,
-                                 OSSL_INDICATOR_CALLBACK **cb);
- -

DESCRIPTION

- -

OSSL_INDICATOR_set_callback() sets a user callback cb associated with a libctx that will be called when a non approved FIPS operation is detected.

- -

The user's callback may be triggered multiple times during an algorithm operation to indicate different approved mode checks have failed.

- -

Non approved operations may only occur if the user has deliberately chosen to do so (either by setting a global FIPS configuration option or via an option in an algorithm's operation context).

- -

The user's callback OSSL_INDICATOR_CALLBACK type and desc contain the algorithm type and operation that is not approved. params is not currently used.

- -

If the user callback returns 0, an error will occur in the caller. This can be used for testing purposes.

- -

RETURN VALUES

- -

OSSL_INDICATOR_get_callback() returns the callback that has been set via OSSL_INDICATOR_set_callback() for the given library context libctx, or NULL if no callback is currently set.

- -

EXAMPLES

- -

A simple indicator callback to log non approved FIPS operations

- -
 static int indicator_cb(const char *type, const char *desc,
-                         const OSSL_PARAM params[])
- {
-     if (type != NULL && desc != NULL)
-         fprintf(stdout, "%s %s is not approved\n", type, desc);
-end:
-     /* For Testing purposes you could return 0 here to cause an error */
-     return 1;
- }
-
- OSSL_INDICATOR_set_callback(libctx, indicator_cb);
- -

SEE ALSO

- -

openssl-core.h(7), OSSL_PROVIDER-FIPS(7) OSSL_LIB_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_ITEM.html b/openssl-install/share/doc/openssl/html/man3/OSSL_ITEM.html deleted file mode 100644 index 99e30ec0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_ITEM.html +++ /dev/null @@ -1,62 +0,0 @@ - - - - -OSSL_ITEM - - - - - - - - - - -

NAME

- -

OSSL_ITEM - OpenSSL Core type for generic itemized data

- -

SYNOPSIS

- -
#include <openssl/core.h>
-
-typedef struct ossl_item_st OSSL_ITEM;
-struct ossl_item_st {
-    unsigned int id;
-    void *ptr;
-};
- -

DESCRIPTION

- -

This type is a tuple of integer and pointer. It's a generic type used as a generic descriptor, its exact meaning being defined by how it's used. Arrays of this type are passed between the OpenSSL libraries and the providers, and must be terminated with a tuple where the integer is zero and the pointer NULL.

- -

This is currently mainly used for the return value of the provider's error reason strings array, see "Provider Functions" in provider-base(7).

- -

SEE ALSO

- -

crypto(7), provider-base(7), openssl-core.h(7)

- -

HISTORY

- -

OSSL_ITEM was added in OpenSSL 3.0

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX.html b/openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX.html deleted file mode 100644 index 05da7b8f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -OSSL_LIB_CTX - - - - - - - - - - -

NAME

- -

OSSL_LIB_CTX, OSSL_LIB_CTX_get_data, OSSL_LIB_CTX_new, OSSL_LIB_CTX_new_from_dispatch, OSSL_LIB_CTX_new_child, OSSL_LIB_CTX_free, OSSL_LIB_CTX_load_config, OSSL_LIB_CTX_get0_global_default, OSSL_LIB_CTX_set0_default - OpenSSL library context

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-typedef struct ossl_lib_ctx_st OSSL_LIB_CTX;
-
-OSSL_LIB_CTX *OSSL_LIB_CTX_new(void);
-OSSL_LIB_CTX *OSSL_LIB_CTX_new_from_dispatch(const OSSL_CORE_HANDLE *handle,
-                                             const OSSL_DISPATCH *in);
-OSSL_LIB_CTX *OSSL_LIB_CTX_new_child(const OSSL_CORE_HANDLE *handle,
-                                     const OSSL_DISPATCH *in);
-int OSSL_LIB_CTX_load_config(OSSL_LIB_CTX *ctx, const char *config_file);
-void OSSL_LIB_CTX_free(OSSL_LIB_CTX *ctx);
-OSSL_LIB_CTX *OSSL_LIB_CTX_get0_global_default(void);
-OSSL_LIB_CTX *OSSL_LIB_CTX_set0_default(OSSL_LIB_CTX *ctx);
-void *OSSL_LIB_CTX_get_data(OSSL_LIB_CTX *ctx, int index);
- -

DESCRIPTION

- -

OSSL_LIB_CTX is an internal OpenSSL library context type. Applications may allocate their own, but may also use NULL to use a default context with functions that take an OSSL_LIB_CTX argument.

- -

When a non default library context is in use care should be taken with multi-threaded applications to properly clean up thread local resources before the OSSL_LIB_CTX is freed. See OPENSSL_thread_stop_ex(3) for more information.

- -

OSSL_LIB_CTX_new() creates a new OpenSSL library context.

- -

OSSL_LIB_CTX_new_from_dispatch() creates a new OpenSSL library context initialised to use callbacks from the OSSL_DISPATCH structure. This is primarily useful for provider authors. The handle and dispatch structure arguments passed should be the same ones as passed to a provider's OSSL_provider_init function. Some OpenSSL functions, such as BIO_new_from_core_bio(3), require the library context to be created in this way in order to work.

- -

OSSL_LIB_CTX_new_child() is only useful to provider authors and does the same thing as OSSL_LIB_CTX_new_from_dispatch() except that it additionally links the new library context to the application library context. The new library context is a full library context in its own right, but will have all the same providers available to it that are available in the application library context (without having to reload them). If the application loads or unloads providers from the application library context then this will be automatically mirrored in the child library context.

- -

In addition providers that are not loaded in the parent library context can be explicitly loaded into the child library context independently from the parent library context. Providers loaded independently in this way will not be mirrored in the parent library context and will not be affected if the parent library context subsequently loads the same provider.

- -

A provider may call the function OSSL_PROVIDER_load(3) with the child library context as required. If the provider already exists due to it being mirrored from the parent library context then it will remain available and its reference count will be increased. If OSSL_PROVIDER_load(3) is called in this way then OSSL_PROVIDER_unload(3) should be subsequently called to decrement the reference count. OSSL_PROVIDER_unload(3) must not be called for a provider in the child library context that did not have an earlier OSSL_PROVIDER_load(3) call for that provider in that child library context.

- -

In addition to providers, a child library context will also mirror the default properties (set via EVP_set_default_properties(3)) from the parent library context. If EVP_set_default_properties(3) is called directly on a child library context then the new properties will override anything from the parent library context and mirroring of the properties will stop.

- -

When OSSL_LIB_CTX_new_child() is called from within the scope of a provider's OSSL_provider_init function the currently initialising provider is not yet available in the application's library context and therefore will similarly not yet be available in the newly constructed child library context. As soon as the OSSL_provider_init function returns then the new provider is available in the application's library context and will be similarly mirrored in the child library context.

- -

OSSL_LIB_CTX_load_config() loads a configuration file using the given ctx. This can be used to associate a library context with providers that are loaded from a configuration. This function must not be called concurrently from multiple threads on a single ctx.

- -

OSSL_LIB_CTX_free() frees the given ctx, unless it happens to be the default OpenSSL library context. If the argument is NULL, nothing is done.

- -

OSSL_LIB_CTX_get0_global_default() returns a concrete (non NULL) reference to the global default library context.

- -

OSSL_LIB_CTX_set0_default() sets the default OpenSSL library context to be ctx in the current thread. The previous default library context is returned. Care should be taken by the caller to restore the previous default library context with a subsequent call of this function. If ctx is NULL then no change is made to the default library context, but a pointer to the current library context is still returned. On a successful call of this function the returned value will always be a concrete (non NULL) library context.

- -

Care should be taken when changing the default library context and starting async jobs (see ASYNC_start_job(3)), as the default library context when the job is started will be used throughout the lifetime of an async job, no matter how the calling thread makes further default library context changes in the mean time. This means that the calling thread must not free the library context that was the default at the start of the async job before that job has finished.

- -

OSSL_LIB_CTX_get_data() returns a memory address whose interpretation depends on the index. The index argument refers to a context member which is to be retrieved. The values for index are all private to OpenSSL currently and so applications should not typically call this function. If ctx is NULL then the function operates on the default library context. OSSL_LIB_CTX_get_data() returns a memory address whose interpretation depends on the index.

- -

RETURN VALUES

- -

OSSL_LIB_CTX_new(), OSSL_LIB_CTX_get0_global_default() and OSSL_LIB_CTX_set0_default() return a library context pointer on success, or NULL on error.

- -

OSSL_LIB_CTX_free() doesn't return any value.

- -

OSSL_LIB_CTX_load_config() returns 1 on success, 0 on error.

- -

OSSL_LIB_CTX_get_data() returns a memory address whose interpretation depends on the index.

- -

HISTORY

- -

All of the functions described on this page were added in OpenSSL 3.0.

- -

OSSL_LIB_CTX_get_data() was introduced in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX_set_conf_diagnostics.html b/openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX_set_conf_diagnostics.html deleted file mode 100644 index 2d193895..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_LIB_CTX_set_conf_diagnostics.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -OSSL_LIB_CTX_set_conf_diagnostics - - - - - - - - - - -

NAME

- -

OSSL_LIB_CTX_set_conf_diagnostics, OSSL_LIB_CTX_get_conf_diagnostics - Set and get configuration diagnostics

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-void OSSL_LIB_CTX_set_conf_diagnostics(OSSL_LIB_CTX *ctx, int value);
-int OSSL_LIB_CTX_get_conf_diagnostics(OSSL_LIB_CTX *ctx);
- -

DESCRIPTION

- -

OSSL_LIB_CTX_set_conf_diagnostics() sets the value of the configuration diagnostics flag. If value is nonzero subsequent parsing and application of configuration data can report errors that would otherwise be ignored. In particular any errors in the ssl configuration module will cause a failure of SSL_CTX_new(3) and SSL_CTX_new_ex(3) calls. The configuration diagnostics flag can be also set when a configuration file is being loaded into OSSL_LIB_CTX with OSSL_LIB_CTX_load_config(3). If the configuration sets a config_diagnostics value as described in config(5), it will override the value set by OSSL_LIB_CTX_set_conf_diagnostics() before loading the configuration file.

- -

OSSL_LIB_CTX_get_conf_diagnostics() returns the current value of the configuration diagnostics flag.

- -

RETURN VALUES

- -

OSSL_LIB_CTX_get_conf_diagnostics() returns 0 if the configuration diagnostics should not be performed, nonzero otherwise.

- -

SEE ALSO

- -

SSL_CTX_new(3), OSSL_LIB_CTX_load_config(3), config(5)

- -

HISTORY

- -

The functions described on this page were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM.html b/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM.html deleted file mode 100644 index aa99628f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM.html +++ /dev/null @@ -1,314 +0,0 @@ - - - - -OSSL_PARAM - - - - - - - - - - -

NAME

- -

OSSL_PARAM - a structure to pass or request object parameters

- -

SYNOPSIS

- -
#include <openssl/core.h>
-
-typedef struct ossl_param_st OSSL_PARAM;
-struct ossl_param_st {
-    const char *key;             /* the name of the parameter */
-    unsigned int data_type;      /* declare what kind of content is in data */
-    void *data;                  /* value being passed in or out */
-    size_t data_size;            /* data size */
-    size_t return_size;          /* returned size */
-};
- -

DESCRIPTION

- -

OSSL_PARAM is a type that allows passing arbitrary data for some object between two parties that have no or very little shared knowledge about their respective internal structures for that object.

- -

A typical usage example could be an application that wants to set some parameters for an object, or wants to find out some parameters of an object.

- -

Arrays of this type can be used for the following purposes:

- - - -

Normally, the order of the an OSSL_PARAM array is not relevant. However, if the responder can handle multiple elements with the same key, those elements must be handled in the order they are in.

- -

An OSSL_PARAM array must have a terminating element, where key is NULL. The usual full terminating template is:

- -
{ NULL, 0, NULL, 0, 0 }
- -

This can also be specified using OSSL_PARAM_END(3).

- -

Functional support

- -

Libcrypto offers a limited set of helper functions to handle OSSL_PARAM items and arrays, please see OSSL_PARAM_get_int(3). Developers are free to extend or replace those as they see fit.

- -

OSSL_PARAM fields

- -
- -
key
-
- -

The identity of the parameter in the form of a string.

- -

In an OSSL_PARAM array, an item with this field set to NULL is considered a terminating item.

- -
-
data_type
-
- -

The data_type is a value that describes the type and organization of the data. See "Supported types" below for a description of the types.

- -
-
data
-
- -
-
data_size
-
- -

data is a pointer to the memory where the parameter data is (when setting parameters) or shall (when requesting parameters) be stored, and data_size is its size in bytes. The organization of the data depends on the parameter type and flag.

- -

The data_size needs special attention with the parameter type OSSL_PARAM_UTF8_STRING in relation to C strings. When setting parameters, the size should be set to the length of the string, not counting the terminating NUL byte. When requesting parameters, the size should be set to the size of the buffer to be populated, which should accommodate enough space for a terminating NUL byte.

- -

When requesting parameters, it's acceptable for data to be NULL. This can be used by the requester to figure out dynamically exactly how much buffer space is needed to store the parameter data. In this case, data_size is ignored.

- -

When the OSSL_PARAM is used as a parameter descriptor, data should be ignored. If data_size is zero, it means that an arbitrary data size is accepted, otherwise it specifies the maximum size allowed.

- -
-
return_size
-
- -

When an array of OSSL_PARAM is used to request data, the responder must set this field to indicate size of the parameter data, including padding as the case may be. In case the data_size is an unsuitable size for the data, the responder must still set this field to indicate the minimum data size required. (further notes on this in "NOTES" below).

- -

When the OSSL_PARAM is used as a parameter descriptor, return_size should be ignored.

- -
-
- -

NOTE:

- -

The key names and associated types are defined by the entity that offers these parameters, i.e. names for parameters provided by the OpenSSL libraries are defined by the libraries, and names for parameters provided by providers are defined by those providers, except for the pointer form of strings (see data type descriptions below). Entities that want to set or request parameters need to know what those keys are and of what type, any functionality between those two entities should remain oblivious and just pass the OSSL_PARAM array along.

- -

Supported types

- -

The data_type field can be one of the following types:

- -
- -
OSSL_PARAM_INTEGER
-
- -
-
OSSL_PARAM_UNSIGNED_INTEGER
-
- -

The parameter data is an integer (signed or unsigned) of arbitrary length, organized in native form, i.e. most significant byte first on Big-Endian systems, and least significant byte first on Little-Endian systems.

- -
-
OSSL_PARAM_REAL
-
- -

The parameter data is a floating point value in native form.

- -
-
OSSL_PARAM_UTF8_STRING
-
- -

The parameter data is a printable string.

- -
-
OSSL_PARAM_OCTET_STRING
-
- -

The parameter data is an arbitrary string of bytes.

- -
-
OSSL_PARAM_UTF8_PTR
-
- -

The parameter data is a pointer to a printable string.

- -

The difference between this and OSSL_PARAM_UTF8_STRING is that data doesn't point directly at the data, but to a pointer that points to the data.

- -

If there is any uncertainty about which to use, OSSL_PARAM_UTF8_STRING is almost certainly the correct choice.

- -

This is used to indicate that constant data is or will be passed, and there is therefore no need to copy the data that is passed, just the pointer to it.

- -

data_size must be set to the size of the data, not the size of the pointer to the data. If this is used in a parameter request, data_size is not relevant. However, the responder will set return_size to the size of the data.

- -

Note that the use of this type is fragile and can only be safely used for data that remains constant and in a constant location for a long enough duration (such as the life-time of the entity that offers these parameters).

- -
-
OSSL_PARAM_OCTET_PTR
-
- -

The parameter data is a pointer to an arbitrary string of bytes.

- -

The difference between this and OSSL_PARAM_OCTET_STRING is that data doesn't point directly at the data, but to a pointer that points to the data.

- -

If there is any uncertainty about which to use, OSSL_PARAM_OCTET_STRING is almost certainly the correct choice.

- -

This is used to indicate that constant data is or will be passed, and there is therefore no need to copy the data that is passed, just the pointer to it.

- -

data_size must be set to the size of the data, not the size of the pointer to the data. If this is used in a parameter request, data_size is not relevant. However, the responder will set return_size to the size of the data.

- -

Note that the use of this type is fragile and can only be safely used for data that remains constant and in a constant location for a long enough duration (such as the life-time of the entity that offers these parameters).

- -
-
- -

NOTES

- -

Both when setting and requesting parameters, the functions that are called will have to decide what is and what is not an error. The recommended behaviour is:

- - - -

EXAMPLES

- -

A couple of examples to just show how OSSL_PARAM arrays could be set up.

- -

Example 1

- -

This example is for setting parameters on some object:

- -
#include <openssl/core.h>
-
-const char *foo = "some string";
-size_t foo_l = strlen(foo);
-const char bar[] = "some other string";
-OSSL_PARAM set[] = {
-    { "foo", OSSL_PARAM_UTF8_PTR, &foo, foo_l, 0 },
-    { "bar", OSSL_PARAM_UTF8_STRING, (void *)&bar, sizeof(bar) - 1, 0 },
-    { NULL, 0, NULL, 0, 0 }
-};
- -

Example 2

- -

This example is for requesting parameters on some object:

- -
const char *foo = NULL;
-size_t foo_l;
-char bar[1024];
-size_t bar_l;
-OSSL_PARAM request[] = {
-    { "foo", OSSL_PARAM_UTF8_PTR, &foo, 0 /*irrelevant*/, 0 },
-    { "bar", OSSL_PARAM_UTF8_STRING, &bar, sizeof(bar), 0 },
-    { NULL, 0, NULL, 0, 0 }
-};
- -

A responder that receives this array (as params in this example) could fill in the parameters like this:

- -
/* OSSL_PARAM *params */
-
-int i;
-
-for (i = 0; params[i].key != NULL; i++) {
-    if (strcmp(params[i].key, "foo") == 0) {
-        *(char **)params[i].data = "foo value";
-        params[i].return_size = 9; /* length of "foo value" string */
-    } else if (strcmp(params[i].key, "bar") == 0) {
-        memcpy(params[i].data, "bar value", 10);
-        params[i].return_size = 9; /* length of "bar value" string */
-    }
-    /* Ignore stuff we don't know */
-}
- -

SEE ALSO

- -

openssl-core.h(7), OSSL_PARAM_get_int(3), OSSL_PARAM_dup(3), OSSL_PARAM_construct_utf8_string(3)

- -

HISTORY

- -

OSSL_PARAM was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_BLD.html b/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_BLD.html deleted file mode 100644 index 0a3f6843..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_BLD.html +++ /dev/null @@ -1,169 +0,0 @@ - - - - -OSSL_PARAM_BLD - - - - - - - - - - -

NAME

- -

OSSL_PARAM_BLD, OSSL_PARAM_BLD_new, OSSL_PARAM_BLD_to_param, OSSL_PARAM_BLD_free, OSSL_PARAM_BLD_push_int, OSSL_PARAM_BLD_push_uint, OSSL_PARAM_BLD_push_long, OSSL_PARAM_BLD_push_ulong, OSSL_PARAM_BLD_push_int32, OSSL_PARAM_BLD_push_uint32, OSSL_PARAM_BLD_push_int64, OSSL_PARAM_BLD_push_uint64, OSSL_PARAM_BLD_push_size_t, OSSL_PARAM_BLD_push_time_t, OSSL_PARAM_BLD_push_double, OSSL_PARAM_BLD_push_BN, OSSL_PARAM_BLD_push_BN_pad, OSSL_PARAM_BLD_push_utf8_string, OSSL_PARAM_BLD_push_utf8_ptr, OSSL_PARAM_BLD_push_octet_string, OSSL_PARAM_BLD_push_octet_ptr - functions to assist in the creation of OSSL_PARAM arrays

- -

SYNOPSIS

- -
#include <openssl/param_build.h>
-
-typedef struct OSSL_PARAM_BLD;
-
-OSSL_PARAM_BLD *OSSL_PARAM_BLD_new(void);
-OSSL_PARAM *OSSL_PARAM_BLD_to_param(OSSL_PARAM_BLD *bld);
-void OSSL_PARAM_BLD_free(OSSL_PARAM_BLD *bld);
-
-int OSSL_PARAM_BLD_push_TYPE(OSSL_PARAM_BLD *bld, const char *key, TYPE val);
-
-int OSSL_PARAM_BLD_push_BN(OSSL_PARAM_BLD *bld, const char *key,
-                           const BIGNUM *bn);
-int OSSL_PARAM_BLD_push_BN_pad(OSSL_PARAM_BLD *bld, const char *key,
-                               const BIGNUM *bn, size_t sz);
-
-int OSSL_PARAM_BLD_push_utf8_string(OSSL_PARAM_BLD *bld, const char *key,
-                                    const char *buf, size_t bsize);
-int OSSL_PARAM_BLD_push_utf8_ptr(OSSL_PARAM_BLD *bld, const char *key,
-                                 char *buf, size_t bsize);
-int OSSL_PARAM_BLD_push_octet_string(OSSL_PARAM_BLD *bld, const char *key,
-                                     const void *buf, size_t bsize);
-int OSSL_PARAM_BLD_push_octet_ptr(OSSL_PARAM_BLD *bld, const char *key,
-                                  void *buf, size_t bsize);
- -

DESCRIPTION

- -

A collection of utility functions that simplify the creation of OSSL_PARAM arrays. The TYPE names are as per OSSL_PARAM_int(3).

- -

OSSL_PARAM_BLD_new() allocates and initialises a new OSSL_PARAM_BLD structure so that values can be added. Any existing values are cleared.

- -

OSSL_PARAM_BLD_free() deallocates the memory allocates by OSSL_PARAM_BLD_new(). If the argument is NULL, nothing is done.

- -

OSSL_PARAM_BLD_to_param() converts a built up OSSL_PARAM_BLD structure bld into an allocated OSSL_PARAM array. The OSSL_PARAM array and all associated storage must be freed by calling OSSL_PARAM_free() with the functions return value. OSSL_PARAM_BLD_free() can safely be called any time after this function is.

- -

OSSL_PARAM_BLD_push_TYPE() are a series of functions which will create OSSL_PARAM objects of the specified size and correct type for the val argument. val is stored by value and an expression or auto variable can be used.

- -

When TYPE denotes an integer type, signed integer types will normally get the OSSL_PARAM type OSSL_PARAM_INTEGER params. When TYPE denotes an unsigned integer type will get the OSSL_PARAM type OSSL_PARAM_UNSIGNED_INTEGER.

- -

OSSL_PARAM_BLD_push_BN() is a function that will create an OSSL_PARAM object that holds the specified BIGNUM bn. When the bn is zero or positive, its OSSL_PARAM type becomes OSSL_PARAM_UNSIGNED_INTEGER. When the bn is negative, its OSSL_PARAM type becomes OSSL_PARAM_INTEGER. If bn is marked as being securely allocated, its OSSL_PARAM representation will also be securely allocated. The bn argument is stored by reference and the underlying BIGNUM object must exist until after OSSL_PARAM_BLD_to_param() has been called.

- -

OSSL_PARAM_BLD_push_BN_pad() is a function that will create an OSSL_PARAM object that holds the specified BIGNUM bn. The object will be padded to occupy exactly sz bytes, if insufficient space is specified an error results. When the bn is zero or positive, its OSSL_PARAM type becomes OSSL_PARAM_UNSIGNED_INTEGER. When the bn is negative, its OSSL_PARAM type becomes OSSL_PARAM_INTEGER. If bn is marked as being securely allocated, its OSSL_PARAM representation will also be securely allocated. The bn argument is stored by reference and the underlying BIGNUM object must exist until after OSSL_PARAM_BLD_to_param() has been called.

- -

OSSL_PARAM_BLD_push_utf8_string() is a function that will create an OSSL_PARAM object that references the UTF8 string specified by buf. The length of the string bsize should not include the terminating NUL byte. If it is zero then it will be calculated. The string that buf points to is stored by reference and must remain in scope until after OSSL_PARAM_BLD_to_param() has been called.

- -

OSSL_PARAM_BLD_push_octet_string() is a function that will create an OSSL_PARAM object that references the octet string specified by buf and <bsize>. The memory that buf points to is stored by reference and must remain in scope until after OSSL_PARAM_BLD_to_param() has been called.

- -

OSSL_PARAM_BLD_push_utf8_ptr() is a function that will create an OSSL_PARAM object that references the UTF8 string specified by buf. The length of the string bsize should not include the terminating NUL byte. If it is zero then it will be calculated. The string buf points to is stored by reference and must remain in scope until the OSSL_PARAM array is freed.

- -

OSSL_PARAM_BLD_push_octet_ptr() is a function that will create an OSSL_PARAM object that references the octet string specified by buf. The memory buf points to is stored by reference and must remain in scope until the OSSL_PARAM array is freed.

- -

RETURN VALUES

- -

OSSL_PARAM_BLD_new() returns the allocated OSSL_PARAM_BLD structure, or NULL on error.

- -

OSSL_PARAM_BLD_to_param() returns the allocated OSSL_PARAM array, or NULL on error.

- -

All of the OSSL_PARAM_BLD_push_TYPE functions return 1 on success and 0 on error.

- -

NOTES

- -

OSSL_PARAM_BLD_push_BN() and OSSL_PARAM_BLD_push_BN_pad() only support nonnegative BIGNUMs. They return an error on negative BIGNUMs. To pass signed BIGNUMs, use OSSL_PARAM_BLD_push_signed_BN().

- -

EXAMPLES

- -

Both examples creating an OSSL_PARAM array that contains an RSA key. For both, the predefined key variables are:

- -
BIGNUM *n;           /* modulus */
-unsigned int e;      /* public exponent */
-BIGNUM *d;           /* private exponent */
-BIGNUM *p, *q;       /* first two prime factors */
-BIGNUM *dmp1, *dmq1; /* first two CRT exponents */
-BIGNUM *iqmp;        /* first CRT coefficient */
- -

Example 1

- -

This example shows how to create an OSSL_PARAM array that contains an RSA private key.

- -
OSSL_PARAM_BLD *bld = OSSL_PARAM_BLD_new();
-OSSL_PARAM *params = NULL;
-
-if (bld == NULL
-    || !OSSL_PARAM_BLD_push_BN(bld, "n", n)
-    || !OSSL_PARAM_BLD_push_uint(bld, "e", e)
-    || !OSSL_PARAM_BLD_push_BN(bld, "d", d)
-    || !OSSL_PARAM_BLD_push_BN(bld, "rsa-factor1", p)
-    || !OSSL_PARAM_BLD_push_BN(bld, "rsa-factor2", q)
-    || !OSSL_PARAM_BLD_push_BN(bld, "rsa-exponent1", dmp1)
-    || !OSSL_PARAM_BLD_push_BN(bld, "rsa-exponent2", dmq1)
-    || !OSSL_PARAM_BLD_push_BN(bld, "rsa-coefficient1", iqmp)
-    || (params = OSSL_PARAM_BLD_to_param(bld)) == NULL)
-    goto err;
-OSSL_PARAM_BLD_free(bld);
-/* Use params */
-...
-OSSL_PARAM_free(params);
- -

Example 2

- -

This example shows how to create an OSSL_PARAM array that contains an RSA public key.

- -
OSSL_PARAM_BLD *bld = OSSL_PARAM_BLD_new();
-OSSL_PARAM *params = NULL;
-
-if (nld == NULL
-    || !OSSL_PARAM_BLD_push_BN(bld, "n", n)
-    || !OSSL_PARAM_BLD_push_uint(bld, "e", e)
-    || (params = OSSL_PARAM_BLD_to_param(bld)) == NULL)
-    goto err;
-OSSL_PARAM_BLD_free(bld);
-/* Use params */
-...
-OSSL_PARAM_free(params);
- -

SEE ALSO

- -

OSSL_PARAM_int(3), OSSL_PARAM(3), OSSL_PARAM_free(3)

- -

HISTORY

- -

The functions described here were all added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_allocate_from_text.html b/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_allocate_from_text.html deleted file mode 100644 index effb76a1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_allocate_from_text.html +++ /dev/null @@ -1,207 +0,0 @@ - - - - -OSSL_PARAM_allocate_from_text - - - - - - - - - - -

NAME

- -

OSSL_PARAM_allocate_from_text - OSSL_PARAM construction utilities

- -

SYNOPSIS

- -
#include <openssl/params.h>
-
-int OSSL_PARAM_allocate_from_text(OSSL_PARAM *to,
-                                  const OSSL_PARAM *paramdefs,
-                                  const char *key, const char *value,
-                                  size_t value_n,
-                                  int *found);
- -

DESCRIPTION

- -

With OpenSSL before version 3.0, parameters were passed down to or retrieved from algorithm implementations via control functions. Some of these control functions existed in variants that took string parameters, for example EVP_PKEY_CTX_ctrl_str(3).

- -

OpenSSL 3.0 introduces a new mechanism to do the same thing with an array of parameters that contain name, value, value type and value size (see OSSL_PARAM(3) for more information).

- -

OSSL_PARAM_allocate_from_text() uses key to look up an item in paramdefs. If an item was found, it converts value to something suitable for that item's data_type, and stores the result in to->data as well as its size in to->data_size. to->key and to->data_type are assigned the corresponding values from the item that was found, and to->return_size is set to zero.

- -

to->data is always allocated using OPENSSL_zalloc(3) and needs to be freed by the caller when it's not useful any more, using OPENSSL_free(3).

- -

If found is not NULL, *found is set to 1 if key could be located in paramdefs, and to 0 otherwise.

- -

The use of key and value in detail

- -

OSSL_PARAM_allocate_from_text() takes note if key starts with "hex", and will only use the rest of key to look up an item in paramdefs in that case. As an example, if key is "hexid", "id" will be looked up in paramdefs.

- -

When an item in paramdefs has been found, value is converted depending on that item's data_type, as follows:

- -
- -
OSSL_PARAM_INTEGER and OSSL_PARAM_UNSIGNED_INTEGER
-
- -

If key didn't start with "hex", value is assumed to contain value_n decimal characters, which are decoded, and the resulting bytes become the number stored in the to->data storage.

- -

If value starts with "0x", it is assumed to contain value_n hexadecimal characters.

- -

If key started with "hex", value is assumed to contain value_n hexadecimal characters without the "0x" prefix.

- -

If value contains characters that couldn't be decoded as hexadecimal or decimal characters, OSSL_PARAM_allocate_from_text() considers that an error.

- -
-
OSSL_PARAM_UTF8_STRING
-
- -

If key started with "hex", OSSL_PARAM_allocate_from_text() considers that an error.

- -

Otherwise, value is considered a C string and is copied to the to->data storage. On systems where the native character encoding is EBCDIC, the bytes in to->data are converted to ASCII.

- -
-
OSSL_PARAM_OCTET_STRING
-
- -

If key started with "hex", value is assumed to contain value_n hexadecimal characters, which are decoded, and the resulting bytes are stored in the to->data storage. If value contains characters that couldn't be decoded as hexadecimal or decimal characters, OSSL_PARAM_allocate_from_text() considers that an error.

- -

If key didn't start with "hex", value_n bytes from value are copied to the to->data storage.

- -
-
- -

RETURN VALUES

- -

OSSL_PARAM_allocate_from_text() returns 1 if key was found in paramdefs and there was no other failure, otherwise 0.

- -

NOTES

- -

The parameter descriptor array comes from functions dedicated to return them. The following OSSL_PARAM(3) attributes are used:

- -
- -
key
-
- -
-
data_type
-
- -
-
data_size
-
- -
-
- -

All other attributes are ignored.

- -

The data_size attribute can be zero, meaning that the parameter it describes expects arbitrary length data.

- -

EXAMPLES

- -

Code that looked like this:

- -
int mac_ctrl_string(EVP_PKEY_CTX *ctx, const char *value)
-{
-    int rv;
-    char *stmp, *vtmp = NULL;
-
-    stmp = OPENSSL_strdup(value);
-    if (stmp == NULL)
-        return -1;
-    vtmp = strchr(stmp, ':');
-    if (vtmp != NULL)
-        *vtmp++ = '\0';
-    rv = EVP_MAC_ctrl_str(ctx, stmp, vtmp);
-    OPENSSL_free(stmp);
-    return rv;
-}
-
-...
-
-
-for (i = 0; i < sk_OPENSSL_STRING_num(macopts); i++) {
-    char *macopt = sk_OPENSSL_STRING_value(macopts, i);
-
-    if (pkey_ctrl_string(mac_ctx, macopt) <= 0) {
-        BIO_printf(bio_err,
-                   "MAC parameter error \"%s\"\n", macopt);
-        ERR_print_errors(bio_err);
-        goto mac_end;
-    }
-}
- -

Can be written like this instead:

- -
 OSSL_PARAM *params =
-     OPENSSL_zalloc(sizeof(*params)
-                    * (sk_OPENSSL_STRING_num(opts) + 1));
- const OSSL_PARAM *paramdefs = EVP_MAC_settable_ctx_params(mac);
- size_t params_n;
- char *opt = "<unknown>";
-
- for (params_n = 0; params_n < (size_t)sk_OPENSSL_STRING_num(opts);
-      params_n++) {
-     char *stmp, *vtmp = NULL;
-
-     opt = sk_OPENSSL_STRING_value(opts, (int)params_n);
-     if ((stmp = OPENSSL_strdup(opt)) == NULL
-             || (vtmp = strchr(stmp, ':')) == NULL)
-         goto err;
-
-     *vtmp++ = '\0';
-     if (!OSSL_PARAM_allocate_from_text(&params[params_n],
-                                        paramdefs, stmp,
-                                        vtmp, strlen(vtmp), NULL))
-         goto err;
- }
- params[params_n] = OSSL_PARAM_construct_end();
- if (!EVP_MAC_CTX_set_params(ctx, params))
-     goto err;
- while (params_n-- > 0)
-     OPENSSL_free(params[params_n].data);
- OPENSSL_free(params);
- /* ... */
- return;
-
-err:
- BIO_printf(bio_err, "MAC parameter error '%s'\n", opt);
- ERR_print_errors(bio_err);
- -

SEE ALSO

- -

OSSL_PARAM(3), OSSL_PARAM_int(3)

- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_dup.html b/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_dup.html deleted file mode 100644 index 96f67f90..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_dup.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -OSSL_PARAM_dup - - - - - - - - - - -

NAME

- -

OSSL_PARAM_dup, OSSL_PARAM_merge, OSSL_PARAM_free - OSSL_PARAM array copy functions

- -

SYNOPSIS

- -
#include <openssl/params.h>
-
-OSSL_PARAM *OSSL_PARAM_dup(const OSSL_PARAM *params);
-OSSL_PARAM *OSSL_PARAM_merge(const OSSL_PARAM *params, const OSSL_PARAM *params1);
-void OSSL_PARAM_free(OSSL_PARAM *params);
- -

DESCRIPTION

- -

Algorithm parameters can be exported/imported from/to providers using arrays of OSSL_PARAM(3). The following utility functions allow the parameters to be duplicated and merged with other OSSL_PARAM(3) to assist in this process.

- -

OSSL_PARAM_dup() duplicates the parameter array params. This function does a deep copy of the data.

- -

OSSL_PARAM_merge() merges the parameter arrays params and params1 into a new parameter array. If params and params1 contain values with the same 'key' then the value from params1 will replace the param value. This function does a shallow copy of the parameters. Either params or params1 may be NULL. The behaviour of the merge is unpredictable if params and params1 contain the same key, and there are multiple entries within either array that have the same key.

- -

OSSL_PARAM_free() frees the parameter array params that was created using OSSL_PARAM_dup(), OSSL_PARAM_merge() or OSSL_PARAM_BLD_to_param(). If the argument to OSSL_PARAM_free() is NULL, nothing is done.

- -

RETURN VALUES

- -

The functions OSSL_PARAM_dup() and OSSL_PARAM_merge() return a newly allocated OSSL_PARAM(3) array, or NULL if there was an error. If both parameters are NULL then NULL is returned.

- -

SEE ALSO

- -

OSSL_PARAM(3), OSSL_PARAM_BLD(3)

- -

HISTORY

- -

The functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_int.html b/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_int.html deleted file mode 100644 index f335cfed..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_PARAM_int.html +++ /dev/null @@ -1,307 +0,0 @@ - - - - -OSSL_PARAM_int - - - - - - - - - - -

NAME

- -

OSSL_PARAM_double, OSSL_PARAM_int, OSSL_PARAM_int32, OSSL_PARAM_int64, OSSL_PARAM_long, OSSL_PARAM_size_t, OSSL_PARAM_time_t, OSSL_PARAM_uint, OSSL_PARAM_uint32, OSSL_PARAM_uint64, OSSL_PARAM_ulong, OSSL_PARAM_BN, OSSL_PARAM_utf8_string, OSSL_PARAM_octet_string, OSSL_PARAM_utf8_ptr, OSSL_PARAM_octet_ptr, OSSL_PARAM_END, OSSL_PARAM_DEFN, OSSL_PARAM_construct_double, OSSL_PARAM_construct_int, OSSL_PARAM_construct_int32, OSSL_PARAM_construct_int64, OSSL_PARAM_construct_long, OSSL_PARAM_construct_size_t, OSSL_PARAM_construct_time_t, OSSL_PARAM_construct_uint, OSSL_PARAM_construct_uint32, OSSL_PARAM_construct_uint64, OSSL_PARAM_construct_ulong, OSSL_PARAM_construct_BN, OSSL_PARAM_construct_utf8_string, OSSL_PARAM_construct_utf8_ptr, OSSL_PARAM_construct_octet_string, OSSL_PARAM_construct_octet_ptr, OSSL_PARAM_construct_end, OSSL_PARAM_locate, OSSL_PARAM_locate_const, OSSL_PARAM_get_double, OSSL_PARAM_get_int, OSSL_PARAM_get_int32, OSSL_PARAM_get_int64, OSSL_PARAM_get_long, OSSL_PARAM_get_size_t, OSSL_PARAM_get_time_t, OSSL_PARAM_get_uint, OSSL_PARAM_get_uint32, OSSL_PARAM_get_uint64, OSSL_PARAM_get_ulong, OSSL_PARAM_get_BN, OSSL_PARAM_get_utf8_string, OSSL_PARAM_get_octet_string, OSSL_PARAM_get_utf8_ptr, OSSL_PARAM_get_octet_ptr, OSSL_PARAM_get_utf8_string_ptr, OSSL_PARAM_get_octet_string_ptr, OSSL_PARAM_set_double, OSSL_PARAM_set_int, OSSL_PARAM_set_int32, OSSL_PARAM_set_int64, OSSL_PARAM_set_long, OSSL_PARAM_set_size_t, OSSL_PARAM_set_time_t, OSSL_PARAM_set_uint, OSSL_PARAM_set_uint32, OSSL_PARAM_set_uint64, OSSL_PARAM_set_ulong, OSSL_PARAM_set_BN, OSSL_PARAM_set_utf8_string, OSSL_PARAM_set_octet_string, OSSL_PARAM_set_utf8_ptr, OSSL_PARAM_set_octet_ptr, OSSL_PARAM_UNMODIFIED, OSSL_PARAM_modified, OSSL_PARAM_set_all_unmodified - OSSL_PARAM helpers

- -

SYNOPSIS

- -
#include <openssl/params.h>
-
-/*
- * TYPE in function names is one of:
- * double, int, int32, int64, long, size_t, time_t, uint, uint32, uint64, ulong
- * Corresponding TYPE in function arguments is one of:
- * double, int, int32_t, int64_t, long, size_t, time_t, unsigned int, uint32_t,
- * uint64_t, unsigned long
- */
-
-#define OSSL_PARAM_TYPE(key, address)
-#define OSSL_PARAM_BN(key, address, size)
-#define OSSL_PARAM_utf8_string(key, address, size)
-#define OSSL_PARAM_octet_string(key, address, size)
-#define OSSL_PARAM_utf8_ptr(key, address, size)
-#define OSSL_PARAM_octet_ptr(key, address, size)
-#define OSSL_PARAM_END
-
-#define OSSL_PARAM_UNMODIFIED
-
-#define OSSL_PARAM_DEFN(key, type, addr, sz)    \
-   { (key), (type), (addr), (sz), OSSL_PARAM_UNMODIFIED }
-
-OSSL_PARAM OSSL_PARAM_construct_TYPE(const char *key, TYPE *buf);
-OSSL_PARAM OSSL_PARAM_construct_BN(const char *key, unsigned char *buf,
-                                   size_t bsize);
-OSSL_PARAM OSSL_PARAM_construct_utf8_string(const char *key, char *buf,
-                                            size_t bsize);
-OSSL_PARAM OSSL_PARAM_construct_octet_string(const char *key, void *buf,
-                                             size_t bsize);
-OSSL_PARAM OSSL_PARAM_construct_utf8_ptr(const char *key, char **buf,
-                                         size_t bsize);
-OSSL_PARAM OSSL_PARAM_construct_octet_ptr(const char *key, void **buf,
-                                          size_t bsize);
-OSSL_PARAM OSSL_PARAM_construct_end(void);
-
-OSSL_PARAM *OSSL_PARAM_locate(OSSL_PARAM *array, const char *key);
-const OSSL_PARAM *OSSL_PARAM_locate_const(const OSSL_PARAM *array,
-                                          const char *key);
-
-int OSSL_PARAM_get_TYPE(const OSSL_PARAM *p, TYPE *val);
-int OSSL_PARAM_set_TYPE(OSSL_PARAM *p, TYPE val);
-
-int OSSL_PARAM_get_BN(const OSSL_PARAM *p, BIGNUM **val);
-int OSSL_PARAM_set_BN(OSSL_PARAM *p, const BIGNUM *val);
-
-int OSSL_PARAM_get_utf8_string(const OSSL_PARAM *p, char **val,
-                               size_t max_len);
-int OSSL_PARAM_set_utf8_string(OSSL_PARAM *p, const char *val);
-
-int OSSL_PARAM_get_octet_string(const OSSL_PARAM *p, void **val,
-                                size_t max_len, size_t *used_len);
-int OSSL_PARAM_set_octet_string(OSSL_PARAM *p, const void *val, size_t len);
-
-int OSSL_PARAM_get_utf8_ptr(const OSSL_PARAM *p, const char **val);
-int OSSL_PARAM_set_utf8_ptr(OSSL_PARAM *p, const char *val);
-
-int OSSL_PARAM_get_octet_ptr(const OSSL_PARAM *p, const void **val,
-                             size_t *used_len);
-int OSSL_PARAM_set_octet_ptr(OSSL_PARAM *p, const void *val,
-                             size_t used_len);
-
-int OSSL_PARAM_get_utf8_string_ptr(const OSSL_PARAM *p, const char **val);
-int OSSL_PARAM_get_octet_string_ptr(const OSSL_PARAM *p, const void **val,
-                                    size_t *used_len);
-
-int OSSL_PARAM_modified(const OSSL_PARAM *param);
-void OSSL_PARAM_set_all_unmodified(OSSL_PARAM *params);
- -

DESCRIPTION

- -

A collection of utility functions that simplify and add type safety to the OSSL_PARAM(3) arrays. The following TYPE names are supported:

- - - -

OSSL_PARAM_TYPE() are a series of macros designed to assist initialising an array of OSSL_PARAM(3) structures. Each of these macros defines a parameter of the specified TYPE with the provided key and parameter variable address.

- -

OSSL_PARAM_utf8_string(), OSSL_PARAM_octet_string(), OSSL_PARAM_utf8_ptr(), OSSL_PARAM_octet_ptr(), OSSL_PARAM_BN() are macros that provide support for defining UTF8 strings, OCTET strings and big numbers. A parameter with name key is defined. The storage for this parameter is at address and is of size bytes.

- -

OSSL_PARAM_END provides an end of parameter list marker. This should terminate all OSSL_PARAM(3) arrays.

- -

The OSSL_PARAM_DEFN() macro provides the ability to construct a single OSSL_PARAM(3) (typically used in the construction of OSSL_PARAM arrays). The key, type, addr and sz arguments correspond to the key, data_type, data and data_size fields of the OSSL_PARAM(3) structure as described on the OSSL_PARAM(3) page.

- -

OSSL_PARAM_construct_TYPE() are a series of functions that create OSSL_PARAM(3) records dynamically. A parameter with name key is created. The parameter will use storage pointed to by buf and return size of ret.

- -

OSSL_PARAM_construct_BN() is a function that constructs a large integer OSSL_PARAM(3) structure. A parameter with name key, storage buf, size bsize and return size rsize is created.

- -

OSSL_PARAM_construct_utf8_string() is a function that constructs a UTF8 string OSSL_PARAM(3) structure. A parameter with name key, storage buf and size bsize is created. If bsize is zero, the string length is determined using strlen(3). Generally pass zero for bsize instead of calling strlen(3) yourself.

- -

OSSL_PARAM_construct_octet_string() is a function that constructs an OCTET string OSSL_PARAM(3) structure. A parameter with name key, storage buf and size bsize is created.

- -

OSSL_PARAM_construct_utf8_ptr() is a function that constructs a UTF8 string pointer OSSL_PARAM(3) structure. A parameter with name key, storage pointer *buf and size bsize is created.

- -

OSSL_PARAM_construct_octet_ptr() is a function that constructs an OCTET string pointer OSSL_PARAM(3) structure. A parameter with name key, storage pointer *buf and size bsize is created.

- -

OSSL_PARAM_construct_end() is a function that constructs the terminating OSSL_PARAM(3) structure.

- -

OSSL_PARAM_locate() is a function that searches an array of parameters for the one matching the key name.

- -

OSSL_PARAM_locate_const() behaves exactly like OSSL_PARAM_locate() except for the presence of const for the array argument and its return value.

- -

OSSL_PARAM_get_TYPE() retrieves a value of type TYPE from the parameter p. The value is copied to the address val. Type coercion takes place as discussed in the NOTES section.

- -

OSSL_PARAM_set_TYPE() stores a value val of type TYPE into the parameter p. If the parameter's data field is NULL, then only its return_size field will be assigned the size the parameter's data buffer should have. Type coercion takes place as discussed in the NOTES section.

- -

OSSL_PARAM_get_BN() retrieves a BIGNUM from the parameter pointed to by p. The BIGNUM referenced by val is updated and is allocated if *val is NULL.

- -

OSSL_PARAM_set_BN() stores the BIGNUM val into the parameter p. If the parameter's data field is NULL, then only its return_size field will be assigned the size the parameter's data buffer should have.

- -

OSSL_PARAM_get_utf8_string() retrieves a UTF8 string from the parameter pointed to by p. The string is stored into *val with a size limit of max_len, which must be large enough to accommodate a terminating NUL byte, otherwise this function will fail. If *val is NULL, memory is allocated for the string (including the terminating NUL byte) and max_len is ignored. If memory is allocated by this function, it must be freed by the caller.

- -

OSSL_PARAM_set_utf8_string() sets a UTF8 string from the parameter pointed to by p to the value referenced by val. If the parameter's data field isn't NULL, its data_size must indicate that the buffer is large enough to accommodate the string that val points at, not including the terminating NUL byte, or this function will fail. A terminating NUL byte is added only if the parameter's data_size indicates the buffer is longer than the string length, otherwise the string will not be NUL terminated. If the parameter's data field is NULL, then only its return_size field will be assigned the minimum size the parameter's data buffer should have to accommodate the string, not including a terminating NUL byte.

- -

OSSL_PARAM_get_octet_string() retrieves an OCTET string from the parameter pointed to by p. The OCTETs are either stored into *val with a length limit of max_len or, in the case when *val is NULL, memory is allocated and max_len is ignored. *used_len is populated with the number of OCTETs stored. If val is NULL then the OCTETS are not stored, but *used_len is still populated. If memory is allocated by this function, it must be freed by the caller.

- -

OSSL_PARAM_set_octet_string() sets an OCTET string from the parameter pointed to by p to the value referenced by val. If the parameter's data field is NULL, then only its return_size field will be assigned the size the parameter's data buffer should have.

- -

OSSL_PARAM_get_utf8_ptr() retrieves the UTF8 string pointer from the parameter referenced by p and stores it in *val.

- -

OSSL_PARAM_set_utf8_ptr() sets the UTF8 string pointer in the parameter referenced by p to the values val.

- -

OSSL_PARAM_get_octet_ptr() retrieves the OCTET string pointer from the parameter referenced by p and stores it in *val. The length of the OCTET string is stored in *used_len.

- -

OSSL_PARAM_set_octet_ptr() sets the OCTET string pointer in the parameter referenced by p to the values val. The length of the OCTET string is provided by used_len.

- -

OSSL_PARAM_get_utf8_string_ptr() retrieves the pointer to a UTF8 string from the parameter pointed to by p, and stores that pointer in *val. This is different from OSSL_PARAM_get_utf8_string(), which copies the string.

- -

OSSL_PARAM_get_octet_string_ptr() retrieves the pointer to a octet string from the parameter pointed to by p, and stores that pointer in *val, along with the string's length in *used_len. This is different from OSSL_PARAM_get_octet_string(), which copies the string.

- -

The OSSL_PARAM_UNMODIFIED macro is used to detect if a parameter was set. On creation, via either the macros or construct calls, the return_size field is set to this. If the parameter is set using the calls defined herein, the return_size field is changed.

- -

OSSL_PARAM_modified() queries if the parameter param has been set or not using the calls defined herein.

- -

OSSL_PARAM_set_all_unmodified() resets the unused indicator for all parameters in the array params.

- -

RETURN VALUES

- -

OSSL_PARAM_construct_TYPE(), OSSL_PARAM_construct_BN(), OSSL_PARAM_construct_utf8_string(), OSSL_PARAM_construct_octet_string(), OSSL_PARAM_construct_utf8_ptr() and OSSL_PARAM_construct_octet_ptr() return a populated OSSL_PARAM(3) structure.

- -

OSSL_PARAM_locate() and OSSL_PARAM_locate_const() return a pointer to the matching OSSL_PARAM(3) object. They return NULL on error or when no object matching key exists in the array.

- -

OSSL_PARAM_modified() returns 1 if the parameter was set and 0 otherwise.

- -

All other functions return 1 on success and 0 on failure.

- -

NOTES

- -

Native types will be converted as required only if the value is exactly representable by the target type or parameter. Apart from that, the functions must be used appropriately for the expected type of the parameter.

- -

OSSL_PARAM_get_BN() and OSSL_PARAM_set_BN() only support nonnegative BIGNUMs when the desired data type is OSSL_PARAM_UNSIGNED_INTEGER. OSSL_PARAM_construct_BN() currently constructs an OSSL_PARAM(3) structure with the data type OSSL_PARAM_UNSIGNED_INTEGER.

- -

For OSSL_PARAM_construct_utf8_ptr() and OSSL_PARAM_consstruct_octet_ptr(), bsize is not relevant if the purpose is to send the OSSL_PARAM(3) array to a responder, i.e. to get parameter data back. In that case, bsize can safely be given zero. See "DESCRIPTION" in OSSL_PARAM(3) for further information on the possible purposes.

- -

EXAMPLES

- -

Reusing the examples from OSSL_PARAM(3) to just show how OSSL_PARAM(3) arrays can be handled using the macros and functions defined herein.

- -

Example 1

- -

This example is for setting parameters on some object:

- -
#include <openssl/core.h>
-
-const char *foo = "some string";
-size_t foo_l = strlen(foo);
-const char bar[] = "some other string";
-const OSSL_PARAM set[] = {
-    OSSL_PARAM_utf8_ptr("foo", &foo, foo_l),
-    OSSL_PARAM_utf8_string("bar", bar, sizeof(bar) - 1),
-    OSSL_PARAM_END
-};
- -

Example 2

- -

This example is for requesting parameters on some object, and also demonstrates that the requester isn't obligated to request all available parameters:

- -
const char *foo = NULL;
-char bar[1024];
-OSSL_PARAM request[] = {
-    OSSL_PARAM_utf8_ptr("foo", &foo, 0),
-    OSSL_PARAM_utf8_string("bar", bar, sizeof(bar)),
-    OSSL_PARAM_END
-};
- -

A responder that receives this array (as params in this example) could fill in the parameters like this:

- -
/* OSSL_PARAM *params */
-
-OSSL_PARAM *p;
-
-if ((p = OSSL_PARAM_locate(params, "foo")) != NULL)
-    OSSL_PARAM_set_utf8_ptr(p, "foo value");
-if ((p = OSSL_PARAM_locate(params, "bar")) != NULL)
-    OSSL_PARAM_set_utf8_string(p, "bar value");
-if ((p = OSSL_PARAM_locate(params, "cookie")) != NULL)
-    OSSL_PARAM_set_utf8_ptr(p, "cookie value");
- -

Example 3

- -

This example shows a special case where -Wincompatible-pointer-types-discards-qualifiers may be set during compilation. The value for buf cannot be a const char * type string. An alternative in this case would be to use OSSL_PARAM macro abbreviated calls rather than the specific callers which allows you to define the sha1 argument as a standard character array (char[]).

- -

For example, this code:

- -
OSSL_PARAM params[2];
-params[0] = OSSL_PARAM_construct_utf8_string("digest", "SHA1", 0);
-params[1] = OSSL_PARAM_construct_end();
- -

Can be made compatible with the following version:

- -
char sha1[] = "SHA1"; /* sha1 is defined as char[] in this case */
-OSSL_PARAM params[2];
-
-params[0] = OSSL_PARAM_construct_utf8_string("digest", sha1, 0);
-params[1] = OSSL_PARAM_construct_end();
- -

SEE ALSO

- -

openssl-core.h(7), OSSL_PARAM(3)

- -

HISTORY

- -

These APIs were introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_PROVIDER.html b/openssl-install/share/doc/openssl/html/man3/OSSL_PROVIDER.html deleted file mode 100644 index f2439598..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_PROVIDER.html +++ /dev/null @@ -1,188 +0,0 @@ - - - - -OSSL_PROVIDER - - - - - - - - - - -

NAME

- -

OSSL_PROVIDER_set_default_search_path, OSSL_PROVIDER_get0_default_search_path, OSSL_PROVIDER, OSSL_PROVIDER_load, OSSL_PROVIDER_try_load, OSSL_PROVIDER_unload, OSSL_PROVIDER_load_ex, OSSL_PROVIDER_try_load_ex, OSSL_PROVIDER_available, OSSL_PROVIDER_do_all, OSSL_PROVIDER_gettable_params, OSSL_PROVIDER_get_params, OSSL_PROVIDER_query_operation, OSSL_PROVIDER_unquery_operation, OSSL_PROVIDER_get0_provider_ctx, OSSL_PROVIDER_get0_dispatch, OSSL_PROVIDER_add_builtin, OSSL_PROVIDER_get0_name, OSSL_PROVIDER_get_capabilities, OSSL_PROVIDER_self_test - provider routines

- -

SYNOPSIS

- -
#include <openssl/provider.h>
-
-typedef struct ossl_provider_st OSSL_PROVIDER;
-
-int OSSL_PROVIDER_set_default_search_path(OSSL_LIB_CTX *libctx,
-                                          const char *path);
-const char *OSSL_PROVIDER_get0_default_search_path(OSSL_LIB_CTX *libctx);
-
-OSSL_PROVIDER *OSSL_PROVIDER_load(OSSL_LIB_CTX *libctx, const char *name);
-OSSL_PROVIDER *OSSL_PROVIDER_load_ex(OSSL_LIB_CTX *, const char *name,
-                                     OSSL_PARAM *params);
-OSSL_PROVIDER *OSSL_PROVIDER_try_load(OSSL_LIB_CTX *libctx, const char *name,
-                                      int retain_fallbacks);
-OSSL_PROVIDER *OSSL_PROVIDER_try_load_ex(OSSL_LIB_CTX *, const char *name,
-                                         OSSL_PARAM *params,
-                                         int retain_fallbacks);
-int OSSL_PROVIDER_unload(OSSL_PROVIDER *prov);
-int OSSL_PROVIDER_available(OSSL_LIB_CTX *libctx, const char *name);
-int OSSL_PROVIDER_do_all(OSSL_LIB_CTX *ctx,
-                         int (*cb)(OSSL_PROVIDER *provider, void *cbdata),
-                         void *cbdata);
-
-const OSSL_PARAM *OSSL_PROVIDER_gettable_params(OSSL_PROVIDER *prov);
-int OSSL_PROVIDER_get_params(OSSL_PROVIDER *prov, OSSL_PARAM params[]);
-
-const OSSL_ALGORITHM *OSSL_PROVIDER_query_operation(const OSSL_PROVIDER *prov,
-                                                    int operation_id,
-                                                    int *no_cache);
-void OSSL_PROVIDER_unquery_operation(const OSSL_PROVIDER *prov,
-                                     int operation_id,
-                                     const OSSL_ALGORITHM *algs);
-void *OSSL_PROVIDER_get0_provider_ctx(const OSSL_PROVIDER *prov);
-const OSSL_DISPATCH *OSSL_PROVIDER_get0_dispatch(const OSSL_PROVIDER *prov);
-
-int OSSL_PROVIDER_add_builtin(OSSL_LIB_CTX *libctx, const char *name,
-                              ossl_provider_init_fn *init_fn);
-
-const char *OSSL_PROVIDER_get0_name(const OSSL_PROVIDER *prov);
-
-int OSSL_PROVIDER_get_capabilities(const OSSL_PROVIDER *prov,
-                                   const char *capability,
-                                   OSSL_CALLBACK *cb,
-                                   void *arg);
-int OSSL_PROVIDER_self_test(const OSSL_PROVIDER *prov);
- -

DESCRIPTION

- -

OSSL_PROVIDER is a type that holds internal information about implementation providers (see provider(7) for information on what a provider is). A provider can be built in to the application or the OpenSSL libraries, or can be a loadable module. The functions described here handle both forms.

- -

Some of these functions operate within a library context, please see OSSL_LIB_CTX(3) for further details.

- -

Functions

- -

OSSL_PROVIDER_set_default_search_path() specifies the default search path that is to be used for looking for providers in the specified libctx. If left unspecified, an environment variable and a fall back default value will be used instead.

- -

OSSL_PROVIDER_get0_default_search_path() retrieves the default search path that is to be used for looking for providers in the specified libctx. If successful returns the path or empty string; the path is valid until the context is released or OSSL_PROVIDER_set_default_search_path() is called.

- -

OSSL_PROVIDER_add_builtin() is used to add a built in provider to OSSL_PROVIDER store in the given library context, by associating a provider name with a provider initialization function. This name can then be used with OSSL_PROVIDER_load().

- -

OSSL_PROVIDER_load() loads and initializes a provider. This may simply initialize a provider that was previously added with OSSL_PROVIDER_add_builtin() and run its given initialization function, or load a provider module with the given name and run its provider entry point, OSSL_provider_init. The name can be a path to a provider module, in that case the provider name as returned by OSSL_PROVIDER_get0_name() will be the path. Interpretation of relative paths is platform dependent and they are relative to the configured "MODULESDIR" directory or the path set in the environment variable OPENSSL_MODULES if set.

- -

OSSL_PROVIDER_try_load() functions like OSSL_PROVIDER_load(), except that it does not disable the fallback providers if the provider cannot be loaded and initialized or if retain_fallbacks is nonzero. If the provider loads successfully and retain_fallbacks is zero, the fallback providers are disabled.

- -

OSSL_PROVIDER_load_ex() and OSSL_PROVIDER_try_load_ex() are the variants of the previous functions accepting an OSSL_PARAM array of the parameters that are passed as the configuration of the loaded provider. The parameters of any type but OSSL_PARAM_UTF8_STRING are silently ignored. If the parameters are provided, they replace all the ones specified in the configuration file.

- -

OSSL_PROVIDER_unload() unloads the given provider. For a provider added with OSSL_PROVIDER_add_builtin(), this simply runs its teardown function.

- -

OSSL_PROVIDER_available() checks if a named provider is available for use.

- -

OSSL_PROVIDER_do_all() iterates over all loaded providers, calling cb for each one, with the current provider in provider and the cbdata that comes from the caller. If no other provider has been loaded before calling this function, the default provider is still available as fallback. See OSSL_PROVIDER-default(7) for more information on this fallback behaviour.

- -

OSSL_PROVIDER_gettable_params() is used to get a provider parameter descriptor set as a constant OSSL_PARAM(3) array.

- -

OSSL_PROVIDER_get_params() is used to get provider parameter values. The caller must prepare the OSSL_PARAM(3) array before calling this function, and the variables acting as buffers for this parameter array should be filled with data when it returns successfully.

- -

OSSL_PROVIDER_self_test() is used to run a provider's self tests on demand. If the self tests fail then the provider will fail to provide any further services and algorithms. OSSL_SELF_TEST_set_callback(3) may be called beforehand in order to display diagnostics for the running self tests.

- -

OSSL_PROVIDER_query_operation() calls the provider's query_operation function (see provider(7)), if the provider has one. It returns an array of OSSL_ALGORITHM for the given operation_id terminated by an all NULL OSSL_ALGORITHM entry. This is considered a low-level function that most applications should not need to call.

- -

OSSL_PROVIDER_unquery_operation() calls the provider's unquery_operation function (see provider(7)), if the provider has one. This is considered a low-level function that most applications should not need to call.

- -

OSSL_PROVIDER_get0_provider_ctx() returns the provider context for the given provider. The provider context is an opaque handle set by the provider itself and is passed back to the provider by libcrypto in various function calls.

- -

OSSL_PROVIDER_get0_dispatch() returns the provider's dispatch table as it was returned in the out parameter from the provider's init function. See provider-base(7).

- -

If it is permissible to cache references to this array then *no_store is set to 0 or 1 otherwise. If the array is not cacheable then it is assumed to have a short lifetime.

- -

OSSL_PROVIDER_get0_name() returns the name of the given provider.

- -

OSSL_PROVIDER_get_capabilities() provides information about the capabilities supported by the provider specified in prov with the capability name capability. For each capability of that name supported by the provider it will call the callback cb and supply a set of OSSL_PARAM(3)s describing the capability. It will also pass back the argument arg. For more details about capabilities and what they can be used for please see "CAPABILTIIES" in provider-base(7).

- -

RETURN VALUES

- -

OSSL_PROVIDER_set_default_search_path(), OSSL_PROVIDER_add(), OSSL_PROVIDER_unload(), OSSL_PROVIDER_get_params() and OSSL_PROVIDER_get_capabilities() return 1 on success, or 0 on error.

- -

OSSL_PROVIDER_get0_default_search_path() returns a pointer to a path on success, or NULL on error or if the path has not previously been set.

- -

OSSL_PROVIDER_load() and OSSL_PROVIDER_try_load() return a pointer to a provider object on success, or NULL on error.

- -

OSSL_PROVIDER_do_all() returns 1 if the callback cb returns 1 for every provider it is called with, or 0 if any provider callback invocation returns 0; callback processing stops at the first callback invocation on a provider that returns 0.

- -

OSSL_PROVIDER_available() returns 1 if the named provider is available, otherwise 0.

- -

OSSL_PROVIDER_gettable_params() returns a pointer to an array of constant OSSL_PARAM(3), or NULL if none is provided.

- -

OSSL_PROVIDER_get_params() and returns 1 on success, or 0 on error.

- -

OSSL_PROVIDER_query_operation() returns an array of OSSL_ALGORITHM or NULL on error.

- -

OSSL_PROVIDER_self_test() returns 1 if the self tests pass, or 0 on error.

- -

EXAMPLES

- -

This demonstrates how to load the provider module "foo" and ask for its build information.

- -
#include <openssl/params.h>
-#include <openssl/provider.h>
-#include <openssl/err.h>
-
-OSSL_PROVIDER *prov = NULL;
-const char *build = NULL;
-OSSL_PARAM request[] = {
-    { "buildinfo", OSSL_PARAM_UTF8_PTR, &build, 0, 0 },
-    { NULL, 0, NULL, 0, 0 }
-};
-
-if ((prov = OSSL_PROVIDER_load(NULL, "foo")) != NULL
-    && OSSL_PROVIDER_get_params(prov, request))
-    printf("Provider 'foo' buildinfo: %s\n", build);
-else
-    ERR_print_errors_fp(stderr);
- -

SEE ALSO

- -

openssl-core.h(7), OSSL_LIB_CTX(3), provider(7)

- -

HISTORY

- -

The type and functions described here were added in OpenSSL 3.0.

- -

The OSSL_PROVIDER_load_ex and OSSL_PROVIDER_try_load_ex functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_QUIC_client_method.html b/openssl-install/share/doc/openssl/html/man3/OSSL_QUIC_client_method.html deleted file mode 100644 index 09902c4a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_QUIC_client_method.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -OSSL_QUIC_client_method - - - - - - - - - - -

NAME

- -

OSSL_QUIC_client_method, OSSL_QUIC_client_thread_method - Provide SSL_METHOD objects for QUIC enabled functions

- -

SYNOPSIS

- -
#include <openssl/quic.h>
-
-const SSL_METHOD *OSSL_QUIC_client_method(void);
-const SSL_METHOD *OSSL_QUIC_client_thread_method(void);
- -

DESCRIPTION

- -

The OSSL_QUIC_client_method(), OSSL_QUIC_client_thread_method(), and OSSL_QUIC_server_method() functions provide methods for the SSL_CTX_new_ex(3) function to provide QUIC protocol support.

- -

The OSSL_QUIC_client_thread_method() uses threads to allow for a blocking mode of operation and avoid the need to return control to the OpenSSL library for processing time based events. The OSSL_QUIC_client_method() does not use threads and depends on nonblocking mode of operation and the application periodically calling SSL functions.

- -

RETURN VALUES

- -

These functions return pointers to the constant method objects.

- -

SEE ALSO

- -

SSL_CTX_new_ex(3)

- -

HISTORY

- -

OSSL_QUIC_client_method() and OSSL_QUIC_client_thread_method() were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_new.html b/openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_new.html deleted file mode 100644 index c2a0bffc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_new.html +++ /dev/null @@ -1,176 +0,0 @@ - - - - -OSSL_SELF_TEST_new - - - - - - - - - - -

NAME

- -

OSSL_SELF_TEST_new, OSSL_SELF_TEST_free, OSSL_SELF_TEST_onbegin, OSSL_SELF_TEST_oncorrupt_byte, OSSL_SELF_TEST_onend - functionality to trigger a callback during a self test

- -

SYNOPSIS

- -
#include <openssl/self_test.h>
-
-OSSL_SELF_TEST *OSSL_SELF_TEST_new(OSSL_CALLBACK *cb, void *cbarg);
-void OSSL_SELF_TEST_free(OSSL_SELF_TEST *st);
-
-void OSSL_SELF_TEST_onbegin(OSSL_SELF_TEST *st, const char *type,
-                            const char *desc);
-int OSSL_SELF_TEST_oncorrupt_byte(OSSL_SELF_TEST *st, unsigned char *bytes);
-void OSSL_SELF_TEST_onend(OSSL_SELF_TEST *st, int ret);
- -

DESCRIPTION

- -

These methods are intended for use by provider implementers, to display diagnostic information during self testing.

- -

OSSL_SELF_TEST_new() allocates an opaque OSSL_SELF_TEST object that has a callback and callback argument associated with it.

- -

The callback cb may be triggered multiple times by a self test to indicate different phases.

- -

OSSL_SELF_TEST_free() frees the space allocated by OSSL_SELF_TEST_new(). If the argument is NULL, nothing is done.

- -

OSSL_SELF_TEST_onbegin() may be inserted at the start of a block of self test code. It can be used for diagnostic purposes. If this method is called the callback cb will receive the following OSSL_PARAM(3) object.

- -
- -
"st-phase" (OSSL_PROV_PARAM_SELF_TEST_PHASE) <UTF8 string>
-
- -

The value is the string "Start"

- -
-
- -

OSSL_SELF_TEST_oncorrupt_byte() may be inserted just after the known answer is calculated, but before the self test compares the result. The first byte in the passed in array of bytes will be corrupted if the callback returns 0, otherwise it leaves the array unaltered. It can be used for failure testing. The type and desc can be used to identify an individual self test to target for failure testing. If this method is called the callback cb will receive the following OSSL_PARAM(3) object.

- -
- -
"st-phase" (OSSL_PROV_PARAM_SELF_TEST_PHASE) <UTF8 string>
-
- -

The value is the string "Corrupt"

- -
-
- -

OSSL_SELF_TEST_onend() may be inserted at the end of a block of self test code just before cleanup to indicate if the test passed or failed. It can be used for diagnostic purposes. If this method is called the callback cb will receive the following OSSL_PARAM(3) object.

- -
- -
"st-phase" (OSSL_PROV_PARAM_SELF_TEST_PHASE) <UTF8 string>
-
- -

The value of the string is "Pass" if ret is non zero, otherwise it has the value "Fail".

- -
-
- -

After the callback cb has been called the values that were set by OSSL_SELF_TEST_onbegin() for type and desc are set to the value "None".

- -

If OSSL_SELF_TEST_onbegin(), OSSL_SELF_TEST_oncorrupt_byte() or OSSL_SELF_TEST_onend() is called the following additional OSSL_PARAM(3) are passed to the callback.

- -
- -
"st-type" (OSSL_PROV_PARAM_SELF_TEST_TYPE) <UTF8 string>
-
- -

The value is setup by the type passed to OSSL_SELF_TEST_onbegin(). This allows the callback to identify the type of test being run.

- -
-
"st-desc" (OSSL_PROV_PARAM_SELF_TEST_DESC) <UTF8 string>
-
- -

The value is setup by the type passed to OSSL_SELF_TEST_onbegin(). This allows the callback to identify the sub category of the test being run.

- -
-
- -

RETURN VALUES

- -

OSSL_SELF_TEST_new() returns the allocated OSSL_SELF_TEST object, or NULL if it fails.

- -

OSSL_SELF_TEST_oncorrupt_byte() returns 1 if corruption occurs, otherwise it returns 0.

- -

EXAMPLES

- -

A single self test could be set up in the following way:

- -
  OSSL_SELF_TEST *st = NULL;
-  OSSL_CALLBACK *cb;
-  void *cbarg;
-  int ok = 0;
-  unsigned char out[EVP_MAX_MD_SIZE];
-  unsigned int out_len = 0;
-  EVP_MD_CTX *ctx = EVP_MD_CTX_new();
-  EVP_MD *md = EVP_MD_fetch(libctx, t->algorithm, NULL);
-
-  /*
-   * Retrieve the callback - will be NULL if not set by the application via
-   * OSSL_SELF_TEST_set_callback().
-   */
-  OSSL_SELF_TEST_get_callback(libctx, &cb, &cbarg);
-
-  st = OSSL_SELF_TEST_new(cb, cb_arg);
-
-  /* Trigger the optional callback */
-  OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_DIGEST,
-                         OSSL_SELF_TEST_DESC_MD_SHA2);
-
-  if (!EVP_DigestInit_ex(ctx, md, NULL)
-      || !EVP_DigestUpdate(ctx, pt, pt_len)
-      || !EVP_DigestFinal(ctx, out, &out_len))
-      goto err;
-
-  /* Optional corruption - If the application callback returns 0 */
-  OSSL_SELF_TEST_oncorrupt_byte(st, out);
-
-  if (out_len != t->expected_len
-      || memcmp(out, t->expected, out_len) != 0)
-      goto err;
-  ok = 1;
-err:
-  OSSL_SELF_TEST_onend(st, ok);
-  EVP_MD_free(md);
-  EVP_MD_CTX_free(ctx);
- -

Multiple self test's can be set up in a similar way by repeating the pattern of OSSL_SELF_TEST_onbegin(), OSSL_SELF_TEST_oncorrupt_byte(), OSSL_SELF_TEST_onend() for each test.

- -

SEE ALSO

- -

OSSL_SELF_TEST_set_callback(3), openssl-core.h(7), OSSL_PROVIDER-FIPS(7)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_set_callback.html b/openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_set_callback.html deleted file mode 100644 index 920c8220..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_SELF_TEST_set_callback.html +++ /dev/null @@ -1,62 +0,0 @@ - - - - -OSSL_SELF_TEST_set_callback - - - - - - - - - - -

NAME

- -

OSSL_SELF_TEST_set_callback, OSSL_SELF_TEST_get_callback - specify a callback for processing self tests

- -

SYNOPSIS

- -
#include <openssl/self_test.h>
-
-void OSSL_SELF_TEST_set_callback(OSSL_LIB_CTX *ctx, OSSL_CALLBACK *cb, void *cbarg);
-void OSSL_SELF_TEST_get_callback(OSSL_LIB_CTX *ctx, OSSL_CALLBACK **cb, void **cbarg);
- -

DESCRIPTION

- -

Set or gets the optional application callback (and the callback argument) that is called during self testing. The application callback OSSL_CALLBACK(3) is associated with a OSSL_LIB_CTX. The application callback function receives information about a running self test, and may return a result to the calling self test. See openssl-core.h(7) for further information on the callback.

- -

RETURN VALUES

- -

OSSL_SELF_TEST_get_callback() returns the callback and callback argument that has been set via OSSL_SELF_TEST_set_callback() for the given library context ctx. These returned parameters will be NULL if OSSL_SELF_TEST_set_callback() has not been called.

- -

SEE ALSO

- -

openssl-core.h(7), OSSL_PROVIDER-FIPS(7) OSSL_SELF_TEST_new(3) OSSL_LIB_CTX(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_INFO.html b/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_INFO.html deleted file mode 100644 index 6a3cf074..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_INFO.html +++ /dev/null @@ -1,187 +0,0 @@ - - - - -OSSL_STORE_INFO - - - - - - - - - - -

NAME

- -

OSSL_STORE_INFO, OSSL_STORE_INFO_get_type, OSSL_STORE_INFO_get0_NAME, OSSL_STORE_INFO_get0_NAME_description, OSSL_STORE_INFO_get0_PARAMS, OSSL_STORE_INFO_get0_PUBKEY, OSSL_STORE_INFO_get0_PKEY, OSSL_STORE_INFO_get0_CERT, OSSL_STORE_INFO_get0_CRL, OSSL_STORE_INFO_get1_NAME, OSSL_STORE_INFO_get1_NAME_description, OSSL_STORE_INFO_get1_PARAMS, OSSL_STORE_INFO_get1_PUBKEY, OSSL_STORE_INFO_get1_PKEY, OSSL_STORE_INFO_get1_CERT, OSSL_STORE_INFO_get1_CRL, OSSL_STORE_INFO_type_string, OSSL_STORE_INFO_free, OSSL_STORE_INFO_new_NAME, OSSL_STORE_INFO_set0_NAME_description, OSSL_STORE_INFO_new_PARAMS, OSSL_STORE_INFO_new_PUBKEY, OSSL_STORE_INFO_new_PKEY, OSSL_STORE_INFO_new_CERT, OSSL_STORE_INFO_new_CRL, OSSL_STORE_INFO_new, OSSL_STORE_INFO_get0_data - Functions to manipulate OSSL_STORE_INFO objects

- -

SYNOPSIS

- -
#include <openssl/store.h>
-
-typedef struct ossl_store_info_st OSSL_STORE_INFO;
-
-int OSSL_STORE_INFO_get_type(const OSSL_STORE_INFO *store_info);
-const char *OSSL_STORE_INFO_get0_NAME(const OSSL_STORE_INFO *store_info);
-char *OSSL_STORE_INFO_get1_NAME(const OSSL_STORE_INFO *store_info);
-const char *OSSL_STORE_INFO_get0_NAME_description(const OSSL_STORE_INFO
-                                                  *store_info);
-char *OSSL_STORE_INFO_get1_NAME_description(const OSSL_STORE_INFO *store_info);
-EVP_PKEY *OSSL_STORE_INFO_get0_PARAMS(const OSSL_STORE_INFO *store_info);
-EVP_PKEY *OSSL_STORE_INFO_get1_PARAMS(const OSSL_STORE_INFO *store_info);
-EVP_PKEY *OSSL_STORE_INFO_get0_PUBKEY(const OSSL_STORE_INFO *info);
-EVP_PKEY *OSSL_STORE_INFO_get1_PUBKEY(const OSSL_STORE_INFO *info);
-EVP_PKEY *OSSL_STORE_INFO_get0_PKEY(const OSSL_STORE_INFO *store_info);
-EVP_PKEY *OSSL_STORE_INFO_get1_PKEY(const OSSL_STORE_INFO *store_info);
-X509 *OSSL_STORE_INFO_get0_CERT(const OSSL_STORE_INFO *store_info);
-X509 *OSSL_STORE_INFO_get1_CERT(const OSSL_STORE_INFO *store_info);
-X509_CRL *OSSL_STORE_INFO_get0_CRL(const OSSL_STORE_INFO *store_info);
-X509_CRL *OSSL_STORE_INFO_get1_CRL(const OSSL_STORE_INFO *store_info);
-
-const char *OSSL_STORE_INFO_type_string(int type);
-
-void OSSL_STORE_INFO_free(OSSL_STORE_INFO *store_info);
-
-OSSL_STORE_INFO *OSSL_STORE_INFO_new_NAME(char *name);
-int OSSL_STORE_INFO_set0_NAME_description(OSSL_STORE_INFO *info, char *desc);
-OSSL_STORE_INFO *OSSL_STORE_INFO_new_PARAMS(DSA *dsa_params);
-OSSL_STORE_INFO *OSSL_STORE_INFO_new_PUBKEY(EVP_PKEY *pubkey);
-OSSL_STORE_INFO *OSSL_STORE_INFO_new_PKEY(EVP_PKEY *pkey);
-OSSL_STORE_INFO *OSSL_STORE_INFO_new_CERT(X509 *x509);
-OSSL_STORE_INFO *OSSL_STORE_INFO_new_CRL(X509_CRL *crl);
-
-OSSL_STORE_INFO *OSSL_STORE_INFO_new(int type, void *data);
-void *OSSL_STORE_INFO_get0_data(int type, const OSSL_STORE_INFO *info);
- -

DESCRIPTION

- -

These functions are primarily useful for applications to retrieve supported objects from OSSL_STORE_INFO objects and for scheme specific loaders to create OSSL_STORE_INFO holders.

- -

Types

- -

OSSL_STORE_INFO is an opaque type that's just an intermediary holder for the objects that have been retrieved by OSSL_STORE_load() and similar functions. Supported OpenSSL type object can be extracted using one of STORE_INFO_get0_<TYPE>() where <TYPE> can be NAME, PARAMS, PKEY, CERT, or CRL. The life time of this extracted object is as long as the life time of the OSSL_STORE_INFO it was extracted from, so care should be taken not to free the latter too early. As an alternative, STORE_INFO_get1_<TYPE>() extracts a duplicate (or the same object with its reference count increased), which can be used after the containing OSSL_STORE_INFO has been freed. The object returned by STORE_INFO_get1_<TYPE>() must be freed separately by the caller. See "SUPPORTED OBJECTS" for more information on the types that are supported.

- -

Functions

- -

OSSL_STORE_INFO_get_type() takes a OSSL_STORE_INFO and returns the STORE type number for the object inside.

- -

STORE_INFO_get_type_string() takes a STORE type number and returns a short string describing it.

- -

OSSL_STORE_INFO_get0_NAME(), OSSL_STORE_INFO_get0_NAME_description(), OSSL_STORE_INFO_get0_PARAMS(), OSSL_STORE_INFO_get0_PUBKEY(), OSSL_STORE_INFO_get0_PKEY(), OSSL_STORE_INFO_get0_CERT(), OSSL_STORE_INFO_get0_CRL() all take a OSSL_STORE_INFO and return the object it holds if the OSSL_STORE_INFO type (as returned by OSSL_STORE_INFO_get_type()) matches the function, otherwise NULL.

- -

OSSL_STORE_INFO_get1_NAME(), OSSL_STORE_INFO_get1_NAME_description(), OSSL_STORE_INFO_get1_PARAMS(), OSSL_STORE_INFO_get1_PUBKEY(), OSSL_STORE_INFO_get1_PKEY(), OSSL_STORE_INFO_get1_CERT() and OSSL_STORE_INFO_get1_CRL() all take a OSSL_STORE_INFO and return a duplicate the object it holds if the OSSL_STORE_INFO type (as returned by OSSL_STORE_INFO_get_type()) matches the function, otherwise NULL.

- -

OSSL_STORE_INFO_free() frees a OSSL_STORE_INFO and its contained type. If the argument is NULL, nothing is done.

- -

OSSL_STORE_INFO_new_NAME() , OSSL_STORE_INFO_new_PARAMS(), , OSSL_STORE_INFO_new_PUBKEY(), OSSL_STORE_INFO_new_PKEY(), OSSL_STORE_INFO_new_CERT() and OSSL_STORE_INFO_new_CRL() create a OSSL_STORE_INFO object to hold the given input object. On success the input object is consumed.

- -

Additionally, for OSSL_STORE_INFO_NAME objects, OSSL_STORE_INFO_set0_NAME_description() can be used to add an extra description. This description is meant to be human readable and should be used for information printout.

- -

OSSL_STORE_INFO_new() creates a OSSL_STORE_INFO with an arbitrary type number and data structure. It's the responsibility of the caller to define type numbers other than the ones defined by <openssl/store.h>, and to handle freeing the associated data structure on their own. Using type numbers that are defined by <openssl/store.h> may cause undefined behaviours, including crashes.

- -

OSSL_STORE_INFO_get0_data() returns the data pointer that was passed to OSSL_STORE_INFO_new() if type matches the type number in info.

- -

OSSL_STORE_INFO_new() and OSSL_STORE_INFO_get0_data() may be useful for applications that define their own STORE data, but must be used with care.

- -

SUPPORTED OBJECTS

- -

Currently supported object types are:

- -
- -
OSSL_STORE_INFO_NAME
-
- -

A name is exactly that, a name. It's like a name in a directory, but formatted as a complete URI. For example, the path in URI file:/foo/bar/ could include a file named cookie.pem, and in that case, the returned OSSL_STORE_INFO_NAME object would have the URI file:/foo/bar/cookie.pem, which can be used by the application to get the objects in that file. This can be applied to all schemes that can somehow support a listing of object URIs.

- -

For file: URIs that are used without the explicit scheme, the returned name will be the path of each object, so if /foo/bar was given and that path has the file cookie.pem, the name /foo/bar/cookie.pem will be returned.

- -

The returned URI is considered canonical and must be unique and permanent for the storage where the object (or collection of objects) resides. Each loader is responsible for ensuring that it only returns canonical URIs. However, it's possible that certain schemes allow an object (or collection thereof) to be reached with alternative URIs; just because one URI is canonical doesn't mean that other variants can't be used.

- -

At the discretion of the loader that was used to get these names, an extra description may be attached as well.

- -
-
OSSL_STORE_INFO_PARAMS
-
- -

Key parameters.

- -
-
OSSL_STORE_INFO_PKEY
-
- -

A keypair or just a private key (possibly with key parameters).

- -
-
OSSL_STORE_INFO_PUBKEY
-
- -

A public key (possibly with key parameters).

- -
-
OSSL_STORE_INFO_CERT
-
- -

An X.509 certificate.

- -
-
OSSL_STORE_INFO_CRL
-
- -

A X.509 certificate revocation list.

- -
-
- -

RETURN VALUES

- -

OSSL_STORE_INFO_get_type() returns the STORE type number of the given OSSL_STORE_INFO. There is no error value.

- -

OSSL_STORE_INFO_get0_NAME(), OSSL_STORE_INFO_get0_NAME_description(), OSSL_STORE_INFO_get0_PARAMS(), OSSL_STORE_INFO_get0_PKEY(), OSSL_STORE_INFO_get0_CERT() and OSSL_STORE_INFO_get0_CRL() all return a pointer to the OpenSSL object on success, NULL otherwise.

- -

OSSL_STORE_INFO_get1_NAME(), OSSL_STORE_INFO_get1_NAME_description(), OSSL_STORE_INFO_get1_PARAMS(), OSSL_STORE_INFO_get1_PKEY(), OSSL_STORE_INFO_get1_CERT() and OSSL_STORE_INFO_get1_CRL() all return a pointer to a duplicate of the OpenSSL object on success, NULL otherwise.

- -

OSSL_STORE_INFO_type_string() returns a string on success, or NULL on failure.

- -

OSSL_STORE_INFO_new_NAME(), OSSL_STORE_INFO_new_PARAMS(), OSSL_STORE_INFO_new_PKEY(), OSSL_STORE_INFO_new_CERT() and OSSL_STORE_INFO_new_CRL() return a OSSL_STORE_INFO pointer on success, or NULL on failure.

- -

OSSL_STORE_INFO_set0_NAME_description() returns 1 on success, or 0 on failure.

- -

SEE ALSO

- -

ossl_store(7), OSSL_STORE_open(3), OSSL_STORE_register_loader(3)

- -

HISTORY

- -

The OSSL_STORE API was added in OpenSSL 1.1.1.

- -

The OSSL_STORE_INFO_PUBKEY object type was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_LOADER.html b/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_LOADER.html deleted file mode 100644 index b0b0c7bf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_LOADER.html +++ /dev/null @@ -1,293 +0,0 @@ - - - - -OSSL_STORE_LOADER - - - - - - - - - - -

NAME

- -

OSSL_STORE_LOADER, OSSL_STORE_LOADER_fetch, OSSL_STORE_LOADER_up_ref, OSSL_STORE_LOADER_free, OSSL_STORE_LOADER_get0_provider, OSSL_STORE_LOADER_get0_properties, OSSL_STORE_LOADER_is_a, OSSL_STORE_LOADER_get0_description, OSSL_STORE_LOADER_do_all_provided, OSSL_STORE_LOADER_names_do_all, OSSL_STORE_LOADER_CTX, OSSL_STORE_LOADER_new, OSSL_STORE_LOADER_get0_engine, OSSL_STORE_LOADER_get0_scheme, OSSL_STORE_LOADER_set_open, OSSL_STORE_LOADER_set_open_ex, OSSL_STORE_LOADER_set_attach, OSSL_STORE_LOADER_set_ctrl, OSSL_STORE_LOADER_set_expect, OSSL_STORE_LOADER_set_find, OSSL_STORE_LOADER_set_load, OSSL_STORE_LOADER_set_eof, OSSL_STORE_LOADER_set_error, OSSL_STORE_LOADER_set_close, OSSL_STORE_register_loader, OSSL_STORE_unregister_loader, OSSL_STORE_open_fn, OSSL_STORE_open_ex_fn, OSSL_STORE_attach_fn, OSSL_STORE_ctrl_fn, OSSL_STORE_expect_fn, OSSL_STORE_find_fn, OSSL_STORE_load_fn, OSSL_STORE_eof_fn, OSSL_STORE_error_fn, OSSL_STORE_close_fn - Types and functions to manipulate, register and unregister STORE loaders for different URI schemes

- -

SYNOPSIS

- -
#include <openssl/store.h>
-
-typedef struct ossl_store_loader_st OSSL_STORE_LOADER;
-
-OSSL_STORE_LOADER *OSSL_STORE_LOADER_fetch(OSSL_LIB_CTX *libctx,
-                                           const char *scheme,
-                                           const char *properties);
-int OSSL_STORE_LOADER_up_ref(OSSL_STORE_LOADER *loader);
-void OSSL_STORE_LOADER_free(OSSL_STORE_LOADER *loader);
-const OSSL_PROVIDER *OSSL_STORE_LOADER_get0_provider(const OSSL_STORE_LOADER *
-                                                loader);
-const char *OSSL_STORE_LOADER_get0_properties(const OSSL_STORE_LOADER *loader);
-const char *OSSL_STORE_LOADER_get0_description(const OSSL_STORE_LOADER *loader);
-int OSSL_STORE_LOADER_is_a(const OSSL_STORE_LOADER *loader,
-                           const char *scheme);
-void OSSL_STORE_LOADER_do_all_provided(OSSL_LIB_CTX *libctx,
-                                       void (*user_fn)(OSSL_STORE_LOADER *loader,
-                                                  void *arg),
-                                       void *user_arg);
-int OSSL_STORE_LOADER_names_do_all(const OSSL_STORE_LOADER *loader,
-                                   void (*fn)(const char *name, void *data),
-                                   void *data);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
OSSL_STORE_LOADER *OSSL_STORE_LOADER_new(ENGINE *e, const char *scheme);
-const ENGINE *OSSL_STORE_LOADER_get0_engine(const OSSL_STORE_LOADER
-                                            *store_loader);
-const char *OSSL_STORE_LOADER_get0_scheme(const OSSL_STORE_LOADER
-                                          *store_loader);
-
-/* struct ossl_store_loader_ctx_st is defined differently by each loader */
-typedef struct ossl_store_loader_ctx_st OSSL_STORE_LOADER_CTX;
-
-typedef OSSL_STORE_LOADER_CTX *(*OSSL_STORE_open_fn)(
-    const char *uri, const UI_METHOD *ui_method, void *ui_data);
-int OSSL_STORE_LOADER_set_open(OSSL_STORE_LOADER *store_loader,
-                               OSSL_STORE_open_fn store_open_function);
-typedef OSSL_STORE_LOADER_CTX *(*OSSL_STORE_open_ex_fn)(
-    const char *uri, const UI_METHOD *ui_method, void *ui_data);
-int OSSL_STORE_LOADER_set_open_ex
-    (OSSL_STORE_LOADER *store_loader,
-     OSSL_STORE_open_ex_fn store_open_ex_function);
-typedef OSSL_STORE_LOADER_CTX *(*OSSL_STORE_attach_fn)
-    (const OSSL_STORE_LOADER *loader, BIO *bio,
-     OSSL_LIB_CTX *libctx, const char *propq,
-     const UI_METHOD *ui_method, void *ui_data);
-int OSSL_STORE_LOADER_set_attach(OSSL_STORE_LOADER *loader,
-                                 OSSL_STORE_attach_fn attach_function);
-typedef int (*OSSL_STORE_ctrl_fn)(OSSL_STORE_LOADER_CTX *ctx, int cmd,
-                                  va_list args);
-int OSSL_STORE_LOADER_set_ctrl(OSSL_STORE_LOADER *store_loader,
-                               OSSL_STORE_ctrl_fn store_ctrl_function);
-typedef int (*OSSL_STORE_expect_fn)(OSSL_STORE_LOADER_CTX *ctx, int expected);
-int OSSL_STORE_LOADER_set_expect(OSSL_STORE_LOADER *loader,
-                                 OSSL_STORE_expect_fn expect_function);
-typedef int (*OSSL_STORE_find_fn)(OSSL_STORE_LOADER_CTX *ctx,
-                                  OSSL_STORE_SEARCH *criteria);
-int OSSL_STORE_LOADER_set_find(OSSL_STORE_LOADER *loader,
-                               OSSL_STORE_find_fn find_function);
-typedef OSSL_STORE_INFO *(*OSSL_STORE_load_fn)(OSSL_STORE_LOADER_CTX *ctx,
-                                               UI_METHOD *ui_method,
-                                               void *ui_data);
-int OSSL_STORE_LOADER_set_load(OSSL_STORE_LOADER *store_loader,
-                               OSSL_STORE_load_fn store_load_function);
-typedef int (*OSSL_STORE_eof_fn)(OSSL_STORE_LOADER_CTX *ctx);
-int OSSL_STORE_LOADER_set_eof(OSSL_STORE_LOADER *store_loader,
-                              OSSL_STORE_eof_fn store_eof_function);
-typedef int (*OSSL_STORE_error_fn)(OSSL_STORE_LOADER_CTX *ctx);
-int OSSL_STORE_LOADER_set_error(OSSL_STORE_LOADER *store_loader,
-                                OSSL_STORE_error_fn store_error_function);
-typedef int (*OSSL_STORE_close_fn)(OSSL_STORE_LOADER_CTX *ctx);
-int OSSL_STORE_LOADER_set_close(OSSL_STORE_LOADER *store_loader,
-                                OSSL_STORE_close_fn store_close_function);
-
-int OSSL_STORE_register_loader(OSSL_STORE_LOADER *loader);
-OSSL_STORE_LOADER *OSSL_STORE_unregister_loader(const char *scheme);
- -

DESCRIPTION

- -

OSSL_STORE_LOADER is a method for OSSL_STORE loaders, which implement OSSL_STORE_open(), OSSL_STORE_open_ex(), OSSL_STORE_load(), OSSL_STORE_eof(), OSSL_STORE_error() and OSSL_STORE_close() for specific storage schemes.

- -

OSSL_STORE_LOADER_fetch() looks for an implementation for a storage scheme within the providers that has been loaded into the OSSL_LIB_CTX given by libctx, and with the properties given by properties.

- -

OSSL_STORE_LOADER_up_ref() increments the reference count for the given loader.

- -

OSSL_STORE_LOADER_free() decrements the reference count for the given loader, and when the count reaches zero, frees it. If the argument is NULL, nothing is done.

- -

OSSL_STORE_LOADER_get0_provider() returns the provider of the given loader.

- -

OSSL_STORE_LOADER_get0_properties() returns the property definition associated with the given loader.

- -

OSSL_STORE_LOADER_is_a() checks if loader is an implementation of an algorithm that's identifiable with scheme.

- -

OSSL_STORE_LOADER_get0_description() returns a description of the loader, meant for display and human consumption. The description is at the discretion of the loader implementation.

- -

OSSL_STORE_LOADER_do_all_provided() traverses all store implementations by all activated providers in the library context libctx, and for each of the implementations, calls user_fn with the implementation method and user_arg as arguments.

- -

OSSL_STORE_LOADER_names_do_all() traverses all names for the given loader, and calls fn with each name and data.

- -

Legacy Types and Functions (deprecated)

- -

These functions help applications and engines to create loaders for schemes they support. These are all deprecated and discouraged in favour of provider implementations, see provider-storemgmt(7).

- -

OSSL_STORE_LOADER_CTX is a type template, to be defined by each loader using struct ossl_store_loader_ctx_st { ... }.

- -

OSSL_STORE_open_fn, OSSL_STORE_open_ex_fn, OSSL_STORE_ctrl_fn, OSSL_STORE_expect_fn, OSSL_STORE_find_fn, OSSL_STORE_load_fn, OSSL_STORE_eof_fn, and OSSL_STORE_close_fn are the function pointer types used within a STORE loader. The functions pointed at define the functionality of the given loader.

- -
- -
OSSL_STORE_open_fn and OSSL_STORE_open_ex_fn
-
- -

OSSL_STORE_open_ex_fn takes a URI and is expected to interpret it in the best manner possible according to the scheme the loader implements. It also takes a UI_METHOD and associated data, to be used any time something needs to be prompted for, as well as a library context libctx with an associated property query propq, to be used when fetching necessary algorithms to perform the loads. Furthermore, this function is expected to initialize what needs to be initialized, to create a private data store (OSSL_STORE_LOADER_CTX, see above), and to return it. If something goes wrong, this function is expected to return NULL.

- -

OSSL_STORE_open_fn does the same thing as OSSL_STORE_open_ex_fn but uses NULL for the library context libctx and property query propq.

- -
-
OSSL_STORE_attach_fn
-
- -

This function takes a BIO, otherwise works like OSSL_STORE_open_ex_fn.

- -
-
OSSL_STORE_ctrl_fn
-
- -

This function takes a OSSL_STORE_LOADER_CTX pointer, a command number cmd and a va_list args and is used to manipulate loader specific parameters.

- -

Loader specific command numbers must begin at OSSL_STORE_C_CUSTOM_START. Any number below that is reserved for future globally known command numbers.

- -

This function is expected to return 1 on success, 0 on error.

- -
-
OSSL_STORE_expect_fn
-
- -

This function takes a OSSL_STORE_LOADER_CTX pointer and a OSSL_STORE_INFO identity expected, and is used to tell the loader what object type is expected. expected may be zero to signify that no specific object type is expected.

- -

This function is expected to return 1 on success, 0 on error.

- -
-
OSSL_STORE_find_fn
-
- -

This function takes a OSSL_STORE_LOADER_CTX pointer and a OSSL_STORE_SEARCH search criterion, and is used to tell the loader what to search for.

- -

When called with the loader context being NULL, this function is expected to return 1 if the loader supports the criterion, otherwise 0.

- -

When called with the loader context being something other than NULL, this function is expected to return 1 on success, 0 on error.

- -
-
OSSL_STORE_load_fn
-
- -

This function takes a OSSL_STORE_LOADER_CTX pointer and a UI_METHOD with associated data. It's expected to load the next available data, mold it into a data structure that can be wrapped in a OSSL_STORE_INFO using one of the OSSL_STORE_INFO(3) functions. If no more data is available or an error occurs, this function is expected to return NULL. The OSSL_STORE_eof_fn and OSSL_STORE_error_fn functions must indicate if it was in fact the end of data or if an error occurred.

- -

Note that this function retrieves one data item only.

- -
-
OSSL_STORE_eof_fn
-
- -

This function takes a OSSL_STORE_LOADER_CTX pointer and is expected to return 1 to indicate that the end of available data has been reached. It is otherwise expected to return 0.

- -
-
OSSL_STORE_error_fn
-
- -

This function takes a OSSL_STORE_LOADER_CTX pointer and is expected to return 1 to indicate that an error occurred in a previous call to the OSSL_STORE_load_fn function. It is otherwise expected to return 0.

- -
-
OSSL_STORE_close_fn
-
- -

This function takes a OSSL_STORE_LOADER_CTX pointer and is expected to close or shut down what needs to be closed, and finally free the contents of the OSSL_STORE_LOADER_CTX pointer. It returns 1 on success and 0 on error.

- -
-
- -

OSSL_STORE_LOADER_new() creates a new OSSL_STORE_LOADER. It takes an ENGINE e and a string scheme. scheme must always be set. Both e and scheme are used as is and must therefore be alive as long as the created loader is.

- -

OSSL_STORE_LOADER_get0_engine() returns the engine of the store_loader. OSSL_STORE_LOADER_get0_scheme() returns the scheme of the store_loader.

- -

OSSL_STORE_LOADER_set_open() sets the opener function for the store_loader.

- -

OSSL_STORE_LOADER_set_open_ex() sets the opener with library context function for the store_loader.

- -

OSSL_STORE_LOADER_set_attach() sets the attacher function for the store_loader.

- -

OSSL_STORE_LOADER_set_ctrl() sets the control function for the store_loader.

- -

OSSL_STORE_LOADER_set_expect() sets the expect function for the store_loader.

- -

OSSL_STORE_LOADER_set_load() sets the loader function for the store_loader.

- -

OSSL_STORE_LOADER_set_eof() sets the end of file checker function for the store_loader.

- -

OSSL_STORE_LOADER_set_close() sets the closing function for the store_loader.

- -

OSSL_STORE_LOADER_free() frees the given store_loader. If the argument is NULL, nothing is done.

- -

OSSL_STORE_register_loader() register the given store_loader and thereby makes it available for use with OSSL_STORE_open(), OSSL_STORE_open_ex(), OSSL_STORE_load(), OSSL_STORE_eof() and OSSL_STORE_close().

- -

OSSL_STORE_unregister_loader() unregister the store loader for the given scheme.

- -

RETURN VALUES

- -

OSSL_STORE_LOADER_fetch() returns a pointer to an OSSL_STORE_LOADER object, or NULL on error.

- -

OSSL_STORE_LOADER_up_ref() returns 1 on success, or 0 on error.

- -

OSSL_STORE_LOADER_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names.

- -

OSSL_STORE_LOADER_free() doesn't return any value.

- -

OSSL_STORE_LOADER_get0_provider() returns a pointer to a provider object, or NULL on error.

- -

OSSL_STORE_LOADER_get0_properties() returns a pointer to a property definition string, or NULL on error.

- -

OSSL_STORE_LOADER_is_a() returns 1 if loader was identifiable, otherwise 0.

- -

OSSL_STORE_LOADER_get0_description() returns a pointer to a description, or NULL if there isn't one.

- -

The functions with the types OSSL_STORE_open_fn, OSSL_STORE_open_ex_fn, OSSL_STORE_ctrl_fn, OSSL_STORE_expect_fn, OSSL_STORE_load_fn, OSSL_STORE_eof_fn and OSSL_STORE_close_fn have the same return values as OSSL_STORE_open(), OSSL_STORE_open_ex(), OSSL_STORE_ctrl(), OSSL_STORE_expect(), OSSL_STORE_load(), OSSL_STORE_eof() and OSSL_STORE_close(), respectively.

- -

OSSL_STORE_LOADER_new() returns a pointer to a OSSL_STORE_LOADER on success, or NULL on failure.

- -

OSSL_STORE_LOADER_set_open(), OSSL_STORE_LOADER_set_open_ex(), OSSL_STORE_LOADER_set_ctrl(), OSSL_STORE_LOADER_set_load(), OSSL_STORE_LOADER_set_eof() and OSSL_STORE_LOADER_set_close() return 1 on success, or 0 on failure.

- -

OSSL_STORE_register_loader() returns 1 on success, or 0 on failure.

- -

OSSL_STORE_unregister_loader() returns the unregistered loader on success, or NULL on failure.

- -

SEE ALSO

- -

ossl_store(7), OSSL_STORE_open(3), OSSL_LIB_CTX(3), provider-storemgmt(7)

- -

HISTORY

- -

OSSL_STORE_LOADER_fetch(), OSSL_STORE_LOADER_up_ref(), OSSL_STORE_LOADER_get0_provider(), OSSL_STORE_LOADER_get0_properties(), OSSL_STORE_LOADER_get0_description(), OSSL_STORE_LOADER_is_a(), OSSL_STORE_LOADER_do_all_provided() and OSSL_STORE_LOADER_names_do_all() were added in OpenSSL 3.0.

- -

OSSL_STORE_LOADER and OSSL_STORE_LOADER_free() were added in OpenSSL 1.1.1.

- -

OSSL_STORE_LOADER_set_open_ex() and OSSL_STORE_open_ex_fn() were added in OpenSSL 3.0, and are deprecated.

- -

OSSL_STORE_LOADER_CTX, OSSL_STORE_LOADER_new(), OSSL_STORE_LOADER_set0_scheme(), OSSL_STORE_LOADER_get0_scheme(), OSSL_STORE_LOADER_get0_engine(), OSSL_STORE_LOADER_set_expect(), OSSL_STORE_LOADER_set_find(), OSSL_STORE_LOADER_set_attach(), OSSL_STORE_LOADER_set_open_ex(), OSSL_STORE_LOADER_set_open(), OSSL_STORE_LOADER_set_ctrl(), OSSL_STORE_LOADER_set_load(), OSSL_STORE_LOADER_set_eof(), OSSL_STORE_LOADER_set_close(), OSSL_STORE_register_loader(), OSSL_STORE_LOADER_set_error(), OSSL_STORE_unregister_loader(), OSSL_STORE_open_fn(), OSSL_STORE_ctrl_fn(), OSSL_STORE_load_fn(), OSSL_STORE_eof_fn() and OSSL_STORE_close_fn() were added in OpenSSL 1.1.1, and became deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_SEARCH.html b/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_SEARCH.html deleted file mode 100644 index d01959aa..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_SEARCH.html +++ /dev/null @@ -1,151 +0,0 @@ - - - - -OSSL_STORE_SEARCH - - - - - - - - - - -

NAME

- -

OSSL_STORE_SEARCH, OSSL_STORE_SEARCH_by_name, OSSL_STORE_SEARCH_by_issuer_serial, OSSL_STORE_SEARCH_by_key_fingerprint, OSSL_STORE_SEARCH_by_alias, OSSL_STORE_SEARCH_free, OSSL_STORE_SEARCH_get_type, OSSL_STORE_SEARCH_get0_name, OSSL_STORE_SEARCH_get0_serial, OSSL_STORE_SEARCH_get0_bytes, OSSL_STORE_SEARCH_get0_string, OSSL_STORE_SEARCH_get0_digest - Type and functions to create OSSL_STORE search criteria

- -

SYNOPSIS

- -
#include <openssl/store.h>
-
-typedef struct ossl_store_search_st OSSL_STORE_SEARCH;
-
-OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(X509_NAME *name);
-OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(X509_NAME *name,
-                                                      const ASN1_INTEGER
-                                                      *serial);
-OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_key_fingerprint(const EVP_MD *digest,
-                                                        const unsigned char
-                                                        *bytes, int len);
-OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_alias(const char *alias);
-
-void OSSL_STORE_SEARCH_free(OSSL_STORE_SEARCH *search);
-
-int OSSL_STORE_SEARCH_get_type(const OSSL_STORE_SEARCH *criterion);
-X509_NAME *OSSL_STORE_SEARCH_get0_name(OSSL_STORE_SEARCH *criterion);
-const ASN1_INTEGER *OSSL_STORE_SEARCH_get0_serial(const OSSL_STORE_SEARCH
-                                                  *criterion);
-const unsigned char *OSSL_STORE_SEARCH_get0_bytes(const OSSL_STORE_SEARCH
-                                                  *criterion, size_t *length);
-const char *OSSL_STORE_SEARCH_get0_string(const OSSL_STORE_SEARCH *criterion);
-const EVP_MD *OSSL_STORE_SEARCH_get0_digest(const OSSL_STORE_SEARCH
-                                            *criterion);
- -

DESCRIPTION

- -

These functions are used to specify search criteria to help search for specific objects through other names than just the URI that's given to OSSL_STORE_open(). For example, this can be useful for an application that has received a URI and then wants to add on search criteria in a uniform and supported manner.

- -

Types

- -

OSSL_STORE_SEARCH is an opaque type that holds the constructed search criterion, and that can be given to an OSSL_STORE context with OSSL_STORE_find().

- -

The calling application owns the allocation of an OSSL_STORE_SEARCH at all times, and should therefore be careful not to deallocate it before OSSL_STORE_close() has been called for the OSSL_STORE context it was given to.

- -

Application Functions

- -

OSSL_STORE_SEARCH_by_name(), OSSL_STORE_SEARCH_by_issuer_serial(), OSSL_STORE_SEARCH_by_key_fingerprint(), and OSSL_STORE_SEARCH_by_alias() are used to create an OSSL_STORE_SEARCH from a subject name, an issuer name and serial number pair, a key fingerprint, and an alias (for example a friendly name). The parameters that are provided are not copied, only referred to in a criterion, so they must have at least the same life time as the created OSSL_STORE_SEARCH.

- -

OSSL_STORE_SEARCH_free() is used to free the OSSL_STORE_SEARCH. If the argument is NULL, nothing is done.

- -

Loader Functions

- -

OSSL_STORE_SEARCH_get_type() returns the criterion type for the given OSSL_STORE_SEARCH.

- -

OSSL_STORE_SEARCH_get0_name(), OSSL_STORE_SEARCH_get0_serial(), OSSL_STORE_SEARCH_get0_bytes(), OSSL_STORE_SEARCH_get0_string(), and OSSL_STORE_SEARCH_get0_digest() are used to retrieve different data from a OSSL_STORE_SEARCH, as available for each type. For more information, see "SUPPORTED CRITERION TYPES" below.

- -

SUPPORTED CRITERION TYPES

- -

Currently supported criterion types are:

- -
- -
OSSL_STORE_SEARCH_BY_NAME
-
- -

This criterion supports a search by exact match of subject name. The subject name itself is a X509_NAME pointer. A criterion of this type is created with OSSL_STORE_SEARCH_by_name(), and the actual subject name is retrieved with OSSL_STORE_SEARCH_get0_name().

- -
-
OSSL_STORE_SEARCH_BY_ISSUER_SERIAL
-
- -

This criterion supports a search by exact match of both issuer name and serial number. The issuer name itself is a X509_NAME pointer, and the serial number is a ASN1_INTEGER pointer. A criterion of this type is created with OSSL_STORE_SEARCH_by_issuer_serial() and the actual issuer name and serial number are retrieved with OSSL_STORE_SEARCH_get0_name() and OSSL_STORE_SEARCH_get0_serial().

- -
-
OSSL_STORE_SEARCH_BY_KEY_FINGERPRINT
-
- -

This criterion supports a search by exact match of key fingerprint. The key fingerprint in itself is a string of bytes and its length, as well as the algorithm that was used to compute the fingerprint. The digest may be left unspecified (NULL), and in that case, the loader has to decide on a default digest and compare fingerprints accordingly. A criterion of this type is created with OSSL_STORE_SEARCH_by_key_fingerprint() and the actual fingerprint and its length can be retrieved with OSSL_STORE_SEARCH_get0_bytes(). The digest can be retrieved with OSSL_STORE_SEARCH_get0_digest().

- -
-
OSSL_STORE_SEARCH_BY_ALIAS
-
- -

This criterion supports a search by match of an alias of some kind. The alias in itself is a simple C string. A criterion of this type is created with OSSL_STORE_SEARCH_by_alias() and the actual alias is retrieved with OSSL_STORE_SEARCH_get0_string().

- -
-
- -

RETURN VALUES

- -

OSSL_STORE_SEARCH_by_name(), OSSL_STORE_SEARCH_by_issuer_serial(), OSSL_STORE_SEARCH_by_key_fingerprint(), and OSSL_STORE_SEARCH_by_alias() return a OSSL_STORE_SEARCH pointer on success, or NULL on failure.

- -

OSSL_STORE_SEARCH_get_type() returns the criterion type of the given OSSL_STORE_SEARCH. There is no error value.

- -

OSSL_STORE_SEARCH_get0_name() returns a X509_NAME pointer on success, or NULL when the given OSSL_STORE_SEARCH was of a different type.

- -

OSSL_STORE_SEARCH_get0_serial() returns a ASN1_INTEGER pointer on success, or NULL when the given OSSL_STORE_SEARCH was of a different type.

- -

OSSL_STORE_SEARCH_get0_bytes() returns a const unsigned char pointer and sets *length to the strings length on success, or NULL when the given OSSL_STORE_SEARCH was of a different type.

- -

OSSL_STORE_SEARCH_get0_string() returns a const char pointer on success, or NULL when the given OSSL_STORE_SEARCH was of a different type.

- -

OSSL_STORE_SEARCH_get0_digest() returns a const EVP_MD pointer. NULL is a valid value and means that the store loader default will be used when applicable.

- -

SEE ALSO

- -

ossl_store(7), OSSL_STORE_supports_search(3), OSSL_STORE_find(3)

- -

HISTORY

- -

OSSL_STORE_SEARCH, OSSL_STORE_SEARCH_by_name(), OSSL_STORE_SEARCH_by_issuer_serial(), OSSL_STORE_SEARCH_by_key_fingerprint(), OSSL_STORE_SEARCH_by_alias(), OSSL_STORE_SEARCH_free(), OSSL_STORE_SEARCH_get_type(), OSSL_STORE_SEARCH_get0_name(), OSSL_STORE_SEARCH_get0_serial(), OSSL_STORE_SEARCH_get0_bytes(), and OSSL_STORE_SEARCH_get0_string() were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_attach.html b/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_attach.html deleted file mode 100644 index 2dab6b59..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_attach.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -OSSL_STORE_attach - - - - - - - - - - -

NAME

- -

OSSL_STORE_attach - Functions to read objects from a BIO

- -

SYNOPSIS

- -
#include <openssl/store.h>
-
-OSSL_STORE_CTX *OSSL_STORE_attach(BIO *bio, const char *scheme,
-                                  OSSL_LIB_CTX *libctx, const char *propq,
-                                  const UI_METHOD *ui_method, void *ui_data,
-                                  const OSSL_PARAM params[],
-                                  OSSL_STORE_post_process_info_fn post_process,
-                                  void *post_process_data);
- -

DESCRIPTION

- -

OSSL_STORE_attach() works like OSSL_STORE_open(3), except it takes a BIO bio instead of a uri, along with a scheme to determine what loader should be used to process the data. The reference count of the BIO object is increased by 1 if the call is successful.

- -

RETURN VALUES

- -

OSSL_STORE_attach() returns a pointer to a OSSL_STORE_CTX on success, or NULL on failure.

- -

SEE ALSO

- -

ossl_store(7), OSSL_STORE_open(3)

- -

HISTORY

- -

OSSL_STORE_attach() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_expect.html b/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_expect.html deleted file mode 100644 index e4c044a6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_expect.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -OSSL_STORE_expect - - - - - - - - - - -

NAME

- -

OSSL_STORE_expect, OSSL_STORE_supports_search, OSSL_STORE_find - Specify what object type is expected

- -

SYNOPSIS

- -
#include <openssl/store.h>
-
-int OSSL_STORE_expect(OSSL_STORE_CTX *ctx, int expected_type);
-
-int OSSL_STORE_supports_search(OSSL_STORE_CTX *ctx, int criterion_type);
-
-int OSSL_STORE_find(OSSL_STORE_CTX *ctx, OSSL_STORE_SEARCH *search);
- -

DESCRIPTION

- -

OSSL_STORE_expect() helps applications filter what OSSL_STORE_load() returns by specifying a OSSL_STORE_INFO type. By default, no expectations on the types of objects to be loaded are made. expected_type may be 0 to indicate explicitly that no expectation is made, or it may be any of the known object types (see "SUPPORTED OBJECTS" in OSSL_STORE_INFO(3)) except for OSSL_STORE_INFO_NAME. For example, if file:/foo/bar/store.pem contains several objects of different type and only certificates are interesting, the application can simply say that it expects the type OSSL_STORE_INFO_CERT.

- -

OSSL_STORE_find() helps applications specify a criterion for a more fine grained search of objects.

- -

OSSL_STORE_supports_search() checks if the loader of the given OSSL_STORE context supports the given search type. See "SUPPORTED CRITERION TYPES" in OSSL_STORE_SEARCH(3) for information on the supported search criterion types.

- -

OSSL_STORE_expect() and OSSL_STORE_find must be called before the first OSSL_STORE_load() of a given session, or they will fail.

- -

NOTES

- -

If a more elaborate filter is required by the application, a better choice would be to use a post-processing function. See OSSL_STORE_open(3) for more information.

- -

However, some loaders may take advantage of the knowledge of an expected type to make object retrieval more efficient, so if a single type is expected, this method is usually preferable.

- -

RETURN VALUES

- -

OSSL_STORE_expect() returns 1 on success, or 0 on failure.

- -

OSSL_STORE_supports_search() returns 1 if the criterion is supported, or 0 otherwise.

- -

OSSL_STORE_find() returns 1 on success, or 0 on failure.

- -

SEE ALSO

- -

ossl_store(7), OSSL_STORE_INFO(3), OSSL_STORE_SEARCH(3), OSSL_STORE_load(3)

- -

HISTORY

- -

OSSL_STORE_expect(), OSSL_STORE_supports_search() and OSSL_STORE_find() were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_open.html b/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_open.html deleted file mode 100644 index f364ddaa..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_STORE_open.html +++ /dev/null @@ -1,153 +0,0 @@ - - - - -OSSL_STORE_open - - - - - - - - - - -

NAME

- -

OSSL_STORE_CTX, OSSL_STORE_post_process_info_fn, OSSL_STORE_open, OSSL_STORE_open_ex, OSSL_STORE_ctrl, OSSL_STORE_load, OSSL_STORE_eof, OSSL_STORE_delete, OSSL_STORE_error, OSSL_STORE_close - Types and functions to read objects from a URI

- -

SYNOPSIS

- -
#include <openssl/store.h>
-
-typedef struct ossl_store_ctx_st OSSL_STORE_CTX;
-
-typedef OSSL_STORE_INFO *(*OSSL_STORE_post_process_info_fn)(OSSL_STORE_INFO *,
-                                                            void *);
-
-OSSL_STORE_CTX *OSSL_STORE_open(const char *uri, const UI_METHOD *ui_method,
-                                void *ui_data,
-                                OSSL_STORE_post_process_info_fn post_process,
-                                void *post_process_data);
-OSSL_STORE_CTX *
-OSSL_STORE_open_ex(const char *uri, OSSL_LIB_CTX *libctx, const char *propq,
-                   const UI_METHOD *ui_method, void *ui_data,
-                   const OSSL_PARAM params[],
-                   OSSL_STORE_post_process_info_fn post_process,
-                   void *post_process_data);
-
-OSSL_STORE_INFO *OSSL_STORE_load(OSSL_STORE_CTX *ctx);
-int OSSL_STORE_eof(OSSL_STORE_CTX *ctx);
-int OSSL_STORE_delete(const char *uri, OSSL_LIB_CTX *libctx, const char *propq,
-                      const UI_METHOD *ui_method, void *ui_data,
-                      const OSSL_PARAM params[]);
-int OSSL_STORE_error(OSSL_STORE_CTX *ctx);
-int OSSL_STORE_close(OSSL_STORE_CTX *ctx);
- -

The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int OSSL_STORE_ctrl(OSSL_STORE_CTX *ctx, int cmd, ... /* args */);
- -

DESCRIPTION

- -

These functions help the application to fetch supported objects (see "SUPPORTED OBJECTS" in OSSL_STORE_INFO(3) for information on which those are) from a given URI. The general method to do so is to "open" the URI using OSSL_STORE_open(), read each available and supported object using OSSL_STORE_load() as long as OSSL_STORE_eof() hasn't been reached, and finish it off with OSSL_STORE_close().

- -

The retrieved information is stored in a OSSL_STORE_INFO, which is further described in OSSL_STORE_INFO(3).

- -

Types

- -

OSSL_STORE_CTX is a context variable that holds all the internal information for OSSL_STORE_open(), OSSL_STORE_open_ex(), OSSL_STORE_load(), OSSL_STORE_eof() and OSSL_STORE_close() to work together.

- -

Functions

- -

OSSL_STORE_open_ex() takes a uri or path uri, password UI method ui_method with associated data ui_data, and post processing callback post_process with associated data post_process_data, a library context libctx with an associated property query propq, and opens a channel to the data located at the URI and returns a OSSL_STORE_CTX with all necessary internal information. The given ui_method and ui_data will be reused by all functions that use OSSL_STORE_CTX when interaction is needed, for instance to provide a password. The auxiliary OSSL_PARAM(3) parameters in params can be set to further modify the store operation. The given post_process and post_process_data will be reused by OSSL_STORE_load() to manipulate or drop the value to be returned. The post_process function drops values by returning NULL, which will cause OSSL_STORE_load() to start its process over with loading the next object, until post_process returns something other than NULL, or the end of data is reached as indicated by OSSL_STORE_eof().

- -

OSSL_STORE_open() is similar to OSSL_STORE_open_ex() but uses NULL for the params, the library context libctx and property query propq.

- -

OSSL_STORE_ctrl() takes a OSSL_STORE_CTX, and command number cmd and more arguments not specified here. The available loader specific command numbers and arguments they each take depends on the loader that's used and is documented together with that loader.

- -

There are also global controls available:

- -
- -
OSSL_STORE_C_USE_SECMEM
-
- -

Controls if the loader should attempt to use secure memory for any allocated OSSL_STORE_INFO and its contents. This control expects one argument, a pointer to an int that is expected to have the value 1 (yes) or 0 (no). Any other value is an error.

- -
-
- -

OSSL_STORE_load() takes a OSSL_STORE_CTX and tries to load the next available object and return it wrapped with OSSL_STORE_INFO.

- -

OSSL_STORE_delete() deletes the object identified by uri.

- -

OSSL_STORE_eof() takes a OSSL_STORE_CTX and checks if we've reached the end of data.

- -

OSSL_STORE_error() takes a OSSL_STORE_CTX and checks if an error occurred in the last OSSL_STORE_load() call. Note that it may still be meaningful to try and load more objects, unless OSSL_STORE_eof() shows that the end of data has been reached.

- -

OSSL_STORE_close() takes a OSSL_STORE_CTX, closes the channel that was opened by OSSL_STORE_open() and frees all other information that was stored in the OSSL_STORE_CTX, as well as the OSSL_STORE_CTX itself. If ctx is NULL it does nothing.

- -

NOTES

- -

A string without a scheme prefix (that is, a non-URI string) is implicitly interpreted as using the file: scheme.

- -

There are some tools that can be used together with OSSL_STORE_open() to determine if any failure is caused by an unparsable URI, or if it's a different error (such as memory allocation failures); if the URI was parsable but the scheme unregistered, the top error will have the reason OSSL_STORE_R_UNREGISTERED_SCHEME.

- -

These functions make no direct assumption regarding the pass phrase received from the password callback. The loaders may make assumptions, however. For example, the file: scheme loader inherits the assumptions made by OpenSSL functionality that handles the different file types; this is mostly relevant for PKCS#12 objects. See passphrase-encoding(7) for further information.

- -

RETURN VALUES

- -

OSSL_STORE_open() returns a pointer to a OSSL_STORE_CTX on success, or NULL on failure.

- -

OSSL_STORE_load() returns a pointer to a OSSL_STORE_INFO on success, or NULL on error or when end of data is reached. Use OSSL_STORE_error() and OSSL_STORE_eof() to determine the meaning of a returned NULL.

- -

OSSL_STORE_eof() returns 1 if the end of data has been reached or an error occurred, 0 otherwise.

- -

OSSL_STORE_error() returns 1 if an error occurred in an OSSL_STORE_load() call, otherwise 0.

- -

OSSL_STORE_delete(), OSSL_STORE_ctrl() and OSSL_STORE_close() return 1 on success, or 0 on failure.

- -

SEE ALSO

- -

ossl_store(7), OSSL_STORE_INFO(3), OSSL_STORE_register_loader(3), passphrase-encoding(7)

- -

HISTORY

- -

OSSL_STORE_delete() was added in OpenSSL 3.2.

- -

OSSL_STORE_open_ex() was added in OpenSSL 3.0.

- -

OSSL_STORE_CTX, OSSL_STORE_post_process_info_fn(), OSSL_STORE_open(), OSSL_STORE_ctrl(), OSSL_STORE_load(), OSSL_STORE_eof() and OSSL_STORE_close() were added in OpenSSL 1.1.1.

- -

Handling of NULL ctx argument for OSSL_STORE_close() was introduced in OpenSSL 1.1.1h.

- -

OSSL_STORE_ctrl() and OSSL_STORE_vctrl() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_sleep.html b/openssl-install/share/doc/openssl/html/man3/OSSL_sleep.html deleted file mode 100644 index fcfc84fc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_sleep.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -OSSL_sleep - - - - - - - - - - -

NAME

- -

OSSL_sleep - delay execution for a specified number of milliseconds

- -

SYNOPSIS

- -
#include <openssl/crypto.h>
-
-void OSSL_sleep(uint64_t millis);
- -

DESCRIPTION

- -

OSSL_sleep() is a convenience function to delay execution of the calling thread for (at least) millis milliseconds. The delay is not guaranteed; it may be affected by system activity, by the time spent processing the call, limitation on the underlying system call parameter size or by system timer granularity.

- -

In particular on Windows the maximum amount of time it will sleep is 49 days and on systems where the regular sleep(3) is used as the underlying system call the maximum sleep time is about 136 years.

- -

RETURN VALUES

- -

OSSL_sleep() does not return any value.

- -

HISTORY

- -

OSSL_sleep() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_trace_enabled.html b/openssl-install/share/doc/openssl/html/man3/OSSL_trace_enabled.html deleted file mode 100644 index 33bbafef..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_trace_enabled.html +++ /dev/null @@ -1,278 +0,0 @@ - - - - -OSSL_trace_enabled - - - - - - - - - - -

NAME

- -

OSSL_trace_enabled, OSSL_trace_begin, OSSL_trace_end, OSSL_TRACE_BEGIN, OSSL_TRACE_END, OSSL_TRACE_CANCEL, OSSL_TRACE, OSSL_TRACE1, OSSL_TRACE2, OSSL_TRACE3, OSSL_TRACE4, OSSL_TRACE5, OSSL_TRACE6, OSSL_TRACE7, OSSL_TRACE8, OSSL_TRACE9, OSSL_TRACEV, OSSL_TRACE_STRING, OSSL_TRACE_STRING_MAX, OSSL_trace_string, OSSL_TRACE_ENABLED - OpenSSL Tracing API

- -

SYNOPSIS

- -
#include <openssl/trace.h>
-
-int OSSL_trace_enabled(int category);
-
-BIO *OSSL_trace_begin(int category);
-void OSSL_trace_end(int category, BIO *channel);
-
-/* trace group macros */
-OSSL_TRACE_BEGIN(category) {
-    ...
-    if (some_error) {
-        /* Leave trace group prematurely in case of an error */
-        OSSL_TRACE_CANCEL(category);
-        goto err;
-    }
-    ...
-} OSSL_TRACE_END(category);
-
-/* one-shot trace macros */
-OSSL_TRACE(category, text)
-OSSL_TRACE1(category, format, arg1)
-OSSL_TRACE2(category, format, arg1, arg2)
-...
-OSSL_TRACE9(category, format, arg1, ..., arg9)
-OSSL_TRACE_STRING(category, text, full, data, len)
-
-#define OSSL_TRACE_STRING_MAX 80
-int OSSL_trace_string(BIO *out, int text, int full,
-                      const unsigned char *data, size_t size);
-
-/* check whether a trace category is enabled */
-if (OSSL_TRACE_ENABLED(category)) {
-    ...
-}
- -

DESCRIPTION

- -

The functions described here are mainly interesting for those who provide OpenSSL functionality, either in OpenSSL itself or in engine modules or similar.

- -

If the tracing facility is enabled (see "Configure Tracing" below), these functions are used to generate free text tracing output.

- -

The tracing output is divided into types which are enabled individually by the application. The tracing types are described in detail in "Trace types" in OSSL_trace_set_callback(3). The fallback type OSSL_TRACE_CATEGORY_ALL should not be used with the functions described here.

- -

Tracing for a specific category is enabled at run-time if a so-called trace channel is attached to it. A trace channel is simply a BIO object to which the application can write its trace output.

- -

The application has two different ways of registering a trace channel, either by directly providing a BIO object using OSSL_trace_set_channel(3), or by providing a callback routine using OSSL_trace_set_callback(3). The latter is wrapped internally by a dedicated BIO object, so for the tracing code both channel types are effectively indistinguishable. We call them a simple trace channel and a callback trace channel, respectively.

- -

To produce trace output, it is necessary to obtain a pointer to the trace channel (i.e., the BIO object) using OSSL_trace_begin(), write to it using arbitrary BIO output routines, and finally releases the channel using OSSL_trace_end(). The OSSL_trace_begin()/OSSL_trace_end() calls surrounding the trace output create a group, which acts as a critical section (guarded by a mutex) to ensure that the trace output of different threads does not get mixed up.

- -

The tracing code normally does not call OSSL_trace_{begin,end}() directly, but rather uses a set of convenience macros, see the "Macros" section below.

- -

Functions

- -

OSSL_trace_enabled() can be used to check if tracing for the given category is enabled, i.e., if the tracing facility has been statically enabled (see "Configure Tracing" below) and a trace channel has been registered using OSSL_trace_set_channel(3) or OSSL_trace_set_callback(3).

- -

OSSL_trace_begin() is used to start a tracing section, and get the channel for the given category in form of a BIO. This BIO can only be used for output. The pointer returned is NULL if the category is invalid or not enabled.

- -

OSSL_trace_end() is used to end a tracing section.

- -

Using OSSL_trace_begin() and OSSL_trace_end() to wrap tracing sections is mandatory. The result of trying to produce tracing output outside of such sections is undefined.

- -

OSSL_trace_string() outputs data of length size as a string on BIO out. If text is 0, the function masks any included control characters apart from newlines and makes sure for nonempty input that the output ends with a newline. Unless full is nonzero, the length is limited (with a suitable warning) to OSSL_TRACE_STRING_MAX characters, which currently is 80.

- -

Macros

- -

There are a number of convenience macros defined, to make tracing easy and consistent.

- -

OSSL_TRACE_BEGIN() and OSSL_TRACE_END() reserve the BIO trc_out and are used as follows to wrap a trace section:

- -
OSSL_TRACE_BEGIN(TLS) {
-
-    BIO_printf(trc_out, ... );
-
-} OSSL_TRACE_END(TLS);
- -

This will normally expand to:

- -
do {
-    BIO *trc_out = OSSL_trace_begin(OSSL_TRACE_CATEGORY_TLS);
-    if (trc_out != NULL) {
-        ...
-        BIO_printf(trc_out, ...);
-    }
-    OSSL_trace_end(OSSL_TRACE_CATEGORY_TLS, trc_out);
-} while (0);
- -

OSSL_TRACE_CANCEL() must be used before returning from or jumping out of a trace section:

- -
OSSL_TRACE_BEGIN(TLS) {
-
-    if (some_error) {
-        OSSL_TRACE_CANCEL(TLS);
-        goto err;
-    }
-    BIO_printf(trc_out, ... );
-
-} OSSL_TRACE_END(TLS);
- -

This will normally expand to:

- -
do {
-    BIO *trc_out = OSSL_trace_begin(OSSL_TRACE_CATEGORY_TLS);
-    if (trc_out != NULL) {
-        if (some_error) {
-            OSSL_trace_end(OSSL_TRACE_CATEGORY_TLS, trc_out);
-            goto err;
-        }
-        BIO_printf(trc_out, ... );
-    }
-    OSSL_trace_end(OSSL_TRACE_CATEGORY_TLS, trc_out);
-} while (0);
- -

OSSL_TRACE() and OSSL_TRACE1(), OSSL_TRACE2(), ... OSSL_TRACE9() are so-called one-shot macros:

- -

The macro call OSSL_TRACE(category, text), produces literal text trace output.

- -

The macro call OSSL_TRACEn(category, format, arg1, ..., argn) produces printf-style trace output with n format field arguments (n=1,...,9). It expands to:

- -
OSSL_TRACE_BEGIN(category) {
-    BIO_printf(trc_out, format, arg1, ..., argN);
-} OSSL_TRACE_END(category)
- -

Internally, all one-shot macros are implemented using a generic OSSL_TRACEV() macro, since C90 does not support variadic macros. This helper macro has a rather weird synopsis and should not be used directly.

- -

The macro call OSSL_TRACE_STRING(category, text, full, data, len) outputs data of length size as a string if tracing for the given category is enabled. It expands to:

- -
OSSL_TRACE_BEGIN(category) {
-    OSSL_trace_string(trc_out, text, full, data, len);
-} OSSL_TRACE_END(category)
- -

The OSSL_TRACE_ENABLED() macro can be used to conditionally execute some code only if a specific trace category is enabled. In some situations this is simpler than entering a trace section using OSSL_TRACE_BEGIN() and OSSL_TRACE_END(). For example, the code

- -
if (OSSL_TRACE_ENABLED(TLS)) {
-    ...
-}
- -

expands to

- -
if (OSSL_trace_enabled(OSSL_TRACE_CATEGORY_TLS) {
-    ...
-}
- -

NOTES

- -

It is not needed to guard trace output function calls like OSSL_TRACE(category, ...) by OSSL_TRACE_ENABLED(category).

- -

If producing the trace output requires carrying out auxiliary calculations, this auxiliary code should be placed inside a conditional block which is executed only if the trace category is enabled.

- -

The most natural way to do this is to place the code inside the trace section itself because it already introduces such a conditional block.

- -
OSSL_TRACE_BEGIN(TLS) {
-    int var = do_some_auxiliary_calculation();
-
-    BIO_printf(trc_out, "var = %d\n", var);
-
-} OSSL_TRACE_END(TLS);
- -

In some cases it is more advantageous to use a simple conditional group instead of a trace section. This is the case if calculations and tracing happen in different locations of the code, or if the calculations are so time consuming that placing them inside a (critical) trace section would create too much contention.

- -
if (OSSL_TRACE_ENABLED(TLS)) {
-    int var = do_some_auxiliary_calculation();
-
-    OSSL_TRACE1("var = %d\n", var);
-}
- -

Note however that premature optimization of tracing code is in general futile and it's better to keep the tracing code as simple as possible. Because most often the limiting factor for the application's speed is the time it takes to print the trace output, not to calculate it.

- -

Configure Tracing

- -

By default, the OpenSSL library is built with tracing disabled. To use the tracing functionality documented here, it is therefore necessary to configure and build OpenSSL with the 'enable-trace' option.

- -

When the library is built with tracing disabled:

- - - -

RETURN VALUES

- -

OSSL_trace_enabled() returns 1 if tracing for the given type is operational and enabled, otherwise 0.

- -

OSSL_trace_begin() returns a BIO pointer if the given type is enabled, otherwise NULL.

- -

OSSL_trace_string() returns the number of characters emitted, or -1 on error.

- -

SEE ALSO

- -

OSSL_trace_set_channel(3), OSSL_trace_set_callback(3)

- -

HISTORY

- -

The OpenSSL Tracing API was added in OpenSSL 3.0.

- -

OSSL_TRACE_STRING(), OSSL_TRACE_STRING_MAX, and OSSL_trace_string were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_trace_get_category_num.html b/openssl-install/share/doc/openssl/html/man3/OSSL_trace_get_category_num.html deleted file mode 100644 index b95c2021..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_trace_get_category_num.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -OSSL_trace_get_category_num - - - - - - - - - - -

NAME

- -

OSSL_trace_get_category_num, OSSL_trace_get_category_name - OpenSSL tracing information functions

- -

SYNOPSIS

- -
#include <openssl/trace.h>
-
-int OSSL_trace_get_category_num(const char *name);
-const char *OSSL_trace_get_category_name(int num);
- -

DESCRIPTION

- -

OSSL_trace_get_category_num() gives the category number corresponding to the given name.

- -

OSSL_trace_get_category_name() gives the category name corresponding to the given num.

- -

RETURN VALUES

- -

OSSL_trace_get_category_num() returns the category number if the given name is a recognised category name, otherwise -1.

- -

OSSL_trace_get_category_name() returns the category name if the given num is a recognised category number, otherwise NULL.

- -

HISTORY

- -

The OpenSSL Tracing API was added ino OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OSSL_trace_set_channel.html b/openssl-install/share/doc/openssl/html/man3/OSSL_trace_set_channel.html deleted file mode 100644 index b52836b4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OSSL_trace_set_channel.html +++ /dev/null @@ -1,350 +0,0 @@ - - - - -OSSL_trace_set_channel - - - - - - - - - - -

NAME

- -

OSSL_trace_set_channel, OSSL_trace_set_prefix, OSSL_trace_set_suffix, OSSL_trace_set_callback, OSSL_trace_cb - Enabling trace output

- -

SYNOPSIS

- -
#include <openssl/trace.h>
-
-typedef size_t (*OSSL_trace_cb)(const char *buf, size_t cnt,
-                                int category, int cmd, void *data);
-
-void OSSL_trace_set_channel(int category, BIO *bio);
-void OSSL_trace_set_prefix(int category, const char *prefix);
-void OSSL_trace_set_suffix(int category, const char *suffix);
-void OSSL_trace_set_callback(int category, OSSL_trace_cb cb, void  *data);
- -

DESCRIPTION

- -

If available (see "Configure Tracing" below), the application can request internal trace output. This output comes in form of free text for humans to read.

- -

The trace output is divided into categories which can be enabled individually. Every category can be enabled individually by attaching a so-called trace channel to it, which in the simplest case is just a BIO object to which the application can write the tracing output for this category. Alternatively, the application can provide a tracer callback in order to get more finegrained trace information. This callback will be wrapped internally by a dedicated BIO object.

- -

For the tracing code, both trace channel types are indistinguishable. These are called a simple trace channel and a callback trace channel, respectively.

- -

OSSL_TRACE_ENABLED(3) can be used to check whether tracing is currently enabled for the given category. Functions like OSSL_TRACE1(3) and macros like OSSL_TRACE_BEGIN(3) can be used for producing free-text trace output.

- -

Functions

- -

OSSL_trace_set_channel() is used to enable the given trace category by attaching the BIO bio object as (simple) trace channel. On success the ownership of the BIO is transferred to the channel, so the caller must not free it directly.

- -

OSSL_trace_set_prefix() and OSSL_trace_set_suffix() can be used to add an extra line for each channel, to be output before and after group of tracing output. What constitutes an output group is decided by the code that produces the output. The lines given here are considered immutable; for more dynamic tracing prefixes, consider setting a callback with OSSL_trace_set_callback() instead.

- -

OSSL_trace_set_callback() is used to enable the given trace category by giving it the tracer callback cb with the associated data data, which will simply be passed through to cb whenever it's called. The callback function is internally wrapped by a dedicated BIO object, the so-called callback trace channel. This should be used when it's desirable to do form the trace output to something suitable for application needs where a prefix and suffix line aren't enough.

- -

OSSL_trace_set_channel() and OSSL_trace_set_callback() are mutually exclusive, calling one of them will clear whatever was set by the previous call.

- -

Calling OSSL_trace_set_channel() with NULL for channel or OSSL_trace_set_callback() with NULL for cb disables tracing for the given category.

- -

Trace callback

- -

The tracer callback must return a size_t, which must be zero on error and otherwise return the number of bytes that were output. It receives a text buffer buf with cnt bytes of text, as well as the category, a control number cmd, and the data that was passed to OSSL_trace_set_callback().

- -

The possible control numbers are:

- -
- -
OSSL_TRACE_CTRL_BEGIN
-
- -

The callback is called from OSSL_trace_begin(), which gives the callback the possibility to output a dynamic starting line, or set a prefix that should be output at the beginning of each line, or something other.

- -
-
OSSL_TRACE_CTRL_WRITE
-
- -

This callback is called whenever data is written to the BIO by some regular BIO output routine. An arbitrary number of OSSL_TRACE_CTRL_WRITE callbacks can occur inside a group marked by a pair of OSSL_TRACE_CTRL_BEGIN and OSSL_TRACE_CTRL_END calls, but never outside such a group.

- -
-
OSSL_TRACE_CTRL_END
-
- -

The callback is called from OSSL_trace_end(), which gives the callback the possibility to output a dynamic ending line, or reset the line prefix that was set with OSSL_TRACE_CTRL_BEGIN, or something other.

- -
-
- -

Trace categories

- -

The trace categories are simple numbers available through macros.

- -
- -
OSSL_TRACE_CATEGORY_TRACE
-
- -

Traces the OpenSSL trace API itself.

- -

More precisely, this will generate trace output any time a new trace hook is set.

- -
-
OSSL_TRACE_CATEGORY_INIT
-
- -

Traces OpenSSL library initialization and cleanup.

- -

This needs special care, as OpenSSL will do automatic cleanup after exit from main(), and any tracing output done during this cleanup will be lost if the tracing channel or callback were cleaned away prematurely. A suggestion is to make such cleanup part of a function that's registered very early with atexit(3).

- -
-
OSSL_TRACE_CATEGORY_TLS
-
- -

Traces the TLS/SSL protocol.

- -
-
OSSL_TRACE_CATEGORY_TLS_CIPHER
-
- -

Traces the ciphers used by the TLS/SSL protocol.

- -
-
OSSL_TRACE_CATEGORY_CONF
-
- -

Traces details about the provider and engine configuration.

- -
-
OSSL_TRACE_CATEGORY_ENGINE_TABLE
-
- -

Traces the ENGINE algorithm table selection.

- -

More precisely, functions like ENGINE_get_pkey_asn1_meth_engine(), ENGINE_get_pkey_meth_engine(), ENGINE_get_cipher_engine(), ENGINE_get_digest_engine(), will generate trace summaries of the handling of internal tables.

- -
-
OSSL_TRACE_CATEGORY_ENGINE_REF_COUNT
-
- -

Traces the ENGINE reference counting.

- -

More precisely, both reference counts in the ENGINE structure will be monitored with a line of trace output generated for each change.

- -
-
OSSL_TRACE_CATEGORY_PKCS5V2
-
- -

Traces PKCS#5 v2 key generation.

- -
-
OSSL_TRACE_CATEGORY_PKCS12_KEYGEN
-
- -

Traces PKCS#12 key generation.

- -
-
OSSL_TRACE_CATEGORY_PKCS12_DECRYPT
-
- -

Traces PKCS#12 decryption.

- -
-
OSSL_TRACE_CATEGORY_X509V3_POLICY
-
- -

Traces X509v3 policy processing.

- -

More precisely, this generates the complete policy tree at various point during evaluation.

- -
-
OSSL_TRACE_CATEGORY_BN_CTX
-
- -

Traces BIGNUM context operations.

- -
-
OSSL_TRACE_CATEGORY_CMP
-
- -

Traces CMP client and server activity.

- -
-
OSSL_TRACE_CATEGORY_STORE
-
- -

Traces STORE operations.

- -
-
OSSL_TRACE_CATEGORY_DECODER
-
- -

Traces decoder operations.

- -
-
OSSL_TRACE_CATEGORY_ENCODER
-
- -

Traces encoder operations.

- -
-
OSSL_TRACE_CATEGORY_REF_COUNT
-
- -

Traces decrementing certain ASN.1 structure references.

- -
-
OSSL_TRACE_CATEGORY_HTTP
-
- -

Traces the HTTP client, such as message headers being sent and received.

- -
-
- -

There is also OSSL_TRACE_CATEGORY_ALL, which works as a fallback and can be used to get all trace output.

- -

Note, however, that in this case all trace output will effectively be associated with the 'ALL' category, which is undesirable if the application intends to include the category name in the trace output. In this case it is better to register separate channels for each trace category instead.

- -

RETURN VALUES

- -

OSSL_trace_set_channel(), OSSL_trace_set_prefix(), OSSL_trace_set_suffix(), and OSSL_trace_set_callback() return 1 on success, or 0 on failure.

- -

EXAMPLES

- -

In all examples below, the trace producing code is assumed to be the following:

- -
int foo = 42;
-const char bar[] = { 0,  1,  2,  3,  4,  5,  6,  7,
-                     8,  9, 10, 11, 12, 13, 14, 15 };
-
-OSSL_TRACE_BEGIN(TLS) {
-    BIO_puts(trc_out, "foo: ");
-    BIO_printf(trc_out, "%d\n", foo);
-    BIO_dump(trc_out, bar, sizeof(bar));
-} OSSL_TRACE_END(TLS);
- -

Simple example

- -

An example with just a channel and constant prefix / suffix.

- -
int main(int argc, char *argv[])
-{
-    BIO *err = BIO_new_fp(stderr, BIO_NOCLOSE | BIO_FP_TEXT);
-    OSSL_trace_set_channel(OSSL_TRACE_CATEGORY_SSL, err);
-    OSSL_trace_set_prefix(OSSL_TRACE_CATEGORY_SSL, "BEGIN TRACE[TLS]");
-    OSSL_trace_set_suffix(OSSL_TRACE_CATEGORY_SSL, "END TRACE[TLS]");
-
-    /* ... work ... */
-}
- -

When the trace producing code above is performed, this will be output on standard error:

- -
BEGIN TRACE[TLS]
-foo: 42
-0000 - 00 01 02 03 04 05 06 07-08 09 0a 0b 0c 0d 0e 0f   ................
-END TRACE[TLS]
- -

Advanced example

- -

This example uses the callback, and depends on pthreads functionality.

- -
static size_t cb(const char *buf, size_t cnt,
-                int category, int cmd, void *vdata)
-{
-    BIO *bio = vdata;
-    const char *label = NULL;
-
-    switch (cmd) {
-    case OSSL_TRACE_CTRL_BEGIN:
-        label = "BEGIN";
-        break;
-    case OSSL_TRACE_CTRL_END:
-        label = "END";
-        break;
-    }
-
-    if (label != NULL) {
-        union {
-            pthread_t tid;
-            unsigned long ltid;
-        } tid;
-
-        tid.tid = pthread_self();
-        BIO_printf(bio, "%s TRACE[%s]:%lx\n",
-                   label, OSSL_trace_get_category_name(category), tid.ltid);
-    }
-    return (size_t)BIO_puts(bio, buf);
-}
-
-int main(int argc, char *argv[])
-{
-    BIO *err = BIO_new_fp(stderr, BIO_NOCLOSE | BIO_FP_TEXT);
-    OSSL_trace_set_callback(OSSL_TRACE_CATEGORY_SSL, cb, err);
-
-    /* ... work ... */
-}
- -

The output is almost the same as for the simple example above.

- -
BEGIN TRACE[TLS]:7f9eb0193b80
-foo: 42
-0000 - 00 01 02 03 04 05 06 07-08 09 0a 0b 0c 0d 0e 0f   ................
-END TRACE[TLS]:7f9eb0193b80
- -

NOTES

- -

Configure Tracing

- -

By default, the OpenSSL library is built with tracing disabled. To use the tracing functionality documented here, it is therefore necessary to configure and build OpenSSL with the 'enable-trace' option.

- -

When the library is built with tracing disabled, the macro OPENSSL_NO_TRACE is defined in <openssl/opensslconf.h> and all functions described here are inoperational, i.e. will do nothing.

- -

SEE ALSO

- -

OSSL_TRACE_ENABLED(3), OSSL_TRACE_BEGIN(3), OSSL_TRACE1(3), atexit(3)

- -

HISTORY

- -

OSSL_trace_set_channel(), OSSL_trace_set_prefix(), OSSL_trace_set_suffix(), and OSSL_trace_set_callback() were all added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OpenSSL_add_all_algorithms.html b/openssl-install/share/doc/openssl/html/man3/OpenSSL_add_all_algorithms.html deleted file mode 100644 index f4f67195..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OpenSSL_add_all_algorithms.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -OpenSSL_add_all_algorithms - - - - - - - - - - -

NAME

- -

OpenSSL_add_all_algorithms, OpenSSL_add_all_ciphers, OpenSSL_add_all_digests, EVP_cleanup - add algorithms to internal table

- -

SYNOPSIS

- -
#include <openssl/evp.h>
- -

The following functions have been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void OpenSSL_add_all_algorithms(void);
-void OpenSSL_add_all_ciphers(void);
-void OpenSSL_add_all_digests(void);
-
-void EVP_cleanup(void);
- -

DESCRIPTION

- -

OpenSSL keeps an internal table of digest algorithms and ciphers. It uses this table to lookup ciphers via functions such as EVP_get_cipher_byname().

- -

OpenSSL_add_all_digests() adds all digest algorithms to the table.

- -

OpenSSL_add_all_algorithms() adds all algorithms to the table (digests and ciphers).

- -

OpenSSL_add_all_ciphers() adds all encryption algorithms to the table including password based encryption algorithms.

- -

In versions prior to 1.1.0 EVP_cleanup() removed all ciphers and digests from the table. It no longer has any effect in OpenSSL 1.1.0.

- -

RETURN VALUES

- -

None of the functions return a value.

- -

SEE ALSO

- -

evp(7), EVP_DigestInit(3), EVP_EncryptInit(3)

- -

HISTORY

- -

The OpenSSL_add_all_algorithms(), OpenSSL_add_all_ciphers(), OpenSSL_add_all_digests(), and EVP_cleanup(), functions were deprecated in OpenSSL 1.1.0 by OPENSSL_init_crypto() and should not be used.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/OpenSSL_version.html b/openssl-install/share/doc/openssl/html/man3/OpenSSL_version.html deleted file mode 100644 index ee479f14..00000000 --- a/openssl-install/share/doc/openssl/html/man3/OpenSSL_version.html +++ /dev/null @@ -1,272 +0,0 @@ - - - - -OpenSSL_version - - - - - - - - - - -

NAME

- -

OPENSSL_VERSION_MAJOR, OPENSSL_VERSION_MINOR, OPENSSL_VERSION_PATCH, OPENSSL_VERSION_PRE_RELEASE, OPENSSL_VERSION_BUILD_METADATA, OPENSSL_VERSION_TEXT, OPENSSL_VERSION_PREREQ, OPENSSL_version_major, OPENSSL_version_minor, OPENSSL_version_patch, OPENSSL_version_pre_release, OPENSSL_version_build_metadata, OpenSSL_version, OPENSSL_VERSION_NUMBER, OpenSSL_version_num, OPENSSL_info - get OpenSSL version number and other information

- -

SYNOPSIS

- -
#include <openssl/opensslv.h>
-
-#define OPENSSL_VERSION_MAJOR  x
-#define OPENSSL_VERSION_MINOR  y
-#define OPENSSL_VERSION_PATCH  z
-
-/* The definitions here are typical release values */
-#define OPENSSL_VERSION_PRE_RELEASE ""
-#define OPENSSL_VERSION_BUILD_METADATA ""
-
-#define OPENSSL_VERSION_TEXT "OpenSSL x.y.z xx XXX xxxx"
-
-#define OPENSSL_VERSION_PREREQ(maj,min)
-
-#include <openssl/crypto.h>
-
-unsigned int OPENSSL_version_major(void);
-unsigned int OPENSSL_version_minor(void);
-unsigned int OPENSSL_version_patch(void);
-const char *OPENSSL_version_pre_release(void);
-const char *OPENSSL_version_build_metadata(void);
-
-const char *OpenSSL_version(int t);
-
-const char *OPENSSL_info(int t);
-
-/* from openssl/opensslv.h */
-#define OPENSSL_VERSION_NUMBER 0xnnnnnnnnL
-
-/* from openssl/crypto.h */
-unsigned long OpenSSL_version_num();
- -

DESCRIPTION

- -

Macros

- -

The three macros OPENSSL_VERSION_MAJOR, OPENSSL_VERSION_MINOR and OPENSSL_VERSION_PATCH represent the three parts of a version identifier, MAJOR.MINOR.PATCH.

- -

The macro OPENSSL_VERSION_PRE_RELEASE is an added bit of text that indicates that this is a pre-release version, such as "-dev" for an ongoing development snapshot or "-alpha3" for an alpha release. The value must be a string.

- -

The macro OPENSSL_VERSION_BUILD_METADATA is extra information, reserved for other parties, such as "+fips", or "+vendor.1"). The OpenSSL project will not touch this macro (will leave it an empty string). The value must be a string.

- -

OPENSSL_VERSION_STR is a convenience macro to get the short version identifier string, "MAJOR.MINOR.PATCH".

- -

OPENSSL_FULL_VERSION_STR is a convenience macro to get the longer version identifier string, which combines OPENSSL_VERSION_STR, OPENSSL_VERSION_PRE_RELEASE and OPENSSL_VERSION_BUILD_METADATA.

- -

OPENSSL_VERSION_TEXT is a convenience macro to get a full descriptive version text, which includes OPENSSL_FULL_VERSION_STR and the release date.

- -

OPENSSL_VERSION_PREREQ is a useful macro for checking whether the OpenSSL version for the headers in use is at least at the given pre-requisite major (maj) and minor (min) number or not. It will evaluate to true if the header version number (OPENSSL_VERSION_MAJOR.OPENSSL_VERSION_MINOR) is greater than or equal to maj.min.

- -

OPENSSL_VERSION_NUMBER is a combination of the major, minor and patch version into a single integer 0xMNN00PP0L, where:

- -
- -
M
-
- -

is the number from OPENSSL_VERSION_MAJOR, in hexadecimal notation

- -
-
NN
-
- -

is the number from OPENSSL_VERSION_MINOR, in hexadecimal notation

- -
-
PP
-
- -

is the number from OPENSSL_VERSION_PATCH, in hexadecimal notation

- -
-
- -

Functions

- -

OPENSSL_version_major(), OPENSSL_version_minor(), OPENSSL_version_patch(), OPENSSL_version_pre_release(), and OPENSSL_version_build_metadata() return the values of the macros above for the build of the library, respectively.

- -

OpenSSL_version() returns different strings depending on t:

- -
- -
OPENSSL_VERSION
-
- -

The value of OPENSSL_VERSION_TEXT

- -
-
OPENSSL_VERSION_STRING
-
- -

The value of OPENSSL_VERSION_STR

- -
-
OPENSSL_FULL_VERSION_STRING
-
- -

The value of OPENSSL_FULL_VERSION_STR

- -
-
OPENSSL_CFLAGS
-
- -

The compiler flags set for the compilation process in the form compiler: ... if available, or compiler: information not available otherwise.

- -
-
OPENSSL_BUILT_ON
-
- -

The date of the build process in the form built on: ... if available or built on: date not available otherwise. The date would not be available in a reproducible build, for example.

- -
-
OPENSSL_PLATFORM
-
- -

The "Configure" target of the library build in the form platform: ... if available, or platform: information not available otherwise.

- -
-
OPENSSL_DIR
-
- -

The OPENSSLDIR setting of the library build in the form OPENSSLDIR: "..." if available, or OPENSSLDIR: N/A otherwise.

- -
-
OPENSSL_ENGINES_DIR
-
- -

The ENGINESDIR setting of the library build in the form ENGINESDIR: "..." if available, or ENGINESDIR: N/A otherwise. This option is deprecated in OpenSSL 3.0.

- -
-
OPENSSL_MODULES_DIR
-
- -

The MODULESDIR setting of the library build in the form MODULESDIR: "..." if available, or MODULESDIR: N/A otherwise.

- -
-
OPENSSL_CPU_INFO
-
- -

The current OpenSSL cpu settings. This is the current setting of the cpu capability flags. It is usually automatically configured but may be set via an environment variable. The value has the same syntax as the environment variable. For x86 the string looks like CPUINFO: OPENSSL_ia32cap=0x123:0x456 or CPUINFO: N/A if not available.

- -
-
OPENSSL_WINCTX
-
- -

The Windows install context. The Windows install context is used to compute the OpenSSL registry key name on Windows. The full registry key is SOFTWARE\WOW6432Node\OpenSSL-{major}.{minor}-{context}, where {major}, {minor} and {context} are OpenSSL's major version number, minor version number and the Windows install context, respectively.

- -
-
- -

For an unknown t, the text not available is returned.

- -

OPENSSL_info() also returns different strings depending on t:

- -
- -
OPENSSL_INFO_CONFIG_DIR
-
- -

The configured OPENSSLDIR, which is the default location for OpenSSL configuration files.

- -
-
OPENSSL_INFO_ENGINES_DIR
-
- -

The configured ENGINESDIR, which is the default location for OpenSSL engines.

- -
-
OPENSSL_INFO_MODULES_DIR
-
- -

The configured MODULESDIR, which is the default location for dynamically loadable OpenSSL modules other than engines.

- -
-
OPENSSL_INFO_DSO_EXTENSION
-
- -

The configured dynamically loadable module extension.

- -
-
OPENSSL_INFO_DIR_FILENAME_SEPARATOR
-
- -

The separator between a directory specification and a filename. Note that on some operating systems, this is not the same as the separator between directory elements.

- -
-
OPENSSL_INFO_LIST_SEPARATOR
-
- -

The OpenSSL list separator. This is typically used in strings that are lists of items, such as the value of the environment variable $PATH on Unix (where the separator is :) or %PATH% on Windows (where the separator is ;).

- -
-
OPENSSL_INFO_CPU_SETTINGS
-
- -

The current OpenSSL cpu settings. This is the current setting of the cpu capability flags. It is usually automatically configured but may be set via an environment variable. The value has the same syntax as the environment variable. For x86 the string looks like OPENSSL_ia32cap=0x123:0x456.

- -
-
OPENSSL_INFO_WINDOWS_CONTEXT
-
- -

The Windows install context. The Windows install context is used to compute the OpenSSL registry key name on Windows. The full registry key is SOFTWARE\WOW6432Node\OpenSSL-{major}.{minor}-{context}, where {major}, {minor} and {context} are OpenSSL's major version number, minor version number and the Windows install context, respectively.

- -
-
- -

For an unknown t, NULL is returned.

- -

OpenSSL_version_num() returns the value of OPENSSL_VERSION_NUMBER.

- -

RETURN VALUES

- -

OPENSSL_version_major(), OPENSSL_version_minor() and OPENSSL_version_patch() return the version number parts as integers.

- -

OPENSSL_version_pre_release() and OPENSSL_version_build_metadata() return the values of OPENSSL_VERSION_PRE_RELEASE and OPENSSL_VERSION_BUILD_METADATA respectively as constant strings. For any of them that is undefined, the empty string is returned.

- -

OpenSSL_version() returns constant strings.

- -

SEE ALSO

- -

crypto(7)

- -

HISTORY

- -

The macros and functions described here were added in OpenSSL 3.0, except for OPENSSL_VERSION_NUMBER and OpenSSL_version_num().

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PBMAC1_get1_pbkdf2_param.html b/openssl-install/share/doc/openssl/html/man3/PBMAC1_get1_pbkdf2_param.html deleted file mode 100644 index 0244af69..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PBMAC1_get1_pbkdf2_param.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -PBMAC1_get1_pbkdf2_param - - - - - - - - - - -

NAME

- -

PBMAC1_get1_pbkdf2_param - Function to manipulate a PBMAC1 MAC structure

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-PBKDF2PARAM *PBMAC1_get1_pbkdf2_param(const X509_ALGOR *macalg);
- -

DESCRIPTION

- -

PBMAC1_get1_pbkdf2_param() retrieves a PBKDF2PARAM structure from an X509_ALGOR structure.

- -

RETURN VALUES

- -

PBMAC1_get1_pbkdf2_param() returns NULL in case when PBMAC1 uses an algorithm apart from PBKDF2 or when passed incorrect parameters and a pointer to PBKDF2PARAM structure otherwise.

- -

CONFORMING TO

- -

IETF RFC 9579 (https://tools.ietf.org/html/rfc9579)

- -

SEE ALSO

- -

openssl-pkcs12(1)

- -

HISTORY

- -

The PBMAC1_get1_pbkdf2_param function was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_X509_INFO_read_bio_ex.html b/openssl-install/share/doc/openssl/html/man3/PEM_X509_INFO_read_bio_ex.html deleted file mode 100644 index a003e516..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_X509_INFO_read_bio_ex.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -PEM_X509_INFO_read_bio_ex - - - - - - - - - - -

NAME

- -

PEM_X509_INFO_read_ex, PEM_X509_INFO_read, PEM_X509_INFO_read_bio_ex, PEM_X509_INFO_read_bio - read PEM-encoded data structures into one or more X509_INFO objects

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-STACK_OF(X509_INFO) *PEM_X509_INFO_read_ex(FILE *fp, STACK_OF(X509_INFO) *sk,
-                                           pem_password_cb *cb, void *u,
-                                           OSSL_LIB_CTX *libctx,
-                                           const char *propq);
-STACK_OF(X509_INFO) *PEM_X509_INFO_read(FILE *fp, STACK_OF(X509_INFO) *sk,
-                                        pem_password_cb *cb, void *u);
-STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bio,
-                                               STACK_OF(X509_INFO) *sk,
-                                               pem_password_cb *cb, void *u,
-                                               OSSL_LIB_CTX *libctx,
-                                               const char *propq);
-STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio(BIO *bp, STACK_OF(X509_INFO) *sk,
-                                            pem_password_cb *cb, void *u);
- -

DESCRIPTION

- -

PEM_X509_INFO_read_ex() loads the X509_INFO objects from a file fp.

- -

PEM_X509_INFO_read() is similar to PEM_X509_INFO_read_ex() but uses the default (NULL) library context libctx and empty property query propq.

- -

PEM_X509_INFO_read_bio_ex() loads the X509_INFO objects using a bio bp.

- -

PEM_X509_INFO_read_bio() is similar to PEM_X509_INFO_read_bio_ex() but uses the default (NULL) library context libctx and empty property query propq.

- -

Each of the loaded X509_INFO objects can contain a CRL, a certificate, and/or a private key. The elements are read sequentially, and as far as they are of different type than the elements read before, they are combined into the same X509_INFO object. The idea behind this is that if, for instance, a certificate is followed by a private key, the private key is supposed to correspond to the certificate.

- -

If the input stack sk is NULL a new stack is allocated, else the given stack is extended.

- -

The optional cb and u parameters can be used for providing a pass phrase needed for decrypting encrypted PEM structures (normally only private keys). See PEM_read_bio_PrivateKey(3) and passphrase-encoding(7) for details.

- -

The library context libctx and property query propq are used for fetching algorithms from providers.

- -

RETURN VALUES

- -

PEM_X509_INFO_read_ex(), PEM_X509_INFO_read(), PEM_X509_INFO_read_bio_ex() and PEM_X509_INFO_read_bio() return a stack of X509_INFO objects or NULL on failure.

- -

SEE ALSO

- -

PEM_read_bio_ex(3), PEM_read_bio_PrivateKey(3), passphrase-encoding(7)

- -

HISTORY

- -

The functions PEM_X509_INFO_read_ex() and PEM_X509_INFO_read_bio_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_bytes_read_bio.html b/openssl-install/share/doc/openssl/html/man3/PEM_bytes_read_bio.html deleted file mode 100644 index c4caece3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_bytes_read_bio.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -PEM_bytes_read_bio - - - - - - - - - - -

NAME

- -

PEM_bytes_read_bio, PEM_bytes_read_bio_secmem - read a PEM-encoded data structure from a BIO

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-int PEM_bytes_read_bio(unsigned char **pdata, long *plen, char **pnm,
-                       const char *name, BIO *bp, pem_password_cb *cb,
-                       void *u);
-int PEM_bytes_read_bio_secmem(unsigned char **pdata, long *plen, char **pnm,
-                              const char *name, BIO *bp, pem_password_cb *cb,
-                              void *u);
- -

DESCRIPTION

- -

PEM_bytes_read_bio() reads PEM-formatted (IETF RFC 1421 and IETF RFC 7468) data from the BIO bp for the data type given in name (RSA PRIVATE KEY, CERTIFICATE, etc.). If multiple PEM-encoded data structures are present in the same stream, PEM_bytes_read_bio() will skip non-matching data types and continue reading. Non-PEM data present in the stream may cause an error.

- -

The PEM header may indicate that the following data is encrypted; if so, the data will be decrypted, waiting on user input to supply a passphrase if needed. The password callback cb and rock u are used to obtain the decryption passphrase, if applicable.

- -

Some data types have compatibility aliases, such as a file containing X509 CERTIFICATE matching a request for the deprecated type CERTIFICATE. The actual type indicated by the file is returned in *pnm if pnm is non-NULL. The caller must free the storage pointed to by *pnm.

- -

The returned data is the DER-encoded form of the requested type, in *pdata with length *plen. The caller must free the storage pointed to by *pdata.

- -

PEM_bytes_read_bio_secmem() is similar to PEM_bytes_read_bio(), but uses memory from the secure heap for its temporary buffers and the storage returned in *pdata and *pnm. Accordingly, the caller must use OPENSSL_secure_free() to free that storage.

- -

NOTES

- -

PEM_bytes_read_bio_secmem() only enforces that the secure heap is used for storage allocated within the PEM processing stack. The BIO stack from which input is read may also use temporary buffers, which are not necessarily allocated from the secure heap. In cases where it is desirable to ensure that the contents of the PEM file only appears in memory from the secure heap, care is needed in generating the BIO passed as bp. In particular, the use of BIO_s_file() indicates the use of the operating system stdio functionality, which includes buffering as a feature; BIO_s_fd() is likely to be more appropriate in such cases.

- -

These functions make no assumption regarding the pass phrase received from the password callback. It will simply be treated as a byte sequence.

- -

RETURN VALUES

- -

PEM_bytes_read_bio() and PEM_bytes_read_bio_secmem() return 1 for success or 0 for failure.

- -

SEE ALSO

- -

PEM_read_bio_ex(3), passphrase-encoding(7)

- -

HISTORY

- -

PEM_bytes_read_bio_secmem() was introduced in OpenSSL 1.1.1

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_read.html b/openssl-install/share/doc/openssl/html/man3/PEM_read.html deleted file mode 100644 index 1188af4b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_read.html +++ /dev/null @@ -1,98 +0,0 @@ - - - - -PEM_read - - - - - - - - - - -

NAME

- -

PEM_write, PEM_write_bio, PEM_read, PEM_read_bio, PEM_do_header, PEM_get_EVP_CIPHER_INFO - PEM encoding routines

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-int PEM_write(FILE *fp, const char *name, const char *header,
-              const unsigned char *data, long len);
-int PEM_write_bio(BIO *bp, const char *name, const char *header,
-                  const unsigned char *data, long len);
-
-int PEM_read(FILE *fp, char **name, char **header,
-             unsigned char **data, long *len);
-int PEM_read_bio(BIO *bp, char **name, char **header,
-                 unsigned char **data, long *len);
-
-int PEM_get_EVP_CIPHER_INFO(char *header, EVP_CIPHER_INFO *cinfo);
-int PEM_do_header(EVP_CIPHER_INFO *cinfo, unsigned char *data, long *len,
-                  pem_password_cb *cb, void *u);
- -

DESCRIPTION

- -

These functions read and write PEM-encoded objects, using the PEM type name, any additional header information, and the raw data of length len.

- -

PEM is the term used for binary content encoding first defined in IETF RFC 1421. The content is a series of base64-encoded lines, surrounded by begin/end markers each on their own line. For example:

- -
-----BEGIN PRIVATE KEY-----
-MIICdg....
-... bhTQ==
------END PRIVATE KEY-----
- -

Optional header line(s) may appear after the begin line, and their existence depends on the type of object being written or read.

- -

PEM_write() writes to the file fp, while PEM_write_bio() writes to the BIO bp. The name is the name to use in the marker, the header is the header value or NULL, and data and len specify the data and its length.

- -

The final data buffer is typically an ASN.1 object which can be decoded with the d2i function appropriate to the type name; see d2i_X509(3) for examples.

- -

PEM_read() reads from the file fp, while PEM_read_bio() reads from the BIO bp. Both skip any non-PEM data that precedes the start of the next PEM object. When an object is successfully retrieved, the type name from the "----BEGIN <type>-----" is returned via the name argument, any encapsulation headers are returned in header and the base64-decoded content and its length are returned via data and len respectively. The name, header and data pointers are allocated via OPENSSL_malloc() and should be freed by the caller via OPENSSL_free() when no longer needed.

- -

PEM_get_EVP_CIPHER_INFO() can be used to determine the data returned by PEM_read() or PEM_read_bio() is encrypted and to retrieve the associated cipher and IV. The caller passes a pointer to structure of type EVP_CIPHER_INFO via the cinfo argument and the header returned via PEM_read() or PEM_read_bio(). If the call is successful 1 is returned and the cipher and IV are stored at the address pointed to by cinfo. When the header is malformed, or not supported or when the cipher is unknown or some internal error happens 0 is returned. This function is deprecated, see NOTES below.

- -

PEM_do_header() can then be used to decrypt the data if the header indicates encryption. The cinfo argument is a pointer to the structure initialized by the previous call to PEM_get_EVP_CIPHER_INFO(). The data and len arguments are those returned by the previous call to PEM_read() or PEM_read_bio(). The cb and u arguments make it possible to override the default password prompt function as described in PEM_read_PrivateKey(3). On successful completion the data is decrypted in place, and len is updated to indicate the plaintext length. This function is deprecated, see NOTES below.

- -

If the data is a priori known to not be encrypted, then neither PEM_do_header() nor PEM_get_EVP_CIPHER_INFO() need be called.

- -

RETURN VALUES

- -

PEM_read() and PEM_read_bio() return 1 on success and 0 on failure, the latter includes the case when no more PEM objects remain in the input file. To distinguish end of file from more serious errors the caller must peek at the error stack and check for PEM_R_NO_START_LINE, which indicates that no more PEM objects were found. See ERR_peek_last_error(3), ERR_GET_REASON(3).

- -

PEM_get_EVP_CIPHER_INFO() and PEM_do_header() return 1 on success, and 0 on failure. The data is likely meaningless if these functions fail.

- -

NOTES

- -

The PEM_get_EVP_CIPHER_INFO() and PEM_do_header() functions are deprecated. This is because the underlying PEM encryption format is obsolete, and should be avoided. It uses an encryption format with an OpenSSL-specific key-derivation function, which employs MD5 with an iteration count of 1! Instead, private keys should be stored in PKCS#8 form, with a strong PKCS#5 v2.0 PBE. See PEM_write_PrivateKey(3) and d2i_PKCS8PrivateKey_bio(3).

- -

PEM_do_header() makes no assumption regarding the pass phrase received from the password callback. It will simply be treated as a byte sequence.

- -

SEE ALSO

- -

ERR_peek_last_error(3), ERR_GET_LIB(3), d2i_PKCS8PrivateKey_bio(3), passphrase-encoding(7)

- -

COPYRIGHT

- -

Copyright 1998-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_read_CMS.html b/openssl-install/share/doc/openssl/html/man3/PEM_read_CMS.html deleted file mode 100644 index 3f095dbf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_read_CMS.html +++ /dev/null @@ -1,110 +0,0 @@ - - - - -PEM_read_CMS - - - - - - - - - - -

NAME

- -

DECLARE_PEM_rw, PEM_read_CMS, PEM_read_bio_CMS, PEM_write_CMS, PEM_write_bio_CMS, PEM_write_DHxparams, PEM_write_bio_DHxparams, PEM_read_ECPKParameters, PEM_read_bio_ECPKParameters, PEM_write_ECPKParameters, PEM_write_bio_ECPKParameters, PEM_read_ECPrivateKey, PEM_write_ECPrivateKey, PEM_write_bio_ECPrivateKey, PEM_read_EC_PUBKEY, PEM_read_bio_EC_PUBKEY, PEM_write_EC_PUBKEY, PEM_write_bio_EC_PUBKEY, PEM_read_NETSCAPE_CERT_SEQUENCE, PEM_read_bio_NETSCAPE_CERT_SEQUENCE, PEM_write_NETSCAPE_CERT_SEQUENCE, PEM_write_bio_NETSCAPE_CERT_SEQUENCE, PEM_read_PKCS8, PEM_read_bio_PKCS8, PEM_write_PKCS8, PEM_write_bio_PKCS8, PEM_write_PKCS8_PRIV_KEY_INFO, PEM_read_bio_PKCS8_PRIV_KEY_INFO, PEM_read_PKCS8_PRIV_KEY_INFO, PEM_write_bio_PKCS8_PRIV_KEY_INFO, PEM_read_SSL_SESSION, PEM_read_bio_SSL_SESSION, PEM_write_SSL_SESSION, PEM_write_bio_SSL_SESSION, PEM_read_X509_PUBKEY, PEM_read_bio_X509_PUBKEY, PEM_write_X509_PUBKEY, PEM_write_bio_X509_PUBKEY - PEM object encoding routines

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-DECLARE_PEM_rw(name, TYPE)
-
-TYPE *PEM_read_TYPE(FILE *fp, TYPE **a, pem_password_cb *cb, void *u);
-TYPE *PEM_read_bio_TYPE(BIO *bp, TYPE **a, pem_password_cb *cb, void *u);
-int PEM_write_TYPE(FILE *fp, const TYPE *a);
-int PEM_write_bio_TYPE(BIO *bp, const TYPE *a);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#include <openssl/pem.h>
-
-int PEM_write_DHxparams(FILE *out, const DH *dh);
-int PEM_write_bio_DHxparams(BIO *out, const DH *dh);
-EC_GROUP *PEM_read_ECPKParameters(FILE *fp, EC_GROUP **x, pem_password_cb *cb, void *u);
-EC_GROUP *PEM_read_bio_ECPKParameters(BIO *bp, EC_GROUP **x, pem_password_cb *cb, void *u);
-int PEM_write_ECPKParameters(FILE *out, const EC_GROUP *x);
-int PEM_write_bio_ECPKParameters(BIO *out, const EC_GROUP *x),
-
-EC_KEY *PEM_read_EC_PUBKEY(FILE *fp, EC_KEY **x, pem_password_cb *cb, void *u);
-EC_KEY *PEM_read_bio_EC_PUBKEY(BIO *bp, EC_KEY **x, pem_password_cb *cb, void *u);
-int PEM_write_EC_PUBKEY(FILE *out, const EC_KEY *x);
-int PEM_write_bio_EC_PUBKEY(BIO *out, const EC_KEY *x);
-
-EC_KEY *PEM_read_ECPrivateKey(FILE *out, EC_KEY **x, pem_password_cb *cb, void *u);
-EC_KEY *PEM_read_bio_ECPrivateKey(BIO *out, EC_KEY **x, pem_password_cb *cb, void *u);
-int PEM_write_ECPrivateKey(FILE *out, const EC_KEY *x, const EVP_CIPHER *enc,
-                           const unsigned char *kstr, int klen,
-                           pem_password_cb *cb, void *u);
-int PEM_write_bio_ECPrivateKey(BIO *out, const EC_KEY *x, const EVP_CIPHER *enc,
-                               const unsigned char *kstr, int klen,
-                               pem_password_cb *cb, void *u);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should use OSSL_ENCODER_to_bio() and OSSL_DECODER_from_bio() instead.

- -

In the description below, TYPE is used as a placeholder for any of the OpenSSL datatypes, such as X509. The macro DECLARE_PEM_rw expands to the set of declarations shown in the next four lines of the synopsis.

- -

These routines convert between local instances of ASN1 datatypes and the PEM encoding. For more information on the templates, see ASN1_ITEM(3). For more information on the lower-level routines used by the functions here, see PEM_read(3).

- -

PEM_read_TYPE() reads a PEM-encoded object of TYPE from the file fp and returns it. The cb and u parameters are as described in pem_password_cb(3).

- -

PEM_read_bio_TYPE() is similar to PEM_read_TYPE() but reads from the BIO bp.

- -

PEM_write_TYPE() writes the PEM encoding of the object a to the file fp.

- -

PEM_write_bio_TYPE() similarly writes to the BIO bp.

- -

NOTES

- -

These functions make no assumption regarding the pass phrase received from the password callback. It will simply be treated as a byte sequence.

- -

RETURN VALUES

- -

PEM_read_TYPE() and PEM_read_bio_TYPE() return a pointer to an allocated object, which should be released by calling TYPE_free(), or NULL on error.

- -

PEM_write_TYPE() and PEM_write_bio_TYPE() return 1 for success or 0 for failure.

- -

SEE ALSO

- -

PEM_read(3), passphrase-encoding(7)

- -

HISTORY

- -

The functions PEM_write_DHxparams(), PEM_write_bio_DHxparams(), PEM_read_ECPKParameters(), PEM_read_bio_ECPKParameters(), PEM_write_ECPKParameters(), PEM_write_bio_ECPKParameters(), PEM_read_EC_PUBKEY(), PEM_read_bio_EC_PUBKEY(), PEM_write_EC_PUBKEY(), PEM_write_bio_EC_PUBKEY(), PEM_read_ECPrivateKey(), PEM_read_bio_ECPrivateKey(), PEM_write_ECPrivateKey() and PEM_write_bio_ECPrivateKey() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 1998-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_read_bio_PrivateKey.html b/openssl-install/share/doc/openssl/html/man3/PEM_read_bio_PrivateKey.html deleted file mode 100644 index d381181c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_read_bio_PrivateKey.html +++ /dev/null @@ -1,439 +0,0 @@ - - - - -PEM_read_bio_PrivateKey - - - - - - - - - - -

NAME

- -

pem_password_cb, PEM_read_bio_PrivateKey_ex, PEM_read_bio_PrivateKey, PEM_read_PrivateKey_ex, PEM_read_PrivateKey, PEM_write_bio_PrivateKey_ex, PEM_write_bio_PrivateKey, PEM_write_bio_PrivateKey_traditional, PEM_write_PrivateKey_ex, PEM_write_PrivateKey, PEM_write_bio_PKCS8PrivateKey, PEM_write_PKCS8PrivateKey, PEM_write_bio_PKCS8PrivateKey_nid, PEM_write_PKCS8PrivateKey_nid, PEM_read_bio_PUBKEY_ex, PEM_read_bio_PUBKEY, PEM_read_PUBKEY_ex, PEM_read_PUBKEY, PEM_write_bio_PUBKEY_ex, PEM_write_bio_PUBKEY, PEM_write_PUBKEY_ex, PEM_write_PUBKEY, PEM_read_bio_RSAPrivateKey, PEM_read_RSAPrivateKey, PEM_write_bio_RSAPrivateKey, PEM_write_RSAPrivateKey, PEM_read_bio_RSAPublicKey, PEM_read_RSAPublicKey, PEM_write_bio_RSAPublicKey, PEM_write_RSAPublicKey, PEM_read_bio_RSA_PUBKEY, PEM_read_RSA_PUBKEY, PEM_write_bio_RSA_PUBKEY, PEM_write_RSA_PUBKEY, PEM_read_bio_DSAPrivateKey, PEM_read_DSAPrivateKey, PEM_write_bio_DSAPrivateKey, PEM_write_DSAPrivateKey, PEM_read_bio_DSA_PUBKEY, PEM_read_DSA_PUBKEY, PEM_write_bio_DSA_PUBKEY, PEM_write_DSA_PUBKEY, PEM_read_bio_Parameters_ex, PEM_read_bio_Parameters, PEM_write_bio_Parameters, PEM_read_bio_DSAparams, PEM_read_DSAparams, PEM_write_bio_DSAparams, PEM_write_DSAparams, PEM_read_bio_DHparams, PEM_read_DHparams, PEM_write_bio_DHparams, PEM_write_DHparams, PEM_read_bio_X509, PEM_read_X509, PEM_write_bio_X509, PEM_write_X509, PEM_read_bio_X509_ACERT, PEM_read_X509_ACERT, PEM_write_bio_X509_ACERT, PEM_write_X509_ACERT, PEM_read_bio_X509_AUX, PEM_read_X509_AUX, PEM_write_bio_X509_AUX, PEM_write_X509_AUX, PEM_read_bio_X509_REQ, PEM_read_X509_REQ, PEM_write_bio_X509_REQ, PEM_write_X509_REQ, PEM_write_bio_X509_REQ_NEW, PEM_write_X509_REQ_NEW, PEM_read_bio_X509_CRL, PEM_read_X509_CRL, PEM_write_bio_X509_CRL, PEM_write_X509_CRL, PEM_read_bio_PKCS7, PEM_read_PKCS7, PEM_write_bio_PKCS7, PEM_write_PKCS7 - PEM routines

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-typedef int pem_password_cb(char *buf, int size, int rwflag, void *u);
-
-EVP_PKEY *PEM_read_bio_PrivateKey_ex(BIO *bp, EVP_PKEY **x,
-                                     pem_password_cb *cb, void *u,
-                                     OSSL_LIB_CTX *libctx, const char *propq);
-EVP_PKEY *PEM_read_bio_PrivateKey(BIO *bp, EVP_PKEY **x,
-                                  pem_password_cb *cb, void *u);
-EVP_PKEY *PEM_read_PrivateKey_ex(FILE *fp, EVP_PKEY **x, pem_password_cb *cb,
-                                 void *u, OSSL_LIB_CTX *libctx,
-                                 const char *propq);
-EVP_PKEY *PEM_read_PrivateKey(FILE *fp, EVP_PKEY **x,
-                              pem_password_cb *cb, void *u);
-int PEM_write_bio_PrivateKey_ex(BIO *bp, const EVP_PKEY *x,
-                                const EVP_CIPHER *enc,
-                                unsigned char *kstr, int klen,
-                                pem_password_cb *cb, void *u,
-                                OSSL_LIB_CTX *libctx, const char *propq);
-int PEM_write_bio_PrivateKey(BIO *bp, const EVP_PKEY *x, const EVP_CIPHER *enc,
-                             unsigned char *kstr, int klen,
-                             pem_password_cb *cb, void *u);
-int PEM_write_bio_PrivateKey_traditional(BIO *bp, EVP_PKEY *x,
-                                         const EVP_CIPHER *enc,
-                                         unsigned char *kstr, int klen,
-                                         pem_password_cb *cb, void *u);
-int PEM_write_PrivateKey_ex(FILE *fp, EVP_PKEY *x, const EVP_CIPHER *enc,
-                            unsigned char *kstr, int klen,
-                            pem_password_cb *cb, void *u,
-                            OSSL_LIB_CTX *libctx, const char *propq);
-int PEM_write_PrivateKey(FILE *fp, EVP_PKEY *x, const EVP_CIPHER *enc,
-                         unsigned char *kstr, int klen,
-                         pem_password_cb *cb, void *u);
-int PEM_write_bio_PKCS8PrivateKey(BIO *bp, EVP_PKEY *x, const EVP_CIPHER *enc,
-                                  char *kstr, int klen,
-                                  pem_password_cb *cb, void *u);
-int PEM_write_PKCS8PrivateKey(FILE *fp, EVP_PKEY *x, const EVP_CIPHER *enc,
-                              char *kstr, int klen,
-                              pem_password_cb *cb, void *u);
-int PEM_write_bio_PKCS8PrivateKey_nid(BIO *bp, const EVP_PKEY *x, int nid,
-                                      char *kstr, int klen,
-                                      pem_password_cb *cb, void *u);
-int PEM_write_PKCS8PrivateKey_nid(FILE *fp, const EVP_PKEY *x, int nid,
-                                  char *kstr, int klen,
-                                  pem_password_cb *cb, void *u);
-
-EVP_PKEY *PEM_read_bio_PUBKEY_ex(BIO *bp, EVP_PKEY **x,
-                                 pem_password_cb *cb, void *u,
-                                 OSSL_LIB_CTX *libctx, const char *propq);
-EVP_PKEY *PEM_read_bio_PUBKEY(BIO *bp, EVP_PKEY **x,
-                              pem_password_cb *cb, void *u);
-EVP_PKEY *PEM_read_PUBKEY_ex(FILE *fp, EVP_PKEY **x,
-                             pem_password_cb *cb, void *u,
-                             OSSL_LIB_CTX *libctx, const char *propq);
-EVP_PKEY *PEM_read_PUBKEY(FILE *fp, EVP_PKEY **x,
-                          pem_password_cb *cb, void *u);
-int PEM_write_bio_PUBKEY_ex(BIO *bp, EVP_PKEY *x,
-                            OSSL_LIB_CTX *libctx, const char *propq);
-int PEM_write_bio_PUBKEY(BIO *bp, EVP_PKEY *x);
-int PEM_write_PUBKEY_ex(FILE *fp, EVP_PKEY *x,
-                        OSSL_LIB_CTX *libctx, const char *propq);
-int PEM_write_PUBKEY(FILE *fp, EVP_PKEY *x);
-
-EVP_PKEY *PEM_read_bio_Parameters_ex(BIO *bp, EVP_PKEY **x,
-                                     OSSL_LIB_CTX *libctx, const char *propq);
-EVP_PKEY *PEM_read_bio_Parameters(BIO *bp, EVP_PKEY **x);
-int PEM_write_bio_Parameters(BIO *bp, const EVP_PKEY *x);
-
-X509 *PEM_read_bio_X509(BIO *bp, X509 **x, pem_password_cb *cb, void *u);
-X509 *PEM_read_X509(FILE *fp, X509 **x, pem_password_cb *cb, void *u);
-int PEM_write_bio_X509(BIO *bp, X509 *x);
-int PEM_write_X509(FILE *fp, X509 *x);
-
-X509_ACERT *PEM_read_bio_X509_ACERT(BIO *bp, X509_ACERT **x,
-                                    pem_password_cb *cb, void *u);
-X509_ACERT *PEM_read_X509_ACERT(FILE *fp, X509_ACERT **x,
-                                    pem_password_cb *cb, void *u);
-int PEM_write_bio_X509_ACERT(BIO *bp, X509_ACERT *x);
-int PEM_write_X509_ACERT(FILE *fp, X509_ACERT *x);
-
-X509 *PEM_read_bio_X509_AUX(BIO *bp, X509 **x, pem_password_cb *cb, void *u);
-X509 *PEM_read_X509_AUX(FILE *fp, X509 **x, pem_password_cb *cb, void *u);
-int PEM_write_bio_X509_AUX(BIO *bp, X509 *x);
-int PEM_write_X509_AUX(FILE *fp, X509 *x);
-
-X509_REQ *PEM_read_bio_X509_REQ(BIO *bp, X509_REQ **x,
-                                pem_password_cb *cb, void *u);
-X509_REQ *PEM_read_X509_REQ(FILE *fp, X509_REQ **x,
-                            pem_password_cb *cb, void *u);
-int PEM_write_bio_X509_REQ(BIO *bp, X509_REQ *x);
-int PEM_write_X509_REQ(FILE *fp, X509_REQ *x);
-int PEM_write_bio_X509_REQ_NEW(BIO *bp, X509_REQ *x);
-int PEM_write_X509_REQ_NEW(FILE *fp, X509_REQ *x);
-
-X509_CRL *PEM_read_bio_X509_CRL(BIO *bp, X509_CRL **x,
-                                pem_password_cb *cb, void *u);
-X509_CRL *PEM_read_X509_CRL(FILE *fp, X509_CRL **x,
-                            pem_password_cb *cb, void *u);
-int PEM_write_bio_X509_CRL(BIO *bp, X509_CRL *x);
-int PEM_write_X509_CRL(FILE *fp, X509_CRL *x);
-
-PKCS7 *PEM_read_bio_PKCS7(BIO *bp, PKCS7 **x, pem_password_cb *cb, void *u);
-PKCS7 *PEM_read_PKCS7(FILE *fp, PKCS7 **x, pem_password_cb *cb, void *u);
-int PEM_write_bio_PKCS7(BIO *bp, PKCS7 *x);
-int PEM_write_PKCS7(FILE *fp, PKCS7 *x);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
RSA *PEM_read_bio_RSAPrivateKey(BIO *bp, RSA **x,
-                                pem_password_cb *cb, void *u);
-RSA *PEM_read_RSAPrivateKey(FILE *fp, RSA **x,
-                            pem_password_cb *cb, void *u);
-int PEM_write_bio_RSAPrivateKey(BIO *bp, RSA *x, const EVP_CIPHER *enc,
-                                unsigned char *kstr, int klen,
-                                pem_password_cb *cb, void *u);
-int PEM_write_RSAPrivateKey(FILE *fp, RSA *x, const EVP_CIPHER *enc,
-                            unsigned char *kstr, int klen,
-                            pem_password_cb *cb, void *u);
-
-RSA *PEM_read_bio_RSAPublicKey(BIO *bp, RSA **x,
-                               pem_password_cb *cb, void *u);
-RSA *PEM_read_RSAPublicKey(FILE *fp, RSA **x,
-                           pem_password_cb *cb, void *u);
-int PEM_write_bio_RSAPublicKey(BIO *bp, RSA *x);
-int PEM_write_RSAPublicKey(FILE *fp, RSA *x);
-
-RSA *PEM_read_bio_RSA_PUBKEY(BIO *bp, RSA **x,
-                             pem_password_cb *cb, void *u);
-RSA *PEM_read_RSA_PUBKEY(FILE *fp, RSA **x,
-                         pem_password_cb *cb, void *u);
-int PEM_write_bio_RSA_PUBKEY(BIO *bp, RSA *x);
-int PEM_write_RSA_PUBKEY(FILE *fp, RSA *x);
-
-DSA *PEM_read_bio_DSAPrivateKey(BIO *bp, DSA **x,
-                                pem_password_cb *cb, void *u);
-DSA *PEM_read_DSAPrivateKey(FILE *fp, DSA **x,
-                            pem_password_cb *cb, void *u);
-int PEM_write_bio_DSAPrivateKey(BIO *bp, DSA *x, const EVP_CIPHER *enc,
-                                unsigned char *kstr, int klen,
-                                pem_password_cb *cb, void *u);
-int PEM_write_DSAPrivateKey(FILE *fp, DSA *x, const EVP_CIPHER *enc,
-                            unsigned char *kstr, int klen,
-                            pem_password_cb *cb, void *u);
-
-DSA *PEM_read_bio_DSA_PUBKEY(BIO *bp, DSA **x,
-                             pem_password_cb *cb, void *u);
-DSA *PEM_read_DSA_PUBKEY(FILE *fp, DSA **x,
-                         pem_password_cb *cb, void *u);
-int PEM_write_bio_DSA_PUBKEY(BIO *bp, DSA *x);
-int PEM_write_DSA_PUBKEY(FILE *fp, DSA *x);
-DSA *PEM_read_bio_DSAparams(BIO *bp, DSA **x, pem_password_cb *cb, void *u);
-DSA *PEM_read_DSAparams(FILE *fp, DSA **x, pem_password_cb *cb, void *u);
-int PEM_write_bio_DSAparams(BIO *bp, DSA *x);
-int PEM_write_DSAparams(FILE *fp, DSA *x);
-
-DH *PEM_read_bio_DHparams(BIO *bp, DH **x, pem_password_cb *cb, void *u);
-DH *PEM_read_DHparams(FILE *fp, DH **x, pem_password_cb *cb, void *u);
-int PEM_write_bio_DHparams(BIO *bp, DH *x);
-int PEM_write_DHparams(FILE *fp, DH *x);
- -

DESCRIPTION

- -

All of the functions described on this page that have a TYPE of DH, DSA and RSA are deprecated. Applications should use OSSL_ENCODER_to_bio(3) and OSSL_DECODER_from_bio(3) instead.

- -

The PEM functions read or write structures in PEM format. In this sense PEM format is simply base64 encoded data surrounded by header lines.

- -

For more details about the meaning of arguments see the PEM FUNCTION ARGUMENTS section.

- -

Each operation has four functions associated with it. For brevity the term "TYPE functions" will be used below to collectively refer to the PEM_read_bio_TYPE(), PEM_read_TYPE(), PEM_write_bio_TYPE(), and PEM_write_TYPE() functions.

- -

Some operations have additional variants that take a library context libctx and a property query string propq. The X509, X509_REQ and X509_CRL objects may have an associated library context or property query string but there are no variants of these functions that take a library context or property query string parameter. In this case it is possible to set the appropriate library context or property query string by creating an empty X509, X509_REQ or X509_CRL object using X509_new_ex(3), X509_REQ_new_ex(3) or X509_CRL_new_ex(3) respectively. Then pass the empty object as a parameter to the relevant PEM function. See the "EXAMPLES" section below.

- -

The PrivateKey functions read or write a private key in PEM format using an EVP_PKEY structure. The write routines use PKCS#8 private key format and are equivalent to PEM_write_bio_PKCS8PrivateKey(). The read functions transparently handle traditional and PKCS#8 format encrypted and unencrypted keys.

- -

PEM_write_bio_PrivateKey_traditional() writes out a private key in the "traditional" format with a simple private key marker and should only be used for compatibility with legacy programs.

- -

PEM_write_bio_PKCS8PrivateKey() and PEM_write_PKCS8PrivateKey() write a private key in an EVP_PKEY structure in PKCS#8 EncryptedPrivateKeyInfo format using PKCS#5 v2.0 password based encryption algorithms. The cipher argument specifies the encryption algorithm to use: unlike some other PEM routines the encryption is applied at the PKCS#8 level and not in the PEM headers. If cipher is NULL then no encryption is used and a PKCS#8 PrivateKeyInfo structure is used instead.

- -

PEM_write_bio_PKCS8PrivateKey_nid() and PEM_write_PKCS8PrivateKey_nid() also write out a private key as a PKCS#8 EncryptedPrivateKeyInfo however it uses PKCS#5 v1.5 or PKCS#12 encryption algorithms instead. The algorithm to use is specified in the nid parameter and should be the NID of the corresponding OBJECT IDENTIFIER (see NOTES section).

- -

The PUBKEY functions process a public key using an EVP_PKEY structure. The public key is encoded as a SubjectPublicKeyInfo structure.

- -

The RSAPrivateKey functions process an RSA private key using an RSA structure. The write routines uses traditional format. The read routines handles the same formats as the PrivateKey functions but an error occurs if the private key is not RSA.

- -

The RSAPublicKey functions process an RSA public key using an RSA structure. The public key is encoded using a PKCS#1 RSAPublicKey structure.

- -

The RSA_PUBKEY functions also process an RSA public key using an RSA structure. However, the public key is encoded using a SubjectPublicKeyInfo structure and an error occurs if the public key is not RSA.

- -

The DSAPrivateKey functions process a DSA private key using a DSA structure. The write routines uses traditional format. The read routines handles the same formats as the PrivateKey functions but an error occurs if the private key is not DSA.

- -

The DSA_PUBKEY functions process a DSA public key using a DSA structure. The public key is encoded using a SubjectPublicKeyInfo structure and an error occurs if the public key is not DSA.

- -

The Parameters functions read or write key parameters in PEM format using an EVP_PKEY structure. The encoding depends on the type of key; for DSA key parameters, it will be a Dss-Parms structure as defined in RFC2459, and for DH key parameters, it will be a PKCS#3 DHparameter structure. These functions only exist for the BIO type.

- -

The DSAparams functions process DSA parameters using a DSA structure. The parameters are encoded using a Dss-Parms structure as defined in RFC2459.

- -

The DHparams functions process DH parameters using a DH structure. The parameters are encoded using a PKCS#3 DHparameter structure.

- -

The X509 functions process an X509 certificate using an X509 structure. They will also process a trusted X509 certificate but any trust settings are discarded.

- -

The X509_ACERT functions process an X509 attribute certificate using an X509_ACERT structure.

- -

The X509_AUX functions process a trusted X509 certificate using an X509 structure.

- -

The X509_REQ and X509_REQ_NEW functions process a PKCS#10 certificate request using an X509_REQ structure. The X509_REQ write functions use CERTIFICATE REQUEST in the header whereas the X509_REQ_NEW functions use NEW CERTIFICATE REQUEST (as required by some CAs). The X509_REQ read functions will handle either form so there are no X509_REQ_NEW read functions.

- -

The X509_CRL functions process an X509 CRL using an X509_CRL structure.

- -

The PKCS7 functions process a PKCS#7 ContentInfo using a PKCS7 structure.

- -

PEM FUNCTION ARGUMENTS

- -

The PEM functions have many common arguments.

- -

The bp BIO parameter (if present) specifies the BIO to read from or write to.

- -

The fp FILE parameter (if present) specifies the FILE pointer to read from or write to.

- -

The PEM read functions all take an argument TYPE **x and return a TYPE * pointer. Where TYPE is whatever structure the function uses. If x is NULL then the parameter is ignored. If x is not NULL but *x is NULL then the structure returned will be written to *x. If neither x nor *x is NULL then an attempt is made to reuse the structure at *x (but see BUGS and EXAMPLES sections). Irrespective of the value of x a pointer to the structure is always returned (or NULL if an error occurred). The caller retains ownership of the returned object and needs to free it when it is no longer needed, e.g. using X509_free() for X509 objects or EVP_PKEY_free() for EVP_PKEY objects.

- -

The PEM functions which write private keys take an enc parameter which specifies the encryption algorithm to use, encryption is done at the PEM level. If this parameter is set to NULL then the private key is written in unencrypted form.

- -

The cb argument is the callback to use when querying for the pass phrase used for encrypted PEM structures (normally only private keys).

- -

For the PEM write routines if the kstr parameter is not NULL then klen bytes at kstr are used as the passphrase and cb is ignored.

- -

If the cb parameters is set to NULL and the u parameter is not NULL then the u parameter is interpreted as a NUL terminated string to use as the passphrase. If both cb and u are NULL then the default callback routine is used which will typically prompt for the passphrase on the current terminal with echoing turned off.

- -

The default passphrase callback is sometimes inappropriate (for example in a GUI application) so an alternative can be supplied. The callback routine has the following form:

- -
int cb(char *buf, int size, int rwflag, void *u);
- -

buf is the buffer to write the passphrase to. size is the maximum length of the passphrase (i.e. the size of buf). rwflag is a flag which is set to 0 when reading and 1 when writing. A typical routine will ask the user to verify the passphrase (for example by prompting for it twice) if rwflag is 1. The u parameter has the same value as the u parameter passed to the PEM routine. It allows arbitrary data to be passed to the callback by the application (for example a window handle in a GUI application). The callback must return the number of characters in the passphrase or -1 if an error occurred. The passphrase can be arbitrary data; in the case where it is a string, it is not NUL terminated. See the "EXAMPLES" section below.

- -

Some implementations may need to use cryptographic algorithms during their operation. If this is the case and libctx and propq parameters have been passed then any algorithm fetches will use that library context and property query string. Otherwise the default library context and property query string will be used.

- -

NOTES

- -

The PEM reading functions will skip any extraneous content or PEM data of a different type than they expect. This allows for example having a certificate (or multiple certificates) and a key in the PEM format in a single file.

- -

The old PrivateKey write routines are retained for compatibility. New applications should write private keys using the PEM_write_bio_PKCS8PrivateKey() or PEM_write_PKCS8PrivateKey() routines because they are more secure (they use an iteration count of 2048 whereas the traditional routines use a count of 1) unless compatibility with older versions of OpenSSL is important.

- -

The PrivateKey read routines can be used in all applications because they handle all formats transparently.

- -

A frequent cause of problems is attempting to use the PEM routines like this:

- -
X509 *x;
-
-PEM_read_bio_X509(bp, &x, 0, NULL);
- -

this is a bug because an attempt will be made to reuse the data at x which is an uninitialised pointer.

- -

These functions make no assumption regarding the pass phrase received from the password callback. It will simply be treated as a byte sequence.

- -

PEM ENCRYPTION FORMAT

- -

These old PrivateKey routines use a non standard technique for encryption.

- -

The private key (or other data) takes the following form:

- -
-----BEGIN RSA PRIVATE KEY-----
-Proc-Type: 4,ENCRYPTED
-DEK-Info: DES-EDE3-CBC,3F17F5316E2BAC89
-
-...base64 encoded data...
------END RSA PRIVATE KEY-----
- -

The line beginning with Proc-Type contains the version and the protection on the encapsulated data. The line beginning DEK-Info contains two comma separated values: the encryption algorithm name as used by EVP_get_cipherbyname() and an initialization vector used by the cipher encoded as a set of hexadecimal digits. After those two lines is the base64-encoded encrypted data.

- -

The encryption key is derived using EVP_BytesToKey(). The cipher's initialization vector is passed to EVP_BytesToKey() as the salt parameter. Internally, PKCS5_SALT_LEN bytes of the salt are used (regardless of the size of the initialization vector). The user's password is passed to EVP_BytesToKey() using the data and datal parameters. Finally, the library uses an iteration count of 1 for EVP_BytesToKey().

- -

The key derived by EVP_BytesToKey() along with the original initialization vector is then used to decrypt the encrypted data. The iv produced by EVP_BytesToKey() is not utilized or needed, and NULL should be passed to the function.

- -

The pseudo code to derive the key would look similar to:

- -
EVP_CIPHER* cipher = EVP_des_ede3_cbc();
-EVP_MD* md = EVP_md5();
-
-unsigned int nkey = EVP_CIPHER_get_key_length(cipher);
-unsigned int niv = EVP_CIPHER_get_iv_length(cipher);
-unsigned char key[nkey];
-unsigned char iv[niv];
-
-memcpy(iv, HexToBin("3F17F5316E2BAC89"), niv);
-rc = EVP_BytesToKey(cipher, md, iv /*salt*/, pword, plen, 1, key, NULL /*iv*/);
-if (rc != nkey)
-    /* Error */
-
-/* On success, use key and iv to initialize the cipher */
- -

BUGS

- -

The PEM read routines in some versions of OpenSSL will not correctly reuse an existing structure. Therefore, the following:

- -
PEM_read_bio_X509(bp, &x, 0, NULL);
- -

where x already contains a valid certificate, may not work, whereas:

- -
X509_free(x);
-x = PEM_read_bio_X509(bp, NULL, 0, NULL);
- -

is guaranteed to work. It is always acceptable for x to contain a newly allocated, empty X509 object (for example allocated via X509_new_ex(3)).

- -

RETURN VALUES

- -

The read routines return either a pointer to the structure read or NULL if an error occurred.

- -

The write routines return 1 for success or 0 for failure.

- -

EXAMPLES

- -

Although the PEM routines take several arguments in almost all applications most of them are set to 0 or NULL.

- -

To read a certificate with a library context in PEM format from a BIO:

- -
X509 *x = X509_new_ex(libctx, NULL);
-
-if (x == NULL)
-    /* Error */
-
-if (PEM_read_bio_X509(bp, &x, 0, NULL) == NULL)
-    /* Error */
- -

Read a certificate in PEM format from a BIO:

- -
X509 *x;
-
-x = PEM_read_bio_X509(bp, NULL, 0, NULL);
-if (x == NULL)
-    /* Error */
- -

Alternative method:

- -
X509 *x = NULL;
-
-if (!PEM_read_bio_X509(bp, &x, 0, NULL))
-    /* Error */
- -

Write a certificate to a BIO:

- -
if (!PEM_write_bio_X509(bp, x))
-    /* Error */
- -

Write a private key (using traditional format) to a BIO using triple DES encryption, the pass phrase is prompted for:

- -
if (!PEM_write_bio_PrivateKey(bp, key, EVP_des_ede3_cbc(), NULL, 0, 0, NULL))
-    /* Error */
- -

Write a private key (using PKCS#8 format) to a BIO using triple DES encryption, using the pass phrase "hello":

- -
if (!PEM_write_bio_PKCS8PrivateKey(bp, key, EVP_des_ede3_cbc(),
-                                   NULL, 0, 0, "hello"))
-    /* Error */
- -

Read a private key from a BIO using a pass phrase callback:

- -
key = PEM_read_bio_PrivateKey(bp, NULL, pass_cb, "My Private Key");
-if (key == NULL)
-    /* Error */
- -

Skeleton pass phrase callback:

- -
int pass_cb(char *buf, int size, int rwflag, void *u)
-{
-
-    /* We'd probably do something else if 'rwflag' is 1 */
-    printf("Enter pass phrase for \"%s\"\n", (char *)u);
-
-    /* get pass phrase, length 'len' into 'tmp' */
-    char *tmp = "hello";
-    if (tmp == NULL) /* An error occurred */
-        return -1;
-
-    size_t len = strlen(tmp);
-
-    if (len > size)
-        len = size;
-    memcpy(buf, tmp, len);
-    return len;
-}
- -

SEE ALSO

- -

EVP_EncryptInit(3), EVP_BytesToKey(3), passphrase-encoding(7)

- -

HISTORY

- -

The old Netscape certificate sequences were no longer documented in OpenSSL 1.1.0; applications should use the PKCS7 standard instead as they will be formally deprecated in a future releases.

- -

PEM_read_bio_PrivateKey_ex(), PEM_read_PrivateKey_ex(), PEM_read_bio_PUBKEY_ex(), PEM_read_PUBKEY_ex() and PEM_read_bio_Parameters_ex() were introduced in OpenSSL 3.0.

- -

The functions PEM_read_bio_RSAPrivateKey(), PEM_read_RSAPrivateKey(), PEM_write_bio_RSAPrivateKey(), PEM_write_RSAPrivateKey(), PEM_read_bio_RSAPublicKey(), PEM_read_RSAPublicKey(), PEM_write_bio_RSAPublicKey(), PEM_write_RSAPublicKey(), PEM_read_bio_RSA_PUBKEY(), PEM_read_RSA_PUBKEY(), PEM_write_bio_RSA_PUBKEY(), PEM_write_RSA_PUBKEY(), PEM_read_bio_DSAPrivateKey(), PEM_read_DSAPrivateKey(), PEM_write_bio_DSAPrivateKey(), PEM_write_DSAPrivateKey(), PEM_read_bio_DSA_PUBKEY(), PEM_read_DSA_PUBKEY(), PEM_write_bio_DSA_PUBKEY(), PEM_write_DSA_PUBKEY(); PEM_read_bio_DSAparams(), PEM_read_DSAparams(), PEM_write_bio_DSAparams(), PEM_write_DSAparams(), PEM_read_bio_DHparams(), PEM_read_DHparams(), PEM_write_bio_DHparams() and PEM_write_DHparams() were deprecated in 3.0.

- -

COPYRIGHT

- -

Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_read_bio_ex.html b/openssl-install/share/doc/openssl/html/man3/PEM_read_bio_ex.html deleted file mode 100644 index d4d63c40..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_read_bio_ex.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -PEM_read_bio_ex - - - - - - - - - - -

NAME

- -

PEM_read_bio_ex, PEM_FLAG_SECURE, PEM_FLAG_EAY_COMPATIBLE, PEM_FLAG_ONLY_B64 - read PEM format files with custom processing

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-#define PEM_FLAG_SECURE             0x1
-#define PEM_FLAG_EAY_COMPATIBLE     0x2
-#define PEM_FLAG_ONLY_B64           0x4
-int PEM_read_bio_ex(BIO *in, char **name, char **header,
-                    unsigned char **data, long *len, unsigned int flags);
- -

DESCRIPTION

- -

PEM_read_bio_ex() reads in PEM formatted data from an input BIO, outputting the name of the type of contained data, the header information regarding the possibly encrypted data, and the binary data payload (after base64 decoding). It should generally only be used to implement PEM_read_bio_-family functions for specific data types or other usage, but is exposed to allow greater flexibility over how processing is performed, if needed.

- -

If PEM_FLAG_SECURE is set, the intermediate buffers used to read in lines of input are allocated from the secure heap.

- -

If PEM_FLAG_EAY_COMPATIBLE is set, a simple algorithm is used to remove whitespace and control characters from the end of each line, so as to be compatible with the historical behavior of PEM_read_bio().

- -

If PEM_FLAG_ONLY_B64 is set, all characters are required to be valid base64 characters (or newlines); non-base64 characters are treated as end of input.

- -

If neither PEM_FLAG_EAY_COMPATIBLE or PEM_FLAG_ONLY_B64 is set, control characters are ignored.

- -

If both PEM_FLAG_EAY_COMPATIBLE and PEM_FLAG_ONLY_B64 are set, an error is returned; these options are not compatible with each other.

- -

NOTES

- -

The caller must release the storage allocated for *name, *header, and *data. If PEM_FLAG_SECURE was set, use OPENSSL_secure_free(); otherwise, OPENSSL_free() is used.

- -

RETURN VALUES

- -

PEM_read_bio_ex() returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

PEM_bytes_read_bio(3)

- -

HISTORY

- -

The PEM_read_bio_ex() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_write_bio_CMS_stream.html b/openssl-install/share/doc/openssl/html/man3/PEM_write_bio_CMS_stream.html deleted file mode 100644 index 485ef490..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_write_bio_CMS_stream.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -PEM_write_bio_CMS_stream - - - - - - - - - - -

NAME

- -

PEM_write_bio_CMS_stream - output CMS_ContentInfo structure in PEM format

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int PEM_write_bio_CMS_stream(BIO *out, CMS_ContentInfo *cms, BIO *data, int flags);
- -

DESCRIPTION

- -

PEM_write_bio_CMS_stream() outputs a CMS_ContentInfo structure in PEM format.

- -

It is otherwise identical to the function SMIME_write_CMS().

- -

NOTES

- -

This function is effectively a version of the PEM_write_bio_CMS() supporting streaming.

- -

RETURN VALUES

- -

PEM_write_bio_CMS_stream() returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_verify(3), CMS_encrypt(3) CMS_decrypt(3), PEM_write(3), SMIME_write_CMS(3), i2d_CMS_bio_stream(3)

- -

HISTORY

- -

The PEM_write_bio_CMS_stream() function was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PEM_write_bio_PKCS7_stream.html b/openssl-install/share/doc/openssl/html/man3/PEM_write_bio_PKCS7_stream.html deleted file mode 100644 index 8f1ea087..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PEM_write_bio_PKCS7_stream.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -PEM_write_bio_PKCS7_stream - - - - - - - - - - -

NAME

- -

PEM_write_bio_PKCS7_stream - output PKCS7 structure in PEM format

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-int PEM_write_bio_PKCS7_stream(BIO *out, PKCS7 *p7, BIO *data, int flags);
- -

DESCRIPTION

- -

PEM_write_bio_PKCS7_stream() outputs a PKCS7 structure in PEM format.

- -

It is otherwise identical to the function SMIME_write_PKCS7().

- -

NOTES

- -

This function is effectively a version of the PEM_write_bio_PKCS7() supporting streaming.

- -

RETURN VALUES

- -

PEM_write_bio_PKCS7_stream() returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), PKCS7_sign(3), PKCS7_verify(3), PKCS7_encrypt(3) PKCS7_decrypt(3), SMIME_write_PKCS7(3), i2d_PKCS7_bio_stream(3)

- -

HISTORY

- -

The PEM_write_bio_PKCS7_stream() function was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2007-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_PBE_keyivgen.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_PBE_keyivgen.html deleted file mode 100644 index 64cfbfaf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_PBE_keyivgen.html +++ /dev/null @@ -1,108 +0,0 @@ - - - - -PKCS12_PBE_keyivgen - - - - - - - - - - -

NAME

- -

PKCS12_PBE_keyivgen, PKCS12_PBE_keyivgen_ex, PKCS12_pbe_crypt, PKCS12_pbe_crypt_ex - PKCS#12 Password based encryption

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int PKCS12_PBE_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
-                        ASN1_TYPE *param, const EVP_CIPHER *cipher,
-                        const EVP_MD *md_type, int en_de);
-int PKCS12_PBE_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
-                           ASN1_TYPE *param, const EVP_CIPHER *cipher,
-                           const EVP_MD *md_type, int en_de,
-                           OSSL_LIB_CTX *libctx, const char *propq);
-unsigned char *PKCS12_pbe_crypt(const X509_ALGOR *algor,
-                                const char *pass, int passlen,
-                                const unsigned char *in, int inlen,
-                                unsigned char **data, int *datalen,
-                                int en_de);
-unsigned char *PKCS12_pbe_crypt_ex(const X509_ALGOR *algor,
-                                   const char *pass, int passlen,
-                                   const unsigned char *in, int inlen,
-                                   unsigned char **data, int *datalen,
-                                   int en_de, OSSL_LIB_CTX *libctx,
-                                   const char *propq);
- -

DESCRIPTION

- -

PKCS12_PBE_keyivgen() and PKCS12_PBE_keyivgen_ex() take a password pass of length passlen, parameters param and a message digest function md_type and perform a key derivation according to PKCS#12. The resulting key is then used to initialise the cipher context ctx with a cipher cipher for encryption (en_de=1) or decryption (en_de=0).

- -

PKCS12_PBE_keyivgen_ex() also allows the application to specify a library context libctx and property query propq to select appropriate algorithm implementations.

- -

PKCS12_pbe_crypt() and PKCS12_pbe_crypt_ex() will encrypt or decrypt a buffer based on the algorithm in algor and password pass of length passlen. The input is from in of length inlen and output is into a malloc'd buffer returned in *data of length datalen. The operation is determined by en_de, encryption (en_de=1) or decryption (en_de=0).

- -

PKCS12_pbe_crypt_ex() allows the application to specify a library context libctx and property query propq to select appropriate algorithm implementations.

- -

pass is the password used in the derivation of length passlen. pass is an optional parameter and can be NULL. If passlen is -1, then the function will calculate the length of pass using strlen().

- -

salt is the salt used in the derivation of length saltlen. If the salt is NULL, then saltlen must be 0. The function will not attempt to calculate the length of the salt because it is not assumed to be NULL terminated.

- -

iter is the iteration count and its value should be greater than or equal to 1. RFC 2898 suggests an iteration count of at least 1000. Any iter less than 1 is treated as a single iteration.

- -

digest is the message digest function used in the derivation.

- -

Functions ending in _ex() take optional parameters libctx and propq which are used to select appropriate algorithm implementations.

- -

NOTES

- -

The functions are typically used in PKCS#12 to encrypt objects.

- -

These functions make no assumption regarding the given password. It will simply be treated as a byte sequence.

- -

RETURN VALUES

- -

PKCS12_PBE_keyivgen(), PKCS12_PBE_keyivgen_ex() return 1 on success or 0 on error.

- -

PKCS12_pbe_crypt() and PKCS12_pbe_crypt_ex() return a buffer containing the output or NULL if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

EVP_PBE_CipherInit_ex(3), PKCS8_encrypt_ex(3), passphrase-encoding(7)

- -

HISTORY

- -

PKCS12_PBE_keyivgen_ex() and PKCS12_pbe_crypt_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2014-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_create_cert.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_create_cert.html deleted file mode 100644 index ed81caba..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_create_cert.html +++ /dev/null @@ -1,105 +0,0 @@ - - - - -PKCS12_SAFEBAG_create_cert - - - - - - - - - - -

NAME

- -

PKCS12_SAFEBAG_create_cert, PKCS12_SAFEBAG_create_crl, PKCS12_SAFEBAG_create_secret, PKCS12_SAFEBAG_create0_p8inf, PKCS12_SAFEBAG_create0_pkcs8, PKCS12_SAFEBAG_create_pkcs8_encrypt, PKCS12_SAFEBAG_create_pkcs8_encrypt_ex - Create PKCS#12 safeBag objects

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_cert(X509 *x509);
-PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_crl(X509_CRL *crl);
-PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_secret(int type, int vtype,
-                                             const unsigned char* value,
-                                             int len);
-PKCS12_SAFEBAG *PKCS12_SAFEBAG_create0_p8inf(PKCS8_PRIV_KEY_INFO *p8);
-PKCS12_SAFEBAG *PKCS12_SAFEBAG_create0_pkcs8(X509_SIG *p8);
-PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_pkcs8_encrypt(int pbe_nid,
-                                                    const char *pass,
-                                                    int passlen,
-                                                    unsigned char *salt,
-                                                    int saltlen, int iter,
-                                                    PKCS8_PRIV_KEY_INFO *p8inf);
-PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_pkcs8_encrypt_ex(int pbe_nid,
-                                                       const char *pass,
-                                                       int passlen,
-                                                       unsigned char *salt,
-                                                       int saltlen, int iter,
-                                                       PKCS8_PRIV_KEY_INFO *p8inf,
-                                                       OSSL_LIB_CTX *ctx,
-                                                       const char *propq);
- -

DESCRIPTION

- -

PKCS12_SAFEBAG_create_cert() creates a new PKCS12_SAFEBAG of type NID_certBag containing the supplied certificate.

- -

PKCS12_SAFEBAG_create_crl() creates a new PKCS12_SAFEBAG of type NID_crlBag containing the supplied crl.

- -

PKCS12_SAFEBAG_create_secret() creates a new PKCS12_SAFEBAG of type corresponding to a PKCS#12 secretBag. The secretBag contents are tagged as type with an ASN1 value of type vtype constructed using the bytes in value of length len.

- -

PKCS12_SAFEBAG_create0_p8inf() creates a new PKCS12_SAFEBAG of type NID_keyBag containing the supplied PKCS8 structure.

- -

PKCS12_SAFEBAG_create0_pkcs8() creates a new PKCS12_SAFEBAG of type NID_pkcs8ShroudedKeyBag containing the supplied PKCS8 structure.

- -

PKCS12_SAFEBAG_create_pkcs8_encrypt() creates a new PKCS12_SAFEBAG of type NID_pkcs8ShroudedKeyBag by encrypting the supplied PKCS8 p8inf. If pbe_nid is 0, a default encryption algorithm is used. pass is the passphrase and iter is the iteration count. If iter is zero then a default value of 2048 is used. If salt is NULL then a salt is generated randomly.

- -

PKCS12_SAFEBAG_create_pkcs8_encrypt_ex() is identical to PKCS12_SAFEBAG_create_pkcs8_encrypt() but allows for a library context ctx and property query propq to be used to select algorithm implementations.

- -

NOTES

- -

PKCS12_SAFEBAG_create_pkcs8_encrypt() makes assumptions regarding the encoding of the given pass phrase. See passphrase-encoding(7) for more information.

- -

PKCS12_SAFEBAG_create_secret() was added in OpenSSL 3.0.

- -

RETURN VALUES

- -

All of these functions return a valid PKCS12_SAFEBAG structure or NULL if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

PKCS12_create(3), PKCS12_add_safe(3), PKCS12_add_safes(3)

- -

HISTORY

- -

PKCS12_SAFEBAG_create_pkcs8_encrypt_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get0_attrs.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get0_attrs.html deleted file mode 100644 index 8038f7e4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get0_attrs.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -PKCS12_SAFEBAG_get0_attrs - - - - - - - - - - -

NAME

- -

PKCS12_SAFEBAG_get0_attrs, PKCS12_get_attr_gen - Retrieve attributes from a PKCS#12 safeBag

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-const STACK_OF(X509_ATTRIBUTE) *PKCS12_SAFEBAG_get0_attrs(const PKCS12_SAFEBAG *bag);
-
-ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs,
-                               int attr_nid);
- -

DESCRIPTION

- -

PKCS12_SAFEBAG_get0_attrs() retrieves the stack of X509_ATTRIBUTEs from a PKCS#12 safeBag. bag is the PKCS12_SAFEBAG to retrieve the attributes from.

- -

PKCS12_get_attr_gen() retrieves an attribute by NID from a stack of X509_ATTRIBUTEs. attr_nid is the NID of the attribute to retrieve.

- -

RETURN VALUES

- -

PKCS12_SAFEBAG_get0_attrs() returns the stack of X509_ATTRIBUTEs from a PKCS#12 safeBag, which could be empty.

- -

PKCS12_get_attr_gen() returns an ASN1_TYPE object containing the attribute, or NULL if the attribute was either not present or an error occurred.

- -

PKCS12_get_attr_gen() does not allocate a new attribute. The returned attribute is still owned by the PKCS12_SAFEBAG in which it resides.

- -

SEE ALSO

- -

PKCS12_get_friendlyname(3), PKCS12_add_friendlyname_asc(3)

- -

COPYRIGHT

- -

Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get1_cert.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get1_cert.html deleted file mode 100644 index ab12def6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_get1_cert.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -PKCS12_SAFEBAG_get1_cert - - - - - - - - - - -

NAME

- -

PKCS12_SAFEBAG_get0_attr, PKCS12_SAFEBAG_get0_type, PKCS12_SAFEBAG_get_nid, PKCS12_SAFEBAG_get_bag_nid, PKCS12_SAFEBAG_get0_bag_obj, PKCS12_SAFEBAG_get0_bag_type, PKCS12_SAFEBAG_get1_cert_ex, PKCS12_SAFEBAG_get1_cert, PKCS12_SAFEBAG_get1_crl_ex, PKCS12_SAFEBAG_get1_crl, PKCS12_SAFEBAG_get0_safes, PKCS12_SAFEBAG_get0_p8inf, PKCS12_SAFEBAG_get0_pkcs8 - Get objects from a PKCS#12 safeBag

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-const ASN1_TYPE *PKCS12_SAFEBAG_get0_attr(const PKCS12_SAFEBAG *bag,
-                                          int attr_nid);
-const ASN1_OBJECT *PKCS12_SAFEBAG_get0_type(const PKCS12_SAFEBAG *bag);
-int PKCS12_SAFEBAG_get_nid(const PKCS12_SAFEBAG *bag);
-int PKCS12_SAFEBAG_get_bag_nid(const PKCS12_SAFEBAG *bag);
-const ASN1_TYPE *PKCS12_SAFEBAG_get0_bag_obj(const PKCS12_SAFEBAG *bag);
-const ASN1_OBJECT *PKCS12_SAFEBAG_get0_bag_type(const PKCS12_SAFEBAG *bag);
-X509_CRL *PKCS12_SAFEBAG_get1_cert_ex(const PKCS12_SAFEBAG *bag,
-                                      OSSL_LIB_CTX *libctx, const char *propq);
-X509 *PKCS12_SAFEBAG_get1_cert(const PKCS12_SAFEBAG *bag);
-X509_CRL *PKCS12_SAFEBAG_get1_crl_ex(const PKCS12_SAFEBAG *bag,
-                                     OSSL_LIB_CTX *libctx, const char *propq);
-X509_CRL *PKCS12_SAFEBAG_get1_crl(const PKCS12_SAFEBAG *bag);
-const STACK_OF(PKCS12_SAFEBAG) *PKCS12_SAFEBAG_get0_safes(const PKCS12_SAFEBAG *bag);
-const PKCS8_PRIV_KEY_INFO *PKCS12_SAFEBAG_get0_p8inf(const PKCS12_SAFEBAG *bag);
-const X509_SIG *PKCS12_SAFEBAG_get0_pkcs8(const PKCS12_SAFEBAG *bag);
- -

DESCRIPTION

- -

PKCS12_SAFEBAG_get0_attr() gets the attribute value corresponding to the attr_nid.

- -

PKCS12_SAFEBAG_get0_type() gets the safeBag type as an OID, whereas PKCS12_SAFEBAG_get_nid() gets the safeBag type as an NID, which could be NID_certBag, NID_crlBag, NID_keyBag, NID_secretBag, NID_safeContentsBag or NID_pkcs8ShroudedKeyBag.

- -

PKCS12_SAFEBAG_get_bag_nid() gets the type of the object contained within the PKCS12_SAFEBAG. This corresponds to the bag type for most bags, but can be arbitrary for secretBags. PKCS12_SAFEBAG_get0_bag_type() gets this type as an OID.

- -

PKCS12_SAFEBAG_get0_bag_obj() retrieves the object contained within the safeBag.

- -

PKCS12_SAFEBAG_get1_cert_ex() and PKCS12_SAFEBAG_get1_crl_ex() return new X509 or X509_CRL objects from the item in the safeBag. libctx and propq are used when fetching algorithms, and may optionally be set to NULL.

- -

PKCS12_SAFEBAG_get1_cert() and PKCS12_SAFEBAG_get1_crl() are the same as PKCS12_SAFEBAG_get1_cert_ex() and PKCS12_SAFEBAG_get1_crl_ex() and set the libctx and prop to NULL. This will use the default library context.

- -

PKCS12_SAFEBAG_get0_p8inf() and PKCS12_SAFEBAG_get0_pkcs8() return the PKCS8 object from a PKCS8shroudedKeyBag or a keyBag.

- -

PKCS12_SAFEBAG_get0_safes() retrieves the set of safeBags contained within a safeContentsBag.

- -

RETURN VALUES

- -

PKCS12_SAFEBAG_get_nid() and PKCS12_SAFEBAG_get_bag_nid() return the NID of the safeBag or bag object, or -1 if there is no corresponding NID. Other functions return a valid object of the specified type or NULL if an error occurred.

- -

SEE ALSO

- -

PKCS12_create(3), PKCS12_add_safe(3), PKCS12_add_safes(3)

- -

HISTORY

- -

The functions PKCS12_SAFEBAG_get1_cert_ex() and PKCS12_SAFEBAG_get1_crl_ex() were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_set0_attrs.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_set0_attrs.html deleted file mode 100644 index 35fc372b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_SAFEBAG_set0_attrs.html +++ /dev/null @@ -1,51 +0,0 @@ - - - - -PKCS12_SAFEBAG_set0_attrs - - - - - - - - - - -

NAME

- -

PKCS12_SAFEBAG_set0_attrs - Set attributes for a PKCS#12 safeBag

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-void PKCS12_SAFEBAG_set0_attrs(PKCS12_SAFEBAG *bag, STACK_OF(X509_ATTRIBUTE) *attrs);
- -

DESCRIPTION

- -

PKCS12_SAFEBAG_set0_attrs() assigns the stack of X509_ATTRIBUTEs to a PKCS#12 safeBag. bag is the PKCS12_SAFEBAG to assign the attributes to.

- -

RETURN VALUES

- -

PKCS12_SAFEBAG_set0_attrs() does not return a value.

- -

COPYRIGHT

- -

Copyright 2019-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_add1_attr_by_NID.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_add1_attr_by_NID.html deleted file mode 100644 index a5657ceb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_add1_attr_by_NID.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -PKCS12_add1_attr_by_NID - - - - - - - - - - -

NAME

- -

PKCS12_add1_attr_by_NID, PKCS12_add1_attr_by_txt - Add an attribute to a PKCS#12 safeBag structure

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_add1_attr_by_NID(PKCS12_SAFEBAG *bag, int nid, int type,
-                            const unsigned char *bytes, int len);
-int PKCS12_add1_attr_by_txt(PKCS12_SAFEBAG *bag, const char *attrname, int type,
-                            const unsigned char *bytes, int len);
- -

DESCRIPTION

- -

These functions add a PKCS#12 Attribute to the Attribute Set of the bag.

- -

PKCS12_add1_attr_by_NID() adds an attribute of type nid with a value of ASN1 type type constructed using len bytes from bytes.

- -

PKCS12_add1_attr_by_txt() adds an attribute of type attrname with a value of ASN1 type type constructed using len bytes from bytes.

- -

NOTES

- -

These functions do not check whether an existing attribute of the same type is present. There can be multiple attributes with the same type assigned to a safeBag.

- -

Both functions were added in OpenSSL 3.0.

- -

RETURN VALUES

- -

A return value of 1 indicates success, 0 indicates failure.

- -

SEE ALSO

- -

PKCS12_create(3)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_CSPName_asc.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_add_CSPName_asc.html deleted file mode 100644 index b7ff3bfa..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_CSPName_asc.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -PKCS12_add_CSPName_asc - - - - - - - - - - -

NAME

- -

PKCS12_add_CSPName_asc - Add a Microsoft CSP Name attribute to a PKCS#12 safeBag

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_add_CSPName_asc(PKCS12_SAFEBAG *bag, const char *name, int namelen);
- -

DESCRIPTION

- -

PKCS12_add_CSPName_asc() adds an ASCII string representation of the Microsoft CSP Name attribute to a PKCS#12 safeBag.

- -

bag is the PKCS12_SAFEBAG to add the attribute to.

- -

RETURN VALUES

- -

Returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

PKCS12_add_friendlyname_asc(3)

- -

COPYRIGHT

- -

Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_cert.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_add_cert.html deleted file mode 100644 index 279802d6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_cert.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -PKCS12_add_cert - - - - - - - - - - -

NAME

- -

PKCS12_add_cert, PKCS12_add_key, PKCS12_add_key_ex, PKCS12_add_secret - Add an object to a set of PKCS#12 safeBags

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-PKCS12_SAFEBAG *PKCS12_add_cert(STACK_OF(PKCS12_SAFEBAG) **pbags, X509 *cert);
-PKCS12_SAFEBAG *PKCS12_add_key(STACK_OF(PKCS12_SAFEBAG) **pbags,
-                              EVP_PKEY *key, int key_usage, int iter,
-                              int key_nid, const char *pass);
-PKCS12_SAFEBAG *PKCS12_add_key_ex(STACK_OF(PKCS12_SAFEBAG) **pbags,
-                                  EVP_PKEY *key, int key_usage, int iter,
-                                  int key_nid, const char *pass,
-                                  OSSL_LIB_CTX *ctx, const char *propq);
-
-PKCS12_SAFEBAG *PKCS12_add_secret(STACK_OF(PKCS12_SAFEBAG) **pbags,
-                                 int nid_type, const unsigned char *value, int len);
- -

DESCRIPTION

- -

These functions create a new PKCS12_SAFEBAG and add it to the set of safeBags in pbags.

- -

PKCS12_add_cert() creates a PKCS#12 certBag containing the supplied certificate and adds this to the set of PKCS#12 safeBags.

- -

PKCS12_add_key() creates a PKCS#12 keyBag (unencrypted) or a pkcs8shroudedKeyBag (encrypted) containing the supplied EVP_PKEY and adds this to the set of PKCS#12 safeBags. If key_nid is not -1 then the key is encrypted with the supplied algorithm, using pass as the passphrase and iter as the iteration count. If iter is zero then a default value for iteration count of 2048 is used.

- -

PKCS12_add_key_ex() is identical to PKCS12_add_key() but allows for a library context ctx and property query propq to be used to select algorithm implementations.

- -

PKCS12_add_secret() creates a PKCS#12 secretBag with an OID corresponding to the supplied nid_type containing the supplied value as an ASN1 octet string. This is then added to the set of PKCS#12 safeBags.

- -

NOTES

- -

If a certificate contains an alias or a keyid then this will be used for the corresponding friendlyName or localKeyID in the PKCS12 structure.

- -

PKCS12_add_key() makes assumptions regarding the encoding of the given pass phrase. See passphrase-encoding(7) for more information.

- -

RETURN VALUES

- -

A valid PKCS12_SAFEBAG structure or NULL if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

PKCS12_create(3)

- -

HISTORY

- -

PKCS12_add_secret() and PKCS12_add_key_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_friendlyname_asc.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_add_friendlyname_asc.html deleted file mode 100644 index 9bf33345..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_friendlyname_asc.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -PKCS12_add_friendlyname_asc - - - - - - - - - - -

NAME

- -

PKCS12_add_friendlyname_asc, PKCS12_add_friendlyname_utf8, PKCS12_add_friendlyname_uni - Functions to add the friendlyname attribute to a PKCS#12 safeBag

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_add_friendlyname_asc(PKCS12_SAFEBAG *bag, const char *name,
-                                int namelen);
-
-int PKCS12_add_friendlyname_utf8(PKCS12_SAFEBAG *bag, const char *name,
-                                int namelen);
-
-int PKCS12_add_friendlyname_uni(PKCS12_SAFEBAG *bag,
-                                const unsigned char *name, int namelen);
- -

DESCRIPTION

- -

PKCS12_add_friendlyname_asc() adds an ASCII string representation of the PKCS#9 friendlyName attribute to a PKCS#12 safeBag.

- -

PKCS12_add_friendlyname_utf8() adds a UTF-8 string representation of the PKCS#9 friendlyName attribute to a PKCS#12 safeBag.

- -

PKCS12_add_friendlyname_uni() adds a Unicode string representation of the PKCS#9 friendlyName attribute to a PKCS#12 safeBag.

- -

bag is the PKCS12_SAFEBAG to add the attribute to.

- -

RETURN VALUES

- -

Returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

PKCS12_get_friendlyname(3)

- -

COPYRIGHT

- -

Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_localkeyid.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_add_localkeyid.html deleted file mode 100644 index 231bf7ad..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_localkeyid.html +++ /dev/null @@ -1,59 +0,0 @@ - - - - -PKCS12_add_localkeyid - - - - - - - - - - -

NAME

- -

PKCS12_add_localkeyid - Add the localKeyId attribute to a PKCS#12 safeBag

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, const char *name,
-                          int namelen);
- -

DESCRIPTION

- -

PKCS12_add_localkeyid() adds an octet string representation of the PKCS#9 localKeyId attribute to a PKCS#12 safeBag.

- -

bag is the PKCS12_SAFEBAG to add the attribute to.

- -

RETURN VALUES

- -

Returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

PKCS12_add_friendlyname_asc(3)

- -

COPYRIGHT

- -

Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_safe.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_add_safe.html deleted file mode 100644 index 4031928e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_add_safe.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -PKCS12_add_safe - - - - - - - - - - -

NAME

- -

PKCS12_add_safe, PKCS12_add_safe_ex, PKCS12_add_safes, PKCS12_add_safes_ex - Create and add objects to a PKCS#12 structure

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_add_safe(STACK_OF(PKCS7) **psafes, STACK_OF(PKCS12_SAFEBAG) *bags,
-                   int safe_nid, int iter, const char *pass);
-int PKCS12_add_safe_ex(STACK_OF(PKCS7) **psafes, STACK_OF(PKCS12_SAFEBAG) *bags,
-                       int safe_nid, int iter, const char *pass,
-                       OSSL_LIB_CTX *ctx, const char *propq);
-
-PKCS12 *PKCS12_add_safes(STACK_OF(PKCS7) *safes, int p7_nid);
-PKCS12 *PKCS12_add_safes_ex(STACK_OF(PKCS7) *safes, int p7_nid,
-                            OSSL_LIB_CTX *ctx, const char *propq);
- -

DESCRIPTION

- -

PKCS12_add_safe() creates a new PKCS7 contentInfo containing the supplied PKCS12_SAFEBAGs and adds this to a set of PKCS7 contentInfos. Its type depends on the value of safe_nid:

- - - -

PKCS12_add_safe_ex() is identical to PKCS12_add_safe() but allows for a library context ctx and property query propq to be used to select algorithm implementations.

- -

PKCS12_add_safes() creates a PKCS12 structure containing the supplied set of PKCS7 contentInfos. The safes are enclosed first within a PKCS7 contentInfo of type p7_nid. Currently the only supported type is NID_pkcs7_data.

- -

PKCS12_add_safes_ex() is identical to PKCS12_add_safes() but allows for a library context ctx and property query propq to be used to select algorithm implementations.

- -

NOTES

- -

PKCS12_add_safe() makes assumptions regarding the encoding of the given pass phrase. See passphrase-encoding(7) for more information.

- -

RETURN VALUES

- -

PKCS12_add_safe() returns a value of 1 indicating success or 0 for failure.

- -

PKCS12_add_safes() returns a valid PKCS12 structure or NULL if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

PKCS12_create(3)

- -

HISTORY

- -

PKCS12_add_safe_ex() and PKCS12_add_safes_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_create.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_create.html deleted file mode 100644 index 9253266f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_create.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -PKCS12_create - - - - - - - - - - -

NAME

- -

PKCS12_create, PKCS12_create_ex, PKCS12_create_cb, PKCS12_create_ex2 - create a PKCS#12 structure

- -

SYNOPSIS

- -
 #include <openssl/pkcs12.h>
-
- PKCS12 *PKCS12_create(const char *pass, const char *name, EVP_PKEY *pkey,
-                       X509 *cert, STACK_OF(X509) *ca,
-                       int nid_key, int nid_cert, int iter, int mac_iter, int keytype);
- PKCS12 *PKCS12_create_ex(const char *pass, const char *name, EVP_PKEY *pkey,
-                          X509 *cert, STACK_OF(X509) *ca, int nid_key, int nid_cert,
-                          int iter, int mac_iter, int keytype,
-                          OSSL_LIB_CTX *ctx, const char *propq);
-
- typedef int PKCS12_create_cb(PKCS12_SAFEBAG *bag, void *cbarg);
-
- PKCS12 *PKCS12_create_ex2(const char *pass, const char *name, EVP_PKEY *pkey,
-                           X509 *cert, STACK_OF(X509) *ca, int nid_key, int nid_cert,
-                           int iter, int mac_iter, int keytype,
-                           OSSL_LIB_CTX *ctx, const char *propq,
-                           PKCS12_create_cb *cb, void *cbarg);
-=head1 DESCRIPTION
- -

PKCS12_create() creates a PKCS#12 structure.

- -

pass is the passphrase to use. name is the friendlyName to use for the supplied certificate and key. pkey is the private key to include in the structure and cert its corresponding certificates. ca, if not NULL is an optional set of certificates to also include in the structure.

- -

nid_key and nid_cert are the encryption algorithms that should be used for the key and certificate respectively. The modes GCM, CCM, XTS, and OCB are unsupported. iter is the encryption algorithm iteration count to use and mac_iter is the MAC iteration count to use. keytype is the type of key.

- -

PKCS12_create_ex() is identical to PKCS12_create() but allows for a library context ctx and property query propq to be used to select algorithm implementations.

- -

PKCS12_create_ex2() is identical to PKCS12_create_ex() but allows for a user defined callback cb of type PKCS12_create_cb to be specified and also allows for an optional argument cbarg to be passed back to the callback.

- -

The cb if specified will be called for every safebag added to the PKCS12 structure and allows for optional application processing on the associated safebag. For example one such use could be to add attributes to the safebag.

- -

NOTES

- -

The parameters nid_key, nid_cert, iter, mac_iter and keytype can all be set to zero and sensible defaults will be used.

- -

These defaults are: AES password based encryption (PBES2 with PBKDF2 and AES-256-CBC) for private keys and certificates, the PBKDF2 and MAC key derivation iteration count of PKCS12_DEFAULT_ITER (currently 2048), and MAC algorithm HMAC with SHA2-256. The MAC key derivation algorithm used for the outer PKCS#12 structure is PKCS12KDF.

- -

The default MAC iteration count is 1 in order to retain compatibility with old software which did not interpret MAC iteration counts. If such compatibility is not required then mac_iter should be set to PKCS12_DEFAULT_ITER.

- -

keytype adds a flag to the store private key. This is a non standard extension that is only currently interpreted by MSIE. If set to zero the flag is omitted, if set to KEY_SIG the key can be used for signing only, if set to KEY_EX it can be used for signing and encryption. This option was useful for old export grade software which could use signing only keys of arbitrary size but had restrictions on the permissible sizes of keys which could be used for encryption.

- -

If name is NULL and cert contains an alias then this will be used for the corresponding friendlyName in the PKCS12 structure instead. Similarly, if pkey is NULL and cert contains a keyid then this will be used for the corresponding localKeyID in the PKCS12 structure instead of the id calculated from the pkey.

- -

For all certificates in ca then if a certificate contains an alias or keyid then this will be used for the corresponding friendlyName or localKeyID in the PKCS12 structure.

- -

Either pkey, cert or both can be NULL to indicate that no key or certificate is required. In previous versions both had to be present or a fatal error is returned.

- -

nid_key or nid_cert can be set to -1 indicating that no encryption should be used.

- -

mac_iter can be set to -1 and the MAC will then be omitted entirely. This can be useful when running with the FIPS provider as the PKCS12KDF is not a FIPS approvable algorithm.

- -

PKCS12_create() makes assumptions regarding the encoding of the given pass phrase. See passphrase-encoding(7) for more information.

- -

If cb is specified, then it should return 1 for success and -1 for a fatal error. A return of 0 is intended to mean to not add the bag after all.

- -

RETURN VALUES

- -

PKCS12_create() returns a valid PKCS12 structure or NULL if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

EVP_KDF-PKCS12KDF(7), d2i_PKCS12(3), OSSL_PROVIDER-FIPS(7), passphrase-encoding(7)

- -

HISTORY

- -

PKCS12_create_ex() was added in OpenSSL 3.0. PKCS12_create_ex2() was added in OpenSSL 3.2.

- -

The defaults for encryption algorithms, MAC algorithm, and the MAC key derivation iteration count were changed in OpenSSL 3.0 to more modern standards.

- -

COPYRIGHT

- -

Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_decrypt_skey.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_decrypt_skey.html deleted file mode 100644 index 26c64133..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_decrypt_skey.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -PKCS12_decrypt_skey - - - - - - - - - - -

NAME

- -

PKCS12_decrypt_skey, PKCS12_decrypt_skey_ex - PKCS12 shrouded keyBag decrypt functions

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-PKCS8_PRIV_KEY_INFO *PKCS12_decrypt_skey(const PKCS12_SAFEBAG *bag,
-                                         const char *pass, int passlen);
-PKCS8_PRIV_KEY_INFO *PKCS12_decrypt_skey_ex(const PKCS12_SAFEBAG *bag,
-                                            const char *pass, int passlen,
-                                            OSSL_LIB_CTX *ctx,
-                                            const char *propq);
- -

DESCRIPTION

- -

PKCS12_decrypt_skey() Decrypt the PKCS#8 shrouded keybag contained within bag using the supplied password pass of length passlen.

- -

PKCS12_decrypt_skey_ex() is similar to the above but allows for a library context ctx and property query propq to be used to select algorithm implementations.

- -

RETURN VALUES

- -

Both functions will return the decrypted key or NULL if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

PKCS8_decrypt_ex(3), PKCS8_encrypt_ex(3), PKCS12_add_key_ex(3), PKCS12_SAFEBAG_create_pkcs8_encrypt_ex(3)

- -

HISTORY

- -

PKCS12_decrypt_skey_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_gen_mac.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_gen_mac.html deleted file mode 100644 index 545ed79e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_gen_mac.html +++ /dev/null @@ -1,102 +0,0 @@ - - - - -PKCS12_gen_mac - - - - - - - - - - -

NAME

- -

PKCS12_gen_mac, PKCS12_setup_mac, PKCS12_set_mac, PKCS12_set_pbmac1_pbkdf2, PKCS12_verify_mac, PKCS12_get0_mac - Functions to create and manipulate a PKCS#12 MAC structure

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_gen_mac(PKCS12 *p12, const char *pass, int passlen,
-                   unsigned char *mac, unsigned int *maclen);
-int PKCS12_verify_mac(PKCS12 *p12, const char *pass, int passlen);
-int PKCS12_set_mac(PKCS12 *p12, const char *pass, int passlen,
-                   unsigned char *salt, int saltlen, int iter,
-                   const EVP_MD *md_type);
-int PKCS12_set_pbmac1_pbkdf2(PKCS12 *p12, const char *pass, int passlen,
-                                  unsigned char *salt, int saltlen, int iter,
-                                  const EVP_MD *md_type,
-                                  const char *prf_md_name);
-int PKCS12_setup_mac(PKCS12 *p12, int iter, unsigned char *salt,
-                     int saltlen, const EVP_MD *md_type);
-
-void PKCS12_get0_mac(const ASN1_OCTET_STRING **pmac,
-                     const X509_ALGOR **pmacalg,
-                     const ASN1_OCTET_STRING **psalt,
-                     const ASN1_INTEGER **piter,
-                     const PKCS12 *p12);
- -

DESCRIPTION

- -

PKCS12_gen_mac() generates an HMAC over the entire PKCS#12 object using the supplied password along with a set of already configured parameters. The default key generation mechanism used is PKCS12KDF.

- -

PKCS12_verify_mac() verifies the PKCS#12 object's HMAC using the supplied password.

- -

PKCS12_setup_mac() sets the MAC part of the PKCS#12 structure with the supplied parameters.

- -

PKCS12_set_mac() sets the MAC and MAC parameters into the PKCS#12 object. PKCS12_set_pbmac1_pbkdf2() sets the MAC and MAC parameters into the PKCS#12 object when PBMAC1 with PBKDF2 is used for protection of the PKCS#12 object.

- -

pass is the passphrase to use in the HMAC. salt is the salt value to use, iter is the iteration count and md_type is the message digest function to use. prf_md_name specifies the digest used for the PBKDF2 in PBMAC1 KDF.

- -

PKCS12_get0_mac() retrieves any included MAC value, X509_ALGOR object, salt, and iter count from the PKCS12 object.

- -

NOTES

- -

If salt is NULL then a suitable salt will be generated and used.

- -

If iter is 1 then an iteration count will be omitted from the PKCS#12 structure.

- -

PKCS12_gen_mac(), PKCS12_verify_mac(), PKCS12_set_mac() and PKCS12_set_pbmac1_pbkdf2() make assumptions regarding the encoding of the given passphrase. See passphrase-encoding(7) for more information.

- -

RETURN VALUES

- -

All functions returning an integer return 1 on success and 0 if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292) IETF RFC 9579 (https://tools.ietf.org/html/rfc9579)

- -

SEE ALSO

- -

d2i_PKCS12(3), EVP_KDF-PKCS12KDF(7), PKCS12_create(3), passphrase-encoding(7)

- -

HISTORY

- -

The PKCS12_set_pbmac1_pbkdf2 function was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_get_friendlyname.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_get_friendlyname.html deleted file mode 100644 index 7f01ee75..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_get_friendlyname.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -PKCS12_get_friendlyname - - - - - - - - - - -

NAME

- -

PKCS12_get_friendlyname - Retrieve the friendlyname attribute from a PKCS#12 safeBag

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-char *PKCS12_get_friendlyname(PKCS12_SAFEBAG *bag);
- -

DESCRIPTION

- -

PKCS12_get_friendlyname() retrieves a UTF-8 string representation of the PKCS#9 friendlyName attribute for a PKCS#12 safeBag item.

- -

bag is the PKCS12_SAFEBAG to retrieve the attribute from.

- -

RETURN VALUES

- -

A UTF-8 string, or NULL if the attribute was either not present or an error occurred.

- -

The returned string is allocated by OpenSSL and should be freed by the user.

- -

SEE ALSO

- -

PKCS12_add_friendlyname_asc(3)

- -

COPYRIGHT

- -

Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_init.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_init.html deleted file mode 100644 index 724e2276..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_init.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -PKCS12_init - - - - - - - - - - -

NAME

- -

PKCS12_init, PKCS12_init_ex - Create a new empty PKCS#12 structure

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-PKCS12 *PKCS12_init(int mode);
-PKCS12 *PKCS12_init_ex(int mode, OSSL_LIB_CTX *ctx, const char *propq);
- -

DESCRIPTION

- -

PKCS12_init() creates an empty PKCS#12 structure. Any PKCS#7 authSafes added to this structure are enclosed first within a single PKCS#7 contentInfo of type mode. Currently the only supported type is NID_pkcs7_data.

- -

PKCS12_init_ex() creates an empty PKCS#12 structure and assigns the supplied ctx and propq to be used to select algorithm implementations for operations performed on the PKCS12 object.

- -

RETURN VALUES

- -

PKCS12_init() and PKCS12_init_ex() return a valid PKCS12 structure or NULL if an error occurred.

- -

SEE ALSO

- -

d2i_PKCS12(3), PKCS12_create(3), passphrase-encoding(7)

- -

HISTORY

- -

PKCS12_init_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_item_decrypt_d2i.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_item_decrypt_d2i.html deleted file mode 100644 index 97b3fab9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_item_decrypt_d2i.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -PKCS12_item_decrypt_d2i - - - - - - - - - - -

NAME

- -

PKCS12_item_decrypt_d2i, PKCS12_item_decrypt_d2i_ex, PKCS12_item_i2d_encrypt, PKCS12_item_i2d_encrypt_ex - PKCS12 item encrypt/decrypt functions

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-void *PKCS12_item_decrypt_d2i(const X509_ALGOR *algor, const ASN1_ITEM *it,
-                              const char *pass, int passlen,
-                              const ASN1_OCTET_STRING *oct, int zbuf);
-void *PKCS12_item_decrypt_d2i_ex(const X509_ALGOR *algor, const ASN1_ITEM *it,
-                                 const char *pass, int passlen,
-                                 const ASN1_OCTET_STRING *oct, int zbuf,
-                                 OSSL_LIB_CTX *libctx,
-                                 const char *propq);
-ASN1_OCTET_STRING *PKCS12_item_i2d_encrypt(X509_ALGOR *algor,
-                                           const ASN1_ITEM *it,
-                                           const char *pass, int passlen,
-                                           void *obj, int zbuf);
-ASN1_OCTET_STRING *PKCS12_item_i2d_encrypt_ex(X509_ALGOR *algor,
-                                              const ASN1_ITEM *it,
-                                              const char *pass, int passlen,
-                                              void *obj, int zbuf,
-                                              OSSL_LIB_CTX *ctx,
-                                              const char *propq);
- -

DESCRIPTION

- -

PKCS12_item_decrypt_d2i() and PKCS12_item_decrypt_d2i_ex() decrypt an octet string containing an ASN.1 encoded object using the algorithm algor and password pass of length passlen. If zbuf is nonzero then the output buffer will zeroed after the decrypt.

- -

PKCS12_item_i2d_encrypt() and PKCS12_item_i2d_encrypt_ex() encrypt an ASN.1 object it using the algorithm algor and password pass of length passlen, returning an encoded object in obj. If zbuf is nonzero then the buffer containing the input encoding will be zeroed after the encrypt.

- -

Functions ending in _ex() allow for a library context ctx and property query propq to be used to select algorithm implementations.

- -

RETURN VALUES

- -

PKCS12_item_decrypt_d2i() and PKCS12_item_decrypt_d2i_ex() return the decrypted object or NULL if an error occurred.

- -

PKCS12_item_i2d_encrypt() and PKCS12_item_i2d_encrypt_ex() return the encrypted data as an ASN.1 Octet String or NULL if an error occurred.

- -

SEE ALSO

- -

PKCS12_pbe_crypt_ex(3), PKCS8_encrypt_ex(3)

- -

HISTORY

- -

PKCS12_item_decrypt_d2i_ex() and PKCS12_item_i2d_encrypt_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_key_gen_utf8_ex.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_key_gen_utf8_ex.html deleted file mode 100644 index 15a8b4d0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_key_gen_utf8_ex.html +++ /dev/null @@ -1,133 +0,0 @@ - - - - -PKCS12_key_gen_utf8_ex - - - - - - - - - - -

NAME

- -

PKCS12_key_gen_asc, PKCS12_key_gen_asc_ex, PKCS12_key_gen_uni, PKCS12_key_gen_uni_ex, PKCS12_key_gen_utf8, PKCS12_key_gen_utf8_ex - PKCS#12 Password based key derivation

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_key_gen_asc(const char *pass, int passlen, unsigned char *salt,
-                       int saltlen, int id, int iter, int n,
-                       unsigned char *out, const EVP_MD *md_type);
-int PKCS12_key_gen_asc_ex(const char *pass, int passlen, unsigned char *salt,
-                          int saltlen, int id, int iter, int n,
-                          unsigned char *out, const EVP_MD *md_type,
-                          OSSL_LIB_CTX *ctx, const char *propq);
-int PKCS12_key_gen_uni(unsigned char *pass, int passlen, unsigned char *salt,
-                       int saltlen, int id, int iter, int n,
-                       unsigned char *out, const EVP_MD *md_type);
-int PKCS12_key_gen_uni_ex(unsigned char *pass, int passlen, unsigned char *salt,
-                          int saltlen, int id, int iter, int n,
-                          unsigned char *out, const EVP_MD *md_type,
-                          OSSL_LIB_CTX *ctx, const char *propq);
-int PKCS12_key_gen_utf8(const char *pass, int passlen, unsigned char *salt,
-                        int saltlen, int id, int iter, int n,
-                        unsigned char *out, const EVP_MD *md_type);
-int PKCS12_key_gen_utf8_ex(const char *pass, int passlen, unsigned char *salt,
-                           int saltlen, int id, int iter, int n,
-                           unsigned char *out, const EVP_MD *md_type,
-                           OSSL_LIB_CTX *ctx, const char *propq);
- -

DESCRIPTION

- -

These methods perform a key derivation according to PKCS#12 (RFC7292) with an input password pass of length passlen, a salt salt of length saltlen, an iteration count iter and a digest algorithm md_type. The ID byte id determines how the resulting key is intended to be used:

- - - -

The intended format of the supplied password is determined by the method chosen:

- - - -

pass is the password used in the derivation of length passlen. pass is an optional parameter and can be NULL. If passlen is -1, then the function will calculate the length of pass using strlen().

- -

salt is the salt used in the derivation of length saltlen. If the salt is NULL, then saltlen must be 0. The function will not attempt to calculate the length of the salt because it is not assumed to be NULL terminated.

- -

iter is the iteration count and its value should be greater than or equal to 1. RFC 2898 suggests an iteration count of at least 1000. Any iter less than 1 is treated as a single iteration.

- -

digest is the message digest function used in the derivation.

- -

The derived key will be written to out. The size of the out buffer is specified via n.

- -

Functions ending in _ex() allow for a library context ctx and property query propq to be used to select algorithm implementations.

- -

NOTES

- -

A typical application of this function is to derive keying material for an encryption algorithm from a password in the pass, a salt in salt, and an iteration count.

- -

Increasing the iter parameter slows down the algorithm which makes it harder for an attacker to perform a brute force attack using a large number of candidate passwords.

- -

RETURN VALUES

- -

Returns 1 on success or 0 on error.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

PKCS12_create_ex(3), PKCS12_pbe_crypt_ex(3), passphrase-encoding(7)

- -

HISTORY

- -

PKCS12_key_gen_asc_ex(), PKCS12_key_gen_uni_ex() and PKCS12_key_gen_utf8_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_newpass.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_newpass.html deleted file mode 100644 index 8cd4c9f7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_newpass.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -PKCS12_newpass - - - - - - - - - - -

NAME

- -

PKCS12_newpass - change the password of a PKCS12 structure

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_newpass(PKCS12 *p12, const char *oldpass, const char *newpass);
- -

DESCRIPTION

- -

PKCS12_newpass() changes the password of a PKCS12 structure.

- -

p12 is a pointer to a PKCS12 structure. oldpass is the existing password and newpass is the new password.

- -

Each of oldpass and newpass is independently interpreted as a string in the UTF-8 encoding. If it is not valid UTF-8, it is assumed to be ISO8859-1 instead.

- -

In particular, this means that passwords in the locale character set (or code page on Windows) must potentially be converted to UTF-8 before use. This may include passwords from local text files, or input from the terminal or command line. Refer to the documentation of UI_OpenSSL(3), for example.

- -

If the PKCS#12 structure does not have a password, then you must use the empty string "" for oldpass. Using NULL for oldpass will result in a PKCS12_newpass() failure.

- -

If the wrong password is used for oldpass then the function will fail, with a MAC verification error. In rare cases the PKCS12 structure does not contain a MAC: in this case it will usually fail with a decryption padding error.

- -

RETURN VALUES

- -

PKCS12_newpass() returns 1 on success or 0 on failure. Applications can retrieve the most recent error from PKCS12_newpass() with ERR_get_error().

- -

EXAMPLES

- -

This example loads a PKCS#12 file, changes its password and writes out the result to a new file.

- -
#include <stdio.h>
-#include <stdlib.h>
-#include <openssl/pem.h>
-#include <openssl/err.h>
-#include <openssl/pkcs12.h>
-
-int main(int argc, char **argv)
-{
-    FILE *fp;
-    PKCS12 *p12;
-
-    if (argc != 5) {
-        fprintf(stderr, "Usage: pkread p12file password newpass opfile\n");
-        return 1;
-    }
-    if ((fp = fopen(argv[1], "rb")) == NULL) {
-        fprintf(stderr, "Error opening file %s\n", argv[1]);
-        return 1;
-    }
-    p12 = d2i_PKCS12_fp(fp, NULL);
-    fclose(fp);
-    if (p12 == NULL) {
-        fprintf(stderr, "Error reading PKCS#12 file\n");
-        ERR_print_errors_fp(stderr);
-        return 1;
-    }
-    if (PKCS12_newpass(p12, argv[2], argv[3]) == 0) {
-        fprintf(stderr, "Error changing password\n");
-        ERR_print_errors_fp(stderr);
-        PKCS12_free(p12);
-        return 1;
-    }
-    if ((fp = fopen(argv[4], "wb")) == NULL) {
-        fprintf(stderr, "Error opening file %s\n", argv[4]);
-        PKCS12_free(p12);
-        return 1;
-    }
-    i2d_PKCS12_fp(fp, p12);
-    PKCS12_free(p12);
-    fclose(fp);
-    return 0;
-}
- -

BUGS

- -

The password format is a NULL terminated ASCII string which is converted to Unicode form internally. As a result some passwords cannot be supplied to this function.

- -

SEE ALSO

- -

PKCS12_create(3), ERR_get_error(3), passphrase-encoding(7)

- -

COPYRIGHT

- -

Copyright 2016-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_pack_p7encdata.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_pack_p7encdata.html deleted file mode 100644 index 367b3576..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_pack_p7encdata.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -PKCS12_pack_p7encdata - - - - - - - - - - -

NAME

- -

PKCS12_pack_p7encdata, PKCS12_pack_p7encdata_ex - Pack a set of PKCS#12 safeBags into a PKCS#7 encrypted data object

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-PKCS7 *PKCS12_pack_p7encdata(int pbe_nid, const char *pass, int passlen,
-                             unsigned char *salt, int saltlen, int iter,
-                             STACK_OF(PKCS12_SAFEBAG) *bags);
-PKCS7 *PKCS12_pack_p7encdata_ex(int pbe_nid, const char *pass, int passlen,
-                                unsigned char *salt, int saltlen, int iter,
-                                STACK_OF(PKCS12_SAFEBAG) *bags,
-                                OSSL_LIB_CTX *ctx, const char *propq);
- -

DESCRIPTION

- -

PKCS12_pack_p7encdata() generates a PKCS#7 ContentInfo object of encrypted-data type from the set of safeBags bags. The algorithm ID in pbe_nid can be a PKCS#12 or PKCS#5 password based encryption algorithm, or a cipher algorithm. If a cipher algorithm is passed, the PKCS#5 PBES2 algorithm will be used with this cipher as a parameter. The password pass of length passlen, salt salt of length saltlen and iteration count iter are inputs into the encryption operation.

- -

PKCS12_pack_p7encdata_ex() operates similar to the above but allows for a library context ctx and property query propq to be used to select the algorithm implementation.

- -

RETURN VALUES

- -

A PKCS7 object if successful, or NULL if an error occurred.

- -

CONFORMING TO

- -

IETF RFC 2315 (https://tools.ietf.org/html/rfc2315)

- -

SEE ALSO

- -

PKCS12_pbe_crypt_ex(3)

- -

HISTORY

- -

PKCS12_pack_p7encdata_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS12_parse.html b/openssl-install/share/doc/openssl/html/man3/PKCS12_parse.html deleted file mode 100644 index 72431607..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS12_parse.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -PKCS12_parse - - - - - - - - - - -

NAME

- -

PKCS12_parse - parse a PKCS#12 structure

- -

SYNOPSIS

- -
#include <openssl/pkcs12.h>
-
-int PKCS12_parse(PKCS12 *p12, const char *pass, EVP_PKEY **pkey, X509 **cert,
-                 STACK_OF(X509) **ca);
- -

DESCRIPTION

- -

PKCS12_parse() parses a PKCS12 structure.

- -

p12 is the PKCS12 structure to parse. pass is the passphrase to use. If successful the private key will be written to *pkey, the corresponding certificate to *cert and any additional certificates to *ca.

- -

NOTES

- -

Each of the parameters pkey, cert, and ca can be NULL in which case the private key, the corresponding certificate, or the additional certificates, respectively, will be discarded. If any of pkey and cert is non-NULL the variable it points to is initialized. If ca is non-NULL and *ca is NULL a new STACK will be allocated. If ca is non-NULL and *ca is a valid STACK then additional certificates are appended in the given order to *ca.

- -

The friendlyName and localKeyID attributes (if present) on each certificate will be stored in the alias and keyid attributes of the X509 structure.

- -

The parameter pass is interpreted as a string in the UTF-8 encoding. If it is not valid UTF-8, then it is assumed to be ISO8859-1 instead.

- -

In particular, this means that passwords in the locale character set (or code page on Windows) must potentially be converted to UTF-8 before use. This may include passwords from local text files, or input from the terminal or command line. Refer to the documentation of UI_OpenSSL(3), for example.

- -

RETURN VALUES

- -

PKCS12_parse() returns 1 for success and zero if an error occurred.

- -

The error can be obtained from ERR_get_error(3)

- -

BUGS

- -

Only a single private key and corresponding certificate is returned by this function. More complex PKCS#12 files with multiple private keys will only return the first match.

- -

Only friendlyName and localKeyID attributes are currently stored in certificates. Other attributes are discarded.

- -

Attributes currently cannot be stored in the private key EVP_PKEY structure.

- -

SEE ALSO

- -

d2i_PKCS12(3), passphrase-encoding(7)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS5_PBE_keyivgen.html b/openssl-install/share/doc/openssl/html/man3/PKCS5_PBE_keyivgen.html deleted file mode 100644 index 57d56514..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS5_PBE_keyivgen.html +++ /dev/null @@ -1,173 +0,0 @@ - - - - -PKCS5_PBE_keyivgen - - - - - - - - - - -

NAME

- -

PKCS5_PBE_keyivgen, PKCS5_PBE_keyivgen_ex, PKCS5_pbe2_set, PKCS5_pbe2_set_iv, PKCS5_pbe2_set_iv_ex, PKCS5_pbe_set, PKCS5_pbe_set_ex, PKCS5_pbe2_set_scrypt, PKCS5_pbe_set0_algor, PKCS5_pbe_set0_algor_ex, PKCS5_v2_PBE_keyivgen, PKCS5_v2_PBE_keyivgen_ex, PKCS5_v2_scrypt_keyivgen, PKCS5_v2_scrypt_keyivgen_ex, PKCS5_pbkdf2_set, PKCS5_pbkdf2_set_ex, EVP_PBE_scrypt, EVP_PBE_scrypt_ex - PKCS#5 Password based encryption routines

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int PKCS5_PBE_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
-                       ASN1_TYPE *param, const EVP_CIPHER *cipher,
-                       const EVP_MD *md, int en_de);
-int PKCS5_PBE_keyivgen_ex(EVP_CIPHER_CTX *cctx, const char *pass, int passlen,
-                          ASN1_TYPE *param, const EVP_CIPHER *cipher,
-                          const EVP_MD *md, int en_de, OSSL_LIB_CTX *libctx,
-                          const char *propq);
-int PKCS5_v2_PBE_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
-                          ASN1_TYPE *param, const EVP_CIPHER *cipher,
-                          const EVP_MD *md, int en_de);
-int PKCS5_v2_PBE_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
-                             ASN1_TYPE *param, const EVP_CIPHER *cipher,
-                             const EVP_MD *md, int en_de,
-                             OSSL_LIB_CTX *libctx, const char *propq);
-int EVP_PBE_scrypt(const char *pass, size_t passlen,
-                   const unsigned char *salt, size_t saltlen,
-                   uint64_t N, uint64_t r, uint64_t p, uint64_t maxmem,
-                   unsigned char *key, size_t keylen);
-int EVP_PBE_scrypt_ex(const char *pass, size_t passlen,
-                      const unsigned char *salt, size_t saltlen,
-                      uint64_t N, uint64_t r, uint64_t p, uint64_t maxmem,
-                      unsigned char *key, size_t keylen,
-                      OSSL_LIB_CTX *ctx, const char *propq);
-int PKCS5_v2_scrypt_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass,
-                             int passlen, ASN1_TYPE *param,
-                             const EVP_CIPHER *c, const EVP_MD *md, int en_de);
-int PKCS5_v2_scrypt_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass,
-                                int passlen, ASN1_TYPE *param,
-                                const EVP_CIPHER *c, const EVP_MD *md, int en_de,
-                                OSSL_LIB_CTX *libctx, const char *propq);
-
-#include <openssl/x509.h>
-
-int PKCS5_pbe_set0_algor(X509_ALGOR *algor, int alg, int iter,
-                         const unsigned char *salt, int saltlen);
-int PKCS5_pbe_set0_algor_ex(X509_ALGOR *algor, int alg, int iter,
-                            const unsigned char *salt, int saltlen,
-                            OSSL_LIB_CTX *libctx);
-
-X509_ALGOR *PKCS5_pbe_set(int alg, int iter,
-                          const unsigned char *salt, int saltlen);
-X509_ALGOR *PKCS5_pbe_set_ex(int alg, int iter,
-                             const unsigned char *salt, int saltlen,
-                             OSSL_LIB_CTX *libctx);
-
-X509_ALGOR *PKCS5_pbe2_set(const EVP_CIPHER *cipher, int iter,
-                           unsigned char *salt, int saltlen);
-X509_ALGOR *PKCS5_pbe2_set_iv(const EVP_CIPHER *cipher, int iter,
-                              unsigned char *salt, int saltlen,
-                              unsigned char *aiv, int prf_nid);
-X509_ALGOR *PKCS5_pbe2_set_iv_ex(const EVP_CIPHER *cipher, int iter,
-                                 unsigned char *salt, int saltlen,
-                                 unsigned char *aiv, int prf_nid,
-                                 OSSL_LIB_CTX *libctx);
-X509_ALGOR *PKCS5_pbe2_set_scrypt(const EVP_CIPHER *cipher,
-                                  const unsigned char *salt, int saltlen,
-                                  unsigned char *aiv, uint64_t N, uint64_t r,
-                                  uint64_t p);
-
-X509_ALGOR *PKCS5_pbkdf2_set(int iter, unsigned char *salt, int saltlen,
-                             int prf_nid, int keylen);
-X509_ALGOR *PKCS5_pbkdf2_set_ex(int iter, unsigned char *salt, int saltlen,
-                                int prf_nid, int keylen,
-                                OSSL_LIB_CTX *libctx);
- -

DESCRIPTION

- -

Key Derivation

- -

PKCS5_PBE_keyivgen() and PKCS5_PBE_keyivgen_ex() take a password pass of length passlen, parameters param and a message digest function md_type and performs a key derivation according to PKCS#5 PBES1. The resulting key is then used to initialise the cipher context ctx with a cipher cipher for encryption (en_de=1) or decryption (en_de=0).

- -

pass is an optional parameter and can be NULL. If passlen is -1, then the function will calculate the length of pass using strlen().

- -

PKCS5_v2_PBE_keyivgen() and PKCS5_v2_PBE_keyivgen_ex() are similar to the above but instead use PKCS#5 PBES2 as the encryption algorithm using the supplied parameters.

- -

PKCS5_v2_scrypt_keyivgen() and PKCS5_v2_scrypt_keyivgen_ex() use SCRYPT as the key derivation part of the encryption algorithm.

- -

salt is the salt used in the derivation of length saltlen. If the salt is NULL, then saltlen must be 0. The function will not attempt to calculate the length of the salt because it is not assumed to be NULL terminated.

- -

iter is the iteration count and its value should be greater than or equal to 1. RFC 2898 suggests an iteration count of at least 1000. Any iter less than 1 is treated as a single iteration.

- -

digest is the message digest function used in the derivation.

- -

Functions ending in _ex() take optional parameters libctx and propq which are used to select appropriate algorithm implementations.

- -

Algorithm Identifier Creation

- -

PKCS5_pbe_set(), PKCS5_pbe_set_ex(), PKCS5_pbe2_set(), PKCS5_pbe2_set_iv(), PKCS5_pbe2_set_iv_ex() and PKCS5_pbe2_set_scrypt() generate an X509_ALGOR object which represents an AlgorithmIdentifier containing the algorithm OID and associated parameters for the PBE algorithm.

- -

PKCS5_pbkdf2_set() and PKCS5_pbkdf2_set_ex() generate an X509_ALGOR object which represents an AlgorithmIdentifier containing the algorithm OID and associated parameters for the PBKDF2 algorithm.

- -

PKCS5_pbe_set0_algor() and PKCS5_pbe_set0_algor_ex() set the PBE algorithm OID and parameters into the supplied X509_ALGOR.

- -

If salt is NULL, then saltlen specifies the size in bytes of the random salt to generate. If saltlen is 0 then a default size is used. For PBE related functions such as PKCS5_pbe_set_ex() the default salt length is 8 bytes. For PBE2 related functions that use PBKDF2 such as PKCS5_pbkdf2_set(), PKCS5_pbe2_set_scrypt() and PKCS5_pbe2_set() the default salt length is 16 bytes.

- -

NOTES

- -

The *_keyivgen() functions are typically used in PKCS#12 to encrypt objects.

- -

These functions make no assumption regarding the given password. It will simply be treated as a byte sequence.

- -

RETURN VALUES

- -

PKCS5_PBE_keyivgen(), PKCS5_v2_PBE_keyivgen(), PKCS5_v2_PBE_keyivgen_ex(), PKCS5_v2_scrypt_keyivgen(), PKCS5_v2_scrypt_keyivgen_ex(), PKCS5_pbe_set0_algor() and PKCS5_pbe_set0_algor_ex() return 1 for success and 0 if an error occurs.

- -

PKCS5_pbe_set(), PKCS5_pbe_set_ex(), PKCS5_pbe2_set(), PKCS5_pbe2_set_iv(), PKCS5_pbe2_set_iv_ex(), PKCS5_pbe2_set_scrypt(), PKCS5_pbkdf2_set() and PKCS5_pbkdf2_set_ex() return an X509_ALGOR object or NULL if an error occurs.

- -

CONFORMING TO

- -

IETF RFC 8018 (https://tools.ietf.org/html/rfc8018)

- -

SEE ALSO

- -

EVP_PBE_CipherInit_ex(3), PKCS12_pbe_crypt_ex(3), passphrase-encoding(7)

- -

HISTORY

- -

PKCS5_v2_PBE_keyivgen_ex(), EVP_PBE_scrypt_ex(), PKCS5_v2_scrypt_keyivgen_ex(), PKCS5_pbe_set0_algor_ex(), PKCS5_pbe_set_ex(), PKCS5_pbe2_set_iv_ex() and PKCS5_pbkdf2_set_ex() were added in OpenSSL 3.0.

- -

From OpenSSL 3.0 the PBKDF1 algorithm used in PKCS5_PBE_keyivgen() and PKCS5_PBE_keyivgen_ex() has been moved to the legacy provider as an EVP_KDF.

- -

In OpenSSL 3.2 the default salt length changed from 8 bytes to 16 bytes for PBE2 related functions such as PKCS5_pbe2_set(). This is required for PBKDF2 FIPS compliance.

- -

COPYRIGHT

- -

Copyright 2021-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS5_PBKDF2_HMAC.html b/openssl-install/share/doc/openssl/html/man3/PKCS5_PBKDF2_HMAC.html deleted file mode 100644 index 24ce333b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS5_PBKDF2_HMAC.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -PKCS5_PBKDF2_HMAC - - - - - - - - - - -

NAME

- -

PKCS5_PBKDF2_HMAC, PKCS5_PBKDF2_HMAC_SHA1 - password based derivation routines with salt and iteration count

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-int PKCS5_PBKDF2_HMAC(const char *pass, int passlen,
-                      const unsigned char *salt, int saltlen, int iter,
-                      const EVP_MD *digest,
-                      int keylen, unsigned char *out);
-
-int PKCS5_PBKDF2_HMAC_SHA1(const char *pass, int passlen,
-                           const unsigned char *salt, int saltlen, int iter,
-                           int keylen, unsigned char *out);
- -

DESCRIPTION

- -

PKCS5_PBKDF2_HMAC() derives a key from a password using a salt and iteration count as specified in RFC 2898.

- -

pass is the password used in the derivation of length passlen. pass is an optional parameter and can be NULL. If passlen is -1, then the function will calculate the length of pass using strlen().

- -

salt is the salt used in the derivation of length saltlen. If the salt is NULL, then saltlen must be 0. The function will not attempt to calculate the length of the salt because it is not assumed to be NULL terminated.

- -

iter is the iteration count and its value should be greater than or equal to 1. RFC 2898 suggests an iteration count of at least 1000. Any iter value less than 1 is invalid; such values will result in failure and raise the PROV_R_INVALID_ITERATION_COUNT error.

- -

digest is the message digest function used in the derivation. PKCS5_PBKDF2_HMAC_SHA1() calls PKCS5_PBKDF2_HMAC() with EVP_sha1().

- -

The derived key will be written to out. The size of the out buffer is specified via keylen.

- -

NOTES

- -

A typical application of this function is to derive keying material for an encryption algorithm from a password in the pass, a salt in salt, and an iteration count.

- -

Increasing the iter parameter slows down the algorithm which makes it harder for an attacker to perform a brute force attack using a large number of candidate passwords.

- -

These functions make no assumption regarding the given password. It will simply be treated as a byte sequence.

- -

RETURN VALUES

- -

PKCS5_PBKDF2_HMAC() and PBKCS5_PBKDF2_HMAC_SHA1() return 1 on success or 0 on error.

- -

SEE ALSO

- -

evp(7), RAND_bytes(3), EVP_BytesToKey(3), passphrase-encoding(7)

- -

COPYRIGHT

- -

Copyright 2014-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS7_decrypt.html b/openssl-install/share/doc/openssl/html/man3/PKCS7_decrypt.html deleted file mode 100644 index 30643b73..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS7_decrypt.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -PKCS7_decrypt - - - - - - - - - - -

NAME

- -

PKCS7_decrypt - decrypt content from a PKCS#7 envelopedData structure

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-int PKCS7_decrypt(PKCS7 *p7, EVP_PKEY *pkey, X509 *cert, BIO *data, int flags);
- -

DESCRIPTION

- -

PKCS7_decrypt() extracts and decrypts the content from a PKCS#7 envelopedData structure. pkey is the private key of the recipient, cert is the recipients certificate, data is a BIO to write the content to and flags is an optional set of flags.

- -

NOTES

- -

Although the recipients certificate is not needed to decrypt the data it is needed to locate the appropriate (of possible several) recipients in the PKCS#7 structure.

- -

The following flags can be passed in the flags parameter.

- -

If the PKCS7_TEXT flag is set MIME headers for type text/plain are deleted from the content. If the content is not of type text/plain then an error is returned.

- -

RETURN VALUES

- -

PKCS7_decrypt() returns either 1 for success or 0 for failure. The error can be obtained from ERR_get_error(3)

- -

BUGS

- -

PKCS7_decrypt() must be passed the correct recipient key and certificate. It would be better if it could look up the correct key and certificate from a database.

- -

The lack of single pass processing and need to hold all data in memory as mentioned in PKCS7_sign() also applies to PKCS7_verify().

- -

SEE ALSO

- -

ERR_get_error(3), PKCS7_encrypt(3)

- -

COPYRIGHT

- -

Copyright 2002-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS7_encrypt.html b/openssl-install/share/doc/openssl/html/man3/PKCS7_encrypt.html deleted file mode 100644 index ec329f2d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS7_encrypt.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -PKCS7_encrypt - - - - - - - - - - -

NAME

- -

PKCS7_encrypt_ex, PKCS7_encrypt - create a PKCS#7 envelopedData structure

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-PKCS7 *PKCS7_encrypt_ex(STACK_OF(X509) *certs, BIO *in,
-                        const EVP_CIPHER *cipher, int flags,
-                        OSSL_LIB_CTX *libctx, const char *propq);
-PKCS7 *PKCS7_encrypt(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher,
-                     int flags);
- -

DESCRIPTION

- -

PKCS7_encrypt_ex() creates and returns a PKCS#7 envelopedData structure. certs is a list of recipient certificates. in is the content to be encrypted. cipher is the symmetric cipher to use. flags is an optional set of flags. The library context libctx and the property query propq are used when retrieving algorithms from providers.

- -

Only RSA keys are supported in PKCS#7 and envelopedData so the recipient certificates supplied to this function must all contain RSA public keys, though they do not have to be signed using the RSA algorithm.

- -

EVP_des_ede3_cbc() (triple DES) is the algorithm of choice for S/MIME use because most clients will support it.

- -

Some old "export grade" clients may only support weak encryption using 40 or 64 bit RC2. These can be used by passing EVP_rc2_40_cbc() and EVP_rc2_64_cbc() respectively.

- -

The algorithm passed in the cipher parameter must support ASN1 encoding of its parameters.

- -

Many browsers implement a "sign and encrypt" option which is simply an S/MIME envelopedData containing an S/MIME signed message. This can be readily produced by storing the S/MIME signed message in a memory BIO and passing it to PKCS7_encrypt().

- -

The following flags can be passed in the flags parameter.

- -

If the PKCS7_TEXT flag is set MIME headers for type text/plain are prepended to the data.

- -

Normally the supplied content is translated into MIME canonical format (as required by the S/MIME specifications) if PKCS7_BINARY is set no translation occurs. This option should be used if the supplied data is in binary format otherwise the translation will corrupt it. If PKCS7_BINARY is set then PKCS7_TEXT is ignored.

- -

If the PKCS7_STREAM flag is set a partial PKCS7 structure is output suitable for streaming I/O: no data is read from the BIO in.

- -

If the flag PKCS7_STREAM is set the returned PKCS7 structure is not complete and outputting its contents via a function that does not properly finalize the PKCS7 structure will give unpredictable results.

- -

Several functions including SMIME_write_PKCS7(), i2d_PKCS7_bio_stream(), PEM_write_bio_PKCS7_stream() finalize the structure. Alternatively finalization can be performed by obtaining the streaming ASN1 BIO directly using BIO_new_PKCS7().

- -

PKCS7_encrypt() is similar to PKCS7_encrypt_ex() but uses default values of NULL for the library context libctx and the property query propq.

- -

RETURN VALUES

- -

PKCS7_encrypt_ex() and PKCS7_encrypt() return either a PKCS7 structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), PKCS7_decrypt(3)

- -

HISTORY

- -

The function PKCS7_encrypt_ex() was added in OpenSSL 3.0.

- -

The PKCS7_STREAM flag was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS7_get_octet_string.html b/openssl-install/share/doc/openssl/html/man3/PKCS7_get_octet_string.html deleted file mode 100644 index 8d5ba0fe..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS7_get_octet_string.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -PKCS7_get_octet_string - - - - - - - - - - -

NAME

- -

PKCS7_get_octet_string - return octet string from a PKCS#7 envelopedData structure

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-ASN1_OCTET_STRING *PKCS7_get_octet_string(PKCS7 *p7);
- -

DESCRIPTION

- -

PKCS7_get_octet_string() returns a pointer to an ASN1 octet string from a PKCS#7 envelopedData structure or NULL if the structure cannot be parsed.

- -

NOTES

- -

As the 0 implies, PKCS7_get_octet_string() returns internal pointers which should not be freed by the caller.

- -

RETURN VALUES

- -

PKCS7_get_octet_string() returns an ASN1_OCTET_STRING pointer.

- -

SEE ALSO

- -

PKCS7_type_is_data(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS7_sign.html b/openssl-install/share/doc/openssl/html/man3/PKCS7_sign.html deleted file mode 100644 index 46df38a5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS7_sign.html +++ /dev/null @@ -1,110 +0,0 @@ - - - - -PKCS7_sign - - - - - - - - - - -

NAME

- -

PKCS7_sign_ex, PKCS7_sign - create a PKCS#7 signedData structure

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
-                     BIO *data, int flags, OSSL_LIB_CTX *libctx,
-                     const char *propq);
-PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
-                  BIO *data, int flags);
- -

DESCRIPTION

- -

PKCS7_sign_ex() creates and returns a PKCS#7 signedData structure. signcert is the certificate to sign with, pkey is the corresponding private key. certs is an optional set of extra certificates to include in the PKCS#7 structure (for example any intermediate CAs in the chain). The library context libctx and property query propq are used when retrieving algorithms from providers.

- -

The data to be signed is read from BIO data.

- -

flags is an optional set of flags.

- -

Any of the following flags (ored together) can be passed in the flags parameter.

- -

Many S/MIME clients expect the signed content to include valid MIME headers. If the PKCS7_TEXT flag is set MIME headers for type text/plain are prepended to the data.

- -

If PKCS7_NOCERTS is set the signer's certificate and the extra certs will not be included in the PKCS7 structure. The signer's certificate must still be supplied in the signcert parameter though. This can reduce the size of the signatures if the signer's certificates can be obtained by other means: for example a previously signed message.

- -

The data being signed is included in the PKCS7 structure, unless PKCS7_DETACHED is set in which case it is omitted. This is used for PKCS7 detached signatures which are used in S/MIME plaintext signed messages for example.

- -

Normally the supplied content is translated into MIME canonical format (as required by the S/MIME specifications) if PKCS7_BINARY is set no translation occurs. This option should be used if the supplied data is in binary format otherwise the translation will corrupt it.

- -

The signedData structure includes several PKCS#7 authenticatedAttributes including the signing time, the PKCS#7 content type and the supported list of ciphers in an SMIMECapabilities attribute. If PKCS7_NOATTR is set then no authenticatedAttributes will be used. If PKCS7_NOSMIMECAP is set then just the SMIMECapabilities are omitted.

- -

If present the SMIMECapabilities attribute indicates support for the following algorithms: triple DES, 128 bit RC2, 64 bit RC2, DES and 40 bit RC2. If any of these algorithms is disabled then it will not be included.

- -

If the flags PKCS7_STREAM is set then the returned PKCS7 structure is just initialized ready to perform the signing operation. The signing is however not performed and the data to be signed is not read from the data parameter. Signing is deferred until after the data has been written. In this way data can be signed in a single pass.

- -

If the PKCS7_PARTIAL flag is set a partial PKCS7 structure is output to which additional signers and capabilities can be added before finalization.

- -

If the flag PKCS7_STREAM is set the returned PKCS7 structure is not complete and outputting its contents via a function that does not properly finalize the PKCS7 structure will give unpredictable results.

- -

Several functions including SMIME_write_PKCS7(), i2d_PKCS7_bio_stream(), PEM_write_bio_PKCS7_stream() finalize the structure. Alternatively finalization can be performed by obtaining the streaming ASN1 BIO directly using BIO_new_PKCS7().

- -

If a signer is specified it will use the default digest for the signing algorithm. This is SHA256 for both RSA and DSA keys.

- -

The certs, signcert and pkey parameters can all be NULL if the PKCS7_PARTIAL flag is set. One or more signers can be added using the function PKCS7_sign_add_signer(). PKCS7_final() must also be called to finalize the structure if streaming is not enabled. Alternative signing digests can also be specified using this method.

- -

If signcert and pkey are NULL then a certificates only PKCS#7 structure is output.

- -

In versions of OpenSSL before 1.0.0 the signcert and pkey parameters must not be NULL.

- -

PKCS7_sign() is like PKCS7_sign_ex() except that it uses default values of NULL for the library context libctx and the property query propq. This is retained for API backward compatibility.

- -

BUGS

- -

Some advanced attributes such as counter signatures are not supported.

- -

RETURN VALUES

- -

PKCS7_sign_ex() and PKCS7_sign() return either a valid PKCS7 structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), PKCS7_verify(3)

- -

HISTORY

- -

The function PKCS7_sign_ex() was added in OpenSSL 3.0.

- -

The PKCS7_PARTIAL flag, and the ability for certs, signcert, and pkey parameters to be NULL were added in OpenSSL 1.0.0.

- -

The PKCS7_STREAM flag was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS7_sign_add_signer.html b/openssl-install/share/doc/openssl/html/man3/PKCS7_sign_add_signer.html deleted file mode 100644 index 6834f781..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS7_sign_add_signer.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -PKCS7_sign_add_signer - - - - - - - - - - -

NAME

- -

PKCS7_sign_add_signer, PKCS7_add_certificate, PKCS7_add_crl - add information to PKCS7 structure

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-PKCS7_SIGNER_INFO *PKCS7_sign_add_signer(PKCS7 *p7, X509 *signcert,
-                                         EVP_PKEY *pkey, const EVP_MD *md, int flags);
-int PKCS7_add_certificate(PKCS7 *p7, X509 *cert);
-int PKCS7_add_crl(PKCS7 *p7, X509_CRL *crl);
- -

DESCRIPTION

- -

PKCS7_sign_add_signer() adds a signer with certificate signcert and private key pkey using message digest md to a PKCS7 signed data structure p7.

- -

The PKCS7 structure should be obtained from an initial call to PKCS7_sign() with the flag PKCS7_PARTIAL set or in the case or re-signing a valid PKCS#7 signed data structure.

- -

If the md parameter is NULL then the default digest for the public key algorithm will be used.

- -

Unless the PKCS7_REUSE_DIGEST flag is set the returned PKCS7 structure is not complete and must be finalized either by streaming (if applicable) or a call to PKCS7_final().

- -

NOTES

- -

The main purpose of this function is to provide finer control over a PKCS#7 signed data structure where the simpler PKCS7_sign() function defaults are not appropriate. For example if multiple signers or non default digest algorithms are needed.

- -

Any of the following flags (ored together) can be passed in the flags parameter.

- -

If PKCS7_REUSE_DIGEST is set then an attempt is made to copy the content digest value from the PKCS7 structure: to add a signer to an existing structure. An error occurs if a matching digest value cannot be found to copy. The returned PKCS7 structure will be valid and finalized when this flag is set.

- -

If PKCS7_PARTIAL is set in addition to PKCS7_REUSE_DIGEST then the PKCS7_SIGNER_INO structure will not be finalized so additional attributes can be added. In this case an explicit call to PKCS7_SIGNER_INFO_sign() is needed to finalize it.

- -

If PKCS7_NOCERTS is set the signer's certificate will not be included in the PKCS7 structure, the signer's certificate must still be supplied in the signcert parameter though. This can reduce the size of the signature if the signers certificate can be obtained by other means: for example a previously signed message.

- -

The signedData structure includes several PKCS#7 authenticatedAttributes including the signing time, the PKCS#7 content type and the supported list of ciphers in an SMIMECapabilities attribute. If PKCS7_NOATTR is set then no authenticatedAttributes will be used. If PKCS7_NOSMIMECAP is set then just the SMIMECapabilities are omitted.

- -

If present the SMIMECapabilities attribute indicates support for the following algorithms: triple DES, 128 bit RC2, 64 bit RC2, DES and 40 bit RC2. If any of these algorithms is disabled then it will not be included.

- -

PKCS7_sign_add_signers() returns an internal pointer to the PKCS7_SIGNER_INFO structure just added, which can be used to set additional attributes before it is finalized.

- -

PKCS7_add_certificate() adds to the PKCS7 structure p7 the certificate cert, which may be an end-entity (signer) certificate or a CA certificate useful for chain building. This is done internally by PKCS7_sign_ex(3) and similar signing functions. It may have to be used before calling PKCS7_verify(3) in order to provide any missing certificate(s) needed for verification.

- -

PKCS7_add_crl() adds the CRL crl to the PKCS7 structure p7. This may be called to provide certificate status information to be included when signing or to use when verifying the PKCS7 structure.

- -

RETURN VALUES

- -

PKCS7_sign_add_signers() returns an internal pointer to the PKCS7_SIGNER_INFO structure just added or NULL if an error occurs.

- -

PKCS7_add_certificate() and PKCS7_add_crl() return 1 on success, 0 on error.

- -

SEE ALSO

- -

ERR_get_error(3), PKCS7_sign_ex(3), PKCS7_final(3), PKCS7_verify(3)

- -

HISTORY

- -

The PPKCS7_sign_add_signer() function was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2007-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS7_type_is_other.html b/openssl-install/share/doc/openssl/html/man3/PKCS7_type_is_other.html deleted file mode 100644 index 582bc48b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS7_type_is_other.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -PKCS7_type_is_other - - - - - - - - - - -

NAME

- -

PKCS7_type_is_other - determine content type of PKCS#7 envelopedData structure

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-int PKCS7_type_is_other(PKCS7 *p7);
- -

DESCRIPTION

- -

PKCS7_type_is_other() returns the whether the content type of a PKCS#7 envelopedData structure is one of the following content types:

- -

NID_pkcs7_data NID_pkcs7_signed NID_pkcs7_enveloped NID_pkcs7_signedAndEnveloped NID_pkcs7_digest NID_pkcs7_encrypted

- -

RETURN VALUES

- -

PKCS7_type_is_other() returns either 0 if the content type is matched or 1 otherwise.

- -

SEE ALSO

- -

PKCS7_type_is_data(3), PKCS7_get_octet_string(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS7_verify.html b/openssl-install/share/doc/openssl/html/man3/PKCS7_verify.html deleted file mode 100644 index 8452223d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS7_verify.html +++ /dev/null @@ -1,110 +0,0 @@ - - - - -PKCS7_verify - - - - - - - - - - -

NAME

- -

PKCS7_verify, PKCS7_get0_signers - verify a PKCS#7 signedData structure

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-int PKCS7_verify(PKCS7 *p7, STACK_OF(X509) *certs, X509_STORE *store,
-                 BIO *indata, BIO *out, int flags);
-
-STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, STACK_OF(X509) *certs, int flags);
- -

DESCRIPTION

- -

PKCS7_verify() is very similar to CMS_verify(3). It verifies a PKCS#7 signedData structure given in p7. The optional certs parameter refers to a set of certificates in which to search for signer's certificates. It is also used as a source of untrusted intermediate CA certificates for chain building. p7 may contain extra untrusted CA certificates that may be used for chain building as well as CRLs that may be used for certificate validation. store may be NULL or point to the trusted certificate store to use for chain verification. indata refers to the signed data if the content is detached from p7. Otherwise indata should be NULL, and then the signed data must be in p7. The content is written to the BIO out unless it is NULL. flags is an optional set of flags, which can be used to modify the operation.

- -

PKCS7_get0_signers() retrieves the signer's certificates from p7, it does not check their validity or whether any signatures are valid. The certs and flags parameters have the same meanings as in PKCS7_verify().

- -

VERIFY PROCESS

- -

Normally the verify process proceeds as follows.

- -

Initially some sanity checks are performed on p7. The type of p7 must be SignedData. There must be at least one signature on the data and if the content is detached indata cannot be NULL. If the content is not detached and indata is not NULL then the structure has both embedded and external content. To treat this as an error, use the flag PKCS7_NO_DUAL_CONTENT. The default behavior allows this, for compatibility with older versions of OpenSSL.

- -

An attempt is made to locate all the signer's certificates, first looking in the certs parameter (if it is not NULL). Then they are looked up in any certificates contained in the p7 structure unless PKCS7_NOINTERN is set. If any signer's certificates cannot be located the operation fails.

- -

Each signer's certificate is chain verified using the smimesign purpose and using the trusted certificate store store if supplied. Any internal certificates in the message, which may have been added using PKCS7_add_certificate(3), are used as untrusted CAs unless PKCS7_NOCHAIN is set. If CRL checking is enabled in store and PKCS7_NOCRL is not set, any internal CRLs, which may have been added using PKCS7_add_crl(3), are used in addition to attempting to look them up in store. If store is not NULL and any chain verify fails an error code is returned.

- -

Finally the signed content is read (and written to out unless it is NULL) and the signature is checked.

- -

If all signatures verify correctly then the function is successful.

- -

Any of the following flags (ored together) can be passed in the flags parameter to change the default verify behaviour. Only the flag PKCS7_NOINTERN is meaningful to PKCS7_get0_signers().

- -

If PKCS7_NOINTERN is set the certificates in the message itself are not searched when locating the signer's certificates. This means that all the signer's certificates must be in the certs parameter.

- -

If PKCS7_NOCRL is set and CRL checking is enabled in store then any CRLs in the message itself are ignored.

- -

If the PKCS7_TEXT flag is set MIME headers for type text/plain are deleted from the content. If the content is not of type text/plain then an error is returned.

- -

If PKCS7_NOVERIFY is set the signer's certificates are not chain verified.

- -

If PKCS7_NOCHAIN is set then the certificates contained in the message are not used as untrusted CAs. This means that the whole verify chain (apart from the signer's certificates) must be contained in the trusted store.

- -

If PKCS7_NOSIGS is set then the signatures on the data are not checked.

- -

NOTES

- -

One application of PKCS7_NOINTERN is to only accept messages signed by a small number of certificates. The acceptable certificates would be passed in the certs parameter. In this case if the signer's certificate is not one of the certificates supplied in certs then the verify will fail because the signer cannot be found.

- -

Care should be taken when modifying the default verify behaviour, for example setting PKCS7_NOVERIFY|PKCS7_NOSIGS will totally disable all verification and any signed message will be considered valid. This combination is however useful if one merely wishes to write the content to out and its validity is not considered important.

- -

Chain verification should arguably be performed using the signing time rather than the current time. However, since the signing time is supplied by the signer it cannot be trusted without additional evidence (such as a trusted timestamp).

- -

RETURN VALUES

- -

PKCS7_verify() returns 1 for a successful verification and 0 if an error occurs.

- -

PKCS7_get0_signers() returns all signers or NULL if an error occurred.

- -

The error can be obtained from ERR_get_error(3).

- -

BUGS

- -

The trusted certificate store is not searched for the signer's certificates. This is primarily due to the inadequacies of the current X509_STORE functionality.

- -

The lack of single pass processing means that the signed content must all be held in memory if it is not detached.

- -

SEE ALSO

- -

CMS_verify(3), PKCS7_add_certificate(3), PKCS7_add_crl(3), ERR_get_error(3), PKCS7_sign(3)

- -

COPYRIGHT

- -

Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS8_encrypt.html b/openssl-install/share/doc/openssl/html/man3/PKCS8_encrypt.html deleted file mode 100644 index c10a2991..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS8_encrypt.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -PKCS8_encrypt - - - - - - - - - - -

NAME

- -

PKCS8_decrypt, PKCS8_decrypt_ex, PKCS8_encrypt, PKCS8_encrypt_ex, PKCS8_set0_pbe, PKCS8_set0_pbe_ex - PKCS8 encrypt/decrypt functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-PKCS8_PRIV_KEY_INFO *PKCS8_decrypt(const X509_SIG *p8, const char *pass,
-                                   int passlen);
-PKCS8_PRIV_KEY_INFO *PKCS8_decrypt_ex(const X509_SIG *p8, const char *pass,
-                                      int passlen, OSSL_LIB_CTX *ctx,
-                                      const char *propq);
-X509_SIG *PKCS8_encrypt(int pbe_nid, const EVP_CIPHER *cipher,
-                        const char *pass, int passlen, unsigned char *salt,
-                        int saltlen, int iter, PKCS8_PRIV_KEY_INFO *p8);
-X509_SIG *PKCS8_encrypt_ex(int pbe_nid, const EVP_CIPHER *cipher,
-                           const char *pass, int passlen, unsigned char *salt,
-                           int saltlen, int iter, PKCS8_PRIV_KEY_INFO *p8,
-                           OSSL_LIB_CTX *ctx, const char *propq);
-X509_SIG *PKCS8_set0_pbe(const char *pass, int passlen,
-                        PKCS8_PRIV_KEY_INFO *p8inf, X509_ALGOR *pbe);
-X509_SIG *PKCS8_set0_pbe_ex(const char *pass, int passlen,
-                            PKCS8_PRIV_KEY_INFO *p8inf, X509_ALGOR *pbe,
-                            OSSL_LIB_CTX *ctx);
- -

DESCRIPTION

- -

PKCS8_encrypt() and PKCS8_encrypt_ex() perform encryption of an object p8 using the password pass of length passlen, salt salt of length saltlen and iteration count iter. The resulting X509_SIG contains the encoded algorithm parameters and encrypted key.

- -

PKCS8_decrypt() and PKCS8_decrypt_ex() perform decryption of an X509_SIG in p8 using the password pass of length passlen along with algorithm parameters obtained from the p8.

- -

PKCS8_set0_pbe() and PKCS8_set0_pbe_ex() perform encryption of the p8inf using the password pass of length passlen and parameters pbe.

- -

Functions ending in _ex() allow for a library context ctx and property query propq to be used to select algorithm implementations.

- -

RETURN VALUES

- -

PKCS8_encrypt(), PKCS8_encrypt_ex(), PKCS8_set0_pbe() and PKCS8_set0_pbe_ex() return an encrypted key in a X509_SIG structure or NULL if an error occurs.

- -

PKCS8_decrypt() and PKCS8_decrypt_ex() return a PKCS8_PRIV_KEY_INFO or NULL if an error occurs.

- -

CONFORMING TO

- -

IETF RFC 7292 (https://tools.ietf.org/html/rfc7292)

- -

SEE ALSO

- -

crypto(7)

- -

HISTORY

- -

PKCS8_decrypt_ex(), PKCS8_encrypt_ex() and PKCS8_set0_pbe_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/PKCS8_pkey_add1_attr.html b/openssl-install/share/doc/openssl/html/man3/PKCS8_pkey_add1_attr.html deleted file mode 100644 index 4f065fef..00000000 --- a/openssl-install/share/doc/openssl/html/man3/PKCS8_pkey_add1_attr.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -PKCS8_pkey_add1_attr - - - - - - - - - - -

NAME

- -

PKCS8_pkey_get0_attrs, PKCS8_pkey_add1_attr, PKCS8_pkey_add1_attr_by_NID, PKCS8_pkey_add1_attr_by_OBJ - PKCS8 attribute functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-const STACK_OF(X509_ATTRIBUTE) *
-PKCS8_pkey_get0_attrs(const PKCS8_PRIV_KEY_INFO *p8);
-int PKCS8_pkey_add1_attr(PKCS8_PRIV_KEY_INFO *p8, X509_ATTRIBUTE *attr);
-int PKCS8_pkey_add1_attr_by_NID(PKCS8_PRIV_KEY_INFO *p8, int nid, int type,
-                                const unsigned char *bytes, int len);
-int PKCS8_pkey_add1_attr_by_OBJ(PKCS8_PRIV_KEY_INFO *p8, const ASN1_OBJECT *obj,
-                               int type, const unsigned char *bytes, int len);
- -

DESCRIPTION

- -

PKCS8_pkey_get0_attrs() returns a const STACK of X509_ATTRIBUTE present in the passed const PKCS8_PRIV_KEY_INFO structure p8.

- -

PKCS8_pkey_add1_attr() adds a constructed X509_ATTRIBUTE attr to the existing PKCS8_PRIV_KEY_INFO structure p8.

- -

PKCS8_pkey_add1_attr_by_NID() and PKCS8_pkey_add1_attr_by_OBJ() construct a new X509_ATTRIBUTE from the passed arguments and add it to the existing PKCS8_PRIV_KEY_INFO structure p8.

- -

RETURN VALUES

- -

PKCS8_pkey_add1_attr(), PKCS8_pkey_add1_attr_by_NID(), and PKCS8_pkey_add1_attr_by_OBJ() return 1 for success and 0 for failure.

- -

NOTES

- -

STACK of X509_ATTRIBUTE is present in many X509-related structures and some of them have the corresponding set of similar functions.

- -

SEE ALSO

- -

crypto(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_add.html b/openssl-install/share/doc/openssl/html/man3/RAND_add.html deleted file mode 100644 index d816bf42..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_add.html +++ /dev/null @@ -1,92 +0,0 @@ - - - - -RAND_add - - - - - - - - - - -

NAME

- -

RAND_add, RAND_poll, RAND_seed, RAND_status, RAND_event, RAND_screen, RAND_keep_random_devices_open - add randomness to the PRNG or get its status

- -

SYNOPSIS

- -
#include <openssl/rand.h>
-
-int RAND_status(void);
-int RAND_poll();
-
-void RAND_add(const void *buf, int num, double randomness);
-void RAND_seed(const void *buf, int num);
-
-void RAND_keep_random_devices_open(int keep);
- -

The following functions have been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RAND_event(UINT iMsg, WPARAM wParam, LPARAM lParam);
-void RAND_screen(void);
- -

DESCRIPTION

- -

These functions can be used to seed the random generator and to check its seeded state. In general, manual (re-)seeding of the default OpenSSL random generator (RAND_OpenSSL(3)) is not necessary (but allowed), since it does (re-)seed itself automatically using trusted system entropy sources. This holds unless the default RAND_METHOD has been replaced or OpenSSL was built with automatic reseeding disabled, see RAND(7) for more details.

- -

RAND_status() indicates whether or not the random generator has been sufficiently seeded. If not, functions such as RAND_bytes(3) will fail.

- -

RAND_poll() uses the system's capabilities to seed the random generator using random input obtained from polling various trusted entropy sources. The default choice of the entropy source can be modified at build time, see RAND(7) for more details.

- -

RAND_add() mixes the num bytes at buf into the internal state of the random generator. This function will not normally be needed, as mentioned above. The randomness argument is an estimate of how much randomness is contained in buf, in bytes, and should be a number between zero and num. Details about sources of randomness and how to estimate their randomness can be found in the literature; for example [NIST SP 800-90B]. The content of buf cannot be recovered from subsequent random generator output. Applications that intend to save and restore random state in an external file should consider using RAND_load_file(3) instead.

- -

NOTE: In FIPS mode, random data provided by the application is not considered to be a trusted entropy source. It is mixed into the internal state of the RNG as additional data only and this does not count as a full reseed. For more details, see EVP_RAND(7).

- -

RAND_seed() is equivalent to RAND_add() with randomness set to num.

- -

RAND_keep_random_devices_open() is used to control file descriptor usage by the random seed sources. Some seed sources maintain open file descriptors by default, which allows such sources to operate in a chroot(2) jail without the associated device nodes being available. When the keep argument is zero, this call disables the retention of file descriptors. Conversely, a nonzero argument enables the retention of file descriptors. This function is usually called during initialization and it takes effect immediately. This capability only applies to the default provider.

- -

RAND_event() and RAND_screen() are equivalent to RAND_poll() and exist for compatibility reasons only. See HISTORY section below.

- -

RETURN VALUES

- -

RAND_status() returns 1 if the random generator has been seeded with enough data, 0 otherwise.

- -

RAND_poll() returns 1 if it generated seed data, 0 otherwise.

- -

RAND_event() returns RAND_status().

- -

The other functions do not return values.

- -

SEE ALSO

- -

RAND_bytes(3), RAND_egd(3), RAND_load_file(3), RAND(7) EVP_RAND(7)

- -

HISTORY

- -

RAND_event() and RAND_screen() were deprecated in OpenSSL 1.1.0 and should not be used.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_bytes.html b/openssl-install/share/doc/openssl/html/man3/RAND_bytes.html deleted file mode 100644 index cdce7401..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_bytes.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -RAND_bytes - - - - - - - - - - -

NAME

- -

RAND_bytes, RAND_priv_bytes, RAND_bytes_ex, RAND_priv_bytes_ex, RAND_pseudo_bytes - generate random data

- -

SYNOPSIS

- -
#include <openssl/rand.h>
-
-int RAND_bytes(unsigned char *buf, int num);
-int RAND_priv_bytes(unsigned char *buf, int num);
-
-int RAND_bytes_ex(OSSL_LIB_CTX *ctx, unsigned char *buf, size_t num,
-                  unsigned int strength);
-int RAND_priv_bytes_ex(OSSL_LIB_CTX *ctx, unsigned char *buf, size_t num,
-                       unsigned int strength);
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RAND_pseudo_bytes(unsigned char *buf, int num);
- -

DESCRIPTION

- -

RAND_bytes() generates num random bytes using a cryptographically secure pseudo random generator (CSPRNG) and stores them in buf.

- -

RAND_priv_bytes() has the same semantics as RAND_bytes(). It is intended to be used for generating values that should remain private. If using the default RAND_METHOD, this function uses a separate "private" PRNG instance so that a compromise of the "public" PRNG instance will not affect the secrecy of these private values, as described in RAND(7) and EVP_RAND(7).

- -

RAND_bytes_ex() and RAND_priv_bytes_ex() are the same as RAND_bytes() and RAND_priv_bytes() except that they both take additional strength and ctx parameters. The bytes generated will have a security strength of at least strength bits. The DRBG used for the operation is the public or private DRBG associated with the specified ctx. The parameter can be NULL, in which case the default library context is used (see OSSL_LIB_CTX(3). If the default RAND_METHOD has been changed then for compatibility reasons the RAND_METHOD will be used in preference and the DRBG of the library context ignored.

- -

NOTES

- -

By default, the OpenSSL CSPRNG supports a security level of 256 bits, provided it was able to seed itself from a trusted entropy source. On all major platforms supported by OpenSSL (including the Unix-like platforms and Windows), OpenSSL is configured to automatically seed the CSPRNG on first use using the operating systems's random generator.

- -

If the entropy source fails or is not available, the CSPRNG will enter an error state and refuse to generate random bytes. For that reason, it is important to always check the error return value of RAND_bytes() and RAND_priv_bytes() and not take randomness for granted.

- -

On other platforms, there might not be a trusted entropy source available or OpenSSL might have been explicitly configured to use different entropy sources. If you are in doubt about the quality of the entropy source, don't hesitate to ask your operating system vendor or post a question on GitHub or the openssl-users mailing list.

- -

RETURN VALUES

- -

RAND_bytes() and RAND_priv_bytes() return 1 on success, -1 if not supported by the current RAND method, or 0 on other failure. The error code can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

RAND_add(3), RAND_bytes(3), RAND_priv_bytes(3), ERR_get_error(3), RAND(7), EVP_RAND(7)

- -

HISTORY

- - - -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_cleanup.html b/openssl-install/share/doc/openssl/html/man3/RAND_cleanup.html deleted file mode 100644 index 5e993d4c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_cleanup.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -RAND_cleanup - - - - - - - - - - -

NAME

- -

RAND_cleanup - erase the PRNG state

- -

SYNOPSIS

- -
#include <openssl/rand.h>
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void RAND_cleanup(void);
- -

DESCRIPTION

- -

Prior to OpenSSL 1.1.0, RAND_cleanup() released all resources used by the PRNG. As of version 1.1.0, it does nothing and should not be called, since no explicit initialisation or de-initialisation is necessary. See OPENSSL_init_crypto(3).

- -

RETURN VALUES

- -

RAND_cleanup() returns no value.

- -

SEE ALSO

- -

RAND(7)

- -

HISTORY

- -

RAND_cleanup() was deprecated in OpenSSL 1.1.0; do not use it. See OPENSSL_init_crypto(3)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_egd.html b/openssl-install/share/doc/openssl/html/man3/RAND_egd.html deleted file mode 100644 index b817521a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_egd.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -RAND_egd - - - - - - - - - - -

NAME

- -

RAND_egd, RAND_egd_bytes, RAND_query_egd_bytes - query entropy gathering daemon

- -

SYNOPSIS

- -
#include <openssl/rand.h>
-
-int RAND_egd_bytes(const char *path, int num);
-int RAND_egd(const char *path);
-
-int RAND_query_egd_bytes(const char *path, unsigned char *buf, int num);
- -

DESCRIPTION

- -

On older platforms without a good source of randomness such as /dev/urandom, it is possible to query an Entropy Gathering Daemon (EGD) over a local socket to obtain randomness and seed the OpenSSL RNG. The protocol used is defined by the EGDs available at http://egd.sourceforge.net/ or http://prngd.sourceforge.net.

- -

RAND_egd_bytes() requests num bytes of randomness from an EGD at the specified socket path, and passes the data it receives into RAND_add(). RAND_egd() is equivalent to RAND_egd_bytes() with num set to 255.

- -

RAND_query_egd_bytes() requests num bytes of randomness from an EGD at the specified socket path, where num must be less than 256. If buf is NULL, it is equivalent to RAND_egd_bytes(). If buf is not NULL, then the data is copied to the buffer and RAND_add() is not called.

- -

OpenSSL can be configured at build time to try to use the EGD for seeding automatically.

- -

RETURN VALUES

- -

RAND_egd() and RAND_egd_bytes() return the number of bytes read from the daemon on success, or -1 if the connection failed or the daemon did not return enough data to fully seed the PRNG.

- -

RAND_query_egd_bytes() returns the number of bytes read from the daemon on success, or -1 if the connection failed.

- -

SEE ALSO

- -

RAND_add(3), RAND_bytes(3), RAND(7)

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_get0_primary.html b/openssl-install/share/doc/openssl/html/man3/RAND_get0_primary.html deleted file mode 100644 index d325434d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_get0_primary.html +++ /dev/null @@ -1,92 +0,0 @@ - - - - -RAND_get0_primary - - - - - - - - - - -

NAME

- -

RAND_get0_primary, RAND_get0_public, RAND_get0_private, RAND_set0_public, RAND_set0_private - get access to the global EVP_RAND_CTX instances

- -

SYNOPSIS

- -
#include <openssl/rand.h>
-
-EVP_RAND_CTX *RAND_get0_primary(OSSL_LIB_CTX *ctx);
-EVP_RAND_CTX *RAND_get0_public(OSSL_LIB_CTX *ctx);
-EVP_RAND_CTX *RAND_get0_private(OSSL_LIB_CTX *ctx);
-int RAND_set0_public(OSSL_LIB_CTX *ctx, EVP_RAND_CTX *rand);
-int RAND_set0_private(OSSL_LIB_CTX *ctx, EVP_RAND_CTX *rand);
- -

DESCRIPTION

- -

The default RAND API implementation (RAND_OpenSSL()) utilizes three shared DRBG instances which are accessed via the RAND API:

- -

The public and private DRBG are thread-local instances, which are used by RAND_bytes() and RAND_priv_bytes(), respectively. The primary DRBG is a global instance, which is not intended to be used directly, but is used internally to reseed the other two instances.

- -

The three get functions provide access to the shared DRBG instances.

- -

The two set functions allow the public and private DRBG instances to be replaced by another random number generator.

- -

RETURN VALUES

- -

RAND_get0_primary() returns a pointer to the primary DRBG instance for the given OSSL_LIB_CTX ctx.

- -

RAND_get0_public() returns a pointer to the public DRBG instance for the given OSSL_LIB_CTX ctx.

- -

RAND_get0_private() returns a pointer to the private DRBG instance for the given OSSL_LIB_CTX ctx.

- -

RAND_set0_public() and RAND_set0_private() return 1 on success and 0 on error.

- -

NOTES

- -

It is not thread-safe to access the primary DRBG instance. The public and private DRBG instance can be accessed safely, because they are thread-local. Note however, that changes to these two instances apply only to the current thread.

- -

For that reason it is recommended not to change the settings of these three instances directly. Instead, an application should change the default settings for new DRBG instances at initialization time, before creating additional threads.

- -

During initialization, it is possible to change the reseed interval and reseed time interval. It is also possible to exchange the reseeding callbacks entirely.

- -

To set the type of DRBG that will be instantiated, use the RAND_set_DRBG_type(3) call before accessing the random number generation infrastructure.

- -

The two set functions, operate on the current thread. If you want to use the same random number generator across all threads, each thread must individually call the set functions.

- -

SEE ALSO

- -

EVP_RAND(3), RAND_set_DRBG_type(3)

- -

HISTORY

- -

RAND_set0_public() and RAND_set0_private() were added in OpenSSL 3.1.

- -

The remaining functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_load_file.html b/openssl-install/share/doc/openssl/html/man3/RAND_load_file.html deleted file mode 100644 index 1cd04431..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_load_file.html +++ /dev/null @@ -1,94 +0,0 @@ - - - - -RAND_load_file - - - - - - - - - - -

NAME

- -

RAND_load_file, RAND_write_file, RAND_file_name - PRNG seed file

- -

SYNOPSIS

- -
#include <openssl/rand.h>
-
-int RAND_load_file(const char *filename, long max_bytes);
-
-int RAND_write_file(const char *filename);
-
-const char *RAND_file_name(char *buf, size_t num);
- -

DESCRIPTION

- -

RAND_load_file() reads a number of bytes from file filename and adds them to the PRNG. If max_bytes is nonnegative, up to max_bytes are read; if max_bytes is -1, the complete file is read. Do not load the same file multiple times unless its contents have been updated by RAND_write_file() between reads. Also, note that filename should be adequately protected so that an attacker cannot replace or examine the contents. If filename is not a regular file, then user is considered to be responsible for any side effects, e.g. non-anticipated blocking or capture of controlling terminal.

- -

RAND_write_file() writes a number of random bytes (currently 128) to file filename which can be used to initialize the PRNG by calling RAND_load_file() in a later session.

- -

RAND_file_name() generates a default path for the random seed file. buf points to a buffer of size num in which to store the filename.

- -

On all systems, if the environment variable RANDFILE is set, its value will be used as the seed filename. Otherwise, the file is called .rnd, found in platform dependent locations:

- -
- -
On Windows (in order of preference)
-
- -
%HOME%, %USERPROFILE%, %SYSTEMROOT%, C:\
- -
-
On VMS
-
- -
SYS$LOGIN:
- -
-
On all other systems
-
- -
$HOME
- -
-
- -

If $HOME (on non-Windows and non-VMS system) is not set either, or num is too small for the pathname, an error occurs.

- -

RETURN VALUES

- -

RAND_load_file() returns the number of bytes read or -1 on error.

- -

RAND_write_file() returns the number of bytes written, or -1 if the bytes written were generated without appropriate seeding.

- -

RAND_file_name() returns a pointer to buf on success, and NULL on error.

- -

SEE ALSO

- -

RAND_add(3), RAND_bytes(3), RAND(7)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_set_DRBG_type.html b/openssl-install/share/doc/openssl/html/man3/RAND_set_DRBG_type.html deleted file mode 100644 index 911ea1bb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_set_DRBG_type.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -RAND_set_DRBG_type - - - - - - - - - - -

NAME

- -

RAND_set_DRBG_type, RAND_set_seed_source_type - specify the global random number generator types

- -

SYNOPSIS

- -
#include <openssl/rand.h>
-
-int RAND_set_DRBG_type(OSSL_LIB_CTX *ctx, const char *drbg, const char *propq,
-                       const char *cipher, const char *digest);
-int RAND_set_seed_source_type(OSSL_LIB_CTX *ctx, const char *seed,
-                              const char *propq);
- -

DESCRIPTION

- -

RAND_set_DRBG_type() specifies the random bit generator that will be used within the library context ctx. A generator of name drbg with properties propq will be fetched. It will be instantiated with either cipher or digest as its underlying cryptographic algorithm. This specifies the type that will be used for the primary, public and private random instances.

- -

RAND_set_seed_source_type() specifies the seed source that will be used within the library context ctx. The seed source of name seed with properties propq will be fetched and used to seed the primary random bit generator.

- -

RETURN VALUES

- -

These function return 1 on success and 0 on failure.

- -

NOTES

- -

These functions must be called before the random bit generators are first created in the library context. They will return an error if the call is made too late.

- -

The default DRBG is "CTR-DRBG" using the "AES-256-CTR" cipher.

- -

The default seed source can be configured when OpenSSL is compiled by setting -DOPENSSL_DEFAULT_SEED_SRC=SEED-SRC. If not set then "SEED-SRC" is used.

- -

EXAMPLES

- -
unsigned char bytes[100];
-RAND_set_seed_source_type(NULL, "JITTER", NULL);
-RAND_bytes(bytes, 100);
- -

SEE ALSO

- -

EVP_RAND(3), RAND_get0_primary(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RAND_set_rand_method.html b/openssl-install/share/doc/openssl/html/man3/RAND_set_rand_method.html deleted file mode 100644 index 7dd273d2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RAND_set_rand_method.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -RAND_set_rand_method - - - - - - - - - - -

NAME

- -

RAND_set_rand_method, RAND_get_rand_method, RAND_OpenSSL - select RAND method

- -

SYNOPSIS

- -
#include <openssl/rand.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
RAND_METHOD *RAND_OpenSSL(void);
-
-int RAND_set_rand_method(const RAND_METHOD *meth);
-
-const RAND_METHOD *RAND_get_rand_method(void);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use RAND_set_DRBG_type(3), EVP_RAND(3) and EVP_RAND(7).

- -

A RAND_METHOD specifies the functions that OpenSSL uses for random number generation.

- -

RAND_OpenSSL() returns the default RAND_METHOD implementation by OpenSSL. This implementation ensures that the PRNG state is unique for each thread.

- -

If an ENGINE is loaded that provides the RAND API, however, it will be used instead of the method returned by RAND_OpenSSL(). This is deprecated in OpenSSL 3.0.

- -

RAND_set_rand_method() makes meth the method for PRNG use. If an ENGINE was providing the method, it will be released first.

- -

RAND_get_rand_method() returns a pointer to the current RAND_METHOD.

- -

THE RAND_METHOD STRUCTURE

- -
typedef struct rand_meth_st {
-    int (*seed)(const void *buf, int num);
-    int (*bytes)(unsigned char *buf, int num);
-    void (*cleanup)(void);
-    int (*add)(const void *buf, int num, double entropy);
-    int (*pseudorand)(unsigned char *buf, int num);
-    int (*status)(void);
-} RAND_METHOD;
- -

The fields point to functions that are used by, in order, RAND_seed(), RAND_bytes(), internal RAND cleanup, RAND_add(), RAND_pseudo_rand() and RAND_status(). Each pointer may be NULL if the function is not implemented.

- -

RETURN VALUES

- -

RAND_set_rand_method() returns 1 on success and 0 on failure. RAND_get_rand_method() and RAND_OpenSSL() return pointers to the respective methods.

- -

SEE ALSO

- -

EVP_RAND(3), RAND_set_DRBG_type(3), RAND_bytes(3), ENGINE_by_id(3), EVP_RAND(7), RAND(7)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RC4_set_key.html b/openssl-install/share/doc/openssl/html/man3/RC4_set_key.html deleted file mode 100644 index 20eb2cf2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RC4_set_key.html +++ /dev/null @@ -1,85 +0,0 @@ - - - - -RC4_set_key - - - - - - - - - - -

NAME

- -

RC4_set_key, RC4 - RC4 encryption

- -

SYNOPSIS

- -
#include <openssl/rc4.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void RC4_set_key(RC4_KEY *key, int len, const unsigned char *data);
-
-void RC4(RC4_KEY *key, unsigned long len, const unsigned char *indata,
-         unsigned char *outdata);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_EncryptInit_ex(3), EVP_EncryptUpdate(3) and EVP_EncryptFinal_ex(3) or the equivalently named decrypt functions.

- -

This library implements the Alleged RC4 cipher, which is described for example in Applied Cryptography. It is believed to be compatible with RC4[TM], a proprietary cipher of RSA Security Inc.

- -

RC4 is a stream cipher with variable key length. Typically, 128 bit (16 byte) keys are used for strong encryption, but shorter insecure key sizes have been widely used due to export restrictions.

- -

RC4 consists of a key setup phase and the actual encryption or decryption phase.

- -

RC4_set_key() sets up the RC4_KEY key using the len bytes long key at data.

- -

RC4() encrypts or decrypts the len bytes of data at indata using key and places the result at outdata. Repeated RC4() calls with the same key yield a continuous key stream.

- -

Since RC4 is a stream cipher (the input is XORed with a pseudo-random key stream to produce the output), decryption uses the same function calls as encryption.

- -

RETURN VALUES

- -

RC4_set_key() and RC4() do not return values.

- -

NOTE

- -

Applications should use the higher level functions EVP_EncryptInit(3) etc. instead of calling these functions directly.

- -

It is difficult to securely use stream ciphers. For example, do not perform multiple encryptions using the same key stream.

- -

SEE ALSO

- -

EVP_EncryptInit(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RIPEMD160_Init.html b/openssl-install/share/doc/openssl/html/man3/RIPEMD160_Init.html deleted file mode 100644 index 2901e2b5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RIPEMD160_Init.html +++ /dev/null @@ -1,92 +0,0 @@ - - - - -RIPEMD160_Init - - - - - - - - - - -

NAME

- -

RIPEMD160, RIPEMD160_Init, RIPEMD160_Update, RIPEMD160_Final - RIPEMD-160 hash function

- -

SYNOPSIS

- -
#include <openssl/ripemd.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
unsigned char *RIPEMD160(const unsigned char *d, unsigned long n,
-                         unsigned char *md);
-
-int RIPEMD160_Init(RIPEMD160_CTX *c);
-int RIPEMD160_Update(RIPEMD160_CTX *c, const void *data, unsigned long len);
-int RIPEMD160_Final(unsigned char *md, RIPEMD160_CTX *c);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_DigestInit_ex(3), EVP_DigestUpdate(3) and EVP_DigestFinal_ex(3).

- -

RIPEMD-160 is a cryptographic hash function with a 160 bit output.

- -

RIPEMD160() computes the RIPEMD-160 message digest of the n bytes at d and places it in md (which must have space for RIPEMD160_DIGEST_LENGTH == 20 bytes of output). If md is NULL, the digest is placed in a static array.

- -

The following functions may be used if the message is not completely stored in memory:

- -

RIPEMD160_Init() initializes a RIPEMD160_CTX structure.

- -

RIPEMD160_Update() can be called repeatedly with chunks of the message to be hashed (len bytes at data).

- -

RIPEMD160_Final() places the message digest in md, which must have space for RIPEMD160_DIGEST_LENGTH == 20 bytes of output, and erases the RIPEMD160_CTX.

- -

RETURN VALUES

- -

RIPEMD160() returns a pointer to the hash value.

- -

RIPEMD160_Init(), RIPEMD160_Update() and RIPEMD160_Final() return 1 for success, 0 otherwise.

- -

NOTE

- -

Applications should use the higher level functions EVP_DigestInit(3) etc. instead of calling these functions directly.

- -

CONFORMING TO

- -

ISO/IEC 10118-3:2016 Dedicated Hash-Function 1 (RIPEMD-160).

- -

SEE ALSO

- -

EVP_DigestInit(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_blinding_on.html b/openssl-install/share/doc/openssl/html/man3/RSA_blinding_on.html deleted file mode 100644 index 5c9cc165..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_blinding_on.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -RSA_blinding_on - - - - - - - - - - -

NAME

- -

RSA_blinding_on, RSA_blinding_off - protect the RSA operation from timing attacks

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_blinding_on(RSA *rsa, BN_CTX *ctx);
-
-void RSA_blinding_off(RSA *rsa);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated.

- -

RSA is vulnerable to timing attacks. In a setup where attackers can measure the time of RSA decryption or signature operations, blinding must be used to protect the RSA operation from that attack.

- -

RSA_blinding_on() turns blinding on for key rsa and generates a random blinding factor. ctx is NULL or a preallocated and initialized BN_CTX.

- -

RSA_blinding_off() turns blinding off and frees the memory used for the blinding factor.

- -

RETURN VALUES

- -

RSA_blinding_on() returns 1 on success, and 0 if an error occurred.

- -

RSA_blinding_off() returns no value.

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_check_key.html b/openssl-install/share/doc/openssl/html/man3/RSA_check_key.html deleted file mode 100644 index eb2f418b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_check_key.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -RSA_check_key - - - - - - - - - - -

NAME

- -

RSA_check_key_ex, RSA_check_key - validate private RSA keys

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_check_key_ex(const RSA *rsa, BN_GENCB *cb);
-
-int RSA_check_key(const RSA *rsa);
- -

DESCRIPTION

- -

Both of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_public_check(3), EVP_PKEY_private_check(3) and EVP_PKEY_pairwise_check(3).

- -

RSA_check_key_ex() function validates RSA keys. It checks that p and q are in fact prime, and that n = p*q.

- -

It does not work on RSA public keys that have only the modulus and public exponent elements populated. It also checks that d*e = 1 mod (p-1*q-1), and that dmp1, dmq1 and iqmp are set correctly or are NULL. It performs integrity checks on all the RSA key material, so the RSA key structure must contain all the private key data too. Therefore, it cannot be used with any arbitrary RSA key object, even if it is otherwise fit for regular RSA operation.

- -

The cb parameter is a callback that will be invoked in the same manner as BN_is_prime_ex(3).

- -

RSA_check_key() is equivalent to RSA_check_key_ex() with a NULL cb.

- -

RETURN VALUES

- -

RSA_check_key_ex() and RSA_check_key() return 1 if rsa is a valid RSA key, and 0 otherwise. They return -1 if an error occurs while checking the key.

- -

If the key is invalid or an error occurred, the reason code can be obtained using ERR_get_error(3).

- -

NOTES

- -

Unlike most other RSA functions, this function does not work transparently with any underlying ENGINE implementation because it uses the key data in the RSA structure directly. An ENGINE implementation can override the way key data is stored and handled, and can even provide support for HSM keys - in which case the RSA structure may contain no key data at all! If the ENGINE in question is only being used for acceleration or analysis purposes, then in all likelihood the RSA key data is complete and untouched, but this can't be assumed in the general case.

- -

BUGS

- -

A method of verifying the RSA key using opaque RSA API functions might need to be considered. Right now RSA_check_key() simply uses the RSA structure elements directly, bypassing the RSA_METHOD table altogether (and completely violating encapsulation and object-orientation in the process). The best fix will probably be to introduce a "check_key()" handler to the RSA_METHOD function table so that alternative implementations can also provide their own verifiers.

- -

SEE ALSO

- -

BN_is_prime_ex(3), ERR_get_error(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

RSA_check_key_ex() appeared after OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_generate_key.html b/openssl-install/share/doc/openssl/html/man3/RSA_generate_key.html deleted file mode 100644 index 0cd335ab..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_generate_key.html +++ /dev/null @@ -1,113 +0,0 @@ - - - - -RSA_generate_key - - - - - - - - - - -

NAME

- -

EVP_RSA_gen, RSA_generate_key_ex, RSA_generate_key, RSA_generate_multi_prime_key - generate RSA key pair

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
-
-EVP_PKEY *EVP_RSA_gen(unsigned int bits);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_generate_key_ex(RSA *rsa, int bits, BIGNUM *e, BN_GENCB *cb);
-int RSA_generate_multi_prime_key(RSA *rsa, int bits, int primes, BIGNUM *e, BN_GENCB *cb);
- -

The following function has been deprecated since OpenSSL 0.9.8, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
RSA *RSA_generate_key(int bits, unsigned long e,
-                      void (*callback)(int, int, void *), void *cb_arg);
- -

DESCRIPTION

- -

EVP_RSA_gen() generates a new RSA key pair with modulus size bits.

- -

All of the functions described below are deprecated. Applications should instead use EVP_RSA_gen(), EVP_PKEY_Q_keygen(3), or EVP_PKEY_keygen_init(3) and EVP_PKEY_keygen(3).

- -

RSA_generate_key_ex() generates a 2-prime RSA key pair and stores it in the RSA structure provided in rsa.

- -

RSA_generate_multi_prime_key() generates a multi-prime RSA key pair and stores it in the RSA structure provided in rsa. The number of primes is given by the primes parameter. If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

The modulus size will be of length bits, the number of primes to form the modulus will be primes, and the public exponent will be e. Key sizes with num < 1024 should be considered insecure. The exponent is an odd number, typically 3, 17 or 65537.

- -

In order to maintain adequate security level, the maximum number of permitted primes depends on modulus bit length:

- -
<1024 | >=1024 | >=4096 | >=8192
-------+--------+--------+-------
-  2   |   3    |   4    |   5
- -

A callback function may be used to provide feedback about the progress of the key generation. If cb is not NULL, it will be called as follows using the BN_GENCB_call() function described on the BN_generate_prime(3) page.

- -

RSA_generate_key() is similar to RSA_generate_key_ex() but expects an old-style callback function; see BN_generate_prime(3) for information on the old-style callback.

- - - -

The process is then repeated for prime q and other primes (if any) with BN_GENCB_call(cb, 3, i) where i indicates the i-th prime.

- -

RETURN VALUES

- -

EVP_RSA_gen() returns an EVP_PKEY or NULL on failure.

- -

RSA_generate_multi_prime_key() returns 1 on success or 0 on error. RSA_generate_key_ex() returns 1 on success or 0 on error. The error codes can be obtained by ERR_get_error(3).

- -

RSA_generate_key() returns a pointer to the RSA structure or NULL if the key generation fails.

- -

BUGS

- -

BN_GENCB_call(cb, 2, x) is used with two different meanings.

- -

SEE ALSO

- -

EVP_PKEY_Q_keygen(3) BN_generate_prime(3), ERR_get_error(3), RAND_bytes(3), RAND(7)

- -

HISTORY

- -

EVP_RSA_gen() was added in OpenSSL 3.0. All other functions described here were deprecated in OpenSSL 3.0. For replacement see EVP_PKEY-RSA(7).

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_get0_key.html b/openssl-install/share/doc/openssl/html/man3/RSA_get0_key.html deleted file mode 100644 index 8ec3fb02..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_get0_key.html +++ /dev/null @@ -1,144 +0,0 @@ - - - - -RSA_get0_key - - - - - - - - - - -

NAME

- -

RSA_set0_key, RSA_set0_factors, RSA_set0_crt_params, RSA_get0_key, RSA_get0_factors, RSA_get0_crt_params, RSA_get0_n, RSA_get0_e, RSA_get0_d, RSA_get0_p, RSA_get0_q, RSA_get0_dmp1, RSA_get0_dmq1, RSA_get0_iqmp, RSA_get0_pss_params, RSA_clear_flags, RSA_test_flags, RSA_set_flags, RSA_get0_engine, RSA_get_multi_prime_extra_count, RSA_get0_multi_prime_factors, RSA_get0_multi_prime_crt_params, RSA_set0_multi_prime_params, RSA_get_version - Routines for getting and setting data in an RSA object

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_set0_key(RSA *r, BIGNUM *n, BIGNUM *e, BIGNUM *d);
-int RSA_set0_factors(RSA *r, BIGNUM *p, BIGNUM *q);
-int RSA_set0_crt_params(RSA *r, BIGNUM *dmp1, BIGNUM *dmq1, BIGNUM *iqmp);
-void RSA_get0_key(const RSA *r,
-                  const BIGNUM **n, const BIGNUM **e, const BIGNUM **d);
-void RSA_get0_factors(const RSA *r, const BIGNUM **p, const BIGNUM **q);
-void RSA_get0_crt_params(const RSA *r,
-                         const BIGNUM **dmp1, const BIGNUM **dmq1,
-                         const BIGNUM **iqmp);
-const BIGNUM *RSA_get0_n(const RSA *d);
-const BIGNUM *RSA_get0_e(const RSA *d);
-const BIGNUM *RSA_get0_d(const RSA *d);
-const BIGNUM *RSA_get0_p(const RSA *d);
-const BIGNUM *RSA_get0_q(const RSA *d);
-const BIGNUM *RSA_get0_dmp1(const RSA *r);
-const BIGNUM *RSA_get0_dmq1(const RSA *r);
-const BIGNUM *RSA_get0_iqmp(const RSA *r);
-const RSA_PSS_PARAMS *RSA_get0_pss_params(const RSA *r);
-void RSA_clear_flags(RSA *r, int flags);
-int RSA_test_flags(const RSA *r, int flags);
-void RSA_set_flags(RSA *r, int flags);
-ENGINE *RSA_get0_engine(RSA *r);
-int RSA_get_multi_prime_extra_count(const RSA *r);
-int RSA_get0_multi_prime_factors(const RSA *r, const BIGNUM *primes[]);
-int RSA_get0_multi_prime_crt_params(const RSA *r, const BIGNUM *exps[],
-                                    const BIGNUM *coeffs[]);
-int RSA_set0_multi_prime_params(RSA *r, BIGNUM *primes[], BIGNUM *exps[],
-                               BIGNUM *coeffs[], int pnum);
-int RSA_get_version(RSA *r);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_get_bn_param(3) for any methods that return a BIGNUM. Refer to EVP_PKEY-DH(7) for more information.

- -

An RSA object contains the components for the public and private key, n, e, d, p, q, dmp1, dmq1 and iqmp. n is the modulus common to both public and private key, e is the public exponent and d is the private exponent. p, q, dmp1, dmq1 and iqmp are the factors for the second representation of a private key (see PKCS#1 section 3 Key Types), where p and q are the first and second factor of n and dmp1, dmq1 and iqmp are the exponents and coefficient for CRT calculations.

- -

For multi-prime RSA (defined in RFC 8017), there are also one or more 'triplet' in an RSA object. A triplet contains three members, r, d and t. r is the additional prime besides p and q. d and t are the exponent and coefficient for CRT calculations.

- -

The n, e and d parameters can be obtained by calling RSA_get0_key(). If they have not been set yet, then *n, *e and *d will be set to NULL. Otherwise, they are set to pointers to their respective values. These point directly to the internal representations of the values and therefore should not be freed by the caller.

- -

The n, e and d parameter values can be set by calling RSA_set0_key() and passing the new values for n, e and d as parameters to the function. The values n and e must be non-NULL the first time this function is called on a given RSA object. The value d may be NULL. On subsequent calls any of these values may be NULL which means the corresponding RSA field is left untouched. Calling this function transfers the memory management of the values to the RSA object, and therefore the values that have been passed in should not be freed by the caller after this function has been called.

- -

In a similar fashion, the p and q parameters can be obtained and set with RSA_get0_factors() and RSA_set0_factors(), and the dmp1, dmq1 and iqmp parameters can be obtained and set with RSA_get0_crt_params() and RSA_set0_crt_params().

- -

For RSA_get0_key(), RSA_get0_factors(), and RSA_get0_crt_params(), NULL value BIGNUM ** output parameters are permitted. The functions ignore NULL parameters but return values for other, non-NULL, parameters.

- -

For multi-prime RSA, RSA_get0_multi_prime_factors() and RSA_get0_multi_prime_params() can be used to obtain other primes and related CRT parameters. The return values are stored in an array of BIGNUM *. RSA_set0_multi_prime_params() sets a collect of multi-prime 'triplet' members (prime, exponent and coefficient) into an RSA object.

- -

Any of the values n, e, d, p, q, dmp1, dmq1, and iqmp can also be retrieved separately by the corresponding function RSA_get0_n(), RSA_get0_e(), RSA_get0_d(), RSA_get0_p(), RSA_get0_q(), RSA_get0_dmp1(), RSA_get0_dmq1(), and RSA_get0_iqmp(), respectively.

- -

RSA_get0_pss_params() is used to retrieve the RSA-PSS parameters.

- -

RSA_set_flags() sets the flags in the flags parameter on the RSA object. Multiple flags can be passed in one go (bitwise ORed together). Any flags that are already set are left set. RSA_test_flags() tests to see whether the flags passed in the flags parameter are currently set in the RSA object. Multiple flags can be tested in one go. All flags that are currently set are returned, or zero if none of the flags are set. RSA_clear_flags() clears the specified flags within the RSA object.

- -

RSA_get0_engine() returns a handle to the ENGINE that has been set for this RSA object, or NULL if no such ENGINE has been set.

- -

RSA_get_version() returns the version of an RSA object r.

- -

NOTES

- -

Values retrieved with RSA_get0_key() are owned by the RSA object used in the call and may therefore not be passed to RSA_set0_key(). If needed, duplicate the received value using BN_dup() and pass the duplicate. The same applies to RSA_get0_factors() and RSA_set0_factors() as well as RSA_get0_crt_params() and RSA_set0_crt_params().

- -

The caller should obtain the size by calling RSA_get_multi_prime_extra_count() in advance and allocate sufficient buffer to store the return values before calling RSA_get0_multi_prime_factors() and RSA_get0_multi_prime_params().

- -

RSA_set0_multi_prime_params() always clears the original multi-prime triplets in RSA object r and assign the new set of triplets into it.

- -

RETURN VALUES

- -

RSA_set0_key(), RSA_set0_factors(), RSA_set0_crt_params() and RSA_set0_multi_prime_params() return 1 on success or 0 on failure.

- -

RSA_get0_n(), RSA_get0_e(), RSA_get0_d(), RSA_get0_p(), RSA_get0_q(), RSA_get0_dmp1(), RSA_get0_dmq1(), and RSA_get0_iqmp() return the respective value.

- -

RSA_get0_pss_params() returns a RSA_PSS_PARAMS pointer, or NULL if there is none.

- -

RSA_get0_multi_prime_factors() and RSA_get0_multi_prime_crt_params() return 1 on success or 0 on failure.

- -

RSA_get_multi_prime_extra_count() returns two less than the number of primes in use, which is 0 for traditional RSA and the number of extra primes for multi-prime RSA.

- -

RSA_get_version() returns RSA_ASN1_VERSION_MULTI for multi-prime RSA and RSA_ASN1_VERSION_DEFAULT for normal two-prime RSA, as defined in RFC 8017.

- -

RSA_test_flags() returns the current state of the flags in the RSA object.

- -

RSA_get0_engine() returns the ENGINE set for the RSA object or NULL if no ENGINE has been set.

- -

SEE ALSO

- -

RSA_new(3), RSA_size(3)

- -

HISTORY

- -

The RSA_get0_pss_params() function was added in OpenSSL 1.1.1e.

- -

The RSA_get_multi_prime_extra_count(), RSA_get0_multi_prime_factors(), RSA_get0_multi_prime_crt_params(), RSA_set0_multi_prime_params(), and RSA_get_version() functions were added in OpenSSL 1.1.1.

- -

Other functions described here were added in OpenSSL 1.1.0.

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_meth_new.html b/openssl-install/share/doc/openssl/html/man3/RSA_meth_new.html deleted file mode 100644 index d1e21a0a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_meth_new.html +++ /dev/null @@ -1,208 +0,0 @@ - - - - -RSA_meth_new - - - - - - - - - - -

NAME

- -

RSA_meth_get0_app_data, RSA_meth_set0_app_data, RSA_meth_new, RSA_meth_free, RSA_meth_dup, RSA_meth_get0_name, RSA_meth_set1_name, RSA_meth_get_flags, RSA_meth_set_flags, RSA_meth_get_pub_enc, RSA_meth_set_pub_enc, RSA_meth_get_pub_dec, RSA_meth_set_pub_dec, RSA_meth_get_priv_enc, RSA_meth_set_priv_enc, RSA_meth_get_priv_dec, RSA_meth_set_priv_dec, RSA_meth_get_mod_exp, RSA_meth_set_mod_exp, RSA_meth_get_bn_mod_exp, RSA_meth_set_bn_mod_exp, RSA_meth_get_init, RSA_meth_set_init, RSA_meth_get_finish, RSA_meth_set_finish, RSA_meth_get_sign, RSA_meth_set_sign, RSA_meth_get_verify, RSA_meth_set_verify, RSA_meth_get_keygen, RSA_meth_set_keygen, RSA_meth_get_multi_prime_keygen, RSA_meth_set_multi_prime_keygen - Routines to build up RSA methods

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
RSA_METHOD *RSA_meth_new(const char *name, int flags);
-void RSA_meth_free(RSA_METHOD *meth);
-
-RSA_METHOD *RSA_meth_dup(const RSA_METHOD *meth);
-
-const char *RSA_meth_get0_name(const RSA_METHOD *meth);
-int RSA_meth_set1_name(RSA_METHOD *meth, const char *name);
-
-int RSA_meth_get_flags(const RSA_METHOD *meth);
-int RSA_meth_set_flags(RSA_METHOD *meth, int flags);
-
-void *RSA_meth_get0_app_data(const RSA_METHOD *meth);
-int RSA_meth_set0_app_data(RSA_METHOD *meth, void *app_data);
-
-int (*RSA_meth_get_pub_enc(const RSA_METHOD *meth))(int flen, const unsigned char *from,
-                                                    unsigned char *to, RSA *rsa, int padding);
-int RSA_meth_set_pub_enc(RSA_METHOD *rsa,
-                         int (*pub_enc)(int flen, const unsigned char *from,
-                                        unsigned char *to, RSA *rsa,
-                                        int padding));
-
-int (*RSA_meth_get_pub_dec(const RSA_METHOD *meth))
-    (int flen, const unsigned char *from,
-     unsigned char *to, RSA *rsa, int padding);
-int RSA_meth_set_pub_dec(RSA_METHOD *rsa,
-                         int (*pub_dec)(int flen, const unsigned char *from,
-                                        unsigned char *to, RSA *rsa,
-                                        int padding));
-
-int (*RSA_meth_get_priv_enc(const RSA_METHOD *meth))(int flen, const unsigned char *from,
-                                                     unsigned char *to, RSA *rsa,
-                                                     int padding);
-int RSA_meth_set_priv_enc(RSA_METHOD *rsa,
-                          int (*priv_enc)(int flen, const unsigned char *from,
-                                          unsigned char *to, RSA *rsa, int padding));
-
-int (*RSA_meth_get_priv_dec(const RSA_METHOD *meth))(int flen, const unsigned char *from,
-                                                     unsigned char *to, RSA *rsa,
-                                                     int padding);
-int RSA_meth_set_priv_dec(RSA_METHOD *rsa,
-                          int (*priv_dec)(int flen, const unsigned char *from,
-                                          unsigned char *to, RSA *rsa, int padding));
-
-/* Can be null */
-int (*RSA_meth_get_mod_exp(const RSA_METHOD *meth))(BIGNUM *r0, const BIGNUM *i,
-                                                    RSA *rsa, BN_CTX *ctx);
-int RSA_meth_set_mod_exp(RSA_METHOD *rsa,
-                         int (*mod_exp)(BIGNUM *r0, const BIGNUM *i, RSA *rsa,
-                                        BN_CTX *ctx));
-
-/* Can be null */
-int (*RSA_meth_get_bn_mod_exp(const RSA_METHOD *meth))(BIGNUM *r, const BIGNUM *a,
-                                                       const BIGNUM *p, const BIGNUM *m,
-                                                       BN_CTX *ctx, BN_MONT_CTX *m_ctx);
-int RSA_meth_set_bn_mod_exp(RSA_METHOD *rsa,
-                            int (*bn_mod_exp)(BIGNUM *r, const BIGNUM *a,
-                                              const BIGNUM *p, const BIGNUM *m,
-                                              BN_CTX *ctx, BN_MONT_CTX *m_ctx));
-
-/* called at new */
-int (*RSA_meth_get_init(const RSA_METHOD *meth) (RSA *rsa);
-int RSA_meth_set_init(RSA_METHOD *rsa, int (*init (RSA *rsa));
-
-/* called at free */
-int (*RSA_meth_get_finish(const RSA_METHOD *meth))(RSA *rsa);
-int RSA_meth_set_finish(RSA_METHOD *rsa, int (*finish)(RSA *rsa));
-
-int (*RSA_meth_get_sign(const RSA_METHOD *meth))(int type, const unsigned char *m,
-                                                 unsigned int m_length,
-                                                 unsigned char *sigret,
-                                                 unsigned int *siglen, const RSA *rsa);
-int RSA_meth_set_sign(RSA_METHOD *rsa,
-                      int (*sign)(int type, const unsigned char *m,
-                                  unsigned int m_length, unsigned char *sigret,
-                                  unsigned int *siglen, const RSA *rsa));
-
-int (*RSA_meth_get_verify(const RSA_METHOD *meth))(int dtype, const unsigned char *m,
-                                                   unsigned int m_length,
-                                                   const unsigned char *sigbuf,
-                                                   unsigned int siglen, const RSA *rsa);
-int RSA_meth_set_verify(RSA_METHOD *rsa,
-                        int (*verify)(int dtype, const unsigned char *m,
-                                      unsigned int m_length,
-                                      const unsigned char *sigbuf,
-                                      unsigned int siglen, const RSA *rsa));
-
-int (*RSA_meth_get_keygen(const RSA_METHOD *meth))(RSA *rsa, int bits, BIGNUM *e,
-                                                   BN_GENCB *cb);
-int RSA_meth_set_keygen(RSA_METHOD *rsa,
-                        int (*keygen)(RSA *rsa, int bits, BIGNUM *e,
-                                      BN_GENCB *cb));
-
-int (*RSA_meth_get_multi_prime_keygen(const RSA_METHOD *meth))(RSA *rsa, int bits,
-                                                               int primes, BIGNUM *e,
-                                                               BN_GENCB *cb);
-
-int RSA_meth_set_multi_prime_keygen(RSA_METHOD *meth,
-                                    int (*keygen) (RSA *rsa, int bits,
-                                                   int primes, BIGNUM *e,
-                                                   BN_GENCB *cb));
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the OSSL_PROVIDER APIs.

- -

The RSA_METHOD type is a structure used for the provision of custom RSA implementations. It provides a set of functions used by OpenSSL for the implementation of the various RSA capabilities.

- -

RSA_meth_new() creates a new RSA_METHOD structure. It should be given a unique name and a set of flags. The name should be a NULL terminated string, which will be duplicated and stored in the RSA_METHOD object. It is the callers responsibility to free the original string. The flags will be used during the construction of a new RSA object based on this RSA_METHOD. Any new RSA object will have those flags set by default.

- -

RSA_meth_dup() creates a duplicate copy of the RSA_METHOD object passed as a parameter. This might be useful for creating a new RSA_METHOD based on an existing one, but with some differences.

- -

RSA_meth_free() destroys an RSA_METHOD structure and frees up any memory associated with it. If the argument is NULL, nothing is done.

- -

RSA_meth_get0_name() will return a pointer to the name of this RSA_METHOD. This is a pointer to the internal name string and so should not be freed by the caller. RSA_meth_set1_name() sets the name of the RSA_METHOD to name. The string is duplicated and the copy is stored in the RSA_METHOD structure, so the caller remains responsible for freeing the memory associated with the name.

- -

RSA_meth_get_flags() returns the current value of the flags associated with this RSA_METHOD. RSA_meth_set_flags() provides the ability to set these flags.

- -

The functions RSA_meth_get0_app_data() and RSA_meth_set0_app_data() provide the ability to associate implementation specific data with the RSA_METHOD. It is the application's responsibility to free this data before the RSA_METHOD is freed via a call to RSA_meth_free().

- -

RSA_meth_get_sign() and RSA_meth_set_sign() get and set the function used for creating an RSA signature respectively. This function will be called in response to the application calling RSA_sign(). The parameters for the function have the same meaning as for RSA_sign().

- -

RSA_meth_get_verify() and RSA_meth_set_verify() get and set the function used for verifying an RSA signature respectively. This function will be called in response to the application calling RSA_verify(). The parameters for the function have the same meaning as for RSA_verify().

- -

RSA_meth_get_mod_exp() and RSA_meth_set_mod_exp() get and set the function used for CRT computations.

- -

RSA_meth_get_bn_mod_exp() and RSA_meth_set_bn_mod_exp() get and set the function used for CRT computations, specifically the following value:

- -
r = a ^ p mod m
- -

Both the mod_exp() and bn_mod_exp() functions are called by the default OpenSSL method during encryption, decryption, signing and verification.

- -

RSA_meth_get_init() and RSA_meth_set_init() get and set the function used for creating a new RSA instance respectively. This function will be called in response to the application calling RSA_new() (if the current default RSA_METHOD is this one) or RSA_new_method(). The RSA_new() and RSA_new_method() functions will allocate the memory for the new RSA object, and a pointer to this newly allocated structure will be passed as a parameter to the function. This function may be NULL.

- -

RSA_meth_get_finish() and RSA_meth_set_finish() get and set the function used for destroying an instance of an RSA object respectively. This function will be called in response to the application calling RSA_free(). A pointer to the RSA to be destroyed is passed as a parameter. The destroy function should be used for RSA implementation specific clean up. The memory for the RSA itself should not be freed by this function. This function may be NULL.

- -

RSA_meth_get_keygen() and RSA_meth_set_keygen() get and set the function used for generating a new RSA key pair respectively. This function will be called in response to the application calling RSA_generate_key_ex(). The parameter for the function has the same meaning as for RSA_generate_key_ex().

- -

RSA_meth_get_multi_prime_keygen() and RSA_meth_set_multi_prime_keygen() get and set the function used for generating a new multi-prime RSA key pair respectively. This function will be called in response to the application calling RSA_generate_multi_prime_key(). The parameter for the function has the same meaning as for RSA_generate_multi_prime_key().

- -

RSA_meth_get_pub_enc(), RSA_meth_set_pub_enc(), RSA_meth_get_pub_dec(), RSA_meth_set_pub_dec(), RSA_meth_get_priv_enc(), RSA_meth_set_priv_enc(), RSA_meth_get_priv_dec(), RSA_meth_set_priv_dec() get and set the functions used for public and private key encryption and decryption. These functions will be called in response to the application calling RSA_public_encrypt(), RSA_private_decrypt(), RSA_private_encrypt() and RSA_public_decrypt() and take the same parameters as those.

- -

RETURN VALUES

- -

RSA_meth_new() and RSA_meth_dup() return the newly allocated RSA_METHOD object or NULL on failure.

- -

RSA_meth_get0_name() and RSA_meth_get_flags() return the name and flags associated with the RSA_METHOD respectively.

- -

All other RSA_meth_get_*() functions return the appropriate function pointer that has been set in the RSA_METHOD, or NULL if no such pointer has yet been set.

- -

RSA_meth_set1_name and all RSA_meth_set_*() functions return 1 on success or 0 on failure.

- -

SEE ALSO

- -

RSA_new(3), RSA_generate_key_ex(3), RSA_sign(3), RSA_set_method(3), RSA_size(3), RSA_get0_key(3), RSA_generate_multi_prime_key(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

RSA_meth_get_multi_prime_keygen() and RSA_meth_set_multi_prime_keygen() were added in OpenSSL 1.1.1.

- -

Other functions described here were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_new.html b/openssl-install/share/doc/openssl/html/man3/RSA_new.html deleted file mode 100644 index f17a31fd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_new.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -RSA_new - - - - - - - - - - -

NAME

- -

RSA_new, RSA_free - allocate and free RSA objects

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
RSA *RSA_new(void);
-
-void RSA_free(RSA *rsa);
- -

DESCRIPTION

- -

RSA_new() allocates and initializes an RSA structure. It is equivalent to calling RSA_new_method(NULL).

- -

RSA_free() frees the RSA structure and its components. The key is erased before the memory is returned to the system. If rsa is NULL nothing is done.

- -

RETURN VALUES

- -

If the allocation fails, RSA_new() returns NULL and sets an error code that can be obtained by ERR_get_error(3). Otherwise it returns a pointer to the newly allocated structure.

- -

RSA_free() returns no value.

- -

SEE ALSO

- -

ERR_get_error(3), RSA_generate_key(3), RSA_new_method(3)

- -

HISTORY

- -

All functions described here were deprecated in OpenSSL 3.0. For replacement see EVP_PKEY-RSA(7).

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_padding_add_PKCS1_type_1.html b/openssl-install/share/doc/openssl/html/man3/RSA_padding_add_PKCS1_type_1.html deleted file mode 100644 index cf1dce94..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_padding_add_PKCS1_type_1.html +++ /dev/null @@ -1,148 +0,0 @@ - - - - -RSA_padding_add_PKCS1_type_1 - - - - - - - - - - -

NAME

- -

RSA_padding_add_PKCS1_type_1, RSA_padding_check_PKCS1_type_1, RSA_padding_add_PKCS1_type_2, RSA_padding_check_PKCS1_type_2, RSA_padding_add_PKCS1_OAEP, RSA_padding_check_PKCS1_OAEP, RSA_padding_add_PKCS1_OAEP_mgf1, RSA_padding_check_PKCS1_OAEP_mgf1, RSA_padding_add_none, RSA_padding_check_none - asymmetric encryption padding

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_padding_add_PKCS1_type_1(unsigned char *to, int tlen,
-                                 const unsigned char *f, int fl);
-
-int RSA_padding_check_PKCS1_type_1(unsigned char *to, int tlen,
-                                   const unsigned char *f, int fl, int rsa_len);
-
-int RSA_padding_add_PKCS1_type_2(unsigned char *to, int tlen,
-                                 const unsigned char *f, int fl);
-
-int RSA_padding_check_PKCS1_type_2(unsigned char *to, int tlen,
-                                   const unsigned char *f, int fl, int rsa_len);
-
-int RSA_padding_add_PKCS1_OAEP(unsigned char *to, int tlen,
-                               const unsigned char *f, int fl,
-                               const unsigned char *p, int pl);
-
-int RSA_padding_check_PKCS1_OAEP(unsigned char *to, int tlen,
-                                 const unsigned char *f, int fl, int rsa_len,
-                                 const unsigned char *p, int pl);
-
-int RSA_padding_add_PKCS1_OAEP_mgf1(unsigned char *to, int tlen,
-                                    const unsigned char *f, int fl,
-                                    const unsigned char *p, int pl,
-                                    const EVP_MD *md, const EVP_MD *mgf1md);
-
-int RSA_padding_check_PKCS1_OAEP_mgf1(unsigned char *to, int tlen,
-                                      const unsigned char *f, int fl, int rsa_len,
-                                      const unsigned char *p, int pl,
-                                      const EVP_MD *md, const EVP_MD *mgf1md);
-
-int RSA_padding_add_none(unsigned char *to, int tlen,
-                         const unsigned char *f, int fl);
-
-int RSA_padding_check_none(unsigned char *to, int tlen,
-                           const unsigned char *f, int fl, int rsa_len);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the EVP PKEY APIs.

- -

The RSA_padding_xxx_xxx() functions are called from the RSA encrypt, decrypt, sign and verify functions. Normally they should not be called from application programs.

- -

However, they can also be called directly to implement padding for other asymmetric ciphers. RSA_padding_add_PKCS1_OAEP() and RSA_padding_check_PKCS1_OAEP() may be used in an application combined with RSA_NO_PADDING in order to implement OAEP with an encoding parameter.

- -

RSA_padding_add_xxx() encodes fl bytes from f so as to fit into tlen bytes and stores the result at to. An error occurs if fl does not meet the size requirements of the encoding method.

- -

The following encoding methods are implemented:

- -
- -
PKCS1_type_1
-
- -

PKCS #1 v2.0 EMSA-PKCS1-v1_5 (PKCS #1 v1.5 block type 1); used for signatures

- -
-
PKCS1_type_2
-
- -

PKCS #1 v2.0 EME-PKCS1-v1_5 (PKCS #1 v1.5 block type 2)

- -
-
PKCS1_OAEP
-
- -

PKCS #1 v2.0 EME-OAEP

- -
-
none
-
- -

simply copy the data

- -
-
- -

The random number generator must be seeded prior to calling RSA_padding_add_xxx(). If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

RSA_padding_check_xxx() verifies that the fl bytes at f contain a valid encoding for a rsa_len byte RSA key in the respective encoding method and stores the recovered data of at most tlen bytes (for RSA_NO_PADDING: of size tlen) at to.

- -

For RSA_padding_xxx_OAEP(), p points to the encoding parameter of length pl. p may be NULL if pl is 0.

- -

For RSA_padding_xxx_OAEP_mgf1(), md points to the md hash, if md is NULL that means md=sha1, and mgf1md points to the mgf1 hash, if mgf1md is NULL that means mgf1md=md.

- -

RETURN VALUES

- -

The RSA_padding_add_xxx() functions return 1 on success, 0 on error. The RSA_padding_check_xxx() functions return the length of the recovered data, -1 on error. Error codes can be obtained by calling ERR_get_error(3).

- -

WARNINGS

- -

The result of RSA_padding_check_PKCS1_type_2() is exactly the information which is used to mount a classical Bleichenbacher padding oracle attack. This is an inherent weakness in the PKCS #1 v1.5 padding design. Prefer PKCS1_OAEP padding. If that is not possible, the result of RSA_padding_check_PKCS1_type_2() should be checked in constant time if it matches the expected length of the plaintext and additionally some application specific consistency checks on the plaintext need to be performed in constant time. If the plaintext is rejected it must be kept secret which of the checks caused the application to reject the message. Do not remove the zero-padding from the decrypted raw RSA data which was computed by RSA_private_decrypt() with RSA_NO_PADDING, as this would create a small timing side channel which could be used to mount a Bleichenbacher attack against any padding mode including PKCS1_OAEP.

- -

You should prefer the use of EVP PKEY APIs for PKCS#1 v1.5 decryption as they implement the necessary workarounds internally.

- -

SEE ALSO

- -

RSA_public_encrypt(3), RSA_private_decrypt(3), RSA_sign(3), RSA_verify(3), RAND(7)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_print.html b/openssl-install/share/doc/openssl/html/man3/RSA_print.html deleted file mode 100644 index b880d5a0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_print.html +++ /dev/null @@ -1,88 +0,0 @@ - - - - -RSA_print - - - - - - - - - - -

NAME

- -

RSA_print, RSA_print_fp, DSAparams_print, DSAparams_print_fp, DSA_print, DSA_print_fp, DHparams_print, DHparams_print_fp - print cryptographic parameters

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_print(BIO *bp, const RSA *x, int offset);
-int RSA_print_fp(FILE *fp, const RSA *x, int offset);
-
-#include <openssl/dsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DSAparams_print(BIO *bp, const DSA *x);
-int DSAparams_print_fp(FILE *fp, const DSA *x);
-int DSA_print(BIO *bp, const DSA *x, int offset);
-int DSA_print_fp(FILE *fp, const DSA *x, int offset);
-
-#include <openssl/dh.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int DHparams_print(BIO *bp, DH *x);
-int DHparams_print_fp(FILE *fp, const DH *x);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_print_params(3) and EVP_PKEY_print_private(3).

- -

A human-readable hexadecimal output of the components of the RSA key, DSA parameters or key or DH parameters is printed to bp or fp.

- -

The output lines are indented by offset spaces.

- -

RETURN VALUES

- -

DSAparams_print(), DSAparams_print_fp(), DSA_print(), and DSA_print_fp() return 1 for success and 0 or a negative value for failure.

- -

DHparams_print() and DHparams_print_fp() return 1 on success, 0 on error.

- -

SEE ALSO

- -
L<EVP_PKEY_print_params(3)>,
-L<EVP_PKEY_print_private(3)>,
-L<BN_bn2bin(3)>
- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_private_encrypt.html b/openssl-install/share/doc/openssl/html/man3/RSA_private_encrypt.html deleted file mode 100644 index 51514bec..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_private_encrypt.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -RSA_private_encrypt - - - - - - - - - - -

NAME

- -

RSA_private_encrypt, RSA_public_decrypt - low-level signature operations

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_private_encrypt(int flen, unsigned char *from,
-                        unsigned char *to, RSA *rsa, int padding);
-
-int RSA_public_decrypt(int flen, unsigned char *from,
-                       unsigned char *to, RSA *rsa, int padding);
- -

DESCRIPTION

- -

Both of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_sign_init_ex(3), EVP_PKEY_sign(3), EVP_PKEY_verify_recover_init(3), and EVP_PKEY_verify_recover(3).

- -

These functions handle RSA signatures at a low-level.

- -

RSA_private_encrypt() signs the flen bytes at from (usually a message digest with an algorithm identifier) using the private key rsa and stores the signature in to. to must point to RSA_size(rsa) bytes of memory.

- -

padding denotes one of the following modes:

- -
- -
RSA_PKCS1_PADDING
-
- -

PKCS #1 v1.5 padding. This function does not handle the algorithmIdentifier specified in PKCS #1. When generating or verifying PKCS #1 signatures, RSA_sign(3) and RSA_verify(3) should be used.

- -
-
RSA_NO_PADDING
-
- -

Raw RSA signature. This mode should only be used to implement cryptographically sound padding modes in the application code. Signing user data directly with RSA is insecure.

- -
-
- -

RSA_public_decrypt() recovers the message digest from the flen bytes long signature at from using the signer's public key rsa. to must point to a memory section large enough to hold the message digest (which is smaller than RSA_size(rsa) - 11). padding is the padding mode that was used to sign the data.

- -

RETURN VALUES

- -

RSA_private_encrypt() returns the size of the signature (i.e., RSA_size(rsa)). RSA_public_decrypt() returns the size of the recovered message digest.

- -

On error, -1 is returned; the error codes can be obtained by ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), RSA_sign(3), RSA_verify(3), EVP_PKEY_sign(3), EVP_PKEY_verify_recover(3)

- -

HISTORY

- -

Both of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_public_encrypt.html b/openssl-install/share/doc/openssl/html/man3/RSA_public_encrypt.html deleted file mode 100644 index fa0a1e94..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_public_encrypt.html +++ /dev/null @@ -1,111 +0,0 @@ - - - - -RSA_public_encrypt - - - - - - - - - - -

NAME

- -

RSA_public_encrypt, RSA_private_decrypt - RSA public key cryptography

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_public_encrypt(int flen, const unsigned char *from,
-                       unsigned char *to, RSA *rsa, int padding);
-
-int RSA_private_decrypt(int flen, const unsigned char *from,
-                        unsigned char *to, RSA *rsa, int padding);
- -

DESCRIPTION

- -

Both of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_encrypt_init_ex(3), EVP_PKEY_encrypt(3), EVP_PKEY_decrypt_init_ex(3) and EVP_PKEY_decrypt(3).

- -

RSA_public_encrypt() encrypts the flen bytes at from (usually a session key) using the public key rsa and stores the ciphertext in to. to must point to RSA_size(rsa) bytes of memory.

- -

padding denotes one of the following modes:

- -
- -
RSA_PKCS1_PADDING
-
- -

PKCS #1 v1.5 padding. This currently is the most widely used mode. However, it is highly recommended to use RSA_PKCS1_OAEP_PADDING in new applications. SEE WARNING BELOW.

- -
-
RSA_PKCS1_OAEP_PADDING
-
- -

EME-OAEP as defined in PKCS #1 v2.0 with SHA-1, MGF1 and an empty encoding parameter. This mode is recommended for all new applications.

- -
-
RSA_NO_PADDING
-
- -

Raw RSA encryption. This mode should only be used to implement cryptographically sound padding modes in the application code. Encrypting user data directly with RSA is insecure.

- -
-
- -

When encrypting flen must not be more than RSA_size(rsa) - 11 for the PKCS #1 v1.5 based padding modes, not more than RSA_size(rsa) - 42 for RSA_PKCS1_OAEP_PADDING and exactly RSA_size(rsa) for RSA_NO_PADDING. When a padding mode other than RSA_NO_PADDING is in use, then RSA_public_encrypt() will include some random bytes into the ciphertext and therefore the ciphertext will be different each time, even if the plaintext and the public key are exactly identical. The returned ciphertext in to will always be zero padded to exactly RSA_size(rsa) bytes. to and from may overlap.

- -

RSA_private_decrypt() decrypts the flen bytes at from using the private key rsa and stores the plaintext in to. flen should be equal to RSA_size(rsa) but may be smaller, when leading zero bytes are in the ciphertext. Those are not important and may be removed, but RSA_public_encrypt() does not do that. to must point to a memory section large enough to hold the maximal possible decrypted data (which is equal to RSA_size(rsa) for RSA_NO_PADDING, RSA_size(rsa) - 11 for the PKCS #1 v1.5 based padding modes and RSA_size(rsa) - 42 for RSA_PKCS1_OAEP_PADDING). padding is the padding mode that was used to encrypt the data. to and from may overlap.

- -

RETURN VALUES

- -

RSA_public_encrypt() returns the size of the encrypted data (i.e., RSA_size(rsa)). RSA_private_decrypt() returns the size of the recovered plaintext. A return value of 0 is not an error and means only that the plaintext was empty.

- -

On error, -1 is returned; the error codes can be obtained by ERR_get_error(3).

- -

WARNINGS

- -

Decryption failures in the RSA_PKCS1_PADDING mode leak information which can potentially be used to mount a Bleichenbacher padding oracle attack. This is an inherent weakness in the PKCS #1 v1.5 padding design. Prefer RSA_PKCS1_OAEP_PADDING.

- -

In OpenSSL before version 3.2.0, both the return value and the length of returned value could be used to mount the Bleichenbacher attack. Since version 3.2.0, the default provider in OpenSSL does not return an error when padding checks fail. Instead it generates a random message based on used private key and provided ciphertext so that application code doesn't have to implement a side-channel secure error handling. Applications that want to be secure against side-channel attacks with providers that don't implement implicit rejection, still need to handle the returned values using side-channel free code. Side-channel free handling of the error stack can be performed using either a pair of unconditional ERR_set_mark(3) and ERR_pop_to_mark(3) calls or by using the ERR_clear_error(3) call.

- -

CONFORMING TO

- -

SSL, PKCS #1 v2.0

- -

SEE ALSO

- -

ERR_get_error(3), RAND_bytes(3), RSA_size(3), EVP_PKEY_decrypt(3), EVP_PKEY_encrypt(3)

- -

HISTORY

- -

Both of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_set_method.html b/openssl-install/share/doc/openssl/html/man3/RSA_set_method.html deleted file mode 100644 index cfa9d0ce..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_set_method.html +++ /dev/null @@ -1,167 +0,0 @@ - - - - -RSA_set_method - - - - - - - - - - -

NAME

- -

RSA_set_default_method, RSA_get_default_method, RSA_set_method, RSA_get_method, RSA_PKCS1_OpenSSL, RSA_flags, RSA_new_method - select RSA method

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void RSA_set_default_method(const RSA_METHOD *meth);
-
-const RSA_METHOD *RSA_get_default_method(void);
-
-int RSA_set_method(RSA *rsa, const RSA_METHOD *meth);
-
-const RSA_METHOD *RSA_get_method(const RSA *rsa);
-
-const RSA_METHOD *RSA_PKCS1_OpenSSL(void);
-
-int RSA_flags(const RSA *rsa);
-
-RSA *RSA_new_method(ENGINE *engine);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use the OSSL_PROVIDER APIs.

- -

An RSA_METHOD specifies the functions that OpenSSL uses for RSA operations. By modifying the method, alternative implementations such as hardware accelerators may be used. IMPORTANT: See the NOTES section for important information about how these RSA API functions are affected by the use of ENGINE API calls.

- -

Initially, the default RSA_METHOD is the OpenSSL internal implementation, as returned by RSA_PKCS1_OpenSSL().

- -

RSA_set_default_method() makes meth the default method for all RSA structures created later. NB: This is true only whilst no ENGINE has been set as a default for RSA, so this function is no longer recommended. This function is not thread-safe and should not be called at the same time as other OpenSSL functions.

- -

RSA_get_default_method() returns a pointer to the current default RSA_METHOD. However, the meaningfulness of this result is dependent on whether the ENGINE API is being used, so this function is no longer recommended.

- -

RSA_set_method() selects meth to perform all operations using the key rsa. This will replace the RSA_METHOD used by the RSA key and if the previous method was supplied by an ENGINE, the handle to that ENGINE will be released during the change. It is possible to have RSA keys that only work with certain RSA_METHOD implementations (e.g. from an ENGINE module that supports embedded hardware-protected keys), and in such cases attempting to change the RSA_METHOD for the key can have unexpected results.

- -

RSA_get_method() returns a pointer to the RSA_METHOD being used by rsa. This method may or may not be supplied by an ENGINE implementation, but if it is, the return value can only be guaranteed to be valid as long as the RSA key itself is valid and does not have its implementation changed by RSA_set_method().

- -

RSA_flags() returns the flags that are set for rsa's current RSA_METHOD. See the BUGS section.

- -

RSA_new_method() allocates and initializes an RSA structure so that engine will be used for the RSA operations. If engine is NULL, the default ENGINE for RSA operations is used, and if no default ENGINE is set, the RSA_METHOD controlled by RSA_set_default_method() is used.

- -

RSA_flags() returns the flags that are set for rsa's current method.

- -

RSA_new_method() allocates and initializes an RSA structure so that method will be used for the RSA operations. If method is NULL, the default method is used.

- -

THE RSA_METHOD STRUCTURE

- -
typedef struct rsa_meth_st
-{
-    /* name of the implementation */
-    const char *name;
-
-    /* encrypt */
-    int (*rsa_pub_enc)(int flen, unsigned char *from,
-                       unsigned char *to, RSA *rsa, int padding);
-
-    /* verify arbitrary data */
-    int (*rsa_pub_dec)(int flen, unsigned char *from,
-                       unsigned char *to, RSA *rsa, int padding);
-
-    /* sign arbitrary data */
-    int (*rsa_priv_enc)(int flen, unsigned char *from,
-                        unsigned char *to, RSA *rsa, int padding);
-
-    /* decrypt */
-    int (*rsa_priv_dec)(int flen, unsigned char *from,
-                        unsigned char *to, RSA *rsa, int padding);
-
-    /* compute r0 = r0 ^ I mod rsa->n (May be NULL for some implementations) */
-    int (*rsa_mod_exp)(BIGNUM *r0, BIGNUM *I, RSA *rsa);
-
-    /* compute r = a ^ p mod m (May be NULL for some implementations) */
-    int (*bn_mod_exp)(BIGNUM *r, BIGNUM *a, const BIGNUM *p,
-                      const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *m_ctx);
-
-    /* called at RSA_new */
-    int (*init)(RSA *rsa);
-
-    /* called at RSA_free */
-    int (*finish)(RSA *rsa);
-
-    /*
-     * RSA_FLAG_EXT_PKEY        - rsa_mod_exp is called for private key
-     *                            operations, even if p,q,dmp1,dmq1,iqmp
-     *                            are NULL
-     * RSA_METHOD_FLAG_NO_CHECK - don't check pub/private match
-     */
-    int flags;
-
-    char *app_data; /* ?? */
-
-    int (*rsa_sign)(int type,
-                    const unsigned char *m, unsigned int m_length,
-                    unsigned char *sigret, unsigned int *siglen, const RSA *rsa);
-    int (*rsa_verify)(int dtype,
-                      const unsigned char *m, unsigned int m_length,
-                      const unsigned char *sigbuf, unsigned int siglen,
-                      const RSA *rsa);
-    /* keygen. If NULL built-in RSA key generation will be used */
-    int (*rsa_keygen)(RSA *rsa, int bits, BIGNUM *e, BN_GENCB *cb);
-
-} RSA_METHOD;
- -

RETURN VALUES

- -

RSA_PKCS1_OpenSSL(), RSA_PKCS1_null_method(), RSA_get_default_method() and RSA_get_method() return pointers to the respective RSA_METHODs.

- -

RSA_set_default_method() returns no value.

- -

RSA_set_method() returns a pointer to the old RSA_METHOD implementation that was replaced. However, this return value should probably be ignored because if it was supplied by an ENGINE, the pointer could be invalidated at any time if the ENGINE is unloaded (in fact it could be unloaded as a result of the RSA_set_method() function releasing its handle to the ENGINE). For this reason, the return type may be replaced with a void declaration in a future release.

- -

RSA_new_method() returns NULL and sets an error code that can be obtained by ERR_get_error(3) if the allocation fails. Otherwise it returns a pointer to the newly allocated structure.

- -

BUGS

- -

The behaviour of RSA_flags() is a mis-feature that is left as-is for now to avoid creating compatibility problems. RSA functionality, such as the encryption functions, are controlled by the flags value in the RSA key itself, not by the flags value in the RSA_METHOD attached to the RSA key (which is what this function returns). If the flags element of an RSA key is changed, the changes will be honoured by RSA functionality but will not be reflected in the return value of the RSA_flags() function - in effect RSA_flags() behaves more like an RSA_default_flags() function (which does not currently exist).

- -

SEE ALSO

- -

RSA_new(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

The RSA_null_method(), which was a partial attempt to avoid patent issues, was replaced to always return NULL in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_sign.html b/openssl-install/share/doc/openssl/html/man3/RSA_sign.html deleted file mode 100644 index ea194524..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_sign.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -RSA_sign - - - - - - - - - - -

NAME

- -

RSA_sign, RSA_verify - RSA signatures

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_sign(int type, const unsigned char *m, unsigned int m_len,
-             unsigned char *sigret, unsigned int *siglen, RSA *rsa);
-
-int RSA_verify(int type, const unsigned char *m, unsigned int m_len,
-               unsigned char *sigbuf, unsigned int siglen, RSA *rsa);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP_PKEY_sign_init(3), EVP_PKEY_sign(3), EVP_PKEY_verify_init(3) and EVP_PKEY_verify(3).

- -

RSA_sign() signs the message digest m of size m_len using the private key rsa using RSASSA-PKCS1-v1_5 as specified in RFC 3447. It stores the signature in sigret and the signature size in siglen. sigret must point to RSA_size(rsa) bytes of memory. Note that PKCS #1 adds meta-data, placing limits on the size of the key that can be used. See RSA_private_encrypt(3) for lower-level operations.

- -

type denotes the message digest algorithm that was used to generate m. If type is NID_md5_sha1, an SSL signature (MD5 and SHA1 message digests with PKCS #1 padding and no algorithm identifier) is created.

- -

RSA_verify() verifies that the signature sigbuf of size siglen matches a given message digest m of size m_len. type denotes the message digest algorithm that was used to generate the signature. rsa is the signer's public key.

- -

RETURN VALUES

- -

RSA_sign() returns 1 on success and 0 for failure. RSA_verify() returns 1 on successful verification and 0 for failure.

- -

The error codes can be obtained by ERR_get_error(3).

- -

CONFORMING TO

- -

SSL, PKCS #1 v2.0

- -

SEE ALSO

- -

ERR_get_error(3), RSA_private_encrypt(3), RSA_public_decrypt(3)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_sign_ASN1_OCTET_STRING.html b/openssl-install/share/doc/openssl/html/man3/RSA_sign_ASN1_OCTET_STRING.html deleted file mode 100644 index cc448cb6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_sign_ASN1_OCTET_STRING.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -RSA_sign_ASN1_OCTET_STRING - - - - - - - - - - -

NAME

- -

RSA_sign_ASN1_OCTET_STRING, RSA_verify_ASN1_OCTET_STRING - RSA signatures

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_sign_ASN1_OCTET_STRING(int dummy, unsigned char *m,
-                               unsigned int m_len, unsigned char *sigret,
-                               unsigned int *siglen, RSA *rsa);
-
-int RSA_verify_ASN1_OCTET_STRING(int dummy, unsigned char *m,
-                                 unsigned int m_len, unsigned char *sigbuf,
-                                 unsigned int siglen, RSA *rsa);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. Applications should instead use EVP PKEY APIs.

- -

RSA_sign_ASN1_OCTET_STRING() signs the octet string m of size m_len using the private key rsa represented in DER using PKCS #1 padding. It stores the signature in sigret and the signature size in siglen. sigret must point to RSA_size(rsa) bytes of memory.

- -

dummy is ignored.

- -

The random number generator must be seeded when calling RSA_sign_ASN1_OCTET_STRING(). If the automatic seeding or reseeding of the OpenSSL CSPRNG fails due to external circumstances (see RAND(7)), the operation will fail.

- -

RSA_verify_ASN1_OCTET_STRING() verifies that the signature sigbuf of size siglen is the DER representation of a given octet string m of size m_len. dummy is ignored. rsa is the signer's public key.

- -

RETURN VALUES

- -

RSA_sign_ASN1_OCTET_STRING() returns 1 on success, 0 otherwise. RSA_verify_ASN1_OCTET_STRING() returns 1 on successful verification, 0 otherwise.

- -

The error codes can be obtained by ERR_get_error(3).

- -

BUGS

- -

These functions serve no recognizable purpose.

- -

SEE ALSO

- -

ERR_get_error(3), RAND_bytes(3), RSA_sign(3), RSA_verify(3), RAND(7)

- -

HISTORY

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/RSA_size.html b/openssl-install/share/doc/openssl/html/man3/RSA_size.html deleted file mode 100644 index 007d5157..00000000 --- a/openssl-install/share/doc/openssl/html/man3/RSA_size.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -RSA_size - - - - - - - - - - -

NAME

- -

RSA_size, RSA_bits, RSA_security_bits - get RSA modulus size or security bits

- -

SYNOPSIS

- -
#include <openssl/rsa.h>
-
-int RSA_bits(const RSA *rsa);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int RSA_size(const RSA *rsa);
-
-int RSA_security_bits(const RSA *rsa);
- -

DESCRIPTION

- -

RSA_bits() returns the number of significant bits.

- -

rsa and rsa->n must not be NULL.

- -

The remaining functions described on this page are deprecated. Applications should instead use EVP_PKEY_get_size(3), EVP_PKEY_get_bits(3) and EVP_PKEY_get_security_bits(3).

- -

RSA_size() returns the RSA modulus size in bytes. It can be used to determine how much memory must be allocated for an RSA encrypted value.

- -

RSA_security_bits() returns the number of security bits of the given rsa key. See BN_security_bits(3).

- -

RETURN VALUES

- -

RSA_bits() returns the number of bits in the key.

- -

RSA_size() returns the size of modulus in bytes.

- -

RSA_security_bits() returns the number of security bits.

- -

SEE ALSO

- -

BN_num_bits(3)

- -

HISTORY

- -

The RSA_size() and RSA_security_bits() functions were deprecated in OpenSSL 3.0.

- -

The RSA_bits() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SCT_new.html b/openssl-install/share/doc/openssl/html/man3/SCT_new.html deleted file mode 100644 index 95470eba..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SCT_new.html +++ /dev/null @@ -1,203 +0,0 @@ - - - - -SCT_new - - - - - - - - - - -

NAME

- -

SCT_new, SCT_new_from_base64, SCT_free, SCT_LIST_free, SCT_get_version, SCT_set_version, SCT_get_log_entry_type, SCT_set_log_entry_type, SCT_get0_log_id, SCT_set0_log_id, SCT_set1_log_id, SCT_get_timestamp, SCT_set_timestamp, SCT_get_signature_nid, SCT_set_signature_nid, SCT_get0_signature, SCT_set0_signature, SCT_set1_signature, SCT_get0_extensions, SCT_set0_extensions, SCT_set1_extensions, SCT_get_source, SCT_set_source - A Certificate Transparency Signed Certificate Timestamp

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-typedef enum {
-    CT_LOG_ENTRY_TYPE_NOT_SET = -1,
-    CT_LOG_ENTRY_TYPE_X509 = 0,
-    CT_LOG_ENTRY_TYPE_PRECERT = 1
-} ct_log_entry_type_t;
-
-typedef enum {
-    SCT_VERSION_NOT_SET = -1,
-    SCT_VERSION_V1 = 0
-} sct_version_t;
-
-typedef enum {
-    SCT_SOURCE_UNKNOWN,
-    SCT_SOURCE_TLS_EXTENSION,
-    SCT_SOURCE_X509V3_EXTENSION,
-    SCT_SOURCE_OCSP_STAPLED_RESPONSE
-} sct_source_t;
-
-SCT *SCT_new(void);
-SCT *SCT_new_from_base64(unsigned char version,
-                         const char *logid_base64,
-                         ct_log_entry_type_t entry_type,
-                         uint64_t timestamp,
-                         const char *extensions_base64,
-                         const char *signature_base64);
-
-void SCT_free(SCT *sct);
-void SCT_LIST_free(STACK_OF(SCT) *a);
-
-sct_version_t SCT_get_version(const SCT *sct);
-int SCT_set_version(SCT *sct, sct_version_t version);
-
-ct_log_entry_type_t SCT_get_log_entry_type(const SCT *sct);
-int SCT_set_log_entry_type(SCT *sct, ct_log_entry_type_t entry_type);
-
-size_t SCT_get0_log_id(const SCT *sct, unsigned char **log_id);
-int SCT_set0_log_id(SCT *sct, unsigned char *log_id, size_t log_id_len);
-int SCT_set1_log_id(SCT *sct, const unsigned char *log_id, size_t log_id_len);
-
-uint64_t SCT_get_timestamp(const SCT *sct);
-void SCT_set_timestamp(SCT *sct, uint64_t timestamp);
-
-int SCT_get_signature_nid(const SCT *sct);
-int SCT_set_signature_nid(SCT *sct, int nid);
-
-size_t SCT_get0_signature(const SCT *sct, unsigned char **sig);
-void SCT_set0_signature(SCT *sct, unsigned char *sig, size_t sig_len);
-int SCT_set1_signature(SCT *sct, const unsigned char *sig, size_t sig_len);
-
-size_t SCT_get0_extensions(const SCT *sct, unsigned char **ext);
-void SCT_set0_extensions(SCT *sct, unsigned char *ext, size_t ext_len);
-int SCT_set1_extensions(SCT *sct, const unsigned char *ext, size_t ext_len);
-
-sct_source_t SCT_get_source(const SCT *sct);
-int SCT_set_source(SCT *sct, sct_source_t source);
- -

DESCRIPTION

- -

Signed Certificate Timestamps (SCTs) are defined by RFC 6962, Section 3.2. They constitute a promise by a Certificate Transparency (CT) log to publicly record a certificate. By cryptographically verifying that a log did indeed issue an SCT, some confidence can be gained that the certificate is publicly known.

- -

An internal representation of an SCT can be created in one of two ways. The first option is to create a blank SCT, using SCT_new(), and then populate it using:

- - - -

Alternatively, the SCT can be pre-populated from the following data using SCT_new_from_base64():

- - - -

SCT_set_source() can be used to record where the SCT was found (TLS extension, X.509 certificate extension or OCSP response). This is not required for verifying the SCT.

- -

SCT_free() frees the specified SCT. If the argument is NULL, nothing is done.

- -

SCT_LIST_free() frees the specified stack of SCTs. If the argument is NULL, nothing is done.

- -

NOTES

- -

Some of the setters return int, instead of void. These will all return 1 on success, 0 on failure. They will not make changes on failure.

- -

All of the setters will reset the validation status of the SCT to SCT_VALIDATION_STATUS_NOT_SET (see SCT_validate(3)).

- -

SCT_set_source() will call SCT_set_log_entry_type() if the type of certificate the SCT was issued for can be inferred from where the SCT was found. For example, an SCT found in an X.509 extension must have been issued for a pre- certificate.

- -

SCT_set_source() will not refuse unknown values.

- -

RETURN VALUES

- -

SCT_set_version() returns 1 if the specified version is supported, 0 otherwise.

- -

SCT_set_log_entry_type() returns 1 if the specified log entry type is supported, 0 otherwise.

- -

SCT_set0_log_id() and SCT_set1_log_id return 1 if the specified LogID is a valid SHA-256 hash, 0 otherwise. Additionally, SCT_set1_log_id returns 0 if malloc fails.

- -

SCT_set_signature_nid returns 1 if the specified NID is supported, 0 otherwise.

- -

SCT_set1_extensions and SCT_set1_signature return 1 if the supplied buffer is copied successfully, 0 otherwise (i.e. if malloc fails).

- -

SCT_set_source returns 1 on success, 0 otherwise.

- -

SEE ALSO

- -

ct(7), SCT_validate(3), OBJ_nid2obj(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SCT_print.html b/openssl-install/share/doc/openssl/html/man3/SCT_print.html deleted file mode 100644 index 46cd749a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SCT_print.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -SCT_print - - - - - - - - - - -

NAME

- -

SCT_print, SCT_LIST_print, SCT_validation_status_string - Prints Signed Certificate Timestamps in a human-readable way

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-void SCT_print(const SCT *sct, BIO *out, int indent, const CTLOG_STORE *logs);
-void SCT_LIST_print(const STACK_OF(SCT) *sct_list, BIO *out, int indent,
-                    const char *separator, const CTLOG_STORE *logs);
-const char *SCT_validation_status_string(const SCT *sct);
- -

DESCRIPTION

- -

SCT_print() prints a single Signed Certificate Timestamp (SCT) to a BIO in a human-readable format. SCT_LIST_print() prints an entire list of SCTs in a similar way. A separator can be specified to delimit each SCT in the output.

- -

The output can be indented by a specified number of spaces. If a CTLOG_STORE is provided, it will be used to print the description of the CT log that issued each SCT (if that log is in the CTLOG_STORE). Alternatively, NULL can be passed as the CTLOG_STORE parameter to disable this feature.

- -

SCT_validation_status_string() will return the validation status of an SCT as a human-readable string. Call SCT_validate() or SCT_LIST_validate() beforehand in order to set the validation status of an SCT first.

- -

RETURN VALUES

- -

SCT_validation_status_string() returns a NUL-terminated string representing the validation status of an SCT object.

- -

SEE ALSO

- -

ct(7), bio(7), CTLOG_STORE_new(3), SCT_validate(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SCT_validate.html b/openssl-install/share/doc/openssl/html/man3/SCT_validate.html deleted file mode 100644 index 8a26fe7b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SCT_validate.html +++ /dev/null @@ -1,108 +0,0 @@ - - - - -SCT_validate - - - - - - - - - - -

NAME

- -

SCT_validate, SCT_LIST_validate, SCT_get_validation_status - checks Signed Certificate Timestamps (SCTs) are valid

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-typedef enum {
-    SCT_VALIDATION_STATUS_NOT_SET,
-    SCT_VALIDATION_STATUS_UNKNOWN_LOG,
-    SCT_VALIDATION_STATUS_VALID,
-    SCT_VALIDATION_STATUS_INVALID,
-    SCT_VALIDATION_STATUS_UNVERIFIED,
-    SCT_VALIDATION_STATUS_UNKNOWN_VERSION
-} sct_validation_status_t;
-
-int SCT_validate(SCT *sct, const CT_POLICY_EVAL_CTX *ctx);
-int SCT_LIST_validate(const STACK_OF(SCT) *scts, CT_POLICY_EVAL_CTX *ctx);
-sct_validation_status_t SCT_get_validation_status(const SCT *sct);
- -

DESCRIPTION

- -

SCT_validate() will check that an SCT is valid and verify its signature. SCT_LIST_validate() performs the same checks on an entire stack of SCTs. The result of the validation checks can be obtained by passing the SCT to SCT_get_validation_status().

- -

A CT_POLICY_EVAL_CTX must be provided that specifies:

- - - -

If the SCT is of an unsupported version (only v1 is currently supported), the validation status will be SCT_VALIDATION_STATUS_UNKNOWN_VERSION.

- -

If the SCT's signature is incorrect, its timestamp is in the future (relative to the time in CT_POLICY_EVAL_CTX), or if it is otherwise invalid, the validation status will be SCT_VALIDATION_STATUS_INVALID.

- -

If all checks pass, the validation status will be SCT_VALIDATION_STATUS_VALID.

- -

NOTES

- -

A return value of 0 from SCT_LIST_validate() should not be interpreted as a failure. At a minimum, only one valid SCT may provide sufficient confidence that a certificate has been publicly logged.

- -

RETURN VALUES

- -

SCT_validate() returns a negative integer if an internal error occurs, 0 if the SCT fails validation, or 1 if the SCT passes validation.

- -

SCT_LIST_validate() returns a negative integer if an internal error occurs, 0 if any of SCTs fails validation, or 1 if they all pass validation.

- -

SCT_get_validation_status() returns the validation status of the SCT. If SCT_validate() or SCT_LIST_validate() have not been passed that SCT, the returned value will be SCT_VALIDATION_STATUS_NOT_SET.

- -

SEE ALSO

- -

ct(7)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SHA256_Init.html b/openssl-install/share/doc/openssl/html/man3/SHA256_Init.html deleted file mode 100644 index 3f4644a4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SHA256_Init.html +++ /dev/null @@ -1,110 +0,0 @@ - - - - -SHA256_Init - - - - - - - - - - -

NAME

- -

SHA1, SHA1_Init, SHA1_Update, SHA1_Final, SHA224, SHA224_Init, SHA224_Update, SHA224_Final, SHA256, SHA256_Init, SHA256_Update, SHA256_Final, SHA384, SHA384_Init, SHA384_Update, SHA384_Final, SHA512, SHA512_Init, SHA512_Update, SHA512_Final - Secure Hash Algorithm

- -

SYNOPSIS

- -
#include <openssl/sha.h>
-
-unsigned char *SHA1(const unsigned char *data, size_t count, unsigned char *md_buf);
-unsigned char *SHA224(const unsigned char *data, size_t count, unsigned char *md_buf);
-unsigned char *SHA256(const unsigned char *data, size_t count, unsigned char *md_buf);
-unsigned char *SHA384(const unsigned char *data, size_t count, unsigned char *md_buf);
-unsigned char *SHA512(const unsigned char *data, size_t count, unsigned char *md_buf);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int SHA1_Init(SHA_CTX *c);
-int SHA1_Update(SHA_CTX *c, const void *data, size_t len);
-int SHA1_Final(unsigned char *md, SHA_CTX *c);
-
-int SHA224_Init(SHA256_CTX *c);
-int SHA224_Update(SHA256_CTX *c, const void *data, size_t len);
-int SHA224_Final(unsigned char *md, SHA256_CTX *c);
-
-int SHA256_Init(SHA256_CTX *c);
-int SHA256_Update(SHA256_CTX *c, const void *data, size_t len);
-int SHA256_Final(unsigned char *md, SHA256_CTX *c);
-
-int SHA384_Init(SHA512_CTX *c);
-int SHA384_Update(SHA512_CTX *c, const void *data, size_t len);
-int SHA384_Final(unsigned char *md, SHA512_CTX *c);
-
-int SHA512_Init(SHA512_CTX *c);
-int SHA512_Update(SHA512_CTX *c, const void *data, size_t len);
-int SHA512_Final(unsigned char *md, SHA512_CTX *c);
- -

DESCRIPTION

- -

All of the functions described on this page except for SHA1(), SHA224(), SHA256(), SHA384() and SHA512() are deprecated. Applications should instead use EVP_DigestInit_ex(3), EVP_DigestUpdate(3) and EVP_DigestFinal_ex(3), or the quick one-shot function EVP_Q_digest(3). SHA1(), SHA224(), SHA256(), SHA384(), and SHA256() can continue to be used. They can also be replaced by, e.g.,

- -
(EVP_Q_digest(d, n, md, NULL, NULL, "SHA256", NULL) ? md : NULL)
- -

SHA-1 (Secure Hash Algorithm) is a cryptographic hash function with a 160 bit output.

- -

SHA1() computes the SHA-1 message digest of the n bytes at d and places it in md (which must have space for SHA_DIGEST_LENGTH == 20 bytes of output). If md is NULL, the digest is placed in a static array. Note: setting md to NULL is not thread safe.

- -

The following functions may be used if the message is not completely stored in memory:

- -

SHA1_Init() initializes a SHA_CTX structure.

- -

SHA1_Update() can be called repeatedly with chunks of the message to be hashed (len bytes at data).

- -

SHA1_Final() places the message digest in md, which must have space for SHA_DIGEST_LENGTH == 20 bytes of output, and erases the SHA_CTX.

- -

The SHA224, SHA256, SHA384 and SHA512 families of functions operate in the same way as for the SHA1 functions. Note that SHA224 and SHA256 use a SHA256_CTX object instead of SHA_CTX. SHA384 and SHA512 use SHA512_CTX. The buffer md must have space for the output from the SHA variant being used (defined by SHA224_DIGEST_LENGTH, SHA256_DIGEST_LENGTH, SHA384_DIGEST_LENGTH and SHA512_DIGEST_LENGTH). Also note that, as for the SHA1() function above, the SHA224(), SHA256(), SHA384() and SHA512() functions are not thread safe if md is NULL.

- -

RETURN VALUES

- -

SHA1(), SHA224(), SHA256(), SHA384() and SHA512() return a pointer to the hash value.

- -

SHA1_Init(), SHA1_Update() and SHA1_Final() and equivalent SHA224, SHA256, SHA384 and SHA512 functions return 1 for success, 0 otherwise.

- -

CONFORMING TO

- -

US Federal Information Processing Standard FIPS PUB 180-4 (Secure Hash Standard), ANSI X9.30

- -

SEE ALSO

- -

EVP_Q_digest(3), EVP_DigestInit(3)

- -

HISTORY

- -

All of these functions except SHA*() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SMIME_read_ASN1.html b/openssl-install/share/doc/openssl/html/man3/SMIME_read_ASN1.html deleted file mode 100644 index f2bb274e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SMIME_read_ASN1.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -SMIME_read_ASN1 - - - - - - - - - - -

NAME

- -

SMIME_read_ASN1_ex, SMIME_read_ASN1 - parse S/MIME message

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-ASN1_VALUE *SMIME_read_ASN1_ex(BIO *in, int flags, BIO **bcont,
-                               const ASN1_ITEM *it, ASN1_VALUE **x,
-                               OSSL_LIB_CTX *libctx, const char *propq);
-ASN1_VALUE *SMIME_read_ASN1(BIO *in, BIO **bcont, const ASN1_ITEM *it);
- -

DESCRIPTION

- -

SMIME_read_ASN1_ex() parses a message in S/MIME format.

- -

in is a BIO to read the message from. If the flags argument contains CMS_BINARY then the input is assumed to be in binary format and is not translated to canonical form. If in addition SMIME_ASCIICRLF is set then the binary input is assumed to be followed by CR and LF characters, else only by an LF character. x can be used to optionally supply a previously created it ASN1_VALUE object (such as CMS_ContentInfo or PKCS7), it can be set to NULL. Valid values that can be used by ASN.1 structure it are ASN1_ITEM_rptr(PKCS7) or ASN1_ITEM_rptr(CMS_ContentInfo). Any algorithm fetches that occur during the operation will use the OSSL_LIB_CTX supplied in the libctx parameter, and use the property query string propq See "ALGORITHM FETCHING" in crypto(7) for further details about algorithm fetching.

- -

If cleartext signing is used then the content is saved in a memory bio which is written to *bcont, otherwise *bcont is set to NULL.

- -

The parsed ASN1_VALUE structure is returned or NULL if an error occurred.

- -

SMIME_read_ASN1() is similar to SMIME_read_ASN1_ex() but sets the value of x to NULL and the value of flags to 0.

- -

NOTES

- -

The higher level functions SMIME_read_CMS_ex(3) and SMIME_read_PKCS7_ex(3) should be used instead of SMIME_read_ASN1_ex().

- -

To support future functionality if bcont is not NULL *bcont should be initialized to NULL.

- -

BUGS

- -

The MIME parser used by SMIME_read_ASN1_ex() is somewhat primitive. While it will handle most S/MIME messages more complex compound formats may not work.

- -

The use of a memory BIO to hold the signed content limits the size of message which can be processed due to memory restraints: a streaming single pass option should be available.

- -

RETURN VALUES

- -

SMIME_read_ASN1_ex() and SMIME_read_ASN1() return a valid ASN1_VALUE structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), SMIME_read_CMS_ex(3), SMIME_read_PKCS7_ex(3), SMIME_write_ASN1(3), SMIME_write_ASN1_ex(3)

- -

HISTORY

- -

The function SMIME_read_ASN1_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SMIME_read_CMS.html b/openssl-install/share/doc/openssl/html/man3/SMIME_read_CMS.html deleted file mode 100644 index 2bf4ed95..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SMIME_read_CMS.html +++ /dev/null @@ -1,94 +0,0 @@ - - - - -SMIME_read_CMS - - - - - - - - - - -

NAME

- -

SMIME_read_CMS_ex, SMIME_read_CMS - parse S/MIME message

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-CMS_ContentInfo *SMIME_read_CMS_ex(BIO *bio, int flags, BIO **bcont,
-                                   CMS_ContentInfo **cms);
-CMS_ContentInfo *SMIME_read_CMS(BIO *in, BIO **bcont);
- -

DESCRIPTION

- -

SMIME_read_CMS() parses a message in S/MIME format.

- -

in is a BIO to read the message from.

- -

If cleartext signing is used then the content is saved in a memory bio which is written to *bcont, otherwise *bcont is set to NULL.

- -

The parsed CMS_ContentInfo structure is returned or NULL if an error occurred.

- -

SMIME_read_CMS_ex() is similar to SMIME_read_CMS() but optionally a previously created cms CMS_ContentInfo object can be supplied as well as some flags. To create a cms object use CMS_ContentInfo_new_ex(3). If the flags argument contains CMS_BINARY then the input is assumed to be in binary format and is not translated to canonical form. If in addition SMIME_ASCIICRLF is set then the binary input is assumed to be followed by CR and LF characters, else only by an LF character. If flags is 0 and cms is NULL then it is identical to SMIME_read_CMS().

- -

NOTES

- -

If *bcont is not NULL then the message is clear text signed. *bcont can then be passed to CMS_verify() with the CMS_DETACHED flag set.

- -

Otherwise the type of the returned structure can be determined using CMS_get0_type().

- -

To support future functionality if bcont is not NULL *bcont should be initialized to NULL. For example:

- -
BIO *cont = NULL;
-CMS_ContentInfo *cms;
-
-cms = SMIME_read_CMS(in, &cont);
- -

BUGS

- -

The MIME parser used by SMIME_read_CMS() is somewhat primitive. While it will handle most S/MIME messages more complex compound formats may not work.

- -

The parser assumes that the CMS_ContentInfo structure is always base64 encoded and will not handle the case where it is in binary format or uses quoted printable format.

- -

The use of a memory BIO to hold the signed content limits the size of message which can be processed due to memory restraints: a streaming single pass option should be available.

- -

RETURN VALUES

- -

SMIME_read_CMS_ex() and SMIME_read_CMS() return a valid CMS_ContentInfo structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_verify(3), CMS_encrypt(3), CMS_decrypt(3)

- -

HISTORY

- -

The function SMIME_read_CMS_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2008-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SMIME_read_PKCS7.html b/openssl-install/share/doc/openssl/html/man3/SMIME_read_PKCS7.html deleted file mode 100644 index 0a906f12..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SMIME_read_PKCS7.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -SMIME_read_PKCS7 - - - - - - - - - - -

NAME

- -

SMIME_read_PKCS7_ex, SMIME_read_PKCS7 - parse S/MIME message

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-PKCS7 *SMIME_read_PKCS7_ex(BIO *bio, BIO **bcont, PKCS7 **p7);
-PKCS7 *SMIME_read_PKCS7(BIO *in, BIO **bcont);
- -

DESCRIPTION

- -

SMIME_read_PKCS7() parses a message in S/MIME format.

- -

in is a BIO to read the message from.

- -

If cleartext signing is used then the content is saved in a memory bio which is written to *bcont, otherwise *bcont is set to NULL.

- -

The parsed PKCS#7 structure is returned or NULL if an error occurred.

- -

SMIME_read_PKCS7_ex() is similar to SMIME_read_PKCS7() but can optionally supply a previously created p7 PKCS#7 object. If p7 is NULL then it is identical to SMIME_read_PKCS7(). To create a p7 object use PKCS7_new_ex(3).

- -

NOTES

- -

If *bcont is not NULL then the message is clear text signed. *bcont can then be passed to PKCS7_verify() with the PKCS7_DETACHED flag set.

- -

Otherwise the type of the returned structure can be determined using PKCS7_type_is_enveloped(), etc.

- -

To support future functionality if bcont is not NULL *bcont should be initialized to NULL. For example:

- -
BIO *cont = NULL;
-PKCS7 *p7;
-
-p7 = SMIME_read_PKCS7(in, &cont);
- -

BUGS

- -

The MIME parser used by SMIME_read_PKCS7() is somewhat primitive. While it will handle most S/MIME messages more complex compound formats may not work.

- -

The parser assumes that the PKCS7 structure is always base64 encoded and will not handle the case where it is in binary format or uses quoted printable format.

- -

The use of a memory BIO to hold the signed content limits the size of message which can be processed due to memory restraints: a streaming single pass option should be available.

- -

RETURN VALUES

- -

SMIME_read_PKCS7_ex() and SMIME_read_PKCS7() return a valid PKCS7 structure or NULL if an error occurred. The error can be obtained from ERR_get_error(3).

- -

SEE ALSO

- -

ERR_get_error(3), SMIME_read_PKCS7(3), PKCS7_sign(3), PKCS7_verify(3), PKCS7_encrypt(3) PKCS7_decrypt(3)

- -

HISTORY

- -

The function SMIME_read_PKCS7_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SMIME_write_ASN1.html b/openssl-install/share/doc/openssl/html/man3/SMIME_write_ASN1.html deleted file mode 100644 index ec3b6dd9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SMIME_write_ASN1.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -SMIME_write_ASN1 - - - - - - - - - - -

NAME

- -

SMIME_write_ASN1_ex, SMIME_write_ASN1 - convert structure to S/MIME format

- -

SYNOPSIS

- -
#include <openssl/asn1.h>
-
-int SMIME_write_ASN1_ex(BIO *out, ASN1_VALUE *val, BIO *data, int flags,
-                        int ctype_nid, int econt_nid,
-                        STACK_OF(X509_ALGOR) *mdalgs, const ASN1_ITEM *it,
-                        OSSL_LIB_CTX *libctx, const char *propq);
-
-int SMIME_write_ASN1(BIO *out,
-    ASN1_VALUE *val, BIO *data, int flags, int ctype_nid, int econt_nid,
-    STACK_OF(X509_ALGOR) *mdalgs, const ASN1_ITEM *it);
- -

DESCRIPTION

- -

SMIME_write_ASN1_ex() adds the appropriate MIME headers to an object structure to produce an S/MIME message.

- -

out is the BIO to write the data to. value is the appropriate ASN1_VALUE structure (either CMS_ContentInfo or PKCS7). If streaming is enabled then the content must be supplied via data. flags is an optional set of flags. ctype_nid is the NID of the content type, econt_nid is the NID of the embedded content type and mdalgs is a list of signed data digestAlgorithms. Valid values that can be used by the ASN.1 structure it are ASN1_ITEM_rptr(PKCS7) or ASN1_ITEM_rptr(CMS_ContentInfo). The library context libctx and the property query propq are used when retrieving algorithms from providers.

- -

NOTES

- -

The higher level functions SMIME_write_CMS(3) and SMIME_write_PKCS7(3) should be used instead of SMIME_write_ASN1().

- -

The following flags can be passed in the flags parameter.

- -

If CMS_DETACHED is set then cleartext signing will be used, this option only makes sense for SignedData where CMS_DETACHED is also set when the sign() method is called.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are added to the content, this only makes sense if CMS_DETACHED is also set.

- -

If the CMS_STREAM flag is set streaming is performed. This flag should only be set if CMS_STREAM was also set in the previous call to a CMS_ContentInfo or PKCS7 creation function.

- -

If cleartext signing is being used and CMS_STREAM not set then the data must be read twice: once to compute the signature in sign method and once to output the S/MIME message.

- -

If streaming is performed the content is output in BER format using indefinite length constructed encoding except in the case of signed data with detached content where the content is absent and DER format is used.

- -

RETURN VALUES

- -

SMIME_write_ASN1_ex() and SMIME_write_ASN1() return 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), SMIME_write_CMS(3), SMIME_write_PKCS7(3)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SMIME_write_CMS.html b/openssl-install/share/doc/openssl/html/man3/SMIME_write_CMS.html deleted file mode 100644 index b093f94a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SMIME_write_CMS.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -SMIME_write_CMS - - - - - - - - - - -

NAME

- -

SMIME_write_CMS - convert CMS structure to S/MIME format

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int SMIME_write_CMS(BIO *out, CMS_ContentInfo *cms, BIO *data, int flags);
- -

DESCRIPTION

- -

SMIME_write_CMS() adds the appropriate MIME headers to a CMS structure to produce an S/MIME message.

- -

out is the BIO to write the data to. cms is the appropriate CMS_ContentInfo structure. If streaming is enabled then the content must be supplied in the data argument. flags is an optional set of flags.

- -

NOTES

- -

The following flags can be passed in the flags parameter.

- -

If CMS_DETACHED is set then cleartext signing will be used, this option only makes sense for SignedData where CMS_DETACHED is also set when CMS_sign() is called.

- -

If the CMS_TEXT flag is set MIME headers for type text/plain are added to the content, this only makes sense if CMS_DETACHED is also set.

- -

If the CMS_STREAM flag is set streaming is performed. This flag should only be set if CMS_STREAM was also set in the previous call to a CMS_ContentInfo creation function.

- -

If cleartext signing is being used and CMS_STREAM not set then the data must be read twice: once to compute the signature in CMS_sign() and once to output the S/MIME message.

- -

If streaming is performed the content is output in BER format using indefinite length constructed encoding except in the case of signed data with detached content where the content is absent and DER format is used.

- -

BUGS

- -

SMIME_write_CMS() always base64 encodes CMS structures, there should be an option to disable this.

- -

RETURN VALUES

- -

SMIME_write_CMS() returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_verify(3), CMS_encrypt(3) CMS_decrypt(3)

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SMIME_write_PKCS7.html b/openssl-install/share/doc/openssl/html/man3/SMIME_write_PKCS7.html deleted file mode 100644 index 96bf4e95..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SMIME_write_PKCS7.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -SMIME_write_PKCS7 - - - - - - - - - - -

NAME

- -

SMIME_write_PKCS7 - convert PKCS#7 structure to S/MIME format

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-int SMIME_write_PKCS7(BIO *out, PKCS7 *p7, BIO *data, int flags);
- -

DESCRIPTION

- -

SMIME_write_PKCS7() adds the appropriate MIME headers to a PKCS#7 structure to produce an S/MIME message.

- -

out is the BIO to write the data to. p7 is the appropriate PKCS7 structure. If streaming is enabled then the content must be supplied in the data argument. flags is an optional set of flags.

- -

NOTES

- -

The following flags can be passed in the flags parameter.

- -

If PKCS7_DETACHED is set then cleartext signing will be used, this option only makes sense for signedData where PKCS7_DETACHED is also set when PKCS7_sign() is also called.

- -

If the PKCS7_TEXT flag is set MIME headers for type text/plain are added to the content, this only makes sense if PKCS7_DETACHED is also set.

- -

If the PKCS7_STREAM flag is set streaming is performed. This flag should only be set if PKCS7_STREAM was also set in the previous call to PKCS7_sign() or PKCS7_encrypt().

- -

If cleartext signing is being used and PKCS7_STREAM not set then the data must be read twice: once to compute the signature in PKCS7_sign() and once to output the S/MIME message.

- -

If streaming is performed the content is output in BER format using indefinite length constructed encoding except in the case of signed data with detached content where the content is absent and DER format is used.

- -

BUGS

- -

SMIME_write_PKCS7() always base64 encodes PKCS#7 structures, there should be an option to disable this.

- -

RETURN VALUES

- -

SMIME_write_PKCS7() returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), PKCS7_sign(3), PKCS7_verify(3), PKCS7_encrypt(3) PKCS7_decrypt(3)

- -

COPYRIGHT

- -

Copyright 2002-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SRP_Calc_B.html b/openssl-install/share/doc/openssl/html/man3/SRP_Calc_B.html deleted file mode 100644 index 0f3665d6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SRP_Calc_B.html +++ /dev/null @@ -1,92 +0,0 @@ - - - - -SRP_Calc_B - - - - - - - - - - -

NAME

- -

SRP_Calc_server_key, SRP_Calc_A, SRP_Calc_B_ex, SRP_Calc_B, SRP_Calc_u_ex, SRP_Calc_u, SRP_Calc_x_ex, SRP_Calc_x, SRP_Calc_client_key_ex, SRP_Calc_client_key - SRP authentication primitives

- -

SYNOPSIS

- -
#include <openssl/srp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
/* server side .... */
-BIGNUM *SRP_Calc_server_key(const BIGNUM *A, const BIGNUM *v, const BIGNUM *u,
-                            const BIGNUM *b, const BIGNUM *N);
-BIGNUM *SRP_Calc_B_ex(const BIGNUM *b, const BIGNUM *N, const BIGNUM *g,
-                      const BIGNUM *v, OSSL_LIB_CTX *libctx, const char *propq);
-BIGNUM *SRP_Calc_B(const BIGNUM *b, const BIGNUM *N, const BIGNUM *g,
-                  const BIGNUM *v);
-
-BIGNUM *SRP_Calc_u_ex(const BIGNUM *A, const BIGNUM *B, const BIGNUM *N,
-                      OSSL_LIB_CTX *libctx, const char *propq);
-BIGNUM *SRP_Calc_u(const BIGNUM *A, const BIGNUM *B, const BIGNUM *N);
-
-/* client side .... */
-BIGNUM *SRP_Calc_client_key_ex(const BIGNUM *N, const BIGNUM *B, const BIGNUM *g,
-                            const BIGNUM *x, const BIGNUM *a, const BIGNUM *u,
-                            OSSL_LIB_CTX *libctx, const char *propq);
-BIGNUM *SRP_Calc_client_key(const BIGNUM *N, const BIGNUM *B, const BIGNUM *g,
-                            const BIGNUM *x, const BIGNUM *a, const BIGNUM *u);
-BIGNUM *SRP_Calc_x_ex(const BIGNUM *s, const char *user, const char *pass,
-                      OSSL_LIB_CTX *libctx, const char *propq);
-BIGNUM *SRP_Calc_x(const BIGNUM *s, const char *user, const char *pass);
-BIGNUM *SRP_Calc_A(const BIGNUM *a, const BIGNUM *N, const BIGNUM *g);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. There are no available replacement functions at this time.

- -

The SRP functions described on this page are used to calculate various parameters and keys used by SRP as defined in RFC2945. The server key and B and u parameters are used on the server side and are calculated via SRP_Calc_server_key(), SRP_Calc_B_ex(), SRP_Calc_B(), SRP_Calc_u_ex() and SRP_Calc_u(). The client key and x and A parameters are used on the client side and are calculated via the functions SRP_Calc_client_key_ex(), SRP_Calc_client_key(), SRP_Calc_x_ex(), SRP_Calc_x() and SRP_Calc_A(). See RFC2945 for a detailed description of their usage and the meaning of the various BIGNUM parameters to these functions.

- -

Most of these functions come in two forms. Those that take a libctx and propq parameter, and those that don't. Any cryptogrpahic functions that are fetched and used during the calculation use the provided libctx and propq. See "ALGORITHM FETCHING" in crypto(7) for more details. The variants that do not take a libctx and propq parameter use the default library context and property query string. The SRP_Calc_server_key() and SRP_Calc_A() functions do not have a form that takes libctx or propq parameters because they do not need to fetch any cryptographic algorithms.

- -

RETURN VALUES

- -

All these functions return the calculated key or parameter, or NULL on error.

- -

SEE ALSO

- -

openssl-srp(1), SRP_VBASE_new(3), SRP_user_pwd_new(3)

- -

HISTORY

- -

SRP_Calc_B_ex, SRP_Calc_u_ex, SRP_Calc_client_key_ex and SRP_Calc_x_ex were introduced in OpenSSL 3.0.

- -

All of the other functions were added in OpenSSL 1.0.1.

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SRP_VBASE_new.html b/openssl-install/share/doc/openssl/html/man3/SRP_VBASE_new.html deleted file mode 100644 index d1fff7d3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SRP_VBASE_new.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -SRP_VBASE_new - - - - - - - - - - -

NAME

- -

SRP_VBASE_new, SRP_VBASE_free, SRP_VBASE_init, SRP_VBASE_add0_user, SRP_VBASE_get1_by_user, SRP_VBASE_get_by_user - Functions to create and manage a stack of SRP user verifier information

- -

SYNOPSIS

- -
#include <openssl/srp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
SRP_VBASE *SRP_VBASE_new(char *seed_key);
-void SRP_VBASE_free(SRP_VBASE *vb);
-
-int SRP_VBASE_init(SRP_VBASE *vb, char *verifier_file);
-
-int SRP_VBASE_add0_user(SRP_VBASE *vb, SRP_user_pwd *user_pwd);
-SRP_user_pwd *SRP_VBASE_get1_by_user(SRP_VBASE *vb, char *username);
-SRP_user_pwd *SRP_VBASE_get_by_user(SRP_VBASE *vb, char *username);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. There are no available replacement functions at this time.

- -

The SRP_VBASE_new() function allocates a structure to store server side SRP verifier information. If seed_key is not NULL a copy is stored and used to generate dummy parameters for users that are not found by SRP_VBASE_get1_by_user(). This allows the server to hide the fact that it doesn't have a verifier for a particular username, as described in section 2.5.1.3 'Unknown SRP' of RFC 5054. The seed string should contain random NUL terminated binary data (therefore the random data should not contain NUL bytes!).

- -

The SRP_VBASE_free() function frees up the vb structure. If vb is NULL, nothing is done.

- -

The SRP_VBASE_init() function parses the information in a verifier file and populates the vb structure. The verifier file is a text file containing multiple entries, whose format is: flag base64(verifier) base64(salt) username gNid userinfo(optional) where the flag can be 'V' (valid) or 'R' (revoked). Note that the base64 encoding used here is non-standard so it is recommended to use openssl-srp(1) to generate this file.

- -

The SRP_VBASE_add0_user() function adds the user_pwd verifier information to the vb structure. See SRP_user_pwd_new(3) to create and populate this record. The library takes ownership of user_pwd, it should not be freed by the caller.

- -

The SRP_VBASE_get1_by_user() function returns the password info for the user whose username matches username. It replaces the deprecated SRP_VBASE_get_by_user(). If no matching user is found but a seed_key and default gN parameters have been set, dummy authentication information is generated from the seed_key, allowing the server to hide the fact that it doesn't have a verifier for a particular username. When using SRP as a TLS authentication mechanism, this will cause the handshake to proceed normally but the first client will be rejected with a "bad_record_mac" alert, as if the password was incorrect. If no matching user is found and the seed_key is not set, NULL is returned. Ownership of the returned pointer is released to the caller, it must be freed with SRP_user_pwd_free().

- -

RETURN VALUES

- -

SRP_VBASE_init() returns SRP_NO_ERROR (0) on success and a positive value on failure. The error codes are SRP_ERR_OPEN_FILE if the file could not be opened, SRP_ERR_VBASE_INCOMPLETE_FILE if the file could not be parsed, SRP_ERR_MEMORY on memory allocation failure and SRP_ERR_VBASE_BN_LIB for invalid decoded parameter values.

- -

SRP_VBASE_add0_user() returns 1 on success and 0 on failure.

- -

SEE ALSO

- -

openssl-srp(1), SRP_create_verifier(3), SRP_user_pwd_new(3), SSL_CTX_set_srp_password(3)

- -

HISTORY

- -

The SRP_VBASE_add0_user() function was added in OpenSSL 3.0.

- -

All other functions were added in OpenSSL 1.0.1.

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SRP_create_verifier.html b/openssl-install/share/doc/openssl/html/man3/SRP_create_verifier.html deleted file mode 100644 index 745fa7aa..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SRP_create_verifier.html +++ /dev/null @@ -1,122 +0,0 @@ - - - - -SRP_create_verifier - - - - - - - - - - -

NAME

- -

SRP_create_verifier_ex, SRP_create_verifier, SRP_create_verifier_BN_ex, SRP_create_verifier_BN, SRP_check_known_gN_param, SRP_get_default_gN - SRP authentication primitives

- -

SYNOPSIS

- -
#include <openssl/srp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int SRP_create_verifier_BN_ex(const char *user, const char *pass, BIGNUM **salt,
-                              BIGNUM **verifier, const BIGNUM *N,
-                              const BIGNUM *g, OSSL_LIB_CTX *libctx,
-                              const char *propq);
-char *SRP_create_verifier_BN(const char *user, const char *pass, BIGNUM **salt,
-                             BIGNUM **verifier, const BIGNUM *N, const BIGNUM *g);
-char *SRP_create_verifier_ex(const char *user, const char *pass, char **salt,
-                             char **verifier, const char *N, const char *g,
-                             OSSL_LIB_CTX *libctx, const char *propq);
-char *SRP_create_verifier(const char *user, const char *pass, char **salt,
-                          char **verifier, const char *N, const char *g);
-
-char *SRP_check_known_gN_param(const BIGNUM *g, const BIGNUM *N);
-SRP_gN *SRP_get_default_gN(const char *id);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. There are no available replacement functions at this time.

- -

The SRP_create_verifier_BN_ex() function creates an SRP password verifier from the supplied parameters as defined in section 2.4 of RFC 5054 using the library context libctx and property query string propq. Any cryptographic algorithms that need to be fetched will use the libctx and propq. See "ALGORITHM FETCHING" in crypto(7).

- -

SRP_create_verifier_BN() is the same as SRP_create_verifier_BN_ex() except the default library context and property query string is used.

- -

On successful exit *verifier will point to a newly allocated BIGNUM containing the verifier and (if a salt was not provided) *salt will be populated with a newly allocated BIGNUM containing a random salt. If *salt is not NULL then the provided salt is used instead. The caller is responsible for freeing the allocated *salt and *verifier BIGNUMS (use BN_free(3)).

- -

The SRP_create_verifier() function is similar to SRP_create_verifier_BN() but all numeric parameters are in a non-standard base64 encoding originally designed for compatibility with libsrp. This is mainly present for historical compatibility and its use is discouraged. It is possible to pass NULL as N and an SRP group id as g instead to load the appropriate gN values (see SRP_get_default_gN()). If both N and g are NULL the 8192-bit SRP group parameters are used. The caller is responsible for freeing the allocated *salt and *verifier (use OPENSSL_free(3)).

- -

The SRP_check_known_gN_param() function checks that g and N are valid SRP group parameters from RFC 5054 appendix A.

- -

The SRP_get_default_gN() function returns the gN parameters for the RFC 5054 id SRP group size. The known ids are "1024", "1536", "2048", "3072", "4096", "6144" and "8192".

- -

RETURN VALUES

- -

SRP_create_verifier_BN_ex() and SRP_create_verifier_BN() return 1 on success and 0 on failure.

- -

SRP_create_verifier_ex() and SRP_create_verifier() return NULL on failure and a non-NULL value on success: "*" if N is not NULL, the selected group id otherwise. This value should not be freed.

- -

SRP_check_known_gN_param() returns the text representation of the group id (i.e. the prime bit size) or NULL if the arguments are not valid SRP group parameters. This value should not be freed.

- -

SRP_get_default_gN() returns NULL if id is not a valid group size, or the 8192-bit group parameters if id is NULL.

- -

EXAMPLES

- -

Generate and store a 8192 bit password verifier (error handling omitted for clarity):

- -
#include <openssl/bn.h>
-#include <openssl/srp.h>
-
-const char *username = "username";
-const char *password = "password";
-
-SRP_VBASE *srpData = SRP_VBASE_new(NULL);
-
-SRP_gN *gN = SRP_get_default_gN("8192");
-
-BIGNUM *salt = NULL, *verifier = NULL;
-SRP_create_verifier_BN_ex(username, password, &salt, &verifier, gN->N, gN->g,
-                          NULL, NULL);
-
-SRP_user_pwd *pwd = SRP_user_pwd_new();
-SRP_user_pwd_set1_ids(pwd, username, NULL);
-SRP_user_pwd_set0_sv(pwd, salt, verifier);
-SRP_user_pwd_set_gN(pwd, gN->g, gN->N);
-
-SRP_VBASE_add0_user(srpData, pwd);
- -

SEE ALSO

- -

openssl-srp(1), SRP_VBASE_new(3), SRP_user_pwd_new(3)

- -

HISTORY

- -

SRP_create_verifier_BN_ex() and SRP_create_verifier_ex() were introduced in OpenSSL 3.0. All other functions were added in OpenSSL 1.0.1.

- -

All of these functions were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SRP_user_pwd_new.html b/openssl-install/share/doc/openssl/html/man3/SRP_user_pwd_new.html deleted file mode 100644 index 40ed5362..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SRP_user_pwd_new.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -SRP_user_pwd_new - - - - - - - - - - -

NAME

- -

SRP_user_pwd_new, SRP_user_pwd_free, SRP_user_pwd_set1_ids, SRP_user_pwd_set_gN, SRP_user_pwd_set0_sv - Functions to create a record of SRP user verifier information

- -

SYNOPSIS

- -
#include <openssl/srp.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
SRP_user_pwd *SRP_user_pwd_new(void);
-void SRP_user_pwd_free(SRP_user_pwd *user_pwd);
-
-int SRP_user_pwd_set1_ids(SRP_user_pwd *user_pwd, const char *id, const char *info);
-void SRP_user_pwd_set_gN(SRP_user_pwd *user_pwd, const BIGNUM *g, const BIGNUM *N);
-int SRP_user_pwd_set0_sv(SRP_user_pwd *user_pwd, BIGNUM *s, BIGNUM *v);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. There are no available replacement functions at this time.

- -

The SRP_user_pwd_new() function allocates a structure to store a user verifier record.

- -

The SRP_user_pwd_free() function frees up the user_pwd structure. If user_pwd is NULL, nothing is done.

- -

The SRP_user_pwd_set1_ids() function sets the username to id and the optional user info to info for user_pwd. The library allocates new copies of id and info, the caller still owns the original memory.

- -

The SRP_user_pwd_set0_sv() function sets the user salt to s and the verifier to v for user_pwd. The library takes ownership of the values, they should not be freed by the caller.

- -

The SRP_user_pwd_set_gN() function sets the SRP group parameters for user_pwd. The memory is not freed by SRP_user_pwd_free(), the caller must make sure it is freed once it is no longer used.

- -

RETURN VALUES

- -

SRP_user_pwd_set1_ids() returns 1 on success and 0 on failure or if id was NULL.

- -

SRP_user_pwd_set0_sv() returns 1 if both s and v are not NULL, 0 otherwise.

- -

SEE ALSO

- -

openssl-srp(1), SRP_create_verifier(3), SRP_VBASE_new(3), SSL_CTX_set_srp_password(3)

- -

HISTORY

- -

These functions were made public in OpenSSL 3.0 and are deprecated.

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CIPHER_get_name.html b/openssl-install/share/doc/openssl/html/man3/SSL_CIPHER_get_name.html deleted file mode 100644 index a5742073..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CIPHER_get_name.html +++ /dev/null @@ -1,181 +0,0 @@ - - - - -SSL_CIPHER_get_name - - - - - - - - - - -

NAME

- -

SSL_CIPHER_get_name, SSL_CIPHER_standard_name, OPENSSL_cipher_name, SSL_CIPHER_get_bits, SSL_CIPHER_get_version, SSL_CIPHER_description, SSL_CIPHER_get_cipher_nid, SSL_CIPHER_get_digest_nid, SSL_CIPHER_get_handshake_digest, SSL_CIPHER_get_kx_nid, SSL_CIPHER_get_auth_nid, SSL_CIPHER_is_aead, SSL_CIPHER_find, SSL_CIPHER_get_id, SSL_CIPHER_get_protocol_id - get SSL_CIPHER properties

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_CIPHER_get_name(const SSL_CIPHER *cipher);
-const char *SSL_CIPHER_standard_name(const SSL_CIPHER *cipher);
-const char *OPENSSL_cipher_name(const char *stdname);
-int SSL_CIPHER_get_bits(const SSL_CIPHER *cipher, int *alg_bits);
-const char *SSL_CIPHER_get_version(const SSL_CIPHER *cipher);
-char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int size);
-int SSL_CIPHER_get_cipher_nid(const SSL_CIPHER *c);
-int SSL_CIPHER_get_digest_nid(const SSL_CIPHER *c);
-const EVP_MD *SSL_CIPHER_get_handshake_digest(const SSL_CIPHER *c);
-int SSL_CIPHER_get_kx_nid(const SSL_CIPHER *c);
-int SSL_CIPHER_get_auth_nid(const SSL_CIPHER *c);
-int SSL_CIPHER_is_aead(const SSL_CIPHER *c);
-const SSL_CIPHER *SSL_CIPHER_find(SSL *ssl, const unsigned char *ptr);
-uint32_t SSL_CIPHER_get_id(const SSL_CIPHER *c);
-uint32_t SSL_CIPHER_get_protocol_id(const SSL_CIPHER *c);
- -

DESCRIPTION

- -

SSL_CIPHER_get_name() returns a pointer to the name of cipher. If the cipher is NULL, it returns "(NONE)".

- -

SSL_CIPHER_standard_name() returns a pointer to the standard RFC name of cipher. If the cipher is NULL, it returns "(NONE)". If the cipher has no standard name, it returns NULL. If cipher was defined in both SSLv3 and TLS, it returns the TLS name.

- -

OPENSSL_cipher_name() returns a pointer to the OpenSSL name of stdname. If the stdname is NULL, or stdname has no corresponding OpenSSL name, it returns "(NONE)". Where both exist, stdname should be the TLS name rather than the SSLv3 name.

- -

SSL_CIPHER_get_bits() returns the number of secret bits used for cipher. If cipher is NULL, 0 is returned.

- -

SSL_CIPHER_get_version() returns string which indicates the SSL/TLS protocol version that first defined the cipher. It returns "(NONE)" if cipher is NULL.

- -

SSL_CIPHER_get_cipher_nid() returns the cipher NID corresponding to c. If there is no cipher (e.g. for cipher suites with no encryption) then NID_undef is returned.

- -

SSL_CIPHER_get_digest_nid() returns the digest NID corresponding to the MAC used by c during record encryption/decryption. If there is no digest (e.g. for AEAD cipher suites) then NID_undef is returned.

- -

SSL_CIPHER_get_handshake_digest() returns an EVP_MD for the digest used during the SSL/TLS handshake when using the SSL_CIPHER c. Note that this may be different to the digest used to calculate the MAC for encrypted records.

- -

SSL_CIPHER_get_kx_nid() returns the key exchange NID corresponding to the method used by c. If there is no key exchange, then NID_undef is returned. If any appropriate key exchange algorithm can be used (as in the case of TLS 1.3 cipher suites) NID_kx_any is returned. Examples (not comprehensive):

- -
NID_kx_rsa
-NID_kx_ecdhe
-NID_kx_dhe
-NID_kx_psk
- -

SSL_CIPHER_get_auth_nid() returns the authentication NID corresponding to the method used by c. If there is no authentication, then NID_undef is returned. If any appropriate authentication algorithm can be used (as in the case of TLS 1.3 cipher suites) NID_auth_any is returned. Examples (not comprehensive):

- -
NID_auth_rsa
-NID_auth_ecdsa
-NID_auth_psk
- -

SSL_CIPHER_is_aead() returns 1 if the cipher c is AEAD (e.g. GCM or ChaCha20/Poly1305), and 0 if it is not AEAD.

- -

SSL_CIPHER_find() returns a SSL_CIPHER structure which has the cipher ID stored in ptr. The ptr parameter is a two element array of char, which stores the two-byte TLS cipher ID (as allocated by IANA) in network byte order. This parameter is usually retrieved from a TLS packet by using functions like SSL_client_hello_get0_ciphers(3). SSL_CIPHER_find() returns NULL if an error occurs or the indicated cipher is not found.

- -

SSL_CIPHER_get_id() returns the OpenSSL-specific ID of the given cipher c. That ID is not the same as the IANA-specific ID.

- -

SSL_CIPHER_get_protocol_id() returns the two-byte ID used in the TLS protocol of the given cipher c.

- -

SSL_CIPHER_description() returns a textual description of the cipher used into the buffer buf of length len provided. If buf is provided, it must be at least 128 bytes. If buf is NULL it will be allocated using OPENSSL_malloc(). If the provided buffer is too small, or the allocation fails, NULL is returned.

- -

The string returned by SSL_CIPHER_description() consists of several fields separated by whitespace:

- -
- -
<ciphername>
-
- -

Textual representation of the cipher name.

- -
-
<protocol version>
-
- -

The minimum protocol version that the ciphersuite supports, such as TLSv1.2. Note that this is not always the same as the protocol version in which the ciphersuite was first defined because some ciphersuites are backwards compatible with earlier protocol versions.

- -
-
Kx=<key exchange>
-
- -

Key exchange method such as RSA, ECDHE, etc.

- -
-
Au=<authentication>
-
- -

Authentication method such as RSA, None, etc.. None is the representation of anonymous ciphers.

- -
-
Enc=<symmetric encryption method>
-
- -

Encryption method, with number of secret bits, such as AESGCM(128).

- -
-
Mac=<message authentication code>
-
- -

Message digest, such as SHA256.

- -
-
- -

Some examples for the output of SSL_CIPHER_description():

- -
ECDHE-RSA-AES256-GCM-SHA256 TLSv1.2 Kx=ECDH     Au=RSA  Enc=AESGCM(256) Mac=AEAD
-RSA-PSK-AES256-CBC-SHA384 TLSv1.0 Kx=RSAPSK   Au=RSA  Enc=AES(256)  Mac=SHA384
- -

RETURN VALUES

- -

SSL_CIPHER_get_name(), SSL_CIPHER_standard_name(), OPENSSL_cipher_name(), SSL_CIPHER_get_version() and SSL_CIPHER_description() return the corresponding value in a NUL-terminated string for a specific cipher or "(NONE)" if the cipher is not found.

- -

SSL_CIPHER_get_bits() returns a positive integer representing the number of secret bits or 0 if an error occurred.

- -

SSL_CIPHER_get_cipher_nid(), SSL_CIPHER_get_digest_nid(), SSL_CIPHER_get_kx_nid() and SSL_CIPHER_get_auth_nid() return the NID value or NID_undef if an error occurred.

- -

SSL_CIPHER_get_handshake_digest() returns a valid EVP_MD structure or NULL if an error occurred.

- -

SSL_CIPHER_is_aead() returns 1 if the cipher is AEAD or 0 otherwise.

- -

SSL_CIPHER_find() returns a valid SSL_CIPHER structure or NULL if an error occurred.

- -

SSL_CIPHER_get_id() returns a 4-byte integer representing the OpenSSL-specific ID.

- -

SSL_CIPHER_get_protocol_id() returns a 2-byte integer representing the TLS protocol-specific ID.

- -

SEE ALSO

- -

ssl(7), SSL_get_current_cipher(3), SSL_get_ciphers(3), openssl-ciphers(1)

- -

HISTORY

- -

The SSL_CIPHER_get_version() function was updated to always return the correct protocol string in OpenSSL 1.1.0.

- -

The SSL_CIPHER_description() function was changed to return NULL on error, rather than a fixed string, in OpenSSL 1.1.0.

- -

The SSL_CIPHER_get_handshake_digest() function was added in OpenSSL 1.1.1.

- -

The SSL_CIPHER_standard_name() function was globally available in OpenSSL 1.1.1. Before OpenSSL 1.1.1, tracing (enable-ssl-trace argument to Configure) was required to enable this function.

- -

The OPENSSL_cipher_name() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_COMP_add_compression_method.html b/openssl-install/share/doc/openssl/html/man3/SSL_COMP_add_compression_method.html deleted file mode 100644 index c5fa921e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_COMP_add_compression_method.html +++ /dev/null @@ -1,133 +0,0 @@ - - - - -SSL_COMP_add_compression_method - - - - - - - - - - -

NAME

- -

SSL_COMP_add_compression_method, SSL_COMP_get_compression_methods, SSL_COMP_get0_name, SSL_COMP_get_id, SSL_COMP_free_compression_methods - handle SSL/TLS integrated compression methods

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_COMP_add_compression_method(int id, COMP_METHOD *cm);
-STACK_OF(SSL_COMP) *SSL_COMP_get_compression_methods(void);
-const char *SSL_COMP_get0_name(const SSL_COMP *comp);
-int SSL_COMP_get_id(const SSL_COMP *comp);
- -

The following function has been deprecated since OpenSSL 1.1.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void SSL_COMP_free_compression_methods(void);
- -

DESCRIPTION

- -

SSL_COMP_add_compression_method() adds the compression method cm with the identifier id to the list of available compression methods. This list is globally maintained for all SSL operations within this application. It cannot be set for specific SSL_CTX or SSL objects.

- -

SSL_COMP_get_compression_methods() returns a stack of all of the available compression methods or NULL on error.

- -

SSL_COMP_get0_name() returns the name of the compression method comp.

- -

SSL_COMP_get_id() returns the id of the compression method comp.

- -

SSL_COMP_free_compression_methods() releases any resources acquired to maintain the internal table of compression methods.

- -

NOTES

- -

The TLS standard (or SSLv3) allows the integration of compression methods into the communication. The TLS RFC does however not specify compression methods or their corresponding identifiers, so there is currently no compatible way to integrate compression with unknown peers. It is therefore currently not recommended to integrate compression into applications. Applications for non-public use may agree on certain compression methods. Using different compression methods with the same identifier will lead to connection failure.

- -

An OpenSSL client speaking a protocol that allows compression (SSLv3, TLSv1) will unconditionally send the list of all compression methods enabled with SSL_COMP_add_compression_method() to the server during the handshake. Unlike the mechanisms to set a cipher list, there is no method available to restrict the list of compression method on a per connection basis.

- -

An OpenSSL server will match the identifiers listed by a client against its own compression methods and will unconditionally activate compression when a matching identifier is found. There is no way to restrict the list of compression methods supported on a per connection basis.

- -

If enabled during compilation, the OpenSSL library will have the following compression methods available:

- -
- -
COMP_zlib()
-
- -
-
COMP_brotli()
-
- -
-
COMP_brotli_oneshot()
-
- -
-
COMP_zstd()
-
- -
-
COMP_zstd_oneshot()
-
- -
-
- -

RETURN VALUES

- -

SSL_COMP_add_compression_method() may return the following values:

- -
- -
0
-
- -

The operation succeeded.

- -
-
1
-
- -

The operation failed. Check the error queue to find out the reason.

- -
-
- -

SSL_COMP_get_compression_methods() returns the stack of compressions methods or NULL on error.

- -

SSL_COMP_get0_name() returns the name of the compression method or NULL on error.

- -

SSL_COMP_get_id() returns the name of the compression method or -1 on error.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

The SSL_COMP_free_compression_methods() function was deprecated in OpenSSL 1.1.0. The SSL_COMP_get0_name() and SSL_comp_get_id() functions were added in OpenSSL 1.1.0d.

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_new.html deleted file mode 100644 index 1481a124..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_new.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -SSL_CONF_CTX_new - - - - - - - - - - -

NAME

- -

SSL_CONF_CTX_new, SSL_CONF_CTX_free - SSL configuration allocation functions

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL_CONF_CTX *SSL_CONF_CTX_new(void);
-void SSL_CONF_CTX_free(SSL_CONF_CTX *cctx);
- -

DESCRIPTION

- -

The function SSL_CONF_CTX_new() allocates and initialises an SSL_CONF_CTX structure for use with the SSL_CONF functions.

- -

The function SSL_CONF_CTX_free() frees up the context cctx. If cctx is NULL nothing is done.

- -

RETURN VALUES

- -

SSL_CONF_CTX_new() returns either the newly allocated SSL_CONF_CTX structure or NULL if an error occurs.

- -

SSL_CONF_CTX_free() does not return a value.

- -

SEE ALSO

- -

ssl(7), SSL_CONF_CTX_set_flags(3), SSL_CONF_CTX_set_ssl_ctx(3), SSL_CONF_CTX_set1_prefix(3), SSL_CONF_cmd(3), SSL_CONF_cmd_argv(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2012-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set1_prefix.html b/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set1_prefix.html deleted file mode 100644 index f9c2dc1d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set1_prefix.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -SSL_CONF_CTX_set1_prefix - - - - - - - - - - -

NAME

- -

SSL_CONF_CTX_set1_prefix - Set configuration context command prefix

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-unsigned int SSL_CONF_CTX_set1_prefix(SSL_CONF_CTX *cctx, const char *prefix);
- -

DESCRIPTION

- -

The function SSL_CONF_CTX_set1_prefix() sets the command prefix of cctx to prefix. If prefix is NULL it is restored to the default value.

- -

NOTES

- -

Command prefixes alter the commands recognised by subsequent SSL_CONF_cmd() calls. For example for files, if the prefix "SSL" is set then command names such as "SSLProtocol", "SSLOptions" etc. are recognised instead of "Protocol" and "Options". Similarly for command lines if the prefix is "--ssl-" then "--ssl-no_tls1_2" is recognised instead of "-no_tls1_2".

- -

If the SSL_CONF_FLAG_CMDLINE flag is set then prefix checks are case sensitive and "-" is the default. In the unlikely even an application explicitly wants to set no prefix it must be explicitly set to "".

- -

If the SSL_CONF_FLAG_FILE flag is set then prefix checks are case insensitive and no prefix is the default.

- -

RETURN VALUES

- -

SSL_CONF_CTX_set1_prefix() returns 1 for success and 0 for failure.

- -

SEE ALSO

- -

ssl(7), SSL_CONF_CTX_new(3), SSL_CONF_CTX_set_flags(3), SSL_CONF_CTX_set_ssl_ctx(3), SSL_CONF_cmd(3), SSL_CONF_cmd_argv(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2012-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_flags.html b/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_flags.html deleted file mode 100644 index b6a47920..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_flags.html +++ /dev/null @@ -1,105 +0,0 @@ - - - - -SSL_CONF_CTX_set_flags - - - - - - - - - - -

NAME

- -

SSL_CONF_CTX_set_flags, SSL_CONF_CTX_clear_flags - Set or clear SSL configuration context flags

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-unsigned int SSL_CONF_CTX_set_flags(SSL_CONF_CTX *cctx, unsigned int flags);
-unsigned int SSL_CONF_CTX_clear_flags(SSL_CONF_CTX *cctx, unsigned int flags);
- -

DESCRIPTION

- -

The function SSL_CONF_CTX_set_flags() sets flags in the context cctx.

- -

The function SSL_CONF_CTX_clear_flags() clears flags in the context cctx.

- -

NOTES

- -

The flags set affect how subsequent calls to SSL_CONF_cmd() or SSL_CONF_argv() behave.

- -

Currently the following flags values are recognised:

- -
- -
SSL_CONF_FLAG_CMDLINE, SSL_CONF_FLAG_FILE
-
- -

recognise options intended for command line or configuration file use. At least one of these flags must be set.

- -
-
SSL_CONF_FLAG_CLIENT, SSL_CONF_FLAG_SERVER
-
- -

recognise options intended for use in SSL/TLS clients or servers. One or both of these flags must be set.

- -
-
SSL_CONF_FLAG_CERTIFICATE
-
- -

recognise certificate and private key options.

- -
-
SSL_CONF_FLAG_REQUIRE_PRIVATE
-
- -

If this option is set then if a private key is not specified for a certificate it will attempt to load a private key from the certificate file when SSL_CONF_CTX_finish() is called. If a key cannot be loaded from the certificate file an error occurs.

- -
-
SSL_CONF_FLAG_SHOW_ERRORS
-
- -

indicate errors relating to unrecognised options or missing arguments in the error queue. If this option isn't set such errors are only reflected in the return values of SSL_CONF_set_cmd() or SSL_CONF_set_argv()

- -
-
- -

RETURN VALUES

- -

SSL_CONF_CTX_set_flags() and SSL_CONF_CTX_clear_flags() returns the new flags value after setting or clearing flags.

- -

SEE ALSO

- -

ssl(7), SSL_CONF_CTX_new(3), SSL_CONF_CTX_set_ssl_ctx(3), SSL_CONF_CTX_set1_prefix(3), SSL_CONF_cmd(3), SSL_CONF_cmd_argv(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2012-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_ssl_ctx.html b/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_ssl_ctx.html deleted file mode 100644 index e117ba7b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_CTX_set_ssl_ctx.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -SSL_CONF_CTX_set_ssl_ctx - - - - - - - - - - -

NAME

- -

SSL_CONF_CTX_finish, SSL_CONF_CTX_set_ssl_ctx, SSL_CONF_CTX_set_ssl - set context to configure

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CONF_CTX_set_ssl_ctx(SSL_CONF_CTX *cctx, SSL_CTX *ctx);
-void SSL_CONF_CTX_set_ssl(SSL_CONF_CTX *cctx, SSL *ssl);
-int SSL_CONF_CTX_finish(SSL_CONF_CTX *cctx);
- -

DESCRIPTION

- -

SSL_CONF_CTX_set_ssl_ctx() sets the context associated with cctx to the SSL_CTX structure ctx. Any previous SSL or SSL_CTX associated with cctx is cleared. Subsequent calls to SSL_CONF_cmd() will be sent to ctx.

- -

SSL_CONF_CTX_set_ssl() sets the context associated with cctx to the SSL structure ssl. Any previous SSL or SSL_CTX associated with cctx is cleared. Subsequent calls to SSL_CONF_cmd() will be sent to ssl.

- -

The function SSL_CONF_CTX_finish() must be called after all configuration operations have been completed. It is used to finalise any operations or to process defaults.

- -

NOTES

- -

The context need not be set or it can be set to NULL in which case only syntax checking of commands is performed, where possible.

- -

RETURN VALUES

- -

SSL_CONF_CTX_set_ssl_ctx() and SSL_CTX_set_ssl() do not return a value.

- -

SSL_CONF_CTX_finish() returns 1 for success and 0 for failure.

- -

SEE ALSO

- -

ssl(7), SSL_CONF_CTX_new(3), SSL_CONF_CTX_set_flags(3), SSL_CONF_CTX_set1_prefix(3), SSL_CONF_cmd(3), SSL_CONF_cmd_argv(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2012-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd.html b/openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd.html deleted file mode 100644 index 2cdedfce..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd.html +++ /dev/null @@ -1,652 +0,0 @@ - - - - -SSL_CONF_cmd - - - - - - - - - - -

NAME

- -

SSL_CONF_cmd_value_type, SSL_CONF_cmd - send configuration command

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CONF_cmd(SSL_CONF_CTX *ctx, const char *option, const char *value);
-int SSL_CONF_cmd_value_type(SSL_CONF_CTX *ctx, const char *option);
- -

DESCRIPTION

- -

The function SSL_CONF_cmd() performs configuration operation option with optional parameter value on ctx. Its purpose is to simplify application configuration of SSL_CTX or SSL structures by providing a common framework for command line options or configuration files.

- -

SSL_CONF_cmd_value_type() returns the type of value that option refers to.

- -

SUPPORTED COMMAND LINE COMMANDS

- -

Currently supported option names for command lines (i.e. when the flag SSL_CONF_FLAG_CMDLINE is set) are listed below. Note: all option names are case sensitive. Unless otherwise stated commands can be used by both clients and servers and the value parameter is not used. The default prefix for command line commands is - and that is reflected below.

- -
- -
-bugs
-
- -

Various bug workarounds are set, same as setting SSL_OP_ALL.

- -
-
-no_comp
-
- -

Disables support for SSL/TLS compression, same as setting SSL_OP_NO_COMPRESSION. As of OpenSSL 1.1.0, compression is off by default.

- -
-
-comp
-
- -

Enables support for SSL/TLS compression, same as clearing SSL_OP_NO_COMPRESSION. This command was introduced in OpenSSL 1.1.0. As of OpenSSL 1.1.0, compression is off by default. TLS compression can only be used in security level 1 or lower. From OpenSSL 3.2.0 and above the default security level is 2, so this option will have no effect without also changing the security level. See SSL_CTX_set_security_level(3).

- -
-
-no_ticket
-
- -

Disables support for session tickets, same as setting SSL_OP_NO_TICKET.

- -
-
-serverpref
-
- -

Use server and not client preference order when determining which cipher suite, signature algorithm or elliptic curve to use for an incoming connection. Equivalent to SSL_OP_CIPHER_SERVER_PREFERENCE. Only used by servers.

- -
-
-client_renegotiation
-
- -

Allows servers to accept client-initiated renegotiation. Equivalent to setting SSL_OP_ALLOW_CLIENT_RENEGOTIATION. Only used by servers.

- -
-
-legacy_renegotiation
-
- -

Permits the use of unsafe legacy renegotiation. Equivalent to setting SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION.

- -
-
-no_renegotiation
-
- -

Disables all attempts at renegotiation in (D)TLSv1.2 and earlier, same as setting SSL_OP_NO_RENEGOTIATION.

- -
-
-no_resumption_on_reneg
-
- -

Sets SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION. Only used by servers.

- -
-
-legacy_server_connect, -no_legacy_server_connect
-
- -

Permits or prohibits the use of unsafe legacy renegotiation for OpenSSL clients only. Equivalent to setting or clearing SSL_OP_LEGACY_SERVER_CONNECT.

- -
-
-prioritize_chacha
-
- -

Prioritize ChaCha ciphers when the client has a ChaCha20 cipher at the top of its preference list. This usually indicates a client without AES hardware acceleration (e.g. mobile) is in use. Equivalent to SSL_OP_PRIORITIZE_CHACHA. Only used by servers. Requires -serverpref.

- -
-
-allow_no_dhe_kex
-
- -

In TLSv1.3 allow a non-(ec)dhe based key exchange mode on resumption. This means that there will be no forward secrecy for the resumed session.

- -
-
-prefer_no_dhe_kex
-
- -

In TLSv1.3, on resumption let the server prefer a non-(ec)dhe based key exchange mode over an (ec)dhe based one. Requires -allow_no_dhe_kex. Equivalent to SSL_OP_PREFER_NO_DHE_KEX. Only used by servers.

- -
-
-strict
-
- -

Enables strict mode protocol handling. Equivalent to setting SSL_CERT_FLAG_TLS_STRICT.

- -
-
-sigalgs algs
-
- -

This sets the supported signature algorithms for TLSv1.2 and TLSv1.3. For clients this value is used directly for the supported signature algorithms extension. For servers it is used to determine which signature algorithms to support.

- -

The algs argument should be a colon separated list of signature algorithms in order of decreasing preference of the form algorithm+hash or signature_scheme. For the default providers shipped with OpenSSL, algorithm is one of RSA, DSA or ECDSA and hash is a supported algorithm OID short name such as SHA1, SHA224, SHA256, SHA384 or SHA512. Note: algorithm and hash names are case sensitive. signature_scheme is one of the signature schemes defined in TLSv1.3, specified using the IETF name, e.g., ecdsa_secp256r1_sha256, ed25519, or rsa_pss_pss_sha256. Additional providers may make available further algorithms via the TLS_SIGALG capability. See "CAPABILITIES" in provider-base(7).

- -

If this option is not set then all signature algorithms supported by all activated providers are permissible.

- -

Note: algorithms which specify a PKCS#1 v1.5 signature scheme (either by using RSA as the algorithm or by using one of the rsa_pkcs1_* identifiers) are ignored in TLSv1.3 and will not be negotiated.

- -
-
-client_sigalgs algs
-
- -

This sets the supported signature algorithms associated with client authentication for TLSv1.2 and TLSv1.3. For servers the algs is used in the signature_algorithms field of a CertificateRequest message. For clients it is used to determine which signature algorithm to use with the client certificate. If a server does not request a certificate this option has no effect.

- -

The syntax of algs is identical to -sigalgs. If not set, then the value set for -sigalgs will be used instead.

- -
-
-groups groups
-
- -

This sets the supported groups. For clients, the groups are sent using the supported groups extension. For servers, it is used to determine which group to use. This setting affects groups used for signatures (in TLSv1.2 and earlier) and key exchange. The first group listed will also be used for the key_share sent by a client in a TLSv1.3 ClientHello.

- -

The groups argument is a colon separated list of groups. The group can be either the NIST name (e.g. P-256), some other commonly used name where applicable (e.g. X25519, ffdhe2048) or an OpenSSL OID name (e.g. prime256v1). Group names are case sensitive. The list should be in order of preference with the most preferred group first.

- -

Currently supported groups for TLSv1.3 are P-256, P-384, P-521, X25519, X448, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192.

- -
-
-curves groups
-
- -

This is a synonym for the -groups command.

- -
-
-named_curve curve
-
- -

This sets the temporary curve used for ephemeral ECDH modes. Only used by servers.

- -
-
-tx_cert_comp
-
- -

Enables support for sending TLSv1.3 compressed certificates.

- -
-
-no_tx_cert_comp
-
- -

Disables support for sending TLSv1.3 compressed certificates.

- -
-
-rx_cert_comp
-
- -

Enables support for receiving TLSv1.3 compressed certificates.

- -
-
-no_rx_cert_comp
-
- -

Disables support for receiving TLSv1.3 compressed certificates.

- -
-
-comp
-
- -

The groups argument is a curve name or the special value auto which picks an appropriate curve based on client and server preferences. The curve can be either the NIST name (e.g. P-256) or an OpenSSL OID name (e.g. prime256v1). Curve names are case sensitive.

- -
-
-cipher ciphers
-
- -

Sets the TLSv1.2 and below ciphersuite list to ciphers. This list will be combined with any configured TLSv1.3 ciphersuites. Note: syntax checking of ciphers is currently not performed unless a SSL or SSL_CTX structure is associated with ctx.

- -
-
-ciphersuites 1.3ciphers
-
- -

Sets the available ciphersuites for TLSv1.3 to value. This is a colon-separated list of TLSv1.3 ciphersuite names in order of preference. This list will be combined any configured TLSv1.2 and below ciphersuites. See openssl-ciphers(1) for more information.

- -
-
-min_protocol minprot, -max_protocol maxprot
-
- -

Sets the minimum and maximum supported protocol. Currently supported protocol values are SSLv3, TLSv1, TLSv1.1, TLSv1.2, TLSv1.3 for TLS; DTLSv1, DTLSv1.2 for DTLS, and None for no limit. If either the lower or upper bound is not specified then only the other bound applies, if specified. If your application supports both TLS and DTLS you can specify any of these options twice, once with a bound for TLS and again with an appropriate bound for DTLS. To restrict the supported protocol versions use these commands rather than the deprecated alternative commands below.

- -
-
-record_padding padding
-
- -

Controls use of TLSv1.3 record layer padding. padding is a string of the form "number[,number]" where the (required) first number is the padding block size (in octets) for application data, and the optional second number is the padding block size for handshake and alert messages. If the optional second number is omitted, the same padding will be applied to all messages.

- -

Padding attempts to pad TLSv1.3 records so that they are a multiple of the set length on send. A value of 0 or 1 turns off padding as relevant. Otherwise, the values must be >1 or <=16384.

- -
-
-debug_broken_protocol
-
- -

Ignored.

- -
-
-no_middlebox
-
- -

Turn off "middlebox compatibility", as described below.

- -
-
- -

Additional Options

- -

The following options are accepted by SSL_CONF_cmd(), but are not processed by the OpenSSL commands.

- -
- -
-cert file
-
- -

Attempts to use file as the certificate for the appropriate context. It currently uses SSL_CTX_use_certificate_chain_file() if an SSL_CTX structure is set or SSL_use_certificate_file() with filetype PEM if an SSL structure is set. This option is only supported if certificate operations are permitted.

- -
-
-key file
-
- -

Attempts to use file as the private key for the appropriate context. This option is only supported if certificate operations are permitted. Note: if no -key option is set then a private key is not loaded unless the flag SSL_CONF_FLAG_REQUIRE_PRIVATE is set.

- -
-
-dhparam file
-
- -

Attempts to use file as the set of temporary DH parameters for the appropriate context. This option is only supported if certificate operations are permitted.

- -
-
-no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3
-
- -

Disables protocol support for SSLv3, TLSv1.0, TLSv1.1, TLSv1.2 or TLSv1.3 by setting the corresponding options SSL_OP_NO_SSLv3, SSL_OP_NO_TLSv1, SSL_OP_NO_TLSv1_1, SSL_OP_NO_TLSv1_2 and SSL_OP_NO_TLSv1_3 respectively. These options are deprecated, use -min_protocol and -max_protocol instead.

- -
-
-anti_replay, -no_anti_replay
-
- -

Switches replay protection, on or off respectively. With replay protection on, OpenSSL will automatically detect if a session ticket has been used more than once, TLSv1.3 has been negotiated, and early data is enabled on the server. A full handshake is forced if a session ticket is used a second or subsequent time. Anti-Replay is on by default unless overridden by a configuration file and is only used by servers. Anti-replay measures are required for compliance with the TLSv1.3 specification. Some applications may be able to mitigate the replay risks in other ways and in such cases the built-in OpenSSL functionality is not required. Switching off anti-replay is equivalent to SSL_OP_NO_ANTI_REPLAY.

- -
-
- -

SUPPORTED CONFIGURATION FILE COMMANDS

- -

Currently supported option names for configuration files (i.e., when the flag SSL_CONF_FLAG_FILE is set) are listed below. All configuration file option names are case insensitive so signaturealgorithms is recognised as well as SignatureAlgorithms. Unless otherwise stated the value names are also case insensitive.

- -

Note: the command prefix (if set) alters the recognised option values.

- -
- -
CipherString
-
- -

Sets the ciphersuite list for TLSv1.2 and below to value. This list will be combined with any configured TLSv1.3 ciphersuites. Note: syntax checking of value is currently not performed unless an SSL or SSL_CTX structure is associated with ctx.

- -
-
Ciphersuites
-
- -

Sets the available ciphersuites for TLSv1.3 to value. This is a colon-separated list of TLSv1.3 ciphersuite names in order of preference. This list will be combined any configured TLSv1.2 and below ciphersuites. See openssl-ciphers(1) for more information.

- -
-
Certificate
-
- -

Attempts to use the file value as the certificate for the appropriate context. It currently uses SSL_CTX_use_certificate_chain_file() if an SSL_CTX structure is set or SSL_use_certificate_file() with filetype PEM if an SSL structure is set. This option is only supported if certificate operations are permitted.

- -
-
PrivateKey
-
- -

Attempts to use the file value as the private key for the appropriate context. This option is only supported if certificate operations are permitted. Note: if no PrivateKey option is set then a private key is not loaded unless the SSL_CONF_FLAG_REQUIRE_PRIVATE is set.

- -
-
ChainCAFile, ChainCAPath, VerifyCAFile, VerifyCAPath
-
- -

These options indicate a file or directory used for building certificate chains or verifying certificate chains. These options are only supported if certificate operations are permitted.

- -
-
RequestCAFile
-
- -

This option indicates a file containing a set of certificates in PEM form. The subject names of the certificates are sent to the peer in the certificate_authorities extension for TLS 1.3 (in ClientHello or CertificateRequest) or in a certificate request for previous versions or TLS.

- -
-
ServerInfoFile
-
- -

Attempts to use the file value in the "serverinfo" extension using the function SSL_CTX_use_serverinfo_file.

- -
-
DHParameters
-
- -

Attempts to use the file value as the set of temporary DH parameters for the appropriate context. This option is only supported if certificate operations are permitted.

- -
-
RecordPadding
-
- -

Controls use of TLSv1.3 record layer padding. value is a string of the form "number[,number]" where the (required) first number is the padding block size (in octets) for application data, and the optional second number is the padding block size for handshake and alert messages. If the optional second number is omitted, the same padding will be applied to all messages.

- -

Padding attempts to pad TLSv1.3 records so that they are a multiple of the set length on send. A value of 0 or 1 turns off padding as relevant. Otherwise, the values must be >1 or <=16384.

- -
-
SignatureAlgorithms
-
- -

This sets the supported signature algorithms for TLSv1.2 and TLSv1.3. For clients this value is used directly for the supported signature algorithms extension. For servers it is used to determine which signature algorithms to support.

- -

The value argument should be a colon separated list of signature algorithms in order of decreasing preference of the form algorithm+hash or signature_scheme. For the default providers shipped with OpenSSL, algorithm is one of RSA, DSA or ECDSA and hash is a supported algorithm OID short name such as SHA1, SHA224, SHA256, SHA384 or SHA512. Note: algorithm and hash names are case sensitive. signature_scheme is one of the signature schemes defined in TLSv1.3, specified using the IETF name, e.g., ecdsa_secp256r1_sha256, ed25519, or rsa_pss_pss_sha256. Additional providers may make available further algorithms via the TLS_SIGALG capability. See "CAPABILITIES" in provider-base(7).

- -

If this option is not set then all signature algorithms supported by all activated providers are permissible.

- -

Note: algorithms which specify a PKCS#1 v1.5 signature scheme (either by using RSA as the algorithm or by using one of the rsa_pkcs1_* identifiers) are ignored in TLSv1.3 and will not be negotiated.

- -
-
ClientSignatureAlgorithms
-
- -

This sets the supported signature algorithms associated with client authentication for TLSv1.2 and TLSv1.3. For servers the value is used in the signature_algorithms field of a CertificateRequest message. For clients it is used to determine which signature algorithm to use with the client certificate. If a server does not request a certificate this option has no effect.

- -

The syntax of value is identical to SignatureAlgorithms. If not set then the value set for SignatureAlgorithms will be used instead.

- -
-
Groups
-
- -

This sets the supported groups. For clients, the groups are sent using the supported groups extension. For servers, it is used to determine which group to use. This setting affects groups used for signatures (in TLSv1.2 and earlier) and key exchange. The first group listed will also be used for the key_share sent by a client in a TLSv1.3 ClientHello.

- -

The value argument is a colon separated list of groups. The group can be either the NIST name (e.g. P-256), some other commonly used name where applicable (e.g. X25519, ffdhe2048) or an OpenSSL OID name (e.g. prime256v1). Group names are case sensitive. The list should be in order of preference with the most preferred group first.

- -

Currently supported groups for TLSv1.3 are P-256, P-384, P-521, X25519, X448, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144, ffdhe8192.

- -
-
Curves
-
- -

This is a synonym for the "Groups" command.

- -
-
MinProtocol
-
- -

This sets the minimum supported SSL, TLS or DTLS version.

- -

Currently supported protocol values are SSLv3, TLSv1, TLSv1.1, TLSv1.2, TLSv1.3, DTLSv1 and DTLSv1.2. The SSL and TLS bounds apply only to TLS-based contexts, while the DTLS bounds apply only to DTLS-based contexts. The command can be repeated with one instance setting a TLS bound, and the other setting a DTLS bound. The value None applies to both types of contexts and disables the limits.

- -
-
MaxProtocol
-
- -

This sets the maximum supported SSL, TLS or DTLS version.

- -

Currently supported protocol values are SSLv3, TLSv1, TLSv1.1, TLSv1.2, TLSv1.3, DTLSv1 and DTLSv1.2. The SSL and TLS bounds apply only to TLS-based contexts, while the DTLS bounds apply only to DTLS-based contexts. The command can be repeated with one instance setting a TLS bound, and the other setting a DTLS bound. The value None applies to both types of contexts and disables the limits.

- -
-
Protocol
-
- -

This can be used to enable or disable certain versions of the SSL, TLS or DTLS protocol.

- -

The value argument is a comma separated list of supported protocols to enable or disable. If a protocol is preceded by - that version is disabled.

- -

All protocol versions are enabled by default. You need to disable at least one protocol version for this setting have any effect. Only enabling some protocol versions does not disable the other protocol versions.

- -

Currently supported protocol values are SSLv3, TLSv1, TLSv1.1, TLSv1.2, TLSv1.3, DTLSv1 and DTLSv1.2. The special value ALL refers to all supported versions.

- -

This can't enable protocols that are disabled using MinProtocol or MaxProtocol, but can disable protocols that are still allowed by them.

- -

The Protocol command is fragile and deprecated; do not use it. Use MinProtocol and MaxProtocol instead. If you do use Protocol, make sure that the resulting range of enabled protocols has no "holes", e.g. if TLS 1.0 and TLS 1.2 are both enabled, make sure to also leave TLS 1.1 enabled.

- -
-
Options
-
- -

The value argument is a comma separated list of various flags to set. If a flag string is preceded - it is disabled. See the SSL_CTX_set_options(3) function for more details of individual options.

- -

Each option is listed below. Where an operation is enabled by default the -flag syntax is needed to disable it.

- -

SessionTicket: session ticket support, enabled by default. Inverse of SSL_OP_NO_TICKET: that is -SessionTicket is the same as setting SSL_OP_NO_TICKET.

- -

Compression: SSL/TLS compression support, disabled by default. Inverse of SSL_OP_NO_COMPRESSION.

- -

EmptyFragments: use empty fragments as a countermeasure against a SSL 3.0/TLS 1.0 protocol vulnerability affecting CBC ciphers. It is set by default. Inverse of SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS.

- -

Bugs: enable various bug workarounds. Same as SSL_OP_ALL.

- -

DHSingle: enable single use DH keys, set by default. Inverse of SSL_OP_DH_SINGLE. Only used by servers.

- -

ECDHSingle: enable single use ECDH keys, set by default. Inverse of SSL_OP_ECDH_SINGLE. Only used by servers.

- -

ServerPreference: use server and not client preference order when determining which cipher suite, signature algorithm or elliptic curve to use for an incoming connection. Equivalent to SSL_OP_CIPHER_SERVER_PREFERENCE. Only used by servers.

- -

PrioritizeChaCha: prioritizes ChaCha ciphers when the client has a ChaCha20 cipher at the top of its preference list. This usually indicates a mobile client is in use. Equivalent to SSL_OP_PRIORITIZE_CHACHA. Only used by servers.

- -

NoResumptionOnRenegotiation: set SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION flag. Only used by servers.

- -

NoRenegotiation: disables all attempts at renegotiation in TLSv1.2 and earlier, same as setting SSL_OP_NO_RENEGOTIATION.

- -

UnsafeLegacyRenegotiation: permits the use of unsafe legacy renegotiation. Equivalent to SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION.

- -

UnsafeLegacyServerConnect: permits the use of unsafe legacy renegotiation for OpenSSL clients only. Equivalent to SSL_OP_LEGACY_SERVER_CONNECT.

- -

EncryptThenMac: use encrypt-then-mac extension, enabled by default. Inverse of SSL_OP_NO_ENCRYPT_THEN_MAC: that is, -EncryptThenMac is the same as setting SSL_OP_NO_ENCRYPT_THEN_MAC.

- -

AllowNoDHEKEX: In TLSv1.3 allow a non-(ec)dhe based key exchange mode on resumption. This means that there will be no forward secrecy for the resumed session. Equivalent to SSL_OP_ALLOW_NO_DHE_KEX.

- -

PreferNoDHEKEX: In TLSv1.3, on resumption let the server prefer a non-(ec)dhe based key exchange mode over an (ec)dhe based one. Requires AllowNoDHEKEX. Equivalent to SSL_OP_PREFER_NO_DHE_KEX. Only used by servers.

- -

MiddleboxCompat: If set then dummy Change Cipher Spec (CCS) messages are sent in TLSv1.3. This has the effect of making TLSv1.3 look more like TLSv1.2 so that middleboxes that do not understand TLSv1.3 will not drop the connection. This option is set by default. A future version of OpenSSL may not set this by default. Equivalent to SSL_OP_ENABLE_MIDDLEBOX_COMPAT.

- -

AntiReplay: If set then OpenSSL will automatically detect if a session ticket has been used more than once, TLSv1.3 has been negotiated, and early data is enabled on the server. A full handshake is forced if a session ticket is used a second or subsequent time. This option is set by default and is only used by servers. Anti-replay measures are required to comply with the TLSv1.3 specification. Some applications may be able to mitigate the replay risks in other ways and in such cases the built-in OpenSSL functionality is not required. Disabling anti-replay is equivalent to setting SSL_OP_NO_ANTI_REPLAY.

- -

ExtendedMasterSecret: use extended master secret extension, enabled by default. Inverse of SSL_OP_NO_EXTENDED_MASTER_SECRET: that is, -ExtendedMasterSecret is the same as setting SSL_OP_NO_EXTENDED_MASTER_SECRET.

- -

CANames: use CA names extension, enabled by default. Inverse of SSL_OP_DISABLE_TLSEXT_CA_NAMES: that is, -CANames is the same as setting SSL_OP_DISABLE_TLSEXT_CA_NAMES.

- -

KTLS: Enables kernel TLS if support has been compiled in, and it is supported by the negotiated ciphersuites and extensions. Equivalent to SSL_OP_ENABLE_KTLS.

- -

StrictCertCheck: Enable strict certificate checking. Equivalent to setting SSL_CERT_FLAG_TLS_STRICT with SSL_CTX_set_cert_flags().

- -

TxCertificateCompression: support sending compressed certificates, enabled by default. Inverse of SSL_OP_NO_TX_CERTIFICATE_COMPRESSION: that is, -TxCertificateCompression is the same as setting SSL_OP_NO_TX_CERTIFICATE_COMPRESSION.

- -

RxCertificateCompression: support receiving compressed certificates, enabled by default. Inverse of SSL_OP_NO_RX_CERTIFICATE_COMPRESSION: that is, -RxCertificateCompression is the same as setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION.

- -

KTLSTxZerocopySendfile: use the zerocopy TX mode of sendfile(), which gives a performance boost when used with KTLS hardware offload. Note that invalid TLS records might be transmitted if the file is changed while being sent. This option has no effect if KTLS is not enabled. Equivalent to SSL_OP_ENABLE_KTLS_TX_ZEROCOPY_SENDFILE. This option only applies to Linux. KTLS sendfile on FreeBSD doesn't offer an option to disable zerocopy and always runs in this mode.

- -

IgnoreUnexpectedEOF: Equivalent to SSL_OP_IGNORE_UNEXPECTED_EOF. You should only enable this option if the protocol running over TLS can detect a truncation attack itself, and that the application is checking for that truncation attack.

- -
-
VerifyMode
-
- -

The value argument is a comma separated list of flags to set.

- -

Peer enables peer verification: for clients only.

- -

Request requests but does not require a certificate from the client. Servers only.

- -

Require requests and requires a certificate from the client: an error occurs if the client does not present a certificate. Servers only.

- -

Once requests a certificate from a client only on the initial connection: not when renegotiating. Servers only.

- -

RequestPostHandshake configures the connection to support requests but does not require a certificate from the client post-handshake. A certificate will not be requested during the initial handshake. The server application must provide a mechanism to request a certificate post-handshake. Servers only. TLSv1.3 only.

- -

RequiresPostHandshake configures the connection to support requests and requires a certificate from the client post-handshake: an error occurs if the client does not present a certificate. A certificate will not be requested during the initial handshake. The server application must provide a mechanism to request a certificate post-handshake. Servers only. TLSv1.3 only.

- -
-
ClientCAFile, ClientCAPath
-
- -

A file or directory of certificates in PEM format whose names are used as the set of acceptable names for client CAs. Servers only. This option is only supported if certificate operations are permitted.

- -
-
- -

SUPPORTED COMMAND TYPES

- -

The function SSL_CONF_cmd_value_type() currently returns one of the following types:

- -
- -
SSL_CONF_TYPE_UNKNOWN
-
- -

The option string is unrecognised, this return value can be use to flag syntax errors.

- -
-
SSL_CONF_TYPE_STRING
-
- -

The value is a string without any specific structure.

- -
-
SSL_CONF_TYPE_FILE
-
- -

The value is a filename.

- -
-
SSL_CONF_TYPE_DIR
-
- -

The value is a directory name.

- -
-
SSL_CONF_TYPE_NONE
-
- -

The value string is not used e.g. a command line option which doesn't take an argument.

- -
-
- -

NOTES

- -

The order of operations is significant. This can be used to set either defaults or values which cannot be overridden. For example if an application calls:

- -
SSL_CONF_cmd(ctx, "Protocol", "-SSLv3");
-SSL_CONF_cmd(ctx, userparam, uservalue);
- -

it will disable SSLv3 support by default but the user can override it. If however the call sequence is:

- -
SSL_CONF_cmd(ctx, userparam, uservalue);
-SSL_CONF_cmd(ctx, "Protocol", "-SSLv3");
- -

SSLv3 is always disabled and attempt to override this by the user are ignored.

- -

By checking the return code of SSL_CONF_cmd() it is possible to query if a given option is recognised, this is useful if SSL_CONF_cmd() values are mixed with additional application specific operations.

- -

For example an application might call SSL_CONF_cmd() and if it returns -2 (unrecognised command) continue with processing of application specific commands.

- -

Applications can also use SSL_CONF_cmd() to process command lines though the utility function SSL_CONF_cmd_argv() is normally used instead. One way to do this is to set the prefix to an appropriate value using SSL_CONF_CTX_set1_prefix(), pass the current argument to option and the following argument to value (which may be NULL).

- -

In this case if the return value is positive then it is used to skip that number of arguments as they have been processed by SSL_CONF_cmd(). If -2 is returned then option is not recognised and application specific arguments can be checked instead. If -3 is returned a required argument is missing and an error is indicated. If 0 is returned some other error occurred and this can be reported back to the user.

- -

The function SSL_CONF_cmd_value_type() can be used by applications to check for the existence of a command or to perform additional syntax checking or translation of the command value. For example if the return value is SSL_CONF_TYPE_FILE an application could translate a relative pathname to an absolute pathname.

- -

RETURN VALUES

- -

SSL_CONF_cmd() returns 1 if the value of option is recognised and value is NOT used and 2 if both option and value are used. In other words it returns the number of arguments processed. This is useful when processing command lines.

- -

A return value of -2 means option is not recognised.

- -

A return value of -3 means option is recognised and the command requires a value but value is NULL.

- -

A return code of 0 indicates that both option and value are valid but an error occurred attempting to perform the operation: for example due to an error in the syntax of value in this case the error queue may provide additional information.

- -

EXAMPLES

- -

Set supported signature algorithms:

- -
SSL_CONF_cmd(ctx, "SignatureAlgorithms", "ECDSA+SHA256:RSA+SHA256:DSA+SHA256");
- -

There are various ways to select the supported protocols.

- -

This set the minimum protocol version to TLSv1, and so disables SSLv3. This is the recommended way to disable protocols.

- -
SSL_CONF_cmd(ctx, "MinProtocol", "TLSv1");
- -

The following also disables SSLv3:

- -
SSL_CONF_cmd(ctx, "Protocol", "-SSLv3");
- -

The following will first enable all protocols, and then disable SSLv3. If no protocol versions were disabled before this has the same effect as "-SSLv3", but if some versions were disables this will re-enable them before disabling SSLv3.

- -
SSL_CONF_cmd(ctx, "Protocol", "ALL,-SSLv3");
- -

Only enable TLSv1.2:

- -
SSL_CONF_cmd(ctx, "MinProtocol", "TLSv1.2");
-SSL_CONF_cmd(ctx, "MaxProtocol", "TLSv1.2");
- -

This also only enables TLSv1.2:

- -
SSL_CONF_cmd(ctx, "Protocol", "-ALL,TLSv1.2");
- -

Disable TLS session tickets:

- -
SSL_CONF_cmd(ctx, "Options", "-SessionTicket");
- -

Enable compression:

- -
SSL_CONF_cmd(ctx, "Options", "Compression");
- -

Set supported curves to P-256, P-384:

- -
SSL_CONF_cmd(ctx, "Curves", "P-256:P-384");
- -

SEE ALSO

- -

ssl(7), SSL_CONF_CTX_new(3), SSL_CONF_CTX_set_flags(3), SSL_CONF_CTX_set1_prefix(3), SSL_CONF_CTX_set_ssl_ctx(3), SSL_CONF_cmd_argv(3), SSL_CTX_set_options(3)

- -

HISTORY

- -

The SSL_CONF_cmd() function was added in OpenSSL 1.0.2.

- -

The SSL_OP_NO_SSL2 option doesn't have effect since 1.1.0, but the macro is retained for backwards compatibility.

- -

The SSL_CONF_TYPE_NONE was added in OpenSSL 1.1.0. In earlier versions of OpenSSL passing a command which didn't take an argument would return SSL_CONF_TYPE_UNKNOWN.

- -

MinProtocol and MaxProtocol where added in OpenSSL 1.1.0.

- -

AllowNoDHEKEX and PrioritizeChaCha were added in OpenSSL 1.1.1.

- -

The UnsafeLegacyServerConnect option is no longer set by default from OpenSSL 3.0.

- -

The TxCertificateCompression and RxCertificateCompression options were added in OpenSSL 3.2.

- -

PreferNoDHEKEX was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2012-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd_argv.html b/openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd_argv.html deleted file mode 100644 index 9f826994..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CONF_cmd_argv.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -SSL_CONF_cmd_argv - - - - - - - - - - -

NAME

- -

SSL_CONF_cmd_argv - SSL configuration command line processing

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CONF_cmd_argv(SSL_CONF_CTX *cctx, int *pargc, char ***pargv);
- -

DESCRIPTION

- -

The function SSL_CONF_cmd_argv() processes at most two command line arguments from pargv and pargc. The values of pargv and pargc are updated to reflect the number of command options processed. The pargc argument can be set to NULL if it is not used.

- -

RETURN VALUES

- -

SSL_CONF_cmd_argv() returns the number of command arguments processed: 0, 1, 2 or a negative error code.

- -

If -2 is returned then an argument for a command is missing.

- -

If -1 is returned the command is recognised but couldn't be processed due to an error: for example a syntax error in the argument.

- -

SEE ALSO

- -

ssl(7), SSL_CONF_CTX_new(3), SSL_CONF_CTX_set_flags(3), SSL_CONF_CTX_set1_prefix(3), SSL_CONF_CTX_set_ssl_ctx(3), SSL_CONF_cmd(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2012-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add1_chain_cert.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add1_chain_cert.html deleted file mode 100644 index 4582801e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add1_chain_cert.html +++ /dev/null @@ -1,122 +0,0 @@ - - - - -SSL_CTX_add1_chain_cert - - - - - - - - - - -

NAME

- -

SSL_CTX_set0_chain, SSL_CTX_set1_chain, SSL_CTX_add0_chain_cert, SSL_CTX_add1_chain_cert, SSL_CTX_get0_chain_certs, SSL_CTX_clear_chain_certs, SSL_set0_chain, SSL_set1_chain, SSL_add0_chain_cert, SSL_add1_chain_cert, SSL_get0_chain_certs, SSL_clear_chain_certs, SSL_CTX_build_cert_chain, SSL_build_cert_chain, SSL_CTX_select_current_cert, SSL_select_current_cert, SSL_CTX_set_current_cert, SSL_set_current_cert - extra chain certificate processing

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set0_chain(SSL_CTX *ctx, STACK_OF(X509) *sk);
-int SSL_CTX_set1_chain(SSL_CTX *ctx, STACK_OF(X509) *sk);
-int SSL_CTX_add0_chain_cert(SSL_CTX *ctx, X509 *x509);
-int SSL_CTX_add1_chain_cert(SSL_CTX *ctx, X509 *x509);
-int SSL_CTX_get0_chain_certs(SSL_CTX *ctx, STACK_OF(X509) **sk);
-int SSL_CTX_clear_chain_certs(SSL_CTX *ctx);
-
-int SSL_set0_chain(SSL *ssl, STACK_OF(X509) *sk);
-int SSL_set1_chain(SSL *ssl, STACK_OF(X509) *sk);
-int SSL_add0_chain_cert(SSL *ssl, X509 *x509);
-int SSL_add1_chain_cert(SSL *ssl, X509 *x509);
-int SSL_get0_chain_certs(SSL *ssl, STACK_OF(X509) **sk);
-int SSL_clear_chain_certs(SSL *ssl);
-
-int SSL_CTX_build_cert_chain(SSL_CTX *ctx, flags);
-int SSL_build_cert_chain(SSL *ssl, flags);
-
-int SSL_CTX_select_current_cert(SSL_CTX *ctx, X509 *x509);
-int SSL_select_current_cert(SSL *ssl, X509 *x509);
-int SSL_CTX_set_current_cert(SSL_CTX *ctx, long op);
-int SSL_set_current_cert(SSL *ssl, long op);
- -

DESCRIPTION

- -

SSL_CTX_set0_chain() and SSL_CTX_set1_chain() set the certificate chain associated with the current certificate of ctx to sk.

- -

SSL_CTX_add0_chain_cert() and SSL_CTX_add1_chain_cert() append the single certificate x509 to the chain associated with the current certificate of ctx.

- -

SSL_CTX_get0_chain_certs() retrieves the chain associated with the current certificate of ctx.

- -

SSL_CTX_clear_chain_certs() clears any existing chain associated with the current certificate of ctx. (This is implemented by calling SSL_CTX_set0_chain() with sk set to NULL).

- -

SSL_CTX_build_cert_chain() builds the certificate chain for ctx. Normally this uses the chain store or the verify store if the chain store is not set. If the function is successful the built chain will replace any existing chain. The flags parameter can be set to SSL_BUILD_CHAIN_FLAG_UNTRUSTED to use existing chain certificates as untrusted CAs, SSL_BUILD_CHAIN_FLAG_NO_ROOT to omit the root CA from the built chain, SSL_BUILD_CHAIN_FLAG_CHECK to use all existing chain certificates only to build the chain (effectively sanity checking and rearranging them if necessary), the flag SSL_BUILD_CHAIN_FLAG_IGNORE_ERROR ignores any errors during verification: if flag SSL_BUILD_CHAIN_FLAG_CLEAR_ERROR is also set verification errors are cleared from the error queue. Details of the chain building process are described in "Certification Path Building" in openssl-verification-options(1).

- -

Each of these functions operates on the current end entity (i.e. server or client) certificate. This is the last certificate loaded or selected on the corresponding ctx structure.

- -

SSL_CTX_select_current_cert() selects x509 as the current end entity certificate, but only if x509 has already been loaded into ctx using a function such as SSL_CTX_use_certificate().

- -

SSL_set0_chain(), SSL_set1_chain(), SSL_add0_chain_cert(), SSL_add1_chain_cert(), SSL_get0_chain_certs(), SSL_clear_chain_certs(), SSL_build_cert_chain(), SSL_select_current_cert() and SSL_set_current_cert() are similar except they apply to SSL structure ssl.

- -

SSL_CTX_set_current_cert() changes the current certificate to a value based on the op argument. Currently op can be SSL_CERT_SET_FIRST to use the first valid certificate or SSL_CERT_SET_NEXT to set the next valid certificate after the current certificate. These two operations can be used to iterate over all certificates in an SSL_CTX structure.

- -

SSL_set_current_cert() also supports the option SSL_CERT_SET_SERVER. If ssl is a server and has sent a certificate to a connected client this option sets that certificate to the current certificate and returns 1. If the negotiated cipher suite is anonymous (and thus no certificate will be sent) 2 is returned and the current certificate is unchanged. If ssl is not a server or a certificate has not been sent 0 is returned and the current certificate is unchanged.

- -

All these functions are implemented as macros. Those containing a 1 increment the reference count of the supplied certificate or chain so it must be freed at some point after the operation. Those containing a 0 do not increment reference counts and the supplied certificate or chain MUST NOT be freed after the operation.

- -

NOTES

- -

The chains associate with an SSL_CTX structure are copied to any SSL structures when SSL_new() is called. SSL structures will not be affected by any chains subsequently changed in the parent SSL_CTX.

- -

One chain can be set for each key type supported by a server. So, for example, an RSA and a DSA certificate can (and often will) have different chains.

- -

The functions SSL_CTX_build_cert_chain() and SSL_build_cert_chain() can be used to check application configuration and to ensure any necessary subordinate CAs are sent in the correct order. Misconfigured applications sending incorrect certificate chains often cause problems with peers.

- -

For example an application can add any set of certificates using SSL_CTX_use_certificate_chain_file() then call SSL_CTX_build_cert_chain() with the option SSL_BUILD_CHAIN_FLAG_CHECK to check and reorder them.

- -

Applications can issue non fatal warnings when checking chains by setting the flag SSL_BUILD_CHAIN_FLAG_IGNORE_ERRORS and checking the return value.

- -

Calling SSL_CTX_build_cert_chain() or SSL_build_cert_chain() is more efficient than the automatic chain building as it is only performed once. Automatic chain building is performed on each new session.

- -

If any certificates are added using these functions no certificates added using SSL_CTX_add_extra_chain_cert() will be used.

- -

RETURN VALUES

- -

SSL_set_current_cert() with SSL_CERT_SET_SERVER return 1 for success, 2 if no server certificate is used because the cipher suites is anonymous and 0 for failure.

- -

SSL_CTX_build_cert_chain() and SSL_build_cert_chain() return 1 for success and 0 for failure. If the flag SSL_BUILD_CHAIN_FLAG_IGNORE_ERROR and a verification error occurs then 2 is returned.

- -

All other functions return 1 for success and 0 for failure.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_add_extra_chain_cert(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2013-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_extra_chain_cert.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_extra_chain_cert.html deleted file mode 100644 index c9eccc51..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_extra_chain_cert.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -SSL_CTX_add_extra_chain_cert - - - - - - - - - - -

NAME

- -

SSL_CTX_add_extra_chain_cert, SSL_CTX_get_extra_chain_certs, SSL_CTX_get_extra_chain_certs_only, SSL_CTX_clear_extra_chain_certs - add, get or clear extra chain certificates

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_add_extra_chain_cert(SSL_CTX *ctx, X509 *x509);
-long SSL_CTX_get_extra_chain_certs(SSL_CTX *ctx, STACK_OF(X509) **sk);
-long SSL_CTX_get_extra_chain_certs_only(SSL_CTX *ctx, STACK_OF(X509) **sk);
-long SSL_CTX_clear_extra_chain_certs(SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_add_extra_chain_cert() adds the certificate x509 to the extra chain certificates associated with ctx. Several certificates can be added one after another.

- -

SSL_CTX_get_extra_chain_certs() retrieves the extra chain certificates associated with ctx, or the chain associated with the current certificate of ctx if the extra chain is empty. The returned stack should not be freed by the caller.

- -

SSL_CTX_get_extra_chain_certs_only() retrieves the extra chain certificates associated with ctx. The returned stack should not be freed by the caller.

- -

SSL_CTX_clear_extra_chain_certs() clears all extra chain certificates associated with ctx.

- -

These functions are implemented as macros.

- -

NOTES

- -

When sending a certificate chain, extra chain certificates are sent in order following the end entity certificate.

- -

If no chain is specified, the library will try to complete the chain from the available CA certificates in the trusted CA storage, see SSL_CTX_load_verify_locations(3).

- -

The x509 certificate provided to SSL_CTX_add_extra_chain_cert() will be freed by the library when the SSL_CTX is destroyed. An application should not free the x509 object.

- -

RESTRICTIONS

- -

Only one set of extra chain certificates can be specified per SSL_CTX structure. Different chains for different certificates (for example if both RSA and DSA certificates are specified by the same server) or different SSL structures with the same parent SSL_CTX cannot be specified using this function. For more flexibility functions such as SSL_add1_chain_cert() should be used instead.

- -

RETURN VALUES

- -

SSL_CTX_add_extra_chain_cert() and SSL_CTX_clear_extra_chain_certs() return 1 on success and 0 for failure. Check out the error stack to find out the reason for failure.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_use_certificate(3), SSL_CTX_set_client_cert_cb(3), SSL_CTX_load_verify_locations(3) SSL_CTX_set0_chain(3) SSL_CTX_set1_chain(3) SSL_CTX_add0_chain_cert(3) SSL_CTX_add1_chain_cert(3) SSL_set0_chain(3) SSL_set1_chain(3) SSL_add0_chain_cert(3) SSL_add1_chain_cert(3) SSL_CTX_build_cert_chain(3) SSL_build_cert_chain(3)

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_session.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_session.html deleted file mode 100644 index 929518c1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_add_session.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -SSL_CTX_add_session - - - - - - - - - - -

NAME

- -

SSL_CTX_add_session, SSL_CTX_remove_session - manipulate session cache

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_add_session(SSL_CTX *ctx, SSL_SESSION *c);
-
-int SSL_CTX_remove_session(SSL_CTX *ctx, SSL_SESSION *c);
- -

DESCRIPTION

- -

SSL_CTX_add_session() adds the session c to the context ctx. The reference count for session c is incremented by 1. If a session with the same session id already exists, the old session is removed by calling SSL_SESSION_free(3).

- -

SSL_CTX_remove_session() removes the session c from the context ctx and marks it as non-resumable. SSL_SESSION_free(3) is called once for c.

- -

NOTES

- -

When adding a new session to the internal session cache, it is examined whether a session with the same session id already exists. In this case it is assumed that both sessions are identical. If the same session is stored in a different SSL_SESSION object, The old session is removed and replaced by the new session. If the session is actually identical (the SSL_SESSION object is identical), SSL_CTX_add_session() is a no-op, and the return value is 0.

- -

If a server SSL_CTX is configured with the SSL_SESS_CACHE_NO_INTERNAL_STORE flag then the internal cache will not be populated automatically by new sessions negotiated by the SSL/TLS implementation, even though the internal cache will be searched automatically for session-resume requests (the latter can be suppressed by SSL_SESS_CACHE_NO_INTERNAL_LOOKUP). So the application can use SSL_CTX_add_session() directly to have full control over the sessions that can be resumed if desired.

- -

RETURN VALUES

- -

The following values are returned by all functions:

- -
- -
0
-
- -

The operation failed. In case of the add operation, it was tried to add the same (identical) session twice. In case of the remove operation, the session was not found in the cache.

- -
-
1
-
- -

The operation succeeded.

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_session_cache_mode(3), SSL_SESSION_free(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_config.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_config.html deleted file mode 100644 index 58f1bddb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_config.html +++ /dev/null @@ -1,102 +0,0 @@ - - - - -SSL_CTX_config - - - - - - - - - - -

NAME

- -

SSL_CTX_config, SSL_config - configure SSL_CTX or SSL structure

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_config(SSL_CTX *ctx, const char *name);
-int SSL_config(SSL *s, const char *name);
- -

DESCRIPTION

- -

The functions SSL_CTX_config() and SSL_config() configure an SSL_CTX or SSL structure using the configuration name.

- -

By calling SSL_CTX_config() or SSL_config() an application can perform many complex tasks based on the contents of the configuration file: greatly simplifying application configuration code. A degree of future proofing can also be achieved: an application can support configuration features in newer versions of OpenSSL automatically.

- -

A configuration file must have been previously loaded, for example using CONF_modules_load_file(). See config(5) for details of the configuration file syntax.

- -

RETURN VALUES

- -

SSL_CTX_config() and SSL_config() return 1 for success or 0 if an error occurred.

- -

EXAMPLES

- -

If the file "config.cnf" contains the following:

- -
testapp = test_sect
-
-[test_sect]
-# list of configuration modules
-
-ssl_conf = ssl_sect
-
-[ssl_sect]
-server = server_section
-
-[server_section]
-RSA.Certificate = server-rsa.pem
-ECDSA.Certificate = server-ecdsa.pem
-Ciphers = ALL:!RC4
- -

An application could call:

- -
if (CONF_modules_load_file("config.cnf", "testapp", 0) <= 0) {
-    fprintf(stderr, "Error processing config file\n");
-    goto err;
-}
-
-ctx = SSL_CTX_new(TLS_server_method());
-
-if (SSL_CTX_config(ctx, "server") == 0) {
-    fprintf(stderr, "Error configuring server.\n");
-    goto err;
-}
- -

In this example two certificates and the cipher list are configured without the need for any additional application code.

- -

SEE ALSO

- -

ssl(7), config(5), SSL_CONF_cmd(3), CONF_modules_load_file(3)

- -

HISTORY

- -

The SSL_CTX_config() and SSL_config() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_ctrl.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_ctrl.html deleted file mode 100644 index 0ec1c02b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_ctrl.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -SSL_CTX_ctrl - - - - - - - - - - -

NAME

- -

SSL_CTX_ctrl, SSL_CTX_callback_ctrl, SSL_ctrl, SSL_callback_ctrl - internal handling functions for SSL_CTX and SSL objects

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_ctrl(SSL_CTX *ctx, int cmd, long larg, void *parg);
-long SSL_CTX_callback_ctrl(SSL_CTX *, int cmd, void (*fp)());
-
-long SSL_ctrl(SSL *ssl, int cmd, long larg, void *parg);
-long SSL_callback_ctrl(SSL *, int cmd, void (*fp)());
- -

DESCRIPTION

- -

The SSL_*_ctrl() family of functions is used to manipulate settings of the SSL_CTX and SSL objects. Depending on the command cmd the arguments larg, parg, or fp are evaluated. These functions should never be called directly. All functionalities needed are made available via other functions or macros.

- -

RETURN VALUES

- -

The return values of the SSL*_ctrl() functions depend on the command supplied via the cmd parameter.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_dane_enable.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_dane_enable.html deleted file mode 100644 index 0b737d2b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_dane_enable.html +++ /dev/null @@ -1,255 +0,0 @@ - - - - -SSL_CTX_dane_enable - - - - - - - - - - -

NAME

- -

SSL_CTX_dane_enable, SSL_CTX_dane_mtype_set, SSL_dane_enable, SSL_dane_tlsa_add, SSL_get0_dane_authority, SSL_get0_dane_tlsa, SSL_CTX_dane_set_flags, SSL_CTX_dane_clear_flags, SSL_dane_set_flags, SSL_dane_clear_flags - enable DANE TLS authentication of the remote TLS server in the local TLS client

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_dane_enable(SSL_CTX *ctx);
-int SSL_CTX_dane_mtype_set(SSL_CTX *ctx, const EVP_MD *md,
-                           uint8_t mtype, uint8_t ord);
-int SSL_dane_enable(SSL *s, const char *basedomain);
-int SSL_dane_tlsa_add(SSL *s, uint8_t usage, uint8_t selector,
-                      uint8_t mtype, const unsigned char *data, size_t dlen);
-int SSL_get0_dane_authority(SSL *s, X509 **mcert, EVP_PKEY **mspki);
-int SSL_get0_dane_tlsa(SSL *s, uint8_t *usage, uint8_t *selector,
-                       uint8_t *mtype, const unsigned char **data,
-                       size_t *dlen);
-unsigned long SSL_CTX_dane_set_flags(SSL_CTX *ctx, unsigned long flags);
-unsigned long SSL_CTX_dane_clear_flags(SSL_CTX *ctx, unsigned long flags);
-unsigned long SSL_dane_set_flags(SSL *ssl, unsigned long flags);
-unsigned long SSL_dane_clear_flags(SSL *ssl, unsigned long flags);
- -

DESCRIPTION

- -

These functions implement support for DANE TLSA (RFC6698 and RFC7671) peer authentication.

- -

SSL_CTX_dane_enable() must be called first to initialize the shared state required for DANE support. Individual connections associated with the context can then enable per-connection DANE support as appropriate. DANE authentication is implemented in the X509_verify_cert(3) function, and applications that override X509_verify_cert(3) via SSL_CTX_set_cert_verify_callback(3) are responsible to authenticate the peer chain in whatever manner they see fit.

- -

SSL_CTX_dane_mtype_set() may then be called zero or more times to adjust the supported digest algorithms. This must be done before any SSL handles are created for the context.

- -

The mtype argument specifies a DANE TLSA matching type and the md argument specifies the associated digest algorithm handle. The ord argument specifies a strength ordinal. Algorithms with a larger strength ordinal are considered more secure. Strength ordinals are used to implement RFC7671 digest algorithm agility. Specifying a NULL digest algorithm for a matching type disables support for that matching type. Matching type Full(0) cannot be modified or disabled.

- -

By default, matching type SHA2-256(1) (see RFC7218 for definitions of the DANE TLSA parameter acronyms) is mapped to EVP_sha256() with a strength ordinal of 1 and matching type SHA2-512(2) is mapped to EVP_sha512() with a strength ordinal of 2.

- -

SSL_dane_enable() must be called before the SSL handshake is initiated with SSL_connect(3) if (and only if) you want to enable DANE for that connection. (The connection must be associated with a DANE-enabled SSL context). The basedomain argument specifies the RFC7671 TLSA base domain, which will be the primary peer reference identifier for certificate name checks. Additional server names can be specified via SSL_add1_host(3). The basedomain is used as the default SNI hint if none has yet been specified via SSL_set_tlsext_host_name(3).

- -

SSL_dane_tlsa_add() may then be called one or more times, to load each of the TLSA records that apply to the remote TLS peer. (This too must be done prior to the beginning of the SSL handshake). The arguments specify the fields of the TLSA record. The data field is provided in binary (wire RDATA) form, not the hexadecimal ASCII presentation form, with an explicit length passed via dlen. The library takes a copy of the data buffer contents and the caller may free the original data buffer when convenient. A return value of 0 indicates that "unusable" TLSA records (with invalid or unsupported parameters) were provided. A negative return value indicates an internal error in processing the record.

- -

The caller is expected to check the return value of each SSL_dane_tlsa_add() call and take appropriate action if none are usable or an internal error is encountered in processing some records.

- -

If no TLSA records are added successfully, DANE authentication is not enabled, and authentication will be based on any configured traditional trust-anchors; authentication success in this case does not mean that the peer was DANE-authenticated.

- -

SSL_get0_dane_authority() can be used to get more detailed information about the matched DANE trust-anchor after successful connection completion. The return value is negative if DANE verification failed (or was not enabled), 0 if an EE TLSA record directly matched the leaf certificate, or a positive number indicating the depth at which a TA record matched an issuer certificate. The complete verified chain can be retrieved via SSL_get0_verified_chain(3). The return value is an index into this verified chain, rather than the list of certificates sent by the peer as returned by SSL_get_peer_cert_chain(3).

- -

If the mcert argument is not NULL and a TLSA record matched a chain certificate, a pointer to the matching certificate is returned via mcert. The returned address is a short-term internal reference to the certificate and must not be freed by the application. Applications that want to retain access to the certificate can call X509_up_ref(3) to obtain a long-term reference which must then be freed via X509_free(3) once no longer needed.

- -

If no TLSA records directly matched any elements of the certificate chain, but a DANE-TA(2) SPKI(1) Full(0) record provided the public key that signed an element of the chain, then that key is returned via mspki argument (if not NULL). In this case the return value is the depth of the top-most element of the validated certificate chain. As with mcert this is a short-term internal reference, and EVP_PKEY_up_ref(3) and EVP_PKEY_free(3) can be used to acquire and release long-term references respectively.

- -

SSL_get0_dane_tlsa() can be used to retrieve the fields of the TLSA record that matched the peer certificate chain. The return value indicates the match depth or failure to match just as with SSL_get0_dane_authority(). When the return value is nonnegative, the storage pointed to by the usage, selector, mtype and data parameters is updated to the corresponding TLSA record fields. The data field is in binary wire form, and is therefore not NUL-terminated, its length is returned via the dlen parameter. If any of these parameters is NULL, the corresponding field is not returned. The data parameter is set to a short-term internal-copy of the associated data field and must not be freed by the application. Applications that need long-term access to this field need to copy the content.

- -

SSL_CTX_dane_set_flags() and SSL_dane_set_flags() can be used to enable optional DANE verification features. SSL_CTX_dane_clear_flags() and SSL_dane_clear_flags() can be used to disable the same features. The flags argument is a bit-mask of the features to enable or disable. The flags set for an SSL_CTX context are copied to each SSL handle associated with that context at the time the handle is created. Subsequent changes in the context's flags have no effect on the flags set for the handle.

- -

At present, the only available option is DANE_FLAG_NO_DANE_EE_NAMECHECKS which can be used to disable server name checks when authenticating via DANE-EE(3) TLSA records. For some applications, primarily web browsers, it is not safe to disable name checks due to "unknown key share" attacks, in which a malicious server can convince a client that a connection to a victim server is instead a secure connection to the malicious server. The malicious server may then be able to violate cross-origin scripting restrictions. Thus, despite the text of RFC7671, name checks are by default enabled for DANE-EE(3) TLSA records, and can be disabled in applications where it is safe to do so. In particular, SMTP and XMPP clients should set this option as SRV and MX records already make it possible for a remote domain to redirect client connections to any server of its choice, and in any case SMTP and XMPP clients do not execute scripts downloaded from remote servers.

- -

RETURN VALUES

- -

The functions SSL_CTX_dane_enable(), SSL_CTX_dane_mtype_set(), SSL_dane_enable() and SSL_dane_tlsa_add() return a positive value on success. Negative return values indicate resource problems (out of memory, etc.) in the SSL library, while a return value of 0 indicates incorrect usage or invalid input, such as an unsupported TLSA record certificate usage, selector or matching type. Invalid input also includes malformed data, either a digest length that does not match the digest algorithm, or a Full(0) (binary ASN.1 DER form) certificate or a public key that fails to parse.

- -

The functions SSL_get0_dane_authority() and SSL_get0_dane_tlsa() return a negative value when DANE authentication failed or was not enabled, a nonnegative value indicates the chain depth at which the TLSA record matched a chain certificate, or the depth of the top-most certificate, when the TLSA record is a full public key that is its signer.

- -

The functions SSL_CTX_dane_set_flags(), SSL_CTX_dane_clear_flags(), SSL_dane_set_flags() and SSL_dane_clear_flags() return the flags in effect before they were called.

- -

EXAMPLES

- -

Suppose "smtp.example.com" is the MX host of the domain "example.com", and has DNSSEC-validated TLSA records. The calls below will perform DANE authentication and arrange to match either the MX hostname or the destination domain name in the SMTP server certificate. Wildcards are supported, but must match the entire label. The actual name matched in the certificate (which might be a wildcard) is retrieved, and must be copied by the application if it is to be retained beyond the lifetime of the SSL connection.

- -
SSL_CTX *ctx;
-SSL *ssl;
-int (*verify_cb)(int ok, X509_STORE_CTX *sctx) = NULL;
-int num_usable = 0;
-const char *nexthop_domain = "example.com";
-const char *dane_tlsa_domain = "smtp.example.com";
-uint8_t usage, selector, mtype;
-
-if ((ctx = SSL_CTX_new(TLS_client_method())) == NULL)
-    /* error */
-if (SSL_CTX_dane_enable(ctx) <= 0)
-    /* error */
-if ((ssl = SSL_new(ctx)) == NULL)
-    /* error */
-if (SSL_dane_enable(ssl, dane_tlsa_domain) <= 0)
-    /* error */
-
-/*
- * For many applications it is safe to skip DANE-EE(3) namechecks.  Do not
- * disable the checks unless "unknown key share" attacks pose no risk for
- * your application.
- */
-SSL_dane_set_flags(ssl, DANE_FLAG_NO_DANE_EE_NAMECHECKS);
-
-if (!SSL_add1_host(ssl, nexthop_domain))
-    /* error */
-SSL_set_hostflags(ssl, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS);
-
-for (... each TLSA record ...) {
-    unsigned char *data;
-    size_t len;
-    int ret;
-
-    /* set usage, selector, mtype, data, len */
-
-    /*
-     * Opportunistic DANE TLS clients support only DANE-TA(2) or DANE-EE(3).
-     * They treat all other certificate usages, and in particular PKIX-TA(0)
-     * and PKIX-EE(1), as unusable.
-     */
-    switch (usage) {
-    default:
-    case 0:     /* PKIX-TA(0) */
-    case 1:     /* PKIX-EE(1) */
-        continue;
-    case 2:     /* DANE-TA(2) */
-    case 3:     /* DANE-EE(3) */
-        break;
-    }
-
-    ret = SSL_dane_tlsa_add(ssl, usage, selector, mtype, data, len);
-    /* free data as appropriate */
-
-    if (ret < 0)
-        /* handle SSL library internal error */
-    else if (ret == 0)
-        /* handle unusable TLSA record */
-    else
-        ++num_usable;
-}
-
-/*
- * At this point, the verification mode is still the default SSL_VERIFY_NONE.
- * Opportunistic DANE clients use unauthenticated TLS when all TLSA records
- * are unusable, so continue the handshake even if authentication fails.
- */
-if (num_usable == 0) {
-    /* Log all records unusable? */
-
-    /* Optionally set verify_cb to a suitable non-NULL callback. */
-    SSL_set_verify(ssl, SSL_VERIFY_NONE, verify_cb);
-} else {
-    /* At least one usable record.  We expect to verify the peer */
-
-    /* Optionally set verify_cb to a suitable non-NULL callback. */
-
-    /*
-     * Below we elect to fail the handshake when peer verification fails.
-     * Alternatively, use the permissive SSL_VERIFY_NONE verification mode,
-     * complete the handshake, check the verification status, and if not
-     * verified disconnect gracefully at the application layer, especially if
-     * application protocol supports informing the server that authentication
-     * failed.
-     */
-    SSL_set_verify(ssl, SSL_VERIFY_PEER, verify_cb);
-}
-
-/*
- * Load any saved session for resumption, making sure that the previous
- * session applied the same security and authentication requirements that
- * would be expected of a fresh connection.
- */
-
-/* Perform SSL_connect() handshake and handle errors here */
-
-if (SSL_session_reused(ssl)) {
-    if (SSL_get_verify_result(ssl) == X509_V_OK) {
-        /*
-         * Resumed session was originally verified, this connection is
-         * authenticated.
-         */
-    } else {
-        /*
-         * Resumed session was not originally verified, this connection is not
-         * authenticated.
-         */
-    }
-} else if (SSL_get_verify_result(ssl) == X509_V_OK) {
-    const char *peername = SSL_get0_peername(ssl);
-    EVP_PKEY *mspki = NULL;
-
-    int depth = SSL_get0_dane_authority(ssl, NULL, &mspki);
-    if (depth >= 0) {
-        (void) SSL_get0_dane_tlsa(ssl, &usage, &selector, &mtype, NULL, NULL);
-        printf("DANE TLSA %d %d %d ", usage, selector, mtype);
-        if (SSL_get0_peer_rpk(ssl) == NULL)
-            printf("%s certificate at depth %d\n",
-                   (mspki != NULL) ? "signed the peer" :
-                   mdpth ? "matched the TA" : "matched the EE", mdpth);
-        else
-            printf(bio, "matched the peer raw public key\n");
-    }
-    if (peername != NULL) {
-        /* Name checks were in scope and matched the peername */
-        printf("Verified peername: %s\n", peername);
-    }
-} else {
-    /*
-     * Not authenticated, presumably all TLSA rrs unusable, but possibly a
-     * callback suppressed connection termination despite the presence of
-     * usable TLSA RRs none of which matched.  Do whatever is appropriate for
-     * fresh unauthenticated connections.
-     */
-}
- -

NOTES

- -

It is expected that the majority of clients employing DANE TLS will be doing "opportunistic DANE TLS" in the sense of RFC7672 and RFC7435. That is, they will use DANE authentication when DNSSEC-validated TLSA records are published for a given peer, and otherwise will use unauthenticated TLS or even cleartext.

- -

Such applications should generally treat any TLSA records published by the peer with usages PKIX-TA(0) and PKIX-EE(1) as "unusable", and should not include them among the TLSA records used to authenticate peer connections. In addition, some TLSA records with supported usages may be "unusable" as a result of invalid or unsupported parameters.

- -

When a peer has TLSA records, but none are "usable", an opportunistic application must avoid cleartext, but cannot authenticate the peer, and so should generally proceed with an unauthenticated connection. Opportunistic applications need to note the return value of each call to SSL_dane_tlsa_add(), and if all return 0 (due to invalid or unsupported parameters) disable peer authentication by calling SSL_set_verify(3) with mode equal to SSL_VERIFY_NONE.

- -

SEE ALSO

- -

ssl(7), SSL_new(3), SSL_add1_host(3), SSL_set_hostflags(3), SSL_set_tlsext_host_name(3), SSL_set_verify(3), SSL_CTX_set_cert_verify_callback(3), SSL_get0_verified_chain(3), SSL_get_peer_cert_chain(3), SSL_get_verify_result(3), SSL_connect(3), SSL_get0_peername(3), X509_verify_cert(3), X509_up_ref(3), X509_free(3), EVP_get_digestbyname(3), EVP_PKEY_up_ref(3), EVP_PKEY_free(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_flush_sessions.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_flush_sessions.html deleted file mode 100644 index cbe03f0f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_flush_sessions.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -SSL_CTX_flush_sessions - - - - - - - - - - -

NAME

- -

SSL_CTX_flush_sessions_ex, SSL_CTX_flush_sessions - remove expired sessions

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_flush_sessions_ex(SSL_CTX *ctx, time_t tm);
- -

The following functions have been deprecated since OpenSSL 3.4, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void SSL_CTX_flush_sessions(SSL_CTX *ctx, long tm);
- -

DESCRIPTION

- -

SSL_CTX_flush_sessions_ex() causes a run through the session cache of ctx to remove sessions expired at time tm.

- -

SSL_CTX_flush_sessions() is an older variant of the function that is not Y2038 safe due to usage of long datatype instead of time_t.

- -

NOTES

- -

If enabled, the internal session cache will collect all sessions established up to the specified maximum number (see SSL_CTX_sess_set_cache_size()). As sessions will not be reused ones they are expired, they should be removed from the cache to save resources. This can either be done automatically whenever 255 new sessions were established (see SSL_CTX_set_session_cache_mode(3)) or manually by calling SSL_CTX_flush_sessions_ex().

- -

The parameter tm specifies the time which should be used for the expiration test, in most cases the actual time given by time(0) will be used.

- -

SSL_CTX_flush_sessions_ex() will only check sessions stored in the internal cache. When a session is found and removed, the remove_session_cb is however called to synchronize with the external cache (see SSL_CTX_sess_set_get_cb(3)).

- -

RETURN VALUES

- -

SSL_CTX_flush_sessions_ex() does not return a value.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_session_cache_mode(3), SSL_CTX_set_timeout(3), SSL_CTX_sess_set_get_cb(3)

- -

HISTORY

- -

SSL_CTX_flush_sessions_ex() was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_free.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_free.html deleted file mode 100644 index b69d86cf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_free.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -SSL_CTX_free - - - - - - - - - - -

NAME

- -

SSL_CTX_free - free an allocated SSL_CTX object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_free(SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_free() decrements the reference count of ctx, and removes the SSL_CTX object pointed to by ctx and frees up the allocated memory if the reference count has reached 0.

- -

It also calls the free()ing procedures for indirectly affected items, if applicable: the session cache, the list of ciphers, the list of Client CAs, the certificates and keys.

- -

If ctx is NULL nothing is done.

- -

WARNINGS

- -

If a session-remove callback is set (SSL_CTX_sess_set_remove_cb()), this callback will be called for each session being freed from ctx's session cache. This implies, that all corresponding sessions from an external session cache are removed as well. If this is not desired, the user should explicitly unset the callback by calling SSL_CTX_sess_set_remove_cb(ctx, NULL) prior to calling SSL_CTX_free().

- -

RETURN VALUES

- -

SSL_CTX_free() does not provide diagnostic information.

- -

SEE ALSO

- -

SSL_CTX_new(3), ssl(7), SSL_CTX_sess_set_get_cb(3)

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_get0_param.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_get0_param.html deleted file mode 100644 index 6d0403d4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_get0_param.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -SSL_CTX_get0_param - - - - - - - - - - -

NAME

- -

SSL_CTX_get0_param, SSL_get0_param, SSL_CTX_set1_param, SSL_set1_param, SSL_CTX_set_purpose, SSL_CTX_set_trust, SSL_set_purpose, SSL_set_trust - get and set verification parameters

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx);
-X509_VERIFY_PARAM *SSL_get0_param(SSL *ssl);
-int SSL_CTX_set1_param(SSL_CTX *ctx, X509_VERIFY_PARAM *vpm);
-int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm);
-
-int SSL_CTX_set_purpose(SSL_CTX *ctx, int purpose);
-int SSL_set_purpose(SSL *ssl, int purpose);
-
-int SSL_CTX_set_trust(SSL_CTX *ctx, int trust);
-int SSL_set_trust(SSL *ssl, int trust);
- -

DESCRIPTION

- -

SSL_CTX_get0_param() and SSL_get0_param() retrieve an internal pointer to the verification parameters for ctx or ssl respectively. The returned pointer must not be freed by the calling application.

- -

SSL_CTX_set1_param() and SSL_set1_param() set the verification parameters to vpm for ctx or ssl.

- -

The functions SSL_CTX_set_purpose() and SSL_set_purpose() are shorthands which set the purpose parameter on the verification parameters object. These functions are equivalent to calling X509_VERIFY_PARAM_set_purpose() directly.

- -

The functions SSL_CTX_set_trust() and SSL_set_trust() are similarly shorthands which set the trust parameter on the verification parameters object. These functions are equivalent to calling X509_VERIFY_PARAM_set_trust() directly.

- -

NOTES

- -

Typically parameters are retrieved from an SSL_CTX or SSL structure using SSL_CTX_get0_param() or SSL_get0_param() and an application modifies them to suit its needs: for example to add a hostname check.

- -

RETURN VALUES

- -

SSL_CTX_get0_param() and SSL_get0_param() return a pointer to an X509_VERIFY_PARAM structure.

- -

SSL_CTX_set1_param(), SSL_set1_param(), SSL_CTX_set_purpose(), SSL_set_purpose(), SSL_CTX_set_trust() and SSL_set_trust() return 1 for success and 0 for failure.

- -

EXAMPLES

- -

Check hostname matches "www.foo.com" in peer certificate:

- -
X509_VERIFY_PARAM *vpm = SSL_get0_param(ssl);
-X509_VERIFY_PARAM_set1_host(vpm, "www.foo.com", 0);
- -

SEE ALSO

- -

ssl(7), X509_VERIFY_PARAM_set_flags(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_get_verify_mode.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_get_verify_mode.html deleted file mode 100644 index 466794ee..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_get_verify_mode.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -SSL_CTX_get_verify_mode - - - - - - - - - - -

NAME

- -

SSL_CTX_get_verify_mode, SSL_get_verify_mode, SSL_CTX_get_verify_depth, SSL_get_verify_depth, SSL_get_verify_callback, SSL_CTX_get_verify_callback - get currently set verification parameters

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_get_verify_mode(const SSL_CTX *ctx);
-int SSL_get_verify_mode(const SSL *ssl);
-int SSL_CTX_get_verify_depth(const SSL_CTX *ctx);
-int SSL_get_verify_depth(const SSL *ssl);
-int (*SSL_CTX_get_verify_callback(const SSL_CTX *ctx))(int, X509_STORE_CTX *);
-int (*SSL_get_verify_callback(const SSL *ssl))(int, X509_STORE_CTX *);
- -

DESCRIPTION

- -

SSL_CTX_get_verify_mode() returns the verification mode currently set in ctx.

- -

SSL_get_verify_mode() returns the verification mode currently set in ssl.

- -

SSL_CTX_get_verify_depth() returns the verification depth limit currently set in ctx. If no limit has been explicitly set, -1 is returned and the default value will be used.

- -

SSL_get_verify_depth() returns the verification depth limit currently set in ssl. If no limit has been explicitly set, -1 is returned and the default value will be used.

- -

SSL_CTX_get_verify_callback() returns a function pointer to the verification callback currently set in ctx. If no callback was explicitly set, the NULL pointer is returned and the default callback will be used.

- -

SSL_get_verify_callback() returns a function pointer to the verification callback currently set in ssl. If no callback was explicitly set, the NULL pointer is returned and the default callback will be used.

- -

RETURN VALUES

- -

See DESCRIPTION

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_verify(3)

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_has_client_custom_ext.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_has_client_custom_ext.html deleted file mode 100644 index 1d1da679..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_has_client_custom_ext.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -SSL_CTX_has_client_custom_ext - - - - - - - - - - -

NAME

- -

SSL_CTX_has_client_custom_ext - check whether a handler exists for a particular client extension type

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_has_client_custom_ext(const SSL_CTX *ctx, unsigned int ext_type);
- -

DESCRIPTION

- -

SSL_CTX_has_client_custom_ext() checks whether a handler has been set for a client extension of type ext_type using SSL_CTX_add_client_custom_ext().

- -

RETURN VALUES

- -

Returns 1 if a handler has been set, 0 otherwise.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_add_client_custom_ext(3)

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_load_verify_locations.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_load_verify_locations.html deleted file mode 100644 index 634ea61f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_load_verify_locations.html +++ /dev/null @@ -1,141 +0,0 @@ - - - - -SSL_CTX_load_verify_locations - - - - - - - - - - -

NAME

- -

SSL_CTX_load_verify_dir, SSL_CTX_load_verify_file, SSL_CTX_load_verify_store, SSL_CTX_set_default_verify_paths, SSL_CTX_set_default_verify_dir, SSL_CTX_set_default_verify_file, SSL_CTX_set_default_verify_store, SSL_CTX_load_verify_locations - set default locations for trusted CA certificates

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_load_verify_dir(SSL_CTX *ctx, const char *CApath);
-int SSL_CTX_load_verify_file(SSL_CTX *ctx, const char *CAfile);
-int SSL_CTX_load_verify_store(SSL_CTX *ctx, const char *CAstore);
-
-int SSL_CTX_set_default_verify_paths(SSL_CTX *ctx);
-
-int SSL_CTX_set_default_verify_dir(SSL_CTX *ctx);
-int SSL_CTX_set_default_verify_file(SSL_CTX *ctx);
-int SSL_CTX_set_default_verify_store(SSL_CTX *ctx);
-
-int SSL_CTX_load_verify_locations(SSL_CTX *ctx, const char *CAfile,
-                                  const char *CApath);
- -

DESCRIPTION

- -

SSL_CTX_load_verify_locations(), SSL_CTX_load_verify_dir(), SSL_CTX_load_verify_file(), SSL_CTX_load_verify_store() specifies the locations for ctx, at which CA certificates for verification purposes are located. The certificates available via CAfile, CApath and CAstore are trusted.

- -

Details of the certificate verification and chain checking process are described in "Certification Path Validation" in openssl-verification-options(1).

- -

SSL_CTX_set_default_verify_paths() specifies that the default locations from which CA certificates are loaded should be used. There is one default directory, one default file and one default store. The default CA certificates directory is called certs in the default OpenSSL directory, and this is also the default store. Alternatively the SSL_CERT_DIR environment variable can be defined to override this location. The default CA certificates file is called cert.pem in the default OpenSSL directory. Alternatively the SSL_CERT_FILE environment variable can be defined to override this location.

- -

SSL_CTX_set_default_verify_dir() is similar to SSL_CTX_set_default_verify_paths() except that just the default directory is used.

- -

SSL_CTX_set_default_verify_file() is similar to SSL_CTX_set_default_verify_paths() except that just the default file is used.

- -

SSL_CTX_set_default_verify_store() is similar to SSL_CTX_set_default_verify_paths() except that just the default store is used.

- -

NOTES

- -

If CAfile is not NULL, it points to a file of CA certificates in PEM format. The file can contain several CA certificates identified by

- -
-----BEGIN CERTIFICATE-----
-... (CA certificate in base64 encoding) ...
------END CERTIFICATE-----
- -

sequences. Before, between, and after the certificates text is allowed which can be used e.g. for descriptions of the certificates.

- -

The CAfile is processed on execution of the SSL_CTX_load_verify_locations() function.

- -

If CApath is not NULL, it points to a directory containing CA certificates in PEM format. The files each contain one CA certificate. The files are looked up by the CA subject name hash value, which must hence be available. If more than one CA certificate with the same name hash value exist, the extension must be different (e.g. 9d66eef0.0, 9d66eef0.1 etc). The search is performed in the ordering of the extension number, regardless of other properties of the certificates. Use the c_rehash utility to create the necessary links.

- -

The certificates in CApath are only looked up when required, e.g. when building the certificate chain or when actually performing the verification of a peer certificate.

- -

When looking up CA certificates for chain building, the OpenSSL library will search for suitable certificates first in CAfile, then in CApath. Details of the chain building process are described in "Certification Path Building" in openssl-verification-options(1).

- -

If CAstore is not NULL, it's a URI for to a store, which may represent a single container or a whole catalogue of containers. Apart from the CAstore not necessarily being a local file or directory, it's generally treated the same way as a CApath.

- -

In server mode, when requesting a client certificate, the server must send the list of CAs of which it will accept client certificates. This list is not influenced by the contents of CAfile or CApath and must explicitly be set using the SSL_CTX_set_client_CA_list(3) family of functions.

- -

When building its own certificate chain, an OpenSSL client/server will try to fill in missing certificates from CAfile/CApath, if the certificate chain was not explicitly specified (see SSL_CTX_add_extra_chain_cert(3), SSL_CTX_use_certificate(3).

- -

WARNINGS

- -

If several CA certificates matching the name, key identifier, and serial number condition are available, only the first one will be examined. This may lead to unexpected results if the same CA certificate is available with different expiration dates. If a "certificate expired" verification error occurs, no other certificate will be searched. Make sure to not have expired certificates mixed with valid ones.

- -

RETURN VALUES

- -

For SSL_CTX_load_verify_locations the following return values can occur:

- -
- -
0
-
- -

The operation failed because CAfile and CApath are NULL or the processing at one of the locations specified failed. Check the error stack to find out the reason.

- -
-
1
-
- -

The operation succeeded.

- -
-
- -

SSL_CTX_set_default_verify_paths(), SSL_CTX_set_default_verify_dir() and SSL_CTX_set_default_verify_file() all return 1 on success or 0 on failure. A missing default location is still treated as a success.

- -

EXAMPLES

- -

Generate a CA certificate file with descriptive text from the CA certificates ca1.pem ca2.pem ca3.pem:

- -
#!/bin/sh
-rm CAfile.pem
-for i in ca1.pem ca2.pem ca3.pem ; do
-    openssl x509 -in $i -text >> CAfile.pem
-done
- -

Prepare the directory /some/where/certs containing several CA certificates for use as CApath:

- -
cd /some/where/certs
-c_rehash .
- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_client_CA_list(3), SSL_get_client_CA_list(3), SSL_CTX_use_certificate(3), SSL_CTX_add_extra_chain_cert(3), SSL_CTX_set_cert_store(3), SSL_CTX_set_client_CA_list(3)

- -

COPYRIGHT

- -

Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_new.html deleted file mode 100644 index 20edd1a1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_new.html +++ /dev/null @@ -1,221 +0,0 @@ - - - - -SSL_CTX_new - - - - - - - - - - -

NAME

- -

TLSv1_2_method, TLSv1_2_server_method, TLSv1_2_client_method, SSL_CTX_new, SSL_CTX_new_ex, SSL_CTX_up_ref, SSLv3_method, SSLv3_server_method, SSLv3_client_method, TLSv1_method, TLSv1_server_method, TLSv1_client_method, TLSv1_1_method, TLSv1_1_server_method, TLSv1_1_client_method, TLS_method, TLS_server_method, TLS_client_method, SSLv23_method, SSLv23_server_method, SSLv23_client_method, DTLS_method, DTLS_server_method, DTLS_client_method, DTLSv1_method, DTLSv1_server_method, DTLSv1_client_method, DTLSv1_2_method, DTLSv1_2_server_method, DTLSv1_2_client_method - create a new SSL_CTX object as framework for TLS/SSL or DTLS enabled functions

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL_CTX *SSL_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq,
-                        const SSL_METHOD *method);
-SSL_CTX *SSL_CTX_new(const SSL_METHOD *method);
-int SSL_CTX_up_ref(SSL_CTX *ctx);
-
-const SSL_METHOD *TLS_method(void);
-const SSL_METHOD *TLS_server_method(void);
-const SSL_METHOD *TLS_client_method(void);
-
-const SSL_METHOD *SSLv23_method(void);
-const SSL_METHOD *SSLv23_server_method(void);
-const SSL_METHOD *SSLv23_client_method(void);
-
-#ifndef OPENSSL_NO_SSL3_METHOD
-const SSL_METHOD *SSLv3_method(void);
-const SSL_METHOD *SSLv3_server_method(void);
-const SSL_METHOD *SSLv3_client_method(void);
-#endif
-
-#ifndef OPENSSL_NO_TLS1_METHOD
-const SSL_METHOD *TLSv1_method(void);
-const SSL_METHOD *TLSv1_server_method(void);
-const SSL_METHOD *TLSv1_client_method(void);
-#endif
-
-#ifndef OPENSSL_NO_TLS1_1_METHOD
-const SSL_METHOD *TLSv1_1_method(void);
-const SSL_METHOD *TLSv1_1_server_method(void);
-const SSL_METHOD *TLSv1_1_client_method(void);
-#endif
-
-#ifndef OPENSSL_NO_TLS1_2_METHOD
-const SSL_METHOD *TLSv1_2_method(void);
-const SSL_METHOD *TLSv1_2_server_method(void);
-const SSL_METHOD *TLSv1_2_client_method(void);
-#endif
-
-const SSL_METHOD *DTLS_method(void);
-const SSL_METHOD *DTLS_server_method(void);
-const SSL_METHOD *DTLS_client_method(void);
-
-#ifndef OPENSSL_NO_DTLS1_METHOD
-const SSL_METHOD *DTLSv1_method(void);
-const SSL_METHOD *DTLSv1_server_method(void);
-const SSL_METHOD *DTLSv1_client_method(void);
-#endif
-
-#ifndef OPENSSL_NO_DTLS1_2_METHOD
-const SSL_METHOD *DTLSv1_2_method(void);
-const SSL_METHOD *DTLSv1_2_server_method(void);
-const SSL_METHOD *DTLSv1_2_client_method(void);
-#endif
- -

DESCRIPTION

- -

SSL_CTX_new_ex() creates a new SSL_CTX object, which holds various configuration and data relevant to SSL/TLS or DTLS session establishment. These are later inherited by the SSL object representing an active session. The method parameter specifies whether the context will be used for the client or server side or both - for details see the "NOTES" below. The library context libctx (see OSSL_LIB_CTX(3)) is used to provide the cryptographic algorithms needed for the session. Any cryptographic algorithms that are used by any SSL objects created from this SSL_CTX will be fetched from the libctx using the property query string propq (see "ALGORITHM FETCHING" in crypto(7). Either or both the libctx or propq parameters may be NULL.

- -

SSL_CTX_new() does the same as SSL_CTX_new_ex() except that the default library context is used and no property query string is specified.

- -

An SSL_CTX object is reference counted. Creating an SSL_CTX object for the first time increments the reference count. Freeing the SSL_CTX (using SSL_CTX_free) decrements it. When the reference count drops to zero, any memory or resources allocated to the SSL_CTX object are freed. SSL_CTX_up_ref() increments the reference count for an existing SSL_CTX structure.

- -

An SSL_CTX object should not be changed after it is used to create any SSL objects or from multiple threads concurrently, since the implementation does not provide serialization of access for these cases.

- -

NOTES

- -

On session establishment, by default, no peer credentials verification is done. This must be explicitly requested, typically using SSL_CTX_set_verify(3). For verifying peer certificates many options can be set using various functions such as SSL_CTX_load_verify_locations(3) and SSL_CTX_set1_param(3).

- -

The SSL/(D)TLS implementation uses the X509_STORE_CTX_set_default(3) function to prepare checks for X509_PURPOSE_SSL_SERVER on the client side and X509_PURPOSE_SSL_CLIENT on the server side. The X509_VERIFY_PARAM_set_purpose(3) function can be used, also in conjunction with SSL_CTX_get0_param(3), to override the default purpose of the session.

- -

The SSL_CTX object uses method as the connection method. Three method variants are available: a generic method (for either client or server use), a server-only method, and a client-only method.

- -

The method parameter of SSL_CTX_new_ex() and SSL_CTX_new() can be one of the following:

- -
- -
TLS_method(), TLS_server_method(), TLS_client_method()
-
- -

These are the general-purpose version-flexible SSL/TLS methods. The actual protocol version used will be negotiated to the highest version mutually supported by the client and the server. The supported protocols are SSLv3, TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3. Applications should use these methods, and avoid the version-specific methods described below, which are deprecated.

- -
-
SSLv23_method(), SSLv23_server_method(), SSLv23_client_method()
-
- -

These functions do not exist anymore, they have been renamed to TLS_method(), TLS_server_method() and TLS_client_method() respectively. Currently, the old function calls are renamed to the corresponding new ones by preprocessor macros, to ensure that existing code which uses the old function names still compiles. However, using the old function names is deprecated and new code should call the new functions instead.

- -
-
TLSv1_2_method(), TLSv1_2_server_method(), TLSv1_2_client_method()
-
- -

A TLS/SSL connection established with these methods will only understand the TLSv1.2 protocol. These methods are deprecated.

- -
-
TLSv1_1_method(), TLSv1_1_server_method(), TLSv1_1_client_method()
-
- -

A TLS/SSL connection established with these methods will only understand the TLSv1.1 protocol. These methods are deprecated.

- -
-
TLSv1_method(), TLSv1_server_method(), TLSv1_client_method()
-
- -

A TLS/SSL connection established with these methods will only understand the TLSv1 protocol. These methods are deprecated.

- -
-
SSLv3_method(), SSLv3_server_method(), SSLv3_client_method()
-
- -

A TLS/SSL connection established with these methods will only understand the SSLv3 protocol. The SSLv3 protocol is deprecated and should not be used.

- -
-
DTLS_method(), DTLS_server_method(), DTLS_client_method()
-
- -

These are the version-flexible DTLS methods. Currently supported protocols are DTLS 1.0 and DTLS 1.2.

- -
-
DTLSv1_2_method(), DTLSv1_2_server_method(), DTLSv1_2_client_method()
-
- -

These are the version-specific methods for DTLSv1.2. These methods are deprecated.

- -
-
DTLSv1_method(), DTLSv1_server_method(), DTLSv1_client_method()
-
- -

These are the version-specific methods for DTLSv1. These methods are deprecated.

- -
-
- -

SSL_CTX_new() initializes the list of ciphers, the session cache setting, the callbacks, the keys and certificates and the options to their default values.

- -

TLS_method(), TLS_server_method(), TLS_client_method(), DTLS_method(), DTLS_server_method() and DTLS_client_method() are the version-flexible methods. All other methods only support one specific protocol version. Use the version-flexible methods instead of the version specific methods.

- -

If you want to limit the supported protocols for the version flexible methods you can use SSL_CTX_set_min_proto_version(3), SSL_set_min_proto_version(3), SSL_CTX_set_max_proto_version(3) and SSL_set_max_proto_version(3) functions. Using these functions it is possible to choose e.g. TLS_server_method() and be able to negotiate with all possible clients, but to only allow newer protocols like TLS 1.0, TLS 1.1, TLS 1.2 or TLS 1.3.

- -

The list of protocols available can also be limited using the SSL_OP_NO_SSLv3, SSL_OP_NO_TLSv1, SSL_OP_NO_TLSv1_1, SSL_OP_NO_TLSv1_3, SSL_OP_NO_TLSv1_2 and SSL_OP_NO_TLSv1_3 options of the SSL_CTX_set_options(3) or SSL_set_options(3) functions, but this approach is not recommended. Clients should avoid creating "holes" in the set of protocols they support. When disabling a protocol, make sure that you also disable either all previous or all subsequent protocol versions. In clients, when a protocol version is disabled without disabling all previous protocol versions, the effect is to also disable all subsequent protocol versions.

- -

The SSLv3 protocol is deprecated and should generally not be used. Applications should typically use SSL_CTX_set_min_proto_version(3) to set the minimum protocol to at least TLS1_VERSION.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
NULL
-
- -

The creation of a new SSL_CTX object failed. Check the error stack to find out the reason.

- -
-
Pointer to an SSL_CTX object
-
- -

The return value points to an allocated SSL_CTX object.

- -

SSL_CTX_up_ref() returns 1 for success and 0 for failure.

- -
-
- -

SEE ALSO

- -

SSL_CTX_set_options(3), SSL_CTX_free(3), X509_STORE_CTX_set_default(3), SSL_CTX_set_verify(3), SSL_CTX_set1_param(3), SSL_CTX_get0_param(3), SSL_connect(3), SSL_accept(3), SSL_CTX_set_min_proto_version(3), ssl(7), SSL_set_connect_state(3)

- -

HISTORY

- -

Support for SSLv2 and the corresponding SSLv2_method(), SSLv2_server_method() and SSLv2_client_method() functions where removed in OpenSSL 1.1.0.

- -

SSLv23_method(), SSLv23_server_method() and SSLv23_client_method() were deprecated and the preferred TLS_method(), TLS_server_method() and TLS_client_method() functions were added in OpenSSL 1.1.0.

- -

All version-specific methods were deprecated in OpenSSL 1.1.0.

- -

SSL_CTX_new_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_number.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_number.html deleted file mode 100644 index e7d37b38..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_number.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -SSL_CTX_sess_number - - - - - - - - - - -

NAME

- -

SSL_CTX_sess_number, SSL_CTX_sess_connect, SSL_CTX_sess_connect_good, SSL_CTX_sess_connect_renegotiate, SSL_CTX_sess_accept, SSL_CTX_sess_accept_good, SSL_CTX_sess_accept_renegotiate, SSL_CTX_sess_hits, SSL_CTX_sess_cb_hits, SSL_CTX_sess_misses, SSL_CTX_sess_timeouts, SSL_CTX_sess_cache_full - obtain session cache statistics

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_sess_number(SSL_CTX *ctx);
-long SSL_CTX_sess_connect(SSL_CTX *ctx);
-long SSL_CTX_sess_connect_good(SSL_CTX *ctx);
-long SSL_CTX_sess_connect_renegotiate(SSL_CTX *ctx);
-long SSL_CTX_sess_accept(SSL_CTX *ctx);
-long SSL_CTX_sess_accept_good(SSL_CTX *ctx);
-long SSL_CTX_sess_accept_renegotiate(SSL_CTX *ctx);
-long SSL_CTX_sess_hits(SSL_CTX *ctx);
-long SSL_CTX_sess_cb_hits(SSL_CTX *ctx);
-long SSL_CTX_sess_misses(SSL_CTX *ctx);
-long SSL_CTX_sess_timeouts(SSL_CTX *ctx);
-long SSL_CTX_sess_cache_full(SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_sess_number() returns the current number of sessions in the internal session cache.

- -

SSL_CTX_sess_connect() returns the number of started SSL/TLS handshakes in client mode.

- -

SSL_CTX_sess_connect_good() returns the number of successfully established SSL/TLS sessions in client mode.

- -

SSL_CTX_sess_connect_renegotiate() returns the number of started renegotiations in client mode.

- -

SSL_CTX_sess_accept() returns the number of started SSL/TLS handshakes in server mode.

- -

SSL_CTX_sess_accept_good() returns the number of successfully established SSL/TLS sessions in server mode.

- -

SSL_CTX_sess_accept_renegotiate() returns the number of started renegotiations in server mode.

- -

SSL_CTX_sess_hits() returns the number of successfully reused sessions. In client mode a session set with SSL_set_session(3) successfully reused is counted as a hit. In server mode a session successfully retrieved from internal or external cache is counted as a hit.

- -

SSL_CTX_sess_cb_hits() returns the number of successfully retrieved sessions from the external session cache in server mode.

- -

SSL_CTX_sess_misses() returns the number of sessions proposed by clients that were not found in the internal session cache in server mode.

- -

SSL_CTX_sess_timeouts() returns the number of sessions proposed by clients and either found in the internal or external session cache in server mode, but that were invalid due to timeout. These sessions are not included in the SSL_CTX_sess_hits() count.

- -

SSL_CTX_sess_cache_full() returns the number of sessions that were removed because the maximum session cache size was exceeded.

- -

RETURN VALUES

- -

The functions return the values indicated in the DESCRIPTION section.

- -

SEE ALSO

- -

ssl(7), SSL_set_session(3), SSL_CTX_set_session_cache_mode(3) SSL_CTX_sess_set_cache_size(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_cache_size.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_cache_size.html deleted file mode 100644 index 4f1146ac..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_cache_size.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -SSL_CTX_sess_set_cache_size - - - - - - - - - - -

NAME

- -

SSL_CTX_sess_set_cache_size, SSL_CTX_sess_get_cache_size - manipulate session cache size

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_sess_set_cache_size(SSL_CTX *ctx, long t);
-long SSL_CTX_sess_get_cache_size(SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_sess_set_cache_size() sets the size of the internal session cache of context ctx to t. This value is a hint and not an absolute; see the notes below.

- -

SSL_CTX_sess_get_cache_size() returns the currently valid session cache size.

- -

NOTES

- -

The internal session cache size is SSL_SESSION_CACHE_MAX_SIZE_DEFAULT, currently 1024*20, so that up to 20000 sessions can be held. This size can be modified using the SSL_CTX_sess_set_cache_size() call. A special case is the size 0, which is used for unlimited size.

- -

If adding the session makes the cache exceed its size, then unused sessions are dropped from the end of the cache. Cache space may also be reclaimed by calling SSL_CTX_flush_sessions(3) to remove expired sessions.

- -

If the size of the session cache is reduced and more sessions are already in the session cache, old session will be removed at the next time a session shall be added. This removal is not synchronized with the expiration of sessions.

- -

RETURN VALUES

- -

SSL_CTX_sess_set_cache_size() returns the previously valid size.

- -

SSL_CTX_sess_get_cache_size() returns the currently valid size.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_session_cache_mode(3), SSL_CTX_sess_number(3), SSL_CTX_flush_sessions(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_get_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_get_cb.html deleted file mode 100644 index c00cf225..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sess_set_get_cb.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -SSL_CTX_sess_set_get_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_sess_set_new_cb, SSL_CTX_sess_set_remove_cb, SSL_CTX_sess_set_get_cb, SSL_CTX_sess_get_new_cb, SSL_CTX_sess_get_remove_cb, SSL_CTX_sess_get_get_cb - provide callback functions for server side external session caching

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_sess_set_new_cb(SSL_CTX *ctx,
-                             int (*new_session_cb)(SSL *, SSL_SESSION *));
-void SSL_CTX_sess_set_remove_cb(SSL_CTX *ctx,
-                                void (*remove_session_cb)(SSL_CTX *ctx,
-                                                          SSL_SESSION *));
-void SSL_CTX_sess_set_get_cb(SSL_CTX *ctx,
-                             SSL_SESSION (*get_session_cb)(SSL *,
-                                                           const unsigned char *,
-                                                           int, int *));
-
-int (*SSL_CTX_sess_get_new_cb(SSL_CTX *ctx))(struct ssl_st *ssl,
-                                             SSL_SESSION *sess);
-void (*SSL_CTX_sess_get_remove_cb(SSL_CTX *ctx))(struct ssl_ctx_st *ctx,
-                                                 SSL_SESSION *sess);
-SSL_SESSION *(*SSL_CTX_sess_get_get_cb(SSL_CTX *ctx))(struct ssl_st *ssl,
-                                                      const unsigned char *data,
-                                                      int len, int *copy);
- -

DESCRIPTION

- -

SSL_CTX_sess_set_new_cb() sets the callback function that is called whenever a new session was negotiated.

- -

SSL_CTX_sess_set_remove_cb() sets the callback function that is called whenever a session is removed by the SSL engine. For example, this can occur because a session is considered faulty or has become obsolete because of exceeding the timeout value.

- -

SSL_CTX_sess_set_get_cb() sets the callback function that is called whenever a TLS client proposed to resume a session but the session could not be found in the internal session cache (see SSL_CTX_set_session_cache_mode(3)). (TLS server only.)

- -

SSL_CTX_sess_get_new_cb(), SSL_CTX_sess_get_remove_cb(), and SSL_CTX_sess_get_get_cb() retrieve the function pointers set by the corresponding set callback functions. If a callback function has not been set, the NULL pointer is returned.

- -

NOTES

- -

In order to allow external session caching, synchronization with the internal session cache is realized via callback functions. Inside these callback functions, session can be saved to disk or put into a database using the d2i_SSL_SESSION(3) interface.

- -

The new_session_cb() is called whenever a new session has been negotiated and session caching is enabled (see SSL_CTX_set_session_cache_mode(3)). The new_session_cb() is passed the ssl connection and the nascent ssl session sess. Since sessions are reference-counted objects, the reference count on the session is incremented before the callback, on behalf of the application. If the callback returns 0, the session will be immediately removed from the internal cache and the reference count released. If the callback returns 1, the application retains the reference (for an entry in the application-maintained "external session cache"), and is responsible for calling SSL_SESSION_free() when the session reference is no longer in use.

- -

Note that in TLSv1.3, sessions are established after the main handshake has completed. The server decides when to send the client the session information and this may occur some time after the end of the handshake (or not at all). This means that applications should expect the new_session_cb() function to be invoked during the handshake (for <= TLSv1.2) or after the handshake (for TLSv1.3). It is also possible in TLSv1.3 for multiple sessions to be established with a single connection. In these case the new_session_cb() function will be invoked multiple times.

- -

In TLSv1.3 it is recommended that each SSL_SESSION object is only used for resumption once. One way of enforcing that is for applications to call SSL_CTX_remove_session(3) after a session has been used.

- -

The remove_session_cb() is called whenever the SSL engine removes a session from the internal cache. This can happen when the session is removed because it is expired or when a connection was not shutdown cleanly. It also happens for all sessions in the internal session cache when SSL_CTX_free(3) is called. The remove_session_cb() is passed the ctx and the ssl session sess. It does not provide any feedback.

- -

The get_session_cb() is only called on SSL/TLS servers, and is given the session id proposed by the client. The get_session_cb() is always called, even when session caching was disabled. The get_session_cb() is passed the ssl connection and the session id of length length at the memory location data. By setting the parameter copy to 1, the callback can require the SSL engine to increment the reference count of the SSL_SESSION object; setting copy to 0 causes the reference count to remain unchanged. If the get_session_cb() does not write to copy, the reference count is incremented and the session must be explicitly freed with SSL_SESSION_free(3).

- -

RETURN VALUES

- -

SSL_CTX_sess_get_new_cb(), SSL_CTX_sess_get_remove_cb() and SSL_CTX_sess_get_get_cb() return different callback function pointers respectively.

- -

SEE ALSO

- -

ssl(7), d2i_SSL_SESSION(3), SSL_CTX_set_session_cache_mode(3), SSL_CTX_flush_sessions(3), SSL_SESSION_free(3), SSL_CTX_free(3)

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sessions.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sessions.html deleted file mode 100644 index f39028d3..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_sessions.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -SSL_CTX_sessions - - - - - - - - - - -

NAME

- -

SSL_CTX_sessions - access internal session cache

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-LHASH_OF(SSL_SESSION) *SSL_CTX_sessions(SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_sessions() returns a pointer to the lhash databases containing the internal session cache for ctx.

- -

NOTES

- -

The sessions in the internal session cache are kept in an LHASH(3) type database. It is possible to directly access this database e.g. for searching. In parallel, the sessions form a linked list which is maintained separately from the LHASH(3) operations, so that the database must not be modified directly but by using the SSL_CTX_add_session(3) family of functions.

- -

RETURN VALUES

- -

SSL_CTX_sessions() returns a pointer to the lhash of SSL_SESSION.

- -

SEE ALSO

- -

ssl(7), LHASH(3), SSL_CTX_add_session(3), SSL_CTX_set_session_cache_mode(3)

- -

COPYRIGHT

- -

Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set0_CA_list.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set0_CA_list.html deleted file mode 100644 index 24dfbaae..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set0_CA_list.html +++ /dev/null @@ -1,130 +0,0 @@ - - - - -SSL_CTX_set0_CA_list - - - - - - - - - - -

NAME

- -

SSL_CTX_set_client_CA_list, SSL_set_client_CA_list, SSL_get_client_CA_list, SSL_CTX_get_client_CA_list, SSL_CTX_add_client_CA, SSL_add_client_CA, SSL_set0_CA_list, SSL_CTX_set0_CA_list, SSL_get0_CA_list, SSL_CTX_get0_CA_list, SSL_add1_to_CA_list, SSL_CTX_add1_to_CA_list, SSL_get0_peer_CA_list - get or set CA list

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_client_CA_list(SSL_CTX *ctx, STACK_OF(X509_NAME) *list);
-void SSL_set_client_CA_list(SSL *s, STACK_OF(X509_NAME) *list);
-STACK_OF(X509_NAME) *SSL_get_client_CA_list(const SSL *s);
-STACK_OF(X509_NAME) *SSL_CTX_get_client_CA_list(const SSL_CTX *ctx);
-int SSL_CTX_add_client_CA(SSL_CTX *ctx, X509 *cacert);
-int SSL_add_client_CA(SSL *ssl, X509 *cacert);
-
-void SSL_CTX_set0_CA_list(SSL_CTX *ctx, STACK_OF(X509_NAME) *name_list);
-void SSL_set0_CA_list(SSL *s, STACK_OF(X509_NAME) *name_list);
-const STACK_OF(X509_NAME) *SSL_CTX_get0_CA_list(const SSL_CTX *ctx);
-const STACK_OF(X509_NAME) *SSL_get0_CA_list(const SSL *s);
-int SSL_CTX_add1_to_CA_list(SSL_CTX *ctx, const X509 *x);
-int SSL_add1_to_CA_list(SSL *ssl, const X509 *x);
-
-const STACK_OF(X509_NAME) *SSL_get0_peer_CA_list(const SSL *s);
- -

DESCRIPTION

- -

The functions described here set and manage the list of CA names that are sent between two communicating peers.

- -

For TLS versions 1.2 and earlier the list of CA names is only sent from the server to the client when requesting a client certificate. So any list of CA names set is never sent from client to server and the list of CA names retrieved by SSL_get0_peer_CA_list() is always NULL.

- -

For TLS 1.3 the list of CA names is sent using the certificate_authorities extension and may be sent by a client (in the ClientHello message) or by a server (when requesting a certificate).

- -

In most cases it is not necessary to set CA names on the client side. The list of CA names that are acceptable to the client will be sent in plaintext to the server. This has privacy implications and may also have performance implications if the list is large. This optional capability was introduced as part of TLSv1.3 and therefore setting CA names on the client side will have no impact if that protocol version has been disabled. Most servers do not need this and so this should be avoided unless required.

- -

The "client CA list" functions below only have an effect when called on the server side.

- -

SSL_CTX_set_client_CA_list() sets the list of CAs sent to the client when requesting a client certificate for ctx. Ownership of list is transferred to ctx and it should not be freed by the caller.

- -

SSL_set_client_CA_list() sets the list of CAs sent to the client when requesting a client certificate for the chosen ssl, overriding the setting valid for ssl's SSL_CTX object. Ownership of list is transferred to s and it should not be freed by the caller.

- -

SSL_CTX_get_client_CA_list() returns the list of client CAs explicitly set for ctx using SSL_CTX_set_client_CA_list(). The returned list should not be freed by the caller.

- -

SSL_get_client_CA_list() returns the list of client CAs explicitly set for ssl using SSL_set_client_CA_list() or ssl's SSL_CTX object with SSL_CTX_set_client_CA_list(), when in server mode. In client mode, SSL_get_client_CA_list returns the list of client CAs sent from the server, if any. The returned list should not be freed by the caller.

- -

SSL_CTX_add_client_CA() adds the CA name extracted from cacert to the list of CAs sent to the client when requesting a client certificate for ctx.

- -

SSL_add_client_CA() adds the CA name extracted from cacert to the list of CAs sent to the client when requesting a client certificate for the chosen ssl, overriding the setting valid for ssl's SSL_CTX object.

- -

SSL_get0_peer_CA_list() retrieves the list of CA names (if any) the peer has sent. This can be called on either the server or the client side. The returned list should not be freed by the caller.

- -

The "generic CA list" functions below are very similar to the "client CA list" functions except that they have an effect on both the server and client sides. The lists of CA names managed are separate - so you cannot (for example) set CA names using the "client CA list" functions and then get them using the "generic CA list" functions. Where a mix of the two types of functions has been used on the server side then the "client CA list" functions take precedence. Typically, on the server side, the "client CA list " functions should be used in preference. As noted above in most cases it is not necessary to set CA names on the client side.

- -

SSL_CTX_set0_CA_list() sets the list of CAs to be sent to the peer to name_list. Ownership of name_list is transferred to ctx and it should not be freed by the caller.

- -

SSL_set0_CA_list() sets the list of CAs to be sent to the peer to name_list overriding any list set in the parent SSL_CTX of s. Ownership of name_list is transferred to s and it should not be freed by the caller.

- -

SSL_CTX_get0_CA_list() retrieves any previously set list of CAs set for ctx. The returned list should not be freed by the caller.

- -

SSL_get0_CA_list() retrieves any previously set list of CAs set for s or if none are set the list from the parent SSL_CTX is retrieved. The returned list should not be freed by the caller.

- -

SSL_CTX_add1_to_CA_list() appends the CA subject name extracted from x to the list of CAs sent to peer for ctx.

- -

SSL_add1_to_CA_list() appends the CA subject name extracted from x to the list of CAs sent to the peer for s, overriding the setting in the parent SSL_CTX.

- -

NOTES

- -

When a TLS/SSL server requests a client certificate (see SSL_CTX_set_verify(3)), it sends a list of CAs, for which it will accept certificates, to the client.

- -

This list must explicitly be set using SSL_CTX_set_client_CA_list() or SSL_CTX_set0_CA_list() for ctx and SSL_set_client_CA_list() or SSL_set0_CA_list() for the specific ssl. The list specified overrides the previous setting. The CAs listed do not become trusted (list only contains the names, not the complete certificates); use SSL_CTX_load_verify_locations(3) to additionally load them for verification.

- -

If the list of acceptable CAs is compiled in a file, the SSL_load_client_CA_file(3) function can be used to help to import the necessary data.

- -

SSL_CTX_add_client_CA(), SSL_CTX_add1_to_CA_list(), SSL_add_client_CA() and SSL_add1_to_CA_list() can be used to add additional items the list of CAs. If no list was specified before using SSL_CTX_set_client_CA_list(), SSL_CTX_set0_CA_list(), SSL_set_client_CA_list() or SSL_set0_CA_list(), a new CA list for ctx or ssl (as appropriate) is opened.

- -

RETURN VALUES

- -

SSL_CTX_set_client_CA_list(), SSL_set_client_CA_list(), SSL_CTX_set_client_CA_list(), SSL_set_client_CA_list(), SSL_CTX_set0_CA_list() and SSL_set0_CA_list() do not return a value.

- -

SSL_CTX_get_client_CA_list(), SSL_get_client_CA_list(), SSL_CTX_get0_CA_list() and SSL_get0_CA_list() return a stack of CA names or NULL is no CA names are set.

- -

SSL_CTX_add_client_CA(),SSL_add_client_CA(), SSL_CTX_add1_to_CA_list() and SSL_add1_to_CA_list() return 1 for success and 0 for failure.

- -

SSL_get0_peer_CA_list() returns a stack of CA names sent by the peer or NULL or an empty stack if no list was sent.

- -

EXAMPLES

- -

Scan all certificates in CAfile and list them as acceptable CAs:

- -
SSL_CTX_set_client_CA_list(ctx, SSL_load_client_CA_file(CAfile));
- -

SEE ALSO

- -

ssl(7), SSL_load_client_CA_file(3), SSL_CTX_load_verify_locations(3)

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_cert_comp_preference.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_cert_comp_preference.html deleted file mode 100644 index 2788d8e9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_cert_comp_preference.html +++ /dev/null @@ -1,133 +0,0 @@ - - - - -SSL_CTX_set1_cert_comp_preference - - - - - - - - - - -

NAME

- -

SSL_CTX_set1_cert_comp_preference, SSL_set1_cert_comp_preference, SSL_CTX_compress_certs, SSL_compress_certs, SSL_CTX_get1_compressed_cert, SSL_get1_compressed_cert, SSL_CTX_set1_compressed_cert, SSL_set1_compressed_cert - Certificate compression functions

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set1_cert_comp_preference(SSL_CTX *ctx, int *algs, size_t len);
-int SSL_set1_cert_comp_preference(SSL *ssl, int *algs, size_t len);
-
-int SSL_CTX_compress_certs(SSL_CTX *ctx, int alg);
-int SSL_compress_certs(SSL *ssl, int alg);
-
-size_t SSL_CTX_get1_compressed_cert(SSL_CTX *ctx, int alg, unsigned char **data,
-                                    size_t *orig_len);
-size_t SSL_get1_compressed_cert(SSL *ssl, int alg, unsigned char **data,
-                                size_t *orig_len);
-
-int SSL_CTX_set1_compressed_cert(SSL_CTX *ctx, int alg,
-                                 unsigned char *comp_data,
-                                 size_t comp_length, size_t orig_length);
-int SSL_set1_compressed_cert(SSL *ssl, int alg, unsigned char *comp_data,
-                             size_t comp_length, size_t orig_length);
- -

DESCRIPTION

- -

These functions control the certificate compression feature. Certificate compression is only available for TLSv1.3 as defined in RFC8879.

- -

SSL_CTX_set1_cert_comp_preference() and SSL_set1_cert_comp_preference() are used to specify the preferred compression algorithms. The algs argument is an array of algorithms, and length is number of elements in the algs array. Only those algorithms enabled in the library will be accepted in algs, unknown algorithms in algs are ignored. On an error, the preference order is left unmodified.

- -

The following compression algorithms (alg arguments) may be used:

- - - -

The above is also the default preference order. If a preference order is not specified, then the default preference order is sent to the peer and the received peer's preference order will be used when compressing a certificate. Otherwise, the configured preference order is sent to the peer and is used to filter the peer's preference order.

- -

SSL_CTX_compress_certs() and SSL_compress_certs() are used to pre-compress all the configured certificates on an SSL_CTX/SSL object with algorithm alg. If alg is 0, then the certificates are compressed with the algorithms specified in the preference list. Calling these functions on a client SSL_CTX/SSL object will result in an error, as only server certificates may be pre-compressed.

- -

SSL_CTX_get1_compressed_cert() and SSL_get1_compressed_cert() are used to get the pre-compressed certificate most recently set that may be stored for later use. Calling these functions on a client SSL_CTX/SSL object will result in an error, as only server certificates may be pre-compressed. The data and orig_len arguments are required.

- -

The compressed certificate data may be passed to SSL_CTX_set1_compressed_cert() or SSL_set1_compressed_cert() to provide a pre-compressed version of the most recently set certificate. This pre-compressed certificate can only be used by a server.

- -

NOTES

- -

Each side of the connection sends their compression algorithm preference list to their peer indicating compressed certificate support. The received preference list is filtered by the configured preference list (i.e. the intersection is saved). As the default list includes all the enabled algorithms, not specifying a preference will allow any enabled algorithm by the peer. The filtered peer's preference order is used to determine what algorithm to use when sending a compressed certificate.

- -

Only server certificates may be pre-compressed. Calling any of these functions (except SSL_CTX_set1_cert_comp_preference()/SSL_set1_cert_comp_preference()) on a client SSL_CTX/SSL object will return an error. Client certificates are compressed on-demand as unique context data from the server is compressed along with the certificate.

- -

For SSL_CTX_set1_cert_comp_preference() and SSL_set1_cert_comp_preference() the len argument is the size of the algs argument in bytes.

- -

The compressed certificate returned by SSL_CTX_get1_compressed_cert() and SSL_get1_compressed_cert() is the last certificate set on the SSL_CTX/SSL object. The certificate is copied by the function and the caller must free *data via OPENSSL_free().

- -

The compressed certificate data set by SSL_CTX_set1_compressed_cert() and SSL_set1_compressed_cert() is copied into the SSL_CTX/SSL object.

- -

SSL_CTX_compress_certs() and SSL_compress_certs() return an error under the following conditions:

- - - -

Sending compressed certificates may be disabled on a connection via the SSL_OP_NO_TX_CERTIFICATE_COMPRESSION option. Receiving compressed certificates may be disabled on a connection via the SSL_OP_NO_RX_CERTIFICATE_COMPRESSION option.

- -

RETURN VALUES

- -

SSL_CTX_set1_cert_comp_preference(), SSL_set1_cert_comp_preference(), SSL_CTX_compress_certs(), SSL_compress_certs(), SSL_CTX_set1_compressed_cert(), and SSL_set1_compressed_cert() return 1 for success and 0 on error.

- -

SSL_CTX_get1_compressed_cert() and SSL_get1_compressed_cert() return the length of the allocated memory on success and 0 on error.

- -

SEE ALSO

- -

SSL_CTX_set_options(3), SSL_CTX_use_certificate(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_curves.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_curves.html deleted file mode 100644 index 74b41193..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_curves.html +++ /dev/null @@ -1,132 +0,0 @@ - - - - -SSL_CTX_set1_curves - - - - - - - - - - -

NAME

- -

SSL_CTX_set1_groups, SSL_CTX_set1_groups_list, SSL_set1_groups, SSL_set1_groups_list, SSL_get1_groups, SSL_get0_iana_groups, SSL_get_shared_group, SSL_get_negotiated_group, SSL_CTX_set1_curves, SSL_CTX_set1_curves_list, SSL_set1_curves, SSL_set1_curves_list, SSL_get1_curves, SSL_get_shared_curve - EC supported curve functions

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set1_groups(SSL_CTX *ctx, int *glist, int glistlen);
-int SSL_CTX_set1_groups_list(SSL_CTX *ctx, char *list);
-
-int SSL_set1_groups(SSL *ssl, int *glist, int glistlen);
-int SSL_set1_groups_list(SSL *ssl, char *list);
-
-int SSL_get1_groups(SSL *ssl, int *groups);
-int SSL_get0_iana_groups(SSL *ssl, uint16_t **out);
-int SSL_get_shared_group(SSL *s, int n);
-int SSL_get_negotiated_group(SSL *s);
-
-int SSL_CTX_set1_curves(SSL_CTX *ctx, int *clist, int clistlen);
-int SSL_CTX_set1_curves_list(SSL_CTX *ctx, char *list);
-
-int SSL_set1_curves(SSL *ssl, int *clist, int clistlen);
-int SSL_set1_curves_list(SSL *ssl, char *list);
-
-int SSL_get1_curves(SSL *ssl, int *curves);
-int SSL_get_shared_curve(SSL *s, int n);
- -

DESCRIPTION

- -

For all of the functions below that set the supported groups there must be at least one group in the list. A number of these functions identify groups via a unique integer NID value. However, support for some groups may be added by external providers. In this case there will be no NID assigned for the group. When setting such groups applications should use the "list" form of these functions (i.e. SSL_CTX_set1_groups_list() and SSL_set1_groups_list).

- -

SSL_CTX_set1_groups() sets the supported groups for ctx to glistlen groups in the array glist. The array consist of all NIDs of supported groups. Currently supported groups for TLSv1.3 are NID_X9_62_prime256v1, NID_secp384r1, NID_secp521r1, NID_X25519, NID_X448, NID_brainpoolP256r1tls13, NID_brainpoolP384r1tls13, NID_brainpoolP512r1tls13, NID_ffdhe2048, NID_ffdhe3072, NID_ffdhe4096, NID_ffdhe6144 and NID_ffdhe8192. OpenSSL will use this array in different ways depending on TLS role and version:

- -
- -
For a TLS client, the groups are used directly in the supported groups extension. The extension's preference order, to be evaluated by the server, is determined by the order of the elements in the array.
-
- -
-
For a TLS 1.2 server, the groups determine the selected group. If SSL_OP_CIPHER_SERVER_PREFERENCE is set, the order of the elements in the array determines the selected group. Otherwise, the order is ignored and the client's order determines the selection.
-
- -
-
For a TLS 1.3 server, the groups determine the selected group, but selection is more complex. A TLS 1.3 client sends both a group list as well as a predicted subset of groups. Choosing a group outside the predicted subset incurs an extra roundtrip. However, in some situations, the most preferred group may not be predicted. OpenSSL considers all supported groups to be comparable in security and prioritizes avoiding roundtrips above either client or server preference order. If an application uses an external provider to extend OpenSSL with, e.g., a post-quantum algorithm, this behavior may allow a network attacker to downgrade connections to a weaker algorithm.
-
- -
-
- -

SSL_CTX_set1_groups_list() sets the supported groups for ctx to string list. The string is a colon separated list of group names, for example "P-521:P-384:P-256:X25519:ffdhe2048". The groups are used as in SSL_CTX_set1_groups(), described above. Currently supported groups for TLSv1.3 are P-256, P-384, P-521, X25519, X448, brainpoolP256r1tls13, brainpoolP384r1tls13, brainpoolP512r1tls13, ffdhe2048, ffdhe3072, ffdhe4096, ffdhe6144 and ffdhe8192. Support for other groups may be added by external providers, however note the discussion on TLS 1.3 selection criteria above. If a group name is preceded with the ? character, it will be ignored if an implementation is missing.

- -

SSL_set1_groups() and SSL_set1_groups_list() are similar except they set supported groups for the SSL structure ssl.

- -

SSL_get1_groups() returns the set of supported groups sent by a client in the supported groups extension. It returns the total number of supported groups. The groups parameter can be NULL to simply return the number of groups for memory allocation purposes. The groups array is in the form of a set of group NIDs in preference order. It can return zero if the client did not send a supported groups extension. If a supported group NID is unknown then the value is set to the bitwise OR of TLSEXT_nid_unknown (0x1000000) and the id of the group.

- -

SSL_get0_iana_groups() retrieves the list of groups sent by the client in the supported_groups extension. The *out array of bytes is populated with the host-byte-order representation of the uint16_t group identifiers, as assigned by IANA. The group list is returned in the same order that was received in the ClientHello. The return value is the number of groups, not the number of bytes written.

- -

SSL_get_shared_group() returns the NID of the shared group n for a server-side SSL ssl. If n is -1 then the total number of shared groups is returned, which may be zero. Other than for diagnostic purposes, most applications will only be interested in the first shared group so n is normally set to zero. If the value n is out of range, NID_undef is returned. If the NID for the shared group is unknown then the value is set to the bitwise OR of TLSEXT_nid_unknown (0x1000000) and the id of the group.

- -

SSL_get_negotiated_group() returns the NID of the negotiated group used for the handshake key exchange process. For TLSv1.3 connections this typically reflects the state of the current connection, though in the case of PSK-only resumption, the returned value will be from a previous connection. For earlier TLS versions, when a session has been resumed, it always reflects the group used for key exchange during the initial handshake (otherwise it is from the current, non-resumption, connection). This can be called by either client or server. If the NID for the shared group is unknown then the value is set to the bitwise OR of TLSEXT_nid_unknown (0x1000000) and the id of the group. See also SSL_get0_group_name(3) which returns the name of the negotiated group directly and is generally preferred over SSL_get_negotiated_group().

- -

All these functions are implemented as macros.

- -

The curve functions are synonyms for the equivalently named group functions and are identical in every respect. They exist because, prior to TLS1.3, there was only the concept of supported curves. In TLS1.3 this was renamed to supported groups, and extended to include Diffie Hellman groups. The group functions should be used in preference.

- -

NOTES

- -

If an application wishes to make use of several of these functions for configuration purposes either on a command line or in a file it should consider using the SSL_CONF interface instead of manually parsing options.

- -

RETURN VALUES

- -

SSL_CTX_set1_groups(), SSL_CTX_set1_groups_list(), SSL_set1_groups() and SSL_set1_groups_list(), return 1 for success and 0 for failure.

- -

SSL_get1_groups() returns the number of groups, which may be zero.

- -

SSL_get0_iana_groups() returns the number of (uint16_t) groups, which may be zero.

- -

SSL_get_shared_group() returns the NID of shared group n or NID_undef if there is no shared group n; or the total number of shared groups if n is -1.

- -

When called on a client ssl, SSL_get_shared_group() has no meaning and returns -1.

- -

SSL_get_negotiated_group() returns the NID of the negotiated group used for key exchange, or NID_undef if there was no negotiated group.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_add_extra_chain_cert(3), SSL_get0_group_name(3)

- -

HISTORY

- -

The curve functions were added in OpenSSL 1.0.2. The equivalent group functions were added in OpenSSL 1.1.1. The SSL_get_negotiated_group() function was added in OpenSSL 3.0.0.

- -

Support for ignoring unknown groups in SSL_CTX_set1_groups_list() and SSL_set1_groups_list() was added in OpenSSL 3.3.

- -

Earlier versions of this document described the list as a preference order. However, OpenSSL's behavior as a TLS 1.3 server is to consider all supported groups as comparable in security.

- -

COPYRIGHT

- -

Copyright 2013-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_sigalgs.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_sigalgs.html deleted file mode 100644 index f7068e4e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_sigalgs.html +++ /dev/null @@ -1,111 +0,0 @@ - - - - -SSL_CTX_set1_sigalgs - - - - - - - - - - -

NAME

- -

SSL_CTX_set1_sigalgs, SSL_set1_sigalgs, SSL_CTX_set1_sigalgs_list, SSL_set1_sigalgs_list, SSL_CTX_set1_client_sigalgs, SSL_set1_client_sigalgs, SSL_CTX_set1_client_sigalgs_list, SSL_set1_client_sigalgs_list - set supported signature algorithms

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set1_sigalgs(SSL_CTX *ctx, const int *slist, long slistlen);
-long SSL_set1_sigalgs(SSL *ssl, const int *slist, long slistlen);
-long SSL_CTX_set1_sigalgs_list(SSL_CTX *ctx, const char *str);
-long SSL_set1_sigalgs_list(SSL *ssl, const char *str);
-
-long SSL_CTX_set1_client_sigalgs(SSL_CTX *ctx, const int *slist, long slistlen);
-long SSL_set1_client_sigalgs(SSL *ssl, const int *slist, long slistlen);
-long SSL_CTX_set1_client_sigalgs_list(SSL_CTX *ctx, const char *str);
-long SSL_set1_client_sigalgs_list(SSL *ssl, const char *str);
- -

DESCRIPTION

- -

SSL_CTX_set1_sigalgs() and SSL_set1_sigalgs() set the supported signature algorithms for ctx or ssl. The array slist of length slistlen must consist of pairs of NIDs corresponding to digest and public key algorithms.

- -

SSL_CTX_set1_sigalgs_list() and SSL_set1_sigalgs_list() set the supported signature algorithms for ctx or ssl. The str parameter must be a null terminated string consisting of a colon separated list of elements, where each element is either a combination of a public key algorithm and a digest separated by +, or a TLS 1.3-style named SignatureScheme such as rsa_pss_pss_sha256. If a list entry is preceded with the ? character, it will be ignored if an implementation is missing.

- -

SSL_CTX_set1_client_sigalgs(), SSL_set1_client_sigalgs(), SSL_CTX_set1_client_sigalgs_list() and SSL_set1_client_sigalgs_list() set signature algorithms related to client authentication, otherwise they are identical to SSL_CTX_set1_sigalgs(), SSL_set1_sigalgs(), SSL_CTX_set1_sigalgs_list() and SSL_set1_sigalgs_list().

- -

All these functions are implemented as macros. The signature algorithm parameter (integer array or string) is not freed: the application should free it, if necessary.

- -

NOTES

- -

If an application wishes to allow the setting of signature algorithms as one of many user configurable options it should consider using the more flexible SSL_CONF API instead.

- -

The signature algorithms set by a client are used directly in the supported signature algorithm in the client hello message.

- -

The supported signature algorithms set by a server are not sent to the client but are used to determine the set of shared signature algorithms and (if server preferences are set with SSL_OP_CIPHER_SERVER_PREFERENCE) their order.

- -

The client authentication signature algorithms set by a server are sent in a certificate request message if client authentication is enabled, otherwise they are unused.

- -

Similarly client authentication signature algorithms set by a client are used to determined the set of client authentication shared signature algorithms.

- -

Signature algorithms will neither be advertised nor used if the security level prohibits them (for example SHA1 if the security level is 4 or more).

- -

Currently the NID_md5, NID_sha1, NID_sha224, NID_sha256, NID_sha384 and NID_sha512 digest NIDs are supported and the public key algorithm NIDs EVP_PKEY_RSA, EVP_PKEY_RSA_PSS, EVP_PKEY_DSA and EVP_PKEY_EC.

- -

The short or long name values for digests can be used in a string (for example "MD5", "SHA1", "SHA224", "SHA256", "SHA384", "SHA512") and the public key algorithm strings "RSA", "RSA-PSS", "DSA" or "ECDSA".

- -

The TLS 1.3 signature scheme names (such as "rsa_pss_pss_sha256") can also be used with the _list forms of the API.

- -

The use of MD5 as a digest is strongly discouraged due to security weaknesses.

- -

RETURN VALUES

- -

All these functions return 1 for success and 0 for failure.

- -

EXAMPLES

- -

Set supported signature algorithms to SHA256 with ECDSA and SHA256 with RSA using an array:

- -
const int slist[] = {NID_sha256, EVP_PKEY_EC, NID_sha256, EVP_PKEY_RSA};
-
-SSL_CTX_set1_sigalgs(ctx, slist, 4);
- -

Set supported signature algorithms to SHA256 with ECDSA and SHA256 with RSA using a string:

- -
SSL_CTX_set1_sigalgs_list(ctx, "ECDSA+SHA256:RSA+SHA256");
- -

SEE ALSO

- -

ssl(7), SSL_get_shared_sigalgs(3), SSL_CONF_CTX_new(3)

- -

HISTORY

- -

Support for ignoring unknown signature algorithms in SSL_CTX_set1_sigalgs_list(), SSL_set1_sigalgs_list(), SSL_CTX_set1_client_sigalgs_list() and SSL_set1_client_sigalgs_list() was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_verify_cert_store.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_verify_cert_store.html deleted file mode 100644 index 8bd9aeb8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set1_verify_cert_store.html +++ /dev/null @@ -1,96 +0,0 @@ - - - - -SSL_CTX_set1_verify_cert_store - - - - - - - - - - -

NAME

- -

SSL_CTX_set0_verify_cert_store, SSL_CTX_set1_verify_cert_store, SSL_CTX_set0_chain_cert_store, SSL_CTX_set1_chain_cert_store, SSL_set0_verify_cert_store, SSL_set1_verify_cert_store, SSL_set0_chain_cert_store, SSL_set1_chain_cert_store, SSL_CTX_get0_verify_cert_store, SSL_CTX_get0_chain_cert_store, SSL_get0_verify_cert_store, SSL_get0_chain_cert_store - set certificate verification or chain store

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set0_verify_cert_store(SSL_CTX *ctx, X509_STORE *st);
-int SSL_CTX_set1_verify_cert_store(SSL_CTX *ctx, X509_STORE *st);
-int SSL_CTX_set0_chain_cert_store(SSL_CTX *ctx, X509_STORE *st);
-int SSL_CTX_set1_chain_cert_store(SSL_CTX *ctx, X509_STORE *st);
-int SSL_CTX_get0_verify_cert_store(SSL_CTX *ctx, X509_STORE **st);
-int SSL_CTX_get0_chain_cert_store(SSL_CTX *ctx, X509_STORE **st);
-
-int SSL_set0_verify_cert_store(SSL *ctx, X509_STORE *st);
-int SSL_set1_verify_cert_store(SSL *ctx, X509_STORE *st);
-int SSL_set0_chain_cert_store(SSL *ctx, X509_STORE *st);
-int SSL_set1_chain_cert_store(SSL *ctx, X509_STORE *st);
-int SSL_get0_verify_cert_store(SSL *ctx, X509_STORE **st);
-int SSL_get0_chain_cert_store(SSL *ctx, X509_STORE **st);
- -

DESCRIPTION

- -

SSL_CTX_set0_verify_cert_store() and SSL_CTX_set1_verify_cert_store() set the certificate store used for certificate verification to st.

- -

SSL_CTX_set0_chain_cert_store() and SSL_CTX_set1_chain_cert_store() set the certificate store used for certificate chain building to st.

- -

SSL_set0_verify_cert_store(), SSL_set1_verify_cert_store(), SSL_set0_chain_cert_store() and SSL_set1_chain_cert_store() are similar except they apply to SSL structure ssl.

- -

SSL_CTX_get0_verify_chain_store(), SSL_get0_verify_chain_store(), SSL_CTX_get0_chain_cert_store() and SSL_get0_chain_cert_store() retrieve the objects previously set via the above calls. A pointer to the object (or NULL if no such object has been set) is written to *st.

- -

All these functions are implemented as macros. Those containing a 1 increment the reference count of the supplied store so it must be freed at some point after the operation. Those containing a 0 do not increment reference counts and the supplied store MUST NOT be freed after the operation.

- -

NOTES

- -

The stores pointers associated with an SSL_CTX structure are copied to any SSL structures when SSL_new() is called. As a result SSL structures will not be affected if the parent SSL_CTX store pointer is set to a new value.

- -

The verification store is used to verify the certificate chain sent by the peer: that is an SSL/TLS client will use the verification store to verify the server's certificate chain and a SSL/TLS server will use it to verify any client certificate chain.

- -

The chain store is used to build the certificate chain. Details of the chain building and checking process are described in "Certification Path Building" in openssl-verification-options(1) and "Certification Path Validation" in openssl-verification-options(1).

- -

If the mode SSL_MODE_NO_AUTO_CHAIN is set or a certificate chain is configured already (for example using the functions such as SSL_CTX_add1_chain_cert(3) or SSL_CTX_add_extra_chain_cert(3)) then automatic chain building is disabled.

- -

If the mode SSL_MODE_NO_AUTO_CHAIN is set then automatic chain building is disabled.

- -

If the chain or the verification store is not set then the store associated with the parent SSL_CTX is used instead to retain compatibility with previous versions of OpenSSL.

- -

RETURN VALUES

- -

All these functions return 1 for success and 0 for failure.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_add_extra_chain_cert(3) SSL_CTX_set0_chain(3) SSL_CTX_set1_chain(3) SSL_CTX_add0_chain_cert(3) SSL_CTX_add1_chain_cert(3) SSL_set0_chain(3) SSL_set1_chain(3) SSL_add0_chain_cert(3) SSL_add1_chain_cert(3) SSL_CTX_build_cert_chain(3) SSL_build_cert_chain(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2013-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_alpn_select_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_alpn_select_cb.html deleted file mode 100644 index 9076a604..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_alpn_select_cb.html +++ /dev/null @@ -1,171 +0,0 @@ - - - - -SSL_CTX_set_alpn_select_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_alpn_protos, SSL_set_alpn_protos, SSL_CTX_set_alpn_select_cb, SSL_CTX_set_next_proto_select_cb, SSL_CTX_set_next_protos_advertised_cb, SSL_select_next_proto, SSL_get0_alpn_selected, SSL_get0_next_proto_negotiated - handle application layer protocol negotiation (ALPN)

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set_alpn_protos(SSL_CTX *ctx, const unsigned char *protos,
-                            unsigned int protos_len);
-int SSL_set_alpn_protos(SSL *ssl, const unsigned char *protos,
-                        unsigned int protos_len);
-void SSL_CTX_set_alpn_select_cb(SSL_CTX *ctx,
-                                int (*cb) (SSL *ssl,
-                                           const unsigned char **out,
-                                           unsigned char *outlen,
-                                           const unsigned char *in,
-                                           unsigned int inlen,
-                                           void *arg), void *arg);
-void SSL_get0_alpn_selected(const SSL *ssl, const unsigned char **data,
-                            unsigned int *len);
-
-void SSL_CTX_set_next_protos_advertised_cb(SSL_CTX *ctx,
-                                           int (*cb)(SSL *ssl,
-                                                     const unsigned char **out,
-                                                     unsigned int *outlen,
-                                                     void *arg),
-                                           void *arg);
-void SSL_CTX_set_next_proto_select_cb(SSL_CTX *ctx,
-                              int (*cb)(SSL *s,
-                                        unsigned char **out,
-                                        unsigned char *outlen,
-                                        const unsigned char *in,
-                                        unsigned int inlen,
-                                        void *arg),
-                              void *arg);
-int SSL_select_next_proto(unsigned char **out, unsigned char *outlen,
-                          const unsigned char *server,
-                          unsigned int server_len,
-                          const unsigned char *client,
-                          unsigned int client_len);
-void SSL_get0_next_proto_negotiated(const SSL *s, const unsigned char **data,
-                            unsigned *len);
- -

DESCRIPTION

- -

SSL_CTX_set_alpn_protos() and SSL_set_alpn_protos() are used by the client to set the list of protocols available to be negotiated. The protos must be in protocol-list format, described below. The length of protos is specified in protos_len. Setting protos_len to 0 clears any existing list of ALPN protocols and no ALPN extension will be sent to the server.

- -

SSL_CTX_set_alpn_select_cb() sets the application callback cb used by a server to select which protocol to use for the incoming connection. When cb is NULL, ALPN is not used. The arg value is a pointer which is passed to the application callback.

- -

cb is the application defined callback. The in, inlen parameters are a vector in protocol-list format. The value of the out, outlen vector should be set to the value of a single protocol selected from the in, inlen vector. The out buffer may point directly into in, or to a buffer that outlives the handshake. The arg parameter is the pointer set via SSL_CTX_set_alpn_select_cb().

- -

SSL_select_next_proto() is a helper function used to select protocols. It implements the standard protocol selection. It is expected that this function is called from the application callback cb. The protocol data in server, server_len and client, client_len must be in the protocol-list format described below. The first item in the server, server_len list that matches an item in the client, client_len list is selected, and returned in out, outlen. The out value will point into either server or client, so it should be copied immediately. The client list must include at least one valid (nonempty) protocol entry in the list.

- -

The SSL_select_next_proto() helper function can be useful from either the ALPN callback or the NPN callback (described below). If no match is found, the first item in client, client_len is returned in out, outlen and OPENSSL_NPN_NO_OVERLAP is returned. This can be useful when implementing the NPN callback. In the ALPN case, the value returned in out and outlen must be ignored if OPENSSL_NPN_NO_OVERLAP has been returned from SSL_select_next_proto().

- -

SSL_CTX_set_next_proto_select_cb() sets a callback cb that is called when a client needs to select a protocol from the server's provided list, and a user-defined pointer argument arg which will be passed to this callback. For the callback itself, out must be set to point to the selected protocol (which may be within in). The length of the protocol name must be written into outlen. The server's advertised protocols are provided in in and inlen. The callback can assume that in is syntactically valid. The client must select a protocol (although it may be an empty, zero length protocol). It is fatal to the connection if this callback returns a value other than SSL_TLSEXT_ERR_OK or if the zero length protocol is selected. The arg parameter is the pointer set via SSL_CTX_set_next_proto_select_cb().

- -

SSL_CTX_set_next_protos_advertised_cb() sets a callback cb that is called when a TLS server needs a list of supported protocols for Next Protocol Negotiation. The returned list must be in protocol-list format, described below. The list is returned by setting out to point to it and outlen to its length. This memory will not be modified, but the SSL does keep a reference to it. The callback should return SSL_TLSEXT_ERR_OK if it wishes to advertise. Otherwise, no such extension will be included in the ServerHello.

- -

SSL_get0_alpn_selected() returns a pointer to the selected protocol in data with length len. It is not NUL-terminated. data is set to NULL and len is set to 0 if no protocol has been selected. data must not be freed.

- -

SSL_get0_next_proto_negotiated() sets data and len to point to the client's requested protocol for this connection. If the client did not request any protocol or NPN is not enabled, then data is set to NULL and len to 0. Note that the client can request any protocol it chooses. The value returned from this function need not be a member of the list of supported protocols provided by the callback.

- -

NPN functionality cannot be used with QUIC SSL objects. Use of ALPN is mandatory when using QUIC SSL objects. SSL_CTX_set_next_protos_advertised_cb() and SSL_CTX_set_next_proto_select_cb() have no effect if called on a QUIC SSL context.

- -

NOTES

- -

The protocol-lists must be in wire-format, which is defined as a vector of nonempty, 8-bit length-prefixed, byte strings. The length-prefix byte is not included in the length. Each string is limited to 255 bytes. A byte-string length of 0 is invalid. A truncated byte-string is invalid. The length of the vector is not in the vector itself, but in a separate variable.

- -

Example:

- -
unsigned char vector[] = {
-    6, 's', 'p', 'd', 'y', '/', '1',
-    8, 'h', 't', 't', 'p', '/', '1', '.', '1'
-};
-unsigned int length = sizeof(vector);
- -

The ALPN callback is executed after the servername callback; as that servername callback may update the SSL_CTX, and subsequently, the ALPN callback.

- -

If there is no ALPN proposed in the ClientHello, the ALPN callback is not invoked.

- -

RETURN VALUES

- -

SSL_CTX_set_alpn_protos() and SSL_set_alpn_protos() return 0 on success, and non-0 on failure. WARNING: these functions reverse the return value convention.

- -

SSL_select_next_proto() returns one of the following:

- -
- -
OPENSSL_NPN_NEGOTIATED
-
- -

A match was found and is returned in out, outlen.

- -
-
OPENSSL_NPN_NO_OVERLAP
-
- -

No match was found. The first item in client, client_len is returned in out, outlen (or NULL and 0 in the case where the first entry in client is invalid).

- -
-
- -

The ALPN select callback cb, must return one of the following:

- -
- -
SSL_TLSEXT_ERR_OK
-
- -

ALPN protocol selected.

- -
-
SSL_TLSEXT_ERR_ALERT_FATAL
-
- -

There was no overlap between the client's supplied list and the server configuration.

- -
-
SSL_TLSEXT_ERR_NOACK
-
- -

ALPN protocol not selected, e.g., because no ALPN protocols are configured for this connection.

- -
-
- -

The callback set using SSL_CTX_set_next_proto_select_cb() should return SSL_TLSEXT_ERR_OK if successful. Any other value is fatal to the connection.

- -

The callback set using SSL_CTX_set_next_protos_advertised_cb() should return SSL_TLSEXT_ERR_OK if it wishes to advertise. Otherwise, no such extension will be included in the ServerHello.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_tlsext_servername_callback(3), SSL_CTX_set_tlsext_servername_arg(3)

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_cb.html deleted file mode 100644 index 02317c9f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_cb.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -SSL_CTX_set_cert_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_cert_cb, SSL_set_cert_cb - handle certificate callback function

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_cert_cb(SSL_CTX *c, int (*cert_cb)(SSL *ssl, void *arg),
-                         void *arg);
-void SSL_set_cert_cb(SSL *s, int (*cert_cb)(SSL *ssl, void *arg), void *arg);
- -

DESCRIPTION

- -

SSL_CTX_set_cert_cb() and SSL_set_cert_cb() sets the cert_cb callback, arg value is pointer which is passed to the application callback.

- -

When cert_cb is NULL, no callback function is used.

- -

cert_cb is the application defined callback. It is called before a certificate will be used by a client or server. The callback can then inspect the passed ssl structure and set or clear any appropriate certificates. If the callback is successful it MUST return 1 even if no certificates have been set. A zero is returned on error which will abort the handshake with a fatal internal error alert. A negative return value will suspend the handshake and the handshake function will return immediately. SSL_get_error(3) will return SSL_ERROR_WANT_X509_LOOKUP to indicate, that the handshake was suspended. The next call to the handshake function will again lead to the call of cert_cb. It is the job of the cert_cb to store information about the state of the last call, if required to continue.

- -

NOTES

- -

An application will typically call SSL_use_certificate() and SSL_use_PrivateKey() to set the end entity certificate and private key. It can add intermediate and optionally the root CA certificates using SSL_add1_chain_cert().

- -

It might also call SSL_certs_clear() to delete any certificates associated with the SSL object.

- -

The certificate callback functionality supersedes the (largely broken) functionality provided by the old client certificate callback interface. It is always called even is a certificate is already set so the callback can modify or delete the existing certificate.

- -

A more advanced callback might examine the handshake parameters and set whatever chain is appropriate. For example a legacy client supporting only TLSv1.0 might receive a certificate chain signed using SHA1 whereas a TLSv1.2 or later client which advertises support for SHA256 could receive a chain using SHA256.

- -

Normal server sanity checks are performed on any certificates set by the callback. So if an EC chain is set for a curve the client does not support it will not be used.

- -

RETURN VALUES

- -

SSL_CTX_set_cert_cb() and SSL_set_cert_cb() do not return values.

- -

SEE ALSO

- -

ssl(7), SSL_use_certificate(3), SSL_add1_chain_cert(3), SSL_get_client_CA_list(3), SSL_clear(3), SSL_free(3)

- -

COPYRIGHT

- -

Copyright 2014-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_store.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_store.html deleted file mode 100644 index 90bae68b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_store.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -SSL_CTX_set_cert_store - - - - - - - - - - -

NAME

- -

SSL_CTX_set_cert_store, SSL_CTX_set1_cert_store, SSL_CTX_get_cert_store - manipulate X509 certificate verification storage

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_cert_store(SSL_CTX *ctx, X509_STORE *store);
-void SSL_CTX_set1_cert_store(SSL_CTX *ctx, X509_STORE *store);
-X509_STORE *SSL_CTX_get_cert_store(const SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_set_cert_store() sets/replaces the certificate verification storage of ctx to/with store. If another X509_STORE object is currently set in ctx, it will be X509_STORE_free()ed. SSL_CTX_set_cert_store() will take ownership of the store, i.e., the call X509_STORE_free(store) is no longer needed.

- -

SSL_CTX_set1_cert_store() sets/replaces the certificate verification storage of ctx to/with store. The store's reference count is incremented. If another X509_STORE object is currently set in ctx, it will be X509_STORE_free()ed.

- -

SSL_CTX_get_cert_store() returns a pointer to the current certificate verification storage.

- -

NOTES

- -

In order to verify the certificates presented by the peer, trusted CA certificates must be accessed. These CA certificates are made available via lookup methods, handled inside the X509_STORE. From the X509_STORE the X509_STORE_CTX used when verifying certificates is created.

- -

Typically the trusted certificate store is handled indirectly via using SSL_CTX_load_verify_locations(3). Using the SSL_CTX_set_cert_store() and SSL_CTX_get_cert_store() functions it is possible to manipulate the X509_STORE object beyond the SSL_CTX_load_verify_locations(3) call.

- -

Currently no detailed documentation on how to use the X509_STORE object is available. Not all members of the X509_STORE are used when the verification takes place. So will e.g. the verify_callback() be overridden with the verify_callback() set via the SSL_CTX_set_verify(3) family of functions. This document must therefore be updated when documentation about the X509_STORE object and its handling becomes available.

- -

SSL_CTX_set_cert_store() does not increment the store's reference count, so it should not be used to assign an X509_STORE that is owned by another SSL_CTX.

- -

To share X509_STOREs between two SSL_CTXs, use SSL_CTX_get_cert_store() to get the X509_STORE from the first SSL_CTX, and then use SSL_CTX_set1_cert_store() to assign to the second SSL_CTX and increment the reference count of the X509_STORE.

- -

RESTRICTIONS

- -

The X509_STORE structure used by an SSL_CTX is used for verifying peer certificates and building certificate chains, it is also shared by every child SSL structure. Applications wanting finer control can use functions such as SSL_CTX_set1_verify_cert_store() instead.

- -

RETURN VALUES

- -

SSL_CTX_set_cert_store() does not return diagnostic output.

- -

SSL_CTX_set1_cert_store() does not return diagnostic output.

- -

SSL_CTX_get_cert_store() returns the current setting.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_load_verify_locations(3), SSL_CTX_set_verify(3)

- -

COPYRIGHT

- -

Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_verify_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_verify_callback.html deleted file mode 100644 index b0ad982e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cert_verify_callback.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -SSL_CTX_set_cert_verify_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_cert_verify_callback - set peer certificate verification procedure

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_cert_verify_callback(SSL_CTX *ctx,
-                                      int (*callback)(X509_STORE_CTX *, void *),
-                                      void *arg);
- -

DESCRIPTION

- -

SSL_CTX_set_cert_verify_callback() sets the verification callback function for ctx. SSL objects that are created from ctx inherit the setting valid at the time when SSL_new(3) is called.

- -

NOTES

- -

When a peer certificate has been received during a SSL/TLS handshake, a verification function is called regardless of the verification mode. If the application does not explicitly specify a verification callback function, the built-in verification function is used. If a verification callback callback is specified via SSL_CTX_set_cert_verify_callback(), the supplied callback function is called instead with the arguments callback(X509_STORE_CTX *x509_store_ctx, void *arg). The argument arg is specified by the application when setting callback. By setting callback to NULL, the default behaviour is restored.

- -

callback should return 1 to indicate verification success and 0 to indicate verification failure. In server mode, a return value of 0 leads to handshake failure. In client mode, the behaviour is as follows. All values, including 0, are ignored if the verification mode is SSL_VERIFY_NONE. Otherwise, when the return value is less than or equal to 0, the handshake will fail.

- -

In client mode callback may also call the SSL_set_retry_verify(3) function on the SSL object set in the x509_store_ctx ex data (see SSL_get_ex_data_X509_STORE_CTX_idx(3)) and return 1. This would be typically done in case the certificate verification was not yet able to succeed. This makes the handshake suspend and return control to the calling application with SSL_ERROR_WANT_RETRY_VERIFY. The app can for instance fetch further certificates or cert status information needed for the verification. Calling SSL_connect(3) again resumes the connection attempt by retrying the server certificate verification step. This process may even be repeated if need be.

- -

In any case a viable verification result value must be reflected in the error member of x509_store_ctx, which can be done using X509_STORE_CTX_set_error(3). This is particularly important in case the callback allows the connection to continue (by returning 1). Note that the verification status in the store context is a possibly durable indication of the chain's validity! This gets recorded in the SSL session (and thus also in session tickets) and the validity of the originally presented chain is then visible on resumption, even though no chain is presented int that case. Moreover, the calling application will be informed about the detailed result of the verification procedure and may elect to base further decisions on it.

- -

Within x509_store_ctx, callback has access to the verify_callback function set using SSL_CTX_set_verify(3).

- -

RETURN VALUES

- -

SSL_CTX_set_cert_verify_callback() does not return a value.

- -

WARNINGS

- -

Do not mix the verification callback described in this function with the verify_callback function called during the verification process. The latter is set using the SSL_CTX_set_verify(3) family of functions.

- -

Providing a complete verification procedure including certificate purpose settings etc is a complex task. The built-in procedure is quite powerful and in most cases it should be sufficient to modify its behaviour using the verify_callback function.

- -

BUGS

- -

SSL_CTX_set_cert_verify_callback() does not provide diagnostic information.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_verify(3), X509_STORE_CTX_set_error(3), SSL_get_verify_result(3), SSL_set_retry_verify(3), SSL_CTX_load_verify_locations(3)

- -

COPYRIGHT

- -

Copyright 2001-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cipher_list.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cipher_list.html deleted file mode 100644 index 6f9e219b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_cipher_list.html +++ /dev/null @@ -1,129 +0,0 @@ - - - - -SSL_CTX_set_cipher_list - - - - - - - - - - -

NAME

- -

SSL_CTX_set_cipher_list, SSL_set_cipher_list, SSL_CTX_set_ciphersuites, SSL_set_ciphersuites, OSSL_default_cipher_list, OSSL_default_ciphersuites - choose list of available SSL_CIPHERs

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set_cipher_list(SSL_CTX *ctx, const char *str);
-int SSL_set_cipher_list(SSL *ssl, const char *str);
-
-int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str);
-int SSL_set_ciphersuites(SSL *s, const char *str);
-
-const char *OSSL_default_cipher_list(void);
-const char *OSSL_default_ciphersuites(void);
- -

DESCRIPTION

- -

SSL_CTX_set_cipher_list() sets the list of available ciphers (TLSv1.2 and below) for ctx using the control string str. The format of the string is described in openssl-ciphers(1). The list of ciphers is inherited by all ssl objects created from ctx. This function does not impact TLSv1.3 ciphersuites. Use SSL_CTX_set_ciphersuites() to configure those.

- -

SSL_set_cipher_list() sets the list of ciphers (TLSv1.2 and below) only for ssl.

- -

SSL_CTX_set_ciphersuites() is used to configure the available TLSv1.3 ciphersuites for ctx. This is a simple colon (":") separated list of TLSv1.3 ciphersuite names in order of preference. Valid TLSv1.3 ciphersuite names are:

- -
- -
TLS_AES_128_GCM_SHA256
-
- -
-
TLS_AES_256_GCM_SHA384
-
- -
-
TLS_CHACHA20_POLY1305_SHA256
-
- -
-
TLS_AES_128_CCM_SHA256
-
- -
-
TLS_AES_128_CCM_8_SHA256
-
- -
-
TLS_SHA384_SHA384 - integrity-only
-
- -
-
TLS_SHA256_SHA256 - integrity-only
-
- -
-
- -

An empty list is permissible. The default value for this setting is:

- -

"TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256"

- -

SSL_set_ciphersuites() is the same as SSL_CTX_set_ciphersuites() except it configures the ciphersuites for ssl.

- -

OSSL_default_cipher_list() returns the default cipher string for TLSv1.2 (and earlier) ciphers. OSSL_default_ciphersuites() returns the default cipher string for TLSv1.3 ciphersuites.

- -

NOTES

- -

The control string str for SSL_CTX_set_cipher_list(), SSL_set_cipher_list(), SSL_CTX_set_ciphersuites() and SSL_set_ciphersuites() should be universally usable and not depend on details of the library configuration (ciphers compiled in). Thus no syntax checking takes place. Items that are not recognized, because the corresponding ciphers are not compiled in or because they are mistyped, are simply ignored. Failure is only flagged if no ciphers could be collected at all.

- -

It should be noted, that inclusion of a cipher to be used into the list is a necessary condition. On the client side, the inclusion into the list is also sufficient unless the security level excludes it. On the server side, additional restrictions apply. All ciphers have additional requirements. ADH ciphers don't need a certificate, but DH-parameters must have been set. All other ciphers need a corresponding certificate and key.

- -

An RSA cipher can only be chosen, when an RSA certificate is available. RSA ciphers using DHE need a certificate and key and additional DH-parameters (see SSL_CTX_set_tmp_dh_callback(3)).

- -

A DSA cipher can only be chosen, when a DSA certificate is available. DSA ciphers always use DH key exchange and therefore need DH-parameters (see SSL_CTX_set_tmp_dh_callback(3)).

- -

When these conditions are not met for any cipher in the list (e.g. a client only supports export RSA ciphers with an asymmetric key length of 512 bits and the server is not configured to use temporary RSA keys), the "no shared cipher" (SSL_R_NO_SHARED_CIPHER) error is generated and the handshake will fail.

- -

OSSL_default_cipher_list() and OSSL_default_ciphersuites() replace SSL_DEFAULT_CIPHER_LIST and TLS_DEFAULT_CIPHERSUITES, respectively. The cipher list defines are deprecated as of 3.0.

- -

RETURN VALUES

- -

SSL_CTX_set_cipher_list() and SSL_set_cipher_list() return 1 if any cipher could be selected and 0 on complete failure.

- -

SSL_CTX_set_ciphersuites() and SSL_set_ciphersuites() return 1 if the requested ciphersuite list was configured, and 0 otherwise.

- -

SEE ALSO

- -

ssl(7), SSL_get_ciphers(3), SSL_CTX_use_certificate(3), SSL_CTX_set_tmp_dh_callback(3), openssl-ciphers(1)

- -

HISTORY

- -

OSSL_default_cipher_list() and OSSL_default_ciphersites() are new in 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_cert_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_cert_cb.html deleted file mode 100644 index 60a0cfc0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_cert_cb.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -SSL_CTX_set_client_cert_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_client_cert_cb, SSL_CTX_get_client_cert_cb - handle client certificate callback function

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_client_cert_cb(SSL_CTX *ctx,
-                                int (*client_cert_cb)(SSL *ssl, X509 **x509,
-                                                      EVP_PKEY **pkey));
-int (*SSL_CTX_get_client_cert_cb(SSL_CTX *ctx))(SSL *ssl, X509 **x509,
-                                                EVP_PKEY **pkey);
- -

DESCRIPTION

- -

SSL_CTX_set_client_cert_cb() sets the client_cert_cb callback, that is called when a client certificate is requested by a server and no certificate was yet set for the SSL object.

- -

When client_cert_cb is NULL, no callback function is used.

- -

SSL_CTX_get_client_cert_cb() returns a pointer to the currently set callback function.

- -

client_cert_cb is the application defined callback. If it wants to set a certificate, a certificate/private key combination must be set using the x509 and pkey arguments and "1" must be returned. The certificate will be installed into ssl, see the NOTES and BUGS sections. If no certificate should be set, "0" has to be returned and no certificate will be sent. A negative return value will suspend the handshake and the handshake function will return immediately. SSL_get_error(3) will return SSL_ERROR_WANT_X509_LOOKUP to indicate, that the handshake was suspended. The next call to the handshake function will again lead to the call of client_cert_cb. It is the job of the client_cert_cb to store information about the state of the last call, if required to continue.

- -

NOTES

- -

During a handshake (or renegotiation) a server may request a certificate from the client. A client certificate must only be sent, when the server did send the request.

- -

When a certificate was set using the SSL_CTX_use_certificate(3) family of functions, it will be sent to the server. The TLS standard requires that only a certificate is sent, if it matches the list of acceptable CAs sent by the server. This constraint is violated by the default behavior of the OpenSSL library. Using the callback function it is possible to implement a proper selection routine or to allow a user interaction to choose the certificate to be sent.

- -

If a callback function is defined and no certificate was yet defined for the SSL object, the callback function will be called. If the callback function returns a certificate, the OpenSSL library will try to load the private key and certificate data into the SSL object using the SSL_use_certificate() and SSL_use_private_key() functions. Thus it will permanently install the certificate and key for this SSL object. It will not be reset by calling SSL_clear(3). If the callback returns no certificate, the OpenSSL library will not send a certificate.

- -

RETURN VALUES

- -

SSL_CTX_get_client_cert_cb() returns function pointer of client_cert_cb or NULL if the callback is not set.

- -

BUGS

- -

The client_cert_cb cannot return a complete certificate chain, it can only return one client certificate. If the chain only has a length of 2, the root CA certificate may be omitted according to the TLS standard and thus a standard conforming answer can be sent to the server. For a longer chain, the client must send the complete chain (with the option to leave out the root CA certificate). This can only be accomplished by either adding the intermediate CA certificates into the trusted certificate store for the SSL_CTX object (resulting in having to add CA certificates that otherwise maybe would not be trusted), or by adding the chain certificates using the SSL_CTX_add_extra_chain_cert(3) function, which is only available for the SSL_CTX object as a whole and that therefore probably can only apply for one client certificate, making the concept of the callback function (to allow the choice from several certificates) questionable.

- -

Once the SSL object has been used in conjunction with the callback function, the certificate will be set for the SSL object and will not be cleared even when SSL_clear(3) is being called. It is therefore mandatory to destroy the SSL object using SSL_free(3) and create a new one to return to the previous state.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_use_certificate(3), SSL_CTX_add_extra_chain_cert(3), SSL_get_client_CA_list(3), SSL_clear(3), SSL_free(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_hello_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_hello_cb.html deleted file mode 100644 index 0fe1360b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_client_hello_cb.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -SSL_CTX_set_client_hello_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_client_hello_cb, SSL_client_hello_cb_fn, SSL_client_hello_isv2, SSL_client_hello_get0_legacy_version, SSL_client_hello_get0_random, SSL_client_hello_get0_session_id, SSL_client_hello_get0_ciphers, SSL_client_hello_get0_compression_methods, SSL_client_hello_get1_extensions_present, SSL_client_hello_get_extension_order, SSL_client_hello_get0_ext - callback functions for early server-side ClientHello processing

- -

SYNOPSIS

- -
typedef int (*SSL_client_hello_cb_fn)(SSL *s, int *al, void *arg);
-void SSL_CTX_set_client_hello_cb(SSL_CTX *c, SSL_client_hello_cb_fn *f,
-                                 void *arg);
-int SSL_client_hello_isv2(SSL *s);
-unsigned int SSL_client_hello_get0_legacy_version(SSL *s);
-size_t SSL_client_hello_get0_random(SSL *s, const unsigned char **out);
-size_t SSL_client_hello_get0_session_id(SSL *s, const unsigned char **out);
-size_t SSL_client_hello_get0_ciphers(SSL *s, const unsigned char **out);
-size_t SSL_client_hello_get0_compression_methods(SSL *s,
-                                                 const unsigned char **out);
-int SSL_client_hello_get1_extensions_present(SSL *s, int **out,
-                                             size_t *outlen);
-int SSL_client_hello_get_extension_order(SSL *s, uint16_t *exts,
-                                         size_t *num_exts);
-int SSL_client_hello_get0_ext(SSL *s, unsigned int type, const unsigned char **out,
-                              size_t *outlen);
- -

DESCRIPTION

- -

SSL_CTX_set_client_hello_cb() sets the callback function, which is automatically called during the early stages of ClientHello processing on the server. The argument supplied when setting the callback is passed back to the callback at run time. A callback that returns failure (0) will cause the connection to terminate, and callbacks returning failure should indicate what alert value is to be sent in the al parameter. A callback may also return a negative value to suspend the handshake, and the handshake function will return immediately. SSL_get_error(3) will return SSL_ERROR_WANT_CLIENT_HELLO_CB to indicate that the handshake was suspended. It is the job of the ClientHello callback to store information about the state of the last call if needed to continue. On the next call into the handshake function, the ClientHello callback will be called again, and, if it returns success, normal handshake processing will continue from that point.

- -

SSL_client_hello_isv2() indicates whether the ClientHello was carried in a SSLv2 record and is in the SSLv2 format. The SSLv2 format has substantial differences from the normal SSLv3 format, including using three bytes per cipher suite, and not allowing extensions. Additionally, the SSLv2 format 'challenge' field is exposed via SSL_client_hello_get0_random(), padded to SSL3_RANDOM_SIZE bytes with zeros if needed. For SSLv2 format ClientHellos, SSL_client_hello_get0_compression_methods() returns a dummy list that only includes the null compression method, since the SSLv2 format does not include a mechanism by which to negotiate compression.

- -

SSL_client_hello_get0_random(), SSL_client_hello_get0_session_id(), SSL_client_hello_get0_ciphers(), and SSL_client_hello_get0_compression_methods() provide access to the corresponding ClientHello fields, returning the field length and optionally setting an out pointer to the octets of that field.

- -

Similarly, SSL_client_hello_get0_ext() provides access to individual extensions from the ClientHello on a per-extension basis. For the provided wire protocol extension type value, the extension value and length are returned in the output parameters (if present).

- -

SSL_client_hello_get1_extensions_present() can be used prior to SSL_client_hello_get0_ext(), to determine which extensions are present in the ClientHello before querying for them. The out and outlen parameters are both required, and on success the caller must release the storage allocated for *out using OPENSSL_free(). The contents of *out is an array of integers holding the numerical value of the TLS extension types in the order they appear in the ClientHello. *outlen contains the number of elements in the array. In situations when the ClientHello has no extensions, the function will return success with *out set to NULL and *outlen set to 0.

- -

SSL_client_hello_get_extension_order() is similar to SSL_client_hello_get1_extensions_present(), without internal memory allocation. When called with exts set to NULL, returns the number of extensions (e.g., to allocate storage for a subsequent call). Otherwise, *exts is populated with the ExtensionType values in the order that the corresponding extensions appeared in the ClientHello. *num_exts is an input/output parameter, used as input to supply the size of storage allocated by the caller, and as output to indicate how many ExtensionType values were written. If the input *num_exts is smaller then the number of extensions in question, that is treated as an error. A subsequent call with exts set to NULL can retrieve the size of storage needed. A ClientHello that contained no extensions is treated as success, with *num_exts set to 0.

- -

NOTES

- -

The ClientHello callback provides a vast window of possibilities for application code to affect the TLS handshake. A primary use of the callback is to allow the server to examine the server name indication extension provided by the client in order to select an appropriate certificate to present, and make other configuration adjustments relevant to that server name and its configuration. Such configuration changes can include swapping out the associated SSL_CTX pointer, modifying the server's list of permitted TLS versions, changing the server's cipher list in response to the client's cipher list, etc.

- -

It is also recommended that applications utilize a ClientHello callback and not use a servername callback, in order to avoid unexpected behavior that occurs due to the relative order of processing between things like session resumption and the historical servername callback.

- -

The SSL_client_hello_* family of functions may only be called from code executing within a ClientHello callback.

- -

RETURN VALUES

- -

The application's supplied ClientHello callback returns SSL_CLIENT_HELLO_SUCCESS on success, SSL_CLIENT_HELLO_ERROR on failure, and SSL_CLIENT_HELLO_RETRY to suspend processing.

- -

SSL_client_hello_isv2() returns 1 for SSLv2-format ClientHellos and 0 otherwise.

- -

SSL_client_hello_get0_random(), SSL_client_hello_get0_session_id(), SSL_client_hello_get0_ciphers(), and SSL_client_hello_get0_compression_methods() return the length of the corresponding ClientHello fields. If zero is returned, the output pointer should not be assumed to be valid.

- -

SSL_client_hello_get0_ext() returns 1 if the extension of type 'type' is present, and 0 otherwise.

- -

SSL_client_hello_get1_extensions_present() returns 1 on success and 0 on failure.

- -

SSL_client_hello_get_extension_order() returns 1 on success and 0 on failure.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_tlsext_servername_callback(3), SSL_bytes_to_cipher_list(3)

- -

HISTORY

- -

The SSL ClientHello callback, SSL_client_hello_isv2(), SSL_client_hello_get0_random(), SSL_client_hello_get0_session_id(), SSL_client_hello_get0_ciphers(), SSL_client_hello_get0_compression_methods(), SSL_client_hello_get0_ext(), and SSL_client_hello_get1_extensions_present() were added in OpenSSL 1.1.1. SSL_client_hello_get_extension_order() was added in OpenSSL 3.2.0.

- -

COPYRIGHT

- -

Copyright 2017-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ct_validation_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ct_validation_callback.html deleted file mode 100644 index 80ff7c0e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ct_validation_callback.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -SSL_CTX_set_ct_validation_callback - - - - - - - - - - -

NAME

- -

ssl_ct_validation_cb, SSL_enable_ct, SSL_CTX_enable_ct, SSL_disable_ct, SSL_CTX_disable_ct, SSL_set_ct_validation_callback, SSL_CTX_set_ct_validation_callback, SSL_ct_is_enabled, SSL_CTX_ct_is_enabled - control Certificate Transparency policy

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*ssl_ct_validation_cb)(const CT_POLICY_EVAL_CTX *ctx,
-                                   const STACK_OF(SCT) *scts, void *arg);
-
-int SSL_enable_ct(SSL *s, int validation_mode);
-int SSL_CTX_enable_ct(SSL_CTX *ctx, int validation_mode);
-int SSL_set_ct_validation_callback(SSL *s, ssl_ct_validation_cb callback,
-                                   void *arg);
-int SSL_CTX_set_ct_validation_callback(SSL_CTX *ctx,
-                                       ssl_ct_validation_cb callback,
-                                       void *arg);
-void SSL_disable_ct(SSL *s);
-void SSL_CTX_disable_ct(SSL_CTX *ctx);
-int SSL_ct_is_enabled(const SSL *s);
-int SSL_CTX_ct_is_enabled(const SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_enable_ct() and SSL_CTX_enable_ct() enable the processing of signed certificate timestamps (SCTs) either for a given SSL connection or for all connections that share the given SSL context, respectively. This is accomplished by setting a built-in CT validation callback. The behaviour of the callback is determined by the validation_mode argument, which can be either of SSL_CT_VALIDATION_PERMISSIVE or SSL_CT_VALIDATION_STRICT as described below.

- -

If validation_mode is equal to SSL_CT_VALIDATION_STRICT, then in a full TLS handshake with the verification mode set to SSL_VERIFY_PEER, if the peer presents no valid SCTs the handshake will be aborted. If the verification mode is SSL_VERIFY_NONE, the handshake will continue despite lack of valid SCTs. However, in that case if the verification status before the built-in callback was X509_V_OK it will be set to X509_V_ERR_NO_VALID_SCTS after the callback. Applications can call SSL_get_verify_result(3) to check the status at handshake completion, even after session resumption since the verification status is part of the saved session state. See SSL_set_verify(3), <SSL_get_verify_result(3)>, SSL_session_reused(3).

- -

If validation_mode is equal to SSL_CT_VALIDATION_PERMISSIVE, then the handshake continues, and the verification status is not modified, regardless of the validation status of any SCTs. The application can still inspect the validation status of the SCTs at handshake completion. Note that with session resumption there will not be any SCTs presented during the handshake. Therefore, in applications that delay SCT policy enforcement until after handshake completion, such delayed SCT checks should only be performed when the session is not resumed.

- -

SSL_set_ct_validation_callback() and SSL_CTX_set_ct_validation_callback() register a custom callback that may implement a different policy than either of the above. This callback can examine the peer's SCTs and determine whether they are sufficient to allow the connection to continue. The TLS handshake is aborted if the verification mode is not SSL_VERIFY_NONE and the callback returns a non-positive result.

- -

An arbitrary callback data argument, arg, can be passed in when setting the callback. This will be passed to the callback whenever it is invoked. Ownership of this context remains with the caller.

- -

If no callback is set, SCTs will not be requested and Certificate Transparency validation will not occur.

- -

No callback will be invoked when the peer presents no certificate, e.g. by employing an anonymous (aNULL) cipher suite. In that case the handshake continues as it would had no callback been requested. Callbacks are also not invoked when the peer certificate chain is invalid or validated via DANE-TA(2) or DANE-EE(3) TLSA records which use a private X.509 PKI, or no X.509 PKI at all, respectively. Clients that require SCTs are expected to not have enabled any aNULL ciphers nor to have specified server verification via DANE-TA(2) or DANE-EE(3) TLSA records.

- -

SSL_disable_ct() and SSL_CTX_disable_ct() turn off CT processing, whether enabled via the built-in or the custom callbacks, by setting a NULL callback. These may be implemented as macros.

- -

SSL_ct_is_enabled() and SSL_CTX_ct_is_enabled() return 1 if CT processing is enabled via either SSL_enable_ct() or a non-null custom callback, and 0 otherwise.

- -

NOTES

- -

When SCT processing is enabled, OCSP stapling will be enabled. This is because one possible source of SCTs is the OCSP response from a server.

- -

The time returned by SSL_SESSION_get_time_ex() will be used to evaluate whether any presented SCTs have timestamps that are in the future (and therefore invalid).

- -

RESTRICTIONS

- -

Certificate Transparency validation cannot be enabled and so a callback cannot be set if a custom client extension handler has been registered to handle SCT extensions (TLSEXT_TYPE_signed_certificate_timestamp).

- -

RETURN VALUES

- -

SSL_enable_ct(), SSL_CTX_enable_ct(), SSL_CTX_set_ct_validation_callback() and SSL_set_ct_validation_callback() return 1 if the callback is successfully set. They return 0 if an error occurs, e.g. a custom client extension handler has been setup to handle SCTs.

- -

SSL_disable_ct() and SSL_CTX_disable_ct() do not return a result.

- -

SSL_CTX_ct_is_enabled() and SSL_ct_is_enabled() return a 1 if a non-null CT validation callback is set, or 0 if no callback (or equivalently a NULL callback) is set.

- -

SEE ALSO

- -

ssl(7), <SSL_get_verify_result(3)>, SSL_session_reused(3), SSL_set_verify(3), SSL_CTX_set_verify(3), SSL_SESSION_get_time(3)

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ctlog_list_file.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ctlog_list_file.html deleted file mode 100644 index 39733c99..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ctlog_list_file.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -SSL_CTX_set_ctlog_list_file - - - - - - - - - - -

NAME

- -

SSL_CTX_set_default_ctlog_list_file, SSL_CTX_set_ctlog_list_file - load a Certificate Transparency log list from a file

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set_default_ctlog_list_file(SSL_CTX *ctx);
-int SSL_CTX_set_ctlog_list_file(SSL_CTX *ctx, const char *path);
- -

DESCRIPTION

- -

SSL_CTX_set_default_ctlog_list_file() loads a list of Certificate Transparency (CT) logs from the default file location, "ct_log_list.cnf", found in the directory where OpenSSL is installed.

- -

SSL_CTX_set_ctlog_list_file() loads a list of CT logs from a specific path. See CTLOG_STORE_new(3) for the file format.

- -

NOTES

- -

These functions will not clear the existing CT log list - it will be appended to. To replace the existing list, use SSL_CTX_set0_ctlog_store(3) first.

- -

If an error occurs whilst parsing a particular log entry in the file, that log entry will be skipped.

- -

RETURN VALUES

- -

SSL_CTX_set_default_ctlog_list_file() and SSL_CTX_set_ctlog_list_file() return 1 if the log list is successfully loaded, and 0 if an error occurs. In the case of an error, the log list may have been partially loaded.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_ct_validation_callback(3), CTLOG_STORE_new(3)

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_default_passwd_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_default_passwd_cb.html deleted file mode 100644 index 378bd77f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_default_passwd_cb.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -SSL_CTX_set_default_passwd_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_default_passwd_cb, SSL_CTX_set_default_passwd_cb_userdata, SSL_CTX_get_default_passwd_cb, SSL_CTX_get_default_passwd_cb_userdata, SSL_set_default_passwd_cb, SSL_set_default_passwd_cb_userdata, SSL_get_default_passwd_cb, SSL_get_default_passwd_cb_userdata - set or get passwd callback for encrypted PEM file handling

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_default_passwd_cb(SSL_CTX *ctx, pem_password_cb *cb);
-void SSL_CTX_set_default_passwd_cb_userdata(SSL_CTX *ctx, void *u);
-pem_password_cb *SSL_CTX_get_default_passwd_cb(SSL_CTX *ctx);
-void *SSL_CTX_get_default_passwd_cb_userdata(SSL_CTX *ctx);
-
-void SSL_set_default_passwd_cb(SSL *s, pem_password_cb *cb);
-void SSL_set_default_passwd_cb_userdata(SSL *s, void *u);
-pem_password_cb *SSL_get_default_passwd_cb(SSL *s);
-void *SSL_get_default_passwd_cb_userdata(SSL *s);
- -

DESCRIPTION

- -

SSL_CTX_set_default_passwd_cb() sets the default password callback called when loading/storing a PEM certificate with encryption.

- -

SSL_CTX_set_default_passwd_cb_userdata() sets a pointer to userdata, u, which will be provided to the password callback on invocation.

- -

SSL_CTX_get_default_passwd_cb() returns a function pointer to the password callback currently set in ctx. If no callback was explicitly set, the NULL pointer is returned.

- -

SSL_CTX_get_default_passwd_cb_userdata() returns a pointer to the userdata currently set in ctx. If no userdata was explicitly set, the NULL pointer is returned.

- -

SSL_set_default_passwd_cb(), SSL_set_default_passwd_cb_userdata(), SSL_get_default_passwd_cb() and SSL_get_default_passwd_cb_userdata() perform the same function as their SSL_CTX counterparts, but using an SSL object.

- -

The password callback, which must be provided by the application, hands back the password to be used during decryption. On invocation a pointer to userdata is provided. The function must store the password into the provided buffer buf which is of size size. The actual length of the password must be returned to the calling function. rwflag indicates whether the callback is used for reading/decryption (rwflag=0) or writing/encryption (rwflag=1). For more details, see pem_password_cb(3).

- -

NOTES

- -

When loading or storing private keys, a password might be supplied to protect the private key. The way this password can be supplied may depend on the application. If only one private key is handled, it can be practical to have the callback handle the password dialog interactively. If several keys have to be handled, it can be practical to ask for the password once, then keep it in memory and use it several times. In the last case, the password could be stored into the userdata storage and the callback only returns the password already stored.

- -

When asking for the password interactively, the callback can use rwflag to check, whether an item shall be encrypted (rwflag=1). In this case the password dialog may ask for the same password twice for comparison in order to catch typos, that would make decryption impossible.

- -

Other items in PEM formatting (certificates) can also be encrypted, it is however not usual, as certificate information is considered public.

- -

RETURN VALUES

- -

These functions do not provide diagnostic information.

- -

EXAMPLES

- -

The following example returns the password provided as userdata to the calling function. The password is considered to be a '\0' terminated string. If the password does not fit into the buffer, the password is truncated.

- -
int my_cb(char *buf, int size, int rwflag, void *u)
-{
-    strncpy(buf, (char *)u, size);
-    buf[size - 1] = '\0';
-    return strlen(buf);
-}
- -

SEE ALSO

- -

ssl(7), SSL_CTX_use_certificate(3)

- -

HISTORY

- -

SSL_CTX_get_default_passwd_cb(), SSL_CTX_get_default_passwd_cb_userdata(), SSL_set_default_passwd_cb() and SSL_set_default_passwd_cb_userdata() were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2019 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_generate_session_id.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_generate_session_id.html deleted file mode 100644 index 65cfd25a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_generate_session_id.html +++ /dev/null @@ -1,116 +0,0 @@ - - - - -SSL_CTX_set_generate_session_id - - - - - - - - - - -

NAME

- -

SSL_CTX_set_generate_session_id, SSL_set_generate_session_id, SSL_has_matching_session_id, GEN_SESSION_CB - manipulate generation of SSL session IDs (server only)

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*GEN_SESSION_CB)(SSL *ssl, unsigned char *id,
-                              unsigned int *id_len);
-
-int SSL_CTX_set_generate_session_id(SSL_CTX *ctx, GEN_SESSION_CB cb);
-int SSL_set_generate_session_id(SSL *ssl, GEN_SESSION_CB, cb);
-int SSL_has_matching_session_id(const SSL *ssl, const unsigned char *id,
-                                unsigned int id_len);
- -

DESCRIPTION

- -

SSL_CTX_set_generate_session_id() sets the callback function for generating new session ids for SSL/TLS sessions for ctx to be cb.

- -

SSL_set_generate_session_id() sets the callback function for generating new session ids for SSL/TLS sessions for ssl to be cb.

- -

SSL_has_matching_session_id() checks, whether a session with id id (of length id_len) is already contained in the internal session cache of the parent context of ssl.

- -

NOTES

- -

When a new session is established between client and server, the server generates a session id. The session id is an arbitrary sequence of bytes. The length of the session id is between 1 and 32 bytes. The session id is not security critical but must be unique for the server. Additionally, the session id is transmitted in the clear when reusing the session so it must not contain sensitive information.

- -

Without a callback being set, an OpenSSL server will generate a unique session id from pseudo random numbers of the maximum possible length. Using the callback function, the session id can be changed to contain additional information like e.g. a host id in order to improve load balancing or external caching techniques.

- -

The callback function receives a pointer to the memory location to put id into and a pointer to the maximum allowed length id_len. The buffer at location id is only guaranteed to have the size id_len. The callback is only allowed to generate a shorter id and reduce id_len; the callback must never increase id_len or write to the location id exceeding the given limit.

- -

The location id is filled with 0x00 before the callback is called, so the callback may only fill part of the possible length and leave id_len untouched while maintaining reproducibility.

- -

Since the sessions must be distinguished, session ids must be unique. Without the callback a random number is used, so that the probability of generating the same session id is extremely small (2^256 for SSLv3/TLSv1). In order to assure the uniqueness of the generated session id, the callback must call SSL_has_matching_session_id() and generate another id if a conflict occurs. If an id conflict is not resolved, the handshake will fail. If the application codes e.g. a unique host id, a unique process number, and a unique sequence number into the session id, uniqueness could easily be achieved without randomness added (it should however be taken care that no confidential information is leaked this way). If the application can not guarantee uniqueness, it is recommended to use the maximum id_len and fill in the bytes not used to code special information with random data to avoid collisions.

- -

SSL_has_matching_session_id() will only query the internal session cache, not the external one. Since the session id is generated before the handshake is completed, it is not immediately added to the cache. If another thread is using the same internal session cache, a race condition can occur in that another thread generates the same session id. Collisions can also occur when using an external session cache, since the external cache is not tested with SSL_has_matching_session_id() and the same race condition applies.

- -

The callback must return 0 if it cannot generate a session id for whatever reason and return 1 on success.

- -

RETURN VALUES

- -

SSL_CTX_set_generate_session_id() and SSL_set_generate_session_id() return 1 on success and 0 for failure.

- -

SSL_has_matching_session_id() returns 1 if another session with the same id is already in the cache, or 0 otherwise.

- -

EXAMPLES

- -

The callback function listed will generate a session id with the server id given, and will fill the rest with pseudo random bytes:

- -
const char session_id_prefix = "www-18";
-
-#define MAX_SESSION_ID_ATTEMPTS 10
-static int generate_session_id(SSL *ssl, unsigned char *id,
-                               unsigned int *id_len)
-{
-    unsigned int count = 0;
-
-    do {
-        RAND_pseudo_bytes(id, *id_len);
-        /*
-         * Prefix the session_id with the required prefix. NB: If our
-         * prefix is too long, clip it - but there will be worse effects
-         * anyway, e.g. the server could only possibly create 1 session
-         * ID (i.e. the prefix!) so all future session negotiations will
-         * fail due to conflicts.
-         */
-        memcpy(id, session_id_prefix, strlen(session_id_prefix) < *id_len ?
-                                      strlen(session_id_prefix) : *id_len);
-    } while (SSL_has_matching_session_id(ssl, id, *id_len)
-              && ++count < MAX_SESSION_ID_ATTEMPTS);
-    if (count >= MAX_SESSION_ID_ATTEMPTS)
-        return 0;
-    return 1;
-}
- -

SEE ALSO

- -

ssl(7), SSL_get_version(3)

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_info_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_info_callback.html deleted file mode 100644 index c4c66297..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_info_callback.html +++ /dev/null @@ -1,190 +0,0 @@ - - - - -SSL_CTX_set_info_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_info_callback, SSL_CTX_get_info_callback, SSL_set_info_callback, SSL_get_info_callback - handle information callback for SSL connections

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_info_callback(SSL_CTX *ctx,
-                               void (*callback) (const SSL *ssl, int type, int val));
-
-void (*SSL_CTX_get_info_callback(SSL_CTX *ctx)) (const SSL *ssl, int type, int val);
-
-void SSL_set_info_callback(SSL *ssl,
-                           void (*callback) (const SSL *ssl, int type, int val));
-
-void (*SSL_get_info_callback(const SSL *ssl)) (const SSL *ssl, int type, int val);
- -

DESCRIPTION

- -

SSL_CTX_set_info_callback() sets the callback function, that can be used to obtain state information for SSL objects created from ctx during connection setup and use. The setting for ctx is overridden from the setting for a specific SSL object, if specified. When callback is NULL, no callback function is used.

- -

SSL_set_info_callback() sets the callback function, that can be used to obtain state information for ssl during connection setup and use. When callback is NULL, the callback setting currently valid for ctx is used.

- -

SSL_CTX_get_info_callback() returns a pointer to the currently set information callback function for ctx.

- -

SSL_get_info_callback() returns a pointer to the currently set information callback function for ssl.

- -

NOTES

- -

When setting up a connection and during use, it is possible to obtain state information from the SSL/TLS engine. When set, an information callback function is called whenever a significant event occurs such as: the state changes, an alert appears, or an error occurs.

- -

The callback function is called as callback(SSL *ssl, int where, int ret). The where argument specifies information about where (in which context) the callback function was called. If ret is 0, an error condition occurred. If an alert is handled, SSL_CB_ALERT is set and ret specifies the alert information.

- -

where is a bit-mask made up of the following bits:

- -
- -
SSL_CB_LOOP
-
- -

Callback has been called to indicate state change or some other significant state machine event. This may mean that the callback gets invoked more than once per state in some situations.

- -
-
SSL_CB_EXIT
-
- -

Callback has been called to indicate exit of a handshake function. This will happen after the end of a handshake, but may happen at other times too such as on error or when IO might otherwise block and nonblocking is being used.

- -
-
SSL_CB_READ
-
- -

Callback has been called during read operation.

- -
-
SSL_CB_WRITE
-
- -

Callback has been called during write operation.

- -
-
SSL_CB_ALERT
-
- -

Callback has been called due to an alert being sent or received.

- -
-
SSL_CB_READ_ALERT (SSL_CB_ALERT|SSL_CB_READ)
-
- -
-
SSL_CB_WRITE_ALERT (SSL_CB_ALERT|SSL_CB_WRITE)
-
- -
-
SSL_CB_ACCEPT_LOOP (SSL_ST_ACCEPT|SSL_CB_LOOP)
-
- -
-
SSL_CB_ACCEPT_EXIT (SSL_ST_ACCEPT|SSL_CB_EXIT)
-
- -
-
SSL_CB_CONNECT_LOOP (SSL_ST_CONNECT|SSL_CB_LOOP)
-
- -
-
SSL_CB_CONNECT_EXIT (SSL_ST_CONNECT|SSL_CB_EXIT)
-
- -
-
SSL_CB_HANDSHAKE_START
-
- -

Callback has been called because a new handshake is started. It also occurs when resuming a handshake following a pause to handle early data.

- -
-
SSL_CB_HANDSHAKE_DONE
-
- -

Callback has been called because a handshake is finished. It also occurs if the handshake is paused to allow the exchange of early data.

- -
-
- -

The current state information can be obtained using the SSL_state_string(3) family of functions.

- -

The ret information can be evaluated using the SSL_alert_type_string(3) family of functions.

- -

RETURN VALUES

- -

SSL_set_info_callback() does not provide diagnostic information.

- -

SSL_get_info_callback() returns the current setting.

- -

EXAMPLES

- -

The following example callback function prints state strings, information about alerts being handled and error messages to the bio_err BIO.

- -
void apps_ssl_info_callback(const SSL *s, int where, int ret)
-{
-    const char *str;
-    int w = where & ~SSL_ST_MASK;
-
-    if (w & SSL_ST_CONNECT)
-        str = "SSL_connect";
-    else if (w & SSL_ST_ACCEPT)
-        str = "SSL_accept";
-    else
-        str = "undefined";
-
-    if (where & SSL_CB_LOOP) {
-        BIO_printf(bio_err, "%s:%s\n", str, SSL_state_string_long(s));
-    } else if (where & SSL_CB_ALERT) {
-        str = (where & SSL_CB_READ) ? "read" : "write";
-        BIO_printf(bio_err, "SSL3 alert %s:%s:%s\n", str,
-                   SSL_alert_type_string_long(ret),
-                   SSL_alert_desc_string_long(ret));
-    } else if (where & SSL_CB_EXIT) {
-        if (ret == 0) {
-            BIO_printf(bio_err, "%s:failed in %s\n",
-                       str, SSL_state_string_long(s));
-        } else if (ret < 0) {
-            BIO_printf(bio_err, "%s:error in %s\n",
-                       str, SSL_state_string_long(s));
-        }
-    }
-}
- -

SEE ALSO

- -

ssl(7), SSL_state_string(3), SSL_alert_type_string(3)

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_keylog_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_keylog_callback.html deleted file mode 100644 index a8c1153a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_keylog_callback.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -SSL_CTX_set_keylog_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_keylog_callback, SSL_CTX_get_keylog_callback, SSL_CTX_keylog_cb_func - logging TLS key material

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef void (*SSL_CTX_keylog_cb_func)(const SSL *ssl, const char *line);
-
-void SSL_CTX_set_keylog_callback(SSL_CTX *ctx, SSL_CTX_keylog_cb_func cb);
-SSL_CTX_keylog_cb_func SSL_CTX_get_keylog_callback(const SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_set_keylog_callback() sets the TLS key logging callback. This callback is called whenever TLS key material is generated or received, in order to allow applications to store this keying material for debugging purposes.

- -

SSL_CTX_get_keylog_callback() retrieves the previously set TLS key logging callback. If no callback has been set, this will return NULL. When there is no key logging callback, or if SSL_CTX_set_keylog_callback is called with NULL as the value of cb, no logging of key material will be done.

- -

The key logging callback is called with two items: the ssl object associated with the connection, and line, a string containing the key material in the format used by NSS for its SSLKEYLOGFILE debugging output. To recreate that file, the key logging callback should log line, followed by a newline. line will always be a NUL-terminated string.

- -

RETURN VALUES

- -

SSL_CTX_get_keylog_callback() returns a pointer to SSL_CTX_keylog_cb_func or NULL if the callback is not set.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2016-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_max_cert_list.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_max_cert_list.html deleted file mode 100644 index 25b7340c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_max_cert_list.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -SSL_CTX_set_max_cert_list - - - - - - - - - - -

NAME

- -

SSL_CTX_set_max_cert_list, SSL_CTX_get_max_cert_list, SSL_set_max_cert_list, SSL_get_max_cert_list - manipulate allowed size for the peer's certificate chain

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_max_cert_list(SSL_CTX *ctx, long size);
-long SSL_CTX_get_max_cert_list(SSL_CTX *ctx);
-
-long SSL_set_max_cert_list(SSL *ssl, long size);
-long SSL_get_max_cert_list(SSL *ctx);
- -

DESCRIPTION

- -

SSL_CTX_set_max_cert_list() sets the maximum size allowed for the peer's certificate chain for all SSL objects created from ctx to be <size> bytes. The SSL objects inherit the setting valid for ctx at the time SSL_new(3) is being called.

- -

SSL_CTX_get_max_cert_list() returns the currently set maximum size for ctx.

- -

SSL_set_max_cert_list() sets the maximum size allowed for the peer's certificate chain for ssl to be <size> bytes. This setting stays valid until a new value is set.

- -

SSL_get_max_cert_list() returns the currently set maximum size for ssl.

- -

NOTES

- -

During the handshake process, the peer may send a certificate chain. The TLS/SSL standard does not give any maximum size of the certificate chain. The OpenSSL library handles incoming data by a dynamically allocated buffer. In order to prevent this buffer from growing without bounds due to data received from a faulty or malicious peer, a maximum size for the certificate chain is set.

- -

The default value for the maximum certificate chain size is 100kB (30kB on the 16-bit DOS platform). This should be sufficient for usual certificate chains (OpenSSL's default maximum chain length is 10, see SSL_CTX_set_verify(3), and certificates without special extensions have a typical size of 1-2kB).

- -

For special applications it can be necessary to extend the maximum certificate chain size allowed to be sent by the peer, see e.g. the work on "Internet X.509 Public Key Infrastructure Proxy Certificate Profile" and "TLS Delegation Protocol" at http://www.ietf.org/ and http://www.globus.org/ .

- -

Under normal conditions it should never be necessary to set a value smaller than the default, as the buffer is handled dynamically and only uses the memory actually required by the data sent by the peer.

- -

If the maximum certificate chain size allowed is exceeded, the handshake will fail with a SSL_R_EXCESSIVE_MESSAGE_SIZE error.

- -

RETURN VALUES

- -

SSL_CTX_set_max_cert_list() and SSL_set_max_cert_list() return the previously set value.

- -

SSL_CTX_get_max_cert_list() and SSL_get_max_cert_list() return the currently set value.

- -

SEE ALSO

- -

ssl(7), SSL_new(3), SSL_CTX_set_verify(3)

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_min_proto_version.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_min_proto_version.html deleted file mode 100644 index 0d1f5692..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_min_proto_version.html +++ /dev/null @@ -1,82 +0,0 @@ - - - - -SSL_CTX_set_min_proto_version - - - - - - - - - - -

NAME

- -

SSL_CTX_set_min_proto_version, SSL_CTX_set_max_proto_version, SSL_CTX_get_min_proto_version, SSL_CTX_get_max_proto_version, SSL_set_min_proto_version, SSL_set_max_proto_version, SSL_get_min_proto_version, SSL_get_max_proto_version - Get and set minimum and maximum supported protocol version

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set_min_proto_version(SSL_CTX *ctx, int version);
-int SSL_CTX_set_max_proto_version(SSL_CTX *ctx, int version);
-int SSL_CTX_get_min_proto_version(SSL_CTX *ctx);
-int SSL_CTX_get_max_proto_version(SSL_CTX *ctx);
-
-int SSL_set_min_proto_version(SSL *ssl, int version);
-int SSL_set_max_proto_version(SSL *ssl, int version);
-int SSL_get_min_proto_version(SSL *ssl);
-int SSL_get_max_proto_version(SSL *ssl);
- -

DESCRIPTION

- -

The functions get or set the minimum and maximum supported protocol versions for the ctx or ssl. This works in combination with the options set via SSL_CTX_set_options(3) that also make it possible to disable specific protocol versions. Use these functions instead of disabling specific protocol versions.

- -

Setting the minimum or maximum version to 0 (default), will enable protocol versions down to the lowest version, or up to the highest version supported by the library, respectively. The supported versions might be controlled by system configuration.

- -

Getters return 0 in case ctx or ssl have been configured to automatically use the lowest or highest version supported by the library.

- -

Currently supported versions are SSL3_VERSION, TLS1_VERSION, TLS1_1_VERSION, TLS1_2_VERSION, TLS1_3_VERSION for TLS and DTLS1_VERSION, DTLS1_2_VERSION for DTLS.

- -

In the current version of OpenSSL only QUICv1 is supported in conjunction with TLSv1.3. Calling these functions on a QUIC object has no effect.

- -

RETURN VALUES

- -

These setter functions return 1 on success and 0 on failure. The getter functions return the configured version or 0 for auto-configuration of lowest or highest protocol, respectively.

- -

NOTES

- -

All these functions are implemented using macros.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_options(3), SSL_CONF_cmd(3)

- -

HISTORY

- -

The setter functions were added in OpenSSL 1.1.0. The getter functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_mode.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_mode.html deleted file mode 100644 index a0026de0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_mode.html +++ /dev/null @@ -1,138 +0,0 @@ - - - - -SSL_CTX_set_mode - - - - - - - - - - -

NAME

- -

SSL_CTX_set_mode, SSL_CTX_clear_mode, SSL_set_mode, SSL_clear_mode, SSL_CTX_get_mode, SSL_get_mode - manipulate SSL engine mode

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_mode(SSL_CTX *ctx, long mode);
-long SSL_CTX_clear_mode(SSL_CTX *ctx, long mode);
-long SSL_set_mode(SSL *ssl, long mode);
-long SSL_clear_mode(SSL *ssl, long mode);
-
-long SSL_CTX_get_mode(SSL_CTX *ctx);
-long SSL_get_mode(SSL *ssl);
- -

DESCRIPTION

- -

SSL_CTX_set_mode() adds the mode set via bit-mask in mode to ctx. Options already set before are not cleared. SSL_CTX_clear_mode() removes the mode set via bit-mask in mode from ctx.

- -

SSL_set_mode() adds the mode set via bit-mask in mode to ssl. Options already set before are not cleared. SSL_clear_mode() removes the mode set via bit-mask in mode from ssl.

- -

SSL_CTX_get_mode() returns the mode set for ctx.

- -

SSL_get_mode() returns the mode set for ssl.

- -

NOTES

- -

The following mode changes are available:

- -
- -
SSL_MODE_ENABLE_PARTIAL_WRITE
-
- -

Allow SSL_write_ex(..., n, &r) to return with 0 < r < n (i.e. report success when just a single record has been written). This works in a similar way for SSL_write(). When not set (the default), SSL_write_ex() or SSL_write() will only report success once the complete chunk was written. Once SSL_write_ex() or SSL_write() returns successful, r bytes have been written and the next call to SSL_write_ex() or SSL_write() must only send the n-r bytes left, imitating the behaviour of write().

- -

This mode cannot be enabled while in the middle of an incomplete write operation.

- -
-
SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER
-
- -

Make it possible to retry SSL_write_ex() or SSL_write() with changed buffer location (the buffer contents must stay the same). This is not the default to avoid the misconception that nonblocking SSL_write() behaves like nonblocking write().

- -
-
SSL_MODE_AUTO_RETRY
-
- -

During normal operations, non-application data records might need to be sent or received that the application is not aware of. If a non-application data record was processed, SSL_read_ex(3) and SSL_read(3) can return with a failure and indicate the need to retry with SSL_ERROR_WANT_READ. If such a non-application data record was processed, the flag SSL_MODE_AUTO_RETRY causes it to try to process the next record instead of returning.

- -

In a nonblocking environment applications must be prepared to handle incomplete read/write operations. Setting SSL_MODE_AUTO_RETRY for a nonblocking BIO will process non-application data records until either no more data is available or an application data record has been processed.

- -

In a blocking environment, applications are not always prepared to deal with the functions returning intermediate reports such as retry requests, and setting the SSL_MODE_AUTO_RETRY flag will cause the functions to only return after successfully processing an application data record or a failure.

- -

Turning off SSL_MODE_AUTO_RETRY can be useful with blocking BIOs in case they are used in combination with something like select() or poll(). Otherwise the call to SSL_read() or SSL_read_ex() might hang when a non-application record was sent and no application data was sent.

- -
-
SSL_MODE_RELEASE_BUFFERS
-
- -

When we no longer need a read buffer or a write buffer for a given SSL, then release the memory we were using to hold it. Using this flag can save around 34k per idle SSL connection. This flag has no effect on SSL v2 connections, or on DTLS connections.

- -
-
SSL_MODE_SEND_FALLBACK_SCSV
-
- -

Send TLS_FALLBACK_SCSV in the ClientHello. To be set only by applications that reconnect with a downgraded protocol version; see draft-ietf-tls-downgrade-scsv-00 for details.

- -

DO NOT ENABLE THIS if your application attempts a normal handshake. Only use this in explicit fallback retries, following the guidance in draft-ietf-tls-downgrade-scsv-00.

- -
-
SSL_MODE_ASYNC
-
- -

Enable asynchronous processing. TLS I/O operations may indicate a retry with SSL_ERROR_WANT_ASYNC with this mode set if an asynchronous capable engine is used to perform cryptographic operations. See SSL_get_error(3).

- -
-
SSL_MODE_DTLS_SCTP_LABEL_LENGTH_BUG
-
- -

Older versions of OpenSSL had a bug in the computation of the label length used for computing the endpoint-pair shared secret. The bug was that the terminating zero was included in the length of the label. Setting this option enables this behaviour to allow interoperability with such broken implementations. Please note that setting this option breaks interoperability with correct implementations. This option only applies to DTLS over SCTP.

- -
-
- -

All modes are off by default except for SSL_MODE_AUTO_RETRY which is on by default since 1.1.1.

- -

RETURN VALUES

- -

SSL_CTX_set_mode() and SSL_set_mode() return the new mode bit-mask after adding mode.

- -

SSL_CTX_get_mode() and SSL_get_mode() return the current bit-mask.

- -

SEE ALSO

- -

ssl(7), SSL_read_ex(3), SSL_read(3), SSL_write_ex(3) or SSL_write(3), SSL_get_error(3)

- -

HISTORY

- -

SSL_MODE_ASYNC was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_msg_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_msg_callback.html deleted file mode 100644 index d49abf37..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_msg_callback.html +++ /dev/null @@ -1,183 +0,0 @@ - - - - -SSL_CTX_set_msg_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_msg_callback, SSL_CTX_set_msg_callback_arg, SSL_set_msg_callback, SSL_set_msg_callback_arg, SSL_trace - install callback for observing protocol messages

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_msg_callback(SSL_CTX *ctx,
-                              void (*cb)(int write_p, int version,
-                                         int content_type, const void *buf,
-                                         size_t len, SSL *ssl, void *arg));
-void SSL_CTX_set_msg_callback_arg(SSL_CTX *ctx, void *arg);
-
-void SSL_set_msg_callback(SSL *ssl,
-                          void (*cb)(int write_p, int version,
-                                     int content_type, const void *buf,
-                                     size_t len, SSL *ssl, void *arg));
-void SSL_set_msg_callback_arg(SSL *ssl, void *arg);
-
-void SSL_trace(int write_p, int version, int content_type,
-               const void *buf, size_t len, SSL *ssl, void *arg);
- -

DESCRIPTION

- -

SSL_CTX_set_msg_callback() or SSL_set_msg_callback() can be used to define a message callback function cb for observing all SSL/TLS/QUIC protocol messages (such as handshake messages) that are received or sent, as well as other events that occur during processing. SSL_CTX_set_msg_callback_arg() and SSL_set_msg_callback_arg() can be used to set argument arg to the callback function, which is available for arbitrary application use.

- -

SSL_CTX_set_msg_callback() and SSL_CTX_set_msg_callback_arg() specify default settings that will be copied to new SSL objects by SSL_new(3). SSL_set_msg_callback() and SSL_set_msg_callback_arg() modify the actual settings of an SSL object. Using a NULL pointer for cb disables the message callback.

- -

When cb is called by the SSL/TLS/QUIC library the function arguments have the following meaning:

- -
- -
write_p
-
- -

This flag is 0 when a protocol message has been received and 1 when a protocol message has been sent.

- -
-
version
-
- -

The protocol version according to which the protocol message is interpreted by the library such as TLS1_3_VERSION, TLS1_2_VERSION, OSSL_QUIC1_VERSION etc. For the SSL3_RT_HEADER pseudo content type (see NOTES below) this value will be the decoded version/legacy_version field of the record header.

- -
-
content_type
-
- -

This is one of the content type values defined in the protocol specification (SSL3_RT_CHANGE_CIPHER_SPEC, SSL3_RT_ALERT, SSL3_RT_HANDSHAKE; but never SSL3_RT_APPLICATION_DATA because the callback will only be called for protocol messages). Alternatively it may be a "pseudo" content type. These pseudo content types are used to signal some other event in the processing of data (see NOTES below).

- -
-
buf, len
-
- -

buf points to a buffer containing the protocol message or other data (in the case of pseudo content types), which consists of len bytes. The buffer is no longer valid after the callback function has returned.

- -
-
ssl
-
- -

The SSL object that received or sent the message.

- -
-
arg
-
- -

The user-defined argument optionally defined by SSL_CTX_set_msg_callback_arg() or SSL_set_msg_callback_arg().

- -
-
- -

The SSL_trace() function can be used as a pre-written callback in a call to SSL_CTX_set_msg_callback() or SSL_set_msg_callback(). It requires a BIO to be set as the callback argument via SSL_CTX_set_msg_callback_arg() or SSL_set_msg_callback_arg(). Setting this callback will cause human readable diagostic tracing information about an SSL/TLS/QUIC connection to be written to the BIO.

- -

NOTES

- -

Protocol messages are passed to the callback function after decryption and fragment collection where applicable. (Thus record boundaries are not visible.)

- -

If processing a received protocol message results in an error, the callback function may not be called. For example, the callback function will never see messages that are considered too large to be processed.

- -

Due to automatic protocol version negotiation, version is not necessarily the protocol version used by the sender of the message: If a TLS 1.0 ClientHello message is received by an SSL 3.0-only server, version will be SSL3_VERSION.

- -

Pseudo content type values may be sent at various points during the processing of data. The following pseudo content types are currently defined:

- -
- -
SSL3_RT_HEADER
-
- -

Used when a TLS record is sent or received. The buf contains the record header bytes only.

- -
-
SSL3_RT_INNER_CONTENT_TYPE
-
- -

Used when an encrypted TLSv1.3 record is sent or received. In encrypted TLSv1.3 records the content type in the record header is always SSL3_RT_APPLICATION_DATA. The real content type for the record is contained in an "inner" content type. buf contains the encoded "inner" content type byte.

- -
-
SSL3_RT_QUIC_DATAGRAM
-
- -

Used when a QUIC datagram is sent or received.

- -
-
SSL3_RT_QUIC_PACKET
-
- -

Used when a QUIC packet is sent or received.

- -
-
SSL3_RT_QUIC_FRAME_FULL
-
- -

Used when a QUIC frame is sent or received. This is only used for non-crypto and stream data related frames. The full QUIC frame data is supplied.

- -
-
SSL3_RT_QUIC_FRAME_HEADER
-
- -

Used when a QUIC stream data or crypto frame is sent or received. Only the QUIC frame header data is supplied.

- -
-
SSL3_RT_QUIC_FRAME_PADDING
-
- -

Used when a sequence of one or more QUIC padding frames is sent or received. A padding frame consists of a single byte and it is common to have multiple such frames in a sequence. Rather than supplying each frame individually the callback will supply all the padding frames in one go via this pseudo content type.

- -
-
- -

RETURN VALUES

- -

SSL_CTX_set_msg_callback(), SSL_CTX_set_msg_callback_arg(), SSL_set_msg_callback() and SSL_set_msg_callback_arg() do not return values.

- -

SEE ALSO

- -

ssl(7), SSL_new(3)

- -

HISTORY

- -

The pseudo content type SSL3_RT_INNER_CONTENT_TYPE was added in OpenSSL 1.1.1.

- -

The pseudo content types SSL3_RT_QUIC_DATAGRAM, SSL3_RT_QUIC_PACKET, SSL3_RT_QUIC_FRAME_FULL, SSL3_RT_QUIC_FRAME_HEADER and SSL3_RT_QUIC_FRAME_PADDING were added in OpenSSL 3.2.

- -

In versions previous to OpenSSL 3.0 cb was called with 0 as version for the pseudo content type SSL3_RT_HEADER for TLS records.

- -

In versions previous to OpenSSL 3.2 cb was called with 0 as version for the pseudo content type SSL3_RT_HEADER for DTLS records.

- -

COPYRIGHT

- -

Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_num_tickets.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_num_tickets.html deleted file mode 100644 index 6c22bd6e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_num_tickets.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -SSL_CTX_set_num_tickets - - - - - - - - - - -

NAME

- -

SSL_set_num_tickets, SSL_get_num_tickets, SSL_CTX_set_num_tickets, SSL_CTX_get_num_tickets, SSL_new_session_ticket - control the number of TLSv1.3 session tickets that are issued

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set_num_tickets(SSL *s, size_t num_tickets);
-size_t SSL_get_num_tickets(const SSL *s);
-int SSL_CTX_set_num_tickets(SSL_CTX *ctx, size_t num_tickets);
-size_t SSL_CTX_get_num_tickets(const SSL_CTX *ctx);
-int SSL_new_session_ticket(SSL *s);
- -

DESCRIPTION

- -

SSL_CTX_set_num_tickets() and SSL_set_num_tickets() can be called for a server application and set the number of TLSv1.3 session tickets that will be sent to the client after a full handshake. Set the desired value (which could be 0) in the num_tickets argument. Typically these functions should be called before the start of the handshake.

- -

The default number of tickets is 2. Following a resumption the number of tickets issued will never be more than 1 regardless of the value set via SSL_set_num_tickets() or SSL_CTX_set_num_tickets(). If num_tickets is set to 0 then no tickets will be issued for either a normal connection or a resumption.

- -

Tickets are also issued on receipt of a post-handshake certificate from the client following a request by the server using SSL_verify_client_post_handshake(3). These new tickets will be associated with the updated client identity (i.e. including their certificate and verification status). The number of tickets issued will normally be the same as was used for the initial handshake. If the initial handshake was a full handshake then SSL_set_num_tickets() can be called again prior to calling SSL_verify_client_post_handshake() to update the number of tickets that will be sent.

- -

To issue tickets after other events (such as application-layer changes), SSL_new_session_ticket() is used by a server application to request that a new ticket be sent when it is safe to do so. New tickets are only allowed to be sent in this manner after the initial handshake has completed, and only for TLS 1.3 connections. By default, the ticket generation and transmission are delayed until the server is starting a new write operation, so that it is bundled with other application data being written and properly aligned to a record boundary. If the connection was at a record boundary when SSL_new_session_ticket() was called, the ticket can be sent immediately (without waiting for the next application write) by calling SSL_do_handshake(). SSL_new_session_ticket() can be called more than once to request additional tickets be sent; all such requests are queued and written together when it is safe to do so and triggered by SSL_write() or SSL_do_handshake(). Note that a successful return from SSL_new_session_ticket() indicates only that the request to send a ticket was processed, not that the ticket itself was sent. To be notified when the ticket itself is sent, a new-session callback can be registered with SSL_CTX_sess_set_new_cb(3) that will be invoked as the ticket or tickets are generated.

- -

SSL_CTX_get_num_tickets() and SSL_get_num_tickets() return the number of tickets set by a previous call to SSL_CTX_set_num_tickets() or SSL_set_num_tickets(), or 2 if no such call has been made.

- -

RETURN VALUES

- -

SSL_CTX_set_num_tickets(), SSL_set_num_tickets(), and SSL_new_session_ticket() return 1 on success or 0 on failure.

- -

SSL_CTX_get_num_tickets() and SSL_get_num_tickets() return the number of tickets that have been previously set.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

SSL_new_session_ticket() was added in OpenSSL 3.0.0. SSL_set_num_tickets(), SSL_get_num_tickets(), SSL_CTX_set_num_tickets(), and SSL_CTX_get_num_tickets() were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_options.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_options.html deleted file mode 100644 index 855f582f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_options.html +++ /dev/null @@ -1,503 +0,0 @@ - - - - -SSL_CTX_set_options - - - - - - - - - - -

NAME

- -

SSL_CTX_set_options, SSL_set_options, SSL_CTX_clear_options, SSL_clear_options, SSL_CTX_get_options, SSL_get_options, SSL_get_secure_renegotiation_support - manipulate SSL options

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-uint64_t SSL_CTX_set_options(SSL_CTX *ctx, uint64_t options);
-uint64_t SSL_set_options(SSL *ssl, uint64_t options);
-
-uint64_t SSL_CTX_clear_options(SSL_CTX *ctx, uint64_t options);
-uint64_t SSL_clear_options(SSL *ssl, uint64_t options);
-
-uint64_t SSL_CTX_get_options(const SSL_CTX *ctx);
-uint64_t SSL_get_options(const SSL *ssl);
-
-long SSL_get_secure_renegotiation_support(SSL *ssl);
- -

DESCRIPTION

- -

SSL_CTX_set_options() adds the options set via bit-mask in options to ctx. Options already set before are not cleared!

- -

SSL_set_options() adds the options set via bit-mask in options to ssl. Options already set before are not cleared!

- -

SSL_CTX_clear_options() clears the options set via bit-mask in options to ctx.

- -

SSL_clear_options() clears the options set via bit-mask in options to ssl.

- -

SSL_CTX_get_options() returns the options set for ctx.

- -

SSL_get_options() returns the options set for ssl.

- -

SSL_get_secure_renegotiation_support() indicates whether the peer supports secure renegotiation. Note, this is implemented via a macro.

- -

NOTES

- -

The behaviour of the SSL library can be changed by setting several options. The options are coded as bit-masks and can be combined by a bitwise or operation (|).

- -

SSL_CTX_set_options() and SSL_set_options() affect the (external) protocol behaviour of the SSL library. The (internal) behaviour of the API can be changed by using the similar SSL_CTX_set_mode(3) and SSL_set_mode() functions.

- -

During a handshake, the option settings of the SSL object are used. When a new SSL object is created from a context using SSL_new(), the current option setting is copied. Changes to ctx do not affect already created SSL objects. SSL_clear() does not affect the settings.

- -

The following bug workaround options are available:

- -
- -
SSL_OP_CRYPTOPRO_TLSEXT_BUG
-
- -

Add server-hello extension from the early version of cryptopro draft when GOST ciphersuite is negotiated. Required for interoperability with CryptoPro CSP 3.x.

- -
-
SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS
-
- -

Disables a countermeasure against a SSL 3.0/TLS 1.0 protocol vulnerability affecting CBC ciphers, which cannot be handled by some broken SSL implementations. This option has no effect for connections using other ciphers.

- -
-
SSL_OP_SAFARI_ECDHE_ECDSA_BUG
-
- -

Don't prefer ECDHE-ECDSA ciphers when the client appears to be Safari on OS X. OS X 10.8..10.8.3 has broken support for ECDHE-ECDSA ciphers.

- -
-
SSL_OP_TLSEXT_PADDING
-
- -

Adds a padding extension to ensure the ClientHello size is never between 256 and 511 bytes in length. This is needed as a workaround for some implementations.

- -
-
SSL_OP_ALL
-
- -

All of the above bug workarounds.

- -
-
- -

It is usually safe to use SSL_OP_ALL to enable the bug workaround options if compatibility with somewhat broken implementations is desired.

- -

The following modifying options are available:

- -
- -
SSL_OP_ALLOW_CLIENT_RENEGOTIATION
-
- -

Client-initiated renegotiation is disabled by default. Use this option to enable it.

- -
-
SSL_OP_ALLOW_NO_DHE_KEX
-
- -

In TLSv1.3 allow a non-(ec)dhe based key exchange mode on resumption. This means that there will be no forward secrecy for the resumed session.

- -
-
SSL_OP_PREFER_NO_DHE_KEX
-
- -

In TLSv1.3, on resumption let the server prefer a non-(ec)dhe based key exchange mode over an (ec)dhe based one. Ignored without SSL_OP_ALLOW_NO_DHE_KEX being set as well. Always ignored on the client.

- -
-
SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION
-
- -

Allow legacy insecure renegotiation between OpenSSL and unpatched clients or servers. See the SECURE RENEGOTIATION section for more details.

- -
-
SSL_OP_CIPHER_SERVER_PREFERENCE
-
- -

When choosing a cipher, use the server's preferences instead of the client preferences. When not set, the SSL server will always follow the clients preferences. When set, the SSL/TLS server will choose following its own preferences.

- -
-
SSL_OP_CISCO_ANYCONNECT
-
- -

Use Cisco's version identifier of DTLS_BAD_VER when establishing a DTLSv1 connection. Only available when using the deprecated DTLSv1_client_method() API.

- -
-
SSL_OP_CLEANSE_PLAINTEXT
-
- -

By default TLS and QUIC SSL objects keep a copy of received plaintext application data in a static buffer until it is overwritten by the next portion of data. When enabling SSL_OP_CLEANSE_PLAINTEXT deciphered application data is cleansed by calling OPENSSL_cleanse(3) after passing data to the application. Data is also cleansed when releasing the connection (e.g. SSL_free(3)).

- -

Since OpenSSL only cleanses internal buffers, the application is still responsible for cleansing all other buffers. Most notably, this applies to buffers passed to functions like SSL_read(3), SSL_peek(3) but also like SSL_write(3).

- -

TLS connections do not buffer data to be sent in plaintext. QUIC stream objects do buffer plaintext data to be sent and this option will also cause that data to be cleansed when it is discarded.

- -

This option can be set differently on individual QUIC stream objects and has no effect on QUIC connection objects (except where a default stream is being used).

- -
- -
- -

Turn on Cookie Exchange as described in RFC4347 Section 4.2.1. Only affects DTLS connections.

- -
-
SSL_OP_DISABLE_TLSEXT_CA_NAMES
-
- -

Disable TLS Extension CA Names. You may want to disable it for security reasons or for compatibility with some Windows TLS implementations crashing when this extension is larger than 1024 bytes.

- -
-
SSL_OP_ENABLE_KTLS
-
- -

Enable the use of kernel TLS. In order to benefit from kernel TLS OpenSSL must have been compiled with support for it, and it must be supported by the negotiated ciphersuites and extensions. The specific ciphersuites and extensions that are supported may vary by platform and kernel version.

- -

The kernel TLS data-path implements the record layer, and the encryption algorithm. The kernel will utilize the best hardware available for encryption. Using the kernel data-path should reduce the memory footprint of OpenSSL because no buffering is required. Also, the throughput should improve because data copy is avoided when user data is encrypted into kernel memory instead of the usual encrypt then copy to kernel.

- -

Kernel TLS might not support all the features of OpenSSL. For instance, renegotiation, and setting the maximum fragment size is not possible as of Linux 4.20.

- -

Note that with kernel TLS enabled some cryptographic operations are performed by the kernel directly and not via any available OpenSSL Providers. This might be undesirable if, for example, the application requires all cryptographic operations to be performed by the FIPS provider.

- -
-
SSL_OP_ENABLE_KTLS_TX_ZEROCOPY_SENDFILE
-
- -

With this option, sendfile() will use the zerocopy mode, which gives a performance boost when used with KTLS hardware offload. Note that invalid TLS records might be transmitted if the file is changed while being sent. This option has no effect if SSL_OP_ENABLE_KTLS is not enabled.

- -

This option only applies to Linux. KTLS sendfile on FreeBSD doesn't offer an option to disable zerocopy and always runs in this mode.

- -
-
SSL_OP_ENABLE_MIDDLEBOX_COMPAT
-
- -

If set then dummy Change Cipher Spec (CCS) messages are sent in TLSv1.3. This has the effect of making TLSv1.3 look more like TLSv1.2 so that middleboxes that do not understand TLSv1.3 will not drop the connection. Regardless of whether this option is set or not CCS messages received from the peer will always be ignored in TLSv1.3. This option is set by default. To switch it off use SSL_clear_options(). A future version of OpenSSL may not set this by default.

- -
-
SSL_OP_IGNORE_UNEXPECTED_EOF
-
- -

Some TLS implementations do not send the mandatory close_notify alert on shutdown. If the application tries to wait for the close_notify alert but the peer closes the connection without sending it, an error is generated. When this option is enabled the peer does not need to send the close_notify alert and a closed connection will be treated as if the close_notify alert was received.

- -

You should only enable this option if the protocol running over TLS can detect a truncation attack itself, and that the application is checking for that truncation attack.

- -

For more information on shutting down a connection, see SSL_shutdown(3).

- -
-
SSL_OP_LEGACY_SERVER_CONNECT
-
- -

Allow legacy insecure renegotiation between OpenSSL and unpatched servers only. See the SECURE RENEGOTIATION section for more details.

- -
-
SSL_OP_NO_ANTI_REPLAY
-
- -

By default, when a server is configured for early data (i.e., max_early_data > 0), OpenSSL will switch on replay protection. See SSL_read_early_data(3) for a description of the replay protection feature. Anti-replay measures are required to comply with the TLSv1.3 specification. Some applications may be able to mitigate the replay risks in other ways and in such cases the built in OpenSSL functionality is not required. Those applications can turn this feature off by setting this option. This is a server-side option only. It is ignored by clients.

- -
-
SSL_OP_NO_TX_CERTIFICATE_COMPRESSION
-
- -

Normally clients and servers will transparently attempt to negotiate the RFC8879 certificate compression option on TLSv1.3 connections.

- -

If this option is set, the certificate compression extension is ignored upon receipt and compressed certificates will not be sent to the peer.

- -
-
SSL_OP_NO_RX_CERTIFICATE_COMPRESSION
-
- -

Normally clients and servers will transparently attempt to negotiate the RFC8879 certificate compression option on TLSv1.3 connections.

- -

If this option is set, the certificate compression extension will not be sent and compressed certificates will not be accepted from the peer.

- -
-
SSL_OP_NO_COMPRESSION
-
- -

Do not use TLS record compression even if it is supported. This option is set by default. To switch it off use SSL_clear_options(). Note that TLS record compression is not recommended and is not available at security level 2 or above. From OpenSSL 3.2 the default security level is 2, so clearing this option will have no effect without also changing the default security level. See SSL_CTX_set_security_level(3).

- -
-
SSL_OP_NO_ENCRYPT_THEN_MAC
-
- -

Normally clients and servers will transparently attempt to negotiate the RFC7366 Encrypt-then-MAC option on TLS and DTLS connection.

- -

If this option is set, Encrypt-then-MAC is disabled. Clients will not propose, and servers will not accept the extension.

- -
-
SSL_OP_NO_EXTENDED_MASTER_SECRET
-
- -

Normally clients and servers will transparently attempt to negotiate the RFC7627 Extended Master Secret option on TLS and DTLS connection.

- -

If this option is set, Extended Master Secret is disabled. Clients will not propose, and servers will not accept the extension.

- -
-
SSL_OP_NO_QUERY_MTU
-
- -

Do not query the MTU. Only affects DTLS connections.

- -
-
SSL_OP_NO_RENEGOTIATION
-
- -

Disable all renegotiation in (D)TLSv1.2 and earlier. Do not send HelloRequest messages, and ignore renegotiation requests via ClientHello.

- -
-
SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION
-
- -

When performing renegotiation as a server, always start a new session (i.e., session resumption requests are only accepted in the initial handshake). This option is not needed for clients.

- -
-
SSL_OP_NO_SSLv3, SSL_OP_NO_TLSv1, SSL_OP_NO_TLSv1_1, SSL_OP_NO_TLSv1_2, SSL_OP_NO_TLSv1_3, SSL_OP_NO_DTLSv1, SSL_OP_NO_DTLSv1_2
-
- -

These options turn off the SSLv3, TLSv1, TLSv1.1, TLSv1.2 or TLSv1.3 protocol versions with TLS or the DTLSv1, DTLSv1.2 versions with DTLS, respectively. As of OpenSSL 1.1.0, these options are deprecated, use SSL_CTX_set_min_proto_version(3) and SSL_CTX_set_max_proto_version(3) instead.

- -
-
SSL_OP_NO_TICKET
-
- -

SSL/TLS supports two mechanisms for resuming sessions: session ids and stateless session tickets.

- -

When using session ids a copy of the session information is cached on the server and a unique id is sent to the client. When the client wishes to resume it provides the unique id so that the server can retrieve the session information from its cache.

- -

When using stateless session tickets the server uses a session ticket encryption key to encrypt the session information. This encrypted data is sent to the client as a "ticket". When the client wishes to resume it sends the encrypted data back to the server. The server uses its key to decrypt the data and resume the session. In this way the server can operate statelessly - no session information needs to be cached locally.

- -

The TLSv1.3 protocol only supports tickets and does not directly support session ids. However, OpenSSL allows two modes of ticket operation in TLSv1.3: stateful and stateless. Stateless tickets work the same way as in TLSv1.2 and below. Stateful tickets mimic the session id behaviour available in TLSv1.2 and below. The session information is cached on the server and the session id is wrapped up in a ticket and sent back to the client. When the client wishes to resume, it presents a ticket in the same way as for stateless tickets. The server can then extract the session id from the ticket and retrieve the session information from its cache.

- -

By default OpenSSL will use stateless tickets. The SSL_OP_NO_TICKET option will cause stateless tickets to not be issued. In TLSv1.2 and below this means no ticket gets sent to the client at all. In TLSv1.3 a stateful ticket will be sent. This is a server-side option only.

- -

In TLSv1.3 it is possible to suppress all tickets (stateful and stateless) from being sent by calling SSL_CTX_set_num_tickets(3) or SSL_set_num_tickets(3).

- -
-
SSL_OP_PRIORITIZE_CHACHA
-
- -

When SSL_OP_CIPHER_SERVER_PREFERENCE is set, temporarily reprioritize ChaCha20-Poly1305 ciphers to the top of the server cipher list if a ChaCha20-Poly1305 cipher is at the top of the client cipher list. This helps those clients (e.g. mobile) use ChaCha20-Poly1305 if that cipher is anywhere in the server cipher list; but still allows other clients to use AES and other ciphers. Requires SSL_OP_CIPHER_SERVER_PREFERENCE.

- -
-
SSL_OP_TLS_ROLLBACK_BUG
-
- -

Disable version rollback attack detection.

- -

During the client key exchange, the client must send the same information about acceptable SSL/TLS protocol levels as during the first hello. Some clients violate this rule by adapting to the server's answer. (Example: the client sends a SSLv2 hello and accepts up to SSLv3.1=TLSv1, the server only understands up to SSLv3. In this case the client must still use the same SSLv3.1=TLSv1 announcement. Some clients step down to SSLv3 with respect to the server's answer and violate the version rollback protection.)

- -
-
- -

The following options no longer have any effect but their identifiers are retained for compatibility purposes:

- -
- -
SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG
-
- -
-
SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER
-
- -
-
SSL_OP_SSLEAY_080_CLIENT_DH_BUG
-
- -
-
SSL_OP_TLS_D5_BUG
-
- -
-
SSL_OP_TLS_BLOCK_PADDING_BUG
-
- -
-
SSL_OP_MSIE_SSLV2_RSA_PADDING
-
- -
-
SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG
-
- -
-
SSL_OP_MICROSOFT_SESS_ID_BUG
-
- -
-
SSL_OP_NETSCAPE_CHALLENGE_BUG
-
- -
-
SSL_OP_PKCS1_CHECK_1
-
- -
-
SSL_OP_PKCS1_CHECK_2
-
- -
-
SSL_OP_SINGLE_DH_USE
-
- -
-
SSL_OP_SINGLE_ECDH_USE
-
- -
-
SSL_OP_EPHEMERAL_RSA
-
- -
-
SSL_OP_NETSCAPE_CA_DN_BUG
-
- -
-
SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG
-
- -
-
- -

SECURE RENEGOTIATION

- -

OpenSSL always attempts to use secure renegotiation as described in RFC5746. This counters the prefix attack described in CVE-2009-3555 and elsewhere.

- -

This attack has far reaching consequences which application writers should be aware of. In the description below an implementation supporting secure renegotiation is referred to as patched. A server not supporting secure renegotiation is referred to as unpatched.

- -

The following sections describe the operations permitted by OpenSSL's secure renegotiation implementation.

- -

Patched client and server

- -

Connections and renegotiation are always permitted by OpenSSL implementations.

- -

Unpatched client and patched OpenSSL server

- -

The initial connection succeeds but client renegotiation is denied by the server with a no_renegotiation warning alert if TLS v1.0 is used or a fatal handshake_failure alert in SSL v3.0.

- -

If the patched OpenSSL server attempts to renegotiate a fatal handshake_failure alert is sent. This is because the server code may be unaware of the unpatched nature of the client.

- -

If the option SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION is set then renegotiation always succeeds.

- -

Patched OpenSSL client and unpatched server

- -

If the option SSL_OP_LEGACY_SERVER_CONNECT or SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION is set then initial connections and renegotiation between patched OpenSSL clients and unpatched servers succeeds. If neither option is set then initial connections to unpatched servers will fail.

- -

Setting the option SSL_OP_LEGACY_SERVER_CONNECT has security implications; clients that are willing to connect to servers that do not implement RFC 5746 secure renegotiation are subject to attacks such as CVE-2009-3555.

- -

OpenSSL client applications wishing to ensure they can connect to unpatched servers should always set SSL_OP_LEGACY_SERVER_CONNECT

- -

OpenSSL client applications that want to ensure they can not connect to unpatched servers (and thus avoid any security issues) should always clear SSL_OP_LEGACY_SERVER_CONNECT using SSL_CTX_clear_options() or SSL_clear_options().

- -

The difference between the SSL_OP_LEGACY_SERVER_CONNECT and SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION options is that SSL_OP_LEGACY_SERVER_CONNECT enables initial connections and secure renegotiation between OpenSSL clients and unpatched servers only, while SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION allows initial connections and renegotiation between OpenSSL and unpatched clients or servers.

- -

Applicability of options to QUIC connections and streams

- -

These options apply to SSL objects referencing a QUIC connection:

- -
- -
SSL_OP_ALLOW_NO_DHE_KEX
-
- -
-
SSL_OP_NO_TX_CERTIFICATE_COMPRESSION
-
- -
-
SSL_OP_NO_RX_CERTIFICATE_COMPRESSION
-
- -
-
SSL_OP_NO_TICKET
-
- -
-
SSL_OP_PRIORITIZE_CHACHA
-
- -
-
- -

These options apply to SSL objects referencing a QUIC stream:

- -
- -
SSL_OP_CLEANSE_PLAINTEXT
-
- -
-
- -

Options on QUIC connections are initialized from the options set on SSL_CTX before a QUIC connection SSL object is created. Options on QUIC streams are initialised from the options configured on the QUIC connection SSL object they are created from.

- -

Setting options which relate to QUIC streams on a QUIC connection SSL object has no direct effect on the QUIC connection SSL object itself, but will change the options set on the default stream (if there is one) and will also determine the default options set on any future streams which are created.

- -

Other options not mentioned above do not have an effect and will be ignored.

- -

Options which relate to QUIC streams may also be set directly on QUIC stream SSL objects. Setting connection-related options on such an object has no effect.

- -

RETURN VALUES

- -

SSL_CTX_set_options() and SSL_set_options() return the new options bit-mask after adding options.

- -

SSL_CTX_clear_options() and SSL_clear_options() return the new options bit-mask after clearing options.

- -

SSL_CTX_get_options() and SSL_get_options() return the current bit-mask.

- -

SSL_get_secure_renegotiation_support() returns 1 is the peer supports secure renegotiation and 0 if it does not.

- -

SEE ALSO

- -

ssl(7), SSL_new(3), SSL_clear(3), SSL_shutdown(3) SSL_CTX_set_tmp_dh_callback(3), SSL_CTX_set_min_proto_version(3), openssl-dhparam(1)

- -

HISTORY

- -

The attempt to always try to use secure renegotiation was added in OpenSSL 0.9.8m.

- -

The SSL_OP_PRIORITIZE_CHACHA and SSL_OP_NO_RENEGOTIATION options were added in OpenSSL 1.1.1.

- -

The SSL_OP_NO_EXTENDED_MASTER_SECRET and SSL_OP_IGNORE_UNEXPECTED_EOF options were added in OpenSSL 3.0.

- -

The SSL_OP_ constants and the corresponding parameter and return values of the affected functions were changed to uint64_t type in OpenSSL 3.0. For that reason it is no longer possible use the SSL_OP_ macro values in preprocessor #if conditions. However it is still possible to test whether these macros are defined or not.

- -

COPYRIGHT

- -

Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_psk_client_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_psk_client_callback.html deleted file mode 100644 index 912ce930..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_psk_client_callback.html +++ /dev/null @@ -1,143 +0,0 @@ - - - - -SSL_CTX_set_psk_client_callback - - - - - - - - - - -

NAME

- -

SSL_psk_client_cb_func, SSL_psk_use_session_cb_func, SSL_CTX_set_psk_client_callback, SSL_set_psk_client_callback, SSL_CTX_set_psk_use_session_callback, SSL_set_psk_use_session_callback - set PSK client callback

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*SSL_psk_use_session_cb_func)(SSL *ssl, const EVP_MD *md,
-                                           const unsigned char **id,
-                                           size_t *idlen,
-                                           SSL_SESSION **sess);
-
-
-void SSL_CTX_set_psk_use_session_callback(SSL_CTX *ctx,
-                                          SSL_psk_use_session_cb_func cb);
-void SSL_set_psk_use_session_callback(SSL *s, SSL_psk_use_session_cb_func cb);
-
-
-typedef unsigned int (*SSL_psk_client_cb_func)(SSL *ssl,
-                                               const char *hint,
-                                               char *identity,
-                                               unsigned int max_identity_len,
-                                               unsigned char *psk,
-                                               unsigned int max_psk_len);
-
-void SSL_CTX_set_psk_client_callback(SSL_CTX *ctx, SSL_psk_client_cb_func cb);
-void SSL_set_psk_client_callback(SSL *ssl, SSL_psk_client_cb_func cb);
- -

DESCRIPTION

- -

A client application wishing to use TLSv1.3 PSKs should use either SSL_CTX_set_psk_use_session_callback() or SSL_set_psk_use_session_callback() as appropriate. These functions cannot be used for TLSv1.2 and below PSKs.

- -

The callback function is given a pointer to the SSL connection in ssl.

- -

The first time the callback is called for a connection the md parameter is NULL. In some circumstances the callback will be called a second time. In that case the server will have specified a ciphersuite to use already and the PSK must be compatible with the digest for that ciphersuite. The digest will be given in md. The PSK returned by the callback is allowed to be different between the first and second time it is called.

- -

On successful completion the callback must store a pointer to an identifier for the PSK in *id. The identifier length in bytes should be stored in *idlen. The memory pointed to by *id remains owned by the application and should be freed by it as required at any point after the handshake is complete.

- -

Additionally the callback should store a pointer to an SSL_SESSION object in *sess. This is used as the basis for the PSK, and should, at a minimum, have the following fields set:

- -
- -
The master key
-
- -

This can be set via a call to SSL_SESSION_set1_master_key(3).

- -
-
A ciphersuite
-
- -

Only the handshake digest associated with the ciphersuite is relevant for the PSK (the server may go on to negotiate any ciphersuite which is compatible with the digest). The application can use any TLSv1.3 ciphersuite. If md is not NULL the handshake digest for the ciphersuite should be the same. The ciphersuite can be set via a call to <SSL_SESSION_set_cipher(3)>. The handshake digest of an SSL_CIPHER object can be checked using <SSL_CIPHER_get_handshake_digest(3)>.

- -
-
The protocol version
-
- -

This can be set via a call to SSL_SESSION_set_protocol_version(3) and should be TLS1_3_VERSION.

- -
-
- -

Additionally the maximum early data value should be set via a call to SSL_SESSION_set_max_early_data(3) if the PSK will be used for sending early data.

- -

Alternatively an SSL_SESSION created from a previous non-PSK handshake may also be used as the basis for a PSK.

- -

Ownership of the SSL_SESSION object is passed to the OpenSSL library and so it should not be freed by the application.

- -

It is also possible for the callback to succeed but not supply a PSK. In this case no PSK will be sent to the server but the handshake will continue. To do this the callback should return successfully and ensure that *sess is NULL. The contents of *id and *idlen will be ignored.

- -

A client application wishing to use PSK ciphersuites for TLSv1.2 and below must provide a different callback function. This function will be called when the client is sending the ClientKeyExchange message to the server.

- -

The purpose of the callback function is to select the PSK identity and the pre-shared key to use during the connection setup phase.

- -

The callback is set using functions SSL_CTX_set_psk_client_callback() or SSL_set_psk_client_callback(). The callback function is given the connection in parameter ssl, a NUL-terminated PSK identity hint sent by the server in parameter hint, a buffer identity of length max_identity_len bytes (including the NUL-terminator) where the resulting NUL-terminated identity is to be stored, and a buffer psk of length max_psk_len bytes where the resulting pre-shared key is to be stored.

- -

The callback for use in TLSv1.2 will also work in TLSv1.3 although it is recommended to use SSL_CTX_set_psk_use_session_callback() or SSL_set_psk_use_session_callback() for this purpose instead. If TLSv1.3 has been negotiated then OpenSSL will first check to see if a callback has been set via SSL_CTX_set_psk_use_session_callback() or SSL_set_psk_use_session_callback() and it will use that in preference. If no such callback is present then it will check to see if a callback has been set via SSL_CTX_set_psk_client_callback() or SSL_set_psk_client_callback() and use that. In this case the hint value will always be NULL and the handshake digest will default to SHA-256 for any returned PSK. TLSv1.3 early data exchanges are possible in PSK connections only with the SSL_psk_use_session_cb_func callback, and are not possible with the SSL_psk_client_cb_func callback.

- -

NOTES

- -

Note that parameter hint given to the callback may be NULL.

- -

A connection established via a TLSv1.3 PSK will appear as if session resumption has occurred so that SSL_session_reused(3) will return true.

- -

There are no known security issues with sharing the same PSK between TLSv1.2 (or below) and TLSv1.3. However, the RFC has this note of caution:

- -

"While there is no known way in which the same PSK might produce related output in both versions, only limited analysis has been done. Implementations can ensure safety from cross-protocol related output by not reusing PSKs between TLS 1.3 and TLS 1.2."

- -

RETURN VALUES

- -

Return values from the SSL_psk_client_cb_func callback are interpreted as follows:

- -

On success (callback found a PSK identity and a pre-shared key to use) the length (> 0) of psk in bytes is returned.

- -

Otherwise or on errors the callback should return 0. In this case the connection setup fails.

- -

The SSL_psk_use_session_cb_func callback should return 1 on success or 0 on failure. In the event of failure the connection setup fails.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_psk_find_session_callback(3), SSL_set_psk_find_session_callback(3)

- -

HISTORY

- -

SSL_CTX_set_psk_use_session_callback() and SSL_set_psk_use_session_callback() were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_quiet_shutdown.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_quiet_shutdown.html deleted file mode 100644 index 0d59f3a6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_quiet_shutdown.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -SSL_CTX_set_quiet_shutdown - - - - - - - - - - -

NAME

- -

SSL_CTX_set_quiet_shutdown, SSL_CTX_get_quiet_shutdown, SSL_set_quiet_shutdown, SSL_get_quiet_shutdown - manipulate shutdown behaviour

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_quiet_shutdown(SSL_CTX *ctx, int mode);
-int SSL_CTX_get_quiet_shutdown(const SSL_CTX *ctx);
-
-void SSL_set_quiet_shutdown(SSL *ssl, int mode);
-int SSL_get_quiet_shutdown(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_CTX_set_quiet_shutdown() sets the "quiet shutdown" flag for ctx to be mode. SSL objects created from ctx inherit the mode valid at the time SSL_new(3) is called. mode may be 0 or 1.

- -

SSL_CTX_get_quiet_shutdown() returns the "quiet shutdown" setting of ctx.

- -

SSL_set_quiet_shutdown() sets the "quiet shutdown" flag for ssl to be mode. The setting stays valid until ssl is removed with SSL_free(3) or SSL_set_quiet_shutdown() is called again. It is not changed when SSL_clear(3) is called. mode may be 0 or 1.

- -

SSL_get_quiet_shutdown() returns the "quiet shutdown" setting of ssl.

- -

These functions are not supported for QUIC SSL objects. SSL_set_quiet_shutdown() has no effect if called on a QUIC SSL object.

- -

NOTES

- -

Normally when a SSL connection is finished, the parties must send out close_notify alert messages using SSL_shutdown(3) for a clean shutdown.

- -

When setting the "quiet shutdown" flag to 1, SSL_shutdown(3) will set the internal flags to SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN. (SSL_shutdown(3) then behaves like SSL_set_shutdown(3) called with SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN.) The session is thus considered to be shutdown, but no close_notify alert is sent to the peer. This behaviour violates the TLS standard.

- -

The default is normal shutdown behaviour as described by the TLS standard.

- -

RETURN VALUES

- -

SSL_CTX_set_quiet_shutdown() and SSL_set_quiet_shutdown() do not return diagnostic information.

- -

SSL_CTX_get_quiet_shutdown() and SSL_get_quiet_shutdown() return the current setting.

- -

SEE ALSO

- -

ssl(7), SSL_shutdown(3), SSL_set_shutdown(3), SSL_new(3), SSL_clear(3), SSL_free(3)

- -

COPYRIGHT

- -

Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_read_ahead.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_read_ahead.html deleted file mode 100644 index 535276de..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_read_ahead.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -SSL_CTX_set_read_ahead - - - - - - - - - - -

NAME

- -

SSL_CTX_set_read_ahead, SSL_CTX_get_read_ahead, SSL_set_read_ahead, SSL_get_read_ahead, SSL_CTX_get_default_read_ahead - manage whether to read as many input bytes as possible

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_set_read_ahead(SSL *s, int yes);
-int SSL_get_read_ahead(const SSL *s);
-
-SSL_CTX_set_read_ahead(SSL_CTX *ctx, int yes);
-long SSL_CTX_get_read_ahead(SSL_CTX *ctx);
-long SSL_CTX_get_default_read_ahead(SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_set_read_ahead() and SSL_set_read_ahead() set whether we should read as many input bytes as possible (for nonblocking reads) or not. For example if x bytes are currently required by OpenSSL, but y bytes are available from the underlying BIO (where y > x), then OpenSSL will read all y bytes into its buffer (providing that the buffer is large enough) if reading ahead is on, or x bytes otherwise. Setting the parameter yes to 0 turns reading ahead is off, other values turn it on. SSL_CTX_set_default_read_ahead() is identical to SSL_CTX_set_read_ahead().

- -

SSL_CTX_get_read_ahead() and SSL_get_read_ahead() indicate whether reading ahead has been set or not. SSL_CTX_get_default_read_ahead() is identical to SSL_CTX_get_read_ahead().

- -

These functions cannot be used with QUIC SSL objects. SSL_set_read_ahead() has no effect if called on a QUIC SSL object.

- -

NOTES

- -

These functions have no impact when used with DTLS. The return values for SSL_CTX_get_read_head() and SSL_get_read_ahead() are undefined for DTLS. Setting read_ahead can impact the behaviour of the SSL_pending() function (see SSL_pending(3)).

- -

Since SSL_read() can return SSL_ERROR_WANT_READ for non-application data records, and SSL_has_pending() can't tell the difference between processed and unprocessed data, it's recommended that if read ahead is turned on that SSL_MODE_AUTO_RETRY is not turned off using SSL_CTX_clear_mode(). That will prevent getting SSL_ERROR_WANT_READ when there is still a complete record available that hasn't been processed.

- -

If the application wants to continue to use the underlying transport (e.g. TCP connection) after the SSL connection is finished using SSL_shutdown() reading ahead should be turned off. Otherwise the SSL structure might read data that it shouldn't.

- -

RETURN VALUES

- -

SSL_get_read_ahead() and SSL_CTX_get_read_ahead() return 0 if reading ahead is off, and non zero otherwise.

- -

SEE ALSO

- -

ssl(7), SSL_pending(3)

- -

COPYRIGHT

- -

Copyright 2015-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_record_padding_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_record_padding_callback.html deleted file mode 100644 index 26e29230..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_record_padding_callback.html +++ /dev/null @@ -1,106 +0,0 @@ - - - - -SSL_CTX_set_record_padding_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_record_padding_callback, SSL_set_record_padding_callback, SSL_CTX_set_record_padding_callback_arg, SSL_set_record_padding_callback_arg, SSL_CTX_get_record_padding_callback_arg, SSL_get_record_padding_callback_arg, SSL_CTX_set_block_padding, SSL_CTX_set_block_padding_ex, SSL_set_block_padding, SSL_set_block_padding_ex - install callback to specify TLS 1.3 record padding

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_record_padding_callback(SSL_CTX *ctx, size_t (*cb)(SSL *s, int type, size_t len, void *arg));
-int SSL_set_record_padding_callback(SSL *ssl, size_t (*cb)(SSL *s, int type, size_t len, void *arg));
-
-void SSL_CTX_set_record_padding_callback_arg(SSL_CTX *ctx, void *arg);
-void *SSL_CTX_get_record_padding_callback_arg(const SSL_CTX *ctx);
-
-void SSL_set_record_padding_callback_arg(SSL *ssl, void *arg);
-void *SSL_get_record_padding_callback_arg(const SSL *ssl);
-
-int SSL_CTX_set_block_padding(SSL_CTX *ctx, size_t block_size);
-int SSL_set_block_padding(SSL *ssl, size_t block_size);
-int SSL_CTX_set_block_padding_ex(SSL_CTX *ctx, size_t app_block_size, size_t hs_block_size);
-int SSL_set_block_padding_ex(SSL *ssl, size_t app_block_size, size_t hs_block_size);
- -

DESCRIPTION

- -

SSL_CTX_set_record_padding_callback() or SSL_set_record_padding_callback() can be used to assign a callback function cb to specify the padding for TLS 1.3 records. The value set in ctx is copied to a new SSL by SSL_new(). Kernel TLS is not possible if the record padding callback is set, and the callback function cannot be set if Kernel TLS is already configured for the current SSL object.

- -

SSL_CTX_set_record_padding_callback_arg() and SSL_set_record_padding_callback_arg() assign a value arg that is passed to the callback when it is invoked. The value set in ctx is copied to a new SSL by SSL_new().

- -

SSL_CTX_get_record_padding_callback_arg() and SSL_get_record_padding_callback_arg() retrieve the arg value that is passed to the callback.

- -

SSL_CTX_set_block_padding() and SSL_set_block_padding() pads the record to a multiple of the block_size. A block_size of 0 or 1 disables block padding. The limit of block_size is SSL3_RT_MAX_PLAIN_LENGTH.

- -

SSL_CTX_set_block_padding_ex() and SSL_set_block_padding_ex() do similarly but allow the caller to separately specify the padding block size to be applied to handshake and application data messages.

- -

The callback is invoked for every record before encryption. The type parameter is the TLS record type that is being processed; may be one of SSL3_RT_APPLICATION_DATA, SSL3_RT_HANDSHAKE, or SSL3_RT_ALERT. The len parameter is the current plaintext length of the record before encryption. The arg parameter is the value set via SSL_CTX_set_record_padding_callback_arg() or SSL_set_record_padding_callback_arg().

- -

These functions cannot be used with QUIC SSL objects. SSL_set_record_padding_callback() and SSL_set_block_padding() fail if called on a QUIC SSL object.

- -

RETURN VALUES

- -

The SSL_CTX_get_record_padding_callback_arg() and SSL_get_record_padding_callback_arg() functions return the arg value assigned in the corresponding set functions.

- -

The SSL_CTX_set_block_padding() and SSL_set_block_padding() functions return 1 on success or 0 if block_size is too large.

- -

The cb returns the number of padding bytes to add to the record. A return of 0 indicates no padding will be added. A return value that causes the record to exceed the maximum record size (SSL3_RT_MAX_PLAIN_LENGTH) will pad out to the maximum record size.

- -

The SSL_CTX_get_record_padding_callback_arg() function returns 1 on success or 0 if the callback function is not set because Kernel TLS is configured for the SSL object.

- -

NOTES

- -

The default behavior is to add no padding to the record.

- -

A user-supplied padding callback function will override the behavior set by SSL_set_block_padding() or SSL_CTX_set_block_padding(). Setting the user-supplied callback to NULL will restore the configured block padding behavior.

- -

These functions only apply to TLS 1.3 records being written.

- -

Padding bytes are not added in constant-time.

- -

SEE ALSO

- -

ssl(7), SSL_new(3)

- -

HISTORY

- -

The record padding API was added for TLS 1.3 support in OpenSSL 1.1.1.

- -

The return type of SSL_CTX_set_record_padding_callback() function was changed to int in OpenSSL 3.0.

- -

The functions SSL_set_block_padding_ex() and SSL_CTX_set_block_padding_ex() were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_security_level.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_security_level.html deleted file mode 100644 index d8bb16ea..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_security_level.html +++ /dev/null @@ -1,170 +0,0 @@ - - - - -SSL_CTX_set_security_level - - - - - - - - - - -

NAME

- -

SSL_CTX_set_security_level, SSL_set_security_level, SSL_CTX_get_security_level, SSL_get_security_level, SSL_CTX_set_security_callback, SSL_set_security_callback, SSL_CTX_get_security_callback, SSL_get_security_callback, SSL_CTX_set0_security_ex_data, SSL_set0_security_ex_data, SSL_CTX_get0_security_ex_data, SSL_get0_security_ex_data - SSL/TLS security framework

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_security_level(SSL_CTX *ctx, int level);
-void SSL_set_security_level(SSL *s, int level);
-
-int SSL_CTX_get_security_level(const SSL_CTX *ctx);
-int SSL_get_security_level(const SSL *s);
-
-void SSL_CTX_set_security_callback(SSL_CTX *ctx,
-                                   int (*cb)(SSL *s, SSL_CTX *ctx, int op,
-                                             int bits, int nid,
-                                             void *other, void *ex));
-
-void SSL_set_security_callback(SSL *s, int (*cb)(SSL *s, SSL_CTX *ctx, int op,
-                                                 int bits, int nid,
-                                                 void *other, void *ex));
-
-int (*SSL_CTX_get_security_callback(const SSL_CTX *ctx))(SSL *s, SSL_CTX *ctx, int op,
-                                                         int bits, int nid, void *other,
-                                                         void *ex);
-int (*SSL_get_security_callback(const SSL *s))(SSL *s, SSL_CTX *ctx, int op,
-                                               int bits, int nid, void *other,
-                                               void *ex);
-
-void SSL_CTX_set0_security_ex_data(SSL_CTX *ctx, void *ex);
-void SSL_set0_security_ex_data(SSL *s, void *ex);
-
-void *SSL_CTX_get0_security_ex_data(const SSL_CTX *ctx);
-void *SSL_get0_security_ex_data(const SSL *s);
- -

DESCRIPTION

- -

The functions SSL_CTX_set_security_level() and SSL_set_security_level() set the security level to level. If not set the library default security level is used.

- -

The functions SSL_CTX_get_security_level() and SSL_get_security_level() retrieve the current security level.

- -

SSL_CTX_set_security_callback(), SSL_set_security_callback(), SSL_CTX_get_security_callback() and SSL_get_security_callback() get or set the security callback associated with ctx or s. If not set a default security callback is used. The meaning of the parameters and the behaviour of the default callbacks is described below.

- -

SSL_CTX_set0_security_ex_data(), SSL_set0_security_ex_data(), SSL_CTX_get0_security_ex_data() and SSL_get0_security_ex_data() set the extra data pointer passed to the ex parameter of the callback. This value is passed to the callback verbatim and can be set to any convenient application specific value.

- -

DEFAULT CALLBACK BEHAVIOUR

- -

If an application doesn't set its own security callback the default callback is used. It is intended to provide sane defaults. The meaning of each level is described below.

- -
- -
Level 0
-
- -

Everything is permitted. This retains compatibility with previous versions of OpenSSL.

- -
-
Level 1
-
- -

The security level corresponds to a minimum of 80 bits of security. Any parameters offering below 80 bits of security are excluded. As a result RSA, DSA and DH keys shorter than 1024 bits and ECC keys shorter than 160 bits are prohibited. Any cipher suite using MD5 for the MAC is also prohibited. Any cipher suites using CCM with a 64 bit authentication tag are prohibited. Note that signatures using SHA1 and MD5 are also forbidden at this level as they have less than 80 security bits. Additionally, SSLv3, TLS 1.0, TLS 1.1 and DTLS 1.0 are all disabled at this level.

- -
-
Level 2
-
- -

Security level set to 112 bits of security. As a result RSA, DSA and DH keys shorter than 2048 bits and ECC keys shorter than 224 bits are prohibited. In addition to the level 1 exclusions any cipher suite using RC4 is also prohibited. Compression is disabled.

- -
-
Level 3
-
- -

Security level set to 128 bits of security. As a result RSA, DSA and DH keys shorter than 3072 bits and ECC keys shorter than 256 bits are prohibited. In addition to the level 2 exclusions cipher suites not offering forward secrecy are prohibited. Session tickets are disabled.

- -
-
Level 4
-
- -

Security level set to 192 bits of security. As a result RSA, DSA and DH keys shorter than 7680 bits and ECC keys shorter than 384 bits are prohibited. Cipher suites using SHA1 for the MAC are prohibited.

- -
-
Level 5
-
- -

Security level set to 256 bits of security. As a result RSA, DSA and DH keys shorter than 15360 bits and ECC keys shorter than 512 bits are prohibited.

- -
-
- -

APPLICATION DEFINED SECURITY CALLBACKS

- -

Documentation to be provided.

- -

NOTES

- -

The default security level can be configured when OpenSSL is compiled by setting -DOPENSSL_TLS_SECURITY_LEVEL=level. If not set then 2 is used.

- -

The security framework disables or reject parameters inconsistent with the set security level. In the past this was difficult as applications had to set a number of distinct parameters (supported ciphers, supported curves supported signature algorithms) to achieve this end and some cases (DH parameter size for example) could not be checked at all.

- -

By setting an appropriate security level much of this complexity can be avoided.

- -

The bits of security limits affect all relevant parameters including cipher suite encryption algorithms, supported ECC curves, supported signature algorithms, DH parameter sizes, certificate key sizes and signature algorithms. This limit applies no matter what other custom settings an application has set: so if the cipher suite is set to ALL then only cipher suites consistent with the security level are permissible.

- -

See SP800-57 for how the security limits are related to individual algorithms.

- -

Some security levels require large key sizes for non-ECC public key algorithms which can severely degrade performance. For example 256 bits of security requires the use of RSA keys of at least 15360 bits in size.

- -

Some restrictions can be gracefully handled: for example cipher suites offering insufficient security are not sent by the client and will not be selected by the server. Other restrictions such as the peer certificate key size or the DH parameter size will abort the handshake with a fatal alert.

- -

Attempts to set certificates or parameters with insufficient security are also blocked. For example trying to set a certificate using a 512 bit RSA key or a certificate with a signature with SHA1 digest at level 1 using SSL_CTX_use_certificate(). Applications which do not check the return values for errors will misbehave: for example it might appear that a certificate is not set at all because it had been rejected.

- -

RETURN VALUES

- -

SSL_CTX_set_security_level() and SSL_set_security_level() do not return values.

- -

SSL_CTX_get_security_level() and SSL_get_security_level() return a integer that represents the security level with SSL_CTX or SSL, respectively.

- -

SSL_CTX_set_security_callback() and SSL_set_security_callback() do not return values.

- -

SSL_CTX_get_security_callback() and SSL_get_security_callback() return the pointer to the security callback or NULL if the callback is not set.

- -

SSL_CTX_get0_security_ex_data() and SSL_get0_security_ex_data() return the extra data pointer or NULL if the ex data is not set.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2014-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_cache_mode.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_cache_mode.html deleted file mode 100644 index 0218ca2f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_cache_mode.html +++ /dev/null @@ -1,134 +0,0 @@ - - - - -SSL_CTX_set_session_cache_mode - - - - - - - - - - -

NAME

- -

SSL_CTX_set_session_cache_mode, SSL_CTX_get_session_cache_mode - enable/disable session caching

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_session_cache_mode(SSL_CTX ctx, long mode);
-long SSL_CTX_get_session_cache_mode(SSL_CTX ctx);
- -

DESCRIPTION

- -

SSL_CTX_set_session_cache_mode() enables/disables session caching by setting the operational mode for ctx to <mode>.

- -

SSL_CTX_get_session_cache_mode() returns the currently used cache mode.

- -

NOTES

- -

The OpenSSL library can store/retrieve SSL/TLS sessions for later reuse. The sessions can be held in memory for each ctx, if more than one SSL_CTX object is being maintained, the sessions are unique for each SSL_CTX object.

- -

In order to reuse a session, a client must send the session's id to the server. It can only send exactly one id. The server then either agrees to reuse the session or it starts a full handshake (to create a new session).

- -

A server will look up the session in its internal session storage. If the session is not found in internal storage or lookups for the internal storage have been deactivated (SSL_SESS_CACHE_NO_INTERNAL_LOOKUP), the server will try the external storage if available.

- -

Since a client may try to reuse a session intended for use in a different context, the session id context must be set by the server (see SSL_CTX_set_session_id_context(3)).

- -

The following session cache modes and modifiers are available:

- -
- -
SSL_SESS_CACHE_OFF
-
- -

No session caching for client or server takes place.

- -
-
SSL_SESS_CACHE_CLIENT
-
- -

Client sessions are added to the session cache. As there is no reliable way for the OpenSSL library to know whether a session should be reused or which session to choose (due to the abstract BIO layer the SSL engine does not have details about the connection), the application must select the session to be reused by using the SSL_set_session(3) function. This option is not activated by default.

- -
-
SSL_SESS_CACHE_SERVER
-
- -

Server sessions are added to the session cache. When a client proposes a session to be reused, the server looks for the corresponding session in (first) the internal session cache (unless SSL_SESS_CACHE_NO_INTERNAL_LOOKUP is set), then (second) in the external cache if available. If the session is found, the server will try to reuse the session. This is the default.

- -
-
SSL_SESS_CACHE_BOTH
-
- -

Enable both SSL_SESS_CACHE_CLIENT and SSL_SESS_CACHE_SERVER at the same time.

- -
-
SSL_SESS_CACHE_NO_AUTO_CLEAR
-
- -

Normally the session cache is checked for expired sessions every 255 connections using the SSL_CTX_flush_sessions(3) function. Since this may lead to a delay which cannot be controlled, the automatic flushing may be disabled and SSL_CTX_flush_sessions(3) can be called explicitly by the application.

- -
-
SSL_SESS_CACHE_NO_INTERNAL_LOOKUP
-
- -

By setting this flag, session-resume operations in an SSL/TLS server will not automatically look up sessions in the internal cache, even if sessions are automatically stored there. If external session caching callbacks are in use, this flag guarantees that all lookups are directed to the external cache. As automatic lookup only applies for SSL/TLS servers, the flag has no effect on clients.

- -
-
SSL_SESS_CACHE_NO_INTERNAL_STORE
-
- -

Depending on the presence of SSL_SESS_CACHE_CLIENT and/or SSL_SESS_CACHE_SERVER, sessions negotiated in an SSL/TLS handshake may be cached for possible reuse. Normally a new session is added to the internal cache as well as any external session caching (callback) that is configured for the SSL_CTX. This flag will prevent sessions being stored in the internal cache (though the application can add them manually using SSL_CTX_add_session(3)). Note: in any SSL/TLS servers where external caching is configured, any successful session lookups in the external cache (i.e. for session-resume requests) would normally be copied into the local cache before processing continues - this flag prevents these additions to the internal cache as well.

- -
-
SSL_SESS_CACHE_NO_INTERNAL
-
- -

Enable both SSL_SESS_CACHE_NO_INTERNAL_LOOKUP and SSL_SESS_CACHE_NO_INTERNAL_STORE at the same time.

- -
-
SSL_SESS_CACHE_UPDATE_TIME
-
- -

Updates the timestamp of the session when it is used, increasing the lifespan of the session. The session timeout applies to last use, rather then creation time.

- -
-
- -

The default mode is SSL_SESS_CACHE_SERVER.

- -

RETURN VALUES

- -

SSL_CTX_set_session_cache_mode() returns the previously set cache mode.

- -

SSL_CTX_get_session_cache_mode() returns the currently set cache mode.

- -

SEE ALSO

- -

ssl(7), SSL_set_session(3), SSL_session_reused(3), SSL_CTX_add_session(3), SSL_CTX_sess_number(3), SSL_CTX_sess_set_cache_size(3), SSL_CTX_sess_set_get_cb(3), SSL_CTX_set_session_id_context(3), SSL_CTX_set_timeout(3), SSL_CTX_flush_sessions(3)

- -

COPYRIGHT

- -

Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_id_context.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_id_context.html deleted file mode 100644 index d350333f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_id_context.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -SSL_CTX_set_session_id_context - - - - - - - - - - -

NAME

- -

SSL_CTX_set_session_id_context, SSL_set_session_id_context - set context within which session can be reused (server side only)

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set_session_id_context(SSL_CTX *ctx, const unsigned char *sid_ctx,
-                                   unsigned int sid_ctx_len);
-int SSL_set_session_id_context(SSL *ssl, const unsigned char *sid_ctx,
-                               unsigned int sid_ctx_len);
- -

DESCRIPTION

- -

SSL_CTX_set_session_id_context() sets the context sid_ctx of length sid_ctx_len within which a session can be reused for the ctx object.

- -

SSL_set_session_id_context() sets the context sid_ctx of length sid_ctx_len within which a session can be reused for the ssl object.

- -

NOTES

- -

Sessions are generated within a certain context. When exporting/importing sessions with i2d_SSL_SESSION/d2i_SSL_SESSION it would be possible, to re-import a session generated from another context (e.g. another application), which might lead to malfunctions. Therefore, each application must set its own session id context sid_ctx which is used to distinguish the contexts and is stored in exported sessions. The sid_ctx can be any kind of binary data with a given length, it is therefore possible to use e.g. the name of the application and/or the hostname and/or service name ...

- -

The session id context becomes part of the session. The session id context is set by the SSL/TLS server. The SSL_CTX_set_session_id_context() and SSL_set_session_id_context() functions are therefore only useful on the server side.

- -

OpenSSL clients will check the session id context returned by the server when reusing a session.

- -

The maximum length of the sid_ctx is limited to SSL_MAX_SID_CTX_LENGTH.

- -

WARNINGS

- -

If the session id context is not set on an SSL/TLS server and client certificates are used, stored sessions will not be reused but a fatal error will be flagged and the handshake will fail.

- -

If a server returns a different session id context to an OpenSSL client when reusing a session, an error will be flagged and the handshake will fail. OpenSSL servers will always return the correct session id context, as an OpenSSL server checks the session id context itself before reusing a session as described above.

- -

RETURN VALUES

- -

SSL_CTX_set_session_id_context() and SSL_set_session_id_context() return the following values:

- -
- -
0
-
- -

The length sid_ctx_len of the session id context sid_ctx exceeded the maximum allowed length of SSL_MAX_SID_CTX_LENGTH. The error is logged to the error stack.

- -
-
1
-
- -

The operation succeeded.

- -
-
- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_ticket_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_ticket_cb.html deleted file mode 100644 index 1e9ec80f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_session_ticket_cb.html +++ /dev/null @@ -1,169 +0,0 @@ - - - - -SSL_CTX_set_session_ticket_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_session_ticket_cb, SSL_SESSION_get0_ticket_appdata, SSL_SESSION_set1_ticket_appdata, SSL_CTX_generate_session_ticket_fn, SSL_CTX_decrypt_session_ticket_fn - manage session ticket application data

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*SSL_CTX_generate_session_ticket_fn)(SSL *s, void *arg);
-typedef SSL_TICKET_RETURN (*SSL_CTX_decrypt_session_ticket_fn)(SSL *s, SSL_SESSION *ss,
-                                                               const unsigned char *keyname,
-                                                               size_t keyname_len,
-                                                               SSL_TICKET_STATUS status,
-                                                               void *arg);
-int SSL_CTX_set_session_ticket_cb(SSL_CTX *ctx,
-                                  SSL_CTX_generate_session_ticket_fn gen_cb,
-                                  SSL_CTX_decrypt_session_ticket_fn dec_cb,
-                                  void *arg);
-int SSL_SESSION_set1_ticket_appdata(SSL_SESSION *ss, const void *data, size_t len);
-int SSL_SESSION_get0_ticket_appdata(SSL_SESSION *ss, void **data, size_t *len);
- -

DESCRIPTION

- -

SSL_CTX_set_set_session_ticket_cb() sets the application callbacks gen_cb and dec_cb that are used by a server to set and get application data stored with a session, and placed into a session ticket. Either callback function may be set to NULL. The value of arg is passed to the callbacks.

- -

gen_cb is the application defined callback invoked when a session ticket is about to be created. The application can call SSL_SESSION_set1_ticket_appdata() at this time to add application data to the session ticket. The value of arg is the same as that given to SSL_CTX_set_session_ticket_cb(). The gen_cb callback is defined as type SSL_CTX_generate_session_ticket_fn.

- -

dec_cb is the application defined callback invoked after session ticket decryption has been attempted and any session ticket application data is available. If ticket decryption was successful then the ss argument contains the session data. The keyname and keyname_len arguments identify the key used to decrypt the session ticket. The status argument is the result of the ticket decryption. See the "NOTES" section below for further details. The value of arg is the same as that given to SSL_CTX_set_session_ticket_cb(). The dec_cb callback is defined as type SSL_CTX_decrypt_session_ticket_fn.

- -

SSL_SESSION_set1_ticket_appdata() sets the application data specified by data and len into ss which is then placed into any generated session tickets. It can be called at any time before a session ticket is created to update the data placed into the session ticket. However, given that sessions and tickets are created by the handshake, the gen_cb is provided to notify the application that a session ticket is about to be generated.

- -

SSL_SESSION_get0_ticket_appdata() assigns data to the session ticket application data and assigns len to the length of the session ticket application data from ss. The application data can be set via SSL_SESSION_set1_ticket_appdata() or by a session ticket. NULL will be assigned to data and 0 will be assigned to len if there is no session ticket application data. SSL_SESSION_get0_ticket_appdata() can be called any time after a session has been created. The dec_cb is provided to notify the application that a session ticket has just been decrypted.

- -

NOTES

- -

When the dec_cb callback is invoked, the SSL_SESSION ss has not yet been assigned to the SSL s. The status indicates the result of the ticket decryption. The callback must check the status value before performing any action, as it is called even if ticket decryption fails.

- -

The keyname and keyname_len arguments to dec_cb may be used to identify the key that was used to encrypt the session ticket.

- -

The status argument can be any of these values:

- -
- -
SSL_TICKET_EMPTY
-
- -

Empty ticket present. No ticket data will be used and a new ticket should be sent to the client. This only occurs in TLSv1.2 or below. In TLSv1.3 it is not valid for a client to send an empty ticket.

- -
-
SSL_TICKET_NO_DECRYPT
-
- -

The ticket couldn't be decrypted. No ticket data will be used and a new ticket should be sent to the client.

- -
-
SSL_TICKET_SUCCESS
-
- -

A ticket was successfully decrypted, any session ticket application data should be available. A new ticket should not be sent to the client.

- -
-
SSL_TICKET_SUCCESS_RENEW
-
- -

Same as SSL_TICKET_SUCCESS, but a new ticket should be sent to the client.

- -
-
- -

The return value can be any of these values:

- -
- -
SSL_TICKET_RETURN_ABORT
-
- -

The handshake should be aborted, either because of an error or because of some policy. Note that in TLSv1.3 a client may send more than one ticket in a single handshake. Therefore, just because one ticket is unacceptable it does not mean that all of them are. For this reason this option should be used with caution.

- -
-
SSL_TICKET_RETURN_IGNORE
-
- -

Do not use a ticket (if one was available). Do not send a renewed ticket to the client.

- -
-
SSL_TICKET_RETURN_IGNORE_RENEW
-
- -

Do not use a ticket (if one was available). Send a renewed ticket to the client.

- -

If the callback does not wish to change the default ticket behaviour then it should return this value if status is SSL_TICKET_EMPTY or SSL_TICKET_NO_DECRYPT.

- -
-
SSL_TICKET_RETURN_USE
-
- -

Use the ticket. Do not send a renewed ticket to the client. It is an error for the callback to return this value if status has a value other than SSL_TICKET_SUCCESS or SSL_TICKET_SUCCESS_RENEW.

- -

If the callback does not wish to change the default ticket behaviour then it should return this value if status is SSL_TICKET_SUCCESS.

- -
-
SSL_TICKET_RETURN_USE_RENEW
-
- -

Use the ticket. Send a renewed ticket to the client. It is an error for the callback to return this value if status has a value other than SSL_TICKET_SUCCESS or SSL_TICKET_SUCCESS_RENEW.

- -

If the callback does not wish to change the default ticket behaviour then it should return this value if status is SSL_TICKET_SUCCESS_RENEW.

- -
-
- -

If status has the value SSL_TICKET_EMPTY or SSL_TICKET_NO_DECRYPT then no session data will be available and the callback must not use the ss argument. If status has the value SSL_TICKET_SUCCESS or SSL_TICKET_SUCCESS_RENEW then the application can call SSL_SESSION_get0_ticket_appdata() using the session provided in the ss argument to retrieve the application data.

- -

When the gen_cb callback is invoked, the SSL_get_session() function can be used to retrieve the SSL_SESSION for SSL_SESSION_set1_ticket_appdata().

- -

By default, in TLSv1.2 and below, a new session ticket is not issued on a successful resumption and therefore gen_cb will not be called. In TLSv1.3 the default behaviour is to always issue a new ticket on resumption. In both cases this behaviour can be changed if a ticket key callback is in use (see SSL_CTX_set_tlsext_ticket_key_cb(3)).

- -

RETURN VALUES

- -

The SSL_CTX_set_session_ticket_cb(), SSL_SESSION_set1_ticket_appdata() and SSL_SESSION_get0_ticket_appdata() functions return 1 on success and 0 on failure.

- -

The gen_cb callback must return 1 to continue the connection. A return of 0 will terminate the connection with an INTERNAL_ERROR alert.

- -

The dec_cb callback must return a value as described in "NOTES" above.

- -

SEE ALSO

- -

ssl(7), SSL_get_session(3)

- -

HISTORY

- -

The SSL_CTX_set_session_ticket_cb(), SSL_SESSION_set1_ticket_appdata() and SSL_SESSION_get_ticket_appdata() functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_split_send_fragment.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_split_send_fragment.html deleted file mode 100644 index 1bf6196c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_split_send_fragment.html +++ /dev/null @@ -1,152 +0,0 @@ - - - - -SSL_CTX_set_split_send_fragment - - - - - - - - - - -

NAME

- -

SSL_CTX_set_max_send_fragment, SSL_set_max_send_fragment, SSL_CTX_set_split_send_fragment, SSL_set_split_send_fragment, SSL_CTX_set_max_pipelines, SSL_set_max_pipelines, SSL_CTX_set_default_read_buffer_len, SSL_set_default_read_buffer_len, SSL_CTX_set_tlsext_max_fragment_length, SSL_set_tlsext_max_fragment_length, SSL_SESSION_get_max_fragment_length - Control fragment size settings and pipelining operations

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_max_send_fragment(SSL_CTX *ctx, long);
-long SSL_set_max_send_fragment(SSL *ssl, long m);
-
-long SSL_CTX_set_max_pipelines(SSL_CTX *ctx, long m);
-long SSL_set_max_pipelines(SSL_CTX *ssl, long m);
-
-long SSL_CTX_set_split_send_fragment(SSL_CTX *ctx, long m);
-long SSL_set_split_send_fragment(SSL *ssl, long m);
-
-void SSL_CTX_set_default_read_buffer_len(SSL_CTX *ctx, size_t len);
-void SSL_set_default_read_buffer_len(SSL *s, size_t len);
-
-int SSL_CTX_set_tlsext_max_fragment_length(SSL_CTX *ctx, uint8_t mode);
-int SSL_set_tlsext_max_fragment_length(SSL *ssl, uint8_t mode);
-uint8_t SSL_SESSION_get_max_fragment_length(const SSL_SESSION *session);
- -

DESCRIPTION

- -

Some engines are able to process multiple simultaneous crypto operations. This capability could be utilised to parallelise the processing of a single connection. For example a single write can be split into multiple records and each one encrypted independently and in parallel. Note: this will only work in TLS1.1+. There is no support in SSLv3, TLSv1.0 or DTLS (any version). This capability is known as "pipelining" within OpenSSL.

- -

In order to benefit from the pipelining capability. You need to have an engine that provides ciphers that support this. The OpenSSL "dasync" engine provides AES128-SHA based ciphers that have this capability. However, these are for development and test purposes only.

- -

SSL_CTX_set_max_send_fragment() and SSL_set_max_send_fragment() set the max_send_fragment parameter for SSL_CTX and SSL objects respectively. This value restricts the amount of plaintext bytes that will be sent in any one SSL/TLS record. By default its value is SSL3_RT_MAX_PLAIN_LENGTH (16384). These functions will only accept a value in the range 512 - SSL3_RT_MAX_PLAIN_LENGTH.

- -

SSL_CTX_set_max_pipelines() and SSL_set_max_pipelines() set the maximum number of pipelines that will be used at any one time. This value applies to both "read" pipelining and "write" pipelining. By default only one pipeline will be used (i.e. normal non-parallel operation). The number of pipelines set must be in the range 1 - SSL_MAX_PIPELINES (32). Setting this to a value > 1 will also automatically turn on "read_ahead" (see SSL_CTX_set_read_ahead(3)). This is explained further below. OpenSSL will only ever use more than one pipeline if a cipher suite is negotiated that uses a pipeline capable cipher provided by an engine.

- -

Pipelining operates slightly differently for reading encrypted data compared to writing encrypted data. SSL_CTX_set_split_send_fragment() and SSL_set_split_send_fragment() define how data is split up into pipelines when writing encrypted data. The number of pipelines used will be determined by the amount of data provided to the SSL_write_ex() or SSL_write() call divided by split_send_fragment.

- -

For example if split_send_fragment is set to 2000 and max_pipelines is 4 then:

- -

SSL_write/SSL_write_ex called with 0-2000 bytes == 1 pipeline used

- -

SSL_write/SSL_write_ex called with 2001-4000 bytes == 2 pipelines used

- -

SSL_write/SSL_write_ex called with 4001-6000 bytes == 3 pipelines used

- -

SSL_write/SSL_write_ex called with 6001+ bytes == 4 pipelines used

- -

split_send_fragment must always be less than or equal to max_send_fragment. By default it is set to be equal to max_send_fragment. This will mean that the same number of records will always be created as would have been created in the non-parallel case, although the data will be apportioned differently. In the parallel case data will be spread equally between the pipelines.

- -

Read pipelining is controlled in a slightly different way than with write pipelining. While reading we are constrained by the number of records that the peer (and the network) can provide to us in one go. The more records we can get in one go the more opportunity we have to parallelise the processing. As noted above when setting max_pipelines to a value greater than one, read_ahead is automatically set. The read_ahead parameter causes OpenSSL to attempt to read as much data into the read buffer as the network can provide and will fit into the buffer. Without this set data is read into the read buffer one record at a time. The more data that can be read, the more opportunity there is for parallelising the processing at the cost of increased memory overhead per connection. Setting read_ahead can impact the behaviour of the SSL_pending() function (see SSL_pending(3)). In addition the default size of the internal read buffer is multiplied by the number of pipelines available to ensure that we can read multiple records in one go. This can therefore have a significant impact on memory usage.

- -

The SSL_CTX_set_default_read_buffer_len() and SSL_set_default_read_buffer_len() functions control the size of the read buffer that will be used. The len parameter sets the size of the buffer. The value will only be used if it is greater than the default that would have been used anyway. The normal default value depends on a number of factors but it will be at least SSL3_RT_MAX_PLAIN_LENGTH + SSL3_RT_MAX_ENCRYPTED_OVERHEAD (16704) bytes.

- -

SSL_CTX_set_tlsext_max_fragment_length() sets the default maximum fragment length negotiation mode via value mode to ctx. This setting affects only SSL instances created after this function is called. It affects the client-side as only its side may initiate this extension use.

- -

SSL_set_tlsext_max_fragment_length() sets the maximum fragment length negotiation mode via value mode to ssl. This setting will be used during a handshake when extensions are exchanged between client and server. So it only affects SSL sessions created after this function is called. It affects the client-side as only its side may initiate this extension use.

- -

SSL_SESSION_get_max_fragment_length() gets the maximum fragment length negotiated in session.

- -

These functions cannot be used with QUIC SSL objects. SSL_set_max_send_fragment(), SSL_set_max_pipelines(), SSL_set_split_send_fragment(), SSL_set_default_read_buffer_len() and SSL_set_tlsext_max_fragment_length() fail if called on a QUIC SSL object.

- -

RETURN VALUES

- -

All non-void functions return 1 on success and 0 on failure.

- -

NOTES

- -

The Maximum Fragment Length extension support is optional on the server side. If the server does not support this extension then SSL_SESSION_get_max_fragment_length() will return: TLSEXT_max_fragment_length_DISABLED.

- -

The following modes are available:

- -
- -
TLSEXT_max_fragment_length_DISABLED
-
- -

Disables Maximum Fragment Length Negotiation (default).

- -
-
TLSEXT_max_fragment_length_512
-
- -

Sets Maximum Fragment Length to 512 bytes.

- -
-
TLSEXT_max_fragment_length_1024
-
- -

Sets Maximum Fragment Length to 1024.

- -
-
TLSEXT_max_fragment_length_2048
-
- -

Sets Maximum Fragment Length to 2048.

- -
-
TLSEXT_max_fragment_length_4096
-
- -

Sets Maximum Fragment Length to 4096.

- -
-
- -

With the exception of SSL_CTX_set_default_read_buffer_len() SSL_set_default_read_buffer_len(), SSL_CTX_set_tlsext_max_fragment_length(), SSL_set_tlsext_max_fragment_length() and SSL_SESSION_get_max_fragment_length() all these functions are implemented using macros.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_read_ahead(3), SSL_pending(3)

- -

HISTORY

- -

The SSL_CTX_set_max_pipelines(), SSL_set_max_pipelines(), SSL_CTX_set_split_send_fragment(), SSL_set_split_send_fragment(), SSL_CTX_set_default_read_buffer_len() and SSL_set_default_read_buffer_len() functions were added in OpenSSL 1.1.0.

- -

The SSL_CTX_set_tlsext_max_fragment_length(), SSL_set_tlsext_max_fragment_length() and SSL_SESSION_get_max_fragment_length() functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_srp_password.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_srp_password.html deleted file mode 100644 index 6c0ab943..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_srp_password.html +++ /dev/null @@ -1,177 +0,0 @@ - - - - -SSL_CTX_set_srp_password - - - - - - - - - - -

NAME

- -

SSL_CTX_set_srp_username, SSL_CTX_set_srp_password, SSL_CTX_set_srp_strength, SSL_CTX_set_srp_cb_arg, SSL_CTX_set_srp_username_callback, SSL_CTX_set_srp_client_pwd_callback, SSL_CTX_set_srp_verify_param_callback, SSL_set_srp_server_param, SSL_set_srp_server_param_pw, SSL_get_srp_g, SSL_get_srp_N, SSL_get_srp_username, SSL_get_srp_userinfo - SRP control operations

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int SSL_CTX_set_srp_username(SSL_CTX *ctx, char *name);
-int SSL_CTX_set_srp_password(SSL_CTX *ctx, char *password);
-int SSL_CTX_set_srp_strength(SSL_CTX *ctx, int strength);
-int SSL_CTX_set_srp_cb_arg(SSL_CTX *ctx, void *arg);
-int SSL_CTX_set_srp_username_callback(SSL_CTX *ctx,
-                                      int (*cb) (SSL *s, int *ad, void *arg));
-int SSL_CTX_set_srp_client_pwd_callback(SSL_CTX *ctx,
-                                        char *(*cb) (SSL *s, void *arg));
-int SSL_CTX_set_srp_verify_param_callback(SSL_CTX *ctx,
-                                          int (*cb) (SSL *s, void *arg));
-
-int SSL_set_srp_server_param(SSL *s, const BIGNUM *N, const BIGNUM *g,
-                             BIGNUM *sa, BIGNUM *v, char *info);
-int SSL_set_srp_server_param_pw(SSL *s, const char *user, const char *pass,
-                                const char *grp);
-
-BIGNUM *SSL_get_srp_g(SSL *s);
-BIGNUM *SSL_get_srp_N(SSL *s);
-
-char *SSL_get_srp_username(SSL *s);
-char *SSL_get_srp_userinfo(SSL *s);
- -

DESCRIPTION

- -

All of the functions described on this page are deprecated. There are no available replacement functions at this time.

- -

These functions provide access to SRP (Secure Remote Password) parameters, an alternate authentication mechanism for TLS. SRP allows the use of usernames and passwords over unencrypted channels without revealing the password to an eavesdropper. SRP also supplies a shared secret at the end of the authentication sequence that can be used to generate encryption keys.

- -

The SRP protocol, version 3 is specified in RFC 2945. SRP version 6 is described in RFC 5054 with applications to TLS authentication.

- -

The SSL_CTX_set_srp_username() function sets the SRP username for ctx. This should be called on the client prior to creating a connection to the server. The length of name must be shorter or equal to 255 characters.

- -

The SSL_CTX_set_srp_password() function sets the SRP password for ctx. This may be called on the client prior to creating a connection to the server. This overrides the effect of SSL_CTX_set_srp_client_pwd_callback().

- -

The SSL_CTX_set_srp_strength() function sets the SRP strength for ctx. This is the minimal length of the SRP prime in bits. If not specified 1024 is used. If not satisfied by the server key exchange the connection will be rejected.

- -

The SSL_CTX_set_srp_cb_arg() function sets an extra parameter that will be passed to all following callbacks as arg.

- -

The SSL_CTX_set_srp_username_callback() function sets the server side callback that is invoked when an SRP username is found in a ClientHello. The callback parameters are the SSL connection s, a writable error flag ad and the extra argument arg set by SSL_CTX_set_srp_cb_arg(). This callback should setup the server for the key exchange by calling SSL_set_srp_server_param() with the appropriate parameters for the received username. The username can be obtained by calling SSL_get_srp_username(). See SRP_VBASE_init(3) to parse the verifier file created by openssl-srp(1) or SRP_create_verifier(3) to generate it. The callback should return SSL_ERROR_NONE to proceed with the server key exchange, SSL3_AL_FATAL for a fatal error or any value < 0 for a retryable error. In the event of a SSL3_AL_FATAL the alert flag given by *al will be sent back. By default this will be SSL_AD_UNKNOWN_PSK_IDENTITY.

- -

The SSL_CTX_set_srp_client_pwd_callback() function sets the client password callback on the client. The callback parameters are the SSL connection s and the extra argument arg set by SSL_CTX_set_srp_cb_arg(). The callback will be called as part of the generation of the client secrets. It should return the client password in text form or NULL to abort the connection. The resulting memory will be freed by the library as part of the callback resolution. This overrides the effect of SSL_CTX_set_srp_password().

- -

The SSL_CTX_set_srp_verify_param_callback() sets the SRP gN parameter verification callback on the client. This allows the client to perform custom verification when receiving the server SRP proposed parameters. The callback parameters are the SSL connection s and the extra argument arg set by SSL_CTX_set_srp_cb_arg(). The callback should return a positive value to accept the server parameters. Returning 0 or a negative value will abort the connection. The server parameters can be obtained by calling SSL_get_srp_N() and SSL_get_srp_g(). Sanity checks are already performed by the library after the handshake (B % N non zero, check against the strength parameter) and are not necessary. If no callback is set the g and N parameters will be checked against known RFC 5054 values.

- -

The SSL_set_srp_server_param() function sets all SRP parameters for the connection s. N and g are the SRP group parameters, sa is the user salt, v the password verifier and info is the optional user info.

- -

The SSL_set_srp_server_param_pw() function sets all SRP parameters for the connection s by generating a random salt and a password verifier. user is the username, pass the password and grp the SRP group parameters identifier for SRP_get_default_gN(3).

- -

The SSL_get_srp_g() function returns the SRP group generator for s, or from the underlying SSL_CTX if it is NULL.

- -

The SSL_get_srp_N() function returns the SRP prime for s, or from the underlying SSL_CTX if it is NULL.

- -

The SSL_get_srp_username() function returns the SRP username for s, or from the underlying SSL_CTX if it is NULL.

- -

The SSL_get_srp_userinfo() function returns the SRP user info for s, or from the underlying SSL_CTX if it is NULL.

- -

RETURN VALUES

- -

All SSL_CTX_set_* functions return 1 on success and 0 on failure.

- -

SSL_set_srp_server_param() returns 1 on success and -1 on failure.

- -

The SSL_get_SRP_* functions return a pointer to the requested data, the memory is owned by the library and should not be freed by the caller.

- -

EXAMPLES

- -

Setup SRP parameters on the client:

- -
#include <openssl/ssl.h>
-
-const char *username = "username";
-const char *password = "password";
-
-SSL_CTX *ctx = SSL_CTX_new(TLS_client_method());
-if (!ctx)
-    /* Error */
-if (!SSL_CTX_set_srp_username(ctx, username))
-    /* Error */
-if (!SSL_CTX_set_srp_password(ctx, password))
-    /* Error */
- -

Setup SRP server with verifier file:

- -
#include <openssl/srp.h>
-#include <openssl/ssl.h>
-
-const char *srpvfile = "password.srpv";
-
-int srpServerCallback(SSL *s, int *ad, void *arg)
-{
-    SRP_VBASE *srpData = (SRP_VBASE*) arg;
-    char *username = SSL_get_srp_username(s);
-
-    SRP_user_pwd *user_pwd = SRP_VBASE_get1_by_user(srpData, username);
-    if (!user_pwd)
-        /* Error */
-        return SSL3_AL_FATAL;
-
-    if (SSL_set_srp_server_param(s, user_pwd->N, user_pwd->g,
-        user_pwd->s, user_pwd->v, user_pwd->info) < 0)
-        /* Error */
-
-    SRP_user_pwd_free(user_pwd);
-    return SSL_ERROR_NONE;
-}
-
-SSL_CTX *ctx = SSL_CTX_new(TLS_server_method());
-if (!ctx)
-    /* Error */
-
-/*
- * seedKey should contain a NUL terminated sequence
- * of random non NUL bytes
- */
-const char *seedKey;
-
-SRP_VBASE *srpData = SRP_VBASE_new(seedKey);
-if (SRP_VBASE_init(srpData, (char*) srpvfile) != SRP_NO_ERROR)
-   /* Error */
-
-SSL_CTX_set_srp_cb_arg(ctx, srpData);
-SSL_CTX_set_srp_username_callback(ctx, srpServerCallback);
- -

SEE ALSO

- -

ssl(7), openssl-srp(1), SRP_VBASE_new(3), SRP_create_verifier(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.1 and deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ssl_version.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ssl_version.html deleted file mode 100644 index 505acf82..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_ssl_version.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -SSL_CTX_set_ssl_version - - - - - - - - - - -

NAME

- -

SSL_CTX_set_ssl_version, SSL_CTX_get_ssl_method, SSL_set_ssl_method, SSL_get_ssl_method - choose a new TLS/SSL method

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set_ssl_version(SSL_CTX *ctx, const SSL_METHOD *method);
-const SSL_METHOD *SSL_CTX_get_ssl_method(const SSL_CTX *ctx);
-
-int SSL_set_ssl_method(SSL *s, const SSL_METHOD *method);
-const SSL_METHOD *SSL_get_ssl_method(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_CTX_set_ssl_version() sets a new default TLS/SSL method for SSL objects newly created from this ctx. Most of the configuration attached to the SSL_CTX object is retained, with the exception of the configured TLS ciphers, which are reset to the default values. SSL objects already created from this SSL_CTX with SSL_new(3) are not affected, except when SSL_clear(3) is being called, as described below.

- -

SSL_CTX_get_ssl_method() returns the SSL_METHOD which was used to construct the SSL_CTX.

- -

SSL_set_ssl_method() sets a new TLS/SSL method for a particular ssl object. It may be reset, when SSL_clear() is called.

- -

SSL_get_ssl_method() returns a pointer to the TLS/SSL method set in ssl.

- -

NOTES

- -

The available method choices are described in SSL_CTX_new(3).

- -

When SSL_clear(3) is called and no session is connected to an SSL object, the method of the SSL object is reset to the method currently set in the corresponding SSL_CTX object.

- -

SSL_CTX_set_version() has unusual semantics and no clear use case; it would usually be preferable to create a new SSL_CTX object than to try to reuse an existing one in this fashion. Its usage is considered deprecated.

- -

SSL_set_ssl_method() cannot be used to change a non-QUIC SSL object to a QUIC SSL object or vice versa, or change a QUIC SSL object from one QUIC method to another.

- -

RETURN VALUES

- -

The following return values can occur for SSL_CTX_set_ssl_version() and SSL_set_ssl_method():

- -
- -
0
-
- -

The new choice failed, check the error stack to find out the reason.

- -
-
1
-
- -

The operation succeeded.

- -
-
- -

SSL_CTX_get_ssl_method() and SSL_get_ssl_method() always return non-NULL pointers.

- -

SEE ALSO

- -

SSL_CTX_new(3), SSL_new(3), SSL_clear(3), ssl(7), SSL_set_connect_state(3)

- -

HISTORY

- -

SSL_CTX_set_ssl_version() was deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_stateless_cookie_generate_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_stateless_cookie_generate_cb.html deleted file mode 100644 index 61118eb7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_stateless_cookie_generate_cb.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -SSL_CTX_set_stateless_cookie_generate_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_stateless_cookie_generate_cb, SSL_CTX_set_stateless_cookie_verify_cb, SSL_CTX_set_cookie_generate_cb, SSL_CTX_set_cookie_verify_cb - Callback functions for stateless TLS1.3 cookies

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_CTX_set_stateless_cookie_generate_cb(
-    SSL_CTX *ctx,
-    int (*gen_stateless_cookie_cb) (SSL *ssl,
-                                    unsigned char *cookie,
-                                    size_t *cookie_len));
-void SSL_CTX_set_stateless_cookie_verify_cb(
-    SSL_CTX *ctx,
-    int (*verify_stateless_cookie_cb) (SSL *ssl,
-                                       const unsigned char *cookie,
-                                       size_t cookie_len));
-
-void SSL_CTX_set_cookie_generate_cb(SSL_CTX *ctx,
-                                    int (*app_gen_cookie_cb) (SSL *ssl,
-                                                              unsigned char
-                                                              *cookie,
-                                                              unsigned int
-                                                              *cookie_len));
-void SSL_CTX_set_cookie_verify_cb(SSL_CTX *ctx,
-                                  int (*app_verify_cookie_cb) (SSL *ssl,
-                                                               const unsigned
-                                                               char *cookie,
-                                                               unsigned int
-                                                               cookie_len));
- -

DESCRIPTION

- -

SSL_CTX_set_stateless_cookie_generate_cb() sets the callback used by SSL_stateless(3) to generate the application-controlled portion of the cookie provided to clients in the HelloRetryRequest transmitted as a response to a ClientHello with a missing or invalid cookie. gen_stateless_cookie_cb() must write at most SSL_COOKIE_LENGTH bytes into cookie, and must write the number of bytes written to cookie_len. If a cookie cannot be generated, a zero return value can be used to abort the handshake.

- -

SSL_CTX_set_stateless_cookie_verify_cb() sets the callback used by SSL_stateless(3) to determine whether the application-controlled portion of a ClientHello cookie is valid. The cookie data is pointed to by cookie and is of length cookie_len. A nonzero return value from verify_stateless_cookie_cb() communicates that the cookie is valid. The integrity of the entire cookie, including the application-controlled portion, is automatically verified by HMAC before verify_stateless_cookie_cb() is called.

- -

SSL_CTX_set_cookie_generate_cb() sets the callback used by DTLSv1_listen(3) to generate the cookie provided to clients in the HelloVerifyRequest transmitted as a response to a ClientHello with a missing or invalid cookie. app_gen_cookie_cb() must write at most DTLS1_COOKIE_LENGTH bytes into cookie, and must write the number of bytes written to cookie_len. If a cookie cannot be generated, a zero return value can be used to abort the handshake.

- -

SSL_CTX_set_cookie_verify_cb() sets the callback used by DTLSv1_listen(3) to determine whether the cookie in a ClientHello is valid. The cookie data is pointed to by cookie and is of length cookie_len. A nonzero return value from app_verify_cookie_cb() communicates that the cookie is valid. The integrity of the cookie is not verified by OpenSSL. This is an application responsibility.

- -

RETURN VALUES

- -

Neither function returns a value.

- -

SEE ALSO

- -

ssl(7), SSL_stateless(3), DTLSv1_listen(3)

- -

HISTORY

- -

SSL_CTX_set_stateless_cookie_generate_cb() and SSL_CTX_set_stateless_cookie_verify_cb() were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_timeout.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_timeout.html deleted file mode 100644 index a0a673b7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_timeout.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -SSL_CTX_set_timeout - - - - - - - - - - -

NAME

- -

SSL_CTX_set_timeout, SSL_CTX_get_timeout - manipulate timeout values for session caching

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_timeout(SSL_CTX *ctx, long t);
-long SSL_CTX_get_timeout(SSL_CTX *ctx);
- -

DESCRIPTION

- -

SSL_CTX_set_timeout() sets the timeout for newly created sessions for ctx to t. The timeout value t must be given in seconds.

- -

SSL_CTX_get_timeout() returns the currently set timeout value for ctx.

- -

NOTES

- -

Whenever a new session is created, it is assigned a maximum lifetime. This lifetime is specified by storing the creation time of the session and the timeout value valid at this time. If the actual time is later than creation time plus timeout, the session is not reused.

- -

Due to this realization, all sessions behave according to the timeout value valid at the time of the session negotiation. Changes of the timeout value do not affect already established sessions.

- -

The expiration time of a single session can be modified using the SSL_SESSION_get_time(3) family of functions.

- -

Expired sessions are removed from the internal session cache, whenever SSL_CTX_flush_sessions(3) is called, either directly by the application or automatically (see SSL_CTX_set_session_cache_mode(3))

- -

The default value for session timeout is decided on a per protocol basis, see SSL_get_default_timeout(3). All currently supported protocols have the same default timeout value of 300 seconds.

- -

This timeout value is used as the ticket lifetime hint for stateless session tickets. It is also used as the timeout value within the ticket itself.

- -

For TLSv1.3, RFC8446 limits transmission of this value to 1 week (604800 seconds).

- -

For TLSv1.2, tickets generated during an initial handshake use the value as specified. Tickets generated during a resumed handshake have a value of 0 for the ticket lifetime hint.

- -

RETURN VALUES

- -

SSL_CTX_set_timeout() returns the previously set timeout value.

- -

SSL_CTX_get_timeout() returns the currently set timeout value.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_session_cache_mode(3), SSL_SESSION_get_time(3), SSL_CTX_flush_sessions(3), SSL_get_default_timeout(3)

- -

COPYRIGHT

- -

Copyright 2001-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_servername_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_servername_callback.html deleted file mode 100644 index 6ee76709..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_servername_callback.html +++ /dev/null @@ -1,167 +0,0 @@ - - - - -SSL_CTX_set_tlsext_servername_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_tlsext_servername_callback, SSL_CTX_set_tlsext_servername_arg, SSL_get_servername_type, SSL_get_servername, SSL_set_tlsext_host_name - handle server name indication (SNI)

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_tlsext_servername_callback(SSL_CTX *ctx,
-                                  int (*cb)(SSL *s, int *al, void *arg));
-long SSL_CTX_set_tlsext_servername_arg(SSL_CTX *ctx, void *arg);
-
-const char *SSL_get_servername(const SSL *s, const int type);
-int SSL_get_servername_type(const SSL *s);
-
-int SSL_set_tlsext_host_name(const SSL *s, const char *name);
- -

DESCRIPTION

- -

The functionality provided by the servername callback is mostly superseded by the ClientHello callback, which can be set using SSL_CTX_set_client_hello_cb(). However, even where the ClientHello callback is used, the servername callback is still necessary in order to acknowledge the servername requested by the client.

- -

SSL_CTX_set_tlsext_servername_callback() sets the application callback cb used by a server to perform any actions or configuration required based on the servername extension received in the incoming connection. When cb is NULL, SNI is not used.

- -

The servername callback should return one of the following values:

- -
- -
SSL_TLSEXT_ERR_OK
-
- -

This is used to indicate that the servername requested by the client has been accepted. Typically a server will call SSL_set_SSL_CTX() in the callback to set up a different configuration for the selected servername in this case.

- -
-
SSL_TLSEXT_ERR_ALERT_FATAL
-
- -

In this case the servername requested by the client is not accepted and the handshake will be aborted. The value of the alert to be used should be stored in the location pointed to by the al parameter to the callback. By default this value is initialised to SSL_AD_UNRECOGNIZED_NAME.

- -
-
SSL_TLSEXT_ERR_ALERT_WARNING
-
- -

If this value is returned then the servername is not accepted by the server. However, the handshake will continue and send a warning alert instead. The value of the alert should be stored in the location pointed to by the al parameter as for SSL_TLSEXT_ERR_ALERT_FATAL above. Note that TLSv1.3 does not support warning alerts, so if TLSv1.3 has been negotiated then this return value is treated the same way as SSL_TLSEXT_ERR_NOACK.

- -
-
SSL_TLSEXT_ERR_NOACK
-
- -

This return value indicates that the servername is not accepted by the server. No alerts are sent and the server will not acknowledge the requested servername.

- -
-
- -

SSL_CTX_set_tlsext_servername_arg() sets a context-specific argument to be passed into the callback (via the arg parameter) for this SSL_CTX.

- -

The behaviour of SSL_get_servername() depends on a number of different factors. In particular note that in TLSv1.3 the servername is negotiated in every handshake. In TLSv1.2 the servername is only negotiated on initial handshakes and not on resumption handshakes.

- -
- -
On the client, before the handshake
-
- -

If a servername has been set via a call to SSL_set_tlsext_host_name() then it will return that servername.

- -

If one has not been set, but a TLSv1.2 resumption is being attempted and the session from the original handshake had a servername accepted by the server then it will return that servername.

- -

Otherwise it returns NULL.

- -
-
On the client, during or after the handshake and a TLSv1.2 (or below) resumption occurred
-
- -

If the session from the original handshake had a servername accepted by the server then it will return that servername.

- -

Otherwise it returns the servername set via SSL_set_tlsext_host_name() or NULL if it was not called.

- -
-
On the client, during or after the handshake and a TLSv1.2 (or below) resumption did not occur
-
- -

It will return the servername set via SSL_set_tlsext_host_name() or NULL if it was not called.

- -
-
On the server, before the handshake
-
- -

The function will always return NULL before the handshake

- -
-
On the server, after the servername extension has been processed and a TLSv1.2 (or below) resumption occurred
-
- -

If a servername was accepted by the server in the original handshake then it will return that servername, or NULL otherwise.

- -
-
On the server, after the servername extension has been processed and a TLSv1.2 (or below) resumption did not occur
-
- -

The function will return the servername requested by the client in this handshake or NULL if none was requested.

- -
-
- -

Note that the ClientHello callback occurs before a servername extension from the client is processed. The servername, certificate and ALPN callbacks occur after a servername extension from the client is processed.

- -

SSL_get_servername_type() returns the servername type or -1 if no servername is present. Currently the only supported type (defined in RFC3546) is TLSEXT_NAMETYPE_host_name.

- -

SSL_set_tlsext_host_name() sets the server name indication ClientHello extension to contain the value name. The type of server name indication extension is set to TLSEXT_NAMETYPE_host_name (defined in RFC3546).

- -

NOTES

- -

Several callbacks are executed during ClientHello processing, including the ClientHello, ALPN, and servername callbacks. The ClientHello callback is executed first, then the servername callback, followed by the ALPN callback.

- -

The SSL_set_tlsext_host_name() function should only be called on SSL objects that will act as clients; otherwise the configured name will be ignored.

- -

RETURN VALUES

- -

SSL_CTX_set_tlsext_servername_callback() and SSL_CTX_set_tlsext_servername_arg() both always return 1 indicating success. SSL_set_tlsext_host_name() returns 1 on success, 0 in case of error.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_alpn_select_cb(3), SSL_get0_alpn_selected(3), SSL_CTX_set_client_hello_cb(3)

- -

HISTORY

- -

SSL_get_servername() historically provided some unexpected results in certain corner cases. This has been fixed from OpenSSL 1.1.1e.

- -

Prior to 1.1.1e, when the client requested a servername in an initial TLSv1.2 handshake, the server accepted it, and then the client successfully resumed but set a different explicit servername in the second handshake then when called by the client it returned the servername from the second handshake. This has now been changed to return the servername requested in the original handshake.

- -

Also prior to 1.1.1e, if the client sent a servername in the first handshake but the server did not accept it, and then a second handshake occurred where TLSv1.2 resumption was successful then when called by the server it returned the servername requested in the original handshake. This has now been changed to NULL.

- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_status_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_status_cb.html deleted file mode 100644 index 9d6cbfea..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_status_cb.html +++ /dev/null @@ -1,92 +0,0 @@ - - - - -SSL_CTX_set_tlsext_status_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_tlsext_status_cb, SSL_CTX_get_tlsext_status_cb, SSL_CTX_set_tlsext_status_arg, SSL_CTX_get_tlsext_status_arg, SSL_CTX_set_tlsext_status_type, SSL_CTX_get_tlsext_status_type, SSL_set_tlsext_status_type, SSL_get_tlsext_status_type, SSL_get_tlsext_status_ocsp_resp, SSL_set_tlsext_status_ocsp_resp - OCSP Certificate Status Request functions

- -

SYNOPSIS

- -
#include <openssl/tls1.h>
-
-long SSL_CTX_set_tlsext_status_cb(SSL_CTX *ctx, int (*callback)(SSL *, void *));
-long SSL_CTX_get_tlsext_status_cb(SSL_CTX *ctx, int (**callback)(SSL *, void *));
-
-long SSL_CTX_set_tlsext_status_arg(SSL_CTX *ctx, void *arg);
-long SSL_CTX_get_tlsext_status_arg(SSL_CTX *ctx, void **arg);
-
-long SSL_CTX_set_tlsext_status_type(SSL_CTX *ctx, int type);
-long SSL_CTX_get_tlsext_status_type(SSL_CTX *ctx);
-
-long SSL_set_tlsext_status_type(SSL *s, int type);
-long SSL_get_tlsext_status_type(SSL *s);
-
-long SSL_get_tlsext_status_ocsp_resp(ssl, unsigned char **resp);
-long SSL_set_tlsext_status_ocsp_resp(ssl, unsigned char *resp, int len);
- -

DESCRIPTION

- -

A client application may request that a server send back an OCSP status response (also known as OCSP stapling). To do so the client should call the SSL_CTX_set_tlsext_status_type() function prior to the creation of any SSL objects. Alternatively an application can call the SSL_set_tlsext_status_type() function on an individual SSL object prior to the start of the handshake. Currently the only supported type is TLSEXT_STATUSTYPE_ocsp. This value should be passed in the type argument. Calling SSL_CTX_get_tlsext_status_type() will return the type TLSEXT_STATUSTYPE_ocsp previously set via SSL_CTX_set_tlsext_status_type() or -1 if not set.

- -

The client should additionally provide a callback function to decide what to do with the returned OCSP response by calling SSL_CTX_set_tlsext_status_cb(). The callback function should determine whether the returned OCSP response is acceptable or not. The callback will be passed as an argument the value previously set via a call to SSL_CTX_set_tlsext_status_arg(). Note that the callback will not be called in the event of a handshake where session resumption occurs (because there are no Certificates exchanged in such a handshake). The callback previously set via SSL_CTX_set_tlsext_status_cb() can be retrieved by calling SSL_CTX_get_tlsext_status_cb(), and the argument by calling SSL_CTX_get_tlsext_status_arg().

- -

On the client side SSL_get_tlsext_status_type() can be used to determine whether the client has previously called SSL_set_tlsext_status_type(). It will return TLSEXT_STATUSTYPE_ocsp if it has been called or -1 otherwise. On the server side SSL_get_tlsext_status_type() can be used to determine whether the client requested OCSP stapling. If the client requested it then this function will return TLSEXT_STATUSTYPE_ocsp, or -1 otherwise.

- -

The response returned by the server can be obtained via a call to SSL_get_tlsext_status_ocsp_resp(). The value *resp will be updated to point to the OCSP response data and the return value will be the length of that data. Typically a callback would obtain an OCSP_RESPONSE object from this data via a call to the d2i_OCSP_RESPONSE() function. If the server has not provided any response data then *resp will be NULL and the return value from SSL_get_tlsext_status_ocsp_resp() will be -1.

- -

A server application must also call the SSL_CTX_set_tlsext_status_cb() function if it wants to be able to provide clients with OCSP Certificate Status responses. Typically the server callback would obtain the server certificate that is being sent back to the client via a call to SSL_get_certificate(); obtain the OCSP response to be sent back; and then set that response data by calling SSL_set_tlsext_status_ocsp_resp(). A pointer to the response data should be provided in the resp argument, and the length of that data should be in the len argument.

- -

RETURN VALUES

- -

The callback when used on the client side should return a negative value on error; 0 if the response is not acceptable (in which case the handshake will fail) or a positive value if it is acceptable.

- -

The callback when used on the server side should return with either SSL_TLSEXT_ERR_OK (meaning that the OCSP response that has been set should be returned), SSL_TLSEXT_ERR_NOACK (meaning that an OCSP response should not be returned) or SSL_TLSEXT_ERR_ALERT_FATAL (meaning that a fatal error has occurred).

- -

SSL_CTX_set_tlsext_status_cb(), SSL_CTX_set_tlsext_status_arg(), SSL_CTX_set_tlsext_status_type(), SSL_set_tlsext_status_type() and SSL_set_tlsext_status_ocsp_resp() return 0 on error or 1 on success.

- -

SSL_CTX_get_tlsext_status_type() returns the value previously set by SSL_CTX_set_tlsext_status_type(), or -1 if not set.

- -

SSL_get_tlsext_status_ocsp_resp() returns the length of the OCSP response data or -1 if there is no OCSP response data.

- -

SSL_get_tlsext_status_type() returns TLSEXT_STATUSTYPE_ocsp on the client side if SSL_set_tlsext_status_type() was previously called, or on the server side if the client requested OCSP stapling. Otherwise -1 is returned.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

The SSL_get_tlsext_status_type(), SSL_CTX_get_tlsext_status_type() and SSL_CTX_set_tlsext_status_type() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_ticket_key_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_ticket_key_cb.html deleted file mode 100644 index 524f1c12..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_ticket_key_cb.html +++ /dev/null @@ -1,213 +0,0 @@ - - - - -SSL_CTX_set_tlsext_ticket_key_cb - - - - - - - - - - -

NAME

- -

SSL_CTX_set_tlsext_ticket_key_evp_cb, SSL_CTX_set_tlsext_ticket_key_cb - set a callback for session ticket processing

- -

SYNOPSIS

- -
#include <openssl/tls1.h>
-
-int SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL_CTX sslctx,
-    int (*cb)(SSL *s, unsigned char key_name[16],
-              unsigned char iv[EVP_MAX_IV_LENGTH],
-              EVP_CIPHER_CTX *ctx, EVP_MAC_CTX *hctx, int enc));
- -

The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
int SSL_CTX_set_tlsext_ticket_key_cb(SSL_CTX sslctx,
-    int (*cb)(SSL *s, unsigned char key_name[16],
-              unsigned char iv[EVP_MAX_IV_LENGTH],
-              EVP_CIPHER_CTX *ctx, HMAC_CTX *hctx, int enc));
- -

DESCRIPTION

- -

SSL_CTX_set_tlsext_ticket_key_evp_cb() sets a callback function cb for handling session tickets for the ssl context sslctx. Session tickets, defined in RFC5077 provide an enhanced session resumption capability where the server implementation is not required to maintain per session state. It only applies to TLS and there is no SSLv3 implementation.

- -

The callback function cb will be called for every client instigated TLS session when session ticket extension is presented in the TLS hello message. It is the responsibility of this function to create or retrieve the cryptographic parameters and to maintain their state.

- -

The OpenSSL library uses your callback function to help implement a common TLS ticket construction state according to RFC5077 Section 4 such that per session state is unnecessary and a small set of cryptographic variables needs to be maintained by the callback function implementation.

- -

In order to reuse a session, a TLS client must send the session ticket extension to the server. The client must send exactly one session ticket. The server, through the callback function, either agrees to reuse the session ticket information or it starts a full TLS handshake to create a new session ticket.

- -

Before the callback function is started ctx and hctx have been initialised with EVP_CIPHER_CTX_reset(3) and EVP_MAC_CTX_new(3) respectively.

- -

For new sessions tickets, when the client doesn't present a session ticket, or an attempted retrieval of the ticket failed, or a renew option was indicated, the callback function will be called with enc equal to 1. The OpenSSL library expects that the function will set an arbitrary name, initialize iv, and set the cipher context ctx and the hash context hctx.

- -

The name is 16 characters long and is used as a key identifier.

- -

The iv length is the length of the IV of the corresponding cipher. The maximum IV length is EVP_MAX_IV_LENGTH bytes defined in <openssl/evp.h>.

- -

The initialization vector iv should be a random value. The cipher context ctx should use the initialisation vector iv. The cipher context can be set using EVP_EncryptInit_ex(3). The hmac context and digest can be set using EVP_MAC_CTX_set_params(3) with the OSSL_MAC_PARAM_KEY and OSSL_MAC_PARAM_DIGEST parameters respectively.

- -

When the client presents a session ticket, the callback function with be called with enc set to 0 indicating that the cb function should retrieve a set of parameters. In this case name and iv have already been parsed out of the session ticket. The OpenSSL library expects that the name will be used to retrieve a cryptographic parameters and that the cryptographic context ctx will be set with the retrieved parameters and the initialization vector iv. using a function like EVP_DecryptInit_ex(3). The key material and digest for hctx need to be set using EVP_MAC_CTX_set_params(3) with the OSSL_MAC_PARAM_KEY and OSSL_MAC_PARAM_DIGEST parameters respectively.

- -

If the name is still valid but a renewal of the ticket is required the callback function should return 2. The library will call the callback again with an argument of enc equal to 1 to set the new ticket.

- -

The return value of the cb function is used by OpenSSL to determine what further processing will occur. The following return values have meaning:

- -
- -
2
-
- -

This indicates that the ctx and hctx have been set and the session can continue on those parameters. Additionally it indicates that the session ticket is in a renewal period and should be replaced. The OpenSSL library will call cb again with an enc argument of 1 to set the new ticket (see RFC5077 3.3 paragraph 2).

- -
-
1
-
- -

This indicates that the ctx and hctx have been set and the session can continue on those parameters.

- -
-
0
-
- -

This indicates that it was not possible to set/retrieve a session ticket and the SSL/TLS session will continue by negotiating a set of cryptographic parameters or using the alternate SSL/TLS resumption mechanism, session ids.

- -

If called with enc equal to 0 the library will call the cb again to get a new set of parameters.

- -
-
less than 0
-
- -

This indicates an error.

- -
-
- -

The SSL_CTX_set_tlsext_ticket_key_cb() function is identical to SSL_CTX_set_tlsext_ticket_key_evp_cb() except that it takes a deprecated HMAC_CTX pointer instead of an EVP_MAC_CTX one. Before this callback function is started hctx will have been initialised with EVP_MAC_CTX_new(3) and the digest set with EVP_MAC_CTX_set_params(3). The hctx key material can be set using HMAC_Init_ex(3).

- -

NOTES

- -

Session resumption shortcuts the TLS handshake so that the client certificate negotiation doesn't occur. It makes up for this by storing the client certificate and all other negotiated state information encrypted within the ticket. In a resumed session the applications will have all this state information available exactly as if a full negotiation had occurred.

- -

If an attacker can obtain the key used to encrypt a session ticket, they can obtain the master secret for any ticket using that key and decrypt any traffic using that session: even if the cipher suite supports forward secrecy. As a result applications may wish to use multiple keys and avoid using long term keys stored in files.

- -

Applications can use longer keys to maintain a consistent level of security. For example if a cipher suite uses 256 bit ciphers but only a 128 bit ticket key the overall security is only 128 bits because breaking the ticket key will enable an attacker to obtain the session keys.

- -

RETURN VALUES

- -

Returns 1 to indicate the callback function was set and 0 otherwise.

- -

EXAMPLES

- -

Reference Implementation:

- -
SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL, ssl_tlsext_ticket_key_cb);
-...
-
-static int ssl_tlsext_ticket_key_cb(SSL *s, unsigned char key_name[16],
-                                    unsigned char *iv, EVP_CIPHER_CTX *ctx,
-                                    EVP_MAC_CTX *hctx, int enc)
-{
-    OSSL_PARAM params[3];
-    your_type_t *key; /* something that you need to implement */
-
-    if (enc) { /* create new session */
-        if (RAND_bytes(iv, EVP_MAX_IV_LENGTH) <= 0)
-            return -1; /* insufficient random */
-
-        key = currentkey(); /* something that you need to implement */
-        if (key == NULL) {
-            /* current key doesn't exist or isn't valid */
-            key = createkey(); /*
-                                * Something that you need to implement.
-                                * createkey needs to initialise a name,
-                                * an aes_key, a hmac_key and optionally
-                                * an expire time.
-                                */
-            if (key == NULL) /* key couldn't be created */
-                return 0;
-        }
-        memcpy(key_name, key->name, 16);
-
-        if (EVP_EncryptInit_ex(&ctx, EVP_aes_256_cbc(), NULL, key->aes_key,
-                               iv) == 0)
-           return -1; /* error in cipher initialisation */
-
-        params[0] = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY,
-                                                      key->hmac_key, 32);
-        params[1] = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST,
-                                                     "sha256", 0);
-        params[2] = OSSL_PARAM_construct_end();
-        if (EVP_MAC_CTX_set_params(hctx, params) == 0)
-           return -1; /* error in mac initialisation */
-
-        return 1;
-
-    } else { /* retrieve session */
-        time_t t = time(NULL);
-        key = findkey(key_name); /* something that you need to implement */
-
-        if (key == NULL || key->expire < t)
-            return 0;
-
-        params[0] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY,
-                                                      key->hmac_key, 32);
-        params[1] = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST,
-                                                     "sha256", 0);
-        params[2] = OSSL_PARAM_construct_end();
-        if (EVP_MAC_CTX_set_params(hctx, params) == 0)
-           return -1; /* error in mac initialisation */
-
-        if (EVP_DecryptInit_ex(&ctx, EVP_aes_256_cbc(), NULL, key->aes_key,
-                               iv) == 0)
-           return -1; /* error in cipher initialisation */
-
-        if (key->expire < t - RENEW_TIME) { /* RENEW_TIME: implement */
-            /*
-             * return 2 - This session will get a new ticket even though the
-             * current one is still valid.
-             */
-            return 2;
-        }
-        return 1;
-    }
-}
- -

SEE ALSO

- -

ssl(7), SSL_set_session(3), SSL_session_reused(3), SSL_CTX_add_session(3), SSL_CTX_sess_number(3), SSL_CTX_sess_set_get_cb(3), SSL_CTX_set_session_id_context(3),

- -

HISTORY

- -

The SSL_CTX_set_tlsext_ticket_key_cb() function was deprecated in OpenSSL 3.0.

- -

The SSL_CTX_set_tlsext_ticket_key_evp_cb() function was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2014-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_use_srtp.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_use_srtp.html deleted file mode 100644 index 7275e7fe..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tlsext_use_srtp.html +++ /dev/null @@ -1,156 +0,0 @@ - - - - -SSL_CTX_set_tlsext_use_srtp - - - - - - - - - - -

NAME

- -

SSL_CTX_set_tlsext_use_srtp, SSL_set_tlsext_use_srtp, SSL_get_srtp_profiles, SSL_get_selected_srtp_profile - Configure and query SRTP support

- -

SYNOPSIS

- -
#include <openssl/srtp.h>
-
-int SSL_CTX_set_tlsext_use_srtp(SSL_CTX *ctx, const char *profiles);
-int SSL_set_tlsext_use_srtp(SSL *ssl, const char *profiles);
-
-STACK_OF(SRTP_PROTECTION_PROFILE) *SSL_get_srtp_profiles(SSL *ssl);
-SRTP_PROTECTION_PROFILE *SSL_get_selected_srtp_profile(SSL *s);
- -

DESCRIPTION

- -

SRTP is the Secure Real-Time Transport Protocol. OpenSSL implements support for the "use_srtp" DTLS extension defined in RFC5764. This provides a mechanism for establishing SRTP keying material, algorithms and parameters using DTLS. This capability may be used as part of an implementation that conforms to RFC5763. OpenSSL does not implement SRTP itself or RFC5763. Note that OpenSSL does not support the use of SRTP Master Key Identifiers (MKIs). Also note that this extension is only supported in DTLS. Any SRTP configuration will be ignored if a TLS connection is attempted.

- -

An OpenSSL client wishing to send the "use_srtp" extension should call SSL_CTX_set_tlsext_use_srtp() to set its use for all SSL objects subsequently created from an SSL_CTX. Alternatively a client may call SSL_set_tlsext_use_srtp() to set its use for an individual SSL object. The profiles parameters should point to a NUL-terminated, colon delimited list of SRTP protection profile names.

- -

The currently supported protection profile names are:

- -
- -
SRTP_AES128_CM_SHA1_80
-
- -

This corresponds to SRTP_AES128_CM_HMAC_SHA1_80 defined in RFC5764.

- -
-
SRTP_AES128_CM_SHA1_32
-
- -

This corresponds to SRTP_AES128_CM_HMAC_SHA1_32 defined in RFC5764.

- -
-
SRTP_AEAD_AES_128_GCM
-
- -

This corresponds to the profile of the same name defined in RFC7714.

- -
-
SRTP_AEAD_AES_256_GCM
-
- -

This corresponds to the profile of the same name defined in RFC7714.

- -
-
SRTP_DOUBLE_AEAD_AES_128_GCM_AEAD_AES_128_GCM
-
- -

This corresponds to the profile of the same name defined in RFC8723.

- -
-
SRTP_DOUBLE_AEAD_AES_256_GCM_AEAD_AES_256_GCM
-
- -

This corresponds to the profile of the same name defined in RFC8723.

- -
-
SRTP_ARIA_128_CTR_HMAC_SHA1_80
-
- -

This corresponds to the profile of the same name defined in RFC8269.

- -
-
SRTP_ARIA_128_CTR_HMAC_SHA1_32
-
- -

This corresponds to the profile of the same name defined in RFC8269.

- -
-
SRTP_ARIA_256_CTR_HMAC_SHA1_80
-
- -

This corresponds to the profile of the same name defined in RFC8269.

- -
-
SRTP_ARIA_256_CTR_HMAC_SHA1_32
-
- -

This corresponds to the profile of the same name defined in RFC8269.

- -
-
SRTP_AEAD_ARIA_128_GCM
-
- -

This corresponds to the profile of the same name defined in RFC8269.

- -
-
SRTP_AEAD_ARIA_256_GCM
-
- -

This corresponds to the profile of the same name defined in RFC8269.

- -
-
- -

Supplying an unrecognised protection profile name will result in an error.

- -

An OpenSSL server wishing to support the "use_srtp" extension should also call SSL_CTX_set_tlsext_use_srtp() or SSL_set_tlsext_use_srtp() to indicate the protection profiles that it is willing to negotiate.

- -

The currently configured list of protection profiles for either a client or a server can be obtained by calling SSL_get_srtp_profiles(). This returns a stack of SRTP_PROTECTION_PROFILE objects. The memory pointed to in the return value of this function should not be freed by the caller.

- -

After a handshake has been completed the negotiated SRTP protection profile (if any) can be obtained (on the client or the server) by calling SSL_get_selected_srtp_profile(). This function will return NULL if no SRTP protection profile was negotiated. The memory returned from this function should not be freed by the caller.

- -

If an SRTP protection profile has been successfully negotiated then the SRTP keying material (on both the client and server) should be obtained via a call to SSL_export_keying_material(3). This call should provide a label value of "EXTRACTOR-dtls_srtp" and a NULL context value (use_context is 0). The total length of keying material obtained should be equal to two times the sum of the master key length and the salt length as defined for the protection profile in use. This provides the client write master key, the server write master key, the client write master salt and the server write master salt in that order.

- -

These functions cannot be used with QUIC SSL objects. SSL_CTX_set_tlsext_use_srtp() fails if called on a QUIC SSL context. SSL_set_tlsext_use_srtp() fails if called on a QUIC SSL object.

- -

RETURN VALUES

- -

SSL_CTX_set_tlsext_use_srtp() and SSL_set_tlsext_use_srtp() return 0 on success or 1 on error.

- -

SSL_get_srtp_profiles() returns a stack of SRTP_PROTECTION_PROFILE objects on success or NULL on error or if no protection profiles have been configured.

- -

SSL_get_selected_srtp_profile() returns a pointer to an SRTP_PROTECTION_PROFILE object if one has been negotiated or NULL otherwise.

- -

SEE ALSO

- -

ssl(7), SSL_export_keying_material(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_dh_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_dh_callback.html deleted file mode 100644 index 90deafd9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_dh_callback.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -SSL_CTX_set_tmp_dh_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_dh_auto, SSL_set_dh_auto, SSL_CTX_set0_tmp_dh_pkey, SSL_set0_tmp_dh_pkey, SSL_CTX_set_tmp_dh_callback, SSL_CTX_set_tmp_dh, SSL_set_tmp_dh_callback, SSL_set_tmp_dh - handle DH keys for ephemeral key exchange

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_dh_auto(SSL_CTX *ctx, int onoff);
-long SSL_set_dh_auto(SSL *s, int onoff);
-int SSL_CTX_set0_tmp_dh_pkey(SSL_CTX *ctx, EVP_PKEY *dhpkey);
-int SSL_set0_tmp_dh_pkey(SSL *s, EVP_PKEY *dhpkey);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
void SSL_CTX_set_tmp_dh_callback(SSL_CTX *ctx,
-                                 DH *(*tmp_dh_callback)(SSL *ssl, int is_export,
-                                                        int keylength));
-long SSL_CTX_set_tmp_dh(SSL_CTX *ctx, DH *dh);
-
-void SSL_set_tmp_dh_callback(SSL *ctx,
-                             DH *(*tmp_dh_callback)(SSL *ssl, int is_export,
-                                                    int keylength));
-long SSL_set_tmp_dh(SSL *ssl, DH *dh);
- -

DESCRIPTION

- -

The functions described on this page are relevant for servers only.

- -

Some ciphersuites may use ephemeral Diffie-Hellman (DH) key exchange. In these cases, the session data is negotiated using the ephemeral/temporary DH key and the key supplied and certified by the certificate chain is only used for signing. Anonymous ciphers (without a permanent server key) also use ephemeral DH keys.

- -

Using ephemeral DH key exchange yields forward secrecy as the connection can only be decrypted when the DH key is known. By generating a temporary DH key inside the server application that is lost when the application is left, it becomes impossible for an attacker to decrypt past sessions, even if they get hold of the normal (certified) key, as this key was only used for signing.

- -

In order to perform a DH key exchange the server must use a DH group (DH parameters) and generate a DH key. The server will always generate a new DH key during the negotiation.

- -

As generating DH parameters is extremely time consuming, an application should not generate the parameters on the fly. DH parameters can be reused, as the actual key is newly generated during the negotiation.

- -

Typically applications should use well known DH parameters that have built-in support in OpenSSL. The macros SSL_CTX_set_dh_auto() and SSL_set_dh_auto() configure OpenSSL to use the default built-in DH parameters for the SSL_CTX and SSL objects respectively. Passing a value of 1 in the onoff parameter switches the feature on, and passing a value of 0 switches it off. The default setting is off.

- -

If "auto" DH parameters are switched on then the parameters will be selected to be consistent with the size of the key associated with the server's certificate. If there is no certificate (e.g. for PSK ciphersuites), then it it will be consistent with the size of the negotiated symmetric cipher key.

- -

Applications may supply their own DH parameters instead of using the built-in values. This approach is discouraged and applications should in preference use the built-in parameter support described above. Applications wishing to supply their own DH parameters should call SSL_CTX_set0_tmp_dh_pkey() or SSL_set0_tmp_dh_pkey() to supply the parameters for the SSL_CTX or SSL respectively. The parameters should be supplied in the dhpkey argument as an EVP_PKEY containing DH parameters. Ownership of the dhpkey value is passed to the SSL_CTX or SSL object as a result of this call, and so the caller should not free it if the function call is successful.

- -

The deprecated macros SSL_CTX_set_tmp_dh() and SSL_set_tmp_dh() do the same thing as SSL_CTX_set0_tmp_dh_pkey() and SSL_set0_tmp_dh_pkey() except that the DH parameters are supplied in a DH object instead in the dh argument, and ownership of the DH object is retained by the application. Applications should use "auto" parameters instead, or call SSL_CTX_set0_tmp_dh_pkey() or SSL_set0_tmp_dh_pkey() as appropriate.

- -

An application may instead specify the DH parameters via a callback function using the functions SSL_CTX_set_tmp_dh_callback() or SSL_set_tmp_dh_callback() to set the callback for the SSL_CTX or SSL object respectively. These functions are deprecated. Applications should instead use "auto" parameters, or specify the parameters via SSL_CTX_set0_tmp_dh_pkey() or SSL_set0_tmp_dh_pkey() as appropriate.

- -

The callback will be invoked during a connection when DH parameters are required. The SSL object for the current connection is supplied as an argument. Previous versions of OpenSSL used the is_export and keylength arguments to control parameter generation for export and non-export cipher suites. Modern OpenSSL does not support export ciphersuites and so these arguments are unused and can be ignored by the callback. The callback should return the parameters to be used in a DH object. Ownership of the DH object is retained by the application and should later be freed.

- -

RETURN VALUES

- -

All of these functions/macros return 1 for success or 0 on error.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_cipher_list(3), SSL_CTX_set_options(3), openssl-ciphers(1), openssl-dhparam(1)

- -

COPYRIGHT

- -

Copyright 2001-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_ecdh.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_ecdh.html deleted file mode 100644 index fa8aaaf0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_tmp_ecdh.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -SSL_CTX_set_tmp_ecdh - - - - - - - - - - -

NAME

- -

SSL_CTX_set_tmp_ecdh, SSL_set_tmp_ecdh, SSL_CTX_set_ecdh_auto, SSL_set_ecdh_auto - handle ECDH keys for ephemeral key exchange

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_CTX_set_tmp_ecdh(SSL_CTX *ctx, const EC_KEY *ecdh);
-long SSL_set_tmp_ecdh(SSL *ssl, const EC_KEY *ecdh);
-
-long SSL_CTX_set_ecdh_auto(SSL_CTX *ctx, int state);
-long SSL_set_ecdh_auto(SSL *ssl, int state);
- -

DESCRIPTION

- -

SSL_CTX_set_tmp_ecdh() sets ECDH parameters to be used to be ecdh. The key is inherited by all ssl objects created from ctx. This macro is deprecated in favor of SSL_CTX_set1_groups(3).

- -

SSL_set_tmp_ecdh() sets the parameters only for ssl. This macro is deprecated in favor of SSL_set1_groups(3).

- -

SSL_CTX_set_ecdh_auto() and SSL_set_ecdh_auto() are deprecated and have no effect.

- -

RETURN VALUES

- -

SSL_CTX_set_tmp_ecdh() and SSL_set_tmp_ecdh() return 1 on success and 0 on failure.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set1_curves(3), SSL_CTX_set_cipher_list(3), SSL_CTX_set_options(3), SSL_CTX_set_tmp_dh_callback(3), openssl-ciphers(1), openssl-ecparam(1)

- -

COPYRIGHT

- -

Copyright 2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_verify.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_verify.html deleted file mode 100644 index 75964f2c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_set_verify.html +++ /dev/null @@ -1,270 +0,0 @@ - - - - -SSL_CTX_set_verify - - - - - - - - - - -

NAME

- -

SSL_get_ex_data_X509_STORE_CTX_idx, SSL_CTX_set_verify, SSL_set_verify, SSL_CTX_set_verify_depth, SSL_set_verify_depth, SSL_verify_cb, SSL_verify_client_post_handshake, SSL_set_post_handshake_auth, SSL_CTX_set_post_handshake_auth - set various SSL/TLS parameters for peer certificate verification

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*SSL_verify_cb)(int preverify_ok, X509_STORE_CTX *x509_ctx);
-
-void SSL_CTX_set_verify(SSL_CTX *ctx, int mode, SSL_verify_cb verify_callback);
-void SSL_set_verify(SSL *ssl, int mode, SSL_verify_cb verify_callback);
-SSL_get_ex_data_X509_STORE_CTX_idx(void);
-
-void SSL_CTX_set_verify_depth(SSL_CTX *ctx, int depth);
-void SSL_set_verify_depth(SSL *ssl, int depth);
-
-int SSL_verify_client_post_handshake(SSL *ssl);
-void SSL_CTX_set_post_handshake_auth(SSL_CTX *ctx, int val);
-void SSL_set_post_handshake_auth(SSL *ssl, int val);
- -

DESCRIPTION

- -

SSL_CTX_set_verify() sets the verification flags for ctx to be mode and specifies the verify_callback function to be used. If no callback function shall be specified, the NULL pointer can be used for verify_callback.

- -

SSL_set_verify() sets the verification flags for ssl to be mode and specifies the verify_callback function to be used. If no callback function shall be specified, the NULL pointer can be used for verify_callback. In this case last verify_callback set specifically for this ssl remains. If no special callback was set before, the default callback for the underlying ctx is used, that was valid at the time ssl was created with SSL_new(3). Within the callback function, SSL_get_ex_data_X509_STORE_CTX_idx can be called to get the data index of the current SSL object that is doing the verification.

- -

In client mode verify_callback may also call the SSL_set_retry_verify(3) function on the SSL object set in the x509_store_ctx ex data (see SSL_get_ex_data_X509_STORE_CTX_idx(3)) and return 1. This would be typically done in case the certificate verification was not yet able to succeed. This makes the handshake suspend and return control to the calling application with SSL_ERROR_WANT_RETRY_VERIFY. The application can for instance fetch further certificates or cert status information needed for the verification. Calling SSL_connect(3) again resumes the connection attempt by retrying the server certificate verification step. This process may even be repeated if need be. Note that the handshake may still be aborted if a subsequent invocation of the callback (e.g., at a lower depth, or for a separate error condition) returns 0.

- -

SSL_CTX_set_verify_depth() sets the maximum depth for the certificate chain verification that shall be allowed for ctx.

- -

SSL_set_verify_depth() sets the maximum depth for the certificate chain verification that shall be allowed for ssl.

- -

SSL_CTX_set_post_handshake_auth() and SSL_set_post_handshake_auth() enable the Post-Handshake Authentication extension to be added to the ClientHello such that post-handshake authentication can be requested by the server. If val is 0 then the extension is not sent, otherwise it is. By default the extension is not sent. A certificate callback will need to be set via SSL_CTX_set_client_cert_cb() if no certificate is provided at initialization.

- -

SSL_verify_client_post_handshake() causes a CertificateRequest message to be sent by a server on the given ssl connection. The SSL_VERIFY_PEER flag must be set; the SSL_VERIFY_POST_HANDSHAKE flag is optional.

- -

NOTES

- -

The verification of certificates can be controlled by a set of logically or'ed mode flags:

- -
- -
SSL_VERIFY_NONE
-
- -

Server mode: the server will not send a client certificate request to the client, so the client will not send a certificate.

- -

Client mode: if not using an anonymous cipher (by default disabled), the server will send a certificate which will be checked. The result of the certificate verification process can be checked after the TLS/SSL handshake using the SSL_get_verify_result(3) function. The handshake will be continued regardless of the verification result.

- -
-
SSL_VERIFY_PEER
-
- -

Server mode: the server sends a client certificate request to the client. The certificate returned (if any) is checked. If the verification process fails, the TLS/SSL handshake is immediately terminated with an alert message containing the reason for the verification failure. The behaviour can be controlled by the additional SSL_VERIFY_FAIL_IF_NO_PEER_CERT, SSL_VERIFY_CLIENT_ONCE and SSL_VERIFY_POST_HANDSHAKE flags.

- -

Client mode: the server certificate is verified. If the verification process fails, the TLS/SSL handshake is immediately terminated with an alert message containing the reason for the verification failure. If no server certificate is sent, because an anonymous cipher is used, SSL_VERIFY_PEER is ignored.

- -
-
SSL_VERIFY_FAIL_IF_NO_PEER_CERT
-
- -

Server mode: if the client did not return a certificate, the TLS/SSL handshake is immediately terminated with a "handshake failure" alert. This flag must be used together with SSL_VERIFY_PEER.

- -

Client mode: ignored (see BUGS)

- -
-
SSL_VERIFY_CLIENT_ONCE
-
- -

Server mode: only request a client certificate once during the connection. Do not ask for a client certificate again during renegotiation or post-authentication if a certificate was requested during the initial handshake. This flag must be used together with SSL_VERIFY_PEER.

- -

Client mode: ignored (see BUGS)

- -
-
SSL_VERIFY_POST_HANDSHAKE
-
- -

Server mode: the server will not send a client certificate request during the initial handshake, but will send the request via SSL_verify_client_post_handshake(). This allows the SSL_CTX or SSL to be configured for post-handshake peer verification before the handshake occurs. This flag must be used together with SSL_VERIFY_PEER. TLSv1.3 only; no effect on pre-TLSv1.3 connections.

- -

Client mode: ignored (see BUGS)

- -
-
- -

If the mode is SSL_VERIFY_NONE none of the other flags may be set.

- -

If verification flags are not modified explicitly by SSL_CTX_set_verify() or SSL_set_verify(), the default value will be SSL_VERIFY_NONE.

- -

The actual verification procedure is performed either using the built-in verification procedure or using another application provided verification function set with SSL_CTX_set_cert_verify_callback(3). The following descriptions apply in the case of the built-in procedure. An application provided procedure also has access to the verify depth information and the verify_callback() function, but the way this information is used may be different.

- -

SSL_CTX_set_verify_depth() and SSL_set_verify_depth() set a limit on the number of certificates between the end-entity and trust-anchor certificates. Neither the end-entity nor the trust-anchor certificates count against depth. If the certificate chain needed to reach a trusted issuer is longer than depth+2, X509_V_ERR_CERT_CHAIN_TOO_LONG will be issued. The depth count is "level 0:peer certificate", "level 1: CA certificate", "level 2: higher level CA certificate", and so on. Setting the maximum depth to 2 allows the levels 0, 1, 2 and 3 (0 being the end-entity and 3 the trust-anchor). The default depth limit is 100, allowing for the peer certificate, at most 100 intermediate CA certificates and a final trust anchor certificate.

- -

The verify_callback function is used to control the behaviour when the SSL_VERIFY_PEER flag is set. It must be supplied by the application and receives two arguments: preverify_ok indicates, whether the verification of the certificate in question was passed (preverify_ok=1) or not (preverify_ok=0). x509_ctx is a pointer to the complete context used for the certificate chain verification.

- -

The certificate chain is checked starting with the deepest nesting level (the root CA certificate) and worked upward to the peer's certificate. At each level signatures and issuer attributes are checked. Whenever a verification error is found, the error number is stored in x509_ctx and verify_callback is called with preverify_ok=0. By applying X509_CTX_store_* functions verify_callback can locate the certificate in question and perform additional steps (see EXAMPLES). If no error is found for a certificate, verify_callback is called with preverify_ok=1 before advancing to the next level.

- -

The return value of verify_callback controls the strategy of the further verification process. If verify_callback returns 0, the verification process is immediately stopped with "verification failed" state. If SSL_VERIFY_PEER is set, a verification failure alert is sent to the peer and the TLS/SSL handshake is terminated. If verify_callback returns 1, the verification process is continued. If verify_callback always returns 1, the TLS/SSL handshake will not be terminated with respect to verification failures and the connection will be established. The calling process can however retrieve the error code of the last verification error using SSL_get_verify_result(3) or by maintaining its own error storage managed by verify_callback.

- -

If no verify_callback is specified, the default callback will be used. Its return value is identical to preverify_ok, so that any verification failure will lead to a termination of the TLS/SSL handshake with an alert message, if SSL_VERIFY_PEER is set.

- -

After calling SSL_set_post_handshake_auth(), the client will need to add a certificate or certificate callback to its configuration before it can successfully authenticate. This must be called before SSL_connect().

- -

SSL_verify_client_post_handshake() requires that verify flags have been previously set, and that a client sent the post-handshake authentication extension. When the client returns a certificate the verify callback will be invoked. A write operation must take place for the Certificate Request to be sent to the client, this can be done with SSL_do_handshake() or SSL_write_ex(). Only one certificate request may be outstanding at any time.

- -

When post-handshake authentication occurs, a refreshed NewSessionTicket message is sent to the client.

- -

Post-handshake authentication cannot be used with QUIC. SSL_set_post_handshake_auth() has no effect if called on a QUIC SSL object.

- -

BUGS

- -

In client mode, it is not checked whether the SSL_VERIFY_PEER flag is set, but whether any flags other than SSL_VERIFY_NONE are set. This can lead to unexpected behaviour if SSL_VERIFY_PEER and other flags are not used as required.

- -

RETURN VALUES

- -

The SSL*_set_verify*() functions do not provide diagnostic information.

- -

The SSL_verify_client_post_handshake() function returns 1 if the request succeeded, and 0 if the request failed. The error stack can be examined to determine the failure reason.

- -

EXAMPLES

- -

The following code sequence realizes an example verify_callback function that will always continue the TLS/SSL handshake regardless of verification failure, if wished. The callback realizes a verification depth limit with more informational output.

- -

All verification errors are printed; information about the certificate chain is printed on request. The example is realized for a server that does allow but not require client certificates.

- -

The example makes use of the ex_data technique to store application data into/retrieve application data from the SSL structure (see CRYPTO_get_ex_new_index(3), SSL_get_ex_data_X509_STORE_CTX_idx(3)).

- -
...
-typedef struct {
-  int verbose_mode;
-  int verify_depth;
-  int always_continue;
-} mydata_t;
-int mydata_index;
-
-...
-static int verify_callback(int preverify_ok, X509_STORE_CTX *ctx)
-{
-    char    buf[256];
-    X509   *err_cert;
-    int     err, depth;
-    SSL    *ssl;
-    mydata_t *mydata;
-
-    err_cert = X509_STORE_CTX_get_current_cert(ctx);
-    err = X509_STORE_CTX_get_error(ctx);
-    depth = X509_STORE_CTX_get_error_depth(ctx);
-
-    /*
-     * Retrieve the pointer to the SSL of the connection currently treated
-     * and the application specific data stored into the SSL object.
-     */
-    ssl = X509_STORE_CTX_get_ex_data(ctx, SSL_get_ex_data_X509_STORE_CTX_idx());
-    mydata = SSL_get_ex_data(ssl, mydata_index);
-
-    X509_NAME_oneline(X509_get_subject_name(err_cert), buf, 256);
-
-    /*
-     * Catch a too long certificate chain. The depth limit set using
-     * SSL_CTX_set_verify_depth() is by purpose set to "limit+1" so
-     * that whenever the "depth>verify_depth" condition is met, we
-     * have violated the limit and want to log this error condition.
-     * We must do it here, because the CHAIN_TOO_LONG error would not
-     * be found explicitly; only errors introduced by cutting off the
-     * additional certificates would be logged.
-     */
-    if (depth > mydata->verify_depth) {
-        preverify_ok = 0;
-        err = X509_V_ERR_CERT_CHAIN_TOO_LONG;
-        X509_STORE_CTX_set_error(ctx, err);
-    }
-    if (!preverify_ok) {
-        printf("verify error:num=%d:%s:depth=%d:%s\n", err,
-               X509_verify_cert_error_string(err), depth, buf);
-    } else if (mydata->verbose_mode) {
-        printf("depth=%d:%s\n", depth, buf);
-    }
-
-    /*
-     * At this point, err contains the last verification error. We can use
-     * it for something special
-     */
-    if (!preverify_ok && (err == X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT)) {
-        X509_NAME_oneline(X509_get_issuer_name(err_cert), buf, 256);
-        printf("issuer= %s\n", buf);
-    }
-
-    if (mydata->always_continue)
-        return 1;
-    else
-        return preverify_ok;
-}
-...
-
-mydata_t mydata;
-
-...
-mydata_index = SSL_get_ex_new_index(0, "mydata index", NULL, NULL, NULL);
-
-...
-SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE,
-                   verify_callback);
-
-/*
- * Let the verify_callback catch the verify_depth error so that we get
- * an appropriate error in the logfile.
- */
-SSL_CTX_set_verify_depth(verify_depth + 1);
-
-/*
- * Set up the SSL specific data into "mydata" and store it into th SSL
- * structure.
- */
-mydata.verify_depth = verify_depth; ...
-SSL_set_ex_data(ssl, mydata_index, &mydata);
-
-...
-SSL_accept(ssl);       /* check of success left out for clarity */
-if (peer = SSL_get_peer_certificate(ssl)) {
-    if (SSL_get_verify_result(ssl) == X509_V_OK) {
-        /* The client sent a certificate which verified OK */
-    }
-}
- -

SEE ALSO

- -

ssl(7), SSL_new(3), SSL_CTX_get_verify_mode(3), SSL_get_verify_result(3), SSL_CTX_load_verify_locations(3), SSL_get_peer_certificate(3), SSL_CTX_set_cert_verify_callback(3), SSL_get_ex_data_X509_STORE_CTX_idx(3), SSL_CTX_set_client_cert_cb(3), CRYPTO_get_ex_new_index(3)

- -

HISTORY

- -

The SSL_VERIFY_POST_HANDSHAKE option, and the SSL_verify_client_post_handshake() and SSL_set_post_handshake_auth() functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_certificate.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_certificate.html deleted file mode 100644 index b5cd53bb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_certificate.html +++ /dev/null @@ -1,121 +0,0 @@ - - - - -SSL_CTX_use_certificate - - - - - - - - - - -

NAME

- -

SSL_CTX_use_certificate, SSL_CTX_use_certificate_ASN1, SSL_CTX_use_certificate_file, SSL_use_certificate, SSL_use_certificate_ASN1, SSL_use_certificate_file, SSL_CTX_use_certificate_chain_file, SSL_use_certificate_chain_file, SSL_CTX_use_PrivateKey, SSL_CTX_use_PrivateKey_ASN1, SSL_CTX_use_PrivateKey_file, SSL_CTX_use_RSAPrivateKey, SSL_CTX_use_RSAPrivateKey_ASN1, SSL_CTX_use_RSAPrivateKey_file, SSL_use_PrivateKey_file, SSL_use_PrivateKey_ASN1, SSL_use_PrivateKey, SSL_use_RSAPrivateKey, SSL_use_RSAPrivateKey_ASN1, SSL_use_RSAPrivateKey_file, SSL_CTX_check_private_key, SSL_check_private_key, SSL_CTX_use_cert_and_key, SSL_use_cert_and_key - load certificate and key data

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_use_certificate(SSL_CTX *ctx, X509 *x);
-int SSL_CTX_use_certificate_ASN1(SSL_CTX *ctx, int len, const unsigned char *d);
-int SSL_CTX_use_certificate_file(SSL_CTX *ctx, const char *file, int type);
-int SSL_use_certificate(SSL *ssl, X509 *x);
-int SSL_use_certificate_ASN1(SSL *ssl, const unsigned char *d, int len);
-int SSL_use_certificate_file(SSL *ssl, const char *file, int type);
-
-int SSL_CTX_use_certificate_chain_file(SSL_CTX *ctx, const char *file);
-int SSL_use_certificate_chain_file(SSL *ssl, const char *file);
-
-int SSL_CTX_use_PrivateKey(SSL_CTX *ctx, EVP_PKEY *pkey);
-int SSL_CTX_use_PrivateKey_ASN1(int pk, SSL_CTX *ctx, const unsigned char *d,
-                                long len);
-int SSL_CTX_use_PrivateKey_file(SSL_CTX *ctx, const char *file, int type);
-int SSL_CTX_use_RSAPrivateKey(SSL_CTX *ctx, RSA *rsa);
-int SSL_CTX_use_RSAPrivateKey_ASN1(SSL_CTX *ctx, const unsigned char *d, long len);
-int SSL_CTX_use_RSAPrivateKey_file(SSL_CTX *ctx, const char *file, int type);
-int SSL_use_PrivateKey(SSL *ssl, EVP_PKEY *pkey);
-int SSL_use_PrivateKey_ASN1(int pk, SSL *ssl, const unsigned char *d, long len);
-int SSL_use_PrivateKey_file(SSL *ssl, const char *file, int type);
-int SSL_use_RSAPrivateKey(SSL *ssl, RSA *rsa);
-int SSL_use_RSAPrivateKey_ASN1(SSL *ssl, const unsigned char *d, long len);
-int SSL_use_RSAPrivateKey_file(SSL *ssl, const char *file, int type);
-
-int SSL_CTX_check_private_key(const SSL_CTX *ctx);
-int SSL_check_private_key(const SSL *ssl);
-
-int SSL_CTX_use_cert_and_key(SSL_CTX *ctx, X509 *x, EVP_PKEY *pkey, STACK_OF(X509) *chain, int override);
-int SSL_use_cert_and_key(SSL *ssl, X509 *x, EVP_PKEY *pkey, STACK_OF(X509) *chain, int override);
- -

DESCRIPTION

- -

These functions load the certificates and private keys into the SSL_CTX or SSL object, respectively.

- -

The SSL_CTX_* class of functions loads the certificates and keys into the SSL_CTX object ctx. The information is passed to SSL objects ssl created from ctx with SSL_new(3) by copying, so that changes applied to ctx do not propagate to already existing SSL objects.

- -

The SSL_* class of functions only loads certificates and keys into a specific SSL object. The specific information is kept, when SSL_clear(3) is called for this SSL object.

- -

SSL_CTX_use_certificate() loads the certificate x into ctx, SSL_use_certificate() loads x into ssl. The rest of the certificates needed to form the complete certificate chain can be specified using the SSL_CTX_add_extra_chain_cert(3) function. On success the reference counter of the x is incremented.

- -

SSL_CTX_use_certificate_ASN1() loads the ASN1 encoded certificate from the memory location d (with length len) into ctx, SSL_use_certificate_ASN1() loads the ASN1 encoded certificate into ssl.

- -

SSL_CTX_use_certificate_file() loads the first certificate stored in file into ctx. The formatting type of the certificate must be specified from the known types SSL_FILETYPE_PEM, SSL_FILETYPE_ASN1. SSL_use_certificate_file() loads the certificate from file into ssl. See the NOTES section on why SSL_CTX_use_certificate_chain_file() should be preferred.

- -

SSL_CTX_use_certificate_chain_file() loads a certificate chain from file into ctx. The certificates must be in PEM format and must be sorted starting with the subject's certificate (actual client or server certificate), followed by intermediate CA certificates if applicable, and ending at the highest level (root) CA. SSL_use_certificate_chain_file() is similar except it loads the certificate chain into ssl.

- -

SSL_CTX_use_PrivateKey() adds pkey as private key to ctx. SSL_CTX_use_RSAPrivateKey() adds the private key rsa of type RSA to ctx. SSL_use_PrivateKey() adds pkey as private key to ssl; SSL_use_RSAPrivateKey() adds rsa as private key of type RSA to ssl. If a certificate has already been set and the private key does not belong to the certificate an error is returned. To change a [certificate/private-key] pair, the new certificate needs to be set first with SSL_use_certificate() or SSL_CTX_use_certificate() before setting the private key with SSL_CTX_use_PrivateKey() or SSL_use_PrivateKey(). On success the reference counter of the pkey/rsa is incremented.

- -

SSL_CTX_use_cert_and_key() and SSL_use_cert_and_key() assign the X.509 certificate x, private key key, and certificate chain onto the corresponding ssl or ctx. The pkey argument must be the private key of the X.509 certificate x. If the override argument is 0, then x, pkey and chain are set only if all were not previously set. If override is non-0, then the certificate, private key and chain certs are always set. If pkey is NULL, then the public key of x is used as the private key. This is intended to be used with hardware (via the ENGINE interface) that stores the private key securely, such that it cannot be accessed by OpenSSL. The reference count of the public key is incremented (twice if there is no private key); it is not copied nor duplicated. This allows all private key validations checks to succeed without an actual private key being assigned via SSL_CTX_use_PrivateKey(), etc.

- -

SSL_CTX_use_PrivateKey_ASN1() adds the private key of type pk stored at memory location d (length len) to ctx. SSL_CTX_use_RSAPrivateKey_ASN1() adds the private key of type RSA stored at memory location d (length len) to ctx. SSL_use_PrivateKey_ASN1() and SSL_use_RSAPrivateKey_ASN1() add the private key to ssl.

- -

SSL_CTX_use_PrivateKey_file() adds the first private key found in file to ctx. The formatting type of the private key must be specified from the known types SSL_FILETYPE_PEM, SSL_FILETYPE_ASN1. SSL_CTX_use_RSAPrivateKey_file() adds the first private RSA key found in file to ctx. SSL_use_PrivateKey_file() adds the first private key found in file to ssl; SSL_use_RSAPrivateKey_file() adds the first private RSA key found to ssl.

- -

SSL_CTX_check_private_key() checks the consistency of a private key with the corresponding certificate loaded into ctx. If more than one key/certificate pair (RSA/DSA) is installed, the last item installed will be checked. If e.g. the last item was an RSA certificate or key, the RSA key/certificate pair will be checked. SSL_check_private_key() performs the same check for ssl. If no key/certificate was explicitly added for this ssl, the last item added into ctx will be checked.

- -

NOTES

- -

The internal certificate store of OpenSSL can hold several private key/certificate pairs at a time. The certificate used depends on the cipher selected, see also SSL_CTX_set_cipher_list(3).

- -

When reading certificates and private keys from file, files of type SSL_FILETYPE_ASN1 (also known as DER, binary encoding) can only contain one certificate or private key, consequently SSL_CTX_use_certificate_chain_file() is only applicable to PEM formatting. Files of type SSL_FILETYPE_PEM can contain more than one item.

- -

SSL_CTX_use_certificate_chain_file() adds the first certificate found in the file to the certificate store. The other certificates are added to the store of chain certificates using SSL_CTX_add1_chain_cert(3). Note: versions of OpenSSL before 1.0.2 only had a single certificate chain store for all certificate types, OpenSSL 1.0.2 and later have a separate chain store for each type. SSL_CTX_use_certificate_chain_file() should be used instead of the SSL_CTX_use_certificate_file() function in order to allow the use of complete certificate chains even when no trusted CA storage is used or when the CA issuing the certificate shall not be added to the trusted CA storage.

- -

If additional certificates are needed to complete the chain during the TLS negotiation, CA certificates are additionally looked up in the locations of trusted CA certificates, see SSL_CTX_load_verify_locations(3).

- -

The private keys loaded from file can be encrypted. In order to successfully load encrypted keys, a function returning the passphrase must have been supplied, see SSL_CTX_set_default_passwd_cb(3). (Certificate files might be encrypted as well from the technical point of view, it however does not make sense as the data in the certificate is considered public anyway.)

- -

All of the functions to set a new certificate will replace any existing certificate of the same type that has already been set. Similarly all of the functions to set a new private key will replace any private key that has already been set. Applications should call SSL_CTX_check_private_key(3) or SSL_check_private_key(3) as appropriate after loading a new certificate and private key to confirm that the certificate and key match.

- -

RETURN VALUES

- -

On success, the functions return 1. Otherwise check out the error stack to find out the reason.

- -

SEE ALSO

- -

ssl(7), SSL_new(3), SSL_clear(3), SSL_CTX_load_verify_locations(3), SSL_CTX_set_default_passwd_cb(3), SSL_CTX_set_cipher_list(3), SSL_CTX_set_client_CA_list(3), SSL_CTX_set_client_cert_cb(3), SSL_CTX_add_extra_chain_cert(3)

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_psk_identity_hint.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_psk_identity_hint.html deleted file mode 100644 index 18530de8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_psk_identity_hint.html +++ /dev/null @@ -1,123 +0,0 @@ - - - - -SSL_CTX_use_psk_identity_hint - - - - - - - - - - -

NAME

- -

SSL_psk_server_cb_func, SSL_psk_find_session_cb_func, SSL_CTX_use_psk_identity_hint, SSL_use_psk_identity_hint, SSL_CTX_set_psk_server_callback, SSL_set_psk_server_callback, SSL_CTX_set_psk_find_session_callback, SSL_set_psk_find_session_callback - set PSK identity hint to use

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*SSL_psk_find_session_cb_func)(SSL *ssl,
-                                            const unsigned char *identity,
-                                            size_t identity_len,
-                                            SSL_SESSION **sess);
-
-
-void SSL_CTX_set_psk_find_session_callback(SSL_CTX *ctx,
-                                           SSL_psk_find_session_cb_func cb);
-void SSL_set_psk_find_session_callback(SSL *s, SSL_psk_find_session_cb_func cb);
-
-typedef unsigned int (*SSL_psk_server_cb_func)(SSL *ssl,
-                                               const char *identity,
-                                               unsigned char *psk,
-                                               unsigned int max_psk_len);
-
-int SSL_CTX_use_psk_identity_hint(SSL_CTX *ctx, const char *hint);
-int SSL_use_psk_identity_hint(SSL *ssl, const char *hint);
-
-void SSL_CTX_set_psk_server_callback(SSL_CTX *ctx, SSL_psk_server_cb_func cb);
-void SSL_set_psk_server_callback(SSL *ssl, SSL_psk_server_cb_func cb);
- -

DESCRIPTION

- -

A server application wishing to use TLSv1.3 PSKs should set a callback using either SSL_CTX_set_psk_find_session_callback() or SSL_set_psk_find_session_callback() as appropriate.

- -

The callback function is given a pointer to the SSL connection in ssl and an identity in identity of length identity_len. The callback function should identify an SSL_SESSION object that provides the PSK details and store it in *sess. The SSL_SESSION object should, as a minimum, set the master key, the ciphersuite and the protocol version. See SSL_CTX_set_psk_use_session_callback(3) for details.

- -

It is also possible for the callback to succeed but not supply a PSK. In this case no PSK will be used but the handshake will continue. To do this the callback should return successfully and ensure that *sess is NULL.

- -

Identity hints are not relevant for TLSv1.3. A server application wishing to use PSK ciphersuites for TLSv1.2 and below may call SSL_CTX_use_psk_identity_hint() to set the given NUL-terminated PSK identity hint hint for SSL context object ctx. SSL_use_psk_identity_hint() sets the given NUL-terminated PSK identity hint hint for the SSL connection object ssl. If hint is NULL the current hint from ctx or ssl is deleted.

- -

In the case where PSK identity hint is NULL, the server does not send the ServerKeyExchange message to the client.

- -

A server application wishing to use PSKs for TLSv1.2 and below must provide a callback function which is called when the server receives the ClientKeyExchange message from the client. The purpose of the callback function is to validate the received PSK identity and to fetch the pre-shared key used during the connection setup phase. The callback is set using the functions SSL_CTX_set_psk_server_callback() or SSL_set_psk_server_callback(). The callback function is given the connection in parameter ssl, NUL-terminated PSK identity sent by the client in parameter identity, and a buffer psk of length max_psk_len bytes where the pre-shared key is to be stored.

- -

The callback for use in TLSv1.2 will also work in TLSv1.3 although it is recommended to use SSL_CTX_set_psk_find_session_callback() or SSL_set_psk_find_session_callback() for this purpose instead. If TLSv1.3 has been negotiated then OpenSSL will first check to see if a callback has been set via SSL_CTX_set_psk_find_session_callback() or SSL_set_psk_find_session_callback() and it will use that in preference. If no such callback is present then it will check to see if a callback has been set via SSL_CTX_set_psk_server_callback() or SSL_set_psk_server_callback() and use that. In this case the handshake digest will default to SHA-256 for any returned PSK. TLSv1.3 early data exchanges are possible in PSK connections only with the SSL_psk_find_session_cb_func callback, and are not possible with the SSL_psk_server_cb_func callback.

- -

A connection established via a TLSv1.3 PSK will appear as if session resumption has occurred so that SSL_session_reused(3) will return true.

- -

RETURN VALUES

- -

SSL_CTX_use_psk_identity_hint() and SSL_use_psk_identity_hint() return 1 on success, 0 otherwise.

- -

Return values from the TLSv1.2 and below server callback are interpreted as follows:

- -
- -
0
-
- -

PSK identity was not found. An "unknown_psk_identity" alert message will be sent and the connection setup fails.

- -
-
>0
-
- -

PSK identity was found and the server callback has provided the PSK successfully in parameter psk. Return value is the length of psk in bytes. It is an error to return a value greater than max_psk_len.

- -

If the PSK identity was not found but the callback instructs the protocol to continue anyway, the callback must provide some random data to psk and return the length of the random data, so the connection will fail with decryption_error before it will be finished completely.

- -
-
- -

The SSL_psk_find_session_cb_func callback should return 1 on success or 0 on failure. In the event of failure the connection setup fails.

- -

NOTES

- -

There are no known security issues with sharing the same PSK between TLSv1.2 (or below) and TLSv1.3. However, the RFC has this note of caution:

- -

"While there is no known way in which the same PSK might produce related output in both versions, only limited analysis has been done. Implementations can ensure safety from cross-protocol related output by not reusing PSKs between TLS 1.3 and TLS 1.2."

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_psk_use_session_callback(3), SSL_set_psk_use_session_callback(3)

- -

HISTORY

- -

SSL_CTX_set_psk_find_session_callback() and SSL_set_psk_find_session_callback() were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_serverinfo.html b/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_serverinfo.html deleted file mode 100644 index bc257b61..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_CTX_use_serverinfo.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -SSL_CTX_use_serverinfo - - - - - - - - - - -

NAME

- -

SSL_CTX_use_serverinfo_ex, SSL_CTX_use_serverinfo, SSL_CTX_use_serverinfo_file - use serverinfo extension

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_use_serverinfo_ex(SSL_CTX *ctx, unsigned int version,
-                              const unsigned char *serverinfo,
-                              size_t serverinfo_length);
-
-int SSL_CTX_use_serverinfo(SSL_CTX *ctx, const unsigned char *serverinfo,
-                           size_t serverinfo_length);
-
-int SSL_CTX_use_serverinfo_file(SSL_CTX *ctx, const char *file);
- -

DESCRIPTION

- -

These functions load "serverinfo" TLS extensions into the SSL_CTX. A "serverinfo" extension is returned in response to an empty ClientHello Extension.

- -

SSL_CTX_use_serverinfo_ex() loads one or more serverinfo extensions from a byte array into ctx. The version parameter specifies the format of the byte array provided in *serverinfo which is of length serverinfo_length.

- -

If version is SSL_SERVERINFOV2 then the extensions in the array must consist of a 4-byte context, a 2-byte Extension Type, a 2-byte length, and then length bytes of extension_data. The context and type values have the same meaning as for SSL_CTX_add_custom_ext(3). If serverinfo is being loaded for extensions to be added to a Certificate message, then the extension will only be added for the first certificate in the message (which is always the end-entity certificate).

- -

If version is SSL_SERVERINFOV1 then the extensions in the array must consist of a 2-byte Extension Type, a 2-byte length, and then length bytes of extension_data. The type value has the same meaning as for SSL_CTX_add_custom_ext(3). The following default context value will be used in this case:

- -
SSL_EXT_TLS1_2_AND_BELOW_ONLY | SSL_EXT_CLIENT_HELLO
-| SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_IGNORE_ON_RESUMPTION
- -

SSL_CTX_use_serverinfo() does the same thing as SSL_CTX_use_serverinfo_ex() except that there is no version parameter so a default version of SSL_SERVERINFOV1 is used instead.

- -

SSL_CTX_use_serverinfo_file() loads one or more serverinfo extensions from file into ctx. The extensions must be in PEM format. Each extension must be in a format as described above for SSL_CTX_use_serverinfo_ex(). Each PEM extension name must begin with the phrase "BEGIN SERVERINFOV2 FOR " for SSL_SERVERINFOV2 data or "BEGIN SERVERINFO FOR " for SSL_SERVERINFOV1 data.

- -

If more than one certificate (RSA/DSA) is installed using SSL_CTX_use_certificate(), the serverinfo extension will be loaded into the last certificate installed. If e.g. the last item was an RSA certificate, the loaded serverinfo extension data will be loaded for that certificate. To use the serverinfo extension for multiple certificates, SSL_CTX_use_serverinfo() needs to be called multiple times, once after each time a certificate is loaded via a call to SSL_CTX_use_certificate().

- -

RETURN VALUES

- -

On success, the functions return 1. On failure, the functions return 0. Check out the error stack to find out the reason.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2013-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_free.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_free.html deleted file mode 100644 index 7a4eb15d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_free.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -SSL_SESSION_free - - - - - - - - - - -

NAME

- -

SSL_SESSION_new, SSL_SESSION_dup, SSL_SESSION_up_ref, SSL_SESSION_free - create, free and manage SSL_SESSION structures

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL_SESSION *SSL_SESSION_new(void);
-SSL_SESSION *SSL_SESSION_dup(const SSL_SESSION *src);
-int SSL_SESSION_up_ref(SSL_SESSION *ses);
-void SSL_SESSION_free(SSL_SESSION *session);
- -

DESCRIPTION

- -

SSL_SESSION_new() creates a new SSL_SESSION structure and returns a pointer to it.

- -

SSL_SESSION_dup() creates a new SSL_SESSION structure that is a copy of src. The copy is not owned by any cache that src may have been in.

- -

SSL_SESSION_up_ref() increments the reference count on the given SSL_SESSION structure.

- -

SSL_SESSION_free() decrements the reference count of session and removes the SSL_SESSION structure pointed to by session and frees up the allocated memory, if the reference count has reached 0. If session is NULL nothing is done.

- -

NOTES

- -

SSL_SESSION objects are allocated, when a TLS/SSL handshake operation is successfully completed. Depending on the settings, see SSL_CTX_set_session_cache_mode(3), the SSL_SESSION objects are internally referenced by the SSL_CTX and linked into its session cache. SSL objects may be using the SSL_SESSION object; as a session may be reused, several SSL objects may be using one SSL_SESSION object at the same time. It is therefore crucial to keep the reference count (usage information) correct and not delete a SSL_SESSION object that is still used, as this may lead to program failures due to dangling pointers. These failures may also appear delayed, e.g. when an SSL_SESSION object was completely freed as the reference count incorrectly became 0, but it is still referenced in the internal session cache and the cache list is processed during a SSL_CTX_flush_sessions(3) operation.

- -

SSL_SESSION_free() must only be called for SSL_SESSION objects, for which the reference count was explicitly incremented (e.g. by calling SSL_get1_session(), see SSL_get_session(3)) or when the SSL_SESSION object was generated outside a TLS handshake operation, e.g. by using d2i_SSL_SESSION(3). It must not be called on other SSL_SESSION objects, as this would cause incorrect reference counts and therefore program failures.

- -

RETURN VALUES

- -

SSL_SESSION_new returns a pointer to the newly allocated SSL_SESSION structure or NULL on error.

- -

SSL_SESSION_dup returns a pointer to the new copy or NULL on error.

- -

SSL_SESSION_up_ref returns 1 on success or 0 on error.

- -

SEE ALSO

- -

ssl(7), SSL_get_session(3), SSL_CTX_set_session_cache_mode(3), SSL_CTX_flush_sessions(3), d2i_SSL_SESSION(3)

- -

HISTORY

- -

The SSL_SESSION_dup() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_cipher.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_cipher.html deleted file mode 100644 index a5343e21..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_cipher.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -SSL_SESSION_get0_cipher - - - - - - - - - - -

NAME

- -

SSL_SESSION_get0_cipher, SSL_SESSION_set_cipher - set and retrieve the SSL cipher associated with a session

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const SSL_CIPHER *SSL_SESSION_get0_cipher(const SSL_SESSION *s);
-int SSL_SESSION_set_cipher(SSL_SESSION *s, const SSL_CIPHER *cipher);
- -

DESCRIPTION

- -

SSL_SESSION_get0_cipher() retrieves the cipher that was used by the connection when the session was created, or NULL if it cannot be determined.

- -

The value returned is a pointer to an object maintained within s and should not be released.

- -

SSL_SESSION_set_cipher() can be used to set the ciphersuite associated with the SSL_SESSION s to cipher. For example, this could be used to set up a session based PSK (see SSL_CTX_set_psk_use_session_callback(3)).

- -

RETURN VALUES

- -

SSL_SESSION_get0_cipher() returns the SSL_CIPHER associated with the SSL_SESSION or NULL if it cannot be determined.

- -

SSL_SESSION_set_cipher() returns 1 on success or 0 on failure.

- -

SEE ALSO

- -

ssl(7), d2i_SSL_SESSION(3), SSL_SESSION_get_time(3), SSL_SESSION_get0_hostname(3), SSL_SESSION_free(3), SSL_CTX_set_psk_use_session_callback(3)

- -

HISTORY

- -

The SSL_SESSION_get0_cipher() function was added in OpenSSL 1.1.0. The SSL_SESSION_set_cipher() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2016-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_hostname.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_hostname.html deleted file mode 100644 index 93c32d62..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_hostname.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -SSL_SESSION_get0_hostname - - - - - - - - - - -

NAME

- -

SSL_SESSION_get0_hostname, SSL_SESSION_set1_hostname, SSL_SESSION_get0_alpn_selected, SSL_SESSION_set1_alpn_selected - get and set SNI and ALPN data associated with a session

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_SESSION_get0_hostname(const SSL_SESSION *s);
-int SSL_SESSION_set1_hostname(SSL_SESSION *s, const char *hostname);
-
-void SSL_SESSION_get0_alpn_selected(const SSL_SESSION *s,
-                                    const unsigned char **alpn,
-                                    size_t *len);
-int SSL_SESSION_set1_alpn_selected(SSL_SESSION *s, const unsigned char *alpn,
-                                   size_t len);
- -

DESCRIPTION

- -

SSL_SESSION_get0_hostname() retrieves the SNI value that was sent by the client when the session was created if it was accepted by the server. Otherwise NULL is returned.

- -

The value returned is a pointer to memory maintained within s and should not be free'd.

- -

SSL_SESSION_set1_hostname() sets the SNI value for the hostname to a copy of the string provided in hostname.

- -

SSL_SESSION_get0_alpn_selected() retrieves the selected ALPN protocol for this session and its associated length in bytes. The returned value of *alpn is a pointer to memory maintained within s and should not be free'd.

- -

SSL_SESSION_set1_alpn_selected() sets the ALPN protocol for this session to the value in alpn which should be of length len bytes. A copy of the input value is made, and the caller retains ownership of the memory pointed to by alpn.

- -

RETURN VALUES

- -

SSL_SESSION_get0_hostname() returns either a string or NULL based on if there is the SNI value sent by client.

- -

SSL_SESSION_set1_hostname() returns 1 on success or 0 on error.

- -

SSL_SESSION_set1_alpn_selected() returns 1 on success or 0 on error.

- -

SEE ALSO

- -

ssl(7), d2i_SSL_SESSION(3), SSL_SESSION_get_time(3), SSL_SESSION_free(3)

- -

HISTORY

- -

The SSL_SESSION_set1_hostname(), SSL_SESSION_get0_alpn_selected() and SSL_SESSION_set1_alpn_selected() functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_id_context.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_id_context.html deleted file mode 100644 index 1c8b93a0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_id_context.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -SSL_SESSION_get0_id_context - - - - - - - - - - -

NAME

- -

SSL_SESSION_get0_id_context, SSL_SESSION_set1_id_context - get and set the SSL ID context associated with a session

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const unsigned char *SSL_SESSION_get0_id_context(const SSL_SESSION *s,
-                                                 unsigned int *len);
-int SSL_SESSION_set1_id_context(SSL_SESSION *s, const unsigned char *sid_ctx,
-                               unsigned int sid_ctx_len);
- -

DESCRIPTION

- -

See SSL_CTX_set_session_id_context(3) for further details on session ID contexts.

- -

SSL_SESSION_get0_id_context() returns the ID context associated with the SSL/TLS session s. The length of the ID context is written to *len if len is not NULL.

- -

The value returned is a pointer to an object maintained within s and should not be released.

- -

SSL_SESSION_set1_id_context() takes a copy of the provided ID context given in sid_ctx and associates it with the session s. The length of the ID context is given by sid_ctx_len which must not exceed SSL_MAX_SID_CTX_LENGTH bytes.

- -

RETURN VALUES

- -

SSL_SESSION_set1_id_context() returns 1 on success or 0 on error.

- -

SEE ALSO

- -

ssl(7), SSL_set_session_id_context(3)

- -

HISTORY

- -

The SSL_SESSION_get0_id_context() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_peer.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_peer.html deleted file mode 100644 index 871bd69b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get0_peer.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -SSL_SESSION_get0_peer - - - - - - - - - - -

NAME

- -

SSL_SESSION_get0_peer - get details about peer's certificate for a session

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-X509 *SSL_SESSION_get0_peer(SSL_SESSION *s);
- -

DESCRIPTION

- -

SSL_SESSION_get0_peer() returns the peer certificate associated with the session s or NULL if no peer certificate is available. The caller should not free the returned value (unless X509_up_ref(3) has also been called).

- -

RETURN VALUES

- -

SSL_SESSION_get0_peer() returns a pointer to the peer certificate or NULL if no peer certificate is available.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_compress_id.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_compress_id.html deleted file mode 100644 index b4154636..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_compress_id.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -SSL_SESSION_get_compress_id - - - - - - - - - - -

NAME

- -

SSL_SESSION_get_compress_id - get details about the compression associated with a session

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-unsigned int SSL_SESSION_get_compress_id(const SSL_SESSION *s);
- -

DESCRIPTION

- -

If compression has been negotiated for an ssl session then SSL_SESSION_get_compress_id() will return the id for the compression method or 0 otherwise. The only built-in supported compression method is zlib which has an id of 1.

- -

RETURN VALUES

- -

SSL_SESSION_get_compress_id() returns the id of the compression method or 0 if none.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_protocol_version.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_protocol_version.html deleted file mode 100644 index 5268c54b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_protocol_version.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -SSL_SESSION_get_protocol_version - - - - - - - - - - -

NAME

- -

SSL_SESSION_get_protocol_version, SSL_SESSION_set_protocol_version - get and set the session protocol version

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_SESSION_get_protocol_version(const SSL_SESSION *s);
-int SSL_SESSION_set_protocol_version(SSL_SESSION *s, int version);
- -

DESCRIPTION

- -

SSL_SESSION_get_protocol_version() returns the protocol version number used by session s.

- -

SSL_SESSION_set_protocol_version() sets the protocol version associated with the SSL_SESSION object s to the value version. This value should be a version constant such as TLS1_3_VERSION etc. For example, this could be used to set up a session based PSK (see SSL_CTX_set_psk_use_session_callback(3)).

- -

RETURN VALUES

- -

SSL_SESSION_get_protocol_version() returns a number indicating the protocol version used for the session; this number matches the constants e.g. TLS1_VERSION, TLS1_2_VERSION or TLS1_3_VERSION.

- -

Note that the SSL_SESSION_get_protocol_version() function does not perform a null check on the provided session s pointer.

- -

SSL_SESSION_set_protocol_version() returns 1 on success or 0 on failure.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_psk_use_session_callback(3)

- -

HISTORY

- -

The SSL_SESSION_get_protocol_version() function was added in OpenSSL 1.1.0. The SSL_SESSION_set_protocol_version() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2001-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_time.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_time.html deleted file mode 100644 index ad5b62d7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_get_time.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -SSL_SESSION_get_time - - - - - - - - - - -

NAME

- -

SSL_SESSION_get_time, SSL_SESSION_set_time, SSL_SESSION_get_timeout, SSL_SESSION_set_timeout, SSL_SESSION_get_time_ex, SSL_SESSION_set_time_ex, SSL_get_time, SSL_set_time, SSL_get_timeout, SSL_set_timeout - retrieve and manipulate session time and timeout settings

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_SESSION_get_timeout(const SSL_SESSION *s);
-long SSL_SESSION_set_timeout(SSL_SESSION *s, long tm);
-
-long SSL_get_timeout(const SSL_SESSION *s);
-long SSL_set_timeout(SSL_SESSION *s, long tm);
-
-time_t SSL_SESSION_get_time_ex(const SSL_SESSION *s);
-time_t SSL_SESSION_set_time_ex(SSL_SESSION *s, time_t tm);
- -

The following functions have been deprecated since OpenSSL 3.4, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
long SSL_SESSION_get_time(const SSL_SESSION *s);
-long SSL_SESSION_set_time(SSL_SESSION *s, long tm);
-long SSL_get_time(const SSL_SESSION *s);
-long SSL_set_time(SSL_SESSION *s, long tm);
- -

DESCRIPTION

- -

SSL_SESSION_get_time_ex() returns the time at which the session s was established. The time is given in seconds since the Epoch and therefore compatible to the time delivered by the time() call.

- -

SSL_SESSION_set_time_ex() replaces the creation time of the session s with the chosen value tm.

- -

SSL_SESSION_get_timeout() returns the timeout value set for session s in seconds.

- -

SSL_SESSION_set_timeout() sets the timeout value for session s in seconds to tm.

- -

SSL_SESSION_get_time() and SSL_SESSION_set_time() functions use the long datatype instead of time_t and are therefore deprecated due to not being Y2038-safe on 32 bit systems. Note that such systems still need to be configured to use 64 bit time_t to be able to avoid overflow in system time.

- -

The SSL_get_time(), SSL_set_time(), SSL_get_timeout(), and SSL_set_timeout() functions are synonyms for the SSL_SESSION_*() counterparts.

- -

NOTES

- -

Sessions are expired by examining the creation time and the timeout value. Both are set at creation time of the session to the actual time and the default timeout value at creation, respectively, as set by SSL_CTX_set_timeout(3). Using these functions it is possible to extend or shorten the lifetime of the session.

- -

RETURN VALUES

- -

SSL_SESSION_get_time_ex() and SSL_SESSION_get_timeout() return the currently valid values.

- -

SSL_SESSION_set_time_ex() returns time on success.

- -

SSL_SESSION_set_timeout() returns 1 on success.

- -

If any of the function is passed the NULL pointer for the session s, 0 is returned.

- -

BUGS

- -

The data type long is typically 32 bits on many systems, hence the old functions SSL_SESSION_get_time() and SSL_SESSION_set_time() are not always Y2038 safe.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_timeout(3), SSL_get_default_timeout(3)

- -

HISTORY

- -

The functions SSL_SESSION_get_time_ex() and SSL_SESSION_set_time_ex() were added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_has_ticket.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_has_ticket.html deleted file mode 100644 index ebf36b7a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_has_ticket.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -SSL_SESSION_has_ticket - - - - - - - - - - -

NAME

- -

SSL_SESSION_get0_ticket, SSL_SESSION_has_ticket, SSL_SESSION_get_ticket_lifetime_hint - get details about the ticket associated with a session

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_SESSION_has_ticket(const SSL_SESSION *s);
-unsigned long SSL_SESSION_get_ticket_lifetime_hint(const SSL_SESSION *s);
-void SSL_SESSION_get0_ticket(const SSL_SESSION *s, const unsigned char **tick,
-                             size_t *len);
- -

DESCRIPTION

- -

SSL_SESSION_has_ticket() returns 1 if there is a Session Ticket associated with this session, and 0 otherwise.

- -

SSL_SESSION_get_ticket_lifetime_hint returns the lifetime hint in seconds associated with the session ticket.

- -

SSL_SESSION_get0_ticket obtains a pointer to the ticket associated with a session. The length of the ticket is written to *len. If tick is non NULL then a pointer to the ticket is written to *tick. The pointer is only valid while the connection is in use. The session (and hence the ticket pointer) may also become invalid as a result of a call to SSL_CTX_flush_sessions().

- -

RETURN VALUES

- -

SSL_SESSION_has_ticket() returns 1 if session ticket exists or 0 otherwise.

- -

SSL_SESSION_get_ticket_lifetime_hint() returns the number of seconds.

- -

SEE ALSO

- -

ssl(7), d2i_SSL_SESSION(3), SSL_SESSION_get_time(3), SSL_SESSION_free(3)

- -

HISTORY

- -

The SSL_SESSION_has_ticket(), SSL_SESSION_get_ticket_lifetime_hint() and SSL_SESSION_get0_ticket() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_is_resumable.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_is_resumable.html deleted file mode 100644 index 114306c0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_is_resumable.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -SSL_SESSION_is_resumable - - - - - - - - - - -

NAME

- -

SSL_SESSION_is_resumable - determine whether an SSL_SESSION object can be used for resumption

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_SESSION_is_resumable(const SSL_SESSION *s);
- -

DESCRIPTION

- -

SSL_SESSION_is_resumable() determines whether an SSL_SESSION object can be used to resume a session or not. Returns 1 if it can or 0 if not. Note that attempting to resume with a non-resumable session will result in a full handshake.

- -

RETURN VALUES

- -

SSL_SESSION_is_resumable() returns 1 if the session is resumable or 0 otherwise.

- -

SEE ALSO

- -

ssl(7), SSL_get_session(3), SSL_CTX_sess_set_new_cb(3)

- -

HISTORY

- -

The SSL_SESSION_is_resumable() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_print.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_print.html deleted file mode 100644 index 3fd87b1f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_print.html +++ /dev/null @@ -1,62 +0,0 @@ - - - - -SSL_SESSION_print - - - - - - - - - - -

NAME

- -

SSL_SESSION_print, SSL_SESSION_print_fp, SSL_SESSION_print_keylog - printf information about a session

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_SESSION_print(BIO *fp, const SSL_SESSION *ses);
-int SSL_SESSION_print_fp(FILE *fp, const SSL_SESSION *ses);
-int SSL_SESSION_print_keylog(BIO *bp, const SSL_SESSION *x);
- -

DESCRIPTION

- -

SSL_SESSION_print() prints summary information about the session provided in ses to the BIO fp.

- -

SSL_SESSION_print_fp() does the same as SSL_SESSION_print() except it prints it to the FILE fp.

- -

SSL_SESSION_print_keylog() prints session information to the provided BIO <bp> in NSS keylog format.

- -

RETURN VALUES

- -

SSL_SESSION_print(), SSL_SESSION_print_fp() and SSL_SESSION_print_keylog return 1 on success or 0 on error.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_set1_id.html b/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_set1_id.html deleted file mode 100644 index 5722e119..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_SESSION_set1_id.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -SSL_SESSION_set1_id - - - - - - - - - - -

NAME

- -

SSL_SESSION_get_id, SSL_SESSION_set1_id - get and set the SSL session ID

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const unsigned char *SSL_SESSION_get_id(const SSL_SESSION *s,
-                                        unsigned int *len);
-int SSL_SESSION_set1_id(SSL_SESSION *s, const unsigned char *sid,
-                        unsigned int sid_len);
- -

DESCRIPTION

- -

SSL_SESSION_get_id() returns a pointer to the internal session id value for the session s. The length of the id in bytes is stored in *len. The length may be 0. The caller should not free the returned pointer directly.

- -

SSL_SESSION_set1_id() sets the session ID for the ssl SSL/TLS session to sid of length sid_len.

- -

RETURN VALUES

- -

SSL_SESSION_get_id() returns a pointer to the session id value. SSL_SESSION_set1_id() returns 1 for success and 0 for failure, for example if the supplied session ID length exceeds SSL_MAX_SSL_SESSION_ID_LENGTH.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

The SSL_SESSION_set1_id() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_accept.html b/openssl-install/share/doc/openssl/html/man3/SSL_accept.html deleted file mode 100644 index a970cfd4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_accept.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -SSL_accept - - - - - - - - - - -

NAME

- -

SSL_accept - wait for a TLS/SSL client to initiate a TLS/SSL handshake

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_accept(SSL *ssl);
- -

DESCRIPTION

- -

SSL_accept() waits for a TLS/SSL client to initiate the TLS/SSL handshake. The communication channel must already have been set and assigned to the ssl by setting an underlying BIO.

- -

NOTES

- -

The behaviour of SSL_accept() depends on the underlying BIO.

- -

If the underlying BIO is blocking, SSL_accept() will only return once the handshake has been finished or an error occurred.

- -

If the underlying BIO is nonblocking, SSL_accept() will also return when the underlying BIO could not satisfy the needs of SSL_accept() to continue the handshake, indicating the problem by the return value -1. In this case a call to SSL_get_error() with the return value of SSL_accept() will yield SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE. The calling process then must repeat the call after taking appropriate action to satisfy the needs of SSL_accept(). The action depends on the underlying BIO. When using a nonblocking socket, nothing is to be done, but select() can be used to check for the required condition. When using a buffering BIO, like a BIO pair, data must be written into or retrieved out of the BIO before being able to continue.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0
-
- -

The TLS/SSL handshake was not successful but was shut down controlled and by the specifications of the TLS/SSL protocol. Call SSL_get_error() with the return value ret to find out the reason.

- -
-
1
-
- -

The TLS/SSL handshake was successfully completed, a TLS/SSL connection has been established.

- -
-
<0
-
- -

The TLS/SSL handshake was not successful because a fatal error occurred either at the protocol level or a connection failure occurred. The shutdown was not clean. It can also occur if action is needed to continue the operation for nonblocking BIOs. Call SSL_get_error() with the return value ret to find out the reason.

- -
-
- -

SEE ALSO

- -

SSL_get_error(3), SSL_connect(3), SSL_shutdown(3), ssl(7), bio(7), SSL_set_connect_state(3), SSL_do_handshake(3), SSL_CTX_new(3)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_accept_stream.html b/openssl-install/share/doc/openssl/html/man3/SSL_accept_stream.html deleted file mode 100644 index 32f866a6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_accept_stream.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -SSL_accept_stream - - - - - - - - - - -

NAME

- -

SSL_accept_stream, SSL_get_accept_stream_queue_len, SSL_ACCEPT_STREAM_NO_BLOCK - accept an incoming QUIC stream from a QUIC peer

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_ACCEPT_STREAM_NO_BLOCK
-
-SSL *SSL_accept_stream(SSL *ssl, uint64_t flags);
-
-size_t SSL_get_accept_stream_queue_len(SSL *ssl);
- -

DESCRIPTION

- -

The SSL_accept_stream() function attempts to dequeue an incoming stream from the given QUIC connection SSL object and returns the newly allocated QUIC stream SSL object.

- -

If the queue of incoming streams is empty, this function returns NULL (in nonblocking mode) or waits for an incoming stream (in blocking mode). This function may still return NULL in blocking mode, for example if the underlying connection is terminated.

- -

The caller is responsible for managing the lifetime of the returned QUIC stream SSL object; for more information, see SSL_free(3).

- -

This function will block if the QUIC connection SSL object is configured in blocking mode (see SSL_set_blocking_mode(3)), but this may be bypassed by passing the flag SSL_ACCEPT_STREAM_NO_BLOCK in flags. If this flag is set, this function never blocks.

- -

Calling SSL_accept_stream() if there is no default stream already present inhibits the future creation of a default stream. See openssl-quic(7).

- -

SSL_get_accept_stream_queue_len() returns the number of incoming streams currently waiting in the accept queue.

- -

These functions can be used from multiple threads for the same QUIC connection.

- -

Depending on whether default stream functionality is being used, it may be necessary to explicitly configure the incoming stream policy before streams can be accepted; see SSL_set_incoming_stream_policy(3). See also "MODES OF OPERATION" in openssl-quic(7) for more information on default stream functionality.

- -

RETURN VALUES

- -

SSL_accept_stream() returns a newly allocated QUIC stream SSL object, or NULL if no new incoming streams are available, or if the connection has been terminated, or if called on a SSL object other than a QUIC connection SSL object. SSL_get_error(3) can be used to obtain further information in this case.

- -

SSL_get_accept_stream_queue_len() returns the number of incoming streams currently waiting in the accept queue, or 0 if called on a SSL object other than a QUIC connection SSL object.

- -

SEE ALSO

- -

"MODES OF OPERATION" in openssl-quic(7), SSL_new_stream(3), SSL_set_blocking_mode(3), SSL_free(3)

- -

HISTORY

- -

SSL_accept_stream() and SSL_get_accept_stream_queue_len() were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_alert_type_string.html b/openssl-install/share/doc/openssl/html/man3/SSL_alert_type_string.html deleted file mode 100644 index 8571b758..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_alert_type_string.html +++ /dev/null @@ -1,255 +0,0 @@ - - - - -SSL_alert_type_string - - - - - - - - - - -

NAME

- -

SSL_alert_type_string, SSL_alert_type_string_long, SSL_alert_desc_string, SSL_alert_desc_string_long - get textual description of alert information

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_alert_type_string(int value);
-const char *SSL_alert_type_string_long(int value);
-
-const char *SSL_alert_desc_string(int value);
-const char *SSL_alert_desc_string_long(int value);
- -

DESCRIPTION

- -

SSL_alert_type_string() returns a one letter string indicating the type of the alert specified by value.

- -

SSL_alert_type_string_long() returns a string indicating the type of the alert specified by value.

- -

SSL_alert_desc_string() returns a two letter string as a short form describing the reason of the alert specified by value.

- -

SSL_alert_desc_string_long() returns a string describing the reason of the alert specified by value.

- -

NOTES

- -

When one side of an SSL/TLS communication wants to inform the peer about a special situation, it sends an alert. The alert is sent as a special message and does not influence the normal data stream (unless its contents results in the communication being canceled).

- -

A warning alert is sent, when a non-fatal error condition occurs. The "close notify" alert is sent as a warning alert. Other examples for non-fatal errors are certificate errors ("certificate expired", "unsupported certificate"), for which a warning alert may be sent. (The sending party may however decide to send a fatal error.) The receiving side may cancel the connection on reception of a warning alert on it discretion.

- -

Several alert messages must be sent as fatal alert messages as specified by the TLS RFC. A fatal alert always leads to a connection abort.

- -

RETURN VALUES

- -

The following strings can occur for SSL_alert_type_string() or SSL_alert_type_string_long():

- -
- -
"W"/"warning"
-
- -
-
"F"/"fatal"
-
- -
-
"U"/"unknown"
-
- -

This indicates that no support is available for this alert type. Probably value does not contain a correct alert message.

- -
-
- -

The following strings can occur for SSL_alert_desc_string() or SSL_alert_desc_string_long():

- -
- -
"CN"/"close notify"
-
- -

The connection shall be closed. This is a warning alert.

- -
-
"UM"/"unexpected message"
-
- -

An inappropriate message was received. This alert is always fatal and should never be observed in communication between proper implementations.

- -
-
"BM"/"bad record mac"
-
- -

This alert is returned if a record is received with an incorrect MAC. This message is always fatal.

- -
-
"DF"/"decompression failure"
-
- -

The decompression function received improper input (e.g. data that would expand to excessive length). This message is always fatal.

- -
-
"HF"/"handshake failure"
-
- -

Reception of a handshake_failure alert message indicates that the sender was unable to negotiate an acceptable set of security parameters given the options available. This is a fatal error.

- -
-
"NC"/"no certificate"
-
- -

A client, that was asked to send a certificate, does not send a certificate (SSLv3 only).

- -
-
"BC"/"bad certificate"
-
- -

A certificate was corrupt, contained signatures that did not verify correctly, etc

- -
-
"UC"/"unsupported certificate"
-
- -

A certificate was of an unsupported type.

- -
-
"CR"/"certificate revoked"
-
- -

A certificate was revoked by its signer.

- -
-
"CE"/"certificate expired"
-
- -

A certificate has expired or is not currently valid.

- -
-
"CU"/"certificate unknown"
-
- -

Some other (unspecified) issue arose in processing the certificate, rendering it unacceptable.

- -
-
"IP"/"illegal parameter"
-
- -

A field in the handshake was out of range or inconsistent with other fields. This is always fatal.

- -
-
"DC"/"decryption failed"
-
- -

A TLSCiphertext decrypted in an invalid way: either it wasn't an even multiple of the block length or its padding values, when checked, weren't correct. This message is always fatal.

- -
-
"RO"/"record overflow"
-
- -

A TLSCiphertext record was received which had a length more than 2^14+2048 bytes, or a record decrypted to a TLSCompressed record with more than 2^14+1024 bytes. This message is always fatal.

- -
-
"CA"/"unknown CA"
-
- -

A valid certificate chain or partial chain was received, but the certificate was not accepted because the CA certificate could not be located or couldn't be matched with a known, trusted CA. This message is always fatal.

- -
-
"AD"/"access denied"
-
- -

A valid certificate was received, but when access control was applied, the sender decided not to proceed with negotiation. This message is always fatal.

- -
-
"DE"/"decode error"
-
- -

A message could not be decoded because some field was out of the specified range or the length of the message was incorrect. This message is always fatal.

- -
-
"CY"/"decrypt error"
-
- -

A handshake cryptographic operation failed, including being unable to correctly verify a signature, decrypt a key exchange, or validate a finished message.

- -
-
"ER"/"export restriction"
-
- -

A negotiation not in compliance with export restrictions was detected; for example, attempting to transfer a 1024 bit ephemeral RSA key for the RSA_EXPORT handshake method. This message is always fatal.

- -
-
"PV"/"protocol version"
-
- -

The protocol version the client has attempted to negotiate is recognized, but not supported. (For example, old protocol versions might be avoided for security reasons). This message is always fatal.

- -
-
"IS"/"insufficient security"
-
- -

Returned instead of handshake_failure when a negotiation has failed specifically because the server requires ciphers more secure than those supported by the client. This message is always fatal.

- -
-
"IE"/"internal error"
-
- -

An internal error unrelated to the peer or the correctness of the protocol makes it impossible to continue (such as a memory allocation failure). This message is always fatal.

- -
-
"US"/"user canceled"
-
- -

This handshake is being canceled for some reason unrelated to a protocol failure. If the user cancels an operation after the handshake is complete, just closing the connection by sending a close_notify is more appropriate. This alert should be followed by a close_notify. This message is generally a warning.

- -
-
"NR"/"no renegotiation"
-
- -

Sent by the client in response to a hello request or by the server in response to a client hello after initial handshaking. Either of these would normally lead to renegotiation; when that is not appropriate, the recipient should respond with this alert; at that point, the original requester can decide whether to proceed with the connection. One case where this would be appropriate would be where a server has spawned a process to satisfy a request; the process might receive security parameters (key length, authentication, etc.) at startup and it might be difficult to communicate changes to these parameters after that point. This message is always a warning.

- -
-
"UP"/"unknown PSK identity"
-
- -

Sent by the server to indicate that it does not recognize a PSK identity or an SRP identity.

- -
-
"UK"/"unknown"
-
- -

This indicates that no description is available for this alert type. Probably value does not contain a correct alert message.

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_info_callback(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_alloc_buffers.html b/openssl-install/share/doc/openssl/html/man3/SSL_alloc_buffers.html deleted file mode 100644 index 6f87d8cc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_alloc_buffers.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -SSL_alloc_buffers - - - - - - - - - - -

NAME

- -

SSL_free_buffers, SSL_alloc_buffers - manage SSL structure buffers

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_free_buffers(SSL *ssl);
-int SSL_alloc_buffers(SSL *ssl);
- -

DESCRIPTION

- -

SSL_free_buffers() frees the read and write buffers of the given ssl. SSL_alloc_buffers() allocates the read and write buffers of the given ssl.

- -

The SSL_MODE_RELEASE_BUFFERS mode releases read or write buffers whenever the buffers have been drained. These functions allow applications to manually control when buffers are freed and allocated.

- -

After freeing the buffers, the buffers are automatically reallocated upon a new read or write. The SSL_alloc_buffers() does not need to be called, but can be used to make sure the buffers are preallocated. This can be used to avoid allocation during data processing or with CRYPTO_set_mem_functions() to control where and how buffers are allocated.

- -

These functions are no-ops when used with QUIC SSL objects. For QUIC, SSL_free_buffers() always fails, and SSL_alloc_buffers() always succeeds.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0 (Failure)
-
- -

The SSL_free_buffers() function returns 0 when there is pending data to be read or written. The SSL_alloc_buffers() function returns 0 when there is an allocation failure.

- -
-
1 (Success)
-
- -

The SSL_free_buffers() function returns 1 if the buffers have been freed. This value is also returned if the buffers had been freed before calling SSL_free_buffers(). The SSL_alloc_buffers() function returns 1 if the buffers have been allocated. This value is also returned if the buffers had been allocated before calling SSL_alloc_buffers().

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_free(3), SSL_clear(3), SSL_new(3), SSL_CTX_set_mode(3), CRYPTO_set_mem_functions(3)

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_check_chain.html b/openssl-install/share/doc/openssl/html/man3/SSL_check_chain.html deleted file mode 100644 index 0048c6bc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_check_chain.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -SSL_check_chain - - - - - - - - - - -

NAME

- -

SSL_check_chain - check certificate chain suitability

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain);
- -

DESCRIPTION

- -

SSL_check_chain() checks whether certificate x, private key pk and certificate chain chain is suitable for use with the current session s.

- -

RETURN VALUES

- -

SSL_check_chain() returns a bitmap of flags indicating the validity of the chain.

- -

CERT_PKEY_VALID: the chain can be used with the current session. If this flag is not set then the certificate will never be used even if the application tries to set it because it is inconsistent with the peer preferences.

- -

CERT_PKEY_SIGN: the EE key can be used for signing.

- -

CERT_PKEY_EE_SIGNATURE: the signature algorithm of the EE certificate is acceptable.

- -

CERT_PKEY_CA_SIGNATURE: the signature algorithms of all CA certificates are acceptable.

- -

CERT_PKEY_EE_PARAM: the parameters of the end entity certificate are acceptable (e.g. it is a supported curve).

- -

CERT_PKEY_CA_PARAM: the parameters of all CA certificates are acceptable.

- -

CERT_PKEY_EXPLICIT_SIGN: the end entity certificate algorithm can be used explicitly for signing (i.e. it is mentioned in the signature algorithms extension).

- -

CERT_PKEY_ISSUER_NAME: the issuer name is acceptable. This is only meaningful for client authentication.

- -

CERT_PKEY_CERT_TYPE: the certificate type is acceptable. Only meaningful for client authentication.

- -

CERT_PKEY_SUITEB: chain is suitable for Suite B use.

- -

NOTES

- -

SSL_check_chain() must be called in servers after a client hello message or in clients after a certificate request message. It will typically be called in the certificate callback.

- -

An application wishing to support multiple certificate chains may call this function on each chain in turn: starting with the one it considers the most secure. It could then use the chain of the first set which returns suitable flags.

- -

As a minimum the flag CERT_PKEY_VALID must be set for a chain to be usable. An application supporting multiple chains with different CA signature algorithms may also wish to check CERT_PKEY_CA_SIGNATURE too. If no chain is suitable a server should fall back to the most secure chain which sets CERT_PKEY_VALID.

- -

The validity of a chain is determined by checking if it matches a supported signature algorithm, supported curves and in the case of client authentication certificate types and issuer names.

- -

Since the supported signature algorithms extension is only used in TLS 1.2, TLS 1.3 and DTLS 1.2 the results for earlier versions of TLS and DTLS may not be very useful. Applications may wish to specify a different "legacy" chain for earlier versions of TLS or DTLS.

- -

SEE ALSO

- -

SSL_CTX_set_cert_cb(3), ssl(7)

- -

COPYRIGHT

- -

Copyright 2015-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_clear.html b/openssl-install/share/doc/openssl/html/man3/SSL_clear.html deleted file mode 100644 index 81d302ff..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_clear.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -SSL_clear - - - - - - - - - - -

NAME

- -

SSL_clear - reset SSL object to allow another connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_clear(SSL *ssl);
- -

DESCRIPTION

- -

Reset ssl to allow another connection. All settings (method, ciphers, BIOs) are kept.

- -

NOTES

- -

SSL_clear is used to prepare an SSL object for a new connection. While all settings are kept, a side effect is the handling of the current SSL session. If a session is still open, it is considered bad and will be removed from the session cache, as required by RFC2246. A session is considered open, if SSL_shutdown(3) was not called for the connection or at least SSL_set_shutdown(3) was used to set the SSL_SENT_SHUTDOWN state.

- -

If a session was closed cleanly, the session object will be kept and all settings corresponding. This explicitly means, that e.g. the special method used during the session will be kept for the next handshake. So if the session was a TLSv1 session, a SSL client object will use a TLSv1 client method for the next handshake and a SSL server object will use a TLSv1 server method, even if TLS_*_methods were chosen on startup. This will might lead to connection failures (see SSL_new(3)) for a description of the method's properties.

- -

This function is not supported on QUIC SSL objects and returns failure if called on such an object.

- -

WARNINGS

- -

SSL_clear() resets the SSL object to allow for another connection. The reset operation however keeps several settings of the last sessions (some of these settings were made automatically during the last handshake). It only makes sense for a new connection with the exact same peer that shares these settings, and may fail if that peer changes its settings between connections. Use the sequence SSL_get_session(3); SSL_new(3); SSL_set_session(3); SSL_free(3) instead to avoid such failures (or simply SSL_free(3); SSL_new(3) if session reuse is not desired).

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0
-
- -

The SSL_clear() operation could not be performed. Check the error stack to find out the reason.

- -
-
1
-
- -

The SSL_clear() operation was successful.

- -
-
- -

SSL_new(3), SSL_free(3), SSL_shutdown(3), SSL_set_shutdown(3), SSL_CTX_set_options(3), ssl(7), SSL_CTX_set_client_cert_cb(3)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_connect.html b/openssl-install/share/doc/openssl/html/man3/SSL_connect.html deleted file mode 100644 index 36f8528c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_connect.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -SSL_connect - - - - - - - - - - -

NAME

- -

SSL_connect - initiate the TLS/SSL handshake with an TLS/SSL server

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_connect(SSL *ssl);
- -

DESCRIPTION

- -

SSL_connect() initiates the TLS/SSL handshake with a server. The communication channel must already have been set and assigned to the ssl by setting an underlying BIO.

- -

NOTES

- -

The behaviour of SSL_connect() depends on the underlying BIO.

- -

If the underlying BIO is blocking, SSL_connect() will only return once the handshake has been finished or an error occurred.

- -

If the underlying BIO is nonblocking, SSL_connect() will also return when the underlying BIO could not satisfy the needs of SSL_connect() to continue the handshake, indicating the problem by the return value -1. In this case a call to SSL_get_error() with the return value of SSL_connect() will yield SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE. The calling process then must repeat the call after taking appropriate action to satisfy the needs of SSL_connect(). The action depends on the underlying BIO. When using a nonblocking socket, nothing is to be done, but select() can be used to check for the required condition. When using a buffering BIO, like a BIO pair, data must be written into or retrieved out of the BIO before being able to continue.

- -

Many systems implement Nagle's algorithm by default which means that it will buffer outgoing TCP data if a TCP packet has already been sent for which no corresponding ACK has been received yet from the peer. This can have performance impacts after a successful TLSv1.3 handshake or a successful TLSv1.2 (or below) resumption handshake, because the last peer to communicate in the handshake is the client. If the client is also the first to send application data (as is typical for many protocols) then this data could be buffered until an ACK has been received for the final handshake message.

- -

The TCP_NODELAY socket option is often available to disable Nagle's algorithm. If an application opts to disable Nagle's algorithm consideration should be given to turning it back on again later if appropriate. The helper function BIO_set_tcp_ndelay() can be used to turn on or off the TCP_NODELAY option.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0
-
- -

The TLS/SSL handshake was not successful but was shut down controlled and by the specifications of the TLS/SSL protocol. Call SSL_get_error() with the return value ret to find out the reason.

- -
-
1
-
- -

The TLS/SSL handshake was successfully completed, a TLS/SSL connection has been established.

- -
-
<0
-
- -

The TLS/SSL handshake was not successful, because a fatal error occurred either at the protocol level or a connection failure occurred. The shutdown was not clean. It can also occur if action is needed to continue the operation for nonblocking BIOs. Call SSL_get_error() with the return value ret to find out the reason.

- -
-
- -

SEE ALSO

- -

SSL_get_error(3), SSL_accept(3), SSL_shutdown(3), ssl(7), bio(7), SSL_set_connect_state(3), SSL_do_handshake(3), SSL_CTX_new(3)

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_do_handshake.html b/openssl-install/share/doc/openssl/html/man3/SSL_do_handshake.html deleted file mode 100644 index e7404469..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_do_handshake.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -SSL_do_handshake - - - - - - - - - - -

NAME

- -

SSL_do_handshake - perform a TLS/SSL handshake

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_do_handshake(SSL *ssl);
- -

DESCRIPTION

- -

SSL_do_handshake() will wait for a SSL/TLS handshake to take place. If the connection is in client mode, the handshake will be started. The handshake routines may have to be explicitly set in advance using either SSL_set_connect_state(3) or SSL_set_accept_state(3).

- -

NOTES

- -

The behaviour of SSL_do_handshake() depends on the underlying BIO.

- -

If the underlying BIO is blocking, SSL_do_handshake() will only return once the handshake has been finished or an error occurred.

- -

If the underlying BIO is nonblocking, SSL_do_handshake() will also return when the underlying BIO could not satisfy the needs of SSL_do_handshake() to continue the handshake. In this case a call to SSL_get_error() with the return value of SSL_do_handshake() will yield SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE. The calling process then must repeat the call after taking appropriate action to satisfy the needs of SSL_do_handshake(). The action depends on the underlying BIO. When using a nonblocking socket, nothing is to be done, but select() can be used to check for the required condition. When using a buffering BIO, like a BIO pair, data must be written into or retrieved out of the BIO before being able to continue.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0
-
- -

The TLS/SSL handshake was not successful but was shut down controlled and by the specifications of the TLS/SSL protocol. Call SSL_get_error() with the return value ret to find out the reason.

- -
-
1
-
- -

The TLS/SSL handshake was successfully completed, a TLS/SSL connection has been established.

- -
-
<0
-
- -

The TLS/SSL handshake was not successful because a fatal error occurred either at the protocol level or a connection failure occurred. The shutdown was not clean. It can also occur if action is needed to continue the operation for nonblocking BIOs. Call SSL_get_error() with the return value ret to find out the reason.

- -
-
- -

SEE ALSO

- -

SSL_get_error(3), SSL_connect(3), SSL_accept(3), ssl(7), bio(7), SSL_set_connect_state(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_export_keying_material.html b/openssl-install/share/doc/openssl/html/man3/SSL_export_keying_material.html deleted file mode 100644 index dd5d3c09..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_export_keying_material.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -SSL_export_keying_material - - - - - - - - - - -

NAME

- -

SSL_export_keying_material, SSL_export_keying_material_early - obtain keying material for application use

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_export_keying_material(SSL *s, unsigned char *out, size_t olen,
-                               const char *label, size_t llen,
-                               const unsigned char *context,
-                               size_t contextlen, int use_context);
-
-int SSL_export_keying_material_early(SSL *s, unsigned char *out, size_t olen,
-                                     const char *label, size_t llen,
-                                     const unsigned char *context,
-                                     size_t contextlen);
- -

DESCRIPTION

- -

During the creation of a TLS or DTLS connection shared keying material is established between the two endpoints. The functions SSL_export_keying_material() and SSL_export_keying_material_early() enable an application to use some of this keying material for its own purposes in accordance with RFC5705 (for TLSv1.2 and below) or RFC8446 (for TLSv1.3).

- -

SSL_export_keying_material() derives keying material using the exporter_master_secret established in the handshake.

- -

SSL_export_keying_material_early() is only usable with TLSv1.3, and derives keying material using the early_exporter_master_secret (as defined in the TLS 1.3 RFC). For the client, the early_exporter_master_secret is only available when the client attempts to send 0-RTT data. For the server, it is only available when the server accepts 0-RTT data.

- -

An application may need to securely establish the context within which this keying material will be used. For example this may include identifiers for the application session, application algorithms or parameters, or the lifetime of the context. The context value is left to the application but must be the same on both sides of the communication.

- -

For a given SSL connection s, olen bytes of data will be written to out. The application specific context should be supplied in the location pointed to by context and should be contextlen bytes long. Provision of a context is optional. If the context should be omitted entirely then use_context should be set to 0. Otherwise it should be any other value. If use_context is 0 then the values of context and contextlen are ignored. Note that in TLSv1.2 and below a zero length context is treated differently from no context at all, and will result in different keying material being returned. In TLSv1.3 a zero length context is that same as no context at all and will result in the same keying material being returned.

- -

An application specific label should be provided in the location pointed to by label and should be llen bytes long. Typically this will be a value from the IANA Exporter Label Registry (https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#exporter-labels). Alternatively labels beginning with "EXPERIMENTAL" are permitted by the standard to be used without registration. TLSv1.3 imposes a maximum label length of 249 bytes.

- -

Note that this function is only defined for TLSv1.0 and above, and DTLSv1.0 and above. Attempting to use it in SSLv3 will result in an error.

- -

RETURN VALUES

- -

SSL_export_keying_material() returns 0 or -1 on failure or 1 on success.

- -

SSL_export_keying_material_early() returns 0 on failure or 1 on success.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

The SSL_export_keying_material_early() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_extension_supported.html b/openssl-install/share/doc/openssl/html/man3/SSL_extension_supported.html deleted file mode 100644 index 483e08d7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_extension_supported.html +++ /dev/null @@ -1,266 +0,0 @@ - - - - -SSL_extension_supported - - - - - - - - - - -

NAME

- -

SSL_extension_supported, SSL_custom_ext_add_cb_ex, SSL_custom_ext_free_cb_ex, SSL_custom_ext_parse_cb_ex, SSL_CTX_add_custom_ext, SSL_CTX_add_client_custom_ext, SSL_CTX_add_server_custom_ext, custom_ext_add_cb, custom_ext_free_cb, custom_ext_parse_cb - custom TLS extension handling

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*SSL_custom_ext_add_cb_ex)(SSL *s, unsigned int ext_type,
-                                        unsigned int context,
-                                        const unsigned char **out,
-                                        size_t *outlen, X509 *x,
-                                        size_t chainidx, int *al,
-                                        void *add_arg);
-
-typedef void (*SSL_custom_ext_free_cb_ex)(SSL *s, unsigned int ext_type,
-                                          unsigned int context,
-                                          const unsigned char *out,
-                                          void *add_arg);
-
-typedef int (*SSL_custom_ext_parse_cb_ex)(SSL *s, unsigned int ext_type,
-                                          unsigned int context,
-                                          const unsigned char *in,
-                                          size_t inlen, X509 *x,
-                                          size_t chainidx, int *al,
-                                          void *parse_arg);
-
-int SSL_CTX_add_custom_ext(SSL_CTX *ctx, unsigned int ext_type,
-                           unsigned int context,
-                           SSL_custom_ext_add_cb_ex add_cb,
-                           SSL_custom_ext_free_cb_ex free_cb,
-                           void *add_arg,
-                           SSL_custom_ext_parse_cb_ex parse_cb,
-                           void *parse_arg);
-
-typedef int (*custom_ext_add_cb)(SSL *s, unsigned int ext_type,
-                                 const unsigned char **out,
-                                 size_t *outlen, int *al,
-                                 void *add_arg);
-
-typedef void (*custom_ext_free_cb)(SSL *s, unsigned int ext_type,
-                                   const unsigned char *out,
-                                   void *add_arg);
-
-typedef int (*custom_ext_parse_cb)(SSL *s, unsigned int ext_type,
-                                   const unsigned char *in,
-                                   size_t inlen, int *al,
-                                   void *parse_arg);
-
-int SSL_CTX_add_client_custom_ext(SSL_CTX *ctx, unsigned int ext_type,
-                                  custom_ext_add_cb add_cb,
-                                  custom_ext_free_cb free_cb, void *add_arg,
-                                  custom_ext_parse_cb parse_cb,
-                                  void *parse_arg);
-
-int SSL_CTX_add_server_custom_ext(SSL_CTX *ctx, unsigned int ext_type,
-                                  custom_ext_add_cb add_cb,
-                                  custom_ext_free_cb free_cb, void *add_arg,
-                                  custom_ext_parse_cb parse_cb,
-                                  void *parse_arg);
-
-int SSL_extension_supported(unsigned int ext_type);
- -

DESCRIPTION

- -

SSL_CTX_add_custom_ext() adds a custom extension for a TLS/DTLS client or server for all supported protocol versions with extension type ext_type and callbacks add_cb, free_cb and parse_cb (see the "EXTENSION CALLBACKS" section below). The context value determines which messages and under what conditions the extension will be added/parsed (see the "EXTENSION CONTEXTS" section below).

- -

SSL_CTX_add_client_custom_ext() adds a custom extension for a TLS/DTLS client with extension type ext_type and callbacks add_cb, free_cb and parse_cb. This function is similar to SSL_CTX_add_custom_ext() except it only applies to clients, uses the older style of callbacks, and implicitly sets the context value to:

- -
SSL_EXT_TLS1_2_AND_BELOW_ONLY | SSL_EXT_CLIENT_HELLO
-| SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_IGNORE_ON_RESUMPTION
- -

SSL_CTX_add_server_custom_ext() adds a custom extension for a TLS/DTLS server with extension type ext_type and callbacks add_cb, free_cb and parse_cb. This function is similar to SSL_CTX_add_custom_ext() except it only applies to servers, uses the older style of callbacks, and implicitly sets the context value to the same as for SSL_CTX_add_client_custom_ext() above.

- -

The ext_type parameter corresponds to the extension_type field of RFC5246 et al. It is not a NID. In all cases the extension type must not be handled by OpenSSL internally or an error occurs.

- -

SSL_extension_supported() returns 1 if the extension ext_type is handled internally by OpenSSL and 0 otherwise.

- -

EXTENSION CALLBACKS

- -

The callback add_cb is called to send custom extension data to be included in various TLS messages. The ext_type parameter is set to the extension type which will be added and add_arg to the value set when the extension handler was added. When using the new style callbacks the context parameter will indicate which message is currently being constructed e.g. for the ClientHello it will be set to SSL_EXT_CLIENT_HELLO.

- -

If the application wishes to include the extension ext_type it should set *out to the extension data, set *outlen to the length of the extension data and return 1.

- -

If the add_cb does not wish to include the extension it must return 0.

- -

If add_cb returns -1 a fatal handshake error occurs using the TLS alert value specified in *al.

- -

When constructing the ClientHello, if add_cb is set to NULL a zero length extension is added for ext_type. For all other messages if add_cb is set to NULL then no extension is added.

- -

When constructing a Certificate message the callback will be called for each certificate in the message. The x parameter will indicate the current certificate and the chainidx parameter will indicate the position of the certificate in the message. The first certificate is always the end entity certificate and has a chainidx value of 0. The certificates are in the order that they were received in the Certificate message.

- -

For all messages except the ServerHello and EncryptedExtensions every registered add_cb is always called to see if the application wishes to add an extension (as long as all requirements of the specified context are met).

- -

For the ServerHello and EncryptedExtension messages every registered add_cb is called once if and only if the requirements of the specified context are met and the corresponding extension was received in the ClientHello. That is, if no corresponding extension was received in the ClientHello then add_cb will not be called.

- -

If an extension is added (that is add_cb returns 1) free_cb is called (if it is set) with the value of out set by the add callback. It can be used to free up any dynamic extension data set by add_cb. Since out is constant (to permit use of constant data in add_cb) applications may need to cast away const to free the data.

- -

The callback parse_cb receives data for TLS extensions. The callback is only called if the extension is present and relevant for the context (see "EXTENSION CONTEXTS" below).

- -

The extension data consists of inlen bytes in the buffer in for the extension ext_type.

- -

If the message being parsed is a TLSv1.3 compatible Certificate message then parse_cb will be called for each certificate contained within the message. The x parameter will indicate the current certificate and the chainidx parameter will indicate the position of the certificate in the message. The first certificate is always the end entity certificate and has a chainidx value of 0.

- -

If the parse_cb considers the extension data acceptable it must return 1. If it returns 0 or a negative value a fatal handshake error occurs using the TLS alert value specified in *al.

- -

The buffer in is a temporary internal buffer which will not be valid after the callback returns.

- -

EXTENSION CONTEXTS

- -

An extension context defines which messages and under which conditions an extension should be added or expected. The context is built up by performing a bitwise OR of multiple pre-defined values together. The valid context values are:

- -
- -
SSL_EXT_TLS_ONLY
-
- -

The extension is only allowed in TLS

- -
-
SSL_EXT_DTLS_ONLY
-
- -

The extension is only allowed in DTLS

- -
-
SSL_EXT_TLS_IMPLEMENTATION_ONLY
-
- -

The extension is allowed in DTLS, but there is only a TLS implementation available (so it is ignored in DTLS).

- -
-
SSL_EXT_SSL3_ALLOWED
-
- -

Extensions are not typically defined for SSLv3. Setting this value will allow the extension in SSLv3. Applications will not typically need to use this.

- -
-
SSL_EXT_TLS1_2_AND_BELOW_ONLY
-
- -

The extension is only defined for TLSv1.2/DTLSv1.2 and below. Servers will ignore this extension if it is present in the ClientHello and TLSv1.3 is negotiated.

- -
-
SSL_EXT_TLS1_3_ONLY
-
- -

The extension is only defined for TLS1.3 and above. Servers will ignore this extension if it is present in the ClientHello and TLSv1.2 or below is negotiated.

- -
-
SSL_EXT_IGNORE_ON_RESUMPTION
-
- -

The extension will be ignored during parsing if a previous session is being successfully resumed.

- -
-
SSL_EXT_CLIENT_HELLO
-
- -

The extension may be present in the ClientHello message.

- -
-
SSL_EXT_TLS1_2_SERVER_HELLO
-
- -

The extension may be present in a TLSv1.2 or below compatible ServerHello message.

- -
-
SSL_EXT_TLS1_3_SERVER_HELLO
-
- -

The extension may be present in a TLSv1.3 compatible ServerHello message.

- -
-
SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS
-
- -

The extension may be present in an EncryptedExtensions message.

- -
-
SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST
-
- -

The extension may be present in a HelloRetryRequest message.

- -
-
SSL_EXT_TLS1_3_CERTIFICATE
-
- -

The extension may be present in a TLSv1.3 compatible Certificate message.

- -
-
SSL_EXT_TLS1_3_NEW_SESSION_TICKET
-
- -

The extension may be present in a TLSv1.3 compatible NewSessionTicket message.

- -
-
SSL_EXT_TLS1_3_CERTIFICATE_REQUEST
-
- -

The extension may be present in a TLSv1.3 compatible CertificateRequest message.

- -
-
- -

The context must include at least one message value (otherwise the extension will never be used).

- -

NOTES

- -

The add_arg and parse_arg parameters can be set to arbitrary values which will be passed to the corresponding callbacks. They can, for example, be used to store the extension data received in a convenient structure or pass the extension data to be added or freed when adding extensions.

- -

If the same custom extension type is received multiple times a fatal decode_error alert is sent and the handshake aborts. If a custom extension is received in a ServerHello/EncryptedExtensions message which was not sent in the ClientHello a fatal unsupported_extension alert is sent and the handshake is aborted. The ServerHello/EncryptedExtensions add_cb callback is only called if the corresponding extension was received in the ClientHello. This is compliant with the TLS specifications. This behaviour ensures that each callback is called at most once and that an application can never send unsolicited extensions.

- -

RETURN VALUES

- -

SSL_CTX_add_custom_ext(), SSL_CTX_add_client_custom_ext() and SSL_CTX_add_server_custom_ext() return 1 for success and 0 for failure. A failure can occur if an attempt is made to add the same ext_type more than once, if an attempt is made to use an extension type handled internally by OpenSSL or if an internal error occurs (for example a memory allocation failure).

- -

SSL_extension_supported() returns 1 if the extension ext_type is handled internally by OpenSSL and 0 otherwise.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

The SSL_CTX_add_custom_ext() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2014-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_free.html b/openssl-install/share/doc/openssl/html/man3/SSL_free.html deleted file mode 100644 index b6955d0c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_free.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -SSL_free - - - - - - - - - - -

NAME

- -

SSL_free - free an allocated SSL structure

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_free(SSL *ssl);
- -

DESCRIPTION

- -

SSL_free() decrements the reference count of ssl, and removes the SSL structure pointed to by ssl and frees up the allocated memory if the reference count has reached 0. If ssl is NULL nothing is done.

- -

NOTES

- -

SSL_free() also calls the free()ing procedures for indirectly affected items, if applicable: the buffering BIO, the read and write BIOs, cipher lists specially created for this ssl, the SSL_SESSION. Do not explicitly free these indirectly freed up items before or after calling SSL_free(), as trying to free things twice may lead to program failure.

- -

The ssl session has reference counts from two users: the SSL object, for which the reference count is removed by SSL_free() and the internal session cache. If the session is considered bad, because SSL_shutdown(3) was not called for the connection and SSL_set_shutdown(3) was not used to set the SSL_SENT_SHUTDOWN state, the session will also be removed from the session cache as required by RFC2246.

- -

When used to free a QUIC stream SSL object, the respective sending and receiving parts of the stream are reset unless those parts have already been concluded normally:

- - - -

A QUIC stream SSL object maintains a reference to a QUIC connection SSL object internally, therefore a QUIC stream SSL object and its parent QUIC connection SSL object can be freed in either order.

- -

RETURN VALUES

- -

SSL_free() does not provide diagnostic information.

- -

SSL_new(3), SSL_clear(3), SSL_shutdown(3), SSL_set_shutdown(3), ssl(7)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get0_connection.html b/openssl-install/share/doc/openssl/html/man3/SSL_get0_connection.html deleted file mode 100644 index 693ee3cc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get0_connection.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -SSL_get0_connection - - - - - - - - - - -

NAME

- -

SSL_get0_connection, SSL_is_connection - get a QUIC connection SSL object from a QUIC stream SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL *SSL_get0_connection(SSL *ssl);
-int SSL_is_connection(SSL *ssl);
- -

DESCRIPTION

- -

The SSL_get0_connection() function, when called on a QUIC stream SSL object, returns the QUIC connection SSL object which the QUIC stream SSL object belongs to.

- -

When called on a QUIC connection SSL object, it returns the same object.

- -

When called on a non-QUIC object, it returns the same object it was passed.

- -

SSL_is_connection() returns 1 for QUIC connection SSL objects and for non-QUIC SSL objects, but returns 0 for QUIC stream SSL objects.

- -

RETURN VALUES

- -

SSL_get0_connection() returns the QUIC connection SSL object (for a QUIC stream SSL object) and otherwise returns the same SSL object passed. It always returns non-NULL.

- -

SSL_is_connection() returns 1 if the SSL object is not a QUIC stream SSL object and 0 otherwise.

- -

SEE ALSO

- -

SSL_new(3), SSL_new_stream(3), SSL_accept_stream(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get0_group_name.html b/openssl-install/share/doc/openssl/html/man3/SSL_get0_group_name.html deleted file mode 100644 index 652d9cb9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get0_group_name.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -SSL_get0_group_name - - - - - - - - - - -

NAME

- -

SSL_get0_group_name - get name of the group that was used for the key agreement of the current TLS session establishment

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_get0_group_name(SSL *s);
- -

DESCRIPTION

- -

SSL_get0_group_name() returns the name of the group that was used for the key agreement of the current TLS session establishment.

- -

RETURN VALUES

- -

If non-NULL, SSL_get0_group_name() returns the name of the group that was used for the key agreement of the current TLS session establishment. If SSL_get0_group_name() returns NULL, an error occurred; possibly no TLS session has been established. See also SSL_get_negotiated_group(3).

- -

Note that the return value is valid only during the lifetime of the SSL object ssl.

- -

SEE ALSO

- -

ssl(7), SSL_get_negotiated_group(3)

- -

HISTORY

- -

This function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_rpk.html b/openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_rpk.html deleted file mode 100644 index 42bfc4df..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_rpk.html +++ /dev/null @@ -1,98 +0,0 @@ - - - - -SSL_get0_peer_rpk - - - - - - - - - - -

NAME

- -

SSL_add_expected_rpk, SSL_get_negotiated_client_cert_type, SSL_get_negotiated_server_cert_type, SSL_get0_peer_rpk, SSL_SESSION_get0_peer_rpk - raw public key (RFC7250) support

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_add_expected_rpk(SSL *s, EVP_PKEY *rpk);
-int SSL_get_negotiated_client_cert_type(const SSL *s);
-int SSL_get_negotiated_server_cert_type(const SSL *s);
-EVP_PKEY *SSL_get0_peer_rpk(const SSL *s);
-EVP_PKEY *SSL_SESSION_get0_peer_rpk(const SSL_SESSION *ss);
- -

DESCRIPTION

- -

SSL_add_expected_rpk() adds a DANE TLSA record matching public key rpk to SSL s's DANE validation policy.

- -

SSL_get_negotiated_client_cert_type() returns the connection's negotiated client certificate type.

- -

SSL_get_negotiated_server_cert_type() returns the connection's negotiated server certificate type.

- -

SSL_get0_peer_rpk() returns the peer's raw public key from SSL s.

- -

SSL_SESSION_get0_peer_rpk() returns the peer's raw public key from SSL_SESSION ss.

- -

NOTES

- -

Raw public keys are used in place of certificates when the option is negotiated. SSL_add_expected_rpk() may be called multiple times to configure multiple trusted keys, this makes it possible to allow for key rotation, where a peer might be expected to offer an "old" or "new" key and the endpoint must be able to accept either one.

- -

When raw public keys are used, the certificate verify callback is called, and may be used to inspect the public key via X509_STORE_CTX_get0_rpk(3). Raw public keys have no subject, issuer, validity dates nor digital signature to verify. They can, however, be matched verbatim or by their digest value, this is done by specifying one or more TLSA records, see SSL_CTX_dane_enable(3).

- -

The raw public key is typically taken from the certificate assigned to the connection (e.g. via SSL_use_certificate(3)), but if a certificate is not configured, then the public key will be extracted from the assigned private key.

- -

The SSL_add_expected_rpk() function is a wrapper around SSL_dane_tlsa_add(3). When DANE is enabled via SSL_dane_enable(3), the configured TLSA records will be used to validate the peer's public key or certificate. If DANE is not enabled, then no validation will occur.

- -

RETURN VALUES

- -

SSL_add_expected_rpk() returns 1 on success and 0 on failure.

- -

SSL_get0_peer_rpk() and SSL_SESSION_get0_peer_rpk() return the peer's raw public key as an EVP_PKEY or NULL when the raw public key is not available.

- -

SSL_get_negotiated_client_cert_type() and SSL_get_negotiated_server_cert_type() return one of the following values:

- -
- -
TLSEXT_cert_type_x509
-
- -
-
TLSEXT_cert_type_rpk
-
- -
-
- -

SEE ALSO

- -

SSL_CTX_dane_enable(3), SSL_CTX_set_options(3), SSL_dane_enable(3), SSL_get_verify_result(3), SSL_set_verify(3), SSL_use_certificate(3), X509_STORE_CTX_get0_rpk(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_scts.html b/openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_scts.html deleted file mode 100644 index 2c928526..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get0_peer_scts.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -SSL_get0_peer_scts - - - - - - - - - - -

NAME

- -

SSL_get0_peer_scts - get SCTs received

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const STACK_OF(SCT) *SSL_get0_peer_scts(SSL *s);
- -

DESCRIPTION

- -

SSL_get0_peer_scts() returns the signed certificate timestamps (SCTs) that have been received. If this is the first time that this function has been called for a given SSL instance, it will examine the TLS extensions, OCSP response and the peer's certificate for SCTs. Future calls will return the same SCTs.

- -

RESTRICTIONS

- -

If no Certificate Transparency validation callback has been set (using SSL_CTX_set_ct_validation_callback or SSL_set_ct_validation_callback), this function is not guaranteed to return all of the SCTs that the peer is capable of sending.

- -

RETURN VALUES

- -

SSL_get0_peer_scts() returns a list of SCTs found, or NULL if an error occurs.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_ct_validation_callback(3)

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get1_builtin_sigalgs.html b/openssl-install/share/doc/openssl/html/man3/SSL_get1_builtin_sigalgs.html deleted file mode 100644 index 975691d7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get1_builtin_sigalgs.html +++ /dev/null @@ -1,61 +0,0 @@ - - - - -SSL_get1_builtin_sigalgs - - - - - - - - - - -

NAME

- -

SSL_get1_builtin_sigalgs - get list of built-in signature algorithms

- -

SYNOPSIS

- -
#include <openssl/tls1.h>
-
-char *SSL_get1_builtin_sigalgs(OSSL_LIB_CTX *libctx);
- -

DESCRIPTION

- -

Return the colon-separated list of built-in and available TLS signature algorithms. The string returned must be freed by the user using OPENSSL_free(3).

- -

NOTES

- -

The string may be empty (strlen==0) if none of the built-in TLS signature algorithms can be activated, e.g., if suitable providers are missing.

- -

RETURN VALUES

- -

NULL may be returned if no memory could be allocated. Otherwise, a newly allocated string is always returned but it may have strlen == 0.

- -

HISTORY

- -

This call was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_SSL_CTX.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_SSL_CTX.html deleted file mode 100644 index 601fc70d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_SSL_CTX.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -SSL_get_SSL_CTX - - - - - - - - - - -

NAME

- -

SSL_get_SSL_CTX - get the SSL_CTX from which an SSL is created

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL_CTX *SSL_get_SSL_CTX(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_SSL_CTX() returns a pointer to the SSL_CTX object, from which ssl was created with SSL_new(3).

- -

RETURN VALUES

- -

The pointer to the SSL_CTX object is returned.

- -

SEE ALSO

- -

ssl(7), SSL_new(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_all_async_fds.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_all_async_fds.html deleted file mode 100644 index cf91aa76..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_all_async_fds.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -SSL_get_all_async_fds - - - - - - - - - - -

NAME

- -

SSL_waiting_for_async, SSL_get_all_async_fds, SSL_get_changed_async_fds - manage asynchronous operations

- -

SYNOPSIS

- -
#include <openssl/async.h>
-#include <openssl/ssl.h>
-
-int SSL_waiting_for_async(SSL *s);
-int SSL_get_all_async_fds(SSL *s, OSSL_ASYNC_FD *fd, size_t *numfds);
-int SSL_get_changed_async_fds(SSL *s, OSSL_ASYNC_FD *addfd, size_t *numaddfds,
-                              OSSL_ASYNC_FD *delfd, size_t *numdelfds);
- -

DESCRIPTION

- -

SSL_waiting_for_async() determines whether an SSL connection is currently waiting for asynchronous operations to complete (see the SSL_MODE_ASYNC mode in SSL_CTX_set_mode(3)).

- -

SSL_get_all_async_fds() returns a list of file descriptor which can be used in a call to select() or poll() to determine whether the current asynchronous operation has completed or not. A completed operation will result in data appearing as "read ready" on the file descriptor (no actual data should be read from the file descriptor). This function should only be called if the SSL object is currently waiting for asynchronous work to complete (i.e. SSL_ERROR_WANT_ASYNC has been received - see SSL_get_error(3)). Typically the list will only contain one file descriptor. However, if multiple asynchronous capable engines are in use then more than one is possible. The number of file descriptors returned is stored in *numfds and the file descriptors themselves are in *fds. The fds parameter may be NULL in which case no file descriptors are returned but *numfds is still populated. It is the callers responsibility to ensure sufficient memory is allocated at *fds so typically this function is called twice (once with a NULL fds parameter and once without).

- -

SSL_get_changed_async_fds() returns a list of the asynchronous file descriptors that have been added and a list that have been deleted since the last SSL_ERROR_WANT_ASYNC was received (or since the SSL object was created if no SSL_ERROR_WANT_ASYNC has been received). Similar to SSL_get_all_async_fds() it is the callers responsibility to ensure that *addfd and *delfd have sufficient memory allocated, although they may be NULL. The number of added fds and the number of deleted fds are stored in *numaddfds and *numdelfds respectively.

- -

RETURN VALUES

- -

SSL_waiting_for_async() will return 1 if the current SSL operation is waiting for an async operation to complete and 0 otherwise.

- -

SSL_get_all_async_fds() and SSL_get_changed_async_fds() return 1 on success or 0 on error.

- -

NOTES

- -

On Windows platforms the <openssl/async.h> header is dependent on some of the types customarily made available by including <windows.h>. The application developer is likely to require control over when the latter is included, commonly as one of the first included headers. Therefore, it is defined as an application developer's responsibility to include <windows.h> prior to <openssl/async.h>.

- -

SEE ALSO

- -

ssl(7), SSL_get_error(3), SSL_CTX_set_mode(3)

- -

HISTORY

- -

The SSL_waiting_for_async(), SSL_get_all_async_fds() and SSL_get_changed_async_fds() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_certificate.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_certificate.html deleted file mode 100644 index a62cfec8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_certificate.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -SSL_get_certificate - - - - - - - - - - -

NAME

- -

SSL_get_certificate, SSL_get_privatekey - retrieve TLS/SSL certificate and private key

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-X509 *SSL_get_certificate(const SSL *s);
-EVP_PKEY *SSL_get_privatekey(const SSL *s);
- -

DESCRIPTION

- -

SSL_get_certificate() returns a pointer to an X509 object representing a certificate used as the local peer's identity.

- -

Multiple certificates can be configured; for example, a server might have both RSA and ECDSA certificates. The certificate which is returned by SSL_get_certificate() is determined as follows:

- - - -

Certificate selection occurs during the handshake; therefore, the value returned by SSL_get_certificate() during any callback made during the handshake process will depend on whether that callback is made before or after certificate selection occurs.

- -

A specific use for SSL_get_certificate() is inside a callback set via a call to SSL_CTX_set_tlsext_status_cb(3). This callback occurs after certificate selection, where it can be used to examine a server's chosen certificate, for example for the purpose of identifying a certificate's OCSP responder URL so that an OCSP response can be obtained.

- -

SSL_get_privatekey() returns a pointer to the EVP_PKEY object corresponding to the certificate returned by SSL_get_certificate(), if any.

- -

RETURN VALUES

- -

These functions return pointers to their respective objects, or NULL if no such object is available. Returned objects are owned by the SSL object and should not be freed by users of these functions.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_tlsext_status_cb(3)

- -

COPYRIGHT

- -

Copyright 2001-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_ciphers.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_ciphers.html deleted file mode 100644 index 1ace06b6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_ciphers.html +++ /dev/null @@ -1,89 +0,0 @@ - - - - -SSL_get_ciphers - - - - - - - - - - -

NAME

- -

SSL_get1_supported_ciphers, SSL_get_client_ciphers, SSL_get_ciphers, SSL_CTX_get_ciphers, SSL_bytes_to_cipher_list, SSL_get_cipher_list, SSL_get_shared_ciphers - get list of available SSL_CIPHERs

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *ssl);
-STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx);
-STACK_OF(SSL_CIPHER) *SSL_get1_supported_ciphers(SSL *s);
-STACK_OF(SSL_CIPHER) *SSL_get_client_ciphers(const SSL *ssl);
-int SSL_bytes_to_cipher_list(SSL *s, const unsigned char *bytes, size_t len,
-                             int isv2format, STACK_OF(SSL_CIPHER) **sk,
-                             STACK_OF(SSL_CIPHER) **scsvs);
-const char *SSL_get_cipher_list(const SSL *ssl, int priority);
-char *SSL_get_shared_ciphers(const SSL *s, char *buf, int size);
- -

DESCRIPTION

- -

SSL_get_ciphers() returns the stack of available SSL_CIPHERs for ssl, sorted by preference. If ssl is NULL or no ciphers are available, NULL is returned.

- -

SSL_CTX_get_ciphers() returns the stack of available SSL_CIPHERs for ctx.

- -

SSL_get1_supported_ciphers() returns the stack of enabled SSL_CIPHERs for ssl as would be sent in a ClientHello (that is, sorted by preference). The list depends on settings like the cipher list, the supported protocol versions, the security level, and the enabled signature algorithms. SRP and PSK ciphers are only enabled if the appropriate callbacks or settings have been applied. The list of ciphers that would be sent in a ClientHello can differ from the list of ciphers that would be acceptable when acting as a server. For example, additional ciphers may be usable by a server if there is a gap in the list of supported protocols, and some ciphers may not be usable by a server if there is not a suitable certificate configured. If ssl is NULL or no ciphers are available, NULL is returned.

- -

SSL_get_client_ciphers() returns the stack of available SSL_CIPHERs matching the list received from the client on ssl. If ssl is NULL, no ciphers are available, or ssl is not operating in server mode, NULL is returned.

- -

SSL_bytes_to_cipher_list() treats the supplied len octets in bytes as a wire-protocol cipher suite specification (in the three-octet-per-cipher SSLv2 wire format if isv2format is nonzero; otherwise the two-octet SSLv3/TLS wire format), and parses the cipher suites supported by the library into the returned stacks of SSL_CIPHER objects sk and Signalling Cipher-Suite Values scsvs. Unsupported cipher suites are ignored. Returns 1 on success and 0 on failure.

- -

SSL_get_cipher_list() returns a pointer to the name of the SSL_CIPHER listed for ssl with priority. If ssl is NULL, no ciphers are available, or there are less ciphers than priority available, NULL is returned.

- -

SSL_get_shared_ciphers() creates a colon separated and NUL terminated list of SSL_CIPHER names that are available in both the client and the server. buf is the buffer that should be populated with the list of names and size is the size of that buffer. A pointer to buf is returned on success or NULL on error. If the supplied buffer is not large enough to contain the complete list of names then a truncated list of names will be returned. Note that just because a ciphersuite is available (i.e. it is configured in the cipher list) and shared by both the client and the server it does not mean that it is enabled (see the description of SSL_get1_supported_ciphers() above). This function will return available shared ciphersuites whether or not they are enabled. This is a server side function only and must only be called after the completion of the initial handshake.

- -

NOTES

- -

The details of the ciphers obtained by SSL_get_ciphers(), SSL_CTX_get_ciphers() SSL_get1_supported_ciphers() and SSL_get_client_ciphers() can be obtained using the SSL_CIPHER_get_name(3) family of functions.

- -

Call SSL_get_cipher_list() with priority starting from 0 to obtain the sorted list of available ciphers, until NULL is returned.

- -

Note: SSL_get_ciphers(), SSL_CTX_get_ciphers() and SSL_get_client_ciphers() return a pointer to an internal cipher stack, which will be freed later on when the SSL or SSL_SESSION object is freed. Therefore, the calling code MUST NOT free the return value itself.

- -

The stack returned by SSL_get1_supported_ciphers() should be freed using sk_SSL_CIPHER_free().

- -

The stacks returned by SSL_bytes_to_cipher_list() should be freed using sk_SSL_CIPHER_free().

- -

RETURN VALUES

- -

See DESCRIPTION

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_cipher_list(3), SSL_CIPHER_get_name(3)

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_client_random.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_client_random.html deleted file mode 100644 index a8198e43..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_client_random.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -SSL_get_client_random - - - - - - - - - - -

NAME

- -

SSL_get_client_random, SSL_get_server_random, SSL_SESSION_get_master_key, SSL_SESSION_set1_master_key - get internal TLS/SSL random values and get/set master key

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-size_t SSL_get_client_random(const SSL *ssl, unsigned char *out, size_t outlen);
-size_t SSL_get_server_random(const SSL *ssl, unsigned char *out, size_t outlen);
-size_t SSL_SESSION_get_master_key(const SSL_SESSION *session,
-                                  unsigned char *out, size_t outlen);
-int SSL_SESSION_set1_master_key(SSL_SESSION *sess, const unsigned char *in,
-                                size_t len);
- -

DESCRIPTION

- -

SSL_get_client_random() extracts the random value sent from the client to the server during the initial SSL/TLS handshake. It copies as many bytes as it can of this value into the buffer provided in out, which must have at least outlen bytes available. It returns the total number of bytes that were actually copied. If outlen is zero, SSL_get_client_random() copies nothing, and returns the total size of the client_random value.

- -

SSL_get_server_random() behaves the same, but extracts the random value sent from the server to the client during the initial SSL/TLS handshake.

- -

SSL_SESSION_get_master_key() behaves the same, but extracts the master secret used to guarantee the security of the SSL/TLS session. This one can be dangerous if misused; see NOTES below.

- -

SSL_SESSION_set1_master_key() sets the master key value associated with the SSL_SESSION sess. For example, this could be used to set up a session based PSK (see SSL_CTX_set_psk_use_session_callback(3)). The master key of length len should be provided at in. The supplied master key is copied by the function, so the caller is responsible for freeing and cleaning any memory associated with in. The caller must ensure that the length of the key is suitable for the ciphersuite associated with the SSL_SESSION.

- -

NOTES

- -

You probably shouldn't use these functions.

- -

These functions expose internal values from the TLS handshake, for use in low-level protocols. You probably should not use them, unless you are implementing something that needs access to the internal protocol details.

- -

Despite the names of SSL_get_client_random() and SSL_get_server_random(), they ARE NOT random number generators. Instead, they return the mostly-random values that were already generated and used in the TLS protocol. Using them in place of RAND_bytes() would be grossly foolish.

- -

The security of your TLS session depends on keeping the master key secret: do not expose it, or any information about it, to anybody. If you need to calculate another secret value that depends on the master secret, you should probably use SSL_export_keying_material() instead, and forget that you ever saw these functions.

- -

In current versions of the TLS protocols, the length of client_random (and also server_random) is always SSL3_RANDOM_SIZE bytes. Support for other outlen arguments to the SSL_get_*_random() functions is provided in case of the unlikely event that a future version or variant of TLS uses some other length there.

- -

Finally, though the "client_random" and "server_random" values are called "random", many TLS implementations will generate four bytes of those values based on their view of the current time.

- -

RETURN VALUES

- -

SSL_SESSION_set1_master_key() returns 1 on success or 0 on failure.

- -

For the other functions, if outlen is greater than 0 then these functions return the number of bytes actually copied, which will be less than or equal to outlen. If outlen is 0 then these functions return the maximum number of bytes they would copy -- that is, the length of the underlying field.

- -

SEE ALSO

- -

ssl(7), RAND_bytes(3), SSL_export_keying_material(3), SSL_CTX_set_psk_use_session_callback(3)

- -

COPYRIGHT

- -

Copyright 2015-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_conn_close_info.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_conn_close_info.html deleted file mode 100644 index 4671432c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_conn_close_info.html +++ /dev/null @@ -1,157 +0,0 @@ - - - - -SSL_get_conn_close_info - - - - - - - - - - -

NAME

- -

SSL_get_conn_close_info, SSL_CONN_CLOSE_FLAG_LOCAL, SSL_CONN_CLOSE_FLAG_TRANSPORT, OSSL_QUIC_ERR_NO_ERROR, OSSL_QUIC_ERR_INTERNAL_ERROR, OSSL_QUIC_ERR_CONNECTION_REFUSED, OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, OSSL_QUIC_ERR_STREAM_STATE_ERROR, OSSL_QUIC_ERR_FINAL_SIZE_ERROR, OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR, OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR, OSSL_QUIC_ERR_PROTOCOL_VIOLATION, OSSL_QUIC_ERR_INVALID_TOKEN, OSSL_QUIC_ERR_APPLICATION_ERROR, OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED, OSSL_QUIC_ERR_KEY_UPDATE_ERROR, OSSL_QUIC_ERR_AEAD_LIMIT_REACHED, OSSL_QUIC_ERR_NO_VIABLE_PATH, OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN, OSSL_QUIC_ERR_CRYPTO_ERR_END, OSSL_QUIC_ERR_CRYPTO_ERR, OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT - get information about why a QUIC connection was closed

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_CONN_CLOSE_FLAG_LOCAL
-#define SSL_CONN_CLOSE_FLAG_TRANSPORT
-
-typedef struct ssl_conn_close_info_st {
-    uint64_t error_code, frame_type;
-    char     *reason;
-    size_t   reason_len;
-    uint32_t flags;
-} SSL_CONN_CLOSE_INFO;
-
-int SSL_get_conn_close_info(SSL *ssl, SSL_CONN_CLOSE_INFO *info,
-                            size_t info_len);
-
-#define OSSL_QUIC_ERR_NO_ERROR                  0x00
-#define OSSL_QUIC_ERR_INTERNAL_ERROR            0x01
-#define OSSL_QUIC_ERR_CONNECTION_REFUSED        0x02
-#define OSSL_QUIC_ERR_FLOW_CONTROL_ERROR        0x03
-#define OSSL_QUIC_ERR_STREAM_LIMIT_ERROR        0x04
-#define OSSL_QUIC_ERR_STREAM_STATE_ERROR        0x05
-#define OSSL_QUIC_ERR_FINAL_SIZE_ERROR          0x06
-#define OSSL_QUIC_ERR_FRAME_ENCODING_ERROR      0x07
-#define OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR 0x08
-#define OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR 0x09
-#define OSSL_QUIC_ERR_PROTOCOL_VIOLATION        0x0A
-#define OSSL_QUIC_ERR_INVALID_TOKEN             0x0B
-#define OSSL_QUIC_ERR_APPLICATION_ERROR         0x0C
-#define OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED    0x0D
-#define OSSL_QUIC_ERR_KEY_UPDATE_ERROR          0x0E
-#define OSSL_QUIC_ERR_AEAD_LIMIT_REACHED        0x0F
-#define OSSL_QUIC_ERR_NO_VIABLE_PATH            0x10
-
-/* Inclusive range for handshake-specific errors. */
-#define OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN          0x0100
-#define OSSL_QUIC_ERR_CRYPTO_ERR_END            0x01FF
-
-#define OSSL_QUIC_ERR_CRYPTO_ERR(X)
-
-#define OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT
- -

DESCRIPTION

- -

The SSL_get_conn_close_info() function provides information about why and how a QUIC connection was closed.

- -

Connection closure information is written to *info, which must be non-NULL. info_len must be set to sizeof(*info).

- -

The following fields are set:

- -
- -
error_code
-
- -

This is a 62-bit QUIC error code. It is either a 62-bit application error code (if SSL_CONN_CLOSE_FLAG_TRANSPORT not set in flags) or a 62-bit standard QUIC transport error code (if SSL_CONN_CLOSE_FLAG_TRANSPORT is set in flags).

- -
-
frame_type
-
- -

If SSL_CONN_CLOSE_FLAG_TRANSPORT is set, this may be set to a QUIC frame type number which caused the connection to be closed. It may also be set to 0 if no frame type was specified as causing the connection to be closed. If SSL_CONN_CLOSE_FLAG_TRANSPORT is not set, this is set to 0.

- -
-
reason
-
- -

If non-NULL, this is intended to be a UTF-8 textual string briefly describing the reason for connection closure. The length of the reason string in bytes is given in reason_len. While, if non-NULL, OpenSSL guarantees that this string will be zero terminated, consider that this buffer may originate from the (untrusted) peer and thus may also contain zero bytes elsewhere. Therefore, use of reason_len is recommended.

- -

While it is intended as per the QUIC protocol that this be a UTF-8 string, there is no guarantee that this is the case for strings received from the peer.

- -
-
SSL_CONN_CLOSE_FLAG_LOCAL
-
- -

If flags has SSL_CONN_CLOSE_FLAG_LOCAL set, connection closure was locally triggered. This could be due to an application request (e.g. if SSL_CONN_CLOSE_FLAG_TRANSPORT is unset), or (if SSL_CONN_CLOSE_FLAG_TRANSPORT is set) due to logic internal to the QUIC implementation (for example, if the peer engages in a protocol violation, or an idle timeout occurs).

- -

If unset, connection closure was remotely triggered.

- -
-
SSL_CONN_CLOSE_FLAG_TRANSPORT
-
- -

If flags has SSL_CONN_CLOSE_FLAG_TRANSPORT set, connection closure was triggered for QUIC protocol reasons. Otherwise, connection closure was triggered by the local or remote application.

- -
-
- -

The OSSL_QUIC_ERR macro definitions provide the QUIC transport error codes as defined by RFC 9000. The OSSL_QUIC_ERR_CRYPTO_ERR() macro can be used to convert a TLS alert code into a QUIC transport error code by mapping it into the range reserved for such codes by RFC 9000. This range begins at OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN and ends at OSSL_QUIC_ERR_CRYPTO_ERR_END inclusive.

- -

NON-STANDARD TRANSPORT ERROR CODES

- -

Some conditions which can cause QUIC connection termination are not signalled on the wire and therefore do not have standard error codes. OpenSSL indicates these errors via SSL_get_conn_close_info() by setting SSL_CONN_CLOSE_FLAG_TRANSPORT and using one of the following error values. These codes are specific to OpenSSL, and cannot be sent over the wire, as they are above 2**62.

- -
- -
OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT
-
- -

The connection was terminated immediately due to the idle timeout expiring.

- -
-
- -

RETURN VALUES

- -

SSL_get_conn_close_info() returns 1 on success and 0 on failure. This function fails if called on a QUIC connection SSL object which has not yet been terminated. It also fails if called on a QUIC stream SSL object or a non-QUIC SSL object.

- -

SEE ALSO

- -

SSL_shutdown_ex(3)

- -

HISTORY

- -

This function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_current_cipher.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_current_cipher.html deleted file mode 100644 index 1de8272b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_current_cipher.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -SSL_get_current_cipher - - - - - - - - - - -

NAME

- -

SSL_get_current_cipher, SSL_get_cipher_name, SSL_get_cipher, SSL_get_cipher_bits, SSL_get_cipher_version, SSL_get_pending_cipher - get SSL_CIPHER of a connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const SSL_CIPHER *SSL_get_current_cipher(const SSL *ssl);
-const SSL_CIPHER *SSL_get_pending_cipher(const SSL *ssl);
-
-const char *SSL_get_cipher_name(const SSL *s);
-const char *SSL_get_cipher(const SSL *s);
-int SSL_get_cipher_bits(const SSL *s, int *np);
-const char *SSL_get_cipher_version(const SSL *s);
- -

DESCRIPTION

- -

SSL_get_current_cipher() returns a pointer to an SSL_CIPHER object containing the description of the actually used cipher of a connection established with the ssl object. See SSL_CIPHER_get_name(3) for more details.

- -

SSL_get_cipher_name() obtains the name of the currently used cipher. SSL_get_cipher() is identical to SSL_get_cipher_name(). SSL_get_cipher_bits() is a macro to obtain the number of secret/algorithm bits used and SSL_get_cipher_version() returns the protocol name.

- -

SSL_get_pending_cipher() returns a pointer to an SSL_CIPHER object containing the description of the cipher (if any) that has been negotiated for future use on the connection established with the ssl object, but is not yet in use. This may be the case during handshake processing, when control flow can be returned to the application via any of several callback methods. The internal sequencing of handshake processing and callback invocation is not guaranteed to be stable from release to release, and at present only the callback set by SSL_CTX_set_alpn_select_cb() is guaranteed to have a non-NULL return value. Other callbacks may be added to this list over time.

- -

RETURN VALUES

- -

SSL_get_current_cipher() returns the cipher actually used, or NULL if no session has been established.

- -

SSL_get_pending_cipher() returns the cipher to be used at the next change of cipher suite, or NULL if no such cipher is known.

- -

NOTES

- -

SSL_get_cipher, SSL_get_cipher_bits, SSL_get_cipher_version, and SSL_get_cipher_name are implemented as macros.

- -

SEE ALSO

- -

ssl(7), SSL_CIPHER_get_name(3)

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_default_timeout.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_default_timeout.html deleted file mode 100644 index 40a063e8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_default_timeout.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -SSL_get_default_timeout - - - - - - - - - - -

NAME

- -

SSL_get_default_timeout - get default session timeout value

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_get_default_timeout(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_default_timeout() returns the default timeout value assigned to SSL_SESSION objects negotiated for the protocol valid for ssl.

- -

NOTES

- -

Whenever a new session is negotiated, it is assigned a timeout value, after which it will not be accepted for session reuse. If the timeout value was not explicitly set using SSL_CTX_set_timeout(3), the hardcoded default timeout for the protocol will be used.

- -

SSL_get_default_timeout() return this hardcoded value, which is 300 seconds for all currently supported protocols.

- -

RETURN VALUES

- -

See description.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_session_cache_mode(3), SSL_SESSION_get_time(3), SSL_CTX_flush_sessions(3), SSL_get_default_timeout(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_error.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_error.html deleted file mode 100644 index 335663ad..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_error.html +++ /dev/null @@ -1,154 +0,0 @@ - - - - -SSL_get_error - - - - - - - - - - -

NAME

- -

SSL_get_error - obtain result code for TLS/SSL I/O operation

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_error(const SSL *ssl, int ret);
- -

DESCRIPTION

- -

SSL_get_error() returns a result code (suitable for the C "switch" statement) for a preceding call to SSL_connect(), SSL_accept(), SSL_do_handshake(), SSL_read_ex(), SSL_read(), SSL_peek_ex(), SSL_peek(), SSL_shutdown(), SSL_write_ex() or SSL_write() on ssl. The value returned by that TLS/SSL I/O function must be passed to SSL_get_error() in parameter ret.

- -

In addition to ssl and ret, SSL_get_error() inspects the current thread's OpenSSL error queue. Thus, SSL_get_error() must be used in the same thread that performed the TLS/SSL I/O operation, and no other OpenSSL function calls should appear in between. The current thread's error queue must be empty before the TLS/SSL I/O operation is attempted, or SSL_get_error() will not work reliably.

- -

NOTES

- -

Some TLS implementations do not send a close_notify alert on shutdown.

- -

On an unexpected EOF, versions before OpenSSL 3.0 returned SSL_ERROR_SYSCALL, nothing was added to the error stack, and errno was 0. Since OpenSSL 3.0 the returned error is SSL_ERROR_SSL with a meaningful error on the error stack (SSL_R_UNEXPECTED_EOF_WHILE_READING). This error reason code may be used for control flow decisions (see the man page for ERR_GET_REASON(3) for further details on this).

- -

RETURN VALUES

- -

The following return values can currently occur:

- -
- -
SSL_ERROR_NONE
-
- -

The TLS/SSL I/O operation completed. This result code is returned if and only if ret > 0.

- -
-
SSL_ERROR_ZERO_RETURN
-
- -

The TLS/SSL peer has closed the connection for writing by sending the close_notify alert. No more data can be read. Note that SSL_ERROR_ZERO_RETURN does not necessarily indicate that the underlying transport has been closed.

- -

This error can also appear when the option SSL_OP_IGNORE_UNEXPECTED_EOF is set. See SSL_CTX_set_options(3) for more details.

- -
-
SSL_ERROR_WANT_READ, SSL_ERROR_WANT_WRITE
-
- -

The operation did not complete and can be retried later.

- -

For non-QUIC SSL objects, SSL_ERROR_WANT_READ is returned when the last operation was a read operation from a nonblocking BIO. It means that not enough data was available at this time to complete the operation. If at a later time the underlying BIO has data available for reading the same function can be called again.

- -

SSL_read() and SSL_read_ex() can also set SSL_ERROR_WANT_READ when there is still unprocessed data available at either the SSL or the BIO layer, even for a blocking BIO. See SSL_read(3) for more information.

- -

For non-QUIC SSL objects, SSL_ERROR_WANT_WRITE is returned when the last operation was a write to a nonblocking BIO and it was unable to send all data to the BIO. When the BIO is writable again, the same function can be called again.

- -

Note that the retry may again lead to an SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE condition. There is no fixed upper limit for the number of iterations that may be necessary until progress becomes visible at application protocol level.

- -

For QUIC SSL objects, the meaning of SSL_ERROR_WANT_READ and SSL_ERROR_WANT_WRITE have different but largely compatible semantics. Since QUIC implements its own flow control and uses UDP datagrams, backpressure conditions in terms of the underlying BIO providing network I/O are not directly relevant to the circumstances in which these errors are produced. In particular, SSL_ERROR_WANT_WRITE indicates that the OpenSSL internal send buffer for a given QUIC stream has been filled. Likewise, SSL_ERROR_WANT_READ indicates that the OpenSSL internal receive buffer for a given QUIC stream is empty.

- -

It is safe to call SSL_read() or SSL_read_ex() when more data is available even when the call that set this error was an SSL_write() or SSL_write_ex(). However, if the call was an SSL_write() or SSL_write_ex(), it should be called again to continue sending the application data. If you get SSL_ERROR_WANT_WRITE from SSL_write() or SSL_write_ex() then you should not do any other operation that could trigger IO other than to repeat the previous SSL_write() call.

- -

For socket BIOs (e.g. when SSL_set_fd() was used), select() or poll() on the underlying socket can be used to find out when the TLS/SSL I/O function should be retried.

- -

Caveat: Any TLS/SSL I/O function can lead to either of SSL_ERROR_WANT_READ and SSL_ERROR_WANT_WRITE. In particular, SSL_read_ex(), SSL_read(), SSL_peek_ex(), or SSL_peek() may want to write data and SSL_write() or SSL_write_ex() may want to read data. This is mainly because TLS/SSL handshakes may occur at any time during the protocol (initiated by either the client or the server); SSL_read_ex(), SSL_read(), SSL_peek_ex(), SSL_peek(), SSL_write_ex(), and SSL_write() will handle any pending handshakes.

- -
-
SSL_ERROR_WANT_CONNECT, SSL_ERROR_WANT_ACCEPT
-
- -

The operation did not complete; the same TLS/SSL I/O function should be called again later. The underlying BIO was not connected yet to the peer and the call would block in connect()/accept(). The SSL function should be called again when the connection is established. These messages can only appear with a BIO_s_connect() or BIO_s_accept() BIO, respectively. In order to find out, when the connection has been successfully established, on many platforms select() or poll() for writing on the socket file descriptor can be used.

- -
-
SSL_ERROR_WANT_X509_LOOKUP
-
- -

The operation did not complete because an application callback set by SSL_CTX_set_client_cert_cb() has asked to be called again. The TLS/SSL I/O function should be called again later. Details depend on the application.

- -
-
SSL_ERROR_WANT_ASYNC
-
- -

The operation did not complete because an asynchronous engine is still processing data. This will only occur if the mode has been set to SSL_MODE_ASYNC using SSL_CTX_set_mode(3) or SSL_set_mode(3) and an asynchronous capable engine is being used. An application can determine whether the engine has completed its processing using select() or poll() on the asynchronous wait file descriptor. This file descriptor is available by calling SSL_get_all_async_fds(3) or SSL_get_changed_async_fds(3). The TLS/SSL I/O function should be called again later. The function must be called from the same thread that the original call was made from.

- -
-
SSL_ERROR_WANT_ASYNC_JOB
-
- -

The asynchronous job could not be started because there were no async jobs available in the pool (see ASYNC_init_thread(3)). This will only occur if the mode has been set to SSL_MODE_ASYNC using SSL_CTX_set_mode(3) or SSL_set_mode(3) and a maximum limit has been set on the async job pool through a call to ASYNC_init_thread(3). The application should retry the operation after a currently executing asynchronous operation for the current thread has completed.

- -
-
SSL_ERROR_WANT_CLIENT_HELLO_CB
-
- -

The operation did not complete because an application callback set by SSL_CTX_set_client_hello_cb() has asked to be called again. The TLS/SSL I/O function should be called again later. Details depend on the application.

- -
-
SSL_ERROR_SYSCALL
-
- -

Some non-recoverable, fatal I/O error occurred. The OpenSSL error queue may contain more information on the error. For socket I/O on Unix systems, consult errno for details. If this error occurs then no further I/O operations should be performed on the connection and SSL_shutdown() must not be called.

- -

This value can also be returned for other errors, check the error queue for details.

- -
-
SSL_ERROR_SSL
-
- -

A non-recoverable, fatal error in the SSL library occurred, usually a protocol error. The OpenSSL error queue contains more information on the error. If this error occurs then no further I/O operations should be performed on the connection and SSL_shutdown() must not be called.

- -
-
- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

The SSL_ERROR_WANT_ASYNC error code was added in OpenSSL 1.1.0. The SSL_ERROR_WANT_CLIENT_HELLO_CB error code was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_event_timeout.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_event_timeout.html deleted file mode 100644 index 6fcf9a05..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_event_timeout.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -SSL_get_event_timeout - - - - - - - - - - -

NAME

- -

SSL_get_event_timeout - determine when an SSL object next needs to have events handled

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_event_timeout(SSL *s, struct timeval *tv, int *is_infinite);
- -

DESCRIPTION

- -

SSL_get_event_timeout() determines when the SSL object next needs to perform internal processing due to the passage of time.

- -

All arguments are required; tv and is_infinite must be non-NULL.

- -

Upon the successful return of SSL_get_event_timeout(), one of the following cases applies:

- - - -

This function is currently applicable only to DTLS and QUIC connection SSL objects. If it is called on any other kind of SSL object, it always outputs infinity. This is considered a success condition.

- -

For DTLS, this function can be used instead of the older DTLSv1_get_timeout(3) function. Note that this function differs from DTLSv1_get_timeout(3) in that the case where no timeout is active is considered a success condition.

- -

Note that the value output by a call to SSL_get_event_timeout() may change as a result of other calls to the SSL object.

- -

Once the timeout expires, SSL_handle_events(3) should be called to handle any internal processing which is due; for more information, see SSL_handle_events(3).

- -

Note that SSL_get_event_timeout() supersedes the older DTLSv1_get_timeout(3) function for all use cases.

- -

If the call to SSL_get_event_timeout() fails, the values of *tv and *is_infinite may still be changed and their values become unspecified.

- -

RETURN VALUES

- -

Returns 1 on success and 0 on failure.

- -

SEE ALSO

- -

SSL_handle_events(3), DTLSv1_get_timeout(3), ssl(7)

- -

HISTORY

- -

The SSL_get_event_timeout() function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_extms_support.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_extms_support.html deleted file mode 100644 index 492b4dbb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_extms_support.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -SSL_get_extms_support - - - - - - - - - - -

NAME

- -

SSL_get_extms_support - extended master secret support

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_extms_support(SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_extms_support() indicates whether the current session used extended master secret.

- -

This function is implemented as a macro.

- -

RETURN VALUES

- -

SSL_get_extms_support() returns 1 if the current session used extended master secret, 0 if it did not and -1 if a handshake is currently in progress i.e. it is not possible to determine if extended master secret was used.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_fd.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_fd.html deleted file mode 100644 index 69afed60..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_fd.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -SSL_get_fd - - - - - - - - - - -

NAME

- -

SSL_get_fd, SSL_get_rfd, SSL_get_wfd - get file descriptor linked to an SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_fd(const SSL *ssl);
-int SSL_get_rfd(const SSL *ssl);
-int SSL_get_wfd(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_fd() returns the file descriptor which is linked to ssl. SSL_get_rfd() and SSL_get_wfd() return the file descriptors for the read or the write channel, which can be different. If the read and the write channel are different, SSL_get_fd() will return the file descriptor of the read channel.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
-1
-
- -

The operation failed, because the underlying BIO is not of the correct type (suitable for file descriptors).

- -
-
>=0
-
- -

The file descriptor linked to ssl.

- -
-
- -

SEE ALSO

- -

SSL_set_fd(3), ssl(7) , bio(7)

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_handshake_rtt.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_handshake_rtt.html deleted file mode 100644 index 6f41ebbb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_handshake_rtt.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -SSL_get_handshake_rtt - - - - - - - - - - -

NAME

- -

SSL_get_handshake_rtt - get round trip time for SSL Handshake

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_handshake_rtt(const SSL *s, uint64_t *rtt);
- -

DESCRIPTION

- -

SSL_get_handshake_rtt() retrieves the round-trip time (RTT) for ssl.

- -

This metric is represented in microseconds (us) as a uint64_t data type.

- -

NOTES

- -

This metric is created by taking two timestamps during the handshake and providing the difference between these two times.

- -

When acting as the server, one timestamp is taken when the server is finished writing to the client. This is during the ServerFinished in TLS 1.3 and ServerHelloDone in TLS 1.2. The other timestamp is taken when the server is done reading the client's response. This is after the client has responded with ClientFinished.

- -

When acting as the client, one timestamp is taken when the client is finished writing the ClientHello and early data (if any). The other is taken when client is done reading the server's response. This is after ServerFinished in TLS 1.3 and after ServerHelloDone in TLS 1.2.

- -

In addition to network propagation delay and network stack overhead, this metric includes processing time on both endpoints, as this is based on TLS protocol-level messages and the TLS protocol is not designed to measure network timings. In some cases the processing time can be significant, especially when the processing includes asymmetric cryptographic operations.

- -

RETURN VALUES

- -

Returns 1 if the TLS handshake RTT is successfully retrieved. Returns 0 if the TLS handshake RTT cannot be determined yet. Returns -1 if, while retrieving the TLS handshake RTT, an error occurs.

- -

HISTORY

- -

This function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_cert_chain.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_cert_chain.html deleted file mode 100644 index 51ce42ba..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_cert_chain.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -SSL_get_peer_cert_chain - - - - - - - - - - -

NAME

- -

SSL_get_peer_cert_chain, SSL_get0_verified_chain - get the X509 certificate chain of the peer

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-STACK_OF(X509) *SSL_get_peer_cert_chain(const SSL *ssl);
-STACK_OF(X509) *SSL_get0_verified_chain(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_peer_cert_chain() returns a pointer to STACK_OF(X509) certificates forming the certificate chain sent by the peer. If called on the client side, the stack also contains the peer's certificate; if called on the server side, the peer's certificate must be obtained separately using SSL_get_peer_certificate(3). If the peer did not present a certificate, NULL is returned.

- -

NB: SSL_get_peer_cert_chain() returns the peer chain as sent by the peer: it only consists of certificates the peer has sent (in the order the peer has sent them) it is not a verified chain.

- -

SSL_get0_verified_chain() returns the verified certificate chain of the peer including the peer's end entity certificate. It must be called after a session has been successfully established. If peer verification was not successful (as indicated by SSL_get_verify_result() not returning X509_V_OK) the chain may be incomplete or invalid.

- -

NOTES

- -

If the session is resumed peers do not send certificates so a NULL pointer is returned by these functions. Applications can call SSL_session_reused() to determine whether a session is resumed.

- -

The reference count of each certificate in the returned STACK_OF(X509) object is not incremented and the returned stack may be invalidated by renegotiation. If applications wish to use any certificates in the returned chain indefinitely they must increase the reference counts using X509_up_ref() or obtain a copy of the whole chain with X509_chain_up_ref().

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
NULL
-
- -

No certificate was presented by the peer or no connection was established or the certificate chain is no longer available when a session is reused.

- -
-
Pointer to a STACK_OF(X509)
-
- -

The return value points to the certificate chain presented by the peer.

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_get_peer_certificate(3), X509_up_ref(3), X509_chain_up_ref(3)

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_certificate.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_certificate.html deleted file mode 100644 index 8e40c292..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_certificate.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -SSL_get_peer_certificate - - - - - - - - - - -

NAME

- -

SSL_get_peer_certificate, SSL_get0_peer_certificate, SSL_get1_peer_certificate - get the X509 certificate of the peer

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-X509 *SSL_get0_peer_certificate(const SSL *ssl);
-X509 *SSL_get1_peer_certificate(const SSL *ssl);
- -

The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
X509 *SSL_get_peer_certificate(const SSL *ssl);
- -

DESCRIPTION

- -

These functions return a pointer to the X509 certificate the peer presented. If the peer did not present a certificate, NULL is returned.

- -

NOTES

- -

Due to the protocol definition, a TLS/SSL server will always send a certificate, if present. A client will only send a certificate when explicitly requested to do so by the server (see SSL_CTX_set_verify(3)). If an anonymous cipher is used, no certificates are sent.

- -

That a certificate is returned does not indicate information about the verification state, use SSL_get_verify_result(3) to check the verification state.

- -

The reference count of the X509 object returned by SSL_get1_peer_certificate() is incremented by one, so that it will not be destroyed when the session containing the peer certificate is freed. The X509 object must be explicitly freed using X509_free().

- -

The reference count of the X509 object returned by SSL_get0_peer_certificate() is not incremented, and must not be freed.

- -

SSL_get_peer_certificate() is an alias of SSL_get1_peer_certificate().

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
NULL
-
- -

No certificate was presented by the peer or no connection was established.

- -
-
Pointer to an X509 certificate
-
- -

The return value points to the certificate presented by the peer.

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_get_verify_result(3), SSL_CTX_set_verify(3)

- -

HISTORY

- -

SSL_get0_peer_certificate() and SSL_get1_peer_certificate() were added in 3.0.0. SSL_get_peer_certificate() was deprecated in 3.0.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_signature_nid.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_signature_nid.html deleted file mode 100644 index 68ab4d84..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_signature_nid.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -SSL_get_peer_signature_nid - - - - - - - - - - -

NAME

- -

SSL_get_peer_signature_nid, SSL_get_peer_signature_type_nid, SSL_get_signature_nid, SSL_get_signature_type_nid - get TLS message signing types

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_peer_signature_nid(SSL *ssl, int *psig_nid);
-int SSL_get_peer_signature_type_nid(const SSL *ssl, int *psigtype_nid);
-int SSL_get_signature_nid(SSL *ssl, int *psig_nid);
-int SSL_get_signature_type_nid(const SSL *ssl, int *psigtype_nid);
- -

DESCRIPTION

- -

SSL_get_peer_signature_nid() sets *psig_nid to the NID of the digest used by the peer to sign TLS messages. It is implemented as a macro.

- -

SSL_get_peer_signature_type_nid() sets *psigtype_nid to the signature type used by the peer to sign TLS messages. Currently the signature type is the NID of the public key type used for signing except for PSS signing where it is EVP_PKEY_RSA_PSS. To differentiate between rsa_pss_rsae_* and rsa_pss_pss_* signatures, it's necessary to check the type of public key in the peer's certificate.

- -

SSL_get_signature_nid() and SSL_get_signature_type_nid() return the equivalent information for the local end of the connection.

- -

RETURN VALUES

- -

These functions return 1 for success and 0 for failure. There are several possible reasons for failure: the cipher suite has no signature (e.g. it uses RSA key exchange or is anonymous), the TLS version is below 1.2 or the functions were called too early, e.g. before the peer signed a message.

- -

SEE ALSO

- -

ssl(7), SSL_get_peer_certificate(3),

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_tmp_key.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_tmp_key.html deleted file mode 100644 index f932ad40..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_peer_tmp_key.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -SSL_get_peer_tmp_key - - - - - - - - - - -

NAME

- -

SSL_get_peer_tmp_key, SSL_get_server_tmp_key, SSL_get_tmp_key - get information about temporary keys used during a handshake

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_get_peer_tmp_key(SSL *ssl, EVP_PKEY **key);
-long SSL_get_server_tmp_key(SSL *ssl, EVP_PKEY **key);
-long SSL_get_tmp_key(SSL *ssl, EVP_PKEY **key);
- -

DESCRIPTION

- -

SSL_get_peer_tmp_key() returns the temporary key provided by the peer and used during key exchange. For example, if ECDHE is in use, then this represents the peer's public ECDHE key. On success a pointer to the key is stored in *key. It is the caller's responsibility to free this key after use using EVP_PKEY_free(3).

- -

SSL_get_server_tmp_key() is a backwards compatibility alias for SSL_get_peer_tmp_key(). Under that name it worked just on the client side of the connection, its behaviour on the server end is release-dependent.

- -

SSL_get_tmp_key() returns the equivalent information for the local end of the connection.

- -

RETURN VALUES

- -

All these functions return 1 on success and 0 otherwise.

- -

NOTES

- -

This function is implemented as a macro.

- -

SEE ALSO

- -

ssl(7), EVP_PKEY_free(3)

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_psk_identity.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_psk_identity.html deleted file mode 100644 index d4735682..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_psk_identity.html +++ /dev/null @@ -1,59 +0,0 @@ - - - - -SSL_get_psk_identity - - - - - - - - - - -

NAME

- -

SSL_get_psk_identity, SSL_get_psk_identity_hint - get PSK client identity and hint

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_get_psk_identity_hint(const SSL *ssl);
-const char *SSL_get_psk_identity(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_psk_identity_hint() is used to retrieve the PSK identity hint used during the connection setup related to SSL object ssl. Similarly, SSL_get_psk_identity() is used to retrieve the PSK identity used during the connection setup.

- -

RETURN VALUES

- -

If non-NULL, SSL_get_psk_identity_hint() returns the PSK identity hint and SSL_get_psk_identity() returns the PSK identity. Both are NULL-terminated. SSL_get_psk_identity_hint() may return NULL if no PSK identity hint was used during the connection setup.

- -

Note that the return value is valid only during the lifetime of the SSL object ssl.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2006-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_rbio.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_rbio.html deleted file mode 100644 index 1f7ab3ce..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_rbio.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -SSL_get_rbio - - - - - - - - - - -

NAME

- -

SSL_get_rbio, SSL_get_wbio - get BIO linked to an SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-BIO *SSL_get_rbio(SSL *ssl);
-BIO *SSL_get_wbio(SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_rbio() and SSL_get_wbio() return pointers to the BIOs for the read or the write channel, which can be different. The reference count of the BIO is not incremented.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
NULL
-
- -

No BIO was connected to the SSL object

- -
-
Any other pointer
-
- -

The BIO linked to ssl.

- -
-
- -

SEE ALSO

- -

SSL_set_bio(3), ssl(7) , bio(7)

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_rpoll_descriptor.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_rpoll_descriptor.html deleted file mode 100644 index f3b10ef9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_rpoll_descriptor.html +++ /dev/null @@ -1,91 +0,0 @@ - - - - -SSL_get_rpoll_descriptor - - - - - - - - - - -

NAME

- -

SSL_get_rpoll_descriptor, SSL_get_wpoll_descriptor, SSL_net_read_desired, SSL_net_write_desired - obtain information which can be used to determine when network I/O can be performed

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_rpoll_descriptor(SSL *s, BIO_POLL_DESCRIPTOR *desc);
-int SSL_get_wpoll_descriptor(SSL *s, BIO_POLL_DESCRIPTOR *desc);
-int SSL_net_read_desired(SSL *s);
-int SSL_net_write_desired(SSL *s);
- -

DESCRIPTION

- -

The functions SSL_get_rpoll_descriptor() and SSL_get_wpoll_descriptor() can be used to determine when an SSL object which represents a QUIC connection can perform useful network I/O, so that an application using a QUIC connection SSL object in nonblocking mode can determine when it should call SSL_handle_events().

- -

On success, these functions output poll descriptors. For more information on poll descriptors, see BIO_get_rpoll_descriptor(3).

- -

The functions SSL_net_read_desired() and SSL_net_write_desired() return 1 or 0 depending on whether the SSL object is currently interested in receiving data from the network and/or writing data to the network respectively. If an SSL object is not interested in reading data from the network at the current time, SSL_net_read_desired() will return 0; likewise, if an SSL object is not interested in writing data to the network at the current time, SSL_net_write_desired() will return 0.

- -

The intention is that an application using QUIC in nonblocking mode can use these calls, in conjunction with SSL_get_event_timeout(3) to wait for network I/O conditions which allow the SSL object to perform useful work. When such a condition arises, SSL_handle_events(3) should be called.

- -

In particular, the expected usage is as follows:

- - - -

The return values of the SSL_net_read_desired() and SSL_net_write_desired() functions may change in response to any call to the SSL object other than SSL_net_read_desired(), SSL_net_write_desired(), SSL_get_rpoll_descriptor(), SSL_get_wpoll_descriptor() and SSL_get_event_timeout().

- -

On non-QUIC SSL objects, calls to SSL_get_rpoll_descriptor() and SSL_get_wpoll_descriptor() function the same as calls to BIO_get_rpoll_descriptor() and BIO_get_wpoll_descriptor() on the respective read and write BIOs configured on the SSL object.

- -

On non-QUIC SSL objects, calls to SSL_net_read_desired() and SSL_net_write_desired() function identically to calls to SSL_want_read() and SSL_want_write() respectively.

- -

RETURN VALUES

- -

These functions return 1 on success and 0 on failure.

- -

SEE ALSO

- -

SSL_handle_events(3), SSL_get_event_timeout(3), ssl(7)

- -

HISTORY

- -

The SSL_get_rpoll_descriptor(), SSL_get_wpoll_descriptor(), SSL_net_read_desired() and SSL_net_write_desired() functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_session.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_session.html deleted file mode 100644 index e00f6743..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_session.html +++ /dev/null @@ -1,97 +0,0 @@ - - - - -SSL_get_session - - - - - - - - - - -

NAME

- -

SSL_get_session, SSL_get0_session, SSL_get1_session - retrieve TLS/SSL session data

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL_SESSION *SSL_get_session(const SSL *ssl);
-SSL_SESSION *SSL_get0_session(const SSL *ssl);
-SSL_SESSION *SSL_get1_session(SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_session() returns a pointer to the SSL_SESSION actually used in ssl. The reference count of the SSL_SESSION is not incremented, so that the pointer can become invalid by other operations.

- -

SSL_get0_session() is the same as SSL_get_session().

- -

SSL_get1_session() is the same as SSL_get_session(), but the reference count of the SSL_SESSION is incremented by one.

- -

NOTES

- -

The ssl session contains all information required to re-establish the connection without a full handshake for SSL versions up to and including TLSv1.2. In TLSv1.3 the same is true, but sessions are established after the main handshake has occurred. The server will send the session information to the client at a time of its choosing, which may be some while after the initial connection is established (or never). Calling these functions on the client side in TLSv1.3 before the session has been established will still return an SSL_SESSION object but that object cannot be used for resuming the session. See SSL_SESSION_is_resumable(3) for information on how to determine whether an SSL_SESSION object can be used for resumption or not.

- -

Additionally, in TLSv1.3, a server can send multiple messages that establish a session for a single connection. In that case, on the client side, the above functions will only return information on the last session that was received. On the server side they will only return information on the last session that was sent, or if no session tickets were sent then the session for the current connection.

- -

The preferred way for applications to obtain a resumable SSL_SESSION object is to use a new session callback as described in SSL_CTX_sess_set_new_cb(3). The new session callback is only invoked when a session is actually established, so this avoids the problem described above where an application obtains an SSL_SESSION object that cannot be used for resumption in TLSv1.3. It also enables applications to obtain information about all sessions sent by the server.

- -

A session will be automatically removed from the session cache and marked as non-resumable if the connection is not closed down cleanly, e.g. if a fatal error occurs on the connection or SSL_shutdown(3) is not called prior to SSL_free(3).

- -

In TLSv1.3 it is recommended that each SSL_SESSION object is only used for resumption once.

- -

SSL_get0_session() returns a pointer to the actual session. As the reference counter is not incremented, the pointer is only valid while the connection is in use. If SSL_clear(3) or SSL_free(3) is called, the session may be removed completely (if considered bad), and the pointer obtained will become invalid. Even if the session is valid, it can be removed at any time due to timeout during SSL_CTX_flush_sessions(3).

- -

If the data is to be kept, SSL_get1_session() will increment the reference count, so that the session will not be implicitly removed by other operations but stays in memory. In order to remove the session SSL_SESSION_free(3) must be explicitly called once to decrement the reference count again.

- -

SSL_SESSION objects keep internal link information about the session cache list, when being inserted into one SSL_CTX object's session cache. One SSL_SESSION object, regardless of its reference count, must therefore only be used with one SSL_CTX object (and the SSL objects created from this SSL_CTX object).

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
NULL
-
- -

There is no session available in ssl.

- -
-
Pointer to an SSL_SESSION
-
- -

The return value points to the data of an SSL session.

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_free(3), SSL_clear(3), SSL_SESSION_free(3)

- -

COPYRIGHT

- -

Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_shared_sigalgs.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_shared_sigalgs.html deleted file mode 100644 index c2ccfc02..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_shared_sigalgs.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -SSL_get_shared_sigalgs - - - - - - - - - - -

NAME

- -

SSL_get_shared_sigalgs, SSL_get_sigalgs - get supported signature algorithms

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_shared_sigalgs(SSL *s, int idx,
-                           int *psign, int *phash, int *psignhash,
-                           unsigned char *rsig, unsigned char *rhash);
-
-int SSL_get_sigalgs(SSL *s, int idx,
-                    int *psign, int *phash, int *psignhash,
-                    unsigned char *rsig, unsigned char *rhash);
- -

DESCRIPTION

- -

SSL_get_shared_sigalgs() returns information about the shared signature algorithms supported by peer s. The parameter idx indicates the index of the shared signature algorithm to return starting from zero. The signature algorithm NID is written to *psign, the hash NID to *phash and the sign and hash NID to *psignhash. The raw signature and hash values are written to *rsig and *rhash.

- -

SSL_get_sigalgs() is similar to SSL_get_shared_sigalgs() except it returns information about all signature algorithms supported by s in the order they were sent by the peer.

- -

RETURN VALUES

- -

SSL_get_shared_sigalgs() and SSL_get_sigalgs() return the number of signature algorithms or 0 if the idx parameter is out of range.

- -

NOTES

- -

These functions are typically called for debugging purposes (to report the peer's preferences) or where an application wants finer control over certificate selection. Most applications will rely on internal handling and will not need to call them.

- -

If an application is only interested in the highest preference shared signature algorithm it can just set idx to zero.

- -

Any or all of the parameters psign, phash, psignhash, rsig or rhash can be set to NULL if the value is not required. By setting them all to NULL and setting idx to zero the total number of signature algorithms can be determined: which can be zero.

- -

These functions must be called after the peer has sent a list of supported signature algorithms: after a client hello (for servers) or a certificate request (for clients). They can (for example) be called in the certificate callback.

- -

Only TLS 1.2, TLS 1.3 and DTLS 1.2 currently support signature algorithms. If these functions are called on an earlier version of TLS or DTLS zero is returned.

- -

The shared signature algorithms returned by SSL_get_shared_sigalgs() are ordered according to configuration and peer preferences.

- -

The raw values correspond to the on the wire form as defined by RFC5246 et al. The NIDs are OpenSSL equivalents. For example if the peer sent sha256(4) and rsa(1) then *rhash would be 4, *rsign 1, *phash NID_sha256, *psig NID_rsaEncryption and *psignhash NID_sha256WithRSAEncryption.

- -

If a signature algorithm is not recognised the corresponding NIDs will be set to NID_undef. This may be because the value is not supported, is not an appropriate combination (for example MD5 and DSA) or the signature algorithm does not use a hash (for example Ed25519).

- -

SEE ALSO

- -

SSL_CTX_set_cert_cb(3), ssl(7)

- -

COPYRIGHT

- -

Copyright 2015-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_stream_id.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_stream_id.html deleted file mode 100644 index f7348a89..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_stream_id.html +++ /dev/null @@ -1,112 +0,0 @@ - - - - -SSL_get_stream_id - - - - - - - - - - -

NAME

- -

SSL_get_stream_id, SSL_get_stream_type, SSL_STREAM_TYPE_NONE, SSL_STREAM_TYPE_READ, SSL_STREAM_TYPE_WRITE, SSL_STREAM_TYPE_BIDI, SSL_is_stream_local - get QUIC stream ID and stream type information

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-uint64_t SSL_get_stream_id(SSL *ssl);
-
-#define SSL_STREAM_TYPE_NONE
-#define SSL_STREAM_TYPE_BIDI
-#define SSL_STREAM_TYPE_READ
-#define SSL_STREAM_TYPE_WRITE
-int SSL_get_stream_type(SSL *ssl);
-
-int SSL_is_stream_local(SSL *ssl);
- -

DESCRIPTION

- -

The SSL_get_stream_id() function returns the QUIC stream ID for a QUIC stream SSL object, or for a QUIC connection SSL object which has a default stream attached.

- -

The SSL_get_stream_type() function identifies what operations can be performed on the stream, and returns one of the following values:

- -
- -
SSL_STREAM_TYPE_NONE
-
- -

The SSL object is a QUIC connection SSL object without a default stream attached.

- -
-
SSL_STREAM_TYPE_BIDI
-
- -

The SSL object is a non-QUIC SSL object, or is a QUIC stream object (or QUIC connection SSL object with a default stream attached), and that stream is a bidirectional QUIC stream.

- -
-
SSL_STREAM_TYPE_READ
-
- -

The SSL object is a QUIC stream object (or QUIC connection SSL object with a default stream attached), and that stream is a unidirectional QUIC stream which was initiated by the remote peer; thus, it can be read from, but not written to.

- -
-
SSL_STREAM_TYPE_WRITE
-
- -

The SSL object is a QUIC stream object (or QUIC connection SSL object with a default stream attached), and that stream is a unidirectional QUIC stream which was initiated by the local application; thus, it can be written to, but not read from.

- -
-
- -

The SSL_is_stream_local() function determines whether a stream was locally created.

- -

NOTES

- -

While QUICv1 assigns specific meaning to the low two bits of a QUIC stream ID, QUIC stream IDs in future versions of QUIC are not required to have the same semantics. Do not determine stream properties using these bits. Instead, use SSL_get_stream_type() to determine the stream type and SSL_get_stream_is_local() to determine the stream initiator.

- -

The SSL_get_stream_type() identifies the type of a QUIC stream based on its identity, and does not indicate whether an operation can currently be successfully performed on a stream. For example, you might locally initiate a unidirectional stream, write to it, and then conclude the stream using SSL_stream_conclude(3), meaning that it can no longer be written to, but SSL_get_stream_type() would still return SSL_STREAM_TYPE_WRITE. The value returned by SSL_get_stream_type() does not vary over the lifespan of a stream.

- -

RETURN VALUES

- -

SSL_get_stream_id() returns a QUIC stream ID, or UINT64_MAX if called on an SSL object which is not a QUIC SSL object, or if called on a QUIC connection SSL object without a default stream attached. Note that valid QUIC stream IDs are always below 2**62.

- -

SSL_get_stream_type() returns one of the SSL_STREAM_TYPE values.

- -

SSL_is_stream_local() returns 1 if called on a QUIC stream SSL object which represents a stream which was locally initiated. It returns 0 if called on a QUIC stream SSL object which represents a stream which was remotely initiated by a peer, and -1 if called on any other kind of SSL object.

- -

SEE ALSO

- -

SSL_new_stream(3), SSL_accept_stream(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_stream_read_state.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_stream_read_state.html deleted file mode 100644 index 890208c9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_stream_read_state.html +++ /dev/null @@ -1,144 +0,0 @@ - - - - -SSL_get_stream_read_state - - - - - - - - - - -

NAME

- -

SSL_get_stream_read_state, SSL_get_stream_write_state, SSL_get_stream_read_error_code, SSL_get_stream_write_error_code, SSL_STREAM_STATE_NONE, SSL_STREAM_STATE_OK, SSL_STREAM_STATE_WRONG_DIR, SSL_STREAM_STATE_FINISHED, SSL_STREAM_STATE_RESET_LOCAL, SSL_STREAM_STATE_RESET_REMOTE, SSL_STREAM_STATE_CONN_CLOSED - get QUIC stream state

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_STREAM_STATE_NONE
-#define SSL_STREAM_STATE_OK
-#define SSL_STREAM_STATE_WRONG_DIR
-#define SSL_STREAM_STATE_FINISHED
-#define SSL_STREAM_STATE_RESET_LOCAL
-#define SSL_STREAM_STATE_RESET_REMOTE
-#define SSL_STREAM_STATE_CONN_CLOSED
-
-int SSL_get_stream_read_state(SSL *ssl);
-int SSL_get_stream_write_state(SSL *ssl);
-
-int SSL_get_stream_read_error_code(SSL *ssl, uint64_t *app_error_code);
-int SSL_get_stream_write_error_code(SSL *ssl, uint64_t *app_error_code);
- -

DESCRIPTION

- -

SSL_get_stream_read_state() and SSL_get_stream_write_state() retrieve the overall state of the receiving and sending parts of a QUIC stream, respectively.

- -

They both return one of the following values:

- -
- -
SSL_STREAM_STATE_NONE
-
- -

This value is returned if called on a non-QUIC SSL object, or on a QUIC connection SSL object without a default stream attached.

- -
-
SSL_STREAM_STATE_OK
-
- -

This value is returned on a stream which has not been concluded and remains healthy.

- -
-
SSL_STREAM_STATE_WRONG_DIR
-
- -

This value is returned if SSL_get_stream_read_state() is called on a locally-initiated (and thus send-only) unidirectional stream, or, conversely, if SSL_get_stream_write_state() is called on a remotely-initiated (and thus receive-only) unidirectional stream.

- -
-
SSL_STREAM_STATE_FINISHED
-
- -

For SSL_get_stream_read_state(), this value is returned when the remote peer has signalled the end of the receiving part of the stream. Note that there may still be residual data available to read via SSL_read(3) when this state is returned.

- -

For SSL_get_stream_write_state(), this value is returned when the local application has concluded the stream using SSL_stream_conclude(3). Future SSL_write(3) calls will not succeed.

- -
-
SSL_STREAM_STATE_RESET_LOCAL
-
- -

This value is returned when the applicable stream part was reset by the local application.

- -

For SSL_get_stream_read_state(), this means that the receiving part of the stream was aborted using a locally transmitted QUIC STOP_SENDING frame. It may or may not still be possible to obtain any residual data which remains to be read by calling SSL_read(3).

- -

For SSL_get_stream_write_state(), this means that the sending part of the stream was aborted, for example because the application called SSL_stream_reset(3), or because a QUIC stream SSL object with an un-concluded sending part was freed using SSL_free(3). Calls to SSL_write(3) will fail.

- -

When this value is returned, the application error code which was signalled can be obtained by calling SSL_get_stream_read_error_code() or SSL_get_stream_write_error_code() as appropriate.

- -
-
SSL_STREAM_STATE_RESET_REMOTE
-
- -

This value is returned when the applicable stream part was reset by the remote peer.

- -

For SSL_get_stream_read_state(), this means that the peer sent a QUIC RESET_STREAM frame for the receiving part of the stream; the receiving part of the stream was logically aborted by the peer.

- -

For SSL_get_stream_write_state(), this means that the peer sent a QUIC STOP_SENDING frame for the sending part of the stream; the peer has indicated that it does not wish to receive further data on the sending part of the stream. Calls to SSL_write(3) will fail.

- -

When this value is returned, the application error code which was signalled can be obtained by calling SSL_get_stream_read_error_code() or SSL_get_stream_write_error_code() as appropriate.

- -
-
SSL_STREAM_STATE_CONN_CLOSED
-
- -

The QUIC connection to which the stream belongs was closed. You can obtain information about the circumstances of this closure using SSL_get_conn_close_info(3). There may still be residual data available to read via SSL_read(3) when this state is returned. Calls to SSL_write(3) will fail. SSL_get_stream_read_state() will return this state if and only if SSL_get_stream_write_state() will also return this state.

- -
-
- -

SSL_get_stream_read_error_code() and SSL_get_stream_write_error_code() provide the application error code which was signalled during non-normal termination of the receiving or sending parts of a stream, respectively. On success, the application error code is written to *app_error_code.

- -

NOTES

- -

If a QUIC connection is closed, the stream state for all streams transitions to SSL_STREAM_STATE_CONN_CLOSED, but no application error code can be retrieved using SSL_get_stream_read_error_code() or SSL_get_stream_write_error_code(), as the QUIC connection closure process does not cause an application error code to be associated with each individual stream still existing at the time of connection closure. However, you can obtain the overall error code associated with the connection closure using SSL_get_conn_close_info(3).

- -

RETURN VALUES

- -

SSL_get_stream_read_state() and SSL_get_stream_write_state() return one of the SSL_STREAM_STATE values. If called on a non-QUIC SSL object, or a QUIC connection SSL object without a default stream, SSL_STREAM_STATE_NONE is returned.

- -

SSL_get_stream_read_error_code() and SSL_get_stream_write_error_code() return 1 on success and 0 if the stream was terminated normally. They return -1 on error, for example if the stream is still healthy, was still healthy at the time of connection closure, if called on a stream for which the respective stream part does not exist (e.g. on a unidirectional stream), or if called on a non-QUIC object or a QUIC connection SSL object without a default stream attached.

- -

SEE ALSO

- -

SSL_stream_conclude(3), SSL_stream_reset(3), SSL_new_stream(3), SSL_accept_stream(3), SSL_get_conn_close_info(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_value_uint.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_value_uint.html deleted file mode 100644 index e646bc45..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_value_uint.html +++ /dev/null @@ -1,280 +0,0 @@ - - - - -SSL_get_value_uint - - - - - - - - - - -

NAME

- -

SSL_get_value_uint, SSL_set_value_uint, SSL_get_generic_value_uint, SSL_set_generic_value_uint, SSL_get_feature_request_uint, SSL_set_feature_request_uint, SSL_get_feature_peer_request_uint, SSL_get_feature_negotiated_uint, SSL_get_quic_stream_bidi_local_avail, SSL_get_quic_stream_bidi_remote_avail, SSL_get_quic_stream_uni_local_avail, SSL_get_quic_stream_uni_remote_avail, SSL_VALUE_CLASS_GENERIC, SSL_VALUE_CLASS_FEATURE_REQUEST, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, SSL_VALUE_CLASS_FEATURE_NEGOTIATED, SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL, SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL, SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL, SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL, SSL_VALUE_QUIC_IDLE_TIMEOUT, SSL_VALUE_EVENT_HANDLING_MODE, SSL_VALUE_EVENT_HANDLING_MODE_INHERIT, SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT, SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT, SSL_get_event_handling_mode, SSL_set_event_handling_mode, SSL_VALUE_STREAM_WRITE_BUF_SIZE, SSL_get_stream_write_buf_size, SSL_VALUE_STREAM_WRITE_BUF_USED, SSL_get_stream_write_buf_used, SSL_VALUE_STREAM_WRITE_BUF_AVAIL, SSL_get_stream_write_buf_avail - manage negotiable features and configuration values for a SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_get_value_uint(SSL *ssl, uint32_t class_, uint32_t id,
-                       uint64_t *value);
-int SSL_set_value_uint(SSL *ssl, uint32_t class_, uint32_t id,
-                       uint64_t value);
-
-#define SSL_VALUE_CLASS_GENERIC
-#define SSL_VALUE_CLASS_FEATURE_REQUEST
-#define SSL_VALUE_CLASS_FEATURE_PEER_REQUEST
-#define SSL_VALUE_CLASS_FEATURE_NEGOTIATED
-
-#define SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL
-#define SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL
-#define SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL
-#define SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL
-#define SSL_VALUE_QUIC_IDLE_TIMEOUT
-
-#define SSL_VALUE_EVENT_HANDLING_MODE
-#define SSL_VALUE_EVENT_HANDLING_MODE_INHERIT
-#define SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT
-#define SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT
-
-#define SSL_VALUE_STREAM_WRITE_BUF_SIZE
-#define SSL_VALUE_STREAM_WRITE_BUF_USED
-#define SSL_VALUE_STREAM_WRITE_BUF_AVAIL
- -

The following convenience macros can also be used:

- -
int SSL_get_generic_value_uint(SSL *ssl, uint32_t id, uint64_t *value);
-int SSL_set_generic_value_uint(SSL *ssl, uint32_t id, uint64_t value);
-
-int SSL_get_feature_request_uint(SSL *ssl, uint32_t id, uint64_t *value);
-int SSL_set_feature_request_uint(SSL *ssl, uint32_t id, uint64_t value);
-
-int SSL_get_feature_peer_request_uint(SSL *ssl, uint32_t id, uint64_t *value);
-int SSL_get_feature_negotiated_uint(SSL *ssl, uint32_t id, uint64_t *value);
-
-int SSL_get_quic_stream_bidi_local_avail(SSL *ssl, uint64_t *value);
-int SSL_get_quic_stream_bidi_remote_avail(SSL *ssl, uint64_t *value);
-int SSL_get_quic_stream_uni_local_avail(SSL *ssl, uint64_t *value);
-int SSL_get_quic_stream_uni_remote_avail(SSL *ssl, uint64_t *value);
-
-int SSL_get_event_handling_mode(SSL *ssl, uint64_t *value);
-int SSL_set_event_handling_mode(SSL *ssl, uint64_t value);
-
-int SSL_get_stream_write_buf_size(SSL *ssl, uint64_t *value);
-int SSL_get_stream_write_buf_avail(SSL *ssl, uint64_t *value);
-int SSL_get_stream_write_buf_used(SSL *ssl, uint64_t *value);
- -

DESCRIPTION

- -

SSL_get_value_uint() and SSL_set_value_uint() provide access to configurable parameters for a given SSL object. Amongst other things, they are used to provide control over the feature negotiation process during establishment of a connection, and access to statistics about that connection.

- -

SSL_get_value_uint() and SSL_set_value_uint() get and set configurable values within a given value class. The value classes are enumerated by SSL_VALUE_CLASS and are as follows:

- -
- -
SSL_VALUE_CLASS_GENERIC
-
- -

Values in this class do not participate in the feature negotiation process. They may represent connection parameters which do not participate in explicit negotiation or provide connection statistics. Values in this class might be read-write or read-only.

- -

You can access values in this class using the convenience macros SSL_get_generic_value_uint() and SSL_set_generic_value_uint() for brevity.

- -
-
SSL_VALUE_CLASS_FEATURE_REQUEST
-
- -

Values in this class are read-write, and represent what the local party is requesting during feature negotiation. Such a request will not necessarily be honoured; see SSL_VALUE_CLASS_FEATURE_NEGOTIATED.

- -

A value in this class may become read-only in certain circumstances; for example, after a connection has been established, for a value which cannot be renegotiated after connection establishment. Setting a value in this class after connection establishment represents a request for online renegotiation of the specified feature.

- -

You can access values in this class using the convenience macros SSL_get_feature_request_uint() and SSL_set_feature_request_uint() for brevity.

- -
-
SSL_VALUE_CLASS_FEATURE_PEER_REQUEST
-
- -

Values in this value class are read-only, and represent what was requested by a peer during feature negotiation. Such a request has not necessarily been honoured; see SSL_VALUE_CLASS_FEATURE_NEGOTIATED.

- -

You can access values in this class using the convenience macro SSL_get_feature_peer_request_uint() for brevity.

- -
-
SSL_VALUE_CLASS_FEATURE_NEGOTIATED
-
- -

Values in this value class are read-only, and represent the value which was actually negotiated based on both local and peer input during feature negotiation. This is the effective value in actual use.

- -

Attempting to read a value in this class will generally fail if the feature negotiation process has not yet completed and the value is therefore currently unknown, unless the nature of the feature in question causes a provisional value to be used prior to completion of feature negotiation, in which case that value may be returned. If an online (post-handshake) renegotiation of a feature is in progress, retrieving the negotiated value will continue to retrieve the previous negotiated value until that process is completed. See the documentation of specific values for full details of its behaviour.

- -

You can access values in this class using the convenience macro SSL_get_feature_negotiated_uint() for brevity.

- -
-
- -

CONFIGURABLE VALUES FOR QUIC OBJECTS

- -

The following configurable values are supported for QUIC SSL objects. Whether a value is supported for a QUIC connection SSL object or a QUIC stream SSL object is indicated in the heading for each value. Values supported for QUIC stream SSL objects are also supported on QUIC connection SSL objects if they have a default stream attached.

- -

SSL_get_value() does not cause internal event processing to occur unless the documentation for a specific value specifies otherwise.

- -
- -
SSL_VALUE_QUIC_IDLE_TIMEOUT (connection object)
-
- -

Negotiated feature value. This configures the desired QUIC idle timeout in milliseconds, where 0 represents a lack of an idle timeout. This feature can only be configured prior to connection establishment and cannot be subsequently changed.

- -

This release of OpenSSL uses a default value of 30 seconds. This default value may change between releases of OpenSSL.

- -
-
SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL (connection object)
-
- -

Generic read-only statistical value. The number of bidirectional, locally-initiated streams available to be created (but not yet created). For example, a value of 100 would mean that SSL_new_stream(3) could be called 100 times to create 100 bidirectional streams before SSL_new_stream(3) would block or fail due to backpressure.

- -

Can be queried using the convenience macro SSL_get_quic_stream_bidi_local_avail().

- -
-
SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL (connection object)
-
- -

As above, but provides the number of unidirectional, locally-initiated streams available to be created (but not yet created).

- -

Can be queried using the convenience macro SSL_get_quic_stream_uni_local_avail().

- -
-
SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL (connection object)
-
- -

As above, but provides the number of bidirectional, remotely-initiated streams available to be created (but not yet created) by the peer. This represents the number of streams the local endpoint has authorised the peer to create in terms of QUIC stream creation flow control.

- -

Can be queried using the convenience macro SSL_get_quic_stream_bidi_remote_avail().

- -
-
SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL (connection object)
-
- -

As above, but provides the number of unidirectional, remotely-initiated streams available to be created (but not yet created).

- -

Can be queried using the convenience macro SSL_get_quic_stream_uni_remote_avail().

- -
-
SSL_VALUE_EVENT_HANDLING_MODE (connection or stream object)
-
- -

Generic value. This is an integer value which takes one of the following values, and determines the event handling mode in use:

- -
- -
SSL_VALUE_EVENT_HANDLING_MODE_INHERIT
-
- -

When set, the event handling mode used is inherited from the value set on the parent connection (for a stream), or, for a connection, defaults to the implicit event handling model.

- -

When a new connection is created, or a new stream is created or accepted, it defaults to this setting.

- -
-
SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT (Implicit event handling)
-
- -

If set to this value, the implicit event handling model is used. Under this model, QUIC objects will automatically perform background event processing (equivalent to a call to SSL_handle_events(3)) when calls to I/O functions such as SSL_read_ex(3) or SSL_write_ex(3) are made on a QUIC SSL object. This helps to maintain the health of the QUIC connection and ensures that incoming datagrams and timeout events are processed.

- -
-
SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT (Explicit event handling)
-
- -

If set to this value, the explicit event handling model is used. Under this model, nonblocking calls to I/O functions such as SSL_read_ex(3) or SSL_write_ex(3) do not result in the automatic processing of QUIC events. Any new incoming network traffic is not handled; no new outgoing network traffic is generated, and pending timeout events are not processed. This allows an application to obtain greater control over the circumstances in which QUIC event processing occurs. If this event handling model is used, it is the application's responsibility to call SSL_handle_events(3) as and when called for by the QUIC implementation; see the SSL_get_rpoll_descriptor(3) man page for more information.

- -

Selecting this model does not affect the operation of blocking I/O calls, which will continue to use the implicit event handling model. Therefore, applications using this model will generally want to disable blocking operation using SSL_set_blocking_mode(3).

- -
-
- -

Can be configured using the convenience macros SSL_get_event_handling_mode() and SSL_set_event_handling_mode().

- -

A call to SSL_set_value_uint() which causes this value to switch back to the implicit event handling model does not in itself cause implicit event handling to occur; such handling will occur on the next I/O API call. Equally, a call to SSL_set_value_uint() which causes this value to switch to the explicit event handling model will not cause event handling to occur before making that transition.

- -

This value controls whether implicit event handling occurs when making an I/O API call on the SSL object it is set on. However, event processing is not confined to state which relates to only that object. For example, if you configure explicit event handling on QUIC stream SSL object "A" and configure implicit event handling on QUIC stream SSL object "B", a call to an I/O function on "B" may result in state changes to "A". In other words, if event handling does happen as a result of an API call to an object related to a connection, processing of background events (for example, received QUIC network traffic) may also affect the state of any other object related to a connection.

- -
-
SSL_VALUE_STREAM_WRITE_BUF_SIZE (stream object)
-
- -

Generic read-only statistical value. The size of the write buffer allocated to hold data written to a stream with SSL_write_ex(3) until it is transmitted and subsequently acknowledged by the peer. This value may change at any time, as buffer sizes are optimised in response to network conditions to optimise throughput.

- -

Can be queried using the convenience macro SSL_get_stream_write_buf_size().

- -
-
SSL_VALUE_STREAM_WRITE_BUF_USED (stream object)
-
- -

Generic read-only statistical value. The number of bytes currently consumed in the write buffer which have yet to be acknowledged by the peer. Successful calls to SSL_write_ex(3) which accept data cause this number to increase. This number will then decrease as data is acknowledged by the peer.

- -

Can be queried using the convenience macro SSL_get_stream_write_buf_used().

- -
-
SSL_VALUE_STREAM_WRITE_BUF_AVAIL (stream object)
-
- -

Generic read-only statistical value. The number of bytes available in the write buffer which have yet to be consumed by calls to SSL_write_ex(3). Successful calls to SSL_write_ex(3) which accept data cause this number to decrease. This number will increase as data is acknowledged by the peer. It may also change if the buffer is resized automatically to optimise throughput.

- -

Can be queried using the convenience macro SSL_get_stream_write_buf_avail().

- -
-
- -

No configurable values are currently defined for non-QUIC SSL objects.

- -

RETURN VALUES

- -

Returns 1 on success or 0 on failure. This function can fail for a number of reasons:

- - - -

SEE ALSO

- -

SSL_ctrl(3), SSL_get_accept_stream_queue_len(3), SSL_get_stream_read_state(3), SSL_get_stream_write_state(3), SSL_get_stream_read_error_code(3), SSL_get_stream_write_error_code(3), SSL_set_default_stream_mode(3), SSL_set_incoming_stream_policy(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_verify_result.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_verify_result.html deleted file mode 100644 index a587d215..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_verify_result.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -SSL_get_verify_result - - - - - - - - - - -

NAME

- -

SSL_get_verify_result - get result of peer certificate verification

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-long SSL_get_verify_result(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_get_verify_result() returns the result of the verification of the X509 certificate presented by the peer, if any.

- -

NOTES

- -

SSL_get_verify_result() can only return one error code while the verification of a certificate can fail because of many reasons at the same time. Only the last verification error that occurred during the processing is available from SSL_get_verify_result().

- -

Sometimes there can be a sequence of errors leading to the verification failure as reported by SSL_get_verify_result(). To get the errors, it is necessary to setup a verify callback via SSL_CTX_set_verify(3) or SSL_set_verify(3) and retrieve the errors from the error stack there, because once SSL_connect(3) returns, these errors may no longer be available.

- -

The verification result is part of the established session and is restored when a session is reused.

- -

BUGS

- -

If no peer certificate was presented, the returned result code is X509_V_OK. This is because no verification error occurred, it does however not indicate success. SSL_get_verify_result() is only useful in connection with SSL_get_peer_certificate(3).

- -

RETURN VALUES

- -

The following return values can currently occur:

- -
- -
X509_V_OK
-
- -

The verification succeeded or no peer certificate was presented.

- -
-
Any other value
-
- -

Documented in openssl-verify(1).

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_set_verify_result(3), SSL_get_peer_certificate(3), openssl-verify(1)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_get_version.html b/openssl-install/share/doc/openssl/html/man3/SSL_get_version.html deleted file mode 100644 index 44b173cf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_get_version.html +++ /dev/null @@ -1,201 +0,0 @@ - - - - -SSL_get_version - - - - - - - - - - -

NAME

- -

SSL_client_version, SSL_get_version, SSL_is_dtls, SSL_is_tls, SSL_is_quic, SSL_version - get the protocol information of a connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_client_version(const SSL *s);
-
-const char *SSL_get_version(const SSL *ssl);
-
-int SSL_is_dtls(const SSL *ssl);
-int SSL_is_tls(const SSL *ssl);
-int SSL_is_quic(const SSL *ssl);
-
-int SSL_version(const SSL *s);
- -

DESCRIPTION

- -

For SSL, TLS and DTLS protocols SSL_client_version() returns the numeric protocol version advertised by the client in the legacy_version field of the ClientHello when initiating the connection. Note that, for TLS, this value will never indicate a version greater than TLSv1.2 even if TLSv1.3 is subsequently negotiated. For QUIC connections it returns OSSL_QUIC1_VERSION.

- -

SSL_get_version() returns the name of the protocol used for the connection. SSL_version() returns the numeric protocol version used for the connection. They should only be called after the initial handshake has been completed. Prior to that the results returned from these functions may be unreliable.

- -

SSL_is_dtls() returns 1 if the connection is using DTLS or 0 if not.

- -

SSL_is_tls() returns 1 if the connection is using SSL/TLS or 0 if not.

- -

SSL_is_quic() returns 1 if the connection is using QUIC or 0 if not.

- -

RETURN VALUES

- -

SSL_get_version() returns one of the following strings:

- -
- -
SSLv3
-
- -

The connection uses the SSLv3 protocol.

- -
-
TLSv1
-
- -

The connection uses the TLSv1.0 protocol.

- -
-
TLSv1.1
-
- -

The connection uses the TLSv1.1 protocol.

- -
-
TLSv1.2
-
- -

The connection uses the TLSv1.2 protocol.

- -
-
TLSv1.3
-
- -

The connection uses the TLSv1.3 protocol.

- -
-
DTLSv0.9
-
- -

The connection uses an obsolete pre-standardisation DTLS protocol

- -
-
DTLSv1
-
- -

The connection uses the DTLSv1 protocol

- -
-
DTLSv1.2
-
- -

The connection uses the DTLSv1.2 protocol

- -
-
QUICv1
-
- -

The connection uses the QUICv1 protocol.

- -
-
unknown
-
- -

This indicates an unknown protocol version.

- -
-
- -

SSL_version() and SSL_client_version() return an integer which could include any of the following:

- -
- -
SSL3_VERSION
-
- -

The connection uses the SSLv3 protocol.

- -
-
TLS1_VERSION
-
- -

The connection uses the TLSv1.0 protocol.

- -
-
TLS1_1_VERSION
-
- -

The connection uses the TLSv1.1 protocol.

- -
-
TLS1_2_VERSION
-
- -

The connection uses the TLSv1.2 protocol.

- -
-
TLS1_3_VERSION
-
- -

The connection uses the TLSv1.3 protocol (never returned for SSL_client_version()).

- -
-
DTLS1_BAD_VER
-
- -

The connection uses an obsolete pre-standardisation DTLS protocol

- -
-
DTLS1_VERSION
-
- -

The connection uses the DTLSv1 protocol

- -
-
DTLS1_2_VERSION
-
- -

The connection uses the DTLSv1.2 protocol

- -
-
OSSL_QUIC1_VERSION
-
- -

The connection uses the QUICv1 protocol.

- -
-
- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

The SSL_is_dtls() function was added in OpenSSL 1.1.0. The SSL_is_tls() and SSL_is_quic() functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_group_to_name.html b/openssl-install/share/doc/openssl/html/man3/SSL_group_to_name.html deleted file mode 100644 index 8a5eec49..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_group_to_name.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -SSL_group_to_name - - - - - - - - - - -

NAME

- -

SSL_group_to_name - get name of group

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_group_to_name(SSL *ssl, int id);
- -

DESCRIPTION

- -

SSL_group_to_name() is used to retrieve the TLS group name associated with a given TLS group ID, as registered via built-in or external providers and as returned by a call to SSL_get1_groups() or SSL_get_shared_group().

- -

RETURN VALUES

- -

If non-NULL, SSL_group_to_name() returns the TLS group name corresponding to the given id as a NUL-terminated string. If SSL_group_to_name() returns NULL, an error occurred; possibly no corresponding tlsname was registered during provider initialisation.

- -

Note that the return value is valid only during the lifetime of the SSL object ssl.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_handle_events.html b/openssl-install/share/doc/openssl/html/man3/SSL_handle_events.html deleted file mode 100644 index da0eb89d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_handle_events.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -SSL_handle_events - - - - - - - - - - -

NAME

- -

SSL_handle_events - advance asynchronous state machine and perform network I/O

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_handle_events(SSL *ssl);
- -

DESCRIPTION

- -

SSL_handle_events() performs any internal processing which is due on a SSL object. The exact operations performed by SSL_handle_events() vary depending on what kind of protocol is being used with the given SSL object. For example, SSL_handle_events() may handle timeout events which have become due, or may attempt, to the extent currently possible, to perform network I/O operations on one of the BIOs underlying the SSL object.

- -

The primary use case for SSL_handle_events() is to allow an application which uses OpenSSL in nonblocking mode to give OpenSSL an opportunity to handle timer events, or to respond to the availability of new data to be read from an underlying BIO, or to respond to the opportunity to write pending data to an underlying BIO.

- -

SSL_handle_events() can be used only with the following types of SSL object:

- -
- -
DTLS SSL objects
-
- -

Using SSL_handle_events() on an SSL object being used with a DTLS method allows timeout events to be handled properly. This is equivalent to a call to DTLSv1_handle_timeout(3). Since SSL_handle_events() handles a superset of the use cases of DTLSv1_handle_timeout(3), it should be preferred for new applications which do not require support for OpenSSL 3.1 or older.

- -

When using DTLS, an application must call SSL_handle_events() as indicated by calls to SSL_get_event_timeout(3); event handling is not performed automatically by calls to other SSL functions such as SSL_read(3) or SSL_write(3). Note that this is different to QUIC which also performs event handling implicitly; see below.

- -
-
QUIC connection SSL objects
-
- -

Using SSL_handle_events() on an SSL object which represents a QUIC connection allows timeout events to be handled properly, as well as incoming network data to be processed, and queued outgoing network data to be written, if the underlying BIO has the capacity to accept it.

- -

Ordinarily, when an application uses an SSL object in blocking mode, it does not need to call SSL_handle_events() because OpenSSL performs ticking internally on an automatic basis. However, if an application uses a QUIC connection in nonblocking mode, it must at a minimum ensure that SSL_handle_events() is called periodically to allow timeout events to be handled. An application can find out when it next needs to call SSL_handle_events() for this purpose (if at all) by calling SSL_get_event_timeout(3).

- -

Calling SSL_handle_events() on a QUIC connection SSL object being used in blocking mode is not necessary unless no I/O calls (such as SSL_read(3) or SSL_write(3)) will be made to the object for a substantial period of time. So long as at least one call to the SSL object is blocking, no such call is needed. However, SSL_handle_events() may optionally be used on a QUIC connection object if desired.

- -

With the thread-assisted mode of operation OSSL_QUIC_client_thread_method(3) it is unnecessary to call SSL_handle_events() as the assist thread handles the QUIC connection events.

- -
-
- -

Calling SSL_handle_events() on any other kind of SSL object is a no-op. This is considered a success case.

- -

Note that SSL_handle_events() supersedes the older DTLSv1_handle_timeout(3) function for all use cases.

- -

RETURN VALUES

- -

Returns 1 on success and 0 on failure.

- -

SEE ALSO

- -

SSL_get_event_timeout(3), DTLSv1_handle_timeout(3), ssl(7)

- -

HISTORY

- -

The SSL_handle_events() function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_in_init.html b/openssl-install/share/doc/openssl/html/man3/SSL_in_init.html deleted file mode 100644 index 62681f8c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_in_init.html +++ /dev/null @@ -1,117 +0,0 @@ - - - - -SSL_in_init - - - - - - - - - - -

NAME

- -

SSL_in_before, SSL_in_init, SSL_is_init_finished, SSL_in_connect_init, SSL_in_accept_init, SSL_get_state - retrieve information about the handshake state machine

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_in_init(const SSL *s);
-int SSL_in_before(const SSL *s);
-int SSL_is_init_finished(const SSL *s);
-
-int SSL_in_connect_init(SSL *s);
-int SSL_in_accept_init(SSL *s);
-
-OSSL_HANDSHAKE_STATE SSL_get_state(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_in_init() returns 1 if the SSL/TLS state machine is currently processing or awaiting handshake messages, or 0 otherwise.

- -

SSL_in_before() returns 1 if no SSL/TLS handshake has yet been initiated, or 0 otherwise.

- -

SSL_is_init_finished() returns 1 if the SSL/TLS connection is in a state where fully protected application data can be transferred or 0 otherwise.

- -

Note that in some circumstances (such as when early data is being transferred) SSL_in_init(), SSL_in_before() and SSL_is_init_finished() can all return 0.

- -

SSL_in_connect_init() returns 1 if s is acting as a client and SSL_in_init() would return 1, or 0 otherwise.

- -

SSL_in_accept_init() returns 1 if s is acting as a server and SSL_in_init() would return 1, or 0 otherwise.

- -

SSL_in_connect_init() and SSL_in_accept_init() are implemented as macros.

- -

SSL_get_state() returns a value indicating the current state of the handshake state machine. OSSL_HANDSHAKE_STATE is an enumerated type where each value indicates a discrete state machine state. Note that future versions of OpenSSL may define more states so applications should expect to receive unrecognised state values. The naming format is made up of a number of elements as follows:

- -

protocol_ST_role_message

- -

protocol is one of TLS or DTLS. DTLS is used where a state is specific to the DTLS protocol. Otherwise TLS is used.

- -

role is one of CR, CW, SR or SW to indicate "client reading", "client writing", "server reading" or "server writing" respectively.

- -

message is the name of a handshake message that is being or has been sent, or is being or has been processed.

- -

Additionally there are some special states that do not conform to the above format. These are:

- -
- -
TLS_ST_BEFORE
-
- -

No handshake messages have yet been been sent or received.

- -
-
TLS_ST_OK
-
- -

Handshake message sending/processing has completed.

- -
-
TLS_ST_EARLY_DATA
-
- -

Early data is being processed

- -
-
TLS_ST_PENDING_EARLY_DATA_END
-
- -

Awaiting the end of early data processing

- -
-
- -

RETURN VALUES

- -

SSL_in_init(), SSL_in_before(), SSL_is_init_finished(), SSL_in_connect_init() and SSL_in_accept_init() return values as indicated above.

- -

SSL_get_state() returns the current handshake state.

- -

SEE ALSO

- -

ssl(7), SSL_read_early_data(3)

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_inject_net_dgram.html b/openssl-install/share/doc/openssl/html/man3/SSL_inject_net_dgram.html deleted file mode 100644 index 1ca9e55d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_inject_net_dgram.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -SSL_inject_net_dgram - - - - - - - - - - -

NAME

- -

SSL_inject_net_dgram - inject a datagram as though received from the network

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_inject_net_dgram(SSL *s, const unsigned char *buf,
-                         size_t buf_len,
-                         const BIO_ADDR *peer,
-                         const BIO_ADDR *local);
- -

DESCRIPTION

- -

This function can be used to inject a datagram payload to a QUIC connection SSL object. The payload is processed as though it was received from the network. This function can be used for debugging purposes or to allow datagrams to be fed to QUIC from alternative sources.

- -

buf is required and must point to a datagram payload to inject. buf_len is the length of the buffer in bytes. The buffer is copied and need not remain valid after this function returns.

- -

peer and local are optional values pointing to BIO_ADDR structures describing the remote and local UDP endpoint addresses for the packet. Though the injected packet was not actually received from the network directly by OpenSSL, the packet will be processed as though the received datagram had the given addresses.

- -

RETURN VALUES

- -

Returns 1 on success or 0 on failure. This function always fails if called on a SSL object which is not a QUIC connection SSL object.

- -

SEE ALSO

- -

OSSL_QUIC_client_method(3), SSL_handle_events(3), SSL_set_blocking_mode(3)

- -

HISTORY

- -

The function SSL_inject_net_dgram() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_key_update.html b/openssl-install/share/doc/openssl/html/man3/SSL_key_update.html deleted file mode 100644 index 9ceeb8e8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_key_update.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -SSL_key_update - - - - - - - - - - -

NAME

- -

SSL_key_update, SSL_get_key_update_type, SSL_renegotiate, SSL_renegotiate_abbreviated, SSL_renegotiate_pending - initiate and obtain information about updating connection keys

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_key_update(SSL *s, int updatetype);
-int SSL_get_key_update_type(const SSL *s);
-
-int SSL_renegotiate(SSL *s);
-int SSL_renegotiate_abbreviated(SSL *s);
-int SSL_renegotiate_pending(const SSL *s);
- -

DESCRIPTION

- -

SSL_key_update() schedules an update of the keys for the current TLS connection. If the updatetype parameter is set to SSL_KEY_UPDATE_NOT_REQUESTED then the sending keys for this connection will be updated and the peer will be informed of the change. If the updatetype parameter is set to SSL_KEY_UPDATE_REQUESTED then the sending keys for this connection will be updated and the peer will be informed of the change along with a request for the peer to additionally update its sending keys. It is an error if updatetype is set to SSL_KEY_UPDATE_NONE.

- -

SSL_key_update() must only be called after the initial handshake has been completed and TLSv1.3 or QUIC has been negotiated, at the same time, the application needs to ensure that the writing of data has been completed. The key update will not take place until the next time an IO operation such as SSL_read_ex() or SSL_write_ex() takes place on the connection. Alternatively SSL_do_handshake() can be called to force the update to take place immediately.

- -

SSL_get_key_update_type() can be used to determine whether a key update operation has been scheduled but not yet performed. The type of the pending key update operation will be returned if there is one, or SSL_KEY_UPDATE_NONE otherwise.

- -

SSL_renegotiate() and SSL_renegotiate_abbreviated() should only be called for connections that have negotiated TLSv1.2 or less. Calling them on any other connection will result in an error.

- -

When called from the client side, SSL_renegotiate() schedules a completely new handshake over an existing SSL/TLS connection. The next time an IO operation such as SSL_read_ex() or SSL_write_ex() takes place on the connection a check will be performed to confirm that it is a suitable time to start a renegotiation. If so, then it will be initiated immediately. OpenSSL will not attempt to resume any session associated with the connection in the new handshake. Note that some servers will respond to reneogitation attempts with a "no_renegotiation" alert. An OpenSSL will immediately fail the connection in this case.

- -

When called from the client side, SSL_renegotiate_abbreviated() works in the same was as SSL_renegotiate() except that OpenSSL will attempt to resume the session associated with the current connection in the new handshake.

- -

When called from the server side, SSL_renegotiate() and SSL_renegotiate_abbreviated() behave identically. They both schedule a request for a new handshake to be sent to the client. The next time an IO operation is performed then the same checks as on the client side are performed and then, if appropriate, the request is sent. The client may or may not respond with a new handshake and it may or may not attempt to resume an existing session. If a new handshake is started then this will be handled transparently by calling any OpenSSL IO function.

- -

If an OpenSSL client receives a renegotiation request from a server then again this will be handled transparently through calling any OpenSSL IO function. For a TLS connection the client will attempt to resume the current session in the new handshake. For historical reasons, DTLS clients will not attempt to resume the session in the new handshake.

- -

The SSL_renegotiate_pending() function returns 1 if a renegotiation or renegotiation request has been scheduled but not yet acted on, or 0 otherwise.

- -

USAGE WITH QUIC

- -

SSL_key_update() can also be used to perform a key update when using QUIC. The function must be called on a QUIC connection SSL object. This is normally done automatically when needed. Since a locally initiated QUIC key update always causes a peer to also trigger a key update, passing SSL_KEY_UPDATE_NOT_REQUESTED as updatetype has the same effect as passing SSL_KEY_UPDATE_REQUESTED.

- -

The QUIC connection must have been fully established before a key update can be performed, and other QUIC protocol rules govern how frequently QUIC key update can be performed. SSL_key_update() will fail if these requirements are not met.

- -

Because QUIC key updates are always handled immediately, SSL_get_key_update_type() always returns SSL_KEY_UPDATE_NONE when called on a QUIC connection SSL object.

- -

RETURN VALUES

- -

SSL_key_update(), SSL_renegotiate() and SSL_renegotiate_abbreviated() return 1 on success or 0 on error.

- -

SSL_get_key_update_type() returns the update type of the pending key update operation or SSL_KEY_UPDATE_NONE if there is none.

- -

SSL_renegotiate_pending() returns 1 if a renegotiation or renegotiation request has been scheduled but not yet acted on, or 0 otherwise.

- -

SEE ALSO

- -

ssl(7), SSL_read_ex(3), SSL_write_ex(3), SSL_do_handshake(3)

- -

HISTORY

- -

The SSL_key_update() and SSL_get_key_update_type() functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_library_init.html b/openssl-install/share/doc/openssl/html/man3/SSL_library_init.html deleted file mode 100644 index 72ebd391..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_library_init.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -SSL_library_init - - - - - - - - - - -

NAME

- -

SSL_library_init, OpenSSL_add_ssl_algorithms - initialize SSL library by registering algorithms

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_library_init(void);
-
-int OpenSSL_add_ssl_algorithms(void);
- -

DESCRIPTION

- -

SSL_library_init() registers the available SSL/TLS ciphers and digests.

- -

OpenSSL_add_ssl_algorithms() is a synonym for SSL_library_init() and is implemented as a macro.

- -

NOTES

- -

SSL_library_init() must be called before any other action takes place. SSL_library_init() is not reentrant.

- -

WARNINGS

- -

SSL_library_init() adds ciphers and digests used directly and indirectly by SSL/TLS.

- -

RETURN VALUES

- -

SSL_library_init() always returns "1", so it is safe to discard the return value.

- -

SEE ALSO

- -

ssl(7), RAND_add(3)

- -

HISTORY

- -

The SSL_library_init() and OpenSSL_add_ssl_algorithms() functions were deprecated in OpenSSL 1.1.0 by OPENSSL_init_ssl().

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_load_client_CA_file.html b/openssl-install/share/doc/openssl/html/man3/SSL_load_client_CA_file.html deleted file mode 100644 index eaa08f49..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_load_client_CA_file.html +++ /dev/null @@ -1,134 +0,0 @@ - - - - -SSL_load_client_CA_file - - - - - - - - - - -

NAME

- -

SSL_load_client_CA_file_ex, SSL_load_client_CA_file, SSL_add_file_cert_subjects_to_stack, SSL_add_dir_cert_subjects_to_stack, SSL_add_store_cert_subjects_to_stack - load certificate names

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-STACK_OF(X509_NAME) *SSL_load_client_CA_file_ex(const char *file,
-                                                OSSL_LIB_CTX *libctx,
-                                                const char *propq);
-STACK_OF(X509_NAME) *SSL_load_client_CA_file(const char *file);
-
-int SSL_add_file_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack,
-                                        const char *file);
-int SSL_add_dir_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack,
-                                       const char *dir);
-int SSL_add_store_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack,
-                                         const char *store);
- -

DESCRIPTION

- -

SSL_load_client_CA_file_ex() reads certificates from file and returns a STACK_OF(X509_NAME) with the subject names found. The library context libctx and property query propq are used when fetching algorithms from providers.

- -

SSL_load_client_CA_file() is similar to SSL_load_client_CA_file_ex() but uses NULL for the library context libctx and property query propq.

- -

SSL_add_file_cert_subjects_to_stack() reads certificates from file, and adds their subject name to the already existing stack.

- -

SSL_add_dir_cert_subjects_to_stack() reads certificates from every file in the directory dir, and adds their subject name to the already existing stack.

- -

SSL_add_store_cert_subjects_to_stack() loads certificates from the store URI, and adds their subject name to the already existing stack.

- -

NOTES

- -

SSL_load_client_CA_file() reads a file of PEM formatted certificates and extracts the X509_NAMES of the certificates found. While the name suggests the specific usage as support function for SSL_CTX_set_client_CA_list(3), it is not limited to CA certificates.

- -

RETURN VALUES

- -

The following return values can occur for SSL_load_client_CA_file_ex(), and SSL_load_client_CA_file():

- -
- -
NULL
-
- -

The operation failed, check out the error stack for the reason.

- -
-
Pointer to STACK_OF(X509_NAME)
-
- -

Pointer to the subject names of the successfully read certificates.

- -
-
- -

The following return values can occur for SSL_add_file_cert_subjects_to_stack(), SSL_add_dir_cert_subjects_to_stack(), and SSL_add_store_cert_subjects_to_stack():

- -
- -
0 (Failure)
-
- -

The operation failed.

- -
-
1 (Success)
-
- -

The operation succeeded.

- -
-
- -

EXAMPLES

- -

Load names of CAs from file and use it as a client CA list:

- -
SSL_CTX *ctx;
-STACK_OF(X509_NAME) *cert_names;
-
-...
-cert_names = SSL_load_client_CA_file("/path/to/CAfile.pem");
-if (cert_names != NULL)
-    SSL_CTX_set_client_CA_list(ctx, cert_names);
-else
-    /* error */
-...
- -

SEE ALSO

- -

ssl(7), ossl_store(7), SSL_CTX_set_client_CA_list(3)

- -

HISTORY

- -

SSL_load_client_CA_file_ex() and SSL_add_store_cert_subjects_to_stack() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_new.html b/openssl-install/share/doc/openssl/html/man3/SSL_new.html deleted file mode 100644 index e4497e74..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_new.html +++ /dev/null @@ -1,182 +0,0 @@ - - - - -SSL_new - - - - - - - - - - -

NAME

- -

SSL_dup, SSL_new, SSL_up_ref - create an SSL structure for a connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL *SSL_dup(SSL *s);
-SSL *SSL_new(SSL_CTX *ctx);
-int SSL_up_ref(SSL *s);
- -

DESCRIPTION

- -

SSL_new() creates a new SSL structure which is needed to hold the data for a TLS/SSL connection. The new structure inherits the settings of the underlying context ctx: connection method, options, verification settings, timeout settings. An SSL structure is reference counted. Creating an SSL structure for the first time increments the reference count. Freeing it (using SSL_free) decrements it. When the reference count drops to zero, any memory or resources allocated to the SSL structure are freed.

- -

SSL_up_ref() increments the reference count for an existing SSL structure.

- -

The function SSL_dup() creates and returns a new SSL structure from the same SSL_CTX that was used to create s. It additionally duplicates a subset of the settings in s into the new SSL object.

- -

For SSL_dup() to work, the connection MUST be in its initial state and MUST NOT have yet started the SSL handshake. For connections that are not in their initial state SSL_dup() just increments an internal reference count and returns the same handle. It may be possible to use SSL_clear(3) to recycle an SSL handle that is not in its initial state for reuse, but this is best avoided. Instead, save and restore the session, if desired, and construct a fresh handle for each connection.

- -

The subset of settings in s that are duplicated are:

- -
- -
any session data if configured (including the session_id_context)
-
- -
-
any tmp_dh settings set via SSL_set_tmp_dh(3), SSL_set_tmp_dh_callback(3), or SSL_set_dh_auto(3)
-
- -
-
any configured certificates, private keys or certificate chains
-
- -
-
any configured signature algorithms, or client signature algorithms
-
- -
-
any DANE settings
-
- -
-
any Options set via SSL_set_options(3)
-
- -
-
any Mode set via SSL_set_mode(3)
-
- -
-
any minimum or maximum protocol settings set via SSL_set_min_proto_version(3) or SSL_set_max_proto_version(3) (Note: Only from OpenSSL 1.1.1h and above)
-
- -
-
any verify mode, callback or depth set via SSL_set_verify(3) or SSL_set_verify_depth(3) or any configured X509 verification parameters
-
- -
-
any msg callback or info callback set via SSL_set_msg_callback(3) or SSL_set_info_callback(3)
-
- -
-
any default password callback set via SSL_set_default_passwd_cb(3)
-
- -
-
any session id generation callback set via SSL_set_generate_session_id(3)
-
- -
-
any configured Cipher List
-
- -
-
initial accept (server) or connect (client) state
-
- -
-
the max cert list value set via SSL_set_max_cert_list(3)
-
- -
-
the read_ahead value set via SSL_set_read_ahead(3)
-
- -
-
application specific data set via SSL_set_ex_data(3)
-
- -
-
any CA list or client CA list set via SSL_set0_CA_list(3), SSL_set0_client_CA_list() or similar functions
-
- -
-
any security level settings or callbacks
-
- -
-
any configured serverinfo data
-
- -
-
any configured PSK identity hint
-
- -
-
any configured custom extensions
-
- -
-
any client certificate types configured via SSL_set1_client_certificate_types
-
- -
-
- -

SSL_dup() is not supported on QUIC SSL objects and returns NULL if called on such an object.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
NULL
-
- -

The creation of a new SSL structure failed. Check the error stack to find out the reason.

- -
-
Pointer to an SSL structure
-
- -

The return value points to an allocated SSL structure.

- -

SSL_up_ref() returns 1 for success and 0 for failure.

- -
-
- -

SEE ALSO

- -

SSL_free(3), SSL_clear(3), SSL_CTX_set_options(3), SSL_get_SSL_CTX(3), ssl(7)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_new_stream.html b/openssl-install/share/doc/openssl/html/man3/SSL_new_stream.html deleted file mode 100644 index 13372b45..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_new_stream.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -SSL_new_stream - - - - - - - - - - -

NAME

- -

SSL_new_stream, SSL_STREAM_FLAG_UNI, SSL_STREAM_FLAG_NO_BLOCK, SSL_STREAM_FLAG_ADVANCE - create a new locally-initiated QUIC stream

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_STREAM_FLAG_UNI          (1U << 0)
-#define SSL_STREAM_FLAG_NO_BLOCK     (1U << 1)
-#define SSL_STREAM_FLAG_ADVANCE      (1U << 2)
-SSL *SSL_new_stream(SSL *ssl, uint64_t flags);
- -

DESCRIPTION

- -

The SSL_new_stream() function, when passed a QUIC connection SSL object, creates a new locally-initiated bidirectional or unidirectional QUIC stream and returns the newly created QUIC stream SSL object.

- -

If the SSL_STREAM_FLAG_UNI flag is passed, a unidirectional stream is created; else a bidirectional stream is created.

- -

To retrieve the stream ID of the newly created stream, use SSL_get_stream_id(3).

- -

It is the caller's responsibility to free the QUIC stream SSL object using SSL_free(3). The lifetime of the QUIC connection SSL object must exceed that of the QUIC stream SSL object; in other words, the QUIC stream SSL object must be freed first.

- -

Once a stream has been created using SSL_new_stream(), it may be used in the normal way using SSL_read(3) and SSL_write(3).

- -

This function can only be used to create stream objects for locally-initiated streams. To accept incoming streams initiated by a peer, use SSL_accept_stream(3).

- -

Calling SSL_new_stream() if there is no default stream already present inhibits the future creation of a default stream. See openssl-quic(7).

- -

The creation of new streams is subject to flow control by the QUIC protocol. If it is currently not possible to create a new locally initiated stream of the specified type, a call to SSL_new_stream() will either block (if the connection is configured in blocking mode) until a new stream can be created, or otherwise return NULL.

- -

This function operates in blocking mode if the QUIC connection SSL object is configured in blocking mode (see SSL_set_blocking_mode(3)). It may also be used in nonblocking mode on a connection configured in blocking mode by passing the flag SSL_STREAM_FLAG_NO_BLOCK.

- -

The flag SSL_STREAM_FLAG_ADVANCE may be used to create a QUIC stream SSL object even if a new QUIC stream cannot yet be opened due to flow control. The caller may begin to use the new stream and fill the write buffer of the stream by calling SSL_write(3). However, no actual stream data (or QUIC frames regarding the stream) will be sent until QUIC flow control allows it. Any queued data will be sent as soon as a peer permits it. There is no guarantee the stream will be eventually created; for example, the connection could fail, or a peer might simply decide never to increase the number of allowed streams for the remainder of the connection lifetime.

- -

RETURN VALUES

- -

SSL_new_stream() returns a new stream object, or NULL on error.

- -

This function fails if called on a QUIC stream SSL object or on a non-QUIC SSL object.

- -

SEE ALSO

- -

SSL_accept_stream(3), SSL_free(3)

- -

HISTORY

- -

SSL_new_stream() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_pending.html b/openssl-install/share/doc/openssl/html/man3/SSL_pending.html deleted file mode 100644 index 4b970e6e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_pending.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -SSL_pending - - - - - - - - - - -

NAME

- -

SSL_pending, SSL_has_pending - check for readable bytes buffered in an SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_pending(const SSL *ssl);
-int SSL_has_pending(const SSL *s);
- -

DESCRIPTION

- -

Data is received in whole blocks known as records from the peer. A whole record is processed (e.g. decrypted) in one go and is buffered by OpenSSL until it is read by the application via a call to SSL_read_ex(3) or SSL_read(3).

- -

SSL_pending() returns the number of bytes which have been processed, buffered and are available inside ssl for immediate read.

- -

If the SSL object's read_ahead flag is set (see SSL_CTX_set_read_ahead(3)), additional protocol bytes (beyond the current record) may have been read containing more TLS/SSL records. This also applies to DTLS and pipelining (see SSL_CTX_set_split_send_fragment(3)). These additional bytes will be buffered by OpenSSL but will remain unprocessed until they are needed. As these bytes are still in an unprocessed state SSL_pending() will ignore them. Therefore, it is possible for no more bytes to be readable from the underlying BIO (because OpenSSL has already read them) and for SSL_pending() to return 0, even though readable application data bytes are available (because the data is in unprocessed buffered records).

- -

SSL_has_pending() returns 1 if s has buffered data (whether processed or unprocessed) and 0 otherwise. Note that it is possible for SSL_has_pending() to return 1, and then a subsequent call to SSL_read_ex() or SSL_read() to return no data because the unprocessed buffered data when processed yielded no application data (for example this can happen during renegotiation). It is also possible in this scenario for SSL_has_pending() to continue to return 1 even after an SSL_read_ex() or SSL_read() call because the buffered and unprocessed data is not yet processable (e.g. because OpenSSL has only received a partial record so far).

- -

RETURN VALUES

- -

SSL_pending() returns the number of buffered and processed application data bytes that are pending and are available for immediate read. SSL_has_pending() returns 1 if there is buffered record data in the SSL object and 0 otherwise.

- -

SEE ALSO

- -

SSL_read_ex(3), SSL_read(3), SSL_CTX_set_read_ahead(3), SSL_CTX_set_split_send_fragment(3), ssl(7)

- -

HISTORY

- -

The SSL_has_pending() function was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_poll.html b/openssl-install/share/doc/openssl/html/man3/SSL_poll.html deleted file mode 100644 index e163da9b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_poll.html +++ /dev/null @@ -1,298 +0,0 @@ - - - - -SSL_poll - - - - - - - - - - -

NAME

- -

SSL_poll, SSL_POLL_EVENT_NONE, SSL_POLL_EVENT_F, SSL_POLL_EVENT_EC, SSL_POLL_EVENT_ECD, SSL_POLL_EVENT_ER, SSL_POLL_EVENT_EW, SSL_POLL_EVENT_R, SSL_POLL_EVENT_W, SSL_POLL_EVENT_ISB, SSL_POLL_EVENT_ISU, SSL_POLL_EVENT_OSB, SSL_POLL_EVENT_OSU, SSL_POLL_EVENT_RW, SSL_POLL_EVENT_RE, SSL_POLL_EVENT_WE, SSL_POLL_EVENT_RWE, SSL_POLL_EVENT_E, SSL_POLL_EVENT_IS, SSL_POLL_EVENT_ISE, SSL_POLL_EVENT_I, SSL_POLL_EVENT_OS, SSL_POLL_EVENT_OSE, SSL_POLL_FLAG_NO_HANDLE_EVENTS - determine or await readiness conditions for one or more pollable objects

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_POLL_EVENT_NONE        0
-
-#define SSL_POLL_EVENT_F           /* F   (Failure) */
-#define SSL_POLL_EVENT_EC          /* EC  (Exception on Conn) */
-#define SSL_POLL_EVENT_ECD         /* ECD (Exception on Conn Drained) */
-#define SSL_POLL_EVENT_ER          /* ER  (Exception on Read) */
-#define SSL_POLL_EVENT_EW          /* EW  (Exception on Write) */
-#define SSL_POLL_EVENT_R           /* R   (Readable) */
-#define SSL_POLL_EVENT_W           /* W   (Writable) */
-#define SSL_POLL_EVENT_ISB         /* ISB (Incoming Stream: Bidi) */
-#define SSL_POLL_EVENT_ISU         /* ISU (Incoming Stream: Uni) */
-#define SSL_POLL_EVENT_OSB         /* OSB (Outgoing Stream: Bidi) */
-#define SSL_POLL_EVENT_OSU         /* OSU (Outgoing Stream: Uni) */
-
-#define SSL_POLL_EVENT_RW          /* R   | W         */
-#define SSL_POLL_EVENT_RE          /* R   | ER        */
-#define SSL_POLL_EVENT_WE          /* W   | EW        */
-#define SSL_POLL_EVENT_RWE         /* RE  | WE        */
-#define SSL_POLL_EVENT_E           /* EC  | ER  | EW  */
-#define SSL_POLL_EVENT_IS          /* ISB | ISU       */
-#define SSL_POLL_EVENT_ISE         /* IS  | EC        */
-#define SSL_POLL_EVENT_I           /* IS              */
-#define SSL_POLL_EVENT_OS          /* OSB | OSU       */
-#define SSL_POLL_EVENT_OSE         /* OS  | EC        */
-
-typedef struct ssl_poll_item_st {
-    BIO_POLL_DESCRIPTOR desc;
-    uint64_t            events, revents;
-} SSL_POLL_ITEM;
-
-#define SSL_POLL_FLAG_NO_HANDLE_EVENTS
-
-int SSL_poll(SSL_POLL_ITEM         *items,
-             size_t                num_items,
-             size_t                stride,
-             const struct timeval  *timeout,
-             uint64_t              flags,
-             size_t                *result_count);
- -

DESCRIPTION

- -

SSL_poll() allows the readiness conditions of the resources represented by one or more BIO_POLL_DESCRIPTOR structures to be determined. In particular, it can be used to query for readiness conditions on QUIC connection SSL objects and QUIC stream SSL objects in a single call.

- -

A call to SSL_poll() specifies an array of SSL_POLL_ITEM structures, each of which designates a resource which is being polled for readiness, and a set of event flags which indicate the specific readiness events which the caller is interested in in relation to the specified resource.

- -

The fields of SSL_POLL_ITEM are as follows:

- -
- -
desc
-
- -

The resource being polled for readiness, as represented by a BIO_POLL_DESCRIPTOR. Currently, this must be a poll descriptor of type BIO_POLL_DESCRIPTOR_TYPE_SSL, representing a SSL object pointer, and the SSL object must be a QUIC connection SSL object or QUIC stream SSL object.

- -

If a SSL_POLL_ITEM has a poll descriptor type of BIO_POLL_DESCRIPTOR_TYPE_NONE, or the SSL object pointer is NULL, the SSL_POLL_ITEM array entry is ignored and revents will be set to 0 on return.

- -
-
events
-
- -

This is the set of zero or more events which the caller is interested in learning about in relation to the resource described by desc. It is a collection of zero or more SSL_POLL_EVENT flags. See "EVENT TYPES" for a description of each of the event types.

- -
-
revents
-
- -

After SSL_poll() returns, this is the set of zero or more events which are actually applicable to the resource described by desc. As for events, it is a collection of zero or more SSL_POLL_EVENT flags.

- -

revents need not be a subset of the events specified in events, as some event types are defined as always being enabled (non-maskable). See "EVENT TYPES" for more information.

- -
-
- -

To use SSL_poll(), call it with an array of SSL_POLL_ITEM structures. The array need remain allocated only for the duration of the call. num_items must be set to the number of entries in the array, and stride must be set to sizeof(SSL_POLL_ITEM).

- -

The present implementation of SSL_poll() is a subset of the functionality which will eventually be available. Only a nonblocking mode of operation is available at this time, where SSL_poll() always returns immediately. As such, timeout must point to a valid struct timeval and that structure must be set to zero. In future, other inputs to the timeout argument will result in a blocking mode of operation, which is not currently supported. For more information, see "LIMITATIONS".

- -

The following flags are currently defined for the flags argument:

- -
- -
SSL_POLL_FLAG_NO_HANDLE_EVENTS
-
- -

This flag indicates that internal state machine processing should not be performed in an attempt to generate new readiness events. Only existing readiness events will be reported.

- -
-
- -

The result_count argument is optional. If it is non-NULL, it is used to output the number of entries in the array which have nonzero revents fields when the call to SSL_poll() returns; see "RETURN VALUES" for details.

- -

EVENT TYPES

- -

The SSL_poll() interface reports zero or more event types on a given resource, represented by a bit mask.

- -

All of the event types are level triggered and represent a readiness or permanent exception condition; as such, after an event has been reported by SSL_poll() for a resource, it will continue to be reported in future SSL_poll() calls until the condition ceases to be in effect. A caller must mask the given event type bit in future SSL_poll() calls if it does not wish to receive repeated notifications and has not caused the underlying readiness condition (for example, consuming all available data using SSL_read_ex(3) after SSL_POLL_EVENT_R is reported) to be deasserted.

- -

Some event types do not make sense on a given kind of resource. In this case, specifying that event type in events is a no-op and will be ignored, and the given event will never be reported in revents.

- -

Failure of the polling mechanism itself is considered distinct from an exception condition on a resource which was successfully polled. See SSL_POLL_EVENT_F and "RETURN VALUES" for details.

- -

In general, an application should always listen for the event types corresponding to exception conditions if it is listening to the corresponding non-exception event types (e.g. SSL_POLL_EVENT_EC and SSL_POLL_EVENT_ER for SSL_POLL_EVENT_R), as not doing so is unlikely to be a sound design.

- -

Some event types are non-maskable and may be reported in revents regardless of whether they were requested in events.

- -

The following event types are supported:

- -
- -
SSL_POLL_EVENT_F
-
- -

Polling failure. This event is raised when a resource could not be polled. It is distinct from an exception condition reported on a resource which was successfully polled and represents a failure of the polling process itself in relation to a resource. This may mean that SSL_poll() does not support the kind of resource specified.

- -

Where this event is raised on at least one item in items, SSL_poll() will return 0 and the ERR stack will contain information pertaining to the first item in items with SSL_POLL_EVENT_F set. See "RETURN VALUES" for more information.

- -

This event type may be raised even if it was not requested in events; specifying this event type in events does nothing.

- -
-
SSL_POLL_EVENT_EC
-
- -

Error at connection level. This event is raised when a connection has failed. In particular, it is raised when a connection begins terminating.

- -

This event is never raised on objects which are not connections.

- -
-
SSL_POLL_EVENT_DCD
-
- -

Error at connection level (drained). This event is raised when a connection has finished terminating, and has reached the terminated state. This event will generally occur after an interval of time passes after the SSL_POLL_EVENT_EC event is raised on a connection.

- -

This event is never raised on objects which are not connections.

- -
-
SSL_POLL_EVENT_ER
-
- -

Error in read direction. For QUIC, this is raised only in the event that a stream has a read part and that read part has been reset by the peer (for example, using a RESET_STREAM frame).

- -
-
SSL_POLL_EVENT_EW
-
- -

Error in write direction. For QUIC, this is raised only in the event that a stream has a write part and that write part has been reset by the peer using a STOP_SENDING frame.

- -
-
SSL_POLL_EVENT_R
-
- -

Readable. This event is raised when a QUIC stream SSL object (or a QUIC connection SSL object with a default stream attached) has application data waiting to be read using SSL_read_ex(3), or a FIN event as represented by SSL_ERROR_ZERO_RETURN waiting to be read.

- -

It is not raised in the event of the receiving part of the QUIC stream being reset by the peer; see SSL_POLL_EVENT_ER.

- -
-
SSL_POLL_EVENT_W
-
- -

Writable. This event is raised when a QUIC stream SSL object (or a QUIC connection SSL object with a default stream attached) could accept more application data using SSL_write_ex(3).

- -

This event is never raised by a receive-only stream.

- -

This event is never raised by a stream which has had its send part concluded normally (as with SSL_stream_conclude(3)) or locally reset (as with SSL_stream_reset(3)).

- -

This event does not guarantee that a subsequent call to SSL_write_ex(3) will succeed.

- -
-
SSL_POLL_EVENT_ISB
-
- -

This event, which is only raised by a QUIC connection SSL object, is raised when one or more incoming bidirectional streams are available to be accepted using SSL_accept_stream(3).

- -
-
SSL_POLL_EVENT_ISU
-
- -

This event, which is only raised by a QUIC connection SSL object, is raised when one or more incoming unidirectional streams are available to be accepted using SSL_accept_stream(3).

- -
-
SSL_POLL_EVENT_OSB
-
- -

This event, which is only raised by a QUIC connection SSL object, is raised when QUIC stream creation flow control currently permits at least one additional bidirectional stream to be locally created.

- -
-
SSL_POLL_EVENT_OSU
-
- -

This event, which is only raised by a QUIC connection SSL object, is raised when QUIC stream creation flow control currently permits at least one additional unidirectional stream to be locally created.

- -
-
- -

LIMITATIONS

- -

SSL_poll() as presently implemented has the following limitations:

- - - -

These limitations will be revised in a future release of OpenSSL.

- -

RETURN VALUES

- -

SSL_poll() returns 1 on success and 0 on failure.

- -

Unless the items pointer itself is invalid, SSL_poll() will always initialise the revents fields of all items in the input array upon returning, even if it returns failure.

- -

If result_count is non-NULL, it is always written with the number of items in the array with nonzero revents fields, even if the SSL_poll() call returns failure.

- -

It is possible for result_count to be written as 0 even if the SSL_poll() call returns success, namely if no events were output but the polling process was successful (e.g. in nonblocking usage) or timed out.

- -

It is possible for result_count to be written as a nonzero value if the SSL_poll() call returns failure, for example due to SSL_POLL_EVENT_F events, or because some events were detected and output before encountering a failure condition while processing a subsequent entry in the items array.

- -

If at least one SSL_POLL_EVENT_F event is output, SSL_poll() is guaranteed to return 0 and guaranteed to place at least one ERR on the error stack describing the first SSL_POLL_EVENT_F output. Detailed information on any additional SSL_POLL_EVENT_F events is not available. SSL_poll() may or may not return more than one SSL_POLL_EVENT_F event at once.

- -

"Normal" events representing exceptional I/O conditions which do not constitute a failure of the SSL_poll() mechanism itself are not considered errors by SSL_poll() and are instead represented using their own event type; see "EVENT TYPES" for details.

- -

The caller can establish the meaning of the SSL_poll() return and output values as follows:

- - - -

SEE ALSO

- -

BIO_get_rpoll_descriptor(3), BIO_get_wpoll_descriptor(3), SSL_get_rpoll_descriptor(3), SSL_get_wpoll_descriptor(3)

- -

HISTORY

- -

SSL_poll() was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_read.html b/openssl-install/share/doc/openssl/html/man3/SSL_read.html deleted file mode 100644 index 7f208eca..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_read.html +++ /dev/null @@ -1,108 +0,0 @@ - - - - -SSL_read - - - - - - - - - - -

NAME

- -

SSL_read_ex, SSL_read, SSL_peek_ex, SSL_peek - read bytes from a TLS/SSL connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_read_ex(SSL *ssl, void *buf, size_t num, size_t *readbytes);
-int SSL_read(SSL *ssl, void *buf, int num);
-
-int SSL_peek_ex(SSL *ssl, void *buf, size_t num, size_t *readbytes);
-int SSL_peek(SSL *ssl, void *buf, int num);
- -

DESCRIPTION

- -

SSL_read_ex() and SSL_read() try to read num bytes from the specified ssl into the buffer buf. On success SSL_read_ex() will store the number of bytes actually read in *readbytes.

- -

SSL_peek_ex() and SSL_peek() are identical to SSL_read_ex() and SSL_read() respectively except no bytes are actually removed from the underlying BIO during the read, so that a subsequent call to SSL_read_ex() or SSL_read() will yield at least the same bytes.

- -

NOTES

- -

In the paragraphs below a "read function" is defined as one of SSL_read_ex(), SSL_read(), SSL_peek_ex() or SSL_peek().

- -

If necessary, a read function will negotiate a TLS/SSL session, if not already explicitly performed by SSL_connect(3) or SSL_accept(3). If the peer requests a re-negotiation, it will be performed transparently during the read function operation. The behaviour of the read functions depends on the underlying BIO.

- -

For the transparent negotiation to succeed, the ssl must have been initialized to client or server mode. This is being done by calling SSL_set_connect_state(3) or SSL_set_accept_state() before the first invocation of a read function.

- -

The read functions work based on the SSL/TLS records. The data are received in records (with a maximum record size of 16kB). Only when a record has been completely received, can it be processed (decryption and check of integrity). Therefore, data that was not retrieved at the last read call can still be buffered inside the SSL layer and will be retrieved on the next read call. If num is higher than the number of bytes buffered then the read functions will return with the bytes buffered. If no more bytes are in the buffer, the read functions will trigger the processing of the next record. Only when the record has been received and processed completely will the read functions return reporting success. At most the contents of one record will be returned. As the size of an SSL/TLS record may exceed the maximum packet size of the underlying transport (e.g. TCP), it may be necessary to read several packets from the transport layer before the record is complete and the read call can succeed.

- -

If SSL_MODE_AUTO_RETRY has been switched off and a non-application data record has been processed, the read function can return and set the error to SSL_ERROR_WANT_READ. In this case there might still be unprocessed data available in the BIO. If read ahead was set using SSL_CTX_set_read_ahead(3), there might also still be unprocessed data available in the SSL. This behaviour can be controlled using the SSL_CTX_set_mode(3) call.

- -

If the underlying BIO is blocking, a read function will only return once the read operation has been finished or an error occurred, except when a non-application data record has been processed and SSL_MODE_AUTO_RETRY is not set. Note that if SSL_MODE_AUTO_RETRY is set and only non-application data is available the call will hang.

- -

If the underlying BIO is nonblocking, a read function will also return when the underlying BIO could not satisfy the needs of the function to continue the operation. In this case a call to SSL_get_error(3) with the return value of the read function will yield SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE. As at any time it's possible that non-application data needs to be sent, a read function can also cause write operations. The calling process then must repeat the call after taking appropriate action to satisfy the needs of the read function. The action depends on the underlying BIO. When using a nonblocking socket, nothing is to be done, but select() can be used to check for the required condition. When using a buffering BIO, like a BIO pair, data must be written into or retrieved out of the BIO before being able to continue.

- -

SSL_pending(3) can be used to find out whether there are buffered bytes available for immediate retrieval. In this case the read function can be called without blocking or actually receiving new data from the underlying socket.

- -

When used with a QUIC SSL object, calling an I/O function such as SSL_read() allows internal network event processing to be performed. It is important that this processing is performed regularly. If an application is not using thread assisted mode, an application should ensure that an I/O function such as SSL_read() is called regularly, or alternatively ensure that SSL_handle_events() is called regularly. See openssl-quic(7) and SSL_handle_events(3) for more information.

- -

RETURN VALUES

- -

SSL_read_ex() and SSL_peek_ex() will return 1 for success or 0 for failure. Success means that 1 or more application data bytes have been read from the SSL connection. Failure means that no bytes could be read from the SSL connection. Failures can be retryable (e.g. we are waiting for more bytes to be delivered by the network) or non-retryable (e.g. a fatal network error). In the event of a failure call SSL_get_error(3) to find out the reason which indicates whether the call is retryable or not.

- -

For SSL_read() and SSL_peek() the following return values can occur:

- -
- -
> 0
-
- -

The read operation was successful. The return value is the number of bytes actually read from the TLS/SSL connection.

- -
-
<= 0
-
- -

The read operation was not successful, because either the connection was closed, an error occurred or action must be taken by the calling process. Call SSL_get_error(3) with the return value ret to find out the reason.

- -

Old documentation indicated a difference between 0 and -1, and that -1 was retryable. You should instead call SSL_get_error() to find out if it's retryable.

- -
-
- -

SEE ALSO

- -

SSL_get_error(3), SSL_write_ex(3), SSL_CTX_set_mode(3), SSL_CTX_new(3), SSL_connect(3), SSL_accept(3) SSL_set_connect_state(3), SSL_pending(3), SSL_shutdown(3), SSL_set_shutdown(3), ssl(7), bio(7)

- -

HISTORY

- -

The SSL_read_ex() and SSL_peek_ex() functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_read_early_data.html b/openssl-install/share/doc/openssl/html/man3/SSL_read_early_data.html deleted file mode 100644 index 98d31b6c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_read_early_data.html +++ /dev/null @@ -1,186 +0,0 @@ - - - - -SSL_read_early_data - - - - - - - - - - -

NAME

- -

SSL_set_max_early_data, SSL_CTX_set_max_early_data, SSL_get_max_early_data, SSL_CTX_get_max_early_data, SSL_set_recv_max_early_data, SSL_CTX_set_recv_max_early_data, SSL_get_recv_max_early_data, SSL_CTX_get_recv_max_early_data, SSL_SESSION_get_max_early_data, SSL_SESSION_set_max_early_data, SSL_write_early_data, SSL_read_early_data, SSL_get_early_data_status, SSL_allow_early_data_cb_fn, SSL_CTX_set_allow_early_data_cb, SSL_set_allow_early_data_cb - functions for sending and receiving early data

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_CTX_set_max_early_data(SSL_CTX *ctx, uint32_t max_early_data);
-uint32_t SSL_CTX_get_max_early_data(const SSL_CTX *ctx);
-int SSL_set_max_early_data(SSL *s, uint32_t max_early_data);
-uint32_t SSL_get_max_early_data(const SSL *s);
-
-int SSL_CTX_set_recv_max_early_data(SSL_CTX *ctx, uint32_t recv_max_early_data);
-uint32_t SSL_CTX_get_recv_max_early_data(const SSL_CTX *ctx);
-int SSL_set_recv_max_early_data(SSL *s, uint32_t recv_max_early_data);
-uint32_t SSL_get_recv_max_early_data(const SSL *s);
-
-uint32_t SSL_SESSION_get_max_early_data(const SSL_SESSION *s);
-int SSL_SESSION_set_max_early_data(SSL_SESSION *s, uint32_t max_early_data);
-
-int SSL_write_early_data(SSL *s, const void *buf, size_t num, size_t *written);
-
-int SSL_read_early_data(SSL *s, void *buf, size_t num, size_t *readbytes);
-
-int SSL_get_early_data_status(const SSL *s);
-
-
-typedef int (*SSL_allow_early_data_cb_fn)(SSL *s, void *arg);
-
-void SSL_CTX_set_allow_early_data_cb(SSL_CTX *ctx,
-                                     SSL_allow_early_data_cb_fn cb,
-                                     void *arg);
-void SSL_set_allow_early_data_cb(SSL *s,
-                                 SSL_allow_early_data_cb_fn cb,
-                                 void *arg);
- -

DESCRIPTION

- -

These functions are used to send and receive early data where TLSv1.3 has been negotiated. Early data can be sent by the client immediately after its initial ClientHello without having to wait for the server to complete the handshake. Early data can be sent if a session has previously been established with the server or when establishing a new session using an out-of-band PSK, and only when the server is known to support it. Additionally these functions can be used to send data from the server to the client when the client has not yet completed the authentication stage of the handshake.

- -

Early data has weaker security properties than other data sent over an SSL/TLS connection. In particular the data does not have forward secrecy. There are also additional considerations around replay attacks (see "REPLAY PROTECTION" below). For these reasons extreme care should be exercised when using early data. For specific details, consult the TLS 1.3 specification.

- -

When a server receives early data it may opt to immediately respond by sending application data back to the client. Data sent by the server at this stage is done before the full handshake has been completed. Specifically the client's authentication messages have not yet been received, i.e. the client is unauthenticated at this point and care should be taken when using this capability.

- -

A server or client can determine whether the full handshake has been completed or not by calling SSL_is_init_finished(3).

- -

On the client side, the function SSL_SESSION_get_max_early_data() can be used to determine if a session established with a server can be used to send early data. If the session cannot be used then this function will return 0. Otherwise it will return the maximum number of early data bytes that can be sent.

- -

The function SSL_SESSION_set_max_early_data() sets the maximum number of early data bytes that can be sent for a session. This would typically be used when creating a PSK session file (see SSL_CTX_set_psk_use_session_callback(3)). If using a ticket based PSK then this is set automatically to the value provided by the server.

- -

A client uses the function SSL_write_early_data() to send early data. This function is similar to the SSL_write_ex(3) function, but with the following differences. See SSL_write_ex(3) for information on how to write bytes to the underlying connection, and how to handle any errors that may arise. This page describes the differences between SSL_write_early_data() and SSL_write_ex(3).

- -

When called by a client, SSL_write_early_data() must be the first IO function called on a new connection, i.e. it must occur before any calls to SSL_write_ex(3), SSL_read_ex(3), SSL_connect(3), SSL_do_handshake(3) or other similar functions. It may be called multiple times to stream data to the server, but the total number of bytes written must not exceed the value returned from SSL_SESSION_get_max_early_data(). Once the initial SSL_write_early_data() call has completed successfully the client may interleave calls to SSL_read_ex(3) and SSL_read(3) with calls to SSL_write_early_data() as required.

- -

If SSL_write_early_data() fails you should call SSL_get_error(3) to determine the correct course of action, as for SSL_write_ex(3).

- -

When the client no longer wishes to send any more early data then it should complete the handshake by calling a function such as SSL_connect(3) or SSL_do_handshake(3). Alternatively you can call a standard write function such as SSL_write_ex(3), which will transparently complete the connection and write the requested data.

- -

A server may choose to ignore early data that has been sent to it. Once the connection has been completed you can determine whether the server accepted or rejected the early data by calling SSL_get_early_data_status(). This will return SSL_EARLY_DATA_ACCEPTED if the data was accepted, SSL_EARLY_DATA_REJECTED if it was rejected or SSL_EARLY_DATA_NOT_SENT if no early data was sent. This function may be called by either the client or the server.

- -

A server uses the SSL_read_early_data() function to receive early data on a connection for which early data has been enabled using SSL_CTX_set_max_early_data() or SSL_set_max_early_data(). As for SSL_write_early_data(), this must be the first IO function called on a connection, i.e. it must occur before any calls to SSL_write_ex(3), SSL_read_ex(3), SSL_accept(3), SSL_do_handshake(3), or other similar functions.

- -

SSL_read_early_data() is similar to SSL_read_ex(3) with the following differences. Refer to SSL_read_ex(3) for full details.

- -

SSL_read_early_data() may return 3 possible values:

- -
- -
SSL_READ_EARLY_DATA_ERROR
-
- -

This indicates an IO or some other error occurred. This should be treated in the same way as a 0 return value from SSL_read_ex(3).

- -
-
SSL_READ_EARLY_DATA_SUCCESS
-
- -

This indicates that early data was successfully read. This should be treated in the same way as a 1 return value from SSL_read_ex(3). You should continue to call SSL_read_early_data() to read more data.

- -
-
SSL_READ_EARLY_DATA_FINISH
-
- -

This indicates that no more early data can be read. It may be returned on the first call to SSL_read_early_data() if the client has not sent any early data, or if the early data was rejected.

- -
-
- -

Once the initial SSL_read_early_data() call has completed successfully (i.e. it has returned SSL_READ_EARLY_DATA_SUCCESS or SSL_READ_EARLY_DATA_FINISH) then the server may choose to write data immediately to the unauthenticated client using SSL_write_early_data(). If SSL_read_early_data() returned SSL_READ_EARLY_DATA_FINISH then in some situations (e.g. if the client only supports TLSv1.2) the handshake may have already been completed and calls to SSL_write_early_data() are not allowed. Call SSL_is_init_finished(3) to determine whether the handshake has completed or not. If the handshake is still in progress then the server may interleave calls to SSL_write_early_data() with calls to SSL_read_early_data() as required.

- -

Servers must not call SSL_read_ex(3), SSL_read(3), SSL_write_ex(3) or SSL_write(3) until SSL_read_early_data() has returned with SSL_READ_EARLY_DATA_FINISH. Once it has done so the connection to the client still needs to be completed. Complete the connection by calling a function such as SSL_accept(3) or SSL_do_handshake(3). Alternatively you can call a standard read function such as SSL_read_ex(3), which will transparently complete the connection and read the requested data. Note that it is an error to attempt to complete the connection before SSL_read_early_data() has returned SSL_READ_EARLY_DATA_FINISH.

- -

Only servers may call SSL_read_early_data().

- -

Calls to SSL_read_early_data() may, in certain circumstances, complete the connection immediately without further need to call a function such as SSL_accept(3). This can happen if the client is using a protocol version less than TLSv1.3. Applications can test for this by calling SSL_is_init_finished(3). Alternatively, applications may choose to call SSL_accept(3) anyway. Such a call will successfully return immediately with no further action taken.

- -

When a session is created between a server and a client the server will specify the maximum amount of any early data that it will accept on any future connection attempt. By default the server does not accept early data; a server may indicate support for early data by calling SSL_CTX_set_max_early_data() or SSL_set_max_early_data() to set it for the whole SSL_CTX or an individual SSL object respectively. The max_early_data parameter specifies the maximum amount of early data in bytes that is permitted to be sent on a single connection. Similarly the SSL_CTX_get_max_early_data() and SSL_get_max_early_data() functions can be used to obtain the current maximum early data settings for the SSL_CTX and SSL objects respectively. Generally a server application will either use both of SSL_read_early_data() and SSL_CTX_set_max_early_data() (or SSL_set_max_early_data()), or neither of them, since there is no practical benefit from using only one of them. If the maximum early data setting for a server is nonzero then replay protection is automatically enabled (see "REPLAY PROTECTION" below).

- -

If the server rejects the early data sent by a client then it will skip over the data that is sent. The maximum amount of received early data that is skipped is controlled by the recv_max_early_data setting. If a client sends more than this then the connection will abort. This value can be set by calling SSL_CTX_set_recv_max_early_data() or SSL_set_recv_max_early_data(). The current value for this setting can be obtained by calling SSL_CTX_get_recv_max_early_data() or SSL_get_recv_max_early_data(). The default value for this setting is 16,384 bytes.

- -

The recv_max_early_data value also has an impact on early data that is accepted. The amount of data that is accepted will always be the lower of the max_early_data for the session and the recv_max_early_data setting for the server. If a client sends more data than this then the connection will abort.

- -

The configured value for max_early_data on a server may change over time as required. However, clients may have tickets containing the previously configured max_early_data value. The recv_max_early_data should always be equal to or higher than any recently configured max_early_data value in order to avoid aborted connections. The recv_max_early_data should never be set to less than the current configured max_early_data value.

- -

Some server applications may wish to have more control over whether early data is accepted or not, for example to mitigate replay risks (see "REPLAY PROTECTION" below) or to decline early_data when the server is heavily loaded. The functions SSL_CTX_set_allow_early_data_cb() and SSL_set_allow_early_data_cb() set a callback which is called at a point in the handshake immediately before a decision is made to accept or reject early data. The callback is provided with a pointer to the user data argument that was provided when the callback was first set. Returning 1 from the callback will allow early data and returning 0 will reject it. Note that the OpenSSL library may reject early data for other reasons in which case this callback will not get called. Notably, the built-in replay protection feature will still be used even if a callback is present unless it has been explicitly disabled using the SSL_OP_NO_ANTI_REPLAY option. See "REPLAY PROTECTION" below.

- -

These functions cannot currently be used with QUIC SSL objects. SSL_set_max_early_data(), SSL_set_recv_max_early_data(), SSL_write_early_data(), SSL_read_early_data(), SSL_get_early_data_status() and SSL_set_allow_early_data_cb() fail if called on a QUIC SSL object.

- -

NOTES

- -

The whole purpose of early data is to enable a client to start sending data to the server before a full round trip of network traffic has occurred. Application developers should ensure they consider optimisation of the underlying TCP socket to obtain a performant solution. For example Nagle's algorithm is commonly used by operating systems in an attempt to avoid lots of small TCP packets. In many scenarios this is beneficial for performance, but it does not work well with the early data solution as implemented in OpenSSL. In Nagle's algorithm the OS will buffer outgoing TCP data if a TCP packet has already been sent which we have not yet received an ACK for from the peer. The buffered data will only be transmitted if enough data to fill an entire TCP packet is accumulated, or if the ACK is received from the peer. The initial ClientHello will be sent in the first TCP packet along with any data from the first call to SSL_write_early_data(). If the amount of data written will exceed the size of a single TCP packet, or if there are more calls to SSL_write_early_data() then that additional data will be sent in subsequent TCP packets which will be buffered by the OS and not sent until an ACK is received for the first packet containing the ClientHello. This means the early data is not actually sent until a complete round trip with the server has occurred which defeats the objective of early data.

- -

In many operating systems the TCP_NODELAY socket option is available to disable Nagle's algorithm. If an application opts to disable Nagle's algorithm consideration should be given to turning it back on again after the handshake is complete if appropriate.

- -

In rare circumstances, it may be possible for a client to have a session that reports a max early data value greater than 0, but where the server does not support this. For example, this can occur if a server has had its configuration changed to accept a lower max early data value such as by calling SSL_CTX_set_recv_max_early_data(). Another example is if a server used to support TLSv1.3 but was later downgraded to TLSv1.2. Sending early data to such a server will cause the connection to abort. Clients that encounter an aborted connection while sending early data may want to retry the connection without sending early data as this does not happen automatically. A client will have to establish a new transport layer connection to the server and attempt the SSL/TLS connection again but without sending early data. Note that it is inadvisable to retry with a lower maximum protocol version.

- -

REPLAY PROTECTION

- -

When early data is in use the TLS protocol provides no security guarantees that the same early data was not replayed across multiple connections. As a mitigation for this issue OpenSSL automatically enables replay protection if the server is configured with a nonzero max early data value. With replay protection enabled sessions are forced to be single use only. If a client attempts to reuse a session ticket more than once, then the second and subsequent attempts will fall back to a full handshake (and any early data that was submitted will be ignored). Note that single use tickets are enforced even if a client does not send any early data.

- -

The replay protection mechanism relies on the internal OpenSSL server session cache (see SSL_CTX_set_session_cache_mode(3)). When replay protection is being used the server will operate as if the SSL_OP_NO_TICKET option had been selected (see SSL_CTX_set_options(3)). Sessions will be added to the cache whenever a session ticket is issued. When a client attempts to resume the session, OpenSSL will check for its presence in the internal cache. If it exists then the resumption is allowed and the session is removed from the cache. If it does not exist then the resumption is not allowed and a full handshake will occur.

- -

Note that some applications may maintain an external cache of sessions (see SSL_CTX_sess_set_new_cb(3) and similar functions). It is the application's responsibility to ensure that any sessions in the external cache are also populated in the internal cache and that once removed from the internal cache they are similarly removed from the external cache. Failing to do this could result in an application becoming vulnerable to replay attacks. Note that OpenSSL will lock the internal cache while a session is removed but that lock is not held when the remove session callback (see SSL_CTX_sess_set_remove_cb(3)) is called. This could result in a small amount of time where the session has been removed from the internal cache but is still available in the external cache. Applications should be designed with this in mind in order to minimise the possibility of replay attacks.

- -

The OpenSSL replay protection does not apply to external Pre Shared Keys (PSKs) (e.g. see SSL_CTX_set_psk_find_session_callback(3)). Therefore, extreme caution should be applied when combining external PSKs with early data.

- -

Some applications may mitigate the replay risks in other ways. For those applications it is possible to turn off the built-in replay protection feature using the SSL_OP_NO_ANTI_REPLAY option. See SSL_CTX_set_options(3) for details. Applications can also set a callback to make decisions about accepting early data or not. See SSL_CTX_set_allow_early_data_cb() above for details.

- -

RETURN VALUES

- -

SSL_write_early_data() returns 1 for success or 0 for failure. In the event of a failure call SSL_get_error(3) to determine the correct course of action.

- -

SSL_read_early_data() returns SSL_READ_EARLY_DATA_ERROR for failure, SSL_READ_EARLY_DATA_SUCCESS for success with more data to read and SSL_READ_EARLY_DATA_FINISH for success with no more to data be read. In the event of a failure call SSL_get_error(3) to determine the correct course of action.

- -

SSL_get_max_early_data(), SSL_CTX_get_max_early_data() and SSL_SESSION_get_max_early_data() return the maximum number of early data bytes that may be sent.

- -

SSL_set_max_early_data(), SSL_CTX_set_max_early_data() and SSL_SESSION_set_max_early_data() return 1 for success or 0 for failure.

- -

SSL_get_early_data_status() returns SSL_EARLY_DATA_ACCEPTED if early data was accepted by the server, SSL_EARLY_DATA_REJECTED if early data was rejected by the server, or SSL_EARLY_DATA_NOT_SENT if no early data was sent.

- -

SEE ALSO

- -

SSL_get_error(3), SSL_write_ex(3), SSL_read_ex(3), SSL_connect(3), SSL_accept(3), SSL_do_handshake(3), SSL_CTX_set_psk_use_session_callback(3), ssl(7)

- -

HISTORY

- -

All of the functions described above were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2017-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_rstate_string.html b/openssl-install/share/doc/openssl/html/man3/SSL_rstate_string.html deleted file mode 100644 index 180c7bc0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_rstate_string.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -SSL_rstate_string - - - - - - - - - - -

NAME

- -

SSL_rstate_string, SSL_rstate_string_long - get textual description of state of an SSL object during read operation

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_rstate_string(SSL *ssl);
-const char *SSL_rstate_string_long(SSL *ssl);
- -

DESCRIPTION

- -

SSL_rstate_string() returns a 2 letter string indicating the current read state of the SSL object ssl.

- -

SSL_rstate_string_long() returns a string indicating the current read state of the SSL object ssl.

- -

NOTES

- -

When performing a read operation, the SSL/TLS engine must parse the record, consisting of header and body. When working in a blocking environment, SSL_rstate_string[_long]() should always return "RD"/"read done".

- -

This function should only seldom be needed in applications.

- -

RETURN VALUES

- -

SSL_rstate_string() and SSL_rstate_string_long() can return the following values:

- -
- -
"RH"/"read header"
-
- -

The header of the record is being evaluated.

- -
-
"RB"/"read body"
-
- -

The body of the record is being evaluated.

- -
-
"unknown"/"unknown"
-
- -

The read state is unknown. This should never happen.

- -
-
- -

When used with QUIC SSL objects, these functions always return "RH"/"read header" in normal conditions.

- -

SEE ALSO

- -

ssl(7)

- -

COPYRIGHT

- -

Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_session_reused.html b/openssl-install/share/doc/openssl/html/man3/SSL_session_reused.html deleted file mode 100644 index ee92b0a8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_session_reused.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -SSL_session_reused - - - - - - - - - - -

NAME

- -

SSL_session_reused - query whether a reused session was negotiated during handshake

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_session_reused(const SSL *ssl);
- -

DESCRIPTION

- -

Query, whether a reused session was negotiated during the handshake.

- -

NOTES

- -

During the negotiation, a client can propose to reuse a session. The server then looks up the session in its cache. If both client and server agree on the session, it will be reused and a flag is being set that can be queried by the application.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0
-
- -

A new session was negotiated.

- -
-
1
-
- -

A session was reused.

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_set_session(3), SSL_CTX_set_session_cache_mode(3)

- -

COPYRIGHT

- -

Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set1_host.html b/openssl-install/share/doc/openssl/html/man3/SSL_set1_host.html deleted file mode 100644 index 71daa5bb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set1_host.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -SSL_set1_host - - - - - - - - - - -

NAME

- -

SSL_set1_host, SSL_add1_host, SSL_set_hostflags, SSL_get0_peername - SSL server verification parameters

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set1_host(SSL *s, const char *host);
-int SSL_add1_host(SSL *s, const char *host);
-void SSL_set_hostflags(SSL *s, unsigned int flags);
-const char *SSL_get0_peername(SSL *s);
- -

DESCRIPTION

- -

These functions configure server hostname checks in the SSL client.

- -

SSL_set1_host() sets in the verification parameters of s the expected DNS hostname or IP address to host, clearing any previously specified IP address and hostnames. If host is NULL or the empty string, IP address and hostname checks are not performed on the peer certificate. When a nonempty host is specified, certificate verification automatically checks the peer hostname via X509_check_host(3) with flags as specified via SSL_set_hostflags(). Clients that enable DANE TLSA authentication via SSL_dane_enable(3) should leave it to that function to set the primary reference identifier of the peer, and should not call SSL_set1_host().

- -

SSL_add1_host() adds host as an additional reference identifier that can match the peer's certificate. Any previous hostnames set via SSL_set1_host() or SSL_add1_host() are retained. Adding an IP address is allowed only if no IP address has been set before. No change is made if host is NULL or empty. When an IP address and/or multiple hostnames are configured, the peer is considered verified when any of these matches. This function is required for DANE TLSA in the presence of service name indirection via CNAME, MX or SRV records as specified in RFCs 7671, 7672, and 7673.

- -

TLS clients are recommended to use SSL_set1_host() or SSL_add1_host() for server hostname or IP address validation, as well as SSL_set_tlsext_host_name(3) for Server Name Indication (SNI), which may be crucial also for correct routing of the connection request.

- -

SSL_set_hostflags() sets the flags that will be passed to X509_check_host(3) when name checks are applicable, by default the flags value is 0. See X509_check_host(3) for the list of available flags and their meaning.

- -

SSL_get0_peername() returns the DNS hostname or subject CommonName from the peer certificate that matched one of the reference identifiers. When wildcard matching is not disabled, the name matched in the peer certificate may be a wildcard name. When one of the reference identifiers configured via SSL_set1_host() or SSL_add1_host() starts with ".", which indicates a parent domain prefix rather than a fixed name, the matched peer name may be a sub-domain of the reference identifier. The returned string is allocated by the library and is no longer valid once the associated ssl handle is cleared or freed, or a renegotiation takes place. Applications must not free the return value.

- -

SSL clients are advised to use these functions in preference to explicitly calling X509_check_host(3). Hostname checks may be out of scope with the RFC 7671 DANE-EE(3) certificate usage, and the internal check will be suppressed as appropriate when DANE is enabled.

- -

RETURN VALUES

- -

SSL_set1_host() and SSL_add1_host() return 1 for success and 0 for failure.

- -

SSL_set_hostflags() returns nothing at all.

- -

SSL_get0_peername() returns NULL if peername verification is not applicable (as with RFC 7671 DANE-EE(3)), or no trusted peername was matched. Otherwise, it returns the matched peername. To determine whether verification succeeded call SSL_get_verify_result(3).

- -

EXAMPLES

- -

Suppose "smtp.example.com" is the MX host of the domain "example.com". The calls below will arrange to match either the MX hostname or the destination domain name in the SMTP server certificate. Wildcards are supported, but must match the entire label. The actual name matched in the certificate (which might be a wildcard) is retrieved, and must be copied by the application if it is to be retained beyond the lifetime of the SSL connection.

- -
SSL_set_hostflags(ssl, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS);
-if (!SSL_set1_host(ssl, "smtp.example.com"))
-    /* error */
-if (!SSL_add1_host(ssl, "example.com"))
-    /* error */
-
-/* XXX: Perform SSL_connect() handshake and handle errors here */
-
-if (SSL_get_verify_result(ssl) == X509_V_OK) {
-    const char *peername = SSL_get0_peername(ssl);
-
-    if (peername != NULL)
-        /* Name checks were in scope and matched the peername */
-}
- -

SEE ALSO

- -

ssl(7), X509_check_host(3), SSL_set_tlsext_host_name(3), SSL_get_verify_result(3), SSL_dane_enable(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set1_initial_peer_addr.html b/openssl-install/share/doc/openssl/html/man3/SSL_set1_initial_peer_addr.html deleted file mode 100644 index b83fab0f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set1_initial_peer_addr.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -SSL_set1_initial_peer_addr - - - - - - - - - - -

NAME

- -

SSL_set1_initial_peer_addr - set the initial peer address for a QUIC connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set1_initial_peer_addr(SSL *s, const BIO_ADDR *addr);
- -

DESCRIPTION

- -

SSL_set1_initial_peer_addr() sets the initial destination peer address to be used for the purposes of establishing a QUIC connection in client mode. This function can be used only on a QUIC connection SSL object, and can be used only before a connection attempt is first made. addr must point to a BIO_ADDR representing a UDP destination address of the server to connect to.

- -

Where a QUIC connection object is provided with a write BIO which supports the BIO_CTRL_DGRAM_GET_PEER control (for example, BIO_s_dgram), the initial destination peer address can be detected automatically; if BIO_CTRL_DGRAM_GET_PEER returns a valid (non-AF_UNSPEC) peer address and no valid peer address has yet been set, this will be set automatically as the initial peer address. This behaviour can be overridden by calling SSL_set1_initial_peer_addr() with a valid peer address explicitly.

- -

The destination address used by QUIC may change over time in response to connection events, such as connection migration (where supported). SSL_set1_initial_peer_addr() configures the destination address used for initial connection establishment, and does not confer any guarantee about the destination address being used for communication at any later time in the connection lifecycle.

- -

This function makes a copy of the address passed by the caller; the BIO_ADDR structure pointed to by addr may be freed by the caller after this function returns.

- -

RETURN VALUES

- -

Returns 1 on success and 0 on failure.

- -

SEE ALSO

- -

BIO_ADDR(3), ssl(7)

- -

HISTORY

- -

The SSL_set1_initial_peer_addr() function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set1_server_cert_type.html b/openssl-install/share/doc/openssl/html/man3/SSL_set1_server_cert_type.html deleted file mode 100644 index 73c34db9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set1_server_cert_type.html +++ /dev/null @@ -1,183 +0,0 @@ - - - - -SSL_set1_server_cert_type - - - - - - - - - - -

NAME

- -

SSL_set1_client_cert_type, SSL_set1_server_cert_type, SSL_CTX_set1_client_cert_type, SSL_CTX_set1_server_cert_type, SSL_get0_client_cert_type, SSL_get0_server_cert_type, SSL_CTX_get0_client_cert_type, SSL_CTX_get0_server_cert_type - certificate type (RFC7250) support

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set1_client_cert_type(SSL *s, const unsigned char *val, size_t len);
-int SSL_set1_server_cert_type(SSL *s, const unsigned char *val, size_t len);
-int SSL_CTX_set1_client_cert_type(SSL_CTX *ctx, const unsigned char *val, size_t len);
-int SSL_CTX_set1_server_cert_type(SSL_CTX *ctx, const unsigned char *val, size_t len);
-int SSL_get0_client_cert_type(const SSL *s, unsigned char **val, size_t *len);
-int SSL_get0_server_cert_type(const SSL *s, unsigned char **val, size_t *len);
-int SSL_CTX_get0_client_cert_type(const SSL_CTX *ctx, unsigned char **val, size_t *len);
-int SSL_CTX_get0_server_cert_type(const SSL_CTX *s, unsigned char **val, size_t *len);
- -

DESCRIPTION

- -

The SSL_set1_client_cert_type() and SSL_CTX_set1_client_cert_type() functions set the values for the client certificate type extension. The SSL_get0_client_cert_type() and SSL_CTX_get0_client_cert_type() functions retrieve the local values to be used in the client certificate type extension.

- -

The SSL_set1_server_cert_type() and SSL_CTX_set1_server_cert_type() functions set the values for the server certificate type extension. The SSL_get0_server_cert_type() and SSL_CTX_get0_server_cert_type() functions retrieve the local values to be used in the server certificate type extension.

- -

NOTES

- -

The certificate type extensions are used to negotiate the certificate type to be used in the handshake. These extensions let each side know what its peer is able to accept.

- -

The client certificate type is sent from the client to the server to indicate what certificate types the client is able to present. Values are configured in preference order. On the server, this setting determines which certificate types the server is willing to accept. The server ultimately chooses what type to request (if any) from the values that are mutually supported. By default (if no explicit settings are specified), only X.509 certificates are supported.

- -

The server certificate type is sent from the client to the server to indicate what certificate types the client accepts. Values are configured in preference order. On the server, this setting determines which certificate types the server is willing to present. The server ultimately chooses what type to use from the values that are mutually supported. By default (if no explicit settings are specified), only X.509 certificates are supported.

- -

Having RPK specified first means that side will attempt to send (or request) RPKs if its peer also supports RPKs, otherwise X.509 certificate will be used if both have specified that (or have not configured these options).

- -

The two supported values in the val array are:

- -
- -
TLSEXT_cert_type_x509
-
- -

Which corresponds to an X.509 certificate normally used in TLS.

- -
-
TLSEXT_cert_type_rpk
-
- -

Which corresponds to a raw public key.

- -
-
- -

If val is set to a non-NULL value, then the extension is sent in the handshake. If b<val> is set to a NULL value (and len is 0), then the extension is disabled. The default value is NULL, meaning the extension is not sent, and X.509 certificates are used in the handshake.

- -

Raw public keys may be used in place of certificates when specified in the certificate type and negotiated. Raw public keys have no subject, issuer, validity dates or digital signature.

- -

Use the SSL_get_negotiated_client_cert_type(3) and SSL_get_negotiated_server_cert_type(3) functions to get the negotiated cert type values (at the conclusion of the handshake, or in callbacks that happen after the TLS ServerHello has been processed).

- -

RETURN VALUES

- -

All functions return 1 on success and 0 on failure.

- -

The memory returned from the get0 functions must not be freed.

- -

EXAMPLES

- -

To use raw public keys on the server, set up the SSL_CTX and SSL as follows:

- -
SSL_CTX *ctx;
-SSL *ssl;
-unsigned char cert_type[] = { TLSEXT_cert_type_rpk, TLSEXT_cert_type_x509 };
-EVP_PKEY *rpk;
-
-/* Assign rpk to an EVP_PKEY from a file or other means */
-
-if ((ctx = SSL_CTX_new(TLS_server_method())) == NULL)
-    /* error */
-if ((ssl = SSL_new(ctx)) == NULL)
-    /* error */
-if (!SSL_set1_server_cert_type(ssl, cert_type, sizeof(cert_type)))
-    /* error */
-
-/* A certificate does not need to be specified when using raw public keys */
-if (!SSL_use_PrivateKey(ssl, rpk))
-    /* error */
-
-/* Perform SSL_accept() operations */
- -

To connect to this server, set the client SSL_CTX and SSL as follows:

- -
/* Connect function */
-
-SSL_CTX *ctx;
-SSL *ssl;
-const char *dane_tlsa_domain = "smtp.example.com";
-unsigned char cert_type[] = { TLSEXT_cert_type_rpk, TLSEXT_cert_type_x509 };
-EVP_PKEY *rpk;
-int verify_result;
-
-/* Assign rpk to an EVP_PKEY from a file or other means */
-
-if ((ctx = SSL_CTX_new(TLS_client_method())) == NULL)
-    /* error */
-if (SSL_CTX_dane_enable(ctx) <= 0)
-    /* error */
-if ((ssl = SSL_new(ctx)) == NULL)
-    /* error */
-/*
- * The `dane_tlsa_domain` arguments sets the default SNI hostname.
- * It may be set to NULL when enabling DANE on the server side.
- */
-if (SSL_dane_enable(ssl, dane_tlsa_domain) <= 0)
-    /* error */
-if (!SSL_set1_server_cert_type(ssl, cert_type, sizeof(cert_type)))
-    /* error */
-if (!SSL_add_expected_rpk(ssl, rpk))
-    /* error */
-
-/* Do SSL_connect() handshake and handle errors here */
-
-/* Optional: verify the peer RPK */
-verify_result = SSL_get_verify_result(ssl);
-if (verify_result == X509_V_OK) {
-    /* The server's raw public key matched the TLSA record */
-} else if (verify_result == X509_V_ERR_DANE_NO_MATCH) {
-    /*
-     * The server's raw public key, or public key in certificate, did not
-     * match the TLSA record
-     */
-} else if (verify_result == X509_V_ERR_RPK_UNTRUSTED) {
-    /*
-     * No TLSA records of the correct type are available to verify the
-     * server's raw public key. This would not happen in this example,
-     * as a TLSA record is configured.
-     */
-} else {
-    /* Some other verify error */
-}
- -

To validate client raw public keys, code from the client example may need to be incorporated into the server side.

- -

SEE ALSO

- -

SSL_get0_peer_rpk(3), SSL_get_negotiated_client_cert_type(3), SSL_get_negotiated_server_cert_type(3), SSL_use_certificate(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_async_callback.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_async_callback.html deleted file mode 100644 index dbf46ed4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_async_callback.html +++ /dev/null @@ -1,107 +0,0 @@ - - - - -SSL_set_async_callback - - - - - - - - - - -

NAME

- -

SSL_CTX_set_async_callback, SSL_CTX_set_async_callback_arg, SSL_set_async_callback, SSL_set_async_callback_arg, SSL_get_async_status, SSL_async_callback_fn - manage asynchronous operations

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*SSL_async_callback_fn)(SSL *s, void *arg);
-int SSL_CTX_set_async_callback(SSL_CTX *ctx, SSL_async_callback_fn callback);
-int SSL_CTX_set_async_callback_arg(SSL_CTX *ctx, void *arg);
-int SSL_set_async_callback(SSL *s, SSL_async_callback_fn callback);
-int SSL_set_async_callback_arg(SSL *s, void *arg);
-int SSL_get_async_status(SSL *s, int *status);
- -

DESCRIPTION

- -

SSL_CTX_set_async_callback() sets an asynchronous callback function. All SSL objects generated based on this SSL_CTX will get this callback. If an engine supports the callback mechanism, it will be automatically called if SSL_MODE_ASYNC has been set and an asynchronous capable engine completes a cryptography operation to notify the application to resume the paused work flow.

- -

SSL_CTX_set_async_callback_arg() sets the callback argument.

- -

SSL_set_async_callback() allows an application to set a callback in an asynchronous SSL object, so that when an engine completes a cryptography operation, the callback will be called to notify the application to resume the paused work flow.

- -

SSL_set_async_callback_arg() sets an argument for the SSL object when the above callback is called.

- -

SSL_get_async_status() returns the engine status. This function facilitates the communication from the engine to the application. During an SSL session, cryptographic operations are dispatched to an engine. The engine status is very useful for an application to know if the operation has been successfully dispatched. If the engine does not support this additional callback method, ASYNC_STATUS_UNSUPPORTED will be returned. See ASYNC_WAIT_CTX_set_status() for a description of all of the status values.

- -

An example of the above functions would be the following:

- -
    - -
  1. Application sets the async callback and callback data on an SSL connection by calling SSL_set_async_callback().

    - -
  2. -
  3. Application sets SSL_MODE_ASYNC and makes an asynchronous SSL call

    - -
  4. -
  5. OpenSSL submits the asynchronous request to the engine. If a retry occurs at this point then the status within the ASYNC_WAIT_CTX would be set and the async callback function would be called (goto Step 7).

    - -
  6. -
  7. The OpenSSL engine pauses the current job and returns, so that the application can continue processing other connections.

    - -
  8. -
  9. At a future point in time (probably via a polling mechanism or via an interrupt) the engine will become aware that the asynchronous request has finished processing.

    - -
  10. -
  11. The engine will call the application's callback passing the callback data as a parameter.

    - -
  12. -
  13. The callback function should then run. Note: it is a requirement that the callback function is small and nonblocking as it will be run in the context of a polling mechanism or an interrupt.

    - -
  14. -
  15. It is the application's responsibility via the callback function to schedule recalling the OpenSSL asynchronous function and to continue processing.

    - -
  16. -
  17. The callback function has the option to check the status returned via SSL_get_async_status() to determine whether a retry happened instead of the request being submitted, allowing different processing if required.

    - -
  18. -
- -

RETURN VALUES

- -

SSL_CTX_set_async_callback(), SSL_set_async_callback(), SSL_CTX_set_async_callback_arg(), SSL_CTX_set_async_callback_arg() and SSL_get_async_status() return 1 on success or 0 on error.

- -

SEE ALSO

- -

ssl(7)

- -

HISTORY

- -

SSL_CTX_set_async_callback(), SSL_CTX_set_async_callback_arg(), SSL_set_async_callback(), SSL_set_async_callback_arg() and SSL_get_async_status() were first added to OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_bio.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_bio.html deleted file mode 100644 index c7c0b160..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_bio.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -SSL_set_bio - - - - - - - - - - -

NAME

- -

SSL_set_bio, SSL_set0_rbio, SSL_set0_wbio - connect the SSL object with a BIO

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_set_bio(SSL *ssl, BIO *rbio, BIO *wbio);
-void SSL_set0_rbio(SSL *s, BIO *rbio);
-void SSL_set0_wbio(SSL *s, BIO *wbio);
- -

DESCRIPTION

- -

SSL_set0_rbio() connects the BIO rbio for the read operations of the ssl object. The SSL engine inherits the behaviour of rbio. If the BIO is nonblocking then the ssl object will also have nonblocking behaviour. This function transfers ownership of rbio to ssl. It will be automatically freed using BIO_free_all(3) when the ssl is freed. On calling this function, any existing rbio that was previously set will also be freed via a call to BIO_free_all(3) (this includes the case where the rbio is set to the same value as previously).

- -

If using a custom BIO, rbio must implement either BIO_meth_set_read_ex(3) or BIO_meth_set_read(3).

- -

SSL_set0_wbio() works in the same as SSL_set0_rbio() except that it connects the BIO wbio for the write operations of the ssl object. Note that if the rbio and wbio are the same then SSL_set0_rbio() and SSL_set0_wbio() each take ownership of one reference. Therefore, it may be necessary to increment the number of references available using BIO_up_ref(3) before calling the set0 functions.

- -

If using a custom BIO, wbio must implement BIO_meth_set_write_ex(3) or BIO_meth_set_write(3). It additionally must implement BIO_flush(3) using BIO_CTRL_FLUSH and BIO_meth_set_ctrl(3). If flushing is unnecessary with wbio, BIO_flush(3) should return one and do nothing.

- -

SSL_set_bio() is similar to SSL_set0_rbio() and SSL_set0_wbio() except that it connects both the rbio and the wbio at the same time, and transfers the ownership of rbio and wbio to ssl according to the following set of rules:

- - - -

Because of this complexity, this function should be avoided; use SSL_set0_rbio() and SSL_set0_wbio() instead.

- -

Where a new BIO is set on a QUIC connection SSL object, blocking mode will be disabled on that SSL object if the BIO cannot support blocking mode. If another BIO is subsequently set on the SSL object which can support blocking mode, blocking mode will not be automatically re-enabled. For more information, see SSL_set_blocking_mode(3).

- -

RETURN VALUES

- -

SSL_set_bio(), SSL_set0_rbio() and SSL_set0_wbio() cannot fail.

- -

SEE ALSO

- -

SSL_get_rbio(3), SSL_connect(3), SSL_accept(3), SSL_shutdown(3), ssl(7), bio(7)

- -

HISTORY

- -

SSL_set0_rbio() and SSL_set0_wbio() were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_blocking_mode.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_blocking_mode.html deleted file mode 100644 index c6de2b7f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_blocking_mode.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -SSL_set_blocking_mode - - - - - - - - - - -

NAME

- -

SSL_set_blocking_mode, SSL_get_blocking_mode - configure blocking mode for a QUIC SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set_blocking_mode(SSL *s, int blocking);
-int SSL_get_blocking_mode(SSL *s);
- -

DESCRIPTION

- -

SSL_set_blocking_mode() can be used to enable or disable blocking mode on a QUIC connection SSL object. By default, blocking is enabled, unless the SSL object is configured to use an underlying read or write BIO which cannot provide a poll descriptor (see BIO_get_rpoll_descriptor(3)), as blocking mode cannot be supported in this case.

- -

To enable blocking mode, call SSL_set_blocking_mode() with blocking set to 1; to disable it, call SSL_set_blocking_mode() with blocking set to 0.

- -

To retrieve the current blocking mode, call SSL_get_blocking_mode().

- -

Blocking mode means that calls such as SSL_read() and SSL_write() will block until the requested operation can be performed. In nonblocking mode, these calls will fail if the requested operation cannot be performed immediately; see SSL_get_error(3).

- -

These functions are only applicable to QUIC connection SSL objects. Other kinds of SSL object, such as those for TLS, automatically function in blocking or nonblocking mode based on whether the underlying network read and write BIOs provided to the SSL object are themselves configured in nonblocking mode.

- -

Where a QUIC connection SSL object is used in nonblocking mode, an application is responsible for ensuring that the SSL object is ticked regularly; see SSL_handle_events(3).

- -

Blocking mode is disabled automatically if the application provides a QUIC connection SSL object with a network BIO which cannot support blocking mode. To re-enable blocking mode in this case, an application must set a network BIO which can support blocking mode and explicitly call SSL_set_blocking_mode().

- -

RETURN VALUES

- -

SSL_set_blocking_mode() returns 1 on success and 0 on failure. The function fails if called on a SSL object which does not represent a QUIC connection, or if blocking mode cannot be used for the given connection.

- -

SSL_get_blocking_mode() returns 1 if blocking is currently enabled. It returns -1 if called on an unsupported SSL object.

- -

SEE ALSO

- -

SSL_handle_events(3), ssl(7)

- -

HISTORY

- -

The SSL_set_blocking_mode() and SSL_get_blocking_mode() functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_connect_state.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_connect_state.html deleted file mode 100644 index adbe9cfa..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_connect_state.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -SSL_set_connect_state - - - - - - - - - - -

NAME

- -

SSL_set_connect_state, SSL_set_accept_state, SSL_is_server - functions for manipulating and examining the client or server mode of an SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_set_connect_state(SSL *ssl);
-
-void SSL_set_accept_state(SSL *ssl);
-
-int SSL_is_server(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_set_connect_state() sets ssl to work in client mode.

- -

SSL_set_accept_state() sets ssl to work in server mode.

- -

SSL_is_server() checks if ssl is working in server mode.

- -

NOTES

- -

When the SSL_CTX object was created with SSL_CTX_new(3), it was either assigned a dedicated client method, a dedicated server method, or a generic method, that can be used for both client and server connections. (The method might have been changed with SSL_CTX_set_ssl_version(3) or SSL_set_ssl_method(3).)

- -

When beginning a new handshake, the SSL engine must know whether it must call the connect (client) or accept (server) routines. Even though it may be clear from the method chosen, whether client or server mode was requested, the handshake routines must be explicitly set.

- -

When using the SSL_connect(3) or SSL_accept(3) routines, the correct handshake routines are automatically set. When performing a transparent negotiation using SSL_write_ex(3), SSL_write(3), SSL_read_ex(3), or SSL_read(3), the handshake routines must be explicitly set in advance using either SSL_set_connect_state() or SSL_set_accept_state().

- -

If SSL_is_server() is called before SSL_set_connect_state() or SSL_set_accept_state() is called (either automatically or explicitly), the result depends on what method was used when SSL_CTX was created with SSL_CTX_new(3). If a generic method or a dedicated server method was passed to SSL_CTX_new(3), SSL_is_server() returns 1; otherwise, it returns 0.

- -

RETURN VALUES

- -

SSL_set_connect_state() and SSL_set_accept_state() do not return diagnostic information.

- -

SSL_is_server() returns 1 if ssl is working in server mode or 0 for client mode.

- -

SEE ALSO

- -

ssl(7), SSL_new(3), SSL_CTX_new(3), SSL_connect(3), SSL_accept(3), SSL_write_ex(3), SSL_write(3), SSL_read_ex(3), SSL_read(3), SSL_do_handshake(3), SSL_CTX_set_ssl_version(3)

- -

COPYRIGHT

- -

Copyright 2001-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_default_stream_mode.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_default_stream_mode.html deleted file mode 100644 index 1b231646..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_default_stream_mode.html +++ /dev/null @@ -1,107 +0,0 @@ - - - - -SSL_set_default_stream_mode - - - - - - - - - - -

NAME

- -

SSL_set_default_stream_mode, SSL_DEFAULT_STREAM_MODE_NONE, SSL_DEFAULT_STREAM_MODE_AUTO_BIDI, SSL_DEFAULT_STREAM_MODE_AUTO_UNI - manage the default stream for a QUIC connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_DEFAULT_STREAM_MODE_NONE
-#define SSL_DEFAULT_STREAM_MODE_AUTO_BIDI
-#define SSL_DEFAULT_STREAM_MODE_AUTO_UNI
-
-int SSL_set_default_stream_mode(SSL *conn, uint32_t mode);
- -

DESCRIPTION

- -

A QUIC connection SSL object may have a default stream attached to it. A default stream is a QUIC stream to which calls to SSL_read(3) and SSL_write(3) made on a QUIC connection SSL object are redirected. Default stream handling allows legacy applications to use QUIC similarly to a traditional TLS connection.

- -

When not disabled, a default stream is automatically created on an outgoing connection once SSL_read(3) or SSL_write(3) is called.

- -

A QUIC stream must be explicitly designated as client-initiated or server-initiated up front. This broadly corresponds to whether an application protocol involves the client transmitting first, or the server transmitting first. As such, if SSL_read(3) is called first (before any call to SSL_write(3)) after establishing a connection, OpenSSL will wait for the server to open the first server-initiated stream, and then bind this as the default stream. Conversely, if SSL_write(3) is called before any call to SSL_read(3), OpenSSL assumes the client wishes to transmit first, creates a client-initiated stream, and binds this as the default stream.

- -

By default, the default stream created is bidirectional. If a unidirectional stream is desired, or if the application wishes to disable default stream functionality, SSL_set_default_stream_mode() (discussed below) can be used to accomplish this.

- -

When a QUIC connection SSL object has no default stream currently associated with it, for example because default stream functionality was disabled, calls to functions which require a stream on the QUIC connection SSL object (for example, SSL_read(3) and SSL_write(3)) will fail.

- -

It is recommended that new applications and applications which rely on multiple streams forego use of the default stream functionality, which is intended for legacy applications.

- -

SSL_set_default_stream_mode() can be used to configure or disable default stream handling. It can only be called on a QUIC connection SSL object prior to any default stream being created. If used, it is recommended to call it immediately after calling SSL_new(3), prior to initiating a connection. The argument mode may be one of the following options:

- -
- -
SSL_DEFAULT_STREAM_MODE_AUTO_BIDI
-
- -

This is the default setting. If SSL_write(3) is called prior to any call to SSL_read(3), a bidirectional client-initiated stream is created and bound as the default stream. If SSL_read(3) is called prior to any call to SSL_write(3), OpenSSL waits for an incoming stream from the peer (causing SSL_read(3) to block if the connection is in blocking mode), and then binds that stream as the default stream. Note that this incoming stream may be either bidirectional or unidirectional; thus, this setting does not guarantee the presence of a bidirectional stream when SSL_read(3) is called first. To determine the type of a stream after a call to SSL_read(3), use SSL_get_stream_type(3).

- -
-
SSL_DEFAULT_STREAM_MODE_AUTO_UNI
-
- -

In this mode, if SSL_write(3) is called prior to any call to SSL_read(3), a unidirectional client-initiated stream is created and bound as the default stream. The behaviour is otherwise identical to that of SSL_DEFAULT_STREAM_MODE_AUTO_BIDI. The behaviour when SSL_read(3) is called prior to any call to SSL_write(3) is unchanged.

- -
-
SSL_DEFAULT_STREAM_MODE_NONE
-
- -

Default stream creation is inhibited. This is the recommended mode of operation. SSL_read(3) and SSL_write(3) calls cannot be made on the QUIC connection SSL object directly. You must obtain streams using SSL_new_stream(3) or SSL_accept_stream(3) in order to communicate with the peer.

- -
-
- -

A default stream will not be automatically created on a QUIC connection SSL object if the default stream mode is set to SSL_DEFAULT_STREAM_MODE_NONE.

- -

SSL_set_incoming_stream_policy(3) interacts significantly with the default stream functionality.

- -

RETURN VALUES

- -

SSL_set_default_stream_mode() returns 1 on success and 0 on failure.

- -

SSL_set_default_stream_mode() fails if it is called after a default stream has already been established.

- -

These functions fail if called on a QUIC stream SSL object or on a non-QUIC SSL object.

- -

SEE ALSO

- -

SSL_new_stream(3), SSL_accept_stream(3), SSL_free(3), SSL_set_incoming_stream_policy(3)

- -

HISTORY

- -

These functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_fd.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_fd.html deleted file mode 100644 index 238b0a0a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_fd.html +++ /dev/null @@ -1,87 +0,0 @@ - - - - -SSL_set_fd - - - - - - - - - - -

NAME

- -

SSL_set_fd, SSL_set_rfd, SSL_set_wfd - connect the SSL object with a file descriptor

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set_fd(SSL *ssl, int fd);
-int SSL_set_rfd(SSL *ssl, int fd);
-int SSL_set_wfd(SSL *ssl, int fd);
- -

DESCRIPTION

- -

SSL_set_fd() sets the file descriptor fd as the input/output facility for the TLS/SSL (encrypted) side of ssl. fd will typically be the socket file descriptor of a network connection.

- -

When performing the operation, a socket BIO is automatically created to interface between the ssl and fd. The BIO and hence the SSL engine inherit the behaviour of fd. If fd is nonblocking, the ssl will also have nonblocking behaviour.

- -

When used on a QUIC connection SSL object, a datagram BIO is automatically created instead of a socket BIO. These functions fail if called on a QUIC stream SSL object.

- -

If there was already a BIO connected to ssl, BIO_free() will be called (for both the reading and writing side, if different).

- -

SSL_set_rfd() and SSL_set_wfd() perform the respective action, but only for the read channel or the write channel, which can be set independently.

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0
-
- -

The operation failed. Check the error stack to find out why.

- -
-
1
-
- -

The operation succeeded.

- -
-
- -

NOTES

- -

On Windows, a socket handle is a 64-bit data type (UINT_PTR), which leads to a compiler warning (conversion from 'SOCKET' to 'int', possible loss of data) when passing the socket handle to SSL_set_*fd(). For the time being, this warning can safely be ignored, because although the Microsoft documentation claims that the upper limit is INVALID_SOCKET-1 (2^64 - 2), in practice the current socket() implementation returns an index into the kernel handle table, the size of which is limited to 2^24.

- -

SEE ALSO

- -

SSL_get_fd(3), SSL_set_bio(3), SSL_connect(3), SSL_accept(3), SSL_shutdown(3), ssl(7) , bio(7)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_incoming_stream_policy.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_incoming_stream_policy.html deleted file mode 100644 index 6f4fdc79..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_incoming_stream_policy.html +++ /dev/null @@ -1,106 +0,0 @@ - - - - -SSL_set_incoming_stream_policy - - - - - - - - - - -

NAME

- -

SSL_set_incoming_stream_policy, SSL_INCOMING_STREAM_POLICY_AUTO, SSL_INCOMING_STREAM_POLICY_ACCEPT, SSL_INCOMING_STREAM_POLICY_REJECT - manage the QUIC incoming stream policy

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_INCOMING_STREAM_POLICY_AUTO
-#define SSL_INCOMING_STREAM_POLICY_ACCEPT
-#define SSL_INCOMING_STREAM_POLICY_REJECT
-
-int SSL_set_incoming_stream_policy(SSL *conn, int policy,
-                                          uint64_t app_error_code);
- -

DESCRIPTION

- -

SSL_set_incoming_stream_policy() policy changes the incoming stream policy for a QUIC connection. Depending on the policy configured, OpenSSL QUIC may automatically reject incoming streams initiated by the peer. This is intended to ensure that legacy applications using single-stream operation with a default stream on a QUIC connection SSL object are not passed remotely-initiated streams by a peer which those applications are not prepared to handle.

- -

app_error_code is an application error code which will be used in any QUIC STOP_SENDING or RESET_STREAM frames generated to implement the policy. The default application error code is 0.

- -

The valid values for policy are:

- -
- -
SSL_INCOMING_STREAM_POLICY_AUTO
-
- -

This is the default setting. Incoming streams are accepted according to the following rules:

- -
    - -
  • If the default stream mode (configured using SSL_set_default_stream_mode(3)) is set to SSL_DEFAULT_STREAM_MODE_AUTO_BIDI (the default) or SSL_DEFAULT_STREAM_MODE_AUTO_UNI, the incoming stream is rejected.

    - -
  • -
  • Otherwise (where the default stream mode is SSL_DEFAULT_STREAM_MODE_NONE), the application is assumed to be stream aware, and the incoming stream is accepted.

    - -
  • -
- -
-
SSL_INCOMING_STREAM_POLICY_ACCEPT
-
- -

Always accept incoming streams, allowing them to be dequeued using SSL_accept_stream(3).

- -
-
SSL_INCOMING_STREAM_POLICY_REJECT
-
- -

Always reject incoming streams.

- -
-
- -

Where an incoming stream is rejected, it is rejected immediately and it is not possible to gain access to the stream using SSL_accept_stream(3). The stream is rejected using QUIC STOP_SENDING and RESET_STREAM frames as appropriate.

- -

RETURN VALUES

- -

Returns 1 on success and 0 on failure.

- -

This function fails if called on a QUIC stream SSL object, or on a non-QUIC SSL object.

- -

SEE ALSO

- -

SSL_set_default_stream_mode(3), SSL_accept_stream(3)

- -

HISTORY

- -

SSL_set_incoming_stream_policy() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_retry_verify.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_retry_verify.html deleted file mode 100644 index f26c69e0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_retry_verify.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -SSL_set_retry_verify - - - - - - - - - - -

NAME

- -

SSL_set_retry_verify - indicate that certificate verification should be retried

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set_retry_verify(SSL *ssl);
- -

DESCRIPTION

- -

SSL_set_retry_verify() should be called from the certificate verification callback on a client when the application wants to indicate that the handshake should be suspended and the control should be returned to the application. SSL_want_retry_verify(3) will return 1 as a consequence until the handshake is resumed again by the application, retrying the verification step.

- -

Please refer to SSL_CTX_set_cert_verify_callback(3) for further details.

- -

NOTES

- -

The effect of calling SSL_set_retry_verify() outside of the certificate verification callback on the client side is undefined.

- -

RETURN VALUES

- -

SSL_set_retry verify() returns 1 on success, 0 otherwise.

- -

EXAMPLES

- -

The following code snippet shows how to obtain the SSL object associated with the X509_STORE_CTX to call the SSL_set_retry_verify() function:

- -
int idx = SSL_get_ex_data_X509_STORE_CTX_idx();
-SSL *ssl;
-
-/* this should not happen but check anyway */
-if (idx < 0
-    || (ssl = X509_STORE_CTX_get_ex_data(ctx, idx)) == NULL)
-    return 0;
-
-if (/* we need to retry verification callback */)
-    return SSL_set_retry_verify(ssl);
-
-/* do normal processing of the verification callback */
- -

SEE ALSO

- -

ssl(7), SSL_connect(3), SSL_CTX_set_cert_verify_callback(3), SSL_want_retry_verify(3)

- -

HISTORY

- -

SSL_set_retry_verify() was added in OpenSSL 3.0.2 to replace backwards incompatible handling of a negative return value from the verification callback.

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_session.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_session.html deleted file mode 100644 index bb44cdc5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_session.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -SSL_set_session - - - - - - - - - - -

NAME

- -

SSL_set_session - set a TLS/SSL session to be used during TLS/SSL connect

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_set_session(SSL *ssl, SSL_SESSION *session);
- -

DESCRIPTION

- -

SSL_set_session() sets session to be used when the TLS/SSL connection is to be established. SSL_set_session() is only useful for TLS/SSL clients. When the session is set, the reference count of session is incremented by 1. If the session is not reused, the reference count is decremented again during SSL_connect(). Whether the session was reused can be queried with the SSL_session_reused(3) call.

- -

If there is already a session set inside ssl (because it was set with SSL_set_session() before or because the same ssl was already used for a connection), SSL_SESSION_free() will be called for that session. This is also the case when session is a NULL pointer. If that old session is still open, it is considered bad and will be removed from the session cache (if used). A session is considered open, if SSL_shutdown(3) was not called for the connection (or at least SSL_set_shutdown(3) was used to set the SSL_SENT_SHUTDOWN state).

- -

NOTES

- -

SSL_SESSION objects keep internal link information about the session cache list, when being inserted into one SSL_CTX object's session cache. One SSL_SESSION object, regardless of its reference count, must therefore only be used with one SSL_CTX object (and the SSL objects created from this SSL_CTX object).

- -

RETURN VALUES

- -

The following return values can occur:

- -
- -
0
-
- -

The operation failed; check the error stack to find out the reason.

- -
-
1
-
- -

The operation succeeded.

- -
-
- -

SEE ALSO

- -

ssl(7), SSL_SESSION_free(3), SSL_get_session(3), SSL_session_reused(3), SSL_CTX_set_session_cache_mode(3)

- -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_session_secret_cb.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_session_secret_cb.html deleted file mode 100644 index 8dafe192..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_session_secret_cb.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -SSL_set_session_secret_cb - - - - - - - - - - -

NAME

- -

SSL_set_session_secret_cb, tls_session_secret_cb_fn - set the session secret callback

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef int (*tls_session_secret_cb_fn)(SSL *s, void *secret, int *secret_len,
-                                        STACK_OF(SSL_CIPHER) *peer_ciphers,
-                                        const SSL_CIPHER **cipher, void *arg);
-
-int SSL_set_session_secret_cb(SSL *s,
-                              tls_session_secret_cb_fn session_secret_cb,
-                              void *arg);
- -

DESCRIPTION

- -

SSL_set_session_secret_cb() sets the session secret callback to be used (session_secret_cb), and an optional argument (arg) to be passed to that callback when it is called. This is only useful for an implementation of EAP-FAST (RFC4851). The presence of the callback also modifies the internal OpenSSL TLS state machine to match the modified TLS behaviour as described in RFC4851. Therefore this callback should not be used except when implementing EAP-FAST.

- -

The callback is expected to set the master secret to be used by filling in the data pointed to by *secret. The size of the secret buffer is initially available in *secret_len and may be updated by the callback (but must not be larger than the initial value).

- -

On the server side the set of ciphersuites offered by the peer is provided in the peer_ciphers stack. Optionally the callback may select the preferred ciphersuite by setting it in *cipher.

- -

On the client side the peer_ciphers stack will always be NULL. The callback may specify the preferred cipher in *cipher and this will be associated with the SSL_SESSION - but it does not affect the ciphersuite selected by the server.

- -

The callback is also supplied with an additional argument in arg which is the argument that was provided to the original SSL_set_session_secret_cb() call.

- -

RETURN VALUES

- -

SSL_set_session_secret_cb() returns 1 on success and 0 on failure.

- -

If the callback returns 1 then this indicates it has successfully set the secret. A return value of 0 indicates that the secret has not been set. On the client this will cause an immediate abort of the handshake.

- -

SEE ALSO

- -

ssl(7), SSL_get_session(3)

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_shutdown.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_shutdown.html deleted file mode 100644 index cb745285..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_shutdown.html +++ /dev/null @@ -1,99 +0,0 @@ - - - - -SSL_set_shutdown - - - - - - - - - - -

NAME

- -

SSL_set_shutdown, SSL_get_shutdown - manipulate shutdown state of an SSL connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_set_shutdown(SSL *ssl, int mode);
-
-int SSL_get_shutdown(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_set_shutdown() sets the shutdown state of ssl to mode.

- -

SSL_get_shutdown() returns the shutdown mode of ssl.

- -

NOTES

- -

The shutdown state of an ssl connection is a bit-mask of:

- -
- -
0
-
- -

No shutdown setting, yet.

- -
-
SSL_SENT_SHUTDOWN
-
- -

A close_notify shutdown alert was sent to the peer, the connection is being considered closed and the session is closed and correct.

- -
-
SSL_RECEIVED_SHUTDOWN
-
- -

A shutdown alert was received form the peer, either a normal close_notify or a fatal error.

- -
-
- -

SSL_SENT_SHUTDOWN and SSL_RECEIVED_SHUTDOWN can be set at the same time.

- -

The shutdown state of the connection is used to determine the state of the ssl session. If the session is still open, when SSL_clear(3) or SSL_free(3) is called, it is considered bad and removed according to RFC2246. The actual condition for a correctly closed session is SSL_SENT_SHUTDOWN (according to the TLS RFC, it is acceptable to only send the close_notify alert but to not wait for the peer's answer, when the underlying connection is closed). SSL_set_shutdown() can be used to set this state without sending a close alert to the peer (see SSL_shutdown(3)).

- -

If a close_notify was received, SSL_RECEIVED_SHUTDOWN will be set, for setting SSL_SENT_SHUTDOWN the application must however still call SSL_shutdown(3) or SSL_set_shutdown() itself.

- -

SSL_set_shutdown() is not supported for QUIC SSL objects.

- -

RETURN VALUES

- -

SSL_set_shutdown() does not return diagnostic information.

- -

SSL_get_shutdown() returns the current shutdown state as set or based on the actual connection state.

- -

SSL_get_shutdown() returns 0 if called on a QUIC stream SSL object. If it is called on a QUIC connection SSL object, it returns a value with SSL_SENT_SHUTDOWN set if CONNECTION_CLOSE has been sent to the peer and it returns a value with SSL_RECEIVED_SHUTDOWN set if CONNECTION_CLOSE has been received from the peer or the QUIC connection is fully terminated for other reasons.

- -

SEE ALSO

- -

ssl(7), SSL_shutdown(3), SSL_CTX_set_quiet_shutdown(3), SSL_clear(3), SSL_free(3)

- -

COPYRIGHT

- -

Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_set_verify_result.html b/openssl-install/share/doc/openssl/html/man3/SSL_set_verify_result.html deleted file mode 100644 index 9ccf7d11..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_set_verify_result.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -SSL_set_verify_result - - - - - - - - - - -

NAME

- -

SSL_set_verify_result - override result of peer certificate verification

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-void SSL_set_verify_result(SSL *ssl, long verify_result);
- -

DESCRIPTION

- -

SSL_set_verify_result() sets verify_result of the object ssl to be the result of the verification of the X509 certificate presented by the peer, if any.

- -

NOTES

- -

SSL_set_verify_result() overrides the verification result. It only changes the verification result of the ssl object. It does not become part of the established session, so if the session is to be reused later, the original value will reappear.

- -

The valid codes for verify_result are documented in openssl-verify(1).

- -

RETURN VALUES

- -

SSL_set_verify_result() does not provide a return value.

- -

SEE ALSO

- -

ssl(7), SSL_get_verify_result(3), SSL_get_peer_certificate(3), openssl-verify(1)

- -

COPYRIGHT

- -

Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_shutdown.html b/openssl-install/share/doc/openssl/html/man3/SSL_shutdown.html deleted file mode 100644 index 7f6aecb4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_shutdown.html +++ /dev/null @@ -1,296 +0,0 @@ - - - - -SSL_shutdown - - - - - - - - - - -

NAME

- -

SSL_shutdown, SSL_shutdown_ex - shut down a TLS/SSL or QUIC connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_shutdown(SSL *ssl);
-
-typedef struct ssl_shutdown_ex_args_st {
-    uint64_t    quic_error_code;
-    const char  *quic_reason;
-} SSL_SHUTDOWN_EX_ARGS;
-
-__owur int SSL_shutdown_ex(SSL *ssl, uint64_t flags,
-                           const SSL_SHUTDOWN_EX_ARGS *args,
-                           size_t args_len);
- -

DESCRIPTION

- -

SSL_shutdown() shuts down an active connection represented by an SSL object.

- -

SSL_shutdown_ex() is an extended version of SSL_shutdown(). If non-NULL, args must point to a SSL_SHUTDOWN_EX_ARGS structure and args_len must be set to sizeof(SSL_SHUTDOWN_EX_ARGS). The SSL_SHUTDOWN_EX_ARGS structure must be zero-initialized. If args is NULL, the behaviour is the same as passing a zero-initialised SSL_SHUTDOWN_EX_ARGS structure. Currently, all extended arguments relate to usage with QUIC, therefore this call functions identically to SSL_shutdown() when not being used with QUIC.

- -

While the general operation of SSL_shutdown() is common between protocols, the exact nature of how a shutdown is performed depends on the underlying protocol being used. See the section below pertaining to each protocol for more information.

- -

In general, calling SSL_shutdown() in nonblocking mode will initiate the shutdown process and return 0 to indicate that the shutdown process has not yet completed. Once the shutdown process has completed, subsequent calls to SSL_shutdown() will return 1. See the RETURN VALUES section for more information.

- -

SSL_shutdown() should not be called if a previous fatal error has occurred on a connection; i.e., if SSL_get_error(3) has returned SSL_ERROR_SYSCALL or SSL_ERROR_SSL.

- -

TLS AND DTLS-SPECIFIC CONSIDERATIONS

- -

Shutdown for SSL/TLS and DTLS is implemented in terms of the SSL/TLS/DTLS close_notify alert message. The shutdown process for SSL/TLS and DTLS consists of two steps:

- - - -

These steps can occur in either order depending on whether the connection shutdown process was first initiated by the local application or by the peer.

- -

Locally-Initiated Shutdown

- -

Calling SSL_shutdown() on a SSL/TLS or DTLS SSL object initiates the shutdown process and causes OpenSSL to try to send a close_notify shutdown alert to the peer. The shutdown process will then be considered completed once the peer responds in turn with a close_notify shutdown alert message.

- -

Calling SSL_shutdown() only closes the write direction of the connection; the read direction is closed by the peer. Once SSL_shutdown() is called, SSL_write(3) can no longer be used, but SSL_read(3) may still be used until the peer decides to close the connection in turn. The peer might continue sending data for some period of time before handling the local application's shutdown indication.

- -

SSL_shutdown() does not affect an underlying network connection such as a TCP connection, which remains open.

- -

Remotely-Initiated Shutdown

- -

If the peer was the first to initiate the shutdown process by sending a close_notify alert message, an application will be notified of this as an EOF condition when calling SSL_read(3) (i.e., SSL_read(3) will fail and SSL_get_error(3) will return SSL_ERROR_ZERO_RETURN), after all application data sent by the peer prior to initiating the shutdown has been read. An application should handle this condition by calling SSL_shutdown() to respond with a close_notify alert in turn, completing the shutdown process, though it may choose to write additional application data using SSL_write(3) before doing so. If an application does not call SSL_shutdown() in this case, a close_notify alert will not be sent and the behaviour will not be fully standards compliant.

- -

Shutdown Lifecycle

- -

Regardless of whether a shutdown was initiated locally or by the peer, if the underlying BIO is blocking, a call to SSL_shutdown() will return firstly once a close_notify alert message is written to the peer (returning 0), and upon a second and subsequent call, once a corresponding message is received from the peer (returning 1 and completing the shutdown process). Calls to SSL_shutdown() with a blocking underlying BIO will also return if an error occurs.

- -

If the underlying BIO is nonblocking and the shutdown process is not yet complete (for example, because a close_notify alert message has not yet been received from the peer, or because a close_notify alert message needs to be sent but would currently block), SSL_shutdown() returns 0 to indicate that the shutdown process is still ongoing; in this case, a call to SSL_get_error(3) will yield SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE.

- -

An application can then detect completion of the shutdown process by calling SSL_shutdown() again repeatedly until it returns 1, indicating that the shutdown process is complete (with a close_notify alert having both been sent and received).

- -

However, the preferred method of waiting for the shutdown to complete is to use SSL_read(3) until SSL_get_error(3) indicates EOF by returning SSL_ERROR_ZERO_RETURN. This ensures any data received immediately before the peer's close_notify alert is still provided to the application. It also ensures any final handshake-layer messages received are processed (for example, messages issuing new session tickets).

- -

If this approach is not used, the second call to SSL_shutdown() (to complete the shutdown by confirming receipt of the peer's close_notify message) will fail if it is called when the application has not read all pending application data sent by the peer using SSL_read(3).

- -

When calling SSL_shutdown(), the SSL_SENT_SHUTDOWN flag is set once an attempt is made to send a close_notify alert, regardless of whether the attempt was successful. The SSL_RECEIVED_SHUTDOWN flag is set once a close_notify alert is received, which may occur during any call which processes incoming data from the network, such as SSL_read(3) or SSL_shutdown(). These flags may be checked using SSL_get_shutdown(3).

- -

Fast Shutdown

- -

Alternatively, it is acceptable for an application to call SSL_shutdown() once (such that it returns 0) and then close the underlying connection without waiting for the peer's response. This allows for a more rapid shutdown process if the application does not wish to wait for the peer.

- -

This alternative "fast shutdown" approach should only be done if it is known that the peer will not send more data, otherwise there is a risk of an application exposing itself to a truncation attack. The full SSL_shutdown() process, in which both parties send close_notify alerts and SSL_shutdown() returns 1, provides a cryptographically authenticated indication of the end of a connection.

- -

This approach of a single SSL_shutdown() call without waiting is preferable to simply calling SSL_free(3) or SSL_clear(3) as calling SSL_shutdown() beforehand makes an SSL session eligible for subsequent reuse and notifies the peer of connection shutdown.

- -

The fast shutdown approach can only be used if there is no intention to reuse the underlying connection (e.g. a TCP connection) for further communication; in this case, the full shutdown process must be performed to ensure synchronisation.

- -

Effects on Session Reuse

- -

Calling SSL_shutdown() sets the SSL_SENT_SHUTDOWN flag (see SSL_set_shutdown(3)), regardless of whether the transmission of the close_notify alert was successful or not. This makes the SSL session eligible for reuse; the SSL session is considered properly closed and can be reused for future connections.

- -

Quiet Shutdown

- -

SSL_shutdown() can be modified to set the connection to the "shutdown" state without actually sending a close_notify alert message; see SSL_CTX_set_quiet_shutdown(3). When "quiet shutdown" is enabled, SSL_shutdown() will always succeed and return 1 immediately.

- -

This is not standards-compliant behaviour. It should only be done when the application protocol in use enables the peer to ensure that all data has been received, such that it doesn't need to wait for a close_notify alert, otherwise application data may be truncated unexpectedly.

- -

Non-Compliant Peers

- -

There are SSL/TLS implementations that never send the required close_notify alert message but simply close the underlying transport (e.g. a TCP connection) instead. This will ordinarily result in an error being generated.

- -

If compatibility with such peers is desired, the option SSL_OP_IGNORE_UNEXPECTED_EOF can be set. For more information, see SSL_CTX_set_options(3).

- -

Note that use of this option means that the EOF condition for application data does not receive cryptographic protection, and therefore renders an application potentially vulnerable to truncation attacks. Thus, this option must only be used in conjunction with an application protocol which indicates unambiguously when all data has been received.

- -

An alternative approach is to simply avoid calling SSL_read(3) if it is known that no more data is going to be sent. This requires an application protocol which indicates unambiguously when all data has been sent.

- -

Session Ticket Handling

- -

If a client application only writes to a SSL/TLS or DTLS connection and never reads, OpenSSL may never process new SSL/TLS session tickets sent by the server. This is because OpenSSL ordinarily processes handshake messages received from a peer during calls to SSL_read(3) by the application.

- -

Therefore, client applications which only write and do not read but which wish to benefit from session resumption are advised to perform a complete shutdown procedure by calling SSL_shutdown() until it returns 1, as described above. This will ensure there is an opportunity for SSL/TLS session ticket messages to be received and processed by OpenSSL.

- -

QUIC-SPECIFIC SHUTDOWN CONSIDERATIONS

- -

When used with a QUIC connection SSL object, SSL_shutdown() initiates a QUIC immediate close using QUIC CONNECTION_CLOSE frames.

- -

SSL_shutdown() cannot be used on QUIC stream SSL objects. To conclude a stream normally, see SSL_stream_conclude(3); to perform a non-normal stream termination, see SSL_stream_reset(3).

- -

SSL_shutdown_ex() may be used instead of SSL_shutdown() by an application to provide additional information to the peer on the reason why a connection is being shut down. The information which can be provided is as follows:

- -
- -
quic_error_code
-
- -

An optional 62-bit application error code to be signalled to the peer. The value must be in the range [0, 2**62-1], else the call to SSL_shutdown_ex() fails. If not provided, an error code of 0 is used by default.

- -
-
quic_reason
-
- -

An optional zero-terminated (UTF-8) reason string to be signalled to the peer. The application is responsible for providing a valid UTF-8 string and OpenSSL will not validate the string. If a reason is not provided, or SSL_shutdown() is used, a zero-length string is used as the reason. If provided, the reason string is copied and stored inside the QUIC connection SSL object and need not remain allocated after the call to SSL_shutdown_ex() returns. Reason strings are bounded by the path MTU and may be silently truncated if they are too long to fit in a QUIC packet.

- -

Reason strings are intended for human diagnostic purposes only, and should not be used for application signalling.

- -
-
- -

The arguments to SSL_shutdown_ex() are used only on the first call to SSL_shutdown_ex() (or SSL_shutdown()) for a given QUIC connection SSL object. These arguments are ignored on subsequent calls.

- -

These functions do not affect an underlying network BIO or the resource it represents; for example, a UDP datagram provided to a QUIC connection as the network BIO will remain open.

- -

Note that when using QUIC, an application must call SSL_shutdown() if it wants to ensure that all transmitted data was received by the peer. This is unlike a TLS/TCP connection, where reliable transmission of buffered data is the responsibility of the operating system. If an application calls SSL_free() on a QUIC connection SSL object or exits before completing the shutdown process using SSL_shutdown(), data which was written by the application using SSL_write(), but could not yet be transmitted, or which was sent but lost in the network, may not be received by the peer.

- -

When using QUIC, calling SSL_shutdown() allows internal network event processing to be performed. It is important that this processing is performed regularly, whether during connection usage or during shutdown. If an application is not using thread assisted mode, an application conducting shutdown should either ensure that SSL_shutdown() is called regularly, or alternatively ensure that SSL_handle_events() is called regularly. See openssl-quic(7) and SSL_handle_events(3) for more information.

- -

Application Data Drainage Behaviour

- -

When using QUIC, SSL_shutdown() or SSL_shutdown_ex() ordinarily waits until all data written to a stream by an application has been acknowledged by the peer. In other words, the shutdown process waits until all data written by the application has been sent to the peer, and until the receipt of all such data is acknowledged by the peer. Only once this process is completed is the shutdown considered complete.

- -

An exception to this is streams which terminated in a non-normal fashion, for example due to a stream reset; only streams which are non-terminated at the time SSL_shutdown() is called, or which terminated in a normal fashion, have their pending send buffers flushed in this manner.

- -

This behaviour of flushing streams during the shutdown process can be skipped by setting the SSL_SHUTDOWN_FLAG_NO_STREAM_FLUSH flag in a call to SSL_shutdown_ex(); in this case, data remaining in stream send buffers may not be transmitted to the peer. This flag may be used when a non-normal application condition has occurred and the delivery of data written to streams via SSL_write(3) is no longer relevant.

- -

Shutdown Mode

- -

Aspects of how QUIC handles connection closure must be taken into account by applications. Ordinarily, QUIC expects a connection to continue to be serviced for a substantial period of time after it is nominally closed. This is necessary to ensure that any connection closure notification sent to the peer was successfully received. However, a consequence of this is that a fully RFC-compliant QUIC connection closure process could take of the order of seconds. This may be unsuitable for some applications, such as short-lived processes which need to exit immediately after completing an application-layer transaction.

- -

As such, there are two shutdown modes available to users of QUIC connection SSL objects:

- -
- -
RFC compliant shutdown mode
-
- -

This is the default behaviour. The shutdown process may take a period of time up to three times the current estimated RTT to the peer. It is possible for the closure process to complete much faster in some circumstances but this cannot be relied upon.

- -

In blocking mode, the function will return once the closure process is complete. In nonblocking mode, SSL_shutdown_ex() should be called until it returns 1, indicating the closure process is complete and the connection is now fully shut down.

- -
-
Rapid shutdown mode
-
- -

In this mode, the peer is notified of connection closure on a best effort basis by sending a single QUIC packet. If that QUIC packet is lost, the peer will not know that the connection has terminated until the negotiated idle timeout (if any) expires.

- -

This will generally return 0 on success, indicating that the connection has not yet been fully shut down (unless it has already done so, in which case it will return 1).

- -
-
- -

If SSL_SHUTDOWN_FLAG_RAPID is specified in flags, a rapid shutdown is performed, otherwise an RFC-compliant shutdown is performed.

- -

If an application calls SSL_shutdown_ex() with SSL_SHUTDOWN_FLAG_RAPID, an application can subsequently change its mind about performing a rapid shutdown by making a subsequent call to SSL_shutdown_ex() without the flag set.

- -

Peer-Initiated Shutdown

- -

In some cases, an application may wish to wait for a shutdown initiated by the peer rather than triggered locally. To do this, call SSL_shutdown_ex() with SSL_SHUTDOWN_FLAG_WAIT_PEER specified in flags. In blocking mode, this waits until the peer initiates a shutdown or the connection otherwise becomes terminated for another reason. In nonblocking mode it exits immediately with either success or failure depending on whether a shutdown has occurred.

- -

If a locally initiated shutdown has already been triggered or the connection has started terminating for another reason, this flag has no effect.

- -

SSL_SHUTDOWN_FLAG_WAIT_PEER implies SSL_SHUTDOWN_FLAG_NO_STREAM_FLUSH, as stream data cannot be flushed after a peer closes the connection. Stream data may still be sent to the peer in any time spent waiting before the peer closes the connection, though there is no guarantee of this.

- -

Nonblocking Mode

- -

SSL_shutdown() and SSL_shutdown_ex() block if the connection is configured in blocking mode. This may be overridden by specifying SSL_SHUTDOWN_FLAG_NO_BLOCK in flags when calling SSL_shutdown_ex(), which causes the call to operate as though in nonblocking mode.

- -

RETURN VALUES

- -

For both SSL_shutdown() and SSL_shutdown_ex() the following return values can occur:

- -
- -
0
-
- -

The shutdown process is ongoing and has not yet completed.

- -

For TLS and DTLS, this means that a close_notify alert has been sent but the peer has not yet replied in turn with its own close_notify.

- -

For QUIC connection SSL objects, a CONNECTION_CLOSE frame may have been sent but the connection closure process has not yet completed.

- -

Unlike most other functions, returning 0 does not indicate an error. SSL_get_error(3) should not be called; it may misleadingly indicate an error even though no error occurred.

- -
-
1
-
- -

The shutdown was successfully completed.

- -

For TLS and DTLS, this means that a close_notify alert was sent and the peer's close_notify alert was received.

- -

For QUIC connection SSL objects, this means that the connection closure process has completed.

- -
-
<0
-
- -

The shutdown was not successful. Call SSL_get_error(3) with the return value ret to find out the reason. It can occur if an action is needed to continue the operation for nonblocking BIOs.

- -

It can also occur when not all data was read using SSL_read(), or if called on a QUIC stream SSL object.

- -

This value is also returned when called on QUIC stream SSL objects.

- -
-
- -

SEE ALSO

- -

SSL_get_error(3), SSL_connect(3), SSL_accept(3), SSL_set_shutdown(3), SSL_CTX_set_quiet_shutdown(3), SSL_CTX_set_options(3) SSL_clear(3), SSL_free(3), ssl(7), bio(7)

- -

HISTORY

- -

The SSL_shutdown_ex() function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_state_string.html b/openssl-install/share/doc/openssl/html/man3/SSL_state_string.html deleted file mode 100644 index f82bb88c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_state_string.html +++ /dev/null @@ -1,68 +0,0 @@ - - - - -SSL_state_string - - - - - - - - - - -

NAME

- -

SSL_state_string, SSL_state_string_long - get textual description of state of an SSL object

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-const char *SSL_state_string(const SSL *ssl);
-const char *SSL_state_string_long(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_state_string() returns an abbreviated string indicating the current state of the SSL object ssl. The returned NUL-terminated string contains 6 or fewer characters.

- -

SSL_state_string_long() returns a descriptive string indicating the current state of the SSL object ssl.

- -

NOTES

- -

During its use, an SSL objects passes several states. The state is internally maintained. Querying the state information is not very informative before or when a connection has been established. It however can be of significant interest during the handshake.

- -

When using nonblocking sockets, the function call performing the handshake may return with SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE condition, so that SSL_state_string[_long]() may be called.

- -

For both blocking or nonblocking sockets, the details state information can be used within the info_callback function set with the SSL_set_info_callback() call.

- -

RETURN VALUES

- -

Detailed description of possible states to be included later.

- -

SEE ALSO

- -

ssl(7), SSL_CTX_set_info_callback(3)

- -

COPYRIGHT

- -

Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_stream_conclude.html b/openssl-install/share/doc/openssl/html/man3/SSL_stream_conclude.html deleted file mode 100644 index b35ffe0a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_stream_conclude.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -SSL_stream_conclude - - - - - - - - - - -

NAME

- -

SSL_stream_conclude - conclude the sending part of a QUIC stream

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-__owur int SSL_stream_conclude(SSL *s, uint64_t flags);
- -

DESCRIPTION

- -

SSL_stream_conclude() signals the normal end-of-stream condition for the send part of a QUIC stream. If called on a QUIC connection SSL object with an associated default stream, it signals the end of the single stream to the peer.

- -

Any data already queued for transmission via a call to SSL_write() will still be written in a reliable manner before the end-of-stream is signalled, assuming the connection remains healthy. This function can be thought of as appending a logical end-of-stream marker after any data which has previously been written to the stream via calls to SSL_write(). Further attempts to call SSL_write() after calling this function will fail.

- -

When calling this on a stream, the receive part of the stream remains unaffected, and the peer may continue to send data until it also signals the end of the stream. Thus, SSL_read() can still be used.

- -

flags is reserved and should be set to 0.

- -

Only the first call to this function has any effect for a given stream; subsequent calls are no-ops. This is considered a success case.

- -

This function is not supported on an object other than a QUIC stream SSL object.

- -

RETURN VALUES

- -

Returns 1 on success and 0 on failure.

- -

Returns 0 if called on an SSL object not representing a QUIC stream.

- -

SEE ALSO

- -

openssl-quic(7), ssl(7), SSL_shutdown_ex(3)

- -

HISTORY

- -

The SSL_stream_conclude() function was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_stream_reset.html b/openssl-install/share/doc/openssl/html/man3/SSL_stream_reset.html deleted file mode 100644 index e128e4e0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_stream_reset.html +++ /dev/null @@ -1,88 +0,0 @@ - - - - -SSL_stream_reset - - - - - - - - - - -

NAME

- -

SSL_stream_reset - reset a QUIC stream

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-typedef struct ssl_stream_reset_args_st {
-    uint64_t quic_error_code;
-} SSL_STREAM_RESET_ARGS;
-
-int SSL_stream_reset(SSL *ssl,
-                     const SSL_STREAM_RESET_ARGS *args,
-                     size_t args_len);
- -

DESCRIPTION

- -

The SSL_stream_reset() function resets the send part of a QUIC stream when called on a QUIC stream SSL object, or on a QUIC connection SSL object with a default stream attached.

- -

If args is non-NULL, args_len must be set to sizeof(*args).

- -

quic_error_code is an application-specified error code, which must be in the range [0, 2**62-1]. If args is NULL, a value of 0 is used.

- -

Resetting a stream indicates to an application that the sending part of the stream is terminating abnormally. When a stream is reset, the implementation does not guarantee that any data already passed to SSL_write(3) will be received by the peer, and data already passed to SSL_write(3) but not yet transmitted may or may not be discarded. As such, you should only reset a stream when the information transmitted on the stream no longer matters, for example due to an error condition.

- -

This function cannot be called on a unidirectional stream initiated by the peer, as only the sending side of a stream can initiate a stream reset.

- -

It is also possible to trigger a stream reset by calling SSL_free(3); see the documentation for SSL_free(3) for details.

- -

The receiving part of the stream (for bidirectional streams) continues to function normally.

- -

NOTES

- -

This function corresponds to the QUIC RESET_STREAM frame.

- -

RETURN VALUES

- -

Returns 1 on success and 0 on failure.

- -

This function fails if called on a QUIC connection SSL object without a default stream attached, or on a non-QUIC SSL object.

- -

After the first call to this function succeeds for a given stream, subsequent calls succeed but are ignored. The application error code used is that passed to the first successful call to this function.

- -

SEE ALSO

- -

SSL_free(3)

- -

HISTORY

- -

SSL_stream_reset() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_want.html b/openssl-install/share/doc/openssl/html/man3/SSL_want.html deleted file mode 100644 index d1c5f2d6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_want.html +++ /dev/null @@ -1,137 +0,0 @@ - - - - -SSL_want - - - - - - - - - - -

NAME

- -

SSL_want, SSL_want_nothing, SSL_want_read, SSL_want_write, SSL_want_x509_lookup, SSL_want_retry_verify, SSL_want_async, SSL_want_async_job, SSL_want_client_hello_cb - obtain state information TLS/SSL I/O operation

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-int SSL_want(const SSL *ssl);
-int SSL_want_nothing(const SSL *ssl);
-int SSL_want_read(const SSL *ssl);
-int SSL_want_write(const SSL *ssl);
-int SSL_want_x509_lookup(const SSL *ssl);
-int SSL_want_retry_verify(const SSL *ssl);
-int SSL_want_async(const SSL *ssl);
-int SSL_want_async_job(const SSL *ssl);
-int SSL_want_client_hello_cb(const SSL *ssl);
- -

DESCRIPTION

- -

SSL_want() returns state information for the SSL object ssl.

- -

The other SSL_want_*() calls are shortcuts for the possible states returned by SSL_want().

- -

NOTES

- -

SSL_want() examines the internal state information of the SSL object. Its return values are similar to that of SSL_get_error(3). Unlike SSL_get_error(3), which also evaluates the error queue, the results are obtained by examining an internal state flag only. The information must therefore only be used for normal operation under nonblocking I/O. Error conditions are not handled and must be treated using SSL_get_error(3).

- -

The result returned by SSL_want() should always be consistent with the result of SSL_get_error(3).

- -

RETURN VALUES

- -

The following return values can currently occur for SSL_want():

- -
- -
SSL_NOTHING
-
- -

There is no data to be written or to be read.

- -
-
SSL_WRITING
-
- -

There are data in the SSL buffer that must be written to the underlying BIO layer in order to complete the actual SSL_*() operation. A call to SSL_get_error(3) should return SSL_ERROR_WANT_WRITE.

- -
-
SSL_READING
-
- -

More data must be read from the underlying BIO layer in order to complete the actual SSL_*() operation. A call to SSL_get_error(3) should return SSL_ERROR_WANT_READ.

- -
-
SSL_X509_LOOKUP
-
- -

The operation did not complete because an application callback set by SSL_CTX_set_client_cert_cb() has asked to be called again. A call to SSL_get_error(3) should return SSL_ERROR_WANT_X509_LOOKUP.

- -
-
SSL_RETRY_VERIFY
-
- -

The operation did not complete because a certificate verification callback has asked to be called again via SSL_set_retry_verify(3). A call to SSL_get_error(3) should return SSL_ERROR_WANT_RETRY_VERIFY.

- -
-
SSL_ASYNC_PAUSED
-
- -

An asynchronous operation partially completed and was then paused. See SSL_get_all_async_fds(3). A call to SSL_get_error(3) should return SSL_ERROR_WANT_ASYNC.

- -
-
SSL_ASYNC_NO_JOBS
-
- -

The asynchronous job could not be started because there were no async jobs available in the pool (see ASYNC_init_thread(3)). A call to SSL_get_error(3) should return SSL_ERROR_WANT_ASYNC_JOB.

- -
-
SSL_CLIENT_HELLO_CB
-
- -

The operation did not complete because an application callback set by SSL_CTX_set_client_hello_cb() has asked to be called again. A call to SSL_get_error(3) should return SSL_ERROR_WANT_CLIENT_HELLO_CB.

- -
-
- -

SSL_want_nothing(), SSL_want_read(), SSL_want_write(), SSL_want_x509_lookup(), SSL_want_retry_verify(), SSL_want_async(), SSL_want_async_job(), and SSL_want_client_hello_cb() return 1 when the corresponding condition is true or 0 otherwise.

- -

QUIC-SPECIFIC CONSIDERATIONS

- -

For QUIC, these functions relate only to the TLS handshake layer.

- -

SEE ALSO

- -

ssl(7), SSL_get_error(3)

- -

HISTORY

- -

The SSL_want_client_hello_cb() function and the SSL_CLIENT_HELLO_CB return value were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/SSL_write.html b/openssl-install/share/doc/openssl/html/man3/SSL_write.html deleted file mode 100644 index 468a26bc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/SSL_write.html +++ /dev/null @@ -1,154 +0,0 @@ - - - - -SSL_write - - - - - - - - - - -

NAME

- -

SSL_write_ex2, SSL_write_ex, SSL_write, SSL_sendfile, SSL_WRITE_FLAG_CONCLUDE - write bytes to a TLS/SSL connection

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-#define SSL_WRITE_FLAG_CONCLUDE
-
-ossl_ssize_t SSL_sendfile(SSL *s, int fd, off_t offset, size_t size, int flags);
-int SSL_write_ex2(SSL *s, const void *buf, size_t num,
-                  uint64_t flags,
-                  size_t *written);
-int SSL_write_ex(SSL *s, const void *buf, size_t num, size_t *written);
-int SSL_write(SSL *ssl, const void *buf, int num);
- -

DESCRIPTION

- -

SSL_write_ex() and SSL_write() write num bytes from the buffer buf into the specified ssl connection. On success SSL_write_ex() will store the number of bytes written in *written.

- -

SSL_write_ex2() functions similarly to SSL_write_ex() but can also accept optional flags which modify its behaviour. Calling SSL_write_ex2() with a flags argument of 0 is exactly equivalent to calling SSL_write_ex().

- -

SSL_sendfile() writes size bytes from offset offset in the file descriptor fd to the specified SSL connection s. This function provides efficient zero-copy semantics. SSL_sendfile() is available only when Kernel TLS is enabled, which can be checked by calling BIO_get_ktls_send(). It is provided here to allow users to maintain the same interface. The meaning of flags is platform dependent. Currently, under Linux it is ignored.

- -

The flags argument to SSL_write_ex2() can accept zero or more of the following flags. Note that which flags are supported will depend on the kind of SSL object and underlying protocol being used:

- -
- -
SSL_WRITE_FLAG_CONCLUDE
-
- -

This flag is only supported on QUIC stream SSL objects (or QUIC connection SSL objects with a default stream attached).

- -

If this flag is set, and the call to SSL_write_ex2() succeeds, and all of the data passed to the call is written (meaning that *written == num), the relevant QUIC stream's send part is concluded automatically as though SSL_stream_conclude(3) was called (causing transmission of a FIN for the stream).

- -

While using this flag is semantically equivalent to calling SSL_stream_conclude(3) after a successful call to this function, using this flag enables greater efficiency than making these two API calls separately, as it enables the written stream data and the FIN flag indicating the end of the stream to be scheduled as part of the same QUIC STREAM frame and QUIC packet.

- -

Setting this flag does not cause a stream's send part to be concluded if not all of the data passed to the call was consumed.

- -
-
- -

A call to SSL_write_ex2() fails if a flag is passed which is not supported or understood by the given SSL object. An application should determine if a flag is supported (for example, for SSL_WRITE_FLAG_CONCLUDE, that a QUIC stream SSL object is being used) before attempting to use it.

- -

NOTES

- -

In the paragraphs below a "write function" is defined as one of either SSL_write_ex(), or SSL_write().

- -

If necessary, a write function will negotiate a TLS/SSL session, if not already explicitly performed by SSL_connect(3) or SSL_accept(3). If the peer requests a re-negotiation, it will be performed transparently during the write function operation. The behaviour of the write functions depends on the underlying BIO.

- -

For the transparent negotiation to succeed, the ssl must have been initialized to client or server mode. This is being done by calling SSL_set_connect_state(3) or SSL_set_accept_state() before the first call to a write function.

- -

If the underlying BIO is blocking, the write functions will only return, once the write operation has been finished or an error occurred.

- -

If the underlying BIO is nonblocking the write functions will also return when the underlying BIO could not satisfy the needs of the function to continue the operation. In this case a call to SSL_get_error(3) with the return value of the write function will yield SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE. As at any time a re-negotiation is possible, a call to a write function can also cause read operations! The calling process then must repeat the call after taking appropriate action to satisfy the needs of the write function. The action depends on the underlying BIO. When using a nonblocking socket, nothing is to be done, but select() can be used to check for the required condition. When using a buffering BIO, like a BIO pair, data must be written into or retrieved out of the BIO before being able to continue.

- -

The write functions will only return with success when the complete contents of buf of length num has been written. This default behaviour can be changed with the SSL_MODE_ENABLE_PARTIAL_WRITE option of SSL_CTX_set_mode(3). When this flag is set the write functions will also return with success when a partial write has been successfully completed. In this case the write function operation is considered completed. The bytes are sent and a new write call with a new buffer (with the already sent bytes removed) must be started. A partial write is performed with the size of a message block, which is 16kB.

- -

When used with a QUIC SSL object, calling an I/O function such as SSL_write() allows internal network event processing to be performed. It is important that this processing is performed regularly. If an application is not using thread assisted mode, an application should ensure that an I/O function such as SSL_write() is called regularly, or alternatively ensure that SSL_handle_events() is called regularly. See openssl-quic(7) and SSL_handle_events(3) for more information.

- -

WARNINGS

- -

When a write function call has to be repeated because SSL_get_error(3) returned SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE, it must be repeated with the same arguments. The data that was passed might have been partially processed. When SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER was set using SSL_CTX_set_mode(3) the pointer can be different, but the data and length should still be the same.

- -

You should not call SSL_write() with num=0, it will return an error. SSL_write_ex() can be called with num=0, but will not send application data to the peer.

- -

RETURN VALUES

- -

SSL_write_ex() and SSL_write_ex2() return 1 for success or 0 for failure. Success means that all requested application data bytes have been written to the SSL connection or, if SSL_MODE_ENABLE_PARTIAL_WRITE is in use, at least 1 application data byte has been written to the SSL connection. Failure means that not all the requested bytes have been written yet (if SSL_MODE_ENABLE_PARTIAL_WRITE is not in use) or no bytes could be written to the SSL connection (if SSL_MODE_ENABLE_PARTIAL_WRITE is in use). Failures can be retryable (e.g. the network write buffer has temporarily filled up) or non-retryable (e.g. a fatal network error). In the event of a failure call SSL_get_error(3) to find out the reason which indicates whether the call is retryable or not.

- -

For SSL_write() the following return values can occur:

- -
- -
> 0
-
- -

The write operation was successful, the return value is the number of bytes actually written to the TLS/SSL connection.

- -
-
<= 0
-
- -

The write operation was not successful, because either the connection was closed, an error occurred or action must be taken by the calling process. Call SSL_get_error() with the return value ret to find out the reason.

- -

Old documentation indicated a difference between 0 and -1, and that -1 was retryable. You should instead call SSL_get_error() to find out if it's retryable.

- -
-
- -

For SSL_sendfile(), the following return values can occur:

- -
- -
>= 0
-
- -

The write operation was successful, the return value is the number of bytes of the file written to the TLS/SSL connection. The return value can be less than size for a partial write.

- -
-
< 0
-
- -

The write operation was not successful, because either the connection was closed, an error occurred or action must be taken by the calling process. Call SSL_get_error() with the return value to find out the reason.

- -
-
- -

SEE ALSO

- -

SSL_get_error(3), SSL_read_ex(3), SSL_read(3) SSL_CTX_set_mode(3), SSL_CTX_new(3), SSL_connect(3), SSL_accept(3) SSL_set_connect_state(3), BIO_ctrl(3), ssl(7), bio(7)

- -

HISTORY

- -

The SSL_write_ex() function was added in OpenSSL 1.1.1. The SSL_sendfile() function was added in OpenSSL 3.0. The SSL_write_ex2() function was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/TS_RESP_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/TS_RESP_CTX_new.html deleted file mode 100644 index 99bdade1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/TS_RESP_CTX_new.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -TS_RESP_CTX_new - - - - - - - - - - -

NAME

- -

TS_RESP_CTX_new_ex, TS_RESP_CTX_new, TS_RESP_CTX_free - Timestamp response context object creation

- -

SYNOPSIS

- -
#include <openssl/ts.h>
-
-TS_RESP_CTX *TS_RESP_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
-TS_RESP_CTX *TS_RESP_CTX_new(void);
-void TS_RESP_CTX_free(TS_RESP_CTX *ctx);
- -

DESCRIPTION

- -

Creates a response context that can be used for generating responses.

- -

TS_RESP_CTX_new_ex() allocates and initializes a TS_RESP_CTX structure with a library context of libctx and a property query of propq. The library context and property query can be used to select which providers supply the fetched algorithms.

- -

TS_RESP_CTX_new() is similar to TS_RESP_CTX_new_ex() but sets the library context and property query to NULL. This results in the default (NULL) library context being used for any operations requiring algorithm fetches.

- -

TS_RESP_CTX_free() frees the TS_RESP_CTX object ctx. If the argument is NULL, nothing is done.

- -

RETURN VALUES

- -

If the allocation fails, TS_RESP_CTX_new_ex() and TS_RESP_CTX_new() return NULL, otherwise it returns a pointer to the newly allocated structure.

- -

HISTORY

- -

The function TS_RESP_CTX_new_ex() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/TS_VERIFY_CTX.html b/openssl-install/share/doc/openssl/html/man3/TS_VERIFY_CTX.html deleted file mode 100644 index dc59089d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/TS_VERIFY_CTX.html +++ /dev/null @@ -1,133 +0,0 @@ - - - - -TS_VERIFY_CTX - - - - - - - - - - -

NAME

- -

TS_VERIFY_CTX, TS_VERIFY_CTX_new, TS_VERIFY_CTX_init, TS_VERIFY_CTX_free, TS_VERIFY_CTX_cleanup, TS_VERIFY_CTX_set_flags, TS_VERIFY_CTX_add_flags, TS_VERIFY_CTX_set0_data, TS_VERIFY_CTX_set0_imprint, TS_VERIFY_CTX_set0_store, TS_VERIFY_CTX_set0_certs, TS_VERIFY_CTX_set_certs, TS_VERIFY_CTS_set_certs, TS_VERIFY_CTX_set_data, TS_VERIFY_CTX_set_imprint, TS_VERIFY_CTX_set_store - manage the TS response verification context

- -

SYNOPSIS

- -
#include <openssl/ts.h>
-
-typedef struct TS_verify_ctx TS_VERIFY_CTX;
-
-TS_VERIFY_CTX *TS_VERIFY_CTX_new(void);
-void TS_VERIFY_CTX_init(TS_VERIFY_CTX *ctx);
-void TS_VERIFY_CTX_free(TS_VERIFY_CTX *ctx);
-void TS_VERIFY_CTX_cleanup(TS_VERIFY_CTX *ctx);
-int TS_VERIFY_CTX_set_flags(TS_VERIFY_CTX *ctx, int f);
-int TS_VERIFY_CTX_add_flags(TS_VERIFY_CTX *ctx, int f);
-int TS_VERIFY_CTX_set0_data(TS_VERIFY_CTX *ctx, BIO *b);
-int TS_VERIFY_CTX_set0_imprint(TS_VERIFY_CTX *ctx,
-                               unsigned char *hexstr, long len);
-int TS_VERIFY_CTX_set0_store(TS_VERIFY_CTX *ctx, X509_STORE *s);
-int TS_VERIFY_CTX_set0_certs(TS_VERIFY_CTX *ctx, STACK_OF(X509) *certs);
- -

The following functions have been deprecated since OpenSSL 3.4:

- -
BIO *TS_VERIFY_CTX_set_data(TS_VERIFY_CTX *ctx, BIO *b);
-unsigned char *TS_VERIFY_CTX_set_imprint(TS_VERIFY_CTX *ctx,
-                                         unsigned char *hexstr, long len);
-X509_STORE *TS_VERIFY_CTX_set_store(TS_VERIFY_CTX *ctx, X509_STORE *s);
-STACK_OF(X509) *TS_VERIFY_CTX_set_certs(TS_VERIFY_CTX *ctx,
-                                        STACK_OF(X509) *certs);
- -

The following function has been deprecated since OpenSSL 3.0:

- -
STACK_OF(X509) *TS_VERIFY_CTS_set_certs(TS_VERIFY_CTX *ctx,
-                                        STACK_OF(X509) *certs);
- -

DESCRIPTION

- -

The Time-Stamp Protocol (TSP) is defined by RFC 3161. TSP is a protocol used to provide long-term proof of the existence of certain data before a particular time. TSP defines a Time Stamping Authority (TSA) and an entity that makes requests to the TSA. Usually, the TSA is referred to as the server side, and the requesting entity is referred to as the client.

- -

In TSP, when a server sends a response to a client, the server normally needs to sign the response data - the TimeStampToken (TST) - with its private key. Then the client verifies the received TST using the server's certificate chain.

- -

For all the following methods, unless noted otherwise, ctx is the verification context created in advance.

- -

TS_VERIFY_CTX_new() returns an allocated TS_VERIFY_CTX structure.

- -

TS_VERIFY_CTX_init() initializes a verification context.

- -

TS_VERIFY_CTX_free() frees up a TS_VERIFY_CTX object. ctx is the verification context to be freed. If ctx is NULL, the call is ignored.

- -

TS_VERIFY_CTX_set_flags() sets the flags in the verification context. f are the flags to be set.

- -

TS_VERIFY_CTX_add_flags() adds flags to the verification context. f are the flags to be added (OR'd).

- -

TS_VERIFY_CTX_set0_data() sets the data to be verified. b is the BIO with the data. A previously assigned BIO is freed.

- -

TS_VERIFY_CTX_set0_imprint() sets the message imprint. hexstr is the message imprint to be assigned. A previously assigned imprint is freed.

- -

TS_VERIFY_CTX_set0_store() sets the store for the verification context. s is the store to be assigned. A previously assigned store is freed.

- -

TS_VERIFY_CTX_set0_certs() is used to set the server's certificate chain when verifying a TST. certs is a stack of X509 certificates.

- -

TS_VERIFY_CTX_cleanup() frees all data associated with the given TS_VERIFY_CTX object and initializes it. ctx is the verification context created in advance. If ctx is NULL, the call is ignored.

- -

All of the following functions described are deprecated. Applications should instead use the functions TS_VERIFY_CTX_set0_data(3), TS_VERIFY_CTX_set0_imprint(3), TS_VERIFY_CTX_set0_store(3), TS_VERIFY_CTX_set0_certs(3).

- -

TS_VERIFY_CTX_set_data() is used to set the BIO with the data to be verified. A previously assigned BIO is not freed by this call. b is the BIO with the data to assign.

- -

TS_VERIFY_CTX_set_imprint() is used to set the message imprint. A previously assigned imprint is freed by this call. hexstr is the string with the message imprint to assign.

- -

TS_VERIFY_CTX_set_store() is used to set the certificate store. A previously assigned store is not freed by this call. s is the store to assign.

- -

TS_VERIFY_CTX_set_certs() is used to set the server's certificate chain. A previously assigned stack is not freed by this call. certs is a stack of X509 certificates.

- -

TS_VERIFY_CTS_set_certs() is a misspelled version of TS_VERIFY_CTX_set_certs() which takes the same parameters and returns the same result.

- -

RETURN VALUES

- -

TS_VERIFY_CTX_new() returns an allocated TS_VERIFY_CTX structure.

- -

TS_VERIFY_CTX_set_flags() returns the flags passed via parameter f.

- -

TS_VERIFY_CTX_add_flags() returns the flags of the context after the ones passed via parameter f are added to it.

- -

TS_VERIFY_CTX_set0_data(), TS_VERIFY_CTX_set0_imprint(), TS_VERIFY_CTX_set0_store(), and TS_VERIFY_CTX_set0_certs() return 1 if the value could be successfully set and 0 in case of any error.

- -

The deprecated functions TS_VERIFY_CTX_set_data(), TS_VERIFY_CTX_set_imprint(), TS_VERIFY_CTX_set_store(), TS_VERIFY_CTX_set_certs() return the parameter the user passes via parameter bio, hexstr, s or certs.

- -

SEE ALSO

- -

OSSL_ESS_check_signing_certs(3)

- -

HISTORY

- -

TS_VERIFY_CTX_set0_data(), TS_VERIFY_CTX_set0_imprint(), TS_VERIFY_CTX_set0_store(), TS_VERIFY_CTX_set0_certs() replace the functions TS_VERIFY_CTX_set_data(), TS_VERIFY_CTX_set_imprint(), TS_VERIFY_CTX_set_store(), TS_VERIFY_CTX_set_certs() that were deprecated in OpenSSL 3.4.0.

- -

The spelling of TS_VERIFY_CTX_set_certs() was corrected in OpenSSL 3.0.0. The misspelled version TS_VERIFY_CTS_set_certs() has been retained for compatibility reasons, but it is deprecated in OpenSSL 3.0.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/UI_STRING.html b/openssl-install/share/doc/openssl/html/man3/UI_STRING.html deleted file mode 100644 index 5b8a89f4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/UI_STRING.html +++ /dev/null @@ -1,113 +0,0 @@ - - - - -UI_STRING - - - - - - - - - - -

NAME

- -

UI_STRING, UI_string_types, UI_get_string_type, UI_get_input_flags, UI_get0_output_string, UI_get0_action_string, UI_get0_result_string, UI_get_result_string_length, UI_get0_test_string, UI_get_result_minsize, UI_get_result_maxsize, UI_set_result, UI_set_result_ex - User interface string parsing

- -

SYNOPSIS

- -
#include <openssl/ui.h>
-
-typedef struct ui_string_st UI_STRING;
-
-enum UI_string_types {
-    UIT_NONE = 0,
-    UIT_PROMPT,                 /* Prompt for a string */
-    UIT_VERIFY,                 /* Prompt for a string and verify */
-    UIT_BOOLEAN,                /* Prompt for a yes/no response */
-    UIT_INFO,                   /* Send info to the user */
-    UIT_ERROR                   /* Send an error message to the user */
-};
-
-enum UI_string_types UI_get_string_type(UI_STRING *uis);
-int UI_get_input_flags(UI_STRING *uis);
-const char *UI_get0_output_string(UI_STRING *uis);
-const char *UI_get0_action_string(UI_STRING *uis);
-const char *UI_get0_result_string(UI_STRING *uis);
-int UI_get_result_string_length(UI_STRING *uis);
-const char *UI_get0_test_string(UI_STRING *uis);
-int UI_get_result_minsize(UI_STRING *uis);
-int UI_get_result_maxsize(UI_STRING *uis);
-int UI_set_result(UI *ui, UI_STRING *uis, const char *result);
-int UI_set_result_ex(UI *ui, UI_STRING *uis, const char *result, int len);
- -

DESCRIPTION

- -

The UI_STRING gets created internally and added to a UI whenever one of the functions UI_add_input_string(), UI_dup_input_string(), UI_add_verify_string(), UI_dup_verify_string(), UI_add_input_boolean(), UI_dup_input_boolean(), UI_add_info_string(), UI_dup_info_string(), UI_add_error_string() or UI_dup_error_string() is called. For a UI_METHOD user, there's no need to know more. For a UI_METHOD creator, it is of interest to fetch text from these UI_STRING objects as well as adding results to some of them.

- -

UI_get_string_type() is used to retrieve the type of the given UI_STRING.

- -

UI_get_input_flags() is used to retrieve the flags associated with the given UI_STRING.

- -

UI_get0_output_string() is used to retrieve the actual string to output (prompt, info, error, ...).

- -

UI_get0_action_string() is used to retrieve the action description associated with a UIT_BOOLEAN type UI_STRING. For all other UI_STRING types, NULL is returned. See UI_add_input_boolean(3).

- -

UI_get0_result_string() and UI_get_result_string_length() are used to retrieve the result of a prompt and its length. This is only useful for UIT_PROMPT and UIT_VERIFY type strings. For all other UI_STRING types, UI_get0_result_string() returns NULL and UI_get_result_string_length() returns -1.

- -

UI_get0_test_string() is used to retrieve the string to compare the prompt result with. This is only useful for UIT_VERIFY type strings. For all other UI_STRING types, NULL is returned.

- -

UI_get_result_minsize() and UI_get_result_maxsize() are used to retrieve the minimum and maximum required size of the result. This is only useful for UIT_PROMPT and UIT_VERIFY type strings. For all other UI_STRING types, -1 is returned.

- -

UI_set_result_ex() is used to set the result value of a prompt and its length. For UIT_PROMPT and UIT_VERIFY type UI strings, this sets the result retrievable with UI_get0_result_string() by copying the contents of result if its length fits the minimum and maximum size requirements. For UIT_BOOLEAN type UI strings, this sets the first character of the result retrievable with UI_get0_result_string() to the first ok_char given with UI_add_input_boolean() or UI_dup_input_boolean() if the result matched any of them, or the first of the cancel_chars if the result matched any of them, otherwise it's set to the NUL char \0. See UI_add_input_boolean(3) for more information on ok_chars and cancel_chars.

- -

UI_set_result() does the same thing as UI_set_result_ex(), but calculates its length internally. It expects the string to be terminated with a NUL byte, and is therefore only useful with normal C strings.

- -

RETURN VALUES

- -

UI_get_string_type() returns the UI string type.

- -

UI_get_input_flags() returns the UI string flags.

- -

UI_get0_output_string() returns the UI string output string.

- -

UI_get0_action_string() returns the UI string action description string for UIT_BOOLEAN type UI strings, NULL for any other type.

- -

UI_get0_result_string() returns the UI string result buffer for UIT_PROMPT and UIT_VERIFY type UI strings, NULL for any other type.

- -

UI_get_result_string_length() returns the UI string result buffer's content length for UIT_PROMPT and UIT_VERIFY type UI strings, -1 for any other type.

- -

UI_get0_test_string() returns the UI string action description string for UIT_VERIFY type UI strings, NULL for any other type.

- -

UI_get_result_minsize() returns the minimum allowed result size for the UI string for UIT_PROMPT and UIT_VERIFY type strings, -1 for any other type.

- -

UI_get_result_maxsize() returns the minimum allowed result size for the UI string for UIT_PROMPT and UIT_VERIFY type strings, -1 for any other type.

- -

UI_set_result() returns 0 on success or when the UI string is of any type other than UIT_PROMPT, UIT_VERIFY or UIT_BOOLEAN, -1 on error.

- -

SEE ALSO

- -

UI(3)

- -

COPYRIGHT

- -

Copyright 2001-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/UI_UTIL_read_pw.html b/openssl-install/share/doc/openssl/html/man3/UI_UTIL_read_pw.html deleted file mode 100644 index d4336ab8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/UI_UTIL_read_pw.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -UI_UTIL_read_pw - - - - - - - - - - -

NAME

- -

UI_UTIL_read_pw_string, UI_UTIL_read_pw, UI_UTIL_wrap_read_pem_callback - user interface utilities

- -

SYNOPSIS

- -
#include <openssl/ui.h>
-
-int UI_UTIL_read_pw_string(char *buf, int length, const char *prompt,
-                           int verify);
-int UI_UTIL_read_pw(char *buf, char *buff, int size, const char *prompt,
-                    int verify);
-UI_METHOD *UI_UTIL_wrap_read_pem_callback(pem_password_cb *cb, int rwflag);
- -

DESCRIPTION

- -

UI_UTIL_read_pw_string() asks for a passphrase, using prompt as a prompt, and stores it in buf. The maximum allowed size is given with length, including the terminating NUL byte. If verify is nonzero, the password will be verified as well.

- -

UI_UTIL_read_pw() does the same as UI_UTIL_read_pw_string(), the difference is that you can give it an external buffer buff for the verification passphrase.

- -

UI_UTIL_wrap_read_pem_callback() can be used to create a temporary UI_METHOD that wraps a given PEM password callback cb. rwflag is used to specify if this method will be used for passphrase entry without (0) or with (1) verification. When not used any more, the returned method should be freed with UI_destroy_method().

- -

NOTES

- -

UI_UTIL_read_pw_string() and UI_UTIL_read_pw() use default UI_METHOD. See UI_get_default_method(3) and friends for more information.

- -

The result from the UI_METHOD created by UI_UTIL_wrap_read_pem_callback() will generate password strings in the encoding that the given password callback generates. The default password prompting functions (apart from UI_UTIL_read_pw_string() and UI_UTIL_read_pw(), there is PEM_def_callback(), EVP_read_pw_string() and EVP_read_pw_string_min()) all use the default UI_METHOD.

- -

RETURN VALUES

- -

UI_UTIL_read_pw_string() and UI_UTIL_read_pw() return 0 on success or a negative value on error.

- -

UI_UTIL_wrap_read_pem_callback() returns a valid UI_METHOD structure or NULL if an error occurred.

- -

SEE ALSO

- -

UI_get_default_method(3)

- -

COPYRIGHT

- -

Copyright 2001-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/UI_create_method.html b/openssl-install/share/doc/openssl/html/man3/UI_create_method.html deleted file mode 100644 index e5b23c74..00000000 --- a/openssl-install/share/doc/openssl/html/man3/UI_create_method.html +++ /dev/null @@ -1,178 +0,0 @@ - - - - -UI_create_method - - - - - - - - - - -

NAME

- -

UI_METHOD, UI_create_method, UI_destroy_method, UI_method_set_opener, UI_method_set_writer, UI_method_set_flusher, UI_method_set_reader, UI_method_set_closer, UI_method_set_data_duplicator, UI_method_set_prompt_constructor, UI_method_set_ex_data, UI_method_get_opener, UI_method_get_writer, UI_method_get_flusher, UI_method_get_reader, UI_method_get_closer, UI_method_get_data_duplicator, UI_method_get_data_destructor, UI_method_get_prompt_constructor, UI_method_get_ex_data - user interface method creation and destruction

- -

SYNOPSIS

- -
#include <openssl/ui.h>
-
-typedef struct ui_method_st UI_METHOD;
-
-UI_METHOD *UI_create_method(const char *name);
-void UI_destroy_method(UI_METHOD *ui_method);
-int UI_method_set_opener(UI_METHOD *method, int (*opener) (UI *ui));
-int UI_method_set_writer(UI_METHOD *method,
-                         int (*writer) (UI *ui, UI_STRING *uis));
-int UI_method_set_flusher(UI_METHOD *method, int (*flusher) (UI *ui));
-int UI_method_set_reader(UI_METHOD *method,
-                         int (*reader) (UI *ui, UI_STRING *uis));
-int UI_method_set_closer(UI_METHOD *method, int (*closer) (UI *ui));
-int UI_method_set_data_duplicator(UI_METHOD *method,
-                                  void *(*duplicator) (UI *ui, void *ui_data),
-                                  void (*destructor)(UI *ui, void *ui_data));
-int UI_method_set_prompt_constructor(UI_METHOD *method,
-                                     char *(*prompt_constructor) (UI *ui,
-                                                                  const char
-                                                                  *object_desc,
-                                                                  const char
-                                                                  *object_name));
-int UI_method_set_ex_data(UI_METHOD *method, int idx, void *data);
-int (*UI_method_get_opener(const UI_METHOD *method)) (UI *);
-int (*UI_method_get_writer(const UI_METHOD *method)) (UI *, UI_STRING *);
-int (*UI_method_get_flusher(const UI_METHOD *method)) (UI *);
-int (*UI_method_get_reader(const UI_METHOD *method)) (UI *, UI_STRING *);
-int (*UI_method_get_closer(const UI_METHOD *method)) (UI *);
-char *(*UI_method_get_prompt_constructor(const UI_METHOD *method))
-    (UI *, const char *, const char *);
-void *(*UI_method_get_data_duplicator(const UI_METHOD *method)) (UI *, void *);
-void (*UI_method_get_data_destructor(const UI_METHOD *method)) (UI *, void *);
-const void *UI_method_get_ex_data(const UI_METHOD *method, int idx);
- -

DESCRIPTION

- -

A method contains a few functions that implement the low-level of the User Interface. These functions are:

- -
- -
an opener
-
- -

This function takes a reference to a UI and starts a session, for example by opening a channel to a tty, or by creating a dialog box.

- -
-
a writer
-
- -

This function takes a reference to a UI and a UI String, and writes the string where appropriate, maybe to the tty, maybe added as a field label in a dialog box. Note that this gets fed all strings associated with a UI, one after the other, so care must be taken which ones it actually uses.

- -
-
a flusher
-
- -

This function takes a reference to a UI, and flushes everything that has been output so far. For example, if the method builds up a dialog box, this can be used to actually display it and accepting input ended with a pressed button.

- -
-
a reader
-
- -

This function takes a reference to a UI and a UI string and reads off the given prompt, maybe from the tty, maybe from a field in a dialog box. Note that this gets fed all strings associated with a UI, one after the other, so care must be taken which ones it actually uses.

- -
-
a closer
-
- -

This function takes a reference to a UI, and closes the session, maybe by closing the channel to the tty, maybe by destroying a dialog box.

- -
-
- -

All of these functions are expected to return 0 on error, 1 on success, or -1 on out-off-band events, for example if some prompting has been cancelled (by pressing Ctrl-C, for example). Only the flusher or the reader are expected to return -1. If returned by another of the functions, it's treated as if 0 was returned.

- -

Regarding the writer and the reader, don't assume the former should only write and don't assume the latter should only read. This depends on the needs of the method.

- -

For example, a typical tty reader wouldn't write the prompts in the write, but would rather do so in the reader, because of the sequential nature of prompting on a tty. This is how the UI_OpenSSL() method does it.

- -

In contrast, a method that builds up a dialog box would add all prompt text in the writer, have all input read in the flusher and store the results in some temporary buffer, and finally have the reader just fetch those results.

- -

The central function that uses these method functions is UI_process(), and it does it in five steps:

- -
    - -
  1. Open the session using the opener function if that one's defined. If an error occurs, jump to 5.

    - -
  2. -
  3. For every UI String associated with the UI, call the writer function if that one's defined. If an error occurs, jump to 5.

    - -
  4. -
  5. Flush everything using the flusher function if that one's defined. If an error occurs, jump to 5.

    - -
  6. -
  7. For every UI String associated with the UI, call the reader function if that one's defined. If an error occurs, jump to 5.

    - -
  8. -
  9. Close the session using the closer function if that one's defined.

    - -
  10. -
- -

UI_create_method() creates a new UI method with a given name.

- -

UI_destroy_method() destroys the given UI method ui_method.

- -

UI_method_set_opener(), UI_method_set_writer(), UI_method_set_flusher(), UI_method_set_reader() and UI_method_set_closer() set the five main method function to the given function pointer.

- -

UI_method_set_data_duplicator() sets the user data duplicator and destructor. See UI_dup_user_data(3).

- -

UI_method_set_prompt_constructor() sets the prompt constructor. See UI_construct_prompt(3).

- -

UI_method_set_ex_data() sets application specific data with a given EX_DATA index. See CRYPTO_get_ex_new_index(3) for general information on how to get that index.

- -

UI_method_get_opener(), UI_method_get_writer(), UI_method_get_flusher(), UI_method_get_reader(), UI_method_get_closer(), UI_method_get_data_duplicator(), UI_method_get_data_destructor() and UI_method_get_prompt_constructor() return the different method functions.

- -

UI_method_get_ex_data() returns the application data previously stored with UI_method_set_ex_data().

- -

RETURN VALUES

- -

UI_create_method() returns a UI_METHOD pointer on success, NULL on error.

- -

UI_method_set_opener(), UI_method_set_writer(), UI_method_set_flusher(), UI_method_set_reader(), UI_method_set_closer(), UI_method_set_data_duplicator() and UI_method_set_prompt_constructor() return 0 on success, -1 if the given method is NULL.

- -

UI_method_set_ex_data() returns 1 on success and 0 on error (because CRYPTO_set_ex_data() does so).

- -

UI_method_get_opener(), UI_method_get_writer(), UI_method_get_flusher(), UI_method_get_reader(), UI_method_get_closer(), UI_method_get_data_duplicator(), UI_method_get_data_destructor() and UI_method_get_prompt_constructor() return the requested function pointer if it's set in the method, otherwise NULL.

- -

UI_method_get_ex_data() returns a pointer to the application specific data associated with the method.

- -

SEE ALSO

- -

UI(3), CRYPTO_get_ex_data(3), UI_STRING(3)

- -

HISTORY

- -

The UI_method_set_data_duplicator(), UI_method_get_data_duplicator() and UI_method_get_data_destructor() functions were added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/UI_new.html b/openssl-install/share/doc/openssl/html/man3/UI_new.html deleted file mode 100644 index acb9409a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/UI_new.html +++ /dev/null @@ -1,178 +0,0 @@ - - - - -UI_new - - - - - - - - - - -

NAME

- -

UI, UI_new, UI_new_method, UI_free, UI_add_input_string, UI_dup_input_string, UI_add_verify_string, UI_dup_verify_string, UI_add_input_boolean, UI_dup_input_boolean, UI_add_info_string, UI_dup_info_string, UI_add_error_string, UI_dup_error_string, UI_construct_prompt, UI_add_user_data, UI_dup_user_data, UI_get0_user_data, UI_get0_result, UI_get_result_length, UI_process, UI_ctrl, UI_set_default_method, UI_get_default_method, UI_get_method, UI_set_method, UI_OpenSSL, UI_null - user interface

- -

SYNOPSIS

- -
#include <openssl/ui.h>
-
-typedef struct ui_st UI;
-
-UI *UI_new(void);
-UI *UI_new_method(const UI_METHOD *method);
-void UI_free(UI *ui);
-
-int UI_add_input_string(UI *ui, const char *prompt, int flags,
-                        char *result_buf, int minsize, int maxsize);
-int UI_dup_input_string(UI *ui, const char *prompt, int flags,
-                        char *result_buf, int minsize, int maxsize);
-int UI_add_verify_string(UI *ui, const char *prompt, int flags,
-                         char *result_buf, int minsize, int maxsize,
-                         const char *test_buf);
-int UI_dup_verify_string(UI *ui, const char *prompt, int flags,
-                         char *result_buf, int minsize, int maxsize,
-                         const char *test_buf);
-int UI_add_input_boolean(UI *ui, const char *prompt, const char *action_desc,
-                         const char *ok_chars, const char *cancel_chars,
-                         int flags, char *result_buf);
-int UI_dup_input_boolean(UI *ui, const char *prompt, const char *action_desc,
-                         const char *ok_chars, const char *cancel_chars,
-                         int flags, char *result_buf);
-int UI_add_info_string(UI *ui, const char *text);
-int UI_dup_info_string(UI *ui, const char *text);
-int UI_add_error_string(UI *ui, const char *text);
-int UI_dup_error_string(UI *ui, const char *text);
-
-char *UI_construct_prompt(UI *ui_method,
-                          const char *phrase_desc, const char *object_name);
-
-void *UI_add_user_data(UI *ui, void *user_data);
-int UI_dup_user_data(UI *ui, void *user_data);
-void *UI_get0_user_data(UI *ui);
-
-const char *UI_get0_result(UI *ui, int i);
-int UI_get_result_length(UI *ui, int i);
-
-int UI_process(UI *ui);
-
-int UI_ctrl(UI *ui, int cmd, long i, void *p, void (*f)());
-
-void UI_set_default_method(const UI_METHOD *meth);
-const UI_METHOD *UI_get_default_method(void);
-const UI_METHOD *UI_get_method(UI *ui);
-const UI_METHOD *UI_set_method(UI *ui, const UI_METHOD *meth);
-
-UI_METHOD *UI_OpenSSL(void);
-const UI_METHOD *UI_null(void);
- -

DESCRIPTION

- -

UI stands for User Interface, and is general purpose set of routines to prompt the user for text-based information. Through user-written methods (see UI_create_method(3)), prompting can be done in any way imaginable, be it plain text prompting, through dialog boxes or from a cell phone.

- -

All the functions work through a context of the type UI. This context contains all the information needed to prompt correctly as well as a reference to a UI_METHOD, which is an ordered vector of functions that carry out the actual prompting.

- -

The first thing to do is to create a UI with UI_new() or UI_new_method(), then add information to it with the UI_add or UI_dup functions. Also, user-defined random data can be passed down to the underlying method through calls to UI_add_user_data() or UI_dup_user_data(). The default UI method doesn't care about these data, but other methods might. Finally, use UI_process() to actually perform the prompting and UI_get0_result() and UI_get_result_length() to find the result to the prompt and its length.

- -

A UI can contain more than one prompt, which are performed in the given sequence. Each prompt gets an index number which is returned by the UI_add and UI_dup functions, and has to be used to get the corresponding result with UI_get0_result() and UI_get_result_length().

- -

UI_process() can be called more than once on the same UI, thereby allowing a UI to have a long lifetime, but can just as well have a short lifetime.

- -

The functions are as follows:

- -

UI_new() creates a new UI using the default UI method. When done with this UI, it should be freed using UI_free().

- -

UI_new_method() creates a new UI using the given UI method. When done with this UI, it should be freed using UI_free().

- -

UI_OpenSSL() returns the built-in UI method (note: not necessarily the default one, since the default can be changed. See further on). This method is the most machine/OS dependent part of OpenSSL and normally generates the most problems when porting.

- -

UI_null() returns a UI method that does nothing. Its use is to avoid getting internal defaults for passed UI_METHOD pointers.

- -

UI_free() removes a UI from memory, along with all other pieces of memory that's connected to it, like duplicated input strings, results and others. If ui is NULL nothing is done.

- -

UI_add_input_string() and UI_add_verify_string() add a prompt to the UI, as well as flags and a result buffer and the desired minimum and maximum sizes of the result, not counting the final NUL character. The given information is used to prompt for information, for example a password, and to verify a password (i.e. having the user enter it twice and check that the same string was entered twice). UI_add_verify_string() takes and extra argument that should be a pointer to the result buffer of the input string that it's supposed to verify, or verification will fail.

- -

UI_add_input_boolean() adds a prompt to the UI that's supposed to be answered in a boolean way, with a single character for yes and a different character for no. A set of characters that can be used to cancel the prompt is given as well. The prompt itself is divided in two, one part being the descriptive text (given through the prompt argument) and one describing the possible answers (given through the action_desc argument).

- -

UI_add_info_string() and UI_add_error_string() add strings that are shown at the same time as the prompt for extra information or to show an error string. The difference between the two is only conceptual. With the built-in method, there's no technical difference between them. Other methods may make a difference between them, however.

- -

The flags currently supported are UI_INPUT_FLAG_ECHO, which is relevant for UI_add_input_string() and will have the users response be echoed (when prompting for a password, this flag should obviously not be used, and UI_INPUT_FLAG_DEFAULT_PWD, which means that a default password of some sort will be used (completely depending on the application and the UI method).

- -

UI_dup_input_string(), UI_dup_verify_string(), UI_dup_input_boolean(), UI_dup_info_string() and UI_dup_error_string() are basically the same as their UI_add counterparts, except that they make their own copies of all strings.

- -

UI_construct_prompt() is a helper function that can be used to create a prompt from two pieces of information: a phrase description phrase_desc and an object name object_name, where the latter may be NULL. The default constructor (if there is none provided by the method used) creates a string "Enter phrase_desc for object_name:" where the " for object_name" part is left out if object_name is NULL. With the description "pass phrase" and the filename "foo.key", that becomes "Enter pass phrase for foo.key:". Other methods may create whatever string and may include encodings that will be processed by the other method functions.

- -

UI_add_user_data() adds a user data pointer for the method to use at any time. The built-in UI method doesn't care about this info. Note that several calls to this function doesn't add data, it replaces the previous blob with the one given as argument.

- -

UI_dup_user_data() duplicates the user data and works as an alternative to UI_add_user_data() when the user data needs to be preserved for a longer duration, perhaps even the lifetime of the application. The UI object takes ownership of this duplicate and will free it whenever it gets replaced or the UI is destroyed. UI_dup_user_data() returns 0 on success, or -1 on memory allocation failure or if the method doesn't have a duplicator function.

- -

UI_get0_user_data() retrieves the data that has last been given to the UI with UI_add_user_data() or UI_dup_user_data.

- -

UI_get0_result() returns a pointer to the result buffer associated with the information indexed by i.

- -

UI_get_result_length() returns the length of the result buffer associated with the information indexed by i.

- -

UI_process() goes through the information given so far, does all the printing and prompting and returns the final status, which is -2 on out-of-band events (Interrupt, Cancel, ...), -1 on error and 0 on success.

- -

UI_ctrl() adds extra control for the application author. For now, it understands two commands: UI_CTRL_PRINT_ERRORS, which makes UI_process() print the OpenSSL error stack as part of processing the UI, and UI_CTRL_IS_REDOABLE, which returns a flag saying if the used UI can be used again or not.

- -

UI_set_default_method() changes the default UI method to the one given. This function is not thread-safe and should not be called at the same time as other OpenSSL functions.

- -

UI_get_default_method() returns a pointer to the current default UI method.

- -

UI_get_method() returns the UI method associated with a given UI.

- -

UI_set_method() changes the UI method associated with a given UI.

- -

NOTES

- -

The resulting strings that the built in method UI_OpenSSL() generate are assumed to be encoded according to the current locale or (for Windows) code page. For applications having different demands, these strings need to be converted appropriately by the caller. For Windows, if the OPENSSL_WIN32_UTF8 environment variable is set, the built-in method UI_OpenSSL() will produce UTF-8 encoded strings instead.

- -

RETURN VALUES

- -

UI_new() and UI_new_method() return a valid UI structure or NULL if an error occurred.

- -

UI_add_input_string(), UI_dup_input_string(), UI_add_verify_string(), UI_dup_verify_string(), UI_add_input_boolean(), UI_dup_input_boolean(), UI_add_info_string(), UI_dup_info_string(), UI_add_error_string() and UI_dup_error_string() return a positive number on success or a value which is less than or equal to 0 otherwise.

- -

UI_construct_prompt() returns a string or NULL if an error occurred.

- -

UI_dup_user_data() returns 0 on success or -1 on error.

- -

UI_get0_result() returns a string or NULL on error.

- -

UI_get_result_length() returns a positive integer or 0 on success; otherwise it returns -1 on error.

- -

UI_process() returns 0 on success or a negative value on error.

- -

UI_ctrl() returns a mask on success or -1 on error.

- -

UI_get_default_method(), UI_get_method(), UI_OpenSSL(), UI_null() and UI_set_method() return either a valid UI_METHOD structure or NULL respectively.

- -

HISTORY

- -

The UI_dup_user_data() function was added in OpenSSL 1.1.1.

- -

COPYRIGHT

- -

Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509V3_get_d2i.html b/openssl-install/share/doc/openssl/html/man3/X509V3_get_d2i.html deleted file mode 100644 index 717c1596..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509V3_get_d2i.html +++ /dev/null @@ -1,223 +0,0 @@ - - - - -X509V3_get_d2i - - - - - - - - - - -

NAME

- -

X509V3_get_d2i, X509V3_add1_i2d, X509V3_EXT_d2i, X509V3_EXT_i2d, X509_get_ext_d2i, X509_add1_ext_i2d, X509_ACERT_get_ext_d2i, X509_ACERT_add1_ext_i2d, X509_CRL_get_ext_d2i, X509_CRL_add1_ext_i2d, X509_REVOKED_get_ext_d2i, X509_REVOKED_add1_ext_i2d, X509_get0_extensions, X509_ACERT_get0_extensions, X509_CRL_get0_extensions, X509_REVOKED_get0_extensions - X509 extension decode and encode functions

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-void *X509V3_get_d2i(const STACK_OF(X509_EXTENSION) *x, int nid, int *crit,
-                     int *idx);
-int X509V3_add1_i2d(STACK_OF(X509_EXTENSION) **x, int nid, void *value,
-                    int crit, unsigned long flags);
-
-void *X509V3_EXT_d2i(X509_EXTENSION *ext);
-X509_EXTENSION *X509V3_EXT_i2d(int ext_nid, int crit, void *ext_struc);
-
-void *X509_get_ext_d2i(const X509 *x, int nid, int *crit, int *idx);
-int X509_add1_ext_i2d(X509 *x, int nid, void *value, int crit,
-                      unsigned long flags);
-
-void *X509_ACERT_get_ext_d2i(const X509_ACERT *x, int nid, int *crit, int *idx);
-int X509_ACERT_add1_ext_i2d(X509_ACERT *x, int nid, void *value, int crit,
-                            unsigned long flags);
-
-void *X509_CRL_get_ext_d2i(const X509_CRL *crl, int nid, int *crit, int *idx);
-int X509_CRL_add1_ext_i2d(X509_CRL *crl, int nid, void *value, int crit,
-                          unsigned long flags);
-
-void *X509_REVOKED_get_ext_d2i(const X509_REVOKED *r, int nid, int *crit, int *idx);
-int X509_REVOKED_add1_ext_i2d(X509_REVOKED *r, int nid, void *value, int crit,
-                              unsigned long flags);
-
-const STACK_OF(X509_EXTENSION) *X509_get0_extensions(const X509 *x);
-const STACK_OF(X509_EXTENSION) *X509_ACERT_get0_extensions(const X509 *x);
-const STACK_OF(X509_EXTENSION) *X509_CRL_get0_extensions(const X509_CRL *crl);
-const STACK_OF(X509_EXTENSION) *X509_REVOKED_get0_extensions(const X509_REVOKED *r);
- -

DESCRIPTION

- -

X509V3_get_d2i() looks for an extension with OID nid in the extensions x and, if found, decodes it. If idx is NULL then only one occurrence of an extension is permissible, otherwise the first extension after index *idx is returned and *idx updated to the location of the extension. If crit is not NULL then *crit is set to a status value: -2 if the extension occurs multiple times (this is only returned if idx is NULL), -1 if the extension could not be found, 0 if the extension is found and is not critical and 1 if critical. A pointer to an extension specific structure or NULL is returned.

- -

X509V3_add1_i2d() adds extension value to STACK *x (allocating a new STACK if necessary) using OID nid and criticality crit according to flags.

- -

X509V3_EXT_d2i() attempts to decode the ASN.1 data contained in extension ext and returns a pointer to an extension specific structure or NULL if the extension could not be decoded (invalid syntax or not supported).

- -

X509V3_EXT_i2d() encodes the extension specific structure ext_struc with OID ext_nid and criticality crit.

- -

X509_get_ext_d2i() and X509_add1_ext_i2d() operate on the extensions of certificate x. They are otherwise identical to X509V3_get_d2i() and X509V3_add1_i2d().

- -

X509_ACERT_get_ext_d2i() and X509_ACERT_add1_ext_i2d() operate on the extensions of X509_ACERT structure x. They are otherwise identical to X509V3_get_d2i() and X509V3_add1_i2d().

- -

X509_CRL_get_ext_d2i() and X509_CRL_add1_ext_i2d() operate on the extensions of CRL crl. They are otherwise identical to X509V3_get_d2i() and X509V3_add1_i2d().

- -

X509_REVOKED_get_ext_d2i() and X509_REVOKED_add1_ext_i2d() operate on the extensions of X509_REVOKED structure r (i.e for CRL entry extensions). They are otherwise identical to X509V3_get_d2i() and X509V3_add1_i2d().

- -

X509_get0_extensions(), X509_ACERT_get0_extensions(), X509_CRL_get0_extensions() and X509_REVOKED_get0_extensions() return a STACK of all the extensions of a certificate, an attribute certificate, a CRL or a CRL entry respectively.

- -

NOTES

- -

In almost all cases an extension can occur at most once and multiple occurrences is an error. Therefore, the idx parameter is usually NULL.

- -

The flags parameter may be one of the following values.

- -

X509V3_ADD_DEFAULT appends a new extension only if the extension does not exist. An error is returned if the extension exists.

- -

X509V3_ADD_APPEND appends a new extension, ignoring whether the extension exists.

- -

X509V3_ADD_REPLACE replaces an existing extension. If the extension does not exist, appends a new extension.

- -

X509V3_ADD_REPLACE_EXISTING replaces an existing extension. If the extension does not exist, returns an error.

- -

X509V3_ADD_KEEP_EXISTING appends a new extension only if the extension does not exist. An error is not returned if the extension exists.

- -

X509V3_ADD_DELETE deletes and frees an existing extension. If the extension does not exist, returns an error. No new extension is added.

- -

If X509V3_ADD_SILENT is bitwise ORed with flags: any error returned will not be added to the error queue.

- -

The function X509V3_get_d2i() and its variants will return NULL if the extension is not found, occurs multiple times or cannot be decoded. It is possible to determine the precise reason by checking the value of *crit. The returned pointer must be explicitly freed.

- -

The function X509V3_add1_i2d() and its variants allocate X509_EXTENSION objects on STACK *x depending on flags. The X509_EXTENSION objects must be explicitly freed using X509_EXTENSION_free().

- -

SUPPORTED EXTENSIONS

- -

The following sections contain a list of all supported extensions including their name and NID.

- -

PKIX Certificate Extensions

- -

The following certificate extensions are defined in PKIX standards such as RFC5280.

- -
Basic Constraints                  NID_basic_constraints
-Key Usage                          NID_key_usage
-Extended Key Usage                 NID_ext_key_usage
-
-Subject Key Identifier             NID_subject_key_identifier
-Authority Key Identifier           NID_authority_key_identifier
-
-Private Key Usage Period           NID_private_key_usage_period
-
-Subject Alternative Name           NID_subject_alt_name
-Issuer Alternative Name            NID_issuer_alt_name
-
-Authority Information Access       NID_info_access
-Subject Information Access         NID_sinfo_access
-
-Name Constraints                   NID_name_constraints
-
-Certificate Policies               NID_certificate_policies
-Policy Mappings                    NID_policy_mappings
-Policy Constraints                 NID_policy_constraints
-Inhibit Any Policy                 NID_inhibit_any_policy
-
-TLS Feature                        NID_tlsfeature
- -

Netscape Certificate Extensions

- -

The following are (largely obsolete) Netscape certificate extensions.

- -
Netscape Cert Type                 NID_netscape_cert_type
-Netscape Base Url                  NID_netscape_base_url
-Netscape Revocation Url            NID_netscape_revocation_url
-Netscape CA Revocation Url         NID_netscape_ca_revocation_url
-Netscape Renewal Url               NID_netscape_renewal_url
-Netscape CA Policy Url             NID_netscape_ca_policy_url
-Netscape SSL Server Name           NID_netscape_ssl_server_name
-Netscape Comment                   NID_netscape_comment
- -

Miscellaneous Certificate Extensions

- -
Strong Extranet ID                 NID_sxnet
-Proxy Certificate Information      NID_proxyCertInfo
- -

PKIX CRL Extensions

- -

The following are CRL extensions from PKIX standards such as RFC5280.

- -
CRL Number                         NID_crl_number
-CRL Distribution Points            NID_crl_distribution_points
-Delta CRL Indicator                NID_delta_crl
-Freshest CRL                       NID_freshest_crl
-Invalidity Date                    NID_invalidity_date
-Issuing Distribution Point         NID_issuing_distribution_point
- -

The following are CRL entry extensions from PKIX standards such as RFC5280.

- -
CRL Reason Code                    NID_crl_reason
-Certificate Issuer                 NID_certificate_issuer
- -

OCSP Extensions

- -
OCSP Nonce                         NID_id_pkix_OCSP_Nonce
-OCSP CRL ID                        NID_id_pkix_OCSP_CrlID
-Acceptable OCSP Responses          NID_id_pkix_OCSP_acceptableResponses
-OCSP No Check                      NID_id_pkix_OCSP_noCheck
-OCSP Archive Cutoff                NID_id_pkix_OCSP_archiveCutoff
-OCSP Service Locator               NID_id_pkix_OCSP_serviceLocator
-Hold Instruction Code              NID_hold_instruction_code
- -

Certificate Transparency Extensions

- -

The following extensions are used by certificate transparency, RFC6962

- -
CT Precertificate SCTs             NID_ct_precert_scts
-CT Certificate SCTs                NID_ct_cert_scts
- -

RETURN VALUES

- -

X509V3_get_d2i(), its variants, and X509V3_EXT_d2i() return a pointer to an extension specific structure or NULL if an error occurs.

- -

X509V3_add1_i2d() and its variants return 1 if the operation is successful and 0 if it fails due to a non-fatal error (extension not found, already exists, cannot be encoded) or -1 due to a fatal error such as a memory allocation failure.

- -

X509V3_EXT_i2d() returns a pointer to an X509_EXTENSION structure or NULL if an error occurs.

- -

X509_get0_extensions(), X509_CRL_get0_extensions() and X509_REVOKED_get0_extensions() return a stack of extensions. They return NULL if no extensions are present.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509_verify_cert(3)

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509V3_set_ctx.html b/openssl-install/share/doc/openssl/html/man3/X509V3_set_ctx.html deleted file mode 100644 index 398942fa..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509V3_set_ctx.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -X509V3_set_ctx - - - - - - - - - - -

NAME

- -

X509V3_set_ctx, X509V3_set_issuer_pkey - X.509 v3 extension generation utilities

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-void X509V3_set_ctx(X509V3_CTX *ctx, X509 *issuer, X509 *subject,
-                    X509_REQ *req, X509_CRL *crl, int flags);
-int X509V3_set_issuer_pkey(X509V3_CTX *ctx, EVP_PKEY *pkey);
- -

DESCRIPTION

- -

X509V3_set_ctx() fills in the basic fields of ctx of type X509V3_CTX, providing details potentially needed by functions producing X509 v3 extensions. These may make use of fields of the certificate subject, the certification request req, or the certificate revocation list crl. At most one of these three parameters can be non-NULL. When constructing the subject key identifier of a certificate by computing a hash value of its public key, the public key is taken from subject or req. Similarly, when constructing subject alternative names from any email addresses contained in a subject DN, the subject DN is taken from subject or req. If subject or crl is provided, issuer should point to its issuer, for instance as a reference for generating the authority key identifier extension. issuer may be the same pointer value as subject (which usually is an indication that the subject certificate is self-issued or even self-signed). In this case the fallback source for generating the authority key identifier extension will be taken from any value provided using X509V3_set_issuer_pkey(). flags may be 0 or contain X509V3_CTX_TEST, which means that just the syntax of extension definitions is to be checked without actually producing any extension, or X509V3_CTX_REPLACE, which means that each X.509v3 extension added as defined in some configuration section shall replace any already existing extension with the same OID.

- -

X509V3_set_issuer_pkey() explicitly sets the issuer private key of the subject certificate that has been provided in ctx. This should be done in case the issuer and subject arguments to X509V3_set_ctx() have the same pointer value to provide fallback data for the authority key identifier extension.

- -

RETURN VALUES

- -

X509V3_set_issuer_pkey() returns 1 on success and 0 on error.

- -

SEE ALSO

- -

X509_add_ext(3)

- -

HISTORY

- -

X509V3_set_issuer_pkey() was added in OpenSSL 3.0.

- -

CTX_TEST was deprecated in OpenSSL 3.0; use X509V3_CTX_TEST instead.

- -

COPYRIGHT

- -

Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_add1_attr.html b/openssl-install/share/doc/openssl/html/man3/X509_ACERT_add1_attr.html deleted file mode 100644 index ab8f1c0d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_add1_attr.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -X509_ACERT_add1_attr - - - - - - - - - - -

NAME

- -

X509_ACERT_add1_attr, X509_ACERT_add1_attr_by_NID, X509_ACERT_add1_attr_by_OBJ, X509_ACERT_add1_attr_by_txt, X509_ACERT_delete_attr - X509_ACERT attribute functions

- -

SYNOPSIS

- -
#include <openssl/x509_acert.h>
-
-int X509_ACERT_add1_attr(X509_ACERT *x, X509_ATTRIBUTE *attr);
-int X509_ACERT_add1_attr_by_NID(X509_ACERT *x, int nid, int type,
-                                const void *bytes, int len);
-int X509_ACERT_add1_attr_by_OBJ(X509_ACERT *x, const ASN1_OBJECT *obj,
-                                int type, const void *bytes, int len);
-int X509_ACERT_add1_attr_by_txt(X509_ACERT *x, const char *attrname, int type,
-                                const unsigned char *bytes, int len);
-X509_ATTRIBUTE *X509_ACERT_delete_attr(X509_ACERT *x, int loc);
- -

DESCRIPTION

- -

X509_ACERT_add1_attr() adds a constructed X509_ATTRIBUTE attr to the existing X509_ACERT structure x.

- -

X509_ACERT_add1_attr_by_NID() and X509_ACERT_add1_attr_by_OBJ() add an attribute of type nid or obj with a value of ASN1 type type constructed using len bytes from bytes.

- -

X509_ACERT_add1_attr_by_txt() adds an attribute of type attrname with a value of ASN1 type type constructed using len bytes from bytes.

- -

X509_ACERT_delete_attr() will delete the locth attribute from x and return a pointer to it or NULL if there are fewer than loc attributes contained in x.

- -

RETURN VALUES

- -

X509_ACERT_add1_attr(), X509_ACERT_add1_attr_by_NID(), and X509_ACERT_add1_attr_by_OBJ() return 1 for success and 0 for failure.

- -

X509_ACERT_delete_attr() returns a X509_ATTRIBUTE pointer on success or NULL on failure.

- -

SEE ALSO

- -

X509_ACERT_get_attr_count(3)

- -

HISTORY

- -

X509_ACERT_add1_attr(), X509_ACERT_add1_attr_by_NID(), X509_ACERT_add1_attr_by_OBJ(), X509_ACERT_add1_attr_by_txt() and X509_ACERT_delete_attr() were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_add_attr_nconf.html b/openssl-install/share/doc/openssl/html/man3/X509_ACERT_add_attr_nconf.html deleted file mode 100644 index fedc6707..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_add_attr_nconf.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -X509_ACERT_add_attr_nconf - - - - - - - - - - -

NAME

- -

X509_ACERT_add_attr_nconf - Add attributes to X509_ACERT from configuration section

- -

SYNOPSIS

- -
#include <openssl/x509_acert.h>
-
-int X509_ACERT_add_attr_nconf(CONF *conf, const char *section,
-                              X509_ACERT *acert);
- -

DESCRIPTION

- -

X509_ACERT_add_attr_nconf() adds one or more X509_ATTRIBUTEs to the existing X509_ACERT structure acert. The attributes are read from a section of the conf object.

- -

The give section of the configuration should contain attribute descriptions of the form:

- -
attribute_name = value
- -

The format of value will vary depending on the attribute_name. value can either be a string value or an ASN1_TYPE object.

- -

To encode an ASN1_TYPE object, use the prefix "ASN1:" followed by the object description that uses the same syntax as ASN1_generate_nconf(3). For example:

- -
id-aca-group = ASN1:SEQUENCE:ietfattr
-
-[ietfattr]
-values = SEQUENCE:groups
-
-[groups]
-1.string = UTF8:mygroup1
- -

RETURN VALUES

- -

X509_ACERT_add_attr_nconf() returns 1 for success and 0 for failure.

- -

SEE ALSO

- -

ASN1_generate_nconf(3).

- -

HISTORY

- -

The function X509_ACERT_add_attr_nconf() was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_get0_holder_baseCertId.html b/openssl-install/share/doc/openssl/html/man3/X509_ACERT_get0_holder_baseCertId.html deleted file mode 100644 index c8aa18fa..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_get0_holder_baseCertId.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -X509_ACERT_get0_holder_baseCertId - - - - - - - - - - -

NAME

- -

X509_ACERT_get0_holder_baseCertId, X509_ACERT_get0_holder_digest, X509_ACERT_get0_holder_entityName, X509_ACERT_set0_holder_baseCertId, X509_ACERT_set0_holder_digest, X509_ACERT_set0_holder_entityName, OSSL_ISSUER_SERIAL_get0_issuer, OSSL_ISSUER_SERIAL_get0_issuerUID, OSSL_ISSUER_SERIAL_get0_serial, OSSL_ISSUER_SERIAL_set1_issuer, OSSL_ISSUER_SERIAL_set1_issuerUID, OSSL_ISSUER_SERIAL_set1_serial, OSSL_OBJECT_DIGEST_INFO_get0_digest, OSSL_OBJECT_DIGEST_INFO_set1_digest - get and set Attribute Certificate holder fields

- -

SYNOPSIS

- -
#include <openssl/x509_acert.h>
-
-const GENERAL_NAMES *X509_ACERT_get0_holder_entityName(const X509_ACERT *x);
-OSSL_ISSUER_SERIAL *X509_ACERT_get0_holder_baseCertId(const X509_ACERT *x);
-OSSL_OBJECT_DIGEST_INFO * X509_ACERT_get0_holder_digest(const X509_ACERT *x);
-void X509_ACERT_set0_holder_entityName(X509_ACERT *x, GENERAL_NAMES *name);
-void X509_ACERT_set0_holder_baseCertId(X509_ACERT *x, OSSL_ISSUER_SERIAL *isss);
-void X509_ACERT_set0_holder_digest(X509_ACERT *x,
-                                   OSSL_OBJECT_DIGEST_INFO *dinfo);
-
-X509_NAME *OSSL_ISSUER_SERIAL_get0_issuer(OSSL_ISSUER_SERIAL *isss);
-ASN1_INTEGER *OSSL_ISSUER_SERIAL_get0_serial(OSSL_ISSUER_SERIAL *isss);
-ASN1_BIT_STRING *OSSL_ISSUER_SERIAL_get0_issuerUID(OSSL_ISSUER_SERIAL *isss);
-int OSSL_ISSUER_SERIAL_set1_issuer(OSSL_ISSUER_SERIAL *isss, X509_NAME *issuer);
-int OSSL_ISSUER_SERIAL_set1_serial(OSSL_ISSUER_SERIAL *isss, ASN1_INTEGER *serial);
-int OSSL_ISSUER_SERIAL_set1_issuerUID(OSSL_ISSUER_SERIAL *isss, ASN1_BIT_STRING *uid);
-
-void OSSL_OBJECT_DIGEST_INFO_get0_digest(OSSL_OBJECT_DIGEST_INFO *o,
-                                         ASN1_ENUMERATED **digestedObjectType,
-                                         X509_ALGOR **digestAlgorithm,
-                                         ASN1_BIT_STRING **digest);
-void OSSL_OBJECT_DIGEST_INFO_set1_digest(OSSL_OBJECT_DIGEST_INFO *o,
-                                         ASN1_ENUMERATED *digestedObjectType,
-                                         X509_ALGOR *digestAlgorithm,
-                                         ASN1_BIT_STRING *digest);
- -

DESCRIPTION

- -

These routines set and get the holder identity of an X509 attribute certificate.

- -

X509_ACERT_set0_holder_entityName() sets the identity as a GENERAL_NAME name, X509_ACERT_set0_holder_baseCertId() sets the identity based on the issuer and serial number of a certificate detailed in isss and X509_ACERT_set0_holder_digest() sets the holder entity based on digest information dinfo. Although RFC 5755 section 4.2.2 recommends that only one of the above methods be used to set the holder identity for a given attribute certificate x, setting multiple methods at the same time is possible. It is up to the application to handle cases when conflicting identity information is specified using different methods.

- -

Pointers to the internal structures describing the holder identity of attribute certificate x can be retrieved with X509_ACERT_get0_holder_entityName(), X509_ACERT_get0_holder_baseCertId(), and X509_ACERT_get0_holder_digest().

- -

A OSSL_ISSUER_SERIAL object holds the subject name and UID of a certificate issuer and a certificate's serial number. OSSL_ISSUER_SERIAL_set1_issuer(), OSSL_ISSUER_SERIAL_set1_issuerUID(), and OSSL_ISSUER_SERIAL_set1_serial() respectively copy these values into the OSSL_ISSUER_SERIAL structure. The application is responsible for freeing its own copy of these values after use. OSSL_ISSUER_SERIAL_get0_issuer(), OSSL_ISSUER_SERIAL_get0_issuerUID(), and OSSL_ISSUER_SERIAL_get0_serial() return pointers to these values in the object.

- -

An OSSL_OBJECT_DIGEST_INFO object holds a digest of data to identify the attribute certificate holder. OSSL_OBJECT_DIGEST_INFO_set1_digest() sets the digest information of the object. The type of digest information is given by digestedObjectType and can be one of:

- -
- -
OSSL_OBJECT_DIGEST_INFO_PUBLIC_KEY
-
- -

Hash of a public key

- -
-
OSSL_OBJECT_DIGEST_INFO_PUBLIC_KEY_CERT
-
- -

Hash of a public key certificate

- -
-
OSSL_OBJECT_DIGEST_INFO_OTHER
-
- -

Hash of another object. See NOTES below.

- -
-
- -

digestAlgorithm indicates the algorithm used to compute digest.

- -

RETURN VALUES

- -

All set0/set1 routines return 1 for success and 0 for failure. All get0 functions return a pointer to the object's inner structure. These pointers must not be freed after use.

- -

NOTES

- -

Although the value of OSSL_OBJECT_DIGEST_INFO_OTHER is defined in RFC 5755, its use is prohibited for conformant attribute certificates.

- -

HISTORY

- -

These functions were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_get_attr.html b/openssl-install/share/doc/openssl/html/man3/X509_ACERT_get_attr.html deleted file mode 100644 index 015ea57d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_get_attr.html +++ /dev/null @@ -1,66 +0,0 @@ - - - - -X509_ACERT_get_attr - - - - - - - - - - -

NAME

- -

X509_ACERT_get_attr, X509_ACERT_get_attr_by_NID, X509_ACERT_get_attr_by_OBJ, X509_ACERT_get_attr_count - Retrieve attributes from an X509_ACERT structure

- -

SYNOPSIS

- -
#include <openssl/x509_acert.h>
-
-X509_ATTRIBUTE *X509_ACERT_get_attr(const X509_ACERT *x, int loc);
-int X509_ACERT_get_attr_by_NID(const X509_ACERT *x, int nid, int lastpos);
-int X509_ACERT_get_attr_by_OBJ(const X509_ACERT *x, const ASN1_OBJECT *obj,
-                               int lastpos);
-int X509_ACERT_get_attr_count(const X509_ACERT *x);
- -

DESCRIPTION

- -

X509_ACERT_get0_attr() retrieves the locth X509_ATTRIBUTE from an X509_ACERT x. X509_ACERT_get_attr_count() returns the total number of attributes in the X509_ACERT.

- -

X509_ACERT_get_attr_by_NID() and X509_ACERT_get_attr_by_OBJ() retrieve the next attribute location matching nid or obj after lastpos. lastpos should initially be set to -1. If there are no more entries -1 is returned. If nid is invalid (doesn't correspond to a valid OID) then -2 is returned.

- -

RETURN VALUES

- -

X509_ACERT_get0_attr() return a X509_ATTRIBUTE from an attribute certificate, or NULL if the specified attribute is not found.

- -

X509_ACERT_get_attr_by_NID() and X509_ACERT_get_attr_by_OBJ() return the location of the next attribute requested or -1 if not found. X509_ACERT_get_attr_by_NID() can also return -2 if the supplied NID is invalid.

- -

X509_ACERT_get_attr_count() returns the number of attributes in the given attribute certificate.

- -

HISTORY

- -

X509_ACERT_get0_attr(), X509_ACERT_get_attr_by_NID(), X509_ACERT_get_attr_by_OBJ() and X509_ACERT_get_attr_count() were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_print_ex.html b/openssl-install/share/doc/openssl/html/man3/X509_ACERT_print_ex.html deleted file mode 100644 index e87d2e38..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_ACERT_print_ex.html +++ /dev/null @@ -1,110 +0,0 @@ - - - - -X509_ACERT_print_ex - - - - - - - - - - -

NAME

- -

X509_ACERT_print_ex, X509_ACERT_print - X509_ACERT printing routines

- -

SYNOPSIS

- -
#include <openssl/x509_acert.h>
-
-int X509_ACERT_print(BIO *bp, X509_ACERT *acert);
-int X509_ACERT_print_ex(BIO *bp, X509_ACERT *acert, unsigned long nmflags,
-                        unsigned long cflag);
- -

DESCRIPTION

- -

X509_ACERT_print_ex() prints a human readable version of the attribute certificate acert to BIO bp.

- -

The following data contained in the attribute certificate is printed in order:

- - - -

RETURN VALUES

- -

X509_ACERT_print_ex() X509_ACERT_print() return 1 for success and 0 for failure.

- -

SEE ALSO

- -

X509_NAME_print_ex(3)

- -

HISTORY

- -

X509_ACERT_print() and X509_ACERT_print_ex() were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_ALGOR_dup.html b/openssl-install/share/doc/openssl/html/man3/X509_ALGOR_dup.html deleted file mode 100644 index 65679411..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_ALGOR_dup.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -X509_ALGOR_dup - - - - - - - - - - -

NAME

- -

X509_ALGOR_dup, X509_ALGOR_set0, X509_ALGOR_get0, X509_ALGOR_set_md, X509_ALGOR_cmp, X509_ALGOR_copy - AlgorithmIdentifier functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-X509_ALGOR *X509_ALGOR_dup(X509_ALGOR *alg);
-int X509_ALGOR_set0(X509_ALGOR *alg, ASN1_OBJECT *aobj, int ptype, void *pval);
-void X509_ALGOR_get0(const ASN1_OBJECT **paobj, int *pptype,
-                     const void **ppval, const X509_ALGOR *alg);
-void X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md);
-int X509_ALGOR_cmp(const X509_ALGOR *a, const X509_ALGOR *b);
-int X509_ALGOR_copy(X509_ALGOR *dest, const X509_ALGOR *src);
- -

DESCRIPTION

- -

X509_ALGOR_dup() returns a copy of alg.

- -

X509_ALGOR_set0() sets the algorithm OID of alg to aobj and the associated parameter type to ptype with value pval. If ptype is V_ASN1_UNDEF the parameter is omitted, otherwise ptype and pval have the same meaning as the type and value parameters to ASN1_TYPE_set(). All the supplied parameters are used internally so must NOT be freed after this call succeeded; otherwise ownership remains with the caller and alg remains untouched.

- -

X509_ALGOR_get0() is the inverse of X509_ALGOR_set0(): it returns the algorithm OID in *paobj and the associated parameter in *pptype and *ppval from the AlgorithmIdentifier alg.

- -

X509_ALGOR_set_md() sets the AlgorithmIdentifier alg to appropriate values for the message digest md.

- -

X509_ALGOR_cmp() compares a and b and returns 0 if they have identical encodings and nonzero otherwise.

- -

X509_ALGOR_copy() copies the source values into the dest structs; making a duplicate of each (and free any thing pointed to from within *dest).

- -

RETURN VALUES

- -

X509_ALGOR_dup() returns a valid X509_ALGOR structure or NULL if an error occurred.

- -

X509_ALGOR_set0() and X509_ALGOR_copy() return 1 on success or 0 on error.

- -

X509_ALGOR_get0() and X509_ALGOR_set_md() return no values.

- -

X509_ALGOR_cmp() returns 0 if the two parameters have identical encodings and nonzero otherwise.

- -

HISTORY

- -

The X509_ALGOR_copy() was added in 1.1.1e.

- -

COPYRIGHT

- -

Copyright 2002-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_ATTRIBUTE.html b/openssl-install/share/doc/openssl/html/man3/X509_ATTRIBUTE.html deleted file mode 100644 index 9087cd5b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_ATTRIBUTE.html +++ /dev/null @@ -1,184 +0,0 @@ - - - - -X509_ATTRIBUTE - - - - - - - - - - -

NAME

- -

X509_ATTRIBUTE, X509at_get_attr, X509at_get_attr_count, X509at_get_attr_by_NID, X509at_get_attr_by_OBJ, X509at_delete_attr, X509at_add1_attr, X509at_add1_attr_by_OBJ, X509at_add1_attr_by_NID, X509at_add1_attr_by_txt, X509at_get0_data_by_OBJ, X509_ATTRIBUTE_create, X509_ATTRIBUTE_create_by_NID, X509_ATTRIBUTE_create_by_OBJ, X509_ATTRIBUTE_create_by_txt, X509_ATTRIBUTE_set1_object, X509_ATTRIBUTE_set1_data, X509_ATTRIBUTE_count, X509_ATTRIBUTE_get0_data, X509_ATTRIBUTE_get0_object, X509_ATTRIBUTE_get0_type - X509 attribute functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-typedef struct x509_attributes_st X509_ATTRIBUTE;
-
-int X509at_get_attr_count(const STACK_OF(X509_ATTRIBUTE) *x);
-int X509at_get_attr_by_NID(const STACK_OF(X509_ATTRIBUTE) *x, int nid,
-                           int lastpos);
-int X509at_get_attr_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *sk,
-                           const ASN1_OBJECT *obj, int lastpos);
-X509_ATTRIBUTE *X509at_get_attr(const STACK_OF(X509_ATTRIBUTE) *x, int loc);
-X509_ATTRIBUTE *X509at_delete_attr(STACK_OF(X509_ATTRIBUTE) *x, int loc);
-STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr(STACK_OF(X509_ATTRIBUTE) **x,
-                                           X509_ATTRIBUTE *attr);
-STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_OBJ(STACK_OF(X509_ATTRIBUTE)
-                                                  **x, const ASN1_OBJECT *obj,
-                                                  int type,
-                                                  const unsigned char *bytes,
-                                                  int len);
-STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_NID(STACK_OF(X509_ATTRIBUTE)
-                                                  **x, int nid, int type,
-                                                  const unsigned char *bytes,
-                                                  int len);
-STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_txt(STACK_OF(X509_ATTRIBUTE)
-                                                  **x, const char *attrname,
-                                                  int type,
-                                                  const unsigned char *bytes,
-                                                  int len);
-void *X509at_get0_data_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *x,
-                              const ASN1_OBJECT *obj, int lastpos, int type);
-X509_ATTRIBUTE *X509_ATTRIBUTE_create(int nid, int atrtype, void *value);
-X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_NID(X509_ATTRIBUTE **attr, int nid,
-                                             int atrtype, const void *data,
-                                             int len);
-X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_OBJ(X509_ATTRIBUTE **attr,
-                                             const ASN1_OBJECT *obj,
-                                             int atrtype, const void *data,
-                                             int len);
-X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_txt(X509_ATTRIBUTE **attr,
-                                             const char *atrname, int type,
-                                             const unsigned char *bytes,
-                                             int len);
-int X509_ATTRIBUTE_set1_object(X509_ATTRIBUTE *attr, const ASN1_OBJECT *obj);
-int X509_ATTRIBUTE_set1_data(X509_ATTRIBUTE *attr, int attrtype,
-                             const void *data, int len);
-void *X509_ATTRIBUTE_get0_data(X509_ATTRIBUTE *attr, int idx, int atrtype,
-                               void *data);
-int X509_ATTRIBUTE_count(const X509_ATTRIBUTE *attr);
-ASN1_OBJECT *X509_ATTRIBUTE_get0_object(X509_ATTRIBUTE *attr);
-ASN1_TYPE *X509_ATTRIBUTE_get0_type(X509_ATTRIBUTE *attr, int idx);
- -

DESCRIPTION

- -

X509_ATTRIBUTE objects are used by many standards including X509, X509_REQ, PKCS12, PKCS8, PKCS7 and CMS.

- -

The X509_ATTRIBUTE object is used to represent the ASN.1 Attribute as defined in RFC 5280, i.e.

- -
Attribute ::= SEQUENCE {
-  type             AttributeType,
-  values    SET OF AttributeValue }
-
-AttributeType ::= OBJECT IDENTIFIER
-AttributeValue ::= ANY -- DEFINED BY AttributeType
- -

For example CMS defines the signing-time attribute as:

- -
id-signingTime OBJECT IDENTIFIER ::= { iso(1) member-body(2)
-    us(840) rsadsi(113549) pkcs(1) pkcs9(9) 5 }
-
-SigningTime ::= Time
-
-Time ::= CHOICE {
-  utcTime UTCTime,
-  generalizedTime GeneralizedTime }
- -

In OpenSSL AttributeType maps to an ASN1_OBJECT object and AttributeValue maps to a list of ASN1_TYPE objects.

- -

The following functions are used for X509_ATTRIBUTE objects.

- -

X509at_get_attr_by_OBJ() finds the location of the first matching object obj in a list of attributes sk. The search starts at the position after lastpos. If the returned value is positive then it can be used on the next call to X509at_get_attr_by_OBJ() as the value of lastpos in order to iterate through the remaining attributes. lastpos can be set to any negative value on the first call, in order to start searching from the start of the list.

- -

X509at_get_attr_by_NID() is similar to X509at_get_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

X509at_get_attr() returns the X509_ATTRIBUTE object at index loc in the list of attributes x. loc should be in the range from 0 to X509at_get_attr_count() - 1.

- -

X509at_delete_attr() removes the X509_ATTRIBUTE object at index loc in the list of attributes x.

- -

X509at_add1_attr() pushes a copy of the passed in X509_ATTRIBUTE object to the list x. Both x and attr must be non NULL or an error will occur. If *x is NULL then a new list is created, otherwise it uses the passed in list. An error will occur if an existing attribute (with the same attribute type) already exists in the attribute list.

- -

X509at_add1_attr_by_OBJ() creates a new X509_ATTRIBUTE using X509_ATTRIBUTE_set1_object() and X509_ATTRIBUTE_set1_data() to assign a new obj with type type and data bytes of length len and then pushes it to the attribute list x. Both x and attr must be non NULL or an error will occur. If *x is NULL then a new attribute list is created. If obj already exists in the attribute list then an error occurs.

- -

X509at_add1_attr_by_NID() is similar to X509at_add1_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

X509at_add1_attr_by_txt() is similar to X509at_add1_attr_by_OBJ() except that it passes a name attrname associated with the object. See <openssl/obj_mac.h> for a list of SN_* names.

- -

X509_ATTRIBUTE_set1_object() assigns a ASN1_OBJECT obj to the attribute attr. If attr contained an existing ASN1_OBJECT then it is freed. An error occurs if either attr or obj are NULL, or if the passed in obj cannot be duplicated.

- -

X509_ATTRIBUTE_set1_data() pushes a new ASN1_TYPE object onto the attr attributes list. The new object is assigned a copy of the data in data of size len. If attrtype has flag MBSTRING_FLAG set then a table lookup using the attr attributes NID is used to set an ASN1_STRING using ASN1_STRING_set_by_NID(), and the passed in data must be in the format required for that object type or an error will occur. If len is not -1 then internally ASN1_STRING_type_new() is used with the passed in attrtype. If attrtype is 0 the call does nothing except return 1.

- -

X509_ATTRIBUTE_create() creates a new X509_ATTRIBUTE using the nid to set the ASN1_OBJECT OID and the atrtype and value to set the ASN1_TYPE.

- -

X509_ATTRIBUTE_create_by_OBJ() uses X509_ATTRIBUTE_set1_object() and X509_ATTRIBUTE_set1_data() to assign a new obj with type atrtype and data data of length len. If the passed in attribute attr OR *attr is NULL then a new X509_ATTRIBUTE will be returned, otherwise the passed in X509_ATTRIBUTE is used. Note that the ASN1_OBJECT obj is pushed onto the attributes existing list of objects, which could be an issue if the attributes <ASN1_OBJECT> was different.

- -

X509_ATTRIBUTE_create_by_NID() is similar to X509_ATTRIBUTE_create_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

X509_ATTRIBUTE_create_by_txt() is similar to X509_ATTRIBUTE_create_by_OBJ() except that it passes a name atrname associated with the object. See <openssl/obj_mac.h> for a list of SN_* names.

- -

X509_ATTRIBUTE_count() returns the number of ASN1_TYPE objects in an attribute attr.

- -

X509_ATTRIBUTE_get0_type() returns the ASN1_TYPE object at index idx in the attribute list attr. idx should be in the range of 0 to X509_ATTRIBUTE_count() - 1 or an error will occur.

- -

X509_ATTRIBUTE_get0_data() returns the data of an ASN1_TYPE object at index idx in the attribute attr. data is unused and can be set to NULL. An error will occur if the attribute type atrtype does not match the type of the ASN1_TYPE object at index idx OR if atrtype is either V_ASN1_BOOLEAN or V_ASN1_NULL OR if the idx is not in the range 0 to X509_ATTRIBUTE_count() - 1.

- -

X509at_get0_data_by_OBJ() finds the first attribute in an attribute list x that matches the obj starting at index lastpos and returns the data retrieved from the found attributes first ASN1_TYPE object. An error will occur if the attribute type type does not match the type of the ASN1_TYPE object OR if type is either V_ASN1_BOOLEAN or V_ASN1_NULL OR the attribute is not found. If lastpos is less than -1 then an error will occur if there are multiple objects in the list x that match obj. If lastpos is less than -2 then an error will occur if there is more than one ASN1_TYPE object in the found attribute.

- -

RETURN VALUES

- -

X509at_get_attr_count() returns the number of attributes in the list x or -1 if x is NULL.

- -

X509at_get_attr_by_OBJ() returns -1 if either the list is empty OR the object is not found, otherwise it returns the location of the object in the list.

- -

X509at_get_attr_by_NID() is similar to X509at_get_attr_by_OBJ(), except that it returns -2 if the nid is not known by OpenSSL.

- -

X509at_get_attr() returns either an X509_ATTRIBUTE or NULL if there is a error.

- -

X509at_delete_attr() returns either the removed X509_ATTRIBUTE or NULL if there is a error.

- -

X509_ATTRIBUTE_count() returns -1 on error, otherwise it returns the number of ASN1_TYPE elements.

- -

X509_ATTRIBUTE_get0_type() returns NULL on error, otherwise it returns a ASN1_TYPE object.

- -

X509_ATTRIBUTE_get0_data() returns NULL if an error occurs, otherwise it returns the data associated with an ASN1_TYPE object.

- -

X509_ATTRIBUTE_set1_object() and X509_ATTRIBUTE_set1_data() returns 1 on success, or 0 otherwise.

- -

X509_ATTRIBUTE_create(), X509_ATTRIBUTE_create_by_OBJ(), X509_ATTRIBUTE_create_by_NID() and X509_ATTRIBUTE_create_by_txt() return either a X509_ATTRIBUTE on success, or NULL if there is a error.

- -

X509at_add1_attr(), X509at_add1_attr_by_OBJ(), X509at_add1_attr_by_NID() and X509at_add1_attr_by_txt() return NULL on error, otherwise they return a list of X509_ATTRIBUTE.

- -

X509at_get0_data_by_OBJ() returns the data retrieved from the found attributes first ASN1_TYPE object, or NULL if an error occurs.

- -

SEE ALSO

- -

ASN1_TYPE_get(3), ASN1_INTEGER_get(3), ASN1_ENUMERATED_get(3), ASN1_STRING_get0_data(3), ASN1_STRING_length(3), ASN1_STRING_type(3), X509_REQ_get_attr(3), EVP_PKEY_get_attr(3), CMS_signed_get_attr(3), PKCS8_pkey_get0_attrs(3),

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_CRL_get0_by_serial.html b/openssl-install/share/doc/openssl/html/man3/X509_CRL_get0_by_serial.html deleted file mode 100644 index dbeb03a5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_CRL_get0_by_serial.html +++ /dev/null @@ -1,99 +0,0 @@ - - - - -X509_CRL_get0_by_serial - - - - - - - - - - -

NAME

- -

X509_CRL_get0_by_serial, X509_CRL_get0_by_cert, X509_CRL_get_REVOKED, X509_REVOKED_get0_serialNumber, X509_REVOKED_get0_revocationDate, X509_REVOKED_set_serialNumber, X509_REVOKED_set_revocationDate, X509_CRL_add0_revoked, X509_CRL_sort - CRL revoked entry utility functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_CRL_get0_by_serial(X509_CRL *crl,
-                            X509_REVOKED **ret, const ASN1_INTEGER *serial);
-int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, X509 *x);
-
-STACK_OF(X509_REVOKED) *X509_CRL_get_REVOKED(X509_CRL *crl);
-
-const ASN1_INTEGER *X509_REVOKED_get0_serialNumber(const X509_REVOKED *r);
-const ASN1_TIME *X509_REVOKED_get0_revocationDate(const X509_REVOKED *r);
-
-int X509_REVOKED_set_serialNumber(X509_REVOKED *r, ASN1_INTEGER *serial);
-int X509_REVOKED_set_revocationDate(X509_REVOKED *r, ASN1_TIME *tm);
-
-int X509_CRL_add0_revoked(X509_CRL *crl, X509_REVOKED *rev);
-
-int X509_CRL_sort(X509_CRL *crl);
- -

DESCRIPTION

- -

X509_CRL_get0_by_serial() attempts to find a revoked entry in crl for serial number serial. If it is successful, it sets *ret to the internal pointer of the matching entry. As a result, *ret MUST NOT be freed after the call.

- -

X509_CRL_get0_by_cert() is similar to X509_get0_by_serial() except it looks for a revoked entry using the serial number of certificate x.

- -

X509_CRL_get_REVOKED() returns an internal pointer to a STACK of all revoked entries for crl.

- -

X509_REVOKED_get0_serialNumber() returns an internal pointer to the serial number of r.

- -

X509_REVOKED_get0_revocationDate() returns an internal pointer to the revocation date of r.

- -

X509_REVOKED_set_serialNumber() sets the serial number of r to serial. The supplied serial pointer is not used internally so it should be freed after use.

- -

X509_REVOKED_set_revocationDate() sets the revocation date of r to tm. The supplied tm pointer is not used internally so it should be freed after use.

- -

X509_CRL_add0_revoked() appends revoked entry rev to CRL crl. The pointer rev is used internally so it MUST NOT be freed after the call: it is freed when the parent CRL is freed.

- -

X509_CRL_sort() sorts the revoked entries of crl into ascending serial number order.

- -

NOTES

- -

Applications can determine the number of revoked entries returned by X509_CRL_get_REVOKED() using sk_X509_REVOKED_num() and examine each one in turn using sk_X509_REVOKED_value().

- -

RETURN VALUES

- -

X509_CRL_get0_by_serial() and X509_CRL_get0_by_cert() return 0 for failure, 1 on success except if the revoked entry has the reason removeFromCRL (8), in which case 2 is returned.

- -

X509_CRL_get_REVOKED() returns a STACK of revoked entries.

- -

X509_REVOKED_get0_serialNumber() returns an ASN1_INTEGER structure.

- -

X509_REVOKED_get0_revocationDate() returns an ASN1_TIME structure.

- -

X509_REVOKED_set_serialNumber(), X509_REVOKED_set_revocationDate(), X509_CRL_add0_revoked() and X509_CRL_sort() return 1 for success and 0 for failure.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

COPYRIGHT

- -

Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_EXTENSION_set_object.html b/openssl-install/share/doc/openssl/html/man3/X509_EXTENSION_set_object.html deleted file mode 100644 index 37c6d709..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_EXTENSION_set_object.html +++ /dev/null @@ -1,96 +0,0 @@ - - - - -X509_EXTENSION_set_object - - - - - - - - - - -

NAME

- -

X509_EXTENSION_set_object, X509_EXTENSION_set_critical, X509_EXTENSION_set_data, X509_EXTENSION_create_by_NID, X509_EXTENSION_create_by_OBJ, X509_EXTENSION_get_object, X509_EXTENSION_get_critical, X509_EXTENSION_get_data - extension utility functions

- -

SYNOPSIS

- -
int X509_EXTENSION_set_object(X509_EXTENSION *ex, const ASN1_OBJECT *obj);
-int X509_EXTENSION_set_critical(X509_EXTENSION *ex, int crit);
-int X509_EXTENSION_set_data(X509_EXTENSION *ex, ASN1_OCTET_STRING *data);
-
-X509_EXTENSION *X509_EXTENSION_create_by_NID(X509_EXTENSION **ex,
-                                             int nid, int crit,
-                                             ASN1_OCTET_STRING *data);
-X509_EXTENSION *X509_EXTENSION_create_by_OBJ(X509_EXTENSION **ex,
-                                             const ASN1_OBJECT *obj, int crit,
-                                             ASN1_OCTET_STRING *data);
-
-ASN1_OBJECT *X509_EXTENSION_get_object(X509_EXTENSION *ex);
-int X509_EXTENSION_get_critical(const X509_EXTENSION *ex);
-ASN1_OCTET_STRING *X509_EXTENSION_get_data(X509_EXTENSION *ne);
- -

DESCRIPTION

- -

X509_EXTENSION_set_object() sets the extension type of ex to obj. The obj pointer is duplicated internally so obj should be freed up after use.

- -

X509_EXTENSION_set_critical() sets the criticality of ex to crit. If crit is zero the extension in non-critical otherwise it is critical.

- -

X509_EXTENSION_set_data() sets the data in extension ex to data. The data pointer is duplicated internally.

- -

X509_EXTENSION_create_by_NID() creates an extension of type nid, criticality crit using data data. The created extension is returned and written to *ex reusing or allocating a new extension if necessary so *ex should either be NULL or a valid X509_EXTENSION structure it must not be an uninitialised pointer.

- -

X509_EXTENSION_create_by_OBJ() is identical to X509_EXTENSION_create_by_NID() except it creates and extension using obj instead of a NID.

- -

X509_EXTENSION_get_object() returns the extension type of ex as an ASN1_OBJECT pointer. The returned pointer is an internal value which must not be freed up.

- -

X509_EXTENSION_get_critical() returns the criticality of extension ex it returns 1 for critical and 0 for non-critical.

- -

X509_EXTENSION_get_data() returns the data of extension ex. The returned pointer is an internal value which must not be freed up.

- -

NOTES

- -

These functions manipulate the contents of an extension directly. Most applications will want to parse or encode and add an extension: they should use the extension encode and decode functions instead such as X509_add1_ext_i2d() and X509_get_ext_d2i().

- -

The data associated with an extension is the extension encoding in an ASN1_OCTET_STRING structure.

- -

RETURN VALUES

- -

X509_EXTENSION_set_object() X509_EXTENSION_set_critical() and X509_EXTENSION_set_data() return 1 for success and 0 for failure.

- -

X509_EXTENSION_create_by_NID() and X509_EXTENSION_create_by_OBJ() return an X509_EXTENSION pointer or NULL if an error occurs.

- -

X509_EXTENSION_get_object() returns an ASN1_OBJECT pointer.

- -

X509_EXTENSION_get_critical() returns 0 for non-critical and 1 for critical.

- -

X509_EXTENSION_get_data() returns an ASN1_OCTET_STRING pointer.

- -

SEE ALSO

- -

X509V3_get_d2i(3)

- -

COPYRIGHT

- -

Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP.html b/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP.html deleted file mode 100644 index cadbc1c7..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP.html +++ /dev/null @@ -1,186 +0,0 @@ - - - - -X509_LOOKUP - - - - - - - - - - -

NAME

- -

X509_LOOKUP, X509_LOOKUP_TYPE, X509_LOOKUP_new, X509_LOOKUP_free, X509_LOOKUP_init, X509_LOOKUP_shutdown, X509_LOOKUP_set_method_data, X509_LOOKUP_get_method_data, X509_LOOKUP_ctrl_ex, X509_LOOKUP_ctrl, X509_LOOKUP_load_file_ex, X509_LOOKUP_load_file, X509_LOOKUP_add_dir, X509_LOOKUP_add_store_ex, X509_LOOKUP_add_store, X509_LOOKUP_load_store_ex, X509_LOOKUP_load_store, X509_LOOKUP_get_store, X509_LOOKUP_by_subject_ex, X509_LOOKUP_by_subject, X509_LOOKUP_by_issuer_serial, X509_LOOKUP_by_fingerprint, X509_LOOKUP_by_alias - OpenSSL certificate lookup mechanisms

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-typedef x509_lookup_st X509_LOOKUP;
-
-typedef enum X509_LOOKUP_TYPE;
-
-X509_LOOKUP *X509_LOOKUP_new(X509_LOOKUP_METHOD *method);
-int X509_LOOKUP_init(X509_LOOKUP *ctx);
-int X509_LOOKUP_shutdown(X509_LOOKUP *ctx);
-void X509_LOOKUP_free(X509_LOOKUP *ctx);
-
-int X509_LOOKUP_set_method_data(X509_LOOKUP *ctx, void *data);
-void *X509_LOOKUP_get_method_data(const X509_LOOKUP *ctx);
-
-int X509_LOOKUP_ctrl_ex(X509_LOOKUP *ctx, int cmd, const char *argc, long argl,
-                        char **ret, OSSL_LIB_CTX *libctx, const char *propq);
-int X509_LOOKUP_ctrl(X509_LOOKUP *ctx, int cmd, const char *argc,
-                     long argl, char **ret);
-int X509_LOOKUP_load_file_ex(X509_LOOKUP *ctx, char *name, long type,
-                             OSSL_LIB_CTX *libctx, const char *propq);
-int X509_LOOKUP_load_file(X509_LOOKUP *ctx, char *name, long type);
-int X509_LOOKUP_load_file_ex(X509_LOOKUP *ctx, char *name, long type,
-                             OSSL_LIB_CTX *libctx, const char *propq);
-int X509_LOOKUP_add_dir(X509_LOOKUP *ctx, char *name, long type);
-int X509_LOOKUP_add_store_ex(X509_LOOKUP *ctx, char *uri, OSSL_LIB_CTX *libctx,
-                             const char *propq);
-int X509_LOOKUP_add_store(X509_LOOKUP *ctx, char *uri);
-int X509_LOOKUP_load_store_ex(X509_LOOKUP *ctx, char *uri, OSSL_LIB_CTX *libctx,
-                              const char *propq);
-int X509_LOOKUP_load_store(X509_LOOKUP *ctx, char *uri);
-
-X509_STORE *X509_LOOKUP_get_store(const X509_LOOKUP *ctx);
-
-int X509_LOOKUP_by_subject_ex(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type,
-                              const X509_NAME *name, X509_OBJECT *ret,
-                              OSSL_LIB_CTX *libctx, const char *propq);
-int X509_LOOKUP_by_subject(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type,
-                           const X509_NAME *name, X509_OBJECT *ret);
-int X509_LOOKUP_by_issuer_serial(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type,
-                                 const X509_NAME *name,
-                                 const ASN1_INTEGER *serial, X509_OBJECT *ret);
-int X509_LOOKUP_by_fingerprint(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type,
-                               const unsigned char *bytes, int len,
-                               X509_OBJECT *ret);
-int X509_LOOKUP_by_alias(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type,
-                         const char *str, int len, X509_OBJECT *ret);
- -

DESCRIPTION

- -

The X509_LOOKUP structure holds the information needed to look up certificates and CRLs according to an associated X509_LOOKUP_METHOD(3). Multiple X509_LOOKUP instances can be added to an X509_STORE(3) to enable lookup in that store.

- -

X509_LOOKUP_new() creates a new X509_LOOKUP using the given lookup method. It can also be created by calling X509_STORE_add_lookup(3), which will associate a X509_STORE with the lookup mechanism.

- -

X509_LOOKUP_init() initializes the internal state and resources as needed by the given X509_LOOKUP to do its work.

- -

X509_LOOKUP_shutdown() tears down the internal state and resources of the given X509_LOOKUP.

- -

X509_LOOKUP_free() destructs the given X509_LOOKUP. If the argument is NULL, nothing is done.

- -

X509_LOOKUP_set_method_data() and X509_LOOKUP_get_method_data() associates and retrieves a pointer to application data to and from the given X509_LOOKUP, respectively.

- -

X509_LOOKUP_ctrl_ex() is used to set or get additional data to or from a X509_LOOKUP structure using any control function in the associated X509_LOOKUP_METHOD(3). The arguments of the control command are passed via argc and argl, its return value via *ret. The library context libctx and property query propq are used when fetching algorithms from providers. The meaning of the arguments depends on the cmd number of the control command. In general, this function is not called directly, but wrapped by a macro call, see below. The control cmds known to OpenSSL are discussed in more depth in "Control Commands".

- -

X509_LOOKUP_ctrl() is similar to X509_LOOKUP_ctrl_ex() but uses NULL for the library context libctx and property query propq.

- -

X509_LOOKUP_load_file_ex() passes a filename to be loaded immediately into the associated X509_STORE. The library context libctx and property query propq are used when fetching algorithms from providers. type indicates what type of object is expected. This can only be used with a lookup using the implementation X509_LOOKUP_file(3).

- -

X509_LOOKUP_load_file() is similar to X509_LOOKUP_load_file_ex() but uses NULL for the library context libctx and property query propq.

- -

X509_LOOKUP_add_dir() passes a directory specification from which certificates and CRLs are loaded on demand into the associated X509_STORE. type indicates what type of object is expected. This can only be used with a lookup using the implementation X509_LOOKUP_hash_dir(3).

- -

X509_LOOKUP_add_store_ex() passes a URI for a directory-like structure from which containers with certificates and CRLs are loaded on demand into the associated X509_STORE. The library context libctx and property query propq are used when fetching algorithms from providers.

- -

X509_LOOKUP_add_store() is similar to X509_LOOKUP_add_store_ex() but uses NULL for the library context libctx and property query propq.

- -

X509_LOOKUP_load_store_ex() passes a URI for a single container from which certificates and CRLs are immediately loaded into the associated X509_STORE. The library context libctx and property query propq are used when fetching algorithms from providers. These functions can only be used with a lookup using the implementation X509_LOOKUP_store(3).

- -

X509_LOOKUP_load_store() is similar to X509_LOOKUP_load_store_ex() but uses NULL for the library context libctx and property query propq.

- -

X509_LOOKUP_load_file_ex(), X509_LOOKUP_load_file(), X509_LOOKUP_add_dir(), X509_LOOKUP_add_store_ex() X509_LOOKUP_add_store(), X509_LOOKUP_load_store_ex() and X509_LOOKUP_load_store() are implemented as macros that use X509_LOOKUP_ctrl().

- -

X509_LOOKUP_by_subject_ex(), X509_LOOKUP_by_subject(), X509_LOOKUP_by_issuer_serial(), X509_LOOKUP_by_fingerprint(), and X509_LOOKUP_by_alias() look up certificates and CRLs in the X509_STORE(3) associated with the X509_LOOKUP using different criteria, where the looked up object is stored in ret. Some of the underlying X509_LOOKUP_METHODs will also cache objects matching the criteria in the associated X509_STORE, which makes it possible to handle cases where the criteria have more than one hit.

- -

Control Commands

- -

The X509_LOOKUP_METHODs built into OpenSSL recognize the following X509_LOOKUP_ctrl() cmds:

- -
- -
X509_L_FILE_LOAD
-
- -

This is the command that X509_LOOKUP_load_file_ex() and X509_LOOKUP_load_file() use. The filename is passed in argc, and the type in argl.

- -
-
X509_L_ADD_DIR
-
- -

This is the command that X509_LOOKUP_add_dir() uses. The directory specification is passed in argc, and the type in argl.

- -
-
X509_L_ADD_STORE
-
- -

This is the command that X509_LOOKUP_add_store_ex() and X509_LOOKUP_add_store() use. The URI is passed in argc.

- -
-
X509_L_LOAD_STORE
-
- -

This is the command that X509_LOOKUP_load_store_ex() and X509_LOOKUP_load_store() use. The URI is passed in argc.

- -
-
- -

RETURN VALUES

- -

X509_LOOKUP_new() returns a X509_LOOKUP pointer when successful, or NULL on error.

- -

X509_LOOKUP_init() and X509_LOOKUP_shutdown() return 1 on success, or 0 on error.

- -

X509_LOOKUP_ctrl_ex() and X509_LOOKUP_ctrl() return -1 if the X509_LOOKUP doesn't have an associated X509_LOOKUP_METHOD, or 1 if the doesn't have a control function. Otherwise, it returns what the control function in the X509_LOOKUP_METHOD returns, which is usually 1 on success and 0 on error but could also be -1 on failure.

- -

X509_LOOKUP_get_store() returns a X509_STORE pointer if there is one, otherwise NULL.

- -

X509_LOOKUP_by_subject_ex() returns 0 if there is no X509_LOOKUP_METHOD that implements any of the get_by_subject_ex() or get_by_subject() functions. It calls get_by_subject_ex() if present, otherwise get_by_subject(), and returns the result of the function, which is usually 1 on success and 0 on error.

- -

X509_LOOKUP_by_subject() is similar to X509_LOOKUP_by_subject_ex() but passes NULL for both the libctx and propq.

- -

X509_LOOKUP_by_issuer_serial(), X509_LOOKUP_by_fingerprint(), and X509_LOOKUP_by_alias() all return 0 if there is no X509_LOOKUP_METHOD or that method doesn't implement the corresponding function. Otherwise, they return what the corresponding function in the X509_LOOKUP_METHOD returns, which is usually 1 on success and 0 in error.

- -

SEE ALSO

- -

X509_LOOKUP_METHOD(3), X509_STORE(3)

- -

HISTORY

- -

The functions X509_LOOKUP_by_subject_ex() and X509_LOOKUP_ctrl_ex() were added in OpenSSL 3.0.

- -

The macros X509_LOOKUP_load_file_ex(), X509_LOOKUP_load_store_ex() and 509_LOOKUP_add_store_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_hash_dir.html b/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_hash_dir.html deleted file mode 100644 index ccf87c49..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_hash_dir.html +++ /dev/null @@ -1,123 +0,0 @@ - - - - -X509_LOOKUP_hash_dir - - - - - - - - - - -

NAME

- -

X509_LOOKUP_hash_dir, X509_LOOKUP_file, X509_LOOKUP_store, X509_load_cert_file_ex, X509_load_cert_file, X509_load_crl_file, X509_load_cert_crl_file_ex, X509_load_cert_crl_file - Default OpenSSL certificate lookup methods

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-X509_LOOKUP_METHOD *X509_LOOKUP_hash_dir(void);
-X509_LOOKUP_METHOD *X509_LOOKUP_file(void);
-X509_LOOKUP_METHOD *X509_LOOKUP_store(void);
-
-int X509_load_cert_file_ex(X509_LOOKUP *ctx, const char *file, int type,
-                           OSSL_LIB_CTX *libctx, const char *propq);
-int X509_load_cert_file(X509_LOOKUP *ctx, const char *file, int type);
-int X509_load_crl_file(X509_LOOKUP *ctx, const char *file, int type);
-int X509_load_cert_crl_file_ex(X509_LOOKUP *ctx, const char *file, int type,
-                               OSSL_LIB_CTX *libctx, const char *propq);
-int X509_load_cert_crl_file(X509_LOOKUP *ctx, const char *file, int type);
- -

DESCRIPTION

- -

X509_LOOKUP_hash_dir and X509_LOOKUP_file are two certificate lookup methods to use with X509_STORE, provided by OpenSSL library.

- -

Users of the library typically do not need to create instances of these methods manually, they would be created automatically by X509_STORE_load_locations(3) or SSL_CTX_load_verify_locations(3) functions.

- -

Internally loading of certificates and CRLs is implemented via functions X509_load_cert_crl_file, X509_load_cert_file and X509_load_crl_file. These functions support parameter type, which can be one of constants FILETYPE_PEM, FILETYPE_ASN1 and FILETYPE_DEFAULT. They load certificates and/or CRLs from specified file into memory cache of X509_STORE objects which given ctx parameter is associated with.

- -

Functions X509_load_cert_file and X509_load_crl_file can load both PEM and DER formats depending of type value. Because DER format cannot contain more than one certificate or CRL object (while PEM can contain several concatenated PEM objects) X509_load_cert_crl_file with FILETYPE_ASN1 is equivalent to X509_load_cert_file.

- -

Constant FILETYPE_DEFAULT with NULL filename causes these functions to load default certificate store file (see X509_STORE_set_default_paths(3).

- -

Functions return number of objects loaded from file or 0 in case of error.

- -

Both methods support adding several certificate locations into one X509_STORE.

- -

This page documents certificate store formats used by these methods and caching policy.

- -

File Method

- -

The X509_LOOKUP_file method loads all the certificates or CRLs present in a file into memory at the time the file is added as a lookup source.

- -

File format is ASCII text which contains concatenated PEM certificates and CRLs.

- -

This method should be used by applications which work with a small set of CAs.

- -

Hashed Directory Method

- -

X509_LOOKUP_hash_dir is a more advanced method, which loads certificates and CRLs on demand, and caches them in memory once they are loaded. As of OpenSSL 1.0.0, it also checks for newer CRLs upon each lookup, so that newer CRLs are as soon as they appear in the directory.

- -

The directory should contain one certificate or CRL per file in PEM format, with a filename of the form hash.N for a certificate, or hash.rN for a CRL. The hash is the value returned by the X509_NAME_hash_ex(3) function applied to the subject name for certificates or issuer name for CRLs. The hash can also be obtained via the -hash option of the openssl-x509(1) or openssl-crl(1) commands.

- -

The .N or .rN suffix is a sequence number that starts at zero, and is incremented consecutively for each certificate or CRL with the same hash value. Gaps in the sequence numbers are not supported, it is assumed that there are no more objects with the same hash beyond the first missing number in the sequence.

- -

Sequence numbers make it possible for the directory to contain multiple certificates with same subject name hash value. For example, it is possible to have in the store several certificates with same subject or several CRLs with same issuer (and, for example, different validity period).

- -

When checking for new CRLs once one CRL for given hash value is loaded, hash_dir lookup method checks only for certificates with sequence number greater than that of the already cached CRL.

- -

Note that the hash algorithm used for subject name hashing changed in OpenSSL 1.0.0, and all certificate stores have to be rehashed when moving from OpenSSL 0.9.8 to 1.0.0.

- -

OpenSSL includes a openssl-rehash(1) utility which creates symlinks with hashed names for all files with .pem suffix in a given directory.

- -

OSSL_STORE Method

- -

X509_LOOKUP_store is a method that allows access to any store of certificates and CRLs through any loader supported by ossl_store(7). It works with the help of URIs, which can be direct references to certificates or CRLs, but can also be references to catalogues of such objects (that behave like directories).

- -

This method overlaps the "File Method" and "Hashed Directory Method" because of the 'file:' scheme loader. It does no caching of its own, but can use a caching ossl_store(7) loader, and therefore depends on the loader's capability.

- -

RETURN VALUES

- -

X509_LOOKUP_hash_dir(), X509_LOOKUP_file() and X509_LOOKUP_store() always return a valid X509_LOOKUP_METHOD structure.

- -

X509_load_cert_file(), X509_load_crl_file() and X509_load_cert_crl_file() return the number of loaded objects or 0 on error.

- -

SEE ALSO

- -

PEM_read_PrivateKey(3), X509_STORE_load_locations(3), SSL_CTX_load_verify_locations(3), X509_LOOKUP_meth_new(3), ossl_store(7)

- -

HISTORY

- -

The functions X509_load_cert_file_ex(), X509_load_cert_crl_file_ex() and X509_LOOKUP_store() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_meth_new.html b/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_meth_new.html deleted file mode 100644 index 64add8cd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_LOOKUP_meth_new.html +++ /dev/null @@ -1,158 +0,0 @@ - - - - -X509_LOOKUP_meth_new - - - - - - - - - - -

NAME

- -

X509_LOOKUP_METHOD, X509_LOOKUP_meth_new, X509_LOOKUP_meth_free, X509_LOOKUP_meth_set_new_item, X509_LOOKUP_meth_get_new_item, X509_LOOKUP_meth_set_free, X509_LOOKUP_meth_get_free, X509_LOOKUP_meth_set_init, X509_LOOKUP_meth_get_init, X509_LOOKUP_meth_set_shutdown, X509_LOOKUP_meth_get_shutdown, X509_LOOKUP_ctrl_fn, X509_LOOKUP_meth_set_ctrl, X509_LOOKUP_meth_get_ctrl, X509_LOOKUP_get_by_subject_fn, X509_LOOKUP_meth_set_get_by_subject, X509_LOOKUP_meth_get_get_by_subject, X509_LOOKUP_get_by_issuer_serial_fn, X509_LOOKUP_meth_set_get_by_issuer_serial, X509_LOOKUP_meth_get_get_by_issuer_serial, X509_LOOKUP_get_by_fingerprint_fn, X509_LOOKUP_meth_set_get_by_fingerprint, X509_LOOKUP_meth_get_get_by_fingerprint, X509_LOOKUP_get_by_alias_fn, X509_LOOKUP_meth_set_get_by_alias, X509_LOOKUP_meth_get_get_by_alias, X509_OBJECT_set1_X509, X509_OBJECT_set1_X509_CRL - Routines to build up X509_LOOKUP methods

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-typedef x509_lookup_method_st X509_LOOKUP_METHOD;
-
-X509_LOOKUP_METHOD *X509_LOOKUP_meth_new(const char *name);
-void X509_LOOKUP_meth_free(X509_LOOKUP_METHOD *method);
-
-int X509_LOOKUP_meth_set_new_item(X509_LOOKUP_METHOD *method,
-                                  int (*new_item) (X509_LOOKUP *ctx));
-int (*X509_LOOKUP_meth_get_new_item(const X509_LOOKUP_METHOD* method))
-    (X509_LOOKUP *ctx);
-
-int X509_LOOKUP_meth_set_free(X509_LOOKUP_METHOD *method,
-                              void (*free) (X509_LOOKUP *ctx));
-void (*X509_LOOKUP_meth_get_free(const X509_LOOKUP_METHOD* method))
-    (X509_LOOKUP *ctx);
-
-int X509_LOOKUP_meth_set_init(X509_LOOKUP_METHOD *method,
-                              int (*init) (X509_LOOKUP *ctx));
-int (*X509_LOOKUP_meth_get_init(const X509_LOOKUP_METHOD* method))
-    (X509_LOOKUP *ctx);
-
-int X509_LOOKUP_meth_set_shutdown(X509_LOOKUP_METHOD *method,
-                                  int (*shutdown) (X509_LOOKUP *ctx));
-int (*X509_LOOKUP_meth_get_shutdown(const X509_LOOKUP_METHOD* method))
-    (X509_LOOKUP *ctx);
-
-typedef int (*X509_LOOKUP_ctrl_fn)(X509_LOOKUP *ctx, int cmd, const char *argc,
-                                   long argl, char **ret);
-int X509_LOOKUP_meth_set_ctrl(X509_LOOKUP_METHOD *method,
-    X509_LOOKUP_ctrl_fn ctrl_fn);
-X509_LOOKUP_ctrl_fn X509_LOOKUP_meth_get_ctrl(const X509_LOOKUP_METHOD *method);
-
-typedef int (*X509_LOOKUP_get_by_subject_fn)(X509_LOOKUP *ctx,
-                                             X509_LOOKUP_TYPE type,
-                                             const X509_NAME *name,
-                                             X509_OBJECT *ret);
-int X509_LOOKUP_meth_set_get_by_subject(X509_LOOKUP_METHOD *method,
-    X509_LOOKUP_get_by_subject_fn fn);
-X509_LOOKUP_get_by_subject_fn X509_LOOKUP_meth_get_get_by_subject(
-    const X509_LOOKUP_METHOD *method);
-
-typedef int (*X509_LOOKUP_get_by_issuer_serial_fn)(X509_LOOKUP *ctx,
-                                                   X509_LOOKUP_TYPE type,
-                                                   const X509_NAME *name,
-                                                   const ASN1_INTEGER *serial,
-                                                   X509_OBJECT *ret);
-int X509_LOOKUP_meth_set_get_by_issuer_serial(
-    X509_LOOKUP_METHOD *method, X509_LOOKUP_get_by_issuer_serial_fn fn);
-X509_LOOKUP_get_by_issuer_serial_fn X509_LOOKUP_meth_get_get_by_issuer_serial(
-    const X509_LOOKUP_METHOD *method);
-
-typedef int (*X509_LOOKUP_get_by_fingerprint_fn)(X509_LOOKUP *ctx,
-                                                 X509_LOOKUP_TYPE type,
-                                                 const unsigned char* bytes,
-                                                 int len,
-                                                 X509_OBJECT *ret);
-int X509_LOOKUP_meth_set_get_by_fingerprint(X509_LOOKUP_METHOD *method,
-    X509_LOOKUP_get_by_fingerprint_fn fn);
-X509_LOOKUP_get_by_fingerprint_fn X509_LOOKUP_meth_get_get_by_fingerprint(
-    const X509_LOOKUP_METHOD *method);
-
-typedef int (*X509_LOOKUP_get_by_alias_fn)(X509_LOOKUP *ctx,
-                                           X509_LOOKUP_TYPE type,
-                                           const char *str,
-                                           int len,
-                                           X509_OBJECT *ret);
-int X509_LOOKUP_meth_set_get_by_alias(X509_LOOKUP_METHOD *method,
-    X509_LOOKUP_get_by_alias_fn fn);
-X509_LOOKUP_get_by_alias_fn X509_LOOKUP_meth_get_get_by_alias(
-    const X509_LOOKUP_METHOD *method);
-
-int X509_OBJECT_set1_X509(X509_OBJECT *a, X509 *obj);
-int X509_OBJECT_set1_X509_CRL(X509_OBJECT *a, X509_CRL *obj);
- -

DESCRIPTION

- -

The X509_LOOKUP_METHOD type is a structure used for the implementation of new X509_LOOKUP types. It provides a set of functions used by OpenSSL for the implementation of various X509 and X509_CRL lookup capabilities. One instance of an X509_LOOKUP_METHOD can be associated to many instantiations of an X509_LOOKUP structure.

- -

X509_LOOKUP_meth_new() creates a new X509_LOOKUP_METHOD structure. It should be given a human-readable string containing a brief description of the lookup method.

- -

X509_LOOKUP_meth_free() destroys a X509_LOOKUP_METHOD structure. If the argument is NULL, nothing is done.

- -

X509_LOOKUP_get_new_item() and X509_LOOKUP_set_new_item() get and set the function that is called when an X509_LOOKUP object is created with X509_LOOKUP_new(). If an X509_LOOKUP_METHOD requires any per-X509_LOOKUP specific data, the supplied new_item function should allocate this data and invoke X509_LOOKUP_set_method_data(3).

- -

X509_LOOKUP_get_free() and X509_LOOKUP_set_free() get and set the function that is used to free any method data that was allocated and set from within new_item function.

- -

X509_LOOKUP_meth_get_init() and X509_LOOKUP_meth_set_init() get and set the function that is used to initialize the method data that was set with X509_LOOKUP_set_method_data(3) as part of the new_item routine.

- -

X509_LOOKUP_meth_get_shutdown() and X509_LOOKUP_meth_set_shutdown() get and set the function that is used to shut down the method data whose state was previously initialized in the init function.

- -

X509_LOOKUP_meth_get_ctrl() and X509_LOOKUP_meth_set_ctrl() get and set a function to be used to handle arbitrary control commands issued by X509_LOOKUP_ctrl(). The control function is given the X509_LOOKUP ctx, along with the arguments passed by X509_LOOKUP_ctrl. cmd is an arbitrary integer that defines some operation. argc is a pointer to an array of characters. argl is an integer. ret, if set, points to a location where any return data should be written to. How argc and argl are used depends entirely on the control function.

- -

X509_LOOKUP_set_get_by_subject(), X509_LOOKUP_set_get_by_issuer_serial(), X509_LOOKUP_set_get_by_fingerprint(), X509_LOOKUP_set_get_by_alias() set the functions used to retrieve an X509 or X509_CRL object by the object's subject, issuer, fingerprint, and alias respectively. These functions are given the X509_LOOKUP context, the type of the X509_OBJECT being requested, parameters related to the lookup, and an X509_OBJECT that will receive the requested object.

- -

Implementations must add objects they find to the X509_STORE object using X509_STORE_add_cert() or X509_STORE_add_crl(). This increments its reference count. However, the X509_STORE_CTX_get_by_subject(3) function also increases the reference count which leads to one too many references being held. Therefore, applications should additionally call X509_free() or X509_CRL_free() to decrement the reference count again.

- -

Implementations should also use either X509_OBJECT_set1_X509() or X509_OBJECT_set1_X509_CRL() to set the result. Note that this also increments the result's reference count.

- -

Any method data that was created as a result of the new_item function set by X509_LOOKUP_meth_set_new_item() can be accessed with X509_LOOKUP_get_method_data(3). The X509_STORE object that owns the X509_LOOKUP may be accessed with X509_LOOKUP_get_store(3). Successful lookups should return 1, and unsuccessful lookups should return 0.

- -

X509_LOOKUP_get_get_by_subject(), X509_LOOKUP_get_get_by_issuer_serial(), X509_LOOKUP_get_get_by_fingerprint(), X509_LOOKUP_get_get_by_alias() retrieve the function set by the corresponding setter.

- -

RETURN VALUES

- -

The X509_LOOKUP_meth_set functions return 1 on success or 0 on error.

- -

The X509_LOOKUP_meth_get functions return the corresponding function pointers.

- -

SEE ALSO

- -

X509_STORE_CTX_get_by_subject(3), X509_STORE_new(3), SSL_CTX_set_cert_store(3)

- -

HISTORY

- -

The functions described here were added in OpenSSL 1.1.0i.

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_NAME_ENTRY_get_object.html b/openssl-install/share/doc/openssl/html/man3/X509_NAME_ENTRY_get_object.html deleted file mode 100644 index 84a81378..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_NAME_ENTRY_get_object.html +++ /dev/null @@ -1,94 +0,0 @@ - - - - -X509_NAME_ENTRY_get_object - - - - - - - - - - -

NAME

- -

X509_NAME_ENTRY_get_object, X509_NAME_ENTRY_get_data, X509_NAME_ENTRY_set_object, X509_NAME_ENTRY_set_data, X509_NAME_ENTRY_create_by_txt, X509_NAME_ENTRY_create_by_NID, X509_NAME_ENTRY_create_by_OBJ - X509_NAME_ENTRY utility functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne);
-ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne);
-
-int X509_NAME_ENTRY_set_object(X509_NAME_ENTRY *ne, const ASN1_OBJECT *obj);
-int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type,
-                             const unsigned char *bytes, int len);
-
-X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_txt(X509_NAME_ENTRY **ne, const char *field,
-                                               int type, const unsigned char *bytes,
-                                               int len);
-X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_NID(X509_NAME_ENTRY **ne, int nid,
-                                               int type, const unsigned char *bytes,
-                                               int len);
-X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_OBJ(X509_NAME_ENTRY **ne,
-                                               const ASN1_OBJECT *obj, int type,
-                                               const unsigned char *bytes, int len);
- -

DESCRIPTION

- -

X509_NAME_ENTRY_get_object() retrieves the field name of ne in and ASN1_OBJECT structure.

- -

X509_NAME_ENTRY_get_data() retrieves the field value of ne in and ASN1_STRING structure.

- -

X509_NAME_ENTRY_set_object() sets the field name of ne to obj.

- -

X509_NAME_ENTRY_set_data() sets the field value of ne to string type type and value determined by bytes and len.

- -

X509_NAME_ENTRY_create_by_txt(), X509_NAME_ENTRY_create_by_NID() and X509_NAME_ENTRY_create_by_OBJ() create and return an X509_NAME_ENTRY structure.

- -

NOTES

- -

X509_NAME_ENTRY_get_object() and X509_NAME_ENTRY_get_data() can be used to examine an X509_NAME_ENTRY function as returned by X509_NAME_get_entry() for example.

- -

X509_NAME_ENTRY_create_by_txt(), X509_NAME_ENTRY_create_by_OBJ(), X509_NAME_ENTRY_create_by_NID() and X509_NAME_ENTRY_set_data() are seldom used in practice because X509_NAME_ENTRY structures are almost always part of X509_NAME structures and the corresponding X509_NAME functions are typically used to create and add new entries in a single operation.

- -

The arguments of these functions support similar options to the similarly named ones of the corresponding X509_NAME functions such as X509_NAME_add_entry_by_txt(). So for example type can be set to MBSTRING_ASC but in the case of X509_set_data() the field name must be set first so the relevant field information can be looked up internally.

- -

RETURN VALUES

- -

X509_NAME_ENTRY_get_object() returns a valid ASN1_OBJECT structure if it is set or NULL if an error occurred.

- -

X509_NAME_ENTRY_get_data() returns a valid ASN1_STRING structure if it is set or NULL if an error occurred.

- -

X509_NAME_ENTRY_set_object() and X509_NAME_ENTRY_set_data() return 1 on success or 0 on error.

- -

X509_NAME_ENTRY_create_by_txt(), X509_NAME_ENTRY_create_by_NID() and X509_NAME_ENTRY_create_by_OBJ() return a valid X509_NAME_ENTRY on success or NULL if an error occurred.

- -

SEE ALSO

- -

ERR_get_error(3), d2i_X509_NAME(3), OBJ_nid2obj(3)

- -

COPYRIGHT

- -

Copyright 2002-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_NAME_add_entry_by_txt.html b/openssl-install/share/doc/openssl/html/man3/X509_NAME_add_entry_by_txt.html deleted file mode 100644 index 60316845..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_NAME_add_entry_by_txt.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -X509_NAME_add_entry_by_txt - - - - - - - - - - -

NAME

- -

X509_NAME_add_entry_by_txt, X509_NAME_add_entry_by_OBJ, X509_NAME_add_entry_by_NID, X509_NAME_add_entry, X509_NAME_delete_entry - X509_NAME modification functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_NAME_add_entry_by_txt(X509_NAME *name, const char *field, int type,
-                               const unsigned char *bytes, int len, int loc, int set);
-
-int X509_NAME_add_entry_by_OBJ(X509_NAME *name, const ASN1_OBJECT *obj, int type,
-                               const unsigned char *bytes, int len, int loc, int set);
-
-int X509_NAME_add_entry_by_NID(X509_NAME *name, int nid, int type,
-                               const unsigned char *bytes, int len, int loc, int set);
-
-int X509_NAME_add_entry(X509_NAME *name, const X509_NAME_ENTRY *ne, int loc, int set);
-
-X509_NAME_ENTRY *X509_NAME_delete_entry(X509_NAME *name, int loc);
- -

DESCRIPTION

- -

X509_NAME_add_entry_by_txt(), X509_NAME_add_entry_by_OBJ() and X509_NAME_add_entry_by_NID() add a field whose name is defined by a string field, an object obj or a NID nid respectively. The field value to be added is in bytes of length len. If len is -1 then the field length is calculated internally using strlen(bytes).

- -

The type of field is determined by type which can either be a definition of the type of bytes (such as MBSTRING_ASC) or a standard ASN1 type (such as V_ASN1_IA5STRING). The new entry is added to a position determined by loc and set.

- -

X509_NAME_add_entry() adds a copy of X509_NAME_ENTRY structure ne to name. The new entry is added to a position determined by loc and set. Since a copy of ne is added ne must be freed up after the call.

- -

X509_NAME_delete_entry() deletes an entry from name at position loc. The deleted entry is returned and must be freed up.

- -

NOTES

- -

The use of string types such as MBSTRING_ASC or MBSTRING_UTF8 is strongly recommended for the type parameter. This allows the internal code to correctly determine the type of the field and to apply length checks according to the relevant standards. This is done using ASN1_STRING_set_by_NID().

- -

If instead an ASN1 type is used no checks are performed and the supplied data in bytes is used directly.

- -

In X509_NAME_add_entry_by_txt() the field string represents the field name using OBJ_txt2obj(field, 0).

- -

The loc and set parameters determine where a new entry should be added. For almost all applications loc can be set to -1 and set to 0. This adds a new entry to the end of name as a single valued RelativeDistinguishedName (RDN).

- -

loc actually determines the index where the new entry is inserted: if it is -1 it is appended.

- -

set determines how the new type is added. If it is zero a new RDN is created.

- -

If set is -1 or 1 it is added as a new set member to the previous or next RDN structure, respectively. This will then become part of a multi-valued RDN (containing a set of AVAs). Since multi-valued RDNs are very rarely used set typically will be zero.

- -

RETURN VALUES

- -

X509_NAME_add_entry_by_txt(), X509_NAME_add_entry_by_OBJ(), X509_NAME_add_entry_by_NID() and X509_NAME_add_entry() return 1 for success of 0 if an error occurred.

- -

X509_NAME_delete_entry() returns either the deleted X509_NAME_ENTRY structure or NULL if an error occurred.

- -

EXAMPLES

- -

Create an X509_NAME structure:

- -

"C=UK, O=Disorganized Organization, CN=Joe Bloggs"

- -
X509_NAME *nm;
-
-nm = X509_NAME_new();
-if (nm == NULL)
-    /* Some error */
-if (!X509_NAME_add_entry_by_txt(nm, "C", MBSTRING_ASC,
-                                "UK", -1, -1, 0))
-    /* Error */
-if (!X509_NAME_add_entry_by_txt(nm, "O", MBSTRING_ASC,
-                                "Disorganized Organization", -1, -1, 0))
-    /* Error */
-if (!X509_NAME_add_entry_by_txt(nm, "CN", MBSTRING_ASC,
-                                "Joe Bloggs", -1, -1, 0))
-    /* Error */
- -

BUGS

- -

type can still be set to V_ASN1_APP_CHOOSE to use a different algorithm to determine field types. Since this form does not understand multicharacter types, performs no length checks and can result in invalid field types its use is strongly discouraged.

- -

SEE ALSO

- -

ERR_get_error(3), d2i_X509_NAME(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_NAME_get0_der.html b/openssl-install/share/doc/openssl/html/man3/X509_NAME_get0_der.html deleted file mode 100644 index 0a569daf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_NAME_get0_der.html +++ /dev/null @@ -1,57 +0,0 @@ - - - - -X509_NAME_get0_der - - - - - - - - - - -

NAME

- -

X509_NAME_get0_der - get X509_NAME DER encoding

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_NAME_get0_der(const X509_NAME *nm, const unsigned char **pder,
-                       size_t *pderlen);
- -

DESCRIPTION

- -

The function X509_NAME_get0_der() returns an internal pointer to the encoding of an X509_NAME structure in *pder and consisting of *pderlen bytes. It is useful for applications that wish to examine the encoding of an X509_NAME structure without copying it.

- -

RETURN VALUES

- -

The function X509_NAME_get0_der() returns 1 for success and 0 if an error occurred.

- -

SEE ALSO

- -

d2i_X509(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_NAME_get_index_by_NID.html b/openssl-install/share/doc/openssl/html/man3/X509_NAME_get_index_by_NID.html deleted file mode 100644 index 5038f7af..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_NAME_get_index_by_NID.html +++ /dev/null @@ -1,115 +0,0 @@ - - - - -X509_NAME_get_index_by_NID - - - - - - - - - - -

NAME

- -

X509_NAME_get_index_by_NID, X509_NAME_get_index_by_OBJ, X509_NAME_get_entry, X509_NAME_entry_count, X509_NAME_get_text_by_NID, X509_NAME_get_text_by_OBJ - X509_NAME lookup and enumeration functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_NAME_get_index_by_NID(const X509_NAME *name, int nid, int lastpos);
-int X509_NAME_get_index_by_OBJ(const X509_NAME *name,
-                               const ASN1_OBJECT *obj, int lastpos);
-
-int X509_NAME_entry_count(const X509_NAME *name);
-X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc);
-
-int X509_NAME_get_text_by_NID(const X509_NAME *name, int nid,
-                              char *buf, int len);
-int X509_NAME_get_text_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj,
-                              char *buf, int len);
- -

DESCRIPTION

- -

These functions allow an X509_NAME structure to be examined. The X509_NAME structure is the same as the Name type defined in RFC2459 (and elsewhere) and used for example in certificate subject and issuer names.

- -

X509_NAME_get_index_by_NID() and X509_NAME_get_index_by_OBJ() retrieve the next index matching nid or obj after lastpos. lastpos should initially be set to -1. If there are no more entries -1 is returned. If nid is invalid (doesn't correspond to a valid OID) then -2 is returned.

- -

X509_NAME_entry_count() returns the total number of entries in name.

- -

X509_NAME_get_entry() retrieves the X509_NAME_ENTRY from name corresponding to index loc. Acceptable values for loc run from 0 to (X509_NAME_entry_count(name) - 1). The value returned is an internal pointer which must not be freed.

- -

X509_NAME_get_text_by_NID(), X509_NAME_get_text_by_OBJ() retrieve the "text" from the first entry in name which matches nid or obj, if no such entry exists -1 is returned. At most len bytes will be written and the text written to buf will be null terminated. The length of the output string written is returned excluding the terminating null. If buf is <NULL> then the amount of space needed in buf (excluding the final null) is returned.

- -

NOTES

- -

X509_NAME_get_text_by_NID() and X509_NAME_get_text_by_OBJ() should be considered deprecated because they have various limitations which make them of minimal use in practice. They can only find the first matching entry and will copy the contents of the field verbatim: this can be highly confusing if the target is a multicharacter string type like a BMPString or a UTF8String.

- -

For a more general solution X509_NAME_get_index_by_NID() or X509_NAME_get_index_by_OBJ() should be used followed by X509_NAME_get_entry() on any matching indices and then the various X509_NAME_ENTRY utility functions on the result.

- -

The list of all relevant NID_* and OBJ_* codes can be found in the source code header files <openssl/obj_mac.h> and/or <openssl/objects.h>.

- -

Applications which could pass invalid NIDs to X509_NAME_get_index_by_NID() should check for the return value of -2. Alternatively the NID validity can be determined first by checking OBJ_nid2obj(nid) is not NULL.

- -

RETURN VALUES

- -

X509_NAME_get_index_by_NID() and X509_NAME_get_index_by_OBJ() return the index of the next matching entry or -1 if not found. X509_NAME_get_index_by_NID() can also return -2 if the supplied NID is invalid.

- -

X509_NAME_entry_count() returns the total number of entries, and 0 for failure.

- -

X509_NAME_get_entry() returns an X509_NAME pointer to the requested entry or NULL if the index is invalid.

- -

EXAMPLES

- -

Process all entries:

- -
int i;
-X509_NAME_ENTRY *e;
-
-for (i = 0; i < X509_NAME_entry_count(nm); i++) {
-    e = X509_NAME_get_entry(nm, i);
-    /* Do something with e */
-}
- -

Process all commonName entries:

- -
int lastpos = -1;
-X509_NAME_ENTRY *e;
-
-for (;;) {
-    lastpos = X509_NAME_get_index_by_NID(nm, NID_commonName, lastpos);
-    if (lastpos == -1)
-        break;
-    e = X509_NAME_get_entry(nm, lastpos);
-    /* Do something with e */
-}
- -

SEE ALSO

- -

ERR_get_error(3), d2i_X509_NAME(3)

- -

COPYRIGHT

- -

Copyright 2002-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_NAME_print_ex.html b/openssl-install/share/doc/openssl/html/man3/X509_NAME_print_ex.html deleted file mode 100644 index e0d8535b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_NAME_print_ex.html +++ /dev/null @@ -1,108 +0,0 @@ - - - - -X509_NAME_print_ex - - - - - - - - - - -

NAME

- -

X509_NAME_print_ex, X509_NAME_print_ex_fp, X509_NAME_print, X509_NAME_oneline - X509_NAME printing routines

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_NAME_print_ex(BIO *out, const X509_NAME *nm,
-                       int indent, unsigned long flags);
-int X509_NAME_print_ex_fp(FILE *fp, const X509_NAME *nm,
-                          int indent, unsigned long flags);
-char *X509_NAME_oneline(const X509_NAME *a, char *buf, int size);
-int X509_NAME_print(BIO *bp, const X509_NAME *name, int obase);
- -

DESCRIPTION

- -

X509_NAME_print_ex() prints a human readable version of nm to BIO out. Each line (for multiline formats) is indented by indent spaces. The output format can be extensively customised by use of the flags parameter.

- -

X509_NAME_print_ex_fp() is identical to X509_NAME_print_ex() except the output is written to FILE pointer fp.

- -

X509_NAME_oneline() prints an ASCII version of a to buf. This supports multi-valued RDNs and escapes / and + characters in values. If buf is NULL then a buffer is dynamically allocated and returned, and size is ignored. Otherwise, at most size bytes will be written, including the ending '\0', and buf is returned.

- -

X509_NAME_print() prints out name to bp indenting each line by obase characters. Multiple lines are used if the output (including indent) exceeds 80 characters.

- -

NOTES

- -

The functions X509_NAME_oneline() and X509_NAME_print() produce a non standard output form, they don't handle multi-character fields and have various quirks and inconsistencies. Their use is strongly discouraged in new applications and they could be deprecated in a future release.

- -

Although there are a large number of possible flags for most purposes XN_FLAG_ONELINE, XN_FLAG_MULTILINE or XN_FLAG_RFC2253 will suffice. As noted on the ASN1_STRING_print_ex(3) manual page for UTF8 terminals the ASN1_STRFLGS_ESC_MSB should be unset: so for example XN_FLAG_ONELINE & ~ASN1_STRFLGS_ESC_MSB would be used.

- -

The complete set of the flags supported by X509_NAME_print_ex() is listed below.

- -

Several options can be ored together.

- -

The options XN_FLAG_SEP_COMMA_PLUS, XN_FLAG_SEP_CPLUS_SPC, XN_FLAG_SEP_SPLUS_SPC and XN_FLAG_SEP_MULTILINE determine the field separators to use. Two distinct separators are used between distinct RelativeDistinguishedName components and separate values in the same RDN for a multi-valued RDN. Multi-valued RDNs are currently very rare so the second separator will hardly ever be used.

- -

XN_FLAG_SEP_COMMA_PLUS uses comma and plus as separators. XN_FLAG_SEP_CPLUS_SPC uses comma and plus with spaces: this is more readable that plain comma and plus. XN_FLAG_SEP_SPLUS_SPC uses spaced semicolon and plus. XN_FLAG_SEP_MULTILINE uses spaced newline and plus respectively.

- -

If XN_FLAG_DN_REV is set the whole DN is printed in reversed order.

- -

The fields XN_FLAG_FN_SN, XN_FLAG_FN_LN, XN_FLAG_FN_OID, XN_FLAG_FN_NONE determine how a field name is displayed. It will use the short name (e.g. CN) the long name (e.g. commonName) always use OID numerical form (normally OIDs are only used if the field name is not recognised) and no field name respectively.

- -

If XN_FLAG_SPC_EQ is set then spaces will be placed around the '=' character separating field names and values.

- -

If XN_FLAG_DUMP_UNKNOWN_FIELDS is set then the encoding of unknown fields is printed instead of the values.

- -

If XN_FLAG_FN_ALIGN is set then field names are padded to 20 characters: this is only of use for multiline format.

- -

Additionally all the options supported by ASN1_STRING_print_ex() can be used to control how each field value is displayed.

- -

In addition a number options can be set for commonly used formats.

- -

XN_FLAG_RFC2253 sets options which produce an output compatible with RFC2253. It is equivalent to: ASN1_STRFLGS_RFC2253 | XN_FLAG_SEP_COMMA_PLUS | XN_FLAG_DN_REV | XN_FLAG_FN_SN | XN_FLAG_DUMP_UNKNOWN_FIELDS

- -

XN_FLAG_ONELINE is a more readable one line format which is the same as: ASN1_STRFLGS_RFC2253 | ASN1_STRFLGS_ESC_QUOTE | XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_SPC_EQ | XN_FLAG_FN_SN

- -

XN_FLAG_MULTILINE is a multiline format which is the same as: ASN1_STRFLGS_ESC_CTRL | ASN1_STRFLGS_ESC_MSB | XN_FLAG_SEP_MULTILINE | XN_FLAG_SPC_EQ | XN_FLAG_FN_LN | XN_FLAG_FN_ALIGN

- -

XN_FLAG_COMPAT uses a format identical to X509_NAME_print(): in fact it calls X509_NAME_print() internally.

- -

RETURN VALUES

- -

X509_NAME_oneline() returns a valid string on success or NULL on error.

- -

X509_NAME_print() returns 1 on success or 0 on error.

- -

X509_NAME_print_ex() and X509_NAME_print_ex_fp() return 1 on success or 0 on error if the XN_FLAG_COMPAT is set, which is the same as X509_NAME_print(). Otherwise, it returns -1 on error or other values on success.

- -

SEE ALSO

- -

ASN1_STRING_print_ex(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_PUBKEY_new.html b/openssl-install/share/doc/openssl/html/man3/X509_PUBKEY_new.html deleted file mode 100644 index eea464d6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_PUBKEY_new.html +++ /dev/null @@ -1,147 +0,0 @@ - - - - -X509_PUBKEY_new - - - - - - - - - - -

NAME

- -

X509_PUBKEY_new_ex, X509_PUBKEY_new, X509_PUBKEY_free, X509_PUBKEY_dup, X509_PUBKEY_set, X509_PUBKEY_get0, X509_PUBKEY_get, d2i_PUBKEY_ex, d2i_PUBKEY, i2d_PUBKEY, d2i_PUBKEY_ex_bio, d2i_PUBKEY_bio, d2i_PUBKEY_ex_fp, d2i_PUBKEY_fp, i2d_PUBKEY_fp, i2d_PUBKEY_bio, X509_PUBKEY_set0_public_key, X509_PUBKEY_set0_param, X509_PUBKEY_get0_param, X509_PUBKEY_eq - SubjectPublicKeyInfo public key functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-X509_PUBKEY *X509_PUBKEY_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
-X509_PUBKEY *X509_PUBKEY_new(void);
-void X509_PUBKEY_free(X509_PUBKEY *a);
-X509_PUBKEY *X509_PUBKEY_dup(const X509_PUBKEY *a);
-
-int X509_PUBKEY_set(X509_PUBKEY **x, EVP_PKEY *pkey);
-EVP_PKEY *X509_PUBKEY_get0(const X509_PUBKEY *key);
-EVP_PKEY *X509_PUBKEY_get(const X509_PUBKEY *key);
-
-EVP_PKEY *d2i_PUBKEY_ex(EVP_PKEY **a, const unsigned char **pp, long length,
-                        OSSL_LIB_CTX *libctx, const char *propq);
-EVP_PKEY *d2i_PUBKEY(EVP_PKEY **a, const unsigned char **pp, long length);
-int i2d_PUBKEY(const EVP_PKEY *a, unsigned char **pp);
-
-EVP_PKEY *d2i_PUBKEY_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
-                            const char *propq);
-EVP_PKEY *d2i_PUBKEY_bio(BIO *bp, EVP_PKEY **a);
-
-EVP_PKEY *d2i_PUBKEY_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
-                           const char *propq);
-EVP_PKEY *d2i_PUBKEY_fp(FILE *fp, EVP_PKEY **a);
-
-int i2d_PUBKEY_fp(const FILE *fp, EVP_PKEY *pkey);
-int i2d_PUBKEY_bio(BIO *bp, const EVP_PKEY *pkey);
-
-void X509_PUBKEY_set0_public_key(X509_PUBKEY *pub,
-                                 unsigned char *penc, int penclen);
-int X509_PUBKEY_set0_param(X509_PUBKEY *pub, ASN1_OBJECT *aobj,
-                           int ptype, void *pval,
-                           unsigned char *penc, int penclen);
-int X509_PUBKEY_get0_param(ASN1_OBJECT **ppkalg,
-                           const unsigned char **pk, int *ppklen,
-                           X509_ALGOR **pa, const X509_PUBKEY *pub);
-int X509_PUBKEY_eq(X509_PUBKEY *a, X509_PUBKEY *b);
- -

DESCRIPTION

- -

The X509_PUBKEY structure represents the ASN.1 SubjectPublicKeyInfo structure defined in RFC5280 and used in certificates and certificate requests.

- -

X509_PUBKEY_new_ex() allocates and initializes an X509_PUBKEY structure associated with the given OSSL_LIB_CTX in the libctx parameter. Any algorithm fetches associated with using the X509_PUBKEY object will use the property query string propq. See "ALGORITHM FETCHING" in crypto(7) for further information about algorithm fetching.

- -

X509_PUBKEY_new() is the same as X509_PUBKEY_new_ex() except that the default (NULL) OSSL_LIB_CTX and a NULL property query string are used.

- -

X509_PUBKEY_dup() creates a duplicate copy of the X509_PUBKEY object specified by a.

- -

X509_PUBKEY_free() frees up X509_PUBKEY structure a. If a is NULL nothing is done.

- -

X509_PUBKEY_set() sets the public key in *x to the public key contained in the EVP_PKEY structure pkey. If *x is not NULL any existing public key structure will be freed.

- -

X509_PUBKEY_get0() returns the public key contained in key. The returned value is an internal pointer which MUST NOT be freed after use.

- -

X509_PUBKEY_get() is similar to X509_PUBKEY_get0() except the reference count on the returned key is incremented so it MUST be freed using EVP_PKEY_free() after use.

- -

d2i_PUBKEY_ex() decodes an EVP_PKEY structure using SubjectPublicKeyInfo format. Some public key decoding implementations may use cryptographic algorithms. In this case the supplied library context libctx and property query string propq are used. d2i_PUBKEY() does the same as d2i_PUBKEY_ex() except that the default library context and property query string are used.

- -

i2d_PUBKEY() encodes an EVP_PKEY structure using SubjectPublicKeyInfo format.

- -

d2i_PUBKEY_bio(), d2i_PUBKEY_fp(), i2d_PUBKEY_bio() and i2d_PUBKEY_fp() are similar to d2i_PUBKEY() and i2d_PUBKEY() except they decode or encode using a BIO or FILE pointer.

- -

d2i_PUBKEY_ex_bio() and d2i_PUBKEY_ex_fp() are similar to d2i_PUBKEY_ex() except they decode using a BIO or FILE pointer.

- -

X509_PUBKEY_set0_public_key() sets the public-key encoding of pub to the penclen bytes contained in buffer penc. Any earlier public-key encoding in pub is freed. penc may be NULL to indicate that there is no actual public key data. Ownership of the penc argument is passed to pub.

- -

X509_PUBKEY_set0_param() sets the public-key parameters of pub. The OID associated with the algorithm is set to aobj. The type of the algorithm parameters is set to type using the structure pval. If penc is not NULL the encoding of the public key itself is set to the penclen bytes contained in buffer penc and any earlier public-key encoding in pub is freed. On success ownership of all the supplied arguments is passed to pub so they must not be freed after the call.

- -

X509_PUBKEY_get0_param() retrieves the public key parameters from pub, *ppkalg is set to the associated OID and the encoding consists of *ppklen bytes at *pk, *pa is set to the associated AlgorithmIdentifier for the public key. If the value of any of these parameters is not required it can be set to NULL. All of the retrieved pointers are internal and must not be freed after the call.

- -

X509_PUBKEY_eq() compares two X509_PUBKEY values.

- -

NOTES

- -

The X509_PUBKEY functions can be used to encode and decode public keys in a standard format.

- -

In many cases applications will not call the X509_PUBKEY functions directly: they will instead call wrapper functions such as X509_get0_pubkey().

- -

RETURN VALUES

- -

If the allocation fails, X509_PUBKEY_new() and X509_PUBKEY_dup() return NULL and set an error code that can be obtained by ERR_get_error(3). Otherwise they return a pointer to the newly allocated structure.

- -

X509_PUBKEY_free() does not return a value.

- -

X509_PUBKEY_get0(), X509_PUBKEY_get(), d2i_PUBKEY_ex(), d2i_PUBKEY(), d2i_PUBKEY_ex_bio(), d2i_PUBKEY_bio(), d2i_PUBKEY_ex_fp() and d2i_PUBKEY_fp() return a pointer to an EVP_PKEY structure or NULL if an error occurs.

- -

i2d_PUBKEY() returns the number of bytes successfully encoded or a negative value if an error occurs.

- -

i2d_PUBKEY_fp() and i2d_PUBKEY_bio() return 1 if successfully encoded or 0 if an error occurs.

- -

X509_PUBKEY_set0_public_key() does not return a value.

- -

X509_PUBKEY_set(), X509_PUBKEY_set0_param() and X509_PUBKEY_get0_param() return 1 for success and 0 if an error occurred.

- -

X509_PUBKEY_eq() returns 1 for equal, 0 for different, and < 0 on error.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_get_pubkey(3),

- -

HISTORY

- -

The X509_PUBKEY_new_ex() and X509_PUBKEY_eq() functions were added in OpenSSL 3.0.

- -

The X509_PUBKEY_set0_public_key(), d2i_PUBKEY_ex_bio() and d2i_PUBKEY_ex_fp() functions were added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_REQ_get_attr.html b/openssl-install/share/doc/openssl/html/man3/X509_REQ_get_attr.html deleted file mode 100644 index a45d62cd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_REQ_get_attr.html +++ /dev/null @@ -1,102 +0,0 @@ - - - - -X509_REQ_get_attr - - - - - - - - - - -

NAME

- -

X509_REQ_get_attr_count, X509_REQ_get_attr_by_NID, X509_REQ_get_attr_by_OBJ, X509_REQ_get_attr, X509_REQ_delete_attr, X509_REQ_add1_attr, X509_REQ_add1_attr_by_OBJ, X509_REQ_add1_attr_by_NID, X509_REQ_add1_attr_by_txt - X509_ATTRIBUTE support for signed certificate requests

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_REQ_get_attr_count(const X509_REQ *req);
-int X509_REQ_get_attr_by_NID(const X509_REQ *req, int nid, int lastpos);
-int X509_REQ_get_attr_by_OBJ(const X509_REQ *req, const ASN1_OBJECT *obj,
-                             int lastpos);
-X509_ATTRIBUTE *X509_REQ_get_attr(const X509_REQ *req, int loc);
-X509_ATTRIBUTE *X509_REQ_delete_attr(X509_REQ *req, int loc);
-int X509_REQ_add1_attr(X509_REQ *req, X509_ATTRIBUTE *attr);
-int X509_REQ_add1_attr_by_OBJ(X509_REQ *req,
-                              const ASN1_OBJECT *obj, int type,
-                              const unsigned char *bytes, int len);
-int X509_REQ_add1_attr_by_NID(X509_REQ *req,
-                              int nid, int type,
-                              const unsigned char *bytes, int len);
-int X509_REQ_add1_attr_by_txt(X509_REQ *req,
-                              const char *attrname, int type,
-                              const unsigned char *bytes, int len);
- -

DESCRIPTION

- -

X509_REQ_get_attr_by_OBJ() finds the location of the first matching object obj in the req attribute list. The search starts at the position after lastpos. If the returned value is positive then it can be used on the next call to X509_REQ_get_attr_by_OBJ() as the value of lastpos in order to iterate through the remaining attributes. lastpos can be set to any negative value on the first call, in order to start searching from the start of the attribute list.

- -

X509_REQ_get_attr_by_NID() is similar to X509_REQ_get_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

X509_REQ_get_attr() returns the X509_ATTRIBUTE object at index loc in the req attribute list. loc should be in the range from 0 to X509_REQ_get_attr_count() - 1.

- -

X509_REQ_delete_attr() removes the X509_ATTRIBUTE object at index loc in the req objects list of attributes. An error occurs if req is NULL.

- -

X509_REQ_add1_attr() pushes a copy of the passed in X509_ATTRIBUTE attr> to the req object's attribute list. An error will occur if either the attribute list is NULL or the attribute already exists.

- -

X509_REQ_add1_attr_by_OBJ() creates a new X509_ATTRIBUTE using X509_ATTRIBUTE_set1_object() and X509_ATTRIBUTE_set1_data() to assign a new obj with type type and data bytes of length len and then pushes it to the req object's attribute list. req must be non NULL or an error will occur. If obj already exists in the attribute list then an error occurs.

- -

X509_REQ_add1_attr_by_NID() is similar to X509_REQ_add1_attr_by_OBJ() except that it passes the numerical identifier (NID) nid associated with the object. See <openssl/obj_mac.h> for a list of NID_*.

- -

X509_REQ_add1_attr_by_txt() is similar to X509_REQ_add1_attr_by_OBJ() except that it passes a name attrname associated with the object. See <openssl/obj_mac.h> for a list of SN_* names.

- -

Refer to X509_ATTRIBUTE(3) for information related to attributes.

- -

RETURN VALUES

- -

X509_REQ_get_attr_count() returns the number of attributes in the req object attribute list or -1 if the attribute list is NULL.

- -

X509_REQ_get_attr_by_OBJ() returns -1 if either the req object's attribute list is empty OR obj is not found, otherwise it returns the location of the obj in the attribute list.

- -

X509_REQ_get_attr_by_NID() is similar to X509_REQ_get_attr_by_OBJ(), except that it returns -2 if the nid is not known by OpenSSL.

- -

X509_REQ_get_attr() returns either an X509_ATTRIBUTE or NULL on error.

- -

X509_REQ_delete_attr() returns either the removed X509_ATTRIBUTE or NULL if there is a error.

- -

X509_REQ_add1_attr(), X509_REQ_add1_attr_by_OBJ(), X509_REQ_add1_attr_by_NID() and X509_REQ_add1_attr_by_txt() return 1 on success or 0 on error.

- -

NOTES

- -

Any functions that modify the attributes (add or delete) internally set a flag to indicate the ASN.1 encoding has been modified.

- -

SEE ALSO

- -

X509_ATTRIBUTE(3)

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_REQ_get_extensions.html b/openssl-install/share/doc/openssl/html/man3/X509_REQ_get_extensions.html deleted file mode 100644 index 27a780ce..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_REQ_get_extensions.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -X509_REQ_get_extensions - - - - - - - - - - -

NAME

- -

X509_REQ_get_extensions, X509_REQ_add_extensions, X509_REQ_add_extensions_nid - handle X.509 extension attributes of a CSR

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-STACK_OF(X509_EXTENSION) *X509_REQ_get_extensions(const X509_REQ *req);
-int X509_REQ_add_extensions(X509_REQ *req, const STACK_OF(X509_EXTENSION) *exts);
-int X509_REQ_add_extensions_nid(X509_REQ *req,
-                                const STACK_OF(X509_EXTENSION) *exts, int nid);
- -

DESCRIPTION

- -

X509_REQ_get_extensions() returns the first list of X.509 extensions found in the attributes of req. The returned list is empty if there are no such extensions in req. The caller is responsible for freeing the list obtained.

- -

X509_REQ_add_extensions_nid() adds to req a list of X.509 extensions exts, using nid to identify the extensions attribute. req is unchanged if exts is NULL or an empty list. This function may be called more than once on the same req and nid. In such case any previous extensions are augmented, where an extension to be added that has the same OID as a pre-existing one replaces this earlier one.

- -

X509_REQ_add_extensions() is like X509_REQ_add_extensions_nid() except that the default NID_ext_req is used.

- -

RETURN VALUES

- -

X509_REQ_get_extensions() returns a pointer to STACK_OF(X509_EXTENSION) or NULL on error.

- -

X509_REQ_add_extensions() and X509_REQ_add_extensions_nid() return 1 on success, 0 on error.

- -

COPYRIGHT

- -

Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_SIG_get0.html b/openssl-install/share/doc/openssl/html/man3/X509_SIG_get0.html deleted file mode 100644 index cbc24e79..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_SIG_get0.html +++ /dev/null @@ -1,59 +0,0 @@ - - - - -X509_SIG_get0 - - - - - - - - - - -

NAME

- -

X509_SIG_get0, X509_SIG_getm - DigestInfo functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-void X509_SIG_get0(const X509_SIG *sig, const X509_ALGOR **palg,
-                   const ASN1_OCTET_STRING **pdigest);
-void X509_SIG_getm(X509_SIG *sig, X509_ALGOR **palg,
-                   ASN1_OCTET_STRING **pdigest);
- -

DESCRIPTION

- -

X509_SIG_get0() returns pointers to the algorithm identifier and digest value in sig. X509_SIG_getm() is identical to X509_SIG_get0() except the pointers returned are not constant and can be modified: for example to initialise them.

- -

RETURN VALUES

- -

X509_SIG_get0() and X509_SIG_getm() return no values.

- -

SEE ALSO

- -

d2i_X509(3)

- -

COPYRIGHT

- -

Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_by_subject.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_by_subject.html deleted file mode 100644 index c55ad1d4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_by_subject.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -X509_STORE_CTX_get_by_subject - - - - - - - - - - -

NAME

- -

X509_STORE_CTX_get_by_subject, X509_STORE_CTX_get_obj_by_subject - X509 and X509_CRL lookup functions

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-int X509_STORE_CTX_get_by_subject(const X509_STORE_CTX *vs,
-                                  X509_LOOKUP_TYPE type,
-                                  const X509_NAME *name, X509_OBJECT *ret);
-X509_OBJECT *X509_STORE_CTX_get_obj_by_subject(X509_STORE_CTX *vs,
-                                               X509_LOOKUP_TYPE type,
-                                               const X509_NAME *name);
- -

DESCRIPTION

- -

X509_STORE_CTX_get_by_subject() tries to find an object of given type, which may be X509_LU_X509 or X509_LU_CRL, and subject name from the store in the provided store context vs. If found and ret is not NULL, it increments the reference count and stores the looked up object in ret.

- -

X509_STORE_CTX_get_obj_by_subject() is like X509_STORE_CTX_get_by_subject() but returns the found object on success, else NULL.

- -

RETURN VALUES

- -

X509_STORE_CTX_get_by_subject() returns 1 if the lookup was successful, else 0.

- -

X509_STORE_CTX_get_obj_by_subject() returns an object on success, else NULL.

- -

SEE ALSO

- -

X509_LOOKUP_meth_set_get_by_subject(3), X509_LOOKUP_by_subject(3)

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_error.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_error.html deleted file mode 100644 index 4dbdebb9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_get_error.html +++ /dev/null @@ -1,565 +0,0 @@ - - - - -X509_STORE_CTX_get_error - - - - - - - - - - -

NAME

- -

X509_STORE_CTX_get_error, X509_STORE_CTX_set_error, X509_STORE_CTX_get_error_depth, X509_STORE_CTX_set_error_depth, X509_STORE_CTX_get_current_cert, X509_STORE_CTX_set_current_cert, X509_STORE_CTX_get0_cert, X509_STORE_CTX_get1_chain, X509_verify_cert_error_string - get or set certificate verification status information

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int   X509_STORE_CTX_get_error(const X509_STORE_CTX *ctx);
-void  X509_STORE_CTX_set_error(X509_STORE_CTX *ctx, int s);
-int   X509_STORE_CTX_get_error_depth(const X509_STORE_CTX *ctx);
-void  X509_STORE_CTX_set_error_depth(X509_STORE_CTX *ctx, int depth);
-X509 *X509_STORE_CTX_get_current_cert(const X509_STORE_CTX *ctx);
-void  X509_STORE_CTX_set_current_cert(X509_STORE_CTX *ctx, X509 *x);
-X509 *X509_STORE_CTX_get0_cert(const X509_STORE_CTX *ctx);
-
-STACK_OF(X509) *X509_STORE_CTX_get1_chain(const X509_STORE_CTX *ctx);
-
-const char *X509_verify_cert_error_string(long n);
- -

DESCRIPTION

- -

These functions are typically called after certificate or chain verification using X509_verify_cert(3) or X509_STORE_CTX_verify(3) has indicated an error or in a verification callback to determine the nature of an error.

- -

X509_STORE_CTX_get_error() returns the error code of ctx. See the "ERROR CODES" section for a full description of all error codes. It may return a code != X509_V_OK even if X509_verify_cert() did not indicate an error, likely because a verification callback function has waived the error.

- -

X509_STORE_CTX_set_error() sets the error code of ctx to s. For example it might be used in a verification callback to set an error based on additional checks.

- -

X509_STORE_CTX_get_error_depth() returns the depth of the error. This is a nonnegative integer representing where in the certificate chain the error occurred. If it is zero it occurred in the end entity certificate, one if it is the certificate which signed the end entity certificate and so on.

- -

X509_STORE_CTX_set_error_depth() sets the error depth. This can be used in combination with X509_STORE_CTX_set_error() to set the depth at which an error condition was detected.

- -

X509_STORE_CTX_get_current_cert() returns the current certificate in ctx. If an error occurred, the current certificate will be the one that is most closely related to the error, or possibly NULL if no such certificate is relevant.

- -

X509_STORE_CTX_set_current_cert() sets the certificate x in ctx which caused the error. This value is not intended to remain valid for very long, and remains owned by the caller. It may be examined by a verification callback invoked to handle each error encountered during chain verification and is no longer required after such a callback. If a callback wishes the save the certificate for use after it returns, it needs to increment its reference count via X509_up_ref(3). Once such a saved certificate is no longer needed it can be freed with X509_free(3).

- -

X509_STORE_CTX_get0_cert() retrieves an internal pointer to the certificate being verified by the ctx. It may be NULL if a raw public key is being verified.

- -

X509_STORE_CTX_get1_chain() returns a complete validate chain if a previous verification is successful. Otherwise the returned chain may be incomplete or invalid. The returned chain persists after the ctx structure is freed. When it is no longer needed it should be free up using:

- -
OSSL_STACK_OF_X509_free(chain);
- -

X509_verify_cert_error_string() returns a human readable error string for verification error n.

- -

RETURN VALUES

- -

X509_STORE_CTX_get_error() returns X509_V_OK or an error code.

- -

X509_STORE_CTX_get_error_depth() returns a nonnegative error depth.

- -

X509_STORE_CTX_get_current_cert() returns the certificate which caused the error or NULL if no certificate is relevant to the error.

- -

X509_verify_cert_error_string() returns a human readable error string for verification error n.

- -

ERROR CODES

- -

A list of error codes and messages is shown below. Some of the error codes are defined but currently never returned: these are described as "unused".

- -
- -
X509_V_OK: ok
-
- -

The operation was successful.

- -
-
X509_V_ERR_UNSPECIFIED: unspecified certificate verification error
-
- -

Unspecified error; should not happen.

- -
-
X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT: unable to get issuer certificate
-
- -

The issuer certificate of a locally looked up certificate could not be found. This normally means the list of trusted certificates is not complete. To allow any certificate (not only a self-signed one) in the trust store to terminate the chain the X509_V_FLAG_PARTIAL_CHAIN flag may be set.

- -
-
X509_V_ERR_UNABLE_TO_GET_CRL: unable to get certificate CRL
-
- -

The CRL of a certificate could not be found.

- -
-
X509_V_ERR_UNABLE_TO_DECRYPT_CERT_SIGNATURE: unable to decrypt certificate's signature
-
- -

The certificate signature could not be decrypted. This means that the actual signature value could not be determined rather than it not matching the expected value, this is only meaningful for RSA keys.

- -
-
X509_V_ERR_UNABLE_TO_DECRYPT_CRL_SIGNATURE: unable to decrypt CRL's signature
-
- -

The CRL signature could not be decrypted: this means that the actual signature value could not be determined rather than it not matching the expected value. Unused.

- -
-
X509_V_ERR_UNABLE_TO_DECODE_ISSUER_PUBLIC_KEY: unable to decode issuer public key
-
- -

The public key in the certificate SubjectPublicKeyInfo field could not be read.

- -
-
X509_V_ERR_CERT_SIGNATURE_FAILURE: certificate signature failure
-
- -

The signature of the certificate is invalid.

- -
-
X509_V_ERR_CRL_SIGNATURE_FAILURE: CRL signature failure
-
- -

The signature of the CRL is invalid.

- -
-
X509_V_ERR_CERT_NOT_YET_VALID: certificate is not yet valid
-
- -

The certificate is not yet valid: the notBefore date is after the current time.

- -
-
X509_V_ERR_CERT_HAS_EXPIRED: certificate has expired
-
- -

The certificate has expired: that is the notAfter date is before the current time.

- -
-
X509_V_ERR_CRL_NOT_YET_VALID: CRL is not yet valid
-
- -

The CRL is not yet valid.

- -
-
X509_V_ERR_CRL_HAS_EXPIRED: CRL has expired
-
- -

The CRL has expired.

- -
-
X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD: format error in certificate's notBefore field
-
- -

The certificate notBefore field contains an invalid time.

- -
-
X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD: format error in certificate's notAfter field
-
- -

The certificate notAfter field contains an invalid time.

- -
-
X509_V_ERR_ERROR_IN_CRL_LAST_UPDATE_FIELD: format error in CRL's lastUpdate field
-
- -

The CRL lastUpdate field contains an invalid time.

- -
-
X509_V_ERR_ERROR_IN_CRL_NEXT_UPDATE_FIELD: format error in CRL's nextUpdate field
-
- -

The CRL nextUpdate field contains an invalid time.

- -
-
X509_V_ERR_OUT_OF_MEM: out of memory
-
- -

An error occurred trying to allocate memory.

- -
-
X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT: self-signed certificate
-
- -

The passed certificate is self-signed and the same certificate cannot be found in the list of trusted certificates.

- -
-
X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN: self-signed certificate in certificate chain
-
- -

The certificate chain could be built up using the untrusted certificates but no suitable trust anchor (which typically is a self-signed root certificate) could be found in the trust store.

- -
-
X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY: unable to get local issuer certificate
-
- -

The issuer certificate could not be found: this occurs if the issuer certificate of an untrusted certificate cannot be found.

- -
-
X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE: unable to verify the first certificate
-
- -

No signatures could be verified because the chain contains only one certificate and it is not self-signed and the X509_V_FLAG_PARTIAL_CHAIN flag is not set.

- -
-
X509_V_ERR_CERT_CHAIN_TOO_LONG: certificate chain too long
-
- -

The certificate chain length is greater than the supplied maximum depth.

- -
-
X509_V_ERR_CERT_REVOKED: certificate revoked
-
- -

The certificate has been revoked.

- -
-
X509_V_ERR_NO_ISSUER_PUBLIC_KEY: issuer certificate doesn't have a public key
-
- -

The issuer certificate does not have a public key.

- -
-
X509_V_ERR_PATH_LENGTH_EXCEEDED: path length constraint exceeded
-
- -

The basicConstraints path-length parameter has been exceeded.

- -
-
X509_V_ERR_INVALID_PURPOSE: unsuitable certificate purpose
-
- -

The target certificate cannot be used for the specified purpose.

- -
-
X509_V_ERR_CERT_UNTRUSTED: certificate not trusted
-
- -

The root CA is not marked as trusted for the specified purpose.

- -
-
X509_V_ERR_CERT_REJECTED: certificate rejected
-
- -

The root CA is marked to reject the specified purpose.

- -
-
X509_V_ERR_SUBJECT_ISSUER_MISMATCH: subject issuer mismatch
-
- -

The current candidate issuer certificate was rejected because its subject name did not match the issuer name of the current certificate.

- -
-
X509_V_ERR_AKID_SKID_MISMATCH: authority and subject key identifier mismatch
-
- -

The current candidate issuer certificate was rejected because its subject key identifier was present and did not match the authority key identifier current certificate.

- -
-
X509_V_ERR_AKID_ISSUER_SERIAL_MISMATCH: authority and issuer serial number mismatch
-
- -

The current candidate issuer certificate was rejected because its issuer name and serial number was present and did not match the authority key identifier of the current certificate.

- -
-
X509_V_ERR_KEYUSAGE_NO_CERTSIGN: key usage does not include certificate signing
-
- -

The current candidate issuer certificate was rejected because its keyUsage extension does not permit certificate signing.

- -
-
X509_V_ERR_UNABLE_TO_GET_CRL_ISSUER: unable to get CRL issuer certificate
-
- -

Unable to get CRL issuer certificate.

- -
-
X509_V_ERR_UNHANDLED_CRITICAL_EXTENSION: unhandled critical extension
-
- -

Unhandled critical extension.

- -
-
X509_V_ERR_KEYUSAGE_NO_CRL_SIGN: key usage does not include CRL signing
-
- -

Key usage does not include CRL signing.

- -
-
X509_V_ERR_UNHANDLED_CRITICAL_CRL_EXTENSION: unhandled critical CRL extension
-
- -

Unhandled critical CRL extension.

- -
-
X509_V_ERR_INVALID_NON_CA: invalid non-CA certificate (has CA markings)
-
- -

Invalid non-CA certificate has CA markings.

- -
-
X509_V_ERR_PROXY_PATH_LENGTH_EXCEEDED: proxy path length constraint exceeded
-
- -

Proxy path length constraint exceeded.

- -
-
X509_V_ERR_KEYUSAGE_NO_DIGITAL_SIGNATURE: key usage does not include digital signature
-
- -

Key usage does not include digital signature, and therefore cannot sign certificates.

- -
-
X509_V_ERR_PROXY_CERTIFICATES_NOT_ALLOWED: proxy certificates not allowed, please set the appropriate flag
-
- -

Proxy certificates not allowed unless the X509_V_FLAG_ALLOW_PROXY_CERTS flag is set.

- -
-
X509_V_ERR_INVALID_EXTENSION: invalid or inconsistent certificate extension
-
- -

A certificate extension had an invalid value (for example an incorrect encoding) or some value inconsistent with other extensions.

- -
-
X509_V_ERR_INVALID_POLICY_EXTENSION: invalid or inconsistent certificate policy extension
-
- -

A certificate policies extension had an invalid value (for example an incorrect encoding) or some value inconsistent with other extensions. This error only occurs if policy processing is enabled.

- -
-
X509_V_ERR_NO_EXPLICIT_POLICY: no explicit policy
-
- -

The verification flags were set to require and explicit policy but none was present.

- -
-
X509_V_ERR_DIFFERENT_CRL_SCOPE: different CRL scope
-
- -

The only CRLs that could be found did not match the scope of the certificate.

- -
-
X509_V_ERR_UNSUPPORTED_EXTENSION_FEATURE: unsupported extension feature
-
- -

Some feature of a certificate extension is not supported. Unused.

- -
-
X509_V_ERR_UNNESTED_RESOURCE: RFC 3779 resource not subset of parent's resources
-
- -

See RFC 3779 for details.

- -
-
X509_V_ERR_PERMITTED_VIOLATION: permitted subtree violation
-
- -

A name constraint violation occurred in the permitted subtrees.

- -
-
X509_V_ERR_EXCLUDED_VIOLATION: excluded subtree violation
-
- -

A name constraint violation occurred in the excluded subtrees.

- -
-
X509_V_ERR_SUBTREE_MINMAX: name constraints minimum and maximum not supported
-
- -

A certificate name constraints extension included a minimum or maximum field: this is not supported.

- -
-
X509_V_ERR_APPLICATION_VERIFICATION: application verification failure
-
- -

An application specific error. This will never be returned unless explicitly set by an application callback.

- -
-
X509_V_ERR_UNSUPPORTED_CONSTRAINT_TYPE: unsupported name constraint type
-
- -

An unsupported name constraint type was encountered. OpenSSL currently only supports directory name, DNS name, email and URI types.

- -
-
X509_V_ERR_UNSUPPORTED_CONSTRAINT_SYNTAX: unsupported or invalid name constraint syntax
-
- -

The format of the name constraint is not recognised: for example an email address format of a form not mentioned in RFC3280. This could be caused by a garbage extension or some new feature not currently supported.

- -
-
X509_V_ERR_UNSUPPORTED_NAME_SYNTAX: unsupported or invalid name syntax
-
- -

Unsupported or invalid name syntax.

- -
-
X509_V_ERR_CRL_PATH_VALIDATION_ERROR: CRL path validation error
-
- -

An error occurred when attempting to verify the CRL path. This error can only happen if extended CRL checking is enabled.

- -
-
X509_V_ERR_PATH_LOOP: path loop
-
- -

Path loop.

- -
-
X509_V_ERR_HOSTNAME_MISMATCH: hostname mismatch
-
- -

Hostname mismatch.

- -
-
X509_V_ERR_EMAIL_MISMATCH: email address mismatch
-
- -

Email address mismatch.

- -
-
X509_V_ERR_IP_ADDRESS_MISMATCH: IP address mismatch
-
- -

IP address mismatch.

- -
-
X509_V_ERR_DANE_NO_MATCH: no matching DANE TLSA records
-
- -

DANE TLSA authentication is enabled, but no TLSA records matched the certificate chain. This error is only possible in openssl-s_client(1).

- -
-
X509_V_ERR_EE_KEY_TOO_SMALL: EE certificate key too weak
-
- -

EE certificate key too weak.

- -
-
X509_V_ERR_CA_KEY_TOO_SMALL: CA certificate key too weak
-
- -

CA certificate key too weak.

- -
-
X509_V_ERR_CA_MD_TOO_WEAK: CA signature digest algorithm too weak
-
- -

CA signature digest algorithm too weak.

- -
-
X509_V_ERR_INVALID_CALL: invalid certificate verification context
-
- -

Invalid certificate verification context.

- -
-
X509_V_ERR_STORE_LOOKUP: issuer certificate lookup error
-
- -

Issuer certificate lookup error.

- -
-
X509_V_ERR_NO_VALID_SCTS: certificate transparency required, but no valid SCTs found
-
- -

Certificate Transparency required, but no valid SCTs found.

- -
-
X509_V_ERR_PROXY_SUBJECT_NAME_VIOLATION: proxy subject name violation
-
- -

Proxy subject name violation.

- -
-
X509_V_ERR_OCSP_VERIFY_NEEDED: OCSP verification needed
-
- -

Returned by the verify callback to indicate an OCSP verification is needed.

- -
-
X509_V_ERR_OCSP_VERIFY_FAILED: OCSP verification failed
-
- -

Returned by the verify callback to indicate OCSP verification failed.

- -
-
X509_V_ERR_OCSP_CERT_UNKNOWN: OCSP unknown cert
-
- -

Returned by the verify callback to indicate that the certificate is not recognized by the OCSP responder.

- -
-
X509_V_ERR_UNSUPPORTED_SIGNATURE_ALGORITHM: unsupported signature algorithm
-
- -

Cannot find certificate signature algorithm.

- -
-
X509_V_ERR_SIGNATURE_ALGORITHM_MISMATCH: subject signature algorithm and issuer public key algorithm mismatch
-
- -

The issuer's public key is not of the type required by the signature in the subject's certificate.

- -
-
X509_V_ERR_SIGNATURE_ALGORITHM_INCONSISTENCY: cert info signature and signature algorithm mismatch
-
- -

The algorithm given in the certificate info is inconsistent with the one used for the certificate signature.

- -
-
X509_V_ERR_INVALID_CA: invalid CA certificate
-
- -

A CA certificate is invalid. Either it is not a CA or its extensions are not consistent with the supplied purpose.

- -
-
X509_V_ERR_RPK_UNTRUSTED: raw public key untrusted, no trusted keys configured
-
- -

No TLS records were configured to validate the raw public key, or DANE was not enabled on the connection.

- -
-
- -

NOTES

- -

The above functions should be used instead of directly referencing the fields in the X509_VERIFY_CTX structure.

- -

In versions of OpenSSL before 1.0 the current certificate returned by X509_STORE_CTX_get_current_cert() was never NULL. Applications should check the return value before printing out any debugging information relating to the current certificate.

- -

If an unrecognised error code is passed to X509_verify_cert_error_string() the numerical value of the unknown code is returned in a static buffer. This is not thread safe but will never happen unless an invalid code is passed.

- -

BUGS

- -

Previous versions of this documentation swapped the meaning of the X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT and X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY error codes.

- -

SEE ALSO

- -

X509_verify_cert(3), X509_STORE_CTX_verify(3), X509_up_ref(3), X509_free(3).

- -

COPYRIGHT

- -

Copyright 2009-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_new.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_new.html deleted file mode 100644 index 2ac1efcd..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_new.html +++ /dev/null @@ -1,181 +0,0 @@ - - - - -X509_STORE_CTX_new - - - - - - - - - - -

NAME

- -

X509_STORE_CTX_new_ex, X509_STORE_CTX_new, X509_STORE_CTX_cleanup, X509_STORE_CTX_free, X509_STORE_CTX_init, X509_STORE_CTX_init_rpk, X509_STORE_CTX_set0_trusted_stack, X509_STORE_CTX_set_cert, X509_STORE_CTX_set0_crls, X509_STORE_CTX_set0_rpk, X509_STORE_CTX_get0_param, X509_STORE_CTX_set0_param, X509_STORE_CTX_get0_untrusted, X509_STORE_CTX_set0_untrusted, X509_STORE_CTX_get_num_untrusted, X509_STORE_CTX_get0_chain, X509_STORE_CTX_set0_verified_chain, X509_STORE_CTX_get0_rpk, X509_STORE_CTX_set_default, X509_STORE_CTX_set_verify, X509_STORE_CTX_verify_fn, X509_STORE_CTX_set_purpose, X509_STORE_CTX_set_trust, X509_STORE_CTX_purpose_inherit - X509_STORE_CTX initialisation

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-X509_STORE_CTX *X509_STORE_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
-X509_STORE_CTX *X509_STORE_CTX_new(void);
-void X509_STORE_CTX_cleanup(X509_STORE_CTX *ctx);
-void X509_STORE_CTX_free(X509_STORE_CTX *ctx);
-
-int X509_STORE_CTX_init(X509_STORE_CTX *ctx, X509_STORE *trust_store,
-                        X509 *target, STACK_OF(X509) *untrusted);
-int X509_STORE_CTX_init_rpk(X509_STORE_CTX *ctx, X509_STORE *trust_store,
-                            EVP_PKEY *rpk);
-
-void X509_STORE_CTX_set0_trusted_stack(X509_STORE_CTX *ctx, STACK_OF(X509) *sk);
-
-void X509_STORE_CTX_set_cert(X509_STORE_CTX *ctx, X509 *target);
-void X509_STORE_CTX_set0_crls(X509_STORE_CTX *ctx, STACK_OF(X509_CRL) *sk);
-void X509_STORE_CTX_set0_rpk(X509_STORE_CTX *ctx, EVP_PKEY *target);
-
-X509_VERIFY_PARAM *X509_STORE_CTX_get0_param(const X509_STORE_CTX *ctx);
-void X509_STORE_CTX_set0_param(X509_STORE_CTX *ctx, X509_VERIFY_PARAM *param);
-
-STACK_OF(X509)* X509_STORE_CTX_get0_untrusted(const X509_STORE_CTX *ctx);
-void X509_STORE_CTX_set0_untrusted(X509_STORE_CTX *ctx, STACK_OF(X509) *sk);
-
-int X509_STORE_CTX_get_num_untrusted(const X509_STORE_CTX *ctx);
-STACK_OF(X509) *X509_STORE_CTX_get0_chain(const X509_STORE_CTX *ctx);
-void X509_STORE_CTX_set0_verified_chain(X509_STORE_CTX *ctx, STACK_OF(X509) *chain);
-EVP_PKEY *X509_STORE_CTX_get0_rpk(const X509_STORE_CTX *ctx);
-
-int X509_STORE_CTX_set_default(X509_STORE_CTX *ctx, const char *name);
-typedef int (*X509_STORE_CTX_verify_fn)(X509_STORE_CTX *);
-void X509_STORE_CTX_set_verify(X509_STORE_CTX *ctx, X509_STORE_CTX_verify_fn verify);
-
-int X509_STORE_CTX_set_purpose(X509_STORE_CTX *ctx, int purpose);
-int X509_STORE_CTX_set_trust(X509_STORE_CTX *ctx, int trust);
-int X509_STORE_CTX_purpose_inherit(X509_STORE_CTX *ctx, int def_purpose,
-                                   int purpose, int trust);
- -

DESCRIPTION

- -

These functions initialise an X509_STORE_CTX structure for subsequent use by X509_verify_cert(3) or X509_STORE_CTX_verify(3).

- -

X509_STORE_CTX_new_ex() returns a newly initialised X509_STORE_CTX structure associated with the specified library context libctx and property query string propq. Any cryptographic algorithms fetched while performing processing with the X509_STORE_CTX will use that library context and property query string.

- -

X509_STORE_CTX_new() is the same as X509_STORE_CTX_new_ex() except that the default library context and a NULL property query string are used.

- -

X509_STORE_CTX_cleanup() internally cleans up an X509_STORE_CTX structure. It is used by X509_STORE_CTX_init() and X509_STORE_CTX_free().

- -

X509_STORE_CTX_free() completely frees up ctx. After this call ctx is no longer valid. If ctx is NULL nothing is done.

- -

X509_STORE_CTX_init() sets up ctx for a subsequent verification operation.

- -

X509_STORE_CTX_init() initializes the internal state and resources of the given ctx. Among others, it sets the verification parameters associcated with the method name default, which includes the any purpose, and takes over callback function pointers from trust_store (unless NULL). It must be called before each call to X509_verify_cert(3) or X509_STORE_CTX_verify(3), i.e., a context is only good for one verification. If you want to verify a further certificate or chain with the same ctx then you must call X509_STORE_CTX_init() again. The trusted certificate store is set to trust_store of type X509_STORE. This may be NULL because there are no trusted certificates or because they are provided simply as a list using X509_STORE_CTX_set0_trusted_stack(). The certificate to be verified is set to target, and a list of additional certificates may be provided in untrusted, which will be untrusted but may be used to build the chain. The target certificate is not copied (its reference count is not updated), and the caller must not free it before verification is complete. Each of the trust_store, target and untrusted parameters can be NULL. Yet note that X509_verify_cert(3) and X509_STORE_CTX_verify(3) will need a verification target. This can also be set using X509_STORE_CTX_set_cert(). For X509_STORE_CTX_verify(3), which takes by default the first element of the list of untrusted certificates as its verification target, this can be also set indirectly using X509_STORE_CTX_set0_untrusted().

- -

X509_STORE_CTX_init_rpk() sets up ctx for a subsequent verification operation for the target raw public key. It behaves similarly to X509_STORE_CTX_init(). The target raw public key can also be supplied separately, via X509_STORE_CTX_set0_rpk(). The target public key is not copied (its reference count is not updated), and the caller must not free it before verification is complete.

- -

X509_STORE_CTX_set0_trusted_stack() sets the set of trusted certificates of ctx to sk. This is an alternative way of specifying trusted certificates instead of using an X509_STORE where its complexity is not needed or to make sure that only the given set sk of certificates are trusted.

- -

X509_STORE_CTX_set_cert() sets the target certificate to be verified in ctx to target. The target certificate is not copied (its reference count is not updated), and the caller must not free it before verification is complete.

- -

X509_STORE_CTX_set0_rpk() sets the target raw public key to be verified in ctx to target, a non-NULL raw public key preempts any target certificate, which is then ignored. The target public key is not copied (its reference count is not updated), and the caller must not free it before verification is complete.

- -

X509_STORE_CTX_set0_verified_chain() sets the validated chain to chain. Ownership of the chain is transferred to ctx, and so it should not be free'd by the caller.

- -

X509_STORE_CTX_get0_chain() returns the internal pointer used by the ctx that contains the constructed (output) chain.

- -

X509_STORE_CTX_get0_rpk() returns the internal pointer used by the ctx that contains the raw public key.

- -

X509_STORE_CTX_set0_crls() sets a set of CRLs to use to aid certificate verification to sk. These CRLs will only be used if CRL verification is enabled in the associated X509_VERIFY_PARAM structure. This might be used where additional "useful" CRLs are supplied as part of a protocol, for example in a PKCS#7 structure.

- -

X509_STORE_CTX_get0_param() retrieves an internal pointer to the verification parameters associated with ctx.

- -

X509_STORE_CTX_set0_param() sets the internal verification parameter pointer to param. After this call param should not be used.

- -

X509_STORE_CTX_get0_untrusted() retrieves an internal pointer to the stack of untrusted certificates associated with ctx.

- -

X509_STORE_CTX_set0_untrusted() sets the internal pointer to the stack of untrusted certificates associated with ctx to sk. X509_STORE_CTX_verify() will take the first element, if any, as its default target if the target certificate is not set explicitly.

- -

X509_STORE_CTX_get_num_untrusted() returns the number of untrusted certificates that were used in building the chain. This is can be used after calling X509_verify_cert(3) and similar functions. With X509_STORE_CTX_verify(3), this does not count the first chain element.

- -

X509_STORE_CTX_get0_chain() returns the internal pointer used by the ctx that contains the validated chain.

- -

Details of the chain building and checking process are described in "Certification Path Building" in openssl-verification-options(1) and "Certification Path Validation" in openssl-verification-options(1).

- -

X509_STORE_CTX_set0_verified_chain() sets the validated chain used by ctx to be chain. Ownership of the chain is transferred to ctx, and so it should not be free'd by the caller.

- -

X509_STORE_CTX_set_default() looks up and sets the default verification method. This uses the function X509_VERIFY_PARAM_lookup() to find the set of parameters associated with the given verification method name. Among others, the parameters determine the trust model and verification purpose. More detail, including the list of currently predefined methods, is described for the -verify_name command-line option in "Verification Options" in openssl-verification-options(1).

- -

X509_STORE_CTX_set_verify() provides the capability for overriding the default verify function. This function is responsible for verifying chain signatures and expiration times.

- -

A verify function is defined as an X509_STORE_CTX_verify type which has the following signature:

- -
int (*verify)(X509_STORE_CTX *);
- -

This function should receive the current X509_STORE_CTX as a parameter and return 1 on success or 0 on failure.

- -

X509 certificates may contain information about what purposes keys contained within them can be used for. For example "TLS WWW Server Authentication" or "Email Protection". This "key usage" information is held internally to the certificate itself. In addition the trust store containing trusted certificates can declare what purposes we trust different certificates for. This "trust" information is not held within the certificate itself but is "meta" information held alongside it. This "meta" information is associated with the certificate after it is issued and could be determined by a system administrator. For example a certificate might declare that it is suitable for use for both "TLS WWW Server Authentication" and "TLS Client Authentication", but a system administrator might only trust it for the former. An X.509 certificate extension exists that can record extended key usage information to supplement the purpose information described above. This extended mechanism is arbitrarily extensible and not well suited for a generic library API; applications that need to validate extended key usage information in certificates will need to define a custom "purpose" (see below) or supply a nondefault verification callback (X509_STORE_set_verify_cb_func(3)).

- -

X509_STORE_CTX_set_purpose() sets the purpose for the target certificate being verified in the ctx. Built-in available values for the purpose argument are X509_PURPOSE_SSL_CLIENT, X509_PURPOSE_SSL_SERVER, X509_PURPOSE_NS_SSL_SERVER, X509_PURPOSE_SMIME_SIGN, X509_PURPOSE_SMIME_ENCRYPT, X509_PURPOSE_CRL_SIGN, X509_PURPOSE_ANY, X509_PURPOSE_OCSP_HELPER, X509_PURPOSE_TIMESTAMP_SIGN and X509_PURPOSE_CODE_SIGN. It is also possible to create a custom purpose value. Setting a purpose requests that the key usage and extended key usage (EKU) extensions optionally declared within the certificate and its chain are verified to be consistent with that purpose. For SSL client, SSL server, and S/MIME purposes, the EKU is checked also for the CA certificates along the chain, including any given trust anchor certificate. Potentially also further checks are done (depending on the purpose given). Every purpose also has an associated default trust value, which will also be set at the same time. During verification, this trust setting will be verified to check whether it is consistent with the trust set by the system administrator for certificates in the chain.

- -

X509_STORE_CTX_set_trust() sets the trust value for the target certificate being verified in the ctx. Built-in available values for the trust argument are X509_TRUST_COMPAT, X509_TRUST_SSL_CLIENT, X509_TRUST_SSL_SERVER, X509_TRUST_EMAIL, X509_TRUST_OBJECT_SIGN, X509_TRUST_OCSP_SIGN, X509_TRUST_OCSP_REQUEST and X509_TRUST_TSA. It is also possible to create a custom trust value. Since X509_STORE_CTX_set_purpose() also sets the trust value it is normally sufficient to only call that function. If both are called then X509_STORE_CTX_set_trust() should be called after X509_STORE_CTX_set_purpose() since the trust setting of the last call will be used.

- -

It should not normally be necessary for end user applications to call X509_STORE_CTX_purpose_inherit() directly. Typically applications should call X509_STORE_CTX_set_purpose() or X509_STORE_CTX_set_trust() instead. Using this function it is possible to set the purpose and trust values for the ctx at the same time. Both ctx and its internal verification parameter pointer must not be NULL. The def_purpose and purpose arguments can have the same purpose values as described for X509_STORE_CTX_set_purpose() above. The trust argument can have the same trust values as described in X509_STORE_CTX_set_trust() above. Any of the def_purpose, purpose or trust values may also have the value 0 to indicate that the supplied parameter should be ignored. After calling this function the purpose to be used for verification is set from the purpose argument unless the purpose was already set in ctx before, and the trust is set from the trust argument unless the trust was already set in ctx before. If trust is 0 then the trust value will be set from the default trust value for purpose. If the default trust value for the purpose is X509_TRUST_DEFAULT and trust is 0 then the default trust value associated with the def_purpose value is used for the trust setting instead.

- -

NOTES

- -

The certificates and CRLs in a store are used internally and should not be freed up until after the associated X509_STORE_CTX is freed.

- -

BUGS

- -

The certificates and CRLs in a context are used internally and should not be freed up until after the associated X509_STORE_CTX is freed. Copies should be made or reference counts increased instead.

- -

RETURN VALUES

- -

X509_STORE_CTX_new() returns a newly allocated context or NULL if an error occurred.

- -

X509_STORE_CTX_init() and X509_STORE_CTX_init_rpk() return 1 for success or 0 if an error occurred.

- -

X509_STORE_CTX_get0_param() returns a pointer to an X509_VERIFY_PARAM structure or NULL if an error occurred.

- -

X509_STORE_CTX_get0_rpk() returns a pointer to an EVP_PKEY structure if present, or NULL if absent.

- -

X509_STORE_CTX_cleanup(), X509_STORE_CTX_free(), X509_STORE_CTX_set0_trusted_stack(), X509_STORE_CTX_set_cert(), X509_STORE_CTX_set0_crls() and X509_STORE_CTX_set0_param() do not return values.

- -

X509_STORE_CTX_set_default() returns 1 for success or 0 if an error occurred.

- -

X509_STORE_CTX_get_num_untrusted() returns the number of untrusted certificates used.

- -

SEE ALSO

- -

X509_verify_cert(3), X509_STORE_CTX_verify(3), X509_VERIFY_PARAM_set_flags(3)

- -

HISTORY

- -

The X509_STORE_CTX_set0_crls() function was added in OpenSSL 1.0.0. The X509_STORE_CTX_get_num_untrusted() function was added in OpenSSL 1.1.0. The X509_STORE_CTX_new_ex() function was added in OpenSSL 3.0. The X509_STORE_CTX_init_rpk(), X509_STORE_CTX_get0_rpk(), and X509_STORE_CTX_set0_rpk() functions were added in OpenSSL 3.2.

- -

There is no need to call X509_STORE_CTX_cleanup() explicitly since OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2009-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_set_verify_cb.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_set_verify_cb.html deleted file mode 100644 index b117554e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_CTX_set_verify_cb.html +++ /dev/null @@ -1,200 +0,0 @@ - - - - -X509_STORE_CTX_set_verify_cb - - - - - - - - - - -

NAME

- -

X509_STORE_CTX_get_cleanup, X509_STORE_CTX_get_lookup_crls, X509_STORE_CTX_get_lookup_certs, X509_STORE_CTX_get_check_policy, X509_STORE_CTX_get_cert_crl, X509_STORE_CTX_get_check_crl, X509_STORE_CTX_get_get_crl, X509_STORE_CTX_set_get_crl, X509_STORE_CTX_get_check_revocation, X509_STORE_CTX_get_check_issued, X509_STORE_CTX_get_get_issuer, X509_STORE_CTX_get_verify_cb, X509_STORE_CTX_set_verify_cb, X509_STORE_CTX_verify_cb, X509_STORE_CTX_print_verify_cb, X509_STORE_CTX_set_current_reasons - get and set X509_STORE_CTX components such as verification callback

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-typedef int (*X509_STORE_CTX_verify_cb)(int, X509_STORE_CTX *);
-int X509_STORE_CTX_print_verify_cb(int ok, X509_STORE_CTX *ctx);
-
-X509_STORE_CTX_verify_cb X509_STORE_CTX_get_verify_cb(X509_STORE_CTX *ctx);
-
-void X509_STORE_CTX_set_verify_cb(X509_STORE_CTX *ctx,
-                                  X509_STORE_CTX_verify_cb verify_cb);
-
-X509_STORE_CTX_get_issuer_fn X509_STORE_CTX_get_get_issuer(X509_STORE_CTX *ctx);
-X509_STORE_CTX_check_issued_fn X509_STORE_CTX_get_check_issued(X509_STORE_CTX *ctx);
-X509_STORE_CTX_check_revocation_fn X509_STORE_CTX_get_check_revocation(X509_STORE_CTX *ctx);
-
-X509_STORE_CTX_get_crl_fn X509_STORE_CTX_get_get_crl(X509_STORE_CTX *ctx);
-
-void X509_STORE_CTX_set_get_crl(X509_STORE_CTX *ctx,
-                                X509_STORE_CTX_get_crl_fn get_crl);
-
-X509_STORE_CTX_check_crl_fn X509_STORE_CTX_get_check_crl(X509_STORE_CTX *ctx);
-X509_STORE_CTX_cert_crl_fn X509_STORE_CTX_get_cert_crl(X509_STORE_CTX *ctx);
-X509_STORE_CTX_check_policy_fn X509_STORE_CTX_get_check_policy(X509_STORE_CTX *ctx);
-X509_STORE_CTX_lookup_certs_fn X509_STORE_CTX_get_lookup_certs(X509_STORE_CTX *ctx);
-X509_STORE_CTX_lookup_crls_fn X509_STORE_CTX_get_lookup_crls(X509_STORE_CTX *ctx);
-X509_STORE_CTX_cleanup_fn X509_STORE_CTX_get_cleanup(X509_STORE_CTX *ctx);
-void X509_STORE_CTX_set_current_reasons(X509_STORE_CTX *ctx,
-                                        unsigned int current_reasons);
- -

DESCRIPTION

- -

X509_STORE_CTX_set_verify_cb() sets the verification callback of ctx to verify_cb overwriting any existing callback.

- -

The verification callback can be used to customise the operation of certificate verification, for instance by overriding error conditions or logging errors for debugging purposes.

- -

However, a verification callback is not essential and the default operation is often sufficient.

- -

The ok parameter to the callback indicates the value the callback should return to retain the default behaviour. If it is zero then an error condition is indicated. If it is 1 then no error occurred. If the flag X509_V_FLAG_NOTIFY_POLICY is set then ok is set to 2 to indicate the policy checking is complete.

- -

The ctx parameter to the callback is the X509_STORE_CTX structure that is performing the verification operation. A callback can examine this structure and receive additional information about the error, for example by calling X509_STORE_CTX_get_current_cert(). Additional application data can be passed to the callback via the ex_data mechanism.

- -

X509_STORE_CTX_print_verify_cb() is a verification callback function that, when a certificate verification has failed, adds an entry to the error queue with code X509_R_CERTIFICATE_VERIFICATION_FAILED and with diagnostic details, including the most relevant fields of the target certificate that failed to verify and, if appropriate, of the available untrusted and trusted certificates.

- -

X509_STORE_CTX_get_verify_cb() returns the value of the current callback for the specific ctx.

- -

X509_STORE_CTX_get_get_issuer(), X509_STORE_CTX_get_check_issued(), X509_STORE_CTX_get_check_revocation(), X509_STORE_CTX_get_get_crl(), X509_STORE_CTX_get_check_crl(), X509_STORE_CTX_get_cert_crl(), X509_STORE_CTX_get_check_policy(), X509_STORE_CTX_get_lookup_certs(), X509_STORE_CTX_get_lookup_crls() and X509_STORE_CTX_get_cleanup() return the function pointers cached from the corresponding X509_STORE, please see X509_STORE_set_verify(3) for more information.

- -

X509_STORE_CTX_set_get_crl() sets the function to get the crl for a given certificate x. When found, the crl must be assigned to *crl. This function must return 0 on failure and 1 on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_CTX_set_current_reasons() is used in conjunction with X509_STORE_CTX_get_crl_fn. The X509_STORE_CTX_get_crl_fn callback must use this method to set the reason why the certificate is invalid.

- -

WARNINGS

- -

In general a verification callback should NOT unconditionally return 1 in all circumstances because this will allow verification to succeed no matter what the error. This effectively removes all security from the application because any certificate (including untrusted generated ones) will be accepted.

- -

NOTES

- -

The verification callback can be set and inherited from the parent structure performing the operation. In some cases (such as S/MIME verification) the X509_STORE_CTX structure is created and destroyed internally and the only way to set a custom verification callback is by inheriting it from the associated X509_STORE.

- -

RETURN VALUES

- -

X509_STORE_CTX_set_verify_cb() does not return a value.

- -

EXAMPLES

- -

Default callback operation:

- -
int verify_callback(int ok, X509_STORE_CTX *ctx) {
-    return ok;
-}
- -

Simple example, suppose a certificate in the chain is expired and we wish to continue after this error:

- -
int verify_callback(int ok, X509_STORE_CTX *ctx) {
-    /* Tolerate certificate expiration */
-    if (X509_STORE_CTX_get_error(ctx) == X509_V_ERR_CERT_HAS_EXPIRED)
-        return 1;
-    /* Otherwise don't override */
-    return ok;
-}
- -

More complex example, we don't wish to continue after any certificate has expired just one specific case:

- -
int verify_callback(int ok, X509_STORE_CTX *ctx)
-{
-    int err = X509_STORE_CTX_get_error(ctx);
-    X509 *err_cert = X509_STORE_CTX_get_current_cert(ctx);
-
-    if (err == X509_V_ERR_CERT_HAS_EXPIRED) {
-        if (check_is_acceptable_expired_cert(err_cert)
-            return 1;
-    }
-    return ok;
-}
- -

Full featured logging callback. In this case the bio_err is assumed to be a global logging BIO, an alternative would to store a BIO in ctx using ex_data.

- -
int verify_callback(int ok, X509_STORE_CTX *ctx)
-{
-    X509 *err_cert;
-    int err, depth;
-
-    err_cert = X509_STORE_CTX_get_current_cert(ctx);
-    err = X509_STORE_CTX_get_error(ctx);
-    depth = X509_STORE_CTX_get_error_depth(ctx);
-
-    BIO_printf(bio_err, "depth=%d ", depth);
-    if (err_cert) {
-        X509_NAME_print_ex(bio_err, X509_get_subject_name(err_cert),
-                           0, XN_FLAG_ONELINE);
-        BIO_puts(bio_err, "\n");
-    }
-    else
-        BIO_puts(bio_err, "<no cert>\n");
-    if (!ok)
-        BIO_printf(bio_err, "verify error:num=%d:%s\n", err,
-                   X509_verify_cert_error_string(err));
-    switch (err) {
-    case X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT:
-        BIO_puts(bio_err, "issuer= ");
-        X509_NAME_print_ex(bio_err, X509_get_issuer_name(err_cert),
-                           0, XN_FLAG_ONELINE);
-        BIO_puts(bio_err, "\n");
-        break;
-    case X509_V_ERR_CERT_NOT_YET_VALID:
-    case X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD:
-        BIO_printf(bio_err, "notBefore=");
-        ASN1_TIME_print(bio_err, X509_get_notBefore(err_cert));
-        BIO_printf(bio_err, "\n");
-        break;
-    case X509_V_ERR_CERT_HAS_EXPIRED:
-    case X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD:
-        BIO_printf(bio_err, "notAfter=");
-        ASN1_TIME_print(bio_err, X509_get_notAfter(err_cert));
-        BIO_printf(bio_err, "\n");
-        break;
-    case X509_V_ERR_NO_EXPLICIT_POLICY:
-        policies_print(bio_err, ctx);
-        break;
-    }
-    if (err == X509_V_OK && ok == 2)
-        /* print out policies */
-
-    BIO_printf(bio_err, "verify return:%d\n", ok);
-    return(ok);
-}
- -

SEE ALSO

- -

X509_STORE_CTX_get_error(3) X509_STORE_set_verify_cb_func(3) X509_STORE_CTX_get_ex_new_index(3)

- -

HISTORY

- -

The X509_STORE_CTX_get_get_issuer(), X509_STORE_CTX_get_check_issued(), X509_STORE_CTX_get_check_revocation(), X509_STORE_CTX_get_get_crl(), X509_STORE_CTX_get_check_crl(), X509_STORE_CTX_get_cert_crl(), X509_STORE_CTX_get_check_policy(), X509_STORE_CTX_get_lookup_certs(), X509_STORE_CTX_get_lookup_crls() and X509_STORE_CTX_get_cleanup() functions were added in OpenSSL 1.1.0.

- -

X509_STORE_CTX_print_verify_cb() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2009-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_add_cert.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_add_cert.html deleted file mode 100644 index c0ecb817..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_add_cert.html +++ /dev/null @@ -1,119 +0,0 @@ - - - - -X509_STORE_add_cert - - - - - - - - - - -

NAME

- -

X509_STORE, X509_STORE_add_cert, X509_STORE_add_crl, X509_STORE_set_depth, X509_STORE_set_flags, X509_STORE_set_purpose, X509_STORE_set_trust, X509_STORE_add_lookup, X509_STORE_load_file_ex, X509_STORE_load_file, X509_STORE_load_path, X509_STORE_load_store_ex, X509_STORE_load_store, X509_STORE_set_default_paths_ex, X509_STORE_set_default_paths, X509_STORE_load_locations_ex, X509_STORE_load_locations - X509_STORE manipulation

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-typedef x509_store_st X509_STORE;
-
-int X509_STORE_add_cert(X509_STORE *xs, X509 *x);
-int X509_STORE_add_crl(X509_STORE *xs, X509_CRL *x);
-int X509_STORE_set_depth(X509_STORE *store, int depth);
-int X509_STORE_set_flags(X509_STORE *xs, unsigned long flags);
-int X509_STORE_set_purpose(X509_STORE *xs, int purpose);
-int X509_STORE_set_trust(X509_STORE *xs, int trust);
-
-X509_LOOKUP *X509_STORE_add_lookup(X509_STORE *store,
-                                   X509_LOOKUP_METHOD *meth);
-
-int X509_STORE_set_default_paths_ex(X509_STORE *xs, OSSL_LIB_CTX *libctx,
-                                    const char *propq);
-int X509_STORE_set_default_paths(X509_STORE *xs);
-int X509_STORE_load_file_ex(X509_STORE *xs, const char *file,
-                            OSSL_LIB_CTX *libctx, const char *propq);
-int X509_STORE_load_file(X509_STORE *xs, const char *file);
-int X509_STORE_load_path(X509_STORE *xs, const char *dir);
-int X509_STORE_load_store_ex(X509_STORE *xs, const char *uri,
-                             OSSL_LIB_CTX *libctx, const char *propq);
-int X509_STORE_load_store(X509_STORE *xs, const char *uri);
-int X509_STORE_load_locations_ex(X509_STORE *xs, const char *file,
-                                 const char *dir, OSSL_LIB_CTX *libctx,
-                                 const char *propq);
-int X509_STORE_load_locations(X509_STORE *xs,
-                              const char *file, const char *dir);
- -

DESCRIPTION

- -

The X509_STORE structure is intended to be a consolidated mechanism for holding information about X.509 certificates and CRLs, and constructing and validating chains of certificates terminating in trusted roots. It admits multiple lookup mechanisms and efficient scaling performance with large numbers of certificates, and a great deal of flexibility in how validation and policy checks are performed.

- -

Details of the chain building and checking process are described in "Certification Path Building" in openssl-verification-options(1) and "Certification Path Validation" in openssl-verification-options(1).

- -

X509_STORE_new(3) creates an empty X509_STORE structure, which contains no information about trusted certificates or where such certificates are located on disk, and is generally not usable. Normally, trusted certificates will be added to the X509_STORE to prepare it for use, via mechanisms such as X509_STORE_add_lookup() and X509_LOOKUP_file(), or PEM_read_bio_X509_AUX() and X509_STORE_add_cert(). CRLs can also be added, and many behaviors configured as desired.

- -

Once the X509_STORE is suitably configured, X509_STORE_CTX_new() is used to instantiate a single-use X509_STORE_CTX for each chain-building and verification operation. That process includes providing the end-entity certificate to be verified and an additional set of untrusted certificates that may be used in chain-building. As such, it is expected that the certificates included in the X509_STORE are certificates that represent trusted entities such as root certificate authorities (CAs). OpenSSL represents these trusted certificates internally as X509 objects with an associated X509_CERT_AUX, as are produced by PEM_read_bio_X509_AUX() and similar routines that refer to X509_AUX. The public interfaces that operate on such trusted certificates still operate on pointers to X509 objects, though.

- -

X509_STORE_add_cert() and X509_STORE_add_crl() add the respective object to the X509_STORE's local storage. Untrusted objects should not be added in this way. The added object's reference count is incremented by one, hence the caller retains ownership of the object and needs to free it when it is no longer needed.

- -

X509_STORE_set_depth(), X509_STORE_set_flags(), X509_STORE_set_purpose(), X509_STORE_set_trust(), and X509_STORE_set1_param() set the default values for the corresponding values used in certificate chain validation. Their behavior is documented in the corresponding X509_VERIFY_PARAM manual pages, e.g., X509_VERIFY_PARAM_set_depth(3).

- -

X509_STORE_add_lookup() finds or creates a X509_LOOKUP(3) with the X509_LOOKUP_METHOD(3) meth and adds it to the X509_STORE store. This also associates the X509_STORE with the lookup, so X509_LOOKUP functions can look up objects in that store.

- -

X509_STORE_load_file_ex() loads trusted certificate(s) into an X509_STORE from a given file. The library context libctx and property query propq are used when fetching algorithms from providers.

- -

X509_STORE_load_file() is similar to X509_STORE_load_file_ex() but uses NULL for the library context libctx and property query propq.

- -

X509_STORE_load_path() loads trusted certificate(s) into an X509_STORE from a given directory path. The certificates in the directory must be in hashed form, as documented in X509_LOOKUP_hash_dir(3).

- -

X509_STORE_load_store_ex() loads trusted certificate(s) into an X509_STORE from a store at a given URI. The library context libctx and property query propq are used when fetching algorithms from providers.

- -

X509_STORE_load_store() is similar to X509_STORE_load_store_ex() but uses NULL for the library context libctx and property query propq.

- -

X509_STORE_load_locations_ex() combines X509_STORE_load_file_ex() and X509_STORE_load_path() for a given file and/or directory path. It is permitted to specify just a file, just a directory, or both paths.

- -

X509_STORE_load_locations() is similar to X509_STORE_load_locations_ex() but uses NULL for the library context libctx and property query propq.

- -

X509_STORE_set_default_paths_ex() is somewhat misnamed, in that it does not set what default paths should be used for loading certificates. Instead, it loads certificates into the X509_STORE from the hardcoded default paths. The library context libctx and property query propq are used when fetching algorithms from providers.

- -

X509_STORE_set_default_paths() is similar to X509_STORE_set_default_paths_ex() but uses NULL for the library context libctx and property query propq.

- -

RETURN VALUES

- -

X509_STORE_add_cert(), X509_STORE_add_crl(), X509_STORE_set_depth(), X509_STORE_set_flags(), X509_STORE_set_purpose(), X509_STORE_set_trust(), X509_STORE_load_file_ex(), X509_STORE_load_file(), X509_STORE_load_path(), X509_STORE_load_store_ex(), X509_STORE_load_store(), X509_STORE_load_locations_ex(), X509_STORE_load_locations(), X509_STORE_set_default_paths_ex() and X509_STORE_set_default_paths() return 1 on success or 0 on failure.

- -

X509_STORE_add_lookup() returns the found or created X509_LOOKUP(3), or NULL on error.

- -

SEE ALSO

- -

X509_LOOKUP_hash_dir(3). X509_VERIFY_PARAM_set_depth(3). X509_STORE_new(3), X509_STORE_get0_param(3)

- -

HISTORY

- -

The functions X509_STORE_set_default_paths_ex(), X509_STORE_load_file_ex(), X509_STORE_load_store_ex() and X509_STORE_load_locations_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_get0_param.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_get0_param.html deleted file mode 100644 index edfc3133..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_get0_param.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -X509_STORE_get0_param - - - - - - - - - - -

NAME

- -

X509_STORE_get0_param, X509_STORE_set1_param, X509_STORE_get1_objects, X509_STORE_get0_objects, X509_STORE_get1_all_certs - X509_STORE setter and getter functions

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-X509_VERIFY_PARAM *X509_STORE_get0_param(const X509_STORE *xs);
-int X509_STORE_set1_param(X509_STORE *xs, const X509_VERIFY_PARAM *pm);
-STACK_OF(X509_OBJECT) *X509_STORE_get1_objects(X509_STORE *xs);
-STACK_OF(X509_OBJECT) *X509_STORE_get0_objects(const X509_STORE *xs);
-STACK_OF(X509) *X509_STORE_get1_all_certs(X509_STORE *xs);
- -

DESCRIPTION

- -

X509_STORE_set1_param() sets the verification parameters to pm for xs.

- -

X509_STORE_get0_param() retrieves an internal pointer to the verification parameters for xs. The returned pointer must not be freed by the calling application

- -

X509_STORE_get1_objects() returns a snapshot of all objects in the store's X509 cache. The cache contains X509 and X509_CRL objects. The caller is responsible for freeing the returned list.

- -

X509_STORE_get0_objects() retrieves an internal pointer to the store's X509 object cache. The cache contains X509 and X509_CRL objects. The returned pointer must not be freed by the calling application. If the store is shared across multiple threads, it is not safe to use the result of this function. Use X509_STORE_get1_objects() instead, which avoids this problem.

- -

X509_STORE_get1_all_certs() returns a list of all certificates in the store. The caller is responsible for freeing the returned list.

- -

RETURN VALUES

- -

X509_STORE_get0_param() returns a pointer to an X509_VERIFY_PARAM structure.

- -

X509_STORE_set1_param() returns 1 for success and 0 for failure.

- -

X509_STORE_get1_objects() returns a pointer to a stack of the retrieved objects on success, else NULL.

- -

X509_STORE_get0_objects() returns a pointer to a stack of X509_OBJECT.

- -

X509_STORE_get1_all_certs() returns a pointer to a stack of the retrieved certificates on success, else NULL.

- -

SEE ALSO

- -

X509_STORE_new(3)

- -

HISTORY

- -

X509_STORE_get0_param and X509_STORE_get0_objects were added in OpenSSL 1.1.0. X509_STORE_get1_certs was added in OpenSSL 3.0. X509_STORE_get1_objects was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_new.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_new.html deleted file mode 100644 index bc1d9d4d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_new.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -X509_STORE_new - - - - - - - - - - -

NAME

- -

X509_STORE_new, X509_STORE_up_ref, X509_STORE_free, X509_STORE_lock,X509_STORE_unlock - X509_STORE allocation, freeing and locking functions

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-X509_STORE *X509_STORE_new(void);
-void X509_STORE_free(X509_STORE *xs);
-int X509_STORE_lock(X509_STORE *xs);
-int X509_STORE_unlock(X509_STORE *xs);
-int X509_STORE_up_ref(X509_STORE *xs);
- -

DESCRIPTION

- -

The X509_STORE_new() function returns a new X509_STORE.

- -

X509_STORE_up_ref() increments the reference count associated with the X509_STORE object.

- -

X509_STORE_lock() locks the store from modification by other threads, X509_STORE_unlock() unlocks it.

- -

X509_STORE_free() frees up a single X509_STORE object. If the argument is NULL, nothing is done.

- -

RETURN VALUES

- -

X509_STORE_new() returns a newly created X509_STORE or NULL if the call fails.

- -

X509_STORE_up_ref(), X509_STORE_lock() and X509_STORE_unlock() return 1 for success and 0 for failure.

- -

X509_STORE_free() does not return values.

- -

SEE ALSO

- -

X509_STORE_set_verify_cb_func(3) X509_STORE_get0_param(3)

- -

HISTORY

- -

The X509_STORE_up_ref(), X509_STORE_lock() and X509_STORE_unlock() functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_STORE_set_verify_cb_func.html b/openssl-install/share/doc/openssl/html/man3/X509_STORE_set_verify_cb_func.html deleted file mode 100644 index 0dc4935d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_STORE_set_verify_cb_func.html +++ /dev/null @@ -1,181 +0,0 @@ - - - - -X509_STORE_set_verify_cb_func - - - - - - - - - - -

NAME

- -

X509_STORE_set_lookup_crls_cb, X509_STORE_set_verify_func, X509_STORE_get_cleanup, X509_STORE_set_cleanup, X509_STORE_get_lookup_crls, X509_STORE_set_lookup_crls, X509_STORE_get_lookup_certs, X509_STORE_set_lookup_certs, X509_STORE_get_check_policy, X509_STORE_set_check_policy, X509_STORE_get_cert_crl, X509_STORE_set_cert_crl, X509_STORE_get_check_crl, X509_STORE_set_check_crl, X509_STORE_get_get_crl, X509_STORE_set_get_crl, X509_STORE_get_check_revocation, X509_STORE_set_check_revocation, X509_STORE_get_check_issued, X509_STORE_set_check_issued, X509_STORE_CTX_get1_issuer, X509_STORE_get_get_issuer, X509_STORE_set_get_issuer, X509_STORE_CTX_get_verify, X509_STORE_set_verify, X509_STORE_get_verify_cb, X509_STORE_set_verify_cb_func, X509_STORE_set_verify_cb, X509_STORE_CTX_cert_crl_fn, X509_STORE_CTX_check_crl_fn, X509_STORE_CTX_check_issued_fn, X509_STORE_CTX_check_policy_fn, X509_STORE_CTX_check_revocation_fn, X509_STORE_CTX_cleanup_fn, X509_STORE_CTX_get_crl_fn, X509_STORE_CTX_get_issuer_fn, X509_STORE_CTX_lookup_certs_fn, X509_STORE_CTX_lookup_crls_fn - set verification callback

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-typedef int (*X509_STORE_CTX_get_issuer_fn)(X509 **issuer,
-                                            X509_STORE_CTX *ctx, X509 *x);
-typedef int (*X509_STORE_CTX_check_issued_fn)(X509_STORE_CTX *ctx,
-                                              X509 *x, X509 *issuer);
-typedef int (*X509_STORE_CTX_check_revocation_fn)(X509_STORE_CTX *ctx);
-typedef int (*X509_STORE_CTX_get_crl_fn)(X509_STORE_CTX *ctx,
-                                         X509_CRL **crl, X509 *x);
-typedef int (*X509_STORE_CTX_check_crl_fn)(X509_STORE_CTX *ctx, X509_CRL *crl);
-typedef int (*X509_STORE_CTX_cert_crl_fn)(X509_STORE_CTX *ctx,
-                                          X509_CRL *crl, X509 *x);
-typedef int (*X509_STORE_CTX_check_policy_fn)(X509_STORE_CTX *ctx);
-typedef STACK_OF(X509) *(*X509_STORE_CTX_lookup_certs_fn)(X509_STORE_CTX *ctx,
-                                                          const X509_NAME *nm);
-typedef STACK_OF(X509_CRL) *(*X509_STORE_CTX_lookup_crls_fn)(const
-                                                             X509_STORE_CTX *ctx,
-                                                             const X509_NAME *nm);
-typedef int (*X509_STORE_CTX_cleanup_fn)(X509_STORE_CTX *ctx);
-
-void X509_STORE_set_verify_cb(X509_STORE *xs,
-                              X509_STORE_CTX_verify_cb verify_cb);
-X509_STORE_CTX_verify_cb X509_STORE_get_verify_cb(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_verify(X509_STORE *xs, X509_STORE_CTX_verify_fn verify);
-X509_STORE_CTX_verify_fn X509_STORE_CTX_get_verify(const X509_STORE_CTX *ctx);
-
-int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, X509 *x);
-X509_STORE_CTX_get_issuer_fn X509_STORE_get_get_issuer(const X509_STORE_CTX *ctx);
-void X509_STORE_set_get_issuer(X509_STORE *xs,
-                               X509_STORE_CTX_get_issuer_fn get_issuer);
-
-void X509_STORE_set_check_issued(X509_STORE *xs,
-                                 X509_STORE_CTX_check_issued_fn check_issued);
-X509_STORE_CTX_check_issued_fn
-    X509_STORE_get_check_issued(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_check_revocation(X509_STORE *xs,
-                                     X509_STORE_CTX_check_revocation_fn check_revocation);
-X509_STORE_CTX_check_revocation_fn
-    X509_STORE_get_check_revocation(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_get_crl(X509_STORE *xs,
-                            X509_STORE_CTX_get_crl_fn get_crl);
-X509_STORE_CTX_get_crl_fn X509_STORE_get_get_crl(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_check_crl(X509_STORE *xs,
-                              X509_STORE_CTX_check_crl_fn check_crl);
-X509_STORE_CTX_check_crl_fn
-    X509_STORE_get_check_crl(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_cert_crl(X509_STORE *xs,
-                             X509_STORE_CTX_cert_crl_fn cert_crl);
-X509_STORE_CTX_cert_crl_fn X509_STORE_get_cert_crl(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_check_policy(X509_STORE *xs,
-                                 X509_STORE_CTX_check_policy_fn check_policy);
-X509_STORE_CTX_check_policy_fn
-    X509_STORE_get_check_policy(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_lookup_certs(X509_STORE *xs,
-                                 X509_STORE_CTX_lookup_certs_fn lookup_certs);
-X509_STORE_CTX_lookup_certs_fn
-    X509_STORE_get_lookup_certs(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_lookup_crls(X509_STORE *xs,
-                                X509_STORE_CTX_lookup_crls_fn lookup_crls);
-X509_STORE_CTX_lookup_crls_fn
-    X509_STORE_get_lookup_crls(const X509_STORE_CTX *ctx);
-
-void X509_STORE_set_cleanup(X509_STORE *xs,
-                            X509_STORE_CTX_cleanup_fn cleanup);
-X509_STORE_CTX_cleanup_fn X509_STORE_get_cleanup(const X509_STORE_CTX *ctx);
-
-/* Aliases */
-void X509_STORE_set_verify_cb_func(X509_STORE *st,
-                                   X509_STORE_CTX_verify_cb verify_cb);
-void X509_STORE_set_verify_func(X509_STORE *xs,
-                                X509_STORE_CTX_verify_fn verify);
-void X509_STORE_set_lookup_crls_cb(X509_STORE *xs,
-                                   X509_STORE_CTX_lookup_crls_fn lookup_crls);
- -

DESCRIPTION

- -

X509_STORE_set_verify_cb() sets the verification callback of xs to verify_cb overwriting the previous callback. The callback assigned with this function becomes a default for the one that can be assigned directly to the corresponding X509_STORE_CTX, please see X509_STORE_CTX_set_verify_cb(3) for further information.

- -

X509_STORE_set_verify() sets the final chain verification function for xs to verify. Its purpose is to go through the chain of certificates and check that all signatures are valid and that the current time is within the limits of each certificate's first and last validity time. The final chain verification functions must return 0 on failure and 1 on success. If no chain verification function is provided, the internal default function will be used instead.

- -

X509_STORE_CTX_get1_issuer() tries to find a certificate from the store component of ctx that has a subject name matching the issuer name of x and is accepted by the check_issued function in ctx. On success it assigns to *issuer the first match that has a suitable validity period or otherwise has the latest expiration date of all matching certificates. If the function returns 1 the caller is responsible for freeing *issuer. Note that this search does not support backtracking.

- -

X509_STORE_set_get_issuer() sets the function get_issuer that is used to get the "best" candidate issuer certificate of the given certificate x. When such a certificate is found, get_issuer must up-ref and assign it to *issuer and then return 1. Otherwise get_issuer must return 0 if not found and -1 (or 0) on failure. If X509_STORE_set_get_issuer() is not used or get_issuer is NULL then X509_STORE_CTX_get1_issuer() is used as the default implementation.

- -

X509_STORE_set_check_issued() sets the function to check that a given certificate x is issued by the issuer certificate issuer. This function must return 0 on failure (among others if x hasn't been issued with issuer) and 1 on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_set_check_revocation() sets the revocation checking function. Its purpose is to look through the final chain and check the revocation status for each certificate. It must return 0 on failure and 1 on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_set_get_crl() sets the function to get the crl for a given certificate x. When found, the crl must be assigned to *crl. This function must return 0 on failure and 1 on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_set_check_crl() sets the function to check the validity of the given crl. This function must return 0 on failure and 1 on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_set_cert_crl() sets the function to check the revocation status of the given certificate x against the given crl. This function must return 0 on failure and 1 on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_set_check_policy() sets the function to check the policies of all the certificates in the final chain.. This function must return 0 on failure and 1 on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_set_lookup_certs() and X509_STORE_set_lookup_crls() set the functions to look up all the certs or all the CRLs that match the given name nm. These functions return NULL on failure and a pointer to a stack of certificates (X509) or to a stack of CRLs (X509_CRL) on success. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_set_cleanup() sets the final cleanup function, which is called when the context (X509_STORE_CTX) is being torn down. This function doesn't return any value. If no function to get the issuer is provided, the internal default function will be used instead.

- -

X509_STORE_get_verify_cb(), X509_STORE_CTX_get_verify(), X509_STORE_get_get_issuer(), X509_STORE_get_check_issued(), X509_STORE_get_check_revocation(), X509_STORE_get_get_crl(), X509_STORE_get_check_crl(), X509_STORE_set_verify(), X509_STORE_set_get_issuer(), X509_STORE_get_cert_crl(), X509_STORE_get_check_policy(), X509_STORE_get_lookup_certs(), X509_STORE_get_lookup_crls() and X509_STORE_get_cleanup() all return the function pointer assigned with X509_STORE_set_check_issued(), X509_STORE_set_check_revocation(), X509_STORE_set_get_crl(), X509_STORE_set_check_crl(), X509_STORE_set_cert_crl(), X509_STORE_set_check_policy(), X509_STORE_set_lookup_certs(), X509_STORE_set_lookup_crls() and X509_STORE_set_cleanup(), or NULL if no assignment has been made.

- -

X509_STORE_set_verify_cb_func(), X509_STORE_set_verify_func() and X509_STORE_set_lookup_crls_cb() are aliases for X509_STORE_set_verify_cb(), X509_STORE_set_verify() and X509_STORE_set_lookup_crls, available as macros for backward compatibility.

- -

NOTES

- -

All the callbacks from a X509_STORE are inherited by the corresponding X509_STORE_CTX structure when it is initialized. See X509_STORE_CTX_set_verify_cb(3) for further details.

- -

BUGS

- -

The macro version of this function was the only one available before OpenSSL 1.0.0.

- -

RETURN VALUES

- -

The X509_STORE_set_*() functions do not return a value.

- -

The X509_STORE_get_*() functions return a pointer of the appropriate function type.

- -

X509_STORE_CTX_get1_issuer() returns 1 if a suitable certificate is found, 0 if not found, -1 on other error.

- -

SEE ALSO

- -

X509_STORE_CTX_set_verify_cb(3), X509_STORE_CTX_get0_chain(3), X509_STORE_CTX_verify_cb(3), X509_STORE_CTX_verify_fn(3), CMS_verify(3)

- -

HISTORY

- -

The X509_STORE_set_verify_cb() function was added in OpenSSL 1.0.0.

- -

The functions X509_STORE_set_verify_cb(), X509_STORE_get_verify_cb(), X509_STORE_set_verify(), X509_STORE_CTX_get_verify(), X509_STORE_set_get_issuer(), X509_STORE_get_get_issuer(), X509_STORE_set_check_issued(), X509_STORE_get_check_issued(), X509_STORE_set_check_revocation(), X509_STORE_get_check_revocation(), X509_STORE_set_get_crl(), X509_STORE_get_get_crl(), X509_STORE_set_check_crl(), X509_STORE_get_check_crl(), X509_STORE_set_cert_crl(), X509_STORE_get_cert_crl(), X509_STORE_set_check_policy(), X509_STORE_get_check_policy(), X509_STORE_set_lookup_certs(), X509_STORE_get_lookup_certs(), X509_STORE_set_lookup_crls(), X509_STORE_get_lookup_crls(), X509_STORE_set_cleanup() and X509_STORE_get_cleanup() were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2009-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_VERIFY_PARAM_set_flags.html b/openssl-install/share/doc/openssl/html/man3/X509_VERIFY_PARAM_set_flags.html deleted file mode 100644 index 9f2dea68..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_VERIFY_PARAM_set_flags.html +++ /dev/null @@ -1,246 +0,0 @@ - - - - -X509_VERIFY_PARAM_set_flags - - - - - - - - - - -

NAME

- -

X509_VERIFY_PARAM_set_flags, X509_VERIFY_PARAM_clear_flags, X509_VERIFY_PARAM_get_flags, X509_VERIFY_PARAM_set_purpose, X509_VERIFY_PARAM_get_inh_flags, X509_VERIFY_PARAM_set_inh_flags, X509_VERIFY_PARAM_set_trust, X509_VERIFY_PARAM_set_depth, X509_VERIFY_PARAM_get_depth, X509_VERIFY_PARAM_set_auth_level, X509_VERIFY_PARAM_get_auth_level, X509_VERIFY_PARAM_set_time, X509_VERIFY_PARAM_get_time, X509_VERIFY_PARAM_add0_policy, X509_VERIFY_PARAM_set1_policies, X509_VERIFY_PARAM_get0_host, X509_VERIFY_PARAM_set1_host, X509_VERIFY_PARAM_add1_host, X509_VERIFY_PARAM_set_hostflags, X509_VERIFY_PARAM_get_hostflags, X509_VERIFY_PARAM_get0_peername, X509_VERIFY_PARAM_get0_email, X509_VERIFY_PARAM_set1_email, X509_VERIFY_PARAM_set1_ip, X509_VERIFY_PARAM_get1_ip_asc, X509_VERIFY_PARAM_set1_ip_asc - X509 verification parameters

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-int X509_VERIFY_PARAM_set_flags(X509_VERIFY_PARAM *param,
-                                unsigned long flags);
-int X509_VERIFY_PARAM_clear_flags(X509_VERIFY_PARAM *param,
-                                  unsigned long flags);
-unsigned long X509_VERIFY_PARAM_get_flags(const X509_VERIFY_PARAM *param);
-
-int X509_VERIFY_PARAM_set_inh_flags(X509_VERIFY_PARAM *param,
-                                    uint32_t flags);
-uint32_t X509_VERIFY_PARAM_get_inh_flags(const X509_VERIFY_PARAM *param);
-
-int X509_VERIFY_PARAM_set_purpose(X509_VERIFY_PARAM *param, int purpose);
-int X509_VERIFY_PARAM_set_trust(X509_VERIFY_PARAM *param, int trust);
-
-void X509_VERIFY_PARAM_set_time(X509_VERIFY_PARAM *param, time_t t);
-time_t X509_VERIFY_PARAM_get_time(const X509_VERIFY_PARAM *param);
-
-int X509_VERIFY_PARAM_add0_policy(X509_VERIFY_PARAM *param,
-                                  ASN1_OBJECT *policy);
-int X509_VERIFY_PARAM_set1_policies(X509_VERIFY_PARAM *param,
-                                    STACK_OF(ASN1_OBJECT) *policies);
-
-void X509_VERIFY_PARAM_set_depth(X509_VERIFY_PARAM *param, int depth);
-int X509_VERIFY_PARAM_get_depth(const X509_VERIFY_PARAM *param);
-
-void X509_VERIFY_PARAM_set_auth_level(X509_VERIFY_PARAM *param,
-                                      int auth_level);
-int X509_VERIFY_PARAM_get_auth_level(const X509_VERIFY_PARAM *param);
-
-char *X509_VERIFY_PARAM_get0_host(X509_VERIFY_PARAM *param, int n);
-int X509_VERIFY_PARAM_set1_host(X509_VERIFY_PARAM *param,
-                                const char *name, size_t namelen);
-int X509_VERIFY_PARAM_add1_host(X509_VERIFY_PARAM *param,
-                                const char *name, size_t namelen);
-void X509_VERIFY_PARAM_set_hostflags(X509_VERIFY_PARAM *param,
-                                     unsigned int flags);
-unsigned int X509_VERIFY_PARAM_get_hostflags(const X509_VERIFY_PARAM *param);
-char *X509_VERIFY_PARAM_get0_peername(const X509_VERIFY_PARAM *param);
-char *X509_VERIFY_PARAM_get0_email(X509_VERIFY_PARAM *param);
-int X509_VERIFY_PARAM_set1_email(X509_VERIFY_PARAM *param,
-                                 const char *email, size_t emaillen);
-char *X509_VERIFY_PARAM_get1_ip_asc(X509_VERIFY_PARAM *param);
-int X509_VERIFY_PARAM_set1_ip(X509_VERIFY_PARAM *param,
-                              const unsigned char *ip, size_t iplen);
-int X509_VERIFY_PARAM_set1_ip_asc(X509_VERIFY_PARAM *param, const char *ipasc);
- -

DESCRIPTION

- -

These functions manipulate the X509_VERIFY_PARAM structure associated with a certificate verification operation.

- -

The X509_VERIFY_PARAM_set_flags() function sets the flags in param by oring it with flags. See "VERIFICATION FLAGS" for a complete description of values the flags parameter can take.

- -

X509_VERIFY_PARAM_get_flags() returns the flags in param.

- -

X509_VERIFY_PARAM_get_inh_flags() returns the inheritance flags in param which specifies how verification flags are copied from one structure to another. X509_VERIFY_PARAM_set_inh_flags() sets the inheritance flags. See the INHERITANCE FLAGS section for a description of these bits.

- -

X509_VERIFY_PARAM_clear_flags() clears the flags flags in param.

- -

X509_VERIFY_PARAM_set_purpose() sets the verification purpose in param to purpose. This determines the acceptable purpose of the certificate chain, for example X509_PURPOSE_SSL_CLIENT. The purpose requirement is cleared if purpose is 0.

- -

X509_VERIFY_PARAM_set_trust() sets the trust setting in param to trust.

- -

X509_VERIFY_PARAM_set_time() sets the verification time in param to t. Normally the current time is used.

- -

X509_VERIFY_PARAM_add0_policy() adds policy to the acceptable policy set. Contrary to preexisting documentation of this function it does not enable policy checking.

- -

X509_VERIFY_PARAM_set1_policies() enables policy checking (it is disabled by default) and sets the acceptable policy set to policies. Any existing policy set is cleared. The policies parameter can be NULL to clear an existing policy set.

- -

X509_VERIFY_PARAM_set_depth() sets the maximum verification depth to depth. That is the maximum number of intermediate CA certificates that can appear in a chain. A maximal depth chain contains 2 more certificates than the limit, since neither the end-entity certificate nor the trust-anchor count against this limit. Thus a depth limit of 0 only allows the end-entity certificate to be signed directly by the trust anchor, while with a depth limit of 1 there can be one intermediate CA certificate between the trust anchor and the end-entity certificate.

- -

X509_VERIFY_PARAM_set_auth_level() sets the authentication security level to auth_level. The authentication security level determines the acceptable signature and public key strength when verifying certificate chains. For a certificate chain to validate, the public keys of all the certificates must meet the specified security level. The signature algorithm security level is not enforced for the chain's trust anchor certificate, which is either directly trusted or validated by means other than its signature. See SSL_CTX_set_security_level(3) for the definitions of the available levels. The default security level is -1, or "not set". At security level 0 or lower all algorithms are acceptable. Security level 1 requires at least 80-bit-equivalent security and is broadly interoperable, though it will, for example, reject MD5 signatures or RSA keys shorter than 1024 bits.

- -

X509_VERIFY_PARAM_get0_host() returns the nth expected DNS hostname that has been set using X509_VERIFY_PARAM_set1_host() or X509_VERIFY_PARAM_add1_host(). To obtain all names start with n = 0 and increment n as long as no NULL pointer is returned.

- -

X509_VERIFY_PARAM_set1_host() sets the expected DNS hostname to name clearing any previously specified hostname. If name is NULL, or empty the list of hostnames is cleared, and name checks are not performed on the peer certificate. If name is NUL-terminated, namelen may be zero, otherwise namelen must be set to the length of name.

- -

When a hostname is specified, certificate verification automatically invokes X509_check_host(3) with flags equal to the flags argument given to X509_VERIFY_PARAM_set_hostflags() (default zero). Applications are strongly advised to use this interface in preference to explicitly calling X509_check_host(3), hostname checks may be out of scope with the DANE-EE(3) certificate usage, and the internal check will be suppressed as appropriate when DANE verification is enabled.

- -

When the subject CommonName will not be ignored, whether as a result of the X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT host flag, or because no DNS subject alternative names are present in the certificate, any DNS name constraints in issuer certificates apply to the subject CommonName as well as the subject alternative name extension.

- -

When the subject CommonName will be ignored, whether as a result of the X509_CHECK_FLAG_NEVER_CHECK_SUBJECT host flag, or because some DNS subject alternative names are present in the certificate, DNS name constraints in issuer certificates will not be applied to the subject DN. As described in X509_check_host(3) the X509_CHECK_FLAG_NEVER_CHECK_SUBJECT flag takes precedence over the X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT flag.

- -

X509_VERIFY_PARAM_get_hostflags() returns any host flags previously set via a call to X509_VERIFY_PARAM_set_hostflags().

- -

X509_VERIFY_PARAM_add1_host() adds name as an additional reference identifier that can match the peer's certificate. Any previous names set via X509_VERIFY_PARAM_set1_host() or X509_VERIFY_PARAM_add1_host() are retained, no change is made if name is NULL or empty. When multiple names are configured, the peer is considered verified when any name matches.

- -

X509_VERIFY_PARAM_get0_peername() returns the DNS hostname or subject CommonName from the peer certificate that matched one of the reference identifiers. When wildcard matching is not disabled, or when a reference identifier specifies a parent domain (starts with ".") rather than a hostname, the peer name may be a wildcard name or a sub-domain of the reference identifier respectively. The return string is allocated by the library and is no longer valid once the associated param argument is freed. Applications must not free the return value.

- -

X509_VERIFY_PARAM_get0_email() returns the expected RFC822 email address.

- -

X509_VERIFY_PARAM_set1_email() sets the expected RFC822 email address to email. If email is NUL-terminated, emaillen may be zero, otherwise emaillen must be set to the length of email. When an email address is specified, certificate verification automatically invokes X509_check_email(3).

- -

X509_VERIFY_PARAM_get1_ip_asc() returns the expected IP address as a string. The caller is responsible for freeing it.

- -

X509_VERIFY_PARAM_set1_ip() sets the expected IP address to ip. The ip argument is in binary format, in network byte-order and iplen must be set to 4 for IPv4 and 16 for IPv6. When an IP address is specified, certificate verification automatically invokes X509_check_ip(3).

- -

X509_VERIFY_PARAM_set1_ip_asc() sets the expected IP address to ipasc. The ipasc argument is a NUL-terminal ASCII string: dotted decimal quad for IPv4 and colon-separated hexadecimal for IPv6. The condensed "::" notation is supported for IPv6 addresses.

- -

RETURN VALUES

- -

X509_VERIFY_PARAM_set_flags(), X509_VERIFY_PARAM_clear_flags(), X509_VERIFY_PARAM_set_inh_flags(), X509_VERIFY_PARAM_set_purpose(), X509_VERIFY_PARAM_set_trust(), X509_VERIFY_PARAM_add0_policy() X509_VERIFY_PARAM_set1_policies(), X509_VERIFY_PARAM_set1_host(), X509_VERIFY_PARAM_add1_host(), X509_VERIFY_PARAM_set1_email(), X509_VERIFY_PARAM_set1_ip() and X509_VERIFY_PARAM_set1_ip_asc() return 1 for success and 0 for failure.

- -

X509_VERIFY_PARAM_get0_host(), X509_VERIFY_PARAM_get0_email(), and X509_VERIFY_PARAM_get1_ip_asc(), return the string pointers specified above or NULL if the respective value has not been set or on error.

- -

X509_VERIFY_PARAM_get_flags() returns the current verification flags.

- -

X509_VERIFY_PARAM_get_hostflags() returns any current host flags.

- -

X509_VERIFY_PARAM_get_inh_flags() returns the current inheritance flags.

- -

X509_VERIFY_PARAM_set_time() and X509_VERIFY_PARAM_set_depth() do not return values.

- -

X509_VERIFY_PARAM_get_depth() returns the current verification depth.

- -

X509_VERIFY_PARAM_get_auth_level() returns the current authentication security level.

- -

VERIFICATION FLAGS

- -

The verification flags consists of zero or more of the following flags ored together.

- -

X509_V_FLAG_CRL_CHECK enables CRL checking for the certificate chain leaf certificate. An error occurs if a suitable CRL cannot be found.

- -

X509_V_FLAG_CRL_CHECK_ALL expands CRL checking to the entire certificate chain if X509_V_FLAG_CRL_CHECK has also been enabled, and is otherwise ignored.

- -

X509_V_FLAG_IGNORE_CRITICAL disables critical extension checking. By default any unhandled critical extensions in certificates or (if checked) CRLs result in a fatal error. If this flag is set unhandled critical extensions are ignored. WARNING setting this option for anything other than debugging purposes can be a security risk. Finer control over which extensions are supported can be performed in the verification callback.

- -

The X509_V_FLAG_X509_STRICT flag disables workarounds for some broken certificates and makes the verification strictly apply X509 rules.

- -

X509_V_FLAG_ALLOW_PROXY_CERTS enables proxy certificate verification.

- -

X509_V_FLAG_POLICY_CHECK enables certificate policy checking, by default no policy checking is performed. Additional information is sent to the verification callback relating to policy checking.

- -

X509_V_FLAG_EXPLICIT_POLICY, X509_V_FLAG_INHIBIT_ANY and X509_V_FLAG_INHIBIT_MAP set the require explicit policy, inhibit any policy and inhibit policy mapping flags respectively as defined in RFC3280. Policy checking is automatically enabled if any of these flags are set.

- -

If X509_V_FLAG_NOTIFY_POLICY is set and the policy checking is successful a special status code is set to the verification callback. This permits it to examine the valid policy tree and perform additional checks or simply log it for debugging purposes.

- -

By default some additional features such as indirect CRLs and CRLs signed by different keys are disabled. If X509_V_FLAG_EXTENDED_CRL_SUPPORT is set they are enabled.

- -

If X509_V_FLAG_USE_DELTAS is set delta CRLs (if present) are used to determine certificate status. If not set deltas are ignored.

- -

X509_V_FLAG_CHECK_SS_SIGNATURE requests checking the signature of the last certificate in a chain if the certificate is supposedly self-signed. This is prohibited and will result in an error if it is a non-conforming CA certificate with key usage restrictions not including the keyCertSign bit. By default this check is disabled because it doesn't add any additional security but in some cases applications might want to check the signature anyway. A side effect of not checking the self-signature of such a certificate is that disabled or unsupported message digests used for the signature are not treated as fatal errors.

- -

When X509_V_FLAG_TRUSTED_FIRST is set, which is always the case since OpenSSL 1.1.0, construction of the certificate chain in X509_verify_cert(3) searches the trust store for issuer certificates before searching the provided untrusted certificates. Local issuer certificates are often more likely to satisfy local security requirements and lead to a locally trusted root. This is especially important when some certificates in the trust store have explicit trust settings (see "TRUST SETTINGS" in openssl-x509(1)).

- -

The X509_V_FLAG_NO_ALT_CHAINS flag could have been used before OpenSSL 1.1.0 to suppress checking for alternative chains. By default, unless X509_V_FLAG_TRUSTED_FIRST is set, when building a certificate chain, if the first certificate chain found is not trusted, then OpenSSL will attempt to replace untrusted certificates supplied by the peer with certificates from the trust store to see if an alternative chain can be found that is trusted. As of OpenSSL 1.1.0, with X509_V_FLAG_TRUSTED_FIRST always set, this option has no effect.

- -

The X509_V_FLAG_PARTIAL_CHAIN flag causes non-self-signed certificates in the trust store to be treated as trust anchors, in the same way as self-signed root CA certificates. This makes it possible to trust self-issued certificates as well as certificates issued by an intermediate CA without having to trust their ancestor root CA. With OpenSSL 1.1.0 and later and X509_V_FLAG_PARTIAL_CHAIN set, chain construction stops as soon as the first certificate contained in the trust store is added to the chain, whether that certificate is a self-signed "root" certificate or a not self-signed "intermediate" or self-issued certificate. Thus, when an intermediate certificate is found in the trust store, the verified chain passed to callbacks may be shorter than it otherwise would be without the X509_V_FLAG_PARTIAL_CHAIN flag.

- -

The X509_V_FLAG_NO_CHECK_TIME flag suppresses checking the validity period of certificates and CRLs against the current time. If X509_VERIFY_PARAM_set_time() is used to specify a verification time, the check is not suppressed.

- -

INHERITANCE FLAGS

- -

These flags specify how parameters are "inherited" from one structure to another.

- -

If X509_VP_FLAG_ONCE is set then the current setting is zeroed after the next call.

- -

If X509_VP_FLAG_LOCKED is set then no values are copied. This overrides all of the following flags.

- -

If X509_VP_FLAG_DEFAULT is set then anything set in the source is copied to the destination. Effectively the values in "to" become default values which will be used only if nothing new is set in "from". This is the default.

- -

If X509_VP_FLAG_OVERWRITE is set then all value are copied across whether they are set or not. Flags is still Ored though.

- -

If X509_VP_FLAG_RESET_FLAGS is set then the flags value is copied instead of ORed.

- -

NOTES

- -

The above functions should be used to manipulate verification parameters instead of functions which work in specific structures such as X509_STORE_CTX_set_flags() which are likely to be deprecated in a future release.

- -

BUGS

- -

Delta CRL checking is currently primitive. Only a single delta can be used and (partly due to limitations of X509_STORE) constructed CRLs are not maintained.

- -

If CRLs checking is enable CRLs are expected to be available in the corresponding X509_STORE structure. No attempt is made to download CRLs from the CRL distribution points extension.

- -

EXAMPLES

- -

Enable CRL checking when performing certificate verification during SSL connections associated with an SSL_CTX structure ctx:

- -
X509_VERIFY_PARAM *param;
-
-param = X509_VERIFY_PARAM_new();
-X509_VERIFY_PARAM_set_flags(param, X509_V_FLAG_CRL_CHECK);
-SSL_CTX_set1_param(ctx, param);
-X509_VERIFY_PARAM_free(param);
- -

SEE ALSO

- -

X509_verify_cert(3), X509_check_host(3), X509_check_email(3), X509_check_ip(3), openssl-x509(1)

- -

HISTORY

- -

The X509_V_FLAG_NO_ALT_CHAINS flag was added in OpenSSL 1.1.0. The flag X509_V_FLAG_CB_ISSUER_CHECK was deprecated in OpenSSL 1.1.0 and has no effect.

- -

The X509_VERIFY_PARAM_get_hostflags() function was added in OpenSSL 1.1.0i.

- -

The X509_VERIFY_PARAM_get0_host(), X509_VERIFY_PARAM_get0_email(), and X509_VERIFY_PARAM_get1_ip_asc() functions were added in OpenSSL 3.0.

- -

The function X509_VERIFY_PARAM_add0_policy() was historically documented as enabling policy checking however the implementation has never done this. The documentation was changed to align with the implementation.

- -

COPYRIGHT

- -

Copyright 2009-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_add_cert.html b/openssl-install/share/doc/openssl/html/man3/X509_add_cert.html deleted file mode 100644 index 8b0a9281..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_add_cert.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -X509_add_cert - - - - - - - - - - -

NAME

- -

X509_add_cert, X509_add_certs - X509 certificate list addition functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_add_cert(STACK_OF(X509) *sk, X509 *cert, int flags);
-int X509_add_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int flags);
- -

DESCRIPTION

- -

X509_add_cert() adds a certificate cert to the given list sk. It is an error for the cert argument to be NULL.

- -

X509_add_certs() adds a list of certificate certs to the given list sk. The certs argument may be NULL, which implies no effect. It does not modify the list certs but in case the X509_ADD_FLAG_UP_REF flag (described below) is set the reference counters of those of its members added to sk are increased.

- -

Both these functions have a flags parameter, which is used to control details of the operation.

- -

The value X509_ADD_FLAG_DEFAULT, which equals 0, means no special semantics.

- -

If X509_ADD_FLAG_UP_REF is set then the reference counts of those certificates added successfully are increased.

- -

If X509_ADD_FLAG_PREPEND is set then the certificates are prepended to sk. By default they are appended to sk. In both cases the original order of the added certificates is preserved.

- -

If X509_ADD_FLAG_NO_DUP is set then certificates already contained in sk, which is determined using X509_cmp(3), are ignored.

- -

If X509_ADD_FLAG_NO_SS is set then certificates that are marked self-signed, which is determined using X509_self_signed(3), are ignored.

- -

RETURN VALUES

- -

Both functions return 1 for success and 0 for failure.

- -

NOTES

- -

If X509_add_certs() is used with the flags X509_ADD_FLAG_NO_DUP or X509_ADD_FLAG_NO_SS it is advisable to use also X509_ADD_FLAG_UP_REF because otherwise likely not for all members of the certs list the ownership is transferred to the list of certificates sk.

- -

Care should also be taken in case the certs argument equals sk.

- -

SEE ALSO

- -

X509_cmp(3) X509_self_signed(3)

- -

HISTORY

- -

The functions X509_add_cert() and X509_add_certs() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_check_ca.html b/openssl-install/share/doc/openssl/html/man3/X509_check_ca.html deleted file mode 100644 index 159220bf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_check_ca.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -X509_check_ca - - - - - - - - - - -

NAME

- -

X509_check_ca - check if given certificate is CA certificate

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-int X509_check_ca(X509 *cert);
- -

DESCRIPTION

- -

This function checks if given certificate is CA certificate (can be used to sign other certificates). The certificate must be a complete certificate otherwise an error is returned.

- -

RETURN VALUES

- -

Function return 0, if it is not CA certificate, 1 if it is proper X509v3 CA certificate with basicConstraints extension CA:TRUE, 3, if it is self-signed X509 v1 certificate, 4, if it is certificate with keyUsage extension with bit keyCertSign set, but without basicConstraints, and 5 if it has outdated Netscape Certificate Type extension telling that it is CA certificate.

- -

This function will also return 0 on error.

- -

Actually, any nonzero value means that this certificate could have been used to sign other certificates.

- -

SEE ALSO

- -

X509_verify_cert(3), X509_check_issued(3), X509_check_purpose(3)

- -

COPYRIGHT

- -

Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_check_host.html b/openssl-install/share/doc/openssl/html/man3/X509_check_host.html deleted file mode 100644 index 5530d945..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_check_host.html +++ /dev/null @@ -1,128 +0,0 @@ - - - - -X509_check_host - - - - - - - - - - -

NAME

- -

X509_check_host, X509_check_email, X509_check_ip, X509_check_ip_asc - X.509 certificate matching

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-int X509_check_host(X509 *, const char *name, size_t namelen,
-                    unsigned int flags, char **peername);
-int X509_check_email(X509 *, const char *address, size_t addresslen,
-                     unsigned int flags);
-int X509_check_ip(X509 *, const unsigned char *address, size_t addresslen,
-                  unsigned int flags);
-int X509_check_ip_asc(X509 *, const char *address, unsigned int flags);
- -

DESCRIPTION

- -

The certificate matching functions are used to check whether a certificate matches a given hostname, email address, or IP address. The validity of the certificate and its trust level has to be checked by other means.

- -

X509_check_host() checks if the certificate Subject Alternative Name (SAN) or Subject CommonName (CN) matches the specified hostname, which must be encoded in the preferred name syntax described in section 3.5 of RFC 1034. By default, wildcards are supported and they match only in the left-most label; but they may match part of that label with an explicit prefix or suffix. For example, by default, the host name "www.example.com" would match a certificate with a SAN or CN value of "*.example.com", "w*.example.com" or "*w.example.com".

- -

Per section 6.4.2 of RFC 6125, name values representing international domain names must be given in A-label form. The namelen argument must be the number of characters in the name string or zero in which case the length is calculated with strlen(name). When name starts with a dot (e.g. ".example.com"), it will be matched by a certificate valid for any sub-domain of name, (see also X509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS below).

- -

When the certificate is matched, and peername is not NULL, a pointer to a copy of the matching SAN or CN from the peer certificate is stored at the address passed in peername. The application is responsible for freeing the peername via OPENSSL_free() when it is no longer needed.

- -

X509_check_email() checks if the certificate matches the specified email address. The mailbox syntax of RFC 822 is supported, comments are not allowed, and no attempt is made to normalize quoted characters. The mailbox syntax of RFC 6531 is supported for SmtpUTF8Mailbox address in subjectAltName according to RFC 8398, with similar limitations as for RFC 822 syntax, and no attempt is made to convert from A-label to U-label before comparison. The addresslen argument must be the number of characters in the address string or zero in which case the length is calculated with strlen(address).

- -

X509_check_ip() checks if the certificate matches a specified IPv4 or IPv6 address. The address array is in binary format, in network byte order. The length is either 4 (IPv4) or 16 (IPv6). Only explicitly marked addresses in the certificates are considered; IP addresses stored in DNS names and Common Names are ignored. There are currently no flags that would affect the behavior of this call.

- -

X509_check_ip_asc() is similar, except that the NUL-terminated string address is first converted to the internal representation.

- -

The flags argument is usually 0. It can be the bitwise OR of the flags:

- -
- -
X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT,
-
- -
-
X509_CHECK_FLAG_NEVER_CHECK_SUBJECT,
-
- -
-
X509_CHECK_FLAG_NO_WILDCARDS,
-
- -
-
X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS,
-
- -
-
X509_CHECK_FLAG_MULTI_LABEL_WILDCARDS.
-
- -
-
X509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS.
-
- -
-
- -

The X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT flag causes the function to consider the subject DN even if the certificate contains at least one subject alternative name of the right type (DNS name or email address as appropriate); the default is to ignore the subject DN when at least one corresponding subject alternative names is present.

- -

The X509_CHECK_FLAG_NEVER_CHECK_SUBJECT flag causes the function to never consider the subject DN even if the certificate contains no subject alternative names of the right type (DNS name or email address as appropriate); the default is to use the subject DN when no corresponding subject alternative names are present. If both X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT and X509_CHECK_FLAG_NEVER_CHECK_SUBJECT are specified, the latter takes precedence and the subject DN is not checked for matching names.

- -

If set, X509_CHECK_FLAG_NO_WILDCARDS disables wildcard expansion; this only applies to X509_check_host.

- -

If set, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS suppresses support for "*" as wildcard pattern in labels that have a prefix or suffix, such as: "www*" or "*www"; this only applies to X509_check_host.

- -

If set, X509_CHECK_FLAG_MULTI_LABEL_WILDCARDS allows a "*" that constitutes the complete label of a DNS name (e.g. "*.example.com") to match more than one label in name; this flag only applies to X509_check_host.

- -

If set, X509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS restricts name values which start with ".", that would otherwise match any sub-domain in the peer certificate, to only match direct child sub-domains. Thus, for instance, with this flag set a name of ".example.com" would match a peer certificate with a DNS name of "www.example.com", but would not match a peer certificate with a DNS name of "www.sub.example.com"; this flag only applies to X509_check_host.

- -

RETURN VALUES

- -

The functions return 1 for a successful match, 0 for a failed match and -1 for an internal error: typically a memory allocation failure or an ASN.1 decoding error.

- -

All functions can also return -2 if the input is malformed. For example, X509_check_host() returns -2 if the provided name contains embedded NULs.

- -

NOTES

- -

Applications are encouraged to use X509_VERIFY_PARAM_set1_host() rather than explicitly calling X509_check_host(3). Hostname checks may be out of scope with the DANE-EE(3) certificate usage, and the internal checks will be suppressed as appropriate when DANE support is enabled.

- -

SEE ALSO

- -

SSL_get_verify_result(3), X509_VERIFY_PARAM_set1_host(3), X509_VERIFY_PARAM_add1_host(3), X509_VERIFY_PARAM_set1_email(3), X509_VERIFY_PARAM_set1_ip(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.0.2.

- -

COPYRIGHT

- -

Copyright 2012-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_check_issued.html b/openssl-install/share/doc/openssl/html/man3/X509_check_issued.html deleted file mode 100644 index ea6bca3e..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_check_issued.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -X509_check_issued - - - - - - - - - - -

NAME

- -

X509_check_issued - checks if certificate is apparently issued by another certificate

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-int X509_check_issued(X509 *issuer, X509 *subject);
- -

DESCRIPTION

- -

X509_check_issued() checks if certificate subject was apparently issued using (CA) certificate issuer. This function takes into account not only matching of the issuer field of subject with the subject field of issuer, but also compares all sub-fields of the authorityKeyIdentifier extension of subject, as far as present, with the respective subjectKeyIdentifier, serial number, and issuer fields of issuer, as far as present. It also checks if the keyUsage field (if present) of issuer allows certificate signing. It does not actually check the certificate signature. An error is returned if the issuer or the subject are incomplete certificates.

- -

RETURN VALUES

- -

X509_check_issued() returns X509_V_OK if all checks are successful or some X509_V_ERR* constant to indicate an error.

- -

SEE ALSO

- -

X509_verify_cert(3), X509_verify(3), X509_check_ca(3), openssl-verify(1), X509_self_signed(3)

- -

COPYRIGHT

- -

Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_check_private_key.html b/openssl-install/share/doc/openssl/html/man3/X509_check_private_key.html deleted file mode 100644 index f8f312dc..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_check_private_key.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -X509_check_private_key - - - - - - - - - - -

NAME

- -

X509_check_private_key, X509_REQ_check_private_key - check the consistency of a private key with the public key in an X509 certificate or certificate request

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_check_private_key(const X509 *cert, EVP_PKEY *pkey);
-
-int X509_REQ_check_private_key(X509_REQ *req, EVP_PKEY *pkey);
- -

DESCRIPTION

- -

X509_check_private_key() function checks the consistency of private key pkey with the public key in cert.

- -

X509_REQ_check_private_key() is equivalent to X509_check_private_key() except that req represents a certificate request of structure X509_REQ.

- -

RETURN VALUES

- -

X509_check_private_key() and X509_REQ_check_private_key() return 1 if the keys match each other, and 0 if not.

- -

If the key is invalid or an error occurred, the reason code can be obtained using ERR_get_error(3).

- -

BUGS

- -

The X509_check_private_key() and X509_REQ_check_private_key() functions do not check if pkey itself is indeed a private key or not. They merely compare the public materials (e.g., exponent and modulus of an RSA key) and/or key parameters (e.g. EC params of an EC key) of a key pair. So they also return success if pkey is a matching public key.

- -

SEE ALSO

- -

ERR_get_error(3)

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_check_purpose.html b/openssl-install/share/doc/openssl/html/man3/X509_check_purpose.html deleted file mode 100644 index cab2269f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_check_purpose.html +++ /dev/null @@ -1,114 +0,0 @@ - - - - -X509_check_purpose - - - - - - - - - - -

NAME

- -

X509_check_purpose - Check the purpose of a certificate

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-int X509_check_purpose(X509 *x, int id, int ca);
- -

DESCRIPTION

- -

This function checks if certificate x was created with the purpose represented by id. If ca is nonzero, then certificate x is checked to determine if it's a possible CA with various levels of certainty possibly returned. The certificate x must be a complete certificate otherwise the function returns an error.

- -

Below are the potential ID's that can be checked:

- -
# define X509_PURPOSE_SSL_CLIENT        1
-# define X509_PURPOSE_SSL_SERVER        2
-# define X509_PURPOSE_NS_SSL_SERVER     3
-# define X509_PURPOSE_SMIME_SIGN        4
-# define X509_PURPOSE_SMIME_ENCRYPT     5
-# define X509_PURPOSE_CRL_SIGN          6
-# define X509_PURPOSE_ANY               7
-# define X509_PURPOSE_OCSP_HELPER       8
-# define X509_PURPOSE_TIMESTAMP_SIGN    9
-# define X509_PURPOSE_CODE_SIGN        10
- -

The checks performed take into account the X.509 extensions keyUsage, extendedKeyUsage, and basicConstraints.

- -

RETURN VALUES

- -

For non-CA checks

- -
- -
-1 an error condition has occurred
-
- -
-
1 if the certificate was created to perform the purpose represented by id
-
- -
-
0 if the certificate was not created to perform the purpose represented by id
-
- -
-
- -

For CA checks the below integers could be returned with the following meanings:

- -
- -
-1 an error condition has occurred
-
- -
-
0 not a CA or does not have the purpose represented by id
-
- -
-
1 is a CA.
-
- -
-
2 Only possible in old versions of openSSL when basicConstraints are absent. New versions will not return this value. May be a CA
-
- -
-
3 basicConstraints absent but self signed V1.
-
- -
-
4 basicConstraints absent but keyUsage present and keyCertSign asserted.
-
- -
-
5 legacy Netscape specific CA Flags present
-
- -
-
- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_cmp.html b/openssl-install/share/doc/openssl/html/man3/X509_cmp.html deleted file mode 100644 index 213bc09f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_cmp.html +++ /dev/null @@ -1,81 +0,0 @@ - - - - -X509_cmp - - - - - - - - - - -

NAME

- -

X509_cmp, X509_NAME_cmp, X509_issuer_and_serial_cmp, X509_issuer_name_cmp, X509_subject_name_cmp, X509_CRL_cmp, X509_CRL_match - compare X509 certificates and related values

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_cmp(const X509 *a, const X509 *b);
-int X509_NAME_cmp(const X509_NAME *a, const X509_NAME *b);
-int X509_issuer_and_serial_cmp(const X509 *a, const X509 *b);
-int X509_issuer_name_cmp(const X509 *a, const X509 *b);
-int X509_subject_name_cmp(const X509 *a, const X509 *b);
-int X509_CRL_cmp(const X509_CRL *a, const X509_CRL *b);
-int X509_CRL_match(const X509_CRL *a, const X509_CRL *b);
- -

DESCRIPTION

- -

This set of functions are used to compare X509 objects, including X509 certificates, X509 CRL objects and various values in an X509 certificate.

- -

The X509_cmp() function compares two X509 objects indicated by parameters a and b. The comparison is based on the memcmp result of the hash values of two X509 objects and the canonical (DER) encoding values.

- -

The X509_NAME_cmp() function compares two X509_NAME objects indicated by parameters a and b, any of which may be NULL. The comparison is based on the memcmp result of the canonical (DER) encoding values of the two objects using i2d_X509_NAME(3). This procedure adheres to the matching rules for Distinguished Names (DN) given in RFC 4517 section 4.2.15 and RFC 5280 section 7.1. In particular, the order of Relative Distinguished Names (RDNs) is relevant. On the other hand, if an RDN is multi-valued, i.e., it contains a set of AttributeValueAssertions (AVAs), its members are effectively not ordered.

- -

The X509_issuer_and_serial_cmp() function compares the serial number and issuer values in the given X509 objects a and b.

- -

The X509_issuer_name_cmp(), X509_subject_name_cmp() and X509_CRL_cmp() functions are effectively wrappers of the X509_NAME_cmp() function. These functions compare issuer names and subject names of the objects, or issuers of X509_CRL objects, respectively.

- -

The X509_CRL_match() function compares two X509_CRL objects. Unlike the X509_CRL_cmp() function, this function compares the whole CRL content instead of just the issuer name.

- -

RETURN VALUES

- -

The X509 comparison functions return -1, 0, or 1 if object a is found to be less than, to match, or be greater than object b, respectively.

- -

X509_NAME_cmp(), X509_issuer_and_serial_cmp(), X509_issuer_name_cmp(), X509_subject_name_cmp(), X509_CRL_cmp(), and X509_CRL_match() may return -2 to indicate an error.

- -

NOTES

- -

These functions in fact utilize the underlying memcmp of the C library to do the comparison job. Data to be compared varies from DER encoding data, hash value or ASN1_STRING. The sign of the comparison can be used to order the objects but it does not have a special meaning in some cases.

- -

X509_NAME_cmp() and wrappers utilize the value -2 to indicate errors in some circumstances, which could cause confusion for the applications.

- -

SEE ALSO

- -

i2d_X509_NAME(3), i2d_X509(3)

- -

COPYRIGHT

- -

Copyright 2019-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_cmp_time.html b/openssl-install/share/doc/openssl/html/man3/X509_cmp_time.html deleted file mode 100644 index 0f3585fb..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_cmp_time.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -X509_cmp_time - - - - - - - - - - -

NAME

- -

X509_cmp_time, X509_cmp_current_time, X509_cmp_timeframe, X509_time_adj, X509_time_adj_ex, X509_gmtime_adj - X509 time functions

- -

SYNOPSIS

- -
int X509_cmp_time(const ASN1_TIME *asn1_time, time_t *in_tm);
-int X509_cmp_current_time(const ASN1_TIME *asn1_time);
-int X509_cmp_timeframe(const X509_VERIFY_PARAM *vpm,
-                       const ASN1_TIME *start, const ASN1_TIME *end);
-ASN1_TIME *X509_time_adj(ASN1_TIME *asn1_time, long offset_sec, time_t *in_tm);
-ASN1_TIME *X509_time_adj_ex(ASN1_TIME *asn1_time, int offset_day, long
-                            offset_sec, time_t *in_tm);
-ASN1_TIME *X509_gmtime_adj(ASN1_TIME *asn1_time, long offset_sec);
- -

DESCRIPTION

- -

X509_cmp_time() compares the ASN1_TIME in asn1_time with the time in <in_tm>.

- -

X509_cmp_current_time() compares the ASN1_TIME in asn1_time with the current time, expressed as time_t.

- -

X509_cmp_timeframe() compares the given time period with the reference time included in the verification parameters vpm if they are not NULL and contain X509_V_FLAG_USE_CHECK_TIME; else the current time is used as reference time.

- -

X509_time_adj_ex() sets the ASN1_TIME structure asn1_time to the time offset_day and offset_sec after in_tm.

- -

X509_time_adj() sets the ASN1_TIME structure asn1_time to the time offset_sec after in_tm. This method can only handle second offsets up to the capacity of long, so the newer X509_time_adj_ex() API should be preferred.

- -

In both methods, if asn1_time is NULL, a new ASN1_TIME structure is allocated and returned.

- -

In all methods, if in_tm is NULL, the current time, expressed as time_t, is used.

- -

asn1_time must satisfy the ASN1_TIME format mandated by RFC 5280, i.e., its format must be either YYMMDDHHMMSSZ or YYYYMMDDHHMMSSZ.

- -

X509_gmtime_adj() sets the ASN1_TIME structure asn1_time to the time offset_sec after the current time. It is equivalent to calling X509_time_adj() with the last parameter as NULL.

- -

BUGS

- -

Unlike many standard comparison functions, X509_cmp_time() and X509_cmp_current_time() return 0 on error.

- -

RETURN VALUES

- -

X509_cmp_time() and X509_cmp_current_time() return -1 if asn1_time is earlier than, or equal to, in_tm (resp. current time), and 1 otherwise. These methods return 0 on error.

- -

X509_cmp_timeframe() returns 0 if vpm is not NULL and the verification parameters do not contain X509_V_FLAG_USE_CHECK_TIME but do contain X509_V_FLAG_NO_CHECK_TIME. Otherwise it returns 1 if the end time is not NULL and the reference time (which has determined as stated above) is past the end time, -1 if the start time is not NULL and the reference time is before, else 0 to indicate that the reference time is in range (implying that the end time is not before the start time if both are present).

- -

X509_time_adj(), X509_time_adj_ex() and X509_gmtime_adj() return a pointer to the updated ASN1_TIME structure, and NULL on error.

- -

HISTORY

- -

X509_cmp_timeframe() was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_digest.html b/openssl-install/share/doc/openssl/html/man3/X509_digest.html deleted file mode 100644 index 33d95ce4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_digest.html +++ /dev/null @@ -1,90 +0,0 @@ - - - - -X509_digest - - - - - - - - - - -

NAME

- -

X509_digest, X509_digest_sig, X509_CRL_digest, X509_pubkey_digest, X509_NAME_digest, X509_REQ_digest, PKCS7_ISSUER_AND_SERIAL_digest - get digest of various objects

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_digest(const X509 *data, const EVP_MD *type, unsigned char *md,
-                unsigned int *len);
-ASN1_OCTET_STRING *X509_digest_sig(const X509 *cert,
-                                   EVP_MD **md_used, int *md_is_fallback);
-
-int X509_CRL_digest(const X509_CRL *data, const EVP_MD *type, unsigned char *md,
-                    unsigned int *len);
-
-int X509_pubkey_digest(const X509 *data, const EVP_MD *type,
-                       unsigned char *md, unsigned int *len);
-
-int X509_REQ_digest(const X509_REQ *data, const EVP_MD *type,
-                    unsigned char *md, unsigned int *len);
-
-int X509_NAME_digest(const X509_NAME *data, const EVP_MD *type,
-                     unsigned char *md, unsigned int *len);
-
-#include <openssl/pkcs7.h>
-
-int PKCS7_ISSUER_AND_SERIAL_digest(PKCS7_ISSUER_AND_SERIAL *data,
-                                   const EVP_MD *type, unsigned char *md,
-                                   unsigned int *len);
- -

DESCRIPTION

- -

X509_digest_sig() calculates a digest of the given certificate cert using the same hash algorithm as in its signature, if the digest is an integral part of the certificate signature algorithm identifier. Otherwise, a fallback hash algorithm is determined as follows: SHA512 if the signature algorithm is ED25519, SHAKE256 if it is ED448, otherwise SHA256. The output parameters are assigned as follows. Unless md_used is NULL, the hash algorithm used is provided in *md_used and must be freed by the caller (if it is not NULL). Unless md_is_fallback is NULL, the *md_is_fallback is set to 1 if the hash algorithm used is a fallback, otherwise to 0.

- -

X509_pubkey_digest() returns a digest of the DER representation of the public key in the specified X509 data object.

- -

All other functions described here return a digest of the DER representation of their entire data objects.

- -

The type parameter specifies the digest to be used, such as EVP_sha1(). The md is a pointer to the buffer where the digest will be copied and is assumed to be large enough; the constant EVP_MAX_MD_SIZE is suggested. The len parameter, if not NULL, points to a place where the digest size will be stored.

- -

RETURN VALUES

- -

X509_digest_sig() returns an ASN1_OCTET_STRING pointer on success, else NULL.

- -

All other functions described here return 1 for success and 0 for failure.

- -

SEE ALSO

- -

EVP_sha1(3)

- -

HISTORY

- -

The X509_digest_sig() function was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_dup.html b/openssl-install/share/doc/openssl/html/man3/X509_dup.html deleted file mode 100644 index 0083f721..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_dup.html +++ /dev/null @@ -1,96 +0,0 @@ - - - - -X509_dup - - - - - - - - - - -

NAME

- -

DECLARE_ASN1_FUNCTIONS, IMPLEMENT_ASN1_FUNCTIONS, ASN1_ITEM, ACCESS_DESCRIPTION_free, ACCESS_DESCRIPTION_new, ADMISSIONS_free, ADMISSIONS_new, ADMISSION_SYNTAX_free, ADMISSION_SYNTAX_new, ASIdOrRange_free, ASIdOrRange_new, ASIdentifierChoice_free, ASIdentifierChoice_new, ASIdentifiers_free, ASIdentifiers_new, ASRange_free, ASRange_new, AUTHORITY_INFO_ACCESS_free, AUTHORITY_INFO_ACCESS_new, AUTHORITY_KEYID_free, AUTHORITY_KEYID_new, BASIC_CONSTRAINTS_free, BASIC_CONSTRAINTS_new, CERTIFICATEPOLICIES_free, CERTIFICATEPOLICIES_new, CMS_ContentInfo_free, CMS_ContentInfo_new, CMS_ContentInfo_new_ex, CMS_ContentInfo_print_ctx, CMS_EnvelopedData_it, CMS_ReceiptRequest_free, CMS_ReceiptRequest_new, CMS_SignedData_free, CMS_SignedData_new, CRL_DIST_POINTS_free, CRL_DIST_POINTS_new, DIRECTORYSTRING_free, DIRECTORYSTRING_new, DISPLAYTEXT_free, DISPLAYTEXT_new, DIST_POINT_NAME_free, DIST_POINT_NAME_new, DIST_POINT_NAME_dup, DIST_POINT_free, DIST_POINT_new, DSAparams_dup, ECPARAMETERS_free, ECPARAMETERS_new, ECPKPARAMETERS_free, ECPKPARAMETERS_new, EDIPARTYNAME_free, EDIPARTYNAME_new, ESS_CERT_ID_dup, ESS_CERT_ID_free, ESS_CERT_ID_new, ESS_CERT_ID_V2_dup, ESS_CERT_ID_V2_free, ESS_CERT_ID_V2_new, ESS_ISSUER_SERIAL_dup, ESS_ISSUER_SERIAL_free, ESS_ISSUER_SERIAL_new, ESS_SIGNING_CERT_dup, ESS_SIGNING_CERT_free, ESS_SIGNING_CERT_it, ESS_SIGNING_CERT_new, ESS_SIGNING_CERT_V2_dup, ESS_SIGNING_CERT_V2_free, ESS_SIGNING_CERT_V2_it, ESS_SIGNING_CERT_V2_new, EXTENDED_KEY_USAGE_free, EXTENDED_KEY_USAGE_new, GENERAL_NAMES_free, GENERAL_NAMES_new, GENERAL_NAME_dup, GENERAL_NAME_free, GENERAL_NAME_new, GENERAL_SUBTREE_free, GENERAL_SUBTREE_new, OSSL_IETF_ATTR_SYNTAX_free, OSSL_IETF_ATTR_SYNTAX_it, OSSL_IETF_ATTR_SYNTAX_new, IPAddressChoice_free, IPAddressChoice_new, IPAddressFamily_free, IPAddressFamily_new, IPAddressOrRange_free, IPAddressOrRange_new, IPAddressRange_free, IPAddressRange_new, ISSUER_SIGN_TOOL_free, ISSUER_SIGN_TOOL_it, ISSUER_SIGN_TOOL_new, ISSUING_DIST_POINT_free, ISSUING_DIST_POINT_it, ISSUING_DIST_POINT_new, NAME_CONSTRAINTS_free, NAME_CONSTRAINTS_new, NAMING_AUTHORITY_free, NAMING_AUTHORITY_new, NETSCAPE_CERT_SEQUENCE_free, NETSCAPE_CERT_SEQUENCE_new, NETSCAPE_SPKAC_free, NETSCAPE_SPKAC_new, NETSCAPE_SPKI_free, NETSCAPE_SPKI_new, NOTICEREF_free, NOTICEREF_new, OCSP_BASICRESP_free, OCSP_BASICRESP_new, OCSP_CERTID_dup, OCSP_CERTID_new, OCSP_CERTSTATUS_free, OCSP_CERTSTATUS_new, OCSP_CRLID_free, OCSP_CRLID_new, OCSP_ONEREQ_free, OCSP_ONEREQ_new, OCSP_REQINFO_free, OCSP_REQINFO_new, OCSP_RESPBYTES_free, OCSP_RESPBYTES_new, OCSP_RESPDATA_free, OCSP_RESPDATA_new, OCSP_RESPID_free, OCSP_RESPID_new, OCSP_RESPONSE_new, OCSP_REVOKEDINFO_free, OCSP_REVOKEDINFO_new, OCSP_SERVICELOC_free, OCSP_SERVICELOC_new, OCSP_SIGNATURE_free, OCSP_SIGNATURE_new, OCSP_SINGLERESP_free, OCSP_SINGLERESP_new, OSSL_ATTRIBUTES_SYNTAX_free, OSSL_ATTRIBUTES_SYNTAX_it, OSSL_ATTRIBUTES_SYNTAX_new, OSSL_BASIC_ATTR_CONSTRAINTS_free, OSSL_BASIC_ATTR_CONSTRAINTS_it, OSSL_BASIC_ATTR_CONSTRAINTS_new, OSSL_CMP_ATAVS_new, OSSL_CMP_ATAVS_free, OSSL_CMP_ATAVS_it, OSSL_CMP_CRLSTATUS_free, OSSL_CMP_ITAV_dup, OSSL_CMP_ITAV_free, OSSL_CMP_MSG_dup, OSSL_CMP_MSG_it, OSSL_CMP_MSG_free, OSSL_CMP_PKIHEADER_free, OSSL_CMP_PKIHEADER_it, OSSL_CMP_PKIHEADER_new, OSSL_CMP_PKISI_dup, OSSL_CMP_PKISI_free, OSSL_CMP_PKISI_it, OSSL_CMP_PKISI_new, OSSL_CMP_PKISTATUS_it, OSSL_CRMF_CERTID_dup, OSSL_CRMF_CERTID_free, OSSL_CRMF_CERTID_it, OSSL_CRMF_CERTID_new, OSSL_CRMF_CERTTEMPLATE_free, OSSL_CRMF_CERTTEMPLATE_it, OSSL_CRMF_CERTTEMPLATE_new, OSSL_CRMF_CERTTEMPLATE_dup, OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup, OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free, OSSL_CRMF_ENCRYPTEDVALUE_free, OSSL_CRMF_ENCRYPTEDVALUE_it, OSSL_CRMF_ENCRYPTEDVALUE_new, OSSL_CRMF_MSGS_free, OSSL_CRMF_MSGS_it, OSSL_CRMF_MSGS_new, OSSL_CRMF_MSG_dup, OSSL_CRMF_MSG_free, OSSL_CRMF_MSG_it, OSSL_CRMF_MSG_new, OSSL_CRMF_PBMPARAMETER_free, OSSL_CRMF_PBMPARAMETER_it, OSSL_CRMF_PBMPARAMETER_new, OSSL_CRMF_PKIPUBLICATIONINFO_free, OSSL_CRMF_PKIPUBLICATIONINFO_it, OSSL_CRMF_PKIPUBLICATIONINFO_new, OSSL_CRMF_SINGLEPUBINFO_free, OSSL_CRMF_SINGLEPUBINFO_it, OSSL_CRMF_SINGLEPUBINFO_new, OSSL_TARGET_CERT_free, OSSL_TARGET_CERT_it, OSSL_TARGET_CERT_new, OSSL_TARGET_free, OSSL_TARGET_it, OSSL_TARGET_new, OSSL_TARGETING_INFORMATION_free, OSSL_TARGETING_INFORMATION_it, OSSL_TARGETING_INFORMATION_new, OSSL_TARGETS_free, OSSL_TARGETS_it, OSSL_TARGETS_new, OSSL_IETF_ATTR_SYNTAX_VALUE_free, OSSL_IETF_ATTR_SYNTAX_VALUE_it, OSSL_IETF_ATTR_SYNTAX_VALUE_new, OSSL_ISSUER_SERIAL_free, OSSL_ISSUER_SERIAL_new, OSSL_OBJECT_DIGEST_INFO_free, OSSL_OBJECT_DIGEST_INFO_new, OSSL_USER_NOTICE_SYNTAX_free, OSSL_USER_NOTICE_SYNTAX_new, OSSL_USER_NOTICE_SYNTAX_it, OTHERNAME_free, OTHERNAME_new, PBE2PARAM_free, PBE2PARAM_new, PBEPARAM_free, PBEPARAM_new, PBKDF2PARAM_free, PBKDF2PARAM_new, PBMAC1PARAM_free, PBMAC1PARAM_it, PBMAC1PARAM_new, PKCS12_BAGS_free, PKCS12_BAGS_new, PKCS12_MAC_DATA_free, PKCS12_MAC_DATA_new, PKCS12_SAFEBAG_free, PKCS12_SAFEBAG_new, PKCS12_free, PKCS12_new, PKCS7_DIGEST_free, PKCS7_DIGEST_new, PKCS7_ENCRYPT_free, PKCS7_ENCRYPT_new, PKCS7_ENC_CONTENT_free, PKCS7_ENC_CONTENT_new, PKCS7_ENVELOPE_free, PKCS7_ENVELOPE_new, PKCS7_ISSUER_AND_SERIAL_free, PKCS7_ISSUER_AND_SERIAL_new, PKCS7_RECIP_INFO_free, PKCS7_RECIP_INFO_new, PKCS7_SIGNED_free, PKCS7_SIGNED_new, PKCS7_SIGNER_INFO_free, PKCS7_SIGNER_INFO_new, PKCS7_SIGN_ENVELOPE_free, PKCS7_SIGN_ENVELOPE_new, PKCS7_dup, PKCS7_free, PKCS7_new_ex, PKCS7_new, PKCS7_print_ctx, PKCS8_PRIV_KEY_INFO_free, PKCS8_PRIV_KEY_INFO_new, PKEY_USAGE_PERIOD_free, PKEY_USAGE_PERIOD_new, POLICYINFO_free, POLICYINFO_new, POLICYQUALINFO_free, POLICYQUALINFO_new, POLICY_CONSTRAINTS_free, POLICY_CONSTRAINTS_new, POLICY_MAPPING_free, POLICY_MAPPING_new, PROFESSION_INFOS_free, PROFESSION_INFOS_new, PROFESSION_INFO_free, PROFESSION_INFO_new, PROXY_CERT_INFO_EXTENSION_free, PROXY_CERT_INFO_EXTENSION_new, PROXY_POLICY_free, PROXY_POLICY_new, RSAPrivateKey_dup, RSAPublicKey_dup, RSA_OAEP_PARAMS_free, RSA_OAEP_PARAMS_new, RSA_PSS_PARAMS_free, RSA_PSS_PARAMS_new, RSA_PSS_PARAMS_dup, SCRYPT_PARAMS_free, SCRYPT_PARAMS_new, SXNETID_free, SXNETID_new, SXNET_free, SXNET_new, TLS_FEATURE_free, TLS_FEATURE_new, TS_ACCURACY_dup, TS_ACCURACY_free, TS_ACCURACY_new, TS_MSG_IMPRINT_dup, TS_MSG_IMPRINT_free, TS_MSG_IMPRINT_new, TS_REQ_dup, TS_REQ_free, TS_REQ_new, TS_RESP_dup, TS_RESP_free, TS_RESP_new, TS_STATUS_INFO_dup, TS_STATUS_INFO_free, TS_STATUS_INFO_new, TS_TST_INFO_dup, TS_TST_INFO_free, TS_TST_INFO_new, USERNOTICE_free, USERNOTICE_new, X509_ACERT_dup, X509_ACERT_free, X509_ACERT_it, X509_ACERT_new, X509_ACERT_INFO_free, X509_ACERT_INFO_it, X509_ACERT_INFO_new, X509_ACERT_ISSUER_V2FORM_free, X509_ACERT_ISSUER_V2FORM_new, X509_ALGOR_free, X509_ALGOR_it, X509_ALGOR_new, X509_ATTRIBUTE_dup, X509_ATTRIBUTE_free, X509_ATTRIBUTE_new, X509_CERT_AUX_free, X509_CERT_AUX_new, X509_CINF_free, X509_CINF_new, X509_CRL_INFO_free, X509_CRL_INFO_new, X509_CRL_dup, X509_CRL_free, X509_CRL_new_ex, X509_CRL_new, X509_EXTENSION_dup, X509_EXTENSION_free, X509_EXTENSION_new, X509_NAME_ENTRY_dup, X509_NAME_ENTRY_free, X509_NAME_ENTRY_new, X509_NAME_dup, X509_NAME_free, X509_NAME_new, X509_REQ_INFO_free, X509_REQ_INFO_new, X509_REQ_dup, X509_REQ_free, X509_REQ_new, X509_REQ_new_ex, X509_REVOKED_dup, X509_REVOKED_free, X509_REVOKED_new, X509_SIG_free, X509_SIG_new, X509_VAL_free, X509_VAL_new, X509_dup, - ASN1 object utilities

- -

SYNOPSIS

- -
#include <openssl/asn1t.h>
-
-DECLARE_ASN1_FUNCTIONS(type)
-IMPLEMENT_ASN1_FUNCTIONS(stname)
-
-typedef struct ASN1_ITEM_st ASN1_ITEM;
-
-extern const ASN1_ITEM TYPE_it;
-TYPE *TYPE_new(void);
-TYPE *TYPE_dup(const TYPE *a);
-void TYPE_free(TYPE *a);
-int TYPE_print_ctx(BIO *out, TYPE *a, int indent, const ASN1_PCTX *pctx);
- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
DSA *DSAparams_dup(const DSA *dsa);
-RSA *RSAPrivateKey_dup(const RSA *rsa);
-RSA *RSAPublicKey_dup(const RSA *rsa);
- -

DESCRIPTION

- -

In the description below, TYPE is used as a placeholder for any of the OpenSSL datatypes, such as X509.

- -

The OpenSSL ASN1 parsing library templates are like a data-driven bytecode interpreter. Every ASN1 object as a global variable, TYPE_it, that describes the item such as its fields. (On systems which cannot export variables from shared libraries, the global is instead a function which returns a pointer to a static variable.

- -

The macro DECLARE_ASN1_FUNCTIONS() is typically used in header files to generate the function declarations.

- -

The macro IMPLEMENT_ASN1_FUNCTIONS() is used once in a source file to generate the function bodies.

- -

TYPE_new() allocates an empty object of the indicated type. The object returned must be released by calling TYPE_free().

- -

TYPE_new_ex() is similar to TYPE_new() but also passes the library context libctx and the property query propq to use when retrieving algorithms from providers. This created object can then be used when loading binary data using d2i_TYPE().

- -

TYPE_dup() copies an existing object, leaving it untouched. Note, however, that the internal representation of the object may contain (besides the ASN.1 structure) further data, which is not copied. For instance, an X509 object usually is augmented by cached information on X.509v3 extensions, etc., and losing it can lead to wrong validation results. To avoid such situations, better use TYPE_up_ref() if available. For the case of X509 objects, an alternative to using X509_up_ref(3) may be to still call TYPE_dup(), e.g., copied_cert = X509_dup(cert), followed by X509_check_purpose(copied_cert, -1, 0), which re-builds the cached data.

- -

TYPE_free() releases the object and all pointers and sub-objects within it. If the argument is NULL, nothing is done.

- -

TYPE_print_ctx() prints the object a on the specified BIO out. Each line will be prefixed with indent spaces. The pctx specifies the printing context and is for internal use; use NULL to get the default behavior. If a print function is user-defined, then pass in any pctx down to any nested calls.

- -

RETURN VALUES

- -

TYPE_new(), TYPE_new_ex() and TYPE_dup() return a pointer to the object or NULL on failure.

- -

TYPE_print_ctx() returns 1 on success or zero on failure.

- -

SEE ALSO

- -

X509_up_ref(3)

- -

HISTORY

- -

The functions X509_REQ_new_ex(), X509_CRL_new_ex(), PKCS7_new_ex() and CMS_ContentInfo_new_ex() were added in OpenSSL 3.0.

- -

The functions DSAparams_dup(), RSAPrivateKey_dup() and RSAPublicKey_dup() were deprecated in 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get0_distinguishing_id.html b/openssl-install/share/doc/openssl/html/man3/X509_get0_distinguishing_id.html deleted file mode 100644 index a3b2db9a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get0_distinguishing_id.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -X509_get0_distinguishing_id - - - - - - - - - - -

NAME

- -

X509_get0_distinguishing_id, X509_set0_distinguishing_id, X509_REQ_get0_distinguishing_id, X509_REQ_set0_distinguishing_id - get or set the Distinguishing ID for certificate operations

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-ASN1_OCTET_STRING *X509_get0_distinguishing_id(X509 *x);
-void X509_set0_distinguishing_id(X509 *x, ASN1_OCTET_STRING *distid);
-ASN1_OCTET_STRING *X509_REQ_get0_distinguishing_id(X509_REQ *x);
-void X509_REQ_set0_distinguishing_id(X509_REQ *x, ASN1_OCTET_STRING *distid);
- -

DESCRIPTION

- -

The Distinguishing ID is defined in FIPS 196 as follows:

- -
- -
Distinguishing identifier
-
- -

Information which unambiguously distinguishes an entity in the authentication process.

- -
-
- -

The SM2 signature algorithm requires a Distinguishing ID value when generating and verifying a signature, but the Ddistinguishing ID may also find other uses. In the context of SM2, the Distinguishing ID is often referred to as the "SM2 ID".

- -

For the purpose off verifying a certificate or a certification request, a Distinguishing ID may be attached to it, so functions like X509_verify(3) or X509_REQ_verify(3) have easy access to that identity for signature verification.

- -

X509_get0_distinguishing_id() gets the Distinguishing ID value of a certificate x by returning an ASN1_OCTET_STRING object which should not be freed by the caller.

- -

X509_set0_distinguishing_id() assigns distid to the certificate x. Calling this function transfers the memory management of the value to the X509 object, and therefore the value that has been passed in should not be freed by the caller after this function has been called.

- -

X509_REQ_get0_distinguishing_id() and X509_REQ_set0_distinguishing_id() have the same functionality as X509_get0_distinguishing_id() and X509_set0_distinguishing_id() except that they deal with X509_REQ objects instead of X509.

- -

RETURN VALUES

- -

X509_set0_distinguishing_id() and X509_REQ_set0_distinguishing_id() do not return a value.

- -

SEE ALSO

- -

X509_verify(3), SM2(7)

- -

COPYRIGHT

- -

Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get0_notBefore.html b/openssl-install/share/doc/openssl/html/man3/X509_get0_notBefore.html deleted file mode 100644 index 6c529717..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get0_notBefore.html +++ /dev/null @@ -1,103 +0,0 @@ - - - - -X509_get0_notBefore - - - - - - - - - - -

NAME

- -

X509_get0_notBefore, X509_getm_notBefore, X509_get0_notAfter, X509_getm_notAfter, X509_set1_notBefore, X509_set1_notAfter, X509_ACERT_get0_notBefore, X509_ACERT_get0_notAfter, X509_ACERT_set1_notBefore, X509_ACERT_set1_notAfter, X509_CRL_get0_lastUpdate, X509_CRL_get0_nextUpdate, X509_CRL_set1_lastUpdate, X509_CRL_set1_nextUpdate - get or set certificate or CRL dates

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-const ASN1_TIME *X509_get0_notBefore(const X509 *x);
-const ASN1_TIME *X509_get0_notAfter(const X509 *x);
-
-ASN1_TIME *X509_getm_notBefore(const X509 *x);
-ASN1_TIME *X509_getm_notAfter(const X509 *x);
-
-int X509_set1_notBefore(X509 *x, const ASN1_TIME *tm);
-int X509_set1_notAfter(X509 *x, const ASN1_TIME *tm);
-
-const ASN1_GENERALIZEDTIME *X509_ACERT_get0_notBefore(const X509 *x);
-const ASN1_GENERALIZEDTIME *X509_ACERT_get0_notAfter(const X509 *x);
-
-int X509_ACERT_set1_notBefore(X509_ACERT *x, const ASN1_GENERALIZEDTIME *tm);
-int X509_ACERT_set1_notAfter(X509_ACERT *x, const ASN1_GENERALIZEDTIME *tm);
-
-const ASN1_TIME *X509_CRL_get0_lastUpdate(const X509_CRL *crl);
-const ASN1_TIME *X509_CRL_get0_nextUpdate(const X509_CRL *crl);
-
-int X509_CRL_set1_lastUpdate(X509_CRL *x, const ASN1_TIME *tm);
-int X509_CRL_set1_nextUpdate(X509_CRL *x, const ASN1_TIME *tm);
- -

DESCRIPTION

- -

X509_get0_notBefore() and X509_get0_notAfter() return the notBefore and notAfter fields of certificate x respectively. The value returned is an internal pointer which must not be freed up after the call.

- -

X509_getm_notBefore() and X509_getm_notAfter() are similar to X509_get0_notBefore() and X509_get0_notAfter() except they return non-constant mutable references to the associated date field of the certificate.

- -

X509_set1_notBefore() and X509_set1_notAfter() set the notBefore and notAfter fields of x to tm. Ownership of the passed parameter tm is not transferred by these functions so it must be freed up after the call.

- -

X509_ACERT_get0_notBefore() and X509_ACERT_get0_notAfter() return the notBefore and notAfter fields of certificate x respectively. returned is an internal pointer which must not be freed up after the call.

- -

X509_ACERT_set1_notBefore() and X509_ACERT_set1_notAfter() set the notBefore and notAfter fields of x to tm. Ownership of the passed parameter tm is not transferred by these functions so it must be freed up after the call.

- -

X509_CRL_get0_lastUpdate() and X509_CRL_get0_nextUpdate() return the lastUpdate and nextUpdate fields of crl. The value returned is an internal pointer which must not be freed up after the call. If the nextUpdate field is absent from crl then NULL is returned.

- -

X509_CRL_set1_lastUpdate() and X509_CRL_set1_nextUpdate() set the lastUpdate and nextUpdate fields of crl to tm. Ownership of the passed parameter tm is not transferred by these functions so it must be freed up after the call. For X509_CRL_set1_nextUpdate() the tm argument may be NULL, which implies removal of the optional nextUpdate field.

- -

RETURN VALUES

- -

X509_get0_notBefore(), X509_get0_notAfter() and X509_CRL_get0_lastUpdate() return a pointer to an ASN1_TIME structure.

- -

X509_CRL_get0_lastUpdate() return a pointer to an ASN1_TIME structure or NULL if the lastUpdate field is absent.

- -

X509_set1_notBefore(), X509_set1_notAfter(), X509_CRL_set1_lastUpdate() and X509_CRL_set1_nextUpdate() return 1 for success or 0 for failure.

- -

NOTES

- -

Unlike the X509 and X509_CRL routines, the X509_ACERT routines use the ASN1_GENERALIZEDTIME format instead of ASN1_TIME for holding time data.

- -

SEE ALSO

- -

d2i_X509(3), ASN1_GENERALIZEDTIME_check(3) ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

HISTORY

- -

These functions are available in all versions of OpenSSL.

- -

X509_get_notBefore() and X509_get_notAfter() were deprecated in OpenSSL 1.1.0

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get0_signature.html b/openssl-install/share/doc/openssl/html/man3/X509_get0_signature.html deleted file mode 100644 index 7b7b32b2..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get0_signature.html +++ /dev/null @@ -1,125 +0,0 @@ - - - - -X509_get0_signature - - - - - - - - - - -

NAME

- -

X509_get0_signature, X509_REQ_set0_signature, X509_REQ_set1_signature_algo, X509_get_signature_nid, X509_get0_tbs_sigalg, X509_REQ_get0_signature, X509_REQ_get_signature_nid, X509_CRL_get0_signature, X509_CRL_get_signature_nid, X509_ACERT_get0_signature, X509_ACERT_get0_info_sigalg, X509_ACERT_get_signature_nid, X509_get_signature_info, X509_SIG_INFO_get, X509_SIG_INFO_set - signature information

- -

SYNOPSIS

- -
 #include <openssl/x509.h>
-
- void X509_get0_signature(const ASN1_BIT_STRING **psig,
-                          const X509_ALGOR **palg,
-                          const X509 *x);
- void X509_REQ_set0_signature(X509_REQ *req, ASN1_BIT_STRING *psig);
- int X509_REQ_set1_signature_algo(X509_REQ *req, X509_ALGOR *palg);
- int X509_get_signature_nid(const X509 *x);
- const X509_ALGOR *X509_get0_tbs_sigalg(const X509 *x);
-
- void X509_REQ_get0_signature(const X509_REQ *crl,
-                              const ASN1_BIT_STRING **psig,
-                              const X509_ALGOR **palg);
- int X509_REQ_get_signature_nid(const X509_REQ *crl);
-
- const X509_ALGOR *X509_ACERT_get0_info_sigalg(const X509_ACERT *x);
-
- void X509_CRL_get0_signature(const X509_CRL *crl,
-                              const ASN1_BIT_STRING **psig,
-                              const X509_ALGOR **palg);
- int X509_CRL_get_signature_nid(const X509_CRL *crl);
-
- int X509_get_signature_info(X509 *x, int *mdnid, int *pknid, int *secbits,
-                             uint32_t *flags);
-
- int X509_SIG_INFO_get(const X509_SIG_INFO *siginf, int *mdnid, int *pknid,
-                      int *secbits, uint32_t *flags);
- void X509_SIG_INFO_set(X509_SIG_INFO *siginf, int mdnid, int pknid,
-                        int secbits, uint32_t flags);
-
- #include <openssl/x509_acert.h>
-
- void X509_ACERT_get0_signature(const X509_ACERT *x,
-                                const ASN1_BIT_STRING **psig,
-                                const X509_ALGOR **palg);
- int X509_ACERT_get_signature_nid(const X509_ACERT *x);
-=head1 DESCRIPTION
- -

X509_get0_signature() sets *psig to the signature of x and *palg to the signature algorithm of x. The values returned are internal pointers which MUST NOT be freed up after the call.

- -

X509_set0_signature() and X509_REQ_set1_signature_algo() are the equivalent setters for the two values of X509_get0_signature().

- -

X509_get0_tbs_sigalg() returns the signature algorithm in the signed portion of x.

- -

X509_get_signature_nid() returns the NID corresponding to the signature algorithm of x.

- -

X509_REQ_get0_signature(), X509_REQ_get_signature_nid() X509_CRL_get0_signature() and X509_CRL_get_signature_nid() perform the same function for certificate requests and CRLs.

- -

X509_ACERT_get0_signature(), X509_ACERT_get_signature_nid() and X509_ACERT_get0_info_sigalg() perform the same function for attribute certificates.

- -

X509_get_signature_info() retrieves information about the signature of certificate x. The NID of the signing digest is written to *mdnid, the public key algorithm to *pknid, the effective security bits to *secbits and flag details to *flags. Any of the parameters can be set to NULL if the information is not required.

- -

X509_SIG_INFO_get() and X509_SIG_INFO_set() get and set information about a signature in an X509_SIG_INFO structure. They are only used by implementations of algorithms which need to set custom signature information: most applications will never need to call them.

- -

NOTES

- -

These functions provide lower level access to signatures in certificates where an application wishes to analyse or generate a signature in a form where X509_sign() et al is not appropriate (for example a non standard or unsupported format).

- -

The security bits returned by X509_get_signature_info() refers to information available from the certificate signature (such as the signing digest). In some cases the actual security of the signature is less because the signing key is less secure: for example a certificate signed using SHA-512 and a 1024 bit RSA key.

- -

RETURN VALUES

- -

X509_get_signature_nid(), X509_REQ_get_signature_nid() and X509_CRL_get_signature_nid() return a NID.

- -

X509_get0_signature(), X509_REQ_get0_signature() and X509_CRL_get0_signature() do not return values.

- -

X509_get_signature_info() returns 1 if the signature information returned is valid or 0 if the information is not available (e.g. unknown algorithms or malformed parameters).

- -

X509_REQ_set1_signature_algo() returns 0 on success; or 1 on an error (e.g. null ALGO pointer). X509_REQ_set0_signature does not return an error value.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

HISTORY

- -

The X509_get0_signature() and X509_get_signature_nid() functions were added in OpenSSL 1.0.2.

- -

The X509_REQ_get0_signature(), X509_REQ_get_signature_nid(), X509_CRL_get0_signature() and X509_CRL_get_signature_nid() were added in OpenSSL 1.1.0.

- -

The X509_REQ_set0_signature() and X509_REQ_set1_signature_algo() were added in OpenSSL 1.1.1e.

- -

The X509_ACERT_get0_signature(), X509_ACERT_get0_info_sigalg() and X509_ACERT_get_signature_nid() functions were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get0_uids.html b/openssl-install/share/doc/openssl/html/man3/X509_get0_uids.html deleted file mode 100644 index 92f57cc5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get0_uids.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -X509_get0_uids - - - - - - - - - - -

NAME

- -

X509_get0_uids, X509_ACERT_get0_issuerUID - get certificate and attribute certificate unique identifiers

- -

SYNOPSIS

- -
 #include <openssl/x509.h>
-
- void X509_get0_uids(const X509 *x, const ASN1_BIT_STRING **piuid,
-                     const ASN1_BIT_STRING **psuid);
-
- #include <openssl/x509_acert.h>
-
- ASN1_BIT_STRING *X509_ACERT_get0_issuerUID(X509_ACERT *x);
-=head1 DESCRIPTION
- -

X509_get0_uids() sets *piuid and *psuid to the issuer and subject unique identifiers of certificate x or NULL if the fields are not present.

- -

X509_ACERT_get0_issuerUID() returns the issuer unique identifier of the attribute certificate x or NULL if the field is not present.

- -

NOTES

- -

The issuer and subject unique identifier fields are very rarely encountered in practice outside test cases.

- -

RETURN VALUES

- -

X509_get0_uids() does not return a value.

- -

X509_ACERT_get0_issuerUID() returns a unique identifier on success or NULL on failure.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

HISTORY

- -

X509_get0_uids() was added in OpenSSL 1.1.0.

- -

X509_ACERT_get0_issuerUID() was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get_default_cert_file.html b/openssl-install/share/doc/openssl/html/man3/X509_get_default_cert_file.html deleted file mode 100644 index 8dbefabf..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get_default_cert_file.html +++ /dev/null @@ -1,71 +0,0 @@ - - - - -X509_get_default_cert_file - - - - - - - - - - -

NAME

- -

X509_get_default_cert_file, X509_get_default_cert_file_env, X509_get_default_cert_dir, X509_get_default_cert_dir_env - retrieve default locations for trusted CA certificates

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-const char *X509_get_default_cert_file(void);
-const char *X509_get_default_cert_dir(void);
-
-const char *X509_get_default_cert_file_env(void);
-const char *X509_get_default_cert_dir_env(void);
- -

DESCRIPTION

- -

The X509_get_default_cert_file() function returns the default path to a file containing trusted CA certificates. OpenSSL will use this as the default path when it is asked to load trusted CA certificates from a file and no other path is specified. If the file exists, CA certificates are loaded from the file.

- -

The X509_get_default_cert_dir() function returns a default delimeter-separated list of paths to a directories containing trusted CA certificates named in the hashed format. OpenSSL will use this as the default list of paths when it is asked to load trusted CA certificates from a directory and no other path is specified. If a given directory in the list exists, OpenSSL attempts to lookup CA certificates in this directory by calculating a filename based on a hash of the certificate's subject name.

- -

X509_get_default_cert_file_env() returns an environment variable name which is recommended to specify a nondefault value to be used instead of the value returned by X509_get_default_cert_file(). The value returned by the latter function is not affected by these environment variables; you must check for this environment variable yourself, using this function to retrieve the correct environment variable name. If an environment variable is not set, the value returned by the X509_get_default_cert_file() should be used.

- -

X509_get_default_cert_dir_env() returns the environment variable name which is recommended to specify a nondefault value to be used instead of the value returned by X509_get_default_cert_dir(). The value specified by this environment variable can also be a store URI (but see BUGS below).

- -

BUGS

- -

By default (for example, when X509_STORE_set_default_paths(3) is used), the environment variable name returned by X509_get_default_cert_dir_env() is interpreted both as a delimiter-separated list of paths, and as a store URI. This is ambiguous. For example, specifying a value of "file:///etc/certs" would cause instantiation of the "file" store provided as part of the default provider, but would also cause an X509_LOOKUP_hash_dir(3) instance to look for certificates in the directory "file" (relative to the current working directory) and the directory "///etc/certs". This can be avoided by avoiding use of the environment variable mechanism and using other methods to construct X509_LOOKUP instances.

- -

RETURN VALUES

- -

These functions return pointers to constant strings with static storage duration.

- -

SEE ALSO

- -

X509_LOOKUP(3), SSL_CTX_set_default_verify_file(3), SSL_CTX_set_default_verify_dir(3), SSL_CTX_set_default_verify_store(3), SSL_CTX_load_verify_file(3), SSL_CTX_load_verify_dir(3), SSL_CTX_load_verify_store(3), SSL_CTX_load_verify_locations(3)

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get_extension_flags.html b/openssl-install/share/doc/openssl/html/man3/X509_get_extension_flags.html deleted file mode 100644 index 1a189aa9..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get_extension_flags.html +++ /dev/null @@ -1,190 +0,0 @@ - - - - -X509_get_extension_flags - - - - - - - - - - -

NAME

- -

X509_get0_subject_key_id, X509_get0_authority_key_id, X509_get0_authority_issuer, X509_get0_authority_serial, X509_get_pathlen, X509_get_extension_flags, X509_get_key_usage, X509_get_extended_key_usage, X509_set_proxy_flag, X509_set_proxy_pathlen, X509_get_proxy_pathlen - retrieve certificate extension data

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-long X509_get_pathlen(X509 *x);
-uint32_t X509_get_extension_flags(X509 *x);
-uint32_t X509_get_key_usage(X509 *x);
-uint32_t X509_get_extended_key_usage(X509 *x);
-const ASN1_OCTET_STRING *X509_get0_subject_key_id(X509 *x);
-const ASN1_OCTET_STRING *X509_get0_authority_key_id(X509 *x);
-const GENERAL_NAMES *X509_get0_authority_issuer(X509 *x);
-const ASN1_INTEGER *X509_get0_authority_serial(X509 *x);
-void X509_set_proxy_flag(X509 *x);
-void X509_set_proxy_pathlen(int l);
-long X509_get_proxy_pathlen(X509 *x);
- -

DESCRIPTION

- -

These functions retrieve information related to commonly used certificate extensions.

- -

X509_get_pathlen() retrieves the path length extension from a certificate. This extension is used to limit the length of a cert chain that may be issued from that CA.

- -

X509_get_extension_flags() retrieves general information about a certificate, it will return one or more of the following flags ored together.

- -
- -
EXFLAG_V1
-
- -

The certificate is an obsolete version 1 certificate.

- -
-
EXFLAG_BCONS
-
- -

The certificate contains a basic constraints extension.

- -
-
EXFLAG_CA
-
- -

The certificate contains basic constraints and asserts the CA flag.

- -
-
EXFLAG_PROXY
-
- -

The certificate is a valid proxy certificate.

- -
-
EXFLAG_SI
-
- -

The certificate is self issued (that is subject and issuer names match).

- -
-
EXFLAG_SS
-
- -

The subject and issuer names match and extension values imply it is self signed.

- -
-
EXFLAG_FRESHEST
-
- -

The freshest CRL extension is present in the certificate.

- -
-
EXFLAG_CRITICAL
-
- -

The certificate contains an unhandled critical extension.

- -
-
EXFLAG_INVALID
-
- -

Some certificate extension values are invalid or inconsistent. The certificate should be rejected. This bit may also be raised after an out-of-memory error while processing the X509 object, so it may not be related to the processed ASN1 object itself.

- -
-
EXFLAG_NO_FINGERPRINT
-
- -

Failed to compute the internal SHA1 hash value of the certificate or CRL. This may be due to malloc failure or because no SHA1 implementation was found.

- -
-
EXFLAG_INVALID_POLICY
-
- -

The NID_certificate_policies certificate extension is invalid or inconsistent. The certificate should be rejected. This bit may also be raised after an out-of-memory error while processing the X509 object, so it may not be related to the processed ASN1 object itself.

- -
-
EXFLAG_KUSAGE
-
- -

The certificate contains a key usage extension. The value can be retrieved using X509_get_key_usage().

- -
-
EXFLAG_XKUSAGE
-
- -

The certificate contains an extended key usage extension. The value can be retrieved using X509_get_extended_key_usage().

- -
-
- -

X509_get_key_usage() returns the value of the key usage extension. If key usage is present will return zero or more of the flags: KU_DIGITAL_SIGNATURE, KU_NON_REPUDIATION, KU_KEY_ENCIPHERMENT, KU_DATA_ENCIPHERMENT, KU_KEY_AGREEMENT, KU_KEY_CERT_SIGN, KU_CRL_SIGN, KU_ENCIPHER_ONLY or KU_DECIPHER_ONLY corresponding to individual key usage bits. If key usage is absent then UINT32_MAX is returned.

- -

X509_get_extended_key_usage() returns the value of the extended key usage extension. If extended key usage is present it will return zero or more of the flags: XKU_SSL_SERVER, XKU_SSL_CLIENT, XKU_SMIME, XKU_CODE_SIGN XKU_OCSP_SIGN, XKU_TIMESTAMP, XKU_DVCS or XKU_ANYEKU. These correspond to the OIDs id-kp-serverAuth, id-kp-clientAuth, id-kp-emailProtection, id-kp-codeSigning, id-kp-OCSPSigning, id-kp-timeStamping, id-kp-dvcs and anyExtendedKeyUsage respectively. Additionally XKU_SGC is set if either Netscape or Microsoft SGC OIDs are present.

- -

X509_get0_subject_key_id() returns an internal pointer to the subject key identifier of x as an ASN1_OCTET_STRING or NULL if the extension is not present or cannot be parsed.

- -

X509_get0_authority_key_id() returns an internal pointer to the authority key identifier of x as an ASN1_OCTET_STRING or NULL if the extension is not present or cannot be parsed.

- -

X509_get0_authority_issuer() returns an internal pointer to the authority certificate issuer of x as a stack of GENERAL_NAME structures or NULL if the extension is not present or cannot be parsed.

- -

X509_get0_authority_serial() returns an internal pointer to the authority certificate serial number of x as an ASN1_INTEGER or NULL if the extension is not present or cannot be parsed.

- -

X509_set_proxy_flag() marks the certificate with the EXFLAG_PROXY flag. This is for the users who need to mark non-RFC3820 proxy certificates as such, as OpenSSL only detects RFC3820 compliant ones.

- -

X509_set_proxy_pathlen() sets the proxy certificate path length for the given certificate x. This is for the users who need to mark non-RFC3820 proxy certificates as such, as OpenSSL only detects RFC3820 compliant ones.

- -

X509_get_proxy_pathlen() returns the proxy certificate path length for the given certificate x if it is a proxy certificate.

- -

NOTES

- -

The value of the flags correspond to extension values which are cached in the X509 structure. If the flags returned do not provide sufficient information an application should examine extension values directly for example using X509_get_ext_d2i().

- -

If the key usage or extended key usage extension is absent then typically usage is unrestricted. For this reason X509_get_key_usage() and X509_get_extended_key_usage() return UINT32_MAX when the corresponding extension is absent. Applications can additionally check the return value of X509_get_extension_flags() and take appropriate action is an extension is absent.

- -

If X509_get0_subject_key_id() returns NULL then the extension may be absent or malformed. Applications can determine the precise reason using X509_get_ext_d2i().

- -

RETURN VALUES

- -

X509_get_pathlen() returns the path length value, or -1 if the extension is not present.

- -

X509_get_extension_flags(), X509_get_key_usage() and X509_get_extended_key_usage() return sets of flags corresponding to the certificate extension values.

- -

X509_get0_subject_key_id() returns the subject key identifier as a pointer to an ASN1_OCTET_STRING structure or NULL if the extension is absent or an error occurred during parsing.

- -

X509_get_proxy_pathlen() returns the path length value if the given certificate is a proxy one and has a path length set, and -1 otherwise.

- -

SEE ALSO

- -

X509_check_purpose(3)

- -

HISTORY

- -

X509_get_pathlen(), X509_set_proxy_flag(), X509_set_proxy_pathlen() and X509_get_proxy_pathlen() were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get_pubkey.html b/openssl-install/share/doc/openssl/html/man3/X509_get_pubkey.html deleted file mode 100644 index 634a440f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get_pubkey.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -X509_get_pubkey - - - - - - - - - - -

NAME

- -

X509_get_pubkey, X509_get0_pubkey, X509_set_pubkey, X509_get_X509_PUBKEY, X509_REQ_get_pubkey, X509_REQ_get0_pubkey, X509_REQ_set_pubkey, X509_REQ_get_X509_PUBKEY - get or set certificate or certificate request public key

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-EVP_PKEY *X509_get_pubkey(X509 *x);
-EVP_PKEY *X509_get0_pubkey(const X509 *x);
-int X509_set_pubkey(X509 *x, EVP_PKEY *pkey);
-X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x);
-
-EVP_PKEY *X509_REQ_get_pubkey(X509_REQ *req);
-EVP_PKEY *X509_REQ_get0_pubkey(X509_REQ *req);
-int X509_REQ_set_pubkey(X509_REQ *x, EVP_PKEY *pkey);
-X509_PUBKEY *X509_REQ_get_X509_PUBKEY(X509_REQ *x);
- -

DESCRIPTION

- -

X509_get_pubkey() attempts to decode the public key for certificate x. If successful it returns the public key as an EVP_PKEY pointer with its reference count incremented: this means the returned key must be freed up after use. X509_get0_pubkey() is similar except it does not increment the reference count of the returned EVP_PKEY so it must not be freed up after use.

- -

X509_get_X509_PUBKEY() returns an internal pointer to the X509_PUBKEY structure which encodes the certificate of x. The returned value must not be freed up after use.

- -

X509_set_pubkey() attempts to set the public key for certificate x to pkey. The key pkey should be freed up after use.

- -

X509_REQ_get_pubkey(), X509_REQ_get0_pubkey(), X509_REQ_set_pubkey() and X509_REQ_get_X509_PUBKEY() are similar but operate on certificate request req.

- -

NOTES

- -

The first time a public key is decoded the EVP_PKEY structure is cached in the certificate or certificate request itself. Subsequent calls return the cached structure with its reference count incremented to improve performance.

- -

RETURN VALUES

- -

X509_get_pubkey(), X509_get0_pubkey(), X509_get_X509_PUBKEY(), X509_REQ_get_pubkey() and X509_REQ_get_X509_PUBKEY() return a public key or NULL if an error occurred.

- -

X509_set_pubkey() and X509_REQ_set_pubkey() return 1 for success and 0 for failure.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

COPYRIGHT

- -

Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get_serialNumber.html b/openssl-install/share/doc/openssl/html/man3/X509_get_serialNumber.html deleted file mode 100644 index f130c23a..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get_serialNumber.html +++ /dev/null @@ -1,78 +0,0 @@ - - - - -X509_get_serialNumber - - - - - - - - - - -

NAME

- -

X509_get_serialNumber, X509_get0_serialNumber, X509_set_serialNumber, X509_ACERT_get0_serialNumber, X509_ACERT_set1_serialNumber - get or set certificate serial number

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-ASN1_INTEGER *X509_get_serialNumber(X509 *x);
-const ASN1_INTEGER *X509_get0_serialNumber(const X509 *x);
-int X509_set_serialNumber(X509 *x, ASN1_INTEGER *serial);
-
-#include <openssl/x509_acert.h>
-
-ASN1_INTEGER *X509_ACERT_get0_serialNumber(X509_ACERT *x);
-int X509_ACERT_set1_serialNumber(X509_ACERT *x, ASN1_INTEGER *serial);
- -

DESCRIPTION

- -

X509_get_serialNumber() returns the serial number of certificate x as an ASN1_INTEGER structure which can be examined or initialised. The value returned is an internal pointer which MUST NOT be freed up after the call.

- -

X509_get0_serialNumber() is the same as X509_get_serialNumber() except it accepts a const parameter and returns a const result.

- -

X509_set_serialNumber() sets the serial number of certificate x to serial. A copy of the serial number is used internally so serial should be freed up after use.

- -

X509_ACERT_get0_serialNumber() performs the same operation as X509_get_serialNumber() for attribute certificates.

- -

X509_ACERT_set1_serialNumber() performs the same operation as X509_set_serialNumber() for attribute certificates.

- -

RETURN VALUES

- -

X509_get_serialNumber(), X509_get0_serialNumber() and X509_ACERT_get0_serialNumber() return a pointer to an ASN1_INTEGER structure.

- -

X509_set_serialNumber() and X509_ACERT_set1_serialNumber() return 1 for success and 0 for failure.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

HISTORY

- -

The X509_get_serialNumber() and X509_set_serialNumber() functions are available in all versions of OpenSSL. The X509_get0_serialNumber() function was added in OpenSSL 1.1.0. The X509_ACERT_get0_serialNumber() and X509_ACERT_set1_serialNumber() functions were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get_subject_name.html b/openssl-install/share/doc/openssl/html/man3/X509_get_subject_name.html deleted file mode 100644 index 1e1ab2f5..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get_subject_name.html +++ /dev/null @@ -1,112 +0,0 @@ - - - - -X509_get_subject_name - - - - - - - - - - -

NAME

- -

X509_NAME_hash_ex, X509_NAME_hash, X509_get_subject_name, X509_set_subject_name, X509_subject_name_hash, X509_get_issuer_name, X509_set_issuer_name, X509_issuer_name_hash, X509_REQ_get_subject_name, X509_REQ_set_subject_name, X509_ACERT_get0_issuerName, X509_ACERT_set1_issuerName, X509_CRL_get_issuer, X509_CRL_set_issuer_name - get X509_NAME hashes or get and set issuer or subject names

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-unsigned long X509_NAME_hash_ex(const X509_NAME *x, OSSL_LIB_CTX *libctx,
-                                const char *propq, int *ok);
-
-X509_NAME *X509_get_subject_name(const X509 *x);
-int X509_set_subject_name(X509 *x, const X509_NAME *name);
-unsigned long X509_subject_name_hash(X509 *x);
-
-X509_NAME *X509_get_issuer_name(const X509 *x);
-int X509_set_issuer_name(X509 *x, const X509_NAME *name);
-unsigned long X509_issuer_name_hash(X509 *x);
-
-X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req);
-int X509_REQ_set_subject_name(X509_REQ *req, const X509_NAME *name);
-
-X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl);
-int X509_CRL_set_issuer_name(X509_CRL *x, const X509_NAME *name);
-
-#include <openssl/x509_acert.h>
-
-X509_NAME *X509_ACERT_get0_issuerName(const X509_ACERT *x);
-int X509_ACERT_set1_issuerName(X509_ACERT *x, const X509_NAME *name);
- -

The following macro has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#define X509_NAME_hash(x) X509_NAME_hash_ex(x, NULL, NULL, NULL)
- -

DESCRIPTION

- -

X509_NAME_hash_ex() returns a hash value of name x or 0 on failure, using any given library context libctx and property query propq. The ok result argument may be NULL or else is used to return 1 for success and 0 for failure. Failure may happen on malloc error or if no SHA1 implementation is available.

- -

X509_NAME_hash() returns a hash value of name x or 0 on failure, using the default library context and default property query.

- -

X509_get_subject_name() returns the subject name of certificate x. The returned value is an internal pointer which MUST NOT be freed.

- -

X509_set_subject_name() sets the issuer name of certificate x to name. The name parameter is copied internally and should be freed up when it is no longer needed.

- -

X509_subject_name_hash() returns a hash value of the subject name of certificate x.

- -

X509_get_issuer_name(), X509_set_issuer_name(), and X509_issuer_name_hash() are identical to X509_get_subject_name(), X509_set_subject_name(), and X509_subject_name_hash() except they relate to the issuer name of x.

- -

Similarly X509_REQ_get_subject_name(), X509_REQ_set_subject_name(), X509_ACERT_get0_issuerName(), X509_ACERT_set1_issuerName(), X509_CRL_get_issuer() and X509_CRL_set_issuer_name() get or set the subject or issuer names of certificate requests of CRLs respectively.

- -

Since attribute certificates do not have a subject name, only the issuer name can be set. For details on setting X509_ACERT holder identities, see X509_ACERT_set0_holder_entityName(3).

- -

RETURN VALUES

- -

X509_get_subject_name(), X509_get_issuer_name(), X509_REQ_get_subject_name() X509_ACERT_get0_issuerName() and X509_CRL_get_issuer() return an X509_NAME pointer.

- -

X509_NAME_hash_ex(), X509_NAME_hash(), X509_subject_name_hash() and X509_issuer_name_hash() return the first four bytes of the SHA1 hash value, converted to unsigned long in little endian order, or 0 on failure.

- -

X509_set_subject_name(), X509_set_issuer_name(), X509_REQ_set_subject_name(), X509_ACERT_get0_issuerName() and X509_CRL_set_issuer_name() return 1 for success and 0 for failure.

- -

BUGS

- -

In case X509_NAME_hash(), X509_subject_name_hash(), or X509_issuer_name_hash() returns 0 it remains unclear if this is the real hash value or due to failure. Better use X509_NAME_hash_ex() instead.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), d2i_X509(3) X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

HISTORY

- -

X509_REQ_get_subject_name() is a function in OpenSSL 1.1.0 and a macro in earlier versions.

- -

X509_CRL_get_issuer() is a function in OpenSSL 1.1.0. It was previously added in OpenSSL 1.0.0 as a macro.

- -

X509_NAME_hash() was turned into a macro and deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_get_version.html b/openssl-install/share/doc/openssl/html/man3/X509_get_version.html deleted file mode 100644 index 55ea6ff4..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_get_version.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -X509_get_version - - - - - - - - - - -

NAME

- -

X509_get_version, X509_set_version, X509_REQ_get_version, X509_REQ_set_version, X509_ACERT_get_version, X509_ACERT_set_version, X509_CRL_get_version, X509_CRL_set_version - get or set certificate, certificate request or CRL version

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-long X509_get_version(const X509 *x);
-int X509_set_version(X509 *x, long version);
-
-long X509_REQ_get_version(const X509_REQ *req);
-int X509_REQ_set_version(X509_REQ *x, long version);
-
-long X509_CRL_get_version(const X509_CRL *crl);
-int X509_CRL_set_version(X509_CRL *x, long version);
-
-#include <openssl/x509_acert.h>
-
-int X509_ACERT_set_version(X509_ACERT *x, long version);
-long X509_ACERT_get_version(const X509_ACERT *x);
- -

DESCRIPTION

- -

X509_get_version() returns the numerical value of the version field of certificate x. These correspond to the constants X509_VERSION_1, X509_VERSION_2, and X509_VERSION_3. Note: the values of these constants are defined by standards (X.509 et al) to be one less than the certificate version. So X509_VERSION_3 has value 2 and X509_VERSION_1 has value 0.

- -

X509_set_version() sets the numerical value of the version field of certificate x to version.

- -

Similarly X509_REQ_get_version(), X509_REQ_set_version(), X509_ACERT_get_version(), X509_ACERT_set_version(), X509_CRL_get_version() and X509_CRL_set_version() get and set the version number of certificate requests and CRLs. They use constants X509_REQ_VERSION_1, X509_ACERT_VERSION_2, X509_CRL_VERSION_1, and X509_CRL_VERSION_2.

- -

NOTES

- -

The version field of certificates, certificate requests and CRLs has a DEFAULT value of v1(0) meaning the field should be omitted for version 1. This is handled transparently by these functions.

- -

RETURN VALUES

- -

X509_get_version(), X509_REQ_get_version() and X509_CRL_get_version() return the numerical value of the version field.

- -

X509_set_version(), X509_REQ_set_version() and X509_CRL_set_version() return 1 for success and 0 for failure.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

HISTORY

- -

X509_get_version(), X509_REQ_get_version() and X509_CRL_get_version() are functions in OpenSSL 1.1.0, in previous versions they were macros.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_load_http.html b/openssl-install/share/doc/openssl/html/man3/X509_load_http.html deleted file mode 100644 index 167129e1..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_load_http.html +++ /dev/null @@ -1,75 +0,0 @@ - - - - -X509_load_http - - - - - - - - - - -

NAME

- -

X509_load_http, X509_http_nbio, X509_CRL_load_http, X509_CRL_http_nbio - certificate and CRL loading functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-X509 *X509_load_http(const char *url, BIO *bio, BIO *rbio, int timeout);
-X509_CRL *X509_CRL_load_http(const char *url, BIO *bio, BIO *rbio, int timeout);
- -

The following macros have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
#define X509_http_nbio(rctx, pcert)
-#define X509_CRL_http_nbio(rctx, pcrl)
- -

DESCRIPTION

- -

X509_load_http() and X509_CRL_load_http() loads a certificate or a CRL, respectively, in ASN.1 format using HTTP from the given url.

- -

Maximum size of the HTTP response is 100 kB for certificates and 32 MB for CRLs and hard coded in the functions.

- -

If bio is given and rbio is NULL then this BIO is used instead of an internal one for connecting, writing the request, and reading the response. If both bio and rbio are given (which may be memory BIOs, for instance) then no explicit connection is attempted, bio is used for writing the request, and rbio for reading the response.

- -

If the timeout parameter is > 0 this indicates the maximum number of seconds to wait until the transfer is complete. A value of 0 enables waiting indefinitely, while a value < 0 immediately leads to a timeout condition.

- -

X509_http_nbio() and X509_CRL_http_nbio() are macros for backward compatibility that have the same effect as the functions above but with infinite timeout and without the possibility to specify custom BIOs.

- -

RETURN VALUES

- -

On success the function yield the loaded value, else NULL. Error conditions include connection/transfer timeout, parse errors, etc.

- -

SEE ALSO

- -

OSSL_HTTP_get(3)

- -

HISTORY

- -

X509_load_http() and X509_CRL_load_http() were added in OpenSSL 3.0. X509_http_nbio() and X509_CRL_http_nbio() were deprecated in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_new.html b/openssl-install/share/doc/openssl/html/man3/X509_new.html deleted file mode 100644 index 86b543f6..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_new.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -X509_new - - - - - - - - - - -

NAME

- -

X509_new, X509_new_ex, X509_free, X509_up_ref, X509_chain_up_ref, OSSL_STACK_OF_X509_free - X509 certificate ASN1 allocation and deallocation functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-X509 *X509_new(void);
-X509 *X509_new_ex(OSSL_LIB_CTX *libctx, const char *propq);
-void X509_free(X509 *a);
-int X509_up_ref(X509 *a);
-STACK_OF(X509) *X509_chain_up_ref(STACK_OF(X509) *x);
-void OSSL_STACK_OF_X509_free(STACK_OF(X509) *certs);
- -

DESCRIPTION

- -

The X509 ASN1 allocation routines allocate and free an X509 structure, which represents an X509 certificate.

- -

X509_new_ex() allocates and initializes a X509 structure with a library context of libctx, property query of propq and a reference count of 1. Many X509 functions such as X509_check_purpose(), and X509_verify() use this library context to select which providers supply the fetched algorithms (SHA1 is used internally). This created X509 object can then be used when loading binary data using d2i_X509().

- -

X509_new() is similar to X509_new_ex() but sets the library context and property query to NULL. This results in the default (NULL) library context being used for any X509 operations requiring algorithm fetches.

- -

X509_free() decrements the reference count of X509 structure a and frees it up if the reference count is zero. If the argument is NULL, nothing is done.

- -

X509_up_ref() increments the reference count of a.

- -

X509_chain_up_ref() increases the reference count of all certificates in chain x and returns a copy of the stack, or an empty stack if a is NULL.

- -

OSSL_STACK_OF_X509_free() deallocates the given list of pointers to certificates after calling X509_free() on all its elements. If the argument is NULL, nothing is done.

- -

NOTES

- -

The function X509_up_ref() if useful if a certificate structure is being used by several different operations each of which will free it up after use: this avoids the need to duplicate the entire certificate structure.

- -

The function X509_chain_up_ref() doesn't just up the reference count of each certificate. It also returns a copy of the stack, using sk_X509_dup(), but it serves a similar purpose: the returned chain persists after the original has been freed.

- -

RETURN VALUES

- -

If the allocation fails, X509_new() returns NULL and sets an error code that can be obtained by ERR_get_error(3). Otherwise it returns a pointer to the newly allocated structure.

- -

X509_up_ref() returns 1 for success and 0 for failure.

- -

X509_chain_up_ref() returns a copy of the stack or NULL if an error occurred.

- -

OSSL_STACK_OF_X509_free() has no return value.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

HISTORY

- -

X509_new_ex() was added in OpenSSL 3.0.

- -

OSSL_STACK_OF_X509_free() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_sign.html b/openssl-install/share/doc/openssl/html/man3/X509_sign.html deleted file mode 100644 index dad81e07..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_sign.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -X509_sign - - - - - - - - - - -

NAME

- -

X509_sign, X509_sign_ctx, X509_REQ_sign, X509_REQ_sign_ctx, X509_ACERT_sign, X509_ACERT_sign_ctx, X509_CRL_sign, X509_CRL_sign_ctx - sign certificate, certificate request, or CRL signature

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_sign(X509 *x, EVP_PKEY *pkey, const EVP_MD *md);
-int X509_sign_ctx(X509 *x, EVP_MD_CTX *ctx);
-
-int X509_REQ_sign(X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md);
-int X509_REQ_sign_ctx(X509_REQ *x, EVP_MD_CTX *ctx);
-
-int X509_CRL_sign(X509_CRL *x, EVP_PKEY *pkey, const EVP_MD *md);
-int X509_CRL_sign_ctx(X509_CRL *x, EVP_MD_CTX *ctx);
-
-#include <openssl/x509_acert.h>
-
-int X509_ACERT_sign(X509_ACERT *x, EVP_PKEY *pkey, const EVP_MD *md);
-int X509_ACERT_sign_ctx(X509_ACERT *x, EVP_MD_CTX *ctx);
- -

DESCRIPTION

- -

X509_sign() signs certificate x using private key pkey and message digest md and sets the signature in x. X509_sign_ctx() also signs certificate x but uses the parameters contained in digest context ctx. If the certificate information includes X.509 extensions, these two functions make sure that the certificate bears X.509 version 3.

- -

X509_REQ_sign(), X509_REQ_sign_ctx(), X509_ACERT_sign(), X509_ACERT_sign_ctx(), X509_CRL_sign(), and X509_CRL_sign_ctx() sign certificate requests and CRLs, respectively.

- -

NOTES

- -

X509_sign_ctx() is used where the default parameters for the corresponding public key and digest are not suitable. It can be used to sign keys using RSA-PSS for example.

- -

For efficiency reasons and to work around ASN.1 encoding issues the encoding of the signed portion of a certificate, certificate request and CRL is cached internally. If the signed portion of the structure is modified the encoding is not always updated meaning a stale version is sometimes used. This is not normally a problem because modifying the signed portion will invalidate the signature and signing will always update the encoding.

- -

RETURN VALUES

- -

All functions return the size of the signature in bytes for success and zero for failure.

- -

SEE ALSO

- -

ERR_get_error(3), X509_NAME_add_entry_by_txt(3), X509_new(3), X509_verify_cert(3), X509_verify(3), X509_REQ_verify_ex(3), X509_REQ_verify(3), X509_CRL_verify(3)

- -

HISTORY

- -

The X509_sign(), X509_REQ_sign() and X509_CRL_sign() functions are available in all versions of OpenSSL.

- -

The X509_sign_ctx(), X509_REQ_sign_ctx() and X509_CRL_sign_ctx() functions were added in OpenSSL 1.0.1.

- -

The X509_ACERT_sign() and X509_ACERT_sign_ctx() functions were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_verify.html b/openssl-install/share/doc/openssl/html/man3/X509_verify.html deleted file mode 100644 index 885b9ac0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_verify.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -X509_verify - - - - - - - - - - -

NAME

- -

X509_verify, X509_self_signed, X509_REQ_verify_ex, X509_REQ_verify, X509_CRL_verify, X509_ACERT_verify - verify certificate, certificate request, or CRL signature

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509_verify(X509 *x, EVP_PKEY *pkey);
-int X509_self_signed(X509 *cert, int verify_signature);
-
-int X509_REQ_verify_ex(X509_REQ *a, EVP_PKEY *pkey, OSSL_LIB_CTX *libctx,
-                       const char *propq);
-int X509_REQ_verify(X509_REQ *a, EVP_PKEY *r);
-int X509_CRL_verify(X509_CRL *a, EVP_PKEY *r);
-
-#include <openssl/x509_acert.h>
-int X509_ACERT_verify(X509_CRL *a, EVP_PKEY *r);
- -

DESCRIPTION

- -

X509_verify() verifies the signature of certificate x using public key pkey. Only the signature is checked: no other checks (such as certificate chain validity) are performed.

- -

X509_self_signed() checks whether certificate cert is self-signed. For success the issuer and subject names must match, the components of the authority key identifier (if present) must match the subject key identifier etc. The signature itself is actually verified only if verify_signature is 1, as for explicitly trusted certificates this verification is not worth the effort.

- -

X509_REQ_verify_ex(), X509_REQ_verify(), X509_CRL_verify() and X509_ACERT_verify() verify the signatures of certificate requests, CRLs and attribute certificates respectively.

- -

RETURN VALUES

- -

X509_verify(), X509_REQ_verify_ex(), X509_REQ_verify() and X509_CRL_verify() return 1 if the signature is valid and 0 if the signature check fails. If the signature could not be checked at all because it was ill-formed, the certificate or the request was not complete or some other error occurred then -1 is returned.

- -

X509_self_signed() returns the same values but also returns 1 if all respective fields match and verify_signature is 0.

- -

SEE ALSO

- -

d2i_X509(3), ERR_get_error(3), X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509V3_get_d2i(3), X509_verify_cert(3), OSSL_LIB_CTX(3)

- -

HISTORY

- -

The X509_verify(), X509_REQ_verify(), and X509_CRL_verify() functions are available in all versions of OpenSSL.

- -

X509_REQ_verify_ex(), and X509_self_signed() were added in OpenSSL 3.0.

- -

X509_ACERT_verify() was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509_verify_cert.html b/openssl-install/share/doc/openssl/html/man3/X509_verify_cert.html deleted file mode 100644 index cc9d942c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509_verify_cert.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -X509_verify_cert - - - - - - - - - - -

NAME

- -

X509_build_chain, X509_verify_cert, X509_STORE_CTX_verify - build and verify X509 certificate chain

- -

SYNOPSIS

- -
#include <openssl/x509_vfy.h>
-
-STACK_OF(X509) *X509_build_chain(X509 *target, STACK_OF(X509) *certs,
-                                 X509_STORE *store, int with_self_signed,
-                                 OSSL_LIB_CTX *libctx, const char *propq);
-int X509_verify_cert(X509_STORE_CTX *ctx);
-int X509_STORE_CTX_verify(X509_STORE_CTX *ctx);
- -

DESCRIPTION

- -

X509_build_chain() builds a certificate chain starting from target using the optional list of intermediate CA certificates certs. If store is NULL it builds the chain as far down as possible, ignoring errors. Else the chain must reach a trust anchor contained in store. It internally uses a X509_STORE_CTX structure associated with the library context libctx and property query string propq, both of which may be NULL. In case there is more than one possibility for the chain, only one is taken.

- -

On success it returns a pointer to a new stack of (up_ref'ed) certificates starting with target and followed by all available intermediate certificates. A self-signed trust anchor is included only if target is the trust anchor of with_self_signed is 1. If a non-NULL stack is returned the caller is responsible for freeing it.

- -

The X509_verify_cert() function attempts to discover and validate a certificate chain based on parameters in ctx. The verification context, of type X509_STORE_CTX, can be constructed using X509_STORE_CTX_new(3) and X509_STORE_CTX_init(3). It usually includes a target certificate to be verified, a set of certificates serving as trust anchors, a list of non-trusted certificates that may be helpful for chain construction, flags such as X509_V_FLAG_X509_STRICT, and various other optional components such as a callback function that allows customizing the verification outcome. A complete description of the certificate verification process is contained in the openssl-verification-options(1) manual page.

- -

Applications rarely call this function directly but it is used by OpenSSL internally for certificate validation, in both the S/MIME and SSL/TLS code.

- -

A negative return value from X509_verify_cert() can occur if it is invoked incorrectly, such as with no certificate set in ctx, or when it is called twice in succession without reinitialising ctx for the second call. A negative return value can also happen due to internal resource problems or because an internal inconsistency has been detected. Applications must interpret any return value <= 0 as an error.

- -

The X509_STORE_CTX_verify() behaves like X509_verify_cert() except that its target certificate is the first element of the list of untrusted certificates in ctx unless a target certificate is set explicitly.

- -

When the verification target is a raw public key, rather than a certificate, both functions validate the target raw public key. In that case the number of possible checks is significantly reduced. The raw public key can be authenticated only via DANE TLSA records, either locally synthesised or obtained by the application from DNS. Raw public key DANE TLSA records may be added via SSL_add_expected_rpk(3) or SSL_dane_tlsa_add(3).

- -

RETURN VALUES

- -

X509_build_chain() returns NULL on error, else a stack of certificates.

- -

Both X509_verify_cert() and X509_STORE_CTX_verify() return 1 if a complete chain can be built and validated, otherwise they return 0, and in exceptional circumstances (such as malloc failure and internal errors) they can also return a negative code.

- -

If a complete chain can be built and validated both functions return 1. If the certificate must be rejected on the basis of the data available or any required certificate status data is not available they return 0. If no definite answer possible they usually return a negative code.

- -

On error or failure additional error information can be obtained by examining ctx using, for example, X509_STORE_CTX_get_error(3). Even if verification indicated success, the stored error code may be different from X509_V_OK, likely because a verification callback function has waived the error.

- -

SEE ALSO

- -

SSL_add_expected_rpk(3), SSL_CTX_dane_enable(3), SSL_dane_tlsa_add(3), X509_STORE_CTX_new(3), X509_STORE_CTX_init(3), X509_STORE_CTX_init_rpk(3), X509_STORE_CTX_get_error(3)

- -

HISTORY

- -

X509_build_chain() and X509_STORE_CTX_verify() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2009-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/X509v3_get_ext_by_NID.html b/openssl-install/share/doc/openssl/html/man3/X509v3_get_ext_by_NID.html deleted file mode 100644 index d0fa0f3b..00000000 --- a/openssl-install/share/doc/openssl/html/man3/X509v3_get_ext_by_NID.html +++ /dev/null @@ -1,140 +0,0 @@ - - - - -X509v3_get_ext_by_NID - - - - - - - - - - -

NAME

- -

X509v3_get_ext_count, X509v3_get_ext, X509v3_get_ext_by_NID, X509v3_get_ext_by_OBJ, X509v3_get_ext_by_critical, X509v3_delete_ext, X509v3_add_ext, X509v3_add_extensions, X509_get_ext_count, X509_get_ext, X509_get_ext_by_NID, X509_get_ext_by_OBJ, X509_get_ext_by_critical, X509_delete_ext, X509_add_ext, X509_CRL_get_ext_count, X509_CRL_get_ext, X509_CRL_get_ext_by_NID, X509_CRL_get_ext_by_OBJ, X509_CRL_get_ext_by_critical, X509_CRL_delete_ext, X509_CRL_add_ext, X509_REVOKED_get_ext_count, X509_REVOKED_get_ext, X509_REVOKED_get_ext_by_NID, X509_REVOKED_get_ext_by_OBJ, X509_REVOKED_get_ext_by_critical, X509_REVOKED_delete_ext, X509_REVOKED_add_ext - extension stack utility functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION) *x);
-X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc);
-
-int X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION) *x,
-                          int nid, int lastpos);
-int X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION) *x,
-                          const ASN1_OBJECT *obj, int lastpos);
-int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION) *x,
-                               int crit, int lastpos);
-X509_EXTENSION *X509v3_delete_ext(STACK_OF(X509_EXTENSION) *x, int loc);
-STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x,
-                                         X509_EXTENSION *ex, int loc);
-STACK_OF(X509_EXTENSION)
-     *X509v3_add_extensions(STACK_OF(X509_EXTENSION) **target,
-                            const STACK_OF(X509_EXTENSION) *exts);
-
-int X509_get_ext_count(const X509 *x);
-X509_EXTENSION *X509_get_ext(const X509 *x, int loc);
-int X509_get_ext_by_NID(const X509 *x, int nid, int lastpos);
-int X509_get_ext_by_OBJ(const X509 *x, const ASN1_OBJECT *obj, int lastpos);
-int X509_get_ext_by_critical(const X509 *x, int crit, int lastpos);
-X509_EXTENSION *X509_delete_ext(X509 *x, int loc);
-int X509_add_ext(X509 *x, X509_EXTENSION *ex, int loc);
-
-int X509_CRL_get_ext_count(const X509_CRL *x);
-X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc);
-int X509_CRL_get_ext_by_NID(const X509_CRL *x, int nid, int lastpos);
-int X509_CRL_get_ext_by_OBJ(const X509_CRL *x, const ASN1_OBJECT *obj,
-                            int lastpos);
-int X509_CRL_get_ext_by_critical(const X509_CRL *x, int crit, int lastpos);
-X509_EXTENSION *X509_CRL_delete_ext(X509_CRL *x, int loc);
-int X509_CRL_add_ext(X509_CRL *x, X509_EXTENSION *ex, int loc);
-
-int X509_REVOKED_get_ext_count(const X509_REVOKED *x);
-X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc);
-int X509_REVOKED_get_ext_by_NID(const X509_REVOKED *x, int nid, int lastpos);
-int X509_REVOKED_get_ext_by_OBJ(const X509_REVOKED *x, const ASN1_OBJECT *obj,
-                                int lastpos);
-int X509_REVOKED_get_ext_by_critical(const X509_REVOKED *x, int crit, int lastpos);
-X509_EXTENSION *X509_REVOKED_delete_ext(X509_REVOKED *x, int loc);
-int X509_REVOKED_add_ext(X509_REVOKED *x, X509_EXTENSION *ex, int loc);
- -

DESCRIPTION

- -

X509v3_get_ext_count() retrieves the number of extensions in x.

- -

X509v3_get_ext() retrieves extension loc from x. The index loc can take any value from 0 to X509_get_ext_count(x) - 1. The returned extension is an internal pointer which MUST NOT be freed by the application.

- -

X509v3_get_ext_by_NID() and X509v3_get_ext_by_OBJ() look for an extension with nid or obj from extension STACK x. The search starts from the extension after lastpos or from the beginning if lastpos is -1. If the extension is found, its index is returned, otherwise -1 is returned.

- -

X509v3_get_ext_by_critical() is similar to X509v3_get_ext_by_NID() except it looks for an extension of criticality crit. A zero value for crit looks for a non-critical extension. A nonzero value looks for a critical extension.

- -

X509v3_delete_ext() deletes the extension with index loc from x. The deleted extension is returned and must be freed by the caller. If loc is an invalid index value, NULL is returned.

- -

X509v3_add_ext() inserts extension ex to STACK *x at position loc. If loc is -1, the new extension is added to the end. A new STACK is allocated if *x is NULL. The passed extension ex is duplicated so it must be freed after use.

- -

X509v3_add_extensions() adds the list of extensions exts to STACK *target. The STACK *target is returned unchanged if exts is NULL or an empty list. Otherwise a new stack is allocated if *target is NULL. An extension to be added that has the same OID as a pre-existing one replaces this earlier one.

- -

X509_get_ext_count(), X509_get_ext(), X509_get_ext_by_NID(), X509_get_ext_by_OBJ(), X509_get_ext_by_critical(), X509_delete_ext() and X509_add_ext() operate on the extensions of certificate x. They are otherwise identical to the X509v3 functions.

- -

X509_CRL_get_ext_count(), X509_CRL_get_ext(), X509_CRL_get_ext_by_NID(), X509_CRL_get_ext_by_OBJ(), X509_CRL_get_ext_by_critical(), X509_CRL_delete_ext() and X509_CRL_add_ext() operate on the extensions of CRL x. They are otherwise identical to the X509v3 functions.

- -

X509_REVOKED_get_ext_count(), X509_REVOKED_get_ext(), X509_REVOKED_get_ext_by_NID(), X509_REVOKED_get_ext_by_OBJ(), X509_REVOKED_get_ext_by_critical(), X509_REVOKED_delete_ext() and X509_REVOKED_add_ext() operate on the extensions of CRL entry x. They are otherwise identical to the X509v3 functions.

- -

NOTES

- -

These functions are used to examine stacks of extensions directly. Applications that want to parse or encode and add an extension should use the extension encode and decode functions instead, such as X509_add1_ext_i2d() and X509_get_ext_d2i().

- -

For X509v3_get_ext_by_NID(), X509v3_get_ext_by_OBJ(), X509v3_get_ext_by_critical() and its variants, a zero index return value is not an error since extension STACK x indices start from zero. These search functions start from the extension after the lastpos parameter so it should initially be set to -1. If it is set to zero, the initial extension will not be checked.

- -

X509v3_delete_ext() and its variants are a bit counter-intuitive because these functions do not free the extension they delete. They return an X509_EXTENSION object which must be explicitly freed using X509_EXTENSION_free().

- -

RETURN VALUES

- -

X509v3_get_ext_count() returns the extension count or 0 for failure.

- -

X509v3_get_ext(), X509v3_delete_ext() and X509_delete_ext() return an X509_EXTENSION structure or NULL if an error occurs.

- -

X509v3_get_ext_by_OBJ() and X509v3_get_ext_by_critical() return the extension index or -1 if an error occurs.

- -

X509v3_get_ext_by_NID() returns the extension index or negative values if an error occurs.

- -

X509v3_add_ext() returns a STACK of extensions or NULL on error.

- -

X509v3_add_extensions() returns a STACK of extensions or NULL on error or if *target is NULL and exts is NULL or an empty list.

- -

X509_add_ext() returns 1 on success and 0 on error.

- -

SEE ALSO

- -

X509V3_get_d2i(3)

- -

HISTORY

- -

X509v3_add_extensions() was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/b2i_PVK_bio_ex.html b/openssl-install/share/doc/openssl/html/man3/b2i_PVK_bio_ex.html deleted file mode 100644 index 0275ff8f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/b2i_PVK_bio_ex.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -b2i_PVK_bio_ex - - - - - - - - - - -

NAME

- -

b2i_PVK_bio, b2i_PVK_bio_ex, i2b_PVK_bio, i2b_PVK_bio_ex - Decode and encode functions for reading and writing MSBLOB format private keys

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-EVP_PKEY *b2i_PVK_bio(BIO *in, pem_password_cb *cb, void *u);
-EVP_PKEY *b2i_PVK_bio_ex(BIO *in, pem_password_cb *cb, void *u,
-                         OSSL_LIB_CTX *libctx, const char *propq);
-int i2b_PVK_bio(BIO *out, const EVP_PKEY *pk, int enclevel,
-                pem_password_cb *cb, void *u);
-int i2b_PVK_bio_ex(BIO *out, const EVP_PKEY *pk, int enclevel,
-                   pem_password_cb *cb, void *u,
-                   OSSL_LIB_CTX *libctx, const char *propq);
- -

DESCRIPTION

- -

b2i_PVK_bio_ex() decodes a private key of MSBLOB format read from a BIO. It attempts to automatically determine the key type. If the key is encrypted then cb is called with the user data u in order to obtain a password to decrypt the key. The supplied library context libctx and property query string propq are used in any decrypt operation.

- -

b2i_PVK_bio() does the same as b2i_PVK_bio_ex() except that the default library context and property query string are used.

- -

i2b_PVK_bio_ex() encodes pk using MSBLOB format. If enclevel is 1 then a password obtained via pem_password_cb is used to encrypt the private key. If enclevel is 0 then no encryption is applied. The user data in u is passed to the password callback. The supplied library context libctx and property query string propq are used in any decrypt operation.

- -

i2b_PVK_bio() does the same as i2b_PVK_bio_ex() except that the default library context and property query string are used.

- -

RETURN VALUES

- -

The b2i_PVK_bio() and b2i_PVK_bio_ex() functions return a valid EVP_KEY structure or NULL if an error occurs. The error code can be obtained by calling ERR_get_error(3).

- -

i2b_PVK_bio() and i2b_PVK_bio_ex() return the number of bytes successfully encoded or a negative value if an error occurs. The error code can be obtained by calling ERR_get_error(3).

- -

SEE ALSO

- -

crypto(7), d2i_PKCS8PrivateKey_bio(3)

- -

HISTORY

- -

b2i_PVK_bio_ex() and i2b_PVK_bio_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/d2i_PKCS8PrivateKey_bio.html b/openssl-install/share/doc/openssl/html/man3/d2i_PKCS8PrivateKey_bio.html deleted file mode 100644 index 758b9271..00000000 --- a/openssl-install/share/doc/openssl/html/man3/d2i_PKCS8PrivateKey_bio.html +++ /dev/null @@ -1,86 +0,0 @@ - - - - -d2i_PKCS8PrivateKey_bio - - - - - - - - - - -

NAME

- -

d2i_PKCS8PrivateKey_bio, d2i_PKCS8PrivateKey_fp, i2d_PKCS8PrivateKey_bio, i2d_PKCS8PrivateKey_fp, i2d_PKCS8PrivateKey_nid_bio, i2d_PKCS8PrivateKey_nid_fp - PKCS#8 format private key functions

- -

SYNOPSIS

- -
#include <openssl/pem.h>
-
-EVP_PKEY *d2i_PKCS8PrivateKey_bio(BIO *bp, EVP_PKEY **x, pem_password_cb *cb, void *u);
-EVP_PKEY *d2i_PKCS8PrivateKey_fp(FILE *fp, EVP_PKEY **x, pem_password_cb *cb, void *u);
-
-int i2d_PKCS8PrivateKey_bio(BIO *bp, const EVP_PKEY *x, const EVP_CIPHER *enc,
-                            char *kstr, int klen,
-                            pem_password_cb *cb, void *u);
-
-int i2d_PKCS8PrivateKey_fp(FILE *fp, const EVP_PKEY *x, const EVP_CIPHER *enc,
-                           char *kstr, int klen,
-                           pem_password_cb *cb, void *u);
-
-int i2d_PKCS8PrivateKey_nid_bio(BIO *bp, const EVP_PKEY *x, int nid,
-                                char *kstr, int klen,
-                                pem_password_cb *cb, void *u);
-
-int i2d_PKCS8PrivateKey_nid_fp(FILE *fp, const EVP_PKEY *x, int nid,
-                               char *kstr, int klen,
-                               pem_password_cb *cb, void *u);
- -

DESCRIPTION

- -

The PKCS#8 functions encode and decode private keys in PKCS#8 format using both PKCS#5 v1.5 and PKCS#5 v2.0 password based encryption algorithms.

- -

Other than the use of DER as opposed to PEM these functions are identical to the corresponding PEM function as described in PEM_read_PrivateKey(3).

- -

NOTES

- -

These functions are currently the only way to store encrypted private keys using DER format.

- -

Currently all the functions use BIOs or FILE pointers, there are no functions which work directly on memory: this can be readily worked around by converting the buffers to memory BIOs, see BIO_s_mem(3) for details.

- -

These functions make no assumption regarding the pass phrase received from the password callback. It will simply be treated as a byte sequence.

- -

RETURN VALUES

- -

d2i_PKCS8PrivateKey_bio() and d2i_PKCS8PrivateKey_fp() return a valid EVP_PKEY structure or NULL if an error occurred.

- -

i2d_PKCS8PrivateKey_bio(), i2d_PKCS8PrivateKey_fp(), i2d_PKCS8PrivateKey_nid_bio() and i2d_PKCS8PrivateKey_nid_fp() return 1 on success or 0 on error.

- -

SEE ALSO

- -

PEM_read_PrivateKey(3), passphrase-encoding(7)

- -

COPYRIGHT

- -

Copyright 2002-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/d2i_PrivateKey.html b/openssl-install/share/doc/openssl/html/man3/d2i_PrivateKey.html deleted file mode 100644 index f8db05de..00000000 --- a/openssl-install/share/doc/openssl/html/man3/d2i_PrivateKey.html +++ /dev/null @@ -1,114 +0,0 @@ - - - - -d2i_PrivateKey - - - - - - - - - - -

NAME

- -

d2i_PrivateKey_ex, d2i_PrivateKey, d2i_PublicKey, d2i_KeyParams, d2i_AutoPrivateKey_ex, d2i_AutoPrivateKey, i2d_PrivateKey, i2d_PublicKey, i2d_KeyParams, i2d_KeyParams_bio, d2i_PrivateKey_ex_bio, d2i_PrivateKey_bio, d2i_PrivateKey_ex_fp, d2i_PrivateKey_fp, d2i_KeyParams_bio, i2d_PrivateKey_bio, i2d_PrivateKey_fp - decode and encode functions for reading and saving EVP_PKEY structures

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-
-EVP_PKEY *d2i_PrivateKey_ex(int type, EVP_PKEY **a, const unsigned char **pp,
-                            long length, OSSL_LIB_CTX *libctx,
-                            const char *propq);
-EVP_PKEY *d2i_PrivateKey(int type, EVP_PKEY **a, const unsigned char **pp,
-                         long length);
-EVP_PKEY *d2i_PublicKey(int type, EVP_PKEY **a, const unsigned char **pp,
-                        long length);
-EVP_PKEY *d2i_KeyParams(int type, EVP_PKEY **a, const unsigned char **pp,
-                        long length);
-EVP_PKEY *d2i_AutoPrivateKey_ex(EVP_PKEY **a, const unsigned char **pp,
-                                long length, OSSL_LIB_CTX *libctx,
-                                const char *propq);
-EVP_PKEY *d2i_AutoPrivateKey(EVP_PKEY **a, const unsigned char **pp,
-                             long length);
-
-int i2d_PrivateKey(const EVP_PKEY *a, unsigned char **pp);
-int i2d_PublicKey(const EVP_PKEY *a, unsigned char **pp);
-int i2d_KeyParams(const EVP_PKEY *a, unsigned char **pp);
-int i2d_KeyParams_bio(BIO *bp, const EVP_PKEY *pkey);
-EVP_PKEY *d2i_KeyParams_bio(int type, EVP_PKEY **a, BIO *in);
-
-
-#include <openssl/x509.h>
-
-EVP_PKEY *d2i_PrivateKey_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
-                                const char *propq);
-EVP_PKEY *d2i_PrivateKey_bio(BIO *bp, EVP_PKEY **a);
-EVP_PKEY *d2i_PrivateKey_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
-                               const char *propq);
-EVP_PKEY *d2i_PrivateKey_fp(FILE *fp, EVP_PKEY **a);
-
-int i2d_PrivateKey_bio(BIO *bp, const EVP_PKEY *pkey);
-int i2d_PrivateKey_fp(FILE *fp, const EVP_PKEY *pkey);
- -

DESCRIPTION

- -

d2i_PrivateKey_ex() decodes a private key using algorithm type. It attempts to use any key-specific format or PKCS#8 unencrypted PrivateKeyInfo format. The type parameter should be a public key algorithm constant such as EVP_PKEY_RSA. An error occurs if the decoded key does not match type. Some private key decoding implementations may use cryptographic algorithms (for example to automatically derive the public key if it is not explicitly included in the encoding). In this case the supplied library context libctx and property query string propq are used. If successful and the a parameter is not NULL the function assigns the returned EVP_PKEY structure pointer to *a, overwriting any previous value.

- -

d2i_PrivateKey() does the same as d2i_PrivateKey_ex() except that the default library context and property query string are used. d2i_PublicKey() does the same for public keys. d2i_KeyParams() does the same for key parameters.

- -

The d2i_PrivateKey_ex_bio() and d2i_PrivateKey_bio() functions are similar to d2i_PrivateKey_ex() and d2i_PrivateKey() respectively except that they decode the data read from the given BIO. The d2i_PrivateKey_ex_fp() and d2i_PrivateKey_fp() functions are the same except that they read the data from the given FILE.

- -

d2i_AutoPrivateKey_ex() and d2i_AutoPrivateKey() are similar to d2i_PrivateKey_ex() and d2i_PrivateKey() respectively except that they attempt to automatically detect the private key format.

- -

i2d_PrivateKey() encodes a. It uses a key specific format or, if none is defined for that key type, PKCS#8 unencrypted PrivateKeyInfo format. i2d_PublicKey() does the same for public keys. i2d_KeyParams() does the same for key parameters. These functions are similar to the d2i_X509() functions; see d2i_X509(3). i2d_PrivateKey_bio() and i2d_PrivateKey_fp() do the same thing except that they encode to a BIO or FILE respectively. Again, these work similarly to the functions described in d2i_X509(3).

- -

NOTES

- -

All the functions that operate on data in memory update the data pointer *pp after a successful operation, just like the other d2i and i2d functions; see d2i_X509(3).

- -

All these functions use DER format and unencrypted keys. Applications wishing to encrypt or decrypt private keys should use other functions such as d2i_PKCS8PrivateKey() instead.

- -

To decode a key with type EVP_PKEY_EC, d2i_PublicKey() requires *a to be a non-NULL EVP_PKEY structure assigned an EC_KEY structure referencing the proper EC_GROUP.

- -

RETURN VALUES

- -

The d2i_PrivateKey_ex(), d2i_PrivateKey(), d2i_AutoPrivateKey_ex(), d2i_AutoPrivateKey(), d2i_PrivateKey_ex_bio(), d2i_PrivateKey_bio(), d2i_PrivateKey_ex_fp(), d2i_PrivateKey_fp(), d2i_PublicKey(), d2i_KeyParams() and d2i_KeyParams_bio() functions return a valid EVP_PKEY structure or NULL if an error occurs. The error code can be obtained by calling ERR_get_error(3).

- -

i2d_PrivateKey(), i2d_PublicKey() and i2d_KeyParams() return the number of bytes successfully encoded or a negative value if an error occurs. The error code can be obtained by calling ERR_get_error(3).

- -

i2d_PrivateKey_bio(), i2d_PrivateKey_fp() and i2d_KeyParams_bio() return 1 if successfully encoded or zero if an error occurs.

- -

SEE ALSO

- -

crypto(7), d2i_PKCS8PrivateKey_bio(3)

- -

HISTORY

- -

d2i_PrivateKey_ex(), d2i_PrivateKey_ex_bio(), d2i_PrivateKey_ex_fp(), and d2i_AutoPrivateKey_ex() were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/d2i_RSAPrivateKey.html b/openssl-install/share/doc/openssl/html/man3/d2i_RSAPrivateKey.html deleted file mode 100644 index d7a5d40d..00000000 --- a/openssl-install/share/doc/openssl/html/man3/d2i_RSAPrivateKey.html +++ /dev/null @@ -1,231 +0,0 @@ - - - - -d2i_RSAPrivateKey - - - - - - - - - - -

NAME

- -

d2i_DSAPrivateKey, d2i_DSAPrivateKey_bio, d2i_DSAPrivateKey_fp, d2i_DSAPublicKey, d2i_DSA_PUBKEY, d2i_DSA_PUBKEY_bio, d2i_DSA_PUBKEY_fp, d2i_DSAparams, d2i_RSAPrivateKey, d2i_RSAPrivateKey_bio, d2i_RSAPrivateKey_fp, d2i_RSAPublicKey, d2i_RSAPublicKey_bio, d2i_RSAPublicKey_fp, d2i_RSA_PUBKEY, d2i_RSA_PUBKEY_bio, d2i_RSA_PUBKEY_fp, d2i_DHparams, d2i_DHparams_bio, d2i_DHparams_fp, d2i_ECParameters, d2i_ECPrivateKey, d2i_ECPrivateKey_bio, d2i_ECPrivateKey_fp, d2i_EC_PUBKEY, d2i_EC_PUBKEY_bio, d2i_EC_PUBKEY_fp, i2d_RSAPrivateKey, i2d_RSAPrivateKey_bio, i2d_RSAPrivateKey_fp, i2d_RSAPublicKey, i2d_RSAPublicKey_bio, i2d_RSAPublicKey_fp, i2d_RSA_PUBKEY, i2d_RSA_PUBKEY_bio, i2d_RSA_PUBKEY_fp, i2d_DHparams, i2d_DHparams_bio, i2d_DHparams_fp, i2d_DSAPrivateKey, i2d_DSAPrivateKey_bio, i2d_DSAPrivateKey_fp, i2d_DSAPublicKey, i2d_DSA_PUBKEY, i2d_DSA_PUBKEY_bio, i2d_DSA_PUBKEY_fp, i2d_DSAparams, i2d_ECParameters, i2d_ECPrivateKey, i2d_ECPrivateKey_bio, i2d_ECPrivateKey_fp, i2d_EC_PUBKEY, i2d_EC_PUBKEY_bio, i2d_EC_PUBKEY_fp - DEPRECATED

- -

SYNOPSIS

- -

The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining OPENSSL_API_COMPAT with a suitable version value, see openssl_user_macros(7):

- -
TYPE *d2i_TYPEPrivateKey(TYPE **a, const unsigned char **ppin, long length);
-TYPE *d2i_TYPEPrivateKey_bio(BIO *bp, TYPE **a);
-TYPE *d2i_TYPEPrivateKey_fp(FILE *fp, TYPE **a);
-TYPE *d2i_TYPEPublicKey(TYPE **a, const unsigned char **ppin, long length);
-TYPE *d2i_TYPEPublicKey_bio(BIO *bp, TYPE **a);
-TYPE *d2i_TYPEPublicKey_fp(FILE *fp, TYPE **a);
-TYPE *d2i_TYPEparams(TYPE **a, const unsigned char **ppin, long length);
-TYPE *d2i_TYPEparams_bio(BIO *bp, TYPE **a);
-TYPE *d2i_TYPEparams_fp(FILE *fp, TYPE **a);
-TYPE *d2i_TYPE_PUBKEY(TYPE **a, const unsigned char **ppin, long length);
-TYPE *d2i_TYPE_PUBKEY_bio(BIO *bp, TYPE **a);
-TYPE *d2i_TYPE_PUBKEY_fp(FILE *fp, TYPE **a);
-
-int i2d_TYPEPrivateKey(const TYPE *a, unsigned char **ppout);
-int i2d_TYPEPrivateKey(TYPE *a, unsigned char **ppout);
-int i2d_TYPEPrivateKey_fp(FILE *fp, const TYPE *a);
-int i2d_TYPEPrivateKey_fp(FILE *fp, TYPE *a);
-int i2d_TYPEPrivateKey_bio(BIO *bp, const TYPE *a);
-int i2d_TYPEPrivateKey_bio(BIO *bp, TYPE *a);
-int i2d_TYPEPublicKey(const TYPE *a, unsigned char **ppout);
-int i2d_TYPEPublicKey(TYPE *a, unsigned char **ppout);
-int i2d_TYPEPublicKey_fp(FILE *fp, const TYPE *a);
-int i2d_TYPEPublicKey_fp(FILE *fp, TYPE *a);
-int i2d_TYPEPublicKey_bio(BIO *bp, const TYPE *a);
-int i2d_TYPEPublicKey_bio(BIO *bp, TYPE *a);
-int i2d_TYPEparams(const TYPE *a, unsigned char **ppout);
-int i2d_TYPEparams(TYPE *a, unsigned char **ppout);
-int i2d_TYPEparams_fp(FILE *fp, const TYPE *a);
-int i2d_TYPEparams_fp(FILE *fp, TYPE *a);
-int i2d_TYPEparams_bio(BIO *bp, const TYPE *a);
-int i2d_TYPEparams_bio(BIO *bp, TYPE *a);
-int i2d_TYPE_PUBKEY(const TYPE *a, unsigned char **ppout);
-int i2d_TYPE_PUBKEY(TYPE *a, unsigned char **ppout);
-int i2d_TYPE_PUBKEY_fp(FILE *fp, const TYPE *a);
-int i2d_TYPE_PUBKEY_fp(FILE *fp, TYPE *a);
-int i2d_TYPE_PUBKEY_bio(BIO *bp, const TYPE *a);
-int i2d_TYPE_PUBKEY_bio(BIO *bp, TYPE *a);
- -

DESCRIPTION

- -

All functions described here are deprecated. Please use OSSL_DECODER(3) instead of the d2i functions and OSSL_ENCODER(3) instead of the i2d functions. See "Migration" below.

- -

In the description here, TYPE is used a placeholder for any of the OpenSSL datatypes, such as RSA. The function parameters ppin and ppout are generally either both named pp in the headers, or in and out.

- -

All the functions here behave the way that's described in d2i_X509(3).

- -

Please note that not all functions in the synopsis are available for all key types. For example, there are no d2i_RSAparams() or i2d_RSAparams(), because the PKCS#1 RSA structure doesn't include any key parameters.

- -

d2i_TYPEPrivateKey() and derivates thereof decode DER encoded TYPE private key data organized in a type specific structure.

- -

d2i_TYPEPublicKey() and derivates thereof decode DER encoded TYPE public key data organized in a type specific structure.

- -

d2i_TYPEparams() and derivates thereof decode DER encoded TYPE key parameters organized in a type specific structure.

- -

d2i_TYPE_PUBKEY() and derivates thereof decode DER encoded TYPE public key data organized in a SubjectPublicKeyInfo structure.

- -

i2d_TYPEPrivateKey() and derivates thereof encode the private key TYPE data into a type specific DER encoded structure.

- -

i2d_TYPEPublicKey() and derivates thereof encode the public key TYPE data into a type specific DER encoded structure.

- -

i2d_TYPEparams() and derivates thereof encode the TYPE key parameters data into a type specific DER encoded structure.

- -

i2d_TYPE_PUBKEY() and derivates thereof encode the public key TYPE data into a DER encoded SubjectPublicKeyInfo structure.

- -

For example, d2i_RSAPrivateKey() and d2i_RSAPublicKey() expects the structure defined by PKCS#1. Similarly, i2d_RSAPrivateKey() and i2d_RSAPublicKey() produce DER encoded string organized according to PKCS#1.

- -

Migration

- -

Migration from the diverse TYPEs requires using corresponding new OpenSSL types. For all TYPEs described here, the corresponding new type is EVP_PKEY. The rest of this section assumes that this has been done, exactly how to do that is described elsewhere.

- -

There are two migration paths:

- - - -

Migrating i2d functions to OSSL_ENCODER

- -

The exact OSSL_ENCODER(3) output is driven by arguments rather than by function names. The sample code to get DER encoded output in a type specific structure is uniform, the only things that vary are the selection of what part of the EVP_PKEY should be output, and the structure. The i2d functions names can therefore be translated into two variables, selection and structure as follows:

- -
- -
i2d_TYPEPrivateKey() translates into:
-
- -
int selection = EVP_PKEY_KEYPAIR;
-const char *structure = "type-specific";
- -
-
i2d_TYPEPublicKey() translates into:
-
- -
int selection = EVP_PKEY_PUBLIC_KEY;
-const char *structure = "type-specific";
- -
-
i2d_TYPEparams() translates into:
-
- -
int selection = EVP_PKEY_PARAMETERS;
-const char *structure = "type-specific";
- -
-
i2d_TYPE_PUBKEY() translates into:
-
- -
int selection = EVP_PKEY_PUBLIC_KEY;
-const char *structure = "SubjectPublicKeyInfo";
- -
-
- -

The following sample code does the rest of the work:

- -
unsigned char *p = buffer;     /* |buffer| is supplied by the caller */
-size_t len = buffer_size;      /* assumed be the size of |buffer| */
-OSSL_ENCODER_CTX *ctx =
-    OSSL_ENCODER_CTX_new_for_pkey(pkey, selection, "DER", structure,
-                                  NULL, NULL);
-if (ctx == NULL) {
-    /* fatal error handling */
-}
-if (OSSL_ENCODER_CTX_get_num_encoders(ctx) == 0) {
-    OSSL_ENCODER_CTX_free(ctx);
-    /* non-fatal error handling */
-}
-if (!OSSL_ENCODER_to_data(ctx, &p, &len)) {
-    OSSL_ENCODER_CTX_free(ctx);
-    /* error handling */
-}
-OSSL_ENCODER_CTX_free(ctx);
- -

NOTES

- -

The letters i and d in i2d_TYPE() stand for "internal" (that is, an internal C structure) and "DER" respectively. So i2d_TYPE() converts from internal to DER.

- -

The functions can also understand BER forms.

- -

The actual TYPE structure passed to i2d_TYPE() must be a valid populated TYPE structure -- it cannot simply be fed with an empty structure such as that returned by TYPE_new().

- -

The encoded data is in binary form and may contain embedded zeros. Therefore, any FILE pointers or BIOs should be opened in binary mode. Functions such as strlen() will not return the correct length of the encoded structure.

- -

The ways that *ppin and *ppout are incremented after the operation can trap the unwary. See the WARNINGS section in d2i_X509(3) for some common errors. The reason for this-auto increment behaviour is to reflect a typical usage of ASN1 functions: after one structure is encoded or decoded another will be processed after it.

- -

The following points about the data types might be useful:

- -
- -
DSA_PUBKEY
-
- -

Represents a DSA public key using a SubjectPublicKeyInfo structure.

- -
-
DSAPublicKey, DSAPrivateKey
-
- -

Use a non-standard OpenSSL format and should be avoided; use DSA_PUBKEY, PEM_write_PrivateKey(3), or similar instead.

- -
-
- -

RETURN VALUES

- -

d2i_TYPE(), d2i_TYPE_bio() and d2i_TYPE_fp() return a valid TYPE structure or NULL if an error occurs. If the "reuse" capability has been used with a valid structure being passed in via a, then the object is freed in the event of error and *a is set to NULL.

- -

i2d_TYPE() returns the number of bytes successfully encoded or a negative value if an error occurs.

- -

i2d_TYPE_bio() and i2d_TYPE_fp() return 1 for success and 0 if an error occurs.

- -

SEE ALSO

- -

OSSL_ENCODER(3), OSSL_DECODER(3), d2i_PrivateKey(3), d2i_PublicKey(3), d2i_KeyParams(3), d2i_PUBKEY(3), i2d_PrivateKey(3), i2d_PublicKey(3), i2d_KeyParams(3), i2d_PUBKEY(3)

- -

COPYRIGHT

- -

Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/d2i_SSL_SESSION.html b/openssl-install/share/doc/openssl/html/man3/d2i_SSL_SESSION.html deleted file mode 100644 index b520d1df..00000000 --- a/openssl-install/share/doc/openssl/html/man3/d2i_SSL_SESSION.html +++ /dev/null @@ -1,70 +0,0 @@ - - - - -d2i_SSL_SESSION - - - - - - - - - - -

NAME

- -

d2i_SSL_SESSION, d2i_SSL_SESSION_ex, i2d_SSL_SESSION - convert SSL_SESSION object from/to ASN1 representation

- -

SYNOPSIS

- -
#include <openssl/ssl.h>
-
-SSL_SESSION *d2i_SSL_SESSION(SSL_SESSION **a, const unsigned char **pp,
-                             long length);
-SSL_SESSION *d2i_SSL_SESSION_ex(SSL_SESSION **a, const unsigned char **pp,
-                                long length, OSSL_LIB_CTX *libctx,
-                                const char *propq);
-int i2d_SSL_SESSION(SSL_SESSION *in, unsigned char **pp);
- -

DESCRIPTION

- -

These functions decode and encode an SSL_SESSION object. For encoding details see d2i_X509(3).

- -

SSL_SESSION objects keep internal link information about the session cache list, when being inserted into one SSL_CTX object's session cache. One SSL_SESSION object, regardless of its reference count, must therefore only be used with one SSL_CTX object (and the SSL objects created from this SSL_CTX object).

- -

RETURN VALUES

- -

d2i_SSL_SESSION() and d2i_SSL_SESSION_ex() return a pointer to the newly allocated SSL_SESSION object. In case of failure the NULL-pointer is returned and the error message can be retrieved from the error stack.

- -

i2d_SSL_SESSION() returns the size of the ASN1 representation in bytes. When the session is not valid, 0 is returned and no operation is performed.

- -

SEE ALSO

- -

ssl(7), SSL_SESSION_free(3), SSL_CTX_sess_set_get_cb(3), d2i_X509(3)

- -

HISTORY

- -

The function d2i_SSL_SESSION_ex() was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/d2i_X509.html b/openssl-install/share/doc/openssl/html/man3/d2i_X509.html deleted file mode 100644 index 7243782c..00000000 --- a/openssl-install/share/doc/openssl/html/man3/d2i_X509.html +++ /dev/null @@ -1,242 +0,0 @@ - - - - -d2i_X509 - - - - - - - - - - -

NAME

- -

d2i_ACCESS_DESCRIPTION, d2i_ADMISSIONS, d2i_ADMISSION_SYNTAX, d2i_ASIdOrRange, d2i_ASIdentifierChoice, d2i_ASIdentifiers, d2i_ASN1_BIT_STRING, d2i_ASN1_BMPSTRING, d2i_ASN1_ENUMERATED, d2i_ASN1_GENERALIZEDTIME, d2i_ASN1_GENERALSTRING, d2i_ASN1_IA5STRING, d2i_ASN1_INTEGER, d2i_ASN1_NULL, d2i_ASN1_OBJECT, d2i_ASN1_OCTET_STRING, d2i_ASN1_PRINTABLE, d2i_ASN1_PRINTABLESTRING, d2i_ASN1_SEQUENCE_ANY, d2i_ASN1_SET_ANY, d2i_ASN1_T61STRING, d2i_ASN1_TIME, d2i_ASN1_TYPE, d2i_ASN1_UINTEGER, d2i_ASN1_UNIVERSALSTRING, d2i_ASN1_UTCTIME, d2i_ASN1_UTF8STRING, d2i_ASN1_VISIBLESTRING, d2i_ASRange, d2i_AUTHORITY_INFO_ACCESS, d2i_AUTHORITY_KEYID, d2i_BASIC_CONSTRAINTS, d2i_CERTIFICATEPOLICIES, d2i_CMS_ContentInfo, d2i_CMS_ReceiptRequest, d2i_CMS_bio, d2i_CRL_DIST_POINTS, d2i_DHxparams, d2i_DIRECTORYSTRING, d2i_DISPLAYTEXT, d2i_DIST_POINT, d2i_DIST_POINT_NAME, d2i_DSA_SIG, d2i_ECDSA_SIG, d2i_ECPKParameters, d2i_EDIPARTYNAME, d2i_ESS_CERT_ID, d2i_ESS_CERT_ID_V2, d2i_ESS_ISSUER_SERIAL, d2i_ESS_SIGNING_CERT, d2i_ESS_SIGNING_CERT_V2, d2i_EXTENDED_KEY_USAGE, d2i_GENERAL_NAME, d2i_GENERAL_NAMES, d2i_IPAddressChoice, d2i_IPAddressFamily, d2i_IPAddressOrRange, d2i_IPAddressRange, d2i_ISSUER_SIGN_TOOL, d2i_ISSUING_DIST_POINT, d2i_NAMING_AUTHORITY, d2i_NETSCAPE_CERT_SEQUENCE, d2i_NETSCAPE_SPKAC, d2i_NETSCAPE_SPKI, d2i_NOTICEREF, d2i_OCSP_BASICRESP, d2i_OCSP_CERTID, d2i_OCSP_CERTSTATUS, d2i_OCSP_CRLID, d2i_OCSP_ONEREQ, d2i_OCSP_REQINFO, d2i_OCSP_REQUEST, d2i_OCSP_RESPBYTES, d2i_OCSP_RESPDATA, d2i_OCSP_RESPID, d2i_OCSP_RESPONSE, d2i_OCSP_REVOKEDINFO, d2i_OCSP_SERVICELOC, d2i_OCSP_SIGNATURE, d2i_OCSP_SINGLERESP, d2i_OSSL_ATTRIBUTES_SYNTAX, d2i_OSSL_BASIC_ATTR_CONSTRAINTS, d2i_OSSL_CMP_ATAVS, d2i_OSSL_CMP_MSG, d2i_OSSL_CMP_PKIHEADER, d2i_OSSL_CMP_PKISI, d2i_OSSL_CRMF_CERTID, d2i_OSSL_CRMF_CERTTEMPLATE, d2i_OSSL_CRMF_ENCRYPTEDVALUE, d2i_OSSL_CRMF_MSG, d2i_OSSL_CRMF_MSGS, d2i_OSSL_CRMF_PBMPARAMETER, d2i_OSSL_CRMF_PKIPUBLICATIONINFO, d2i_OSSL_CRMF_SINGLEPUBINFO, d2i_OSSL_IETF_ATTR_SYNTAX, d2i_OSSL_ISSUER_SERIAL, d2i_OSSL_OBJECT_DIGEST_INFO, d2i_OSSL_TARGET_CERT, d2i_OSSL_TARGET, d2i_OSSL_TARGETING_INFORMATION, d2i_OSSL_TARGETS, d2i_OSSL_USER_NOTICE_SYNTAX, d2i_OTHERNAME, d2i_PBE2PARAM, d2i_PBEPARAM, d2i_PBKDF2PARAM, d2i_PBMAC1PARAM, d2i_PKCS12, d2i_PKCS12_BAGS, d2i_PKCS12_MAC_DATA, d2i_PKCS12_SAFEBAG, d2i_PKCS12_bio, d2i_PKCS12_fp, d2i_PKCS7, d2i_PKCS7_DIGEST, d2i_PKCS7_ENCRYPT, d2i_PKCS7_ENC_CONTENT, d2i_PKCS7_ENVELOPE, d2i_PKCS7_ISSUER_AND_SERIAL, d2i_PKCS7_RECIP_INFO, d2i_PKCS7_SIGNED, d2i_PKCS7_SIGNER_INFO, d2i_PKCS7_SIGN_ENVELOPE, d2i_PKCS7_bio, d2i_PKCS7_fp, d2i_PKCS8_PRIV_KEY_INFO, d2i_PKCS8_PRIV_KEY_INFO_bio, d2i_PKCS8_PRIV_KEY_INFO_fp, d2i_PKCS8_bio, d2i_PKCS8_fp, d2i_PKEY_USAGE_PERIOD, d2i_POLICYINFO, d2i_POLICYQUALINFO, d2i_PROFESSION_INFO, d2i_PROXY_CERT_INFO_EXTENSION, d2i_PROXY_POLICY, d2i_RSA_OAEP_PARAMS, d2i_RSA_PSS_PARAMS, d2i_SCRYPT_PARAMS, d2i_SCT_LIST, d2i_SXNET, d2i_SXNETID, d2i_TS_ACCURACY, d2i_TS_MSG_IMPRINT, d2i_TS_MSG_IMPRINT_bio, d2i_TS_MSG_IMPRINT_fp, d2i_TS_REQ, d2i_TS_REQ_bio, d2i_TS_REQ_fp, d2i_TS_RESP, d2i_TS_RESP_bio, d2i_TS_RESP_fp, d2i_TS_STATUS_INFO, d2i_TS_TST_INFO, d2i_TS_TST_INFO_bio, d2i_TS_TST_INFO_fp, d2i_USERNOTICE, d2i_X509, d2i_X509_bio, d2i_X509_fp, d2i_X509_ACERT, d2i_X509_ACERT_bio, d2i_X509_ACERT_fp, d2i_X509_ALGOR, d2i_X509_ALGORS, d2i_X509_ATTRIBUTE, d2i_X509_CERT_AUX, d2i_X509_CINF, d2i_X509_CRL, d2i_X509_CRL_INFO, d2i_X509_CRL_bio, d2i_X509_CRL_fp, d2i_X509_EXTENSION, d2i_X509_EXTENSIONS, d2i_X509_NAME, d2i_X509_NAME_ENTRY, d2i_X509_PUBKEY, d2i_X509_PUBKEY_bio, d2i_X509_PUBKEY_fp, d2i_X509_REQ, d2i_X509_REQ_INFO, d2i_X509_REQ_bio, d2i_X509_REQ_fp, d2i_X509_REVOKED, d2i_X509_SIG, d2i_X509_VAL, i2d_ACCESS_DESCRIPTION, i2d_ADMISSIONS, i2d_ADMISSION_SYNTAX, i2d_ASIdOrRange, i2d_ASIdentifierChoice, i2d_ASIdentifiers, i2d_ASN1_BIT_STRING, i2d_ASN1_BMPSTRING, i2d_ASN1_ENUMERATED, i2d_ASN1_GENERALIZEDTIME, i2d_ASN1_GENERALSTRING, i2d_ASN1_IA5STRING, i2d_ASN1_INTEGER, i2d_ASN1_NULL, i2d_ASN1_OBJECT, i2d_ASN1_OCTET_STRING, i2d_ASN1_PRINTABLE, i2d_ASN1_PRINTABLESTRING, i2d_ASN1_SEQUENCE_ANY, i2d_ASN1_SET_ANY, i2d_ASN1_T61STRING, i2d_ASN1_TIME, i2d_ASN1_TYPE, i2d_ASN1_UNIVERSALSTRING, i2d_ASN1_UTCTIME, i2d_ASN1_UTF8STRING, i2d_ASN1_VISIBLESTRING, i2d_ASN1_bio_stream, i2d_ASRange, i2d_AUTHORITY_INFO_ACCESS, i2d_AUTHORITY_KEYID, i2d_BASIC_CONSTRAINTS, i2d_CERTIFICATEPOLICIES, i2d_CMS_ContentInfo, i2d_CMS_ReceiptRequest, i2d_CMS_bio, i2d_CRL_DIST_POINTS, i2d_DHxparams, i2d_DIRECTORYSTRING, i2d_DISPLAYTEXT, i2d_DIST_POINT, i2d_DIST_POINT_NAME, i2d_DSA_SIG, i2d_ECDSA_SIG, i2d_ECPKParameters, i2d_EDIPARTYNAME, i2d_ESS_CERT_ID, i2d_ESS_CERT_ID_V2, i2d_ESS_ISSUER_SERIAL, i2d_ESS_SIGNING_CERT, i2d_ESS_SIGNING_CERT_V2, i2d_EXTENDED_KEY_USAGE, i2d_GENERAL_NAME, i2d_GENERAL_NAMES, i2d_IPAddressChoice, i2d_IPAddressFamily, i2d_IPAddressOrRange, i2d_IPAddressRange, i2d_ISSUER_SIGN_TOOL, i2d_ISSUING_DIST_POINT, i2d_NAMING_AUTHORITY, i2d_NETSCAPE_CERT_SEQUENCE, i2d_NETSCAPE_SPKAC, i2d_NETSCAPE_SPKI, i2d_NOTICEREF, i2d_OCSP_BASICRESP, i2d_OCSP_CERTID, i2d_OCSP_CERTSTATUS, i2d_OCSP_CRLID, i2d_OCSP_ONEREQ, i2d_OCSP_REQINFO, i2d_OCSP_REQUEST, i2d_OCSP_RESPBYTES, i2d_OCSP_RESPDATA, i2d_OCSP_RESPID, i2d_OCSP_RESPONSE, i2d_OCSP_REVOKEDINFO, i2d_OCSP_SERVICELOC, i2d_OCSP_SIGNATURE, i2d_OCSP_SINGLERESP, i2d_OSSL_ATTRIBUTES_SYNTAX, i2d_OSSL_BASIC_ATTR_CONSTRAINTS, i2d_OSSL_CMP_ATAVS, i2d_OSSL_CMP_MSG, i2d_OSSL_CMP_PKIHEADER, i2d_OSSL_CMP_PKISI, i2d_OSSL_CRMF_CERTID, i2d_OSSL_CRMF_CERTTEMPLATE, i2d_OSSL_CRMF_ENCRYPTEDVALUE, i2d_OSSL_CRMF_MSG, i2d_OSSL_CRMF_MSGS, i2d_OSSL_CRMF_PBMPARAMETER, i2d_OSSL_CRMF_PKIPUBLICATIONINFO, i2d_OSSL_CRMF_SINGLEPUBINFO, i2d_OSSL_IETF_ATTR_SYNTAX, i2d_OSSL_ISSUER_SERIAL, i2d_OSSL_OBJECT_DIGEST_INFO, i2d_OSSL_TARGET_CERT, i2d_OSSL_TARGET, i2d_OSSL_TARGETING_INFORMATION, i2d_OSSL_TARGETS, i2d_OSSL_USER_NOTICE_SYNTAX, i2d_OTHERNAME, i2d_PBE2PARAM, i2d_PBEPARAM, i2d_PBKDF2PARAM, i2d_PBMAC1PARAM, i2d_PKCS12, i2d_PKCS12_BAGS, i2d_PKCS12_MAC_DATA, i2d_PKCS12_SAFEBAG, i2d_PKCS12_bio, i2d_PKCS12_fp, i2d_PKCS7, i2d_PKCS7_DIGEST, i2d_PKCS7_ENCRYPT, i2d_PKCS7_ENC_CONTENT, i2d_PKCS7_ENVELOPE, i2d_PKCS7_ISSUER_AND_SERIAL, i2d_PKCS7_NDEF, i2d_PKCS7_RECIP_INFO, i2d_PKCS7_SIGNED, i2d_PKCS7_SIGNER_INFO, i2d_PKCS7_SIGN_ENVELOPE, i2d_PKCS7_bio, i2d_PKCS7_fp, i2d_PKCS8PrivateKeyInfo_bio, i2d_PKCS8PrivateKeyInfo_fp, i2d_PKCS8_PRIV_KEY_INFO, i2d_PKCS8_PRIV_KEY_INFO_bio, i2d_PKCS8_PRIV_KEY_INFO_fp, i2d_PKCS8_bio, i2d_PKCS8_fp, i2d_PKEY_USAGE_PERIOD, i2d_POLICYINFO, i2d_POLICYQUALINFO, i2d_PROFESSION_INFO, i2d_PROXY_CERT_INFO_EXTENSION, i2d_PROXY_POLICY, i2d_RSA_OAEP_PARAMS, i2d_RSA_PSS_PARAMS, i2d_SCRYPT_PARAMS, i2d_SCT_LIST, i2d_SXNET, i2d_SXNETID, i2d_TS_ACCURACY, i2d_TS_MSG_IMPRINT, i2d_TS_MSG_IMPRINT_bio, i2d_TS_MSG_IMPRINT_fp, i2d_TS_REQ, i2d_TS_REQ_bio, i2d_TS_REQ_fp, i2d_TS_RESP, i2d_TS_RESP_bio, i2d_TS_RESP_fp, i2d_TS_STATUS_INFO, i2d_TS_TST_INFO, i2d_TS_TST_INFO_bio, i2d_TS_TST_INFO_fp, i2d_USERNOTICE, i2d_X509, i2d_X509_bio, i2d_X509_fp, i2d_X509_ACERT, i2d_X509_ACERT_bio, i2d_X509_ACERT_fp, i2d_X509_ALGOR, i2d_X509_ALGORS, i2d_X509_ATTRIBUTE, i2d_X509_CERT_AUX, i2d_X509_CINF, i2d_X509_CRL, i2d_X509_CRL_INFO, i2d_X509_CRL_bio, i2d_X509_CRL_fp, i2d_X509_EXTENSION, i2d_X509_EXTENSIONS, i2d_X509_NAME, i2d_X509_NAME_ENTRY, i2d_X509_PUBKEY, i2d_X509_PUBKEY_bio, i2d_X509_PUBKEY_fp, i2d_X509_REQ, i2d_X509_REQ_INFO, i2d_X509_REQ_bio, i2d_X509_REQ_fp, i2d_X509_REVOKED, i2d_X509_SIG, i2d_X509_VAL, - convert objects from/to ASN.1/DER representation

- -

SYNOPSIS

- -
TYPE *d2i_TYPE(TYPE **a, const unsigned char **ppin, long length);
-TYPE *d2i_TYPE_bio(BIO *bp, TYPE **a);
-TYPE *d2i_TYPE_fp(FILE *fp, TYPE **a);
-
-int i2d_TYPE(const TYPE *a, unsigned char **ppout);
-int i2d_TYPE(TYPE *a, unsigned char **ppout);
-int i2d_TYPE_fp(FILE *fp, const TYPE *a);
-int i2d_TYPE_fp(FILE *fp, TYPE *a);
-int i2d_TYPE_bio(BIO *bp, const TYPE *a);
-int i2d_TYPE_bio(BIO *bp, TYPE *a);
- -

DESCRIPTION

- -

In the description here, TYPE is used a placeholder for any of the OpenSSL datatypes, such as X509_CRL. The function parameters ppin and ppout are generally either both named pp in the headers, or in and out.

- -

These functions convert OpenSSL objects to and from their ASN.1/DER encoding. Unlike the C structures which can have pointers to sub-objects within, the DER is a serialized encoding, suitable for sending over the network, writing to a file, and so on.

- -

d2i_TYPE() attempts to decode len bytes at *ppin. If successful a pointer to the TYPE structure is returned and *ppin is incremented to the byte following the parsed data. If a is not NULL then a pointer to the returned structure is also written to *a. If an error occurred then NULL is returned. The caller retains ownership of the returned object and needs to free it when it is no longer needed, e.g. using X509_free() for X509 objects or DSA_SIG_free() for DSA_SIG objects.

- -

On a successful return, if *a is not NULL then it is assumed that *a contains a valid TYPE structure and an attempt is made to reuse it. For TYPE structures where it matters it is possible to set up a library context on the decoded structure this way (see the EXAMPLES section). However using the "reuse" capability for other purposes is strongly discouraged (see BUGS below, and the discussion in the RETURN VALUES section).

- -

d2i_TYPE_bio() is similar to d2i_TYPE() except it attempts to parse data from BIO bp.

- -

d2i_TYPE_fp() is similar to d2i_TYPE() except it attempts to parse data from FILE pointer fp.

- -

i2d_TYPE() encodes the structure pointed to by a into DER format. If ppout is not NULL, it writes the DER encoded data to the buffer at *ppout, and increments it to point after the data just written. If the return value is negative an error occurred, otherwise it returns the length of the encoded data.

- -

If *ppout is NULL memory will be allocated for a buffer and the encoded data written to it. In this case *ppout is not incremented and it points to the start of the data just written.

- -

i2d_TYPE_bio() is similar to i2d_TYPE() except it writes the encoding of the structure a to BIO bp and it returns 1 for success and 0 for failure.

- -

i2d_TYPE_fp() is similar to i2d_TYPE() except it writes the encoding of the structure a to FILE pointer fp and it returns 1 for success and 0 for failure.

- -

These routines do not encrypt private keys and therefore offer no security; use PEM_write_PrivateKey(3) or similar for writing to files.

- -

NOTES

- -

The letters i and d in i2d_TYPE() stand for "internal" (that is, an internal C structure) and "DER" respectively. So i2d_TYPE() converts from internal to DER.

- -

The functions can also understand BER forms.

- -

The actual TYPE structure passed to i2d_TYPE() must be a valid populated TYPE structure -- it cannot simply be fed with an empty structure such as that returned by TYPE_new().

- -

The encoded data is in binary form and may contain embedded zeros. Therefore, any FILE pointers or BIOs should be opened in binary mode. Functions such as strlen() will not return the correct length of the encoded structure.

- -

The ways that *ppin and *ppout are incremented after the operation can trap the unwary. See the WARNINGS section for some common errors. The reason for this-auto increment behaviour is to reflect a typical usage of ASN1 functions: after one structure is encoded or decoded another will be processed after it.

- -

The following points about the data types might be useful:

- -
- -
ASN1_OBJECT
-
- -

Represents an ASN1 OBJECT IDENTIFIER.

- -
-
DHparams
-
- -

Represents a PKCS#3 DH parameters structure.

- -
-
DHxparams
-
- -

Represents an ANSI X9.42 DH parameters structure.

- -
-
ECDSA_SIG
-
- -

Represents an ECDSA signature.

- -
-
X509_ALGOR
-
- -

Represents an AlgorithmIdentifier structure as used in IETF RFC 6960 and elsewhere.

- -
-
X509_NAME
-
- -

Represents a Name type as used for subject and issuer names in IETF RFC 6960 and elsewhere.

- -
-
X509_REQ
-
- -

Represents a PKCS#10 certificate request.

- -
-
X509_SIG
-
- -

Represents the DigestInfo structure defined in PKCS#1 and PKCS#7.

- -
-
- -

RETURN VALUES

- -

d2i_TYPE(), d2i_TYPE_bio() and d2i_TYPE_fp() return a valid TYPE structure or NULL if an error occurs. If the "reuse" capability has been used with a valid structure being passed in via a, then the object is freed in the event of error and *a is set to NULL.

- -

i2d_TYPE() returns the number of bytes successfully encoded or a negative value if an error occurs.

- -

i2d_TYPE_bio() and i2d_TYPE_fp() return 1 for success and 0 if an error occurs.

- -

EXAMPLES

- -

Allocate and encode the DER encoding of an X509 structure:

- -
int len;
-unsigned char *buf;
-
-buf = NULL;
-len = i2d_X509(x, &buf);
-if (len < 0)
-    /* error */
- -

Attempt to decode a buffer:

- -
X509 *x;
-unsigned char *buf;
-const unsigned char *p;
-int len;
-
-/* Set up buf and len to point to the input buffer. */
-p = buf;
-x = d2i_X509(NULL, &p, len);
-if (x == NULL)
-    /* error */
- -

Alternative technique:

- -
X509 *x;
-unsigned char *buf;
-const unsigned char *p;
-int len;
-
-/* Set up buf and len to point to the input buffer. */
-p = buf;
-x = NULL;
-
-if (d2i_X509(&x, &p, len) == NULL)
-    /* error */
- -

Setting up a library context and property query:

- -
X509 *x;
-unsigned char *buf;
-const unsigned char *p;
-int len;
-OSSL_LIB_CTX *libctx = ....;
-const char *propq = ....;
-
-/* Set up buf and len to point to the input buffer. */
-p = buf;
-x = X509_new_ex(libctx, propq);
-
-if (d2i_X509(&x, &p, len) == NULL)
-    /* error, x was freed and NULL assigned to it (see RETURN VALUES) */
- -

WARNINGS

- -

Using a temporary variable is mandatory. A common mistake is to attempt to use a buffer directly as follows:

- -
int len;
-unsigned char *buf;
-
-len = i2d_X509(x, NULL);
-buf = OPENSSL_malloc(len);
-...
-i2d_X509(x, &buf);
-...
-OPENSSL_free(buf);
- -

This code will result in buf apparently containing garbage because it was incremented after the call to point after the data just written. Also buf will no longer contain the pointer allocated by OPENSSL_malloc() and the subsequent call to OPENSSL_free() is likely to crash.

- -

Another trap to avoid is misuse of the a argument to d2i_TYPE():

- -
X509 *x;
-
-if (d2i_X509(&x, &p, len) == NULL)
-    /* error */
- -

This will probably crash somewhere in d2i_X509(). The reason for this is that the variable x is uninitialized and an attempt will be made to interpret its (invalid) value as an X509 structure, typically causing a segmentation violation. If x is set to NULL first then this will not happen.

- -

BUGS

- -

In some versions of OpenSSL the "reuse" behaviour of d2i_TYPE() when *a is valid is broken and some parts of the reused structure may persist if they are not present in the new one. Additionally, in versions of OpenSSL prior to 1.1.0, when the "reuse" behaviour is used and an error occurs the behaviour is inconsistent. Some functions behaved as described here, while some did not free *a on error and did not set *a to NULL.

- -

As a result of the above issues the "reuse" behaviour is strongly discouraged.

- -

i2d_TYPE() will not return an error in many versions of OpenSSL, if mandatory fields are not initialized due to a programming error then the encoded structure may contain invalid data or omit the fields entirely and will not be parsed by d2i_TYPE(). This may be fixed in future so code should not assume that i2d_TYPE() will always succeed.

- -

Any function which encodes a structure (i2d_TYPE(), i2d_TYPE_bio() or i2d_TYPE_fp()) may return a stale encoding if the structure has been modified after deserialization or previous serialization. This is because some objects cache the encoding for efficiency reasons.

- -

COPYRIGHT

- -

Copyright 1998-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/i2d_CMS_bio_stream.html b/openssl-install/share/doc/openssl/html/man3/i2d_CMS_bio_stream.html deleted file mode 100644 index 4c41f8f0..00000000 --- a/openssl-install/share/doc/openssl/html/man3/i2d_CMS_bio_stream.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -i2d_CMS_bio_stream - - - - - - - - - - -

NAME

- -

i2d_CMS_bio_stream - output CMS_ContentInfo structure in BER format

- -

SYNOPSIS

- -
#include <openssl/cms.h>
-
-int i2d_CMS_bio_stream(BIO *out, CMS_ContentInfo *cms, BIO *data, int flags);
- -

DESCRIPTION

- -

i2d_CMS_bio_stream() outputs a CMS_ContentInfo structure in BER format.

- -

It is otherwise identical to the function SMIME_write_CMS().

- -

NOTES

- -

This function is effectively a version of the i2d_CMS_bio() supporting streaming.

- -

BUGS

- -

The prefix "i2d" is arguably wrong because the function outputs BER format.

- -

RETURN VALUES

- -

i2d_CMS_bio_stream() returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), CMS_sign(3), CMS_verify(3), CMS_encrypt(3) CMS_decrypt(3), SMIME_write_CMS(3), PEM_write_bio_CMS_stream(3)

- -

HISTORY

- -

The i2d_CMS_bio_stream() function was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/i2d_PKCS7_bio_stream.html b/openssl-install/share/doc/openssl/html/man3/i2d_PKCS7_bio_stream.html deleted file mode 100644 index e6044c68..00000000 --- a/openssl-install/share/doc/openssl/html/man3/i2d_PKCS7_bio_stream.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -i2d_PKCS7_bio_stream - - - - - - - - - - -

NAME

- -

i2d_PKCS7_bio_stream - output PKCS7 structure in BER format

- -

SYNOPSIS

- -
#include <openssl/pkcs7.h>
-
-int i2d_PKCS7_bio_stream(BIO *out, PKCS7 *p7, BIO *data, int flags);
- -

DESCRIPTION

- -

i2d_PKCS7_bio_stream() outputs a PKCS7 structure in BER format.

- -

It is otherwise identical to the function SMIME_write_PKCS7().

- -

NOTES

- -

This function is effectively a version of the d2i_PKCS7_bio() supporting streaming.

- -

BUGS

- -

The prefix "i2d" is arguably wrong because the function outputs BER format.

- -

RETURN VALUES

- -

i2d_PKCS7_bio_stream() returns 1 for success or 0 for failure.

- -

SEE ALSO

- -

ERR_get_error(3), PKCS7_sign(3), PKCS7_verify(3), PKCS7_encrypt(3) PKCS7_decrypt(3), SMIME_write_PKCS7(3), PEM_write_bio_PKCS7_stream(3)

- -

HISTORY

- -

The i2d_PKCS7_bio_stream() function was added in OpenSSL 1.0.0.

- -

COPYRIGHT

- -

Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/i2d_re_X509_tbs.html b/openssl-install/share/doc/openssl/html/man3/i2d_re_X509_tbs.html deleted file mode 100644 index 3b5cb30f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/i2d_re_X509_tbs.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -i2d_re_X509_tbs - - - - - - - - - - -

NAME

- -

d2i_X509_AUX, i2d_X509_AUX, i2d_re_X509_tbs, i2d_re_X509_CRL_tbs, i2d_re_X509_REQ_tbs - X509 encode and decode functions

- -

SYNOPSIS

- -
#include <openssl/x509.h>
-
-X509 *d2i_X509_AUX(X509 **px, const unsigned char **in, long len);
-int i2d_X509_AUX(const X509 *x, unsigned char **out);
-int i2d_re_X509_tbs(X509 *x, unsigned char **out);
-int i2d_re_X509_CRL_tbs(X509_CRL *crl, unsigned char **pp);
-int i2d_re_X509_REQ_tbs(X509_REQ *req, unsigned char **pp);
- -

DESCRIPTION

- -

The X509 encode and decode routines encode and parse an X509 structure, which represents an X509 certificate.

- -

d2i_X509_AUX() is similar to d2i_X509(3) but the input is expected to consist of an X509 certificate followed by auxiliary trust information. This is used by the PEM routines to read "TRUSTED CERTIFICATE" objects. This function should not be called on untrusted input.

- -

i2d_X509_AUX() is similar to i2d_X509(3), but the encoded output contains both the certificate and any auxiliary trust information. This is used by the PEM routines to write "TRUSTED CERTIFICATE" objects. Note that this is a non-standard OpenSSL-specific data format.

- -

i2d_re_X509_tbs() is similar to i2d_X509(3) except it encodes only the TBSCertificate portion of the certificate. i2d_re_X509_CRL_tbs() and i2d_re_X509_REQ_tbs() are analogous for CRL and certificate request, respectively. The "re" in i2d_re_X509_tbs stands for "re-encode", and ensures that a fresh encoding is generated in case the object has been modified after creation (see the BUGS section).

- -

The encoding of the TBSCertificate portion of a certificate is cached in the X509 structure internally to improve encoding performance and to ensure certificate signatures are verified correctly in some certificates with broken (non-DER) encodings.

- -

If, after modification, the X509 object is re-signed with X509_sign(), the encoding is automatically renewed. Otherwise, the encoding of the TBSCertificate portion of the X509 can be manually renewed by calling i2d_re_X509_tbs().

- -

RETURN VALUES

- -

d2i_X509_AUX() returns a valid X509 structure or NULL if an error occurred.

- -

i2d_X509_AUX() returns the length of encoded data or -1 on error.

- -

i2d_re_X509_tbs(), i2d_re_X509_CRL_tbs() and i2d_re_X509_REQ_tbs() return the length of encoded data or <=0 on error.

- -

SEE ALSO

- -

ERR_get_error(3) X509_CRL_get0_by_serial(3), X509_get0_signature(3), X509_get_ext_d2i(3), X509_get_extension_flags(3), X509_get_pubkey(3), X509_get_subject_name(3), X509_get_version(3), X509_NAME_add_entry_by_txt(3), X509_NAME_ENTRY_get_object(3), X509_NAME_get_index_by_NID(3), X509_NAME_print_ex(3), X509_new(3), X509_sign(3), X509V3_get_d2i(3), X509_verify_cert(3)

- -

COPYRIGHT

- -

Copyright 2002-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/o2i_SCT_LIST.html b/openssl-install/share/doc/openssl/html/man3/o2i_SCT_LIST.html deleted file mode 100644 index 15010b0f..00000000 --- a/openssl-install/share/doc/openssl/html/man3/o2i_SCT_LIST.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -o2i_SCT_LIST - - - - - - - - - - -

NAME

- -

o2i_SCT_LIST, i2o_SCT_LIST, o2i_SCT, i2o_SCT - decode and encode Signed Certificate Timestamp lists in TLS wire format

- -

SYNOPSIS

- -
#include <openssl/ct.h>
-
-STACK_OF(SCT) *o2i_SCT_LIST(STACK_OF(SCT) **a, const unsigned char **pp,
-                            size_t len);
-int i2o_SCT_LIST(const STACK_OF(SCT) *a, unsigned char **pp);
-SCT *o2i_SCT(SCT **psct, const unsigned char **in, size_t len);
-int i2o_SCT(const SCT *sct, unsigned char **out);
- -

DESCRIPTION

- -

The SCT_LIST and SCT functions are very similar to the i2d and d2i family of functions, except that they convert to and from TLS wire format, as described in RFC 6962. See d2i_SCT_LIST(3) for more information about how the parameters are treated and the return values.

- -

RETURN VALUES

- -

All of the functions have return values consistent with those stated for d2i_SCT_LIST(3) and i2d_SCT_LIST(3).

- -

SEE ALSO

- -

ct(7), d2i_SCT_LIST(3), i2d_SCT_LIST(3)

- -

HISTORY

- -

These functions were added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man3/s2i_ASN1_IA5STRING.html b/openssl-install/share/doc/openssl/html/man3/s2i_ASN1_IA5STRING.html deleted file mode 100644 index 11a3d4e8..00000000 --- a/openssl-install/share/doc/openssl/html/man3/s2i_ASN1_IA5STRING.html +++ /dev/null @@ -1,97 +0,0 @@ - - - - -s2i_ASN1_IA5STRING - - - - - - - - - - -

NAME

- -

i2s_ASN1_IA5STRING, s2i_ASN1_IA5STRING, i2s_ASN1_INTEGER, s2i_ASN1_INTEGER, i2s_ASN1_OCTET_STRING, s2i_ASN1_OCTET_STRING, i2s_ASN1_ENUMERATED, i2s_ASN1_ENUMERATED_TABLE, i2s_ASN1_UTF8STRING, s2i_ASN1_UTF8STRING - convert objects from/to ASN.1/string representation

- -

SYNOPSIS

- -
#include <openssl/x509v3.h>
-
-char *i2s_ASN1_IA5STRING(X509V3_EXT_METHOD *method, ASN1_IA5STRING *ia5);
-ASN1_IA5STRING *s2i_ASN1_IA5STRING(X509V3_EXT_METHOD *method,
-                                  X509V3_CTX *ctx, const char *str);
-char *i2s_ASN1_INTEGER(X509V3_EXT_METHOD *method, const ASN1_INTEGER *a);
-ASN1_INTEGER *s2i_ASN1_INTEGER(X509V3_EXT_METHOD *method, const char *value);
-char *i2s_ASN1_OCTET_STRING(X509V3_EXT_METHOD *method,
-                           const ASN1_OCTET_STRING *oct);
-ASN1_OCTET_STRING *s2i_ASN1_OCTET_STRING(X509V3_EXT_METHOD *method,
-                                        X509V3_CTX *ctx, const char *str);
-char *i2s_ASN1_ENUMERATED(X509V3_EXT_METHOD *method, const ASN1_ENUMERATED *a);
-char *i2s_ASN1_ENUMERATED_TABLE(X509V3_EXT_METHOD *method,
-                               const ASN1_ENUMERATED *e);
-
-char *i2s_ASN1_UTF8STRING(X509V3_EXT_METHOD *method,
-                          ASN1_UTF8STRING *utf8);
-ASN1_UTF8STRING *s2i_ASN1_UTF8STRING(X509V3_EXT_METHOD *method,
-                                     X509V3_CTX *ctx, const char *str);
- -

DESCRIPTION

- -

These functions convert OpenSSL objects to and from their ASN.1/string representation. This function is used for X509v3 extensions.

- -

NOTES

- -

The letters i and s in i2s and s2i stand for "internal" (that is, an internal C structure) and string respectively. So i2s_ASN1_IA5STRING() converts from internal to string.

- -

It is the caller's responsibility to free the returned string. In the i2s_ASN1_IA5STRING() function the string is copied and the ownership of the original string remains with the caller.

- -

RETURN VALUES

- -

i2s_ASN1_IA5STRING() returns the pointer to a IA5 string or NULL if an error occurs.

- -

s2i_ASN1_IA5STRING() return a valid ASN1_IA5STRING structure or NULL if an error occurs.

- -

i2s_ASN1_INTEGER() return a valid string or NULL if an error occurs.

- -

s2i_ASN1_INTEGER() returns the pointer to a ASN1_INTEGER structure or NULL if an error occurs.

- -

i2s_ASN1_OCTET_STRING() returns the pointer to a OCTET_STRING string or NULL if an error occurs.

- -

s2i_ASN1_OCTET_STRING() return a valid ASN1_OCTET_STRING structure or NULL if an error occurs.

- -

i2s_ASN1_ENUMERATED() return a valid string or NULL if an error occurs.

- -

s2i_ASN1_ENUMERATED() returns the pointer to a ASN1_ENUMERATED structure or NULL if an error occurs.

- -

s2i_ASN1_UTF8STRING() return a valid ASN1_UTF8STRING structure or NULL if an error occurs.

- -

i2s_ASN1_UTF8STRING() returns the pointer to a UTF-8 string or NULL if an error occurs.

- -

HISTORY

- -

i2s_ASN1_UTF8STRING() and s2i_ASN1_UTF8STRING() were made public in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man5/config.html b/openssl-install/share/doc/openssl/html/man5/config.html deleted file mode 100644 index 70303ee7..00000000 --- a/openssl-install/share/doc/openssl/html/man5/config.html +++ /dev/null @@ -1,501 +0,0 @@ - - - - -config - - - - - - - - - - -

NAME

- -

config - OpenSSL CONF library configuration files

- -

DESCRIPTION

- -

This page documents the syntax of OpenSSL configuration files, as parsed by NCONF_load(3) and related functions. This format is used by many of the OpenSSL commands, and to initialize the libraries when used by any application.

- -

The first part describes the general syntax of the configuration files, and subsequent sections describe the semantics of individual modules. Other modules are described in fips_config(5) and x509v3_config(5). The syntax for defining ASN.1 values is described in ASN1_generate_nconf(3).

- -

SYNTAX

- -

A configuration file is a series of lines. Blank lines, and whitespace between the elements of a line, have no significance. A comment starts with a # character; the rest of the line is ignored. If the # is the first non-space character in a line, the entire line is ignored.

- -

Directives

- -

Two directives can be used to control the parsing of configuration files: .include and .pragma.

- -

For compatibility with older versions of OpenSSL, an equal sign after the directive will be ignored. Older versions will treat it as an assignment, so care should be taken if the difference in semantics is important.

- -

A file can include other files using the include syntax:

- -
.include [=] pathname
- -

If pathname is a simple filename, that file is included directly at that point. Included files can have .include statements that specify other files. If pathname is a directory, all files within that directory that have a .cnf or .conf extension will be included. (This is only available on systems with POSIX IO support.) Any sub-directories found inside the pathname are ignored. Similarly, if a file is opened while scanning a directory, and that file has an .include directive that specifies a directory, that is also ignored.

- -

As a general rule, the pathname should be an absolute path; this can be enforced with the abspath and includedir pragmas, described below. The environment variable OPENSSL_CONF_INCLUDE, if it exists, is prepended to all relative pathnames. If the pathname is still relative, it is interpreted based on the current working directory.

- -

To require all file inclusions to name absolute paths, use the following directive:

- -
.pragma [=] abspath:value
- -

The default behavior, where the value is false or off, is to allow relative paths. To require all .include pathnames to be absolute paths, use a value of true or on.

- -

In these files, the dollar sign, $, is used to reference a variable, as described below. On some platforms, however, it is common to treat $ as a regular character in symbol names. Supporting this behavior can be done with the following directive:

- -
.pragma [=] dollarid:value
- -

The default behavior, where the value is false or off, is to treat the dollarsign as indicating a variable name; foo$bar is interpreted as foo followed by the expansion of the variable bar. If value is true or on, then foo$bar is a single seven-character name and variable expansions must be specified using braces or parentheses.

- -
.pragma [=] includedir:value
- -

If a relative pathname is specified in the .include directive, and the OPENSSL_CONF_INCLUDE environment variable doesn't exist, then the value of the includedir pragma, if it exists, is prepended to the pathname.

- -

Settings

- -

A configuration file is divided into a number of sections. A section begins with the section name in square brackets, and ends when a new section starts, or at the end of the file. The section name can consist of alphanumeric characters and underscores. Whitespace between the name and the brackets is removed.

- -

The first section of a configuration file is special and is referred to as the default section. This section is usually unnamed and spans from the start of file until the first named section. When a name is being looked up, it is first looked up in the current or named section, and then the default section if necessary.

- -

The environment is mapped onto a section called ENV.

- -

Within a section are a series of name/value assignments, described in more detail below. As a reminder, the square brackets shown in this example are required, not optional:

- -
[ section ]
-name1 = This is value1
-name2 = Another value
-...
-[ newsection ]
-name1 = New value1
-name3 = Value 3
- -

The name can contain any alphanumeric characters as well as a few punctuation symbols such as . , ; and _. Whitespace after the name and before the equal sign is ignored.

- -

If a name is repeated in the same section, then all but the last value are ignored. In certain circumstances, such as with Certificate DNs, the same field may occur multiple times. In order to support this, commands like openssl-req(1) ignore any leading text that is preceded with a period. For example:

- -
1.OU = First OU
-2.OU = Second OU
- -

The value consists of the string following the = character until end of line with any leading and trailing whitespace removed.

- -

The value string undergoes variable expansion. The text $var or ${var} inserts the value of the named variable from the current section. To use a value from another section use $section::name or ${section::name}. By using $ENV::name, the value of the specified environment variable will be substituted.

- -

Variables must be defined before their value is referenced, otherwise an error is flagged and the file will not load. This can be worked around by specifying a default value in the default section before the variable is used.

- -

Any name/value settings in an ENV section are available to the configuration file, but are not propagated to the environment.

- -

It is an error if the value ends up longer than 64k.

- -

It is possible to escape certain characters by using a single ' or double " quote around the value, or using a backslash \ before the character, By making the last character of a line a \ a value string can be spread across multiple lines. In addition the sequences \n, \r, \b and \t are recognized.

- -

The expansion and escape rules as described above that apply to value also apply to the pathname of the .include directive.

- -

OPENSSL LIBRARY CONFIGURATION

- -

The sections below use the informal term module to refer to a part of the OpenSSL functionality. This is not the same as the formal term FIPS module, for example.

- -

The OpenSSL configuration looks up the value of openssl_conf in the default section and takes that as the name of a section that specifies how to configure any modules in the library. It is not an error to leave any module in its default configuration. An application can specify a different name by calling CONF_modules_load_file(), for example, directly.

- -

OpenSSL also looks up the value of config_diagnostics. If this exists and has a nonzero numeric value, any error suppressing flags passed to CONF_modules_load() will be ignored. This is useful for diagnosing misconfigurations but its use in production requires additional consideration. With this option enabled, a configuration error will completely prevent access to a service. Without this option and in the presence of a configuration error, access will be allowed but the desired configuration will not be used.

- -
# These must be in the default section
-config_diagnostics = 1
-openssl_conf = openssl_init
-
-[openssl_init]
-oid_section = oids
-providers = providers
-alg_section = evp_properties
-ssl_conf = ssl_configuration
-engines = engines
-random = random
-
-[oids]
-... new oids here ...
-
-[providers]
-... provider stuff here ...
-
-[evp_properties]
-... EVP properties here ...
-
-[ssl_configuration]
-... SSL/TLS configuration properties here ...
-
-[engines]
-... engine properties here ...
-
-[random]
-... random properties here ...
- -

The semantics of each module are described below. The phrase "in the initialization section" refers to the section identified by the openssl_conf or other name (given as openssl_init in the example above). The examples below assume the configuration above is used to specify the individual sections.

- -

ASN.1 Object Identifier Configuration

- -

The name oid_section in the initialization section names the section containing name/value pairs of OID's. The name is the short name; the value is an optional long name followed by a comma, and the numeric value. While some OpenSSL commands have their own section for specifying OID's, this section makes them available to all commands and applications.

- -
[oids]
-shortName = a very long OID name, 1.2.3.4
-newoid1 = 1.2.3.4.1
-some_other_oid = 1.2.3.5
- -

If a full configuration with the above fragment is in the file example.cnf, then the following command line:

- -
OPENSSL_CONF=example.cnf openssl asn1parse -genstr OID:1.2.3.4.1
- -

will output:

- -
0:d=0  hl=2 l=   4 prim: OBJECT            :newoid1
- -

showing that the OID "newoid1" has been added as "1.2.3.4.1".

- -

Provider Configuration

- -

The name providers in the initialization section names the section containing cryptographic provider configuration. The name/value assignments in this section each name a provider, and point to the configuration section for that provider. The provider-specific section is used to specify how to load the module, activate it, and set other parameters.

- -

Within a provider section, the following names have meaning:

- -
- -
identity
-
- -

This is used to specify an alternate name, overriding the default name specified in the list of providers. For example:

- -
[providers]
-foo = foo_provider
-
-[foo_provider]
-identity = my_fips_module
- -
-
module
-
- -

Specifies the pathname of the module (typically a shared library) to load.

- -
-
activate
-
- -

If present and set to one of the values yes, on, true or 1, then the associated provider will be activated. Conversely, setting this value to no, off, false, or 0 will prevent the provider from being activated. Settings can be given in lower or uppercase. Setting activate to any other setting, or omitting a setting value will result in an error.

- -

= item soft_load

- -

If enabled, informs the library to clear the error stack on failure to activate requested provider. A value of 1, yes, true or on (in lower or uppercase) will activate this setting, while a value of 0, no, false, or off (again in lower or uppercase) will disable this setting. Any other value will produce an error. Note this setting defaults to off if not provided

- -
-
- -

All parameters in the section as well as sub-sections are made available to the provider.

- -

Default provider and its activation

- -

If no providers are activated explicitly, the default one is activated implicitly. See OSSL_PROVIDER-default(7) for more details.

- -

If you add a section explicitly activating any other provider(s), you most probably need to explicitly activate the default provider, otherwise it becomes unavailable in openssl. It may make the system remotely unavailable.

- -

EVP Configuration

- -

The name alg_section in the initialization section names the section containing algorithmic properties when using the EVP API.

- -

Within the algorithm properties section, the following names have meaning:

- -
- -
default_properties
-
- -

The value may be anything that is acceptable as a property query string for EVP_set_default_properties().

- -
-
fips_mode (deprecated)
-
- -

The value is a boolean that can be yes or no. If the value is yes, this is exactly equivalent to:

- -
default_properties = fips=yes
- -

If the value is no, nothing happens. Using this name is deprecated, and if used, it must be the only name in the section.

- -
-
- -

SSL Configuration

- -

The name ssl_conf in the initialization section names the section containing the list of SSL/TLS configurations. As with the providers, each name in this section identifies a section with the configuration for that name. For example:

- -
[ssl_configuration]
-server = server_tls_config
-client = client_tls_config
-system_default = tls_system_default
-
-[server_tls_config]
-... configuration for SSL/TLS servers ...
-
-[client_tls_config]
-... configuration for SSL/TLS clients ...
- -

The configuration name system_default has a special meaning. If it exists, it is applied whenever an SSL_CTX object is created. For example, to impose system-wide minimum TLS and DTLS protocol versions:

- -
[tls_system_default]
-MinProtocol = TLSv1.2
-MinProtocol = DTLSv1.2
- -

The minimum TLS protocol is applied to SSL_CTX objects that are TLS-based, and the minimum DTLS protocol to those are DTLS-based. The same applies also to maximum versions set with MaxProtocol.

- -

Each configuration section consists of name/value pairs that are parsed by SSL_CONF_cmd(3), which will be called by SSL_CTX_config() or SSL_config(), appropriately. Note that any characters before an initial dot in the configuration section are ignored, so that the same command can be used multiple times. This probably is most useful for loading different key types, as shown here:

- -
[server_tls_config]
-RSA.Certificate = server-rsa.pem
-ECDSA.Certificate = server-ecdsa.pem
- -

Engine Configuration

- -

The name engines in the initialization section names the section containing the list of ENGINE configurations. As with the providers, each name in this section identifies an engine with the configuration for that engine. The engine-specific section is used to specify how to load the engine, activate it, and set other parameters.

- -

Within an engine section, the following names have meaning:

- -
- -
engine_id
-
- -

This is used to specify an alternate name, overriding the default name specified in the list of engines. If present, it must be first. For example:

- -
[engines]
-foo = foo_engine
-
-[foo_engine]
-engine_id = myfoo
- -
-
dynamic_path
-
- -

This loads and adds an ENGINE from the given path. It is equivalent to sending the ctrls SO_PATH with the path argument followed by LIST_ADD with value 2 and LOAD to the dynamic ENGINE. If this is not the required behaviour then alternative ctrls can be sent directly to the dynamic ENGINE using ctrl commands.

- -
-
init
-
- -

This specifies whether to initialize the ENGINE. If the value is 0 the ENGINE will not be initialized, if the value is 1 an attempt is made to initialize the ENGINE immediately. If the init command is not present then an attempt will be made to initialize the ENGINE after all commands in its section have been processed.

- -
-
default_algorithms
-
- -

This sets the default algorithms an ENGINE will supply using the function ENGINE_set_default_string().

- -
-
- -

All other names are taken to be the name of a ctrl command that is sent to the ENGINE, and the value is the argument passed with the command. The special value EMPTY means no value is sent with the command. For example:

- -
[engines]
-foo = foo_engine
-
-[foo_engine]
-dynamic_path = /some/path/fooengine.so
-some_ctrl = some_value
-default_algorithms = ALL
-other_ctrl = EMPTY
- -

Random Configuration

- -

The name random in the initialization section names the section containing the random number generator settings.

- -

Within the random section, the following names have meaning:

- -
- -
random
-
- -

This is used to specify the random bit generator. For example:

- -
[random]
-random = CTR-DRBG
- -

The available random bit generators are:

- -
- -
CTR-DRBG
-
- -
-
HASH-DRBG
-
- -
-
HMAC-DRBG
-
- -
-
- -
-
cipher
-
- -

This specifies what cipher a CTR-DRBG random bit generator will use. Other random bit generators ignore this name. The default value is AES-256-CTR.

- -
-
digest
-
- -

This specifies what digest the HASH-DRBG or HMAC-DRBG random bit generators will use. Other random bit generators ignore this name.

- -
-
properties
-
- -

This sets the property query used when fetching the random bit generator and any underlying algorithms.

- -
-
seed
-
- -

This sets the randomness source that should be used. By default SEED-SRC will be used outside of the FIPS provider. The FIPS provider uses call backs to access the same randomness sources from outside the validated boundary.

- -
-
seed_properties
-
- -

This sets the property query used when fetching the randomness source.

- -
-
- -

EXAMPLES

- -

This example shows how to use quoting and escaping.

- -
# This is the default section.
-HOME = /temp
-configdir = $ENV::HOME/config
-
-[ section_one ]
-# Quotes permit leading and trailing whitespace
-any = " any variable name "
-other = A string that can \
-cover several lines \
-by including \\ characters
-message = Hello World\n
-
-[ section_two ]
-greeting = $section_one::message
- -

This example shows how to expand environment variables safely. In this example, the variable tempfile is intended to refer to a temporary file, and the environment variable TEMP or TMP, if present, specify the directory where the file should be put. Since the default section is checked if a variable does not exist, it is possible to set TMP to default to /tmp, and TEMP to default to TMP.

- -
# These two lines must be in the default section.
-TMP = /tmp
-TEMP = $ENV::TMP
-
-# This can be used anywhere
-tmpfile = ${ENV::TEMP}/tmp.filename
- -

This example shows how to enforce FIPS mode for the application sample.

- -
sample = fips_config
-
-[fips_config]
-alg_section = evp_properties
-
-[evp_properties]
-default_properties = "fips=yes"
- -

ENVIRONMENT

- -
- -
OPENSSL_CONF
-
- -

The path to the config file, or the empty string for none. Ignored in set-user-ID and set-group-ID programs.

- -
-
OPENSSL_ENGINES
-
- -

The path to the engines directory. Ignored in set-user-ID and set-group-ID programs.

- -
-
OPENSSL_MODULES
-
- -

The path to the directory with OpenSSL modules, such as providers. Ignored in set-user-ID and set-group-ID programs.

- -
-
OPENSSL_CONF_INCLUDE
-
- -

The optional path to prepend to all .include paths.

- -
-
- -

BUGS

- -

There is no way to include characters using the octal \nnn form. Strings are all null terminated so nulls cannot form part of the value.

- -

The escaping isn't quite right: if you want to use sequences like \n you can't use any quote escaping on the same line.

- -

The limit that only one directory can be opened and read at a time can be considered a bug and should be fixed.

- -

HISTORY

- -

An undocumented API, NCONF_WIN32(), used a slightly different set of parsing rules there were intended to be tailored to the Microsoft Windows platform. Specifically, the backslash character was not an escape character and could be used in pathnames, only the double-quote character was recognized, and comments began with a semi-colon. This function was deprecated in OpenSSL 3.0; applications with configuration files using that syntax will have to be modified.

- -

SEE ALSO

- -

openssl-x509(1), openssl-req(1), openssl-ca(1), openssl-fipsinstall(1), ASN1_generate_nconf(3), EVP_set_default_properties(3), CONF_modules_load(3), CONF_modules_load_file(3), fips_config(5), and x509v3_config(5).

- -

COPYRIGHT

- -

Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man5/fips_config.html b/openssl-install/share/doc/openssl/html/man5/fips_config.html deleted file mode 100644 index fcb58c9f..00000000 --- a/openssl-install/share/doc/openssl/html/man5/fips_config.html +++ /dev/null @@ -1,307 +0,0 @@ - - - - -fips_config - - - - - - - - - - -

NAME

- -

fips_config - OpenSSL FIPS configuration

- -

DESCRIPTION

- -

A separate configuration file, using the OpenSSL config(5) syntax, is used to hold information about the FIPS module. This includes a digest of the shared library file, and status about the self-testing. This data is used automatically by the module itself for two purposes:

- -
- -
- Run the startup FIPS self-test known answer tests (KATS).
-
- -

This is normally done once, at installation time, but may also be set up to run each time the module is used.

- -
-
- Verify the module's checksum.
-
- -

This is done each time the module is used.

- -
-
- -

This file is generated by the openssl-fipsinstall(1) program, and used internally by the FIPS module during its initialization.

- -

The following options are supported. They should all appear in a section whose name is identified by the fips option in the providers section, as described in "Provider Configuration Module" in config(5).

- -
- -
activate
-
- -

If present, the module is activated. The value assigned to this name is not significant.

- -
-
conditional-errors
-
- -

The FIPS module normally enters an internal error mode if any self test fails. Once this error mode is active, no services or cryptographic algorithms are accessible from this point on. Continuous tests are a subset of the self tests (e.g., a key pair test during key generation, or the CRNG output test). Setting this value to 0 allows the error mode to not be triggered if any continuous test fails. The default value of 1 will trigger the error mode. Regardless of the value, the operation (e.g., key generation) that called the continuous test will return an error code if its continuous test fails. The operation may then be retried if the error mode has not been triggered.

- -
-
module-mac
-
- -

The calculated MAC of the FIPS provider file.

- -
-
install-version
-
- -

A version number for the fips install process. Should be 1.

- -
-
install-status
-
- -

An indicator that the self-tests were successfully run. This should only be written after the module has successfully passed its self tests during installation. If this field is not present, then the self tests will run when the module loads.

- -
-
install-mac
-
- -

A MAC of the value of the install-status option, to prevent accidental changes to that value. It is written-to at the same time as install-status is updated.

- -
-
- -

FIPS indicator options

- -

The following FIPS configuration options indicate if run-time checks related to enforcement of FIPS security parameters such as minimum security strength of keys and approved curve names are used. A value of '1' will perform the checks, otherwise if the value is '0' the checks are not performed and FIPS compliance must be done by procedures documented in the relevant Security Policy.

- -

See "OPTIONS" in openssl-fipsinstall(1) for further information related to these options.

- -
- -
security-checks
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -no_security_checks

- -
-
tls1-prf-ems-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -ems_check

- -
-
no-short-mac
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -no_short_mac

- -
-
drbg-no-trunc-md
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -no_drbg_truncated_digests

- -
-
signature-digest-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -signature_digest_check

- -
-
hkdf-digest-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -hkdf_digest_check

- -
-
tls13-kdf-digest-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -tls13_kdf_digest_check

- -
-
tls1-prf-digest-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -tls1_prf_digest_check

- -
-
sshkdf-digest-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -sshkdf_digest_check

- -
-
sskdf-digest-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -sskdf_digest_check

- -
-
x963kdf-digest-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -x963kdf_digest_check

- -
-
dsa-sign-disabled
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -dsa_sign_disabled

- -
-
tdes-encrypt-disabled
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -tdes_encrypt_disabled

- -
-
rsa-pkcs15-pad-disabled
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -rsa_pkcs15_pad_disabled

- -
-
rsa-pss-saltlen-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -rsa_pss_saltlen_check

- -
-
rsa-sign-x931-pad-disabled
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -rsa_sign_x931_disabled

- -
-
hkdf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -hkdf_key_check

- -
-
kbkdf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -kbkdf_key_check

- -
-
tls13-kdf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -tls13_kdf_key_check

- -
-
tls1-prf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -tls1_prf_key_check

- -
-
sshkdf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -sshkdf_key_check

- -
-
sskdf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -sskdf_key_check

- -
-
x963kdf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -x963kdf_key_check

- -
-
x942kdf-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -x942kdf_key_check

- -
-
pbkdf2-lower-bound-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -no_pbkdf2_lower_bound_check

- -
-
ecdh-cofactor-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -ecdh_cofactor_check

- -
-
hmac-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -hmac_key_check

- -
-
kmac-key-check
-
- -

See "OPTIONS" in openssl-fipsinstall(1) -kmac_key_check

- -
-
- -

For example:

- -
[fips_sect]
-activate = 1
-install-version = 1
-conditional-errors = 1
-security-checks = 1
-module-mac = 41:D0:FA:C2:5D:41:75:CD:7D:C3:90:55:6F:A4:DC
-install-mac = FE:10:13:5A:D3:B4:C7:82:1B:1E:17:4C:AC:84:0C
-install-status = INSTALL_SELF_TEST_KATS_RUN
- -

NOTES

- -

When using the FIPS provider, it is recommended that the config_diagnostics option is enabled to prevent accidental use of non-FIPS validated algorithms via broken or mistaken configuration. See config(5).

- -

SEE ALSO

- -

config(5) openssl-fipsinstall(1)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man5/x509v3_config.html b/openssl-install/share/doc/openssl/html/man5/x509v3_config.html deleted file mode 100644 index 63902f1e..00000000 --- a/openssl-install/share/doc/openssl/html/man5/x509v3_config.html +++ /dev/null @@ -1,540 +0,0 @@ - - - - -x509v3_config - - - - - - - - - - -

NAME

- -

x509v3_config - X509 V3 certificate extension configuration format

- -

DESCRIPTION

- -

Several OpenSSL commands can add extensions to a certificate or certificate request based on the contents of a configuration file and CLI options such as -addext. The syntax of configuration files is described in config(5). The commands typically have an option to specify the name of the configuration file, and a section within that file; see the documentation of the individual command for details.

- -

This page uses extensions as the name of the section, when needed in examples.

- -

Each entry in the extension section takes the form:

- -
name = [critical, ]value(s)
- -

If critical is present then the extension will be marked as critical.

- -

If multiple entries are processed for the same extension name, later entries override earlier ones with the same name.

- -

The format of values depends on the value of name, many have a type-value pairing where the type and value are separated by a colon. There are four main types of extension:

- -
string
-multi-valued
-raw
-arbitrary
- -

Each is described in the following paragraphs.

- -

String extensions simply have a string which contains either the value itself or how it is obtained.

- -

Multi-valued extensions have a short form and a long form. The short form is a comma-separated list of names and values:

- -
basicConstraints = critical, CA:true, pathlen:1
- -

The long form allows the values to be placed in a separate section:

- -
[extensions]
-basicConstraints = critical, @basic_constraints
-
-[basic_constraints]
-CA = true
-pathlen = 1
- -

Both forms are equivalent.

- -

If an extension is multi-value and a field value must contain a comma the long form must be used otherwise the comma would be misinterpreted as a field separator. For example:

- -
subjectAltName = URI:ldap://somehost.com/CN=foo,OU=bar
- -

will produce an error but the equivalent form:

- -
[extensions]
-subjectAltName = @subject_alt_section
-
-[subject_alt_section]
-subjectAltName = URI:ldap://somehost.com/CN=foo,OU=bar
- -

is valid.

- -

OpenSSL does not support multiple occurrences of the same field within a section. In this example:

- -
[extensions]
-subjectAltName = @alt_section
-
-[alt_section]
-email = steve@example.com
-email = steve@example.org
- -

will only recognize the last value. To specify multiple values append a numeric identifier, as shown here:

- -
[extensions]
-subjectAltName = @alt_section
-
-[alt_section]
-email.1 = steve@example.com
-email.2 = steve@example.org
- -

The syntax of raw extensions is defined by the source code that parses the extension but should be documented. See "Certificate Policies" for an example of a raw extension.

- -

If an extension type is unsupported, then the arbitrary extension syntax must be used, see the "ARBITRARY EXTENSIONS" section for more details.

- -

STANDARD EXTENSIONS

- -

The following sections describe the syntax of each supported extension. They do not define the semantics of the extension.

- -

Basic Constraints

- -

This is a multi-valued extension which indicates whether a certificate is a CA certificate. The first value is CA followed by TRUE or FALSE. If CA is TRUE then an optional pathlen name followed by a nonnegative value can be included.

- -

For example:

- -
basicConstraints = CA:TRUE
-
-basicConstraints = CA:FALSE
-
-basicConstraints = critical, CA:TRUE, pathlen:1
- -

A CA certificate must include the basicConstraints name with the CA parameter set to TRUE. An end-user certificate must either have CA:FALSE or omit the extension entirely. The pathlen parameter specifies the maximum number of CAs that can appear below this one in a chain. A pathlen of zero means the CA cannot sign any sub-CA's, and can only sign end-entity certificates.

- -

Key Usage

- -

Key usage is a multi-valued extension consisting of a list of names of the permitted key usages. The defined values are: digitalSignature, nonRepudiation, keyEncipherment, dataEncipherment, keyAgreement, keyCertSign, cRLSign, encipherOnly, and decipherOnly.

- -

Examples:

- -
keyUsage = digitalSignature, nonRepudiation
-
-keyUsage = critical, keyCertSign
- -

Extended Key Usage

- -

This extension consists of a list of values indicating purposes for which the certificate public key can be used. Each value can be either a short text name or an OID. The following text names, and their intended meaning, are known:

- -
Value                  Meaning according to RFC 5280 etc.
------                  ----------------------------------
-serverAuth             SSL/TLS WWW Server Authentication
-clientAuth             SSL/TLS WWW Client Authentication
-codeSigning            Code Signing
-emailProtection        E-mail Protection (S/MIME)
-timeStamping           Trusted Timestamping
-OCSPSigning            OCSP Signing
-ipsecIKE               ipsec Internet Key Exchange
-msCodeInd              Microsoft Individual Code Signing (authenticode)
-msCodeCom              Microsoft Commercial Code Signing (authenticode)
-msCTLSign              Microsoft Trust List Signing
-msEFS                  Microsoft Encrypted File System
- -

While IETF RFC 5280 says that id-kp-serverAuth and id-kp-clientAuth are only for WWW use, in practice they are used for all kinds of TLS clients and servers, and this is what OpenSSL assumes as well.

- -

Examples:

- -
extendedKeyUsage = critical, codeSigning, 1.2.3.4
-
-extendedKeyUsage = serverAuth, clientAuth
- -

Subject Key Identifier

- -

The SKID extension specification has a value with three choices.

- -
- -
none
-
- -

No SKID extension will be included.

- -
-
hash
-
- -

The process specified in RFC 5280 section 4.2.1.2. (1) is followed: The keyIdentifier is composed of the 160-bit SHA-1 hash of the value of the BIT STRING subjectPublicKey (excluding the tag, length, and number of unused bits).

- -
-
A hex string (possibly with : separating bytes)
-
- -

The provided value is output directly. This choice is strongly discouraged.

- -
-
- -

By default the x509, req, and ca apps behave as if hash was given.

- -

Example:

- -
subjectKeyIdentifier = hash
- -

Authority Key Identifier

- -

The AKID extension specification may have the value none indicating that no AKID shall be included. Otherwise it may have the value keyid or issuer or both of them, separated by ,. Either or both can have the option always, indicated by putting a colon : between the value and this option. For self-signed certificates the AKID is suppressed unless always is present.

- -

By default the x509, req, and ca apps behave as if none was given for self-signed certificates and keyid, issuer otherwise.

- -

If keyid is present, an attempt is made to copy the subject key identifier (SKID) from the issuer certificate except if the issuer certificate is the same as the current one and it is not self-signed. The hash of the public key related to the signing key is taken as fallback if the issuer certificate is the same as the current certificate. If always is present but no value can be obtained, an error is returned.

- -

If issuer is present, and in addition it has the option always specified or keyid is not present, then the issuer DN and serial number are copied from the issuer certificate. If this fails, an error is returned.

- -

Examples:

- -
authorityKeyIdentifier = keyid, issuer
-
-authorityKeyIdentifier = keyid, issuer:always
- -

Subject Alternative Name

- -

This is a multi-valued extension that supports several types of name identifier, including email (an email address), URI (a uniform resource indicator), DNS (a DNS domain name), RID (a registered ID: OBJECT IDENTIFIER), IP (an IP address), dirName (a distinguished name), and otherName. The syntax of each is described in the following paragraphs.

- -

The email option has two special values. copy will automatically include any email addresses contained in the certificate subject name in the extension. move will automatically move any email addresses from the certificate subject name to the extension.

- -

The IP address used in the IP option can be in either IPv4 or IPv6 format.

- -

The value of dirName is specifies the configuration section containing the distinguished name to use, as a set of name-value pairs. Multi-valued AVAs can be formed by prefacing the name with a + character.

- -

The value of otherName can include arbitrary data associated with an OID; the value should be the OID followed by a semicolon and the content in specified using the syntax in ASN1_generate_nconf(3).

- -

Examples:

- -
subjectAltName = email:copy, email:my@example.com, URI:http://my.example.com/
-
-subjectAltName = IP:192.168.7.1
-
-subjectAltName = IP:13::17
-
-subjectAltName = email:my@example.com, RID:1.2.3.4
-
-subjectAltName = otherName:1.2.3.4;UTF8:some other identifier
-
-[extensions]
-subjectAltName = dirName:dir_sect
-
-[dir_sect]
-C = UK
-O = My Organization
-OU = My Unit
-CN = My Name
- -

Non-ASCII Email Address conforming the syntax defined in Section 3.3 of RFC 6531 are provided as otherName.SmtpUTF8Mailbox. According to RFC 8398, the email address should be provided as UTF8String. To enforce the valid representation in the certificate, the SmtpUTF8Mailbox should be provided as follows

- -
subjectAltName=@alts
-[alts]
-otherName = 1.3.6.1.5.5.7.8.9;FORMAT:UTF8,UTF8String:nonasciiname.example.com
- -

Issuer Alternative Name

- -

This extension supports most of the options of subject alternative name; it does not support email:copy. It also adds issuer:copy as an allowed value, which copies any subject alternative names from the issuer certificate, if possible.

- -

Example:

- -
issuerAltName = issuer:copy
- -

Authority Info Access

- -

This extension gives details about how to retrieve information that related to the certificate that the CA makes available. The syntax is access_id;location, where access_id is an object identifier (although only a few values are well-known) and location has the same syntax as subject alternative name (except that email:copy is not supported).

- -

Possible values for access_id include OCSP (OCSP responder), caIssuers (CA Issuers), ad_timestamping (AD Time Stamping), AD_DVCS (ad dvcs), caRepository (CA Repository).

- -

Examples:

- -
authorityInfoAccess = OCSP;URI:http://ocsp.example.com/,caIssuers;URI:http://myca.example.com/ca.cer
-
-authorityInfoAccess = OCSP;URI:http://ocsp.example.com/
- -

CRL distribution points

- -

This is a multi-valued extension whose values can be either a name-value pair using the same form as subject alternative name or a single value specifying the section name containing all the distribution point values.

- -

When a name-value pair is used, a DistributionPoint extension will be set with the given value as the fullName field as the distributionPoint value, and the reasons and cRLIssuer fields will be omitted.

- -

When a single option is used, the value specifies the section, and that section can have the following items:

- -
- -
fullname
-
- -

The full name of the distribution point, in the same format as the subject alternative name.

- -
-
relativename
-
- -

The value is taken as a distinguished name fragment that is set as the value of the nameRelativeToCRLIssuer field.

- -
-
CRLIssuer
-
- -

The value must in the same format as the subject alternative name.

- -
-
reasons
-
- -

A multi-value field that contains the reasons for revocation. The recognized values are: keyCompromise, CACompromise, affiliationChanged, superseded, cessationOfOperation, certificateHold, privilegeWithdrawn, and AACompromise.

- -
-
- -

Only one of fullname or relativename should be specified.

- -

Simple examples:

- -
crlDistributionPoints = URI:http://example.com/myca.crl
-
-crlDistributionPoints = URI:http://example.com/myca.crl, URI:http://example.org/my.crl
- -

Full distribution point example:

- -
[extensions]
-crlDistributionPoints = crldp1_section
-
-[crldp1_section]
-fullname = URI:http://example.com/myca.crl
-CRLissuer = dirName:issuer_sect
-reasons = keyCompromise, CACompromise
-
-[issuer_sect]
-C = UK
-O = Organisation
-CN = Some Name
- -

Issuing Distribution Point

- -

This extension should only appear in CRLs. It is a multi-valued extension whose syntax is similar to the "section" pointed to by the CRL distribution points extension. The following names have meaning:

- -
- -
fullname
-
- -

The full name of the distribution point, in the same format as the subject alternative name.

- -
-
relativename
-
- -

The value is taken as a distinguished name fragment that is set as the value of the nameRelativeToCRLIssuer field.

- -
-
onlysomereasons
-
- -

A multi-value field that contains the reasons for revocation. The recognized values are: keyCompromise, CACompromise, affiliationChanged, superseded, cessationOfOperation, certificateHold, privilegeWithdrawn, and AACompromise.

- -
-
onlyuser, onlyCA, onlyAA, indirectCRL
-
- -

The value for each of these names is a boolean.

- -
-
- -

Example:

- -
[extensions]
-issuingDistributionPoint = critical, @idp_section
-
-[idp_section]
-fullname = URI:http://example.com/myca.crl
-indirectCRL = TRUE
-onlysomereasons = keyCompromise, CACompromise
- -

Certificate Policies

- -

This is a raw extension that supports all of the defined fields of the certificate extension.

- -

Policies without qualifiers are specified by giving the OID. Multiple policies are comma-separated. For example:

- -
certificatePolicies = 1.2.4.5, 1.1.3.4
- -

To include policy qualifiers, use the "@section" syntax to point to a section that specifies all the information.

- -

The section referred to must include the policy OID using the name policyIdentifier. cPSuri qualifiers can be included using the syntax:

- -
CPS.nnn = value
- -

where nnn is a number.

- -

userNotice qualifiers can be set using the syntax:

- -
userNotice.nnn = @notice
- -

The value of the userNotice qualifier is specified in the relevant section. This section can include explicitText, organization, and noticeNumbers options. explicitText and organization are text strings, noticeNumbers is a comma separated list of numbers. The organization and noticeNumbers options (if included) must BOTH be present. Some software might require the ia5org option at the top level; this changes the encoding from Displaytext to IA5String.

- -

Example:

- -
[extensions]
-certificatePolicies = ia5org, 1.2.3.4, 1.5.6.7.8, @polsect
-
-[polsect]
-policyIdentifier = 1.3.5.8
-CPS.1 = "http://my.host.example.com/"
-CPS.2 = "http://my.your.example.com/"
-userNotice.1 = @notice
-
-[notice]
-explicitText = "Explicit Text Here"
-organization = "Organisation Name"
-noticeNumbers = 1, 2, 3, 4
- -

The character encoding of explicitText can be specified by prefixing the value with UTF8, BMP, or VISIBLE followed by colon. For example:

- -
[notice]
-explicitText = "UTF8:Explicit Text Here"
- -

Policy Constraints

- -

This is a multi-valued extension which consisting of the names requireExplicitPolicy or inhibitPolicyMapping and a non negative integer value. At least one component must be present.

- -

Example:

- -
policyConstraints = requireExplicitPolicy:3
- -

Inhibit Any Policy

- -

This is a string extension whose value must be a non negative integer.

- -

Example:

- -
inhibitAnyPolicy = 2
- -

Name Constraints

- -

This is a multi-valued extension. The name should begin with the word permitted or excluded followed by a ;. The rest of the name and the value follows the syntax of subjectAltName except email:copy is not supported and the IP form should consist of an IP addresses and subnet mask separated by a /.

- -

Examples:

- -
nameConstraints = permitted;IP:192.168.0.0/255.255.0.0
-
-nameConstraints = permitted;email:.example.com
-
-nameConstraints = excluded;email:.com
- -

OCSP No Check

- -

This is a string extension. It is parsed, but ignored.

- -

Example:

- -
noCheck = ignored
- -

TLS Feature (aka Must Staple)

- -

This is a multi-valued extension consisting of a list of TLS extension identifiers. Each identifier may be a number (0..65535) or a supported name. When a TLS client sends a listed extension, the TLS server is expected to include that extension in its reply.

- -

The supported names are: status_request and status_request_v2.

- -

Example:

- -
tlsfeature = status_request
- -

DEPRECATED EXTENSIONS

- -

The following extensions are non standard, Netscape specific and largely obsolete. Their use in new applications is discouraged.

- -

Netscape String extensions

- -

Netscape Comment (nsComment) is a string extension containing a comment which will be displayed when the certificate is viewed in some browsers. Other extensions of this type are: nsBaseUrl, nsRevocationUrl, nsCaRevocationUrl, nsRenewalUrl, nsCaPolicyUrl and nsSslServerName.

- -

Netscape Certificate Type

- -

This is a multi-valued extensions which consists of a list of flags to be included. It was used to indicate the purposes for which a certificate could be used. The basicConstraints, keyUsage and extended key usage extensions are now used instead.

- -

Acceptable values for nsCertType are: client, server, email, objsign, reserved, sslCA, emailCA, objCA.

- -

ARBITRARY EXTENSIONS

- -

If an extension is not supported by the OpenSSL code then it must be encoded using the arbitrary extension format. It is also possible to use the arbitrary format for supported extensions. Extreme care should be taken to ensure that the data is formatted correctly for the given extension type.

- -

There are two ways to encode arbitrary extensions.

- -

The first way is to use the word ASN1 followed by the extension content using the same syntax as ASN1_generate_nconf(3). For example:

- -
[extensions]
-1.2.3.4 = critical, ASN1:UTF8String:Some random data
-1.2.3.4.1 = ASN1:SEQUENCE:seq_sect
-
-[seq_sect]
-field1 = UTF8:field1
-field2 = UTF8:field2
- -

It is also possible to use the word DER to include the raw encoded data in any extension.

- -
1.2.3.4 = critical, DER:01:02:03:04
-1.2.3.4.1 = DER:01020304
- -

The value following DER is a hex dump of the DER encoding of the extension Any extension can be placed in this form to override the default behaviour. For example:

- -
basicConstraints = critical, DER:00:01:02:03
- -

WARNINGS

- -

There is no guarantee that a specific implementation will process a given extension. It may therefore be sometimes possible to use certificates for purposes prohibited by their extensions because a specific application does not recognize or honour the values of the relevant extensions.

- -

The DER and ASN1 options should be used with caution. It is possible to create invalid extensions if they are not used carefully.

- -

SEE ALSO

- -

openssl-req(1), openssl-ca(1), openssl-x509(1), ASN1_generate_nconf(3)

- -

COPYRIGHT

- -

Copyright 2004-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-RSA.html b/openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-RSA.html deleted file mode 100644 index a237f190..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-RSA.html +++ /dev/null @@ -1,168 +0,0 @@ - - - - -EVP_ASYM_CIPHER-RSA - - - - - - - - - - -

NAME

- -

EVP_ASYM_CIPHER-RSA - RSA Asymmetric Cipher algorithm support

- -

DESCRIPTION

- -

Asymmetric Cipher support for the RSA key type.

- -

RSA Asymmetric Cipher parameters

- -
- -
"pad-mode" (OSSL_ASYM_CIPHER_PARAM_PAD_MODE) <UTF8 string>
-
- -

The default provider understands these RSA padding modes in string form:

- -
- -
"none" (OSSL_PKEY_RSA_PAD_MODE_NONE)
-
- -
-
"oaep" (OSSL_PKEY_RSA_PAD_MODE_OAEP)
-
- -
-
"pkcs1" (OSSL_PKEY_RSA_PAD_MODE_PKCSV15)
-
- -

This padding mode is no longer supported by the FIPS provider for key agreement and key transport. (This is a FIPS 140-3 requirement)

- -
-
"x931" (OSSL_PKEY_RSA_PAD_MODE_X931)
-
- -
-
- -
-
"pad-mode" (OSSL_ASYM_CIPHER_PARAM_PAD_MODE) <integer>
-
- -

The default provider understands these RSA padding modes in integer form:

- -
- -
1 (RSA_PKCS1_PADDING)
-
- -

This padding mode is no longer supported by the FIPS provider for key agreement and key transport. (This is a FIPS 140-3 requirement)

- -
-
3 (RSA_NO_PADDING)
-
- -
-
4 (RSA_PKCS1_OAEP_PADDING)
-
- -
-
5 (RSA_X931_PADDING)
-
- -
-
- -

See EVP_PKEY_CTX_set_rsa_padding(3) for further details.

- -
-
"digest" (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST) <UTF8 string>
-
- -
-
"digest-props" (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS) <UTF8 string>
-
- -
-
"mgf1-digest" (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST) <UTF8 string>
-
- -
-
"mgf1-digest-props" (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS) <UTF8 string>
-
- -
-
"oaep-label" (OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL) <octet string>
-
- -
-
"tls-client-version" (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) <unsigned integer>
-
- -

See RSA_PKCS1_WITH_TLS_PADDING on the page EVP_PKEY_CTX_set_rsa_padding(3).

- -
-
"tls-negotiated-version" (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) <unsigned integer>
-
- -

See RSA_PKCS1_WITH_TLS_PADDING on the page EVP_PKEY_CTX_set_rsa_padding(3).

- -

See "Asymmetric Cipher Parameters" in provider-asym_cipher(7) for more information.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"key-check" (OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

See "Asymmetric Cipher Parameters" in provider-asym_cipher(7) for more information.

- -
-
"pkcs15-pad-disabled" (OSSL_ASYM_CIPHER_PARAM_FIPS_RSA_PKCS15_PAD_DISABLED) <integer>
-
- -

The default value of 1 causes an error during encryption if the RSA padding mode is set to "pkcs1". Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

SEE ALSO

- -

EVP_PKEY-RSA(7), EVP_PKEY(3), provider-asym_cipher(7), provider-keymgmt(7), OSSL_PROVIDER-default(7) OSSL_PROVIDER-FIPS(7)

- -

COPYRIGHT

- -

Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-SM2.html b/openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-SM2.html deleted file mode 100644 index 9a2bed71..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_ASYM_CIPHER-SM2.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -EVP_ASYM_CIPHER-SM2 - - - - - - - - - - -

NAME

- -

EVP_ASYM_CIPHER-SM2 - SM2 Asymmetric Cipher algorithm support

- -

DESCRIPTION

- -

Asymmetric Cipher support for the SM2 key type.

- -

SM2 Asymmetric Cipher parameters

- -
- -
"digest" (OSSL_ASYM_CIPHER_PARAM_DIGEST) <UTF8 string>
-
- -
-
"digest-props" (OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS) <UTF8 string>
-
- -

See "Asymmetric Cipher Parameters" in provider-asym_cipher(7).

- -
-
- -

SEE ALSO

- -

EVP_PKEY-SM2(7), EVP_PKEY(3), provider-asym_cipher(7), provider-keymgmt(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-AES.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-AES.html deleted file mode 100644 index 2df1b313..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-AES.html +++ /dev/null @@ -1,135 +0,0 @@ - - - - -EVP_CIPHER-AES - - - - - - - - - - -

NAME

- -

EVP_CIPHER-AES - The AES EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for AES symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the FIPS provider as well as the default provider:

- -
- -
"AES-128-CBC", "AES-192-CBC" and "AES-256-CBC"
-
- -
-
"AES-128-CBC-CTS", "AES-192-CBC-CTS" and "AES-256-CBC-CTS"
-
- -
-
"AES-128-CFB", "AES-192-CFB", "AES-256-CFB", "AES-128-CFB1", "AES-192-CFB1", "AES-256-CFB1", "AES-128-CFB8", "AES-192-CFB8" and "AES-256-CFB8"
-
- -
-
"AES-128-CTR", "AES-192-CTR" and "AES-256-CTR"
-
- -
-
"AES-128-ECB", "AES-192-ECB" and "AES-256-ECB"
-
- -
-
"AES-192-OFB", "AES-128-OFB" and "AES-256-OFB"
-
- -
-
"AES-128-XTS" and "AES-256-XTS"
-
- -
-
"AES-128-CCM", "AES-192-CCM" and "AES-256-CCM"
-
- -
-
"AES-128-GCM", "AES-192-GCM" and "AES-256-GCM"
-
- -
-
"AES-128-WRAP", "AES-192-WRAP", "AES-256-WRAP", "AES-128-WRAP-PAD", "AES-192-WRAP-PAD", "AES-256-WRAP-PAD", "AES-128-WRAP-INV", "AES-192-WRAP-INV", "AES-256-WRAP-INV", "AES-128-WRAP-PAD-INV", "AES-192-WRAP-PAD-INV" and "AES-256-WRAP-PAD-INV"
-
- -
-
"AES-128-CBC-HMAC-SHA1", "AES-256-CBC-HMAC-SHA1", "AES-128-CBC-HMAC-SHA256" and "AES-256-CBC-HMAC-SHA256"
-
- -
-
- -

The following algorithms are available in the default provider, but not the FIPS provider:

- -
- -
"AES-128-OCB", "AES-192-OCB" and "AES-256-OCB"
-
- -
-
"AES-128-SIV", "AES-192-SIV" and "AES-256-SIV"
-
- -
-
"AES-128-GCM-SIV", "AES-192-GCM-SIV" and "AES-256-GCM-SIV"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

NOTES

- -

The AES-SIV and AES-WRAP mode implementations do not support streaming. That means to obtain correct results there can be only one EVP_EncryptUpdate(3) or EVP_DecryptUpdate(3) call after the initialization of the context.

- -

The AES-XTS implementations allow streaming to be performed, but each EVP_EncryptUpdate(3) or EVP_DecryptUpdate(3) call requires each input to be a multiple of the blocksize. Only the final EVP_EncryptUpdate() or EVP_DecryptUpdate() call can optionally have an input that is not a multiple of the blocksize but is larger than one block. In that case ciphertext stealing (CTS) is used to fill the block.

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-default(7)

- -

HISTORY

- -

The GCM-SIV mode ciphers were added in OpenSSL version 3.2.

- -

COPYRIGHT

- -

Copyright 2021-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-ARIA.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-ARIA.html deleted file mode 100644 index 9d93e368..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-ARIA.html +++ /dev/null @@ -1,93 +0,0 @@ - - - - -EVP_CIPHER-ARIA - - - - - - - - - - -

NAME

- -

EVP_CIPHER-ARIA - The ARIA EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for ARIA symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the default provider:

- -
- -
"ARIA-128-CBC", "ARIA-192-CBC" and "ARIA-256-CBC"
-
- -
-
"ARIA-128-CFB", "ARIA-192-CFB", "ARIA-256-CFB", "ARIA-128-CFB1", "ARIA-192-CFB1", "ARIA-256-CFB1", "ARIA-128-CFB8", "ARIA-192-CFB8" and "ARIA-256-CFB8"
-
- -
-
"ARIA-128-CTR", "ARIA-192-CTR" and "ARIA-256-CTR"
-
- -
-
"ARIA-128-ECB", "ARIA-192-ECB" and "ARIA-256-ECB"
-
- -
-
"AES-192-OCB", "AES-128-OCB" and "AES-256-OCB"
-
- -
-
"ARIA-128-OFB", "ARIA-192-OFB" and "ARIA-256-OFB"
-
- -
-
"ARIA-128-CCM", "ARIA-192-CCM" and "ARIA-256-CCM"
-
- -
-
"ARIA-128-GCM", "ARIA-192-GCM" and "ARIA-256-GCM"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-BLOWFISH.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-BLOWFISH.html deleted file mode 100644 index a0b8250d..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-BLOWFISH.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_CIPHER-BLOWFISH - - - - - - - - - - -

NAME

- -

EVP_CIPHER-BLOWFISH - The BLOBFISH EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for BLOWFISH symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the legacy provider:

- -
- -
"BF-ECB"
-
- -
-
"BF-CBC"
-
- -
-
"BF-OFB"
-
- -
-
"BF-CFB"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAMELLIA.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAMELLIA.html deleted file mode 100644 index 22d1c0cc..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAMELLIA.html +++ /dev/null @@ -1,85 +0,0 @@ - - - - -EVP_CIPHER-CAMELLIA - - - - - - - - - - -

NAME

- -

EVP_CIPHER-CAMELLIA - The CAMELLIA EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for CAMELLIA symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the default provider:

- -
- -
"CAMELLIA-128-CBC", "CAMELLIA-192-CBC" and "CAMELLIA-256-CBC"
-
- -
-
"CAMELLIA-128-CBC-CTS", "CAMELLIA-192-CBC-CTS" and "CAMELLIA-256-CBC-CTS"
-
- -
-
"CAMELLIA-128-CFB", "CAMELLIA-192-CFB", "CAMELLIA-256-CFB", "CAMELLIA-128-CFB1", "CAMELLIA-192-CFB1", "CAMELLIA-256-CFB1", "CAMELLIA-128-CFB8", "CAMELLIA-192-CFB8" and "CAMELLIA-256-CFB8"
-
- -
-
"CAMELLIA-128-CTR", "CAMELLIA-192-CTR" and "CAMELLIA-256-CTR"
-
- -
-
"CAMELLIA-128-ECB", "CAMELLIA-192-ECB" and "CAMELLIA-256-ECB"
-
- -
-
"CAMELLIA-192-OFB", "CAMELLIA-128-OFB" and "CAMELLIA-256-OFB"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAST.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAST.html deleted file mode 100644 index 4eadbc84..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CAST.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_CIPHER-CAST - - - - - - - - - - -

NAME

- -

EVP_CIPHER-CAST - The CAST EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for CAST symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the legacy provider:

- -
- -
"CAST-128-CBC", "CAST-192-CBC" and "CAST-256-CBC"
-
- -
-
"CAST-128-CFB", "CAST-192-CFB", "CAST-256-CFB"
-
- -
-
"CAST-128-ECB", "CAST-192-ECB" and "CAST-256-ECB"
-
- -
-
"CAST-192-OFB", "CAST-128-OFB" and "CAST-256-OFB"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CHACHA.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CHACHA.html deleted file mode 100644 index e981c85b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-CHACHA.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -EVP_CIPHER-CHACHA - - - - - - - - - - -

NAME

- -

EVP_CIPHER-CHACHA - The CHACHA EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for CHACHA symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the default provider:

- -
- -
"ChaCha20"
-
- -
-
"ChaCha20-Poly1305"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-DES.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-DES.html deleted file mode 100644 index 7dbc28a6..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-DES.html +++ /dev/null @@ -1,125 +0,0 @@ - - - - -EVP_CIPHER-DES - - - - - - - - - - -

NAME

- -

EVP_CIPHER-DES - The DES EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for DES symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the FIPS provider as well as the default provider:

- -
- -
"DES-EDE3-ECB" or "DES-EDE3"
-
- -
-
"DES-EDE3-CBC" or "DES3"
-
- -
-
- -

The following algorithms are available in the default provider, but not the FIPS provider:

- -
- -
"DES-EDE3-CFB8" and "DES-EDE3-CFB1"
-
- -
-
"DES-EDE-ECB" or "DES-EDE"
-
- -
-
"DES-EDE-CBC"
-
- -
-
"DES-EDE-OFB"
-
- -
-
"DES-EDE-CFB"
-
- -
-
"DES3-WRAP"
-
- -
-
- -

The following algorithms are available in the legacy provider:

- -
- -
"DES-ECB"
-
- -
-
"DES-CBC"
-
- -
-
"DES-OFB"
-
- -
-
"DES-CFB", "DES-CFB1" and "DES-CFB8"
-
- -
-
"DESX-CBC"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3) including "encrypt-check" and "fips-indicator".

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-legacy(7),

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-IDEA.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-IDEA.html deleted file mode 100644 index e9501f80..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-IDEA.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_CIPHER-IDEA - - - - - - - - - - -

NAME

- -

EVP_CIPHER-IDEA - The IDEA EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for IDEA symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the legacy provider:

- -
- -
"IDEA-ECB"
-
- -
-
"IDEA-CBC"
-
- -
-
"IDEA-OFB" or "IDEA-OFB64"
-
- -
-
"IDEA-CFB" or "IDEA-CFB64"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-NULL.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-NULL.html deleted file mode 100644 index 8d71b58e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-NULL.html +++ /dev/null @@ -1,112 +0,0 @@ - - - - -EVP_CIPHER-NULL - - - - - - - - - - -

NAME

- -

EVP_CIPHER-NULL - The NULL EVP_CIPHER implementation

- -

DESCRIPTION

- -

Support for a NULL symmetric encryption using the EVP_CIPHER API. This is used when the TLS cipher suite is TLS_NULL_WITH_NULL_NULL. This does no encryption (just copies the data) and has a mac size of zero.

- -

Algorithm Name

- -

The following algorithm is available in the default provider:

- -
- -
"NULL"
-
- -
-
- -

Parameters

- -

This implementation supports the following parameters:

- -

Gettable EVP_CIPHER parameters

- -

See "Gettable EVP_CIPHER parameters" in EVP_EncryptInit(3)

- -

Gettable EVP_CIPHER_CTX parameters

- -
- -
"keylen" (OSSL_CIPHER_PARAM_KEYLEN) <unsigned integer>
-
- -
-
"ivlen" (OSSL_CIPHER_PARAM_IVLEN and <OSSL_CIPHER_PARAM_AEAD_IVLEN) <unsigned integer>
-
- -
-
"tls-mac" (OSSL_CIPHER_PARAM_TLS_MAC) <octet ptr>
-
- -
-
- -

See "PARAMETERS" in EVP_EncryptInit(3) for further information.

- -

Settable EVP_CIPHER_CTX parameters

- -
- -
"tls-mac-size" (OSSL_CIPHER_PARAM_TLS_MAC_SIZE) <unsigned integer>
-
- -
-
- -

See "PARAMETERS" in EVP_EncryptInit(3) for further information.

- -

CONFORMING TO

- -

RFC 5246 section-6.2.3.1

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC2.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC2.html deleted file mode 100644 index 67f988c7..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC2.html +++ /dev/null @@ -1,85 +0,0 @@ - - - - -EVP_CIPHER-RC2 - - - - - - - - - - -

NAME

- -

EVP_CIPHER-RC2 - The RC2 EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for RC2 symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the legacy provider:

- -
- -
"RC2-CBC", "RC2" or "RC2-128"
-
- -
-
"RC2-40-CBC" or "RC2-40"
-
- -
-
"RC2-64-CBC" or "RC2-64"
-
- -
-
"RC2-ECB"
-
- -
-
"RC2-CFB"
-
- -
-
"RC2-OFB"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC4.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC4.html deleted file mode 100644 index f0ba9dfd..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC4.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -EVP_CIPHER-RC4 - - - - - - - - - - -

NAME

- -

EVP_CIPHER-RC4 - The RC4 EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for RC4 symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the legacy provider:

- -
- -
"RC4"
-
- -
-
"RC4-40"
-
- -
-
"RC4-HMAC-MD5"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC5.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC5.html deleted file mode 100644 index dc75071e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-RC5.html +++ /dev/null @@ -1,79 +0,0 @@ - - - - -EVP_CIPHER-RC5 - - - - - - - - - - -

NAME

- -

EVP_CIPHER-RC5 - The RC5 EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for RC5 symmetric encryption using the EVP_CIPHER API.

- -

Disabled by default. Use the enable-rc5 configuration option to enable.

- -

Algorithm Names

- -

The following algorithms are available in the legacy provider:

- -
- -
"RC5-CBC" or "RC5"
-
- -
-
"RC5-ECB"
-
- -
-
"RC5-OFB"
-
- -
-
"RC5-CFB"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SEED.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SEED.html deleted file mode 100644 index 0e825ed2..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SEED.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_CIPHER-SEED - - - - - - - - - - -

NAME

- -

EVP_CIPHER-SEED - The SEED EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for SEED symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the legacy provider:

- -
- -
"SEED-CBC" or "SEED"
-
- -
-
"SEED-ECB"
-
- -
-
"SEED-OFB" or "SEED-OFB128"
-
- -
-
"SEED-CFB" or "SEED-CFB128"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SM4.html b/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SM4.html deleted file mode 100644 index 184849c4..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_CIPHER-SM4.html +++ /dev/null @@ -1,98 +0,0 @@ - - - - -EVP_CIPHER-SM4 - - - - - - - - - - -

NAME

- -

EVP_CIPHER-SM4 - The SM4 EVP_CIPHER implementations

- -

DESCRIPTION

- -

Support for SM4 symmetric encryption using the EVP_CIPHER API.

- -

Algorithm Names

- -

The following algorithms are available in the default provider:

- -
- -
"SM4-CBC:SM4"
-
- -
-
"SM4-ECB"
-
- -
-
"SM4-CTR"
-
- -
-
"SM4-OFB" or "SM4-OFB128"
-
- -
-
"SM4-CFB" or "SM4-CFB128"
-
- -
-
"SM4-GCM"
-
- -
-
"SM4-CCM"
-
- -
-
"SM4-XTS"
-
- -
-
- -

Parameters

- -

This implementation supports the parameters described in "PARAMETERS" in EVP_EncryptInit(3).

- -

NOTES

- -

The SM4-XTS implementation allows streaming to be performed, but each EVP_EncryptUpdate(3) or EVP_DecryptUpdate(3) call requires each input to be a multiple of the blocksize. Only the final EVP_EncryptUpdate() or EVP_DecryptUpdate() call can optionally have an input that is not a multiple of the blocksize but is larger than one block. In that case ciphertext stealing (CTS) is used to fill the block.

- -

SEE ALSO

- -

provider-cipher(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-ARGON2.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-ARGON2.html deleted file mode 100644 index d8967ba2..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-ARGON2.html +++ /dev/null @@ -1,216 +0,0 @@ - - - - -EVP_KDF-ARGON2 - - - - - - - - - - -

NAME

- -

EVP_KDF-ARGON2 - The Argon2 EVP KDF implementation

- -

DESCRIPTION

- -

Support for computing the argon2 password-based KDF through the EVP_KDF API.

- -

The EVP_KDF-ARGON2 algorithm implements the Argon2 password-based key derivation function, as described in IETF RFC 9106. It is memory-hard in the sense that it deliberately requires a significant amount of RAM for efficient computation. The intention of this is to render brute forcing of passwords on systems that lack large amounts of main memory (such as GPUs or ASICs) computationally infeasible.

- -

Argon2d (Argon2i) uses data-dependent (data-independent) memory access and primary seek to address trade-off (side-channel) attacks.

- -

Argon2id is a hybrid construction which, in the first two slices of the first pass, generates reference addresses data-independently as in Argon2i, whereas in later slices and next passes it generates them data-dependently as in Argon2d.

- -

Sbox-hardened version Argon2ds is not supported.

- -

For more information, please refer to RFC 9106.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -
-
"secret" (OSSL_KDF_PARAM_SECRET) <octet string>
-
- -
-
"iter" (OSSL_KDF_PARAM_ITER) <unsigned integer>
-
- -
-
"size" (OSSL_KDF_PARAM_SIZE) <unsigned integer>
-
- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -

Note that RFC 9106 recommends 128 bits salt for most applications, or 64 bits salt in the case of space constraints. At least 128 bits output length is recommended.

- -

Note that secret (or pepper) is an optional secret data used along the password.

- -
-
"threads" (OSSL_KDF_PARAM_THREADS) <unsigned integer>
-
- -

The number of threads, bounded above by the number of lanes.

- -

This can only be used with built-in thread support. Threading must be explicitly enabled. See EXAMPLES section for more information.

- -
-
"ad" (OSSL_KDF_PARAM_ARGON2_AD) <octet string>
-
- -

Optional associated data, may be used to "tag" a group of keys, or tie them to a particular public key, without having to modify salt.

- -
-
"lanes" (OSSL_KDF_PARAM_ARGON2_LANES) <unsigned integer>
-
- -

Argon2 splits the requested memory size into lanes, each of which is designed to be processed in parallel. For example, on a system with p cores, it's recommended to use p lanes.

- -

The number of lanes is used to derive the key. It is possible to specify more lanes than the number of available computational threads. This is especially encouraged if multi-threading is disabled.

- -
-
"memcost" (OSSL_KDF_PARAM_ARGON2_MEMCOST) <unsigned integer>
-
- -

Memory cost parameter (the number of 1k memory blocks used).

- -
-
"version" (OSSL_KDF_PARAM_ARGON2_VERSION) <unsigned integer>
-
- -

Argon2 version. Supported values: 0x10, 0x13 (default).

- -
-
"early_clean" (OSSL_KDF_PARAM_EARLY_CLEAN) <unsigned integer>
-
- -

If set (nonzero), password and secret stored in Argon2 context are zeroed early during initial hash computation, as soon as they are not needed. Otherwise, they are zeroed along the rest of Argon2 context data on clear, free, reset.

- -

This can be useful if, for example, multiple keys with different ad value are to be generated from a single password and secret.

- -
-
- -

EXAMPLES

- -

This example uses Argon2d with password "1234567890", salt "saltsalt", using 2 lanes, 2 threads, and memory cost of 65536:

- -
#include <string.h>                 /* strlen               */
-#include <openssl/core_names.h>     /* OSSL_KDF_*           */
-#include <openssl/params.h>         /* OSSL_PARAM_*         */
-#include <openssl/thread.h>         /* OSSL_set_max_threads */
-#include <openssl/kdf.h>            /* EVP_KDF_*            */
-
-int main(void)
-{
-    int retval = 1;
-
-    EVP_KDF *kdf = NULL;
-    EVP_KDF_CTX *kctx = NULL;
-    OSSL_PARAM params[6], *p = params;
-
-    /* argon2 params, please refer to RFC9106 for recommended defaults */
-    uint32_t lanes = 2, threads = 2, memcost = 65536;
-    char pwd[] = "1234567890", salt[] = "saltsalt";
-
-    /* derive result */
-    size_t outlen = 128;
-    unsigned char result[outlen];
-
-    /* required if threads > 1 */
-    if (OSSL_set_max_threads(NULL, threads) != 1)
-        goto fail;
-
-    p = params;
-    *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_THREADS, &threads);
-    *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_ARGON2_LANES,
-                                       &lanes);
-    *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_ARGON2_MEMCOST,
-                                       &memcost);
-    *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
-                                             salt,
-                                             strlen((const char *)salt));
-    *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASSWORD,
-                                             pwd,
-                                             strlen((const char *)pwd));
-    *p++ = OSSL_PARAM_construct_end();
-
-    if ((kdf = EVP_KDF_fetch(NULL, "ARGON2D", NULL)) == NULL)
-        goto fail;
-    if ((kctx = EVP_KDF_CTX_new(kdf)) == NULL)
-        goto fail;
-    if (EVP_KDF_derive(kctx, &result[0], outlen, params) != 1)
-        goto fail;
-
-    printf("Output = %s\n", OPENSSL_buf2hexstr(result, outlen));
-    retval = 0;
-
-fail:
-    EVP_KDF_free(kdf);
-    EVP_KDF_CTX_free(kctx);
-    OSSL_set_max_threads(NULL, 0);
-
-    return retval;
-}
- -

NOTES

- -

"ARGON2I", "ARGON2D", and "ARGON2ID" are the names for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

CONFORMING TO

- -

RFC 9106 Argon2, see https://www.rfc-editor.org/rfc/rfc9106.txt.

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added to OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-HKDF.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-HKDF.html deleted file mode 100644 index 4f0728d5..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-HKDF.html +++ /dev/null @@ -1,190 +0,0 @@ - - - - -EVP_KDF-HKDF - - - - - - - - - - -

NAME

- -

EVP_KDF-HKDF - The HKDF EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the HKDF KDF through the EVP_KDF API.

- -

The EVP_KDF-HKDF algorithm implements the HKDF key derivation function. HKDF follows the "extract-then-expand" paradigm, where the KDF logically consists of two modules. The first stage takes the input keying material and "extracts" from it a fixed-length pseudorandom key K. The second stage "expands" the key K into several additional pseudorandom keys (the output of the KDF).

- -

The output is considered to be keying material.

- -

Identity

- -

"HKDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"info" (OSSL_KDF_PARAM_INFO) <octet string>
-
- -

This parameter sets the info value. The length of the context info buffer cannot exceed 1024 bytes; this should be more than enough for any normal use of HKDF.

- -
-
"mode" (OSSL_KDF_PARAM_MODE) <UTF8 string> or <integer>
-
- -

This parameter sets the mode for the HKDF operation. There are three modes that are currently defined:

- -
- -
"EXTRACT_AND_EXPAND" or EVP_KDF_HKDF_MODE_EXTRACT_AND_EXPAND
-
- -

This is the default mode. Calling EVP_KDF_derive(3) on an EVP_KDF_CTX set up for HKDF will perform an extract followed by an expand operation in one go. The derived key returned will be the result after the expand operation. The intermediate fixed-length pseudorandom key K is not returned.

- -

In this mode the digest, key, salt and info values must be set before a key is derived otherwise an error will occur.

- -
-
"EXTRACT_ONLY" or EVP_KDF_HKDF_MODE_EXTRACT_ONLY
-
- -

In this mode calling EVP_KDF_derive(3) will just perform the extract operation. The value returned will be the intermediate fixed-length pseudorandom key K. The keylen parameter must match the size of K, which can be looked up by calling EVP_KDF_CTX_get_kdf_size() after setting the mode and digest.

- -

The digest, key and salt values must be set before a key is derived otherwise an error will occur.

- -
-
"EXPAND_ONLY" or EVP_KDF_HKDF_MODE_EXPAND_ONLY
-
- -

In this mode calling EVP_KDF_derive(3) will just perform the expand operation. The input key should be set to the intermediate fixed-length pseudorandom key K returned from a previous extract operation.

- -

The digest, key and info values must be set before a key is derived otherwise an error will occur.

- -
-
- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if "key-check" is set to 0 and the check fails.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_KEY) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

A context for HKDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "HKDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of an HKDF expand operation is specified via the keylen parameter to the EVP_KDF_derive(3) function. When using EVP_KDF_HKDF_MODE_EXTRACT_ONLY the keylen parameter must equal the size of the intermediate fixed-length pseudorandom key otherwise an error will occur. For that mode, the fixed output size can be looked up by calling EVP_KDF_CTX_get_kdf_size() after setting the mode and digest on the EVP_KDF_CTX.

- -

EXAMPLES

- -

This example derives 10 bytes using SHA-256 with the secret key "secret", salt value "salt" and info value "label":

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[5], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "HKDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-                                        SN_sha256, strlen(SN_sha256));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY,
-                                         "secret", (size_t)6);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO,
-                                         "label", (size_t)5);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
-                                         "salt", (size_t)4);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) {
-    error("EVP_KDF_derive");
-}
-
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

RFC 5869

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3), EVP_KDF-TLS13_KDF(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-HMAC-DRBG.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-HMAC-DRBG.html deleted file mode 100644 index 41c96db1..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-HMAC-DRBG.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -EVP_KDF-HMAC-DRBG - - - - - - - - - - -

NAME

- -

EVP_KDF-HMAC-DRBG - The HMAC DRBG DETERMINISTIC EVP_KDF implementation

- -

DESCRIPTION

- -

Support for a deterministic HMAC DRBG using the EVP_KDF API. This is similar to EVP_RAND-HMAC-DRBG(7), but uses fixed values for its entropy and nonce values. This is used to generate deterministic nonce value required by ECDSA and DSA (as defined in RFC 6979).

- -

Identity

- -

"HMAC-DRBG-KDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"digest" (OSSL_DRBG_PARAM_DIGEST) <UTF8 string>
-
- -
-
"properties" (OSSL_DRBG_PARAM_PROPERTIES) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"entropy" (OSSL_KDF_PARAM_HMACDRBG_ENTROPY) <octet string>
-
- -

Sets the entropy bytes supplied to the HMAC-DRBG.

- -
-
"nonce" (OSSL_KDF_PARAM_HMACDRBG_NONCE) <octet string>
-
- -

Sets the nonce bytes supplied to the HMAC-DRBG.

- -
-
- -

NOTES

- -

A context for KDF HMAC DRBG can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "HMAC-DRBG-KDF", NULL);
-EVP_KDF_CTX *kdf_ctx = EVP_KDF_CTX_new(kdf, NULL);
- -

CONFORMING TO

- -

RFC 6979

- -

SEE ALSO

- -

EVP_KDF(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

The EVP_KDF-HMAC-DRBG functionality was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-KB.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-KB.html deleted file mode 100644 index 485e5fec..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-KB.html +++ /dev/null @@ -1,232 +0,0 @@ - - - - -EVP_KDF-KB - - - - - - - - - - -

NAME

- -

EVP_KDF-KB - The Key-Based EVP_KDF implementation

- -

DESCRIPTION

- -

The EVP_KDF-KB algorithm implements the Key-Based key derivation function (KBKDF). KBKDF derives a key from repeated application of a keyed MAC to an input secret (and other optional values).

- -

The output is considered to be keying material.

- -

Identity

- -

"KBKDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"mode" (OSSL_KDF_PARAM_MODE) <UTF8 string>
-
- -

The mode parameter determines which flavor of KBKDF to use - currently the choices are "counter" and "feedback". "counter" is the default, and will be used if unspecified.

- -
-
"mac" (OSSL_KDF_PARAM_MAC) <UTF8 string>
-
- -

The value is either CMAC, HMAC, KMAC128 or KMAC256.

- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -
-
"cipher" (OSSL_KDF_PARAM_CIPHER) <UTF8 string>
-
- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -
-
"info (OSSL_KDF_PARAM_INFO) <octet string>
-
- -
-
"seed" (OSSL_KDF_PARAM_SEED) <octet string>
-
- -

The seed parameter is unused in counter mode.

- -
-
"use-l" (OSSL_KDF_PARAM_KBKDF_USE_L) <integer>
-
- -

Set to 0 to disable use of the optional Fixed Input data 'L' (see SP800-108). The default value of 1 will be used if unspecified.

- -
-
"use-separator" (OSSL_KDF_PARAM_KBKDF_USE_SEPARATOR) <integer>
-
- -

Set to 0 to disable use of the optional Fixed Input data 'zero separator' (see SP800-108) that is placed between the Label and Context. The default value of 1 will be used if unspecified.

- -
-
"r" (OSSL_KDF_PARAM_KBKDF_R) <integer>
-
- -

Set the fixed value 'r', indicating the length of the counter in bits.

- -

Supported values are 8, 16, 24, and 32. The default value of 32 will be used if unspecified.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if "key-check" is set to 0 and the check fails.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_KEY) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

Depending on whether mac is CMAC or HMAC, either digest or cipher is required (respectively) and the other is unused. They are unused for KMAC128 and KMAC256.

- -

The parameters key, salt, info, and seed correspond to KI, Label, Context, and IV (respectively) in SP800-108. As in that document, salt, info, and seed are optional and may be omitted.

- -

"mac", "digest", cipher" and "properties" are described in "PARAMETERS" in EVP_KDF(3).

- -

NOTES

- -

A context for KBKDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of an KBKDF is specified via the keylen parameter to the EVP_KDF_derive(3) function.

- -

Note that currently OpenSSL only implements counter and feedback modes. Other variants may be supported in the future.

- -

EXAMPLES

- -

This example derives 10 bytes using COUNTER-HMAC-SHA256, with KI "secret", Label "label", and Context "context".

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[6], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-                                        "SHA2-256", 0);
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC,
-                                        "HMAC", 0);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY,
-                                         "secret", strlen("secret"));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
-                                         "label", strlen("label"));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO,
-                                         "context", strlen("context"));
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0)
-    error("EVP_KDF_derive");
-
-EVP_KDF_CTX_free(kctx);
- -

This example derives 10 bytes using FEEDBACK-CMAC-AES256, with KI "secret", Label "label", and IV "sixteen bytes iv".

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[8], *p = params;
-unsigned char *iv = "sixteen bytes iv";
-
-kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, "AES256", 0);
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, "CMAC", 0);
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MODE, "FEEDBACK", 0);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY,
-                                         "secret", strlen("secret"));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
-                                         "label", strlen("label"));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO,
-                                         "context", strlen("context"));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SEED,
-                                         iv, strlen(iv));
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0)
-    error("EVP_KDF_derive");
-
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

NIST SP800-108, IETF RFC 6803, IETF RFC 8009.

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

Support for KMAC was added in OpenSSL 3.1.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. Copyright 2019 Red Hat, Inc.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-KRB5KDF.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-KRB5KDF.html deleted file mode 100644 index c0d50275..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-KRB5KDF.html +++ /dev/null @@ -1,133 +0,0 @@ - - - - -EVP_KDF-KRB5KDF - - - - - - - - - - -

NAME

- -

EVP_KDF-KRB5KDF - The RFC3961 Krb5 KDF EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the KRB5KDF KDF through the EVP_KDF API.

- -

The EVP_KDF-KRB5KDF algorithm implements the key derivation function defined in RFC 3961, section 5.1 and is used by Krb5 to derive session keys. Three inputs are required to perform key derivation: a cipher, (for example AES-128-CBC), the initial key, and a constant.

- -

Identity

- -

"KRB5KDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"cipher" (OSSL_KDF_PARAM_CIPHER) <UTF8 string>
-
- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"constant" (OSSL_KDF_PARAM_CONSTANT) <octet string>
-
- -

This parameter sets the constant value for the KDF. If a value is already set, the contents are replaced.

- -
-
- -

NOTES

- -

A context for KRB5KDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of the KRB5KDF derivation is specified via the keylen parameter to the EVP_KDF_derive(3) function, and MUST match the key length for the chosen cipher or an error is returned. Moreover, the constant's length must not exceed the block size of the cipher. Since the KRB5KDF output length depends on the chosen cipher, calling EVP_KDF_CTX_get_kdf_size(3) to obtain the requisite length returns the correct length only after the cipher is set. Prior to that EVP_MAX_KEY_LENGTH is returned. The caller must allocate a buffer of the correct length for the chosen cipher, and pass that buffer to the EVP_KDF_derive(3) function along with that length.

- -

EXAMPLES

- -

This example derives a key using the AES-128-CBC cipher:

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char key[16] = "01234...";
-unsigned char constant[] = "I'm a constant";
-unsigned char out[16];
-size_t outlen = sizeof(out);
-OSSL_PARAM params[4], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER,
-                                        SN_aes_128_cbc,
-                                        strlen(SN_aes_128_cbc));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY,
-                                         key, (size_t)16);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_CONSTANT,
-                                         constant, strlen(constant));
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, outlen, params) <= 0)
-    /* Error */
-
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

RFC 3961

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF1.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF1.html deleted file mode 100644 index 4b73129f..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF1.html +++ /dev/null @@ -1,108 +0,0 @@ - - - - -EVP_KDF-PBKDF1 - - - - - - - - - - -

NAME

- -

EVP_KDF-PBKDF1 - The PBKDF1 EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the PBKDF1 password-based KDF through the EVP_KDF API.

- -

The EVP_KDF-PBKDF1 algorithm implements the PBKDF1 password-based key derivation function, as described in RFC 8018; it derives a key from a password using a salt and iteration count.

- -

Identity

- -

"PBKDF1" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -
-
"iter" (OSSL_KDF_PARAM_ITER) <unsigned integer>
-
- -

This parameter has a default value of 0 and should be set.

- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
- -

NOTES

- -

A typical application of this algorithm is to derive keying material for an encryption algorithm from a password in the "pass", a salt in "salt", and an iteration count.

- -

Increasing the "iter" parameter slows down the algorithm which makes it harder for an attacker to perform a brute force attack using a large number of candidate passwords.

- -

No assumption is made regarding the given password; it is simply treated as a byte sequence.

- -

The legacy provider needs to be available in order to access this algorithm.

- -

CONFORMING TO

- -

RFC 8018

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3), OSSL_PROVIDER-legacy(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF2.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF2.html deleted file mode 100644 index 7afdcad6..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PBKDF2.html +++ /dev/null @@ -1,142 +0,0 @@ - - - - -EVP_KDF-PBKDF2 - - - - - - - - - - -

NAME

- -

EVP_KDF-PBKDF2 - The PBKDF2 EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the PBKDF2 password-based KDF through the EVP_KDF API.

- -

The EVP_KDF-PBKDF2 algorithm implements the PBKDF2 password-based key derivation function, as described in SP800-132; it derives a key from a password using a salt and iteration count.

- -

The output is considered to be a cryptographic key.

- -

Identity

- -

"PBKDF2" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -
-
"iter" (OSSL_KDF_PARAM_ITER) <unsigned integer>
-
- -

This parameter has a default value of 2048.

- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"pkcs5" (OSSL_KDF_PARAM_PKCS5) <integer>
-
- -

This parameter can be used to enable or disable SP800-132 compliance checks. Setting the mode to 0 enables the compliance checks.

- -

The checks performed are:

- -
- -
- the iteration count is at least 1000.
-
- -
-
- the salt length is at least 128 bits.
-
- -
-
- the derived key length is at least 112 bits.
-
- -
-
- -

The default provider uses a default mode of 1 for backwards compatibility, and the FIPS provider uses a default mode of 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

This option is used by the OpenSSL FIPS provider.

- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if "pkcs5" is set to 1 and the derived key length, salt length or iteration count test fails.

- -
-
- -

NOTES

- -

A typical application of this algorithm is to derive keying material for an encryption algorithm from a password in the "pass", a salt in "salt", and an iteration count.

- -

Increasing the "iter" parameter slows down the algorithm which makes it harder for an attacker to perform a brute force attack using a large number of candidate passwords.

- -

No assumption is made regarding the given password; it is simply treated as a byte sequence.

- -

CONFORMING TO

- -

SP800-132

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PKCS12KDF.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PKCS12KDF.html deleted file mode 100644 index 3da53a3f..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PKCS12KDF.html +++ /dev/null @@ -1,112 +0,0 @@ - - - - -EVP_KDF-PKCS12KDF - - - - - - - - - - -

NAME

- -

EVP_KDF-PKCS12KDF - The PKCS#12 EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the PKCS#12 password-based KDF through the EVP_KDF API.

- -

The EVP_KDF-PKCS12KDF algorithm implements the PKCS#12 password-based key derivation function, as described in appendix B of RFC 7292 (PKCS #12: Personal Information Exchange Syntax); it derives a key from a password using a salt, iteration count and the intended usage.

- -

Identity

- -

"PKCS12KDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -
-
"iter" (OSSL_KDF_PARAM_ITER) <unsigned integer>
-
- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"id" (OSSL_KDF_PARAM_PKCS12_ID) <integer>
-
- -

This parameter is used to specify the intended usage of the output bits, as per RFC 7292 section B.3.

- -
-
- -

NOTES

- -

This algorithm is not available in the FIPS provider as it is not FIPS approvable.

- -

A typical application of this algorithm is to derive keying material for an encryption algorithm from a password in the "pass", a salt in "salt", and an iteration count.

- -

Increasing the "iter" parameter slows down the algorithm which makes it harder for an attacker to perform a brute force attack using a large number of candidate passwords.

- -

No assumption is made regarding the given password; it is simply treated as a byte sequence.

- -

CONFORMING TO

- -

RFC7292

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3), OSSL_PROVIDER-FIPS(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PVKKDF.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PVKKDF.html deleted file mode 100644 index 4ade8e6b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-PVKKDF.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -EVP_KDF-PVKKDF - - - - - - - - - - -

NAME

- -

EVP_KDF-PVKKDF - The PVK EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the PVK KDF PIN-based KDF through the EVP_KDF API.

- -

The EVP_KDF-PVKKDF algorithm implements a PVK PIN-based key derivation function; it derives a key from a password using a salt.

- -

Identity

- -

"PVKKDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
- -

NOTES

- -

A typical application of this algorithm is to derive keying material for an encryption algorithm from a password in the "pass" and a salt in "salt".

- -

No assumption is made regarding the given password; it is simply treated as a byte sequence.

- -

The legacy provider needs to be available in order to access this algorithm.

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3), OSSL_PROVIDER-legacy(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SCRYPT.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SCRYPT.html deleted file mode 100644 index ab63023e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SCRYPT.html +++ /dev/null @@ -1,164 +0,0 @@ - - - - -EVP_KDF-SCRYPT - - - - - - - - - - -

NAME

- -

EVP_KDF-SCRYPT - The scrypt EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the scrypt password-based KDF through the EVP_KDF API.

- -

The EVP_KDF-SCRYPT algorithm implements the scrypt password-based key derivation function, as described in RFC 7914. It is memory-hard in the sense that it deliberately requires a significant amount of RAM for efficient computation. The intention of this is to render brute forcing of passwords on systems that lack large amounts of main memory (such as GPUs or ASICs) computationally infeasible.

- -

scrypt provides three work factors that can be customized: N, r and p. N, which has to be a positive power of two, is the general work factor and scales CPU time in an approximately linear fashion. r is the block size of the internally used hash function and p is the parallelization factor. Both r and p need to be greater than zero. The amount of RAM that scrypt requires for its computation is roughly (128 * N * r * p) bytes.

- -

In the original paper of Colin Percival ("Stronger Key Derivation via Sequential Memory-Hard Functions", 2009), the suggested values that give a computation time of less than 5 seconds on a 2.5 GHz Intel Core 2 Duo are N = 2^20 = 1048576, r = 8, p = 1. Consequently, the required amount of memory for this computation is roughly 1 GiB. On a more recent CPU (Intel i7-5930K at 3.5 GHz), this computation takes about 3 seconds. When N, r or p are not specified, they default to 1048576, 8, and 1, respectively. The maximum amount of RAM that may be used by scrypt defaults to 1025 MiB.

- -

Identity

- -

"SCRYPT" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"n" (OSSL_KDF_PARAM_SCRYPT_N) <unsigned integer>
-
- -
-
"r" (OSSL_KDF_PARAM_SCRYPT_R) <unsigned integer>
-
- -
-
"p" (OSSL_KDF_PARAM_SCRYPT_P) <unsigned integer>
-
- -
-
"maxmem_bytes" (OSSL_KDF_PARAM_SCRYPT_MAXMEM) <unsigned integer>
-
- -

These parameters configure the scrypt work factors N, r, maxmem and p. Both N and maxmem_bytes are parameters of type uint64_t. Both r and p are parameters of type uint32_t.

- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -

This can be used to set the property query string when fetching the fixed digest internally. NULL is used if this value is not set.

- -
-
- -

NOTES

- -

A context for scrypt can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "SCRYPT", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of an scrypt key derivation is specified via the "keylen" parameter to the EVP_KDF_derive(3) function.

- -

EXAMPLES

- -

This example derives a 64-byte long test vector using scrypt with the password "password", salt "NaCl" and N = 1024, r = 8, p = 16.

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[64];
-OSSL_PARAM params[6], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "SCRYPT", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASSWORD,
-                                         "password", (size_t)8);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
-                                         "NaCl", (size_t)4);
-*p++ = OSSL_PARAM_construct_uint64(OSSL_KDF_PARAM_SCRYPT_N, (uint64_t)1024);
-*p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_SCRYPT_R, (uint32_t)8);
-*p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_SCRYPT_P, (uint32_t)16);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) {
-    error("EVP_KDF_derive");
-}
-
-{
-    const unsigned char expected[sizeof(out)] = {
-        0xfd, 0xba, 0xbe, 0x1c, 0x9d, 0x34, 0x72, 0x00,
-        0x78, 0x56, 0xe7, 0x19, 0x0d, 0x01, 0xe9, 0xfe,
-        0x7c, 0x6a, 0xd7, 0xcb, 0xc8, 0x23, 0x78, 0x30,
-        0xe7, 0x73, 0x76, 0x63, 0x4b, 0x37, 0x31, 0x62,
-        0x2e, 0xaf, 0x30, 0xd9, 0x2e, 0x22, 0xa3, 0x88,
-        0x6f, 0xf1, 0x09, 0x27, 0x9d, 0x98, 0x30, 0xda,
-        0xc7, 0x27, 0xaf, 0xb9, 0x4a, 0x83, 0xee, 0x6d,
-        0x83, 0x60, 0xcb, 0xdf, 0xa2, 0xcc, 0x06, 0x40
-    };
-
-    assert(!memcmp(out, expected, sizeof(out)));
-}
-
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

RFC 7914

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SS.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SS.html deleted file mode 100644 index 6e20574b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SS.html +++ /dev/null @@ -1,242 +0,0 @@ - - - - -EVP_KDF-SS - - - - - - - - - - -

NAME

- -

EVP_KDF-SS - The Single Step / One Step EVP_KDF implementation

- -

DESCRIPTION

- -

The EVP_KDF-SS algorithm implements the Single Step key derivation function (SSKDF). SSKDF derives a key using input such as a shared secret key (that was generated during the execution of a key establishment scheme) and fixedinfo. SSKDF is also informally referred to as 'Concat KDF'.

- -

The output is considered to be keying material.

- -

Auxiliary function

- -

The implementation uses a selectable auxiliary function H, which can be one of:

- -
- -
H(x) = hash(x, digest=md)
-
- -
-
H(x) = HMAC_hash(x, key=salt, digest=md)
-
- -
-
H(x) = KMACxxx(x, key=salt, custom="KDF", outlen=mac_size)
-
- -
-
- -

Both the HMAC and KMAC implementations set the key using the 'salt' value. The hash and HMAC also require the digest to be set.

- -

Identity

- -

"SSKDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

This parameter is ignored for KMAC.

- -
-
"mac" (OSSL_KDF_PARAM_MAC) <UTF8 string>
-
- -
-
"maclen" (OSSL_KDF_PARAM_MAC_SIZE) <unsigned integer>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"key" (OSSL_KDF_PARAM_SECRET) <octet string>
-
- -

This parameter set the shared secret that is used for key derivation.

- -
-
"info" (OSSL_KDF_PARAM_INFO) <octet string>
-
- -

This parameter sets an optional value for fixedinfo, also known as otherinfo.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if "key-check" is set to 0 and the check fails.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_KEY) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

A context for SSKDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of an SSKDF is specified via the keylen parameter to the EVP_KDF_derive(3) function.

- -

EXAMPLES

- -

This example derives 10 bytes using H(x) = SHA-256, with the secret key "secret" and fixedinfo value "label":

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[4], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-                                        SN_sha256, strlen(SN_sha256));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY,
-                                         "secret", (size_t)6);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO,
-                                         "label", (size_t)5);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) {
-    error("EVP_KDF_derive");
-}
-
-EVP_KDF_CTX_free(kctx);
- -

This example derives 10 bytes using H(x) = HMAC(SHA-256), with the secret key "secret", fixedinfo value "label" and salt "salt":

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[6], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC,
-                                        SN_hmac, strlen(SN_hmac));
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-                                        SN_sha256, strlen(SN_sha256));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET,
-                                         "secret", (size_t)6);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO,
-                                         "label", (size_t)5);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
-                                         "salt", (size_t)4);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) {
-    error("EVP_KDF_derive");
-}
-
-EVP_KDF_CTX_free(kctx);
- -

This example derives 10 bytes using H(x) = KMAC128(x,salt,outlen), with the secret key "secret" fixedinfo value "label", salt of "salt" and KMAC outlen of 20:

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[6], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC,
-                                        SN_kmac128, strlen(SN_kmac128));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET,
-                                         "secret", (size_t)6);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO,
-                                         "label", (size_t)5);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
-                                         "salt", (size_t)4);
-*p++ = OSSL_PARAM_construct_size_t(OSSL_KDF_PARAM_MAC_SIZE, (size_t)20);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) {
-    error("EVP_KDF_derive");
-}
-
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

NIST SP800-56Cr1.

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. Copyright (c) 2019, Oracle and/or its affiliates. All rights reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SSHKDF.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SSHKDF.html deleted file mode 100644 index 0e839499..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-SSHKDF.html +++ /dev/null @@ -1,214 +0,0 @@ - - - - -EVP_KDF-SSHKDF - - - - - - - - - - -

NAME

- -

EVP_KDF-SSHKDF - The SSHKDF EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the SSHKDF KDF through the EVP_KDF API.

- -

The EVP_KDF-SSHKDF algorithm implements the SSHKDF key derivation function. It is defined in RFC 4253, section 7.2 and is used by SSH to derive IVs, encryption keys and integrity keys. Five inputs are required to perform key derivation: The hashing function (for example SHA256), the Initial Key, the Exchange Hash, the Session ID, and the derivation key type.

- -

The output is considered to be keying material.

- -

Identity

- -

"SSHKDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"xcghash" (OSSL_KDF_PARAM_SSHKDF_XCGHASH) <octet string>
-
- -
-
"session_id" (OSSL_KDF_PARAM_SSHKDF_SESSION_ID) <octet string>
-
- -

These parameters set the respective values for the KDF. If a value is already set, the contents are replaced.

- -
-
"type" (OSSL_KDF_PARAM_SSHKDF_TYPE) <UTF8 string>
-
- -

This parameter sets the type for the SSHKDF operation. There are six supported types:

- -
- -
EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV
-
- -

The Initial IV from client to server. A single char of value 65 (ASCII char 'A').

- -
-
EVP_KDF_SSHKDF_TYPE_INITIAL_IV_SRV_TO_CLI
-
- -

The Initial IV from server to client A single char of value 66 (ASCII char 'B').

- -
-
EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_CLI_TO_SRV
-
- -

The Encryption Key from client to server A single char of value 67 (ASCII char 'C').

- -
-
EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_SRV_TO_CLI
-
- -

The Encryption Key from server to client A single char of value 68 (ASCII char 'D').

- -
-
EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_CLI_TO_SRV
-
- -

The Integrity Key from client to server A single char of value 69 (ASCII char 'E').

- -
-
EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_SRV_TO_CLI
-
- -

The Integrity Key from client to server A single char of value 70 (ASCII char 'F').

- -
-
- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if any "***-check" related parameter is set to 0 and the check fails.

- -
-
"digest-check" (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if used digest is not approved. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -

According to SP 800-135r1, the following are approved digest algorithms: SHA-1, SHA2-224, SHA2-256, SHA2-384, SHA2-512.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_KEY) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

A context for SSHKDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "SSHKDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of the SSHKDF derivation is specified via the keylen parameter to the EVP_KDF_derive(3) function. Since the SSHKDF output length is variable, calling EVP_KDF_CTX_get_kdf_size(3) to obtain the requisite length is not meaningful. The caller must allocate a buffer of the desired length, and pass that buffer to the EVP_KDF_derive(3) function along with the desired length.

- -

EXAMPLES

- -

This example derives an 8 byte IV using SHA-256 with a 1K "key" and appropriate "xcghash" and "session_id" values:

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-char type = EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV;
-unsigned char key[1024] = "01234...";
-unsigned char xcghash[32] = "012345...";
-unsigned char session_id[32] = "012345...";
-unsigned char out[8];
-size_t outlen = sizeof(out);
-OSSL_PARAM params[6], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "SSHKDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-                                        SN_sha256, strlen(SN_sha256));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY,
-                                         key, (size_t)1024);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SSHKDF_XCGHASH,
-                                         xcghash, (size_t)32);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SSHKDF_SESSION_ID,
-                                         session_id, (size_t)32);
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_SSHKDF_TYPE,
-                                        &type, sizeof(type));
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, outlen, params) <= 0)
-    /* Error */
- -

CONFORMING TO

- -

RFC 4253

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS13_KDF.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS13_KDF.html deleted file mode 100644 index 951f7c4c..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS13_KDF.html +++ /dev/null @@ -1,177 +0,0 @@ - - - - -EVP_KDF-TLS13_KDF - - - - - - - - - - -

NAME

- -

EVP_KDF-TLS13_KDF - The TLS 1.3 EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the TLS 1.3 version of the HKDF KDF through the EVP_KDF API.

- -

The EVP_KDF-TLS13_KDF algorithm implements the HKDF key derivation function as used by TLS 1.3.

- -

The output is considered to be keying material.

- -

Identity

- -

"TLS13-KDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -
-
"salt" (OSSL_KDF_PARAM_SALT) <octet string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"prefix" (OSSL_KDF_PARAM_PREFIX) <octet string>
-
- -

This parameter sets the label prefix on the specified TLS 1.3 KDF context. For TLS 1.3 this should be set to the ASCII string "tls13 " without a trailing zero byte. Refer to RFC 8446 section 7.1 "Key Schedule" for details.

- -
-
"label" (OSSL_KDF_PARAM_LABEL) <octet string>
-
- -

This parameter sets the label on the specified TLS 1.3 KDF context. Refer to RFC 8446 section 7.1 "Key Schedule" for details.

- -
-
"data" (OSSL_KDF_PARAM_DATA) <octet string>
-
- -

This parameter sets the context data on the specified TLS 1.3 KDF context. Refer to RFC 8446 section 7.1 "Key Schedule" for details.

- -
-
"mode" (OSSL_KDF_PARAM_MODE) <UTF8 string> or <integer>
-
- -

This parameter sets the mode for the TLS 1.3 KDF operation. There are two modes that are currently defined:

- -
- -
"EXTRACT_ONLY" or EVP_KDF_HKDF_MODE_EXTRACT_ONLY
-
- -

In this mode calling EVP_KDF_derive(3) will just perform the extract operation. The value returned will be the intermediate fixed-length pseudorandom key K. The keylen parameter must match the size of K, which can be looked up by calling EVP_KDF_CTX_get_kdf_size() after setting the mode and digest.

- -

The digest, key and salt values must be set before a key is derived otherwise an error will occur.

- -
-
"EXPAND_ONLY" or EVP_KDF_HKDF_MODE_EXPAND_ONLY
-
- -

In this mode calling EVP_KDF_derive(3) will just perform the expand operation. The input key should be set to the intermediate fixed-length pseudorandom key K returned from a previous extract operation.

- -

The digest, key and info values must be set before a key is derived otherwise an error will occur.

- -
-
- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if any "***-check" related parameter is set to 0 and the check fails.

- -
-
"digest-check" (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if used digest is not approved. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -

According to RFC 8446, the following are approved digest algorithms: SHA2-256, SHA2-384.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_KEY) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

This KDF is intended for use by the TLS 1.3 implementation in libssl. It does not support all the options and capabilities that HKDF does.

- -

The OSSL_PARAM array passed to EVP_KDF_derive(3) or EVP_KDF_CTX_set_params(3) must specify all of the parameters required. This KDF does not support a piecemeal approach to providing these.

- -

A context for a TLS 1.3 KDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "TLS13-KDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of a TLS 1.3 KDF expand operation is specified via the keylen parameter to the EVP_KDF_derive(3) function. When using EVP_KDF_HKDF_MODE_EXTRACT_ONLY the keylen parameter must equal the size of the intermediate fixed-length pseudorandom key otherwise an error will occur. For that mode, the fixed output size can be looked up by calling EVP_KDF_CTX_get_kdf_size() after setting the mode and digest on the EVP_KDF_CTX.

- -

CONFORMING TO

- -

RFC 8446

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3), EVP_KDF-HKDF(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS1_PRF.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS1_PRF.html deleted file mode 100644 index 3b162969..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-TLS1_PRF.html +++ /dev/null @@ -1,169 +0,0 @@ - - - - -EVP_KDF-TLS1_PRF - - - - - - - - - - -

NAME

- -

EVP_KDF-TLS1_PRF - The TLS1 PRF EVP_KDF implementation

- -

DESCRIPTION

- -

Support for computing the TLS1 PRF through the EVP_KDF API.

- -

The EVP_KDF-TLS1_PRF algorithm implements the PRF used by TLS versions up to and including TLS 1.2.

- -

The output is considered to be keying material.

- -

Identity

- -

"TLS1-PRF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -

The OSSL_KDF_PARAM_DIGEST parameter is used to set the message digest associated with the TLS PRF. EVP_md5_sha1() is treated as a special case which uses the PRF algorithm using both MD5 and SHA1 as used in TLS 1.0 and 1.1.

- -
-
"secret" (OSSL_KDF_PARAM_SECRET) <octet string>
-
- -

This parameter sets the secret value of the TLS PRF. Any existing secret value is replaced.

- -
-
"seed" (OSSL_KDF_PARAM_SEED) <octet string>
-
- -

This parameter sets the context seed. The length of the context seed cannot exceed 1024 bytes; this should be more than enough for any normal use of the TLS PRF.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if any "***-check" related parameter is set to 0 and the check fails.

- -
-
"ems_check" (OSSL_KDF_PARAM_FIPS_EMS_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_derive() if "master secret" is used instead of "extended master secret" Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"digest-check" (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if used digest is not approved. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -

According to SP 800-135r1, the following are approved digest algorithms: SHA2-256, SHA2-384, SHA2-512.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_SECRET) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

A context for the TLS PRF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "TLS1-PRF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The digest, secret value and seed must be set before a key is derived otherwise an error will occur.

- -

The output length of the PRF is specified by the keylen parameter to the EVP_KDF_derive() function.

- -

EXAMPLES

- -

This example derives 10 bytes using SHA-256 with the secret key "secret" and seed value "seed":

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[4], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "TLS1-PRF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-                                        SN_sha256, strlen(SN_sha256));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET,
-                                         "secret", (size_t)6);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SEED,
-                                         "seed", (size_t)4);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) {
-    error("EVP_KDF_derive");
-}
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

RFC 2246, RFC 5246 and NIST SP 800-135 r1

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-ASN1.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-ASN1.html deleted file mode 100644 index 71434019..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-ASN1.html +++ /dev/null @@ -1,198 +0,0 @@ - - - - -EVP_KDF-X942-ASN1 - - - - - - - - - - -

NAME

- -

EVP_KDF-X942-ASN1 - The X9.42-2003 asn1 EVP_KDF implementation

- -

DESCRIPTION

- -

The EVP_KDF-X942-ASN1 algorithm implements the key derivation function X942KDF-ASN1. It is used by DH KeyAgreement, to derive a key using input such as a shared secret key and other info. The other info is DER encoded data that contains a 32 bit counter as well as optional fields for "partyu-info", "partyv-info", "supp-pubinfo" and "supp-privinfo". This kdf is used by Cryptographic Message Syntax (CMS).

- -

The output is considered to be keying material.

- -

Identity

- -

"X942KDF-ASN1" or "X942KDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"secret" (OSSL_KDF_PARAM_SECRET) <octet string>
-
- -

The shared secret used for key derivation. This parameter sets the secret.

- -
-
"acvp-info" (OSSL_KDF_PARAM_X942_ACVPINFO) <octet string>
-
- -

This value should not be used in production and should only be used for ACVP testing. It is an optional octet string containing a combined DER encoded blob of any of the optional fields related to "partyu-info", "partyv-info", "supp-pubinfo" and "supp-privinfo". If it is specified then none of these other fields should be used.

- -
-
"partyu-info" (OSSL_KDF_PARAM_X942_PARTYUINFO) <octet string>
-
- -

An optional octet string containing public info contributed by the initiator.

- -
-
"ukm" (OSSL_KDF_PARAM_UKM) <octet string>
-
- -

An alias for "partyu-info". In CMS this is the user keying material.

- -
-
"partyv-info" (OSSL_KDF_PARAM_X942_PARTYVINFO) <octet string>
-
- -

An optional octet string containing public info contributed by the responder.

- -
-
"supp-pubinfo" (OSSL_KDF_PARAM_X942_SUPP_PUBINFO) <octet string>
-
- -

An optional octet string containing some additional, mutually-known public information. Setting this value also sets "use-keybits" to 0.

- -
-
"use-keybits" (OSSL_KDF_PARAM_X942_USE_KEYBITS) <integer>
-
- -

The default value of 1 will use the KEK key length (in bits) as the "supp-pubinfo". A value of 0 disables setting the "supp-pubinfo".

- -
-
"supp-privinfo" (OSSL_KDF_PARAM_X942_SUPP_PRIVINFO) <octet string>
-
- -

An optional octet string containing some additional, mutually-known private information.

- -
-
"cekalg" (OSSL_KDF_PARAM_CEK_ALG) <UTF8 string>
-
- -

This parameter sets the CEK wrapping algorithm name. Valid values are "AES-128-WRAP", "AES-192-WRAP", "AES-256-WRAP" and "DES3-WRAP".

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if "key-check" parameter is set to 0 and the check fails.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_KEY) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

A context for X942KDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "X942KDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of an X942KDF is specified via the keylen parameter to the EVP_KDF_derive(3) function.

- -

EXAMPLES

- -

This example derives 24 bytes, with the secret key "secret" and random user keying material:

- -
EVP_KDF_CTX *kctx;
-EVP_KDF_CTX *kctx;
-unsigned char out[192/8];
-unsignred char ukm[64];
-OSSL_PARAM params[5], *p = params;
-
-if (RAND_bytes(ukm, sizeof(ukm)) <= 0)
-    error("RAND_bytes");
-
-kdf = EVP_KDF_fetch(NULL, "X942KDF", NULL);
-if (kctx == NULL)
-    error("EVP_KDF_fetch");
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-if (kctx == NULL)
-    error("EVP_KDF_CTX_new");
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, "SHA256", 0);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET,
-                                         "secret", (size_t)6);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_UKM, ukm, sizeof(ukm));
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CEK_ALG, "AES-256-WRAP, 0);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0)
-    error("EVP_KDF_derive");
-
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

ANS1 X9.42-2003 RFC 2631

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-CONCAT.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-CONCAT.html deleted file mode 100644 index 338d0aee..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X942-CONCAT.html +++ /dev/null @@ -1,56 +0,0 @@ - - - - -EVP_KDF-X942-CONCAT - - - - - - - - - - -

NAME

- -

EVP_KDF-X942-CONCAT - The X942 Concat EVP_KDF implementation

- -

DESCRIPTION

- -

The EVP_KDF-X942-CONCAT algorithm is identical to EVP_KDF-X963. It is used for key agreement to derive a key using input such as a shared secret key and shared info.

- -

Identity

- -

"X942KDF_CONCAT" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

This is an alias for "X963KDF".

- -

See EVP_KDF-X963(7) for a list of supported parameters and examples.

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X963.html b/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X963.html deleted file mode 100644 index f3bbb6ae..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KDF-X963.html +++ /dev/null @@ -1,160 +0,0 @@ - - - - -EVP_KDF-X963 - - - - - - - - - - -

NAME

- -

EVP_KDF-X963 - The X9.63-2001 EVP_KDF implementation

- -

DESCRIPTION

- -

The EVP_KDF-X963 algorithm implements the key derivation function (X963KDF). X963KDF is used by Cryptographic Message Syntax (CMS) for EC KeyAgreement, to derive a key using input such as a shared secret key and shared info.

- -

The output is considered to be keying material.

- -

Identity

- -

"X963KDF" is the name for this implementation; it can be used with the EVP_KDF_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_KDF(3).

- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -

The shared secret used for key derivation. This parameter sets the secret.

- -
-
"info" (OSSL_KDF_PARAM_INFO) <octet string>
-
- -

This parameter specifies an optional value for shared info.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_KDF_derive. It returns 0 if any "***-check" related parameter is set to 0 and the check fails.

- -
-
"digest-check" (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) <int>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if used digest is not approved. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -

According to ANSI X9.63-2001, the following are approved digest algorithms: SHA2-224, SHA2-256, SHA2-384, SHA2-512, SHA2-512/224, SHA2-512/256, SHA3-224, SHA3-256, SHA3-384, SHA3-512.

- -
-
"key-check" (OSSL_KDF_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

The default value of 1 causes an error during EVP_KDF_CTX_set_params() if the length of used key-derivation key (OSSL_KDF_PARAM_KEY) is shorter than 112 bits. Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

X963KDF is very similar to the SSKDF that uses a digest as the auxiliary function, X963KDF appends the counter to the secret, whereas SSKDF prepends the counter.

- -

A context for X963KDF can be obtained by calling:

- -
EVP_KDF *kdf = EVP_KDF_fetch(NULL, "X963KDF", NULL);
-EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf);
- -

The output length of an X963KDF is specified via the keylen parameter to the EVP_KDF_derive(3) function.

- -

EXAMPLES

- -

This example derives 10 bytes, with the secret key "secret" and sharedinfo value "label":

- -
EVP_KDF *kdf;
-EVP_KDF_CTX *kctx;
-unsigned char out[10];
-OSSL_PARAM params[4], *p = params;
-
-kdf = EVP_KDF_fetch(NULL, "X963KDF", NULL);
-kctx = EVP_KDF_CTX_new(kdf);
-EVP_KDF_free(kdf);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-                                        SN_sha256, strlen(SN_sha256));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET,
-                                         "secret", (size_t)6);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO,
-                                         "label", (size_t)5);
-*p = OSSL_PARAM_construct_end();
-if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) {
-    error("EVP_KDF_derive");
-}
-
-EVP_KDF_CTX_free(kctx);
- -

CONFORMING TO

- -

"SEC 1: Elliptic Curve Cryptography"

- -

SEE ALSO

- -

EVP_KDF(3), EVP_KDF_CTX_new(3), EVP_KDF_CTX_free(3), EVP_KDF_CTX_set_params(3), EVP_KDF_CTX_get_kdf_size(3), EVP_KDF_derive(3), "PARAMETERS" in EVP_KDF(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KEM-EC.html b/openssl-install/share/doc/openssl/html/man7/EVP_KEM-EC.html deleted file mode 100644 index 8f27c3f4..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KEM-EC.html +++ /dev/null @@ -1,94 +0,0 @@ - - - - -EVP_KEM-EC - - - - - - - - - - -

NAME

- -

EVP_KEM-EC - EVP_KEM EC keytype and algorithm support

- -

DESCRIPTION

- -

The EC keytype and its parameters are described in EVP_PKEY-EC(7). See EVP_PKEY_encapsulate(3) and EVP_PKEY_decapsulate(3) for more info.

- -

EC KEM parameters

- -
- -
"operation" (OSSL_KEM_PARAM_OPERATION)<UTF8 string>
-
- -

The OpenSSL EC Key Encapsulation Mechanisms only supports the following operation:

- -
- -
"DHKEM" (OSSL_KEM_PARAM_OPERATION_DHKEM)
-
- -

The encapsulate function generates an ephemeral keypair. It produces keymaterial by doing an ECDH key exchange using the ephemeral private key and a supplied recipient public key. A HKDF operation using the keymaterial and a kem context then produces a shared secret. The shared secret and the ephemeral public key are returned. The decapsulate function uses the recipient private key and the ephemeral public key to produce the same keymaterial, which can then be used to produce the same shared secret. See https://www.rfc-editor.org/rfc/rfc9180.html#name-dh-based-kem-dhkem

- -
-
- -

This can be set using either EVP_PKEY_CTX_set_kem_op() or EVP_PKEY_CTX_set_params().

- -
-
"ikme" (OSSL_KEM_PARAM_IKME) <octet string>
-
- -

Used to specify the key material used for generation of the ephemeral key. This value should not be reused for other purposes. It can only be used for the curves "P-256", "P-384" and "P-521" and should have a length of at least the size of the encoded private key (i.e. 32, 48 and 66 for the listed curves). If this value is not set, then a random ikm is used.

- -
-
- -

CONFORMING TO

- -
- -
RFC9180
-
- -
-
- -

SEE ALSO

- -

EVP_PKEY_CTX_set_kem_op(3), EVP_PKEY_encapsulate(3), EVP_PKEY_decapsulate(3) EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KEM-RSA.html b/openssl-install/share/doc/openssl/html/man7/EVP_KEM-RSA.html deleted file mode 100644 index 825202c3..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KEM-RSA.html +++ /dev/null @@ -1,100 +0,0 @@ - - - - -EVP_KEM-RSA - - - - - - - - - - -

NAME

- -

EVP_KEM-RSA - EVP_KEM RSA keytype and algorithm support

- -

DESCRIPTION

- -

The RSA keytype and its parameters are described in EVP_PKEY-RSA(7). See EVP_PKEY_encapsulate(3) and EVP_PKEY_decapsulate(3) for more info.

- -

RSA KEM parameters

- -
- -
"operation" (OSSL_KEM_PARAM_OPERATION) <UTF8 string>
-
- -

The OpenSSL RSA Key Encapsulation Mechanism only currently supports the following operation

- -
- -
"RSASVE"
-
- -

The encapsulate function simply generates a secret using random bytes and then encrypts the secret using the RSA public key (with no padding). The decapsulate function recovers the secret using the RSA private key.

- -
-
- -

This can be set using EVP_PKEY_CTX_set_kem_op().

- -
-
"fips-indicator" (OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"key-check" (OSSL_KEM_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

These parameters are described in provider-kem(7).

- -
-
- -

CONFORMING TO

- -
- -
SP800-56Br2
-
- -

Section 7.2.1.2 RSASVE Generate Operation (RSASVE.GENERATE). Section 7.2.1.3 RSASVE Recovery Operation (RSASVE.RECOVER).

- -
-
- -

SEE ALSO

- -

EVP_PKEY_CTX_set_kem_op(3), EVP_PKEY_encapsulate(3), EVP_PKEY_decapsulate(3) EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KEM-X25519.html b/openssl-install/share/doc/openssl/html/man7/EVP_KEM-X25519.html deleted file mode 100644 index b96dcb40..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KEM-X25519.html +++ /dev/null @@ -1,94 +0,0 @@ - - - - -EVP_KEM-X25519 - - - - - - - - - - -

NAME

- -

EVP_KEM-X25519, EVP_KEM-X448 - EVP_KEM X25519 and EVP_KEM X448 keytype and algorithm support

- -

DESCRIPTION

- -

The X25519 and <X448> keytype and its parameters are described in EVP_PKEY-X25519(7). See EVP_PKEY_encapsulate(3) and EVP_PKEY_decapsulate(3) for more info.

- -

X25519 and X448 KEM parameters

- -
- -
"operation" (OSSL_KEM_PARAM_OPERATION)<UTF8 string>
-
- -

The OpenSSL X25519 and X448 Key Encapsulation Mechanisms only support the following operation:

- -
- -
"DHKEM" (OSSL_KEM_PARAM_OPERATION_DHKEM)
-
- -

The encapsulate function generates an ephemeral keypair. It produces keymaterial by doing an X25519 or X448 key exchange using the ephemeral private key and a supplied recipient public key. A HKDF operation using the keymaterial and a kem context then produces a shared secret. The shared secret and the ephemeral public key are returned. The decapsulate function uses the recipient private key and the ephemeral public key to produce the same keymaterial, which can then be used to produce the same shared secret. See https://www.rfc-editor.org/rfc/rfc9180.html#name-dh-based-kem-dhkem

- -
-
- -

This can be set using either EVP_PKEY_CTX_set_kem_op() or EVP_PKEY_CTX_set_params().

- -
-
"ikme" (OSSL_KEM_PARAM_IKME) <octet string>
-
- -

Used to specify the key material used for generation of the ephemeral key. This value should not be reused for other purposes. It should have a length of at least 32 for X25519, and 56 for X448. If this value is not set, then a random ikm is used.

- -
-
- -

CONFORMING TO

- -
- -
RFC9180
-
- -
-
- -

SEE ALSO

- -

EVP_PKEY_CTX_set_kem_op(3), EVP_PKEY_encapsulate(3), EVP_PKEY_decapsulate(3) EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.2.

- -

COPYRIGHT

- -

Copyright 2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-DH.html b/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-DH.html deleted file mode 100644 index 42a570c4..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-DH.html +++ /dev/null @@ -1,156 +0,0 @@ - - - - -EVP_KEYEXCH-DH - - - - - - - - - - -

NAME

- -

EVP_KEYEXCH-DH - DH Key Exchange algorithm support

- -

DESCRIPTION

- -

Key exchange support for the DH and DHX key types.

- -

Please note that although both key types support the same key exchange operations, they cannot be used together in a single key exchange. It is not possible to use a private key of the DH type in key exchange with the public key of DHX type and vice versa.

- -

DH and DHX key exchange parameters

- -
- -
"pad" (OSSL_EXCHANGE_PARAM_PAD) <unsigned integer>
-
- -

Sets the padding mode for the associated key exchange ctx. Setting a value of 1 will turn padding on. Setting a value of 0 will turn padding off. If padding is off then the derived shared secret may be smaller than the largest possible secret size. If padding is on then the derived shared secret will have its first bytes filled with zeros where necessary to make the shared secret the same size as the largest possible secret size. The padding mode parameter is ignored (and padding implicitly enabled) when the KDF type is set to "X942KDF-ASN1" (OSSL_KDF_NAME_X942KDF_ASN1).

- -
-
"kdf-type" (OSSL_EXCHANGE_PARAM_KDF_TYPE) <UTF8 string>
-
- -
-
"kdf-digest" (OSSL_EXCHANGE_PARAM_KDF_DIGEST) <UTF8 string>
-
- -
-
"kdf-digest-props" (OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS) <UTF8 string>
-
- -
-
"kdf-outlen" (OSSL_EXCHANGE_PARAM_KDF_OUTLEN) <unsigned integer>
-
- -
-
"kdf-ukm" (OSSL_EXCHANGE_PARAM_KDF_UKM) <octet string>
-
- -
-
"fips-indicator" (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"key-check" (OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK) <integer>
-
- -
-
"digest-check" (OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

See "Common Key Exchange parameters" in provider-keyexch(7).

- -
-
"cekalg" (OSSL_KDF_PARAM_CEK_ALG) <octet string ptr>
-
- -

See "KDF Parameters" in provider-kdf(7).

- -
-
- -

EXAMPLES

- -

The examples assume a host and peer both generate keys using the same named group (or domain parameters). See "Examples" in EVP_PKEY-DH(7). Both the host and peer transfer their public key to each other.

- -

To convert the peer's generated key pair to a public key in DER format in order to transfer to the host:

- -
EVP_PKEY *peer_key; /* It is assumed this contains the peers generated key */
-unsigned char *peer_pub_der = NULL;
-int peer_pub_der_len;
-
-peer_pub_der_len = i2d_PUBKEY(peer_key, &peer_pub_der);
-...
-OPENSSL_free(peer_pub_der);
- -

To convert the received peer's public key from DER format on the host:

- -
const unsigned char *pd = peer_pub_der;
-EVP_PKEY *peer_pub_key = d2i_PUBKEY(NULL, &pd, peer_pub_der_len);
-...
-EVP_PKEY_free(peer_pub_key);
- -

To derive a shared secret on the host using the host's key and the peer's public key:

- -
/* It is assumed that the host_key and peer_pub_key are set up */
-void derive_secret(EVP_KEY *host_key, EVP_PKEY *peer_pub_key)
-{
-    unsigned int pad = 1;
-    OSSL_PARAM params[2];
-    unsigned char *secret = NULL;
-    size_t secret_len = 0;
-    EVP_PKEY_CTX *dctx = EVP_PKEY_CTX_new_from_pkey(NULL, host_key, NULL);
-
-    EVP_PKEY_derive_init(dctx);
-
-    /* Optionally set the padding */
-    params[0] = OSSL_PARAM_construct_uint(OSSL_EXCHANGE_PARAM_PAD, &pad);
-    params[1] = OSSL_PARAM_construct_end();
-    EVP_PKEY_CTX_set_params(dctx, params);
-
-    EVP_PKEY_derive_set_peer(dctx, peer_pub_key);
-
-    /* Get the size by passing NULL as the buffer */
-    EVP_PKEY_derive(dctx, NULL, &secret_len);
-    secret = OPENSSL_zalloc(secret_len);
-
-    EVP_PKEY_derive(dctx, secret, &secret_len);
-    ...
-    OPENSSL_clear_free(secret, secret_len);
-    EVP_PKEY_CTX_free(dctx);
-}
- -

Very similar code can be used by the peer to derive the same shared secret using the host's public key and the peer's generated key pair.

- -

SEE ALSO

- -

EVP_PKEY-DH(7), EVP_PKEY-FFC(7), EVP_PKEY(3), provider-keyexch(7), provider-keymgmt(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-FIPS(7),

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-ECDH.html b/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-ECDH.html deleted file mode 100644 index 0c46ea6b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-ECDH.html +++ /dev/null @@ -1,157 +0,0 @@ - - - - -EVP_KEYEXCH-ECDH - - - - - - - - - - -

NAME

- -

EVP_KEYEXCH-ECDH - ECDH Key Exchange algorithm support

- -

DESCRIPTION

- -

Key exchange support for the ECDH key type.

- -

ECDH Key Exchange parameters

- -
- -
"ecdh-cofactor-mode" (OSSL_EXCHANGE_PARAM_EC_ECDH_COFACTOR_MODE) <integer>
-
- -

Sets or gets the ECDH mode of operation for the associated key exchange ctx.

- -

In the context of an Elliptic Curve Diffie-Hellman key exchange, this parameter can be used to select between the plain Diffie-Hellman (DH) or Cofactor Diffie-Hellman (CDH) variants of the key exchange algorithm.

- -

When setting, the value should be 1, 0 or -1, respectively forcing cofactor mode on, off, or resetting it to the default for the private key associated with the given key exchange ctx.

- -

When getting, the value should be either 1 or 0, respectively signaling if the cofactor mode is on or off.

- -

See also provider-keymgmt(7) for the related OSSL_PKEY_PARAM_USE_COFACTOR_ECDH parameter that can be set on a per-key basis.

- -
-
"kdf-type" (OSSL_EXCHANGE_PARAM_KDF_TYPE) <UTF8 string>
-
- -
-
"kdf-digest" (OSSL_EXCHANGE_PARAM_KDF_DIGEST) <UTF8 string>
-
- -
-
"kdf-digest-props" (OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS) <UTF8 string>
-
- -
-
"kdf-outlen" (OSSL_EXCHANGE_PARAM_KDF_OUTLEN) <unsigned integer>
-
- -
-
"kdf-ukm" (OSSL_EXCHANGE_PARAM_KDF_UKM) <octet string>
-
- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"key-check" (OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK) <integer>
-
- -
-
"digest-check" (OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

See "Common Key Exchange parameters" in provider-keyexch(7).

- -
-
"ecdh-cofactor-check" (OSSL_EXCHANGE_PARAM_FIPS_ECDH_COFACTOR_CHECK) <integer>
-
- -

If required this parameter should before OSSL_FUNC_keyexch_derive(). The default value of 1 causes an error during the OSSL_FUNC_keyexch_derive if the EC curve has a cofactor that is not 1, and the cofactor is not used. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

EXAMPLES

- -

Examples of key agreement can be found in demos/keyexch.

- -

Keys for the host and peer must be generated as shown in "Examples" in EVP_PKEY-EC(7) using the same curve name.

- -

The code to generate a shared secret for the normal case is identical to "Examples" in EVP_KEYEXCH-DH(7).

- -

To derive a shared secret on the host using the host's key and the peer's public key but also using X963KDF with a user key material:

- -
/* It is assumed that the host_key, peer_pub_key and ukm are set up */
-void derive_secret(EVP_PKEY *host_key, EVP_PKEY *peer_key,
-                   unsigned char *ukm, size_t ukm_len)
-{
-    unsigned char secret[64];
-    size_t out_len = sizeof(secret);
-    size_t secret_len = out_len;
-    unsigned int pad = 1;
-    OSSL_PARAM params[6];
-    EVP_PKEY_CTX *dctx = EVP_PKEY_CTX_new_from_pkey(NULL, host_key, NULL);
-
-    EVP_PKEY_derive_init(dctx);
-
-    params[0] = OSSL_PARAM_construct_uint(OSSL_EXCHANGE_PARAM_PAD, &pad);
-    params[1] = OSSL_PARAM_construct_utf8_string(OSSL_EXCHANGE_PARAM_KDF_TYPE,
-                                                 "X963KDF", 0);
-    params[2] = OSSL_PARAM_construct_utf8_string(OSSL_EXCHANGE_PARAM_KDF_DIGEST,
-                                                 "SHA1", 0);
-    params[3] = OSSL_PARAM_construct_size_t(OSSL_EXCHANGE_PARAM_KDF_OUTLEN,
-                                            &out_len);
-    params[4] = OSSL_PARAM_construct_octet_string(OSSL_EXCHANGE_PARAM_KDF_UKM,
-                                                  ukm, ukm_len);
-    params[5] = OSSL_PARAM_construct_end();
-    EVP_PKEY_CTX_set_params(dctx, params);
-
-    EVP_PKEY_derive_set_peer(dctx, peer_pub_key);
-    EVP_PKEY_derive(dctx, secret, &secret_len);
-    ...
-    OPENSSL_clear_free(secret, secret_len);
-    EVP_PKEY_CTX_free(dctx);
-}
- -

SEE ALSO

- -

EVP_PKEY-EC(7) EVP_PKEY(3), provider-keyexch(7), provider-keymgmt(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-FIPS(7),

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-X25519.html b/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-X25519.html deleted file mode 100644 index edfa6f0b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_KEYEXCH-X25519.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -EVP_KEYEXCH-X25519 - - - - - - - - - - -

NAME

- -

EVP_KEYEXCH-X25519, EVP_KEYEXCH-X448 - X25519 and X448 Key Exchange algorithm support

- -

DESCRIPTION

- -

Key exchange support for the X25519 and X448 key types.

- -

Key exchange parameters

- -
- -
"pad" (OSSL_EXCHANGE_PARAM_PAD) <unsigned integer>
-
- -
-
"fips-indicator" (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

X25519 and X448 are not FIPS approved in FIPS 140-3. So this getter will return 0.

- -

See "Common Key Exchange parameters" in provider-keyexch(7).

- -
-
- -

EXAMPLES

- -

Keys for the host and peer can be generated as shown in "Examples" in EVP_PKEY-X25519(7).

- -

The code to generate a shared secret is identical to "Examples" in EVP_KEYEXCH-DH(7).

- -

SEE ALSO

- -

EVP_PKEY-FFC(7), EVP_PKEY-DH(7) EVP_PKEY(3), provider-keyexch(7), provider-keymgmt(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-FIPS(7),

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-BLAKE2.html b/openssl-install/share/doc/openssl/html/man7/EVP_MAC-BLAKE2.html deleted file mode 100644 index 185e6f87..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-BLAKE2.html +++ /dev/null @@ -1,110 +0,0 @@ - - - - -EVP_MAC-BLAKE2 - - - - - - - - - - -

NAME

- -

EVP_MAC-BLAKE2, EVP_MAC-BLAKE2BMAC, EVP_MAC-BLAKE2SMAC - The BLAKE2 EVP_MAC implementations

- -

DESCRIPTION

- -

Support for computing BLAKE2 MACs through the EVP_MAC API.

- -

Identity

- -

These implementations are identified with one of these names and properties, to be used with EVP_MAC_fetch():

- -
- -
"BLAKE2BMAC", "provider=default"
-
- -
-
"BLAKE2SMAC", "provider=default"
-
- -
-
- -

Supported parameters

- -

The general description of these parameters can be found in "PARAMETERS" in EVP_MAC(3).

- -

All these parameters (except for "block-size") can be set with EVP_MAC_CTX_set_params(). Furthermore, the "size" parameter can be retrieved with EVP_MAC_CTX_get_params(), or with EVP_MAC_CTX_get_mac_size(). The length of the "size" parameter should not exceed that of a size_t. Likewise, the "block-size" parameter can be retrieved with EVP_MAC_CTX_get_params(), or with EVP_MAC_CTX_get_block_size().

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the MAC key. It may be at most 64 bytes for BLAKE2BMAC or 32 for BLAKE2SMAC and at least 1 byte in both cases. Setting this parameter is identical to passing a key to EVP_MAC_init(3).

- -
-
"custom" (OSSL_MAC_PARAM_CUSTOM) <octet string>
-
- -

Sets the customization/personalization string. It is an optional value of at most 16 bytes for BLAKE2BMAC or 8 for BLAKE2SMAC, and is empty by default.

- -
-
"salt" (OSSL_MAC_PARAM_SALT) <octet string>
-
- -

Sets the salt. It is an optional value of at most 16 bytes for BLAKE2BMAC or 8 for BLAKE2SMAC, and is empty by default.

- -
-
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

Sets the MAC size. It can be any number between 1 and 32 for EVP_MAC_BLAKE2S or between 1 and 64 for EVP_MAC_BLAKE2B. It is 32 and 64 respectively by default.

- -
-
"block-size" (OSSL_MAC_PARAM_BLOCK_SIZE) <unsigned integer>
-
- -

Gets the MAC block size. It is 64 for EVP_MAC_BLAKE2S and 128 for EVP_MAC_BLAKE2B.

- -
-
- -

SEE ALSO

- -

EVP_MAC_CTX_get_params(3), EVP_MAC_CTX_set_params(3), "PARAMETERS" in EVP_MAC(3), OSSL_PARAM(3)

- -

HISTORY

- -

The macros and functions described here were added to OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-CMAC.html b/openssl-install/share/doc/openssl/html/man7/EVP_MAC-CMAC.html deleted file mode 100644 index 107a7809..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-CMAC.html +++ /dev/null @@ -1,125 +0,0 @@ - - - - -EVP_MAC-CMAC - - - - - - - - - - -

NAME

- -

EVP_MAC-CMAC - The CMAC EVP_MAC implementation

- -

DESCRIPTION

- -

Support for computing CMAC MACs through the EVP_MAC API.

- -

This implementation uses EVP_CIPHER functions to get access to the underlying cipher.

- -

Identity

- -

This implementation is identified with this name and properties, to be used with EVP_MAC_fetch():

- -
- -
"CMAC", "provider=default" or "provider=fips"
-
- -
-
- -

Supported parameters

- -

The general description of these parameters can be found in "PARAMETERS" in EVP_MAC(3).

- -

The following parameter can be set with EVP_MAC_CTX_set_params():

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the MAC key. Setting this parameter is identical to passing a key to EVP_MAC_init(3).

- -
-
"cipher" (OSSL_MAC_PARAM_CIPHER) <UTF8 string>
-
- -

Sets the name of the underlying cipher to be used. The mode of the cipher must be CBC.

- -
-
"properties" (OSSL_MAC_PARAM_PROPERTIES) <UTF8 string>
-
- -

Sets the properties to be queried when trying to fetch the underlying cipher. This must be given together with the cipher naming parameter to be considered valid.

- -
-
"encrypt-check" (OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK) <integer>
-
- -

This option is used by the OpenSSL FIPS provider. If required this parameter should be set before EVP_MAC_init()

- -

The default value of 1 causes an error when a unapproved Triple-DES encryption operation is triggered. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

The following parameters can be retrieved with EVP_MAC_CTX_get_params():

- -
- -
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

The "size" parameter can also be retrieved with with EVP_MAC_CTX_get_mac_size(). The length of the "size" parameter is equal to that of an unsigned int.

- -
-
"block-size" (OSSL_MAC_PARAM_BLOCK_SIZE) <unsigned integer>
-
- -

Gets the MAC block size. The "block-size" parameter can also be retrieved with EVP_MAC_CTX_get_block_size().

- -
-
"fips-indicator" (OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

This option is used by the OpenSSL FIPS provider.

- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling EVP_MAC_final(). It may return 0 if the "encrypt-check" option is set to 0.

- -
-
- -

SEE ALSO

- -

EVP_MAC_CTX_get_params(3), EVP_MAC_CTX_set_params(3), "PARAMETERS" in EVP_MAC(3), OSSL_PARAM(3)

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-GMAC.html b/openssl-install/share/doc/openssl/html/man7/EVP_MAC-GMAC.html deleted file mode 100644 index d2df75a4..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-GMAC.html +++ /dev/null @@ -1,111 +0,0 @@ - - - - -EVP_MAC-GMAC - - - - - - - - - - -

NAME

- -

EVP_MAC-GMAC - The GMAC EVP_MAC implementation

- -

DESCRIPTION

- -

Support for computing GMAC MACs through the EVP_MAC API.

- -

This implementation uses EVP_CIPHER functions to get access to the underlying cipher.

- -

Identity

- -

This implementation is identified with this name and properties, to be used with EVP_MAC_fetch():

- -
- -
"GMAC", "provider=default" or "provider=fips"
-
- -
-
- -

Supported parameters

- -

The general description of these parameters can be found in "PARAMETERS" in EVP_MAC(3).

- -

The following parameter can be set with EVP_MAC_CTX_set_params():

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the MAC key. Setting this parameter is identical to passing a key to EVP_MAC_init(3).

- -
-
"iv" (OSSL_MAC_PARAM_IV) <octet string>
-
- -

Sets the IV of the underlying cipher, when applicable.

- -
-
"cipher" (OSSL_MAC_PARAM_CIPHER) <UTF8 string>
-
- -

Sets the name of the underlying cipher to be used.

- -
-
"properties" (OSSL_MAC_PARAM_PROPERTIES) <UTF8 string>
-
- -

Sets the properties to be queried when trying to fetch the underlying cipher. This must be given together with the cipher naming parameter to be considered valid.

- -
-
- -

The following parameters can be retrieved with EVP_MAC_CTX_get_params():

- -
- -
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

Gets the MAC size.

- -
-
- -

The "size" parameter can also be retrieved with EVP_MAC_CTX_get_mac_size(). The length of the "size" parameter is equal to that of an unsigned int.

- -

SEE ALSO

- -

EVP_MAC_CTX_get_params(3), EVP_MAC_CTX_set_params(3), "PARAMETERS" in EVP_MAC(3), OSSL_PARAM(3)

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-HMAC.html b/openssl-install/share/doc/openssl/html/man7/EVP_MAC-HMAC.html deleted file mode 100644 index 77296738..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-HMAC.html +++ /dev/null @@ -1,137 +0,0 @@ - - - - -EVP_MAC-HMAC - - - - - - - - - - -

NAME

- -

EVP_MAC-HMAC - The HMAC EVP_MAC implementation

- -

DESCRIPTION

- -

Support for computing HMAC MACs through the EVP_MAC API.

- -

This implementation uses EVP_MD functions to get access to the underlying digest.

- -

Identity

- -

This implementation is identified with this name and properties, to be used with EVP_MAC_fetch():

- -
- -
"HMAC", "provider=default" or "provider=fips"
-
- -
-
- -

Supported parameters

- -

The general description of these parameters can be found in "PARAMETERS" in EVP_MAC(3).

- -

The following parameters can be set with EVP_MAC_CTX_set_params():

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the MAC key. Setting this parameter is identical to passing a key to EVP_MAC_init(3).

- -
-
"digest" (OSSL_MAC_PARAM_DIGEST) <UTF8 string>
-
- -

Sets the name of the underlying digest to be used.

- -
-
"properties" (OSSL_MAC_PARAM_PROPERTIES) <UTF8 string>
-
- -

Sets the properties to be queried when trying to fetch the underlying digest. This must be given together with the digest naming parameter ("digest", or OSSL_MAC_PARAM_DIGEST) to be considered valid.

- -
-
"digest-noinit" (OSSL_MAC_PARAM_DIGEST_NOINIT) <integer>
-
- -

A flag to set the MAC digest to not initialise the implementation specific data. The value 0 or 1 is expected. This option is deprecated and will be removed in a future release. It may be set but is currently ignored

- -
-
"digest-oneshot" (OSSL_MAC_PARAM_DIGEST_ONESHOT) <integer>
-
- -

A flag to set the MAC digest to be a one-shot operation. The value 0 or 1 is expected. This option is deprecated and will be removed in a future release. It may be set but is currently ignored.

- -
-
"tls-data-size" (OSSL_MAC_PARAM_TLS_DATA_SIZE) <unsigned integer>
-
- -
-
"key-check" (OSSL_MAC_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

See "Mac Parameters" in provider-mac(7).

- -
-
- -

The following parameters can be retrieved with EVP_MAC_CTX_get_params():

- -
- -
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

The "size" parameter can also be retrieved with EVP_MAC_CTX_get_mac_size(). The length of the "size" parameter is equal to that of an unsigned int.

- -
-
"block-size" (OSSL_MAC_PARAM_BLOCK_SIZE) <unsigned integer>
-
- -

Gets the MAC block size. The "block-size" parameter can also be retrieved with EVP_MAC_CTX_get_block_size().

- -
-
"fips-indicator" (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

See "Mac Parameters" in provider-mac(7).

- -
-
- -

SEE ALSO

- -

EVP_MAC_CTX_get_params(3), EVP_MAC_CTX_set_params(3), "PARAMETERS" in EVP_MAC(3), OSSL_PARAM(3), HMAC(3)

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-KMAC.html b/openssl-install/share/doc/openssl/html/man7/EVP_MAC-KMAC.html deleted file mode 100644 index ba197c48..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-KMAC.html +++ /dev/null @@ -1,191 +0,0 @@ - - - - -EVP_MAC-KMAC - - - - - - - - - - -

NAME

- -

EVP_MAC-KMAC, EVP_MAC-KMAC128, EVP_MAC-KMAC256 - The KMAC EVP_MAC implementations

- -

DESCRIPTION

- -

Support for computing KMAC MACs through the EVP_MAC API.

- -

Identity

- -

These implementations are identified with one of these names and properties, to be used with EVP_MAC_fetch():

- -
- -
"KMAC-128", "provider=default" or "provider=fips"
-
- -
-
"KMAC-256", "provider=default" or "provider=fips"
-
- -
-
- -

Supported parameters

- -

The general description of these parameters can be found in "PARAMETERS" in EVP_MAC(3).

- -

All these parameters (except for "block-size") can be set with EVP_MAC_CTX_set_params(). Furthermore, the "size" parameter can be retrieved with EVP_MAC_CTX_get_params(), or with EVP_MAC_CTX_get_mac_size(). The length of the "size" parameter should not exceed that of a size_t. Likewise, the "block-size" parameter can be retrieved with EVP_MAC_CTX_get_params(), or with EVP_MAC_CTX_get_block_size().

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the MAC key. Setting this parameter is identical to passing a key to EVP_MAC_init(3). The length of the key (in bytes) must be in the range 4...512.

- -
-
"custom" (OSSL_MAC_PARAM_CUSTOM) <octet string>
-
- -

Sets the customization string. It is an optional value with a length of at most 512 bytes, and is empty by default.

- -
-
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

Sets the MAC size. By default, it is 32 for KMAC-128 and 64 for KMAC-256.

- -
-
"block-size" (OSSL_MAC_PARAM_BLOCK_SIZE) <unsigned integer>
-
- -

Gets the MAC block size. It is 168 for KMAC-128 and 136 for KMAC-256.

- -
-
"xof" (OSSL_MAC_PARAM_XOF) <integer>
-
- -

The "xof" parameter value is expected to be 1 or 0. Use 1 to enable XOF mode. The default value is 0.

- -
-
"fips-indicator" (OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR) <int>
-
- -

This settable parameter is described in provider-mac(7).

- -
-
"no-short-mac" (OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC) <integer>
-
- -

This settable parameter is described in provider-mac(7). It is used by the OpenSSL FIPS provider and the minimum length output for KMAC is defined by NIST's SP 800-185 8.4.2.

- -
-
"key-check" (OSSL_MAC_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

This settable parameter is described in provider-mac(7).

- -
-
- -

The "custom" and "no-short-mac" parameters must be set as part of or before the EVP_MAC_init() call. The "xof" and "size" parameters can be set at any time before EVP_MAC_final(). The "key" parameter is set as part of the EVP_MAC_init() call, but can be set before it instead.

- -

EXAMPLES

- -
#include <openssl/evp.h>
-#include <openssl/params.h>
-
-static int do_kmac(const unsigned char *in, size_t in_len,
-                   const unsigned char *key, size_t key_len,
-                   const unsigned char *custom, size_t custom_len,
-                   int xof_enabled, unsigned char *out, int out_len)
-{
-    EVP_MAC_CTX *ctx = NULL;
-    EVP_MAC *mac = NULL;
-    OSSL_PARAM params[4], *p;
-    int ret = 0;
-    size_t l = 0;
-
-    mac = EVP_MAC_fetch(NULL, "KMAC-128", NULL);
-    if (mac == NULL)
-        goto err;
-    ctx = EVP_MAC_CTX_new(mac);
-    /* The mac can be freed after it is used by EVP_MAC_CTX_new */
-    EVP_MAC_free(mac);
-    if (ctx == NULL)
-        goto err;
-
-    /*
-     * Setup parameters required before calling EVP_MAC_init()
-     * The parameters OSSL_MAC_PARAM_XOF and OSSL_MAC_PARAM_SIZE may also be
-     * used at this point.
-     */
-    p = params;
-    *p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY,
-                                             (void *)key, key_len);
-    if (custom != NULL && custom_len != 0)
-      *p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_CUSTOM,
-                                               (void *)custom, custom_len);
-    *p = OSSL_PARAM_construct_end();
-    if (!EVP_MAC_CTX_set_params(ctx, params))
-        goto err;
-
-    if (!EVP_MAC_init(ctx))
-        goto err;
-
-    /*
-     * Note: the following optional parameters can be set any time
-     * before EVP_MAC_final().
-     */
-    p = params;
-    *p++ = OSSL_PARAM_construct_int(OSSL_MAC_PARAM_XOF, &xof_enabled);
-    *p++ = OSSL_PARAM_construct_int(OSSL_MAC_PARAM_SIZE, &out_len);
-    *p = OSSL_PARAM_construct_end();
-    if (!EVP_MAC_CTX_set_params(ctx, params))
-        goto err;
-
-    /* The update may be called multiple times here for streamed input */
-    if (!EVP_MAC_update(ctx, in, in_len))
-        goto err;
-    if (!EVP_MAC_final(ctx, out, &l, out_len))
-        goto err;
-    ret = 1;
-err:
-    EVP_MAC_CTX_free(ctx);
-    return ret;
-}
- -

SEE ALSO

- -

EVP_MAC_CTX_get_params(3), EVP_MAC_CTX_set_params(3), "PARAMETERS" in EVP_MAC(3), OSSL_PARAM(3), SP 800-185 8.4.2

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-Poly1305.html b/openssl-install/share/doc/openssl/html/man7/EVP_MAC-Poly1305.html deleted file mode 100644 index 3c30ece9..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-Poly1305.html +++ /dev/null @@ -1,98 +0,0 @@ - - - - -EVP_MAC-Poly1305 - - - - - - - - - - -

NAME

- -

EVP_MAC-Poly1305 - The Poly1305 EVP_MAC implementation

- -

DESCRIPTION

- -

Support for computing Poly1305 MACs through the EVP_MAC API.

- -

Identity

- -

This implementation is identified with this name and properties, to be used with EVP_MAC_fetch():

- -
- -
"POLY1305", "provider=default"
-
- -
-
- -

Supported parameters

- -

The general description of these parameters can be found in "PARAMETERS" in EVP_MAC(3).

- -

The following parameter can be set with EVP_MAC_CTX_set_params():

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the MAC key. Setting this parameter is identical to passing a key to EVP_MAC_init(3).

- -
-
- -

The following parameters can be retrieved with EVP_MAC_CTX_get_params():

- -
- -
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

Gets the MAC size.

- -
-
- -

The "size" parameter can also be retrieved with with EVP_MAC_CTX_get_mac_size(). The length of the "size" parameter should not exceed that of an unsigned int.

- -

NOTES

- -

The OpenSSL implementation of the Poly 1305 MAC corresponds to RFC 7539.

- -

It is critical to never reuse the key. The security implication noted in RFC 8439 applies equally to the OpenSSL implementation.

- -

SEE ALSO

- -

EVP_MAC_CTX_get_params(3), EVP_MAC_CTX_set_params(3), "PARAMETERS" in EVP_MAC(3), OSSL_PARAM(3)

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-Siphash.html b/openssl-install/share/doc/openssl/html/man7/EVP_MAC-Siphash.html deleted file mode 100644 index e1292221..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MAC-Siphash.html +++ /dev/null @@ -1,95 +0,0 @@ - - - - -EVP_MAC-Siphash - - - - - - - - - - -

NAME

- -

EVP_MAC-Siphash - The Siphash EVP_MAC implementation

- -

DESCRIPTION

- -

Support for computing Siphash MACs through the EVP_MAC API.

- -

Identity

- -

This implementation is identified with this name and properties, to be used with EVP_MAC_fetch():

- -
- -
"SIPHASH", "provider=default"
-
- -
-
- -

Supported parameters

- -

The general description of these parameters can be found in "PARAMETERS" in EVP_MAC(3).

- -

All these parameters can be set with EVP_MAC_CTX_set_params(). Furthermore, the "size" parameter can be retrieved with EVP_MAC_CTX_get_params(), or with EVP_MAC_CTX_get_mac_size(). The length of the "size" parameter should not exceed that of a size_t.

- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the MAC key. Setting this parameter is identical to passing a key to EVP_MAC_init(3).

- -
-
"size" (OSSL_MAC_PARAM_SIZE) <unsigned integer>
-
- -

Sets the MAC size.

- -
-
"c-rounds" (OSSL_MAC_PARAM_C_ROUNDS) <unsigned integer>
-
- -

Specifies the number of rounds per message block. By default this is 2.

- -
-
"d-rounds" (OSSL_MAC_PARAM_D_ROUNDS) <unsigned integer>
-
- -

Specifies the number of finalisation rounds. By default this is 4.

- -
-
- -

SEE ALSO

- -

EVP_MAC_CTX_get_params(3), EVP_MAC_CTX_set_params(3), "PARAMETERS" in EVP_MAC(3), OSSL_PARAM(3)

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-BLAKE2.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-BLAKE2.html deleted file mode 100644 index 7ab50214..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-BLAKE2.html +++ /dev/null @@ -1,108 +0,0 @@ - - - - -EVP_MD-BLAKE2 - - - - - - - - - - -

NAME

- -

EVP_MD-BLAKE2 - The BLAKE2 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing BLAKE2 digests through the EVP_MD API.

- -

Identities

- -

This implementation is only available with the default provider, and includes the following varieties:

- -
- -
BLAKE2S-256
-
- -

Known names are "BLAKE2S-256" and "BLAKE2s256".

- -
-
BLAKE2B-512
-
- -

Known names are "BLAKE2B-512" and "BLAKE2b512".

- -
-
- -

Settable Parameters

- -

"BLAKE2B-512" supports the following EVP_MD_CTX_set_params() key described in "PARAMETERS" in EVP_DigestInit(3).

- -
- -
"size" (OSSL_DIGEST_PARAM_SIZE) <unsigned integer>
-
- -
-
- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

Settable Context Parameters

- -

The implementation supports the following OSSL_PARAM(3) entries which are settable for an EVP_MD_CTX with EVP_DigestInit_ex2(3) or EVP_MD_CTX_set_params(3):

- -
- -
"size" (OSSL_DIGEST_PARAM_SIZE) <unsigned integer>
-
- -

Sets a different digest length for the EVP_DigestFinal(3) output. The value of the "size" parameter must not exceed the default digest length of the respective BLAKE2 algorithm variants, 64 for BLAKE2B-512 and 32 for BLAKE2S-256. The parameter must be set with the EVP_DigestInit_ex2(3) call to have an immediate effect. When set with EVP_MD_CTX_set_params(3) it will have an effect only if the EVP_MD_CTX context is reinitialized.

- -
-
- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

The variable size support was added in OpenSSL 3.2 for BLAKE2B-512 and in OpenSSL 3.3 for BLAKE2S-256.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-KECCAK.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-KECCAK.html deleted file mode 100644 index a93eeb74..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-KECCAK.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_MD-KECCAK - - - - - - - - - - -

NAME

- -

EVP_MD-KECCAK - The KECCAK EVP_MD implementations

- -

DESCRIPTION

- -

Support for computing KECCAK digests through the EVP_MD API.

- -

Identities

- -

This implementation is available in the default provider and includes the following varieties:

- -
- -
"KECCAK-224"
-
- -
-
"KECCAK-256"
-
- -
-
"KECCAK-384"
-
- -
-
"KECCAK-512"
-
- -
-
- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD2.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD2.html deleted file mode 100644 index c972cb33..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD2.html +++ /dev/null @@ -1,57 +0,0 @@ - - - - -EVP_MD-MD2 - - - - - - - - - - -

NAME

- -

EVP_MD-MD2 - The MD2 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing MD2 digests through the EVP_MD API.

- -

Identity

- -

This implementation is only available with the legacy provider, and is identified with the name "MD2".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD4.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD4.html deleted file mode 100644 index ad9abfbe..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD4.html +++ /dev/null @@ -1,57 +0,0 @@ - - - - -EVP_MD-MD4 - - - - - - - - - - -

NAME

- -

EVP_MD-MD4 - The MD4 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing MD4 digests through the EVP_MD API.

- -

Identity

- -

This implementation is only available with the legacy provider, and is identified with the name "MD4".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5-SHA1.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5-SHA1.html deleted file mode 100644 index 4bdc4605..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5-SHA1.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -EVP_MD-MD5-SHA1 - - - - - - - - - - -

NAME

- -

EVP_MD-MD5-SHA1 - The MD5-SHA1 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing MD5-SHA1 digests through the EVP_MD API.

- -

MD5-SHA1 is a rather special digest that's used with SSLv3.

- -

Identity

- -

This implementation is only available with the default provider, and is identified with the name "MD5-SHA1".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

Settable Context Parameters

- -

This implementation supports the following OSSL_PARAM(3) entries, settable for an EVP_MD_CTX with EVP_MD_CTX_set_params(3):

- -
- -
"ssl3-ms" (OSSL_DIGEST_PARAM_SSL3_MS) <octet string>
-
- -

This parameter is set by libssl in order to calculate a signature hash for an SSLv3 CertificateVerify message as per RFC6101. It is only set after all handshake messages have already been digested via OP_digest_update() calls. The parameter provides the master secret value to be added to the digest. The digest implementation should calculate the complete digest as per RFC6101 section 5.6.8. The next call after setting this parameter should be OP_digest_final().

- -
-
- -

SEE ALSO

- -

EVP_MD_CTX_set_params(3), provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5.html deleted file mode 100644 index d7ccdfb5..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MD5.html +++ /dev/null @@ -1,57 +0,0 @@ - - - - -EVP_MD-MD5 - - - - - - - - - - -

NAME

- -

EVP_MD-MD5 - The MD5 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing MD5 digests through the EVP_MD API.

- -

Identity

- -

This implementation is only available with the default provider, and is identified with the name "MD5".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MDC2.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-MDC2.html deleted file mode 100644 index bcc810ef..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-MDC2.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -EVP_MD-MDC2 - - - - - - - - - - -

NAME

- -

EVP_MD-MDC2 - The MDC2 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing MDC2 digests through the EVP_MD API.

- -

Identity

- -

This implementation is only available with the legacy provider, and is identified with the name "MDC2".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

Settable Context Parameters

- -

This implementation supports the following OSSL_PARAM(3) entries, settable for an EVP_MD_CTX with EVP_MD_CTX_set_params(3):

- -
- -
"pad-type" (OSSL_DIGEST_PARAM_PAD_TYPE) <unsigned integer>
-
- -

Sets the padding type to be used. Normally the final MDC2 block is padded with zeros. If the pad type is set to 2 then the final block is padded with 0x80 followed by zeros.

- -
-
- -

SEE ALSO

- -

EVP_MD_CTX_set_params(3), provider-digest(7), OSSL_PROVIDER-legacy(7)

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-NULL.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-NULL.html deleted file mode 100644 index cf81fb31..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-NULL.html +++ /dev/null @@ -1,65 +0,0 @@ - - - - -EVP_MD-NULL - - - - - - - - - - -

NAME

- -

EVP_MD-NULL - The NULL EVP_MD implementation

- -

DESCRIPTION

- -

Support for a NULL digest through the EVP_MD API. This algorithm does nothing and returns 1 for its init, update and final methods.

- -

Algorithm Name

- -

The following algorithm is available in the default provider:

- -
- -
"NULL"
-
- -
-
- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

EVP_MD_CTX_set_params(3), provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-RIPEMD160.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-RIPEMD160.html deleted file mode 100644 index ae792e48..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-RIPEMD160.html +++ /dev/null @@ -1,62 +0,0 @@ - - - - -EVP_MD-RIPEMD160 - - - - - - - - - - -

NAME

- -

EVP_MD-RIPEMD160 - The RIPEMD160 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing RIPEMD160 digests through the EVP_MD API.

- -

Identities

- -

This implementation is available in both the default and legacy providers, and is identified with any of the names "RIPEMD-160", "RIPEMD160", "RIPEMD" and "RMD160".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

HISTORY

- -

This digest was added to the default provider in OpenSSL 3.0.7.

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA1.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA1.html deleted file mode 100644 index 29de65cd..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA1.html +++ /dev/null @@ -1,72 +0,0 @@ - - - - -EVP_MD-SHA1 - - - - - - - - - - -

NAME

- -

EVP_MD-SHA1 - The SHA1 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing SHA1 digests through the EVP_MD API.

- -

Identities

- -

This implementation is available with the FIPS provider as well as the default provider, and is identified with the names "SHA1" and "SHA-1".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

Settable Context Parameters

- -

This implementation supports the following OSSL_PARAM(3) entries, settable for an EVP_MD_CTX with EVP_MD_CTX_set_params(3):

- -
- -
"ssl3-ms" (OSSL_DIGEST_PARAM_SSL3_MS) <octet string>
-
- -

This parameter is set by libssl in order to calculate a signature hash for an SSLv3 CertificateVerify message as per RFC6101. It is only set after all handshake messages have already been digested via OP_digest_update() calls. The parameter provides the master secret value to be added to the digest. The digest implementation should calculate the complete digest as per RFC6101 section 5.6.8. The next call after setting this parameter should be OP_digest_final().

- -
-
- -

SEE ALSO

- -

EVP_MD_CTX_set_params(3), provider-digest(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA2.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA2.html deleted file mode 100644 index b0a2237f..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA2.html +++ /dev/null @@ -1,117 +0,0 @@ - - - - -EVP_MD-SHA2 - - - - - - - - - - -

NAME

- -

EVP_MD-SHA2 - The SHA2 EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing SHA2 digests through the EVP_MD API.

- -

Identities

- -

This implementation includes the following varieties:

- - - -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA3.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA3.html deleted file mode 100644 index ff15e63a..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHA3.html +++ /dev/null @@ -1,77 +0,0 @@ - - - - -EVP_MD-SHA3 - - - - - - - - - - -

NAME

- -

EVP_MD-SHA3 - The SHA3 EVP_MD implementations

- -

DESCRIPTION

- -

Support for computing SHA3 digests through the EVP_MD API.

- -

Identities

- -

This implementation is available with the FIPS provider as well as the default provider, and includes the following varieties:

- -
- -
"SHA3-224"
-
- -
-
"SHA3-256"
-
- -
-
"SHA3-384"
-
- -
-
"SHA3-512"
-
- -
-
- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHAKE.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHAKE.html deleted file mode 100644 index c2119924..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SHAKE.html +++ /dev/null @@ -1,121 +0,0 @@ - - - - -EVP_MD-SHAKE - - - - - - - - - - -

NAME

- -

EVP_MD-SHAKE, EVP_MD-KECCAK-KMAC - The SHAKE / KECCAK family EVP_MD implementations

- -

DESCRIPTION

- -

Support for computing SHAKE or KECCAK-KMAC digests through the EVP_MD API.

- -

KECCAK-KMAC is an Extendable Output Function (XOF), with a definition similar to SHAKE, used by the KMAC EVP_MAC implementation (see EVP_MAC-KMAC(7)).

- -

Identities

- -

This implementation is available in the FIPS provider as well as the default provider, and includes the following varieties:

- -
- -
KECCAK-KMAC-128
-
- -

Known names are "KECCAK-KMAC-128" and "KECCAK-KMAC128". This is used by EVP_MAC-KMAC128(7). Using the notation from NIST FIPS 202 (Section 6.2), we have KECCAK-KMAC-128(M, d) = KECCAK[256](M || 00, d) (see the description of KMAC128 in Appendix A of NIST SP 800-185).

- -
-
KECCAK-KMAC-256
-
- -

Known names are "KECCAK-KMAC-256" and "KECCAK-KMAC256". This is used by EVP_MAC-KMAC256(7). Using the notation from NIST FIPS 202 (Section 6.2), we have KECCAK-KMAC-256(M, d) = KECCAK[512](M || 00, d) (see the description of KMAC256 in Appendix A of NIST SP 800-185).

- -
-
SHAKE-128
-
- -

Known names are "SHAKE-128" and "SHAKE128".

- -
-
SHAKE-256
-
- -

Known names are "SHAKE-256" and "SHAKE256".

- -
-
- -

Parameters

- -

This implementation supports the following OSSL_PARAM(3) entries:

- -
- -
"xoflen" (OSSL_DIGEST_PARAM_XOFLEN) <unsigned integer>
-
- -

Sets or Gets the digest length for extendable output functions. The length of the "xoflen" parameter should not exceed that of a size_t.

- -

The SHAKE-128 and SHAKE-256 implementations do not have any default digest length.

- -

This parameter must be set before calling either EVP_DigestFinal_ex() or EVP_DigestFinal(), since these functions were not designed to handle variable length output. It is recommended to either use EVP_DigestSqueeze() or EVP_DigestFinalXOF() instead.

- -
-
"size" (OSSL_DIGEST_PARAM_SIZE) <unsigned integer>
-
- -

An alias of "xoflen".

- -
-
- -

See "PARAMETERS" in EVP_DigestInit(3) for further information related to parameters

- -

NOTES

- -

For SHAKE-128, to ensure the maximum security strength of 128 bits, the output length passed to EVP_DigestFinalXOF() should be at least 32.

- -

For SHAKE-256, to ensure the maximum security strength of 256 bits, the output length passed to EVP_DigestFinalXOF() should be at least 64.

- -

SEE ALSO

- -

EVP_MD_CTX_set_params(3), provider-digest(7), OSSL_PROVIDER-default(7)

- -

HISTORY

- -

Since OpenSSL 3.4 the SHAKE-128 and SHAKE-256 implementations have no default digest length.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SM3.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-SM3.html deleted file mode 100644 index 662b804c..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-SM3.html +++ /dev/null @@ -1,57 +0,0 @@ - - - - -EVP_MD-SM3 - - - - - - - - - - -

NAME

- -

EVP_MD-SM3 - The SM3 EVP_MD implementations

- -

DESCRIPTION

- -

Support for computing SM3 digests through the EVP_MD API.

- -

Identity

- -

This implementation is only available with the default provider, and is identified with the name "SM3".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-WHIRLPOOL.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-WHIRLPOOL.html deleted file mode 100644 index 1408eff9..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-WHIRLPOOL.html +++ /dev/null @@ -1,57 +0,0 @@ - - - - -EVP_MD-WHIRLPOOL - - - - - - - - - - -

NAME

- -

EVP_MD-WHIRLPOOL - The WHIRLPOOL EVP_MD implementation

- -

DESCRIPTION

- -

Support for computing WHIRLPOOL digests through the EVP_MD API.

- -

Identity

- -

This implementation is only available with the legacy provider, and is identified with the name "WHIRLPOOL".

- -

Gettable Parameters

- -

This implementation supports the common gettable parameters described in EVP_MD-common(7).

- -

SEE ALSO

- -

provider-digest(7), OSSL_PROVIDER-default(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_MD-common.html b/openssl-install/share/doc/openssl/html/man7/EVP_MD-common.html deleted file mode 100644 index 69940eee..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_MD-common.html +++ /dev/null @@ -1,74 +0,0 @@ - - - - -EVP_MD-common - - - - - - - - - - -

NAME

- -

EVP_MD-common - The OpenSSL EVP_MD implementations, common things

- -

DESCRIPTION

- -

All the OpenSSL EVP_MD implementations understand the following OSSL_PARAM(3) entries that are gettable with EVP_MD_get_params(3), as well as these:

- -
- -
"blocksize" (OSSL_DIGEST_PARAM_BLOCK_SIZE) <unsigned integer>
-
- -

The digest block size. The length of the "blocksize" parameter should not exceed that of a size_t.

- -

This value can also be retrieved with EVP_MD_get_block_size(3).

- -
-
"size" (OSSL_DIGEST_PARAM_SIZE) <unsigned integer>
-
- -

The digest output size. The length of the "size" parameter should not exceed that of a size_t.

- -

This value can also be retrieved with EVP_MD_get_size(3).

- -
-
"flags" (OSSL_DIGEST_PARAM_FLAGS) <unsigned integer>
-
- -

Diverse flags that describe exceptional behaviour for the digest. These flags are described in "DESCRIPTION" in EVP_MD_meth_set_flags(3).

- -

The length of the "flags" parameter should equal that of an unsigned long int.

- -

This value can also be retrieved with EVP_MD_get_flags(3).

- -
-
- -

SEE ALSO

- -

"PARAMETERS" in EVP_DigestInit(3), EVP_MD_get_params(3), provider-digest(7)

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DH.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DH.html deleted file mode 100644 index 13defa56..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DH.html +++ /dev/null @@ -1,337 +0,0 @@ - - - - -EVP_PKEY-DH - - - - - - - - - - -

NAME

- -

EVP_PKEY-DH, EVP_PKEY-DHX, EVP_KEYMGMT-DH, EVP_KEYMGMT-DHX - EVP_PKEY DH and DHX keytype and algorithm support

- -

DESCRIPTION

- -

For finite field Diffie-Hellman key agreement, two classes of domain parameters can be used: "safe" domain parameters that are associated with approved named safe-prime groups, and a class of "FIPS186-type" domain parameters. FIPS186-type domain parameters should only be used for backward compatibility with existing applications that cannot be upgraded to use the approved safe-prime groups.

- -

See EVP_PKEY-FFC(7) for more information about FFC keys.

- -

The DH key type uses PKCS#3 format which saves p and g, but not the q value. The DHX key type uses X9.42 format which saves the value of q and this must be used for FIPS186-4. If key validation is required, users should be aware of the nuances associated with FIPS186-4 style parameters as discussed in "DH and DHX key validation".

- -

DH and DHX domain parameters

- -

In addition to the common FFC parameters that all FFC keytypes should support (see "FFC parameters" in EVP_PKEY-FFC(7)) the DHX and DH keytype implementations support the following:

- -
- -
"group" (OSSL_PKEY_PARAM_GROUP_NAME) <UTF8 string>
-
- -

Sets or gets a string that associates a DH or DHX named safe prime group with known values for p, q and g.

- -

The following values can be used by the OpenSSL's default and FIPS providers: "ffdhe2048", "ffdhe3072", "ffdhe4096", "ffdhe6144", "ffdhe8192", "modp_2048", "modp_3072", "modp_4096", "modp_6144", "modp_8192".

- -

The following additional values can also be used by OpenSSL's default provider: "modp_1536", "dh_1024_160", "dh_2048_224", "dh_2048_256".

- -

DH/DHX named groups can be easily validated since the parameters are well known. For protocols that only transfer p and g the value of q can also be retrieved.

- -
-
- -

DH and DHX additional parameters

- -
- -
"encoded-pub-key" (OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY) <octet string>
-
- -

Used for getting and setting the encoding of the DH public key used in a key exchange message for the TLS protocol. See EVP_PKEY_set1_encoded_public_key() and EVP_PKEY_get1_encoded_public_key().

- -
-
- -

DH additional domain parameters

- -
- -
"safeprime-generator" (OSSL_PKEY_PARAM_DH_GENERATOR) <integer>
-
- -

Used for DH generation of safe primes using the old safe prime generator code. The default value is 2. It is recommended to use a named safe prime group instead, if domain parameter validation is required.

- -

Randomly generated safe primes are not allowed by FIPS, so setting this value for the OpenSSL FIPS provider will instead choose a named safe prime group based on the size of p.

- -
-
- -

DH and DHX domain parameter / key generation parameters

- -

In addition to the common FFC key generation parameters that all FFC key types should support (see "FFC key generation parameters" in EVP_PKEY-FFC(7)) the DH and DHX keytype implementation supports the following:

- -
- -
"type" (OSSL_PKEY_PARAM_FFC_TYPE) <UTF8 string>
-
- -

Sets the type of parameter generation. For DH valid values are:

- -
- -
"fips186_4"
-
- -
-
"default"
-
- -
-
"fips186_2"
-
- -

These are described in "FFC key generation parameters" in EVP_PKEY-FFC(7)

- -
-
"group"
-
- -

This specifies that a named safe prime name will be chosen using the "pbits" type.

- -
-
"generator"
-
- -

A safe prime generator. See the "safeprime-generator" type above. This is only valid for DH keys.

- -
-
- -
-
"pbits" (OSSL_PKEY_PARAM_FFC_PBITS) <unsigned integer>
-
- -

Sets the size (in bits) of the prime 'p'.

- -

For "fips186_4" this must be 2048. For "fips186_2" this must be 1024. For "group" this can be any one of 2048, 3072, 4096, 6144 or 8192.

- -
-
"priv_len" (OSSL_PKEY_PARAM_DH_PRIV_LEN) <integer>
-
- -

An optional value to set the maximum length of the generated private key. The default value used if this is not set is the maximum value of BN_num_bits(q)). The minimum value that this can be set to is 2 * s. Where s is the security strength of the key which has values of 112, 128, 152, 176 and 200 for key sizes of 2048, 3072, 4096, 6144 and 8192.

- -
-
- -

DH and DHX key validation

- -

For keys that are not a named group the FIPS186-4 standard specifies that the values used for FFC parameter generation are also required for parameter validation. This means that optional FFC domain parameter values for seed, pcounter and gindex or hindex may need to be stored for validation purposes. For DHX the seed and pcounter can be stored in ASN1 data (but the gindex or hindex cannot be stored). It is recommended to use a DH parameters with named safe prime group instead.

- -

With the OpenSSL FIPS provider, EVP_PKEY_param_check(3) and EVP_PKEY_param_check_quick(3) behave in the following way: the parameters are tested if they are either an approved safe prime group OR that the FFC parameters conform to FIPS186-4 as defined in SP800-56Ar3 Assurances of Domain-Parameter Validity.

- -

The OpenSSL default provider uses simpler checks that allows there to be no q value for backwards compatibility, however the EVP_PKEY_param_check(3) will test the p value for being a prime (and a safe prime if q is missing) which can take significant time. The EVP_PKEY_param_check_quick(3) avoids the prime tests.

- -

EVP_PKEY_public_check(3) conforms to SP800-56Ar3 FFC Full Public-Key Validation.

- -

EVP_PKEY_public_check_quick(3) conforms to SP800-56Ar3 FFC Partial Public-Key Validation when the key is an approved named safe prime group, otherwise it is the same as EVP_PKEY_public_check(3).

- -

EVP_PKEY_private_check(3) tests that the private key is in the correct range according to SP800-56Ar3. The OpenSSL FIPS provider requires the value of q to be set (note that this is implicitly set for named safe prime groups). For backwards compatibility the OpenSSL default provider only requires p to be set.

- -

EVP_PKEY_pairwise_check(3) conforms to SP800-56Ar3 Owner Assurance of Pair-wise Consistency.

- -

EXAMPLES

- -

An EVP_PKEY context can be obtained by calling:

- -
EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "DH", NULL);
- -

A DH key can be generated with a named safe prime group by calling:

- -
int priv_len = 2 * 112;
-OSSL_PARAM params[3];
-EVP_PKEY *pkey = NULL;
-EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "DH", NULL);
-
-params[0] = OSSL_PARAM_construct_utf8_string("group", "ffdhe2048", 0);
-/* "priv_len" is optional */
-params[1] = OSSL_PARAM_construct_int("priv_len", &priv_len);
-params[2] = OSSL_PARAM_construct_end();
-
-EVP_PKEY_keygen_init(pctx);
-EVP_PKEY_CTX_set_params(pctx, params);
-EVP_PKEY_generate(pctx, &pkey);
-...
-EVP_PKEY_free(pkey);
-EVP_PKEY_CTX_free(pctx);
- -

DHX domain parameters can be generated according to FIPS186-4 by calling:

- -
int gindex = 2;
-unsigned int pbits = 2048;
-unsigned int qbits = 256;
-OSSL_PARAM params[6];
-EVP_PKEY *param_key = NULL;
-EVP_PKEY_CTX *pctx = NULL;
-
-pctx = EVP_PKEY_CTX_new_from_name(NULL, "DHX", NULL);
-EVP_PKEY_paramgen_init(pctx);
-
-params[0] = OSSL_PARAM_construct_uint("pbits", &pbits);
-params[1] = OSSL_PARAM_construct_uint("qbits", &qbits);
-params[2] = OSSL_PARAM_construct_int("gindex", &gindex);
-params[3] = OSSL_PARAM_construct_utf8_string("type", "fips186_4", 0);
-params[4] = OSSL_PARAM_construct_utf8_string("digest", "SHA256", 0);
-params[5] = OSSL_PARAM_construct_end();
-EVP_PKEY_CTX_set_params(pctx, params);
-
-EVP_PKEY_generate(pctx, &param_key);
-
-EVP_PKEY_print_params(bio_out, param_key, 0, NULL);
-...
-EVP_PKEY_free(param_key);
-EVP_PKEY_CTX_free(pctx);
- -

A DH key can be generated using domain parameters by calling:

- -
EVP_PKEY *key = NULL;
-EVP_PKEY_CTX *gctx = EVP_PKEY_CTX_new_from_pkey(NULL, param_key, NULL);
-
-EVP_PKEY_keygen_init(gctx);
-EVP_PKEY_generate(gctx, &key);
-EVP_PKEY_print_private(bio_out, key, 0, NULL);
-...
-EVP_PKEY_free(key);
-EVP_PKEY_CTX_free(gctx);
- -

To validate FIPS186-4 DHX domain parameters decoded from PEM or DER data, additional values used during generation may be required to be set into the key.

- -

EVP_PKEY_todata(), OSSL_PARAM_merge(), and EVP_PKEY_fromdata() are useful to add these parameters to the original key or domain parameters before the actual validation. In production code the return values should be checked.

- -
EVP_PKEY *received_domp = ...; /* parameters received and decoded */
-unsigned char *seed = ...;     /* and additional parameters received */
-size_t seedlen = ...;          /* by other means, required */
-int gindex = ...;              /* for the validation */
-int pcounter = ...;
-int hindex = ...;
-OSSL_PARAM extra_params[4];
-OSSL_PARAM *domain_params = NULL;
-OSSL_PARAM *merged_params = NULL;
-EVP_PKEY_CTX *ctx = NULL, *validate_ctx = NULL;
-EVP_PKEY *complete_domp = NULL;
-
-EVP_PKEY_todata(received_domp, OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
-                &domain_params);
-extra_params[0] = OSSL_PARAM_construct_octet_string("seed", seed, seedlen);
-/*
- * NOTE: For unverifiable g use "hindex" instead of "gindex"
- * extra_params[1] = OSSL_PARAM_construct_int("hindex", &hindex);
- */
-extra_params[1] = OSSL_PARAM_construct_int("gindex", &gindex);
-extra_params[2] = OSSL_PARAM_construct_int("pcounter", &pcounter);
-extra_params[3] = OSSL_PARAM_construct_end();
-merged_params = OSSL_PARAM_merge(domain_params, extra_params);
-
-ctx = EVP_PKEY_CTX_new_from_name(NULL, "DHX", NULL);
-EVP_PKEY_fromdata_init(ctx);
-EVP_PKEY_fromdata(ctx, &complete_domp, OSSL_KEYMGMT_SELECT_ALL,
-                  merged_params);
-
-validate_ctx = EVP_PKEY_CTX_new_from_pkey(NULL, complete_domp, NULL);
-if (EVP_PKEY_param_check(validate_ctx) > 0)
-    /* validation_passed(); */
-else
-    /* validation_failed(); */
-
-OSSL_PARAM_free(domain_params);
-OSSL_PARAM_free(merged_params);
-EVP_PKEY_CTX_free(ctx);
-EVP_PKEY_CTX_free(validate_ctx);
-EVP_PKEY_free(complete_domp);
- -

CONFORMING TO

- -
- -
RFC 7919 (TLS ffdhe named safe prime groups)
-
- -
-
RFC 3526 (IKE modp named safe prime groups)
-
- -
-
RFC 5114 (Additional DH named groups for dh_1024_160", "dh_2048_224" and "dh_2048_256").
-
- -
-
- -

The following sections of SP800-56Ar3:

- -
- -
5.5.1.1 FFC Domain Parameter Selection/Generation
-
- -
-
Appendix D: FFC Safe-prime Groups
-
- -
-
- -

The following sections of FIPS186-4:

- -
- -
A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function.
-
- -
-
A.2.3 Generation of canonical generator g.
-
- -
-
A.2.1 Unverifiable Generation of the Generator g.
-
- -
-
- -

SEE ALSO

- -

EVP_PKEY-FFC(7), EVP_KEYEXCH-DH(7) EVP_PKEY(3), provider-keymgmt(7), EVP_KEYMGMT(3), OSSL_PROVIDER-default(7), OSSL_PROVIDER-FIPS(7)

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DSA.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DSA.html deleted file mode 100644 index 17706a9f..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-DSA.html +++ /dev/null @@ -1,156 +0,0 @@ - - - - -EVP_PKEY-DSA - - - - - - - - - - -

NAME

- -

EVP_PKEY-DSA, EVP_KEYMGMT-DSA - EVP_PKEY DSA keytype and algorithm support

- -

DESCRIPTION

- -

For DSA the FIPS 186-4 standard specifies that the values used for FFC parameter generation are also required for parameter validation. This means that optional FFC domain parameter values for seed, pcounter and gindex may need to be stored for validation purposes. For DSA these fields are not stored in the ASN1 data so they need to be stored externally if validation is required.

- -

As part of FIPS 140-3 DSA is not longer FIPS approved for key generation and signature validation, but is still allowed for signature verification.

- -

DSA parameters

- -

The DSA key type supports the FFC parameters (see "FFC parameters" in EVP_PKEY-FFC(7)).

- -

It also supports the following parameters:

- -
- -
"sign-check" (OSSL_PKEY_PARAM_FIPS_SIGN_CHECK) <integer
-
- -
-
"fips-indicator" (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

See "Common Information Parameters" in provider-keymgmt(7) for more information.

- -
-
- -

DSA key generation parameters

- -

The DSA key type supports the FFC key generation parameters (see "FFC key generation parameters" in EVP_PKEY-FFC(7)

- -

The following restrictions apply to the "pbits" field:

- -

For "fips186_4" this must be either 2048 or 3072. For "fips186_2" this must be 1024. For "group" this can be any one of 2048, 3072, 4096, 6144 or 8192.

- -

DSA key validation

- -

For DSA keys, EVP_PKEY_param_check(3) behaves in the following way: The OpenSSL FIPS provider conforms to the rules within the FIPS186-4 standard for FFC parameter validation. For backwards compatibility the OpenSSL default provider uses a much simpler check (see below) for parameter validation, unless the seed parameter is set.

- -

For DSA keys, EVP_PKEY_param_check_quick(3) behaves in the following way: A simple check of L and N and partial g is performed. The default provider also supports validation of legacy "fips186_2" keys.

- -

For DSA keys, EVP_PKEY_public_check(3), EVP_PKEY_private_check(3) and EVP_PKEY_pairwise_check(3) the OpenSSL default and FIPS providers conform to the rules within SP800-56Ar3 for public, private and pairwise tests respectively.

- -

EXAMPLES

- -

An EVP_PKEY context can be obtained by calling:

- -
EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "DSA", NULL);
- -

The DSA domain parameters can be generated by calling:

- -
unsigned int pbits = 2048;
-unsigned int qbits = 256;
-int gindex = 1;
-OSSL_PARAM params[5];
-EVP_PKEY *param_key = NULL;
-EVP_PKEY_CTX *pctx = NULL;
-
-pctx = EVP_PKEY_CTX_new_from_name(NULL, "DSA", NULL);
-EVP_PKEY_paramgen_init(pctx);
-
-params[0] = OSSL_PARAM_construct_uint("pbits", &pbits);
-params[1] = OSSL_PARAM_construct_uint("qbits", &qbits);
-params[2] = OSSL_PARAM_construct_int("gindex", &gindex);
-params[3] = OSSL_PARAM_construct_utf8_string("digest", "SHA384", 0);
-params[4] = OSSL_PARAM_construct_end();
-EVP_PKEY_CTX_set_params(pctx, params);
-
-EVP_PKEY_generate(pctx, &param_key);
-EVP_PKEY_CTX_free(pctx);
-
-EVP_PKEY_print_params(bio_out, param_key, 0, NULL);
- -

A DSA key can be generated using domain parameters by calling:

- -
EVP_PKEY *key = NULL;
-EVP_PKEY_CTX *gctx = NULL;
-
-gctx = EVP_PKEY_CTX_new_from_pkey(NULL, param_key, NULL);
-EVP_PKEY_keygen_init(gctx);
-EVP_PKEY_generate(gctx, &key);
-EVP_PKEY_CTX_free(gctx);
-EVP_PKEY_print_private(bio_out, key, 0, NULL);
- -

CONFORMING TO

- -

The following sections of FIPS186-4:

- -
- -
A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function.
-
- -
-
A.2.3 Generation of canonical generator g.
-
- -
-
A.2.1 Unverifiable Generation of the Generator g.
-
- -
-
- -

SEE ALSO

- -

EVP_PKEY-FFC(7), EVP_SIGNATURE-DSA(7) EVP_PKEY(3), provider-keymgmt(7), EVP_KEYMGMT(3), OSSL_PROVIDER-default(7), OSSL_PROVIDER-FIPS(7)

- -

HISTORY

- -

DSA Key generation and signature generation are no longer FIPS approved in OpenSSL 3.4. See "FIPS indicators" in fips_module(7) for more information.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-EC.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-EC.html deleted file mode 100644 index 5296b49c..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-EC.html +++ /dev/null @@ -1,322 +0,0 @@ - - - - -EVP_PKEY-EC - - - - - - - - - - -

NAME

- -

EVP_PKEY-EC, EVP_KEYMGMT-EC - EVP_PKEY EC keytype and algorithm support

- -

DESCRIPTION

- -

The EC keytype is implemented in OpenSSL's default provider.

- -

Common EC parameters

- -

The normal way of specifying domain parameters for an EC curve is via the curve name "group". For curves with no curve name, explicit parameters can be used that specify "field-type", "p", "a", "b", "generator" and "order". Explicit parameters are supported for backwards compatibility reasons, but they are not compliant with multiple standards (including RFC5915) which only allow named curves.

- -

The following Key generation/Gettable/Import/Export types are available for the built-in EC algorithm:

- -
- -
"group" (OSSL_PKEY_PARAM_GROUP_NAME) <UTF8 string>
-
- -

The curve name.

- -
-
"field-type" (OSSL_PKEY_PARAM_EC_FIELD_TYPE) <UTF8 string>
-
- -

The value should be either "prime-field" or "characteristic-two-field", which correspond to prime field Fp and binary field F2^m.

- -
-
"p" (OSSL_PKEY_PARAM_EC_P) <unsigned integer>
-
- -

For a curve over Fp p is the prime for the field. For a curve over F2^m p represents the irreducible polynomial - each bit represents a term in the polynomial. Therefore, there will either be three or five bits set dependent on whether the polynomial is a trinomial or a pentanomial.

- -
-
"a" (OSSL_PKEY_PARAM_EC_A) <unsigned integer>
-
- -
-
"b" (OSSL_PKEY_PARAM_EC_B) <unsigned integer>
-
- -
-
"seed" (OSSL_PKEY_PARAM_EC_SEED) <octet string>
-
- -

a and b represents the coefficients of the curve For Fp: y^2 mod p = x^3 +ax + b mod p OR For F2^m: y^2 + xy = x^3 + ax^2 + b

- -

seed is an optional value that is for information purposes only. It represents the random number seed used to generate the coefficient b from a random number.

- -
-
"generator" (OSSL_PKEY_PARAM_EC_GENERATOR) <octet string>
-
- -
-
"order" (OSSL_PKEY_PARAM_EC_ORDER) <unsigned integer>
-
- -
-
"cofactor" (OSSL_PKEY_PARAM_EC_COFACTOR) <unsigned integer>
-
- -

The generator is a well defined point on the curve chosen for cryptographic operations. The encoding conforms with Sec. 2.3.3 of the SECG SEC 1 ("Elliptic Curve Cryptography") standard. See EC_POINT_oct2point(). Integers used for point multiplications will be between 0 and order - 1. cofactor is an optional value. order multiplied by the cofactor gives the number of points on the curve.

- -
-
"decoded-from-explicit" (OSSL_PKEY_PARAM_EC_DECODED_FROM_EXPLICIT_PARAMS) <integer>
-
- -

Gets a flag indicating whether the key or parameters were decoded from explicit curve parameters. Set to 1 if so or 0 if a named curve was used.

- -
-
"use-cofactor-flag" (OSSL_PKEY_PARAM_USE_COFACTOR_ECDH) <integer>
-
- -

Enable Cofactor DH (ECC CDH) if this value is 1, otherwise it uses normal EC DH if the value is zero. The cofactor variant multiplies the shared secret by the EC curve's cofactor (note for some curves the cofactor is 1).

- -

See also EVP_KEYEXCH-ECDH(7) for the related OSSL_EXCHANGE_PARAM_EC_ECDH_COFACTOR_MODE parameter that can be set on a per-operation basis.

- -
-
"encoding" (OSSL_PKEY_PARAM_EC_ENCODING) <UTF8 string>
-
- -

Set the format used for serializing the EC group parameters. Valid values are "explicit" or "named_curve". The default value is "named_curve".

- -
-
"point-format" (OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT) <UTF8 string>
-
- -

Sets or gets the point_conversion_form for the key. For a description of point_conversion_forms please see EC_POINT_new(3). Valid values are "uncompressed" or "compressed". The default value is "uncompressed".

- -
-
"group-check" (OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE) <UTF8 string>
-
- -

Sets or Gets the type of group check done when EVP_PKEY_param_check() is called. Valid values are "default", "named" and "named-nist". The "named" type checks that the domain parameters match the inbuilt curve parameters, "named-nist" is similar but also checks that the named curve is a nist curve. The "default" type does domain parameter validation for the OpenSSL default provider, but is equivalent to "named-nist" for the OpenSSL FIPS provider.

- -
-
"include-public" (OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC) <integer>
-
- -

Setting this value to 0 indicates that the public key should not be included when encoding the private key. The default value of 1 will include the public key.

- -
-
"pub" (OSSL_PKEY_PARAM_PUB_KEY) <octet string>
-
- -

The public key value in encoded EC point format conforming to Sec. 2.3.3 and 2.3.4 of the SECG SEC 1 ("Elliptic Curve Cryptography") standard. This parameter is used when importing or exporting the public key value with the EVP_PKEY_fromdata() and EVP_PKEY_todata() functions.

- -

Note, in particular, that the choice of point compression format used for encoding the exported value via EVP_PKEY_todata() depends on the underlying provider implementation. Before OpenSSL 3.0.8, the implementation of providers included with OpenSSL always opted for an encoding in compressed format, unconditionally. Since OpenSSL 3.0.8, the implementation has been changed to honor the OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT parameter, if set, or to default to uncompressed format.

- -
-
"priv" (OSSL_PKEY_PARAM_PRIV_KEY) <unsigned integer>
-
- -

The private key value.

- -
-
"encoded-pub-key" (OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY) <octet string>
-
- -

Used for getting and setting the encoding of an EC public key. The public key is expected to be a point conforming to Sec. 2.3.4 of the SECG SEC 1 ("Elliptic Curve Cryptography") standard.

- -
-
"qx" (OSSL_PKEY_PARAM_EC_PUB_X) <unsigned integer>
-
- -

Used for getting the EC public key X component.

- -
-
"qy" (OSSL_PKEY_PARAM_EC_PUB_Y) <unsigned integer>
-
- -

Used for getting the EC public key Y component.

- -
-
"default-digest" (OSSL_PKEY_PARAM_DEFAULT_DIGEST) <UTF8 string>
-
- -

Getter that returns the default digest name. (Currently returns "SHA256" as of OpenSSL 3.0).

- -
-
"dhkem-ikm" (OSSL_PKEY_PARAM_DHKEM_IKM) <octet string>
-
- -

DHKEM requires the generation of a keypair using an input key material (seed). Use this to specify the key material used for generation of the private key. This value should not be reused for other purposes. It can only be used for the curves "P-256", "P-384" and "P-521" and should have a length of at least the size of the encoded private key (i.e. 32, 48 and 66 for the listed curves).

- -
-
- -

The following Gettable types are also available for the built-in EC algorithm:

- -
- -
"basis-type" (OSSL_PKEY_PARAM_EC_CHAR2_TYPE) <UTF8 string>
-
- -

Supports the values "tpBasis" for a trinomial or "ppBasis" for a pentanomial. This field is only used for a binary field F2^m.

- -
-
"m" (OSSL_PKEY_PARAM_EC_CHAR2_M) <integer>
-
- -
-
"tp" (OSSL_PKEY_PARAM_EC_CHAR2_TP_BASIS) <integer>
-
- -
-
"k1" (OSSL_PKEY_PARAM_EC_CHAR2_PP_K1) <integer>
-
- -
-
"k2" (OSSL_PKEY_PARAM_EC_CHAR2_PP_K2) <integer>
-
- -
-
"k3" (OSSL_PKEY_PARAM_EC_CHAR2_PP_K3) <integer>
-
- -

These fields are only used for a binary field F2^m. m is the degree of the binary field.

- -

tp is the middle bit of a trinomial so its value must be in the range m > tp > 0.

- -

k1, k2 and k3 are used to get the middle bits of a pentanomial such that m > k3 > k2 > k1 > 0

- -
-
- -

The following key generation settable parameter is also available for the OpenSSL FIPS provider's EC algorithm:

- -
- -
"key-check" (OSSL_PKEY_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

See "Common Information Parameters" in provider-keymgmt(7) for further information.

- -
-
- -

The following key generation Gettable parameter is available for the OpenSSL FIPS provider's EC algorithm:

- -
- -
"fips-indicator" (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

See "Common Information Parameters" in provider-keymgmt(7) for further information.

- -
-
- -

EC key validation

- -

For EC keys, EVP_PKEY_param_check(3) behaves in the following way: For the OpenSSL default provider it uses either EC_GROUP_check(3) or EC_GROUP_check_named_curve(3) depending on the flag EC_FLAG_CHECK_NAMED_GROUP. The OpenSSL FIPS provider uses EC_GROUP_check_named_curve(3) in order to conform to SP800-56Ar3 Assurances of Domain-Parameter Validity.

- -

For EC keys, EVP_PKEY_param_check_quick(3) is equivalent to EVP_PKEY_param_check(3).

- -

For EC keys, EVP_PKEY_public_check(3) and EVP_PKEY_public_check_quick(3) conform to SP800-56Ar3 ECC Full Public-Key Validation and ECC Partial Public-Key Validation respectively.

- -

For EC Keys, EVP_PKEY_private_check(3) and EVP_PKEY_pairwise_check(3) conform to SP800-56Ar3 Private key validity and Owner Assurance of Pair-wise Consistency respectively.

- -

EXAMPLES

- -

An EVP_PKEY context can be obtained by calling:

- -
EVP_PKEY_CTX *pctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL);
- -

An EVP_PKEY ECDSA or ECDH key can be generated with a "P-256" named group by calling:

- -
pkey = EVP_EC_gen("P-256");
- -

or like this:

- -
EVP_PKEY *key = NULL;
-OSSL_PARAM params[2];
-EVP_PKEY_CTX *gctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL);
-
-EVP_PKEY_keygen_init(gctx);
-
-params[0] = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME,
-                                             "P-256", 0);
-params[1] = OSSL_PARAM_construct_end();
-EVP_PKEY_CTX_set_params(gctx, params);
-
-EVP_PKEY_generate(gctx, &key);
-
-EVP_PKEY_print_private(bio_out, key, 0, NULL);
-...
-EVP_PKEY_free(key);
-EVP_PKEY_CTX_free(gctx);
- -

An EVP_PKEY EC CDH (Cofactor Diffie-Hellman) key can be generated with a "K-571" named group by calling:

- -
int use_cdh = 1;
-EVP_PKEY *key = NULL;
-OSSL_PARAM params[3];
-EVP_PKEY_CTX *gctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL);
-
-EVP_PKEY_keygen_init(gctx);
-
-params[0] = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME,
-                                             "K-571", 0);
-/*
- * This curve has a cofactor that is not 1 - so setting CDH mode changes
- * the behaviour. For many curves the cofactor is 1 - so setting this has
- * no effect.
- */
-params[1] = OSSL_PARAM_construct_int(OSSL_PKEY_PARAM_USE_COFACTOR_ECDH,
-                                     &use_cdh);
-params[2] = OSSL_PARAM_construct_end();
-EVP_PKEY_CTX_set_params(gctx, params);
-
-EVP_PKEY_generate(gctx, &key);
-EVP_PKEY_print_private(bio_out, key, 0, NULL);
-...
-EVP_PKEY_free(key);
-EVP_PKEY_CTX_free(gctx);
- -

SEE ALSO

- -

EVP_EC_gen(3), EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7), EVP_SIGNATURE-ECDSA(7), EVP_KEYEXCH-ECDH(7)

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-FFC.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-FFC.html deleted file mode 100644 index 6e50746c..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-FFC.html +++ /dev/null @@ -1,266 +0,0 @@ - - - - -EVP_PKEY-FFC - - - - - - - - - - -

NAME

- -

EVP_PKEY-FFC - EVP_PKEY DSA and DH/DHX shared FFC parameters.

- -

DESCRIPTION

- -

Finite field cryptography (FFC) is a method of implementing discrete logarithm cryptography using finite field mathematics. DSA is an example of FFC and Diffie-Hellman key establishment algorithms specified in SP800-56A can also be implemented as FFC.

- -

The DSA, DH and DHX keytypes are implemented in OpenSSL's default and FIPS providers. The implementations support the basic DSA, DH and DHX keys, containing the public and private keys pub and priv as well as the three main domain parameters p, q and g.

- -

For DSA (and DH that is not a named group) the FIPS186-4 standard specifies that the values used for FFC parameter generation are also required for parameter validation. This means that optional FFC domain parameter values for seed, pcounter and gindex may need to be stored for validation purposes. For DH the seed and pcounter can be stored in ASN1 data (but the gindex is not). For DSA however, these fields are not stored in the ASN1 data so they need to be stored externally if validation is required.

- -

The DH key type uses PKCS#3 format which saves p and g, but not the 'q' value. The DHX key type uses X9.42 format which saves the value of 'q' and this must be used for FIPS186-4.

- -

FFC parameters

- -

In addition to the common parameters that all keytypes should support (see "Common parameters" in provider-keymgmt(7)), the DSA, DH and DHX keytype implementations support the following.

- -
- -
"pub" (OSSL_PKEY_PARAM_PUB_KEY) <unsigned integer>
-
- -

The public key value.

- -
-
"priv" (OSSL_PKEY_PARAM_PRIV_KEY) <unsigned integer>
-
- -

The private key value.

- -
-
- -

FFC DSA, DH and DHX domain parameters

- -
- -
"p" (OSSL_PKEY_PARAM_FFC_P) <unsigned integer>
-
- -

A DSA or Diffie-Hellman prime "p" value.

- -
-
"g" (OSSL_PKEY_PARAM_FFC_G) <unsigned integer>
-
- -

A DSA or Diffie-Hellman generator "g" value.

- -
-
- -

FFC DSA and DHX domain parameters

- -
- -
"q" (OSSL_PKEY_PARAM_FFC_Q) <unsigned integer>
-
- -

A DSA or Diffie-Hellman prime "q" value.

- -
-
"seed" (OSSL_PKEY_PARAM_FFC_SEED) <octet string>
-
- -

An optional domain parameter seed value used during generation and validation of p, q and canonical g. For validation this needs to set the seed that was produced during generation.

- -
-
"gindex" (OSSL_PKEY_PARAM_FFC_GINDEX) <integer>
-
- -

Sets the index to use for canonical generation and verification of the generator g. Set this to a positive value from 0..FF to use this mode. This gindex can then be reused during key validation to verify the value of g. If this value is not set or is -1 then unverifiable generation of the generator g will be used.

- -
-
"pcounter" (OSSL_PKEY_PARAM_FFC_PCOUNTER) <integer>
-
- -

An optional domain parameter counter value that is output during generation of p. This value must be saved if domain parameter validation is required.

- -
-
"hindex" (OSSL_PKEY_PARAM_FFC_H) <integer>
-
- -

For unverifiable generation of the generator g this value is output during generation of g. Its value is the first integer larger than one that satisfies g = h^j mod p (where g != 1 and "j" is the cofactor).

- -
-
"j" (OSSL_PKEY_PARAM_FFC_COFACTOR) <unsigned integer>
-
- -

An optional informational cofactor parameter that should equal to (p - 1) / q.

- -
-
"validate-pq" (OSSL_PKEY_PARAM_FFC_VALIDATE_PQ) <unsigned integer>
-
- -
-
"validate-g" (OSSL_PKEY_PARAM_FFC_VALIDATE_G) <unsigned integer>
-
- -

These boolean values are used during FIPS186-4 or FIPS186-2 key validation checks (See EVP_PKEY_param_check(3)) to select validation options. By default validate-pq and validate-g are both set to 1 to check that p,q and g are valid. Either of these may be set to 0 to skip a test, which is mainly useful for testing purposes.

- -
-
"validate-legacy" (OSSL_PKEY_PARAM_FFC_VALIDATE_LEGACY) <unsigned integer>
-
- -

This boolean value is used during key validation checks (See EVP_PKEY_param_check(3)) to select the validation type. The default value of 0 selects FIPS186-4 validation. Setting this value to 1 selects FIPS186-2 validation.

- -
-
- -

FFC key generation parameters

- -

The following key generation types are available for DSA and DHX algorithms:

- -
- -
"type" (OSSL_PKEY_PARAM_FFC_TYPE) <UTF8 string>
-
- -

Sets the type of parameter generation. The shared valid values are:

- -
- -
"fips186_4"
-
- -

The current standard.

- -
-
"fips186_2"
-
- -

The old standard that should only be used for legacy purposes.

- -
-
"default"
-
- -

This can choose one of "fips186_4" or "fips186_2" depending on other parameters set for parameter generation.

- -
-
- -
-
"pbits" (OSSL_PKEY_PARAM_FFC_PBITS) <unsigned integer>
-
- -

Sets the size (in bits) of the prime 'p'.

- -
-
"qbits" (OSSL_PKEY_PARAM_FFC_QBITS) <unsigned integer>
-
- -

Sets the size (in bits) of the prime 'q'.

- -

For "fips186_4" this can be either 224 or 256. For "fips186_2" this has a size of 160.

- -
-
"digest" (OSSL_PKEY_PARAM_FFC_DIGEST) <UTF8 string>
-
- -

Sets the Digest algorithm to be used as part of the Key Generation Function associated with the given Key Generation ctx. This must also be set for key validation.

- -
-
"properties" (OSSL_PKEY_PARAM_FFC_DIGEST_PROPS) <UTF8 string>
-
- -

Sets properties to be used upon look up of the implementation for the selected Digest algorithm for the Key Generation Function associated with the given key generation ctx. This may also be set for key validation.

- -
-
"seed" (OSSL_PKEY_PARAM_FFC_SEED) <octet string>
-
- -

For "fips186_4" or "fips186_2" generation this sets the seed data to use instead of generating a random seed internally. This should be used for testing purposes only. This will either produce fixed values for the generated parameters OR it will fail if the seed did not generate valid primes.

- -
-
"gindex" (OSSL_PKEY_PARAM_FFC_GINDEX) <integer>
-
- -
-
"pcounter" (OSSL_PKEY_PARAM_FFC_PCOUNTER) <integer>
-
- -
-
"hindex" (OSSL_PKEY_PARAM_FFC_H) <integer>
-
- -

These types are described above.

- -
-
- -

CONFORMING TO

- -

The following sections of SP800-56Ar3:

- -
- -
5.5.1.1 FFC Domain Parameter Selection/Generation
-
- -
-
- -

The following sections of FIPS186-4:

- -
- -
A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function.
-
- -
-
A.2.3 Generation of canonical generator g.
-
- -
-
A.2.1 Unverifiable Generation of the Generator g.
-
- -
-
- -

SEE ALSO

- -

EVP_PKEY-DSA(7), EVP_PKEY-DH(7), EVP_SIGNATURE-DSA(7), EVP_KEYEXCH-DH(7) EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-FIPS(7),

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-HMAC.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-HMAC.html deleted file mode 100644 index c55379bf..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-HMAC.html +++ /dev/null @@ -1,121 +0,0 @@ - - - - -EVP_PKEY-HMAC - - - - - - - - - - -

NAME

- -

EVP_PKEY-HMAC, EVP_KEYMGMT-HMAC, EVP_PKEY-Siphash, EVP_KEYMGMT-Siphash, EVP_PKEY-Poly1305, EVP_KEYMGMT-Poly1305, EVP_PKEY-CMAC, EVP_KEYMGMT-CMAC - EVP_PKEY legacy MAC keytypes and algorithm support

- -

DESCRIPTION

- -

The HMAC and CMAC key types are implemented in OpenSSL's default and FIPS providers. Additionally the Siphash and Poly1305 key types are implemented in the default provider. Performing MAC operations via an EVP_PKEY is considered legacy and are only available for backwards compatibility purposes and for a restricted set of algorithms. The preferred way of performing MAC operations is via the EVP_MAC APIs. See EVP_MAC_init(3).

- -

For further details on using EVP_PKEY based MAC keys see EVP_SIGNATURE-HMAC(7), EVP_SIGNATURE-Siphash(7), EVP_SIGNATURE-Poly1305(7) or EVP_SIGNATURE-CMAC(7).

- -

Common MAC parameters

- -

All the MAC keytypes support the following parameters.

- -
- -
"priv" (OSSL_PKEY_PARAM_PRIV_KEY) <octet string>
-
- -

The MAC key value.

- -
-
"properties" (OSSL_PKEY_PARAM_PROPERTIES) <UTF8 string>
-
- -

A property query string to be used when any algorithms are fetched.

- -
-
- -

CMAC parameters

- -

As well as the parameters described above, the CMAC keytype additionally supports the following parameters.

- -
- -
"cipher" (OSSL_PKEY_PARAM_CIPHER) <UTF8 string>
-
- -

The name of a cipher to be used when generating the MAC.

- -
-
"engine" (OSSL_PKEY_PARAM_ENGINE) <UTF8 string>
-
- -

The name of an engine to be used for the specified cipher (if any).

- -
-
- -

Common MAC key generation parameters

- -

MAC key generation is unusual in that no new key is actually generated. Instead a new provider side key object is created with the supplied raw key value. This is done for backwards compatibility with previous versions of OpenSSL.

- -
- -
"priv" (OSSL_PKEY_PARAM_PRIV_KEY) <octet string>
-
- -

The MAC key value.

- -
-
- -

CMAC key generation parameters

- -

In addition to the common MAC key generation parameters, the CMAC key generation additionally recognises the following.

- -
- -
"cipher" (OSSL_PKEY_PARAM_CIPHER) <UTF8 string>
-
- -

The name of a cipher to be used when generating the MAC.

- -
-
- -

SEE ALSO

- -

EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7)

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-RSA.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-RSA.html deleted file mode 100644 index 874a5603..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-RSA.html +++ /dev/null @@ -1,364 +0,0 @@ - - - - -EVP_PKEY-RSA - - - - - - - - - - -

NAME

- -

EVP_PKEY-RSA, EVP_KEYMGMT-RSA, RSA - EVP_PKEY RSA keytype and algorithm support

- -

DESCRIPTION

- -

The RSA keytype is implemented in OpenSSL's default and FIPS providers. That implementation supports the basic RSA keys, containing the modulus n, the public exponent e, the private exponent d, and a collection of prime factors, exponents and coefficient for CRT calculations, of which the first few are known as p and q, dP and dQ, and qInv.

- -

Common RSA parameters

- -

In addition to the common parameters that all keytypes should support (see "Common parameters" in provider-keymgmt(7)), the RSA keytype implementation supports the following.

- -
- -
"n" (OSSL_PKEY_PARAM_RSA_N) <unsigned integer>
-
- -

The RSA modulus "n" value.

- -
-
"e" (OSSL_PKEY_PARAM_RSA_E) <unsigned integer>
-
- -

The RSA public exponent "e" value. This value must always be set when creating a raw key using EVP_PKEY_fromdata(3). Note that when a decryption operation is performed, that this value is used for blinding purposes to prevent timing attacks.

- -
-
"d" (OSSL_PKEY_PARAM_RSA_D) <unsigned integer>
-
- -

The RSA private exponent "d" value.

- -
-
"rsa-factor1" (OSSL_PKEY_PARAM_RSA_FACTOR1) <unsigned integer>
-
- -
-
"rsa-factor2" (OSSL_PKEY_PARAM_RSA_FACTOR2) <unsigned integer>
-
- -
-
"rsa-factor3" (OSSL_PKEY_PARAM_RSA_FACTOR3) <unsigned integer>
-
- -
-
"rsa-factor4" (OSSL_PKEY_PARAM_RSA_FACTOR4) <unsigned integer>
-
- -
-
"rsa-factor5" (OSSL_PKEY_PARAM_RSA_FACTOR5) <unsigned integer>
-
- -
-
"rsa-factor6" (OSSL_PKEY_PARAM_RSA_FACTOR6) <unsigned integer>
-
- -
-
"rsa-factor7" (OSSL_PKEY_PARAM_RSA_FACTOR7) <unsigned integer>
-
- -
-
"rsa-factor8" (OSSL_PKEY_PARAM_RSA_FACTOR8) <unsigned integer>
-
- -
-
"rsa-factor9" (OSSL_PKEY_PARAM_RSA_FACTOR9) <unsigned integer>
-
- -
-
"rsa-factor10" (OSSL_PKEY_PARAM_RSA_FACTOR10) <unsigned integer>
-
- -

RSA prime factors. The factors are known as "p", "q" and "r_i" in RFC8017. Up to eight additional "r_i" prime factors are supported.

- -
-
"rsa-exponent1" (OSSL_PKEY_PARAM_RSA_EXPONENT1) <unsigned integer>
-
- -
-
"rsa-exponent2" (OSSL_PKEY_PARAM_RSA_EXPONENT2) <unsigned integer>
-
- -
-
"rsa-exponent3" (OSSL_PKEY_PARAM_RSA_EXPONENT3) <unsigned integer>
-
- -
-
"rsa-exponent4" (OSSL_PKEY_PARAM_RSA_EXPONENT4) <unsigned integer>
-
- -
-
"rsa-exponent5" (OSSL_PKEY_PARAM_RSA_EXPONENT5) <unsigned integer>
-
- -
-
"rsa-exponent6" (OSSL_PKEY_PARAM_RSA_EXPONENT6) <unsigned integer>
-
- -
-
"rsa-exponent7" (OSSL_PKEY_PARAM_RSA_EXPONENT7) <unsigned integer>
-
- -
-
"rsa-exponent8" (OSSL_PKEY_PARAM_RSA_EXPONENT8) <unsigned integer>
-
- -
-
"rsa-exponent9" (OSSL_PKEY_PARAM_RSA_EXPONENT9) <unsigned integer>
-
- -
-
"rsa-exponent10" (OSSL_PKEY_PARAM_RSA_EXPONENT10) <unsigned integer>
-
- -

RSA CRT (Chinese Remainder Theorem) exponents. The exponents are known as "dP", "dQ" and "d_i" in RFC8017. Up to eight additional "d_i" exponents are supported.

- -
-
"rsa-coefficient1" (OSSL_PKEY_PARAM_RSA_COEFFICIENT1) <unsigned integer>
-
- -
-
"rsa-coefficient2" (OSSL_PKEY_PARAM_RSA_COEFFICIENT2) <unsigned integer>
-
- -
-
"rsa-coefficient3" (OSSL_PKEY_PARAM_RSA_COEFFICIENT3) <unsigned integer>
-
- -
-
"rsa-coefficient4" (OSSL_PKEY_PARAM_RSA_COEFFICIENT4) <unsigned integer>
-
- -
-
"rsa-coefficient5" (OSSL_PKEY_PARAM_RSA_COEFFICIENT5) <unsigned integer>
-
- -
-
"rsa-coefficient6" (OSSL_PKEY_PARAM_RSA_COEFFICIENT6) <unsigned integer>
-
- -
-
"rsa-coefficient7" (OSSL_PKEY_PARAM_RSA_COEFFICIENT7) <unsigned integer>
-
- -
-
"rsa-coefficient8" (OSSL_PKEY_PARAM_RSA_COEFFICIENT8) <unsigned integer>
-
- -
-
"rsa-coefficient9" (OSSL_PKEY_PARAM_RSA_COEFFICIENT9) <unsigned integer>
-
- -

RSA CRT (Chinese Remainder Theorem) coefficients. The coefficients are known as "qInv" and "t_i". Up to eight additional "t_i" exponents are supported.

- -
-
- -

RSA key generation parameters

- -

When generating RSA keys, the following key generation parameters may be used.

- -
- -
"bits" (OSSL_PKEY_PARAM_RSA_BITS) <unsigned integer>
-
- -

The value should be the cryptographic length for the RSA cryptosystem, in bits.

- -
-
"primes" (OSSL_PKEY_PARAM_RSA_PRIMES) <unsigned integer>
-
- -

The value should be the number of primes for the generated RSA key. The default is 2. It isn't permitted to specify a larger number of primes than 10. Additionally, the number of primes is limited by the length of the key being generated so the maximum number could be less. Some providers may only support a value of 2.

- -
-
"e" (OSSL_PKEY_PARAM_RSA_E) <unsigned integer>
-
- -

The RSA "e" value. The value may be any odd number greater than or equal to 65537. The default value is 65537. For legacy reasons a value of 3 is currently accepted but is deprecated.

- -
-
"rsa-derive-from-pq" (OSSL_PKEY_PARAM_RSA_DERIVE_FROM_PQ) <unsigned integer>
-
- -

Indicate that missing parameters not passed in the parameter list should be derived if not provided. Setting a nonzero value will cause all needed exponents and coefficients to be derived if not available. Setting this option requires at least OSSL_PARAM_RSA_FACTOR1, OSSL_PARAM_RSA_FACTOR2, and OSSL_PARAM_RSA_N to be provided. This option is ignored if OSSL_KEYMGMT_SELECT_PRIVATE_KEY is not set in the selection parameter.

- -
-
- -

RSA key generation parameters for FIPS module testing

- -

When generating RSA keys, the following additional key generation parameters may be used for algorithm testing purposes only. Do not use these to generate RSA keys for a production environment.

- -
- -
"xp" (OSSL_PKEY_PARAM_RSA_TEST_XP) <unsigned integer>
-
- -
-
"xq" (OSSL_PKEY_PARAM_RSA_TEST_XQ) <unsigned integer>
-
- -

These 2 fields are normally randomly generated and are used to generate "p" and "q".

- -
-
"xp1" (OSSL_PKEY_PARAM_RSA_TEST_XP1) <unsigned integer>
-
- -
-
"xp2" (OSSL_PKEY_PARAM_RSA_TEST_XP2) <unsigned integer>
-
- -
-
"xq1" (OSSL_PKEY_PARAM_RSA_TEST_XQ1) <unsigned integer>
-
- -
-
"xq2" (OSSL_PKEY_PARAM_RSA_TEST_XQ2) <unsigned integer>
-
- -

These 4 fields are normally randomly generated. The prime factors "p1", "p2", "q1" and "q2" are determined from these values.

- -
-
- -

RSA key parameters for FIPS module testing

- -

The following intermediate values can be retrieved only if the values specified in "RSA key generation parameters for FIPS module testing" are set. These should not be accessed in a production environment.

- -
- -
"p1" (OSSL_PKEY_PARAM_RSA_TEST_P1) <unsigned integer>
-
- -
-
"p2" (OSSL_PKEY_PARAM_RSA_TEST_P2) <unsigned integer>
-
- -
-
"q1" (OSSL_PKEY_PARAM_RSA_TEST_Q1) <unsigned integer>
-
- -
-
"q2" (OSSL_PKEY_PARAM_RSA_TEST_Q2) <unsigned integer>
-
- -

The auxiliary probable primes.

- -
-
- -

RSA key validation

- -

For RSA keys, EVP_PKEY_param_check(3) and EVP_PKEY_param_check_quick(3) both return 1 unconditionally.

- -

For RSA keys, EVP_PKEY_public_check(3) conforms to the SP800-56Br1 public key check when the OpenSSL FIPS provider is used. The OpenSSL default provider performs similar tests but relaxes the keysize restrictions for backwards compatibility.

- -

For RSA keys, EVP_PKEY_public_check_quick(3) is the same as EVP_PKEY_public_check(3).

- -

For RSA keys, EVP_PKEY_private_check(3) conforms to the SP800-56Br1 private key test.

- -

For RSA keys, EVP_PKEY_pairwise_check(3) conforms to the SP800-56Br1 KeyPair Validation check for the OpenSSL FIPS provider. The OpenSSL default provider allows testing of the validity of multi-primes.

- -

CONFORMING TO

- -
- -
FIPS186-4
-
- -

Section B.3.6 Generation of Probable Primes with Conditions Based on Auxiliary Probable Primes

- -
-
RFC 8017, excluding RSA-PSS and RSA-OAEP
-
- -
-
- -

EXAMPLES

- -

An EVP_PKEY context can be obtained by calling:

- -
EVP_PKEY_CTX *pctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL);
- -

An RSA key can be generated simply like this:

- -
pkey = EVP_RSA_gen(4096);
- -

or like this:

- -
EVP_PKEY *pkey = NULL;
-EVP_PKEY_CTX *pctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL);
-
-EVP_PKEY_keygen_init(pctx);
-EVP_PKEY_generate(pctx, &pkey);
-EVP_PKEY_CTX_free(pctx);
- -

An RSA key can be generated with key generation parameters:

- -
unsigned int primes = 3;
-unsigned int bits = 4096;
-OSSL_PARAM params[3];
-EVP_PKEY *pkey = NULL;
-EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL);
-
-EVP_PKEY_keygen_init(pctx);
-
-params[0] = OSSL_PARAM_construct_uint("bits", &bits);
-params[1] = OSSL_PARAM_construct_uint("primes", &primes);
-params[2] = OSSL_PARAM_construct_end();
-EVP_PKEY_CTX_set_params(pctx, params);
-
-EVP_PKEY_generate(pctx, &pkey);
-EVP_PKEY_print_private(bio_out, pkey, 0, NULL);
-EVP_PKEY_CTX_free(pctx);
- -

SEE ALSO

- -

EVP_RSA_gen(3), EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7)

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-SM2.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-SM2.html deleted file mode 100644 index 70661cd1..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-SM2.html +++ /dev/null @@ -1,105 +0,0 @@ - - - - -EVP_PKEY-SM2 - - - - - - - - - - -

NAME

- -

EVP_PKEY-SM2, EVP_KEYMGMT-SM2, SM2 - EVP_PKEY keytype support for the Chinese SM2 signature and encryption algorithms

- -

DESCRIPTION

- -

The SM2 algorithm was first defined by the Chinese national standard GM/T 0003-2012 and was later standardized by ISO as ISO/IEC 14888. SM2 is actually an elliptic curve based algorithm. The current implementation in OpenSSL supports both signature and encryption schemes via the EVP interface.

- -

When doing the SM2 signature algorithm, it requires a distinguishing identifier to form the message prefix which is hashed before the real message is hashed.

- -

Common SM2 parameters

- -

SM2 uses the parameters defined in "Common EC parameters" in EVP_PKEY-EC(7). The following parameters are different:

- -
- -
"cofactor" (OSSL_PKEY_PARAM_EC_COFACTOR) <unsigned integer>
-
- -

This parameter is ignored for SM2.

- -
-
(OSSL_PKEY_PARAM_DEFAULT_DIGEST) <UTF8 string>
-
- -

Getter that returns the default digest name. (Currently returns "SM3" as of OpenSSL 3.0).

- -
-
- -

NOTES

- -

SM2 signatures can be generated by using the 'DigestSign' series of APIs, for instance, EVP_DigestSignInit(), EVP_DigestSignUpdate() and EVP_DigestSignFinal(). Ditto for the verification process by calling the 'DigestVerify' series of APIs. Note that the SM2 algorithm requires the presence of the public key for signatures, as such the OSSL_PKEY_PARAM_PUB_KEY option must be set on any key used in signature generation.

- -

Before computing an SM2 signature, an EVP_PKEY_CTX needs to be created, and an SM2 ID must be set for it, like this:

- -
EVP_PKEY_CTX_set1_id(pctx, id, id_len);
- -

Before calling the EVP_DigestSignInit() or EVP_DigestVerifyInit() functions, that EVP_PKEY_CTX should be assigned to the EVP_MD_CTX, like this:

- -
EVP_MD_CTX_set_pkey_ctx(mctx, pctx);
- -

There is normally no need to pass a pctx parameter to EVP_DigestSignInit() or EVP_DigestVerifyInit() in such a scenario.

- -

SM2 can be tested with the openssl-speed(1) application since version 3.0. Currently, the only valid algorithm name is sm2.

- -

Since version 3.0, SM2 keys can be generated and loaded only when the domain parameters specify the SM2 elliptic curve.

- -

EXAMPLES

- -

This example demonstrates the calling sequence for using an EVP_PKEY to verify a message with the SM2 signature algorithm and the SM3 hash algorithm:

- -
#include <openssl/evp.h>
-
-/* obtain an EVP_PKEY using whatever methods... */
-mctx = EVP_MD_CTX_new();
-pctx = EVP_PKEY_CTX_new(pkey, NULL);
-EVP_PKEY_CTX_set1_id(pctx, id, id_len);
-EVP_MD_CTX_set_pkey_ctx(mctx, pctx);
-EVP_DigestVerifyInit(mctx, NULL, EVP_sm3(), NULL, pkey);
-EVP_DigestVerifyUpdate(mctx, msg, msg_len);
-EVP_DigestVerifyFinal(mctx, sig, sig_len)
- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_DigestSignInit(3), EVP_DigestVerifyInit(3), EVP_PKEY_CTX_set1_id(3), EVP_MD_CTX_set_pkey_ctx(3)

- -

COPYRIGHT

- -

Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-X25519.html b/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-X25519.html deleted file mode 100644 index d6ff31f4..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_PKEY-X25519.html +++ /dev/null @@ -1,154 +0,0 @@ - - - - -EVP_PKEY-X25519 - - - - - - - - - - -

NAME

- -

EVP_PKEY-X25519, EVP_PKEY-X448, EVP_PKEY-ED25519, EVP_PKEY-ED448, EVP_KEYMGMT-X25519, EVP_KEYMGMT-X448, EVP_KEYMGMT-ED25519, EVP_KEYMGMT-ED448 - EVP_PKEY X25519, X448, ED25519 and ED448 keytype and algorithm support

- -

DESCRIPTION

- -

The X25519, X448, ED25519 and ED448 keytypes are implemented in OpenSSL's default and FIPS providers. These implementations support the associated key, containing the public key pub and the private key priv.

- -

Keygen Parameters

- -
- -
"dhkem-ikm" (OSSL_PKEY_PARAM_DHKEM_IKM) <octet string>
-
- -

DHKEM requires the generation of a keypair using an input key material (seed). Use this to specify the key material used for generation of the private key. This value should not be reused for other purposes. It should have a length of at least 32 for X25519, and 56 for X448. This is only supported by X25519 and X448.

- -
-
"fips-indicator" (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

This getter is only supported by X25519 and X448 for the FIPS provider. Since X25519 and X448 are unapproved in FIPS 140-3 this getter return 0.

- -

See "Common Information Parameters" in provider-keymgmt(7) for further information.

- -
-
- -

Use EVP_PKEY_CTX_set_params() after calling EVP_PKEY_keygen_init().

- -

Common X25519, X448, ED25519 and ED448 parameters

- -

In addition to the common parameters that all keytypes should support (see "Common parameters" in provider-keymgmt(7)), the implementation of these keytypes support the following.

- -
- -
"group" (OSSL_PKEY_PARAM_GROUP_NAME) <UTF8 string>
-
- -

This is only supported by X25519 and X448. The group name must be "x25519" or "x448" respectively for those algorithms. This is only present for consistency with other key exchange algorithms and is typically not needed.

- -
-
"pub" (OSSL_PKEY_PARAM_PUB_KEY) <octet string>
-
- -

The public key value.

- -
-
"priv" (OSSL_PKEY_PARAM_PRIV_KEY) <octet string>
-
- -

The private key value.

- -
-
"encoded-pub-key" (OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY) <octet string>
-
- -

Used for getting and setting the encoding of a public key for the X25519 and X448 key types. Public keys are expected be encoded in a format as defined by RFC7748.

- -
-
- -

ED25519 and ED448 parameters

- -
- -
"mandatory-digest" (OSSL_PKEY_PARAM_MANDATORY_DIGEST) <UTF8 string>
-
- -

The empty string, signifying that no digest may be specified.

- -
-
- -

CONFORMING TO

- -
- -
RFC 8032
-
- -
-
RFC 8410
-
- -
-
- -

EXAMPLES

- -

An EVP_PKEY context can be obtained by calling:

- -
EVP_PKEY_CTX *pctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "X25519", NULL);
-
-EVP_PKEY_CTX *pctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "X448", NULL);
-
-EVP_PKEY_CTX *pctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "ED25519", NULL);
-
-EVP_PKEY_CTX *pctx =
-    EVP_PKEY_CTX_new_from_name(NULL, "ED448", NULL);
- -

An X25519 key can be generated like this:

- -
pkey = EVP_PKEY_Q_keygen(NULL, NULL, "X25519");
- -

An X448, ED25519, or ED448 key can be generated likewise.

- -

SEE ALSO

- -

EVP_KEYMGMT(3), EVP_PKEY(3), provider-keymgmt(7), EVP_KEYEXCH-X25519(7), EVP_KEYEXCH-X448(7), EVP_SIGNATURE-ED25519(7), EVP_SIGNATURE-ED448(7)

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-CRNG-TEST.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND-CRNG-TEST.html deleted file mode 100644 index f0b11710..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-CRNG-TEST.html +++ /dev/null @@ -1,99 +0,0 @@ - - - - -EVP_RAND-CRNG-TEST - - - - - - - - - - -

NAME

- -

EVP_RAND-CRNG-TEST - The FIPS health testing EVP_RAND filter

- -

DESCRIPTION

- -

This EVP_RAND object acts as a filter between the entropy source and its users. It performs CRNG health tests as defined in SP 800-90B Section 4 "Health Tests". Most requests are forwarded to the entropy source, either via its parent reference or via the provider entropy upcalls.

- -

Identity

- -

"CRNG-TEST" is the name for this implementation; it can be used with the EVP_RAND_fetch() function.

- -

Supported parameters

- -

If a parent EVP_RAND is specified on context creation, the parent's parameters are supported because the request is forwarded to the parent seed source for processing.

- -

If no parent EVP_RAND is specified on context creation, the following parameters are supported:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -
-
"max_request" (OSSL_RAND_PARAM_MAX_REQUEST) <unsigned integer>
-
- -

These parameters work as described in "PARAMETERS" in EVP_RAND(3).

- -
-
"fips-indicator" (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

This parameter works as described in "PARAMETERS" in provider-rand(7).

- -
-
- -

NOTES

- -

This EVP_RAND is only implemented by the OpenSSL FIPS provider.

- -

A context for a health test filter can be obtained by calling:

- -
EVP_RAND *parent = ...;
-EVP_RAND *rand = EVP_RAND_fetch(NULL, "CRNG-TEST", NULL);
-EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, parent);
- -

SEE ALSO

- -

EVP_RAND(3), OSSL_PROVIDER-FIPS(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-CTR-DRBG.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND-CTR-DRBG.html deleted file mode 100644 index 4c9d6e58..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-CTR-DRBG.html +++ /dev/null @@ -1,160 +0,0 @@ - - - - -EVP_RAND-CTR-DRBG - - - - - - - - - - -

NAME

- -

EVP_RAND-CTR-DRBG - The CTR DRBG EVP_RAND implementation

- -

DESCRIPTION

- -

Support for the counter deterministic random bit generator through the EVP_RAND API.

- -

Identity

- -

"CTR-DRBG" is the name for this implementation; it can be used with the EVP_RAND_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -
-
"max_request" (OSSL_RAND_PARAM_MAX_REQUEST) <unsigned integer>
-
- -
-
"reseed_requests" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -
-
"reseed_time_interval" (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) <integer>
-
- -
-
"min_entropylen" (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) <unsigned integer>
-
- -
-
"max_entropylen" (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) <unsigned integer>
-
- -
-
"min_noncelen" (OSSL_DRBG_PARAM_MIN_NONCELEN) <unsigned integer>
-
- -
-
"max_noncelen" (OSSL_DRBG_PARAM_MAX_NONCELEN) <unsigned integer>
-
- -
-
"max_perslen" (OSSL_DRBG_PARAM_MAX_PERSLEN) <unsigned integer>
-
- -
-
"max_adinlen" (OSSL_DRBG_PARAM_MAX_ADINLEN) <unsigned integer>
-
- -
-
"reseed_counter" (OSSL_DRBG_PARAM_RESEED_COUNTER) <unsigned integer>
-
- -
-
"properties" (OSSL_DRBG_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"cipher" (OSSL_DRBG_PARAM_CIPHER) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_RAND(3).

- -
-
"use_derivation_function" (OSSL_DRBG_PARAM_USE_DF) <integer>
-
- -

This Boolean indicates if a derivation function should be used or not. A nonzero value (the default) uses the derivation function. A zero value does not.

- -
-
- -

NOTES

- -

A context for CTR DRBG can be obtained by calling:

- -
EVP_RAND *rand = EVP_RAND_fetch(NULL, "CTR-DRBG", NULL);
-EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL);
- -

EXAMPLES

- -
EVP_RAND *rand;
-EVP_RAND_CTX *rctx;
-unsigned char bytes[100];
-OSSL_PARAM params[2], *p = params;
-unsigned int strength = 128;
-
-rand = EVP_RAND_fetch(NULL, "CTR-DRBG", NULL);
-rctx = EVP_RAND_CTX_new(rand, NULL);
-EVP_RAND_free(rand);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER,
-                                        SN_aes_256_ctr, 0);
-*p = OSSL_PARAM_construct_end();
-EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params);
-
-EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0);
-
-EVP_RAND_CTX_free(rctx);
- -

CONFORMING TO

- -

NIST SP 800-90A and SP 800-90B

- -

SEE ALSO

- -

EVP_RAND(3), "PARAMETERS" in EVP_RAND(3)

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-HASH-DRBG.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND-HASH-DRBG.html deleted file mode 100644 index e9469e23..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-HASH-DRBG.html +++ /dev/null @@ -1,194 +0,0 @@ - - - - -EVP_RAND-HASH-DRBG - - - - - - - - - - -

NAME

- -

EVP_RAND-HASH-DRBG - The HASH DRBG EVP_RAND implementation

- -

DESCRIPTION

- -

Support for the hash deterministic random bit generator through the EVP_RAND API.

- -

Identity

- -

"HASH-DRBG" is the name for this implementation; it can be used with the EVP_RAND_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -
-
"max_request" (OSSL_RAND_PARAM_MAX_REQUEST) <unsigned integer>
-
- -
-
"reseed_requests" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -
-
"reseed_time_interval" (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) <integer>
-
- -
-
"min_entropylen" (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) <unsigned integer>
-
- -
-
"max_entropylen" (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) <unsigned integer>
-
- -
-
"min_noncelen" (OSSL_DRBG_PARAM_MIN_NONCELEN) <unsigned integer>
-
- -
-
"max_noncelen" (OSSL_DRBG_PARAM_MAX_NONCELEN) <unsigned integer>
-
- -
-
"max_perslen" (OSSL_DRBG_PARAM_MAX_PERSLEN) <unsigned integer>
-
- -
-
"max_adinlen" (OSSL_DRBG_PARAM_MAX_ADINLEN) <unsigned integer>
-
- -
-
"reseed_counter" (OSSL_DRBG_PARAM_RESEED_COUNTER) <unsigned integer>
-
- -
-
"properties" (OSSL_DRBG_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"digest" (OSSL_DRBG_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_RAND(3).

- -
-
"fips-indicator" (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"digest-check" (OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

These parameters work as described in "PARAMETERS" in provider-rand(7).

- -
-
- -

NOTES

- -

When the FIPS provider is installed using the -no_drbg_truncated_digests option to fipsinstall, only these digests are permitted (as per FIPS 140-3 IG D.R):

- -
- -
SHA-1
-
- -
-
SHA2-256
-
- -
-
SHA2-512
-
- -
-
SHA3-256
-
- -
-
SHA3-512
-
- -
-
- -

A context for HASH DRBG can be obtained by calling:

- -
EVP_RAND *rand = EVP_RAND_fetch(NULL, "HASH-DRBG", NULL);
-EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL);
- -

EXAMPLES

- -
EVP_RAND *rand;
-EVP_RAND_CTX *rctx;
-unsigned char bytes[100];
-OSSL_PARAM params[2], *p = params;
-unsigned int strength = 128;
-
-rand = EVP_RAND_fetch(NULL, "HASH-DRBG", NULL);
-rctx = EVP_RAND_CTX_new(rand, NULL);
-EVP_RAND_free(rand);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_DIGEST, SN_sha512, 0);
-*p = OSSL_PARAM_construct_end();
-EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params);
-
-EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0);
-
-EVP_RAND_CTX_free(rctx);
- -

CONFORMING TO

- -

NIST SP 800-90A and SP 800-90B

- -

SEE ALSO

- -

EVP_RAND(3), "PARAMETERS" in EVP_RAND(3), openssl-fipsinstall(1)

- -

HISTORY

- -

OpenSSL 3.1.1 introduced the -no_drbg_truncated_digests option to fipsinstall which restricts the permitted digests when using the FIPS provider in a complaint manner. For details refer to FIPS 140-3 IG D.R.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-HMAC-DRBG.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND-HMAC-DRBG.html deleted file mode 100644 index 8274d390..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-HMAC-DRBG.html +++ /dev/null @@ -1,199 +0,0 @@ - - - - -EVP_RAND-HMAC-DRBG - - - - - - - - - - -

NAME

- -

EVP_RAND-HMAC-DRBG - The HMAC DRBG EVP_RAND implementation

- -

DESCRIPTION

- -

Support for the HMAC deterministic random bit generator through the EVP_RAND API.

- -

Identity

- -

"HMAC-DRBG" is the name for this implementation; it can be used with the EVP_RAND_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -
-
"max_request" (OSSL_RAND_PARAM_MAX_REQUEST) <unsigned integer>
-
- -
-
"reseed_requests" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -
-
"reseed_time_interval" (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) <integer>
-
- -
-
"min_entropylen" (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) <unsigned integer>
-
- -
-
"max_entropylen" (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) <unsigned integer>
-
- -
-
"min_noncelen" (OSSL_DRBG_PARAM_MIN_NONCELEN) <unsigned integer>
-
- -
-
"max_noncelen" (OSSL_DRBG_PARAM_MAX_NONCELEN) <unsigned integer>
-
- -
-
"max_perslen" (OSSL_DRBG_PARAM_MAX_PERSLEN) <unsigned integer>
-
- -
-
"max_adinlen" (OSSL_DRBG_PARAM_MAX_ADINLEN) <unsigned integer>
-
- -
-
"reseed_counter" (OSSL_DRBG_PARAM_RESEED_COUNTER) <unsigned integer>
-
- -
-
"properties" (OSSL_DRBG_PARAM_PROPERTIES) <UTF8 string>
-
- -
-
"mac" (OSSL_DRBG_PARAM_MAC) <UTF8 string>
-
- -
-
"digest" (OSSL_DRBG_PARAM_DIGEST) <UTF8 string>
-
- -

These parameters work as described in "PARAMETERS" in EVP_RAND(3).

- -
-
"fips-indicator" (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"digest-check" (OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

These parameters work as described in "PARAMETERS" in provider-rand(7).

- -
-
- -

NOTES

- -

When using the FIPS provider, only these digests are permitted (as per FIPS 140-3 IG D.R):

- -
- -
SHA-1
-
- -
-
SHA2-256
-
- -
-
SHA2-512
-
- -
-
SHA3-256
-
- -
-
SHA3-512
-
- -
-
- -

A context for HMAC DRBG can be obtained by calling:

- -
EVP_RAND *rand = EVP_RAND_fetch(NULL, "HMAC-DRBG", NULL);
-EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL);
- -

EXAMPLES

- -
EVP_RAND *rand;
-EVP_RAND_CTX *rctx;
-unsigned char bytes[100];
-OSSL_PARAM params[3], *p = params;
-unsigned int strength = 128;
-
-rand = EVP_RAND_fetch(NULL, "HMAC-DRBG", NULL);
-rctx = EVP_RAND_CTX_new(rand, NULL);
-EVP_RAND_free(rand);
-
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_MAC, SN_hmac, 0);
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_DIGEST, SN_sha256, 0);
-*p = OSSL_PARAM_construct_end();
-EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params);
-
-EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0);
-
-EVP_RAND_CTX_free(rctx);
- -

CONFORMING TO

- -

NIST SP 800-90A and SP 800-90B

- -

SEE ALSO

- -

EVP_RAND(3), "PARAMETERS" in EVP_RAND(3), openssl-fipsinstall(1)

- -

HISTORY

- -

OpenSSL 3.1.1 introduced the -no_drbg_truncated_digests option to fipsinstall which restricts the permitted digests when using the FIPS provider in a complaint manner. For details refer to FIPS 140-3 IG D.R).

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-JITTER.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND-JITTER.html deleted file mode 100644 index 89aa543f..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-JITTER.html +++ /dev/null @@ -1,120 +0,0 @@ - - - - -EVP_RAND-JITTER - - - - - - - - - - -

NAME

- -

EVP_RAND-JITTER - The randomness seed source EVP_RAND implementation

- -

DESCRIPTION

- -

Support for deterministic random number generator seeding through the EVP_RAND API.

- -

This software seed source produces randomness based on tiny CPU "jitter" fluctuations.

- -

It is available when OpenSSL is compiled with enable-jitter option. When available it is listed in openssl list -random-generators and openssl info -seeds.

- -

Identity

- -

"JITTER" is the name for this implementation; it can be used with the EVP_RAND_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -
-
"max_request" (OSSL_RAND_PARAM_MAX_REQUEST) <unsigned integer>
-
- -

These parameters work as described in "PARAMETERS" in EVP_RAND(3).

- -
-
- -

NOTES

- -

A context for the seed source can be obtained by calling:

- -
EVP_RAND *rand = EVP_RAND_fetch(NULL, "JITTER", NULL);
-EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL);
- -

The enable-jitter configuration option was added in OpenSSL 3.4.

- -

EXAMPLES

- -
EVP_RAND *rand;
-EVP_RAND_CTX *seed, *rctx;
-unsigned char bytes[100];
-OSSL_PARAM params[2], *p = params;
-unsigned int strength = 128;
-
-/* Create and instantiate a seed source */
-rand = EVP_RAND_fetch(NULL, "JITTER", NULL);
-seed = EVP_RAND_CTX_new(rand, NULL);
-EVP_RAND_instantiate(seed, strength, 0, NULL, 0, NULL);
-EVP_RAND_free(rand);
-
-/* Feed this into a DRBG */
-rand = EVP_RAND_fetch(NULL, "CTR-DRBG", NULL);
-rctx = EVP_RAND_CTX_new(rand, seed);
-EVP_RAND_free(rand);
-
-/* Configure the DRBG */
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER,
-                                        SN_aes_256_ctr, 0);
-*p = OSSL_PARAM_construct_end();
-EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params);
-
-EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0);
-
-EVP_RAND_CTX_free(rctx);
-EVP_RAND_CTX_free(seed);
- -

SEE ALSO

- -

EVP_RAND(3), "PARAMETERS" in EVP_RAND(3)

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-SEED-SRC.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND-SEED-SRC.html deleted file mode 100644 index 252b3853..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-SEED-SRC.html +++ /dev/null @@ -1,116 +0,0 @@ - - - - -EVP_RAND-SEED-SRC - - - - - - - - - - -

NAME

- -

EVP_RAND-SEED-SRC - The randomness seed source EVP_RAND implementation

- -

DESCRIPTION

- -

Support for deterministic random number generator seeding through the EVP_RAND API.

- -

The seed sources used are specified at the time OpenSSL is configured for building using the --with-rand-seed= option. By default, operating system randomness sources are used.

- -

Identity

- -

"SEED-SRC" is the name for this implementation; it can be used with the EVP_RAND_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -
-
"max_request" (OSSL_RAND_PARAM_MAX_REQUEST) <unsigned integer>
-
- -

These parameters work as described in "PARAMETERS" in EVP_RAND(3).

- -
-
- -

NOTES

- -

A context for the seed source can be obtained by calling:

- -
EVP_RAND *rand = EVP_RAND_fetch(NULL, "SEED-SRC", NULL);
-EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL);
- -

EXAMPLES

- -
EVP_RAND *rand;
-EVP_RAND_CTX *seed, *rctx;
-unsigned char bytes[100];
-OSSL_PARAM params[2], *p = params;
-unsigned int strength = 128;
-
-/* Create and instantiate a seed source */
-rand = EVP_RAND_fetch(NULL, "SEED-SRC", NULL);
-seed = EVP_RAND_CTX_new(rand, NULL);
-EVP_RAND_instantiate(seed, strength, 0, NULL, 0, NULL);
-EVP_RAND_free(rand);
-
-/* Feed this into a DRBG */
-rand = EVP_RAND_fetch(NULL, "CTR-DRBG", NULL);
-rctx = EVP_RAND_CTX_new(rand, seed);
-EVP_RAND_free(rand);
-
-/* Configure the DRBG */
-*p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER,
-                                        SN_aes_256_ctr, 0);
-*p = OSSL_PARAM_construct_end();
-EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params);
-
-EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0);
-
-EVP_RAND_CTX_free(rctx);
-EVP_RAND_CTX_free(seed);
- -

SEE ALSO

- -

EVP_RAND(3), "PARAMETERS" in EVP_RAND(3)

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-TEST-RAND.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND-TEST-RAND.html deleted file mode 100644 index 7be23c75..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND-TEST-RAND.html +++ /dev/null @@ -1,175 +0,0 @@ - - - - -EVP_RAND-TEST-RAND - - - - - - - - - - -

NAME

- -

EVP_RAND-TEST-RAND - The test EVP_RAND implementation

- -

DESCRIPTION

- -

Support for a test generator through the EVP_RAND API. This generator is for test purposes only, it does not generate random numbers.

- -

Identity

- -

"TEST-RAND" is the name for this implementation; it can be used with the EVP_RAND_fetch() function.

- -

Supported parameters

- -

The supported parameters are:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -
-
"fips-indicator" (OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

These parameter works as described in "PARAMETERS" in EVP_RAND(3).

- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -
-
"reseed_requests" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -
-
"reseed_time_interval" (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) <integer>
-
- -
-
"max_request" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -
-
"min_entropylen" (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) <unsigned integer>
-
- -
-
"max_entropylen" (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) <unsigned integer>
-
- -
-
"min_noncelen" (OSSL_DRBG_PARAM_MIN_NONCELEN) <unsigned integer>
-
- -
-
"max_noncelen" (OSSL_DRBG_PARAM_MAX_NONCELEN) <unsigned integer>
-
- -
-
"max_perslen" (OSSL_DRBG_PARAM_MAX_PERSLEN) <unsigned integer>
-
- -
-
"max_adinlen" (OSSL_DRBG_PARAM_MAX_ADINLEN) <unsigned integer>
-
- -
-
"reseed_counter" (OSSL_DRBG_PARAM_RESEED_COUNTER) <unsigned integer>
-
- -

These parameters work as described in "PARAMETERS" in EVP_RAND(3), except that they can all be set as well as read.

- -
-
"test_entropy" (OSSL_RAND_PARAM_TEST_ENTROPY) <octet string>
-
- -

Sets the bytes returned when the test generator is sent an entropy request. The current position is remembered across generate calls. If there are insufficient data present to satisfy a call, an error is returned.

- -
-
"test_nonce" (OSSL_RAND_PARAM_TEST_NONCE) <octet string>
-
- -

Sets the bytes returned when the test generator is sent a nonce request. Each nonce request will return all of the bytes.

- -
-
"generate" (OSSL_RAND_PARAM_GENERATE) <integer>
-
- -

If this parameter is zero, it will only emit the nonce and entropy data supplied via the aforementioned parameters. Otherwise, low quality non-cryptographic pseudorandom output is produced. This parameter defaults to zero.

- -
-
- -

NOTES

- -

A context for a test generator can be obtained by calling:

- -
EVP_RAND *rand = EVP_RAND_fetch(NULL, "TEST-RAND", NULL);
-EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL);
- -

EXAMPLES

- -
EVP_RAND *rand;
-EVP_RAND_CTX *rctx;
-unsigned char bytes[100];
-OSSL_PARAM params[4], *p = params;
-unsigned char entropy[1000] = { ... };
-unsigned char nonce[20] = { ... };
-unsigned int strength = 48;
-
-rand = EVP_RAND_fetch(NULL, "TEST-RAND", NULL);
-rctx = EVP_RAND_CTX_new(rand, NULL);
-EVP_RAND_free(rand);
-
-*p++ = OSSL_PARAM_construct_uint(OSSL_RAND_PARAM_STRENGTH, &strength);
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY,
-                                         entropy, sizeof(entropy));
-*p++ = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_NONCE,
-                                         nonce, sizeof(nonce));
-*p = OSSL_PARAM_construct_end();
-EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params);
-
-EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0);
-
-EVP_RAND_CTX_free(rctx);
- -

SEE ALSO

- -

EVP_RAND(3), "PARAMETERS" in EVP_RAND(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_RAND.html b/openssl-install/share/doc/openssl/html/man7/EVP_RAND.html deleted file mode 100644 index 3c3d50c2..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_RAND.html +++ /dev/null @@ -1,234 +0,0 @@ - - - - -EVP_RAND - - - - - - - - - - -

NAME

- -

EVP_RAND - the random bit generator

- -

SYNOPSIS

- -
#include <openssl/evp.h>
-#include <rand.h>
- -

DESCRIPTION

- -

The default OpenSSL RAND method is based on the EVP_RAND classes to provide non-deterministic inputs to other cryptographic algorithms.

- -

While the RAND API is the 'frontend' which is intended to be used by application developers for obtaining random bytes, the EVP_RAND API serves as the 'backend', connecting the former with the operating systems's entropy sources and providing access to deterministic random bit generators (DRBG) and their configuration parameters. A DRBG is a certain type of cryptographically-secure pseudo-random number generator (CSPRNG), which is described in [NIST SP 800-90A Rev. 1].

- -

Disclaimer

- -

Unless you have very specific requirements for your random generator, it is in general not necessary to utilize the EVP_RAND API directly. The usual way to obtain random bytes is to use RAND_bytes(3) or RAND_priv_bytes(3), see also RAND(7).

- -

Typical Use Cases

- -

Typical examples for such special use cases are the following:

- - - -

EVP_RAND CHAINING

- -

An EVP_RAND instance can be used as the entropy source of another EVP_RAND instance, provided it has itself access to a valid entropy source. The EVP_RAND instance which acts as entropy source is called the parent, the other instance the child. Typically, the child will be a DRBG because it does not make sense for the child to be an entropy source.

- -

This is called chaining. A chained EVP_RAND instance is created by passing a pointer to the parent EVP_RAND_CTX as argument to the EVP_RAND_CTX_new() call. It is possible to create chains of more than two DRBG in a row. It is also possible to use any EVP_RAND_CTX class as the parent, however, only a live entropy source may ignore and not use its parent.

- -

THE THREE SHARED DRBG INSTANCES

- -

Currently, there are three shared DRBG instances, the <primary>, <public>, and <private> DRBG. While the <primary> DRBG is a single global instance, the <public> and <private> DRBG are created per thread and accessed through thread-local storage.

- -

By default, the functions RAND_bytes(3) and RAND_priv_bytes(3) use the thread-local <public> and <private> DRBG instance, respectively.

- -

The <primary> DRBG instance

- -

The <primary> DRBG is not used directly by the application, only for reseeding the two other two DRBG instances. It reseeds itself by obtaining randomness either from os entropy sources or by consuming randomness which was added previously by RAND_add(3).

- -

The <public> DRBG instance

- -

This instance is used per default by RAND_bytes(3).

- -

The <private> DRBG instance

- -

This instance is used per default by RAND_priv_bytes(3)

- -

LOCKING

- -

The <primary> DRBG is intended to be accessed concurrently for reseeding by its child DRBG instances. The necessary locking is done internally. It is not thread-safe to access the <primary> DRBG directly via the EVP_RAND interface. The <public> and <private> DRBG are thread-local, i.e. there is an instance of each per thread. So they can safely be accessed without locking via the EVP_RAND interface.

- -

Pointers to these DRBG instances can be obtained using RAND_get0_primary(), RAND_get0_public() and RAND_get0_private(), respectively. Note that it is not allowed to store a pointer to one of the thread-local DRBG instances in a variable or other memory location where it will be accessed and used by multiple threads.

- -

All other DRBG instances created by an application don't support locking, because they are intended to be used by a single thread. Instead of accessing a single DRBG instance concurrently from different threads, it is recommended to instantiate a separate DRBG instance per thread. Using the <primary> DRBG as entropy source for multiple DRBG instances on different threads is thread-safe, because the DRBG instance will lock the <primary> DRBG automatically for obtaining random input.

- -

THE OVERALL PICTURE

- -

The following picture gives an overview over how the DRBG instances work together and are being used.

- -
           +--------------------+
-           | os entropy sources |
-           +--------------------+
-                    |
-                    v           +-----------------------------+
- RAND_add() ==> <primary>     <-| shared DRBG (with locking)  |
-                  /   \         +-----------------------------+
-                 /     \              +---------------------------+
-          <public>     <private>   <- | per-thread DRBG instances |
-             |             |          +---------------------------+
-             v             v
-           RAND_bytes()   RAND_priv_bytes()
-                |               ^
-                |               |
-+------------------+      +------------------------------------+
-| general purpose  |      | used for secrets like session keys |
-| random generator |      | and private keys for certificates  |
-+------------------+      +------------------------------------+
- -

The usual way to obtain random bytes is to call RAND_bytes(...) or RAND_priv_bytes(...). These calls are roughly equivalent to calling EVP_RAND_generate(<public>, ...) and EVP_RAND_generate(<private>, ...), respectively.

- -

RESEEDING

- -

A DRBG instance seeds itself automatically, pulling random input from its entropy source. The entropy source can be either a trusted operating system entropy source, or another DRBG with access to such a source.

- -

Automatic reseeding occurs after a predefined number of generate requests. The selection of the trusted entropy sources is configured at build time using the --with-rand-seed option. The following sections explain the reseeding process in more detail.

- -

Automatic Reseeding

- -

Before satisfying a generate request (EVP_RAND_generate(3)), the DRBG reseeds itself automatically, if one of the following conditions holds:

- -

- the DRBG was not instantiated (=seeded) yet or has been uninstantiated.

- -

- the number of generate requests since the last reseeding exceeds a certain threshold, the so called reseed_interval. This behaviour can be disabled by setting the reseed_interval to 0.

- -

- the time elapsed since the last reseeding exceeds a certain time interval, the so called reseed_time_interval. This can be disabled by setting the reseed_time_interval to 0.

- -

- the DRBG is in an error state.

- -

Note: An error state is entered if the entropy source fails while the DRBG is seeding or reseeding. The last case ensures that the DRBG automatically recovers from the error as soon as the entropy source is available again.

- -

Manual Reseeding

- -

In addition to automatic reseeding, the caller can request an immediate reseeding of the DRBG with fresh entropy by setting the prediction resistance parameter to 1 when calling EVP_RAND_generate(3).

- -

The document [NIST SP 800-90C] describes prediction resistance requests in detail and imposes strict conditions on the entropy sources that are approved for providing prediction resistance. A request for prediction resistance can only be satisfied by pulling fresh entropy from a live entropy source (section 5.5.2 of [NIST SP 800-90C]). It is up to the user to ensure that a live entropy source is configured and is being used.

- -

For the three shared DRBGs (and only for these) there is another way to reseed them manually: If RAND_add(3) is called with a positive randomness argument (or RAND_seed(3)), then this will immediately reseed the <primary> DRBG. The <public> and <private> DRBG will detect this on their next generate call and reseed, pulling randomness from <primary>.

- -

The last feature has been added to support the common practice used with previous OpenSSL versions to call RAND_add() before calling RAND_bytes().

- -

Entropy Input and Additional Data

- -

The DRBG distinguishes two different types of random input: entropy, which comes from a trusted source, and additional input', which can optionally be added by the user and is considered untrusted. It is possible to add additional input not only during reseeding, but also for every generate request.

- -

Configuring the Random Seed Source

- -

In most cases OpenSSL will automatically choose a suitable seed source for automatically seeding and reseeding its <primary> DRBG. The default seed source can be configured when OpenSSL is compiled by setting -DOPENSSL_DEFAULT_SEED_SRC=SEED-SRC. If not set then "SEED-SRC" is used. One can specify a third-party provider seed-source, or -DOPENSSL_DEFAULT_SEED_SRC=JITTER if available.

- -

In some cases however, it will be necessary to explicitly specify a seed source used by "SEED-SRC" during configuration, using the --with-rand-seed option. For more information, see the INSTALL instructions. There are also operating systems where no seed source is available and automatic reseeding is disabled by default.

- -

The following two sections describe the reseeding process of the primary DRBG, depending on whether automatic reseeding is available or not.

- -

Reseeding the primary DRBG with automatic seeding enabled

- -

Calling RAND_poll() or RAND_add() is not necessary, because the DRBG pulls the necessary entropy from its source automatically. However, both calls are permitted, and do reseed the RNG.

- -

RAND_add() can be used to add both kinds of random input, depending on the value of the randomness argument:

- -
- -
randomness == 0:
-
- -

The random bytes are mixed as additional input into the current state of the DRBG. Mixing in additional input is not considered a full reseeding, hence the reseed counter is not reset.

- -
-
randomness > 0:
-
- -

The random bytes are used as entropy input for a full reseeding (resp. reinstantiation) if the DRBG is instantiated (resp. uninstantiated or in an error state). The number of random bits required for reseeding is determined by the security strength of the DRBG. Currently it defaults to 256 bits (32 bytes). It is possible to provide less randomness than required. In this case the missing randomness will be obtained by pulling random input from the trusted entropy sources.

- -
-
- -

NOTE: Manual reseeding is *not allowed* in FIPS mode, because [NIST SP-800-90Ar1] mandates that entropy *shall not* be provided by the consuming application for instantiation (Section 9.1) or reseeding (Section 9.2). For that reason, the randomness argument is ignored and the random bytes provided by the RAND_add(3) and RAND_seed(3) calls are treated as additional data.

- -

Reseeding the primary DRBG with automatic seeding disabled

- -

Calling RAND_poll() will always fail.

- -

RAND_add() needs to be called for initial seeding and periodic reseeding. At least 48 bytes (384 bits) of randomness have to be provided, otherwise the (re-)seeding of the DRBG will fail. This corresponds to one and a half times the security strength of the DRBG. The extra half is used for the nonce during instantiation.

- -

More precisely, the number of bytes needed for seeding depend on the security strength of the DRBG, which is set to 256 by default.

- -

SEE ALSO

- -

RAND(7), EVP_RAND(3)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-DSA.html b/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-DSA.html deleted file mode 100644 index 63a2a5cf..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-DSA.html +++ /dev/null @@ -1,170 +0,0 @@ - - - - -EVP_SIGNATURE-DSA - - - - - - - - - - -

NAME

- -

EVP_SIGNATURE-DSA - The EVP_PKEY DSA signature implementation

- -

DESCRIPTION

- -

Support for computing DSA signatures. The signature produced with EVP_PKEY_sign(3) is DER encoded ASN.1 in the form described in RFC 3279, section 2.2.2. See EVP_PKEY-DSA(7) for information related to DSA keys.

- -

As part of FIPS 140-3 DSA is not longer FIPS approved for key generation and signature validation, but is still allowed for signature verification.

- -

Algorithm Names

- -

In this list, names are grouped together to signify that they are the same algorithm having multiple names. This also includes the OID in canonical decimal form (which means that they are possible to fetch if the caller has a mere OID which came out in this form after a call to OBJ_obj2txt(3)).

- -
- -
"DSA", "dsaEncryption", "1.2.840.10040.4.1"
-
- -

The base signature algorithm, supported explicitly fetched with EVP_PKEY_sign_init_ex2(3), and implicitly fetched (through EC keys) with EVP_DigestSignInit(3) and EVP_DigestVerifyInit(3).

- -

It can't be used with EVP_PKEY_sign_message_init(3)

- -
-
"DSA-SHA1", "DSA-SHA-1", "dsaWithSHA1", "1.2.840.10040.4.3"
-
- -
-
"DSA-SHA2-224", "DSA-SHA224", "dsa_with_SHA224", "2.16.840.1.101.3.4.3.1"
-
- -
-
"DSA-SHA2-256", "DSA-SHA256", "dsa_with_SHA256", "2.16.840.1.101.3.4.3.2"
-
- -
-
"DSA-SHA2-384", "DSA-SHA384", "dsa_with_SHA384", "id-dsa-with-sha384", "1.2.840.1.101.3.4.3.3"
-
- -
-
"DSA-SHA2-512", "DSA-SHA512", "dsa_with_SHA512", "id-dsa-with-sha512", "1.2.840.1.101.3.4.3.4"
-
- -
-
"DSA-SHA3-224", "dsa_with_SHA3-224", "id-dsa-with-sha3-224", "2.16.840.1.101.3.4.3.5"
-
- -
-
"DSA-SHA3-256", "dsa_with_SHA3-256", "id-dsa-with-sha3-256", "2.16.840.1.101.3.4.3.6"
-
- -
-
"DSA-SHA3-384", "dsa_with_SHA3-384", "id-dsa-with-sha3-384", "2.16.840.1.101.3.4.3.7"
-
- -
-
"DSA-SHA3-512", "dsa_with_SHA3-512", "id-dsa-with-sha3-512", "2.16.840.1.101.3.4.3.8"
-
- -

DSA signature schemes with diverse message digest algorithms. They are all supported explicitly fetched with EVP_PKEY_sign_init_ex2(3) and EVP_PKEY_sign_message_init(3).

- -
-
- -

Signature Parameters

- -

The following signature parameters can be set using EVP_PKEY_CTX_set_params(). This may be called after EVP_PKEY_sign_init() or EVP_PKEY_verify_init(), and before calling EVP_PKEY_sign() or EVP_PKEY_verify(). They may also be set using EVP_PKEY_sign_init_ex() or EVP_PKEY_verify_init_ex().

- -
- -
"digest" (OSSL_SIGNATURE_PARAM_DIGEST) <UTF8 string>
-
- -
-
"properties" (OSSL_SIGNATURE_PARAM_PROPERTIES) <UTF8 string>
-
- -

These two are not supported with the DSA signature schemes that already include a message digest algorithm, See "Algorithm Names" above.

- -
-
"nonce-type" (OSSL_SIGNATURE_PARAM_NONCE_TYPE) <unsigned integer>
-
- -
-
"key-check" (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) <integer>
-
- -
-
"digest-check" (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -
-
"sign-check" (OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK) <int>
-
- -

The settable parameters are described in provider-signature(7).

- -
-
- -

The following signature parameters can be retrieved using EVP_PKEY_CTX_get_params().

- -
- -
"algorithm-id" (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) <octet string>
-
- -
-
"digest" (OSSL_SIGNATURE_PARAM_DIGEST) <UTF8 string>
-
- -
-
"nonce-type" (OSSL_SIGNATURE_PARAM_NONCE_TYPE) <unsigned integer>
-
- -
-
"fips-indicator" (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

The gettable parameters are described in provider-signature(7).

- -
-
- -

SEE ALSO

- -

EVP_PKEY_CTX_set_params(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), provider-signature(7),

- -

HISTORY

- -

DSA Key generation and signature generation are no longer FIPS approved in OpenSSL 3.4. See "FIPS indicators" in fips_module(7) for more information.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ECDSA.html b/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ECDSA.html deleted file mode 100644 index 0c8dbe82..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ECDSA.html +++ /dev/null @@ -1,163 +0,0 @@ - - - - -EVP_SIGNATURE-ECDSA - - - - - - - - - - -

NAME

- -

EVP_SIGNATURE-ECDSA - The EVP_PKEY ECDSA signature implementation.

- -

DESCRIPTION

- -

Support for computing ECDSA signatures. See EVP_PKEY-EC(7) for information related to EC keys.

- -

Algorithm Names

- -

In this list, names are grouped together to signify that they are the same algorithm having multiple names. This also includes the OID in canonical decimal form (which means that they are possible to fetch if the caller has a mere OID which came out in this form after a call to OBJ_obj2txt(3)).

- -
- -
"ECDSA"
-
- -

The base signature algorithm, supported explicitly fetched with EVP_PKEY_sign_init_ex2(3), and implicitly fetched (through EC keys) with EVP_DigestSignInit(3) and EVP_DigestVerifyInit(3).

- -

It can't be used with EVP_PKEY_sign_message_init(3)

- -
-
"ECDSA-SHA1", "ECDSA-SHA-1", "ecdsa-with-SHA1", "1.2.840.10045.4.1"
-
- -
-
"ECDSA-SHA2-224", "ECDSA-SHA224", "ecdsa-with-SHA224", "1.2.840.10045.4.3.1"
-
- -
-
"ECDSA-SHA2-256", "ECDSA-SHA256", "ecdsa-with-SHA256", "1.2.840.10045.4.3.2"
-
- -
-
"ECDSA-SHA2-384", "ECDSA-SHA384", "ecdsa-with-SHA384", "1.2.840.10045.4.3.3"
-
- -
-
"ECDSA-SHA2-512", "ECDSA-SHA512", "ecdsa-with-SHA512", "1.2.840.10045.4.3.4"
-
- -
-
"ECDSA-SHA3-224", "ecdsa_with_SHA3-224", "id-ecdsa-with-sha3-224", "2.16.840.1.101.3.4.3.9"
-
- -
-
"ECDSA-SHA3-256", "ecdsa_with_SHA3-256", "id-ecdsa-with-sha3-256", "2.16.840.1.101.3.4.3.10"
-
- -
-
"ECDSA-SHA3-384", "ecdsa_with_SHA3-384", "id-ecdsa-with-sha3-384", "2.16.840.1.101.3.4.3.11"
-
- -
-
"ECDSA-SHA3-512", "ecdsa_with_SHA3-512", "id-ecdsa-with-sha3-512", "2.16.840.1.101.3.4.3.12"
-
- -

ECDSA signature schemes with diverse message digest algorithms. They are all supported explicitly fetched with EVP_PKEY_sign_init_ex2(3) and EVP_PKEY_sign_message_init(3).

- -
-
- -

ECDSA Signature Parameters

- -

The following signature parameters can be set using EVP_PKEY_CTX_set_params(). This may be called after EVP_PKEY_sign_init() or EVP_PKEY_verify_init(), and before calling EVP_PKEY_sign() or EVP_PKEY_verify().

- -
- -
"digest" (OSSL_SIGNATURE_PARAM_DIGEST) <UTF8 string>
-
- -
-
"properties" (OSSL_SIGNATURE_PARAM_PROPERTIES) <UTF8 string>
-
- -

These two are not supported with the ECDSA signature schemes that already include a message digest algorithm, See "Algorithm Names" above.

- -
-
"nonce-type" (OSSL_SIGNATURE_PARAM_NONCE_TYPE) <unsigned integer>
-
- -
-
"key-check" (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) <integer>
-
- -
-
"digest-check" (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

These parameters are described in provider-signature(7).

- -
-
- -

The following signature parameters can be retrieved using EVP_PKEY_CTX_get_params().

- -
- -
"algorithm-id" (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) <octet string>
-
- -
-
"digest" (OSSL_SIGNATURE_PARAM_DIGEST) <UTF8 string>
-
- -
-
"nonce-type" (OSSL_SIGNATURE_PARAM_NONCE_TYPE) <unsigned integer>
-
- -
-
"fips-indicator" (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"verify-message" (OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE <integer>
-
- -

The parameters are described in provider-signature(7).

- -
-
- -

SEE ALSO

- -

EVP_PKEY_CTX_set_params(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), provider-signature(7),

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ED25519.html b/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ED25519.html deleted file mode 100644 index 91cde3f2..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-ED25519.html +++ /dev/null @@ -1,161 +0,0 @@ - - - - -EVP_SIGNATURE-ED25519 - - - - - - - - - - -

NAME

- -

EVP_SIGNATURE-ED25519, EVP_SIGNATURE-ED448, Ed25519, Ed448 - EVP_PKEY Ed25519 and Ed448 support

- -

DESCRIPTION

- -

The Ed25519 and Ed448 EVP_PKEY implementation supports key generation, one-shot digest-sign and digest-verify using the EdDSA signature schemes described in RFC 8032. It has associated private and public key formats compatible with RFC 8410.

- -

EdDSA Instances

- -

RFC 8032 describes five EdDSA instances: Ed25519, Ed25519ctx, Ed25519ph, Ed448, Ed448ph.

- -

The instances Ed25519, Ed25519ctx, Ed448 are referred to as PureEdDSA schemes. For these three instances, the sign and verify procedures require access to the complete message (not a digest of the message).

- -

The instances Ed25519ph, Ed448ph are referred to as HashEdDSA schemes. For these two instances, the sign and verify procedures do not require access to the complete message; they operate on a hash of the message. For Ed25519ph, the hash function is SHA512. For Ed448ph, the hash function is SHAKE256 with an output length of 512 bits.

- -

The instances Ed25519ctx, Ed25519ph, Ed448, Ed448ph accept an optional context-string as input to sign and verify operations (and for Ed25519ctx, the context-string must be nonempty). For the Ed25519 instance, a nonempty context-string is not permitted.

- -

These instances can be specified as signature parameters when using EVP_DigestSignInit(3) and EVP_DigestVerifyInit(3), see "ED25519 and ED448 Signature Parameters" below.

- -

These instances are also explicitly fetchable as algorithms using EVP_SIGNATURE_fetch(3), which can be used with EVP_PKEY_sign_init_ex2(3), EVP_PKEY_verify_init_ex2(3), EVP_PKEY_sign_message_init(3) and EVP_PKEY_verify_message_init(3).

- -

ED25519 and ED448 Signature Parameters

- -

Two parameters can be set during signing or verification: the EdDSA instance name and the context-string value. They can be set by passing an OSSL_PARAM array to EVP_DigestSignInit_ex().

- - - -

Both of these parameters are optional.

- -

When using EVP_DigestSignInit(3) or EVP_DigestVerifyInit(3), the signature algorithm is derived from the key type name. The key type name ("Ed25519" or "Ed448") is also the default for the instance, but this can be changed with the "instance" parameter.

- -

Note that a message digest name must NOT be specified when signing or verifying.

- -

When using EVP_PKEY_sign_init_ex2(3), EVP_PKEY_verify_init_ex2(3), EVP_PKEY_sign_message_init(3) or EVP_PKEY_verify_message_init(3), the instance is the explicit signature algorithm name, and may not be changed (trying to give one with the "instance" parameter is therefore an error).

- -

If a context-string is not specified, then an empty context-string is used.

- -

See EVP_PKEY-X25519(7) for information related to X25519 and X448 keys.

- -

The following signature parameters can be retrieved using EVP_PKEY_CTX_get_params().

- - - -

The parameters are described in provider-signature(7).

- -

NOTES

- -

The PureEdDSA instances do not support the streaming mechanism of other signature algorithms using, for example, EVP_DigestUpdate(). The message to sign or verify must be passed using the one-shot EVP_DigestSign() and EVP_DigestVerify() functions.

- -

The HashEdDSA instances do not yet support the streaming mechanisms (so the one-shot functions must be used with HashEdDSA as well).

- -

When calling EVP_DigestSignInit() or EVP_DigestVerifyInit(), the digest type parameter MUST be set to NULL.

- -

Applications wishing to sign certificates (or other structures such as CRLs or certificate requests) using Ed25519 or Ed448 can either use X509_sign() or X509_sign_ctx() in the usual way.

- -

Ed25519 or Ed448 private keys can be set directly using EVP_PKEY_new_raw_private_key(3) or loaded from a PKCS#8 private key file using PEM_read_bio_PrivateKey(3) (or similar function). Completely new keys can also be generated (see the example below). Setting a private key also sets the associated public key.

- -

Ed25519 or Ed448 public keys can be set directly using EVP_PKEY_new_raw_public_key(3) or loaded from a SubjectPublicKeyInfo structure in a PEM file using PEM_read_bio_PUBKEY(3) (or similar function).

- -

Ed25519 and Ed448 can be tested with the openssl-speed(1) application since version 1.1.1. Valid algorithm names are ed25519, ed448 and eddsa. If eddsa is specified, then both Ed25519 and Ed448 are benchmarked.

- -

EXAMPLES

- -

To sign a message using an ED25519 EVP_PKEY structure:

- -
void do_sign(EVP_PKEY *ed_key, unsigned char *msg, size_t msg_len)
-{
-    size_t sig_len;
-    unsigned char *sig = NULL;
-    EVP_MD_CTX *md_ctx = EVP_MD_CTX_new();
-
-    const OSSL_PARAM params[] = {
-        OSSL_PARAM_utf8_string ("instance", "Ed25519ctx", 10),
-        OSSL_PARAM_octet_string("context-string", (unsigned char *)"A protocol defined context string", 33),
-        OSSL_PARAM_END
-    };
-
-    /* The input "params" is not needed if default options are acceptable.
-       Use NULL in place of "params" in that case. */
-    EVP_DigestSignInit_ex(md_ctx, NULL, NULL, NULL, NULL, ed_key, params);
-    /* Calculate the required size for the signature by passing a NULL buffer. */
-    EVP_DigestSign(md_ctx, NULL, &sig_len, msg, msg_len);
-    sig = OPENSSL_zalloc(sig_len);
-
-    EVP_DigestSign(md_ctx, sig, &sig_len, msg, msg_len);
-    ...
-    OPENSSL_free(sig);
-    EVP_MD_CTX_free(md_ctx);
-}
- -

SEE ALSO

- -

EVP_PKEY-X25519(7) provider-signature(7), EVP_DigestSignInit(3), EVP_DigestVerifyInit(3),

- -

COPYRIGHT

- -

Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-HMAC.html b/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-HMAC.html deleted file mode 100644 index 3251a2a1..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-HMAC.html +++ /dev/null @@ -1,50 +0,0 @@ - - - - -EVP_SIGNATURE-HMAC - - - - - - - - - - -

NAME

- -

EVP_SIGNATURE-HMAC, EVP_SIGNATURE-Siphash, EVP_SIGNATURE-Poly1305, EVP_SIGNATURE-CMAC - The legacy EVP_PKEY MAC signature implementations

- -

DESCRIPTION

- -

The algorithms described here have legacy support for creating MACs using EVP_DigestSignInit(3) and related functions. This is not the preferred way of creating MACs. Instead you should use the newer EVP_MAC_init(3) functions. This mechanism is provided for backwards compatibility with older versions of OpenSSL.

- -

The same signature parameters can be set using EVP_PKEY_CTX_set_params() as can be set via EVP_MAC_CTX_set_params() for the underlying EVP_MAC. See EVP_MAC-HMAC(7), EVP_MAC-Siphash(7), EVP_MAC-Poly1305(7) and EVP_MAC-CMAC(7) for details.

- -
See L<EVP_PKEY-HMAC(7)>, L<EVP_PKEY-Siphash(7)>, L<EVP_PKEY-Poly1305(7)> or
-L<EVP_PKEY-CMAC(7)> for details about parameters that are supported during the
-creation of an EVP_PKEY.
- -

SEE ALSO

- -

EVP_MAC_init(3), EVP_DigestSignInit(3), EVP_PKEY-HMAC(7), EVP_PKEY-Siphash(7), EVP_PKEY-Poly1305(7), EVP_PKEY-CMAC(7), EVP_MAC-HMAC(7), EVP_MAC-Siphash(7), EVP_MAC-Poly1305(7), EVP_MAC-CMAC(7), provider-signature(7),

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-RSA.html b/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-RSA.html deleted file mode 100644 index f1dc19c2..00000000 --- a/openssl-install/share/doc/openssl/html/man7/EVP_SIGNATURE-RSA.html +++ /dev/null @@ -1,273 +0,0 @@ - - - - -EVP_SIGNATURE-RSA - - - - - - - - - - -

NAME

- -

EVP_SIGNATURE-RSA - The EVP_PKEY RSA signature implementation

- -

DESCRIPTION

- -

Support for computing RSA signatures. See EVP_PKEY-RSA(7) for information related to RSA keys.

- -

Algorithm Names

- -

In this list, names are grouped together to signify that they are the same algorithm having multiple names. This also includes the OID in canonical decimal form (which means that they are possible to fetch if the caller has a mere OID which came out in this form after a call to OBJ_obj2txt(3)).

- -
- -
"RSA", "rsaEncryption", "1.2.840.113549.1.1.1"
-
- -

The base signature algorithm, supported explicitly fetched with EVP_PKEY_sign_init_ex2(3), and implicitly fetched (through RSA keys) with EVP_DigestSignInit(3) and EVP_DigestVerifyInit(3).

- -

It can't be used with EVP_PKEY_sign_message_init(3)

- -
-
"RSA-RIPEMD160", "ripemd160WithRSA", "1.3.36.3.3.1.2"
-
- -
-
"RSA-SHA2-256", "RSA-SHA256", "sha256WithRSAEncryption", "1.2.840.113549.1.1.11"
-
- -
-
"RSA-SHA2-384", "RSA-SHA384", "sha384WithRSAEncryption", "1.2.840.113549.1.1.12"
-
- -
-
"RSA-SHA2-512", "RSA-SHA512", "sha512WithRSAEncryption", "1.2.840.113549.1.1.13"
-
- -
-
"RSA-SHA2-224", "RSA-SHA224", "sha224WithRSAEncryption", "1.2.840.113549.1.1.14"
-
- -
-
"RSA-SHA2-512/224", "RSA-SHA512-224", "sha512-224WithRSAEncryption", "1.2.840.113549.1.1.15"
-
- -
-
"RSA-SHA2-512/256", "RSA-SHA512-256", "sha512-256WithRSAEncryption", "1.2.840.113549.1.1.16"
-
- -
-
"RSA-SHA3-224", "id-rsassa-pkcs1-v1_5-with-sha3-224", "2.16.840.1.101.3.4.3.13"
-
- -
-
"RSA-SHA3-256", "id-rsassa-pkcs1-v1_5-with-sha3-256", "2.16.840.1.101.3.4.3.14"
-
- -
-
"RSA-SHA3-384", "id-rsassa-pkcs1-v1_5-with-sha3-384", "2.16.840.1.101.3.4.3.15"
-
- -
-
"RSA-SHA3-512", "id-rsassa-pkcs1-v1_5-with-sha3-512", "2.16.840.1.101.3.4.3.16"
-
- -
-
"RSA-SM3", "sm3WithRSAEncryption", "1.2.156.10197.1.504"
-
- -

PKCS#1 v1.5 RSA signature schemes with diverse message digest algorithms. They are all supported explicitly fetched with EVP_PKEY_sign_init_ex2(3) and EVP_PKEY_sign_message_init(3). They are all pre-set to use the pad mode "pkcs1". This cannot be changed.

- -
-
- -

Signature Parameters

- -

The following signature parameters can be set using EVP_PKEY_CTX_set_params(). This may be called after EVP_PKEY_sign_init() or EVP_PKEY_verify_init(), and before calling EVP_PKEY_sign() or EVP_PKEY_verify(). They may also be set using EVP_PKEY_sign_init_ex() or EVP_PKEY_verify_init_ex().

- -
- -
"digest" (OSSL_SIGNATURE_PARAM_DIGEST) <UTF8 string>
-
- -
-
"properties" (OSSL_SIGNATURE_PARAM_PROPERTIES) <UTF8 string>
-
- -

These are not supported with the RSA signature schemes that already include a message digest algorithm, See "Algorithm Names" above.

- -

These common parameters are described in provider-signature(7).

- -
-
"pad-mode" (OSSL_SIGNATURE_PARAM_PAD_MODE) <UTF8 string>
-
- -

The type of padding to be used. Its value can be one of the following:

- -
- -
"none" (OSSL_PKEY_RSA_PAD_MODE_NONE)
-
- -
-
"pkcs1" (OSSL_PKEY_RSA_PAD_MODE_PKCSV15)
-
- -
-
"x931" (OSSL_PKEY_RSA_PAD_MODE_X931)
-
- -

This padding mode is no longer supported by the FIPS provider for signature generation, but may be used for signature verification for legacy use cases. (This is a FIPS 140-3 requirement)

- -
-
"pss" (OSSL_PKEY_RSA_PAD_MODE_PSS)
-
- -
-
- -
-
"mgf1-digest" (OSSL_SIGNATURE_PARAM_MGF1_DIGEST) <UTF8 string>
-
- -

The digest algorithm name to use for the maskGenAlgorithm used by "pss" mode.

- -
-
"mgf1-properties" (OSSL_SIGNATURE_PARAM_MGF1_PROPERTIES) <UTF8 string>
-
- -

Sets the name of the property query associated with the "mgf1-digest" algorithm. NULL is used if this optional value is not set.

- -
-
"saltlen" (OSSL_SIGNATURE_PARAM_PSS_SALTLEN) <integer> or <UTF8 string>
-
- -

The "pss" mode minimum salt length. The value can either be an integer, a string value representing a number or one of the following string values:

- -
- -
"digest" (OSSL_PKEY_RSA_PSS_SALT_LEN_DIGEST)
-
- -

Use the same length as the digest size.

- -
-
"max" (OSSL_PKEY_RSA_PSS_SALT_LEN_MAX)
-
- -

Use the maximum salt length.

- -
-
"auto" (OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO)
-
- -

Auto detect the salt length.

- -
-
"auto-digestmax" (OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO_DIGEST_MAX)
-
- -

Auto detect the salt length when verifying. Maximize the salt length up to the digest size when signing to comply with FIPS 186-4 section 5.5.

- -
-
- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"key-check" (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) <integer>
-
- -
-
"digest-check" (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -
-
"sign-x931-pad-check" (OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK) <integer>
-
- -

These parameters are described in provider-signature(7).

- -
-
"rsa-pss-saltlen-check" (OSSL_SIGNATURE_PARAM_FIPS_RSA_PSS_SALTLEN_CHECK) <integer>
-
- -

The default value of 1 causes an error during signature generation or verification if salt length (OSSL_SIGNATURE_PARAM_PSS_SALTLEN) is not between zero and the output block size of the digest function (inclusive). Setting this to zero will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

The following signature parameters can be retrieved using EVP_PKEY_CTX_get_params().

- -
- -
"algorithm-id" (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) <octet string>
-
- -
-
"fips-indicator" (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -
-
"verify-message" (OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE <integer>
-
- -

These common parameter are described in provider-signature(7).

- -
-
"digest" (OSSL_SIGNATURE_PARAM_DIGEST) <UTF8 string>
-
- -
-
"pad-mode" (OSSL_SIGNATURE_PARAM_PAD_MODE) <UTF8 string>
-
- -
-
"mgf1-digest" (OSSL_SIGNATURE_PARAM_MGF1_DIGEST) <UTF8 string>
-
- -
-
"saltlen" (OSSL_SIGNATURE_PARAM_PSS_SALTLEN) <integer> or <UTF8 string>
-
- -

These parameters are as described above.

- -
-
- -

SEE ALSO

- -

EVP_PKEY_CTX_set_params(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), provider-signature(7),

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-FIPS.html b/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-FIPS.html deleted file mode 100644 index 15b40539..00000000 --- a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-FIPS.html +++ /dev/null @@ -1,730 +0,0 @@ - - - - -OSSL_PROVIDER-FIPS - - - - - - - - - - -

NAME

- -

OSSL_PROVIDER-FIPS - OpenSSL FIPS provider

- -

DESCRIPTION

- -

The OpenSSL FIPS provider is a special provider that conforms to the Federal Information Processing Standards (FIPS) specified in FIPS 140-3. This 'module' contains an approved set of cryptographic algorithms that is validated by an accredited testing laboratory.

- -

Properties

- -

The implementations in this provider specifically have these properties defined:

- -
- -
"provider=fips"
-
- -
-
"fips=yes"
-
- -
-
- -

It may be used in a property query string with fetching functions such as EVP_MD_fetch(3) or EVP_CIPHER_fetch(3), as well as with other functions that take a property query string, such as EVP_PKEY_CTX_new_from_name(3).

- -

To be FIPS compliant, it is mandatory to include fips=yes as part of all property queries. This ensures that only FIPS approved implementations are used for cryptographic operations. The fips=yes query may also include other non-crypto support operations that are not in the FIPS provider, such as asymmetric key encoders, see "Asymmetric Key Management" in OSSL_PROVIDER-default(7).

- -

It is not mandatory to include provider=fips as part of your property query. Including provider=fips in your property query guarantees that the OpenSSL FIPS provider is used for cryptographic operations rather than other FIPS capable providers.

- -

Provider parameters

- -

See "Provider parameters" in provider-base(7) for a list of base parameters. Additionally the OpenSSL FIPS provider also supports the following gettable parameters:

- -
- -
"security-checks" (OSSL_OSSL_PROV_PARAM_SECURITY_CHECKS) <unsigned integer>
-
- -

For further information refer to the openssl-fipsinstall(1) option -no_security_checks.

- -
-
- -

OPERATIONS AND ALGORITHMS

- -

The OpenSSL FIPS provider supports these operations and algorithms:

- -

Hashing Algorithms / Message Digests

- -
- -
SHA1, see EVP_MD-SHA1(7)
-
- -
-
SHA2, see EVP_MD-SHA2(7)
-
- -
-
SHA3, see EVP_MD-SHA3(7)
-
- -
-
KECCAK-KMAC, see EVP_MD-KECCAK-KMAC(7)
-
- -
-
SHAKE, see EVP_MD-SHAKE(7)
-
- -
-
- -

Symmetric Ciphers

- -
- -
AES, see EVP_CIPHER-AES(7)
-
- -
-
3DES, see EVP_CIPHER-DES(7)
-
- -

This is an unapproved algorithm.

- -
-
- -

Message Authentication Code (MAC)

- -
- -
CMAC, see EVP_MAC-CMAC(7)
-
- -
-
GMAC, see EVP_MAC-GMAC(7)
-
- -
-
HMAC, see EVP_MAC-HMAC(7)
-
- -
-
KMAC, see EVP_MAC-KMAC(7)
-
- -
-
- -

Key Derivation Function (KDF)

- -
- -
HKDF, see EVP_KDF-HKDF(7)
-
- -
-
TLS13-KDF, see EVP_KDF-TLS13_KDF(7)
-
- -
-
SSKDF, see EVP_KDF-SS(7)
-
- -
-
PBKDF2, see EVP_KDF-PBKDF2(7)
-
- -
-
SSHKDF, see EVP_KDF-SSHKDF(7)
-
- -
-
TLS1-PRF, see EVP_KDF-TLS1_PRF(7)
-
- -
-
KBKDF, see EVP_KDF-KB(7)
-
- -
-
X942KDF-ASN1, see EVP_KDF-X942-ASN1(7)
-
- -
-
X942KDF-CONCAT, see EVP_KDF-X942-CONCAT(7)
-
- -
-
X963KDF, see EVP_KDF-X963(7)
-
- -
-
- -

Key Exchange

- -
- -
DH, see EVP_KEYEXCH-DH(7)
-
- -
-
ECDH, see EVP_KEYEXCH-ECDH(7)
-
- -
-
X25519, see EVP_KEYEXCH-X25519(7)
-
- -
-
X448, see EVP_KEYEXCH-X448(7)
-
- -
-
TLS1-PRF
-
- -
-
HKDF
-
- -
-
- -

Asymmetric Signature

- -
- -
RSA, see EVP_SIGNATURE-RSA(7)
-
- -

The X931 padding mode "OSSL_PKEY_RSA_PAD_MODE_X931" is no longer supported for signature generation, but may be used for verification for legacy use cases. (This is a FIPS 140-3 requirement)

- -
-
DSA, see EVP_SIGNATURE-DSA(7)
-
- -
-
ED25519, see EVP_SIGNATURE-ED25519(7)
-
- -
-
ED448, see EVP_SIGNATURE-ED448(7)
-
- -
-
ECDSA, see EVP_SIGNATURE-ECDSA(7)
-
- -
-
HMAC, see EVP_SIGNATURE-HMAC(7)
-
- -
-
CMAC, see EVP_SIGNATURE-CMAC(7)
-
- -
-
- -

Asymmetric Cipher

- -
- -
RSA, see EVP_ASYM_CIPHER-RSA(7)
-
- -
-
- -

Asymmetric Key Encapsulation

- -
- -
RSA, see EVP_KEM-RSA(7)
-
- -
-
- -

Asymmetric Key Management

- -
- -
DH, see EVP_KEYMGMT-DH(7)
-
- -
-
DHX, see EVP_KEYMGMT-DHX(7)
-
- -
-
DSA, see EVP_KEYMGMT-DSA(7)
-
- -
-
RSA, see EVP_KEYMGMT-RSA(7)
-
- -
-
RSA-PSS
-
- -
-
EC, see EVP_KEYMGMT-EC(7)
-
- -
-
X25519, see EVP_KEYMGMT-X25519(7)
-
- -

This is an unapproved algorithm.

- -
-
X448, see EVP_KEYMGMT-X448(7)
-
- -

This is an unapproved algorithm.

- -
-
ED25519, see EVP_KEYMGMT-ED25519(7)
-
- -

This is an unapproved algorithm.

- -
-
ED448, see EVP_KEYMGMT-ED448(7)
-
- -

This is an unapproved algorithm.

- -
-
TLS1-PRF
-
- -
-
HKDF
-
- -
-
HMAC, see EVP_KEYMGMT-HMAC(7)
-
- -
-
CMAC, see EVP_KEYMGMT-CMAC(7)
-
- -
-
- -

Random Number Generation

- -
- -
CRNG-TEST, see EVP_RAND-CRNG-TEST(7)
-
- -
-
CTR-DRBG, see EVP_RAND-CTR-DRBG(7)
-
- -
-
HASH-DRBG, see EVP_RAND-HASH-DRBG(7)
-
- -
-
HMAC-DRBG, see EVP_RAND-HMAC-DRBG(7)
-
- -
-
TEST-RAND, see EVP_RAND-TEST-RAND(7)
-
- -

TEST-RAND is an unapproved algorithm.

- -
-
- -

SELF TESTING

- -

One of the requirements for the FIPS module is self testing. An optional callback mechanism is available to return information to the user using OSSL_SELF_TEST_set_callback(3).

- -

The parameters passed to the callback are described in OSSL_SELF_TEST_new(3)

- -

The OpenSSL FIPS module uses the following mechanism to provide information about the self tests as they run. This is useful for debugging if a self test is failing. The callback also allows forcing any self test to fail, in order to check that it operates correctly on failure. Note that all self tests run even if a self test failure occurs.

- -

The FIPS module passes the following type(s) to OSSL_SELF_TEST_onbegin().

- -
- -
"Module_Integrity" (OSSL_SELF_TEST_TYPE_MODULE_INTEGRITY)
-
- -

Uses HMAC SHA256 on the module file to validate that the module has not been modified. The integrity value is compared to a value written to a configuration file during installation.

- -
-
"Install_Integrity" (OSSL_SELF_TEST_TYPE_INSTALL_INTEGRITY)
-
- -

Uses HMAC SHA256 on a fixed string to validate that the installation process has already been performed and the self test KATS have already been tested, The integrity value is compared to a value written to a configuration file after successfully running the self tests during installation.

- -
-
"KAT_Cipher" (OSSL_SELF_TEST_TYPE_KAT_CIPHER)
-
- -

Known answer test for a symmetric cipher.

- -
-
"KAT_AsymmetricCipher" (OSSL_SELF_TEST_TYPE_KAT_ASYM_CIPHER)
-
- -

Known answer test for a asymmetric cipher.

- -
-
"KAT_Digest" (OSSL_SELF_TEST_TYPE_KAT_DIGEST)
-
- -

Known answer test for a digest.

- -
-
"KAT_Signature" (OSSL_SELF_TEST_TYPE_KAT_SIGNATURE)
-
- -

Known answer test for a signature.

- -
-
"PCT_Signature" (OSSL_SELF_TEST_TYPE_PCT_SIGNATURE)
-
- -

Pairwise Consistency check for a signature.

- -
-
"KAT_KDF" (OSSL_SELF_TEST_TYPE_KAT_KDF)
-
- -

Known answer test for a key derivation function.

- -
-
"KAT_KA" (OSSL_SELF_TEST_TYPE_KAT_KA)
-
- -

Known answer test for key agreement.

- -
-
"DRBG" (OSSL_SELF_TEST_TYPE_DRBG)
-
- -

Known answer test for a Deterministic Random Bit Generator.

- -
-
"Conditional_PCT" (OSSL_SELF_TEST_TYPE_PCT)
-
- -

Conditional test that is run during the generation of key pairs.

- -
-
"Continuous_RNG_Test" (OSSL_SELF_TEST_TYPE_CRNG)
-
- -

Continuous random number generator test.

- -
-
- -

The "Module_Integrity" self test is always run at startup. The "Install_Integrity" self test is used to check if the self tests have already been run at installation time. If they have already run then the self tests are not run on subsequent startups. All other self test categories are run once at installation time, except for the "Pairwise_Consistency_Test".

- -

There is only one instance of the "Module_Integrity" and "Install_Integrity" self tests. All other self tests may have multiple instances.

- -

The FIPS module passes the following descriptions(s) to OSSL_SELF_TEST_onbegin().

- -
- -
"HMAC" (OSSL_SELF_TEST_DESC_INTEGRITY_HMAC)
-
- -

"Module_Integrity" and "Install_Integrity" use this.

- -
-
"RSA" (OSSL_SELF_TEST_DESC_PCT_RSA_PKCS1)
-
- -
-
"RSA" (OSSL_SELF_TEST_DESC_PCT_RSA)
-
- -
-
"ECDSA" (OSSL_SELF_TEST_DESC_PCT_ECDSA)
-
- -
-
"EDDSA" (OSSL_SELF_TEST_DESC_PCT_EDDSA)
-
- -
-
"DSA" (OSSL_SELF_TEST_DESC_PCT_DSA)
-
- -

Key generation tests used with the "Pairwise_Consistency_Test" type.

- -
-
"RSA_Encrypt" (OSSL_SELF_TEST_DESC_ASYM_RSA_ENC)
-
- -
-
"RSA_Decrypt" (OSSL_SELF_TEST_DESC_ASYM_RSA_DEC)
-
- -

"KAT_AsymmetricCipher" uses this to indicate an encrypt or decrypt KAT.

- -
-
"AES_GCM" (OSSL_SELF_TEST_DESC_CIPHER_AES_GCM)
-
- -
-
"AES_ECB_Decrypt" (OSSL_SELF_TEST_DESC_CIPHER_AES_ECB)
-
- -
-
"TDES" (OSSL_SELF_TEST_DESC_CIPHER_TDES)
-
- -

Symmetric cipher tests used with the "KAT_Cipher" type.

- -
-
"SHA1" (OSSL_SELF_TEST_DESC_MD_SHA1)
-
- -
-
"SHA2" (OSSL_SELF_TEST_DESC_MD_SHA2)
-
- -
-
"SHA3" (OSSL_SELF_TEST_DESC_MD_SHA3)
-
- -

Digest tests used with the "KAT_Digest" type.

- -
-
"DSA" (OSSL_SELF_TEST_DESC_SIGN_DSA)
-
- -
-
"RSA" (OSSL_SELF_TEST_DESC_SIGN_RSA)
-
- -
-
"ECDSA" (OSSL_SELF_TEST_DESC_SIGN_ECDSA)
-
- -
-
"EDDSA" (OSSL_SELF_TEST_DESC_SIGN_EDDSA)
-
- -

Signature tests used with the "KAT_Signature" type.

- -
-
"ECDH" (OSSL_SELF_TEST_DESC_KA_ECDH)
-
- -
-
"DH" (OSSL_SELF_TEST_DESC_KA_DH)
-
- -

Key agreement tests used with the "KAT_KA" type.

- -
-
"HKDF" (OSSL_SELF_TEST_DESC_KDF_HKDF)
-
- -
-
"TLS13_KDF_EXTRACT" (OSSL_SELF_TEST_DESC_KDF_TLS13_EXTRACT)
-
- -
-
"TLS13_KDF_EXPAND" (OSSL_SELF_TEST_DESC_KDF_TLS13_EXPAND)
-
- -
-
"SSKDF" (OSSL_SELF_TEST_DESC_KDF_SSKDF)
-
- -
-
"X963KDF" (OSSL_SELF_TEST_DESC_KDF_X963KDF)
-
- -
-
"X942KDF" (OSSL_SELF_TEST_DESC_KDF_X942KDF)
-
- -
-
"PBKDF2" (OSSL_SELF_TEST_DESC_KDF_PBKDF2)
-
- -
-
"SSHKDF" (OSSL_SELF_TEST_DESC_KDF_SSHKDF)
-
- -
-
"TLS12_PRF" (OSSL_SELF_TEST_DESC_KDF_TLS12_PRF)
-
- -
-
"KBKDF" (OSSL_SELF_TEST_DESC_KDF_KBKDF)
-
- -

Key Derivation Function tests used with the "KAT_KDF" type.

- -
-
"CTR" (OSSL_SELF_TEST_DESC_DRBG_CTR)
-
- -
-
"HASH" (OSSL_SELF_TEST_DESC_DRBG_HASH)
-
- -
-
"HMAC" (OSSL_SELF_TEST_DESC_DRBG_HMAC)
-
- -

DRBG tests used with the "DRBG" type.

- -
-
"RNG" (OSSL_SELF_TEST_DESC_RNG)
-
- -

"Continuous_RNG_Test" uses this.

- -
-
- -

EXAMPLES

- -

A simple self test callback is shown below for illustrative purposes.

- -
#include <openssl/self_test.h>
-
-static OSSL_CALLBACK self_test_cb;
-
-static int self_test_cb(const OSSL_PARAM params[], void *arg)
-{
-  int ret = 0;
-  const OSSL_PARAM *p = NULL;
-  const char *phase = NULL, *type = NULL, *desc = NULL;
-
-  p = OSSL_PARAM_locate_const(params, OSSL_PROV_PARAM_SELF_TEST_PHASE);
-  if (p == NULL || p->data_type != OSSL_PARAM_UTF8_STRING)
-      goto err;
-  phase = (const char *)p->data;
-
-  p = OSSL_PARAM_locate_const(params, OSSL_PROV_PARAM_SELF_TEST_DESC);
-  if (p == NULL || p->data_type != OSSL_PARAM_UTF8_STRING)
-      goto err;
-  desc = (const char *)p->data;
-
-  p = OSSL_PARAM_locate_const(params, OSSL_PROV_PARAM_SELF_TEST_TYPE);
-  if (p == NULL || p->data_type != OSSL_PARAM_UTF8_STRING)
-      goto err;
-  type = (const char *)p->data;
-
-  /* Do some logging */
-  if (strcmp(phase, OSSL_SELF_TEST_PHASE_START) == 0)
-      BIO_printf(bio_out, "%s : (%s) : ", desc, type);
-  if (strcmp(phase, OSSL_SELF_TEST_PHASE_PASS) == 0
-          || strcmp(phase, OSSL_SELF_TEST_PHASE_FAIL) == 0)
-      BIO_printf(bio_out, "%s\n", phase);
-
-  /* Corrupt the SHA1 self test during the 'corrupt' phase by returning 0 */
-  if (strcmp(phase, OSSL_SELF_TEST_PHASE_CORRUPT) == 0
-          && strcmp(desc, OSSL_SELF_TEST_DESC_MD_SHA1) == 0) {
-      BIO_printf(bio_out, "%s %s", phase, desc);
-      return 0;
-  }
-  ret = 1;
-err:
-  return ret;
-}
- -

NOTES

- -

Some released versions of OpenSSL do not include a validated FIPS provider. To determine which versions have undergone the validation process, please refer to the OpenSSL Downloads page. If you require FIPS-approved functionality, it is essential to build your FIPS provider using one of the validated versions listed there. Normally, it is possible to utilize a FIPS provider constructed from one of the validated versions alongside libcrypto and libssl compiled from any release within the same major release series. This flexibility enables you to address bug fixes and CVEs that fall outside the FIPS boundary.

- -

The FIPS provider in OpenSSL 3.1 includes some non-FIPS validated algorithms, consequently the property query fips=yes is mandatory for applications that want to operate in a FIPS approved manner. The algorithms are:

- -
- -
Triple DES ECB
-
- -
-
Triple DES CBC
-
- -
-
EdDSA
-
- -
-
- -

You can load the FIPS provider into multiple library contexts as any other provider. However the following restriction applies. The FIPS provider cannot be used by multiple copies of OpenSSL libcrypto in a single process.

- -

As the provider saves core callbacks to the libcrypto obtained in the OSSL_provider_init() call to global data it will fail if subsequent invocations of its OSSL_provider_init() function yield different addresses of these callbacks than in the initial call. This happens when different copies of libcrypto are present in the memory of the process and both try to load the same FIPS provider. A workaround is to have a different copy of the FIPS provider loaded for each of the libcrypto instances in the process.

- -

SEE ALSO

- -

openssl-fipsinstall(1), fips_config(5), OSSL_SELF_TEST_set_callback(3), OSSL_SELF_TEST_new(3), OSSL_PARAM(3), openssl-core.h(7), openssl-core_dispatch.h(7), provider(7), https://www.openssl.org/source/

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-base.html b/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-base.html deleted file mode 100644 index 0c2b64ee..00000000 --- a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-base.html +++ /dev/null @@ -1,257 +0,0 @@ - - - - -OSSL_PROVIDER-base - - - - - - - - - - -

NAME

- -

OSSL_PROVIDER-base - OpenSSL base provider

- -

DESCRIPTION

- -

The OpenSSL base provider supplies the encoding for OpenSSL's asymmetric cryptography.

- -

Properties

- -

The implementations in this provider specifically have this property defined:

- -
- -
"provider=base"
-
- -
-
- -

It may be used in a property query string with fetching functions.

- -

It isn't mandatory to query for this property, except to make sure to get implementations of this provider and none other.

- -
- -
"type=parameters"
-
- -
-
"type=private"
-
- -
-
"type=public"
-
- -
-
- -

These may be used in a property query string with fetching functions to select which data are to be encoded. Either the private key material, the public key material or the domain parameters can be selected.

- -
- -
"format=der"
-
- -
-
"format=pem"
-
- -
-
"format=text"
-
- -
-
- -

These may be used in a property query string with fetching functions to select the encoding output format. Either the DER, PEM and plaintext are currently permitted.

- -

OPERATIONS AND ALGORITHMS

- -

The OpenSSL base provider supports these operations and algorithms:

- -

Random Number Generation

- -
- -
SEED-SRC, see EVP_RAND-SEED-SRC(7)
-
- -
-
JITTER, see EVP_RAND-JITTER(7)
-
- -
-
- -

In addition to this provider, the "SEED-SRC" and "JITTER" algorithms are also available in the default provider.

- -

Asymmetric Key Encoder

- -
- -
RSA
-
- -
-
RSA-PSS
-
- -
-
DH
-
- -
-
DHX
-
- -
-
DSA
-
- -
-
EC
-
- -
-
ED25519
-
- -
-
ED448
-
- -
-
X25519
-
- -
-
X448
-
- -
-
SM2
-
- -
-
- -

In addition to this provider, all of these encoding algorithms are also available in the default provider. Some of these algorithms may be used in combination with the FIPS provider.

- -

Asymmetric Key Decoder

- -
- -
RSA
-
- -
-
RSA-PSS
-
- -
-
DH
-
- -
-
DHX
-
- -
-
DSA
-
- -
-
EC
-
- -
-
ED25519
-
- -
-
ED448
-
- -
-
X25519
-
- -
-
X448
-
- -
-
SM2
-
- -
-
DER
-
- -
-
- -

In addition to this provider, all of these decoding algorithms are also available in the default provider. Some of these algorithms may be used in combination with the FIPS provider.

- -

Stores

- -
- -
file
-
- -
-
org.openssl.winstore, see OSSL_STORE-winstore(7)
-
- -
-
- -

In addition to this provider, all of these store algorithms are also available in the default provider.

- -

SEE ALSO

- -

OSSL_PROVIDER-default(7), openssl-core.h(7), openssl-core_dispatch.h(7), provider(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-default.html b/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-default.html deleted file mode 100644 index 19606499..00000000 --- a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-default.html +++ /dev/null @@ -1,638 +0,0 @@ - - - - -OSSL_PROVIDER-default - - - - - - - - - - -

NAME

- -

OSSL_PROVIDER-default - OpenSSL default provider

- -

DESCRIPTION

- -

The OpenSSL default provider supplies the majority of OpenSSL's diverse algorithm implementations. If an application doesn't specify anything else explicitly (e.g. in the application or via config), then this is the provider that will be used as fallback: It is loaded automatically the first time that an algorithm is fetched from a provider or a function acting on providers is called and no other provider has been loaded yet.

- -

If an attempt to load a provider has already been made (whether successful or not) then the default provider won't be loaded automatically. Therefore if the default provider is to be used in conjunction with other providers then it must be loaded explicitly. Automatic loading of the default provider only occurs a maximum of once; if the default provider is explicitly unloaded then the default provider will not be automatically loaded again.

- -

Properties

- -

The implementations in this provider specifically have this property defined:

- -
- -
"provider=default"
-
- -
-
- -

It may be used in a property query string with fetching functions such as EVP_MD_fetch(3) or EVP_CIPHER_fetch(3), as well as with other functions that take a property query string, such as EVP_PKEY_CTX_new_from_name(3).

- -

It isn't mandatory to query for this property, except to make sure to get implementations of this provider and none other.

- -

Some implementations may define additional properties. Exact information is listed below

- -

OPERATIONS AND ALGORITHMS

- -

The OpenSSL default provider supports these operations and algorithms:

- -

Hashing Algorithms / Message Digests

- -
- -
SHA1, see EVP_MD-SHA1(7)
-
- -
-
SHA2, see EVP_MD-SHA2(7)
-
- -
-
SHA3, see EVP_MD-SHA3(7)
-
- -
-
KECCAK, see EVP_MD-KECCAK(7)
-
- -
-
KECCAK-KMAC, see EVP_MD-KECCAK-KMAC(7)
-
- -
-
SHAKE, see EVP_MD-SHAKE(7)
-
- -
-
BLAKE2, see EVP_MD-BLAKE2(7)
-
- -
-
SM3, see EVP_MD-SM3(7)
-
- -
-
MD5, see EVP_MD-MD5(7)
-
- -
-
MD5-SHA1, see EVP_MD-MD5-SHA1(7)
-
- -
-
RIPEMD160, see EVP_MD-RIPEMD160(7)
-
- -
-
NULL, see EVP_MD-NULL(7)
-
- -
-
- -

Symmetric Ciphers

- -
- -
AES, see EVP_CIPHER-AES(7)
-
- -
-
ARIA, see EVP_CIPHER-ARIA(7)
-
- -
-
CAMELLIA, see EVP_CIPHER-CAMELLIA(7)
-
- -
-
3DES, see EVP_CIPHER-DES(7)
-
- -
-
SM4, see EVP_CIPHER-SM4(7)
-
- -
-
ChaCha20, see EVP_CIPHER-CHACHA(7)
-
- -
-
ChaCha20-Poly1305, see EVP_CIPHER-CHACHA(7)
-
- -
-
NULL, see EVP_CIPHER-NULL(7)
-
- -
-
- -

Message Authentication Code (MAC)

- -
- -
BLAKE2, see EVP_MAC-BLAKE2(7)
-
- -
-
CMAC, see EVP_MAC-CMAC(7)
-
- -
-
GMAC, see EVP_MAC-GMAC(7)
-
- -
-
HMAC, see EVP_MAC-HMAC(7)
-
- -
-
KMAC, see EVP_MAC-KMAC(7)
-
- -
-
SIPHASH, see EVP_MAC-Siphash(7)
-
- -
-
POLY1305, see EVP_MAC-Poly1305(7)
-
- -
-
- -

Key Derivation Function (KDF)

- -
- -
HKDF, see EVP_KDF-HKDF(7)
-
- -
-
TLS13-KDF, see EVP_KDF-TLS13_KDF(7)
-
- -
-
SSKDF, see EVP_KDF-SS(7)
-
- -
-
PBKDF2, see EVP_KDF-PBKDF2(7)
-
- -
-
PKCS12KDF, see EVP_KDF-PKCS12KDF(7)
-
- -
-
SSHKDF, see EVP_KDF-SSHKDF(7)
-
- -
-
TLS1-PRF, see EVP_KDF-TLS1_PRF(7)
-
- -
-
KBKDF, see EVP_KDF-KB(7)
-
- -
-
X942KDF-ASN1, see EVP_KDF-X942-ASN1(7)
-
- -
-
X942KDF-CONCAT, see EVP_KDF-X942-CONCAT(7)
-
- -
-
X963KDF, see EVP_KDF-X963(7)
-
- -
-
SCRYPT, see EVP_KDF-SCRYPT(7)
-
- -
-
KRB5KDF, see EVP_KDF-KRB5KDF(7)
-
- -
-
HMAC-DRBG, see EVP_KDF-HMAC-DRBG(7)
-
- -
-
ARGON2, see EVP_KDF-ARGON2(7)
-
- -
-
- -

Key Exchange

- -
- -
DH, see EVP_KEYEXCH-DH(7)
-
- -
-
ECDH, see EVP_KEYEXCH-ECDH(7)
-
- -
-
X25519, see EVP_KEYEXCH-X25519(7)
-
- -
-
X448, see EVP_KEYEXCH-X448(7)
-
- -
-
TLS1-PRF
-
- -
-
HKDF
-
- -
-
SCRYPT
-
- -
-
- -

Asymmetric Signature

- -
- -
DSA, see EVP_SIGNATURE-DSA(7)
-
- -
-
RSA, see EVP_SIGNATURE-RSA(7)
-
- -
-
ED25519, see EVP_SIGNATURE-ED25519(7)
-
- -
-
ED448, see EVP_SIGNATURE-ED448(7)
-
- -
-
ECDSA, see EVP_SIGNATURE-ECDSA(7)
-
- -
-
SM2
-
- -
-
HMAC, see EVP_SIGNATURE-HMAC(7)
-
- -
-
SIPHASH, see EVP_SIGNATURE-Siphash(7)
-
- -
-
POLY1305, see EVP_SIGNATURE-Poly1305(7)
-
- -
-
CMAC, see EVP_SIGNATURE-CMAC(7)
-
- -
-
- -

Asymmetric Cipher

- -
- -
RSA, see EVP_ASYM_CIPHER-RSA(7)
-
- -
-
SM2, see EVP_ASYM_CIPHER-SM2(7)
-
- -
-
- -

Asymmetric Key Encapsulation

- -
- -
RSA, see EVP_KEM-RSA(7)
-
- -
-
X25519, see EVP_KEM-X25519(7)
-
- -
-
X448, see EVP_KEM-X448(7)
-
- -
-
EC, see EVP_KEM-EC(7)
-
- -
-
- -

Asymmetric Key Management

- -
- -
DH, see EVP_KEYMGMT-DH(7)
-
- -
-
DHX, see EVP_KEYMGMT-DHX(7)
-
- -
-
DSA, see EVP_KEYMGMT-DSA(7)
-
- -
-
RSA, see EVP_KEYMGMT-RSA(7)
-
- -
-
RSA-PSS
-
- -
-
EC, see EVP_KEYMGMT-EC(7)
-
- -
-
X25519, see EVP_KEYMGMT-X25519(7)
-
- -
-
X448, see EVP_KEYMGMT-X448(7)
-
- -
-
ED25519, see EVP_KEYMGMT-ED25519(7)
-
- -
-
ED448, see EVP_KEYMGMT-ED448(7)
-
- -
-
TLS1-PRF
-
- -
-
HKDF
-
- -
-
SCRYPT
-
- -
-
HMAC, see EVP_KEYMGMT-HMAC(7)
-
- -
-
SIPHASH, see EVP_KEYMGMT-Siphash(7)
-
- -
-
POLY1305, see EVP_KEYMGMT-Poly1305(7)
-
- -
-
CMAC, see EVP_KEYMGMT-CMAC(7)
-
- -
-
SM2, see EVP_KEYMGMT-SM2(7)
-
- -
-
- -

Random Number Generation

- -
- -
CTR-DRBG, see EVP_RAND-CTR-DRBG(7)
-
- -
-
HASH-DRBG, see EVP_RAND-HASH-DRBG(7)
-
- -
-
HMAC-DRBG, see EVP_RAND-HMAC-DRBG(7)
-
- -
-
SEED-SRC, see EVP_RAND-SEED-SRC(7)
-
- -
-
JITTER, see EVP_RAND-JITTER(7)
-
- -
-
TEST-RAND, see EVP_RAND-TEST-RAND(7)
-
- -
-
- -

In addition to this provider, the "SEED-SRC" and "JITTER" algorithms are also available in the base provider.

- -

Asymmetric Key Encoder

- -
- -
RSA
-
- -
-
RSA-PSS
-
- -
-
DH
-
- -
-
DHX
-
- -
-
DSA
-
- -
-
EC
-
- -
-
ED25519
-
- -
-
ED448
-
- -
-
X25519
-
- -
-
X448
-
- -
-
SM2
-
- -
-
- -

In addition to this provider, all of these encoding algorithms are also available in the base provider. Some of these algorithms may be used in combination with the FIPS provider.

- -

Asymmetric Key Decoder

- -
- -
RSA
-
- -
-
RSA-PSS
-
- -
-
DH
-
- -
-
DHX
-
- -
-
DSA
-
- -
-
EC
-
- -
-
ED25519
-
- -
-
ED448
-
- -
-
X25519
-
- -
-
X448
-
- -
-
SM2
-
- -
-
DER
-
- -
-
- -

In addition to this provider, all of these decoding algorithms are also available in the base provider. Some of these algorithms may be used in combination with the FIPS provider.

- -

Stores

- -
- -
file
-
- -
-
org.openssl.winstore, see OSSL_STORE-winstore(7)
-
- -
-
- -

In addition to this provider, all of these store algorithms are also available in the base provider.

- -

SEE ALSO

- -

openssl-core.h(7), openssl-core_dispatch.h(7), provider(7), OSSL_PROVIDER-base(7)

- -

HISTORY

- -

The RIPEMD160 digest was added to the default provider in OpenSSL 3.0.7.

- -

All other functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-legacy.html b/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-legacy.html deleted file mode 100644 index 267ce999..00000000 --- a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-legacy.html +++ /dev/null @@ -1,168 +0,0 @@ - - - - -OSSL_PROVIDER-legacy - - - - - - - - - - -

NAME

- -

OSSL_PROVIDER-legacy - OpenSSL legacy provider

- -

DESCRIPTION

- -

The OpenSSL legacy provider supplies OpenSSL implementations of algorithms that have been deemed legacy. Such algorithms have commonly fallen out of use, have been deemed insecure by the cryptography community, or something similar.

- -

We can consider this the retirement home of cryptographic algorithms.

- -

Properties

- -

The implementations in this provider specifically has this property defined:

- -
- -
"provider=legacy"
-
- -
-
- -

It may be used in a property query string with fetching functions such as EVP_MD_fetch(3) or EVP_CIPHER_fetch(3), as well as with other functions that take a property query string, such as EVP_PKEY_CTX_new_from_name(3).

- -

It isn't mandatory to query for any of these properties, except to make sure to get implementations of this provider and none other.

- -

OPERATIONS AND ALGORITHMS

- -

The OpenSSL legacy provider supports these operations and algorithms:

- -

Hashing Algorithms / Message Digests

- -
- -
MD2, see EVP_MD-MD2(7)
-
- -

Disabled by default. Use enable-md2 config option to enable.

- -
-
MD4, see EVP_MD-MD4(7)
-
- -
-
MDC2, see EVP_MD-MDC2(7)
-
- -
-
WHIRLPOOL, see EVP_MD-WHIRLPOOL(7)
-
- -
-
RIPEMD160, see EVP_MD-RIPEMD160(7)
-
- -
-
- -

Symmetric Ciphers

- -

Not all of these symmetric cipher algorithms are enabled by default.

- -
- -
Blowfish, see EVP_CIPHER-BLOWFISH(7)
-
- -
-
CAST, see EVP_CIPHER-CAST(7)
-
- -
-
DES, see EVP_CIPHER-DES(7)
-
- -

The algorithm names are: DES_ECB, DES_CBC, DES_OFB, DES_CFB, DES_CFB1, DES_CFB8 and DESX_CBC.

- -
-
IDEA, see EVP_CIPHER-IDEA(7)
-
- -
-
RC2, see EVP_CIPHER-RC2(7)
-
- -
-
RC4, see EVP_CIPHER-RC4(7)
-
- -
-
RC5, see EVP_CIPHER-RC5(7)
-
- -

Disabled by default. Use enable-rc5 config option to enable.

- -
-
SEED, see EVP_CIPHER-SEED(7)
-
- -
-
- -

Key Derivation Function (KDF)

- -
- -
PBKDF1
-
- -
-
PVKKDF
-
- -
-
- -

SEE ALSO

- -

OSSL_PARAM(3), openssl-core.h(7), openssl-core_dispatch.h(7), provider(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-null.html b/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-null.html deleted file mode 100644 index 4239bb1b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/OSSL_PROVIDER-null.html +++ /dev/null @@ -1,64 +0,0 @@ - - - - -OSSL_PROVIDER-null - - - - - - - - - - -

NAME

- -

OSSL_PROVIDER-null - OpenSSL null provider

- -

DESCRIPTION

- -

The OpenSSL null provider supplies no algorithms.

- -

It can used to guarantee that the default library context and a fallback provider will not be accidentally accessed.

- -

Properties

- -

The null provider defines no properties.

- -

OPERATIONS AND ALGORITHMS

- -

The OpenSSL null provider supports no operations and algorithms.

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/OSSL_STORE-winstore.html b/openssl-install/share/doc/openssl/html/man7/OSSL_STORE-winstore.html deleted file mode 100644 index 947ba56e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/OSSL_STORE-winstore.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -OSSL_STORE-winstore - - - - - - - - - - -

NAME

- -

OSSL_STORE-winstore - OpenSSL built in OSSL_STORE for Windows

- -

DESCRIPTION

- -

The OSSL_STORE implementation for Windows provides access to Windows' system ROOT certificate store through URIs, using the URI scheme org.openssl.winstore.

- -

Supported URIs

- -

There is only one supported URI:

- -
org.openssl.winstore:
- -

No authority (host, etc), no path, no query, no fragment.

- -

Supported OSSL_STORE_SEARCH operations

- -
- -
OSSL_STORE_SEARCH_by_name(3)
-
- -

As a matter of fact, this must be used. It is not possible to enumerate all available certificates in the store.

- -
-
- -

Windows certificate store features

- -

Apart from diverse constraints present in the certificates themselves, the Windows certificate store also has the ability to associate additional constraining properties alongside a certificate in the store. This includes both documented and undocumented capabilities:

- - - -

Such constraints are not checked by this OSSL_STORE implementation, and thereby not honoured.

- -

However, once extracted with OSSL_STORE_load(3), certificates that have constraints in their X.509 extensions will go through the usual constraint checks when used by OpenSSL, and are thereby honoured.

- -

SEE ALSO

- -

ossl_store(7), OSSL_STORE_open_ex(3), OSSL_STORE_SEARCH(3)

- -

HISTORY

- -

The winstore (org.openssl.winstore) implementation was added in OpenSSL 3.2.0.

- -

NOTES

- -

OpenSSL uses OSSL_DECODER(3) implementations under the hood. To influence what OSSL_DECODER(3) implementations are used, it's advisable to use OSSL_STORE_open_ex(3) and set the propq argument.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/RAND.html b/openssl-install/share/doc/openssl/html/man7/RAND.html deleted file mode 100644 index 64ff8e92..00000000 --- a/openssl-install/share/doc/openssl/html/man7/RAND.html +++ /dev/null @@ -1,59 +0,0 @@ - - - - -RAND - - - - - - - - - - -

NAME

- -

RAND - the OpenSSL random generator

- -

DESCRIPTION

- -

Random numbers are a vital part of cryptography, they are needed to provide unpredictability for tasks like key generation, creating salts, and many more. Software-based generators must be seeded with external randomness before they can be used as a cryptographically-secure pseudo-random number generator (CSPRNG). The availability of common hardware with special instructions and modern operating systems, which may use items such as interrupt jitter and network packet timings, can be reasonable sources of seeding material.

- -

OpenSSL comes with a default implementation of the RAND API which is based on the deterministic random bit generator (DRBG) model as described in [NIST SP 800-90A Rev. 1]. The default random generator will initialize automatically on first use and will be fully functional without having to be initialized ('seeded') explicitly. It seeds and reseeds itself automatically using trusted random sources provided by the operating system.

- -

As a normal application developer, you do not have to worry about any details, just use RAND_bytes(3) to obtain random data. Having said that, there is one important rule to obey: Always check the error return value of RAND_bytes(3) and do not take randomness for granted. Although (re-)seeding is automatic, it can fail because no trusted random source is available or the trusted source(s) temporarily fail to provide sufficient random seed material. In this case the CSPRNG enters an error state and ceases to provide output, until it is able to recover from the error by reseeding itself. For more details on reseeding and error recovery, see EVP_RAND(7).

- -

For values that should remain secret, you can use RAND_priv_bytes(3) instead. This method does not provide 'better' randomness, it uses the same type of CSPRNG. The intention behind using a dedicated CSPRNG exclusively for private values is that none of its output should be visible to an attacker (e.g., used as salt value), in order to reveal as little information as possible about its internal state, and that a compromise of the "public" CSPRNG instance will not affect the secrecy of these private values.

- -

In the rare case where the default implementation does not satisfy your special requirements, the default RAND internals can be replaced by your own EVP_RAND(3) objects.

- -

Changing the default random generator should be necessary only in exceptional cases and is not recommended, unless you have a profound knowledge of cryptographic principles and understand the implications of your changes.

- -

DEFAULT SETUP

- -

The default OpenSSL RAND method is based on the EVP_RAND deterministic random bit generator (DRBG) classes. A DRBG is a certain type of cryptographically-secure pseudo-random number generator (CSPRNG), which is described in [NIST SP 800-90A Rev. 1].

- -

SEE ALSO

- -

RAND_bytes(3), RAND_priv_bytes(3), EVP_RAND(3), RAND_get0_primary(3), EVP_RAND(7)

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/RSA-PSS.html b/openssl-install/share/doc/openssl/html/man7/RSA-PSS.html deleted file mode 100644 index 8fe29433..00000000 --- a/openssl-install/share/doc/openssl/html/man7/RSA-PSS.html +++ /dev/null @@ -1,73 +0,0 @@ - - - - -RSA-PSS - - - - - - - - - - -

NAME

- -

RSA-PSS - EVP_PKEY RSA-PSS algorithm support

- -

DESCRIPTION

- -

The RSA-PSS EVP_PKEY implementation is a restricted version of the RSA algorithm which only supports signing, verification and key generation using PSS padding modes with optional parameter restrictions.

- -

It has associated private key and public key formats.

- -

This algorithm shares several control operations with the RSA algorithm but with some restrictions described below.

- -

Signing and Verification

- -

Signing and verification is similar to the RSA algorithm except the padding mode is always PSS. If the key in use has parameter restrictions then the corresponding signature parameters are set to the restrictions: for example, if the key can only be used with digest SHA256, MGF1 SHA256 and minimum salt length 32 then the digest, MGF1 digest and salt length will be set to SHA256, SHA256 and 32 respectively.

- -

Key Generation

- -

By default no parameter restrictions are placed on the generated key.

- -

NOTES

- -

The public key format is documented in RFC4055.

- -

The PKCS#8 private key format used for RSA-PSS keys is similar to the RSA format except it uses the id-RSASSA-PSS OID and the parameters field, if present, restricts the key parameters in the same way as the public key.

- -

CONFORMING TO

- -

RFC 4055

- -

SEE ALSO

- -

EVP_PKEY_CTX_set_rsa_pss_keygen_md(3), EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md(3), EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen(3), EVP_PKEY_CTX_new(3), EVP_PKEY_CTX_ctrl_str(3), EVP_PKEY_derive(3)

- -

COPYRIGHT

- -

Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/X25519.html b/openssl-install/share/doc/openssl/html/man7/X25519.html deleted file mode 100644 index 1ea9307e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/X25519.html +++ /dev/null @@ -1,80 +0,0 @@ - - - - -X25519 - - - - - - - - - - -

NAME

- -

X25519, X448 - EVP_PKEY X25519 and X448 support

- -

DESCRIPTION

- -

The X25519 and X448 EVP_PKEY implementation supports key generation and key derivation using X25519 and X448. It has associated private and public key formats compatible with RFC 8410.

- -

No additional parameters can be set during key generation.

- -

The peer public key must be set using EVP_PKEY_derive_set_peer() when performing key derivation.

- -

NOTES

- -

A context for the X25519 algorithm can be obtained by calling:

- -
EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X25519, NULL);
- -

For the X448 algorithm a context can be obtained by calling:

- -
EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X448, NULL);
- -

X25519 or X448 private keys can be set directly using EVP_PKEY_new_raw_private_key(3) or loaded from a PKCS#8 private key file using PEM_read_bio_PrivateKey(3) (or similar function). Completely new keys can also be generated (see the example below). Setting a private key also sets the associated public key.

- -

X25519 or X448 public keys can be set directly using EVP_PKEY_new_raw_public_key(3) or loaded from a SubjectPublicKeyInfo structure in a PEM file using PEM_read_bio_PUBKEY(3) (or similar function).

- -

EXAMPLES

- -

This example generates an X25519 private key and writes it to standard output in PEM format:

- -
#include <openssl/evp.h>
-#include <openssl/pem.h>
-...
-EVP_PKEY *pkey = NULL;
-EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X25519, NULL);
-EVP_PKEY_keygen_init(pctx);
-EVP_PKEY_keygen(pctx, &pkey);
-EVP_PKEY_CTX_free(pctx);
-PEM_write_PrivateKey(stdout, pkey, NULL, NULL, 0, NULL, NULL);
- -

The key derivation example in EVP_PKEY_derive(3) can be used with X25519 and X448.

- -

SEE ALSO

- -

EVP_PKEY_CTX_new(3), EVP_PKEY_keygen(3), EVP_PKEY_derive(3), EVP_PKEY_derive_set_peer(3)

- -

COPYRIGHT

- -

Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/bio.html b/openssl-install/share/doc/openssl/html/man7/bio.html deleted file mode 100644 index 6a50b144..00000000 --- a/openssl-install/share/doc/openssl/html/man7/bio.html +++ /dev/null @@ -1,101 +0,0 @@ - - - - -bio - - - - - - - - - - -

NAME

- -

bio - Basic I/O abstraction

- -

SYNOPSIS

- -
#include <openssl/bio.h>
- -

DESCRIPTION

- -

A BIO is an I/O abstraction, it hides many of the underlying I/O details from an application. If an application uses a BIO for its I/O it can transparently handle SSL connections, unencrypted network connections and file I/O.

- -

There are two types of BIO, a source/sink BIO and a filter BIO.

- -

As its name implies a source/sink BIO is a source and/or sink of data, examples include a socket BIO and a file BIO.

- -

A filter BIO takes data from one BIO and passes it through to another, or the application. The data may be left unmodified (for example a message digest BIO) or translated (for example an encryption BIO). The effect of a filter BIO may change according to the I/O operation it is performing: for example an encryption BIO will encrypt data if it is being written to and decrypt data if it is being read from.

- -

BIOs can be joined together to form a chain (a single BIO is a chain with one component). A chain normally consists of one source/sink BIO and one or more filter BIOs. Data read from or written to the first BIO then traverses the chain to the end (normally a source/sink BIO).

- -

Some BIOs (such as memory BIOs) can be used immediately after calling BIO_new(). Others (such as file BIOs) need some additional initialization, and frequently a utility function exists to create and initialize such BIOs.

- -

If BIO_free() is called on a BIO chain it will only free one BIO resulting in a memory leak.

- -

Calling BIO_free_all() on a single BIO has the same effect as calling BIO_free() on it other than the discarded return value.

- -

Normally the type argument is supplied by a function which returns a pointer to a BIO_METHOD. There is a naming convention for such functions: a source/sink BIO typically starts with BIO_s_ and a filter BIO with BIO_f_.

- -

TCP Fast Open

- -

TCP Fast Open (RFC7413), abbreviated "TFO", is supported by the BIO interface since OpenSSL 3.2. TFO is supported in the following operating systems:

- - - -

Each operating system has a slightly different API for TFO. Please refer to the operating systems' API documentation when using sockets directly.

- -

EXAMPLES

- -

Create a memory BIO:

- -
BIO *mem = BIO_new(BIO_s_mem());
- -

SEE ALSO

- -

BIO_ctrl(3), BIO_f_base64(3), BIO_f_buffer(3), BIO_f_cipher(3), BIO_f_md(3), BIO_f_null(3), BIO_f_ssl(3), BIO_f_readbuffer(3), BIO_find_type(3), BIO_get_conn_mode(3), BIO_new(3), BIO_new_bio_pair(3), BIO_push(3), BIO_read_ex(3), BIO_s_accept(3), BIO_s_bio(3), BIO_s_connect(3), BIO_s_fd(3), BIO_s_file(3), BIO_s_mem(3), BIO_s_null(3), BIO_s_socket(3), BIO_set_callback(3), BIO_set_conn_mode(3), BIO_set_tfo(3), BIO_set_tfo_accept(3), BIO_should_retry(3)

- -

COPYRIGHT

- -

Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ct.html b/openssl-install/share/doc/openssl/html/man7/ct.html deleted file mode 100644 index b73e303e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ct.html +++ /dev/null @@ -1,58 +0,0 @@ - - - - -ct - - - - - - - - - - -

NAME

- -

ct - Certificate Transparency

- -

SYNOPSIS

- -
#include <openssl/ct.h>
- -

DESCRIPTION

- -

This library implements Certificate Transparency (CT) verification for TLS clients, as defined in RFC 6962. This verification can provide some confidence that a certificate has been publicly logged in a set of CT logs.

- -

By default, these checks are disabled. They can be enabled using SSL_CTX_enable_ct(3) or SSL_enable_ct(3).

- -

This library can also be used to parse and examine CT data structures, such as Signed Certificate Timestamps (SCTs), or to read a list of CT logs. There are functions for: - decoding and encoding SCTs in DER and TLS wire format. - printing SCTs. - verifying the authenticity of SCTs. - loading a CT log list from a CONF file.

- -

SEE ALSO

- -

d2i_SCT_LIST(3), CTLOG_STORE_new(3), CTLOG_STORE_get0_log_by_id(3), SCT_new(3), SCT_print(3), SCT_validate(3), SCT_validate(3), CT_POLICY_EVAL_CTX_new(3), SSL_CTX_set_ct_validation_callback(3)

- -

HISTORY

- -

The ct library was added in OpenSSL 1.1.0.

- -

COPYRIGHT

- -

Copyright 2016-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/des_modes.html b/openssl-install/share/doc/openssl/html/man7/des_modes.html deleted file mode 100644 index 015434a9..00000000 --- a/openssl-install/share/doc/openssl/html/man7/des_modes.html +++ /dev/null @@ -1,214 +0,0 @@ - - - - -des_modes - - - - - - - - - - -

NAME

- -

des_modes - the variants of DES and other crypto algorithms of OpenSSL

- -

DESCRIPTION

- -

Several crypto algorithms for OpenSSL can be used in a number of modes. Those are used for using block ciphers in a way similar to stream ciphers, among other things.

- -

OVERVIEW

- -

Electronic Codebook Mode (ECB)

- -

Normally, this is found as the function algorithm_ecb_encrypt().

- - - -

Cipher Block Chaining Mode (CBC)

- -

Normally, this is found as the function algorithm_cbc_encrypt(). Be aware that des_cbc_encrypt() is not really DES CBC (it does not update the IV); use des_ncbc_encrypt() instead.

- - - -

Cipher Feedback Mode (CFB)

- -

Normally, this is found as the function algorithm_cfb_encrypt().

- - - -

Output Feedback Mode (OFB)

- -

Normally, this is found as the function algorithm_ofb_encrypt().

- - - -

Triple ECB Mode

- -

Normally, this is found as the function algorithm_ecb3_encrypt().

- - - -

Triple CBC Mode

- -

Normally, this is found as the function algorithm_ede3_cbc_encrypt().

- - - -

NOTES

- -

This text was been written in large parts by Eric Young in his original documentation for SSLeay, the predecessor of OpenSSL. In turn, he attributed it to:

- -
AS 2805.5.2
-Australian Standard
-Electronic funds transfer - Requirements for interfaces,
-Part 5.2: Modes of operation for an n-bit block cipher algorithm
-Appendix A
- -

SEE ALSO

- -

BF_encrypt(3), DES_crypt(3)

- -

COPYRIGHT

- -

Copyright 2000-2017 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/evp.html b/openssl-install/share/doc/openssl/html/man7/evp.html deleted file mode 100644 index 8e740593..00000000 --- a/openssl-install/share/doc/openssl/html/man7/evp.html +++ /dev/null @@ -1,83 +0,0 @@ - - - - -evp - - - - - - - - - - -

NAME

- -

evp - high-level cryptographic functions

- -

SYNOPSIS

- -
#include <openssl/evp.h>
- -

DESCRIPTION

- -

The EVP library provides a high-level interface to cryptographic functions.

- -

The EVP_SealXXX and EVP_OpenXXX functions provide public key encryption and decryption to implement digital "envelopes".

- -

The EVP_DigestSignXXX and EVP_DigestVerifyXXX functions implement digital signatures and Message Authentication Codes (MACs). Also see the older EVP_SignXXX and EVP_VerifyXXX functions.

- -

Symmetric encryption is available with the EVP_EncryptXXX functions. The EVP_DigestXXX functions provide message digests.

- -

The EVP_PKEYXXX functions provide a high-level interface to asymmetric algorithms. To create a new EVP_PKEY see EVP_PKEY_new(3). EVP_PKEYs can be associated with a private key of a particular algorithm by using the functions described on the EVP_PKEY_fromdata(3) page, or new keys can be generated using EVP_PKEY_keygen(3). EVP_PKEYs can be compared using EVP_PKEY_eq(3), or printed using EVP_PKEY_print_private(3). EVP_PKEY_todata(3) can be used to convert a key back into an OSSL_PARAM(3) array.

- -

The EVP_PKEY functions support the full range of asymmetric algorithm operations:

- -
- -
For key agreement see EVP_PKEY_derive(3)
-
- -
-
For signing and verifying see EVP_PKEY_sign(3), EVP_PKEY_verify(3) and EVP_PKEY_verify_recover(3). However, note that these functions do not perform a digest of the data to be signed. Therefore, normally you would use the EVP_DigestSignInit(3) functions for this purpose.
-
- -
-
For encryption and decryption see EVP_PKEY_encrypt(3) and EVP_PKEY_decrypt(3) respectively. However, note that these functions perform encryption and decryption only. As public key encryption is an expensive operation, normally you would wrap an encrypted message in a "digital envelope" using the EVP_SealInit(3) and EVP_OpenInit(3) functions.
-
- -
-
- -

The EVP_BytesToKey(3) function provides some limited support for password based encryption. Careful selection of the parameters will provide a PKCS#5 PBKDF1 compatible implementation. However, new applications should not typically use this (preferring, for example, PBKDF2 from PCKS#5).

- -

The EVP_EncodeXXX and EVP_DecodeXXX functions implement base64 encoding and decoding.

- -

All the symmetric algorithms (ciphers), digests and asymmetric algorithms (public key algorithms) can be replaced by ENGINE modules providing alternative implementations. If ENGINE implementations of ciphers or digests are registered as defaults, then the various EVP functions will automatically use those implementations automatically in preference to built in software implementations. For more information, consult the engine(3) man page.

- -

Although low-level algorithm specific functions exist for many algorithms their use is discouraged. They cannot be used with an ENGINE and ENGINE versions of new algorithms cannot be accessed using the low-level functions. Also makes code harder to adapt to new algorithms and some options are not cleanly supported at the low-level and some operations are more efficient using the high-level interface.

- -

SEE ALSO

- -

EVP_DigestInit(3), EVP_EncryptInit(3), EVP_OpenInit(3), EVP_SealInit(3), EVP_DigestSignInit(3), EVP_SignInit(3), EVP_VerifyInit(3), EVP_EncodeInit(3), EVP_PKEY_new(3), EVP_PKEY_fromdata(3), EVP_PKEY_todata(3), EVP_PKEY_keygen(3), EVP_PKEY_print_private(3), EVP_PKEY_decrypt(3), EVP_PKEY_encrypt(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3), EVP_PKEY_derive(3), EVP_BytesToKey(3), ENGINE_by_id(3)

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/fips_module.html b/openssl-install/share/doc/openssl/html/man7/fips_module.html deleted file mode 100644 index 37b7c2f6..00000000 --- a/openssl-install/share/doc/openssl/html/man7/fips_module.html +++ /dev/null @@ -1,503 +0,0 @@ - - - - -fips_module - - - - - - - - - - -

NAME

- -

fips_module - OpenSSL fips module guide

- -

SYNOPSIS

- -

See the individual manual pages for details.

- -

DESCRIPTION

- -

This guide details different ways that OpenSSL can be used in conjunction with the FIPS module. Which is the correct approach to use will depend on your own specific circumstances and what you are attempting to achieve.

- -

For information related to installing the FIPS module see https://github.com/openssl/openssl/blob/master/README-FIPS.md.

- -

Note that the old functions FIPS_mode() and FIPS_mode_set() are no longer present so you must remove them from your application if you use them.

- -

Applications written to use the OpenSSL 3.0 FIPS module should not use any legacy APIs or features that avoid the FIPS module. Specifically this includes:

- - - -

All of the above APIs are deprecated in OpenSSL 3.0 - so a simple rule is to avoid using all deprecated functions. See ossl-guide-migration(7) for a list of deprecated functions.

- -

Making all applications use the FIPS module by default

- -

One simple approach is to cause all applications that are using OpenSSL to only use the FIPS module for cryptographic algorithms by default.

- -

This approach can be done purely via configuration. As long as applications are built and linked against OpenSSL 3.0 and do not override the loading of the default config file or its settings then they can automatically start using the FIPS module without the need for any further code changes.

- -

To do this the default OpenSSL config file will have to be modified. The location of this config file will depend on the platform, and any options that were given during the build process. You can check the location of the config file by running this command:

- -
$ openssl version -d
-OPENSSLDIR: "/usr/local/ssl"
- -

Caution: Many Operating Systems install OpenSSL by default. It is a common error to not have the correct version of OpenSSL in your $PATH. Check that you are running an OpenSSL 3.0 version like this:

- -
$ openssl version -v
-OpenSSL 3.0.0-dev xx XXX xxxx (Library: OpenSSL 3.0.0-dev xx XXX xxxx)
- -

The OPENSSLDIR value above gives the directory name for where the default config file is stored. So in this case the default config file will be called /usr/local/ssl/openssl.cnf.

- -

Edit the config file to add the following lines near the beginning:

- -
config_diagnostics = 1
-openssl_conf = openssl_init
-
-.include /usr/local/ssl/fipsmodule.cnf
-
-[openssl_init]
-providers = provider_sect
-alg_section = algorithm_sect
-
-[provider_sect]
-fips = fips_sect
-base = base_sect
-
-[base_sect]
-activate = 1
-
-[algorithm_sect]
-default_properties = fips=yes
- -

Obviously the include file location above should match the path and name of the FIPS module config file that you installed earlier. See https://github.com/openssl/openssl/blob/master/README-FIPS.md.

- -

For FIPS usage, it is recommended that the config_diagnostics option is enabled to prevent accidental use of non-FIPS validated algorithms via broken or mistaken configuration. See config(5).

- -

Any applications that use OpenSSL 3.0 and are started after these changes are made will start using only the FIPS module unless those applications take explicit steps to avoid this default behaviour. Note that this configuration also activates the "base" provider. The base provider does not include any cryptographic algorithms (and therefore does not impact the validation status of any cryptographic operations), but does include other supporting algorithms that may be required. It is designed to be used in conjunction with the FIPS module.

- -

This approach has the primary advantage that it is simple, and no code changes are required in applications in order to benefit from the FIPS module. There are some disadvantages to this approach:

- - - -

Selectively making applications use the FIPS module by default

- -

A variation on the above approach is to do the same thing on an individual application basis. The default OpenSSL config file depends on the compiled in value for OPENSSLDIR as described in the section above. However it is also possible to override the config file to be used via the OPENSSL_CONF environment variable. For example the following, on Unix, will cause the application to be executed with a non-standard config file location:

- -
$ OPENSSL_CONF=/my/nondefault/openssl.cnf myapplication
- -

Using this mechanism you can control which config file is loaded (and hence whether the FIPS module is loaded) on an application by application basis.

- -

This removes the disadvantage listed above that you may not want all applications to use the FIPS module. All the other advantages and disadvantages still apply.

- -

Programmatically loading the FIPS module (default library context)

- -

Applications may choose to load the FIPS provider explicitly rather than relying on config to do this. The config file is still necessary in order to hold the FIPS module config data (such as its self test status and integrity data). But in this case we do not automatically activate the FIPS provider via that config file.

- -

To do things this way configure as per "Making all applications use the FIPS module by default" above, but edit the fipsmodule.cnf file to remove or comment out the line which says activate = 1 (note that setting this value to 0 is not sufficient). This means all the required config information will be available to load the FIPS module, but it is not automatically loaded when the application starts. The FIPS provider can then be loaded programmatically like this:

- -
#include <openssl/provider.h>
-
-int main(void)
-{
-    OSSL_PROVIDER *fips;
-    OSSL_PROVIDER *base;
-
-    fips = OSSL_PROVIDER_load(NULL, "fips");
-    if (fips == NULL) {
-        printf("Failed to load FIPS provider\n");
-        exit(EXIT_FAILURE);
-    }
-    base = OSSL_PROVIDER_load(NULL, "base");
-    if (base == NULL) {
-        OSSL_PROVIDER_unload(fips);
-        printf("Failed to load base provider\n");
-        exit(EXIT_FAILURE);
-    }
-
-    /* Rest of application */
-
-    OSSL_PROVIDER_unload(base);
-    OSSL_PROVIDER_unload(fips);
-    exit(EXIT_SUCCESS);
-}
- -

Note that this should be one of the first things that you do in your application. If any OpenSSL functions get called that require the use of cryptographic functions before this occurs then, if no provider has yet been loaded, then the default provider will be automatically loaded. If you then later explicitly load the FIPS provider then you will have both the FIPS and the default provider loaded at the same time. It is unspecified which implementation of an algorithm will be used if multiple implementations are available and you have not explicitly specified via a property query (see below) which one should be used.

- -

Also note that in this example we have additionally loaded the "base" provider. This loads a sub-set of algorithms that are also available in the default provider - specifically non cryptographic ones which may be used in conjunction with the FIPS provider. For example this contains algorithms for encoding and decoding keys. If you decide not to load the default provider then you will usually want to load the base provider instead.

- -

In this example we are using the "default" library context. OpenSSL functions operate within the scope of a library context. If no library context is explicitly specified then the default library context is used. For further details about library contexts see the OSSL_LIB_CTX(3) man page.

- -

Loading the FIPS module at the same time as other providers

- -

It is possible to have the FIPS provider and other providers (such as the default provider) all loaded at the same time into the same library context. You can use a property query string during algorithm fetches to specify which implementation you would like to use.

- -

For example to fetch an implementation of SHA256 which conforms to FIPS standards you can specify the property query fips=yes like this:

- -
EVP_MD *sha256;
-
-sha256 = EVP_MD_fetch(NULL, "SHA2-256", "fips=yes");
- -

If no property query is specified, or more than one implementation matches the property query then it is unspecified which implementation of a particular algorithm will be returned.

- -

This example shows an explicit request for an implementation of SHA256 from the default provider:

- -
EVP_MD *sha256;
-
-sha256 = EVP_MD_fetch(NULL, "SHA2-256", "provider=default");
- -

It is also possible to set a default property query string. The following example sets the default property query of fips=yes for all fetches within the default library context:

- -
EVP_set_default_properties(NULL, "fips=yes");
- -

If a fetch function has both an explicit property query specified, and a default property query is defined then the two queries are merged together and both apply. The local property query overrides the default properties if the same property name is specified in both.

- -

There are two important built-in properties that you should be aware of:

- -

The "provider" property enables you to specify which provider you want an implementation to be fetched from, e.g. provider=default or provider=fips. All algorithms implemented in a provider have this property set on them.

- -

There is also the fips property. All FIPS algorithms match against the property query fips=yes. There are also some non-cryptographic algorithms available in the default and base providers that also have the fips=yes property defined for them. These are the encoder and decoder algorithms that can (for example) be used to write out a key generated in the FIPS provider to a file. The encoder and decoder algorithms are not in the FIPS module itself but are allowed to be used in conjunction with the FIPS algorithms.

- -

It is possible to specify default properties within a config file. For example the following config file automatically loads the default and FIPS providers and sets the default property value to be fips=yes. Note that this config file does not load the "base" provider. All supporting algorithms that are in "base" are also in "default", so it is unnecessary in this case:

- -
config_diagnostics = 1
-openssl_conf = openssl_init
-
-.include /usr/local/ssl/fipsmodule.cnf
-
-[openssl_init]
-providers = provider_sect
-alg_section = algorithm_sect
-
-[provider_sect]
-fips = fips_sect
-default = default_sect
-
-[default_sect]
-activate = 1
-
-[algorithm_sect]
-default_properties = fips=yes
- -

Programmatically loading the FIPS module (nondefault library context)

- -

In addition to using properties to separate usage of the FIPS module from other usages this can also be achieved using library contexts. In this example we create two library contexts. In one we assume the existence of a config file called openssl-fips.cnf that automatically loads and configures the FIPS and base providers. The other library context will just use the default provider.

- -
OSSL_LIB_CTX *fips_libctx, *nonfips_libctx;
-OSSL_PROVIDER *defctxnull = NULL;
-EVP_MD *fipssha256 = NULL, *nonfipssha256 = NULL;
-int ret = 1;
-
-/*
- * Create two nondefault library contexts. One for fips usage and
- * one for non-fips usage
- */
-fips_libctx = OSSL_LIB_CTX_new();
-nonfips_libctx = OSSL_LIB_CTX_new();
-if (fips_libctx == NULL || nonfips_libctx == NULL)
-    goto err;
-
-/* Prevent anything from using the default library context */
-defctxnull = OSSL_PROVIDER_load(NULL, "null");
-
-/*
- * Load config file for the FIPS library context. We assume that
- * this config file will automatically activate the FIPS and base
- * providers so we don't need to explicitly load them here.
- */
-if (!OSSL_LIB_CTX_load_config(fips_libctx, "openssl-fips.cnf"))
-    goto err;
-
-/*
- * Set the default property query on the FIPS library context to
- * ensure that only FIPS algorithms can be used.  There are a few non-FIPS
- * approved algorithms in the FIPS provider for backward compatibility reasons.
- */
-if (!EVP_set_default_properties(fips_libctx, "fips=yes"))
-    goto err;
-
-/*
- * We don't need to do anything special to load the default
- * provider into nonfips_libctx. This happens automatically if no
- * other providers are loaded.
- * Because we don't call OSSL_LIB_CTX_load_config() explicitly for
- * nonfips_libctx it will just use the default config file.
- */
-
-/* As an example get some digests */
-
-/* Get a FIPS validated digest */
-fipssha256 = EVP_MD_fetch(fips_libctx, "SHA2-256", NULL);
-if (fipssha256 == NULL)
-    goto err;
-
-/* Get a non-FIPS validated digest */
-nonfipssha256 = EVP_MD_fetch(nonfips_libctx, "SHA2-256", NULL);
-if (nonfipssha256 == NULL)
-    goto err;
-
-/* Use the digests */
-
-printf("Success\n");
-ret = 0;
-
-err:
-EVP_MD_free(fipssha256);
-EVP_MD_free(nonfipssha256);
-OSSL_LIB_CTX_free(fips_libctx);
-OSSL_LIB_CTX_free(nonfips_libctx);
-OSSL_PROVIDER_unload(defctxnull);
-
-return ret;
- -

Note that we have made use of the special "null" provider here which we load into the default library context. We could have chosen to use the default library context for FIPS usage, and just create one additional library context for other usages - or vice versa. However if code has not been converted to use library contexts then the default library context will be automatically used. This could be the case for your own existing applications as well as certain parts of OpenSSL itself. Not all parts of OpenSSL are library context aware. If this happens then you could "accidentally" use the wrong library context for a particular operation. To be sure this doesn't happen you can load the "null" provider into the default library context. Because a provider has been explicitly loaded, the default provider will not automatically load. This means code using the default context by accident will fail because no algorithms will be available.

- -

See "Library Context" in ossl-guide-migration(7) for additional information about the Library Context.

- -

Using Encoders and Decoders with the FIPS module

- -

Encoders and decoders are used to read and write keys or parameters from or to some external format (for example a PEM file). If your application generates keys or parameters that then need to be written into PEM or DER format then it is likely that you will need to use an encoder to do this. Similarly you need a decoder to read previously saved keys and parameters. In most cases this will be invisible to you if you are using APIs that existed in OpenSSL 1.1.1 or earlier such as i2d_PrivateKey(3). However the appropriate encoder/decoder will need to be available in the library context associated with the key or parameter object. The built-in OpenSSL encoders and decoders are implemented in both the default and base providers and are not in the FIPS module boundary. However since they are not cryptographic algorithms themselves it is still possible to use them in conjunction with the FIPS module, and therefore these encoders/decoders have the fips=yes property against them. You should ensure that either the default or base provider is loaded into the library context in this case.

- -

Using the FIPS module in SSL/TLS

- -

Writing an application that uses libssl in conjunction with the FIPS module is much the same as writing a normal libssl application. If you are using global properties and the default library context to specify usage of FIPS validated algorithms then this will happen automatically for all cryptographic algorithms in libssl. If you are using a nondefault library context to load the FIPS provider then you can supply this to libssl using the function SSL_CTX_new_ex(3). This works as a drop in replacement for the function SSL_CTX_new(3) except it provides you with the capability to specify the library context to be used. You can also use the same function to specify libssl specific properties to use.

- -

In this first example we create two SSL_CTX objects using two different library contexts.

- -
/*
- * We assume that a nondefault library context with the FIPS
- * provider loaded has been created called fips_libctx.
- */
-SSL_CTX *fips_ssl_ctx = SSL_CTX_new_ex(fips_libctx, "fips=yes", TLS_method());
-/*
- * We assume that a nondefault library context with the default
- * provider loaded has been created called non_fips_libctx.
- */
-SSL_CTX *non_fips_ssl_ctx = SSL_CTX_new_ex(non_fips_libctx, NULL,
-                                           TLS_method());
- -

In this second example we create two SSL_CTX objects using different properties to specify FIPS usage:

- -
/*
- * The "fips=yes" property includes all FIPS approved algorithms
- * as well as encoders from the default provider that are allowed
- * to be used. The NULL below indicates that we are using the
- * default library context.
- */
-SSL_CTX *fips_ssl_ctx = SSL_CTX_new_ex(NULL, "fips=yes", TLS_method());
-/*
- * The "provider!=fips" property allows algorithms from any
- * provider except the FIPS provider
- */
-SSL_CTX *non_fips_ssl_ctx = SSL_CTX_new_ex(NULL, "provider!=fips",
-                                           TLS_method());
- -

Confirming that an algorithm is being provided by the FIPS module

- -

A chain of links needs to be followed to go from an algorithm instance to the provider that implements it. The process is similar for all algorithms. Here the example of a digest is used.

- -

To go from an EVP_MD_CTX to an EVP_MD, use EVP_MD_CTX_md(3) . To go from the EVP_MD to its OSSL_PROVIDER, use EVP_MD_get0_provider(3). To extract the name from the OSSL_PROVIDER, use OSSL_PROVIDER_get0_name(3).

- -

FIPS indicators

- -

FIPS indicators have been added to the FIPS provider in OpenSSL 3.4. FIPS 140-3 requires indicators to be used if the FIPS provider allows non approved algorithms. An algorithm is approved if it passes all required checks such as minimum key size. By default an error will occur if any check fails. For backwards compatibility individual algorithms may override the checks by using either an option in the FIPS configuration (See "FIPS indicator options" in fips_config(5)) OR in code using an algorithm context setter. Overriding the check means that the algorithm is not FIPS compliant. OSSL_INDICATOR_set_callback(3) can be called to register a callback to log unapproved algorithms. At the end of any algorithm operation the approved status can be queried using an algorithm context getter to retrieve the indicator (e.g. "fips-indicator"). An example of an algorithm context setter is "key-check" in "Supported parameters" in EVP_KDF-HKDF(7).

- -

The following algorithms use "fips-indicator" to query if the algorithm is approved:

- -
- -
DSA Key generation
-
- -

DSA Key generation is no longer approved. See "DSA parameters" in EVP_PKEY-DSA(7)

- -
-
DSA Signatures
-
- -

DSA Signature generation is no longer approved. See "Signature Parameters" in EVP_SIGNATURE-DSA(7)

- -
-
ECDSA Signatures
-
- -

See "ECDSA Signature Parameters" in EVP_SIGNATURE-ECDSA(7)

- -
-
EC Key Generation
-
- -

See "Common EC parameters" in EVP_PKEY-EC(7)

- -
-
RSA Encryption
-
- -

"pkcs1" padding is no longer approved.

- -

See "RSA Asymmetric Cipher parameters" in EVP_ASYM_CIPHER-RSA(7) and "RSA KEM parameters" in EVP_KEM-RSA(7)

- -
-
RSA Signatures
-
- -

See "Signature Parameters" in EVP_SIGNATURE-RSA(7)

- -
-
DRBGS
-
- -

See "Supported parameters" in EVP_RAND-HASH-DRBG(7) and EVP_RAND-HMAC-DRBG(7)/Supported parameters>

- -
-
DES
-
- -

Triple-DES is not longer approved for encryption. See "Parameters" in EVP_CIPHER-DES(7)

- -
-
DH
-
- -

See "DH and DHX key exchange parameters" in EVP_KEYEXCH-DH(7)

- -
-
ECDH
-
- -

See "ECDH Key Exchange parameters" in EVP_KEYEXCH-ECDH(7)

- -
-
KDFS
-
- -

See relevant KDF documentation e.g. "Supported parameters" in EVP_KDF-HKDF(7)

- -
-
CMAC and KMAC
-
- -

See "Supported parameters" in EVP_MAC-CMAC(7) and "Supported parameters" in EVP_MAC-KMAC(7)

- -
-
- -

The following FIPS algorithms are unapproved and use the "fips-indicator".

- -
- -
RAND-TEST-RAND
-
- -

See "Supported parameters" in EVP_RAND-TEST-RAND(7) The indicator callback is NOT triggered for this algorithm since it is used internally for non security purposes.

- -
-
X25519 and X448 Key Generation and Key Exchange
-
- -
-
- -

The unapproved (non FIPS validated) algorithms have a property query value of "fips=no".

- -

The following algorithms use a unique indicator and do not trigger the indicator callback.

- -
- -
AES-GCM ciphers support the indicator "iv-generated"
-
- -

See "PARAMETERS" in EVP_EncryptInit(3) for further information.

- -
-
ECDSA and RSA Signatures support the indicator "verify-message".
-
- -

See "ECDSA Signature Parameters" in EVP_SIGNATURE-ECDSA(7) and "Signature Parameters" in EVP_SIGNATURE-RSA(7) /for further information.

- -
-
- -

NOTES

- -

Some released versions of OpenSSL do not include a validated FIPS provider. To determine which versions have undergone the validation process, please refer to the OpenSSL Downloads page. If you require FIPS-approved functionality, it is essential to build your FIPS provider using one of the validated versions listed there. Normally, it is possible to utilize a FIPS provider constructed from one of the validated versions alongside libcrypto and libssl compiled from any release within the same major release series. This flexibility enables you to address bug fixes and CVEs that fall outside the FIPS boundary.

- -

As the FIPS provider still supports non-FIPS validated algorithms, The property query fips=yes is mandatory for applications that want to operate in a FIPS approved manner.

- -

SEE ALSO

- -

ossl-guide-migration(7), crypto(7), fips_config(5), https://www.openssl.org/source/

- -

HISTORY

- -

The FIPS module guide was created for use with the new FIPS provider in OpenSSL 3.0. FIPS indicators were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/img/cipher.png b/openssl-install/share/doc/openssl/html/man7/img/cipher.png deleted file mode 100644 index 79b8b621e6aa96e74b6810a8fdd0a4b2fd97510a..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 81349 zcma&N1yCGa*d{u_5G=SmA-EF~Ah-s13vR*PT@&0bxCeK4m_X3r?(Xg`cZPib*510i zRktam=+md)^SV3}A}=e3j7We80059B#6=VV0H7@Z0Nn%s2K*n!PsYLEUvCVg#6$ou zkgu$^f;a$x3?LyQsO*|{xa8(Ztn&17He)ip=$K9Km~F(!og*|CKh<0%o|+0>^w6Vt zNsr@WIli4AxtY%(x``C*pXHk~PBtW?j@_<22TV|v&k|4vYBZ0*?#6PP@OAK8&*xiB z$6iwH?cBLe#x}8;EZ+?BR^4q5;RQuVP(lKu?(;}T7FDhI!zr{B zWim6pB9*J)Zlgw5#0XAY75=w9!q*JyuY!_4l^ps9wj;fZEt4JK}Wv19}#de^Dh)CfIDU{ewtuV|XNuyAji9Y2d@Q3*&V7=No6gGK%%8q1e6&&@1YbJAuD zuPc11MD~O&icLha@8_rrBN5p*Bl~3H5EPU*mHFnXYJ&1d5v=MZgf?lhO3gwrtCC2l zXv*5fMfh`B6!q`|_<#2hJEmo-yU9892JID((2nbhBqIF|_00OKj>)|9Y&yjryy6r; zVq5Cv&9eWdKm@KR?zbdMU%@%50%qI7qP`&4gN@&J0xJz9254>HK7$I+Os(yqVIP=R z#z1TX1uB#&X|L* z_U!H7pLNhLDr?9JZR4Q~yovOGm;Lvj(ZZpZk|SygROwq&;(zqcTd9K|8@%pCggic2 z&qB4IP7u#Urm(~>9;M~&Ty$gevOyaROK=0$O z>8c^(MV!{QVRxhnK%eWMQCVC#^v+Ye4Epp`6ozBj<=9hO zx@LFIxE#q*ZXWMoUwU(oS3{?}5V!~40&fEG--(83!`^&$5k8db<-fSsH`cN5X;0; zUoc}MTJN?~y{4}SDy4i$-*qy9e1S{vl8qkLAxB`oUH*+ZDXp$}$kT%rg}6}z*GR!hC7+&J@%J%z7UGVQj$$B`E|kqA zGT>)7%2Bd#$)l*QZP2`DKg^;bXDtrRD*Wh9Pyr+d7Vi^$y2}9hVCXX;j1-^mE_cDb zi2Wg1TgZzS{Z3Sb=^5)YI9NLZ^EB~LSyFNul*IkS1eqX6`;M|hi zepvP8&mBA!Ov`20P+0Wsxs>0?Cq@JI1NDTuxD;)|6yL`_zROI#SFYN?2g_&aRo1-Y zVNyRYncpSR(CyG2hKQ3aIg6%l!&3wo7MH_Xt1P}8^IER{?H-=OY;v61BXjZRE0UC1 ze>_RXXJm3_GOVYj++gCRu~Up3z{OU*)!HsJF!=!HTQfaG7v19%6B!9tTRlnF$m59- z8(5v@Y@FOcMW-I8iO0N-yHedKleys`?rcd=s7dsbH!)5j&-~a_&`9yX zNNjWHU#`c->v~;pCsMVJe4?ouNmp;j<> z-_*M-yO{(T!0jvch-6Et`MfXn*>n4$DX5FQ?rK(LXocHj>~a>uN4Hz2v%UmulZj!Q zWnDD7(EdJt*aX&ffL82cVdovFau|WiztH)QU4(;;%mY(L^V`b;_}-l6xtr{=p}D|| zo@cHABtP`@v1fKnQ7D4N(!SnUilmM4DK@3N#7HJ*2C(wv)9(%Q?}B}wA#+D*Tc_V& z8^oS54~#J%_A$q_bLb^JwTZIoIt+{s{uDp@WWN5C6~tDn?u z{e?60zAFXtsTVF@Hm)NJ&{PHm`?x=k=TRT?e(PHaBQB)r5oucjosz7w(JgL`DHWEb z=^lPvAQZd?mf2YG&zKw`lX-kv{s}MjOKCg9F)bfVR&2Xek?s;y$UL=z`l3TSQs_O` zzJN)S-BcciZ2;0HtYnSJee)o3w=BfHW5q$d)zW~)-$YbN125_5C*aZAO4mmbd^FS3 zL^T}7hef_F7x$dmkou;%F%8M@TcJZ>9SvW>F7d@9I zKgX*cks_MVoy(kTMvqdjC~a~J@D8}OGbwG1&o%fWH+;CGAQ>n%Eut@Z#wqS#vP`J) zDqr8umnDtNyrz|jmGbNIyYWrdS?{0xLf`2)wS#rXhDFE1l&%6eSzl`8b}zBxW=d~E zxP9Y0Vf%THp`GGbjyFKm%mXuU&$6!5MPS-L*~nJ|*MBqOUB8yYV7G_doVZt9(3 zoR=!t5E6C0xCYdr<^D7cZq{F_DD{3y=f>MU@0UoeU74?g{#q@Gk5`|Dsb@LWK5U27 z*DKnjAgX)m=JRroFIjdanlwyOwwpi}L^p_}Oge4tbz`a|^2A^--FnupHx_$B)mRXk z-Us%XwCtKNy?7H=ud$|gs(v3TO-*E_#1HidyEIJGq7@)(9KE;0@Yil#AhGuObjpZH@1tfU`AOAiH zn-TW3PRSa^*xz$1YWStN$N`e_%}^wZW=(iW@DRmFfM(JIeT=2CdYT4;Jel6pGywjB zfAJ;8425w3_!5%~S@1zpJhM9=gk&zC10C*8$BwG0?YyceC);_?*@_Y7_wA4cG zA?h+I~KIEYWh<$d%DAg!jco8z}=z@~v~neMOX~g_PxKaA)1M;Sp(LRl_=tU%x&6V>gCjjo&OX`V=%)nOa(lpeRg(3u z_FpGQboRi?HY^)Ntb)-Q*z?g=*pfgj?#R8bbU;M5CT8~_4?5j1m-_K-P@dY`oCNzkd*(7XSq1*m1is-e zIpIbgv+cx!-Z*$y1+?~?%*9!(eS~w&;=B&qAsL%dB}PLJK5rtBl?qXi=_Vvqd}&h+ z%FJ= z(l=cZW2LxwL!|k>m^{BMc79M_K1n?W&69NNuU%R%{)4~=jgU@~WWPx$oI7FDEhmJb~@*q6;u$`0LG zh@0S2b-vf<^6)xr;wu``f{P|l^D>q4iXrgX`z_J=J9K&a7OR-6p?68p2y#TmuTWrP z*lMe{y~_yI8FAKVRhNs82lZDldfiB8^(tjpzJH_fy*V7S85JjB3wV_jdy=ruKIXSGyOXED{|Orhsbb?za`Y!`_{ zk)BQx6-n=e!gw7Juj+%KAmUGHzey))?J}+euW#{jyOT}M4g$0bK_{t}y3@?_<7?Rfg4hw0)pIO% z5WRHtk<}6;Ybu6Ol(5yW%60rv`J7kcr}QH$O?|B1=h;4{$#b7mFFyD=GzFo3Op4GX zm9`B@Q?Y!kB;e&mmOWj9zE};4+nme=@v%D3VP^x%!I#62S%Ktg;k2`8tQ-W0=O#?A z0ParRbDKBTF|U*;c+-Y2ky(E5d2VxMs#J{r>tB7?9slJ$ZHK4c*A!kphO*}3IVEIb zc~dpQD?!bF-lJ{K+p1X==DzfWudeE7XoQ1mpE%x_Z7_10sxH~W)2p=ughXzyY~i(r z>4qroTY)C3`AEpLbs?O3R6#=5ud+--K9lY4k(A-ARdoU3LVEuz7i2!(wU_Gx4G5c_ ze(F}68`WUqhE7krLubRUyaYL)P}?;*I;VBs_}O$f(MI8L%drC2aRG(rDg(@ z0s@>ot*@E})60&Qm9|V|pAu=*{NrJ-&J5wJg0-MZk;ZD`e?fDi1IAY1_V$q$bMm5c z;$gDf4dpeS+GGe+tYv;}&2b#u&4=Q{7nJOi$abow%RN(d*0g&I5Qr#kRA)LyHu&;F zDPO*5aV;Efq!abeR~jr}N9!fKm9 znHu`S?^E!jwg}jNXj7=Ess!%xBI}Y6muf!!k}C78tZTR5+vm6O)>3NHE)=tD*DaZm z+zS)8eqt>jX?By@V$dSzB}E8qy1%7_lcO3SmMCA}0hC<@Fwfb>+_2re?&PDgQ z5~ph>Z`1mCaErGOoD>eT@c=CU>M_0#U^UuHtZJr`SpDfY9E0ltW4p_C1LvWy*Jslx zZO*6oxZ4qj5$MzT$2%=Mvp+F#MDQPI#1)S+*A94N81n z2+|m9T=dJ16xeDSUT-=T>6gJ(@=4vviKy#Pz=t9*&0qqD^&r(zVqRYra#(?L;YB-J zj7_>1irk9{i6P&O8&jA!5LBC~)zzI`1Q_(X`=q1&$mHcR>vxiICZk%W)eqz2mF7Wu zM~}4Z9ae;kJB`+U+v?DCx5IC^7fZ=wJHjyBavF5Gw~$E7Uv6GqhLRWVYIU}r&Rsud zMfT$9^JD(2{|Xkjq#W8$6`$$6nv)hsC;#0~I+wlO!{4M8CZ$jJo5Z8%4a6Wd5ts1n zJrg*UC-Of;oX@r@*KYZ_vpuXov*etsR-xm$zH6A|IM&Tbk}J^}QV?#mTdDt+m_6Ju z@&PM~=h6gVe%zEv&lJ&kc5m_dc2xN8c6W@2Z|5^0BbB>AxQ3%!s-FqOo$j3zsZ3aQ z%2GAU>W--J(vDH8l0*t}DT0&$(mhyVnF;-M?THYpN8Vt}NFLH?$r?NnDiRpK`Ho8{B{)pTcQy$Y}Ez1d2u zRSf=bshN|Gw0Db>1-|d(UE6CR#|__0KE$B|3x~4sAl$j4<8J0H9%rjwp_ko<;m!ch2dOP(tc?8 zOigh%*a^vR;By|BocyU;x%`$|H-&FtrwZEJlWnoAV7WG-^IQnyPMPnoxY@m6|KE#r zni{m8;(-?`C+tM0J_&G2xUoMIpX*)^9E`MJOVFH>jd>Wb+!T$(agC~czA`X*RjZUC za0A&Y%IE#r4FDdeEgIm(`&xJLZec}0_>9s; z4f&)@qua~r^YhuHQmJ}PVB*fuMhyQ;2sP;wJs=F%s`=;XwpCk=t-e@C!p#jn`)OUI z^`s*s)AbCk7JRtrh@GI>wbnq6;KF??v4N#CZsu;Tzs>>WvdriL+AtvSJ+T_P)7_L& z7QZMb&Qw`DZguXxxkdS0P}?wX1lb1q9or`bud15Y`Gyf6kr-xd}A7_w%o(u zyXb$`61C|(#_Lq`-TMNZuH1e zMAvHQ(}C~7V%)DDZFk_Qxs6fv2N=v40%Fh!Gc;l$LkzVc@=y0G@JSA`y)PDWi&({vc(+UL4~SHPlh z*rd*q>v2j*zmAvzbC{Ou)mTb-15w?bp4VMSQGetr@5NIqI+@rJEh`+p)hsjiPjtLi zSI$?`xbm4)8K!ssh1!)@!-~b1%a@4m%aZP;pzj0F#ki3xlQ~KRra@`!^NM}$jQ|y> zxP7+$?RGXu>!ZG+^Z%}Md*rwYUG9#VPWhpTVJ=~}-+)U(@I<6HuZ9C^1z=0SM4jH9 z_~)r8WZA`N3RAgGXcd6IET42}!RBLm;g*X2f2i&8_^modsZEMcWio$=HIubNanhm5 z4$l~8EdNUXSN8ATdxML9Cw|-kYK378SMp&aDkY6NADXnHK906HVWCVr=hC?oK1@=0?t9VGi?sYsX4nr&MaIv4zLU?AlCI^4mq+ zwh71G<9A7fI`E$4Xm>wsoNOT7BadpxctktZ7DneO6##diIYsVGWrx(uMmF(9?36gJ% zwJ-q1Jt_X|(@OK`3ydf%qm zMn6(^z5dU&ciE1WEH+ZNlLsLA03qzjYYur`3k`O55#az2USD)Oxr# z{2v7J8(fFD*0?wlvs>aso^y+FcOa97f41^3FC4!n_;4#5@B+A&ntGE16pR+>9zM%n za+F<$`=uh$MAq7%$^1uyuuOh4Tc&S3#*Hm4QtIgtnx6d z`{ywUfX;V9zc~r*Zb$Q6?0{qndykEL6?iOTd)-Tv8|C)!-7Xprj#L|IEPt(IOpci5 z{t6a)jeRdp1o&98roytFrC3D2=eKL@{59t!<~cWBR^4yW+YmW<@HU69n+6O;?+^sC zj`to*i+paH29NE^&$E9nEceYAdvEZPE`8JdzjhW}irVQqno(_Cv(C9{a_b=WqA*6< z;3ytsvJ(1sDWIaHk)x>Oam8Q8O#z{yAIPx% zjpgg;iNodOtEZERD5{tBJx7K6i#ESMDUZuthx;4M=B{@l;JclAec z5Il$8JG^JZo&SPje&E(%+E9C6DKdwa|;xVQ$4f>Hs@F${V>6NBWiB_g7 z!d2>X4JE>Bi(#`37pE3M8?jkdSHa<#V0J|D>8CT_sxd?Jv(0 zVizs-LmpzLL^rm`rK)1-gQo6Og)P9tc9Eo;yrLHH0>_|~ zgu#RPthZofWAcwI+Jy_7>Il}QzG3c@$KUi}Y8iOZJOM0#siXae#Nfi5ox{3|=mL$E zmegjK^K+oL!Xcif3~nS5~)NIS_u}-0F3%fu`v4RIg8oIiBRG{A4l>^MxdYail52U z7aojfT#gdu@90j=R<%W#zkGi$K%MhAeiKSvGmY#B)d3}OwUT&$`2wY zp~7sA4|^K%!}P_bxq0u2f9b3no3c6GOy1wWaY+!Z-}tkMQ@_LAbuuIYAW~ z5WU+ot};~MBb+gMo}YKaZsO@z(W>fxU@FP*-A^ZT(z#fnlr9RpqWTd(qLMaDutEn$ntz$Wj;R~)i$N>7ybH{ z$nD)mO_r3PFROS;2M2J!1ShYG zeDFBY$=dt>(9g*KZ zkZF7QY1UpU#M=XuZ7xGd78G@h#v35(Y7c6xNd!!;5^{Fl|7KAm?buxH7ioImukuKw zcVV&ZkZ|MF<77=Moag|V!aH6~$v*ms%u2}DN1G#ApsDkR(a5O7ejgvcc<}Dkjc1+q&NTU^ZTKT%* z)O^AyLG-)OBC7HhPnJ#sDP_reYBI4^qD2;D-g+?i7BZKt-HCq3yty&?J7rf`h%iHB zB7){mR+#wZSNdg3Ec5e9EMx3N>|Z52&DDpAv{B&EaEaICZ)b;tOjgZqGuNDAX~o;3 zil`fz{SO_L>)=5to*|^;u#{Fja3H0YRxq#?`bOv`J>osNj!Js*G?4Q5ABFF56*SKI z<%JYpd%Zk@u(kx1%0E&!$l7CCavMU^%S5*lQQz)whylMK{XVm^J~v#l!--){X9|VR z$RWKED+wj;h7_lguT3d*9nD5hIVX2sTg25p?;0YWJ|EGzlSqR0iSOMg6O3RlL_oFn zxi~Fg{c%{>MZF_ZI#CG+*`9!D#W6SS$N`%JmpU3kboie2>wXG4nyrTv@Wt4~WdTm# znr}CHx?$**WB0#xM{*ptRFu*?=U5l;&`Fdbp_pIoed$ReS3;PW5~DrG7Ca7jP$FS; zCWj=H+*M%sM7~%`$L$hxusJ1pCh*)bPqXC5*93XJ>`>X0I9->GzL@uFxZJ8yIHFJr zleyE9AM#to6O5uJMW_q=fO;H$xY$hBO@pNdCJ>lWGv@06yEYM*iM#LfU1Vni@Lr+S zAQCsGQ~3AVZ;?j*ig({h(a?2&Ff0(O{cM9ZV#ZF7`L(G13R{rwxil^K(h|t`n9+&r zrvUQw; z`ZeHOR|F^IoT}48U*dGp8V0UivzEhPo+;FSa#62#W))L{$w9bk13b-0kR#lmzT1di z1&(62_Vg;^GSa+`pp88sIZ*hVGN2XJ6RxqXPhDC~UbW68sZT_d^kzR(PqnsoHYR+I zN|Je@7xt_`{_~er(|{)^)N@op(r^{)ta1Z|DnkM=)eB)v&#v0wt+t)v?g7l$+`)SU zLNVwewxMLWTnM7$b8i1T0%q7$+QfGKy>btX-1|vip0$2{39H(i**Qpe?I;G)T1b*f zhvxwt0%yzQjdPWl2oJUFYlBJ3ihIfIfum|aN;c*PVZpE;>C^;WK9=w}VSftm20o6f zCgU4IT;w%gRTl2h27N9tVLczajKNKt!Tf8OpL*SdHBBDW%r~~o0sJgyJ<8@|Il>nN z?K9*0MdMOpB}g85VB;2{%f9+Kso*ygEp2yR;V!s)6 z1Eti`Q4}Xmw+_f0u+!fcJGAu?*(Y;^C67Q_5=Vxw!kB~sL9d1zz_IcMAR5iJrG3y) zK|vdXc{fYy$e+beu6tUCeS^!LxA&$;tV_|ZQ4M3)5Bh-`!!vqPRrynkkJ;6!eBAeS zinOk_xI~+-U$2e=2uT`yEX~zciwuHTctdFF25(q=!V+a8oGDk%kKDm?YTTG?8k=A$ z8wx0!;DLk4&8z$SP2}S!RVNKcC9MME8`}(B_`~cKr7%$YJB|62|LW7 zvOomloq2yiCiKQi?|lQhQS|FE!9`MCbCh@lMZcJeKkrBQNZcu2U;PY#8pdj`40p7; zl8)u|tx}2DskQfKaCt(Uv{>6qn~0oGvHbZDvXaaf^PDc|m~;gh@aO`U-6Jh*r7P%! z>>dkPA=OD}ht}Hj?%-Jpi;@us5_|9_Hf9->!NFaDSr3_oq!0UZ80!!{xcIrU5c@pF z>q+;*0&e{{v@|z;WdxH?j&DJE5${0uIjK0oSeTwl>J9u_($W9=bU1`N;D?Ou1 z)5vqOb~o*eEIuAGVC%29BjRKt80Z(Nd|4@g_Y*Y5NRm0s2loe>-ggWBFRUA?%rsSB z@weO2JxC5Q_ohcBLgfe{=FoiR*%7ri=5j@_vN0C1X zri0N?Q-@WCIitvqHL&=lEO>a*Py5T_!OV|{3~v~r#;Bqyp2j2xibrr96|$Nub(ReF z^BJt2eIRrv;mm>~Y53eO%_@SP3n*jQ;4NCbiY{8=aUl!55lg4us2^IqFUmRP!;#z& zaAom~DZLC%aj5M$2$j*S2!NGebD>Q5)G6^1xYx0E8~YSkZ~u&EJCxyLlxE6uig z3M~<-i2UGxk_XjxHf|C}Y@LGFa=Ffp*0eBV{M^`m7oaIX0Ddu={sv|Oin~tH++*Pv z4{CRRvJyK9z7xg2Azm4?ZF1FJ=Es?}<#msY5$M3M(ezy3oR#cziJ<% z^;pV@Tq&<+{LJ_T8Ia%^zPj#+tL#%eI|$&CiNL>)wQyPckmmK(+Uc*B@g5uxYmh(N zZTPu&)Zcvn*ZReqn1VFL4cQ_6oVlMO?QiW#eVTW_|Lfm}@9n>CO?cG}c4IYGkhWp8 zSIlPQ|J+9TcY6-3{Fe0K=U{ZJPcr!GUP}L405OfWL7*i&_;j!5_*(@5mDVV{{Q)-8 z|5%gy?`+>7{^yk)iLZao(V$+^ff@F1)m+-^A#zm&I>0{Ub+ewNp?|b%AiQPx-xii# z>4mcrf^Q`aLsD?r$1T2)j;>NuGjKG5?B+=Q&ulbM4!?q#d8z#F*>Y9f-RGOzzvgU@ zBL@VaoD_khnB-R@T=gAn-r-^Q#kTpOkFntC@2uS`NzH_i1Y__E62UWx!X#GDrGVgS zJMv*P#iH^d!z+PHuQ`Ho?iFlWjHryhv>c|W9~nQODWW-4v^(krjTFEKW-y}D+(vVEW+)Yaqmz;C6jzJa`G{>?1E(n z9O3*iT)N;zDbIpH6!vs@)dRv#u{jCC9FAQCPg{~V{c`7;=D>IW62MF3&--t z^;^wMB=qz2@S^rl`l03UT0WiDxEQ|~{=eHBqK>TP9zwP-yNb7#kxagS84G*h~jeJdCeNimS? zUCy_-4<3VsJL+hXFq3oK&xdMiT9l|;?Y@7P93)QI8@7y6-R+7H|Nh)5+2@CmilMSm z+!+Q1Q9@?IUiAhg%}_=v@XV$tLKO?r2~0X3dCd!cKBL|;tfsg<_<}-k54E}+$n!4X;1SXG zU4X%mF!BSy#dV_4WCo~4m>z;z@IxcaXj?IIEK2XxRU7j zMZq@-_xpLCMF&~}rYB4{xdS_a83xs33g&Tl)~(^JW>2b9&|9V=JNO$K{t1Q~ z-KX+q?F~vI{v(=#wHiN`m>(rx5|tft>oI;47Xnddz!yZ3pzfvtDX_4|S#&5?Ir+Jk zM`nx%=41PJ=mxxY*~4)wtaUR>Xu=c04IW+otOj-hW*sFMPbRj)vZpVQkoCJ0?qcx>bf?6Wjaz&noxG5ZPoSfzQjG z-VU@_TJ9WY^E-ZdptQh>4xzQ6=WI|l)ir-oC+hQyW$jT}V26uUt<{HsIi?$^g4#n%U&f&|dx>mPxaC8=y|DCQpM`Hk0w} z86dQlZ}$-Nv9(hbM59-M>#@fKVxh8U=RflB8avMlX{WtT_j7&Pr z>iCo{)KeL%e>Qle-t8(8(Q&C4&!Wri)a7cocc=-5&CQ+8y_GDX4%_{>%9r`K)~YqU zgkTH$j=FL%@kbE&BOy4M0a>N{4>=#^cRrYWOnZ2@S_1(p%GBz&)_#hUGSP)|f6y`x zJFE7d4#`sc0~R=Y{Y1v|U_11s#iDm{>3y__6H4WD;vblzka<3x`7yCzzT=CvrA6*0 z7M&hZVJ$SKYd0Yr2DDW9H}@qDK*ax zL!@S68G9hTRf7~JX@J&9&$_gSl}!G%X)%B5xeZyiJb++v*rB!{>e#^WET7Wnmu(n6 zmhr47@hyD-zE}s)8R{6&F8UD0@c^Tym=y34x=)eDmNAP3skjOO%NVr`M#o@-@l%CT z68bMJ>%E17u^CDIK)6(^j^a8!LB2;QsE&=veRM0g_uzI$1ZUrimsb@OsA6yg;Kn`r ztN$$4b*{zkEPswc^K8!1&+?Jsqe2ou9Nd!*+gFW9EbE^nk-0KaI;TG;?ETxU+|ncE zao<;<=wd~)Tnl=*jcN=$Q)K)7pyLe|EXH$e)tt8ScW(JR)s`@hje;ZGpT-rodxzZN zEuJok!^>d&su5&r4Ja>l7m6N!{+m~G&{=&bRnE|IR$o)4^3d!!rK`==k~8{cs^Lzk zHXChvu?k!Qm^~fo$#!jl5v*W$do*AL4ziXItRr3xC9HAP);ziuD+Xsv$PsJ6mFBR~ z-;*{<5S*3eOD?ic$6U{oOHQTpkOm^#x0GDaBzygxK3kob!_!>+i2Uxt9Tp;?)zmVd zc{!-2Y08odsgQ)T?%fJ5&EV!|)LUWh>T(x0TRuV?kB9dG(mwYljAww_{_n@0Omeyw{W4K|{htxI>O>WZk@ zM~o@PijzYc)v*JS&xthij;-L2wU7&@_DEq+AZN;0Etohw)*@%Zg8fp!h`*_pT9e8~ z-cs^>Zqu`+5NDqi5wjDv6)E%4QLZr}k7g2f+446Wc^T!C?|NVXME1V>JTjwF3;sOT zpBKphB;Pf`XnscVSW+0$!hOL1XBPI=XCd9;oO@NHN+1+vlN-Z14<9xDRV zW>0q-u&ht+iEUwQ$p}pXy!<;mml&_3;x;9t6C^M=Ztf1Z#^>0zSAN`5iE&O1A;_IY z^hkX@iHtgU7_r{2j6OFL&c1oDUV_UM%R8N$tdB@!k+`0@$_#j*c3N~b)68F!xr(S? z)U-O51LV-GlCA}V_P(kVy;)Ak^4iFYyDv0jD`2?T$d7OmJb%kF%iW;@js|p5$Wk?G zg|>FDV=-DEIA;@StY*Kp1wI76?$Z7Wz^z@PoV{S0tp6tYKn36T`>7x}x{3!dnhft5 zBVOeR&zDsJ-rlXI7pLbHmXiINM9ZYgtii2L&|tkusfm=CvBVeDXBSaYmH+zfhKHST z^~cAT?{@r%Y#&hySd`X3uPP!Uku-GQ7fh9!Z9H3zO-qNFx*@0K*B0;xaisY?xm&9N z`18DKY_c5g3n|4EX%HjdSZB-g%n=;ejA$&FF6;+(D1mxu2S?5J5u^_?FE2R|8&uLI zvwdL#l0Tm)HeT&#V&SCd2+?<^+CJ9iew1iO;qp@-+c$RBZ0Jv6EKrTITcI-08K5zP+9DgLW7 zAn~^UChYiJU>PeQlt|?NimnZNE%DMJ@J_smk8=8DaW?W_vl_}ewshbhTLWe)z-7{Y zl;YPKBmPx>#={Q(PJ>R(gF0~F&6D3XJqb_B_nehJ8dLOP0z>~s6a7{InfdbK<`u)c zx!XiSYtDJOw2K2DBRipcIIKi9CFm_gF z^2%hw!)*vQ6jYuCJ^pTEtLvM2;?D<%7%*%OH__+rZ{hQo7`fa#=cq*4{amWNfnrn% z3|?;atCzW!2hOIRhnI~C3uAT{j3zORcOj`{8XO2A%AfXijN@n&Zi>Y60aX0ostMPt5k)QaZmO0wq^KExufGug$FHMFqp-1P1cv9)m5u+?z4m>AzYdGc&m zwbZbg@UekmD8qMY2lraYn7LktE-(pWW;G@h+uB;U*Xt=aM(5=95fm7fGDm~q3&CNw zwTX@{?yk6Bav%F-%G#^-qXMN`P3-yAL_~hgD#M70P_!IWnN^}PoVqm_N<>Qk)Nex= zzJ4M3@-P{R(7L{IuP#1~?`4KoM4AMY3#mFIrHAmeSLPr zI==64;@BKHlho2g*C}3M1M7YL>Rv%i?6D5cj8PO32ha)WM#8V8`M^6;Sb= ze>U45_3H13Nd1ZG3Mi&t;~9cbWZZ?Qo~zL1&cIsYkhUA_uMrtLzHt&mUlJ1FmOu|s zpK#k%Ry}ToEX}Vh=}J<(I#5g&{!Z?%F~yqR9Ce4e?!Zv+x)2Ac80p~VYmHHJIjKt6 zFwgPH`3Byx`Mg;sUX=;4zCU@fP^IAta()S?D{&V!4B_XBWoxp@w_;YsdU%^9NAdef zx`fWs!|u60M*NDe;-z#=T`!_bnx{+6!a%sNeYC4sr&{)`DH%2%6#zm`Gh-K@+a20n>Eba&RF#K6C@8-mc|7W zRqi}-zC#+pY}(nG3htgQ4;?mA7khsn?nb-_QtMmHmg4R}iiZw5Kd#6JOk5pY^mJct zo~lL~p*=?Q*zB$Tgkrh$?!&Zwzxw75{5ty0tpU3CW77-H>PLpA$(%o}$tINBy7p4j zaGts57CVn89A55c#l`SS#eqHfL+w4^vy;ttJ`TS08*<(VVV&Tr7ocQ1-@*Gk)kL(h zVch5{9(+D|3&$A*K%?dkR(aUpkYD9tpv!02_ZcbpwhPg^+ z>H0QDOsbt#rcBm~`AnUAwvuAyvL#ny#0wwf5JTK94&i|6u!I$JLQVUu4o2#|H({#} zRDoD#2rot|y9EZEZt~2v;;BhIjxGbn5;5qzRkEks#*vYRO2=;e{)S=9>;&jMFmx=U zKJiaVAec399wM<-qSzC~H}wXcpNTxTjE6T40N7RH`xhF@b-x|zBRHezbC|AW9hJJw zN6z3IVFAN-65sYqPguNUb(_2Ip@+LXK91~oL!*U#3XhOY_aZpk*T3^@2P?+hZm2I< zF><~}q)=A^p=Pm$3%1V|VSIhQ-K|v3N=!N7KXag_($XvmmEuTf9wMfNr7xoX&S&z$ zzlE`7Q&loTQN5v9`oORjFDLDjeRp}_1B22XO6v3TUHPY9hzJdv0EYfpSD6p%|APgv zy3@gp1Sku{o z5!0^`g&l_W{!UrT1j5i`)>9(nkfE>&q%0Wk81b8puE@`H5zJ94w&~nj20Ik)tnBUB z@C7MHjjJk><*dzCsT3>bF|(6A6}vbpl};^$Nx8$hq9@vUNDOA0El3$n zWtmc3cVDlsPJwOwVp-?>E_|GnG+krK(&LPWNrEX!J^k#3q(hD&$xUPaBGrm{*e#KL zu;o{A9%rtS3G*A9){a3Hl#}{E*u=D(?w5i=F5(?aLc3#FINVQzEw|`YDp$dm5gDOj zZ*4PNsN_%F9+{d}*XIOJQc6c)lXO0jHPfno??n;eqz1d`^gGXTuu#d#$K9z7Cc?r| zxY5x6yZRYIuR3p)X8nTyyTqL*D%aTJgd&ASAXhWl6bK!?e+AkSZz{10x=Mc@;Q%}S zZ`)U^`0_#`{#=ZxIS1*YuFr8fzQM_3UQ7x!A27bZUknn$Y!&e-UBlSCnV z{Spobh0YJZ{frVLFOskNLcvvc&z7&t&UyG1avOYUoWIw@tW*P2#D0}k&#iDQ7)w({<;P7f>gV2)5Sdic?nj%MAmZ5nUTwj- z%Csu1r`%T+jI|Pz7-gWS5>?stAGgg)mO(zgJATjadS9gh`Jw){D^Q;C4LcGC*8dWT zG2AN5>bopW@FxFV;y4~KnNT;-*x)B)sYh6g=y05|AdioKka^EUuE-1_e8t$I2kFXVh)GVx7iW)IXFkIeI%c#` zAA;lP|5~gyH<;}H$<@1R`o}9z|93ZP0C60Iuv%#ZBJ`N+ zD&Qz`FcHK+*OZz0>z@gAgHZN9*^V9HaaWR1S)pl~&<^dJ>8dm+Za#?B&3>-S<}v{1h|r80ca% zUXs+uD@Hxf&k1?Oo_G~R1JPBXdI2|jUB&C5I}mBrJJoU6?tEq4H7iNWm_GKa$MB~A zhpx8{X!7m;#~CTDbR)b8krbp;=~fUJJ%);OcML>Yxfr!>PyIwn6TAh5jmY z!tr`#1*>dd!k=>g+*I4-t(FW@`3+A+##S6cUSS*8mQ5q8enoGO$Iw<@v*|;42)F}eEx|2HrWPfV|%fefFPW3=k5-E7KGGo z09icPL^1Gf3J)%An8L(Dw1Ky=wYYs+eJG0IM14Tbx(2kqen0jcMn2q}b8s}>mC&^8 zmb-#GIEA(sTyvR0eVt3{*otC=Fi@eueO;l{v8-3>Wvc{w#7Try-DI+`a9*7PR1ivm z98SqqX9wOc^h8aCldAY*e2a)17zH2Zy9^|#l@7^~%~{{ig`g&uK4}B4`fHt#?KL;w za%q5+>$km_DJ|B@<;9PQ41exY{M?6^JT7F1Oj(Gsj-bXCHAe=|EmFO18huT?4-x)I zwV`dKojXySsi`4vXDfyq^UNu?HP$Y1pWl%;mMuk6%%c*4%y@w(6>Gjtl-1=l7G4ZdQWwb7mOGCOL8-G z$-9c9rJZ+W5H4gfe!Z}fX~y-&+eSw0Bi{F|hdYO}BAGLFM($wnF|%Og&sl_;ro-J% zc?MmB{MfLXV@=$>f`5tS-p^D57A2`b zy!v_v^BmI$wwupIsy%$yOD9^RQ3txZalweD*2TCGSZQH(7Vs1j^+C!sx!M~s;L5!H z2)9*g_!}d|AzePsqwV3G7ErbxO__*S%U^o={?ZGp2u}#-0`EZ#A!V>!(7{)4*<-t| zH^dAARRt)+i0p{g@FgVA$fk;Fs?CQdq2at!8qn6)!uuo;GH=OpsJF#gp3v061X^Z?R}fCLz$o+AFv;(_>B7VhqL0{4`{A;DjpPfVLbl#{T4#A92vsT8 zFK=}`Z;&hOq!E4W^5O~oj+nZ@n{%5J5>fuUR zR=tWQK&*U!t@FV3ia%aIIF!}Y%AY{W`q;-sZW{)PV-?+;#8V(}Da1M-5Hp+&T!EUj zQU-5Bl#WirME~bni`5Q$f|f7R$5YCJSoqyvS}IC)O}u6sm?Nub+y{xZS-;;3c@8ba z{k}8Jd%ZotCCmhxi{qsc=k-v)!L%`=D(w^lOoS~j2gPfxn>FVe^IlUvZsyxixwaSJ zDz2G-$$RTFugA+-J`6iX&~bQ^^n(0^Q;Ix`&W%MXZ|x<5;95$+l{!k-@x1I?W{Y-p zLOLp*PBTIt!3F*xFS9kYA_UJie)hi%M{9LD;UZmH-(A#BJ0?~1N_2_u241Ie(kDjjOc_koQH-YNt>5vP%*m*HhjG?;T( zX!)&faUhGj?&R#MTa;YO)raOf;`+EA+mXJhMe$z^*P@>+2{(?zzT2Tw%0>QJo%0P? zh)}8L77e1@QN@T9u>>@J9k|vm;7S!Krrx>dp^c7s^-+YQx;&w;mA_P<_3^U0W;kQS zYlp;;!kyV|fS&KT4jiB6Qyq z$#62BA@Cu+f4L0RKXP_9Pm4q!du}z$)W<#D%iASqT%c9((|-1QqyTG8u|e3fD(gS; z>h0U$^~XBO zTUb5VNCinQHal7Ul#9T!9#jH!{;Q3I&8(=?}(?Xf3mzesYIzrL>|8lJ zM~H`g)w9W-rDjkw2&eC!hv382FT}&mEr4BpN>;l<+s`-E_Pfpd>1up1 z<{KZ+BN3}AS*dIaxOj}wf=s_6;RN0v{*=&H*tKuaOGZe5Q0fzBRoFIrto3Wo)5c_i z&CDcIFIo1j76ow@nwcMO;c|5wucrs%b<9iIT#iNP4RP@m8 zORC(t$aw>BIK?k)Q8S{;R}sF2qNnd)mXG65G!0Ju`cJAF^g+7%0vTKSE77fE3ga5iUcTH#S%11FNE0uh;P|+yKV9_BiUY`n za)Uy_V)=JGARsMfV|-0DHL}CoVz-!{z=^`x60ay_2vM^B4%W|pC)23LC`DuSkGFH1 zc{p%aucFASJ;eyHS)lcZQZ}}xV*=_6+q1nOml+??p-bP+&L~5Y8ePvU<{lw$fe!V9(lQe7!HUKNoDkrX}-PvaH6Roq)LIH3(m zZ~acg9WjOmynq{@`l2m_iB=$8mC#L=vj0$?QF%{=zN~m~7CgG5BD8uF-39wDhbdJV zrb_&L;6gnPEu0osDa0>SzPTPH!6?YI3F3sd`aTDc^8avVZIe<%x>iG|og3;H_~wZ; zrVmw$Vny})wA%b*iEjpC1*%wWb&IV#LY~G1@V>U}XT@obccX>=BNw9k`ZF!+cO93= ztR^2}p2JrL#4$c{u$Oi+M}d`HYv?@vbKdG8sCKR_`esED)1E5&CLFnW(Da|D)4aUx zxKHM4IP>&#WqZpZiXZJ!bWa`ZRu&71%VMe>5ZMOSPdmrQK-0;5-U6>?;ZV zZ}1eS;c>O;F*sN(ZqUxvi^k7Bsm>(iAOc=5tr=UdeQNfN&})IxuOUm<_YgZJnfQUVN@64%_Z>MkO)qHLY*xbKElTZv$<~E@S1P8qP@9$G;PDTAj+wwfpq^1v0CFnMK)}Un&C&4iR7DR$~sT%JpFSL4( zB!FhUCylUxpgclRHNJvL1B8XNdP@~Szg|m#w}OspMqRBq^mPXfbstC`(yG2faEyoR zG?>&)CGhJ=lR75|w(qJ!1vRzYXi4H_$+GMJWP;MH3~42Uh?&YiZ?2g=LT!Nu-w>Lz z{;@?VBkYU>El-0!mNSao(w$?ArEIkzQ2;4yEEZ4+%U!Fdh{1IsKg6pw!e#&$n)_cp;XNa z<}98w>K%6+w#hHh;iEH;$IYzovNz82t~BrF?E6FXUyNJ}$>-j6UX;;(+tC|8YaDEV z)tXuUz$w){0TE)B_}cFKPbPvHv_U)$C4EbY)&m#Xx4tm7(=Nohf%Hq-ym3=89@+ArJI(r?lxuD4k}s>=)JIqM)p5`_Qj~kMBMGYlXK~ ze{qAoRxBVyIx}<+N%M}f%b4~Oz(27BNIBL2s9wHNNwL0|YD${asWE=3{ULD)-ju!S zsDexEOg>5*{Yd)Xl~O-v71RWh@Vdr7AkFhg?2I;r9KDUX;R+d*+}2Zf1dpJE}bVqqbt@KHI9Zlm<*A_q5mwMHfA*X9J|xGc94M* zpkB-Wn=%0zX_RG^vm3qcOhh7}1B4#;5G0sRa{YffoiWzc&Smc;*WD{7G?6C?N>#`tN=5T#AlgXn0+}<8d3loLQ>9l5BG05`7( zPxhTjf>JVYe5I%}vOo@t*QJ{9uVNIF8;_PaKgQQ2tL62e@sQpTC|i)7dhht{Utc?8 zLT#j-E2)BC5$Z`LCe+WjefcU|M$N59_?q#~ zbXg5$9VG&Wkglq7gdO;8iPc|`@K6i$x<&(Bz0xFQa}>=@eOnSjG*~LIsL=A`UzzC` z0`fJ^s7dY3K&2*O!aaeaRL(`Y26V#e!5}97-`hIJ(l@koxwv|HKLRU}b}^v(feKg> zyq$-Q7>KBbNZ9`CbbNGxtsZ_fs89W!M+yt_Kp(GSNdPDkS7RG7t{JJ$KS84>V zj~5R8G?4%n$NqDFT<4pr!yKQwnvM?72A*26uCCz>oN%izn!$>KqRZfERSykqL@pxz ztyMi2ikx|?aFQo_Y!5ss2a)xVujE|#K`lcK#t)%@6ElGNK(_cphQaWCTWMSG2u`TF zae^z=pmOpQxs^uAu{R%kusBQiBdYa5TX7*lQaH&1F-Py@M;jucFHeeL+xgGt@0Ju* zO+}%YAo3Wj3JjwGcQX(hcgjwI3YB=x6f)8{%Z^A1T(fIlJ3hv@NZ1X*D7wTi_}qf9 z0wdQXMXZzZzh#R!m~{8MeJNy!twlf76ixjNfqmM}r9#H3bS-3~rOE6aU z8jJ^natYGIgOS@%S%foafWoq5yLE1=GHINX)k%`kvQKW{QH9rx$bMq2)r;I~1UdEj zncX~YyO*liGQGxe&HOE=8VMEtk=FUS%m!f?B&%;bI-jE0^5^2H^(*#q5uw{dso>L-u3JN`TnXkalf^MJM8>v>F#W0w!XN>uoYr#Jn%oblO9$s0oKBXTbx1fgE>eX)t z`PiW+{M^x$il+~qU66l1N(-8G1wQeA7okl3RR2CLg{U-gcIKu-D)nFTYsUu7%W?D`4LJdMqtS=1wEhr2!2`WDE@&i zbIdQt5Pk~p0=cGND+^8hLGhr*#_eOS`0N_(?A6;rcXpU^st+!i z7$vy0nphtHl-%3Ddt5>18ck`OpFnv`8f`InxV_C_^TPapj2F2YUAr|oFzhYAtJB5# zXG-R~(GLAKYT{!NP-XbagJ(X{70(~vF%9>&O7AOapOnKnP-6zbt?!CtK9aPo;$W|F!0WFq zZyn%*mxZflA0nqH$jYAwDccDi9`e~f7%sol*uL0`OrI(pE5PAT>TVogEl#)L>Jc+{ zOH<3`y||?k42x2H?{ofca?5;6I2p|Srq(GKuGxE2DDDf{3G0p`OW~WCcX@RKA<)5E zDrdl1q`tgvU!1b206B#f?rIE4+n1y>Q?smy!PV~IoDt?BFLQ$Zx|=c_zOcyP>2_0e zJCP_DsVF>fjjGhncfqE8-&aBq9E3!x${4AlUxG*7ZI5u+-^}(^4P>EuXdTzqezPC5 zD<)pB_6NwFtZ4DNgG<{e%0bdKZ#MF|)FWJ7)dzjwEZ>T8p{_}6wf%ZGDR{V27Hplv zc)57YiwiXk7AV~mH-n4yfwM{e7PrDH!% z$=^8Iy$5&eVsY_H;k38DI>$e^GxN$-QsPwfYIz=HwK_mibvGt7N;%!g+}-OGB*rZ7 z2)LicZDX|1{XYC`=(+(Xj9K|GJ7@j8oorTlj%e=9Ph8{V$iuedp$50i&xzo@6*f5I zR27O7!3<}BxIPe54-B4^8Yr=<)79#E>&!m+Z%nHcPkA!>oYqv6_m0{ee|N*@X_nl^ zf8r**Zm1z>r<@TiB-27%CJoZ*x6l!X7LeIG!nJb_smQ){^pol?1i^e|_)^4Tnw)IT zYxbS1gz<>uZN#x0qdb^1Zt#&2R+2$WuYttR>sU(O9n5|b_1{^5Y}<(ZpP_H+3n9iNt1g zA9Xk6P3HbYPh3o({J_+)3ur87Nbj&zV18DcEkf>&KCYd(B5`!|xNuAPDMv|~Gketc z#o)$jOY4psM#dTLos(sK+PuLt<=0kVKj{BoX#_gHtufbhEr;Ww5w(H#elz`>dZ&U;P6XU90IT+iPWxIkxw%_D*foT$@Y z3wgvx{jKvX9C{3?HY&H#jm5)V^*AP5YnPi1vAu2-<_pUS&6R>;!!(j7_v8$F8Fk@;kyV96#Rh{;AS6lBRH5im`u>N9dj9}fwQ`nSg>VxNeUi^k(Cif_yCZkaR?x%&7 zj_s9n4Z|+N?j|}Up9y9B;o*GDGR1y#^##?5lvL%eCi7LbZ_WC&%6^kV80bVOEty_G%&&gUUAXZ_0lMyX;w*F@`)5H_u% z;zTXJk7=k|t7}2fEUi?)Zusb+JF+`n%;bsvEo6^JC6U1-U5*1)w%ZoIs_EMS>FS@aKX0s z6&tS^U$!HhPL~2wecn-^#{6fr_H{?JN$YD~Z`1d6z_g*7nmAKLniTg(H9#~~&J-S? z!5AS!5-IX~BG*Ka_G=kwvr?bjT&OSgs}J~dnzC-9GA z$dAoP-~cznSP{g!D}-I}>&ot$oNPt_WO{#E^WmEMY~}P;1_PQmG=OFpMgO}TsW~9+ zS)e1-roz*LP%BQn+rL17H7*JUz#^?2XMr3EK$))vDwhwSUE;tpKBn~OIFqsEK|W0H z%_W-DA@%<2!G=_B=eIS12~S3QqZqSdYd)}kRe0@$6N{utHK>r+S-IY{8l9AyKq7$A zruW+S4Hw|}@40$;xUD18{-Oc00E}mbOs|!GJgQM#5s$Y$7H~2?@lFG{<8hFx}wuD%% zrjmX(>VRAFZI8vT;g4??04DRFRn!bZ0*!Bu;ZW(t$@nQ#t zqhsBwOX}V1<_Dj1agTBVRkslxkE;P*oho23RZnk-DQrr0;$-QV)YeoKEYA` zHUKPbrwRu1-?+^IoJaXZXkbQb4KI{lDt+D(HG8$GkJ}#Jg9USQ6OpFLY7zjMCMW(D z-U_HNhSB0h6UfruwM)ve{wJ7~hR6BrX<(RQ*|6~C@ojV3eb|xqd8;&Vgy|l0*{h-E z;+fcbgx@b$47*Vr*R51j0HoJ>K!_$-mkZ&ZG&!LxBG#Qz-~cphl&T5zA;KE*%5}$^ zC(8ASq&3Z z7hgUZWWOa)!hw2#MvgwYO{(ykviYr{9qG$^s3g>-dJ^)@*;q?Hnl!gjP$p(t>#iLQ zkIv|9wBg%}g~@`<)~^c&6x||Hg#E>p+O>|_LXG?4Qunt$))ZFEGNl7hz79qU%nb|< zl@6wY?cson#g5UUY2Vf6bnf?UhziOPnI7#YynGCk?EK z5JdSp*7uFv6uRY@TZvpMPe+6T==$(m%Ltf5KnO(u=lZ?0?zOeNmlK5RHy*pRH&9O+ z=%Hq)sCB(WJ7(gFDg)AYX!Uwl5FGiPSO-BNo&mXLb(6R{wxOn4PNv9pU<&^9ATfAkBOlCgOAv3PI@2tM5E z;xr96b;koxBT7=rGn#8W?-27yE-uYO4_b_D-p)w0nps^hfRpfQ=dTv!->bb|) zFkv5;w`6%L_h9soH2S76_4>5;N8FjB#U&Nb58B+!4JVc8{svy8 zo&G5wK`;Ikqz9|$!q=7qcGq{bl?N&JB(*ELtn}LAH^(q%05Esb9RU6K@mpDIW`oWK z%x$E0j_(g?RZ#-D5mR-nHE8v*zM>2cAY>)prK%fdXMpN)8x<7v9{nSHJs@%K*v@xI zd=-?Zceeva<{`jxm$O6^^d%ezUF@et3q50*6au2n%&4mg;KqikrL%Yf7-oC3&tUEh z&mWC`e+0k!LAF7-&ILayb<&R25|M|tI(zZDkFNh}QCWK5IBVDH4M6Kx&B&jRXGk)$ zkm!^~eRR|tXGg2A7QiGFx*zo(zc9U^hP3w{iFWRY`fGi)&IuCT8zHasxq_vol5BJ= zrCl_#V-U2Tu}J3jCpZtmJZmTE1aZzdTwcV_c835GpT?cuP=t4yy*4md?LyH-q#i z(t}M-jK&BAo&4k`ZzOm6VW!n0LJ{dN-Jyq~Hl1rCa}mD%bg4t{I6bJOSZ{zYU#^EI zt0rh!I7`D9x}_0nLmyEJF72Y+Gz~<8TJ5rBOPH&Eec36( z+)>Yu&=}>(eNJ-I`{F+cDh@ch(o{k(aizF|g-?|oRaz~SEz!L4Hv8`GXVtT*(e@-e zw!OdLBw_eg6U&|edTSpp4B)rL662ulH`1yLul_NgmE37|#=)Jur-@V8wMd%t?lZCJDn4>R#~DaM0Ubi zd>$^E=ye*PCZVK3gKEIjPvy#J&+Y;r(?5YQW-Iq-P_oegJzAskGYIqLqJ39_f{WIe zJ(zJ&Ccjy1#=~VYWdK>A#)=#UU}ahlLetXHn~~u$j)6{JgD|p~m_LLD#T7EN@=P$I zTmiMFtS#{INiA61;TRZ(O{E!UY@n4lZHXBQr4Y$+C7(;KB&fH;I&qKoPKPnRxbf<~2hPQ(pK&oB}Fg8;y+0ZxUbvcAr)(3yoi|Gz~ zqDSsS)LngfYn@q172+uqPTYXmU#(T97|O~}Mw$D|V4jdnaA1_#<4)UR-L*)4yUUwd z87G8-S-$v__G;p+uk}fS8BHOLAl;QbwfzEF2}FS;<+3t+akO5XkDGnO6fzPK2@JsM zXwtDVjD%10t};5^=ccJ+MiX_xQqH08eAq1^Saw!K!Z!CP(MAOQhINAL#j*WZuG2;6 z&mhReFRYzn_9V0?_n2#9zBa{D(ezkDt`Gz^g#QKp!HH$mi1%|JizT-;g+`ih$)C({ ze^)7xSxy1@?w-W=>;^nov}+p{^f@)uD_r;@!l7Iy!U1#fR8Xp@^julL9$c6(F&(O^ zfQKCSJC148^f}Z0!NY`Zkgb1BvA^X=?WAlmNhu!+mVUh8dR^~Sw#=Wg5g@7v4?HJ)(NQMdM3(jnq&GPkuAiusrp!V5Z<)GQ@gGxzB01)^Bm# zJi~bQ=68|F8i&mwj4PaBAyB0nKg;~?=<%kL@{FP3M(5g3aL3FvT8{2+Ej{m)DGy?l zD#o5M4fj%{JKNauu@?Nd+NRnq_E`EpeMr~GyCWHqn~wKA?v}lCbjMdFq3Sf4DJh*# z>S+2(T)&O4T(bUrl!Rd0E)MB)3y#>QML$`aM=S^o+r?EQ?;8g6B8HFcHss?VU1O6_ zv-)%VTsu`_<-WTY+vbp#b3Att?$Fj*%n#Cb-Qg%&|4)Zws6sIaL%}8aWv;D8(XoYD z%Cuc~15EA%I+Dc+ZK%w2d6RIqm|H8f!B-yyzPlb_0j6?}*Z2&pL`+>yfuWmxsPHO8C7oY`W-gWv)zA@Q$?8W{7L&3Rt)`7ZY9@<}wc73gZA@{-UhD+uKuFWHP7oGiRs^q5o@Xly*$;@sVUga(WCn-Da zbU}oT?to)hR5@tY(JDNYUt1{WC=S;yi9X)d+#oaKgfN`4k_vSPRc%IvW>+9wF1*3+ z3EtrmL_!kjCaxi2x(fsgyD(T*o$c>t4yK9TXFeJxXo@fg$a#c;gKE8-`so&HlkYj= z#!tHMvW!9QpD2|2L>d&LC>v)5=R6*o7`S%LhP6^rJvC+7#>j7T~}+2%n#se?=V0IL#?e0yTsQR?aa^I35*d13f>Wy5mSin zVdcwbg!0WylPV#M1CxbuzF(-=5)(5QNu41gomEF$fBFK%5z=-0vn1=3bv&xyKLC^L z@>#KGB9rL+NL~(!)SZ`^znT}vf9z;m zD;TJABYR4~8$S;EKth%9IliBPX7-FsL7-s`?o^3m3j~HaJh8$w5IEM}?Vdq+&+Z8o zRammOZSVd{(2fpIPKd`g2}b}YhWw1wtHu|0a z@XiSPvezZQAsL5`^|i%Pwg)rHpIB;_E3U@tRJwls&9d=SkSc^Ef%fxu7eS0&KStEv z3joO%<2&*xmuyoLbn3a*UKmXx2ZknNQ zxyvTyykn1UT)aewalhbS_^_+=S@3RY9k=3S$WaBTmX^0jQqdy`RdvGlD)F~G1+TkK z#~2#C@&S=(A1pL`F17me?s zQY`Wf?Od+rrI5moRFs$trw5SAHZcpnZvBYE74f52%%N>@Pv-Nc6;5hs^%(D-3A>8{TSv=x7~yP zT;R*mv$566!y9UpS2#Ir8djS9CVL#N%Ua&>|2vopDp0uC*)8x+mcg$0C-g-B3e1)r zmjCdT)AOEdr@@vo;ZSe1gGl$xk^dzQM=khtdLqMOHli^e|ICgpWkaaGT$r3d~< zFKh|$hn2vKE7=Izg+s7tYS^w?k7qXUf%tbe}_4W$KyTvM{Y1u)P+KBEF3^?@t)EBI z*7{6AD7RzK6DJSQL!!~_7lSCjunuh-Ld*IiqN<~8B;mSKGi8>-_vMP>s)tr_`8-v- zwqH2w_JELY#?cVOChmR7&5Yqz%6_Au|uwo+8A9p5Fc1hmJ17WPkjd5)S-hU844xXl zpdD_e!;EOBL#bBO@^kNbcD$VGn-~vaN>m#n=6*aZ&-wp7rrRuxjbW%7MiyUMU<|?d ze*7-V{%n3K2Rcd5)Mh16R7PvAs%?~M-igrHkoUE)wEHK3Yod^2$ z#4(y$`jQVb@m9!{FSaJ~k00)_Kb#;5{tyE-^K^5qk1b|W>S!x%x6c`!kFf7oq9`q+ zy)3*8uZGO)QsWPG_8KR>SCdF1LdWWla4Tn_>gg!N_I_PzpeBI?| zF>KF2o%}Q~#5nY_aD6{S;c3;gFZi=uCDgD0x{7SEs($-1TjzY-7m`Ua_XlgQZqGB} z98w;`B!|I~_ZC*8CSFcaq`lfS&n=Z`V37yON6}QuPS!gNn-o^Nw~+m3i1}^ku?R!O z*Q1t@Y~b*oO)x?*H&ts{NMT#+E#r=}r!4JuqeCb#q#CTooh*{n2TOmo_`15Xl?rn` z2fo`POjB^|WvxJ^(z&l3hV2~(hMDcuds*w#hZJ-7DWkUa;j_D;VE2}oudrO=<`+A< zMu$`4l<$OmKQ2fu3pTuG;yqRhaoTjUv9>vDcl55%fcyIN+Y&Ll23!(ctG z%|}Y(VawH`etQA(iS6lW@9VfP6SLJVJ!z%%_BC9zhWD?8ZT%s>O;@jL8MkXLcG8{z z0agjQGE-fie~0Uo$0Nv|#Ip;jXD7>%;%nj$?fSIUC7w%?3Nuqgun#@N5oa|_r|%gq zJl*4vB9_Q?MzD`op{blT;Rb3_70BMo+JzmMoBow?q{H30%*r=YWbpOpB2=?>B*>@E zPs#OfFB?A`Pr(AkbqSbWtl*C zB3fz50p0Vd4_Uwh*gCuF068HNVe{5Xvqzj8!9^eAArmusnfmyTN(JpVHg=aHF*{H^s@;`B(0MZhwbqxRz9G>U!>sp z7BK71tDAj=N>H1`Q_CM{P*l5k72{wXGceJJ?!PJ{QgUbZgGjOH9^r`Ax#}n?`o)U_ zxcojDIkE2f#^d%yytca{d3NH=uL=hw&?Y}6koG-hFBX>SD>qZ<+z6#ywxBvPBb>yw z^y)~mijI>|mv*z*7^Iz~rCqJbVuw?;aNpXe8sDsCM24~Dh!H#o@akNRQYq`mhbAP( zz;3iCcz)#~So^h0pRlx>;HBKOgQah};4d-UHfKyOe8QNlTnFSk(6@Dyy*bsTe1;q* zX6CZZRiF3fuirBnp%UGdliKnU6*p7K?tN}=ADnx}D;4G~Gx@Q)HGdn|lC(h-ah@Xg zh`NbTYSVm*fK`qNTeLO)}2m1IS;Ksz|r#^Hi3E+^driLTlMC zt^YQ1;Ts`jkz_v4*G$aV_a3Z>BfLD$xJHRyEK{-0uP#jNfniDTQE z7hTsw?7K8^Bk0WD&`H?Q^cR`>e`o)3yGzC;6xKnQh|p}du#>O^LBVP#k1DEvr}|C4 zNJ+ibs_{82e*#BETU%+ZJJTyf>L<$42xc|N|8Aep(wR*ephigH=r?3Urj#xO;Qm`k z@MVNBvhJC<-%H}g<6Sd5k{N%%)8~GhprZfmZg!qpxQ}#gTpr-~RC#B%?iZg6arwhw z451WMf(!VUaW-7|X7;x_hga2BGi2AT`u1|a_pfR)P_j1$lEPS>FJ_|%7(J^nXOuYw zX22evey?%7v}nEna+)#3>W?E|NBP~l?wsUe@2Q`G*q?!$fxdf=E*n4n5oOaeT`TA_ zqi=P+O(4GyyAzljevg6^ao*PZrF%@1o4btnISAgm5t=r(C`+}~3p*iSddSV&?ATjC$qzaIN9GQDI%yk;5rpatXlZO^wM^`S;-MjwZSpWuR)GyQH(4LPs;&0xTINnZPr;uQNo~AACycgPT z6G$m5A&V{enRhPdJzN83_VN`G;0A&{*T&nFPGOwMhDVsJ z*UZM)NZk1&g|H%$>{EX{rIYsRn0rXADik5`^{%uRy$fe6W3~_m%pMJ~ec&8Lf9PBaF7?_S7cHfQb zrg*vjP9!xz-p01QGv=YU>h8%#+{mBVg>&cdc}8J#ul@I3RIIfPNY7w+=B@3^NMvvC ze!|5FV<$a0G*C-ZbOR-~LB6bnjyKILe+%upSQ+1NznV^(r*EyP}G-oD3HKo|zr4c28IXV4kYp`_$y-y+_@hKbcXera0pUL{}0~YtjkM+X!Q`GOj+{<%4KODOae;TOW{~@qxZC2Xm}91gc^H2 zIJ(Fl3{hpF>b~1!h+N+vMu*Uny38H5I>Pn|kD^vtgl1tJrn{5SoQ-YBJQsG%FLsg$ zJsM;`TF1`Gw$1}r4<%#>7eTe*0oD3igl}0ZvvXo2Pe5o>Hj<&^z`lT$?F*Odtkq1? zrG8uCJ22xoJF*|MRph^#tbgUlFl{M%S3`(KmTg;NxSziGaxoY?=9 zoTxBO+?MvhkaBIu1Yw8pCgmHR<6ay<8Eb}w$YKolhVqk-{|PT;w*ro<%_sMmI#`vQ zt*g19+cxZUBir&FQe0}qm3wcU{dg-`Pb66Wr0Enq`umM|_6KyifYhA6)6iQVVesWS z69aY|#n+~nT|s3i$I9A<5Rke!3xV^SRLLog`6B}|rpM|($PltlZ3cfh8DZD7+mCx) z)XBg01pes^jHLIo=Fpx!|55PiEmYm%TM!rfRD}b6yQ=5=_w0#)2N7S-&=+EB6JVe^ z|IQ(kPfzh-5762|`f`_3FkM_819?nnYV@OztWlSX2BM=^u&8HGHR&92qq0*!B>3~U zDodadhEv%YowDe1nh811h>S_LnJTTcVwopF($LCF?vFRSs=QN^?ikRiRNZsphjdBD z*TH9Bu8y5YSy&|bc)ULj>o|FF@UmyDWHV2T#{e&>(!4#aFu-+lRmT7BP~|_VGR^NA z1E1HmTQX7E##DaoY?_=*hW-=-fV&;v+S-`nb}EQA&u9I)b6dOlPiF+lF%REK92F`C z3!rAGm3CGozB|ZspgKJQG)Z9HjjcOZ7SzL0G;!yBgE?O)Adh*xGLElE&^kA(gRvq^ zi{mwR{dMYziL|sHIo@u{m{Y>=rNR|fvNNUFHS>CYJ(gHa$K zp6H`#)yKuyHzZa``Z{^8q)xXG3v+$;{cX7Cfi|9>4)}h2Va!kYCQdC=GZ&Q-Un28Z zW!hpQ8loy0FGt8XKI&Dxf2GrcYw;ce@zBJvBC1TfEZ5iCILpf#OG`dJBWZz=Vykkc z9gSS;+F3ah3pVna@rn#xH%ll-K3SSs25YUXz>FL;1BoS z@}oAZx>`;b&iD4tn_tF9h_NXx1j95G=;Yq_Hl_yPUhiL3Y5tRXiN~RM@Pl}J&I&sh z8tUY%iMbrkKQ5&|`NwT|5Zyh_Ufqfg6h@EwXpYoATP*e6z?S~Ab!GJD2s3RQO z0$_n2g`Ja<63bsw^?k&YBY!{(vaGa>$+m5{jcMITWZ{=^u22%HIquoT-_0;QZ0Mck zxz?qX@8(iUETOlsE6{YjmDa-RaL{#*1pKn=-o>f#(%ZLJamUJ_H-Nw@BXynf&aYH0vcr$g0}rzH_eX6Q&I*Q?RsKI#k!Oqm;^O1$UMCcbjU% zCx7>lmpwtgOEI-elrn_U^0nvfw)}b&NYT}%W!C9+G%DW`Avxn_Q+!$YDv=^}ErC9s zRy{@7_$^!ZQ5ce1slm3L+O*Pq?0N3~RcQFk%uH6zUfLBK$8BA|BXSdD7@fcrGl)Y~zAK+tEXlP&$F1aA4( zIB)-RX8~QT>zeKBQ}seH^x3Y>4j9f$W=qXc-zx&v4on(-nq`*pN5;q^GTiW+^^H{% zrQV@t=!+hfM|GeD;n92L>Sa(>uAUb-@?3x`o@%omGJ(wHG;}Vcf|h>f(cX)eZQgQW z(|>o^z^k!C&gB&IJ`fj4O|!Z`h!=pR5y{#4)4llnyy-eJvtZp&=ap<$TlvmCraP-v zvOn*T_{*GxC3-I=sB>p0vr4RJCNPL{M0Y0?x5m3FUi0S< zs~=`QiS%t2oxD;HsxTc_H`l44?y-yx7{ee31U2KoYNS;p3z%w^(VYkPl-x0hbxCo( zVe)z4x8Fx0ErIX3N}&)+g^gC*)1dY+`(E`A^{HAlv*&!-yZZXcaGP2u&FxDZ<`TAh z1p@;79y=#lCE+Jek@daxcSTOrh?j`tMmd<`pEq% zrlT(CFG2O0b}jde78`oO;wNcX3na9s4YjX6Q?E7ApM?sfI=PX%T=(gWiq#Z29MOXG z;ldO_jalzYf;+V#b8Pdl)$S)o`pNk(8b~|$%CdA5=)#Ta`-HNd(#N>^Y&p*rYaS+c z&hzOOsJ1(X`0TT)@ak3mzGpWmT&R@dBer|Nj_^8eQU9vLg}B<{B+@G%?9<#zv#C>H zCuNfJPb$3UP&C{w#49-t|N6!VegkO(+VeJ-4#O}s)c-`mjGsi-N6;j|aa)mzh|KtB zs{w;@*dXkf0C&6Csht=~nbz{}P@Pu#iTtJHPBK&WyrXR?6Q8tX>N5dCPv<;r0>9AP zyXBDfvj^Co<*PHOhP;VSG`&khuM+SI#2w~lCujM4Lv9>>+@8qEr5!4<>_7u~-C^HN zO_>*;JUYBNUj+UPPAdlg3FNc2DfS1=-`gLt&ii*K$S#iviVToHI!FBWqiiFaDL`0x zKlTvi-Ux z+0OxI4;du(aYP~dE`Pf|f^WZGi1G?}xw64D*Uo%)aVQ8xCMgeObWx3fXB0cHAKD`| zwkyMRVYiPc;Q!w)62cmxy}=Y;zj$~k79w(AmL+w#fFrqWtF@g19r`C-P*zf56K;^m z#Z`~Wn(Ga|w1pvd&ji8`P^9(tU3pr|*RZ@dR}*Yzy(na;OiO&w-S#nltX}ku!X$Kd zkG9FEWwW39tL}G2Vr(ax-JC51`_A$_d)gu{+TJ<_Fj*)|TFhF>0I&Sk$qR;$Ww1I&YQU@@Hd|HR{3V-xXA=LzZYX_?OQeK7yUE={?gL zc|MET_4K5z1l9!BH5M@i$-u#FvoDLwB}H-u6)eI;8~jE|@{$_}wGJcX=8vre<^<-o zAgjEehl1EtG-%@8oBB76-2!P{-V*Xf$KAOP+<2|5jrNJW?gFb;3i$S3>v0?-!{YgY z?Q|{Bo7){PcpiSKJ@l}B)Y&*4sppnAt-9|EtQgElN96qO>8ZL`EWXzrNjG^zo@YD%@S!Gynu>j2Wl}j7F%}?&AlMH+tzqOO)0!M(~lPAP2}O0 z@)*i{M>O{ja|y~L$a}p{MHOnw$#%)hG6c-XC|}HvVRd|V=*lkcC-nb@PBfD>W{p+cNAF|bU$Q)lmW!Yo}9ux z@z?nGMgYWUl&j+NZbcJTx2Y$z!#cvk#yf!Vz2#F7cjzS6Lrq0r zo-HZXfl#>bIZ`|YmOBdpac}ROTK~`Hv6l98LQI!zPp4hsWVQKoU{DM9cFrFIlYkc3 z{npzGk>hNvxtzjE*RhM2>_AM7<;WSh1AR)dO1ZHe zG(mzQHuJN?phz>Mk4oeWLK2uu{w&M=nWH^)CcY#NBhMRY-P4R|VAB4XpO0vjyx!Y% z%dck~4IY5B#SBiS%`G}R!!~9S;Fxd)K#wJ7c@jDBV`Z?8M@7Q!x`CaN9hkt1Ypvw-i4dZ8lD7mxMk!`63r7owUZRHEn#H~+Ps z<({edz~h_3W9T9`8I*Xr-CTA;>M9Exo1*Ldd0QwTTrJxwFm3zOJRTge1xcai^hG(= zH|98xok)*J8h*KIzlSVDY%Hs@1ePFE4!G`OEs(mEU!970L$98;5LRk+CJebx^$|Mx z&i6n2-LS4zTz<1{h|y^5aJctvsR!HVw3NZ~=Thv{=T4SJqnU^&472h2|H!at&eh(Y zdDoW0h-4bfr`|?82WYN}B}+W_YU?F4(a?EEVByYPae8Lgyk<6>FsY=%>Jab5--F?p z`JLD%M=Q4tb%fW)rht&+rm3kX+upj&k=oSLFJ%75V2 zv*0r7r+b^pbo_7wA3rf(km6IiFr&Z}U&ECPmHq3#mYfBm5mOc|+GZg=5;pb|@RqBr?ou3aewi$*@ULyP zP4iGChu~|+oHCa`{lKl^ro#C1(j*M4FpIFzXSqMyO4K+z)=R2KcEwHS9L;dOo0<1! zc^g>36lWzggc+*-JeAbhf6hLj9g?!KK_U-i(+~q?8vwQ{+Okgg7BeNmsg(Ohh$#dzbty_`K5zQKO1~~xd_Kc@o zi5?}@*e59g1=2{R(70J8L7sTQVHLgaOdGm6obbd86u*4v6-rIb2s6Fx0lT9UIbQqi8(0N2> z*boEpD4fbBaVu!kNBJ`u$~BuN2C$>#@W+I%O~|J52EB^*_o(#QZd0kPy|r_(Iz*5u zobB{F4#1t?*wz0R$GQ4!;aqx%(9D~xc0>wBqXXWMT>NWM6`rfY=&xGV;4kWFxVTb} zhTI#%7QEhSTdAVbY2)I%FRuC!8M?h}O$ciZAVYKEJ=4h}JMVo;kH^Q2nCDV^2nx7! zQf+}Wt6udYVZ~JmqJKsf%`Q*wuaA$7^DeZsGvQQmdDHI`&E?#uvRm*v$mMdv;dH0G zKikeA5Ef!qbaIWM8nv@i0 zf=`+9C5=+t7)CRg=#uh`t63t$?-PMV?CL|kfk$T-RcL#`@?Q7EAK5=_JN&w!Ho4gS z3cG>Cjnv88DjYeUvl*6er+gvofSIBdu6iw7!o{0;Os!kb#B!n`)s{ zT>f%oiZ1(W6gW8bKl;rj?$rDro=$=87;J5hcnu|y8QEnUcYi@8nG?C=q<|ctEk18F(jI8b0kYGqrWo~GU9=^F|WT@FJ3`b6@qWx8HCDQ54`QlyG ze|^@@*jqz}qA%@p*3F~jf57pt71zd|0b ztk6y9{R9+ua&y^$AZ_}-T9NF89NzuYSj=NCr~U9^g!eVL;}fINEnp9jH5Yq+d+uA+ zW#2IY7w-1hXTN67-Vzg#!qy4w;_JJmD;*ey1ew|?JzQV8Cg>K(`;0Yw6;f1f`V~Xin%*Lq(AB`ZwFA1@yl{jRi#mmio`If50iHYn5%U^;?V+MU5>(h3t zGt3=6^op1cb9w2ijdLoYmEjEg7z3C-Or)3#(TlzzC}(QgxS*zf?`C0;k@uHPZxR@L z7Zf~8F7pnxh_0yy`kjnN+Q8{SsC;SgKp?%nV<+ zB3@L6N1Ieb9juzRyP8rFNI?2MR?8!5**;h!} z^c_zxgR`H(v*H-wcIq(~c^E3*`r+M>&sJ||&px=jbhG;U7VWkTIa^{7UUCHI)tT7g z%CO&`S|jGYafQh-T`B%}RM3guQH8(tljkp`(G}+Ee{=Buwgqd5w00ZM%bm`w^+p+gmT_wkN6v zeOvzhezJA;rgHG4QH7<69{KKZ@}nCV%5N1Fv)|f$YHQsq3BrMWY<^l}u$O=REy?8UNhCktRsnO>4m1HcY|2 zjjS6IQ#bPE89aJ}N)AxHzuOWW2TC1e5%XAok+an^mz{a(HA-B zR}=6~vZ&t%VNr90sxg>Vvz^J))zBzo+|fa2dyG%$Yo7gc1{IA1zK_3r2)ViL`S^yU z{e7Pr=XL;ZHCsH7`vi-(bR0BZoGIl+HX7z@=Y%EuvRmu8hWOJ>diHjho1`L}Zld7h z9Rv-6VJ2ly0?XBU|M-+9E2Ndt&F-Q>4MqMM6`x{H^v2TjRR2{2FkdfpUx&ne3%7gX zuaan0|GwGhAvbh%rIXqFSZB5kd6j;d`96p;l5X3juv2U>y z(8i%4Y9s}1)k#@xwkI23u6j>F!r*{&rmfq1VOG6;^*%a=@X-j<&u$24%od!VM=>LJ z0P(xfCv@kd+os38nK)m@HXf*cMX{yG4{oHRCFV1>W`8ThPld&tN`KMvXjnB3%-gaJ zwYoEXQR6I0z5+ndaZd#(gK&j3O-1#AG+gJOeV$l-AG^)x87){*tu(RTq^}o<+lWRP z7HDghIy`Zww5Q5Z*mIjVj}Z)2c~>DZma{}BV)_OMAuJMD8}lP(F;?nzK~-_U+DGs3 zP=!VK7ppM$QNHbM(^XlrX~ol&KM8`Nv35^ND}^qBZ|c5@Sx~c37Ses=Csh{iF#C49 zx9$FnIzc;0(}gFY;#N41X@{U^%l?+jm^Ddh=1fiC>K=X89gJwdPhW;~tBGu&%DBA) z7}L!Zv-YI9j{aAm^GToy2K-XkUizQxpIT_H1lQEmDd57R zII(i-;X9j@g-d$gNnGbC!3_fLf4A?j+M)3->5J~`v|yTEr0orknL{7o}|S|-KI}DqnCz0yU(fXc;XzzhC7<(XJf5sEr`RBPL%D60q(CS8}FgBC(~a1x)Ss|%GB%bM^V@|CgYki>z%}=AP+)4%4xi`pQ6U@kTEPiQM*f!J5 ztp7m9i%#b2o)g6Ma!XT(usVF=&4w4Wo4@(klC@BZpw z1tBd4mVCb3f)! zy=!YHJytkmori4lee~wf30INO%fR?@cb7){jt)wOhBxfz}KT z_Gv%kX*%cA0K9AZUh9A1F2%XI1RZ++o_uPf=~<*aJ%C<^Uh*?)-PQ_}*h)?o4!=$aZ@LEUw|%wtsL+5TIF3<2J~2kwSXlvc5y4N zqREGQJaOfop)&14aoZ1PYC8;9vlf6(0Qki3{N(ZXD_JH* z1M5zyCTGB5Ko8Y>vUMF2OjNF~+$c6q7NduaaI~v0ao4M$)X*{aqm&6dvV+ao&i>U! z38||{9TUvpnk5C@b8dTy-LvT8U-b^+_a=LJhjbL@NWn7q*Qg=mJ3u;dsRzlAX7V6% zwrAhbL%=rJ5p(ow9$i`Etz`YxZQR^G{4#o)G-aCoLL{kvHP4;xCZ-;twQQx~pxs5V zeydQwGtu~-pOlQ#f$!#iYkFM`&i}yr;&E8v2{U@;#XAR9eKEhv${x|S3ot|5lJj23 z4zG0mqp;OSBg$x|*tI8e9^|=`0W;qGs;iO|DDiIe%1{uM7@h+%mUI*}!fJeXez7i< zH|+S|!ItL%E}U)XoLlZEYH|2>9&|nrN~yG+M|dCx8N(I;0wzwht$vq9d6 zm*mwekG8*E{(#zx$q=DE=J99EMO-s3C#x+~)>1WIZ6WeyqPr08yfF00)C9ger1$sl zSZf?URdLl?6K138yXlY$JlY?1b95jLIe*0+mt>!PHs7HCRSQ5^oQd6Na2m{2C+>al zV0JlQaipuxH@;hJx2Y*c4!`s};Os7CSfI|})x_kl4q`g74(X12w;L7&-!U_30kgbUk`zl8o}#)RK)Mm)I-&A)L0iL!)9vRFj}l_A)PnIQ%^7p?O1F#P z;jBZmN7keN^tCS$rw%zqj_7xRTrw)p6N-q-i^uJ(9ELwH0{&ZeH7=M4orqkBfzEra z%{;@m)v<8-3<v@nuggyYLoWCz#yaZ!|I1oU%^O5yK^qz><@0aNhfpw!|(l;wLkPQF#E>Io-EVD9A8#BFyXJ1298N)2p4-gZ#@0>Tx-Q-cu&|MOd_d*#vZ*Au7_Zzv`W|R^{G{a z=AUB!_2}AvuwG8eALxj<+hg|3Q9^KQwn@{-v^hI2h;P2!_(uEJ^XxJ~F?lcz zQoC4a;+#m^>x|c;t&$NP|BF^46#m)H4hA!Gp!)tYwTNs-U|eTC7@c4^oBz;It@xH5 zBqc8sU0wd&Kd3GZy_CW0W-wdV(!-c0s-OBms*<>%bH(yQ!PY|v{eT`~If;-}FDEdP zR;~AIEK&!)+ejb@CQ-DHhl)q9S|A*MU^=tz>Z!ERov{4weDZ$0(XAwf;)whbP9slWGZ6fGzE!b175_30V#wS6r#@XE{RGadOsYxOx*lCIG!kL*G7%2NERD=;L}8?ZcVXS> ziUI;-5JedIwgr+4OoBCq(36$XD-xFy3)>;q46){rOjba@S&jn=eNEz}>P0>-UAkbZ zod$c1=2mwmeMgjP`($|~3jz3L%t|pg)Xc;HE+rXT5gYKghbZ)nRd80V+DL&pRt!Dk zMFsIFszJok0Cy(O@$ub*ptiWfC=3iHn0^GI&(n6b{?my3P@ScrR{ZcvH5yTnfax$5 z*Yc~nP#8Bd_~oex8#@q(7ZQ^kUWuNWtpwMsG>MridgH?6c-5!N9KtqDw+~~h8 zKq4dFaR)8HQ}9>caxl}#oE|z2=srhbNK=W0zff>6u6@30RiB5?CdD})+SP>5VSkA` z)`K?Dkqg3F_6|`X!$%z6xgzn+Z50PdN;v9aosl$Pl6h9pq!Qa96DXDwWZ(x_N*v{= zQl7D(TSI!781K+s88|4^-H@5z#lX8egKVi}V9vBnnz-*508c?1V5dY@yg|RMfS~I` zo-#A8{g_2GynntDa&3k@FG=uQiCZ1gzOxpoh;}9@$f&LRID)d{H2SVIvPR@Bh%m_B zNy#pc+Za-ht|oU}B$GlTEt!y=Sj0IgI8o3&%f4JAl<`U$!x_yiM;UM(Dv2W1BW|Z? zqfHXA`6D`~fxQM9tGcu;oOOlV*ui}%kP&E27vhqZMnG4qvYG+eW0Rl6!4CZ&c;6=X z@I}zoo6{;$cf$iMRX|2J`g@2KN$Jq5QpDOGV?>?~VogeMhpy(PU!@Y_K0H>1M9oGc ztlu>|#9zoFn!UqZQ&pdVcVE$rSU7eVBDb{&;1w@!W7UB5)_9qqSryql&RAW@fCJxuNvXVaJvj` zmDpB)#xv9c`FiDqYScudeGweJ#3ru1{^W99+F}1LP!9CMl2)j5k2HRIPZA zR%k3io=Lm%<=kCiK7vDEPOb#EGo9alTh!m=u+!vAb#!*r%S4>TLEFgBp*rDqQiyj@qH%~fXRry#Wo2bQo-`*^zPRsvc9U!&)k3{Th4eI zXYT={%!D~fKq*9!iE-`Wx5fVvbOls$y|p8p;iG5--U|Ihiwo&Pufd?}uTx`o{GcYOOKRRc=^1G<_c zMl=nmc8T+&05u1$wG!WY}LoBOP3>qjPgDT!&3Mp@3n^) zx4j3y?>=pXh8KIT97A~`P6C)T@O_rvOITO&|MwG_%N>>c^Lutzs8sm=rfJle4* zvJq+E68s%DvbOhisY}@f<`Bz&;RyWMa*_j2OzlHhPY@XoBSdegsD{>!DvpA{F%gf? z{ot8H3}6PfvxeFBi{_*5(d6q4QK4sv#u3f*giDI!Yvms){dQEI7B`ug^I+1%;0j*% zy|ku|Qr5qfJ){N1Per{<;mT%K`IEk(``ANNiF@_w}^b-@k&>tjF^s z`{9A&^_{UdLgNPUQp$@s7GXo+ZbgmNZ{Qh`T`z|#3*ObHI|+525>Yw_hSnt!a?npN z^$V6~X*a$%Qv8FWHrh46+iRw9g$f_Hk{{oJKaklzQtha-ikir0ZrQF!s(?#ch{}Ij z?&K~;SBDD)gt1*miT+lP7`NrSB;8Ck`DXMlMc^*skW*A(FV6{{Yz@jZyqwl+wHYhZNp@fs1Na z&7JW*tcO=#@^V1^Ae3i(<9jVhXX`7F{|cT%YEu z*k-D2yas*d^pyPSc2>RH2kA z{Y)XE(Cw84ziO;+#`9C@ov z)!Qt=sy4n200}`^$IZpvBus`w8W)@`_0~`2Fpj<8LIFb_(bkkUPs1U?JUT0Q42-ut$y0@-L&i=1qpl_MIMi4fV+?{1JLk-pYmYJL#_B?x-z>>CZ z?BW~JmM$JLJnGGp$sJzkPM%tPWZx%=@Yr!CR;6g8;7&gZF&2-O~Q+GjuZbKT*Uacfgz`%ORE`yFq}umuQay=YH9s#*KpioYX}S(Uzi9Kyq= zG^dI3{kw;~H*p)v^CF>^x{#PVuIJML)j>0p9t)*fajvlu>{S(PQbhMhi5x$xCRN^0 zGsnL|M?zJkCs7f6JFv&kV<&(Wu9-4HE8rV#!>;6X)bzd7{aLUX!~;r@x{wH^b=hkv z>uKVw>^7}eU?{hwBrQZq?dDVsA4o#{F7jWuyfcb8$rtgV?Qi0Ha3o1m27Xl3)t1?_aP6?rW)$IYecP=Wp-t%KVdw>-N=gW(rQ867V)8*wPOZ7cz?&cYYHm+n{41B+K69hM+FJmCs){=Wg~g`C5+`SFP?svYNiOT zny}B@@e8xAAI+7<8CNdd?j18mrFNR@n%T-$gu=&>SL_`nzoL&}dB9}7U!&B{RE}5pUY=2K zoA5p&SxiKC0{Qf)Ieq>4fUdc8B4-&jQtehfF?@fVAPA`<99 z8Tl9f7|N`d5JicAElse1%LBHCbcZ1JudPR+)y{?fJyHGT=$CzbU=h>DK65x4{iNcm|vuxsQI#k-S>Ts4v4H+)=7&57f0tVCvo7zym zhR@87`Gtrr?x}GCFV`vAf2Zf0p_9nD+bLIM z*3pO?V;cy0*6P8()-L}&dovL%=0pP3o)>;$ZS^`fXo}i7{ zS*4-(Ac7JCN&wYeHOM$t>&9b~?+R`2IpO1fg(Ko$6iEK}T0MWK+Zb397T#)5xm+`G zyegfKzbc)NF-~@5W7IUe`i?zvWlPECzn2P%cD*Y07ZCi9H{Ji4J#=N=3_0LqdFRt$ zWYtT^G;087ExKkpTtwU2(zFA)I&c|d?vV8q8#PgHYsZg}Z6t3H4Q zd}jmeqP*?pIT1GnSk-)hI6_0uM^S&G!%c;ZSM<>fz*ubW2Z=w?22fS1fX%|z3J9=1 zx(X%MTmYLN%+NkihOrmmk^sadtpDhz^p5aU)_}?6y{qUXtw4x)CZV>#$>^O2U=I=0 z98Qe;v45uc5T@n`z!iyC(a8w&Y$R~Tz7V|lE%48@UyF#jkCU+m6{Hv3Ezi`7?XMaw zp!|mkI|iDbAPs*ky9~IW26JS_>cwk31&kHc)PlZ4CmS4V=_?d~n_Qv7_JF1fDGMaL zfwn6YUqw0x#yR5Uyv_XKUzK`*OHhBv*|cGpG5%T&LXTQKAEEk5ppl{-pu z%{zrc_pAG!s|BpHps-Gy*fQGV=&9QG$$X?En1_$lTGG=S_#Kj2lFiH`Pe#VF>&*_b zdnad`hF7qI#=KJ0*jnj-kPE}Ky6zyi-bnFZmTZh^d6tbd`a;9DeL0pmRrx>5*761H zfIr_FO%jm|r3`tjQy}-X1Jd>A_BFmU9;C)*?AZ%j9rzYAM3*}v6RksdjV_CE8e)+t&UW52?ySz zSF86mR&?Gq_B6t|+ZS!%x@DAp+%a^r z44N*G?Bmn#b9^6;aFJ-8bKM`UyL=zKXMB+sNGM=E;{{u4w?VEv*N+0CaXA@MKhkFo z2>u(wb#!6Fuo{b3T*6rnhsRvS>+7s8mtj1Kl9E8W8Fc5v1x_bwu|zm7osLqI&jB%C zi@kTUFFO8y2Q$>>&6rj^H%02q1v7N7q8##jRY?Y*gIYqae&k0Q!87!3bbxwC_DlQQ zIoyGyZet;Q&BQpZjg`7LZMs#0z8NaCgps=mbvB&O?8F;@YR_Tf%MNp|j8v^nKxx%e zda5^WX>kX8QVR|VNUZBSkd3U@6m&QB-)ndRZ)&Q!_f@s*<)n9 z6lOijWj00^Gfy3CgpQMZRjif(-b?A237njda{WJERoTazW{K zXqoM+m+5{@1|+*rgZhR&VFg>pmz@85W~J7h&PlNM7Pui+M^j*-DcZOTnOd|ck#wq; z2gPUPe3;5KzJ(O~k<6-HHuOr*Fqp(y8zMmt z40CsFtS!i8Ul3+(MKK`k%Y5N!=<_Eo^jV*^CUZnQ`ge6HpeIO*>_R6u$7$61fN}jV zVaMDut7s!Mb>uzRL|@{oZ!YPienOc8@}v)t2NejCZmr5mbp8{jv2V z`0QHXv1YnEV;{qWbx4{&pDB7tz-3#T?LLW}0%$NGQkfPAk;oSTq%JEDfz{{>#fF`a z@;G=M5oqH<-qzF0JgSX)MuZ}+cPJMKg0vO7MUYN5JTg}+RzGDMUlhtg#*?Bx{O2Oh zlvomw%OYZ4#f;bpLH3qqNCZoURRPJ5Go2AQAhjUIG%XgAHX_SpK{q8hSt1Vsv747M z;>!NDy5DdBra|@S>9F6jL|5OdR-f0y16nuWHvO@{kCYj~V z>b(x@@uio^{_Tp@h1HrU=c^SnZ4y}m&KkQ&X0ZLd^fJg;vW9u*7G&;bYDKRvRaxIB zV5$Xty|@++(aC`9oo5}_jw0kRbquIF52SJJ2MZynKI@TO#LRwDrOAsC3me+{kBtcYx0NGaC`e&4jdblmL(}`L_|b;H+s%GC525 zh|kNQ4@*B}WpEwBNKr^Z{OlF}zeWeJCBImAZA1Bp=+*bDjK5sL?CT~}kodj*KP|2T zhA|YRU6EVSg{=tF6}>B1j6pp!FYW-sj}?JDcrSOCX2ZQ`9snPiv2P%Ii*h^cAASPp z>NLxS-9BU848AIYr~k#xwGa6bnD?ib&DTRwz_bp(ahLvMN-ehy)j)3(R5fuB^S*7t zxJ`8f(T6UeJM!h*nZ|OcQ=p8+YU7MEu8*IeW6&)8fSwFwG*^mce!y>s<~oPGy)0ZpaPr zf>YqmJ_hSeH@-muxqybkp>w4XDji1`4^=_;?%zM2q~)N1&?M2Pf+>AQ`<9197Oo?`-Puz!R!te zU$bdZJKgn?*~!P^`5emM_4Jzp&)i@=@(y@nkP^;Dlu8$9PCFBK7%P8`>(qE6#^LYp z+TG^RC%I=#iYaCWusfg4{KR?{hS8Sj6Bl$YbC{V5NJ7y|kM}nx*9$ z@2}Vrtc{NbU(v}F4!NM&zh)!waB8k7U(xYIV9rNBM%G6#AWZJGnanL{P#vN;Rm~$x zkZ-HAo~emW>O&GDSr)DBQesZ85d6nLsYhP+W#omx8xL^t~P;XLOjN?v6tv zwIj`D;;2<|5aT%|S7MXnjebD^ES7f5dwrqp@ZA`K0b5R z|a-?uy4pl2L{XHP|S8-?!i zlH^6qKKDrUohC5LNIn6!6UGwf@Fe^$n!VC25MEpr#osRonbDnMZZb56(==DI?XP%2Poz+MGtEX?4f9>*WBwhX z@v+d1JyspH@6Y+Ly4dgt90{g4ThNn;X~-%DzluFKIeln)Y1N0Mm%8}$qR^&MH z4%%?q-kPM10ld=-ENeLJ2V0t%tMq=nCf+l!|nQIaorQ3csv;?sjx4r$NlCv z5lA=lpuusE%8M2dJ5IEypR12E&J2xw7vT?={HOP!UT*obTv~PsQV!x#{O*qzBrQQd zflQaQ?#EFNI(gv;jK4_L_S$rlo181*V56a`i zoUJhc|7;ALZ!xl%HCcjwOx)fX6q2AZT&KF@j|Irk?JX@mcO-k_TVOm)aiQ2CD?x^%WnVJ*39^FX^^bbdc;#8M5fB{i;-zNkwa5 z_mTU+ZHC#;dx>={#Q~&nnmT35O*!oQ-}W?cSnMXVT*;ee2v8yR85It+V2Xz@<1fsRw*fmvB^K&@#1$2rJ+^Ct5!O;& zS$kLnmK#_PJEzdODx?3Ru_S^!XMpol{ttWpjb0n7g2c?O{DW2U>^HHrTO-oR9owi& zdTt%o8DUXf<0L&qjH#17p38=aSJEwBEeK(Mh@52GaP<$_@wu)w_Xb6ShR0-MyEEpws-G#3o-=HUn4iNOzPep)1Kc#z zguSwNSc*75fv9Y*5JTJ+d-!#0uZ00{X`i;Ii8-T@OAytVi&#*Lap~Y(%qH50&zsaB zj_;8|kLK^%$_5>2bqY9|C6NuWN1!5tVC5@=5t5zWL0k+oami0Z`8FJVNMvB5=d1fb zbPnCc*ma4{(G@h4apBKwK!2pUn&mO&Z*fo5s8>U<`kPC5y_1e;^M>*z>5IG(9~$(GdnSniq(E2! zUWWAU#mYgbBJK(Q>NXEhfmpr!=U<|nEIXRt?Bt4Ovw=S2VunZ_ zKbR|o;=Id$;^1=y7WQ;RPY}h}MliPxAWhwq5l$42yx==}(m#-3T&)0kO<({V2Tu3c zgu@eD6VM!A95C-LI*x>1)fCgUhlrIBj-KE$o{($}b4k|zuV8G&%bzlKTy(v>~aJ&HhlGu%o zF6OcG!a3uQnmxPoPmchu+)e|2xVO`eXkktm-x>^b0I5<3u_xPa1BpHM?`%|Xnll_ccWR$~xI zW%IeH_45wS#0@yBA0Lnuwux?MPtz5BN#aaBUbM)ImAg5&U0$MSYB#xU5$OaI$j@HI zwB0yUimQ0T+8Lz96FHky_%1oMjm*uFHSL!XrR6)TBITgkJFB52*^YHYI80}w${fKe z-={%sA^Pa31}I^A0Z1+ev}Z>5xB65d=Nqm0v~I`Fb9^g_2tlz?ri>K&g6NE zO;zC5&_Iq)o6kyKX-I)*j;!ZP=9#Tl8~gy=&ZyM?%~|Xl1>AShh}52O;`{RcmX&yI zd5`El7NO1%R&?3ht-@{!Okt1d3BH$N1&1;<=R=v=sGD|y`PCkUy$wWJnYcYUB|c<6 z?{@?j3>vbfDIg9w+3og|sE~H(v&HAwdyw7ZYp>5!9>;kYKSth&4V+bqS$)TuA7Dj5k=Jz@dOTqsf78gQ=(a69J?IAi+jy9Lk-TFt$YD7DO5Z+9R>qeSDWL@7x2O5*UK}f1UNXs`gYv>}W+O;5xPVwq{~3fj zk?fd7#_8g2-QCvf%)a!MA2aQ5eo_%g)Ve0ON|b@Po)@L%tNh+?8x;`FHiy$6T20?Q zUc>W+zNr%PIyh<&gcB>`gY7-4GZ%D0sNNp%>;Ahl)Sy2llJf}C71NyapgP6%JA#{T zq&xRl(%a1>+ebODAln;RWI^Its{hnLxUR`Gcb;XsfJ)@hRj@CBDg$unDKu zOP(N9D#FKj+c!wzyZ)$6-rM*j)o-=@p*`|=G9)~iOZ6Q2`CW>J5K|!qJqeP)+TlYq z(c&^Hcx4E0DV6qd6D!Kl548!|oqEB;Q{IZtCMAF@5DU4E>O8gkdv$ep&=J>h=Qbm2 z2bx4fgw%?U(#~(HE8Ka9S}8f&4!#u~Su>>$A7y>YHvO3U{I>25h1W|mD)|KrwB!=5 znx$r?<`xsD;LRhjsISi*luli3{E+K76I_VibK#k8|y}u9e_Mc~L*1A+=9PY@` zqtX|udRA^`|7qoMFAn>{ZNWu#$msjnhCGi7trJY_7dfFUt)MV%a>RCCeg5moD((TwwY_S9es@C_~ zL)p1TRfPtx(f9m)Kk$0CTS!CP`D6uD_EH7?hIHqlk#@gBK>LV1{$*3mew+(_c7keW zb7$TeJA;pS5-NIVJJoms$k#?>4mDQExX+yxf(4U`j4CSdSj+7F3jy1jjdcabl^-tt zCCyD9L~Nz`1aWwnsXA&shlbsH0c#8)K`?^1u{&#tY_lc{-jX=f=nI#y=tE*Y$vQhK zSjV1Vix^Ow1cCF8XoUVke7t!`VH)pPh^*YY>+Q=k&Zip3O7n`PdfNL?F?p~O+?G~2 zhE7o_3j4C%$W0R}D!5d~A%^f<4FHu+&Ax1z;wmc?L5)9q6xvO+KtLyq!tJ@nnfsaI zN7Hv3Bp-aZb0gIzKM56TqvRFjGb42)vauz+o|-^Gld7H3_@aYzD#Y51uXASg36M`| z*D2V-lYVt-trHDUljk$?W@nQP6w5$Rbvq#cDNTnETkvnwtlHL@{6Cz%XHb(})HX_o z&>{3H(xf+~NK-^ns)9%qgb+|bdhbno7ZC{31Vum)5)lw-p-T}&TIfN9NKL2#LOC}+ z&-1?L%$)gte19^`uxH=9thM&KuD#aU!qLwR5jbs5^ivCIaZ?-6&WH6!zxFMtrEnU1b2+sd?CjRetWvhjE-NgPxS?>J_?Z^xuZWjdK1@rU{b#a4dZD`f!<Lga9$~x(KST@oPPJB7Izx)n=?~f^{j&X+&9sLPSXBgTZJNvTMnE(i{Oj|T|Gqs zo5JKC3t0n^Il++zdU_rz^CcoV20 zJZUzdJbFY)#o8YJfCO0HMW8)-Z$OB*qCmKh(?w51wVsdiKz)su;`g1-T1nhGtuVQX zF2RZjzWze6mu6N4_MJvypn4XjlFJ~fH8>mL`i&_92}gaB9a7eA<5{a|L^vZ1bg;~@)pR1wVsDac}vwUwXwO>m9@bCiTLj>ky$<~2*GoiE; zhO~Q~mm5!Dx{9l|d3l@f?y6@6N>IKls8w>~%o$D>QuG_9PFC2v6~xKW5pY$rx={%I z-Ga8r;K*Clt(C!p?R|utBqE=>CAFdFj3z)Z$MArkVuDAR>x^$Xb@I9S>XeeRje}iE zp8!e;a)WhqEd#BlO6A-n(0LV3F3hvlebvmTQ; z$}NEqn@nN|YYLn@#+6g%LaQH5Br(qvxc#Wdv0b$)2%GdXQp&_?X@ zVgT*AZeeGBU7IQ-8ranqzb32mU8R1JN278hSbcdZP?THl>K@DNJ;7lEW1&`+8-;hoShW*_FeD<=Q!U`Vh=)9Ba)5sF zRu!taSFE;t1}eAOYiwpDbUq;gbm)m<`WI1W?QFdpIaytc1Q`R7I%}?8-Cq{K|D1tj z`-INGVdf9&Plw!$yBFnRF0#1n{n`RFdpTi?yD*vAib3Q>Ohs<`3g;NfnXObC*{z5#uGF588!oCpy-c{t6jfx-nu0chMO0T*=KjE z^YjSwO|Jme>iM{YJkjZy+8eJ&ft53q^rVThqKY>gxzG8 zN-lvqdxJlN4Mr_QgNg{B&olD_F?6`w-HYy+lh5`VErQD_UcTe04{jA2Z$kU+GyC~CEE}@y|l$$WTJOT zh{>>eT@e`bfVe!Fvh!Y|ifJ}#e_ zeV5KSXNQ7YS{5F`z?YXYYVr!^d`Uxh`isZukLO1;cLj%2T4+?Kp^5h2J?2V1)uvo=77H_ge`h_Y zW_9&30&K~bX5!+ti4ACtiV_UKe*N>%%}omF6QnVi{yhJwuTSM*Sh$nr^cLV#>o@7| zQB6Zt!iuc4?VV28#ER}fmp8R^;oUZ3)X$dEKl~kBA`524 zZV;2b2j(4hrFYA>gVxOSMXi>Cqkp-=xT3VRdV+;wj;a9nG2h`uIUl!?&)oE>!HKaQ zYnJugT@NWCNxe%`_bWb_A{&f^_rMJ<-zVH+qs_g>^z6AtLv?MuFikoObmgso$}y@c zgKbI*6<(1loaK2l=jX53m+9cv%^cf~_keUAFs%3pQ8Ec8eI$4E+WcaL%l4X){KP*d zBd3w|tH^r-mSQ7YfMUbTZ;k6p76xDF>u9s1*96;V8dRAVctQ$tO=*TK2iM-ytSPXE z_mE8+w$G5iW&0Fp@Z0;4DDJFi2*DJ6<$&mu zzOh;kSV9x3@ane#xm>cbO9r1GCKHjF3nR#Pg-jzgg_}laC1IrsAn}n^Dcx`uS{3&P zPG^nsh@%9Zx@DbEU4N?3zo*p|Kl1xMzQaUg`N${#fiScCs?Q#4xX(RUa=&9aZH@AC z!nv=0de`HWr#?JXIKSAaTw=PY=QiadFVBq)<7Vh;Cw`poFC7uUd>k~UMr?gou>fl8 zG__vfPAl{tnrTq40)WEqC*ib^`JcMKewn6DPmh>JbNPYI%^v0@Hn3*3`}b-_035F; z)M4OB)l?q;@rlAAm@Mt062=X5`ZTz#_UGd#b9CSVx4t8*%T-FpC%FoQR$s_Blp5Oo z3XcIi#4~lHrh(JIr7pMthkuB1e}Z+9cw!v(pD~4ogRq zt-vKu;;j|&3wF+2uuS(;0AEHO(Hx0kDp72RxmT*PiQb!_2wPs2u%mMblWr)YWdx6$ z`MpjG0f1Ax!Ccj~X29^lecO5H!xlmt>)nm$ zhFylXnF$>omX((ncUjK4Mg`7pTt;iid=c0gF+kgF%uf=Q3F)=oZqYj+cC@LChT zkLv*^e5B*|o)DweK!fRGi$Spj2hn$`K~CD$ndl@+uq2&Jt(9tkbrbtkD|x!oqOd8W zrR&L=cCOun!^|!kKJr=4m~doo_X7G&FgRwqvmP-+!N{B38gC>YMmKY9tA$iL;kUK| z(@dAzoZKkqwIRO{7~bl{cyUW?|71)QgrcU?D((Vef6v>edY9j*LKa84~)YhGLs}uC7Io)^^MRN8}LF*!N zdvk@eUjuh=QAR2xOqXjvYs3gs85zxmL7k|9RHFsi{&Ce_hWQ>OR%xwyPW za>z;^@!81o_p^lA0X+cQyr zsk5yd{^Rri2U1qIJE?O>B|J!JQ%3nCuCLsIuPrbFcmEnWm8%l#?^QE4L7zSy+IXp4 zAW?xeILA__m97-DHK`oagWqg+{?aZ)@t}C+)0gScwLU(-AvF=A>7g#DmNPr}OQMJe zMb_+zN!uB8o|uQJSvcA9u6)@q3gI~XIKiO&t(C5^g^8}NHM1ZQe**bb)dgAHm(0pr zkAp<{v1!^t=_cuyjgK^?)n=j~i+*~D4U5Q+1Zoc^4!a;0v0M49=+GO`5qG5VQ{VJ+ zKoSbMSof?eC;R(PUD*4bQ_1<68RebjT=)Lk@5!mD$}VGXZ38erZs?KNB(^B8jayC_ z0*;DmbMr~NhTt0e$kcS2i!-rWf3q=dpuICrr-3Z!2A!BsQ%qplabEX| znHy?qcDQZPvr;pJ(tFX3)VTYl!mYr!49b%3TA+w6S1ESYWAtie21 z%;L%s1Dbu6_MujY#DAb*HZQqH5CEj}m+Ce?>HY%Tv`t>oXvu$J{C?lFD-XxVm8H1T zO0()~n`>HAA4abs+Mq&pa^8h+`>GDcS3%T=o>d8(ThF6% zb`)ZEeoC$r?;F;h@+`M0ayfN6e>@*`AjmRDEy2*r>pPb+tg{!jSyjH0J&BWXcFxU= z#i?T%Nd)e6Y)nRuoa5ytf=$5)jV(a4h+C9{eh(CGLIiui!XXUGA##LzRqRx_edm!Z2>^=;~_(qC@YSD zmuV`D1%bnPe$IrPo~q1!@jIMp2!1!>R8w2CGh4pAJhV82^>CwG+09YnkhNmobU12{ zNy-2)|6Ic%TB6k{e^)Wr z%4IpcnVAn(RYsq3XI-u+(zzh{ZQPlm-}48}#3Rq3UdI1o0feWd^%t=yE9sW6@4rCS zwIlRO=Y7oTpD`MwYIw!^Z~9?pjBdQn_3tF&)Nm$AZZ($$&fXDDckfI48D@Bcw@$BP zPxcI06Ua%j>T3B5V{KG%L;4K7%7be4KZ3(oe%943HhZ^r&Lr0xv?&ZumF_{{zcxtT zjZhmqyN9!5Q2YB8k=hG0J@`}MxtVnF|37e#1$OEjvXj$0xe2JhecR#cPJ)WC=0D|1Cd+`e+i<_BwlU5;Gh-zvME8II$hS&g!e7MiBKqxJeZux67TT*Lb z?8gs@EnC-JM3qt+V#Aes{@qEz2juloGH0XS2@|$ea(!2oF_Y1zLJ~R$r&0&XnG=Py zv=WG0cE}yKw*zh40oIANPI`CqJHJIy0{Zo;g;o{H**TBoyKpFZeE$_OO)JO{@Cana zRU^FpW%@;~2)HD-Kd^Xt?J{!m_CWp?4lRjYd1Y;?82jWbjKnfBg?#?Qi{?z2iQ?9~ z7y*^tEmb@DBCj*d;p1z~HqI%IHJ9=MTM&3t%Ia0WogSY8TR-xLu(rN5Mz3-^Y-a_PpT@c%zIN0 zprf_z7TOyfWFUy)hp>YyvK+h$-V5ynScP|Io~3egbLb&ptM33Dag~$TrrEXZq^`OL zYhOw~y3!*~lK1!L2mky*&rNrVowzsyg@ER~`aeW*$cB8g^ZNJo^)^ga$%K(x$y{4G-2D91Kvj6s3z(MLyZH}zBe+1!rBjATPf`iSQu+q~nG>tgM@=VghqXby!HHp94 zN&rIxEuIc*V*BPG>Vbk{-y*(C)d`!qO7wYP%phSI(})lSBH7tZ0_}~xYj5|!tHM;5 zLK%w44ETIB#Mq8`ys^`!cyOrw8Lzul(tULV{KuO7%^l|TdR68F`m7xF#v(rBg)bc} zaH-!Gi1qmiG9cCSL)lp7g6$EO$MGMVTT(-5u(@wGpuTBSD-Uxu=&yP=BBLecBgUPE zi(67|_&QCUXUTm!ef8OBOMte}(#eh90KSMOz_4es!x5$79r$c)>iZxa|SNLLm)q|sMZ^BO!B_yO-f z1=Xx6{x*&wc)pz+5>T}*uMY&=Pnu;TUyZSf zr=rn+cw0L))@6HOeZ){`fqu!Yt5}bRuFZrnIV_)SewgUIgWbw*K%OwA`uEj8e-=`Z zm(x|d15E~qTZj7#`8%?Fcn6#|N26-Kap9jj7d7&OSi))a`|r6-O!NNd1VcB=Ty=Yc z&|&J~wp8`IxU>N_k{u(XMpc~WL)W!n_m;y$fW#ri`O~`?VQa4BiebltNw8j`JnKyR z?HaBvsSKU1sSI^HDV(p7na$+L7W>QiOLcF&HT%4Ub!F7ZcU)A#6|^JOzt_YQ_ek$H z&F&)66no$+YvL%5;Q2^%&t}?wqpJT6ftaR2@pEa`|K)!8Ot^U(NkZW-cP(N-$LF?R?h*hjD1@#2os=TI%g4 zmg2cPwgrA82=?l*o-UX(NnYTlt0+eRG>G@zQfCirjpTKnx-6DzW%o6-F(b%s`dr(! zJsSNtcY&)^Qrt;Lq`qx~Nz3B} zo^;^7jpf^hWoj?m8J@mkZ>y8QcuJq*dr)ULQc9Uqy0sCR6$T0_liCDqTaT}=X6yTM zryBn%OQ#>Q*q25xx*NbJ$A_F>4|hg}3Aw;^?b>{Z_Y(fz+wp}H%HDvc5+wjEt;I5| zjogS`&vtwEx)E9Hdx}rtogf#Nc6JWdm>uH~4r$`%&Rk3#v8xejo+MvUk+R-$LPiXCliBTcY=6 zD_Jkw!TN0?koHY3`t0tg8HZ9^AmRn~nBSW4*Ikg|gY~XK=Oo>e$rR@g7)x zk7;=>6L47|({!c`)B>~dU)fEPS=r@PC0N3cyaKAbKUmPw6o6fGg)u9J4i{^yV}X}0 zl=XeEp(a8>SlR9PyQVjG^UE(pho6U$kv6$oev8KfLmIzl=UpZo<%P_v zol%wwzR!~4CP|R@SIK8TTzYgG=OdlpQp%}q;GSSxR5Q~18)0A;q}AwY{}Dkav>JQ) z0sLaD3}RVd#FBk`4;**A;hsyoM_TeZw}w+1QXN)oLj=hWO<5x6zuWCJ8V``yaNW4{ zku{UKm}ZRGgT%V6yW>vj4dFa^O~FINa}hz)U@)RT7`i>NPWELg>k9-)joroIh*Smu&GdjFWI~Qy{c{LZ6Noo5SUA}uecJbN0q!mROA?7+>#kh^B-vgs)nxZ`bx z47v~N4R-a_7Q`BDiouFLXWO0l!|#t|1i#sg=p9orqZu}^ZhzUe854s^lWq!J0>uA6 z*KyZbdrKL^ z9Z-%lw8L^m}|R zIn(zh5J16YD)IqS1`A0UL`_G$^dD8tW)*s8C0T;B=S60QlVGYJMsH5j0$?e-S zA(UX>g0>^hG|*McvVxrm=Hhl$>9#R5cwZPOt4aU&Q)=nzE-?(KlEPVO**Z{SJR%4) zkH!QKVZ1w#Tyr)g)s)jNw5RVCiu7m{NQwqpLXS`od+HGlMokAi0|dB0@C`wgib^Qk0*C>9rvl#2OW);7xoz+ zTTyn~RpH~H4GO1_rA3g?YSJADdcy-l@n*H*{;0`r3ePSWI(NCXYgt5)?7?1#LJafG zKkh1Z^2w5HV84#5DWWI`?!1zo`mVt)#Y+9r&zM75)XiNsz^*dm+N|cpVI|XNi3!?F zw)%$?k+qO7W9kU+PzUzbIOgL0cM)b0H4!_=cUW_RU*6pCaDjel8gLIZk$nH^3CFVU z0TcFQVKQp_e}Imyu`+h^QP%B{uV*qF#x;b(#I`-9scG$Drl@U#ofIzE7NjUTN272M zz+v#Hg`z@BrBHGRbUux+O>w?u1#fj_?VK3E%Iii)Dfs$pianS~{z#QvUUJX;sr2%v zxyY`lmKgJwfhK|kUSaUlJ&oCp%Kgp7mKf%gE_!JfUv_0D&Zt~5Lo}|v>5AUOIG>O% zKL+s(nTynT27cz8T1M`N;)qcpEtLE8ks0H z0iXV5buOoNN&RL2??2{|-u+Zww;Ue^lO7)|MaY8^2s-g0 z>*PRA9%nf9s@MXe>?$?M9T(3-QX@r7OI)2@4jfi=qY4DzJ77RR>L5Nt4Bww*1 z3~fBOD_}-@m_f}Tia2hJ3cR>kaBtxz8@u-dAqBnow)W|Wv#uuIY^cHp45~<>$`HWr zjMaW*=^f4N+t&iIO(*tBXU)+|cXv-}cj!FpMA=`=%Do)3)Hqp#U)G5adLuv)Glu|Y zt@{gN9;4KepWdi~tP_L*jpGN454VxMv56#TxxuChdVT9GYEI&k`;I(odq9PX=31X^1A( zaMG3phVh$=N)!gn0Quf@B#y=rpUR}L>WnfdxZJxO32F=`t0oEW?hdVoS#vQOID3#T z_xe-fLoqR@Di7~R@*_pMN@1;M4Jh2RXX(tayNVPQZhNFIBQgKp*|rNm*&4SyS!|rwZu1(+mm?+AxHxl>B`+? z4nRWDW#HFH_827G`Ohm1^2YDIwgTacmIHx_h7R*(1(rJT1tH8|cpHas?K(PfqoWt^ zNve~ar7(1=kZM!_ajgcNEEl0vFj3&*o!uVfOfDA9NOZSzAH7H-i9 zQSleScP@>cn4@yG;Ep4y zps)FmX%De66DSRC;n}j!;bCi z10>zhic*3t_BSKO*zkZ=hh8?8T(GnImL92lhmI`=$%JkD!8PI7OvOTSzUbPNMI^-l z!R|ztbxmA=OnIVvAnYwWFSr%FCj1mOrz``vc*+V%4s4!FOE}euzn)CNcTeh5SDraa z5P7{HHhLYTz|3WE>q|T>7nFP?+%6*%kF$du+!an}xS_D{%*3#AQv9HiGw0{md!)`1 zVldzR#*%ZrWfZx~i^yZ0Q$<5_6ABrtcR>DPo5iw84MUtdF} zg1bpFdUwIWw#DD=rR`Wz{Y!GS`(MKLgA^}4J1AM%}a;%SvY zjYDtA(aqoPn@m0r#A?RHSZRTeAEz|TwWf;Vtt_9YTSj=c*-2*+9as@`2yZ-G*I#Ad z0oi+V-~R2e7>`bT-zPec%goeI?Rqh1i7DQIv*Vg>OM~E@y}8vKIotdD>|xv<*jA8b zpSwbVY3K?h{GKbWo5lVp!4qX{e-xLmU^0-efRjXMZQgSkzIYVC1|sUjv%ZKBUQM|> zkQ3)SUQGr#QfBqgC;_2Pl%05`#-^-2Rg1b_L0aF`+(_t)Qz~V7M(VX(tGhPDM&wvrI}+mTN$)y2`#ez!j=5Q0NS^!+`< z9mluopmgc?JSEn}3)(dluVk_7?DBwAiwn}>!qGI`lr9EOF?^4=_>vNohTHbe794S=rGfog1S^O!WdOSNUUW){3j{!B=B3Dh5IlNk6oV4(kEB_DhL**zh^K*YCQuY>PMvI3{^VS0pc zbQxO*Vyl}S^3Wk|sqrf_*cE64*m41}44VNb3A~z6C+0d?Ds!=1a#wppb(_vJQxq*! zD+^*lbKcvlJ3wbV=bf>7L^Cfb38->cu+>ub$9XX+52A}u*nfJH}1z6Z{UM~hoiHecy3CR&U-pUQ`5yfy6%sg4TMZOo_~qvp0Hn0 zBfKUy8Lsp$)(<4~A@01V+w=y?Awu{|VpAGXqN3yNseebGfARcNkw60~m5(UC$|eFG z+;N8@$7{aI?>%rf0?Xi)6Mgiw$xhyM)drG1iG_4%N0 z-2zr1D$4cS{nRO4Lf<|0u^+O3$282eZWyNE;K;DSs`D!K{ByFls=KbSlD4`a%@ zilWE=bQKG9qXJE<`7 zx1ZkXjPe2lbPQ?tnrE^-bg{m^@co|-4RsW-%F=Vzz=5(C1ALe#O{`L9v;-w-_&HEA zK#SV33Q+a)WrbZp$mCEY=KFAZ-x>#o{davG>0@mLu2_)BrI+*h3W+WM-AkH#?11fJ zxIMs9%yApVQXIxjH_*{uG}qbw(gM0*+Bh*N{ddv|5J1#*Hvnzb4OJ*GEc}wQxzyrc z`R@#LeC&9)lhi&G00Icem+nT6AwfTNxW(P)e3AZcv`8^*kOL|VNKM&gV0L8;wo7H~ z5Utz^#NG11OTDeOw*3ZnOZh7bb9 zP34IGBcvztS(};a#jwil#5>(4=# z>ut@!9XF%QA~&8nX8#>KGlPMa0`@+1nrBK>SMz)ZKXY^lUi0on(MNxmK<9pp0;mKpE+9C9H=R`UD`*J9$2JKqzz8Z|C{pQ zA%n1x+Ylhnqm(8eCvlE!B^4*bkqt7|@lsb(4NBR~`$HEP3i{|&RZNeMXSiIZd8d;+ z$?%Un@^HIef`TQVo!?tmJ=l!lABuV#wOa&k}Km|I_vCY2!>2YDm#{$wLL z6O^oH6qq@zTg#RD?sMUX&eB?023>s@)}q z)xP9iIC&hgN~6jcppF+)9!^r^INX z*x9;_9|YcDa=ry!D(SfM=h~M#o&;OC-gkC*y){H_RYzZnFngO|QeLM_`_=!ifKVw6 zvm)Gw;jlsdAjZKPS`_PofngVwBj?42_KCI`$(JhrsL5*y@*-rVI|h4!%OtzsCbB1# znCvI(N}Slc{G{R{6Nfa1k1|ua6_fjDRDY;WFrXGu6@hcai`>--3W0UyDplPsgLU=k z)gOZ#q`4PPjV@4DqS{OL|8$-5tei^pj0fov{#v+b651rSJ*y`o^O$4%AV#lTucj<#Xb4Tt9q;n!1$jYPL<)IJ3`4vL*(QZ7&73;P0cg2RiRBOKLAeDPE^U3W z5~He4I^Q)jZGlzY^hEa^JRK1J1IO&i|BV^nMfI~gOy@g4PGN>dh&z@SEU8@2#3A$6dr z#u86zIuzUA{V9xZ^5gER9+vW6ceck{3)@)keGAyeUY|y$5#8PqOW7<9np3Y42BBa6 zS$dwtGWd?zEcI!vVQOxYRn!hY@?Bzs2J2v(Sm$Kb@r{TMFPB1R=rN@WD##*1+3m*r z-OV4Yb=sf+P1Ww0Hs>MgAr;$;L&gxT_;Bj#4Q>}sTGebaT(=lq60*&oi)X7BweL@X zn~(qaO)%nQ@G($1iGnZQNOGB?@Vl0vFv5JnqxePtexoq4iH-L-jnO3_->@KM36k?` z1Br;m0wFPW=9Z}P`Zck4@Ca{1#C$9D5Zy@&R7h%woZ1fDSV&Q*U2xob)(e3rQNO>L zx)Grbv*wU9ow^bvP!h;;`Dd-UoS~SRnq>&wci{T4{W2>w$Kgmq!^u&s51lG2hgEKQ8%VK zT3&t^a_M$4d!zJ;cJr0~=h&hMCACjR=fTU$m%iXg3T)Uk!c7<(+jUDP z(;OMItm0$loi9yJ_=C6JchoI7L3d;Jb9q09?vb<;@%sRrBmRhJy# z)Y;TaOK;7Ei!V#yS1^Gs^Wm&wy4I|LuF_)6v9G*RI9^99uhyCywD;YULg4T`xm3L9RB^@>!_38FcEyPi_TU!N*g%?Qpt9-`Lf-N?A&P6c>3vKj1kl{ zePR>E8vOqbCSLca@23dHt3G9Wd)qpgLBQM=layI zODm)+tD{iL&wF98?LlBG!!a{2vmA=*gWTx1ThHyzDpAC2DEYcSj2u6!V6hic*|iPY z&60QMFh*mhvhg`S3DuDd$8qNYz(&_}EFWMetJsJ-%EL-qUTSrEIq{jNv!oU8$8HXN z>KJ=BSCwlDYIYSUI>7NRw{sURHowqmJ?nye>)}SJAQao<^yYADS9qRWcx)N^C}M7XjNRGHf>A(Ra`;A zfj!e8Ytpi+ON^u;fUHK-P)m&^X|0-ri8@We$3%68*DLdYU$48rm}~8MYtPZLm_ zI^&$TU~1gswo)yvLg7pBXQn0-M&%)j2f_SZ;qzD8<}-o40yzPO<;BN_AI&4Gf0sHy1VbZqq~ixS zzdsO|I+dt4-zBCqdCYvEicnfEwssw4JU!(Kuq<%Bm7bFvC%ZZ+@bV*^VD`-#9^q#; zjx7#kYgcaJ?x#jFR_J;$?&l^`&Bc9Wc5t8P^_rY})L9jUY|?Cf7ff^AM<)Z9cRwnq z!7Xv?<{O4wdh1(&@ThS-@Fv3>txs{YuP?5(X(gSUa@u9|two$iv99wlbj4a_jKS!m zohz89fpF_usspe*90ykA>(S;EcSba+P3UvKSU+Df{??{;srTUA*=K`6@(zWC^ZOOh zot)k~y}pUhhD}^T<2DrBUz#C^Z-%Qsw#Z8$YVr+hzfL3kyc)ymO4!bi%CT|ND&e@z z{Gi5vP7vM9vd{1x?`;c?1TC$*P(g8MiIcadU23TBZu_9iT!Ls*2(9yd28;|Ou%_tWa3#GT2kc>~udhF~o%78fG7;q9piqq24@uz~P&i($7^ z>F7>+|GrD(VBgi$o_1PU+LjS*r2V8IQwxqMQn;pWNLIm$R`B~4|LWmaP)z-L&n;<* z)k1_vs+H9IVc7f&rKr#*&~eN_w9-7T@O!pG(WP8qs%>WkDx!8I;9O<)vnei^te~=f zBqpI>7IgvjM#D|N{9UY=wRhnaXw7a9E*&w z>{0hc#WA1aKRn+}E+6;WnMYQ&O|^Svj3##9{MV;&gv9=QJg@~1J`9nz*R}tWxUHX_ zw0Rq~qRvCVpyK@3KkAIQ$mU&zdQb{*-0II9 z9z2%kIZ*dAW_<5|N19rl)gx$#S^-CrCR+Giv}%>7cIKij?>=je^16=U0CzIh9`W|y zDbNQLS4_y66~YD!US-)W#A*pR7^a36{Ok#3ytR50wNkzI{^bCPHKhQ_)1`oLd7HO( z$lp~HQ1Gtf?LPvwO3tXCj)b&L{(rDaS$v|}u=&Oz%B@z(;4;_VMNE9Rg9ZQubCIiF zwx;|1fdBoE&knG?F`ap{&JJ0QBqEsj7Wo{*r82e$3sRMQSKglk&VNwCEC2{!MFB*Q z>|fME+~(nsyu!rw@GtxJ7v6X#B&x{)3wcj~mXy^)*AoU&_Y%U>jHhZOiHaJN$kZws z{oN{n(-gR;fTjGJq!v6rD1FZk_^Q=E_(dbFmJ`4)=4$%?wmbqQs9n@0OQqpX4IH&1 zuPg~}MEGwE`~#?TXh?JL@qhG#Rh_0Q{GKL+>5vU#p7KgB;P+6L_L6$}bWLynX9Cfe zB0BTh;wbXkdPFeyD<6#lNX&!xfzdM}09O7^5jcA}*;u{Vj1@dyL@24kb>7eT^FT}h zv^4!c00&@^SOLC2gT-5x-kLKdi6Sr30J2HEzFrVY+3%i#ddWuj&w533p#WTBzFTQ5 z%tHrKC69CT+Q!d?T>T4CbDsQzhG>MI>B}l$?}#jqN~x1dtouvuf2p~poVe}SrSYta z#JafDKd&$JzaIbGqK7BOxM)On<^?Ue4J^KgN9;5_;=Yuq$N`UwxzQY%;3b6!c2D~c z*a7ol0qwYJq=Lvy(pkKJv)@%W?$W=>$?Ef-B z1kGPQ+swI}ET4_T-K{*w_hO&DV&+>@6czB>J^C*T0L(Nh!bJh=B(l7#lJpH1lR;)& zneP-;fIo#qo(NRi7MbouqyzHz?`C#F#quh(5@n`Y#ys>1 zYGYUeisLJtsuR>rCWQw@-vg{6>G(?tf~H`_96;Ot)AsUZfKQiKUJ2z$P|Lh<-GnJm zB?92_pG7Dz8mIy!E=Nw^JuDfn>_1o!U~O}N-;a9%AF+4@P$iwYGAQ#awT@7Ekkr^* zYW_$H$`x{@eB*!hiRK;{;1jUl;?FjqNJy8U&El=f`XLm+$B6oJR zuhf;yIbAeUTUGm--CP(|C37x&@vnN4tMt)^o6LpI z1+4KplBI1;oZJ%=Qu%7n5~8-nfO1Bw1%EsMpH$K}M$&%ZFCJS0}Df!jrD6_W3 zI~Y$4=|I2J8+j_QD=TUk{=-*W41Fw65&O@UtkVDOS3c*t(GRRGY|t5Xu@CJ18i9YS z9${izAa&AZj|oN5V`fn;@Eaub*_|P_`+nu(q7yk@0i)7(2JrSC1I`YX z&=9;oE4Qa3t(YG(pSP%(k97CT!%m$WuZ!4sI(n~R5 zxx|O5x0ihGOWLn+eJSd`w)TJ_^vaU?&#BA-TtT}|H{kBuZHF8FEC12VweR^9fC}wO z+$;{{9y*k+lc0l(cojqDNtzj|W0mF5k$IR=xgkj^Wf;XVSY6v$erp9H>0D3VlAK>C zTPbo>LRmLYt(rZ6Yoz)j0Cv6g;D0qyXBXV~lEwQcC1NM5`RYF>c_Kp}cRB;L0#0@D$IX{o^Z(UC8ih*%)Ewh%u_jAF(FJ00?2{8B zKuP9PL z^Z_x)zl;uU+ZI`HQWYjB(jLf)&1g{OG19M5Pp_p*0JTR`3wt8%wq3I2>?J1_S7@gQ zJFKZ#g@p|pHEZpw&f%r65Y-HA{$DuI71@4iq=RHxwnYKX3JY7hl{3ea=-Qmn^`1yx zgU>6meA6dt0q*t%xVpM%oM6F_6%j|Pw%0Z8#Mu?(R{vESuM9Y|I_fyy#3pn= zL11`@khz7TL%pw@u!D1s!K4S=Xb|cgIui+jXZA_{09AytiPU^f@CP2wndow?d`0X* zn&R9^s9!nZuA>iwE~}0QR7xL*LB>8^#z#S?`M=#~3U=?DGj;KTlhiYU1Lm$1m}`qr z+-)sq@u2LxM~4)Rvg4F~5le+Zf;sX{)mb4AzM8G7T_pv7?53V~oyL6OZwq^km_I~9 zbDbccJO$SmJ1ZAspKQvNG|Bht%ahTGzXFK$zdOvub{u`YpdKS2N9GTGK4=o*dNhrv zTDUeK44^mBN>+=a7v)xIGN?oLI%iQ$%D5Lyq(r@f!g!;(os(|ju+nE|b9}s))_y2Q zmMzxakS~NDZ0)rLa7yXeaE8>3#|ahpa|^_T5%x;z=+pMfiGH=hG%Wh8G3vzaT?otP zJnvm6sLSs?7gF)xB9&fz@G|emh}kt%YTH^35*Ol?v;QFR$Bo+nyZu-9VJL8i*vpc5 z8r}$%s2(cAFO$zRksL8jR4sZ0k8rLDb9=-|eicwaI5h^Dyo#Kd%P{aj zvwX>&5n#YV+i&;*!Ej#U^@E~WA*8vE^XA1V(@>r9Thbxr_xo5pye4-qXR>%~=MPzt z4HmV92@ZMBgzWC~#ry_)Z1b;eL5Zc2cEO%aFI1Pu_9Ud)R+W61M)Kl8Z2q=IF4M4v zWK(+`{NURVraZ*UX)(heQ=mqbGyW!ySV`HQ&4vwyh2Lt@CM+mTdyPLW(SehibORFG z4cZx?+$IumWjFLWgcj`2*wa~a*ydLwTqoBv7$_yC+?)tpCj4CuU4fPuqpvLqeHMf) z5cIsCSQfPteXC*95+>a*;2=^*iEY^)yo z$Q7r=;CD;FUz&wQ5#WyK#35M5)&!zSbLq#lH=Ai{1i6@p3u^md{l5LQj`W+-_*xB^ zo)VsQ)?3@C-R0ylzDb3Q5p{80UH9hd5AfP2%wZ_XDV-1=lTa zvzb2etIgRpeZr5)n&^TLf#5?P+2_gu#QQ(iF+Iu~Y5vOu$ciVuCgq`|oDjkozy)Cm zlx`FIwDZC7hHP3oKO(yEP^?qCyEFY#9Cp%=UF={c)o9 zjd=wd8M)t0EY zo8T=5cK+}4nplt$C)Ne*HAaZ1zx zMGNej%w(wJZfL-rLq0AS2`_sortpLCM@m8&cg6ekjrteLDrGX%KOUUk7<_pVZo_%Y z1M`n%R8IReP?l+3ijv-(y5k2Z1o$SzQDuD9AZpE2y5gHF_5|&5()uYmEF`Em#W#Q4 zB$e*10I+5IH=*8!yYSD!#=&Oc#L7NLGegqPiur?Y^B2uduHyd%S?o92Wug66Gq!u6 zn{R^jXEZN!)uT_S1@;5c*6&dJRu6N!m`k&bVpX4WUbp$AuHwCvvqtqCygTU-T9nH! z*BF@HZTzuYK#{Cp_Ep%N#!khnx!l4Oh_Yv=?VM0E@jw7dqf?frGNWe_HUG`NZ2*LO zwFD!e6u<7%yI5GyDVIg|t9O}XQ;kisssYT(TK>0N$ z?PYQXoN$UBTv#-xd1m=qs$6o&|Jk9p#iML$g|AN2nYBz$#UAM@ew&rojYr}j{*Sz< zvc3C782aYmPSfGOUn3<&r;SZd-EMmt|GA_?Ex^sx(%=N$&ok5D`6n#U?B3TpWfexf zmQ+;f``k0{dsbj~8<61?p7PwG3@indA8XdGDI3>&FJW~=6k8?RCpLrxPHDq+5{l{U zJ{O5FDm@IAP)wg=j{=DpFQpu29x)=N6#-OLWwSy^(& z{a*)|(x`x+OYqK~CPi zHOycmwMG&oIhFLHw9xOY|3z&Kzj9DMTdG=mD*Q8?Qstqrd)SS&m3kVeUy=9W;Z4Tl zovlgLw#1|dU1yVxIKF7Jt>Wy9RHGUw8HA-qWQnZxS4vSOqp^>0DDdHCJqq`Jf#?+G zl*~KUX-9u!z9y=rivyxIg!F32?N^Bh6`!3cuBlhA*V0+Mh|j2=(y;7I=f6n6EK0rhn<=Qmh88 zKuDACGOzusFYYy2KNlK0dui592Ijr?uo00N1G+rxop-=NL9DJ+^%w z#NV&l+>6}SDm^t^f7WW@I|F{EnwehY$;h0`sYlVeoE|RN<0nxPyZ0OJSj*7B<5G!! z>56TOI8ImF90%i)=FCUNPivFN*SA}8)=s`wxYlpg*H#!kJ#SWEIFS-+4~mvb+q`2z z^%$_ljkV}iy`iqixEyJ_&W;*ZR;#Ue#B@*5lXCwEpPk`b**?e$`*_tigGGQ8(_=5 ziDtIvV$i1V3MlnPi|x0T?hSt*M94DViQTyFVNFf4ohN_L#j*e+Fb55E(Du(K)pp?N!gc9)>;X1x#R!(~@=_TMgUfsp-Ri^Sp-*edp0$o(oQoxKetzR)DxSbT1JDDn}quPq(Neb(J=^N7BkN-75#G zYo%PrQc}6Jc1oZ5vlLszqQLDZfw6nX0Ry>>yr@|+t`_s_f5&KlaFLCV8}N1ds3!=T zoCPtwHz@t?<;i8GUP_XaULXe?P za4qusE#Ty%Eslz|@ZavTv%b<2n5B4r_)2RKmvteN>w_RayNVKHGMD?XP^~4*sT_nG zofxS~K&ewU%b{M%C|OTa*&4;bN-*<4cti{g(etLr091(1cp7}bGwQN4Guu#GV|5~s zsD$~6a8x;fGp+`#RGvZ8{ZX%t7ckutSyEJAD?{JaP7OMb5|%~?dM&C4oGnPMLkm1A z{?+k=OM^(|(%{|<6rC+q0^$m=?=M5KX3`Q-p|_(%@*2uMK8IM6XVEQ0f##FArHFPm zHcu>6R5NLvB7cWS$sk9a|@q>kC)WEudx%2$eZ3AzPrGOopzY;2W01v|cnRQG$AG6_ebJ?%>_JqSo~lG}L~fMMUOSp{LTjRXDeAF|Xmv(+!!)?`4?umRBnMO>3K{n21P^wxUg9<< zfVo=y5}THKj)}-6kP8*ONi3L=2V_)lgnT11GsAeJumMxh$Gz+Ai)Ln+cu`TG8lR+A zyj=a+5)0&N6ZEDl`RX*Y>)SCgVe4jQL(;Z08-IytECS}I-OXiY({8E~Ks+&keM>X9%VmQLD z$qDvBp2W0m7I8mVCc~G1_a^!mqq|8OT*c8#77S_ZCsDZ{ZK8>{>8yG}K>Z}kk6{$F z-Bju2zvn}75+Teo?X>zdy9Bl~<*N+?DOwa^Hv&0Nc4!xxB%mWB2WailPvdX+fBqIA4ntwKO;8O$diAuBvWu(WCL&K zEOpiV`f!q@fq5d6AwT0@LM_CAw|sb}DV+#OlS|yf+~8Ih{4B&@knv}j;BKJcuLQE? z6s=YE;olN=k=if>ElG)~T1x0(eG9)IAL@B%U+hO8UxQ0pi@SpD#iMM2zbY+;`+v zet0SY)vVw(E(@qD;XIMut#ePpvU+k4YM4crNz(i|U3b_i@;hCdL#VO^)}@CP@LsqU zd|v2!8@cQ~)LQWyJ456|fOz(5{4Id=aOq_&bU6F>$#EIp)^je)T2XD*#64z63PzxO z*dzF!uvxAd2*g1R)_7o4=cXIXbaE)j#jl)P;Vhj9LXstL>pg4w5^twS>8YZ&@?70u zYDX9qdAMUv+?10azz2<*%0a<&47)%@=`Z0XI>W8V_m(>j3Z#K#1U1zv!0{8=Zu9I7 z5k`+fc!!)SqkVG;5fA*&_cW)&3D0AtZn#7Ix7pw;W-QTy4! zE%j)vxc2f+uy-4XCZ(tbZ?&O_8u~Sla#gdfr0X^WC)Pu?@7dRu4r}03w^JE5Yhi!4 zeBT__^=`rGc)<>lCA$xyCmGae zj1+YQhiM1&o=xV~?S&1+eoUR*i-(F*hf4`9PQ*)z?r2ZSYZJl5ofi(^C1C^UYG2K( zw-lL=1VOM{dK@`fTfmzk)w6>U{80PJhc@w>x#GkA#Qm>pE;Z5TpAhqUtbSvl>w+XE zl|;u5$B^v{CJPO-=kE4zR)q0NUCc$pvx?S6x4S?`BoG}RcBt=u_{yDER< z*!6-WCfD`R4)vUHHOUt>I2|MbXC_ZR)CN4kN1PFTSbMQem|I?bpjbv}Xu#@Lt@#I$ zSnYEuh`m&tJWh{KI#olsLB>{2;qy5!-E<0FRWie1z$D~vRkYEq1=Iw-{d0SYX%2bQ zlzN2GZ8~d=PGL|2#l2zf6+y347#}`SLF4H7E3C8^D~kE;ip8ely^6r;ZV71h=k@a` zc9*FT9d3>1wSB@(*4Nhb(9ofgEFFsRxvC;XE25(GZCsjI(kWm0a6H8}kLaiheBm#@ zHu_OlztBV5 zaV^085$2+#Hby8VoU<}Z&O@j~NA@kXC+V;ZYEmA1+3vsfs23soVm=_Ct%LeE0#>Dg z1K>ekj8_c2Uh)*4HSz~OnmbnR9zYs(4Zf6!BfkF0503h9uRjqb3C~*I0*ikS2ngy# zNhx8^UI=10baZ{{t$$!SP%)_2-7WnVkl75RbDQaNdp*bDADu6(1=F>@Fu)K!n5E{% z&IW(CjG+vL?jt0sKYC>Uz>zl)4!F-aLNcB(e#=3ty&iC zM*1_|=6p~pI-;`r?on{RHT?YFOk2@HZP7!7wWk{9C?IcB{Ej)yo@QFqIMAJId+C&h zu%56Oge5RwIx71x5|%6=nr>B*Rb6SGIWhi-LL#K}n^I^Aof_baX;L3t)hT=~UrBof zZ`i?~@U|5mMSEMKK@je-EGU(a*{a;rqH7Jleg2ICRNQ(2XNGUWj^LxiGV6;oy5NER zZ~oKGW?JlMb2uG$t6N*HLwmu8gU8Odg>=lo*$PsrMk&XZ@Kgzqqr+B$xWdk&>vR!3 zRkt!-?PsOquX3_p(50dx@~$ZKr~cXAoGXrSXn&?dOyFXUT4W00;NPkyaVS}R5Ff8h z(}Q5#wj(bI+_yE;Hh)0T#ZzAP$PbwJq#gw9Lpq)p06yxV1nus(9qN`89`Hmv!kH(1 zR)c*z{oz@wiaLc>8qso zGrUi+1yh>#*Low92`t(w%||+^Ee{vyhSnilmXCsCRCyDd-aj;(bY?0yBv#F@gMmsq z`}iOc43V%w)=P%`1un4at84JjW4PQ|?Z#tsPi`TL^*itWQ_Jx-)bE{=r}XFeywXuC z_>Z5ItEPttMP40Vd9jav@0Z(*Y6C9DU$2^e#ekC>n4d{{Yt#(S$q3#n%~!$_cS zfBV6O^tQ5Ew|l|xKT18|=*Z&%#Qa#r#c)K(l$#>IBBo}tE-N*>fa1B{-rfO}gKl_^ zS?4(@w~!}^Td`%50EzSgSlV}Pyds%~kt0N|oVO6b#h1bivD?2d)Py_3 z4F!*Rukdc_5}s8W4R0G2uiNjRa^->YsYyah2ihxW#Cs5OB=B3>tR&vg>lCY*n%)m} zL{Jjwmrv$PoxR9%4$#1>UFtyWNwDV8RX{wKta+eK=$LM0U-0}WuD{epF-0qA(+ZEI zge94MjCq@FZ>6fgWM1diTTp0gCgKOihq~R(FnT9zz{=>QWGT+3M61V_Nc!wysh>A# zd34-pz>BoZ5|xH2j+-cqAW0fsV4~5l;?`6Y(WFGkpM$3jXFvGRmGGz2V;Gxfcwwd{ zvJb0k;|?Jgel}*(iX*?g;aSsVI)y1#0*tpfpY`dNMZDn{=i;84gwnw9Ym&uoET1il3r(q>2_ z1sYFtwv$RXPCixo=5W+BYNs9<7P*sZ{5B4y3l}oHSW~%bo7NTFbZ=;{>OQ;-sEyuc~lU;+5V=-)|DAluzL(`|7^ z1Iy3RA3qJuP|Owp8W_poJA+9kjM3d2j@X0mI@}RTxT)?!UZVoFAGkFX_t=B5rzT7n z%64{#*y@9y?||-o-GceV|CE=Dt6k3kE=N3;N@of1wgU{@ceUO~<16XBiPpKgH7W-T zg1>^ZI!0W%W}4B$bzl{bzvr9_BxC#)BvBHD$2kB$ynwaP)s=Mr|C61$jLD$-Q1{S` zXtfW>QspaIOS+Q?ZQmDMLlyEP+A1w`1T+7PdD~F$y4dtsVZy@DQfMn1x^Kh{RC1&f zOmZA@ZS8fAMB`bL#V!xok5^phclEd3z&DSr1M@#mdGv3uxT8<3RC4l_3e~$eJ&472 z?6LimM;M_hk7LfmfE(Xf0zJl#DI-lH>yK6|@Zkn#wMin}N157)eXE|mWdBCz$qby` z#WKMj$l^rk|7jt1G#KrKX0i!J;M`DbC?y-dZ(_ULz^O9QHorJA0OB5?VAU>(Bx3{! zvhdv5;rbdoL6AYpkEj5qqxxJG5*yZUZy9!7v)x2k2y?URF34~RUHv`S?8n`Dr%HG)atpeXCU2g&_&>^LAZ1j1!=M(% zHPP@o?DF2)q%PioaGq!o8Jb&xl$vCR)c^L`<-5%mi9Gf;<+aak6Y-P96Yt@-&_(yK zly@_vvKNIQyO3_j2y2Egn67``-`34xb~B<(4CZ%|YTGO(Uuj^He+m{dwoL)?9HUnb z(&8f0Vs!K1LNkQ2yvx1t;n;27Z0JC>yJA(~A(uKdSaVMaX#0O&Eez3*IG`Ky%>)kR zp+v1HK##xOn0^?|k4;mHaO_!gExNn4dSS^++yO@zmKykcv4}8S56YzQT#wBB zy0w>Q(JTp!xkZ%UPnhfH#KuQO>Rv3pnN8fH!MZhUNcK3`c`O`70(Y!=GFBXos+bJY zPSbkT3TB1+1~&UQPm5oLL))Nbgd|-`EIGY$t# zz;)>Q7{$=xXYV6El+b9gypaHEZ4)mDHN5VHfx#i>CZjJC+Sk8)a&pfng68mFaEDmo z7I|)4dXb$baAuMi9QvFLB$yJemGdGDna>c&ShV0*Z+$f%;e}xl!_W4n02+S=50;Pw zD%24}-@nJhQ*7_tO)ydlc;bHn_~s7hq1ec(FiNP{z-JYS@+bin&#XKn_wDS5>TU<;Ai)Bp?S8W=37MUI=r4d-yHuSf`=%cnlrdf-&Wj)bx#1= zld@#dW$~4}&GG4#3xx`#8LJCBT-((}*K8ri9k<@zV?PlU`g+2@D-Kb9$JV`R{k&-) z?q0IEc4Js@G-9A=cd|Yn5wfrJD_tw6MW>X+=jJy?D8oa8!w$*y?g~^oiX6QXHWfzqf(wpy(o=3*ITXUX11JW;@KFM$9< z>b~^=M&Sn)81|R`GFsIXw*ICfe?@V zA@jVg?FIx^=0q2A%GfjYq1rsi7%yX0xkH|^K}01%8-NO@LdrNCU)V*$7&nQY;~xcS zsFiky+W@4jCP00wsU$&DseE&D*HqgF6Y>v3y5!>#|%Lq0!l54^YQjTxYi z!>s6t184NC|MXq9Y7(Pvme|$8l(erV7^JRu^pYkCCZ69Ub|q)0JbyRlX@9*W{2?*s zlb?oeW0)|pVNYbAlcH!zlGNF4!to*2%)`YXcMaCm8p3yGzMHg=iyZRvM5(84vtnnH zRtEV`yl@n{!MJ#-?xG2x$Zuf3QqRR9#n2$Gh~pl*{VBLx@{QDm$dH+dlO=j!62URW zfs;+GH^?e3ePegw%doX{cnglmLPh&(!E!Dblrw(HF@BRD&~p_!L#kC@OXL@lJtKUFaZvi_@4LN!4;`^N*?;+t|vXXW&(=Wc+0r51rRC_Ie`c+1A6|7%5%0Gfl_1r8Hi zm~@2ycdMkU4vs34L;WUtZBk=+WiYU_9}7noJ&cIOxKICoT8%!ox#{LIZ(%jc`9F7F zS^q&W^+!J4`XAP!AeS<>`$FQe_3ZY4{G_B+!G>E1b^1I5%L6=flntX70<+$|yx4bP zTT~l9d2rO|bs8E@8=3l=^Be9fOnHCsK{0OJ#QOBG#5xd0DcZx+$e23Q;%A;YkSFK$ zZ{PXY9FT8a|BF8v@aGNIj$LXwLsRhyGot5L1Apq4nvE{GozNaLJ$o(adj ziW=NYZUu?(>;-ix->|#fvp~PG_}aYVwlEHRp*NEZ*vg0+PuBF}CB~GSZGPv|&Z{S2 zJ1yLcX%}qB`!x2WB^Uadwf!8*4RW9+z0eY=Qk&fVpz zIVpS*?dYo9|3azN=KFGFQ~IsYw=CM4PS@&;Dn-A=b=i>9#IT4z5h679pbi%x1z+?@|bw+&4Qxw(i=X%})*PYx`)3flH2s(i|3@zFtL zarI1)^Y)K&A9*B~+60#x{fNJ(A>_jwmVMf`=9kL{?5O~igd=SLMrpQ?Z(eP0)Khvc zOBi}jjdKaW*8S)EH?~42Y;lU zI+tcPOA0WuN2TELFyHZ-Nu*YD$gf<0f(W5^m?K9wv?A_=YQ24cDVhtn)_RRyGs8 z8xoIas6@V_v1s~DTBriGyb9FGI*(AShOxUoLx7`RvsB z7@wFfUh@K4GD?TcReJ@U$i&EUXxNI;#tbrum-<@+78_|}0o+MgILk#vmN>?!X%?q+ zO3ZbEPIZ;^qiA-O&O2zkls3!G5ea)woey)To|iw)*+gz-ww$Q(llHYg;Ep;Tc=j!D zo&xV-@VcwwjP3Fr)4SZX$*;SaMDt|>#I*aB-Yw{#5eFzA-hR#HCuM?L7GCblG5_83 z))({M(R0lpy#3t7s>Gs@TdE%QEW-uA%}A7ouk+aMj})*Foj$A&xfpFL{QNn(^?15~ zj#qnssWL1Nb{Qg*E?`h{_*vnk!z29H?}Cd^2e!m2mG*|6VM-=ftH~IETuVL12aK@b z{vV|2z4H#{e8=4n-!t41u68mLAH=iW`k&ywBb`j~Lnh;gnvJpHpwkZK(}^nWnuSBXz>`QaP{UgCxX-Ri zh(y?a3~(li*m>h#r_7drJuVWvy%ZbsYQnkjjnrnn?0~9laaw)G8(^0q@IIH+9l&@5 zUHIJ&y3=>lB9AB63`3AE9{KOvVtJD;9jw130Xo-G z37NWi-Q1DG3Kn*A{Cwc4#omGL>6*CsO1?IyT}@xHPxl+a-Bn&1BHw1*N3zS`Rj)a^ zn`so@gesPOY!D3IGT zEFiVPas=2nbNHjVXfEStk0;V8kzUj*;m164GJdRuTFHNb_l_B;6s!z!;Zib}m&J~W z&c~Tm2ew0y>B+D&$pjYpv{y9pZ+|8!G#PC3w#x;c|A<~VgL~nJynQsf9l-~+iH($K zmkwxsV%G_}>o%-6KZR*uNUqu)C20v6m{nlM6$ln=hU4s#_uK7~y-%LF=?=R#_5szc zu(Hh1SvmA)m1cY;fRq@YZXGmY=*V4!+plr^P9U8As)4qHPb6e=?|%Gwsd$NjS#G!O zHK~H`2EUTX*mTY^i`}TGiU(vVnZMdqdb<@X)~}2$o86ud|CRT9$@_e7%4N>EZQ_#&v+?;H zX`B4wXq+ri`Gynx!aE4}UpgK}>nG5;nZ}ubf!RB-1*+{!Y#!*2H8Qt(r-dluw6Zs3 zV}e^fW_NOUz-F{mwh^6M6ZFg9yy~Ke&1duP&O*d7`^eTMmEa>Z5SQo@nCfq4gHr|{ z>)4sX?PwiKSzjYV?r>dbx65L3MaC z0l)l?H@E~gX7GCMHt}o)$-nNRqBF|USsHwb=DLcJYz6m`r?flCgBDxJkx#Tv1ju_~ z|H!jw0I~|1!~+K-qgrh0nVot<8LGsn!}fy^SEI}N#1qx>|9}2w4WGp}I=M9hK=EpoP!j@%X%C0HmMgWA3QRh1={p!$roO7IJ~ZRO30;TX-f^f~)F< z1C5jwVSj??`fau@B#Wb2OqOhLiNBH?o2T-wAY+jnFjxT~^5J{#s2VV@*I30LIc}*3 zp`scX$rhl=(7LHPPR1y$Hbz+z_LuBdfW!5XXqJt#*#acfM|s);YSG4H{k*%*`gK@5 zfM52}0eM2&cB(;QoOV)FJCx!F$jVkpE8>1bD2b>d+Z3mpZ{Vj#hc7j$8d;E>Zxjjj1`D(nqXc3J{yl9BogJ5* z^Sp2@o5k0ys2<_xEBh{Xlph<-(ssjkM*K!LQI)`}Tw13$srT(2Zk>N^RKd0ObtVK= zOH%4kkI zh1gtoAq7@=)+vm4xDoM|-Sx8c?EUA-hSDFl5=iyTF&s5 z>@O3ps#>0pgb}5VTHsH#OwpgV|Mm{o)}-Y`2F9#B$z|P&X#f5)u^j#_;=4oWM~5=P zd?u#flufd>svm~jP`3~b+m{K#>IoSc$2U#oZkZW2H(7Z`oEHbJ`?PGz@&7+p9*q4> z6NYkp@l^G&w8Xo)Z_k@MwVtrBJ7rttr-gj!hR0xpR7zV^@5a8pcVR^MkRuOGUJBMT`OiU)hR63r!(Qp9k}gU&u*vwF`zEtbhp5u^ZY*&zoMENr*qQkjPeO3HmmK=RjlB=rH>zB+t_(9oJa<*YV3(yca zhME_!*{1)1Ol|pL=abE`3F!dugQK%I_(3*uik64@=6bvJrjS~M2U?3-UP1s& zCx%hUu=8JW{@QtZaea&gT9!>Bw2UZ?>C!GcfdA-tySVLGYgaW z1LPm8qNH%=$#WhSyFc>QTO+FAWM>KBv}T-vjt;dIx!(yjN{>eGMlo7Yve9>}kjY;p z?A7;UyVXQWtbDLC>(nerm2nQ}jMK8nXg(OO6f%4u!-T*ian zlT!2JEng|dPG796Ot7L`8?P}!rNr ztVIA6@Z#2c-R5m!s73S?<9IBce^bz%g6x)GNh)jU`1oFY5|SJ6e{pMI{iRXCf;nWB zJ~+9eg`@lLKGxl+VF7Sp)S(1`$doK?gg;|{ltSIwZ=F*fr z?EKa+_ZyGZbsr;CWnzS^6Vx7=t3=#fh6qJBM66FD&<$O$GWoigs;}-<@mQmpU8bsb zxs5-eRpS_gM$V4M|FBCc!Z(Z%H`RIG-it$1ybLwVACKGqo%x~kA2+c$pl#lsIbdYP zG|G{~auJE;xr|($AZgU`h$dONJ2P7F(fb{0zyy1P>s;=4rm0LI_`4k59|i7m>NOFg zf!~TikHz&6kJKAa;5%pe+~_gaLd)_K4WI2ex|$7IaR*fE#qY-bwIoz?q*l>AI9c17 z>5kL~ar=q#H5hcg`mA>e{pZ!L=yL7$*G~%TgK2%MfL*R3EEmMrLT6H8L2W+{(G%gd>GQ#hniLIrU=7`soU=> zF?7XSaqCw(;KWMRU)OG5FO4r87DY+-8ZMlA`a^qs_k0iT&qHtV-d`i%lsDAe)~;ws z?-D2R82)V5kfIM%mA;}LYCQ;^J%qCwp#s|2)wQLsBL^2M47>DSE{=k8+i20c+^W6~ zR)~K?!7>GA!S-36_PRZc-SL74(VfMtPz%2YHAjPgCU5au9ZO$19M;B2pNdPLZVp$D z{LUe!g$Xg9|5g~y@(|U#IZzpIx&Dy8;k#-oJ@}`Gp=a@D@YCZ1R>)4{8qo4+99C97 z>3Vo%&-KCbPHn_!wbnu`HI2`AIbjJ``>o-RQTwJBM}9;mv~O>loA=iKTE=c4duT{r zJoJ}#8{(MhX}K7Dn4a!^>>S{D)FMwR(_$Zb7RV;N|8|oGO}iqgP!%dBWvz{nUFg=Y zWRpV=Qbw69Q&TAKMwSj9{5&^ysgJ90-g0Tv z3BH)b**KCx-L$F`+75>g`SGJJK35!N9Sv=aH}9_<=JTWVTA<;4kExrFVj?u5PVN!U z_8hGW(6`nGHQ>jJ<=C#V|Ekb67=-UMQ^m@hf-yqVXkwr}heqBf!}!cD+q`Ywb3cOd z$Z{IJSDwAtm$a5_Yq%`@s=~h4Y$MI87_<73EFfe_VqfkNUR*`F>B8FdbhD}E9ys`fXBsBKxv2>SFt!P+^hQUs3!#8^2K3qJoO^KC?3>UbE>7NXjh8 zwQJT@k4!_r&sNEkvo@jIzm_jYzUIbA#jN!w9R}~;a&qgn^j@B9H*TNG99CzWjIA{R zL&iq%Jay@esMC9l1};zfTXGNJPe(;mlgc4PL3q&R=>UUse3`4h*v5@=iHn{QO(B=x zOp5!hWE(9g$suo4V}*x47LP$o3cvBSEv57^lLQHEcaQW*MFw;U4^zK!Spnv1z}nWf zR?lNv7o8&?{^43;p^J}I33;>cOB5)^_~8-C^J3z>a71JNSc=c^$7UVr9$=d9KM7vV zOS5|2s-2k{p=E0dzjGa(;En|TQeT$-Nuhf(Z9a;So_W^rn;!_BJEsVxv*uGSCS(r5 zH=>kFPWtn@N9F#WSnpTh`O%3xL=|1fDziI#iDY#*-(DtwEman|6U*h%1BmtrXve=1 zIi2Bep@~0WzP{el7<}P0Y14V&oyhm%-xe~s0I#g}?{{oi2ifE2G$Lx>G=uu&7860A zq$>aU0`$V>A%nJ+vBz4MF9xdG6o`eJxv&JkSQ&_V@4wDX(rsb@+9+?`8PpgW`s5Kd ziBwRs!Xw?LEW3wH-Ef?%=;^g2l?fJf!%Qo*!&QNP1|QN1N?|S^g#Z!Nr}*W)D$x0) zG;0{D6w!6(<&*Fe`DEks$__iLteUL_Z`5DLV@LidK%5-A=7Z%P_d(A7zV5KrX#%5r zo!0V1vv~S%9Ba0-MwMkX*hVXhunHk^q7e5gx^qMRQR^U+HqcP3wn|7le$-hK=CBq@ zaM&#Pipe6G1H{zNqWs|8N_Ua$upfYWl%LlCX2Eh``ofbF)iRSLeUwH3Vp#xZh=}YoZI@TP zX=1vAigX6S=m{h@10TWmVZ5fUCJ);6EGWPp(yq{!H{UM_Ts7R_1^UT4x1Q~oFYW+-K;gA z0D<2zfdR@xsuo@@Nu8p$s%8eoQh!JMH!3?uFl7CU6^>j4+!$UP`l`u)_&#e^nfqOS zH)?pfm~9V?TaF_*PHYO>NsV=ukIS_%9rD-?fk z67Fo%f|CT#{+bV3huYGc$nucejhU(AneN?P9|JCz@&vzs2sGn;a1QVf>=!NJ z(rYUW?{f=y{fuUoVf8iB_21Ix?-UETJ=Ow@*u=JZ(5s=X#dDoi^L1PquI!P@)T;qp z>4jwv!?S4uadLe^VN6cP^)yFY>Zh6F$bPHhLp_`Ol992)|=H@$NShf)Sz5 zm{Hlarg&*V6_|Kf*!^b^s)HHI{d`#l>#Vsgng#xSncA^a`@Z0**KndW%lQRGl0xiQ zr!MH7YXp`WgX3YTJxRmfpH7vuqS^MvXUn?kV)jmMkuW7uZKxqB&N!B4)sLteDH1r# zGe+w=PX%w31Cx8scsKHb(a9!2g`w9;J%!)^h7{!g5}r;=%!+DkttF~e{g)lBPO2RP zb&_wT_g6hn11M8w>9l=d+&Ve-N+-$@rOMEYCf=6yP%5yxw3;I|`aJ~8{+iA2V1o)> z?f4;4VwG$;`|;>)6X7}DE25VC&o|jD`#!!cQ4`@UbttZYn?qj7GZy56v$ex|LvwE% zV;66Wzda*+_Wn_JZ?gnvTzIYN{I6~FAa=oM>ibQMtwyb=S&V4>%IytLt=}8i={;QA z2!(I)jURJe_?HiXi1wS8x1&Nk77j$h8Cs+8X zUz~uDvW^|UkIG1d@Txt`t@Rc*a1Cj!>vrCi&isNp;|p=tOiSms_$5=$_{+^;u9d@m zOk}+Nx*%izq`!5bB`#$`)i+U2=5)cfgN~Y!xM=^BwJhMK9DiA7u=;Zif{c*}tPbpg zchG0lo3kIt-g>tYdG~rci;bN~A#;ZJaZYihwHfjZ)BC_%()%0QQJ&m+QJryD2cy4*yxUXa*Js&=lBfne`>kk^)wzhr2hOY9 zC1UO?C$Zcz3knSHJ;xb;4LkB`jFQ)JqArYINbjIHklzkw=3I8ikJ3aFv&F7&MM0BA z*FGZYo~sNd(oSuZ6AfvA#&QylT99?7Uo>eCZjq;F@pyT>&946uM$^MH#oLC?Ksw;D zH`VIf>HX`OX=rWXiGW*gaE;E|)!d}r!Z@*zW^XeNtIH7Oc%zK>d1E8#XhoctFvH}~ z?GUL@Th;ZX8JQ?tm*1)*ed7w`gA|bgs@uP=%FQhccb(v6QrcB_aVq{Yjdyoo=h48ub2{2^ zvh3NPuB}t4Q*peT18Tj&)6W*Y*8ET%-7!DQ8=@r}nloAq-7pRm7lT)i>~14{6Aw-u z%7xq>dB1}AN?ZjPN~4N-OKIy$h1}RKu8U%^3*)@{Njb^vO>=gK#w{n$or|n)f`gKO z&G7Hb&7sYfO}SW$wtYav;aRddG&ZJvz_>4*Tt?xFm3z8rV%(jf&T9@eGjQnGTCeH( z%2H9<=!O{?8cJFSjpocILq0~D9kC;yipwZ4IMuCv^xRs2bqNmFOiw%!XP6$kKut&b z#5%3CkkD6@)z=#x*oYsHAZ4ow^l@j^dOA88ac(tWvTs!N5-S2;ac(8viK8X+2c1d+ z-$zL@{`~@^j5_H2<<8H%p+M&#)1DsI48xZy6cZ{UW7A1?6{f%wTjYf3+?Gv8ZM)0# zvdXTwmUqmg4c!yxB;b|rru%wC zzSVziM&($&@vIG>uRlRHiu~7o(Q^0iThNj7n@Ya_x}WZ3nI;wP(W!d$-wnInD2HdG z*ZUM@=;Z+Vny%#h@|Ef|DyFs9B*+1VA&DbNa-Dm9q763< z%%5}TM+;nRcUSK;z@o#5#v{e;jt@_P#sw%UE_x$h9i}2z49sw7CAjslO8O*tCXy?z zxGw&NE5nB&eg{v#wz#>0y&pB@G`rnP$1M#0wNc7OCPJ0Sc!qU`ZQs1se7BO&X$Mvv zHM~=#5ZVLJ#g}GumE_*%4PQP7Ero5c%O2^@I?FRn>oj9p_F|8dJm3Dg`qL(^WgQyW z9BA0v{0yy%q6Kuae`13vjwK%IJO9fvFvwxYsip85@}-Q37dm6IYQ7WJBaU<$Zi@>~ zYvYw^)5^L04`&aA{x=3lbc@i3$1e0P_b*=U-4 zaG_Yq@x#v4ea#PPgF3hk-h@W8kvRp(&$~8}Hc*P+SF-v~%@p?o3E+~*r)=4*WCCR6 z?_T>248ie&B&NVf|0Lf(%>U6tiU*Se>kO0nf-Wv0C{2Y@2Zxl6@zX8V!IJ|=q(a#L zWUR($iS^|hU^!@8J+idx-@)(=^5y%Z7wC*3&;1r%0R*nmSUSS%IA7OvM(iuyx(t7F z`~zF$D>v!`W@NeEf5RCI;Gc7NbFOE??c{V!3Q#rpZ6(rIfN5Qm{zq28T_nKny@OM68%Kyggv9tV4AOHOMWLU3dX@sLn7qjj+>k>9 zsB#xxouxgYA&4ga64hFA1%rt5{5L09moz*(@G9sTGRENFx!9(QGUyZe<|0Dh^%?zhDjWfKNdGUfx0SSQ%|0k-jDaC`>0jY15^*HAT?CSS%EocyW6zT2<3w zcdO%%u~>K**`4MCeq)+_RM?k%x3_3+7Rg;(zK9>?CG_}QC}4XjZTyrXh0qrdQUfi~ z61(DY0lO&X6QS|1apXd8lW3tpmZ!symooGxDkDJUgBIr^)rCA;okg6OtU>!HFN}{k zH8NgA3yHN15r+Ozb~~bA>wDa(&l1v%us9r9acbH;Oxl)AUd-vvU-3=> zetU~DNPsc|la$cl`h!ZHK<4NHB&R&*hqcAZ5`Bgbsf*ab3(ZlF(b>l8m^3kd(27G~ zUgL#f$U)ij3fN^gTelbaN@Tw9jY7X0WyXhJPJ^~S{DN8JODpzxBs2_i;tXJhgw=9D zV|3Uqqa4AgtTqX|`4*RU$9f70D1V@Y zz5N+)7levAI!gJ&>GaQFrNpY873OZ+&dJ2`$?|g?f&1WD)iZRVA#Va5g0?6HJDEXP z7&+G$52hq=rKu9c*~{$pX%>^&1|BhJwIp0#milh}gqOAIzK_5D`@PX^pR29O>NbQx z48w*$Mcg&n)olZY@rp)Z@ri{mIdco@Z=;(t4`cH|)`(_+rdm8_5b9nx=EL-~a&>z< z7(oW!HQnM+UjkmZ$M#lW7p9$aMcLd^!&5gCT&C`$pc1jK)$C^~me*VY!eIwFxf=r) zju(^RK%>@5j{YR~tFvOqdh8iYC^ivvGYd`Ndv~+o2&ya}q>oEO>gBTdN?Kn(zHu{G zcst?Z@peKWj%^Mb(p0|{%{+T`Npff#Xo2ti{)fkdFI^U{CjIiUEr;D3@(hdgu4lG| zyQBx>>CPsYvoE9fn>LO|yl`HQmzS}ITnKjWV+Gr*? znBycg?r!~-vFSn^Qy@9#L9xp>7v94rP1$JEZS5WcYBL2K<7CXV;$NN<=YsLZLY5cx z2_-11+p`;&RJms)IYacG2|BNY4QFODWe^><9Dn6kG%;|swk>=;@udDXbkCR8(clcB z3KWi+mD3{P^7Pd(7$kOUg19Ya37GOWw*aoR>>V^5w%i2T{HiF&<>+GbW;|eI4mk=e zQ64eus|p~ycy*M`AtJJmvz{qn*`3DQI$>FuS?7zhgHgKRa=RV#*_FByl@y> zCkV{D*X0YPB!Br0^r?_y2{rvpEWRwX5~r*CdQteZV5j+)J&a>WO5@Y3Irov0BThAa z90#-+{^XqXGz5s`AOkrdu^%rp#LVzQ*%lg)5Gy6)l03UA6S6LChPH<+fZF?rG@e@3 zKk#LWbXC#Y7Xe&aauB`0j5qSs@m^X-^MPlx1=}m^>)hl$PP7-S05-SsUU-%_i4p zjM$c=)C&(eQ4dYid%4_CJmam?zhci}?DK*$p`SIH#mQXHjEOb(vGm#BPdocZj4Pp> zKJPHU@ij4=Z|r(bF6l3l@p=u&tVHvJ+BwI|4XV$=4qSJlsnr2Lcg-&7U;0>`mOSNV zoLXocGXzx5+&%J1LV%zf8HaQ+4U2C+%~-kU`|+89Ft*JZwZFxlU@ z{muf#-&_1F_s+CZqeYs6jzC4_v8KG<#^o~YF^Xs=c z0U?5=e!XiQc% z3cvqd>OR+$jP08OD#xd#lAd0M<{OCSe=Xp|IUk>^tu2`#p@W!^lkxrUEWpHKL4lNN zJ|Y0aJ}}egwppI{q9s-Hw7nH=dYc|~?*=&ti;&HwW zXRMv)&LIcXig9~3d-+1P$T9c5rpFErvWw6^|WIGYhPCn=!Wx;zKQ%& z)J#_Bmz{L>DVTD%v>?G%cP|X{6!Z3Vnv}rNA= zryFWNMTHkA>pzGL0qb_bEi8;O;HBXBF6M3}2}xAl<%xP_rG!c(+gWnkFD5qT&MxZ1 zbOZHG8tYN#s!LC9ssy|=o48@-BA5-{;)g|*X~HM=v`Q55J71z*-uEu&2!D78^)TbHAv>ezi4N}uR#KObAO2*v@u!~}zst|Mg71fs)mYXJz zgeZ0NLFJ3S&ZkhSu*)?(2ElYPMApVzB&xOdaLX}oi5l=A1wDj1dVXZ!-qYOM&tCqQ z--O?Vhk(fvW5baPB$%%qBa86*QD{|JIX9 zZS}LW|C5KfQaDqxECy`C34(zKO}6&9HRnwaEquS%tD-kIMgxHCbL+~kVlsz=@~l6; zfsuM!)va*IY5zA!g(5@I2K9-aJ%m~PHO6N`9uU}vW5 z<+)+(I68#brY~d3#$P5)cfVGS*e4AMj+hDxsg$WS^me|VVw@&*vO}ml`6H^ll=@&6 zaiePM!z0K*wTK_Ty3&=Z-Q<_J=kFlt!g}yX;J*IrsSkCwrYzamp3f4tX-C%6h?qT{~a=7H~p_higI+zclaq-ow;P9_)y6>Tm)3xYqVpWpn4+y4BgQd)C`J0OSh zO=@Opyw6bT2`f>4ntWAAeF#qsvw$f4_wr7WC71DAFO@ACY1+k6StF47^T!V<9WunU z43|E``FkZqWK>}opNaa8Tk5|AEO@b#3C(1Un_JxQg|gi^5HBqwHLXTo2|ZBdrwDf! z9+ZDOaV{MpLwW!q<{|D>5F{c>U^7Ita2ZY}7e=6K@S|5inZ=_5a6OwPu|w=Gk7&cg zW$<{2D<84){j%1)d9G9H3BwWo!Vk{dbEP~WF|%3J zT1;R4`L1wG%}!D{>X2~p9rD7F2tJrUrL8%)Y^QO1=_w*VPM>1c7sRZd^w375v7}X= zh`cZxjD2+vq0kki9$>E6>Q;(gklv)27v!C)!+Z(x>}R)#VSpK&SW8nC5Bm13n4Pn$V=o4@L8rm%B$|A;+qRac(oOkG7jvf36n; ztM4@ptO9H$%r>lB#>~y`9oeOU3K*;PR2%jR)>3-cRI*XaiIt~I+w^8~H;50n4x6be z11`5%asM{n%9YQpQ0h;D2zpVuB?XjBMB~)#GLkyaZ}G3NG25#{AkG8&AjG+Bk?$Br!izK@x&DR;%~%nWMl?CnrayUxdt6#!g$ zt9~B9ojeU7Ow{4je$GX(NpN(!IIuC0vkFx`9f28dR{3bNMAL`?&od z46hJSfI)`HZrv}+sa8Z&SR`C2kUZ$Q;K9Z{Ct|_$3159r{*x1fP}Mj4;t?%J2M%WZ zK*d!L{uyp8tKG%5Ep?T^-|j{URH<~3Ijb_3EJtWb_-vb3y48nP4+JtSUf%6SQlS*+AsrfZm}dar0Z9O;4;6ipws1WhE@9H+#u{g!BzRcUVMy4WTIh} zM}2xMrXxhPMM7KK*OyV6?lt;%HM0)2 zqG2vIyK_ZKZ@oY$fvf0>d! zTCkTe(~s(LL6-N=_4ha*(0Ny0>Y2TcvMGH17tfAEgf7+U`Xl^3a-q*8>>OWEl1|?D z5y|1+x`8RI0^xxM(hm)!QoaX?3~7i?-1(J1qe)VJ0u4V?HyL&h26x2uv(EGWSrNT{!R zAnVdSzkgE|F&)ND;DC3yk^h=Cpr1?{VYHc+S0)hZYjtwNWgJmF+Ih)LUzV3OE~>`y zii&_N94?=qcVS*$5l|qeir#7PNe8A!yG3*QQeHAOI)Pw`%?v`kR6SLy3VXeYU^@YK zsGWRwM;t469+)E)a!wyPn{Ic;wW{I8LmlY-s$q#DJW|=cT#UibOTIEfqf4d62%WIvB7FWZQ}5CG}&YqS5_W zRG9lXx=EzmdkTJjx|>aTCT2DTmo+uzOL~~yFBG8X(5b~#0@RC9C(o|gv9Y&{Cgh7m2H@Cao2Mi8D# z=rQ^ArK&2IK`wybXj;cWKCj>p|CebG=at`KxoAD6B-?xM8s_*~Yv#NWWRfZOj;WKH zxgeWwF!h5{{x(p%F|i%0*$&z^oq07QUX0<~Cnw1U&ta?Zyq3x4YpUuFoksUN1NhRx zBKt|!ph!%+pp_sj=6PyMq+k1DP5ao%Q|3P1PH=f|{A&0>2GSybJC4l*k)fJIxm3Rz z8>0^6Q%{z@WT_?T4^m)`JnI7Qad)|px$zlHuhasV+NQ4wxD{dBI(Ee3`+^|U?St@H zt#Mygw{6q!z)_q_$?((?6tH?=ax71MXd%hdp0gTj+z-v>=x$bVD`;*0NC9+GlnrcO zZOP&vzI|!^Fx|7^bGr129dHtu9Po%WynOF~?R#@YKW&0?)__%wiiO%&FUbbw#D$e7 ze{>x2H&ult4&zvlik-ORqjhYvGca1`2qbZy2A*1uE8pef{dl?$`m`Q1bhOyU>NK$x z#a0Vx+bN-0U>S{~TKqFnRv^vPm`<&oq}L=3=<~$b)7maw$ZR>^vRYV;BkZgjq?^3h zt1>ZKIHn=P#O@md8jccd0b`r8QXlx{_XE3U6&COP#RmzgKuG4TAjq>yx9P9XjXTKi z`+phC^6}2!2Fyci!7`=DQEsqPwWo(oEheN|RUj>z9n(KC1mTgdLN%e6`P5JCE#U}$ ziv)ZbyuztEC}F(o0#!!nrURMUJsDu`XwzEy4Q|iDOmc_#0}JE>M3cv?uIbK_3XqbI z_J|J{-53!oJFaBQFM?Q9O@Ax9pg6E=zEs>M%8 zg_3<<=9DjO-@nCaXYGWT5+B|QN1cgLg-frZ+<{8$)&jB6*goL5_BG_{CNbPpJHL#J zXgs3VZTSh(-g*MK;KEUpI%k#5NsMsCW%Cdha3$++I&<>}9bI=Tc7zpL$yewi{iqPY zMH6zMd{Jlm_EUKH7kU%68v>xdZg+ODvQ0$#8aOXptPz%4tR?txi%)_tK9ezmpVCJ2 z$|9dTK2H~TSi1PtM5REx0Lxh@+dP$JL&aA%uO~q6^6!CrdN)iaon(TMGj6sFD*2Vh z`-)1Cz}_=1V_lupI~F!#EGy?5Xb%^;KLs>hmmNPugw3d|wG6BBo( zx{d4qWx;nZQDp+y1kF>QN-cspBRy=Vuj`2-d_nDkpe&NkY|eLjVuQEHjzqo+yU_{G z&7068d^J2z(oSbez2q%=Yt9p}giyYnV9wHK+Xu1u1mQhkQl3HBYAeVB%^INSN-U&9 zfoST+0ikH*TAK9T;QJ}A8bt^Zodh}K4nx)@2@n}(Iaim3l-pKznY*!;j7`ep6D6Cm zeUnENPBEQ0f|X1Jn;$LAe`60cK#cQM0cA~70yNOcao0bJD=(hIu@TuzN?NA4KNNc2 z{GgASo-YE}6A{fVxaUe4;>xVWXelb`_|`DGmV^kKhl!x=@nF+xlZqZN=}}W^>tbi| zi|rW?ak0eb*2$v}RhzAuy(L13RI2$Kn-C{267?%LV$XSBa4*VWyqIM zuP*pUEy{iKp;4vGY+yIL=xAr)O$F^Mug#zAh*()kD)5Wd%P$;yx=rQ&{lE#zJQ!;j zJqw-sDyuC%c9Fdi3CS651E=+@_CFB3JNJV=_U4zEnYtxnJ9j+7Y((551Yf8E`KKhN z1#I!}#9uxJjxyBlpI^2Ebs%gNWuJS3476B13gTbjH~>W|irl^b*Mq{6Z$vQDD5Z_* zlVN6^xo@Xcej|Cu`H13W&W197zx@8V(E<^;XQrg5RZ_vC}<3>y|#Tz=CVL(QeR=e?H53LenvR@&+U5Mr3E<;Tfpkk zTTPfRr*2_aj0X3pNY(?n&CvC@T!v*lM%%qmw6*6sjvk(bZOpBmU&?7s9CX!`n>zxZ zObL85B?w@%zw_bZ59CC6e0V_hGjV?kf%2|x#>8RU$pJrW>}==5rZVX6y$k{#oV36M zQMbXm8kiGdG}cz2VgFS*R#?q5XDD*NqlIs_n*Z;>aJf+N&DA$)mLhuyTbX@?t#L;a zkpE_eDt}&3v8SCM4%ze!QUxReUJAjgA!#gwb!cFFAUZ1;Qb@}hh2VND!tZhwqb-4Q zOR2j-eAArH+QyMB>d1%9f1CXd8eP~xr~8W zs-;<_tzihLR_bO^~;-O9Fj$?12}(YYgIv3e*+tRynnxSFG)$6ho; z?09lXiqwGJ^h!Jq80mhxfnAR=?15xxqM? zAczv%tlqCG89}dU@>Xr2M2Q&RE|G_gCaae-nxqJ~N|Ou*kTGizv9R9K(wNeQuv<^~58l0r)W@&iwpFwSn#OxI!Cp%9uS?U@wJlv$iio^4bdnu8 z>O6QI5iqoPFG5Bmp%UPt@3S)djJRx~%Kez=6hkPZdUU zB?NEorRt?7x=w282=FVh-&bU?kS5ERUp}7+^neTU#@sM_SDy2k30%l2nDS4!_?B!t zIl+F#%%7D~Ud1qzv1?jb3e3zOmdP7$47{-#1rk>CSPtZe-lHW-|So@jN1vyb);w}Ybax<$Lsnbt{3V4Q*dz8vr`zZFRy)$6BVicTsgja6DBvAOUn7qb)Zs*9w#25Kt*Wi+R8G~W9o4DFC0{v& zwAm35rBGeFC4?DT+^GmU+`e8|kBtAB`eW^AX zCxnRYh;W~J!jZ4!x?pOmMD|tIrm(u^(8iHLI(d2ps%iR$@qs4Uf@SShb*I7T%=s9dviEOaZcYsHBNefQ~ z1K#=)UjMk*uGVXU6%h$}j4lmMkdadf&mhPqzn<6fI;|bX8b0;MKOE*IGN?XsZ(CpS zbb?7|LkiFSz!!oPI&p>wb^{)7Tb-OJrKeTwZt#qhya+AM4h{X}*zv^?^i(|rPqydV z^|<%XZ6~>tE#qH+NYR3sL;k&@{rOc1XI`n-nf@H6neIuj0yg97Sng??#v~WZ1lLLeq zE8u0F+j^wzds`2e2S4%|IqnS2kF~P;$l+Q}J1efum>YM|KR533>X2JYseHExdL2V} zGkRn1XX0I6+qQov+;-QeRNN=p(%Vl&Mp#c6aHcfIpyHb^{UZC<+d!YB^WtFS&!)ng zKkTz-_JI>38auZw>(&?GZk-CSnTWzK74xkrHAV2}aQ9^q)(I=!qm#&zIT^yq{KS=g zHWP-8N?nF#FeI3we}ji<{xSVB=^v>6kKFU~v8?8Yj|?_XiDbRJ`p!a#yWNd;L;F8o z{t9>v?E`@0e(kD$yUmvn&|`Jv1=-x%&jaA&Os+=7q7k)jog^dko9esRHRcGYX7zdd z=MN-}l!yW^h+#%BQKo@60%nc5!-yzox-r4w7wmz|EDOGEw-T{ zjXCSrjr?-ae&HXOMu#%ocackX$NKi^^2GQwzXux__FOrN1$6!e_&LEgqWcb z(T;+og5NtgY0N!C$Jw69sKS{CUM(@W)e8TX>{voD{OMBVcxJM9> z)xT=vvzexv5c57-5CGjrfIqXsJ@vYfFEgMk|EO@vxvSa0+v!XH_;r^RQi0#_W;bsI zY}xdp-)TL{!0mHS9iO9zwcP9veYQPWhi#~*{f3V}wyBcgiee}I7ftLoi>{_b?*2Mt z%RDkqnH$u~g(xtq?f~_Ny8QH%y<`?>P17`A% z0$fsCZl27cHL+_!+j{((FH=T6l=%-OtJC78+eDpm@FtdjozJJ@3|@x9dn4S8FQ3H< z7O1LW4Ow&*2p8OB;o)M;aME{zN96Mg_g2}&S&nCe)v}K*5Uyx|66gZv!c*oSl~%Oy zZW8+$e3{NmE68uN_E}3;wh`=335jOe%b5MB<0ZX-c}`s7$wy;(DbBfc%hcxnS~yVc z)^8D0r**;mQr7kP@xyAjpU?2nsH;_&Wu~G(Cn|>qYH4v=R9h6+VlkIb$N^LC29LbvGxmG3StP-p z*#Wk^tV|LSf>xcDuB2|aA2F)7s9vA~6_-B;_-oFl+C~d*f78+u^(N!j_H*Kr@J8j0 zpm8gJP6{8HaOmh(o33sS2eL{Mz{tDk`Oxy&$7kgno~=g-cDo0@*Tx>k8dlsEM_3`- zUK}1mn21j>X^L+r=m|cf1-U3qnKH~Us?H}8ri%0@fv7DWRF-e$Qf8rgU|A7B|{1R?~u;_Txxb++5GKmbI@i6{%^e!=dKhs^=fSd7oy(J z2XcSV%kqtdN3DtC1z=ExiEFsehO^6mQU3A&>A(76+YT(yeJovPT>x|}Z0UA$!_1DS z_>ZN+$)iQkH#P@CQ5#*S*N8(jTGdXv1GBx2YW}z`dBtjo#%HWA9d`3UzB>JT*Xa2980H6q5I%jh&akCoc;fn}E(&>TlAwa=2J1seGD z)9kkQrI~<5CtbNreTus%S`GYF76pQt?CG>yquDq+i~sy>C{#Ih;QO|bQ@QJr;0_F&sf&n;3k^N+y^fywct=78MXMX!=*8^+~1)TT0whPDf2 z?-*_~G5{?`8bwb0MZF3ke6!tgST^+fDKa@66*#B_phQj#m_4-* ziree@&j;f6IJnuO@uKvbJt7(23-W-gpYb7LjAPUsfZ331(y3Nk_U5w?Z0ZTx0(0<{Ihr^If``5wd$7tiIeqA{? z0F8hr)MqLRb-;}W22^D<07ulFa)JbbFy!BQ^VCl7rW!N$fGr0U%{}?_XF6^d;{|CH z$i57<5zZ3L()#?A8eOAw*OWz5W#fnKdUq)vzqU5>gI20>ow*cuN=voaBez9b*}k_i z7x%!J!k(%u=;_xVQ=~uRWnk5aiFp%y|C|nlg`)feec|rodTFJ}PLK8gn;PS(wrUcM zYPV6}#)^G~HhF;fwCTC{u~yRL-faZM6JQE8dN*C!A+MNV@Q~S;R2NFQbQQg+Or(_n zWdZ!64Rp9NW#Cpw)oZoEn!IWtu+&Uo8uwc{SoERoU3#stb`V$pEG+|QJfPTHkm{A} z+W6DIZFH4MCqvEA$sgf5;3NLDt(7P>7zvqlPJUv?8K$iCr2AN31Wu;!mZ=s<7Q`D_ zh=*3G@sJhr?4O;N{XXe=dj+@4n(;$cz$gy*SL()M2O}a%C4UEtpD~>jp?X*(bvc#ld-fsg86lnfZhQ>PNU*DtT+wX`4JkiPW$OEGNavlpCand-^a*3sBaMGHD5 zFeeWEC5AS#sYjA{JM+J8@UYyPp8_5fOs+cNu=JZXXa&@bogU7P9sU}+RF#)YjaDdU z%B$Aqys~@4dGet9@dsDIAC96d?sd z+e_tHDDZvcJ|G*8QPaBniwf*4Qr4R%BswV7X9)nooT}*$Xt-}bJ7N`JHHIM3hP^#F zyh^5X9`}!zQe3)1N8U!l5ZWgMmZeUK7}dyr&Bh~Y?@!4jijP5yX4v{%GSfEzj;#_X z@jxBju#_|I`|GhQ{VysT3M0L%rr3KN%X^gp2VQn=Q3*ppVo~5+HH1dB0C?%V;ZsA( z1#zWb6*``#kODwm{OrfOAGR`jr18QdfC=M9QU80>(@hA#j7tV?YqWwho!JgZ7Xulw z^f+h%i-_K2Thmr-=>8i5%2f3mBU0``PxcQeO1d3tk)>n0n|qvwcxs)w5QSc>M+78+^GqoF+_2~u!7UFN5&{YRMJ$K zM``?wSd68fSL(|rPs=dufN9%MrytFM&Io%w;ZXP-e9m0ig{-#mf}l_cP+MHJg*6^z z^IGgh1L5jU<*UQ+yrUG7ul?S81gL#@p?S^+BXsVOX=iVyXGUeFWM;U$ymkst>NNh! zE6u|9pza~D%zIdCL<77brJ=VWg#xEXGt!IOv})R0hGTDN0IQ94Z=J_r)Aj%G^wj}X zbYHYI2+}DC2uOEJOG|f2H%NDPw{&-R30xYH?hdI7QkU+IH+;YM-k-qSVdk72Ywxx8 zxw)Wk2hgJ7D8;auwP9R-0%>X}l@uCnofn#<*!Y|qP3c~-_~^C>Tm=82L{^_c+@4D1Y-d~@dg15GYh4<}PA$>wOmckHW`9RO zUzvJ0^>By@sfdC5DDgo(LVGn7xVO?fIACmT{d)~Z@ri?;jo>5N_{;?53k8>*Wr=BT zb-BnmJEU>5i4fiS!6DxjaSO&qCf=3w)0($-xc;nF56XDzD~tlv>+i_7pwX6OQJ+H{ z{<@YfeIFMFD%m;@Pl{}?n}GmZXx&l8-q^`@Z$r#R>?|oJkA6sJMoB#E9Qba&z5N@B zMm(*OuDHwFq8>M3+kbL6cih-L9QO|gVV`?!^{z#YFHU0P(?2FaSJ51tz#J`jd%0~f zO_QH99WuTSdsp2X!OH_iDc~Q;xCg|U5=QkgYeXS|9hT(%Nf?x%q0t!@$bAue`b6Fq z8)sucz-BKP!)%YYoqm*{ar2`C*$E5S9{g>Kb_?2}zM&ZD*81{#aJX-^%o_fvd&czr z`QJQouq9XzEDVM|dIl=TL@1%`ZkT+WU(gC>0AeNiwFSi3G(7b&9YjBo7yB3xdK%`B zgUUJmC#jiq**$y6lLn^kMK~HG9#dwbGl}t-;|dft^gn;&@Wt3Cz&x4}{ae2pD?@wb zXGfq6NOI|)!UXr}W;Xh#_Z0T6)dGtvn|kqI)JzRH?@9S&7clYFRAR}l$7fCt!~lr~ zE=Vx$A9Hy#>Zv)1;abtgUprW@_;VF*C*M2%Z#J4`ck00ELjJ*hfdj-T1}AbItrHso z-7v4@Cmp{;zTbWjUw!Ar;9%&%x5X*=Dy_4W^=^sz7T7sw)@0Q-Ge6uB@_f_kant+* z-#LxWpU%9%as!d;pF)~rI1m)&xVSlhoOEUA1;qoV{2HJUaOm%-ZoO*k89LqL=I<5G zXOs$!+M^NfrU$?Y<2F4@U#ryW7sA%8RA-$3ZUtB7LPa$D%!SBAb@EGfE4#TA%gs0= z=Fe^qPmfS|X@TGSr%?B2IpA6$PlzJW^2+iB=LUEnm9yQFz-wsxv{N(6S zz@G1n#X)J-I;$Ch3dS793mP3-1J;jhU2*6wSgA8xuZvIEtWC| zTz{4afXD^>+|hqmpNfouWoLHcI9I)(h-hc6rD8H+l441O5K2OCz%=w7TD{=h;hrZs z1CLblXi|Ct78jNflMbl=>hH*$!x4-Le?Y&k@FgEuCRBrdS=A?5-wN{5Fv{PybGvxd z*}!vn1_b%@+w-4sgOR~qV%X^?4U7&-m)-`@im0o>EUeIv^GD!!@Dk8&7^nO%P!26QkW2~a?oWE^U`lYX z2~ZwJLoNq)5E8qLX5U^bnw3~3hiH4|zFmjvH6pi0kQMR;czKj8G;g>Lm}rGBQ4pSH zbMb&j1cPt?%L>gN%NeJoY>9(QX8FLCPS@jhQ;-bCEEa5MBIbm|NL1W7YQUfCFG$hz zH9yMh&eKatvXP7BX0@RKe z>CT=jgSoS19lsjJR3qSzVjJ{kzJ>=DLhnx(knklu$=NIPq{;3W49QBj!mwDH&8xevJq$uPTF{g z5tG+10S|xBA!zv3WT(CF5)HLP!PDJF;gbEH9+&Am$=CA81Nuvw4pL+WRd-QUlBbE7w-1;)fhkLzkUBX7d-40mOo0KfxCowhg2-j|Lmiv z!N~{l26kofy49!za13>d@sQ_^#PaMb!x<0RTl?hUsC<&j+@t%iVEPEFgJMm! zFD0CRuzu|^J~{}mXclsvOx@&h_GYCto~Q(Ht9W>H3U)44DbYJ_UkLRHPgKzd{_*wk zsc&FO{J!VdPN`9lhjQeZ^y}>w*=!GdVF+K9gA00*JV?wJJSr{_f{TSk!bhOBs}s@? zyEM!{m}C?M$&NSW?L{7d^12RAaBufs%SPBS9fPoa@RmOAT-9}5G$&JlWUr;j9n~-p z9-a3&ujIU7-JmbS+u1gbDzKjmJG`fQOhvYa{JJ#^UEw{^&7bW*~K=I6>-%~ zLI|0x8|3M0@P_1&TF)LYhSi5N=w6U2uisahO&1qm9AETpxsbIL&L78p816#BFp6ih z_w=fF`IpLnL^#^J{JNj0pMHcyDGE@R)wUTHhpnT7Nk&dVlbl^k{w%gW1G?fq{f{O; zn4mgQH}{IHPKvv>e4qvt*53D8DajvKhm3*#sOP>%Q44dM`I!s-g3J$_^`7CN$U!^# zhc!-*idt>uK)TBJHcho$e)rum&h^3x-q#1SgJN>)OIfO?Skx_-kq z&TZ8QZf;&*=VIV1Vt*)YoY+`1zO~oDW>z^P0(i*7d=ih*CG9X4xu6_CVkNKzD1&e>`3cvnE1e$m8%*c4O8FN+I9XW)Oas zTHqrdovElF%X{JtC_#iSFxz}7$l68SFgNeZT?6Wemblg=(A|xATmDZ=&nB60ZkRS= z8pskx^GX$vg-HIr$9>Ku+Uh=>xj%f8y>>|2*i1kJ;8Ld?>G2qc&wx~`(s{v}Ql^!r zYsnCNw^P18YJzTOB3p7gKUHA-W?B643Azi3F*Ht2F<{EX$ef3P5^@^)wB#BgVz_e%%AttVZfx3+Y#lZhBRGg>uT9m<&0F;g*4N-t?(L^zSM&b%qRWk_cEz1k z8gXhRs_%mXiq#Iw2Mlzx+O}a8?K}zv(7{S9fuXDXBc;*ya^K-I5Sn4|U~aw0 z6Qf*k6_`k!SD7E~%R_L(W#>Rv$0|vP!gffH$GnXmk$zRg#-8a<;tk$%B0OWJ7mVWP zEDWly+Z+CyJ?Q?UhN8&eWA4%_hNy#!TMx)qKWuD{z~k)vX`Hv8WUXcg%;Y0~1sOSd z`=`4J=ti^7hGqx#^(;v-v`oM?o&*TljYBsUE}>pnU8}l>^Mv)o!G|zjSf@uX4ZU^) zAMJbQ8)Eefs%(x@2VxFy<4-lh55&F;qMR8NdH%_SMV!de)NX%jJi7xqP(*g=hx{On zuU6DWT4h$^xX)`p@pRmAnqZ_~VT>*yrEugppM;L994fXTPs9@ezhb(X<;Zo&pS2a& zF3n*^OFEPD?sV4qKKn)h33I?Xq^{-yu3FRw>aP|^dY7i|~t+jU%V-R!q`_RLcoe|#)=!pK*( z3ZA-jfm5eie={ZK`m>DBdhevffj4g$fAHrem^SQJG(;Ltw~!n^@8THXCwB8k zPRRM=zWrwIvhTY{Y;hVZQ@r;x%vbiO%tH?ik+$q|zDm_9g@!&GMHBSvjIp#RBLem= z@4M#8vtGSBF1g0Fo%QNpm1pvb!QhFtt{Mk4TZ_AHR(3O_Ix#iUkHEDY`cF*)=my}D z%$&0G*wtIk@{<#>X7Ov!0LwVRhkaaP9~-F4>~;w-%yoxd7%YNyO-@UDnc!&zPP1;a z^}V^_$(~TR>2#~4Qg)gB`pnC7Sj3Q~L7M0KA17&;dsp)PC$5=3D>IG8KRw1rL$s zO8Ji6Q}sawoESb#kyoWslI%b$vOvSttj+nQQf!q5LMsV>ok$|f8z&VjcA+fh%=*@S zi$$&5wcQ1R6jYU|df~`;c+MwxbLeh_Jnz3y87VmjQqE#4lTj$8qjtZ&e)+|rTc*9zE4EFk1|MIj zqa}#VrCOsT``s?bON3Nu;E_Y|5#Waumm?~j^B-0NqqCgPm3Hgl>x9B zl010sTxGSO()*hRC||Jo1teKvhdjHD#Mre2+h6PJ;ETKq<>cddT4-okrrjD}=`Uw0 z`;pa#hD}5cj!PicH@D$*R_^XBNb7Md?w zP`)g{N0TQ-G?m$K=Z`UYj=`a!?HQ-OHyhO1&J~{PR()0~Bv4@0QYcZi?L)-H#g^#D zT*Mhjqq5S~4@4)|(C=UdgU@HbFT5IC^W{}6gWr$1Phou$(GoOOFg&$YumXJZ*I;&X zt>n3xn-H~6f5}^S1lXTNTz1{IT~#qV9On#NHn~glJZ&Mw%>turqAljH*F6ah!(JSm zIyY5TI-YFg%-pz4j|!Oz*2VV7jMY9wOw#b(j&d*PnDDOZBr^UP)w2C8$ePl> zlyQCB4}#tT$dVUm`zi5GhtuP&hEHQj6sm=ZxSfhWE!}lS@5*0|c8f{vhCum4-P%51 zhhdbKRI}NQo z`MeHzb>X!%5s<{j-mNiNB$jBIdWHQco+S; z@)Wc6EcAPoq+VDEH8vYta%rMy{8}VjCmkDf(stPCmzpA2S@#NTm5tL`m6lz;CwWi9 z%kyj7MSa-fV)x}~Lj%5=ODdY_n!N(nYl;Q;fC3}05S{3?YSKSp;>ZRgE-9U%xw{X6 zzpSKC01!u|bdB%V&>W_+Jp70ctJN1>k=jO|0CXg(Jk?kmTYuhr375i$RFG0-4_?Uw zi1Vz8goW>xHvNe-z)oy}kLXU2#JuuAZVjuBv8lB`V?v)&q$v^XcsAe}Z^m1xc@S8( zpL5-muc@|yZCEi!v?k_3BCXM1Gcra=QQAj@&v zeuwUT#Hdgx5SAZV`cp+5_if>W@Q*#Hb>u_p?9&EL^g?gWi@SC!PfWJ^$ACiseqO~! zw+h!<$_4F5=%)8Hh)1dGY5)hzDE6ZSGHENDo;VDmzC(C_*HtDD)eId9^Q%gTmZh%H zm~?K+{w1rSAx!+bvh2m@(R4HofV)EWYiS?YOGGj> zEmuM4dw)uLN+lN;YU&*lD}13otBkGQZu_#mqMEcA`!X@DVr#8Gug?UungQTS0699h z?E@6-qmMK|%eH-~err}i$gk0O*{uMI3frs#ozTZFpa^ z5ZOcy1rU#NSN;g3sPu&p6+HsRO?sxa!1raoh8BdhJz6$Fx1cd`oD|^16GwgJ4JEc< z#n}I~<1kACAITGWYL_s`x8#93QU^z3-P|(m%3HFqP2#n*r&HKxehn($z9z`rpM5p> zfUg&#R_(IvvRZ{gIJ}Jy71SH@+u!AMfQfLyf!>~ePbc+aBa>TQoEhfiYUch_@;Z5T z!B5tpxNQL;1JQa~%J`b&@R=m!`H?&P0F(TJSP02>!)>9;1Lk4q?tB9`J~zVEyVM4{ zIDb80&|) ziwogu9F8y-jza|6QB*hJh^FNq3TG;hP*sa&Vg)NaLRsivXO)MxF~2a-s0z+4sOXgJ zez(x0P&L7{2yY-Lrs*x{aX@ub?^<`=rEM?Psgq)rW)uthIi&A@8R+8jANOkW?iN-4 zJof^9{wMp^F6{G%^n)4%7NkLDI78pcZ1u`P^ z?4LHNCdKI&YK7dZf|ASBD8=I$PV=y9Tr1bQl1ewVZ5?ndDy_*wdd4KZr*~O7uGJAP z-Nt8KA58K^Y>&nG@#FdnrmJib5cZC>Ut_`_7)?`lI%XB8`nXnIFA=4 zJ_0s{kq`6EY1F}KbR;yaqEbQsl;rslU+ZceiR;63ereQ@jD<6azeGdCmt}g98&}BF zf_sA|2c2{g%I}bVEIVi!qCMJ&1`8*G5>0etX@Tt)7_@*S)OOzqV)iI5e#T% zIFXF@B79FQ;`Zj4{tnp}{-1J6y5vL3Qwm}xm_y3(2A1^>`|M+FdG(@p;Xvw%QDMS| zKZ81h+L`S-%t$E_mKVMLLET?&=wU1K!%0qR5MVNM4E`~jrEF|kctY9>Jk=EIL`on$ zfG{m%Cl9uJGt8WG15(M0nFqdNu_@j9(}6+qyt&A!ZRq`H>9_sdl~Jp($+rx zNo?w0)`JkrznE{lax}k-<(~^VqHP_QGwecWZ!x?NI;b?5_D#dHnjGDV6VJY<*0ko8 zgCHnZxk7zbIyZ7~O39DByi{jjD#Csa+Z}qXa}kOcibkBA_Kdb-r=cCeb*yf37gJ+- zeEhP#kv`T;7`g&gi2K(&jta<0fVY~%4vx_>J_i8Dh?o1lQm)SwBLZiZu#<;WED9#b z>(_bI-}NFsKcYK~rublEnDm>IeJf_V4g%AtbwZ{a8tjG}Owl=c_H?AAcq&pOhO`)o zGnpc(LMDi*?dK^VSG}gs4+8vo<(BO%?@OVh0?4xCy*lUg8d$C#Zxg4DNfOuM6yCMr zyJK3krywfE;Dv-#cxl_V%Z}HJs75FT(naRwKt-a6&`3RZ1Kfn4P0U{LW%9(V_Ruzd z0nWK*^abq*8zx?aqV`oJHN~^EvY`X}Syly_I*qU?_O)}R(dQ`INz?+amH}s9DB-xT zJV=J0_P-j~cQBL{9K;{o4tMpt6Hlw(L!NMvMd9(pdPSx}3L2nFQ79czg32JQgpNdY z6q$e-iOmDe=U^ddKO=xeeg1|HmIK#1V-Lz*!FHPeg7Lz9?4qil>TI7kmyQW zby2*)%MSg8mV2c5i95jUk53Ts&`!ZkmJB!~PqB5y6H)&W4x;+V#rgKF8+{9iqNBJVBBdj)9yqn^vf2`SF$|E~oAk}yNXtVa7I7jCPB zs)o<2n$^HqmKG0?5auU;4atJJt7F)KG%*WJB3J4bQ?QReO7s59-Db|4teKfkrDrN~$%YGa z;q8GSLPFc5L zeC;UKh4^tL>v({b-P||3<|d@PuoL~ojYrA7?fpjnyCOK6z`Lml+6Qv1}k@=F-5)-&Qkl#E!YE%cBO*-PvTttg`_MPrk|#mPfCh-t7_AhZ!Rxe z^1NM&+wq`flv2nqSoe1f^BW9fs7q>>Z~_A+W{tzM!cg#}dz2m8>cSa5?cmkBPm!DH zPVJjt2x;6gu&4%;RlFzDt8Ie&6y345xX^!MemO73`>FTwTlg+CX@nE0$G)VTp@ZPF z;GMi_*p!UYm>pOkjp@O`N!34!=pp~ zd%}7ij0U6GTvy<%#r%W)ns19_rt^FcEQ#B_2va?pL&eyLhzoU@V7Adp))AaUJ``Wun1~8R2 z{KjLv?IN_I6p+Az1V0 z!2UChIKuw6+4O2CmWWm~l=;cnH!G@kZTtH%e3#q;3>gew_m)7-oxI+|(=B;$5f{YV zK@DzE+hL5~N5x!6o9pcFlACO4<^W^{X)ga`X&+&7azY$A&T?p45D0Z_t!RmiJ+bM{ zGW6(~%o@G`972wB%EZjyzbTd2)1yIc6*}B~T9q-hR#sd$PisY__Sp8wXPn^M;Q>~n zi0Xj!zS+#d*#!x1>K%!D$`c~OVR58q3)5MVm@AlbcOb^C%^wf|GOq&Pl{>?_Y&t&A zEdiyfN((1r;?#0M88Jcpd}gosTkk1_oP5`rFk<(ZP8lw4oJBj$3Ia6x&=XuUy|w|~ zKa4sh4=rF~MBZr7p(`%AqfXJZZO#yl+8UaPRe%jnGsVdQDuz7n`7S&r=@#d>vE6R9 z^6D6%zdBei@|_=F1&ZOSqAE|xjYM|bSR@qO!M`t9Krw9ckJc>5euwJCe}FasPN<<= zrbIxe?E&ERftDxRf7^}?9t7HVR{k;plo3>H0?V|0GB_PFIz!e@ZC8#vt%iE6E?r^| z0>Qt_+{2M0L!$x{fQiCA(+m8FAu&}q7%r~U> zSu-LkRQ$lEBnJ&eWwX0%eBAE&Zk1(m`vm4g<6jC)7KKew1s(-c59&LSkQO*S+;|O& zc@6RF>bfq+w&&9S;C0FE-!GBr#!g*CM+%4o!64D{?yH?5iu9aG(;qd^YZMHsH(4=c z(U8tAI2}|5xEE4;{RRhFboK<$k`J;yg*{oFudWNwNy*upz&d9Vb|DJBH`LwP%_ePH z9_G}3z|4(Ny~Qv^7rQ+ZV`5lPdubn?ur&G~$)Z=Vc{VhRq_!-QjG0sV2ex*bo6_)~ zS$^BGYJm-Zyp5_0$B=~q#}I~M?(SA;5C7C{&!ghBM?6CJZ_K4#0-#o7VBcv3m58sV zd(poUs#YAe?`Z52znvf^x?-B&E6NR8P_YA=5)RqrX08ZN3K)FyB27 zaF<2bh+XegG4Poup--0cFb8+Nxj%DaPGk4Bjj(fnF{Hj=yB`$TFFi}E5ZvYQV7U8| zHu|5e?~wlKol2~7OtZ2x2%lBtJd}bL*%|bS0_Rz9NYjXqH(6`qE{0kn{L*xE?Vc9m29RyK&q6a1V|FhXcMI=b3y#gsj_T zK%@U?IQP$1!XenG#P{>_I$W=m!UJUzj{!$0?_o0hOO;5_Iq!08dVbac@~wxz&Uv2e z7V#FpB)k#gr+du($G>hsojRz7MGfLrSj%;=vp^ZLE+qiU=q65Yx=f)mg8e~`YrnAW z=bn^RKpg1}c;@1^AIawXB!)V;9kj`)8s-Jv8_hRSWC^E0+kd4Q`2(WbMAQL&tsL+M zpgYJ@Jlzxf`{mFN$%lHW;{>zm-eCH^wRDPbZp1bOciv&el2KGjCL>>zB?J(38JQkM zquuZhe~x2&+tiAF@UyB*OI?>y$FpNKB7H7fpu~rU0Y{0QR$-2|Y99xR^UuXfXPn|W zxbu6WE|c{;yS4Vut>RFr!_1WHLr4boJ(+YJQ5VfUE5cG|6hPIm_A~-Ks?SVoHUD|{ z)^9E3b||Mm31F7TF4Jg;rKdG3dvbP%U(tFuTq_fes!p0SNh9VPB6Gp+EjeQz8)1~@ zjb-&w6#`oWhkc&(SZ@`WLGS;H(U#r1`NU+9Bix}iY8PPH^P2F!Nh$p&5hUzHJN(ul z??tp(#cgui+$vUW{xtt6whk5yEgq1H^CE+@cFdC#PR@;ND5KVlH(ec2{Z%3)L<+H4 zcS_x1IYZx~?-9l>vh)<;V7;ISg8IX$v#oNOVD|D3`yxyd^HDrxME`SkKcGBZG>%Hw z<9gLqibaue9aiLH1^TE!6i0RaVh??ukrCxD1lt0G4zp0*e7=lKW7qW&xdY}20Yq~5 z<+lz|v8wCEOQc&n9Um;&kdB%ekAgYw?YrH-yfFfb_rIXaw;FT{!`J#|1yoJBRn3F1 zle>?X+*^gm+gt74S&v7eDfq*GVh#?84C13`1KKLaV*^!#c+bn*s z7}DV~X#E86|1xT5*lCq4iyqU3{qfrTYix2pxIj3ilv`iOr(UUSV2pnsen4N^#B&D_ zL`*yQ7#=d=T!-~;;@;MwD!*DRtWM43S$MnlWP3_w4^^j zQhTgK1Ct9MqYfgF5dpzcP=ExO*1(pA_l<1l<+uY>jzZG91qCa4ZK&=mL9ygH$Z@^c zZ>?~7Pue%ls;Uqi8v=+(!H@Wac-?gT+d$e0AjEhhb_1Ziu<^&_VbI7vLB-3$LjId7Ff_-lk>*u&+eKU-`-)TH%1^vN zqil4UIW?NKa%6}9^_^REg*T!h|4_S#vlY143dDY^{^s(XskrQbr1MHF6Pg-o5EFmF z6;=c+)Ym^Q=}+yCpLxnn3?z<~i%(#dttMt}ctCVU@|p+=zuzc=$+&Sye;WPtEOtFv z;AmB!zjgj5eA)xBG2yxMexRT0!>@B@S>j{-Aa*qq#3|yhuAlUX7CA}JQ|lBxq)T&V z31+=y(;A{kA>23u*h^yIzj=!H*+s@5j6JFU)BY_JM1N*#CYI7!T_ySkEfZd9E;#M& zkpSue&Yh|qL3D+>`OKu(tkZ1k`-Hkheje1*?Y~!d&CE^rw!ISWrJuZ|lCyDhpnZuf z&kzrsPCsW)ItMnae%(`UR9ZtngL|nQ5>k9NPsQOTJ2~>+3nKQ8oBU)erI_aIrybU2 zJ^n?tn|6dgzO**-LYkme;~m0toEAQZt0$MS?4+uojlb1*N4iMT1&y_zfGS4zG|8K_ zk%4>aR{BPN1zmE$`U~y|^TvProVX+r*l-5ali&qGpPCsmTLm^m82z34lEnt4m%P>1}Um9RTqIKwmW*{yGVg zF*!1QT6edgJ^ytR(g**$xQgaI6CkSP!-wrpwnaCc_j5wT#@AQr$=e-7#BxhPqta_} z#Gpq`TmP{v2(xY|&Uz!Kj$^Lf)f{6G%{qDyY!h9B+>&NTrdF%C)Sgy$ZcR=Vxe(j~ z=f*YWepL9A28D;9qw@aTcziVLFwhxsl6&DpW{x_T{NtPXl=BxQl@gF#HJ*Q~N=pZZ zT7;BO$lBO#BtQ7>$I$KHXu1>amTYg_;5Eu(IF0YFhd0T>s8 ze1;t8`ov%2bfMwE`x1%0C|H8FW8U=3o?Rx9=|F1tO%&4D%&s#@{a2oC!8e`3v^O(P zO>tp98Fj-b-+fg6rkeNclg<2rz)`koviTR|0Gwq~%^}*2d~r{D zf9A2JKf+(~O?MmDZa+aTxGe%0T%xgN?)8KBkw4FI!kpy3rWaJOsi6h5NoibwRQig; zrKT(g(Hd=av%uoV8w95!22hJrwV+M4Hb~;uDr8)Qx>Sp7);aYJSof+ZZL3kgW#DKC zCc@DL$w*6pF>%MX`HvE%mw#kZgKWA*T--ucl^vWwt%Sw&Ucx`6fS+mqUd*@K1$`<= zd=)G#5H7l-s%nQKo(phgSVD<@DOYpZZ%bv_4;0XEno~_IYxD~jH9>q&+tdGoT(j-z z7$E8f1e;jX4#K+g8*PtIC3csMoP!kyon=X(Z!=>Pz$499vCmrbk2q24CB9zoS`Lwo z^c(v0pIRG-c8L@(K5M1!NlOb}yP^r4I>C6sk3Pt0t(X;-Uv2wDU3sNHLWO|e`Z$5U#`5JPg|*weEQeXMR`AH{_<8Z21BiZ5Y< zesC{^may-_+{g6kw^ilAS{q+Y6DxAk7VZw1(|>TBQ36s=1}^)!1pWVJjaqsc zC9+0=nihEFgq?t*|`Tiyulc)K$~X90cSJ96N-P_(HKc$I02116QAzw6n!`7JC%IC5o%b zZ#|RVdSF6e?7vA7U}Oszc__IBpzf=KTVSLclLetW#Z|}TZJYe~H6Y7l%OknNiGR)G zk39q7hs5FGi@(;xl(J@5@oQ{lD3?ZB6w~Dj-^rBe#r78MCB&LVLjVE#+q@{CGX=78 z=L&vF>`f5($RH{{^%k;&H1OhgbHXne+vfXpcgUW*{A=e&Kp;Fk4n|p7mPjl8rzw$! zOldm3r>~e8a5&Ip%X9h5jEpp&%7!Stm4Mk;Yh{`dLnUdR5v9CuJV2{)#qpQiE_?0< zX|7yiNv2og^5@gNfAw*4X68bdIm1U|)ThrM1N56MjqtJSOO=l-ZGKUgtp&sc#3eTg zp%Yn|_Ys$1{FxZmpuWmH^%kX_XsN?yS*$|p?hiC@SJZ80OyzvYnAY3{LloEpuc`_$a3QTskhq5)#%@^?f(@Pk|bUdl50gww8AR_%$mYs(NG zNf#eM${HLT25I`H%#-EKYA)!_h%wwgi-f-r{j}Zn6<IaUWl*W$F_o+Uat+3E4lN;^qt=b-|rOybgc=ky49~PLI}R?G`7s^x#x!LC~3J9T>pM_2>TpN(C|5( zHnf|9X?cpYahKJ~V}he(^xxaIS7>SPn`tB7d{&HV8k8D$vdW3&t0FtzkK&r|@<90p z^$LCRr@||GQeaj6QetfSos#3zMVn}~B-FvDJSpvDTiYrRwi8e=MyJY^?QWO+m`Hu= z@29dQQxsNk#)RK8&9iC9+L+b(=@xKD;GKazDKL3HUX45Jz*dxru1@V-3>d9S0~qvi%`1OftraQp)}Y(mv56a}(V7flUW56s zUYJ=xQwM3x1$zF=6YhWO<5*-`LcrP)c?6G~!x6*TGDsYSL80eS7jR067P!yCQ2A%z z?+4&YG0O&N>c&C;hjOLqMT;^Y)|2pH4AwJxcEkhKUC%mLHoQ`dpda7O_=ME(hwd4I z_X~f3??FL;^N{hXX>qg0j~t24SM#1I1_M3~oIf4|{DqYT_~*cn3A@ydso#&{{BL_+ za649FN?%4+4{o<&Q8ve7= zmujTg&x~*;EM2XT3!bk2fEK=VEAB7N$ysptJP@3IUBBcfE{E-8d=`WJw8MXUhyb#+ zu@H;`=8+)OU#WLObt=hf<^PLBgy~f0DX1rP|&E3bcO4sRBHou2mz0QcgOKn~q4dn2%k0I`RNy=r#NN2;H*Gr#_tZ9V>@y zt5K4?xBZ6^UsBNTq!4puQf~q`O<-5a7}@)WR6bajQ}~rP=+RkM=@GbnG5S&`tugk1 zJL0QB%gJe7)=GU6E`}%!zK=^j4r|bFTC(hM)qIIjZlcn-3#$CS)ugSp~BevPs&A|v-KZgWTDix+;wT2#<13i ze{TR@F3id{2D z3H~5)B1XaIUsUWZ1!1?}z%pNvs@&q>T#xFkKTfrKeP)1b_&RwSFJF4g3EuH;U4(t^ zs!jf>09}itsrQcK*P{UJoU^7m`I&Y6))zDo(awxe6zyjuAY<0}A&z9|JZRVVlX>=3hdLuxea*;isiXcITwM{jX~~utZjA@E2FsUA9(xCfaj!b?IC2yrN_--cu@W{{+`d`A6^JzK|>r!r)-V6!&* zJyHBO{=L}3ZrXysN(-cG33_QChrC{gQ{`V}7^-j|+4xL67v6lS8{3`{J?S`=>gVi^WZ`-v4&ycGw_4k1kG7D5xBFwVu>3)5H@7u(Afu&sAfsJ& zSzgjGePhLOaa!{duZ$g9@hLF!hZVkFoMnk6O zueC;`3rR7AKWY=wKZaoVaKtvNr-Q$13!+<#zGSY$#11ws9Zm~i-FdxuEI!>tLcGCb zc`%C^_49~5XrP5WqqNyNb_4B&Ur+7Shv@NKEpfB|PYcjySjt;H$@#JkJDawiKdMee z5%3XlI=#4%TjIP#`9P%ls1gWpx}|LTr3W*t4q;ScN=cLJ>O_wP0AzHCDErMVc2b|< z7yl%ad&QexjyjK*!`U9j?bhx3A~4+c=tAculD|kk8UwZ9XhaR2gLD%rQj3doZ=-e7 zXR-3{wu!mGG?B=Eu}(Ef&7>QoC%YhoZFQ=c;VbK1#1N_9hU)m;ZXM!vW75;8xH0d! zxq2W@m8#Bw)Y~=qPQr=KR;RfZFtB=FwbX_>uce0J=$9m*5P-2~+>zhkZX&vzga`a} zN1$7>X2qyM;dY2gb7*66f6YhkJt>}@26*R$N|fM-%b$tsPC@FvaCN^I!fbY717-{Efh725$*GSvmb z=Z9_$D{A%?D1DX4Q!F?oR+w;S_e3sV;xe3agO8}cFBTTDhSMJ<>Wb6rOjQ&{XGs#F z85oKIoaTf4<0ak7T6~RCx_lH>3H7Y0sa6f1sN8IVB_qgZsY79B??cBUCjw65m-_>_ zML<=Nc&qh=;45v;(d3QSQF8`&+0YYGe@vclNU?Y&&4=p-Q>LnH26NlP(}BObze*44 zJ|b8n7!=r}WCXgEXEcS_Ha8j2`&T=xeSU?|ayAy{??yC*$OCCUS5qlSd6v-{rD~u7 z?v)#1&t7;8w1Rjt+Vj;!J@Hg^E;vEi4C{*8 z9ZH5YF~4%I_6auz_}Kr85ez0mY5F(y`8X~DogYDGYM9F#TnYMj3BS5j#ta@f?!dCB zuDo{E_ww}SD^6NN9aRy~YGJ3;;yw}?e8}>BJT6=;KdeF;tovlacRFf*T;Re%lqqzY z>`90_{#n^(uXD$9HqCX<2lG($x%^+1MwrS2J1_EH-dsG$$ueH)hJo;hJ_E@2<;!~u z0h#v#*XFfsXVhQ?RrpLuN?-lbzB{=S$JCC=Cy^xHL>caQ2?(tILMD z-tnbFziPs*=5TkF%muSR1^!iyX~}${Khb!K_EY_(%eMoQfo4B{-n`jsI~2Wsmw2M% z{Og6N@?Cdes0uYYHd7aSFrXDU%%-=IYFk=#L%1B#8^=RjAA4JoO z*~#j4KKBAzvuk(!NkQu zD%fS05i*G?sp$F}X_7CsQ;2`L{u5wef5YOAmhj$iuKB~oYA@3pV!IZ8Rj)<4Rhi>S z28q7Ol)(fQ2_P}$N6Ee0Z<=0la9!)0P1p|D6IVs#&F`4fT`hqzlQoL=DOY``L|9Jn z_n=+ms&{?2yiOk$ zZQi}bx!Jd}V6jmd-{-r=0&1&NiWoFd?Uv;45&{(=3&YBNsY4irm=XuvsGRY*rCuNO z0-K&yQ=g34ME-%gZqh~Auz>mn^I^i1%O(UY8VY@MHdJ`hLGTd%CvBH_oR>g;tRrQ(D!|Ds@WNifAKj-%B2UBdZsGrGRdZ~ zT&hHOTtHop{74bwCZ;4ox?zMZ?j$r|%c)e~j^rvud)?85m&7ZUYMxL+tGk~&yMErm zV<Qt({jY{GmXp5EUAuk=e|Ef0sYjp5uT!NsyM?7rKm$q`TF{ksq|_EX!uLn8ac zr(bInx+sJHEM&%TXEMHoG~Ir~gZZE{^W)Q1$>SV@PQvNuyz7TfoI8Xw<$&wUMfo;s0w>6O52?Jjv15+fU;Ud0cVhLfC;> zt+#ZcthwIP0;zZEy58EBau2p(k7P7xy9H>BF6i>h9)xB?#C_zw%%3n!f)Vb%zD?Bd1UFx;+c&%DUt+ADY*)gMZ38fc-W&Y+s-zRWc~2(to1De2>=<$ zOyl8Uz=(}ro6vtp^Rc+$BE21EpOaJp_FBZrR$@;#8K>1%OM7yA=AT>*l~z@xY!Z?m zYDbu|e(6>Lv4BEu;MVWmfs8E<=GcW_6SfPzcjujDSLKV)A&=?gA;{#Y$RD*Lg=zk=B1j78~3eeLtgZscFMr(x+x${5-;*_`Q1v z*$I;UC-g7851rGeImB@#<8jJ?OIO7up`f+_uU@~t+ANoEw|00U(FQ=;(C?L7g=Ilq z%m!7SbnyKB4)y@0BuF7J#lNd@Aq6euuB|P`jtIRr{kd?nucqOX-fWYbJgj??)0weh z&bub`rLGgIN#6Rb(_(9%ILok4RTKODaB{6FZ|ZpAc%Ne7wB#A*jJJ-+X0W=^_=5LL zC%|!Uv#rqW7u=$a-y%${O9`;6PS>-jKo~#hcSWI_Z!;9`ET7c6<>rd8U+Z@8x#m;H z{c?&}AgKCz!2R&!?1GlrsH)MSkzFOd;j%n?z$5wOV^n5{#(OWd#^x#G=N4x=r^?)_ zL+e0(GU@+A)LREs)kNLHbeFW!(%oIs4bt5u4Fb}oNOw0%cS_flZj`#jrKP*$62HUq zzVG+_5BJQOGqd;FYpt0*^_4Q_^S-`K{MiqIaB}83zp8(xOY+afe&3SDdD@oXRiq|j zb8FVSwV~7>in>n!QA6Vfp1*Kx9%==g{cJMA`c&PEPOvIyB3+_4aL6IV@v>Er7YBy< zkoUfPqjJ|0o8x#42D3_)Gu@7eQOd~taG)Mc$%L;RiOc5KG_IVx^q zC)HXFMqJsS5X7UCAGhgk1|8laUwMQm=8i+klQT!V(*%F)==2cnOxxP29sguGU1Bi! zp}E-Os=Sj7-|a*t%_x-692tnF{~D=hP6Su|tjwKmn`%0G;^FuPkC(#{OMcv>KPuzZzJC5tr{Q@_^gXwL$vGLwTC14esY{h(_+=pFfz-gS zhT^`3PwL#k*GO&k(f~0c`Q-USU+#gg;%kHR8g*DRL1a9ukr^u<>j7Kts8|(q!n7<)8!fM(E#X* z;0L7nNf$e1b~eS|66@!!qGT||fpgg{VWS-e%X`Y-MbkWo`VGSKt2!16COH#t1+yy9 zn?CQq=^A_yboE-$^P>+|&nZ};!Cae9^=!#%Ya%mryPA6B1}BWOAoGo46RrVmqerul z0+Ao%l517(T)Kr9nf$O^vvm{i-DWeof8AQc4dm~8k-d^nNO7|x?d5veHZjiR!^fyp zVZTU%HQkJpYkOl&iJ_tm@Yw0n2zw{p%}94J=?jYy*U4UFhPu_iX%YB)J?l?T-Z@hR znYyy#({IuJZo|CebXFd@Is8)GBx9vpO)9rB*m30e;bp>&)k@g8(o=k`1Zvr!AM!cd zRSGi)5%Sdm)4|QMz+~_tU|eV!yh^?%p!Rw()uE?r70-NSpd|HRjyMHlXm9O|l)ZI> zF4R0u?0>ymTX&M5N1#Y>Y6$zn`SKo;q2sP1G=+K6sZw`mg1BES9KxK&ThRE5OXmf*l|kFJ?6o*e4SArVD`Dm z3*aoCXLWltj~c$?NR3)R?n1wdC_j^a$N1$k(iG!4gdFq+d>nwA+oGHk zcS!!?L0=m`h>7=SmB_VGhz)jinEmi5BWB1m(M4@5ZXg>(aDUvQ12^P>E2j%x%HA^M zk!o;WP^~?5pPxkjGvT|^b3SYKmC0ijTRLF)ZHka8f7ClEcgu-nhHhH|+kLH)tx!9Q z3^ez-7oOOC7vgHM!nz*K1$*PP1k|7X38?^uM4!1>LTrsW@*3!9UXsAZT|cZ0Y~ZAI zR?1Skh!^A-?YH7ewNsR)`aQP}Iw;TddcDaWpg#p?46tO*4U-qvk$?C;O?b>^Ox}%* zhv_V?-Ho*8N~*mO_T1Cz+#7ycBmb`Lsh7u7DHqT(#aa5*ZGOoiwP7e3I)Z#`$`#uL zKCrS8TIg%KX6JVP{I!6Ssq=&33ywp<+JV*$GTl##;JGD-d2KXd_+nMZ{1x!%qpYsg zl%w;a_uIlXioj3;w15X#zF$D6yr6+lt=5x_gO}?mRex?Uo&Rb0sD&Gy+bqgbz zD*Thg>Mhrk@NB`yk4E5Iia(7mI+Y=PA!BaF*+j7UgPw_jc^pP_U*?Y6SY@bSb{g>9wYS{ix{hQjELy;Zk-NY5q3Mz8vH*3fVeIQ7|B zNpr&TDe^6)y4a;s;%;upp(H;n|NOiLdW*F6h6~!$3Q(fM&9DA(Yhy&`cdowLx7yME z;e;`C(^ype)otkkkftpO#G~F#8&8g=F-$2(i4az|92@yQxz{r-jJupWI7*`p@ad%$ zdK;Ouqq;YF)v`8z-f>nh>Zz?mHsr@Uv|kte2+lUTzCJXn^3|h*A@CG-7-;%&gRt7d zAq-SHD|647_{Mn(@8XAsi%lafp@60rvDq!VWoN_k z-hXcS-30O{O^0y`!d$~l?-a@KJV7_g5Bk*;eu`lfO+s`LV8&MiwUG1MOv*yud@ex) zi~7G|yTAJY+$O$OdJfWcHSW2cIz8;W571vQf4Ui>32`{~F%Mi0-v+ml^KadILyoRA z-FAndt)Yk6p!<7Iiejgd;gg%D(xDcWx$5>mRegQGoKZx}ruMar(JJSKPgU5CC!wSI z!u!LMupKv@x@qWDpLe@Pioq*8A7;bb%eL^BT+nw9BA~+a8~A)AJN7e(2LmmIN1n#y z;UN{a+KASXf3g?2yatm3(`iF-zBzs7SfV(bs&_?-5+~_RwnLeJ>*ts8ze&Jk4!vE) z1|Wjqf8_DCU72}_zLA7M2-y`q5id8BW9i`^?MN}Y=5`CG4c*gm;BsH5CnO2X8}LkB zWjpy0^@BHaad+{Z5+Dvce=K|X-j>z46=z*`nVf0M`Xy#$4lDf9BqB*mC-cc4zg(ry zsOhR1msW+Idt0wYu6{cDPDe@e;diSgZb6ENs10y;wA$CKP!cl}lsDm&5d{sdYE`0A zj99bMYKK-kUwS%E{s0P$WJKU6Cxwi?y2lw1R@EArQ3`R-dv}hrm#U`2fGu_*PTq_k z$(gr;_XnO+&{>)M<~sN)FqsjGy0khznQbJXS7i$0ZF399S+huwaI^szzx1)gP05kJ zTxl#)d^_&8t;V62P9IU8D#X1Tu0lC|SL7Xv^Bn-)CG|H;uJLE?df9M%4SDTDN;c#( zsh(WJZ8#QXOZcttz{NiBM&JwajrLmb0CD=BDig6S0e^@+SM2^OW)VBzoJ*HG@5ne` z3Ni@|AV2=%4T95oXFBG?-VcN3-ekA!hQmR3(HZW^<*r*`u|w`QL@O=fh2WB9G@%u( zSULP03S2QBN6*$DF=uT9lm=df-fKKXrPw+j26R3-eveCOAPU25`b`-+Q~VR(fl5mB z`6r#Y$xwX#4f%|opA+O9g=(G~AK;d(V6MUQs=Rc1~ zA$rNj)*&7k_4v6p!;i27=7SaN(|SN7`131S$Tfj@s_3{u$EuG@$`d1Ilhjiuk;U*I z0#5>+av{WgWM{50p3CXl0kU))L={v%^T0Z;6OMMgThV6zFpaA37}s~u%1bMoxnfI? z%b^!|&xVmX2oE5V0pexf?~n3;_~#&$DN246tGHO$8@ALlKo*Z9d8Loz{eb%7pl1U+ zm1X3s2%!T0e$S+IW&CN5;utxGYiX4~0(iNo>aA8IK+=<@pk?Cn`}WkNVMG_H%xR^J zB@1YHv|2{LEFnK5aPbfl?c~=ibVBiBv3iKS1c3kW9X!1v7_ee_*=fECLgpl=lIDCB zC|$Z56QY#6)K}T92t9xyKADRqNk38>y?LfN(F@(HXN@SZiTg8p&G-$BZXA4SP|PO9DT4=C`!ahDtV)tbBz8@$UX|Ni z6q4yC8?6ir37kPdUl!G&;5lRvLKToN`~3WFI*oPa^3AoOnJsF)B+X1SnE=liB> zLwAFSKGoT()mAps_C}3_w)cpq6zr$^O zyo*KN=#7e*3PGkydp{3>>>m#!wvEK{cEBUkk#&$(;aP*H0Et zEc7@!9wKezvVq6onP*qlt#k0VAjNxR+zu@;WYeZmL_{Gh^i5ypuW@{fevRfaw1pIA zSz4e>{+BIE6-sQLly-b z5bRa7kPHWbO}|Pr-OdhH+Fu z9i;F+b&>w0F7%W2JNq3!>2O%6@2EKMiFYV5gN6cuq(?=S|4vP!j`ojkbJl#s=Ss?O zxc~wFfFQ^@s`_S8b{jDlZu!wkVv{bsAHz}c1{z)+r5+ieJEN#K{O8)Ca~Pfd4q#$D zU`J<`AlDEF8Pt0{D(EiaZQ?98jHNpEDWKff>N*DqN z-1%Ob6^V=)A99jsJeMW!@oEA4oTykw=n&>|NbaC^2i0agnXs<7-r_N5fe zd4K7EKcrp^l2z0wB5##6F+2|^Y@Dm#A_j9^#HZmDxV-xYRnwV^l|B0Tk zGggiViUF>Vy?9`fN7=_-DAy=asUB*|Z^U2ehZ#NLMd=NMy3!DP^(duZKiL4|1u+aZ z9J|-KFWg-p<-mK{_KWtZ*F7G{l^hFvYekdS@XD2a$=qNXCydYO@69AcG&b3NO{5{_ zx7@n*1`ej@-V^aOdw5k!W@Yk~3N@`xA1`XM29D&7y`hqJ<3T*lGCIbj)77*a?VV7` zyxn?@3c-)$V7SHvuizjo3l?arh$P*h8>YH!y(tqM zF9wUdPnp7&k(@^)5@lUy6h#MLB82Iv%CNN6%uh)}r&JcK+81^=B(J7Oztf^;`SHz1sf zSoa+NjwBRA{_qH|!#K4po@3a>aN^z1@t^5o3R$dL z^g4B?jaO|55UsT)mmu*4P-+xv0&;1oI+2rv(7o7e0~@BPK!gwYP8@rGQKa1ah#7>Eiy9+_YE7(z%iH6scxQ*vv64EDmQ$@pahRVu(c z>nK>E{dG6DoG>;cS{%+J@?x>butQ19-Z_(JVb2&|rM4u9O5$jF==vCLs?MQf7{ms! zOay>M>}t?gAtWtruZPf6%z8u44FOo>>QXAk0L*uMA0%A$0Q=^YX)K<4TeO7Ya;=DI zf#rnw`(7{5@^S9b+RP23KH?2!!_A?MOl#^$v6_or#`z}z25@?mD}m_BbDA_Ei4o>D zfpybW3G z@XV{m0sb&qIQC3Ix!)Kwq=8ZQzej|B|MHpR*OquOf_7WprfQUQ&@fk;d(1?U}$r%v3Yaq_+qFL|&s-D1&tp-~x;I0uZItX}PJJunui&3ujb7l-i0@!icI4 zISx^S%O4hR9&BoWyj#Fe2SGf7n_u3rmA8?4lYkp8S=T4N#HR-$+LM{BNHA#;Mwjh7_`pmKjwFVS|q^ zsVcoWG!A56nNRnOf>XYMSeaJlIy^R?HmPSH<-lB&bY*`MZ`PMbq%(4-k-=0D^8Idn z@EoY(%kn*ksRwADcjea!4|j{S^RDRoF~k@0e;I%+kw+Po z?_7?y8(*J}@u(ZrJs9REuQWkrNn(DEK=glJ0HgPIYDRFEm-p7|xJgs>&XRT4_nuMU zZA10Wf14#B+fPc}%|WYdJ=NH*krVWn@yH>xRm%g$7{Ss$U#5l|=Ri~-?{$@`E|TpP zYaTB*!wC}3a0cMvTB+awS-%6fkNlZN6PZA?MgVph{bNUpb!DC7x2`gAKkZu=T#GZ0 zv~iZ1iDyNYHQw0$Y-B+?AmtQPT_k4;p{o&ZvzKgqP2Y_Bgzy)%+WK$%85G!>7E9$+ zO=w7=6q3G$>JD;@QJN17Y3@HhY1PT60Isu;xgQdD9Wer|%@;>`i48;scOCKV9c}dw zj31{Jb$~gI--}Wvh!Qt<8s(Yi8w8L#4fpaVZw-CF0DzrU1#Gr|UorYCy{HeJs^fer z{EZ-S1po4i~4g!m>yJ{~OAi zZ~yCA?msI{&djbOwf<=Oqkg9vh#9>~^SK2ddoJELsl5^)08*8%R87td(#-`mzclFe?QU0^rb(N_mgZwlbv zU$*tkJ4q5;K4h!`+K_md=7FZ^9OPN}AjJ88LSx2^v=znhzk#Eg$a)U9@J;j_XxNNm1hTLC{lBkbx5us?pKJiD@d4q%YY zZpfum7w^)O;za$+ZcNMl3Y#$c1%O1Ukn&ZnDF&Bl>C&G~AoUT6ziZ2cN11pj%798* z6G$%VI%4j+TR!pnWBLH+#1Bj`Lh#xm`bJb5^h)o=(rHc?8x^4O9<&1p)=jh+PaMb#ZrayT<2wsg~XqIEBVn2_u?bNpR9fiFPQ|A zF|K?Kv5Ic?5Vwd#YR9Us8Kt>gLdMIFka`r@KM)?v^88T~#2ZPb9SDmjjXIi;Qzj}v zB;5ZH<7vyP_>BfEUfE6nNt*6Y$)p*lYWOvM(bRQy%TO}K@$!a0!UHXWyj+vPJg~Z3 zzzDsqzuEc$m(WJG((E3CXhBbINOP9-rnwA$mn)HjjU9{&D+V`6H#D2C=CNoXJ@o%c z{2vxAb2wXG^STk3xlo*X2JAtH+zgwvmdEBw_OS27EXMTQnv2QxH(Yq%4gcW#i|9$b zR>MCmCI>%h4g#)VAwwB}&2Ox0>=i3?x>CN}+q0X-$wSgF0IZ1GY=JuBxY zrn(&J_Zf7dm9M5;AO!G_D3>5)b11q{ZAqh2N$+1KWnPL7cvV^ZK^zZ$ekEdI(O$5X zQd{eX9PDn!HGYc?$%g~ftDqj@Rzf`j+m8i5q=MhJqK2Np2S#KQ1e^iPh{yGIMa{4l zW4r=k-k(H+X%X|sp4J`w%yMItzwAPp6Cu2G>3M`eY8|D6y7_%!_H z00USiE$Xr@@6$C{nnuMcs{+}6-3Y#OSY_HQp3FDvv)f{IBE9NPJ=GNh_vzshQojXa0GLS7)!7WlBp5 z!Nk-Em-%gM@Djzf|T#9_p+{WYhX>!<+^ai-;rH6wWTkEd4`#?AP1gpQwr*#LdLi zdkTryx7{1%1)6MXtY?0i8iP?V0Um{Od`I9ZC!_epV!vv|zLU==bph-=k^dP+&&cmj zqVq1G3w`|M4LV9VZ%psJ+h@RW+Ve#mxcd#bg=wu}{dZx!m@1>E(leMBI+@KcG#@O) z8R2%Kx`=dnopOMx*MVD{_q$=1DNkFGmA6(5iWdEXFL6m9tOnNsgBLOdzr59+THCL} z=E3fYea0gytSeSjP2lF$9jcTewrYMK4T>X6i-ms%n=i`cI*x6IDe0kDg~<65t5r%u z&D^RDO()a+M9)64kFi?k!r=%CtO5Sz>9Y-3l3H8i3tgYuHr?|l_ zJmbWw;GC~erws^0`m??=)%7@_GpXLazVtrD54w)nWbWfDppfFMaYtTx zx0CSn@_CXN6isX=qV1Bo)N)u#}HI=s=TevBLlyf6OV}NEe zaKBay-yN+aR?@*B9IixX0vTu?+_dq1!K{HkX|10)Tbwvk@Nkf4ApB=rej`BkNxTv& zdwvrRQ7<}G4B@i5eG96H!>J?51&FAZy3GBI|aXKp#r znaJ85a&VyEXfk$J#?MpL{PSg^9F1>!;&}_im8^u_=Af$f{6&;&ct`>;V!)a5SqmQ< zm6gWiB!5=L+Hw0+eq>sAN2i-iI(&@s_ie2%Gd;KMftK-__$vz;*7NWqv*f^5MN^1q zdm1|{$fQy2YOh+{hM0~kdi$qk-2EA_OuNNT1ftB|R_c($9U&MkMc-D#=7A>Sp0&-; z&0N;)jS3vz)->7B4m`cT346Re_b{Pf!cEV3GUm6ghS`C$g-3NV$#7 z;<-ll+zd%FIrufPqy~{MdOqx6HUzY3%{~~y_ zDS#o3A-lK;D!tCyEg`5>7NkcWauuO>vUq0`#SGX^y5}NWWou!cw>jSw+EhKAyw<+tb^);p1W9CI7nwttNA!<<}Mjq+0qwz zCWCwtoby`@3ls3wwqh0sLcs6;<&f?moeM~hb`TL~6Yn1L{aMB>NHC%0js@`WSm`z0 zGe0sDB@nXu2ET*oK)0J%(irWeY>5GgPp1teu$OMtT(`eHyG$^YPi5ZTZW-_pezttR z?^iVuPi!X45&hdeU{ya9)&yd|6wlZB2T0j61<9Vb0Id=#St~Pd>|Vv{KXJY;T_@VJ zBOSQROV8Op3?{W!zjsij0q1D^c<)KD5HQBnV0ttG{g;C;quad2W#(yhUE>!1UbbYl zsm`%1Akk_^7T=T9Z6sfKTm!K8O8$C>o)eY*Yb!Sd@~3ZzG`aaBvRSpU!2ZoLHiEbJ z!E9mG?!;8>&1(1MPAsx_UFRdI^)c=Jb}eHuQ*~402>mF&NRbHpQ}N*7_v4nv)=qyS zJefxIgRxfVuBA>ndfg#-=0(h>p=U#uB!Ks8GQK~omxxK7>q@uZX+SaB*D^~M#d3IZ zp`DER-f`d=)m?JpeAc6ctlg&3O#}>0yz@0M&*cT5cEr3O=hCKIq-MMzaEOa~Cnpxg zK&;&z_d0fKq`&i_Z6^Q5WIlck?e@i&+T-X$o7LIq3%cF>^i6|gLPH0ldWF`LBe|{i zmX>$$RnE6iHjpDkz!DWwq{tmYu{lVO$Y1|Q;Xc0w#@?-3yk+pXPyF)KE~qB9_bIj% zetD;*4X2f`l?*KNO#0)x@yq|ZW`F$WnlPIH;Q&H84h<7me z$2}GsYjuB6G-~LwWHCN=P>ZhxuInRMWanchNU97hskN3C>Qo@*)BLRX96S_K7ahzGFwPhCkNMYvTX>$>4isZ^a2myD~ed^6Lqt|FI@J9r6zS zpEDWQ?Euafv_IbcNCx2CrhKVnB`=?ezvb<-LeSzXTMzt6iE?VU{4E*T#YW)lPW}4B z{nnp+V&C_`Nu?jji$v4~TW;Xoz+`t^L3(IGV0-<@I68TAZI^ZEUb;yrsGk( z{)&FF8UWVhH2YL`4HsCV3j8S8*u{&kMX|NCjy_cxhidp4P6^*^aaxL*7wqv^JF(86{NXIY zTZU^|aH6=|#`5&B*^>qG8jgCzN^B z7T2YrLOGX`lq?KK8&Q|PQbVMTrmt(xW!>OYVBzp~SgSOosWo&u6swlrEwbn)9=@I7 zRNILE;&1Ce2S55vx*WTG38U=wB)jw-@QXS2>I{*~PJRI7-v>+d4 z3md23duOhn?3;s3+P`SIT6!mX#mK-H?%YdsmIeq%U>%+wgh_-+7`{@cFXyDL9|Lpq zx5r*k(m!h5%hiW5+p`9tvb}jiH@f%?=jtkU;uj*d)K$902^^9)b#ODj78Z(nv;`Um zEW^AyYu%Ts!N~!~6Xyi9!wkZ5c-7e-8fZMZESJSUcm__ivFiCvoc}pAa({mnIeOs- zSZ<&WlmBaghVTycVU6?J-e)yCOm>{c@nbe&0*405;J`Ui(O+gwexZ!5j#gNz=(iU0 z?MT1(Bm|a)An?&nPV~hjABMsX~n_r;MPs|bD=b~FM7?ZM}5vov20=$IxE2qatxi#4yph_ z`RVyiKusps)cr!CqN(RM^ar7D;>a(a3E~WgNy2P~Eb)^-(GUNhQF@ z*A`V9m!Ty~M(n{E{7zxY2k@TV?sQpZEkU>xG%^mu)*OqXl@%q+JK z70a)?XO~;b?N-GucLLf#H)&>0lKUpH>?v^XNy09d*de=d!mC#4pxSMjK{{4 z&#brY`~RBa^?I^zH2;Z@{UU3bj2k)p@N;Td#K`L^E^R&Os_U6$rg4i|G2tuN=}nF8 zOMaIyc6>!AxxjP4X>O>Dei4erK$E>pwbJ#jN%;WgFdVN|Ws|dKxlZLAnpGzM2!d;Q zhc@Ka;8Q9B!;*b8R0G_s@pq}6nyrc{VZ7_~G@e^OlLapc!m@iQ;)82*GM*!RIZ1Ys zdD%^`r%63Tx_dJ<$+%1gT06V8;&>^qVX=G8uq<=@sJ#s|3Ge$h+S{qB^bR(ZJe0{hB$$gz!=6#FipEVR2i#3p7oS;i029?vsd+VBJhm_0?{mVn-9Ttcf zaPvVyClGf2rTI4CjQl&3o9R|JsU&!$$58=(R0UNG6(@|~kPs)-lVi*HSfwMsmgl{E6P^iW@ZIBGlk{D#h2Fjp=GFS@ro=L@OA&L zcH~dlsid6gPFLtkPh`Ad{&X*>a7+I7YfSjy>9((vFMIO+Wo7%%Kj)c=^|J*(8d|q4 zCoMYiI{UwY7Jr_Oa1L$p>>9NQ@7#^lJ!i~JYi(K99wIyZd*THJo;&=>Jt|(HT}<1O0NA5OcL~PJD zcVV~$;DeZr&7QIg?LQAC1h#wlK>)QyO|oQxEVQb8A=g_T_s#mCPV)*(l}wUXcB9)x zjh&0cnWXORl3o#1)IxNg%1m>~SHmu8 zz|4F4z5F-?2O8RZ>P%aV-WqcG?vdfB`jSqk3hCKEoQk99v9*7BL-AR7Q7Jq3EAYy%}V$-)D54PF7Yd3#?^F0zTT}<4( zH?urQ456Qogy&P?0Ms;tV`Ccll>RR+mP3PFv5nFGMCEx#tEjh6WLAo|@NXeIv{nJV z9wrEBlq0p!M80y+=4Q?$&88_20m{i^E$;(TPo##4R`%b?7@>8lJrQkG zCe*A`5)=eUl&A|A_4!Jf!ejP)(u=C{G&m%)T7rhiTU!WeChVWT*zY_%4|Bm{9xEJl z#qbn;-TCj^wBK^M8XufHs3Bzsu+Kbp+gvNb9?_I*Hs;ae^&5+R0T+k4g!m92BmDO77#FCM!^mv~<0LUELf7 z@BtR5qx6tfRNRO&H(jbd`xADuhGKc#I+eD{n*5VVtky(8_Lak>XPCIKz$q}@Q&3+} za0gPr{q`^@o!<9`BtCfRk=G19nk?36Qo!lTBZ?cqobH{?|pzqy(|ADn5yM-;0AsL!wJ zUJD@(tX3o+H8EsIY@-mGy{s=^^TRxzYXV|y6GKg4KYryIvC}L6?9NnEJiH);T(0%# zkPHo=ZNe^0EMF2%dbfsYgrY??GH6PD=v*Ufa_CQ!=qJ>$V%S`i*GDEX54tRh{xSv^zu#?1n&Dv4Mo^jjWS=*tYU4x^ z%6802&oN@x9Zh!f^$bhAXS0)XEQoL(YSLtC=1NQKZr^txu!g`7Z6ny#1!EW}z7R-t zVjfQZHp}5Ap>WR;j_B;)%h+|=>UA9gg{s60=2i>$CvcJ_3(=(>Fmmljl&5G^xDZFt z&^q8H_Zi$nNkD{lC${je6w|z|GhIB+kc1yWFU*`aaFdvbCUh9={g=+NObEX-#;`KP zgP1@-xa>y4z|Iw(=H9WlIvyZCE7tCQ zq!sXj!lD!9odc2Kj1mKnn48?PxwnmAvQ38gGBTvR9JsJ27!myj{?5<&q{f_h73~PU zieqs6q38ZG$Pl_PMILa)ASD*#Wd(QnN>WPTWzpBgaOaJBSSE)pr$qi7l zN)5?(kG#M)nScxTdazf7`bSSSyE#`qEjr6le5Q9lWgwnLAfx|&lN{$|m z9CbYU`o9#0ay)L84l=gZ1GdIz^0u0@?!U*z2?hrGh)p_rjH5C||I6UE8)OUIV}sZA z8t06&n;hn(FJrNP%s~92S4F3@CwajcGgyz-SBc~$)6md*BAUos?pVulHO1L_+9o?h z>hAYZ@aaZ2vKn$>9MD&7c7v!RkU^kB_|)9?^u;xj;=*I^+^BC1v*x|NzR~OtL$B)Z z#9oHcQ&Q-h9$_{nQ&<0`{jZ$mTDCJ*B|w&U&Zeecr%t#=Z&7@5W|Ua`Rp^TOS>sve zz^lDST+MxjW}UnU&vnL1=bwFYCNhiOkCku2CP77ox1VV?^c*PG-&<99#l(Vj97p&Q z{{3Z7EYg8Z+S53`q~p@|?I?rahiMv74q#`VQyI9xbrFID16YS2NPFQUk;jk0$Y1~D z_CIdE$dIY36Pn^dT1@jZ6%g)IL1 zY(?8}V%TT(FK9vF&ArUG{HEiW%RnoYK4{`KX2)E+QibM(WW^-id(C3^gdL9X_ao=T zTu&{mDg`%^C0BVERZ>hsE>c7dF45Hq*Hg07t(W&VAXRx9|9j@&iNM z7|3U~SNF;0kgoA5ixt@bcW`0iHMW=JJVofk_ZRi~+H^VMbd3tHrC!tL#Uo1gH}uMZiQ7XrD8{a$b#xK; zzT^Ay(Z{~Y>361kkPE->5BLrZHcDo>{$2kN2a89ce6~}&KHmkkY^bnVvw}ICEKHVN}56pkBoi@SSzsJ@M zFA}E}5lg>mHG3&2NJO$*^U33$(>8AfBiXe62!kWnY^*mD5i>c z@gw4oQ|md~VtpkS>cQ6Of1MV~Z{sP(YVShaoeM2h&5Uw<21K7SW{&UfBZu5N@w5m% zmuqH)==|u#+0Sv1*fVrfDE@or6khJ9&VE+VdABWAO)(3B-^^smXuf&1X;k~+~pEg!|( zQ<7xDJrPdlJ}MNs{RtAL)hGtCK>FF`=qVDnNEu5O4)AE~k$U(5_GZZ2+e25Aa~1XQ z!iN$pQ*J!UVb#1{mxyCRgqo!D8=Pk=@%@+~b;WYFSqcTclZ+i({&%%1ZMX{kk31BTZXklP>Xn!B$Y6lxpYfiPkb?EA-OV`cgzYY!J}`6AuHX z(sTez6DKe6+<$;8?>7qL$vW2n3mW9ZPE+hlR|5kn$N27TN(>=XANu)_kw5_-^s~a% zXZB}Vccpt$CJaz`rj6(O{5tKmeLVO#2b(i*7Z1#%6F6&rRzOo~s!IW;Jl{Y%C_b@bd@O{5>TvamZS;rM;1`LkVNz5G;v-tQ{7r(Vx*8mo zT)UmrW#q)~VJ=LGtV7`C3`a&;myvg~f$&``O%|;I)5?Lc)ztk{gN&xs9~oolePdNh zl=3buH|&mzAOCQ+8;!}tZtjBsuv+vm%4;6^>X?(f7ZEeD#NIbeAQeenXsl1kTkNP5 zQH7B=3aycSpyfbs#ReKEBR$drW2%&;UKt4r>omne%yV)LKw*)83ig*c!?VhreF~N+ zA9F~~CZBdPTys|}cV@rpv=i8c9g=w+)=wfxKADwh%^FHY%_el`Jt+l3WpYrA5aH`0 zqhEeUjBEr0f$v1{kEKx}ZJ=A50XeQ~{D3JRyedS|DZUN@6%HR>vowSi9GEmCJIi(> zcw-A>-vm&#Q@gTW6iY;O?$pAh!>k=dd`Q)(XuR_wUT_J+pAV70%%f*64|PV~djJ2IL@ABO7M7636Bk4`E1pKQ|xl6#UW zG7@A0h47Hxvib{=7Vt>l)Z<_ZIPL_5?T%S`R$Z#pG=A7!m~g5?vx-$qiXw$S237&n z!U;gLW7IibS?b7tUJ17lJP_&!9eObv3;{U(lZ}7_yzFAoWbR!n@bUQC(lIYCaVMvk zDJcGXr`MJFDFAO+W?tzL?~E~NSRT%WGS<8V4lj|W^gtMi8ubvIzp!4sL^%jR#93G-aK5?o>KybdHTULJhUDj8@ z_MK*cQz59|n=j1L>dvOfqW{f`smzh+^F`aLo}pOi8}bpXKemD_DS~5m`$>>|Vct@H zddS?H{xaVZ(clpfr~D;la1XWdJ|KyIz%{MNix+VThY^>5!jPEH3cxRu6dKW$BQPVu zkTkhX4yl*FxV{}GqGp#SO4F!dkJzTI@pLu&sPFM%7I;{SMu73J=tDK8wF&GlabZXl zhnWa^lvorGdGTz?uxv>fc^C~lwhR*|n9{*WOex^vB09oCt80o--r|IzNPhzBL$H>s zSo*`g@EKu)hlFW8Z^O-Ah&lsZF=#jgQrvirmFMnbMB>z41-eujn$iT}w z)D2iSjO_eweB@7kJ~H6f{SAD2u*@2x$7hQUJ<$8`xBq;8_h*GGnZygx6l-NWhS9vi zl1P#dr(B6lryeOR4Y5s#D$fFj6EHPDOMiwX-M)0YW}R+qFZS|y*`iaWcaCaJl_B38B)^Gu?iNo}MP zE|}uJOg{0sj)-Qu^u!5~&q4d?CIlGXHe`+ND;31al$R8!*?jdt=HYb@mO6)^{_Yz< zFThe@Y)T~N(taeS@o958Xn3KF9HZClS&L)(P@KiYz(CwE!M6+%vKmgli0_Ok+vX%b%Y1*-CkI?b+uovO_1Ie zPp~=`PaISTC|7htN%|v#?Gu|X@lIA$`c!G1sW|0etMf6+Vhge_Vg2_;eW<|qrvi8P zM)=0zdL9Z>v|5Z1X>nGR3>gfJc6tpanq!_RUdQ)8A~~t1^+6Mzz2E{YCB^|h`HKd= z5J3cm8jZW!i{0oR>W#Z@z$YMyw|a{y+|Gg2LQEZ#TE;K=f0l0dNc|P+^86;u=di)ZzH3nX?3&oMf?Ptyjw6k}AcN=1M}R$JxW3hKge-hQJY%~ce{?_a za>BhaE{aq$ZGM+&6Uf|f1!50DPTbuUT31~k8!pfULX1#?o3lvVP(hs3wd~|w&E^+M zjHLR@f;ic7k9Ik08#3ERg-BF`%yKO&i{V*F!YT_arj%vcL^pcIZEwB>coGW95lZLG9GBGj@MN1(%?e^F`skU{_3j)aCumN z>(PbJr!>X)kJ5?^jPkh9$y_98g|U051rLePatI`}{s@e2mTsiJFM$09^&^fJp(v@R zK!w-&1?~)H%DYbLq|}-GC?WFV>3y3KYt@F9 zaXa6Ex7O*#Zu;)lI7RN(*Sd^e zi;EE_+ZI7wQzbVv$PIUpj}sALAM?MAdA7stkSU6OF=fXno=iqIf*%zPccJ_r2L`)EfQ_T1iTv-GDol z&3bSM?1^q{vBE|AO$a4PuLhI+2EY_vI?8W<$%!XEpi$rjey%`zV;{TNXtGa>sX939 zT*F(3L-d1IWlCFGuChzQv^pnJ6}OHupwx=J-(mUqitN+p9UZ^+u+B{08m0C6W~Yc~a~`91K%B?JwHkQqQ% z2i{AklTN~`tgUV{*D_s_cq9x+=&{6Qd z4Q_&&^RhKeMFweHm#i7MK8nT7go9<$|vFmNHo@d(cRNq6O`W z(rwQ!%h`MUMViT}?k~&IE)WVYnHYIDCM3LKxh#3t`H54LIc>l!v~qAL&v$D5WucD3 zu?Hus#nMqo+Nb?c()57wwi0WtvQ8^a?B9%niKYJ4m5GOK#b~)G&(WLF_wwMKtuyY7BV9j8?$7u$$5bUGil zCaVPaUK!2{s<@%=Wq&Jx^da@zU~!e6q@7N5R7^mqf}?|JHz9c!r&Bs3L#os&emBz% z9WVMnWVQg6E8`so4nk91Gio5wK1bc!+G@v?b)&Dz;Rn9@R(vlt28^;vkoavP|l4E$qpU<4Rje~Oyk7}1CANmH|R>{fR5BJ1*rU{ zN=Ysn4_bgcRU&{+&3XcaKvZ$Hbn8*T1qbVq+p{R4?yJ+lm!18CY+3E$@YB>_@2F5K z?1z&#KC&OdC+7KtDy3L;AzwqZ)>akklhT-C6-&9bG&T9^ii)+N@XR6PkLQojSe8t!1(XFDYTVKS#Q+&1zw~Y zgYo-KHY|+si?Pq5!Oy)^%f`fMOPBn}M4$TdEVw1_Ql*)C&wuyYn=!?O;4b0aEg9X~ z{<37BPV9>Glp+cl9B_Y}4IB-7Xk_$|Gcws8xmd_g`RSm>>tZeC!tuS?5ho5q-8;pP zo2dcf*3n@FlcgOTPtX%fzce$92K56cR81=+r=-xQ&Nrb6!IrnW~*0{4SAu&+#OvieJ0*i!<&Bb{FOy z#g#|H`papdibg)`k!py?7IZa4yRwm9fi_Jmdjy*!#2h%}s2kjb&?PsI{5Z(b)nBEa}ztA55>}G=rkOFZIgy_A%~o9j-iZY6Sml z8=yx^V92^vdmOg+r>p!qX%T*>8T2+p5ZxcMg?0`z!@G-r=zFqOEFee>L)nDN9q-8= z^Z9h9f%^5+s++xeLV=$>f?Y{>A(44;%B59>0GBf`#J<>F6ntSklHDc_FbUN))W;ad zG7Q*P|8viog``mG&%si> z;HD&BOKQd&Iyummu7Ga-m=m&Hf&6Z)r?0p&OAEzC=6fMxPbhkP_%oU1Tz3PFX^80-FHSbWa1 ziWlC8WHfZWy(Y8gpV@5)Oesx-num-f7Q_JzXtlnPk-w*x*ZCgQEC)erS=srTG(#En zBN{)sFRejLAot5cray?WEB2ah`;iv_V!lc5ptSB-dP3_{7Tb@3B{ELoV_PHMTFlCy zGBGqVLpCzUuSa_~WC?ayGmXr6y07g)KNF!DS=83awN?$)gZ_Y?egGhnhpE@JF8WM` zp#Yx4$J0nK@+Mozc|p*W`h97vEvg8*3~C&<=?*Zh>03lzPuB)pr<0Cw-n^Y!FX>`V zHFhr$IFzMP`IOnSVc>Zm0VH&(Pyq|iQNKbh!Hjvm>n(}vIDTH3#8RK7?a8!eWI%9sU>~8+p#q9N%iYa)Mj zSSuRKM+eYh$`x0iG?(tIGl8`x^_W7j=ji$c_xCt+Mdj#^U_%DK7vT`l7hJ!wWVHAJ zVhmaof=i8+zhq}0eEiLr7LkKkHq+9YDDU?ZxLtcOBRY)GVznhRzH_6pWE`m7;HUueFIIfn<`1n-VU$??7_ z_EMiSiQ=C};q6J{SWHsli3IT#zAu3Tc?*iEexr8Z$KhcJpA24|_3Dh!sjmLX=@5@# z`fv}DabRU%aNDeb8<-ye8fL=AE~1V#?E`&=5YaY3>1FU}g@CdT>wlx+Yr+qab0 zV1Z_1%$R&IZR29dWMa~_F>#<$;MVn{z(8dfvJQ~RML$A`H3d4Fkg83TD-ly=^ zHuoH5yGFyw+iU^*xQB~HS0WA8By4d6)ng0K61eDJwi$y0mP9o!1B>SE_}p?EFPcg& zW{qyCcsqnMaNqy$#6qw}-JhNWKm??kivV2<)?E8KD7DRn)eYB8>YM1TMmHFV> zccr-x=pb!ofsh)p>=2BHhnI$qKo><+RhE=c7zQklWC%3B{^ndyel7eNzRK1ocODnEDG8Z8+IzPEU z8`gKP&I2x|HYy!07gg0T39&yWdaXH@$IPHfc&%-CDp*tBE$>}6H#9Ur#eDGiE0N!Q zCGV+18k?pUi;7}r*@42b-)OPO-ORvXuE_lmQcjJSS@@w=jO!ZhD=FRB(D2WVp&4jp z7l^t4PGRT0SMy9eg`HzR@nNZgBV-k@AWb zSy_YbqKHJE5q2FN?qZ1-QI#qvzQCe)gCpr$?B{AMSJl*Rorj%sn`Uw*My7oV!9D|` z@qJca8y&$9_q5{hSUzB=i_Nn2w>Dm2ft;J^5r&3__RM=y_rHw-OdM}6S9&7|IF;(J z=Lgc-JdE4MzJ2>v91*mgOzX&)Sy1Bet8R|{=J{7`Egre<9Ca(Ry0pHzmkfJNTlMaJ!>Ed6fA8=QU7dC> zsRy3*#OX;?9=^6&SjVuTvZ_QK@N6?$#j<1E%d`Q93bC zH6K~5)$EY2vlpp4n}z0-d_?g(}o228A3wru9rS5Juo>kNqd{Oap z-!Vqr&LhD&R;)YX`Aez9p~?pa(26P1=YyD9(~8E81ePzZF&V`1u;*TD%d@d(MJdU) zwzk-xEk&)SN;IA65VFKEYRK#UsnYC;xgRc&vHz`F9w#N|Wl;?^O&2d8Hk#5J{1*Ze1R~rlhNuEA^n*MH5(?+5SDnAbe4e{8zu)jPTe(IQA3O^X z4dL597hVDo$xMHGZ^%QFP!7H>IwrJ!z~f4aik?&A8@NjTw)OPcG45%X!RHQzoPu*} zf8)zN)6Mf2WUD_)yW^Fl=oB}Kif|{Jq=_<|+MoDo6mKLTPI|p1yR@VfrVBy>A_w zty}F8{T=%>54`;lnu@B7d|cJS1%;#xT4(Ud!#6k7BvSqB(CbFNk<;?-uBojT!1h_L z!bBPmOuNLo#p0x5N+y#(h5ZVuO&qFZe?<;>cIPJuHBnU+dT~s678McH61-FQu2Ob> z7#3bCl9EM8U*~1QhFgaM*!DVbe~$ppq|t zBQmyhI9?HnRl3Qph?I=of9M+!cUo1Tx-iMOxh4_QER$LXse4o}18ky;OK_GMnBXH? z0F@i@`*79VyKbyzF)Ux=^f-v*?Epm!mcyxs66c9G4#+teT10omxK`mS*_D@)wI!sO zDU|FDgjq&aXjg2AV)6qd($bg1ZPm~|dwLfLD4}papbN~}Zrq)X$RVM&vHt}aqzDv%a&||5 zZxO>zA^73<XdE4zwP@g|~Xgp7~0Gn;X5KOvG$Q zk&BN7lL8N(I<~do+@$VdT0W+a)%7}azT->B*qF=40f3pzG_Fjp`Mv0g7+}}dAsV6G z3`*n5R3Z|NW8fEB@sq!q2hJ`?YJ!sX`2Fbk=gBSJCmBR1V%RdCM~$c+0fn@GPT8MA zGxa}ffCk6&x2;s!nM%#hJ2f(T1#iuSRiDL5=~4y%Iqc{0FB_z|QrYD^ZE2=xWy-;X zSGIE{J1l!Z2~j$g>q+=}hDf3!d{IcU$4k*?%03|p(%pQTeqd{~S^&o{;P{Kb$wF9A zhkz;CDrpNOCS{Q(mZmo@(l_EGjsLF~Aa~*3-=ceJOGeRDKcIUrp+M0E>qIE!u(6$S zIl|eE`kc)!o{_Bv#>lptD>CQ8SGU>-Fw(Nm8B#=Ey?~2kG=$NrHH|U>?UH{Gx!+s#7Auu!)30GY!|J zxv2O;{g9{eu)Y547)k-KiK!{lWil4z=(r1{^d=Xeqs3#d5cIm`yRWQ)XHnA(Kq3y1 zV!wk0DL9C<8frbW5Do=4hFpIH8IpAIKn|H%ctGc_nMpMU3D6=MwXX?zUcDOq3gD1Y z=f8etSsJVmkDaE20R$e)MN;C%sCGkTA_QDDwa1>zslmLLdXJMH!?LHYiVQ@BL&brAz9F-3KM!vOMX*?jaa z5AoyWE^qSgiRb7D{Nnw3osI5zp{(~uW9yM9fQS{J299us;$^$7o+XqT-D>9&=f
c8f!ezW71ZS=_CAvqw4oI!BhFHV<;yftfPJX0?V(u?O=Aj0>#sh1yk;9v z8uLk1=1zE$92RPvP#Oi^JvB|lu$;>5!fJd#buqYZL@B*+*!8lBwzLO}SpiHP&ub3f zuG664ReX|+16>g~01Lda4cfgAY}RA|X8Bc|2dGjB>02sqXlDO{9~CIJv_;^NMD#0< zs02vH#TvOefN5%G<}u~xySr3&_8A4NLBu@nrkdJ~K+o-KRI-^kIm@Skk4!BpoxLFe zIcejfJe-^o`00?{5Ahy{+d2woMbcO}y~otfEsG1z(r}hkHD3Bs#dgZ;ZxsT65z${x zJ#5kWvzX~AB3M-D<@*Ls$)fWcLzDA@zwvV~+;u@i^G7Q{(L^%_|M<{YX_Q=jJ^ejU^oe+d!nIq(~tkx9rDP-(INH%t+hDWYEULB%FYu0#uQ}$T6Zt07H+e4ycgr zV67fiqd+m#?ne>fgKFQuaiUPssDK7@0csMXf`!^2YzY{HD~jLBUIY|^d0eb%4y3pR zJ^AV|`jCo$Dqc-?QBRDe#CjpdQdo{>r^W)Hg^G>$*Tt6-SG*&1zV7dub<18@JC9KB=Yqb|Af)@!Hw;CcwO7BE zu?+zh5gE`EZb@b+4VnubzqKs;bW{U>J@ttPDdw{|OTaj>;B0T9#I_RbY(Jlr&{$9S zX2xJ&U2@ZgsGzLm1$9W{z>PsxaVuCp^FW`GEzodEA4>>%ZR{9;y@VGd_l^0wbdMg5 z+wtS-ve#(l^}vEvGg>>tST!oQs%h@v)UYu7t5>gHtLG@70h?erE3ohjycdCMgVgAz zs?EDygn$|cfIX%C0-(_QnFT$VpW|(t`^xt}4dWV;bPv>u_UFI^Qr+miRHB(5L1lf4 zx&a9oFj{2pzrH!&+w1r9_P*dg@m;Ea94`nH){Q%n0nZBs6sy`f!vQUPnc5k3r@8~D zO+W4rJA~RwSCygHGYgjjUu?CVUl$P{VW}PzzBXjO6_AfH?@LPix+FoSxJ&)&^5p z+ljUC8)Pprr|Zupsy)@!ND#4B<*E)$J?fK&w$6*zlfaT00uUQ{gleT-uah#C-}Y26 zQn*}{TOZx}MH$xv5`U~XOG@q2hQN;#fL z6u-P40E5v?B6WJFa%hPD{>9D`0?iPE4y53%tLVXVPW7V~%`;sSUKBCmGk$ToMnc-W#85G^2qjhz912V}W4BhYH~!5bhC*%oSx+h=>}sR1z?Uh4^4 z6a=nRsccM)JDX~_k_*wOXq;8cl|~9!+sFo5tG?Ul01B=TYXhk0SW~*@WMpJP7BQvB zODB-CDGAKzmb}h;wF|g`T5-pWivY1h%_(N~>{8JSSH`Fnrh>_U03e0^RnO(b@`DpO z+0i@BMg%tY*k&9)hw^L1R%JSMJ7+ozJmP~H1wi2=xFe>VY`lMsG^);6vd_9|jmj0j z!i*3o<0pVd`7}!HKHav6SBJ3 zJSg>sJhoWPE22GQIFYpdk2<)bsl=4$fMG4LAhd^eU}~>PCsa*=!=y^KC{-#_FtZg+ z>5ucY&8-7;oq%q`a8te%<)ti@Aq%xr@PDT0XH6anNdw)&t*iQ4x4cvt+ilGJUcAbv z{DtQ@1wFsA6`wDnI|M{-2-nWgbpQz}09dJS0&<=d8g5JG+vWz=hfpF)l}Fb5)59Ph zUK@eOYdwf*))k{axA*@TaQabalT%Zxyy1-wkEl}t(9`^oH|GJ~z>hAzBB+=?8pN^E z`7yo-B5Gl$ooF)7hzis83mPbe^+ep6JQJTdey{US-lg$Nq$2D(nO*zS)IyE|@K4SD zK-xWkyO~!4m%m1sWWib+y-Pd}_0~33csf0ud-nj6r?T{Ldn2SgaYO##fMjMN6y8c* z+1T!%<8%A_hulNGRbMpfz|=Os#b<<{LRxb2T{F6Ot5nrH5^2EFNN6X%+#%!x)Y+Or zRU@)xF3*{9&ol?7PD$2m0R{I0=pVV-x1MyT;_>oSxIxMra74yqDH0&WEA2J^N06@x zableEXy5&?q}J~a7->t|b*am9h6s$KjN2D1y3!ybQo9dqWdju0WS0~Op& z3-iX;wV&z2zNlrox8U`9BnbWL!til_Zy0C~YSvD?A##(5ZTFbDAyInP*oP~4XtD5H zZ@^!BI3X$BbI+qFprX*ppESzz63|*9N6guVu5#*YR73U~jlT{RiiAGtB%4G)YWfoz zZHpPnv>(#8|DU&cs3RKkTWZFly)z+c1V5&Ycu>f@R1_0xT^{dKCEvIU`Lm%L`21lXk zQUCneWupMC-5YWszD?uSMxZQO05P_?o9XE_>A%b+qyDcb2bGqO_D9h3s_vW?0eaOiquwy%vMVYR-al>cwcMwjlD@-10MJ!tlNP}jawIRU z6F*O2S(NhGnE^DQOS-t1W4_lNe^8e=)McQyk+_A!D+635IFlr;FUc~V5$_pCAFJb7 zC6_ZB83Ib&g-2vAR+F$?uL#PDVYHBxQqe|t#B zE8}Ph;7K3{#Av+^NBmrj`F7Rc9FN*@+2y#6ollxE--N)S=U4^;=oOUJWCd+gq|ojX z^FF&P?WG!&*m$945z?p!Yjsqkk?K(O#1*(7VDcN(oQpe60 zfM7>8UvmZoGr$v4-jo&PX`_KstU#mUQKanxNKXB0D|*RuIOc1 z(>&S^2aUoE{vvt{U51?joux^q`rEgC0|2ik0q~})F;qfjEtVhEyvkmszA_e;NL2il zG*}SlF-^CZuminhhK)SWCnz?a93v~#S=@T@?lxToXL*NWCLzF(OgDDcT(2`$;J)A& z#v65%q{w`FI1GD~E(`%M!2>G4P%ym($R?;AmXP$@M|_9x7C1d@f?gb9hYpe)yHx^2 zC;?5_RLVrfY`S`BJyfiDT=X(X#>~W|V#A~{MK)FNB*CF?IR#wh8M_f$ zH0tbv4gbPGUg!_mS0W3*fSZ2VV6kWo27V{RaVfnR08X?py(2XRJ(&@jC;QIH_TY|3n1PUnm z4mobDZal|lI%gz>I%5s=S}7S}f_Q*6DJ9h4Fh&l7I~;mM?K>&v@%DH1wsiLT4D6YS zP)O_Z%CF-1g*vw%`0HogSpiWe{Y;bq<{lC+P>iJ;KI+A%OS`8q@C<6YV>(S=hFv#9 z_l1Qwk^*Szco-)j%CS!~Zlg+|1tfLdwrB;t;SxFNwCOg@8IRlIAO(Z_YDImjdQ5UF zAoupX&ZVsSQg7pE4{r@gL$`W5e!c|?x8z-#%#r=kk37_y0n^%_Lc008uYxrrCl#&~ zo2Rj51bZ$D1YzO3ufzUu0Gi-9lDLjdgg_r2~ow4_&SS+$2I zcR5Y8V%pl;RoJ0l#LCjm^2?yW>5Elmi1C*n`~!q^mQ~#41v;)p%OkgKO5UH3tS;A= zjy~;IM5ar4c}+2%qs5~HV^m?@KdFcprkU0^0M@R7@$MEckwMX4zoxyTP0}ixOh#1! z{FL;MZwXHcm}kh{-B3F>elF3gE_(QcH+-Q+PKX~^CsNCMS6U9rTw5Od(_m` z7O`&-iXCq;!jn|)m}Busr~>9n&<9{U@id7u<1Soo?0$5@5wtfx<_R=+IA7tb#9qEq zb0VR^=sqajF+iga8-f&2ni;2|A}DDFF z4SxF5oFAv`MSAUBg1Don92tc6KozhK)u@7n&x$&!-8~((V;cGTNgTr~wK!^Kr# zBX79(MBUiXR?+n~()awfi~dKJHX}Nhv*30Uc2fajV>VGLCPSuvUSp6q*zr;);5_Kb@?g;ocFCkMz@Wa36 zKX1q0%b2V$){y7?U3TE{GtEe#6M+RYN`-~zT{d3St3zApsqMj}I%F%)y%ePk#N623 zSdQf%pJKDDyo##EZZy*n%9FreWN!r0e@g>2=AING22@iMJ5Q$_sH=2f!ugMEg`B38 zqWU#q7pznCknqNKbiA<6za+nEZiK$(-YrawN_3&83aT%9zr8k2ETEs3^j^6zAF$nt zr$w@45@L1{bv$(zEfe`)LGw1`DYSLQ$Qk@yXVr_VhS&jI!}7-<*>TyXJ(j+ou-CmL ztQUWu@UZ85-PNxWIc;UHN&~YzKx)UX4v3T4Sjr!~@0lE#-ujlT^$J+Vvw#8rbxI=O zzLGx(mXImc7SC*?tV6kWQ4HVS1KbDx93bZriZf1xiP*6`7r8`XNy*>*k`2JaJ;VSK zlp%yHZnph^>c3Xg$1c=iepGoF$*l=7n-uythx=RYAp#nh;8Wb~oqe>FZ`xg9hz$A& z?rRj?iw(d|ll7C5w`#teO+SW7sbo4$xm4AGU%S!VrB9LQvV?CRlM9v+i7yFRa=fx~ z5mV8CP*LNI$jyjIP#JEhmI~L;xDYL&@4Lp-!dp2jxW7~-lXT0c3e96Fk!+!`F=~%B zWBy~&e9Othw-9NZEimTC9mt_{EO~Y?3&goC@$NKR5t*2Y(5tW6y6z3E+E-mdleJKVTfw9rIZDd^g|yNHq6E z&8{p?&~lr+cHhDWF+#DibV%4QN&&3KI(X{!p)7JRqp{Nd6Y0s4dw(s@u^8_dg@}ll z)vwhC(LC&zHS^#`88`)@7n~;UnTrjj?{E((1s%aQ8Io_8H|4)a)rA450ZueJ{+SyF z{r1R5^#g~LC*p0=Jxy=k=xDq2YA!vFl?Hbz#IsM z6Dmt6a2&uplw2?84`r9`|Ko5Ft_wtkB1A8-`tKISR&Z_)J|=OC74WYkSfB7NeddA* zicqv}F=s;eEuU0Tt?37M4nZFv8@MrkOm0G7z5GxL|7Z2scniuE!7;8>sIh)FH@9n<7cz0sUE%dvw#MxlQKngkaptl9K$hjX_3 zVnF{Qx1p)Eq0OwI4=Im`CPv_)-{GiD>I0TXG3c9#b0#3~)_(l@K51=PCv;h|i4pX$ znVE?IN;{GE zo1>*HG_?>MlCmq$>gI-KDY{$@-t#ym`5F=)swBOjAa2AhKQk7H;)~fr-12JTi%xOv zj6akYbbuIj)&>B!{iCODk=j}vkR>m@O+PD_(rrJp5V2WsRY}Rnl>hq*@Wa$OS}lI2 zGyX(<$eS+-ONF;Qh5ki(aN;QDaX8#2JgY+dw1sa-k@_F81)b4xman?j{!uP%8t8ON zaCPiQ-LUMxB6bC#=UQBmy8ffbsE8AnpYAXK=PilB<-6|6ur8w!zCU|L7&hlEWXBaW zVI|30Y7VwV(Pn@hD+ia23Wi~WX;oy`ZMGL6npyf~t8-h{K2y}B#-PdK65KFC{)OjV>;ol<0 z;v*#ts?y^V;vQh|A9ossg8OT-W84;vo?F1;AiGv&DO(FaeGjY+QCo^ww}E1x`Pdu$ zCA}-PGdtnDlL_#lqu1Ac2)^?=9ARPAUf>R7cJMRyf;n`L-Y^)erkHPB~fiGwOWz`*a2&vCkbnBgDa2xM_^zK0+SB-&>ms18|lO z@?e_L27LU!Tg$+<1hb3iXjL++$iF2gY7b}!#+<>KAAhdnM*w*l$MVgtvL$_L%Fp@eepDT)Nk0M*W zI9D8498v6lRE?sCC41bLAz&}9IR%ea)DR+Q2`Q=<@Iezia*^Kggyt8bcQD9-VZh*PqAX8 zFK{+)b*U|1z|1b7?O(uP|96b^A2THy;jUJ3q?_7( zWUTO~06sUc^D|74DRHO5FQezjIUZnVQ-g*5e+=s#JEJ3E5SMkaubz3H;xGLq&(~wl zV4`>9Ytm#taS(evnQA8*iD?w$II%_@))*6D*SenfP7 z)q4z&JSz_Fm@_4Px}%<)!7eo^wWEqf_bW96;yJD!#e4ItWh475T=C|EQvWu|-XK48 ztcEL*^5ozWSX6dNUa3F90f++&FOmjLVli{6gWZ!c2>b8*nV4uTncrhd#${VKJ^XCr zkox>>0@WtaaLD#%P08OR7=?)JhlcdvorgL65+#bgUIVb(X~=xXSQN(XLgT#Wlc>n? zwp}@JUp*7PL6LlVbq=qkyd&4BS;4-?WpL#s{Y2d(6MAV(<3fwu-DkVB-S*7_Fop>y zP~L$(c-|XG9aKZjvp~!fi&L$C!=ddCQBaxpX_9LhPRCmFfuWiP z<>E)3DB42Y5oS$N8$g(kETPoXg?>-XOE1v-L^A@-J;@ zap(z@YYlge)hVyiK6>_*!_WAROW1EuzPJh$P6l@|y;uWz@kOQQ2Wc@smpkoIS};&; z*KU02#c()C;H#!0t~bp8wM7tMaqPQ&#{IH6APAE#GQawAByL;d!MW=oN%M3c2Oiyw zZlZqJR6Q!{L!Ka#j?0Zom-iC=P!|O;hoVWbF3fg37G8tF$s!`P@;B@uGQ(yYQTnn4 z?&kB=WA#bx2tsGawt@oTIT;qw-(u4H?%3jYJuCJ4&l1-P{<*oR zSG#;%Y%TuG7})wXfQxA&pFN$ubL@L!jxI?02+hZ26X{L}SDdnQ%m`d3iEO7nIvgCy z_4cW4pO1M9t%TZeB>*e#u-4u<(e=-~#2yOq5&scvYK!td)Rr~{73ndf`#v{CM+J%P z8*ls4Im&f*q9;6syJhWDZ~n{7EeMD^A?i~4BV5eFQ9Qd!wRjRwypEnpBJWr7{6UC{NW8b}~9d6QCyFnS2Bq}Q5=IL+E@_!YtH6$@7R@{>bd zoHq&$s0=@yp{>O9&T1Gv=%WOqBUd9lN-6jBD8K+CPKl653fKRYSTs7j>-C$g`muv1 zWc%9B=2Ao}7h=Wp52@~?-4~5(K}H@ zWauL09dG;tNJnbJ=dpLU9q)-=`t7HiBHZ?l$NL8`v)snFG46k~`3cYuKU{VH?cH{^ z-RJjZ4!+85>o|yZC9c8tzNe1PzK!UUAwqqp^$@Nu>1tbyTMOO3@ioM(=-Ow<@1-A-ZC-&z=|SRgv?4WORHaMT;PLu4!^%o}LTNp%J z_--x@KyS&s&g`WVtNq?*-8nvUV;7~V@PSt!*HGnc!7<~-?^H$$pN5~=-#xvu?mB-} z#4w8NA#YPCvJA-%Bl?o2DK<rh)`QW_O)<&HD2`#u`m^IOT(2rdEmei=q+fumSyb(Ga6|vdO>1j@Aey zc?wL5G(1*AY|F;lyUTAln3$f}MLSiqcDA-ohpGe(i{;u)ROp9FxF7cLt{-g`?Ns|{ z5@r3Vtr($N1AIoWg}hI$sMmO=h#FVuMQQLTE-+oNyU;gBBX$`AP+(S}KgSJZ^GWu9 zUbgyPKRJD7<>6`Bl zf0v?q6^X)z+P*2deRgt6@06KbXu#T`Se@btIn0)M?)%htWaH5D3i0!s1)s+lXwRM9 z-XziLdRKEWq*LH&b&W;8%5|oHV0hT2)LmZ>UZ@ApRN+kraWHO?tEIer8zq6jbM~oU zVqqkM#}wGP$K;}t&lJUBD$;+t7@i`F=A*++5f%WHdtL)wNP!-Ox}vT2p+yPaI7uyI6p}~c%5jEHSq2fsb0*p8&X^~&U@Hw#yGOmzIdam?K zlfcF0uVY@HQ4NSM0GIW?32Hi7pv_hUxJS!u*?90hJ2|xoG;`Rebmp26D?ieMH%=|rI!@q*ra6N0CNoS( zh-rbel8F$VZ%9NhaDdW|=M8hb^v#C`xAmV=q4}X3wG5Z!T#KIEyzx!lRZMEs!G`QF zs3QuQyrUrW+n+47?N%B(Cf~6XnTTQ@x%7Vml}lB)3v29iAdrqkM8M!)nzBV6T@QuU z&hZ7~yJ4g@cB0+>WNnvJ9pi49F}$%h$EQuL55&0*bj+uBx_&O)_eJsYUxrw~i{6p6 zP9nmOS79BoyNYODbY{QW_wuhNx1Y6VNlj4d7Z`N<`=F&cxIEM0^}7%w>_We{T_Ypn zk??)tHa_enU(L(Y$-Uad#58gCGM#;*52&_sx0%ewl4qnA`V3XsEeMa%Pw8(dE7nG% z=8pSkC{Q3zAaMkY!SpSdEtKUQD=kJYuC)@v^gGYE!kP&Ua7-|lBHnQ+Q75ZrA`=t- z@*|dbUCq_;9j7)^Yy5A1bx4#bU-oJCVCi{iwDslbO%%w5D9xn_)Ax2Y_+hoMnH|c7 z4qwdSUWw|3Ba`NmSuD(BY>T!1AVr8U@*SET&)+7t$2!v$wbDJgQil$a!SH|_C5*%Q zg&%Te@0)Bn)p8n*(R?Z{_jk~`*>a?M;?bJ%5>R~J0%)4L@38307f&J}C3zNliYrPc z2BOYk<8&e@5xx{-e~7!&uP4nhW;33Dz^jQF+}<7@weXOQgGJnKc?hPSh>=O8-H~2# zrpiwG(lxEP;E>;4J@HQLqG`e6w8?7~3?Loeq&oo&yMc6dukzN9aX-f8@intCMUWHl@T6%y5%#A=8QS&J+8^r6q zB8kfB*-R}A+eYKsKyvTmbwxFd0i#~4w5^jVS9IVh?ceOhVL!s?@4{s{_qA3&)e1nT zE^e~9{PuFg5o9NwRc&Z>S}}$?D{8PURUK-)y)G1KP7VcmS^gm-&ne$wlb6SM&#PS^ zs;+*NIlvO{38&pTv99^yRk*hDqEkqO0Qw`*D#{?Yaf?F(Dc9j8nM;; zm{C|MV@PE^wQ&4S#>rSS3Su&F&7iGZ!+asWZe)N3+`>kqPRs&eE0=-Uj?IF3dP3$0 z!35Oig$@0_-VWfA4&8YGn&E!QOXGFs3FDf_TpDqH&6z0yxqJYzEf)E(?A*f-j{S$< zMr-dXelMfH-B0^x!&VsiB5zY=?gMF!gQXdU*>MiSbS)PbF`AwhjQw-4{sQNXPg&S9 z^ytu%==M77DMoYn^rXf}I}#WM$$h|NR9R?Ir0BydWcqC(Q&Ld5WjPD)Gw*o>2DTI; zi+Xn|hTgJwBuuYq%&a6A{SKd6S(##$(tI~%(;B8y_|5a`Pam`-d|Xq zw7u}##|&gQyTHon=U=JD@(p@<(Ybs0lMAdxEzrmZB+-D)7ic*dm}s3%#4~8p#o@hfN0fA;@BHt0 zE$r>*hq<+-kkF3B;F}3>lysv<$7MOKi&)eLFXFZoucw@Iet#WpQ~nt+hq|IagkcIk zV42`8#q;w9phem`fGMw-gcVNcLsl*1CJLV`s^)kJ!D&BV23Sv$h6EM)(fW%0D=i(7 zDQ<>uEY~I3A0*;jcSbJL?8l6nXX#=~Qs`;OG%0qHK7H!&8c6Lq1s`X)WuZ!NKJxPK z?LHmbUKZ?e-Qj0N5A{*6Xy1nt1CzU-`)3h)+K<=DXGH~^Zc&MYzX{G;vOCYh@^^Q-#}>gRZCrf3t(bF9z(Ors zYkC_CAa?}-ewe@QFd;`e`=c=#HG>mzkcYGgj8 z-uCse1Nn;#-F`@pUn+T7a@)Ple+!gy$lPA%sAC@N7JYtc-*AG()bmU$dw?$6h*8As z85n3yl<&cbU!7l%Sih_C9}!Zqbo-qO+^^yj{xfy%4G3C&R?5R`bdtUQp>muNw=w+p*p! zUm+3vUqAY$0bC90ar-Cg2+Ym;Hx^z7-zfW*Je^leRh9HVlo(gf(r5iy$2K_0F`Rq< zk&I{2J=x++dh8d!D^G71*F^2A8fKE+!!NPmf-tF$QSB_L?%8!e0Z&=7X~cO~A|ojR zKaWL#Nhy!XbQZMt*EfmM@{$kN%wC_+>+xG z@BELv-Qfhi*H3+Ae)f@d%H=K;w*Cki9DELshAggi81Do&h%*?NWtAF_KCRH({?hOh z5n^uLQzbU{ezWrJL8507$y$~{Q#&^J3t3f?`UWkVxgZnS^>W_8(XM4P6f?l)=idhd z-i^XQW1v9st%VU>uDtSyn}u8s^GmnJ)OD`d9kN^MONZr&Zba)?ooCAYp?u;Zdi50g zez*9pl%TvgMM&hx{sR9un&9S!t=7Rvi>r}Kl-RB8=;A-iG9>ti> zb)tbw)od@Fe`MjHhM_k!Z5QwdYUaCT8Zds_MnG zfQg~cNmZU0Zp;_0_GoS(_jcyDHH25(?+NZ`Ut-hsMMLmof{)@cbCo@sjEOp8b?bu( z%hT_3eFtT--)iW1t>-Ag?&(C9B)oAgT3`qGBQD+E%{c;&;ZoNEQU8#kOt$1?# zGXI~(-ZC!A=6f7oVgW%)QkM_}N$GA01pz^F5rG8+L>i=7U{R5fzNNz;B&A#$7Kx>i zUZhrur5hH>|ApT7_xHSf=5xK9YfjIZGiQpfR(f)J%Y_kMfYX^1IrxQe-cvJFV!0+; zLl>K+M5YrE{wfdNf}Un~?rtISRXj4dzwNqk)-X^(aw;!_Hwq1ruJqEMh1o+DT|9Xd z1ZZg!SYyS+HMmeh>#;*QB}OM;d2^YcGW#>k_76%|!w z;!`?XnicI^!z|>T=jeE{S2It{PuGy56pa5!Hr$$3hAF*&{;nphC1;Lfuq<}14wf+?c9SmA92G(lpzflARmdqc6^W)PPbmUJT%Ik? zyS0<=eC_+lV7{PZUy}k?E_{mAstSqQb09R|ErJuhE zI@nVn7J7%7Q+A@L^=$&*p1UF*StzLBOLW+B)QbuHD4aZW!c{md|9Q$s{E$000*Di@ zfyFfzt_hkij$k^VZvy;!{&{qlS!o4J`EeO?mqwv(tWKT(s$P4YK&K#7r1lfLcn1zRa^21Te+QI5Go(xNYhkHz%-6xKbE&?Yl|k}a zzBoVI(rzHw-~|a|D%K`HV#iAb=G^) z78W-Gk$$L?2EQ?z!>0J6A3Ytfm^rnDX;#5be7RYV^Zg!jRMptB+UBtbTr43>NQ63Yqw{)~wZV~zQS^^q`!;{0 zGkV3vgcOPCHrOT|aZe2#PZmi#61h;oj|ENf@L0U4-V4@djr7GN`=v|`&W@^Awb*!V zWkW7bsTjAN`$ML& z*SyB#EgsZ)D_Ti>a3i?O-d&9Vf42j&B`pt4+doI>h?{ZzM2n#d^<(!5-w>JF?mayR z_1>WCCa>)RS(30l>+tc0-dhq!QSQLiDo`_#7^9oY9fUz4pv~tlZw!*`W2jhj zkadh_@$RkQv#?t&o~2Wcalt5>i%zPCkM^}TXq)%#rNxo^p37< zN8N(5HSd1E`92+Q+LSpGplGuEMcAEnTVN?)S?A;xihp}A&2I-jEqlU=bU7u-TMXpU zQwT)*b|W~vYs7_FZ9b`nb;@h%qg1+f3ap`~3x09I-LGU1K)1P_D9CCNFSF`|6XQ3nnRdT^)Bhj+hcQ zbhRWsELmT*whC=Wy09t*H8Jg?q|a8FtoD8)3&I}RUSOY;i_N!<{S)pcF5OgN9Qf#_ zp-<4u&=6Q_VU_+(!`+NnyT=1yDx%~XYj&qlh>ZVuVtcsn*1qseNKp0hqKC7YZ`7Ld zekm4P#B;qqrR`+Z{rqj?>uFVHh|I%1r2x{cSzV)n#(`G(1mEJU=vl2zpJm&xdZ&By zn2WJ_#1zEYO7YAdc-m!rd3Mg?pQ_b(`{Q8WpgorMSp*L13OFrW%^MK!A-Ff%?CTnr4DZ14Z-aNPgcLnQP6K@IWVRC z>3Dk5HvH@aK2Fx(l@1d!5{Rzm5G3olxcGIOZlKofz6~1=Wjpf~Bj2#knDy3CO?H{)95i?Vkbg5=3nt+ZOQg4d|hc7qAWe@lL8WKs0$ zEqCAfN;f@wU-=r#(TY88^zG$Z0&z=6*!D&4(0BayTLA;&)||+X6cxYRYusv*j3#{n zrEOwSdO37hQV@6Wn08=z^p_6G*?ISi?l16&42K1KsilXqi*(kWuEe%G38lMAgyZt3 zCsZ|}31mfU=~s^A2EntxJxSMC&f$6@18p5c^A}J0Y^7Nyhg+Eka%N}lJC{VcT~HkP z)2(f3sPzF+iCosDHBF?1nun&y+2XW|it@2%{gZPi$tiAT29xch&;bj1;GUW4&W%q` zJqO>HZC(q*5;szNZ2nZgy*D!y&DfOa;)SpE=nh_7%!$N0QBid+fdVJn-r3%ZJCAX) zBl$HykESlwzU_cL}L#dZvQhzrCGboe^{ znlMIbK;JJ_mIc8Q*Z|kqf)IvzO?ua-bjAt8rPDH(8kNBqRt&iUv;PHJ`sC2UuV=cB zz1{srmYM-dT*jARHiTNBon-c+TehaJ?e$@Ci2M4t*JzM}nDw_vB{Ig2hCtuGFfb({ z&+E*=$5TF9#$$4g?5VhwK=$y4IE(7#QdRbrj7+`O@FyX2lx)T^csj(}y%KMNwMK_K zQof6i?|*l;hZ)IlKj=Z83M|$f8~}zKzWL5GN1MBFY<9V6We+qvlw%o_Cykqc~tL(&{x#K^~ z-~M%0+f^}i_fB`>(HTyWBj!RlHrg!*JpShHHUnV_#}8z}RfxH`guJQ!`CD_y%vbVS zX7Uy-SC!o zHf<;f%O{Nc&TC8xn*+h54dT9G&Je3XNdF7v@@p~#&{zHP!R#?_PTjtI9dx?B zmLEN9KiWYp*}AZZxNNNHYfgD%a7Fok>)t`dlySm9)aS|%;u@BxY!eeudSe&zBAuI# zXP~XFJ44!a-D_PDALQOzSzYv8bNMXYS)|G%u<=W0op#T2r<@|)yx6yy8Pp2mK)7>D z>6y8)aU@=nZJ>DXd{^miJlUt^JsG?J?o2oqTD!eY0(blf`aVqekokJP0X2~wTXTJ$ zUe3v}%S`}^~76dh$z-#L`2o26dwF@(#8XI0vTxghThnH= zEP)GQV7$r*E&3scka_LoB8?2#7^hi6Bs zzSv0o{HIbOG9*m}!N(uv5{+-_R$8nzPMWWrS`FBz5SfQ=N&m1g>B=J2$+s5qV#hv$(IxvIi2=%ow@oFcHLydM?&S>NpvXr*7QW@Ku*a0>BAM$+q!a!3>yB$pL`Ne$~lRt z`bl{c*Zg2g7W7?jS>NCXV@nIWvzd?}2jRk!%zvhM2W1x~(df7fRSV9FlBO))g&-5n zsZO@SBDs#hkY@aOdIbeju>1K&E6xz4XXGoMF_BHx_{sq+^w~=t!YcGOb1HOC$@znu z^*8u+rhV&PWPk0j%l@62o@w@{Fa4uGnzEM>2WM4j86r@mr`q_rWvlv&bOmZJNya{f ztYerxyP)~SeE$nKv4aa?1rzU+yCu(tKJ_bp@!{q2_{AwWweJLVrxCQ>r;xB1b){mI zIN_8U=9)Smt%Yv}9@Y9;ytJk7qxtq|_?IP>zoN}kg&uU&nh{n0)=-uCYMwQ}pu4N>aeba|G*L4|1Wm?cTJt9`?g z7_WS9*AX%{S=lR-d2V)m`CJmU=NuBG)7o79>{J%UeVEP?ZpYXRo+i(XG)`?Hrs|e5JaL*%e3R444w|}ee`QY%ccz6QwL8JG4%RHack_zd z89v&{+v?au)v4RS=VcX@YZEEM;8r)3gZl%&vt!cbM|WQ$XTNlY@mef49r=g=I2M4! z0&ZRG{^)3s6ENnr4V-+zo>>GsPku}6={Z4MPJ-OU+i@97103Z@ML6$K(0C7Wf%s;! ziSY(ofE8uq_3^Q+pzmSeuP(u-o8C(OKO(?43{_kxT&8Tmhm(Qs6dSvgZUaA}?9Smt zknxkYBc#*IqtYa}5Vb8qf6#--IXVfJ@yxNKBi_7VCG^2U3Y~cGJ)_49kglfQ_V5`K<>{vPXAp>db?Jhkt~FcA|1yDd40}$nGbt)8N7^m z!eo3}$EQ0qY8aE>jmc~&Z)TpjiY5J?Lbng*{O^qb#ybIMgq4EFFMOs~%ZpiQ`9_yH zjcDYZ!jdPX|De4B?9-iE084_uznC#BNS5{>m>uqLyx%);l2%hxqA7eJBqi*g;(;wJ z{7tc)lJ|x+xo5qySB6Q$fj}C7ar!eAOc6|*DJ)!Y+jQU%(b9?Dms;1J^mP75ReQ^t`jp$!0Q&P&RcJ;z zY+Lxo*M8ixU&c@W@wphVIO*bkRXpw;1HlwKp0bL&>O^?Kn>Y6kv}L3A&4bkzO_#O# zXkelo@qY0(XC+YpYlgTN-o`h#6gbr-iLfv#QTUj@RH?>v=ka_c)6IbcKA5RAL3i-k z3Hyv+M{sSCwI;kQb)2zn?Sk{MY6?Jo3%>Q(0 zO2dNN29NfAsY%th(?n~gcYl$>3riY303-fK6+hWOP+)f7W-Dhv1SG=*NoGNQmvZ8h za<1cx0}WcYmakRx)g9XZ_O6yi(L$Hzr%kE{P1ckuhR$w1lQYEM78JE@z(W}IgI*rD z$9O|EJj#VVwou{sr4{b=+utC$W(69E2=T!4gTE8m%44635x7MEwPuX>9&SfM{26=Rq(gI zT>gfAxO}!4&7*rf@X*^^xI{<*l8UKZ)It56CPh0M;^KGvGwy5Lb?2M?(jLYTGqd?~ zN}FGxrKwIY$LZK@T1Mf;CZ{v6&r9+yAXp}MY(S5fwh-Tzkx?{HYvNNp3L;N7^SKtk znG2tb0Kc(+ferpb5F7=*D(~6i!T{ToVZRbYD)82e!Gxwj(knju4a4>^gVfXC)+L_! zJj`iyOkA87LT^c-Qw`&!z>pfrpxM(;->9%TL4i5xjUC#!NKs-_elt`4h$hflZP;rD zbjn;Db}p3ccrtn9!QK`&?gF<2)u0DgrZ98 zKr=xe1Y|TICLH@*g6_9C4@f{?2u%$_*p`g|x|E~v4!@>(%8Q!K5lkMNdVv2v?Or7I z1g1NQs3f7NfrGmubTamTW;6`iamv9ksL7#tW<~^_0cEQ`gufEjTk-7%cADGv`Sakb zud@apkNE7gM*{nWlci1wWqgN$5!3&*Qm{0zv!fps&bsv)Tu@0U=(UAL`8lWhaVSNB z{e3#c_ReF#PA6YIPXpQ!i<&OPN& z|IqqGmj4Sny!WLYzm$wpIc)Mb^gD9LmWm|5<79@i7ZpTELBG^I2f!DGuzlJt@asOy ztWXBF`|CSH4?0j=^WFrE%b8)uv2&EYqtjtcWzyDTtJ2b|4$U}8x(w55k5EtGIKz6A z16nbN{bbz-I=yslb}&iZ)jP()C?R+h)Q<1;xth!!XbQji#nqZc)@$Xq*9Yo>DG zNjz>&DLpGzM(1T(AkP02WI9!x3~93hdGmpRIyVrbLI4HD3x8M+;h`*f?bSebr3hV0 zP8Ym_l*T~p(!=#89w5a9tVq6)WTY1m_PL)s7TX#2J%`WdzIwgroBpAiYrPR`hxC1d z>8;S)TdIO1K}3uZ`?9@{?yMJI{rs(RPYiQ0@#SNJeyJp3?<*b2`VjiVn%eqe z`B5-^9}pbS((--Rcb1tsShgwVVJ2@>g^Lod zxfKizvEebeYK$o#n?MM^uL}#LAl2zuVhN_sNUFGzF)s%BeAQ7Y^*Uk5#%e4uZ~{fM zmx|PqaP}@kRdgP4>Px$x0d#nGlqQ-vs$VySfDIgb$JIACiIq~}E%?^OTe}7aFpx&S zj!}q#6z0f_+nj_hDO!v<{^5m|Pe*o}bp6)`32YEp`Z1NI5`gY1Z69#rHJ;x05pk#R z$!?%yjuVsgxW>_Z`Ghh#~i!osk_(0C(Ku@_d`P6Z1*IKBJ`~vR9x+Kvu^EuhgmyTGI@9E zEHP?z30R*I5%Hq&C$K?R&5On7?uD4U^tLeeF1FvsyNr%2ln9|`vj>Z9TVk?!36@(T z@P#q_)Odu2&wIuJ09fI8kRCivGWKjf~2A_*(6o~oznNB$QwS#0rDkASwb1{Z+L)5fag|5-F=#%%=m@84f!PW=CTuH*Eq?c#q?C8FPnr3gV`6*D$MS-j zu^rAP@6a4Ika5|C3~mDJN4XdhYow${m_MvZ*LoUMFQa-qHIQCIBpLLuzKO z&5<&y=yoXM+l0zaY}-^w7pJK@D_3_(z4B3Bbm0&Y4M(b=45l^^d_^KB8HW zS0yN+W>T2f#N9T~lKuKOHbGP!xZ(XEiE34iQ-$;An)yY_8E zH!Y^iA~dN-nfz#q_Z2IFU;mZ_%U@SZ;yaBcN|*&X6ZNjUlbSqrm;-$2-yW+TkVaQd zj-rOO-P2It)dG1{ME!ijPzR(h{}QIndR36flJHR2)l@wsOPpKYPLhYe4Q0ORt)Rh~PDoZs{Gyl>|o1jWbvPm*a%74kn$`gkV zD!^{KKV{#Y8}${+5r1*#5~|lJ4aL*o1`O+e4OhtKz^YjCn`R5m5y1U2qUpB`|7FBS zB?l}8oN6Vy#OK&T0jwA>txi1kV|#{{?U20M`BeDb&a*M;?Pg1)Y2`CLYiFg zi&Od{X?Ep*Z8iEIf{-@;+aY;G_zcSOKBxSCIYH(mZ@b3+62?Od%G1xl-P94rp_brL zLUc{h1mz-0q^skHjfbcckEylvNmFFp6=%(zr&z0<`eH=0%QBBjDEQ@SXbvGMC~wF1 zl*#@6fR~od-MB%iALzxMV>-ypg|A?_1dAV!>t4t0V-bR0LFZmCnHv=PXY>@|8oe?G^ML; zVsZD7yA{pMUjp-un_QP^VB%6N${FC4K|!qSWA?X>>xq7F$wNHv=(^v@7o1rRitxe4 zl}=C)hwB~{V`le_S7$S^&(-FDT`^m}DN?R;hHx+iqa|go=jOyt)mih4(}fB1IQG9P zURi98vU@g=w{iWUS?QHdiNy}T20ffv2&29s%63Bse$Q9~0hc9){5p=YKh$fS^Q}M` znZFdJg0j^74nmwMfXE#EpRFd0lG>&x3Nw#Dy{9)jGf&Fe2p_l{4Ep8RZD8)}{R*Y1 zaIW8*R007)IDiwgDmQH$U7}y1VNK`&Hpp~%Gq|%zg)Fr^OO+i>U;{nut=ddKI^0)S z(?eHc9t%ioE>K{ECdPm>Azav7x+ND>$zKm1K=9P#HFKTHAyp`sLDV_*pv#AuHq2TA zpZi4&oG9bVwm8)12fZLhqKfrIr@Bf{QA=4c{@@nY38lxo-c&g65GePrCe#Be;Gwt* z*$FDgd8PE;+~-2fRRYP}Ute#Cw|2rbvwv1CX=Zq5*?|P%SCu5mIO*I7;cCktLQ@B8d&k&VL?V z9KUtWx3KMD#sdIod-Aelb3LMnSZ^_TxFQ;GGV&&-E=|5-DeY z+T^r@wTHpey1LV*QFd}9r~u@kh=PP`jT^#6{+lN7#@7_4!b^y8)LEESS$AY-q%qs) zKRcW|Ajy{WCSl zthfo+!FDI-5Nt^K^UlGViZ~Dt=;F2Am|aua z-U)-Vl}1C=%qy^ItgFq8EXIBIDdY$8bu`|K$ET5nKw&cWO!7WjPmxvGWg_d3O8#i& z5!EPc%t<+?K-a0VDV?Gdl&O10)2SytQYIkYn{KFSZx#wpzfI)Zv3CB7LDaEW788VE zvYoW&MhT%V+A4{+NRK6};M!?+4A63$C)o$S?Ne43u$B+-G`qIY6ohHHKQ$@g%L?qs z?Hl&148ur$wQ`O&^9q0aDK+%q;mPn$(p;?je~NigMC^WDYF%vR*~~p;j^3TQ;U^;Y z#8SCCl)G`DXR8%Il4RexwbUTLHy7d#H|&p@t=n932!r*`g1k1oWwssGC5ypQFth5p z)-Z8h**kg{yBzrdr>FIWVcZEg!r{F?I>*mp{E(5ELMQx8&%i<=QsZM z4YMk(tQwEXhAZj+DHBv(tY^IY`^I5ue_3>l1n!GVjz)-X9e-f3@!C zzC7zgGim!;Tnd*~B9|i+Lw>|P`T6T0E>nX)`2kkoDfbc)sxN3>Gx4&%5K1^1@qz3~ zcfPMda`?-$P;?jh@m_b7E>H)2F(N!k3@XxuUu7Kq&Jy`BSNN3v;d_ zKRG(B1=JqjB6vt_Ns?T8VfnYxJOWRsM=(efxR9w4z!OMBO{nNG8VLPqo2z@owN38MBXS!j_@k1A{FHsNK2^CrrtmN5 zQR*#HOHP60{H08dTXW4Q!b)$^5M89`yML?QrU>E^b@4MiIKdlfK18krobJ?(;QNim>|~{VXp=O5ujRdy&7HlT-h~zCm~&B!D;xy|U$Qx$(XIQQ8z!sy6aA zpsYv#F+QAZZ;Ca8iI$JtV`EoCQvG66yZ*rL7U&IOP13tmJkfpJe|XHRT|!^0kh*VY z#F~OGbWLo|t`uBz(|R77gy8AQPZ|VMbxZygW@7cM3GmjUH!5;14o$XU3zkuAQ~Y|bl@NUFIEy;MtAwi%|*pVuY}3_ zCQ-(ViAHClU?3kAUh+PhnuXM8A@!2qVMg8sR+U7FkGdpE;7o!(t_;uSis4F75W^9^ zb$0tTQ#~Z$`M9oT;SCL#Gw(jP7TG(GvwIR8x&g!bP@?$uayjmj!Xn-mCFvqR7tJ{K zuO6P?>N0uyNkorh3gaNVEsnkMp1TElNfq*Ga#~{Uhe{@QId?++s&nXWK6-+11i>Wj zjbOHg4kIfIIU}o7pFZYt2@_$(@DbmzdAdGTCMzOZ#{Hev)=%on&Wh$Ri<&b>uAb=^ zi-u>wu}UZDlOJv90TizLL0M(swi_O2_Vs#Qb<$Vfwzke;*pRoA!F z_WPMeL2~5%4<&~EcsX>!Q?Df|*^~@Ou0Y6%4LFSn#`8sI^~mtAn3tq)#S(tnXznKOz3Eaju)Jy69pl?4 zK&)yvJ9*4~&Gx;piZPdvw$1JubFJNvc8`#&9RF0(WRjl}%iQqu1}WDtnIV2(e@}2k zHyMGkA}o%|d~~Uns2(xHM2Q7P;aEuqTlu&vuaa)DuyIgM4q$%fFaiBJ!oZPzKZ2)| zjG$M; zww7+0b+qaa#7whGh)ciU383*MYYiea1Dp`8+PrtEZVbFMTB$LH0gZj$h7QkQPcEpW=nIISUtKlc*-I|}7z4-%t3=9TVEGyl@1c}_IsxOkRQa)IN@wm`lwE8A=dodbQ{ z4~ZGF#M*NA@LVd|uFY{NG52nyX!z10gECcn(hl6N>W)QYs&ICILC|qGkMzL}#?XJ9 zH~OTvUa@sO800~i<>_8ZP3!lrS^<}%elpTKNLqd1Hu3!vYE^S5fiKPV$;LA?@GoWN z6Tmap1M*Ho^Km7F_Y&T{^Hz~8mz?ZWF)zJn4mh(lMzK`R^l<~Q9MvlU4Y(kekYyB{ zJHN0eS``PK%uEvq`a;pU6brORP3~{G);Dqq@e@mTO&F9E;~odA-T- z{LUQ-$ynS`K_Cme;ZLefBk0_)Qtu1#4C0`)S7 zU2XmgACy~yTM(Hi&f4N=HgA~_|IbFLdo}RCRQ!RthQ`*_2l`K`MpqmLt>?}T9o9-~?Bf*iHapQ9qj7H7skz!zJ7I-E zFjGjEbPv#eZN-$<#If89az zNJ)v=F6l5To-+&Iu~Nc%F`b^Xfv6M~Ub@Np4li`;WGFT94z93vKp7$pAB5bxgvsy5 zJ%zfPD6z}Mah;XpH8jB?_Q#KU%GiVb5?feXBL zIS5x%i^w#WeopUX@@46rq>~h{glXCGjTeW(5w8}0f2jQvw7nBANYhR{E)CnZnY}*S zP0Rk9_jR)p+v6iFN!%HBRbX;!%Qx@)gf!NR`uzI`6lA2|YGiEk?p|U?NAL|u1jqip z;YIG2zo2A+0mz`GG)-pnip`S@-&oz>tKf^CLwOzGg(?THEk)m|qJ|6x3yafV^*J5~ zizy!G8YzuR~&WS#80jY}J!Eq@YDljZkyM$<_(`aX?^N#oj>Q z@1D9RdoM2*&Xt8g*rUO0RNh?O^D3*Cx>xiyi;^M@(J_!j*$qGsiAH6Adie10_zoXg zOGNA@`!(9*o2S+RwrAlkWtZmUVtsm(U+YFZ>+RSJ-5Y8Y?Gjsp=3$_B2tTb^*~=da z|GEIKSNb<2nN;0hgcO1UY{~F|d%Uonef0nNqr_45jFMpK?sC6;Zv+E}`f)^en*aSv z@#lJ40};%PavD{^T;r<93JC8)mIGImy3N%BJvWvHnJvLTv{0#E>EdO4WF(<&`FJe#RrVSu3vK0fT=QUKG#MQ6 zT}wyrS^B7m@?QsRG;kWvr^R2tgp8fHS@=PtN-6We>l5MY)XpfH#5ohZQD*aukFDHp z>?Jc=e~0*M+Vb)>aqu8{#C+w@o8)x2M3QgfjuAMW9GUaj#uH_eWNDNbR6j?FlHBZ; zH{E${8DUJ!#&!>UD(vS z+=xC%+&i8%DiGs& z^_PrCqPZIB4SrmyevR4_jp=v%>})3L(O2a<{m0Az$p1e+N6c|ZQ@w93$G*=!5Ky!< L9;%nA!ovO^)z--C diff --git a/openssl-install/share/doc/openssl/html/man7/img/kdf.png b/openssl-install/share/doc/openssl/html/man7/img/kdf.png deleted file mode 100644 index 144e398a218c1d8e22bde3fe25dde450c5df7c2a..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 22285 zcmcfpWmH?w7d8wB0;IURYjG{^?(S|Wl;ZB*LeK)mwLmGQxH|;57D_0A;!bgQd-D6= z@4MFh_4)FwK@R{xl0+O?uh0-@`lw=w z5g%xF>dFd$m;YX0y30QU0CWIV1zCfD{KJC45QEvjx4pY7s`JA53NmkX|Gc-vQ@m|o zi!wJd2$*f*HmqeOx+OZ$ZA)RO2;`&8hhcOfvog!TV=`!H#IL;a^wWzpWS zn9SWBE26dR1}|;x6Ct|?*i_V;&}QYPkS?sbKkZ+v55&4p)s4od`F@8vqZL(IioeS9 zZW6pUhtk{N0tHb1{Z03(YR*ft&8T;%a1WRuTe{nJtQ?am1IX@u04lcD6VQ zFU{2NfbD-OBv8{(Eg)?HwA9Ci*X~HB$h?p+9oqS>X?xrY4|ZIGgHG4_%+2qqi4^e- z_LyzA$1|4qy@Cr}6D3DtD`c1qRO2VAK3uNMDo2>>-wIyGu1nBn$J{&pvH7P#D z!%TI{NJq|_1s_D=FU5k_c3(T+BMA@K1)3b#eDBMa?&$HJlM23k5*grUQ;Su|u!5Fb zyHTu@2V=uudIX1s@y44p(E0wvH#^a^vPjr(MIg~Sm@z5tserp-5C0N=0p;9|xJbNv zKGqexcGPl>{ILz46WjUJ-hSL1e6`oeH$%XtrcCFYQP>QxGI^ObaBe5p5U!(E_&a2) zK@DHE^9T zVg>!cI-!w%K*;XL?E|5mxBn9YC&3;9mSfZt`Mj||)RE)LI%!%&j|uivoAkJC2Ii0` z=`K*3PIp^AZ^twy@_kBERHKQ?q0tfXT65EOFe6cP;_(S8YdxI6-lQJk>?dHr>~ZHr z+cf{~ok%Y2BC|Rt!1bx52_)7`aJyAmd%sW@3Ywq+hZ!j<@uE%LS1md8uS&gJgSzu0 z#K5_e%gdFG;dO8q&F&~x%@tcfZ<%}J~b_5fZs9w8%3YIeq{%?ouizi3IdJQp*({bd= z^@A|0v2Amr!1Qi}HN8P%MWG!f%NfLnYic*?AF{|mK#1!8CP$NkXn!8gAPYz zAF$RByJiA*t6z{$$IiExE-Uqt#omQWSvSWg^m^lz-q5P9ppP(fa&%`)6}ioO$mC)g zrsK#X#y7m+DP!3&QQ-I2fV=Aw#2K~=WXYFErBr*tjriMJI55jR2duj+)xHflQtG(* z*N591j$}Re=kzk+#i6gC^e*Iz{lAF;jI}%SgI`XA;kD)?Glm%&dC%S*z9*B-z4h9WD`=Z zI;ka1>I;r)mn1extE+u&dw+r~JN@3S(FA)Of0di;z192g;BEuIkDfD-XvK>tt9^;> zT?)q4Ha7ZQ<~&z0@^E#63x$N*XqUE?puHm1k`fzi<+#UYS zzesB7YEhI*c!$@mz%u6KL3PUdVu;kjXA7p zTe$bg-aahsUfw8!FoHf(>a~+yF6QgO8IL~_u@B}vH>Q=n;N;~xK5%f4cd>?>NcWeN zX=R$BCRz)%o8#pik8_1EkGl+shd;V1u(o}qPy=bpFOx4R9 zF9E!hv|R6EGDJ87;2!?}(=&`MqwwVRM!eupyes;!&6CHmd`_mkF28EILD0kXNiWRo z8EkGVW)?e?Ew*<3bbZ*&JyXJ}#wJrw7>$Gy)|_uM?A_}? zP|X?F41M>7hd2|OGq3UCZ28pi|GBLH&|THMv*}C8jx|{!qxEfj?A7oea%WmvDUVif z0j~J}jAC^e$R@GA-O`J@4qijY@f7@R^8Ohlo;c^>hoU&fAl3{6&R1#|B?%3xnh2SE zR+N&m-{-x?90?%ACF8a6{x+nWel1sS9E6v+Berse2Dj13t1d|8!}1+om`&c*Ad~V~ z%hgCIWj%_k(g^}Eg0OCX_lb|+KgVWIF3vXN31z>;bmy1GVDCSue%nUeO9{>@8DR@V z3(?)Z-HcR5O4yTN>?BboJ+h%W)N4HwNgB~lAN1LuUW~Z~9~qNIJVj?{2v7%s=P33Q zwW~ebz_$_0&zVkvL}ikn4KuAc2SC>k>hsN|Rn3Nd+_im}3$JNxsEbCZMi#Y+3rpT; z!Oeo|Lmszd;)b*HLY;91lF#belB_dCu>wde5>4%F?oW}PtVWwO;$gZvWu!LMg0!_S z>{GXo7z68M`*lZ^i_XQ|CUp;j_U&%BG*3li|4B~klx0P1AI#D2-5%p|<;Pxmds5*# z3uL?%!)i0>r2ZM5%;%3yIe(IbHCDn(O=B2@eL5Y3-A%o^B?`}Xt#<@iRu{t|sPkqw zlW0Z`+;F!65yQ2qqvJVA(RaVUa8(TdaAx z9DpZMhu)C+n)RR_ZC{c_gr;{D)Plqjxf`)3bEC8$w>q9j=l`Kc)-oY73Cd!F??H3w zy5=Zji{Y!>(#!N$n&rE@T$H`Cu)Le%-W!A>u&@9a4wRKMg@+tt1md?}<5%PN^W~cz$IF&8cDfubAS2!Aq7Zt`MjqYG8V3&a> z8Yz;h6LfBfy4^M!`ob#Wh;@ovGXB`r7Q}!7}DbvPJlm`N~6ha7l-ZwmJxTlJ+X8>^S&DTo+JJ2+2MMe_v8o&9KJ~M2n z@DEfJ?UuNceF&^pD{dF4Jc?>XcTYf$T%}Ys{;fgUL*SHo1I{Xcyu1tDYV$6q%Y4BZ zjF;q??~S^zi3qJ&{bfa%PulqccR&n7vxKiqm@FX9GJ^&>3t@;mS=m7@XAzN3MQ%rS zI^_Area`*X64iiic{b*q#$EyO=y_0DkW9yRc(IdOtu$BjPgjHP0}h& zl>Qk~s6aeh6xoUwZmTE&u9go02h+jjYrGTcQ<;GKm|!if936T<9Asp}ZbZh^W*KfX8Fr2blV z1mK?%0xcu`Wjw!(-)n+C&Amek{S@W3n>x?4h-Vo+HGdqom4ihuwMMaq2G()rwdIy_|g~)|56@RBt#s7AC?Xk?WLC`?k`!t_kI7lUkwuOI%;VuzJF(7fkLWt7OGR zaBhce%6RkseH{5SK+f4loVDKgvoh7@IdIh%p+ohz|D=ZOwX=s6#+O?t>ttSq=D@gy+MROSRa?jXkOH`&Ahi$4$ z#60j_`~P+}-G}P{y^8_K%&G{iFZ>)%()hDB{$J}_ipVEv;q^K)~{i0y>E#5f57S?#1RKog8p|iDmAeu>w z$tk5-pBN!P+#N~HWJOS~jJB;ur066#j{jn*us&O&F3TPdixbVWls7)-XHP|pg9Ao< z8}q%t63I*8zwcrx)A25#LYa;>UnrvrsWDL<5Y6D6z|9mlR>dkH8kHyF=C zD*k?$1VwX%BIIWmvjA%#;t5BDlK360p8J<*IH=daYg8q)MH?G`y7HWDIPyW{Ec874 z2)Nb@vDVQ|e^ac+!^iC*0%MkBn7>vG`C^V&cIkQAPM~Xc05NmRi}HFOIgoPOg&W5{ z90nnv{=oWkIkFqV4oj609%O&S3!qj7pCZ@2nXhG46F`JyZ{5GV+KZxz_0gR}PQWiC z{A(msZxMZanLEy_a7Kfah?cC7zNw^eCkgtg%&CCTY5F|qmRu*vMBAF4vBnqxdaF~T zK(>a*r0axgryB(AjVuDl3%t%PVLc)zt>2+hlv5R=t0=_yXX5E&iI;Pt#HojS3*sfG z{-Q^OnsXsWeM_Z_r;R-1gM*risUe$Qh#P{YA^#YKhH#2P6-L)QthZiY(q2RZ>zNod5+_|Lj% zNH>hjE4vZv9ZXz)Qf$CKW@kSY3K8$xoFu1_KdxIe2{spAJy{!+Q8 zSpp^EVa0o>kD#2Q4#$|cdyvDVF3#tqm}XYB&Jmt#G*d#OgCz4A42QMG)mXapt zu=pwwA(ojaALL}&Z(Ej`PO?Obsy|y(d^G1A%u-r*n!CF2XHiibe_&!rg_pGjm{24X ze*AF%eYVQyz1Thld1His%J1~5e&HRQs)FR^y=&WNf}F;O$~Re+tVi+5-!E}cFj8Y@ zCh9m{C+C0skXVZ`V(lOa%*l@i#~P(;sVW-;88gtcXXKDD>66*RTlA*Gfl`X0!D_F+ zF@7@?qs~!Z$afh;53H{92w%P7LF4u~*vGk$E2g#o`IbyS;Y6FV)244}v^@b6k(qssXh*~O+5Y1rv5KBvonOyx$BgCb3+uOBo)IHM?4b5KkJZsI=byEoYO3-J zt9};v?rbOBtUK8Me76RqEp#ulHNsUb$&JM#VpA(GEj0}S(Zz4?`H<{CJa?;HuSc%u z=Ua=^JhXL&KB!b##_-*6=JV2{oW2ixR)jB1NREh32s*ri_c&LDUS>o^O>b>cAxQu~ zc!#{e&WMR8yyT0+Mm18eYWNrd!^Q@j0}CAW*Q8Ga>*Uy(=v`jJV1~P9XpSOm%LL#>Wc}OWass z6Li8`)u#%B{~Hu|O=&K>Vv~bCGpVA=;zVpRBVyC+p|SpA$F*)a9l5w}GathvAn=aG z{%8PtY`gktl7!FU(5*+>akjVkC<*mUZ=hTr#Xg@m#?i5$GSiIcI$kmn15n7m=aCLz%><53rJax?CB~_I;4N`jb37UNt!-O=RkK{`bB= zw~75pq(`nl(kCVX#lN-4K**q`xbI>$}|Hn^2S&{QackBSIxwAToW^J5%4VXE`Rxhx5{+p!dXeKg6V8G^@G+ z=s(bG%o*RtRCoVErL~`IEGrYvg~5UnLOKhD0jgvvTGt9zG0rfHnvy0=vD~s7Gy)?} z7ctDIf0r|zCOP34h5k{fjav{#FHQ}Bhs4PsdIHH&U5|Ap@=5J=hu<=odN*+7 zf_)?Y5z`}?=U@ieW_^l;yKf;dHS{&7SyOj0|A?_+bqjn2m8vOVEDc0LN_=!>X0`Il zh9IK(`tN>MS5f(e6&+^590OZ9!UIiDr>_JtVLy`Zar%@VNCERPY!U;%c6?bYUs>zp zu|3+dSzS)JxCjrqj6(Is(iqC#hBUqi0?Vndwm$O=XU;XZTze)4-v2|zd?x(s=;cMz zFw7~kKlb{-R3|Cp&h+Nk*zTvx8qq=E$^CFTg*^$fdJ><&61DiT+HN;MOTOPlsJz`m zQ8#yNcJx)L!=t8jCu203^kfrVe2Kzd5^J|JKbOjDFbTiOAAy-D)_A?5oKczKH4RKy z92r^&_9Mf97i)Z4#4!}4^1H_2!BrHe4v*aQIM>z`VIcbh=&&@Vn&=854pQ+Kr*lXY zbkk$*tijmEmR%ip7EwzBv|uwlMP0p35^!~5BcdnJR`BQo*-O^{>?<|!kp$hWhaF+l znQ9a{yWpe!RS2&>gBm~;2sx3R^KgY&L4gqICc%qyws;uErA%6Qjgo`FQsRe(E=;OI z+4cnv`^dK{{E;&PoCq{Y^9w02wyMl2wud+`lZX%zdhdK>RVJK+5V=L*9@!i3WqC%$ zN)8cX03=gR<26UC5_3lXR0L3cJ!nCyN1g&Lq3rtl$w7x8Z(D_K%{M8C%Yb-ta_l{T z_YnkodBL6H9>N>F_kgyD2D#v{-EDHpY0H!fY@u`i(-`H3EK5L zCGye;Y0%q{L?$k>Y;L4Q{NRpFo*KWNf*V1}`#FYaF-Cr_^pd963*N@NDucL!H~~c2 zNSyArIRmM6nHQ<}D}gG8zV6r`6KDI>E z?fwp<<%`)fGcxSMRj1B3HpGEPhCsQVTD>6DGR3h-u>E%(ko`i`s9?7|j0 zw17Q)T3+Y;3?*bP`gRwL@bkVl09f~8F8W9sy33|6b*DR5 z@o;Ks|4XGVZot>&3xE-Bou#YI>mQ%xMI8@A8v6>PL|($B`lJ!ii&`(YAij*R?gFmE zrvK4~MpsO~oLb>YU(z>i&8X%f&L0eBOe+&9;WcI?c{>=t1lN;YF3E9>F#Y{64vjVe zxFf#uNRHduWTogd1y4i zym8QzP;^o^)8F$&ItGR%Y0!&*dXuQa{%hc+<5;NbjsU&6!n>~gbTDylAnaYqZfsb# z(;ZP+sQ})sa2oP{A|lp9X&ZXG+woE0K<=Y}_CynBJS=A(g#N|~jVjyLG(E_KkUd|J zZ$^(*&CxC#%+e?Rr^xaPYdmc4mL#oui};OgSqW=F{!>a|@k@#QR|h=`dpRdazg{yu zLrYmq$^Awa##^m`#?_-LpQ9Foeue%d29}%h401ZrK!m1yU(3|og~7hnNl+&Rfp}Kx z{JN1}B=_y@qT%C+k)&yvHOQG5gP#v&)|i;8(_p5zr$u?oy05z;*U@$(2#pqSNw|MC zsl=zLVx|2EVdRe}_R&L3!`(Mwyyu(E&guX9_|m?-SVZUiCLg;iPs$U4Be&H|VPSGu zj4T0#W>g)CnHlpVIOi{BG%!n=utiaO#b8|Qn4OA^lT-gGLoauKh7ywaM=F}VyQ=TS zV}17+>GfrkjsQ$ZG6Agi|43L=@XM+kvK%-0xBK>i_>-fYzM35&M*r zbP}r7-c|p6+IGdpok-V9@t_*=!+>jAmL69!@iC5GH^)Vf1P4oGq2?CbBlW@wmmSM2 zJ;bSr@%qjdZ1=FSzj6D5I3s4g#Vxk*=qG6ZOb>0(=W!UKYkk^*klL=VPOhbGO||y& zS!DL#Y>s*&qMOzECMCI7%xw<}9Zsd8*>@Gh?`Q#y6P%PIUSLbbu{52tpXl)1k5|ce ziItU{fz7I3t@K*9f46%G!yxA{P1Px*Ms?Z)4t6p~mBD=LV-wnkD zw!5LlFve+5pRQ z)`s6?C|hp(s@GLD!h5#1#l#n5gnI`MmvC@93uzZXha7+IC7+f~-%WX5x5_ShBuWp9 z|E!!7>dNhSsNbF>?$qBWKr%PxE}BW?A3T3(hl1XzFp7miEL)lJy;?SBQ1Pfxqj!UHeVC$H@mVq(2hc4LEsn%5;0&w69| z1kv0)3x0RDe|DhG|57-6b*wtS{L8FnK&aaF1IsU(-G$%b)B^?~VVm1x55Zvpb(;%L zHZMi77vJm;WvFI=&a~%V1(66do4gwfLQ&*A-N_>3@i!RddnU8V$vV*T=Tt_XLftjt zU9G5OHATkb?sdb5YoSU2d#@73yCgXzwA#yJBVSw(o4|ylopj^7VuKryIwD=YI5}e$ z2BT@pzL#AjT>5cm`KSwAMb2L@gNNqCAvj5Y{ju%#B;#143{(x^Dr>f2jOAVei$*Nn zw$9fge#9P>b;u%Arh8nblK5&74J@NnQ=cMM8OH+^F~^;Vmr6`8BF)^N6UPvnMbBOY znrGdhzW9oGGWXpne9q9~Mag41(1!M$$`No;vs~u7rEx!7Y$E5oJ$K?l>8AUa9e~)* zlMjbPlO4lk;*C) zAm#?rOB0N4QxteX-U*rd@E|w>6DQAkZ&bJyAh8Rq#WxI~>p{TYW$BRAKgI!LkS;z8eT3>Wsdw)m$1aXUtI4uc{4VMOH*QO{;;ZO zeWQSggKYB@U&k7)ucyf5VUAUn+uK_bE&A(%5xXC0N3gwYCJQzKExS(WB|Cd+(4SHt z8|dL;;X}EYc~z%~y-du`**V6=ZZ6-K6x^x!))29hG5H$}rGTXkQ~mss2I1wB2I}IC z2HfS1hVKt_;X7e&(?3ZOCpGnke2#z0hrRM)QzMiWxX~{p^L=9!q#w%=3I1G5{r5L6N!Qq*{Gpt{XC2T;$3P#E17TwH})m($d(iTXKFlxWWvUC^rVN;TM8SvNH}+N%dZp6Z#P9IpsX*JIz>h8S zNKcp=JBQr*&BT$j9lDxw*AIf7`&{G426mweeXu+k<9d_SnHo&c?#6A$r^FeHxA9q= zW-kV45hsBsEpKHYjART{A-iK(_K5I>5<|_QU$UP_&fc!%$%XEU!K<#Y*Zj#@ zQ#E}&6UO!4Q%bD|Tgc6Ix_>zD%5K5`;rj`5?%FJUs{!w`BW^^^YMXeA#vp|gWed6M zK-vLG#uN4g3eO?Us6I2-d&)xJ74I`X^aZ8MLWQOEiq@o*lN0yt*4y;*nx$z1a>}FRCXCHYZ-$u`D)R@9?qpyH7Bgl}EheGeOG7AH2dW-A2Q&^cZr=`~lOg z;Sy&+^5|6ALojP)yyhvuOGXomh>cMIbqQL2 zjl++wl(OV7ufMqO+GXi^p6Do+E?V^j|0pVqf+`^qQiCfc4dHOKj1pT_;+&YUyG~+R zcy4$A5?z}aTcS|92dG3ya>1Y9Z)3R37lr~ zIg}WCTFxxS@c9m_EPBYTsB`_oDmaM!+>%sqQ_8Z0z1Y-Zo3sbCc{|uK>q#A)p5fTr zdhju~TPpsODK1`1v-qN&R&73_(u7dsE=h)I>-V1>TDSUu1W`!4^k1})bxM+$_;EM7 zUKfaU*fO<*X~(x|=R6sHb$5~J)?oV(q{rgOP4AT0Q=2VWN<}XY0tMZ|bi3sw+tj{n z|J37EyEP33B%xTy35Qk1V1wlMN;WF85EeZxe1=jFd3@$P2-qmI2>e1dI8G7U)i#N$ zreEWJ+n$w2@0~fWfMvJEwyMXowmcT_5gN|jk``J)URr|fb9m2VK zGBWm@O3j7-O&r zJx4_&+u>vj4tOqc$Run(K1s?q)|^4^VC>20rWAR-QJDk#;6-VVWQT5zb17RD2bs;x zyze?s1AR{Znql2arBSxK$blqRNZtRKCgh5k?-*k;!uXsOc_%ms)w-HEQNo3mg!Xr= ztu4jfmG)gr&lhfzOsqoXhu)3|tG5`8b`}@m-UQJ1Oq9Tm3Z26ME`tl^qKz&^J_fcS z=D@W!A*VcyDUQ1=WBt}5!AG9DzW(OPgW^iPb|J$wHp$*ddu%?;e}y(L?hz-*!Kv+U z8AyT31kLwurR!^l0X1?VpHCQN$M?QcwD0bw-uB?ibaV)gzB-(Rm>1)2&?enBG0Y8z z*XA=laPg0N3h}@43jbMeu&%`^ChzEDEy>g}61pdLvP-QI_=Dw?eBGmZ93~e z&2w}XX4yD7Y<2hidb_~M#*{0o(BR>0&m=33jCfzuxw5`yi!|z`WE3W8qDFVt5)m|d z_yTEP*z0+J!E+s^&a(vkN}iknPqJyZlUB(6r`&-R2+z2(-F_zF(Y+>sL3c+zH8L%n zp`n-fP#U>j$vgU>Rt7nLRe|ab|1ZUl@`^_qCvdo;Qn43aYabhgIFxY%)XjC=!MlNT zi_5#R0cqE+6X%`4)7!iiQtsqA0HYs1}^ zuODgFg5i?+@z$K5Bsl8@@HjaIho51K>rbDTbZCX&Q5M!Kr)*ZEc*!@n$C__iN4{-n z?%IoGU0^c@UcCX82khV`3Hk##c)$I`Tny(8fSMVFPOoBr)avJ5xfqa6_=$n^rRfiP z_j=(wzL&bw7Fxegm86q;77KG%@`1xTcI!n}$KN?}#D^9GL*$%{Tebf&+aw}-5Ywn$ zBnm4~EL%tWD7l?UAtIb1Q=d1{!U(6fI=n`oH95=(bDLcKj(vmE z*C@5LKE>1C*yqflX62LMs5!LIiS1W1M7|SvU7=vP4u&tW?@!%ykp}W!D-dn(Dikcz zY+U5T_;`Qzq&)x4TtbD;yhr20krLY^n$D2ofgNtyxULUzou| zy_6_9m4Wldnb;30oNNd9QTyDZ#aTaEBIi*2zy-9{9a_y{9=TA~I7+YXy$fU9YG-L$ zFcbfE+Y;Gg>)y!X`M=cA^58#_5scRFRi=pL<>tW6UtNwYtT~hNN^nqJ6lwH%cbLur zjJ5qGAuMdLIoyOjm;2Vu^KE|=;+GW*syvp2?(5{C$OdqF%n)9R2) z|G$c^Hqu79+M6N+-N9A;HwQJD!>w#;=AT_Y?3>yMY&5-uF2>E!fl|zZDpV*cu4R9x#isgb>vqK{eZrPR{-NRHL+NRjOJGV|C-WIxkeO$R$;^p5DlZK}Z z(ytZe>jQ8Bujyt|iI~UtdXJ)-^;1&a758)y^qN8i2ja)BB(Sd7E4SmFm%iUqH}9^O zG!(~(u-PONz(?6p;8#ZJucZ5VYsGGM=+G-!yGSi4gp>MHRuI+op8U@;Sy8xta6!qG{eRFVd}9SXeRc|hnw zEq0R^+?Q+Z@E^9F-m<~ZR5_mWe*l!~TgfzscXBb?ItZ+UkP5tBND);A_^+%j-man- z<*SluTSiELK&qy>@~@sWCW;ZzQafXPvx?FR^Qc+%>u>6GWd%CC-fctA#GBebn-JK$ zmKi}<1F@>)6=xdD(`A#&S8(B2nI!ed&(@gPm6n<;FoJ-t`nrM#nnQ*=hAK>8Dp-kT z`d5ALyGGa_U+3OjXB+8N+=4-UY3tQn#dw(Ky9yXkRfCt-bm2@0oHJ6c+5>HZC41h8 zUuvy!Zi+bGUer3hTX$8|#gkrjSVILD7?c6=*>g>INHRVm(hCHNpHSk%gd@w}SjF7I zR18~TV?8=1%IKaxL@gy|p4j`yNxw($+`a=gqGD$Lwo={uxuhvYJ%S5*0B!vrOs|&5 zOBJ_WiRz|+;Nj~w07!4i`5kWrDT;bBwL#_tx(JQ~K8S&_)0U~L%s9#$>(t0Y%XTp? zlUbu%JQgu^0R-Lz#`s(;#)Isp#M!$CEmi5F9p(IVzV-sy2<|u<(#XL}1N#bpdHp-@ z-J`vB$?_fbC?`ou%`*v8%Nd6aqbvTLiB3o7!G|5>JVc6nFQ?m(ror0%3W!I$`Vl$- zH5`o?p@jB9HtJ-k`4PAjc?ut?2!IUfklG~}Nj{Pu(r{4lt>Zo3_Kj#AfeCR)4ImRp zOF!NasF5qlzV$#%GBdzuHMQ3B@{(++ibgE9WZ;H&eJ85U|X z#+E2Rw~G-^9mfV+_w6NlNxl$4^Pe6$&Q>mkj2WZBe&9c31$gEwddr6uh3dhuQ3|GD z0>heMBw)1je#Bd7XWzA0ok&WlEFuvsw?ATpiWdqx>hWz({Besb@sV1Hh5=JIslE{9 zj8IBTPAU_Pu|d_HzE2_HC^rlw%BL^mG1Z*PuTd-1D@aK*{ODT9t${v6q%Xg$UD()2 zZv|H=?1=YbNZ@v<{xOWu7xB*J+YyE`T4~-AkYu>Io1YPvg-%#FM z?=b&j4aZ%>0*g+3PCdS&P%t$BEfRn!ES0|qmsE|QEl!X6-xJ(|+Fm>^9JUC@C1)tU zJs^^1e%8toR!=e;HhvFV%K3hXo|>S&clcTe)0H7LzsEW5+OCRlizM5V4=-|dOvs3< zL$AH0!0n0B+Bqdt_minitI-46(I=Ww z1hy~3l5y4s&roQ^WpY2d@ zNcbh;nwig;pW@gnZVy(wBg>D8TSoLbW-SDUK2k8rWs=4dOdBkM`vz2U*>38+9k#f? zxb4;lcpSHW;6W4Jbie*%Xet!E_I^!^N%5&%u6446Z4%Uts4#uCaG z8(;D@bu=-#8Pd>6g1)DdtL(oP9(e_Q|CJI^6BD-;IprDbf8hEp+_>Sxeh>6#eEz+g zVuN@}`A5Mvgaiv-CJ3U#PpXe7;93v{KcX52X2#iYX@#Dol4GbHz<{>`8$1P?y9tg4 z4cXT#+1?Qksbrm)5xtHExrdt!Und^i!6^d_@D@d-=~jkPXlnB(;<9DJ_mAm`>&V`b zpHm_hb_F=JjLsbuDkRZD5{F>)bB0VIxG^Y?XmQ;pR}Eg&Jh(;$bM9mDS}i{)T?J9QN{eWJ7mA2 z({OjUHb_wVCAX!G8yG@+rFBgb+Lm!#+-G#zv@_ks7%?qLflJE(Uuetqf}^)%$UZJ8!#YMwe+jhhw{=Fh6 z_FBN>^XSjg43&SsefG7>Gz_#KjaE<)xHIE-0n0`oEWV1#^ueW%UDQEMif?D{?#d8H zOIfB>=5I>$SG~+hZ?B!VZUNv9+YlNVkZQ|4KYuefDcQ#@!YcWOe}lb$zo zubA0XbMtAZ<1(y*DZ2}zy86tj%{xVS+`DjvDeaYjw6~`rAxo2p9@*dv zRF%6HkD7|fsqmugJ4;HHCEp~79gl;pzZ4>PB}u2d@h25Z$d>-} z{`9Uo^VKUV&?81Yue8(fm3PXkn2Zrwj0}Gsw=1x-?NSh*}XNOUDkt1V; z@reUbL4cji0#Rqjv1-!aEt z@z+{(GqE0?y_>{$;Voa>XCl66@=!YOZS`xachoGneOJV>eHg26!9S__Q;(hw?*fH4 z?Ww*EF771%sk%)<^Yz2t}d+lS65SmtGY)#^NlMn zE?j-XdTzYJo>Sm$v5+ZeB$$Z6n9Ujt zVSj>0`03x@P%GTrIeCf%*7mzm$$})4pn8iBOH++0EAySB6K~&a96Yh5EgW%1IUr zaCXJM@(1^62`)O|KPpK<{dN4>s%+{LT2*t)E<#gho zJ!|GKxyq34iys(&?&=J{^_sfaxTaOUEKYd+;TE@(UTr^1RaY2S8NCW700$!;q3T3<#epFNNf5f`O4x`TRB#Rqb zqP$xkd}!2SqSKXkbVceM;DQ06u{6*`rGTao;|QIqX^w<%I9 zuCLa30=vN5T!V_J))>ex-o7><46?_cK(>_qny6L#`oYyMAqEEYF2x5qTujz4Q4(Y8c+1t>Mnu3^ zFpaHytx10-Kri*@RV*FHdAG7b9|ESUywRYu+%)lXS{!A4xEO_MeVA5QMz8oY$FT5O zn`h&z>z+9u0t)~pA=pgXm-2wM+h;&xUv%*pC$n>+px+$+ZSw*AZaMgR=?d9?$Hw(7 zf>zXq*if}?J>hOy9UZWkn#SSVxP8cw;11fDE?8;=m2b3B?viFc(bvqx$52)=h25W(~InK+i`{377= ztQH1BDLPYQ&ODN})TAd!`+S)rQ)Qh}B|a8}J4WH$fO@z~H$yT)&r{=_ioa=a;EaDX z1~ZRd`f4<`ae(4HZN}G4Xh&U+1{HKr>)4n4(cp!24(|;a8+(0oM(wy*JSCO)!meeYQ}O-rYb7sh9n86R1KOf3!Jo&HIN!jk8NcErsrB1%YXi=$=4i*P09(32bQ65gDCuLFv!j0>#yA zsibL;uZrDo+iKl_`RwnVBo^)YK2UKUz#t*1f&hDO(P{`q8&Q`Qzfkd!K5z zxW>HI?abR7_sX*M^xydS-mn=6deaqjQ!^2PB~Bq2m5iQwlN10G5=jnJ2yxy^31Jrq}AYYl?opQsp1d3=J!*oBfeM zTviQRkwc1#!QGiz!pPYuHr1gm!JlYms!p;Pv@Y_zLc*Kpnh#hGM5e?Gjn8)2$}eR| zUX6T^yW-UIKQQ|1e$e>Iq@*hd=Otz}CNsg=_Yoy}qv=;DK(AAc@+qmYo zECgwxo`$~U7-M3%p?>FPWgX7`@g?`{xW)B~>hSf?f`=r*9c_5_>d>*a&$7~7D2rY! z-%cvRsTBo9gL*$Se~u3I$I0~K1OP~W{P({AJd;x|^;b`^sra1%*Fx}TX6hRb^nsLs zDrHKMa@unxx9^MTkTd9Kh_9b8e{L&5U^W&%?VF9I>lBb31?-pRu&YYG3B!1*PTFx_ z3-TD#4AnS(Y_PwAQ|N~_DjA}i{%mhtdAY{-2xGoI3nH&xioBhFjyDn8WlXSE%)g7< zcTzR0{Xei2E!c_fK#xi5n0sr8pSXU!gJX8;Rm{C!ettTeL+r*^9P)eKuyIN@gbNeDNawI)NYmHwQ2s&NrP9Y^!5-+1@9ig^Hd1Zq;OGM;+1({I`3_y^ zq@L?utgJL&`E}8C)ZYGJCL(TN?7y4sSa`?qYxY_uDy@}HYQze1{vf&m!q8v6zlg+i zYCEW4b=3;K*o(Yq1?Dpa6}*U_a9J^YJOIETx|Xtep$~Y67dIS{=XkU{KkK46fu(uDsTTA zlyPZ;_y06=l~GYJZ5v4mA9CrEZUpI&S_BCfB$w7jP^kr^7MAXCNhPF1B$kGiZdfFQ zm5^9UKty0^B;S4BbG~!FpWn~#&zzYvb7rnHb>B1Ry6zz_j!BxBISJQ#H?m2`LPnOJ zE6Uv?Z9FGCnv!+^|K;%@nu}w@kc6o&^#k_^GTfHwE1u%R@sROA z^zX34kfd(@z*H7#5#5BKs-@bIQsC(Ed9(HZJ2W&I!m*ItnGjk}Y*AkU9+dVv2WoY>QK zM{d#R4{2!%yQ^}IDi-JkTuG;a-*3C33PaGMm_EmDeT{$*=^8uT4$^oC=|*~ay5Y+ zP-!#h00Y>=-X`@8hYl;p^8BUoys4pTo_Xpw4L~ckTi_HajNg*o|4QB(t9eN+Eq|J^ za&%<=Uf)E zp`U%p4oll^-1$!)SFLB^T`?s`?}CEWes{C^Ug z{*V3@twKfwBFqVs49f{Kdd&YUoe@V|OI0iE8c66NIA_mpvB@u--UP6`qjHyhjyT{e zefo(d(FrF#J7RgCXdyJC+q?U1K_Kr*zsH7QvU2aO$3AwwSY%)2T}ZHVDl|=>j!s>J z+~SK+rM5-sh<5u5ypS+{zUhs%i*0Sw{NB8t+ibjbCDLjaX6;eFa}Q9tVBR7E*p~+y z(a@wsM)Cpo(4&7(5L<~Xsc1(5<>#qc%aE8I@ETmh?6W)2wnW9usg8-0PNqh2@zba$4_obgaE0a8Ne7b4&^&*dka6tqIjitEwT; z@~nPW-JR?J{(cq#6DJ@Y65}HNzN+aYBe4Qo)m$aFVXo?HdXvrRtd*w3KxlF2Hpely z_#N>KQT`e>Ked2!J#+!8amCdQMoC8Ci|~jG@qb3hSFvYiJ#y<|Y8d8CXL-dvZFOc; zmg;hv;}yf%8N^^FHkz~hQii&td_7d_#Z8dh9+CNC@98>}Yt)kM6(_e^AKWruzrHhW zgq5N_%w=hyfpu0d&e_fg(S%|&ELsQJW|$i0O51#O2S^;Re_=q8p$M3&j19FUf7>`X z;Fj;NOggk#IV?N;JHydk4hQN%H>H-*M zxzDexW~5N=FTmk&x+u=>1`S)J0hB!y^4gVFKy-fK<`eP4UFf|rt-8{0JMUZqbN~dB zm~;MmE*wA7EUV&k|Gpfkr>RI3sv0_=E(`UqT{f_hbdX1CD;GccQe7=yw$#K3yCkfc zQaL6-c9T58?77{6YJS{ZCmAk9QDa2W7GJ>Nqflq)(lpSDvV%p#7VEaEu+qA5mSXh_ zu->|;93~neYQU)x2VbiQ7IvFu~x^*`H6{>VrfM)E3#G;*oR(Y7J~aPv>Kpej>M>J{}xbz_dCrRC-~tgsa;7==MB z_#I7SF*cP_gvG~qYlK0KEyNoM#4(@3i0UC-2f3zS*OO#@L zwvs_*_k7&CZFzTMT#^KS&kOJ>anrr2ztU%2M!0u}lv=tswzW3wn(3ogyY+0op6&Sx zsj-IV_lqer3z3+AJ0HLW)Vdqc?HG1zN*;}bEznnWk^9xD%pbDc5d+m;GcL;3VNu9A z;L3p9jA2;*I;mOoT3HzT(qMf-9pLauxSQ`PDcdvJ4m-tURh{gGKDCv{E{I;+VinGF z_iRL==lcxe+jn`8KRYXYGdZDAc0)LVK;OSF;L(@RYkl0-HI#@w5YvakQLUGuKQ0e? z6EoFyu|&EsB{h#?r+kZ=!rTygMOe6*1w#ntfahAZAjWl`r(qATTh7F z|DzZt|NGUVY>9?Uei@zUqqKxbF14h7;Qb*TpppJK;vyQb?xjK<9ubsg|>Rl20v zL~P%+RSAp9(*|7=~f-Z(ITn)&r+CEv4pEy%`yw8zlM{i1Yj zQUUJBGDhZlL41k4d+GsGtrx{HCT;mCpl>5x)of;MJWUe1;rH8V#FR_Wr<0QJ<}8RL z=2F3Ud?_On-^%!ew!{{X)BM-2OGJO93_Fg*-%zjcRz+09O z&j?Bv&+5E4i!#ZSaUqI=*yS-Z@|opn$J=;?%L!0Xo=*P{4_O>+G+*>JR&WUJY#{Y9xs%&g?)qSBucC$&;e?X$LZ|ThYNgrGF@%ch0cV(_zB|Nqp_s5xUeL!uJ9}e8~ba_|$aQ?^=S@ z|75P1J4p)s$66-8)ywO#i({hHZnOO&TEplc;=83fU0i6qC_*BKsbel(GO@IcL#J*F?H=q3L2X+Bs~eTGzG>m%pYJ=i z{WR7QG7VPGf7FzPY>@ggs41xp002~dqgxZt;2h$;%(R1qybKp|f8PC!AilkOdHiSK zkM~5e{w&hpw)GLUyJN&%ngg(jnKj~Kng^?A7Lrw7W%NAYW^dPnnpNhNv%mx<)Ac3j zg~z~P5?kB;$iAG}bUx3BBP~lYO|R`IqG3?ut+Gd_20rc%OCSyvIb@syGgbAp2hv7S zt7LqDPj>k)?AVEjiY{d2J(Lz`0sk5}02>;5#Qicb&e}^bpq&niB$YXtv@p{yN%Ckg z;$rt^>dn{Qh~tn^kt%C^YrQ}rGidp1z|z`G`N1iUZ=bTKSL6;$xkFS{4%7`S4-7*zR?7IxJkO(P` zCr=}>&Sutw>z5(G5<~$m*2+V~$AdX-^=|0fXORyVz3r|Eh zR^99H$*Djj`eW_2WfAPJCIxtSXiu(Tpmy>Ieahvp|28VAqUtc)u-4bKyOsuCX!=rH z@#&lL`XBNKNF%Fiq55Sz5Q8#DTS{Fs{&Xh0avp8V6}X|cX6FdOy&ZTKGC?XU-KVg{ z-FsKe6p``n#-yH#M#dhly4z5ZjmOCZk>;<|tSKrgin)LlqwK*YW1mDVaJdam(#@_k zF-e?gpRV?7U4@V1TK!EoM?P1l^Y-5T8pU(Cfs4j;VV=%&*p8Q3pj{052^auVE?uz! z>d7Q+nHk%SkD7qi7MS3OS?p~rOM}zVTyIQyxe#dfzLm_avxV2zzDKE-iPaWUAdhsp z^~QVfw%GT~ah^&|P?UaTGqzo#QyZbG$4B>kEgiBw-6pTraq*%32>s@iO+hF(CT=G$ z3UL_mK?-YFz9F{-uc;JuxYvub(8qx9E_*bw`t zS<)#d`8E2p!m@yay9@O52IJ`LZ$tvAgXY*sh(LW=eRP)hcwudAtZasC)#s{JKg!@f z+m_|Q%?c4a%PTQ&$*xrQrM3pQ1#`}j^ZR>Umrvch&K}v_LKXXT5`V@pDOxVv^6}tQLLCA{BHU@yb$~SQ^RQdp%)eg7glceaNef#6K&;C_N_gh zwjd~9{GQ2T+xqtT9tc^|87%+r-bx`uI4#!pjAnU~nt(EAeqY=WkwQ;fCY+}QMgJa9 zOO{=Il?31ZRk}G|d_gdtqnNAg{zVZkDEM9U;^_s2Oqus^wzWRo+|2vE5Or!9cgTKj zOP18`x$65}HB@3z5f3(G_NBJ5r+wK(_CVM8?ey$|%3=5QqUYB!Q}gtPFTM*QQNNkk zeUAG}W^{OH-EDAeoB=DrzPs~ia>3kQTnaC^{g<#)ejw+k35BB_cP~~U9%m|H;UEE9 z5>^b$f6rRu=X~9p4{uu1^xo-q{G6QFt9JG>oO$aJbG*|+zWQS&OhMpI6saj!UH8K; zLN1!r-3b4dB44hKnY%v|_HQ3yP96x**NYrSpY9(ORorOT&DbSGlG1`rXS(*;vXJpo zS;=OFWXT_fY$PcsL~Ttqcn*sVX8SS?(5+B~0@OJq%KolQ{vW6BS`u7~T@&*L7XA3T z?8ybo3Xz?PH~B{?pA}C+_koe5rg@ytto)tIDqk1~ytLJ)RtKgBDO!I6{kh;Ic&`0u z@k!s`EM%-y*82?cj`IKBwgIdBVlY3t=(mH0ndC@7M4y^YH)w(Z6!}#0|{A7|#+LjBVl>L#squeJ)9&yNfSR2b; zvUk<6rfQ_Etq#P-m&-d_zTThCLZ(S^7@G&Jn3Pr&Hs!c<@(%lSPU$P%a+LH{JXI&o@AbuE7F$zdQ7UYUu@e$t0^|uuUI-c!cob7k1Vq~Su ziob4uORxf)O*eE?!|k;t$ixS1nRYVo2+0)u)ruV0S{t1B3$scyK`kk9Q;~~sGca%Xrr*0z@fR-YGI+_U6ULr2 zAy2#5z^dI_{+JkTB2(HXM+s!;MIjp(ESjDTSg(=S(8Y<_&eojgqInb*>gF>~pBK(P z{&(12EP!PrK*`E1nu5wG<(inZFc@S8Bb^vpB2zbOxf6>6)ZS~K=vfxh{Zdq^x&aZ# ona@cICQ1!5L;hESHVz>ZH!690qh~LKk8exxMEfZasp$~@AA(?nsQ>@~ diff --git a/openssl-install/share/doc/openssl/html/man7/img/mac.png b/openssl-install/share/doc/openssl/html/man7/img/mac.png deleted file mode 100644 index d3978767c9f2d7d668cead7ed9fe680fca5b8b26..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 42741 zcmc$_byQSe7&bb?P>Qq?Qi>uVr6OG-ASEE(T@upWA<`frNGlT314s`rgdp9+kTX(4 z4_!mt*1fO>IETH@K4dpYNhWM>`HF z=hfFV8XTuvPH`1(9+aGZN{Df%)?YrZ(+QHU`6Oo#bB!e?MFlI?vWb}G$9=<66Kx0^ z9lW>awoC~U6lHI}?K7CoNvGl4oz1Ax42fn&L2$wE0&Zxt%Z`)yNbpQf7Ik+_fRYxNi<8X7O}-7OrN8E@v=GC z(bDkhOL81szllUG2o=+MQ|^EEpz!M@mF_f#$|N!mkT9i0{UT#?;Iv!xZ*bYK$@|;* z5)b>WVzP)~&4}lWO?{=86u8sq*O8A{dDQw0ln`?R>8A>niVOFIg;c zlRSFn*TOb%v)wvP(5P@rqb4nR{~Cw&R+a0JLDzHd7h$;r=+J5b?)&WR93GE>YbYT! zUg&)Bgx$w@dF}A3GmwY6?=Cf@aWj~#>&ZTDpR{_y_IHRaFRqiHDQAMRk*zY$_?WR? zVdLG9!7MBt#>c*7AbvlF8c%Ii zr^}cmnzP+ zzJhtNyo{>aX<|>5!r|eV&W-~*$$a_+(yQNh+PQFq0FS#QBhtCOwvC#CN%7rC+SEZ{s^9}AZ< zaTgFW4mL)7&<)xrK;1u95u6KfFJ;M;TOC_oAFY;A{#fTKo<}2!PdVf9ZvqQ7u9pMS zn{0;eSGHa}74=w$pAHMhM&<=%hKgYa`487-30-+ajNNl_lPNIV@LZhOHGU`5$tZ0w z)3aG8_iYhEO0TuX;Nx;i8kdo*LF_JIs;g34`_0(;a)h)A%fiLgl%n|Hpa3 zC-jT{CkrT1ZSO4vQwVKdaDp5bCWGQ>z&E=v)|{~%HDk_^i1l?}gW69$H3{AkplLl6 zRFk|Q2E|HUd|nK^C>K+`s%g89mqEIfUB+XV9<2Ut_vLygd;5(5V2EC`eHDPk92oC@ zRDN=}KhDM|?%|wpv1YEtERf(FeCiL1qZ7!K_Q!TL*=E1N4Cl}X{rR5ldLnXpc%2bf zMkoE1SmZFvw?_5@gP&1% zW&QJ1-_14((FTj(njh(N-)Yv8r8H$~v>u@)VTz1$ygyZ5s6rCxL*1N{5^+iZ0tvc;|$zSDlFDqWL>UR#hL^n669nLWB^!x{q)Fo>B|0nUu4?cM+59t zyZ3y4@6P`OE2U1jN$a9#!bGccyPB}D{B5kH=i~OBYzHhY4=bA-(7%VQ)qgQ``94NL zpw-jPm5jxgHJhcy64l0XPn4Omugc4iBx!u5m7Ipx#4C$@zR_!9V-S+?$Jcw3EYSZg z*MDGLs;{i*IxNR>y5UN-h=R2JEvZrZcql8JytvQAW}h@(m|2(lxXhfd{VD6k^WiU> z(Yf8YI%ZRmZ&(`gd!lrdb|P#SLT|fa)o06Ck$D!_BagO%Pmfi?g1Np}Y^xd``<0A# zL@5kt@HeLZ0tfnC2@vN?%U*kCb44WBa)uC}Hq;1kdF$rW*s%b6&C5LZ)LMd;50~VA zIXeMANkxwYPb5UqK2C42x8=A zV?HL=5uf~=HdIdA!R*V6p3yW`ggib8e(cx;X{n?5@|V%)^cQ*l4M}o`gqY)$rFkrq zrtB;un?n*eO~6^7Zdgc_|GW!~WtY*g+j+_l1M6bnYm!niKg}^7|2rU#Po}Y04H{{O zONFUP=9|BkD|o1cU=`8(wLW1|$E0C;yog=fhje_{fT6%)JRQz!`>R-9Bjm=uJj<;_ zsr>@&q|*|3(@3j(-Z_U~uLw=3;YZ9AyeZvY*CSY8Q!gee>Q|d3G^rV|M5XZjsHmvB zB5V$nlu4|`Ry?e%8Y`*ga9)x|ozW08 z&(>3jnHc((8T&UzB)t!ra$5Mz9-b(ekwhGSo2nhfa)x(Cu}{DO1ml#5efUBlDAXF7V1if?ujHw!y{VH_#Cz!}^_VvP*DO2v-(|rR9J)Sxe&v zY2(?U&$lPM?A_NACW#F*BxkxXm5*%KZ;Qc-=mz-7P@KN3tbw|yK4j3g%PPl<18UoY z?X|r1O&2nUO<+rS8@t3d5wX8-yGG|c8-S+gw!@CX1?54fzgMM3WqsR0LHE+9+e1Hi z!R=eCENK~ME-B6&sC#FTFVw((R^?TBHEdhqOUvzFl%e!%5c%J@>!#2T%mgRJ8&<6%E&^VE zt8X_Jh3@Re4BVen&?jpwNIDfN9K7g*eYaYmcK|DL5nanH$c-W3{(3xZOwvfF&8x6&Z4mfh?3we|i?4OW?{t#O7F~hum!Ha3ob5IuAMmf`aQ4+bh z!JNz(F)trPEbOjFT=`F03>}-@s3zhmLu2EAu~^(lo?i^h$<7vB^fiAcQ=Uoo^xn=r z{OPwv{t(A9EvHveA~bqy>)G)wM7CsehU-Y8san)>OXVW2Hl)=~RNou4`{yk19qcON zxSoNg%5-#4n4z}BT992IvK`~OZ76Nbf8NvhRMN?YUMhO}LpA2io>v|4ZEH z*(vpldJ!&@bYI+xVCv5~?qfn)I}r!yeFwh{BJmk`{Xl3|i2GKBTKB5e#69H%mL6PN z$O3uQ;vXMpqD8p9+g#7qNw58!8U}jP2cL{X<#kA6MauIYkE@K93BDM1G{_(9*@nPk z1aLxA&#RutE>92YeEqWTK))yOjePI6C#}D8FBVJFE*T*ZZ@b7#A7>0>qP}Sp(V1{s zH=?4n6LM>^y<)1FF7IH@QNlBg4n}1(7wDVT+w8>)NG)R~pd)*cXQxD=kmWpvGX2O& z0a9B-)jp(`?xv_+6D%N1g|AjbU`qmOvzCC2NFq{2MOlVPSgh%{dtYVjH}6y%KG-nu zvh1-`BlhU=TUNshB8Snp2a6*_Sy{(-S7#Yu&rk7$x}{hq|9J6yDIcho&(pCKs2jwg z;@P$=OO*FA>U-?n`D%lxRHpAnIy;W)J1S)~J=tPLK62c^T^NE{EE5L>CJ$Sm12*JA zeVUlXVJo&x^G6R|tXJ!IA=teL=M!QTq)bYl%(jw@^C+I=HnTSrN#yzWO()ox@pZagE}SJH*Yi`-CF_NOvp z&MXlnt2e~O1HVR^gfCb+{W01UCAY4XK&+e-Fz99tqy`E4;^I7Wpg8p53xvq#n@vB0 zb^0nS*ob`4yvqb-mM3!68bG`)Z_J0Oh1%Q@z`d&teCVNUdmqY+a(BXto-=6Lgm|tf zvtL}~{qTojx%RKkTTjI-PLCwg7*G4o;^H?#jL&?^tvi2LFDe>OG8gY*~XUK@NvhKVVtvDuAbP!Ztj(bBMkL4&gp#aFxYrniopdN1|3gl*pgS(L<>=lp&#ox|kpZ@}2Av~97=px?jM`3duy553E1K?#`Ui>wa7>AgvGivC~x zmxkZ?2%}Kly!KB})_0zuw0gSQD20~q{s`7_R;}9qxBhSVo+v0u(B2R&@{QZl7?f)1 z&Qa`ZM&|N@RP7E!qKeoZ&lJDo-39IuI}EnB6IYjqBO-3U1DtK^7Np?4uzGQb z{B4>Xz*mFzoF6EjSmofW@)*4by5qULAf2vs2sMcyQIVCE1ql)%KDX)^Yr-3WqsLt@ z1-IX);U(}`y#v~6VBQM`d~~=sTKHKSm;r^H1UP1rZLZ3FzI+5}AZI+15TT`M+7P*{ zca>48&j9|BwR`ZujQANblBrCBJ=DAU;|1ZK;NC;ex)nBfF_Iqv8VIcoVJJ~vH-?64 z*285wH5SP*7k* zvurk3ZnkY<&Sypo{Nxq9_EEWXcOL-O*^Xb-@==TmK^vUv?=t)`+H6~Y z!=i@Gh0z6qu-dKm|Jx2e;W9G^%S8m?n1jy@878QIYW0r6T&R|((H zb3QOY+iYLA04t+@@nVn9@pZg^^{~N?9Nrlj;-M2MVjETWjS^Tmt94?di1+~saylKP z%k8J&Y|?-*iP}Ib^DaQQ3#|f;SdIwg5#mRX7Qc4{UlO$3+p~SCT@0A~A4Ry*_I}w8 z34_wu{n+EM;Csj>cr`Gd*dfXG;?e5+09=tHsdxn2&PhP*D}aAQL$0Ha10-AF)xX$s zLO1l3yZ`<(09mDZzG_*CqS4S_(hpro1WAyK|L5t+Q)m%Z^EQ(LgAU<55%-(Zb2-_^ zBVL_0dCldcp{XIfNRRAVb*yia;14Z%ujFw`yhO7RP4dF?TC+NRwM51y%e(l+Aa;3k zVMmnR1kGB>x6rb=PO`sBZwK9+0zoz&mJ|ZU-dtA^? zcg6)}9a)W4$St9N8?!J{ZO3EE?eU=EgM!MCfKi%6H`{5m(zkU~80Il~*)MDL- zWQ$Q_5L9v)vJ4S-d%wA+A8(kJTUio^qOa<`cRRoH+ssQ8=UY4+WdUJ}i#zvV&tgnQ zga_qi?Ct9VERNPgH;xyZOv!VeFT+0d8+i{VJ&Kgu4N}wA%HD33 z61#^lA2IwP{*+G)iw$s_{3)IKg_MvPKiOK{V-~u(Nw69%OOAeSX16|{0O~3&qeWkd z_ykK=S-A!Lu*OphI?R%Rxs!`wiqhGsuJ*1qFoDW~nj=J#uONj{cP0K!n^+R&KI(I3 zCIsd_4f?EP+~n@10b zqP2dBViiM4tF^%rpI~K4sbC3aAF_A`UX3FlY}5OYAVGa;-bUiJ$VaH~n5v9lrwZRC zT2{YzNDy~_lzsJz%l+xo%j}rjc?Z`Y=4N&XpLz7e6^GpTVh}1a8z0Da)Uw@sLE-`y z-D|^5Y+?(+HhYr-xh+=5b}@;gEKnTnrM#^gBb1Uv*X$T+U=a! z>{HS<7Fl)Y>_-H1cgjk9t2#(?S_rUwnL_qjm;(2#bB+smhg66we8iYlJ@jhPDnl)v z(YM^4j8;xr@EjsIQvB0~N8<j4kjC?wtG~bs*;Y0gP>5M;ctdBH%5h-4noI^ePA>JBoY; z%iy>KW(85&qG=Hf9#%p!hN?^o=NN<;5;P1wO&==x$x%icHYZwXbS|f5(&m5n(~rpE zudd8+6Mh>QKVZT%f-VCLGT8QDO6Yr4x!>+S!Bl%1&6nCLsToJtLJwtyyM$2V2I?8bsmPE?}h*~;onm=JHa;72axD|`=&RjCqtf3iIl z|3##{XiWlp>sdfR8V zgAzCIje3-^>S@$+;*{-gwmz6~qf+H=ZQbCDvDtM;1#WpJIFt^0i+W2EVR#A14ofBn zlH9e2oAluUnE5l8q0Fs=V~OrhmX?)LUomb#P{lL@R>13}5&cZ%NxtXvJ)D9vsUGXK zt#3veondN9r~zMpO$2zB4=CO00ynqs5YC5W4D?Qt&BRocN#aenvwZS{fs>TB78CJg zoE{GVcP=Vwkti+k>DVkSzJXnEbg=NBd?c$hk{+5^t*UNLJ*VU)X3-UUP0hjQ!VR>~ zKk4e(Yoq7ja^e0k1Tq7kY+u;?4>&j1Te|No1oTBm#&B3T5l$;-Lbuc@fOgrBz~k!AMJI-F#mVKvrH+!P$@;w&V~~PDf$6 z4ls&vF*aT1HbVkHF6hG+5-SKQ!Sx)D!UX(uKKNxSrsPLY9fg5s-XaOn4E?P~^ve_+ zNOE6&YlgOkoyoj`kdRi85fCPNJPCqgJYN|`Pd!t9?)wFT!m|N0XMJAIB8XQ2M$Hff zOMy(flV`*ozYZ-%+<8iV0yiL)?A)DFBO>E{FZ<73Ls?u%_6X9@HelNc!Jhl%q2J;6 zkl&s#`!JjlKvlrY{~R)9PUw%2U^D7)A8zns$WTV>hrh24i|>?49rdztUg--p9 z{MI`uJIi!coPJUYd3ML)wIm&q$p5b6Er5W)qS*R`LJEB)gQAQX?*Q36YR5aBMff|! z+>mR?C4)cr&Z;pASUuq2>pJ?u3L-t&jB zfXcR7SwM4OHINv16+R4i*Q;S1{6sr?3$2HKXqJ9206hN2H-UDj?=Vy1eZUe4^9Xc!Pk+2J&Uhw&Aid%ukej#Wa)VdN%jc; z321EWIpyHBTJsuJvAanA<hH!GqODvbdApfFH){c9{C}%53Yd@G&6dHTY!IRxZk`+7YXplrlMp|DeevH zvWgsXZnG|%Jva0o_nfUVLMkrtMq&41RqPa)59}}l6%2Uh!bjt+*>{1_QwHf(obi8? zZ~fqBUbn0LD$=HB_A?eVuyn?oI4yDe@v>+8Zv*~jbJWO-ZC1{?AQ0`h%(^HA#nQZT zhE0kz9`!6}9#MYwTj>}6#Ipc3Bq29~0tKp z6NK)#p`W1V{kEuGMP@vHCof0txAB>sc9jXeSe&a?)n9V?0y3#0~3Bc*vwdQ1E0^KJ*s6D~rPP zb|apHU;6_SAD zzO;vV^zuHFEw}~TTf}n$|DwjWvTB3%dL;iu#Rr}fM|YxfeerYyPrNd1)1=kb(-1>w zhrtW~pkgAia|uMac-9cK=-8+*tB#s}OSGrTyr=owqSwrc@~Olh+aXgxK7Q34J|l=+ zmZm)U^Ufe-p`neirFZ^wlU}~#pA+Oa4%5*+_rWG5DJ(3or&$#lxaUj1#fXr_hU!8e zigx(CT=1jjbT@$rQVDc8D*x4z2J+*3u~1DA8Y`k z>el}d9&AsV3CmokQO<5XIMa?ds{SNf_$SZz=+Yi!O&kanEk0kf>`Jq#6eIU3U2Kl5 z*(UOOejtpH-f6Vyeh5U#yoX~v0K|?-{BMG~(n#fs7wWR|H39NY;gP)MT@0L#EPb2lTMahMVyh*Jg*U%a*KO0eNXBVQA;0b_Y4*mTJ^>VS=J z)29NiW^#i#Ko!suNG^Z;7r_1@bm~a<5H(Na{?GkupeO+u;vN$E1L&$DO9g+yt#4|I z){`yhehm031%`16lV)=Pj1xW9v**dSFryDknH~G`X)@dvu2ha_6~ES(eaxQesXW`_ zW=3QNg0ewXdbV_4IdgM*j~u!>RCiz9g3{^X2YlVX;N2tKGs#WlV*T(L$PdwGflVP^ zL|z15G3nQnbj$%7Kx~U@58)_l(jBYoC z9d-B6jldMvl@}zid?C~PY3ZToaEHmMdAa{;05~^^w;|g^+qbqur?Mg38*MRcEgpDA z6nuHBe*w3R-^N*=zZ+)3ZuS7m4+XSoT`(Ws2;L0=GsL8CqFS!t50H1{T*qhpTD=`V zWkYKo?HJTk1AX>zO@$uH-~~=@qoBw4AV@P)#8H|F?lCGY0u%QtFqAq}EL5$!;E3=9 zcDSMU+JW!&_F-;9Ad4~-yZmSyM;94y&I=H`r3)|yJYv?j&W~nxyx$*05Lbp2F0YrM z-1?r|nK@K!F7v~S`=7j|5hH3YupVsAR4Un#YbklhVKc4h_;=Ak00oXL9V~=LboT`Z zz?^XP_@&S%3j**v+;-l)W^W6>(ISkl=@6pNrLJ2wABF=AwtjU0zJvUsj)l-#3dr=e zw}#F^W4|Xtv3|8-Zyp0X=YtsfNqL5sqzm4C)0R3%g14QSy|fUi*9~-ljwQp6eqknX zQhvCPJRBXr@WazJllk688VAr!;3n^o;a^9_<9i97+^N26B87H-g@4H+*qI3=y7+IQ zr}bX^B&_Fk6dn)h3TX%_d>`aQndDVSw5R4cxJ7-NG4^Ez*PiaS{>~u@Baqkn6?Uyx zdn$%}moe^@9XoXQM98uGB|sRY1FL1Pxc%;yRfsZf1$Z%K>b@$_X3JcZwMzLwCQfk^ zfPeDVc~RW;?5{*uO$|ok()_*3koEauRnw}}b0?!>m#I=$xE-?%c|}P^Bd6=y=0?&Z z@3=7ZUGxgaoyZ-r53`-(EKAY=?Qq(bJozY|&c{kR`sl^@{h)~BXOeN^?3*u%cwH)I z_}^O3IRnwy%t!+LM4;sWxo#CR1K>5r?5l+4>W;A+{h|Fi{=a z6(Gv@0-3gs1K)m!^!;{^WI|X2S7A6#@pK=mD4+LIm5a#ZcUxHr_?;Fja_^q@zoL%kL9gq7zlkhr(gg$N)g(^ea~4!nS|=Ht$feN#Xn9s4mbU-@c3C< zEv?mtQtG9)n+9TKgYj=ZA}xhvd)CuEiq0Ts+J5-iRStI;YQnU!6N8r%V`#ow

;^$ zEXp1+o~(*z0?u_Tf#8?vvh2Wam=;;qv)w`JcNd5+@z+zhxmq3&ceQj)l@Xz@@UmOX z5qp259dV=;B_azV-Va~-vW{6QsKgs)DKM%Bi-p{s-}&AWn_uOJgdlli@}&gXRY90} zDe+6ERolD|8`&)*`b!XWNlZ*i>#1#V82aaEQ^o$ZHRdWuE#bZZF}lw=$UVw?*Bmo{ zbRe70vS_*qa~{gvH4VuL4K&>U%DR&bpj!bXB!kB{9^$=wAEZ&j zby`^&Y4%>9t#huwa^qov`?BB#y5KCsRIz0?E7mv)gD9%2T@T+N**;$eB=zNQ6hFYM#v3C``! z&5(lLOXM8qEul9u7$-y4PVtl)7ON^tn%3F3dJf}$gQ8_EJbO03fOwNQ9NxDZ4WNpP zY@X@u2oi^}EM2K1tsaY{^E+-%YP-LQzX*Bo^;k>pcO9jX7$6s&g8rK$EUo|+4A?jU zh?Aw^rC7sUc1+Ad=t6bTdK~%gn$UUZ!ItMXN?+FCpCc$pcr`KOLd|1R^SB=-bq5Vd zJI_*4LRLEeQx^WeZMjJWG2cgQt485Ra`kX*5CDDTWtT%wRGApO`5 zimiNhlJ@l#A|DnJ+WIzAtBd0(#S;bTrpk@^mn1Ny;~w}3D-@PSPEEovt?gvU54$km zhCu)(PyR#gc4ye>O*Vj*BZde5y+uRYx93rvy_9yRFX`HU6)eJ8(OPIknlL?KsO2>suklQ*P(4u@jp9#io|M^dq%5owxd+wt09g+mwxWf%9 zq7kK_r0mPXf;iEQK!Yr9{N2u?Ka;Q(Aj)0SMJ~TV0m^&L7?3zQaXbe9Co&1Di$EC! zIeS+1zmxZ+mZs0)k-nn4)Ospc>2Ocv{4^~n5mOQ{BW#U)AV_OTt0rH)6z;EC z*=6&v&O1a34;z-vd&s1SU5MwoU!frOJ<}6cL!b7bcIvAXoXXA5H}jHht>_M6W#=bI z1(>%pbG+~vA6^Y-g9{=FCi(iZ3oPez%q?~tG{tuV_A2|NSeWzNj%+VJdK+@vCwaZ@ zYxeL25rSnx1EC*O zCvTa{V1ee|uBZ!H01|G)X{KX;@locG398^?Pk0ia{$0;)H-yyWd1Q0Jr77Si ze}5$*it9=4l|}~cqrl!E9+6>B|5|>;820XVb-7`+`kKj*HKu!A`SehhKV-;7-?`Wq zCMKyZaZUE-vJ!HdSNp^?H1?Og65@kqh$l#l0!hAAUdN-8>c{H$1P+_iZ$RlWh2i+)jnY9#|_@_YI!|J3-r7477%1NkR z>_9H^k6V=m?KA#r?DzUY$Stno?AzCB!l$bCvuEI$h67$k{-$w%@96M_Y|J;SvhY@zCd za_gWN2m&2jCNx*{CEu3x_*hp{z_-a<_^K60ZOM1#cel_hzDNz$Hbz=j8n&0=^0u^# zcOt{@t-sSP%D(7i&#jFpwj`M)>t}-gW7Ke&{R8fuD*YC=<6f#cW<9q#YX47kW&(SD zFmCuK{f2U;P|AHb3NO^TFFL4P{&4x%>%)TbVp=H4$-0Kki+M^08-WTMWn^qM z*#|C!VZRuAm$W?7SHDd}%hHbKq^Ac-=n#MZ<|nqfXZgA-M$|)7E zF(xti^-SlxB_-!ewk;LiPoya#Gz^254vt5~{?%g*TK>Gx|26bnG>ve-QBq+D*89H9 zskqFGP1DN?81Fh^mXe(1KQ=5a^@vrNt@t(y{-w@Ty%NBHczdC?{XCxmYO(-q>Ikq`&%2WAD8({WTQUz%T)6hH>wqska+`ap_q-Ttv>PD!-Zl`tG zG!Eg^R@HU0C~~^xa+I18cV-;SC_={bLT`5}?DqaOG)ykf8XL}0@JLlB$t&hm}dd23JoP52zil|RRT5LO7 z??leUS-tU8hpHmdvL*lCa&*K?@{;SD^>fYxW#4j4WLsk~(kw6@T9WQg+ zJ?fXOEr_f7{t+6lm$h&mfT7NQMQ8S&w@pQ(-=h?82%4;p z7Bi;aYvRlMNQU?Y9-ar6?>Ai07i_owRrO|?bD1$i>4eMS)e4G-yg#!qUkm$EdKM{0 z+}Q3ldv+d?AZHNf9apibxy~W0)Q5nxI+7V4|M`OW(Hp3wlkYaZBD=bhPUr1e{JNJl zIo6^|-gZPp1WF=53QXRFz%IyJCX{14t3)7u_ z18P(hO3qL+Tw%s-`^;wp;W^~F*qc-A^lheO1w-x7p;Q--?-0tQ@w+;z*Y0{E=bCSf zn;igiw0m2vx-v$|AbI49{s>IjdBY=@+b%B<<}T*aKa!T7RhHT|3hu*BcgfX{&*rm= zg}kIffF01~WSuAyP+Z_mq$zRzW9<{q`2CpUu?iNjAqWEzvIs_Ijg$NTa%k||>cyLQ z5hQi*%$?f0qBD0j=x$cW))&SEwSesYGt6TsSNy3_RXOb(UuY>|eJfcb*rzC(uGung zpU&(7g3mk%h9!Yh!oR4bj*SPAGvcKRxwqF=bE>6dB=Yry{SM+Ai$)r>)-MP+Z}@a? z0^EZf?Pt3^Z;H%UQ#CsYr*Pfc z92UY{@}*2X(Xn2rckB0*?k26{?-2@Wi!a$^KI<+SZnE5492UZ2mctlcYw$e|^pVw) zXrsquxeK>bQWrQjnm+S8m{I=>i?`Dz&Eu;r(CCb)$;5WtTS*jLV?qb-3P_ zGthbN^=#|T<=sX?f2}Popi1;1l+b}xf$yQ9+Hnf95giWgh2{1pubRB_Y(2OkWF!)g zW1FBrGBY$EJ>s4@CVXNR9i(dH#GBClgj&&p_BE|Q_0`$g@t3o&+N3~wP572@6_8&0 zEs5IzQdiz%$wI~--U)%;7!%$D{HConaLC9X|s=ftC6NV;UJc2AWYn5Ao_Zqt6eHrm4hFFTTCk6Z<085}DDI8yOr zgPM25H}BJl*mgfJ@ATnnZmC=!JWwLcFvC|m)|fcPF~-7?P>Ndl<(y^R+^=&zx1F!n zc`~7elS98e#dRQCqygF1xP@w~Op&)6`DdP4ah|jm0$VsJeoEQ-EBt_a41=o`+;fcJ z?C@i^;AhvZ58J=->XYIx4%ZBkAu;E4EeiTc)>$kTwA849RheH7dWb(D^Lmn~RRyd!+>60n+7kQBA!bJ_=fl+w0J$d}Zs=a;j1<*Sb|~WuqIpoB?IwOU zry)I><Z4&Y+&@7wjEs+-_7@otOwl0pkEC{ok&ZX@_nY_y);ez%cNAn^4t#t<;E z0LG;7sv_2Qe*Py;E^TaY)I>X%hdXA@(=sK$cO3H2NvzU_#y0!RCu%-~G}!_*opV1G z#Xg4O`1V{&#j9yG`H<)UlAgC0-w&NeCXa4a088^F#fi|{qMyzGr9mx?-J_Uln=50q zDne~CUWC#o^SHPhM(snMH6oe?UJ=Ya)7;-mcLyx;?)@s`#9m(f%o>qV(nh>8X#p+6 zMk-}1Op1hh_;ID_B;5a)t(q(-LnXG#rd+wf%7_FOExXrY9FlK)%)9Km-HBIz>!$k*V@=;n@piTsk1{^?5!idTx_kM*S#B?JM<~9no*gs3CL+)I3>*4HWT^KJGAYZVq3$j(?V$7 zIWXMiI_J+_#Jp~R^eB+{J#E*utN@Yj!+(n~QkRdsy7DjXg3jUD3BbvLgd#swC#f~$ zMS0zWg)T2*uQ_wk6K5|@o!Vg!Aup1pGB~r|!L{Y(;)Wg<5z^Khj?p8ktF6Xw6*vh* zDegA#5ZjyHP@YM2afp5?E&VwbFRy#tg(Dqln9)|mUSe}Fj-{mtDO8X47ctruk2X2! zyLrxSGZ;gF2lyLZ1cKF%PIT;tUQwyx!IFwE&$F2s@ei zXtT}*m26O}p6;I~yY(>xe==&8Nsh3QC0S@Y_W9xKa9w&su-@M)Z7|idhu5Tz{tze| zgPVTSTs1GI1fD=Lhdtfy(0s15cuIuXCeIT%BJ0!JyyV z4pr|pvrgAwj(DLJ!#yNnJ%@6u#H)Heug#$3}iI80nm7}40Q)S}bx93iJBEDM6Eb;{pf2WnVgD;87 z=xsII!}X=g-Sq{5*CC+8+8I%D^n!zxL^n%X&JTqGY!3e#WiURE5ueHf?3UEw6&$_*lyPTR{Rv7c^6r9EcP{` zlI3h0Gxw`>wUHZ>#XhF+dh0&ojrT_f-JmFUAuyjXhD=3UZT=_VgX%Q{+Rjr-vSB>0 zEVfs!LhFe9$@TwdEkGSVuhT&QNx!57y{>ngzM9KTf%`S%n@gvK^R=8U8y21sjA8Lg z@ndT#` zDFpUOz_vZg^Q2!VT*)xO_}Pl`?Uv~Phzl5DB~ICrw~$J)b+zzr=Kvqgw?DE$CO2nB z`}}5PF{4*r+nD^)ALXAyVb$<7mZ45cZhJ|G)+lE3g8G&s{55SEB44lU^_E72qmUJz z#)V87;_2*A;nSawL+a}5D(|UpX&BCL8c@ztXr)=Lwc>Egu*WG@Pcl9#+EDGD9%hU@ z=64ps4mDxt-LXv=5AzM>bVUJ=OR^WME@o%J^5m21e_pgwMiDU+Db3CVHS7hdS;>Ca z6dv($S7%(!M6a7=s3JJ+1|$l%IHQXug;?Cb#QKRiD-F>yq@`cSavq*05=pmQtWBp` ztD@3WPB}|WqBN9^8s{SqRbDl{uv?$|Raj~7vr2Ub*YtZ#(6r?|s~r=0v4-0uoqo=N z)Qn5(k82BjH9EQD*j+GLb#glJEa<~boWeeg4V=*P)jww`6Z54+f1Uhhet}y=2+?ZW zpyxJF%N*yE$LHbJZm7V-ba@||y!IEV?(yN;SN<%}XPExacqJY>>E%h*r$Jn)PL%{@ z;;BXEk8{)8rZVptkWgpHIvR?e|FrYFun=4p zE@}_WdqNmf7;b9lrQE;1G(?VSav@4?K^EXS(ZZC25i%tqP zTu<34q&C{`AIPCn)oF!%Q@Ai~1+N1SmGWms8_Frl%Ji0}zo>YmifVNXaJZM@7KxmN zfj7J+G-#B2`q(Tbo(2Th#^ROO_qa~66UwcfH5iYhU>=rmj zDom!|dCXuyR?O~&_qJ>#SLV(M-ebI=$K!v+a$j29S*lxg4{xq16Px9|XX5(nQ(tp@ z8)xdep{obq>X}59^MFUV`kNz_lDT`Ty%&Ne{v5pfkgAHdil>G|^N#3O4IHxt&OOi5 z@$lamcgf}$p<-yrJYvfxrW+Or`=IrTbo=~&HB|1|Ra$;~EpfYZCwXUjeW&+;U($%F zj3;ooiVIhdt;y@0pM9M8dpv$6IhphpD#e<7mO3MEQ09{&gX`zWBkjL9#ABRf%$?Ai zxXFRK6S@4j$ZWL8-YP1NHdq(N-66P3fZ*=#9wfot znc(gg+$FdqNRZ&}OoDrm48a{TxV!w#x6ipaYwgRQyBWHtyX&pDRulL~4IxlRAL8xj`q7x^lJ4hfQXc<= zLAy53Aq>oIGAkDueqbOj1ULN=sHRBA3)J2huC;sSik~m&?F#s!xvPMN<#EwvyPTSH zqD@ROFiu9BR}|GLH$7|grt=r}W7E|{^%}nv{RageM^{+<+DTn=$wG9-5Y6!}nj(TN zSR=+P82RP}?Dxu-0~ec7?E`$az|VZSED`x7X6-z1Fv@|wKPt@QX_rRf$Dvimkd2pKX<-;_x)>c3nXsK>Y0))w zrPXgr1CGOZO)NOrcYOWC;-Nn0-k+Bo`T@4s)$Mzew4U}J z-&SVQNBt@9FRhcrJcfwhDFS(PNxvAaEvMR5gC5@ox(BX$#1$LQ2(;2090>1wnw5hd z1(s9G|1CAdwU7*0aH`$!zM1c`i}%9;gNa*zJ`A%|KnnJ1M^ zRnvM%-iYpEdhtoVH+*K9*F-M%A+~&HoH@UIBmQ??e!25~C0K$!$h-kd?Hp9WE|op_ zz&Tm5*0GrIsfX&;6ehiWg}J8vZ{SIv0@pAp$kNFr4)i?ZCjldY*NN`4Onil$zJQmA zV-+=W@2)S>S~``if}5}=x9ffJZvlpREYVerd%`SDU5~XoJ78e72LA zeTe9ox*WSN1dF@X{!P30M(Ts-G+V~uDfHT#D=(4@*DONY=pxLJKrAg=psAI0+QME2 zI65tPV-L2Z(0n}A7>TZLA&NTGI4Q+4pY2sai6ta@8bm)7QN)!h46{_;HE;}Q_F&p{ zYd(sWQ+3g6$5^ul<{BB;c5?+#$sdy(aFyu3y>MF3U11$dOsxQsNROF;6_V#_1w4(L z#_^bAC~>palbD_r_p5x`hqmu5jTjXV1kMje-3-_6XPOVGF~VS{dS~oG@zfp5U|!c1*J+u8#4pEOaaos@%B8QabT`)1P6; zB(P@MG%i%VIDZ>gI_o1hy_HaeHK6_c-3J#Nnuu4W$4aQ8o~8n8Lq#{{T4n19gJiI85YFd?_N{=OpJXh`8V-w8iTLaF{7{OQ zH*-!}nA;r|>_?gz1dwUks~zR3Rmx%xCB!KO_j{#`^_j87(zP|AgetbfETaz%nl`14 zCV?XXcOVwMhvc<0lZ+l!_6hy)lI%x#Jo`Kl?gnApz>KAj_HOV5f)qt;@U2wI=Qo)Q zDiWU-l!lvWG8Ax~g99>l>hxGMs_;z3Z_F9r<8uZ~ds=w&nC#7H8LD8Xfd>8Hxt#;u zS`h1jqdwsq>fgs(hNW@EyCchW7%@!FJd898fs$iCXos4<$`Y%n8Gh@+_u`vRiyZJ& zVe31{0)m!ryP`L3_d`%max-79JzA_AE=AjS_2C~;nHz5<76|)OEnltElwYtHvhTc& zAwgUzA34c#y~2C+q7P-yn{rr$WoY|8***iy{y2d81mtP;Lq9yHo#xZ z_G2gN-h1wpSsP-hcnvq(oyylBpoKo!vtxWq_8Yo^<)0py{M9soXwuh08lIiN<$cHX zLVi43Xl2M6H(*h(_=XWa9{q&_;h7|epWjeg-!G%9D2GF2V0v$5^Pf#?iH%Lm&VM3E z`BA_Jz5sgEDZ%C;NeKOF^2+uG_uSf**dFj#8tdi~r$OM+v9-w-ML_x%_9OMt_56~o z0RocnoGfu}`hGaI<@Z*GUxqE}_1uz*Ly_%4C1j>oe;JHl53jdMI8byf!8g6JR*?ig zkB~HZWwr1Uxm)XXgc=!iyg_`HaliC_hxHFupH)oi?6JP3GI?MI@jDy4OX1b3JDCad zXbV$D0Zk@l`U#u@+zZm;n0hl~J40(}qiSw%t|3A9PlnsFhddA!KcGhXUeo;WWa-?d z6aSqwAHOQUjT#(<(HvUY6FPzGFpP_!9ocLoiXP}3w z%I3q}j|IXZ3n&Xh;$nF`X^x{1tC$Qs87P^aX*OgHu8hY05O*DYfnan-=&@raw~;M; zU}lf=9hGWe%Rt>FM!Qp$RAhH=lFy=qB*t|X*0pPh`3A`B)}agXlNT8hsO-LdXJbZ& zx7~tk$l7mFzs(&Pq`a^>N=7q!fb)+!d7#$ZEQIIg;%!3YT097C z4Q>5(BM_pS%(oGQG&$>^?KNOlCVm~5elL|wBoS$S-}ouc3edK|6r-D}H!jqvk(Xxc z)cp?>FpqDz%AF%>iTb9*VZ=)oWS$Ama>7ruVuG=YeAxr2>(J|1CQR-)t&DG0!Slav zR{D-w;X$FnupBTNFfS-O2TQ625`&&$3%vbPk`+i1?OcCzs78SG1Pq1l2;bBqA{Mf` zG{&W7bY>SKbIO7paW4X^T)ex+EEQBT02eA6AQX@w35k?|uaYnN^AZ~mcZu4?JZ+g^ zP8eAM&PDRH{AwZa{)d3IAwQtK(6Q~XdP=lBydHJw$ody_(OBZ{KZ=Mo5dDes6yHN5 zbJLRN>uE3-SQjUoO71+nRyK0VpTSA#3M0M))d$D2<{bM<_nYVMjl|cz0d2mN+1FZ& z_nB~A=UV43@$zK%p!G^OPEoujOZIgRFVXq~{&yJjNAB&uR7z@2cq3aRu%Yxi3hTkO zAsRUFff9I7F~KJ&H7 z5KbVkz@@flZHS>VHEpcYiUk`4OOCu8H!dTwq_(#|(S>0IqXQ=)=iq0Gkq+NmytTNR zzcq(gcw_P0F3-glGEHovo7hg1cq8Jl*VXRMLE5V4hg~x?!RzDv;PSBr*f$v2{E$wV z58zMqvHnK4PWFXK$?F{~q1@~8>#FNU{aebui!Jqb!$@5L(Yf#k(iMpqk|$QpuVNWV4<47+_r?s&jGe_6Z!K?@ zf2+F>ZeWWm-5XA~6(iI8Jl;Erz;E@hO@u`QUV%E&50+cnl`u81nr*g*_z*Ir@oU2> zSo<-6a)$XF(U4=&0(ykt(iL{q61y@vkVp!`u86*(uqwDh;})ChxWH35-rG{l{#}+F z(k%d+r4{%Uzg!7T{TodXD_T^@AB+*I)useMTiltl6ulY*3>tkj1tu?xUBfMiW>UsoF-#ia^E!lz*P#vNTCii!B6G?||!LMtC#f$go zp_;MtcY!#5TPZjvao&;$NK4D$N{5+-8x`wusVZ<*NR?prUWHPcIF;Ze#(EXlbBMy&@WF;d;)E#q?w~Woy`%1h+Dw%D zof~axmNf;QzY8XJyc6^xfHEr-fjzNrP)Lsz%Ah&MPcp(-NpKe_eml_j z=mb&0Ln+e{^NR~TZC^fp7#`N-u2Hyr&c?DL4l~;FC~@C`nTi0WbEs0V?XMHBOz&t`iGpGoZ{t(f!VGTVG#; zqZzgsh(*p)Y3(?%!|UT3JFRDNPO*AhF+PEIHDoM+5)04AL#|1P`HszBZ=?% zHe6@T-=#`%Bznm2dDR8l-#%OTsOMXBiY2R0Fi?=6*ljP`!o{WdbK&W)`e1M;)cYe3 z{X^|2Dim2}XU*<2)%0p9+~aLl>8(-a>&A-d3|c>ex8cM58A8nwRDL3eoKA4Z|5`>bnevx!a|8nKL9}V08Hdd0pJx?` zT53l#a?NY(#vjnWuFFY8pJa@_*Vbu7&fNz{GFQ3j*zdCzSl!uAc2x3cb-d@WBNy$+;3dV;Iao>f8CbpO zf8)6u{4xEwTRtSI-`HSQrQf9vq+D$q;$YVx5l8zxKyj!|4trCC?s*iAQ!lM@;Ez_n zKYi__qFw#RTjHJ?Kdm?yBzF42YGeg@xbN7vq)~*7xiAOa;-?*3%0b$HpMI zb7}f9he_-XcUr0CaE;5NE57X0#mJ~eN(7!t*NTGUKt7c$dbqpX9`Sz|e5B&`UZV1u zbj?HW>981R)F2>am!dr7?cbuRWoESkN&N)lXRtjSj*O(0ky$F^I-jx?&*c?=tmzV2 zxv|zL%VHn5m=u$P-5O@bStNO+hL}GvEgBPT7SA?zAe-xMDD{UR_@Qi z@@*?asCzFMB*)GUM8jf^4n!G;>p*&kt6TpjM&`%!?q4l$7prfUVYA`%N8G1>f}Uf~ zv492A_`KDY@06*m8NR_juj&3oe>C$|`O6qNzQ=EN#(k+o3zubA&@y$~Z}d5hO{K-s zgYsRk_QUg%BkppxP6$iv_j&d*AmX<)?2Xy@gqSpRFuMC*CorTe%ly6VeU0$ni|`A~ z{U}NJ$c5+F2J4Y)AZ}4R8s%FZB2YNH*o4>rE&&Q$ob-V(L=SzbH~N#X?Yp{X$HxdA zveptkjbRmHuTeR#~|Srao9Oib)9I4B#>bt56>drlnkr!3E{L~|duRL8hrFQGr{ zZZwOkS&)C((JUG*jDtjw_^${`*a1wUL9@emEeCa``QNV^#K>xRy?`GPVM}7keoC>Y zqg$a#-1w2C(c@}+BzL(m3}~T}p|cO%4A-45>5vfitypT`lUF}6wqx@|&G6%m*LuvW& z8*4HtlYO>|A&ZFM3NX`l5C_APJ-Ukb`w|5U)g`aH7qPLuAcSS7`0Sr0h-^zc z>34ulbS9ot@6>tQQzTmLMMAp#BXo;QTd=b{7h|8+%zH{8lg0A*`l9Oz{D?e&HwfZb z2nsS@P{nUyF&&7y_q2YO{Vj5mV1tE#=ATW$UKI|*BkxsXU+vQN)ljQWHc2nR%@P_H2B~k!bkJB$W94g*v}bf5Vks?EsC9f=B;G z!}3Q!tDr-U$*5tJ@+v$0rb@`haid9`7nHAUXow6+Jbm+)a(4G*5I_i=G(A(el^08) z%AGocOwBOSZ9NXt>(Iz?H0I~w)zAkn}_9nrCdF#)n-hfo@f(`&^RQ`>*>^^}NROMmb^ zKc}=$5;BzA1mHVFr;@l!wVwq~|-M(380T&ul{A=$IP6BGr>*xTx z=yb(gM&ACt?(}2)9pSm8hH`Hxd@sh~G1@$&SDZ=@|35ecpn1%vh=bS@{(zVu3b<@2ojPFxkP?t)D;x_-8z^tbKtCy7dWGxqU zG!qlxMp)TytW4jgU!9&k(ElTMu~gHc&d4Bg$y(|$972VtPFzd?nig+`TW?R%c_>u@ z=I|oZBuIdmEa7xg_023-r7A=%$3vBwb#R*eWhgmV$#>p);t$5ZuN!81qY!zQwu$i5 zi75ixKhdz+!T8{$FpC$u1kGzDv&#!6Sw8+~%m^bc7xbW0g&g!}@n*e`HeN_&nN!0`B??yDQm(ZwJF}o z%u(=tFCsHj|A&fOb?TIqmz1n&SL>`h6igZ6i$cmOCNE{zxT0g+DVVuRmj&Y0|DA|C znyFOdP)~AhfE#(FI{wx;-Y&PR`$BEr;4NxYBIZlAAZai3_AyLvBCG6NFVEer@a)B zY0w)qk1kvKm)}}e2%pS%l#7e~z`y8sT5W&G`qq&sgM!f|OeJCC?)F>=`VWNu2<$+u znx$&CV9YsX3C>0s(Y5%Znkt2*(!vvgW|h`*zjs+-x3LXawX@a1o}@0paVeiWxOX0A z*uMaL-4}Qhp&N!bEh@G2ISF3bT*8)B^V9i*!&$`9T#omO6>uTXORXmvb=JK@Woj&T zkG5AOO2}~j2!nG24Ag9r6(>26pZFmM51p8Qd!7W%c$J^tx(ZUv8XYVkgu>pk5^BRN zi9cNmr7y;Fp+g7=pD*i+ic&NReKyw_HH3C<8Q*F=`wH(J?K?t4x^c0c0tF~u9u#q= zXYHL#!)0+>ZMZfgj^(`MZU1*laE2RP>soM4s+A;U@X#Zs+Smb}EJ9iO9bZT;9?Ek|x27KGPr z;E_AzroVgHlgF^2#dk!;2>W)j8VLSot5NSYKIT`9Y*zdAuL)IK@`s}Pz0I4JR_bN; zg`k99N7mkz0hxR*NU*{#7S9LxPDJI3c^I@7$K10=CB~x$oAYgwVJ!mAUFc~r%#Pz) z(4VcBhu%JjYJsT1&jh4`bN)|l*2|S24&u4y;gQAeE@uTK^o_dawbR}P7MzAU#NWA- zEm<}E-&z11gfe(0OLhPIethKGY+id(WeWJq;G#C4!~I{s&fXg3%wS^~^7x)F+`%Iq zI)q8mVLwEqQ0wj89JG!IPQoXi)GF?Ef!?ZhRFOF?$@V9EZNqv-JSD?4f>OSI7sKTc zNwP_zl#P<7?OUO<&nvbcDIUhTol4Hz9{EcY!%eBY?>P?TCWQ_k=AJI74GW(U;W(4@ z|05@V?#AAX!5ckQ>9-5a*}lb^_^?|elbY|NXmy>0BXfr_vp^Ct{s2IAGH?yYhyBgG zHoiHb^bGb+MCVHa&FKFtZ8=v`IBawc-B>H5LGm{6F@8$f5!$jhY49XYWwO_`Wap1#M|(E@#)PqFE+|68dG%$l8pa#WUB7 zq&D|~N%?7P;F0yCVM>>A2J7FLNy}*U@N8pADDU6w;`I2 z*YN47UOT>LeE`MM$Q+-j>@_(_e9)OvNu6zkz~!3jH&dC7B<`z zbE)#m{rv?_vF7H@!40wUz!xs`P`@`xg@JP$Q4)ClTi&oq$jVQ!f4QChRC+3`_@8`0 zv!Tt8bp&gpsf%wW1qaYiT$mJY81B-j;4K>BLus+MH@#Yv2KR8ouaPz*0FG7nf8khj z0giQ}{XVKz0Jm@cjYH^s3i3D^ZyDZ7q|a?k_YF~sBx`c?O%l#lBWa9_c-U^DGA+^c zCzl(^%1P+yizy97NK}d}S1paUqBl*!Nd*1L?~+aaZGj%Rv*g@G#LbabJ0eAb8}|*d zEX77!arBrV2~>Ul;yzF?7Bro&IquYNGa9x=0po&hgHIF~*sJf?iUp+}$Jkkn^uSSn z+ij1e@{XQoofOkYEj4EEw9D0GMVg&s@7~NIO3=iHBPQPB z_o4D-__KKN_=m|pvu4lPs?uqiJ>RxFj`MqkG3ozrB&#YsIExHWrQW7hY;aQlF&w3U z{1dEo%V#fBeRzw#%$H*$FoTi z{swH-t?$0Kjy434ln`v>lcH+D&%C+$QG*S>vrQ-8AG zvkOM5;#PvonsCmZ3tM;i&tax$sjz;pT`%+cOZ|?Sx+psAD8`h#-%h3)_n(wTk|TW{ zw+N};c}}LV=&sJK>`hAbM2u@s$_Dk0B@68izSAD@fkP!+q(a3aO+r9F4wp?`i`))4 zVM6xdCz0{9=01@>FWuwL?#Q6wMGoY1!@{#PtM`yd+e>oIr)D$01{mE=7V4od7AjNhG$c;_+8|1nkF5XVSp?6_1HEaqmq1r>M7 z1)(H+klKXkAy49l%hCS;e_X&4TA{LC&>M1(c_&+QY0zDzwo=Rch(JjWRNrI(v?!qp zM=3F?mtQJ{hK;$s62dJa-lHeOgbajzlfg8yYA+#bi8p!CY>9yyASfEr8YQ$2?qy1n zTM`skTzkUkf8G+Hz5^v0r#y}e&|J(SWlyP-^K0b183K4dDj*DAW~mex0`OZeEH5cH z+6Tq%6%H%iJQI~*dMxTlt5nk2=UpX|aI2~gY!Yz+a3(jySAY?u*4_n%2rF0uXeP-5 z;Xs4CD@v+c9i`H5uA-+2HX2+jolRiq{rM;1!lt(*zF^dC`2k*l-9c+DzgI64yyy7N z*381gDwY_vO==QVB4q^hl-4ydgb`>0aL2k)9A6dTn0lx#ImI5K0z80+Hr_q3WyEWR z%smED#TfOF2#Wr|+rjdOc?0f5rt~oj`1Khzm`c>=G-!bkkm@ClfryiE;A5tvKA!Xu6&g}v{5}9WQwoe? z08L4`)jDHF4Q5&!xV-Yhmsoy_dK$9tM7v>C5m%M#SAuxSdM%TMC$KDF=HWO#pVUST z`2bl~=P>fMGZ zR|@N9T6@p{RswMsK3H;8#Or(cJ$1jo7z$S^azyP4UdsZ)BhhX79}o{W$Fffko1%ew z$hVD7vVvj>PS$`U(w-z~NUXr>k7}@rqR>b%z)k*g_eQ_ioe+5o;6NepA%&P^{8cuP zD*bNHSb$Q}W6dvNjK89`8iB~JGb&p7eE*l^)A8`RR+E=(!MJbUte@wY>X-*ce+grv zImB`pi1QUAD*NX)mh;Wur#w=obukXLB~P%q=E zQlx@9hZZactp z^^%)Ds|X+d6}7;WA^P&({FnSRKz+M2RnyHrZ7+ev6o1b`^<-9x)4zP_=JPuIi>h3) z&uQ_f!Ncwxy?V>t{)!?%6D|D&F z@qrI7fDmza!Q3^jG>W)Z%(m_(Jxndg7>e-zy4`Mp#><2FQSd7kv$`u5Lm>Y=f$c#ckH=&>;L*|5O}Y+z;gAg9^Ic^0zaC%X50SyZMaO+pgWs&D=_kLE21Q8214v!(g&A_ z(0x6}g*2cJ~`TP6(HwFjKuWLJk3b)6DD1el^ zbublL()|K|PpmIQh1<-ugWoU{8mXcJxn>$*~@5_GIg~0kJeE zZmGg51J+>lwN}ZZ{xH7eylM)z1}+i~Q;adO6ut-L5kn9whE5Na0IpXOt;#A4&WyAO z9vgNC=EH{%dt{b1QllXDiQnz4E71_)iXNuYAWeP!Y}`QoE+5yQjD-O+B^(9^=c?rM z7WGa2Dra}7;Nm9UIe`=tt@ISIX-K$1pg3Z=+U?7y^+Bw}W=tQ6bZha{JO&Df(9P2m zK~5x}>inZP!;z1O{|J^$uvuXXppua^!+h$^!^HXs}a}aV+=Y9%w1S{?YYIm`pMlPdTS; zP|i1k^rEd%qUDRlyaB;nqGjs!E0n|J&;Kvm%FO16p@n08gOxa)Gn?Xn$!Laus=a-q z4Stg^`q6(maXZ+#@70nZJRdzgQy3fs9Z|@F0=-O3fI?Ke>JM9S2!W_!UlV!+6K89B z+G<3QT*Ri9GT)otUmXZo0oK%hhG^|(-mbc{grnyK5ZhoD;eG1p`}w)Kl2Q)96NA2S z0Coi#hK^z=8=cDd%rkB z#zOu~+j;2t95dG(1i|W?bg*jBc)>^@)JR3f+$hyg*sYtC$Xt9_$J*|3l#9Q-i=JNP>sGP1F!gg% zriF^39GGYzUn4x%7Ke}LiwINz0*0@?T2ii1wj774_6&z~D4B{*`D=qHnid(41t;SY zw~RiTm^?Q?gaLyKn#mmF=nc3i%{1wd0|oxjs?@&68=aLlt^DyLZ9fhI6!qFw1KKP~ z={y4{YmUzAKNNsTTO9A#YE64<9jZ^VM7)oY4GyXSH#-HYp3+s`Y3jK=S?e7T`_GXW z9Fz?uQuuS%5kTKRYk|b@Btc^0d0Ka&5Wg14{lw`-adMcH27DUJyLZoAAV`&8^_6_} z6~%D$8tj?RqXwWn%FOtQA)lPsW?#)K#6Tfsy1WJ`W}UQpYNrs697u&t#SA~e4SIHB zO!7q9#B@}?{lt6@BTkVG?>rHtxOEuK`0J)VKOMFI_gaL{{2u*X4?$M=+`dzi6nOpA zhX_tWs-d&l2A6wYBAgyOB^i|R?b<^SH~XVqi7SeG@H&%K|CZ}EDHh6<|JzN9!Xyt) z(qyb(4K8clxRxT6|B^gDu}fln*c4j)+8ksE3S_UV0(@i&U_C@;yAmNoLVd)IMGXxN z2|c{Ly!3xEsZp+H4ZMEZ1v;hyYo-Vo zACxCh=38686%}nR0@k+aQVz5t4R{tLu;<3ErIyXK|P2iFaxAo)n8y6>a}A=Yw4p1d4=R!vxzxxj0JtWF^Gt0Iw4Bv0V<_JiQH!8L-F{Np$z_4SKqUf3}R*2P}UvN6i5x#vuiQl)UtWZ-KI ztrZ&l+kui%l{T*Ta1=1FC~o0GYI+c2sr{)F0ScoER1=*kHo0<(S{=8+FiCg4mk|+z zdT}b2cp#ib<1s71%?r~~WzPnPKfV}PwY@}Dw}?=u2U2ijtmZFEH)=X;3+9N;$VHcR zk)Rfkg~jKDJhqIbU@iPmT$Z#|v3w>b2{TC@Y`HT4&EC>t0{YTCo%u~BN<7_y%K7>6 zu9MBAt4$JQY!we}03?@l$v~OZI!!d>Dm<6@qqawQjo4jLPEHOz(B96@?i&XtCZ^gw zH|XQd_bTA8Yv7`b@Kr3|I9{zn6F(&1xx8F*2{A5AKhZoE6`X5TOkcypz+(+T6XKUU&Ol$v=kXe)Y($c^Z`_JlR?$+ z@^W*hUMf%Jr&~m}9Dc`cQH9-u& zXzjs70PcJZYIZ>gYm=f#UkWIS0BkScVAFJ_7sg^pWMrg>_}w;u$!jVH%79iF0!c)? zKBe`@7EgCew1JBEl zcp>&gUha0rCXMIs(e(9En|P{`K6EJZo)|Zgs|k{laNU~xYI)`KQcbE)DM}~0Ok$@D zc+lFg+h_uM)7Xa%_4V(lUBbC`_c_mn*pyXN=2=R$_JQz67j~<;3SS=7-Mi;|1bC49 z1A~K~1_#E?5Yr!3Rfi2ds)gb!y2@+_=fLBZU0MV90J}>J*KWV0aOBsq)7C8+)$Mit^EJA;uZOpcQe{c?zn4fucIbfev z61}~1qR`sjmb9Yqp-cG5G@tDE&YYUNX_e&MPG}ozLMA0f^C{t=5I+h(|MO9zOh)EY zWQI&kOo3Lz*4v$iG4=-?W>4IPM6UparB->6ad8>}sw=rI*J-yMZ%3w9_hJ9k!QM zRwo64LmF4*sHy(Pd5WP{y$JPe^HtIASqA z3l+P9H>JKl0jv$j9Y5mbNw2;Q3p?XD-(#**(4P}*QwCs;lwab_C@n-I{4xraRVj>* z7o^{WS(A-KSc6xW!)xtNK_2DX@GTzJ%DG9Qd8(!B3(ZUof=+9KEr*}7CEc&fl)&$- zppY1Vkfu289Tw}s_YGN%jK|4~dqkR|jkF|m!NbcIN4iDBQxazqo!r{Ep^!HRRi7YU zlW~K1yfhfUl z?dAoRyt2=;*ZkdtK!|q}BnqC`Qs*BcV2B`oTd&v!WPaWhmOQVpF!&q@xD5WO_)Mt1 zCM^|GI91aILq94jC(-9AdQoM?rXI$eI*+cOfw0~CgL2>sF%MRo&Z`^!yf8)yfBivO z4W*2wys|RKDqbH^RNU_OSA4N4bbhDhza<=BzI^d!2j;XI_67xN1w!X**Q$W*G%cQs z`N|r|0EFxT`wwhtdP`N3)7E;+p-E-lO9Q-p(b%S+dns0&Q=e}(4F|K<;DQx0M#PXY zP?Ee6Pu1!1nBTFn1#*Z&Ruy|9VFXKn(7%~e@wWw3yCjF~9-k9VN&5G&+Hl=ENIkA$tR~VW#d%GD26!1YK}ItDfre8pG(&G8=(&cSDW+iJY^5E%?(CBC61X-kAu`> z#k|}docO5m3(+1rcSlWn;yt4e1$yIR%>hxWK-b zmq^xuci--w04^?3$^cOIH=4S&OjB!Q!>sHZH1HKle4Ay>iHvqeI-?LW2u~Fat zuPCksHV(gg9|+p`0Ur#xy1G)k*D^Kjv4A=@5z(KcG<^4Pzy?0;06mGxnh_j;pS3Zhd~KFs zX==^5H?T@@uWZU8Q~?oE*Ta@lINJROf7wqpCQ{3M)qq<&CILXi{JQjAi+RtX7Txy$ zh!N#d(K*gPB?GBsKtrsG3nR`2 z#U5)Nr~x3dJmUF=4OUb_9O$K&E%*uVhW~FZfIU&QCq=5NjIBPHBmidyatfs?-AEpoME3Xp%p6foal7PxF52 z)0kzwN8}_iCsxxPUO}(d=x5D6eqb4OYJ|1USXI`I=Tj`r!w)UCuQ{}; zZ!!lE`77m$gU|~?HlTv-buEC-EJfV}zTxF7`hL4L^|AXALKXZJ#ckoQW`KFIwK4n; z8c(pI9T}NV(Ms@!;YsdjAXGtbf(XDcCQ<<7N}#i44+aM`ij#Ldq09ycmRXUrx42Mr&i!~F;|22E)Bc%ED7z)* zDTxc(dsL$+0+@OwE-!9?);Q5se$uI!!=9l=d2LYTMY}SLGV21i59D=2c?e|d+2&*6 zC-*axrC6K19DlnoaQh6{Lx#buMn%fGTg>V!Q-6cEuV#hKqs%sccrCg8KqGVrH{5X{ zhFCn{_D=D)dDWG-GV_7HAply7T&C9}`JkhUK2X$QQ~+!icEMVz+@#pevL2Al5Ud+7 zl714gbp#ad=y%#6=~v3E1fVbx^AVj1YEHtcZ*jcbP8ET>dDRq;(>k~~lYuAJ&m3!l z@V)H&0e~o%mL+)7-N2f{eS{gSH@Q}qA*Lx1#I%U#dX**|(5cx0>S|VYB`GuE5?(sj zV_kS_I7n)S-%#>{Sdj3Rky9w{T+c6>Q~D9FG@T2WFly^)U&1Lo3iSSlb9uuAUxnXF zEsO14z4jYgnZ1a&lYEp8`ywmR+jD9dZ%qr^fV>< zBU-s68P}mcGlqS=4^cxf#0VI& zn`Gk1hggU5?u=%twhN6cA z`oI5Axh~@6DC=Og{v4zq#x~AgSbs%3)5FxNE5(Z85hN$U9N{yPZHdFt7ocg72rub- z(z=%YkJB3tZB<8%Lm&iC^{yPYgT%CZlUNwn79z$rsxBOXqcNE1#8A zsq?o}BExKn&#`HQ3yUxS+ugqb?jDA}J^>RnbRtx9xZ|X{I*D)>K9cnhUzI{pBCH?} zY+3;}hPO9=KcW30I*r|>+9I5v14fyESrThXeR{gf2vvxn6WA-oAwrTgcy%6p=gCh^ z-TAEc(>~6ObW-|pDVhmW4a_>&oH)0H+(zO^dZ^>b5G(C+lL$!SLzh2VPY1?8z1eeb zw@6Y_W!H`1^Ig8uueTynQtuI1j;YJnf6*EcrG|_}ba=FXbaVuYhn)REHALQ>dLYn` zYU8<&^=}y7FF6d9va&~i_=$-i*HRablbU_8EKz`pYTm#-l5N# zp|fyk30AvYD^{FZR)ZkFt1@w}ptbzuXXfJKL?u~n4eWJ!Goc`aJKlf^PJCoh>zr#a z#qI8~oSmqoC;q8>%h+l2;q`Q6+RwKu(|op@)e^f^FCz5&|6gtA71h)hHR?cUN)wPK zRa6kAs`L^|kftCay-Pdv5|Q3Sx`2Q*6Tl-P9i(>>x=09!^kM=5g4Bc>Ai%#p|I;1g zzTI*6Q})Q(tL`!9TyxDmzh}_vyUWx7Si?{bc_@!V-HiHS+f9lplV2>l=aRcMzf5g{ zD=KV{%GU%K94>b*WxuKNh$SmE+Vo0SUiDUcmW-^PmR>Y9kD?+w*Jgnyp?o@wDz!}( z?p+l&MXL=_1uPoZ`5bk_9helEn;0O%k~Dd}hr@bBo2-b^5&`0EijI#0j{d!iV^z!r zV*K%I%3i%LX`ppe{MHsv?c4>LEld6)FiU@7ymJ`wr1%lXfc$h?dD(ihkm@~NMP6js z-V=)O=NvMKl!3MAXl}mh09+s!!iQO*C{Hj8Y zjg}FDT&ftK{076cY$|fcoKrg~_5ZSK#YsOowRRcviI02nqrXb*l*VY#K&l7wZ0UNb zpy*F?UgGtzz>$C1`bRUFy3adQ^(>l>B&AsDMzgh6Tu#F+KWYL;PuRA=i(x%`uS1yE zIB`n28|EfY*Hlm`#HZ)d8vMEzcj?Ymd^o+sd#X3K-YrU1w;^O#c)01_v2@Q>tHPqV zSlL}Pd_S`YKe|EGKFU}+i6qbLYmOPeFqy69@;r9xU^6{Jmmht_?D-Dl z={rAL9vW^c?wIN+QvXwU!#(DO_PBgMZ-ukNt20~CwM833j7q=xujNkrDEeQ%#F*3= z^*%hhdQ)ITCtRc=AJ8WNtXWt<#PVzus2nm z6&|=|f3O!7kO)W+{3Fg*ovr=Tz4XBdBqeOX1fzbcu|(7qRWMo-E0&9Gh>*S^!$Ps(~pRg;`3(owR8evu4jGX&-mxhd<0G|PtW8U z|JI3~_*3AfC6JcZ@Zbv~Fgm(-_afsw;_fj2`>!Lnaud!gHNP}lqId~&>N4^^KgNeP)#4M__XJ2HQ3^TYQl zuse%auKbx*T9mka-3Ch|1wM-j@7pUA$FyEKe^o<(?+vUiba{iEBuD*)h6gS9W;+OK z%uWq`%}zPSXRMT?n^IZm;65_Rk8l%F@xN#p@I4*$ZC2|?;gZ(B zm)sJy9zU<~6m%rh9BsSK`jSF1k4T0^EWP^qrIt$W^h7G6`nT-TuZO*4XQ@NyLqE*z zEV@&Xu;1INA%^}JI%2Zu5s@|}5*60BZz|rncjCN!0?Y|Z_|GUAJ{Rw5nCHRwv^2Oi zT*l6uCx)BKCei2x)6=CT%b4lH>r23#6p|3?r_w5i+?V-Q}DGpeT;(UA3KCcgZyUCv>n!{oM~F0&eFSp2-^~)_SlBrIr^t%=_Lt zspB4-`pwJ3#Q#PgN54P_Vg2H2HkPndCZC}ltQZzXZY6j8G8))%-U=kQDm(SPBY@y0 z&xn_toRe>g|Dly>EMC36GB+II=_F4t%+wuAELgWE&CT)IKOm~iHf(M|PY!;`p6oN) z_pAGjmYb1iD7~G1!b~X)QJ-o%kzFzrjh(p|V(gvs#i_l58mM{r>0Ixnk=#qKzz4Pz7{NN9Xa7(SNrFs7}zoFrZn`mPXFoArym+_x|edyEx5 z0&tI3$-w1a9`CiL7d_22dFFk`3G4o~$~MPu8`*m-5XhJ;ceVVEX|g?UpF3Ke(e{DW zsQ?Av($JBR7k4i$&CkgK9@2h6bpi!@7=rZ&ZA5#eAwl^Y77nM|l>*8iJS%=Sx??J+ zz7GtDmo)_PMJz8ZQS)0ozr$~fA(O7X5pJR;U^@HrpPyiIQ+k?zUm$P|-IkycHkju2 zcsH@->Lh2OF#4k+EZpp6-v{TotWe1KnKB1J_q(VwQPHhF))DbEJ7gKh zF>6T)!k+h4ovK|9D5iZm=knCW#kAIIIw#tA_*3O{bo5CdTCl5Goz7pSRxwNf2+ol~ z_rIgrQ|b7!RQvISz;zkn=48s#u;H5{H3w~bQWg=fHAAy6B*JT(?|QEH%t&eWtx#l` zr1#~ss{&#R-1h@%P2=;yc_i!XdoEQxZ5xQ$y7EV{3;mfNRCRbJ%**J!AAGwY>?E%= zekQDh8my<_A%|4PjYK((FU*EREq=vMCfrDd->iG8pbhU^;0-3!p+p78p}Xn>5-C?; z{jw`*Uw7P=>gY~L z^gm*G84p$ec5eu)#dMxqr3GsiN$ahX4_F@&T8+q`8Rv;z)Qk~|^%B%C`)?8v!L+qh zm}Z}A&gcLtTk8i8sGM$~HlVRAMN3}uS1MC_^XT+om|TUIeee3QJnE`qKO46T6cq-P z4u??9CRUf)E>Nx-8z1CCTVEHwJa~k&P zgceraCMw*>qRt0F?h%xgYU#bVCNUdIyTc2Wd(&}gX1&d0gLB5 zswj?h(cS~;+pV+&sZK0W)zOJD7iM#(mOg58R!Hr*nJ{|vZe^C3VtM-T%HU_Kz@6fIt4@z<{j-CM% z7EDB7DEPo(&$4`9Z!=AwqBk%Bz@RsiCTxgfB!wv@ z3|-c=p)edgAS;bLio8nZqKfrm%cgD14#|)=)`I3OQ`ZW>+K6)s&7&00u* zEq-=1>=xli?tLtecWd{dJe0)2r(nd>K`Ua)r;T`|_A2cXzR1*wCG0l6ItqLJ#cv68 z|DkqbT%C^2#3(!UC!vlNl}kJk`gIut4cuorvl;P9v87=|N%E3a4yti6J=n3vhEbxh zbOlK9L<7uR+`U?{G-VC{O3&b7uKG{LU=qVkUo0?)(3i7=jsY!AEHnw2zpgRYx5%s9Eq~kH*B@))Z zZgYgv`BdI_2AX2cW)7kH4rZbL-6b}-u<_gX0~o=mO3$RXg%u+6o6^3bRi?6`YoLa^ zn5LD#bN**%hK2l8tsnVO)${5|Su*~Bt^u4fZur{=C5ECW4`;K!qKN?=g0Fh}t2y4Q zNAD696pkWpKvKXuY0EuCND6CuKR@6C4tx@)PZ_tO?uiVJq)K{s^q4aI6c7#f9c$=J zQCkBoquh}NrR@-*d{EGYFXd9mVzFo7j?w&6vcsK%NRqKR2;DEX33gRlc@=WE0-RS- z)CMQjcVBd^5)h22+7F9EE@&-Z#5L|)mX$bK)4Zx`Xm_fq+~fRYvxAkzk(PY;B02^( z?MaaJDtVEKH9^$m7eG|d-n(uV&WRl}vjUuv-bRwkdATnwN*zMk)l);}-rJU$fe`7c zhn?ohfxL>T$LW6DxPCHU$|g$RO=)Yu!OVHwAd{+btU6r(M|lp~O?N_oBq^M+6Tw~5 zB0j@SX0l22DmT=cZ&PP!;=uaW*xdQ*hpHaf6~$ZFzs6Zy!ju?zhMs6ZYs^CjTBOzg zj6azGO@f80gYO0idYdQU4R5U9CWdd=xCVSzv6sVHeL~E;b>kz7h(429pnuw}S zPrJ!05@e`#r2fk06<#-wgF5s~nxDty@y$TWa~$%ccl(;)%gK-Xx5=V@^p?#0QC>3; z+NMkAyJ|ALyZ3}27)@&a*9Ge#2dmkL!WRQAd>zBh#eD~cTDc*acsJ{#`}CBEl6~^Z z-i4%h!4GzjHhO)B_mfVgaU73+3wS@Q_fP_)EWOEWgUwD8M9vnel{h*k=_2_W=T@Fk)qz5oC(kpe zGFh702kX@!UL16Z^&1VquziQIkY7Ck=QI+1lbB<%#@x6n59CC|t~AY8<6wx;c_6a8 zQh`6?>Buac$NAQffs<7-?eA`dlSu`cD)C$ChbQ9=0vGn^xD5R8jS|h<-{>~D+1Rd3 zIG=JppDgdx&rQG+=H3X2|3+ro8_Go~jK6U`@1Qx?JUd%DL4pg?&nwHE1PV%B6vx*; zyY>q{85fq+9Tc0|y~Af%E10m2`6mS_>x)wO=sl!U;yN)YI#{8;c2>945b7pg)Nv{z zsRK|XhtA@vG>U3?vXiUg-<%hmxaiUt4Q;1SwlP4yRe+h-!TE3XH;nP)tTuO%F{Rg! zt#`(mdD6c&!3)qYTENIYf8GyN*dBif5M?x+`1=E8dr5Tb?;zCu7;(lFE&RvF3nvdx zYENEOtbHtVVm1Pgzy7w4YnXAJP(rPf&wjoTe3EAp`XboQcXpQib?JpN9zMb6s{g}X zYpCT~7!A2Zt|44Ja4W>sORi*4hzKT?wyK-0sE;?)_hVNxZX6!=Dx9bEVI{^I0oZY| z&cta1C%Mx)v~-h|7=AxIVcWiPsBBD4_#aT1!H41L-5JZ}xh1Oc20zqc6w=xQZczVx zQsk4SZ?Hek1f}{~XrKA)uD)Jg<3)&VsW0!4*8=<$LVd=EO?#iH|BM?4Uo@N_87mZb zqtp8lWEcU5ea-TGE7*g0LN_7B_UDh}Fg6*BltsE8r8~WWLR7G_ zcAM_4`bFKeevfYKRPNmOQxOrfilDnqaazW|KzIL7CA4O&L}==mOgEsNVyGb1)&U;} zjOwvEaF@&mfAOkLEw1ky9=&4ErL8jl|ERD4`tbT4TaIsqGi4G-r5zp|-hoir1VAs= zpGLet7Mi#ungUonsSId3_OaYz0+cH^PV4QMvt-U<3i*pAoQ4?7l>n$r=<`+Do|1Ma z0s0_Kph#RCi0J=ZY(tUg{uc08L3M_3Y1)ER61}f=w>W_6;{2!^YJ-P@=tpjJH33h5 z`B-va$tb>sIzVJJ4!C#VcCJ}RtY6CJae)HLwWvwU_R2@#Rh!FXj*sw1DmYq8W-{Nk&pIOPlvY+mr#gQx~j+fnD@ z+<|~Hg1uY4kzbxIv0@Hs(a3DjFCj9T_MyB`qujLmv%Q&KY(Xw8Hpi!!S5r|DI86Dh ziU#YR4X=(=b8u4*C#irRzn%~a&{{y?%Z)<5A3h7pwYX5i-0X_!Dw?Yy#Vfqs3)?aK z`Q(F$$k4TM>dPX*?!5_|0)xJ@`5Op6XN=w*yf?ipz0X}nAE~O!U2b$ZxSQvWyJ_yE zkJGXucQ%sr1Q#%y1CO5G4Rp+hV3FbHn|~;P?Pl<-CbRCyd%i`gnkJn|MeLr+G-9y( zX1{^+OTAvD^CzseqLhTKwy&F@Lqzx4b32k4D`prwO74O}KLb`yu=~JA<^oxNS&S$= z74MCU(-1Iu-i7wY7=iQ^1H7MY3syk|KE!F+1Bm5xMZ%kuNza?!Q$s6r-t<0$d$N~0 z22@!C_?!>ArfwBdX;#M{en6O1}@DPL5%GhVVJ}n#rO5Jy*Qt$)T z{_)t=__#5R0rM;Fe`e}q-%7m}!X(|T9Z{NWN!#0cDD3St+%MtN8)4nfr6KS>PV1I= z=aaQ%1Y>5owZDf5)9k%X`3s4 zpl9w0Oe%Jx{a;wN5smk81Z7JaD)27OLE(nmbnjxlTS~P|zyNN3^TB_{8PUf#;g*KwMY%-Ul>(6~IW>GhuD1Lrt39I&n@?v|o)Qv9= zk|D=`iUi)Ew(6Jc3w|v}9deQOcST`js#B$vkXm)TrsZn*vX*{XlH^WbU{lC{jZ(!uvLy2UT{rF>8G-kFrd`5woP@9wCXL&4t0`0Y(cWd?rF)luO1Q9F16psPQt!T6Gz zl4x};Gywx7C^fP@m^if^-XFuf&O6oGDa9-V0?~PDLm#}L2L~V8Vg{vs2$H@0!Be)z z5;hnOZp7fX&Zq#lvk;Jzs#+4sUQ@OStNxBJkZCyc3AS+V_+U7E(@2yvuk+uN{X*|K z9$*&lSqZstvn)!ny>rRz(tx`D>yW#Q=E=o~5;-2H*bRK#f6{>)e6{^M>W14yt;0}I zSO{TLb#L&*%)K1=TdXh%R_z)DAZoR`hMmEh5)*XVxgYr8OyH$R7-0~$s0LwPMCM}X$u z30|rwlaiE(^y39RiebioFGya*dUXta$Lr%T=dIDRVS9!L5L@B-;Ju}l*)3tFM}lqV z>g=R|+!Lyf@S*W{steE#pJ~ole`YdB9HPDlSs0JX6m~|iN^$c=ZZ>U=L>mVsLKh{| z{Cj2aa2|+Bm59on<&q4^@^jNYTD)-WwaQu4;qS8W^VaQetMmSf1YN>r&G!556fM}E z5jwgZUg6D_dKu_$ZY_&s{c8F27PmRlQvg(p4ay2V-kbI~*OjJ}VNQSLAKwP41?@j^ zF7|^>lq^e$ihOqRzTp1oL)P|OAtUH+e%{2F)4;&6&U((lEQLp}>SgL4H^tQfh(-wl z!r~YIvhfF#Zv`R!QnOtn((k!a#9n)<>=Cc60uTE?ZH~4%r8t*c*C$BA6?WGU({siY z$o`hlosECq2;=@BRhw%mYZFygSqH-_!l7jqz@{=H%`fwA09Z3ndC;=n_eRxFZg;~l z#2Is28vM;;R(_?8!VYpXu9^vS2cjFBc3SvuN@F{78!yA=Qe*Edp{OjqF*yj|8Q%RZ zY>~bY=6ohPgnSlk2|H>uJ(_k7sc{!S&o-b&nTX{Nfe+{54Z|y+s1br$;v$lz)0$Me zPOUpF>nc=)uN%)i-zZ=Ma)0TmCJ(_CsECvO=V(L2e4N*?>QI|fEfx9X9s5M3Rd;bU z9;CRoYCjd64;w0k+uz?UjPe;C-fDI;_)kQD)P|J@+mSC}RdWck&OP7*k#`Ag z0!pDki*AoJF&qvVufwh>f7ccu0sW8m|6bEx^pw0aPQpRmWj9@IQX zGbiMCStKp=LwR&$dn?j`=+87>>4rzbdFi+2@mPac5s_)l0do+8BuN0#Co}fLF4^=r zzg1jh6r?jjjrv5PuzH6K+a3=5FvAG<%q2wy`Jc+HnL@9tl!)F?Q6g;M>-qBNRIEa$ zw4FHL#^=!QZ3SlLG#7XO6`CLGHyoTWz2pR?#u4eW)MfN7hVJNi{*zMn`Z%bzoZIx! ze=@r<5xIf84|8y2p5^6yyVc!xpj2?|zgb$3(zyP-)NIfb7tXQSyzc@9P)U)T`vd0Bk00h^3LE_JtDrn|%>!o)Z@8ZOmi&w~&ovQtHMuC=TmVM!vi!6&VHxMwaz*Osr^tdKa3lz|z4%#k%YzZ$@Xl2HZu<(YRRy>m> z1LL=zz^I*FNSv}TTk6M|A3~NcfEyEsAKm9(+|YA=Rd0MoWTp2(c=UAf(XAYkb8{RG zVaT{T5x}wX&vr)UYYcOgn{4Y0TKQ57Vqy>OVA{3NphO6>bczpVS)UJf8L$ ze8!VqYZn)S>Km_1bdyT3V7Qq^pVZfv#tVo+InzJrd8-w6)?3<%T5kUW76)31+rqeI zVeC>X1B?UB274Tr*pxFD2fxN})o$t@Y{83eZ;PZa=MNMwaFBGVcgOc_krIeZh+LN@ z(tRp!v|!%J=BQc==NHJsUYeRVQ@Si1ey>XMu)Ns&=^z-pUr+p_eml3P#Fqv7Ya zE$DjBF|dhBuhdvY`ykx1DGT@ z;>64?$~f40woZLMZS|YIv`k=U`@dW+KIg0|jGl@=tpw#kz@@FB2d#W)`{sWD&%!jK diff --git a/openssl-install/share/doc/openssl/html/man7/img/pkey.png b/openssl-install/share/doc/openssl/html/man7/img/pkey.png deleted file mode 100644 index d31b5d3841a7befed5a019d089947d3a6cde3db3..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 148963 zcma&Nbx@qm6D_>By9Fmef#cRhyo^IX#}={`y%__%|Ti2M$Fsi1%`uQTo^X zocX=zG%8FDJq(#P6MSil_8So^@<^(wfuH0jHPgVEB3df#noEspQCwj}Bq><>{>a_* z7O=N4{<}!{7~OA|Zt47+%MMq(7RN@ji*Z%gFoxgRdtd#(|1%Q|ae;k#An$UhX}1Ma z$1rN7dl4u6S4!x|{4&`tJAzb|72{bhRGp4#?&hl<^^V!%2v528c;GK5Q>DF`tAilu z3+4E=I)^_?r>Wv6Rfn;GN#TbU`-g2JD?Dj z0a-vv*$1=9u^3eop#)L=bu(P$&pg2|yEPo)^NaE8X3)ub*$#9NMF9}(t_~7+6+%xyH-s*`g1({c~m@j5MFhbyfnm3W_z1LKb9xv?_ zSSzloBMrly%l3mJR%}rvejlzV!?aZWPlam=Ci`sMFo$_7QKcll+R6wlCqSpL?ISs_ z;$O6bdJZe56GX=H;;k|cl-z?_&H`8ANHPm=cCLb@*)kfOw2xYR{Wdev!?)(~U!ADd2 zr0Z$rP!GYxQh&z*9rl)tg7O+%{tlfLrUCx1XRLT8x>2k97Tuj~hi_}_nJ@=idC@u7 z$I(K}Pp{DLBmlnL&1aHyPrH951Z3CK@?XZ%`)@3>EUk4$1*$x;G~2??q;|qpE!8Jn zw8e*FN}v|$F&Wkyh41>4EL+i4N{@}5J+Nj}o0;B@YZ+u*HQUc&F5%GW@KkI5^V~e* zt)&b7pycHKI#nZlTbPsAMc#N(bleC!Pj-*7G3M)O>wl?8)MoSTmxv@b7FJo|h5<54 zX)KH!K|;~`1jl4QAX9TVsq#yLPH{+Zh)l<>@_Z2)9RU~nHfGi2jYh7JiGtJjwmCz_ zQ5;A3foruLpFNPco9Rt81=?C#%FD|1|F^R45_StD9;Z5bPq9GdQ+~g&$6l^1qsxqvAPh>uDJ;PqY5_^juF#MI4B*{2H+B$BMg={zbyf8%KOS zEyXN7DTnDvGT;=J$e&qbw3LQI+JkY~jTjoat6%=P)~nSJb_wjI|)L(ntY8sWHZqvJa zSTR37S(r$9HJ`sPRe-o}oL>tbJ2gh9t1hv7+uRHH47_lGQ-RfBJwa7n$S}Q%~Nj%Q-poTX6&(N4m4!x?F zD$_~G5?%RuOJfuYZJw5no2M}DoSjm~my1ym7n(~mvz8X;*6!t9SM%Mk{hqT5V$n0= zpC(sYo0Zsv43dtXgb;U2^PgUZ3w3X4(IX-R_Hp5Q{Wb%%xBM&BL$fbvY*+Q~Ny zi&ygjvf>wD)$p@Uzxe93v^wh&1v#+i2HX-?jT(5EJ)8dVX)b5h3;Df@1gM`y=J~L7 zB*Sf8Qm?Rd*fAW&HG#p@TkWR)ae( zB@98pi`J9kRsF&}V*+MM{FP(ZKE&V4L~hma{ucQ%uDOJT;Jein2`A(IfPBvSh}*)l^eu}CMcA>Ui{!`eg`+ayIp2k zc6211RNVUt4~umf1!~vc>L52awX|uZh@9p{JFmU&t7d0wr8{mV7SmCS+8P{*-8KwP z{?gpTtwr5&>By9M>iowjzS2I+)z`kn4wBxH73B_+f@4;b{bsx6TR?elW*6;wmWIiR zHi2w<0dkc0*u8F1)7cvh?QAImd22OuZUo#z&8InKO}(#_V!`sSOc@nnrnU%kWxHmJ zrmBSvTDea~6HT`<_qo%<;fdRIgyp6)Zh_i+)(W-)tZ%I1krUw9criFMa`O;yPQCtA zR99ENjsK&@8|^n>)t(#bVRe*Plh18o89Kpc1}yn2VU}P{MF*?nTbeb1(v_Es1=F9F z{8Uiz9nm0kalPe=TtBw4Kw>>o)tk_k_!o{dK1L8x?%@@ODhQ7(?CkBycUK?<7w2Ke z);DYYbu5b!u`zDu5K7WNKlP*!tR^jn76cl^6R4(W8&@Rpe)ot3gtezjW7Ezt2 zR*@s%{a@g97OG8|lm4gb(X`}BW*752Lz>WuPtKYd&diKNMFYyKKn;y1^O>E{huxeH zS$`jj^DZFN?0JQZZwh?$**%`bJ2qtP2VjLnA{fKc#I%xPCk={I*^tS$@w8%%;x=5HKzZ z8JORR0USP+3IJ(3*o3Qm!`ls-NmK5n_Pn>kwLILVY~u>_zel9fuyX0WMlx>51>DI%qYG@ zK16vDcPG7=B99os%kgA|WOtg&NJJnt$03h_^D#?bUYt=(pX%v- z=Df{{V3R-@w~1U&0{oNc6X zPFo#SmGlec=XN-lmje*ptRO#S*?KrNsyuV!G!V7Zy>&uzUf3>btv%9Rt;xGg;r8S^S%i9*}@07J_%B?RSFRr_G2Md)Wop_N5@(wgICzm}K9H--HQ zz$WIO3Js!8w5F@wWDw zsUFPw332TC6N1yfNL1ULgfwz;>AsO*Pqj^M7q7NPk86>XjrHi>d3tdQ(mGaSXwi_! z*|=sPegwduzSo`)BJ7q)P188#E0>cRn_pzgCwsKx=;Zbw`zFZq3kXY$=o&PX9;0!q zH&#ZIca=ChA?Q0i?eFvg48Q&d3@E9=XZKh2GmCa{`FDy6m;Kf*RUrcgOAXowkC*#E zn1sD%rnEE-7~wA7_jKq7g!_)QM9Ng2Ia!YqQ{>c1fi@XHlB{_$ zG{4&}o?Qg-}=jRv$f^KOT@ zB0tm>1^(xX{^2ql38h}Zy&55(f|8Ye9^9XqsDcwr*HK552X3A-e+G_2G*qb>Ji^%T z8!`HVi@j9^1XMTlaSXEEf3xP_^v)Na2&RhzIxy5O>N4?cD=0@P^z4p{s;e`O8Y(n`*LwDe;8J4-eH{6>*`L;|>dm9mEazU2IdPp5f%avJRQo6)@c{f)EiTooHxbnAqh5rk63l*Ol1=*t#z+ z15w15&@)-Nsw>vl9)keDhhM$nql3kJ-@{sd_HSX5PK-c^#1(wek0s*D?d8p2d;D-t zKv$SD(e2@a0`A|ppJ_U~TjSKYxyHL%%tiDwOd;SNgExV_H{*CXpK2Vy@;1C2usJ)j z)8J*Zjh>OrNORAmPg^3_|W649>n-S>r?tcH7oZt z{a8(sQjBy6VU>wjpI!bj@-e!~S2xNYx-woTB&=IXWx=0nPB>hAJ}UpwZ_(s+{)3J` z^jjxE@t8WIZ_m$48ig}I+ujbz&y*8PI?Edj7O$unxcdK&6wI7}f-lrI z8ub$Fc1?sF>0V$#>{zIlQa2c~-x#+PJU#iw-H31}M-ECrvb-F2QaAge}zgKHtQe5!xh+GilH z6p^B{%{Tc03uHf#;?ZOw38^FU*7jv?w4sHm4z7o~{-#7hxcaoxFpu}uPH2;bsP}bx zPmS;+TTA^m#o+zwcG3LXz?PZld#Q+7O3LdetuL=`tAhEtEF60nS|%sJ(Rgv14u%I- zWZM1^q;Ppbikl(O`xjD<$?0&$*jBs~^ZHB1RXvS~v;L;)7{4!_LBOpk?Q85bL|u4G z(Hh0nsUrJl3VB1uCqEn&57txx_a#?x)a#E=cG!D7$ve271z`wjD&(?_tzwEEQK5^N zMu=JI+8M${=k~64L5;W_0ZPR!yKW*M6Yjz&vQcp`F z!aoDjqIITnOs^6{Efm2Bi}d7fv4^^OCva3qf5nunPY2v_(qZ(Y!gXnD>Sxfza3aG&#&rS5TAczmR?M^zi0yHLJHSvJ{N(1g3kj^m+B^=hyw2R zD9MxUs5dvAwVf)>vAVimglQJF0))EgUv}4Hg`;%!?+Z7EA@qGIBZI2=49FCQ|X}~U-?vTbcm)c5$3Q0hV9z z=uy83e-HpX&-O;|x*NXd!-SOC8b{3WFsZmPKe4tq)DC7BYyXcuoP%EU6HGJ+ksg%T zU_aIU_z-n*dpeR|It(co;p^Ym(YH7>JMfG_bSm~1m~ka4 zm?j%T+@d`!Nx6M?htZEcNb;O2xJ^4WQf;Q?B-Z zuWgugA4-Rmc+|%?!;4D$ZS`#mGkm7>FrwJUA21y!CC&T-;v$$zP)@uPdE5{2aQBQE z1N>+`^L()_Tz$IB%eB45MJv;bNWfYWtq;~}o3|euVP%E$x>N5jr?K)&td0ef{J%q8 zkB4fG{6%NuvE+wJfnPMAzfn`(w|gHJF$m1`@#WXPgDQN{G&Ma`Ajdr~D`h zhw>>%>iBp2|KOa9--NdFq0;$J`Gac}XM_v7&eIQGjkO-!c)64J4>I220-tydWajw} zXHXmzs~XJz|7y!wcVbP8;hsLgKm@z#1j^VVT!5u!TR$kBoSbT!Y{%Zk?s3TYqYjMw%w_M)0Qd zAtdj#?J!Ekf>-m-B^8hL_4VdKR-U%B%IhK})g_ZVwr#@?wa|ry-PDsUD00OUTq}G?VD$f-gCJ zxpK5mxVPjR!FmL9nUQG1F--Sd{MoJ>Ni*83qhhyWIf$OG#y z(I7l-9Xu6Qq~gpvhd;9olvl92210=(Z|Q%Gr=_o4kDCg8;|mq(OjlKc-|6{PI0iAIp{CR_i!+3bZM1TrSI! z^4=yGk<)Cyb*BY==8zNXN9uH49)Ze>&I{B1qVrxYpm4XPCdVo+a9{l7BXZR6M3r#~ zIHHn-lZ2BNo=uaF_Qm9TUP4e@g($goa5a2S43t^gXqMuC0F_D-#V3{PHRl#RLB#{8 zt(6sNjpmp%|5Akeg;Vwe^2blB*SP&HU3ouSh>sWLCevS4)w&cMNup}dOl9*<)4hGR zhl)@=eB4mOknz6=5??bAKY@4{)m6NcKav+P_VHzv7g1ncAn+dB?-726lZwkGm6&S} z_tU5;@I+rF=Ugj9#NHNCPwhGme!a$*&59zN=ByNl39R9>twvq)RdvQ+b#B?}LuHcC z44jSgD-qv3)ZSax<+<$~wi4jl8YBEs#MfGMmeQ_3Faql)7DxQ0^!{)O@rT1hx#=)MwtIBZq0xwX5gMryTbX zc{EPLE>8>$cmV7mo?$5oRq@Js-^~*%Q~pntu7s-6WWDdLwWjch?khjG`q@*w`@Egy z)J_`Q>f28$h#t?(#P4lPrean5U5D_}u?+0vVog_v^``JRgN=+bvsqrJ@QV4GZda5$Xu*)st?B$Wn;`1iNyM@TC|-KTX&BK=gScGRZ4X=5nsZ^d|ApJae6 zfj3G&k1)C7_kl2dqo?Gl*t%?`)6sc3`g?mhec1lxKCwVN?(I@ic7KzK zo$zL0cFvAyULEJDtbg)%$dgT24o|H}y;&{KtlCfW_8uyttYkPxBrZSvusd8>uhPb{ zzLZ)y+ZCwZJfm^pGN8rCN;=)qUeT`pIja**e>15#FP9wOrTJx#R*j*GH4pq{2qB$I z!8)!Q@$YcH-+M}KN+$}lJ-E*oBVM4gP?vC|=roTyy^_v1!d!rX6^VQVQ0yqLmGV#%S$Sts+KhLd?30JYa(_SP#6I@6yi?2aZ>{N^yM`t%eR>7DwBJBlx41`5wL{~NP$$a$1 z6sG^B`WHl1zP@?6KB4ktf$$z0hutyIINbWoZKOZ;{4@4-(b3m24#fe4q>vb%+!(~t zFc){ED&KV?aw3_JxZ^m&lsJTLaUO#)h>r*hDFdF6UKS+K<&T$z(4BnfLBcy&o-iLN zke$Bp+1D`${L7Af?KRw(h)q{x^=83tfwu!rYo`**0T%Oa1l7M%ETY{@b8{lVGhA8fvjk2 zjNPHT$Y?j#6E3#<;ot<-qwT8)0{ zlsnr3!is#47hdAg)bY)n6RsDEunJgP^@(5Bu{)+jWWI7IF`O)`;(OBJ>0OW43R2KSe^ z6E)fN=n*yJ9WP=c!JQLfBBR*AG>B%226*sU?K}h@I((fMgA@u(+?G=E_!(=4t@)v{ zc9Gelp|0LPL&>tnv{sQL%Q7WV;Zey&qVW%rX_4tOmVYDmOJ+Rj7{clR@NcD5>u%B{ zKH}8UpGCPZp=-Ye&Uj4A^k`UO)N1GnZPI#7l)TUe6es~n^#3Na)g73SqYWSneD_B5 zprek?EBF0!5_x#5?Y^I3*VwbBL>a=e+OZ8o2LDYGq2WGFz6>!{U#1GD*~=0ZPKA4)ORvH7 z9^`eiZXAQu1|cXzCdOL{ss3lO0ad<8=Ft~3)8nbhkeQ+%{MlJ41o=k>o2T)jO3EFc zRzZG+4(X6-e+q*UtopKqH;V|%E?9%q83+(c$HN;I8U8JYT@OtiktG@#A`H0Wjr zNR#lkGH{NYzr!G()KT$0DKbj=QEm6|(Luv35iaS4J|QLI^*ypMOf;<1u71L~br626 zsa2TkFkZcp=nG`!!uv>B&m!AE6P3 z=FqKVM`DKd0f%5V0#ZOg`QWK%oWE$n%ZgkKChCygzL$MN@3w=JrF znF?SeNB@*u)cpN~wR=P#te|cNnOdpg+(w7Zx2$wD%SlDhNV8K%1BB0#2?q2>C=r=$ zL`uFS6-bQe|AEdYr0P3L4+t;HL=lWfo3GnM%lnIUnTP!Qdpi6GdEnM*&v>f*=}0bn z{^Emf{$2M5o$4j5o%@&FC7$wLriAYgYmx{JjfLmpx(aH~{O@e*uE%9%(d^T$U6;H? zPdORSir;ps!Kr08@c-gh#|*TC`%usGhSO!mq}~uD3&YMo$I@E>Y{%pnzw4~nHeC83%pRfNU__@=M z4YGzazf=o@deuzW0v4wJc!k#JO22kVcev+nvu!GdO-JPSK6O5?_C}fI2c9O&PA8(1 z-ee~*on<2mRxvX$VG~`!)WXF%wYFLqcv*#pF6VXTie#2wX4IctY;9=sGVDihbu*@Y z*qPA8PDi#xsCCBx(x-edMHV*uGLlooOA^em=x@Ga9OFP(V?aJQy^6ur{In9MtaiW+GSq_m>#vZ&0M8NU!Z(hyg|O$ES9r5tgI>g(=}nn11}7 zSbu_ldB%<7mL(ajA1F|2-8L-|9qO~bo+cTSPDX+lvQ!Rmn+_A4Wo!Fr?Q&g0|Eike z=3r7IXDvZa@K_HA{Fa@U4Fcy(Odq|8sbhQrr^VL~S}Y-3-JOcE5?!a8E*PwIjI9?( zXfpsxn2NXcQ2sn?-o(iVdQUf>5#nbjw$3C_tm1 z*U2jSkpitH?@XLz`~E)OkCw8s4BZI;SrMD5>#)AFE?I%zg-oRtn`-U;6iJ8&4!AY_ zy*qs=K;at-qgn<9-$)J3W=w~hL3{PRWFM~XG$bM4tV}*%#N~9(H@3mrOxes`Jw`LE z1lL@0-Ye+3Hk!M}Q4KS&U#0N6Et%`wMv-QsaXZf*V3xYWPlTi4=lwR?TB^Nct1fW@Vf0V}vDD zbBqIduuL`*bg>qh$1pacD*Z|_4wAilyAi}BF4d{;*Pk`VHlfgZ@)x9SK z?x4bGm_*X8Eur#IlU?KH!Zdahw?w;z2XrC_jp9hAHK4!k_aa@SsX}`(w=Y*QEVtkn^HslX z>VllsTBB0e(Sb+qX4PTeB&|8LlUI8tie!f^%oAIW`zkLIAZKw z8lh}_2w3OWuBHj~mRs!;PR24=Io}~iUGRIyZx1@8{$j*9Ff5FPLi}bAv>W*|pT7B9 zzkd>*?Axry5(njNIdN|ocZaQjwS#Yq9A~nhvU#}_AJfYx4ZD9UcMtCi+5O!$MwrVH zK8J~psn*dFsbvn?vRu+g@w&_rXeHXbPOW?6_}2xearO=EQ?@|aoGx)4^B&4wm%s`e zBvRn>e7?Vdw$k3cYox_NNm0ANyMguT^vK|z%`>_Lj; zBW196*zT=nEZTtu`?sWDT6|6QgZF`JAZ~ySE9)_It_;Qb8<#Jb$A`bij4F39Bnr`jQqLODtP-AlfJ|h*XCcrAz!x=0v@fs zP7}R`#kQAn7$1=EEOW^1D>Rt>BWR`$_tJ6EL}piEdyQBiW&n6V!t z!U6ulq1opT1OZ$x%h{NQo;2J@-p?1%w#<7>gfS=l-9_**5KS7E6btmtJ(sYNS?)(MF6HD=kAhX!*? zM4nUwSR!S^iHh%kwv;Ud|4c)`93Em*LNTB$u-DI_d%KGscrkQ`u(EjR1ybRpug%Rf zVmqaw+hUV@A&BqKh;+Z(BV|%uA4--D|A4t(H3N|(3j<#B0N7U^*aaMdk1d2)URjZHL1dLKF_gM@bTV#wyb;i zdS{Eqn3S5chU)p@sn&2dO~vJ6MAT$(YZEgXO*Kwo!2O`~zO}Kmgz8?Sy-n%XLQBMX zjH5&C$btfbdxDhHNC1PZ4W01A&)GHcb z73{QZBFvpH+}|-aW4S`$o~v0ykfG@#N85&BAP394Rix0fECn&rnLuE&f*&%e z;utT(3a7KmVYh4?YG#E3rDdk2M7sxykQbYJ5ORS6pr8Z|2$QiFIWhEr3lJ65>S$b0 zK_mT8Jgk2=o-Tt{^_<9Fv7v+$3eid2?4&OivDPC$SwR+J-xUVQ_*aUT3Y^YsYo;T4 zLk|cX(++Sa+uyDQ#INk~jkb}WT+(9pN8k;RpPg>_5`ZKRYv7IfMa@ghI^FT(S=k%q zUMsZLrSE)0$pV;w!M9jo4#Q4AKH+27w7=bH&6JNY^UnJ5ghmMK7~ zuhj~Ev&irfeO?U+H1uU)NlV}xT?ijD{_H5d#)`#UD10Gjy3CIs#fYGLV+K-nY6@Nz zt-F4lec`+FF9J#)xm(B*iz3c}<^%!Ko(KuwiC`r1*zpWegq@)4lo*y;gGP5Be8bPb z;!4xK1|OzJa`Z{su39-I8S*X!b>F_ZM{X#DIEJ6POnC$3 zOb*q4eiEKcJT?DYeGp|N=xiw$VUCUST2%fAoG|T08zzl?LNGIgZJ6pg7;;Bjr;HA2 zT;`}$7O4noN7vtuHr0mV^j?|h!@7>c26?iS=y`)6jNW=0eueTFDeD0ynH$UL*o*rG z0GR#(0MBkb!lT*+sv0ZP21ArYC;muJVq8KyhVSfAz#}RFS(0-1xs`O!nv{CepaV%-WFe0 zyR;D3OjFdTD`KIl_Q8Ik9QXn4v`6y*tfR?@WTMQd!VOhXM?Q-z_pGvYtztVnhx zn^o!d4W(<&IOv!Gw`e=#e65S)!dR+os?+Pj;p%~n0kj!Opi0~*ZY3|-7H<{9GkaO? zR2!ME;NMGW(Yz}y+j=%I4-;Jupn9i{QNu5PQXf0kzRoTA>kFO6uT}X8KQW(ZetPm# zai_h_h!uB8el(hI`60$+G3mA&S@ChkGj9nzBKxO-Uv)FZn2C|?4-H$U+qvRvEuZe6 zCovWcXFazY7L+!Dgg^R~V6bl^DPUQL0K`)*kwihUz@$O_4aT#MyCnez5){n-3 zjr^+vNqz_wTZH+}sG~GpT(JgsP;V$zTvHdipWn|AoK9_9)OqRyYvb2UpZ!d)r_bqa zV+Q~>=hkb`M$Y;=;REjS?V-C0k}IgoR(%s<*Vb-SC^lRJg!R>3f{xVSq!2gJr@1- zFoojXfBM-WmEoFSR`#8^xIxQu`bFG;>t@Bd|7~3MVs_`KZ*V6^)X#2GQm)j|ezqiL zTk?}K`Z|yNH1SQGSYqUD7?VTvI*Mr?2nXioo(58>1eSY82k(&6)A>DQ{$-KyW)mf5 z6uRHwk86u3`08aLdGtmI|5f=Ip6f!$sLh`PuNU5)+$cno8elI5jq>a1w~#zroCz{7 zp*)RFdR7)f9#q@(JL@bV6u@4)IURM8rs^l$W(BYU5CN3IJ0eelE@eLNskR zN+M;}j7P2Zzf%?MdBTs3V=D6x+)5zSS)q8(#Tn~r_qy^;GHLPnxp+EbO6+ADUzq=K z&Bc6%ZdsIF{}7uN#>Mjb&_ktPYG-_}O@!N=fZU#=fma{sv8pSGt!}1y@e}}i4LjBl zWnId|)PL0AP;$kEB`aLzOx%{?bHAdu^|m0KiD}5KKGzV^=lVbA^5;c9flqUQv^kE- z&cz4&HEkqX)J-+Q~WzXnfb!fF=L# zu())4bA6qQg818IO3&}vZ$hb8x)wddiS?fg&Y$`xI#VS{m-!$$CVXMPmaKg5YupnSA(w7ACCEVp2>??&8f-~|xveAFjw%KyHwWfHtsJ+X1n=j`?TV<%}r zmd=%+4_g%va z%~7}*!PDLpQvF}vhfAj^z@#JI8g6ypf~;z8wj3-X+!(T3VEl~gRtA-Y@Kp4KRttva zqqCuU?`ii=v1B@=KuWv&k>PFr{1E7}W(2g*dpXSgmg1l*8qyG{NE=*_&v_bxlwUU8 zG(nTuJ$e@A#&sCKB`$-SSaaW>&UzdC4lH`0k&@wW{Bm40lQZGn>Bqx}jv1|d#|kON zES7FqCLz`G{hY zEkfBO2p5akz1?_Xxd}X06+$P);&x$2M3I0t@B+QT2KX>FGia?O<=hmLv;k}i<3wNf=4+q zi?HGew-*1L@N%>n;f-y^tnbL@BJf~+An@J_R{ITGSlvPK?+(lVb`6NXAx|K{x12;) z0&KW#00u8s?|aB*Z-X@+9X$xD?xt}6p02wp~3bpBR zVY$B)s`soZsZ|AU)_>K!J!MvEK>vfx7xpc1uIaJa;uQ~}tBQC!&UlP0S|z0=kWw#y zqz`6o`hRzq5DqY*$bprOru40w?}xvd9&I7=N5N&c>cZFOuw%@tF`KziRPkE+Hdwnm z!>7hWh&^|@ApwI;`|Z4mVCZg>$RxDCPJ$RQ75zarN_OC_@u7OKxhxYZV(I7*TOoYo zp)(aD7^Qgu68NLEpSIt)V3fec8v}LU5l{Ewv?UkZ=%qkdlEGu|D4P>*I9rp2Esrom z$?qYyTjbB18))3e{FkRgC~x|x<<9oJF+Hnz8se9|L^uq7b89U2@IfSz6qtB|^tQ^Z z$B?=fS3fjkqa99@xs6nbdk###WBLcLtx~k*u6^0iMZtHC7dEolo@bfZP|1tY7?P`4 zSCj&5D1wd;eZ@;_|J~q`Lwjk<%=-pENvoY90htA@e*a7zT@;z3xKp5SPz_x00ShN} zMd)e2yQ$F|g@}Nk3ksG|jj~H%GC=AdZwjGkU7y&b9jJ@rLK0x8y2+afj3XUDtIDus z{Pgun_A&Ov+;_2Eas=}Yv*-oc@!~9=K^e7U1&GQh$5CACAhJRht?DTz3G^QB6{eyJ z6D5Q_VRz-eU2V(j~s1}W~%rG@5oo@11e ziYN47Z_h*4pW^X%rx<2u%i2_42YwSxIvAHi7SDYiG4|btof8Jd{>Xd|a+r-aWrm3uFYK5g?zFXR&v}*0XT48o1;GhHJD;fL zrzYa+__8qyL|^-J>QD6kTz1~^i1YM*;e1C|JDhS6= zZQFhp@^GO5Nw{5kKR67h#=s+Is;d);Q*8&-PnS+hN{zntF`Nj=xOOheyPn>GkU~xI6OW{DQVjzfSGVEV!~6nZXGFZlJVe%ZV@hXBq5M}nGvE9j5OzBxIn&vv(>{QQN8b+qvx}AR z$**=N;qrF*CtBfrdP`@owv=Pq48WD0#igy?CVhZEoFk#|?L{hk<}JXiu+irBf-D5r zQ^@CD@mm2rC_d_aUqUM4h)Tio-#l|Rf(B(ZNj0@W2gu+*v#xPMeb9uL(P2kI9d{pa zI{ibhvX74U$YqV4VuKl1)T2Cn#eDjF@CFmg_tgZwcJwuv!aS7XU=;+r z#A+NI{<8J5(0vyDtY@Ho)pbbow$uB9ViCtZv!Q8>nXiz)Fk{Tkg$_< z1O>Kt?|z`IuZJP!ymxb|d0-s(xd#YZw{9=LlLUG)6!RtxsZ5jjdhGQ^Gc*;&cokZ^ z$Q-LKUFuy|xfrkO|o&8r7hs3r*2F@^TS_o3}o3(A+bgHd?GU zja~m(-h}C}ew&MjzeLB*;_(IVC}dzK4^Mfj6l`+$n`P!2C2JJguj;M-KnlG}QA(SX ze1#oZQug;wy{*0yVJ978;W_Jl67dKaO`UZLmT9|MZ_1{I zjaLC8*&TeKrb{D7OrL^>%-7cyO%}Dmi-FcP8L2spoUqb+1D{)k4=F~~6sMOx%qq~G zH4pT=chQra}Uu?}P+Ozy8Sd7IvMDTCMKBcw0I< zGgfO(o+^{6QF_DH`!@E+7MEj2Y|~{xglvRJ=ddlCaBl&P17j*wxlxo85ejT?iqna@tREaR&iqQ};Lnu@|`&l)@g$%63#j-vA z-Hwf7kGDg*$Q@k@lY}fhSW!bb?3dR~W8kndM;X&{8^h$Kw$5Dj>tc>`S&GH!r=Ka! z+-prCL#I7Kaq^^h`uxv5--Gd(m*itWu?nL+HA!on)hsM2=>qJ6Wk$rEUAQ|I{^zpb zW=r>xFpQS5^mI7kZY=Pz>@P=mA~<0I@x?? zPKkdsg}`6&K)wlOQhYDi*Ou@dc^3R1WpDS&Cp7M90oQz@KWK6Cqi&WOD$xlm&U^Q$ z3WWo40LCYnWBK8y-ueKn?eChIp;fB z*()z-gd|?|e}XFROxjRy^S9Cdz;By6YY6ADLAP2vQ-8GjAhCj?3RZ0OJS@b=ICoiW z;~ZEpn=a8Xc864rA5Lf@W(Q`53xARo;-;zy8tz=8n!*13c?TlABkNXb5A5GUtbTpj zCz)3M^i)_H6+^zm_8moZ{eNcx_H--7YT1ISgL#XxZ`7jL>R3P-B=QQyB7Tjv=G>NE zgYw4@Sw-RfXQ4Kldl*ab?@oHx;C!t~c3^!3mioBCe}1gyxg^2NE9kZUpz9b3FJvp? zS9wNgKwJ8gxvT~M6au*`_?#nhMzsnmC2S_{K9|jNmX^=B%X2x1KdfuAbpec0I6Lf? zO0U@T-+j(1Oyu3D@#Q9@+-^LJZSSghn4r1)iOBuoYv@5)x|oCJ^@i!FY3u3L zvrUT#i^A5G#RlkoXTvK*uGZyOhN9S{AosX}WfXLVjP$C(n(xW7{B0Yv?Qwi_my|eQ zEr_Q#3_YwB6Ev6vJxZf&OwF^TfPVaRfe3HJ)X5rLEG8Z7hRfeA=e#HR)$ElT>OFfS zS0H>xx2BjY8$6xDIbKaCJZh^NuFpkt&*Jkvg^+yr}|rR#N`;BC^~){vT&&d3&+PUXG(7I)>}AK_PpvtL1x=tWMOvMTic< z*_)F=sXQm4CdwrClum4BrdkztJu5^}ZG{5`cS=t3+l5udembuZmo+^Gn;iDeyo^lgpfi#aFvN|U(~c-LJdvqoVY*L|666IgSNQnK zUX#qL&&acpAMpKtPi3pt*5deSxoz(gR3*`^1gIRQ%ICptm_qvN@ zpn{vv8zm=)VgB0`=*5%QQgWpBl#HXW z-o%cEyCZqnTueckfIrnSdPv3Zi83wk#you4VUOW-d}ql~T0vYK9(J@XgH@R(fC8B> z5Suj)ugpJWGd2K%N5UhR8Z2F`ro<=p|IB=%y0i4uJxx<=Yv)-Ex782D^ZM=kGjs&L z$O{9kl^$R9M?UNcXVaK~LD8s+^kZKkuaiwDK2T1f*bRXSlB`~nJmBxpS=$GipD28m zwx8T`5UI|(9)DqJB%kI21u2E;z?N}&%t%6c`eg`=#-k$t3lWjqxz5QD4K^%)y>7Sd4FFdJKzgO{S-{$0o!H7*8`!WKn`le$Df~s&$6Y&SEt`qM?wS2njoW*szdTZ2c1vNG zM!rpxZ~9crvj9|o0^Sob4Wj8hzVG-nXEP=DRp?pM2;igv{()JS_6OZ>mr^+3pG)rq}l3Hfkpnf!&F zf#i!yoQ(JS9_P9QiOr)CulIPg;*dyP;|tIl`|>-Ir?U$Ad0h@oB$)68N@j8mw;`@8 z+}!e+$LNtfd-H=pJQ2 ztK!lrj+_+7-~L`Qe}*BU1aD$`Hs=YlppS9`jep2)Na7w9R+%EA7>KZ3s3*9S*JYW5 zZ;lqSmWbl9ercL$>sULFqIYOK61lv64n=jn&-=mE<^;!SH0S*!d3}bL(;gAU3^sze z3qlvBYLC+gT(*C=R3pWEe>%KuETW7OhI+jj4s`R^F|$clXW&|`1AxnC0OE)>8waqA z<_3%-86Go2`4I_8b6ol81|eYt+lA>o{{8VL_*?PbM|#$`w760|aq>iWBNdLxk(Nis zCAPwwp(v)8b)wDx{S+bq3d{|}58>Ulq|Q^IBw-ZlZfVFGn|SXs_v-C@PcO~oGZ`cp z12XP-Z)f?Rp&Nd>%59!Y^`)97o%!5gY%u8o;jki+L zg>a22JKv5Xe6#RYv7Z@L{4;DaI1KqI+>Y0{gL~lSifX)xgt#Y96OB5n!#(c2q91R9 zCyW=`g5i|a#_PSx+o}caklG%I=P-U>Q@mSBt1EIbS}AB@EKOel4(|M!CsqR+w0xm^ zT}VJg0o^Vf3~fvH@LT?4a{VOVX?4YUtwd0SPn*W4C1vt6M>SSIDsomDZI#R3AABRT zgf4)ERuHWK zMiaE&e*2aA7NTE=d*EeE z(y5HKS2_I{Ng;&b;73cY$nZNhCT_A_>(uJ{mF`ni2Hn`kTxbSDT6P6~w(z&rwKM#J z7JOiZ@BURXOcUeZ+|}iJdrtZzP<9R*$;oQ7I^4AtX{W z#5Id<2{iR_p7F5xqW9(80$PlX-%t^Vkhw$SzCBLaKeW#_={U2}#G!o>;?@u!R@;Qj zdbJ56Og4yr^RNqRYo<1fA7LIY#iZvLiKwVf<$n>jeNjtin6Kw%Gj%Mk-33 z9mVhiPzKS5TEErA2L|QDFN7+Pd#*P8dUuj^9pd{PgwCguwk~mZkzc?~SlCY%e1RYU z2*pxw>==U-M=1^+qaQl~xoT2m84nMozw7+ll71JUJh9JM6|b+~vQV=`N%4s4*tsv8 z-w}D7U!15CvW+>Ue)uyy_YSSO@q$!nG!1I#EhPaS;sfr5x$>>-cFl$9%0*-?xxab! zmVVO~asU$U@ZJ)`!TWCZsk2NFY^>l44ma^8cYv*m2KPKvTy_hM5;5X2{2Mv~-4EG% zj~LR9xJ|}mUD-Amgx_;GA+C0)%tytO!-5&MjMBP zS>^XAT-#}hNR{&&WphBtDT}t7dbJ;p-cB>WgaaU zFmWfoun;MdDrpPd$&bQwbOL3y0`8tL!r7h>_&0>PcHy}XQJu=ZD8Gb3`a~doiZO}g zsK_T<;AdI#8K0ZgPIg-Q_Du$xX~AZkG74bDQ$FZg;p9#}7~8OuGLnYlYkAp62m*l0 zb2al7B&+gmqX5i~IP40;MHRh@u_{d}xfB#6kN5<`sGbKDT5&$!kW^IcwY3~dGM|ez zW=CMP`{wubze##yi-AXH(zhRF?1)cb14V>!PC{wJJTwQ=%>3#&%K*RUaknmM0YVR4yiPV8pSLwQv6K>tId)u z+QLI4@a$yM6UrC(Vu75KO0)?L=V=XWRU~H|{XN&N%*YaMdp&F*A?OmeP0M$ksH|q&D}@ zj<=tuL!<)%(TCdZF^$D%T-IZ~$p#3l^%W3EHt7|9QhS3Ga-W!5UVAZN@lN))3k0;E zHe;KUL<&W(1WTWeaY;ihI6CVte{+%|%4k5vIf>_Fp^Xwr!(JhLaxtrijPVlIB=h@) zNT^Q!8~OAW`)gq6D{=?<+nTg{oqt*YMv%(qGNc{1z~os`55DE{2<$&^{k`Ythm5Oy z{U^~FQ6jR!Zj|3vYxb5mw7*5C3I@qR;x@aJr6VW@d-VfNZifyg;N-&R7M|@2>N-TqO?6I|v?6 z90&aQ>vtcnj}&w$2$&JYdx9O#&ORq{!Se&vG4%XmnkG6z1PYd2NgXvJ{Opc~|&gTHoDuU5+3Lof*PvBvvno zPRzIcZ@!`$DDd%~<9fbch`c5?)(YLzo%$&bj+C+IT=+rq8YNr)rhvolJPWyd4`73? z=zL+jcq+^WiMlL!pMNGTFuS=%-~q`NK)4R%;Y0Uzqt5eUOI~ z0-6sLE4;}Rbt6?t@BMoql>@~^HPyDqUYOEvAoK5=ZD_!5E8cu~euZ{g1uO*F8!qd*IJx` z`NSI|EDaNE_diOe!JWU`C|AnxcEQ{)KmD@$CCoJ{B_G^oir_9-np+o7U3&$~E!O;> zbn}Y9f6yN7A6piT2Q9O8pni6c3_t!$l9`0amuSvYc^j*L&=g{%{8-qJwMo&6koaVE z*Fi;5a9jew5f$ga5y)23L5Awgr{6UEBNV@?>1fZPgbi|J$lv6jp#L3iZs^!kb{j>0 z9RVaP!xhy@R|TxD+EJvR&fky1uF+J&9M@K`B~PodjNexl^CQn2HxH%yMZgfKY0-4< z32VYv$-t-={gL{#uih0(?MbL^1LP>7(zDPIlxHj9$1hMTZ^|CZ!5+;@EljOnw1INt z(Q)a!;iR{p4$L=%_NTAx*()$j^5>`=Z23roC;6k^Agyi;iXQt{u+^%OY%MRD%Q}fM z^_Q#ChTytk{TZHA!iQhZOvv;Z&=y+7$1EjXwITeZv|F5`r?x{SV}Qi{YRnPCJ?w`h zYaSv?`jR>kogxR+(I{1RRZ>XRnP1hif+5EK-7=-E<9~>=D0_BY(RS{?3}g z0vTK(Z_ZguF3?3Y$+*ajCVw|^AgEcrCEODeTrA(mKC~afQk~mm?;PWM7qb)nJ8Gqc z_dw2iZo0SoTkuW<8Nx$o` zC8BoExEYmLg?t$d6*8v&&#Ua;KATjGn5u>FA9ECigUXvS|1*8 z2h#itTvl|AIsO_qwz9#4_`sVx+I%ek!Y)~-axItv$PO>Z*@HHZosjURtiC` z^IPfRi*EOHiX@yV=mP=Zd05-xFYCl`gQ$?NSux6^r4dY>4)v zjfCOiu8GNCyg~JIBXX|Yw|XqlvIii&8}TD+go9ZHtF~)dn&fdTO<2_)WP!P>c+5W$ zl)D8d$Rg1hat=-y7_bRYeZpx*Y+oLn@2}KLw=e_v18^su*YR0&4akEEE8sN=KIR{) z;Ovfz8N!@UI6r7G0M^g7aoe@!vCWZJ8h#t=vjKM`{28m_V*qqzXI~>!rRXu4G86m{ zn0f@6C(Z2ZPevJH+h6O~mGGe->ILVcUg0P_&S#PxPVSPf62-OOKnL|8(>yhiUC(0H z1hrYT;X^X?aP!On4Gi*clsGV|J`~Vg6sQA)?F}MNs~q`^NL{-Ks+-`Z?Iwu1QLv2j z=?4;pd(;-!e?Luy8hrTAg>o`-^AL-5zIx$ zvtY$_!^s(h(cY0x;n_F(too;hhk?FDkR84mVt}PlyqXNEQs&}Hnh7`=&X`} zvj?TMMm}Lz}@Gyxhw`z&F6pj9qymKB>n0|G2jacz4xJTm|(sGE{@B1_{rj( zlUU{-Ai=PS7|LuRRT|DdI$VoQ*i;Cy@rhJdOAl7cVDUMNdc}OQyx`)cQXp`lHsQoc z1rU7Y?y=#RDgI@(VA)@6%NC$}5vcyV{VAmU+9bC5q#675!c;1Igt;T!o!?`R;6akf zPdP~tmC@sdP|Y;ezOi{<@bw=!9e+2=ZDufpL)Jp5oxUD%>fIEz4Qm;fxvYZsjggW~@1VAEXDlqP zd^Xm?P3_ORDhrrO$TY1mEmiC@%}no%Yv^MsFuk>tT?ZD(n8?c>rR)&rJ$;;FCKj zTIyAk+xAPqBsMb%L8B=dC+DC*3^43ih|-R6bOOnur*V%T^JD&NsD!Y+w10%mFwuCs z5glVIxx<&~u}fECH$L* zDS_Q|pIJ-memmfDNeE@(MGbw794?F6zRB&Ir{i4S8LpWYkSJV`t-BM_Y^=Vi|nEQ)E%w09mmRAw&b;#=9 zEk*a!tQ^bwJHd8%L6tldUu3kC?O)`!L#y9H;yX|fVWGYR>Kg=@`hJcUa_i3mElWY7 zO;PWra51fhcan!I&8p_A|6`P!nm;m4JTfbMmbc&Wc71#KFY;ryCBuc`111fX3=Ilm zFjwvws_mXw7zm+yVsv(Bt2SuI%u4p^h!fK7xNcH2Rb)Nw1xP@7_puFr9 zId6IW+N}Ba2w6#Q37MTFG_=Bp`Y(CcMgd+xRP5|tj=r4YoY#=gor9ouEJO;2-KF)C zO-_&Il>Zh{9@r1~yV+yC_t=jZ^}7!uky*0NAOfoEzC=6tiwS)J*Z&4Y4AoceVhTct*VlQKW#`W33Jl0xd8@fj@1fCB0*nxz`>KZH$|7hbQgh=;N1G zo`@X}v&cqDIKIN2Uel);3t|-5#DGmGvX1X{W5Z95ZBo@u&(&CRdDVA*TJzb=jpSe1 zKg_2qSnodtUrT%mxDM(VEAcI;vqq1Ten@60adkn9CKk8Yvd!Mo^vmmPE?j(*DRdi1 zy(lTRP^?ynjh9h8#heh;bb0V9{Db9*BUCVB(uIP=avU9S{jZ;JC4#uE#K^Vh&SK%9 zB>(g!o&EFNMLxCvo0#=JbTcs{HYo!}(CI`-a2mx_V>>_#R}65?4P8>S zbeHYKudrd(gDJ~p!%vQSgW2qR0yhba6dPS8qqnEt<(VaA_MX>~j@MGn3)S@AR{;57 zvERkq6pKGeJIMJack9@zN9#XtgGW3^OwNoq7`-z ziiL4EKdwr^jj>9QB;-A5f9YZriUdN#7cu6Vf^8_J)X5bo^2P6GpHx=dExl^3uhb^o zUcyk`nC>7=SR`XF=h&)WrDrADKxRJLn)BVQ3a0?OfYN98#eb*8y9CwVEI0S`%y-j`JhHu*LhB&+AlYy$)PI@N{>|zHHqpve=or# zr#7%hrTi-%+=w>?9Y~i2Gonif`+x((@)f0l;u<=Hwkmevl?W{5*1iV4|JU2+(f^a2 zzS!#5$9PHp^0yi)LzTY4xyJ{4Nr32&gV!%Y8Ix)Tj9l^`86(@(Xd@VtCbM=kLNJ#n z%Tkl)ujyQylcBx^JDBiE5AFd3gN)yA3qSn z^+7!6Wb7-SELIa&;76O_p)KJWsdMel4yGGSKpC#J9g()1a-nv`o^2~7O(Uj0%G|JI z%(zH#*ohBz%WxMzr#A>yLbCp|QG_3GGQPvP^`RQ|T-CX?n>PFuBJ9g}7~?4LKg z+>P9$3~X4p`#N4wfJgz?o%O)98+)AJxb$<{2bHX;(lRr)O|5#qw8*5DRHLbH@^+89 z`S!;HpPkRI(bV|fb8n;v1&OjU7e1l5JzIRT;%!(lzY*09Nf@wrKsyw(hD1|ZhI+O0 zYKB828h-KM+ckDIG%|dUBt_q%o3k*Vgq14?1YB-#!bD$_E?(&q!?EF8hgeSPI($E~vs zde+mnAh!w#1T#v@Q8?}(zSb?oV+?yuWDE>^{)Ubngz5ir0X~by`XG*t)-8`*qLoE_ zqLx{0^7QCfk6pnP-(Tpp5BPT{w(=^U8!gP&MjnK=2T~ya4e)oNWQ(adwu8StjHEjF z06|;dfFr_Gg%xPWIhg@j(gWJYl&}*gP=O0%8V)W?jd^!SslR6%G6%pbe_^s6=f6Dq zC4+JyxbD|EtgqZiWr%+@5D9q}cEbN^1z)EbofH1>|cq~q? zDl_gw5QNi5Y5I)HGy$zezfm^)qT&;(+fdqb!0v?*M|tL~iTg9foh7v$&P(3y+<$BF zJyTS(v5RBg6Y_;kOG;QwGm|cx*M3B7`6c5=nrbA0CAhqFZgIQ9s2Rgmi`ywtI5_9+ z0R)8!`m>g8-5@GN3T54ZjMwJXRt<^D8Qb7#q;K`U%&NBvK*>PP(&<5qc!RM68@xYL zHh<;P8w%HkNW!4|v(u>ALPzxob7M385b)_4P66>bPH%r!m-L~(0WD8NxDiI!FaS@p z;;*gbIK3M8%Ip_kjwAO4a6;I6h6HFr_y-7{$Wa+V&FS?pYKIS;%w>T z`6Qt1O~i1~9h6?c5w{I$$GOq^HClbi=qe^cf8Ig^yH?0lyY!D>b`=1;HQ4dc9k6BI z+*%-!VrC4}o(wN*=`ft-UlsqnvI@Wi<`O?i8h`43=!+USQm^15O1V^<7`F<5;Hzl1 zbAu`g6KyoN$&7znPZBB1`R|X2d7@)C4127FO&2#Y)R%;I0@7 z@qqvfL@e|qyF*x;_i)44MgT-X?2?gi=6w`?)F-XRa$-G+|AWQnpX|bPEUN+C$oY5Z zb6+2*p3on~qF>QTm}V$i{2aJPu@HTK0z(qG&#dYr?sR3}E7{J|?3d(oJma?EMYtsG zJE)Vl286?OnJMS0K-@GhY&4qrCDm}$iQq1T?eca)P%Q&wU;*GI=YA7PJY1YUXDEiI z7B)by?S4|VdL3q`Jru`%y1XtHZx;k7SNueo443nopM&nCu($=`y}hoN7hpW)-a4C+ zK$%8JyD(votk{Lpnpr2BXELRJG;&vL&IsY-;~CWftVKFF1t%2_%OWl(6<{%Qv7p39 zkCnVU@2%i8!973yk-+qx8Ux$#WTL|+`^)u?xnf=7%wqvUp#SV1>e$i??R68|nYbTa z^dpWaU;jv9M&7AX`D=GlUFYPhJWZz$+U0Ey9_taM~58mv>#7g&+irk?+*WsZGf6f+IbJ9|>$6Sh|^5Y_1ZQVeH2ip8Q z09a1{Zha^AaY)M3*y{-}&1M%PlfSv{;@#mp} z0>7F8U}S8`#GU4vULFA*`H4yZ!~pv>`zm+H`f<;EeJkhAwxOAytQwwl28+{*vJ>P` zU+vwl13~gGGlo^7H$nBN>KAcP0`dWbab-|w4#QcUeRYzBEcx=!Z410=tmO4Dbd`7? zI^FoBjPuWs^NVjxENw&C$U`C70jC2POe7u4L&AFWDscdoFFg5ThVp7FkqgrVI}S)i zL4}@fxt%)ftWk7L^_YC^5Gy_a5elb<1 z*MvTHecfRwpZ+t4F5onqkB2%xzJBq3XWiSYzyXxb$7YF$W{yj6oqJrsM&;QhY@H@ zo~Htx_UhI%%;id$c2PX&ylno%VE#_r`^Q!?OT**@Wl-A;)z9F7L)Rqk5!nU1AOzhw4O9S>v%2u(oL-(Vp{jrrEKc*_hY#xqO2&n6~DoP3nks5_>ZVXht z)eiIcy~ITxw+*-1yOUazpQDV?J5op8K203&!%*USr+Foh`_wsx2g8G=V?MYMRVtOM zMz>*aPMMw>I$24D6)uj#Te8SUC}Y}Dl~u>UHvtmBh~oX`YtW3O(BWKhb?Y#}1kXEe zByNeoC(NI0{lIr#R6)gID~FB#p=C?&T+{(uXLzo^y4eE?6k3`tsG#fLbKJx6S7KsN zI{`3%tLA7jz?EoKoYev<5$wDNAfv*XQX!mD!LIT<5{~cGK`hU0VLFkNbg=sg@Gk!h z6DIVt9n1c_$MuK3&=ikCh(vg$!sTIBi~N@~%r0F5f+V4Gl>++z-#202(R!=wu5sT{ z_u_0$RGUInM~Yd8O&)f*>E!paR3ISitvtYh$|;HA90+$#X?w^Bk@BFXgz=TWpAh#~ zk$%>~I1y2g(WowsfV|myfEicQxo!p|#tSP!r9vctN~N;;;WL!;-%9z8c2&36o6c(b z18K)z7#3#0_ND&YzUWrNj|DZnT<@=T|E^-y0axc_`hRI9HjU4 z2pVq8dl3YNui2=Q+yPA^9MBa_-rC#Vg^wR&>cx#~8=80#HS3FXG8M1B(`7)o9Nubq zQo^ISTsxRIggYH%dv=I2KC2j6rr@=YpBp-yh^qHc zBtWx;TRd)XTLyNn7){L}<7d+t<_`mJ5^0N7 z|p7wAvy(M)^MM}_$%Rp_EzaZUk8lQ_Tcpq5;EFW^t0Py9L%Xc;8F8e3;EaAbYC zk8uQ|o%TypBuTO#&%hx+_d%ZW#&E7i<v8oggBvW{QGrGbIf_5LOOSqR)OWv5bxVH$7oX{Y;6g9V_}l4TQu-27X4 zX{;wv2X7~0L-*uQs*}`h46|_pYUadW-DAeiSmna76AX})ZjB&GgZ!pY=3IPnac0=w zP)B{?y)K2YHHK1BV@GpEWBDy4XGzW7v$_|g8v58x(q?YtXaJ0a8(b!P;{pY#%@`eG z-6dGbjXB09PdkPHE)S7n0RUcD_!4xqLs$-$T0rirQ97w#tW&2?6aD=mbA*lQLoHRA zK$h9!U4q#R6kZ^4JnXj9O`eL=pX>0 z@7|&aj84BUA-(dk^4D8K{VkYs^0;V7`wr(thvZc=64+4Omh2bj+$?+wQq(tZE@0~- z@2txeAtxeR1Ob=;x1R}n%HS8~hdruS%CL3UP+#|jAK21i5_lcp3x}K2E5hJxzZuP4 zpZeL3$QQY*30FYU>jO6iAyIvrM2dtRmcSr2<_elFR^o2>{Kc3-0s;UGzg$?mef4JI z`+Jc~!PUsY)3EyhK>CFA^XQZLMky|g>Z@SMHErW4XG7c`$wWvaMDQh#YRhIa*Q0^X zEV^?INdN0Z3$B2Fl1IQ`zBt0!;5EiIX3JI&xIOKmq1NUDKE{-EHSjzib&%@yOeuw#HA|Ph&8b4?|6}{F=4_$#R2?6MlvaOKtgCQ z5;CVYp7{PtJt=P|LhCjR0npDH1I*WV(1o@ttn&BjK%pz4T2OR0py_u_;Opk+>Q9dj zMT%|wK1uVfg*4=xe!QeiCUMe3kFWdNVUSEzxU7ehOlZu6NI^;~f+f#~trXoQeQbl% z?f<|pxZ>e<55^B%R_l1*V<;ny3DlxBj#ua)h$1Kd?PeAfWp`7FmhA_4p@M+!fs;LU z_fjz$H-N7AJtPKhsT;g+)`%OxmW1?s{tSNwo?Cw=#u~}7$;uH_iN~zay5IZmKaH_L zp2yq?Y9*Vf5kvmOGTv+uCo7I;@)t4((l8`|2=ZYn^QcdjCDfDRDkEXymd9{RK!F8J z9?8qhf~b4w7LyZJjBz{Grsrojpqce`HW}zJIO)D*s^-v;j%+n)B2suip~gciz&>y( z$ec%Hn}{?!60Ik%IxzH$K|7n!%*Gi29t(KU6gd>S)C@3JAPr8kbFfC*TOgAyBYYo> zGbq=b1>{xzy;Y6$52^tqX!L0hs?YEHFK1)yi_-l*%2uj<_9ybod{B`0>6*8&h8l3# zb++bZiJvgF)bs3!`{#hZ^SPlZWV&6)vuetP$t-%0(_`jCtyi7lq60aM`F+mVq&JiZ zFt2W+4xm7NB4v2J@X2c`ExTu8=?RwSsi4@!Z<;1$9*6C=_1BFz`RHGP|# z4CJw(*jeb-TQLzAhgpZiIVNeihn}4*|j!1kA%a zQCR5Ub#i`$yXhp69%ueJd;c2rMi-EN3%sm*_@y*6r`nUEhSJFyOIZLs;5?H=>1UJq zylY2OCq;Q1Z#29EgtT|e7YP9`>;2DXl~UT@en>D9>@f~Ee<+>isCmH)^q=kTIta;rg27Gcu9FWtM#emeJixPY1 z7t)-*-cg`A5!DGXvu^h9FX#FJNV%rQ!bB89x0%~W54iKKG19zAGoKC~ZLNXJ#4OEc z-es;8%za-1^NuBhx*>Fn=MCpqzHB&vlErz4fE4}PGRFrW`zXL{S~EkhU~9*WP0H0c zJNYPgKfzeReMj|v*qS1ff+%vz%Mfb0;2%XrT(D}G-;#my#9CCS;&Nbcxd?!6))1MC z|7?q}ZvwE~@k9k1zR@G(hG(XP^YabQ!SsN?O)$_BU4fKY!eQ2#^W-7w3l^5OIFy=i zOC;cD=*dL7pyT02LqC1{gey#s7*$&5bx>aWgH%x4(hCk-8sP-yco?VGl?66Oj>u?540tAk6J~;MrdwCzz(*c zRFg?eJcx~jopncec-SO8llGpCZTY1HjQtY-7xeV{K})1dKdSY%Yn$odGnSmi<)T6>1vPv9zioT> zYb6?)JGqGzx?5=(_H$tCm1PaDg8npu70bFx&eHl-Zz}pt*!-`{DgFHD`j5-XAs1a= z)Tq%@erUA_%~L&a973<4e1R;yv&!4Zo!i+5*R4_OqBd-P1bmsV`s|#pUaW4;a^kzH z5Um|ZWd;dVmq^E-k_Y2HSQRjUBK z$otKWxr!HuOM0Oo%V(K|FoFRZHvuA>(d9vZo$}ajuTqDiAXg!?<#4hRA$4xg1%Utp z1i9g~q(N?iGYJ|pPZBC?*9GE2&S`2UU|6maPe0PRYr)|KSxK3_IX)Y6s@q1B7ojY_ z$hAasH|yO$USEt5fgk3d%KweCtl(^CNZzc7zZ0?)+MnV0?=)nuq=9h{Nv)iP?B}7g zGtfEK3vg;`4)89Yd`f_A1%cSW%~V0-p)5iL-K# z`Ags}dM>54TjwsCu+>rwxn-5^U-?}2cmN!sMFr@W7_7~g2P8pp||)`-PDSmf$ar4_pi z&^_3Th6n(<2bj5_2Bd-kpX7457dtsI0LN^rWS+YAn#5kto%qPS-Tbrp);h5R^lDmz zvZDvHylVVL+pkVop}KPsG~QxYp>>j1x;oxRIO|MV%q{ zWW#OMvEiY>ahfsl2}kr~e%ZmdS4+z3xbut{{8XEtiPz+ZX!a8aTGMpP7yD-*6o zzD7++1Cexu|2`%u_w(U0V;UvY3_dTzck|iTAR)SY&^cy)`h<7>=+-+kt%;w zOrU5W9P`uPaE(W=fYu8U(l*oU}f9l~dEL;G4uoqnaVCUzgbcT&rfyM^e zmjB@#n+eaJ;>ubcYRhc+++oY+TB2E34T3VO+wxb2DM!K0;w>A$syX(IMT*mHu8E<2dpqLoJc%PdEcK0mzhoST>EDoCc zIV#v4D}=`qJP3IJXLJ`=_xP)*(X4+fCvh3UothkGwaWuz%mB8OBN*i`NO4l!oQAGS zR3bki@E!ZKjVXTpVzIwlolo+|h<@)i5R8xNTGVlQj*mXb>^Y4Ndch3lX2yYYoGxvL z!F@v5@QBdED=?Om=;gN`+B+v8UU3>^F)fQ#>?g3y#o+fmELMjc^;}I!3A6B5_N>C? z+GY{g-13@Tv0_ucpC7VoVSQM3cNBl@2=0P**y?4|Z^lXNh*`b5qo;)KT@GXRl^)3> z>1Yh@o$hQR22OpmHeqS%)9vQEC}v(Kjk_>?FxtPZQi8>#Q)VV!Y_GWt^;TK%B8_QA zJNdHxy7_p1bGLZ0fZp(l?(pqJV*!|&dHNnxP}IBK6<3 zD#4@<_LgBarF4i89QLuNln@9&$%Xo`dH0pNT-)8(DbNLB1-1s9rA9-(bk^Is;jbF3 z{>AKLJdWAPY4A@zQW)PGMMQexHolvf)TLxwfu*hoVdJLFpUifQ*9qXHBd*?#1^8Xp zdtde!NtNPmeq0T9EfKPs&}`Ooa8d#?gWGY&5fU&~oDfu$iF4H#Nc~v;$^-I2qQN$G zAi%I0?b{L)wbYfO{F5ZHZic)(ABc|PYwoKfI#GNvt4$vZ*qfLmg=JUz4&-Y?CjL^0 zg5(2P{AJiOmzJ`c$21@xY-0+c^!gocS?u$p3%NRP8#?PLk2A~!wTQUXE+|I@+$%IR zLyGA!_Nm>t+OUJDFMM~*Qp44;(#5g&;;_58N~xZIuF>JJxNNodDy`n?F51G^y4>s{ zfJsV{v28Oz9izRf7VLY^W`Gd6e0MMM)7rgbYs!jtrg(3}?-ha1zD&nuGQ;UK1+45s zf;`D5FcNveHE=ZffJ$f-o%aJ9dSqm}Iqab8k(-~^u2q;_Bm0z{U*xL9nQrMJKlHck z_^Q!_q)flLXliVM==^g8jDBhT;bYaUF&6h87N6xz(g)Qjj*=*qS{#$D0ks&CEBhTe z9OC}HE+r(f87BrHAKzMiVVvKqJr$Lz58*Yr_YV)3Fk?|o_v34*W%8~*4$c&y>n+et zH&He3I4pJaC7T}Sy7gWCgk(az*3y@s{DP)V%Yl*DPp0648lC8ah?EorU%X>7bXSBE zPsp!AZ(t9%6B#;9_ktW5j=4*!`mz)pp~Q_370NN&af(;Jt-o6K8T4`C7dlLt62dJg zge!HK?zt!t-+iuYgsaKcY&4J4mi9qQpbSg3`k zUGGg#6R~h>p`y|D-^M5?etR$hpO9&9N&+zcQev9xK1)6dP!I1Y3!{>TwrGvG+!Ib9 zeaou3JhxfzRuON&yumOO@0qf+G5Zq0S4+@XXKulShMj@y3U%_(RIft#*Hc3Eg21aW zhYj94mV=>XF4P#$LrE4fy*H^CD8!XwTx%qgw_4?RoOntpV zkWB_`5j-}Wn)KGhJEP1#y7GQ5?|vT3M4xtp+EhP|ynNbgx@ zV2sqhGIhE4ka$8KG|r4#yMa-NQxsivJuIjlbvW{*Mcg z=`n8$lf<$CCJf~4P>DiyXAsk7Zw8HS4D$Jgu$6;P*0{@_XgXb?;EIBVBq~Z%m&0=L zVK_1@;XSun5|E6Fqt);Gwv19;1aSRj7M2$$Gch~nFB!0+g{Qn8 zYvavcA+w)@t*>#n{V?3TE2>=#dJ((K5d7|H_KY;BVtbNWm8X~qe-*2UCy$!DXeRCP z1G1K*X9vex02W1!#8$2c(j`QAf?;j#6>{092sA9zzegABMb*{K>Rkig$lgS6*&V&- z!?PJ7qQZJk!1vUvR-$miuLXk?C#iC0-NEo%k?N8#i$0MkfZB%HS7O9ev`_=)59G&$@_CGIxQxiR zyHDAP%eZhqg^=vKvJc5NXyPLC8mYv2>#?<8>EhtSf4#4CDN!7qcO1vXd*6AyXR#MH zovw+n?TrsYI(tQp_3lOXlt$JAT7yW+ zIVr(zi5*>Z&`As}yn+@(r%DIPc$(u+bp;#x#4ddrOfRT-$CC@Vf2-yHq*`4$aGO*1 zOY`+w_dGFgQBFjwFYb;tq&SXF3O7}PAA|!Q9s$D@bp9YB`DN%>`LL8;11)X*&UK=^ zOt9RrS@61Mh5c}E%D+8&EbNW}l^DqCzpw&LIu#tSqyb}btltMqb#Ce@5G0LNt(1ar zMhds0_0`Ytmjq+F+i{5|0G%?=hX$fgwCGg{!; z5mKb~S_O=xFAc6JEvvjBo;~l?GM`SF<*wZTNo$iklNA#hCv5_>lWUGo`1;+Y2QNC& z%r9?8*-F$bOUhl6A-qqm*2Yp^+IMzwyv*|5oE+UImO2JOtm8lrMFwWsPR~p}?erI=YD9%h00|P?wJV`z96%-=|@y&7Ov&;4Ho=h z)VpWuVudiODH-H~QOor;1zb{W>sDQufb3B63?~9k8W=H%?I0OFd9WHk_WA7dMyNEWyDJ{s!!upjyclOcV z40LY|Np6~pdoNJw{z%y4Z_c~%UDhtY* zG`JVY1C9Kjl$amZzxmpa){>dX=%|l7cH$mT_)+>`Z$#nBpR& zC^k}SB;T(*sRzIj$TnyXP&9$R1O-TyfrJ(um#gy2u%>8U$(ehcCdQZ>Sa7%DP6%!I zunDf7De^hwEqG^Z757~Cz9u1Ao0{@&SrS>(fTb}NOv;h=I1s)~N)dG095XxdLtY_a z=Q*DPJCmGG<&dg@JDZiuU>o@@r>!Sco}oXU=oh?@r+4GKv50f&1A(TVa@xH=u)F&i zNWJ}C?6rv4wQroYGCj? zHpNZYF5r!tYbW$Z5YCMtP|xQLvqmxqMM$Z5&9pXd}D9=(6Hsyk`^x91n|pGUft=P2zm7*%EJ zx0b|tTk0Oa$rA=}zkH5w-XpS|Uz1laFihg+l&;$5-toT|^8WY2%FxPIVwD@8Z>~O3 zzn>HU(ac?A?`A;`m{@C^Pp$+xVOXsJW0NMG809JEr55}B0!I&uD5wU(5OERLuFVt; zf4LIC6cDik1kr4L8+9bB2sa2ne0DP2mw_`Z>kNTOw?4l#A(1+(+^LUPkh^&#x zP%XP53=lybTg5fNLJ`{*aE9&U2B$I3wfwoF`NtFIaVtTx|EbCBe`?aD z8ab4TH27y1Eb!`yF9s0%NXV#21=rW35T-R0DP!FD@gQO7~C~9_RFLmWP|8Kg>lg{M&d}`OIqsGna zI}!t-=NXH4_i3F~45}Nh@=oea(jZ$JJr|Gtfb{d{N5{zqoC`u&yuW_;)TYH7r{xVoZ6B zF*R2lq=ciIFrl7LALd$lSbseJz!rIf5Pibm=GuS!C;q-q^*4pzDISxXr z;w_8DMk5dHdEG7p)kG;rCEF!5QE9GUFz!*H)9#jvW!kRa2E%;CNzkJrkHz+;C|04D zIa^*%2i-V{ec3eJy~Hit`MSC@B=KjlpzaDiTJ7Y)@ShZl_=dF|MPkH|-uTHw+2C#~ zrL{^)E*H|chp>675amSo0g0aNqfS_p_}#y7r$hTJ>_PR5*4)6|OuCcO_uh=ND*s`r%qRM8roD=hMhuce~-O}A5HPlc;oR{x8zjN1J>)yXuz=C<-{i)~kJfFRH{)SoW z)?fVGFBBey?o|ZsDn&Sj$Qse@u5OpgSH=PFx0#0q&3M?#^cH5~Tse>P^2_vbhG-oI7r2>yd`E$S{(mPP&h!t;X?)GBEEF)`u0K$$g@r_MQu_TPmaTd zMxYp)Sa2hX1fQqJ+YJuWHjR!Z&IWECft3nNhwaz>kydjVri|lB>22!-%YAGheZsK{ zGuP8TQ^nJ7jV#Wo8a!<9YmtXZqgvOXJ*sE@HP7o9GIu(1e+k5?Bgv&-N;eY47 zoE|`}@x(+tF{iQmykGc-F&84OcrKyVk730M+&n3rN7W_um+aU!dv*0JgHWwbC$9-n zzh37JE|kCs#a_al#qfOMS=gzqXk40GEVlg2$;N%X4WWG2RKHA6bbV^lku1Ifq$a(c z+|y#Jp-~VETu4~OCo+6zZjcPKa*{VmO;gch-oR)B9|!e56&VE=p4(+GNpn6M8Ee_T9*yH zVS>Rzm}U^Ol3Nb2Cd!;%eA8^OLQl|plDFyJL^7WCQ*m* zR}ouhJJcQ$RXsjAQ=OTYd~w$EZ%7(AJm< z5aX#|!KvT6sADH~raSGr$A0?f*Tm2d!-6Pbg$qsgC9^HTA#*|D0hXEw^XJiquaA<}fx?PV8n!Q8DWb5!`OppeWwxl| zwg~!jF=^s8hqB~n=+VehsedpOiT6o|@#UTVeACTKr?&W6p`lAeTL)67Ah+sBt=o;P zl0pQv2TpN`C9+P!~q&O-N! zBLMT#sM^uZNTu`^B5^cKqr9w;Av(jkQE`CpltrGsn5d_D0R|jo3uR8y7_9F4QL^k) zd9hnFTkP`a+8r0Hkg8pPT@;e;!v;;dhJwq>O*68NL<;wY`(K6@TppTOAY08A%0ll zf&333SBh{Z#2BgHu3xZ(ZJ4TQmVTIT{7>bBviv^|LT@kbA0sMz-aeD*?};~cWV!j8 zOnA(RE&{_#@_3tnF%5LDQ>L|~Bl|J+3de16v!x!Mx4p5{e|Knct!*W>Er;OmyeYo55U~BLBLGCpJnMkg^ zWw`)MC_8+8(ODp9OEJQBpnAW{zQ5}bwX}tJc~k*K z+Xo$G`{{=TPs=Y2c4L3QNkE{vkFND_9E4e*ej7 zNsQktMcL)Nz25)Eep3XcR98-4-~x~U8*m-nw~UH!o<{?$DOniqt@`kJln3+g1W9B& zqVxX}O?Sf1>aG0SEG;LzG{~~awO4&ek~vcr!( zj${c>*JD=3^mk+X8&RGb!d78b+G9zo$&w{_34c1fU8cBQH<^~#+KLc=UyJ(P1hsb_ zDg?SN@%_rePk;|Ap#O)#>T96Z5KDwyv<-QE23i#-MnruHDxmjj5l?s#5Gq(!V9@c@pDb>qcuD4g z6@Bp_@r6?XI&r53jrGvqN>dRS%y1#9bx)*uD;)BL{lvc{_RQytn{;_TO)nsvp+I{w zY99q{voRsD0{8WdI_wQpv7iJxjNQ7sK~V2@B7g*aa%~00B<-vTeMf+f;_!#X2k$a& z*BZSm6wK1NfnYDbDTVYBWmN9@Itt1G(nkt#lIL$TRC$_LtAj;j?BNQ%3=*QwR0Zi0%csIln|132~h zA8+H4&?*%GczKAx%sv#fJIFeZZ#4mNQte`a;<1v%#(d;t;cRgIB`~D>Uz;FB!h_{w z4mYxyoD@dEsPteW*d!o!^PZdKy8OoA?37C%e$cS?@R<%jdxCY8W?$gp1Gbf#v43a; zMx*V1P%bp8g{Y;-nZT(kg#C+4Za2+o7m&5}v@l0ka&eLZ987a>QN_Zv{X)*xH=swt zudjCxwI*7{R$8yRza(R717e z^ps)Z@)Wk_nL1+FAzcwgBQH;dnM(cLdC$Fx2y?V#s~NqktOJ>X{94SRUNwU5F%6k3kISw ztMhz)oNxxUdupr1#(mVvG?9ke7hynO;Lba>lUXOL4$M190^<)bi7n5Qyzh3ND8jS! zd0V9@^i>ctPXrR>@}L+=15HFwPIMI^VeNy%x#fD3-bdwDii(e`Ao~s20!<*+;;~V_ zOSCDVkCo^C3W{hKR=Z2kpnWhOm-te*cI>x31=~+Vll5CMqOfz+-ppdpyfjqKc>dbI ze+k!BO4XEVoc=yfq|Ur`FL7zy!p(W@_SqPR7Q@cNt1#(jZFI20+Y$1AtZ>ga!d`}5 z8=|*89V-eg#`lNHRJ3Eo!o^3zXZnm3@m>>`Tcc=%rewqLdEO;_Sre}7QfFR5WMnwM z@*LfGo!a*T(xFjQt2}zeshRPKfau(1wV}fa+jo_o_u%z+KaNEo+{;@PQmuDn(1Mt3 z@9X$oGqYVYt%bIq2**5+9Yw-*x#0^6Tesn4#iPqPJ}A6zG?SGF-POV!!Uss$2u!92 z^YQ=va#FFQP>tVQD*5qBOxwNr5VD+Dc?CPE-493n3j;DvD6(1p5nw4ys*t@Y!)dMg zZAz9DeO<A6*SiUbeWwIZ1zN-cc_LcUOE;Zoax5J+`j=?ecz`8S(cKX1l5zxY_)GqYcAIMP>v{|1_VG3E+u&!Ou9jf&SI@ zzEO-ujQ;c#cyRndGzlLR-!tHhFk{q0*9JH`9ptEgMl^$9_4vl`VnDRfDPB*t4BxvY zjw|;zy}qmYXB0hwCg35Xox$ad171?< z6D%)KqBX3Q_Mq76uo%V8En5etUO;8?d`d)&=zGTk%Y95jX$M(bnS}>Jz`1mn8u2^L zF)>Yr8#QD9Niai62kmp&9m(YtWnIr!h}N*iyq`=lab-}*EuCKF%*if={}qy z_NT!XX3dP$(){vZ53PO?hx=b!l9`xS<^otk5d{c!5vIN^`C7GvYGzsYVT%J@px+av z=~ay!&NvV9h)#a^1-*Afj%@mXKD*z!)}JxXY2?j>2`h8d&2$5yLQQdXx_q?kv2ge@ zB?JHo^?uahF50Tf=^9nAJ0H`l2hr;kiiaA>_y%J=B@YrJCSkH)1xppLg*O;{S#3I+ zaa}dyl}9GXfhK)GH4u)vviNsNTh;W@?H5&r{4B}5Ygj{f&En%eur2Y@pW6|Gc-v$g z_B)2p+O8$hmchP>QBN(@fI10dbwDutt>GT}&WPAa%Jya=ES<-1?Z+Va+cwW#DFVEa zXX5Twk}}ISE<8R0lExIE(_X9)a=#J_sEuSMSJ)o+lKfZN)x&ddJpSMTIwGjtS_p;#uSNQ|Kk9Fr#O4;v>z!> zh;>KA!_`+tAy<;|7V^+2j`K}e)r8I`9&O>ew)Bm>sfO4XTG2|=-7U(-MB;1h*RN0 zbBLBOUh=d|#akL|fq7CaPLLYdf zGiX%1t76ZpUQfRpgeuQfJ z$c?kd0NnVttfRKFb{z!_r#;56?av5o3jy0BFA$v3(3(jjSs@>P76_q>@v!q+D|Yc& zD|PIl`dK9%kNg`To}5 zw~YMv7&pEJ%jixo{@HLpSbFJhFe+S#JbaV*oD?PEpf(}mgGX^eBfJNB-_W`FGI z_8jPg<|NM^P^l)?yAli9I1%UZM+uWfg)9r=i9Bv=iC%rJfuE47e>WEV3h$w74AIzC z>ABZC?{u-}srkRGieM}LD$+mImKlw?ta}hYG5kdjK45sS5)@KJgBS9I>bP6^u_zWl z61@keOTpM+6q=7GWG@;U-0m3ar04vKdcQt9Ar8w4k46(crb0jDkas8?WYZqQS(l`b z)a2#8%mj${G(aV4A$1%9#v=@%)ya1SARoupTrOXaYLg&7z~cZW&QNscx1cXa2o%2f zsoEOz1J1w%9sA_Xcu_>}4A`i<3VnuIrAVK@)%zQjga8xS$i}rbW=9L7zN|ZtPO95f zNiR!2I;MkMj3^Q_egK4K+J@TU$+5VWWZQTWv!Kc(01E7I&ZAW{SLQWmI+B%qh7^9%o{uRTALeEb~RedlVQ*ig{|dK*Un z-5N=f^kUnucGQ~06p`Zn!0vG zvBhCdrVf7;c(fCce&ZP?AwiGhr=D=cy?iw=z~eh`Yx_a6?f61<2cYSNp`2h{trT$6 z?w}dq@nJud1`AU)48+)zr=e)gmy^fCs$TM}D1Xqox^eOdTgd&Dv})|F_y&4vAw zZkw&AmpRnoMRmCvX%-I{R&lFL_D;m^ip$t0TFBH3%H^fzw(g=d>D9@|46K8vvhm9C zhrq$KCbkQb!`p`Y7ukc(jH(|R-T;FKEMmsqu9(NLw@nKeC8*?~XT8qux6{8MG|F>) zp3l|_(Nwypulm1Gg-$N5e|r!;>> zc8Nx8eq7`GqngqK3P@aH&rtM4rxTJt(enQ5GSV5zkq0Q6WDDmj$zHGi?AMKF;c`An zprnv5%!=Rp3R4{k+Dax4WHe?^?WCAv%e@ z7ZWX{in#k$#hso$pYvWmG0sY`7OdoTP9-f7!=6bdcBQ?43yQnhT+15uzAXAf@t*K$$^P{3F_TiN9lS?)# z3M-wpu~NEO>!1KSJ~k@-wm~w2kiR?fk|&qoAyB$LQ*PV7F1O9a-}P$9XQ%vfdOw1% zl=rlK3MoS0tc<-IUh-G1+2M#|H|r#TZ+KVC2UWI%oy63D->9m=pq~sLNok1Nb2SL3 zNy^!aOs=!(0oIU}q9H;s7Qeam+VoT=7xS5PJvQ~eFmMQh;#-TIUMb$WB)Xk5ejC;8 zkbP7^5%N}?S15z*jd!mZPmIMN1zKxo9-M@SJNND+$5&OYYaW>uD9>waE_Vx3WS6FS zwN)H~pO9skEG4!zDv`hCYA%mFZ@9*$3{Z3~mY1r@A?3Gwcsq5 zD6{Src-8bj$f=eo-R4B3&9FV(6x6tQSCC$D|6nQ>efw;s?aAi-^E>kygRsSJlD#zD zwF=jdj%zbEx#G{f^c?pp&PlxHnmaq(KGZ)ZpZP`UyMQI!XQ;cc<5xmy3eeeJh;?=phZ&yLI$BfGruW_p0L)zRvKq-rv4p6Pn)N`phC@OE3azW7DVaNKc8MVl)e<|R;4Mv^z2Ss z@K@6J&sL+B--JkOt2|AIF%}PiPP;^P?g>W7U9o@t7iWc6-G^F#9+_}M@c2^1eh98E z=44SHVlHNh*F|SpR_fu2qIfp566=5nkkBu!Mkr`#u@_5!6n}J3CU@V{a~L>KE@x|d zeH(ms{bm4DqQm7$F1BhPiE(3y%iX(bsbOr*dH98jXA~`36Rt4I7iHRi`T@QPzJxz` zm`Q<(P=VHm7D`XB&&hYo^8F;Ns!Mvb%wBCfM8yvk#i`a)H-*-E-@^1PVMw=a2FW+f zdy@r;+$C$r10>~KqwU5@XV^dkj20ab$iTDt4?PD#K(Up_4f2Py+I|$S|3{83s$5y` z#%r*4<=TXcnHvcg9HRXJr79<{CfB?RB6)R`VAs6gVYLTKl>N9zPBx?dN|4|#{hOP> zc|M|Ph7zCBU)%Cx24{vb*-5W9SyPGdSH7?;l)AZ|(C`A^fsb$~P!wX7^*RqVf{Z`e zVtwjf#~GK5fI~gJ_V3c{&AgUF{e5_Li?j-A8sAQtw}xXV5RLNQf}g9M<1ggg;);EM zo_2XiyhFQwqeO2T6};xG@5BC&I={Ow*y!dmUZwsP?%|PETht0zn=;+L8gAEdL_YX( zq$_&QPzn_oBUXoSZl|Hd>T@aQytYuk>Nr}&&Ib9M8>7u!iGs1C)r^aB9TN4Qd5f=K zeeeUOPee5IcZ)A2h>X)QN{FV4j2jJ5l;+qEA_@p|mWPM)%Bh2n!JtJQ;752wn8G=> z5~OyiU2p;_xb1J0kqvexalh$xX$^N84Yx`k!5_8_ZGeI2P+EIpitP2Z1ylSlYjR0Y z{{9ufnzinBCbh#F+r(Yb+ZsqEBftu;Tioa?(aLd5q4cgRzW!{|T2IPz8LY2Uoz)~45^XsrZ2%L8j z&H$=sGD3$Jeji`QIUxbCBC~ScA&lgYaMg{(VQVcmsc$v6u%sc6j)3f{6Um_jBPj!v ziJ~xeInuire)EU!kG|>uI9F%q8J5MjWPQQj85b+Y7=)XyTYXh_bJ$urKj+m%{>!vu zTMgv{kyCk$e@?p^np3X(-E^mqq}?dAgm`O164;1^H;@U?1Muvnq{G$M)RQ#*!kWJ{ zwnOxdxcP!0w?9msTA7^=q#lAfI6{4V)Bo$%IeAJ8972YRIw0dD@Q8@#fV zv+v3>;Gth2I}cUOSW%siaX~{Hm`dUOY+d?m$MMcfnR67CSCBC3A17Z)akG(}kMJdD zW*P(lo<#%1bJd-X?0nVYd!-tTU8mC_Tg-OKmahF=-z>ox10bX`6Ry|v+T~l{uf@;h zsiOhKNfAwCp%!?TgI zC;6JNZ;6%x40xvrrpAIl8PbCX!^QT@04kMI-3hZ_@@VmKn2-_`pmv3A)Kp+4>nDKS zxtXX7g7!gYT|OuR_}jaA;kU=MXe-N8S1t(_iraX7Hs438O;#?uJC-3B&u+ADM{rntPq-uUNKqA)aRmuxpgBYk@ca0EeV_a zxIG>k!;7^-;#95pgH%aH0&_m6cs!is1u>^@8xaCydGJa^9sCz ztP1(kN`A<32U0$hZ8W#%!7K$)@P4De|j=+%uY+t@$oG z(J$$(8G9^m-__#t!Srt;gcjWG?nroyVE*Y_3Aj&fQ;<4y8Xc zdO$Qu(N1A#H)UI2NbM<5gpxwUjpZ&57BZItO8PI<$}4nNe>#@xDUCl|WWBEJEE#v3 zo$J<$iP2UC3|y1zQpm}3K~iwo;mTizuSZ>jl?db@l(Yx5g%Uj9&X=g^$lDb&WnQT7 zSsq46Ig)$~)Z<~ie?1ZtQeJ(%g@IxOCci)_+!NYf2!*My?ToFicpAT1{nf#608~nK z^%Pp~T$+OVth;@Az=c7?1AsHFJi}}|`8&DU@-4wZ`8)pChA7qtK_53_&Blm;l3sdV)$0t&( zcC9lO%65mizBFBV`}FwUpw0@7-nbP**Ym+o0eq_G6zy%O3e1~NoQ&9B(t;DKP!A2a zUMbI{1<0P{1%=o=Jqp~-CzX_es}orw`5j?RRlKQC^Nzx@wA(WZ5*uVN>tXfkkfKH2 zsnh~f$4rD-f^wHB<+J;p;%8$^`fEQd^*?LZ`~R_&bjYCHYUU0D(C=#@LZEWCit647 zO(kVa{9D4kjV+|AH1n)kV5V}e0fTLRiD7|Cw77Hb*M?n+AM|GYzgD#G0qiL)pHmj_ zC36YaALg4DZ`Qf~bJ*tmfH$2{+1tTFwZnV)d~{W{3!Jde2wpqgTkgKFctj%1q8M`pHh+F0qf+t>qr z0A;wzWifl5|2W`hBl4yY3EBy{~T+0HF>-tPJ2t zEV+5APTf76%Cik9UWFh?wCgOY+=tYZ@XmisSd?vZ? ze0QE(O*tP-)`}{|1chHW27T~owtd?fUbg1f0#j_dRxULqO~OSaL^#J!O%%iA2_VD$ zzau({RxJYe$yqn|+(-I9?M{! zVfJf)gEqg3v7jN#%TS`DK1ykdz`u9;BHZ)!g_7Z2F;VGqQpm@F&PAUlBW{CY_JFKtkTW9@g#2pv&Kxd>hza^9w zSJH&i;NQ&1l^gO2Kg)$E zYlkEQz<;Xm37t+JQ~e8iN32%Shc$&2Q=y2sMi(~s_jOlDH(=<@JW$^$#qsPs=+1wk zUZ?vI1}0Gjc7LY|5hE9och)eTsHKvk?cvgeU#q3vI~XBagIwXF&4oTc9_A=WFEfY( z(?nq-SjZgWD~Ld?5>=L3Hnl&e>AIvKKqW%YOJ>C$EFD(~tM@LYsCgOp$RBxwpgV&2!kH)}H)_Xw&( zfl!u{R8;lUMB%7CFGb!B^Vv`4+ZTm~gH~p?2Taaq-cpa5BQ@Ww$xVglXM!|ZO7rlI9NFe1am>C z(v+0eS2D9gGgg?1h0c#(IoX6#>VRIzGwGY=Af1Na6>Fgh2ZWWO(S=_mJM1LF8>UG? z1G)Wly(l?PCN{!mO`>dPHNo6L`QA%IG-@!huaVHr`VM{Qdotsa72YOKhq7t`@}+T? z6isS^+p=D#a-*7v)Ct@0e~%x8-fw=R#bsq7V^C3#OYKJh zCwxkvwD)$_$&LGJ5+sg7TDI)Pw+xvDUm?~V{10aiL)_49^o8aW0@_)2DGpk5yvOL? zXDXtibheVAOF3EgwHzWpDU}kTG@|{c_awiW8dP)p5LiHwb&J#uWI+A<^QgG6*##Rl@5zW$4bS<^dt_aap_uY%mT$TfDlEOgB-0a;vW7tQxyC35_-(A^?N zaR|~^*mtW1qgCBkmPG2`&)R($FGWHnd@zAHYcZNfj}1ZU)w{^Vw=9D2968iVMX$14M1Cq7X(0Rs?%(7x>$GQ+4wvy6c>bS zg?d{LMuv9@=4~2oE3~j1AHs)U$0Kzq=heBVU1uoX$#w>7RvxST(GwpV{8Kh8u_AQw zZ#R~V4sYdY7PZ65GWH||56YEFC1T1_&@S{KO;mgLf?7)JjP7q{TU>Cc3D{0zAT7Lq zwToSr=apGv@J^-czE#V1X%H=A+!JpHHMY_ol}%Gw#*2m$5S>HD>?K^3wp2g(*o@aR z8{S`@eDm=ZCiWdWb7*G4>JeR)U0 zMTU#2>SjCcOPu7A<>*ipu8Z%9R)Ueq_x;AvjXQbf@FeXEn#}4Hpw^a$=5bX{Gd=;R{A~5G$^Ub)qNSty9NzP+5B7p>=Q}_#bIboS?%FxS(UVL z{(}eI1?U&=rowX=KzDG+Xhl}m!?DyR_bt|x1{e@&a~t_@}R zK1Ml{Smq)IY5JQ5I+pz~$~qeHcC-9ck#r3n8V$es;Mg%)B!L+=I~Bf+2$&FOrs9Kf z>%#Fhgx56aT#Np`-&ji0E^ZoEyz!k3hFROIs`!S@Y|_vfJl9~jW@_=x^E>oaB)$U^ zrznXEdZyr)q^4(mRqXJ=o1MDs5}8(b_w;=WXilwLk!k*w+RG^+5HsYUEvWCODyJTt z_Y|{h{veMx9q()Iar@*3Kwl z3TnnzCa}7Dm3DU38XrmXb60r8aaVMuv@$E{=K878P0Zw($jo6d1x&{1%ad+Asf)(T zkWry1!$o6ReT}Us2ijSuPj%J&l$X~_X4F}`?!6Y~7KkVNN7B!dJ{w4JJhb`tR;kZwuR~HPhwHOi(E&5ict0-wN)v61d zSyCV2gWQ`geWxKj7t*zzc5zJsO;+}9lI2`r60!uy9n&Hrna4f2_de46f%iKWjLF;l01MC+CrI74a>%f30 z@?P27A|(wf-2zQ4rR=`ADXTj&{KF7e;{){ACSn5I>zRXCpLpfAga*q(9geFnrPn?H=@K3x9i#Y3;KS38 z@=$JJ<^?V7IRC(h7%FxacMDQ|Qz2Q0P{vygF^b!;X2gakEgO}^3FT9#Bdlp-bwNgJAH#f2|$qp2TG9Z#)WEXVeEHPq}&5djtjsEN$ zr~cS>^Cp|(d-T!GY*ab!7kHm-uN_r^lO4=RP+{9UI6--iU_AU&Grx0YXO-1&O)R=j zIW>V6j(O;F6(Q{BUu=08`Vcl~cZSV>grJ5CyPYpkU%-{NYe1BqOPh@Lu$*ypvcta_ z(_YQicUAL^0MMv?7h#M7UqKG09(6%lai?~g@O`dpg7TvKU1QBmCj_OaFRC;RLl>V^ zlYf_4+a)k?p8^wKM6vWzU%9?#q!b{(AZ$WU(^XVk3pT?1hrg>_r2>IH*>(#=k=9xC8*G7d_#)_=Kys-#1Xe<10%h z&%=mwBKhdRXC7^$r+iPCZDVT?TZ_BV6 z)!dJOkR3<9*roI6%1)9}JCH;5vOZRMTKM1H6#s8-%!(yd}2!Rd=#o=NcHOGregEnL9mRHp8XpH;(CvxGu@1ra&3wKUEH=W|A4>&jRI zS?;qWQsZ@A8@DquICVu9iRj|BucCApEcL4^hBDg6(Nr_znzQUC*NSPJQO z4B2tg(XXHfZdwAFQDJa9$7zM3GBtAADLiTOe2DflOm2bit@A6Th^S>V&5yn2ul+O) z^CJBGY4n^MUoY6z;X;w2^D$M_T}5Z!Z3`EtA|_~=ATOBkOV89pxkoc^aMNnMcSwJF zHR+A}HS7Yga;ePdtApq4C*WbltFG#d-<5^CqGIwf-7E{Ub|(gv5Fnwv{>~ivr^)EA zv+!C*k=eWV&~Hy4%mW*ut0lJ+XoM&>3Dl_P5H}PTea@MsVy2jUoh6vbe5-XMv4QNb zelf5+TVD41k5*^&+dbNCdyD+eCH?6T$XHUi<4eFfO6IV0<}?V%e6MQ%g>AW1dmaXa zhjI^}cUvkY96gEPtr0i5ADbPG98a6tlM#FJoY~nX+f&@?;-vy3rF*@JAL?Wvt?(R^EsAF@naVV~`tJ(dh4YsbM>X!g$YL3w;} zD%1VV|B9cg8wo$>f&hRW%tM^}nqr1qB5c0&+s3Gx^9$-UzRa+V&jqKly1w110GN{rsc)fP_)V)ke&3E4J|mJq;r(1@PwYt}dm+f@7W%wwH;)`(CsfBuALPRNX$83N#3(v=+S5 z&zjzwfJGO6sZ1*VGJALPqQFE*(ZY>2DN8L$`A1aV_hV%f14!AD5(bLu31fr9dI2dhle8qyM&F2Ml~G< z-gSH8rDAL#bG^G4!&^@aX^ViWYMnO_E1;Lq^C6y2BX7o~ZW+YLRpWz9RU?Zs#L@9m zOXvJ!dquH@gSQAp0+QxUfwkKt*?&qDZiiXTqBRTNWm7(YqS6_Fw3Wq`>pmjXtlXFu+u8Dz5Mx5fWrCwJR|1)Y|?Q-&dnuy zNI?35th@QIdum)SU*T*j28~}*1uKJ!u7pKiQPwLJA5fmP6oq#&B zSirkD6)OB%Y9*A>Gm7z+Ni`xaOrqf?%(1Dxps+GylbYmO>^bNhS@m;p^w5NHHTmSHMDb zuey3oF#_oq@h))v5f8(=FMb5{K_l6+?Uj}u`WSVnoJp+6UVqb|92~1tTQg77VOdZD zqXfFG$+uhj8DMsO3qcKZbzu;6pQff<*~}3gMxzW~xyZ6dW|X~We=5)jV@~`J-vlrx3yhc$kHbh61RGxOtZui}J;l0@ z1IdDQIfB);e*Xi5n$d4X5}vk1Q(rxEtU(M(!lTRFe5R>cB2tb)?V(EPpM#}QUC@~f zv;eBBMeBEoSTfeZ@gc5r5falQ&x$I{9@{tDCLu1M$s~vR89pzOby;X4W zPH>;ye=4FRb|J0E*IYHWZ|!t0`n%g4UUfb@m-n55TWbulRmL`CCcIYM{Sb*?I<7$? z`m3+(T5b8=zG!;&U$DEHF@N5&18Ligtsu2%VBIwioLfQ~1-c82a;BQ=d{zKh5V>)K zX*}#UH})0dG54Ok_k7vYp`@tO+SC+^uBN$F;^GAZyuB7puNv$AbS@gwNVp9`g+FB< ziS(Ed?MB)O8S&O%qg(&8>QHkGe;Vr>xCO zy<4YG5DUpf6|kU%>eMvzweuB!yKWzOTXi;bdrAv!yGdd{)SAI~Kn;~tEw|G6{Y=b$ z;SZ;!;R|2WuAu!M**9IwTm9#E*W!lY2*z(Dn0KuEa-1MF7q%QHxrrcHJPRHoEr zKadbLbnjitVsB5`9BIBnw|0UGkqNUqctF_r5V&`6>dCp%=BpJ#c8m7AN%P!2l^nqsBy@3{hIofIwb~ zOzBcYM@DkSW^QV@88*Gi-CrQu_uC!M_Q53jzbyUeo<)~`!cC?oYaTB~g8N&Xo{$P` z4j-0XYyU(oIi}rmK4-;@c5m2`2=tJJo^G?$W6?uKG={Md!+CU5G*!pj?!c2+q>nD7 zIq9hiiU|6=$JD)I_o>6`PCIeCvzUY)s@2lB;Q9k0XY@MHrf=xOFZ(G@0!1rwb{G)w zi`Ux8VD6plaE@As^)3gP6c3LB-)#0Hu^(d*Z<|v0#th2c%+WTR#z;>XfwKa%Ors@C zc%~-qMe+!AG3_q!_4-Qi>0U{!XRP@Gc#^98pJg(*3Z8D=WxDw0ebYXIUASfUVqsVc8#iPOuOPVaiEpjsbkx4DwplM=72mha--KL0IZow9Wxu!#BLMptONS!%|X z<-qe72>gFh#8hHx>L{zdBi6e-FXyF3eJ}nrr_eDsc|X5kQydicVx1 zLkpG;J?=26pZh}q8d=hpfJ?}S74e zj9+S*dU39tU5*UkmoOwmzKt)h9=mJWj-O&d&FqlSKqZp&7;5D5z-)~wVv2YhK!qMi zFBil3ZO3ZlnsPs+=f9;e&sy-tsE{jZWB|JQ*cOa^sbrpj?mHU+tjY(J%sX%7(#XMj zxbc4of3hnIK=@cnlzQ)a9vZuS0_lXqzHX=-y%c|h(Jbzt>j}Fy@)h3PtevfF{T>uj zyuF$xaW}jeNT|)3amxezwy4U7birWMlxlu;g>wOqtaINw)r|?|LIDGwLbHL0DBw zp(sH`5puS(Y(z5)iZ5Ktn;?37i%|bsl97JCDDCImCiyv` zLe*>=nxfY|rlc36e)`EM#{c#s)<-|$7VCbl?njF1g$ue{8@7|@5ENTYmPFpHHATel zFn*(@czsJEid#tj8pU4iUF}s?&>lPA0G_(*jW2V*#eAkHyxYZkLzpvWPuCuWPV>~BpLur44q!Esc#&2occ9oxy zD-XJ1p<24kLQ@gD{{cR4be41eZm6J&=16p1Bz``Bz*Ur>BKnL?`G z%hsPW(>?@On7)N_BkU*T_(C^a%B&bl=N+!}&euKjM58_i@|2ohY?;TsVoM))nPen= zsG-2_-B-B)k&QUS+_LJ_`1|i%-*=|O;MuI&voivf1fD#F=)%bBa`a!H^WH(-6F-_p zJbVz0Y!p3nBX0Us*YoY;UB<_ddCfG+s+7Fn z)j2aSDh`uak=zSfb?SIGn5IR$aqWR@OASi?+5OVNLXY`mqN%o~)}OjyDvScj_iC{O zioQRs@I7}w{{NpOE{iTr^AZr}a}^FR6edcpf#!Ds8P6E@~cM9jxLe;dQ)RSj(#zjT|{ zj6cNvr>=b>ej|^^@xLa9G(x#Y3^qL(o$<&yMn8$$@u-p&StR>;tPYsNsj303QYo9O z^<7^JS9o$Si`tww+*hD+v@Ehc;1U$x+eZj!jQ&UVLGiXDmyBweu+dL5USrl@++Umy z`qm{ISLg7*h16u2`QhwSG({q6)E13i4224yb+@RpGuh6fNH5|gl5Ul@JrbIc+0=sC z^FY9vUq%QTS4`_DXZEv4yu$bf$ZGfbC0@+KayzDmnhn&v<%U z?g!IOAD@gTeOvVaHcC560wyR*)l(#)rXm&&P0M`pKXi_5IsmNYsrj3F`IjhSf2pR> zliaP5+NH@^YmmD7qAIlVhg)DP+SlD>>@hlf+)*obt()Jo)Jkpq-I@kl z$wYw7p5>Q*-G(deABMn0=!@>Kh6OanCRNolmALdbgTuVd-hXJ6LRTj^jsZ*Pe?K#_ zihM~7Sye0KX=eP#-Du4@;8N~N7SAx-NfYzKPv33lq`?na*fP9ZN4B(SQUOXhm!r{u z<-Zm^o-LEyC$ZiatCvCJ*Q^r(=I&m`&NZRPX-1~q?aR~k`|PFhnPuif0#q<%#Blv8 zS?hhp|K9%EDe8<*9!ENHeq1+>fGqL?YM*=y>2(Pxz!PpPbR6v!`Oa%t6;K%2zz;!gwRg2!ebtQK`r=G0OBoOUf%bhbuJf0B zP?>BOGpg()+((qt#Zw2jKE!wwZ6Hk3>8zl_#V>LsD~?)tth0=GZbi{ME!Qnjxi0V& z6HojjN?P?HFhL@!Qoo!`Z@=)Y$DauNC+F(?-iQ{tG6++KrW~#mVU&gDVs~XY(5?=< zv6u_~)c<>3`n_*Aij5@S1q}AEci$oPT9dJOmo1T*M33ALdu3tLJZ^pimWj|@tJZpcc)d)6f)9v6qw{coh@xAsMn3dZ z1M_cZ(#G7<7T3h_bwfUc5$mOKCC|X;zwB@AwF5xx7ZQTM7r(H9(}ajOEdozO)&a7P zV2kF3wIQwiuROD1%twv zCm@hQ82?>19Jp&R#SHSI5!JssS(RN!94G=kv(&Md9?^P_@jB&6A0oV1^y*X7q$`sCsaTk1{44YO00J4aCMKpY5yNVM zRv?zSX#co*gl2nbu3qB{CiaJ5`4w-J`+nA3tJYn#loVM6G{zZjx6p8WXkn>4)E%U6 z#Xzmlx3RJ++_K3B^aV!*hb&gZSYGPbS9TzLhJX;bj_F}L`P`}(f5KGWcWAUk9)Kdg zzYg%_3pVCX|HFK4A)Cd_Kwp6(`pTV{E&L4#*=TBZ6`cEL)l7hg%vq@CMbMf+hkha0 zhq`ErFuC$}pB=YOK!Hv1$R~&5QB;45RP?0>yAwLJ$QIH1<<%70B!_#Nn zU&#h6X}l25w#!R2c@eJa;c_3)N8Pe)-n%bNvj$87@tk8;&3?z6@t65xH(KI-4wX3| zVPC5Jw@)3PAHo9y3diuiUr6IsCn|$(f33?pQb0${Yq;kFU=`B0o_0p$f2dxBn!F4U z3y|pg-9a8R;j+B5JFMVQh{TR$K{p(?W4hVN?dH?=p|G%sS+x$)MEIL0L{_3*YGlL; zpGQJ+z|!)63(q&4z1ZVRpN31$!gc-TPmN-Ax`|4>wflj(1*ZH8GKC>3Z4%X<{*t^S z8h)!g|2AH0{>z=0C%+Y28C-+E;1{eS{6JLL@5q%#JN8+5g&oP;mo`#15njnv?s?Vm zxPo|}u&TlZjH!J0frz7U{+=BO`um4P+C{;WU4UlmsQlSW1@Q@g5zdfo*hB17w{Lr9 zx$f;IM;6qDy4v2hzt;j57$|}|FFybLTi#Ew^rVTwzjkJ>uUrwXRJ<9d=3gFJX{j@8 zHm)k-gAU$?QhsKN!G$9FR}%WRLHJ-_E_{F%Xy{j{R>`(NNiE5oV@7$(+vB6SpR@6K zDIL4u31+rXDH4b9z-6&hz4}zzdU3y7*+zHvg?`$ZtJWhr7(y(B38U}{8?G(6DJF_| znO~ON#l!#0ygVW7datg%v8_bze|bOcY9mG(fr%}>*QzkMeZ3qw~lSiDNN`lS4p+cOS)S#B0(jQwu! z1iPpZ5RZ{sPzL2i=qQp5o!4Q2^U*^t5~*ZR-9Dz=PM!Nk-bweC;~jmH|NZ7+siS&? ztvhI%7M>=OheHlr4LAdPs3aU9zFu^qt!G>-wzqOOc!h*`pxngbN%zJX-SL(Tz>o%3 zio6sX6{@L8zTUpHm%c(T4U+1f&4-3N?rMJd|R~xpX?V{f(gE&)woovRi0> z;#ZRMO3`zcB3=D-gwo)!#j5Sq(X;vnpjv^tRgC{;7Fyj*XFwi!KRTpKyFR-ir$sVg z=|^O+k9{P8`y9*VR8&NUJRRH;{gY~Az3UMfI489j>k)5|UA%*;=kE|QZ0o~f%UB|n zZPYY;t|uaY;Hg>p64I0|+zkSH&gnBHu&GEA)!F+iTh26w;6LQ#qyt0W--2t6XW#|y zLyt)?7O%q?R_c=PLf&8waSAR_ZM%rEwI*n2$m9Xmtx>n{q(xRJsvlyMp-ABC5R!u0 z%6dlh=vjG||2{J>Zi-p7f(H2Y*d&Uw&@~KNO5`PS=|KHepcO(=^C(!W7WK|2R=jBx zDN<+DK{a72gFmMFf1sUqHy+&u>46RzGNFKW(P2NqxxuF7th_K_=f$y-N;0s-NjkA+ z;8#pF0361+h@}y89;4+s5Z(bZMdEa?I9|~3h5h>$-G;lwF{Lp5Ea4wnflZ46$3KBO?Nk40{WV}?S{vy=9&?;*h|$4ta1J47hD?~2M7_OQp*H|21d zFmj6~^cR-6{XOg#bX*BRfDsHN$&oaOf$W5Pt`K>8-V`mvEsbW_!l~B=M|&1VNK-ms zD@F~jmEK}0VYNb;wk5T^7Wo1@I$m^|*P|eAN+<3PeFJ@yYnMhT!hHVmJdnP2&f+U| zrO&`kJ&M-Ke$(!(?o$0GbwuDQa14O zqwso3;n?@q-Iv+EWO~3`CE18L|&B?P5=;{P<8`;zJ7}4=*J5Ao8nP zNATfx1u0SM+NZlravhttEv8awAwH38awO1U78HE_?LURu`i*ZqX_)*$r*&E5lq4h- zMe3R`;Y2{r5?E=4m9Ji$&(@h!Pnekd{$r%5e8@(8luX*f@DWIff0KC26bgTcl{brk zE8g9RrBa?lDP750uhuIM)K=oXLW@omp8B4v7>%8!nvbIY)OE6FjnqCm~9RI85v zx4ccsjWFj1)qi-?|F_se-b7LOXWhd$tP8;atjl&V(wu7LVRedW1?Kz{`j_pis>OBC z6-*1mg}rE@CiRwito+2Vo6x{g3fXV{mwbpn!5q$R>?yzCif39+!sqJ}K3`2ZT(l1V zg@LyYqv$vNZHiKT$e471d_kD&V*E^9|vLo49*tgMO;NH>u4NASR*cA>zo3&~Y)ijCSwV!WU83@; zM6JsuUY55ut|9FL8YxSy;_2n)ogp@Q1xW-A>M)3`dQ%F$7GMO}!~gI^;ct=dTbnuK zIKP9WPIbIoAQ=kyhg2|Q$D#bTZ7+|ueI{RTbj$P~p(o!>9Bly&^NiEJhg%G-M?BaC zUTrOz?Qj=Qg24Wyj~$ATL_RriN&zlXoL7|EK1=?*;V>VXJ6Ro9m*T+UO|LeNq|&^k zl%Z1KJp6vn7kcy47z2yg6{Z~O^T%DqByokxg^jE!YRDCW9wy|p=EFs=_#;$eS2EyK zrXX^~-h>b2P;KLJ{e1jGwk9obs*=M}W;|m22R$E@22vR=&Iv0_?q?{5$o|N~e32rm zFG#t*riyomW;eeLsjgr;LR%oe2;ZY?@|4a>dIuI@W?^5W?~-^ch;;}R(DO;eNfM&b znqNjUMBXeWMVf8^35fq+@qu3ht{kC7 z?0k`V296gg0B|-13?QXv9Hildza4eS&>9}}dq@lG zC#9Y{tX!#n;BO)mzJF$3Nv)A6oa|QfZj5wj2F0ejxI|=3+%ApJDK8=wkmR*8L@qy_ z^JZ>j2PB$W&j-&$tU-ZkBcu6-Hd-K44+8^#-}~_Hb;^VR)S5X$kq(UPB}%I3$!_ znOAky=+Z`1cRH9!4I9cYcznYFhN8B^gk=Pi(xs-);{2r-XSU56H*b!WNJQWx zW}1@!^#Z_t20yp~PHKU-x=@_EHHK!z1y%6ny)MOGHSk-_mvJ*VarFa_SHQBlK=MkO z`96yhCN=rQhB;OK93CrFq4M^*R*Ex3pB&L$$Rt1LxT_KH7U1tt`l410P{5 zhuL>lSgU-Eis(9C)TfDeY+(UI8Mgyp?tBFHt4+N>&Nm(rT}L(RWBRQn9AafAZQXDg z=&%5my7@K=VUNc=oVHrLcCtMF!GR$3WXL`esg(NB{a)0e!PI^sXziIk48@6de+{IQ z1FG~4?%8w;>V&FWS$_NnA!84KF8+A!bX6mNv2kYW6I-<60ccPJS+vWUuN5`(ZE88 zD?}#_m-DK0G&bw_vbi)qt9)SMrrvZO7AvFwS*cweTrp|z?Db8a62Sy)Mo@(?_nfTI zAaLBjG99sNRnMpTfzP%!%9MB?0VjxiHx3$Sc! z;cDN!{Q|@tus#SRz8k$qor7;!K}5f2LCZc85eCkW8s?-O7#-{{So+d-E>vtP(eeus zFA=~`pSPEhvMTN;Cm&Hi)vQrdKVnufK6)N0Kj zrD`AxQ)9NQCeOL%Eej5fh=3pI`fjFc@(06-yFN%ARs&30xYf=fu_PJ^VL)r5Q-vS| z5-OXFYzrif9AIMx5&Oo+bFJnie2T159eP>CJOCJnWmWPq)0MW@^5 z|N3=sTIA6G#5e;c|3!s%;hc;QgRFV`2vODiM{%{qKieU-xLK-mo%>B1l{V&9@8rnWK7_(`10b$WYtQ z`TOTt5Q2g^uF@mM_*1S`doD=H2W`s3;7N3$D*2z0d8Ea!B7tYy{7$B<$xbSEz|;ML z(qQ8_9eu$2jr5tM^K;@O=%-kH?VK%uEdionI=DFBj4A^yDQEd+Gq#Gc0}OXGDk zxQYLKnv)?bs@*n*uQ~imSJ3Bi@8wTFzVI~)LAL5JU60Tm12z1pgMX(2{W+1e{%2n{ zK84FR^SQ;&0}uIut@LYjWh>1-9;c6qnvtno%Dn`9SqR)$Z4r>xxl8=RyNqBH;5C6N z_2h6WnWkeG3E3iI&?~Sl=3#47qVu>^-7&;FW6q>7|EjcG83(AdP?nE$K4;wD)J-YS zh+WGY5TM`RD;XYj4p`8^_DXsW8wjmTDqRaLBWbVO6I1;uALig27uJCftJJRRR3f(N zzt-XeP%{ag@&9AcyG@1>od5vH%)C#QK1r*H_-j+dZi&cCF#8M+;k{iAcW&mz|1s#v zdr*OivcUF2oAjy^s}MiTQwCPFO1(=@flXEfzNcGk_B?^qmw!}6M{L;7WS`!J+k&Kw z)1B$EMIOjDvVshcbLU@~L3_{yJ9I{`_%1{}v#JNN?ig0Mk(?F-IbP#{r$AlW*30OA z)y_95$*#M|_+{Dm?z?#z7sfG8Tf(c-WFy~7Dv?zWjlLW7MOovC?2ry81-;_VYXIDG z!wG{f8H;1<2*7as+A?a#UO4ixRE-musEOC(i3Bv5oI6n(IJ_L&HhD>NTz2l2Fm6k} z8xpqRxe5ykm?Yw@6R>|a9OrM45r#mX0|{^|y+N#3vbd)(s?hom*rz$%$KMu-F$Jl6 zI#TsBmZ0PCOg8}_RtjMfpjJMEGN7rNCh~t(wbam9ko002%ohp&iMw@{4nosk&F~wP z2@CtRtWdndtv$&xEc2W4$gG_94~lg0MS_;IgD1Q11nn6sVHV`a^?~J1?mc}XstjP8 z!{{Y3nG{CxLLMFkto@A?n+X3ln{|ngyqwSermM35p#~GhtW94Ya(}E6<95rMsqvWa z#5Qc?o-6nOs9oYFbsPZ$4IgQo9XqwXirIAy_1<5MoW61H%%L6MDrt#O+WN4)&Es{p zly0JE?;2N-*7jbr+c_{|Yxsz7pEEAyfz3wz$WM_$(2>}<Qqx3WVyo zb##Tgvsn1Eo+*tVM_)?_Ly<)?8{YYnwsOTyRasKOJ+m5Xnyeca7S69!2| zI<+8nV$bobj>aQL!McH|35qX@{_a^Bblx&NDkP&yT1Pw!`~E0jS+1P#%@10+ddD}b zPq6Jyg}cw`2D6k`8$%=f92(C5-ld~QjD_$|acx?1!0e)69rB?bLK|}MA%+SR1^&@z zK0yMF3aVT#%Saa@ertwIm#+>9GVrM{wpy+YkSu$But}FAp!5CZoD7?`S8?8%sm{IZR=xFmNl71ZkCw{adUSNJeH!p7EHU$}1N4&dk@d z;g@6ahIQn|be)EwgBVv|K@x^RrJP5oQe3n5+oH%l1lkFjopF=cZs2-* zD1Kx+f(Y}k$XtQH==dMl=s(xRGdqY8@tvvMpoP$IpN`uqzWjEX=}LkLcYOTnH&R<$ zo0$K_O}!cginR%b-r&o%bxv_kCj^}8z^DErF5H`Jv4G|_2MN_1jt=yIx-amtqjURG zSLVr?!Mn06A6Z3qLvkacxbYT-4tfNZG+6N$=(@K3^G7EVmWt zBIZ2yCuhy_jo%F?x(Duz!GFIJMEzbi4b^+rJHu@i=AzNws2_bj>;U%j;jXzM$0wmV zv;&i8aGc%DjS-QrP701Pqw5bbBKN=heLTEjhG-AF&+}dW7dxNB0gk2F87o%ZO`woO zw>_L)(aY=M*vq9|r4NsN3MoB^hyDs$NNo=5vcH+o^LJ1_eXHsjhR&ktIH}L7yT!2p zp6`1RFiQpxi{QsIK5tq{J6JDzrrwdAOFM;5y_GCJuQszQo1Ka!fABajSme(B+`R|fiT!%w-W;$`?MoR$oK2NX2*ZI4P-!OKy;<)v zD)*Vb9zSaJNUyo8&;+gruy7J5*WiGQEma_k3ce)|oq?FJ5^bEztg;*OSkLRBS@+nF z-wxB}84gdRg!*QH$lF$wFAZy1le>MS8HI9pqy1D=KP;JF*|Swto?FU$o8!HNK@snX zJ}uS$tR~|kE(6^|yP$i(7-SlxSM=*S6*-o8O0&dz1kkR-Ec()zH>CZ7MV%S2?kYzFzGtw!Wk2yW8Gs#& zE}J!kH0_Pkf6O(~yVZLMHmn|=UoD&=r6-cDEeb+?Bkf5KPV82I3%w;J^L9E-xk{&W z6Mz`+{t>m7jZCMZYW1AZUAIrndQ}RV^OUHjEJFX-pG9*JX=;fhiyJpBBxa02Ece=r z^C55x)ybhA&3Pc7ZVwGbp5Usw27Qy-Q|zQTd{krydhRN>zaPGMYT+Uh8cKohPo~Ck zFZ^{`I4RR#f4J>;@Gb@6?-PJe5$6VHVIqxQjXwz5%6}YL*!eS@B1pV#7h+plh=ycG z2^DdZV#(GaM- zCiQ{UK_+`C7WopJ+#-)~B`h)?*i_zF89D;&phXCkj}r zBSnt~p=zeR{>3e(1Uy3q9gYmN)VsqrFlK1O4BIjeH~~m}426x2r$h-~jx8q^EGtCD zcV^T$z1yoC-QPKMKMek8N}pfkP}vyQAYWpRtFQ1??oxIre+ahuTcK?|^fT}iqJ7Rh z!9I8vspCuFBXyM;xh0N!7&kr7X;x0ep}6*Yy@ev(==~LvaIciN=Suj~1`#QJ^$2=} zlHzQtrOL<|jPX@l;>%Cq6^4~6*C6be+#sa+WB{v+-WqxXr1C*{46N$Z?n0|Mqs-6{ zW27Kt-@*QOcjdYmcXv(M*)IXne5?qVHSf#}brb)X;Re&bin=ACxm^1=Ql@=E=ct*z zG2&#uqg>e1M><520S{{yFKgMpN9WUxqZFh{*zbs9>trK^f#3FEensM|jx76sS}Cd7 z`eVeC2&*R!52K$HEhEf%=B75vEdQ#ssoynYYAm+WjH6#Bqp-AiE^QzXP|{jg_DP^# zjPDOwTo`cJ??bC%FzZERP^xd}a?ctPANRKLl14HW>8ZMVd6G?!qp9(<{RD#?`&bY(4FaAD0D;UR(Hl0kb@rQ18L#{AvB ziC5FloW;W9y)+Z|>>7ppyl2Vy?y0mo$Lt!`785q2uEL-YA=CPYSowT)$%f_%v+~}o zb{60A2&Gi`Wib^Odo)icJ=5msR+QcpG0Y{2%;&v_o4}~>@WCv41AHv3Ddj`XR*WDA zbDH>em2BCY7$GK*`kbEo=kpgq&KuE^T#R5TwO!b3l#8k^eq_2);-mTDKf^&brukU9 zsK*9AY^@WnCpUwi-R5th&fOeaWDWAVgd$}TgU+Y%?^F=tHh@z(7>SQ6a?~{U8X1jz z15TnZQA%LEe!+vur|WsTGK^lzLHQ**=kZui7y)-0BypKEx)UGh5nYQVXf-syF^%D^X7)` zBjP8h_QcuUU4tr%IVhO>O-l^hQeu~i!%mQu{%Hwu0!qR6f$$zduE`^cg+DrcF$3$9 zQe6GlqIm+jesrZPUeWA?$rC0}u6W(}BdOdHC2}sbcnf%qO{f)&Uuhv@M~ksiu1 z)GiYi2e!th#Dw~$-3I-K_!FvwbLkB@C@lGSQ6|`&uJvE%-hn7X?i};^mEg>EW*;<- zn6!8;m9p)^y>JW+Dc5HBhPvjlU234DN?s8#Q&B;{DIAd#7m-&l{aO5I{o0OE4?4-U z>uoEH>tn=mE5E_22|OT04K;3Vo4R$;+CjCX9Me8v^$cCUr@Hu&avm)t7MwjnOfWvK z23EO+`Z0grEfTa2X%jG4Euh?g_|+PGyx^{J+|%55kmh3kaTyM7db7gR{UW6?9)^(_&Kn7-yiraoof#kt=0;{${ zGOup$oS=}2$ocBh)>fqf(dAm(Aau!l@4JA+)PQ2a)qbCZU?B~6u^vAb7MAs-^0GCY z_xm{>ZQX_@1QER-P2|a%jx)N$WONQ6RpoYdhTm78S`a1-+0Ep&D)+sNZiOv3@%JRc z_Cd71eYBSreULM7hsqpfv9cM*jdX5l`l=n!IO;?e=@wG9W1n#_amGfElQI7QloN{Re%O^>n<}o{7COOO1rMwu^nmO z;K;H%w8+f(+h&tDq897|Vk?$nWr-8VWr_-4%+nl;NhM*vBy3W{DJ|B>`g zE!dBa%75i-;i;e4QjOy|T5f3(I1D)QlLn$$kkD)){eG=(n8Q8_Qjd)(ryE9jsD=C( ze}{`lMSl>xgNhg3Cy0RP&MoP*Gk-a15;b4TSrr8>QPO)u2^!HXC3#lj)&kx_P-E2j zcMmeWxa>K#nZ1@pN;1Lxy|7KknZnBF3O-`Nzm{Pl5-eQC-(bH(!`q&_PqkGugH3Dvppid)mKZO+xSwu=0EjBto!|mL<_l{wX><+yaKPf%&iKbUFW( zLEb+##1dUh%rm#d?r5_vo~JWu0s)x?J$%D95QnRiLkcRo{`G#dq%VZo z?L9I%%5nRzZ7Ff_GRi~4x0QhD0k@j5O7O?bnU`CM=Z`KD#olq>Ft{ze)#hImQ*Dl$ zHVN*wn8c6cDOVYx+qa}^6~tf76UGsAWEQTgxwJK(L#w^#I^+@1Cr;$&a8o>uH9?`) zgG@TltHT>(9TGR+#VQQa@z=$mjgcOp-y6n0hs`w8bX?0!cAL}6LFR8*k9y7N;SisL zz&C;KV5-PzG?=BK2f_J^I8Su52B}I}m&)#ud%$z(2fAZ+WN4FgC_kpYC;i}XbdsP7bb^UPjwG`n8`)U&(n@HZi$@ zbiElSf{+v3*e&HL(XGP#78c)7cm-9iqBAHLmo?^bVtm;!SqDYm%$li=NP&(P->SC! z+aHbWH-RQZM!Ay%cN;5hhTZ484+IscYuI;|k}{9)vwF%vC)L*W)e zGlQ3k&<7VQF}CsgSgeQlfH{E*_CyvDcT*YPsC*6M^Mofh6cw)~#W*(i30gI#Ca34x`x z2RnQkhGHM{ZbcmZ2V#(Vn7VNESu41auyOE0_1`q0ZUeEIbnm|q*T)(-r}!M0Z;3o$ zbl49BuPi5BZ?-#2>6PvKLcSmUlZGsbz5)wW!$9HjBZz$r{~J$zflhMGEwWAtTOX_) zY*vbwx3B|MmF(n4M7$E^&NEAT$(Y|E&a;bz^mGwC2*Vp!D|5u0rV2_P$Q}|-tN+-4 zfVn2V9u(o-;21PSw9Z(g%ws#d8b5sK3}nU94i^%Ut+Or)0%(hheX;cZiJJ?yBYgj z${PdbTjsVt!$N3p0{{Na4@#d|9YQYdq?$~%MR)NlGKR%A+FM+G_4kxIe}PU7R9ZK7Y%%|iw(h2ofFVa zl#r2!@)J%VMUE0ot;1q7jWHtYopNxxfjh15*BiLGjDDZ5rM%deoCow|3RYy+A9Rcx zwL~78t#;aM=EQX>U-{vE5$~=E50`_<{K_h~gi`mx%>w+zXvTcw?C*8&d_&)M3nLyO zjRPdqtwTK>b4oMES>g)b>6tvQE0$oBiXuK0-9B<~2w;fvjIzZzQV*=2)=O%;I87&t zkdxk#RN(E-Eqj?#2p0_pQ(ZhhaF@&Im-4Mse!^W0oqR3-HIN2rm4WM=LBF{yftsvF zJJCMU`EvfMdR&UA<{;eY=pLB2degNh5)#2*{6a00f#<4=rPnv9s zq!(MgkPD%;318G zFCF|U8AtL3C7TEz?N}KcV4yyn(ncOu1}IAOe+A;zbG~D?_Pd)ZLk!$p)|Fa7(N@q< zu6*DI!z|{ZJbS9p(aA_mzHq^NDz9YXA~QZO1%FW<(W=YcYM}YE9JjgPATym?DfF#| z_QoavJeDK0!cPXvr%Dy?uGTG3((Dq)XcjHVU-J50nP<*we|F@Aqu#a#H~3+U)wfZ}F9mFW3cciT-rpd` zfJ>9rOci-UH0BT-S>aeJ+A-Vy*9(AY+4Pz#KYVafPE6^5KFopLgkplJuPS`YzyTay z8qw-zohb)Lx3P0{h$_fj9jwZLb=EStQSV)52}%m1{PD!)8|pjE0>|dqXg$`ENBD~> zH=q-Mxil-SLuzWlkF?dvMEu|%*7;x=l>!c>LHjvWWM4u+DN zjvhCXY{lTEq8HD5(dY{9D%ef+vzT&XCYTiUW3wAlD+Q%E#(xi^hc}|;!G3?+$IrP* zILvX^%ahS;G_r-iRuTP?b>MhJ+ls7f6vl~rN5%e8gYb#6GJH>*D|KyHP%}&8GL*sS za{IaW*ZOVSOP_w!A+=zozu_T7>Dipi*J=y$Rb9NGuAY?H5Xj5ls;+hP>bD--Nv$i( zSwPIRwpCdmJ$yx}@7rO9(Syj!;e&6JNTL+}@v-$^FFBfn(+u58hu3OK?lHI* zhR(e_E*RJt`i{j08C`6hd`*Ns#FUp_mLcS}Wx~}o-8Cg5e>65kCMDL=_r&Yg$oLhf zh(){teVFzUBU%ahQpwifJ8|c_A*Xbp8=-{Xu=l+Cr~ffxEcQ5jQ-DJO6yQ7KRU!89 zkTmuM26l9jZ|{^h$gE}c=Y`}9?XPb{b7CU}3{(lQTg*+Q3+BEUU+7NDW75M;cKPk8 zP&C_F6E>Z)mT=+mPeuvr3lv7R{GMGz2rw2Qh)OHXV*|cJXtnvLt9|MJGutn>Lr$rS ziHgdo_HX7?BFa)wtuar5{~K+LE|*L{PP+F3{bVY(R9)?pr84T|@P%UOk*J|IP!NyW z@rP7UV)w151iMO~!g@u!_ihO6W@rPQ(eEmY*{S??$u>-aiRabIJDIh|+ow86xoyer z=B1DgUFtzgy6%@J`YLmwaYF+s5rkq1?kzed0dvXGjmMEnGUQh`SFPi_&I1>6?!s&Km zaPNNgp^3ghVo$szZz9H%em>y|>zhV281i{FV&4h%7wt8f1j_=f`$AH2{&tmC4Y6dd zpD?E4y#KN@PEB2}PPtwzo@1d*##uT|OPn_pTl40amLaeiu>*62AOqY1k8eJyy}@_X zzei@Raoh?`&Er`Kq!2dob8|z@f;D;7d{vd|U_Aduz}c+9W*(6e zSK=2+AgI6LVxav^{oMyrvf_{0$X5iLoP@ofp^%?QwTxPc=&9Go6m4~~duQxTcaj@b zBTL zWPV+jb#PeisNb$Ya!n7liG((LgG5-ue8XqkD~B7JYh1?=(PJAdQVNiQUn~0^ccrvB z#ZM3;`YX~=@=x;We^^^A>h>ciYTCL8f9B_JRE--BoA?iVOP9)^%}@|%{DRp(|Iohy z5;p9A5;jz6n_1~be15f1i+w6xrwfKW%BqNJ6RGxRNlVf5j8@R~vUQcq&xIx+ha2l069*ivE0WJA3g^eJ*@ z6D2wW`HHe-GLF2cimr(L=cx2ylI;62HMJO-WhvDI*8UUfdri2Jnhpd)>HGp4oqzTv zhbD5%#NZ{hzZG?GLcji!L3xV)_0uuylXGYA&gklc;)@bVW|u7E*Mk2i6hOP02)Z#R z6Q1o~#j5x~k3UBR2z1EP_Ry^``zCHm@eC?(KQ8aT#@`_0-J*XTOVGxeO`KFh{v*Dc zC}OEYp88Jn=%zT~Myp%Y<1!A_v6RwBNoI7==4nXMPb{TrWvTF3Kj4LyhlByf5sEKl zWbU%f{pM@tPK8dgU8Y1^zWXZXf6|eP>aUdCQsxuFwEH`EQU_+;%!tfD#c(GjJ*8uu z$pNf_WW35%4r-$rlWyAq-?oW!0{`Is!7Lu3*G0%WS!+?bEwtkGD(v7CI9;MkRun%w z{Vo%vPLZ*0e8@c1(7*sBJepRdDW13C@k{s({OSVruOCRWWx{E75WT^@ar4mS@>YNGN#Z1w03Rcn@vX5|Cg1S^>lWU z1g{yuXj1%hNlgN><4G+9DQKk=?j`4csE#AE1j4yyE#NQ~%QB3+les0h4yzb-~le=KZ$|`Zu3PTS4Wt*2;I5D zzlOnu|D}_vZXyirIjhZ4T=JdM2*)hU?ImUcv`yl;i;*)BROeZcBiagj;(2|kI9h$Q z7t5tM%S>-VX;PJdzfJQRFIBJUgQ&S5uH;1 zmCZUHUR>go=ioev%T)P*T`tWKiVfC*{G@Cn^)t!F!&0V zBnTqsyL+=!UbRYqNn-DUCl6#Z0Oc+h)gcAE^K7xiqY- zjk%V`z^@M`Q?9nR`0B^<&%v!BGOYyxYWhVK`ceB^a(+&TSlR4ZFqCA6l~1gjs7Tui z82&Q5-;Jwj8E#^_K3U>@<*;lf2?=fRZ*@Vh3Z-m|&<o6^E(b4VF|4=!HK^4m;u#ROS?5+_RXwyMLZfO5BRw@YKuWyIv$n>6?d+>r zVz?FG(SHk|8pYl6S`Iodc@PZAn_MsMc?Km|uz&J0zHjBt#lXBQwZ;CG?eVBGpImwBfUXRAl8+p~`vAuuAP>WxJ9$nNM^?OtV)Fn{wc&4vh)hI@nx38EXSW z;m9NRotFp^&sR;wO}cixa*IqWZgi4!D2XwF_==&8L8`}7c`!K|S$7os1`;Ie&prri3_Iru*#$*Zw$=v>IjY~! z-S}fYmnJQW0&vEjE3A`{T|SmHw^&mU0j$B z`@XRoO4#tnB@7FzV=^r`*GlU7QZ{Lv@0!*kVodWPE?z8wy8rQx81?!fCE?`-3!Hsg z#SdNh^&YmUh#>bqQbST<)fG!s<;70?^c=4n+qmZo7e?*WLV`BN47zni{O4Eg^R4=C zVXDCkxajdN4;@TTL%m_nTAYienMu=n@HNOH@yEGU!H5dnJH!W9(aar3@QX%tV}QB` zTsG41s9hcFT%Y=h8N{#5=}80C!KN)}(<*BofsJFsr1#O2DVZm> zXOtUekogr<&k{cix8RNaF=$zt-VJvJCN(urAwvJjk%U*&en-(2{E0-tav`)yMCAC# zlAWT_fflEsz2Kz%O9l=M6aTK`M9Sm;xWE#Bf2U&#wXlQN~!~O+h^s#|0TXKi%Jfy(gG^VMM$WEOH*N@SddJc zKx;O}k-}qQWEq=3T#GrnL*d&unAjuS8|b=zc|frgbE;u6{KGU@tnlYO*i*}L61Uh{U$iyL#aI#Q0I2r$FK2 zcXHar7xIEkc(>*p^`A%N-PO?r!JSe6Zlwb|D;e(7Y6utvDD>pJEO^?yY11#{l56}i zo1`~mX&0gmxH463kZEX3|6nU?_e6ae*mT2ZPOBeZv0)AkRKlF|0ovYj=nmBs+u7)!pYctMOIfQGa-PZuUco$Bs6DCCfj`bnMW>|%0%Thu(TF#7Gw;1#yvqA zhqest6KU>o$xYZg@ewM~sZx_1epn1_qv<*Qdu^t6|Cqi)%xE0ds-v=t116LjzFAOq z??ByNnXhqlmQ=aH1=IezsE6H*V;|&dEwrS~*&>4{n^$HMuF`cjZA!>2YS~>k>hseo z?Dj+qqS7NeA)s|A41ci~oA8P7{cQbArerUC!H~u6=x*g~JEk_T^;i|fU~BXePWd}px$^7Nfuv9A}Gk`5%F(IJ*MhxG zEkixH^+w>!uZv)r;o$zNc>*1PIO8c`)$SC(UO-&24)Mj1MtQ;5etcvY{OniZ{T-QK zBU&D>sU)?1T#aaoUDuX?8WtpA>9jhhoN|9##;|(iwYI3sx)CX93F!{$mXwqjx*8p}V`!;PXE3ch*_wtTTTAYq4kVdtV*D>%JRO{OncC5R(z5-+zR4pv1zg8_U~w zy&>7?sP)B7HDc04v2#8W+d@fTJmM=0ZQd(fT>f-o%GxML+d=nlz@BueZI0Zt;f{6@ z+pwsuJg;Mw0-@+2)q^=^11j)$3N9hzH~Q=X4gQ@@oy7vWF4ye!{Z(^@dc%1%g&)F$(xvG2|z-GRwEv0U>& z1l_QM(PX+Ah9fNGo+Z)%sGzq6BL=;)cp7>pwrr0|CUY0-O+Ht?Tk=q%wijI}{C%gE zVKh!!*+l>4ou)f!5SsQ=y5f5ejGVT4wS0rJZ}0cmOLvI~VI3P=P0Mt`bnyP{bc00l zOAiP383S1$m^lh@0-smi-&m=>)IiQmz}#S#|1@N)j~9)%m8{!Jba3}&?Y%R6_1n!_ zC@T>4G;8R$&r?))iKue+%dBdop30e;kcsvgZ+8`-qHGCf00p!O%Av=-h@2n@6(!;y zuFy48NQvu7bUR z=sN9$8|%vNrMiX&78*0mUaiMD+W(EZ$s)XZPYgXKR$A?5WxmYL(FjRs=3+Hsw-2x+ z7RAnNEHs9XjK$#2;0{^6BtMIGH<*poi<6JN+X^eshc1eG8tsMl)TTGvLb?>QkcjjZyD z2Tpv}EIjf8BPT+SZFy=+J~@A>YpT-|!ZeItbgc8zFIm*BxDtxHzhH+^S3mtuwMemH z7BCpAh6I0)Zsi||v~Cmi{GQJrbb)ZIGm4An#pBK`+KL^(1o|Sgq^fxUWDG|?a~oX( zfF%G%)nTh>c^Gd(uF6jPnt>LtF?lU3G%U!2&=7w?M5oi+%O02tL`!*e!>5{gWmHvR zz8w{_0ycfdjoXG)Ot8t!{VG~l7OZxzz{*!fjkL$I;9Ln}nPlpezI-ye^!&lHii_Wz0GN2w zD6fgDex=E_`UVO|SV+8G(Z2|5VgCL~b>1#UBqd(QoC zpfI-vG$;or_fGkKSdrxi=wsE4xy<4&UXgCn1Zm5^k)JZcts)w%nZ(&7^=|+xZ-}`5&qXJb%v(O()bo>zVllBij!ayfdNP%xsE%y$k0Sd6{na-(K^xlskWVh4^ zl9D|u@3C`a71Rb9Z$gRj)dbSo0*SyE)QN@f8^Rmmy5F9>pJdy!e$0d0%M@&QBr99& z_O%YAC2xHE0_9aafb{RR-mRdz#$iGI9rkg&^I%X+>ZnJY0ymE}lVI84 zTuUK*hpl)hus%c-f_c*RJ$j0Br8rK`Qf%!Buq5q|T|VtcVMlRrA{c2;A2CJ3l z9IGpFn+0+prySSS1IxpfmDv~OgZ1)fXbx~5K2GLZt)(0{)H`I6{s%_U#%uMzFp83= z`Y_|Uy-7Wp{it?Yx~mV)`1;*nQ}H&-VT^`->ZpCXU45hP;4!`gwMo8YzGn0tybau? z^vAHX?v5k2aZb~gW=2Z zLN#iT%BwglAAyzt)pxLNU9iNsW1!F(BHyn1Oe~@56#2m>=$$P6++C^*zgkG{i1rXip@!y zlZiD1$ydjQck@`eU1_)+qZu%s@;WUWMgnKwfT@L|zcT^nZl=CDreQe}joHa8I;um) z2MsfgSzN=t8%wda#IffM%)UPBAbzeVJMl{hsHfMsqSe?-LeY(}ZUPPRgECMazOZaJ zdhm5`1&K+-lppwjTpgxzhTnkm46daQ(F3yZg~Hm}P>3S-Zea%?lE@wuvoR49!(5F2 z|AvWtzskTht9F;z(=bKXpnnQg;c{ zxRw%xj?_b@g=!3%yF=oQz;(4a3tn95=6)(oO^bQ<@Z-d~F?$@EL-xvd6E%!|gLiM? zXmi;o@OacyRzRGR&i9Rwygi71uJuw3_dkeA3-o^>DjDf0X!F9gD}m)`>CS2ng8!do zn>0e~9lje59?u%zA-XC&c#-Pf;YXd~i6G-&d5rga>Q~6~??OYK$VU7LKa(={&I!5~ z8!#g7^S^O(Hq!U5x=qMv-F+(lE1lTsVtc6#qAjT^HH^xTO;?#0eJ5r6IOrGx>mN%G zNdQnlX^2RV@!!3^%x?+juxu zR;9%yesENWl(bbHGTyovdN*!m0hCCbXMlCTI!uHq5}nvXTjzRAv7|l#5pHiOw*~`h zct7+65T9!|$&mS@(uQ=LO?UE{*X%s?cP7e1yK#AcvJdHabs@ZXa_JxO*gYi8tqJz* zTF+h$0wfzY?m6$(T1c%>3dPA5t0oHQj5xUbgy}Qp9qY2#K=^JAsFTX!YwCC;prNBN zn~J%wbS4)vgAvG0Bh`;?tRwu56c_i@{Qr>8miELllmn3ihZs`1vcMyNH6=hZ6K=}M zTp96yOL!%}M4;S$zX{!Js|a){1{M0odAD1P?U+B$U6gpd3uB+!sXf=>e%w1^@m%)Q z(uNB$Arj=zu5TC0>RyBY+3a0@6ONHnUfXx!e^H2%<)OH!Ji$~=xA&M7C05Gh7x{as zdu~s6MzoG5gDDHt!r$Ee$5m5uP~ya^A!^$H`aNBz8HaCED))+Zl>&xtb?3#S{8;#0 zYWA$r4Jd}o-8lJis#XeSm;D*4U_Ubje|2-;(mgxaEd&n!p=yT$eV_C9Rj4G#@9WDyk|7rp7>AMYYRg)iE?*wL zEOn&~a)pw0eT7NhP~JbJC@i+DM&|(v#etx@jY!%KwSRM|Y*8Y19F~#2E=YP=TML|{Y1$#-V^v99MZ(l+bn-DHL%ktm<@Emxvo6OvLN%XRVX(qaoLVwQVCLBz?DWW8U zqI{3TJ3!2Clg;}y#f1+`5sRxVA#}Z=Nw#l4|KuPe9WSpd-4n96o5n&x4gmqN^9C$N zH|;Y;qwPpf^k*ukE&c)tuONQ#snL7)%!B+p8r~XlI4ddC{zls4@s;q;g({!rL;TRZ z5ka#xS$HhIqQ?g8`ovs@B83?5ozne>1RljfICwc`uQ zx)i|=6h(l*ka#|0B}P*cf3B@I4T|o)N^iPB|!HOUUguZk3dFI1F8 zMWDfL$Q6m;tkhVF{Vy;a)_4PD{=IL)a{hs0;f#(j71C2Ix3SFDq*9@M6@1|DcnY?H zcQ$6;^QP9u$1e1vPl)0cD6d~aLwn-?;N@WCfAbq&=HTExpM*3jTsY!Nu!ut|{mK!s zm?{~+;qoL5F*o8uXxxT<*55TIm)A<|uGD-`8=TMW;Q^Mqk7oEId+W>}IO^1*hnM2~Gl>}3E&y<0-W-n`ymUj3*i%{q= zJ;=SP<|z%addAVgctAJxh2e!%Nwe^7-u>*W(v>5A$5HY}Fj|(vaDM)b!T4(K)3*WC zl@{}vLa$13%=L~rsqrJhP)i65{z=!qOziuvL1bE~u~uYk}B2CK6pSoy0tb>k{J9f#We5l=tIAAIkZy;5+`Q#o#uM{o#tHF-5@k zg_X>1QgX4}@W3A6^+0u>!S#N}r{|p?sua$)tbOHw_|u*?og-z7(8?m{Lx;tzDTK%$-6#1KW@UBo9r<$5`?s&(+!%>&d4t}m>3(uS4A7r*h~fIY zVnz5Fwp1lxN|@K+mWfxgJCw#mJQSI6?rnmL+cRvR-B;CoFiO=a%2=}IUfgUs!M0|a z0?*A<+;oM1l**fbuF#2XYCC2h7Sc+&4sxoK{Bj=W9q{`uGjm`PC=^T8aYB|Ktg^rh zJ;tI%prgVZI8@ptJ>ftPWSia|g>ed=)$}urM#NO2IS{YI5S!vxvKFru-chLnT*ngA zI=sOFtZhPTal6mRS9ah+wKTzZsu3T*JRR6+6Tk)j@wa`pGUr;pdSjIA(RzHE+oe5* z1{B)-tovN-`zsOUp%1>lpomp2<0s9zsCzIklppr4pkBO}SB{yJ4JVUVQhAk4w^#7x z3YD~&6Wh3tmociH>mL0IR1h#VwtHnmkxyd`avo{CzVx?N?IQ!a1w;|C4{L86{7^l- zHexknJ}JZrH4hkA!PJv&xTA*Su5ci zD)vB55)Rc``G$-%7bJJ`p7gKH437~pWHW^`V8GBhRov! z23NojRwf=zeU2-YFVX`@;U_Fa#mFq6yc>?~X%SA1#2KRgT{!wfpY){ElW8fVhV4l7 zPRPV`cR2Zcfb?X5?m!K12F6A%0DfBN+*%6DwKhW0cXGB|@`CoaIOGxXCM{5ZnSA|t z>#kQ{N*rZdkCC2v2)8hovrWdn&Y@Dce`EW|31frpA6&0d5vEK|i7}<`!ryStQls+x zZt`~)nwq4&cx4SeHzIIU0IEeq0hdRH0}Lz1XmuPwceq!kc7er*<)}290gj`;B%^AIJs3C^P0j` z+8gDz9M0{)fPJ@D^Va}cfW{ib1<{y0)FL!bjh<>F;K^j;oy0nYIiWX%OM>G&%V>dG zc%3I15s+q2Zo0}r-HxjYv}jJpuGYZ9<^r&>j7M~tl0F;|C51ANv?GZjiXjxjE5f(8 z?JT>UT<}6KjZ>56?0mH>?msF$*uSKeiZCuvxCB<>LgkW?VH}b}bd!G-_>RQSD`f6P zwTPy4y6iJ;s}BE$v@>IAU650$$+Y zEsg-z4gxt&He5CmEqpXWE~q=^w~uVv6OIoJ)-qV!#wTIMi-#e363e z#3|07Ub~tp&Xnwh_M~RHocb60mG_ZE&GXt7gmrWu2$tpt-Z}ny?^AeJ?R(}O5IvcV zFKv(h1*SC`QgI}>d$fB+EJDP;D7p~TT*n~M=Wm&fh>NQ9;E3Q6gWpPUorrM~YWH8# zd6d$yqsw;#+H=NelP5iZVC$qVeF=8Xj2zaL_kOZ&)(Rg#pgxR8aW(R6szCw@itHDH zjN1g0rNz<)N;O@qVcbm@V*QL>OINBz@fvW<*V%%ihEw3l+z%Qdx)vAznVGUuGbf;! z{o?6(88MI3hdPfKcO_7&#JdoZ?c@J|n*u9OG1xl+-we?WA{05>(3RkpgWEuRMZ6Wv z6|Ad`D8z^&nEsR*F0jmtEORgkKh|T9VI$W2edlvy* z@WX5EPJReM7NN4ni>{w}0tMW9F@~b;aiwhno9hA%{N;yU%QQz=%V`P)zYW&MBSX1u zH$Z$6M9M#JO7EfZ0G+*f3oc&!c)ZWz56yR2r>$y?4$e*r*FqsTQNG3EOw^Ei)Ozbv zw^nm**n;-HyyE|so=q;GIH`zw7;hINrugmP_Yhs>U_gjRi(nn90mfoj>1$tPZ{iyf z`rsK+c&G@}bMb8G86mLi(yX-c!ctEIZ>OeygqR{&1#DR{9rPllT*CGG=(V??A1ExC zM^YDFG&dkWs~UT<50Mbrut86@Eaf;a0gvB|i;dGQ58wO{$raa7`!p(qoWbZPJ^|X&n zvAl>oLH8yCINH3YbSHt3M#yjGxHN1FE$0VmsK$4Oib_=<8?XX4EbNJ_)3>hTA`p-| zLHRk4a}xYtk7CNF*7`r6VZH~pWf%-Fs0VpyB04dV_ZaB`w3s^OaHZec zEYNK7;Z`pdeWyD?{uXsF+Yl43|8$DMiPX6CNDW5$P2obRv$ZC6l8j!%%jH2)^;!T; z2d)hDRUdGDf%3*{w_emmI2q8>2_Uv(AAOZ(g3$PL%B+FUyPebJ*t$(P}ClA^bI*Mo=u|2Y6Xz2JRWMRO=SJ0$-|V zt{bLbF@bu0d{kZF;?=j*a_>S}N1&Z?s@~*N$=F7ziV&aL!qH2N@7A}h6qWZ{z*u_R z#TX$J*GKWRPlil-B_|JHnsiSOUQz9K{`iy?bl1vr6$XBO`@WCuBQUYKK0~s8*IFG7 zN!Y1`*bV0Qdk;M^EU|B7w(NI#QVB8`NbDobXJIlKGp7h(F>SE8+a<3&gcXGKjxF>jl$Q zcqNN1cRw~Vq>8TDhKi}sD1V?plQ!&0w=Eh+c{o&1Wr7P}bbyGXu4Jix*idXrH~t^l zy5a(;q_Y`i1eWDfGSWsXdLK*>&>-+wny=0|EHto1d5O4a>E<)yr-%Bj>(NJ)&fcLC za`3diPW!`DnZE(xFk!ApEOFp9E8o*u$n#=8v04m|>`93+%(;g>{)1ck18<;XV) zvz;n7VGXVEAY++Etr*>Z(LwKIA~W6Kn z_sj0ya`@{CR2{j+@D$acF^I5)3c&bN$rc2|z?B8L*m2X`6212CR%UD|SU*ZpEVgpX zAA00PTH$)=VuDqLmL8)&zJzz}`!z+3y?d!!4Serow)?<=P_%w@$-KCq7jxetkX|ml zv=nsDc|$zaA>NzbHptZ&Dn!T{6L+_}WUbv1DjbYDH;_g?T?JFEqPAeg*@iyr*l}`% zWM|GXiK0W&6E76JU_9uH;IIpBp}wi2eW+`H7x0N%l+quoJRLM5&jgvv=Zexy zwU{wPrYZonWa||2P2G!53-E?O02z<~~{x~Lz zZ3Kf$tryBzf6qDOR?yZW+9E%z| z!JF++-+Iw7m~b?-ULzaGWYG=8%w79Hbf_rOoC5{hR}Xj*z($|DU5wR#`)9PZE7^5* z!cwUsSC~cV2L6DrBDWk)&0!LSZJm{P%N=uPH01OzLin6EWrk-;tL~I!30*cY>hP9% zN^ZC>((;(;1gdc@XlYRd>2qr*AQ;e1DcfgpVygRa|HNgNbVaDx+fiJ^>t|}gwFC4q zce1Uwpr!rUSKJ)n8qnMp3)(mJ=GUn+iMTa&yVfX8X)WoKm`p}>X+1} zS&AM|f7C=(AO!q!zw&h$3ION87z zX(_A>>~WRi%E@3mYjZkr6Ksgja!!20=GfGu4c^Q+ z_i_z@cbqe1)%0LRKI%OzyA`R>o(ThQ=mHM+#DWwB9tj&0AZNBQhDN$HmDm;Bb@XWz z6wwQWwZe|O*2ar?3kfY;(-o=Xb*zuI*cIbt+;d>VKaF{pM*iX4hv>iO( zpP()#4ue1kV!!`VI-iOLE1Ch^Rml($ON_cImAD=I*A4BJW7tqDde~fm6f>;N`9=;Y zO#1Dlj9!B*k313knA&KI@%s6<2vxW<_lN!sN1nIu*jI(%(iRQ0?rz8%F}H_7M6q1= zU*Rg8=0u?F0)6VGVuHu5p6%O)udvP$gO6;STB~VMx@DbPq5_`!^V&Gx>&{EPha#Tx$9}7Y zWs#D5PvxllS<(h;!Rd!l*x)eo&IvB>eLMWqmFXelzFuF z#5RR}rWUvjRjr!FOX@mEyp$&84HD}G4P4c_rE z^p0k+Asx<&Uu2<)amK4hV^@(aU%?h8w;dB(V7gz3p19Fmg^mJWb1nwv(V5zgFb$4t ze62k5#B?Ef4<=O(G0cO1Y1iXkVizddp7%nyZGx5uCVsnBW0hwFiZ4s!!D9UV z)zGIY@ijgpT@a0zdzOe#*MS%?^^=xNnGhE#+9K)6W7uZlZT)_h(~`gt|BMpI2yK9B?sP%H8<}K%>Jok;qtD@-=ZMm90X3xlt;?4B_KP#W3@pM2SDzqP&G)NM8(r z;#`_*j&oMP1KJ>pW7lQ$;&KMq@``Ky{)rLlB~dE>q3h6yij(@2=H%O{V_Xu!a;p(4 zNSPS$YsucF+6dX}*MhI7kn=N>W*U!AX=&X%9USpLo;|K@enWC*Z`icrEr{!*^irm9&PyScwIOk+artc5*n`p=_i z&rzFh`7KLU=l&`#j^NlHDj1SPO-N6dpE+W1Tc>nf*yY{3&juP%>NVK*P#?~_xyDcE zG+Us2 zSAM8zUF0to%-Fc|_fU|hisu8TTINSlfV+|l2h-_)U{ftBCgB4_b@dKYhIn%G} z{+MXZ*RYV5&$e!*E?4vm0uGXN#eta3_%(x4ZmST~habU6;u6QuI1m^cWdYwAv7LkM zyh!Fm5V5By5gl<%*>strF!Q!&aoJ_NRT>gx>HEGIvu&`~TuMsxe67CUIJ z+W(R8CW_+T@P%EyllsD}Ef@YaZ}%O(B_<|X*RKRTG(6v07zH3_q#1X9Th%_g$ozP$ zifFQID|O|M6@C!X7xa&@WR$VCrNw(QwfEph z*?he__K&~tB^vvatcH#zwuK3sUVFn!{J^ZzlI9K)tQ{6Cii{`|y2$a0I={OT4X`pF zhFwK$P}xwufWmTa_ITG=ORjxt^}=)W;$qbd-;eSKUay{KipLhcr<|W2Z_HzS?><(v z9-#zy-RF2Ozmjo;E7NJu7Ith(Na=X`n=-Q`!TEZl&8wlJ_jO69%G(xBr(uT3gE{ta z*d3LCb+w_oGTU@(o-@chD6Mg&Cb8&*r!p**!{?8w5wFAemR9`Fw-r4(e{_@XJfTUNNrkY!E=%G-{L-d)pGL64!xT*2eXOh6TPtplh+1uf=}MEZ8sRf5<#k; zx2L3aTIkltsqKz$mWJ5YDZ*iQtWBFkdOzDEXiA0j5K}r!ia3ZU#_+Yj2J~r!g#dt1 zp?)y-cNh}_W_+Ln`8I6BB8HW~UK|vCAJ9zTV&ie-&C@DF+vT((fMnu}^KSFiyyLSo zTvdMR_WPFvzNFTZ@fZWi43;sovu_#4izu0y(WDuAU~8O-{pdCgKbyc}qnj4wSip0sE>W0zY^A zwsZaV%G!aH>@8cN{YimHh46^5$-HGBE8Y2x{yg}+pF*Lok+A*JNN_W-Zz2rJbajQ> zRikC?_Ap!cbh`fe?9b5@%MsG)+pTw90*uO@%H(+iuzz~{jZ2H=h-M9C@zr^h^%OO}-ETNPY@oF3 zIoqrTQq$l{i$xxOe_?nVKGUNc1t+Nh_AF(i##Z=3jxgrT1ncKFxo#@?T}*J&Kidd4 zCfE(}>fGOQkRC3%-CdYnKC&*3kD}uHKW|&Bs|Wio6L65`)Gd8850(_O7p&maGZg?; zrcvzk0)5AZdk>zrvcyaGI)YUw1Mh6E`X28nF8Y18>k;n|i}(C$M}(cES&xw`_9|Im zeVFxsmf@h@Q$9V1NVUy#Q8|~g6!KcofHQmG`oGjk3xsJpALFTQIIF)P^MJI*KqnDmAcs_ps|=p0#=emSd0hSrLijZHEH+{hHM?MJ2f>(DQMwTRTzVrucx^4PZ%-_F z51khNxYyg@U!c*Z6_#^OR6f{&Ip+5X&sO+*TM%<__d=s>Gv{*fONi%}k>*UOlf<|b zTN9;+pct$lTx3gCap#ElElM8)RxN_DxtP|p!Fec?FSwYsAOxe%cUbNgyc94rzD5!8 zBJd**m^*V~io^fK0$`H=ozAuTJVJpu*aNt4quAE@cbB~w4A^e+d`|63fTEr0Cz`J{ z2l=!73ol}HcrQGP0j66HK9CZDazS~ZIRbrVFJICq($tfD^V%s?;(N{ZJ{fN09dmSA zgMyFXa`nsFFGu4cqL4Pom`j|cvCBKh^)IE=(@S=+m<-mLb0lQ%XRY<#oY(eW{ZMW6 zxtMv)=W)JXX(>RP^`8TYgFAsA#Y)@JC0lX6vbBK_K;fYyE^$3CcP<>Bv*|jxC*0Tf z!P5=0X1)aHWqd%I>OZ`;3ovape|f-O(=~ua{1r5-=IrsIQ`AN#;GpDy++G0-rx;L`CffiJ2N`Y@x;X z#?V1o#Cj<5d{^NnVlcHN9)ykRiT1EsrP2CcjRXHZp|@Oum50sg!bFiiCC@*)A0BFT z*^PnffrPz3XfbJj3l)QLBct{h#)3Y(TQ5Hpd56DTHp#!P>Nx#zN>#2OX&wRdwJYF} zi2H0B*bzOjfEd4a=N5~41n227)V`wxHHD%h)50^?qU@gbo6LsDY*DjDzO@6jUsj$K5g?+kmH)NbGQY7>Vns4@HHd#%Dgt zNH72c>(4pV`_;}$<9FA)_#(l=2}#or z5)rR{)Acta-Xb_f+FqsAVibK2Hb$KAl@N#OLER1FYqx_9Oaib6waG#xRH2RFU*F*> z5#kZguPmT%)95L`L1nmcD;BjIAjTc z@P&{9D;e!9%G!PLel7vWTrllLsg(>h-vRry%5=t@lhQcRTK6U6Wf&#VrzibeULzw> zGyk=V5CO_ZCqL`TWV}$4hu+I3$ADno`>i~^^P6IvGqG=31S)S=ykIbpqxemD8%P)g z4r*dTaRSeYe1mp_#~7y_B*E;A;LJQqCV<{Jc!6*7VfUw2=EXI+LX`D~uT(Sea)_9p zYQj#6ndZt$Vu}Chs;z!3L)DvdJrA%g^aBpNy1+bJ*oDGt?5WXYz0B{JCGt9tJAopt z2I&1+4jLMmw$>^z-W3{=EhYWxl_{~J$*f?Svwiva=hXf>#kvZ4q@u#* zk(*u;kJa$Ptha+{9a5u(8#}wtl~j|Q8rHVsSN*%$x7zSttj_-DQbKhOKux0d?1w!X z6K3`Ve(W3GuWs7v= z>09jF49=+vDQ2cImHzEO{v8lGfU2;_tDoq!kDKxC2zwLNo-uu?!C^tCy@dCL9VOZB z2oLF*TRvD??ypDXsd4_$5&JNi_kIPO##IY-eH9Erb;QP|Vgb+}Z za|>Z7_3>8KTvU_JV%c{A3YeA- z7Fl=Y=GOFXyYq|5<7kcOMapjGOQZ#$sjeOiL%1@!;&lDSaG!F7laLhbe51byp{?gS))e`>eVPam4cC z;XF4^Ti@3()f;>xgf(SK#YT|BO!E#?YL$O0rfe!l?O#aa8BI6%BD=Lcp+`)paw(WW zN-mErsXt(t=q8fdbMY82|LO*t;jtx=k!Oj~7X0|E=WCr9K^yneBC*!M&Z^%FFnHC8 zwm4WthLUJwP>rNWIkqRgo=!ApH1q3^0LBc6AcQ%zx>!Wm!``L*;OqtOMqDfWpOVp} zo1o1QPUwyVl_3mS!*P;Y{MlHb)H&+lXA9-tgUV1;_Zi6vV6EEtk}z^;KU<*r#!Zbr zFHm>Qu$mah#C!N+CMc;j;;r!6no+4aucO1B&&Mx(MpVA&&e&a@5ONtgJ_S}E(=&O# zp8pZzvsQ1^mv|?AJ}qhbm#(9p!e>XlzZTTZnp6W{Wb((I9Ka^eFz=Uv_?fW1V}yQy zpc1TOgg{FkhZPB^!IDTuN||LBj-lPL#Go7d9wSp)m*t(q^Vl;qQ205VQl#DxoKv)% z0ilt6s;?HfINz1R%iHzP?czF(8+(zj!a<|kuLCcCP4PD=?r-Fe_MS^{2iLl^aI3(( zCUy0%-w)pwENk8pj2u2Ngo)oV7tv8ZTN<(U<-*=wn6TG~^Zlt)HTm^f_Hz!>Q#iBl z!uf97+vv^N)A9B34Mecp6ee*@Y0_%-Kkx*cu7e?F-!m%Cjb?v)*gJTic zgL@}||ADhzaS84sA&B!H7SLqC4)>MC@R4Be{G&+1!&esN6?0m%x~_7Miod}VMuHu8 zzn7nxZoam&X8Aq-f-LnyzN~NfuljLO9OVP5wKjo@&{L0MOL_Dq`RTM9BU3&)Nr(X| zIX0_A|C_F#g%-8+%cn1pm%@Om&=it89Y!71^6RFXbVZo>GmG zs~$i7(AA&gesL8gK6_Da>_0xLahiUET889e`G=qRf0FvSLe^+%`5!|v*xvUKy~vyl z6YvZu5dO@<*XZfdZ{XoHu7xi~yh)b8y znOt?hthbYEB)KV*8yXZdcXU8&MvF7Ex6c-BaK5{?-MFq5OBMkQlia50+P;PgMRF2b z3XBqa<50KU_MX_mFmdY?c`%xrUtxE?=vs+!Z&5*vI@n)(+o#jSP8{!+W3=SKCHM*P z9AlaBUa(PrVl_gfC3=+)kwxvZH2NaH^>ijPuxe0Q(Fbwn*`^3q-_K>n=l)EHRmLcG zSrERxJ1W|W^Gu$u4FkgHyZ~WTn&?C;sou2gMD}{kO&kq(bbAQel*};D?qNO_5fS`m zY|!KV;rF*wZ4)7wdhfn3@+675vh=Sd%)FH|-Kp3=)lE1_ll<&D$BrwXv(PO;3Qo+- z-T3}y@p7Hn7iy#8J3N@=%G2yru`9SAVq@NY9=zc9if-UP#ymxPhBiE4S2X$mX3$?M zL4(Uf%rL`R&t4?=GZhcrA0Bp3?Qfc%A~5e)^s6DE_&MrE==VyMW64U@DRr;}712&{ zyQe;9i?idK8_OA`{g2Kb0v=SL?x|>_M(EE=%=o=r*Kd`qaMN}=uQ-^|WfIB4?qM|y z_!W&qK@+W2D?p^jhwJ1oUcA#`wHVv&^KCXQL4QTyIKKB8+?cMKF)7c+9H;u$M~Mah zd53G9_jFhmLO0cnW0YjMb9XMY@$q|;#524PGJb)<2kW(dHc}$FcRbQMc(0pEp9ddq z%^rabf5dz{zG9QU3B*M`jA)0P0lkk=%*%OBc%(Sa449{* zCTDz-NRf>UFyj|A9WKnwbz4hc!vlOZ;AA~5$jr5y9iSxNKz4uomu19o^1L}Sx3Xf- zLw9X;ZJ$#!Jh<+YJ18QC6)S8dou_6iDeXn2=B{7LQTRlHOX^#Z&eFHiW2xKCe4-QQ z7MGCLkR~`7*NHIiK2VW5_^kHrd(BcG)@!K8MJ8KwntQHh*O)iiFb%+spJUA1i>CUb z?!Zp5@a!$?ItP)$+S{O=R_$hf2g*-AAAz?(8Gr-~B-3Ow)ci#p@y1|=(0w3X6@0LG zYNI?Xi_ncSIQU#nr{gv)MYn+@s_a_ld4G3Rzv2PgDEZ>uw*fJQ=$9{Fyi-0fHc8MqGK#E)C-ON4GkGe zKGyYU226{O8C&QX*b2m*(;%i0{`{v)M62>F>~C(a>)oQ_-c9*ZttKZrv8e_{%-V>i zqggQeyOrW;tLSB+EQ}bZRI@a*H|p=nk17SpbKSx?WNr3gJ!ZF*PjlO7>Q^>Irx=AeO8(G2qHmyXM`RYIj7VgV#8@#7>Ct3{%*9@^%c zg$0Y`07tf~wsRga_Oj{lnZHMfK@}q%s5j~W$Gp+D{zy2Zd@*_uj)92PD8X$){T@x}1lm7DhJQ^omcYDRwpd3nq^uYj zMd>X!wgO-Nkof1YSZTDX4i&aJ8?0|c*il?!5-Ne;{ZN2p=W*(stS%!i+ zjLXV>v^{9yA@%+aW2SF0Dsj;0^sA#|AN{2ak`{otTvTP2QPXy-dev8 z;`B^8mg@EIs?6zvS|_V&TG~4{Cb#(0(V1(R)~5w*{;IcuBU3pErRy%_U_uc4bC~MN zA<;V+;sT2~i!jD47mNy|f>K}toXa74Vh;-gQy`Tu)PQqsDG-S{fsOEmqYUb`U{Mw6 z|0Scj&;cy^i|d@9SD2MrKV4)Xi+b{U$}VRrtW}V?j-w+5{9kg& zk`hXTfOLm+gER-ErQ^^oNOyO4Nr#jo97^g)cXxN5yN~bt-SPeIZ`|)M$3O;quf3i% zpE;jruC>0*$xCrGrebPv=@=6^SkRLBIJ(7Wn@jT_#uk1?;=@>`rQ4zW;(YYc7+(${ zY0iLOz+Af~pUE&SZq;jCxqyN62=%D)&+UF)C9^lZC#8EAq-X$*);&&vutPlG$?W(| z9$$F$Uqw1L#ZkJWFqePKiu@C>HzKTL?V=rt!OI;;uVd}uN(UkxxuQl5;Y%7%?ixrx zotN`k;!jCsX>Y>68waBo5O$&nahiPkS-2S5SZ8(tPz}@EURD z7Y?SdR+1MXAHK0E)vI<_9zz@wk0Ea4p~)1hb!hrh4p1fOzR*EcHubLif{L&|Raw4L zr%Sw!Bfy1INeQnhiK5v3-boM@ zZWCrw6r7avCl`-0ws?8#?jiO183vv?9u1Tc7yBiO6qLUNoI(h=Si;iZH)^^=kj*O% z4JT{e(5F&foL-no*%9Y=jUFyt>pQ)+B1^m6vIIvq7vNnNEce^`6YE4Z4YX^tshBY zdVyEyH}M|y*ORSAaxoR*`3=f?9q0NvNr@28!=zOQL7xHNsvjhp%wf+C=36Rjp`ZMh zb?-jKYw&xi`(jB9gRWY}`H%AY{t(>T@7pRLL*JSrOqaQ9T~Xlc`p2^bNh=PRheVl| z?;i|VeZqh4lXtSwP`i3>ea8cUu+kF7F}FtAxSNHwf?z)d1+$-C~;|Ch_+Up`_} z-!+CuYJ_!Wo{rzyuahr#R^LPvL{F3oSD$qA#rRA&U&oG-{%9+veQlG48~Q-Jqw&;& z{#X+E+`hHb&HR^xWcFgOLk1=6`(}F2wS0-@nX0X;;}KB_4pv8=T-PB)TqlgZ=e+g! z(Q&ngiC@|1S7PmIz~;K%#nmhVnZp`r>EHvGRd%W0Z1v~T17WJW(J~V`JJ$Q!>sS@U zF_-;wr=h>^dj)Lz>X>|g`-ul}Cfb&3u7AFJg^_DY%U(Af8^lVnl*H(nfF%YP=DzBbt_TsTsMal^IbVNArk z7%I=*p?BN@^smRuFVG?~BHO`~UcM`mMu>ywKx&Qo)Vk|aHh3h#9C_p+qh@!V_~V-* zNG&m2>qNVjl2?DMMoI=5z`0_V+d{iA5AWu;2B>_>^8}gM*;-@lLNzNZ0i2k=@M>R1 z(+lQ!6wxu9L~^y!$LqILzDXcIsdFu}gYfE?r-Vl8lFc?oxJ+zr@_e+-UQj#$HCR=a zVR9=RiOrKK6aeT76pu3Z*O}`4f!=1lF00||ekY5{a+Jp1Hj5MC0EB|p0k zENFiK2Ljp)jT%(X6<61#HXT+lsemh(g|MI7*DuV$YE2{2yHK<85&71DUq%o+#$Djp z1a8kwi(~)_j~y6$wA55x;?wpgCAWZcc9)E#8zs_9Pq>csS|Pl|6vZt+Xc!( zV4m!h{fh9k>VGxiADUB54{&}Wvkj;?fi}eFe^MMx$QA>=m)7BG&QL& za`=lklFw?1(0-xi0pd_{dAqdCBplW%;0IE#@7aFyx3#>?%0zxkfke++^E0hCaEwhr z!&NWL9sqQErO_9QSf18ki1#($loC0qu)|*J39^^xqRv;V&>a?mA0u$-UTgfE(?p>P zPPa+%bP@BO3+a-nz=cGLvfa3+x9*@xV8hbe=jx1)1rH<`AXMb>E{kE-O!e^_`1ePV zK~;O_qRi*649}u`C52DL7wyG-R*L-e=-vLa)+u?3J}s>t0DXM74pn1y&$F(7`@@T} zuAAnSP}2pZ30{H*H-mDW-0XCr6;5r1+*mhUnz)ksli4;0hflPBY;h67-QGK-Gs}l1 z9!2V0X{SRQchl^1B=XBMkz#StFV$i#+G71Dpiy)kLq~sDZF&5XAl2-4XNd9CE(3>C zF78UY=g4mN*{e?^BeL?X4DVPrdvd>{CyDs;Ncil&H!}bEbGIJD?jKZS4;z=4&<}Ic zm#MO}YI`ciAPm3y!Jrq%MsQPvL#( z@#MZ@tM;Pn6SXdTGi#Lo;<+b}+Yv+o6~cQ$w6#Kv@MNP%N=os56(>gNQ;S4g7ul7c zI!?u)PydkFdE&uIh5OU3f6buK?ye2gja?&t#z3eu4Tv_syOt9zv-4x@O9SO!Z97@S zIy|;E1N~(t5z4ANktb~!ev-gNFdY+Kmh?iv#+hpA@TyW`PYg?~`Ez(f`ZA7XfUECs zIY8$MydQ>!e6MKYKu*BngxM?7Dx%|Z_rV_h1sE)ho~%49n^-e#rUP2ZfM96XZ2D>f z)&K)+GLa{AFZmqB-WXs_&xaXb@d6Xi-FdT_5=BvQ;+el~e{R*zf1RhUJ4k&p6z?V- zl3&ODj^#2svi;$UCR>a4rW-~TZQ(NNIKJeQkc0UX6dpY)lhg9b`_Xp&$kBukDFnwH zx#O-9j~@j|e$-NJ3WzBqi(YO58fu=ahZKE|5IBiyKv5nmE(KPT)vG!FK#Hk`;rij~ zrXlggILoz-{6c9o8p&EjJ8i$>uE&q1GG{L!Y}20`QU?DNe%eJsMY7L7Gy0Fts#!F^ z`}0XE2i%GG3grRRv)=Vs#5jHNIzE=9$bI7CplWE&MV40@8(XNj1->BR>gdl>o}CWIRTiK5Y-N$d@gZjs zUaV8YkAcA&Coz_Q*>G>Ce|Skk0w*t0JAteX?Ux&3rX!u={dw@M*R-K7p-irVcBxwYB!lP7fZb9RrS7~9}ROzT>Sd}Up<5ngSlp;c$r|h5$ zC$SLs*MhQicZuS!$0{Fge0dj~?uIIlgt(098HHKdq^~S-#-;!obf4*Wx-*t_9!V^q7f0PX*AB8{g z!dmestYM~C*e{mr-=Bf14_YtU12L~m4;D$REw-^zJ6uULt4hoBfuBlzen0YkS3cbT zoxI;d6aL$p71->L^OMrOdf58${c!SkIz-3b#i=j2Vj40CvVnJ{Rk_`f^zo>;loeG? zja5F`Qy(=C7kDwIUD09+=HkNUh6o!YVyTs75ZgirORKI{Hk zx;wv8EIy(8v8`I)Fzq(`_%^f0ba>&G6{i-u;KW?M{Jh38v-U7f`WbM?Al{slIB-gx zuZM&fg8=g|Y`)2yv}@@6*r?_%`mgN+!Kt|@7DR5v7w*oh1> zlfAu>l}o?++kA84H}Npobo?}%Y&}Z?Zt%0V`m*gqNDyKt+DMfc8s+QFnv+w^ny$&vUsTK~K2r308fCESgh%^M|wzl?}=6wI*4qE{DKrJ1OQ;-pT&lz14Yi^=$%@ zgo9Za1`pGzJuk|rMA3uuv>E|DB7>uPBn_eUNpK*i3L~Z*l7(gpogtYfS*HKqG46HU zR`CX=)gn?e=7X_@;|Yys^~+ZnYw}?NBX}KBnnZ!V(z&>%iTisx^L1LIN{Pe-sL~bR zMgKl#QH3DBe**?H?%vyXCG73;GvhiwrE8IqX$uK(SLO2FydA9353>k+$*-W#BGwpG zc>nm2FWMNYVE>|zQujmFD7UvIi{}8P7^kD<;v;YG3qmJRZ!yr?TUGOfVbM&KRk(z8!7EYX;tan?%&x{-ofeUb`P~G9_-9>}*1c&Yyx47RT`9Ylne{6i+ z4+#r|E%l$}w&C=y9p20B6Y=9r>bWkZpqxj1Jy+#n%a+Mh6N<^I-sR*nyI-Wr2(>`pT4mN>ahV~0#G=8WzX>JzAkJ%y)`53l0 ziQrMSFYq)+NUq}rdZ0wuCc5jaihuo;X}Rk}j{w3wNJ)4N`B0xAk9hWWAg6cLN#loB z3M6Ek7}fse4Ps%o9*4lKpo4<7$ZlhG;gW;5{_}PO_6H1(fF5ge$Ts3RMtEQhqDM#b zZ~L&1vWSt43O|&3t6ViYvAmt{_sh}{Tmj1#lvEc$~M95ro#+8 zEmr~R6?xVLou0W_E&>88lJaTf9Kzwhs<3r8{CSV-37S}pVH}qP&gI*U=h6LSffz53 ze-wCz#OZlm<#dWBP_Z#NSu1)B5f`(45l`&;s!#L+B_&&Ap!H^ekH!A55|Wk@<-OHz zCGAbCwDSEW>%&m47tO8pl?x@p7jrs8MtY1TqzC=P-LOO$*Ojq~+0#b%ZXqwZut>gw z!?X>l%pMu#D}SaC{=o`VsVY*7Ht#Ftbn@j55z+>>li9f>y=j&G^BnBWmm1^lXU-Wm z%+)hzc4Efg@lE$i#eJI!1F-@`E%94mvr*ccLXwNNy&V2@ge)I`IF8D-INF=bS6#!6 zK^kul+kGSheW4!w5c-sxOW&aH$dtLog441n+(lAKMakg*qiC}pJ$gP8qq+dmUs$in zyFD*sJ0lcMInY>`0O^d)kLh&htti{kR^nRD99e1kY8fx>s^qGz^OR|iQiq*+f4_RD zIRGLNok6!~0#j(MV?T296LQ>rcWG!gPh7N;$xq9qCE25hr5|lc8O*=(PL}6AEIdh3 zfH~fdKjtR=Nd$@2N$T7y>((=)7@f7F=JspgTKD1)yVV86JKd#1BiJ0@DYyVb0(2Qx z@5^Jrt)WHx5mAt%-l}E4MLyxl^w7t}UcQq2ZVtJMH3n9gOMipG&a}JZToC?fl43*d zb17Apj0GctEKf@@zSCkM6|^2cQS|D>S&=g;E(pts_-?c7^M~@F`mma}Iy2wD;O>-_ z?d|Rbp|qIKV>wgP!S_BRUsZ=pglJwLHz!_%{2zu|f5iOuskK`0AGm+}?d7J((>wmO z*miR;+m`MMsngP|sG{k$V`AC7GP5rxY*|x!xdB_S`#GZp~h|C>z zl@&4`?l|;%`GO;3RzS~C(6%tY+26NoKKF9;NS<=C{-v|)t-i-WRABxJO>}>AfEAUr zkWN#Pxz=Ix_FV#^e#nJnGxjV>ew(1LpP2CqRuH46g`=42N>|0uOEUrM3OmNt)sILp-%RF9Y&tJ4n-wrR$KRCg9Xa@vi zA>zo>kE=shDIl^3sTiXN;uwVzk9&yJ!ZO1MXp~JBrt?ej$i?S-mQybdZUT(?VQHzH z34e4`Q9)#ATUjW-zY=(3gzK!|*VbJv&K0HQD)fT|>XfBrX^uKi0Q;Mp^qHajeOV=` zR*j*Rn0&T>$fJ&M61SH@UHdFBD)8xxhAR8Y&BJwBSL;C3tuh)())zYla2sj{F6$^8 z##7I8l%p?>8R=ik#`v)L-DN!Od_Z-!N#sN*qx|JFC#isayF#_08 z(!a2&^V=Q144TU0=<)u2>`%CYyzhHzGK+k_<*(u4+IKp>5J~ybnZrenbG5q*}Q&hw&9FL5s!RLEJXxg}$-c$x4U}xw9Nx$!1l~M04-L7jImPwU(FYICR6G}lO@_Ai>Ef2ogq`g8fs ztpxt+{tM*0f~&1NXj?Fb<>5-|*47Lbekf(k364L3uBHlseh%o>10@@dyybk;ratl!dKPuTWosWA*JAo{FC+k=d;mv)L0Z0G7Go;;75u$3D>LNrE4n^ z35Y`>(DOX|5^3bC@6Dy-go3w zl#LcgF}{%WVBf-7i~W3mf3jt=ZEJlcx9{ibOPTG#dGj`ZKHLpCFkqzwwfCXa)AeE6 z%gc8D!Y$?ejXJX}&+FahTph27fngDS4c|rQw z4JX1R;pzNG!f(3zNOu-*mS$5PHk<+BY?J}Ocm|C+K%h8UNL5a{G_n?~AN;z(snj?;4#5T+?$7#yW zT)4O}%6eObIC(J2@$;i&izXpx|Jq4eOqB|W|I7V4m9PVd1HMGemuDR8fPW3<^6R~> zWbd*ZO9?PGkg$;a#OUVURXv?PuqnxN8mJ9Llo*8WfCxJHea7xc47X>KLM$MCWpzfE z0%9PmvV(H=^;WC%l+08oZ?^EkN|KbQhv;b!emODKllS8{g>-~AGr-?k8_SWp9Nar| z$6<3a;Egk6dFnM-a_^m>1djf%G4?YmqtGvwUjhA{@_KjGFTUB~2Y0Bz89i+5T;CvQXMX zHxv&qi*3!2pGIG06P)e(_O>?w-;u7SjoR?0_Z?=q_;sM6jsb=8HTA;PSw!G0wSssn z#tx!jn96twLnr-fx=k?L2)1Qp{Ex30h?^;OxkzV>Xd2`1yiy@HeUH01L7=PMa@9kw zb<1s#-O0|2d*1uSUqXC0tbW6~#`cUKdL*b%lvB9VVIn7PWoR)=nm}2aMfZzN_yM^@ z`dimNIQx;Mi{3VI)B$=Bl*m)ChKg(?zE2 zvp-!tgw7*EKP; zx06r-6H76!olRdSjWSB|$`eIht3`O>uQ{0&;!?L`O&P1aZ?$%^mO?Qp=9K-t;UsW- z4ZDLTSn6{#)K_3_&e{TsbV`r=Cx?t*=l?B%=9>D_|G6gENa4p_6|0xMSYKbPB*Vj6 zcR-c159X&zcX@eUqdj|(H%+1lvGjQF#YK%%rk3d2*Tx4#At}yiw6gl-d|zVFm6fzC zn?f203L^8so?ISoVeb07FK9mf%Q%p<4Goe@fJBT$Nt0OMbWAKg0{>iFL$!f`O(s<- z&q=1w2#-OM3(1N11VdaSL6^d#`jn;SJS}>%j`5zB%mXnsh1+tGr(>kPnIe7Bsfu2N zTs_{kbXsTb^B1$j4;ZkJmhI6O#LTDsF|+mmLpA|3)_bZU!sh%UzV{`pgGB$CB!etM zxbe*0{O9+j*>byAX7~0$>ZxfC?HGuQL=%meGbZ} zib36KwA$!s#AC&^FT)xhta8Zy^Ivbvw& zm^x@NCL@O8tL&y*%M}HBMzOtND_;hE+ndHa^JK6ql14MJjyQrd%%#qJx4{(k_PWwpx6Yd0 z2?SXvv?yt8>FMQ*B42FOdbC&eOl*g^6y}J20^Q)zK}&<&;z02 z_Ir?$;rq1wfKaMwBxHXr6~>^ONC4SR{_}-({v*nL|2Ja&7Na0E8~G;r_)@E8FI|07 z;U1du%q6Dv$eG&a#WR;e)0!BsEGzhP?KD>>Z}UDT*-B58SlZNu{3^#S0r0@w=(%Gc*DrseA2X9o58v3XvN zNpjRa)8^)kCx*v!7o3|A`56ULLH&Pr@6*>myk_=t8rh0zAAt*5muH{gr?x@OV+>?U zTZQ+%C3`SZkajUXAUS`oJ|9bB5?R~<9u012pMkv&f=OKDHw5g%_Q2U}>v^-a^HL;y z#k4L>(>k4%12})TB2E&iwMN4uGk3uhP~rarkNcSZJ+@wpvFFB}hY8}CTDW5-stf?e zUdjd_c;-t{psuIH^~!Eidj!4-!j=YQ(;l6b<#jj5Vxtu5_^-FX$&bc^$c|%b_SFsO>TA#5vAxm&3_!{~atBTnk3d7O6QXk;f-7;cB z@nhbXPeVeCBVj3tD5ICa!_}N%P-y{S0~YFWlGV6r_biA@rbFt=x1*o$>4Uq2ktoYl z0tP!KH*0zRGwgm+lm-n;z~g;i^_qFaDo6I)lupP zT0PeHZmtNxW>ERyXU+f`NMaBxe8gNI?f^4^0sSB$C+pCU<$b~8bwGq1Z{MiB46w$H zM%1ZpA!PXz#s^kya?gT$H)ogs1vOgj;HnNJc0xYjdpG-vPhxO6K2}Yo-zU+I5ld{r zKNZhjfXS|{Rv=birxuTZRJxm2ryY#0V-hYw?3HEamvJU~n1fr5yAeqe7iaI01#vHE zAh4LtutKeFf%?n)zZGLN$nnzpQ~6sS7zThISH$qa4vU#Dtz?JXNQ`Lz0}sytY1Obc z>1h$7T7z)~fw_yd+)hN<%4eTKo>h~wI2jR|RSbTb1{;;SkM1?C6)qbBh; zwPBq-1#t&0(`k{-AN6MsL;Vw&C0j6f@wERJSi*5@IOQM5;6ooK&yFKh80Zy!)q-G& z@BS)j=RXKiCzYvquihJ0bp(6$i{aG$EYeWosp;pw!oA+)fi?lL+wjJi8IT=tdNH$~ z!bc}HLzg~qX8I*ednjy=@$U`iRIFtb?$A=b>GvN0o7qb^VD{f32g7sH7J_CPl+9q~ z0xMR0#ryw3ZQj;!rhgp*W>_B8&M9&AC+Aeh3OM^pMU%)&CfCYE)-oSRg+qTWZNnHj z$;Zd9zn#O@fW_3hL72esIuzZBg&n~iwMaa4R9o#Qq82T1+NASJ9X$Dxi4LC0?9ax7 zDe{ejYemz=qq;M5f%BDy>vL?*_zU=WZFLf|*cg=qd;yHU`_VoEHKbsT5Gp@8O^sKn z1s)1bv^*qBgiR#+tyB($z=nXZavo&Ec;V_$%)pO#f*8ZQrvTC)uS3zJfdc91odrBI z?5_PU)IiA%5husJls|i_9pdo=VA9!P{z3n0^(nXV(`MR**gkfDS@^u52GM;5&E3(? zT0=$q$V7Ihjt-ROTRVdH_qdpmsE^c5S9!BVnC~VkdMQ(>`ninQPxuF!yPgeYXPUrb zfOFTNeE+gTTkii0IUKwL!X4#BZoAh*`w((JcsyzMK_)}VD8d^v86;q}%sbU+L@pU2M>K+87&H`|`Y;jw*y+mxUTi`t>yAlVY<$CQvqU?>Pn| z0GUvroGcssf}ukrNOrI7YrwUJP9dXu9~>`iYE7X7wjOWpU#Xfi4GU_An;{?}f-hHY z{n_$=w#v(|1^oTuHz7hgIUYK5pJ0`cu2VbhpYhAsZfQ)2_oD`e>d|N0Vmqy>gBzWRa<-VWQjMbHyeT(JR_`tDcFG2 zyF}1p;Uc@kT~qIFyw~0vQnn1k&sQFPu?^%12wCd?K_;*s*jJU z@eRu!S-ngN1&zevXY?vuobf!6eZj46xPr2zqV8`5c9Ib$V!RPHkwtB?2DU1u`j`Wl zHB2Ftnvyn~seveyAo@C8W?AQl2J=iNdansW`bkl>{_SpG^zbYNQPyI;^2BjOcs!1$ zT}!p&z|mYvpz~gAr9K`OjRFF;ly=b|SuxlE%$zR83B{`i} zfaq~ADrbJO|M}Rv6W<`vF|t;~kkkmnX_?#JNrOVRDK++INRBs%QJ)F$LJ6|aZ~Udn zz{PCUmO6p9nZWuhjshYCo;+iZLQtPmZ1Fo4u26*Ut%j1l*~w#7qWpP?Iw2oqSbl-T z(Ye8}9}oo`4;d9`CvJ*7D4h#ai^GxK?Rpg6MvfoA=@V`)gFbw4Umc6&)Q<}ZkU+$v zrvy#2gDq@{U+ia9F=Pep(5}d=5C&OdWN{jMtdo+b&8J2;nSrk~#ELPUtSrZdG!3^; z)iiYuUTXMqm^+==0rPJ)C&Y%LrjwC_x07u%QE!p5(d?czKqmOVX)b*YqM0vNvJjue zx%9sj3H<CeuQiuHR=MAi}^N%7dji?(EV}1eNv?pP|-UdW5 z+Gw~W&|e1H5hM|a%FzZ?2pDK=9$S{D?8k=1zmZWkw#FOD!(j{w+lebD z!w72HH>WxI#%Lc-W1oAJ(Jg{+=d?)3lp$=BBhXZ^GgcYKd!(S@?N2Fcl<=c=HMZY# z?R%q4vE8dpj1?v%`-(wi>XCy}FsY4XFdzNzschHuVwd1w6i0bXd9s)D2q6L%vZHdV)$dk|%;@=9hAn;8*& z<$DA3szCfHO)=K6;~6!_m@1#*Dwl4Tr@gIO%*k6ud-S7>^7cGz`?hM>R~6m8ukzNU zuLUDvX;K!~2MLMY#s%x>d_-S`Tlcy z%5Sf+`LxcgujfZUYiR<5{J5F^KH=*ofN(F0C9QktadP=xx6E#F0P;uH{(tfN;&XUK zz@YyZUI%Fa@E zm=|uw{@rB_(aF|G+0rhpEhFLX)H-gx<%&56LmrIM7d!G3U1I@ci~QvWnDO0jy9wPD zG?@CTE%m9JSi|{b8Y_iaF!-s9!Z_P_olzY^m+cy5n;pY;{U6uZAENW4v(le?4SLbGu) zm969YQK!B#6Hm4kW|U`~EEG?7D9)YA{oEC)ykyGte* zL*oc&V9nkY03s<$so{co-uUK36}U)SQA3o&*c3$Gav zp4Zf2bda|kYXf;^mDHCqXu|qT)}I?K05ukBfRen`VksSQHQ44Od|C!p$RA*ZY(>D^ z0?yuLVcj3lrN91Vu#=K^{;UKvE&hWNr|?Dc?mK-mBu|!yT}hIrfoLFI)rTMsLf!={ z`^WP3BMruXEex9w3V}3Pft}kAx$-DsecpFQpGNz(ioXs2Ab8un`iDL2MBCk?C-rL3 zR>7j!T6rkEXn{CDO9FY?PXc9nUm;7%tf)97eeF+pbY~&$As+C$-0Jztpr}2A@;gvH z>k#MwOkv_${C`Rvs3Y*YkT#Q@W%c5DHB)-Q9 za$A1l@$bL1HIb;fkkf3B6<@w~yZiWQlIQ3;x6kEsxr~kC)z{KYJhyd=3;y#Q+ zQOytPUTeR30u6!E!r^n^{XPOI?_82WCJ)&{`V5ez!0TE3PFjpc=N%9as<2!PvizTP zAO4sP6f@9x0UZYY$%tlQCez)aD_P8t8Twrz)=U4elU?mP8|(HM0W-uRbEUY2GE-gD z>&reUhSdKf-r~9?39(w>6IFZr=>T@9wL%G=-XhG8K+b^cUuO_L)n%D^9TJ^4&oqUO z;|Hv`1HZg0))Y>PqyGNd-PYWFLn?Hpn4uVIO%C1~)jU;HbHR_rHSM(gGO`w4co++8 zu1BMXzna(<_Gmvwo0HIBGa_1%{$%UBx-+O&`-m(1za^r`2gS`ow-Img8QL1l`A-Rk z+k`)Xg)N&~O_CUyrx;838V&woG_UQ1U-+#o=PNDk3aPc;DjSx;S~xd|P40PlfI1?YOUR z&giITN^`T^3)^q$r!PB7_FnujbuwxN3ieBwk*DE|N;ZnHE+j~>S{~=-ux69%GOM6=(w%@6$Cb7=0Q1n}kTv z=MX4t><*WkH)IAWKSk46L^5DhU-2tjXsO*QfY7e#f-Nkh&VB)~VD8t?hG8DT{(O@$ z7fmI&KT}w-7Lu>3<^_cWFH;lDzj_UH80s6<0G%QMypOp^#qahQI(m%Z7IMx!}+zsqqRZT2;;}0H=1UQU?T}a4l~JrTf0W zWBfqypsE*q@Bp+^k~JU&-GDS7IScy#lj2<64uJL;isn}NUh@}5d^fPlM#r0N#Uocq zxpj!u;BG{Lk7U+T=@nkwQur0hLzUtO^=98Gm)KPC^C{tUQ68E)F->9c7*?o_OwmP$ zB-PVMef`YFpCX`G5)H)PurI-%ffl?Ct#Xat$ut`%8_tU)8qW*5-JEwj4urrNlbPJp z+^FnmZCfe#l!vq)s&OR~XdT|c(;jVsKwjL^DOgvv|Zg zw3#cynd(uj?s+8pAKxjoD;PW&jtgfp$USf(-#_~|%zCPK=S0Dj6=#np;op`cSgt%p zfv$z~(rAm6=2OVjwG!%Uf5j?L8{P&@fFGlG;h+fWE&Jx%W!}p9Vjh6yczPoCH3a;( zPbA7A5&a?#I;|Vv&L+sgnccIm-IGA)@+1cPT6R!z0X}Lq{Vd zXha(p4n$CRhy@Ly! z;`u$18FQlA)VSXC@7qndiNPIPKC{j-^m+E|ge@{so!F5`p2!(uT8w9v^wzjKdIl6; zFJoW`-ltq`A0WuH^vL>-Blwf6-3$%B(LMmN`|H7cX*V>Xd%s@z-dyC|i@ZCvnl(KE z?_(>8v79vF5Q3WQ5kZ`DzzT6T{^1J9j?uZU8Z+pkldYBBH)MN>7$7bpQP_Vh#W%Es z)dmM^i>ud#L)nGDq475%a;P2&d$_A>S zR?2#qpytiZQ`pALm{gz=;RdUe`aIBxM0t(?0wWC&pM@h6{~b}PwA#NN$yhj);Yn&E zb7^nOtP&Rw($#OBBy>ybOmHvbB+As4o}|l0%SJOtdeIeFDN2>dWJz&?MR@&jd&WpY z3{RQf3HIhs?K{8*X1K-ONA}7F@b7|tJ@#PpO&q_SMmp~SV@-oEZkwZR?yc1Lp3Vrd z?AD&bFK+)S;GzmT(J!-5LW&l7CDK_JY;6Hzxe1a z{C&}#x>`8A9tQ6kL4w6jk};j}7geYO7}FmLZN1tFGSx#YE)x<3K>93BJoes@!=-cH zoKa#_B~7i6&bm5BFau2Iy5KDi?A>YQX{nOtJMbaXsNLPYRco5`k3pvHw^2g_EMZ1< zdNDUe<#!g{V2$%D*PgGzt!a>>vYJ|^*IFX68IFOTYTOe&xawXOT-+@(JYvuf;{*Kw|Pry{O_F`2=UO94q0fZBBm-n}K21 zlTnV`;{S9$Gl0%#Be0&nP%zKOZ?F7C;d0-RO4u|3l8=-+V@~JGhJHsMizNZ$-}?Ye z7t?GK7b_AuS{&5{#1p(Z3J(GdmK5{qetgCg&^Ey6p%qAgKuV~y5&G1d5-xJNL53Z= zdxa{M_mZ#^`=}@|6ZtO_KPWMLFZ{PNoKw3PL{B3|?hbm}ohei06!!jj?9M$=Nqf^?Z=n=4f~C-cGuu zow=r&QcXgW$lE%Xb4dBwD)BudDoG`0L*dALHYi&mobmQJu$aA;{N_DJERj?35M(TA!F!LxY9!pqCY3!37uq`h?W zYz&<%T5sxRtLgLP!$Ras%?3$>0UWj(*y>g9N=GLS_}DhA($X6tbKJke!I|scIRYcW zVZAk)#*Y*dEah82a`${5i;(>VkQX-^qLJRb6<}Sny;5qXP~<^^ zIb{7^aM-+Ki_YcV^4|(2{piLyD1TBB&$>f{DivVuI(hIQD}>ELkDXlXhS|Z?-$C_W z>YW=-@BL&Vq?k30+;2yeAsJC41+rAi5c61DEEpGa7mb&c^E^JHe-LoaVFEPoSG!<_ zj#;FYfY&;^IVH=h_z$Av?-}*IPs{zl{YbsznMcqCD)?xYW)vrxU)j|B;@rqo!jR3>~{jy ze&P92(aRz#>S5NJn_U6CJD00%eLGJ-&IMlIFBD^qFAP(DU8;AGIo5+zJ-Fmd6U^%J zwxPBZaq#T#=ikZy^eA((+-i&?#Hzn`@#cD0KSsH>dMJH!i8ZO^i$B!PvU#qEIo`X#BC^ncHt*Mggn;6eeIosp^OiTr3qZ%+{F>GhX zwiwSJ#i6QCL?;D#IjgO`RJFxzfo?y8Jpi7XY*;{Jfrgfi2jva&Nr*G%V~=Jgsi^tD z`=5H}n3p`HQ2gs78w)j{>m4W1PTDR77F}4l zeo4zZ{^?)UZl-dzRtL*IlB(&wVfAqlJ8UzG>hhSp1#DbHRT0HFO2iup)8PHrrWU<* zi0ml>R?ivS--nPp(f-1=J+qe0_bllK7lGVsYKGs^uN_T-k{1ac5ec4VzYWcl zbmsG=@f0SKnpAW0pXr-qgq!_n!$D{(doo`!(`>ae25N=~nXyZ6%DXy0PZo0@e+N@_ zCYw|!|3EUULr;J{Ykx5J$~hLLo4B)|q%ouH>x@i`d+^IWV+kfL5mfQ21t|G0Zam{S zw=eh0IO~*7!ph+cxh}wTc`VyjQ^u|))kU(G#On$;Bd5NWX$|~5&g!}+n}d%s?0I!8i@@d=G*>jZyyO#VaeOZl?HzG(P>PZ4j&Ua*ui_pBPV4|ok)AD7- z&KM4Fi^m(NY1^;W#}IQLpL>Xp5a-Bla%-(Camlq-^v-xQM+wMtb8L7Vy&0i=(EfT= z?W(C}C2*ngwp;Oe4v|6Y88pgk{Mv9i1gL-tQzjs2X$}@ha6;PTwr&Wcl59J2kxv`R z;O36}YosnLEd6UEuk3x%X0WjxH>DlTaAzf8T4zQ(l1SydeKM1Vi)(Cl$rYb5<$yos zUQdr|KUH6C|Nd%EqmO-;)u-~1m_8e(6SFK^iOk{lTzSOG!&=s3>VofRPz_OYq#) z!NXUT-75x-)CBtrT;72gK*+AznH@sRud_Yc&`Tl)6Xr!&2e;j1=UR*{A{2POnroQ* z+421G`-=VSrh(1`!J#zX6RdYCrgo>a|D0Ap?Rtr51sPmqE~eC1!w7sqLc?(fi;deD zSV!~i^$bLK!>))D@ppV!vTY2n45z4^dX8RAc}M9Pem}z@(0z6985P@?N_g4q#YKput|`NqL~isPK*j%VbV)J8(FY9YPAW#@n|(k{cU z#d?xcZ>cPeoQ-Jn1wsHZCdOA0tPr;u$E8;$2taA3UK!}``X7aIyZ*jaJDLiNtiLyy zzPoySSUW-pJl3KjrK34-*6hLF)d56^%?cTw2a>4NJraGV?>sS8lP?y6iWar#S8AT; zWzG4mB!D$<{T_03HFRdQ(ELY3x!sn6^pQ`4K({S}%q~6^C8l%&7b+&T& z658;mYs?2%`(gIw{oB2Wp z3nEC>p<924qd_X_6rdgOQuSw9Depr*NUt;DBhjxYU}sfIj$Uf#&~hVC=VF6@OdM)e zHPHm>LpA!@fC@(hu+=$i7&2{plab#gMS|;=03*sQMduW+wVOr?UAISZ;3AyWq>M|t z9O4e)=tA;Fb3tZ=Iq!`Plg`B#RQVh*xLLemP3vA#cwk_ot}Zi5Iz?AvfLv?6glFaLL{F{siR$ z!0LR@1sTR4?g7h8R60|x zw^>c5HPlcQqlNSt_v)sGAqjYAni60=w zvJC2qy?HL`+OqfS=2VKk&5%WAM0ohhM1Wzv#BR2P(!L=TejTvNB@uZ#^+UCVc@W?L z$kF31yw<5+7Y^iLN>AWhiB;*jKDWO1RV+1F40&7?^ zIQ;(QNK9a!Mz^9PgMY?lc90}u@qu~4MHvSK4 z_gCuUnZs%;*P#nrZVAnJC|a`o*af;ZNjZ|v9KusAoFbbO^5iIS=~E@8#8fN;E5P&C zH6CK5_qY#ubnY++6~zKdRnm2c*THG>S~%GFBU97@Zbaq?(Psg1PczqHMqOGTX2_P7k77ecXxO9J$ZM(oqt>& zcwkOXcU4WDZVX_?z;$CXl+EokwWWyfn1s&b+Kt<|4y1>#TD#mV9!!4VF?&lpfLA@s z8iF7@14xm%^p@kg0PhH)~a$0HQ6zOiV|MfI%|jUDs+X?bl9Tu6f;8d{M>sZ?V56x$sAlDb)KX(%+BwGX^vVXfmA zL|<=ZN$)J>;;o-5anb`L>5co3uQAY2WQ@8}-p`(`SFtN@V|M)eoE*u#*J~-Ei%+ zpGD1{HHnn>bq5Qj%SaSOgrjKFw?4F{=#Z!e9+3y*$3i)|yK}=;-9%ixhH7OGJb)L= zGAFpad0GCH_V!wi#olHo=QI)1Fz~L)raV48fNIoHx3;&djrTIwTibC z2~I9axHzxcEd_*k)rplhY{FV74={sy$&~Ah1#4=W}eszA*%F3l#t#{bHi2mK|cM91RG)1C_yU!J+(6Z9Bw<#KoDb4bsT~ zwGj_QpeviZo6if~Vd!^O)JS1Eri~<)SZ-kI%or!$JnMY*&S>98xH?_I#Cx9zG_*vI z$^QLF@`Gb8jsI;?cJ23PbSk2`?P1?mm;psrWHeSr%dSvq#Cr@`AuRWzXO)>FD{o-1 z`jP)G9#Mt>twmtfJ(+iClzk^5a_}r2NQCBx9%EGw`~X{88e_z7sveJH-R!|C zgd`e#U26T#RxV~X#--Ndg1Ufv*JX?vPLX5UA94lKiC{|3hA>kmua3Me9^-Pbs`PyY z<}_$Y2oMxpTBD19@P97#5dQn+5lu7Rlc39k*okKBwFsy7_>UHBON+I~5|3p;slNPM zp>+xIHt_Zqy=f>)7DJ}Pj}ra{4Exs4`{LPeW^-)q?KELVqE^t2yHmawUj$~E>cH!z z)K7kK;Z4H&m=#e6M{nu+b7k=8pVRESN@A#Dz^J~8MHlJGT*=L^wAYthKXLfDZp<*- zN|ou0Q_!!AeNoV)mD~{;snuzy&!KEEOXL?zRI%fcNU9)ak@QAj;m0jIY~D3AzuT8X zJv=<%J3hd(5M{n*ZAN+W(e$43KIoXgbAK8kTB1|QHX9on<@tV}`FW*Sf%lhJQ&2*g zM%!VF-qJd+mkM{&S)a%zu781Tf>jgyRARKfbSfM-(vJBAw1fht739rR8fGeyIn!M5 zSwWJ2q)JS=Uk3b(C|@hredDMVeiP0kJ}vUD8JGGWEyT1{Uiq1mwSX*aKX<8!L3U+X z6;VRx8Y_B8#|R-0`C+-lZz$nlwN08V)EQFr|DW%=_l3zZAdSv!NTSSB=tX` zvp<^;t`Ch1yK{p*IUF{c3@tQaNgahvHp19I%VtwSc&Z3h-1t?(dFR|t;>$~I+R8LA zKx$AqqmrNN$(cHEl5f2H_Y^pyBFnye3HrlthBs{^-!52uQU0Tq&&c&7%S{8_2qbz9 z_A2Q@DP`+6mc~z3^quS9xBg1Q;9i*}8*D1nd*ZC-cFZ+JMc>EU%HMz=U+qIsFio?h z$@pbr8@FwTlm8m3zC)vfCaXNFq)seBDY1#6z8k~c-5r_uE#U|7D2R0-*FP@wq?lN9 zVeU)(&kL|@<&A78hVtogipjVr{&~K1VW#@=R!Ym+sky7^vAa1Q+o{7~aWiW<_?kkg zHy~3yFmILefHiC1I8*pUBH@c~0d+rzNBer zKWu3#QL*&6(r!@4Vn=EYHyy9Zs;|kZH;cRmTuMPk21VqHr0!?xM86D@Z!w|tvIGs5 z>h?9Z4B<Z`P5jRLQ*%g2AZcK~V_SeooWrwgq~BPe;VK#FJOSnS4oPG$9!1uT z-}o_K?X?Msbylq)$cnj9ix1s0N#=`f&t){2=WmgEx0>jZAN0rxAmU#6 zJ%Egw!{%Z2jg1FCEHXa(-9jP9U>RKP8UmQ(v>jWqk+1)#hL?w07i&yA$y4gDwrf(j zMg^}-ItLcZCl3$-|K_$}dhiq4!Oc zMSH5G<>I5zy=g1zJ!Gq|%$9bC%v&l+crm4e(}JggEHc&?$%klaA`)7*1a10^?XSDS z+}r{+at<8F5vzK&Gcr0tqRBkj1PEy{4O>Iu%(?O{TwFxx2IC|$e0Bzi5#zG_J zcS}|t6fI$86Gn*~PZoE(r|hk?0fchBta03CU9mSWQ@(3m^Hnpo4IlnZcJi7j)_PUM z^SU(Pi|@1#y1v=dSxr1M77J;2y8diw4~n^F{G>u6id00|5f9cTJMP-UdM%3jp9oB_ zc051!&YZR2RqT(1(>mmi-~`<7>kef?6cBSHhLuYwU}lGCIuf3T{`URzNR!IjD+fD3IWI5ofJAJQ(EQSctzDv3f-Cjyi;M7eLbd zgw#sZuW$Af*`?J%ik7nXj00K&$yiz~#2{yG*#_2BOZ-Q>V*Py`zaQ zFFVIIjg2=|^AmpD$O`rM)#2C>CHbRBs7Kxls*56<5gbfIOJu>_lZTHY?UPxV+8Rs+ zbQ$TYa|sTG>t`7>Ln0gcCK9;H34Knkd_DO0263|_v{eb7KxD4h-@Y6AX}v#krd-mD z0JRnbpx>w8j}xq<-y|O^YHEN;U3xj}?aa9p^!4+k?DWacJd*? z8P1k~5voIT)hk*_6aLfrrKA^ae{n8@sF~v!Rfxq?&o2%TS<8c0%DODlSN_n(!B$0u zpc1#@wtOp*=p4H73=g;YYwb7AgbB%xw7QYvJSNdwVNr>m+)NxzjnznRlkV}pIui>T z@HCohnJN59|y7>hp;wq zqK`0LFO#C_vV}>Nr+ywtHzPmlzO_J8;;?Wf>27l98K^mW9`wiOoe_Yfj4$Qy4EP0c zWpJ!=vSUl%N+%yTGr_f*L&G*-?!GH~9>~ZOvg2y6PwcUPizN-DClfCk@=T3R1d#fj z#n(s15G|l}FYVbmYV3)|h7i+fFQj-I2_%MsYO2T@RpSA3de!x}R0yo`@V2!X0UieT z4`3KEi@B}EkaTy6Kbk?9yEA?~49&zB>~pkAyA)hpFQvL3xNyDQ-LsR4G*YWHi`|mj zgBw7}W%yTe_dzk$w$o9=K~B#Y@y$a)4n&02KkY}WGauHd#X&KMO*e7=&lM!EKB<^% zB4kpfo@yd(AWEbH-9U}7FIQ@LAyMPmIi3#d=CmAYvs~GN6?MI0%4b3kvgQu&H-RGK z-Ylitr-R~F3PV}7xhT;+Wco$<$lzxibES3cSw@8teia~8c8j3qXr&#q#)P$8%RQBz zUfsTj^=+%8!3~XLYRDL@LgY~nS-?uMKeKOr5nnw%n-oyP0xheDLN@(ERJ z-JG#n-@dCy%%Kt8)%+!ImBJ9ep)a;oVmw&^y(oTE2}Ij`Pki~SPN)#m>ULf$Z>GWZ z$jNhh8nq)e_nnNQ>gDBXW%Cx+f{`dwID!$`U=wjV)iWPowF(ikyK<~t2p0ZDd~%il zW?%?$7a{YJmik9AwVjjuMKmAR3#Lez&s)cH=t~)x*75vcaFeCfBs$xDkDJ^V#9bvNH~rbPp4gMYO#;tgF=4#w z>kdn&s3Llb-vT`bh2>7~8B0`(wHl9kSmEgu>fX&7ECmDZXXv8#{2UB`K8;BIcG+DjzRsa+M#M=4ADQ!c5kvUwAQQ*VC1 z9l)@@IPLCLvqp0YDbfp%@{!C;UP!6w?sGJNr>c7)fP{vY$v=NDBJUy+|5)TVw_Cr5 z9nbvtjBNwH))mS-ma|Bqz3KIil;<-5rQJrdazCNzoo+oXdBRv6W^xx=jkzBu1@4{$9Hqv+jdz4BNWoQjJDR`Kh0{U;HT~AEUvOeayy-=j+dIVe#oiZSW)aU6%_BUSlD3RBCfe z+#vks(N}mRe%t!UF_a8M9sO)Kj58D0h+3HU$BW;QnT!Bg?+EuYQiz9#hAlcORxbLd zi#YDAWOzDE>h|diPd~*0LI@?;3r6#Zo7=gIB{g%sR`YC1Rv@Lqb{n0GhGUIe_c7n| z>nBdh7_(192FBZ0^eD(*8|l*c`JY3S4L?9akQ7=<+T<#vmd(%qegBq8wDPmY#QLi%G9(bSG}>t?A=# z9*ew{q!eam@=`XUpGd#t1jlu`{u=ED^yj$ZWi`q2{~hd$l~eXKp*OX1*tT3#h>DIw z`CWA^rxjT&#eIJ7xZ?EDj(;9Q3bVSvL9Q1X z{{y=_MZsZ;C(mO6nV$|+=%TzPF7nb(on}>>q$#gc5%tP>)t7@ zwj(H=`6!{@L902ksN9pkL|F_3y`7R5dT{OMN1P1e{HlTZTe7%I%v;sB^OnsctZp8e zv#8Y7(NN5C&fOmelI5DH_^7)5(%pRtulS0~TX2AH1Gd{h8Xj5jGw5o3Zyu&uf4Pl| zZh>gWIk#mduA*YAbpOIO&g361EMRP|EadBmhWsu;M?&H@nCjCB_Jfg`#l8Q#`@>1- zx$fS!-KXRVz3DEB5BE>TtTnI76B?SS4_W|-cAJTJv(sL17BLUu`WgIdBCnvwZ~a!J z9li&H&S-dV{rvnezHykn4Q9mh;VMeARvmC*Q%MtR^l!V8jDZixv3+OHS8Xa zLmf@$y{1o^`3Kub`b@kDO%AC3?E%(eJ34 zh}E|<9VZQ!3sT&vRJCxmvRQ$j$ikV0)h~YD`_|2UegF&AEyT0#KrSmv#5NSM8LrH? zvgChXw6Bf-$y(8kg_Fs~Cr7pHfFrz_c{t>knBb zgrl3XG|l#9mXvsGTn2B{X)y54#c`Ybht^>d6*c%((3vcfYo7l$PYdR(PTua?d6vI= zm>Z)UD;(L~k~I+%Sd%t?_S9C2XzfkQ(evVsPox3%Mj-jmx5HVxm8Qu*-NxK{cL&1i zTs)o~0A>!)i#I%rs=ofl0Lg+bmWh{6)XS6@Sz6%Ipq|^KlRrlz#==$*^s;WL-Fa7t;*WA}U2CtU0Sx-Zn02 zHg6ZLW17oYa=@+FBS5|=$_E&?#~nxDH#r02_b%Ya*Ud^jO#7OGOgbgF(<&WJq)xkW z%&@1fTJGDhO#2(kIDVI(#uC}7#4e4Iddz!3x)+sl---PeQodPwj91Yx%eZc`dZoI^ zh2jeYaC{foV;-dUt+nITxtw4L4KHP^%)%ixo7=IvFiX$QXZ_T5z3@?_H%FNQ!po{S zu(x`fZPBF@L8xq;UP3KruI*Rlc1fx3CDhgO_Vb#B;SjPJ><;ApN7Y!+jx8My2<q=#33~@upN_z?{dRZ3_lq+VUe+&et8p%~93cZxqA^G0EVeA~vui2t?soyv`)%or z+5YNn5`M{#5W*$bv|DPJWz_V0kz0C>U|xp{SJxi1FEwft+7V-jFcIj^s!+@Ii>f-H z0aYuvngx3V3*iQ48ipHf^p9^;ru7ymE}JnQ2!6@$z5S5O1#ON&EUbEI^{nK9Wpy10 z`?Q)gpd@e-giUiV`SrgBj8$6uhSEcJY93LUuNJDG-7=%q@ z)X4A^?`d16lgE2}QDnn1mh&SUjlfM9{g-=e*&oIQ_h6Dc%ifpm9N(GcZT87*4+#Kg zW)8P--~OW5;L9EuIcd@HdNz7_o}C?hKQp%=K!yg;e>Ke;1sHX<^IrU+SEk-%FSwkC^@Ia~T!xzGNd&zq#srC~SyS zxw8(5kF%P^#%Ma?DhcEnV;T5OFuL<}#~MA1Ba#hPt}-S*)Y|M|KdkY{`5MmtmI>UB zB3ip=_V$c;B2PiZ0)#6$;!mmhmf!3BC%LjZM|GWg5T`?ocVU3D>@`xr9eZa#lf>M*dd^)p=tv$b_H5!{;@jzc0dj&NT>WTJTw~S(;H*w zmLWmR1i>nE8vQTl~wyUxW=(SOjq3;;F7cptVt z8;L(mFkLTSDZWt_N^#8b9G{O1zcyzb^8mT2i?W_J1JjF%N1z7H;zk$aItsX`I2o#X zuw0%N%~M1w<;z?yU7EcVIZz5m%A!U1u$rosv?dpdiO{p(zn#rX^F%oi5pM{~k3$U2 z02>|stayE_e^44v>^m7`IB}8~=Kq^}EsUs?szgP8@-*p^O+f>|>gVXM zcxLvVCfQ0>;yl|2#ktqt5UGb&;FDDf?&^+C7udm!pLQ=*iTykEwdXbu=Y`8jn*gaB zBH1Cpa;Vf8y<`aQ;^oVQ^J#QnylB;wh`b~33QZ6thY z=sk?O=kDefQC)ah=;+Rd5_^tBgSDV-*((U_;fFF`$&$xoBx)Qxk_+#xqLZm`%&aV} z_{3SljC$WfuP*Zxx?E06cTJ3kUcg`Uc5(cP5_b&Vnp$rk9%|zIj`HVW&Wb4Qyyn(i zkv}ZDWVeSj{h>Cho_4G5Lr5_L4gmdWp2dZt@2XyQB1Taebr>clwthluM(kG4p{BLx&M^#Av-zDyyV zLwJGS7@ObW(|HKCBfF*mlXW_+q$UyH4BNj^u~xBHs|RG~h5Gm*{Rxaiir)?55j)}*&$ zFK&HUojw1OeZ+mG*H1et3M8{q#(PF(CRWn?{1({&D_jIxjc&fvr_Aj7c#S>Ybl=U{ zgJMcvbRZItn!iGUL~K9>1oo%IbhvN%p&2uSM^@EWz6yzL^!4C{Y3P;@A^;t;K8TLB&~fUOo-~dyI6viZPG(G;|NYS04Y>{ek@M|LwuJZjZh;cbSUZcDG=l z#;&^%tlwXdhBtR~Eu7g$b!@h#yCcKY``_oD;@ji<1a{^mIv+lhX=Z0qLqP-8j$@pC z!$n9%H69bURuRHZVs<(Tl{EO_Zj!BUHBu}Ul0J7KzA@r=Hdl?Mb>4Qg!Z?+q%xej0g(J* zxru;$Sw%F~mH*Y|Z#+3I@mq(F<;7P``a2G_V{Y=r=UUe%6a-sj>EdGc$AsZLnRY$L zyErn~W-{WO1e4S9GWS`{l$7otOV}$`a!_y$W-B+P&8nBIt0JSuW4?JvubW|}(+)IX z2&l~oRS5Mw2t;uskeHInV&j_A^%Ot_#bc*NjSK8oSlG8|Wm8KfmY}?TT3KG!nD*3d zm1RPM(du5XQXKn!688~Mq(=L`@$jE0vB?_CB5P@I@$hfU4bT9I-G!7@W`a3dQ8X~x z-AA$mu1u+MG*|_lEo8~q$aX=s&|oiUjD1MUgAN7@NIXHS<5S&wo&+zCoa+BwC`1bW zOX$87+R(2pSp}qN*+Ykr1yJcJY^AVkP-`j=a*F(rtB~fH3womUaOU#EU&V3xTjheJ z*(Wc~z4i6xx>e0Tb=b`4OQexbobVvH>%_6Ek@DIkvAKJ=`N*^~|1b6=XA&8hF@p&%{ql`wM(TtMzC^ z40;z{CY*p^8aKuep%%ya0YkD*J&1Fw<92+xD1bmZ>;`v+i}|J+`=>Egd&cK%9(5oE z|0O^8MM$w-o{8tIJrD&gm%^?j-nzCk!%~zVBQMIkAe2NBBL!|45XTt^AdC2c`%Jih zwQwJf%xST&-n(AC37e~aKg7rS1)AYYD>R>$s4KiHrTZ3Qf#IY6+E%&rI%h zupPchfnKg)9YI{XbLHJ?R(E}y3Th3J1>Y)BrFuA{FdYucD_ZdRm#a1%feOxZwBYv4 z=9}p#*7;gSNak81!5YCiGy*OG*~J zQlr;*gF*7Xt5+O!@z$B2Jkc=Zjk*7D2Iy1BgM za{n&^-S2{ZdAV~ma0S6;5rHGdRwuKPweU0Wt~@_(b1P7@6a?*m-R2`d?@a@K6>|0I za{L=e*=;{=l&2_dheaP%RvP8viycFlO`^K`1V166ox_X|%^wc5VpAJ)nHw5ZN1L_X z^XtX+%8bdZQu)qCS)V0|%vx+W!h8vqo_kADw)7S+7o}{Jlr~P0eh5m(Y?n=u3SnMP`y(f~wi84E(1O19Y{rjU5wv{KW0 z4F|E&rY+x;qHAi|`)~!stVkA}yVy9ku%}O2!+5phE;O{M@;_rwP9gd7q)uS44EqRq6#7sU;Sr>>+W_>0~7pB@|(~^U&SE&M% znwTI0Ws?X(0DZTN@b-*#9sRh2(dhfo;aqi;UxrC(cv;5w*`1`K4O9M8?FO;<4hiO~ zSLjD{xZo`?D*-5rNGYK=N?_*610Yv~{|aQ(I3cQ>BR{WB{j~Z&PY=>$N*jldR^(9P ztASb&8Kt#|auUSI5W%Co?%yXU6HfTDkUo(G4S*eGa!=&()|Vr;{QRtDOL5R`*->Vd zK?_AWHuU{Rvc_X9(;6LlT+*XG}=O9w%AtMec`IJ zR=X>;RtJ_seUy}W4D+I~a^%fGcL>smNtCh`(+mk_W=dWp!13?i6!`6@)FWS-O{bX9 zC@?;T(pEI!hsO=WLQfg2U2Bi!Y53+D%|`WNc)Td?!vW8^uaqdVZeFC>?Spu^@3Zft zZL~KLAhRh?az`T6mT%2XqKQ)EOhlCF_n$m|2`sLU)@IKc#!6=x5Ax0vOTGWHmnh`H zqzl|&+!gsBbcpA~DVt;-u)WOLZ&E8SGN%u`#%LAG?84ie#v=nbxBIQV%ERA(FQ8xc zzD{!LyU+26#*hoB+^7VnEvq+oxk!nrZyH0QOWCrln+$)ZEA1BM%1yvdPPxFa<1gv%)`>RP|99GuMH1*Pmb--5x4U6=9?chT3^0p2ygJBoXci)n{d8b z!ODDdlWC_m>yDF9Y9p@3WmqrIQC95hy9|VZ=Y>mwX)&$j0K9ivKUKB(G~)+BGQZfd z#K7>m{V!A;$J2bHTohHjwKQkYSrRe3EOz43Qbuk6rIb@?!{6>Q%32qq@@k)IHXU-W zZv#VrI$63MbFX~<2Ly26ka9#jNN<-{i)e<5Wb3>fxH7+;NNz}O^o1e(l)W?G%1Oh= zZ@(Jv-yhJuZ=DD7`M*VgpgCRMth5IaCJc3aW^TpDUy6poWlJ-nu0Nzd>>6@Z+pNU^ z1S;_g1@$~O_OZ-4mmSIRH@#L1NhBQ!tC#uZ=i=E=ODMTn!uc^x*S)g)f;g2`|AYIZ z)r$q3#@wX@S~EieP~E|$0IDjY?QyML@i@!{+*&TR(+^;qgf;f%6}2>pbLRabozPs- z2Es_b{$#vA6!J~Zz98_~MxR>?WkST?G6ubiCTsmt!UR#$mZwmD4}n`>{#FE5mY#7ms&GEGDwT=jK5>LVJrWLW$iAQRvxBb zj!q-&oz?lGfAj*bma=6oK;TB|Ks3FNUHKvTRem<d#AaN)4LPrLY=W|!${b0AJXXO`|(9u7k!<186nErXl9%Aka@e)58HWmY-6w3oSJ z4fokZ#z3>MQnQfpC!30*B~ovCi+CAM6M4vmWVx`5rS`l!4}8U(oU&rujx8||?ztou z=?Xwr@1S<#6e~#BF?w}+Qc}aiPs0Q0_jtCGaa= zO6t~C|9)4`NPUm+lb4jj?zhX?h3lm==s{%Go_>&k4RW_0iF9e7FeT~nJa%P7!Duf$ z<#gi*1e#uBzT`9qp=Lt9wVvczp*V05U5)#COml+ZN#Vyl0BOaguOe59gZ+H+2_(5Pv%j%|-sfmI32+a$P6 z^q5%EqZNH8I>3&cMDbc&ppQ&Z@j+k7s;{A}B1<++|2q$%v)6Mn>kFvux!`Gnes?>f zz3x;Z&R3Yo`x4;hpyXPj1)g}yn!4cgF#9LrQ1Vg{RyIfX+F1!NCtV9glyBf+PGVq^nMPZ64>Va!Q z-|#UM?WA<tWQ6)`_k!sxhw++v z!pv4Q4712U|3#S}L;_c>T@tsirK?WnTZH4B?^J0T@mkDG#b-;6QsY0I9W~8PVc6q$ zj3W6zE!|-hQ&t&Jcj;5RlYF=D!_4*k#ajL(ifKgs^h@65c9+GLIq@sc+}a!ju@9Y1 zbfzC|D!=EBn?*W`pdcC_T_C5{`C?=4`@9}$ae~-(J(iV*TT8G|Oh#!fs*(j;U`%s` zs}dt>1H?lSf(m!fyEfW(J1J{AWrNkt>0`FXbFQY|xnW!B9nUvsU2dCT0qa3UBde%@ zGL_9f|65ByUK*{>X)mXbC^xr?2uhL4pZcxA>WoRk0XF3Z$5W3bfvZeJ-OR54;k1i? z)}#M6hd8rLT0m$+exf~)<><@|NT`yiB9SuF@4!*uLYg&bX7SiMnD?fz#;x0O*-B?U z9+H1P6|ZX_86aRonOw}7((HstvJu_W*Aat&SHi-MSHZ3!-^&2h-fZer2;ZZfGdGND z$!;&hskR&XWJYlQVy4o$A`dMRI zgXPs?(y?8scmx#F(y{q-TiFPIgoZKce}xqbA43#qpu=({iV=Wh$aeJvj94ZDYQV9X zR{lp1|E)~qKWWBd(xz#wW<4`am55HWTYO)??k$nnF!4`9u1;{M`%;(|9YKo zpWcU6SH;Q%)&UpRz9M|JGREwrFW`z6?!u6cZioWU)Pih?Py(Lo(2{dq38Bs{F6q~v zV4+SMIR8nn{%DJi_<)$B_wOW^6w6$O%{?nIIv)~ujNZcg?kuxv+p$kHiDjv{$Af<@ zee;V;8@QVJ=W79p+9jst9>5pULdvm)QWh;kSx^HLb>%r1FtKY#?N5Q|_=o2S(gQhURw(usJncX5@jr6)2C_5%`0pH!e^>FFKj>+0uTcVmm}mk5!Ji>)uGtq#cHD84+= zDtqc|S2oT@ZEE2Bb4{}Rha;n+09}bxJ@w7bA63k}?4yhBJQyi6Qc6xVYQbM^(igne zaVcnWS#$x)Ds#Xz$l>mfvc=F?v1Tt-oO@vyp;W4-B%Y z6^PvVgJa=|lTHM74J?Is9dW@Oo;f}p&uCKS5Z8shBbooexDq*D2hiA@?vQeD^vSJz zFw^}(Zme*Zjx|Q#`kX49_FNuA%{B#>5c2KR{D>D;&_4oHDX3?y>!LKdBhf24IMPlt zc@lWQObZ|)w&ceg>gKy;BBUU6%)Co4mAGE375vC_GHQJxZK2z*#U+Ddh^<`Q3@;l8 zgV|=x*9uQH^>YTFdE76D`0#L!};z{4Oj z5Z|x6!B4Ec{r}d!HHG^0d2yC(Av2qUoTeneq9ro`qOBZH!;p%WF~6pc%qkiK#tFqZ zD@`ZPHQtE?n=|#b9MP0+HvD^i!-9!EoK_94Nh&^;S1p$3$jo9k#k@p$iBB_@$5ip( z6FwT`x5BgdO@Kf;d+ej&WLYq6v}3ed$)NuuS;eCit{(2DN{&LWAb!U{1w%AJk%rq; zTzK}J)Clt6G4poL3JC1iY{se`v59lYRUgdHjd=!Lg(+PFvGJozUVp*W##%AAt*fje z;C8>l^yEJd<1%*XDz_k#dEytMp;OiqQ#I)9)bF-IUQ-o>!)}yk=#bi2dDl*+OoiA_J=%UkEUgS%I!IdXb$Co#lga%GS8L+uTmZXE$1%YPn_MJ3XCe&u z{LB@b- z1I%Ih!#@thCT(kpGVt$5g12EJGw@b+=p7GIh+SU%Svela@Bl9ofZ9*?M^5upO3+S@ zg$A-idoNUoWHkd(_4IE)Y4~a&BLgbxD1{62wWJMPS{NI4A>+pbl(Z>lw?7@j2v%?< z;U;p}SHc3}8I@jCuY{G~jl4NgG=B$92eyesT@xe& z^^7+?Cfm5;NMvhO`}G~bd=~NAf&l&qoO*-Fl7o-2g?kdvXswVT9qrz2qvd#?og{^v zb*JwUjhjSCo+h-qW@+3hyMB&e3=dNTX@8e7GyhUi>@{jxscu?O0kqw|@K3nGF{7{O z8(zBggz%GQ*JSAYQp! z1!si_q)>Ms`G&gA>gI*I%Awt``b3w4)4KNkVY9|Uq#iUB(@cIXL4i6$CG*R)#XBzh ziA}`)ykkx-zH49_CJWC|I)RNCIRcjI!QLGgO)Dg?BT_+^% zdPth1iARWxlKZ9VdZFyXCO2qX4CL<*w#2j+Y+?^Yf=U-`_P(iLg6xyWHRDvAbm}aD z^?*_({+^C`bR&H)Fgq*0??Vj`l+!Tn|M1(i(BtxtQygq3q>0xlU+eGFw_AE_ezH+_ zcW6dsq$w)vTrWmh{B!-4KO-+h!#--Z@~bNRqOB{ERjT|@mv$s0_gA9iRe5xIQ)T>= zfRAf430tVHZ)HPm^{1o=`WdG`EXYienIRcXJwAMn!gwaLsa{o^25ycP80l^qtq$rx z@(x4nvXa;)$_q1U1f14H3C*Po&;6Kx%dED!fk6Q?1Tz7JZ`EfT%vGrD33xGclo>9plS(~l6j47CdxcI) zTvpR2N>!267S3GNBheiNQ2~fYV4k*A$D;K~!hzfFZo?@z)4$5E`JY7z;EG8=4y^51 z97Pw+Tn*C-X2PQ%MVtlEreQXJ-_RZRch$ujVUeah_vTqS&~#A|a+(o13Jr^`d8K_sD}aYBPqRLy44$ ziDlV|GgOoQ47c=6?sI?7+0Qv#{%q=5tFo=Tr zTEuqetA<{cxjN5ju`4%fWhQkG-MFw#SXtq)y>!(6^iQ$m1qngL<2$! zeU!~KA&(NlFyAB~3mcRyO0!5}4UCxY-95ehDRqe9$r{zx%J&DalN#?cTr#(zcmGs_ z9+sGe&2A3hr!^|;WA(Lt*yJ{rpYdxjE#gPbKEpV8A@$1;{K0cCpd01jK;FK7p~;{P zS*7hVB6*s^wiWO&7r)vQ`)?V=h*Jytr2E^oFvwq^{A|e zuc2Le{j!?*N-Nq>%xKXJpl5&43v6^- zLn-k{LxnfKTRybOzj7Ac1_9|`qA~UD{MspLLJ3hwAH9D_J>X8gBDF~=T?m70Kq}$G zND1uEza;IEy~FUHQQt=*IBo|wV@HsgjcxBf*mp6wp=fg)CET~S@=mK>U%()0;k;c0 zP*|NF+(UDhdp+y9LD#d-@ zqQ247P)?-3xkrhxW`S!Zzrs$e`qnZ{2v0aOsA&x1KrgTn~>jAy}2Dhf#TwO^1<;Wh;|MovKt`5x3APr@xVvyT2UE!dWoT1cdD8jI;gGq z(P7~|nREPHCPr)j{?ao{9=Tt%+l2& z`627m%H&;Psf84j)OS5Z%sp;&xF0!CxOa5%a$ zPR$Xf|Di|?FBX6RA=(Wj@?pv=o$~NA$Tgf8agsF53K~VEqAqdnp)H!@yK#Z^MZNgx zIqY#UoFKhF@7Go~`gj4mO?cU=O97nCSOr8-+0(tM2~OhrzCh&mo=~)RXMlA1`zh*4 zLC2SEJHM!t2CG%e7fbO5?4Nuq*{FpKPU~2Cb z#F$6@>u+92+SJQ+QTGIL;VZ5p-6N6s!*jHL_^Ei#1D`n@3NDifxe2JNA+kE9SNJW} zvq;=S+>tjVLC+S?Mz5WteDyTb#QdO&F6nnS-}WCbXZ>QQ_DVl82{4hDOOs~>=NBwIuCEt zL&1DzD>oCdb>bEl8dF)m91wg95&hcgS30j88k5e&{SctO9aw55>uLlU5M%!>x#!B= z8!NYyScUqRalA<)_SU)@PJVpqa!^MdDQ+Mn_W2+Qd&UY?6AtLd$UQfx zhk9yE1+Zm>jG9%OpwcBsr&1!_9RdQOmg((A5POo@ub$KGDYOZ45U>ch z{1aNuuYl*+irgHV8AA8EN;pmPv%N5M{%H}tdy9`ur!&u6wmQ}&Bb3L-cGCYcFWV!U zRw&nxRsCGfLiMi9|nu<-jy;zQ8w8D7iP3qMBc}j*{qZEom)s6ONvv z%JO&TEedo<|IR%o3FSvrQfF|?ht}*d_vE0!z(77!(|Bxbn5dBhB2>2X*8ImcnQT0{ zo3zi*q95N7;fR8k9(qSY`;ueW?Q6&sl@jdf(O47fpkt~2yg8iGp574l7xNCYInjLg zQxvKroNlYXQNtY49C%3z=!}2WHeWCKlCt$Y9Le6P;R{%g6yk@fWQsuyDn0uEqPB+Mo#QW){t-of3Qe<+n zf_fGLPeoJvxnTkyHb}a9(nkrgkuX6`oaX;BIX1NkAsTxF> z;;jF*!PQ7hP?%EZlX9I_A;ef0y_fg0R5;g9WqEYbMI>w?h|J~RpHXbBgI=>`>I5l0QbUPKzmE{Ldgc; zkpF+Z0FyM$Hb5Yn_1FG;Y#9$m6>^_8qjepY*VsCk22BP^H;ZK%Q=){zD%Y5)^EDLB z97frw8^f9ad)q^N&B=frTNg$FP=G~3k(im-Fw({P~CQ3Ov42lZl}|&1@1OuUX^a2 zWktyT{?^5ngBP@s>fFG^#r=jPQWKa%P=GGzqnzD`CGL5@-fB-pwdDfpui9s>Ox23- z$N?tips;`s!y3uN1!4CNQc^d@7RgY66d5R4^8;yWFU}rxMM$0=6WWPK9urblyBTFK z7d%ZrbUWY@DMmUFLYf9#2_(we*OA8|%@dm~flp{eZC{4&Tj~Ek4`vvYHL{hegr->cNL(Gu$7_*rVlGyrLd719X-R6Wxy^;*m8giwLOulKJ3MzMoH#6J*9 zsyO6w@~*hWrG7ce zo8nh|(6rm3AAhRz#_qev5c%`Z^8$)WshBPDtg9SKP|6q2tqE|i2Dl%z`hZ2y?u;sL>0 z5AGFY{vyMEgR-eIAEJUZoZk^FqU{k_TL@x73~^)Q?$Aai`>di-Y-i7k=-&ILaL_bM@A# z!2f&J=KHWGe~4Pv3=-wAM#4*a&Q!PL0KOE!3x56Wl&g(5!5iV=KULj$3Qarszf-y` zF^~XbsPHXDWr>h3*7RTOY#HXUl75-1U#DE z%p&`ZMZ-_&4CLsT#djg#f@3<<_){(MMP*^XE^(l}H<0N%>fauo|MqxRA<%7F;E6ZT z|L$;usrXo79j6(pNYLY!n?awz8oXtLf3e*2-nI5|k=cCdBVo@BuWcIfMf?Nh{)^$Z zKIMbLSQy7p@j>t1_DnzZ)B;&eL0u*B1YX4eKpU^7d`Oor zgT1%jir;d>Ba+?!A-MrBAG6ngiH8U`P8obY9^B^HH{+r3o;aa#KXno4zA(4=>D_sRS=A>@|vEtOaPq637%~Q$D>j>DdK- z2IU~6(uTTjxn;8~VF=fj*(a`5`3K7c>wh=#Rc0y~S&;BdDdLRlmDUdIhK9^``Bx|`_U$4k3L{1lxnv&rMe;t_DCCJ)>z7ULhc?Wq{# zXnX}Z0mpeLfFEZsf&krLlkM|RMp749{hsi1b^U*289tKrQ$t+q8J@6WON8%>yzz$v z6=eCF>7*PVql(bdTJ%A2?guNy)&oK_<{o+9f@S0@g)468i0sLJDAoff;%!01JS8x{ z87tL2&AWRK@Bbqu0Qxubz#GpI-0(sZs5`7fL9KVgXabGzZULKsTWqi%t#9HnVZ(v$ zKmKX{@sFMVo?joi2I236w+6?UD?}_QgDG96lez%!HjBs|%IgTdn+pfj|7~ROC;>l> z)q#=S>$q9+o*cI!khJ9sP}}&v2BHwlumGp8JdV>C^d4(Cn2)@W%UdX2k|Uv4n3Sxo=KtsGw*LMjl2I?po?2xeD>hMdbMzhr)~U?jYtBA4WpvOg zJX2MmRKvj}1U6_(|IGe7sQ;~#8qeCbp$bVm^7aW6eVC2CRkO6mB@AeQeq1qtQQ*Gk zK9`cPx#Fg?EaWjB8&Q5Vc7ovyFW1ap1Kx-p%CB^`+>(RbSh8C#fabsmWR5Mo2lt0~ zfeXJj6;u=Y^JpCeu^$ZU$nqb?;Ub7_QErDgMp?uRS?HaC40=2bqyR{5hrPE199W)DriDBBAV~6f z+UEb0C-I{^J04@N7g}fw2@558!VkDYT@Hi-I*a5cBQ?Ra$#+~x9FQ6TZ^cWOf7p8Y zh^>gU{|mW-z+u5+4PQdq!H;)ZmDzKT!CWyGt%8WU?J^`)7=#dL`vj36$$TNksEh^} z6EnuV{JEwKGPh5aW#^xOyNT%?ZDTzqh)sQTIvIQ6kI=08zZfjtUla6Gb5cwmzyKwS zX?#?6aJKQiIC6-Xam&g3OR9fh>3am3H6xe7uob{A=9q!udW-(Ro$=xogmU5JQ%k78 z`mjF*B*%gB)&IOAO#M-i)p&(6&k>{Y@!USMdFqCN-r$^FZkgP~`ah7!^R=)2S2G$i z5H`1VBi6f-N1@E({}akcvC!iCN_OZ#jns3_W6)4HB+fRzEN_B<$o$6UY(CaRc@dj8 z7fqUDigku=yC zk9L5^6NhpCBNXSF+K~{iqb0s1>8jri{HNUCP?6S;b`5>+PF`WF#tQ&aEH@4f;b2lS zGW!_J&PrIqx>TN+1esf#O-zl0Bq9NZ3y8nGpTh)SEh;98op=Da#{|rY|C9dLN9hw} zSoo7=Q#%03WTblK6ClsBVr@`cUK*IJAMa$hm~G;dy_Ca=5K-{=z^!y2x6(~fd$x-R zOU3G}H2}szgqTU9U9^Bc)sM_8at^7Jq4F$BQ(Bz{wCJD};eRxBwe`O$&*^Og{Ww&W z%$GnpOa=W$1k#gqxNWeg+7Cs1g5HU1O$KbzGZ{C`nd;P)nwgdE;8wE`_$!; zy!=P^RZFV+o@t8}Qj)q|yDt4}1Po#Z_i}ut*>k6VttUAc!u^qn*nvbZa27jgh>Le~%xu{RS!ZP$9Pt=bflFrS) zIde{P3(1*@eB-fu3`);D$d{uh=Ne3Ic`2F^o&+C}dtNI1qD5COu@ zoU1S3&uJN5XWcW!D^}x1w0mVX)3)1D{0$N#{kQ1VzeQH^!o}C%x%KB0RyQAjN|+xFHk-67AMbCqh;jo#ry>5crwP!b)s{@ zdf)6&y{!p8-uT;}ls1E9;B;g#zlY&J>=m`X#i&%SazYb$^X6Y<7C0qV2xWU9P?e~! z9<^BsTfpUTxu0y~pZp#j+0jT<-pChZ7o_H8(8>sdr)$P~f#3BiVZ<}YEUo1);=&a! zcpHOX`~r*{UBezkeiSNUPnwz!Ma;phZAo|l9wUR-B7MS0@2q#rW-9&3JCXiAcgss~ zfH;`49uYt4`=TNK=k@I_?7#Z%xACwh#FaV;OAU#ltCvFi^=Lh!^p<#Tn?J}*tY zCW5xz8gzZqy$3R>Ssxt|*@t-n8nbk8o}wkp^3zmg*7y(nTw!=8C)%YQrKhgnx934; zeh6MqK;zMGdvVn>|MVdGwbLMYk+un@VBpUbKk6A7gBl5+G@d6wTKG(@LoHjTF#iJ? zQ?my$xzvYZhC{v=gNHzw<=V)kusH1*iiOegcdC480=g`wB+zI-Eq2HUkfN-#S z{2!ftrrlYXylM>IQBI6VO`Zpy{THyPAz4u@wxGNkEwjao)-QbQ4PQgR>0{LOIt(8N z3l)bX``*`W-u2$^F6s4F!L)P>;}ItTgRw7e2;xgTQJ#qbPtuyB;C!VbH&_ubaCZ5T zLElN9O_y}*95_Rtci!t(;PC|L(K-1&S!9t95kzD&YUq0pnv$qTGyV+sxUCF%W4z}T z1yV<|xGHGFR^*@(BjI>UxOAY6T;@qVt08aJ8jl^C5%0b;YZJgU5C#;m?$Gmh>o6NhDqXp{_354n`xU3T^e$zH-vz%Q*YNFmsaXmRa9f_LMp( z8_DenVEU~aQzuReB;vVuqC8j`qITQ48b;2yPU3Uez@dpR4%Ykkm1L=e%<= zez%_W01ncb*3iJ5Zv#g^-W?)dljXCZFz$%>V0>M`$~jYx_d+;@5CfS|I33&#StU&y zP^KM-DD0F(m^C&KJ_(o!V_!LC{qD|cra^ z3V&Ayi`T@|GS9wE$fDJtpfU1W-LXDPGws)^Wq0k1kAls;dPPlb?)`w%Q?|UwiSM}K ziWhP?8$o~)KuUs$(yEFGAmpN!Na0gFHO|km_G?z{-`$>RsF>MT7>zgV4MV=)p5)_|7UbS1yQoos0^~kIY=-ia$1I;i(_+ zWAmZ}BLWym2d^nVF`Nw!lzd;ME=i6J%HjC0H^dr;lRK;zb7mbzkkJ>}l;a@)H*7xf z%b{pqYuRRpvd~4&-d*Y`q^${eFoWGN!-&X@kUVQ|fQ=2pIhDOBb3tkvhd>D7As*mXkrfk9m7B63u!wHx zIo4!>spfu(8P1zm_j^+y^*qb4Ppu74gaf!C%!_zu=WQm|D^XmIQyBo3ISH_9Omecivx!aWEYQdFn8VrXzQGTKMn<3DhF+zWhkzQSy0_dH9VMwW@X63u3?l zhXVEazRqo3b!eWni}D4Ywo3^Dt_ffP@-Zuz6?v%F{@GZ~h(}uBctXxzBtT50SlP90 zS%_aq>Q=A8ubMs#;YAoQHL!EGb?N2MDU+Ig=qO3dyD|3AOZ&6UB$mARP$-c<8&5WD z^N>U~`eVq0frR#U8A7zrc))_U-_q$`a^`Kgf?GLZNqYSB&+Q1s=_o=oS2fGsK%40} zS7kC7qmYgqe5L?$&S`xS)&a>KAM;a@W>QK+)Z8wEC*cTv+t4zTfCBJGsFBh z@BuF%?E_^Krin_dTXLA04cO~osIU^zjm~nwhps5u$>?4~k#V@+^1do33560rEc;U< z=6gT5-TOoSob zU%+yLTXIMaGk6Wd0!Ih$;0fK5{c;*)yen?#mRntZ93di0Kx_fcr-S%;E`ML*Fg`jz zeW5f4tWEZEKW|d{eG=T;@ZY?$DoyAMbwD&yPKj^RTSuwGl^rmMe+kBOA&;^W>n`^w zg(Mck7fhbap&lG7xWOWXT??#XQ}p2*WN1l93-WJ`tm8gfSZI4hb{a(m^0iF4yhDoV zkb|;-dE;PXJie=w$UB7P&@FMaBuJW^k3FL1cepM)Ytn7h`1A9zljx&JsrJu?wlpg3 zh&<%Y?pV4{#6K$XBwm~2U=PYY8WZX*#-RuV9Bk~&pjd5$+bx^z9%Yt>EHvDFnZ&1~ z+7J)J(5I;Wg}S>imJC7HEo)4!lMqQNK5MYk00#`ocEe`;Sf6o+H=qTRLJIH&J{K_Y zctqYxzICcv5BTf&wZ5ZEGPunTjo0Qn9jRMvM>k;Hn00peb1G=f+#dp!5oEFP%oOyt zFTfq9QPx-gLeJT48NFOx*WcWv%i6$?Yy|sHbPZdOVh-$GxfQ)#5}9!C^Z|;{eoSz* zHhG4ca%}w&VF%GdHd-%I2@1oxStmU+x$_jEUdJ{Q^6F|MRETR{xg`Q}D+I5GG*~eD zivL_xuG{rW2g`i>4-z=isGwd|64@hYY4s612w=BYO&(9E&q51Q&jQoVCe)QX1Gmvt z>IIvd+-}zlv2%_>VV4zA3sN52mx zk{DG_4T02mCu=RJANAyuKS_#-xjz)iq5=#phKf{2wE-QHuAIi%Z2?``0&1)JcZ6sP z#1r-kMaHbl`dT^Cu6Y`$T<>p;&=UozxIZU=f%DnRhhIi;fWpfG0jsp}eoWKiLq2tN z4nZZaK0hlnjV@5rp{DTiVxjYY>m(`&g_W4=S>fx_!{1S->!uwzUJfG<5F@G?Dc>6{o@;` zGx>>?2bVu|muC<6o?ane7p0O#*TF5G_3R1N_ZkRF3ff@&SPQv*&?DtCT(JTAEdcoEa+W zdj&IQ$8o`4<;{)TP=g)DqO^|*hWVP0;93D z|0RUz@k|H1iou=R_||)q-L6RVOt*?m#8b!?etT2E=@l+NDY}eMP-f_@Ke(5N%Na#l z@Ir7b^A0ii%NH)5cM{;(xBs{T)iQ2>!}pPPSu(or zWMpnqQn4l+6%T;^b|ilyA~xdikT8q{ZK-GLz4XOF6nqt_c+6USTp?zm^enLLQz3AU z!jWe)d8qZ+i*gQyCp}Ah)_k)N_oZmRGwgDkA%NVvpipseQfiZvyE0M`tC)LU$tVJG zMFZ%_qZEZN0v_;2NSkoz@_$JFg{wVjde%0=+uqEfKWm@m>7dT1xY*e?aBl`VRW)ch zRf`m}Vwlcv!BSFanoj&U(y}mue`>ETqf57btX|CqBh

S2B2DPPJK*F3mVv31y_> z>}tp-eQY1Y>`$~Xu$GWD=J}Lh9XV|Oh6raIJ(7^@pvfIlKdvYh9Z+~nSw*wzlyjqE zp=3QjtRyX!8-zGfa=R_96*I&=Mwy-0MTad@F{VdQ_&y)LHDl0ZR!Um;dd$)0*0FK% z|Mdbm%9>N*T{5rQ>z*rg915bFb;&)a#PxlyD$nJquOG!OO6j0&Rz%+1fl!YWGLI^$ zQl0k%xA46yPNW@k<>-#5Z(I7w*5BS$<-uWOc2E6wNV9Hw=oVvB*Y{fFW;og0YMz2b z@6Omsxl!e9`QB9pPD;ME3m`YJVr~2)iU_(=v2Dzr6_^Is=nj7 zIJ_D9g#PD4pp(7z%at6Ti5^WeF|k?P$M&7*jjf7((G#1c&XR?JJci=q zosfyGifxsXD+LMIecZmazP3J@y#eKdJ2ZG(v^9T!Zv1SEL8);&XC>EwA&sJSNirRq z)7z%@u5ByS$7{HRAoy1F`Dl99xavo+G!7bZCY4{qzK~e;4XT4@^PrryK!GOjmwJpnwHt)qo<*?fH0SzM=H4D?` zQLyOM88>wV)z!w~iM! zzqlL`8m0eI_d!Hvr;5~59UBn>9`3x_wr*J=S4BkY{>=lGoZ!{<2d%3D;n%`m(WO^; zez$91XEL4ndC3Rmj>s7)=+*T6yLQEu*}YdmELuw#PimrF@~1JAWu85S_aa=r7oUfZ za;x-^gmaQq#osr!JvSE<)5Vql`;vO=B{dhu!hNlKDF%S&_8(x!I#+k^%;iBXg5+!K zUhyqS@z}d%ar9Cx3H(GKpU9N~#H4@L_N~9VrSFn=oe(WT;+wLyd9)d0v8xXsWCi}y zyYv^aMqCiX#oXW1U_u1`>cwFhG}!f4rhl~1C-jjeZoCr&QX%gEs zF38|sV^i}LRjh@drICnf+_1&sE34zSgNX&$92z zh2r%ZI+5EEO3-EkVf1%osX^kN*?ESdYz-#wY$v9+inN#zweAW+7=?g?=U`iqjjVTu zhj1wlq{QRkO3_`XOm6oFTheI(z>N@CV{NFC*1}6Uus{mdqAUEQd_H6a%J?ow01-J; zm%&`M-JLY4 zpoTs6J`<|TJqa(E!YX{pjK) zJdCV0YTc|zez~ayQG32XXGn?V_ccr*cvHh?ls8Q zPqw$iYJ3&lXd*pq;lqq7VR&uT$c$ynf^bmz$=`fs1B?KcnO93QiUZMr+cQ1K>|U$U zVmT7zLH*YFT&dQv#^JcLM3R7&&@KGIQTl38TdOxLk1gPitAUW$Ve>-`&^Ps*8nx6v zoz&K9tUG=7zrN`kjE=+G#k<_>(xKkxSyLFV>_?bz4XWSznn6FQZ;ch<%KL1Rb=8W%G z-ZaBNDO_fmU5KD^lDCw!!&0Iuvc8d%3I)sb52Xpdx1Qoxioi2xpQAI&>bJMqh#DvW zR_Id@2>{S?vc;c%W$M?5VLZZAq#qNPug3aiRLYLqizsbd=6+4|C1_XEZ z=<3@fiD#Vy_6b{k_sOH*|AW7?(2fxWJIsZ?o=;EsaaH3NzOPYAQ%5x#EVW{e+qEVI zD2e`rDX2WP)vc#q6$1kK2PdiBz!y9-D{Hq*J&&uRV1PoS&=DKoLb==saXCTL1!m3- zQsjK>S4pcQaHz4v;Ftar$Vy(gSzVe)ftEWyJm%;{x6`boef1u?sSRTSpE>L!&-UF? zQo%8Lt7ZWIn4m^>LWj#51F@?gCgqULrZIESzdeJ6YNsyp2a4JO*6#J_cauecNodi+HyTp}lt) zDA8vkCZWsY7J2Crja6#gNMZw=)X8yO7~s^Rgj6Sa0f@lz8q43uIn$0 z$|wcoy~rWz_^1s*K)Js4G!K#-9ykGuCCrM6c+GhC#C0Ieh7JBfq|1P_(8YdCxA4|^ zau&AIkE-bW&=a6YtMKv}G7vaiM6z^FqE{*vdifN{*`ksy4iOO_;HLkPh1Fd~s@R}f zkbqCDSYG;You41l4IxtB?FYSCHpHG5&}g&p3H|Qv=dVtI-IJ4I(k5jk8!ptUe;+{; ziAwnqnb6BMoxw^N^6aUJieTCH(I3yP^O8ym#2n>~^xe_5aD<=%E1-(6Nbgr`cZ->L z9+xNY(mhu5=UyS`Jt+|IXDsW+pkv(VH3!24ZIvar&Gxk+tX)Lc?t_vetV`pGwZ!sD z7XMiWdZ87gLK7d1igFy;lU-JB?pGzgRka)G%bzsXX@rmx0(Rjl8d%1=GxRKV$*HOI zqAN|p&q;;CCy{kA{7VlY8Jp?`JigCVSLvF*KF4b@I1mEnw{p%xvcrpzN{Fb(ccl3p zvQiG!z(%XF4BIiR7e~5&^+u|3pwtz8u=XUFl z%jT`Fd6KmBiTZSm#X#?bRr5OAaaK+nnP>1K7j8`lqA1FJF&X^HDMl0E108f*D(TUx!(bS>d(lmRrMioe?;)rjgYrn8&_s+eVmX| zS!p~+4&ddC|G0B~%8I;YaGSQXkjzl$ckglaOfe*OqwRcAui<-s5}}}1C)5CRR~zcQ z?Ty0o>jiOKR6a47t}qrDfGy`8PBS}=PODGn4|w~QOj7$b%3sy;{X`081ek7*e6{Ao zvu*b>iYbEpN;6p{7+z9|#O7VX9%>2u;)Gh0ac=+@+yVO6gsh_=p~Jz?O$y0TfhQQn zxuL3=a|O*d>G8|8)>C>Xs3PMx1?T9hO=se7Fat<62-J2<`uPUQHQU4x1>E|1*LU{% zzj;Pio4IO;HR-Gsn0qS_&=y`O-sIYT7@K`;WyI&E@csPEgSN(YAMpeaK;4ONk=khHT{pGq3;9o;@crMj zZ~N+sj0{F33n@zh`w)?GNd4!J#dJ?2^iuR|EyEdDP=M^WLfsKeqF7V=jkagj@|tt} zPC^E8eHuDmE{mBv(6h?Q8r}p(prA9XKJv4{TAh&V<8PE-B4XfQ{to|ri7)Ov{ zMl-GaeCFV=%*IXYAnx_~a#x|IN?7R5J|C_bWs3TXt(xcQ?c5w**98b42RpD!6Eq=4 zx`1#0H9y($Gj@_-Y*_xV90ah~b$uI!3>b`(Jpt5`S`*`9Juf-yYjY__Ztf|)1WIH% zK9LUc11E>5$=whUj6U?Kg%|FVxq`|UDnDPy6Kuc8fYmkd*xz~=F5S%vS$*PCDKm@} zRfbU3noQVnQF6MwG%!Ao|gNjvo=0bQR@4o;O< zRq$de75q#@U5pjcF*;_T70{$Lq<*+PVqx<`yHSC^eQHts<#h;6WMo^zgSrb}ZN(cM1ieNDJI-{XO8d%zH(-F(#io1VE>0Pam%@I-CyW z<$0J8szIXG@fQLc>o3s<8>=iQ#=scV^rPI%vg!MXPWO{lQSnm?=@s;{a$KyL7YyI< z@pe2iOyx3ZD95Zu)gWwUSF(SEZ14w^v|WF$s=qtgx^l6#{K!*o1{Bg!uDQV$b7%b zr#);Fl7tk}B{=)-P5l+sUyb1%l$vSz44phRR#ZTIsbr;M%ky4Z0u_u|T}MPXsNM%w z_Ky}zbz5~GyAubTjg1OzBSwSM6Vv9K@JhBHZ8{E&SPn?DPA&j9KnIUV%`V@_QB9G@ zeL3m4oSWa41=S#QB9+juTuyy-5-7GLH z=*SC=R0*%oBaR?%IdB0XMz|aSiuC}8a5I;khayKfX^;o_MJ6Vgn?0F8KlkejN@wkuz+|ea7@u}1bfqYqQ?j38= zDP{HR0+P=giC!zPqxD=RrsuS@wH2cmiqh#ImEdC+bS&dxx>k0m1%+v4uQ*~7j=@Q_ zUlC}qDF2q!r$$JU^O^Q}^k0*%hsMY^N~<@Fi&wQjMFsM+;=(>SJ5Af%GINa>q$ zRujB9TA4#&vmjryY`J@e#eTDVF*n1{y&{@n=NZutAW}A^r>VmhbJ|pYzPMKZ7H+oZ zXlGdpVxGvvKf2N z%YliYv5{>3$F-<2G>x}MOsw{8#7A_s%ympx%H3oOF9|#y=T8$FL`#+-x*3>z5JY!~9}Abe`?nMh~#JS;!-@t&4eY z{W0X<+-l%!Zl;YTh|U%qMi5gfogx#AHVu6xw9Nf^NNJMfgK@glc~M?K^QBh*pR zsMvIRI{UEg#k1dr-%Q8t{E+oAEl;JZ$0I^b&$KR;4Wgg_bo!ldK}>)l7)dvU`o75f zF7Q@60IwF8c#W(|zX#{u(nX(t&o2UFo=M1U5jX7EpQ%bfSem?UBZJGKkHm>><*L$z zMQCkxSC1&;hZU!gunX1zG;oL&L+B-}Cwjc+fLxMQXO73F(-~u{rMPFO(%#r)PH~)u zBh1^JX>ZWfz32-+)iHJJcZx|`k442>%Z&_Z)j8?Mb+_VT&$GeLcGy0 zoVi(o2Tvk06t6qW#@H z@O|bj?{o$aUXAk$J$1n}b9CtwOj7me$>=DL681kthIh8M77E(2ABPj83jhnYN?9(u z!bVEyb~?J+FABVJyo&SOPP|~1>K3|_NFIynaL-P%QV_#()|=imnSzZ9L!(G zzu3i!3Om@G6Naiy5{C0}P1~&EHgjXtz2vk!^xV7@&H75Gg|Y+HU?OnOhQT^}Zm2Hf z@Tr@~{LX0Ip?gggfm|WiE6mvYI)_m4!U}F?>E%3cqk}ZaXqTcm?Kro4&d@ATu}LU+*%)IqeW$=#+JS z1%3zRx|Mt`U2B{Hi+biZZqQV?U$r}9#VPXJh@Y*8w|@RczRty6PZxF<=*sNC>FHp& zn=}kpw`LJ^I9}|xQbiI%aop+}(f)+-=O($xtoGAh*`j|##n0Qk50Z0pGl@GttQ!wb z#^IWOz6UI=GJA{kiobB`%0eH$r~rn%jxeAs%nrzvE7%68Q{JaDU^`0gwAn%Ti2X!z)R_JY|97Nvuf92=Slc$ zOF-qpY%koMl+A3@kr}Rif+jLp(uV63#2?KKYEj*^dy&~ibSeMP*;z&9&s#Ur23uaT z%l$gcV1HJjUmVlZ1AB5udi%OJT?^ml8nb5GsKjc&;}!ypDURy5bJHB3FXL8-6DYR- znun&U$s{Hp=-h<66xeyr#YplG#&4lZczzSXeujOC88fI|0vBbH5bzWJ)-r}js5;W; zHELfoFCiF0%oHPt|GN}ag8MIVx8;XtUfe-m&(2Ug_AyOfS?wsiX*|na`uvlY6G5il zv=2LcKSY}h?rz&dZyo5owLZOuA@q#P+u~X_&oh&i;>6;MxgWYZ~)&@JQjxLSc?-vAgoX(Rdkh}Lsl#x|pQ?7RYY@T+w&zaOH3m(q# zib7{-YisRCa&#o8&Gz{mQD!Nq>x56)aIrUO1pQfEhZZ&gbwWOAb-NDYbtpY|d90_< zbyr>yj|AmCSxKz8)Lvhou)Pati4!^gW;D63aQjjWl}-Dz#xl>}E$MmNV!t`hF!!)K zc$MHPDJyHbTO2H0D%@1{>TfmLoh zS~g|l>LWs@r9qVrLW@4y@O49qvwE`TP$ug&aT=ZlQg>AK7vAg$%AF%dXEj!<-33lJ^@LCNwy|Ubg z5S1e6SoTW*ho(Ev(E;@YQYbaYlI6#Y$es>2;rJBpm1HdO?w%c!4k-IYFPxrO&DT*5`RHOLS%A18Jz0JidY=zo`V135oxC zOhkhw_!rPeZJ24}S2~zf$i&SHr~*|LhEvPK0F7L+@W3or0s~Nf9TL4cI_*vtN5;Dj zyXa7XOp4vz234L;bE?80jw-QMH#pF-yqz#$#%L{7_7!gz3ah62hCp)q$CjwnF!9B= z0r=P+g^V=UHafNwv^}^HxTV4pJqMko;rELj@qWj@P`yiYayJsHXg24ce@YSFvW>Xx z)}9@V*L!1mcsYxetGsKzUVZ6)J9x>Ov}EflrI{zK){MUycrJ5>+~#_y`||sL8F+tZv6AH`LC1e`5z>!cuyMnRmR3U=Dqp}kk=>a2}A4g7Pc!- z8_K@2@(+$01Q@Iw$hrx8dwtmKl$6Rtl{7$R?3@d(Hzo zi)0+)gFu!&d~G@$s_0@?xt#mBUobdkk&P~Ie7l2A)GRKDzgaFZyVs_3muF%-GCEItspFZ{O4=r<-Y?pyPZ3gYw(D5Yq zT|;-$n$$QX{>|m3m{&1pYRm7<=9+K{%=*oC&ch5nRo&P3aXU0lK48qMUe)dK79V>u z`Ar{%M_G*^+Kj>*k3(TXzWzQI!TTJkU-QO$`ch=&E7o8Px+F7L+yBL|0_`@a<9W@=ZO$weZIg;qfrjn{M z*Tb7GIf!lu7DkF*F5L_fBr>2&ut^aUWSa?9&Q20GWHFgb=B1VO_PEy(`fk&%Geb&* zs)#h^)qzw^<0}s{dt*vu%QP@-;8!P%l`!u)ApIjHr=UXj4r)Hc=@k3GQ8qbfH;@$s zEdS25yGp7OdATpwQ%x={hTK;UBsi&s9izzqxvgG1+s`#3n8!4r6`Xw{Fm>c0>o$iS zU|3pi#~-ke%_YCo^m)Hr#H;vslFv?GPf%TMKmwlL=ta~pLsl<2qLb<6tV4jhzT*+U zUth%wY9n3Sp=OJg9g9RlM4B1>CiTX@LS~*jearYwsh*nnGMh!AtEvv}>qoNQ?A2b) zH4CyL28>`+xa&$^ZZmO!E06OZ0j~8pbooo^YNYwMF<$!KE<$C6(4QSy>apQ;7YbKa zm5fRAMYi67JI_X1WyCV!#Os)iBPH|(G0Lq3o)*qTDU%69$NnCK7YQwuxr-tE6_IdZ zZ_5Z7CVm_ql6oW_tmd%brH>)`bu5KDL0fqo;|X?G@ns`+etpzRdfe63pX~d;ct-YR z33;!p%WEia$kgROtvtPME2(MD2H1{VPy-ryH9Nd@!L!_V`Y48tJ^5Dal`=?3Z~$w~ zXs8nSeCct(&Hfa!=sCS(Rcqce;MZa;1pi=e#)z%d;l$qyn}20>L>y{_cY9$bvh0DxRa|<2BOIc0v%%MzbhVhlt0#lDSo_o_dj9cF;$sfxmAZU0kX?w2; zb^&CRj{eNPb=97Zf3tl_UUO25jbd7Re7H3fwOmJ?9~kKP3?EFFo!;H`PLYNW>y&Qw;L*4gwL~$5ty*!BwY2#g;9*=Nf|J!>e={n z^E9uFrRFhl7<&q)pk~$z;q8XlWiUPRp`PqDg_$w0(=M;v0XWQfmaMbi8R^?lN8kr4 zfq3d0y4I85bWVY@6P*Lw+nPjrH} zDcbz-Kn>=wFu*k>%QldLU55pw((KCOOgs^iqe_i#?irF{xbO8Vy?(5TfG;$FH8G@* zv5&t6pMu9H?|>j;vrf^Os|8|8j?rt&inhlX{Nm1$bD$aBu1w9$LZAN=1D_Q*FpoSu z?=y(YQPd7q5quEd>8R9E*YZ%6%mK_fYFY|Yo^aK;$I^s0^BzNZO|;bVMMrO9Xz!Dy zllRWOCy~r#SQiBQWPBiWIpsLnLE{v;B1E*zo&f7%%1%wkPrs1GqJ3?ug`o{w>uTCt zKI{w>jWvXL} z^!v2NrvzIdH=RmsTi_7a+L3%WC@{v@R?(_|7I^8 zIYDY7BY}e)%n*9_j7-UPvs0V@z&L%Nx%>x>u8DQtW24w3(55cHVlsiyu1;>yNs(E+ z64DbmNU?sXUGX@1cPSbn!ckTHhfz_>#?R09=#g$zsSEbSB^<3%kg0n#dUfMy4+(=& zr|JVCM0W?^BDfDHM^WQl;T z1%!lQW@%5TsE+CYHoMT}ReU?uyH(fAupp$H)9Sv?zW&Zq)#vR@AR08XCADi2{w2my zJ1z~ZhwOa>y#&zyH;ogQ-{g7CZxdPMurh)O_`2%fBgx*Ziq>Y;ox3CPR~mY(>J)$U zE1njq!I%Loj3#n^mt&vRIx6o40yZi1|7Oop>>wctEV=M=M8YQ_%j3KF-)g7A$ znJo>iFE{x5j3)kQa51lI0~hEny)4gg?dumlgb6Uasg6Ttd+6)7^6&4X|E59nuQ*#to8mn2#+5PG#;h~e^gBN}!? zz;|zmz6%X?$g5B4jfD)v0VWIp6K474&EV$0&N508y18{!d-4#AB)AZQw3-UWhz)Q# ziDba^fmkAa^U8-Zi@PM3i;tUJAJWk=Qi4L{JifH*(}jR8LpUY~iJGpw2~%IX!9`z1 zfjnhOjD8-T^3)YOiGg}?81CK3C^2|Y{A2w`m*TiqCiH7*-Q|8K!Cm=GJ-W%96;Du* ztJn=p_3u=}4-1!lUqxwtlHHM3A8U(X4up?Ts`W-T_4+wW9xLwV9W6q>!Ft4bAo8WG zI~rcb2_YJk^r7a(?9z9}n~Z>aH#`KkiZ%fAJUnX;Sf#EiynDc{Ey%G&u}SfG9C)(E zP}_DEls;mcojoO3`E{v0JlO9_4QY!dbeA%EZr7cP!X*U_MK67#XmODCVxGMx`|N(l zolOmF_3yHpttAmj^ousIvz`z~ib(HO2F4gvB5~4rc&54|Yvotkd4@7=sIc2{>2>5$ zz%3Z%D76d_;P_D7kKTvp*_(%_frA)#>gv@NWW*{Spcrfa`RnxWhk_8`0DEYc)BOVL zFyIe2RWqIa_}M&=eQOd4d(>U8tG*gNPA1diix`j7y7+8!(HGBw9vG2~NxMK!R?i0Y zdLdJVlDWKhs8it{vVIGr z%mCO1+V2n{lZR)BG)t`JD@2b>AC70eRXQ=Ut_9r1!NX(rFOc+s_EBNAA!Az!j^b!h z!EhCnU(k7Dp^NJn(m%raRaU(Ee2T-%PxAcbtk9u>uB$`zBI~jbBh}i0qtuKs{aFBp0=|(6HC;bgPxcFuxSR0g z+XLdThPt0#c#^{6&g!1%rZAQbdq=X%=SzZli}CpnKK}Ous6TzPr7<+NZTB;^sp+4K z*0%qBd7oPyAzQcyf64>Z*ZCK8?yDzvmZLzOu)M6Ng#cM$MrLw9GDe`poCB_vZ1U$dpR?AFl0FW$IIqKB3FO*>yv+ zlyjXq*~B8cG4Fc2D%U0&;zAN}NwmpNUj7cm(S8@z6 zn2>jHB=c9Gp}$C#c%WFn=_L*8c7{EEvlVdn!10vk!C+{Sr zG%+Q;iXRw zNNJkJ;G;LCHgrP0eszhbqar@^KYytD8x{@2!BcbN*R<^Ith9)HUd~EX< z6nT@0o=UrazL=4MBj}~3Fdr$}k11Iq>YA7<K2`qJO?M?!6`>(@uDy zFo+g&TQ~c6EfQT&Tf02$EjJmF(eijR%a-%_^5%!u;n@K%<}`oVc;nYc3u8}Px`@kM z@d8@1dq$0XeD}Uh!+J9%TfvlPCg12g6kOrppXp((uGr>HEt`DV{cQA0l+9QXEv200 zt9g$`jg&wavOn~%E(M@V1^O~I;ogI>sqzj$_E5Jr%03T0w~zR|T$QVto8Fs};<}(? zvL1FQB`#4(scPKxWBc>V<#(r1>j-7IR~Pa!x4J+bz$YxFO16*Wu+fnHt^}>m;ZIwb zfk;-4Jjcu-Tc~c|6%UxwT~4`wUbWx^T?3??_m?KLn8bb@mhbqKLQ($m|K!d3Q$VwV zPJ?W)9s%l71shZO$UCnAaO_G`y_i4lgK_JS>;4(7M=g1QHjo32d6?9mu+NXmk@ENb zx2K8$$QP%S<_L#>WLqQ+0c}7$(i=vjM6{Ijmm-K>Gt;=}2f8P1Uiks{s+WJx|3jN; zYf=AnZmI!iz>}sf4;A{Sc`Avr_d%HC#SDxX#i)zkvvf13jjIaj!0bMNU7&xsyL4+7Lit~J6 zUBH>}`TFPREzmb+!_fV&C|x2!>efK#&CNtJ-w)bzi^XA!zCvpo8fOG^6p5IP5F4UcoQ=wu5iG zi4vjMkw|BO9y04@8J#HhB~L<{W*(hF0TiN6)$$N=H;}YwU1RBsKKTvsX65%fw*W5> zxtx!)i^APt*l5lpwXM)sl%Th0HfH6WA=zEL8l>1{@ulx%r0gM7h6`5J5C93HN3DT2 z>1hdfsjE{Oo2<~4!ov-nGmo@HES7LUkL9onJn>qh(6fQVoF!@}W+|kTYTBU5>_>daO-ape~L22H4SaDtKy;6Yx+1f~Qk_vFksCs?y z`MQMH9^Vjqt}_fG{&u60%&8#pS^*!}3msWc@jf<18px&t)X7PNw=uaYA1Z$-O zXC@bm<`1OjD_8q|{O05!PoL|k@A}LuYi?OpJr?_MZ#ih|wm*b96NK^$h`1N=TJDgs zo*mkM4Z$O#+%;zSNDO3Lj8e;dbVUc&3XEuwiiL>Q*;_zXLUTyzQ(Me zCm=2>WAY6`4BUC%G!n$^?U8s8as#wLOPT9@34KSqSGjX3Z2s+Xja14%(Vd*p-X2iL zqUbv!Rl=%0Dl-m8N1=Fo-x5}xkOs|8M%=BGhq}AGdeC8@)C>uPtH~TeOxr8!lXjU) z!-^Jq+Fe1Ix8!o2h!vc=B*I3hPg>yw6(O)4l%4{AxUx{hfsnU{ zQamoNs-B!2usoh9A31VdpwXA(qdvN<_=cm!-|$IX zHh5^Vl3r7jdVQ3Zi=O-JsH?r{em{B#YJB;3HTWb`ENjvdO} zWO;5vFPFY|@u#x*jusm{7ab-GrHj&#p~ZAjDO$EBfAnUf2Njj<9wr5sFDl9mW-hVq z#O1_s20)H6b;e$o9US?S)b>Y=`j2^shxN=;{_~mUEa!aIa}X~s@!!=UZNvR zCDX4=_y!u!YX;;C@7-U$Q|&H|6uL{0W+X6~>^8XAv^zUt+>O&-#B*46M5+=oj&ejgtCCc%@Lo<7pyf{4*(1&qgKI-i=Iha=uwT-<=e? zg?-3i|K=KPzl$tcj9A%ad251Py4)S^F{WlBgu(+ctSoiQ0LU=(S2J-oB#9mK(e*pE zz)~~{Y?GM}uCW1eV|dRCl#DjTSX>5R+sS8=t=9ZBUP2?04LZZ(NBJsI9;kUm{D zM&G&HAoXiI{p0pr4TZqpxfi{Z@`LJaX*Uewj?sYW>(KpB0_M>1>B`BquqBbqEa8bwS8DDNWNdY zKmg(7N~;)9TrtP!S_yoqP>C7vuxWzWl*+c; z!79-m>C*JA9jv|-vkDNPA03D-;v4~o7b z8Sys2Zu;GbpDFFN@HB2}Irch^yeiF-%03wCp z*nwa!>N#ULGzy&TMvr%$jg)r}IBS(T7$FX1^9IO(n#J_C8}RIJM!^V@MMZzlWmyL^ zPfppnZi6eyw2<{IO~C1-tY&e?pNC;jVLj8Q$@8a;pL94$8s~M_3RiIA zWubNv1uX}Ci#VmWVt3;W^@XSz5)ZqPp;&(h@4+lS8$nPB*|V=-atgDBZPe>P?C>jr zT~S*c_wmVhjt#{a26Jcs4OqMx6dv?q}6K`*?yu5BI{IjaO z>w^>_S!{Llp##iR(tgM&NpnW$))T9a7f%{>+ROKWQxDa!?T{88+2TZ#SY^(eiM{5| zK?J)dn1bE^^=`V-HJ#Q-Zv7MRMjU++#3?>8V+ulrlm;WpTC5j z7`5_mC6s6%>iCp!q2D7pWCJPhgznB2V z%-Vz3q1Z?^(esooWfO03*Y+L+<;;}2Tk&Vx1*K!yYoL#ZZOpvaI^tNA>(>aRWEcEM9%{&8pa*KDe?NI^O7$e)K5t(?^0grkX80 zd}j4k)L=X_!ckY`@E6``?~J4_x3~QRs=1w|+67l+)4$*EN8zB#Dbovg@BcOOSKKE5 z%!>b30rZ(H2MzlQV{-A+8w*ZO^4R$27Q=?)#fl4R!wn?fKLd+jsWgZlQ86UFtlqMV zP8>7855xd5hoZdei^ijcD(J-vf;QJ8YmymN@TPIL`0wa~?xgjHMFY+DPSU_zO*LR~ z+P9PH)?j}Is|&j$b7t|_3ZwuOJ$Cq!P6|D@O428kQtwj4rb!~Zh^Z@a#ve&dEo_|j zEmx?jTi4_ePiCp_tJYb% z!pc2Q&+ca%ebuoE&3+&gCw61=pTVSHaD9_9CvH*wY{3hR7nz;uTg%io_**E_lv`xw zEV9#^pSUy4?KJ`o>U!z_Ns%Fwlg(Kyf9XiqOedEV23f5xuJ=F*CWaqG0_l%qnXzhZ zjb-rznQo{az5o_e)|C`>8x@wi_cUJ7s6-L zJ?wewz@u`3kLd|Prb1!oGutR9vO>}>sh`6%&MPyEa&pq0Y+ zNe@$x1vrA&WY^>-PdWTCa2g57myd1prC&DMLDL1FegMFdGAM^rW2P__=htWJkory8 z*qHXyK*&&Wzy2HBH)&SUmcFh~cZ@Av$rp2{f|{z-A{&ozH052~Um3R7rlgR5Mn|P& zSIpiRrD9Lj6yp*0z&y9iGqdmQ*nD?dfX5LDzXLyu{XZ9 zJV4tGQRc!FX6~BsHTtNA1%CfsqMY8etUvy`px~_rHB;=q)d}P&3Hz| zn()RzRKG>HHktXY)qi!py!i@ny;I{+hGL_hfv9Vu_wXp=ne6P6qpim? z_x*&fa!=AG9^V(57P0{Cz!=LMVE_u;mOJo{5VSN0kUEtxr7^yyIfb5Dt=Iuwpz}j7 zC7GVyf>pcnd-%q$we>cP!F09+1-CS_BlJuPmT1efD}4v-SKx{Rf|a=XAG8}2IN)lu$MhS z!N~{o0Y3`5E5)@3@^1L|j7ijZ0?6#-4|eA`1kRpBxI>~D9OfssN3=+Y8LUr^3v*NL zWY0_VEJBfn$v&13iUpEceb1?MGYhAaOoHK)XS-d6NxK=6Kgwkp!Vy78&laD*MOil+ zEo^dX@P6*kbg-L1*)s}E0n5h|jTEci+Z>YI(m&kOihzHA@lvY3GQm{}^sl>mX{n9= zH}>+@)!7+3&MHM@gFHg2vG3(0Gacytn~kKqBtG*m=lTGt9pt#yAkE=eP|PoxWwX7{ zDc2N=9IDSp+WvXLe&yY9qzBiv)>9oFB=OYA2aYd(95{Lr`Vau}4`3tK#mF>Qhbkd7 zK6w}x6xy|}W1s}69=KLJ`zE<6FrJyACuIKng+lQ3HZbat?XvlH__p+t9X)C`KNqY+ zKkI)fCLlGzEXXzPUjNO(G5degrWbK<;3d^#RvNU(wpLvdLW*J@SvuLXMDgM63?Da* zmre(1F*rK6jquP1rWg6Pt*^ewRM}E$gjjKcX=Sh1Om76FzRS&dyd+ zJGpQ6HGPR2o?NFQQ^D`2Qx97iZ*Uz*^<_4NVQpun4>qe@Y%ZVvoF<2kS)a9UaRs-N zDDnJMFcuD`s&xT&F*wZPOMwEvo1L?@$8_qy8W$ClFG)PNQw0w&QsiP}T)uIRK|E}= z4Wp=}(`I=Bg|Ij-Ox&h>k*JO+SJ(}O+<(W`s@LiJrm)*TRcm4kJJ=1eAfq7jX78Ll z<#igH4!E1!_#ie05RxC%Tu4jcOro@O%|GObYBTv>=$Y$oj`A~Rg?QWvXYDXvBN1ol z^n(0^@7?S6B`qdB=jIvWTKA^s6+V36sWM#Z7uaYOGgm}IVvVY`B<{zceEuOyD4iD) z%H;gIjJ@5k5$Z%h4s^F9YVo9AOh?$i;1AMz5h#;3QuUw+t4*EYlw?BoKyto?yIXTv zz2NdaVb1$3!0c+AM1-#|SDCl1nWQ)&G5}w(?h$7N}c!%CBGOTj6&0%84(= zpF*+Yf0QEDqq=Z482(!pz>c$EBi>0TK;hc^9`W>da9$_GuULd&erc8B(E6#taC#Wy z{rl?5ow~Q{Gh+Xq?}~(8=!e{~0`Qjz>*4lUBT~&9jSO|Dmua>3n&G_V_TGRdwBTbi z;Et2%)l_KYm=1^y%kw{YujSyEu|rh9aJMf;l?>EU$L#u2m#viUbHeH|!?E@T0ZIUL z3%Y@qeXFWCwWM?P_PY9IvzQ&kJUOXao&C2WN7}xAy>?Y03+U$oO#fWeuATyr#wen< zJ<5zKg``l@>n8OH*fiy2X6T8%u-kp4|K3+l3)ja`=KdpNR+?t|Qj$e;B~SZ@8Uvo^ z+negy|LvZn{sl<$Ct4i~DPN`6*L3MB>ab_8(6~WzXMSux%TWJD(8{hr7DNB*1Ia+i zpr*k1KwHxF>t=C2Ii;61h$2?ng>#lU3r%V)qUMpau(#=SG9g^kFtB`EbYgr~QB*m+^22A#)_s<&)#OYQZ(4=~LJ~LWq%K8MB@sb;iVB%28s7rWA zapLU??^RM7vNt(N)c+bMc4(6pU}IZT$j6!Bq61R{FbEpAM)jXQ&jQiJ(mtK>h;OW{JUvLe0EDM(0E^DFL`%fa6&Dp;E zj{t>6jAm1)i8D`Fu!&ga_vqxSn6dFbd~#Wh=B{iOq7_ZYWzS1^14+ET!B8grGtNYq z@LY6NYt)LkS(fek-yT%z{sOK$`4quZ?q-qSIXPo-R*BP7Q9krXyj%iKD+s}6=t$8oDu`7Y2w6CW# zcKf8H_A9NIEIECgPke=cA4Hb^L9Z&mqnGh#_q5>J*3V*LDO#@kQuW;X2{5YvzmN67 a4uSL&It66;BB7iF_&n6mRWDY9y!}6D+>4w5 diff --git a/openssl-install/share/doc/openssl/html/man7/img/rand.png b/openssl-install/share/doc/openssl/html/man7/img/rand.png deleted file mode 100644 index 7572ca6fd8f10477a692351cf1d37167dc1cd1ee..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 30526 zcmd42bx>TvyZ$+Y22UWkOCSVycN?4x?(S~EVUQrfhTtw4NN@>*%OpW22@(kI3GVK; zlkeSo_qTuSR&8z7))ocSO!ql`PWL(8&-;1aPSDX(A;6`=1poj9svt!$004{!0MPKB zV4=P_NyQsR{ll_RS5X8!{`)EE{+JE`FaT5)<@5pz_7;P3bSJM7$A|6T@oz@}QJ*03 zwGuB^2wfI)fHm@y9TVmp2QOdEXzA-!!3}C<%BN}#s@oU@KEavvYB|eRdH`s+uOvR~ zr7xV`u6Fa~dZnwz+8uBnZU&viw6}|0vaA(d7M(|d)!553{^yV0L2ijaiH~a?9MgTO zZr^P|$C0F*i`53v%!f5-BW$zi&N!qj|0b-Q?`KHB){(-mAOp2YO)7?+%2C5w7yXqy zpr`}AZDBX>SwFnf#!1ECvEG4WDm?C6oRKvDOln!o@_e^${@b9RUEnHlC&#gYrn5SILc7>Veoq){PGNd@YD5Tdr!Fz(w&30ud8Y`%CUxgN?Q5 zm*qPI1W)~Q;8Vt3KKpzWTCHC1zcjaGxew?VaZvKIM)gC4j3nkMHZ3vdH83JKPmc{*B&a5}%D3~>7gAd{84K`r&332W3o zFeYk5I~hch!{_A~xI19l5pdWew#CU_{-yvc9x?=PDY@VAUu{gnGTU+W`t%Cz&1=CQ z-@5~Lj#Pi;zE<0(Ab1KiYH%1H`SVGj-{!L18Y8xtBHqNdY{17lRcoJ)NL)s(GS4?^ zMAr86N~ciBTc!=pjnBV^ z8orUt@1WyJ{`#zY`&!OXkv&tYR&L^bf3@M^w$Y{#`Y^Ss7l7C3c3z2N>W*1BD- zzcVzfbkZlv|M_ukBt8}x^-a45P7#L}Oy(aby4CfvoF7$1^7B-l*QXOcJSD-eD*&q` zU_meUmB+A!+@=zHrWnD~pccFJjzq|+rc~}-mdKR&pN60V5?5D8TK4h@!ry>274_+Q zPe%e0v-=|8SF2zVOZdaz5`nUeA4z0pLC+Um25p=wXr;cIP&c)S@R)SAX#NU%t){Py zu2>Y>C-1)XMO7eGOfOX!rPckaC-%iNjs023P-TAcGZ2Z zIYEW)u2(#J>J2AjQa6iC0!O)zD(Xa{1K04{{?+?~jB%n zVsugA+-K)iKUj`o}E3odtc zx92~SD`3(8$u~$*GMlE!+Eqkde>sqeD67V#muNunr+an5qKgP*s?X9aRsCHd)4f!ufDH&f=n1K7%H^}wcwI}c z$DT=AE4TL6Id%c#<;R1FtJfy2&flUhm%cs2J{UD`U3|A&Aw6`t95yKSF~w?6$dGUA zlkH2o2lbldfWmwR&p`LZtS_`??3p^hx-ebAn- zLLdAqU|Ew|GeC>J$u>@4?3NeOPOD=-M=T0d5DK+MH5NT zK!n}r(2kDd=o|KS>$exm@c=whA_@1m7pt|DzjGx*g!4r_9lnrTqKeChLU%O*26b0O zWm<*d;#xi?Ds*A^=5OZM1L*sjhD9AL4v6*C)}yBwPD(-sQ+`Gs`W7Cv<$Kx>@95JA z9WiK09~;FMN=8{eZkPeIUQ((pN8kANE0O=|3i8FGJ;mdu@)xV`=FfcA&-N5IuI=iC z!wGDJ6nG4c>Rk|u6#3W-M9ea4|7jV&T9ixw{lghG@jN%09vb?uXU~7_#O}`zc&bFs zZ-nrHeNPxgymA?)#Q9R?WL3#&S%#XX>(d}&{*BiJg!7-DHpW&`(PUKJ3d*j1_n@7B zm_`ssf4}yc4(4{_BEl@hDc3tk6(#Tubi{g-RSyU94JanrTa1>ysmCZJ{jb8;qbd7E z19Pbm(669Mk{SZrq0E7tIkPPTc6|jZh7%;ks<_rxLCNWB6-E4wG}N2jP3fnc0nQx* zq&aqy!o%oYJ$ZwSf>!f6e%_uhs0eT%W=b6syV{b4AuG?n#yS;xh1lh%4XgX`d)8?D8FYf~Rm;fahob z`~*Uwna43v@!AhlbF~Bhi2;WT4-s;X%BXqV-KNU^-)a@Q-Z98~_i7sNW|DG1@9!Kv z&7jzu*0PpE>_XadyTI=XN-mSVO#?6y97Bn4cx zAt;OCbbRTG)xjw6-KaxnRHB|sF=-xCyFQ#GN zguIHWyg6SGe~jjWc?@lm`sdJ^t|Nq4qh7r8$KxBYN!l1LaZDkB8tXN&$vCLv+;G*VWNuP*Tv6iUFkvug3xZ-yAX)*o^Lm zm0Ac%4QnCNRy(}IAD_eE1U>-oI1{_1H`5I;jPQmq!qctAiO|AORn*jOm!2P5?x&}& z#o@VO^#CofmC=Ud=%_1t0K=nN zW$=az48VcbgWkf@eE{eL90Ix{<*kTT&`XH71~14-tXK44I(w_#Jsb_suIQZ5n*k#L zVSvnvrP0T6+D}L0Xim5^z|eQkZEUN9A{=2W;jj94_tT;R^Rt)wrEf(M?1&H$M0035 zcx4mB>y-Swc{IeC3wTk-8WB#2)q~Ze*fY<>bAJ!%W%{zEwIax}MFzy$+M;b;P-ly| zE9N@75PNz>bPRbDJnqdSi*{rQS#*JVmg`B8;XMVM&PvPn-Jyvx{5kxchE}fd?*38% zw@mS8mr5Bm^sBQ=>~*p+NK&?M@30(BiDOrJM|Z_cyz)l#^YXk!a3URk$gCj zqkWoTxgPp^RfuTfK3;RfWe{h+lJsfDmdn_+N9S&r|SL{9${}^cLy5hmo;Er{m z>YLOWx!Zj<#US)aaTepOwNf1KVNRRdGJw7DYibR{Id-W1jtnTAnIOIG)m{iUBsi(c zQ2WpU7$XhDd*oQ!g`)AbCsaNa9dV541$a~X`1IxmWdR=n-Zj}%Uj+}TqbEFM>)Ik< zJEQ?+t&v#>T8oZi-Sd!7s2iJA-@O;SW!ZsDSP7$R@`q}d=>eH08_9@0aV5&J2GOs( z6}$W%q9!Eg86F3Bp|XTtDXs1SJjLm0faU3*KdX_BJSP{PyXD>Qs=~yw86WF~u2G8G znFTvuk2WtHSjIITr}Mt~p5jh>${ti|fgz|Mt~br3sju*PD1cK|6ghdI1p3m2CCb?! zk_UKHyXxdQne_lQMsUhfz|5D?>KQfpbv^@*eR&GcQN8H*WD>jEuLe4+V%X+WY3SWo zA)Nl&Ejzsj(uimWIUewUmO1rlSEb^{4@k*f`RBUO2Zxj+U=Nu+8D-QIk!z-p8kkNN!^XNIh;0c#M064Rl3bpmUcIbL{xVV=N!Re!0v_HPU>TbE_E4*YSWnn7d zL3460O)gKi1vsq}2J8ZgKHJvmB^T|$x|SLY31|IwFT=KU>1{`ll3n=*p~y1hA(yu| z#iXgUtsFe5_x4hff8XL{-Zd5@LjV#7&2uDT;XMN`4J$lkfbFD*NUbCv47cK#hp`uD z!<}5qLMIrA?@8KU6@n)53V40`d(_`GKWudK1g+`&5HL9q!HjLGg{U`fDEWz4bo-ZX zrRDSV?wXnCLW%9c(M~BzX5zxmxApM>pBx1^$*pMSQ(13oQBN)`tBLNq+dNLtzC~{1 zGfS#+UaT3$9i#Pp=t?+@^<&15bR)l_)l1wL~CMNal zF~_($^sBvq&kM@mF;@$3w~?X`g=y6zvsbAGKG5o!nP1-((jenFmFzU{B8F`sm&U~C ziUB;9yJ;1z@+=4%LdjiPTWO)&yKDx{AiT8Mzl+e8J8ndM+IOGtU*_eo@cW|FPc}Vw zyDtR}@4pMxS0E>YIG67eQf1XX;_#z=XZmKBoIO1g;8ohnMaD})p9zA3{IV`*NqD5| zWTVux@lQ~zYiV^_MY=|o!%;pbnJ*Rp!mm-g;%0tY{q!Nv%49XSdZVCDq()z_T1x;pF91 zbo(%as^IFV5eQiB*MBdx`uR4i_thaRsZ>?3 zTctOQ*Au4xU#-w;Ld59M{MoylqnVfmN-pntB82T1yVvaHdQWLqB=}9e+!bYm^wii% zp)zQus`NC%j3Vz0QMw|YM)qc_5_S0X%%^j1A6DKQB=Jt88G!^-`Kn!a@6euBApU6FN{!@z1n!4kmNRl+=r zbWSP%YEnLyyFh0|X7*4DrHW$&n+fD)MB!!euZVF!{!$?cPm~9>gewky72)K9q%3`S zp#zA45JAEbYAY0;%eYqP4Rawgb0ak59?H zODjhhr4u(;b`WMu8%{sGoWD=8?+`)nB+(qDIIO?udsk_Ui2AR4L&I1rUL?fDV>fyx{o+ zTL`cmkqv6dNeoTN0;1Se`3@~M1-!o8nliP zU^qeOyE9rzf-@pPmFr15isYKxW}G(iEvkRRQAJ1v7?M*amI9vP2ur}L*uB_~g!rpm z@cD87T>)Ge!HnenEdph%O4iq1VYOl&FO_=vYvEFm&% z+#w>5I_hLc941zobR)u4*>9a^x2P7PZ6LkOnykU~n|ng&4+Np9HIJ|iFu}kfR634P z&JjlEiqn-?LpNWS7nX@)jiMCWzHNeANrHevD7^6DKVg`>1lYAstjTUb9(M7|$)oM` z0Lmz3J}5>cI!N%AP%Q9d?S+`y4Tjy=*EEE$n3^sss0&tU&+DY1EE9`Yeog~0vpx7W zXN$bA*)oI-M&ckt6F@1y4b|+w;E1E2>yfNbt;pGRmnz%K23i=_&;ZFM1Z zUT;1%`8+y_hO!TsCGpLBEplLK6pFLA92UHPpEfnuh_w4$K9xg_m6a(a)7ch?| za8d5`Qc!%Y1CN;SvyE&}P3*Civ1{k9LaY7w{7 z(1s{fXc))Cvu*d!X_?X*oquCE6b1eTxDE;04ynKW<7HUWJ&b~iX5kMko(u|c5ov?A zFUzY+flML$P@$}ib^bBn`g)wH?E#R1s{6ErU3Y`_>SmV|;v^)l)nG@V`-R06T1ayL>X+7-vQwGUrys(N!=8#Ga@=A z443W8(Q(V?8)%%eF&F7tAEe(D@tmwebM-7XH#5`O7S$GBY=J4PXv-&Beh!pxX^f7&(tzTmJ4HhNJ2#$1azQxrmX^MGJd3>-t!<# zW09ARQ?c@oSSjed1Cmmmu(dp=={isA{U@ID3cl|Wd1yubcciem`*M^(4Z+ih<9o~S z>*2n$JdgPc$$>6$ubqiYn|TenFX>Y`m8i1zADKb^&f$w)*XtC%)Lu2o$};{atv;ZE zy+Lg|5ZmGr#+$v2d9vss8@u_cT(8^bNz=o)HELFj3?{!a{FSSNG6RB1jDz&nr*J?= zQoR45y`Cm5UfY)2ve_%eEFB&qab`7k_=g8fPKCp$ERI&DFrrTE!e`|fbFXQkn70-H z`N_TNaS1Zxi0$|Pm^--LN0k3$v;N=AyBjxD5RTUUvlLtvDTdR2JB!f_`DtKjH*m%w zD~CWa_{uI(^ch@9)dSD|SshxUyLismOH3;$S3u8#7F`eE`TEwCe3FgOi)(!I=%tCT z4oa_tFspmlC>dz$>-%F`sJNI;mudQ_RVr6d9s&5Z{|4Eamkw~_C&{C2l5Z)Bmg_MG za2|>I{4NGl9o`e9ph?TR5CoLm6R5Fcg5u8MpyfW771k2>60s_&LB@MNvOvo2x1UhR z!-eP$XoOvZeSmd=k6I7M&_u~|5;0;8e<=}Uf?qM$M)DyHLBJc!70#W2+OI%DWmdd8 z>=wYI;w>d=wN$2o;cNuK+`~D>@qOuhI)^*zo>Jg1#MP+SM~*^VAt}I(f6HcuFjBFT zJdMyj5kIq=oPyAgklR(p84Vv$hi-u>%yfPC#94e^q^$}>QOiOV=&kIvd=&%{! z$?FKol`xh-&J(&_-_ScWE5j1<@yaflCYk|@C07o}Hi8-<2&>d!p9G+6uG=}L#MyJr zz%#`SQa}wbiwW~`CuWfK5J;@ZNgRrs2KkNUgyVNYN1LYV*2z*XRUBxQ7dK?xaD7#R zk_JlXiuZaDjh@}N3li4kB~RGbY*Q=xHmUm#3>$H_cjK9=KY9QRfE;NhO=y*woM%PT z>-Xs>(S|!Qi4c)5DXDX8}bp3e%{n4zCTR1!V>4 z_5t}{Y}r<9i}$~!k4wlzHwy#RArSzXpG@_m*DzAx6q-QfvR%$dw5(py7uk)Dw0$T8Vd{L}2AK>?5EK&YA6PVgj$%EAY#UV~b_dnJ1w{%|H`?BY+x0f5cOxyG^JU=nNFZ zOaVwM;g&W|cJ&H?y<{@~o?n2hdxq5yZHmKaR-Ug&u^?DCT&0eDSty#7qef0GOw=LW z)!!}Moq(K7mzZ94NV}Q4aZ9Y z1$ug}Xu^~QfTGx2Xc~668x2_?O>g1`+{*p?)GH-9*1=)N z-Fl*-%>AUvxkyjVo>5E|wj+^_{QBRy0AA;KPuxO0=E61!4WvQE&=mNv|okkiV(wEw?+E@fTOA8eY}~@E_Vqwx6Xg4 z=sKLs%j)ZHcAB(o7xta-pTj{&rZJ6xenyy)dfb#-8fY4P#lV7ys57; zxOPh%poe)78^`!{SsdIi zCI_bLyT>ybmWZI=r)^;MR-ZmY^v?Ep%~Dd11QTrIy@YNwlcasUuweORze{s?olDgv zV(Q7fe{0C7=_&F)SVvABR$PkK-tov*snWdvDUYW5YY1KLN6AV~6tw?7uqrdQ>#>I0 zCBgrZ@ky`Bh7i7zi)2FYGA}qJXXUhK9YKP$>rUqv9l>1*WU*Sxwx_Gdh-D~TB(gj1 zG5W18YHg}}D8@%2j&m!7Ilzc{i0U}lD3pq%kFB;p>hB*}BG{^Q9@N3+SIt3A`1Z}Z zOuFrhj{@{K#I4NH%pFYdU(C>+XZk-;(}<&Go~u*CN)p7#DY=7y<8DGvuFWEpaG82H*s!-v0qo60O1Mp0 zAa^I3mU`n*oafBLS_vH?*SP52(8Hz|U(KB9{g zLrCb-%mY>%&UTmQsucb>8<4;0$r|p%UCii}tLO4FWWX5B_OuxHH`Mz#Kg{;HY~WiX zC%x?lQ0pF*2IB1Praf-vomrx0YcHX3zxUt4)Zyv-7_(hY(LPIp@;2C8xD z0~D2s%Wv=#n7w3O$R@)MQgzqLbFMzU><#T_-47$^ia*PYY1L+}{iC`)jP1bUPE9a$ zGW&*|n8kpB_IfoQJL&?&Yo2ho9QnM96p4sTk015xrKYqnS>#i>hW%$|Scf6$K}VMH zW}k*i9fm{ID)C-_X7)%$^qAbs=?LjSM)A8>LXV2zbShE-CSv2{UX;R5~0h}ZZZD8j(LN*N+c zpnj%9mkCzGTuVh5jAO@XB5N5@ABC8(q0*vm=tWOB15k_u4GuYz`+K$0RFMIG1?p9B z!43anO&iSfv^>M5IT***asCZp8Yh4DdF=KU`!C+L`%u6@CfL6?#i24p99;^+ zEo)dpqO*42i4190LX+>A0{cYb9yZb$-+7WYF#TCx23n%4S5kSQ_(KdX~ zBardJDXn4I1g2w=@Epm}Js50-er(@q8{v6c#6dEC_3R~v7A76g1idt7+BTw9E=r4| zr2H~~8uq4%ggB=oFqMf%6Kd5&bA@ZPC)ERx2KFdM$AQnYu;TAtVO(GnqFn$lPU!Z# zrVW{0S-CEPIN4g?R?FQm`jkJJ$*lTPi~Z|&2qAN%3y_#o8n}eL!62v2u0QAuLDrf> zzCrUZ&QuKa-J{I@L_7(_4J|n8dX?k0Va|9YaM-B*)t6^Yq!lBl@F*ubsres!qhffY zp|WCSxBbo*nzHg_y!nLgNcc!*MF7TL(dde~7Z<7>ho-_5#z`HSi`ZRaZc&U!9mWxY zCW3azMDmLX!D%JwB^XRnmo6>18pkE;)qAUTAl+Pf%c%d`{1?5 z63c%~OUUAuxpj3Rra4&#h%bNZ8r4Dq{(OaoGjj;sd`9n4odFK=6+Pk~ui>L_dyBJiT+uQ5WY2aw^~ zs|m~{*~2D-VmP*kavlabKp}b<<$w3^BVMjmopP+KS$+QC^GV|9Iq{jL+zl5hqiSL% z4=m2Gx*G>*WehN!Cw5BFlctHSk(k6X{^lYE?ljtz8hq$RyTZDn+x|K8T+t!3s+vj{ zvW2H{@en4?AF3~8RtxDxb3~&D7BjnA!H?+n(=vVWh?jIDInhsYFNyavM65@fv;VcF;*@B3TD_OTa?pQ0En{b5#?_ckL$vj-*L?swRY% zT#Ci_i90L_nm5n0~~!Q`J1){SMoTQ zTA$@44lPNOR=V#cCgsc}2Wr~lKb-Q?DM!8bPc4L2)U5rFR%aZxdz6hbttdKG<%n8H zw__zX5;$fUFUWV(0nc4l1U|Y{JtlECP;Scv(^3!!j`Btj48QbiFQ)Q_JTiQvGsP^( zt_kznYvghuC+GR$4?&`GX4D+tczbW}{k4(sy*gTa!%~QE9%sgaKlD0SDzYiWgW-dJ8f(SsVRqi1X z)`e;TF#3&)W&`1jK%%$Vv%7VTvZesn2>#4Z_tgP(iqk~_iVP?}(M4}RU#_bV;G(FF4xd(FG+YU(4E3^tR zc&ppmS|fXHhkA@|p>IcNr^EXF3-XgO+KSy=rfT%7xlHF&YVS#W)+cCk4n;>kMOSF# zW`E~%Bqi6@&}wC%+HdBfk(TCr1o*0}y;1e&?DZ2Ca-DKHf~it(WMm{YPo*ejDOtKC zw_95o&z?5kZ{Sn<#N$N>4xC~3Gz@46Oj)ePev>+x!A{$9L_R4`L*R*Nh47B+ol1M5 z9rq+$BQMjssP>H!&)0s4vL-!Gi9kCz78~H1m0teYwON>ca)L$d6l`})NyY@MRtFcg zFm39S-=SN$mORJN_z87r=g_5DbzfWPqQ#*?Psb^gjBx}b`EatZ>`Em|| z4o|3pR_4(uw}o-r6ZFf{K>NOM{W z(Q57TRO&>6A|`+^_&Oh3gJqjWk^6}-Ow3@4%7x%BXzktKo=|$^Y}5L4+x>2%kQlxJ zKwI4{Ze8IXP*HpJ+|&#xTyc zA{Y;fpgU$|lDTBY3<~k_U4P8EysPG1(oK3^5TS&&tZ0`Tl!)(ofK?EEXIZd!f6qQ% zKTE!C+d)Oy=GC2Tz{8TG$mMsHUnFQhdc$Vrsg{5Z(oGybc49lM@M|9Lb=2NTn{D^*+hA zv~N)cb8lMcM9C&|;fx^|zS@kVFJY3+OmcIlp@>_&O6Kt|o+IO;!M#kNx9svAE|qe_X~z@he|I1iQNv zF`}ls!z>hCi18rJn^stZKTH(5>%SZzhr?Wy@*Rc^+-JJle+b*|t3kX(3ueUHaS$=z zFtN4snuFe`eh&~GIWz9>zwGpSMBR0>P|?Hs`n_yjAMIc}zNFMVVTZi<25qOPr zwZW~8`^Qi4;$d!XEC!cuxz_`GLMRJGX6?;~RKuVTe5b#|HYBex+IMz9;RkpREIws) z@y&mt1;mX*dGQOpgjBCPx@$r?XX9z+w;!v8Cf?=sn>;n|9UXm(hbZN;x9NSCqQ|h z^QYT7w|$$lW9sor6vdxNBrxh(0oYv&UxsGN2tFsM1|509|(nS1R7QYZ$b-{hxdfSysF}*x(5A@mff4IinS5>=41nFH^=EdGIf2=Uh4!Bc{1f zav@BIqFsXz&v6fDFGUJV^D4%O+X>__!Rc3Qll9cuiFXELI_Q1appP206VSZpq@;kE zm{qYUVa#}n)8DH0N#1~(-B^^THsPn`ecbj%z`>33pEn>(wI8iVKy-1@2%vt&K_L5+ z%ajm1*lLKGnN9OuJ)T|dcNC5I@96yVHOgkO)xexulJ0D~>S&E4+!w#hv7H+dJMLq4 z$jn$E<#P~Tu^HNKY4+<}Hh)P~I}BN(r(ADg)ZSjk4~;)lv9pnUfai9maU2~W8%7xJ z=(eLN-c1A&KOTMs?SJu{_~o z4LcH0U!2Y=#L^fp@^R&?`7N_^A7m9oOwW1#rge4jJ}z1F%WHO<{nFvVK5i{mitx`? z$rm>Fq;YR7<_{5N zSEB;&H1#n514j`514j~)IIA?~mKJ{+QaJy3rC8TMq$1w>m}K^xPJ81+m+VFWO@iPe z3n7Eiy9`=WXlbV=l%b6V$Lcrq&v(suB0-A1up+cBUqZ@zI6P0#WflsgMVu zlSe+ZYr=fybWH4L#cbn5x%SJYdA9bor6bXRYj0t>GRLJMZg$EPI1j7a4d7Z^jKAdz zm2YjNZo?bdzrr<(dq(q1R06o41dmqa*4I}Fj6B0&{3Rj-W_%?zd)p}OPXbM2v_$U} zm}+Slkc@|u@NLMh#i#~ptTZ{$Xg};5-b#K6YO53q1a{G!%4f^;EJ54pbHjTC59(rDV_6DA; zXlmC#beQ%huF4ySarFol*mrV3Qzl1C^ zvg^9$FpMrB_!$~YAi7P`~=s+=mXnAtXeS-y^{l|ev>N3KpXn_-wpTjyK3w|=cl z3a4G`^XrI^g1i8xIOvO_dIfGO;dGQSj$&HS9)vrRiia$B`-XzwzgK^}hY(zSH8UT; z?X#Lp2G20e%2N9x>YK&Gq6Z_%p!-Ly;h0(-ZcsY=+$(8hHm15?wc32;%2B+5IC}`bs9{R4#?V7`m zX~-9($#C1b6|V)-{nid5nG8UpIrA{2e{3?R(Xg+>ZmJtotx$PXC=83EV#*gGNgff< zH0klM4xfOZvUgT?gmAwscljiZ9nWNk+@VCsA&2#f5ypfTW zRmw+lh==audqUa7F2D`r0YKFcEIfH@O5B zw&9BK`k2%yRE^55fpkzZm@tYQx1kvySWyu_uV}cheX^T)0isu~K_p2H#)1u)4963@ z2Z>=Vjl}KC2sJw+N2nYOWgk{Cm3+QDG*5&4ioUAlk&_K*VF=se z$!DnR27_iurE-?BmC{7=Sy_$XmPrNp9BhvJRDx0N50l+&OfU0gmpjt^x-iXD^rFN? zZXTT-LPGxBFO31!9`WN?NDaDh;NwyfMp_^Bg6DBd^j$=&W?=18=Lc`-?NW;}njFWP zaFTmk{)(Tn$Fn@A7sn+nF@avDNoRv=LOF49%lt@_Q+m+r#D;;WdwstjZK~HpabN;t z^CwSbu#p9Hl*A25lZ*u09j z>}SJD_wS3=+H0iSRyU5sh&ha(c0j8iejB^!LwJOIBV((Mflcm8m*Ts7yrF!d z#;y$o+K8+<%xy9n7G5&rRk~}P(v?>|A?jThb{(c5&d=kVq6mrZH^aNL;_OY(puBXj z%GIkX!nJYm3RrvS#)C4JePm)bc|h&($t*{%dE4?yD!7f8l@bSvo{VdflnFQSWR2GT zNj^FGu~tF3FPIuHJ8FeR5z@a&#D zT#tHx9LCk#hgN3X>36^Cn4s`H@D;{^qIf~EJgWt}{$-)gTwdv_1a=`o`A(i$vdvDU;0tqH zv$qS`rA#W$9GQltUym&12YNKWb4f*^h`zrnH(DQ0BvIO=(51o+T}G8inU-DBTY80* zQ{fk_`;@5ttW_Lu1ZB+#HRKNlyR$7rd2IV^+Ri_OVTa~mB4U%>X+j9#ryys9w+UZ*jiVFJ6dWKwoM5PcBW>fhe%OeaQabW?NML#A}RDBFSg} zHjb%Ha*Z+ugu2rH*9Te^AepEzDtSkrZ7WZ+>Y1tt(O1AB`cKIFx$h}pe?z(NS3PyM zkDC-JH3gC$TEDJezgiy0j9-n+j=WEUXJxpo)!-0NKjyt1@z^X2*Xa7hzeR)E^SsUa z!yHFLAvzjNXZxY9`)JQT|j$Qr$ON9Sli_@at22ybdI{iudTi@V`^Qf)s zR#7S9G+izIgy)c#?_dU)R);`H8RKLy3dze)*fVTyNfE&-hp0kS=7ma@yC+%~t(S!h z)8n<}mD6Sl5xZ|bhg?CS=xo3)gcJfPi`kk;LwBMUstQUzQJIkKph`TslH<>3n z1GYIW>d)aVG{lz0l)&%P1_jy7&i*at(W@gs1AFw{dgAd(ruqj6TN++! z=ttA^JIBmkr_B`YID;CxL(#O~!@o=e2K6F56cs9}N#Kus-#23$*_7Cp&wjT*qY{1y zZOAR8p6Veb@TTTj${0g^_r~?c_ghX}S^A)~L74a|y`LGYK~{3Dk4MaZ=A(2kkDS{w zp5(=Yg(n1^LW#cLYOrqKzBM!#IRV(03yF#(eUVIcclz&KfSH1aio(*?6rVz5x(4^~ zw&$G8;@)X-;$69m%?@U0QS*Li2?>97FozHE03D;1p%v>d;w`*0Iq^1TL?j{uc1DM; zr6B(G@@#yDfStk+;GWh4^#*z6?w98$=t9h)^!KN577(l*ysvbgWEmKsOSS{89aarX+pY!1c2Wkps}XewsW z+DYB(uFL=RVR3H)xxVt^uhIi`TQZ}}_hTXTx zly8)2Kc=3K5Dd0qD_^D>h>4VuW~N#XJ0qGu!9$dZ;$zB6uiBq+;kPDxcz|R0R(UsI zP*(@?jHJ=6h4>!9gAAvy?a#uT3laeZqI zK2od$e6c^;c-mCOi|u@se(q=Gjf)G}1M3GOVS9yK8q(pv!?&kc9>snXTSA-?^+pY^ zx>{cKzahV(x{?B~xTE)Aurgpi5_=XaK7%RqVzv9ci7ZEmAHs3%)@Rrvk7YU5HWYJj z27Y=Dk*#R1h0iiXe&ij#8JtfT(>u)j#uff#V0BQ^u;b_ z7gTQUbJu3EV=kKvJu_y2ZVBxJuwDrKn<90BuueYqzQPCHOTy=NGIDRG*6e|tiEVF4w&*e8?3!fj2NT>Jmr_%P%QS7U_1>VJ|*(8&)YEy-)@!< ze`HR}+bBZz|0F=1+OZ3|-5EdA6?@TGMPK_VRCuDoD#~_Iz`WS^+yBGL02Y`% zb;YXdv(yWsE($N}RU*RfVzoub+&|esqKt?B&q(#?1W4L$)PAzlc@|GkvB#?c$gg7? zE)rd^OuW{6V|=Rb0kp!U_C-SNYH51&;hY9+lxQguaPOl7l!8gbA zkt?M~uFo_(hO|dyWJiFVKgCl6#1phoB1igM+W%*>dsUEB?AP*80Lm^F->cmHV`}l7 zRH=A4-|oPmxwegG(w;B!jnj;nBNZU4RQFGMm#Z!|IyT09AA;G(I^4}WkEX^Fs@eI* zdOiMLXC*0%^J%CHYHZ#XpwI%(6T`AjjrO8#d(Hu>Re086)c5x14?>n-n?@UWTS06| z$e>lpL!*2Gf!h;Rhr7@Lf-akmP**1IpKgGD+*q{)Lt^H=o@&DHaFIDp+x2(P({YRi?<_0b}% zh?bU?Z_Tgg3F5sAJeiQ?if2H*L7m-8w9VLuijyp z4GySZ_h0MbzpEJb>*wUUZodeY;lCJ7>FZ~979TQ7bAsRzY`037iBE~_b*jjmBNOk! z%$gluCdzL~yddryTH|aZ2tu!yNm1t3Rf^ddJ+eKJT(6%6DI*KVQ)r zy#C0Z7xo?ceM=4R_cc?{6O-h;4$|yPuueEJv5>n{4^O0dVtnneFGWG;^vCVRCMbzq zr)J^6)LA&Q3B99=sl?NoqH^rnRL;Gn)w`Bw*R_OW?&x8d7vuquxR#2-L0WagAop-0 zdCo*-!GVT^s^dmG<{I?e4?gyq%PzPY9zVTVyb)d0IigblAZ~kJ7?^RXO8a}9pkEk+ zi6n`ND*9z$hE?yw(7w(b@!v&@QhuWOO8vJ16FsORI_1#ncsdzU8_ZAqfE7~ z=aZmS`M%ds^F@)kp5|!zu!V^(Z-zjcj+G!-E~9XV!+@nq7e)duR@lt|L(y?PH5?G+ z3CC>XLdNEsZav6-dXgX;&-JXMXvb!P4LMZh_+4g=xA|5_%)+&ii>b+LU$Bn1Bky9M zqm|o&wZ2B#Z*Fs_!`b%^pn~Tx^aM%(j-zHs%uwagh#Hp404<~ zqNl{mnrF!OrlV$KAi9xb31C~scy;(}*^w|h(8Qmvn#um#OA9&pbT{j%R8z3c!GmC8 zy|AT1MWknq_zB#cY?9sbJLOCNlDHMKP9v&1+MFdfpDibSinBPyd-_O!Rf?I>Nw)b{ zpU*^^t6hEatJBIdoHiVX5pA9#f`al#1sg}Rj&67FPqHi5PnFnv zkLi22_Vpb`=^K+wDm(oTdG&i(e*;fS={M#JOT_7I@MU#oVM3d+DT={FnnbQW6OFaEpEf1!S+ZNn+H%QppR#e%L{Q=y05-@(WtZq4d>Qr zS|z+~&dMc^iMvF4O>HYT~p$8fb8GP1SX2p=15lUDA?LBYNfnXmVS1 zRx@Z$KhqF^0nnYJE4_f*&TbaXK%;m-RJSyKK77Z zuk(lpEt&T^aIyc?UUr#5AjiD2nF@S#evJ9$MH?I>1Gf9Olb$QTR(zcyFpO*$A#HJY zWMOc6x$BeqN4PPrx7@CnOs#iTu21-j>iDfhj&~zf>Kh;7u{sEk zj;gLs_z{xpxZxtg?7byGqRRH*95_N!+%!rUT9dJY5P7i9#$seDBU3$w!Os^BeW`lutG=&89q2^ zWUh-?7&pH;?Sf<4(AVhRg^Bo&-t^TIOXF1%G(tq8d=5R{s`tz$Ui-HPcfiw>e0$%T z#_+%oW3vPjQ0B2eDzX(z=e_(s0uAASixfoPyPj=eHRHz3p6yJ613(wKnD4S zy2gchP{$_Y7D6BsFYBGIQGWHCDLQQ=2K#4ix!zRIfRSG_{ZsQF2y<@n#XFBE4kvaO z8CCecQXj45y$TQ$cb}tpXkeQxQ&D9E20g~pus%v-KhO`M;TGajcNXM*7OpQzyR&pn zRsVLcVrL^8<~%xGUvV%8d^2D@#Y~B-L4b7tGcbjS`XA0qI;Fq>ySoeyb(-UxZC^m% z?{cu|^W1g`9A#S)#m!=7UBuSX&(qF*%aSVoB6! zSVG7)TGD8y#ve?-pARUW zb&q}#f^F@aHOxMtQmJiEI-K`Fr0G*U2>-Ld{p`**i7YsgEiv}&I&X>>9fs?!DcQ}}KHt(B%EGdNK>>waH zQzOqvic(-p`}nEaMV5l>ymk#F-aC**;mLRUA?3ST1&t}{+mOmgJHwcXn2+%!2&OH8 zChRjFagFLnlT(z^-1DVc|CX2HNoLt{VS5JyJYI9K6U@j|rO%l_PKVUWWuLoYLMmc*H-sA!oZ(}xc z(o|v-tt;&ziTgG(T9Ug}LcxjWG%OH$AKTkHQ8zu)|0>cTMso;;eYdH>G5k4SWDrK! zwFL{Po2`w|_^ex&Ue`mC3t%|EU2(Z!xu9-joC4wd+Vysh)`d4EYn+nyhcMChF)~;J zTqnkwlUs!pEw519Sd#oYZ}mG^S>lU;`6tp*+aC+tHX)HW#6#&V4dn`t#`)0q%DCQB z4J$U!XZ?X9)yCr^GW4XLzozetB@g{y4BDn zmN2A(`P@kx*?7i06bGA%4Pt>^;p@y7IEX#IfWM#H2X_>7y^JAAr9mecX9|MQC~TD) z@VEsV4R^#(x_#gwgL1MDgSUDPKX5WE7$e&k;JI#PVZ<*3*`#f3PY+zbJ;O)z^bXR3 z$KMwP7We7*wrT*XACxZ~d&Gl2QC z8c}g#t@bfDZU|PpWVXt!HAm>;l0M+NV3! z+;7_1aT!ckt>}JnPxn_8{!i`7s`v80`S@q*@osy%*dPx z-uMI{q>##75G{|hXiUgUhNG$a!j#CoF%5rXd@hV0jN_=%L0h(E4b-ZhtzyOCT3~1w zYDcNKaqtnv2H-fpR%sPIFJ`Z!sAH+atRu=K#VKlRzb)nBoYQP8Pk}!(p*j`v{{F;W zCwzA2jfgOw`q(90-6dpw=K3y4xx#F$NPnx@$cp?hY#qvSqo|_uhaw!uAwJ~rm1F-Qr=DqZjbJ^bFZXNR7$Z${N&%yIdn&dVb;iT(lb^& zCN6kJVe(>ttry*9Qp3=EFglCyU)(GToO#p7`n+(Xvi!!{fhTnfiwG&z&wq-Sn^W^2 zfwUIa0IHs=P>y^*d*S`J207(ok;y9Te@;s#LbV7O3cyAISx8f>Y0QUjllT~jGIxw+ zJ=$P*j_$BH?Vp1TxO)X)I!=8tHpXinR51bC#0rzu736A7#4?(4p(3*SZ2?bX_DM~j7iTIN#CH#zN~6a0Pu1G=2Q_vIsSQ5yw8xz z;(L(|s||~$84?QffQS~8iMO2z&Tb;o6xFmR!d=9k4A<0?Gy&s(f;>($qPt%7mlk{& zpar9OqN!l0utri@A=O&kv3bxR!-((0tVD)ltyurbTvU|AQlj0d&m9Sv5Q{f{oZ{(P z2_iovNdn=wlUVYH7`1Me)tYd&-bM#3*ew@V?KT0Y9zfTa^$mfG1s5<#=(H*uYE@M z4m>4wdYrfIT)W_eYWq zgA}H$XBl?|UxAhVUElHc){~x?b^vp19K>6>181l2ehvlQP2VNag2f{>rW=zMijdi~ z=@3U{i5*NCkbbh$28or;ENx@PGFeXHbF^N0UT;ffu;hjrqAP=H{{%(Erd9H@{l2k^ z{>s4jda^z}t`v89IR^8o5B9-y+@gTsl-+fx=b2Q(XnN{0Za4MZ?*aIrt2eOugA`hN zD6w=N;XP~brWv%jDDLoxhO&$MbmenO%EGQh?%t^O{gd?7;)(pE1W=S4@ql?%TXtQQ zBK!}Kv+Ig?O5ysgnLkHML6Rh2sJVEJtxieCd6MTcdyuZ~Ao=W9=cXN3f;5 zao2~hstoZf4vumDi zXJvIFPrG8!)jc4e^po9sS$X;Hom7XzBHt^*{@I|s>*i)3?D|DsCzx$^go+iA&~7=hKN&<_P~p}fyVG;)@UGj)#d4$d&&v{Wmf zb*rm8XGUaGc&=kX+T|kdhax4f&KK)_FuQ!m`C0z7_ewx5s0K|j$ujmp{s|WW_OsGB z44}zzk&@X1Mf@#Vgjt(#H^;+iRFse?Qu)vYSMmYz`nTh@3kxSF2{qInoe9r=)#K_| z1nISx(JYHS)v1Jp>BnUXLLX&o2|zCMKIK(acnN+6wEpgkE|Z#Y5zC2-2!mOjan*r~ z?5uW(h8j1WrtS^@!~<~g#fshg6gsK^jg_eLBc3u8$%Ps5$MheES}m?)y$-r;ZDHZ=QANdJ+U$V$-DLV_A&=w5Kc4H2 zwaLk=48KoM%XF~eT7P)WsSwBz>67chgSs15xoQEl`M-JBjv6WNz>e`r_~odhXVHus|W>A_ zw_ocN@sSFmpqD(}aE7!;@5KRqw*6V&D?9J*ew{n#O-Uv^&p{Pns0OaSn)nlR_IJsm z<$pw@5iRvLJ-V%nthsr}Gh_-lUTQ=voSj4=t35keJ6b|Ygu%_BO>GWi^KqlO`I?`n9BAI(=*t_^-qBH9{QejPL{=f|3i+fy z!G?s#+qom7E%jpzd1pqa=$E|Li}Q_TF(aLEbHSceqFlWC)aBUKq$FAVU|^uA_IJFs zipuC9w_HVS^sR}Tk$>4Pxe-iXX)*WJ4Gd&8sS?lIMVi+eixfQ83Vo2#$jYj0jMeke zX@#d>H;uR{^qzLFMo(Y5x1!4j$q` zR#q_J6A<`>$!$nNbFoQvP6BKAOks=lE7;7@^cx^muajXGD2`!A%&&ILAp6?nRM_6u z*{_)aVQlG)mAX}#yQ2ko%JTpn&E|;rEv#~UvY_Y5EMIkC*`0LhMxI*EV7TkV!`8nAqfYq0nHf$4Nh4CWiEq>iy%SPbi$@C5H#-QehtdTxKp6<` zVW(U=lYq*O^~CSC+qXh!CE7K9mI~iQXLlw%{eTDcoB&2BMn00kx1qVW1uR>=oQ@Tn})4E?{n6I$4kBQ|R#c z+_i$17VO_*%hiepBpOv*W_SJI482QF-MK{6gN_+9$OC9lZ*0B`L1*CPylAbi>7h;# z3}QAZae>J&I~TgZ7-}mHe+`UR&R=07`pg1M>?y{cgU@Xpn%V=rdNBF3x?k+KrR6YL zD&smcc!Tp9_asOgmkvp~!i_?#qyGzctV;mXcd`aQ;IiWumh6b}8@2kR?U;kQ3HhV} zOxXq05Mh$={8?QH8V*#98a&P>POU@G6=sC7nx48JX0%;NEwRC8(I`N8&EDbiMB+YJ zX`Nd%4g2|T-?l1FxN(wp77I6sK4!#f#z(}HLkvHF3d4L3D95AVU?`p%=O*=f zw&}4iK1gg|?w2Wo>8q7=h`^vLp#&z1KN)%E?dm1ro%0eg67b=7JLcwVANxKNWxQ5p*cOOABBCc*#rF+`$8%y_N0 z5P8m@pZ7l>weAz9r%jDoGt>nNcOg94rwA4?7YQC#Nzhv4JLA^h$=pE$Edw>ZBB#<- zf0KjUB~7%O8pP46+uT(ppM=D7`FYPg0oQnyU76|;#Pskuw(nAbQsn?;quBM37faq* zN^1`VvHW&@8n9P5PHxdG&TJpi2fiyXAV zkzcb#ADp|CqnAO95j9O^EPICG|D*$;U8>LOJ!QlleQ{Ul=%n` z*P3}}wYw&D=0nnCikyC#>@T#kKKCS3i!1!|-jJY5>Hd)@({;WevgCFB{kKE*iaF|u zXHD!J?rvJYl$@=E8!Lb1_;c&zx9kT(U=4*&oh50giXuhwLY%*Sr z^CE_8RFA|LXO-l5ImYvex3EgI?wKdubuHIeJH?{J*3GoFIVAJz0~MLmPnoy*&#uWm zaoTA2Q_X!pd$W&vQu+1T1VRHDF(9b;YtWob`~0kwa1x%hxV|5;@Lq^zU9Ruj#$Dv1 zgRD%eUDjnyEWek_3%wvJ%;=!QrUfYzyi@WzicfgQgyWdsg2>+3+6@LKO?`CI*}Aj~ zatLCTF;RH^D^)pL?b-n{IwdS{UI3Vs}6 zF1dl*cO;wF)HaXSSum2%t~V{6`|3y#QP$CZg^RkS|5j#Y3v}ay(fclGI<{}bYK9w! zeoCf(Z4@LXeJgV(T0bt`2Pspsl2KlPWmsW664ep3!0W%m+Sw zr^&qm5n8Vv1h{(H^~j3#(mj86U{q)4jti{+yqRN-_}NWvu2~Stm1JC`(AfOO|IM9g zVVB;U@Q{rRPyCw9@aBY?57qWY9`A((3ZR1}lnFEwY_; zl1OIi*bDLTo!wg@?oPKY1~Ly-1p=rC(}|g~u+G5GwXEs~yrGt_kk=8=Lh^yHbDEid z$x@h1Wq-VK7$ZEo#Ik=&p-<(g#IoW^CiRTkgmpRi*ldsNjyu{?glJl zq8ob8*?uVF7XmJmtX`Z-x{Y{~o>DFAS=X>c!aBt1)8if?VJ}Vf@Q>4U;8;!O9Vnxy zqR81=zJM}Y^Iw8#@w#LYWbk6E(Dd~`U-0Ou>V3Zii_%m}K4$n0%en^BCcU!pXE`!N zl|GY=Z|g01B=e}C34--qMmo#nKSHMxvG`wno(G^NRKd6$T#nIU)~;HijL$sVvZt{? zbrnKw%lof;?up9?)LDtuhPFs^A}m2JO7uW{oF37Rp>j1+GgM+EGT0Q1z)G-|6?`p+ zct1osSRxhhayn({ZIe1LPSh0oKTRv`e{B|nIm)CA-c5IcO#*uO^vPdyc=}j40^qSd zt(*c}dCH{3Ckr$iwN`0_O+~@+qZ1)dd_KK$M;f zHPQ_tHzZ=w$~4bC%`y{e6@cuv!oD{R+f~D~_<8?;bGz>UZd(D0aZd>xe_)99P!jsX z>VF%{qshKx{-qgz#WwC?Dpg%=16lpaU*M~6`uQqDAKHfBA+e&gTGv$$*MB>aXgkQH z%6gH1NNmNLlbz8hD4xas@e7TH601I`v^d~nV7poF`$LTdKk`daDbpM?0_JiFahnf; zd5zYF%C$lb$`yuX07-WhEAG7JMz>xT}0u*(`I_CfsYXTJGv_+I~ zZn*XF?+4yi_mOc&Ae#mz6&ej5F%Ji&iS2$}p$d$*0aRN4S*5ML-srV{xS*bA^Ut07 zjS{!&mn+saXd00yO{P6*Wl-)fuP)as!cI7pLnvO@A2MzXOtDC7!eQUi3vutJD#YJ2*{B~7UN1C@M^xknMX(6wNyIFlS&$C%J`PG!A7LwKSm>6+6))?XPWx)F) zNL&5U=zV|DlOV-dwE~IgOy?;|KxmV|<%Y^7H&GYBK>iz(kh#G(b|_@Z$Hw^o_{yf@ z9p9%ChJ(g1@rt->e+kp^l9WXiDP{fJz|xm z{v2U(fog~s#9K>#@RbQDKpn%3lvYlszWw5?6T3!$;w8nafq_5vVZ|#Kv}q`B@4lf@ zm^2V{LpX|h>7yaqoVtt{*Kd0cYt-S(`n;^{1FZPy9ED?1Be%T{*(0US0dc6t)fORB z99#I!|2c4&3GZ-=4gxU zs$$&JV9M6pyWKkOdz*n{E{6AZ^_xN)T9;SbDJIRiy`0@In-$wx6w}$o2v)u`LKq)viM#W1J>{ugA3EG;g&h+hqs-$USq)NO~Ys@XM>XJSrN)fxLM5bxHGklbDy1 zJya;vNw?1SvJ_+T#ks*(yW`1JzL*1pD(q?1ZZ`EPhl5P;KpHCcqBh`lniDMuq`rrM zu%LRUaQ8XpYdyT$U`d9H-{E1DG`!#ZzYeCy4UmH*8cqI08NNK7?Av|=y4^6KPYCuM zN?}4B+x}A6alk{<5`17~m~OBYyR?3f1)PbH$9*CPk0;PQiIN$AK5f0o|`qS`BQdIU@4*#rrvHjYWsyfBxv z=2tOGk~+b|NhCCWYrTE(YW+^)6WBmL{x=&;lsgn;H-CuruN*|pM`>pZP{Tq{TgIU9 zDu5E|-R8cYGG`ly_KU!&7b1It4WZ*RG3=2S7;K7RjSy}!`4wEVN!=X){V^;1*3qa3 z{Oz3+REKg)WwD?QX>&t7NIUC`g0sV=N@@0y+M)`eu+9mW#}8;c#GBN&PkYBXm zOiLH(U^|gLUj0rMo-3STqnuY_XxB`k8w?MwH>1(#KopwwLT&yiHJ4F$j_0P5Xl;N` zUdM7K2y60!hgNSDn(B*+5J%!zBeW2kg|&A>&$b*y7oSOCb~IA_%IWD3lnxm8U>Zy> z(WTMgBqOWMXY#~SA}*&NHq7HTZuCIKpM!7yl7l#P>wN#F5YwG-iOp?qcKxW^3fUd= z*^!_ID{phjH3i3~)hx+veEVRuGhzEOg7^14_O<&3Gk94{iL|=UML}kzKI}vCZFVsnu&7xSMof zy-3yw`mA2Fe=y?OfrOQsV%BIHm*0!v>yZqZ?c&yT^WTx|{M!Y%x(#MdJR%h3_fcbQ zP>fUU?pd*e10}4m)uS|)JfQzWIwwi{p^(-spI~p!c?O+FVEAZP}k$8 zFOHp{=t9=F4H6QmQQnD8rc!h9SB`OvehuF=YqP0sV@BwdNX1?0^PI_jNLGTp9J)~D_!?h}S|ENAu2^sqGdA-E zlxJ(yu9g@DY(r|*wVdB{645D+Y=)ozf#&U=+i{SQ{hn^;U8GGSK*e*4AY$sY6<9GQ ziCD5)TJ_d<4S!IcwBL>E(ranMmZ+=}4$5Ei~KdIlM=TB!6T9;=S#rD%O(>2l^4#c3nvKiaxz%xbBC$ z+_WT`Zmp74f3D-VnAHs)F8JYC*1zk2tNxuXC15Wm?}pbb;z!EV8@B?mCMDv);1>ri)^G+69)*8_Z)+BGM zNtSD_hg0B0Mfj1#T8E3zhHmTSP%JRA+g)W`9W0Opo_MS}ZM&eHuas7e&IFQ}e#zt} zUiv!!U;*NjhD81F*>erx&4wON_Hjj!;XA7{5x*d+>SlDX@)%0H3#N*~+3glyyVPtJ zH)&NH;P)wAtb;47TkTJ8W%3>rifSh_Zm`h&?vP{VWwEbapRr?Ae|EQ1;RbvYp7Y@$ zltrjEU+<6?Jo)%GVPwlktO(|ANJ^j02d~rC&%U|uQo>U8OM@oC<4pj|3Ie>4< zwW@V8Rz&s;V%JjV(yvCyK|EsX*0Dayyt-ZK0lnt}N4*cJX~w?jftN=M7v}^|SSCv| ztbnwWnPLK{p);M35Fp*(PV5d|5AcDt0ZWx>CleHaYdc5!cHKfU_aoN6_nWu|t`n2G z_y4qg&u%R5FGoJ2`TPDpTlHFTa7ONd*2fG{2Hc?GPHtyvh*R5s8y7Zakb1LsRLj4) z&wrTZ}2@IG-qgkl7@Aih;ZpQr0007r6{o*{YA%R z%=~wR(#Q+Mk>}3iU0F@dRvGx?qV*!*YfcO2nR1yD*SAZ9H5Dq%a~n=aSAYCY5&?rv z@+fIPPAaaHzLIn&t)Fb+z+l=$x-T|73EuqYZGX7&@1{fBAq1F>jQ|Ke%K2Wm)Ich|LF|DC8=?4(_p0pl&P|idbCBM zblrywQjcPwEb$9d2)SVw*`gjP{Ww)g17sd;yuxkQYUjXc{t|2V?<-ND0lyB@%Li3a z{L>4dnzZ$pT#r*OJzrD66UjL+9yMq_*y`Pc*iuhGUS6P2@Pw2V&?C-))iqqtnXhEK z4r_We+vQiq)_Q56BvYhIzc`I{bY1WddH2N%xWrA|AZ?P=k?A*ig4CLhFZ2sVk%fXU zp>6%$Ck9<+om*Rf{^yt^a|#l_iGa#`0KYrFihB|0LK?R9Ehju)@q#>@h0=h2Kx}F8qb@tMi`1mg3&M~9 z&Cb&lI3aBv57Yq#D{6Fu_xpP8&&LY$ZQ>0ve;eYNr@O2(B{=4X{My>z&OYKPxSnXY z4-8jKk=+o3>yzDR(MRW;X7qDYu;+c;?>638=yBM_M*&+DG4=ocD^Yon84=Lu`FmD3 Sh58^a+J|?lpqjTP!T%S#0aFD4 diff --git a/openssl-install/share/doc/openssl/html/man7/life_cycle-cipher.html b/openssl-install/share/doc/openssl/html/man7/life_cycle-cipher.html deleted file mode 100644 index bc9b30d4..00000000 --- a/openssl-install/share/doc/openssl/html/man7/life_cycle-cipher.html +++ /dev/null @@ -1,312 +0,0 @@ - - - - -life_cycle-cipher - - - - - - - - -

- -

NAME

- -

life_cycle-cipher - The cipher algorithm life-cycle

- -

DESCRIPTION

- -

All symmetric ciphers (CIPHERs) go through a number of stages in their life-cycle:

- -
- -
start
-
- -

This state represents the CIPHER before it has been allocated. It is the starting state for any life-cycle transitions.

- -
-
newed
-
- -

This state represents the CIPHER after it has been allocated.

- -
-
initialised
-
- -

These states represent the CIPHER when it is set up and capable of processing input. There are three possible initialised states:

- -
- -
initialised using EVP_CipherInit
-
- -
-
initialised for decryption using EVP_DecryptInit
-
- -
-
initialised for encryption using EVP_EncryptInit
-
- -
-
- -
-
updated
-
- -

These states represent the CIPHER when it is set up and capable of processing additional input or generating output. The three possible states directly correspond to those for initialised above. The three different streams should not be mixed.

- -
-
finaled
-
- -

This state represents the CIPHER when it has generated output.

- -
-
freed
-
- -

This state is entered when the CIPHER is freed. It is the terminal state for all life-cycle transitions.

- -
-
- -

State Transition Diagram

- -

The usual life-cycle of a CIPHER is illustrated:

- - - -

Formal State Transitions

- -

This section defines all of the legal state transitions. This is the canonical list.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Function CallCurrent State
startnewedinitialisedupdatedfinaledinitialised
decryption
updated
decryption
initialised
encryption
updated
encryption
freed
EVP_CIPHER_CTX_newnewed
EVP_CipherInitinitialisedinitialisedinitialisedinitialisedinitialisedinitialisedinitialisedinitialised
EVP_DecryptInitinitialised
decryption
initialised
decryption
initialised
decryption
initialised
decryption
initialised
decryption
initialised
decryption
initialised
decryption
initialised
decryption
EVP_EncryptInitinitialised
encryption
initialised
encryption
initialised
encryption
initialised
encryption
initialised
encryption
initialised
encryption
initialised
encryption
initialised
encryption
EVP_CipherUpdateupdatedupdated
EVP_DecryptUpdateupdated
decryption
updated
decryption
EVP_EncryptUpdateupdated
encryption
updated
encryption
EVP_CipherFinalfinaled
EVP_DecryptFinalfinaled
decryption
EVP_EncryptFinalfinaled
decryption
EVP_CIPHER_CTX_freefreedfreedfreedfreedfreedfreedfreedfreedfreed
EVP_CIPHER_CTX_resetnewednewednewednewednewednewednewed
EVP_CIPHER_CTX_get_paramsnewedinitialisedupdatedinitialised
decryption
updated
decryption
initialised
encryption
updated
encryption
EVP_CIPHER_CTX_set_paramsnewedinitialisedupdatedinitialised
decryption
updated
decryption
initialised
encryption
updated
encryption
EVP_CIPHER_CTX_gettable_paramsnewedinitialisedupdatedinitialised
decryption
updated
decryption
initialised
encryption
updated
encryption
EVP_CIPHER_CTX_settable_paramsnewedinitialisedupdatedinitialised
decryption
updated
decryption
initialised
encryption
updated
encryption
- -

NOTES

- -

At some point the EVP layer will begin enforcing the transitions described herein.

- -

SEE ALSO

- -

provider-cipher(7), EVP_EncryptInit(3)

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/life_cycle-digest.html b/openssl-install/share/doc/openssl/html/man7/life_cycle-digest.html deleted file mode 100644 index 7cda7d85..00000000 --- a/openssl-install/share/doc/openssl/html/man7/life_cycle-digest.html +++ /dev/null @@ -1,227 +0,0 @@ - - - - -life_cycle-digest - - - - - - - - - - -

NAME

- -

life_cycle-digest - The digest algorithm life-cycle

- -

DESCRIPTION

- -

All message digests (MDs) go through a number of stages in their life-cycle:

- -
- -
start
-
- -

This state represents the MD before it has been allocated. It is the starting state for any life-cycle transitions.

- -
-
newed
-
- -

This state represents the MD after it has been allocated.

- -
-
initialised
-
- -

This state represents the MD when it is set up and capable of processing input.

- -
-
updated
-
- -

This state represents the MD when it is set up and capable of processing additional input or generating output.

- -
-
finaled
-
- -

This state represents the MD when it has generated output. For an XOF digest, this state represents the MD when it has generated a single-shot output.

- -
-
squeezed
-
- -

For an XOF digest, this state represents the MD when it has generated output. It can be called multiple times to generate more output. The output length is variable for each call.

- -
-
freed
-
- -

This state is entered when the MD is freed. It is the terminal state for all life-cycle transitions.

- -
-
- -

State Transition Diagram

- -

The usual life-cycle of a MD is illustrated:

- - - -

Formal State Transitions

- -

This section defines all of the legal state transitions. This is the canonical list.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Function CallCurrent State
startnewedinitialisedupdatedfinaledsqueezedfreed
EVP_MD_CTX_newnewed
EVP_DigestInitinitialisedinitialisedinitialisedinitialisedinitialised
EVP_DigestUpdateupdatedupdated
EVP_DigestFinalfinaled
EVP_DigestSqueezesqueezedsqueezed
EVP_DigestFinalXOFfinaled
EVP_MD_CTX_freefreedfreedfreedfreedfreed
EVP_MD_CTX_resetnewednewednewednewed
EVP_MD_CTX_get_paramsnewedinitialisedupdated
EVP_MD_CTX_set_paramsnewedinitialisedupdated
EVP_MD_CTX_gettable_paramsnewedinitialisedupdated
EVP_MD_CTX_settable_paramsnewedinitialisedupdated
EVP_MD_CTX_copy_exnewedinitialisedupdatedsqueezed
- -

NOTES

- -

At some point the EVP layer will begin enforcing the transitions described herein.

- -

SEE ALSO

- -

provider-digest(7), EVP_DigestInit(3)

- -

COPYRIGHT

- -

Copyright 2021-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/life_cycle-kdf.html b/openssl-install/share/doc/openssl/html/man7/life_cycle-kdf.html deleted file mode 100644 index f6b882c0..00000000 --- a/openssl-install/share/doc/openssl/html/man7/life_cycle-kdf.html +++ /dev/null @@ -1,147 +0,0 @@ - - - - -life_cycle-kdf - - - - - - - - - - -

NAME

- -

life_cycle-kdf - The KDF algorithm life-cycle

- -

DESCRIPTION

- -

All key derivation functions (KDFs) and pseudo random functions (PRFs) go through a number of stages in their life-cycle:

- -
- -
start
-
- -

This state represents the KDF/PRF before it has been allocated. It is the starting state for any life-cycle transitions.

- -
-
newed
-
- -

This state represents the KDF/PRF after it has been allocated.

- -
-
deriving
-
- -

This state represents the KDF/PRF when it is set up and capable of generating output.

- -
-
freed
-
- -

This state is entered when the KDF/PRF is freed. It is the terminal state for all life-cycle transitions.

- -
-
- -

State Transition Diagram

- -

The usual life-cycle of a KDF/PRF is illustrated:

- - - -

Formal State Transitions

- -

This section defines all of the legal state transitions. This is the canonical list.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Function CallCurrent State
startnewedderivingfreed
EVP_KDF_CTX_newnewed
EVP_KDF_derivederivingderiving
EVP_KDF_CTX_freefreedfreedfreed
EVP_KDF_CTX_resetnewednewed
EVP_KDF_CTX_get_paramsnewedderiving
EVP_KDF_CTX_set_paramsnewedderiving
EVP_KDF_CTX_gettable_paramsnewedderiving
EVP_KDF_CTX_settable_paramsnewedderiving
- -

NOTES

- -

At some point the EVP layer will begin enforcing the transitions described herein.

- -

SEE ALSO

- -

provider-kdf(7), EVP_KDF(3).

- -

HISTORY

- -

The provider KDF interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/life_cycle-mac.html b/openssl-install/share/doc/openssl/html/man7/life_cycle-mac.html deleted file mode 100644 index c482c72b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/life_cycle-mac.html +++ /dev/null @@ -1,191 +0,0 @@ - - - - -life_cycle-mac - - - - - - - - - - -

NAME

- -

life_cycle-mac - The MAC algorithm life-cycle

- -

DESCRIPTION

- -

All message authentication codes (MACs) go through a number of stages in their life-cycle:

- -
- -
start
-
- -

This state represents the MAC before it has been allocated. It is the starting state for any life-cycle transitions.

- -
-
newed
-
- -

This state represents the MAC after it has been allocated.

- -
-
initialised
-
- -

This state represents the MAC when it is set up and capable of processing input.

- -
-
updated
-
- -

This state represents the MAC when it is set up and capable of processing additional input or generating output.

- -
-
finaled
-
- -

This state represents the MAC when it has generated output.

- -
-
freed
-
- -

This state is entered when the MAC is freed. It is the terminal state for all life-cycle transitions.

- -
-
- -

State Transition Diagram

- -

The usual life-cycle of a MAC is illustrated:

- - - -

Formal State Transitions

- -

This section defines all of the legal state transitions. This is the canonical list.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Function CallCurrent State
startnewedinitialisedupdatedfinaledfreed
EVP_MAC_CTX_newnewed
EVP_MAC_initinitialisedinitialisedinitialisedinitialised
EVP_MAC_updateupdatedupdated
EVP_MAC_finalfinaled
EVP_MAC_finalXOFfinaled
EVP_MAC_CTX_freefreedfreedfreedfreedfreed
EVP_MAC_CTX_get_paramsnewedinitialisedupdated
EVP_MAC_CTX_set_paramsnewedinitialisedupdated
EVP_MAC_CTX_gettable_paramsnewedinitialisedupdated
EVP_MAC_CTX_settable_paramsnewedinitialisedupdated
- -

NOTES

- -

At some point the EVP layer will begin enforcing the transitions described herein.

- -

SEE ALSO

- -

provider-mac(7), EVP_MAC(3).

- -

HISTORY

- -

The provider MAC interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/life_cycle-pkey.html b/openssl-install/share/doc/openssl/html/man7/life_cycle-pkey.html deleted file mode 100644 index be134d40..00000000 --- a/openssl-install/share/doc/openssl/html/man7/life_cycle-pkey.html +++ /dev/null @@ -1,637 +0,0 @@ - - - - -life_cycle-pkey - - - - - - - - - - -

NAME

- -

life_cycle-pkey - The PKEY algorithm life-cycle

- -

DESCRIPTION

- -

All public keys (PKEYs) go through a number of stages in their life-cycle:

- -
- -
start
-
- -

This state represents the PKEY before it has been allocated. It is the starting state for any life-cycle transitions.

- -
-
newed
-
- -

This state represents the PKEY after it has been allocated.

- -
-
decapsulate
-
- -

This state represents the PKEY when it is ready to perform a private key decapsulation operation.

- -
-
decrypt
-
- -

This state represents the PKEY when it is ready to decrypt some ciphertext.

- -
-
derive
-
- -

This state represents the PKEY when it is ready to derive a shared secret.

- -
-
digest sign
-
- -

This state represents the PKEY when it is ready to perform a private key signature operation.

- -
-
encapsulate
-
- -

This state represents the PKEY when it is ready to perform a public key encapsulation operation.

- -
-
encrypt
-
- -

This state represents the PKEY when it is ready to encrypt some plaintext.

- -
-
key generation
-
- -

This state represents the PKEY when it is ready to generate a new public/private key.

- -
-
parameter generation
-
- -

This state represents the PKEY when it is ready to generate key parameters.

- -
-
verify
-
- -

This state represents the PKEY when it is ready to verify a public key signature.

- -
-
verify recover
-
- -

This state represents the PKEY when it is ready to recover a public key signature data.

- -
-
freed
-
- -

This state is entered when the PKEY is freed. It is the terminal state for all life-cycle transitions.

- -
-
- -

State Transition Diagram

- -

The usual life-cycle of a PKEY object is illustrated:

- - - -

Formal State Transitions

- -

This section defines all of the legal state transitions. This is the canonical list.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Function CallCurrent State
startneweddigest
sign
verifyverify
recover
encryptdecryptderiveencapsulatedecapsulateparameter
generation
key
generation
freed
EVP_PKEY_CTX_newnewed
EVP_PKEY_CTX_new_idnewed
EVP_PKEY_CTX_new_from_namenewed
EVP_PKEY_CTX_new_from_pkeynewed
EVP_PKEY_sign_initdigest
sign
digest
sign
digest
sign
digest
sign
digest
sign
digest
sign
digest
sign
digest
sign
digest
sign
digest
sign
digest
sign
EVP_PKEY_signdigest
sign
EVP_PKEY_verify_initverifyverifyverifyverifyverifyverifyverifyverifyverifyverifyverify
EVP_PKEY_verifyverify
EVP_PKEY_verify_recover_initverify
recover
verify
recover
verify
recover
verify
recover
verify
recover
verify
recover
verify
recover
verify
recover
verify
recover
verify
recover
verify
recover
EVP_PKEY_verify_recoververify
recover
EVP_PKEY_encrypt_initencryptencryptencryptencryptencryptencryptencryptencryptencryptencryptencrypt
EVP_PKEY_encryptencrypt
EVP_PKEY_decrypt_initdecryptdecryptdecryptdecryptdecryptdecryptdecryptdecryptdecryptdecryptdecrypt
EVP_PKEY_decryptdecrypt
EVP_PKEY_derive_initderivederivederivederivederivederivederivederivederivederivederive
EVP_PKEY_derive_set_peerderive
EVP_PKEY_derivederive
EVP_PKEY_encapsulate_initencapsulateencapsulateencapsulateencapsulateencapsulateencapsulateencapsulateencapsulateencapsulateencapsulateencapsulate
EVP_PKEY_encapsulateencapsulate
EVP_PKEY_decapsulate_initdecapsulatedecapsulatedecapsulatedecapsulatedecapsulatedecapsulatedecapsulatedecapsulatedecapsulatedecapsulatedecapsulate
EVP_PKEY_decapsulatedecapsulate
EVP_PKEY_paramgen_initparameter
generation
parameter
generation
parameter
generation
parameter
generation
parameter
generation
parameter
generation
parameter
generation
parameter
generation
parameter
generation
parameter
generation
parameter
generation
EVP_PKEY_paramgenparameter
generation
EVP_PKEY_keygen_initkey
generation
key
generation
key
generation
key
generation
key
generation
key
generation
key
generation
key
generation
key
generation
key
generation
key
generation
EVP_PKEY_keygenkey
generation
EVP_PKEY_genparameter
generation
key
generation
EVP_PKEY_CTX_get_paramsneweddigest
sign
verifyverify
recover
encryptdecryptderiveencapsulatedecapsulateparameter
generation
key
generation
EVP_PKEY_CTX_set_paramsneweddigest
sign
verifyverify
recover
encryptdecryptderiveencapsulatedecapsulateparameter
generation
key
generation
EVP_PKEY_CTX_gettable_paramsneweddigest
sign
verifyverify
recover
encryptdecryptderiveencapsulatedecapsulateparameter
generation
key
generation
EVP_PKEY_CTX_settable_paramsneweddigest
sign
verifyverify
recover
encryptdecryptderiveencapsulatedecapsulateparameter
generation
key
generation
EVP_PKEY_CTX_freefreedfreedfreedfreedfreedfreedfreedfreedfreedfreedfreedfreed
- -

NOTES

- -

At some point the EVP layer will begin enforcing the transitions described herein.

- -

SEE ALSO

- -

EVP_PKEY_new(3), EVP_PKEY_decapsulate(3), EVP_PKEY_decrypt(3), EVP_PKEY_encapsulate(3), EVP_PKEY_encrypt(3), EVP_PKEY_derive(3), EVP_PKEY_keygen(3), EVP_PKEY_sign(3), EVP_PKEY_verify(3), EVP_PKEY_verify_recover(3)

- -

HISTORY

- -

The provider PKEY interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/life_cycle-rand.html b/openssl-install/share/doc/openssl/html/man7/life_cycle-rand.html deleted file mode 100644 index 47f5e488..00000000 --- a/openssl-install/share/doc/openssl/html/man7/life_cycle-rand.html +++ /dev/null @@ -1,168 +0,0 @@ - - - - -life_cycle-rand - - - - - - - - - - -

NAME

- -

life_cycle-rand - The RAND algorithm life-cycle

- -

DESCRIPTION

- -

All random number generator (RANDs) go through a number of stages in their life-cycle:

- -
- -
start
-
- -

This state represents the RAND before it has been allocated. It is the starting state for any life-cycle transitions.

- -
-
newed
-
- -

This state represents the RAND after it has been allocated but unable to generate any output.

- -
-
instantiated
-
- -

This state represents the RAND when it is set up and capable of generating output.

- -
-
uninstantiated
-
- -

This state represents the RAND when it has been shutdown and it is no longer capable of generating output.

- -
-
freed
-
- -

This state is entered when the RAND is freed. It is the terminal state for all life-cycle transitions.

- -
-
- -

State Transition Diagram

- -

The usual life-cycle of a RAND is illustrated:

- - - -

Formal State Transitions

- -

This section defines all of the legal state transitions. This is the canonical list.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Function CallCurrent State
startnewedinstantiateduninstantiatedfreed
EVP_RAND_CTX_newnewed
EVP_RAND_instantiateinstantiated
EVP_RAND_generateinstantiated
EVP_RAND_uninstantiateuninstantiated
EVP_RAND_CTX_freefreedfreedfreedfreed
EVP_RAND_CTX_get_paramsnewedinstantiateduninstantiated
EVP_RAND_CTX_set_paramsnewedinstantiateduninstantiated
EVP_RAND_CTX_gettable_paramsnewedinstantiateduninstantiated
EVP_RAND_CTX_settable_paramsnewedinstantiateduninstantiated
- -

NOTES

- -

At some point the EVP layer will begin enforcing the transitions described herein.

- -

SEE ALSO

- -

provider-rand(7), EVP_RAND(3).

- -

HISTORY

- -

The provider RAND interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-core.h.html b/openssl-install/share/doc/openssl/html/man7/openssl-core.h.html deleted file mode 100644 index ec78b638..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-core.h.html +++ /dev/null @@ -1,84 +0,0 @@ - - - - -openssl-core.h - - - - - - - - - - -

NAME

- -

openssl/core.h - OpenSSL Core types

- -

SYNOPSIS

- -
#include <openssl/core.h>
- -

DESCRIPTION

- -

The <openssl/core.h> header defines a number of public types that are used to communicate between the OpenSSL libraries and implementation providers. These types are designed to minimise the need for intimate knowledge of internal structures between the OpenSSL libraries and the providers.

- -

The types are:

- -
- -
OSSL_DISPATCH(3)
-
- -
-
OSSL_ITEM(3)
-
- -
-
OSSL_ALGORITHM(3)
-
- -
-
OSSL_PARAM(3)
-
- -
-
OSSL_CALLBACK(3)
-
- -
-
OSSL_PASSPHRASE_CALLBACK(3)
-
- -
-
- -

SEE ALSO

- -

openssl-core_dispatch.h(7)

- -

HISTORY

- -

The types described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-core_dispatch.h.html b/openssl-install/share/doc/openssl/html/man7/openssl-core_dispatch.h.html deleted file mode 100644 index 6f425092..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-core_dispatch.h.html +++ /dev/null @@ -1,76 +0,0 @@ - - - - -openssl-core_dispatch.h - - - - - - - - - - -

NAME

- -

openssl/core_dispatch.h - OpenSSL provider dispatch numbers and function types

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
- -

DESCRIPTION

- -

The <openssl/core_dispatch.h> header defines all the operation numbers, dispatch numbers and provider interface function types currently available.

- -

The operation and dispatch numbers are represented with macros, which are named as follows:

- -
- -
operation numbers
-
- -

These macros have the form OSSL_OP_opname.

- -
-
dipatch numbers
-
- -

These macros have the form OSSL_FUNC_opname_funcname, where opname is the same as in the macro for the operation this function belongs to.

- -
-
- -

With every dispatch number, there is an associated function type.

- -

For further information, please see the provider(7)

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The types and macros described here were added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-core_names.h.html b/openssl-install/share/doc/openssl/html/man7/openssl-core_names.h.html deleted file mode 100644 index 99c95bb0..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-core_names.h.html +++ /dev/null @@ -1,63 +0,0 @@ - - - - -openssl-core_names.h - - - - - - - - - - -

NAME

- -

openssl/core_names.h - OpenSSL provider parameter names

- -

SYNOPSIS

- -
#include <openssl/core_names.h>
- -

DESCRIPTION

- -

The <openssl/core_names.h> header defines a multitude of macros for OSSL_PARAM(3) names, algorithm names and other known names used with OpenSSL's providers, made available for practical purposes only.

- -

Existing names are further described in the manuals for OpenSSL's providers (see "SEE ALSO") and the manuals for each algorithm they provide (listed in those provider manuals).

- -

SEE ALSO

- -

OSSL_PROVIDER-default(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-legacy(7)

- -

HISTORY

- -

The macros described here were added in OpenSSL 3.0.

- -

CAVEATS

- -

This header file does not constitute a general registry of names. Providers that implement new algorithms are to be responsible for their own parameter names.

- -

However, authors of provider that implement their own variants of algorithms that OpenSSL providers support will want to pay attention to the names provided in this header to work in a compatible manner.

- -

COPYRIGHT

- -

Copyright 2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-env.html b/openssl-install/share/doc/openssl/html/man7/openssl-env.html deleted file mode 100644 index 9cb490e9..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-env.html +++ /dev/null @@ -1,255 +0,0 @@ - - - - -openssl-env - - - - - - - - - - -

NAME

- -

openssl-env - OpenSSL environment variables

- -

DESCRIPTION

- -

The OpenSSL libraries use environment variables to override the compiled-in default paths for various data. To avoid security risks, the environment is usually not consulted when the executable is set-user-ID or set-group-ID.

- -
- -
CTLOG_FILE
-
- -

Specifies the path to a certificate transparency log list. See CTLOG_STORE_new(3).

- -
-
OPENSSL
-
- -

Specifies the path to the openssl executable. Used by the rehash script (see "Script Configuration" in openssl-rehash(1)) and by the CA.pl script (see "NOTES" in CA.pl(1)

- -
-
OPENSSL_CONF, OPENSSL_CONF_INCLUDE
-
- -

Specifies the path to a configuration file and the directory for included files. See config(5).

- -
-
OPENSSL_CONFIG
-
- -

Specifies a configuration option and filename for the req and ca commands invoked by the CA.pl script. See CA.pl(1).

- -
-
OPENSSL_ENGINES
-
- -

Specifies the directory from which dynamic engines are loaded. See openssl-engine(1).

- -
-
OPENSSL_MALLOC_FD, OPENSSL_MALLOC_FAILURES
-
- -

If built with debugging, this allows memory allocation to fail. See OPENSSL_malloc(3).

- -
-
OPENSSL_MODULES
-
- -

Specifies the directory from which cryptographic providers are loaded. Equivalently, the generic -provider-path command-line option may be used.

- -
-
OPENSSL_TRACE
-
- -

By default the OpenSSL trace feature is disabled statically. To enable it, OpenSSL must be built with tracing support, which may be configured like this: ./config enable-trace

- -

Unless OpenSSL tracing support is generally disabled, enable trace output of specific parts of OpenSSL libraries, by name. This output usually makes sense only if you know OpenSSL internals well.

- -

The value of this environment varialble is a comma-separated list of names, with the following available:

- -
- -
TRACE
-
- -

Traces the OpenSSL trace API itself.

- -
-
INIT
-
- -

Traces OpenSSL library initialization and cleanup.

- -
-
TLS
-
- -

Traces the TLS/SSL protocol.

- -
-
TLS_CIPHER
-
- -

Traces the ciphers used by the TLS/SSL protocol.

- -
-
CONF
-
- -

Show details about provider and engine configuration.

- -
-
ENGINE_TABLE
-
- -

The function that is used by RSA, DSA (etc) code to select registered ENGINEs, cache defaults and functional references (etc), will generate debugging summaries.

- -
-
ENGINE_REF_COUNT
-
- -

Reference counts in the ENGINE structure will be monitored with a line of generated for each change.

- -
-
PKCS5V2
-
- -

Traces PKCS#5 v2 key generation.

- -
-
PKCS12_KEYGEN
-
- -

Traces PKCS#12 key generation.

- -
-
PKCS12_DECRYPT
-
- -

Traces PKCS#12 decryption.

- -
-
X509V3_POLICY
-
- -

Generates the complete policy tree at various points during X.509 v3 policy evaluation.

- -
-
BN_CTX
-
- -

Traces BIGNUM context operations.

- -
-
CMP
-
- -

Traces CMP client and server activity.

- -
-
STORE
-
- -

Traces STORE operations.

- -
-
DECODER
-
- -

Traces decoder operations.

- -
-
ENCODER
-
- -

Traces encoder operations.

- -
-
REF_COUNT
-
- -

Traces decrementing certain ASN.1 structure references.

- -
-
HTTP
-
- -

Traces the HTTP client and server, such as messages being sent and received.

- -
-
- -
-
OPENSSL_WIN32_UTF8
-
- -

If set, then UI_OpenSSL(3) returns UTF-8 encoded strings, rather than ones encoded in the current code page, and the openssl(1) program also transcodes the command-line parameters from the current code page to UTF-8. This environment variable is only checked on Microsoft Windows platforms.

- -
-
RANDFILE
-
- -

The state file for the random number generator. This should not be needed in normal use. See RAND_load_file(3).

- -
-
SSL_CERT_DIR, SSL_CERT_FILE
-
- -

Specify the default directory or file containing CA certificates. See SSL_CTX_load_verify_locations(3).

- -
-
TSGET
-
- -

Additional arguments for the tsget(1) command.

- -
-
OPENSSL_ia32cap, OPENSSL_sparcv9cap, OPENSSL_ppccap, OPENSSL_armcap, OPENSSL_s390xcap, OPENSSL_riscvcap
-
- -

OpenSSL supports a number of different algorithm implementations for various machines and, by default, it determines which to use based on the processor capabilities and run time feature enquiry. These environment variables can be used to exert more control over this selection process. See OPENSSL_ia32cap(3), OPENSSL_s390xcap(3) and OPENSSL_riscvcap(3).

- -
-
NO_PROXY, HTTPS_PROXY, HTTP_PROXY
-
- -

Specify a proxy hostname. See OSSL_HTTP_parse_url(3).

- -
-
QLOGDIR
-
- -

Specifies a QUIC qlog output directory. See openssl-qlog(7).

- -
-
OSSL_QFILTER
-
- -

Used to set a QUIC qlog filter specification. See openssl-qlog(7).

- -
-
- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-glossary.html b/openssl-install/share/doc/openssl/html/man7/openssl-glossary.html deleted file mode 100644 index 75d5a4e9..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-glossary.html +++ /dev/null @@ -1,245 +0,0 @@ - - - - -openssl-glossary - - - - - - - - - - -

NAME

- -

openssl-glossary - An OpenSSL Glossary

- -

DESCRIPTION

- -
- -
Algorithm
-
- -

Cryptographic primitives such as the SHA256 digest, or AES encryption are referred to in OpenSSL as "algorithms". There can be more than one implementation for any given algorithm available for use.

- -

crypto(7)

- -
-
ASN.1, ASN1
-
- -

ASN.1 ("Abstract Syntax Notation One") is a notation for describing abstract types and values. It is defined in the ITU-T documents X.680 to X.683:

- -

https://www.itu.int/rec/T-REC-X.680, https://www.itu.int/rec/T-REC-X.681, https://www.itu.int/rec/T-REC-X.682, https://www.itu.int/rec/T-REC-X.683

- -
-
Base Provider
-
- -

An OpenSSL Provider that contains encoders and decoders for OpenSSL keys. All the algorithm implementations in the Base Provider are also available in the Default Provider.

- -

OSSL_PROVIDER-base(7)

- -
-
Decoder
-
- -

A decoder is a type of algorithm used for decoding keys and parameters from some external format such as PEM or DER.

- -

OSSL_DECODER_CTX_new_for_pkey(3)

- -
-
Default Provider
-
- -

An OpenSSL Provider that contains the most common OpenSSL algorithm implementations. It is loaded by default if no other provider is available. All the algorithm implementations in the Base Provider are also available in the Default Provider.

- -

OSSL_PROVIDER-default(7)

- -
-
DER ("Distinguished Encoding Rules")
-
- -

DER is a binary encoding of data, structured according to an ASN.1 specification. This is a common encoding used for cryptographic objects such as private and public keys, certificates, CRLs, ...

- -

It is defined in ITU-T document X.690:

- -

https://www.itu.int/rec/T-REC-X.690

- -
-
Encoder
-
- -

An encoder is a type of algorithm used for encoding keys and parameters to some external format such as PEM or DER.

- -

OSSL_ENCODER_CTX_new_for_pkey(3)

- -
-
Explicit Fetching
-
- -

Explicit Fetching is a type of Fetching (see Fetching). Explicit Fetching is where a function call is made to obtain an algorithm object representing an implementation such as EVP_MD_fetch(3) or EVP_CIPHER_fetch(3)

- -
-
Fetching
-
- -

Fetching is the process of looking through the available algorithm implementations, applying selection criteria (via a property query string), and finally choosing the implementation that will be used.

- -

Also see Explicit Fetching and Implicit Fetching.

- -

crypto(7)

- -
-
FIPS Provider
-
- -

An OpenSSL Provider that contains OpenSSL algorithm implementations that have been validated according to the FIPS 140-2 standard.

- -

OSSL_PROVIDER-FIPS(7)

- -
-
Implicit Fetching
-
- -

Implicit Fetching is a type of Fetching (see Fetching). Implicit Fetching is where an algorithm object with no associated implementation is used such as the return value from EVP_sha256(3) or EVP_aes_128_cbc(3). With implicit fetching an implementation is fetched automatically using default selection criteria the first time the algorithm is used.

- -
-
Legacy Provider
-
- -

An OpenSSL Provider that contains algorithm implementations that are considered insecure or are no longer in common use.

- -

OSSL_PROVIDER-legacy(7)

- -
-
Library Context
-
- -

A Library Context in OpenSSL is represented by the type OSSL_LIB_CTX. It can be thought of as a scope within which configuration options apply. If an application does not explicitly create a library context then the "default" one is used. Many OpenSSL functions can take a library context as an argument. A NULL value can always be passed to indicate the default library context.

- -

OSSL_LIB_CTX(3)

- -
-
MSBLOB
-
- -

MSBLOB is a Microsoft specific binary format for RSA and DSA keys, both private and public. This form is never passphrase protected.

- -
-
Null Provider
-
- -

An OpenSSL Provider that contains no algorithm implementations. This can be useful to prevent the default provider from being automatically loaded in a library context.

- -

OSSL_PROVIDER-null(7)

- -
-
Operation
-
- -

An operation is a group of OpenSSL functions with a common purpose such as encryption, or digesting.

- -

crypto(7)

- -
-
PEM ("Privacy Enhanced Message")
-
- -

PEM is a format used for encoding of binary content into a mail and ASCII friendly form. The content is a series of base64-encoded lines, surrounded by begin/end markers each on their own line. For example:

- -
-----BEGIN PRIVATE KEY-----
-MIICdg....
-... bhTQ==
------END PRIVATE KEY-----
- -

Optional header line(s) may appear after the begin line, and their existence depends on the type of object being written or read.

- -

For all OpenSSL uses, the binary content is expected to be a DER encoded structure.

- -

This is defined in IETF RFC 1421:

- -

https://tools.ietf.org/html/rfc1421

- -
-
PKCS#8
-
- -

PKCS#8 is a specification of ASN.1 structures that OpenSSL uses for storing or transmitting any private key in a key type agnostic manner. There are two structures worth noting for OpenSSL use, one that contains the key data in unencrypted form (known as "PrivateKeyInfo") and an encrypted wrapper structure (known as "EncryptedPrivateKeyInfo").

- -

This is specified in RFC 5208:

- -

https://tools.ietf.org/html/rfc5208

- -
-
Property
-
- -

A property is a way of classifying and selecting algorithm implementations. A property is a key/value pair expressed as a string. For example all algorithm implementations in the default provider have the property "provider=default". An algorithm implementation can have multiple properties defined against it.

- -

Also see Property Query String.

- -

property(7)

- -
-
Property Query String
-
- -

A property query string is a string containing a sequence of properties that can be used to select an algorithm implementation. For example the query string "provider=example,foo=bar" will select algorithms from the "example" provider that have a "foo" property defined for them with a value of "bar".

- -

Property Query Strings are used during fetching. See Fetching.

- -

property(7)

- -
-
Provider
-
- -

A provider in OpenSSL is a component that groups together algorithm implementations. Providers can come from OpenSSL itself or from third parties.

- -

provider(7)

- -
-
PVK
-
- -

PVK is a Microsoft specific binary format for RSA and DSA private keys. This form may be passphrase protected.

- -
-
SubjectPublicKeyInfo
-
- -

SubjectPublicKeyInfo is an ASN.1 structure that OpenSSL uses for storing and transmitting any public key in a key type agnostic manner.

- -

This is specified as part of the specification for certificates, RFC 5280:

- -

https://tools.ietf.org/html/rfc5280

- -
-
- -

HISTORY

- -

This glossary was added in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-qlog.html b/openssl-install/share/doc/openssl/html/man7/openssl-qlog.html deleted file mode 100644 index 230f7621..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-qlog.html +++ /dev/null @@ -1,266 +0,0 @@ - - - - -openssl-qlog - - - - - - - - - - -

NAME

- -

openssl-qlog - OpenSSL qlog tracing functionality

- -

DESCRIPTION

- -

OpenSSL has unstable support for generating logs in the qlog logging format, which can be used to obtain diagnostic data for QUIC connections. The data generated includes information on packets sent and received and the frames contained within them, as well as loss detection and other events.

- -

The qlog output generated by OpenSSL can be used to obtain diagnostic visualisations of a given QUIC connection using tools such as qvis.

- -

WARNING: The output of OpenSSL's qlog functionality uses an unstable format based on a draft specification. qlog output is not subject to any format stability or compatibility guarantees at this time, and will change in incompatible ways in future versions of OpenSSL. See FORMAT STABILITY below for details.

- -

USAGE

- -

When OpenSSL is built with qlog support, qlog is enabled at run time by setting the standard QLOGDIR environment variable to point to a directory where qlog files should be written. Once set, any QUIC connection established by OpenSSL will have a qlog file written automatically to the specified directory.

- -

Log files are generated in the .sqlog format based on JSON-SEQ (RFC 7464).

- -

The filenames of generated log files under the specified QLOGDIR use the following structure:

- -
{connection_odcid}_{vantage_point_type}.sqlog
- -

where {connection_odcid} is the lowercase hexadecimal encoding of a QUIC connection's Original Destination Connection ID, which is the Destination Connection ID used in the header of the first Initial packet sent as part of the connection process, and {vantage_point_type} is either client or server, reflecting the perspective of the endpoint producing the qlog output.

- -

The qlog functionality can be disabled at OpenSSL build time using the no-unstable-qlog configure flag.

- -

SUPPORTED EVENT TYPES

- -

The following event types are currently supported:

- -
- -
connectivity:connection_started
-
- -
-
connectivity:connection_state_updated
-
- -
-
connectivity:connection_closed
-
- -
-
transport:parameters_set
-
- -
-
transport:packet_sent
-
- -
-
transport:packet_received
-
- -
-
recovery:packet_lost
-
- -
-
- -

FILTERS

- -

By default, all supported event types are logged. The OSSL_QFILTER environment variable can be used to configure a filter specification which determines which event types are to be logged. Each event type can be turned on and off individually. The filter specification is a space-separated list of terms listing event types to enable or disable. The terms are applied in order, thus the effects of later terms override the effects of earlier terms.

- -

Examples

- -

Here are some example filter specifications:

- -
- -
* (or +*)
-
- -

Enable all supported qlog event types.

- -
-
-*
-
- -

Disable all qlog event types.

- -
-
* -transport:packet_received
-
- -

Enable all qlog event types, but disable the transport:packet_received event type.

- -
-
-* transport:packet_sent
-
- -

Disable all qlog event types, except for the transport:packet_sent event type.

- -
-
-* connectivity:* transport:parameters_set
-
- -

Disable all qlog event types, except for transport:parameters_set and all supported event types in the connectivity category.

- -
-
- -

Filter Syntax Specification

- -

Formally, the format of the filter specification in ABNF is as follows:

- -
filter              = *filter-term
-
-filter-term         = add-sub-term
-
-add-sub-term        = ["-" / "+"] specifier
-
-specifier           = global-specifier / qualified-specifier
-
-global-specifier    = wildcard
-
-qualified-specifier = component-specifier ":" component-specifier
-
-component-specifier = name / wildcard
-
-wildcard            = "*"
-
-name                = 1*(ALPHA / DIGIT / "_" / "-")
- -

Filter terms are interpreted as follows:

- -
- -
+* (or *)
-
- -

Enables all event types.

- -
-
-*
-
- -

Disables all event types.

- -
-
+foo:* (or foo:*)
-
- -

Enables all event types in the foo category.

- -
-
-foo:*
-
- -

Disables all event types in the foo category.

- -
-
+foo:bar (or foo:bar)
-
- -

Enables a specific event type foo:bar.

- -
-
-foo:bar
-
- -

Disables a specific event type foo:bar.

- -
-
- -

Partial wildcard matches are not supported at this time.

- -

Default Configuration

- -

If the OSSL_QFILTER environment variable is not set or set to the empty string, this is equivalent to enabling all event types (i.e., it is equivalent to a filter of *). Note that the QLOGDIR environment variable must also be set to enable qlog.

- -

FORMAT STABILITY

- -

The OpenSSL qlog functionality currently implements a draft version of the qlog specification. Future revisions to the qlog specification in advance of formal standardisation are expected to introduce incompatible and breaking changes to the qlog format. The OpenSSL qlog functionality will transition to producing output in this format in the future once standardisation is complete.

- -

Because of this, the qlog output of OpenSSL will change in incompatible and breaking ways in the future, including in non-major releases of OpenSSL. The qlog output of OpenSSL is considered unstable and not subject to any format stability or compatibility guarantees at this time.

- -

Users of the OpenSSL qlog functionality must be aware that the output may change arbitrarily between releases and that the preservation of compatibility with any given tool between releases is not guaranteed.

- -

Aims

- -

The OpenSSL draft qlog functionality is primarily intended for use in conjunction with the qvis tool https://qvis.quictools.info/. In terms of format compatibility, the output format of the OpenSSL qlog functionality is expected to track what is supported by qvis. As such, future changes to the output of the OpenSSL qlog functionality are expected to track changes in qvis as they occur, and reflect the versions of qlog currently supported by qvis.

- -

This means that prior to the finalisation of the qlog standard, in the event of a disparity between the current draft and what qvis supports, the OpenSSL qlog functionality will generally aim for qvis compatibility over compliance with the latest draft.

- -

As such, OpenSSL's qlog functionality currently implements qlog version 0.3 as defined in draft-ietf-quic-qlog-main-schema-05 and draft-ietf-quic-qlog-quic-events-04. These revisions are intentionally used instead of more recent revisions due to their qvis compatibility.

- -

LIMITATIONS

- -

The OpenSSL implementation of qlog currently has the following limitations:

- -
    - -
  • Not all event types defined by the draft specification are implemented.

    - -
  • -
  • Only the JSON-SEQ (.sqlog) output format is supported.

    - -
  • -
  • Only the QLOGDIR environment variable is supported for configuring the qlog output directory. The standard QLOGFILE environment variable is not supported.

    - -
  • -
  • There is no API for programmatically enabling or controlling the qlog functionality.

    - -
  • -
- -

SEE ALSO

- -

openssl-quic(7), openssl-env(7)

- -

HISTORY

- -

This functionality was added in OpenSSL 3.3.

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-quic.html b/openssl-install/share/doc/openssl/html/man7/openssl-quic.html deleted file mode 100644 index ffe65426..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-quic.html +++ /dev/null @@ -1,574 +0,0 @@ - - - - -openssl-quic - - - - - - - - - - -

NAME

- -

openssl-quic - OpenSSL QUIC

- -

DESCRIPTION

- -

OpenSSL 3.2 and later features support for the QUIC transport protocol. Currently, only client connectivity is supported. This man page describes the usage of QUIC client functionality for both existing and new applications.

- -

QUIC functionality uses the standard SSL API. A QUIC connection is represented by an SSL object in the same way that a TLS connection is. Only minimal changes are needed to existing applications making use of the libssl APIs to make use of QUIC client functionality. To make use of QUIC, use the SSL method OSSL_QUIC_client_method(3) or OSSL_QUIC_client_thread_method(3) with SSL_CTX_new(3).

- -

When a QUIC connection is created, by default, it operates in default stream mode, which is intended to provide compatibility with existing non-QUIC application usage patterns. In this mode, the connection has a single stream associated with it. Calls to SSL_read(3) and SSL_write(3) on the QUIC connection SSL object read and write from that stream. Whether the stream is client-initiated or server-initiated from a QUIC perspective depends on whether SSL_read(3) or SSL_write(3) is called first. See the MODES OF OPERATION section for more information.

- -

The default stream mode is intended for compatibility with existing applications. New applications using QUIC are recommended to disable default stream mode and use the multi-stream API; see the MODES OF OPERATION section and the RECOMMENDATIONS FOR NEW APPLICATIONS section for more information.

- -

The remainder of this man page discusses, in order:

- -
    - -
  • Default stream mode versus multi-stream mode;

    - -
  • -
  • The changes to existing libssl APIs which are driven by QUIC-related implementation requirements, which existing applications should bear in mind;

    - -
  • -
  • Aspects which must be considered by existing applications when adopting QUIC, including potential changes which may be needed.

    - -
  • -
  • Recommended usage approaches for new applications.

    - -
  • -
  • New, QUIC-specific APIs.

    - -
  • -
- -

MODES OF OPERATION

- -

Default Stream Mode

- -

A QUIC client connection can be used in either default stream mode or multi-stream mode. By default, a newly created QUIC connection SSL object uses default stream mode.

- -

In default stream mode, a stream is implicitly created and bound to the QUIC connection SSL object; SSL_read(3) and SSL_write(3) calls to the QUIC connection SSL object work by default and are mapped to that stream.

- -

When default stream mode is used, any API function which can be called on a QUIC stream SSL object can also be called on a QUIC connection SSL object, in which case it affects the default stream bound to the connection.

- -

The identity of a QUIC stream, including its stream ID, varies depending on whether a stream is client-initiated or server-initiated. In default stream mode, if a client application calls SSL_read(3) first before any call to SSL_write(3) on the connection, it is assumed that the application protocol is using a server-initiated stream, and the SSL_read(3) call will not complete (either blocking, or failing appropriately if nonblocking mode is configured) until the server initiates a stream. Conversely, if the client application calls SSL_write(3) before any call to SSL_read(3) on the connection, it is assumed that a client-initiated stream is to be used and such a stream is created automatically.

- -

Default stream mode is intended to aid compatibility with legacy applications. New applications adopting QUIC should use multi-stream mode, described below, and avoid use of the default stream functionality.

- -

It is possible to use additional streams in default stream mode using SSL_new_stream(3) and SSL_accept_stream(3); note that the default incoming stream policy will need to be changed using SSL_set_incoming_stream_policy(3) in order to use SSL_accept_stream(3) in this case. However, applications using additional streams are strongly recommended to use multi-stream mode instead.

- -

Calling SSL_new_stream(3) or SSL_accept_stream(3) before a default stream has been associated with the QUIC connection SSL object will inhibit future creation of a default stream.

- -

Multi-Stream Mode

- -

The recommended usage mode for new applications adopting QUIC is multi-stream mode, in which no default stream is attached to the QUIC connection SSL object and attempts to call SSL_read(3) and SSL_write(3) on the QUIC connection SSL object fail. Instead, an application calls SSL_new_stream(3) or SSL_accept_stream(3) to create individual stream SSL objects for sending and receiving application data using SSL_read(3) and SSL_write(3).

- -

To use multi-stream mode, call SSL_set_default_stream_mode(3) with an argument of SSL_DEFAULT_STREAM_MODE_NONE; this function must be called prior to initiating the connection. The default stream mode cannot be changed after initiating a connection.

- -

When multi-stream mode is used, meaning that no default stream is associated with the connection, calls to API functions which are defined as operating on a QUIC stream fail if called on the QUIC connection SSL object. For example, calls such as SSL_write(3) or SSL_get_stream_id(3) will fail.

- -

CHANGES TO EXISTING APIS

- -

Most SSL APIs, such as SSL_read(3) and SSL_write(3), function as they do for TLS connections and do not have changed semantics, with some exceptions. The changes to the semantics of existing APIs are as follows:

- -
    - -
  • Since QUIC uses UDP, SSL_set_bio(3), SSL_set0_rbio(3) and SSL_set0_wbio(3) function as before, but must now receive a BIO with datagram semantics. There are broadly four options for applications to use as a network BIO:

    - -
      - -
    • BIO_s_datagram(3), recommended for most applications, replaces BIO_s_socket(3) and provides a UDP socket.

      - -
    • -
    • BIO_s_dgram_pair(3) provides BIO pair-like functionality but with datagram semantics, and is recommended for existing applications which use a BIO pair or memory BIO to manage libssl's communication with the network.

      - -
    • -
    • BIO_s_dgram_mem(3) provides a simple memory BIO-like interface but with datagram semantics. Unlike BIO_s_dgram_pair(3), it is unidirectional.

      - -
    • -
    • An application may also choose to implement a custom BIO. The new BIO_sendmmsg(3) and BIO_recvmmsg(3) APIs must be supported.

      - -
    • -
    - -
  • -
  • SSL_set_fd(3), SSL_set_rfd(3) and SSL_set_wfd(3) traditionally instantiate a BIO_s_socket(3). For QUIC, these functions instead instantiate a BIO_s_datagram(3). This is equivalent to instantiating a BIO_s_datagram(3) and using SSL_set0_rbio(3) and SSL_set0_wbio(3).

    - -
  • -
  • Traditionally, whether the application-level I/O APIs (such as SSL_read(3) and SSL_write(3) operated in a blocking fashion was directly correlated with whether the underlying network socket was configured in a blocking fashion. This is no longer the case; applications must explicitly configure the desired application-level blocking mode using SSL_set_blocking_mode(3). See SSL_set_blocking_mode(3) for details.

    - -
  • -
  • Network-level I/O must always be performed in a nonblocking manner. The application can still enjoy blocking semantics for calls to application-level I/O functions such as SSL_read(3) and SSL_write(3), but the underlying network BIO provided to QUIC (such as a BIO_s_datagram(3)) must be configured in nonblocking mode. For application-level blocking functionality, see SSL_set_blocking_mode(3).

    - -
  • -
  • BIO_new_ssl_connect(3) has been changed to automatically use a BIO_s_datagram(3) when used with QUIC, therefore applications which use this do not need to change the BIO they use.

    - -
  • -
  • BIO_new_buffer_ssl_connect(3) cannot be used with QUIC and applications must change to use BIO_new_ssl_connect(3) instead.

    - -
  • -
  • SSL_shutdown(3) has significant changes in relation to how QUIC connections must be shut down. In particular, applications should be advised that the full RFC-conformant QUIC shutdown process may take an extended amount of time. This may not be suitable for short-lived processes which should exit immediately after their usage of a QUIC connection is completed. A rapid shutdown mode is available for such applications. For details, see SSL_shutdown(3).

    - -
  • -
  • SSL_want(3), SSL_want_read(3) and SSL_want_write(3) no longer reflect the I/O state of the network BIO passed to the QUIC SSL object, but instead reflect the flow control state of the QUIC stream associated with the SSL object.

    - -

    When used in nonblocking mode, SSL_ERROR_WANT_READ indicates that the receive part of a QUIC stream does not currently have any more data available to be read, and SSL_ERROR_WANT_WRITE indicates that the stream's internal buffer is full.

    - -

    To determine if the QUIC implementation currently wishes to be informed of incoming network datagrams, use the new function SSL_net_read_desired(3); likewise, to determine if the QUIC implementation currently wishes to be informed when it is possible to transmit network datagrams, use the new function SSL_net_write_desired(3). Only applications which wish to manage their own event loops need to use these functions; see APPLICATION-DRIVEN EVENT LOOPS for further discussion.

    - -
  • -
  • The use of ALPN is mandatory when using QUIC. Attempts to connect without configuring ALPN will fail. For information on how to configure ALPN, see SSL_set_alpn_protos(3).

    - -
  • -
  • Whether QUIC operates in a client or server mode is determined by the SSL_METHOD used, rather than by calls to SSL_set_connect_state(3) or SSL_set_accept_state(3). It is not necessary to call either of SSL_set_connect_state(3) or SSL_set_accept_state(3) before connecting, but if either of these are called, the function called must be congruent with the SSL_METHOD being used. Currently, only client mode is supported.

    - -
  • -
  • The SSL_set_min_proto_version(3) and SSL_set_max_proto_version(3) APIs are not used and the values passed to them are ignored, as OpenSSL QUIC currently always uses TLS 1.3.

    - -
  • -
  • The following libssl functionality is not available when used with QUIC.

    - -
      - -
    • Async functionality

      - -
    • -
    • SSL_MODE_AUTO_RETRY

      - -
    • -
    • Record Padding and Fragmentation (SSL_set_block_padding(3), etc.)

      - -
    • -
    • SSL_stateless(3) support

      - -
    • -
    • SRTP functionality

      - -
    • -
    • TLSv1.3 Early Data

      - -
    • -
    • TLS Next Protocol Negotiation cannot be used and is superseded by ALPN, which must be used instead. The use of ALPN is mandatory with QUIC.

      - -
    • -
    • Post-Handshake Client Authentication is not available as QUIC prohibits its use.

      - -
    • -
    • QUIC requires the use of TLSv1.3 or later, therefore functionality only relevant to older TLS versions is not available.

      - -
    • -
    • Some cipher suites which are generally available for TLSv1.3 are not available for QUIC, such as TLS_AES_128_CCM_8_SHA256. Your application may need to adjust the list of acceptable cipher suites it passes to libssl.

      - -
    • -
    • CCM mode is not currently supported.

      - -
    • -
    - -

    The following libssl functionality is also not available when used with QUIC, but calls to the relevant functions are treated as no-ops:

    - - - -
  • -
- -

CONSIDERATIONS FOR EXISTING APPLICATIONS

- -

Existing applications seeking to adopt QUIC should apply the following list to determine what changes they will need to make:

- -
    - -
  • An application wishing to use QUIC must use OSSL_QUIC_client_method(3) or OSSL_QUIC_client_thread_method(3) as its SSL method. For more information on the differences between these two methods, see THREAD ASSISTED MODE.

    - -
  • -
  • Determine how to provide QUIC with network access. Determine which of the below apply for your application:

    - -
      - -
    • Your application uses BIO_s_socket(3) to construct a BIO which is passed to the SSL object to provide it with network access.

      - -

      Changes needed: Change your application to use BIO_s_datagram(3) instead when using QUIC. The socket must be configured in nonblocking mode. You may or may not need to use SSL_set1_initial_peer_addr(3) to set the initial peer address; see the QUIC-SPECIFIC APIS section for details.

      - -
    • -
    • Your application uses BIO_new_ssl_connect(3) to construct a BIO which is passed to the SSL object to provide it with network access.

      - -

      Changes needed: No changes needed. Use of QUIC is detected automatically and a datagram socket is created instead of a normal TCP socket.

      - -
    • -
    • Your application uses any other I/O strategy in this list but combines it with a BIO_f_buffer(3), for example using BIO_push(3).

      - -

      Changes needed: Disable the usage of BIO_f_buffer(3) when using QUIC. Usage of such a buffer is incompatible with QUIC as QUIC requires datagram semantics in its interaction with the network.

      - -
    • -
    • Your application uses a BIO pair to cause the SSL object to read and write network traffic to a memory buffer. Your application manages the transmission and reception of buffered data itself in a way unknown to libssl.

      - -

      Changes needed: Switch from using a conventional BIO pair to using BIO_s_dgram_pair(3) instead, which has the necessary datagram semantics. You will need to modify your application to transmit and receive using a UDP socket and to use datagram semantics when interacting with the BIO_s_dgram_pair(3) instance.

      - -
    • -
    • Your application uses a custom BIO method to provide the SSL object with network access.

      - -

      Changes needed: The custom BIO must be re-architected to have datagram semantics. BIO_sendmmsg(3) and BIO_recvmmsg(3) must be implemented. These calls must operate in a nonblocking fashion. Optionally, implement the BIO_get_rpoll_descriptor(3) and BIO_get_wpoll_descriptor(3) methods if desired. Implementing these methods is required if blocking semantics at the SSL API level are desired.

      - -
    • -
    - -
  • -
  • An application must explicitly configure whether it wishes to use the SSL APIs in blocking mode or not. Traditionally, an SSL object has automatically operated in blocking or nonblocking mode based on whether the underlying network BIO operates in blocking or nonblocking mode. QUIC requires the use of a nonblocking network BIO, therefore the blocking mode at the application level must be explicitly configured by the application using the new SSL_set_blocking_mode(3) API. The default mode is blocking. If an application wishes to use the SSL object APIs at application level in a nonblocking manner, it must add a call to SSL_set_blocking_mode(3) to disable blocking mode.

    - -
  • -
  • If your application does not choose to use thread assisted mode, it must ensure that it calls an I/O function on the SSL object (for example, SSL_read(3) or SSL_write(3)), or the new function SSL_handle_events(3), regularly. If the SSL object is used in blocking mode, an ongoing blocking call to an I/O function satisfies this requirement. This is required to ensure that timer events required by QUIC are handled in a timely fashion.

    - -

    Most applications will service the SSL object by calling SSL_read(3) or SSL_write(3) regularly. If an application does not do this, it should ensure that SSL_handle_events(3) is called regularly.

    - -

    SSL_get_event_timeout(3) can be used to determine when SSL_handle_events(3) must next be called.

    - -

    If the SSL object is being used with an underlying network BIO which is pollable (such as BIO_s_datagram(3)), the application can use SSL_get_rpoll_descriptor(3), SSL_get_wpoll_descriptor(3) to obtain resources which can be used to determine when SSL_handle_events(3) should be called due to network I/O.

    - -

    Applications which use thread assisted mode do not need to be concerned with this requirement, as the QUIC implementation ensures timeout events are handled in a timely manner. See THREAD ASSISTED MODE for details.

    - -
  • -
  • Ensure that your usage of SSL_want(3), SSL_want_read(3) and SSL_want_write(3) reflects the API changes described in CHANGES TO EXISTING APIS. In particular, you should use these APIs to determine the ability of a QUIC stream to receive or provide application data, not to to determine if network I/O is required.

    - -
  • -
  • Evaluate your application's use of SSL_shutdown(3) in light of the changes discussed in CHANGES TO EXISTING APIS. Depending on whether your application wishes to prioritise RFC conformance or rapid shutdown, consider using the new SSL_shutdown_ex(3) API instead. See QUIC-SPECIFIC APIS for details.

    - -
  • -
- -

RECOMMENDED USAGE IN NEW APPLICATIONS

- -

The recommended usage in new applications varies depending on three independent design decisions:

- -
    - -
  • Whether the application will use blocking or nonblocking I/O at the application level (configured using SSL_set_blocking_mode(3)).

    - -

    If the application does nonblocking I/O at the application level it can choose to manage its own polling and event loop; see APPLICATION-DRIVEN EVENT LOOPS.

    - -
  • -
  • Whether the application intends to give the QUIC implementation direct access to a network socket (e.g. via BIO_s_datagram(3)) or whether it intends to buffer transmitted and received datagrams via a BIO_s_dgram_pair(3) or custom BIO.

    - -

    The former is preferred where possible as it reduces latency to the network, which enables QUIC to achieve higher performance and more accurate connection round trip time (RTT) estimation.

    - -
  • -
  • Whether thread assisted mode will be used (see THREAD ASSISTED MODE).

    - -
  • -
- -

Simple demos for QUIC usage under these various scenarios can be found at https://github.com/openssl/openssl/tree/master/doc/designs/ddd.

- -

Applications which wish to implement QUIC-specific protocols should be aware of the APIs listed under QUIC-SPECIFIC APIS which provide access to QUIC-specific functionality. For example, SSL_stream_conclude(3) can be used to indicate the end of the sending part of a stream, and SSL_shutdown_ex(3) can be used to provide a QUIC application error code when closing a connection.

- -

Regardless of the design decisions chosen above, it is recommended that new applications avoid use of the default stream mode and use the multi-stream API by calling SSL_set_default_stream_mode(3); see the MODES OF OPERATION section for details.

- -

QUIC-SPECIFIC APIS

- -

This section details new APIs which are directly or indirectly related to QUIC. For details on the operation of each API, see the referenced man pages.

- -

The following SSL APIs are new but relevant to both QUIC and DTLS:

- -
- -
SSL_get_event_timeout(3)
-
- -

Determines when the QUIC implementation should next be woken up via a call to SSL_handle_events(3) (or another I/O function such as SSL_read(3) or SSL_write(3)), if ever.

- -

This can also be used with DTLS and supersedes DTLSv1_get_timeout(3) for new usage.

- -
-
SSL_handle_events(3)
-
- -

This is a non-specific I/O operation which makes a best effort attempt to perform any pending I/O or timeout processing. It can be used to advance the QUIC state machine by processing incoming network traffic, generating outgoing network traffic and handling any expired timeout events. Most other I/O functions on an SSL object, such as SSL_read(3) and SSL_write(3) implicitly perform event handling on the SSL object, so calling this function is only needed if no other I/O function is to be called.

- -

This can also be used with DTLS and supersedes DTLSv1_handle_timeout(3) for new usage.

- -
-
- -

The following SSL APIs are specific to QUIC:

- -
- -
SSL_set_blocking_mode(3), SSL_get_blocking_mode(3)
-
- -

Configures whether blocking semantics are used at the application level. This determines whether calls to functions such as SSL_read(3) and SSL_write(3) will block.

- -
-
SSL_get_rpoll_descriptor(3), SSL_get_wpoll_descriptor(3)
-
- -

These functions facilitate operation in nonblocking mode.

- -

When an SSL object is being used with an underlying network read BIO which supports polling, SSL_get_rpoll_descriptor(3) outputs an OS resource which can be used to synchronise on network readability events which should result in a call to SSL_handle_events(3). SSL_get_wpoll_descriptor(3) works in an analogous fashion for the underlying network write BIO.

- -

The poll descriptors provided by these functions need only be used when SSL_net_read_desired(3) and SSL_net_write_desired(3) return 1, respectively.

- -
-
SSL_net_read_desired(3), SSL_net_write_desired(3)
-
- -

These functions facilitate operation in nonblocking mode and are used in conjunction with SSL_get_rpoll_descriptor(3) and SSL_get_wpoll_descriptor(3) respectively. They determine whether the respective poll descriptor is currently relevant for the purposes of polling.

- -
-
SSL_set1_initial_peer_addr(3)
-
- -

This function can be used to set the initial peer address for an outgoing QUIC connection. This function must be used in the general case when creating an outgoing QUIC connection; however, the correct initial peer address can be autodetected in some cases. See SSL_set1_initial_peer_addr(3) for details.

- -
-
SSL_shutdown_ex(3)
-
- -

This augments SSL_shutdown(3) by allowing an application error code to be specified. It also allows a client to decide how quickly it wants a shutdown to be performed, potentially by trading off strict RFC compliance.

- -
-
SSL_stream_conclude(3)
-
- -

This allows an application to indicate the normal end of the sending part of a QUIC stream. This corresponds to the FIN flag in the QUIC RFC. The receiving part of a stream remains usable.

- -
-
SSL_stream_reset(3)
-
- -

This allows an application to indicate the non-normal termination of the sending part of a stream. This corresponds to the RESET_STREAM frame in the QUIC RFC.

- -
-
SSL_get_stream_write_state(3) and SSL_get_stream_read_state(3)
-
- -

This allows an application to determine the current stream states for the sending and receiving parts of a stream respectively.

- -
-
SSL_get_stream_write_error_code(3) and SSL_get_stream_read_error_code(3)
-
- -

This allows an application to determine the application error code which was signalled by a peer which has performed a non-normal stream termination of the respective sending or receiving part of a stream, if any.

- -
-
SSL_get_conn_close_info(3)
-
- -

This allows an application to determine the error code which was signalled when the local or remote endpoint terminated the QUIC connection.

- -
-
SSL_get0_connection(3)
-
- -

Gets the QUIC connection SSL object from a QUIC stream SSL object.

- -
-
SSL_is_connection(3)
-
- -

Returns 1 if a SSL object is not a QUIC stream SSL object.

- -
-
SSL_get_stream_type(3)
-
- -

Provides information on the kind of QUIC stream which is attached to the SSL object.

- -
-
SSL_get_stream_id(3)
-
- -

Returns the QUIC stream ID which the QUIC protocol has associated with a QUIC stream.

- -
-
SSL_new_stream(3)
-
- -

Creates a new QUIC stream SSL object representing a new, locally-initiated QUIC stream.

- -
-
SSL_accept_stream(3)
-
- -

Potentially yields a new QUIC stream SSL object representing a new remotely-initiated QUIC stream, blocking until one is available if the connection is configured to do so.

- -
-
SSL_get_accept_stream_queue_len(3)
-
- -

Provides information on the number of pending remotely-initiated streams.

- -
-
SSL_set_incoming_stream_policy(3)
-
- -

Configures how incoming, remotely-initiated streams are handled. The incoming stream policy can be used to automatically reject streams created by the peer, or allow them to be handled using SSL_accept_stream(3).

- -
-
SSL_set_default_stream_mode(3)
-
- -

Used to configure or disable default stream mode; see the MODES OF OPERATION section for details.

- -
-
- -

The following BIO APIs are not specific to QUIC but have been added to facilitate QUIC-specific requirements and are closely associated with its use:

- -
- -
BIO_s_dgram_pair(3)
-
- -

This is a new BIO method which is similar to a conventional BIO pair but provides datagram semantics.

- -
-
BIO_get_rpoll_descriptor(3), BIO_get_wpoll_descriptor(3)
-
- -

This is a new BIO API which allows a BIO to expose a poll descriptor. This API is used to implement the corresponding SSL APIs SSL_get_rpoll_descriptor(3) and SSL_get_wpoll_descriptor(3).

- -
-
BIO_sendmmsg(3), BIO_recvmmsg(3)
-
- -

This is a new BIO API which can be implemented by BIOs which implement datagram semantics. It is implemented by BIO_s_datagram(3) and BIO_s_dgram_pair(3). It is used by the QUIC implementation to send and receive UDP datagrams.

- -
-
BIO_dgram_set_no_trunc(3), BIO_dgram_get_no_trunc(3)
-
- -

By default, BIO_s_dgram_pair(3) has semantics comparable to those of Berkeley sockets being used with datagram semantics. This allows an alternative mode to be enabled in which datagrams will not be silently truncated if they are too large.

- -
-
BIO_dgram_set_caps(3), BIO_dgram_get_caps(3)
-
- -

These functions are used to allow the user of one end of a BIO_s_dgram_pair(3) to indicate its capabilities to the other end of a BIO_s_dgram_pair(3). In particular, this allows an application to inform the QUIC implementation of whether it is prepared to handle local and/or peer addresses in transmitted datagrams and to provide the applicable information in received datagrams.

- -
-
BIO_dgram_get_local_addr_cap(3), BIO_dgram_set_local_addr_enable(3), BIO_dgram_get_local_addr_enable(3)
-
- -

Local addressing support refers to the ability of a BIO with datagram semantics to allow a source address to be specified on transmission and to report the destination address on reception. These functions can be used to determine if a BIO can support local addressing and to enable local addressing support if it can.

- -
-
BIO_err_is_non_fatal(3)
-
- -

This is used to determine if an error while calling BIO_sendmmsg(3) or BIO_recvmmsg(3) is ephemeral in nature, such as "would block" errors.

- -
-
- -

THREAD ASSISTED MODE

- -

The optional thread assisted mode can be used with OSSL_QUIC_client_thread_method(3). In this mode, a background thread is created automatically. The OpenSSL QUIC implementation then takes responsibility for ensuring that timeout events are handled on a timely basis even if no SSL I/O function such as SSL_read(3) or SSL_write(3) is called by the application for a long time.

- -

All necessary locking is handled automatically internally, but the thread safety guarantees for the public SSL API are unchanged. Therefore, an application must still do its own locking if it wishes to make concurrent use of the public SSL APIs.

- -

Because this method relies on threads, it is not available on platforms where threading support is not available or not supported by OpenSSL. However, it does provide the simplest mode of usage for an application.

- -

The implementation may or may not use a common thread or thread pool to service multiple SSL objects in the same SSL_CTX.

- -

APPLICATION-DRIVEN EVENT LOOPS

- -

OpenSSL's QUIC implementation is designed to facilitate applications which wish to use the SSL APIs in a blocking fashion, but is also designed to facilitate applications which wish to use the SSL APIs in a nonblocking fashion and manage their own event loops and polling directly. This is useful when it is desirable to host OpenSSL's QUIC implementation on top of an application's existing nonblocking I/O infrastructure.

- -

This is supported via the concept of poll descriptors; see BIO_get_rpoll_descriptor(3) for details. Broadly, a BIO_POLL_DESCRIPTOR is a structure which expresses some kind of OS resource which can be used to synchronise on I/O events. The QUIC implementation provides a BIO_POLL_DESCRIPTOR based on the poll descriptor provided by the underlying network BIO. This is typically an OS socket handle, though custom BIOs could choose to implement their own custom poll descriptor format.

- -

Broadly, an application which wishes to manage its own event loop should interact with the SSL object as follows:

- - - -

SEE ALSO

- -

SSL_handle_events(3), SSL_get_event_timeout(3), SSL_net_read_desired(3), SSL_net_write_desired(3), SSL_get_rpoll_descriptor(3), SSL_get_wpoll_descriptor(3), SSL_set_blocking_mode(3), SSL_shutdown_ex(3), SSL_set1_initial_peer_addr(3), SSL_stream_conclude(3), SSL_stream_reset(3), SSL_get_stream_read_state(3), SSL_get_stream_read_error_code(3), SSL_get_conn_close_info(3), SSL_get0_connection(3), SSL_get_stream_type(3), SSL_get_stream_id(3), SSL_new_stream(3), SSL_accept_stream(3), SSL_set_incoming_stream_policy(3), SSL_set_default_stream_mode(3)

- -

COPYRIGHT

- -

Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl-threads.html b/openssl-install/share/doc/openssl/html/man7/openssl-threads.html deleted file mode 100644 index ca3ca817..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl-threads.html +++ /dev/null @@ -1,69 +0,0 @@ - - - - -openssl-threads - - - - - - - - - - -

NAME

- -

openssl-threads - Overview of thread safety in OpenSSL

- -

DESCRIPTION

- -

In this man page, we use the term thread-safe to indicate that an object or function can be used by multiple threads at the same time.

- -

OpenSSL can be built with or without threads support. The most important use of this support is so that OpenSSL itself can use a single consistent API, as shown in "EXAMPLES" in CRYPTO_THREAD_run_once(3). Multi-platform applications can also use this API.

- -

In particular, being configured for threads support does not imply that all OpenSSL objects are thread-safe. To emphasize: most objects are not safe for simultaneous use. Exceptions to this should be documented on the specific manual pages, and some general high-level guidance is given here.

- -

One major use of the OpenSSL thread API is to implement reference counting. Many objects within OpenSSL are reference-counted, so resources are not released, until the last reference is removed. References are often increased automatically (such as when an X509 certificate object is added into an X509_STORE trust store). There is often an object_up_ref() function that can be used to increase the reference count. Failure to match object_up_ref() calls with the right number of object_free() calls is a common source of memory leaks when a program exits.

- -

Many objects have set and get API's to set attributes in the object. A set0 passes ownership from the caller to the object and a get0 returns a pointer but the attribute ownership remains with the object and a reference to it is returned. A set1 or get1 function does not change the ownership, but instead updates the attribute's reference count so that the object is shared between the caller and the object; the caller must free the returned attribute when finished. Functions that involve attributes that have reference counts themselves, but are named with just set or get are historical; and the documentation must state how the references are handled. Get methods are often thread-safe as long as the ownership requirements are met and shared objects are not modified. Set methods, or modifying shared objects, are generally not thread-safe as discussed below.

- -

Objects are thread-safe as long as the API's being invoked don't modify the object; in this case the parameter is usually marked in the API as const. Not all parameters are marked this way. Note that a const declaration does not mean immutable; for example X509_cmp(3) takes pointers to const objects, but the implementation uses a C cast to remove that so it can lock objects, generate and cache a DER encoding, and so on.

- -

Another instance of thread-safety is when updates to an object's internal state, such as cached values, are done with locks. One example of this is the reference counting API's described above.

- -

In all cases, however, it is generally not safe for one thread to mutate an object, such as setting elements of a private or public key, while another thread is using that object, such as verifying a signature.

- -

The same API's can usually be used simultaneously on different objects without interference. For example, two threads can calculate a signature using two different EVP_PKEY_CTX objects.

- -

For implicit global state or singletons, thread-safety depends on the facility. The CRYPTO_secure_malloc(3) and related API's have their own lock, while CRYPTO_malloc(3) assumes the underlying platform allocation will do any necessary locking. Some API's, such as NCONF_load(3) and related do no locking at all; this can be considered a bug.

- -

A separate, although related, issue is modifying "factory" objects when other objects have been created from that. For example, an SSL_CTX object created by SSL_CTX_new(3) is used to create per-connection SSL objects by calling SSL_new(3). In this specific case, and probably for factory methods in general, it is not safe to modify the factory object after it has been used to create other objects.

- -

SEE ALSO

- -

CRYPTO_THREAD_run_once(3), local system threads documentation.

- -

BUGS

- -

This page is admittedly very incomplete.

- -

COPYRIGHT

- -

Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/openssl_user_macros.html b/openssl-install/share/doc/openssl/html/man7/openssl_user_macros.html deleted file mode 100644 index 93153fca..00000000 --- a/openssl-install/share/doc/openssl/html/man7/openssl_user_macros.html +++ /dev/null @@ -1,123 +0,0 @@ - - - - -openssl_user_macros - - - - - - - - - - -

NAME

- -

openssl_user_macros, OPENSSL_API_COMPAT, OPENSSL_NO_DEPRECATED - User defined macros

- -

DESCRIPTION

- -

User defined macros allow the programmer to control certain aspects of what is exposed by the OpenSSL headers.

- -

NOTE: to be effective, a user defined macro must be defined before including any header file that depends on it, either in the compilation command (cc -DMACRO=value) or by defining the macro in source before including any headers.

- -

Other manual pages may refer to this page when declarations depend on user defined macros.

- -

The macros

- -
- -
OPENSSL_API_COMPAT
-
- -

The value is a version number, given in one of the following two forms:

- -
- -
0xMNNFF000L
-
- -

This is the form supported for all versions up to 1.1.x, where M represents the major number, NN represents the minor number, and FF represents the fix number, as a hexadecimal number. For version 1.1.0, that's 0x10100000L.

- -

Any version number may be given, but these numbers are the current known major deprecation points, making them the most meaningful:

- -
- -
0x00908000L (version 0.9.8)
-
- -
-
0x10000000L (version 1.0.0)
-
- -
-
0x10100000L (version 1.1.0)
-
- -
-
- -

For convenience, higher numbers are accepted as well, as long as feasible. For example, 0x60000000L will work as expected. However, it is recommended to start using the second form instead:

- -
-
mmnnpp
-
- -

This form is a simple decimal number calculated with this formula:

- -

major * 10000 + minor * 100 + patch

- -

where major, minor and patch are the desired major, minor and patch components of the version number. For example:

- -
- -
30000 corresponds to version 3.0.0
-
- -
-
10002 corresponds to version 1.0.2
-
- -
-
420101 corresponds to version 42.1.1
-
- -
-
- -
-
- -

If OPENSSL_API_COMPAT is undefined, this default value is used in its place: 30400

- -
-
OPENSSL_NO_DEPRECATED
-
- -

If this macro is defined, all deprecated public symbols in all OpenSSL versions up to and including the version given by OPENSSL_API_COMPAT (or the default value given above, when OPENSSL_API_COMPAT isn't defined) will be hidden.

- -
-
- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-introduction.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-introduction.html deleted file mode 100644 index 99748641..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-introduction.html +++ /dev/null @@ -1,113 +0,0 @@ - - - - -ossl-guide-introduction - - - - - - - - - - -

NAME

- -

ossl-guide-introduction - OpenSSL Guide: An introduction to OpenSSL

- -

WHAT IS OPENSSL?

- -

OpenSSL is a robust, commercial-grade, full-featured toolkit for general-purpose cryptography and secure communication. Its features are made available via a command line application that enables users to perform various cryptography related functions such as generating keys and certificates. Additionally it supplies two libraries that application developers can use to implement cryptography based capabilities and to securely communicate across a network. Finally, it also has a set of providers that supply implementations of a broad set of cryptographic algorithms.

- -

OpenSSL is fully open source. Version 3.0 and above are distributed under the Apache v2 license.

- -

GETTING AND INSTALLING OPENSSL

- -

The OpenSSL Project develops and distributes the source code for OpenSSL. You can obtain that source code via the OpenSSL website (https://www.openssl.org/source).

- -

Many Operating Systems (notably Linux distributions) supply pre-built OpenSSL binaries either pre-installed or available via the package management system in use for that OS. It is worth checking whether this applies to you before attempting to build OpenSSL from the source code.

- -

Some third parties also supply OpenSSL binaries (e.g. for Windows and some other platforms). The OpenSSL project maintains a list of these third parties at https://github.com/openssl/openssl/wiki/Binaries.

- -

If you build and install OpenSSL from the source code then you should download the appropriate files for the version that you want to use from the link given above. Extract the contents of the tar.gz archive file that you downloaded into an appropriate directory. Inside that archive you will find a file named INSTALL.md which will supply detailed instructions on how to build and install OpenSSL from source. Make sure you read the contents of that file carefully in order to achieve a successful build. In the directory you will also find a set of NOTES files that provide further platform specific information. Make sure you carefully read the file appropriate to your platform. As well as the platform specific NOTES files there is also a NOTES-PERL.md file that provides information about setting up Perl for use by the OpenSSL build system across multiple platforms.

- -

Sometimes you may want to build and install OpenSSL from source on a system which already has a pre-built version of OpenSSL installed on it via the Operating System package management system (for example if you want to use a newer version of OpenSSL than the one supplied by your Operating System). In this case it is strongly recommended to install OpenSSL to a different location than where the pre-built version is installed. You should never replace the pre-built version with a different version as this may break your system.

- -

CONTENTS OF THE OPENSSL GUIDE

- -

The OpenSSL Guide is a series of documentation pages (starting with this one) that introduce some of the main concepts in OpenSSL. The guide can either be read end-to-end in order, or alternatively you can simply skip to the parts most applicable to your use case. Note however that later pages may depend on and assume knowledge from earlier pages.

- -

The pages in the guide are as follows:

- -
- -
ossl-guide-libraries-introduction(7): An introduction to the OpenSSL libraries
-
- -
-
ossl-guide-libcrypto-introduction(7): An introduction to libcrypto
-
- -
-
ossl-guide-libssl-introduction(7): An introduction to libssl
-
- -
-
ossl-guide-tls-introduction(7): An introduction to SSL/TLS in OpenSSL
-
- -
-
ossl-guide-tls-client-block(7): Writing a simple blocking TLS client
-
- -
-
ossl-guide-tls-client-non-block(7): Writing a simple nonblocking TLS client
-
- -
-
ossl-guide-tls-server-block(7): Writing a simple blocking TLS server
-
- -
-
ossl-guide-quic-introduction(7): An introduction to QUIC in OpenSSL
-
- -
-
ossl-guide-quic-client-block(7): Writing a simple blocking QUIC client
-
- -
-
ossl-guide-quic-multi-stream(7): Writing a simple multi-stream QUIC client
-
- -
-
ossl-guide-quic-client-non-block(7): Writing a simple nonblocking QUIC client
-
- -
-
ossl-guide-migration(7): Migrating from older OpenSSL versions
-
- -
-
- -

COPYRIGHT

- -

Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-libcrypto-introduction.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-libcrypto-introduction.html deleted file mode 100644 index a9e35891..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-libcrypto-introduction.html +++ /dev/null @@ -1,336 +0,0 @@ - - - - -ossl-guide-libcrypto-introduction - - - - - - - - - - -

NAME

- -

ossl-guide-libcrypto-introduction, crypto - OpenSSL Guide: An introduction to libcrypto

- -

INTRODUCTION

- -

The OpenSSL cryptography library (libcrypto) enables access to a wide range of cryptographic algorithms used in various Internet standards. The services provided by this library are used by the OpenSSL implementations of TLS and CMS, and they have also been used to implement many other third party products and protocols.

- -

The functionality includes symmetric encryption, public key cryptography, key agreement, certificate handling, cryptographic hash functions, cryptographic pseudo-random number generators, message authentication codes (MACs), key derivation functions (KDFs), and various utilities.

- -

Algorithms

- -

Cryptographic primitives such as the SHA256 digest, or AES encryption are referred to in OpenSSL as "algorithms". Each algorithm may have multiple implementations available for use. For example the RSA algorithm is available as a "default" implementation suitable for general use, and a "fips" implementation which has been validated to FIPS 140 standards for situations where that is important. It is also possible that a third party could add additional implementations such as in a hardware security module (HSM).

- -

Algorithms are implemented in providers. See ossl-guide-libraries-introduction(7) for information about providers.

- -

Operations

- -

Different algorithms can be grouped together by their purpose. For example there are algorithms for encryption, and different algorithms for digesting data. These different groups are known as "operations" in OpenSSL. Each operation has a different set of functions associated with it. For example to perform an encryption operation using AES (or any other encryption algorithm) you would use the encryption functions detailed on the EVP_EncryptInit(3) page. Or to perform a digest operation using SHA256 then you would use the digesting functions on the EVP_DigestInit(3) page.

- -

ALGORITHM FETCHING

- -

In order to use an algorithm an implementation for it must first be "fetched". Fetching is the process of looking through the available implementations, applying selection criteria (via a property query string), and finally choosing the implementation that will be used.

- -

Two types of fetching are supported by OpenSSL - "Explicit fetching" and "Implicit fetching".

- -

Explicit fetching

- -

Explicit fetching involves directly calling a specific API to fetch an algorithm implementation from a provider. This fetched object can then be passed to other APIs. These explicit fetching functions usually have the name APINAME_fetch, where APINAME is the name of the operation. For example EVP_MD_fetch(3) can be used to explicitly fetch a digest algorithm implementation. The user is responsible for freeing the object returned from the APINAME_fetch function using APINAME_free when it is no longer needed.

- -

These fetching functions follow a fairly common pattern, where three arguments are passed:

- -
- -
The library context
-
- -

See OSSL_LIB_CTX(3) for a more detailed description. This may be NULL to signify the default (global) library context, or a context created by the user. Only providers loaded in this library context (see OSSL_PROVIDER_load(3)) will be considered by the fetching function. In case no provider has been loaded in this library context then the default provider will be loaded as a fallback (see OSSL_PROVIDER-default(7)).

- -
-
An identifier
-
- -

For all currently implemented fetching functions this is the algorithm name. Each provider supports a list of algorithm implementations. See the provider specific documentation for information on the algorithm implementations available in each provider: "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-default(7), "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-FIPS(7), "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-legacy(7) and "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-base(7).

- -

Note, while providers may register algorithms against a list of names using a string with a colon separated list of names, fetching algorithms using that format is currently unsupported.

- -
-
A property query string
-
- -

The property query string used to guide selection of the algorithm implementation. See "PROPERTY QUERY STRINGS" in ossl-guide-libraries-introduction(7).

- -
-
- -

The algorithm implementation that is fetched can then be used with other diverse functions that use them. For example the EVP_DigestInit_ex(3) function takes as a parameter an EVP_MD object which may have been returned from an earlier call to EVP_MD_fetch(3).

- -

Implicit fetching

- -

OpenSSL has a number of functions that return an algorithm object with no associated implementation, such as EVP_sha256(3), EVP_aes_128_cbc(3), EVP_get_cipherbyname(3) or EVP_get_digestbyname(3). These are present for compatibility with OpenSSL before version 3.0 where explicit fetching was not available.

- -

When they are used with functions like EVP_DigestInit_ex(3) or EVP_CipherInit_ex(3), the actual implementation to be used is fetched implicitly using default search criteria (which uses NULL for the library context and property query string).

- -

In some cases implicit fetching can also occur when a NULL algorithm parameter is supplied. In this case an algorithm implementation is implicitly fetched using default search criteria and an algorithm name that is consistent with the context in which it is being used.

- -

Functions that use an EVP_PKEY_CTX or an EVP_PKEY(3), such as EVP_DigestSignInit(3), all fetch the implementations implicitly. Usually the algorithm to fetch is determined based on the type of key that is being used and the function that has been called.

- -

Performance

- -

If you perform the same operation many times with the same algorithm then it is recommended to use a single explicit fetch of the algorithm and then reuse the explicitly fetched algorithm each subsequent time. This will typically be faster than implicitly fetching the algorithm every time you use it. See an example of Explicit fetching in "USING ALGORITHMS IN APPLICATIONS".

- -

Prior to OpenSSL 3.0, functions such as EVP_sha256() which return a "const" object were used directly to indicate the algorithm to use in various function calls. If you pass the return value of one of these convenience functions to an operation then you are using implicit fetching. If you are converting an application that worked with an OpenSSL version prior to OpenSSL 3.0 then consider changing instances of implicit fetching to explicit fetching instead.

- -

If an explicitly fetched object is not passed to an operation, then any implicit fetch will use an internally cached prefetched object, but it will still be slower than passing the explicitly fetched object directly.

- -

The following functions can be used for explicit fetching:

- -
- -
EVP_MD_fetch(3)
-
- -

Fetch a message digest/hashing algorithm implementation.

- -
-
EVP_CIPHER_fetch(3)
-
- -

Fetch a symmetric cipher algorithm implementation.

- -
-
EVP_KDF_fetch(3)
-
- -

Fetch a Key Derivation Function (KDF) algorithm implementation.

- -
-
EVP_MAC_fetch(3)
-
- -

Fetch a Message Authentication Code (MAC) algorithm implementation.

- -
-
EVP_KEM_fetch(3)
-
- -

Fetch a Key Encapsulation Mechanism (KEM) algorithm implementation

- -
-
OSSL_ENCODER_fetch(3)
-
- -

Fetch an encoder algorithm implementation (e.g. to encode keys to a specified format).

- -
-
OSSL_DECODER_fetch(3)
-
- -

Fetch a decoder algorithm implementation (e.g. to decode keys from a specified format).

- -
-
EVP_RAND_fetch(3)
-
- -

Fetch a Pseudo Random Number Generator (PRNG) algorithm implementation.

- -
-
- -

See "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-default(7), "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-FIPS(7), "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-legacy(7) and "OPERATIONS AND ALGORITHMS" in OSSL_PROVIDER-base(7) for a list of algorithm names that can be fetched.

- -

FETCHING EXAMPLES

- -

The following section provides a series of examples of fetching algorithm implementations.

- -

Fetch any available implementation of SHA2-256 in the default context. Note that some algorithms have aliases. So "SHA256" and "SHA2-256" are synonymous:

- -
EVP_MD *md = EVP_MD_fetch(NULL, "SHA2-256", NULL);
-...
-EVP_MD_free(md);
- -

Fetch any available implementation of AES-128-CBC in the default context:

- -
EVP_CIPHER *cipher = EVP_CIPHER_fetch(NULL, "AES-128-CBC", NULL);
-...
-EVP_CIPHER_free(cipher);
- -

Fetch an implementation of SHA2-256 from the default provider in the default context:

- -
EVP_MD *md = EVP_MD_fetch(NULL, "SHA2-256", "provider=default");
-...
-EVP_MD_free(md);
- -

Fetch an implementation of SHA2-256 that is not from the default provider in the default context:

- -
EVP_MD *md = EVP_MD_fetch(NULL, "SHA2-256", "provider!=default");
-...
-EVP_MD_free(md);
- -

Fetch an implementation of SHA2-256 that is preferably from the FIPS provider in the default context:

- -
EVP_MD *md = EVP_MD_fetch(NULL, "SHA2-256", "provider=?fips");
-...
-EVP_MD_free(md);
- -

Fetch an implementation of SHA2-256 from the default provider in the specified library context:

- -
EVP_MD *md = EVP_MD_fetch(libctx, "SHA2-256", "provider=default");
-...
-EVP_MD_free(md);
- -

Load the legacy provider into the default context and then fetch an implementation of WHIRLPOOL from it:

- -
/* This only needs to be done once - usually at application start up */
-OSSL_PROVIDER *legacy = OSSL_PROVIDER_load(NULL, "legacy");
-
-EVP_MD *md = EVP_MD_fetch(NULL, "WHIRLPOOL", "provider=legacy");
-...
-EVP_MD_free(md);
- -

Note that in the above example the property string "provider=legacy" is optional since, assuming no other providers have been loaded, the only implementation of the "whirlpool" algorithm is in the "legacy" provider. Also note that the default provider should be explicitly loaded if it is required in addition to other providers:

- -
/* This only needs to be done once - usually at application start up */
-OSSL_PROVIDER *legacy = OSSL_PROVIDER_load(NULL, "legacy");
-OSSL_PROVIDER *default = OSSL_PROVIDER_load(NULL, "default");
-
-EVP_MD *md_whirlpool = EVP_MD_fetch(NULL, "whirlpool", NULL);
-EVP_MD *md_sha256 = EVP_MD_fetch(NULL, "SHA2-256", NULL);
-...
-EVP_MD_free(md_whirlpool);
-EVP_MD_free(md_sha256);
- -

USING ALGORITHMS IN APPLICATIONS

- -

Cryptographic algorithms are made available to applications through use of the "EVP" APIs. Each of the various operations such as encryption, digesting, message authentication codes, etc., have a set of EVP function calls that can be invoked to use them. See the evp(7) page for further details.

- -

Most of these follow a common pattern. A "context" object is first created. For example for a digest operation you would use an EVP_MD_CTX, and for an encryption/decryption operation you would use an EVP_CIPHER_CTX. The operation is then initialised ready for use via an "init" function - optionally passing in a set of parameters (using the OSSL_PARAM(3) type) to configure how the operation should behave. Next data is fed into the operation in a series of "update" calls. The operation is finalised using a "final" call which will typically provide some kind of output. Finally the context is cleaned up and freed.

- -

The following shows a complete example for doing this process for digesting data using SHA256. The process is similar for other operations such as encryption/decryption, signatures, message authentication codes, etc. Additional examples can be found in the OpenSSL demos (see "DEMO APPLICATIONS" in ossl-guide-libraries-introduction(7)).

- -
#include <stdio.h>
-#include <openssl/evp.h>
-#include <openssl/bio.h>
-#include <openssl/err.h>
-
-int main(void)
-{
-    EVP_MD_CTX *ctx = NULL;
-    EVP_MD *sha256 = NULL;
-    const unsigned char msg[] = {
-        0x00, 0x01, 0x02, 0x03
-    };
-    unsigned int len = 0;
-    unsigned char *outdigest = NULL;
-    int ret = 1;
-
-    /* Create a context for the digest operation */
-    ctx = EVP_MD_CTX_new();
-    if (ctx == NULL)
-        goto err;
-
-    /*
-     * Fetch the SHA256 algorithm implementation for doing the digest. We're
-     * using the "default" library context here (first NULL parameter), and
-     * we're not supplying any particular search criteria for our SHA256
-     * implementation (second NULL parameter). Any SHA256 implementation will
-     * do.
-     * In a larger application this fetch would just be done once, and could
-     * be used for multiple calls to other operations such as EVP_DigestInit_ex().
-     */
-    sha256 = EVP_MD_fetch(NULL, "SHA256", NULL);
-    if (sha256 == NULL)
-        goto err;
-
-   /* Initialise the digest operation */
-   if (!EVP_DigestInit_ex(ctx, sha256, NULL))
-       goto err;
-
-    /*
-     * Pass the message to be digested. This can be passed in over multiple
-     * EVP_DigestUpdate calls if necessary
-     */
-    if (!EVP_DigestUpdate(ctx, msg, sizeof(msg)))
-        goto err;
-
-    /* Allocate the output buffer */
-    outdigest = OPENSSL_malloc(EVP_MD_get_size(sha256));
-    if (outdigest == NULL)
-        goto err;
-
-    /* Now calculate the digest itself */
-    if (!EVP_DigestFinal_ex(ctx, outdigest, &len))
-        goto err;
-
-    /* Print out the digest result */
-    BIO_dump_fp(stdout, outdigest, len);
-
-    ret = 0;
-
- err:
-    /* Clean up all the resources we allocated */
-    OPENSSL_free(outdigest);
-    EVP_MD_free(sha256);
-    EVP_MD_CTX_free(ctx);
-    if (ret != 0)
-       ERR_print_errors_fp(stderr);
-    return ret;
-}
- -

ENCODING AND DECODING KEYS

- -

Many algorithms require the use of a key. Keys can be generated dynamically using the EVP APIs (for example see EVP_PKEY_Q_keygen(3)). However it is often necessary to save or load keys (or their associated parameters) to or from some external format such as PEM or DER (see openssl-glossary(7)). OpenSSL uses encoders and decoders to perform this task.

- -

Encoders and decoders are just algorithm implementations in the same way as any other algorithm implementation in OpenSSL. They are implemented by providers. The OpenSSL encoders and decoders are available in the default provider. They are also duplicated in the base provider.

- -

For information about encoders see OSSL_ENCODER_CTX_new_for_pkey(3). For information about decoders see OSSL_DECODER_CTX_new_for_pkey(3).

- -

As well as using encoders/decoders directly there are also some helper functions that can be used for certain well known and commonly used formats. For example see PEM_read_PrivateKey(3) and PEM_write_PrivateKey(3) for information about reading and writing key data from PEM encoded files.

- -

FURTHER READING

- -

See ossl-guide-libssl-introduction(7) for an introduction to using libssl.

- -

SEE ALSO

- -

openssl(1), ssl(7), evp(7), OSSL_LIB_CTX(3), openssl-threads(7), property(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-base(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-legacy(7), OSSL_PROVIDER-null(7), openssl-glossary(7), provider(7)

- -

COPYRIGHT

- -

Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-libraries-introduction.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-libraries-introduction.html deleted file mode 100644 index db60be0f..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-libraries-introduction.html +++ /dev/null @@ -1,211 +0,0 @@ - - - - -ossl-guide-libraries-introduction - - - - - - - - - - -

NAME

- -

ossl-guide-libraries-introduction - OpenSSL Guide: An introduction to the OpenSSL libraries

- -

INTRODUCTION

- -

OpenSSL supplies two libraries that can be used by applications known as libcrypto and libssl.

- -

The libcrypto library provides APIs for general purpose cryptography such as encryption, digital signatures, hash functions, etc. It additionally supplies supporting APIs for cryptography related standards, e.g. for reading and writing digital certificates (also known as X.509 certificates). Finally it also supplies various additional supporting APIs that are not directly cryptography related but are nonetheless useful and depended upon by other APIs. For example the "BIO" functions provide capabilities for abstracting I/O, e.g. via a file or over a network.

- -

The libssl library provides functions to perform secure communication between two peers across a network. Most significantly it implements support for the SSL/TLS, DTLS and QUIC standards.

- -

The libssl library depends on and uses many of the capabilities supplied by libcrypto. Any application linked against libssl will also link against libcrypto, and most applications that do this will directly use API functions supplied by both libraries.

- -

Applications may be written that only use libcrypto capabilities and do not link against libssl at all.

- -

PROVIDERS

- -

As well as the two main libraries, OpenSSL also comes with a set of providers.

- -

A provider in OpenSSL is a component that collects together algorithm implementations (for example an implementation of the symmetric encryption algorithm AES). In order to use an algorithm you must have at least one provider loaded that contains an implementation of it. OpenSSL comes with a number of providers and they may also be obtained from third parties.

- -

Providers may either be "built-in" or in the form of a separate loadable module file (typically one ending in ".so" or ".dll" dependent on the platform). A built-in provider is one that is either already present in libcrypto or one that the application has supplied itself directly. Third parties can also supply providers in the form of loadable modules.

- -

If you don't load a provider explicitly (either in program code or via config) then the OpenSSL built-in "default" provider will be automatically loaded.

- -

See "OPENSSL PROVIDERS" below for a description of the providers that OpenSSL itself supplies.

- -

Loading and unloading providers is quite an expensive operation. It is normally done once, early on in the application lifecycle and those providers are kept loaded for the duration of the application execution.

- -

LIBRARY CONTEXTS

- -

Many OpenSSL API functions make use of a library context. A library context can be thought of as a "scope" within which configuration options take effect. When a provider is loaded, it is only loaded within the scope of a given library context. In this way it is possible for different components of a complex application to each use a different library context and have different providers loaded with different configuration settings.

- -

If an application does not explicitly create a library context then the "default" library context will be used.

- -

Library contexts are represented by the OSSL_LIB_CTX type. Many OpenSSL API functions take a library context as a parameter. Applications can always pass NULL for this parameter to just use the default library context.

- -

The default library context is automatically created the first time it is needed. This will automatically load any available configuration file and will initialise OpenSSL for use. Unlike in earlier versions of OpenSSL (prior to 1.1.0) no explicit initialisation steps need to be taken.

- -

Similarly when the application exits, the default library context is automatically destroyed. No explicit de-initialisation steps need to be taken.

- -

See OSSL_LIB_CTX(3) for more information about library contexts. See also "ALGORITHM FETCHING" in ossl-guide-libcrypto-introduction(7).

- -

PROPERTY QUERY STRINGS

- -

In some cases the available providers may mean that more than one implementation of any given algorithm might be available. For example the OpenSSL FIPS provider supplies alternative implementations of many of the same algorithms that are available in the OpenSSL default provider.

- -

The process of selecting an algorithm implementation is known as "fetching". When OpenSSL fetches an algorithm to use it is possible to specify a "property query string" to guide the selection process. For example a property query string of "provider=default" could be used to force the selection to only consider algorithm implementations in the default provider.

- -

Property query strings can be specified explicitly as an argument to a function. It is also possible to specify a default property query string for the whole library context using the EVP_set_default_properties(3) or EVP_default_properties_enable_fips(3) functions. Where both default properties and function specific properties are specified then they are combined. Function specific properties will override default properties where there is a conflict.

- -

See "ALGORITHM FETCHING" in ossl-guide-libcrypto-introduction(7) for more information about fetching. See property(7) for more information about properties.

- -

MULTI-THREADED APPLICATIONS

- -

As long as OpenSSL has been built with support for threads (the default case on most platforms) then most OpenSSL functions are thread-safe in the sense that it is safe to call the same function from multiple threads at the same time. However most OpenSSL data structures are not thread-safe. For example the BIO_write(3) and BIO_read(3) functions are thread safe. However it would not be thread safe to call BIO_write() from one thread while calling BIO_read() in another where both functions are passed the same BIO object since both of them may attempt to make changes to the same BIO object.

- -

There are exceptions to these rules. A small number of functions are not thread safe at all. Where this is the case this restriction should be noted in the documentation for the function. Similarly some data structures may be partially or fully thread safe. For example it is always safe to use an OSSL_LIB_CTX in multiple threads.

- -

See openssl-threads(7) for a more detailed discussion on OpenSSL threading support.

- -

ERROR HANDLING

- -

Most OpenSSL functions will provide a return value indicating whether the function has been successful or not. It is considered best practice to always check the return value from OpenSSL functions (where one is available).

- -

Most functions that return a pointer value will return NULL in the event of a failure.

- -

Most functions that return an integer value will return a positive integer for success. Some of these functions will return 0 to indicate failure. Others may return 0 or a negative value for failure.

- -

Some functions cannot fail and have a void return type. There are also a small number of functions that do not conform to the above conventions (e.g. they may return 0 to indicate success).

- -

Due to the above variations in behaviour it is important to check the documentation for each function for information about how to interpret the return value for it.

- -

It is sometimes necessary to get further information about the cause of a failure (e.g. for debugging or logging purposes). Many (but not all) functions will add further information about a failure to the OpenSSL error stack. By using the error stack you can find out information such as a reason code/string for the error as well as the exact file and source line within OpenSSL that emitted the error.

- -

OpenSSL supplies a set of error handling functions to query the error stack. See ERR_get_error(3) for information about the functions available for querying error data. Also see ERR_print_errors(3) for information on some simple helper functions for printing error data. Finally look at ERR_clear_error(3) for how to clear old errors from the error stack.

- -

OPENSSL PROVIDERS

- -

OpenSSL comes with a set of providers.

- -

The algorithms available in each of these providers may vary due to build time configuration options. The openssl-list(1) command can be used to list the currently available algorithms.

- -

The names of the algorithms shown from openssl-list(1) can be used as an algorithm identifier to the appropriate fetching function. Also see the provider specific manual pages linked below for further details about using the algorithms available in each of the providers.

- -

As well as the OpenSSL providers third parties can also implement providers. For information on writing a provider see provider(7).

- -

Default provider

- -

The default provider is built-in as part of the libcrypto library and contains all of the most commonly used algorithm implementations. Should it be needed (if other providers are loaded and offer implementations of the same algorithms), the property query string "provider=default" can be used as a search criterion for these implementations. The default provider includes all of the functionality in the base provider below.

- -

If you don't load any providers at all then the "default" provider will be automatically loaded. If you explicitly load any provider then the "default" provider would also need to be explicitly loaded if it is required.

- -

See OSSL_PROVIDER-default(7).

- -

Base provider

- -

The base provider is built in as part of the libcrypto library and contains algorithm implementations for encoding and decoding of OpenSSL keys. Should it be needed (if other providers are loaded and offer implementations of the same algorithms), the property query string "provider=base" can be used as a search criterion for these implementations. Some encoding and decoding algorithm implementations are not FIPS algorithm implementations in themselves but support algorithms from the FIPS provider and are allowed for use in "FIPS mode". The property query string "fips=yes" can be used to select such algorithms.

- -

See OSSL_PROVIDER-base(7).

- -

FIPS provider

- -

The FIPS provider is a dynamically loadable module, and must therefore be loaded explicitly, either in code or through OpenSSL configuration (see config(5)). It contains algorithm implementations that have been validated according to FIPS standards. Should it be needed (if other providers are loaded and offer implementations of the same algorithms), the property query string "provider=fips" can be used as a search criterion for these implementations. All approved algorithm implementations in the FIPS provider can also be selected with the property "fips=yes". The FIPS provider may also contain non-approved algorithm implementations and these can be selected with the property "fips=no".

- -

Typically the "Base provider" will also need to be loaded because the FIPS provider does not support the encoding or decoding of keys.

- -

See OSSL_PROVIDER-FIPS(7) and fips_module(7).

- -

Legacy provider

- -

The legacy provider is a dynamically loadable module, and must therefore be loaded explicitly, either in code or through OpenSSL configuration (see config(5)). It contains algorithm implementations that are considered insecure, or are no longer in common use such as MD2 or RC4. Should it be needed (if other providers are loaded and offer implementations of the same algorithms), the property "provider=legacy" can be used as a search criterion for these implementations.

- -

See OSSL_PROVIDER-legacy(7).

- -

Null provider

- -

The null provider is built in as part of the libcrypto library. It contains no algorithms in it at all. When fetching algorithms the default provider will be automatically loaded if no other provider has been explicitly loaded. To prevent that from happening you can explicitly load the null provider.

- -

You can use this if you create your own library context and want to ensure that all API calls have correctly passed the created library context and are not accidentally using the default library context. Load the null provider into the default library context so that the default library context has no algorithm implementations available.

- -

See OSSL_PROVIDER-null(7).

- -

CONFIGURATION

- -

By default OpenSSL will load a configuration file when it is first used. This will set up various configuration settings within the default library context. Applications that create their own library contexts may optionally configure them with a config file using the OSSL_LIB_CTX_load_config(3) function.

- -

The configuration file can be used to automatically load providers and set up default property query strings.

- -

For information on the OpenSSL configuration file format see config(5).

- -

LIBRARY CONVENTIONS

- -

Many OpenSSL functions that "get" or "set" a value follow a naming convention using the numbers 0 and 1, i.e. "get0", "get1", "set0" and "set1". This can also apply to some functions that "add" a value to an existing set, i.e. "add0" and "add1".

- -

For example the functions:

- -
int X509_CRL_add0_revoked(X509_CRL *crl, X509_REVOKED *rev);
-int X509_add1_trust_object(X509 *x, const ASN1_OBJECT *obj);
- -

In the 0 version the ownership of the object is passed to (for an add or set) or retained by (for a get) the parent object. For example after calling the X509_CRL_add0_revoked() function above, ownership of the rev object is passed to the crl object. Therefore, after calling this function rev should not be freed directly. It will be freed implicitly when crl is freed.

- -

In the 1 version the ownership of the object is not passed to or retained by the parent object. Instead a copy or "up ref" of the object is performed. So after calling the X509_add1_trust_object() function above the application will still be responsible for freeing the obj value where appropriate.

- -

Many OpenSSL functions conform to a naming convention of the form CLASSNAME_func_name(). In this naming convention the CLASSNAME is the name of an OpenSSL data structure (given in capital letters) that the function is primarily operating on. The func_name portion of the name is usually in lowercase letters and indicates the purpose of the function.

- -

DEMO APPLICATIONS

- -

OpenSSL is distributed with a set of demo applications which provide some examples of how to use the various API functions. To look at them download the OpenSSL source code from the OpenSSL website (https://www.openssl.org/source/). Extract the downloaded .tar.gz file for the version of OpenSSL that you are using and look at the various files in the demos sub-directory.

- -

The Makefiles in the subdirectories give instructions on how to build and run the demo applications.

- -

FURTHER READING

- -

See ossl-guide-libcrypto-introduction(7) for a more detailed introduction to using libcrypto and ossl-guide-libssl-introduction(7) for more information on libssl.

- -

SEE ALSO

- -

openssl(1), ssl(7), evp(7), OSSL_LIB_CTX(3), openssl-threads(7), property(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-base(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-legacy(7), OSSL_PROVIDER-null(7), openssl-glossary(7), provider(7)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-libssl-introduction.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-libssl-introduction.html deleted file mode 100644 index d9c236c9..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-libssl-introduction.html +++ /dev/null @@ -1,96 +0,0 @@ - - - - -ossl-guide-libssl-introduction - - - - - - - - - - -

NAME

- -

ossl-guide-libssl-introduction, ssl - OpenSSL Guide: An introduction to libssl

- -

INTRODUCTION

- -

The OpenSSL libssl library provides implementations of several secure network communications protocols. Specifically it provides SSL/TLS (SSLv3, TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3), DTLS (DTLSv1 and DTLSv1.2) and QUIC (client side only). The library depends on libcrypto for its underlying cryptographic operations (see ossl-guide-libcrypto-introduction(7)).

- -

The set of APIs supplied by libssl is common across all of these different network protocols, so a developer familiar with writing applications using one of these protocols should be able to transition to using another with relative ease.

- -

An application written to use libssl will include the <openssl/ssl.h> header file and will typically use two main data structures, i.e. SSL and SSL_CTX.

- -

An SSL object is used to represent a connection to a remote peer. Once a connection with a remote peer has been established data can be exchanged with that peer.

- -

When using DTLS any data that is exchanged uses "datagram" semantics, i.e. the packets of data can be delivered in any order, and they are not guaranteed to arrive at all. In this case the SSL object used for the connection is also used for exchanging data with the peer.

- -

Both TLS and QUIC support the concept of a "stream" of data. Data sent via a stream is guaranteed to be delivered in order without any data loss. A stream can be uni- or bi-directional.

- -

SSL/TLS only supports one stream of data per connection and it is always bi-directional. In this case the SSL object used for the connection also represents that stream. See ossl-guide-tls-introduction(7) for more information.

- -

The QUIC protocol can support multiple streams per connection and they can be uni- or bi-directional. In this case an SSL object can represent the underlying connection, or a stream, or both. Where multiple streams are in use a separate SSL object is used for each one. See ossl-guide-quic-introduction(7) for more information.

- -

An SSL_CTX object is used to create the SSL object for the underlying connection. A single SSL_CTX object can be used to create many connections (each represented by a separate SSL object). Many API functions in libssl exist in two forms: one that takes an SSL_CTX and one that takes an SSL. Typically settings that you apply to the SSL_CTX will then be inherited by any SSL object that you create from it. Alternatively you can apply settings directly to the SSL object without affecting other SSL objects. Note that you should not normally make changes to an SSL_CTX after the first SSL object has been created from it.

- -

DATA STRUCTURES

- -

As well as SSL_CTX and SSL there are a number of other data structures that an application may need to use. They are summarised below.

- -
- -
SSL_METHOD (SSL Method)
-
- -

This structure is used to indicate the kind of connection you want to make, e.g. whether it is to represent the client or the server, and whether it is to use SSL/TLS, DTLS or QUIC (client only). It is passed as a parameter when creating the SSL_CTX.

- -
-
SSL_SESSION (SSL Session)
-
- -

After establishing a connection with a peer the agreed cryptographic material can be reused to create future connections with the same peer more rapidly. The set of data used for such a future connection establishment attempt is collected together into an SSL_SESSION object. A single successful connection with a peer may generate zero or more such SSL_SESSION objects for use in future connection attempts.

- -
-
SSL_CIPHER (SSL Cipher)
-
- -

During connection establishment the client and server agree upon cryptographic algorithms they are going to use for encryption and other uses. A single set of cryptographic algorithms that are to be used together is known as a ciphersuite. Such a set is represented by an SSL_CIPHER object.

- -

The set of available ciphersuites that can be used are configured in the SSL_CTX or SSL.

- -
-
- -

FURTHER READING

- -

See ossl-guide-tls-introduction(7) for an introduction to the SSL/TLS protocol and ossl-guide-quic-introduction(7) for an introduction to QUIC.

- -

See ossl-guide-libcrypto-introduction(7) for an introduction to libcrypto.

- -

SEE ALSO

- -

ossl-guide-libcrypto-introduction(7), ossl-guide-tls-introduction(7), ossl-guide-quic-introduction(7)

- -

COPYRIGHT

- -

Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-migration.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-migration.html deleted file mode 100644 index 6c64f8e6..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-migration.html +++ /dev/null @@ -1,1744 +0,0 @@ - - - - -ossl-guide-migration - - - - - - - - - - -

NAME

- -

ossl-guide-migration, migration_guide - OpenSSL Guide: Migrating from older OpenSSL versions

- -

SYNOPSIS

- -

See the individual manual pages for details.

- -

DESCRIPTION

- -

This guide details the changes required to migrate to new versions of OpenSSL. Currently this covers OpenSSL 3.0 & 3.1. For earlier versions refer to https://github.com/openssl/openssl/blob/master/CHANGES.md. For an overview of some of the key concepts introduced in OpenSSL 3.0 see crypto(7).

- -

OPENSSL 3.1

- -

Main Changes from OpenSSL 3.0

- -

The FIPS provider in OpenSSL 3.1 includes some non-FIPS validated algorithms, consequently the property query fips=yes is mandatory for applications that want to operate in a FIPS approved manner. The algorithms are:

- -
- -
Triple DES ECB
-
- -
-
Triple DES CBC
-
- -
-
EdDSA
-
- -
-
- -

There are no other changes requiring additional migration measures since OpenSSL 3.0.

- -

OPENSSL 3.0

- -

Main Changes from OpenSSL 1.1.1

- -

Major Release

- -

OpenSSL 3.0 is a major release and consequently any application that currently uses an older version of OpenSSL will at the very least need to be recompiled in order to work with the new version. It is the intention that the large majority of applications will work unchanged with OpenSSL 3.0 if those applications previously worked with OpenSSL 1.1.1. However this is not guaranteed and some changes may be required in some cases. Changes may also be required if applications need to take advantage of some of the new features available in OpenSSL 3.0 such as the availability of the FIPS module.

- -

License Change

- -

In previous versions, OpenSSL was licensed under the dual OpenSSL and SSLeay licenses (both licenses apply). From OpenSSL 3.0 this is replaced by the Apache License v2.

- -

Providers and FIPS support

- -

One of the key changes from OpenSSL 1.1.1 is the introduction of the Provider concept. Providers collect together and make available algorithm implementations. With OpenSSL 3.0 it is possible to specify, either programmatically or via a config file, which providers you want to use for any given application. OpenSSL 3.0 comes with 5 different providers as standard. Over time third parties may distribute additional providers that can be plugged into OpenSSL. All algorithm implementations available via providers are accessed through the "high level" APIs (for example those functions prefixed with EVP). They cannot be accessed using the "Low Level APIs".

- -

One of the standard providers available is the FIPS provider. This makes available FIPS validated cryptographic algorithms. The FIPS provider is disabled by default and needs to be enabled explicitly at configuration time using the enable-fips option. If it is enabled, the FIPS provider gets built and installed in addition to the other standard providers. No separate installation procedure is necessary. There is however a dedicated install_fips make target, which serves the special purpose of installing only the FIPS provider into an existing OpenSSL installation.

- -

Not all algorithms may be available for the application at a particular moment. If the application code uses any digest or cipher algorithm via the EVP interface, the application should verify the result of the EVP_EncryptInit(3), EVP_EncryptInit_ex(3), and EVP_DigestInit(3) functions. In case when the requested algorithm is not available, these functions will fail.

- -

See also "Legacy Algorithms" for information on the legacy provider.

- -

See also "Completing the installation of the FIPS Module" and "Using the FIPS Module in applications".

- -

Low Level APIs

- -

OpenSSL has historically provided two sets of APIs for invoking cryptographic algorithms: the "high level" APIs (such as the EVP APIs) and the "low level" APIs. The high level APIs are typically designed to work across all algorithm types. The "low level" APIs are targeted at a specific algorithm implementation. For example, the EVP APIs provide the functions EVP_EncryptInit_ex(3), EVP_EncryptUpdate(3) and EVP_EncryptFinal(3) to perform symmetric encryption. Those functions can be used with the algorithms AES, CHACHA, 3DES etc. On the other hand, to do AES encryption using the low level APIs you would have to call AES specific functions such as AES_set_encrypt_key(3), AES_encrypt(3), and so on. The functions for 3DES are different. Use of the low level APIs has been informally discouraged by the OpenSSL development team for a long time. However in OpenSSL 3.0 this is made more formal. All such low level APIs have been deprecated. You may still use them in your applications, but you may start to see deprecation warnings during compilation (dependent on compiler support for this). Deprecated APIs may be removed from future versions of OpenSSL so you are strongly encouraged to update your code to use the high level APIs instead.

- -

This is described in more detail in "Deprecation of Low Level Functions"

- -

Legacy Algorithms

- -

Some cryptographic algorithms such as MD2 and DES that were available via the EVP APIs are now considered legacy and their use is strongly discouraged. These legacy EVP algorithms are still available in OpenSSL 3.0 but not by default. If you want to use them then you must load the legacy provider. This can be as simple as a config file change, or can be done programmatically. See OSSL_PROVIDER-legacy(7) for a complete list of algorithms. Applications using the EVP APIs to access these algorithms should instead use more modern algorithms. If that is not possible then these applications should ensure that the legacy provider has been loaded. This can be achieved either programmatically or via configuration. See crypto(7) man page for more information about providers.

- -

Engines and "METHOD" APIs

- -

The refactoring to support Providers conflicts internally with the APIs used to support engines, including the ENGINE API and any function that creates or modifies custom "METHODS" (for example EVP_MD_meth_new(3), EVP_CIPHER_meth_new(3), EVP_PKEY_meth_new(3), RSA_meth_new(3), EC_KEY_METHOD_new(3), etc.). These functions are being deprecated in OpenSSL 3.0, and users of these APIs should know that their use can likely bypass provider selection and configuration, with unintended consequences. This is particularly relevant for applications written to use the OpenSSL 3.0 FIPS module, as detailed below. Authors and maintainers of external engines are strongly encouraged to refactor their code transforming engines into providers using the new Provider API and avoiding deprecated methods.

- -

Support of legacy engines

- -

If openssl is not built without engine support or deprecated API support, engines will still work. However, their applicability will be limited.

- -

New algorithms provided via engines will still work.

- -

Engine-backed keys can be loaded via custom OSSL_STORE implementation. In this case the EVP_PKEY objects created via ENGINE_load_private_key(3) will be considered legacy and will continue to work.

- -

To ensure the future compatibility, the engines should be turned to providers. To prefer the provider-based hardware offload, you can specify the default properties to prefer your provider.

- -

Setting engine-based or application-based default low-level crypto method such as RSA_METHOD or EC_KEY_METHOD is still possible and keys inside the default provider will use the engine-based implementation for the crypto operations. However EVP_PKEYs created by decoding by using OSSL_DECODER, PEM_ or d2i_ APIs will be provider-based. To create a fully legacy EVP_PKEYs EVP_PKEY_set1_RSA(3), EVP_PKEY_set1_EC_KEY(3) or similar functions must be used.

- -

Versioning Scheme

- -

The OpenSSL versioning scheme has changed with the OpenSSL 3.0 release. The new versioning scheme has this format:

- -

MAJOR.MINOR.PATCH

- -

For OpenSSL 1.1.1 and below, different patch levels were indicated by a letter at the end of the release version number. This will no longer be used and instead the patch level is indicated by the final number in the version. A change in the second (MINOR) number indicates that new features may have been added. OpenSSL versions with the same major number are API and ABI compatible. If the major number changes then API and ABI compatibility is not guaranteed.

- -

For more information, see OpenSSL_version(3).

- -

Other major new features

- -

Certificate Management Protocol (CMP, RFC 4210)

- -

This also covers CRMF (RFC 4211) and HTTP transfer (RFC 6712) See openssl-cmp(1) and OSSL_CMP_exec_certreq(3) as starting points.

- -

HTTP(S) client

- -

A proper HTTP(S) client that supports GET and POST, redirection, plain and ASN.1-encoded contents, proxies, and timeouts.

- -

Key Derivation Function API (EVP_KDF)

- -

This simplifies the process of adding new KDF and PRF implementations.

- -

Previously KDF algorithms had been shoe-horned into using the EVP_PKEY object which was not a logical mapping. Existing applications that use KDF algorithms using EVP_PKEY (scrypt, TLS1 PRF and HKDF) may be slower as they use an EVP_KDF bridge internally. All new applications should use the new EVP_KDF(3) interface. See also "Key Derivation Function (KDF)" in OSSL_PROVIDER-default(7) and "Key Derivation Function (KDF)" in OSSL_PROVIDER-FIPS(7).

- -

Message Authentication Code API (EVP_MAC)

- -

This simplifies the process of adding MAC implementations.

- -

This includes a generic EVP_PKEY to EVP_MAC bridge, to facilitate the continued use of MACs through raw private keys in functionality such as EVP_DigestSign(3) and EVP_DigestVerify(3).

- -

All new applications should use the new EVP_MAC(3) interface. See also "Message Authentication Code (MAC)" in OSSL_PROVIDER-default(7) and "Message Authentication Code (MAC)" in OSSL_PROVIDER-FIPS(7).

- -

Algorithm Fetching

- -

Using calls to convenience functions such as EVP_sha256() and EVP_aes_256_gcm() may incur a performance penalty when using providers. Retrieving algorithms from providers involves searching for an algorithm by name. This is much slower than directly accessing a method table. It is recommended to prefetch algorithms if an algorithm is used many times. See "Performance" in crypto(7), "Explicit fetching" in crypto(7) and "Implicit fetching" in crypto(7).

- -

Support for Linux Kernel TLS

- -

In order to use KTLS, support for it must be compiled in using the enable-ktls configuration option. It must also be enabled at run time using the SSL_OP_ENABLE_KTLS option.

- -

New Algorithms

- -
    - -
  • KDF algorithms "SINGLE STEP" and "SSH"

    - -

    See EVP_KDF-SS(7) and EVP_KDF-SSHKDF(7)

    - -
  • -
  • MAC Algorithms "GMAC" and "KMAC"

    - -

    See EVP_MAC-GMAC(7) and EVP_MAC-KMAC(7).

    - -
  • -
  • KEM Algorithm "RSASVE"

    - -

    See EVP_KEM-RSA(7).

    - -
  • -
  • Cipher Algorithm "AES-SIV"

    - -

    See "SIV Mode" in EVP_EncryptInit(3).

    - -
  • -
  • AES Key Wrap inverse ciphers supported by EVP layer.

    - -

    The inverse ciphers use AES decryption for wrapping, and AES encryption for unwrapping. The algorithms are: "AES-128-WRAP-INV", "AES-192-WRAP-INV", "AES-256-WRAP-INV", "AES-128-WRAP-PAD-INV", "AES-192-WRAP-PAD-INV" and "AES-256-WRAP-PAD-INV".

    - -
  • -
  • CTS ciphers added to EVP layer.

    - -

    The algorithms are "AES-128-CBC-CTS", "AES-192-CBC-CTS", "AES-256-CBC-CTS", "CAMELLIA-128-CBC-CTS", "CAMELLIA-192-CBC-CTS" and "CAMELLIA-256-CBC-CTS". CS1, CS2 and CS3 variants are supported.

    - -
  • -
- -

CMS and PKCS#7 updates

- -
    - -
  • Added CAdES-BES signature verification support.

    - -
  • -
  • Added CAdES-BES signature scheme and attributes support (RFC 5126) to CMS API.

    - -
  • -
  • Added AuthEnvelopedData content type structure (RFC 5083) using AES_GCM

    - -

    This uses the AES-GCM parameter (RFC 5084) for the Cryptographic Message Syntax. Its purpose is to support encryption and decryption of a digital envelope that is both authenticated and encrypted using AES GCM mode.

    - -
  • -
  • PKCS7_get_octet_string(3) and PKCS7_type_is_other(3) were made public.

    - -
  • -
- -

PKCS#12 API updates

- -

The default algorithms for pkcs12 creation with the PKCS12_create() function were changed to more modern PBKDF2 and AES based algorithms. The default MAC iteration count was changed to PKCS12_DEFAULT_ITER to make it equal with the password-based encryption iteration count. The default digest algorithm for the MAC computation was changed to SHA-256. The pkcs12 application now supports -legacy option that restores the previous default algorithms to support interoperability with legacy systems.

- -

Added enhanced PKCS#12 APIs which accept a library context OSSL_LIB_CTX and (where relevant) a property query. Other APIs which handle PKCS#7 and PKCS#8 objects have also been enhanced where required. This includes:

- -

PKCS12_add_key_ex(3), PKCS12_add_safe_ex(3), PKCS12_add_safes_ex(3), PKCS12_create_ex(3), PKCS12_decrypt_skey_ex(3), PKCS12_init_ex(3), PKCS12_item_decrypt_d2i_ex(3), PKCS12_item_i2d_encrypt_ex(3), PKCS12_key_gen_asc_ex(3), PKCS12_key_gen_uni_ex(3), PKCS12_key_gen_utf8_ex(3), PKCS12_pack_p7encdata_ex(3), PKCS12_pbe_crypt_ex(3), PKCS12_PBE_keyivgen_ex(3), PKCS12_SAFEBAG_create_pkcs8_encrypt_ex(3), PKCS5_pbe2_set_iv_ex(3), PKCS5_pbe_set0_algor_ex(3), PKCS5_pbe_set_ex(3), PKCS5_pbkdf2_set_ex(3), PKCS5_v2_PBE_keyivgen_ex(3), PKCS5_v2_scrypt_keyivgen_ex(3), PKCS8_decrypt_ex(3), PKCS8_encrypt_ex(3), PKCS8_set0_pbe_ex(3).

- -

As part of this change the EVP_PBE_xxx APIs can also accept a library context and property query and will call an extended version of the key/IV derivation function which supports these parameters. This includes EVP_PBE_CipherInit_ex(3), EVP_PBE_find_ex(3) and EVP_PBE_scrypt_ex(3).

- -

PKCS#12 KDF versus FIPS

- -

Unlike in 1.x.y, the PKCS12KDF algorithm used when a PKCS#12 structure is created with a MAC that does not work with the FIPS provider as the PKCS12KDF is not a FIPS approvable mechanism.

- -

See EVP_KDF-PKCS12KDF(7), PKCS12_create(3), openssl-pkcs12(1), OSSL_PROVIDER-FIPS(7).

- -

Windows thread synchronization changes

- -

Windows thread synchronization uses read/write primitives (SRWLock) when supported by the OS, otherwise CriticalSection continues to be used.

- -

Trace API

- -

A new generic trace API has been added which provides support for enabling instrumentation through trace output. This feature is mainly intended as an aid for developers and is disabled by default. To utilize it, OpenSSL needs to be configured with the enable-trace option.

- -

If the tracing API is enabled, the application can activate trace output by registering BIOs as trace channels for a number of tracing and debugging categories. See OSSL_trace_enabled(3).

- -

Key validation updates

- -

EVP_PKEY_public_check(3) and EVP_PKEY_param_check(3) now work for more key types. This includes RSA, DSA, ED25519, X25519, ED448 and X448. Previously (in 1.1.1) they would return -2. For key types that do not have parameters then EVP_PKEY_param_check(3) will always return 1.

- -

Other notable deprecations and changes

- -

The function code part of an OpenSSL error code is no longer relevant

- -

This code is now always set to zero. Related functions are deprecated.

- -

STACK and HASH macros have been cleaned up

- -

The type-safe wrappers are declared everywhere and implemented once. See DEFINE_STACK_OF(3) and DEFINE_LHASH_OF_EX(3).

- -

The RAND_DRBG subsystem has been removed

- -

The new EVP_RAND(3) is a partial replacement: the DRBG callback framework is absent. The RAND_DRBG API did not fit well into the new provider concept as implemented by EVP_RAND and EVP_RAND_CTX.

- -

Removed FIPS_mode() and FIPS_mode_set()

- -

These functions are legacy APIs that are not applicable to the new provider model. Applications should instead use EVP_default_properties_is_fips_enabled(3) and EVP_default_properties_enable_fips(3).

- -

Key generation is slower

- -

The Miller-Rabin test now uses 64 rounds, which is used for all prime generation, including RSA key generation. This affects the time for larger keys sizes.

- -

The default key generation method for the regular 2-prime RSA keys was changed to the FIPS186-4 B.3.6 method (Generation of Probable Primes with Conditions Based on Auxiliary Probable Primes). This method is slower than the original method.

- -

Change PBKDF2 to conform to SP800-132 instead of the older PKCS5 RFC2898

- -

This checks that the salt length is at least 128 bits, the derived key length is at least 112 bits, and that the iteration count is at least 1000. For backwards compatibility these checks are disabled by default in the default provider, but are enabled by default in the FIPS provider.

- -

To enable or disable the checks see OSSL_KDF_PARAM_PKCS5 in EVP_KDF-PBKDF2(7). The parameter can be set using EVP_KDF_derive(3).

- -

Enforce a minimum DH modulus size of 512 bits

- -

Smaller sizes now result in an error.

- -

SM2 key changes

- -

EC EVP_PKEYs with the SM2 curve have been reworked to automatically become EVP_PKEY_SM2 rather than EVP_PKEY_EC.

- -

Unlike in previous OpenSSL versions, this means that applications cannot call EVP_PKEY_set_alias_type(pkey, EVP_PKEY_SM2) to get SM2 computations.

- -

Parameter and key generation is also reworked to make it possible to generate EVP_PKEY_SM2 parameters and keys. Applications must now generate SM2 keys directly and must not create an EVP_PKEY_EC key first. It is no longer possible to import an SM2 key with domain parameters other than the SM2 elliptic curve ones.

- -

Validation of SM2 keys has been separated from the validation of regular EC keys, allowing to improve the SM2 validation process to reject loaded private keys that are not conforming to the SM2 ISO standard. In particular, a private scalar k outside the range 1 <= k < n-1 is now correctly rejected.

- -

EVP_PKEY_set_alias_type() method has been removed

- -

This function made a EVP_PKEY object mutable after it had been set up. In OpenSSL 3.0 it was decided that a provided key should not be able to change its type, so this function has been removed.

- -

Functions that return an internal key should be treated as read only

- -

Functions such as EVP_PKEY_get0_RSA(3) behave slightly differently in OpenSSL 3.0. Previously they returned a pointer to the low-level key used internally by libcrypto. From OpenSSL 3.0 this key may now be held in a provider. Calling these functions will only return a handle on the internal key where the EVP_PKEY was constructed using this key in the first place, for example using a function or macro such as EVP_PKEY_assign_RSA(3), EVP_PKEY_set1_RSA(3), etc. Where the EVP_PKEY holds a provider managed key, then these functions now return a cached copy of the key. Changes to the internal provider key that take place after the first time the cached key is accessed will not be reflected back in the cached copy. Similarly any changes made to the cached copy by application code will not be reflected back in the internal provider key.

- -

For the above reasons the keys returned from these functions should typically be treated as read-only. To emphasise this the value returned from EVP_PKEY_get0_RSA(3), EVP_PKEY_get0_DSA(3), EVP_PKEY_get0_EC_KEY(3) and EVP_PKEY_get0_DH(3) have been made const. This may break some existing code. Applications broken by this change should be modified. The preferred solution is to refactor the code to avoid the use of these deprecated functions. Failing this the code should be modified to use a const pointer instead. The EVP_PKEY_get1_RSA(3), EVP_PKEY_get1_DSA(3), EVP_PKEY_get1_EC_KEY(3) and EVP_PKEY_get1_DH(3) functions continue to return a non-const pointer to enable them to be "freed". However they should also be treated as read-only.

- -

The public key check has moved from EVP_PKEY_derive() to EVP_PKEY_derive_set_peer()

- -

This may mean result in an error in EVP_PKEY_derive_set_peer(3) rather than during EVP_PKEY_derive(3). To disable this check use EVP_PKEY_derive_set_peer_ex(dh, peer, 0).

- -

The print format has cosmetic changes for some functions

- -

The output from numerous "printing" functions such as X509_signature_print(3), X509_print_ex(3), X509_CRL_print_ex(3), and other similar functions has been amended such that there may be cosmetic differences between the output observed in 1.1.1 and 3.0. This also applies to the -text output from the openssl x509 and openssl crl applications.

- -

Interactive mode from the openssl program has been removed

- -

From now on, running it without arguments is equivalent to openssl help.

- -

The error return values from some control calls (ctrl) have changed

- -

One significant change is that controls which used to return -2 for invalid inputs, now return -1 indicating a generic error condition instead.

- -

DH and DHX key types have different settable parameters

- -

Previously (in 1.1.1) these conflicting parameters were allowed, but will now result in errors. See EVP_PKEY-DH(7) for further details. This affects the behaviour of openssl-genpkey(1) for DH parameter generation.

- -

EVP_CIPHER_CTX_set_flags() ordering change

- -

If using a cipher from a provider the EVP_CIPH_FLAG_LENGTH_BITS flag can only be set after the cipher has been assigned to the cipher context. See "FLAGS" in EVP_EncryptInit(3) for more information.

- -

Validation of operation context parameters

- -

Due to move of the implementation of cryptographic operations to the providers, validation of various operation parameters can be postponed until the actual operation is executed where previously it happened immediately when an operation parameter was set.

- -

For example when setting an unsupported curve with EVP_PKEY_CTX_set_ec_paramgen_curve_nid() this function call will not fail but later keygen operations with the EVP_PKEY_CTX will fail.

- -

Removal of function code from the error codes

- -

The function code part of the error code is now always set to 0. For that reason the ERR_GET_FUNC() macro was removed. Applications must resolve the error codes only using the library number and the reason code.

- -

ChaCha20-Poly1305 cipher does not allow a truncated IV length to be used

- -

In OpenSSL 3.0 setting the IV length to any value other than 12 will result in an error. Prior to OpenSSL 3.0 the ivlen could be smaller that the required 12 byte length, using EVP_CIPHER_CTX_ctrl(ctx, EVP_CRTL_AEAD_SET_IVLEN, ivlen, NULL). This resulted in an IV that had leading zero padding.

- -

Installation and Compilation

- -

Please refer to the INSTALL.md file in the top of the distribution for instructions on how to build and install OpenSSL 3.0. Please also refer to the various platform specific NOTES files for your specific platform.

- -

Upgrading from OpenSSL 1.1.1

- -

Upgrading to OpenSSL 3.0 from OpenSSL 1.1.1 should be relatively straight forward in most cases. The most likely area where you will encounter problems is if you have used low level APIs in your code (as discussed above). In that case you are likely to start seeing deprecation warnings when compiling your application. If this happens you have 3 options:

- -
    - -
  1. Ignore the warnings. They are just warnings. The deprecated functions are still present and you may still use them. However be aware that they may be removed from a future version of OpenSSL.

    - -
  2. -
  3. Suppress the warnings. Refer to your compiler documentation on how to do this.

    - -
  4. -
  5. Remove your usage of the low level APIs. In this case you will need to rewrite your code to use the high level APIs instead

    - -
  6. -
- -

Error code changes

- -

As OpenSSL 3.0 provides a brand new Encoder/Decoder mechanism for working with widely used file formats, application code that checks for particular error reason codes on key loading failures might need an update.

- -

Password-protected keys may deserve special attention. If only some errors are treated as an indicator that the user should be asked about the password again, it's worth testing these scenarios and processing the newly relevant codes.

- -

There may be more cases to treat specially, depending on the calling application code.

- -

Upgrading from OpenSSL 1.0.2

- -

Upgrading to OpenSSL 3.0 from OpenSSL 1.0.2 is likely to be significantly more difficult. In addition to the issues discussed above in the section about "Upgrading from OpenSSL 1.1.1", the main things to be aware of are:

- -
    - -
  1. The build and installation procedure has changed significantly.

    - -

    Check the file INSTALL.md in the top of the installation for instructions on how to build and install OpenSSL for your platform. Also read the various NOTES files in the same directory, as applicable for your platform.

    - -
  2. -
  3. Many structures have been made opaque in OpenSSL 3.0.

    - -

    The structure definitions have been removed from the public header files and moved to internal header files. In practice this means that you can no longer stack allocate some structures. Instead they must be heap allocated through some function call (typically those function names have a _new suffix to them). Additionally you must use "setter" or "getter" functions to access the fields within those structures.

    - -

    For example code that previously looked like this:

    - -
    EVP_MD_CTX md_ctx;
    -
    -/* This line will now generate compiler errors */
    -EVP_MD_CTX_init(&md_ctx);
    - -

    The code needs to be amended to look like this:

    - -
    EVP_MD_CTX *md_ctx;
    -
    -md_ctx = EVP_MD_CTX_new();
    -...
    -...
    -EVP_MD_CTX_free(md_ctx);
    - -
  4. -
  5. Support for TLSv1.3 has been added.

    - -

    This has a number of implications for SSL/TLS applications. See the TLS1.3 page for further details.

    - -
  6. -
- -

More details about the breaking changes between OpenSSL versions 1.0.2 and 1.1.0 can be found on the OpenSSL 1.1.0 Changes page.

- -

Upgrading from the OpenSSL 2.0 FIPS Object Module

- -

The OpenSSL 2.0 FIPS Object Module was a separate download that had to be built separately and then integrated into your main OpenSSL 1.0.2 build. In OpenSSL 3.0 the FIPS support is fully integrated into the mainline version of OpenSSL and is no longer a separate download. For further information see "Completing the installation of the FIPS Module".

- -

The function calls FIPS_mode() and FIPS_mode_set() have been removed from OpenSSL 3.0. You should rewrite your application to not use them. See fips_module(7) and OSSL_PROVIDER-FIPS(7) for details.

- -

Completing the installation of the FIPS Module

- -

The FIPS Module will be built and installed automatically if FIPS support has been configured. The current documentation can be found in the README-FIPS file.

- -

Programming

- -

Applications written to work with OpenSSL 1.1.1 will mostly just work with OpenSSL 3.0. However changes will be required if you want to take advantage of some of the new features that OpenSSL 3.0 makes available. In order to do that you need to understand some new concepts introduced in OpenSSL 3.0. Read "Library contexts" in crypto(7) for further information.

- -

Library Context

- -

A library context allows different components of a complex application to each use a different library context and have different providers loaded with different configuration settings. See "Library contexts" in crypto(7) for further info.

- -

If the user creates an OSSL_LIB_CTX via OSSL_LIB_CTX_new(3) then many functions may need to be changed to pass additional parameters to handle the library context.

- -

Using a Library Context - Old functions that should be changed

- -

If a library context is needed then all EVP_* digest functions that return a const EVP_MD * such as EVP_sha256() should be replaced with a call to EVP_MD_fetch(3). See "ALGORITHM FETCHING" in crypto(7).

- -

If a library context is needed then all EVP_* cipher functions that return a const EVP_CIPHER * such as EVP_aes_128_cbc() should be replaced vith a call to EVP_CIPHER_fetch(3). See "ALGORITHM FETCHING" in crypto(7).

- -

Some functions can be passed an object that has already been set up with a library context such as d2i_X509(3), d2i_X509_CRL(3), d2i_X509_REQ(3) and d2i_X509_PUBKEY(3). If NULL is passed instead then the created object will be set up with the default library context. Use X509_new_ex(3), X509_CRL_new_ex(3), X509_REQ_new_ex(3) and X509_PUBKEY_new_ex(3) if a library context is required.

- -

All functions listed below with a NAME have a replacement function NAME_ex that takes OSSL_LIB_CTX as an additional argument. Functions that have other mappings are listed along with the respective name.

- - - -

New functions that use a Library context

- -

The following functions can be passed a library context if required. Passing NULL will use the default library context.

- - - -

Providers

- -

Providers are described in detail here "Providers" in crypto(7). See also "OPENSSL PROVIDERS" in crypto(7).

- -

Fetching algorithms and property queries

- -

Implicit and Explicit Fetching is described in detail here "ALGORITHM FETCHING" in crypto(7).

- -

Mapping EVP controls and flags to provider OSSL_PARAM(3) parameters

- -

The existing functions for controls (such as EVP_CIPHER_CTX_ctrl(3)) and manipulating flags (such as EVP_MD_CTX_set_flags(3))internally use OSSL_PARAMS to pass information to/from provider objects. See OSSL_PARAM(3) for additional information related to parameters.

- -

For ciphers see "CONTROLS" in EVP_EncryptInit(3), "FLAGS" in EVP_EncryptInit(3) and "PARAMETERS" in EVP_EncryptInit(3).

- -

For digests see "CONTROLS" in EVP_DigestInit(3), "FLAGS" in EVP_DigestInit(3) and "PARAMETERS" in EVP_DigestInit(3).

- -

Deprecation of Low Level Functions

- -

A significant number of APIs have been deprecated in OpenSSL 3.0. This section describes some common categories of deprecations. See "Deprecated function mappings" for the list of deprecated functions that refer to these categories.

- -

Providers are a replacement for engines and low-level method overrides

- -

Any accessor that uses an ENGINE is deprecated (such as EVP_PKEY_set1_engine()). Applications using engines should instead use providers.

- -

Before providers were added algorithms were overridden by changing the methods used by algorithms. All these methods such as RSA_new_method() and RSA_meth_new() are now deprecated and can be replaced by using providers instead.

- -

Deprecated i2d and d2i functions for low-level key types

- -

Any i2d and d2i functions such as d2i_DHparams() that take a low-level key type have been deprecated. Applications should instead use the OSSL_DECODER(3) and OSSL_ENCODER(3) APIs to read and write files. See "Migration" in d2i_RSAPrivateKey(3) for further details.

- -

Deprecated low-level key object getters and setters

- -

Applications that set or get low-level key objects (such as EVP_PKEY_set1_DH() or EVP_PKEY_get0()) should instead use the OSSL_ENCODER (See OSSL_ENCODER_to_bio(3)) or OSSL_DECODER (See OSSL_DECODER_from_bio(3)) APIs, or alternatively use EVP_PKEY_fromdata(3) or EVP_PKEY_todata(3).

- -

Deprecated low-level key parameter getters

- -

Functions that access low-level objects directly such as RSA_get0_n(3) are now deprecated. Applications should use one of EVP_PKEY_get_bn_param(3), EVP_PKEY_get_int_param(3), l<EVP_PKEY_get_size_t_param(3)>, EVP_PKEY_get_utf8_string_param(3), EVP_PKEY_get_octet_string_param(3) or EVP_PKEY_get_params(3) to access fields from an EVP_PKEY. Gettable parameters are listed in "Common RSA parameters" in EVP_PKEY-RSA(7), "DH parameters" in EVP_PKEY-DH(7), "DSA parameters" in EVP_PKEY-DSA(7), "FFC parameters" in EVP_PKEY-FFC(7), "Common EC parameters" in EVP_PKEY-EC(7) and "Common X25519, X448, ED25519 and ED448 parameters" in EVP_PKEY-X25519(7). Applications may also use EVP_PKEY_todata(3) to return all fields.

- -

Deprecated low-level key parameter setters

- -

Functions that access low-level objects directly such as RSA_set0_crt_params(3) are now deprecated. Applications should use EVP_PKEY_fromdata(3) to create new keys from user provided key data. Keys should be immutable once they are created, so if required the user may use EVP_PKEY_todata(3), OSSL_PARAM_merge(3), and EVP_PKEY_fromdata(3) to create a modified key. See "Examples" in EVP_PKEY-DH(7) for more information. See "Deprecated low-level key generation functions" for information on generating a key using parameters.

- -

Deprecated low-level object creation

- -

Low-level objects were created using methods such as RSA_new(3), RSA_up_ref(3) and RSA_free(3). Applications should instead use the high-level EVP_PKEY APIs, e.g. EVP_PKEY_new(3), EVP_PKEY_up_ref(3) and EVP_PKEY_free(3). See also EVP_PKEY_CTX_new_from_name(3) and EVP_PKEY_CTX_new_from_pkey(3).

- -

EVP_PKEYs may be created in a variety of ways: See also "Deprecated low-level key generation functions", "Deprecated low-level key reading and writing functions" and "Deprecated low-level key parameter setters".

- -

Deprecated low-level encryption functions

- -

Low-level encryption functions such as AES_encrypt(3) and AES_decrypt(3) have been informally discouraged from use for a long time. Applications should instead use the high level EVP APIs EVP_EncryptInit_ex(3), EVP_EncryptUpdate(3), and EVP_EncryptFinal_ex(3) or EVP_DecryptInit_ex(3), EVP_DecryptUpdate(3) and EVP_DecryptFinal_ex(3).

- -

Deprecated low-level digest functions

- -

Use of low-level digest functions such as SHA1_Init(3) have been informally discouraged from use for a long time. Applications should instead use the high level EVP APIs EVP_DigestInit_ex(3), EVP_DigestUpdate(3) and EVP_DigestFinal_ex(3), or the quick one-shot EVP_Q_digest(3).

- -

Note that the functions SHA1(3), SHA224(3), SHA256(3), SHA384(3) and SHA512(3) have changed to macros that use EVP_Q_digest(3).

- -

Deprecated low-level signing functions

- -

Use of low-level signing functions such as DSA_sign(3) have been informally discouraged for a long time. Instead applications should use EVP_DigestSign(3) and EVP_DigestVerify(3). See also EVP_SIGNATURE-RSA(7), EVP_SIGNATURE-DSA(7), EVP_SIGNATURE-ECDSA(7) and EVP_SIGNATURE-ED25519(7).

- -

Deprecated low-level MAC functions

- -

Low-level mac functions such as CMAC_Init(3) are deprecated. Applications should instead use the new EVP_MAC(3) interface, using EVP_MAC_CTX_new(3), EVP_MAC_CTX_free(3), EVP_MAC_init(3), EVP_MAC_update(3) and EVP_MAC_final(3) or the single-shot MAC function EVP_Q_mac(3). See EVP_MAC(3), EVP_MAC-HMAC(7), EVP_MAC-CMAC(7), EVP_MAC-GMAC(7), EVP_MAC-KMAC(7), EVP_MAC-BLAKE2(7), EVP_MAC-Poly1305(7) and EVP_MAC-Siphash(7) for additional information.

- -

Note that the one-shot method HMAC() is still available for compatibility purposes, but this can also be replaced by using EVP_Q_MAC if a library context is required.

- -

Deprecated low-level validation functions

- -

Low-level validation functions such as DH_check(3) have been informally discouraged from use for a long time. Applications should instead use the high-level EVP_PKEY APIs such as EVP_PKEY_check(3), EVP_PKEY_param_check(3), EVP_PKEY_param_check_quick(3), EVP_PKEY_public_check(3), EVP_PKEY_public_check_quick(3), EVP_PKEY_private_check(3), and EVP_PKEY_pairwise_check(3).

- -

Deprecated low-level key exchange functions

- -

Many low-level functions have been informally discouraged from use for a long time. Applications should instead use EVP_PKEY_derive(3). See EVP_KEYEXCH-DH(7), EVP_KEYEXCH-ECDH(7) and EVP_KEYEXCH-X25519(7).

- -

Deprecated low-level key generation functions

- -

Many low-level functions have been informally discouraged from use for a long time. Applications should instead use EVP_PKEY_keygen_init(3) and EVP_PKEY_generate(3) as described in EVP_PKEY-DSA(7), EVP_PKEY-DH(7), EVP_PKEY-RSA(7), EVP_PKEY-EC(7) and EVP_PKEY-X25519(7). The 'quick' one-shot function EVP_PKEY_Q_keygen(3) and macros for the most common cases: <EVP_RSA_gen(3)> and EVP_EC_gen(3) may also be used.

- -

Deprecated low-level key reading and writing functions

- -

Use of low-level objects (such as DSA) has been informally discouraged from use for a long time. Functions to read and write these low-level objects (such as PEM_read_DSA_PUBKEY()) should be replaced. Applications should instead use OSSL_ENCODER_to_bio(3) and OSSL_DECODER_from_bio(3).

- -

Deprecated low-level key printing functions

- -

Use of low-level objects (such as DSA) has been informally discouraged from use for a long time. Functions to print these low-level objects such as DSA_print() should be replaced with the equivalent EVP_PKEY functions. Application should use one of EVP_PKEY_print_public(3), EVP_PKEY_print_private(3), EVP_PKEY_print_params(3), EVP_PKEY_print_public_fp(3), EVP_PKEY_print_private_fp(3) or EVP_PKEY_print_params_fp(3). Note that internally these use OSSL_ENCODER_to_bio(3) and OSSL_DECODER_from_bio(3).

- -

Deprecated function mappings

- -

The following functions have been deprecated in 3.0.

- - - -

NID handling for provided keys and algorithms

- -

The following functions for NID (numeric id) handling have changed semantics.

- -
    - -
  • EVP_PKEY_id(), EVP_PKEY_get_id()

    - -

    This function was previously used to reliably return the NID of an EVP_PKEY object, e.g., to look up the name of the algorithm of such EVP_PKEY by calling OBJ_nid2sn(3). With the introduction of provider(7)s EVP_PKEY_id() or its new equivalent EVP_PKEY_get_id(3) might now also return the value -1 (EVP_PKEY_KEYMGMT) indicating the use of a provider to implement the EVP_PKEY object. Therefore, the use of EVP_PKEY_get0_type_name(3) is recommended for retrieving the name of the EVP_PKEY algorithm.

    - -
  • -
- -

Using the FIPS Module in applications

- -

See fips_module(7) and OSSL_PROVIDER-FIPS(7) for details.

- -

OpenSSL command line application changes

- -

New applications

- -

openssl kdf uses the new EVP_KDF(3) API. openssl kdf uses the new EVP_MAC(3) API.

- -

Added options

- -

-provider_path and -provider are available to all apps and can be used multiple times to load any providers, such as the 'legacy' provider or third party providers. If used then the 'default' provider would also need to be specified if required. The -provider_path must be specified before the -provider option.

- -

The list app has many new options. See openssl-list(1) for more information.

- -

-crl_lastupdate and -crl_nextupdate used by openssl ca allows explicit setting of fields in the generated CRL.

- -

Removed options

- -

Interactive mode is not longer available.

- -

The -crypt option used by openssl passwd. The -c option used by openssl x509, openssl dhparam, openssl dsaparam, and openssl ecparam.

- -

Other Changes

- -

The output of Command line applications may have minor changes. These are primarily changes in capitalisation and white space. However, in some cases, there are additional differences. For example, the DH parameters output from openssl dhparam now lists 'P', 'Q', 'G' and 'pcounter' instead of 'prime', 'generator', 'subgroup order' and 'counter' respectively.

- -

The openssl commands that read keys, certificates, and CRLs now automatically detect the PEM or DER format of the input files so it is not necessary to explicitly specify the input format anymore. However if the input format option is used the specified format will be required.

- -

openssl speed no longer uses low-level API calls. This implies some of the performance numbers might not be comparable with the previous releases due to higher overhead. This applies particularly to measuring performance on smaller data chunks.

- -

b<openssl dhparam>, openssl dsa, openssl gendsa, openssl dsaparam, openssl genrsa and openssl rsa have been modified to use PKEY APIs. openssl genrsa and openssl rsa now write PKCS #8 keys by default.

- -

Default settings

- -

"SHA256" is now the default digest for TS query used by openssl ts.

- -

Deprecated apps

- -

openssl rsautl is deprecated, use openssl pkeyutl instead. openssl dhparam, openssl dsa, openssl gendsa, openssl dsaparam, openssl genrsa, openssl rsa, openssl genrsa and openssl rsa are now in maintenance mode and no new features will be added to them.

- -

TLS Changes

- -
    - -
  • TLS 1.3 FFDHE key exchange support added

    - -

    This uses DH safe prime named groups.

    - -
  • -
  • Support for fully "pluggable" TLSv1.3 groups.

    - -

    This means that providers may supply their own group implementations (using either the "key exchange" or the "key encapsulation" methods) which will automatically be detected and used by libssl.

    - -
  • -
  • SSL and SSL_CTX options are now 64 bit instead of 32 bit.

    - -

    The signatures of the functions to get and set options on SSL and SSL_CTX objects changed from "unsigned long" to "uint64_t" type.

    - -

    This may require source code changes. For example it is no longer possible to use the SSL_OP_ macro values in preprocessor #if conditions. However it is still possible to test whether these macros are defined or not.

    - -

    See SSL_CTX_get_options(3), SSL_CTX_set_options(3), SSL_get_options(3) and SSL_set_options(3).

    - -
  • -
  • SSL_set1_host() and SSL_add1_host() Changes

    - -

    These functions now take IP literal addresses as well as actual hostnames.

    - -
  • -
  • Added SSL option SSL_OP_CLEANSE_PLAINTEXT

    - -

    If the option is set, openssl cleanses (zeroizes) plaintext bytes from internal buffers after delivering them to the application. Note, the application is still responsible for cleansing other copies (e.g.: data received by SSL_read(3)).

    - -
  • -
  • Client-initiated renegotiation is disabled by default.

    - -

    To allow it, use the -client_renegotiation option, the SSL_OP_ALLOW_CLIENT_RENEGOTIATION flag, or the ClientRenegotiation config parameter as appropriate.

    - -
  • -
  • Secure renegotiation is now required by default for TLS connections

    - -

    Support for RFC 5746 secure renegotiation is now required by default for SSL or TLS connections to succeed. Applications that require the ability to connect to legacy peers will need to explicitly set SSL_OP_LEGACY_SERVER_CONNECT. Accordingly, SSL_OP_LEGACY_SERVER_CONNECT is no longer set as part of SSL_OP_ALL.

    - -
  • -
  • Combining the Configure options no-ec and no-dh no longer disables TLSv1.3

    - -

    Typically if OpenSSL has no EC or DH algorithms then it cannot support connections with TLSv1.3. However OpenSSL now supports "pluggable" groups through providers. Therefore third party providers may supply group implementations even where there are no built-in ones. Attempting to create TLS connections in such a build without also disabling TLSv1.3 at run time or using third party provider groups may result in handshake failures. TLSv1.3 can be disabled at compile time using the "no-tls1_3" Configure option.

    - -
  • -
  • SSL_CTX_set_ciphersuites() and SSL_set_ciphersuites() changes.

    - -

    The methods now ignore unknown ciphers.

    - -
  • -
  • Security callback change.

    - -

    The security callback, which can be customised by application code, supports the security operation SSL_SECOP_TMP_DH. This is defined to take an EVP_PKEY in the "other" parameter. In most places this is what is passed. All these places occur server side. However there was one client side call of this security operation and it passed a DH object instead. This is incorrect according to the definition of SSL_SECOP_TMP_DH, and is inconsistent with all of the other locations. Therefore this client side call has been changed to pass an EVP_PKEY instead.

    - -
  • -
  • New SSL option SSL_OP_IGNORE_UNEXPECTED_EOF

    - -

    The SSL option SSL_OP_IGNORE_UNEXPECTED_EOF is introduced. If that option is set, an unexpected EOF is ignored, it pretends a close notify was received instead and so the returned error becomes SSL_ERROR_ZERO_RETURN.

    - -
  • -
  • The security strength of SHA1 and MD5 based signatures in TLS has been reduced.

    - -

    This results in SSL 3, TLS 1.0, TLS 1.1 and DTLS 1.0 no longer working at the default security level of 1 and instead requires security level 0. The security level can be changed either using the cipher string with @SECLEVEL, or calling SSL_CTX_set_security_level(3). This also means that where the signature algorithms extension is missing from a ClientHello then the handshake will fail in TLS 1.2 at security level 1. This is because, although this extension is optional, failing to provide one means that OpenSSL will fallback to a default set of signature algorithms. This default set requires the availability of SHA1.

    - -
  • -
  • X509 certificates signed using SHA1 are no longer allowed at security level 1 and above.

    - -

    In TLS/SSL the default security level is 1. It can be set either using the cipher string with @SECLEVEL, or calling SSL_CTX_set_security_level(3). If the leaf certificate is signed with SHA-1, a call to SSL_CTX_use_certificate(3) will fail if the security level is not lowered first. Outside TLS/SSL, the default security level is -1 (effectively 0). It can be set using X509_VERIFY_PARAM_set_auth_level(3) or using the -auth_level options of the commands.

    - -
  • -
- -

SEE ALSO

- -

fips_module(7)

- -

HISTORY

- -

The migration guide was created for OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-block.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-block.html deleted file mode 100644 index 4fde6816..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-block.html +++ /dev/null @@ -1,295 +0,0 @@ - - - - -ossl-guide-quic-client-block - - - - - - - - - - -

NAME

- -

ossl-guide-quic-client-block - OpenSSL Guide: Writing a simple blocking QUIC client

- -

SIMPLE BLOCKING QUIC CLIENT EXAMPLE

- -

This page will present various source code samples demonstrating how to write a simple blocking QUIC client application which connects to a server, sends an HTTP/1.0 request to it, and reads back the response. Note that HTTP/1.0 over QUIC is non-standard and will not be supported by real world servers. This is for demonstration purposes only.

- -

We assume that you already have OpenSSL installed on your system; that you already have some fundamental understanding of OpenSSL concepts, TLS and QUIC (see ossl-guide-libraries-introduction(7), ossl-guide-tls-introduction(7) and ossl-guide-quic-introduction(7)); and that you know how to write and build C code and link it against the libcrypto and libssl libraries that are provided by OpenSSL. It also assumes that you have a basic understanding of UDP/IP and sockets. The example code that we build in this tutorial will amend the blocking TLS client example that is covered in ossl-guide-tls-client-block(7). Only the differences between that client and this one will be discussed so we also assume that you have run through and understand that tutorial.

- -

For this tutorial our client will be using a single QUIC stream. A subsequent tutorial will discuss how to write a multi-stream client (see ossl-guide-quic-multi-stream(7)).

- -

The complete source code for this example blocking QUIC client is available in the demos/guide directory of the OpenSSL source distribution in the file quic-client-block.c. It is also available online at https://github.com/openssl/openssl/blob/master/demos/guide/quic-client-block.c.

- -

Creating the SSL_CTX and SSL objects

- -

In the TLS tutorial (ossl-guide-tls-client-block(7)) we created an SSL_CTX object for our client and used it to create an SSL object to represent the TLS connection. A QUIC connection works in exactly the same way. We first create an SSL_CTX object and then use it to create an SSL object to represent the QUIC connection.

- -

As in the TLS example the first step is to create an SSL_CTX object for our client. This is done in the same way as before except that we use a different "method". OpenSSL offers two different QUIC client methods, i.e. OSSL_QUIC_client_method(3) and OSSL_QUIC_client_thread_method(3).

- -

The first one is the equivalent of TLS_client_method(3) but for the QUIC protocol. The second one is the same, but it will additionally create a background thread for handling time based events (known as "thread assisted mode", see ossl-guide-quic-introduction(7)). For this tutorial we will be using OSSL_QUIC_client_method(3) because we will not be leaving the QUIC connection idle in our application and so thread assisted mode is not needed.

- -
/*
- * Create an SSL_CTX which we can use to create SSL objects from. We
- * want an SSL_CTX for creating clients so we use OSSL_QUIC_client_method()
- * here.
- */
-ctx = SSL_CTX_new(OSSL_QUIC_client_method());
-if (ctx == NULL) {
-    printf("Failed to create the SSL_CTX\n");
-    goto end;
-}
- -

The other setup steps that we applied to the SSL_CTX for TLS also apply to QUIC except for restricting the TLS versions that we are willing to accept. The QUIC protocol implementation in OpenSSL currently only supports TLSv1.3. There is no need to call SSL_CTX_set_min_proto_version(3) or SSL_CTX_set_max_proto_version(3) in an OpenSSL QUIC application, and any such call will be ignored.

- -

Once the SSL_CTX is created, the SSL object is constructed in exactly the same way as for the TLS application.

- -

Creating the socket and BIO

- -

A major difference between TLS and QUIC is the underlying transport protocol. TLS uses TCP while QUIC uses UDP. The way that the QUIC socket is created in our example code is much the same as for TLS. We use the BIO_lookup_ex(3) and BIO_socket(3) helper functions as we did in the previous tutorial except that we pass SOCK_DGRAM as an argument to indicate UDP (instead of SOCK_STREAM for TCP).

- -
/*
- * Lookup IP address info for the server.
- */
-if (!BIO_lookup_ex(hostname, port, BIO_LOOKUP_CLIENT, family, SOCK_DGRAM, 0,
-                   &res))
-    return NULL;
-
-/*
- * Loop through all the possible addresses for the server and find one
- * we can connect to.
- */
-for (ai = res; ai != NULL; ai = BIO_ADDRINFO_next(ai)) {
-    /*
-     * Create a TCP socket. We could equally use non-OpenSSL calls such
-     * as "socket" here for this and the subsequent connect and close
-     * functions. But for portability reasons and also so that we get
-     * errors on the OpenSSL stack in the event of a failure we use
-     * OpenSSL's versions of these functions.
-     */
-    sock = BIO_socket(BIO_ADDRINFO_family(ai), SOCK_DGRAM, 0, 0);
-    if (sock == -1)
-        continue;
-
-    /* Connect the socket to the server's address */
-    if (!BIO_connect(sock, BIO_ADDRINFO_address(ai), 0)) {
-        BIO_closesocket(sock);
-        sock = -1;
-        continue;
-    }
-
-    /* Set to nonblocking mode */
-    if (!BIO_socket_nbio(sock, 1)) {
-        BIO_closesocket(sock);
-        sock = -1;
-        continue;
-    }
-
-    break;
-}
-
-if (sock != -1) {
-    *peer_addr = BIO_ADDR_dup(BIO_ADDRINFO_address(ai));
-    if (*peer_addr == NULL) {
-        BIO_closesocket(sock);
-        return NULL;
-    }
-}
-
-/* Free the address information resources we allocated earlier */
-BIO_ADDRINFO_free(res);
- -

You may notice a couple of other differences between this code and the version that we used for TLS.

- -

Firstly, we set the socket into nonblocking mode. This must always be done for an OpenSSL QUIC application. This may be surprising considering that we are trying to write a blocking client. Despite this the SSL object will still have blocking behaviour. See ossl-guide-quic-introduction(7) for further information on this.

- -

Secondly, we take note of the IP address of the peer that we are connecting to. We store that information away. We will need it later.

- -

See BIO_lookup_ex(3), BIO_socket(3), BIO_connect(3), BIO_closesocket(3), BIO_ADDRINFO_next(3), BIO_ADDRINFO_address(3), BIO_ADDRINFO_free(3) and BIO_ADDR_dup(3) for further information on the functions used here. In the above example code the hostname and port variables are strings, e.g. "www.example.com" and "443".

- -

As for our TLS client, once the socket has been created and connected we need to associate it with a BIO object:

- -
BIO *bio;
-
-/* Create a BIO to wrap the socket */
-bio = BIO_new(BIO_s_datagram());
-if (bio == NULL) {
-    BIO_closesocket(sock);
-    return NULL;
-}
-
-/*
- * Associate the newly created BIO with the underlying socket. By
- * passing BIO_CLOSE here the socket will be automatically closed when
- * the BIO is freed. Alternatively you can use BIO_NOCLOSE, in which
- * case you must close the socket explicitly when it is no longer
- * needed.
- */
-BIO_set_fd(bio, sock, BIO_CLOSE);
- -

Note the use of BIO_s_datagram(3) here as opposed to BIO_s_socket(3) that we used for our TLS client. This is again due to the fact that QUIC uses UDP instead of TCP for its transport layer. See BIO_new(3), BIO_s_datagram(3) and BIO_set_fd(3) for further information on these functions.

- -

Setting the server's hostname

- -

As in the TLS tutorial we need to set the server's hostname both for SNI (Server Name Indication) and for certificate validation purposes. The steps for this are identical to the TLS tutorial and won't be repeated here.

- -

Setting the ALPN

- -

ALPN (Application-Layer Protocol Negotiation) is a feature of TLS that enables the application to negotiate which protocol will be used over the connection. For example, if you intend to use HTTP/3 over the connection then the ALPN value for that is "h3" (see https://www.iana.org/assignments/tls-extensiontype-values/tls-extensiontype-values.xml#alpn-protocol-ids). OpenSSL provides the ability for a client to specify the ALPN to use via the SSL_set_alpn_protos(3) function. This is optional for a TLS client and so our simple client that we developed in ossl-guide-tls-client-block(7) did not use it. However QUIC mandates that the TLS handshake used in establishing a QUIC connection must use ALPN.

- -
unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '0' };
-
-/* SSL_set_alpn_protos returns 0 for success! */
-if (SSL_set_alpn_protos(ssl, alpn, sizeof(alpn)) != 0) {
-    printf("Failed to set the ALPN for the connection\n");
-    goto end;
-}
- -

The ALPN is specified using a length prefixed array of unsigned chars (it is not a NUL terminated string). Our original TLS blocking client demo was using HTTP/1.0. We will use the same for this example. Unlike most OpenSSL functions SSL_set_alpn_protos(3) returns zero for success and nonzero for failure.

- -

Setting the peer address

- -

An OpenSSL QUIC application must specify the target address of the server that is being connected to. In "Creating the socket and BIO" above we saved that address away for future use. Now we need to use it via the SSL_set1_initial_peer_addr(3) function.

- -
/* Set the IP address of the remote peer */
-if (!SSL_set1_initial_peer_addr(ssl, peer_addr)) {
-    printf("Failed to set the initial peer address\n");
-    goto end;
-}
- -

Note that we will need to free the peer_addr value that we allocated via BIO_ADDR_dup(3) earlier:

- -
BIO_ADDR_free(peer_addr);
- -

The handshake and application data transfer

- -

Once initial setup of the SSL object is complete then we perform the handshake via SSL_connect(3) in exactly the same way as we did for the TLS client, so we won't repeat it here.

- -

We can also perform data transfer using a default QUIC stream that is automatically associated with the SSL object for us. We can transmit data using SSL_write_ex(3), and receive data using SSL_read_ex(3) in the same way as for TLS. The main difference is that we have to account for failures slightly differently. With QUIC the stream can be reset by the peer (which is fatal for that stream), but the underlying connection itself may still be healthy.

- -
/*
- * Get up to sizeof(buf) bytes of the response. We keep reading until the
- * server closes the connection.
- */
-while (SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) {
-    /*
-    * OpenSSL does not guarantee that the returned data is a string or
-    * that it is NUL terminated so we use fwrite() to write the exact
-    * number of bytes that we read. The data could be non-printable or
-    * have NUL characters in the middle of it. For this simple example
-    * we're going to print it to stdout anyway.
-    */
-    fwrite(buf, 1, readbytes, stdout);
-}
-/* In case the response didn't finish with a newline we add one now */
-printf("\n");
-
-/*
- * Check whether we finished the while loop above normally or as the
- * result of an error. The 0 argument to SSL_get_error() is the return
- * code we received from the SSL_read_ex() call. It must be 0 in order
- * to get here. Normal completion is indicated by SSL_ERROR_ZERO_RETURN. In
- * QUIC terms this means that the peer has sent FIN on the stream to
- * indicate that no further data will be sent.
- */
-switch (SSL_get_error(ssl, 0)) {
-case SSL_ERROR_ZERO_RETURN:
-    /* Normal completion of the stream */
-    break;
-
-case SSL_ERROR_SSL:
-    /*
-     * Some stream fatal error occurred. This could be because of a stream
-     * reset - or some failure occurred on the underlying connection.
-     */
-    switch (SSL_get_stream_read_state(ssl)) {
-    case SSL_STREAM_STATE_RESET_REMOTE:
-        printf("Stream reset occurred\n");
-        /* The stream has been reset but the connection is still healthy. */
-        break;
-
-    case SSL_STREAM_STATE_CONN_CLOSED:
-        printf("Connection closed\n");
-        /* Connection is already closed. Skip SSL_shutdown() */
-        goto end;
-
-    default:
-        printf("Unknown stream failure\n");
-        break;
-    }
-    break;
-
-default:
-    /* Some other unexpected error occurred */
-    printf ("Failed reading remaining data\n");
-    break;
-}
- -

In the above code example you can see that SSL_ERROR_SSL indicates a stream fatal error. We can use SSL_get_stream_read_state(3) to determine whether the stream has been reset, or if some other fatal error has occurred.

- -

Shutting down the connection

- -

In the TLS tutorial we knew that the server had finished sending data because SSL_read_ex(3) returned 0, and SSL_get_error(3) returned SSL_ERROR_ZERO_RETURN. The same is true with QUIC except that SSL_ERROR_ZERO_RETURN should be interpreted slightly differently. With TLS we knew that this meant that the server had sent a "close_notify" alert. No more data will be sent from the server on that connection.

- -

With QUIC it means that the server has indicated "FIN" on the stream, meaning that it will no longer send any more data on that stream. However this only gives us information about the stream itself and does not tell us anything about the underlying connection. More data could still be sent from the server on some other stream. Additionally, although the server will not send any more data to the client, it does not prevent the client from sending more data to the server.

- -

In this tutorial, once we have finished reading data from the server on the one stream that we are using, we will close the connection down. As before we do this via the SSL_shutdown(3) function. This example for QUIC is very similar to the TLS version. However the SSL_shutdown(3) function will need to be called more than once:

- -
/*
- * Repeatedly call SSL_shutdown() until the connection is fully
- * closed.
- */
-do {
-    ret = SSL_shutdown(ssl);
-    if (ret < 0) {
-        printf("Error shutting down: %d\n", ret);
-        goto end;
-    }
-} while (ret != 1);
- -

The shutdown process is in two stages. In the first stage we wait until all the data we have buffered for sending on any stream has been successfully sent and acknowledged by the peer, and then we send a CONNECTION_CLOSE to the peer to indicate that the connection is no longer usable. This immediately closes the connection and no more data can be sent or received. SSL_shutdown(3) returns 0 once the first stage has been completed.

- -

In the second stage the connection enters a "closing" state. Application data cannot be sent or received in this state, but late arriving packets coming from the peer will be handled appropriately. Once this stage has completed successfully SSL_shutdown(3) will return 1 to indicate success.

- -

FURTHER READING

- -

See ossl-guide-quic-multi-stream(7) to read a tutorial on how to modify the client developed on this page to support multiple streams.

- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7), ossl-guide-tls-introduction(7), ossl-guide-tls-client-block(7), ossl-guide-quic-introduction(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-non-block.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-non-block.html deleted file mode 100644 index db69a07d..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-client-non-block.html +++ /dev/null @@ -1,330 +0,0 @@ - - - - -ossl-guide-quic-client-non-block - - - - - - - - - - -

NAME

- -

ossl-guide-quic-client-non-block - OpenSSL Guide: Writing a simple nonblocking QUIC client

- -

SIMPLE NONBLOCKING QUIC CLIENT EXAMPLE

- -

This page will build on the example developed on the ossl-guide-quic-client-block(7) page which demonstrates how to write a simple blocking QUIC client. On this page we will amend that demo code so that it supports nonblocking functionality.

- -

The complete source code for this example nonblocking QUIC client is available in the demos/guide directory of the OpenSSL source distribution in the file quic-client-non-block.c. It is also available online at https://github.com/openssl/openssl/blob/master/demos/guide/quic-client-non-block.c.

- -

As we saw in the previous example an OpenSSL QUIC application always uses a nonblocking socket. However, despite this, the SSL object still has blocking behaviour. When the SSL object has blocking behaviour then this means that it waits (blocks) until data is available to read if you attempt to read from it when there is no data yet. Similarly it waits when writing if the SSL object is currently unable to write at the moment. This can simplify the development of code because you do not have to worry about what to do in these cases. The execution of the code will simply stop until it is able to continue. However in many cases you do not want this behaviour. Rather than stopping and waiting your application may need to go and do other tasks whilst the SSL object is unable to read/write, for example updating a GUI or performing operations on some other connection or stream.

- -

We will see later in this tutorial how to change the SSL object so that it has nonblocking behaviour. With a nonblocking SSL object, functions such as SSL_read_ex(3) or SSL_write_ex(3) will return immediately with a non-fatal error if they are currently unable to read or write respectively.

- -

Since this page is building on the example developed on the ossl-guide-quic-client-block(7) page we assume that you are familiar with it and we only explain how this example differs.

- -

Performing work while waiting for the socket

- -

In a nonblocking application you will need work to perform in the event that we want to read or write to the SSL object but we are currently unable to. In fact this is the whole point of using a nonblocking SSL object, i.e. to give the application the opportunity to do something else. Whatever it is that the application has to do, it must also be prepared to come back and retry the operation that it previously attempted periodically to see if it can now complete. Ideally it would only do this in the event that something has changed such that it might succeed on the retry attempt, but this does not have to be the case. It can retry at any time.

- -

Note that it is important that you retry exactly the same operation that you tried last time. You cannot start something new. For example if you were attempting to write the text "Hello World" and the operation failed because the SSL object is currently unable to write, then you cannot then attempt to write some other text when you retry the operation.

- -

In this demo application we will create a helper function which simulates doing other work. In fact, for the sake of simplicity, it will do nothing except wait for the state of the underlying socket to change or until a timeout expires after which the state of the SSL object might have changed. We will call our function wait_for_activity().

- -
    static void wait_for_activity(SSL *ssl)
-    {
-        fd_set wfds, rfds;
-        int width, sock, isinfinite;
-        struct timeval tv;
-        struct timeval *tvp = NULL;
-
-        /* Get hold of the underlying file descriptor for the socket */
-        sock = SSL_get_fd(ssl);
-
-        FD_ZERO(&wfds);
-        FD_ZERO(&rfds);
-
-        /*
-         * Find out if we would like to write to the socket, or read from it (or
-         * both)
-         */
-        if (SSL_net_write_desired(ssl))
-            FD_SET(sock, &wfds);
-        if (SSL_net_read_desired(ssl))
-            FD_SET(sock, &rfds);
-        width = sock + 1;
-
-        /*
-         * Find out when OpenSSL would next like to be called, regardless of
-         * whether the state of the underlying socket has changed or not.
-         */
-        if (SSL_get_event_timeout(ssl, &tv, &isinfinite) && !isinfinite)
-            tvp = &tv;
-
-        /*
-         * Wait until the socket is writeable or readable. We use select here
-         * for the sake of simplicity and portability, but you could equally use
-         * poll/epoll or similar functions
-         *
-         * NOTE: For the purposes of this demonstration code this effectively
-         * makes this demo block until it has something more useful to do. In a
-         * real application you probably want to go and do other work here (e.g.
-         * update a GUI, or service other connections).
-         *
-         * Let's say for example that you want to update the progress counter on
-         * a GUI every 100ms. One way to do that would be to use the timeout in
-         * the last parameter to "select" below. If the tvp value is greater
-         * than 100ms then use 100ms instead. Then, when select returns, you
-         * check if it did so because of activity on the file descriptors or
-         * because of the timeout. If the 100ms GUI timeout has expired but the
-         * tvp timeout has not then go and update the GUI and then restart the
-         * "select" (with updated timeouts).
-         */
-
-        select(width, &rfds, &wfds, NULL, tvp);
-}
- -

If you are familiar with how to write nonblocking applications in OpenSSL for TLS (see ossl-guide-tls-client-non-block(7)) then you should note that there is an important difference here between the way a QUIC application and a TLS application works. With a TLS application if we try to read or write something to the SSL object and we get a "retry" response (SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE) then we can assume that is because OpenSSL attempted to read or write to the underlying socket and the socket signalled the "retry". With QUIC that is not the case. OpenSSL may signal retry as a result of an SSL_read_ex(3) or SSL_write_ex(3) (or similar) call which indicates the state of the stream. This is entirely independent of whether the underlying socket needs to retry or not.

- -

To determine whether OpenSSL currently wants to read or write to the underlying socket for a QUIC application we must call the SSL_net_read_desired(3) and SSL_net_write_desired(3) functions.

- -

It is also important with QUIC that we periodically call an I/O function (or otherwise call the SSL_handle_events(3) function) to ensure that the QUIC connection remains healthy. This is particularly important with a nonblocking application because you are likely to leave the SSL object idle for a while while the application goes off to do other work. The SSL_get_event_timeout(3) function can be used to determine what the deadline is for the next time we need to call an I/O function (or call SSL_handle_events(3)).

- -

An alternative to using SSL_get_event_timeout(3) to find the next deadline that OpenSSL must be called again by is to use "thread assisted" mode. In "thread assisted" mode OpenSSL spawns an additional thread which will periodically call SSL_handle_events(3) automatically, meaning that the application can leave the connection idle safe in the knowledge that the connection will still be maintained in a healthy state. See "Creating the SSL_CTX and SSL objects" below for further details about this.

- -

In this example we are using the select function to check the readability/writeability of the socket because it is very simple to use and is available on most Operating Systems. However you could use any other similar function to do the same thing. select waits for the state of the underlying socket(s) to become readable/writeable or until the timeout has expired before returning.

- -

Handling errors from OpenSSL I/O functions

- -

A QUIC application that has been configured for nonblocking behaviour will need to be prepared to handle errors returned from OpenSSL I/O functions such as SSL_read_ex(3) or SSL_write_ex(3). Errors may be fatal for the stream (for example because the stream has been reset or because the underlying connection has failed), or non-fatal (for example because we are trying to read from the stream but no data has not yet arrived from the peer for that stream).

- -

SSL_read_ex(3) and SSL_write_ex(3) will return 0 to indicate an error and SSL_read(3) and SSL_write(3) will return 0 or a negative value to indicate an error. SSL_shutdown(3) will return a negative value to incidate an error.

- -

In the event of an error an application should call SSL_get_error(3) to find out what type of error has occurred. If the error is non-fatal and can be retried then SSL_get_error(3) will return SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE depending on whether OpenSSL wanted to read to or write from the stream but was unable to. Note that a call to SSL_read_ex(3) or SSL_read(3) can still generate SSL_ERROR_WANT_WRITE. Similarly calls to SSL_write_ex(3) or SSL_write(3) might generate SSL_ERROR_WANT_READ.

- -

Another type of non-fatal error that may occur is SSL_ERROR_ZERO_RETURN. This indicates an EOF (End-Of-File) which can occur if you attempt to read data from an SSL object but the peer has indicated that it will not send any more data on the stream. In this case you may still want to write data to the stream but you will not receive any more data.

- -

Fatal errors that may occur are SSL_ERROR_SYSCALL and SSL_ERROR_SSL. These indicate that the stream is no longer usable. For example, this could be because the stream has been reset by the peer, or because the underlying connection has failed. You can consult the OpenSSL error stack for further details (for example by calling ERR_print_errors(3) to print out details of errors that have occurred). You can also consult the return value of SSL_get_stream_read_state(3) to determine whether the error is local to the stream, or whether the underlying connection has also failed. A return value of SSL_STREAM_STATE_RESET_REMOTE tells you that the stream has been reset by the peer and SSL_STREAM_STATE_CONN_CLOSED tells you that the underlying connection has closed.

- -

In our demo application we will write a function to handle these errors from OpenSSL I/O functions:

- -
static int handle_io_failure(SSL *ssl, int res)
-{
-    switch (SSL_get_error(ssl, res)) {
-    case SSL_ERROR_WANT_READ:
-    case SSL_ERROR_WANT_WRITE:
-        /* Temporary failure. Wait until we can read/write and try again */
-        wait_for_activity(ssl);
-        return 1;
-
-    case SSL_ERROR_ZERO_RETURN:
-        /* EOF */
-        return 0;
-
-    case SSL_ERROR_SYSCALL:
-        return -1;
-
-    case SSL_ERROR_SSL:
-        /*
-         * Some stream fatal error occurred. This could be because of a
-         * stream reset - or some failure occurred on the underlying
-         * connection.
-         */
-        switch (SSL_get_stream_read_state(ssl)) {
-        case SSL_STREAM_STATE_RESET_REMOTE:
-            printf("Stream reset occurred\n");
-            /*
-             * The stream has been reset but the connection is still
-             * healthy.
-             */
-            break;
-
-        case SSL_STREAM_STATE_CONN_CLOSED:
-            printf("Connection closed\n");
-            /* Connection is already closed. */
-            break;
-
-        default:
-            printf("Unknown stream failure\n");
-            break;
-        }
-        /*
-         * If the failure is due to a verification error we can get more
-         * information about it from SSL_get_verify_result().
-         */
-        if (SSL_get_verify_result(ssl) != X509_V_OK)
-            printf("Verify error: %s\n",
-                X509_verify_cert_error_string(SSL_get_verify_result(ssl)));
-        return -1;
-
-    default:
-        return -1;
-    }
-}
- -

This function takes as arguments the SSL object that represents the connection, as well as the return code from the I/O function that failed. In the event of a non-fatal failure, it waits until a retry of the I/O operation might succeed (by using the wait_for_activity() function that we developed in the previous section). It returns 1 in the event of a non-fatal error (except EOF), 0 in the event of EOF, or -1 if a fatal error occurred.

- -

Creating the SSL_CTX and SSL objects

- -

In order to connect to a server we must create SSL_CTX and SSL objects for this. Most of the steps to do this are the same as for a blocking client and are explained on the ossl-guide-quic-client-block(7) page. We won't repeat that information here.

- -

One key difference is that we must put the SSL object into nonblocking mode (the default is blocking mode). To do that we use the SSL_set_blocking_mode(3) function:

- -
/*
- * The underlying socket is always nonblocking with QUIC, but the default
- * behaviour of the SSL object is still to block. We set it for nonblocking
- * mode in this demo.
- */
-if (!SSL_set_blocking_mode(ssl, 0)) {
-    printf("Failed to turn off blocking mode\n");
-    goto end;
-}
- -

Although the demo application that we are developing here does not use it, it is possible to use "thread assisted mode" when developing QUIC applications. Normally, when writing an OpenSSL QUIC application, it is important that SSL_handle_events(3) (or alternatively any I/O function) is called on the connection SSL object periodically to maintain the connection in a healthy state. See "Performing work while waiting for the socket" for more discussion on this. This is particularly important to keep in mind when writing a nonblocking QUIC application because it is common to leave the SSL connection object idle for some time when using nonblocking mode. By using "thread assisted mode" a separate thread is created by OpenSSL to do this automatically which means that the application developer does not need to handle this aspect. To do this we must use OSSL_QUIC_client_thread_method(3) when we construct the SSL_CTX as shown below:

- -
ctx = SSL_CTX_new(OSSL_QUIC_client_thread_method());
-if (ctx == NULL) {
-    printf("Failed to create the SSL_CTX\n");
-    goto end;
-}
- -

Performing the handshake

- -

As in the demo for a blocking QUIC client we use the SSL_connect(3) function to perform the handshake with the server. Since we are using a nonblocking SSL object it is very likely that calls to this function will fail with a non-fatal error while we are waiting for the server to respond to our handshake messages. In such a case we must retry the same SSL_connect(3) call at a later time. In this demo we do this in a loop:

- -
/* Do the handshake with the server */
-while ((ret = SSL_connect(ssl)) != 1) {
-    if (handle_io_failure(ssl, ret) == 1)
-        continue; /* Retry */
-    printf("Failed to connect to server\n");
-    goto end; /* Cannot retry: error */
-}
- -

We continually call SSL_connect(3) until it gives us a success response. Otherwise we use the handle_io_failure() function that we created earlier to work out what we should do next. Note that we do not expect an EOF to occur at this stage, so such a response is treated in the same way as a fatal error.

- -

Sending and receiving data

- -

As with the blocking QUIC client demo we use the SSL_write_ex(3) function to send data to the server. As with SSL_connect(3) above, because we are using a nonblocking SSL object, this call could fail with a non-fatal error. In that case we should retry exactly the same SSL_write_ex(3) call again. Note that the parameters must be exactly the same, i.e. the same pointer to the buffer to write with the same length. You must not attempt to send different data on a retry. An optional mode does exist (SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER) which will configure OpenSSL to allow the buffer being written to change from one retry to the next. However, in this case, you must still retry exactly the same data - even though the buffer that contains that data may change location. See SSL_CTX_set_mode(3) for further details. As in the TLS tutorials (ossl-guide-tls-client-block(7)) we write the request in three chunks.

- -
/* Write an HTTP GET request to the peer */
-while (!SSL_write_ex(ssl, request_start, strlen(request_start), &written)) {
-    if (handle_io_failure(ssl, 0) == 1)
-        continue; /* Retry */
-    printf("Failed to write start of HTTP request\n");
-    goto end; /* Cannot retry: error */
-}
-while (!SSL_write_ex(ssl, hostname, strlen(hostname), &written)) {
-    if (handle_io_failure(ssl, 0) == 1)
-        continue; /* Retry */
-    printf("Failed to write hostname in HTTP request\n");
-    goto end; /* Cannot retry: error */
-}
-while (!SSL_write_ex(ssl, request_end, strlen(request_end), &written)) {
-    if (handle_io_failure(ssl, 0) == 1)
-        continue; /* Retry */
-    printf("Failed to write end of HTTP request\n");
-    goto end; /* Cannot retry: error */
-}
- -

On a write we do not expect to see an EOF response so we treat that case in the same way as a fatal error.

- -

Reading a response back from the server is similar:

- -
do {
-    /*
-     * Get up to sizeof(buf) bytes of the response. We keep reading until
-     * the server closes the connection.
-     */
-    while (!eof && !SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) {
-        switch (handle_io_failure(ssl, 0)) {
-        case 1:
-            continue; /* Retry */
-        case 0:
-            eof = 1;
-            continue;
-        case -1:
-        default:
-            printf("Failed reading remaining data\n");
-            goto end; /* Cannot retry: error */
-        }
-    }
-    /*
-     * OpenSSL does not guarantee that the returned data is a string or
-     * that it is NUL terminated so we use fwrite() to write the exact
-     * number of bytes that we read. The data could be non-printable or
-     * have NUL characters in the middle of it. For this simple example
-     * we're going to print it to stdout anyway.
-     */
-    if (!eof)
-        fwrite(buf, 1, readbytes, stdout);
-} while (!eof);
-/* In case the response didn't finish with a newline we add one now */
-printf("\n");
- -

The main difference this time is that it is valid for us to receive an EOF response when trying to read data from the server. This will occur when the server closes down the connection after sending all the data in its response.

- -

In this demo we just print out all the data we've received back in the response from the server. We continue going around the loop until we either encounter a fatal error, or we receive an EOF (indicating a graceful finish).

- -

Shutting down the connection

- -

As in the QUIC blocking example we must shutdown the connection when we are finished with it.

- -

Even though we have received EOF on the stream that we were reading from above, this tell us nothing about the state of the underlying connection. Our demo application will initiate the connection shutdown process via SSL_shutdown(3).

- -

Since our application is initiating the shutdown then we might expect to see SSL_shutdown(3) give a return value of 0, and then we should continue to call it until we receive a return value of 1 (meaning we have successfully completed the shutdown). Since we are using a nonblocking SSL object we might expect to have to retry this operation several times. If SSL_shutdown(3) returns a negative result then we must call SSL_get_error(3) to work out what to do next. We use our handle_io_failure() function that we developed earlier for this:

- -
/*
- * Repeatedly call SSL_shutdown() until the connection is fully
- * closed.
- */
-while ((ret = SSL_shutdown(ssl)) != 1) {
-    if (ret < 0 && handle_io_failure(ssl, ret) == 1)
-        continue; /* Retry */
-}
- -

Final clean up

- -

As with the blocking QUIC client example, once our connection is finished with we must free it. The steps to do this for this example are the same as for the blocking example, so we won't repeat it here.

- -

FURTHER READING

- -

See ossl-guide-quic-client-block(7) to read a tutorial on how to write a blocking QUIC client. See ossl-guide-quic-multi-stream(7) to see how to write a multi-stream QUIC client.

- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7), ossl-guide-quic-introduction(7), ossl-guide-quic-client-block(7), ossl-guide-quic-multi-stream(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-introduction.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-introduction.html deleted file mode 100644 index de15935b..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-introduction.html +++ /dev/null @@ -1,136 +0,0 @@ - - - - -ossl-guide-quic-introduction - - - - - - - - - - -

NAME

- -

ossl-guide-quic-introduction - OpenSSL Guide: An introduction to QUIC in OpenSSL

- -

INTRODUCTION

- -

This page will provide an introduction to some basic QUIC concepts and background and how it is used within OpenSSL. It assumes that you have a basic understanding of UDP/IP and sockets. It also assumes that you are familiar with some OpenSSL and TLS fundamentals (see ossl-guide-libraries-introduction(7) and ossl-guide-tls-introduction(7)).

- -

WHAT IS QUIC?

- -

QUIC is a general purpose protocol for enabling applications to securely communicate over a network. It is defined in RFC9000 (see https://datatracker.ietf.org/doc/rfc9000/). QUIC integrates parts of the TLS protocol for connection establishment but independently protects packets. It provides similar security guarantees to TLS such as confidentiality, integrity and authentication (see ossl-guide-tls-introduction(7)).

- -

QUIC delivers a number of advantages:

- -
- -
Multiple streams
-
- -

It supports multiple streams of communication (see "QUIC STREAMS" below), allowing application protocols built on QUIC to create arbitrarily many bytestreams for communication between a client and server. This allows an application protocol to avoid problems where one packet of data is held up waiting on another packet being delivered (commonly referred to as "head-of-line blocking"). It also enables an application to open additional logical streams without requiring a round-trip exchange of packets between the client and server as is required when opening an additional TLS/TCP connection.

- -
-
HTTP/3
-
- -

Since QUIC is the basis of HTTP/3, support for QUIC also enables applications to use HTTP/3 using a suitable third-party library.

- -
-
Fast connection initiation
-
- -

Future versions of OpenSSL will offer support for 0-RTT connection initiation, allowing a connection to be initiated to a server and application data to be transmitted without any waiting time. This is similar to TLS 1.3's 0-RTT functionality but also avoids the round trip needed to open a TCP socket; thus, it is similar to a combination of TLS 1.3 0-RTT and TCP Fast Open.

- -
-
Connection migration
-
- -

Future versions of OpenSSL will offer support for connection migration, allowing connections to seamlessly survive IP address changes.

- -
-
Datagram based use cases
-
- -

Future versions of OpenSSL will offer support for the QUIC datagram extension, allowing support for both TLS and DTLS-style use cases on a single connection.

- -
-
Implemented as application library
-
- -

Because most QUIC implementations, including OpenSSL's implementation, are implemented as an application library rather than by an operating system, an application can gain the benefit of QUIC without needing to wait for an OS update to be deployed. Future evolutions and enhancements to the QUIC protocol can be delivered as quickly as an application can be updated without dependency on an OS update cadence.

- -
-
Multiplexing over a single UDP socket
-
- -

Because QUIC is UDP-based, it is possible to multiplex a QUIC connection on the same UDP socket as some other UDP-based protocols, such as RTP.

- -
-
- -

QUIC TIME BASED EVENTS

- -

A key difference between the TLS implementation and the QUIC implementation in OpenSSL is how time is handled. The QUIC protocol requires various actions to be performed on a regular basis regardless of whether application data is being transmitted or received.

- -

OpenSSL introduces a new function SSL_handle_events(3) that will automatically process any outstanding time based events that must be handled. Alternatively calling any I/O function such as SSL_read_ex(3) or SSL_write_ex(3) will also process these events. There is also SSL_get_event_timeout(3) which tells an application the amount of time that remains until SSL_handle_events(3) (or any I/O function) must be called.

- -

Fortunately a blocking application that does not leave the QUIC connection idle, and is regularly calling I/O functions does not typically need to worry about this. However if you are developing a nonblocking application or one that may leave the QUIC connection idle for a period of time then you will need to arrange to call these functions.

- -

OpenSSL provides an optional "thread assisted mode" that will automatically create a background thread and will regularly call SSL_handle_events(3) in a thread safe manner. This provides a simple way for an application to satisfy the QUIC requirements for time based events without having to implement special logic to accomplish it.

- -

QUIC AND TLS

- -

QUIC reuses parts of the TLS protocol in its implementation. Specifically the TLS handshake also exists in QUIC. The TLS handshake messages are wrapped up in QUIC protocol messages in order to send them to the peer. Once the TLS handshake is complete all application data is sent entirely using QUIC protocol messages without using TLS - although some TLS handshake messages may still be sent in some circumstances.

- -

This relationship between QUIC and TLS means that many of the API functions in OpenSSL that apply to TLS connections also apply to QUIC connections and applications can use them in exactly the same way. Some functions do not apply to QUIC at all, and others have altered semantics. You should refer to the documentation pages for each function for information on how it applies to QUIC. Typically if QUIC is not mentioned in the manual pages then the functions apply to both TLS and QUIC.

- -

QUIC STREAMS

- -

QUIC introduces the concept of "streams". A stream provides a reliable mechanism for sending and receiving application data between the endpoints. The bytes transmitted are guaranteed to be received in the same order they were sent without any loss of data or reordering of the bytes. A TLS application effectively has one bi-directional stream available to it per TLS connection. A QUIC application can have multiple uni-directional or bi-directional streams available to it for each connection.

- -

In OpenSSL an SSL object is used to represent both connections and streams. A QUIC application creates an initial SSL object to represent the connection (known as the connection SSL object). Once the connection is complete additional SSL objects can be created to represent streams (known as stream SSL objects). Unless configured otherwise, a "default" stream is also associated with the connection SSL object so you can still write data and read data to/from it. Some OpenSSL API functions can only be used with connection SSL objects, and some can only be used with stream SSL objects. Check the documentation for each function to confirm what type of SSL object can be used in any particular context. A connection SSL object that has a default stream attached to it can be used in contexts that require a connection SSL object or in contexts that require a stream SSL object.

- -

SOCKETS AND BLOCKING

- -

TLS assumes "stream" type semantics for its underlying transport layer protocol (usually achieved by using TCP). However QUIC assumes "datagram" type semantics by using UDP. An OpenSSL application using QUIC is responsible for creating a BIO to represent the underlying transport layer. This BIO must support datagrams and is typically BIO_s_datagram(3), but other BIO choices are available. See bio(7) for an introduction to OpenSSL's BIO concept.

- -

A significant difference between OpenSSL TLS applications and OpenSSL QUIC applications is the way that blocking is implemented. In TLS if your application expects blocking behaviour then you configure the underlying socket for blocking. Conversely if your application wants nonblocking behaviour then the underlying socket is configured to be nonblocking.

- -

With an OpenSSL QUIC application the underlying socket must always be configured to be nonblocking. Howevever the SSL object will, by default, still operate in blocking mode. So, from an application's perspective, calls to functions such as SSL_read_ex(3), SSL_write_ex(3) and other I/O functions will still block. OpenSSL itself provides that blocking capability for QUIC instead of the socket. If nonblocking behaviour is desired then the application must call SSL_set_blocking_mode(3).

- -

FURTHER READING

- -

See ossl-guide-quic-client-block(7) to see an example of applying these concepts in order to write a simple blocking QUIC client.

- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7), ossl-guide-tls-introduction(7), ossl-guide-tls-client-block(7), ossl-guide-quic-client-block(7), bio(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-multi-stream.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-multi-stream.html deleted file mode 100644 index 8a075022..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-quic-multi-stream.html +++ /dev/null @@ -1,277 +0,0 @@ - - - - -ossl-guide-quic-multi-stream - - - - - - - - - - -

NAME

- -

ossl-guide-quic-multi-stream - OpenSSL Guide: Writing a simple multi-stream QUIC client

- -

INTRODUCTION

- -

This page will introduce some important concepts required to write a simple QUIC multi-stream application. It assumes a basic understanding of QUIC and how it is used in OpenSSL. See ossl-guide-quic-introduction(7) and ossl-guide-quic-client-block(7).

- -

QUIC STREAMS

- -

In a QUIC multi-stream application we separate out the concepts of a QUIC "connection" and a QUIC "stream". A connection object represents the overarching details of the connection between a client and a server including all its negotiated and configured parameters. We use the SSL object for that in an OpenSSL application (known as the connection SSL object). It is created by an application calling SSL_new(3).

- -

Separately a connection can have zero or more streams associated with it (although a connection with zero streams is probably not very useful, so normally you would have at least one). A stream is used to send and receive data between the two peers. Each stream is also represented by an SSL object. A stream is logically independent of all the other streams associated with the same connection. Data sent on a stream is guaranteed to be delivered in the order that it was sent within that stream. The same is not true across streams, e.g. if an application sends data on stream 1 first and then sends some more data on stream 2 second, then the remote peer may receive the data sent on stream 2 before it receives the data sent on stream 1.

- -

Once the connection SSL object has completed its handshake (i.e. SSL_connect(3) has returned 1), stream SSL objects are created by the application calling SSL_new_stream(3) or SSL_accept_stream(3) (see "CREATING NEW STREAMS" below).

- -

The same threading rules apply to SSL objects as for most OpenSSL objects (see ossl-guide-libraries-introduction(7)). In particular most OpenSSL functions are thread safe, but the SSL object is not. This means that you can use an SSL object representing one stream at the same time as another thread is using a different SSL object for a different stream on the same connection. But you cannot use the same SSL object on two different threads at the same time (without additional application level locking).

- -

THE DEFAULT STREAM

- -

A connection SSL object may also (optionally) be associated with a stream. This stream is known as the default stream. The default stream is automatically created and associated with the SSL object when the application calls SSL_read_ex(3), SSL_read(3), SSL_write_ex(3) or SSL_write(3) and passes the connection SSL object as a parameter.

- -

If a client application calls SSL_write_ex(3) or SSL_write(3) first then (by default) the default stream will be a client-initiated bi-directional stream. If a client application calls SSL_read_ex(3) or SSL_read(3) first then the first stream initiated by the server will be used as the default stream (whether it is bi-directional or uni-directional).

- -

This behaviour can be controlled via the default stream mode. See SSL_set_default_stream_mode(3) for further details.

- -

It is recommended that new multi-stream applications should not use a default stream at all and instead should use a separate stream SSL object for each stream that is used. This requires calling SSL_set_default_stream_mode(3) and setting the mode to SSL_DEFAULT_STREAM_MODE_NONE.

- -

CREATING NEW STREAMS

- -

An endpoint can create a new stream by calling SSL_new_stream(3). This creates a locally initiated stream. In order to do so you must pass the QUIC connection SSL object as a parameter. You can also specify whether you want a bi-directional or a uni-directional stream.

- -

The function returns a new QUIC stream SSL object for sending and receiving data on that stream.

- -

The peer may also initiate streams. An application can use the function SSL_get_accept_stream_queue_len(3) to determine the number of streams that the peer has initiated that are waiting for the application to handle. An application can call SSL_accept_stream(3) to create a new SSL object for a remotely initiated stream. If the peer has not initiated any then this call will block until one is available if the connection object is in blocking mode (see SSL_set_blocking_mode(3)).

- -

When using a default stream OpenSSL will prevent new streams from being accepted. To override this behaviour you must call SSL_set_incoming_stream_policy(3) to set the policy to SSL_INCOMING_STREAM_POLICY_ACCEPT. See the man page for further details. This is not relevant if the default stream has been disabled as described in "THE DEFAULT STREAM" above.

- -

Any stream may be bi-directional or uni-directional. If it is uni-directional then the initiator can write to it but not read from it, and vice-versa for the peer. You can determine what type of stream an SSL object represents by calling SSL_get_stream_type(3). See the man page for further details.

- -

USING A STREAM TO SEND AND RECEIVE DATA

- -

Once you have a stream SSL object (which includes the connection SSL object if a default stream is in use) then you can send and receive data over it using the SSL_write_ex(3), SSL_write(3), SSL_read_ex(3) or SSL_read(3) functions. See the man pages for further details.

- -

In the event of one of these functions not returning a success code then you should call SSL_get_error(3) to find out further details about the error. In blocking mode this will either be a fatal error (e.g. SSL_ERROR_SYSCALL or SSL_ERROR_SSL), or it will be SSL_ERROR_ZERO_RETURN which can occur when attempting to read data from a stream and the peer has indicated that the stream is concluded (i.e. "FIN" has been signalled on the stream). This means that the peer will send no more data on that stream. Note that the interpretation of SSL_ERROR_ZERO_RETURN is slightly different for a QUIC application compared to a TLS application. In TLS it occurs when the connection has been shutdown by the peer. In QUIC this only tells you that the current stream has been concluded by the peer. It tells you nothing about the underlying connection. If the peer has concluded the stream then no more data will be received on it, however an application can still send data to the peer until the send side of the stream has also been concluded. This can happen by the application calling SSL_stream_conclude(3). It is an error to attempt to send more data on a stream after SSL_stream_conclude(3) has been called.

- -

It is also possible to abandon a stream abnormally by calling SSL_stream_reset(3).

- -

Once a stream object is no longer needed it should be freed via a call to SSL_free(3). An application should not call SSL_shutdown(3) on it since this is only meaningful for connection level SSL objects. Freeing the stream will automatically signal STOP_SENDING to the peer.

- -

STREAMS AND CONNECTIONS

- -

Given a stream object it is possible to get the SSL object corresponding to the connection via a call to SSL_get0_connection(3). Multi-threaded restrictions apply so care should be taken when using the returned connection object. Specifically, if you are handling each of your stream objects in a different thread and call SSL_get0_connection(3) from within that thread then you must be careful to not to call any function that uses the connection object at the same time as one of the other threads is also using that connection object (with the exception of SSL_accept_stream(3) and SSL_get_accept_stream_queue_len(3) which are thread-safe).

- -

A stream object does not inherit all its settings and values from its parent SSL connection object. Therefore certain function calls that are relevant to the connection as a whole will not work on a stream. For example the function SSL_get_certificate(3) can be used to obtain a handle on the peer certificate when called with a connection SSL object. When called with a stream SSL object it will return NULL.

- -

SIMPLE MULTI-STREAM QUIC CLIENT EXAMPLE

- -

This section will present various source code samples demonstrating how to write a simple multi-stream QUIC client application which connects to a server, send some HTTP/1.0 requests to it, and read back the responses. Note that HTTP/1.0 over QUIC is non-standard and will not be supported by real world servers. This is for demonstration purposes only.

- -

We will build on the example code for the simple blocking QUIC client that is covered on the ossl-guide-quic-client-block(7) page and we assume that you are familiar with it. We will only describe the differences between the simple blocking QUIC client and the multi-stream QUIC client. Although the example code uses blocking SSL objects, you can equally use nonblocking SSL objects. See ossl-guide-quic-client-non-block(7) for more information about writing a nonblocking QUIC client.

- -

The complete source code for this example multi-stream QUIC client is available in the demos/guide directory of the OpenSSL source distribution in the file quic-multi-stream.c. It is also available online at https://github.com/openssl/openssl/blob/master/demos/guide/quic-multi-stream.c.

- -

Disabling the default stream

- -

As discussed above in "THE DEFAULT STREAM" we will follow the recommendation to disable the default stream for our multi-stream client. To do this we call the SSL_set_default_stream_mode(3) function and pass in our connection SSL object and the value SSL_DEFAULT_STREAM_MODE_NONE.

- -
/*
- * We will use multiple streams so we will disable the default stream mode.
- * This is not a requirement for using multiple streams but is recommended.
- */
-if (!SSL_set_default_stream_mode(ssl, SSL_DEFAULT_STREAM_MODE_NONE)) {
-    printf("Failed to disable the default stream mode\n");
-    goto end;
-}
- -

Creating the request streams

- -

For the purposes of this example we will create two different streams to send two different HTTP requests to the server. For the purposes of demonstration the first of these will be a bi-directional stream and the second one will be a uni-directional one:

- -
/*
- * We create two new client initiated streams. The first will be
- * bi-directional, and the second will be uni-directional.
- */
-stream1 = SSL_new_stream(ssl, 0);
-stream2 = SSL_new_stream(ssl, SSL_STREAM_FLAG_UNI);
-if (stream1 == NULL || stream2 == NULL) {
-    printf("Failed to create streams\n");
-    goto end;
-}
- -

Writing data to the streams

- -

Once the streams are successfully created we can start writing data to them. In this example we will be sending a different HTTP request on each stream. To avoid repeating too much code we write a simple helper function to send an HTTP request to a stream:

- -
int write_a_request(SSL *stream, const char *request_start,
-                    const char *hostname)
-{
-    const char *request_end = "\r\n\r\n";
-    size_t written;
-
-    if (!SSL_write_ex(stream, request_start, strlen(request_start), &written))
-        return 0;
-    if (!SSL_write_ex(stream, hostname, strlen(hostname), &written))
-        return 0;
-    if (!SSL_write_ex(stream, request_end, strlen(request_end), &written))
-        return 0;
-
-    return 1;
-}
- -

We assume the strings request1_start and request2_start hold the appropriate HTTP requests. We can then call our helper function above to send the requests on the two streams. For the sake of simplicity this example does this sequentially, writing to stream1 first and, when this is successful, writing to stream2 second. Remember that our client is blocking so these calls will only return once they have been successfully completed. A real application would not need to do these writes sequentially or in any particular order. For example we could start two threads (one for each stream) and write the requests to each stream simultaneously.

- -
/* Write an HTTP GET request on each of our streams to the peer */
-if (!write_a_request(stream1, request1_start, hostname)) {
-    printf("Failed to write HTTP request on stream 1\n");
-    goto end;
-}
-
-if (!write_a_request(stream2, request2_start, hostname)) {
-    printf("Failed to write HTTP request on stream 2\n");
-    goto end;
-}
- -

Reading data from a stream

- -

In this example stream1 is a bi-directional stream so, once we have sent the request on it, we can attempt to read the response from the server back. Here we just repeatedly call SSL_read_ex(3) until that function fails (indicating either that there has been a problem, or that the peer has signalled the stream as concluded).

- -
printf("Stream 1 data:\n");
-/*
- * Get up to sizeof(buf) bytes of the response from stream 1 (which is a
- * bidirectional stream). We keep reading until the server closes the
- * connection.
- */
-while (SSL_read_ex(stream1, buf, sizeof(buf), &readbytes)) {
-    /*
-    * OpenSSL does not guarantee that the returned data is a string or
-    * that it is NUL terminated so we use fwrite() to write the exact
-    * number of bytes that we read. The data could be non-printable or
-    * have NUL characters in the middle of it. For this simple example
-    * we're going to print it to stdout anyway.
-    */
-    fwrite(buf, 1, readbytes, stdout);
-}
-/* In case the response didn't finish with a newline we add one now */
-printf("\n");
- -

In a blocking application like this one calls to SSL_read_ex(3) will either succeed immediately returning data that is already available, or they will block waiting for more data to become available and return it when it is, or they will fail with a 0 response code.

- -

Once we exit the while loop above we know that the last call to SSL_read_ex(3) gave a 0 response code so we call the SSL_get_error(3) function to find out more details. Since this is a blocking application this will either return SSL_ERROR_SYSCALL or SSL_ERROR_SSL indicating a fundamental problem, or it will return SSL_ERROR_ZERO_RETURN indicating that the stream is concluded and there will be no more data available to read from it. Care must be taken to distinguish between an error at the stream level (i.e. a stream reset) and an error at the connection level (i.e. a connection closed). The SSL_get_stream_read_state(3) function can be used to distinguish between these different cases.

- -
/*
- * Check whether we finished the while loop above normally or as the
- * result of an error. The 0 argument to SSL_get_error() is the return
- * code we received from the SSL_read_ex() call. It must be 0 in order
- * to get here. Normal completion is indicated by SSL_ERROR_ZERO_RETURN. In
- * QUIC terms this means that the peer has sent FIN on the stream to
- * indicate that no further data will be sent.
- */
-switch (SSL_get_error(stream1, 0)) {
-case SSL_ERROR_ZERO_RETURN:
-    /* Normal completion of the stream */
-    break;
-
-case SSL_ERROR_SSL:
-    /*
-     * Some stream fatal error occurred. This could be because of a stream
-     * reset - or some failure occurred on the underlying connection.
-     */
-    switch (SSL_get_stream_read_state(stream1)) {
-    case SSL_STREAM_STATE_RESET_REMOTE:
-        printf("Stream reset occurred\n");
-        /* The stream has been reset but the connection is still healthy. */
-        break;
-
-    case SSL_STREAM_STATE_CONN_CLOSED:
-        printf("Connection closed\n");
-        /* Connection is already closed. Skip SSL_shutdown() */
-        goto end;
-
-    default:
-        printf("Unknown stream failure\n");
-        break;
-    }
-    break;
-
-default:
-    /* Some other unexpected error occurred */
-    printf ("Failed reading remaining data\n");
-    break;
-}
- -

Accepting an incoming stream

- -

Our stream2 object that we created above was a uni-directional stream so it cannot be used to receive data from the server. In this hypothetical example we assume that the server initiates a new stream to send us back the data that we requested. To do that we call SSL_accept_stream(3). Since this is a blocking application this will wait indefinitely until the new stream has arrived and is available for us to accept. In the event of an error it will return NULL.

- -
/*
- * In our hypothetical HTTP/1.0 over QUIC protocol that we are using we
- * assume that the server will respond with a server initiated stream
- * containing the data requested in our uni-directional stream. This doesn't
- * really make sense to do in a real protocol, but its just for
- * demonstration purposes.
- *
- * We're using blocking mode so this will block until a stream becomes
- * available. We could override this behaviour if we wanted to by setting
- * the SSL_ACCEPT_STREAM_NO_BLOCK flag in the second argument below.
- */
-stream3 = SSL_accept_stream(ssl, 0);
-if (stream3 == NULL) {
-    printf("Failed to accept a new stream\n");
-    goto end;
-}
- -

We can now read data from the stream in the same way that we did for stream1 above. We won't repeat that here.

- -

Cleaning up the streams

- -

Once we have finished using our streams we can simply free them by calling SSL_free(3). Optionally we could call SSL_stream_conclude(3) on them if we want to indicate to the peer that we won't be sending them any more data, but we don't do that in this example because we assume that the HTTP application protocol supplies sufficient information for the peer to know when we have finished sending request data.

- -

We should not call SSL_shutdown(3) or SSL_shutdown_ex(3) on the stream objects since those calls should not be used for streams.

- -
SSL_free(stream1);
-SSL_free(stream2);
-SSL_free(stream3);
- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7) ossl-guide-quic-introduction(7), ossl-guide-quic-client-block(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-block.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-block.html deleted file mode 100644 index 4ae01152..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-block.html +++ /dev/null @@ -1,465 +0,0 @@ - - - - -ossl-guide-tls-client-block - - - - - - - - - - -

NAME

- -

ossl-guide-tls-client-block - OpenSSL Guide: Writing a simple blocking TLS client

- -

SIMPLE BLOCKING TLS CLIENT EXAMPLE

- -

This page will present various source code samples demonstrating how to write a simple TLS client application which connects to a server, sends an HTTP/1.0 request to it, and reads back the response.

- -

We use a blocking socket for the purposes of this example. This means that attempting to read data from a socket that has no data available on it to read will block (and the function will not return), until data becomes available. For example, this can happen if we have sent our request, but we are still waiting for the server's response. Similarly any attempts to write to a socket that is not able to write at the moment will block until writing is possible.

- -

This blocking behaviour simplifies the implementation of a client because you do not have to worry about what happens if data is not yet available. The application will simply wait until it is available.

- -

The complete source code for this example blocking TLS client is available in the demos/guide directory of the OpenSSL source distribution in the file tls-client-block.c. It is also available online at https://github.com/openssl/openssl/blob/master/demos/guide/tls-client-block.c.

- -

We assume that you already have OpenSSL installed on your system; that you already have some fundamental understanding of OpenSSL concepts and TLS (see ossl-guide-libraries-introduction(7) and ossl-guide-tls-introduction(7)); and that you know how to write and build C code and link it against the libcrypto and libssl libraries that are provided by OpenSSL. It also assumes that you have a basic understanding of TCP/IP and sockets.

- -

Creating the SSL_CTX and SSL objects

- -

The first step is to create an SSL_CTX object for our client. We use the SSL_CTX_new(3) function for this purpose. We could alternatively use SSL_CTX_new_ex(3) if we want to associate the SSL_CTX with a particular OSSL_LIB_CTX (see ossl-guide-libraries-introduction(7) to learn about OSSL_LIB_CTX). We pass as an argument the return value of the function TLS_client_method(3). You should use this method whenever you are writing a TLS client. This method will automatically use TLS version negotiation to select the highest version of the protocol that is mutually supported by both the client and the server.

- -
/*
- * Create an SSL_CTX which we can use to create SSL objects from. We
- * want an SSL_CTX for creating clients so we use TLS_client_method()
- * here.
- */
-ctx = SSL_CTX_new(TLS_client_method());
-if (ctx == NULL) {
-    printf("Failed to create the SSL_CTX\n");
-    goto end;
-}
- -

Since we are writing a client we must ensure that we verify the server's certificate. We do this by calling the SSL_CTX_set_verify(3) function and pass the SSL_VERIFY_PEER value to it. The final argument to this function is a callback that you can optionally supply to override the default handling for certificate verification. Most applications do not need to do this so this can safely be set to NULL to get the default handling.

- -
/*
- * Configure the client to abort the handshake if certificate
- * verification fails. Virtually all clients should do this unless you
- * really know what you are doing.
- */
-SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);
- -

In order for certificate verification to be successful you must have configured where the trusted certificate store to be used is located (see ossl-guide-tls-introduction(7)). In most cases you just want to use the default store so we call SSL_CTX_set_default_verify_paths(3).

- -
/* Use the default trusted certificate store */
-if (!SSL_CTX_set_default_verify_paths(ctx)) {
-    printf("Failed to set the default trusted certificate store\n");
-    goto end;
-}
- -

We would also like to restrict the TLS versions that we are willing to accept to TLSv1.2 or above. TLS protocol versions earlier than that are generally to be avoided where possible. We can do that using SSL_CTX_set_min_proto_version(3):

- -
/*
- * TLSv1.1 or earlier are deprecated by IETF and are generally to be
- * avoided if possible. We require a minimum TLS version of TLSv1.2.
- */
-if (!SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION)) {
-    printf("Failed to set the minimum TLS protocol version\n");
-    goto end;
-}
- -

That is all the setup that we need to do for the SSL_CTX, so next we need to create an SSL object to represent the TLS connection. In a real application we might expect to be creating more than one TLS connection over time. In that case we would expect to reuse the SSL_CTX that we already created each time. There is no need to repeat those steps. In fact it is best not to since certain internal resources are cached in the SSL_CTX. You will get better performance by reusing an existing SSL_CTX instead of creating a new one each time.

- -

Creating the SSL object is a simple matter of calling the SSL_new(3) function and passing the SSL_CTX we created as an argument.

- -
/* Create an SSL object to represent the TLS connection */
-ssl = SSL_new(ctx);
-if (ssl == NULL) {
-    printf("Failed to create the SSL object\n");
-    goto end;
-}
- -

Creating the socket and BIO

- -

TLS data is transmitted over an underlying transport layer. Normally a TCP socket. It is the application's responsibility for ensuring that the socket is created and associated with an SSL object (via a BIO).

- -

Socket creation for use by a client is typically a 2 step process, i.e. constructing the socket; and connecting the socket.

- -

How to construct a socket is platform specific - but most platforms (including Windows) provide a POSIX compatible interface via the socket function, e.g. to create an IPv4 TCP socket:

- -
int sock;
-
-sock = socket(AF_INET, SOCK_STREAM, 0);
-if (sock == -1)
-    return NULL;
- -

Once the socket is constructed it must be connected to the remote server. Again the details are platform specific but most platforms (including Windows) provide the POSIX compatible connect function. For example:

- -
struct sockaddr_in serveraddr;
-struct hostent *server;
-
-server = gethostbyname("www.openssl.org");
-if (server == NULL) {
-    close(sock);
-    return NULL;
-}
-
-memset(&serveraddr, 0, sizeof(serveraddr));
-serveraddr.sin_family = server->h_addrtype;
-serveraddr.sin_port = htons(443);
-memcpy(&serveraddr.sin_addr.s_addr, server->h_addr, server->h_length);
-
-if (connect(sock, (struct sockaddr *)&serveraddr,
-            sizeof(serveraddr)) == -1) {
-    close(sock);
-    return NULL;
-}
- -

OpenSSL provides portable helper functions to do these tasks which also integrate into the OpenSSL error system to log error data, e.g.

- -
int sock = -1;
-BIO_ADDRINFO *res;
-const BIO_ADDRINFO *ai = NULL;
-
-/*
- * Lookup IP address info for the server.
- */
-if (!BIO_lookup_ex(hostname, port, BIO_LOOKUP_CLIENT, family, SOCK_STREAM, 0,
-                   &res))
-    return NULL;
-
-/*
- * Loop through all the possible addresses for the server and find one
- * we can connect to.
- */
-for (ai = res; ai != NULL; ai = BIO_ADDRINFO_next(ai)) {
-    /*
-     * Create a TCP socket. We could equally use non-OpenSSL calls such
-     * as "socket" here for this and the subsequent connect and close
-     * functions. But for portability reasons and also so that we get
-     * errors on the OpenSSL stack in the event of a failure we use
-     * OpenSSL's versions of these functions.
-     */
-    sock = BIO_socket(BIO_ADDRINFO_family(ai), SOCK_STREAM, 0, 0);
-    if (sock == -1)
-        continue;
-
-    /* Connect the socket to the server's address */
-    if (!BIO_connect(sock, BIO_ADDRINFO_address(ai), BIO_SOCK_NODELAY)) {
-        BIO_closesocket(sock);
-        sock = -1;
-        continue;
-    }
-
-    /* We have a connected socket so break out of the loop */
-    break;
-}
-
-/* Free the address information resources we allocated earlier */
-BIO_ADDRINFO_free(res);
- -

See BIO_lookup_ex(3), BIO_socket(3), BIO_connect(3), BIO_closesocket(3), BIO_ADDRINFO_next(3), BIO_ADDRINFO_address(3) and BIO_ADDRINFO_free(3) for further information on the functions used here. In the above example code the hostname and port variables are strings, e.g. "www.example.com" and "443". Note also the use of the family variable, which can take the values of AF_INET or AF_INET6 based on the command line -6 option, to allow specific connections to an ipv4 or ipv6 enabled host.

- -

Sockets created using the methods described above will automatically be blocking sockets - which is exactly what we want for this example.

- -

Once the socket has been created and connected we need to associate it with a BIO object:

- -
BIO *bio;
-
-/* Create a BIO to wrap the socket */
-bio = BIO_new(BIO_s_socket());
-if (bio == NULL) {
-    BIO_closesocket(sock);
-    return NULL;
-}
-
-/*
- * Associate the newly created BIO with the underlying socket. By
- * passing BIO_CLOSE here the socket will be automatically closed when
- * the BIO is freed. Alternatively you can use BIO_NOCLOSE, in which
- * case you must close the socket explicitly when it is no longer
- * needed.
- */
-BIO_set_fd(bio, sock, BIO_CLOSE);
- -

See BIO_new(3), BIO_s_socket(3) and BIO_set_fd(3) for further information on these functions.

- -

Finally we associate the SSL object we created earlier with the BIO using the SSL_set_bio(3) function. Note that this passes ownership of the BIO object to the SSL object. Once ownership is passed the SSL object is responsible for its management and will free it automatically when the SSL is freed. So, once SSL_set_bio(3) has been been called, you should not call BIO_free(3) on the BIO.

- -
SSL_set_bio(ssl, bio, bio);
- -

Setting the server's hostname

- -

We have already connected our underlying socket to the server, but the client still needs to know the server's hostname. It uses this information for 2 key purposes and we need to set the hostname for each one.

- -

Firstly, the server's hostname is included in the initial ClientHello message sent by the client. This is known as the Server Name Indication (SNI). This is important because it is common for multiple hostnames to be fronted by a single server that handles requests for all of them. In other words a single server may have multiple hostnames associated with it and it is important to indicate which one we want to connect to. Without this information we may get a handshake failure, or we may get connected to the "default" server which may not be the one we were expecting.

- -

To set the SNI hostname data we call the SSL_set_tlsext_host_name(3) function like this:

- -
/*
- * Tell the server during the handshake which hostname we are attempting
- * to connect to in case the server supports multiple hosts.
- */
-if (!SSL_set_tlsext_host_name(ssl, hostname)) {
-    printf("Failed to set the SNI hostname\n");
-    goto end;
-}
- -

Here the hostname argument is a string representing the hostname of the server, e.g. "www.example.com".

- -

Secondly, we need to tell OpenSSL what hostname we expect to see in the certificate coming back from the server. This is almost always the same one that we asked for in the original request. This is important because, without this, we do not verify that the hostname in the certificate is what we expect it to be and any certificate is acceptable unless your application explicitly checks this itself. We do this via the SSL_set1_host(3) function:

- -
/*
- * Ensure we check during certificate verification that the server has
- * supplied a certificate for the hostname that we were expecting.
- * Virtually all clients should do this unless you really know what you
- * are doing.
- */
-if (!SSL_set1_host(ssl, hostname)) {
-    printf("Failed to set the certificate verification hostname");
-    goto end;
-}
- -

All of the above steps must happen before we attempt to perform the handshake otherwise they will have no effect.

- -

Performing the handshake

- -

Before we can start sending or receiving application data over a TLS connection the TLS handshake must be performed. We can do this explicitly via the SSL_connect(3) function.

- -
/* Do the handshake with the server */
-if (SSL_connect(ssl) < 1) {
-    printf("Failed to connect to the server\n");
-    /*
-     * If the failure is due to a verification error we can get more
-     * information about it from SSL_get_verify_result().
-     */
-    if (SSL_get_verify_result(ssl) != X509_V_OK)
-        printf("Verify error: %s\n",
-            X509_verify_cert_error_string(SSL_get_verify_result(ssl)));
-    goto end;
-}
- -

The SSL_connect(3) function can return 1, 0 or less than 0. Only a return value of 1 is considered a success. For a simple blocking client we only need to concern ourselves with whether the call was successful or not. Anything else indicates that we have failed to connect to the server.

- -

A common cause of failures at this stage is due to a problem verifying the server's certificate. For example if the certificate has expired, or it is not signed by a CA in our trusted certificate store. We can use the SSL_get_verify_result(3) function to find out more information about the verification failure. A return value of X509_V_OK indicates that the verification was successful (so the connection error must be due to some other cause). Otherwise we use the X509_verify_cert_error_string(3) function to get a human readable error message.

- -

Sending and receiving data

- -

Once the handshake is complete we are able to send and receive application data. Exactly what data is sent and in what order is usually controlled by some application level protocol. In this example we are using HTTP 1.0 which is a very simple request and response protocol. The client sends a request to the server. The server sends the response data and then immediately closes down the connection.

- -

To send data to the server we use the SSL_write_ex(3) function and to receive data from the server we use the SSL_read_ex(3) function. In HTTP 1.0 the client always writes data first. Our HTTP request will include the hostname that we are connecting to. For simplicity, we write the HTTP request in three chunks. First we write the start of the request. Secondly we write the hostname we are sending the request to. Finally we send the end of the request.

- -
size_t written;
-const char *request_start = "GET / HTTP/1.0\r\nConnection: close\r\nHost: ";
-const char *request_end = "\r\n\r\n";
-
-/* Write an HTTP GET request to the peer */
-if (!SSL_write_ex(ssl, request_start, strlen(request_start), &written)) {
-    printf("Failed to write start of HTTP request\n");
-    goto end;
-}
-if (!SSL_write_ex(ssl, hostname, strlen(hostname), &written)) {
-    printf("Failed to write hostname in HTTP request\n");
-    goto end;
-}
-if (!SSL_write_ex(ssl, request_end, strlen(request_end), &written)) {
-    printf("Failed to write end of HTTP request\n");
-    goto end;
-}
- -

The SSL_write_ex(3) function returns 0 if it fails and 1 if it is successful. If it is successful then we can proceed to waiting for a response from the server.

- -
size_t readbytes;
-char buf[160];
-
-/*
- * Get up to sizeof(buf) bytes of the response. We keep reading until the
- * server closes the connection.
- */
-while (SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) {
-    /*
-    * OpenSSL does not guarantee that the returned data is a string or
-    * that it is NUL terminated so we use fwrite() to write the exact
-    * number of bytes that we read. The data could be non-printable or
-    * have NUL characters in the middle of it. For this simple example
-    * we're going to print it to stdout anyway.
-    */
-    fwrite(buf, 1, readbytes, stdout);
-}
-/* In case the response didn't finish with a newline we add one now */
-printf("\n");
- -

We use the SSL_read_ex(3) function to read the response. We don't know exactly how much data we are going to receive back so we enter a loop reading blocks of data from the server and printing each block that we receive to the screen. The loop ends as soon as SSL_read_ex(3) returns 0 - meaning that it failed to read any data.

- -

A failure to read data could mean that there has been some error, or it could simply mean that server has sent all the data that it wants to send and has indicated that it has finished by sending a "close_notify" alert. This alert is a TLS protocol level message indicating that the endpoint has finished sending all of its data and it will not send any more. Both of these conditions result in a 0 return value from SSL_read_ex(3) and we need to use the function SSL_get_error(3) to determine the cause of the 0 return value.

- -
/*
- * Check whether we finished the while loop above normally or as the
- * result of an error. The 0 argument to SSL_get_error() is the return
- * code we received from the SSL_read_ex() call. It must be 0 in order
- * to get here. Normal completion is indicated by SSL_ERROR_ZERO_RETURN.
- */
-if (SSL_get_error(ssl, 0) != SSL_ERROR_ZERO_RETURN) {
-    /*
-     * Some error occurred other than a graceful close down by the
-     * peer
-     */
-    printf ("Failed reading remaining data\n");
-    goto end;
-}
- -

If SSL_get_error(3) returns SSL_ERROR_ZERO_RETURN then we know that the server has finished sending its data. Otherwise an error has occurred.

- -

Shutting down the connection

- -

Once we have finished reading data from the server then we are ready to close the connection down. We do this via the SSL_shutdown(3) function which has the effect of sending a TLS protocol level message (a "close_notify" alert) to the server saying that we have finished writing data:

- -
/*
- * The peer already shutdown gracefully (we know this because of the
- * SSL_ERROR_ZERO_RETURN above). We should do the same back.
- */
-ret = SSL_shutdown(ssl);
-if (ret < 1) {
-    /*
-     * ret < 0 indicates an error. ret == 0 would be unexpected here
-     * because that means "we've sent a close_notify and we're waiting
-     * for one back". But we already know we got one from the peer
-     * because of the SSL_ERROR_ZERO_RETURN above.
-     */
-    printf("Error shutting down\n");
-    goto end;
-}
- -

The SSL_shutdown(3) function will either return 1, 0, or less than 0. A return value of 1 is a success, and a return value less than 0 is an error. More precisely a return value of 1 means that we have sent a "close_notify" alert to the server, and that we have also received one back. A return value of 0 means that we have sent a "close_notify" alert to the server, but we have not yet received one back. Usually in this scenario you would call SSL_shutdown(3) again which (with a blocking socket) would block until the "close_notify" is received. However in this case we already know that the server has sent us a "close_notify" because of the SSL_ERROR_ZERO_RETURN that we received from the call to SSL_read_ex(3). So this scenario should never happen in practice. We just treat it as an error in this example.

- -

Final clean up

- -

Before the application exits we have to clean up some memory that we allocated. If we are exiting due to an error we might also want to display further information about that error if it is available to the user:

- -
   /* Success! */
-   res = EXIT_SUCCESS;
-end:
-   /*
-    * If something bad happened then we will dump the contents of the
-    * OpenSSL error stack to stderr. There might be some useful diagnostic
-    * information there.
-    */
-   if (res == EXIT_FAILURE)
-       ERR_print_errors_fp(stderr);
-
-   /*
-    * Free the resources we allocated. We do not free the BIO object here
-    * because ownership of it was immediately transferred to the SSL object
-    * via SSL_set_bio(). The BIO will be freed when we free the SSL object.
-    */
-   SSL_free(ssl);
-   SSL_CTX_free(ctx);
-   return res;
- -

To display errors we make use of the ERR_print_errors_fp(3) function which simply dumps out the contents of any errors on the OpenSSL error stack to the specified location (in this case stderr).

- -

We need to free up the SSL object that we created for the connection via the SSL_free(3) function. Also, since we are not going to be creating any more TLS connections we must also free up the SSL_CTX via a call to SSL_CTX_free(3).

- -

TROUBLESHOOTING

- -

There are a number of things that might go wrong when running the demo application. This section describes some common things you might encounter.

- -

Failure to connect the underlying socket

- -

This could occur for numerous reasons. For example if there is a problem in the network route between the client and the server; or a firewall is blocking the communication; or the server is not in DNS. Check the network configuration.

- -

Verification failure of the server certificate

- -

A verification failure of the server certificate would result in a failure when running the SSL_connect(3) function. ERR_print_errors_fp(3) would display an error which would look something like this:

- -
Verify error: unable to get local issuer certificate
-40E74AF1F47F0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:2069:
- -

A server certificate verification failure could be caused for a number of reasons. For example

- -
- -
Failure to correctly setup the trusted certificate store
-
- -

See the page ossl-guide-tls-introduction(7) and check that your trusted certificate store is correctly configured

- -
-
Unrecognised CA
-
- -

If the CA used by the server's certificate is not in the trusted certificate store for the client then this will cause a verification failure during connection. Often this can occur if the server is using a self-signed certificate (i.e. a test certificate that has not been signed by a CA at all).

- -
-
Missing intermediate CAs
-
- -

This is a server misconfiguration where the client has the relevant root CA in its trust store, but the server has not supplied all of the intermediate CA certificates between that root CA and the server's own certificate. Therefore a trust chain cannot be established.

- -
-
Mismatched hostname
-
- -

If for some reason the hostname of the server that the client is expecting does not match the hostname in the certificate then this will cause verification to fail.

- -
-
Expired certificate
-
- -

The date that the server's certificate is valid to has passed.

- -
-
- -

The "unable to get local issuer certificate" we saw in the example above means that we have been unable to find the issuer of the server's certificate (or one of its intermediate CA certificates) in our trusted certificate store (e.g. because the trusted certificate store is misconfigured, or there are missing intermediate CAs, or the issuer is simply unrecognised).

- -

FURTHER READING

- -

See ossl-guide-tls-client-non-block(7) to read a tutorial on how to modify the client developed on this page to support a nonblocking socket.

- -

See ossl-guide-tls-server-block(7) for a tutorial on how to implement a simple TLS server handling one client at a time over a blocking socket.

- -

See ossl-guide-quic-client-block(7) to read a tutorial on how to modify the client developed on this page to support QUIC instead of TLS.

- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7), ossl-guide-tls-introduction(7), ossl-guide-tls-client-non-block(7), ossl-guide-quic-client-block(7)

- -

COPYRIGHT

- -

Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-non-block.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-non-block.html deleted file mode 100644 index ddb32294..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-client-non-block.html +++ /dev/null @@ -1,286 +0,0 @@ - - - - -ossl-guide-tls-client-non-block - - - - - - - - - - -

NAME

- -

ossl-guide-tls-client-non-block - OpenSSL Guide: Writing a simple nonblocking TLS client

- -

SIMPLE NONBLOCKING TLS CLIENT EXAMPLE

- -

This page will build on the example developed on the ossl-guide-tls-client-block(7) page which demonstrates how to write a simple blocking TLS client. On this page we will amend that demo code so that it supports a nonblocking socket.

- -

The complete source code for this example nonblocking TLS client is available in the demos/guide directory of the OpenSSL source distribution in the file tls-client-non-block.c. It is also available online at https://github.com/openssl/openssl/blob/master/demos/guide/tls-client-non-block.c.

- -

As we saw in the previous example a blocking socket is one which waits (blocks) until data is available to read if you attempt to read from it when there is no data yet. Similarly it waits when writing if the socket is currently unable to write at the moment. This can simplify the development of code because you do not have to worry about what to do in these cases. The execution of the code will simply stop until it is able to continue. However in many cases you do not want this behaviour. Rather than stopping and waiting your application may need to go and do other tasks whilst the socket is unable to read/write, for example updating a GUI or performing operations on some other socket.

- -

With a nonblocking socket attempting to read or write to a socket that is currently unable to read or write will return immediately with a non-fatal error. Although OpenSSL does the reading/writing to the socket this nonblocking behaviour is propagated up to the application so that OpenSSL I/O functions such as SSL_read_ex(3) or SSL_write_ex(3) will not block.

- -

Since this page is building on the example developed on the ossl-guide-tls-client-block(7) page we assume that you are familiar with it and we only explain how this example differs.

- -

Setting the socket to be nonblocking

- -

The first step in writing an application that supports nonblocking is to set the socket into nonblocking mode. A socket will be default be blocking. The exact details on how to do this can differ from one platform to another. Fortunately OpenSSL offers a portable function that will do this for you:

- -
/* Set to nonblocking mode */
-if (!BIO_socket_nbio(sock, 1)) {
-    sock = -1;
-    continue;
-}
- -

You do not have to use OpenSSL's function for this. You can of course directly call whatever functions that your Operating System provides for this purpose on your platform.

- -

Performing work while waiting for the socket

- -

In a nonblocking application you will need work to perform in the event that we want to read or write to the socket, but we are currently unable to. In fact this is the whole point of using a nonblocking socket, i.e. to give the application the opportunity to do something else. Whatever it is that the application has to do, it must also be prepared to come back and retry the operation that it previously attempted periodically to see if it can now complete. Ideally it would only do this in the event that the state of the underlying socket has actually changed (e.g. become readable where it wasn't before), but this does not have to be the case. It can retry at any time.

- -

Note that it is important that you retry exactly the same operation that you tried last time. You cannot start something new. For example if you were attempting to write the text "Hello World" and the operation failed because the socket is currently unable to write, then you cannot then attempt to write some other text when you retry the operation.

- -

In this demo application we will create a helper function which simulates doing other work. In fact, for the sake of simplicity, it will do nothing except wait for the state of the socket to change.

- -

We call our function wait_for_activity() because all it does is wait until the underlying socket has become readable or writeable when it wasn't before.

- -
static void wait_for_activity(SSL *ssl, int write)
-{
-    fd_set fds;
-    int width, sock;
-
-    /* Get hold of the underlying file descriptor for the socket */
-    sock = SSL_get_fd(ssl);
-
-    FD_ZERO(&fds);
-    FD_SET(sock, &fds);
-    width = sock + 1;
-
-    /*
-     * Wait until the socket is writeable or readable. We use select here
-     * for the sake of simplicity and portability, but you could equally use
-     * poll/epoll or similar functions
-     *
-     * NOTE: For the purposes of this demonstration code this effectively
-     * makes this demo block until it has something more useful to do. In a
-     * real application you probably want to go and do other work here (e.g.
-     * update a GUI, or service other connections).
-     *
-     * Let's say for example that you want to update the progress counter on
-     * a GUI every 100ms. One way to do that would be to add a 100ms timeout
-     * in the last parameter to "select" below. Then, when select returns,
-     * you check if it did so because of activity on the file descriptors or
-     * because of the timeout. If it is due to the timeout then update the
-     * GUI and then restart the "select".
-     */
-    if (write)
-        select(width, NULL, &fds, NULL, NULL);
-    else
-        select(width, &fds, NULL, NULL, NULL);
-}
- -

In this example we are using the select function because it is very simple to use and is available on most Operating Systems. However you could use any other similar function to do the same thing. select waits for the state of the underlying socket(s) to become readable/writeable before returning. It also supports a "timeout" (as do most other similar functions) so in your own applications you can make use of this to periodically wake up and perform work while waiting for the socket state to change. But we don't use that timeout capability in this example for the sake of simplicity.

- -

Handling errors from OpenSSL I/O functions

- -

An application that uses a nonblocking socket will need to be prepared to handle errors returned from OpenSSL I/O functions such as SSL_read_ex(3) or SSL_write_ex(3). Errors may be fatal (for example because the underlying connection has failed), or non-fatal (for example because we are trying to read from the underlying socket but the data has not yet arrived from the peer).

- -

SSL_read_ex(3) and SSL_write_ex(3) will return 0 to indicate an error and SSL_read(3) and SSL_write(3) will return 0 or a negative value to indicate an error. SSL_shutdown(3) will return a negative value to incidate an error.

- -

In the event of an error an application should call SSL_get_error(3) to find out what type of error has occurred. If the error is non-fatal and can be retried then SSL_get_error(3) will return SSL_ERROR_WANT_READ or SSL_ERROR_WANT_WRITE depending on whether OpenSSL wanted to read to or write from the socket but was unable to. Note that a call to SSL_read_ex(3) or SSL_read(3) can still generate SSL_ERROR_WANT_WRITE because OpenSSL may need to write protocol messages (such as to update cryptographic keys) even if the application is only trying to read data. Similarly calls to SSL_write_ex(3) or SSL_write(3) might generate SSL_ERROR_WANT_READ.

- -

Another type of non-fatal error that may occur is SSL_ERROR_ZERO_RETURN. This indicates an EOF (End-Of-File) which can occur if you attempt to read data from an SSL object but the peer has indicated that it will not send any more data on it. In this case you may still want to write data to the connection but you will not receive any more data.

- -

Fatal errors that may occur are SSL_ERROR_SYSCALL and SSL_ERROR_SSL. These indicate that the underlying connection has failed. You should not attempt to shut it down with SSL_shutdown(3). SSL_ERROR_SYSCALL indicates that OpenSSL attempted to make a syscall that failed. You can consult errno for further details. SSL_ERROR_SSL indicates that some OpenSSL error occurred. You can consult the OpenSSL error stack for further details (for example by calling ERR_print_errors(3) to print out details of errors that have occurred).

- -

In our demo application we will write a function to handle these errors from OpenSSL I/O functions:

- -
static int handle_io_failure(SSL *ssl, int res)
-{
-    switch (SSL_get_error(ssl, res)) {
-    case SSL_ERROR_WANT_READ:
-        /* Temporary failure. Wait until we can read and try again */
-        wait_for_activity(ssl, 0);
-        return 1;
-
-    case SSL_ERROR_WANT_WRITE:
-        /* Temporary failure. Wait until we can write and try again */
-        wait_for_activity(ssl, 1);
-        return 1;
-
-    case SSL_ERROR_ZERO_RETURN:
-        /* EOF */
-        return 0;
-
-    case SSL_ERROR_SYSCALL:
-        return -1;
-
-    case SSL_ERROR_SSL:
-        /*
-        * If the failure is due to a verification error we can get more
-        * information about it from SSL_get_verify_result().
-        */
-        if (SSL_get_verify_result(ssl) != X509_V_OK)
-            printf("Verify error: %s\n",
-                X509_verify_cert_error_string(SSL_get_verify_result(ssl)));
-        return -1;
-
-    default:
-        return -1;
-    }
-}
- -

This function takes as arguments the SSL object that represents the connection, as well as the return code from the I/O function that failed. In the event of a non-fatal failure, it waits until a retry of the I/O operation might succeed (by using the wait_for_activity() function that we developed in the previous section). It returns 1 in the event of a non-fatal error (except EOF), 0 in the event of EOF, or -1 if a fatal error occurred.

- -

Creating the SSL_CTX and SSL objects

- -

In order to connect to a server we must create SSL_CTX and SSL objects for this. The steps do this are the same as for a blocking client and are explained on the ossl-guide-tls-client-block(7) page. We won't repeat that information here.

- -

Performing the handshake

- -

As in the demo for a blocking TLS client we use the SSL_connect(3) function to perform the TLS handshake with the server. Since we are using a nonblocking socket it is very likely that calls to this function will fail with a non-fatal error while we are waiting for the server to respond to our handshake messages. In such a case we must retry the same SSL_connect(3) call at a later time. In this demo we this in a loop:

- -
/* Do the handshake with the server */
-while ((ret = SSL_connect(ssl)) != 1) {
-    if (handle_io_failure(ssl, ret) == 1)
-        continue; /* Retry */
-    printf("Failed to connect to server\n");
-    goto end; /* Cannot retry: error */
-}
- -

We continually call SSL_connect(3) until it gives us a success response. Otherwise we use the handle_io_failure() function that we created earlier to work out what we should do next. Note that we do not expect an EOF to occur at this stage, so such a response is treated in the same way as a fatal error.

- -

Sending and receiving data

- -

As with the blocking TLS client demo we use the SSL_write_ex(3) function to send data to the server. As with SSL_connect(3) above, because we are using a nonblocking socket, this call could fail with a non-fatal error. In that case we should retry exactly the same SSL_write_ex(3) call again. Note that the parameters must be exactly the same, i.e. the same pointer to the buffer to write with the same length. You must not attempt to send different data on a retry. An optional mode does exist (SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER) which will configure OpenSSL to allow the buffer being written to change from one retry to the next. However, in this case, you must still retry exactly the same data - even though the buffer that contains that data may change location. See SSL_CTX_set_mode(3) for further details. As in the TLS client blocking tutorial (ossl-guide-tls-client-block(7)) we write the request in three chunks.

- -
/* Write an HTTP GET request to the peer */
-while (!SSL_write_ex(ssl, request_start, strlen(request_start), &written)) {
-    if (handle_io_failure(ssl, 0) == 1)
-        continue; /* Retry */
-    printf("Failed to write start of HTTP request\n");
-    goto end; /* Cannot retry: error */
-}
-while (!SSL_write_ex(ssl, hostname, strlen(hostname), &written)) {
-    if (handle_io_failure(ssl, 0) == 1)
-        continue; /* Retry */
-    printf("Failed to write hostname in HTTP request\n");
-    goto end; /* Cannot retry: error */
-}
-while (!SSL_write_ex(ssl, request_end, strlen(request_end), &written)) {
-    if (handle_io_failure(ssl, 0) == 1)
-        continue; /* Retry */
-    printf("Failed to write end of HTTP request\n");
-    goto end; /* Cannot retry: error */
-}
- -

On a write we do not expect to see an EOF response so we treat that case in the same way as a fatal error.

- -

Reading a response back from the server is similar:

- -
do {
-    /*
-     * Get up to sizeof(buf) bytes of the response. We keep reading until
-     * the server closes the connection.
-     */
-    while (!eof && !SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) {
-        switch (handle_io_failure(ssl, 0)) {
-        case 1:
-            continue; /* Retry */
-        case 0:
-            eof = 1;
-            continue;
-        case -1:
-        default:
-            printf("Failed reading remaining data\n");
-            goto end; /* Cannot retry: error */
-        }
-    }
-    /*
-     * OpenSSL does not guarantee that the returned data is a string or
-     * that it is NUL terminated so we use fwrite() to write the exact
-     * number of bytes that we read. The data could be non-printable or
-     * have NUL characters in the middle of it. For this simple example
-     * we're going to print it to stdout anyway.
-     */
-    if (!eof)
-        fwrite(buf, 1, readbytes, stdout);
-} while (!eof);
-/* In case the response didn't finish with a newline we add one now */
-printf("\n");
- -

The main difference this time is that it is valid for us to receive an EOF response when trying to read data from the server. This will occur when the server closes down the connection after sending all the data in its response.

- -

In this demo we just print out all the data we've received back in the response from the server. We continue going around the loop until we either encounter a fatal error, or we receive an EOF (indicating a graceful finish).

- -

Shutting down the connection

- -

As in the TLS blocking example we must shutdown the connection when we are finished with it.

- -

If our application was initiating the shutdown then we would expect to see SSL_shutdown(3) give a return value of 0, and then we would continue to call it until we received a return value of 1 (meaning we have successfully completed the shutdown). In this particular example we don't expect SSL_shutdown() to return 0 because we have already received EOF from the server indicating that it has shutdown already. So we just keep calling it until SSL_shutdown() returns 1. Since we are using a nonblocking socket we might expect to have to retry this operation several times. If SSL_shutdown(3) returns a negative result then we must call SSL_get_error(3) to work out what to do next. We use our handle_io_failure() function that we developed earlier for this:

- -
/*
- * The peer already shutdown gracefully (we know this because of the
- * SSL_ERROR_ZERO_RETURN (i.e. EOF) above). We should do the same back.
- */
-while ((ret = SSL_shutdown(ssl)) != 1) {
-    if (ret < 0 && handle_io_failure(ssl, ret) == 1)
-        continue; /* Retry */
-    /*
-     * ret == 0 is unexpected here because that means "we've sent a
-     * close_notify and we're waiting for one back". But we already know
-     * we got one from the peer because of the SSL_ERROR_ZERO_RETURN
-     * (i.e. EOF) above.
-     */
-    printf("Error shutting down\n");
-    goto end; /* Cannot retry: error */
-}
- -

Final clean up

- -

As with the blocking TLS client example, once our connection is finished with we must free it. The steps to do this for this example are the same as for the blocking example, so we won't repeat it here.

- -

FURTHER READING

- -

See ossl-guide-tls-client-block(7) to read a tutorial on how to write a blocking TLS client. See ossl-guide-quic-client-block(7) to see how to do the same thing for a QUIC client.

- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7), ossl-guide-tls-introduction(7), ossl-guide-tls-client-block(7), ossl-guide-quic-client-block(7)

- -

COPYRIGHT

- -

Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-introduction.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-introduction.html deleted file mode 100644 index efda9776..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-introduction.html +++ /dev/null @@ -1,163 +0,0 @@ - - - - -ossl-guide-tls-introduction - - - - - - - - - - -

NAME

- -

ossl-guide-tls-introduction - OpenSSL Guide: An introduction to SSL/TLS in OpenSSL

- -

INTRODUCTION

- -

This page will provide an introduction to some basic SSL/TLS concepts and background and how it is used within OpenSSL. It assumes that you have a basic understanding of TCP/IP and sockets.

- -

WHAT IS TLS?

- -

TLS stands for Transport Layer Security. TLS allows applications to securely communicate with each other across a network such that the confidentiality of the information exchanged is protected (i.e. it prevents eavesdroppers from listening in to the communication). Additionally it protects the integrity of the information exchanged to prevent an attacker from changing it. Finally it provides authentication so that one or both parties can be sure that they are talking to who they think they are talking to and not some imposter.

- -

Sometimes TLS is referred to by its predecessor's name SSL (Secure Sockets Layer). OpenSSL dates from a time when the SSL name was still in common use and hence many of the functions and names used by OpenSSL contain the "SSL" abbreviation. Nonetheless OpenSSL contains a fully fledged TLS implementation.

- -

TLS is based on a client/server model. The application that initiates a communication is known as the client. The application that responds to a remotely initiated communication is the server. The term "endpoint" refers to either of the client or the server in a communication. The term "peer" refers to the endpoint at the other side of the communication that we are currently referring to. So if we are currently talking about the client then the peer would be the server.

- -

TLS is a standardised protocol and there are numerous different implementations of it. Due to the standards an OpenSSL client or server is able to communicate seamlessly with an application using some different implementation of TLS. TLS (and its predecessor SSL) have been around for a significant period of time and the protocol has undergone various changes over the years. Consequently there are different versions of the protocol available. TLS includes the ability to perform version negotiation so that the highest protocol version that the client and server share in common is used.

- -

TLS acts as a security layer over some lower level transport protocol. Typically the transport layer will be TCP.

- -

SSL AND TLS VERSIONS

- -

SSL was initially developed by Netscape Communications and its first publicly released version was SSLv2 in 1995. Note that SSLv1 was never publicly released. SSLv3 came along quickly afterwards in 1996. Subsequently development of the protocol moved to the IETF which released the first version of TLS (TLSv1.0) in 1999 as RFC2246. TLSv1.1 was released in 2006 as RFC4346 and TLSv1.2 came along in 2008 as RFC5246. The most recent version of the standard is TLSv1.3 which was released in 2018 as RFC8446.

- -

Today TLSv1.3 and TLSv1.2 are the most commonly deployed versions of the protocol. The IETF have formally deprecated TLSv1.1 and TLSv1.0, so anything below TLSv1.2 should be avoided since the older protocol versions are susceptible to security problems.

- -

OpenSSL does not support SSLv2 (it was removed in OpenSSL 1.1.0). Support for SSLv3 is available as a compile time option - but it is not built by default. Support for TLSv1.0, TLSv1.1, TLSv1.2 and TLSv1.3 are all available by default in a standard build of OpenSSL. However special run-time configuration is required in order to make TLSv1.0 and TLSv1.1 work successfully.

- -

OpenSSL will always try to negotiate the highest protocol version that it has been configured to support. In most cases this will mean either TLSv1.3 or TLSv1.2 is chosen.

- -

CERTIFICATES

- -

In order for a client to establish a connection to a server it must authenticate the identity of that server, i.e. it needs to confirm that the server is really the server that it claims to be and not some imposter. In order to do this the server will send to the client a digital certificate (also commonly referred to as an X.509 certificate). The certificate contains various information about the server including its full DNS hostname. Also within the certificate is the server's public key. The server operator will have a private key which is linked to the public key and must not be published.

- -

Along with the certificate the server will also send to the client proof that it knows the private key associated with the public key in the certificate. It does this by digitally signing a message to the client using that private key. The client can verify the signature using the public key from the certificate. If the signature verifies successfully then the client knows that the server is in possession of the correct private key.

- -

The certificate that the server sends will also be signed by a Certificate Authority. The Certificate Authority (commonly known as a CA) is a third party organisation that is responsible for verifying the information in the server's certificate (including its DNS hostname). The CA should only sign the certificate if it has been able to confirm that the server operator does indeed have control of the server associated with its DNS hostname and that the server operator has control of the private key.

- -

In this way, if the client trusts the CA that has signed the server's certificate and it can verify that the server has the right private key then it can trust that the server truly does represent the DNS hostname given in the certificate. The client must also verify that the hostname given in the certificate matches the hostname that it originally sent the request to.

- -

Once all of these checks have been done the client has successfully verified the identify of the server. OpenSSL can perform all of these checks automatically but it must be provided with certain information in order to do so, i.e. the set of CAs that the client trusts as well as the DNS hostname for the server that this client is trying to connect to.

- -

Note that it is common for certificates to be built up into a chain. For example a server's certificate may be signed by a key owned by a an intermediate CA. That intermediate CA also has a certificate containing its public key which is in turn signed by a key owned by a root CA. The client may only trust the root CA, but if the server sends both its own certificate and the certificate for the intermediate CA then the client can still successfully verify the identity of the server. There is a chain of trust between the root CA and the server.

- -

By default it is only the client that authenticates the server using this method. However it is also possible to set things up such that the server additionally authenticates the client. This is known as "client authentication". In this approach the client will still authenticate the server in the same way, but the server will request a certificate from the client. The client sends the server its certificate and the server authenticates it in the same way that the client does.

- -

TRUSTED CERTIFICATE STORE

- -

The system described above only works if a chain of trust can be built between the set of CAs that the endpoint trusts and the certificate that the peer is using. The endpoint must therefore have a set of certificates for CAs that it trusts before any communication can take place. OpenSSL itself does not provide such a set of certificates. Therefore you will need to make sure you have them before you start if you are going to be verifying certificates (i.e. always if the endpoint is a client, and only if client authentication is in use for a server).

- -

Fortunately other organisations do maintain such a set of certificates. If you have obtained your copy of OpenSSL from an Operating System (OS) vendor (e.g. a Linux distribution) then normally the set of CA certificates will also be distributed with that copy.

- -

You can check this by running the OpenSSL command line application like this:

- -
openssl version -d
- -

This will display a value for OPENSSLDIR. Look in the certs sub directory of OPENSSLDIR and check its contents. For example if OPENSSLDIR is "/usr/local/ssl", then check the contents of the "/usr/local/ssl/certs" directory.

- -

You are expecting to see a list of files, typically with the suffix ".pem" or ".0". If they exist then you already have a suitable trusted certificate store.

- -

If you are running your version of OpenSSL on Windows then OpenSSL (from version 3.2 onwards) will use the default Windows set of trusted CAs.

- -

If you have built your version of OpenSSL from source, or obtained it from some other location and it does not have a set of trusted CA certificates then you will have to obtain them yourself. One such source is the Curl project. See the page https://curl.se/docs/caextract.html where you can download trusted certificates in a single file. Rename the file to "cert.pem" and store it directly in OPENSSLDIR. For example if OPENSSLDIR is "/usr/local/ssl", then save it as "/usr/local/ssl/cert.pem".

- -

You can also use environment variables to override the default location that OpenSSL will look for its trusted certificate store. Set the SSL_CERT_PATH environment variable to give the directory where OpenSSL should looks for its certificates or the SSL_CERT_FILE environment variable to give the name of a single file containing all of the certificates. See openssl-env(7) for further details about OpenSSL environment variables. For example you could use this capability to have multiple versions of OpenSSL all installed on the same system using different values for OPENSSLDIR but all using the same trusted certificate store.

- -

You can test that your trusted certificate store is setup correctly by using it via the OpenSSL command line. Use the following command to connect to a TLS server:

- -
openssl s_client www.openssl.org:443
- -

Once the command has connected type the letter "Q" followed by "<enter>" to exit the session. This will print a lot of information on the screen about the connection. Look for a block of text like this:

- -
SSL handshake has read 4584 bytes and written 403 bytes
-Verification: OK
- -

Hopefully if everything has worked then the "Verification" line will say "OK". If its not working as expected then you might see output like this instead:

- -
SSL handshake has read 4584 bytes and written 403 bytes
-Verification error: unable to get local issuer certificate
- -

The "unable to get local issuer certificate" error means that OpenSSL has been unable to find a trusted CA for the chain of certificates provided by the server in its trusted certificate store. Check your trusted certificate store configuration again.

- -

Note that s_client is a testing tool and will still allow you to connect to the TLS server regardless of the verification error. Most applications should not do this and should abort the connection in the event of a verification error.

- -

IMPORTANT OBJECTS FOR AN OPENSSL TLS APPLICATION

- -

A TLS connection is represented by the SSL object in an OpenSSL based application. Once a connection with a remote peer has been established an endpoint can "write" data to the SSL object to send data to the peer, or "read" data from it to receive data from the server.

- -

A new SSL object is created from an SSL_CTX object. Think of an SSL_CTX as a "factory" for creating SSL objects. You can create a single SSL_CTX object and then create multiple connections (i.e. SSL objects) from it. Typically you can set up common configuration options on the SSL_CTX so that all the SSL object created from it inherit the same configuration options.

- -

Note that internally to OpenSSL various items that are shared between multiple SSL objects are cached in the SSL_CTX for performance reasons. Therefore it is considered best practice to create one SSL_CTX for use by multiple SSL objects instead of having one SSL_CTX for each SSL object that you create.

- -

Each SSL object is also associated with two BIO objects. A BIO object is used for sending or receiving data from the underlying transport layer. For example you might create a BIO to represent a TCP socket. The SSL object uses one BIO for reading data and one BIO for writing data. In most cases you would use the same BIO for each direction but there could be some circumstances where you want them to be different.

- -

It is up to the application programmer to create the BIO objects that are needed and supply them to the SSL object. See ossl-guide-tls-client-block(7) and ossl-guide-tls-server-block(7) for usage examples.

- -

Finally, an endpoint can establish a "session" with its peer. The session holds various TLS parameters about the connection between the client and the server. The session details can then be reused in a subsequent connection attempt to speed up the process of connecting. This is known as "resumption". Sessions are represented in OpenSSL by the SSL_SESSION object. In TLSv1.2 there is always exactly one session per connection. In TLSv1.3 there can be any number per connection including none.

- -

PHASES OF A TLS CONNECTION

- -

A TLS connection starts with an initial "set up" phase. The endpoint creates the SSL_CTX (if one has not already been created) and configures it.

- -

A client then creates an SSL object to represent the new TLS connection. Any connection specific configuration parameters are then applied and the underlying socket is created and associated with the SSL via BIO objects.

- -

A server will create a socket for listening for incoming connection attempts from clients. Once a connection attempt is made the server will create an SSL object in the same way as for a client and associate it with a BIO for the newly created incoming socket.

- -

After set up is complete the TLS "handshake" phase begins. A TLS handshake consists of the client and server exchanging a series of TLS handshake messages to establish the connection. The client starts by sending a "ClientHello" handshake message and the server responds with a "ServerHello". The handshake is complete once an endpoint has sent its last message (known as the "Finished" message) and received a Finished message from its peer. Note that this might occur at slightly different times for each peer. For example in TLSv1.3 the server always sends its Finished message before the client. The client later responds with its Finished message. At this point the client has completed the handshake because it has both sent and received a Finished message. The server has sent its Finished message but the Finished message from the client may still be in-flight, so the server is still in the handshake phase. It is even possible that the server will fail to complete the handshake (if it considers there is some problem with the messages sent from the client), even though the client may have already progressed to sending application data. In TLSv1.2 this can happen the other way around, i.e. the server finishes first and the client finishes second.

- -

Once the handshake is complete the application data transfer phase begins. Strictly speaking there are some situations where the client can start sending application data even earlier (using the TLSv1.3 "early data" capability) - but we're going to skip over that for this basic introduction.

- -

During application data transfer the client and server can read and write data to the connection freely. The details of this are typically left to some higher level application protocol (for example HTTP). Not all information exchanged during this phase is application data. Some protocol level messages may still be exchanged - so it is not necessarily the case that, just because the underlying socket is "readable", that application data will be available to read.

- -

When the connection is no longer required then it should be shutdown. A shutdown may be initiated by either the client or the server via a message known as a "close_notify" alert. The client or server that receives a close_notify may respond with one and then the connection is fully closed and application data can no longer be sent or received.

- -

Once shutdown is complete a TLS application must clean up by freeing the SSL object.

- -

FURTHER READING

- -

See ossl-guide-tls-client-block(7) for an example of how to apply these concepts in order to write a simple TLS client based on a blocking socket. See ossl-guide-tls-server-block(7) for an example of how to apply these concepts in order to write a simple TLS server handling one client at a time over a blocking socket. See ossl-guide-quic-introduction(7) for an introduction to QUIC in OpenSSL.

- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7), ossl-guide-tls-client-block(7), ossl-guide-tls-server-block(7), ossl-guide-quic-introduction(7)

- -

COPYRIGHT

- -

Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-server-block.html b/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-server-block.html deleted file mode 100644 index 4c9d3a73..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl-guide-tls-server-block.html +++ /dev/null @@ -1,275 +0,0 @@ - - - - -ossl-guide-tls-server-block - - - - - - - - - - -

NAME

- -

ossl-guide-tls-server-block - OpenSSL Guide: Writing a simple blocking TLS server

- -

SIMPLE BLOCKING TLS SERVER EXAMPLE

- -

This page will present various source code samples demonstrating how to write a simple, non-concurrent, TLS "echo" server application which accepts one client connection at a time, echoing input from the client back to the same client. Once the current client disconnects, the next client connection is accepted.

- -

Both the acceptor socket and client connections are "blocking". A more typical server might use nonblocking sockets with an event loop and callbacks for I/O events.

- -

The complete source code for this example blocking TLS server is available in the demos/guide directory of the OpenSSL source distribution in the file tls-server-block.c. It is also available online at https://github.com/openssl/openssl/blob/master/demos/guide/tls-server-block.c.

- -

We assume that you already have OpenSSL installed on your system; that you already have some fundamental understanding of OpenSSL concepts and TLS (see ossl-guide-libraries-introduction(7) and ossl-guide-tls-introduction(7)); and that you know how to write and build C code and link it against the libcrypto and libssl libraries that are provided by OpenSSL. It also assumes that you have a basic understanding of TCP/IP and sockets.

- -

Creating the SSL_CTX and SSL objects

- -

The first step is to create an SSL_CTX object for our server. We use the SSL_CTX_new(3) function for this purpose. We could alternatively use SSL_CTX_new_ex(3) if we want to associate the SSL_CTX with a particular OSSL_LIB_CTX (see ossl-guide-libraries-introduction(7) to learn about OSSL_LIB_CTX). We pass as an argument the return value of the function TLS_server_method(3). You should use this method whenever you are writing a TLS server. This method will automatically use TLS version negotiation to select the highest version of the protocol that is mutually supported by both the server and the client.

- -
/*
- * An SSL_CTX holds shared configuration information for multiple
- * subsequent per-client SSL connections.
- */
-ctx = SSL_CTX_new(TLS_server_method());
-if (ctx == NULL) {
-    ERR_print_errors_fp(stderr);
-    errx(res, "Failed to create server SSL_CTX");
-}
- -

We would also like to restrict the TLS versions that we are willing to accept to TLSv1.2 or above. TLS protocol versions earlier than that are generally to be avoided where possible. We can do that using SSL_CTX_set_min_proto_version(3):

- -
/*
- * TLS versions older than TLS 1.2 are deprecated by IETF and SHOULD
- * be avoided if possible.
- */
-if (!SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION)) {
-    SSL_CTX_free(ctx);
-    ERR_print_errors_fp(stderr);
-    errx(res, "Failed to set the minimum TLS protocol version");
-}
- -

Next we configure some option flags, see SSL_CTX_set_options(3) for details:

- -
/*
- * Tolerate clients hanging up without a TLS "shutdown".  Appropriate in all
- * application protocols which perform their own message "framing", and
- * don't rely on TLS to defend against "truncation" attacks.
- */
-opts = SSL_OP_IGNORE_UNEXPECTED_EOF;
-
-/*
- * Block potential CPU-exhaustion attacks by clients that request frequent
- * renegotiation.  This is of course only effective if there are existing
- * limits on initial full TLS handshake or connection rates.
- */
-opts |= SSL_OP_NO_RENEGOTIATION;
-
-/*
- * Most servers elect to use their own cipher preference rather than that of
- * the client.
- */
-opts |= SSL_OP_CIPHER_SERVER_PREFERENCE;
-
-/* Apply the selection options */
-SSL_CTX_set_options(ctx, opts);
- -

Servers need a private key and certificate. Though anonymous ciphers (no server certificate) are possible in TLS 1.2, they are rarely applicable, and are not currently defined for TLS 1.3. Additional intermediate issuer CA certificates are often also required, and both the server (end-entity or EE) certificate and the issuer ("chain") certificates are most easily configured in a single "chain file". Below we load such a chain file (the EE certificate must appear first), and then load the corresponding private key, checking that it matches the server certificate. No checks are performed to check the integrity of the chain (CA signatures or certificate expiration dates, for example).

- -
/*
- * Load the server's certificate *chain* file (PEM format), which includes
- * not only the leaf (end-entity) server certificate, but also any
- * intermediate issuer-CA certificates.  The leaf certificate must be the
- * first certificate in the file.
- *
- * In advanced use-cases this can be called multiple times, once per public
- * key algorithm for which the server has a corresponding certificate.
- * However, the corresponding private key (see below) must be loaded first,
- * *before* moving on to the next chain file.
- */
-if (SSL_CTX_use_certificate_chain_file(ctx, "chain.pem") <= 0) {
-    SSL_CTX_free(ctx);
-    ERR_print_errors_fp(stderr);
-    errx(res, "Failed to load the server certificate chain file");
-}
-
-/*
- * Load the corresponding private key, this also checks that the private
- * key matches the just loaded end-entity certificate.  It does not check
- * whether the certificate chain is valid, the certificates could be
- * expired, or may otherwise fail to form a chain that a client can validate.
- */
-if (SSL_CTX_use_PrivateKey_file(ctx, "pkey.pem", SSL_FILETYPE_PEM) <= 0) {
-    SSL_CTX_free(ctx);
-    ERR_print_errors_fp(stderr);
-    errx(res, "Error loading the server private key file, "
-              "possible key/cert mismatch???");
-}
- -

Next we enable session caching, which makes it possible for clients to more efficiently make additional TLS connections after completing an initial full TLS handshake. With TLS 1.3, session resumption typically still performs a fresh key agreement, but the certificate exchange is avoided.

- -
/*
- * Servers that want to enable session resumption must specify a cache id
- * byte array, that identifies the server application, and reduces the
- * chance of inappropriate cache sharing.
- */
-SSL_CTX_set_session_id_context(ctx, (void *)cache_id, sizeof(cache_id));
-SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_SERVER);
-
-/*
- * How many client TLS sessions to cache.  The default is
- * SSL_SESSION_CACHE_MAX_SIZE_DEFAULT (20k in recent OpenSSL versions),
- * which may be too small or too large.
- */
-SSL_CTX_sess_set_cache_size(ctx, 1024);
-
-/*
- * Sessions older than this are considered a cache miss even if still in
- * the cache.  The default is two hours.  Busy servers whose clients make
- * many connections in a short burst may want a shorter timeout, on lightly
- * loaded servers with sporadic connections from any given client, a longer
- * time may be appropriate.
- */
-SSL_CTX_set_timeout(ctx, 3600);
- -

Most servers, including this one, do not solicit client certificates. We therefore do not need a "trust store" and allow the handshake to complete even when the client does not present a certificate. Note: Even if a client did present a trusted ceritificate, for it to be useful, the server application would still need custom code to use the verified identity to grant nondefault access to that particular client. Some servers grant access to all clients with certificates from a private CA, this then requires processing of certificate revocation lists to deauthorise a client. It is often simpler and more secure to instead keep a list of authorised public keys.

- -

Though this is the default setting, we explicitly call the SSL_CTX_set_verify(3) function and pass the SSL_VERIFY_NONE value to it. The final argument to this function is a callback that you can optionally supply to override the default handling for certificate verification. Most applications do not need to do this so this can safely be set to NULL to get the default handling.

- -
/*
- * Clients rarely employ certificate-based authentication, and so we don't
- * require "mutual" TLS authentication (indeed there's no way to know
- * whether or how the client authenticated the server, so the term "mutual"
- * is potentially misleading).
- *
- * Since we're not soliciting or processing client certificates, we don't
- * need to configure a trusted-certificate store, so no call to
- * SSL_CTX_set_default_verify_paths() is needed.  The server's own
- * certificate chain is assumed valid.
- */
-SSL_CTX_set_verify(ctx, SSL_VERIFY_NONE, NULL);
- -

That is all the setup that we need to do for the SSL_CTX. Next we create an acceptor BIO on which to accept client connections. This just records the intended port (and optional "host:" prefix), without actually creating the socket. This delayed processing allows the programmer to specify additional behaviours before the listening socket is actually created.

- -
/*
- * Create a listener socket wrapped in a BIO.
- * The first call to BIO_do_accept() initialises the socket
- */
-acceptor_bio = BIO_new_accept(hostport);
-if (acceptor_bio == NULL) {
-    SSL_CTX_free(ctx);
-    ERR_print_errors_fp(stderr);
-    errx(res, "Error creating acceptor bio");
-}
- -

Servers almost always want to use the "SO_REUSEADDR" option to avoid startup failures if there are still lingering client connections, so we do that before making the first call to BIO_do_accept(3) which creates the listening socket, without accepting a client connection. Subsequent calls to the same function will accept new connections.

- -
BIO_set_bind_mode(acceptor_bio, BIO_BIND_REUSEADDR);
-if (BIO_do_accept(acceptor_bio) <= 0) {
-    SSL_CTX_free(ctx);
-    ERR_print_errors_fp(stderr);
-    errx(res, "Error setting up acceptor socket");
-}
- -

Server loop

- -

The server now enters a "forever" loop handling one client connection at a time. Before each connection we clear the OpenSSL error stack, so that any error reports are related to just the new connection.

- -
/* Pristine error stack for each new connection */
-ERR_clear_error();
- -

At this point the server blocks to accept the next client:

- -
/* Wait for the next client to connect */
-if (BIO_do_accept(acceptor_bio) <= 0) {
-    /* Client went away before we accepted the connection */
-    continue;
-}
- -

On success the accepted client connection has been wrapped in a fresh BIO and pushed onto the end of the acceptor BIO chain. We pop it off returning the acceptor BIO to its initial state.

- -
/* Pop the client connection from the BIO chain */
-client_bio = BIO_pop(acceptor_bio);
-fprintf(stderr, "New client connection accepted\n");
- -

Next, we create an SSL object by calling the SSL_new(3) function and passing the SSL_CTX we created as an argument. The client connection BIO is configured as the I/O conduit for this SSL handle. SSL_set_bio transfers ownership of the BIO or BIOs involved (our client_bio) to the SSL handle.

- -
/* Associate a new SSL handle with the new connection */
-if ((ssl = SSL_new(ctx)) == NULL) {
-    ERR_print_errors_fp(stderr);
-    warnx("Error creating SSL handle for new connection");
-    BIO_free(client_bio);
-    continue;
-}
-SSL_set_bio(ssl, client_bio, client_bio);
- -

And now we're ready to attempt the SSL handshake. With a blocking socket OpenSSL will perform all the read and write operations required to complete the handshake (or detect and report a failure) before returning.

- -
/* Attempt an SSL handshake with the client */
-if (SSL_accept(ssl) <= 0) {
-    ERR_print_errors_fp(stderr);
-    warnx("Error performing SSL handshake with client");
-    SSL_free(ssl);
-    continue;
-}
- -

With the handshake complete, the server loops echoing client input back to the client:

- -
while (SSL_read_ex(ssl, buf, sizeof(buf), &nread) > 0) {
-    if (SSL_write_ex(ssl, buf, nread, &nwritten) > 0 &&
-        nwritten == nread) {
-        total += nwritten;
-        continue;
-    }
-    warnx("Error echoing client input");
-    break;
-}
- -

Once the client closes its connection, we report the number of bytes sent to stderr and free the SSL handle, which also frees the client_bio and closes the underlying socket.

- -
fprintf(stderr, "Client connection closed, %zu bytes sent\n", total);
-SSL_free(ssl);
- -

The server is now ready to accept the next client connection.

- -

Final clean up

- -

If the server could somehow manage to break out of the infinite loop, and be ready to exit, it would first deallocate the constructed SSL_CTX.

- -
/*
- * Unreachable placeholder cleanup code, the above loop runs forever.
- */
-SSL_CTX_free(ctx);
-return EXIT_SUCCESS;
- -

SEE ALSO

- -

ossl-guide-introduction(7), ossl-guide-libraries-introduction(7), ossl-guide-libssl-introduction(7), ossl-guide-tls-introduction(7), ossl-guide-tls-client-non-block(7), ossl-guide-quic-client-block(7)

- -

COPYRIGHT

- -

Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl_store-file.html b/openssl-install/share/doc/openssl/html/man7/ossl_store-file.html deleted file mode 100644 index b2a0cdcb..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl_store-file.html +++ /dev/null @@ -1,60 +0,0 @@ - - - - -ossl_store-file - - - - - - - - - - -

NAME

- -

ossl_store-file - The store 'file' scheme loader

- -

SYNOPSIS

- -

#include <openssl/store.h>

- -

DESCRIPTION

- -

Support for the 'file' scheme is built into libcrypto. Since files come in all kinds of formats and content types, the 'file' scheme has its own layer of functionality called "file handlers", which are used to try to decode diverse types of file contents.

- -

In case a file is formatted as PEM, each called file handler receives the PEM name (everything following any '-----BEGIN ') as well as possible PEM headers, together with the decoded PEM body. Since PEM formatted files can contain more than one object, the file handlers are called upon for each such object.

- -

If the file isn't determined to be formatted as PEM, the content is loaded in raw form in its entirety and passed to the available file handlers as is, with no PEM name or headers.

- -

Each file handler is expected to handle PEM and non-PEM content as appropriate. Some may refuse non-PEM content for the sake of determinism (for example, there are keys out in the wild that are represented as an ASN.1 OCTET STRING. In raw form, it's not easily possible to distinguish those from any other data coming as an ASN.1 OCTET STRING, so such keys would naturally be accepted as PEM files only).

- -

NOTES

- -

When needed, the 'file' scheme loader will require a pass phrase by using the UI_METHOD that was passed via OSSL_STORE_open(). This pass phrase is expected to be UTF-8 encoded, anything else will give an undefined result. The files made accessible through this loader are expected to be standard compliant with regards to pass phrase encoding. Files that aren't should be re-generated with a correctly encoded pass phrase. See passphrase-encoding(7) for more information.

- -

SEE ALSO

- -

ossl_store(7), passphrase-encoding(7)

- -

COPYRIGHT

- -

Copyright 2018 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/ossl_store.html b/openssl-install/share/doc/openssl/html/man7/ossl_store.html deleted file mode 100644 index e87c7042..00000000 --- a/openssl-install/share/doc/openssl/html/man7/ossl_store.html +++ /dev/null @@ -1,110 +0,0 @@ - - - - -ossl_store - - - - - - - - - - -

NAME

- -

ossl_store - Store retrieval functions

- -

SYNOPSIS

- -

#include <openssl/store.h>

- -

DESCRIPTION

- -

General

- -

A STORE is a layer of functionality to retrieve a number of supported objects from a repository of any kind, addressable as a filename or as a URI.

- -

The functionality supports the pattern "open a channel to the repository", "loop and retrieve one object at a time", and "finish up by closing the channel".

- -

The retrieved objects are returned as a wrapper type OSSL_STORE_INFO, from which an OpenSSL type can be retrieved.

- -

URI schemes and loaders

- -

Support for a URI scheme is called a STORE "loader", and can be added dynamically from the calling application or from a loadable engine.

- -

Support for the 'file' scheme is built into libcrypto. See ossl_store-file(7) for more information.

- -

UI_METHOD and pass phrases

- -

The OSS_STORE API does nothing to enforce any specific format or encoding on the pass phrase that the UI_METHOD provides. However, the pass phrase is expected to be UTF-8 encoded. The result of any other encoding is undefined.

- -

EXAMPLES

- -

A generic call

- -
#include <openssl/ui.h> /* for UI_get_default_method */
-#include <openssl/store.h>
-
-OSSL_STORE_CTX *ctx = OSSL_STORE_open("file:/foo/bar/data.pem",
-                       UI_get_default_method(), NULL, NULL, NULL);
-
-/*
- * OSSL_STORE_eof() simulates file semantics for any repository to signal
- * that no more data can be expected
- */
-while (!OSSL_STORE_eof(ctx)) {
-    OSSL_STORE_INFO *info = OSSL_STORE_load(ctx);
-
-    /*
-     * Do whatever is necessary with the OSSL_STORE_INFO,
-     * here just one example
-     */
-    switch (OSSL_STORE_INFO_get_type(info)) {
-    case OSSL_STORE_INFO_CERT:
-        /* Print the X.509 certificate text */
-        X509_print_fp(stdout, OSSL_STORE_INFO_get0_CERT(info));
-        /* Print the X.509 certificate PEM output */
-        PEM_write_X509(stdout, OSSL_STORE_INFO_get0_CERT(info));
-        break;
-    }
-    OSSL_STORE_INFO_free(info);
-}
-
-OSSL_STORE_close(ctx);
- -

SEE ALSO

- -

OSSL_STORE_INFO(3), OSSL_STORE_LOADER(3), OSSL_STORE_open(3), OSSL_STORE_expect(3), OSSL_STORE_SEARCH(3)

- -

COPYRIGHT

- -

Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/passphrase-encoding.html b/openssl-install/share/doc/openssl/html/man7/passphrase-encoding.html deleted file mode 100644 index 863e9191..00000000 --- a/openssl-install/share/doc/openssl/html/man7/passphrase-encoding.html +++ /dev/null @@ -1,124 +0,0 @@ - - - - -passphrase-encoding - - - - - - - - - - -

NAME

- -

passphrase-encoding - How diverse parts of OpenSSL treat pass phrases character encoding

- -

DESCRIPTION

- -

In a modern world with all sorts of character encodings, the treatment of pass phrases has become increasingly complex. This manual page attempts to give an overview over how this problem is currently addressed in different parts of the OpenSSL library.

- -

The general case

- -

The OpenSSL library doesn't treat pass phrases in any special way as a general rule, and trusts the application or user to choose a suitable character set and stick to that throughout the lifetime of affected objects. This means that for an object that was encrypted using a pass phrase encoded in ISO-8859-1, that object needs to be decrypted using a pass phrase encoded in ISO-8859-1. Using the wrong encoding is expected to cause a decryption failure.

- -

PKCS#12

- -

PKCS#12 is a bit different regarding pass phrase encoding. The standard stipulates that the pass phrase shall be encoded as an ASN.1 BMPString, which consists of the code points of the basic multilingual plane, encoded in big endian (UCS-2 BE).

- -

OpenSSL tries to adapt to this requirements in one of the following manners:

- -
    - -
  1. Treats the received pass phrase as UTF-8 encoded and tries to re-encode it to UTF-16 (which is the same as UCS-2 for characters U+0000 to U+D7FF and U+E000 to U+FFFF, but becomes an expansion for any other character), or failing that, proceeds with step 2.

    - -
  2. -
  3. Assumes that the pass phrase is encoded in ASCII or ISO-8859-1 and opportunistically prepends each byte with a zero byte to obtain the UCS-2 encoding of the characters, which it stores as a BMPString.

    - -

    Note that since there is no check of your locale, this may produce UCS-2 / UTF-16 characters that do not correspond to the original pass phrase characters for other character sets, such as any ISO-8859-X encoding other than ISO-8859-1 (or for Windows, CP 1252 with exception for the extra "graphical" characters in the 0x80-0x9F range).

    - -
  4. -
- -

OpenSSL versions older than 1.1.0 do variant 2 only, and that is the reason why OpenSSL still does this, to be able to read files produced with older versions.

- -

It should be noted that this approach isn't entirely fault free.

- -

A pass phrase encoded in ISO-8859-2 could very well have a sequence such as 0xC3 0xAF (which is the two characters "LATIN CAPITAL LETTER A WITH BREVE" and "LATIN CAPITAL LETTER Z WITH DOT ABOVE" in ISO-8859-2 encoding), but would be misinterpreted as the perfectly valid UTF-8 encoded code point U+00EF (LATIN SMALL LETTER I WITH DIAERESIS) if the pass phrase doesn't contain anything that would be invalid UTF-8. A pass phrase that contains this kind of byte sequence will give a different outcome in OpenSSL 1.1.0 and newer than in OpenSSL older than 1.1.0.

- -
0x00 0xC3 0x00 0xAF                    # OpenSSL older than 1.1.0
-0x00 0xEF                              # OpenSSL 1.1.0 and newer
- -

On the same accord, anything encoded in UTF-8 that was given to OpenSSL older than 1.1.0 was misinterpreted as ISO-8859-1 sequences.

- -

OSSL_STORE

- -

ossl_store(7) acts as a general interface to access all kinds of objects, potentially protected with a pass phrase, a PIN or something else. This API stipulates that pass phrases should be UTF-8 encoded, and that any other pass phrase encoding may give undefined results. This API relies on the application to ensure UTF-8 encoding, and doesn't check that this is the case, so what it gets, it will also pass to the underlying loader.

- -

RECOMMENDATIONS

- -

This section assumes that you know what pass phrase was used for encryption, but that it may have been encoded in a different character encoding than the one used by your current input method. For example, the pass phrase may have been used at a time when your default encoding was ISO-8859-1 (i.e. "naïve" resulting in the byte sequence 0x6E 0x61 0xEF 0x76 0x65), and you're now in an environment where your default encoding is UTF-8 (i.e. "naïve" resulting in the byte sequence 0x6E 0x61 0xC3 0xAF 0x76 0x65). Whenever it's mentioned that you should use a certain character encoding, it should be understood that you either change the input method to use the mentioned encoding when you type in your pass phrase, or use some suitable tool to convert your pass phrase from your default encoding to the target encoding.

- -

Also note that the sub-sections below discuss human readable pass phrases. This is particularly relevant for PKCS#12 objects, where human readable pass phrases are assumed. For other objects, it's as legitimate to use any byte sequence (such as a sequence of bytes from /dev/urandom that's been saved away), which makes any character encoding discussion irrelevant; in such cases, simply use the same byte sequence as it is.

- -

Creating new objects

- -

For creating new pass phrase protected objects, make sure the pass phrase is encoded using UTF-8. This is default on most modern Unixes, but may involve an effort on other platforms. Specifically for Windows, setting the environment variable OPENSSL_WIN32_UTF8 will have anything entered on [Windows] console prompt converted to UTF-8 (command line and separately prompted pass phrases alike).

- -

Opening existing objects

- -

For opening pass phrase protected objects where you know what character encoding was used for the encryption pass phrase, make sure to use the same encoding again.

- -

For opening pass phrase protected objects where the character encoding that was used is unknown, or where the producing application is unknown, try one of the following:

- -
    - -
  1. Try the pass phrase that you have as it is in the character encoding of your environment. It's possible that its byte sequence is exactly right.

    - -
  2. -
  3. Convert the pass phrase to UTF-8 and try with the result. Specifically with PKCS#12, this should open up any object that was created according to the specification.

    - -
  4. -
  5. Do a naïve (i.e. purely mathematical) ISO-8859-1 to UTF-8 conversion and try with the result. This differs from the previous attempt because ISO-8859-1 maps directly to U+0000 to U+00FF, which other non-UTF-8 character sets do not.

    - -

    This also takes care of the case when a UTF-8 encoded string was used with OpenSSL older than 1.1.0. (for example, ï, which is 0xC3 0xAF when encoded in UTF-8, would become 0xC3 0x83 0xC2 0xAF when re-encoded in the naïve manner. The conversion to BMPString would then yield 0x00 0xC3 0x00 0xA4 0x00 0x00, the erroneous/non-compliant encoding used by OpenSSL older than 1.1.0)

    - -
  6. -
- -

SEE ALSO

- -

evp(7), ossl_store(7), EVP_BytesToKey(3), EVP_DecryptInit(3), PEM_do_header(3), PKCS12_parse(3), PKCS12_newpass(3), d2i_PKCS8PrivateKey_bio(3)

- -

COPYRIGHT

- -

Copyright 2018-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/property.html b/openssl-install/share/doc/openssl/html/man7/property.html deleted file mode 100644 index f438d7ed..00000000 --- a/openssl-install/share/doc/openssl/html/man7/property.html +++ /dev/null @@ -1,134 +0,0 @@ - - - - -property - - - - - - - - - - -

NAME

- -

property - Properties, a selection mechanism for algorithm implementations

- -

DESCRIPTION

- -

As of OpenSSL 3.0, a new method has been introduced to decide which of multiple implementations of an algorithm will be used. The method is centered around the concept of properties. Each implementation defines a number of properties and when an algorithm is being selected, filters based on these properties can be used to choose the most appropriate implementation of the algorithm.

- -

Properties are like variables, they are referenced by name and have a value assigned.

- -

Property Names

- -

Property names fall into two categories: those reserved by the OpenSSL project and user defined names. A reserved property name consists of a single C-style identifier (except for leading underscores not being permitted), which begins with a letter and can be followed by any number of letters, numbers and underscores. Property names are case-insensitive, but OpenSSL will only use lowercase letters.

- -

A user defined property name is similar, but it must consist of two or more C-style identifiers, separated by periods. The last identifier in the name can be considered the 'true' property name, which is prefixed by some sort of 'namespace'. Providers for example could include their name in the prefix and use property names like

- -
<provider_name>.<property_name>
-<provider_name>.<algorithm_name>.<property_name>
- -

Properties

- -

A property is a name=value pair. A property definition is a sequence of comma separated properties. There can be any number of properties in a definition, however each name must be unique. For example: "" defines an empty property definition (i.e., no restriction); "my.foo=bar" defines a property named my.foo which has a string value bar and "iteration.count=3" defines a property named iteration.count which has a numeric value of 3. The full syntax for property definitions appears below.

- -

Implementations

- -

Each implementation of an algorithm can define any number of properties. For example, the default provider defines the property provider=default for all of its algorithms. Likewise, OpenSSL's FIPS provider defines provider=fips and the legacy provider defines provider=legacy for all of their algorithms.

- -

Queries

- -

A property query clause is a single conditional test. For example, "fips=yes", "provider!=default" or "?iteration.count=3". The first two represent mandatory clauses, such clauses must match for any algorithm to even be under consideration. The third clause represents an optional clause. Matching such clauses is not a requirement, but any additional optional match counts in favor of the algorithm. More details about that in the Lookups section. A property query is a sequence of comma separated property query clauses. It is an error if a property name appears in more than one query clause. The full syntax for property queries appears below, but the available syntactic features are:

- -
    - -
  • = is an infix operator providing an equality test.

    - -
  • -
  • != is an infix operator providing an inequality test.

    - -
  • -
  • ? is a prefix operator that means that the following clause is optional but preferred.

    - -
  • -
  • - is a prefix operator that means any global query clause involving the following property name should be ignored.

    - -
  • -
  • "..." is a quoted string. The quotes are not included in the body of the string.

    - -
  • -
  • '...' is a quoted string. The quotes are not included in the body of the string.

    - -
  • -
- -

Lookups

- -

When an algorithm is looked up, a property query is used to determine the best matching algorithm. All mandatory query clauses must be present and the implementation that additionally has the largest number of matching optional query clauses will be used. If there is more than one such optimal candidate, the result will be chosen from amongst those in an indeterminate way. Ordering of optional clauses is not significant.

- -

Shortcut

- -

In order to permit a more concise expression of boolean properties, there is one short cut: a property name alone (e.g. "my.property") is exactly equivalent to "my.property=yes" in both definitions and queries.

- -

Global and Local

- -

Two levels of property query are supported. A context based property query that applies to all fetch operations and a local property query. Where both the context and local queries include a clause with the same name, the local clause overrides the context clause.

- -

It is possible for a local property query to remove a clause in the context property query by preceding the property name with a '-'. For example, a context property query that contains "fips=yes" would normally result in implementations that have "fips=yes".

- -

However, if the setting of the "fips" property is irrelevant to the operations being performed, the local property query can include the clause "-fips". Note that the local property query could not use "fips=no" because that would disallow any implementations with "fips=yes" rather than not caring about the setting.

- -

SYNTAX

- -

The lexical syntax in EBNF is given by:

- -
Definition     ::= PropertyName ( '=' Value )?
-                       ( ',' PropertyName ( '=' Value )? )*
-Query          ::= PropertyQuery ( ',' PropertyQuery )*
-PropertyQuery  ::= '-' PropertyName
-                 | '?'? ( PropertyName (( '=' | '!=' ) Value)?)
-Value          ::= NumberLiteral | StringLiteral
-StringLiteral  ::= QuotedString | UnquotedString
-QuotedString   ::= '"' [^"]* '"' | "'" [^']* "'"
-UnquotedString ::= [A-Za-z] [^{space},]+
-NumberLiteral  ::= '0' ( [0-7]* | 'x' [0-9A-Fa-f]+ ) | '-'? [1-9] [0-9]+
-PropertyName   ::= [A-Za-z] [A-Za-z0-9_]* ( '.' [A-Za-z] [A-Za-z0-9_]* )*
- -

The flavour of EBNF being used is defined by: https://www.w3.org/TR/2010/REC-xquery-20101214/#EBNFNotation.

- -

HISTORY

- -

Properties were added in OpenSSL 3.0

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-asym_cipher.html b/openssl-install/share/doc/openssl/html/man7/provider-asym_cipher.html deleted file mode 100644 index 9f30be4e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-asym_cipher.html +++ /dev/null @@ -1,255 +0,0 @@ - - - - -provider-asym_cipher - - - - - - - - - - -

NAME

- -

provider-asym_cipher - The asym_cipher library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_asym_cipher_newctx(void *provctx);
-void OSSL_FUNC_asym_cipher_freectx(void *ctx);
-void *OSSL_FUNC_asym_cipher_dupctx(void *ctx);
-
-/* Encryption */
-int OSSL_FUNC_asym_cipher_encrypt_init(void *ctx, void *provkey,
-                                       const OSSL_PARAM params[]);
-int OSSL_FUNC_asym_cipher_encrypt(void *ctx, unsigned char *out, size_t *outlen,
-                                  size_t outsize, const unsigned char *in,
-                                  size_t inlen);
-
-/* Decryption */
-int OSSL_FUNC_asym_cipher_decrypt_init(void *ctx, void *provkey,
-                                       const OSSL_PARAM params[]);
-int OSSL_FUNC_asym_cipher_decrypt(void *ctx, unsigned char *out, size_t *outlen,
-                                  size_t outsize, const unsigned char *in,
-                                  size_t inlen);
-
-/* Asymmetric Cipher parameters */
-int OSSL_FUNC_asym_cipher_get_ctx_params(void *ctx, OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_asym_cipher_gettable_ctx_params(void *provctx);
-int OSSL_FUNC_asym_cipher_set_ctx_params(void *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_asym_cipher_settable_ctx_params(void *provctx);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The asymmetric cipher (OSSL_OP_ASYM_CIPHER) operation enables providers to implement asymmetric cipher algorithms and make them available to applications via the API functions EVP_PKEY_encrypt(3), EVP_PKEY_decrypt(3) and other related functions).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_asym_cipher_newctx() has these:

- -
typedef void *(OSSL_FUNC_asym_cipher_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_asym_cipher_newctx_fn
-    OSSL_FUNC_asym_cipher_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_asym_cipher_newctx               OSSL_FUNC_ASYM_CIPHER_NEWCTX
-OSSL_FUNC_asym_cipher_freectx              OSSL_FUNC_ASYM_CIPHER_FREECTX
-OSSL_FUNC_asym_cipher_dupctx               OSSL_FUNC_ASYM_CIPHER_DUPCTX
-
-OSSL_FUNC_asym_cipher_encrypt_init         OSSL_FUNC_ASYM_CIPHER_ENCRYPT_INIT
-OSSL_FUNC_asym_cipher_encrypt              OSSL_FUNC_ASYM_CIPHER_ENCRYPT
-
-OSSL_FUNC_asym_cipher_decrypt_init         OSSL_FUNC_ASYM_CIPHER_DECRYPT_INIT
-OSSL_FUNC_asym_cipher_decrypt              OSSL_FUNC_ASYM_CIPHER_DECRYPT
-
-OSSL_FUNC_asym_cipher_get_ctx_params       OSSL_FUNC_ASYM_CIPHER_GET_CTX_PARAMS
-OSSL_FUNC_asym_cipher_gettable_ctx_params  OSSL_FUNC_ASYM_CIPHER_GETTABLE_CTX_PARAMS
-OSSL_FUNC_asym_cipher_set_ctx_params       OSSL_FUNC_ASYM_CIPHER_SET_CTX_PARAMS
-OSSL_FUNC_asym_cipher_settable_ctx_params  OSSL_FUNC_ASYM_CIPHER_SETTABLE_CTX_PARAMS
- -

An asymmetric cipher algorithm implementation may not implement all of these functions. In order to be a consistent set of functions a provider must implement OSSL_FUNC_asym_cipher_newctx and OSSL_FUNC_asym_cipher_freectx. It must also implement both of OSSL_FUNC_asym_cipher_encrypt_init and OSSL_FUNC_asym_cipher_encrypt, or both of OSSL_FUNC_asym_cipher_decrypt_init and OSSL_FUNC_asym_cipher_decrypt. OSSL_FUNC_asym_cipher_get_ctx_params is optional but if it is present then so must OSSL_FUNC_asym_cipher_gettable_ctx_params. Similarly, OSSL_FUNC_asym_cipher_set_ctx_params is optional but if it is present then so must OSSL_FUNC_asym_cipher_settable_ctx_params.

- -

An asymmetric cipher algorithm must also implement some mechanism for generating, loading or importing keys via the key management (OSSL_OP_KEYMGMT) operation. See provider-keymgmt(7) for further details.

- -

Context Management Functions

- -

OSSL_FUNC_asym_cipher_newctx() should create and return a pointer to a provider side structure for holding context information during an asymmetric cipher operation. A pointer to this context will be passed back in a number of the other asymmetric cipher operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)).

- -

OSSL_FUNC_asym_cipher_freectx() is passed a pointer to the provider side asymmetric cipher context in the ctx parameter. This function should free any resources associated with that context.

- -

OSSL_FUNC_asym_cipher_dupctx() should duplicate the provider side asymmetric cipher context in the ctx parameter and return the duplicate copy.

- -

Encryption Functions

- -

OSSL_FUNC_asym_cipher_encrypt_init() initialises a context for an asymmetric encryption given a provider side asymmetric cipher context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_asym_cipher_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)). OSSL_FUNC_asym_cipher_encrypt() performs the actual encryption itself. A previously initialised asymmetric cipher context is passed in the ctx parameter. The data to be encrypted is pointed to by the in parameter which is inlen bytes long. Unless out is NULL, the encrypted data should be written to the location pointed to by the out parameter and it should not exceed outsize bytes in length. The length of the encrypted data should be written to *outlen. If out is NULL then the maximum length of the encrypted data should be written to *outlen.

- -

Decryption Functions

- -

OSSL_FUNC_asym_cipher_decrypt_init() initialises a context for an asymmetric decryption given a provider side asymmetric cipher context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_asym_cipher_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)).

- -

OSSL_FUNC_asym_cipher_decrypt() performs the actual decryption itself. A previously initialised asymmetric cipher context is passed in the ctx parameter. The data to be decrypted is pointed to by the in parameter which is inlen bytes long. Unless out is NULL, the decrypted data should be written to the location pointed to by the out parameter and it should not exceed outsize bytes in length. The length of the decrypted data should be written to *outlen. If out is NULL then the maximum length of the decrypted data should be written to *outlen.

- -

Asymmetric Cipher Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by the OSSL_FUNC_asym_cipher_get_ctx_params() and OSSL_FUNC_asym_cipher_set_ctx_params() functions.

- -

OSSL_FUNC_asym_cipher_get_ctx_params() gets asymmetric cipher parameters associated with the given provider side asymmetric cipher context ctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_asym_cipher_set_ctx_params() sets the asymmetric cipher parameters associated with the given provider side asymmetric cipher context ctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

Parameters currently recognised by built-in asymmetric cipher algorithms are as follows. Not all parameters are relevant to, or are understood by all asymmetric cipher algorithms:

- -
- -
"pad-mode" (OSSL_ASYM_CIPHER_PARAM_PAD_MODE) <UTF8 string> OR <integer>
-
- -

The type of padding to be used. The interpretation of this value will depend on the algorithm in use.

- -
-
"digest" (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST) <UTF8 string>
-
- -

Gets or sets the name of the OAEP digest algorithm used when OAEP padding is in use.

- -
-
"digest" (OSSL_ASYM_CIPHER_PARAM_DIGEST) <UTF8 string>
-
- -

Gets or sets the name of the digest algorithm used by the algorithm (where applicable).

- -
-
"digest-props" (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS) <UTF8 string>
-
- -

Gets or sets the properties to use when fetching the OAEP digest algorithm.

- -
-
"digest-props" (OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS) <UTF8 string>
-
- -

Gets or sets the properties to use when fetching the cipher digest algorithm.

- -
-
"mgf1-digest" (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST) <UTF8 string>
-
- -

Gets or sets the name of the MGF1 digest algorithm used when OAEP or PSS padding is in use.

- -
-
"mgf1-digest-props" (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS) <UTF8 string>
-
- -

Gets or sets the properties to use when fetching the MGF1 digest algorithm.

- -
-
"oaep-label" (OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL) <octet string ptr>
-
- -

Gets the OAEP label used when OAEP padding is in use.

- -
-
"oaep-label" (OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL) <octet string>
-
- -

Sets the OAEP label used when OAEP padding is in use.

- -
-
"tls-client-version" (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) <unsigned integer>
-
- -

The TLS protocol version first requested by the client.

- -
-
"tls-negotiated-version" (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) <unsigned integer>
-
- -

The negotiated TLS protocol version.

- -
-
"implicit-rejection" (OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION) <unsigned integer>
-
- -

Gets or sets the use of the implicit rejection mechanism for RSA PKCS#1 v1.5 decryption. When set (non zero value), the decryption API will return a deterministically random value if the PKCS#1 v1.5 padding check fails. This makes exploitation of the Bleichenbacher significantly harder, even if the code using the RSA decryption API is not implemented in side-channel free manner. Set by default in OpenSSL providers.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling either OSSL_FUNC_asym_cipher_encrypt() or OSSL_FUNC_asym_cipher_decrypt(). It may return 0 if "key-check" is set to 0.

- -
-
"key-check" (OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

If required this parameter should be set using either OSSL_FUNC_asym_cipher_encrypt_init() or OSSL_FUNC_asym_cipher_decrypt_init(). The default value of 1 causes an error during the init if the key is not FIPS approved (e.g. The key has a security strength of less than 112 bits). Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

OSSL_FUNC_asym_cipher_gettable_ctx_params() and OSSL_FUNC_asym_cipher_settable_ctx_params() get a constant OSSL_PARAM(3) array that describes the gettable and settable parameters, i.e. parameters that can be used with OSSL_FUNC_asym_cipherget_ctx_params() and OSSL_FUNC_asym_cipher_set_ctx_params() respectively.

- -

RETURN VALUES

- -

OSSL_FUNC_asym_cipher_newctx() and OSSL_FUNC_asym_cipher_dupctx() should return the newly created provider side asymmetric cipher context, or NULL on failure.

- -

All other functions should return 1 for success or 0 on error.

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The provider ASYM_CIPHER interface was introduced in OpenSSL 3.0. The Asymmetric Cipher Parameters "fips-indicator" and "key-check" were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-base.html b/openssl-install/share/doc/openssl/html/man7/provider-base.html deleted file mode 100644 index 683c15e7..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-base.html +++ /dev/null @@ -1,830 +0,0 @@ - - - - -provider-base - - - - - - - - - - -

NAME

- -

provider-base - The basic OpenSSL library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Functions offered by libcrypto to the providers */
-const OSSL_ITEM *core_gettable_params(const OSSL_CORE_HANDLE *handle);
-int core_get_params(const OSSL_CORE_HANDLE *handle, OSSL_PARAM params[]);
-
-typedef void (*OSSL_thread_stop_handler_fn)(void *arg);
-int core_thread_start(const OSSL_CORE_HANDLE *handle,
-                      OSSL_thread_stop_handler_fn handfn,
-                      void *arg);
-
-OPENSSL_CORE_CTX *core_get_libctx(const OSSL_CORE_HANDLE *handle);
-void core_new_error(const OSSL_CORE_HANDLE *handle);
-void core_set_error_debug(const OSSL_CORE_HANDLE *handle,
-                          const char *file, int line, const char *func);
-void core_vset_error(const OSSL_CORE_HANDLE *handle,
-                     uint32_t reason, const char *fmt, va_list args);
-
-int core_obj_add_sigid(const OSSL_CORE_HANDLE *prov, const char  *sign_name,
-                       const char *digest_name, const char *pkey_name);
-int core_obj_create(const OSSL_CORE_HANDLE *handle, const char *oid,
-                    const char *sn, const char *ln);
-
-/*
- * Some OpenSSL functionality is directly offered to providers via
- * dispatch
- */
-void *CRYPTO_malloc(size_t num, const char *file, int line);
-void *CRYPTO_zalloc(size_t num, const char *file, int line);
-void CRYPTO_free(void *ptr, const char *file, int line);
-void CRYPTO_clear_free(void *ptr, size_t num,
-                       const char *file, int line);
-void *CRYPTO_realloc(void *addr, size_t num,
-                     const char *file, int line);
-void *CRYPTO_clear_realloc(void *addr, size_t old_num, size_t num,
-                           const char *file, int line);
-void *CRYPTO_secure_malloc(size_t num, const char *file, int line);
-void *CRYPTO_secure_zalloc(size_t num, const char *file, int line);
-void CRYPTO_secure_free(void *ptr, const char *file, int line);
-void CRYPTO_secure_clear_free(void *ptr, size_t num,
-                              const char *file, int line);
-int CRYPTO_secure_allocated(const void *ptr);
-void OPENSSL_cleanse(void *ptr, size_t len);
-
-unsigned char *OPENSSL_hexstr2buf(const char *str, long *buflen);
-
-OSSL_CORE_BIO *BIO_new_file(const char *filename, const char *mode);
-OSSL_CORE_BIO *BIO_new_membuf(const void *buf, int len);
-int BIO_read_ex(OSSL_CORE_BIO *bio, void *data, size_t data_len,
-                size_t *bytes_read);
-int BIO_write_ex(OSSL_CORE_BIO *bio, const void *data, size_t data_len,
-                 size_t *written);
-int BIO_up_ref(OSSL_CORE_BIO *bio);
-int BIO_free(OSSL_CORE_BIO *bio);
-int BIO_vprintf(OSSL_CORE_BIO *bio, const char *format, va_list args);
-int BIO_vsnprintf(char *buf, size_t n, const char *fmt, va_list args);
-
-void OSSL_SELF_TEST_set_callback(OSSL_LIB_CTX *libctx, OSSL_CALLBACK *cb,
-                                 void *cbarg);
-
-size_t get_entropy(const OSSL_CORE_HANDLE *handle,
-                   unsigned char **pout, int entropy,
-                   size_t min_len, size_t max_len);
-size_t get_user_entropy(const OSSL_CORE_HANDLE *handle,
-                        unsigned char **pout, int entropy,
-                        size_t min_len, size_t max_len);
-void cleanup_entropy(const OSSL_CORE_HANDLE *handle,
-                     unsigned char *buf, size_t len);
-void cleanup_user_entropy(const OSSL_CORE_HANDLE *handle,
-                          unsigned char *buf, size_t len);
-size_t get_nonce(const OSSL_CORE_HANDLE *handle,
-                 unsigned char **pout, size_t min_len, size_t max_len,
-                 const void *salt, size_t salt_len);
-size_t get_user_nonce(const OSSL_CORE_HANDLE *handle,
-                      unsigned char **pout, size_t min_len, size_t max_len,
-                      const void *salt, size_t salt_len);
-void cleanup_nonce(const OSSL_CORE_HANDLE *handle,
-                   unsigned char *buf, size_t len);
-void cleanup_user_nonce(const OSSL_CORE_HANDLE *handle,
-                        unsigned char *buf, size_t len);
-
-/* Functions for querying the providers in the application library context */
-int provider_register_child_cb(const OSSL_CORE_HANDLE *handle,
-                    int (*create_cb)(const OSSL_CORE_HANDLE *provider,
-                                     void *cbdata),
-                    int (*remove_cb)(const OSSL_CORE_HANDLE *provider,
-                                     void *cbdata),
-                    int (*global_props_cb)(const char *props, void *cbdata),
-                    void *cbdata);
-void provider_deregister_child_cb(const OSSL_CORE_HANDLE *handle);
-const char *provider_name(const OSSL_CORE_HANDLE *prov);
-void *provider_get0_provider_ctx(const OSSL_CORE_HANDLE *prov);
-const OSSL_DISPATCH *provider_get0_dispatch(const OSSL_CORE_HANDLE *prov);
-int provider_up_ref(const OSSL_CORE_HANDLE *prov, int activate);
-int provider_free(const OSSL_CORE_HANDLE *prov, int deactivate);
-
-/* Functions offered by the provider to libcrypto */
-void provider_teardown(void *provctx);
-const OSSL_ITEM *provider_gettable_params(void *provctx);
-int provider_get_params(void *provctx, OSSL_PARAM params[]);
-const OSSL_ALGORITHM *provider_query_operation(void *provctx,
-                                               int operation_id,
-                                               const int *no_store);
-void provider_unquery_operation(void *provctx, int operation_id,
-                                const OSSL_ALGORITHM *algs);
-const OSSL_ITEM *provider_get_reason_strings(void *provctx);
-int provider_get_capabilities(void *provctx, const char *capability,
-                              OSSL_CALLBACK *cb, void *arg);
-int provider_self_test(void *provctx);
- -

DESCRIPTION

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays, in the call of the provider initialization function. See "Provider" in provider(7) for a description of the initialization function. They are known as "upcalls".

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from a OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" core_gettable_params() has these:

- -
typedef OSSL_PARAM *
-    (OSSL_FUNC_core_gettable_params_fn)(const OSSL_CORE_HANDLE *handle);
-static ossl_inline OSSL_NAME_core_gettable_params_fn
-    OSSL_FUNC_core_gettable_params(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -

For in (the OSSL_DISPATCH(3) array passed from libcrypto to the provider):

- -
core_gettable_params           OSSL_FUNC_CORE_GETTABLE_PARAMS
-core_get_params                OSSL_FUNC_CORE_GET_PARAMS
-core_thread_start              OSSL_FUNC_CORE_THREAD_START
-core_get_libctx                OSSL_FUNC_CORE_GET_LIBCTX
-core_new_error                 OSSL_FUNC_CORE_NEW_ERROR
-core_set_error_debug           OSSL_FUNC_CORE_SET_ERROR_DEBUG
-core_vset_error                OSSL_FUNC_CORE_VSET_ERROR
-core_obj_add_sigid             OSSL_FUNC_CORE_OBJ_ADD_SIGID
-core_obj_create                OSSL_FUNC_CORE_OBJ_CREATE
-CRYPTO_malloc                  OSSL_FUNC_CRYPTO_MALLOC
-CRYPTO_zalloc                  OSSL_FUNC_CRYPTO_ZALLOC
-CRYPTO_free                    OSSL_FUNC_CRYPTO_FREE
-CRYPTO_clear_free              OSSL_FUNC_CRYPTO_CLEAR_FREE
-CRYPTO_realloc                 OSSL_FUNC_CRYPTO_REALLOC
-CRYPTO_clear_realloc           OSSL_FUNC_CRYPTO_CLEAR_REALLOC
-CRYPTO_secure_malloc           OSSL_FUNC_CRYPTO_SECURE_MALLOC
-CRYPTO_secure_zalloc           OSSL_FUNC_CRYPTO_SECURE_ZALLOC
-CRYPTO_secure_free             OSSL_FUNC_CRYPTO_SECURE_FREE
-CRYPTO_secure_clear_free       OSSL_FUNC_CRYPTO_SECURE_CLEAR_FREE
-CRYPTO_secure_allocated        OSSL_FUNC_CRYPTO_SECURE_ALLOCATED
-BIO_new_file                   OSSL_FUNC_BIO_NEW_FILE
-BIO_new_mem_buf                OSSL_FUNC_BIO_NEW_MEMBUF
-BIO_read_ex                    OSSL_FUNC_BIO_READ_EX
-BIO_write_ex                   OSSL_FUNC_BIO_WRITE_EX
-BIO_up_ref                     OSSL_FUNC_BIO_UP_REF
-BIO_free                       OSSL_FUNC_BIO_FREE
-BIO_vprintf                    OSSL_FUNC_BIO_VPRINTF
-BIO_vsnprintf                  OSSL_FUNC_BIO_VSNPRINTF
-BIO_puts                       OSSL_FUNC_BIO_PUTS
-BIO_gets                       OSSL_FUNC_BIO_GETS
-BIO_ctrl                       OSSL_FUNC_BIO_CTRL
-OPENSSL_cleanse                OSSL_FUNC_OPENSSL_CLEANSE
-OSSL_SELF_TEST_set_callback    OSSL_FUNC_SELF_TEST_CB
-ossl_rand_get_entropy          OSSL_FUNC_GET_ENTROPY
-ossl_rand_get_user_entropy     OSSL_FUNC_GET_USER_ENTROPY
-ossl_rand_cleanup_entropy      OSSL_FUNC_CLEANUP_ENTROPY
-ossl_rand_cleanup_user_entropy OSSL_FUNC_CLEANUP_USER_ENTROPY
-ossl_rand_get_nonce            OSSL_FUNC_GET_NONCE
-ossl_rand_get_user_nonce       OSSL_FUNC_GET_USER_NONCE
-ossl_rand_cleanup_nonce        OSSL_FUNC_CLEANUP_NONCE
-ossl_rand_cleanup_user_nonce   OSSL_FUNC_CLEANUP_USER_NONCE
-provider_register_child_cb     OSSL_FUNC_PROVIDER_REGISTER_CHILD_CB
-provider_deregister_child_cb   OSSL_FUNC_PROVIDER_DEREGISTER_CHILD_CB
-provider_name                  OSSL_FUNC_PROVIDER_NAME
-provider_get0_provider_ctx     OSSL_FUNC_PROVIDER_GET0_PROVIDER_CTX
-provider_get0_dispatch         OSSL_FUNC_PROVIDER_GET0_DISPATCH
-provider_up_ref                OSSL_FUNC_PROVIDER_UP_REF
-provider_free                  OSSL_FUNC_PROVIDER_FREE
- -

For *out (the OSSL_DISPATCH(3) array passed from the provider to libcrypto):

- -
provider_teardown              OSSL_FUNC_PROVIDER_TEARDOWN
-provider_gettable_params       OSSL_FUNC_PROVIDER_GETTABLE_PARAMS
-provider_get_params            OSSL_FUNC_PROVIDER_GET_PARAMS
-provider_query_operation       OSSL_FUNC_PROVIDER_QUERY_OPERATION
-provider_unquery_operation     OSSL_FUNC_PROVIDER_UNQUERY_OPERATION
-provider_get_reason_strings    OSSL_FUNC_PROVIDER_GET_REASON_STRINGS
-provider_get_capabilities      OSSL_FUNC_PROVIDER_GET_CAPABILITIES
-provider_self_test             OSSL_FUNC_PROVIDER_SELF_TEST
- -

Core functions

- -

core_gettable_params() returns a constant array of descriptor OSSL_PARAM(3), for parameters that core_get_params() can handle.

- -

core_get_params() retrieves parameters from the core for the given handle. See "Core parameters" below for a description of currently known parameters.

- -

The core_thread_start() function informs the core that the provider has stated an interest in the current thread. The core will inform the provider when the thread eventually stops. It must be passed the handle for this provider, as well as a callback handfn which will be called when the thread stops. The callback will subsequently be called, with the supplied argument arg, from the thread that is stopping and gets passed the provider context as an argument. This may be useful to perform thread specific clean up such as freeing thread local variables.

- -

core_get_libctx() retrieves the core context in which the library object for the current provider is stored, accessible through the handle. This function is useful only for built-in providers such as the default provider. Never cast this to OSSL_LIB_CTX in a provider that is not built-in as the OSSL_LIB_CTX of the library loading the provider might be a completely different structure than the OSSL_LIB_CTX of the library the provider is linked to. Use OSSL_LIB_CTX_new_child(3) instead to obtain a proper library context that is linked to the application library context.

- -

core_new_error(), core_set_error_debug() and core_vset_error() are building blocks for reporting an error back to the core, with reference to the handle.

- -
- -
core_new_error()
-
- -

allocates a new thread specific error record.

- -

This corresponds to the OpenSSL function ERR_new(3).

- -
-
core_set_error_debug()
-
- -

sets debugging information in the current thread specific error record. The debugging information includes the name of the file file, the line line and the function name func where the error occurred.

- -

This corresponds to the OpenSSL function ERR_set_debug(3).

- -
-
core_vset_error()
-
- -

sets the reason for the error, along with any addition data. The reason is a number defined by the provider and used to index the reason strings table that's returned by provider_get_reason_strings(). The additional data is given as a format string fmt and a set of arguments args, which are treated in the same manner as with BIO_vsnprintf(). file and line may also be passed to indicate exactly where the error occurred or was reported.

- -

This corresponds to the OpenSSL function ERR_vset_error(3).

- -
-
- -

The core_obj_create() function registers a new OID and associated short name sn and long name ln for the given handle. It is similar to the OpenSSL function OBJ_create(3) except that it returns 1 on success or 0 on failure. It will treat as success the case where the OID already exists (even if the short name sn or long name ln provided as arguments differ from those associated with the existing OID, in which case the new names are not associated).

- -

The core_obj_add_sigid() function registers a new composite signature algorithm (sign_name) consisting of an underlying signature algorithm (pkey_name) and digest algorithm (digest_name) for the given handle. It assumes that the OIDs for the composite signature algorithm as well as for the underlying signature and digest algorithms are either already known to OpenSSL or have been registered via a call to core_obj_create(). It corresponds to the OpenSSL function OBJ_add_sigid(3), except that the objects are identified by name rather than a numeric NID. Any name (OID, short name or long name) can be used to identify the object. It will treat as success the case where the composite signature algorithm already exists (even if registered against a different underlying signature or digest algorithm). For digest_name, NULL or an empty string is permissible for signature algorithms that do not need a digest to operate correctly. The function returns 1 on success or 0 on failure.

- -

CRYPTO_malloc(), CRYPTO_zalloc(), CRYPTO_free(), CRYPTO_clear_free(), CRYPTO_realloc(), CRYPTO_clear_realloc(), CRYPTO_secure_malloc(), CRYPTO_secure_zalloc(), CRYPTO_secure_free(), CRYPTO_secure_clear_free(), CRYPTO_secure_allocated(), BIO_new_file(), BIO_new_mem_buf(), BIO_read_ex(), BIO_write_ex(), BIO_up_ref(), BIO_free(), BIO_vprintf(), BIO_vsnprintf(), BIO_gets(), BIO_puts(), BIO_ctrl(), OPENSSL_cleanse() and OPENSSL_hexstr2buf() correspond exactly to the public functions with the same name. As a matter of fact, the pointers in the OSSL_DISPATCH(3) array are typically direct pointers to those public functions. Note that the BIO functions take an OSSL_CORE_BIO type rather than the standard BIO type. This is to ensure that a provider does not mix BIOs from the core with BIOs used on the provider side (the two are not compatible). OSSL_SELF_TEST_set_callback() is used to set an optional callback that can be passed into a provider. This may be ignored by a provider.

- -

get_entropy() retrieves seeding material from the operating system. The seeding material will have at least entropy bytes of randomness and the output will have at least min_len and at most max_len bytes. The buffer address is stored in *pout and the buffer length is returned to the caller. On error, zero is returned.

- -

get_user_entropy() is the same as get_entropy() except that it will attempt to gather seed material via the seed source specified by a call to RAND_set_seed_source_type(3) or via "Random Configuration" in config(5).

- -

cleanup_entropy() is used to clean up and free the buffer returned by get_entropy(). The entropy pointer returned by get_entropy() is passed in buf and its length in len.

- -

cleanup_user_entropy() is used to clean up and free the buffer returned by get_user_entropy(). The entropy pointer returned by get_user_entropy() is passed in buf and its length in len.

- -

get_nonce() retrieves a nonce using the passed salt parameter of length salt_len and operating system specific information. The salt should contain uniquely identifying information and this is included, in an unspecified manner, as part of the output. The output is stored in a buffer which contains at least min_len and at most max_len bytes. The buffer address is stored in *pout and the buffer length returned to the caller. On error, zero is returned.

- -

get_user_nonce() is the same as get_nonce() except that it will attempt to gather seed material via the seed source specified by a call to RAND_set_seed_source_type(3) or via "Random Configuration" in config(5).

- -

cleanup_nonce() is used to clean up and free the buffer returned by get_nonce(). The nonce pointer returned by get_nonce() is passed in buf and its length in len.

- -

cleanup_user_nonce() is used to clean up and free the buffer returned by get_user_nonce(). The nonce pointer returned by get_user_nonce() is passed in buf and its length in len.

- -

provider_register_child_cb() registers callbacks for being informed about the loading and unloading of providers in the application's library context. handle is this provider's handle and cbdata is this provider's data that will be passed back to the callbacks. It returns 1 on success or 0 otherwise. These callbacks may be called while holding locks in libcrypto. In order to avoid deadlocks the callback implementation must not be long running and must not call other OpenSSL API functions or upcalls.

- -

create_cb is a callback that will be called when a new provider is loaded into the application's library context. It is also called for any providers that are already loaded at the point that this callback is registered. The callback is passed the handle being used for the new provider being loadded and this provider's data in cbdata. It should return 1 on success or 0 on failure.

- -

remove_cb is a callback that will be called when a new provider is unloaded from the application's library context. It is passed the handle being used for the provider being unloaded and this provider's data in cbdata. It should return 1 on success or 0 on failure.

- -

global_props_cb is a callback that will be called when the global properties from the parent library context are changed. It should return 1 on success or 0 on failure.

- -

provider_deregister_child_cb() unregisters callbacks previously registered via provider_register_child_cb(). If provider_register_child_cb() has been called then provider_deregister_child_cb() should be called at or before the point that this provider's teardown function is called.

- -

provider_name() returns a string giving the name of the provider identified by handle.

- -

provider_get0_provider_ctx() returns the provider context that is associated with the provider identified by prov.

- -

provider_get0_dispatch() gets the dispatch table registered by the provider identified by prov when it initialised.

- -

provider_up_ref() increments the reference count on the provider prov. If activate is nonzero then the provider is also loaded if it is not already loaded. It returns 1 on success or 0 on failure.

- -

provider_free() decrements the reference count on the provider prov. If deactivate is nonzero then the provider is also unloaded if it is not already loaded. It returns 1 on success or 0 on failure.

- -

Provider functions

- -

provider_teardown() is called when a provider is shut down and removed from the core's provider store. It must free the passed provctx.

- -

provider_gettable_params() should return a constant array of descriptor OSSL_PARAM(3), for parameters that provider_get_params() can handle.

- -

provider_get_params() should process the OSSL_PARAM(3) array params, setting the values of the parameters it understands.

- -

provider_query_operation() should return a constant OSSL_ALGORITHM(3) that corresponds to the given operation_id. It should indicate if the core may store a reference to this array by setting *no_store to 0 (core may store a reference) or 1 (core may not store a reference).

- -

provider_unquery_operation() informs the provider that the result of a provider_query_operation() is no longer directly required and that the function pointers have been copied. The operation_id should match that passed to provider_query_operation() and algs should be its return value.

- -

provider_get_reason_strings() should return a constant OSSL_ITEM(3) array that provides reason strings for reason codes the provider may use when reporting errors using core_put_error().

- -

The provider_get_capabilities() function should call the callback cb passing it a set of OSSL_PARAM(3)s and the caller supplied argument arg. The OSSL_PARAM(3)s should provide details about the capability with the name given in the capability argument relevant for the provider context provctx. If a provider supports multiple capabilities with the given name then it may call the callback multiple times (one for each capability). Capabilities can be useful for describing the services that a provider can offer. For further details see the "CAPABILITIES" section below. It should return 1 on success or 0 on error.

- -

The provider_self_test() function should perform known answer tests on a subset of the algorithms that it uses, and may also verify the integrity of the provider module. It should return 1 on success or 0 on error. It will return 1 if this function is not used.

- -

None of these functions are mandatory, but a provider is fairly useless without at least provider_query_operation(), and provider_gettable_params() is fairly useless if not accompanied by provider_get_params().

- -

Provider parameters

- -

provider_get_params() can return the following provider parameters to the core:

- -
- -
"name" (OSSL_PROV_PARAM_NAME) <UTF8 ptr>
-
- -

This points to a string that should give a unique name for the provider.

- -
-
"version" (OSSL_PROV_PARAM_VERSION) <UTF8 ptr>
-
- -

This points to a string that is a version number associated with this provider. OpenSSL in-built providers use OPENSSL_VERSION_STR, but this may be different for any third party provider. This string is for informational purposes only.

- -
-
"buildinfo" (OSSL_PROV_PARAM_BUILDINFO) <UTF8 ptr>
-
- -

This points to a string that is a build information associated with this provider. OpenSSL in-built providers use OPENSSL_FULL_VERSION_STR, but this may be different for any third party provider.

- -
-
"status" (OSSL_PROV_PARAM_STATUS) <unsigned integer>
-
- -

This returns 0 if the provider has entered an error state, otherwise it returns 1.

- -
-
- -

provider_gettable_params() should return the above parameters.

- -

Core parameters

- -

core_get_params() can retrieve the following core parameters for each provider:

- -
- -
"openssl-version" (OSSL_PROV_PARAM_CORE_VERSION) <UTF8 string ptr>
-
- -

This points to the OpenSSL libraries' full version string, i.e. the string expanded from the macro OPENSSL_VERSION_STR.

- -
-
"provider-name" (OSSL_PROV_PARAM_CORE_PROV_NAME) <UTF8 string ptr>
-
- -

This points to the OpenSSL libraries' idea of what the calling provider is named.

- -
-
"module-filename" (OSSL_PROV_PARAM_CORE_MODULE_FILENAME) <UTF8 string ptr>
-
- -

This points to a string containing the full filename of the providers module file.

- -
-
- -

Additionally, provider specific configuration parameters from the config file are available, in dotted name form. The dotted name form is a concatenation of section names and final config command name separated by periods.

- -

For example, let's say we have the following config example:

- -
config_diagnostics = 1
-openssl_conf = openssl_init
-
-[openssl_init]
-providers = providers_sect
-
-[providers_sect]
-foo = foo_sect
-
-[foo_sect]
-activate = 1
-data1 = 2
-data2 = str
-more = foo_more
-
-[foo_more]
-data3 = foo,bar
- -

The provider will have these additional parameters available:

- -
- -
"activate"
-
- -

pointing at the string "1"

- -
-
"data1"
-
- -

pointing at the string "2"

- -
-
"data2"
-
- -

pointing at the string "str"

- -
-
"more.data3"
-
- -

pointing at the string "foo,bar"

- -
-
- -

For more information on handling parameters, see OSSL_PARAM(3) as OSSL_PARAM_int(3).

- -

CAPABILITIES

- -

Capabilities describe some of the services that a provider can offer. Applications can query the capabilities to discover those services.

- -

"TLS-GROUP" Capability

- -

The "TLS-GROUP" capability can be queried by libssl to discover the list of TLS groups that a provider can support. Each group supported can be used for key exchange (KEX) or key encapsulation method (KEM) during a TLS handshake. TLS clients can advertise the list of TLS groups they support in the supported_groups extension, and TLS servers can select a group from the offered list that they also support. In this way a provider can add to the list of groups that libssl already supports with additional ones.

- -

Each TLS group that a provider supports should be described via the callback passed in through the provider_get_capabilities function. Each group should have the following details supplied (all are mandatory, except OSSL_CAPABILITY_TLS_GROUP_IS_KEM):

- -
- -
"tls-group-name" (OSSL_CAPABILITY_TLS_GROUP_NAME) <UTF8 string>
-
- -

The name of the group as given in the IANA TLS Supported Groups registry https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-parameters-8.

- -
-
"tls-group-name-internal" (OSSL_CAPABILITY_TLS_GROUP_NAME_INTERNAL) <UTF8 string>
-
- -

The name of the group as known by the provider. This could be the same as the "tls-group-name", but does not have to be.

- -
-
"tls-group-id" (OSSL_CAPABILITY_TLS_GROUP_ID) <unsigned integer>
-
- -

The TLS group id value as given in the IANA TLS Supported Groups registry.

- -

It is possible to register the same group id from within different providers. Users should note that if no property query is specified, or more than one implementation matches the property query then it is unspecified which implementation for a particular group id will be used.

- -
-
"tls-group-alg" (OSSL_CAPABILITY_TLS_GROUP_ALG) <UTF8 string>
-
- -

The name of a Key Management algorithm that the provider offers and that should be used with this group. Keys created should be able to support key exchange or key encapsulation method (KEM), as implied by the optional OSSL_CAPABILITY_TLS_GROUP_IS_KEM flag. The algorithm must support key and parameter generation as well as the key/parameter generation parameter, OSSL_PKEY_PARAM_GROUP_NAME. The group name given via "tls-group-name-internal" above will be passed via OSSL_PKEY_PARAM_GROUP_NAME when libssl wishes to generate keys/parameters.

- -
-
"tls-group-sec-bits" (OSSL_CAPABILITY_TLS_GROUP_SECURITY_BITS) <unsigned integer>
-
- -

The number of bits of security offered by keys in this group. The number of bits should be comparable with the ones given in table 2 and 3 of the NIST SP800-57 document.

- -
-
"tls-group-is-kem" (OSSL_CAPABILITY_TLS_GROUP_IS_KEM) <unsigned integer>
-
- -

Boolean flag to describe if the group should be used in key exchange (KEX) mode (0, default) or in key encapsulation method (KEM) mode (1).

- -

This parameter is optional: if not specified, KEX mode is assumed as the default mode for the group.

- -

In KEX mode, in a typical Diffie-Hellman fashion, both sides execute keygen then derive against the peer public key. To operate in KEX mode, the group implementation must support the provider functions as described in provider-keyexch(7).

- -

In KEM mode, the client executes keygen and sends its public key, the server executes encapsulate using the client's public key and sends back the resulting ciphertext, finally the client executes decapsulate to retrieve the same shared secret generated by the server's encapsulate. To operate in KEM mode, the group implementation must support the provider functions as described in provider-kem(7).

- -

Both in KEX and KEM mode, the resulting shared secret is then used according to the protocol specification.

- -
-
"tls-min-tls" (OSSL_CAPABILITY_TLS_GROUP_MIN_TLS) <integer>
-
- -
-
"tls-max-tls" (OSSL_CAPABILITY_TLS_GROUP_MAX_TLS) <integer>
-
- -
-
"tls-min-dtls" (OSSL_CAPABILITY_TLS_GROUP_MIN_DTLS) <integer>
-
- -
-
"tls-max-dtls" (OSSL_CAPABILITY_TLS_GROUP_MAX_DTLS) <integer>
-
- -

These parameters can be used to describe the minimum and maximum TLS and DTLS versions supported by the group. The values equate to the on-the-wire encoding of the various TLS versions. For example TLSv1.3 is 0x0304 (772 decimal), and TLSv1.2 is 0x0303 (771 decimal). A 0 indicates that there is no defined minimum or maximum. A -1 indicates that the group should not be used in that protocol.

- -
-
- -

"TLS-SIGALG" Capability

- -

The "TLS-SIGALG" capability can be queried by libssl to discover the list of TLS signature algorithms that a provider can support. Each signature supported can be used for client- or server-authentication in addition to the built-in signature algorithms. TLS1.3 clients can advertise the list of TLS signature algorithms they support in the signature_algorithms extension, and TLS servers can select an algorithm from the offered list that they also support. In this way a provider can add to the list of signature algorithms that libssl already supports with additional ones.

- -

Each TLS signature algorithm that a provider supports should be described via the callback passed in through the provider_get_capabilities function. Each algorithm can have the following details supplied:

- -
- -
"iana-name" (OSSL_CAPABILITY_TLS_SIGALG_IANA_NAME) <UTF8 string>
-
- -

The name of the signature algorithm as given in the IANA TLS Signature Scheme registry as "Description": https://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-signaturescheme. This value must be supplied.

- -
-
"iana-code-point" (OSSL_CAPABILITY_TLS_SIGALG_CODE_POINT) <unsigned integer>
-
- -

The TLS algorithm ID value as given in the IANA TLS SignatureScheme registry. This value must be supplied.

- -

It is possible to register the same code point from within different providers. Users should note that if no property query is specified, or more than one implementation matches the property query then it is unspecified which implementation for a particular code point will be used.

- -
-
"sigalg-name" (OSSL_CAPABILITY_TLS_SIGALG_NAME) <UTF8 string>
-
- -

A name for the full (possibly composite hash-and-signature) signature algorithm. The provider may, but is not obligated to, provide a signature implementation with this name; if it doesn't, this is assumed to be a composite of a pure signature algorithm and a hash algorithm, which must be given with the parameters "sig-name" and "hash-name". This value must be supplied.

- -
-
"sigalg-oid" (OSSL_CAPABILITY_TLS_SIGALG_OID) <UTF8 string>
-
- -

The OID of the "sigalg-name" algorithm in canonical numeric text form. If this parameter is given, OBJ_create() will be used to create an OBJ and a NID for this OID, using the "sigalg-name" parameter for its (short) name. Otherwise, it's assumed to already exist in the object database, possibly done by the provider with the core_obj_create() upcall. This value is optional.

- -
-
"sig-name" (OSSL_CAPABILITY_TLS_SIGALG_SIG_NAME) <UTF8 string>
-
- -

The name of the pure signature algorithm that is part of a composite "sigalg-name". If "sigalg-name" is implemented by the provider, this parameter is redundant and must not be given. This value is optional.

- -
-
"sig-oid" (OSSL_CAPABILITY_TLS_SIGALG_SIG_OID) <UTF8 string>
-
- -

The OID of the "sig-name" algorithm in canonical numeric text form. If this parameter is given, OBJ_create() will be used to create an OBJ and a NID for this OID, using the "sig-name" parameter for its (short) name. Otherwise, it is assumed to already exist in the object database. This can be done by the provider using the core_obj_create() upcall. This value is optional.

- -
-
"hash-name" (OSSL_CAPABILITY_TLS_SIGALG_HASH_NAME) <UTF8 string>
-
- -

The name of the hash algorithm that is part of a composite "sigalg-name". If "sigalg-name" is implemented by the provider, this parameter is redundant and must not be given. This value is optional.

- -
-
"hash-oid" (OSSL_CAPABILITY_TLS_SIGALG_HASH_OID) <UTF8 string>
-
- -

The OID of the "hash-name" algorithm in canonical numeric text form. If this parameter is given, OBJ_create() will be used to create an OBJ and a NID for this OID, using the "hash-name" parameter for its (short) name. Otherwise, it's assumed to already exist in the object database, possibly done by the provider with the core_obj_create() upcall. This value is optional.

- -
-
"key-type" (OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE) <UTF8 string>
-
- -

The key type of the public key of applicable certificates. If this parameter isn't present, it's assumed to be the same as "sig-name" if that's present, otherwise "sigalg-name". This value is optional.

- -
-
"key-type-oid" (OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE_OID) <UTF8 string>
-
- -

The OID of the "key-type" in canonical numeric text form. If this parameter is given, OBJ_create() will be used to create an OBJ and a NID for this OID, using the "key-type" parameter for its (short) name. Otherwise, it's assumed to already exist in the object database, possibly done by the provider with the core_obj_create() upcall. This value is optional.

- -
-
"sec-bits" (OSSL_CAPABILITY_TLS_SIGALG_SECURITY_BITS) <unsigned integer>
-
- -

The number of bits of security offered by keys of this algorithm. The number of bits should be comparable with the ones given in table 2 and 3 of the NIST SP800-57 document. This number is used to determine the security strength of the algorithm if no digest algorithm has been registered that otherwise defines the security strength. If the signature algorithm implements its own digest internally, this value needs to be set to properly reflect the overall security strength. This value must be supplied.

- -
-
"tls-min-tls" (OSSL_CAPABILITY_TLS_SIGALG_MIN_TLS) <integer>
-
- -
-
"tls-max-tls" (OSSL_CAPABILITY_TLS_SIGALG_MAX_TLS) <integer>
-
- -

These parameters can be used to describe the minimum and maximum TLS versions supported by the signature algorithm. The values equate to the on-the-wire encoding of the various TLS versions. For example TLSv1.3 is 0x0304 (772 decimal), and TLSv1.2 is 0x0303 (771 decimal). A 0 indicates that there is no defined minimum or maximum. A -1 indicates that the signature algorithm should not be used in that protocol. Presently values representing anything other than TLS1.3 mean that the complete algorithm is ignored.

- -
-
- -

NOTES

- -

The core_obj_create() and core_obj_add_sigid() functions were not thread safe in OpenSSL 3.0.

- -

EXAMPLES

- -

This is an example of a simple provider made available as a dynamically loadable module. It implements the fictitious algorithm FOO for the fictitious operation BAR.

- -
#include <malloc.h>
-#include <openssl/core.h>
-#include <openssl/core_dispatch.h>
-
-/* Errors used in this provider */
-#define E_MALLOC       1
-
-static const OSSL_ITEM reasons[] = {
-    { E_MALLOC, "memory allocation failure" }.
-    OSSL_DISPATCH_END
-};
-
-/*
- * To ensure we get the function signature right, forward declare
- * them using function types provided by openssl/core_dispatch.h
- */
-OSSL_FUNC_bar_newctx_fn foo_newctx;
-OSSL_FUNC_bar_freectx_fn foo_freectx;
-OSSL_FUNC_bar_init_fn foo_init;
-OSSL_FUNC_bar_update_fn foo_update;
-OSSL_FUNC_bar_final_fn foo_final;
-
-OSSL_FUNC_provider_query_operation_fn p_query;
-OSSL_FUNC_provider_get_reason_strings_fn p_reasons;
-OSSL_FUNC_provider_teardown_fn p_teardown;
-
-OSSL_provider_init_fn OSSL_provider_init;
-
-OSSL_FUNC_core_put_error *c_put_error = NULL;
-
-/* Provider context */
-struct prov_ctx_st {
-    OSSL_CORE_HANDLE *handle;
-}
-
-/* operation context for the algorithm FOO */
-struct foo_ctx_st {
-    struct prov_ctx_st *provctx;
-    int b;
-};
-
-static void *foo_newctx(void *provctx)
-{
-    struct foo_ctx_st *fooctx = malloc(sizeof(*fooctx));
-
-    if (fooctx != NULL)
-        fooctx->provctx = provctx;
-    else
-        c_put_error(provctx->handle, E_MALLOC, __FILE__, __LINE__);
-    return fooctx;
-}
-
-static void foo_freectx(void *fooctx)
-{
-    free(fooctx);
-}
-
-static int foo_init(void *vfooctx)
-{
-    struct foo_ctx_st *fooctx = vfooctx;
-
-    fooctx->b = 0x33;
-}
-
-static int foo_update(void *vfooctx, unsigned char *in, size_t inl)
-{
-    struct foo_ctx_st *fooctx = vfooctx;
-
-    /* did you expect something serious? */
-    if (inl == 0)
-        return 1;
-    for (; inl-- > 0; in++)
-        *in ^= fooctx->b;
-    return 1;
-}
-
-static int foo_final(void *vfooctx)
-{
-    struct foo_ctx_st *fooctx = vfooctx;
-
-    fooctx->b = 0x66;
-}
-
-static const OSSL_DISPATCH foo_fns[] = {
-    { OSSL_FUNC_BAR_NEWCTX, (void (*)(void))foo_newctx },
-    { OSSL_FUNC_BAR_FREECTX, (void (*)(void))foo_freectx },
-    { OSSL_FUNC_BAR_INIT, (void (*)(void))foo_init },
-    { OSSL_FUNC_BAR_UPDATE, (void (*)(void))foo_update },
-    { OSSL_FUNC_BAR_FINAL, (void (*)(void))foo_final },
-    OSSL_DISPATCH_END
-};
-
-static const OSSL_ALGORITHM bars[] = {
-    { "FOO", "provider=chumbawamba", foo_fns },
-    { NULL, NULL, NULL }
-};
-
-static const OSSL_ALGORITHM *p_query(void *provctx, int operation_id,
-                                     int *no_store)
-{
-    switch (operation_id) {
-    case OSSL_OP_BAR:
-        return bars;
-    }
-    return NULL;
-}
-
-static const OSSL_ITEM *p_reasons(void *provctx)
-{
-    return reasons;
-}
-
-static void p_teardown(void *provctx)
-{
-    free(provctx);
-}
-
-static const OSSL_DISPATCH prov_fns[] = {
-    { OSSL_FUNC_PROVIDER_TEARDOWN, (void (*)(void))p_teardown },
-    { OSSL_FUNC_PROVIDER_QUERY_OPERATION, (void (*)(void))p_query },
-    { OSSL_FUNC_PROVIDER_GET_REASON_STRINGS, (void (*)(void))p_reasons },
-    OSSL_DISPATCH_END
-};
-
-int OSSL_provider_init(const OSSL_CORE_HANDLE *handle,
-                       const OSSL_DISPATCH *in,
-                       const OSSL_DISPATCH **out,
-                       void **provctx)
-{
-    struct prov_ctx_st *pctx = NULL;
-
-    for (; in->function_id != 0; in++)
-        switch (in->function_id) {
-        case OSSL_FUNC_CORE_PUT_ERROR:
-            c_put_error = OSSL_FUNC_core_put_error(in);
-            break;
-        }
-
-    *out = prov_fns;
-
-    if ((pctx = malloc(sizeof(*pctx))) == NULL) {
-        /*
-         * ALEA IACTA EST, if the core retrieves the reason table
-         * regardless, that string will be displayed, otherwise not.
-         */
-        c_put_error(handle, E_MALLOC, __FILE__, __LINE__);
-        return 0;
-    }
-    pctx->handle = handle;
-    return 1;
-}
- -

This relies on a few things existing in openssl/core_dispatch.h:

- -
#define OSSL_OP_BAR            4711
-
-#define OSSL_FUNC_BAR_NEWCTX      1
-typedef void *(OSSL_FUNC_bar_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_bar_newctx(const OSSL_DISPATCH *opf)
-{ return (OSSL_FUNC_bar_newctx_fn *)opf->function; }
-
-#define OSSL_FUNC_BAR_FREECTX     2
-typedef void (OSSL_FUNC_bar_freectx_fn)(void *ctx);
-static ossl_inline OSSL_FUNC_bar_freectx(const OSSL_DISPATCH *opf)
-{ return (OSSL_FUNC_bar_freectx_fn *)opf->function; }
-
-#define OSSL_FUNC_BAR_INIT        3
-typedef void *(OSSL_FUNC_bar_init_fn)(void *ctx);
-static ossl_inline OSSL_FUNC_bar_init(const OSSL_DISPATCH *opf)
-{ return (OSSL_FUNC_bar_init_fn *)opf->function; }
-
-#define OSSL_FUNC_BAR_UPDATE      4
-typedef void *(OSSL_FUNC_bar_update_fn)(void *ctx,
-                                      unsigned char *in, size_t inl);
-static ossl_inline OSSL_FUNC_bar_update(const OSSL_DISPATCH *opf)
-{ return (OSSL_FUNC_bar_update_fn *)opf->function; }
-
-#define OSSL_FUNC_BAR_FINAL       5
-typedef void *(OSSL_FUNC_bar_final_fn)(void *ctx);
-static ossl_inline OSSL_FUNC_bar_final(const OSSL_DISPATCH *opf)
-{ return (OSSL_FUNC_bar_final_fn *)opf->function; }
- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The concept of providers and everything surrounding them was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-cipher.html b/openssl-install/share/doc/openssl/html/man7/provider-cipher.html deleted file mode 100644 index e8083042..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-cipher.html +++ /dev/null @@ -1,177 +0,0 @@ - - - - -provider-cipher - - - - - - - - - - -

NAME

- -

provider-cipher - The cipher library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_cipher_newctx(void *provctx);
-void OSSL_FUNC_cipher_freectx(void *cctx);
-void *OSSL_FUNC_cipher_dupctx(void *cctx);
-
-/* Encryption/decryption */
-int OSSL_FUNC_cipher_encrypt_init(void *cctx, const unsigned char *key,
-                                  size_t keylen, const unsigned char *iv,
-                                  size_t ivlen, const OSSL_PARAM params[]);
-int OSSL_FUNC_cipher_decrypt_init(void *cctx, const unsigned char *key,
-                                  size_t keylen, const unsigned char *iv,
-                                  size_t ivlen, const OSSL_PARAM params[]);
-int OSSL_FUNC_cipher_update(void *cctx, unsigned char *out, size_t *outl,
-                            size_t outsize, const unsigned char *in, size_t inl);
-int OSSL_FUNC_cipher_final(void *cctx, unsigned char *out, size_t *outl,
-                           size_t outsize);
-int OSSL_FUNC_cipher_cipher(void *cctx, unsigned char *out, size_t *outl,
-                            size_t outsize, const unsigned char *in, size_t inl);
-
-/* Cipher parameter descriptors */
-const OSSL_PARAM *OSSL_FUNC_cipher_gettable_params(void *provctx);
-
-/* Cipher operation parameter descriptors */
-const OSSL_PARAM *OSSL_FUNC_cipher_gettable_ctx_params(void *cctx,
-                                                       void *provctx);
-const OSSL_PARAM *OSSL_FUNC_cipher_settable_ctx_params(void *cctx,
-                                                       void *provctx);
-
-/* Cipher parameters */
-int OSSL_FUNC_cipher_get_params(OSSL_PARAM params[]);
-
-/* Cipher operation parameters */
-int OSSL_FUNC_cipher_get_ctx_params(void *cctx, OSSL_PARAM params[]);
-int OSSL_FUNC_cipher_set_ctx_params(void *cctx, const OSSL_PARAM params[]);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The CIPHER operation enables providers to implement cipher algorithms and make them available to applications via the API functions EVP_EncryptInit_ex(3), EVP_EncryptUpdate(3) and EVP_EncryptFinal(3) (as well as the decrypt equivalents and other related functions).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_cipher_newctx() has these:

- -
typedef void *(OSSL_FUNC_cipher_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_cipher_newctx_fn
-    OSSL_FUNC_cipher_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_cipher_newctx               OSSL_FUNC_CIPHER_NEWCTX
-OSSL_FUNC_cipher_freectx              OSSL_FUNC_CIPHER_FREECTX
-OSSL_FUNC_cipher_dupctx               OSSL_FUNC_CIPHER_DUPCTX
-
-OSSL_FUNC_cipher_encrypt_init         OSSL_FUNC_CIPHER_ENCRYPT_INIT
-OSSL_FUNC_cipher_decrypt_init         OSSL_FUNC_CIPHER_DECRYPT_INIT
-OSSL_FUNC_cipher_update               OSSL_FUNC_CIPHER_UPDATE
-OSSL_FUNC_cipher_final                OSSL_FUNC_CIPHER_FINAL
-OSSL_FUNC_cipher_cipher               OSSL_FUNC_CIPHER_CIPHER
-
-OSSL_FUNC_cipher_get_params           OSSL_FUNC_CIPHER_GET_PARAMS
-OSSL_FUNC_cipher_get_ctx_params       OSSL_FUNC_CIPHER_GET_CTX_PARAMS
-OSSL_FUNC_cipher_set_ctx_params       OSSL_FUNC_CIPHER_SET_CTX_PARAMS
-
-OSSL_FUNC_cipher_gettable_params      OSSL_FUNC_CIPHER_GETTABLE_PARAMS
-OSSL_FUNC_cipher_gettable_ctx_params  OSSL_FUNC_CIPHER_GETTABLE_CTX_PARAMS
-OSSL_FUNC_cipher_settable_ctx_params  OSSL_FUNC_CIPHER_SETTABLE_CTX_PARAMS
- -

A cipher algorithm implementation may not implement all of these functions. In order to be a consistent set of functions there must at least be a complete set of "encrypt" functions, or a complete set of "decrypt" functions, or a single "cipher" function. In all cases the OSSL_FUNC_cipher_get_params and both OSSL_FUNC_cipher_newctx and OSSL_FUNC_cipher_freectx functions must be present. All other functions are optional.

- -

Context Management Functions

- -

OSSL_FUNC_cipher_newctx() should create and return a pointer to a provider side structure for holding context information during a cipher operation. A pointer to this context will be passed back in a number of the other cipher operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)).

- -

OSSL_FUNC_cipher_freectx() is passed a pointer to the provider side cipher context in the cctx parameter. This function should free any resources associated with that context.

- -

OSSL_FUNC_cipher_dupctx() should duplicate the provider side cipher context in the cctx parameter and return the duplicate copy.

- -

Encryption/Decryption Functions

- -

OSSL_FUNC_cipher_encrypt_init() initialises a cipher operation for encryption given a newly created provider side cipher context in the cctx parameter. The key to be used is given in key which is keylen bytes long. The IV to be used is given in iv which is ivlen bytes long. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_cipher_set_ctx_params().

- -

OSSL_FUNC_cipher_decrypt_init() is the same as OSSL_FUNC_cipher_encrypt_init() except that it initialises the context for a decryption operation.

- -

OSSL_FUNC_cipher_update() is called to supply data to be encrypted/decrypted as part of a previously initialised cipher operation. The cctx parameter contains a pointer to a previously initialised provider side context. OSSL_FUNC_cipher_update() should encrypt/decrypt inl bytes of data at the location pointed to by in. The encrypted data should be stored in out and the amount of data written to *outl which should not exceed outsize bytes. OSSL_FUNC_cipher_update() may be called multiple times for a single cipher operation. It is the responsibility of the cipher implementation to handle input lengths that are not multiples of the block length. In such cases a cipher implementation will typically cache partial blocks of input data until a complete block is obtained. The pointers out and in may point to the same location, in which case the encryption must be done in-place. If out and in point to different locations, the requirements of EVP_EncryptUpdate(3) and EVP_DecryptUpdate(3) guarantee that the two buffers are disjoint. Similarly, the requirements of EVP_EncryptUpdate(3) and EVP_DecryptUpdate(3) ensure that the buffer pointed to by out contains sufficient room for the operation being performed.

- -

OSSL_FUNC_cipher_final() completes an encryption or decryption started through previous OSSL_FUNC_cipher_encrypt_init() or OSSL_FUNC_cipher_decrypt_init(), and OSSL_FUNC_cipher_update() calls. The cctx parameter contains a pointer to the provider side context. Any final encryption/decryption output should be written to out and the amount of data written to *outl which should not exceed outsize bytes. The same expectations apply to outsize as documented for EVP_EncryptFinal(3) and EVP_DecryptFinal(3).

- -

OSSL_FUNC_cipher_cipher() performs encryption/decryption using the provider side cipher context in the cctx parameter that should have been previously initialised via a call to OSSL_FUNC_cipher_encrypt_init() or OSSL_FUNC_cipher_decrypt_init(). This should call the raw underlying cipher function without any padding. This will be invoked in the provider as a result of the application calling EVP_Cipher(3). The application is responsible for ensuring that the input is a multiple of the block length. The data to be encrypted/decrypted will be in in, and it will be inl bytes in length. The output from the encryption/decryption should be stored in out and the amount of data stored should be put in *outl which should be no more than outsize bytes.

- -

Cipher Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by these functions.

- -

OSSL_FUNC_cipher_get_params() gets details of the algorithm implementation and stores them in params.

- -

OSSL_FUNC_cipher_set_ctx_params() sets cipher operation parameters for the provider side cipher context cctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

OSSL_FUNC_cipher_get_ctx_params() gets cipher operation details details from the given provider side cipher context cctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_cipher_gettable_params(), OSSL_FUNC_cipher_gettable_ctx_params(), and OSSL_FUNC_cipher_settable_ctx_params() all return constant OSSL_PARAM(3) arrays as descriptors of the parameters that OSSL_FUNC_cipher_get_params(), OSSL_FUNC_cipher_get_ctx_params(), and OSSL_FUNC_cipher_set_ctx_params() can handle, respectively. OSSL_FUNC_cipher_gettable_ctx_params() and OSSL_FUNC_cipher_settable_ctx_params() will return the parameters associated with the provider side context cctx in its current state if it is not NULL. Otherwise, they return the parameters associated with the provider side algorithm provctx.

- -

Parameters currently recognised by built-in ciphers are listed in "PARAMETERS" in EVP_EncryptInit(3). Not all parameters are relevant to, or are understood by all ciphers.

- -

RETURN VALUES

- -

OSSL_FUNC_cipher_newctx() and OSSL_FUNC_cipher_dupctx() should return the newly created provider side cipher context, or NULL on failure.

- -

OSSL_FUNC_cipher_encrypt_init(), OSSL_FUNC_cipher_decrypt_init(), OSSL_FUNC_cipher_update(), OSSL_FUNC_cipher_final(), OSSL_FUNC_cipher_cipher(), OSSL_FUNC_cipher_get_params(), OSSL_FUNC_cipher_get_ctx_params() and OSSL_FUNC_cipher_set_ctx_params() should return 1 for success or 0 on error.

- -

OSSL_FUNC_cipher_gettable_params(), OSSL_FUNC_cipher_gettable_ctx_params() and OSSL_FUNC_cipher_settable_ctx_params() should return a constant OSSL_PARAM(3) array, or NULL if none is offered.

- -

SEE ALSO

- -

provider(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-legacy(7), EVP_CIPHER-AES(7), EVP_CIPHER-ARIA(7), EVP_CIPHER-BLOWFISH(7), EVP_CIPHER-CAMELLIA(7), EVP_CIPHER-CAST(7), EVP_CIPHER-CHACHA(7), EVP_CIPHER-DES(7), EVP_CIPHER-IDEA(7), EVP_CIPHER-RC2(7), EVP_CIPHER-RC4(7), EVP_CIPHER-RC5(7), EVP_CIPHER-SEED(7), EVP_CIPHER-SM4(7), EVP_CIPHER-NULL(7), life_cycle-cipher(7), EVP_EncryptInit(3)

- -

HISTORY

- -

The provider CIPHER interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-decoder.html b/openssl-install/share/doc/openssl/html/man7/provider-decoder.html deleted file mode 100644 index c96eb194..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-decoder.html +++ /dev/null @@ -1,293 +0,0 @@ - - - - -provider-decoder - - - - - - - - - - -

NAME

- -

provider-decoder - The OSSL_DECODER library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Decoder parameter accessor and descriptor */
-const OSSL_PARAM *OSSL_FUNC_decoder_gettable_params(void *provctx);
-int OSSL_FUNC_decoder_get_params(OSSL_PARAM params[]);
-
-/* Functions to construct / destruct / manipulate the decoder context */
-void *OSSL_FUNC_decoder_newctx(void *provctx);
-void OSSL_FUNC_decoder_freectx(void *ctx);
-const OSSL_PARAM *OSSL_FUNC_decoder_settable_ctx_params(void *provctx);
-int OSSL_FUNC_decoder_set_ctx_params(void *ctx, const OSSL_PARAM params[]);
-
-/* Functions to check selection support */
-int OSSL_FUNC_decoder_does_selection(void *provctx, int selection);
-
-/* Functions to decode object data */
-int OSSL_FUNC_decoder_decode(void *ctx, OSSL_CORE_BIO *in,
-                             int selection,
-                             OSSL_CALLBACK *data_cb, void *data_cbarg,
-                             OSSL_PASSPHRASE_CALLBACK *cb, void *cbarg);
-
-/* Functions to export a decoded object */
-int OSSL_FUNC_decoder_export_object(void *ctx,
-                                      const void *objref, size_t objref_sz,
-                                      OSSL_CALLBACK *export_cb,
-                                      void *export_cbarg);
- -

DESCRIPTION

- -

The term "decode" is used throughout this manual. This includes but is not limited to deserialization as individual decoders can also do decoding into intermediate data formats.

- -

The DECODER operation is a generic method to create a provider-native object reference or intermediate decoded data from an encoded form read from the given OSSL_CORE_BIO. If the caller wants to decode data from memory, it should provide a BIO_s_mem(3) BIO. The decoded data or object reference is passed along with eventual metadata to the metadata_cb as OSSL_PARAM(3) parameters.

- -

The decoder doesn't need to know more about the OSSL_CORE_BIO pointer than being able to pass it to the appropriate BIO upcalls (see "Core functions" in provider-base(7)).

- -

The DECODER implementation may be part of a chain, where data is passed from one to the next. For example, there may be an implementation to decode an object from PEM to DER, and another one that decodes DER to a provider-native object.

- -

The last decoding step in the decoding chain is usually supposed to create a provider-native object referenced by an object reference. To import that object into a different provider the OSSL_FUNC_decoder_export_object() can be called as the final step of the decoding process.

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_decoder_decode() has these:

- -
typedef int
-    (OSSL_FUNC_decoder_decode_fn)(void *ctx, OSSL_CORE_BIO *in,
-                                  int selection,
-                                  OSSL_CALLBACK *data_cb, void *data_cbarg,
-                                  OSSL_PASSPHRASE_CALLBACK *cb, void *cbarg);
-static ossl_inline OSSL_FUNC_decoder_decode_fn*
-    OSSL_FUNC_decoder_decode(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_decoder_get_params          OSSL_FUNC_DECODER_GET_PARAMS
-OSSL_FUNC_decoder_gettable_params     OSSL_FUNC_DECODER_GETTABLE_PARAMS
-
-OSSL_FUNC_decoder_newctx              OSSL_FUNC_DECODER_NEWCTX
-OSSL_FUNC_decoder_freectx             OSSL_FUNC_DECODER_FREECTX
-OSSL_FUNC_decoder_set_ctx_params      OSSL_FUNC_DECODER_SET_CTX_PARAMS
-OSSL_FUNC_decoder_settable_ctx_params OSSL_FUNC_DECODER_SETTABLE_CTX_PARAMS
-
-OSSL_FUNC_decoder_does_selection      OSSL_FUNC_DECODER_DOES_SELECTION
-
-OSSL_FUNC_decoder_decode              OSSL_FUNC_DECODER_DECODE
-
-OSSL_FUNC_decoder_export_object       OSSL_FUNC_DECODER_EXPORT_OBJECT
- -

Names and properties

- -

The name of an implementation should match the target type of object it decodes. For example, an implementation that decodes an RSA key should be named "RSA". Likewise, an implementation that decodes DER data from PEM input should be named "DER".

- -

Properties, as defined in the OSSL_ALGORITHM(3) array element of each decoder implementation, can be used to further specify details about an implementation:

- -
- -
input
-
- -

This property is used to specify what format of input the implementation can decode.

- -

This property is mandatory.

- -

OpenSSL providers recognize the following input types:

- -
- -
pem
-
- -

An implementation with that input type decodes PEM formatted data.

- -
-
der
-
- -

An implementation with that input type decodes DER formatted data.

- -
-
msblob
-
- -

An implementation with that input type decodes MSBLOB formatted data.

- -
-
pvk
-
- -

An implementation with that input type decodes PVK formatted data.

- -
-
- -
-
structure
-
- -

This property is used to specify the structure that the decoded data is expected to have.

- -

This property is optional.

- -

Structures currently recognised by built-in decoders:

- -
- -
"type-specific"
-
- -

Type specific structure.

- -
-
"pkcs8"
-
- -

Structure according to the PKCS#8 specification.

- -
-
"SubjectPublicKeyInfo"
-
- -

Encoding of public keys according to the Subject Public Key Info of RFC 5280.

- -
-
- -
-
- -

The possible values of both these properties is open ended. A provider may very well specify input types and structures that libcrypto doesn't know anything about.

- -

Subset selections

- -

Sometimes, an object has more than one subset of data that is interesting to treat separately or together. It's possible to specify what subsets are to be decoded, with a set of bits selection that are passed in an int.

- -

This set of bits depend entirely on what kind of provider-side object is to be decoded. For example, those bits are assumed to be the same as those used with provider-keymgmt(7) (see "Key Objects" in provider-keymgmt(7)) when the object is an asymmetric keypair - e.g., OSSL_KEYMGMT_SELECT_PRIVATE_KEY if the object to be decoded is supposed to contain private key components.

- -

OSSL_FUNC_decoder_does_selection() should tell if a particular implementation supports any of the combinations given by selection.

- -

Context functions

- -

OSSL_FUNC_decoder_newctx() returns a context to be used with the rest of the functions.

- -

OSSL_FUNC_decoder_freectx() frees the given ctx as created by OSSL_FUNC_decoder_newctx().

- -

OSSL_FUNC_decoder_set_ctx_params() sets context data according to parameters from params that it recognises. Unrecognised parameters should be ignored. Passing NULL for params should return true.

- -

OSSL_FUNC_decoder_settable_ctx_params() returns a constant OSSL_PARAM(3) array describing the parameters that OSSL_FUNC_decoder_set_ctx_params() can handle.

- -

See OSSL_PARAM(3) for further details on the parameters structure used by OSSL_FUNC_decoder_set_ctx_params() and OSSL_FUNC_decoder_settable_ctx_params().

- -

Export function

- -

When a provider-native object is created by a decoder it would be unsuitable for direct use with a foreign provider. The export function allows for exporting the object into that foreign provider if the foreign provider supports the type of the object and provides an import function.

- -

OSSL_FUNC_decoder_export_object() should export the object of size objref_sz referenced by objref as an OSSL_PARAM(3) array and pass that into the export_cb as well as the given export_cbarg.

- -

Decoding functions

- -

OSSL_FUNC_decoder_decode() should decode the data as read from the OSSL_CORE_BIO in to produce decoded data or an object to be passed as reference in an OSSL_PARAM(3) array along with possible other metadata that was decoded from the input. This OSSL_PARAM(3) array is then passed to the data_cb callback. The selection bits, if relevant, should determine what the input data should contain. The decoding functions also take an OSSL_PASSPHRASE_CALLBACK(3) function pointer along with a pointer to application data cbarg, which should be used when a pass phrase prompt is needed.

- -

It's important to understand that the return value from this function is interpreted as follows:

- -
- -
True (1)
-
- -

This means "carry on the decoding process", and is meaningful even though this function couldn't decode the input into anything, because there may be another decoder implementation that can decode it into something.

- -

The data_cb callback should never be called when this function can't decode the input into anything.

- -
-
False (0)
-
- -

This means "stop the decoding process", and is meaningful when the input could be decoded into some sort of object that this function understands, but further treatment of that object results into errors that won't be possible for some other decoder implementation to get a different result.

- -
-
- -

The conditions to stop the decoding process are at the discretion of the implementation.

- -

Decoder operation parameters

- -

There are currently no operation parameters currently recognised by the built-in decoders.

- -

Parameters currently recognised by the built-in pass phrase callback:

- -
- -
"info" (OSSL_PASSPHRASE_PARAM_INFO) <UTF8 string>
-
- -

A string of information that will become part of the pass phrase prompt. This could be used to give the user information on what kind of object it's being prompted for.

- -
-
- -

RETURN VALUES

- -

OSSL_FUNC_decoder_newctx() returns a pointer to a context, or NULL on failure.

- -

OSSL_FUNC_decoder_set_ctx_params() returns 1, unless a recognised parameter was invalid or caused an error, for which 0 is returned.

- -

OSSL_FUNC_decoder_settable_ctx_params() returns a pointer to an array of constant OSSL_PARAM(3) elements.

- -

OSSL_FUNC_decoder_does_selection() returns 1 if the decoder implementation supports any of the selection bits, otherwise 0.

- -

OSSL_FUNC_decoder_decode() returns 1 to signal that the decoding process should continue, or 0 to signal that it should stop.

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The DECODER interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-digest.html b/openssl-install/share/doc/openssl/html/man7/provider-digest.html deleted file mode 100644 index 36a6010e..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-digest.html +++ /dev/null @@ -1,241 +0,0 @@ - - - - -provider-digest - - - - - - - - - - -

NAME

- -

provider-digest - The digest library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * Digests support the following function signatures in OSSL_DISPATCH arrays.
- * (The function signatures are not actual functions).
- */
-
-/* Context management */
-void *OSSL_FUNC_digest_newctx(void *provctx);
-void OSSL_FUNC_digest_freectx(void *dctx);
-void *OSSL_FUNC_digest_dupctx(void *dctx);
-
-/* Digest generation */
-int OSSL_FUNC_digest_init(void *dctx, const OSSL_PARAM params[]);
-int OSSL_FUNC_digest_update(void *dctx, const unsigned char *in, size_t inl);
-int OSSL_FUNC_digest_final(void *dctx, unsigned char *out, size_t *outl,
-                           size_t outsz);
-int OSSL_FUNC_digest_digest(void *provctx, const unsigned char *in, size_t inl,
-                            unsigned char *out, size_t *outl, size_t outsz);
-
-/* Digest parameter descriptors */
-const OSSL_PARAM *OSSL_FUNC_digest_gettable_params(void *provctx);
-
-/* Digest operation parameter descriptors */
-const OSSL_PARAM *OSSL_FUNC_digest_gettable_ctx_params(void *dctx,
-                                                       void *provctx);
-const OSSL_PARAM *OSSL_FUNC_digest_settable_ctx_params(void *dctx,
-                                                       void *provctx);
-
-/* Digest parameters */
-int OSSL_FUNC_digest_get_params(OSSL_PARAM params[]);
-
-/* Digest operation parameters */
-int OSSL_FUNC_digest_set_ctx_params(void *dctx, const OSSL_PARAM params[]);
-int OSSL_FUNC_digest_get_ctx_params(void *dctx, OSSL_PARAM params[]);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The DIGEST operation enables providers to implement digest algorithms and make them available to applications via the API functions EVP_DigestInit_ex(3), EVP_DigestUpdate(3) and EVP_DigestFinal(3) (and other related functions).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_digest_newctx() has these:

- -
typedef void *(OSSL_FUNC_digest_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_digest_newctx_fn
-    OSSL_FUNC_digest_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_digest_newctx               OSSL_FUNC_DIGEST_NEWCTX
-OSSL_FUNC_digest_freectx              OSSL_FUNC_DIGEST_FREECTX
-OSSL_FUNC_digest_dupctx               OSSL_FUNC_DIGEST_DUPCTX
-
-OSSL_FUNC_digest_init                 OSSL_FUNC_DIGEST_INIT
-OSSL_FUNC_digest_update               OSSL_FUNC_DIGEST_UPDATE
-OSSL_FUNC_digest_final                OSSL_FUNC_DIGEST_FINAL
-OSSL_FUNC_digest_digest               OSSL_FUNC_DIGEST_DIGEST
-
-OSSL_FUNC_digest_get_params           OSSL_FUNC_DIGEST_GET_PARAMS
-OSSL_FUNC_digest_get_ctx_params       OSSL_FUNC_DIGEST_GET_CTX_PARAMS
-OSSL_FUNC_digest_set_ctx_params       OSSL_FUNC_DIGEST_SET_CTX_PARAMS
-
-OSSL_FUNC_digest_gettable_params      OSSL_FUNC_DIGEST_GETTABLE_PARAMS
-OSSL_FUNC_digest_gettable_ctx_params  OSSL_FUNC_DIGEST_GETTABLE_CTX_PARAMS
-OSSL_FUNC_digest_settable_ctx_params  OSSL_FUNC_DIGEST_SETTABLE_CTX_PARAMS
- -

A digest algorithm implementation may not implement all of these functions. In order to be usable all or none of OSSL_FUNC_digest_newctx, OSSL_FUNC_digest_freectx, OSSL_FUNC_digest_init, OSSL_FUNC_digest_update and OSSL_FUNC_digest_final should be implemented. All other functions are optional.

- -

Context Management Functions

- -

OSSL_FUNC_digest_newctx() should create and return a pointer to a provider side structure for holding context information during a digest operation. A pointer to this context will be passed back in a number of the other digest operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)).

- -

OSSL_FUNC_digest_freectx() is passed a pointer to the provider side digest context in the dctx parameter. This function should free any resources associated with that context.

- -

OSSL_FUNC_digest_dupctx() should duplicate the provider side digest context in the dctx parameter and return the duplicate copy.

- -

Digest Generation Functions

- -

OSSL_FUNC_digest_init() initialises a digest operation given a newly created provider side digest context in the dctx parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_digest_set_ctx_params().

- -

OSSL_FUNC_digest_update() is called to supply data to be digested as part of a previously initialised digest operation. The dctx parameter contains a pointer to a previously initialised provider side context. OSSL_FUNC_digest_update() should digest inl bytes of data at the location pointed to by in. OSSL_FUNC_digest_update() may be called multiple times for a single digest operation.

- -

OSSL_FUNC_digest_final() generates a digest started through previous OSSL_FUNC_digest_init() and OSSL_FUNC_digest_update() calls. The dctx parameter contains a pointer to the provider side context. The digest should be written to *out and the length of the digest to *outl. The digest should not exceed outsz bytes.

- -

OSSL_FUNC_digest_digest() is a "oneshot" digest function. No provider side digest context is used. Instead the provider context that was created during provider initialisation is passed in the provctx parameter (see provider(7)). inl bytes at in should be digested and the result should be stored at out. The length of the digest should be stored in *outl which should not exceed outsz bytes.

- -

Digest Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by these functions.

- -

OSSL_FUNC_digest_get_params() gets details of the algorithm implementation and stores them in params.

- -

OSSL_FUNC_digest_set_ctx_params() sets digest operation parameters for the provider side digest context dctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

OSSL_FUNC_digest_get_ctx_params() gets digest operation details details from the given provider side digest context dctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_digest_gettable_params() returns a constant OSSL_PARAM(3) array containing descriptors of the parameters that OSSL_FUNC_digest_get_params() can handle.

- -

OSSL_FUNC_digest_gettable_ctx_params() and OSSL_FUNC_digest_settable_ctx_params() both return constant OSSL_PARAM(3) arrays as descriptors of the parameters that OSSL_FUNC_digest_get_ctx_params() and OSSL_FUNC_digest_set_ctx_params() can handle, respectively. The array is based on the current state of the provider side context if dctx is not NULL and on the provider side algorithm provctx otherwise.

- -

Parameters currently recognised by built-in digests with this function are as follows. Not all parameters are relevant to, or are understood by all digests:

- -
- -
"blocksize" (OSSL_DIGEST_PARAM_BLOCK_SIZE) <unsigned integer>
-
- -

The digest block size. The length of the "blocksize" parameter should not exceed that of a size_t.

- -
-
"size" (OSSL_DIGEST_PARAM_SIZE) <unsigned integer>
-
- -

The digest output size. The length of the "size" parameter should not exceed that of a size_t.

- -
-
"flags" (OSSL_DIGEST_PARAM_FLAGS) <unsigned integer>
-
- -

Diverse flags that describe exceptional behaviour for the digest:

- -
- -
EVP_MD_FLAG_ONESHOT
-
- -

This digest method can only handle one block of input.

- -
-
EVP_MD_FLAG_XOF
-
- -

This digest method is an extensible-output function (XOF).

- -
-
EVP_MD_FLAG_DIGALGID_NULL
-
- -

When setting up a DigestAlgorithmIdentifier, this flag will have the parameter set to NULL by default. Use this for PKCS#1. Note: if combined with EVP_MD_FLAG_DIGALGID_ABSENT, the latter will override.

- -
-
EVP_MD_FLAG_DIGALGID_ABSENT
-
- -

When setting up a DigestAlgorithmIdentifier, this flag will have the parameter be left absent by default. Note: if combined with EVP_MD_FLAG_DIGALGID_NULL, the latter will be overridden.

- -
-
EVP_MD_FLAG_DIGALGID_CUSTOM
-
- -

Custom DigestAlgorithmIdentifier handling via ctrl, with EVP_MD_FLAG_DIGALGID_ABSENT as default. Note: if combined with EVP_MD_FLAG_DIGALGID_NULL, the latter will be overridden. Currently unused.

- -
-
- -

The length of the "flags" parameter should equal that of an unsigned long int.

- -
-
- -

Digest Context Parameters

- -

OSSL_FUNC_digest_set_ctx_params() sets digest parameters associated with the given provider side digest context dctx to params. Any parameter settings are additional to any that were previously set. See OSSL_PARAM(3) for further details on the parameters structure.

- -

OSSL_FUNC_digest_get_ctx_params() gets details of currently set parameters values associated with the give provider side digest context dctx and stores them in params. See OSSL_PARAM(3) for further details on the parameters structure.

- -

RETURN VALUES

- -

OSSL_FUNC_digest_newctx() and OSSL_FUNC_digest_dupctx() should return the newly created provider side digest context, or NULL on failure.

- -

OSSL_FUNC_digest_init(), OSSL_FUNC_digest_update(), OSSL_FUNC_digest_final(), OSSL_FUNC_digest_digest(), OSSL_FUNC_digest_set_params() and OSSL_FUNC_digest_get_params() should return 1 for success or 0 on error.

- -

OSSL_FUNC_digest_size() should return the digest size.

- -

OSSL_FUNC_digest_block_size() should return the block size of the underlying digest algorithm.

- -

BUGS

- -

The EVP_Q_digest(), EVP_Digest() and EVP_DigestFinal_ex() API calls do not expect the digest size to be larger than EVP_MAX_MD_SIZE. Any algorithm which produces larger digests is unusable with those API calls.

- -

SEE ALSO

- -

provider(7), OSSL_PROVIDER-FIPS(7), OSSL_PROVIDER-default(7), OSSL_PROVIDER-legacy(7), EVP_MD-common(7), EVP_MD-BLAKE2(7), EVP_MD-MD2(7), EVP_MD-MD4(7), EVP_MD-MD5(7), EVP_MD-MD5-SHA1(7), EVP_MD-MDC2(7), EVP_MD-RIPEMD160(7), EVP_MD-SHA1(7), EVP_MD-SHA2(7), EVP_MD-SHA3(7), EVP_MD-KECCAK(7) EVP_MD-SHAKE(7), EVP_MD-SM3(7), EVP_MD-WHIRLPOOL(7), EVP_MD-NULL(7), life_cycle-digest(7), EVP_DigestInit(3)

- -

HISTORY

- -

The provider DIGEST interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-encoder.html b/openssl-install/share/doc/openssl/html/man7/provider-encoder.html deleted file mode 100644 index c7cb7cd4..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-encoder.html +++ /dev/null @@ -1,288 +0,0 @@ - - - - -provider-encoder - - - - - - - - - - -

NAME

- -

provider-encoder - The OSSL_ENCODER library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Encoder parameter accessor and descriptor */
-const OSSL_PARAM *OSSL_FUNC_encoder_gettable_params(void *provctx);
-int OSSL_FUNC_encoder_get_params(OSSL_PARAM params[]);
-
-/* Functions to construct / destruct / manipulate the encoder context */
-void *OSSL_FUNC_encoder_newctx(void *provctx);
-void OSSL_FUNC_encoder_freectx(void *ctx);
-int OSSL_FUNC_encoder_set_ctx_params(void *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_encoder_settable_ctx_params(void *provctx);
-
-/* Functions to check selection support */
-int OSSL_FUNC_encoder_does_selection(void *provctx, int selection);
-
-/* Functions to encode object data */
-int OSSL_FUNC_encoder_encode(void *ctx, OSSL_CORE_BIO *out,
-                             const void *obj_raw,
-                             const OSSL_PARAM obj_abstract[],
-                             int selection,
-                             OSSL_PASSPHRASE_CALLBACK *cb,
-                             void *cbarg);
-
-/* Functions to import and free a temporary object to be encoded */
-void *OSSL_FUNC_encoder_import_object(void *ctx, int selection,
-                                      const OSSL_PARAM params[]);
-void OSSL_FUNC_encoder_free_object(void *obj);
- -

DESCRIPTION

- -

We use the wide term "encode" in this manual. This includes but is not limited to serialization.

- -

The ENCODER operation is a generic method to encode a provider-native object (obj_raw) or an object abstraction (object_abstract, see provider-object(7)) into an encoded form, and write the result to the given OSSL_CORE_BIO. If the caller wants to get the encoded stream to memory, it should provide a BIO_s_mem(3) BIO.

- -

The encoder doesn't need to know more about the OSSL_CORE_BIO pointer than being able to pass it to the appropriate BIO upcalls (see "Core functions" in provider-base(7)).

- -

The ENCODER implementation may be part of a chain, where data is passed from one to the next. For example, there may be an implementation to encode an object to DER (that object is assumed to be provider-native and thereby passed via obj_raw), and another one that encodes DER to PEM (that one would receive the DER encoding via obj_abstract).

- -

The encoding using the OSSL_PARAM(3) array form allows a encoder to be used for data that's been exported from another provider, and thereby allow them to exist independently of each other.

- -

The encoding using a provider side object can only be safely used with provider data coming from the same provider, for example keys with the KEYMGMT provider.

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_encoder_encode() has these:

- -
typedef int
-    (OSSL_FUNC_encoder_encode_fn)(void *ctx, OSSL_CORE_BIO *out,
-                                  const void *obj_raw,
-                                  const OSSL_PARAM obj_abstract[],
-                                  int selection,
-                                  OSSL_PASSPHRASE_CALLBACK *cb, void *cbarg);
-static ossl_inline OSSL_FUNC_encoder_encode_fn
-    OSSL_FUNC_encoder_encode(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_encoder_get_params          OSSL_FUNC_ENCODER_GET_PARAMS
-OSSL_FUNC_encoder_gettable_params     OSSL_FUNC_ENCODER_GETTABLE_PARAMS
-
-OSSL_FUNC_encoder_newctx              OSSL_FUNC_ENCODER_NEWCTX
-OSSL_FUNC_encoder_freectx             OSSL_FUNC_ENCODER_FREECTX
-OSSL_FUNC_encoder_set_ctx_params      OSSL_FUNC_ENCODER_SET_CTX_PARAMS
-OSSL_FUNC_encoder_settable_ctx_params OSSL_FUNC_ENCODER_SETTABLE_CTX_PARAMS
-
-OSSL_FUNC_encoder_does_selection      OSSL_FUNC_ENCODER_DOES_SELECTION
-
-OSSL_FUNC_encoder_encode              OSSL_FUNC_ENCODER_ENCODE
-
-OSSL_FUNC_encoder_import_object       OSSL_FUNC_ENCODER_IMPORT_OBJECT
-OSSL_FUNC_encoder_free_object         OSSL_FUNC_ENCODER_FREE_OBJECT
- -

Names and properties

- -

The name of an implementation should match the type of object it handles. For example, an implementation that encodes an RSA key should be named "RSA". Likewise, an implementation that further encodes DER should be named "DER".

- -

Properties, as defined in the OSSL_ALGORITHM(3) array element of each decoder implementation, can be used to further specify details about an implementation:

- -
- -
output
-
- -

This property is used to specify what type of output the implementation produces.

- -

This property is mandatory.

- -

OpenSSL providers recognize the following output types:

- -
- -
text
-
- -

An implementation with that output type outputs human readable text, making that implementation suitable for -text output in diverse openssl(1) commands.

- -
-
pem
-
- -

An implementation with that output type outputs PEM formatted data.

- -
-
der
-
- -

An implementation with that output type outputs DER formatted data.

- -
-
msblob
-
- -

An implementation with that output type outputs MSBLOB formatted data.

- -
-
pvk
-
- -

An implementation with that output type outputs PVK formatted data.

- -
-
- -
-
structure
-
- -

This property is used to specify the structure that is used for the encoded object. An example could be pkcs8, to specify explicitly that an object (presumably an asymmetric key pair, in this case) will be wrapped in a PKCS#8 structure as part of the encoding.

- -

This property is optional.

- -
-
- -

The possible values of both these properties is open ended. A provider may very well specify output types and structures that libcrypto doesn't know anything about.

- -

Subset selections

- -

Sometimes, an object has more than one subset of data that is interesting to treat separately or together. It's possible to specify what subsets are to be encoded, with a set of bits selection that are passed in an int.

- -

This set of bits depend entirely on what kind of provider-side object is passed. For example, those bits are assumed to be the same as those used with provider-keymgmt(7) (see "Key Objects" in provider-keymgmt(7)) when the object is an asymmetric keypair.

- -

ENCODER implementations are free to regard the selection as a set of hints, but must do so with care. In the end, the output must make sense, and if there's a corresponding decoder, the resulting decoded object must match the original object that was encoded.

- -

OSSL_FUNC_encoder_does_selection() should tell if a particular implementation supports any of the combinations given by selection.

- -

Context functions

- -

OSSL_FUNC_encoder_newctx() returns a context to be used with the rest of the functions.

- -

OSSL_FUNC_encoder_freectx() frees the given ctx, if it was created by OSSL_FUNC_encoder_newctx().

- -

OSSL_FUNC_encoder_set_ctx_params() sets context data according to parameters from params that it recognises. Unrecognised parameters should be ignored. Passing NULL for params should return true.

- -

OSSL_FUNC_encoder_settable_ctx_params() returns a constant OSSL_PARAM(3) array describing the parameters that OSSL_FUNC_encoder_set_ctx_params() can handle.

- -

See OSSL_PARAM(3) for further details on the parameters structure used by OSSL_FUNC_encoder_set_ctx_params() and OSSL_FUNC_encoder_settable_ctx_params().

- -

Import functions

- -

A provider-native object may be associated with a foreign provider, and may therefore be unsuitable for direct use with a given ENCODER implementation. Provided that the foreign provider's implementation to handle the object has a function to export that object in OSSL_PARAM(3) array form, the ENCODER implementation should be able to import that array and create a suitable object to be passed to OSSL_FUNC_encoder_encode()'s obj_raw.

- -

OSSL_FUNC_encoder_import_object() should import the subset of params given with selection to create a provider-native object that can be passed as obj_raw to OSSL_FUNC_encoder_encode().

- -

OSSL_FUNC_encoder_free_object() should free the object that was created with OSSL_FUNC_encoder_import_object().

- -

Encoding functions

- -

OSSL_FUNC_encoder_encode() should take a provider-native object (in obj_raw) or an object abstraction (in obj_abstract), and should output the object in encoded form to the OSSL_CORE_BIO. The selection bits, if relevant, should determine in greater detail what will be output. The encoding functions also take an OSSL_PASSPHRASE_CALLBACK(3) function pointer along with a pointer to application data cbarg, which should be used when a pass phrase prompt is needed.

- -

Encoder operation parameters

- -

Operation parameters currently recognised by built-in encoders are as follows:

- -
- -
"cipher" (OSSL_ENCODER_PARAM_CIPHER) <UTF8 string>
-
- -

The name of the encryption cipher to be used when generating encrypted encoding. This is used when encoding private keys, as well as other objects that need protection.

- -

If this name is invalid for the encoding implementation, the implementation should refuse to perform the encoding, i.e. OSSL_FUNC_encoder_encode_data() and OSSL_FUNC_encoder_encode_object() should return an error.

- -
-
"properties" (OSSL_ENCODER_PARAM_PROPERTIES) <UTF8 string>
-
- -

The properties to be queried when trying to fetch the algorithm given with the "cipher" parameter. This must be given together with the "cipher" parameter to be considered valid.

- -

The encoding implementation isn't obligated to use this value. However, it is recommended that implementations that do not handle property strings return an error on receiving this parameter unless its value NULL or the empty string.

- -
-
"save-parameters" (OSSL_ENCODER_PARAM_SAVE_PARAMETERS) <integer>
-
- -

If set to 0 disables saving of key domain parameters. Default is 1. It currently has an effect only on DSA keys.

- -
-
- -

Parameters currently recognised by the built-in pass phrase callback:

- -
- -
"info" (OSSL_PASSPHRASE_PARAM_INFO) <UTF8 string>
-
- -

A string of information that will become part of the pass phrase prompt. This could be used to give the user information on what kind of object it's being prompted for.

- -
-
- -

RETURN VALUES

- -

OSSL_FUNC_encoder_newctx() returns a pointer to a context, or NULL on failure.

- -

OSSL_FUNC_encoder_set_ctx_params() returns 1, unless a recognised parameter was invalid or caused an error, for which 0 is returned.

- -

OSSL_FUNC_encoder_settable_ctx_params() returns a pointer to an array of constant OSSL_PARAM(3) elements.

- -

OSSL_FUNC_encoder_does_selection() returns 1 if the encoder implementation supports any of the selection bits, otherwise 0.

- -

OSSL_FUNC_encoder_encode() returns 1 on success, or 0 on failure.

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The ENCODER interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-kdf.html b/openssl-install/share/doc/openssl/html/man7/provider-kdf.html deleted file mode 100644 index 3d29faeb..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-kdf.html +++ /dev/null @@ -1,384 +0,0 @@ - - - - -provider-kdf - - - - - - - - - - -

NAME

- -

provider-kdf - The KDF library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_kdf_newctx(void *provctx);
-void OSSL_FUNC_kdf_freectx(void *kctx);
-void *OSSL_FUNC_kdf_dupctx(void *src);
-
-/* Encryption/decryption */
-int OSSL_FUNC_kdf_reset(void *kctx);
-int OSSL_FUNC_kdf_derive(void *kctx, unsigned char *key, size_t keylen,
-                         const OSSL_PARAM params[]);
-
-/* KDF parameter descriptors */
-const OSSL_PARAM *OSSL_FUNC_kdf_gettable_params(void *provctx);
-const OSSL_PARAM *OSSL_FUNC_kdf_gettable_ctx_params(void *kcxt, void *provctx);
-const OSSL_PARAM *OSSL_FUNC_kdf_settable_ctx_params(void *kcxt, void *provctx);
-
-/* KDF parameters */
-int OSSL_FUNC_kdf_get_params(OSSL_PARAM params[]);
-int OSSL_FUNC_kdf_get_ctx_params(void *kctx, OSSL_PARAM params[]);
-int OSSL_FUNC_kdf_set_ctx_params(void *kctx, const OSSL_PARAM params[]);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The KDF operation enables providers to implement KDF algorithms and make them available to applications via the API functions EVP_KDF_CTX_reset(3), and EVP_KDF_derive(3).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_kdf_newctx() has these:

- -
typedef void *(OSSL_FUNC_kdf_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_kdf_newctx_fn
-    OSSL_FUNC_kdf_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) array entries are identified by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_kdf_newctx               OSSL_FUNC_KDF_NEWCTX
-OSSL_FUNC_kdf_freectx              OSSL_FUNC_KDF_FREECTX
-OSSL_FUNC_kdf_dupctx               OSSL_FUNC_KDF_DUPCTX
-
-OSSL_FUNC_kdf_reset                OSSL_FUNC_KDF_RESET
-OSSL_FUNC_kdf_derive               OSSL_FUNC_KDF_DERIVE
-
-OSSL_FUNC_kdf_get_params           OSSL_FUNC_KDF_GET_PARAMS
-OSSL_FUNC_kdf_get_ctx_params       OSSL_FUNC_KDF_GET_CTX_PARAMS
-OSSL_FUNC_kdf_set_ctx_params       OSSL_FUNC_KDF_SET_CTX_PARAMS
-
-OSSL_FUNC_kdf_gettable_params      OSSL_FUNC_KDF_GETTABLE_PARAMS
-OSSL_FUNC_kdf_gettable_ctx_params  OSSL_FUNC_KDF_GETTABLE_CTX_PARAMS
-OSSL_FUNC_kdf_settable_ctx_params  OSSL_FUNC_KDF_SETTABLE_CTX_PARAMS
- -

A KDF algorithm implementation may not implement all of these functions. In order to be a consistent set of functions, at least the following functions must be implemented: OSSL_FUNC_kdf_newctx(), OSSL_FUNC_kdf_freectx(), OSSL_FUNC_kdf_set_ctx_params(), OSSL_FUNC_kdf_derive(). All other functions are optional.

- -

Context Management Functions

- -

OSSL_FUNC_kdf_newctx() should create and return a pointer to a provider side structure for holding context information during a KDF operation. A pointer to this context will be passed back in a number of the other KDF operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)).

- -

OSSL_FUNC_kdf_freectx() is passed a pointer to the provider side KDF context in the kctx parameter. If it receives NULL as kctx value, it should not do anything other than return. This function should free any resources associated with that context.

- -

OSSL_FUNC_kdf_dupctx() should duplicate the provider side KDF context in the kctx parameter and return the duplicate copy.

- -

Encryption/Decryption Functions

- -

OSSL_FUNC_kdf_reset() initialises a KDF operation given a provider side KDF context in the kctx parameter.

- -

OSSL_FUNC_kdf_derive() performs the KDF operation after processing the params as per OSSL_FUNC_kdf_set_ctx_params(). The kctx parameter contains a pointer to the provider side context. The resulting key of the desired keylen should be written to key. If the algorithm does not support the requested keylen the function must return error.

- -

KDF Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by these functions.

- -

OSSL_FUNC_kdf_get_params() gets details of parameter values associated with the provider algorithm and stores them in params.

- -

OSSL_FUNC_kdf_set_ctx_params() sets KDF parameters associated with the given provider side KDF context kctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

OSSL_FUNC_kdf_get_ctx_params() retrieves gettable parameter values associated with the given provider side KDF context kctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_kdf_gettable_params(), OSSL_FUNC_kdf_gettable_ctx_params(), and OSSL_FUNC_kdf_settable_ctx_params() all return constant OSSL_PARAM(3) arrays as descriptors of the parameters that OSSL_FUNC_kdf_get_params(), OSSL_FUNC_kdf_get_ctx_params(), and OSSL_FUNC_kdf_set_ctx_params() can handle, respectively. OSSL_FUNC_kdf_gettable_ctx_params() and OSSL_FUNC_kdf_settable_ctx_params() will return the parameters associated with the provider side context kctx in its current state if it is not NULL. Otherwise, they return the parameters associated with the provider side algorithm provctx.

- -

Parameters currently recognised by built-in KDFs are as follows. Not all parameters are relevant to, or are understood by all KDFs:

- -
- -
"size" (OSSL_KDF_PARAM_SIZE) <unsigned integer>
-
- -

Gets the output size from the associated KDF ctx. If the algorithm produces a variable amount of output, SIZE_MAX should be returned. If the input parameters required to calculate the fixed output size have not yet been supplied, 0 should be returned indicating an error.

- -
-
"key" (OSSL_KDF_PARAM_KEY) <octet string>
-
- -

Sets the key in the associated KDF ctx.

- -
-
"secret" (OSSL_KDF_PARAM_SECRET) <octet string>
-
- -

Sets the secret in the associated KDF ctx.

- -
-
"pass" (OSSL_KDF_PARAM_PASSWORD) <octet string>
-
- -

Sets the password in the associated KDF ctx.

- -
-
"cipher" (OSSL_KDF_PARAM_CIPHER) <UTF8 string>
-
- -
-
"digest" (OSSL_KDF_PARAM_DIGEST) <UTF8 string>
-
- -
-
"mac" (OSSL_KDF_PARAM_MAC) <UTF8 string>
-
- -

Sets the name of the underlying cipher, digest or MAC to be used. It must name a suitable algorithm for the KDF that's being used.

- -
-
"maclen" (OSSL_KDF_PARAM_MAC_SIZE) <octet string>
-
- -

Sets the length of the MAC in the associated KDF ctx.

- -
-
"properties" (OSSL_KDF_PARAM_PROPERTIES) <UTF8 string>
-
- -

Sets the properties to be queried when trying to fetch the underlying algorithm. This must be given together with the algorithm naming parameter to be considered valid.

- -
-
"iter" (OSSL_KDF_PARAM_ITER) <unsigned integer>
-
- -

Sets the number of iterations in the associated KDF ctx.

- -
-
"mode" (OSSL_KDF_PARAM_MODE) <UTF8 string>
-
- -

Sets the mode in the associated KDF ctx.

- -
-
"pkcs5" (OSSL_KDF_PARAM_PKCS5) <integer>
-
- -

Enables or disables the SP800-132 compliance checks. A mode of 0 enables the compliance checks.

- -

The checks performed are:

- -
- -
- the iteration count is at least 1000.
-
- -
-
- the salt length is at least 128 bits.
-
- -
-
- the derived key length is at least 112 bits.
-
- -
-
- -
-
"ukm" (OSSL_KDF_PARAM_UKM) <octet string>
-
- -

Sets an optional random string that is provided by the sender called "partyAInfo". In CMS this is the user keying material.

- -
-
"cekalg" (OSSL_KDF_PARAM_CEK_ALG) <UTF8 string>
-
- -

Sets the CEK wrapping algorithm name in the associated KDF ctx.

- -
-
"n" (OSSL_KDF_PARAM_SCRYPT_N) <unsigned integer>
-
- -

Sets the scrypt work factor parameter N in the associated KDF ctx.

- -
-
"r" (OSSL_KDF_PARAM_SCRYPT_R) <unsigned integer>
-
- -

Sets the scrypt work factor parameter r in the associated KDF ctx.

- -
-
"p" (OSSL_KDF_PARAM_SCRYPT_P) <unsigned integer>
-
- -

Sets the scrypt work factor parameter p in the associated KDF ctx.

- -
-
"maxmem_bytes" (OSSL_KDF_PARAM_SCRYPT_MAXMEM) <unsigned integer>
-
- -

Sets the scrypt work factor parameter maxmem in the associated KDF ctx.

- -
-
"prefix" (OSSL_KDF_PARAM_PREFIX) <octet string>
-
- -

Sets the prefix string using by the TLS 1.3 version of HKDF in the associated KDF ctx.

- -
-
"label" (OSSL_KDF_PARAM_LABEL) <octet string>
-
- -

Sets the label string using by the TLS 1.3 version of HKDF in the associated KDF ctx.

- -
-
"data" (OSSL_KDF_PARAM_DATA) <octet string>
-
- -

Sets the context string using by the TLS 1.3 version of HKDF in the associated KDF ctx.

- -
-
"info" (OSSL_KDF_PARAM_INFO) <octet string>
-
- -

Sets the optional shared info in the associated KDF ctx.

- -
-
"seed" (OSSL_KDF_PARAM_SEED) <octet string>
-
- -

Sets the IV in the associated KDF ctx.

- -
-
"xcghash" (OSSL_KDF_PARAM_SSHKDF_XCGHASH) <octet string>
-
- -

Sets the xcghash in the associated KDF ctx.

- -
-
"session_id" (OSSL_KDF_PARAM_SSHKDF_SESSION_ID) <octet string>
-
- -

Sets the session ID in the associated KDF ctx.

- -
-
"type" (OSSL_KDF_PARAM_SSHKDF_TYPE) <UTF8 string>
-
- -

Sets the SSH KDF type parameter in the associated KDF ctx. There are six supported types:

- -
- -
EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV
-
- -

The Initial IV from client to server. A single char of value 65 (ASCII char 'A').

- -
-
EVP_KDF_SSHKDF_TYPE_INITIAL_IV_SRV_TO_CLI
-
- -

The Initial IV from server to client A single char of value 66 (ASCII char 'B').

- -
-
EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_CLI_TO_SRV
-
- -

The Encryption Key from client to server A single char of value 67 (ASCII char 'C').

- -
-
EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_SRV_TO_CLI
-
- -

The Encryption Key from server to client A single char of value 68 (ASCII char 'D').

- -
-
EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_CLI_TO_SRV
-
- -

The Integrity Key from client to server A single char of value 69 (ASCII char 'E').

- -
-
EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_SRV_TO_CLI
-
- -

The Integrity Key from client to server A single char of value 70 (ASCII char 'F').

- -
-
- -
-
"constant" (OSSL_KDF_PARAM_CONSTANT) <octet string>
-
- -

Sets the constant value in the associated KDF ctx.

- -
-
"id" (OSSL_KDF_PARAM_PKCS12_ID) <integer>
-
- -

Sets the intended usage of the output bits in the associated KDF ctx. It is defined as per RFC 7292 section B.3.

- -
-
- -

RETURN VALUES

- -

OSSL_FUNC_kdf_newctx() and OSSL_FUNC_kdf_dupctx() should return the newly created provider side KDF context, or NULL on failure.

- -

OSSL_FUNC_kdf_derive(), OSSL_FUNC_kdf_get_params(), OSSL_FUNC_kdf_get_ctx_params() and OSSL_FUNC_kdf_set_ctx_params() should return 1 for success or 0 on error.

- -

OSSL_FUNC_kdf_gettable_params(), OSSL_FUNC_kdf_gettable_ctx_params() and OSSL_FUNC_kdf_settable_ctx_params() should return a constant OSSL_PARAM(3) array, or NULL if none is offered.

- -

NOTES

- -

The KDF life-cycle is described in life_cycle-kdf(7). Providers should ensure that the various transitions listed there are supported. At some point the EVP layer will begin enforcing the listed transitions.

- -

SEE ALSO

- -

provider(7), life_cycle-kdf(7), EVP_KDF(3).

- -

HISTORY

- -

The provider KDF interface was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-kem.html b/openssl-install/share/doc/openssl/html/man7/provider-kem.html deleted file mode 100644 index 8708b4ac..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-kem.html +++ /dev/null @@ -1,199 +0,0 @@ - - - - -provider-kem - - - - - - - - - - -

NAME

- -

provider-kem - The kem library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_kem_newctx(void *provctx);
-void OSSL_FUNC_kem_freectx(void *ctx);
-void *OSSL_FUNC_kem_dupctx(void *ctx);
-
-/* Encapsulation */
-int OSSL_FUNC_kem_encapsulate_init(void *ctx, void *provkey,
-                                   const OSSL_PARAM params[]);
-int OSSL_FUNC_kem_auth_encapsulate_init(void *ctx, void *provkey,
-                                        void *provauthkey,
-                                        const OSSL_PARAM params[]);
-int OSSL_FUNC_kem_encapsulate(void *ctx, unsigned char *out, size_t *outlen,
-                              unsigned char *secret, size_t *secretlen);
-
-/* Decapsulation */
-int OSSL_FUNC_kem_decapsulate_init(void *ctx, void *provkey);
-int OSSL_FUNC_kem_auth_decapsulate_init(void *ctx, void *provkey,
-                                        void *provauthkey,
-                                        const OSSL_PARAM params[]);
-int OSSL_FUNC_kem_decapsulate(void *ctx, unsigned char *out, size_t *outlen,
-                              const unsigned char *in, size_t inlen);
-
-/* KEM parameters */
-int OSSL_FUNC_kem_get_ctx_params(void *ctx, OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_kem_gettable_ctx_params(void *ctx, void *provctx);
-int OSSL_FUNC_kem_set_ctx_params(void *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_kem_settable_ctx_params(void *ctx, void *provctx);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The asymmetric kem (OSSL_OP_KEM) operation enables providers to implement asymmetric kem algorithms and make them available to applications via the API functions EVP_PKEY_encapsulate(3), EVP_PKEY_decapsulate(3) and other related functions.

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_kem_newctx() has these:

- -
typedef void *(OSSL_FUNC_kem_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_kem_newctx_fn
-    OSSL_FUNC_kem_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_kem_newctx                OSSL_FUNC_KEM_NEWCTX
-OSSL_FUNC_kem_freectx               OSSL_FUNC_KEM_FREECTX
-OSSL_FUNC_kem_dupctx                OSSL_FUNC_KEM_DUPCTX
-
-OSSL_FUNC_kem_encapsulate_init      OSSL_FUNC_KEM_ENCAPSULATE_INIT
-OSSL_FUNC_kem_auth_encapsulate_init OSSL_FUNC_KEM_AUTH_ENCAPSULATE_INIT
-OSSL_FUNC_kem_encapsulate           OSSL_FUNC_KEM_ENCAPSULATE
-
-OSSL_FUNC_kem_decapsulate_init      OSSL_FUNC_KEM_DECAPSULATE_INIT
-OSSL_FUNC_kem_auth_decapsulate_init OSSL_FUNC_KEM_AUTH_DECAPSULATE_INIT
-OSSL_FUNC_kem_decapsulate           OSSL_FUNC_KEM_DECAPSULATE
-
-OSSL_FUNC_kem_get_ctx_params        OSSL_FUNC_KEM_GET_CTX_PARAMS
-OSSL_FUNC_kem_gettable_ctx_params   OSSL_FUNC_KEM_GETTABLE_CTX_PARAMS
-OSSL_FUNC_kem_set_ctx_params        OSSL_FUNC_KEM_SET_CTX_PARAMS
-OSSL_FUNC_kem_settable_ctx_params   OSSL_FUNC_KEM_SETTABLE_CTX_PARAMS
- -

An asymmetric kem algorithm implementation may not implement all of these functions. In order to be a consistent set of functions a provider must implement OSSL_FUNC_kem_newctx and OSSL_FUNC_kem_freectx. It must also implement both of OSSL_FUNC_kem_encapsulate_init and OSSL_FUNC_kem_encapsulate, or both of OSSL_FUNC_kem_decapsulate_init and OSSL_FUNC_kem_decapsulate. OSSL_FUNC_kem_auth_encapsulate_init is optional but if it is present then so must OSSL_FUNC_kem_auth_decapsulate_init. OSSL_FUNC_kem_get_ctx_params is optional but if it is present then so must OSSL_FUNC_kem_gettable_ctx_params. Similarly, OSSL_FUNC_kem_set_ctx_params is optional but if it is present then OSSL_FUNC_kem_settable_ctx_params must also be present.

- -

An asymmetric kem algorithm must also implement some mechanism for generating, loading or importing keys via the key management (OSSL_OP_KEYMGMT) operation. See provider-keymgmt(7) for further details.

- -

Context Management Functions

- -

OSSL_FUNC_kem_newctx() should create and return a pointer to a provider side structure for holding context information during an asymmetric kem operation. A pointer to this context will be passed back in a number of the other asymmetric kem operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)).

- -

OSSL_FUNC_kem_freectx() is passed a pointer to the provider side asymmetric kem context in the ctx parameter. This function should free any resources associated with that context.

- -

OSSL_FUNC_kem_dupctx() should duplicate the provider side asymmetric kem context in the ctx parameter and return the duplicate copy.

- -

Asymmetric Key Encapsulation Functions

- -

OSSL_FUNC_kem_encapsulate_init() initialises a context for an asymmetric encapsulation given a provider side asymmetric kem context in the ctx parameter, a pointer to a provider key object in the provkey parameter and the name of the algorithm. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_kem_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)>.

- -

OSSL_FUNC_kem_auth_encapsulate_init() is similar to OSSL_FUNC_kem_encapsulate_init(), but also passes an additional authentication key provauthkey which cannot be NULL.

- -

OSSL_FUNC_kem_encapsulate() performs the actual encapsulation itself. A previously initialised asymmetric kem context is passed in the ctx parameter. Unless out is NULL, the data to be encapsulated is internally generated, and returned into the buffer pointed to by the secret parameter and the encapsulated data should also be written to the location pointed to by the out parameter. The length of the encapsulated data should be written to *outlen and the length of the generated secret should be written to *secretlen.

- -

If out is NULL then the maximum length of the encapsulated data should be written to *outlen, and the maximum length of the generated secret should be written to *secretlen.

- -

Decapsulation Functions

- -

OSSL_FUNC_kem_decapsulate_init() initialises a context for an asymmetric decapsulation given a provider side asymmetric kem context in the ctx parameter, a pointer to a provider key object in the provkey parameter, and a name of the algorithm. The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)>.

- -

OSSL_FUNC_kem_auth_decapsulate_init() is similar to OSSL_FUNC_kem_decapsulate_init(), but also passes an additional authentication key provauthkey which cannot be NULL.

- -

OSSL_FUNC_kem_decapsulate() performs the actual decapsulation itself. A previously initialised asymmetric kem context is passed in the ctx parameter. The data to be decapsulated is pointed to by the in parameter which is inlen bytes long. Unless out is NULL, the decapsulated data should be written to the location pointed to by the out parameter. The length of the decapsulated data should be written to *outlen. If out is NULL then the maximum length of the decapsulated data should be written to *outlen.

- -

Asymmetric Key Encapsulation Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by the OSSL_FUNC_kem_get_ctx_params() and OSSL_FUNC_kem_set_ctx_params() functions.

- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling either OSSL_FUNC_kem_encapsulate() or OSSL_FUNC_kem_decapsulate(). It may return 0 if the "key-check" is set to 0.

- -
-
"key-check" (OSSL_KEM_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

If required this parameter should be set using OSSL_FUNC_kem_encapsulate_init() or OSSL_FUNC_kem_decapsulate_init(). The default value of 1 causes an error during the init if the key is not FIPS approved (e.g. The key has a security strength of less than 112 bits). Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

Asymmetric Key Encapsulation Parameter Functions

- -

OSSL_FUNC_kem_get_ctx_params() gets asymmetric KEM parameters associated with the given provider side asymmetric kem context ctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_kem_set_ctx_params() sets the asymmetric KEM parameters associated with the given provider side asymmetric kem context ctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

No parameters are currently recognised by built-in asymmetric kem algorithms.

- -

OSSL_FUNC_kem_gettable_ctx_params() and OSSL_FUNC_kem_settable_ctx_params() get a constant OSSL_PARAM(3) array that describes the gettable and settable parameters, i.e. parameters that can be used with OSSL_FUNC_kem_get_ctx_params() and OSSL_FUNC_kem_set_ctx_params() respectively.

- -

RETURN VALUES

- -

OSSL_FUNC_kem_newctx() and OSSL_FUNC_kem_dupctx() should return the newly created provider side asymmetric kem context, or NULL on failure.

- -

All other functions should return 1 for success or 0 on error.

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The provider KEM interface was introduced in OpenSSL 3.0.

- -

OSSL_FUNC_kem_auth_encapsulate_init() and OSSL_FUNC_kem_auth_decapsulate_init() were added in OpenSSL 3.2.

- -

The Asymmetric Key Encapsulation Parameters "fips-indicator" and "key-check" were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-keyexch.html b/openssl-install/share/doc/openssl/html/man7/provider-keyexch.html deleted file mode 100644 index 2e64bacf..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-keyexch.html +++ /dev/null @@ -1,224 +0,0 @@ - - - - -provider-keyexch - - - - - - - - - - -

NAME

- -

provider-keyexch - The keyexch library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_keyexch_newctx(void *provctx);
-void OSSL_FUNC_keyexch_freectx(void *ctx);
-void *OSSL_FUNC_keyexch_dupctx(void *ctx);
-
-/* Shared secret derivation */
-int OSSL_FUNC_keyexch_init(void *ctx, void *provkey,
-                           const OSSL_PARAM params[]);
-int OSSL_FUNC_keyexch_set_peer(void *ctx, void *provkey);
-int OSSL_FUNC_keyexch_derive(void *ctx, unsigned char *secret, size_t *secretlen,
-                             size_t outlen);
-
-/* Key Exchange parameters */
-int OSSL_FUNC_keyexch_set_ctx_params(void *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_keyexch_settable_ctx_params(void *ctx,
-                                                        void *provctx);
-int OSSL_FUNC_keyexch_get_ctx_params(void *ctx, OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_keyexch_gettable_ctx_params(void *ctx,
-                                                        void *provctx);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The key exchange (OSSL_OP_KEYEXCH) operation enables providers to implement key exchange algorithms and make them available to applications via EVP_PKEY_derive(3) and other related functions).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_keyexch_newctx() has these:

- -
typedef void *(OSSL_FUNC_keyexch_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_keyexch_newctx_fn
-    OSSL_FUNC_keyexch_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_keyexch_newctx                OSSL_FUNC_KEYEXCH_NEWCTX
-OSSL_FUNC_keyexch_freectx               OSSL_FUNC_KEYEXCH_FREECTX
-OSSL_FUNC_keyexch_dupctx                OSSL_FUNC_KEYEXCH_DUPCTX
-
-OSSL_FUNC_keyexch_init                  OSSL_FUNC_KEYEXCH_INIT
-OSSL_FUNC_keyexch_set_peer              OSSL_FUNC_KEYEXCH_SET_PEER
-OSSL_FUNC_keyexch_derive                OSSL_FUNC_KEYEXCH_DERIVE
-
-OSSL_FUNC_keyexch_set_ctx_params        OSSL_FUNC_KEYEXCH_SET_CTX_PARAMS
-OSSL_FUNC_keyexch_settable_ctx_params   OSSL_FUNC_KEYEXCH_SETTABLE_CTX_PARAMS
-OSSL_FUNC_keyexch_get_ctx_params        OSSL_FUNC_KEYEXCH_GET_CTX_PARAMS
-OSSL_FUNC_keyexch_gettable_ctx_params   OSSL_FUNC_KEYEXCH_GETTABLE_CTX_PARAMS
- -

A key exchange algorithm implementation may not implement all of these functions. In order to be a consistent set of functions a provider must implement OSSL_FUNC_keyexch_newctx, OSSL_FUNC_keyexch_freectx, OSSL_FUNC_keyexch_init and OSSL_FUNC_keyexch_derive. All other functions are optional.

- -

A key exchange algorithm must also implement some mechanism for generating, loading or importing keys via the key management (OSSL_OP_KEYMGMT) operation. See provider-keymgmt(7) for further details.

- -

Context Management Functions

- -

OSSL_FUNC_keyexch_newctx() should create and return a pointer to a provider side structure for holding context information during a key exchange operation. A pointer to this context will be passed back in a number of the other key exchange operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)).

- -

OSSL_FUNC_keyexch_freectx() is passed a pointer to the provider side key exchange context in the ctx parameter. This function should free any resources associated with that context.

- -

OSSL_FUNC_keyexch_dupctx() should duplicate the provider side key exchange context in the ctx parameter and return the duplicate copy.

- -

Shared Secret Derivation Functions

- -

OSSL_FUNC_keyexch_init() initialises a key exchange operation given a provider side key exchange context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_keyexch_set_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)>.

- -

OSSL_FUNC_keyexch_set_peer() is called to supply the peer's public key (in the provkey parameter) to be used when deriving the shared secret. It is also passed a previously initialised key exchange context in the ctx parameter. The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)>.

- -

OSSL_FUNC_keyexch_derive() performs the actual key exchange itself by deriving a shared secret. A previously initialised key exchange context is passed in the ctx parameter. The derived secret should be written to the location secret which should not exceed outlen bytes. The length of the shared secret should be written to *secretlen. If secret is NULL then the maximum length of the shared secret should be written to *secretlen.

- -

Key Exchange Parameters Functions

- -

OSSL_FUNC_keyexch_set_ctx_params() sets key exchange parameters associated with the given provider side key exchange context ctx to params, see "Common Key Exchange parameters". Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

OSSL_FUNC_keyexch_get_ctx_params() gets key exchange parameters associated with the given provider side key exchange context ctx into params, see "Common Key Exchange parameters". Passing NULL for params should return true.

- -

OSSL_FUNC_keyexch_settable_ctx_params() yields a constant OSSL_PARAM(3) array that describes the settable parameters, i.e. parameters that can be used with OP_signature_set_ctx_params(). If OSSL_FUNC_keyexch_settable_ctx_params() is present, OSSL_FUNC_keyexch_set_ctx_params() must also be present, and vice versa. Similarly, OSSL_FUNC_keyexch_gettable_ctx_params() yields a constant OSSL_PARAM(3) array that describes the gettable parameters, i.e. parameters that can be handled by OP_signature_get_ctx_params(). If OSSL_FUNC_keyexch_gettable_ctx_params() is present, OSSL_FUNC_keyexch_get_ctx_params() must also be present, and vice versa.

- -

Notice that not all settable parameters are also gettable, and vice versa.

- -

Common Key Exchange parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by the OSSL_FUNC_keyexch_set_ctx_params() and OSSL_FUNC_keyexch_get_ctx_params() functions.

- -

Common parameters currently recognised by built-in key exchange algorithms are as follows.

- -
- -
"kdf-type" (OSSL_EXCHANGE_PARAM_KDF_TYPE) <UTF8 string>
-
- -

Sets or gets the Key Derivation Function type to apply within the associated key exchange ctx.

- -
-
"kdf-digest" (OSSL_EXCHANGE_PARAM_KDF_DIGEST) <UTF8 string>
-
- -

Sets or gets the Digest algorithm to be used as part of the Key Derivation Function associated with the given key exchange ctx.

- -
-
"kdf-digest-props" (OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS) <UTF8 string>
-
- -

Sets properties to be used upon look up of the implementation for the selected Digest algorithm for the Key Derivation Function associated with the given key exchange ctx.

- -
-
"kdf-outlen" (OSSL_EXCHANGE_PARAM_KDF_OUTLEN) <unsigned integer>
-
- -

Sets or gets the desired size for the output of the chosen Key Derivation Function associated with the given key exchange ctx. The length of the "kdf-outlen" parameter should not exceed that of a size_t.

- -
-
"kdf-ukm" (OSSL_EXCHANGE_PARAM_KDF_UKM) <octet string>
-
- -

Sets the User Key Material to be used as part of the selected Key Derivation Function associated with the given key exchange ctx.

- -
-
"kdf-ukm" (OSSL_EXCHANGE_PARAM_KDF_UKM) <octet string ptr>
-
- -

Gets a pointer to the User Key Material to be used as part of the selected Key Derivation Function associated with the given key exchange ctx. Providers usually do not need to support this gettable parameter as its sole purpose is to support functionality of the deprecated EVP_PKEY_CTX_get0_ecdh_kdf_ukm() and EVP_PKEY_CTX_get0_dh_kdf_ukm() functions.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling OSSL_FUNC_keyexch_derive(). It may return 0 if either the "digest-check" or the "key-check" are set to 0.

- -
-
"key-check" (OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

If required this parameter should be set using OSSL_FUNC_keyexch_init(). The default value of 1 causes an error during the init if the key is not FIPS approved (e.g. The key has a security strength of less than 112 bits). Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"digest-check" (OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

If required this parameter should be set before any optional digest is set. The default value of 1 causes an error when the digest is set if the digest is not FIPS approved. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

RETURN VALUES

- -

OSSL_FUNC_keyexch_newctx() and OSSL_FUNC_keyexch_dupctx() should return the newly created provider side key exchange context, or NULL on failure.

- -

OSSL_FUNC_keyexch_init(), OSSL_FUNC_keyexch_set_peer(), OSSL_FUNC_keyexch_derive(), OSSL_FUNC_keyexch_set_params(), and OSSL_FUNC_keyexch_get_params() should return 1 for success or 0 on error.

- -

OSSL_FUNC_keyexch_settable_ctx_params() and OSSL_FUNC_keyexch_gettable_ctx_params() should always return a constant OSSL_PARAM(3) array.

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The provider KEYEXCH interface was introduced in OpenSSL 3.0.

- -

The Key Exchange Parameters "fips-indicator", "key-check" and "digest-check" were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-keymgmt.html b/openssl-install/share/doc/openssl/html/man7/provider-keymgmt.html deleted file mode 100644 index 176d0cd1..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-keymgmt.html +++ /dev/null @@ -1,397 +0,0 @@ - - - - -provider-keymgmt - - - - - - - - - - -

NAME

- -

provider-keymgmt - The KEYMGMT library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Key object (keydata) creation and destruction */
-void *OSSL_FUNC_keymgmt_new(void *provctx);
-void OSSL_FUNC_keymgmt_free(void *keydata);
-
-/* Generation, a more complex constructor */
-void *OSSL_FUNC_keymgmt_gen_init(void *provctx, int selection,
-                                 const OSSL_PARAM params[]);
-int OSSL_FUNC_keymgmt_gen_set_template(void *genctx, void *template);
-int OSSL_FUNC_keymgmt_gen_get_params(void *genctx, OSSL_PARAM params[]);
-int OSSL_FUNC_keymgmt_gen_set_params(void *genctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_gen_gettable_params(void *genctx,
-                                                        void *provctx);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_gen_settable_params(void *genctx,
-                                                        void *provctx);
-void *OSSL_FUNC_keymgmt_gen(void *genctx, OSSL_CALLBACK *cb, void *cbarg);
-void OSSL_FUNC_keymgmt_gen_cleanup(void *genctx);
-
-/* Key loading by object reference, also a constructor */
-void *OSSL_FUNC_keymgmt_load(const void *reference, size_t reference_sz);
-
-/* Key object information */
-int OSSL_FUNC_keymgmt_get_params(void *keydata, OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_gettable_params(void *provctx);
-int OSSL_FUNC_keymgmt_set_params(void *keydata, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_settable_params(void *provctx);
-
-/* Key object content checks */
-int OSSL_FUNC_keymgmt_has(const void *keydata, int selection);
-int OSSL_FUNC_keymgmt_match(const void *keydata1, const void *keydata2,
-                            int selection);
-
-/* Discovery of supported operations */
-const char *OSSL_FUNC_keymgmt_query_operation_name(int operation_id);
-
-/* Key object import and export functions */
-int OSSL_FUNC_keymgmt_import(void *keydata, int selection, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_import_types(int selection);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_import_types_ex(void *provctx, int selection);
-int OSSL_FUNC_keymgmt_export(void *keydata, int selection,
-                             OSSL_CALLBACK *param_cb, void *cbarg);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_export_types(int selection);
-const OSSL_PARAM *OSSL_FUNC_keymgmt_export_types_ex(void *provctx, int selection);
-
-/* Key object duplication, a constructor */
-void *OSSL_FUNC_keymgmt_dup(const void *keydata_from, int selection);
-
-/* Key object validation */
-int OSSL_FUNC_keymgmt_validate(const void *keydata, int selection, int checktype);
- -

DESCRIPTION

- -

The KEYMGMT operation doesn't have much public visibility in OpenSSL libraries, it's rather an internal operation that's designed to work in tandem with operations that use private/public key pairs.

- -

Because the KEYMGMT operation shares knowledge with the operations it works with in tandem, they must belong to the same provider. The OpenSSL libraries will ensure that they do.

- -

The primary responsibility of the KEYMGMT operation is to hold the provider side key data for the OpenSSL library EVP_PKEY structure.

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from a OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_keymgmt_new() has these:

- -
typedef void *(OSSL_FUNC_keymgmt_new_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_keymgmt_new_fn
-    OSSL_FUNC_keymgmt_new(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_keymgmt_new                  OSSL_FUNC_KEYMGMT_NEW
-OSSL_FUNC_keymgmt_free                 OSSL_FUNC_KEYMGMT_FREE
-
-OSSL_FUNC_keymgmt_gen_init             OSSL_FUNC_KEYMGMT_GEN_INIT
-OSSL_FUNC_keymgmt_gen_set_template     OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE
-OSSL_FUNC_keymgmt_gen_get_params       OSSL_FUNC_KEYMGMT_GEN_GET_PARAMS
-OSSL_FUNC_keymgmt_gen_gettable_params  OSSL_FUNC_KEYMGMT_GEN_GETTABLE_PARAMS
-OSSL_FUNC_keymgmt_gen_set_params       OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS
-OSSL_FUNC_keymgmt_gen_settable_params  OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS
-OSSL_FUNC_keymgmt_gen                  OSSL_FUNC_KEYMGMT_GEN
-OSSL_FUNC_keymgmt_gen_cleanup          OSSL_FUNC_KEYMGMT_GEN_CLEANUP
-
-OSSL_FUNC_keymgmt_load                 OSSL_FUNC_KEYMGMT_LOAD
-
-OSSL_FUNC_keymgmt_get_params           OSSL_FUNC_KEYMGMT_GET_PARAMS
-OSSL_FUNC_keymgmt_gettable_params      OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS
-OSSL_FUNC_keymgmt_set_params           OSSL_FUNC_KEYMGMT_SET_PARAMS
-OSSL_FUNC_keymgmt_settable_params      OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS
-
-OSSL_FUNC_keymgmt_query_operation_name OSSL_FUNC_KEYMGMT_QUERY_OPERATION_NAME
-
-OSSL_FUNC_keymgmt_has                  OSSL_FUNC_KEYMGMT_HAS
-OSSL_FUNC_keymgmt_validate             OSSL_FUNC_KEYMGMT_VALIDATE
-OSSL_FUNC_keymgmt_match                OSSL_FUNC_KEYMGMT_MATCH
-
-OSSL_FUNC_keymgmt_import               OSSL_FUNC_KEYMGMT_IMPORT
-OSSL_FUNC_keymgmt_import_types         OSSL_FUNC_KEYMGMT_IMPORT_TYPES
-OSSL_FUNC_keymgmt_import_types_ex      OSSL_FUNC_KEYMGMT_IMPORT_TYPES_EX
-OSSL_FUNC_keymgmt_export               OSSL_FUNC_KEYMGMT_EXPORT
-OSSL_FUNC_keymgmt_export_types         OSSL_FUNC_KEYMGMT_EXPORT_TYPES
-OSSL_FUNC_keymgmt_export_types_ex      OSSL_FUNC_KEYMGMT_EXPORT_TYPES_EX
-
-OSSL_FUNC_keymgmt_dup                  OSSL_FUNC_KEYMGMT_DUP
- -

Key Objects

- -

A key object is a collection of data for an asymmetric key, and is represented as keydata in this manual.

- -

The exact contents of a key object are defined by the provider, and it is assumed that different operations in one and the same provider use the exact same structure to represent this collection of data, so that for example, a key object that has been created using the KEYMGMT interface that we document here can be passed as is to other provider operations, such as OP_signature_sign_init() (see provider-signature(7)).

- -

With some of the KEYMGMT functions, it's possible to select a specific subset of data to handle, governed by the bits in a selection indicator. The bits are:

- -
- -
OSSL_KEYMGMT_SELECT_PRIVATE_KEY
-
- -

Indicating that the private key data in a key object should be considered.

- -
-
OSSL_KEYMGMT_SELECT_PUBLIC_KEY
-
- -

Indicating that the public key data in a key object should be considered.

- -
-
OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS
-
- -

Indicating that the domain parameters in a key object should be considered.

- -
-
OSSL_KEYMGMT_SELECT_OTHER_PARAMETERS
-
- -

Indicating that other parameters in a key object should be considered.

- -

Other parameters are key parameters that don't fit any other classification. In other words, this particular selector bit works as a last resort bit bucket selector.

- -
-
- -

Some selector bits have also been combined for easier use:

- -
- -
OSSL_KEYMGMT_SELECT_ALL_PARAMETERS
-
- -

Indicating that all key object parameters should be considered, regardless of their more granular classification.

- -

This is a combination of OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS and OSSL_KEYMGMT_SELECT_OTHER_PARAMETERS.

- -
-
OSSL_KEYMGMT_SELECT_KEYPAIR
-
- -

Indicating that both the whole key pair in a key object should be considered, i.e. the combination of public and private key.

- -

This is a combination of OSSL_KEYMGMT_SELECT_PRIVATE_KEY and OSSL_KEYMGMT_SELECT_PUBLIC_KEY.

- -
-
OSSL_KEYMGMT_SELECT_ALL
-
- -

Indicating that everything in a key object should be considered.

- -
-
- -

The exact interpretation of those bits or how they combine is left to each function where you can specify a selector.

- -

It's left to the provider implementation to decide what is reasonable to do with regards to received selector bits and how to do it. Among others, an implementation of OSSL_FUNC_keymgmt_match() might opt to not compare the private half if it has compared the public half, since a match of one half implies a match of the other half.

- -

Constructing and Destructing Functions

- -

OSSL_FUNC_keymgmt_new() should create a provider side key object. The provider context provctx is passed and may be incorporated in the key object, but that is not mandatory.

- -

OSSL_FUNC_keymgmt_free() should free the passed keydata.

- -

OSSL_FUNC_keymgmt_gen_init(), OSSL_FUNC_keymgmt_gen_set_template(), OSSL_FUNC_keymgmt_gen_get_params(), OSSL_FUNC_keymgmt_gen_gettable_params(), OSSL_FUNC_keymgmt_gen_set_params(), OSSL_FUNC_keymgmt_gen_settable_params(), OSSL_FUNC_keymgmt_gen() and OSSL_FUNC_keymgmt_gen_cleanup() work together as a more elaborate context based key object constructor.

- -

OSSL_FUNC_keymgmt_gen_init() should create the key object generation context and initialize it with selections, which will determine what kind of contents the key object to be generated should get. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_keymgmt_set_params().

- -

OSSL_FUNC_keymgmt_gen_set_template() should add template to the context genctx. The template is assumed to be a key object constructed with the same KEYMGMT, and from which content that the implementation chooses can be used as a template for the key object to be generated. Typically, the generation of a DSA or DH key would get the domain parameters from this template.

- -

OSSL_FUNC_keymgmt_gen_get_params() should retrieve parameters into params in the key object generation context genctx.

- -

OSSL_FUNC_keymgmt_gen_gettable_params() should return a constant array of descriptor OSSL_PARAM(3), for parameters that OSSL_FUNC_keymgmt_gen_get_params() can handle.

- -

OSSL_FUNC_keymgmt_gen_set_params() should set additional parameters from params in the key object generation context genctx.

- -

OSSL_FUNC_keymgmt_gen_settable_params() should return a constant array of descriptor OSSL_PARAM(3), for parameters that OSSL_FUNC_keymgmt_gen_set_params() can handle.

- -

OSSL_FUNC_keymgmt_gen() should perform the key object generation itself, and return the result. The callback cb should be called at regular intervals with indications on how the key object generation progresses.

- -

OSSL_FUNC_keymgmt_gen_cleanup() should clean up and free the key object generation context genctx

- -

OSSL_FUNC_keymgmt_load() creates a provider side key object based on a reference object with a size of reference_sz bytes, that only the provider knows how to interpret, but that may come from other operations. Outside the provider, this reference is simply an array of bytes.

- -

At least one of OSSL_FUNC_keymgmt_new(), OSSL_FUNC_keymgmt_gen() and OSSL_FUNC_keymgmt_load() are mandatory, as well as OSSL_FUNC_keymgmt_free() and OSSL_FUNC_keymgmt_has(). Additionally, if OSSL_FUNC_keymgmt_gen() is present, OSSL_FUNC_keymgmt_gen_init() and OSSL_FUNC_keymgmt_gen_cleanup() must be present as well.

- -

Key Object Information Functions

- -

OSSL_FUNC_keymgmt_get_params() should extract information data associated with the given keydata, see "Common Information Parameters".

- -

OSSL_FUNC_keymgmt_gettable_params() should return a constant array of descriptor OSSL_PARAM(3), for parameters that OSSL_FUNC_keymgmt_get_params() can handle.

- -

If OSSL_FUNC_keymgmt_gettable_params() is present, OSSL_FUNC_keymgmt_get_params() must also be present, and vice versa.

- -

OSSL_FUNC_keymgmt_set_params() should update information data associated with the given keydata, see "Common Information Parameters".

- -

OSSL_FUNC_keymgmt_settable_params() should return a constant array of descriptor OSSL_PARAM(3), for parameters that OSSL_FUNC_keymgmt_set_params() can handle.

- -

If OSSL_FUNC_keymgmt_settable_params() is present, OSSL_FUNC_keymgmt_set_params() must also be present, and vice versa.

- -

Key Object Checking Functions

- -

OSSL_FUNC_keymgmt_query_operation_name() should return the name of the supported algorithm for the operation operation_id. This is similar to provider_query_operation() (see provider-base(7)), but only works as an advisory. If this function is not present, or returns NULL, the caller is free to assume that there's an algorithm from the same provider, of the same name as the one used to fetch the keymgmt and try to use that.

- -

OSSL_FUNC_keymgmt_has() should check whether the given keydata contains the subsets of data indicated by the selector. A combination of several selector bits must consider all those subsets, not just one. An implementation is, however, free to consider an empty subset of data to still be a valid subset. For algorithms where some selection is not meaningful such as OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS for RSA keys the function should just return 1 as the selected subset is not really missing in the key.

- -

OSSL_FUNC_keymgmt_validate() should check if the keydata contains valid data subsets indicated by selection. Some combined selections of data subsets may cause validation of the combined data. For example, the combination of OSSL_KEYMGMT_SELECT_PRIVATE_KEY and OSSL_KEYMGMT_SELECT_PUBLIC_KEY (or OSSL_KEYMGMT_SELECT_KEYPAIR for short) is expected to check that the pairwise consistency of keydata is valid. The checktype parameter controls what type of check is performed on the subset of data. Two types of check are defined: OSSL_KEYMGMT_VALIDATE_FULL_CHECK and OSSL_KEYMGMT_VALIDATE_QUICK_CHECK. The interpretation of how much checking is performed in a full check versus a quick check is key type specific. Some providers may have no distinction between a full check and a quick check. For algorithms where some selection is not meaningful such as OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS for RSA keys the function should just return 1 as there is nothing to validate for that selection.

- -

OSSL_FUNC_keymgmt_match() should check if the data subset indicated by selection in keydata1 and keydata2 match. It is assumed that the caller has ensured that keydata1 and keydata2 are both owned by the implementation of this function.

- -

Key Object Import, Export and Duplication Functions

- -

OSSL_FUNC_keymgmt_import() should import data indicated by selection into keydata with values taken from the OSSL_PARAM(3) array params.

- -

OSSL_FUNC_keymgmt_export() should extract values indicated by selection from keydata, create an OSSL_PARAM(3) array with them and call param_cb with that array as well as the given cbarg.

- -

OSSL_FUNC_keymgmt_import_types() and OSSL_FUNC_keymgmt_import_types_ex() should return a constant array of descriptor OSSL_PARAM(3) for data indicated by selection, for parameters that OSSL_FUNC_keymgmt_import() can handle. Either OSSL_FUNC_keymgmt_import_types() or OSSL_FUNC_keymgmt_import_types_ex(), must be implemented, if OSSL_FUNC_keymgmt_import_types_ex() is implemented, then it is preferred over OSSL_FUNC_keymgmt_import_types(). Providers that are supposed to be backward compatible with OpenSSL 3.0 or 3.1 must continue to implement OSSL_FUNC_keymgmt_import_types().

- -

OSSL_FUNC_keymgmt_export_types() and OSSL_FUNC_keymgmt_export_types_ex() should return a constant array of descriptor OSSL_PARAM(3) for data indicated by selection, that the OSSL_FUNC_keymgmt_export() callback can expect to receive. Either OSSL_FUNC_keymgmt_export_types() or OSSL_FUNC_keymgmt_export_types_ex(), must be implemented, if OSSL_FUNC_keymgmt_export_types_ex() is implemented, then it is preferred over OSSL_FUNC_keymgmt_export_types(). Providers that are supposed to be backward compatible with OpenSSL 3.0 or 3.1 must continue to implement OSSL_FUNC_keymgmt_export_types().

- -

OSSL_FUNC_keymgmt_dup() should duplicate data subsets indicated by selection or the whole key data keydata_from and create a new provider side key object with the data.

- -

Common Information Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure.

- -

Common information parameters currently recognised by all built-in keymgmt algorithms are as follows:

- -
- -
"bits" (OSSL_PKEY_PARAM_BITS) <integer>
-
- -

The value should be the cryptographic length of the cryptosystem to which the key belongs, in bits. The definition of cryptographic length is specific to the key cryptosystem.

- -
-
"max-size" (OSSL_PKEY_PARAM_MAX_SIZE) <integer>
-
- -

The value should be the maximum size that a caller should allocate to safely store a signature (called sig in provider-signature(7)), the result of asymmetric encryption / decryption (out in provider-asym_cipher(7), a derived secret (secret in provider-keyexch(7), and similar data).

- -

Providers need to implement this parameter in order to properly support various use cases such as CMS signing.

- -

Because an EVP_KEYMGMT method is always tightly bound to another method (signature, asymmetric cipher, key exchange, ...) and must be of the same provider, this number only needs to be synchronised with the dimensions handled in the rest of the same provider.

- -
-
"security-bits" (OSSL_PKEY_PARAM_SECURITY_BITS) <integer>
-
- -

The value should be the number of security bits of the given key. Bits of security is defined in SP800-57.

- -
-
"mandatory-digest" (OSSL_PKEY_PARAM_MANDATORY_DIGEST) <UTF8 string>
-
- -

If there is a mandatory digest for performing a signature operation with keys from this keymgmt, this parameter should get its name as value.

- -

When EVP_PKEY_get_default_digest_name() queries this parameter and it's filled in by the implementation, its return value will be 2.

- -

If the keymgmt implementation fills in the value "" or "UNDEF", EVP_PKEY_get_default_digest_name(3) will place the string "UNDEF" into its argument mdname. This signifies that no digest should be specified with the corresponding signature operation.

- -
-
"default-digest" (OSSL_PKEY_PARAM_DEFAULT_DIGEST) <UTF8 string>
-
- -

If there is a default digest for performing a signature operation with keys from this keymgmt, this parameter should get its name as value.

- -

When EVP_PKEY_get_default_digest_name(3) queries this parameter and it's filled in by the implementation, its return value will be 1. Note that if OSSL_PKEY_PARAM_MANDATORY_DIGEST is responded to as well, EVP_PKEY_get_default_digest_name(3) ignores the response to this parameter.

- -

If the keymgmt implementation fills in the value "" or "UNDEF", EVP_PKEY_get_default_digest_name(3) will place the string "UNDEF" into its argument mdname. This signifies that no digest has to be specified with the corresponding signature operation, but may be specified as an option.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling OSSL_FUNC_keymgmt_gen() function. It may return 0 if either the "key-check", or "sign-check" are set to 0.

- -
-
"key-check" (OSSL_PKEY_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

If required this parameter should be set using OSSL_FUNC_keymgmt_gen_set_params() or OSSL_FUNC_keymgmt_gen_init(). The default value of 1 causes an error during the init if the key is not FIPS approved (e.g. The key has a security strength of less than 112 bits). Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"sign-check" (OSSL_PKEY_PARAM_FIPS_SIGN_CHECK) <integer>
-
- -

If required this parameter should be set before the OSSL_FUNC_keymgmt_gen() function. This value is not supported by all keygen algorithms. The default value of 1 will cause an error if the generated key is not allowed to be used for signing. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

RETURN VALUES

- -

OSSL_FUNC_keymgmt_new() and OSSL_FUNC_keymgmt_dup() should return a valid reference to the newly created provider side key object, or NULL on failure.

- -

OSSL_FUNC_keymgmt_import(), OSSL_FUNC_keymgmt_export(), OSSL_FUNC_keymgmt_get_params() and OSSL_FUNC_keymgmt_set_params() should return 1 for success or 0 on error.

- -

OSSL_FUNC_keymgmt_validate() should return 1 on successful validation, or 0 on failure.

- -

OSSL_FUNC_keymgmt_has() should return 1 if all the selected data subsets are contained in the given keydata or 0 otherwise.

- -

OSSL_FUNC_keymgmt_query_operation_name() should return a pointer to a string matching the requested operation, or NULL if the same name used to fetch the keymgmt applies.

- -

OSSL_FUNC_keymgmt_gettable_params() and OSSL_FUNC_keymgmt_settable_params() OSSL_FUNC_keymgmt_import_types(), OSSL_FUNC_keymgmt_import_types_ex(), OSSL_FUNC_keymgmt_export_types(), OSSL_FUNC_keymgmt_export_types_ex() should always return a constant OSSL_PARAM(3) array.

- -

SEE ALSO

- -

EVP_PKEY_get_size(3), EVP_PKEY_get_bits(3), EVP_PKEY_get_security_bits(3), provider(7), EVP_PKEY-X25519(7), EVP_PKEY-X448(7), EVP_PKEY-ED25519(7), EVP_PKEY-ED448(7), EVP_PKEY-EC(7), EVP_PKEY-RSA(7), EVP_PKEY-DSA(7), EVP_PKEY-DH(7)

- -

HISTORY

- -

The KEYMGMT interface was introduced in OpenSSL 3.0.

- -

Functions OSSL_FUNC_keymgmt_import_types_ex(), and OSSL_FUNC_keymgmt_export_types_ex() were added with OpenSSL 3.2.

- -

The functions OSSL_FUNC_keymgmt_gen_get_params() and OSSL_FUNC_keymgmt_gen_gettable_params() were added in OpenSSL 3.4.

- -

The parameters "sign-check" and "fips-indicator" were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-mac.html b/openssl-install/share/doc/openssl/html/man7/provider-mac.html deleted file mode 100644 index 79232755..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-mac.html +++ /dev/null @@ -1,230 +0,0 @@ - - - - -provider-mac - - - - - - - - - - -

NAME

- -

provider-mac - The mac library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_mac_newctx(void *provctx);
-void OSSL_FUNC_mac_freectx(void *mctx);
-void *OSSL_FUNC_mac_dupctx(void *src);
-
-/* Encryption/decryption */
-int OSSL_FUNC_mac_init(void *mctx, unsigned char *key, size_t keylen,
-                       const OSSL_PARAM params[]);
-int OSSL_FUNC_mac_update(void *mctx, const unsigned char *in, size_t inl);
-int OSSL_FUNC_mac_final(void *mctx, unsigned char *out, size_t *outl, size_t outsize);
-
-/* MAC parameter descriptors */
-const OSSL_PARAM *OSSL_FUNC_mac_gettable_params(void *provctx);
-const OSSL_PARAM *OSSL_FUNC_mac_gettable_ctx_params(void *mctx, void *provctx);
-const OSSL_PARAM *OSSL_FUNC_mac_settable_ctx_params(void *mctx, void *provctx);
-
-/* MAC parameters */
-int OSSL_FUNC_mac_get_params(OSSL_PARAM params[]);
-int OSSL_FUNC_mac_get_ctx_params(void *mctx, OSSL_PARAM params[]);
-int OSSL_FUNC_mac_set_ctx_params(void *mctx, const OSSL_PARAM params[]);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The MAC operation enables providers to implement mac algorithms and make them available to applications via the API functions EVP_MAC_init(3), EVP_MAC_update(3) and EVP_MAC_final(3).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_mac_newctx() has these:

- -
typedef void *(OSSL_FUNC_mac_newctx_fn)(void *provctx);
-static ossl_inline OSSL_FUNC_mac_newctx_fn
-    OSSL_FUNC_mac_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_mac_newctx               OSSL_FUNC_MAC_NEWCTX
-OSSL_FUNC_mac_freectx              OSSL_FUNC_MAC_FREECTX
-OSSL_FUNC_mac_dupctx               OSSL_FUNC_MAC_DUPCTX
-
-OSSL_FUNC_mac_init                 OSSL_FUNC_MAC_INIT
-OSSL_FUNC_mac_update               OSSL_FUNC_MAC_UPDATE
-OSSL_FUNC_mac_final                OSSL_FUNC_MAC_FINAL
-
-OSSL_FUNC_mac_get_params           OSSL_FUNC_MAC_GET_PARAMS
-OSSL_FUNC_mac_get_ctx_params       OSSL_FUNC_MAC_GET_CTX_PARAMS
-OSSL_FUNC_mac_set_ctx_params       OSSL_FUNC_MAC_SET_CTX_PARAMS
-
-OSSL_FUNC_mac_gettable_params      OSSL_FUNC_MAC_GETTABLE_PARAMS
-OSSL_FUNC_mac_gettable_ctx_params  OSSL_FUNC_MAC_GETTABLE_CTX_PARAMS
-OSSL_FUNC_mac_settable_ctx_params  OSSL_FUNC_MAC_SETTABLE_CTX_PARAMS
- -

A mac algorithm implementation may not implement all of these functions. In order to be a consistent set of functions, at least the following functions must be implemented: OSSL_FUNC_mac_newctx(), OSSL_FUNC_mac_freectx(), OSSL_FUNC_mac_init(), OSSL_FUNC_mac_update(), OSSL_FUNC_mac_final(). All other functions are optional.

- -

Context Management Functions

- -

OSSL_FUNC_mac_newctx() should create and return a pointer to a provider side structure for holding context information during a mac operation. A pointer to this context will be passed back in a number of the other mac operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)).

- -

OSSL_FUNC_mac_freectx() is passed a pointer to the provider side mac context in the mctx parameter. If it receives NULL as mctx value, it should not do anything other than return. This function should free any resources associated with that context.

- -

OSSL_FUNC_mac_dupctx() should duplicate the provider side mac context in the mctx parameter and return the duplicate copy.

- -

Encryption/Decryption Functions

- -

OSSL_FUNC_mac_init() initialises a mac operation given a newly created provider side mac context in the mctx parameter. The params are set before setting the MAC key of keylen bytes.

- -

OSSL_FUNC_mac_update() is called to supply data for MAC computation of a previously initialised mac operation. The mctx parameter contains a pointer to a previously initialised provider side context. OSSL_FUNC_mac_update() may be called multiple times for a single mac operation.

- -

OSSL_FUNC_mac_final() completes the MAC computation started through previous OSSL_FUNC_mac_init() and OSSL_FUNC_mac_update() calls. The mctx parameter contains a pointer to the provider side context. The resulting MAC should be written to out and the amount of data written to *outl, which should not exceed outsize bytes. The same expectations apply to outsize as documented for EVP_MAC_final(3).

- -

Mac Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by these functions.

- -

OSSL_FUNC_mac_get_params() gets details of parameter values associated with the provider algorithm and stores them in params.

- -

OSSL_FUNC_mac_set_ctx_params() sets mac parameters associated with the given provider side mac context mctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

OSSL_FUNC_mac_get_ctx_params() gets details of currently set parameter values associated with the given provider side mac context mctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_mac_gettable_params(), OSSL_FUNC_mac_gettable_ctx_params(), and OSSL_FUNC_mac_settable_ctx_params() all return constant OSSL_PARAM(3) arrays as descriptors of the parameters that OSSL_FUNC_mac_get_params(), OSSL_FUNC_mac_get_ctx_params(), and OSSL_FUNC_mac_set_ctx_params() can handle, respectively. OSSL_FUNC_mac_gettable_ctx_params() and OSSL_FUNC_mac_settable_ctx_params() will return the parameters associated with the provider side context mctx in its current state if it is not NULL. Otherwise, they return the parameters associated with the provider side algorithm provctx.

- -

All MAC implementations are expected to handle the following parameters:

- -
- -
with OSSL_FUNC_set_ctx_params():
-
- -
- -
"key" (OSSL_MAC_PARAM_KEY) <octet string>
-
- -

Sets the key in the associated MAC ctx. This is identical to passing a key argument to the OSSL_FUNC_mac_init() function.

- -
-
- -
-
with OSSL_FUNC_get_params():
-
- -
- -
"size" (OSSL_MAC_PARAM_SIZE) <integer>
-
- -

Can be used to get the default MAC size (which might be the only allowable MAC size for the implementation).

- -

Note that some implementations allow setting the size that the resulting MAC should have as well, see the documentation of the implementation.

- -
-
- -
- -
"size" (OSSL_MAC_PARAM_BLOCK_SIZE) <integer>
-
- -

Can be used to get the MAC block size (if supported by the algorithm).

- -
-
- -
-
- -

The OpenSSL FIPS provider may support the following parameters:

- -
- -
"fips-indicator" (OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR) <int>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling the final function. It may return 0 if either "no-short-mac" or "key-check" are set to 0.

- -
-
"no-short-mac" (OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC) <integer>
-
- -

If required this parameter should be set early via an init function. The default value of 1 causes an error when too short MAC output is asked for. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"key-check" (OSSL_MAC_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

If required this parameter should be set before OSSL_FUNC_mac_init. The default value of 1 causes an error when small key sizes are asked for. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

NOTES

- -

The MAC life-cycle is described in life_cycle-rand(7). Providers should ensure that the various transitions listed there are supported. At some point the EVP layer will begin enforcing the listed transitions.

- -

RETURN VALUES

- -

OSSL_FUNC_mac_newctx() and OSSL_FUNC_mac_dupctx() should return the newly created provider side mac context, or NULL on failure.

- -

OSSL_FUNC_mac_init(), OSSL_FUNC_mac_update(), OSSL_FUNC_mac_final(), OSSL_FUNC_mac_get_params(), OSSL_FUNC_mac_get_ctx_params() and OSSL_FUNC_mac_set_ctx_params() should return 1 for success or 0 on error.

- -

OSSL_FUNC_mac_gettable_params(), OSSL_FUNC_mac_gettable_ctx_params() and OSSL_FUNC_mac_settable_ctx_params() should return a constant OSSL_PARAM(3) array, or NULL if none is offered.

- -

SEE ALSO

- -

provider(7), EVP_MAC-BLAKE2(7), EVP_MAC-CMAC(7), EVP_MAC-GMAC(7), EVP_MAC-HMAC(7), EVP_MAC-KMAC(7), EVP_MAC-Poly1305(7), EVP_MAC-Siphash(7), life_cycle-mac(7), EVP_MAC(3)

- -

HISTORY

- -

The provider MAC interface was introduced in OpenSSL 3.0. The parameters "no-short-mac" and "fips-indicator" were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-object.html b/openssl-install/share/doc/openssl/html/man7/provider-object.html deleted file mode 100644 index 20276b4f..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-object.html +++ /dev/null @@ -1,181 +0,0 @@ - - - - -provider-object - - - - - - - - - - -

NAME

- -

provider-object - A specification for a provider-native object abstraction

- -

SYNOPSIS

- -
#include <openssl/core_object.h>
-#include <openssl/core_names.h>
- -

DESCRIPTION

- -

The provider-native object abstraction is a set of OSSL_PARAM(3) keys and values that can be used to pass provider-native objects to OpenSSL library code or between different provider operation implementations with the help of OpenSSL library code.

- -

The intention is that certain provider-native operations can pass any sort of object that belong with other operations, or with OpenSSL library code.

- -

An object may be passed in the following manners:

- -
    - -
  1. By value

    - -

    This means that the object data is passed as an octet string or an UTF8 string, which can be handled in diverse ways by other provided implementations. The encoding of the object depends on the context it's used in; for example, OSSL_DECODER(3) allows multiple encodings, depending on existing decoders. If central OpenSSL library functionality is to handle the data directly, it must be encoded in DER for all object types except for OSSL_OBJECT_NAME (see "Parameter reference" below), where it's assumed to a plain UTF8 string.

    - -
  2. -
  3. By reference

    - -

    This means that the object data isn't passed directly, an object reference is passed instead. It's an octet string that only the correct provider understands correctly.

    - -
  4. -
- -

Objects by value can be used by anything that handles DER encoded objects.

- -

Objects by reference need a higher level of cooperation from the implementation where the object originated (let's call it X) and its target implementation (let's call it Y):

- -
    - -
  1. An object loading function in the target implementation

    - -

    The target implementation (Y) may have a function that can take an object reference. This can only be used if the target implementation is from the same provider as the one originating the object abstraction in question (X).

    - -

    The exact target implementation to use is determined from the object type and possibly the object data type. For example, when the OpenSSL library receives an object abstraction with the object type OSSL_OBJECT_PKEY, it will fetch a provider-keymgmt(7) using the object data type as its key type (the second argument in EVP_KEYMGMT_fetch(3)).

    - -
  2. -
  3. An object exporter in the originating implementation

    - -

    The originating implementation (X) may have an exporter function. This exporter function can be used to export the object in OSSL_PARAM(3) form, that can then be imported by the target implementation's imported function.

    - -

    This can be used when it's not possible to fetch the target implementation (Y) from the same provider.

    - -
  4. -
- -

Parameter reference

- -

A provider-native object abstraction is an OSSL_PARAM(3) with a selection of the following parameters:

- -
- -
"data" (OSSL_OBJECT_PARAM_DATA) <octet string> or <UTF8 string>
-
- -

The object data passed by value.

- -
-
"reference" (OSSL_OBJECT_PARAM_REFERENCE) <octet string>
-
- -

The object data passed by reference.

- -
-
"type" (OSSL_OBJECT_PARAM_TYPE) <integer>
-
- -

The object type, a number that may have any of the following values (all defined in <openssl/core_object.h>):

- -
- -
OSSL_OBJECT_NAME
-
- -

The object data may only be passed by value, and should be a UTF8 string.

- -

This is useful for provider-storemgmt(7) when a URI load results in new URIs.

- -
-
OSSL_OBJECT_PKEY
-
- -

The object data is suitable as provider-native EVP_PKEY key data. The object data may be passed by value or passed by reference.

- -
-
OSSL_OBJECT_CERT
-
- -

The object data is suitable as X509 data. The object data for this object type can only be passed by value, and should be an octet string.

- -

Since there's no provider-native X.509 object, OpenSSL libraries that receive this object abstraction are expected to convert the data to a X509 object with d2i_X509().

- -
-
OSSL_OBJECT_CRL
-
- -

The object data is suitable as X509_CRL data. The object data can only be passed by value, and should be an octet string.

- -

Since there's no provider-native X.509 CRL object, OpenSSL libraries that receive this object abstraction are expected to convert the data to a X509_CRL object with d2i_X509_CRL().

- -
-
- -
-
"data-type" (OSSL_OBJECT_PARAM_DATA_TYPE) <UTF8 string>
-
- -

The specific type of the object content. Legitimate values depend on the object type; if it is OSSL_OBJECT_PKEY, the data type is expected to be a key type suitable for fetching a provider-keymgmt(7) that can handle the data.

- -
-
"data-structure" (OSSL_OBJECT_PARAM_DATA_STRUCTURE) <UTF8 string>
-
- -

The outermost structure of the object content. Legitimate values depend on the object type.

- -
-
"desc" (OSSL_OBJECT_PARAM_DESC) <UTF8 string>
-
- -

A human readable text that describes extra details on the object.

- -
-
- -

When a provider-native object abstraction is used, it must contain object data in at least one form (object data passed by value, i.e. the "data" item, or object data passed by reference, i.e. the "reference" item). Both may be present at once, in which case the OpenSSL library code that receives this will use the most optimal variant.

- -

For objects with the object type OSSL_OBJECT_NAME, that object type must be given.

- -

SEE ALSO

- -

provider(7), OSSL_DECODER(3)

- -

HISTORY

- -

The concept of providers and everything surrounding them was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-rand.html b/openssl-install/share/doc/openssl/html/man7/provider-rand.html deleted file mode 100644 index f800cd52..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-rand.html +++ /dev/null @@ -1,303 +0,0 @@ - - - - -provider-rand - - - - - - - - - - -

NAME

- -

provider-rand - The random number generation library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_rand_newctx(void *provctx, void *parent,
-                            const OSSL_DISPATCH *parent_calls);
-void OSSL_FUNC_rand_freectx(void *ctx);
-
-/* Random number generator functions: NIST */
-int OSSL_FUNC_rand_instantiate(void *ctx, unsigned int strength,
-                               int prediction_resistance,
-                               const unsigned char *pstr, size_t pstr_len,
-                               const OSSL_PARAM params[]);
-int OSSL_FUNC_rand_uninstantiate(void *ctx);
-int OSSL_FUNC_rand_generate(void *ctx, unsigned char *out, size_t outlen,
-                            unsigned int strength, int prediction_resistance,
-                            const unsigned char *addin, size_t addin_len);
-int OSSL_FUNC_rand_reseed(void *ctx, int prediction_resistance,
-                          const unsigned char *ent, size_t ent_len,
-                          const unsigned char *addin, size_t addin_len);
-
-/* Random number generator functions: additional */
-size_t OSSL_FUNC_rand_nonce(void *ctx, unsigned char *out, size_t outlen,
-                            int strength, size_t min_noncelen,
-                            size_t max_noncelen);
-size_t OSSL_FUNC_rand_get_seed(void *ctx, unsigned char **buffer,
-                               int entropy, size_t min_len, size_t max_len,
-                               int prediction_resistance,
-                               const unsigned char *adin, size_t adin_len);
-void OSSL_FUNC_rand_clear_seed(void *ctx, unsigned char *buffer, size_t b_len);
-int OSSL_FUNC_rand_verify_zeroization(void *ctx);
-
-/* Context Locking */
-int OSSL_FUNC_rand_enable_locking(void *ctx);
-int OSSL_FUNC_rand_lock(void *ctx);
-void OSSL_FUNC_rand_unlock(void *ctx);
-
-/* RAND parameter descriptors */
-const OSSL_PARAM *OSSL_FUNC_rand_gettable_params(void *provctx);
-const OSSL_PARAM *OSSL_FUNC_rand_gettable_ctx_params(void *ctx, void *provctx);
-const OSSL_PARAM *OSSL_FUNC_rand_settable_ctx_params(void *ctx, void *provctx);
-
-/* RAND parameters */
-int OSSL_FUNC_rand_get_params(OSSL_PARAM params[]);
-int OSSL_FUNC_rand_get_ctx_params(void *ctx, OSSL_PARAM params[]);
-int OSSL_FUNC_rand_set_ctx_params(void *ctx, const OSSL_PARAM params[]);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The RAND operation enables providers to implement random number generation algorithms and random number sources and make them available to applications via the API function EVP_RAND(3).

- -

Context Management Functions

- -

OSSL_FUNC_rand_newctx() should create and return a pointer to a provider side structure for holding context information during a rand operation. A pointer to this context will be passed back in a number of the other rand operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)). The parameter parent specifies another rand instance to be used for seeding purposes. If NULL and the specific instance supports it, the operating system will be used for seeding. The parameter parent_calls points to the dispatch table for parent. Thus, the parent need not be from the same provider as the new instance.

- -

OSSL_FUNC_rand_freectx() is passed a pointer to the provider side rand context in the mctx parameter. If it receives NULL as ctx value, it should not do anything other than return. This function should free any resources associated with that context.

- -

Random Number Generator Functions: NIST

- -

These functions correspond to those defined in NIST SP 800-90A and SP 800-90C.

- -

OSSL_FUNC_rand_instantiate() is used to instantiate the DRBG ctx at a requested security strength. In addition, prediction_resistance can be requested. Additional input addin of length addin_len bytes can optionally be provided. The parameters specified in params configure the DRBG and these should be processed before instantiation.

- -

OSSL_FUNC_rand_uninstantiate() is used to uninstantiate the DRBG ctx. After being uninstantiated, a DRBG is unable to produce output until it is instantiated anew.

- -

OSSL_FUNC_rand_generate() is used to generate random bytes from the DRBG ctx. It will generate outlen bytes placing them into the buffer pointed to by out. The generated bytes will meet the specified security strength and, if prediction_resistance is true, the bytes will be produced after reseeding from a live entropy source. Additional input addin of length addin_len bytes can optionally be provided.

- -

Random Number Generator Functions: Additional

- -

OSSL_FUNC_rand_nonce() is used to generate a nonce of the given strength with a length from min_noncelen to max_noncelen. If the output buffer out is NULL, the length of the nonce should be returned.

- -

OSSL_FUNC_rand_get_seed() is used by deterministic generators to obtain their seeding material from their parent. The seed bytes will meet the specified security level of entropy bits and there will be between min_len and max_len inclusive bytes in total. If prediction_resistance is true, the bytes will be produced from a live entropy source. Additional input addin of length addin_len bytes can optionally be provided. A pointer to the seed material is returned in *buffer and this must be freed by a later call to OSSL_FUNC_rand_clear_seed().

- -

OSSL_FUNC_rand_clear_seed() frees a seed buffer of length b_len bytes which was previously allocated by OSSL_FUNC_rand_get_seed().

- -

OSSL_FUNC_rand_verify_zeroization() is used to determine if the internal state of the DRBG is zero. This capability is mandated by NIST as part of the self tests, it is unlikely to be useful in other circumstances.

- -

Context Locking

- -

When DRBGs are used by multiple threads, there must be locking employed to ensure their proper operation. Because locking introduces an overhead, it is disabled by default.

- -

OSSL_FUNC_rand_enable_locking() allows locking to be turned on for a DRBG and all of its parent DRBGs. From this call onwards, the DRBG can be used in a thread safe manner.

- -

OSSL_FUNC_rand_lock() is used to lock a DRBG. Once locked, exclusive access is guaranteed.

- -

OSSL_FUNC_rand_unlock() is used to unlock a DRBG.

- -

Rand Parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by these functions.

- -

OSSL_FUNC_rand_get_params() gets details of parameter values associated with the provider algorithm and stores them in params.

- -

OSSL_FUNC_rand_set_ctx_params() sets rand parameters associated with the given provider side rand context ctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

OSSL_FUNC_rand_get_ctx_params() gets details of currently set parameter values associated with the given provider side rand context ctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_rand_gettable_params(), OSSL_FUNC_rand_gettable_ctx_params(), and OSSL_FUNC_rand_settable_ctx_params() all return constant OSSL_PARAM(3) arrays as descriptors of the parameters that OSSL_FUNC_rand_get_params(), OSSL_FUNC_rand_get_ctx_params(), and OSSL_FUNC_rand_set_ctx_params() can handle, respectively. OSSL_FUNC_rand_gettable_ctx_params() and OSSL_FUNC_rand_settable_ctx_params() will return the parameters associated with the provider side context ctx in its current state if it is not NULL. Otherwise, they return the parameters associated with the provider side algorithm provctx.

- -

Parameters currently recognised by built-in rands are as follows. Not all parameters are relevant to, or are understood by all rands:

- -
- -
"state" (OSSL_RAND_PARAM_STATE) <integer>
-
- -

Returns the state of the random number generator.

- -
-
"strength" (OSSL_RAND_PARAM_STRENGTH) <unsigned integer>
-
- -

Returns the bit strength of the random number generator.

- -
-
"fips-indicator" (OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This option is used by the OpenSSL FIPS provider and is not supported by all EVP_RAND sources.

- -
-
- -

For rands that are also deterministic random bit generators (DRBGs), these additional parameters are recognised. Not all parameters are relevant to, or are understood by all DRBG rands:

- -
- -
"reseed_requests" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -

Reads or set the number of generate requests before reseeding the associated RAND ctx.

- -
-
"reseed_time_interval" (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) <integer>
-
- -

Reads or set the number of elapsed seconds before reseeding the associated RAND ctx.

- -
-
"max_request" (OSSL_DRBG_PARAM_RESEED_REQUESTS) <unsigned integer>
-
- -

Specifies the maximum number of bytes that can be generated in a single call to OSSL_FUNC_rand_generate.

- -
-
"min_entropylen" (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) <unsigned integer>
-
- -
-
"max_entropylen" (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) <unsigned integer>
-
- -

Specify the minimum and maximum number of bytes of random material that can be used to seed the DRBG.

- -
-
"min_noncelen" (OSSL_DRBG_PARAM_MIN_NONCELEN) <unsigned integer>
-
- -
-
"max_noncelen" (OSSL_DRBG_PARAM_MAX_NONCELEN) <unsigned integer>
-
- -

Specify the minimum and maximum number of bytes of nonce that can be used to instantiate the DRBG.

- -
-
"max_perslen" (OSSL_DRBG_PARAM_MAX_PERSLEN) <unsigned integer>
-
- -
-
"max_adinlen" (OSSL_DRBG_PARAM_MAX_ADINLEN) <unsigned integer>
-
- -

Specify the minimum and maximum number of bytes of personalisation string that can be used with the DRBG.

- -
-
"reseed_counter" (OSSL_DRBG_PARAM_RESEED_COUNTER) <unsigned integer>
-
- -

Specifies the number of times the DRBG has been seeded or reseeded.

- -
-
"digest" (OSSL_DRBG_PARAM_DIGEST) <UTF8 string>
-
- -
-
"cipher" (OSSL_DRBG_PARAM_CIPHER) <UTF8 string>
-
- -
-
"mac" (OSSL_DRBG_PARAM_MAC) <UTF8 string>
-
- -

Sets the name of the underlying cipher, digest or MAC to be used. It must name a suitable algorithm for the DRBG that's being used.

- -
-
"properties" (OSSL_DRBG_PARAM_PROPERTIES) <UTF8 string>
-
- -

Sets the properties to be queried when trying to fetch an underlying algorithm. This must be given together with the algorithm naming parameter to be considered valid.

- -
-
- -

The OpenSSL FIPS provider also supports the following parameters:

- -
- -
"fips-indicator" (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling OSSL_FUNC_rand_generate(). It may return 0 if the "digest-check" is set to 0.

- -
-
"digest-check" (OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

If required this parameter should be set before the digest is set. The default value of 1 causes an error when the digest is set if the digest is not FIPS approved (e.g. truncated digests). Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

RETURN VALUES

- -

OSSL_FUNC_rand_newctx() should return the newly created provider side rand context, or NULL on failure.

- -

OSSL_FUNC_rand_gettable_params(), OSSL_FUNC_rand_gettable_ctx_params() and OSSL_FUNC_rand_settable_ctx_params() should return a constant OSSL_PARAM(3) array, or NULL if none is offered.

- -

OSSL_FUNC_rand_nonce() returns the size of the generated nonce, or 0 on error.

- -

OSSL_FUNC_rand_get_seed() returns the size of the generated seed, or 0 on error.

- -

All of the remaining functions should return 1 for success or 0 on error.

- -

NOTES

- -

The RAND life-cycle is described in life_cycle-rand(7). Providers should ensure that the various transitions listed there are supported. At some point the EVP layer will begin enforcing the listed transitions.

- -

SEE ALSO

- -

provider(7), RAND(7), EVP_RAND(7), life_cycle-rand(7), EVP_RAND(3)

- -

HISTORY

- -

The provider RAND interface was introduced in OpenSSL 3.0. The Rand Parameters "fips-indicator" and "digest-check" were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-signature.html b/openssl-install/share/doc/openssl/html/man7/provider-signature.html deleted file mode 100644 index 6d0df914..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-signature.html +++ /dev/null @@ -1,466 +0,0 @@ - - - - -provider-signature - - - - - - - - - - -

NAME

- -

provider-signature - The signature library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-#include <openssl/core_names.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-/* Context management */
-void *OSSL_FUNC_signature_newctx(void *provctx, const char *propq);
-void OSSL_FUNC_signature_freectx(void *ctx);
-void *OSSL_FUNC_signature_dupctx(void *ctx);
-
-/* Get the key types that a signature algorithm supports */
-const char **OSSL_FUNC_signature_query_key_types(void);
-
-/* Signing */
-int OSSL_FUNC_signature_sign_init(void *ctx, void *provkey,
-                                  const OSSL_PARAM params[]);
-int OSSL_FUNC_signature_sign(void *ctx, unsigned char *sig, size_t *siglen,
-                             size_t sigsize, const unsigned char *tbs, size_t tbslen);
-int OSSL_FUNC_signature_sign_message_init(void *ctx, void *provkey,
-                                          const OSSL_PARAM params[]);
-int OSSL_FUNC_signature_sign_message_update(void *ctx, const unsigned char *in,
-                                            size_t inlen);
-int OSSL_FUNC_signature_sign_message_final(void *ctx, unsigned char *sig,
-                                           size_t *siglen, size_t sigsize);
-
-/* Verifying */
-int OSSL_FUNC_signature_verify_init(void *ctx, void *provkey,
-                                    const OSSL_PARAM params[]);
-int OSSL_FUNC_signature_verify(void *ctx, const unsigned char *sig, size_t siglen,
-                               const unsigned char *tbs, size_t tbslen);
-int OSSL_FUNC_signature_verify_message_init(void *ctx, void *provkey,
-                                            const OSSL_PARAM params[]);
-int OSSL_FUNC_signature_verify_message_update(void *ctx, const unsigned char *in,
-                                              size_t inlen);
-/*
- * OSSL_FUNC_signature_verify_message_final requires that the signature to be
- * verified is specified via a "signature" OSSL_PARAM, which is given with a
- * previous call of OSSL_FUNC_signature_set_ctx_params().
- */
-int OSSL_FUNC_signature_verify_message_final(void *ctx);
-
-/* Verify Recover */
-int OSSL_FUNC_signature_verify_recover_init(void *ctx, void *provkey,
-                                            const OSSL_PARAM params[]);
-int OSSL_FUNC_signature_verify_recover(void *ctx, unsigned char *rout,
-                                       size_t *routlen, size_t routsize,
-                                       const unsigned char *sig, size_t siglen);
-
-/* Digest Sign */
-int OSSL_FUNC_signature_digest_sign_init(void *ctx, const char *mdname,
-                                         void *provkey,
-                                         const OSSL_PARAM params[]);
-int OSSL_FUNC_signature_digest_sign_update(void *ctx, const unsigned char *data,
-                                    size_t datalen);
-int OSSL_FUNC_signature_digest_sign_final(void *ctx, unsigned char *sig,
-                                          size_t *siglen, size_t sigsize);
-int OSSL_FUNC_signature_digest_sign(void *ctx,
-                             unsigned char *sig, size_t *siglen,
-                             size_t sigsize, const unsigned char *tbs,
-                             size_t tbslen);
-
-/* Digest Verify */
-int OSSL_FUNC_signature_digest_verify_init(void *ctx, const char *mdname,
-                                           void *provkey,
-                                           const OSSL_PARAM params[]);
-int OSSL_FUNC_signature_digest_verify_update(void *ctx,
-                                             const unsigned char *data,
-                                             size_t datalen);
-int OSSL_FUNC_signature_digest_verify_final(void *ctx, const unsigned char *sig,
-                                     size_t siglen);
-int OSSL_FUNC_signature_digest_verify(void *ctx, const unsigned char *sig,
-                               size_t siglen, const unsigned char *tbs,
-                               size_t tbslen);
-
-/* Signature parameters */
-int OSSL_FUNC_signature_get_ctx_params(void *ctx, OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_signature_gettable_ctx_params(void *ctx,
-                                                          void *provctx);
-int OSSL_FUNC_signature_set_ctx_params(void *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM *OSSL_FUNC_signature_settable_ctx_params(void *ctx,
-                                                          void *provctx);
-/* MD parameters */
-int OSSL_FUNC_signature_get_ctx_md_params(void *ctx, OSSL_PARAM params[]);
-const OSSL_PARAM * OSSL_FUNC_signature_gettable_ctx_md_params(void *ctx);
-int OSSL_FUNC_signature_set_ctx_md_params(void *ctx, const OSSL_PARAM params[]);
-const OSSL_PARAM * OSSL_FUNC_signature_settable_ctx_md_params(void *ctx);
- -

DESCRIPTION

- -

This documentation is primarily aimed at provider authors. See provider(7) for further information.

- -

The signature (OSSL_OP_SIGNATURE) operation enables providers to implement signature algorithms and make them available to applications via the API functions EVP_PKEY_sign(3), EVP_PKEY_verify(3), and EVP_PKEY_verify_recover(3) (as well as other related functions).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from an OSSL_DISPATCH(3) element named OSSL_FUNC_{name}. For example, the "function" OSSL_FUNC_signature_newctx() has these:

- -
typedef void *(OSSL_FUNC_signature_newctx_fn)(void *provctx, const char *propq);
-static ossl_inline OSSL_FUNC_signature_newctx_fn
-    OSSL_FUNC_signature_newctx(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_signature_newctx                 OSSL_FUNC_SIGNATURE_NEWCTX
-OSSL_FUNC_signature_freectx                OSSL_FUNC_SIGNATURE_FREECTX
-OSSL_FUNC_signature_dupctx                 OSSL_FUNC_SIGNATURE_DUPCTX
-
-OSSL_FUNC_signature_query_key_types        OSSL_FUNC_SIGNATURE_QUERY_KEY_TYPES
-
-OSSL_FUNC_signature_sign_init              OSSL_FUNC_SIGNATURE_SIGN_INIT
-OSSL_FUNC_signature_sign                   OSSL_FUNC_SIGNATURE_SIGN
-OSSL_FUNC_signature_sign_message_init      OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_INIT
-OSSL_FUNC_signature_sign_message_update    OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_UPDATE
-OSSL_FUNC_signature_sign_message_final     OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_FINAL
-
-OSSL_FUNC_signature_verify_init            OSSL_FUNC_SIGNATURE_VERIFY_INIT
-OSSL_FUNC_signature_verify                 OSSL_FUNC_SIGNATURE_VERIFY
-OSSL_FUNC_signature_verify_message_init    OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_INIT
-OSSL_FUNC_signature_verify_message_update  OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_UPDATE
-OSSL_FUNC_signature_verify_message_final   OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_FINAL
-
-OSSL_FUNC_signature_verify_recover_init    OSSL_FUNC_SIGNATURE_VERIFY_RECOVER_INIT
-OSSL_FUNC_signature_verify_recover         OSSL_FUNC_SIGNATURE_VERIFY_RECOVER
-
-OSSL_FUNC_signature_digest_sign_init       OSSL_FUNC_SIGNATURE_DIGEST_SIGN_INIT
-OSSL_FUNC_signature_digest_sign_update     OSSL_FUNC_SIGNATURE_DIGEST_SIGN_UPDATE
-OSSL_FUNC_signature_digest_sign_final      OSSL_FUNC_SIGNATURE_DIGEST_SIGN_FINAL
-OSSL_FUNC_signature_digest_sign            OSSL_FUNC_SIGNATURE_DIGEST_SIGN
-
-OSSL_FUNC_signature_digest_verify_init     OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_INIT
-OSSL_FUNC_signature_digest_verify_update   OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_UPDATE
-OSSL_FUNC_signature_digest_verify_final    OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_FINAL
-OSSL_FUNC_signature_digest_verify          OSSL_FUNC_SIGNATURE_DIGEST_VERIFY
-
-OSSL_FUNC_signature_get_ctx_params         OSSL_FUNC_SIGNATURE_GET_CTX_PARAMS
-OSSL_FUNC_signature_gettable_ctx_params    OSSL_FUNC_SIGNATURE_GETTABLE_CTX_PARAMS
-OSSL_FUNC_signature_set_ctx_params         OSSL_FUNC_SIGNATURE_SET_CTX_PARAMS
-OSSL_FUNC_signature_settable_ctx_params    OSSL_FUNC_SIGNATURE_SETTABLE_CTX_PARAMS
-
-OSSL_FUNC_signature_get_ctx_md_params      OSSL_FUNC_SIGNATURE_GET_CTX_MD_PARAMS
-OSSL_FUNC_signature_gettable_ctx_md_params OSSL_FUNC_SIGNATURE_GETTABLE_CTX_MD_PARAMS
-OSSL_FUNC_signature_set_ctx_md_params      OSSL_FUNC_SIGNATURE_SET_CTX_MD_PARAMS
-OSSL_FUNC_signature_settable_ctx_md_params OSSL_FUNC_SIGNATURE_SETTABLE_CTX_MD_PARAMS
- -

A signature algorithm implementation may not implement all of these functions. In order to be a consistent set of functions we must have at least a set of context functions (OSSL_FUNC_signature_newctx and OSSL_FUNC_signature_freectx) as well as a set of "signature" functions, i.e. at least one of:

- -
- -
OSSL_FUNC_signature_sign_init and OSSL_FUNC_signature_sign
-
- -
-
OSSL_FUNC_signature_sign_message_init and OSSL_FUNC_signature_sign
-
- -
-
OSSL_FUNC_signature_sign_message_init, OSSL_FUNC_signature_sign_message_update and OSSL_FUNC_signature_sign_message_final
-
- -
-
OSSL_FUNC_signature_verify_init and OSSL_FUNC_signature_verify
-
- -
-
OSSL_FUNC_signature_verify_message_init and OSSL_FUNC_signature_verify
-
- -
-
OSSL_FUNC_signature_verify_message_init, OSSL_FUNC_signature_verify_message_update and OSSL_FUNC_signature_verify_message_final
-
- -
-
OSSL_FUNC_signature_verify_recover_init and OSSL_FUNC_signature_verify_recover
-
- -
-
OSSL_FUNC_signature_digest_sign_init, OSSL_FUNC_signature_digest_sign_update and OSSL_FUNC_signature_digest_sign_final
-
- -
-
OSSL_FUNC_signature_digest_verify_init, OSSL_FUNC_signature_digest_verify_update and OSSL_FUNC_signature_digest_verify_final
-
- -
-
OSSL_FUNC_signature_digest_sign_init and OSSL_FUNC_signature_digest_sign
-
- -
-
OSSL_FUNC_signature_digest_verify_init and OSSL_FUNC_signature_digest_verify
-
- -
-
- -

OSSL_FUNC_signature_set_ctx_params and OSSL_FUNC_signature_settable_ctx_params are optional, but if one of them is present then the other one must also be present. The same applies to OSSL_FUNC_signature_get_ctx_params and OSSL_FUNC_signature_gettable_ctx_params, as well as the "md_params" functions. The OSSL_FUNC_signature_dupctx function is optional.

- -

A signature algorithm must also implement some mechanism for generating, loading or importing keys via the key management (OSSL_OP_KEYMGMT) operation. See provider-keymgmt(7) for further details.

- -

Context Management Functions

- -

OSSL_FUNC_signature_newctx() should create and return a pointer to a provider side structure for holding context information during a signature operation. A pointer to this context will be passed back in a number of the other signature operation function calls. The parameter provctx is the provider context generated during provider initialisation (see provider(7)). The propq parameter is a property query string that may be (optionally) used by the provider during any "fetches" that it may perform (if it performs any).

- -

OSSL_FUNC_signature_freectx() is passed a pointer to the provider side signature context in the ctx parameter. This function should free any resources associated with that context.

- -

OSSL_FUNC_signature_dupctx() should duplicate the provider side signature context in the ctx parameter and return the duplicate copy.

- -

Signing Functions

- -

OSSL_FUNC_signature_sign_init() initialises a context for signing given a provider side signature context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_signature_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)).

- -

OSSL_FUNC_signature_sign() performs the actual signing itself. A previously initialised signature context is passed in the ctx parameter. The data to be signed is pointed to be the tbs parameter which is tbslen bytes long. Unless sig is NULL, the signature should be written to the location pointed to by the sig parameter and it should not exceed sigsize bytes in length. The length of the signature should be written to *siglen. If sig is NULL then the maximum length of the signature should be written to *siglen.

- -

Message Signing Functions

- -

These functions are suitable for providers that implement algorithms that accumulate a full message and sign the result of that accumulation, such as RSA-SHA256.

- -

OSSL_FUNC_signature_sign_message_init() initialises a context for signing a message given a provider side signature context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_signature_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)).

- -

OSSL_FUNC_signature_sign_message_update() gathers the data pointed at by in, which is inlen bytes long.

- -

OSSL_FUNC_signature_sign_message_final() performs the actual signing on the data that was gathered with OSSL_FUNC_signature_sign_message_update().

- -

OSSL_FUNC_signature_sign() can be used for one-shot signature calls. In that case, tbs is expected to be the whole message to be signed, tbslen bytes long.

- -

For both OSSL_FUNC_signature_sign_message_final() and OSSL_FUNC_signature_sign(), if sig is not NULL, the signature should be written to the location pointed to by sig, and it should not exceed sigsize bytes in length. The length of the signature should be written to *siglen. If sig is NULL then the maximum length of the signature should be written to *siglen.

- -

Verify Functions

- -

OSSL_FUNC_signature_verify_init() initialises a context for verifying a signature given a provider side signature context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_signature_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)).

- -

OSSL_FUNC_signature_verify() performs the actual verification itself. A previously initialised signature context is passed in the ctx parameter. The data that the signature covers is pointed to be the tbs parameter which is tbslen bytes long. The signature is pointed to by the sig parameter which is siglen bytes long.

- -

Message Verify Functions

- -

These functions are suitable for providers that implement algorithms that accumulate a full message and verify a signature on the result of that accumulation, such as RSA-SHA256.

- -

OSSL_FUNC_signature_verify_message_init() initialises a context for verifying a signature on a message given a provider side signature context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_signature_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)).

- -

OSSL_FUNC_signature_verify_message_update() gathers the data pointed at by in, which is inlen bytes long.

- -

OSSL_FUNC_signature_verify_message_final() performs the actual verification on the data that was gathered with OSSL_FUNC_signature_verify_message_update(). The signature itself must have been passed through the "signature" (OSSL_SIGNATURE_PARAM_SIGNATURE) Signature parameter before this function is called.

- -

OSSL_FUNC_signature_verify() can be used for one-shot verification calls. In that case, tbs is expected to be the whole message to be verified on, tbslen bytes long.

- -

Verify Recover Functions

- -

OSSL_FUNC_signature_verify_recover_init() initialises a context for recovering the signed data given a provider side signature context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_signature_set_ctx_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)).

- -

OSSL_FUNC_signature_verify_recover() performs the actual verify recover itself. A previously initialised signature context is passed in the ctx parameter. The signature is pointed to by the sig parameter which is siglen bytes long. Unless rout is NULL, the recovered data should be written to the location pointed to by rout which should not exceed routsize bytes in length. The length of the recovered data should be written to *routlen. If rout is NULL then the maximum size of the output buffer is written to the routlen parameter.

- -

Digest Sign Functions

- -

OSSL_FUNC_signature_digest_sign_init() initialises a context for signing given a provider side signature context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to using OSSL_FUNC_signature_set_ctx_params() and OSSL_FUNC_signature_set_ctx_md_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)). The name of the digest to be used will be in the mdname parameter.

- -

OSSL_FUNC_signature_digest_sign_update() provides data to be signed in the data parameter which should be of length datalen. A previously initialised signature context is passed in the ctx parameter. This function may be called multiple times to cumulatively add data to be signed.

- -

OSSL_FUNC_signature_digest_sign_final() finalises a signature operation previously started through OSSL_FUNC_signature_digest_sign_init() and OSSL_FUNC_signature_digest_sign_update() calls. Once finalised no more data will be added through OSSL_FUNC_signature_digest_sign_update(). A previously initialised signature context is passed in the ctx parameter. Unless sig is NULL, the signature should be written to the location pointed to by the sig parameter and it should not exceed sigsize bytes in length. The length of the signature should be written to *siglen. If sig is NULL then the maximum length of the signature should be written to *siglen.

- -

OSSL_FUNC_signature_digest_sign() implements a "one shot" digest sign operation previously started through OSSL_FUNC_signature_digest_sign_init(). A previously initialised signature context is passed in the ctx parameter. The data to be signed is in tbs which should be tbslen bytes long. Unless sig is NULL, the signature should be written to the location pointed to by the sig parameter and it should not exceed sigsize bytes in length. The length of the signature should be written to *siglen. If sig is NULL then the maximum length of the signature should be written to *siglen.

- -

Digest Verify Functions

- -

OSSL_FUNC_signature_digest_verify_init() initialises a context for verifying given a provider side verification context in the ctx parameter, and a pointer to a provider key object in the provkey parameter. The params, if not NULL, should be set on the context in a manner similar to OSSL_FUNC_signature_set_ctx_params() and OSSL_FUNC_signature_set_ctx_md_params(). The key object should have been previously generated, loaded or imported into the provider using the key management (OSSL_OP_KEYMGMT) operation (see provider-keymgmt(7)). The name of the digest to be used will be in the mdname parameter.

- -

OSSL_FUNC_signature_digest_verify_update() provides data to be verified in the data parameter which should be of length datalen. A previously initialised verification context is passed in the ctx parameter. This function may be called multiple times to cumulatively add data to be verified.

- -

OSSL_FUNC_signature_digest_verify_final() finalises a verification operation previously started through OSSL_FUNC_signature_digest_verify_init() and OSSL_FUNC_signature_digest_verify_update() calls. Once finalised no more data will be added through OSSL_FUNC_signature_digest_verify_update(). A previously initialised verification context is passed in the ctx parameter. The signature to be verified is in sig which is siglen bytes long.

- -

OSSL_FUNC_signature_digest_verify() implements a "one shot" digest verify operation previously started through OSSL_FUNC_signature_digest_verify_init(). A previously initialised verification context is passed in the ctx parameter. The data to be verified is in tbs which should be tbslen bytes long. The signature to be verified is in sig which is siglen bytes long.

- -

Signature parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by the OSSL_FUNC_signature_get_ctx_params() and OSSL_FUNC_signature_set_ctx_params() functions.

- -

OSSL_FUNC_signature_get_ctx_params() gets signature parameters associated with the given provider side signature context ctx and stored them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_signature_set_ctx_params() sets the signature parameters associated with the given provider side signature context ctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

Common parameters currently recognised by built-in signature algorithms are as follows.

- -
- -
"digest" (OSSL_SIGNATURE_PARAM_DIGEST) <UTF8 string>
-
- -

Get or sets the name of the digest algorithm used for the input to the signature functions. It is required in order to calculate the "algorithm-id".

- -
-
"properties" (OSSL_SIGNATURE_PARAM_PROPERTIES) <UTF8 string>
-
- -

Sets the name of the property query associated with the "digest" algorithm. NULL is used if this optional value is not set.

- -
-
- -

Note that when implementing a signature algorithm that gathers a full message, like RSA-SHA256, the "digest" and "properties" parameters should not be used. For such implementations, it's acceptable to simply ignore them if they happen to be passed in a call to OSSL_FUNC_signature_set_ctx_params(). For such implementations, however, it is not acceptable to have them in the OSSL_PARAM array that's returned by OSSL_FUNC_signature_settable_ctx_params().

- -
- -
"signature" (OSSL_SIGNATURE_PARAM_SIGNATURE) <octet string>
-
- -

Sets the signature to verify, specifically when OSSL_FUNC_signature_verify_message_final() is used.

- -
-
"digest-size" (OSSL_SIGNATURE_PARAM_DIGEST_SIZE) <unsigned integer>
-
- -

Gets or sets the output size of the digest algorithm used for the input to the signature functions. The length of the "digest-size" parameter should not exceed that of a size_t.

- -
-
"algorithm-id" (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) <octet string>
-
- -

Gets the DER-encoded AlgorithmIdentifier for the signature operation. This typically corresponds to the combination of a digest algorithm with a purely asymmetric signature algorithm, such as SHA256WithECDSA.

- -

The ASN1_item_sign_ctx(3) relies on this operation and is used by many other functions signing ASN.1 structures such as X.509 certificates, certificate requests, and CRLs, as well as OCSP, CMP, and CMS messages.

- -
-
"nonce-type" (OSSL_SIGNATURE_PARAM_NONCE_TYPE) <unsigned integer>
-
- -

Set this to 1 to use deterministic digital signature generation with ECDSA or DSA, as defined in RFC 6979 (see Section 3.2 "Generation of k"). In this case, the "digest" parameter must be explicitly set (otherwise, deterministic nonce generation will fail). Before using deterministic digital signature generation, please read RFC 6979 Section 4 "Security Considerations". The default value for "nonce-type" is 0 and results in a random value being used for the nonce k as defined in FIPS 186-4 Section 6.3 "Secret Number Generation".

- -

The FIPS provider does not support deterministic digital signature generation.

- -
-
"kat" (OSSL_SIGNATURE_PARAM_KAT) <unsigned integer>
-
- -

Sets a flag to modify the sign operation to return an error if the initial calculated signature is invalid. In the normal mode of operation - new random values are chosen until the signature operation succeeds. By default it retries until a signature is calculated. Setting the value to 0 causes the sign operation to retry, otherwise the sign operation is only tried once and returns whether or not it was successful. Known answer tests can be performed if the random generator is overridden to supply known values that either pass or fail.

- -
-
- -

The following parameters are used by the OpenSSL FIPS provider:

- -
- -
"fips-indicator" (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) <integer>
-
- -

A getter that returns 1 if the operation is FIPS approved, or 0 otherwise. This may be used after calling either the sign or verify final functions. It may return 0 if either the "digest-check", "key-check", or "sign-check" are set to 0.

- -
-
"verify-message" (OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE <integer>
-
- -

A getter that returns 1 if a signature verification operation acted on a raw message, or 0 if it verified a predigested message. A value of 0 indicates likely non-approved usage of the FIPS provider. This flag is set when any signature verification initialisation function is called. It is also set to 1 when any signing operation is performed to signify compliance. See FIPS 140-3 IG 2.4.B for further information.

- -
-
"key-check" (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) <integer>
-
- -

If required this parameter should be set early via an init function (e.g. OSSL_FUNC_signature_sign_init() or OSSL_FUNC_signature_verify_init()). The default value of 1 causes an error during the init if the key is not FIPS approved (e.g. The key has a security strength of less than 112 bits). Setting this to 0 will ignore the error and set the approved "indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"digest-check" (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) <integer>
-
- -

If required this parameter should be set before the signature digest is set. The default value of 1 causes an error when the digest is set if the digest is not FIPS approved (e.g. SHA1 is used for signing). Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"sign-check" (OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK) <integer>
-
- -

If required this parameter should be set early via an init function. The default value of 1 causes an error when a signing algorithm is used. (This is triggered by deprecated signing algorithms). Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
"sign-x931-pad-check" (OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK) <integer>
-
- -

If required this parameter should be set before the padding mode is set. The default value of 1 causes an error if the padding mode is set to X9.31 padding for a RSA signing operation. Setting this to 0 will ignore the error and set the approved "fips-indicator" to 0. This option breaks FIPS compliance if it causes the approved "fips-indicator" to return 0.

- -
-
- -

OSSL_FUNC_signature_gettable_ctx_params() and OSSL_FUNC_signature_settable_ctx_params() get a constant OSSL_PARAM(3) array that describes the gettable and settable parameters, i.e. parameters that can be used with OSSL_FUNC_signature_get_ctx_params() and OSSL_FUNC_signature_set_ctx_params() respectively.

- -

MD parameters

- -

See OSSL_PARAM(3) for further details on the parameters structure used by the OSSL_FUNC_signature_get_md_ctx_params() and OSSL_FUNC_signature_set_md_ctx_params() functions.

- -

OSSL_FUNC_signature_get_md_ctx_params() gets digest parameters associated with the given provider side digest signature context ctx and stores them in params. Passing NULL for params should return true.

- -

OSSL_FUNC_signature_set_ms_ctx_params() sets the digest parameters associated with the given provider side digest signature context ctx to params. Any parameter settings are additional to any that were previously set. Passing NULL for params should return true.

- -

Parameters currently recognised by built-in signature algorithms are the same as those for built-in digest algorithms. See "Digest Parameters" in provider-digest(7) for further information.

- -

OSSL_FUNC_signature_gettable_md_ctx_params() and OSSL_FUNC_signature_settable_md_ctx_params() get a constant OSSL_PARAM(3) array that describes the gettable and settable digest parameters, i.e. parameters that can be used with OSSL_FUNC_signature_get_md_ctx_params() and OSSL_FUNC_signature_set_md_ctx_params() respectively.

- -

RETURN VALUES

- -

OSSL_FUNC_signature_newctx() and OSSL_FUNC_signature_dupctx() should return the newly created provider side signature context, or NULL on failure.

- -

OSSL_FUNC_signature_gettable_ctx_params(), OSSL_FUNC_signature_settable_ctx_params(), OSSL_FUNC_signature_gettable_md_ctx_params() and OSSL_FUNC_signature_settable_md_ctx_params(), return the gettable or settable parameters in a constant OSSL_PARAM(3) array.

- -

All other functions should return 1 for success or 0 on error.

- -

SEE ALSO

- -

provider(7), ASN1_item_sign_ctx(3)

- -

HISTORY

- -

The provider SIGNATURE interface was introduced in OpenSSL 3.0. The Signature Parameters "fips-indicator", "key-check" and "digest-check" were added in OpenSSL 3.4.

- -

COPYRIGHT

- -

Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider-storemgmt.html b/openssl-install/share/doc/openssl/html/man7/provider-storemgmt.html deleted file mode 100644 index ded56b7d..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider-storemgmt.html +++ /dev/null @@ -1,205 +0,0 @@ - - - - -provider-storemgmt - - - - - - - - - - -

NAME

- -

provider-storemgmt - The OSSL_STORE library <-> provider functions

- -

SYNOPSIS

- -
#include <openssl/core_dispatch.h>
-
-/*
- * None of these are actual functions, but are displayed like this for
- * the function signatures for functions that are offered as function
- * pointers in OSSL_DISPATCH arrays.
- */
-
-void *OSSL_FUNC_store_open(void *provctx, const char *uri);
-void *OSSL_FUNC_store_attach(void *provctx, OSSL_CORE_BIO *bio);
-const OSSL_PARAM *store_settable_ctx_params(void *provctx);
-int OSSL_FUNC_store_set_ctx_params(void *loaderctx, const OSSL_PARAM[]);
-int OSSL_FUNC_store_load(void *loaderctx,
-                         OSSL_CALLBACK *object_cb, void *object_cbarg,
-                         OSSL_PASSPHRASE_CALLBACK *pw_cb, void *pw_cbarg);
-int OSSL_FUNC_store_eof(void *loaderctx);
-int OSSL_FUNC_store_close(void *loaderctx);
-
-int OSSL_FUNC_store_export_object
-    (void *loaderctx, const void *objref, size_t objref_sz,
-     OSSL_CALLBACK *export_cb, void *export_cbarg);
-void *OSSL_FUNC_store_open_ex(void *provctx, const char *uri,
-                              const OSSL_PARAM params[],
-                              OSSL_PASSPHRASE_CALLBACK *pw_cb,
-                              void *pw_cbarg);
-
-int OSSL_FUNC_store_delete(void *provctx, const char *uri,
-                   const OSSL_PARAM params[],
-                   OSSL_PASSPHRASE_CALLBACK *pw_cb, void *pw_cbarg);
- -

DESCRIPTION

- -

The STORE operation is the provider side of the ossl_store(7) API.

- -

The primary responsibility of the STORE operation is to load all sorts of objects from a container indicated by URI. These objects are given to the OpenSSL library in provider-native object abstraction form (see provider-object(7)). The OpenSSL library is then responsible for passing on that abstraction to suitable provided functions.

- -

Examples of functions that the OpenSSL library can pass the abstraction to include OSSL_FUNC_keymgmt_load() (provider-keymgmt(7)), OSSL_FUNC_store_export_object() (which exports the object in parameterized form).

- -

All "functions" mentioned here are passed as function pointers between libcrypto and the provider in OSSL_DISPATCH(3) arrays via OSSL_ALGORITHM(3) arrays that are returned by the provider's provider_query_operation() function (see "Provider Functions" in provider-base(7)).

- -

All these "functions" have a corresponding function type definition named OSSL_FUNC_{name}_fn, and a helper function to retrieve the function pointer from a OSSL_DISPATCH(3) element named OSSL_get_{name}. For example, the "function" OSSL_FUNC_store_attach() has these:

- -
typedef void *(OSSL_FUNC_store_attach_fn)(void *provctx,
-                                          OSSL_CORE_BIO * bio);
-static ossl_inline OSSL_FUNC_store_attach_fn
-    OSSL_FUNC_store_attach(const OSSL_DISPATCH *opf);
- -

OSSL_DISPATCH(3) arrays are indexed by numbers that are provided as macros in openssl-core_dispatch.h(7), as follows:

- -
OSSL_FUNC_store_open                 OSSL_FUNC_STORE_OPEN
-OSSL_FUNC_store_attach               OSSL_FUNC_STORE_ATTACH
-OSSL_FUNC_store_settable_ctx_params  OSSL_FUNC_STORE_SETTABLE_CTX_PARAMS
-OSSL_FUNC_store_set_ctx_params       OSSL_FUNC_STORE_SET_CTX_PARAMS
-OSSL_FUNC_store_load                 OSSL_FUNC_STORE_LOAD
-OSSL_FUNC_store_eof                  OSSL_FUNC_STORE_EOF
-OSSL_FUNC_store_close                OSSL_FUNC_STORE_CLOSE
-OSSL_FUNC_store_export_object        OSSL_FUNC_STORE_EXPORT_OBJECT
-OSSL_FUNC_store_delete               OSSL_FUNC_STORE_DELETE
-OSSL_FUNC_store_open_ex              OSSL_FUNC_STORE_OPEN_EX
- -

Functions

- -

OSSL_FUNC_store_open() should create a provider side context with data based on the input uri. The implementation is entirely responsible for the interpretation of the URI.

- -

OSSL_FUNC_store_attach() should create a provider side context with the core BIO bio attached. This is an alternative to using a URI to find storage, supporting OSSL_STORE_attach(3).

- -

OSSL_FUNC_store_settable_ctx_params() should return a constant array of descriptor OSSL_PARAM(3), for parameters that OSSL_FUNC_store_set_ctx_params() can handle.

- -

OSSL_FUNC_store_set_ctx_params() should set additional parameters, such as what kind of data to expect, search criteria, and so on. More on those below, in "Load Parameters". Whether unrecognised parameters are an error or simply ignored is at the implementation's discretion. Passing NULL for params should return true.

- -

OSSL_FUNC_store_load() loads the next object from the URI opened by OSSL_FUNC_store_open(), creates an object abstraction for it (see provider-object(7)), and calls object_cb with it as well as object_cbarg. object_cb will then interpret the object abstraction and do what it can to wrap it or decode it into an OpenSSL structure. In case a passphrase needs to be prompted to unlock an object, pw_cb should be called.

- -

OSSL_FUNC_store_eof() indicates if the end of the set of objects from the URI has been reached. When that happens, there's no point trying to do any further loading.

- -

OSSL_FUNC_store_close() frees the provider side context ctx.

- -

When a provider-native object is created by a store manager it would be unsuitable for direct use with a foreign provider. The export function allows for exporting the object to that foreign provider if the foreign provider supports the type of the object and provides an import function.

- -

OSSL_FUNC_store_export_object() should export the object of size objref_sz referenced by objref as an OSSL_PARAM(3) array and pass that to the export_cb as well as the given export_cbarg.

- -

OSSL_FUNC_store_delete() deletes the object identified by the uri. The implementation is entirely responsible for the interpretation of the URI. In case a passphrase needs to be prompted to remove an object, pw_cb should be called.

- -

OSSL_FUNC_store_open_ex() is an extended variant of OSSL_FUNC_store_open(). If the provider does not implement this function the code internally falls back to use the original OSSL_FUNC_store_open(). This variant additionally accepts an OSSL_PARAM(3) object and a pw_cb callback that can be used to request a passphrase in cases where the whole store needs to be unlocked before performing any load operation.

- -

Load Parameters

- -
- -
"expect" (OSSL_STORE_PARAM_EXPECT) <integer>
-
- -

Is a hint of what type of data the OpenSSL library expects to get. This is only useful for optimization, as the library will check that the object types match the expectation too.

- -

The number that can be given through this parameter is found in <openssl/store.h>, with the macros having names starting with OSSL_STORE_INFO_. These are further described in "SUPPORTED OBJECTS" in OSSL_STORE_INFO(3).

- -
-
"subject" (OSSL_STORE_PARAM_SUBJECT) <octet string>
-
- -

Indicates that the caller wants to search for an object with the given subject associated. This can be used to select specific certificates by subject.

- -

The contents of the octet string is expected to be in DER form.

- -
-
"issuer" (OSSL_STORE_PARAM_ISSUER) <octet string>
-
- -

Indicates that the caller wants to search for an object with the given issuer associated. This can be used to select specific certificates by issuer.

- -

The contents of the octet string is expected to be in DER form.

- -
-
"serial" (OSSL_STORE_PARAM_SERIAL) <integer>
-
- -

Indicates that the caller wants to search for an object with the given serial number associated.

- -
-
"digest" (OSSL_STORE_PARAM_DIGEST) <UTF8 string>
-
- -
-
"fingerprint" (OSSL_STORE_PARAM_FINGERPRINT) <octet string>
-
- -

Indicates that the caller wants to search for an object with the given fingerprint, computed with the given digest.

- -
-
"alias" (OSSL_STORE_PARAM_ALIAS) <UTF8 string>
-
- -

Indicates that the caller wants to search for an object with the given alias (some call it a "friendly name").

- -
-
"properties" (OSSL_STORE_PARAM_PROPERTIES) <utf8 string>
-
- -

Property string to use when querying for algorithms such as the OSSL_DECODER decoder implementations.

- -
-
"input-type" (OSSL_STORE_PARAM_INPUT_TYPE) <utf8 string>
-
- -

Type of the input format as a hint to use when decoding the objects in the store.

- -
-
- -

Several of these search criteria may be combined. For example, to search for a certificate by issuer+serial, both the "issuer" and the "serial" parameters will be given.

- -

SEE ALSO

- -

provider(7)

- -

HISTORY

- -

The STORE interface was introduced in OpenSSL 3.0.

- -

OSSL_FUNC_store_delete() callback was added in OpenSSL 3.2

- -

COPYRIGHT

- -

Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/provider.html b/openssl-install/share/doc/openssl/html/man7/provider.html deleted file mode 100644 index 2806439a..00000000 --- a/openssl-install/share/doc/openssl/html/man7/provider.html +++ /dev/null @@ -1,229 +0,0 @@ - - - - -provider - - - - - - - - - - -

NAME

- -

provider - OpenSSL operation implementation providers

- -

SYNOPSIS

- -

#include <openssl/provider.h>

- -

DESCRIPTION

- -

General

- -

This page contains information useful to provider authors.

- -

A provider, in OpenSSL terms, is a unit of code that provides one or more implementations for various operations for diverse algorithms that one might want to perform.

- -

An operation is something one wants to do, such as encryption and decryption, key derivation, MAC calculation, signing and verification, etc.

- -

An algorithm is a named method to perform an operation. Very often, the algorithms revolve around cryptographic operations, but may also revolve around other types of operation, such as managing certain types of objects.

- -

See crypto(7) for further details.

- -

Provider

- -

A provider offers an initialization function, as a set of base functions in the form of an OSSL_DISPATCH(3) array, and by extension, a set of OSSL_ALGORITHM(3)s (see openssl-core.h(7)). It may be a dynamically loadable module, or may be built-in, in OpenSSL libraries or in the application. If it's a dynamically loadable module, the initialization function must be named OSSL_provider_init and must be exported. If it's built-in, the initialization function may have any name.

- -

The initialization function must have the following signature:

- -
int NAME(const OSSL_CORE_HANDLE *handle,
-         const OSSL_DISPATCH *in, const OSSL_DISPATCH **out,
-         void **provctx);
- -

handle is the OpenSSL library object for the provider, and works as a handle for everything the OpenSSL libraries need to know about the provider. For the provider itself, it is passed to some of the functions given in the dispatch array in.

- -

in is a dispatch array of base functions offered by the OpenSSL libraries, and the available functions are further described in provider-base(7).

- -

*out must be assigned a dispatch array of base functions that the provider offers to the OpenSSL libraries. The functions that may be offered are further described in provider-base(7), and they are the central means of communication between the OpenSSL libraries and the provider.

- -

*provctx should be assigned a provider specific context to allow the provider multiple simultaneous uses. This pointer will be passed to various operation functions offered by the provider.

- -

Note that the provider will not be made available for applications to use until the initialization function has completed and returned successfully.

- -

One of the functions the provider offers to the OpenSSL libraries is the central mechanism for the OpenSSL libraries to get access to operation implementations for diverse algorithms. Its referred to with the number OSSL_FUNC_PROVIDER_QUERY_OPERATION and has the following signature:

- -
const OSSL_ALGORITHM *provider_query_operation(void *provctx,
-                                               int operation_id,
-                                               const int *no_store);
- -

provctx is the provider specific context that was passed back by the initialization function.

- -

operation_id is an operation identity (see "Operations" below).

- -

no_store is a flag back to the OpenSSL libraries which, when nonzero, signifies that the OpenSSL libraries will not store a reference to the returned data in their internal store of implementations.

- -

The returned OSSL_ALGORITHM(3) is the foundation of any OpenSSL library API that uses providers for their implementation, most commonly in the fetching type of functions (see "ALGORITHM FETCHING" in crypto(7)).

- -

Operations

- -

Operations are referred to with numbers, via macros with names starting with OSSL_OP_.

- -

With each operation comes a set of defined function types that a provider may or may not offer, depending on its needs.

- -

Currently available operations are:

- -
- -
Digests
-
- -

In the OpenSSL libraries, the corresponding method object is EVP_MD. The number for this operation is OSSL_OP_DIGEST. The functions the provider can offer are described in provider-digest(7).

- -
-
Symmetric ciphers
-
- -

In the OpenSSL libraries, the corresponding method object is EVP_CIPHER. The number for this operation is OSSL_OP_CIPHER. The functions the provider can offer are described in provider-cipher(7).

- -
-
Message Authentication Code (MAC)
-
- -

In the OpenSSL libraries, the corresponding method object is EVP_MAC. The number for this operation is OSSL_OP_MAC. The functions the provider can offer are described in provider-mac(7).

- -
-
Key Derivation Function (KDF)
-
- -

In the OpenSSL libraries, the corresponding method object is EVP_KDF. The number for this operation is OSSL_OP_KDF. The functions the provider can offer are described in provider-kdf(7).

- -
-
Key Exchange
-
- -

In the OpenSSL libraries, the corresponding method object is EVP_KEYEXCH. The number for this operation is OSSL_OP_KEYEXCH. The functions the provider can offer are described in provider-keyexch(7).

- -
-
Asymmetric Ciphers
-
- -

In the OpenSSL libraries, the corresponding method object is EVP_ASYM_CIPHER. The number for this operation is OSSL_OP_ASYM_CIPHER. The functions the provider can offer are described in provider-asym_cipher(7).

- -
-
Asymmetric Key Encapsulation
-
- -

In the OpenSSL libraries, the corresponding method object is EVP_KEM. The number for this operation is OSSL_OP_KEM. The functions the provider can offer are described in provider-kem(7).

- -
-
Encoding
-
- -

In the OpenSSL libraries, the corresponding method object is OSSL_ENCODER. The number for this operation is OSSL_OP_ENCODER. The functions the provider can offer are described in provider-encoder(7).

- -
-
Decoding
-
- -

In the OpenSSL libraries, the corresponding method object is OSSL_DECODER. The number for this operation is OSSL_OP_DECODER. The functions the provider can offer are described in provider-decoder(7).

- -
-
Random Number Generation
-
- -

The number for this operation is OSSL_OP_RAND. The functions the provider can offer for random number generation are described in provider-rand(7).

- -
-
Key Management
-
- -

The number for this operation is OSSL_OP_KEYMGMT. The functions the provider can offer for key management are described in provider-keymgmt(7).

- -
-
Signing and Signature Verification
-
- -

The number for this operation is OSSL_OP_SIGNATURE. The functions the provider can offer for digital signatures are described in provider-signature(7).

- -
-
Store Management
-
- -

The number for this operation is OSSL_OP_STORE. The functions the provider can offer for store management are described in provider-storemgmt(7).

- -
-
- -

Algorithm naming

- -

Algorithm names are case insensitive. Any particular algorithm can have multiple aliases associated with it. The canonical OpenSSL naming scheme follows this format:

- -

ALGNAME[VERSION?][-SUBNAME[VERSION?]?][-SIZE?][-MODE?]

- -

VERSION is only present if there are multiple versions of an algorithm (e.g. MD2, MD4, MD5). It may be omitted if there is only one version.

- -

SUBNAME may be present where multiple algorithms are combined together, e.g. MD5-SHA1.

- -

SIZE is only present if multiple versions of an algorithm exist with different sizes (e.g. AES-128-CBC, AES-256-CBC)

- -

MODE is only present where applicable.

- -

Other aliases may exist for example where standards bodies or common practice use alternative names or names that OpenSSL has used historically.

- -

Provider dependencies

- -

Providers may depend for their proper operation on the availability of (functionality implemented in) other providers. As there is no mechanism to express such dependencies towards the OpenSSL core, provider authors must take care that such dependencies are either completely avoided or made visible to users, e.g., by documentation and/or defensive programming, e.g., outputting error messages if required external dependencies are not available, e.g., when no provider implementing the required functionality has been activated. In particular, provider initialization should not depend on other providers already having been initialized.

- -

Note on naming clashes

- -

It is possible to register the same algorithm name from within different providers. Users should note that if no property query is specified, or more than one implementation matches the property query then it is unspecified which implementation of a particular algorithm will be returned. Such naming clashes may also occur if algorithms only differ in capitalization as "Algorithm naming" is case insensitive.

- -

OPENSSL PROVIDERS

- -

OpenSSL provides a number of its own providers. These are the default, base, fips, legacy and null providers. See crypto(7) for an overview of these providers.

- -

SEE ALSO

- -

EVP_DigestInit_ex(3), EVP_EncryptInit_ex(3), OSSL_LIB_CTX(3), EVP_set_default_properties(3), EVP_MD_fetch(3), EVP_CIPHER_fetch(3), EVP_KEYMGMT_fetch(3), openssl-core.h(7), provider-base(7), provider-digest(7), provider-cipher(7), provider-keyexch(7)

- -

HISTORY

- -

The concept of providers and everything surrounding them was introduced in OpenSSL 3.0.

- -

COPYRIGHT

- -

Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/proxy-certificates.html b/openssl-install/share/doc/openssl/html/man7/proxy-certificates.html deleted file mode 100644 index db370b71..00000000 --- a/openssl-install/share/doc/openssl/html/man7/proxy-certificates.html +++ /dev/null @@ -1,343 +0,0 @@ - - - - -proxy-certificates - - - - - - - - - - -

NAME

- -

proxy-certificates - Proxy certificates in OpenSSL

- -

DESCRIPTION

- -

Proxy certificates are defined in RFC 3820. They are used to extend rights to some other entity (a computer process, typically, or sometimes to the user itself). This allows the entity to perform operations on behalf of the owner of the EE (End Entity) certificate.

- -

The requirements for a valid proxy certificate are:

- -
    - -
  • They are issued by an End Entity, either a normal EE certificate, or another proxy certificate.

    - -
  • -
  • They must not have the subjectAltName or issuerAltName extensions.

    - -
  • -
  • They must have the proxyCertInfo extension.

    - -
  • -
  • They must have the subject of their issuer, with one commonName added.

    - -
  • -
- -

Enabling proxy certificate verification

- -

OpenSSL expects applications that want to use proxy certificates to be specially aware of them, and make that explicit. This is done by setting an X509 verification flag:

- -
X509_STORE_CTX_set_flags(ctx, X509_V_FLAG_ALLOW_PROXY_CERTS);
- -

or

- -
X509_VERIFY_PARAM_set_flags(param, X509_V_FLAG_ALLOW_PROXY_CERTS);
- -

See "NOTES" for a discussion on this requirement.

- -

Creating proxy certificates

- -

Creating proxy certificates can be done using the openssl-x509(1) command, with some extra extensions:

- -
[ proxy ]
-# A proxy certificate MUST NEVER be a CA certificate.
-basicConstraints = CA:FALSE
-# Usual authority key ID
-authorityKeyIdentifier = keyid,issuer:always
-# The extension which marks this certificate as a proxy
-proxyCertInfo = critical,language:id-ppl-anyLanguage,pathlen:1,policy:text:AB
- -

It's also possible to specify the proxy extension in a separate section:

- -
proxyCertInfo = critical,@proxy_ext
-
-[ proxy_ext ]
-language = id-ppl-anyLanguage
-pathlen = 0
-policy = text:BC
- -

The policy value has a specific syntax, syntag:string, where the syntag determines what will be done with the string. The following syntags are recognised:

- -
- -
text
-
- -

indicates that the string is a byte sequence, without any encoding:

- -
policy=text:räksmörgås
- -
-
hex
-
- -

indicates the string is encoded hexadecimal encoded binary data, with colons between each byte (every second hex digit):

- -
policy=hex:72:E4:6B:73:6D:F6:72:67:E5:73
- -
-
file
-
- -

indicates that the text of the policy should be taken from a file. The string is then a filename. This is useful for policies that are more than a few lines, such as XML or other markup.

- -
-
- -

Note that the proxy policy value is what determines the rights granted to the process during the proxy certificate, and it is up to the application to interpret and combine these policies.>

- -

With a proxy extension, creating a proxy certificate is a matter of two commands:

- -
openssl req -new -config proxy.cnf \
-    -out proxy.req -keyout proxy.key \
-    -subj "/DC=org/DC=openssl/DC=users/CN=proxy"
-
-openssl x509 -req -CAcreateserial -in proxy.req -out proxy.crt \
-    -CA user.crt -CAkey user.key -days 7 \
-    -extfile proxy.cnf -extensions proxy
- -

You can also create a proxy certificate using another proxy certificate as issuer. Note that this example uses a different configuration section for the proxy extensions:

- -
openssl req -new -config proxy.cnf \
-    -out proxy2.req -keyout proxy2.key \
-    -subj "/DC=org/DC=openssl/DC=users/CN=proxy/CN=proxy 2"
-
-openssl x509 -req -CAcreateserial -in proxy2.req -out proxy2.crt \
-    -CA proxy.crt -CAkey proxy.key -days 7 \
-    -extfile proxy.cnf -extensions proxy_2
- -

Using proxy certs in applications

- -

To interpret proxy policies, the application would normally start with some default rights (perhaps none at all), then compute the resulting rights by checking the rights against the chain of proxy certificates, user certificate and CA certificates.

- -

The complicated part is figuring out how to pass data between your application and the certificate validation procedure.

- -

The following ingredients are needed for such processing:

- -
    - -
  • a callback function that will be called for every certificate being validated. The callback is called several times for each certificate, so you must be careful to do the proxy policy interpretation at the right time. You also need to fill in the defaults when the EE certificate is checked.

    - -
  • -
  • a data structure that is shared between your application code and the callback.

    - -
  • -
  • a wrapper function that sets it all up.

    - -
  • -
  • an ex_data index function that creates an index into the generic ex_data store that is attached to an X509 validation context.

    - -
  • -
- -

The following skeleton code can be used as a starting point:

- -
#include <string.h>
-#include <netdb.h>
-#include <openssl/x509.h>
-#include <openssl/x509v3.h>
-
-#define total_rights 25
-
-/*
- * In this example, I will use a view of granted rights as a bit
- * array, one bit for each possible right.
- */
-typedef struct your_rights {
-    unsigned char rights[(total_rights + 7) / 8];
-} YOUR_RIGHTS;
-
-/*
- * The following procedure will create an index for the ex_data
- * store in the X509 validation context the first time it's
- * called.  Subsequent calls will return the same index.
- */
-static int get_proxy_auth_ex_data_idx(X509_STORE_CTX *ctx)
-{
-    static volatile int idx = -1;
-
-    if (idx < 0) {
-        X509_STORE_lock(X509_STORE_CTX_get0_store(ctx));
-        if (idx < 0) {
-            idx = X509_STORE_CTX_get_ex_new_index(0,
-                                                  "for verify callback",
-                                                  NULL,NULL,NULL);
-        }
-        X509_STORE_unlock(X509_STORE_CTX_get0_store(ctx));
-    }
-    return idx;
-}
-
-/* Callback to be given to the X509 validation procedure.  */
-static int verify_callback(int ok, X509_STORE_CTX *ctx)
-{
-    if (ok == 1) {
-        /*
-         * It's REALLY important you keep the proxy policy check
-         * within this section.  It's important to know that when
-         * ok is 1, the certificates are checked from top to
-         * bottom.  You get the CA root first, followed by the
-         * possible chain of intermediate CAs, followed by the EE
-         * certificate, followed by the possible proxy
-         * certificates.
-         */
-        X509 *xs = X509_STORE_CTX_get_current_cert(ctx);
-
-        if (X509_get_extension_flags(xs) & EXFLAG_PROXY) {
-            YOUR_RIGHTS *rights =
-                (YOUR_RIGHTS *)X509_STORE_CTX_get_ex_data(ctx,
-                    get_proxy_auth_ex_data_idx(ctx));
-            PROXY_CERT_INFO_EXTENSION *pci =
-                X509_get_ext_d2i(xs, NID_proxyCertInfo, NULL, NULL);
-
-            switch (OBJ_obj2nid(pci->proxyPolicy->policyLanguage)) {
-            case NID_Independent:
-                /*
-                 * Do whatever you need to grant explicit rights
-                 * to this particular proxy certificate, usually
-                 * by pulling them from some database.  If there
-                 * are none to be found, clear all rights (making
-                 * this and any subsequent proxy certificate void
-                 * of any rights).
-                 */
-                memset(rights->rights, 0, sizeof(rights->rights));
-                break;
-            case NID_id_ppl_inheritAll:
-                /*
-                 * This is basically a NOP, we simply let the
-                 * current rights stand as they are.
-                 */
-                break;
-            default:
-                /*
-                 * This is usually the most complex section of
-                 * code.  You really do whatever you want as long
-                 * as you follow RFC 3820.  In the example we use
-                 * here, the simplest thing to do is to build
-                 * another, temporary bit array and fill it with
-                 * the rights granted by the current proxy
-                 * certificate, then use it as a mask on the
-                 * accumulated rights bit array, and voilà, you
-                 * now have a new accumulated rights bit array.
-                 */
-                {
-                    int i;
-                    YOUR_RIGHTS tmp_rights;
-                    memset(tmp_rights.rights, 0,
-                           sizeof(tmp_rights.rights));
-
-                    /*
-                     * process_rights() is supposed to be a
-                     * procedure that takes a string and its
-                     * length, interprets it and sets the bits
-                     * in the YOUR_RIGHTS pointed at by the
-                     * third argument.
-                     */
-                    process_rights((char *) pci->proxyPolicy->policy->data,
-                                   pci->proxyPolicy->policy->length,
-                                   &tmp_rights);
-
-                    for(i = 0; i < total_rights / 8; i++)
-                        rights->rights[i] &= tmp_rights.rights[i];
-                }
-                break;
-            }
-            PROXY_CERT_INFO_EXTENSION_free(pci);
-        } else if (!(X509_get_extension_flags(xs) & EXFLAG_CA)) {
-            /* We have an EE certificate, let's use it to set default! */
-            YOUR_RIGHTS *rights =
-                (YOUR_RIGHTS *)X509_STORE_CTX_get_ex_data(ctx,
-                    get_proxy_auth_ex_data_idx(ctx));
-
-            /*
-             * The following procedure finds out what rights the
-             * owner of the current certificate has, and sets them
-             * in the YOUR_RIGHTS structure pointed at by the
-             * second argument.
-             */
-            set_default_rights(xs, rights);
-        }
-    }
-    return ok;
-}
-
-static int my_X509_verify_cert(X509_STORE_CTX *ctx,
-                               YOUR_RIGHTS *needed_rights)
-{
-    int ok;
-    int (*save_verify_cb)(int ok,X509_STORE_CTX *ctx) =
-        X509_STORE_CTX_get_verify_cb(ctx);
-    YOUR_RIGHTS rights;
-
-    X509_STORE_CTX_set_verify_cb(ctx, verify_callback);
-    X509_STORE_CTX_set_ex_data(ctx, get_proxy_auth_ex_data_idx(ctx),
-                               &rights);
-    X509_STORE_CTX_set_flags(ctx, X509_V_FLAG_ALLOW_PROXY_CERTS);
-    ok = X509_verify_cert(ctx);
-
-    if (ok == 1) {
-        ok = check_needed_rights(rights, needed_rights);
-    }
-
-    X509_STORE_CTX_set_verify_cb(ctx, save_verify_cb);
-
-    return ok;
-}
- -

If you use SSL or TLS, you can easily set up a callback to have the certificates checked properly, using the code above:

- -
SSL_CTX_set_cert_verify_callback(s_ctx, my_X509_verify_cert,
-                                 &needed_rights);
- -

NOTES

- -

To this date, it seems that proxy certificates have only been used in environments that are aware of them, and no one seems to have investigated how they can be used or misused outside of such an environment.

- -

For that reason, OpenSSL requires that applications aware of proxy certificates must also make that explicit.

- -

subjectAltName and issuerAltName are forbidden in proxy certificates, and this is enforced in OpenSSL. The subject must be the same as the issuer, with one commonName added on.

- -

SEE ALSO

- -

X509_STORE_CTX_set_flags(3), X509_STORE_CTX_set_verify_cb(3), X509_VERIFY_PARAM_set_flags(3), SSL_CTX_set_cert_verify_callback(3), openssl-req(1), openssl-x509(1), RFC 3820

- -

COPYRIGHT

- -

Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/doc/openssl/html/man7/x509.html b/openssl-install/share/doc/openssl/html/man7/x509.html deleted file mode 100644 index 3d460cbb..00000000 --- a/openssl-install/share/doc/openssl/html/man7/x509.html +++ /dev/null @@ -1,67 +0,0 @@ - - - - -x509 - - - - - - - - - - -

NAME

- -

x509 - X.509 certificate handling

- -

SYNOPSIS

- -
#include <openssl/x509.h>
- -

DESCRIPTION

- -

An X.509 certificate is a structured grouping of information about an individual, a device, or anything one can imagine. An X.509 CRL (certificate revocation list) is a tool to help determine if a certificate is still valid. The exact definition of those can be found in the X.509 document from ITU-T, or in RFC3280 from PKIX. In OpenSSL, the type X509 is used to express such a certificate, and the type X509_CRL is used to express a CRL.

- -

A related structure is a certificate request, defined in PKCS#10 from RSA Security, Inc, also reflected in RFC2896. In OpenSSL, the type X509_REQ is used to express such a certificate request.

- -

To handle some complex parts of a certificate, there are the types X509_NAME (to express a certificate name), X509_ATTRIBUTE (to express a certificate attribute), X509_EXTENSION (to express a certificate extension) and a few more.

- -

Finally, there's the supertype X509_INFO, which can contain a CRL, a certificate and a corresponding private key.

- -

X509_XXX, d2i_X509_XXX, and i2d_X509_XXX functions handle X.509 certificates, with some exceptions, shown below.

- -

X509_CRL_XXX, d2i_X509_CRL_XXX, and i2d_X509_CRL_XXX functions handle X.509 CRLs.

- -

X509_REQ_XXX, d2i_X509_REQ_XXX, and i2d_X509_REQ_XXX functions handle PKCS#10 certificate requests.

- -

X509_NAME_XXX functions handle certificate names.

- -

X509_ATTRIBUTE_XXX functions handle certificate attributes.

- -

X509_EXTENSION_XXX functions handle certificate extensions.

- -

SEE ALSO

- -

X509_NAME_ENTRY_get_object(3), X509_NAME_add_entry_by_txt(3), X509_NAME_add_entry_by_NID(3), X509_NAME_print_ex(3), X509_NAME_new(3), PEM_X509_INFO_read(3), d2i_X509(3), d2i_X509_ALGOR(3), d2i_X509_CRL(3), d2i_X509_NAME(3), d2i_X509_REQ(3), d2i_X509_SIG(3), crypto(7)

- -

COPYRIGHT

- -

Copyright 2003-2021 The OpenSSL Project Authors. All Rights Reserved.

- -

Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at https://www.openssl.org/source/license.html.

- - - - - - - diff --git a/openssl-install/share/man/man1/CA.pl.1ossl b/openssl-install/share/man/man1/CA.pl.1ossl deleted file mode 100644 index 98cb154d..00000000 --- a/openssl-install/share/man/man1/CA.pl.1ossl +++ /dev/null @@ -1,317 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CA.PL 1ossl" -.TH CA.PL 1ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CA.pl \- friendlier interface for OpenSSL certificate programs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fB\s-1CA\s0.pl\fR -\&\fB\-?\fR | -\&\fB\-h\fR | -\&\fB\-help\fR -.PP -\&\fB\s-1CA\s0.pl\fR -\&\fB\-newcert\fR | -\&\fB\-newreq\fR | -\&\fB\-newreq\-nodes\fR | -\&\fB\-xsign\fR | -\&\fB\-sign\fR | -\&\fB\-signCA\fR | -\&\fB\-signcert\fR | -\&\fB\-crl\fR | -\&\fB\-newca\fR -[\fB\-extra\-\f(BIcmd\fB\fR \fIparameter\fR] -.PP -\&\fB\s-1CA\s0.pl\fR \fB\-pkcs12\fR [\fIcertname\fR] -.PP -\&\fB\s-1CA\s0.pl\fR \fB\-verify\fR \fIcertfile\fR ... -.PP -\&\fB\s-1CA\s0.pl\fR \fB\-revoke\fR \fIcertfile\fR [\fIreason\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1CA\s0.pl\fR script is a perl script that supplies the relevant command line -arguments to the \fBopenssl\fR\|(1) command for some common certificate operations. -It is intended to simplify the process of certificate creation and management -by the use of some simple options. -.PP -The script is intended as a simple front end for the \fBopenssl\fR\|(1) program for -use by a beginner. Its behaviour isn't always what is wanted. For more control -over the behaviour of the certificate commands call the \fBopenssl\fR\|(1) command -directly. -.PP -Most of the filenames mentioned below can be modified by editing the -\&\fB\s-1CA\s0.pl\fR script. -.PP -Under some environments it may not be possible to run the \fB\s-1CA\s0.pl\fR script -directly (for example Win32) and the default configuration file location may -be wrong. In this case the command: -.PP -.Vb 1 -\& perl \-S CA.pl -.Ve -.PP -can be used and the \fB\s-1OPENSSL_CONF\s0\fR environment variable can be set to point to -the correct path of the configuration file. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-?\fR, \fB\-h\fR, \fB\-help\fR" 4 -.IX Item "-?, -h, -help" -Prints a usage message. -.IP "\fB\-newcert\fR" 4 -.IX Item "-newcert" -Creates a new self signed certificate. The private key is written to the file -\&\fInewkey.pem\fR and the request written to the file \fInewreq.pem\fR. -Invokes \fBopenssl\-req\fR\|(1). -.IP "\fB\-newreq\fR" 4 -.IX Item "-newreq" -Creates a new certificate request. The private key is written to the file -\&\fInewkey.pem\fR and the request written to the file \fInewreq.pem\fR. -Executes \fBopenssl\-req\fR\|(1) under the hood. -.IP "\fB\-newreq\-nodes\fR" 4 -.IX Item "-newreq-nodes" -Is like \fB\-newreq\fR except that the private key will not be encrypted. -Uses \fBopenssl\-req\fR\|(1). -.IP "\fB\-newca\fR" 4 -.IX Item "-newca" -Creates a new \s-1CA\s0 hierarchy for use with the \fBca\fR program (or the \fB\-signcert\fR -and \fB\-xsign\fR options). The user is prompted to enter the filename of the \s-1CA\s0 -certificates (which should also contain the private key) or by hitting \s-1ENTER\s0 -details of the \s-1CA\s0 will be prompted for. The relevant files and directories -are created in a directory called \fIdemoCA\fR in the current directory. -Uses \fBopenssl\-req\fR\|(1) and \fBopenssl\-ca\fR\|(1). -.Sp -If the \fIdemoCA\fR directory already exists then the \fB\-newca\fR command will not -overwrite it and will do nothing. This can happen if a previous call using -the \fB\-newca\fR option terminated abnormally. To get the correct behaviour -delete the directory if it already exists. -.IP "\fB\-pkcs12\fR" 4 -.IX Item "-pkcs12" -Create a PKCS#12 file containing the user certificate, private key and \s-1CA\s0 -certificate. It expects the user certificate and private key to be in the -file \fInewcert.pem\fR and the \s-1CA\s0 certificate to be in the file \fIdemoCA/cacert.pem\fR, -it creates a file \fInewcert.p12\fR. This command can thus be called after the -\&\fB\-sign\fR option. The PKCS#12 file can be imported directly into a browser. -If there is an additional argument on the command line it will be used as the -\&\*(L"friendly name\*(R" for the certificate (which is typically displayed in the browser -list box), otherwise the name \*(L"My Certificate\*(R" is used. -Delegates work to \fBopenssl\-pkcs12\fR\|(1). -.IP "\fB\-sign\fR, \fB\-signcert\fR, \fB\-xsign\fR" 4 -.IX Item "-sign, -signcert, -xsign" -Calls the \fBopenssl\-ca\fR\|(1) command to sign a certificate request. It expects the -request to be in the file \fInewreq.pem\fR. The new certificate is written to the -file \fInewcert.pem\fR except in the case of the \fB\-xsign\fR option when it is -written to standard output. -.IP "\fB\-signCA\fR" 4 -.IX Item "-signCA" -This option is the same as the \fB\-sign\fR option except it uses the -configuration file section \fBv3_ca\fR and so makes the signed request a -valid \s-1CA\s0 certificate. This is useful when creating intermediate \s-1CA\s0 from -a root \s-1CA.\s0 Extra params are passed to \fBopenssl\-ca\fR\|(1). -.IP "\fB\-signcert\fR" 4 -.IX Item "-signcert" -This option is the same as \fB\-sign\fR except it expects a self signed certificate -to be present in the file \fInewreq.pem\fR. -Extra params are passed to \fBopenssl\-x509\fR\|(1) and \fBopenssl\-ca\fR\|(1). -.IP "\fB\-crl\fR" 4 -.IX Item "-crl" -Generate a \s-1CRL.\s0 Executes \fBopenssl\-ca\fR\|(1). -.IP "\fB\-revoke\fR \fIcertfile\fR [\fIreason\fR]" 4 -.IX Item "-revoke certfile [reason]" -Revoke the certificate contained in the specified \fBcertfile\fR. An optional -reason may be specified, and must be one of: \fBunspecified\fR, -\&\fBkeyCompromise\fR, \fBCACompromise\fR, \fBaffiliationChanged\fR, \fBsuperseded\fR, -\&\fBcessationOfOperation\fR, \fBcertificateHold\fR, or \fBremoveFromCRL\fR. -Leverages \fBopenssl\-ca\fR\|(1). -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verifies certificates against the \s-1CA\s0 certificate for \fIdemoCA\fR. If no -certificates are specified on the command line it tries to verify the file -\&\fInewcert.pem\fR. Invokes \fBopenssl\-verify\fR\|(1). -.IP "\fB\-extra\-\f(BIcmd\fB\fR \fIparameter\fR" 4 -.IX Item "-extra-cmd parameter" -For each option \fBextra\-\f(BIcmd\fB\fR, pass \fIparameter\fR to the \fBopenssl\fR\|(1) -sub-command with the same name as \fIcmd\fR, if that sub-command is invoked. -For example, if \fBopenssl\-req\fR\|(1) is invoked, the \fIparameter\fR given with -\&\fB\-extra\-req\fR will be passed to it. -For multi-word parameters, either repeat the option or quote the \fIparameters\fR -so it looks like one word to your shell. -See the individual command documentation for more information. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a \s-1CA\s0 hierarchy: -.PP -.Vb 1 -\& CA.pl \-newca -.Ve -.PP -Complete certificate creation example: create a \s-1CA,\s0 create a request, sign -the request and finally create a PKCS#12 file containing it. -.PP -.Vb 4 -\& CA.pl \-newca -\& CA.pl \-newreq -\& CA.pl \-sign -\& CA.pl \-pkcs12 "My Test Certificate" -.Ve -.SH "ENVIRONMENT" -.IX Header "ENVIRONMENT" -The environment variable \fB\s-1OPENSSL\s0\fR may be used to specify the name of -the OpenSSL program. It can be a full pathname, or a relative one. -.PP -The environment variable \fB\s-1OPENSSL_CONFIG\s0\fR may be used to specify a -configuration option and value to the \fBreq\fR and \fBca\fR commands invoked by -this script. It's value should be the option and pathname, as in -\&\f(CW\*(C`\-config /path/to/conf\-file\*(C'\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -\&\fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-req\fR\|(1), -\&\fBopenssl\-pkcs12\fR\|(1), -\&\fBconfig\fR\|(5) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/asn1parse.1ossl b/openssl-install/share/man/man1/asn1parse.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/asn1parse.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/c_rehash.1ossl b/openssl-install/share/man/man1/c_rehash.1ossl deleted file mode 120000 index e37d1acc..00000000 --- a/openssl-install/share/man/man1/c_rehash.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-rehash.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/ca.1ossl b/openssl-install/share/man/man1/ca.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/ca.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/ciphers.1ossl b/openssl-install/share/man/man1/ciphers.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/ciphers.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/cmp.1ossl b/openssl-install/share/man/man1/cmp.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/cmp.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/cms.1ossl b/openssl-install/share/man/man1/cms.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/cms.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/crl.1ossl b/openssl-install/share/man/man1/crl.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/crl.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/crl2pkcs7.1ossl b/openssl-install/share/man/man1/crl2pkcs7.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/crl2pkcs7.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/dgst.1ossl b/openssl-install/share/man/man1/dgst.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/dgst.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/dhparam.1ossl b/openssl-install/share/man/man1/dhparam.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/dhparam.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/dsa.1ossl b/openssl-install/share/man/man1/dsa.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/dsa.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/dsaparam.1ossl b/openssl-install/share/man/man1/dsaparam.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/dsaparam.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/ec.1ossl b/openssl-install/share/man/man1/ec.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/ec.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/ecparam.1ossl b/openssl-install/share/man/man1/ecparam.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/ecparam.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/enc.1ossl b/openssl-install/share/man/man1/enc.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/enc.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/engine.1ossl b/openssl-install/share/man/man1/engine.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/engine.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/errstr.1ossl b/openssl-install/share/man/man1/errstr.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/errstr.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/gendsa.1ossl b/openssl-install/share/man/man1/gendsa.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/gendsa.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/genpkey.1ossl b/openssl-install/share/man/man1/genpkey.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/genpkey.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/genrsa.1ossl b/openssl-install/share/man/man1/genrsa.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/genrsa.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/info.1ossl b/openssl-install/share/man/man1/info.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/info.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/kdf.1ossl b/openssl-install/share/man/man1/kdf.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/kdf.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/mac.1ossl b/openssl-install/share/man/man1/mac.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/mac.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/nseq.1ossl b/openssl-install/share/man/man1/nseq.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/nseq.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/ocsp.1ossl b/openssl-install/share/man/man1/ocsp.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/ocsp.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/openssl-asn1parse.1ossl b/openssl-install/share/man/man1/openssl-asn1parse.1ossl deleted file mode 100644 index 29500446..00000000 --- a/openssl-install/share/man/man1/openssl-asn1parse.1ossl +++ /dev/null @@ -1,344 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-ASN1PARSE 1ossl" -.TH OPENSSL-ASN1PARSE 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-asn1parse \- ASN.1 parsing command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBasn1parse\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBB64\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-noout\fR] -[\fB\-offset\fR \fInumber\fR] -[\fB\-length\fR \fInumber\fR] -[\fB\-i\fR] -[\fB\-oid\fR \fIfilename\fR] -[\fB\-dump\fR] -[\fB\-dlimit\fR \fInum\fR] -[\fB\-strparse\fR \fIoffset\fR] -[\fB\-genstr\fR \fIstring\fR] -[\fB\-genconf\fR \fIfile\fR] -[\fB\-strictpem\fR] -[\fB\-item\fR \fIname\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is a diagnostic utility that can parse \s-1ASN.1\s0 structures. -It can also be used to extract data from \s-1ASN.1\s0 formatted data. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBB64\fR" 4 -.IX Item "-inform DER|PEM|B64" -The input format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -The input file, default is standard input. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Output file to place the \s-1DER\s0 encoded data into. If this -option is not present then no data will be output. This is most useful when -combined with the \fB\-strparse\fR option. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -Don't output the parsed version of the input file. -.IP "\fB\-offset\fR \fInumber\fR" 4 -.IX Item "-offset number" -Starting offset to begin parsing, default is start of file. -.IP "\fB\-length\fR \fInumber\fR" 4 -.IX Item "-length number" -Number of bytes to parse, default is until end of file. -.IP "\fB\-i\fR" 4 -.IX Item "-i" -Indents the output according to the \*(L"depth\*(R" of the structures. -.IP "\fB\-oid\fR \fIfilename\fR" 4 -.IX Item "-oid filename" -A file containing additional \s-1OBJECT\s0 IDENTIFIERs (OIDs). The format of this -file is described in the \s-1NOTES\s0 section below. -.IP "\fB\-dump\fR" 4 -.IX Item "-dump" -Dump unknown data in hex format. -.IP "\fB\-dlimit\fR \fInum\fR" 4 -.IX Item "-dlimit num" -Like \fB\-dump\fR, but only the first \fBnum\fR bytes are output. -.IP "\fB\-strparse\fR \fIoffset\fR" 4 -.IX Item "-strparse offset" -Parse the contents octets of the \s-1ASN.1\s0 object starting at \fBoffset\fR. This -option can be used multiple times to \*(L"drill down\*(R" into a nested structure. -.IP "\fB\-genstr\fR \fIstring\fR, \fB\-genconf\fR \fIfile\fR" 4 -.IX Item "-genstr string, -genconf file" -Generate encoded data based on \fIstring\fR, \fIfile\fR or both using -\&\fBASN1_generate_nconf\fR\|(3) format. If \fIfile\fR only is -present then the string is obtained from the default section using the name -\&\fBasn1\fR. The encoded data is passed through the \s-1ASN1\s0 parser and printed out as -though it came from a file, the contents can thus be examined and written to a -file using the \fB\-out\fR option. -.IP "\fB\-strictpem\fR" 4 -.IX Item "-strictpem" -If this option is used then \fB\-inform\fR will be ignored. Without this option any -data in a \s-1PEM\s0 format input file will be treated as being base64 encoded and -processed whether it has the normal \s-1PEM BEGIN\s0 and \s-1END\s0 markers or not. This -option will ignore any data prior to the start of the \s-1BEGIN\s0 marker, or after an -\&\s-1END\s0 marker in a \s-1PEM\s0 file. -.IP "\fB\-item\fR \fIname\fR" 4 -.IX Item "-item name" -Attempt to decode and print the data as an \fB\s-1ASN1_ITEM\s0\fR \fIname\fR. This can be -used to print out the fields of any supported \s-1ASN.1\s0 structure if the type is -known. -.SS "Output" -.IX Subsection "Output" -The output will typically contain lines like this: -.PP -.Vb 1 -\& 0:d=0 hl=4 l= 681 cons: SEQUENCE -.Ve -.PP -\&..... -.PP -.Vb 10 -\& 229:d=3 hl=3 l= 141 prim: BIT STRING -\& 373:d=2 hl=3 l= 162 cons: cont [ 3 ] -\& 376:d=3 hl=3 l= 159 cons: SEQUENCE -\& 379:d=4 hl=2 l= 29 cons: SEQUENCE -\& 381:d=5 hl=2 l= 3 prim: OBJECT :X509v3 Subject Key Identifier -\& 386:d=5 hl=2 l= 22 prim: OCTET STRING -\& 410:d=4 hl=2 l= 112 cons: SEQUENCE -\& 412:d=5 hl=2 l= 3 prim: OBJECT :X509v3 Authority Key Identifier -\& 417:d=5 hl=2 l= 105 prim: OCTET STRING -\& 524:d=4 hl=2 l= 12 cons: SEQUENCE -.Ve -.PP -\&..... -.PP -This example is part of a self-signed certificate. Each line starts with the -offset in decimal. \f(CW\*(C`d=XX\*(C'\fR specifies the current depth. The depth is increased -within the scope of any \s-1SET\s0 or \s-1SEQUENCE.\s0 \f(CW\*(C`hl=XX\*(C'\fR gives the header length -(tag and length octets) of the current type. \f(CW\*(C`l=XX\*(C'\fR gives the length of -the contents octets. -.PP -The \fB\-i\fR option can be used to make the output more readable. -.PP -Some knowledge of the \s-1ASN.1\s0 structure is needed to interpret the output. -.PP -In this example the \s-1BIT STRING\s0 at offset 229 is the certificate public key. -The contents octets of this will contain the public key information. This can -be examined using the option \f(CW\*(C`\-strparse 229\*(C'\fR to yield: -.PP -.Vb 3 -\& 0:d=0 hl=3 l= 137 cons: SEQUENCE -\& 3:d=1 hl=3 l= 129 prim: INTEGER :E5D21E1F5C8D208EA7A2166C7FAF9F6BDF2059669C60876DDB70840F1A5AAFA59699FE471F379F1DD6A487E7D5409AB6A88D4A9746E24B91D8CF55DB3521015460C8EDE44EE8A4189F7A7BE77D6CD3A9AF2696F486855CF58BF0EDF2B4068058C7A947F52548DDF7E15E96B385F86422BEA9064A3EE9E1158A56E4A6F47E5897 -\& 135:d=1 hl=2 l= 3 prim: INTEGER :010001 -.Ve -.SH "NOTES" -.IX Header "NOTES" -If an \s-1OID\s0 is not part of OpenSSL's internal table it will be represented in -numerical form (for example 1.2.3.4). The file passed to the \fB\-oid\fR option -allows additional OIDs to be included. Each line consists of three columns, -the first column is the \s-1OID\s0 in numerical format and should be followed by white -space. The second column is the \*(L"short name\*(R" which is a single word followed -by whitespace. The final column is the rest of the line and is the -\&\*(L"long name\*(R". Example: -.PP -\&\f(CW\*(C`1.2.3.4 shortName A long name\*(C'\fR -.PP -For any \s-1OID\s0 with an associated short and long name, this command will display -the long name. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Parse a file: -.PP -.Vb 1 -\& openssl asn1parse \-in file.pem -.Ve -.PP -Parse a \s-1DER\s0 file: -.PP -.Vb 1 -\& openssl asn1parse \-inform DER \-in file.der -.Ve -.PP -Generate a simple UTF8String: -.PP -.Vb 1 -\& openssl asn1parse \-genstr \*(AqUTF8:Hello World\*(Aq -.Ve -.PP -Generate and write out a UTF8String, don't print parsed output: -.PP -.Vb 1 -\& openssl asn1parse \-genstr \*(AqUTF8:Hello World\*(Aq \-noout \-out utf8.der -.Ve -.PP -Generate using a config file: -.PP -.Vb 1 -\& openssl asn1parse \-genconf asn1.cnf \-noout \-out asn1.der -.Ve -.PP -Example config file: -.PP -.Vb 1 -\& asn1=SEQUENCE:seq_sect -\& -\& [seq_sect] -\& -\& field1=BOOL:TRUE -\& field2=EXP:0, UTF8:some random string -.Ve -.SH "BUGS" -.IX Header "BUGS" -There should be options to change the format of output lines. The output of some -\&\s-1ASN.1\s0 types is not well handled (if at all). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBASN1_generate_nconf\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-ca.1ossl b/openssl-install/share/man/man1/openssl-ca.1ossl deleted file mode 100644 index d027a7b3..00000000 --- a/openssl-install/share/man/man1/openssl-ca.1ossl +++ /dev/null @@ -1,937 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CA 1ossl" -.TH OPENSSL-CA 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-ca \- sample minimal CA application -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBca\fR -[\fB\-help\fR] -[\fB\-verbose\fR] -[\fB\-quiet\fR] -[\fB\-config\fR \fIfilename\fR] -[\fB\-name\fR \fIsection\fR] -[\fB\-section\fR \fIsection\fR] -[\fB\-gencrl\fR] -[\fB\-revoke\fR \fIfile\fR] -[\fB\-valid\fR \fIfile\fR] -[\fB\-status\fR \fIserial\fR] -[\fB\-updatedb\fR] -[\fB\-crl_reason\fR \fIreason\fR] -[\fB\-crl_hold\fR \fIinstruction\fR] -[\fB\-crl_compromise\fR \fItime\fR] -[\fB\-crl_CA_compromise\fR \fItime\fR] -[\fB\-crl_lastupdate\fR \fIdate\fR] -[\fB\-crl_nextupdate\fR \fIdate\fR] -[\fB\-crldays\fR \fIdays\fR] -[\fB\-crlhours\fR \fIhours\fR] -[\fB\-crlsec\fR \fIseconds\fR] -[\fB\-crlexts\fR \fIsection\fR] -[\fB\-startdate\fR \fIdate\fR] -[\fB\-not_before\fR \fIdate\fR] -[\fB\-enddate\fR \fIdate\fR] -[\fB\-not_after\fR \fIdate\fR] -[\fB\-days\fR \fIarg\fR] -[\fB\-md\fR \fIarg\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-keyfile\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-key\fR \fIarg\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-cert\fR \fIfile\fR] -[\fB\-certform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR] -[\fB\-selfsign\fR] -[\fB\-in\fR \fIfile\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|<\s-1PEM\s0>] -[\fB\-out\fR \fIfile\fR] -[\fB\-notext\fR] -[\fB\-dateopt\fR] -[\fB\-outdir\fR \fIdir\fR] -[\fB\-infiles\fR] -[\fB\-spkac\fR \fIfile\fR] -[\fB\-ss_cert\fR \fIfile\fR] -[\fB\-preserveDN\fR] -[\fB\-noemailDN\fR] -[\fB\-batch\fR] -[\fB\-msie_hack\fR] -[\fB\-extensions\fR \fIsection\fR] -[\fB\-extfile\fR \fIsection\fR] -[\fB\-subj\fR \fIarg\fR] -[\fB\-utf8\fR] -[\fB\-sigopt\fR \fInm\fR:\fIv\fR] -[\fB\-vfyopt\fR \fInm\fR:\fIv\fR] -[\fB\-create_serial\fR] -[\fB\-rand_serial\fR] -[\fB\-multivalue\-rdn\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIcertreq\fR...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command emulates a \s-1CA\s0 application. -See the \fB\s-1WARNINGS\s0\fR especially when considering to use it productively. -.PP -It generates certificates bearing X.509 version 3. -Unless specified otherwise, -key identifier extensions are included as described in \fBx509v3_config\fR\|(5). -.PP -It can be used to sign certificate requests (CSRs) in a variety of forms -and generate certificate revocation lists (CRLs). -It also maintains a text database of issued certificates and their status. -When signing certificates, a single request can be specified -with the \fB\-in\fR option, or multiple requests can be processed by -specifying a set of \fBcertreq\fR files after all options. -.PP -Note that there are also very lean ways of generating certificates: -the \fBreq\fR and \fBx509\fR commands can be used for directly creating certificates. -See \fBopenssl\-req\fR\|(1) and \fBopenssl\-x509\fR\|(1) for details. -.PP -The descriptions of the \fBca\fR command options are divided into each purpose. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -This prints extra details about the operations being performed. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -This prints fewer details about the operations being performed, which may -be handy during batch scripts or pipelines. -.IP "\fB\-config\fR \fIfilename\fR" 4 -.IX Item "-config filename" -Specifies the configuration file to use. -Optional; for a description of the default value, -see \*(L"\s-1COMMAND SUMMARY\*(R"\s0 in \fBopenssl\fR\|(1). -.IP "\fB\-name\fR \fIsection\fR, \fB\-section\fR \fIsection\fR" 4 -.IX Item "-name section, -section section" -Specifies the configuration file section to use (overrides -\&\fBdefault_ca\fR in the \fBca\fR section). -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -An input filename containing a single certificate request (\s-1CSR\s0) to be -signed by the \s-1CA.\s0 -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The format to use when loading certificate request (\s-1CSR\s0) input files; -by default \s-1PEM\s0 is tried first. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-ss_cert\fR \fIfilename\fR" 4 -.IX Item "-ss_cert filename" -A single self-signed certificate to be signed by the \s-1CA.\s0 -.IP "\fB\-spkac\fR \fIfilename\fR" 4 -.IX Item "-spkac filename" -A file containing a single Netscape signed public key and challenge -and additional field values to be signed by the \s-1CA.\s0 See the \fB\s-1SPKAC FORMAT\s0\fR -section for information on the required input and output format. -.IP "\fB\-infiles\fR" 4 -.IX Item "-infiles" -If present this should be the last option, all subsequent arguments -are taken as the names of files containing certificate requests. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -The output file to output certificates to. The default is standard -output. The certificate details will also be printed out to this -file in \s-1PEM\s0 format (except that \fB\-spkac\fR outputs \s-1DER\s0 format). -.IP "\fB\-outdir\fR \fIdirectory\fR" 4 -.IX Item "-outdir directory" -The directory to output certificates to. The certificate will be -written to a filename consisting of the serial number in hex with -\&\fI.pem\fR appended. -.IP "\fB\-cert\fR \fIfilename\fR" 4 -.IX Item "-cert filename" -The \s-1CA\s0 certificate, which must match with \fB\-keyfile\fR. -.IP "\fB\-certform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR" 4 -.IX Item "-certform DER|PEM|P12" -The format of the data in certificate input files; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-keyfile\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-keyfile filename|uri" -The \s-1CA\s0 private key to sign certificate requests with. -This must match with \fB\-cert\fR. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The format of the private key input file; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-sigopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-sigopt nm:v" -Pass options to the signature algorithm during sign operations. -Names and values of these options are algorithm-specific and -documented in \*(L"Signature parameters\*(R" in \fBprovider\-signature\fR\|(7). -.IP "\fB\-vfyopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-vfyopt nm:v" -Pass options to the signature algorithm during verify operations. -Names and values of these options are algorithm-specific. -.Sp -This often needs to be given while signing too, because the self-signature of -a certificate signing request (\s-1CSR\s0) is verified against the included public key, -and that verification may need its own set of options. -.IP "\fB\-key\fR \fIpassword\fR" 4 -.IX Item "-key password" -The password used to encrypt the private key. Since on some -systems the command line arguments are visible (e.g., when using -\&\fBps\fR\|(1) on Unix), -this option should be used with caution. -Better use \fB\-passin\fR. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The key password source for key files and certificate PKCS#12 files. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-selfsign\fR" 4 -.IX Item "-selfsign" -Indicates the issued certificates are to be signed with the key -the certificate requests were signed with (given with \fB\-keyfile\fR). -Certificate requests signed with a different key are ignored. -If \fB\-spkac\fR, \fB\-ss_cert\fR or \fB\-gencrl\fR are given, \fB\-selfsign\fR is ignored. -.Sp -A consequence of using \fB\-selfsign\fR is that the self-signed -certificate appears among the entries in the certificate database -(see the configuration option \fBdatabase\fR), and uses the same -serial number counter as all other certificates sign with the -self-signed certificate. -.IP "\fB\-notext\fR" 4 -.IX Item "-notext" -Don't output the text form of a certificate to the output file. -.IP "\fB\-dateopt\fR" 4 -.IX Item "-dateopt" -Specify the date output format. Values are: rfc_822 and iso_8601. -Defaults to rfc_822. -.IP "\fB\-startdate\fR \fIdate\fR, \fB\-not_before\fR \fIdate\fR" 4 -.IX Item "-startdate date, -not_before date" -This allows the start date to be explicitly set. The format of the -date is \s-1YYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 UTCTime structure), or -\&\s-1YYYYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 GeneralizedTime structure). In -both formats, seconds \s-1SS\s0 and timezone Z must be present. -Alternatively, you can also use \*(L"today\*(R". -.IP "\fB\-enddate\fR \fIdate\fR, \fB\-not_after\fR \fIdate\fR" 4 -.IX Item "-enddate date, -not_after date" -This allows the expiry date to be explicitly set. The format of the -date is \s-1YYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 UTCTime structure), or -\&\s-1YYYYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 GeneralizedTime structure). In -both formats, seconds \s-1SS\s0 and timezone Z must be present. -Alternatively, you can also use \*(L"today\*(R". -.Sp -This overrides the \fB\-days\fR option. -.IP "\fB\-days\fR \fIarg\fR" 4 -.IX Item "-days arg" -The number of days from today to certify the certificate for. -.Sp -Regardless of the option \fB\-not_before\fR, the days are always counted from -today. -When used together with the option \fB\-not_after\fR/\fB\-startdate\fR, the explicit -expiry date takes precedence. -.IP "\fB\-md\fR \fIalg\fR" 4 -.IX Item "-md alg" -The message digest to use. -Any digest supported by the \fBopenssl\-dgst\fR\|(1) command can be used. For signing -algorithms that do not support a digest (i.e. Ed25519 and Ed448) any message -digest that is set is ignored. This option also applies to CRLs. -.IP "\fB\-policy\fR \fIarg\fR" 4 -.IX Item "-policy arg" -This option defines the \s-1CA\s0 \*(L"policy\*(R" to use. This is a section in -the configuration file which decides which fields should be mandatory -or match the \s-1CA\s0 certificate. Check out the \fB\s-1POLICY FORMAT\s0\fR section -for more information. -.IP "\fB\-msie_hack\fR" 4 -.IX Item "-msie_hack" -This is a deprecated option to make this command work with very old versions -of the \s-1IE\s0 certificate enrollment control \*(L"certenr3\*(R". It used UniversalStrings -for almost everything. Since the old control has various security bugs -its use is strongly discouraged. -.IP "\fB\-preserveDN\fR" 4 -.IX Item "-preserveDN" -Normally the \s-1DN\s0 order of a certificate is the same as the order of the -fields in the relevant policy section. When this option is set the order -is the same as the request. This is largely for compatibility with the -older \s-1IE\s0 enrollment control which would only accept certificates if their -DNs match the order of the request. This is not needed for Xenroll. -.IP "\fB\-noemailDN\fR" 4 -.IX Item "-noemailDN" -The \s-1DN\s0 of a certificate can contain the \s-1EMAIL\s0 field if present in the -request \s-1DN,\s0 however, it is good policy just having the e\-mail set into -the altName extension of the certificate. When this option is set the -\&\s-1EMAIL\s0 field is removed from the certificate' subject and set only in -the, eventually present, extensions. The \fBemail_in_dn\fR keyword can be -used in the configuration file to enable this behaviour. -.IP "\fB\-batch\fR" 4 -.IX Item "-batch" -This sets the batch mode. In this mode no questions will be asked -and all certificates will be certified automatically. -.IP "\fB\-extensions\fR \fIsection\fR" 4 -.IX Item "-extensions section" -The section of the configuration file containing certificate extensions -to be added when a certificate is issued (defaults to \fBx509_extensions\fR -unless the \fB\-extfile\fR option is used). -.Sp -See the \fBx509v3_config\fR\|(5) manual page for details of the -extension section format. -.IP "\fB\-extfile\fR \fIfile\fR" 4 -.IX Item "-extfile file" -An additional configuration file to read certificate extensions from -(using the default section unless the \fB\-extensions\fR option is also -used). -.IP "\fB\-subj\fR \fIarg\fR" 4 -.IX Item "-subj arg" -Supersedes subject name given in the request. -.Sp -The arg must be formatted as \f(CW\*(C`/type0=value0/type1=value1/type2=...\*(C'\fR. -Special characters may be escaped by \f(CW\*(C`\e\*(C'\fR (backslash), whitespace is retained. -Empty values are permitted, but the corresponding type will not be included -in the resulting certificate. -Giving a single \f(CW\*(C`/\*(C'\fR will lead to an empty sequence of RDNs (a NULL-DN). -Multi-valued RDNs can be formed by placing a \f(CW\*(C`+\*(C'\fR character instead of a \f(CW\*(C`/\*(C'\fR -between the AttributeValueAssertions (AVAs) that specify the members of the set. -Example: -.Sp -\&\f(CW\*(C`/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe\*(C'\fR -.IP "\fB\-utf8\fR" 4 -.IX Item "-utf8" -This option causes field values to be interpreted as \s-1UTF8\s0 strings, by -default they are interpreted as \s-1ASCII.\s0 This means that the field -values, whether prompted from a terminal or obtained from a -configuration file, must be valid \s-1UTF8\s0 strings. -.IP "\fB\-create_serial\fR" 4 -.IX Item "-create_serial" -If reading serial from the text file as specified in the configuration -fails, specifying this option creates a new random serial to be used as next -serial number. -To get random serial numbers, use the \fB\-rand_serial\fR flag instead; this -should only be used for simple error-recovery. -.IP "\fB\-rand_serial\fR" 4 -.IX Item "-rand_serial" -Generate a large random number to use as the serial number. -This overrides any option or configuration to use a serial number file. -.IP "\fB\-multivalue\-rdn\fR" 4 -.IX Item "-multivalue-rdn" -This option has been deprecated and has no effect. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "CRL OPTIONS" -.IX Header "CRL OPTIONS" -.IP "\fB\-gencrl\fR" 4 -.IX Item "-gencrl" -This option generates a \s-1CRL\s0 based on information in the index file. -.IP "\fB\-crl_lastupdate\fR \fItime\fR" 4 -.IX Item "-crl_lastupdate time" -Allows the value of the \s-1CRL\s0's lastUpdate field to be explicitly set; if -this option is not present, the current time is used. Accepts times in -\&\s-1YYMMDDHHMMSSZ\s0 format (the same as an \s-1ASN1\s0 UTCTime structure) or -\&\s-1YYYYMMDDHHMMSSZ\s0 format (the same as an \s-1ASN1\s0 GeneralizedTime structure). -.IP "\fB\-crl_nextupdate\fR \fItime\fR" 4 -.IX Item "-crl_nextupdate time" -Allows the value of the \s-1CRL\s0's nextUpdate field to be explicitly set; if -this option is present, any values given for \fB\-crldays\fR, \fB\-crlhours\fR -and \fB\-crlsec\fR are ignored. Accepts times in the same formats as -\&\fB\-crl_lastupdate\fR. -.IP "\fB\-crldays\fR \fInum\fR" 4 -.IX Item "-crldays num" -The number of days before the next \s-1CRL\s0 is due. That is the days from -now to place in the \s-1CRL\s0 nextUpdate field. -.IP "\fB\-crlhours\fR \fInum\fR" 4 -.IX Item "-crlhours num" -The number of hours before the next \s-1CRL\s0 is due. -.IP "\fB\-crlsec\fR \fInum\fR" 4 -.IX Item "-crlsec num" -The number of seconds before the next \s-1CRL\s0 is due. -.IP "\fB\-revoke\fR \fIfilename\fR" 4 -.IX Item "-revoke filename" -A filename containing a certificate to revoke. -.IP "\fB\-valid\fR \fIfilename\fR" 4 -.IX Item "-valid filename" -A filename containing a certificate to add a Valid certificate entry. -.IP "\fB\-status\fR \fIserial\fR" 4 -.IX Item "-status serial" -Displays the revocation status of the certificate with the specified -serial number and exits. -.IP "\fB\-updatedb\fR" 4 -.IX Item "-updatedb" -Updates the database index to purge expired certificates. -.IP "\fB\-crl_reason\fR \fIreason\fR" 4 -.IX Item "-crl_reason reason" -Revocation reason, where \fIreason\fR is one of: \fBunspecified\fR, \fBkeyCompromise\fR, -\&\fBCACompromise\fR, \fBaffiliationChanged\fR, \fBsuperseded\fR, \fBcessationOfOperation\fR, -\&\fBcertificateHold\fR or \fBremoveFromCRL\fR. The matching of \fIreason\fR is case -insensitive. Setting any revocation reason will make the \s-1CRL\s0 v2. -.Sp -In practice \fBremoveFromCRL\fR is not particularly useful because it is only used -in delta CRLs which are not currently implemented. -.IP "\fB\-crl_hold\fR \fIinstruction\fR" 4 -.IX Item "-crl_hold instruction" -This sets the \s-1CRL\s0 revocation reason code to \fBcertificateHold\fR and the hold -instruction to \fIinstruction\fR which must be an \s-1OID.\s0 Although any \s-1OID\s0 can be -used only \fBholdInstructionNone\fR (the use of which is discouraged by \s-1RFC2459\s0) -\&\fBholdInstructionCallIssuer\fR or \fBholdInstructionReject\fR will normally be used. -.IP "\fB\-crl_compromise\fR \fItime\fR" 4 -.IX Item "-crl_compromise time" -This sets the revocation reason to \fBkeyCompromise\fR and the compromise time to -\&\fItime\fR. \fItime\fR should be in GeneralizedTime format that is \fI\s-1YYYYMMDDHHMMSSZ\s0\fR. -.IP "\fB\-crl_CA_compromise\fR \fItime\fR" 4 -.IX Item "-crl_CA_compromise time" -This is the same as \fBcrl_compromise\fR except the revocation reason is set to -\&\fBCACompromise\fR. -.IP "\fB\-crlexts\fR \fIsection\fR" 4 -.IX Item "-crlexts section" -The section of the configuration file containing \s-1CRL\s0 extensions to -include. If no \s-1CRL\s0 extension section is present then a V1 \s-1CRL\s0 is -created, if the \s-1CRL\s0 extension section is present (even if it is -empty) then a V2 \s-1CRL\s0 is created. The \s-1CRL\s0 extensions specified are -\&\s-1CRL\s0 extensions and \fBnot\fR \s-1CRL\s0 entry extensions. It should be noted -that some software (for example Netscape) can't handle V2 CRLs. See -\&\fBx509v3_config\fR\|(5) manual page for details of the -extension section format. -.SH "CONFIGURATION FILE OPTIONS" -.IX Header "CONFIGURATION FILE OPTIONS" -The section of the configuration file containing options for this command -is found as follows: If the \fB\-name\fR command line option is used, -then it names the section to be used. Otherwise the section to -be used must be named in the \fBdefault_ca\fR option of the \fBca\fR section -of the configuration file (or in the default section of the -configuration file). Besides \fBdefault_ca\fR, the following options are -read directly from the \fBca\fR section: - \s-1RANDFILE\s0 - preserve - msie_hack -With the exception of \fB\s-1RANDFILE\s0\fR, this is probably a bug and may -change in future releases. -.PP -Many of the configuration file options are identical to command line -options. Where the option is present in the configuration file -and the command line the command line value is used. Where an -option is described as mandatory then it must be present in -the configuration file or the command line equivalent (if -any) used. -.IP "\fBoid_file\fR" 4 -.IX Item "oid_file" -This specifies a file containing additional \fB\s-1OBJECT IDENTIFIERS\s0\fR. -Each line of the file should consist of the numerical form of the -object identifier followed by whitespace then the short name followed -by whitespace and finally the long name. -.IP "\fBoid_section\fR" 4 -.IX Item "oid_section" -This specifies a section in the configuration file containing extra -object identifiers. Each line should consist of the short name of the -object identifier followed by \fB=\fR and the numerical form. The short -and long names are the same when this option is used. -.IP "\fBnew_certs_dir\fR" 4 -.IX Item "new_certs_dir" -The same as the \fB\-outdir\fR command line option. It specifies -the directory where new certificates will be placed. Mandatory. -.IP "\fBcertificate\fR" 4 -.IX Item "certificate" -The same as \fB\-cert\fR. It gives the file containing the \s-1CA\s0 -certificate. Mandatory. -.IP "\fBprivate_key\fR" 4 -.IX Item "private_key" -Same as the \fB\-keyfile\fR option. The file containing the -\&\s-1CA\s0 private key. Mandatory. -.IP "\fB\s-1RANDFILE\s0\fR" 4 -.IX Item "RANDFILE" -At startup the specified file is loaded into the random number generator, -and at exit 256 bytes will be written to it. (Note: Using a \s-1RANDFILE\s0 is -not necessary anymore, see the \*(L"\s-1HISTORY\*(R"\s0 section. -.IP "\fBdefault_days\fR" 4 -.IX Item "default_days" -The same as the \fB\-days\fR option. The number of days from today to certify -a certificate for. -.IP "\fBdefault_startdate\fR" 4 -.IX Item "default_startdate" -The same as the \fB\-startdate\fR option. The start date to certify -a certificate for. If not set the current time is used. -.IP "\fBdefault_enddate\fR" 4 -.IX Item "default_enddate" -The same as the \fB\-enddate\fR option. Either this option or -\&\fBdefault_days\fR (or the command line equivalents) must be -present. -.IP "\fBdefault_crl_hours default_crl_days\fR" 4 -.IX Item "default_crl_hours default_crl_days" -The same as the \fB\-crlhours\fR and the \fB\-crldays\fR options. These -will only be used if neither command line option is present. At -least one of these must be present to generate a \s-1CRL.\s0 -.IP "\fBdefault_md\fR" 4 -.IX Item "default_md" -The same as the \fB\-md\fR option. Mandatory except where the signing algorithm does -not require a digest (i.e. Ed25519 and Ed448). -.IP "\fBdatabase\fR" 4 -.IX Item "database" -The text database file to use. Mandatory. This file must be present -though initially it will be empty. -.IP "\fBunique_subject\fR" 4 -.IX Item "unique_subject" -If the value \fByes\fR is given, the valid certificate entries in the -database must have unique subjects. if the value \fBno\fR is given, -several valid certificate entries may have the exact same subject. -The default value is \fByes\fR, to be compatible with older (pre 0.9.8) -versions of OpenSSL. However, to make \s-1CA\s0 certificate roll-over easier, -it's recommended to use the value \fBno\fR, especially if combined with -the \fB\-selfsign\fR command line option. -.Sp -Note that it is valid in some circumstances for certificates to be created -without any subject. In the case where there are multiple certificates without -subjects this does not count as a duplicate. -.IP "\fBserial\fR" 4 -.IX Item "serial" -A text file containing the next serial number to use in hex. Mandatory. -This file must be present and contain a valid serial number. -.IP "\fBcrlnumber\fR" 4 -.IX Item "crlnumber" -A text file containing the next \s-1CRL\s0 number to use in hex. The crl number -will be inserted in the CRLs only if this file exists. If this file is -present, it must contain a valid \s-1CRL\s0 number. -.IP "\fBx509_extensions\fR" 4 -.IX Item "x509_extensions" -A fallback to the \fB\-extensions\fR option. -.IP "\fBcrl_extensions\fR" 4 -.IX Item "crl_extensions" -A fallback to the \fB\-crlexts\fR option. -.IP "\fBpreserve\fR" 4 -.IX Item "preserve" -The same as \fB\-preserveDN\fR -.IP "\fBemail_in_dn\fR" 4 -.IX Item "email_in_dn" -The same as \fB\-noemailDN\fR. If you want the \s-1EMAIL\s0 field to be removed -from the \s-1DN\s0 of the certificate simply set this to 'no'. If not present -the default is to allow for the \s-1EMAIL\s0 filed in the certificate's \s-1DN.\s0 -.IP "\fBmsie_hack\fR" 4 -.IX Item "msie_hack" -The same as \fB\-msie_hack\fR -.IP "\fBpolicy\fR" 4 -.IX Item "policy" -The same as \fB\-policy\fR. Mandatory. See the \fB\s-1POLICY FORMAT\s0\fR section -for more information. -.IP "\fBname_opt\fR, \fBcert_opt\fR" 4 -.IX Item "name_opt, cert_opt" -These options allow the format used to display the certificate details -when asking the user to confirm signing. All the options supported by -the \fBx509\fR utilities \fB\-nameopt\fR and \fB\-certopt\fR switches can be used -here, except the \fBno_signame\fR and \fBno_sigdump\fR are permanently set -and cannot be disabled (this is because the certificate signature cannot -be displayed because the certificate has not been signed at this point). -.Sp -For convenience the values \fBca_default\fR are accepted by both to produce -a reasonable output. -.Sp -If neither option is present the format used in earlier versions of -OpenSSL is used. Use of the old format is \fBstrongly\fR discouraged because -it only displays fields mentioned in the \fBpolicy\fR section, mishandles -multicharacter string types and does not display extensions. -.IP "\fBcopy_extensions\fR" 4 -.IX Item "copy_extensions" -Determines how extensions in certificate requests should be handled. -If set to \fBnone\fR or this option is not present then extensions are -ignored and not copied to the certificate. If set to \fBcopy\fR then any -extensions present in the request that are not already present are copied -to the certificate. If set to \fBcopyall\fR then all extensions in the -request are copied to the certificate: if the extension is already present -in the certificate it is deleted first. See the \fB\s-1WARNINGS\s0\fR section before -using this option. -.Sp -The main use of this option is to allow a certificate request to supply -values for certain extensions such as subjectAltName. -.SH "POLICY FORMAT" -.IX Header "POLICY FORMAT" -The policy section consists of a set of variables corresponding to -certificate \s-1DN\s0 fields. If the value is \*(L"match\*(R" then the field value -must match the same field in the \s-1CA\s0 certificate. If the value is -\&\*(L"supplied\*(R" then it must be present. If the value is \*(L"optional\*(R" then -it may be present. Any fields not mentioned in the policy section -are silently deleted, unless the \fB\-preserveDN\fR option is set but -this can be regarded more of a quirk than intended behaviour. -.SH "SPKAC FORMAT" -.IX Header "SPKAC FORMAT" -The input to the \fB\-spkac\fR command line option is a Netscape -signed public key and challenge. This will usually come from -the \fB\s-1KEYGEN\s0\fR tag in an \s-1HTML\s0 form to create a new private key. -It is however possible to create SPKACs using \fBopenssl\-spkac\fR\|(1). -.PP -The file should contain the variable \s-1SPKAC\s0 set to the value of -the \s-1SPKAC\s0 and also the required \s-1DN\s0 components as name value pairs. -If you need to include the same component twice then it can be -preceded by a number and a '.'. -.PP -When processing \s-1SPKAC\s0 format, the output is \s-1DER\s0 if the \fB\-out\fR -flag is used, but \s-1PEM\s0 format if sending to stdout or the \fB\-outdir\fR -flag is used. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Note: these examples assume that the directory structure this command -assumes is already set up and the relevant files already exist. This -usually involves creating a \s-1CA\s0 certificate and private key with -\&\fBopenssl\-req\fR\|(1), a serial number file and an empty index file and -placing them in the relevant directories. -.PP -To use the sample configuration file below the directories \fIdemoCA\fR, -\&\fIdemoCA/private\fR and \fIdemoCA/newcerts\fR would be created. The \s-1CA\s0 -certificate would be copied to \fIdemoCA/cacert.pem\fR and its private -key to \fIdemoCA/private/cakey.pem\fR. A file \fIdemoCA/serial\fR would be -created containing for example \*(L"01\*(R" and the empty index file -\&\fIdemoCA/index.txt\fR. -.PP -Sign a certificate request: -.PP -.Vb 1 -\& openssl ca \-in req.pem \-out newcert.pem -.Ve -.PP -Sign an \s-1SM2\s0 certificate request: -.PP -.Vb 3 -\& openssl ca \-in sm2.csr \-out sm2.crt \-md sm3 \e -\& \-sigopt "distid:1234567812345678" \e -\& \-vfyopt "distid:1234567812345678" -.Ve -.PP -Sign a certificate request, using \s-1CA\s0 extensions: -.PP -.Vb 1 -\& openssl ca \-in req.pem \-extensions v3_ca \-out newcert.pem -.Ve -.PP -Generate a \s-1CRL\s0 -.PP -.Vb 1 -\& openssl ca \-gencrl \-out crl.pem -.Ve -.PP -Sign several requests: -.PP -.Vb 1 -\& openssl ca \-infiles req1.pem req2.pem req3.pem -.Ve -.PP -Certify a Netscape \s-1SPKAC:\s0 -.PP -.Vb 1 -\& openssl ca \-spkac spkac.txt -.Ve -.PP -A sample \s-1SPKAC\s0 file (the \s-1SPKAC\s0 line has been truncated for clarity): -.PP -.Vb 5 -\& SPKAC=MIG0MGAwXDANBgkqhkiG9w0BAQEFAANLADBIAkEAn7PDhCeV/xIxUg8V70YRxK2A5 -\& CN=Steve Test -\& emailAddress=steve@openssl.org -\& 0.OU=OpenSSL Group -\& 1.OU=Another Group -.Ve -.PP -A sample configuration file with the relevant sections for this command: -.PP -.Vb 2 -\& [ ca ] -\& default_ca = CA_default # The default ca section -\& -\& [ CA_default ] -\& -\& dir = ./demoCA # top dir -\& database = $dir/index.txt # index file. -\& new_certs_dir = $dir/newcerts # new certs dir -\& -\& certificate = $dir/cacert.pem # The CA cert -\& serial = $dir/serial # serial no file -\& #rand_serial = yes # for random serial#\*(Aqs -\& private_key = $dir/private/cakey.pem# CA private key -\& -\& default_days = 365 # how long to certify for -\& default_crl_days= 30 # how long before next CRL -\& default_md = sha256 # md to use -\& -\& policy = policy_any # default policy -\& email_in_dn = no # Don\*(Aqt add the email into cert DN -\& -\& name_opt = ca_default # Subject name display option -\& cert_opt = ca_default # Certificate display option -\& copy_extensions = none # Don\*(Aqt copy extensions from request -\& -\& [ policy_any ] -\& countryName = supplied -\& stateOrProvinceName = optional -\& organizationName = optional -\& organizationalUnitName = optional -\& commonName = supplied -\& emailAddress = optional -.Ve -.SH "FILES" -.IX Header "FILES" -Note: the location of all files can change either by compile time options, -configuration file entries, environment variables or command line options. -The values below reflect the default values. -.PP -.Vb 9 -\& /usr/local/ssl/lib/openssl.cnf \- master configuration file -\& ./demoCA \- main CA directory -\& ./demoCA/cacert.pem \- CA certificate -\& ./demoCA/private/cakey.pem \- CA private key -\& ./demoCA/serial \- CA serial number file -\& ./demoCA/serial.old \- CA serial number backup file -\& ./demoCA/index.txt \- CA text database file -\& ./demoCA/index.txt.old \- CA text database backup file -\& ./demoCA/certs \- certificate output file -.Ve -.SH "RESTRICTIONS" -.IX Header "RESTRICTIONS" -The text database index file is a critical part of the process and -if corrupted it can be difficult to fix. It is theoretically possible -to rebuild the index file from all the issued certificates and a current -\&\s-1CRL:\s0 however there is no option to do this. -.PP -V2 \s-1CRL\s0 features like delta CRLs are not currently supported. -.PP -Although several requests can be input and handled at once it is only -possible to include one \s-1SPKAC\s0 or self-signed certificate. -.SH "BUGS" -.IX Header "BUGS" -This command is quirky and at times downright unfriendly. -.PP -The use of an in-memory text database can cause problems when large -numbers of certificates are present because, as the name implies -the database has to be kept in memory. -.PP -This command really needs rewriting or the required functionality -exposed at either a command or interface level so that a more user-friendly -replacement could handle things properly. The script -\&\fB\s-1CA\s0.pl\fR helps a little but not very much. -.PP -Any fields in a request that are not present in a policy are silently -deleted. This does not happen if the \fB\-preserveDN\fR option is used. To -enforce the absence of the \s-1EMAIL\s0 field within the \s-1DN,\s0 as suggested by -RFCs, regardless the contents of the request' subject the \fB\-noemailDN\fR -option can be used. The behaviour should be more friendly and -configurable. -.PP -Canceling some commands by refusing to certify a certificate can -create an empty file. -.SH "WARNINGS" -.IX Header "WARNINGS" -This command was originally meant as an example of how to do things in a \s-1CA.\s0 -Its code does not have production quality. -It was not supposed to be used as a full blown \s-1CA\s0 itself, -nevertheless some people are using it for this purpose at least internally. -When doing so, specific care should be taken to -properly secure the private key(s) used for signing certificates. -It is advisable to keep them in a secure \s-1HW\s0 storage such as a smart card or \s-1HSM\s0 -and access them via a suitable engine or crypto provider. -.PP -This command is effectively a single user command: no locking -is done on the various files and attempts to run more than one \fBopenssl ca\fR -command on the same database can have unpredictable results. -.PP -The \fBcopy_extensions\fR option should be used with caution. If care is -not taken then it can be a security risk. For example if a certificate -request contains a basicConstraints extension with \s-1CA:TRUE\s0 and the -\&\fBcopy_extensions\fR value is set to \fBcopyall\fR and the user does not spot -this when the certificate is displayed then this will hand the requester -a valid \s-1CA\s0 certificate. -This situation can be avoided by setting \fBcopy_extensions\fR to \fBcopy\fR -and including basicConstraints with \s-1CA:FALSE\s0 in the configuration file. -Then if the request contains a basicConstraints extension it will be -ignored. -.PP -It is advisable to also include values for other extensions such -as \fBkeyUsage\fR to prevent a request supplying its own values. -.PP -Additional restrictions can be placed on the \s-1CA\s0 certificate itself. -For example if the \s-1CA\s0 certificate has: -.PP -.Vb 1 -\& basicConstraints = CA:TRUE, pathlen:0 -.Ve -.PP -then even if a certificate is issued with \s-1CA:TRUE\s0 it will not be valid. -.SH "HISTORY" -.IX Header "HISTORY" -Since OpenSSL 1.1.1, the program follows \s-1RFC5280.\s0 Specifically, -certificate validity period (specified by any of \fB\-startdate\fR, -\&\fB\-enddate\fR and \fB\-days\fR) and \s-1CRL\s0 last/next update time (specified by -any of \fB\-crl_lastupdate\fR, \fB\-crl_nextupdate\fR, \fB\-crldays\fR, \fB\-crlhours\fR -and \fB\-crlsec\fR) will be encoded as UTCTime if the dates are -earlier than year 2049 (included), and as GeneralizedTime if the dates -are in year 2050 or later. -.PP -OpenSSL 1.1.1 introduced a new random generator (\s-1CSPRNG\s0) with an improved -seeding mechanism. The new seeding mechanism makes it unnecessary to -define a \s-1RANDFILE\s0 for saving and restoring randomness. This option is -retained mainly for compatibility reasons. -.PP -The \fB\-section\fR option was added in OpenSSL 3.0.0. -.PP -The \fB\-multivalue\-rdn\fR option has become obsolete in OpenSSL 3.0.0 and -has no effect. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -Since OpenSSL 3.2, generated certificates bear X.509 version 3, -and key identifier extensions are included by default. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-req\fR\|(1), -\&\fBopenssl\-spkac\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -\&\s-1\fBCA\s0.pl\fR\|(1), -\&\fBconfig\fR\|(5), -\&\fBx509v3_config\fR\|(5) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-ciphers.1ossl b/openssl-install/share/man/man1/openssl-ciphers.1ossl deleted file mode 100644 index 70333034..00000000 --- a/openssl-install/share/man/man1/openssl-ciphers.1ossl +++ /dev/null @@ -1,926 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CIPHERS 1ossl" -.TH OPENSSL-CIPHERS 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-ciphers \- SSL cipher display and cipher list command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBciphers\fR -[\fB\-help\fR] -[\fB\-s\fR] -[\fB\-v\fR] -[\fB\-V\fR] -[\fB\-ssl3\fR] -[\fB\-tls1\fR] -[\fB\-tls1_1\fR] -[\fB\-tls1_2\fR] -[\fB\-tls1_3\fR] -[\fB\-s\fR] -[\fB\-psk\fR] -[\fB\-srp\fR] -[\fB\-stdname\fR] -[\fB\-convert\fR \fIname\fR] -[\fB\-ciphersuites\fR \fIval\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIcipherlist\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command converts textual OpenSSL cipher lists into -ordered \s-1SSL\s0 cipher preference lists. It can be used to -determine the appropriate cipherlist. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print a usage message. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-s\fR" 4 -.IX Item "-s" -Only list supported ciphers: those consistent with the security level, and -minimum and maximum protocol version. This is closer to the actual cipher list -an application will support. -.Sp -\&\s-1PSK\s0 and \s-1SRP\s0 ciphers are not enabled by default: they require \fB\-psk\fR or \fB\-srp\fR -to enable them. -.Sp -It also does not change the default list of supported signature algorithms. -.Sp -On a server the list of supported ciphers might also exclude other ciphers -depending on the configured certificates and presence of \s-1DH\s0 parameters. -.Sp -If this option is not used then all ciphers that match the cipherlist will be -listed. -.IP "\fB\-psk\fR" 4 -.IX Item "-psk" -When combined with \fB\-s\fR includes cipher suites which require \s-1PSK.\s0 -.IP "\fB\-srp\fR" 4 -.IX Item "-srp" -When combined with \fB\-s\fR includes cipher suites which require \s-1SRP.\s0 This option -is deprecated. -.IP "\fB\-v\fR" 4 -.IX Item "-v" -Verbose output: For each cipher suite, list details as provided by -\&\fBSSL_CIPHER_description\fR\|(3). -.IP "\fB\-V\fR" 4 -.IX Item "-V" -Like \fB\-v\fR, but include the official cipher suite values in hex. -.IP "\fB\-tls1_3\fR, \fB\-tls1_2\fR, \fB\-tls1_1\fR, \fB\-tls1\fR, \fB\-ssl3\fR" 4 -.IX Item "-tls1_3, -tls1_2, -tls1_1, -tls1, -ssl3" -In combination with the \fB\-s\fR option, list the ciphers which could be used if -the specified protocol were negotiated. -Note that not all protocols and flags may be available, depending on how -OpenSSL was built. -.IP "\fB\-stdname\fR" 4 -.IX Item "-stdname" -Precede each cipher suite by its standard name. -.IP "\fB\-convert\fR \fIname\fR" 4 -.IX Item "-convert name" -Convert a standard cipher \fIname\fR to its OpenSSL name. -.IP "\fB\-ciphersuites\fR \fIval\fR" 4 -.IX Item "-ciphersuites val" -Sets the list of TLSv1.3 ciphersuites. This list will be combined with any -TLSv1.2 and below ciphersuites that have been configured. The format for this -list is a simple colon (\*(L":\*(R") separated list of TLSv1.3 ciphersuite names. By -default this value is: -.Sp -.Vb 1 -\& TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256 -.Ve -.IP "\fBcipherlist\fR" 4 -.IX Item "cipherlist" -A cipher list of TLSv1.2 and below ciphersuites to convert to a cipher -preference list. This list will be combined with any TLSv1.3 ciphersuites that -have been configured. If it is not included then the default cipher list will be -used. The format is described below. -.SH "CIPHER LIST FORMAT" -.IX Header "CIPHER LIST FORMAT" -The cipher list consists of one or more \fIcipher strings\fR separated by colons. -Commas or spaces are also acceptable separators but colons are normally used. -.PP -The cipher string may reference a cipher using its standard name from -the \s-1IANA TLS\s0 Cipher Suites Registry -(). -.PP -The actual cipher string can take several different forms. -.PP -It can consist of a single cipher suite such as \fB\s-1RC4\-SHA\s0\fR. -.PP -It can represent a list of cipher suites containing a certain algorithm, or -cipher suites of a certain type. For example \fB\s-1SHA1\s0\fR represents all ciphers -suites using the digest algorithm \s-1SHA1\s0 and \fBSSLv3\fR represents all \s-1SSL\s0 v3 -algorithms. -.PP -Lists of cipher suites can be combined in a single cipher string using the -\&\fB+\fR character. This is used as a logical \fBand\fR operation. For example -\&\fB\s-1SHA1+DES\s0\fR represents all cipher suites containing the \s-1SHA1\s0 \fBand\fR the \s-1DES\s0 -algorithms. -.PP -Each cipher string can be optionally preceded by the characters \fB!\fR, -\&\fB\-\fR or \fB+\fR. -.PP -If \fB!\fR is used then the ciphers are permanently deleted from the list. -The ciphers deleted can never reappear in the list even if they are -explicitly stated. -.PP -If \fB\-\fR is used then the ciphers are deleted from the list, but some or -all of the ciphers can be added again by later options. -.PP -If \fB+\fR is used then the ciphers are moved to the end of the list. This -option doesn't add any new ciphers it just moves matching existing ones. -.PP -If none of these characters is present then the string is just interpreted -as a list of ciphers to be appended to the current preference list. If the -list includes any ciphers already present they will be ignored: that is they -will not moved to the end of the list. -.PP -The cipher string \fB\f(CB@STRENGTH\fB\fR can be used at any point to sort the current -cipher list in order of encryption algorithm key length. -.PP -The cipher string \fB\f(CB@SECLEVEL\fB\fR=\fIn\fR can be used at any point to set the security -level to \fIn\fR, which should be a number between zero and five, inclusive. -See \fBSSL_CTX_set_security_level\fR\|(3) for a description of what each level means. -.PP -The cipher list can be prefixed with the \fB\s-1DEFAULT\s0\fR keyword, which enables -the default cipher list as defined below. Unlike cipher strings, -this prefix may not be combined with other strings using \fB+\fR character. -For example, \fB\s-1DEFAULT+DES\s0\fR is not valid. -.PP -The content of the default list is determined at compile time and normally -corresponds to \fB\s-1ALL:\s0!COMPLEMENTOFDEFAULT:!eNULL\fR. -.SH "CIPHER STRINGS" -.IX Header "CIPHER STRINGS" -The following is a list of all permitted cipher strings and their meanings. -.IP "\fB\s-1COMPLEMENTOFDEFAULT\s0\fR" 4 -.IX Item "COMPLEMENTOFDEFAULT" -The ciphers included in \fB\s-1ALL\s0\fR, but not enabled by default. Currently -this includes all \s-1RC4\s0 and anonymous ciphers. Note that this rule does -not cover \fBeNULL\fR, which is not included by \fB\s-1ALL\s0\fR (use \fB\s-1COMPLEMENTOFALL\s0\fR if -necessary). Note that \s-1RC4\s0 based cipher suites are not built into OpenSSL by -default (see the enable-weak-ssl-ciphers option to Configure). -.IP "\fB\s-1ALL\s0\fR" 4 -.IX Item "ALL" -All cipher suites except the \fBeNULL\fR ciphers (which must be explicitly enabled -if needed). -As of OpenSSL 1.0.0, the \fB\s-1ALL\s0\fR cipher suites are sensibly ordered by default. -.IP "\fB\s-1COMPLEMENTOFALL\s0\fR" 4 -.IX Item "COMPLEMENTOFALL" -The cipher suites not enabled by \fB\s-1ALL\s0\fR, currently \fBeNULL\fR. -.IP "\fB\s-1HIGH\s0\fR" 4 -.IX Item "HIGH" -\&\*(L"High\*(R" encryption cipher suites. This currently means those with key lengths -larger than 128 bits, and some cipher suites with 128\-bit keys. -.IP "\fB\s-1MEDIUM\s0\fR" 4 -.IX Item "MEDIUM" -\&\*(L"Medium\*(R" encryption cipher suites, currently some of those using 128 bit -encryption. -.IP "\fB\s-1LOW\s0\fR" 4 -.IX Item "LOW" -\&\*(L"Low\*(R" encryption cipher suites, currently those using 64 or 56 bit -encryption algorithms but excluding export cipher suites. All these -cipher suites have been removed as of OpenSSL 1.1.0. -.IP "\fBeNULL\fR, \fB\s-1NULL\s0\fR" 4 -.IX Item "eNULL, NULL" -The \*(L"\s-1NULL\*(R"\s0 ciphers that is those offering no encryption. Because these offer no -encryption at all and are a security risk they are not enabled via either the -\&\fB\s-1DEFAULT\s0\fR or \fB\s-1ALL\s0\fR cipher strings. -Be careful when building cipherlists out of lower-level primitives such as -\&\fBkRSA\fR or \fBaECDSA\fR as these do overlap with the \fBeNULL\fR ciphers. When in -doubt, include \fB!eNULL\fR in your cipherlist. -.IP "\fBaNULL\fR" 4 -.IX Item "aNULL" -The cipher suites offering no authentication. This is currently the anonymous -\&\s-1DH\s0 algorithms and anonymous \s-1ECDH\s0 algorithms. These cipher suites are vulnerable -to \*(L"man in the middle\*(R" attacks and so their use is discouraged. -These are excluded from the \fB\s-1DEFAULT\s0\fR ciphers, but included in the \fB\s-1ALL\s0\fR -ciphers. -Be careful when building cipherlists out of lower-level primitives such as -\&\fBkDHE\fR or \fB\s-1AES\s0\fR as these do overlap with the \fBaNULL\fR ciphers. -When in doubt, include \fB!aNULL\fR in your cipherlist. -.IP "\fBkRSA\fR, \fBaRSA\fR, \fB\s-1RSA\s0\fR" 4 -.IX Item "kRSA, aRSA, RSA" -Cipher suites using \s-1RSA\s0 key exchange or authentication. \fB\s-1RSA\s0\fR is an alias for -\&\fBkRSA\fR. -.IP "\fBkDHr\fR, \fBkDHd\fR, \fBkDH\fR" 4 -.IX Item "kDHr, kDHd, kDH" -Cipher suites using static \s-1DH\s0 key agreement and \s-1DH\s0 certificates signed by CAs -with \s-1RSA\s0 and \s-1DSS\s0 keys or either respectively. -All these cipher suites have been removed in OpenSSL 1.1.0. -.IP "\fBkDHE\fR, \fBkEDH\fR, \fB\s-1DH\s0\fR" 4 -.IX Item "kDHE, kEDH, DH" -Cipher suites using ephemeral \s-1DH\s0 key agreement, including anonymous cipher -suites. -.IP "\fB\s-1DHE\s0\fR, \fB\s-1EDH\s0\fR" 4 -.IX Item "DHE, EDH" -Cipher suites using authenticated ephemeral \s-1DH\s0 key agreement. -.IP "\fB\s-1ADH\s0\fR" 4 -.IX Item "ADH" -Anonymous \s-1DH\s0 cipher suites, note that this does not include anonymous Elliptic -Curve \s-1DH\s0 (\s-1ECDH\s0) cipher suites. -.IP "\fBkEECDH\fR, \fBkECDHE\fR, \fB\s-1ECDH\s0\fR" 4 -.IX Item "kEECDH, kECDHE, ECDH" -Cipher suites using ephemeral \s-1ECDH\s0 key agreement, including anonymous -cipher suites. -.IP "\fB\s-1ECDHE\s0\fR, \fB\s-1EECDH\s0\fR" 4 -.IX Item "ECDHE, EECDH" -Cipher suites using authenticated ephemeral \s-1ECDH\s0 key agreement. -.IP "\fB\s-1AECDH\s0\fR" 4 -.IX Item "AECDH" -Anonymous Elliptic Curve Diffie-Hellman cipher suites. -.IP "\fBaDSS\fR, \fB\s-1DSS\s0\fR" 4 -.IX Item "aDSS, DSS" -Cipher suites using \s-1DSS\s0 authentication, i.e. the certificates carry \s-1DSS\s0 keys. -.IP "\fBaDH\fR" 4 -.IX Item "aDH" -Cipher suites effectively using \s-1DH\s0 authentication, i.e. the certificates carry -\&\s-1DH\s0 keys. -All these cipher suites have been removed in OpenSSL 1.1.0. -.IP "\fBaECDSA\fR, \fB\s-1ECDSA\s0\fR" 4 -.IX Item "aECDSA, ECDSA" -Cipher suites using \s-1ECDSA\s0 authentication, i.e. the certificates carry \s-1ECDSA\s0 -keys. -.IP "\fBTLSv1.2\fR, \fBTLSv1.0\fR, \fBSSLv3\fR" 4 -.IX Item "TLSv1.2, TLSv1.0, SSLv3" -Lists cipher suites which are only supported in at least \s-1TLS\s0 v1.2, \s-1TLS\s0 v1.0 or -\&\s-1SSL\s0 v3.0 respectively. -Note: there are no cipher suites specific to \s-1TLS\s0 v1.1. -Since this is only the minimum version, if, for example, TLSv1.0 is negotiated -then both TLSv1.0 and SSLv3.0 cipher suites are available. -.Sp -Note: these cipher strings \fBdo not\fR change the negotiated version of \s-1SSL\s0 or -\&\s-1TLS,\s0 they only affect the list of available cipher suites. -.IP "\fB\s-1AES128\s0\fR, \fB\s-1AES256\s0\fR, \fB\s-1AES\s0\fR" 4 -.IX Item "AES128, AES256, AES" -cipher suites using 128 bit \s-1AES, 256\s0 bit \s-1AES\s0 or either 128 or 256 bit \s-1AES.\s0 -.IP "\fB\s-1AESGCM\s0\fR" 4 -.IX Item "AESGCM" -\&\s-1AES\s0 in Galois Counter Mode (\s-1GCM\s0): these cipher suites are only supported -in \s-1TLS\s0 v1.2. -.IP "\fB\s-1AESCCM\s0\fR, \fB\s-1AESCCM8\s0\fR" 4 -.IX Item "AESCCM, AESCCM8" -\&\s-1AES\s0 in Cipher Block Chaining \- Message Authentication Mode (\s-1CCM\s0): these -cipher suites are only supported in \s-1TLS\s0 v1.2. \fB\s-1AESCCM\s0\fR references \s-1CCM\s0 -cipher suites using both 16 and 8 octet Integrity Check Value (\s-1ICV\s0) -while \fB\s-1AESCCM8\s0\fR only references 8 octet \s-1ICV.\s0 -.IP "\fB\s-1ARIA128\s0\fR, \fB\s-1ARIA256\s0\fR, \fB\s-1ARIA\s0\fR" 4 -.IX Item "ARIA128, ARIA256, ARIA" -Cipher suites using 128 bit \s-1ARIA, 256\s0 bit \s-1ARIA\s0 or either 128 or 256 bit -\&\s-1ARIA.\s0 -.IP "\fB\s-1CAMELLIA128\s0\fR, \fB\s-1CAMELLIA256\s0\fR, \fB\s-1CAMELLIA\s0\fR" 4 -.IX Item "CAMELLIA128, CAMELLIA256, CAMELLIA" -Cipher suites using 128 bit \s-1CAMELLIA, 256\s0 bit \s-1CAMELLIA\s0 or either 128 or 256 bit -\&\s-1CAMELLIA.\s0 -.IP "\fB\s-1CHACHA20\s0\fR" 4 -.IX Item "CHACHA20" -Cipher suites using ChaCha20. -.IP "\fB3DES\fR" 4 -.IX Item "3DES" -Cipher suites using triple \s-1DES.\s0 -.IP "\fB\s-1DES\s0\fR" 4 -.IX Item "DES" -Cipher suites using \s-1DES\s0 (not triple \s-1DES\s0). -All these cipher suites have been removed in OpenSSL 1.1.0. -.IP "\fB\s-1RC4\s0\fR" 4 -.IX Item "RC4" -Cipher suites using \s-1RC4.\s0 -.IP "\fB\s-1RC2\s0\fR" 4 -.IX Item "RC2" -Cipher suites using \s-1RC2.\s0 -.IP "\fB\s-1IDEA\s0\fR" 4 -.IX Item "IDEA" -Cipher suites using \s-1IDEA.\s0 -.IP "\fB\s-1SEED\s0\fR" 4 -.IX Item "SEED" -Cipher suites using \s-1SEED.\s0 -.IP "\fB\s-1MD5\s0\fR" 4 -.IX Item "MD5" -Cipher suites using \s-1MD5.\s0 -.IP "\fB\s-1SHA1\s0\fR, \fB\s-1SHA\s0\fR" 4 -.IX Item "SHA1, SHA" -Cipher suites using \s-1SHA1.\s0 -.IP "\fB\s-1SHA256\s0\fR, \fB\s-1SHA384\s0\fR" 4 -.IX Item "SHA256, SHA384" -Cipher suites using \s-1SHA256\s0 or \s-1SHA384.\s0 -.IP "\fBaGOST\fR" 4 -.IX Item "aGOST" -Cipher suites using \s-1GOST R 34.10\s0 (either 2001 or 94) for authentication -(needs an engine supporting \s-1GOST\s0 algorithms). -.IP "\fBaGOST01\fR" 4 -.IX Item "aGOST01" -Cipher suites using \s-1GOST R 34.10\-2001\s0 authentication. -.IP "\fBkGOST\fR" 4 -.IX Item "kGOST" -Cipher suites, using \s-1VKO 34.10\s0 key exchange, specified in the \s-1RFC 4357.\s0 -.IP "\fB\s-1GOST94\s0\fR" 4 -.IX Item "GOST94" -Cipher suites, using \s-1HMAC\s0 based on \s-1GOST R 34.11\-94.\s0 -.IP "\fB\s-1GOST89MAC\s0\fR" 4 -.IX Item "GOST89MAC" -Cipher suites using \s-1GOST 28147\-89 MAC\s0 \fBinstead of\fR \s-1HMAC.\s0 -.IP "\fB\s-1PSK\s0\fR" 4 -.IX Item "PSK" -All cipher suites using pre-shared keys (\s-1PSK\s0). -.IP "\fBkPSK\fR, \fBkECDHEPSK\fR, \fBkDHEPSK\fR, \fBkRSAPSK\fR" 4 -.IX Item "kPSK, kECDHEPSK, kDHEPSK, kRSAPSK" -Cipher suites using \s-1PSK\s0 key exchange, \s-1ECDHE_PSK, DHE_PSK\s0 or \s-1RSA_PSK.\s0 -.IP "\fBaPSK\fR" 4 -.IX Item "aPSK" -Cipher suites using \s-1PSK\s0 authentication (currently all \s-1PSK\s0 modes apart from -\&\s-1RSA_PSK\s0). -.IP "\fB\s-1SUITEB128\s0\fR, \fB\s-1SUITEB128ONLY\s0\fR, \fB\s-1SUITEB192\s0\fR" 4 -.IX Item "SUITEB128, SUITEB128ONLY, SUITEB192" -Enables suite B mode of operation using 128 (permitting 192 bit mode by peer) -128 bit (not permitting 192 bit by peer) or 192 bit level of security -respectively. -If used these cipherstrings should appear first in the cipher -list and anything after them is ignored. -Setting Suite B mode has additional consequences required to comply with -\&\s-1RFC6460.\s0 -In particular the supported signature algorithms is reduced to support only -\&\s-1ECDSA\s0 and \s-1SHA256\s0 or \s-1SHA384,\s0 only the elliptic curves P\-256 and P\-384 can be -used and only the two suite B compliant cipher suites -(\s-1ECDHE\-ECDSA\-AES128\-GCM\-SHA256\s0 and \s-1ECDHE\-ECDSA\-AES256\-GCM\-SHA384\s0) are -permissible. -.IP "\fB\s-1CBC\s0\fR" 4 -.IX Item "CBC" -All cipher suites using encryption algorithm in Cipher Block Chaining (\s-1CBC\s0) -mode. These cipher suites are only supported in \s-1TLS\s0 v1.2 and earlier. Currently -it's an alias for the following cipherstrings: \fB\s-1SSL_DES\s0\fR, \fB\s-1SSL_3DES\s0\fR, \fB\s-1SSL_RC2\s0\fR, -\&\fB\s-1SSL_IDEA\s0\fR, \fB\s-1SSL_AES128\s0\fR, \fB\s-1SSL_AES256\s0\fR, \fB\s-1SSL_CAMELLIA128\s0\fR, \fB\s-1SSL_CAMELLIA256\s0\fR, \fB\s-1SSL_SEED\s0\fR. -.SH "CIPHER SUITE NAMES" -.IX Header "CIPHER SUITE NAMES" -The following lists give the standard \s-1SSL\s0 or \s-1TLS\s0 cipher suites names from the -relevant specification and their OpenSSL equivalents. You can use either -standard names or OpenSSL names in cipher lists, or a mix of both. -.PP -It should be noted, that several cipher suite names do not include the -authentication used, e.g. \s-1DES\-CBC3\-SHA.\s0 In these cases, \s-1RSA\s0 authentication -is used. -.SS "\s-1SSL\s0 v3.0 cipher suites" -.IX Subsection "SSL v3.0 cipher suites" -.Vb 6 -\& SSL_RSA_WITH_NULL_MD5 NULL\-MD5 -\& SSL_RSA_WITH_NULL_SHA NULL\-SHA -\& SSL_RSA_WITH_RC4_128_MD5 RC4\-MD5 -\& SSL_RSA_WITH_RC4_128_SHA RC4\-SHA -\& SSL_RSA_WITH_IDEA_CBC_SHA IDEA\-CBC\-SHA -\& SSL_RSA_WITH_3DES_EDE_CBC_SHA DES\-CBC3\-SHA -\& -\& SSL_DH_DSS_WITH_3DES_EDE_CBC_SHA DH\-DSS\-DES\-CBC3\-SHA -\& SSL_DH_RSA_WITH_3DES_EDE_CBC_SHA DH\-RSA\-DES\-CBC3\-SHA -\& SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA DHE\-DSS\-DES\-CBC3\-SHA -\& SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA DHE\-RSA\-DES\-CBC3\-SHA -\& -\& SSL_DH_anon_WITH_RC4_128_MD5 ADH\-RC4\-MD5 -\& SSL_DH_anon_WITH_3DES_EDE_CBC_SHA ADH\-DES\-CBC3\-SHA -\& -\& SSL_FORTEZZA_KEA_WITH_NULL_SHA Not implemented. -\& SSL_FORTEZZA_KEA_WITH_FORTEZZA_CBC_SHA Not implemented. -\& SSL_FORTEZZA_KEA_WITH_RC4_128_SHA Not implemented. -.Ve -.SS "\s-1TLS\s0 v1.0 cipher suites" -.IX Subsection "TLS v1.0 cipher suites" -.Vb 6 -\& TLS_RSA_WITH_NULL_MD5 NULL\-MD5 -\& TLS_RSA_WITH_NULL_SHA NULL\-SHA -\& TLS_RSA_WITH_RC4_128_MD5 RC4\-MD5 -\& TLS_RSA_WITH_RC4_128_SHA RC4\-SHA -\& TLS_RSA_WITH_IDEA_CBC_SHA IDEA\-CBC\-SHA -\& TLS_RSA_WITH_3DES_EDE_CBC_SHA DES\-CBC3\-SHA -\& -\& TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA Not implemented. -\& TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA Not implemented. -\& TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA DHE\-DSS\-DES\-CBC3\-SHA -\& TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA DHE\-RSA\-DES\-CBC3\-SHA -\& -\& TLS_DH_anon_WITH_RC4_128_MD5 ADH\-RC4\-MD5 -\& TLS_DH_anon_WITH_3DES_EDE_CBC_SHA ADH\-DES\-CBC3\-SHA -.Ve -.SS "\s-1AES\s0 cipher suites from \s-1RFC3268,\s0 extending \s-1TLS\s0 v1.0" -.IX Subsection "AES cipher suites from RFC3268, extending TLS v1.0" -.Vb 2 -\& TLS_RSA_WITH_AES_128_CBC_SHA AES128\-SHA -\& TLS_RSA_WITH_AES_256_CBC_SHA AES256\-SHA -\& -\& TLS_DH_DSS_WITH_AES_128_CBC_SHA DH\-DSS\-AES128\-SHA -\& TLS_DH_DSS_WITH_AES_256_CBC_SHA DH\-DSS\-AES256\-SHA -\& TLS_DH_RSA_WITH_AES_128_CBC_SHA DH\-RSA\-AES128\-SHA -\& TLS_DH_RSA_WITH_AES_256_CBC_SHA DH\-RSA\-AES256\-SHA -\& -\& TLS_DHE_DSS_WITH_AES_128_CBC_SHA DHE\-DSS\-AES128\-SHA -\& TLS_DHE_DSS_WITH_AES_256_CBC_SHA DHE\-DSS\-AES256\-SHA -\& TLS_DHE_RSA_WITH_AES_128_CBC_SHA DHE\-RSA\-AES128\-SHA -\& TLS_DHE_RSA_WITH_AES_256_CBC_SHA DHE\-RSA\-AES256\-SHA -\& -\& TLS_DH_anon_WITH_AES_128_CBC_SHA ADH\-AES128\-SHA -\& TLS_DH_anon_WITH_AES_256_CBC_SHA ADH\-AES256\-SHA -.Ve -.SS "Camellia cipher suites from \s-1RFC4132,\s0 extending \s-1TLS\s0 v1.0" -.IX Subsection "Camellia cipher suites from RFC4132, extending TLS v1.0" -.Vb 2 -\& TLS_RSA_WITH_CAMELLIA_128_CBC_SHA CAMELLIA128\-SHA -\& TLS_RSA_WITH_CAMELLIA_256_CBC_SHA CAMELLIA256\-SHA -\& -\& TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA DH\-DSS\-CAMELLIA128\-SHA -\& TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA DH\-DSS\-CAMELLIA256\-SHA -\& TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA DH\-RSA\-CAMELLIA128\-SHA -\& TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA DH\-RSA\-CAMELLIA256\-SHA -\& -\& TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA DHE\-DSS\-CAMELLIA128\-SHA -\& TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA DHE\-DSS\-CAMELLIA256\-SHA -\& TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA DHE\-RSA\-CAMELLIA128\-SHA -\& TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA DHE\-RSA\-CAMELLIA256\-SHA -\& -\& TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA ADH\-CAMELLIA128\-SHA -\& TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA ADH\-CAMELLIA256\-SHA -.Ve -.SS "\s-1SEED\s0 cipher suites from \s-1RFC4162,\s0 extending \s-1TLS\s0 v1.0" -.IX Subsection "SEED cipher suites from RFC4162, extending TLS v1.0" -.Vb 1 -\& TLS_RSA_WITH_SEED_CBC_SHA SEED\-SHA -\& -\& TLS_DH_DSS_WITH_SEED_CBC_SHA DH\-DSS\-SEED\-SHA -\& TLS_DH_RSA_WITH_SEED_CBC_SHA DH\-RSA\-SEED\-SHA -\& -\& TLS_DHE_DSS_WITH_SEED_CBC_SHA DHE\-DSS\-SEED\-SHA -\& TLS_DHE_RSA_WITH_SEED_CBC_SHA DHE\-RSA\-SEED\-SHA -\& -\& TLS_DH_anon_WITH_SEED_CBC_SHA ADH\-SEED\-SHA -.Ve -.SS "\s-1GOST\s0 cipher suites from draft-chudov-cryptopro-cptls, extending \s-1TLS\s0 v1.0" -.IX Subsection "GOST cipher suites from draft-chudov-cryptopro-cptls, extending TLS v1.0" -Note: these ciphers require an engine which including \s-1GOST\s0 cryptographic -algorithms, such as the \fBgost\fR engine, which isn't part of the OpenSSL -distribution. -.PP -.Vb 4 -\& TLS_GOSTR341094_WITH_28147_CNT_IMIT GOST94\-GOST89\-GOST89 -\& TLS_GOSTR341001_WITH_28147_CNT_IMIT GOST2001\-GOST89\-GOST89 -\& TLS_GOSTR341094_WITH_NULL_GOSTR3411 GOST94\-NULL\-GOST94 -\& TLS_GOSTR341001_WITH_NULL_GOSTR3411 GOST2001\-NULL\-GOST94 -.Ve -.SS "\s-1GOST\s0 cipher suites, extending \s-1TLS\s0 v1.2" -.IX Subsection "GOST cipher suites, extending TLS v1.2" -Note: these ciphers require an engine which including \s-1GOST\s0 cryptographic -algorithms, such as the \fBgost\fR engine, which isn't part of the OpenSSL -distribution. -.PP -.Vb 2 -\& TLS_GOSTR341112_256_WITH_28147_CNT_IMIT GOST2012\-GOST8912\-GOST8912 -\& TLS_GOSTR341112_256_WITH_NULL_GOSTR3411 GOST2012\-NULL\-GOST12 -.Ve -.PP -Note: \s-1GOST2012\-GOST8912\-GOST8912\s0 is an alias for two ciphers \s-1ID\s0 -old \s-1LEGACY\-GOST2012\-GOST8912\-GOST8912\s0 and new \s-1IANA\-GOST2012\-GOST8912\-GOST8912\s0 -.SS "Additional Export 1024 and other cipher suites" -.IX Subsection "Additional Export 1024 and other cipher suites" -Note: these ciphers can also be used in \s-1SSL\s0 v3. -.PP -.Vb 1 -\& TLS_DHE_DSS_WITH_RC4_128_SHA DHE\-DSS\-RC4\-SHA -.Ve -.SS "Elliptic curve cipher suites" -.IX Subsection "Elliptic curve cipher suites" -.Vb 5 -\& TLS_ECDHE_RSA_WITH_NULL_SHA ECDHE\-RSA\-NULL\-SHA -\& TLS_ECDHE_RSA_WITH_RC4_128_SHA ECDHE\-RSA\-RC4\-SHA -\& TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA ECDHE\-RSA\-DES\-CBC3\-SHA -\& TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA ECDHE\-RSA\-AES128\-SHA -\& TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA ECDHE\-RSA\-AES256\-SHA -\& -\& TLS_ECDHE_ECDSA_WITH_NULL_SHA ECDHE\-ECDSA\-NULL\-SHA -\& TLS_ECDHE_ECDSA_WITH_RC4_128_SHA ECDHE\-ECDSA\-RC4\-SHA -\& TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA ECDHE\-ECDSA\-DES\-CBC3\-SHA -\& TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA ECDHE\-ECDSA\-AES128\-SHA -\& TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA ECDHE\-ECDSA\-AES256\-SHA -\& -\& TLS_ECDH_anon_WITH_NULL_SHA AECDH\-NULL\-SHA -\& TLS_ECDH_anon_WITH_RC4_128_SHA AECDH\-RC4\-SHA -\& TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA AECDH\-DES\-CBC3\-SHA -\& TLS_ECDH_anon_WITH_AES_128_CBC_SHA AECDH\-AES128\-SHA -\& TLS_ECDH_anon_WITH_AES_256_CBC_SHA AECDH\-AES256\-SHA -.Ve -.SS "\s-1TLS\s0 v1.2 cipher suites" -.IX Subsection "TLS v1.2 cipher suites" -.Vb 1 -\& TLS_RSA_WITH_NULL_SHA256 NULL\-SHA256 -\& -\& TLS_RSA_WITH_AES_128_CBC_SHA256 AES128\-SHA256 -\& TLS_RSA_WITH_AES_256_CBC_SHA256 AES256\-SHA256 -\& TLS_RSA_WITH_AES_128_GCM_SHA256 AES128\-GCM\-SHA256 -\& TLS_RSA_WITH_AES_256_GCM_SHA384 AES256\-GCM\-SHA384 -\& -\& TLS_DH_RSA_WITH_AES_128_CBC_SHA256 DH\-RSA\-AES128\-SHA256 -\& TLS_DH_RSA_WITH_AES_256_CBC_SHA256 DH\-RSA\-AES256\-SHA256 -\& TLS_DH_RSA_WITH_AES_128_GCM_SHA256 DH\-RSA\-AES128\-GCM\-SHA256 -\& TLS_DH_RSA_WITH_AES_256_GCM_SHA384 DH\-RSA\-AES256\-GCM\-SHA384 -\& -\& TLS_DH_DSS_WITH_AES_128_CBC_SHA256 DH\-DSS\-AES128\-SHA256 -\& TLS_DH_DSS_WITH_AES_256_CBC_SHA256 DH\-DSS\-AES256\-SHA256 -\& TLS_DH_DSS_WITH_AES_128_GCM_SHA256 DH\-DSS\-AES128\-GCM\-SHA256 -\& TLS_DH_DSS_WITH_AES_256_GCM_SHA384 DH\-DSS\-AES256\-GCM\-SHA384 -\& -\& TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 DHE\-RSA\-AES128\-SHA256 -\& TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 DHE\-RSA\-AES256\-SHA256 -\& TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 DHE\-RSA\-AES128\-GCM\-SHA256 -\& TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 DHE\-RSA\-AES256\-GCM\-SHA384 -\& -\& TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 DHE\-DSS\-AES128\-SHA256 -\& TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 DHE\-DSS\-AES256\-SHA256 -\& TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 DHE\-DSS\-AES128\-GCM\-SHA256 -\& TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 DHE\-DSS\-AES256\-GCM\-SHA384 -\& -\& TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDHE\-RSA\-AES128\-SHA256 -\& TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDHE\-RSA\-AES256\-SHA384 -\& TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDHE\-RSA\-AES128\-GCM\-SHA256 -\& TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDHE\-RSA\-AES256\-GCM\-SHA384 -\& -\& TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 ECDHE\-ECDSA\-AES128\-SHA256 -\& TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 ECDHE\-ECDSA\-AES256\-SHA384 -\& TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 ECDHE\-ECDSA\-AES128\-GCM\-SHA256 -\& TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 ECDHE\-ECDSA\-AES256\-GCM\-SHA384 -\& -\& TLS_DH_anon_WITH_AES_128_CBC_SHA256 ADH\-AES128\-SHA256 -\& TLS_DH_anon_WITH_AES_256_CBC_SHA256 ADH\-AES256\-SHA256 -\& TLS_DH_anon_WITH_AES_128_GCM_SHA256 ADH\-AES128\-GCM\-SHA256 -\& TLS_DH_anon_WITH_AES_256_GCM_SHA384 ADH\-AES256\-GCM\-SHA384 -\& -\& RSA_WITH_AES_128_CCM AES128\-CCM -\& RSA_WITH_AES_256_CCM AES256\-CCM -\& DHE_RSA_WITH_AES_128_CCM DHE\-RSA\-AES128\-CCM -\& DHE_RSA_WITH_AES_256_CCM DHE\-RSA\-AES256\-CCM -\& RSA_WITH_AES_128_CCM_8 AES128\-CCM8 -\& RSA_WITH_AES_256_CCM_8 AES256\-CCM8 -\& DHE_RSA_WITH_AES_128_CCM_8 DHE\-RSA\-AES128\-CCM8 -\& DHE_RSA_WITH_AES_256_CCM_8 DHE\-RSA\-AES256\-CCM8 -\& ECDHE_ECDSA_WITH_AES_128_CCM ECDHE\-ECDSA\-AES128\-CCM -\& ECDHE_ECDSA_WITH_AES_256_CCM ECDHE\-ECDSA\-AES256\-CCM -\& ECDHE_ECDSA_WITH_AES_128_CCM_8 ECDHE\-ECDSA\-AES128\-CCM8 -\& ECDHE_ECDSA_WITH_AES_256_CCM_8 ECDHE\-ECDSA\-AES256\-CCM8 -.Ve -.SS "\s-1ARIA\s0 cipher suites from \s-1RFC6209,\s0 extending \s-1TLS\s0 v1.2" -.IX Subsection "ARIA cipher suites from RFC6209, extending TLS v1.2" -Note: the \s-1CBC\s0 modes mentioned in this \s-1RFC\s0 are not supported. -.PP -.Vb 10 -\& TLS_RSA_WITH_ARIA_128_GCM_SHA256 ARIA128\-GCM\-SHA256 -\& TLS_RSA_WITH_ARIA_256_GCM_SHA384 ARIA256\-GCM\-SHA384 -\& TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 DHE\-RSA\-ARIA128\-GCM\-SHA256 -\& TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 DHE\-RSA\-ARIA256\-GCM\-SHA384 -\& TLS_DHE_DSS_WITH_ARIA_128_GCM_SHA256 DHE\-DSS\-ARIA128\-GCM\-SHA256 -\& TLS_DHE_DSS_WITH_ARIA_256_GCM_SHA384 DHE\-DSS\-ARIA256\-GCM\-SHA384 -\& TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 ECDHE\-ECDSA\-ARIA128\-GCM\-SHA256 -\& TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 ECDHE\-ECDSA\-ARIA256\-GCM\-SHA384 -\& TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 ECDHE\-ARIA128\-GCM\-SHA256 -\& TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 ECDHE\-ARIA256\-GCM\-SHA384 -\& TLS_PSK_WITH_ARIA_128_GCM_SHA256 PSK\-ARIA128\-GCM\-SHA256 -\& TLS_PSK_WITH_ARIA_256_GCM_SHA384 PSK\-ARIA256\-GCM\-SHA384 -\& TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256 DHE\-PSK\-ARIA128\-GCM\-SHA256 -\& TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384 DHE\-PSK\-ARIA256\-GCM\-SHA384 -\& TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256 RSA\-PSK\-ARIA128\-GCM\-SHA256 -\& TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384 RSA\-PSK\-ARIA256\-GCM\-SHA384 -.Ve -.SS "Camellia HMAC-Based cipher suites from \s-1RFC6367,\s0 extending \s-1TLS\s0 v1.2" -.IX Subsection "Camellia HMAC-Based cipher suites from RFC6367, extending TLS v1.2" -.Vb 4 -\& TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE\-ECDSA\-CAMELLIA128\-SHA256 -\& TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE\-ECDSA\-CAMELLIA256\-SHA384 -\& TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE\-RSA\-CAMELLIA128\-SHA256 -\& TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE\-RSA\-CAMELLIA256\-SHA384 -.Ve -.SS "Pre-shared keying (\s-1PSK\s0) cipher suites" -.IX Subsection "Pre-shared keying (PSK) cipher suites" -.Vb 3 -\& PSK_WITH_NULL_SHA PSK\-NULL\-SHA -\& DHE_PSK_WITH_NULL_SHA DHE\-PSK\-NULL\-SHA -\& RSA_PSK_WITH_NULL_SHA RSA\-PSK\-NULL\-SHA -\& -\& PSK_WITH_RC4_128_SHA PSK\-RC4\-SHA -\& PSK_WITH_3DES_EDE_CBC_SHA PSK\-3DES\-EDE\-CBC\-SHA -\& PSK_WITH_AES_128_CBC_SHA PSK\-AES128\-CBC\-SHA -\& PSK_WITH_AES_256_CBC_SHA PSK\-AES256\-CBC\-SHA -\& -\& DHE_PSK_WITH_RC4_128_SHA DHE\-PSK\-RC4\-SHA -\& DHE_PSK_WITH_3DES_EDE_CBC_SHA DHE\-PSK\-3DES\-EDE\-CBC\-SHA -\& DHE_PSK_WITH_AES_128_CBC_SHA DHE\-PSK\-AES128\-CBC\-SHA -\& DHE_PSK_WITH_AES_256_CBC_SHA DHE\-PSK\-AES256\-CBC\-SHA -\& -\& RSA_PSK_WITH_RC4_128_SHA RSA\-PSK\-RC4\-SHA -\& RSA_PSK_WITH_3DES_EDE_CBC_SHA RSA\-PSK\-3DES\-EDE\-CBC\-SHA -\& RSA_PSK_WITH_AES_128_CBC_SHA RSA\-PSK\-AES128\-CBC\-SHA -\& RSA_PSK_WITH_AES_256_CBC_SHA RSA\-PSK\-AES256\-CBC\-SHA -\& -\& PSK_WITH_AES_128_GCM_SHA256 PSK\-AES128\-GCM\-SHA256 -\& PSK_WITH_AES_256_GCM_SHA384 PSK\-AES256\-GCM\-SHA384 -\& DHE_PSK_WITH_AES_128_GCM_SHA256 DHE\-PSK\-AES128\-GCM\-SHA256 -\& DHE_PSK_WITH_AES_256_GCM_SHA384 DHE\-PSK\-AES256\-GCM\-SHA384 -\& RSA_PSK_WITH_AES_128_GCM_SHA256 RSA\-PSK\-AES128\-GCM\-SHA256 -\& RSA_PSK_WITH_AES_256_GCM_SHA384 RSA\-PSK\-AES256\-GCM\-SHA384 -\& -\& PSK_WITH_AES_128_CBC_SHA256 PSK\-AES128\-CBC\-SHA256 -\& PSK_WITH_AES_256_CBC_SHA384 PSK\-AES256\-CBC\-SHA384 -\& PSK_WITH_NULL_SHA256 PSK\-NULL\-SHA256 -\& PSK_WITH_NULL_SHA384 PSK\-NULL\-SHA384 -\& DHE_PSK_WITH_AES_128_CBC_SHA256 DHE\-PSK\-AES128\-CBC\-SHA256 -\& DHE_PSK_WITH_AES_256_CBC_SHA384 DHE\-PSK\-AES256\-CBC\-SHA384 -\& DHE_PSK_WITH_NULL_SHA256 DHE\-PSK\-NULL\-SHA256 -\& DHE_PSK_WITH_NULL_SHA384 DHE\-PSK\-NULL\-SHA384 -\& RSA_PSK_WITH_AES_128_CBC_SHA256 RSA\-PSK\-AES128\-CBC\-SHA256 -\& RSA_PSK_WITH_AES_256_CBC_SHA384 RSA\-PSK\-AES256\-CBC\-SHA384 -\& RSA_PSK_WITH_NULL_SHA256 RSA\-PSK\-NULL\-SHA256 -\& RSA_PSK_WITH_NULL_SHA384 RSA\-PSK\-NULL\-SHA384 -\& PSK_WITH_AES_128_GCM_SHA256 PSK\-AES128\-GCM\-SHA256 -\& PSK_WITH_AES_256_GCM_SHA384 PSK\-AES256\-GCM\-SHA384 -\& -\& ECDHE_PSK_WITH_RC4_128_SHA ECDHE\-PSK\-RC4\-SHA -\& ECDHE_PSK_WITH_3DES_EDE_CBC_SHA ECDHE\-PSK\-3DES\-EDE\-CBC\-SHA -\& ECDHE_PSK_WITH_AES_128_CBC_SHA ECDHE\-PSK\-AES128\-CBC\-SHA -\& ECDHE_PSK_WITH_AES_256_CBC_SHA ECDHE\-PSK\-AES256\-CBC\-SHA -\& ECDHE_PSK_WITH_AES_128_CBC_SHA256 ECDHE\-PSK\-AES128\-CBC\-SHA256 -\& ECDHE_PSK_WITH_AES_256_CBC_SHA384 ECDHE\-PSK\-AES256\-CBC\-SHA384 -\& ECDHE_PSK_WITH_NULL_SHA ECDHE\-PSK\-NULL\-SHA -\& ECDHE_PSK_WITH_NULL_SHA256 ECDHE\-PSK\-NULL\-SHA256 -\& ECDHE_PSK_WITH_NULL_SHA384 ECDHE\-PSK\-NULL\-SHA384 -\& -\& PSK_WITH_CAMELLIA_128_CBC_SHA256 PSK\-CAMELLIA128\-SHA256 -\& PSK_WITH_CAMELLIA_256_CBC_SHA384 PSK\-CAMELLIA256\-SHA384 -\& -\& DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 DHE\-PSK\-CAMELLIA128\-SHA256 -\& DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 DHE\-PSK\-CAMELLIA256\-SHA384 -\& -\& RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256 RSA\-PSK\-CAMELLIA128\-SHA256 -\& RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384 RSA\-PSK\-CAMELLIA256\-SHA384 -\& -\& ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 ECDHE\-PSK\-CAMELLIA128\-SHA256 -\& ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 ECDHE\-PSK\-CAMELLIA256\-SHA384 -\& -\& PSK_WITH_AES_128_CCM PSK\-AES128\-CCM -\& PSK_WITH_AES_256_CCM PSK\-AES256\-CCM -\& DHE_PSK_WITH_AES_128_CCM DHE\-PSK\-AES128\-CCM -\& DHE_PSK_WITH_AES_256_CCM DHE\-PSK\-AES256\-CCM -\& PSK_WITH_AES_128_CCM_8 PSK\-AES128\-CCM8 -\& PSK_WITH_AES_256_CCM_8 PSK\-AES256\-CCM8 -\& DHE_PSK_WITH_AES_128_CCM_8 DHE\-PSK\-AES128\-CCM8 -\& DHE_PSK_WITH_AES_256_CCM_8 DHE\-PSK\-AES256\-CCM8 -.Ve -.SS "ChaCha20\-Poly1305 cipher suites, extending \s-1TLS\s0 v1.2" -.IX Subsection "ChaCha20-Poly1305 cipher suites, extending TLS v1.2" -.Vb 7 -\& TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE\-RSA\-CHACHA20\-POLY1305 -\& TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE\-ECDSA\-CHACHA20\-POLY1305 -\& TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 DHE\-RSA\-CHACHA20\-POLY1305 -\& TLS_PSK_WITH_CHACHA20_POLY1305_SHA256 PSK\-CHACHA20\-POLY1305 -\& TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 ECDHE\-PSK\-CHACHA20\-POLY1305 -\& TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256 DHE\-PSK\-CHACHA20\-POLY1305 -\& TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256 RSA\-PSK\-CHACHA20\-POLY1305 -.Ve -.SS "\s-1TLS\s0 v1.3 cipher suites" -.IX Subsection "TLS v1.3 cipher suites" -.Vb 5 -\& TLS_AES_128_GCM_SHA256 TLS_AES_128_GCM_SHA256 -\& TLS_AES_256_GCM_SHA384 TLS_AES_256_GCM_SHA384 -\& TLS_CHACHA20_POLY1305_SHA256 TLS_CHACHA20_POLY1305_SHA256 -\& TLS_AES_128_CCM_SHA256 TLS_AES_128_CCM_SHA256 -\& TLS_AES_128_CCM_8_SHA256 TLS_AES_128_CCM_8_SHA256 -.Ve -.SS "\s-1TLS\s0 v1.3 integrity-only cipher suites according to \s-1RFC 9150\s0" -.IX Subsection "TLS v1.3 integrity-only cipher suites according to RFC 9150" -.Vb 2 -\& TLS_SHA256_SHA256 TLS_SHA256_SHA256 -\& TLS_SHA384_SHA384 TLS_SHA384_SHA384 -.Ve -.PP -Note: these ciphers are purely \s-1HMAC\s0 based and do not provide any confidentiality -and thus are disabled by default. -These ciphers are only available at security level 0. -.SS "Older names used by OpenSSL" -.IX Subsection "Older names used by OpenSSL" -The following names are accepted by older releases: -.PP -.Vb 2 -\& SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA EDH\-RSA\-DES\-CBC3\-SHA (DHE\-RSA\-DES\-CBC3\-SHA) -\& SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA EDH\-DSS\-DES\-CBC3\-SHA (DHE\-DSS\-DES\-CBC3\-SHA) -.Ve -.SH "NOTES" -.IX Header "NOTES" -Some compiled versions of OpenSSL may not include all the ciphers -listed here because some ciphers were excluded at compile time. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Verbose listing of all OpenSSL ciphers including \s-1NULL\s0 ciphers: -.PP -.Vb 1 -\& openssl ciphers \-v \*(AqALL:eNULL\*(Aq -.Ve -.PP -Include all ciphers except \s-1NULL\s0 and anonymous \s-1DH\s0 then sort by -strength: -.PP -.Vb 1 -\& openssl ciphers \-v \*(AqALL:!ADH:@STRENGTH\*(Aq -.Ve -.PP -Include all ciphers except ones with no encryption (eNULL) or no -authentication (aNULL): -.PP -.Vb 1 -\& openssl ciphers \-v \*(AqALL:!aNULL\*(Aq -.Ve -.PP -Include only 3DES ciphers and then place \s-1RSA\s0 ciphers last: -.PP -.Vb 1 -\& openssl ciphers \-v \*(Aq3DES:+RSA\*(Aq -.Ve -.PP -Include all \s-1RC4\s0 ciphers but leave out those without authentication: -.PP -.Vb 1 -\& openssl ciphers \-v \*(AqRC4:!COMPLEMENTOFDEFAULT\*(Aq -.Ve -.PP -Include all ciphers with \s-1RSA\s0 authentication but leave out ciphers without -encryption. -.PP -.Vb 1 -\& openssl ciphers \-v \*(AqRSA:!COMPLEMENTOFALL\*(Aq -.Ve -.PP -Set security level to 2 and display all ciphers consistent with level 2: -.PP -.Vb 1 -\& openssl ciphers \-s \-v \*(AqALL:@SECLEVEL=2\*(Aq -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-s_client\fR\|(1), -\&\fBopenssl\-s_server\fR\|(1), -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-V\fR option was added in OpenSSL 1.0.0. -.PP -The \fB\-stdname\fR is only available if OpenSSL is built with tracing enabled -(\fBenable-ssl-trace\fR argument to Configure) before OpenSSL 1.1.1. -.PP -The \fB\-convert\fR option was added in OpenSSL 1.1.1. -.PP -Support for standard \s-1IANA\s0 names in cipher lists was added in -OpenSSL 3.2.0. -.PP -The support for \s-1TLS\s0 v1.3 integrity-only cipher suites was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-cmds.1ossl b/openssl-install/share/man/man1/openssl-cmds.1ossl deleted file mode 100644 index 198d0fad..00000000 --- a/openssl-install/share/man/man1/openssl-cmds.1ossl +++ /dev/null @@ -1,277 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CMDS 1ossl" -.TH OPENSSL-CMDS 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -asn1parse, -ca, -ciphers, -cmp, -cms, -crl, -crl2pkcs7, -dgst, -dhparam, -dsa, -dsaparam, -ec, -ecparam, -enc, -engine, -errstr, -gendsa, -genpkey, -genrsa, -info, -kdf, -mac, -nseq, -ocsp, -passwd, -pkcs12, -pkcs7, -pkcs8, -pkey, -pkeyparam, -pkeyutl, -prime, -rand, -rehash, -req, -rsa, -rsautl, -s_client, -s_server, -s_time, -sess_id, -smime, -speed, -spkac, -srp, -storeutl, -ts, -verify, -version, -x509 -\&\- OpenSSL application commands -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fIcmd\fR \fB\-help\fR | [\fI\-option\fR | \fI\-option\fR \fIarg\fR] ... [\fIarg\fR] ... -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Every \fIcmd\fR listed above is a (sub\-)command of the \fBopenssl\fR\|(1) application. -It has its own detailed manual page at \fBopenssl\-\f(BIcmd\fB\fR(1). For example, to -view the manual page for the \fBopenssl dgst\fR command, type \f(CW\*(C`man openssl\-dgst\*(C'\fR. -.SH "OPTIONS" -.IX Header "OPTIONS" -Among others, every subcommand has a help option. -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message for the subcommand. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-asn1parse\fR\|(1), -\&\fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-ciphers\fR\|(1), -\&\fBopenssl\-cmp\fR\|(1), -\&\fBopenssl\-cms\fR\|(1), -\&\fBopenssl\-crl\fR\|(1), -\&\fBopenssl\-crl2pkcs7\fR\|(1), -\&\fBopenssl\-dgst\fR\|(1), -\&\fBopenssl\-dhparam\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-dsaparam\fR\|(1), -\&\fBopenssl\-ec\fR\|(1), -\&\fBopenssl\-ecparam\fR\|(1), -\&\fBopenssl\-enc\fR\|(1), -\&\fBopenssl\-engine\fR\|(1), -\&\fBopenssl\-errstr\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-info\fR\|(1), -\&\fBopenssl\-kdf\fR\|(1), -\&\fBopenssl\-mac\fR\|(1), -\&\fBopenssl\-nseq\fR\|(1), -\&\fBopenssl\-ocsp\fR\|(1), -\&\fBopenssl\-passwd\fR\|(1), -\&\fBopenssl\-pkcs12\fR\|(1), -\&\fBopenssl\-pkcs7\fR\|(1), -\&\fBopenssl\-pkcs8\fR\|(1), -\&\fBopenssl\-pkey\fR\|(1), -\&\fBopenssl\-pkeyparam\fR\|(1), -\&\fBopenssl\-pkeyutl\fR\|(1), -\&\fBopenssl\-prime\fR\|(1), -\&\fBopenssl\-rand\fR\|(1), -\&\fBopenssl\-rehash\fR\|(1), -\&\fBopenssl\-req\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-rsautl\fR\|(1), -\&\fBopenssl\-s_client\fR\|(1), -\&\fBopenssl\-s_server\fR\|(1), -\&\fBopenssl\-s_time\fR\|(1), -\&\fBopenssl\-sess_id\fR\|(1), -\&\fBopenssl\-smime\fR\|(1), -\&\fBopenssl\-speed\fR\|(1), -\&\fBopenssl\-spkac\fR\|(1), -\&\fBopenssl\-srp\fR\|(1), -\&\fBopenssl\-storeutl\fR\|(1), -\&\fBopenssl\-ts\fR\|(1), -\&\fBopenssl\-verify\fR\|(1), -\&\fBopenssl\-version\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -.SH "HISTORY" -.IX Header "HISTORY" -Initially, the manual page entry for the \f(CW\*(C`openssl \f(CIcmd\f(CW\*(C'\fR command used -to be available at \fIcmd\fR(1). Later, the alias \fBopenssl\-\f(BIcmd\fB\fR(1) was -introduced, which made it easier to group the openssl commands using -the \fBapropos\fR\|(1) command or the shell's tab completion. -.PP -In order to reduce cluttering of the global manual page namespace, -the manual page entries without the 'openssl\-' prefix have been -deprecated in OpenSSL 3.0 and will be removed in OpenSSL 4.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-cmp.1ossl b/openssl-install/share/man/man1/openssl-cmp.1ossl deleted file mode 100644 index d4da1da2..00000000 --- a/openssl-install/share/man/man1/openssl-cmp.1ossl +++ /dev/null @@ -1,1538 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CMP 1ossl" -.TH OPENSSL-CMP 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-cmp \- Certificate Management Protocol (CMP, RFC 4210) application -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBcmp\fR -[\fB\-help\fR] -[\fB\-config\fR \fIfilename\fR] -[\fB\-section\fR \fInames\fR] -[\fB\-verbosity\fR \fIlevel\fR] -.PP -Generic message options: -.PP -[\fB\-cmd\fR \fIir|cr|kur|p10cr|rr|genm\fR] -[\fB\-infotype\fR \fIname\fR] -[\fB\-profile\fR \fIname\fR] -[\fB\-geninfo\fR \fIvalues\fR] -[\fB\-template\fR \fIfilename\fR] -[\fB\-keyspec\fR \fIfilename\fR] -.PP -Certificate enrollment options: -.PP -[\fB\-newkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-newkeypass\fR \fIarg\fR] -[\fB\-subject\fR \fIname\fR] -[\fB\-days\fR \fInumber\fR] -[\fB\-reqexts\fR \fIname\fR] -[\fB\-sans\fR \fIspec\fR] -[\fB\-san_nodefault\fR] -[\fB\-policies\fR \fIname\fR] -[\fB\-policy_oids\fR \fInames\fR] -[\fB\-policy_oids_critical\fR] -[\fB\-popo\fR \fInumber\fR] -[\fB\-csr\fR \fIfilename\fR] -[\fB\-out_trusted\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-implicit_confirm\fR] -[\fB\-disable_confirm\fR] -[\fB\-certout\fR \fIfilename\fR] -[\fB\-chainout\fR \fIfilename\fR] -.PP -Certificate enrollment and revocation options: -.PP -[\fB\-oldcert\fR \fIfilename\fR|\fIuri\fR] -[\fB\-issuer\fR \fIname\fR] -[\fB\-serial\fR \fInumber\fR] -[\fB\-revreason\fR \fInumber\fR] -.PP -Message transfer options: -.PP -[\fB\-server\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR] -[\fB\-proxy\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR] -[\fB\-no_proxy\fR \fIaddresses\fR] -[\fB\-recipient\fR \fIname\fR] -[\fB\-path\fR \fIremote_path\fR] -[\fB\-keep_alive\fR \fIvalue\fR] -[\fB\-msg_timeout\fR \fIseconds\fR] -[\fB\-total_timeout\fR \fIseconds\fR] -.PP -Server authentication options: -.PP -[\fB\-trusted\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-untrusted\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-srvcert\fR \fIfilename\fR|\fIuri\fR] -[\fB\-expect_sender\fR \fIname\fR] -[\fB\-ignore_keyusage\fR] -[\fB\-unprotected_errors\fR] -[\fB\-no_cache_extracerts\fR] -[\fB\-srvcertout\fR \fIfilename\fR] -[\fB\-extracertsout\fR \fIfilename\fR] -[\fB\-cacertsout\fR \fIfilename\fR] -[\fB\-oldwithold\fR \fIfilename\fR] -[\fB\-newwithnew\fR \fIfilename\fR] -[\fB\-newwithold\fR \fIfilename\fR] -[\fB\-oldwithnew\fR \fIfilename\fR] -[\fB\-crlcert\fR \fIfilename\fR] -[\fB\-oldcrl\fR \fIfilename\fR] -[\fB\-crlout\fR \fIfilename\fR] -.PP -Client authentication and protection options: -.PP -[\fB\-ref\fR \fIvalue\fR] -[\fB\-secret\fR \fIarg\fR] -[\fB\-cert\fR \fIfilename\fR|\fIuri\fR] -[\fB\-own_trusted\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keypass\fR \fIarg\fR] -[\fB\-digest\fR \fIname\fR] -[\fB\-mac\fR \fIname\fR] -[\fB\-extracerts\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-unprotected_requests\fR] -.PP -Credentials format options: -.PP -[\fB\-certform\fR \fIPEM|DER\fR] -[\fB\-crlform\fR \fIPEM|DER\fR] -[\fB\-keyform\fR \fIPEM|DER|P12|ENGINE\fR] -[\fB\-otherpass\fR \fIarg\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.PP -Random state options: -.PP -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -.PP -\&\s-1TLS\s0 connection options: -.PP -[\fB\-tls_used\fR] -[\fB\-tls_cert\fR \fIfilename\fR|\fIuri\fR] -[\fB\-tls_key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-tls_keypass\fR \fIarg\fR] -[\fB\-tls_extra\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-tls_trusted\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-tls_host\fR \fIname\fR] -.PP -Client-side debugging options: -.PP -[\fB\-batch\fR] -[\fB\-repeat\fR \fInumber\fR] -[\fB\-reqin\fR \fIfilenames\fR] -[\fB\-reqin_new_tid\fR] -[\fB\-reqout\fR \fIfilenames\fR] -[\fB\-reqout_only\fR \fIfilename\fR] -[\fB\-rspin\fR \fIfilenames\fR] -[\fB\-rspout\fR \fIfilenames\fR] -[\fB\-use_mock_srv\fR] -.PP -Mock server options: -.PP -[\fB\-port\fR \fInumber\fR] -[\fB\-max_msgs\fR \fInumber\fR] -[\fB\-srv_ref\fR \fIvalue\fR] -[\fB\-srv_secret\fR \fIarg\fR] -[\fB\-srv_cert\fR \fIfilename\fR|\fIuri\fR] -[\fB\-srv_key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-srv_keypass\fR \fIarg\fR] -[\fB\-srv_trusted\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-srv_untrusted\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-ref_cert\fR \fIfilename\fR|\fIuri\fR] -[\fB\-rsp_cert\fR \fIfilename\fR|\fIuri\fR] -[\fB\-rsp_crl\fR \fIfilename\fR|\fIuri\fR] -[\fB\-rsp_extracerts\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-rsp_capubs\fR \fIfilenames\fR|\fIuris\fR] -[\fB\-rsp_newwithnew\fR \fIfilename\fR|\fIuri\fR] -[\fB\-rsp_newwithold\fR \fIfilename\fR|\fIuri\fR] -[\fB\-rsp_oldwithnew\fR \fIfilename\fR|\fIuri\fR] -[\fB\-poll_count\fR \fInumber\fR] -[\fB\-check_after\fR \fInumber\fR] -[\fB\-grant_implicitconf\fR] -[\fB\-pkistatus\fR \fInumber\fR] -[\fB\-failure\fR \fInumber\fR] -[\fB\-failurebits\fR \fInumber\fR] -[\fB\-statusstring\fR \fIarg\fR] -[\fB\-send_error\fR] -[\fB\-send_unprotected\fR] -[\fB\-send_unprot_err\fR] -[\fB\-accept_unprotected\fR] -[\fB\-accept_unprot_err\fR] -[\fB\-accept_raverified\fR] -.PP -Certificate verification options, for both \s-1CMP\s0 and \s-1TLS:\s0 -.PP -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBcmp\fR command is a client implementation for the Certificate -Management Protocol (\s-1CMP\s0) as defined in \s-1RFC4210.\s0 -It can be used to request certificates from a \s-1CA\s0 server, -update their certificates, -request certificates to be revoked, and perform other types of \s-1CMP\s0 requests. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Display a summary of all options -.IP "\fB\-config\fR \fIfilename\fR" 4 -.IX Item "-config filename" -Configuration file to use. -An empty string \f(CW""\fR means none. -Default filename is from the environment variable \f(CW\*(C`OPENSSL_CONF\*(C'\fR. -.IP "\fB\-section\fR \fInames\fR" 4 -.IX Item "-section names" -Section(s) to use within config file defining \s-1CMP\s0 options. -An empty string \f(CW""\fR means no specific section. -Default is \f(CW\*(C`cmp\*(C'\fR. -.Sp -Multiple section names may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Contents of sections named later may override contents of sections named before. -In any case, as usual, the \f(CW\*(C`[default]\*(C'\fR section and finally the unnamed -section (as far as present) can provide per-option fallback values. -.IP "\fB\-verbosity\fR \fIlevel\fR" 4 -.IX Item "-verbosity level" -Level of verbosity for logging, error output, etc. -0 = \s-1EMERG, 1\s0 = \s-1ALERT, 2\s0 = \s-1CRIT, 3\s0 = \s-1ERR, 4\s0 = \s-1WARN, 5\s0 = \s-1NOTE, -6\s0 = \s-1INFO, 7\s0 = \s-1DEBUG, 8\s0 = \s-1TRACE.\s0 -Defaults to 6 = \s-1INFO.\s0 -.SS "Generic message options" -.IX Subsection "Generic message options" -.IP "\fB\-cmd\fR \fIir|cr|kur|p10cr|rr|genm\fR" 4 -.IX Item "-cmd ir|cr|kur|p10cr|rr|genm" -\&\s-1CMP\s0 command to execute. -Currently implemented commands are: -.RS 4 -.IP "ir \ \- Initialization Request" 8 -.IX Item "ir - Initialization Request" -.PD 0 -.IP "cr \ \- Certificate Request" 8 -.IX Item "cr - Certificate Request" -.IP "p10cr \- PKCS#10 Certification Request (for legacy support)" 8 -.IX Item "p10cr - PKCS#10 Certification Request (for legacy support)" -.IP "kur \ \ \- Key Update Request" 8 -.IX Item "kur - Key Update Request" -.IP "rr \ \- Revocation Request" 8 -.IX Item "rr - Revocation Request" -.IP "genm \- General Message" 8 -.IX Item "genm - General Message" -.RE -.RS 4 -.PD -.Sp -\&\fBir\fR requests initialization of an end entity into a \s-1PKI\s0 hierarchy -by issuing a first certificate. -.Sp -\&\fBcr\fR requests issuing an additional certificate for an end entity already -initialized to the \s-1PKI\s0 hierarchy. -.Sp -\&\fBp10cr\fR requests issuing an additional certificate similarly to \fBcr\fR -but using legacy PKCS#10 \s-1CSR\s0 format. -.Sp -\&\fBkur\fR requests a (key) update for an existing certificate. -.Sp -\&\fBrr\fR requests revocation of an existing certificate. -.Sp -\&\fBgenm\fR requests information using a General Message, where optionally -included \fBInfoTypeAndValue\fRs may be used to state which info is of interest. -Upon receipt of the General Response, information about all received -\&\s-1ITAV\s0 \fBinfoType\fRs is printed to stdout. -.RE -.IP "\fB\-infotype\fR \fIname\fR" 4 -.IX Item "-infotype name" -Set InfoType name to use for requesting specific info in \fBgenm\fR, -e.g., \f(CW\*(C`signKeyPairTypes\*(C'\fR. -There is specific support for \f(CW\*(C`caCerts\*(C'\fR, \f(CW\*(C`rootCaCert\*(C'\fR, -\&\f(CW\*(C`certReqTemplate\*(C'\fR, and \f(CW\*(C`crlStatusList\*(C'\fR (\s-1CRL\s0 update retrieval). -.IP "\fB\-profile\fR \fIname\fR" 4 -.IX Item "-profile name" -Name of a certificate profile to place in -the PKIHeader generalInfo field of request messages. -.IP "\fB\-geninfo\fR \fIvalues\fR" 4 -.IX Item "-geninfo values" -A comma-separated list of InfoTypeAndValue to place in -the generalInfo field of the PKIHeader of requests messages. -Each InfoTypeAndValue gives an \s-1OID\s0 and an integer or string value -of the form \fI\s-1OID\s0\fR:int:\fInumber\fR or \fI\s-1OID\s0\fR:str:\fItext\fR, -e.g., \f(CW\*(Aq1.2.3.4:int:56789, id\-kp:str:name\*(Aq\fR. -.IP "\fB\-template\fR \fIfilename\fR" 4 -.IX Item "-template filename" -The file to save any \s-1CRMF\s0 certTemplate in \s-1DER\s0 format -received in a genp message with id-it-certReqTemplate. -.IP "\fB\-keyspec\fR \fIfilename\fR" 4 -.IX Item "-keyspec filename" -It is optional and used to specify the file to save any keySpec if -present in a genp message with id-it-keyGenParameters. -.Sp -Note: any keySpec field contents received are logged as \s-1INFO.\s0 -.SS "Certificate enrollment options" -.IX Subsection "Certificate enrollment options" -.IP "\fB\-newkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-newkey filename|uri" -The source of the private or public key for the certificate being requested. -Defaults to the public key in the PKCS#10 \s-1CSR\s0 given with the \fB\-csr\fR option, -the public key of the reference certificate, or the current client key. -.Sp -The public portion of the key is placed in the certification request. -.Sp -Unless \fB\-cmd\fR \fIp10cr\fR, \fB\-popo\fR \fI\-1\fR, or \fB\-popo\fR \fI0\fR is given, the -private key will be needed as well to provide the proof of possession (\s-1POPO\s0), -where the \fB\-key\fR option may provide a fallback. -.IP "\fB\-newkeypass\fR \fIarg\fR" 4 -.IX Item "-newkeypass arg" -Pass phrase source for the key given with the \fB\-newkey\fR option. -If not given here, the password will be prompted for if needed. -.Sp -For more information about the format of \fIarg\fR see -\&\fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-subject\fR \fIname\fR" 4 -.IX Item "-subject name" -X.509 Distinguished Name (\s-1DN\s0) to use as subject field -in the requested certificate template in \s-1IR/CR/KUR\s0 messages. -If the NULL-DN (\f(CW\*(C`/\*(C'\fR) is given then no subject is placed in the template. -Default is the subject \s-1DN\s0 of any PKCS#10 \s-1CSR\s0 given with the \fB\-csr\fR option. -For \s-1KUR,\s0 a further fallback is the subject \s-1DN\s0 -of the reference certificate (see \fB\-oldcert\fR) if provided. -This fallback is used for \s-1IR\s0 and \s-1CR\s0 only if no SANs are set. -.Sp -If provided and neither of \fB\-cert\fR, \fB\-oldcert\fR, or \fB\-csr\fR is given, -the subject \s-1DN\s0 is used as fallback sender of outgoing \s-1CMP\s0 messages. -.Sp -The argument must be formatted as \fI/type0=value0/type1=value1/type2=...\fR. -Special characters may be escaped by \f(CW\*(C`\e\*(C'\fR (backslash); whitespace is retained. -Empty values are permitted, but the corresponding type will not be included. -Giving a single \f(CW\*(C`/\*(C'\fR will lead to an empty sequence of RDNs (a NULL-DN). -Multi-valued RDNs can be formed by placing a \f(CW\*(C`+\*(C'\fR character instead of a \f(CW\*(C`/\*(C'\fR -between the AttributeValueAssertions (AVAs) that specify the members of the set. -Example: -.Sp -\&\f(CW\*(C`/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe\*(C'\fR -.IP "\fB\-days\fR \fInumber\fR" 4 -.IX Item "-days number" -Number of days the new certificate is requested to be valid for, counting from -the current time of the host. -Also triggers the explicit request that the -validity period starts from the current time (as seen by the host). -.IP "\fB\-reqexts\fR \fIname\fR" 4 -.IX Item "-reqexts name" -Name of section in OpenSSL config file defining certificate request extensions. -If the \fB\-csr\fR option is present, these extensions augment the extensions -contained the given PKCS#10 \s-1CSR,\s0 overriding any extensions with same OIDs. -.IP "\fB\-sans\fR \fIspec\fR" 4 -.IX Item "-sans spec" -One or more \s-1IP\s0 addresses, email addresses, \s-1DNS\s0 names, or URIs -separated by commas or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R") -to add as Subject Alternative Name(s) (\s-1SAN\s0) certificate request extension. -If the special element \*(L"critical\*(R" is given the SANs are flagged as critical. -Cannot be used if any Subject Alternative Name extension is set via \fB\-reqexts\fR. -.IP "\fB\-san_nodefault\fR" 4 -.IX Item "-san_nodefault" -When Subject Alternative Names are not given via \fB\-sans\fR -nor defined via \fB\-reqexts\fR, -they are copied by default from the reference certificate (see \fB\-oldcert\fR). -This can be disabled by giving the \fB\-san_nodefault\fR option. -.IP "\fB\-policies\fR \fIname\fR" 4 -.IX Item "-policies name" -Name of section in OpenSSL config file defining policies to be set -as certificate request extension. -This option cannot be used together with \fB\-policy_oids\fR. -.IP "\fB\-policy_oids\fR \fInames\fR" 4 -.IX Item "-policy_oids names" -One or more \s-1OID\s0(s), separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R") -to add as certificate policies request extension. -This option cannot be used together with \fB\-policies\fR. -.IP "\fB\-policy_oids_critical\fR" 4 -.IX Item "-policy_oids_critical" -Flag the policies given with \fB\-policy_oids\fR as critical. -.IP "\fB\-popo\fR \fInumber\fR" 4 -.IX Item "-popo number" -Proof-of-possession (\s-1POPO\s0) method to use for \s-1IR/CR/KUR\s0; values: \f(CW\*(C`\-1\*(C'\fR..<2> where -\&\f(CW\*(C`\-1\*(C'\fR = \s-1NONE,\s0 \f(CW0\fR = \s-1RAVERIFIED,\s0 \f(CW1\fR = \s-1SIGNATURE\s0 (default), \f(CW2\fR = \s-1KEYENC.\s0 -.Sp -Note that a signature-based \s-1POPO\s0 can only be produced if a private key -is provided via the \fB\-newkey\fR or \fB\-key\fR options. -.IP "\fB\-csr\fR \fIfilename\fR" 4 -.IX Item "-csr filename" -PKCS#10 \s-1CSR\s0 in \s-1PEM\s0 or \s-1DER\s0 format containing a certificate request. -With \fB\-cmd\fR \fIp10cr\fR it is used directly in a legacy P10CR message. -.Sp -When used with \fB\-cmd\fR \fIir\fR, \fIcr\fR, or \fIkur\fR, -it is transformed into the respective regular \s-1CMP\s0 request. -In this case, a private key must be provided (with \fB\-newkey\fR or \fB\-key\fR) -for the proof of possession (unless \fB\-popo\fR \fI\-1\fR or \fB\-popo\fR \fI0\fR is used) -and the respective public key is placed in the certification request -(rather than taking over the public key contained in the PKCS#10 \s-1CSR\s0). -.Sp -PKCS#10 \s-1CSR\s0 input may also be used with \fB\-cmd\fR \fIrr\fR -to specify the certificate to be revoked -via the included subject name and public key. -Its subject is used as fallback sender in \s-1CMP\s0 message headers -if \fB\-cert\fR and \fB\-oldcert\fR are not given. -.IP "\fB\-out_trusted\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-out_trusted filenames|uris" -Trusted certificate(s) to use for validating the newly enrolled certificate. -During this verification, any certificate status checking is disabled. -.Sp -Multiple sources may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Each source may contain multiple certificates. -.Sp -The certificate verification options -\&\fB\-verify_hostname\fR, \fB\-verify_ip\fR, and \fB\-verify_email\fR -only affect the certificate verification enabled via this option. -.IP "\fB\-implicit_confirm\fR" 4 -.IX Item "-implicit_confirm" -Request implicit confirmation of newly enrolled certificates. -.IP "\fB\-disable_confirm\fR" 4 -.IX Item "-disable_confirm" -Do not send certificate confirmation message for newly enrolled certificate -without requesting implicit confirmation -to cope with broken servers not supporting implicit confirmation correctly. -\&\fB\s-1WARNING:\s0\fR This leads to behavior violating \s-1RFC 4210.\s0 -.IP "\fB\-certout\fR \fIfilename\fR" 4 -.IX Item "-certout filename" -The file where any newly enrolled certificate should be saved. -.IP "\fB\-chainout\fR \fIfilename\fR" 4 -.IX Item "-chainout filename" -The file where the chain of any newly enrolled certificate should be saved. -This chain excludes the leaf certificate, i.e., the newly enrolled certificate. -Also the trust anchor (the root certificate) is not included. -.Sp -If the \fB\-certout\fR option is given, too, with equal \fIfilename\fR argument, -then the file produced contains both outputs concatenated: -the newly enrolled certificate followed by its chain. -.SS "Certificate enrollment and revocation options" -.IX Subsection "Certificate enrollment and revocation options" -.IP "\fB\-oldcert\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-oldcert filename|uri" -The certificate to be updated (i.e., renewed or re-keyed) in Key Update Request -(\s-1KUR\s0) messages or to be revoked in Revocation Request (\s-1RR\s0) messages. -For \s-1KUR\s0 the certificate to be updated defaults to \fB\-cert\fR, -and the resulting certificate is called \fIreference certificate\fR. -For \s-1RR\s0 the certificate to be revoked can also be specified using \fB\-csr\fR. -\&\fB\-oldcert\fR and \fB\-csr\fR is ignored if \fB\-issuer\fR and \fB\-serial\fR is provided. -.Sp -The reference certificate, if any, is also used for -deriving default subject \s-1DN\s0 and Subject Alternative Names and the -default issuer entry in the requested certificate template of an \s-1IR/CR/KUR.\s0 -Its public key is used as a fallback in the template of certification requests. -Its subject is used as sender of outgoing messages if \fB\-cert\fR is not given. -Its issuer is used as default recipient in \s-1CMP\s0 message headers -if neither \fB\-recipient\fR, \fB\-srvcert\fR, nor \fB\-issuer\fR is given. -.IP "\fB\-issuer\fR \fIname\fR" 4 -.IX Item "-issuer name" -X.509 Distinguished Name (\s-1DN\s0) to place as the issuer field -in the requested certificate template in \s-1IR/CR/KUR/RR\s0 messages. -If the NULL-DN (\f(CW\*(C`/\*(C'\fR) is given then no issuer is placed in the template. -.Sp -If provided and neither \fB\-recipient\fR nor \fB\-srvcert\fR is given, -the issuer \s-1DN\s0 is used as fallback recipient of outgoing \s-1CMP\s0 messages. -.Sp -The argument must be formatted as \fI/type0=value0/type1=value1/type2=...\fR. -For details see the description of the \fB\-subject\fR option. -.IP "\fB\-serial\fR \fInumber\fR" 4 -.IX Item "-serial number" -Specify the Serial number of certificate to be revoked in revocation request. -The serial number can be decimal or hex (if preceded by \f(CW\*(C`0x\*(C'\fR) -.IP "\fB\-revreason\fR \fInumber\fR" 4 -.IX Item "-revreason number" -Set CRLReason to be included in revocation request (\s-1RR\s0); values: \f(CW0\fR..\f(CW10\fR -or \f(CW\*(C`\-1\*(C'\fR for none (which is the default). -.Sp -Reason numbers defined in \s-1RFC 5280\s0 are: -.Sp -.Vb 10 -\& CRLReason ::= ENUMERATED { -\& unspecified (0), -\& keyCompromise (1), -\& cACompromise (2), -\& affiliationChanged (3), -\& superseded (4), -\& cessationOfOperation (5), -\& certificateHold (6), -\& \-\- value 7 is not used -\& removeFromCRL (8), -\& privilegeWithdrawn (9), -\& aACompromise (10) -\& } -.Ve -.SS "Message transfer options" -.IX Subsection "Message transfer options" -.IP "\fB\-server\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR" 4 -.IX Item "-server [http[s]://][userinfo@]host[:port][/path][?query][#fragment]" -The \fIhost\fR domain name or \s-1IP\s0 address and optionally \fIport\fR -of the \s-1CMP\s0 server to connect to using \s-1HTTP\s0(S). -\&\s-1IP\s0 address may be for v4 or v6, such as \f(CW127.0.0.1\fR or \f(CW\*(C`[::1]\*(C'\fR for localhost. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -.Sp -This option excludes \fI\-port\fR and \fI\-use_mock_srv\fR. -It is ignored if \fI\-rspin\fR is given with enough filename arguments. -.Sp -If the scheme \f(CW\*(C`https\*(C'\fR is given, the \fB\-tls_used\fR option is implied. -When \s-1TLS\s0 is used, the default port is 443, otherwise 80. -The optional userinfo and fragment components are ignored. -Any given query component is handled as part of the path component. -If a path is included it provides the default value for the \fB\-path\fR option. -.IP "\fB\-proxy\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR" 4 -.IX Item "-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]" -The \s-1HTTP\s0(S) proxy server to use for reaching the \s-1CMP\s0 server unless \fB\-no_proxy\fR -applies, see below. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -The proxy port defaults to 80 or 443 if the scheme is \f(CW\*(C`https\*(C'\fR; apart from that -the optional \f(CW\*(C`http://\*(C'\fR or \f(CW\*(C`https://\*(C'\fR prefix is ignored (note that using \s-1TLS\s0 -may be required by \fB\-tls_used\fR or \fB\-server\fR with the prefix \f(CW\*(C`https\*(C'\fR), -as well as any path, userinfo, and query, and fragment components. -Defaults to the environment variable \f(CW\*(C`http_proxy\*(C'\fR if set, else \f(CW\*(C`HTTP_PROXY\*(C'\fR -in case no \s-1TLS\s0 is used, otherwise \f(CW\*(C`https_proxy\*(C'\fR if set, else \f(CW\*(C`HTTPS_PROXY\*(C'\fR. -This option is ignored if \fI\-server\fR is not given. -.IP "\fB\-no_proxy\fR \fIaddresses\fR" 4 -.IX Item "-no_proxy addresses" -List of \s-1IP\s0 addresses and/or \s-1DNS\s0 names of servers -not to use an \s-1HTTP\s0(S) proxy for, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Default is from the environment variable \f(CW\*(C`no_proxy\*(C'\fR if set, else \f(CW\*(C`NO_PROXY\*(C'\fR. -This option is ignored if \fI\-server\fR is not given. -.IP "\fB\-recipient\fR \fIname\fR" 4 -.IX Item "-recipient name" -Distinguished Name (\s-1DN\s0) to use in the recipient field of \s-1CMP\s0 request message -headers, i.e., the \s-1CMP\s0 server (usually the addressed \s-1CA\s0). -.Sp -The recipient field in the header of a \s-1CMP\s0 message is mandatory. -If not given explicitly the recipient is determined in the following order: -the subject of the \s-1CMP\s0 server certificate given with the \fB\-srvcert\fR option, -the \fB\-issuer\fR option, -the issuer of the certificate given with the \fB\-oldcert\fR option, -the issuer of the \s-1CMP\s0 client certificate (\fB\-cert\fR option), -as far as any of those is present, else the NULL-DN as last resort. -.Sp -The argument must be formatted as \fI/type0=value0/type1=value1/type2=...\fR. -For details see the description of the \fB\-subject\fR option. -.IP "\fB\-path\fR \fIremote_path\fR" 4 -.IX Item "-path remote_path" -\&\s-1HTTP\s0 path at the \s-1CMP\s0 server (aka \s-1CMP\s0 alias) to use for \s-1POST\s0 requests. -Defaults to any path given with \fB\-server\fR, else \f(CW"/"\fR. -.IP "\fB\-keep_alive\fR \fIvalue\fR" 4 -.IX Item "-keep_alive value" -If the given value is 0 then \s-1HTTP\s0 connections are closed after each response -(which would be the default behavior of \s-1HTTP 1.0\s0) -even if a \s-1CMP\s0 transaction needs more than one round trip. -If the value is 1 or 2 -then for each transaction a persistent connection is requested. -If the value is 2 then a persistent connection is required, -i.e., an error occurs if the server does not grant it. -The default value is 1, which means preferring to keep the connection open. -.IP "\fB\-msg_timeout\fR \fIseconds\fR" 4 -.IX Item "-msg_timeout seconds" -Number of seconds a \s-1CMP\s0 request-response message round trip -is allowed to take before a timeout error is returned. -A value <= 0 means no limitation (waiting indefinitely). -Default is to use the \fB\-total_timeout\fR setting. -.IP "\fB\-total_timeout\fR \fIseconds\fR" 4 -.IX Item "-total_timeout seconds" -Maximum total number of seconds a transaction may take, -including polling etc. -A value <= 0 means no limitation (waiting indefinitely). -Default is 0. -.SS "Server authentication options" -.IX Subsection "Server authentication options" -.IP "\fB\-trusted\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-trusted filenames|uris" -The certificate(s), typically of root CAs, the client shall use as trust anchors -when validating signature-based protection of \s-1CMP\s0 response messages. -This option is ignored if the \fB\-srvcert\fR option is given as well. -It provides more flexibility than \fB\-srvcert\fR because the \s-1CMP\s0 protection -certificate of the server is not pinned but may be any certificate -from which a chain to one of the given trust anchors can be constructed. -.Sp -If none of \fB\-trusted\fR, \fB\-srvcert\fR, and \fB\-secret\fR is given, message validation -errors will be thrown unless \fB\-unprotected_errors\fR permits an exception. -.Sp -Multiple sources may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Each source may contain multiple certificates. -.Sp -The certificate verification options -\&\fB\-verify_hostname\fR, \fB\-verify_ip\fR, and \fB\-verify_email\fR -have no effect on the certificate verification enabled via this option. -.IP "\fB\-untrusted\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-untrusted filenames|uris" -Non-trusted intermediate \s-1CA\s0 certificate(s). -Any extra certificates given with the \fB\-cert\fR option are appended to it. -All these certificates may be useful for cert path construction -for the own \s-1CMP\s0 signer certificate (to include in the extraCerts field of -request messages) and for the \s-1TLS\s0 client certificate (if \s-1TLS\s0 is used) -as well as for chain building -when validating server certificates (checking signature-based -\&\s-1CMP\s0 message protection) and when validating newly enrolled certificates. -.Sp -Multiple sources may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Each source may contain multiple certificates. -.IP "\fB\-srvcert\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-srvcert filename|uri" -The specific \s-1CMP\s0 server certificate to expect and directly trust (even if it is -expired) when verifying signature-based protection of \s-1CMP\s0 response messages. -This pins the accepted server and results in ignoring the \fB\-trusted\fR option. -.Sp -If set, the subject of the certificate is also used -as default value for the recipient of \s-1CMP\s0 requests -and as default value for the expected sender of \s-1CMP\s0 responses. -.IP "\fB\-expect_sender\fR \fIname\fR" 4 -.IX Item "-expect_sender name" -Distinguished Name (\s-1DN\s0) expected in the sender field of incoming \s-1CMP\s0 messages. -Defaults to the subject \s-1DN\s0 of the pinned \fB\-srvcert\fR, if any. -.Sp -This can be used to make sure that only a particular entity is accepted as -\&\s-1CMP\s0 message signer, and attackers are not able to use arbitrary certificates -of a trusted \s-1PKI\s0 hierarchy to fraudulently pose as a \s-1CMP\s0 server. -Note that this option gives slightly more freedom than setting the \fB\-srvcert\fR, -which pins the server to the holder of a particular certificate, while the -expected sender name will continue to match after updates of the server cert. -.Sp -The argument must be formatted as \fI/type0=value0/type1=value1/type2=...\fR. -For details see the description of the \fB\-subject\fR option. -.IP "\fB\-ignore_keyusage\fR" 4 -.IX Item "-ignore_keyusage" -Ignore key usage restrictions in \s-1CMP\s0 signer certificates when validating -signature-based protection of incoming \s-1CMP\s0 messages. -By default, \f(CW\*(C`digitalSignature\*(C'\fR must be allowed by \s-1CMP\s0 signer certificates. -This option applies to both \s-1CMP\s0 clients and the mock server. -.IP "\fB\-unprotected_errors\fR" 4 -.IX Item "-unprotected_errors" -Accept missing or invalid protection of negative responses from the server. -This applies to the following message types and contents: -.RS 4 -.IP "\(bu" 4 -error messages -.IP "\(bu" 4 -negative certificate responses (\s-1IP/CP/KUP\s0) -.IP "\(bu" 4 -negative revocation responses (\s-1RP\s0) -.IP "\(bu" 4 -negative PKIConf messages -.RE -.RS 4 -.Sp -\&\fB\s-1WARNING:\s0\fR This setting leads to unspecified behavior and it is meant -exclusively to allow interoperability with server implementations violating -\&\s-1RFC 4210,\s0 e.g.: -.IP "\(bu" 4 -section 5.1.3.1 allows exceptions from protecting only for special -cases: -\&\*(L"There \s-1MAY\s0 be cases in which the PKIProtection \s-1BIT STRING\s0 is deliberately not -used to protect a message [...] because other protection, external to \s-1PKIX,\s0 will -be applied instead.\*(R" -.IP "\(bu" 4 -section 5.3.21 is clear on ErrMsgContent: \*(L"The \s-1CA MUST\s0 always sign it -with a signature key.\*(R" -.IP "\(bu" 4 -appendix D.4 shows PKIConf message having protection -.RE -.RS 4 -.RE -.IP "\fB\-no_cache_extracerts\fR" 4 -.IX Item "-no_cache_extracerts" -Do not cache certificates in the extraCerts field of \s-1CMP\s0 messages received. -By default, they are kept as they may be helful for validating further messages. -This option applies to both \s-1CMP\s0 clients and the mock server. -.IP "\fB\-srvcertout\fR \fIfilename\fR" 4 -.IX Item "-srvcertout filename" -The file where to save the successfully validated certificate, if any, -that the \s-1CMP\s0 server used for signature-based response message protection. -If there is no such certificate, typically because the protection was MAC-based, -this is indicated by deleting the file (if it existed). -.IP "\fB\-extracertsout\fR \fIfilename\fR" 4 -.IX Item "-extracertsout filename" -The file where to save the list of certificates contained in the extraCerts -field of the last received response message that is not a pollRep nor PKIConf. -.IP "\fB\-cacertsout\fR \fIfilename\fR" 4 -.IX Item "-cacertsout filename" -The file where to save the list of \s-1CA\s0 certificates contained in the caPubs field -if a positive certificate response (i.e., \s-1IP, CP,\s0 or \s-1KUP\s0) message was received -or contained in a general response (genp) message with infoType \f(CW\*(C`caCerts\*(C'\fR. -.IP "\fB\-oldwithold\fR \fIfilename\fR" 4 -.IX Item "-oldwithold filename" -The root \s-1CA\s0 certificate to include in a genm request of infoType \f(CW\*(C`rootCaCert\*(C'\fR. -If present and the optional oldWithNew certificate is received, -it is verified using the newWithNew certificate as the (only) trust anchor. -.IP "\fB\-newwithnew\fR \fIfilename\fR" 4 -.IX Item "-newwithnew filename" -This option must be provided when \fB\-infotype\fR \fIrootCaCert\fR is given. -It specifies the file to save the newWithNew certificate -received in a genp message of type \f(CW\*(C`rootCaKeyUpdate\*(C'\fR. -If on success no such cert was received, this file (if present) is deleted -to indicate that the requested root \s-1CA\s0 certificate update is not available. -.Sp -Any received newWithNew certificate is verified -using any received newWithOld certificate as untrusted intermediate certificate -and the certificate provided with \fB\-oldwithold\fR as the (only) trust anchor, -or if not provided, using the certificates given with the \fB\-trusted\fR option. -.Sp -\&\fB\s-1WARNING:\s0\fR -The newWithNew certificate is meant to be a certificate that will be trusted. -The trust placed in it cannot be stronger than the trust placed in -the \fB\-oldwithold\fR certificate if present, otherwise it cannot be stronger than -the weakest trust placed in any of the \fB\-trusted\fR certificates. -.IP "\fB\-newwithold\fR \fIfilename\fR" 4 -.IX Item "-newwithold filename" -The file to save any newWithOld certificate -received in a genp message of infoType \f(CW\*(C`rootCaKeyUpdate\*(C'\fR. -If on success no such cert was received, this is indicated by deleting the file. -.IP "\fB\-oldwithnew\fR \fIfilename\fR" 4 -.IX Item "-oldwithnew filename" -The file to save any oldWithNew certificate -received in a genp message of infoType \f(CW\*(C`rootCaKeyUpdate\*(C'\fR. -If on success no such cert was received, this is indicated by deleting the file. -.IP "\fB\-crlcert\fR \fIfilename\fR" 4 -.IX Item "-crlcert filename" -Certificate to derive \s-1CRL\s0 issuer data for the source field -when obtaining a \s-1CRL\s0 in a genm request with infoType \f(CW\*(C`crlStatusList\*(C'\fR. -Any available distribution point name is preferred over issuer names. -.IP "\fB\-oldcrl\fR \fIfilename\fR" 4 -.IX Item "-oldcrl filename" -The \s-1CRL\s0 to obtain an update for in a genm request with infoType \f(CW\*(C`crlStatusList\*(C'\fR. -Unless the \fB\-crlcert\fR option is provided as well, -the given \s-1CRL\s0 is used for deriving \s-1CRL\s0 issuer data for the source field. -Any available distribution point name is preferred over issuer names. -If the \s-1CRL\s0 contains a thisUpdate field, its value is copied to the request. -.IP "\fB\-crlout\fR \fIfilename\fR" 4 -.IX Item "-crlout filename" -The file to save any \s-1CRL\s0 received in a genp message of infoType \f(CW\*(C`crls\*(C'\fR. -If on success no such \s-1CRL\s0 was received, this is indicated by deleting the file. -.SS "Client authentication options" -.IX Subsection "Client authentication options" -.IP "\fB\-ref\fR \fIvalue\fR" 4 -.IX Item "-ref value" -Reference number/string/value to use as fallback senderKID; this is required -if no sender name can be determined from the \fB\-cert\fR or <\-subject> options and -is typically used when authenticating with pre-shared key (password-based \s-1MAC\s0). -.IP "\fB\-secret\fR \fIarg\fR" 4 -.IX Item "-secret arg" -Provides the source of a secret value to use with MAC-based message protection. -This takes precedence over the \fB\-cert\fR and \fB\-key\fR options. -The secret is used for creating MAC-based protection of outgoing messages -and for validating incoming messages that have MAC-based protection. -The algorithm used by default is Password-Based Message Authentication Code (\s-1PBM\s0) -as defined in \s-1RFC 4210\s0 section 5.1.3.1. -.Sp -For more information about the format of \fIarg\fR see -\&\fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-cert\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-cert filename|uri" -The client's current \s-1CMP\s0 signer certificate. -Requires the corresponding key to be given with \fB\-key\fR. -.Sp -The subject and the public key contained in this certificate -serve as fallback values in the certificate template of \s-1IR/CR/KUR\s0 messages. -.Sp -The subject of this certificate will be used as sender of outgoing \s-1CMP\s0 messages, -while the subject of \fB\-oldcert\fR or \fB\-subjectName\fR may provide fallback values. -.Sp -The issuer of this certificate is used as one of the recipient fallback values -and as fallback issuer entry in the certificate template of \s-1IR/CR/KUR\s0 messages. -.Sp -When performing signature-based message protection, -this \*(L"protection certificate\*(R", also called \*(L"signer certificate\*(R", -will be included first in the extraCerts field of outgoing messages -and the signature is done with the corresponding key. -In Initialization Request (\s-1IR\s0) messages this can be used for authenticating -using an external entity certificate as defined in appendix E.7 of \s-1RFC 4210.\s0 -.Sp -For Key Update Request (\s-1KUR\s0) messages this is also used as -the certificate to be updated if the \fB\-oldcert\fR option is not given. -.Sp -If the file includes further certs, they are appended to the untrusted certs -because they typically constitute the chain of the client certificate, which -is included in the extraCerts field in signature-protected request messages. -.IP "\fB\-own_trusted\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-own_trusted filenames|uris" -If this list of certificates is provided then the chain built for -the client-side \s-1CMP\s0 signer certificate given with the \fB\-cert\fR option -is verified using the given certificates as trust anchors. -.Sp -Multiple sources may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Each source may contain multiple certificates. -.Sp -The certificate verification options -\&\fB\-verify_hostname\fR, \fB\-verify_ip\fR, and \fB\-verify_email\fR -have no effect on the certificate verification enabled via this option. -.IP "\fB\-key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-key filename|uri" -The corresponding private key file for the client's current certificate given in -the \fB\-cert\fR option. -This will be used for signature-based message protection unless the \fB\-secret\fR -option indicating MAC-based protection or \fB\-unprotected_requests\fR is given. -.Sp -It is also used as a fallback for the \fB\-newkey\fR option with \s-1IR/CR/KUR\s0 messages. -.IP "\fB\-keypass\fR \fIarg\fR" 4 -.IX Item "-keypass arg" -Pass phrase source for the private key given with the \fB\-key\fR option. -Also used for \fB\-cert\fR and \fB\-oldcert\fR in case it is an encrypted PKCS#12 file. -If not given here, the password will be prompted for if needed. -.Sp -For more information about the format of \fIarg\fR see -\&\fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-digest\fR \fIname\fR" 4 -.IX Item "-digest name" -Specifies name of supported digest to use in \s-1RFC 4210\s0's \s-1MSG_SIG_ALG\s0 -and as the one-way function (\s-1OWF\s0) in \f(CW\*(C`MSG_MAC_ALG\*(C'\fR. -If applicable, this is used for message protection and -proof-of-possession (\s-1POPO\s0) signatures. -To see the list of supported digests, use \f(CW\*(C`openssl list \-digest\-commands\*(C'\fR. -Defaults to \f(CW\*(C`sha256\*(C'\fR. -.IP "\fB\-mac\fR \fIname\fR" 4 -.IX Item "-mac name" -Specifies the name of the \s-1MAC\s0 algorithm in \f(CW\*(C`MSG_MAC_ALG\*(C'\fR. -To get the names of supported \s-1MAC\s0 algorithms use \f(CW\*(C`openssl list \-mac\-algorithms\*(C'\fR -and possibly combine such a name with the name of a supported digest algorithm, -e.g., hmacWithSHA256. -Defaults to \f(CW\*(C`hmac\-sha1\*(C'\fR as per \s-1RFC 4210.\s0 -.IP "\fB\-extracerts\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-extracerts filenames|uris" -Certificates to append in the extraCerts field when sending messages. -They can be used as the default \s-1CMP\s0 signer certificate chain to include. -.Sp -Multiple sources may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Each source may contain multiple certificates. -.IP "\fB\-unprotected_requests\fR" 4 -.IX Item "-unprotected_requests" -Send request messages without CMP-level protection. -.SS "Credentials format options" -.IX Subsection "Credentials format options" -.IP "\fB\-certform\fR \fIPEM|DER\fR" 4 -.IX Item "-certform PEM|DER" -File format to use when saving a certificate to a file. -Default value is \s-1PEM.\s0 -.IP "\fB\-crlform\fR \fIPEM|DER\fR" 4 -.IX Item "-crlform PEM|DER" -File format to use when saving a \s-1CRL\s0 to a file. -Default value is \s-1DER. -DER\s0 format is preferred because it enables more efficient storage -of large CRLs. -.IP "\fB\-keyform\fR \fIPEM|DER|P12|ENGINE\fR" 4 -.IX Item "-keyform PEM|DER|P12|ENGINE" -The format of the key input; unspecified by default. -See \*(L"Format Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-otherpass\fR \fIarg\fR" 4 -.IX Item "-otherpass arg" -Pass phrase source for certificate given with the \fB\-trusted\fR, \fB\-untrusted\fR, -\&\fB\-own_trusted\fR, \fB\-srvcert\fR, \fB\-crlcert\fR, \fB\-out_trusted\fR, \fB\-extracerts\fR, -\&\fB\-srv_trusted\fR, \fB\-srv_untrusted\fR, \fB\-ref_cert\fR, \fB\-rsp_cert\fR, -\&\fB\-rsp_extracerts\fR, \fB\-rsp_capubs\fR, -\&\fB\-rsp_newwithnew\fR, \fB\-rsp_newwithold\fR, \fB\-rsp_oldwithnew\fR, -\&\fB\-tls_extra\fR, and \fB\-tls_trusted\fR options. -If not given here, the password will be prompted for if needed. -.Sp -For more information about the format of \fIarg\fR see -\&\fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.Sp -As an alternative to using this combination: -.Sp -.Vb 1 -\& \-engine {engineid} \-key {keyid} \-keyform ENGINE -.Ve -.Sp -\&... it's also possible to just give the key \s-1ID\s0 in \s-1URI\s0 form to \fB\-key\fR, -like this: -.Sp -.Vb 1 -\& \-key org.openssl.engine:{engineid}:{keyid} -.Ve -.Sp -This applies to all options specifying keys: \fB\-key\fR, \fB\-newkey\fR, and -\&\fB\-tls_key\fR. -.SS "Provider options" -.IX Subsection "Provider options" -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SS "Random state options" -.IX Subsection "Random state options" -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.SS "\s-1TLS\s0 connection options" -.IX Subsection "TLS connection options" -.IP "\fB\-tls_used\fR" 4 -.IX Item "-tls_used" -Make the \s-1CMP\s0 client use \s-1TLS\s0 (regardless if other TLS-related options are set) -for message exchange with the server via \s-1HTTP.\s0 -This option is not supported with the \fI\-port\fR option. -It is implied if the \fB\-server\fR option is given with the scheme \f(CW\*(C`https\*(C'\fR. -It is ignored if the \fB\-server\fR option is not given or \fB\-use_mock_srv\fR is given -or \fB\-rspin\fR is given with enough filename arguments. -.Sp -The following TLS-related options are ignored if \s-1TLS\s0 is not used. -.IP "\fB\-tls_cert\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-tls_cert filename|uri" -Client's \s-1TLS\s0 certificate to use for authenticating to the \s-1TLS\s0 server. -If the source includes further certs they are used (along with \fB\-untrusted\fR -certs) for constructing the client cert chain provided to the \s-1TLS\s0 server. -.IP "\fB\-tls_key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-tls_key filename|uri" -Private key for the client's \s-1TLS\s0 certificate. -.IP "\fB\-tls_keypass\fR \fIarg\fR" 4 -.IX Item "-tls_keypass arg" -Pass phrase source for client's private \s-1TLS\s0 key \fB\-tls_key\fR. -Also used for \fB\-tls_cert\fR in case it is an encrypted PKCS#12 file. -If not given here, the password will be prompted for if needed. -.Sp -For more information about the format of \fIarg\fR see -\&\fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-tls_extra\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-tls_extra filenames|uris" -Extra certificates to provide to the \s-1TLS\s0 server during handshake. -.IP "\fB\-tls_trusted\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-tls_trusted filenames|uris" -Trusted certificate(s) to use for validating the \s-1TLS\s0 server certificate. -This implies hostname validation. -.Sp -Multiple sources may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Each source may contain multiple certificates. -.Sp -The certificate verification options -\&\fB\-verify_hostname\fR, \fB\-verify_ip\fR, and \fB\-verify_email\fR -have no effect on the certificate verification enabled via this option. -.IP "\fB\-tls_host\fR \fIname\fR" 4 -.IX Item "-tls_host name" -Address to be checked during hostname validation. -This may be a \s-1DNS\s0 name or an \s-1IP\s0 address. -If not given it defaults to the \fB\-server\fR address. -.SS "Client-side options for debugging and offline scenarios" -.IX Subsection "Client-side options for debugging and offline scenarios" -.IP "\fB\-batch\fR" 4 -.IX Item "-batch" -Do not interactively prompt for input, for instance when a password is needed. -This can be useful for batch processing and testing. -.IP "\fB\-repeat\fR \fInumber\fR" 4 -.IX Item "-repeat number" -Invoke the command the given positive number of times with the same parameters. -Default is one invocation. -.IP "\fB\-reqin\fR \fIfilenames\fR" 4 -.IX Item "-reqin filenames" -Take the sequence of \s-1CMP\s0 requests to send to the server from the given file(s) -rather than from the sequence of requests produced internally. -.Sp -This option is useful for supporting offline scenarios where the certificate -request (or any other \s-1CMP\s0 request) is produced beforehand and sent out later. -.Sp -This option is ignored if the \fB\-rspin\fR option is given -because in the latter case no requests are actually sent. -.Sp -Note that in any case the client produces internally its sequence -of \s-1CMP\s0 request messages. Thus, all options required for doing this -(such as \fB\-cmd\fR and all options providing the required parameters) -need to be given also when the \fB\-reqin\fR option is present. -.Sp -If the \fB\-reqin\fR option is given for a certificate request -and no \fB\-newkey\fR, \fB\-key\fR, \fB\-oldcert\fR, or \fB\-csr\fR option is given, -a fallback public key is taken from the request message file -(if it is included in the certificate template). -.Sp -Hint: In case the \fB\-reqin\fR option is given for a certificate request, there are -situations where the client has access to the public key to be certified but -not to the private key that by default will be needed for proof of possession. -In this case the \s-1POPO\s0 is not actually needed (because the internally produced -certificate request message will not be sent), and its generation -can be disabled using the options \fB\-popo\fR \fI\-1\fR or \fB\-popo\fR \fI0\fR. -.Sp -Multiple filenames may be given, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -.Sp -The files are read as far as needed to complete the transaction -and filenames have been provided. If more requests are needed, -the remaining ones are taken from the items at the respective position -in the sequence of requests produced internally. -.Sp -The client needs to update the recipNonce field in the given requests (except -for the first one) in order to satisfy the checks to be performed by the server. -This causes re-protection (if protecting requests is required). -.IP "\fB\-reqin_new_tid\fR" 4 -.IX Item "-reqin_new_tid" -Use a fresh transactionID for \s-1CMP\s0 request messages read using \fB\-reqin\fR, -which causes their reprotection (if protecting requests is required). -This may be needed in case the sequence of requests is reused -and the \s-1CMP\s0 server complains that the transaction \s-1ID\s0 has already been used. -.IP "\fB\-reqout\fR \fIfilenames\fR" 4 -.IX Item "-reqout filenames" -Save the sequence of \s-1CMP\s0 requests created by the client to the given file(s). -These requests are not sent to the server if the \fB\-reqin\fR option is used, too. -.Sp -Multiple filenames may be given, separated by commas and/or whitespace. -.Sp -Files are written as far as needed to save the transaction -and filenames have been provided. -If the transaction contains more requests, the remaining ones are not saved. -.IP "\fB\-reqout_only\fR \fIfilename\fR" 4 -.IX Item "-reqout_only filename" -Save the first \s-1CMP\s0 requests created by the client to the given file and exit. -Any options related to \s-1CMP\s0 servers and their responses are ignored. -.Sp -This option is useful for supporting offline scenarios where the certificate -request (or any other \s-1CMP\s0 request) is produced beforehand and sent out later. -.IP "\fB\-rspin\fR \fIfilenames\fR" 4 -.IX Item "-rspin filenames" -Process the sequence of \s-1CMP\s0 responses provided in the given file(s), -not contacting any given server, -as long as enough filenames are provided to complete the transaction. -.Sp -Multiple filenames may be given, separated by commas and/or whitespace. -.Sp -Any server specified via the \fI\-server\fR or \fI\-use_mock_srv\fR options is contacted -only if more responses are needed to complete the transaction. -In this case the transaction will fail -unless the server has been prepared to continue the already started transaction. -.IP "\fB\-rspout\fR \fIfilenames\fR" 4 -.IX Item "-rspout filenames" -Save the sequence of actually used \s-1CMP\s0 responses to the given file(s). -These have been received from the server unless \fB\-rspin\fR takes effect. -.Sp -Multiple filenames may be given, separated by commas and/or whitespace. -.Sp -Files are written as far as needed to save the responses -contained in the transaction and filenames have been provided. -If the transaction contains more responses, the remaining ones are not saved. -.IP "\fB\-use_mock_srv\fR" 4 -.IX Item "-use_mock_srv" -Test the client using the internal \s-1CMP\s0 server mock-up at \s-1API\s0 level, -bypassing socket-based transfer via \s-1HTTP.\s0 -This excludes the \fB\-server\fR and \fB\-port\fR options. -.SS "Mock server options" -.IX Subsection "Mock server options" -.IP "\fB\-port\fR \fInumber\fR" 4 -.IX Item "-port number" -Act as HTTP-based \s-1CMP\s0 server mock-up listening on the given local port. -The client may address the server via, e.g., \f(CW127.0.0.1\fR or \f(CW\*(C`[::1]\*(C'\fR. -This option excludes the \fB\-server\fR and \fB\-use_mock_srv\fR options. -The \fB\-rspin\fR, \fB\-rspout\fR, \fB\-reqin\fR, and \fB\-reqout\fR options -so far are not supported in this mode. -.IP "\fB\-max_msgs\fR \fInumber\fR" 4 -.IX Item "-max_msgs number" -Maximum number of \s-1CMP\s0 (request) messages the \s-1CMP HTTP\s0 server mock-up -should handle, which must be nonnegative. -The default value is 0, which means that no limit is imposed. -In any case the server terminates on internal errors, but not when it -detects a CMP-level error that it can successfully answer with an error message. -.IP "\fB\-srv_ref\fR \fIvalue\fR" 4 -.IX Item "-srv_ref value" -Reference value to use as senderKID of server in case no \fB\-srv_cert\fR is given. -.IP "\fB\-srv_secret\fR \fIarg\fR" 4 -.IX Item "-srv_secret arg" -Password source for server authentication with a pre-shared key (secret). -.IP "\fB\-srv_cert\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-srv_cert filename|uri" -Certificate of the server. -.IP "\fB\-srv_key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-srv_key filename|uri" -Private key used by the server for signing messages. -.IP "\fB\-srv_keypass\fR \fIarg\fR" 4 -.IX Item "-srv_keypass arg" -Server private key (and cert) file pass phrase source. -.IP "\fB\-srv_trusted\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-srv_trusted filenames|uris" -Trusted certificates for client authentication. -.Sp -The certificate verification options -\&\fB\-verify_hostname\fR, \fB\-verify_ip\fR, and \fB\-verify_email\fR -have no effect on the certificate verification enabled via this option. -.IP "\fB\-srv_untrusted\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-srv_untrusted filenames|uris" -Intermediate \s-1CA\s0 certs that may be useful when validating client certificates. -.IP "\fB\-ref_cert\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-ref_cert filename|uri" -Certificate to be expected for \s-1RR\s0 messages and any oldCertID in \s-1KUR\s0 messages. -.IP "\fB\-rsp_cert\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-rsp_cert filename|uri" -Certificate to be returned as mock enrollment result. -.IP "\fB\-rsp_crl\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-rsp_crl filename|uri" -\&\s-1CRL\s0 to be returned in genp of type \f(CW\*(C`crls\*(C'\fR. -.IP "\fB\-rsp_extracerts\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-rsp_extracerts filenames|uris" -Extra certificates to be included in mock certification responses. -.IP "\fB\-rsp_capubs\fR \fIfilenames\fR|\fIuris\fR" 4 -.IX Item "-rsp_capubs filenames|uris" -\&\s-1CA\s0 certificates to be included in mock Initialization Response (\s-1IP\s0) message. -.IP "\fB\-rsp_newwithnew\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-rsp_newwithnew filename|uri" -Certificate to be returned in newWithNew field of genp of type rootCaKeyUpdate. -.IP "\fB\-rsp_newwithold\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-rsp_newwithold filename|uri" -Certificate to be returned in newWithOld field of genp of type rootCaKeyUpdate. -.IP "\fB\-rsp_oldwithnew\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-rsp_oldwithnew filename|uri" -Certificate to be returned in oldWithNew field of genp of type rootCaKeyUpdate. -.IP "\fB\-poll_count\fR \fInumber\fR" 4 -.IX Item "-poll_count number" -Number of times the client must poll before receiving a certificate. -.IP "\fB\-check_after\fR \fInumber\fR" 4 -.IX Item "-check_after number" -The checkAfter value (number of seconds to wait) to include in poll response. -.IP "\fB\-grant_implicitconf\fR" 4 -.IX Item "-grant_implicitconf" -Grant implicit confirmation of newly enrolled certificate. -.IP "\fB\-pkistatus\fR \fInumber\fR" 4 -.IX Item "-pkistatus number" -PKIStatus to be included in server response. -Valid range is 0 (accepted) .. 6 (keyUpdateWarning). -.IP "\fB\-failure\fR \fInumber\fR" 4 -.IX Item "-failure number" -A single failure info bit number to be included in server response. -Valid range is 0 (badAlg) .. 26 (duplicateCertReq). -.IP "\fB\-failurebits\fR \fInumber\fR Number representing failure bits to be included in server response. Valid range is 0 .. 2^27 \- 1." 4 -.IX Item "-failurebits number Number representing failure bits to be included in server response. Valid range is 0 .. 2^27 - 1." -.PD 0 -.IP "\fB\-statusstring\fR \fIarg\fR" 4 -.IX Item "-statusstring arg" -.PD -Text to be included as status string in server response. -.IP "\fB\-send_error\fR" 4 -.IX Item "-send_error" -Force server to reply with error message. -.IP "\fB\-send_unprotected\fR" 4 -.IX Item "-send_unprotected" -Send response messages without CMP-level protection. -.IP "\fB\-send_unprot_err\fR" 4 -.IX Item "-send_unprot_err" -In case of negative responses, server shall send unprotected error messages, -certificate responses (\s-1IP/CP/KUP\s0), and revocation responses (\s-1RP\s0). -\&\s-1WARNING:\s0 This setting leads to behavior violating \s-1RFC 4210.\s0 -.IP "\fB\-accept_unprotected\fR" 4 -.IX Item "-accept_unprotected" -Accept missing or invalid protection of requests. -.IP "\fB\-accept_unprot_err\fR" 4 -.IX Item "-accept_unprot_err" -Accept unprotected error messages from client. -So far this has no effect because the server does not accept any error messages. -.IP "\fB\-accept_raverified\fR" 4 -.IX Item "-accept_raverified" -Accept \s-1RAVERIFED\s0 as proof of possession (\s-1POPO\s0). -.SS "Certificate verification options, for both \s-1CMP\s0 and \s-1TLS\s0" -.IX Subsection "Certificate verification options, for both CMP and TLS" -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.Sp -The certificate verification options -\&\fB\-verify_hostname\fR, \fB\-verify_ip\fR, and \fB\-verify_email\fR -only affect the certificate verification enabled via the \fB\-out_trusted\fR option. -.SH "NOTES" -.IX Header "NOTES" -When a client obtains, from a \s-1CMP\s0 server, \s-1CA\s0 certificates that it is going to -trust, for instance via the \f(CW\*(C`caPubs\*(C'\fR field of a certificate response -or using general messages with infoType \f(CW\*(C`caCerts\*(C'\fR or \f(CW\*(C`rootCaCert\*(C'\fR, -authentication of the \s-1CMP\s0 server is particularly critical. -So special care must be taken setting up server authentication -using \fB\-trusted\fR and related options for certificate-based authentication -or \fB\-secret\fR for MAC-based protection. -If authentication is certificate-based, the \fB\-srvcertout\fR option -should be used to obtain the validated server certificate -and perform an authorization check based on it. -.PP -When setting up \s-1CMP\s0 configurations and experimenting with enrollment options -typically various errors occur until the configuration is correct and complete. -When the \s-1CMP\s0 server reports an error the client will by default -check the protection of the \s-1CMP\s0 response message. -Yet some \s-1CMP\s0 services tend not to protect negative responses. -In this case the client will reject them, and thus their contents are not shown -although they usually contain hints that would be helpful for diagnostics. -For assisting in such cases the \s-1CMP\s0 client offers a workaround via the -\&\fB\-unprotected_errors\fR option, which allows accepting such negative messages. -.PP -If OpenSSL was built with trace support enabled (e.g., \f(CW\*(C`./config enable\-trace\*(C'\fR) -and the environment variable \fB\s-1OPENSSL_TRACE\s0\fR includes \fB\s-1HTTP\s0\fR, -the requests and the response headers transferred via \s-1HTTP\s0 are printed. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.SS "Simple examples using the default OpenSSL configuration file" -.IX Subsection "Simple examples using the default OpenSSL configuration file" -This \s-1CMP\s0 client implementation comes with demonstrative \s-1CMP\s0 sections -in the example configuration file \fIopenssl/apps/openssl.cnf\fR, -which can be used to interact conveniently with the Insta Demo \s-1CA.\s0 -.PP -In order to enroll an initial certificate from that \s-1CA\s0 it is sufficient -to issue the following shell commands. -.PP -.Vb 1 -\& export OPENSSL_CONF=/path/to/openssl/apps/openssl.cnf -.Ve -.PP -.Vb 2 -\& openssl genrsa \-out insta.priv.pem -\& openssl cmp \-section insta -.Ve -.PP -This should produce the file \fIinsta.cert.pem\fR containing a new certificate -for the private key held in \fIinsta.priv.pem\fR. -It can be viewed using, e.g., -.PP -.Vb 1 -\& openssl x509 \-noout \-text \-in insta.cert.pem -.Ve -.PP -In case the network setup requires using an \s-1HTTP\s0 proxy it may be given as usual -via the environment variable \fBhttp_proxy\fR or via the \fB\-proxy\fR option in the -configuration file or the \s-1CMP\s0 command-line argument \fB\-proxy\fR, for example -.PP -.Vb 1 -\& \-proxy http://192.168.1.1:8080 -.Ve -.PP -In the Insta Demo \s-1CA\s0 scenario both clients and the server may use the pre-shared -secret \fIinsta\fR and the reference value \fI3078\fR to authenticate to each other. -.PP -Alternatively, \s-1CMP\s0 messages may be protected in signature-based manner, -where the trust anchor in this case is \fIinsta.ca.crt\fR -and the client may use any certificate already obtained from that \s-1CA,\s0 -as specified in the \fB[signature]\fR section of the example configuration. -This can be used in combination with the \fB[insta]\fR section simply by -.PP -.Vb 1 -\& openssl cmp \-section insta,signature -.Ve -.PP -By default the \s-1CMP IR\s0 message type is used, yet \s-1CR\s0 works equally here. -This may be specified directly at the command line: -.PP -.Vb 1 -\& openssl cmp \-section insta \-cmd cr -.Ve -.PP -or by referencing in addition the \fB[cr]\fR section of the example configuration: -.PP -.Vb 1 -\& openssl cmp \-section insta,cr -.Ve -.PP -In order to update the enrolled certificate one may call -.PP -.Vb 1 -\& openssl cmp \-section insta,kur,signature -.Ve -.PP -using signature-based protection with the certificate that is to be updated. -For certificate updates, MAC-based protection should generally not be used. -.PP -In a similar way any previously enrolled certificate may be revoked by -.PP -.Vb 1 -\& openssl cmp \-section insta,rr \-trusted insta.ca.crt -.Ve -.PP -or -.PP -.Vb 1 -\& openssl cmp \-section insta,rr,signature -.Ve -.PP -Many more options can be given in the configuration file -and/or on the command line. -For instance, the \fB\-reqexts\fR \s-1CLI\s0 option may refer to a section in the -configuration file defining X.509 extensions to use in certificate requests, -such as \f(CW\*(C`v3_req\*(C'\fR in \fIopenssl/apps/openssl.cnf\fR: -.PP -.Vb 1 -\& openssl cmp \-section insta,cr \-reqexts v3_req -.Ve -.SS "Certificate enrollment" -.IX Subsection "Certificate enrollment" -The following examples do not make use of a configuration file at first. -They assume that a \s-1CMP\s0 server can be contacted on the local \s-1TCP\s0 port 80 -and accepts requests under the alias \fI/pkix/\fR. -.PP -For enrolling its very first certificate the client generates a client key -and sends an initial request message to the local \s-1CMP\s0 server -using a pre-shared secret key for mutual authentication. -In this example the client does not have the \s-1CA\s0 certificate yet, -so we specify the name of the \s-1CA\s0 with the \fB\-recipient\fR option -and save any \s-1CA\s0 certificates that we may receive in the \f(CW\*(C`capubs.pem\*(C'\fR file. -.PP -In below command line usage examples the \f(CW\*(C`\e\*(C'\fR at line ends is used just -for formatting; each of the command invocations should be on a single line. -.PP -.Vb 5 -\& openssl genrsa \-out cl_key.pem -\& openssl cmp \-cmd ir \-server 127.0.0.1:80/pkix/ \-recipient "/CN=CMPserver" \e -\& \-ref 1234 \-secret pass:1234\-5678 \e -\& \-newkey cl_key.pem \-subject "/CN=MyName" \e -\& \-cacertsout capubs.pem \-certout cl_cert.pem -.Ve -.SS "Certificate update" -.IX Subsection "Certificate update" -Then, when the client certificate and its related key pair needs to be updated, -the client can send a key update request taking the certs in \f(CW\*(C`capubs.pem\*(C'\fR -as trusted for authenticating the server and using the previous cert and key -for its own authentication. -Then it can start using the new cert and key. -.PP -.Vb 6 -\& openssl genrsa \-out cl_key_new.pem -\& openssl cmp \-cmd kur \-server 127.0.0.1:80/pkix/ \e -\& \-trusted capubs.pem \e -\& \-cert cl_cert.pem \-key cl_key.pem \e -\& \-newkey cl_key_new.pem \-certout cl_cert.pem -\& cp cl_key_new.pem cl_key.pem -.Ve -.PP -This command sequence can be repeated as often as needed. -.SS "Requesting information from \s-1CMP\s0 server" -.IX Subsection "Requesting information from CMP server" -Requesting \*(L"all relevant information\*(R" with an empty General Message. -This prints information about all received \s-1ITAV\s0 \fBinfoType\fRs to stdout. -.PP -.Vb 2 -\& openssl cmp \-cmd genm \-server 127.0.0.1/pkix/ \-recipient "/CN=CMPserver" \e -\& \-ref 1234 \-secret pass:1234\-5678 -.Ve -.SS "Using a custom configuration file" -.IX Subsection "Using a custom configuration file" -For \s-1CMP\s0 client invocations, in particular for certificate enrollment, -usually many parameters need to be set, which is tedious and error-prone to do -on the command line. -Therefore, the client offers the possibility to read -options from sections of the OpenSSL config file, usually called \fIopenssl.cnf\fR. -The values found there can still be extended and even overridden by any -subsequently loaded sections and on the command line. -.PP -After including in the configuration file the following sections: -.PP -.Vb 8 -\& [cmp] -\& server = 127.0.0.1 -\& path = pkix/ -\& trusted = capubs.pem -\& cert = cl_cert.pem -\& key = cl_key.pem -\& newkey = cl_key.pem -\& certout = cl_cert.pem -\& -\& [init] -\& recipient = "/CN=CMPserver" -\& trusted = -\& cert = -\& key = -\& ref = 1234 -\& secret = pass:1234\-5678\-1234\-567 -\& subject = "/CN=MyName" -\& cacertsout = capubs.pem -.Ve -.PP -the above enrollment transactions reduce to -.PP -.Vb 2 -\& openssl cmp \-section cmp,init -\& openssl cmp \-cmd kur \-newkey cl_key_new.pem -.Ve -.PP -and the above transaction using a general message reduces to -.PP -.Vb 1 -\& openssl cmp \-section cmp,init \-cmd genm -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-genrsa\fR\|(1), \fBopenssl\-ecparam\fR\|(1), \fBopenssl\-list\fR\|(1), -\&\fBopenssl\-req\fR\|(1), \fBopenssl\-x509\fR\|(1), \fBx509v3_config\fR\|(5) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBcmp\fR application was added in OpenSSL 3.0. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-profile\fR option was added in OpenSSL 3.3. -.PP -\&\fB\-crlcert\fR, \fB\-oldcrl\fR, \fB\-crlout\fR, \fB\-crlform\fR -and \fB\-rsp_crl\fR options were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-cms.1ossl b/openssl-install/share/man/man1/openssl-cms.1ossl deleted file mode 100644 index 9c5b85dd..00000000 --- a/openssl-install/share/man/man1/openssl-cms.1ossl +++ /dev/null @@ -1,1000 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CMS 1ossl" -.TH OPENSSL-CMS 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-cms \- CMS command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBcms\fR -[\fB\-help\fR] -.PP -General options: -.PP -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-config\fR \fIconfigfile\fR] -.PP -Operation options: -.PP -[\fB\-encrypt\fR] -[\fB\-decrypt\fR] -[\fB\-sign\fR] -[\fB\-verify\fR] -[\fB\-resign\fR] -[\fB\-sign_receipt\fR] -[\fB\-verify_receipt\fR \fIreceipt\fR] -[\fB\-digest\fR \fIdigest\fR] -[\fB\-digest_create\fR] -[\fB\-digest_verify\fR] -[\fB\-compress\fR] -[\fB\-uncompress\fR] -[\fB\-EncryptedData_encrypt\fR] -[\fB\-EncryptedData_decrypt\fR] -[\fB\-data_create\fR] -[\fB\-data_out\fR] -[\fB\-cmsout\fR] -.PP -File format options: -.PP -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR] -[\fB\-rctform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR] -[\fB\-stream\fR] -[\fB\-indef\fR] -[\fB\-noindef\fR] -[\fB\-binary\fR] -[\fB\-crlfeol\fR] -[\fB\-asciicrlf\fR] -.PP -Keys and password options: -.PP -[\fB\-pwri_password\fR \fIpassword\fR] -[\fB\-secretkey\fR \fIkey\fR] -[\fB\-secretkeyid\fR \fIid\fR] -[\fB\-inkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-keyopt\fR \fIname\fR:\fIparameter\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -.PP -Encryption options: -.PP -[\fB\-originator\fR \fIfile\fR] -[\fB\-recip\fR \fIfile\fR] -[\fIrecipient-cert\fR ...] -[\fB\-\f(BIcipher\fB\fR] -[\fB\-wrap\fR \fIcipher\fR] -[\fB\-aes128\-wrap\fR] -[\fB\-aes192\-wrap\fR] -[\fB\-aes256\-wrap\fR] -[\fB\-des3\-wrap\fR] -[\fB\-debug_decrypt\fR] -.PP -Signing options: -.PP -[\fB\-md\fR \fIdigest\fR] -[\fB\-signer\fR \fIfile\fR] -[\fB\-certfile\fR \fIfile\fR] -[\fB\-cades\fR] -[\fB\-nodetach\fR] -[\fB\-nocerts\fR] -[\fB\-noattr\fR] -[\fB\-nosmimecap\fR] -[\fB\-receipt_request_all\fR] -[\fB\-receipt_request_first\fR] -[\fB\-receipt_request_from\fR \fIemailaddress\fR] -[\fB\-receipt_request_to\fR \fIemailaddress\fR] -.PP -Verification options: -.PP -[\fB\-signer\fR \fIfile\fR] -[\fB\-content\fR \fIfilename\fR] -[\fB\-no_content_verify\fR] -[\fB\-no_attr_verify\fR] -[\fB\-nosigs\fR] -[\fB\-noverify\fR] -[\fB\-nointern\fR] -[\fB\-cades\fR] -[\fB\-verify_retcode\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -.PP -Output options: -.PP -[\fB\-keyid\fR] -[\fB\-econtent_type\fR \fItype\fR] -[\fB\-text\fR] -[\fB\-certsout\fR \fIfile\fR] -[\fB\-to\fR \fIaddr\fR] -[\fB\-from\fR \fIaddr\fR] -[\fB\-subject\fR \fIsubj\fR] -.PP -Printing options: -.PP -[\fB\-noout\fR] -[\fB\-print\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-receipt_request_print\fR] -.PP -Validation options: -.PP -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command handles data in \s-1CMS\s0 format such as S/MIME v3.1 email messages. -It can encrypt, decrypt, sign, verify, compress, uncompress, and print messages. -.SH "OPTIONS" -.IX Header "OPTIONS" -There are a number of operation options that set the type of operation to be -performed: encrypt, decrypt, sign, verify, resign, sign_receipt, verify_receipt, -digest_create, digest_verify, compress, uncompress, -EncryptedData_encrypt, EncryptedData_decrypt, data_create, data_out, or cmsout. -The relevance of the other options depends on the operation type -and their meaning may vary according to it. -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.SS "General options" -.IX Subsection "General options" -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -The input message to be encrypted or signed or the message to be decrypted -or verified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -The message text that has been decrypted or verified or the output \s-1MIME\s0 -format message that has been signed or verified. -.IP "\fB\-config\fR \fIconfigfile\fR" 4 -.IX Item "-config configfile" -See \*(L"Configuration Option\*(R" in \fBopenssl\fR\|(1). -.SS "Operation options" -.IX Subsection "Operation options" -.IP "\fB\-encrypt\fR" 4 -.IX Item "-encrypt" -Encrypt data for the given recipient certificates. Input file is the message -to be encrypted. The output file is the encrypted data in \s-1MIME\s0 format. The -actual \s-1CMS\s0 type is \fBEnvelopedData\fR. -.Sp -Note that no revocation check is done for the recipient cert, so if that -key has been compromised, others may be able to decrypt the text. -.IP "\fB\-decrypt\fR" 4 -.IX Item "-decrypt" -Decrypt data using the supplied certificate and private key. Expects -encrypted datain \s-1MIME\s0 format for the input file. The decrypted data -is written to the output file. -.IP "\fB\-sign\fR" 4 -.IX Item "-sign" -Sign data using the supplied certificate and private key. Input file is -the message to be signed. The signed data in \s-1MIME\s0 format is written -to the output file. -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verify signed data. Expects a signed data on input and outputs -the signed data. Both clear text and opaque signing is supported. -.Sp -By default, validation of signer certificates and their chain -is done w.r.t. the S/MIME signing (\f(CW\*(C`smimesign\*(C'\fR) purpose. -For details see \*(L"Certificate Extensions\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.IP "\fB\-resign\fR" 4 -.IX Item "-resign" -Resign a message: take an existing message and one or more new signers. -.IP "\fB\-sign_receipt\fR" 4 -.IX Item "-sign_receipt" -Generate and output a signed receipt for the supplied message. The input -message \fBmust\fR contain a signed receipt request. Functionality is otherwise -similar to the \fB\-sign\fR operation. -.IP "\fB\-verify_receipt\fR \fIreceipt\fR" 4 -.IX Item "-verify_receipt receipt" -Verify a signed receipt in filename \fBreceipt\fR. The input message \fBmust\fR -contain the original receipt request. Functionality is otherwise similar -to the \fB\-verify\fR operation. -.IP "\fB\-digest\fR \fIdigest\fR" 4 -.IX Item "-digest digest" -When used with \fB\-sign\fR, provides the digest in hexadecimal form instead of -computing it from the original message content. Cannot be combined with \fB\-in\fR -or \fB\-nodetach\fR. -.Sp -This operation is the \s-1CMS\s0 equivalent of \fBopenssl\-pkeyutl\fR\|(1) signing. -When signing a pre-computed digest, the security relies on the digest and its -computation from the original message being trusted. -.IP "\fB\-digest_create\fR" 4 -.IX Item "-digest_create" -Create a \s-1CMS\s0 \fBDigestedData\fR type. -.IP "\fB\-digest_verify\fR" 4 -.IX Item "-digest_verify" -Verify a \s-1CMS\s0 \fBDigestedData\fR type and output the content. -.IP "\fB\-compress\fR" 4 -.IX Item "-compress" -Create a \s-1CMS\s0 \fBCompressedData\fR type. OpenSSL must be compiled with \fBzlib\fR -support for this option to work, otherwise it will output an error. -.IP "\fB\-uncompress\fR" 4 -.IX Item "-uncompress" -Uncompress a \s-1CMS\s0 \fBCompressedData\fR type and output the content. OpenSSL must be -compiled with \fBzlib\fR support for this option to work, otherwise it will -output an error. -.IP "\fB\-EncryptedData_encrypt\fR" 4 -.IX Item "-EncryptedData_encrypt" -Encrypt content using supplied symmetric key and algorithm using a \s-1CMS\s0 -\&\fBEncryptedData\fR type and output the content. -.IP "\fB\-EncryptedData_decrypt\fR" 4 -.IX Item "-EncryptedData_decrypt" -Decrypt content using supplied symmetric key and algorithm using a \s-1CMS\s0 -\&\fBEncryptedData\fR type and output the content. -.IP "\fB\-data_create\fR" 4 -.IX Item "-data_create" -Create a \s-1CMS\s0 \fBData\fR type. -.IP "\fB\-data_out\fR" 4 -.IX Item "-data_out" -\&\fBData\fR type and output the content. -.IP "\fB\-cmsout\fR" 4 -.IX Item "-cmsout" -Takes an input message and writes out a \s-1PEM\s0 encoded \s-1CMS\s0 structure. -.SS "File format options" -.IX Subsection "File format options" -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR" 4 -.IX Item "-inform DER|PEM|SMIME" -The input format of the \s-1CMS\s0 structure (if one is being read); -the default is \fB\s-1SMIME\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR" 4 -.IX Item "-outform DER|PEM|SMIME" -The output format of the \s-1CMS\s0 structure (if one is being written); -the default is \fB\s-1SMIME\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-rctform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR" 4 -.IX Item "-rctform DER|PEM|SMIME" -The signed receipt format for use with the \fB\-receipt_verify\fR; the default -is \fB\s-1SMIME\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-stream\fR, \fB\-indef\fR" 4 -.IX Item "-stream, -indef" -The \fB\-stream\fR and \fB\-indef\fR options are equivalent and enable streaming I/O -for encoding operations. This permits single pass processing of data without -the need to hold the entire contents in memory, potentially supporting very -large files. Streaming is automatically set for S/MIME signing with detached -data if the output format is \fB\s-1SMIME\s0\fR it is currently off by default for all -other operations. -.IP "\fB\-noindef\fR" 4 -.IX Item "-noindef" -Disable streaming I/O where it would produce and indefinite length constructed -encoding. This option currently has no effect. In future streaming will be -enabled by default on all relevant operations and this option will disable it. -.IP "\fB\-binary\fR" 4 -.IX Item "-binary" -Normally the input message is converted to \*(L"canonical\*(R" format which is -effectively using \s-1CR\s0 and \s-1LF\s0 as end of line: as required by the S/MIME -specification. When this option is present no translation occurs. This -is useful when handling binary data which may not be in \s-1MIME\s0 format. -.IP "\fB\-crlfeol\fR" 4 -.IX Item "-crlfeol" -Normally the output file uses a single \fB\s-1LF\s0\fR as end of line. When this -option is present \fB\s-1CRLF\s0\fR is used instead. -.IP "\fB\-asciicrlf\fR" 4 -.IX Item "-asciicrlf" -When signing use \s-1ASCII CRLF\s0 format canonicalisation. This strips trailing -whitespace from all lines, deletes trailing blank lines at \s-1EOF\s0 and sets -the encapsulated content type. This option is normally used with detached -content and an output signature format of \s-1DER.\s0 This option is not normally -needed when verifying as it is enabled automatically if the encapsulated -content format is detected. -.SS "Keys and password options" -.IX Subsection "Keys and password options" -.IP "\fB\-pwri_password\fR \fIpassword\fR" 4 -.IX Item "-pwri_password password" -Specify password for recipient. -.IP "\fB\-secretkey\fR \fIkey\fR" 4 -.IX Item "-secretkey key" -Specify symmetric key to use. The key must be supplied in hex format and be -consistent with the algorithm used. Supported by the \fB\-EncryptedData_encrypt\fR -\&\fB\-EncryptedData_decrypt\fR, \fB\-encrypt\fR and \fB\-decrypt\fR options. When used -with \fB\-encrypt\fR or \fB\-decrypt\fR the supplied key is used to wrap or unwrap the -content encryption key using an \s-1AES\s0 key in the \fBKEKRecipientInfo\fR type. -.IP "\fB\-secretkeyid\fR \fIid\fR" 4 -.IX Item "-secretkeyid id" -The key identifier for the supplied symmetric key for \fBKEKRecipientInfo\fR type. -This option \fBmust\fR be present if the \fB\-secretkey\fR option is used with -\&\fB\-encrypt\fR. With \fB\-decrypt\fR operations the \fIid\fR is used to locate the -relevant key if it is not supplied then an attempt is used to decrypt any -\&\fBKEKRecipientInfo\fR structures. -.IP "\fB\-inkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-inkey filename|uri" -The private key to use when signing or decrypting. This must match the -corresponding certificate. If this option is not specified then the -private key must be included in the certificate file specified with -the \fB\-recip\fR or \fB\-signer\fR file. When signing this option can be used -multiple times to specify successive keys. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The private key password source. For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-keyopt\fR \fIname\fR:\fIparameter\fR" 4 -.IX Item "-keyopt name:parameter" -For signing and encryption this option can be used multiple times to -set customised parameters for the preceding key or certificate. It can -currently be used to set RSA-PSS for signing, RSA-OAEP for encryption -or to modify default parameters for \s-1ECDH.\s0 -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The format of the private key file; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.SS "Encryption and decryption options" -.IX Subsection "Encryption and decryption options" -.IP "\fB\-originator\fR \fIfile\fR" 4 -.IX Item "-originator file" -A certificate of the originator of the encrypted message. Necessary for -decryption when Key Agreement is in use for a shared key. Currently, not -allowed for encryption. -.IP "\fB\-recip\fR \fIfile\fR" 4 -.IX Item "-recip file" -When decrypting a message this specifies the certificate of the recipient. -The certificate must match one of the recipients of the message. -.Sp -When encrypting a message this option may be used multiple times to specify -each recipient. This form \fBmust\fR be used if customised parameters are -required (for example to specify RSA-OAEP). -.Sp -Only certificates carrying \s-1RSA,\s0 Diffie-Hellman or \s-1EC\s0 keys are supported by this -option. -.IP "\fIrecipient-cert\fR ..." 4 -.IX Item "recipient-cert ..." -This is an alternative to using the \fB\-recip\fR option when encrypting a message. -One or more certificate filenames may be given. -.IP "\fB\-\f(BIcipher\fB\fR" 4 -.IX Item "-cipher" -The encryption algorithm to use. For example triple \s-1DES\s0 (168 bits) \- \fB\-des3\fR -or 256 bit \s-1AES\s0 \- \fB\-aes256\fR. Any standard algorithm name (as used by the -\&\fBEVP_get_cipherbyname()\fR function) can also be used preceded by a dash, for -example \fB\-aes\-128\-cbc\fR. See \fBopenssl\-enc\fR\|(1) for a list of ciphers -supported by your version of OpenSSL. -.Sp -Currently the \s-1AES\s0 variants with \s-1GCM\s0 mode are the only supported \s-1AEAD\s0 -algorithms. -.Sp -If not specified triple \s-1DES\s0 is used. Only used with \fB\-encrypt\fR and -\&\fB\-EncryptedData_create\fR commands. -.IP "\fB\-wrap\fR \fIcipher\fR" 4 -.IX Item "-wrap cipher" -Cipher algorithm to use for key wrap when encrypting the message using Key -Agreement for key transport. The algorithm specified should be suitable for key -wrap. -.IP "\fB\-aes128\-wrap\fR, \fB\-aes192\-wrap\fR, \fB\-aes256\-wrap\fR, \fB\-des3\-wrap\fR" 4 -.IX Item "-aes128-wrap, -aes192-wrap, -aes256-wrap, -des3-wrap" -Use \s-1AES128, AES192, AES256,\s0 or 3DES\-EDE, respectively, to wrap key. -Depending on the OpenSSL build options used, \fB\-des3\-wrap\fR may not be supported. -.IP "\fB\-debug_decrypt\fR" 4 -.IX Item "-debug_decrypt" -This option sets the \fB\s-1CMS_DEBUG_DECRYPT\s0\fR flag. This option should be used -with caution: see the notes section below. -.SS "Signing options" -.IX Subsection "Signing options" -.IP "\fB\-md\fR \fIdigest\fR" 4 -.IX Item "-md digest" -Digest algorithm to use when signing or resigning. If not present then the -default digest algorithm for the signing key will be used (usually \s-1SHA1\s0). -.IP "\fB\-signer\fR \fIfile\fR" 4 -.IX Item "-signer file" -A signing certificate. When signing or resigning a message, this option can be -used multiple times if more than one signer is required. -.IP "\fB\-certfile\fR \fIfile\fR" 4 -.IX Item "-certfile file" -Allows additional certificates to be specified. When signing these will -be included with the message. When verifying, these will be searched for -signer certificates and will be used for chain building. -.Sp -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-cades\fR" 4 -.IX Item "-cades" -When used with \fB\-sign\fR, -add an \s-1ESS\s0 signingCertificate or \s-1ESS\s0 signingCertificateV2 signed-attribute -to the SignerInfo, in order to make the signature comply with the requirements -for a CAdES Basic Electronic Signature (CAdES-BES). -.IP "\fB\-nodetach\fR" 4 -.IX Item "-nodetach" -When signing a message use opaque signing: this form is more resistant -to translation by mail relays but it cannot be read by mail agents that -do not support S/MIME. Without this option cleartext signing with -the \s-1MIME\s0 type multipart/signed is used. -.IP "\fB\-nocerts\fR" 4 -.IX Item "-nocerts" -When signing a message the signer's certificate is normally included -with this option it is excluded. This will reduce the size of the -signed message but the verifier must have a copy of the signers certificate -available locally (passed using the \fB\-certfile\fR option for example). -.IP "\fB\-noattr\fR" 4 -.IX Item "-noattr" -Normally when a message is signed a set of attributes are included which -include the signing time and supported symmetric algorithms. With this -option they are not included. -.IP "\fB\-nosmimecap\fR" 4 -.IX Item "-nosmimecap" -Exclude the list of supported algorithms from signed attributes, other options -such as signing time and content type are still included. -.IP "\fB\-receipt_request_all\fR, \fB\-receipt_request_first\fR" 4 -.IX Item "-receipt_request_all, -receipt_request_first" -For \fB\-sign\fR option include a signed receipt request. Indicate requests should -be provided by all recipient or first tier recipients (those mailed directly -and not from a mailing list). Ignored it \fB\-receipt_request_from\fR is included. -.IP "\fB\-receipt_request_from\fR \fIemailaddress\fR" 4 -.IX Item "-receipt_request_from emailaddress" -For \fB\-sign\fR option include a signed receipt request. Add an explicit email -address where receipts should be supplied. -.IP "\fB\-receipt_request_to\fR \fIemailaddress\fR" 4 -.IX Item "-receipt_request_to emailaddress" -Add an explicit email address where signed receipts should be sent to. This -option \fBmust\fR but supplied if a signed receipt is requested. -.SS "Verification options" -.IX Subsection "Verification options" -.IP "\fB\-signer\fR \fIfile\fR" 4 -.IX Item "-signer file" -If a message has been verified successfully then the signers certificate(s) -will be written to this file if the verification was successful. -.IP "\fB\-content\fR \fIfilename\fR" 4 -.IX Item "-content filename" -This specifies a file containing the detached content for operations taking -S/MIME input, such as the \fB\-verify\fR command. This is only usable if the \s-1CMS\s0 -structure is using the detached signature form where the content is -not included. This option will override any content if the input format -is S/MIME and it uses the multipart/signed \s-1MIME\s0 content type. -.IP "\fB\-no_content_verify\fR" 4 -.IX Item "-no_content_verify" -Do not verify signed content signatures. -.IP "\fB\-no_attr_verify\fR" 4 -.IX Item "-no_attr_verify" -Do not verify signed attribute signatures. -.IP "\fB\-nosigs\fR" 4 -.IX Item "-nosigs" -Don't verify message signature. -.IP "\fB\-noverify\fR" 4 -.IX Item "-noverify" -Do not verify the signers certificate of a signed message. -.IP "\fB\-nointern\fR" 4 -.IX Item "-nointern" -When verifying a message normally certificates (if any) included in -the message are searched for the signing certificate. With this option -only the certificates specified in the \fB\-certfile\fR option are used. -The supplied certificates can still be used as untrusted CAs however. -.IP "\fB\-cades\fR" 4 -.IX Item "-cades" -When used with \fB\-verify\fR, require and check signer certificate digest. -See the \s-1NOTES\s0 section for more details. -.IP "\fB\-verify_retcode\fR" 4 -.IX Item "-verify_retcode" -Exit nonzero on verification failure. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.SS "Output options" -.IX Subsection "Output options" -.IP "\fB\-keyid\fR" 4 -.IX Item "-keyid" -Use subject key identifier to identify certificates instead of issuer name and -serial number. The supplied certificate \fBmust\fR include a subject key -identifier extension. Supported by \fB\-sign\fR and \fB\-encrypt\fR options. -.IP "\fB\-econtent_type\fR \fItype\fR" 4 -.IX Item "-econtent_type type" -Set the encapsulated content type to \fItype\fR if not supplied the \fBData\fR type -is used. The \fItype\fR argument can be any valid \s-1OID\s0 name in either text or -numerical format. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -This option adds plain text (text/plain) \s-1MIME\s0 headers to the supplied -message if encrypting or signing. If decrypting or verifying it strips -off text headers: if the decrypted or verified message is not of \s-1MIME\s0 -type text/plain then an error occurs. -.IP "\fB\-certsout\fR \fIfile\fR" 4 -.IX Item "-certsout file" -Any certificates contained in the input message are written to \fIfile\fR. -.IP "\fB\-to\fR, \fB\-from\fR, \fB\-subject\fR" 4 -.IX Item "-to, -from, -subject" -The relevant email headers. These are included outside the signed -portion of a message so they may be included manually. If signing -then many S/MIME mail clients check the signers certificate's email -address matches that specified in the From: address. -.SS "Printing options" -.IX Subsection "Printing options" -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -For the \fB\-cmsout\fR operation do not output the parsed \s-1CMS\s0 structure. -This is useful if the syntax of the \s-1CMS\s0 structure is being checked. -.IP "\fB\-print\fR" 4 -.IX Item "-print" -For the \fB\-cmsout\fR operation print out all fields of the \s-1CMS\s0 structure. -This implies \fB\-noout\fR. -This is mainly useful for testing purposes. -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -For the \fB\-cmsout\fR operation when \fB\-print\fR option is in use, specifies -printing options for string fields. For most cases \fButf8\fR is reasonable value. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-receipt_request_print\fR" 4 -.IX Item "-receipt_request_print" -For the \fB\-verify\fR operation print out the contents of any signed receipt -requests. -.SS "Validation options" -.IX Subsection "Validation options" -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.Sp -Any validation errors cause the command to exit. -.SH "NOTES" -.IX Header "NOTES" -The \s-1MIME\s0 message must be sent without any blank lines between the -headers and the output. Some mail programs will automatically add -a blank line. Piping the mail directly to sendmail is one way to -achieve the correct format. -.PP -The supplied message to be signed or encrypted must include the -necessary \s-1MIME\s0 headers or many S/MIME clients won't display it -properly (if at all). You can use the \fB\-text\fR option to automatically -add plain text headers. -.PP -A \*(L"signed and encrypted\*(R" message is one where a signed message is -then encrypted. This can be produced by encrypting an already signed -message: see the examples section. -.PP -This version of the program only allows one signer per message but it -will verify multiple signers on received messages. Some S/MIME clients -choke if a message contains multiple signers. It is possible to sign -messages \*(L"in parallel\*(R" by signing an already signed message. -.PP -The options \fB\-encrypt\fR and \fB\-decrypt\fR reflect common usage in S/MIME -clients. Strictly speaking these process \s-1CMS\s0 enveloped data: \s-1CMS\s0 -encrypted data is used for other purposes. -.PP -The \fB\-resign\fR option uses an existing message digest when adding a new -signer. This means that attributes must be present in at least one existing -signer using the same message digest or this operation will fail. -.PP -The \fB\-stream\fR and \fB\-indef\fR options enable streaming I/O support. -As a result the encoding is \s-1BER\s0 using indefinite length constructed encoding -and no longer \s-1DER.\s0 Streaming is supported for the \fB\-encrypt\fR operation and the -\&\fB\-sign\fR operation if the content is not detached. -.PP -Streaming is always used for the \fB\-sign\fR operation with detached data but -since the content is no longer part of the \s-1CMS\s0 structure the encoding -remains \s-1DER.\s0 -.PP -If the \fB\-decrypt\fR option is used without a recipient certificate then an -attempt is made to locate the recipient by trying each potential recipient -in turn using the supplied private key. To thwart the \s-1MMA\s0 attack -(Bleichenbacher's attack on \s-1PKCS\s0 #1 v1.5 \s-1RSA\s0 padding) all recipients are -tried whether they succeed or not and if no recipients match the message -is \*(L"decrypted\*(R" using a random key which will typically output garbage. -The \fB\-debug_decrypt\fR option can be used to disable the \s-1MMA\s0 attack protection -and return an error if no recipient can be found: this option should be used -with caution. For a fuller description see \fBCMS_decrypt\fR\|(3)). -.SH "CADES BASIC ELECTRONIC SIGNATURE (CADES-BES)" -.IX Header "CADES BASIC ELECTRONIC SIGNATURE (CADES-BES)" -A CAdES Basic Electronic Signature (CAdES-BES), -as defined in the European Standard \s-1ETSI EN 319 122\-1 V1.1.1,\s0 contains: -.IP "\(bu" 4 -The signed user data as defined in \s-1CMS\s0 (\s-1RFC 3852\s0); -.IP "\(bu" 4 -Content-type of the EncapsulatedContentInfo value being signed; -.IP "\(bu" 4 -Message-digest of the eContent \s-1OCTET STRING\s0 within encapContentInfo being signed; -.IP "\(bu" 4 -An \s-1ESS\s0 signingCertificate or \s-1ESS\s0 signingCertificateV2 attribute, -as defined in Enhanced Security Services (\s-1ESS\s0), \s-1RFC 2634\s0 and \s-1RFC 5035.\s0 -An \s-1ESS\s0 signingCertificate attribute only allows for \s-1SHA\-1\s0 as digest algorithm. -An \s-1ESS\s0 signingCertificateV2 attribute allows for any digest algorithm. -.IP "\(bu" 4 -The digital signature value computed on the user data and, when present, on the signed attributes. -.Sp -\&\s-1NOTE\s0 that the \fB\-cades\fR option applies to the \fB\-sign\fR or \fB\-verify\fR operations. -With this option, the \fB\-verify\fR operation also requires that the -signingCertificate attribute is present and checks that the given identifiers -match the verification trust chain built during the verification process. -.SH "EXIT CODES" -.IX Header "EXIT CODES" -.IP "0" 4 -The operation was completely successfully. -.IP "1" 4 -.IX Item "1" -An error occurred parsing the command options. -.IP "2" 4 -.IX Item "2" -One of the input files could not be read. -.IP "3" 4 -.IX Item "3" -An error occurred creating the \s-1CMS\s0 file or when reading the \s-1MIME\s0 -message. -.IP "4" 4 -.IX Item "4" -An error occurred decrypting or verifying the message. -.IP "5" 4 -.IX Item "5" -The message was verified correctly but an error occurred writing out -the signers certificates. -.SH "COMPATIBILITY WITH PKCS#7 FORMAT" -.IX Header "COMPATIBILITY WITH PKCS#7 FORMAT" -\&\fBopenssl\-smime\fR\|(1) can only process the older \fBPKCS#7\fR format. -\&\fBopenssl cms\fR supports Cryptographic Message Syntax format. -Use of some features will result in messages which cannot be processed by -applications which only support the older format. These are detailed below. -.PP -The use of the \fB\-keyid\fR option with \fB\-sign\fR or \fB\-encrypt\fR. -.PP -The \fB\-outform\fR \fI\s-1PEM\s0\fR option uses different headers. -.PP -The \fB\-compress\fR option. -.PP -The \fB\-secretkey\fR option when used with \fB\-encrypt\fR. -.PP -The use of \s-1PSS\s0 with \fB\-sign\fR. -.PP -The use of \s-1OAEP\s0 or non-RSA keys with \fB\-encrypt\fR. -.PP -Additionally the \fB\-EncryptedData_create\fR and \fB\-data_create\fR type cannot -be processed by the older \fBopenssl\-smime\fR\|(1) command. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a cleartext signed message: -.PP -.Vb 2 -\& openssl cms \-sign \-in message.txt \-text \-out mail.msg \e -\& \-signer mycert.pem -.Ve -.PP -Create an opaque signed message -.PP -.Vb 2 -\& openssl cms \-sign \-in message.txt \-text \-out mail.msg \-nodetach \e -\& \-signer mycert.pem -.Ve -.PP -Create a signed message, include some additional certificates and -read the private key from another file: -.PP -.Vb 2 -\& openssl cms \-sign \-in in.txt \-text \-out mail.msg \e -\& \-signer mycert.pem \-inkey mykey.pem \-certfile mycerts.pem -.Ve -.PP -Create a signed message with two signers, use key identifier: -.PP -.Vb 2 -\& openssl cms \-sign \-in message.txt \-text \-out mail.msg \e -\& \-signer mycert.pem \-signer othercert.pem \-keyid -.Ve -.PP -Send a signed message under Unix directly to sendmail, including headers: -.PP -.Vb 3 -\& openssl cms \-sign \-in in.txt \-text \-signer mycert.pem \e -\& \-from steve@openssl.org \-to someone@somewhere \e -\& \-subject "Signed message" | sendmail someone@somewhere -.Ve -.PP -Verify a message and extract the signer's certificate if successful: -.PP -.Vb 1 -\& openssl cms \-verify \-in mail.msg \-signer user.pem \-out signedtext.txt -.Ve -.PP -Send encrypted mail using triple \s-1DES:\s0 -.PP -.Vb 3 -\& openssl cms \-encrypt \-in in.txt \-from steve@openssl.org \e -\& \-to someone@somewhere \-subject "Encrypted message" \e -\& \-des3 user.pem \-out mail.msg -.Ve -.PP -Sign and encrypt mail: -.PP -.Vb 4 -\& openssl cms \-sign \-in ml.txt \-signer my.pem \-text \e -\& | openssl cms \-encrypt \-out mail.msg \e -\& \-from steve@openssl.org \-to someone@somewhere \e -\& \-subject "Signed and Encrypted message" \-des3 user.pem -.Ve -.PP -Note: the encryption command does not include the \fB\-text\fR option because the -message being encrypted already has \s-1MIME\s0 headers. -.PP -Decrypt a message: -.PP -.Vb 1 -\& openssl cms \-decrypt \-in mail.msg \-recip mycert.pem \-inkey key.pem -.Ve -.PP -The output from Netscape form signing is a PKCS#7 structure with the -detached signature format. You can use this program to verify the -signature by line wrapping the base64 encoded structure and surrounding -it with: -.PP -.Vb 2 -\& \-\-\-\-\-BEGIN PKCS7\-\-\-\-\- -\& \-\-\-\-\-END PKCS7\-\-\-\-\- -.Ve -.PP -and using the command, -.PP -.Vb 1 -\& openssl cms \-verify \-inform PEM \-in signature.pem \-content content.txt -.Ve -.PP -alternatively you can base64 decode the signature and use -.PP -.Vb 1 -\& openssl cms \-verify \-inform DER \-in signature.der \-content content.txt -.Ve -.PP -Create an encrypted message using 128 bit Camellia: -.PP -.Vb 1 -\& openssl cms \-encrypt \-in plain.txt \-camellia128 \-out mail.msg cert.pem -.Ve -.PP -Add a signer to an existing message: -.PP -.Vb 1 -\& openssl cms \-resign \-in mail.msg \-signer newsign.pem \-out mail2.msg -.Ve -.PP -Sign a message using RSA-PSS: -.PP -.Vb 2 -\& openssl cms \-sign \-in message.txt \-text \-out mail.msg \e -\& \-signer mycert.pem \-keyopt rsa_padding_mode:pss -.Ve -.PP -Create an encrypted message using RSA-OAEP: -.PP -.Vb 2 -\& openssl cms \-encrypt \-in plain.txt \-out mail.msg \e -\& \-recip cert.pem \-keyopt rsa_padding_mode:oaep -.Ve -.PP -Use \s-1SHA256 KDF\s0 with an \s-1ECDH\s0 certificate: -.PP -.Vb 2 -\& openssl cms \-encrypt \-in plain.txt \-out mail.msg \e -\& \-recip ecdhcert.pem \-keyopt ecdh_kdf_md:sha256 -.Ve -.PP -Print \s-1CMS\s0 signed binary data in human-readable form: -.PP -openssl cms \-in signed.cms \-binary \-inform \s-1DER\s0 \-cmsout \-print -.SH "BUGS" -.IX Header "BUGS" -The \s-1MIME\s0 parser isn't very clever: it seems to handle most messages that I've -thrown at it but it may choke on others. -.PP -The code currently will only write out the signer's certificate to a file: if -the signer has a separate encryption certificate this must be manually -extracted. There should be some heuristic that determines the correct -encryption certificate. -.PP -Ideally a database should be maintained of a certificates for each email -address. -.PP -The code doesn't currently take note of the permitted symmetric encryption -algorithms as supplied in the SMIMECapabilities signed attribute. this means the -user has to manually include the correct encryption algorithm. It should store -the list of permitted ciphers in a database and only use those. -.PP -No revocation checking is done on the signer's certificate. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\-file\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The use of multiple \fB\-signer\fR options and the \fB\-resign\fR command were first -added in OpenSSL 1.0.0. -.PP -The \fB\-keyopt\fR option was added in OpenSSL 1.0.2. -.PP -Support for RSA-OAEP and RSA-PSS was added in OpenSSL 1.0.2. -.PP -The use of non-RSA keys with \fB\-encrypt\fR and \fB\-decrypt\fR -was added in OpenSSL 1.0.2. -.PP -The \-no_alt_chains option was added in OpenSSL 1.0.2b. -.PP -The \fB\-nameopt\fR option was added in OpenSSL 3.0.0. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-digest\fR option was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-crl.1ossl b/openssl-install/share/man/man1/openssl-crl.1ossl deleted file mode 100644 index 7bd2769d..00000000 --- a/openssl-install/share/man/man1/openssl-crl.1ossl +++ /dev/null @@ -1,305 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CRL 1ossl" -.TH OPENSSL-CRL 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-crl \- CRL command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBcrl\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-key\fR \fIfilename\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR] -[\fB\-dateopt\fR] -[\fB\-text\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-gendelta\fR \fIfilename\fR] -[\fB\-badsig\fR] -[\fB\-verify\fR] -[\fB\-noout\fR] -[\fB\-hash\fR] -[\fB\-hash_old\fR] -[\fB\-fingerprint\fR] -[\fB\-crlnumber\fR] -[\fB\-issuer\fR] -[\fB\-lastupdate\fR] -[\fB\-nextupdate\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes \s-1CRL\s0 files in \s-1DER\s0 or \s-1PEM\s0 format. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The \s-1CRL\s0 input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The \s-1CRL\s0 output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-key\fR \fIfilename\fR" 4 -.IX Item "-key filename" -The private key to be used to sign the \s-1CRL.\s0 -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR" 4 -.IX Item "-keyform DER|PEM|P12" -The format of the private key file; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read from or standard input if this -option is not specified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Specifies the output filename to write to or standard output by -default. -.IP "\fB\-gendelta\fR \fIfilename\fR" 4 -.IX Item "-gendelta filename" -Output a comparison of the main \s-1CRL\s0 and the one specified here. -.IP "\fB\-badsig\fR" 4 -.IX Item "-badsig" -Corrupt the signature before writing it; this can be useful -for testing. -.IP "\fB\-dateopt\fR" 4 -.IX Item "-dateopt" -Specify the date output format. Values are: rfc_822 and iso_8601. -Defaults to rfc_822. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Print out the \s-1CRL\s0 in text form. -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verify the signature in the \s-1CRL.\s0 If the verification fails, -the program will immediately exit, i.e. further option processing -(e.g. \fB\-gendelta\fR) is skipped. -.Sp -This option is implicitly enabled if any of \fB\-CApath\fR, \fB\-CAfile\fR -or \fB\-CAstore\fR is specified. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -Don't output the encoded version of the \s-1CRL.\s0 -.IP "\fB\-fingerprint\fR" 4 -.IX Item "-fingerprint" -Output the fingerprint of the \s-1CRL.\s0 -.IP "\fB\-crlnumber\fR" 4 -.IX Item "-crlnumber" -Output the number of the \s-1CRL.\s0 -.IP "\fB\-hash\fR" 4 -.IX Item "-hash" -Output a hash of the issuer name. This can be use to lookup CRLs in -a directory by issuer name. -.IP "\fB\-hash_old\fR" 4 -.IX Item "-hash_old" -Outputs the \*(L"hash\*(R" of the \s-1CRL\s0 issuer name using the older algorithm -as used by OpenSSL before version 1.0.0. -.IP "\fB\-issuer\fR" 4 -.IX Item "-issuer" -Output the issuer name. -.IP "\fB\-lastupdate\fR" 4 -.IX Item "-lastupdate" -Output the lastUpdate field. -.IP "\fB\-nextupdate\fR" 4 -.IX Item "-nextupdate" -Output the nextUpdate field. -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -This specifies how the subject or issuer names are displayed. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Convert a \s-1CRL\s0 file from \s-1PEM\s0 to \s-1DER:\s0 -.PP -.Vb 1 -\& openssl crl \-in crl.pem \-outform DER \-out crl.der -.Ve -.PP -Output the text form of a \s-1DER\s0 encoded certificate: -.PP -.Vb 1 -\& openssl crl \-in crl.der \-text \-noout -.Ve -.SH "BUGS" -.IX Header "BUGS" -Ideally it should be possible to create a \s-1CRL\s0 using appropriate options -and files too. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-crl2pkcs7\fR\|(1), -\&\fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -\&\fBossl_store\-file\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -Since OpenSSL 3.3, the \fB\-verify\fR option will exit with 1 on failure. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-crl2pkcs7.1ossl b/openssl-install/share/man/man1/openssl-crl2pkcs7.1ossl deleted file mode 100644 index e0a4013c..00000000 --- a/openssl-install/share/man/man1/openssl-crl2pkcs7.1ossl +++ /dev/null @@ -1,238 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CRL2PKCS7 1ossl" -.TH OPENSSL-CRL2PKCS7 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-crl2pkcs7 \- Create a PKCS#7 structure from a CRL and certificates -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBcrl2pkcs7\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-certfile\fR \fIfilename\fR] -[\fB\-nocrl\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command takes an optional \s-1CRL\s0 and one or more -certificates and converts them into a PKCS#7 degenerate \*(L"certificates -only\*(R" structure. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The input format of the \s-1CRL\s0; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The output format of the PKCS#7 object; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read a \s-1CRL\s0 from or standard input if this -option is not specified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Specifies the output filename to write the PKCS#7 structure to or standard -output by default. -.IP "\fB\-certfile\fR \fIfilename\fR" 4 -.IX Item "-certfile filename" -Specifies a filename containing one or more certificates in \fB\s-1PEM\s0\fR format. -All certificates in the file will be added to the PKCS#7 structure. This -option can be used more than once to read certificates from multiple -files. -.IP "\fB\-nocrl\fR" 4 -.IX Item "-nocrl" -Normally a \s-1CRL\s0 is included in the output file. With this option no \s-1CRL\s0 is -included in the output file and a \s-1CRL\s0 is not read from the input file. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a PKCS#7 structure from a certificate and \s-1CRL:\s0 -.PP -.Vb 1 -\& openssl crl2pkcs7 \-in crl.pem \-certfile cert.pem \-out p7.pem -.Ve -.PP -Creates a PKCS#7 structure in \s-1DER\s0 format with no \s-1CRL\s0 from several -different certificates: -.PP -.Vb 2 -\& openssl crl2pkcs7 \-nocrl \-certfile newcert.pem -\& \-certfile demoCA/cacert.pem \-outform DER \-out p7.der -.Ve -.SH "NOTES" -.IX Header "NOTES" -The output file is a PKCS#7 signed data structure containing no signers and -just certificates and an optional \s-1CRL.\s0 -.PP -This command can be used to send certificates and CAs to Netscape as part of -the certificate enrollment process. This involves sending the \s-1DER\s0 encoded output -as \s-1MIME\s0 type application/x\-x509\-user\-cert. -.PP -The \fB\s-1PEM\s0\fR encoded form with the header and footer lines removed can be used to -install user certificates and CAs in \s-1MSIE\s0 using the Xenroll control. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkcs7\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-dgst.1ossl b/openssl-install/share/man/man1/openssl-dgst.1ossl deleted file mode 100644 index cdcfa195..00000000 --- a/openssl-install/share/man/man1/openssl-dgst.1ossl +++ /dev/null @@ -1,402 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-DGST 1ossl" -.TH OPENSSL-DGST 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-dgst \- perform digest operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBdgst\fR|\fIdigest\fR -[\fB\-\f(BIdigest\fB\fR] -[\fB\-list\fR] -[\fB\-help\fR] -[\fB\-c\fR] -[\fB\-d\fR] -[\fB\-debug\fR] -[\fB\-hex\fR] -[\fB\-binary\fR] -[\fB\-xoflen\fR \fIlength\fR] -[\fB\-r\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-sign\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-verify\fR \fIfilename\fR] -[\fB\-prverify\fR \fIfilename\fR] -[\fB\-signature\fR \fIfilename\fR] -[\fB\-sigopt\fR \fInm\fR:\fIv\fR] -[\fB\-hmac\fR \fIkey\fR] -[\fB\-mac\fR \fIalg\fR] -[\fB\-macopt\fR \fInm\fR:\fIv\fR] -[\fB\-fips\-fingerprint\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-engine_impl\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIfile\fR ...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command output the message digest of a supplied file or files -in hexadecimal, and also generates and verifies digital -signatures using message digests. -.PP -The generic name, \fBopenssl dgst\fR, may be used with an option specifying the -algorithm to be used. -The default digest is \fBsha256\fR. -A supported \fIdigest\fR name may also be used as the sub-command name. -To see the list of supported algorithms, use \f(CW\*(C`openssl list \-digest\-algorithms\*(C'\fR -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-\f(BIdigest\fB\fR" 4 -.IX Item "-digest" -Specifies name of a supported digest to be used. See option \fB\-list\fR below : -.IP "\fB\-list\fR" 4 -.IX Item "-list" -Prints out a list of supported message digests. -.IP "\fB\-c\fR" 4 -.IX Item "-c" -Print out the digest in two digit groups separated by colons, only relevant if -the \fB\-hex\fR option is given as well. -.IP "\fB\-d\fR, \fB\-debug\fR" 4 -.IX Item "-d, -debug" -Print out \s-1BIO\s0 debugging information. -.IP "\fB\-hex\fR" 4 -.IX Item "-hex" -Digest is to be output as a hex dump. This is the default case for a \*(L"normal\*(R" -digest as opposed to a digital signature. See \s-1NOTES\s0 below for digital -signatures using \fB\-hex\fR. -.IP "\fB\-binary\fR" 4 -.IX Item "-binary" -Output the digest or signature in binary form. -.IP "\fB\-xoflen\fR \fIlength\fR" 4 -.IX Item "-xoflen length" -Set the output length for \s-1XOF\s0 algorithms, such as \fBshake128\fR and \fBshake256\fR. -This option is not supported for signing operations. -.Sp -For OpenSSL providers it is required to set this value for shake algorithms, -since the previous default values were only set to supply half of the maximum -security strength. -.Sp -To ensure the maximum security strength of 128 bits, the xoflen for \fBshake128\fR -should be set to at least 32 (bytes). For compatibility with previous versions -of OpenSSL, it may be set to 16, resulting in a security strength of only 64 -bits. -.Sp -To ensure the maximum security strength of 256 bits, the xoflen for \fBshake256\fR -should be set to at least 64 (bytes). For compatibility with previous versions -of OpenSSL, it may be set to 32, resulting in a security strength of only 128 -bits. -.IP "\fB\-r\fR" 4 -.IX Item "-r" -Output the digest in the \*(L"coreutils\*(R" format, including newlines. -Used by programs like \fBsha1sum\fR\|(1). -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Filename to output to, or standard output by default. -.IP "\fB\-sign\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-sign filename|uri" -Digitally sign the digest using the given private key. Note this option -does not support Ed25519 or Ed448 private keys. Use the \fBopenssl\-pkeyutl\fR\|(1) -command instead for this. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The format of the key to sign with; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-sigopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-sigopt nm:v" -Pass options to the signature algorithm during sign or verify operations. -Names and values of these options are algorithm-specific and documented -in \*(L"Signature parameters\*(R" in \fBprovider\-signature\fR\|(7). -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The private key password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-verify\fR \fIfilename\fR" 4 -.IX Item "-verify filename" -Verify the signature using the public key in \*(L"filename\*(R". -The output is either \*(L"Verified \s-1OK\*(R"\s0 or \*(L"Verification Failure\*(R". -.IP "\fB\-prverify\fR \fIfilename\fR" 4 -.IX Item "-prverify filename" -Verify the signature using the private key in \*(L"filename\*(R". -.IP "\fB\-signature\fR \fIfilename\fR" 4 -.IX Item "-signature filename" -The actual signature to verify. -.IP "\fB\-hmac\fR \fIkey\fR" 4 -.IX Item "-hmac key" -Create a hashed \s-1MAC\s0 using \*(L"key\*(R". -.Sp -The \fBopenssl\-mac\fR\|(1) command should be preferred to using this command line -option. -.IP "\fB\-mac\fR \fIalg\fR" 4 -.IX Item "-mac alg" -Create \s-1MAC\s0 (keyed Message Authentication Code). The most popular \s-1MAC\s0 -algorithm is \s-1HMAC\s0 (hash-based \s-1MAC\s0), but there are other \s-1MAC\s0 algorithms -which are not based on hash, for instance \fBgost-mac\fR algorithm, -supported by the \fBgost\fR engine. \s-1MAC\s0 keys and other options should be set -via \fB\-macopt\fR parameter. -.Sp -The \fBopenssl\-mac\fR\|(1) command should be preferred to using this command line -option. -.IP "\fB\-macopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-macopt nm:v" -Passes options to \s-1MAC\s0 algorithm, specified by \fB\-mac\fR key. -Following options are supported by both by \fB\s-1HMAC\s0\fR and \fBgost-mac\fR: -.RS 4 -.IP "\fBkey\fR:\fIstring\fR" 4 -.IX Item "key:string" -Specifies \s-1MAC\s0 key as alphanumeric string (use if key contain printable -characters only). String length must conform to any restrictions of -the \s-1MAC\s0 algorithm for example exactly 32 chars for gost-mac. -.IP "\fBhexkey\fR:\fIstring\fR" 4 -.IX Item "hexkey:string" -Specifies \s-1MAC\s0 key in hexadecimal form (two hex digits per byte). -Key length must conform to any restrictions of the \s-1MAC\s0 algorithm -for example exactly 32 chars for gost-mac. -.RE -.RS 4 -.Sp -The \fBopenssl\-mac\fR\|(1) command should be preferred to using this command line -option. -.RE -.IP "\fB\-fips\-fingerprint\fR" 4 -.IX Item "-fips-fingerprint" -Compute \s-1HMAC\s0 using a specific key for certain OpenSSL-FIPS operations. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.Sp -The engine is not used for digests unless the \fB\-engine_impl\fR option is -used or it is configured to do so, see \*(L"Engine Configuration Module\*(R" in \fBconfig\fR\|(5). -.IP "\fB\-engine_impl\fR \fIid\fR" 4 -.IX Item "-engine_impl id" -When used with the \fB\-engine\fR option, it specifies to also use -engine \fIid\fR for digest operations. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fIfile\fR ..." 4 -.IX Item "file ..." -File or files to digest. If no files are specified then standard input is -used. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To create a hex-encoded message digest of a file: -.PP -.Vb 3 -\& openssl dgst \-md5 \-hex file.txt -\& or -\& openssl md5 file.txt -.Ve -.PP -To sign a file using \s-1SHA\-256\s0 with binary file output: -.PP -.Vb 3 -\& openssl dgst \-sha256 \-sign privatekey.pem \-out signature.sign file.txt -\& or -\& openssl sha256 \-sign privatekey.pem \-out signature.sign file.txt -.Ve -.PP -To verify a signature: -.PP -.Vb 3 -\& openssl dgst \-sha256 \-verify publickey.pem \e -\& \-signature signature.sign \e -\& file.txt -.Ve -.SH "NOTES" -.IX Header "NOTES" -The digest mechanisms that are available will depend on the options -used when building OpenSSL. -The \f(CW\*(C`openssl list \-digest\-algorithms\*(C'\fR command can be used to list them. -.PP -New or agile applications should use probably use \s-1SHA\-256.\s0 Other digests, -particularly \s-1SHA\-1\s0 and \s-1MD5,\s0 are still widely used for interoperating -with existing formats and protocols. -.PP -When signing a file, this command will automatically determine the algorithm -(\s-1RSA, ECC,\s0 etc) to use for signing based on the private key's \s-1ASN.1\s0 info. -When verifying signatures, it only handles the \s-1RSA, DSA,\s0 or \s-1ECDSA\s0 signature -itself, not the related data to identify the signer and algorithm used in -formats such as x.509, \s-1CMS,\s0 and S/MIME. -.PP -A source of random numbers is required for certain signing algorithms, in -particular \s-1ECDSA\s0 and \s-1DSA.\s0 -.PP -The signing and verify options should only be used if a single file is -being signed or verified. -.PP -Hex signatures cannot be verified using \fBopenssl\fR. Instead, use \*(L"xxd \-r\*(R" -or similar program to transform the hex signature into a binary signature -prior to verification. -.PP -The \fBopenssl\-mac\fR\|(1) command is preferred over the \fB\-hmac\fR, \fB\-mac\fR and -\&\fB\-macopt\fR command line options. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-mac\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The default digest was changed from \s-1MD5\s0 to \s-1SHA256\s0 in OpenSSL 1.1.0. -The FIPS-related options were removed in OpenSSL 1.1.0. -.PP -The \fB\-engine\fR and \fB\-engine_impl\fR options were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-dhparam.1ossl b/openssl-install/share/man/man1/openssl-dhparam.1ossl deleted file mode 100644 index 9c3895f7..00000000 --- a/openssl-install/share/man/man1/openssl-dhparam.1ossl +++ /dev/null @@ -1,273 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-DHPARAM 1ossl" -.TH OPENSSL-DHPARAM 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-dhparam \- DH parameter manipulation and generation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl dhparam\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-dsaparam\fR] -[\fB\-check\fR] -[\fB\-noout\fR] -[\fB\-text\fR] -[\fB\-verbose\fR] -[\fB\-quiet\fR] -[\fB\-2\fR] -[\fB\-3\fR] -[\fB\-5\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fInumbits\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to manipulate \s-1DH\s0 parameter files. -.PP -See \*(L"\s-1EXAMPLES\*(R"\s0 in \fBopenssl\-genpkey\fR\|(1) for examples on how to generate -a key using a named safe prime group without generating intermediate -parameters. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR, \fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM, -outform DER|PEM" -The input format and output format; the default is \fB\s-1PEM\s0\fR. -The object is compatible with the PKCS#3 \fBDHparameter\fR structure. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read parameters from or standard input if -this option is not specified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename parameters to. Standard output is used -if this option is not present. The output filename should \fBnot\fR be the same -as the input filename. -.IP "\fB\-dsaparam\fR" 4 -.IX Item "-dsaparam" -If this option is used, \s-1DSA\s0 rather than \s-1DH\s0 parameters are read or created; -they are converted to \s-1DH\s0 format. Otherwise, safe primes (such -that (p\-1)/2 is also prime) will be used for \s-1DH\s0 parameter generation. -.Sp -\&\s-1DH\s0 parameter generation with the \fB\-dsaparam\fR option is much faster. -Beware that with such DSA-style \s-1DH\s0 parameters, a fresh \s-1DH\s0 key should be -created for each use to avoid small-subgroup attacks that may be possible -otherwise. -.IP "\fB\-check\fR" 4 -.IX Item "-check" -Performs numerous checks to see if the supplied parameters are valid and -displays a warning if not. -.IP "\fB\-2\fR, \fB\-3\fR, \fB\-5\fR" 4 -.IX Item "-2, -3, -5" -The generator to use, either 2, 3 or 5. If present then the -input file is ignored and parameters are generated instead. If not -present but \fInumbits\fR is present, parameters are generated with the -default generator 2. -.IP "\fInumbits\fR" 4 -.IX Item "numbits" -This option specifies that a parameter set should be generated of size -\&\fInumbits\fR. It must be the last option. If this option is present then -the input file is ignored and parameters are generated instead. If -this option is not present but a generator (\fB\-2\fR, \fB\-3\fR or \fB\-5\fR) is -present, parameters are generated with a default length of 2048 bits. -The minimum length is 512 bits. The maximum length is 10000 bits. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option inhibits the output of the encoded version of the parameters. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -This option prints out the \s-1DH\s0 parameters in human readable form. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -This option enables the output of progress messages, which is handy when -running commands interactively that may take a long time to execute. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -This option suppresses the output of progress messages, which may be -undesirable in batch scripts or pipelines. -.SH "NOTES" -.IX Header "NOTES" -This command replaces the \fBdh\fR and \fBgendh\fR commands of previous -releases. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkeyparam\fR\|(1), -\&\fBopenssl\-dsaparam\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1). -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-C\fR option was removed in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-dsa.1ossl b/openssl-install/share/man/man1/openssl-dsa.1ossl deleted file mode 100644 index f59ff179..00000000 --- a/openssl-install/share/man/man1/openssl-dsa.1ossl +++ /dev/null @@ -1,323 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-DSA 1ossl" -.TH OPENSSL-DSA 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-dsa \- DSA key processing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBdsa\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-aes128\fR] -[\fB\-aes192\fR] -[\fB\-aes256\fR] -[\fB\-aria128\fR] -[\fB\-aria192\fR] -[\fB\-aria256\fR] -[\fB\-camellia128\fR] -[\fB\-camellia192\fR] -[\fB\-camellia256\fR] -[\fB\-des\fR] -[\fB\-des3\fR] -[\fB\-idea\fR] -[\fB\-text\fR] -[\fB\-noout\fR] -[\fB\-modulus\fR] -[\fB\-pubin\fR] -[\fB\-pubout\fR] -[\fB\-pvk\-strong\fR] -[\fB\-pvk\-weak\fR] -[\fB\-pvk\-none\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes \s-1DSA\s0 keys. They can be converted between various -forms and their components printed out. \fBNote\fR This command uses the -traditional SSLeay compatible format for private key encryption: newer -applications should use the more secure PKCS#8 format using the \fBpkcs8\fR -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The key input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The key output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -Private keys are a sequence of \fB\s-1ASN.1 INTEGERS\s0\fR: the version (zero), \fBp\fR, -\&\fBq\fR, \fBg\fR, and the public and private key components. Public keys -are a \fBSubjectPublicKeyInfo\fR structure with the \fB\s-1DSA\s0\fR type. -.Sp -The \fB\s-1PEM\s0\fR format also accepts PKCS#8 data. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read a key from or standard input if this -option is not specified. If the key is encrypted a pass phrase will be -prompted for. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write a key to or standard output by -is not specified. If any encryption options are set then a pass phrase will be -prompted for. The output filename should \fBnot\fR be the same as the input -filename. -.IP "\fB\-passin\fR \fIarg\fR, \fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passin arg, -passout arg" -The password source for the input and output file. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-aes128\fR, \fB\-aes192\fR, \fB\-aes256\fR, \fB\-aria128\fR, \fB\-aria192\fR, \fB\-aria256\fR, \fB\-camellia128\fR, \fB\-camellia192\fR, \fB\-camellia256\fR, \fB\-des\fR, \fB\-des3\fR, \fB\-idea\fR" 4 -.IX Item "-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea" -These options encrypt the private key with the specified -cipher before outputting it. A pass phrase is prompted for. -If none of these options is specified the key is written in plain text. This -means that this command can be used to remove the pass phrase from a key -by not giving any encryption option is given, or to add or change the pass -phrase by setting them. -These options can only be used with \s-1PEM\s0 format output files. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the public, private key components and parameters. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option prevents output of the encoded version of the key. -.IP "\fB\-modulus\fR" 4 -.IX Item "-modulus" -This option prints out the value of the public key component of the key. -.IP "\fB\-pubin\fR" 4 -.IX Item "-pubin" -By default, a private key is read from the input. -With this option a public key is read instead. -If the input contains no public key but a private key, its public part is used. -.IP "\fB\-pubout\fR" 4 -.IX Item "-pubout" -By default, a private key is output. With this option a public -key will be output instead. This option is automatically set if the input is -a public key. -.IP "\fB\-pvk\-strong\fR" 4 -.IX Item "-pvk-strong" -Enable 'Strong' \s-1PVK\s0 encoding level (default). -.IP "\fB\-pvk\-weak\fR" 4 -.IX Item "-pvk-weak" -Enable 'Weak' \s-1PVK\s0 encoding level. -.IP "\fB\-pvk\-none\fR" 4 -.IX Item "-pvk-none" -Don't enforce \s-1PVK\s0 encoding. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.PP -The \fBopenssl\-pkey\fR\|(1) command is capable of performing all the operations -this command can, as well as supporting other public key types. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The documentation for the \fBopenssl\-pkey\fR\|(1) command contains examples -equivalent to the ones listed here. -.PP -To remove the pass phrase on a \s-1DSA\s0 private key: -.PP -.Vb 1 -\& openssl dsa \-in key.pem \-out keyout.pem -.Ve -.PP -To encrypt a private key using triple \s-1DES:\s0 -.PP -.Vb 1 -\& openssl dsa \-in key.pem \-des3 \-out keyout.pem -.Ve -.PP -To convert a private key from \s-1PEM\s0 to \s-1DER\s0 format: -.PP -.Vb 1 -\& openssl dsa \-in key.pem \-outform DER \-out keyout.der -.Ve -.PP -To print out the components of a private key to standard output: -.PP -.Vb 1 -\& openssl dsa \-in key.pem \-text \-noout -.Ve -.PP -To just output the public part of a private key: -.PP -.Vb 1 -\& openssl dsa \-in key.pem \-pubout \-out pubkey.pem -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkey\fR\|(1), -\&\fBopenssl\-dsaparam\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-dsaparam.1ossl b/openssl-install/share/man/man1/openssl-dsaparam.1ossl deleted file mode 100644 index 6164bccb..00000000 --- a/openssl-install/share/man/man1/openssl-dsaparam.1ossl +++ /dev/null @@ -1,259 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-DSAPARAM 1ossl" -.TH OPENSSL-DSAPARAM 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-dsaparam \- DSA parameter manipulation and generation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl dsaparam\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-noout\fR] -[\fB\-text\fR] -[\fB\-genkey\fR] -[\fB\-verbose\fR] -[\fB\-quiet\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fInumbits\fR] -[\fInumqbits\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to manipulate or generate \s-1DSA\s0 parameter files. -.PP -\&\s-1DSA\s0 parameter generation can be a slow process and as a result the same set of -\&\s-1DSA\s0 parameters is often used to generate several distinct keys. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The \s-1DSA\s0 parameters input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The \s-1DSA\s0 parameters output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -Parameters are a sequence of \fB\s-1ASN.1 INTEGER\s0\fRs: \fBp\fR, \fBq\fR, and \fBg\fR. -This is compatible with \s-1RFC 2459\s0 \fBDSS-Parms\fR structure. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read parameters from or standard input if -this option is not specified. If the \fInumbits\fR parameter is included then -this option will be ignored. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename parameters to. Standard output is used -if this option is not present. The output filename should \fBnot\fR be the same -as the input filename. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option inhibits the output of the encoded version of the parameters. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -This option prints out the \s-1DSA\s0 parameters in human readable form. -.IP "\fB\-genkey\fR" 4 -.IX Item "-genkey" -This option will generate a \s-1DSA\s0 either using the specified or generated -parameters. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Print extra details about the operations being performed. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Print fewer details about the operations being performed, which may -be handy during batch scripts and pipelines. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fInumbits\fR" 4 -.IX Item "numbits" -This optional argument specifies that a parameter set should be generated of -size \fInumbits\fR. If this argument is included then the input file (if any) is -ignored. -.IP "\fInumqbits\fR" 4 -.IX Item "numqbits" -This optional argument specifies that a parameter set should be generated with -a subprime parameter q of size \fInumqbits\fR. It must be the last argument. If -this argument is included then the input file (if any) is ignored. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkeyparam\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-C\fR option was removed in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-ec.1ossl b/openssl-install/share/man/man1/openssl-ec.1ossl deleted file mode 100644 index 32083fab..00000000 --- a/openssl-install/share/man/man1/openssl-ec.1ossl +++ /dev/null @@ -1,337 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-EC 1ossl" -.TH OPENSSL-EC 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-ec \- EC key processing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBec\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR|\fIuri\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-des\fR] -[\fB\-des3\fR] -[\fB\-idea\fR] -[\fB\-text\fR] -[\fB\-noout\fR] -[\fB\-param_out\fR] -[\fB\-pubin\fR] -[\fB\-pubout\fR] -[\fB\-conv_form\fR \fIarg\fR] -[\fB\-param_enc\fR \fIarg\fR] -[\fB\-no_public\fR] -[\fB\-check\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBopenssl\-ec\fR\|(1) command processes \s-1EC\s0 keys. They can be converted between -various forms and their components printed out. \fBNote\fR OpenSSL uses the -private key format specified in '\s-1SEC 1:\s0 Elliptic Curve Cryptography' -(http://www.secg.org/). To convert an OpenSSL \s-1EC\s0 private key into the -PKCS#8 private key format use the \fBopenssl\-pkcs8\fR\|(1) command. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-inform DER|PEM|P12|ENGINE" -The key input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The key output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -Private keys are an \s-1SEC1\s0 private key or PKCS#8 format. -Public keys are a \fBSubjectPublicKeyInfo\fR as specified in \s-1IETF RFC 3280.\s0 -.IP "\fB\-in\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-in filename|uri" -This specifies the input to read a key from or standard input if this -option is not specified. If the key is encrypted a pass phrase will be -prompted for. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write a key to or standard output by -is not specified. If any encryption options are set then a pass phrase will be -prompted for. The output filename should \fBnot\fR be the same as the input -filename. -.IP "\fB\-passin\fR \fIarg\fR, \fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passin arg, -passout arg" -The password source for the input and output file. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-des\fR|\fB\-des3\fR|\fB\-idea\fR" 4 -.IX Item "-des|-des3|-idea" -These options encrypt the private key with the \s-1DES,\s0 triple \s-1DES, IDEA\s0 or -any other cipher supported by OpenSSL before outputting it. A pass phrase is -prompted for. -If none of these options is specified the key is written in plain text. This -means that using this command to read in an encrypted key with no -encryption option can be used to remove the pass phrase from a key, or by -setting the encryption options it can be use to add or change the pass phrase. -These options can only be used with \s-1PEM\s0 format output files. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the public, private key components and parameters. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option prevents output of the encoded version of the key. -.IP "\fB\-param_out\fR" 4 -.IX Item "-param_out" -Print the elliptic curve parameters. -.IP "\fB\-pubin\fR" 4 -.IX Item "-pubin" -By default a private key is read from the input. -With this option a public key is read instead. -If the input contains no public key but a private key, its public part is used. -.IP "\fB\-pubout\fR" 4 -.IX Item "-pubout" -By default a private key is output. With this option a public -key will be output instead. This option is automatically set if the input is -a public key. -.IP "\fB\-conv_form\fR \fIarg\fR" 4 -.IX Item "-conv_form arg" -This specifies how the points on the elliptic curve are converted -into octet strings. Possible values are: \fBcompressed\fR, \fBuncompressed\fR (the -default value) and \fBhybrid\fR. For more information regarding -the point conversion forms please read the X9.62 standard. -\&\fBNote\fR Due to patent issues the \fBcompressed\fR option is disabled -by default for binary curves and can be enabled by defining -the preprocessor macro \fB\s-1OPENSSL_EC_BIN_PT_COMP\s0\fR at compile time. -.IP "\fB\-param_enc\fR \fIarg\fR" 4 -.IX Item "-param_enc arg" -This specifies how the elliptic curve parameters are encoded. -Possible value are: \fBnamed_curve\fR, i.e. the ec parameters are -specified by an \s-1OID,\s0 or \fBexplicit\fR where the ec parameters are -explicitly given (see \s-1RFC 3279\s0 for the definition of the -\&\s-1EC\s0 parameters structures). The default value is \fBnamed_curve\fR. -\&\fBNote\fR the \fBimplicitlyCA\fR alternative, as specified in \s-1RFC 3279,\s0 -is currently not implemented in OpenSSL. -.IP "\fB\-no_public\fR" 4 -.IX Item "-no_public" -This option omits the public key components from the private key output. -.IP "\fB\-check\fR" 4 -.IX Item "-check" -This option checks the consistency of an \s-1EC\s0 private or public key. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.PP -The \fBopenssl\-pkey\fR\|(1) command is capable of performing all the operations -this command can, as well as supporting other public key types. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The documentation for the \fBopenssl\-pkey\fR\|(1) command contains examples -equivalent to the ones listed here. -.PP -To encrypt a private key using triple \s-1DES:\s0 -.PP -.Vb 1 -\& openssl ec \-in key.pem \-des3 \-out keyout.pem -.Ve -.PP -To convert a private key from \s-1PEM\s0 to \s-1DER\s0 format: -.PP -.Vb 1 -\& openssl ec \-in key.pem \-outform DER \-out keyout.der -.Ve -.PP -To print out the components of a private key to standard output: -.PP -.Vb 1 -\& openssl ec \-in key.pem \-text \-noout -.Ve -.PP -To just output the public part of a private key: -.PP -.Vb 1 -\& openssl ec \-in key.pem \-pubout \-out pubkey.pem -.Ve -.PP -To change the parameters encoding to \fBexplicit\fR: -.PP -.Vb 1 -\& openssl ec \-in key.pem \-param_enc explicit \-out keyout.pem -.Ve -.PP -To change the point conversion form to \fBcompressed\fR: -.PP -.Vb 1 -\& openssl ec \-in key.pem \-conv_form compressed \-out keyout.pem -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkey\fR\|(1), -\&\fBopenssl\-ecparam\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-conv_form\fR and \fB\-no_public\fR options are no longer supported -with keys loaded from an engine in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2003\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-ecparam.1ossl b/openssl-install/share/man/man1/openssl-ecparam.1ossl deleted file mode 100644 index fb84bf58..00000000 --- a/openssl-install/share/man/man1/openssl-ecparam.1ossl +++ /dev/null @@ -1,321 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-ECPARAM 1ossl" -.TH OPENSSL-ECPARAM 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-ecparam \- EC parameter manipulation and generation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl ecparam\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-noout\fR] -[\fB\-text\fR] -[\fB\-check\fR] -[\fB\-check_named\fR] -[\fB\-name\fR \fIarg\fR] -[\fB\-list_curves\fR] -[\fB\-conv_form\fR \fIarg\fR] -[\fB\-param_enc\fR \fIarg\fR] -[\fB\-no_seed\fR] -[\fB\-genkey\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to manipulate or generate \s-1EC\s0 parameter files. -.PP -OpenSSL is currently not able to generate new groups and therefore -this command can only create \s-1EC\s0 parameters from known (named) curves. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The \s-1EC\s0 parameters input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The \s-1EC\s0 parameters output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -Parameters are encoded as \fBEcpkParameters\fR as specified in \s-1IETF RFC 3279.\s0 -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read parameters from or standard input if -this option is not specified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename parameters to. Standard output is used -if this option is not present. The output filename should \fBnot\fR be the same -as the input filename. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option inhibits the output of the encoded version of the parameters. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -This option prints out the \s-1EC\s0 parameters in human readable form. -.IP "\fB\-check\fR" 4 -.IX Item "-check" -Validate the elliptic curve parameters. -.IP "\fB\-check_named\fR" 4 -.IX Item "-check_named" -Validate the elliptic name curve parameters by checking if the curve parameters -match any built-in curves. -.IP "\fB\-name\fR \fIarg\fR" 4 -.IX Item "-name arg" -Use the \s-1EC\s0 parameters with the specified 'short' name. Use \fB\-list_curves\fR -to get a list of all currently implemented \s-1EC\s0 parameters. -.IP "\fB\-list_curves\fR" 4 -.IX Item "-list_curves" -Print out a list of all currently implemented \s-1EC\s0 parameters names and exit. -.IP "\fB\-conv_form\fR \fIarg\fR" 4 -.IX Item "-conv_form arg" -This specifies how the points on the elliptic curve are converted -into octet strings. Possible values are: \fBcompressed\fR, \fBuncompressed\fR (the -default value) and \fBhybrid\fR. For more information regarding -the point conversion forms please read the X9.62 standard. -\&\fBNote\fR Due to patent issues the \fBcompressed\fR option is disabled -by default for binary curves and can be enabled by defining -the preprocessor macro \fB\s-1OPENSSL_EC_BIN_PT_COMP\s0\fR at compile time. -.IP "\fB\-param_enc\fR \fIarg\fR" 4 -.IX Item "-param_enc arg" -This specifies how the elliptic curve parameters are encoded. -Possible value are: \fBnamed_curve\fR, i.e. the ec parameters are -specified by an \s-1OID,\s0 or \fBexplicit\fR where the ec parameters are -explicitly given (see \s-1RFC 3279\s0 for the definition of the -\&\s-1EC\s0 parameters structures). The default value is \fBnamed_curve\fR. -\&\fBNote\fR the \fBimplicitlyCA\fR alternative, as specified in \s-1RFC 3279,\s0 -is currently not implemented in OpenSSL. -.IP "\fB\-no_seed\fR" 4 -.IX Item "-no_seed" -This option inhibits that the 'seed' for the parameter generation -is included in the ECParameters structure (see \s-1RFC 3279\s0). -.IP "\fB\-genkey\fR" 4 -.IX Item "-genkey" -This option will generate an \s-1EC\s0 private key using the specified parameters. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.PP -The \fBopenssl\-genpkey\fR\|(1) and \fBopenssl\-pkeyparam\fR\|(1) commands are capable -of performing all the operations this command can, as well as supporting -other public key types. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The documentation for the \fBopenssl\-genpkey\fR\|(1) and \fBopenssl\-pkeyparam\fR\|(1) -commands contains examples equivalent to the ones listed here. -.PP -To create \s-1EC\s0 parameters with the group 'prime192v1': -.PP -.Vb 1 -\& openssl ecparam \-out ec_param.pem \-name prime192v1 -.Ve -.PP -To create \s-1EC\s0 parameters with explicit parameters: -.PP -.Vb 1 -\& openssl ecparam \-out ec_param.pem \-name prime192v1 \-param_enc explicit -.Ve -.PP -To validate given \s-1EC\s0 parameters: -.PP -.Vb 1 -\& openssl ecparam \-in ec_param.pem \-check -.Ve -.PP -To create \s-1EC\s0 parameters and a private key: -.PP -.Vb 1 -\& openssl ecparam \-out ec_key.pem \-name prime192v1 \-genkey -.Ve -.PP -To change the point encoding to 'compressed': -.PP -.Vb 1 -\& openssl ecparam \-in ec_in.pem \-out ec_out.pem \-conv_form compressed -.Ve -.PP -To print out the \s-1EC\s0 parameters to standard output: -.PP -.Vb 1 -\& openssl ecparam \-in ec_param.pem \-noout \-text -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkeyparam\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-ec\fR\|(1), -\&\fBopenssl\-dsaparam\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-C\fR option was removed in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2003\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-enc.1ossl b/openssl-install/share/man/man1/openssl-enc.1ossl deleted file mode 100644 index 83a9172e..00000000 --- a/openssl-install/share/man/man1/openssl-enc.1ossl +++ /dev/null @@ -1,619 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-ENC 1ossl" -.TH OPENSSL-ENC 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-enc \- symmetric cipher routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBenc\fR|\fIcipher\fR -[\fB\-\f(BIcipher\fB\fR] -[\fB\-help\fR] -[\fB\-list\fR] -[\fB\-ciphers\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-pass\fR \fIarg\fR] -[\fB\-e\fR] -[\fB\-d\fR] -[\fB\-a\fR] -[\fB\-base64\fR] -[\fB\-A\fR] -[\fB\-k\fR \fIpassword\fR] -[\fB\-kfile\fR \fIfilename\fR] -[\fB\-K\fR \fIkey\fR] -[\fB\-iv\fR \fI\s-1IV\s0\fR] -[\fB\-S\fR \fIsalt\fR] -[\fB\-salt\fR] -[\fB\-nosalt\fR] -[\fB\-z\fR] -[\fB\-md\fR \fIdigest\fR] -[\fB\-iter\fR \fIcount\fR] -[\fB\-pbkdf2\fR] -[\fB\-saltlen\fR \fIsize\fR] -[\fB\-p\fR] -[\fB\-P\fR] -[\fB\-bufsize\fR \fInumber\fR] -[\fB\-nopad\fR] -[\fB\-v\fR] -[\fB\-debug\fR] -[\fB\-none\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.PP -\&\fBopenssl\fR \fIcipher\fR [\fB...\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The symmetric cipher commands allow data to be encrypted or decrypted -using various block and stream ciphers using keys based on passwords -or explicitly provided. Base64 encoding or decoding can also be performed -either by itself or in addition to the encryption or decryption. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-\f(BIcipher\fB\fR" 4 -.IX Item "-cipher" -The cipher to use. -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-list\fR" 4 -.IX Item "-list" -List all supported ciphers. -.IP "\fB\-ciphers\fR" 4 -.IX Item "-ciphers" -Alias of \-list to display all supported ciphers. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -The input filename, standard input by default. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -The output filename, standard output by default. -.IP "\fB\-pass\fR \fIarg\fR" 4 -.IX Item "-pass arg" -The password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-e\fR" 4 -.IX Item "-e" -Encrypt the input data: this is the default. -.IP "\fB\-d\fR" 4 -.IX Item "-d" -Decrypt the input data. -.IP "\fB\-a\fR" 4 -.IX Item "-a" -Base64 process the data. This means that if encryption is taking place -the data is base64 encoded after encryption. If decryption is set then -the input data is base64 decoded before being decrypted. -.Sp -When the \fB\-A\fR option not given, -on encoding a newline is inserted after each 64 characters, and -on decoding a newline is expected among the first 1024 bytes of input. -.IP "\fB\-base64\fR" 4 -.IX Item "-base64" -Same as \fB\-a\fR -.IP "\fB\-A\fR" 4 -.IX Item "-A" -If the \fB\-a\fR option is set then base64 encoding produces output without any -newline character, and base64 decoding does not require any newlines. -Therefore it can be helpful to use the \fB\-A\fR option when decoding unknown input. -.IP "\fB\-k\fR \fIpassword\fR" 4 -.IX Item "-k password" -The password to derive the key from. This is for compatibility with previous -versions of OpenSSL. Superseded by the \fB\-pass\fR argument. -.IP "\fB\-kfile\fR \fIfilename\fR" 4 -.IX Item "-kfile filename" -Read the password to derive the key from the first line of \fIfilename\fR. -This is for compatibility with previous versions of OpenSSL. Superseded by -the \fB\-pass\fR argument. -.IP "\fB\-md\fR \fIdigest\fR" 4 -.IX Item "-md digest" -Use the specified digest to create the key from the passphrase. -The default algorithm is sha\-256. -.IP "\fB\-iter\fR \fIcount\fR" 4 -.IX Item "-iter count" -Use a given number of iterations on the password in deriving the encryption key. -High values increase the time required to brute-force the resulting file. -This option enables the use of \s-1PBKDF2\s0 algorithm to derive the key. -.IP "\fB\-pbkdf2\fR" 4 -.IX Item "-pbkdf2" -Use \s-1PBKDF2\s0 algorithm with a default iteration count of 10000 -unless otherwise specified by the \fB\-iter\fR command line option. -.IP "\fB\-saltlen\fR" 4 -.IX Item "-saltlen" -Set the salt length to use when using the \fB\-pbkdf2\fR option. -For compatibility reasons, the default is 8 bytes. -The maximum value is currently 16 bytes. -If the \fB\-pbkdf2\fR option is not used, then this option is ignored -and a fixed salt length of 8 is used. The salt length used when -encrypting must also be used when decrypting. -.IP "\fB\-nosalt\fR" 4 -.IX Item "-nosalt" -Don't use a salt in the key derivation routines. This option \fB\s-1SHOULD NOT\s0\fR be -used except for test purposes or compatibility with ancient versions of -OpenSSL. -.IP "\fB\-salt\fR" 4 -.IX Item "-salt" -Use salt (randomly generated or provide with \fB\-S\fR option) when -encrypting, this is the default. -.IP "\fB\-S\fR \fIsalt\fR" 4 -.IX Item "-S salt" -The actual salt to use: this must be represented as a string of hex digits. -If this option is used while encrypting, the same exact value will be needed -again during decryption. This salt may be truncated or zero padded to -match the salt length (See \fB\-saltlen\fR). -.IP "\fB\-K\fR \fIkey\fR" 4 -.IX Item "-K key" -The actual key to use: this must be represented as a string comprised only -of hex digits. If only the key is specified, the \s-1IV\s0 must additionally specified -using the \fB\-iv\fR option. When both a key and a password are specified, the -key given with the \fB\-K\fR option will be used and the \s-1IV\s0 generated from the -password will be taken. It does not make much sense to specify both key -and password. -.IP "\fB\-iv\fR \fI\s-1IV\s0\fR" 4 -.IX Item "-iv IV" -The actual \s-1IV\s0 to use: this must be represented as a string comprised only -of hex digits. When only the key is specified using the \fB\-K\fR option, the -\&\s-1IV\s0 must explicitly be defined. When a password is being specified using -one of the other options, the \s-1IV\s0 is generated from this password. -.IP "\fB\-p\fR" 4 -.IX Item "-p" -Print out the key and \s-1IV\s0 used. -.IP "\fB\-P\fR" 4 -.IX Item "-P" -Print out the key and \s-1IV\s0 used then immediately exit: don't do any encryption -or decryption. -.IP "\fB\-bufsize\fR \fInumber\fR" 4 -.IX Item "-bufsize number" -Set the buffer size for I/O. -.IP "\fB\-nopad\fR" 4 -.IX Item "-nopad" -Disable standard block padding. -.IP "\fB\-v\fR" 4 -.IX Item "-v" -Verbose print; display some statistics about I/O and buffer sizes. -.IP "\fB\-debug\fR" 4 -.IX Item "-debug" -Debug the BIOs used for I/O. -.IP "\fB\-z\fR" 4 -.IX Item "-z" -Compress or decompress encrypted data using zlib after encryption or before -decryption. This option exists only if OpenSSL was compiled with the zlib -or zlib-dynamic option. -.IP "\fB\-none\fR" 4 -.IX Item "-none" -Use \s-1NULL\s0 cipher (no encryption or decryption of input). -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.SH "NOTES" -.IX Header "NOTES" -The program can be called either as \f(CW\*(C`openssl \f(CIcipher\f(CW\*(C'\fR or -\&\f(CW\*(C`openssl enc \-\f(CIcipher\f(CW\*(C'\fR. The first form doesn't work with -engine-provided ciphers, because this form is processed before the -configuration file is read and any ENGINEs loaded. -Use the \fBopenssl\-list\fR\|(1) command to get a list of supported ciphers. -.PP -Engines which provide entirely new encryption algorithms (such as the ccgost -engine which provides gost89 algorithm) should be configured in the -configuration file. Engines specified on the command line using \fB\-engine\fR -option can only be used for hardware-assisted implementations of -ciphers which are supported by the OpenSSL core or another engine specified -in the configuration file. -.PP -When the enc command lists supported ciphers, ciphers provided by engines, -specified in the configuration files are listed too. -.PP -A password will be prompted for to derive the key and \s-1IV\s0 if necessary. -.PP -The \fB\-salt\fR option should \fB\s-1ALWAYS\s0\fR be used if the key is being derived -from a password unless you want compatibility with previous versions of -OpenSSL. -.PP -Without the \fB\-salt\fR option it is possible to perform efficient dictionary -attacks on the password and to attack stream cipher encrypted data. The reason -for this is that without the salt the same password always generates the same -encryption key. -.PP -When the salt is generated at random (that means when encrypting using a -passphrase without explicit salt given using \fB\-S\fR option), the first bytes -of the encrypted data are reserved to store the salt for later decrypting. -.PP -Some of the ciphers do not have large keys and others have security -implications if not used correctly. A beginner is advised to just use -a strong block cipher, such as \s-1AES,\s0 in \s-1CBC\s0 mode. -.PP -All the block ciphers normally use PKCS#5 padding, also known as standard -block padding. This allows a rudimentary integrity or password check to -be performed. However, since the chance of random data passing the test -is better than 1 in 256 it isn't a very good test. -.PP -If padding is disabled then the input data must be a multiple of the cipher -block length. -.PP -All \s-1RC2\s0 ciphers have the same key and effective key length. -.PP -Blowfish and \s-1RC5\s0 algorithms use a 128 bit key. -.PP -Please note that OpenSSL 3.0 changed the effect of the \fB\-S\fR option. -Any explicit salt value specified via this option is no longer prepended to the -ciphertext when encrypting, and must again be explicitly provided when decrypting. -Conversely, when the \fB\-S\fR option is used during decryption, the ciphertext -is expected to not have a prepended salt value. -.PP -When using OpenSSL 3.0 or later to decrypt data that was encrypted with an -explicit salt under OpenSSL 1.1.1 do not use the \fB\-S\fR option, the salt will -then be read from the ciphertext. -To generate ciphertext that can be decrypted with OpenSSL 1.1.1 do not use -the \fB\-S\fR option, the salt will be then be generated randomly and prepended -to the output. -.SH "SUPPORTED CIPHERS" -.IX Header "SUPPORTED CIPHERS" -Note that some of these ciphers can be disabled at compile time -and some are available only if an appropriate engine is configured -in the configuration file. The output when invoking this command -with the \fB\-list\fR option (that is \f(CW\*(C`openssl enc \-list\*(C'\fR) is -a list of ciphers, supported by your version of OpenSSL, including -ones provided by configured engines. -.PP -This command does not support authenticated encryption modes -like \s-1CCM\s0 and \s-1GCM,\s0 and will not support such modes in the future. -This is due to having to begin streaming output (e.g., to standard output -when \fB\-out\fR is not used) before the authentication tag could be validated. -When this command is used in a pipeline, the receiving end will not be -able to roll back upon authentication failure. The \s-1AEAD\s0 modes currently in -common use also suffer from catastrophic failure of confidentiality and/or -integrity upon reuse of key/iv/nonce, and since \fBopenssl enc\fR places the -entire burden of key/iv/nonce management upon the user, the risk of -exposing \s-1AEAD\s0 modes is too great to allow. These key/iv/nonce -management issues also affect other modes currently exposed in this command, -but the failure modes are less extreme in these cases, and the -functionality cannot be removed with a stable release branch. -For bulk encryption of data, whether using authenticated encryption -modes or other modes, \fBopenssl\-cms\fR\|(1) is recommended, as it provides a -standard data format and performs the needed key/iv/nonce management. -.PP -When enc is used with key wrapping modes the input data cannot be streamed, -meaning it must be processed in a single pass. -Consequently, the input data size must be less than -the buffer size (\-bufsize arg, default to 8*1024 bytes). -The '*\-wrap' ciphers require the input to be a multiple of 8 bytes long, -because no padding is involved. -The '*\-wrap\-pad' ciphers allow any input length. -In both cases, no \s-1IV\s0 is needed. See example below. -.PP -.Vb 1 -\& base64 Base 64 -\& -\& bf\-cbc Blowfish in CBC mode -\& bf Alias for bf\-cbc -\& blowfish Alias for bf\-cbc -\& bf\-cfb Blowfish in CFB mode -\& bf\-ecb Blowfish in ECB mode -\& bf\-ofb Blowfish in OFB mode -\& -\& cast\-cbc CAST in CBC mode -\& cast Alias for cast\-cbc -\& cast5\-cbc CAST5 in CBC mode -\& cast5\-cfb CAST5 in CFB mode -\& cast5\-ecb CAST5 in ECB mode -\& cast5\-ofb CAST5 in OFB mode -\& -\& chacha20 ChaCha20 algorithm -\& -\& des\-cbc DES in CBC mode -\& des Alias for des\-cbc -\& des\-cfb DES in CFB mode -\& des\-ofb DES in OFB mode -\& des\-ecb DES in ECB mode -\& -\& des\-ede\-cbc Two key triple DES EDE in CBC mode -\& des\-ede Two key triple DES EDE in ECB mode -\& des\-ede\-cfb Two key triple DES EDE in CFB mode -\& des\-ede\-ofb Two key triple DES EDE in OFB mode -\& -\& des\-ede3\-cbc Three key triple DES EDE in CBC mode -\& des\-ede3 Three key triple DES EDE in ECB mode -\& des3 Alias for des\-ede3\-cbc -\& des\-ede3\-cfb Three key triple DES EDE CFB mode -\& des\-ede3\-ofb Three key triple DES EDE in OFB mode -\& -\& desx DESX algorithm. -\& -\& gost89 GOST 28147\-89 in CFB mode (provided by ccgost engine) -\& gost89\-cnt GOST 28147\-89 in CNT mode (provided by ccgost engine) -\& -\& idea\-cbc IDEA algorithm in CBC mode -\& idea same as idea\-cbc -\& idea\-cfb IDEA in CFB mode -\& idea\-ecb IDEA in ECB mode -\& idea\-ofb IDEA in OFB mode -\& -\& rc2\-cbc 128 bit RC2 in CBC mode -\& rc2 Alias for rc2\-cbc -\& rc2\-cfb 128 bit RC2 in CFB mode -\& rc2\-ecb 128 bit RC2 in ECB mode -\& rc2\-ofb 128 bit RC2 in OFB mode -\& rc2\-64\-cbc 64 bit RC2 in CBC mode -\& rc2\-40\-cbc 40 bit RC2 in CBC mode -\& -\& rc4 128 bit RC4 -\& rc4\-64 64 bit RC4 -\& rc4\-40 40 bit RC4 -\& -\& rc5\-cbc RC5 cipher in CBC mode -\& rc5 Alias for rc5\-cbc -\& rc5\-cfb RC5 cipher in CFB mode -\& rc5\-ecb RC5 cipher in ECB mode -\& rc5\-ofb RC5 cipher in OFB mode -\& -\& seed\-cbc SEED cipher in CBC mode -\& seed Alias for seed\-cbc -\& seed\-cfb SEED cipher in CFB mode -\& seed\-ecb SEED cipher in ECB mode -\& seed\-ofb SEED cipher in OFB mode -\& -\& sm4\-cbc SM4 cipher in CBC mode -\& sm4 Alias for sm4\-cbc -\& sm4\-cfb SM4 cipher in CFB mode -\& sm4\-ctr SM4 cipher in CTR mode -\& sm4\-ecb SM4 cipher in ECB mode -\& sm4\-ofb SM4 cipher in OFB mode -\& -\& aes\-[128|192|256]\-cbc 128/192/256 bit AES in CBC mode -\& aes[128|192|256] Alias for aes\-[128|192|256]\-cbc -\& aes\-[128|192|256]\-cfb 128/192/256 bit AES in 128 bit CFB mode -\& aes\-[128|192|256]\-cfb1 128/192/256 bit AES in 1 bit CFB mode -\& aes\-[128|192|256]\-cfb8 128/192/256 bit AES in 8 bit CFB mode -\& aes\-[128|192|256]\-ctr 128/192/256 bit AES in CTR mode -\& aes\-[128|192|256]\-ecb 128/192/256 bit AES in ECB mode -\& aes\-[128|192|256]\-ofb 128/192/256 bit AES in OFB mode -\& -\& aes\-[128|192|256]\-wrap key wrapping using 128/192/256 bit AES -\& aes\-[128|192|256]\-wrap\-pad key wrapping with padding using 128/192/256 bit AES -\& -\& aria\-[128|192|256]\-cbc 128/192/256 bit ARIA in CBC mode -\& aria[128|192|256] Alias for aria\-[128|192|256]\-cbc -\& aria\-[128|192|256]\-cfb 128/192/256 bit ARIA in 128 bit CFB mode -\& aria\-[128|192|256]\-cfb1 128/192/256 bit ARIA in 1 bit CFB mode -\& aria\-[128|192|256]\-cfb8 128/192/256 bit ARIA in 8 bit CFB mode -\& aria\-[128|192|256]\-ctr 128/192/256 bit ARIA in CTR mode -\& aria\-[128|192|256]\-ecb 128/192/256 bit ARIA in ECB mode -\& aria\-[128|192|256]\-ofb 128/192/256 bit ARIA in OFB mode -\& -\& camellia\-[128|192|256]\-cbc 128/192/256 bit Camellia in CBC mode -\& camellia[128|192|256] Alias for camellia\-[128|192|256]\-cbc -\& camellia\-[128|192|256]\-cfb 128/192/256 bit Camellia in 128 bit CFB mode -\& camellia\-[128|192|256]\-cfb1 128/192/256 bit Camellia in 1 bit CFB mode -\& camellia\-[128|192|256]\-cfb8 128/192/256 bit Camellia in 8 bit CFB mode -\& camellia\-[128|192|256]\-ctr 128/192/256 bit Camellia in CTR mode -\& camellia\-[128|192|256]\-ecb 128/192/256 bit Camellia in ECB mode -\& camellia\-[128|192|256]\-ofb 128/192/256 bit Camellia in OFB mode -.Ve -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Just base64 encode a binary file: -.PP -.Vb 1 -\& openssl base64 \-in file.bin \-out file.b64 -.Ve -.PP -Decode the same file -.PP -.Vb 1 -\& openssl base64 \-d \-in file.b64 \-out file.bin -.Ve -.PP -Encrypt a file using \s-1AES\-128\s0 using a prompted password -and \s-1PBKDF2\s0 key derivation: -.PP -.Vb 1 -\& openssl enc \-aes128 \-pbkdf2 \-in file.txt \-out file.aes128 -.Ve -.PP -Decrypt a file using a supplied password: -.PP -.Vb 2 -\& openssl enc \-aes128 \-pbkdf2 \-d \-in file.aes128 \-out file.txt \e -\& \-pass pass: -.Ve -.PP -Encrypt a file then base64 encode it (so it can be sent via mail for example) -using \s-1AES\-256\s0 in \s-1CTR\s0 mode and \s-1PBKDF2\s0 key derivation: -.PP -.Vb 1 -\& openssl enc \-aes\-256\-ctr \-pbkdf2 \-a \-in file.txt \-out file.aes256 -.Ve -.PP -Base64 decode a file then decrypt it using a password supplied in a file: -.PP -.Vb 2 -\& openssl enc \-aes\-256\-ctr \-pbkdf2 \-d \-a \-in file.aes256 \-out file.txt \e -\& \-pass file: -.Ve -.PP -\&\s-1AES\s0 key wrapping: -.PP -.Vb 3 -\& openssl enc \-e \-a \-id\-aes128\-wrap\-pad \-K 000102030405060708090A0B0C0D0E0F \-in file.bin -\&or -\& openssl aes128\-wrap\-pad \-e \-a \-K 000102030405060708090A0B0C0D0E0F \-in file.bin -.Ve -.SH "BUGS" -.IX Header "BUGS" -The \fB\-A\fR option when used with large files doesn't work properly. -On the other hand, when base64 decoding without the \fB\-A\fR option, -if the first 1024 bytes of input do not include a newline character -the first two lines of input are ignored. -.PP -The \fBopenssl enc\fR command only supports a fixed number of algorithms with -certain parameters. So if, for example, you want to use \s-1RC2\s0 with a -76 bit key or \s-1RC4\s0 with an 84 bit key you can't use this program. -.SH "HISTORY" -.IX Header "HISTORY" -The default digest was changed from \s-1MD5\s0 to \s-1SHA256\s0 in OpenSSL 1.1.0. -.PP -The \fB\-list\fR option was added in OpenSSL 1.1.1e. -.PP -The \fB\-ciphers\fR and \fB\-engine\fR options were deprecated in OpenSSL 3.0. -.PP -The \fB\-saltlen\fR option was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-engine.1ossl b/openssl-install/share/man/man1/openssl-engine.1ossl deleted file mode 100644 index 2da0478e..00000000 --- a/openssl-install/share/man/man1/openssl-engine.1ossl +++ /dev/null @@ -1,251 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-ENGINE 1ossl" -.TH OPENSSL-ENGINE 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-engine \- load and query engines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl engine\fR -[\fB\-help\fR] -[\fB\-v\fR] -[\fB\-vv\fR] -[\fB\-vvv\fR] -[\fB\-vvvv\fR] -[\fB\-c\fR] -[\fB\-t\fR] -[\fB\-tt\fR] -[\fB\-pre\fR \fIcommand\fR] ... -[\fB\-post\fR \fIcommand\fR] ... -[\fIengine\fR ...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command has been deprecated. Providers should be used instead of engines. -.PP -This command is used to query the status and capabilities -of the specified \fIengine\fRs. -Engines may be specified before and after all other command-line flags. -Only those specified are queried. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Display an option summary. -.IP "\fB\-v\fR \fB\-vv\fR \fB\-vvv\fR \fB\-vvvv\fR" 4 -.IX Item "-v -vv -vvv -vvvv" -Provides information about each specified engine. The first flag lists -all the possible run-time control commands; the second adds a -description of each command; the third adds the input flags, and the -final option adds the internal input flags. -.IP "\fB\-c\fR" 4 -.IX Item "-c" -Lists the capabilities of each engine. -.IP "\fB\-t\fR" 4 -.IX Item "-t" -Tests if each specified engine is available, and displays the answer. -.IP "\fB\-tt\fR" 4 -.IX Item "-tt" -Displays an error trace for any unavailable engine. -.IP "\fB\-pre\fR \fIcommand\fR" 4 -.IX Item "-pre command" -.PD 0 -.IP "\fB\-post\fR \fIcommand\fR" 4 -.IX Item "-post command" -.PD -Command-line configuration of engines. -The \fB\-pre\fR command is given to the engine before it is loaded and -the \fB\-post\fR command is given after the engine is loaded. -The \fIcommand\fR is of the form \fIcmd\fR:\fIval\fR where \fIcmd\fR is the command, -and \fIval\fR is the value for the command. -See the example below. -.Sp -These two options are cumulative, so they may be given more than once in the -same command. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To list all the commands available to a dynamic engine: -.PP -.Vb 10 -\& $ openssl engine \-t \-tt \-vvvv dynamic -\& (dynamic) Dynamic engine loading support -\& [ unavailable ] -\& SO_PATH: Specifies the path to the new ENGINE shared library -\& (input flags): STRING -\& NO_VCHECK: Specifies to continue even if version checking fails (boolean) -\& (input flags): NUMERIC -\& ID: Specifies an ENGINE id name for loading -\& (input flags): STRING -\& LIST_ADD: Whether to add a loaded ENGINE to the internal list (0=no,1=yes,2=mandatory) -\& (input flags): NUMERIC -\& DIR_LOAD: Specifies whether to load from \*(AqDIR_ADD\*(Aq directories (0=no,1=yes,2=mandatory) -\& (input flags): NUMERIC -\& DIR_ADD: Adds a directory from which ENGINEs can be loaded -\& (input flags): STRING -\& LOAD: Load up the ENGINE specified by other settings -\& (input flags): NO_INPUT -.Ve -.PP -To list the capabilities of the \fBrsax\fR engine: -.PP -.Vb 4 -\& $ openssl engine \-c -\& (rsax) RSAX engine support -\& [RSA] -\& (dynamic) Dynamic engine loading support -.Ve -.SH "ENVIRONMENT" -.IX Header "ENVIRONMENT" -.IP "\fB\s-1OPENSSL_ENGINES\s0\fR" 4 -.IX Item "OPENSSL_ENGINES" -The path to the engines directory. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBconfig\fR\|(5) -.SH "HISTORY" -.IX Header "HISTORY" -This command was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-errstr.1ossl b/openssl-install/share/man/man1/openssl-errstr.1ossl deleted file mode 100644 index bf7de31f..00000000 --- a/openssl-install/share/man/man1/openssl-errstr.1ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-ERRSTR 1ossl" -.TH OPENSSL-ERRSTR 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-errstr \- lookup error codes -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl errstr\fR -[\fB\-help\fR] -\&\fIerror_code...\fR -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Sometimes an application will not load error message texts and only -numerical forms will be available. This command can be -used to display the meaning of the hex code. The hex code is the hex digits -after the second colon. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Display a usage message. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The error code: -.PP -.Vb 1 -\& 27594:error:2006D080:lib(32)::reason(128)::107: -.Ve -.PP -can be displayed with: -.PP -.Vb 1 -\& openssl errstr 2006D080 -.Ve -.PP -to produce the error message: -.PP -.Vb 1 -\& error:2006D080:BIO routines::no such file -.Ve -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-fipsinstall.1ossl b/openssl-install/share/man/man1/openssl-fipsinstall.1ossl deleted file mode 100644 index 3e729c78..00000000 --- a/openssl-install/share/man/man1/openssl-fipsinstall.1ossl +++ /dev/null @@ -1,578 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-FIPSINSTALL 1ossl" -.TH OPENSSL-FIPSINSTALL 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-fipsinstall \- perform FIPS configuration installation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl fipsinstall\fR -[\fB\-help\fR] -[\fB\-in\fR \fIconfigfilename\fR] -[\fB\-out\fR \fIconfigfilename\fR] -[\fB\-module\fR \fImodulefilename\fR] -[\fB\-provider_name\fR \fIprovidername\fR] -[\fB\-section_name\fR \fIsectionname\fR] -[\fB\-verify\fR] -[\fB\-mac_name\fR \fImacname\fR] -[\fB\-macopt\fR \fInm\fR:\fIv\fR] -[\fB\-noout\fR] -[\fB\-quiet\fR] -[\fB\-pedantic\fR] -[\fB\-no_conditional_errors\fR] -[\fB\-no_security_checks\fR] -[\fB\-hmac_key_check\fR] -[\fB\-kmac_key_check\fR] -[\fB\-ems_check\fR] -[\fB\-no_drbg_truncated_digests\fR] -[\fB\-signature_digest_check\fR] -[\fB\-hkdf_digest_check\fR] -[\fB\-tls13_kdf_digest_check\fR] -[\fB\-tls1_prf_digest_check\fR] -[\fB\-sshkdf_digest_check\fR] -[\fB\-sskdf_digest_check\fR] -[\fB\-x963kdf_digest_check\fR] -[\fB\-dsa_sign_disabled\fR] -[\fB\-no_pbkdf2_lower_bound_check\fR] -[\fB\-no_short_mac\fR] -[\fB\-tdes_encrypt_disabled\fR] -[\fB\-rsa_pkcs15_padding_disabled\fR] -[\fB\-rsa_pss_saltlen_check\fR] -[\fB\-rsa_sign_x931_disabled\fR] -[\fB\-hkdf_key_check\fR] -[\fB\-kbkdf_key_check\fR] -[\fB\-tls13_kdf_key_check\fR] -[\fB\-tls1_prf_key_check\fR] -[\fB\-sshkdf_key_check\fR] -[\fB\-sskdf_key_check\fR] -[\fB\-x963kdf_key_check\fR] -[\fB\-x942kdf_key_check\fR] -[\fB\-ecdh_cofactor_check\fR] -[\fB\-self_test_onload\fR] -[\fB\-self_test_oninstall\fR] -[\fB\-corrupt_desc\fR \fIselftest_description\fR] -[\fB\-corrupt_type\fR \fIselftest_type\fR] -[\fB\-config\fR \fIparent_config\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to generate a \s-1FIPS\s0 module configuration file. -This configuration file can be used each time a \s-1FIPS\s0 module is loaded -in order to pass data to the \s-1FIPS\s0 module self tests. The \s-1FIPS\s0 module always -verifies its \s-1MAC,\s0 but optionally only needs to run the \s-1KAT\s0's once, -at installation. -.PP -The generated configuration file consists of: -.IP "\- A \s-1MAC\s0 of the \s-1FIPS\s0 module file." 4 -.IX Item "- A MAC of the FIPS module file." -.PD 0 -.IP "\- A test status indicator." 4 -.IX Item "- A test status indicator." -.PD -This indicates if the Known Answer Self Tests (\s-1KAT\s0's) have successfully run. -.IP "\- A \s-1MAC\s0 of the status indicator." 4 -.IX Item "- A MAC of the status indicator." -.PD 0 -.IP "\- A control for conditional self tests errors." 4 -.IX Item "- A control for conditional self tests errors." -.PD -By default if a continuous test (e.g a key pair test) fails then the \s-1FIPS\s0 module -will enter an error state, and no services or cryptographic algorithms will be -able to be accessed after this point. -The default value of '1' will cause the fips module error state to be entered. -If the value is '0' then the module error state will not be entered. -Regardless of whether the error state is entered or not, the current operation -(e.g. key generation) will return an error. The user is responsible for retrying -the operation if the module error state is not entered. -.IP "\- A control to indicate whether run-time security checks are done." 4 -.IX Item "- A control to indicate whether run-time security checks are done." -This indicates if run-time checks related to enforcement of security parameters -such as minimum security strength of keys and approved curve names are used. -The default value of '1' will perform the checks. -If the value is '0' the checks are not performed and \s-1FIPS\s0 compliance must -be done by procedures documented in the relevant Security Policy. -.PP -This file is described in \fBfips_config\fR\|(5). -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print a usage message. -.IP "\fB\-module\fR \fIfilename\fR" 4 -.IX Item "-module filename" -Filename of the \s-1FIPS\s0 module to perform an integrity check on. -The path provided in the filename is used to load the module when it is -activated, and this overrides the environment variable \fB\s-1OPENSSL_MODULES\s0\fR. -.IP "\fB\-out\fR \fIconfigfilename\fR" 4 -.IX Item "-out configfilename" -Filename to output the configuration data to; the default is standard output. -.IP "\fB\-in\fR \fIconfigfilename\fR" 4 -.IX Item "-in configfilename" -Input filename to load configuration data from. -Must be used if the \fB\-verify\fR option is specified. -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verify that the input configuration file contains the correct information. -.IP "\fB\-provider_name\fR \fIprovidername\fR" 4 -.IX Item "-provider_name providername" -Name of the provider inside the configuration file. -The default value is \f(CW\*(C`fips\*(C'\fR. -.IP "\fB\-section_name\fR \fIsectionname\fR" 4 -.IX Item "-section_name sectionname" -Name of the section inside the configuration file. -The default value is \f(CW\*(C`fips_sect\*(C'\fR. -.IP "\fB\-mac_name\fR \fIname\fR" 4 -.IX Item "-mac_name name" -Specifies the name of a supported \s-1MAC\s0 algorithm which will be used. -The \s-1MAC\s0 mechanisms that are available will depend on the options -used when building OpenSSL. -To see the list of supported \s-1MAC\s0's use the command -\&\f(CW\*(C`openssl list \-mac\-algorithms\*(C'\fR. The default is \fB\s-1HMAC\s0\fR. -.IP "\fB\-macopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-macopt nm:v" -Passes options to the \s-1MAC\s0 algorithm. -A comprehensive list of controls can be found in the \s-1EVP_MAC\s0 implementation -documentation. -Common control strings used for this command are: -.RS 4 -.IP "\fBkey\fR:\fIstring\fR" 4 -.IX Item "key:string" -Specifies the \s-1MAC\s0 key as an alphanumeric string (use if the key contains -printable characters only). -The string length must conform to any restrictions of the \s-1MAC\s0 algorithm. -A key must be specified for every \s-1MAC\s0 algorithm. -If no key is provided, the default that was specified when OpenSSL was -configured is used. -.IP "\fBhexkey\fR:\fIstring\fR" 4 -.IX Item "hexkey:string" -Specifies the \s-1MAC\s0 key in hexadecimal form (two hex digits per byte). -The key length must conform to any restrictions of the \s-1MAC\s0 algorithm. -A key must be specified for every \s-1MAC\s0 algorithm. -If no key is provided, the default that was specified when OpenSSL was -configured is used. -.IP "\fBdigest\fR:\fIstring\fR" 4 -.IX Item "digest:string" -Used by \s-1HMAC\s0 as an alphanumeric string (use if the key contains printable -characters only). -The string length must conform to any restrictions of the \s-1MAC\s0 algorithm. -To see the list of supported digests, use the command -\&\f(CW\*(C`openssl list \-digest\-commands\*(C'\fR. -The default digest is \s-1SHA\-256.\s0 -.RE -.RS 4 -.RE -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -Disable logging of the self tests. -.IP "\fB\-pedantic\fR" 4 -.IX Item "-pedantic" -Configure the module so that it is strictly \s-1FIPS\s0 compliant rather -than being backwards compatible. This enables conditional errors, -security checks etc. Note that any previous configuration options will -be overwritten and any subsequent configuration options that violate -\&\s-1FIPS\s0 compliance will result in an error. -.IP "\fB\-no_conditional_errors\fR" 4 -.IX Item "-no_conditional_errors" -Configure the module to not enter an error state if a conditional self test -fails as described above. -.IP "\fB\-no_security_checks\fR" 4 -.IX Item "-no_security_checks" -Configure the module to not perform run-time security checks as described above. -.Sp -Enabling the configuration option \*(L"no-fips-securitychecks\*(R" provides another way to -turn off the check at compile time. -.IP "\fB\-ems_check\fR" 4 -.IX Item "-ems_check" -Configure the module to enable a run-time Extended Master Secret (\s-1EMS\s0) check -when using the \s-1TLS1_PRF KDF\s0 algorithm. This check is disabled by default. -See \s-1RFC 7627\s0 for information related to \s-1EMS.\s0 -.IP "\fB\-no_short_mac\fR" 4 -.IX Item "-no_short_mac" -Configure the module to not allow short \s-1MAC\s0 outputs. -See \s-1SP 800\-185 8.4.2\s0 and \s-1FIPS 140\-3 ID C.D\s0 for details. -.IP "\fB\-hmac_key_check\fR" 4 -.IX Item "-hmac_key_check" -Configure the module to not allow small keys sizes when using \s-1HMAC.\s0 -See \s-1SP\s0 800\-131Ar2 for details. -.IP "\fB\-kmac_key_check\fR" 4 -.IX Item "-kmac_key_check" -Configure the module to not allow small keys sizes when using \s-1KMAC.\s0 -See \s-1SP\s0 800\-131Ar2 for details. -.IP "\fB\-no_drbg_truncated_digests\fR" 4 -.IX Item "-no_drbg_truncated_digests" -Configure the module to not allow truncated digests to be used with Hash and -\&\s-1HMAC\s0 DRBGs. See \s-1FIPS 140\-3 IG D.R\s0 for details. -.IP "\fB\-signature_digest_check\fR" 4 -.IX Item "-signature_digest_check" -Configure the module to enforce signature algorithms to use digests that are -explicitly permitted by the various standards. -.IP "\fB\-hkdf_digest_check\fR" 4 -.IX Item "-hkdf_digest_check" -Configure the module to enable a run-time digest check when deriving a key by -\&\s-1HKDF.\s0 -See \s-1NIST SP\s0 800\-56Cr2 for details. -.IP "\fB\-tls13_kdf_digest_check\fR" 4 -.IX Item "-tls13_kdf_digest_check" -Configure the module to enable a run-time digest check when deriving a key by -\&\s-1TLS13 KDF.\s0 -See \s-1RFC 8446\s0 for details. -.IP "\fB\-tls1_prf_digest_check\fR" 4 -.IX Item "-tls1_prf_digest_check" -Configure the module to enable a run-time digest check when deriving a key by -\&\s-1TLS_PRF.\s0 -See \s-1NIST SP\s0 800\-135r1 for details. -.IP "\fB\-sshkdf_digest_check\fR" 4 -.IX Item "-sshkdf_digest_check" -Configure the module to enable a run-time digest check when deriving a key by -\&\s-1SSHKDF.\s0 -See \s-1NIST SP\s0 800\-135r1 for details. -.IP "\fB\-sskdf_digest_check\fR" 4 -.IX Item "-sskdf_digest_check" -Configure the module to enable a run-time digest check when deriving a key by -\&\s-1SSKDF.\s0 -See \s-1NIST SP\s0 800\-56Cr2 for details. -.IP "\fB\-x963kdf_digest_check\fR" 4 -.IX Item "-x963kdf_digest_check" -Configure the module to enable a run-time digest check when deriving a key by -X963KDF. -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-dsa_sign_disabled\fR" 4 -.IX Item "-dsa_sign_disabled" -Configure the module to not allow \s-1DSA\s0 signing (\s-1DSA\s0 signature verification is -still allowed). See \s-1FIPS 140\-3 IG C.K\s0 for details. -.IP "\fB\-tdes_encrypt_disabled\fR" 4 -.IX Item "-tdes_encrypt_disabled" -Configure the module to not allow Triple-DES encryption. -Triple-DES decryption is still allowed for legacy purposes. -See SP800\-131Ar2 for details. -.IP "\fB\-rsa_pkcs15_padding_disabled\fR" 4 -.IX Item "-rsa_pkcs15_padding_disabled" -Configure the module to not allow PKCS#1 version 1.5 padding to be used with -\&\s-1RSA\s0 for key transport and key agreement. See \s-1NIST\s0's \s-1SP 800\-131A\s0 Revision 2 -for details. -.IP "\fB\-rsa_pss_saltlen_check\fR" 4 -.IX Item "-rsa_pss_saltlen_check" -Configure the module to enable a run-time salt length check when generating or -verifying a RSA-PSS signature. -See \s-1FIPS 186\-5 5.4\s0 (g) for details. -.IP "\fB\-rsa_sign_x931_disabled\fR" 4 -.IX Item "-rsa_sign_x931_disabled" -Configure the module to not allow X9.31 padding to be used when signing with -\&\s-1RSA.\s0 See \s-1FIPS 140\-3 IG C.K\s0 for details. -.IP "\fB\-hkdf_key_check\fR" 4 -.IX Item "-hkdf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by \s-1HKDF.\s0 -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-kbkdf_key_check\fR" 4 -.IX Item "-kbkdf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by \s-1KBKDF.\s0 -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-tls13_kdf_key_check\fR" 4 -.IX Item "-tls13_kdf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by \s-1TLS13 KDF.\s0 -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-tls1_prf_key_check\fR" 4 -.IX Item "-tls1_prf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by \s-1TLS_PRF.\s0 -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-sshkdf_key_check\fR" 4 -.IX Item "-sshkdf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by \s-1SSHKDF.\s0 -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-sskdf_key_check\fR" 4 -.IX Item "-sskdf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by \s-1SSKDF.\s0 -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-x963kdf_key_check\fR" 4 -.IX Item "-x963kdf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by X963KDF. -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-x942kdf_key_check\fR" 4 -.IX Item "-x942kdf_key_check" -Configure the module to enable a run-time short key-derivation key check when -deriving a key by X942KDF. -See \s-1NIST SP\s0 800\-131Ar2 for details. -.IP "\fB\-no_pbkdf2_lower_bound_check\fR" 4 -.IX Item "-no_pbkdf2_lower_bound_check" -Configure the module to not perform run-time lower bound check for \s-1PBKDF2.\s0 -See \s-1NIST SP 800\-132\s0 for details. -.IP "\fB\-ecdh_cofactor_check\fR" 4 -.IX Item "-ecdh_cofactor_check" -Configure the module to enable a run-time check that \s-1ECDH\s0 uses the \s-1EC\s0 curves -cofactor value when deriving a key. This only affects the 'B' and 'K' curves. -See \s-1SP 800\-56A\s0 r3 Section 5.7.1.2 for details. -.IP "\fB\-self_test_onload\fR" 4 -.IX Item "-self_test_onload" -Do not write the two fields related to the \*(L"test status indicator\*(R" and -\&\*(L"\s-1MAC\s0 status indicator\*(R" to the output configuration file. Without these fields -the self tests \s-1KATS\s0 will run each time the module is loaded. This option could be -used for cross compiling, since the self tests need to run at least once on each -target machine. Once the self tests have run on the target machine the user -could possibly then add the 2 fields into the configuration using some other -mechanism. -.Sp -This is the default. -.IP "\fB\-self_test_oninstall\fR" 4 -.IX Item "-self_test_oninstall" -The converse of \fB\-self_test_oninstall\fR. The two fields related to the -\&\*(L"test status indicator\*(R" and \*(L"\s-1MAC\s0 status indicator\*(R" are written to the -output configuration file. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Do not output pass/fail messages. Implies \fB\-noout\fR. -.IP "\fB\-corrupt_desc\fR \fIselftest_description\fR, \fB\-corrupt_type\fR \fIselftest_type\fR" 4 -.IX Item "-corrupt_desc selftest_description, -corrupt_type selftest_type" -The corrupt options can be used to test failure of one or more self tests by -name. -Either option or both may be used to select the tests to corrupt. -Refer to the entries for \fBst-desc\fR and \fBst-type\fR in \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) for -values that can be used. -.IP "\fB\-config\fR \fIparent_config\fR" 4 -.IX Item "-config parent_config" -Test that a \s-1FIPS\s0 provider can be loaded from the specified configuration file. -A previous call to this application needs to generate the extra configuration -data that is included by the base \f(CW\*(C`parent_config\*(C'\fR configuration file. -See \fBconfig\fR\|(5) for further information on how to set up a provider section. -All other options are ignored if '\-config' is used. -.SH "NOTES" -.IX Header "NOTES" -Self tests results are logged by default if the options \fB\-quiet\fR and \fB\-noout\fR -are not specified, or if either of the options \fB\-corrupt_desc\fR or -\&\fB\-corrupt_type\fR are used. -If the base configuration file is set up to autoload the fips module, then the -fips module will be loaded and self tested \s-1BEFORE\s0 the fipsinstall application -has a chance to set up its own self test callback. As a result of this the self -test output and the options \fB\-corrupt_desc\fR and \fB\-corrupt_type\fR will be ignored. -For normal usage the base configuration file should use the default provider -when generating the fips configuration file. -.PP -The \fB\-self_test_oninstall\fR option was added and the -\&\fB\-self_test_onload\fR option was made the default in OpenSSL 3.1. -.PP -The command and all remaining options were added in OpenSSL 3.0. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Calculate the mac of a \s-1FIPS\s0 module \fIfips.so\fR and run a \s-1FIPS\s0 self test -for the module, and save the \fIfips.cnf\fR configuration file: -.PP -.Vb 1 -\& openssl fipsinstall \-module ./fips.so \-out fips.cnf \-provider_name fips -.Ve -.PP -Verify that the configuration file \fIfips.cnf\fR contains the correct info: -.PP -.Vb 1 -\& openssl fipsinstall \-module ./fips.so \-in fips.cnf \-provider_name fips \-verify -.Ve -.PP -Corrupt any self tests which have the description \f(CW\*(C`SHA1\*(C'\fR: -.PP -.Vb 2 -\& openssl fipsinstall \-module ./fips.so \-out fips.cnf \-provider_name fips \e -\& \-corrupt_desc \*(AqSHA1\*(Aq -.Ve -.PP -Validate that the fips module can be loaded from a base configuration file: -.PP -.Vb 3 -\& export OPENSSL_CONF_INCLUDE= -\& export OPENSSL_MODULES= -\& openssl fipsinstall \-config\*(Aq \*(Aqdefault.cnf\*(Aq -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBconfig\fR\|(5), -\&\fBfips_config\fR\|(5), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -\&\s-1\fBEVP_MAC\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBopenssl-fipsinstall\fR application was added in OpenSSL 3.0. -.PP -The following options were added in OpenSSL 3.1: -.PP -\&\fB\-ems_check\fR, -\&\fB\-self_test_oninstall\fR -.PP -The following options were added in OpenSSL 3.2: -.PP -\&\fB\-pedantic\fR, -\&\fB\-no_drbg_truncated_digests\fR -.PP -The following options were added in OpenSSL 3.4: -.PP -\&\fB\-hmac_key_check\fR, -\&\fB\-kmac_key_check\fR, -\&\fB\-signature_digest_check\fR, -\&\fB\-hkdf_digest_check\fR, -\&\fB\-tls13_kdf_digest_check\fR, -\&\fB\-tls1_prf_digest_check\fR, -\&\fB\-sshkdf_digest_check\fR, -\&\fB\-sskdf_digest_check\fR, -\&\fB\-x963kdf_digest_check\fR, -\&\fB\-dsa_sign_disabled\fR, -\&\fB\-no_pbkdf2_lower_bound_check\fR, -\&\fB\-no_short_mac\fR, -\&\fB\-tdes_encrypt_disabled\fR, -\&\fB\-rsa_pkcs15_padding_disabled\fR, -\&\fB\-rsa_pss_saltlen_check\fR, -\&\fB\-rsa_sign_x931_disabled\fR, -\&\fB\-hkdf_key_check\fR, -\&\fB\-kbkdf_key_check\fR, -\&\fB\-tls13_kdf_key_check\fR, -\&\fB\-tls1_prf_key_check\fR, -\&\fB\-sshkdf_key_check\fR, -\&\fB\-sskdf_key_check\fR, -\&\fB\-x963kdf_key_check\fR, -\&\fB\-x942kdf_key_check\fR, -\&\fB\-ecdh_cofactor_check\fR -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-format-options.1ossl b/openssl-install/share/man/man1/openssl-format-options.1ossl deleted file mode 100644 index 61cde309..00000000 --- a/openssl-install/share/man/man1/openssl-format-options.1ossl +++ /dev/null @@ -1,265 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-FORMAT-OPTIONS 1ossl" -.TH OPENSSL-FORMAT-OPTIONS 1ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-format\-options \- OpenSSL command input and output format options -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR -\&\fIcommand\fR -[ \fIoptions\fR ... ] -[ \fIparameters\fR ... ] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Several OpenSSL commands can take input or generate output in a variety -of formats. -.PP -Since OpenSSL 3.0 keys, single certificates, and CRLs can be read from -files in any of the \fB\s-1DER\s0\fR, \fB\s-1PEM\s0\fR or \fBP12\fR formats. Specifying their input -format is no more needed and the openssl commands will automatically try all -the possible formats. However if the \fB\s-1DER\s0\fR or \fB\s-1PEM\s0\fR input format is specified -it will be enforced. -.PP -In order to access a key via an engine the input format \fB\s-1ENGINE\s0\fR may be used; -alternatively the key identifier in the argument of the respective key -option may be preceded by \f(CW\*(C`org.openssl.engine:\*(C'\fR. -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1) for an example usage of the latter. -.SH "OPTIONS" -.IX Header "OPTIONS" -.SS "Format Options" -.IX Subsection "Format Options" -The options to specify the format are as follows. -Refer to the individual man page to see which options are accepted. -.IP "\fB\-inform\fR \fIformat\fR, \fB\-outform\fR \fIformat\fR" 4 -.IX Item "-inform format, -outform format" -The format of the input or output streams. -.IP "\fB\-keyform\fR \fIformat\fR" 4 -.IX Item "-keyform format" -Format of a private key input source. -.IP "\fB\-CRLform\fR \fIformat\fR" 4 -.IX Item "-CRLform format" -Format of a \s-1CRL\s0 input source. -.SS "Format Option Arguments" -.IX Subsection "Format Option Arguments" -The possible format arguments are described below. -Both uppercase and lowercase are accepted. -.PP -The list of acceptable format arguments, and the default, -is described in each command documentation. -.IP "\fB\s-1DER\s0\fR" 4 -.IX Item "DER" -A binary format, encoded or parsed according to Distinguished Encoding Rules -(\s-1DER\s0) of the \s-1ASN.1\s0 data language. -.IP "\fB\s-1ENGINE\s0\fR" 4 -.IX Item "ENGINE" -Used to specify that the cryptographic material is in an OpenSSL \fBengine\fR. -An engine must be configured or specified using the \fB\-engine\fR option. -A password or \s-1PIN\s0 may be supplied to the engine using the \fB\-passin\fR option. -.IP "\fBP12\fR" 4 -.IX Item "P12" -A DER-encoded file containing a PKCS#12 object. -It might be necessary to provide a decryption password to retrieve -the private key. -.IP "\fB\s-1PEM\s0\fR" 4 -.IX Item "PEM" -A text format defined in \s-1IETF RFC 1421\s0 and \s-1IETF RFC 7468.\s0 Briefly, this is -a block of base\-64 encoding (defined in \s-1IETF RFC 4648\s0), with specific -lines used to mark the start and end: -.Sp -.Vb 7 -\& Text before the BEGIN line is ignored. -\& \-\-\-\-\- BEGIN object\-type \-\-\-\-\- -\& OT43gQKBgQC/2OHZoko6iRlNOAQ/tMVFNq7fL81GivoQ9F1U0Qr+DH3ZfaH8eIkX -\& xT0ToMPJUzWAn8pZv0snA0um6SIgvkCuxO84OkANCVbttzXImIsL7pFzfcwV/ERK -\& UM6j0ZuSMFOCr/lGPAoOQU0fskidGEHi1/kW+suSr28TqsyYZpwBDQ== -\& \-\-\-\-\- END object\-type \-\-\-\-\- -\& Text after the END line is also ignored -.Ve -.Sp -The \fIobject-type\fR must match the type of object that is expected. -For example a \f(CW\*(C`BEGIN X509 CERTIFICATE\*(C'\fR will not match if the command -is trying to read a private key. The types supported include: -.Sp -.Vb 10 -\& ANY PRIVATE KEY -\& CERTIFICATE -\& CERTIFICATE REQUEST -\& CMS -\& DH PARAMETERS -\& DSA PARAMETERS -\& DSA PUBLIC KEY -\& EC PARAMETERS -\& EC PRIVATE KEY -\& ECDSA PUBLIC KEY -\& ENCRYPTED PRIVATE KEY -\& PARAMETERS -\& PKCS #7 SIGNED DATA -\& PKCS7 -\& PRIVATE KEY -\& PUBLIC KEY -\& RSA PRIVATE KEY -\& SSL SESSION PARAMETERS -\& TRUSTED CERTIFICATE -\& X509 CRL -\& X9.42 DH PARAMETERS -.Ve -.Sp -The following legacy \fIobject-type\fR's are also supported for compatibility -with earlier releases: -.Sp -.Vb 4 -\& DSA PRIVATE KEY -\& NEW CERTIFICATE REQUEST -\& RSA PUBLIC KEY -\& X509 CERTIFICATE -.Ve -.IP "\fB\s-1SMIME\s0\fR" 4 -.IX Item "SMIME" -An S/MIME object as described in \s-1IETF RFC 8551.\s0 -Earlier versions were known as \s-1CMS\s0 and are compatible. -Note that the parsing is simple and might fail to parse some legal data. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-gendsa.1ossl b/openssl-install/share/man/man1/openssl-gendsa.1ossl deleted file mode 100644 index 263c6ced..00000000 --- a/openssl-install/share/man/man1/openssl-gendsa.1ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-GENDSA 1ossl" -.TH OPENSSL-GENDSA 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-gendsa \- generate a DSA private key from a set of parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBgendsa\fR -[\fB\-help\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-aes128\fR] -[\fB\-aes192\fR] -[\fB\-aes256\fR] -[\fB\-aria128\fR] -[\fB\-aria192\fR] -[\fB\-aria256\fR] -[\fB\-camellia128\fR] -[\fB\-camellia192\fR] -[\fB\-camellia256\fR] -[\fB\-des\fR] -[\fB\-des3\fR] -[\fB\-idea\fR] -[\fB\-verbose\fR] -[\fB\-quiet\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIparamfile\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command generates a \s-1DSA\s0 private key from a \s-1DSA\s0 parameter file -(which will be typically generated by the \fBopenssl\-dsaparam\fR\|(1) command). -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Output the key to the specified file. If this argument is not specified then -standard output is used. -.IP "\fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passout arg" -The passphrase used for the output file. -See \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-aes128\fR, \fB\-aes192\fR, \fB\-aes256\fR, \fB\-aria128\fR, \fB\-aria192\fR, \fB\-aria256\fR, \fB\-camellia128\fR, \fB\-camellia192\fR, \fB\-camellia256\fR, \fB\-des\fR, \fB\-des3\fR, \fB\-idea\fR" 4 -.IX Item "-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea" -These options encrypt the private key with specified -cipher before outputting it. A pass phrase is prompted for. -If none of these options is specified no encryption is used. -.Sp -Note that all options must be given before the \fIparamfile\fR argument. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Print extra details about the operations being performed. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Print fewer details about the operations being performed, which may -be handy during batch scripts and pipelines. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fIparamfile\fR" 4 -.IX Item "paramfile" -The \s-1DSA\s0 parameter file to use. The parameters in this file determine -the size of the private key. \s-1DSA\s0 parameters can be generated and -examined using the \fBopenssl\-dsaparam\fR\|(1) command. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -\&\s-1DSA\s0 key generation is little more than random number generation so it is -much quicker that \s-1RSA\s0 key generation for example. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-dsaparam\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-genpkey.1ossl b/openssl-install/share/man/man1/openssl-genpkey.1ossl deleted file mode 100644 index e0ee9c8f..00000000 --- a/openssl-install/share/man/man1/openssl-genpkey.1ossl +++ /dev/null @@ -1,634 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-GENPKEY 1ossl" -.TH OPENSSL-GENPKEY 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-genpkey \- generate a private key or key pair -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBgenpkey\fR -[\fB\-help\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-outpubkey\fR \fIfilename\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-verbose\fR] -[\fB\-quiet\fR] -[\fB\-pass\fR \fIarg\fR] -[\fB\-\f(BIcipher\fB\fR] -[\fB\-paramfile\fR \fIfile\fR] -[\fB\-algorithm\fR \fIalg\fR] -[\fB\-pkeyopt\fR \fIopt\fR:\fIvalue\fR] -[\fB\-genparam\fR] -[\fB\-text\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -.PP -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-config\fR \fIconfigfile\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command generates a private key or key pair. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Output the private key to the specified file. If this argument is not -specified then standard output is used. -.IP "\fB\-outpubkey\fR \fIfilename\fR" 4 -.IX Item "-outpubkey filename" -Output the public key to the specified file. If this argument is not -specified then the public key is not output. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The output format, except when \fB\-genparam\fR is given; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -When \fB\-genparam\fR is given, \fB\-outform\fR is ignored. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Output \*(L"status dots\*(R" while generating keys. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Do not output \*(L"status dots\*(R" while generating keys. -.IP "\fB\-pass\fR \fIarg\fR" 4 -.IX Item "-pass arg" -The output file password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-\f(BIcipher\fB\fR" 4 -.IX Item "-cipher" -This option encrypts the private key with the supplied cipher. Any algorithm -name accepted by \fBEVP_get_cipherbyname()\fR is acceptable such as \fBdes3\fR. -.IP "\fB\-algorithm\fR \fIalg\fR" 4 -.IX Item "-algorithm alg" -Public key algorithm to use such as \s-1RSA, DSA, DH\s0 or \s-1DHX.\s0 If used this option must -precede any \fB\-pkeyopt\fR options. The options \fB\-paramfile\fR and \fB\-algorithm\fR -are mutually exclusive. Engines or providers may add algorithms in addition to -the standard built-in ones. -.Sp -Valid built-in algorithm names for private key generation are \s-1RSA,\s0 RSA-PSS, \s-1EC, -X25519, X448, ED25519\s0 and \s-1ED448.\s0 -.Sp -Valid built-in algorithm names for parameter generation (see the \fB\-genparam\fR -option) are \s-1DH, DSA\s0 and \s-1EC.\s0 -.Sp -Note that the algorithm name X9.42 \s-1DH\s0 may be used as a synonym for \s-1DHX\s0 keys and -PKCS#3 refers to \s-1DH\s0 Keys. Some options are not shared between \s-1DH\s0 and \s-1DHX\s0 keys. -.IP "\fB\-pkeyopt\fR \fIopt\fR:\fIvalue\fR" 4 -.IX Item "-pkeyopt opt:value" -Set the public key algorithm option \fIopt\fR to \fIvalue\fR. The precise set of -options supported depends on the public key algorithm used and its -implementation. See \*(L"\s-1KEY GENERATION OPTIONS\*(R"\s0 and -\&\*(L"\s-1PARAMETER GENERATION OPTIONS\*(R"\s0 below for more details. -.Sp -To list the possible \fIopt\fR values for an algorithm use: -\&\fBopenssl\fR \fBgenpkey\fR \-algorithm \s-1XXX\s0 \-help -.IP "\fB\-genparam\fR" 4 -.IX Item "-genparam" -Generate a set of parameters instead of a private key. If used this option must -precede any \fB\-algorithm\fR, \fB\-paramfile\fR or \fB\-pkeyopt\fR options. -.IP "\fB\-paramfile\fR \fIfilename\fR" 4 -.IX Item "-paramfile filename" -Some public key algorithms generate a private key based on a set of parameters. -They can be supplied using this option. If this option is used the public key -algorithm used is determined by the parameters. If used this option must -precede any \fB\-pkeyopt\fR options. The options \fB\-paramfile\fR and \fB\-algorithm\fR -are mutually exclusive. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Print an (unencrypted) text representation of private and public keys and -parameters along with the \s-1PEM\s0 or \s-1DER\s0 structure. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-config\fR \fIconfigfile\fR" 4 -.IX Item "-config configfile" -See \*(L"Configuration Option\*(R" in \fBopenssl\fR\|(1). -.SH "KEY GENERATION OPTIONS" -.IX Header "KEY GENERATION OPTIONS" -The options supported by each algorithm and indeed each implementation of an -algorithm can vary. The options for the OpenSSL implementations are detailed -below. There are no key generation options defined for the X25519, X448, \s-1ED25519\s0 -or \s-1ED448\s0 algorithms. -.SS "\s-1RSA\s0 Key Generation Options" -.IX Subsection "RSA Key Generation Options" -.IP "\fBrsa_keygen_bits:numbits\fR" 4 -.IX Item "rsa_keygen_bits:numbits" -The number of bits in the generated key. If not specified 2048 is used. -.IP "\fBrsa_keygen_primes:numprimes\fR" 4 -.IX Item "rsa_keygen_primes:numprimes" -The number of primes in the generated key. If not specified 2 is used. -.IP "\fBrsa_keygen_pubexp:value\fR" 4 -.IX Item "rsa_keygen_pubexp:value" -The \s-1RSA\s0 public exponent value. This can be a large decimal or -hexadecimal value if preceded by \f(CW\*(C`0x\*(C'\fR. Default value is 65537. -.SS "RSA-PSS Key Generation Options" -.IX Subsection "RSA-PSS Key Generation Options" -Note: by default an \fBRSA-PSS\fR key has no parameter restrictions. -.IP "\fBrsa_keygen_bits\fR:\fInumbits\fR, \fBrsa_keygen_primes\fR:\fInumprimes\fR, \fBrsa_keygen_pubexp\fR:\fIvalue\fR" 4 -.IX Item "rsa_keygen_bits:numbits, rsa_keygen_primes:numprimes, rsa_keygen_pubexp:value" -These options have the same meaning as the \fB\s-1RSA\s0\fR algorithm. -.IP "\fBrsa_pss_keygen_md\fR:\fIdigest\fR" 4 -.IX Item "rsa_pss_keygen_md:digest" -If set the key is restricted and can only use \fIdigest\fR for signing. -.IP "\fBrsa_pss_keygen_mgf1_md\fR:\fIdigest\fR" 4 -.IX Item "rsa_pss_keygen_mgf1_md:digest" -If set the key is restricted and can only use \fIdigest\fR as it's \s-1MGF1\s0 -parameter. -.IP "\fBrsa_pss_keygen_saltlen\fR:\fIlen\fR" 4 -.IX Item "rsa_pss_keygen_saltlen:len" -If set the key is restricted and \fIlen\fR specifies the minimum salt length. -.SS "\s-1EC\s0 Key Generation Options" -.IX Subsection "EC Key Generation Options" -The \s-1EC\s0 key generation options can also be used for parameter generation. -.IP "\fBec_paramgen_curve\fR:\fIcurve\fR" 4 -.IX Item "ec_paramgen_curve:curve" -The \s-1EC\s0 curve to use. OpenSSL supports \s-1NIST\s0 curve names such as \*(L"P\-256\*(R". -.IP "\fBec_param_enc\fR:\fIencoding\fR" 4 -.IX Item "ec_param_enc:encoding" -The encoding to use for parameters. The \fIencoding\fR parameter must be either -\&\fBnamed_curve\fR or \fBexplicit\fR. The default value is \fBnamed_curve\fR. -.SS "\s-1DH\s0 Key Generation Options" -.IX Subsection "DH Key Generation Options" -.IP "\fBgroup\fR:\fIname\fR" 4 -.IX Item "group:name" -The \fBparamfile\fR option is not required if a named group is used here. -See the \*(L"\s-1DH\s0 Parameter Generation Options\*(R" section below. -.SH "PARAMETER GENERATION OPTIONS" -.IX Header "PARAMETER GENERATION OPTIONS" -The options supported by each algorithm and indeed each implementation of an -algorithm can vary. The options for the OpenSSL implementations are detailed -below. -.SS "\s-1DSA\s0 Parameter Generation Options" -.IX Subsection "DSA Parameter Generation Options" -.IP "\fBdsa_paramgen_bits\fR:\fInumbits\fR" 4 -.IX Item "dsa_paramgen_bits:numbits" -The number of bits in the generated prime. If not specified 2048 is used. -.IP "\fBdsa_paramgen_q_bits\fR:\fInumbits\fR" 4 -.IX Item "dsa_paramgen_q_bits:numbits" -.PD 0 -.IP "\fBqbits\fR:\fInumbits\fR" 4 -.IX Item "qbits:numbits" -.PD -The number of bits in the q parameter. Must be one of 160, 224 or 256. If not -specified 224 is used. -.IP "\fBdsa_paramgen_md\fR:\fIdigest\fR" 4 -.IX Item "dsa_paramgen_md:digest" -.PD 0 -.IP "\fBdigest\fR:\fIdigest\fR" 4 -.IX Item "digest:digest" -.PD -The digest to use during parameter generation. Must be one of \fBsha1\fR, \fBsha224\fR -or \fBsha256\fR. If set, then the number of bits in \fBq\fR will match the output size -of the specified digest and the \fBdsa_paramgen_q_bits\fR parameter will be -ignored. If not set, then a digest will be used that gives an output matching -the number of bits in \fBq\fR, i.e. \fBsha1\fR if q length is 160, \fBsha224\fR if it 224 -or \fBsha256\fR if it is 256. -.IP "\fBproperties\fR:\fIquery\fR" 4 -.IX Item "properties:query" -The \fIdigest\fR property \fIquery\fR string to use when fetching a digest from a provider. -.IP "\fBtype\fR:\fItype\fR" 4 -.IX Item "type:type" -The type of generation to use. Set this to 1 to use legacy \s-1FIPS186\-2\s0 parameter -generation. The default of 0 uses \s-1FIPS186\-4\s0 parameter generation. -.IP "\fBgindex\fR:\fIindex\fR" 4 -.IX Item "gindex:index" -The index to use for canonical generation and verification of the generator g. -Set this to a positive value ranging from 0..255 to use this mode. Larger values -will only use the bottom byte. -This \fIindex\fR must then be reused during key validation to verify the value of g. -If this value is not set then g is not verifiable. The default value is \-1. -.IP "\fBhexseed\fR:\fIseed\fR" 4 -.IX Item "hexseed:seed" -The seed \fIseed\fR data to use instead of generating a random seed internally. -This should be used for testing purposes only. This will either produced fixed -values for the generated parameters \s-1OR\s0 it will fail if the seed did not -generate valid primes. -.SS "\s-1DH\s0 Parameter Generation Options" -.IX Subsection "DH Parameter Generation Options" -For most use cases it is recommended to use the \fBgroup\fR option rather than -the \fBtype\fR options. Note that the \fBgroup\fR option is not used by default if -no parameter generation options are specified. -.IP "\fBgroup\fR:\fIname\fR" 4 -.IX Item "group:name" -.PD 0 -.IP "\fBdh_param\fR:\fIname\fR" 4 -.IX Item "dh_param:name" -.PD -Use a named \s-1DH\s0 group to select constant values for the \s-1DH\s0 parameters. -All other options will be ignored if this value is set. -.Sp -Valid values that are associated with the \fBalgorithm\fR of \fB\*(L"\s-1DH\*(R"\s0\fR are: -\&\*(L"ffdhe2048\*(R", \*(L"ffdhe3072\*(R", \*(L"ffdhe4096\*(R", \*(L"ffdhe6144\*(R", \*(L"ffdhe8192\*(R", -\&\*(L"modp_1536\*(R", \*(L"modp_2048\*(R", \*(L"modp_3072\*(R", \*(L"modp_4096\*(R", \*(L"modp_6144\*(R", \*(L"modp_8192\*(R". -.Sp -Valid values that are associated with the \fBalgorithm\fR of \fB\*(L"\s-1DHX\*(R"\s0\fR are the -\&\s-1RFC5114\s0 names \*(L"dh_1024_160\*(R", \*(L"dh_2048_224\*(R", \*(L"dh_2048_256\*(R". -.IP "\fBdh_rfc5114\fR:\fInum\fR" 4 -.IX Item "dh_rfc5114:num" -If this option is set, then the appropriate \s-1RFC5114\s0 parameters are used -instead of generating new parameters. The value \fInum\fR can be one of -1, 2 or 3 that are equivalent to using the option \fBgroup\fR with one of -\&\*(L"dh_1024_160\*(R", \*(L"dh_2048_224\*(R" or \*(L"dh_2048_256\*(R". -All other options will be ignored if this value is set. -.IP "\fBpbits\fR:\fInumbits\fR" 4 -.IX Item "pbits:numbits" -.PD 0 -.IP "\fBdh_paramgen_prime_len\fR:\fInumbits\fR" 4 -.IX Item "dh_paramgen_prime_len:numbits" -.PD -The number of bits in the prime parameter \fIp\fR. The default is 2048. -.IP "\fBqbits\fR:\fInumbits\fR" 4 -.IX Item "qbits:numbits" -.PD 0 -.IP "\fBdh_paramgen_subprime_len\fR:\fInumbits\fR" 4 -.IX Item "dh_paramgen_subprime_len:numbits" -.PD -The number of bits in the sub prime parameter \fIq\fR. The default is 224. -Only relevant if used in conjunction with the \fBdh_paramgen_type\fR option to -generate \s-1DHX\s0 parameters. -.IP "\fBsafeprime-generator\fR:\fIvalue\fR" 4 -.IX Item "safeprime-generator:value" -.PD 0 -.IP "\fBdh_paramgen_generator\fR:\fIvalue\fR" 4 -.IX Item "dh_paramgen_generator:value" -.PD -The value to use for the generator \fIg\fR. The default is 2. -The \fBalgorithm\fR option must be \fB\*(L"\s-1DH\*(R"\s0\fR for this parameter to be used. -.IP "\fBtype\fR:\fIstring\fR" 4 -.IX Item "type:string" -The type name of \s-1DH\s0 parameters to generate. Valid values are: -.RS 4 -.ie n .IP """generator""" 4 -.el .IP "``generator''" 4 -.IX Item "generator" -Use a safe prime generator with the option \fBsafeprime_generator\fR -The \fBalgorithm\fR option must be \fB\*(L"\s-1DH\*(R"\s0\fR. -.ie n .IP """fips186_4""" 4 -.el .IP "``fips186_4''" 4 -.IX Item "fips186_4" -\&\s-1FIPS186\-4\s0 parameter generation. -The \fBalgorithm\fR option must be \fB\*(L"\s-1DHX\*(R"\s0\fR. -.ie n .IP """fips186_2""" 4 -.el .IP "``fips186_2''" 4 -.IX Item "fips186_2" -\&\s-1FIPS186\-4\s0 parameter generation. -The \fBalgorithm\fR option must be \fB\*(L"\s-1DHX\*(R"\s0\fR. -.ie n .IP """group""" 4 -.el .IP "``group''" 4 -.IX Item "group" -Can be used with the option \fBpbits\fR to select one of -\&\*(L"ffdhe2048\*(R", \*(L"ffdhe3072\*(R", \*(L"ffdhe4096\*(R", \*(L"ffdhe6144\*(R" or \*(L"ffdhe8192\*(R". -The \fBalgorithm\fR option must be \fB\*(L"\s-1DH\*(R"\s0\fR. -.ie n .IP """default""" 4 -.el .IP "``default''" 4 -.IX Item "default" -Selects a default type based on the \fBalgorithm\fR. This is used by the -OpenSSL default provider to set the type for backwards compatibility. -If \fBalgorithm\fR is \fB\*(L"\s-1DH\*(R"\s0\fR then \fB\*(L"generator\*(R"\fR is used. -If \fBalgorithm\fR is \fB\*(L"\s-1DHX\*(R"\s0\fR then \fB\*(L"fips186_2\*(R"\fR is used. -.RE -.RS 4 -.RE -.IP "\fBdh_paramgen_type\fR:\fIvalue\fR" 4 -.IX Item "dh_paramgen_type:value" -The type of \s-1DH\s0 parameters to generate. Valid values are 0, 1, 2 or 3 -which correspond to setting the option \fBtype\fR to -\&\*(L"generator\*(R", \*(L"fips186_2\*(R", \*(L"fips186_4\*(R" or \*(L"group\*(R". -.IP "\fBdigest\fR:\fIdigest\fR" 4 -.IX Item "digest:digest" -The digest to use during parameter generation. Must be one of \fBsha1\fR, \fBsha224\fR -or \fBsha256\fR. If set, then the number of bits in \fBqbits\fR will match the output -size of the specified digest and the \fBqbits\fR parameter will be -ignored. If not set, then a digest will be used that gives an output matching -the number of bits in \fBq\fR, i.e. \fBsha1\fR if q length is 160, \fBsha224\fR if it is -224 or \fBsha256\fR if it is 256. -This is only used by \*(L"fips186_4\*(R" and \*(L"fips186_2\*(R" key generation. -.IP "\fBproperties\fR:\fIquery\fR" 4 -.IX Item "properties:query" -The \fIdigest\fR property \fIquery\fR string to use when fetching a digest from a provider. -This is only used by \*(L"fips186_4\*(R" and \*(L"fips186_2\*(R" key generation. -.IP "\fBgindex\fR:\fIindex\fR" 4 -.IX Item "gindex:index" -The index to use for canonical generation and verification of the generator g. -Set this to a positive value ranging from 0..255 to use this mode. Larger values -will only use the bottom byte. -This \fIindex\fR must then be reused during key validation to verify the value of g. -If this value is not set then g is not verifiable. The default value is \-1. -This is only used by \*(L"fips186_4\*(R" and \*(L"fips186_2\*(R" key generation. -.IP "\fBhexseed\fR:\fIseed\fR" 4 -.IX Item "hexseed:seed" -The seed \fIseed\fR data to use instead of generating a random seed internally. -This should be used for testing purposes only. This will either produced fixed -values for the generated parameters \s-1OR\s0 it will fail if the seed did not -generate valid primes. -This is only used by \*(L"fips186_4\*(R" and \*(L"fips186_2\*(R" key generation. -.SS "\s-1EC\s0 Parameter Generation Options" -.IX Subsection "EC Parameter Generation Options" -The \s-1EC\s0 parameter generation options are the same as for key generation. See -\&\*(L"\s-1EC\s0 Key Generation Options\*(R" above. -.SH "NOTES" -.IX Header "NOTES" -The use of the genpkey program is encouraged over the algorithm specific -utilities because additional algorithm options and \s-1ENGINE\s0 provided algorithms -can be used. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Generate an \s-1RSA\s0 private key using default parameters: -.PP -.Vb 1 -\& openssl genpkey \-algorithm RSA \-out key.pem -.Ve -.PP -Encrypt output private key using 128 bit \s-1AES\s0 and the passphrase \*(L"hello\*(R": -.PP -.Vb 1 -\& openssl genpkey \-algorithm RSA \-out key.pem \-aes\-128\-cbc \-pass pass:hello -.Ve -.PP -Generate a 2048 bit \s-1RSA\s0 key using 3 as the public exponent: -.PP -.Vb 2 -\& openssl genpkey \-algorithm RSA \-out key.pem \e -\& \-pkeyopt rsa_keygen_bits:2048 \-pkeyopt rsa_keygen_pubexp:3 -.Ve -.PP -Generate 2048 bit \s-1DSA\s0 parameters that can be validated: The output values for -gindex and seed are required for key validation purposes and are not saved to -the output pem file). -.PP -.Vb 2 -\& openssl genpkey \-genparam \-algorithm DSA \-out dsap.pem \-pkeyopt pbits:2048 \e -\& \-pkeyopt qbits:224 \-pkeyopt digest:SHA256 \-pkeyopt gindex:1 \-text -.Ve -.PP -Generate \s-1DSA\s0 key from parameters: -.PP -.Vb 1 -\& openssl genpkey \-paramfile dsap.pem \-out dsakey.pem -.Ve -.PP -Generate 4096 bit \s-1DH\s0 Key using safe prime group ffdhe4096: -.PP -.Vb 1 -\& openssl genpkey \-algorithm DH \-out dhkey.pem \-pkeyopt group:ffdhe4096 -.Ve -.PP -Generate 2048 bit X9.42 \s-1DH\s0 key with 256 bit subgroup using \s-1RFC5114\s0 group3: -.PP -.Vb 1 -\& openssl genpkey \-algorithm DHX \-out dhkey.pem \-pkeyopt dh_rfc5114:3 -.Ve -.PP -Generate a \s-1DH\s0 key using a \s-1DH\s0 parameters file: -.PP -.Vb 1 -\& openssl genpkey \-paramfile dhp.pem \-out dhkey.pem -.Ve -.PP -Output \s-1DH\s0 parameters for safe prime group ffdhe2048: -.PP -.Vb 1 -\& openssl genpkey \-genparam \-algorithm DH \-out dhp.pem \-pkeyopt group:ffdhe2048 -.Ve -.PP -Output 2048 bit X9.42 \s-1DH\s0 parameters with 224 bit subgroup using \s-1RFC5114\s0 group2: -.PP -.Vb 1 -\& openssl genpkey \-genparam \-algorithm DHX \-out dhp.pem \-pkeyopt dh_rfc5114:2 -.Ve -.PP -Output 2048 bit X9.42 \s-1DH\s0 parameters with 224 bit subgroup using \s-1FIP186\-4\s0 keygen: -.PP -.Vb 3 -\& openssl genpkey \-genparam \-algorithm DHX \-out dhp.pem \-text \e -\& \-pkeyopt pbits:2048 \-pkeyopt qbits:224 \-pkeyopt digest:SHA256 \e -\& \-pkeyopt gindex:1 \-pkeyopt dh_paramgen_type:2 -.Ve -.PP -Output 1024 bit X9.42 \s-1DH\s0 parameters with 160 bit subgroup using \s-1FIP186\-2\s0 keygen: -.PP -.Vb 3 -\& openssl genpkey \-genparam \-algorithm DHX \-out dhp.pem \-text \e -\& \-pkeyopt pbits:1024 \-pkeyopt qbits:160 \-pkeyopt digest:SHA1 \e -\& \-pkeyopt gindex:1 \-pkeyopt dh_paramgen_type:1 -.Ve -.PP -Output 2048 bit \s-1DH\s0 parameters: -.PP -.Vb 2 -\& openssl genpkey \-genparam \-algorithm DH \-out dhp.pem \e -\& \-pkeyopt dh_paramgen_prime_len:2048 -.Ve -.PP -Output 2048 bit \s-1DH\s0 parameters using a generator: -.PP -.Vb 3 -\& openssl genpkey \-genparam \-algorithm DH \-out dhpx.pem \e -\& \-pkeyopt dh_paramgen_prime_len:2048 \e -\& \-pkeyopt dh_paramgen_type:1 -.Ve -.PP -Generate \s-1EC\s0 parameters: -.PP -.Vb 3 -\& openssl genpkey \-genparam \-algorithm EC \-out ecp.pem \e -\& \-pkeyopt ec_paramgen_curve:secp384r1 \e -\& \-pkeyopt ec_param_enc:named_curve -.Ve -.PP -Generate \s-1EC\s0 key from parameters: -.PP -.Vb 1 -\& openssl genpkey \-paramfile ecp.pem \-out eckey.pem -.Ve -.PP -Generate \s-1EC\s0 key directly: -.PP -.Vb 3 -\& openssl genpkey \-algorithm EC \-out eckey.pem \e -\& \-pkeyopt ec_paramgen_curve:P\-384 \e -\& \-pkeyopt ec_param_enc:named_curve -.Ve -.PP -Generate an X25519 private key: -.PP -.Vb 1 -\& openssl genpkey \-algorithm X25519 \-out xkey.pem -.Ve -.PP -Generate an \s-1ED448\s0 private key: -.PP -.Vb 1 -\& openssl genpkey \-algorithm ED448 \-out xkey.pem -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -The ability to use \s-1NIST\s0 curve names, and to generate an \s-1EC\s0 key directly, -were added in OpenSSL 1.0.2. -The ability to generate X25519 keys was added in OpenSSL 1.1.0. -The ability to generate X448, \s-1ED25519\s0 and \s-1ED448\s0 keys was added in OpenSSL 1.1.1. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-genrsa.1ossl b/openssl-install/share/man/man1/openssl-genrsa.1ossl deleted file mode 100644 index a2daa0ed..00000000 --- a/openssl-install/share/man/man1/openssl-genrsa.1ossl +++ /dev/null @@ -1,262 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-GENRSA 1ossl" -.TH OPENSSL-GENRSA 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-genrsa \- generate an RSA private key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBgenrsa\fR -[\fB\-help\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-aes128\fR] -[\fB\-aes192\fR] -[\fB\-aes256\fR] -[\fB\-aria128\fR] -[\fB\-aria192\fR] -[\fB\-aria256\fR] -[\fB\-camellia128\fR] -[\fB\-camellia192\fR] -[\fB\-camellia256\fR] -[\fB\-des\fR] -[\fB\-des3\fR] -[\fB\-idea\fR] -[\fB\-F4\fR] -[\fB\-f4\fR] -[\fB\-3\fR] -[\fB\-primes\fR \fInum\fR] -[\fB\-verbose\fR] -[\fB\-quiet\fR] -[\fB\-traditional\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fBnumbits\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command generates an \s-1RSA\s0 private key. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Output the key to the specified file. If this argument is not specified then -standard output is used. -.IP "\fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passout arg" -The output file password source. For more information about the format -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-aes128\fR, \fB\-aes192\fR, \fB\-aes256\fR, \fB\-aria128\fR, \fB\-aria192\fR, \fB\-aria256\fR, \fB\-camellia128\fR, \fB\-camellia192\fR, \fB\-camellia256\fR, \fB\-des\fR, \fB\-des3\fR, \fB\-idea\fR" 4 -.IX Item "-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea" -These options encrypt the private key with specified -cipher before outputting it. If none of these options is -specified no encryption is used. If encryption is used a pass phrase is prompted -for if it is not supplied via the \fB\-passout\fR argument. -.IP "\fB\-F4\fR, \fB\-f4\fR, \fB\-3\fR" 4 -.IX Item "-F4, -f4, -3" -The public exponent to use, either 65537 or 3. The default is 65537. -The \fB\-3\fR option has been deprecated. -.IP "\fB\-primes\fR \fInum\fR" 4 -.IX Item "-primes num" -Specify the number of primes to use while generating the \s-1RSA\s0 key. The \fInum\fR -parameter must be a positive integer that is greater than 1 and less than 16. -If \fInum\fR is greater than 2, then the generated key is called a 'multi\-prime' -\&\s-1RSA\s0 key, which is defined in \s-1RFC 8017.\s0 -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Print extra details about the operations being performed. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Print fewer details about the operations being performed, which may -be handy during batch scripts and pipelines. -.IP "\fB\-traditional\fR" 4 -.IX Item "-traditional" -Write the key using the traditional PKCS#1 format instead of the PKCS#8 format. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fBnumbits\fR" 4 -.IX Item "numbits" -The size of the private key to generate in bits. This must be the last option -specified. The default is 2048 and values less than 512 are not allowed. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1RSA\s0 private key generation essentially involves the generation of two or more -prime numbers. When generating a private key various symbols will be output to -indicate the progress of the generation. A \fB.\fR represents each number which -has passed an initial sieve test, \fB+\fR means a number has passed a single -round of the Miller-Rabin primality test, \fB*\fR means the current prime starts -a regenerating progress due to some failed tests. A newline means that the number -has passed all the prime tests (the actual number depends on the key size). -.PP -Because key generation is a random process the time taken to generate a key -may vary somewhat. But in general, more primes lead to less generation time -of a key. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-info.1ossl b/openssl-install/share/man/man1/openssl-info.1ossl deleted file mode 100644 index 0789c74b..00000000 --- a/openssl-install/share/man/man1/openssl-info.1ossl +++ /dev/null @@ -1,214 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-INFO 1ossl" -.TH OPENSSL-INFO 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-info \- print OpenSSL built\-in information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl info\fR -[\fB\-help\fR] -[\fB\-configdir\fR] -[\fB\-enginesdir\fR] -[\fB\-modulesdir\fR ] -[\fB\-dsoext\fR] -[\fB\-dirnamesep\fR] -[\fB\-listsep\fR] -[\fB\-seeds\fR] -[\fB\-cpusettings\fR] -[\fB\-windowscontext\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to print out information about OpenSSL. -The information is written exactly as it is with no extra text, which -makes useful for scripts. -.PP -As a consequence, only one item may be chosen for each run of this -command. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-configdir\fR" 4 -.IX Item "-configdir" -Outputs the default directory for OpenSSL configuration files. -.IP "\fB\-enginesdir\fR" 4 -.IX Item "-enginesdir" -Outputs the default directory for OpenSSL engine modules. -.IP "\fB\-modulesdir\fR" 4 -.IX Item "-modulesdir" -Outputs the default directory for OpenSSL dynamically loadable modules -other than engine modules. -.IP "\fB\-dsoext\fR" 4 -.IX Item "-dsoext" -Outputs the \s-1DSO\s0 extension OpenSSL uses. -.IP "\fB\-dirnamesep\fR" 4 -.IX Item "-dirnamesep" -Outputs the separator character between a directory specification and -a filename. -Note that on some operating systems, this is not the same as the -separator between directory elements. -.IP "\fB\-listsep\fR" 4 -.IX Item "-listsep" -Outputs the OpenSSL list separator character. -This is typically used to construct \f(CW$PATH\fR (\f(CW\*(C`%PATH%\*(C'\fR on Windows) -style lists. -.IP "\fB\-seeds\fR" 4 -.IX Item "-seeds" -Outputs the randomness seed sources. -.IP "\fB\-cpusettings\fR" 4 -.IX Item "-cpusettings" -Outputs the OpenSSL \s-1CPU\s0 settings info. -.IP "\fB\-windowscontext\fR" 4 -.IX Item "-windowscontext" -Outputs the Windows install context. -.SH "HISTORY" -.IX Header "HISTORY" -This command was added in OpenSSL 3.0. -.PP -The \fB\-windowscontext\fR option was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-kdf.1ossl b/openssl-install/share/man/man1/openssl-kdf.1ossl deleted file mode 100644 index 46c0e074..00000000 --- a/openssl-install/share/man/man1/openssl-kdf.1ossl +++ /dev/null @@ -1,358 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-KDF 1ossl" -.TH OPENSSL-KDF 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-kdf \- perform Key Derivation Function operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl kdf\fR -[\fB\-help\fR] -[\fB\-cipher\fR] -[\fB\-digest\fR] -[\fB\-mac\fR] -[\fB\-kdfopt\fR \fInm\fR:\fIv\fR] -[\fB\-keylen\fR \fInum\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-binary\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -\&\fIkdf_name\fR -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The key derivation functions generate a derived key from either a secret or -password. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print a usage message. -.IP "\fB\-keylen\fR \fInum\fR" 4 -.IX Item "-keylen num" -The output size of the derived key. This field is required. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Filename to output to, or standard output by default. -.IP "\fB\-binary\fR" 4 -.IX Item "-binary" -Output the derived key in binary form. Uses hexadecimal text format if not specified. -.IP "\fB\-cipher\fR \fIname\fR" 4 -.IX Item "-cipher name" -Specify the cipher to be used by the \s-1KDF.\s0 -Not all KDFs require a cipher and it is an error to use this option in such -cases. -.IP "\fB\-digest\fR \fIname\fR" 4 -.IX Item "-digest name" -Specify the digest to be used by the \s-1KDF.\s0 -Not all KDFs require a digest and it is an error to use this option in such -cases. -To see the list of supported digests, use \f(CW\*(C`openssl list \-digest\-commands\*(C'\fR. -.IP "\fB\-mac\fR \fIname\fR" 4 -.IX Item "-mac name" -Specify the \s-1MAC\s0 to be used by the \s-1KDF.\s0 -Not all KDFs require a \s-1MAC\s0 and it is an error to use this option in such -cases. -.IP "\fB\-kdfopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-kdfopt nm:v" -Passes options to the \s-1KDF\s0 algorithm. -A comprehensive list of parameters can be found in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -Common parameter names used by \fBEVP_KDF_CTX_set_params()\fR are: -.RS 4 -.IP "\fBkey:\fR\fIstring\fR" 4 -.IX Item "key:string" -Specifies the secret key as an alphanumeric string (use if the key contains -printable characters only). -The string length must conform to any restrictions of the \s-1KDF\s0 algorithm. -A key must be specified for most \s-1KDF\s0 algorithms. -.IP "\fBhexkey:\fR\fIstring\fR" 4 -.IX Item "hexkey:string" -Alternative to the \fBkey:\fR option where -the secret key is specified in hexadecimal form (two hex digits per byte). -.IP "\fBpass:\fR\fIstring\fR" 4 -.IX Item "pass:string" -Specifies the password as an alphanumeric string (use if the password contains -printable characters only). -The password must be specified for \s-1PBKDF2\s0 and scrypt. -.IP "\fBhexpass:\fR\fIstring\fR" 4 -.IX Item "hexpass:string" -Alternative to the \fBpass:\fR option where -the password is specified in hexadecimal form (two hex digits per byte). -.IP "\fBsalt:\fR\fIstring\fR" 4 -.IX Item "salt:string" -Specifies a non-secret unique cryptographic salt as an alphanumeric string -(use if it contains printable characters only). -The length must conform to any restrictions of the \s-1KDF\s0 algorithm. -A salt parameter is required for several \s-1KDF\s0 algorithms, -such as \s-1\fBEVP_KDF\-PBKDF2\s0\fR\|(7). -.IP "\fBhexsalt:\fR\fIstring\fR" 4 -.IX Item "hexsalt:string" -Alternative to the \fBsalt:\fR option where -the salt is specified in hexadecimal form (two hex digits per byte). -.IP "\fBinfo:\fR\fIstring\fR" 4 -.IX Item "info:string" -Some \s-1KDF\s0 implementations, such as \s-1\fBEVP_KDF\-HKDF\s0\fR\|(7), take an 'info' parameter -for binding the derived key material -to application\- and context-specific information. -Specifies the info, fixed info, other info or shared info argument -as an alphanumeric string (use if it contains printable characters only). -The length must conform to any restrictions of the \s-1KDF\s0 algorithm. -.IP "\fBhexinfo:\fR\fIstring\fR" 4 -.IX Item "hexinfo:string" -Alternative to the \fBinfo:\fR option where -the info is specified in hexadecimal form (two hex digits per byte). -.IP "\fBdigest:\fR\fIstring\fR" 4 -.IX Item "digest:string" -This option is identical to the \fB\-digest\fR option. -.IP "\fBcipher:\fR\fIstring\fR" 4 -.IX Item "cipher:string" -This option is identical to the \fB\-cipher\fR option. -.IP "\fBmac:\fR\fIstring\fR" 4 -.IX Item "mac:string" -This option is identical to the \fB\-mac\fR option. -.RE -.RS 4 -.RE -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fIkdf_name\fR" 4 -.IX Item "kdf_name" -Specifies the name of a supported \s-1KDF\s0 algorithm which will be used. -The supported algorithms names include \s-1TLS1\-PRF, HKDF, SSKDF, PBKDF2, -SSHKDF, X942KDF\-ASN1, X942KDF\-CONCAT, X963KDF\s0 and \s-1SCRYPT.\s0 -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Use \s-1TLS1\-PRF\s0 to create a hex-encoded derived key from a secret key and seed: -.PP -.Vb 2 -\& openssl kdf \-keylen 16 \-kdfopt digest:SHA2\-256 \-kdfopt key:secret \e -\& \-kdfopt seed:seed TLS1\-PRF -.Ve -.PP -Use \s-1HKDF\s0 to create a hex-encoded derived key from a secret key, salt and info: -.PP -.Vb 2 -\& openssl kdf \-keylen 10 \-kdfopt digest:SHA2\-256 \-kdfopt key:secret \e -\& \-kdfopt salt:salt \-kdfopt info:label HKDF -.Ve -.PP -Use \s-1SSKDF\s0 with \s-1KMAC\s0 to create a hex-encoded derived key from a secret key, salt and info: -.PP -.Vb 3 -\& openssl kdf \-keylen 64 \-kdfopt mac:KMAC\-128 \-kdfopt maclen:20 \e -\& \-kdfopt hexkey:b74a149a161545 \-kdfopt hexinfo:348a37a2 \e -\& \-kdfopt hexsalt:3638271ccd68a2 SSKDF -.Ve -.PP -Use \s-1SSKDF\s0 with \s-1HMAC\s0 to create a hex-encoded derived key from a secret key, salt and info: -.PP -.Vb 3 -\& openssl kdf \-keylen 16 \-kdfopt mac:HMAC \-kdfopt digest:SHA2\-256 \e -\& \-kdfopt hexkey:b74a149a \-kdfopt hexinfo:348a37a2 \e -\& \-kdfopt hexsalt:3638271c SSKDF -.Ve -.PP -Use \s-1SSKDF\s0 with Hash to create a hex-encoded derived key from a secret key, salt and info: -.PP -.Vb 3 -\& openssl kdf \-keylen 14 \-kdfopt digest:SHA2\-256 \e -\& \-kdfopt hexkey:6dbdc23f045488 \e -\& \-kdfopt hexinfo:a1b2c3d4 SSKDF -.Ve -.PP -Use \s-1SSHKDF\s0 to create a hex-encoded derived key from a secret key, hash and session_id: -.PP -.Vb 5 -\& openssl kdf \-keylen 16 \-kdfopt digest:SHA2\-256 \e -\& \-kdfopt hexkey:0102030405 \e -\& \-kdfopt hexxcghash:06090A \e -\& \-kdfopt hexsession_id:01020304 \e -\& \-kdfopt type:A SSHKDF -.Ve -.PP -Use \s-1PBKDF2\s0 to create a hex-encoded derived key from a password and salt: -.PP -.Vb 2 -\& openssl kdf \-keylen 32 \-kdfopt digest:SHA256 \-kdfopt pass:password \e -\& \-kdfopt salt:salt \-kdfopt iter:2 PBKDF2 -.Ve -.PP -Use scrypt to create a hex-encoded derived key from a password and salt: -.PP -.Vb 3 -\& openssl kdf \-keylen 64 \-kdfopt pass:password \-kdfopt salt:NaCl \e -\& \-kdfopt n:1024 \-kdfopt r:8 \-kdfopt p:16 \e -\& \-kdfopt maxmem_bytes:10485760 SCRYPT -.Ve -.SH "NOTES" -.IX Header "NOTES" -The \s-1KDF\s0 mechanisms that are available will depend on the options -used when building OpenSSL. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkeyutl\fR\|(1), -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\s-1\fBEVP_KDF\-SCRYPT\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-TLS1_PRF\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-PBKDF2\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-HKDF\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-SS\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-SSHKDF\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-X942\-ASN1\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-X942\-CONCAT\s0\fR\|(7), -\&\s-1\fBEVP_KDF\-X963\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -Added in OpenSSL 3.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-list.1ossl b/openssl-install/share/man/man1/openssl-list.1ossl deleted file mode 100644 index b20dc160..00000000 --- a/openssl-install/share/man/man1/openssl-list.1ossl +++ /dev/null @@ -1,388 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-LIST 1ossl" -.TH OPENSSL-LIST 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-list \- list algorithms and features -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl list\fR -[\fB\-help\fR] -[\fB\-verbose\fR] -[\fB\-select\fR \fIname\fR] -[\fB\-1\fR] -[\fB\-all\-algorithms\fR] -[\fB\-commands\fR] -[\fB\-standard\-commands\fR] -[\fB\-digest\-algorithms\fR] -[\fB\-digest\-commands\fR] -[\fB\-kdf\-algorithms\fR] -[\fB\-mac\-algorithms\fR] -[\fB\-random\-instances\fR] -[\fB\-random\-generators\fR] -[\fB\-cipher\-algorithms\fR] -[\fB\-cipher\-commands\fR] -[\fB\-encoders\fR] -[\fB\-decoders\fR] -[\fB\-key\-managers\fR] -[\fB\-key\-exchange\-algorithms\fR] -[\fB\-kem\-algorithms\fR] -[\fB\-signature\-algorithms\fR] -[\fB\-tls\-signature\-algorithms\fR] -[\fB\-asymcipher\-algorithms\fR] -[\fB\-public\-key\-algorithms\fR] -[\fB\-public\-key\-methods\fR] -[\fB\-store\-loaders\fR] -[\fB\-providers\fR] -[\fB\-engines\fR] -[\fB\-disabled\fR] -[\fB\-objects\fR] -[\fB\-options\fR \fIcommand\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to generate list of algorithms or disabled -features. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Display a usage message. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Displays extra information. -The options below where verbosity applies say a bit more about what that means. -.IP "\fB\-select\fR \fIname\fR" 4 -.IX Item "-select name" -Only list algorithms that match this name. -.IP "\fB\-1\fR" 4 -.IX Item "-1" -List the commands, digest-commands, or cipher-commands in a single column. -If used, this option must be given first. -.IP "\fB\-all\-algorithms\fR" 4 -.IX Item "-all-algorithms" -Display lists of all algorithms. These include: -.RS 4 -.IP "Asymmetric ciphers" 4 -.IX Item "Asymmetric ciphers" -.PD 0 -.IP "Decoders" 4 -.IX Item "Decoders" -.IP "Digests" 4 -.IX Item "Digests" -.IP "Encoders" 4 -.IX Item "Encoders" -.IP "Key derivation algorithms (\s-1KDF\s0)" 4 -.IX Item "Key derivation algorithms (KDF)" -.IP "Key encapsulation methods (\s-1KEM\s0)" 4 -.IX Item "Key encapsulation methods (KEM)" -.IP "Key exchange algorithms (\s-1KEX\s0)" 4 -.IX Item "Key exchange algorithms (KEX)" -.IP "Key managers" 4 -.IX Item "Key managers" -.IP "Message authentication code algorithms (\s-1MAC\s0)" 4 -.IX Item "Message authentication code algorithms (MAC)" -.IP "Random number generators (\s-1RNG, DRBG\s0)" 4 -.IX Item "Random number generators (RNG, DRBG)" -.IP "Signature algorithms" 4 -.IX Item "Signature algorithms" -.IP "Store loaders" 4 -.IX Item "Store loaders" -.IP "Symmetric ciphers" 4 -.IX Item "Symmetric ciphers" -.RE -.RS 4 -.RE -.IP "\fB\-commands\fR" 4 -.IX Item "-commands" -.PD -Display a list of standard commands. -.IP "\fB\-standard\-commands\fR" 4 -.IX Item "-standard-commands" -List of standard commands. -.IP "\fB\-digest\-commands\fR" 4 -.IX Item "-digest-commands" -This option is deprecated. Use \fBdigest-algorithms\fR instead. -.Sp -Display a list of message digest commands, which are typically used -as input to the \fBopenssl\-dgst\fR\|(1) or \fBopenssl\-speed\fR\|(1) commands. -.IP "\fB\-cipher\-commands\fR" 4 -.IX Item "-cipher-commands" -This option is deprecated. Use \fBcipher-algorithms\fR instead. -.Sp -Display a list of cipher commands, which are typically used as input -to the \fBopenssl\-enc\fR\|(1) or \fBopenssl\-speed\fR\|(1) commands. -.IP "\fB\-cipher\-algorithms\fR, \fB\-digest\-algorithms\fR, \fB\-kdf\-algorithms\fR, \fB\-mac\-algorithms\fR," 4 -.IX Item "-cipher-algorithms, -digest-algorithms, -kdf-algorithms, -mac-algorithms," -Display a list of symmetric cipher, digest, kdf and mac algorithms. -See \*(L"Display of algorithm names\*(R" for a description of how names are -displayed. -.Sp -In verbose mode, the algorithms provided by a provider will get additional -information on what parameters each implementation supports. -.IP "\fB\-random\-instances\fR" 4 -.IX Item "-random-instances" -List the primary, public and private random number generator details. -.IP "\fB\-random\-generators\fR" 4 -.IX Item "-random-generators" -Display a list of random number generators. -See \*(L"Display of algorithm names\*(R" for a description of how names are -displayed. -.IP "\fB\-encoders\fR" 4 -.IX Item "-encoders" -Display a list of encoders. -See \*(L"Display of algorithm names\*(R" for a description of how names are -displayed. -.Sp -In verbose mode, the algorithms provided by a provider will get additional -information on what parameters each implementation supports. -.IP "\fB\-decoders\fR" 4 -.IX Item "-decoders" -Display a list of decoders. -See \*(L"Display of algorithm names\*(R" for a description of how names are -displayed. -.Sp -In verbose mode, the algorithms provided by a provider will get additional -information on what parameters each implementation supports. -.IP "\fB\-public\-key\-algorithms\fR" 4 -.IX Item "-public-key-algorithms" -Display a list of public key algorithms, with each algorithm as -a block of multiple lines, all but the first are indented. -The options \fBkey-exchange-algorithms\fR, \fBkem-algorithms\fR, -\&\fBsignature-algorithms\fR, and \fBasymcipher-algorithms\fR will display similar info. -.IP "\fB\-public\-key\-methods\fR" 4 -.IX Item "-public-key-methods" -Display a list of public key methods. -.IP "\fB\-key\-managers\fR" 4 -.IX Item "-key-managers" -Display a list of key managers. -.IP "\fB\-key\-exchange\-algorithms\fR" 4 -.IX Item "-key-exchange-algorithms" -Display a list of key exchange algorithms. -.IP "\fB\-kem\-algorithms\fR" 4 -.IX Item "-kem-algorithms" -Display a list of key encapsulation algorithms. -.IP "\fB\-signature\-algorithms\fR" 4 -.IX Item "-signature-algorithms" -Display a list of signature algorithms. -.IP "\fB\-tls\-signature\-algorithms\fR" 4 -.IX Item "-tls-signature-algorithms" -Display the list of signature algorithms available for \s-1TLS\s0 handshakes -made available by all currently active providers. -The output format is colon delimited in a form directly usable in -\&\fBSSL_CONF_cmd\fR\|(3) specifying SignatureAlgorithms. -.IP "\fB\-asymcipher\-algorithms\fR" 4 -.IX Item "-asymcipher-algorithms" -Display a list of asymmetric cipher algorithms. -.IP "\fB\-store\-loaders\fR" 4 -.IX Item "-store-loaders" -Display a list of store loaders. -.IP "\fB\-providers\fR" 4 -.IX Item "-providers" -Display a list of all loaded providers with their names, version and status. -.Sp -In verbose mode, the full version and all provider parameters will additionally -be displayed. -.IP "\fB\-engines\fR" 4 -.IX Item "-engines" -This option is deprecated. -.Sp -Display a list of loaded engines. -.IP "\fB\-disabled\fR" 4 -.IX Item "-disabled" -Display a list of disabled features, those that were compiled out -of the installation. -.IP "\fB\-objects\fR" 4 -.IX Item "-objects" -Display a list of built in objects, i.e. OIDs with names. They're listed in the -format described in \*(L"\s-1ASN1\s0 Object Configuration Module\*(R" in \fBconfig\fR\|(5). -.IP "\fB\-options\fR \fIcommand\fR" 4 -.IX Item "-options command" -Output a two-column list of the options accepted by the specified \fIcommand\fR. -The first is the option name, and the second is a one-character indication -of what type of parameter it takes, if any. -This is an internal option, used for checking that the documentation -is complete. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SS "Display of algorithm names" -.IX Subsection "Display of algorithm names" -Algorithm names may be displayed in one of two manners: -.IP "Legacy implementations" 4 -.IX Item "Legacy implementations" -Legacy implementations will simply display the main name of the -algorithm on a line of its own, or in the form \f(CW\*(C`> to show -that \f(CW\*(C`foo\*(C'\fR is an alias for the main name, \f(CW\*(C`bar\*(C'\fR -.IP "Provided implementations" 4 -.IX Item "Provided implementations" -Implementations from a provider are displayed like this if the -implementation is labeled with a single name: -.Sp -.Vb 1 -\& foo @ bar -.Ve -.Sp -or like this if it's labeled with multiple names: -.Sp -.Vb 1 -\& { foo1, foo2 } @bar -.Ve -.Sp -In both cases, \f(CW\*(C`bar\*(C'\fR is the name of the provider. -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engines\fR, \fB\-digest\-commands\fR, and \fB\-cipher\-commands\fR options -were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-mac.1ossl b/openssl-install/share/man/man1/openssl-mac.1ossl deleted file mode 100644 index 2859177c..00000000 --- a/openssl-install/share/man/man1/openssl-mac.1ossl +++ /dev/null @@ -1,305 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-MAC 1ossl" -.TH OPENSSL-MAC 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-mac \- perform Message Authentication Code operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl mac\fR -[\fB\-help\fR] -[\fB\-cipher\fR] -[\fB\-digest\fR] -[\fB\-macopt\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-binary\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -\&\fImac_name\fR -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The message authentication code functions output the \s-1MAC\s0 of a supplied input -file. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print a usage message. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -Input filename to calculate a \s-1MAC\s0 for, or standard input by default. -Standard input is used if the filename is '\-'. -Files and standard input are expected to be in binary format. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Filename to output to, or standard output by default. -.IP "\fB\-binary\fR" 4 -.IX Item "-binary" -Output the \s-1MAC\s0 in binary form. Uses hexadecimal text format if not specified. -.IP "\fB\-cipher\fR \fIname\fR" 4 -.IX Item "-cipher name" -Used by \s-1CMAC\s0 and \s-1GMAC\s0 to specify the cipher algorithm. -For \s-1CMAC\s0 it should be a \s-1CBC\s0 mode cipher e.g. \s-1AES\-128\-CBC.\s0 -For \s-1GMAC\s0 it should be a \s-1GCM\s0 mode cipher e.g. \s-1AES\-128\-GCM.\s0 -.IP "\fB\-digest\fR \fIname\fR" 4 -.IX Item "-digest name" -Used by \s-1HMAC\s0 as an alphanumeric string (use if the key contains printable -characters only). -The string length must conform to any restrictions of the \s-1MAC\s0 algorithm. -To see the list of supported digests, use \f(CW\*(C`openssl list \-digest\-commands\*(C'\fR. -.IP "\fB\-macopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-macopt nm:v" -Passes options to the \s-1MAC\s0 algorithm. -A comprehensive list of controls can be found in the \s-1EVP_MAC\s0 implementation -documentation. -Common parameter names used by \fBEVP_MAC_CTX_get_params()\fR are: -.RS 4 -.IP "\fBkey:\fR\fIstring\fR" 4 -.IX Item "key:string" -Specifies the \s-1MAC\s0 key as an alphanumeric string (use if the key contains -printable characters only). -The string length must conform to any restrictions of the \s-1MAC\s0 algorithm. -A key must be specified for every \s-1MAC\s0 algorithm. -.IP "\fBhexkey:\fR\fIstring\fR" 4 -.IX Item "hexkey:string" -Specifies the \s-1MAC\s0 key in hexadecimal form (two hex digits per byte). -The key length must conform to any restrictions of the \s-1MAC\s0 algorithm. -A key must be specified for every \s-1MAC\s0 algorithm. -.IP "\fBiv:\fR\fIstring\fR" 4 -.IX Item "iv:string" -Used by \s-1GMAC\s0 to specify an \s-1IV\s0 as an alphanumeric string (use if the \s-1IV\s0 contains -printable characters only). -.IP "\fBhexiv:\fR\fIstring\fR" 4 -.IX Item "hexiv:string" -Used by \s-1GMAC\s0 to specify an \s-1IV\s0 in hexadecimal form (two hex digits per byte). -.IP "\fBsize:\fR\fIint\fR" 4 -.IX Item "size:int" -Used by \s-1KMAC128\s0 or \s-1KMAC256\s0 to specify an output length. -The default sizes are 32 or 64 bytes respectively. -.IP "\fBcustom:\fR\fIstring\fR" 4 -.IX Item "custom:string" -Used by \s-1KMAC128\s0 or \s-1KMAC256\s0 to specify a customization string. -The default is the empty string "". -.IP "\fBdigest:\fR\fIstring\fR" 4 -.IX Item "digest:string" -This option is identical to the \fB\-digest\fR option. -.IP "\fBcipher:\fR\fIstring\fR" 4 -.IX Item "cipher:string" -This option is identical to the \fB\-cipher\fR option. -.RE -.RS 4 -.RE -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fImac_name\fR" 4 -.IX Item "mac_name" -Specifies the name of a supported \s-1MAC\s0 algorithm which will be used. -To see the list of supported \s-1MAC\s0's use the command \f(CW\*(C`openssl list -\&\-mac\-algorithms\*(C'\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To create a hex-encoded \s-1HMAC\-SHA1 MAC\s0 of a file and write to stdout: -.PP -.Vb 3 -\& openssl mac \-digest SHA1 \e -\& \-macopt hexkey:000102030405060708090A0B0C0D0E0F10111213 \e -\& \-in msg.bin HMAC -.Ve -.PP -To create a SipHash \s-1MAC\s0 from a file with a binary file output: -.PP -.Vb 2 -\& openssl mac \-macopt hexkey:000102030405060708090A0B0C0D0E0F \e -\& \-in msg.bin \-out out.bin \-binary SipHash -.Ve -.PP -To create a hex-encoded \s-1CMAC\-AES\-128\-CBC MAC\s0 from a file: -.PP -.Vb 3 -\& openssl mac \-cipher AES\-128\-CBC \e -\& \-macopt hexkey:77A77FAF290C1FA30C683DF16BA7A77B \e -\& \-in msg.bin CMAC -.Ve -.PP -To create a hex-encoded \s-1KMAC128 MAC\s0 from a file with a Customisation String -\&'Tag' and output length of 16: -.PP -.Vb 2 -\& openssl mac \-macopt custom:Tag \-macopt hexkey:40414243444546 \e -\& \-macopt size:16 \-in msg.bin KMAC128 -.Ve -.PP -To create a hex-encoded \s-1GMAC\-AES\-128\-GCM\s0 with a \s-1IV\s0 from a file: -.PP -.Vb 2 -\& openssl mac \-cipher AES\-128\-GCM \-macopt hexiv:E0E00F19FED7BA0136A797F3 \e -\& \-macopt hexkey:77A77FAF290C1FA30C683DF16BA7A77B \-in msg.bin GMAC -.Ve -.SH "NOTES" -.IX Header "NOTES" -The \s-1MAC\s0 mechanisms that are available will depend on the options -used when building OpenSSL. -Use \f(CW\*(C`openssl list \-mac\-algorithms\*(C'\fR to list them. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\s-1\fBEVP_MAC\s0\fR\|(3), -\&\s-1\fBEVP_MAC\-CMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-GMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-HMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-KMAC\s0\fR\|(7), -\&\fBEVP_MAC\-Siphash\fR\|(7), -\&\fBEVP_MAC\-Poly1305\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-namedisplay-options.1ossl b/openssl-install/share/man/man1/openssl-namedisplay-options.1ossl deleted file mode 100644 index 2fdeccac..00000000 --- a/openssl-install/share/man/man1/openssl-namedisplay-options.1ossl +++ /dev/null @@ -1,286 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-NAMEDISPLAY-OPTIONS 1ossl" -.TH OPENSSL-NAMEDISPLAY-OPTIONS 1ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-namedisplay\-options \- Distinguished name display options -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR -\&\fIcommand\fR -[ \fIoptions\fR ... ] -[ \fIparameters\fR ... ] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL provides fine-grain control over how the subject and issuer \s-1DN\s0's are -displayed. -This is specified by using the \fB\-nameopt\fR option, which takes a -comma-separated list of options from the following set. -An option may be preceded by a minus sign, \f(CW\*(C`\-\*(C'\fR, to turn it off. -The first four option arguments are the most commonly used. -.PP -The default value is -\&\f(CW\*(C`esc_ctrl,utf8,dump_unknown,dump_der,sep_comma_plus_space,sname\*(C'\fR. -.SH "OPTIONS" -.IX Header "OPTIONS" -.SS "Name Format Option Arguments" -.IX Subsection "Name Format Option Arguments" -The \s-1DN\s0 output format can be fine tuned with the following flags. -.IP "\fBcompat\fR" 4 -.IX Item "compat" -Display the name using an old format from previous OpenSSL versions. -.IP "\fB\s-1RFC2253\s0\fR" 4 -.IX Item "RFC2253" -Display the name using the format defined in \s-1RFC 2253.\s0 -It is equivalent to \fBesc_2253\fR, \fBesc_ctrl\fR, \fBesc_msb\fR, \fButf8\fR, -\&\fBdump_nostr\fR, \fBdump_unknown\fR, \fBdump_der\fR, \fBsep_comma_plus\fR, \fBdn_rev\fR -and \fBsname\fR. -.IP "\fBoneline\fR" 4 -.IX Item "oneline" -Display the name in one line, using a format that is more readable -\&\s-1RFC 2253.\s0 -It is equivalent to \fBesc_2253\fR, \fBesc_ctrl\fR, \fBesc_msb\fR, \fButf8\fR, -\&\fBdump_nostr\fR, \fBdump_der\fR, \fBuse_quote\fR, \fBsep_comma_plus_space\fR, -\&\fBspace_eq\fR and \fBsname\fR options. -.IP "\fBmultiline\fR" 4 -.IX Item "multiline" -Display the name using multiple lines. -It is equivalent to \fBesc_ctrl\fR, \fBesc_msb\fR, \fBsep_multiline\fR, \fBspace_eq\fR, -\&\fBlname\fR and \fBalign\fR. -.IP "\fBesc_2253\fR" 4 -.IX Item "esc_2253" -Escape the \*(L"special\*(R" characters in a field, as required by \s-1RFC 2253.\s0 -That is, any of the characters \f(CW\*(C`,+"<>;\*(C'\fR, \f(CW\*(C`#\*(C'\fR at the beginning of -a string and leading or trailing spaces. -.IP "\fBesc_2254\fR" 4 -.IX Item "esc_2254" -Escape the \*(L"special\*(R" characters in a field as required by \s-1RFC 2254\s0 in a field. -That is, the \fB\s-1NUL\s0\fR character and of \f(CW\*(C`()*\*(C'\fR. -.IP "\fBesc_ctrl\fR" 4 -.IX Item "esc_ctrl" -Escape non-printable \s-1ASCII\s0 characters, codes less than 0x20 (space) -or greater than 0x7F (\s-1DELETE\s0). They are displayed using \s-1RFC 2253\s0 \f(CW\*(C`\eXX\*(C'\fR -notation where \fB\s-1XX\s0\fR are the two hex digits representing the character value. -.IP "\fBesc_msb\fR" 4 -.IX Item "esc_msb" -Escape any characters with the most significant bit set, that is with -values larger than 127, as described in \fBesc_ctrl\fR. -.IP "\fBuse_quote\fR" 4 -.IX Item "use_quote" -Escapes some characters by surrounding the entire string with quotation -marks, \f(CW\*(C`"\*(C'\fR. -Without this option, individual special characters are preceded with -a backslash character, \f(CW\*(C`\e\*(C'\fR. -.IP "\fButf8\fR" 4 -.IX Item "utf8" -Convert all strings to \s-1UTF\-8\s0 format first as required by \s-1RFC 2253.\s0 -If the output device is \s-1UTF\-8\s0 compatible, then using this option (and -not setting \fBesc_msb\fR) may give the correct display of multibyte -characters. -If this option is not set, then multibyte characters larger than 0xFF -will be output as \f(CW\*(C`\eUXXXX\*(C'\fR for 16 bits or \f(CW\*(C`\eWXXXXXXXX\*(C'\fR for 32 bits. -In addition, any UTF8Strings will be converted to their character form first. -.IP "\fBignore_type\fR" 4 -.IX Item "ignore_type" -This option does not attempt to interpret multibyte characters in any -way. That is, the content octets are merely dumped as though one octet -represents each character. This is useful for diagnostic purposes but -will result in rather odd looking output. -.IP "\fBshow_type\fR" 4 -.IX Item "show_type" -Display the type of the \s-1ASN1\s0 character string before the value, -such as \f(CW\*(C`BMPSTRING: Hello World\*(C'\fR. -.IP "\fBdump_der\fR" 4 -.IX Item "dump_der" -Any fields that would be output in hex format are displayed using -the \s-1DER\s0 encoding of the field. -If not set, just the content octets are displayed. -Either way, the \fB#XXXX...\fR format of \s-1RFC 2253\s0 is used. -.IP "\fBdump_nostr\fR" 4 -.IX Item "dump_nostr" -Dump non-character strings, such as \s-1ASN.1\s0 \fB\s-1OCTET STRING\s0\fR. -If this option is not set, then non character string types will be displayed -as though each content octet represents a single character. -.IP "\fBdump_all\fR" 4 -.IX Item "dump_all" -Dump all fields. When this used with \fBdump_der\fR, this allows the -\&\s-1DER\s0 encoding of the structure to be unambiguously determined. -.IP "\fBdump_unknown\fR" 4 -.IX Item "dump_unknown" -Dump any field whose \s-1OID\s0 is not recognised by OpenSSL. -.IP "\fBsep_comma_plus\fR, \fBsep_comma_plus_space\fR, \fBsep_semi_plus_space\fR, \fBsep_multiline\fR" 4 -.IX Item "sep_comma_plus, sep_comma_plus_space, sep_semi_plus_space, sep_multiline" -Specify the field separators. The first word is used between the -Relative Distinguished Names (RDNs) and the second is between -multiple Attribute Value Assertions (AVAs). Multiple AVAs are -very rare and their use is discouraged. -The options ending in \*(L"space\*(R" additionally place a space after the separator to make it more readable. -The \fBsep_multiline\fR starts each field on its own line, and uses \*(L"plus space\*(R" -for the \s-1AVA\s0 separator. -It also indents the fields by four characters. -The default value is \fBsep_comma_plus_space\fR. -.IP "\fBdn_rev\fR" 4 -.IX Item "dn_rev" -Reverse the fields of the \s-1DN\s0 as required by \s-1RFC 2253.\s0 -This also reverses the order of multiple AVAs in a field, but this is -permissible as there is no ordering on values. -.IP "\fBnofname\fR, \fBsname\fR, \fBlname\fR, \fBoid\fR" 4 -.IX Item "nofname, sname, lname, oid" -Specify how the field name is displayed. -\&\fBnofname\fR does not display the field at all. -\&\fBsname\fR uses the \*(L"short name\*(R" form (\s-1CN\s0 for commonName for example). -\&\fBlname\fR uses the long form. -\&\fBoid\fR represents the \s-1OID\s0 in numerical form and is useful for -diagnostic purpose. -.IP "\fBalign\fR" 4 -.IX Item "align" -Align field values for a more readable output. Only usable with -\&\fBsep_multiline\fR. -.IP "\fBspace_eq\fR" 4 -.IX Item "space_eq" -Places spaces round the equal sign, \f(CW\*(C`=\*(C'\fR, character which follows the field -name. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-nseq.1ossl b/openssl-install/share/man/man1/openssl-nseq.1ossl deleted file mode 100644 index 6b0f87c4..00000000 --- a/openssl-install/share/man/man1/openssl-nseq.1ossl +++ /dev/null @@ -1,211 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-NSEQ 1ossl" -.TH OPENSSL-NSEQ 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-nseq \- create or examine a Netscape certificate sequence -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBnseq\fR -[\fB\-help\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-toseq\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command takes a file containing a Netscape certificate -sequence and prints out the certificates contained in it or takes a -file of certificates and converts it into a Netscape certificate -sequence. -.PP -A Netscape certificate sequence is an old Netscape-specific format that -can be sometimes be sent to browsers as an alternative to the standard PKCS#7 -format when several certificates are sent to the browser, for example during -certificate enrollment. It was also used by Netscape certificate server. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read or standard input if this -option is not specified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Specifies the output filename or standard output by default. -.IP "\fB\-toseq\fR" 4 -.IX Item "-toseq" -Normally a Netscape certificate sequence will be input and the output -is the certificates contained in it. With the \fB\-toseq\fR option the -situation is reversed: a Netscape certificate sequence is created from -a file of certificates. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Output the certificates in a Netscape certificate sequence -.PP -.Vb 1 -\& openssl nseq \-in nseq.pem \-out certs.pem -.Ve -.PP -Create a Netscape certificate sequence -.PP -.Vb 1 -\& openssl nseq \-in certs.pem \-toseq \-out nseq.pem -.Ve -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-ocsp.1ossl b/openssl-install/share/man/man1/openssl-ocsp.1ossl deleted file mode 100644 index a1245613..00000000 --- a/openssl-install/share/man/man1/openssl-ocsp.1ossl +++ /dev/null @@ -1,665 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-OCSP 1ossl" -.TH OPENSSL-OCSP 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-ocsp \- Online Certificate Status Protocol command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.SS "\s-1OCSP\s0 Client" -.IX Subsection "OCSP Client" -\&\fBopenssl\fR \fBocsp\fR -[\fB\-help\fR] -[\fB\-out\fR \fIfile\fR] -[\fB\-issuer\fR \fIfile\fR] -[\fB\-cert\fR \fIfile\fR] -[\fB\-no_certs\fR] -[\fB\-serial\fR \fIn\fR] -[\fB\-signer\fR \fIfile\fR] -[\fB\-signkey\fR \fIfile\fR] -[\fB\-sign_other\fR \fIfile\fR] -[\fB\-nonce\fR] -[\fB\-no_nonce\fR] -[\fB\-req_text\fR] -[\fB\-resp_text\fR] -[\fB\-text\fR] -[\fB\-reqout\fR \fIfile\fR] -[\fB\-respout\fR \fIfile\fR] -[\fB\-reqin\fR \fIfile\fR] -[\fB\-respin\fR \fIfile\fR] -[\fB\-url\fR \fI\s-1URL\s0\fR] -[\fB\-host\fR \fIhost\fR:\fIport\fR] -[\fB\-path\fR \fIpathname\fR] -[\fB\-proxy\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR] -[\fB\-no_proxy\fR \fIaddresses\fR] -[\fB\-header\fR] -[\fB\-timeout\fR \fIseconds\fR] -[\fB\-VAfile\fR \fIfile\fR] -[\fB\-validity_period\fR \fIn\fR] -[\fB\-status_age\fR \fIn\fR] -[\fB\-noverify\fR] -[\fB\-verify_other\fR \fIfile\fR] -[\fB\-trust_other\fR] -[\fB\-no_intern\fR] -[\fB\-no_signature_verify\fR] -[\fB\-no_cert_verify\fR] -[\fB\-no_chain\fR] -[\fB\-no_cert_checks\fR] -[\fB\-no_explicit\fR] -[\fB\-port\fR \fInum\fR] -[\fB\-ignore_err\fR] -.SS "\s-1OCSP\s0 Server" -.IX Subsection "OCSP Server" -\&\fBopenssl\fR \fBocsp\fR -[\fB\-index\fR \fIfile\fR] -[\fB\-CA\fR \fIfile\fR] -[\fB\-rsigner\fR \fIfile\fR] -[\fB\-rkey\fR \fIfile\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-rother\fR \fIfile\fR] -[\fB\-rsigopt\fR \fInm\fR:\fIv\fR] -[\fB\-rmd\fR \fIdigest\fR] -[\fB\-badsig\fR] -[\fB\-resp_no_certs\fR] -[\fB\-nmin\fR \fIn\fR] -[\fB\-ndays\fR \fIn\fR] -[\fB\-resp_key_id\fR] -[\fB\-nrequest\fR \fIn\fR] -[\fB\-multi\fR \fIprocess-count\fR] -[\fB\-rcid\fR \fIdigest\fR] -[\fB\-\f(BIdigest\fB\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The Online Certificate Status Protocol (\s-1OCSP\s0) enables applications to -determine the (revocation) state of an identified certificate (\s-1RFC 2560\s0). -.PP -This command performs many common \s-1OCSP\s0 tasks. It can be used -to print out requests and responses, create requests and send queries -to an \s-1OCSP\s0 responder and behave like a mini \s-1OCSP\s0 server itself. -.SH "OPTIONS" -.IX Header "OPTIONS" -This command operates as either a client or a server. -The options are described below, divided into those two modes. -.SS "\s-1OCSP\s0 Client Options" -.IX Subsection "OCSP Client Options" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -specify output filename, default is standard output. -.IP "\fB\-issuer\fR \fIfilename\fR" 4 -.IX Item "-issuer filename" -This specifies the current issuer certificate. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.Sp -This option can be used multiple times. -This option \fB\s-1MUST\s0\fR come before any \fB\-cert\fR options. -.IP "\fB\-cert\fR \fIfilename\fR" 4 -.IX Item "-cert filename" -Add the certificate \fIfilename\fR to the request. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.Sp -This option can be used multiple times. -The issuer certificate is taken from the previous \fB\-issuer\fR option, -or an error occurs if no issuer certificate is specified. -.IP "\fB\-no_certs\fR" 4 -.IX Item "-no_certs" -Don't include any certificates in signed request. -.IP "\fB\-serial\fR \fInum\fR" 4 -.IX Item "-serial num" -Same as the \fB\-cert\fR option except the certificate with serial number -\&\fBnum\fR is added to the request. The serial number is interpreted as a -decimal integer unless preceded by \f(CW\*(C`0x\*(C'\fR. Negative integers can also -be specified by preceding the value by a \f(CW\*(C`\-\*(C'\fR sign. -.IP "\fB\-signer\fR \fIfilename\fR, \fB\-signkey\fR \fIfilename\fR" 4 -.IX Item "-signer filename, -signkey filename" -Sign the \s-1OCSP\s0 request using the certificate specified in the \fB\-signer\fR -option and the private key specified by the \fB\-signkey\fR option. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.Sp -If the \fB\-signkey\fR option is not present then the private key is read -from the same file as the certificate. If neither option is specified then -the \s-1OCSP\s0 request is not signed. -.IP "\fB\-sign_other\fR \fIfilename\fR" 4 -.IX Item "-sign_other filename" -Additional certificates to include in the signed request. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-nonce\fR, \fB\-no_nonce\fR" 4 -.IX Item "-nonce, -no_nonce" -Add an \s-1OCSP\s0 nonce extension to a request or disable \s-1OCSP\s0 nonce addition. -Normally if an \s-1OCSP\s0 request is input using the \fB\-reqin\fR option no -nonce is added: using the \fB\-nonce\fR option will force addition of a nonce. -If an \s-1OCSP\s0 request is being created (using \fB\-cert\fR and \fB\-serial\fR options) -a nonce is automatically added specifying \fB\-no_nonce\fR overrides this. -.IP "\fB\-req_text\fR, \fB\-resp_text\fR, \fB\-text\fR" 4 -.IX Item "-req_text, -resp_text, -text" -Print out the text form of the \s-1OCSP\s0 request, response or both respectively. -.IP "\fB\-reqout\fR \fIfile\fR, \fB\-respout\fR \fIfile\fR" 4 -.IX Item "-reqout file, -respout file" -Write out the \s-1DER\s0 encoded certificate request or response to \fIfile\fR. -.IP "\fB\-reqin\fR \fIfile\fR, \fB\-respin\fR \fIfile\fR" 4 -.IX Item "-reqin file, -respin file" -Read \s-1OCSP\s0 request or response file from \fIfile\fR. These option are ignored -if \s-1OCSP\s0 request or response creation is implied by other options (for example -with \fB\-serial\fR, \fB\-cert\fR and \fB\-host\fR options). -.IP "\fB\-url\fR \fIresponder_url\fR" 4 -.IX Item "-url responder_url" -Specify the responder host and optionally port and path via a \s-1URL.\s0 -Both \s-1HTTP\s0 and \s-1HTTPS\s0 (\s-1SSL/TLS\s0) URLs can be specified. -The optional userinfo and fragment components are ignored. -Any given query component is handled as part of the path component. -For details, see the \fB\-host\fR and \fB\-path\fR options described next. -.IP "\fB\-host\fR \fIhost\fR:\fIport\fR, \fB\-path\fR \fIpathname\fR" 4 -.IX Item "-host host:port, -path pathname" -If the \fB\-host\fR option is present then the \s-1OCSP\s0 request is sent to the host -\&\fIhost\fR on port \fIport\fR. -The \fIhost\fR may be a domain name or an \s-1IP\s0 (v4 or v6) address, -such as \f(CW127.0.0.1\fR or \f(CW\*(C`[::1]\*(C'\fR for localhost. -If it is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -.Sp -The \fB\-path\fR option specifies the \s-1HTTP\s0 pathname to use or \*(L"/\*(R" by default. -This is equivalent to specifying \fB\-url\fR with scheme -http:// and the given \fIhost\fR, \fIport\fR, and optional \fIpathname\fR. -.IP "\fB\-proxy\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR" 4 -.IX Item "-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]" -The \s-1HTTP\s0(S) proxy server to use for reaching the \s-1OCSP\s0 server unless \fB\-no_proxy\fR -applies, see below. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -The proxy port defaults to 80 or 443 if the scheme is \f(CW\*(C`https\*(C'\fR; apart from that -the optional \f(CW\*(C`http://\*(C'\fR or \f(CW\*(C`https://\*(C'\fR prefix is ignored, -as well as any userinfo, path, query, and fragment components. -Defaults to the environment variable \f(CW\*(C`http_proxy\*(C'\fR if set, else \f(CW\*(C`HTTP_PROXY\*(C'\fR -in case no \s-1TLS\s0 is used, otherwise \f(CW\*(C`https_proxy\*(C'\fR if set, else \f(CW\*(C`HTTPS_PROXY\*(C'\fR. -.IP "\fB\-no_proxy\fR \fIaddresses\fR" 4 -.IX Item "-no_proxy addresses" -List of \s-1IP\s0 addresses and/or \s-1DNS\s0 names of servers -not to use an \s-1HTTP\s0(S) proxy for, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Default is from the environment variable \f(CW\*(C`no_proxy\*(C'\fR if set, else \f(CW\*(C`NO_PROXY\*(C'\fR. -.IP "\fB\-header\fR \fIname\fR=\fIvalue\fR" 4 -.IX Item "-header name=value" -Adds the header \fIname\fR with the specified \fIvalue\fR to the \s-1OCSP\s0 request -that is sent to the responder. -This may be repeated. -.IP "\fB\-timeout\fR \fIseconds\fR" 4 -.IX Item "-timeout seconds" -Connection timeout to the \s-1OCSP\s0 responder in seconds. -On \s-1POSIX\s0 systems, when running as an \s-1OCSP\s0 responder, this option also limits -the time that the responder is willing to wait for the client request. -This time is measured from the time the responder accepts the connection until -the complete request is received. -.IP "\fB\-verify_other\fR \fIfile\fR" 4 -.IX Item "-verify_other file" -File or \s-1URI\s0 containing additional certificates to search -when attempting to locate -the \s-1OCSP\s0 response signing certificate. Some responders omit the actual signer's -certificate from the response: this option can be used to supply the necessary -certificate in such cases. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-trust_other\fR" 4 -.IX Item "-trust_other" -The certificates specified by the \fB\-verify_other\fR option should be explicitly -trusted and no additional checks will be performed on them. This is useful -when the complete responder certificate chain is not available or trusting a -root \s-1CA\s0 is not appropriate. -.IP "\fB\-VAfile\fR \fIfile\fR" 4 -.IX Item "-VAfile file" -File or \s-1URI\s0 containing explicitly trusted responder certificates. -Equivalent to the \fB\-verify_other\fR and \fB\-trust_other\fR options. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-noverify\fR" 4 -.IX Item "-noverify" -Don't attempt to verify the \s-1OCSP\s0 response signature or the nonce -values. This option will normally only be used for debugging since it -disables all verification of the responders certificate. -.IP "\fB\-no_intern\fR" 4 -.IX Item "-no_intern" -Ignore certificates contained in the \s-1OCSP\s0 response when searching for the -signers certificate. With this option the signers certificate must be specified -with either the \fB\-verify_other\fR or \fB\-VAfile\fR options. -.IP "\fB\-no_signature_verify\fR" 4 -.IX Item "-no_signature_verify" -Don't check the signature on the \s-1OCSP\s0 response. Since this option -tolerates invalid signatures on \s-1OCSP\s0 responses it will normally only be -used for testing purposes. -.IP "\fB\-no_cert_verify\fR" 4 -.IX Item "-no_cert_verify" -Don't verify the \s-1OCSP\s0 response signers certificate at all. Since this -option allows the \s-1OCSP\s0 response to be signed by any certificate it should -only be used for testing purposes. -.IP "\fB\-no_chain\fR" 4 -.IX Item "-no_chain" -Do not use certificates in the response as additional untrusted \s-1CA\s0 -certificates. -.IP "\fB\-no_explicit\fR" 4 -.IX Item "-no_explicit" -Do not explicitly trust the root \s-1CA\s0 if it is set to be trusted for \s-1OCSP\s0 signing. -.IP "\fB\-no_cert_checks\fR" 4 -.IX Item "-no_cert_checks" -Don't perform any additional checks on the \s-1OCSP\s0 response signers certificate. -That is do not make any checks to see if the signers certificate is authorised -to provide the necessary status information: as a result this option should -only be used for testing purposes. -.IP "\fB\-validity_period\fR \fInsec\fR, \fB\-status_age\fR \fIage\fR" 4 -.IX Item "-validity_period nsec, -status_age age" -These options specify the range of times, in seconds, which will be tolerated -in an \s-1OCSP\s0 response. Each certificate status response includes a \fBnotBefore\fR -time and an optional \fBnotAfter\fR time. The current time should fall between -these two values, but the interval between the two times may be only a few -seconds. In practice the \s-1OCSP\s0 responder and clients clocks may not be precisely -synchronised and so such a check may fail. To avoid this the -\&\fB\-validity_period\fR option can be used to specify an acceptable error range in -seconds, the default value is 5 minutes. -.Sp -If the \fBnotAfter\fR time is omitted from a response then this means that new -status information is immediately available. In this case the age of the -\&\fBnotBefore\fR field is checked to see it is not older than \fIage\fR seconds old. -By default this additional check is not performed. -.IP "\fB\-rcid\fR \fIdigest\fR" 4 -.IX Item "-rcid digest" -This option sets the digest algorithm to use for certificate identification -in the \s-1OCSP\s0 response. Any digest supported by the \fBopenssl\-dgst\fR\|(1) command can -be used. The default is the same digest algorithm used in the request. -.IP "\fB\-\f(BIdigest\fB\fR" 4 -.IX Item "-digest" -This option sets digest algorithm to use for certificate identification in the -\&\s-1OCSP\s0 request. Any digest supported by the OpenSSL \fBdgst\fR command can be used. -The default is \s-1SHA\-1.\s0 This option may be used multiple times to specify the -digest used by subsequent certificate identifiers. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SS "\s-1OCSP\s0 Server Options" -.IX Subsection "OCSP Server Options" -.IP "\fB\-index\fR \fIindexfile\fR" 4 -.IX Item "-index indexfile" -The \fIindexfile\fR parameter is the name of a text index file in \fBca\fR -format containing certificate revocation information. -.Sp -If the \fB\-index\fR option is specified then this command switches to -responder mode, otherwise it is in client mode. The request(s) the responder -processes can be either specified on the command line (using \fB\-issuer\fR -and \fB\-serial\fR options), supplied in a file (using the \fB\-reqin\fR option) -or via external \s-1OCSP\s0 clients (if \fB\-port\fR or \fB\-url\fR is specified). -.Sp -If the \fB\-index\fR option is present then the \fB\-CA\fR and \fB\-rsigner\fR options -must also be present. -.IP "\fB\-CA\fR \fIfile\fR" 4 -.IX Item "-CA file" -\&\s-1CA\s0 certificates corresponding to the revocation information in the index -file given with \fB\-index\fR. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-rsigner\fR \fIfile\fR" 4 -.IX Item "-rsigner file" -The certificate to sign \s-1OCSP\s0 responses with. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-rkey\fR \fIfile\fR" 4 -.IX Item "-rkey file" -The private key to sign \s-1OCSP\s0 responses with: if not present the file -specified in the \fB\-rsigner\fR option is used. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The private key password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-rother\fR \fIfile\fR" 4 -.IX Item "-rother file" -Additional certificates to include in the \s-1OCSP\s0 response. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-rsigopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-rsigopt nm:v" -Pass options to the signature algorithm when signing \s-1OCSP\s0 responses. -Names and values of these options are algorithm-specific. -.IP "\fB\-rmd\fR \fIdigest\fR" 4 -.IX Item "-rmd digest" -The digest to use when signing the response. -.IP "\fB\-badsig\fR" 4 -.IX Item "-badsig" -Corrupt the response signature before writing it; this can be useful -for testing. -.IP "\fB\-resp_no_certs\fR" 4 -.IX Item "-resp_no_certs" -Don't include any certificates in the \s-1OCSP\s0 response. -.IP "\fB\-resp_key_id\fR" 4 -.IX Item "-resp_key_id" -Identify the signer certificate using the key \s-1ID,\s0 default is to use the -subject name. -.IP "\fB\-port\fR \fIportnum\fR" 4 -.IX Item "-port portnum" -Port to listen for \s-1OCSP\s0 requests on. Both IPv4 and IPv6 are possible. -The port may also be specified using the \fB\-url\fR option. -A \f(CW0\fR argument indicates that any available port shall be chosen automatically. -.IP "\fB\-ignore_err\fR" 4 -.IX Item "-ignore_err" -Ignore malformed requests or responses: When acting as an \s-1OCSP\s0 client, retry if -a malformed response is received. When acting as an \s-1OCSP\s0 responder, continue -running instead of terminating upon receiving a malformed request. -.IP "\fB\-nrequest\fR \fInumber\fR" 4 -.IX Item "-nrequest number" -The \s-1OCSP\s0 server will exit after receiving \fInumber\fR requests, default unlimited. -.IP "\fB\-multi\fR \fIprocess-count\fR" 4 -.IX Item "-multi process-count" -Run the specified number of \s-1OCSP\s0 responder child processes, with the parent -process respawning child processes as needed. -Child processes will detect changes in the \s-1CA\s0 index file and automatically -reload it. -When running as a responder \fB\-timeout\fR option is recommended to limit the time -each child is willing to wait for the client's \s-1OCSP\s0 response. -This option is available on \s-1POSIX\s0 systems (that support the \fBfork()\fR and other -required unix system-calls). -.IP "\fB\-nmin\fR \fIminutes\fR, \fB\-ndays\fR \fIdays\fR" 4 -.IX Item "-nmin minutes, -ndays days" -Number of minutes or days when fresh revocation information is available: -used in the \fBnextUpdate\fR field. If neither option is present then the -\&\fBnextUpdate\fR field is omitted meaning fresh revocation information is -immediately available. -.SH "OCSP RESPONSE VERIFICATION" -.IX Header "OCSP RESPONSE VERIFICATION" -\&\s-1OCSP\s0 Response follows the rules specified in \s-1RFC2560.\s0 -.PP -Initially the \s-1OCSP\s0 responder certificate is located and the signature on -the \s-1OCSP\s0 request checked using the responder certificate's public key. -.PP -Then a normal certificate verify is performed on the \s-1OCSP\s0 responder certificate -building up a certificate chain in the process. The locations of the trusted -certificates used to build the chain can be specified by the \fB\-CAfile\fR, -\&\fB\-CApath\fR or \fB\-CAstore\fR options or they will be looked for in the -standard OpenSSL certificates directory. -.PP -If the initial verify fails then the \s-1OCSP\s0 verify process halts with an -error. -.PP -Otherwise the issuing \s-1CA\s0 certificate in the request is compared to the \s-1OCSP\s0 -responder certificate: if there is a match then the \s-1OCSP\s0 verify succeeds. -.PP -Otherwise the \s-1OCSP\s0 responder certificate's \s-1CA\s0 is checked against the issuing -\&\s-1CA\s0 certificate in the request. If there is a match and the OCSPSigning -extended key usage is present in the \s-1OCSP\s0 responder certificate then the -\&\s-1OCSP\s0 verify succeeds. -.PP -Otherwise, if \fB\-no_explicit\fR is \fBnot\fR set the root \s-1CA\s0 of the \s-1OCSP\s0 responders -\&\s-1CA\s0 is checked to see if it is trusted for \s-1OCSP\s0 signing. If it is the \s-1OCSP\s0 -verify succeeds. -.PP -If none of these checks is successful then the \s-1OCSP\s0 verify fails. -.PP -What this effectively means if that if the \s-1OCSP\s0 responder certificate is -authorised directly by the \s-1CA\s0 it is issuing revocation information about -(and it is correctly configured) then verification will succeed. -.PP -If the \s-1OCSP\s0 responder is a \*(L"global responder\*(R" which can give details about -multiple CAs and has its own separate certificate chain then its root -\&\s-1CA\s0 can be trusted for \s-1OCSP\s0 signing. For example: -.PP -.Vb 1 -\& openssl x509 \-in ocspCA.pem \-addtrust OCSPSigning \-out trustedCA.pem -.Ve -.PP -Alternatively the responder certificate itself can be explicitly trusted -with the \fB\-VAfile\fR option. -.SH "NOTES" -.IX Header "NOTES" -As noted, most of the verify options are for testing or debugging purposes. -Normally only the \fB\-CApath\fR, \fB\-CAfile\fR, \fB\-CAstore\fR and (if the responder -is a 'global \s-1VA\s0') \fB\-VAfile\fR options need to be used. -.PP -The \s-1OCSP\s0 server is only useful for test and demonstration purposes: it is -not really usable as a full \s-1OCSP\s0 responder. It contains only a very -simple \s-1HTTP\s0 request handling and can only handle the \s-1POST\s0 form of \s-1OCSP\s0 -queries. It also handles requests serially meaning it cannot respond to -new requests until it has processed the current one. The text index file -format of revocation is also inefficient for large quantities of revocation -data. -.PP -It is possible to run this command in responder mode via a \s-1CGI\s0 -script using the \fB\-reqin\fR and \fB\-respout\fR options. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create an \s-1OCSP\s0 request and write it to a file: -.PP -.Vb 1 -\& openssl ocsp \-issuer issuer.pem \-cert c1.pem \-cert c2.pem \-reqout req.der -.Ve -.PP -Send a query to an \s-1OCSP\s0 responder with \s-1URL\s0 http://ocsp.myhost.com/ save the -response to a file, print it out in text form, and verify the response: -.PP -.Vb 2 -\& openssl ocsp \-issuer issuer.pem \-cert c1.pem \-cert c2.pem \e -\& \-url http://ocsp.myhost.com/ \-resp_text \-respout resp.der -.Ve -.PP -Read in an \s-1OCSP\s0 response and print out text form: -.PP -.Vb 1 -\& openssl ocsp \-respin resp.der \-text \-noverify -.Ve -.PP -\&\s-1OCSP\s0 server on port 8888 using a standard \fBca\fR configuration, and a separate -responder certificate. All requests and responses are printed to a file. -.PP -.Vb 2 -\& openssl ocsp \-index demoCA/index.txt \-port 8888 \-rsigner rcert.pem \-CA demoCA/cacert.pem -\& \-text \-out log.txt -.Ve -.PP -As above but exit after processing one request: -.PP -.Vb 2 -\& openssl ocsp \-index demoCA/index.txt \-port 8888 \-rsigner rcert.pem \-CA demoCA/cacert.pem -\& \-nrequest 1 -.Ve -.PP -Query status information using an internally generated request: -.PP -.Vb 2 -\& openssl ocsp \-index demoCA/index.txt \-rsigner rcert.pem \-CA demoCA/cacert.pem -\& \-issuer demoCA/cacert.pem \-serial 1 -.Ve -.PP -Query status information using request read from a file, and write the response -to a second file. -.PP -.Vb 2 -\& openssl ocsp \-index demoCA/index.txt \-rsigner rcert.pem \-CA demoCA/cacert.pem -\& \-reqin req.der \-respout resp.der -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -The \-no_alt_chains option was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-passphrase-options.1ossl b/openssl-install/share/man/man1/openssl-passphrase-options.1ossl deleted file mode 100644 index 26d45800..00000000 --- a/openssl-install/share/man/man1/openssl-passphrase-options.1ossl +++ /dev/null @@ -1,203 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PASSPHRASE-OPTIONS 1ossl" -.TH OPENSSL-PASSPHRASE-OPTIONS 1ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-passphrase\-options \- Pass phrase options -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR -\&\fIcommand\fR -[ \fIoptions\fR ... ] -[ \fIparameters\fR ... ] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Several OpenSSL commands accept password arguments, typically using \fB\-passin\fR -and \fB\-passout\fR for input and output passwords respectively. These allow -the password to be obtained from a variety of sources. Both of these -options take a single argument whose format is described below. If no -password argument is given and a password is required then the user is -prompted to enter one: this will typically be read from the current -terminal with echoing turned off. -.PP -Note that character encoding may be relevant, please see -\&\fBpassphrase\-encoding\fR\|(7). -.SH "OPTIONS" -.IX Header "OPTIONS" -.SS "Pass Phrase Option Arguments" -.IX Subsection "Pass Phrase Option Arguments" -Pass phrase arguments can be formatted as follows. -.IP "\fBpass:\fR\fIpassword\fR" 4 -.IX Item "pass:password" -The actual password is \fIpassword\fR. Since the password is visible -to utilities (like 'ps' under Unix) this form should only be used -where security is not important. -.IP "\fBenv:\fR\fIvar\fR" 4 -.IX Item "env:var" -Obtain the password from the environment variable \fIvar\fR. Since -the environment of other processes is visible on certain platforms -(e.g. ps under certain Unix OSes) this option should be used with caution. -.IP "\fBfile:\fR\fIpathname\fR" 4 -.IX Item "file:pathname" -Reads the password from the specified file \fIpathname\fR, which can be a regular -file, device, or named pipe. Only the first line, up to the newline character, -is read from the stream. -.Sp -If the same \fIpathname\fR argument is supplied to both \fB\-passin\fR and \fB\-passout\fR -arguments, the first line will be used for the input password, and the next -line will be used for the output password. -.IP "\fBfd:\fR\fInumber\fR" 4 -.IX Item "fd:number" -Reads the password from the file descriptor \fInumber\fR. This can be useful for -sending data via a pipe, for example. The same line handling as described for -\&\fBfile:\fR applies to passwords read from file descriptors. -.Sp -\&\fBfd:\fR is not supported on Windows. -.IP "\fBstdin\fR" 4 -.IX Item "stdin" -Reads the password from standard input. The same line handling as described for -\&\fBfile:\fR applies to passwords read from standard input. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-passwd.1ossl b/openssl-install/share/man/man1/openssl-passwd.1ossl deleted file mode 100644 index 5f4320fb..00000000 --- a/openssl-install/share/man/man1/openssl-passwd.1ossl +++ /dev/null @@ -1,250 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PASSWD 1ossl" -.TH OPENSSL-PASSWD 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-passwd \- compute password hashes -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl passwd\fR -[\fB\-help\fR] -[\fB\-1\fR] -[\fB\-apr1\fR] -[\fB\-aixmd5\fR] -[\fB\-5\fR] -[\fB\-6\fR] -[\fB\-salt\fR \fIstring\fR] -[\fB\-in\fR \fIfile\fR] -[\fB\-stdin\fR] -[\fB\-noverify\fR] -[\fB\-quiet\fR] -[\fB\-table\fR] -[\fB\-reverse\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIpassword\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command computes the hash of a password typed at -run-time or the hash of each password in a list. The password list is -taken from the named file for option \fB\-in\fR, from stdin for -option \fB\-stdin\fR, or from the command line, or from the terminal otherwise. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-1\fR" 4 -.IX Item "-1" -Use the \s-1MD5\s0 based \s-1BSD\s0 password algorithm \fB1\fR (default). -.IP "\fB\-apr1\fR" 4 -.IX Item "-apr1" -Use the \fBapr1\fR algorithm (Apache variant of the \s-1BSD\s0 algorithm). -.IP "\fB\-aixmd5\fR" 4 -.IX Item "-aixmd5" -Use the \fB\s-1AIX MD5\s0\fR algorithm (\s-1AIX\s0 variant of the \s-1BSD\s0 algorithm). -.IP "\fB\-5\fR" 4 -.IX Item "-5" -.PD 0 -.IP "\fB\-6\fR" 4 -.IX Item "-6" -.PD -Use the \fB\s-1SHA256\s0\fR / \fB\s-1SHA512\s0\fR based algorithms defined by Ulrich Drepper. -See . -.IP "\fB\-salt\fR \fIstring\fR" 4 -.IX Item "-salt string" -Use the specified salt. -When reading a password from the terminal, this implies \fB\-noverify\fR. -.IP "\fB\-in\fR \fIfile\fR" 4 -.IX Item "-in file" -Read passwords from \fIfile\fR. -.IP "\fB\-stdin\fR" 4 -.IX Item "-stdin" -Read passwords from \fBstdin\fR. -.IP "\fB\-noverify\fR" 4 -.IX Item "-noverify" -Don't verify when reading a password from the terminal. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Don't output warnings when passwords given at the command line are truncated. -.IP "\fB\-table\fR" 4 -.IX Item "-table" -In the output list, prepend the cleartext password and a \s-1TAB\s0 character -to each password hash. -.IP "\fB\-reverse\fR" 4 -.IX Item "-reverse" -When the \fB\-table\fR option is used, reverse the order of cleartext and hash. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 2 -\& % openssl passwd \-1 \-salt xxxxxxxx password -\& $1$xxxxxxxx$UYCIxa628.9qXjpQCjM4a. -\& -\& % openssl passwd \-apr1 \-salt xxxxxxxx password -\& $apr1$xxxxxxxx$dxHfLAsjHkDRmG83UXe8K0 -\& -\& % openssl passwd \-aixmd5 \-salt xxxxxxxx password -\& xxxxxxxx$8Oaipk/GPKhC64w/YVeFD/ -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-crypt\fR option was removed in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-pkcs12.1ossl b/openssl-install/share/man/man1/openssl-pkcs12.1ossl deleted file mode 100644 index 995e4298..00000000 --- a/openssl-install/share/man/man1/openssl-pkcs12.1ossl +++ /dev/null @@ -1,601 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PKCS12 1ossl" -.TH OPENSSL-PKCS12 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-pkcs12 \- PKCS#12 file command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBpkcs12\fR -[\fB\-help\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-password\fR \fIarg\fR] -[\fB\-twopass\fR] -[\fB\-in\fR \fIfilename\fR|\fIuri\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-nokeys\fR] -[\fB\-nocerts\fR] -[\fB\-noout\fR] -[\fB\-legacy\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -.PP -PKCS#12 input (parsing) options: -[\fB\-info\fR] -[\fB\-nomacver\fR] -[\fB\-clcerts\fR] -[\fB\-cacerts\fR] -.PP -[\fB\-aes128\fR] -[\fB\-aes192\fR] -[\fB\-aes256\fR] -[\fB\-aria128\fR] -[\fB\-aria192\fR] -[\fB\-aria256\fR] -[\fB\-camellia128\fR] -[\fB\-camellia192\fR] -[\fB\-camellia256\fR] -[\fB\-des\fR] -[\fB\-des3\fR] -[\fB\-idea\fR] -[\fB\-noenc\fR] -[\fB\-nodes\fR] -.PP -PKCS#12 output (export) options: -.PP -[\fB\-export\fR] -[\fB\-inkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-certfile\fR \fIfilename\fR] -[\fB\-passcerts\fR \fIarg\fR] -[\fB\-chain\fR] -[\fB\-untrusted\fR \fIfilename\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-name\fR \fIname\fR] -[\fB\-caname\fR \fIname\fR] -[\fB\-CSP\fR \fIname\fR] -[\fB\-LMK\fR] -[\fB\-keyex\fR] -[\fB\-keysig\fR] -[\fB\-keypbe\fR \fIcipher\fR] -[\fB\-certpbe\fR \fIcipher\fR] -[\fB\-descert\fR] -[\fB\-macalg\fR \fIdigest\fR] -[\fB\-pbmac1_pbkdf2\fR] -[\fB\-pbmac1_pbkdf2_md\fR \fIdigest\fR] -[\fB\-iter\fR \fIcount\fR] -[\fB\-noiter\fR] -[\fB\-nomaciter\fR] -[\fB\-maciter\fR] -[\fB\-macsaltlen\fR] -[\fB\-nomac\fR] -[\fB\-jdktrust\fR \fIusage\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command allows PKCS#12 files (sometimes referred to as -\&\s-1PFX\s0 files) to be created and parsed. PKCS#12 files are used by several -programs including Netscape, \s-1MSIE\s0 and \s-1MS\s0 Outlook. -.SH "OPTIONS" -.IX Header "OPTIONS" -There are a lot of options the meaning of some depends of whether a PKCS#12 file -is being created or parsed. By default a PKCS#12 file is parsed. -A PKCS#12 file can be created by using the \fB\-export\fR option (see below). -The PKCS#12 export encryption and \s-1MAC\s0 options such as \fB\-certpbe\fR and \fB\-iter\fR -and many further options such as \fB\-chain\fR are relevant only with \fB\-export\fR. -Conversely, the options regarding encryption of private keys when outputting -PKCS#12 input are relevant only when the \fB\-export\fR option is not given. -.PP -The default encryption algorithm is \s-1AES\-256\-CBC\s0 with \s-1PBKDF2\s0 for key derivation. -.PP -When encountering problems loading legacy PKCS#12 files that involve, -for example, \s-1RC2\-40\-CBC,\s0 -try using the \fB\-legacy\fR option and, if needed, the \fB\-provider\-path\fR option. -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The password source for the input, and for encrypting any private keys that -are output. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passout arg" -The password source for output files. -.IP "\fB\-password\fR \fIarg\fR" 4 -.IX Item "-password arg" -With \fB\-export\fR, \fB\-password\fR is equivalent to \fB\-passout\fR, -otherwise it is equivalent to \fB\-passin\fR. -.IP "\fB\-twopass\fR" 4 -.IX Item "-twopass" -Prompt for separate integrity and encryption passwords: most software -always assumes these are the same so this option will render such -PKCS#12 files unreadable. Cannot be used in combination with the options -\&\fB\-password\fR, \fB\-passin\fR if importing from PKCS#12, or \fB\-passout\fR if exporting. -.IP "\fB\-nokeys\fR" 4 -.IX Item "-nokeys" -No private keys will be output. -.IP "\fB\-nocerts\fR" 4 -.IX Item "-nocerts" -No certificates will be output. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option inhibits all credentials output, -and so the input is just verified. -.IP "\fB\-legacy\fR" 4 -.IX Item "-legacy" -Use legacy mode of operation and automatically load the legacy provider. -If OpenSSL is not installed system-wide, -it is necessary to also use, for example, \f(CW\*(C`\-provider\-path ./providers\*(C'\fR -or to set the environment variable \fB\s-1OPENSSL_MODULES\s0\fR -to point to the directory where the providers can be found. -.Sp -In the legacy mode, the default algorithm for certificate encryption -is \s-1RC2_CBC\s0 or 3DES_CBC depending on whether the \s-1RC2\s0 cipher is enabled -in the build. The default algorithm for private key encryption is 3DES_CBC. -If the legacy option is not specified, then the legacy provider is not loaded -and the default encryption algorithm for both certificates and private keys is -\&\s-1AES_256_CBC\s0 with \s-1PBKDF2\s0 for key derivation. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.SS "PKCS#12 input (parsing) options" -.IX Subsection "PKCS#12 input (parsing) options" -.IP "\fB\-in\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-in filename|uri" -This specifies the input filename or \s-1URI.\s0 -Standard input is used by default. -Without the \fB\-export\fR option this must be PKCS#12 file to be parsed. -For use with the \fB\-export\fR option -see the \*(L"PKCS#12 output (export) options\*(R" section. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -The filename to write certificates and private keys to, standard output by -default. They are all written in \s-1PEM\s0 format. -.IP "\fB\-info\fR" 4 -.IX Item "-info" -Output additional information about the PKCS#12 file structure, algorithms -used and iteration counts. -.IP "\fB\-nomacver\fR" 4 -.IX Item "-nomacver" -Don't attempt to verify the integrity \s-1MAC.\s0 -.IP "\fB\-clcerts\fR" 4 -.IX Item "-clcerts" -Only output client certificates (not \s-1CA\s0 certificates). -.IP "\fB\-cacerts\fR" 4 -.IX Item "-cacerts" -Only output \s-1CA\s0 certificates (not client certificates). -.IP "\fB\-aes128\fR, \fB\-aes192\fR, \fB\-aes256\fR" 4 -.IX Item "-aes128, -aes192, -aes256" -Use \s-1AES\s0 to encrypt private keys before outputting. -.IP "\fB\-aria128\fR, \fB\-aria192\fR, \fB\-aria256\fR" 4 -.IX Item "-aria128, -aria192, -aria256" -Use \s-1ARIA\s0 to encrypt private keys before outputting. -.IP "\fB\-camellia128\fR, \fB\-camellia192\fR, \fB\-camellia256\fR" 4 -.IX Item "-camellia128, -camellia192, -camellia256" -Use Camellia to encrypt private keys before outputting. -.IP "\fB\-des\fR" 4 -.IX Item "-des" -Use \s-1DES\s0 to encrypt private keys before outputting. -.IP "\fB\-des3\fR" 4 -.IX Item "-des3" -Use triple \s-1DES\s0 to encrypt private keys before outputting. -.IP "\fB\-idea\fR" 4 -.IX Item "-idea" -Use \s-1IDEA\s0 to encrypt private keys before outputting. -.IP "\fB\-noenc\fR" 4 -.IX Item "-noenc" -Don't encrypt private keys at all. -.IP "\fB\-nodes\fR" 4 -.IX Item "-nodes" -This option is deprecated since OpenSSL 3.0; use \fB\-noenc\fR instead. -.SS "PKCS#12 output (export) options" -.IX Subsection "PKCS#12 output (export) options" -.IP "\fB\-export\fR" 4 -.IX Item "-export" -This option specifies that a PKCS#12 file will be created rather than -parsed. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies filename to write the PKCS#12 file to. Standard output is used -by default. -.IP "\fB\-in\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-in filename|uri" -This specifies the input filename or \s-1URI.\s0 -Standard input is used by default. -With the \fB\-export\fR option this is a file with certificates and a key, -or a \s-1URI\s0 that refers to a key accessed via an engine. -The order of credentials in a file doesn't matter but one private key and -its corresponding certificate should be present. If additional -certificates are present they will also be included in the PKCS#12 output file. -.IP "\fB\-inkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-inkey filename|uri" -The private key input for \s-1PKCS12\s0 output. -If this option is not specified then the input file (\fB\-in\fR argument) must -contain a private key. -If no engine is used, the argument is taken as a file. -If the \fB\-engine\fR option is used or the \s-1URI\s0 has prefix \f(CW\*(C`org.openssl.engine:\*(C'\fR -then the rest of the \s-1URI\s0 is taken as key identifier for the given engine. -.IP "\fB\-certfile\fR \fIfilename\fR" 4 -.IX Item "-certfile filename" -An input file with extra certificates to be added to the PKCS#12 output -if the \fB\-export\fR option is given. -.IP "\fB\-passcerts\fR \fIarg\fR" 4 -.IX Item "-passcerts arg" -The password source for certificate input such as \fB\-certfile\fR -and \fB\-untrusted\fR. -For more information about the format of \fBarg\fR see -\&\fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-chain\fR" 4 -.IX Item "-chain" -If this option is present then the certificate chain of the end entity -certificate is built and included in the PKCS#12 output file. -The end entity certificate is the first one read from the \fB\-in\fR file -if no key is given, else the first certificate matching the given key. -The standard \s-1CA\s0 trust store is used for chain building, -as well as any untrusted \s-1CA\s0 certificates given with the \fB\-untrusted\fR option. -.IP "\fB\-untrusted\fR \fIfilename\fR" 4 -.IX Item "-untrusted filename" -An input file of untrusted certificates that may be used -for chain building, which is relevant only when a PKCS#12 file is created -with the \fB\-export\fR option and the \fB\-chain\fR option is given as well. -Any certificates that are actually part of the chain are added to the output. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-name\fR \fIfriendlyname\fR" 4 -.IX Item "-name friendlyname" -This specifies the \*(L"friendly name\*(R" for the certificates and private key. This -name is typically displayed in list boxes by software importing the file. -.IP "\fB\-caname\fR \fIfriendlyname\fR" 4 -.IX Item "-caname friendlyname" -This specifies the \*(L"friendly name\*(R" for other certificates. This option may be -used multiple times to specify names for all certificates in the order they -appear. Netscape ignores friendly names on other certificates whereas \s-1MSIE\s0 -displays them. -.IP "\fB\-CSP\fR \fIname\fR" 4 -.IX Item "-CSP name" -Write \fIname\fR as a Microsoft \s-1CSP\s0 name. -The password source for the input, and for encrypting any private keys that -are output. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-LMK\fR" 4 -.IX Item "-LMK" -Add the \*(L"Local Key Set\*(R" identifier to the attributes. -.IP "\fB\-keyex\fR|\fB\-keysig\fR" 4 -.IX Item "-keyex|-keysig" -Specifies that the private key is to be used for key exchange or just signing. -This option is only interpreted by \s-1MSIE\s0 and similar \s-1MS\s0 software. Normally -\&\*(L"export grade\*(R" software will only allow 512 bit \s-1RSA\s0 keys to be used for -encryption purposes but arbitrary length keys for signing. The \fB\-keysig\fR -option marks the key for signing only. Signing only keys can be used for -S/MIME signing, authenticode (ActiveX control signing) and \s-1SSL\s0 client -authentication, however, due to a bug only \s-1MSIE 5.0\s0 and later support -the use of signing only keys for \s-1SSL\s0 client authentication. -.IP "\fB\-keypbe\fR \fIalg\fR, \fB\-certpbe\fR \fIalg\fR" 4 -.IX Item "-keypbe alg, -certpbe alg" -These options allow the algorithm used to encrypt the private key and -certificates to be selected. Any PKCS#5 v1.5 or PKCS#12 \s-1PBE\s0 algorithm name -can be used (see \*(L"\s-1NOTES\*(R"\s0 section for more information). If a cipher name -(as output by \f(CW\*(C`openssl list \-cipher\-algorithms\*(C'\fR) is specified then it -is used with PKCS#5 v2.0. For interoperability reasons it is advisable to only -use PKCS#12 algorithms. -.Sp -Special value \f(CW\*(C`NONE\*(C'\fR disables encryption of the private key and certificates. -.IP "\fB\-descert\fR" 4 -.IX Item "-descert" -Encrypt the certificates using triple \s-1DES.\s0 By default the private -key and the certificates are encrypted using \s-1AES\-256\-CBC\s0 unless -the '\-legacy' option is used. If '\-descert' is used with the '\-legacy' -then both, the private key and the certificates are encrypted using triple \s-1DES.\s0 -.IP "\fB\-macalg\fR \fIdigest\fR" 4 -.IX Item "-macalg digest" -Specify the \s-1MAC\s0 digest algorithm. If not included \s-1SHA256\s0 will be used. -.IP "\fB\-pbmac1_pbkdf2\fR" 4 -.IX Item "-pbmac1_pbkdf2" -Use \s-1PBMAC1\s0 with \s-1PBKDF2\s0 for \s-1MAC\s0 protection of the PKCS#12 file. -.IP "\fB\-pbmac1_pbkdf2_md\fR \fIdigest\fR" 4 -.IX Item "-pbmac1_pbkdf2_md digest" -Specify the \s-1PBKDF2 KDF\s0 digest algorithm. If not specified, \s-1SHA256\s0 will be used. -Unless \f(CW\*(C`\-pbmac1_pbkdf2\*(C'\fR is specified, this parameter is ignored. -.IP "\fB\-iter\fR \fIcount\fR" 4 -.IX Item "-iter count" -This option specifies the iteration count for the encryption key and \s-1MAC.\s0 The -default value is 2048. -.Sp -To discourage attacks by using large dictionaries of common passwords the -algorithm that derives keys from passwords can have an iteration count applied -to it: this causes a certain part of the algorithm to be repeated and slows it -down. The \s-1MAC\s0 is used to check the file integrity but since it will normally -have the same password as the keys and certificates it could also be attacked. -.IP "\fB\-noiter\fR, \fB\-nomaciter\fR" 4 -.IX Item "-noiter, -nomaciter" -By default both encryption and \s-1MAC\s0 iteration counts are set to 2048, using -these options the \s-1MAC\s0 and encryption iteration counts can be set to 1, since -this reduces the file security you should not use these options unless you -really have to. Most software supports both \s-1MAC\s0 and encryption iteration counts. -\&\s-1MSIE 4.0\s0 doesn't support \s-1MAC\s0 iteration counts so it needs the \fB\-nomaciter\fR -option. -.IP "\fB\-maciter\fR" 4 -.IX Item "-maciter" -This option is included for compatibility with previous versions, it used -to be needed to use \s-1MAC\s0 iterations counts but they are now used by default. -.IP "\fB\-macsaltlen\fR" 4 -.IX Item "-macsaltlen" -This option specifies the salt length in bytes for the \s-1MAC.\s0 The salt length -should be at least 16 bytes as per \s-1NIST SP 800\-132.\s0 The default value -is 8 bytes for backwards compatibility. -.IP "\fB\-nomac\fR" 4 -.IX Item "-nomac" -Do not attempt to provide the \s-1MAC\s0 integrity. This can be useful with the \s-1FIPS\s0 -provider as the \s-1PKCS12 MAC\s0 requires \s-1PKCS12KDF\s0 which is not an approved \s-1FIPS\s0 -algorithm and cannot be supported by the \s-1FIPS\s0 provider. -.IP "\fB\-jdktrust\fR" 4 -.IX Item "-jdktrust" -Export pkcs12 file in a format compatible with Java keystore usage. This option -accepts a string parameter indicating the trust oid name to be granted to the -certificate it is associated with. Currently only \*(L"anyExtendedKeyUsage\*(R" is -defined. Note that, as Java keystores do not accept \s-1PKCS12\s0 files with both -trusted certificates and keypairs, use of this option implies the setting of the -\&\fB\-nokeys\fR option -.SH "NOTES" -.IX Header "NOTES" -Although there are a large number of options most of them are very rarely -used. For PKCS#12 file parsing only \fB\-in\fR and \fB\-out\fR need to be used -for PKCS#12 file creation \fB\-export\fR and \fB\-name\fR are also used. -.PP -If none of the \fB\-clcerts\fR, \fB\-cacerts\fR or \fB\-nocerts\fR options are present -then all certificates will be output in the order they appear in the input -PKCS#12 files. There is no guarantee that the first certificate present is -the one corresponding to the private key. -Certain software which tries to get a private key and the corresponding -certificate might assume that the first certificate in the file is the one -corresponding to the private key, but that may not always be the case. -Using the \fB\-clcerts\fR option will solve this problem by only -outputting the certificate corresponding to the private key. If the \s-1CA\s0 -certificates are required then they can be output to a separate file using -the \fB\-nokeys\fR \fB\-cacerts\fR options to just output \s-1CA\s0 certificates. -.PP -The \fB\-keypbe\fR and \fB\-certpbe\fR algorithms allow the precise encryption -algorithms for private keys and certificates to be specified. Normally -the defaults are fine but occasionally software can't handle triple \s-1DES\s0 -encrypted private keys, then the option \fB\-keypbe\fR \fI\s-1PBE\-SHA1\-RC2\-40\s0\fR can -be used to reduce the private key encryption to 40 bit \s-1RC2. A\s0 complete -description of all algorithms is contained in \fBopenssl\-pkcs8\fR\|(1). -.PP -Prior 1.1 release passwords containing non-ASCII characters were encoded -in non-compliant manner, which limited interoperability, in first hand -with Windows. But switching to standard-compliant password encoding -poses problem accessing old data protected with broken encoding. For -this reason even legacy encodings is attempted when reading the -data. If you use PKCS#12 files in production application you are advised -to convert the data, because implemented heuristic approach is not -MT-safe, its sole goal is to facilitate the data upgrade with this -command. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Parse a PKCS#12 file and output it to a \s-1PEM\s0 file: -.PP -.Vb 1 -\& openssl pkcs12 \-in file.p12 \-out file.pem -.Ve -.PP -Output only client certificates to a file: -.PP -.Vb 1 -\& openssl pkcs12 \-in file.p12 \-clcerts \-out file.pem -.Ve -.PP -Don't encrypt the private key: -.PP -.Vb 1 -\& openssl pkcs12 \-in file.p12 \-out file.pem \-noenc -.Ve -.PP -Print some info about a PKCS#12 file: -.PP -.Vb 1 -\& openssl pkcs12 \-in file.p12 \-info \-noout -.Ve -.PP -Print some info about a PKCS#12 file in legacy mode: -.PP -.Vb 1 -\& openssl pkcs12 \-in file.p12 \-info \-noout \-legacy -.Ve -.PP -Create a PKCS#12 file from a \s-1PEM\s0 file that may contain a key and certificates: -.PP -.Vb 1 -\& openssl pkcs12 \-export \-in file.pem \-out file.p12 \-name "My PSE" -.Ve -.PP -Include some extra certificates: -.PP -.Vb 2 -\& openssl pkcs12 \-export \-in file.pem \-out file.p12 \-name "My PSE" \e -\& \-certfile othercerts.pem -.Ve -.PP -Export a PKCS#12 file with data from a certificate \s-1PEM\s0 file and from a further -\&\s-1PEM\s0 file containing a key, with default algorithms as in the legacy provider: -.PP -.Vb 1 -\& openssl pkcs12 \-export \-in cert.pem \-inkey key.pem \-out file.p12 \-legacy -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkcs8\fR\|(1), -\&\fBossl_store\-file\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -The \fB\-nodes\fR option was deprecated in OpenSSL 3.0, too; use \fB\-noenc\fR instead. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-pkcs7.1ossl b/openssl-install/share/man/man1/openssl-pkcs7.1ossl deleted file mode 100644 index 28128b77..00000000 --- a/openssl-install/share/man/man1/openssl-pkcs7.1ossl +++ /dev/null @@ -1,243 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PKCS7 1ossl" -.TH OPENSSL-PKCS7 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-pkcs7 \- PKCS#7 command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBpkcs7\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-print\fR] -[\fB\-print_certs\fR] -[\fB\-quiet\fR] -[\fB\-text\fR] -[\fB\-noout\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes PKCS#7 files. Note that it only understands PKCS#7 -v 1.5 as specified in \s-1IETF RFC 2315.\s0 It cannot currently parse \s-1CMS\s0 as -described in \s-1IETF RFC 2630.\s0 -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR, \fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM, -outform DER|PEM" -The input and formats; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -The data is a PKCS#7 Version 1.5 structure. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read from or standard input if this -option is not specified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Specifies the output filename to write to or standard output by -default. -.IP "\fB\-print\fR" 4 -.IX Item "-print" -Print out the full \s-1PKCS7\s0 object. -.IP "\fB\-print_certs\fR" 4 -.IX Item "-print_certs" -Prints out any certificates or CRLs contained in the file. They are -preceded by their subject and issuer names in one line format. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -When used with \-print_certs, prints out just the PEM-encoded -certificates without any other output. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out certificate details in full rather than just subject and -issuer names. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -Don't output the encoded version of the PKCS#7 structure (or certificates -if \fB\-print_certs\fR is set). -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Convert a PKCS#7 file from \s-1PEM\s0 to \s-1DER:\s0 -.PP -.Vb 1 -\& openssl pkcs7 \-in file.pem \-outform DER \-out file.der -.Ve -.PP -Output all certificates in a file: -.PP -.Vb 1 -\& openssl pkcs7 \-in file.pem \-print_certs \-out certs.pem -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-crl2pkcs7\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-pkcs8.1ossl b/openssl-install/share/man/man1/openssl-pkcs8.1ossl deleted file mode 100644 index a9108e39..00000000 --- a/openssl-install/share/man/man1/openssl-pkcs8.1ossl +++ /dev/null @@ -1,424 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PKCS8 1ossl" -.TH OPENSSL-PKCS8 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-pkcs8 \- PKCS#8 format private key conversion command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBpkcs8\fR -[\fB\-help\fR] -[\fB\-topk8\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-iter\fR \fIcount\fR] -[\fB\-noiter\fR] -[\fB\-nocrypt\fR] -[\fB\-traditional\fR] -[\fB\-v2\fR \fIalg\fR] -[\fB\-v2prf\fR \fIalg\fR] -[\fB\-v1\fR \fIalg\fR] -[\fB\-scrypt\fR] -[\fB\-scrypt_N\fR \fIN\fR] -[\fB\-scrypt_r\fR \fIr\fR] -[\fB\-scrypt_p\fR \fIp\fR] -[\fB\-saltlen\fR \fIsize\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes private keys in PKCS#8 format. It can handle -both unencrypted PKCS#8 PrivateKeyInfo format and EncryptedPrivateKeyInfo -format with a variety of PKCS#5 (v1.5 and v2.0) and PKCS#12 algorithms. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-topk8\fR" 4 -.IX Item "-topk8" -Normally a PKCS#8 private key is expected on input and a private key will be -written to the output file. With the \fB\-topk8\fR option the situation is -reversed: it reads a private key and writes a PKCS#8 format key. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR, \fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM, -outform DER|PEM" -The input and formats; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -If a key is being converted from PKCS#8 form (i.e. the \fB\-topk8\fR option is -not used) then the input file must be in PKCS#8 format. An encrypted -key is expected unless \fB\-nocrypt\fR is included. -.Sp -If \fB\-topk8\fR is not used and \fB\s-1PEM\s0\fR mode is set the output file will be an -unencrypted private key in PKCS#8 format. If the \fB\-traditional\fR option is -used then a traditional format private key is written instead. -.Sp -If \fB\-topk8\fR is not used and \fB\s-1DER\s0\fR mode is set the output file will be an -unencrypted private key in traditional \s-1DER\s0 format. -.Sp -If \fB\-topk8\fR is used then any supported private key can be used for the input -file in a format specified by \fB\-inform\fR. The output file will be encrypted -PKCS#8 format using the specified encryption parameters unless \fB\-nocrypt\fR -is included. -.IP "\fB\-traditional\fR" 4 -.IX Item "-traditional" -When this option is present and \fB\-topk8\fR is not a traditional format private -key is written. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read a key from or standard input if this -option is not specified. If the key is encrypted a pass phrase will be -prompted for. -.IP "\fB\-passin\fR \fIarg\fR, \fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passin arg, -passout arg" -The password source for the input and output file. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write a key to or standard output by -default. If any encryption options are set then a pass phrase will be -prompted for. The output filename should \fBnot\fR be the same as the input -filename. -.IP "\fB\-iter\fR \fIcount\fR" 4 -.IX Item "-iter count" -When creating new PKCS#8 containers, use a given number of iterations on -the password in deriving the encryption key for the PKCS#8 output. -High values increase the time required to brute-force a PKCS#8 container. -.IP "\fB\-noiter\fR" 4 -.IX Item "-noiter" -When creating new PKCS#8 containers, use 1 as iteration count. -.IP "\fB\-nocrypt\fR" 4 -.IX Item "-nocrypt" -PKCS#8 keys generated or input are normally PKCS#8 EncryptedPrivateKeyInfo -structures using an appropriate password based encryption algorithm. With -this option an unencrypted PrivateKeyInfo structure is expected or output. -This option does not encrypt private keys at all and should only be used -when absolutely necessary. Certain software such as some versions of Java -code signing software used unencrypted private keys. -.IP "\fB\-v2\fR \fIalg\fR" 4 -.IX Item "-v2 alg" -This option sets the PKCS#5 v2.0 algorithm. -.Sp -The \fIalg\fR argument is the encryption algorithm to use, valid values include -\&\fBaes128\fR, \fBaes256\fR and \fBdes3\fR. If this option isn't specified then \fBaes256\fR -is used. -.IP "\fB\-v2prf\fR \fIalg\fR" 4 -.IX Item "-v2prf alg" -This option sets the \s-1PRF\s0 algorithm to use with PKCS#5 v2.0. A typical value -value would be \fBhmacWithSHA256\fR. If this option isn't set then the default -for the cipher is used or \fBhmacWithSHA256\fR if there is no default. -.Sp -Some implementations may not support custom \s-1PRF\s0 algorithms and may require -the \fBhmacWithSHA1\fR option to work. -.IP "\fB\-v1\fR \fIalg\fR" 4 -.IX Item "-v1 alg" -This option indicates a PKCS#5 v1.5 or PKCS#12 algorithm should be used. Some -older implementations may not support PKCS#5 v2.0 and may require this option. -If not specified PKCS#5 v2.0 form is used. -.IP "\fB\-scrypt\fR" 4 -.IX Item "-scrypt" -Uses the \fBscrypt\fR algorithm for private key encryption using default -parameters: currently N=16384, r=8 and p=1 and \s-1AES\s0 in \s-1CBC\s0 mode with a 256 bit -key. These parameters can be modified using the \fB\-scrypt_N\fR, \fB\-scrypt_r\fR, -\&\fB\-scrypt_p\fR and \fB\-v2\fR options. -.IP "\fB\-scrypt_N\fR \fIN\fR, \fB\-scrypt_r\fR \fIr\fR, \fB\-scrypt_p\fR \fIp\fR" 4 -.IX Item "-scrypt_N N, -scrypt_r r, -scrypt_p p" -Sets the scrypt \fIN\fR, \fIr\fR or \fIp\fR parameters. -.IP "\fB\-saltlen\fR" 4 -.IX Item "-saltlen" -Sets the length (in bytes) of the salt to use for the \s-1PBE\s0 algorithm. -If this value is not specified, the default for \s-1PBES2\s0 is 16 (128 bits) -and 8 (64 bits) for \s-1PBES1.\s0 -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -By default, when converting a key to PKCS#8 format, PKCS#5 v2.0 using 256 bit -\&\s-1AES\s0 with \s-1HMAC\s0 and \s-1SHA256\s0 is used. -.PP -Some older implementations do not support PKCS#5 v2.0 format and require -the older PKCS#5 v1.5 form instead, possibly also requiring insecure weak -encryption algorithms such as 56 bit \s-1DES.\s0 -.PP -Private keys encrypted using PKCS#5 v2.0 algorithms and high iteration -counts are more secure that those encrypted using the traditional -SSLeay compatible formats. So if additional security is considered -important the keys should be converted. -.PP -It is possible to write out \s-1DER\s0 encoded encrypted private keys in -PKCS#8 format because the encryption details are included at an \s-1ASN1\s0 -level whereas the traditional format includes them at a \s-1PEM\s0 level. -.SH "PKCS#5 V1.5 AND PKCS#12 ALGORITHMS" -.IX Header "PKCS#5 V1.5 AND PKCS#12 ALGORITHMS" -Various algorithms can be used with the \fB\-v1\fR command line option, -including PKCS#5 v1.5 and PKCS#12. These are described in more detail -below. -.IP "\fB\s-1PBE\-MD2\-DES PBE\-MD5\-DES\s0\fR" 4 -.IX Item "PBE-MD2-DES PBE-MD5-DES" -These algorithms were included in the original PKCS#5 v1.5 specification. -They only offer 56 bits of protection since they both use \s-1DES.\s0 -.IP "\fB\s-1PBE\-SHA1\-RC2\-64\s0\fR, \fB\s-1PBE\-MD2\-RC2\-64\s0\fR, \fB\s-1PBE\-MD5\-RC2\-64\s0\fR, \fB\s-1PBE\-SHA1\-DES\s0\fR" 4 -.IX Item "PBE-SHA1-RC2-64, PBE-MD2-RC2-64, PBE-MD5-RC2-64, PBE-SHA1-DES" -These algorithms are not mentioned in the original PKCS#5 v1.5 specification -but they use the same key derivation algorithm and are supported by some -software. They are mentioned in PKCS#5 v2.0. They use either 64 bit \s-1RC2\s0 or -56 bit \s-1DES.\s0 -.IP "\fB\s-1PBE\-SHA1\-RC4\-128\s0\fR, \fB\s-1PBE\-SHA1\-RC4\-40\s0\fR, \fB\s-1PBE\-SHA1\-3DES\s0\fR, \fB\s-1PBE\-SHA1\-2DES\s0\fR, \fB\s-1PBE\-SHA1\-RC2\-128\s0\fR, \fB\s-1PBE\-SHA1\-RC2\-40\s0\fR" 4 -.IX Item "PBE-SHA1-RC4-128, PBE-SHA1-RC4-40, PBE-SHA1-3DES, PBE-SHA1-2DES, PBE-SHA1-RC2-128, PBE-SHA1-RC2-40" -These algorithms use the PKCS#12 password based encryption algorithm and -allow strong encryption algorithms like triple \s-1DES\s0 or 128 bit \s-1RC2\s0 to be used. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Convert a private key to PKCS#8 format using default parameters (\s-1AES\s0 with -256 bit key and \fBhmacWithSHA256\fR): -.PP -.Vb 1 -\& openssl pkcs8 \-in key.pem \-topk8 \-out enckey.pem -.Ve -.PP -Convert a private key to PKCS#8 unencrypted format: -.PP -.Vb 1 -\& openssl pkcs8 \-in key.pem \-topk8 \-nocrypt \-out enckey.pem -.Ve -.PP -Convert a private key to PKCS#5 v2.0 format using triple \s-1DES:\s0 -.PP -.Vb 1 -\& openssl pkcs8 \-in key.pem \-topk8 \-v2 des3 \-out enckey.pem -.Ve -.PP -Convert a private key to PKCS#5 v2.0 format using \s-1AES\s0 with 256 bits in \s-1CBC\s0 -mode and \fBhmacWithSHA512\fR \s-1PRF:\s0 -.PP -.Vb 1 -\& openssl pkcs8 \-in key.pem \-topk8 \-v2 aes\-256\-cbc \-v2prf hmacWithSHA512 \-out enckey.pem -.Ve -.PP -Convert a private key to PKCS#8 using a PKCS#5 1.5 compatible algorithm -(\s-1DES\s0): -.PP -.Vb 1 -\& openssl pkcs8 \-in key.pem \-topk8 \-v1 PBE\-MD5\-DES \-out enckey.pem -.Ve -.PP -Convert a private key to PKCS#8 using a PKCS#12 compatible algorithm -(3DES): -.PP -.Vb 1 -\& openssl pkcs8 \-in key.pem \-topk8 \-out enckey.pem \-v1 PBE\-SHA1\-3DES -.Ve -.PP -Read a \s-1DER\s0 unencrypted PKCS#8 format private key: -.PP -.Vb 1 -\& openssl pkcs8 \-inform DER \-nocrypt \-in key.der \-out key.pem -.Ve -.PP -Convert a private key from any PKCS#8 encrypted format to traditional format: -.PP -.Vb 1 -\& openssl pkcs8 \-in pk8.pem \-traditional \-out key.pem -.Ve -.PP -Convert a private key to PKCS#8 format, encrypting with \s-1AES\-256\s0 and with -one million iterations of the password: -.PP -.Vb 1 -\& openssl pkcs8 \-in key.pem \-topk8 \-v2 aes\-256\-cbc \-iter 1000000 \-out pk8.pem -.Ve -.SH "STANDARDS" -.IX Header "STANDARDS" -Test vectors from this PKCS#5 v2.0 implementation were posted to the -pkcs-tng mailing list using triple \s-1DES, DES\s0 and \s-1RC2\s0 with high iteration -counts, several people confirmed that they could decrypt the private -keys produced and therefore, it can be assumed that the PKCS#5 v2.0 -implementation is reasonably accurate at least as far as these -algorithms are concerned. -.PP -The format of PKCS#8 \s-1DSA\s0 (and other) private keys is not well documented: -it is hidden away in PKCS#11 v2.01, section 11.9. OpenSSL's default \s-1DSA\s0 -PKCS#8 private key format complies with this standard. -.SH "BUGS" -.IX Header "BUGS" -There should be an option that prints out the encryption algorithm -in use and other details such as the iteration count. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-iter\fR option was added in OpenSSL 1.1.0. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-pkey.1ossl b/openssl-install/share/man/man1/openssl-pkey.1ossl deleted file mode 100644 index b4e0a828..00000000 --- a/openssl-install/share/man/man1/openssl-pkey.1ossl +++ /dev/null @@ -1,361 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PKEY 1ossl" -.TH OPENSSL-PKEY 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-pkey \- public or private key processing command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBpkey\fR -[\fB\-help\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-check\fR] -[\fB\-pubcheck\fR] -[\fB\-in\fR \fIfilename\fR|\fIuri\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-pubin\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-\f(BIcipher\fB\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-traditional\fR] -[\fB\-pubout\fR] -[\fB\-noout\fR] -[\fB\-text\fR] -[\fB\-text_pub\fR] -[\fB\-ec_conv_form\fR \fIarg\fR] -[\fB\-ec_param_enc\fR \fIarg\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes public or private keys. They can be -converted between various forms and their components printed. -.SH "OPTIONS" -.IX Header "OPTIONS" -.SS "General options" -.IX Subsection "General options" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-check\fR" 4 -.IX Item "-check" -This option checks the consistency of a key pair for both public and private -components. -.IP "\fB\-pubcheck\fR" 4 -.IX Item "-pubcheck" -This option checks the correctness of either a public key -or the public component of a key pair. -.SS "Input options" -.IX Subsection "Input options" -.IP "\fB\-in\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-in filename|uri" -This specifies the input to read a key from -or standard input if this option is not specified. -If the key input is encrypted and \fB\-passin\fR is not given -a pass phrase will be prompted for. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-inform DER|PEM|P12|ENGINE" -The key input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The password source for the key input. -.Sp -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-pubin\fR" 4 -.IX Item "-pubin" -By default a private key is read from the input. -With this option a public key is read instead. -If the input contains no public key but a private key, its public part is used. -.SS "Output options" -.IX Subsection "Output options" -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to save the encoded and/or text output of key -or standard output if this option is not specified. -If any cipher option is set but no \fB\-passout\fR is given -then a pass phrase will be prompted for. -The output filename should \fBnot\fR be the same as the input filename. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The key output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-\f(BIcipher\fB\fR" 4 -.IX Item "-cipher" -Encrypt the \s-1PEM\s0 encoded private key with the supplied cipher. Any algorithm -name accepted by \fBEVP_get_cipherbyname()\fR is acceptable such as \fBaes128\fR. -Encryption is not supported for \s-1DER\s0 output. -.IP "\fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passout arg" -The password source for the output file. -.Sp -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-traditional\fR" 4 -.IX Item "-traditional" -Normally a private key is written using standard format: this is PKCS#8 form -with the appropriate encryption algorithm (if any). If the \fB\-traditional\fR -option is specified then the older \*(L"traditional\*(R" format is used instead. -.IP "\fB\-pubout\fR" 4 -.IX Item "-pubout" -By default the private and public key is output; -this option restricts the output to the public components. -This option is automatically set if the input is a public key. -.Sp -When combined with \fB\-text\fR, this is equivalent to \fB\-text_pub\fR. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -Do not output the key in encoded form. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Output the various key components in plain text -(possibly in addition to the \s-1PEM\s0 encoded form). -This cannot be combined with encoded output in \s-1DER\s0 format. -.IP "\fB\-text_pub\fR" 4 -.IX Item "-text_pub" -Output in text form only the public key components (also for private keys). -This cannot be combined with encoded output in \s-1DER\s0 format. -.IP "\fB\-ec_conv_form\fR \fIarg\fR" 4 -.IX Item "-ec_conv_form arg" -This option only applies to elliptic-curve based keys. -.Sp -This specifies how the points on the elliptic curve are converted -into octet strings. Possible values are: \fBcompressed\fR (the default -value), \fBuncompressed\fR and \fBhybrid\fR. For more information regarding -the point conversion forms please read the X9.62 standard. -\&\fBNote\fR Due to patent issues the \fBcompressed\fR option is disabled -by default for binary curves and can be enabled by defining -the preprocessor macro \fB\s-1OPENSSL_EC_BIN_PT_COMP\s0\fR at compile time. -.IP "\fB\-ec_param_enc\fR \fIarg\fR" 4 -.IX Item "-ec_param_enc arg" -This option only applies to elliptic curve based public and private keys. -.Sp -This specifies how the elliptic curve parameters are encoded. -Possible value are: \fBnamed_curve\fR, i.e. the ec parameters are -specified by an \s-1OID,\s0 or \fBexplicit\fR where the ec parameters are -explicitly given (see \s-1RFC 3279\s0 for the definition of the -\&\s-1EC\s0 parameters structures). The default value is \fBnamed_curve\fR. -\&\fBNote\fR the \fBimplicitlyCA\fR alternative, as specified in \s-1RFC 3279,\s0 -is currently not implemented in OpenSSL. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To remove the pass phrase on a private key: -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-out keyout.pem -.Ve -.PP -To encrypt a private key using triple \s-1DES:\s0 -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-des3 \-out keyout.pem -.Ve -.PP -To convert a private key from \s-1PEM\s0 to \s-1DER\s0 format: -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-outform DER \-out keyout.der -.Ve -.PP -To print out the components of a private key to standard output: -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-text \-noout -.Ve -.PP -To print out the public components of a private key to standard output: -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-text_pub \-noout -.Ve -.PP -To just output the public part of a private key: -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-pubout \-out pubkey.pem -.Ve -.PP -To change the \s-1EC\s0 parameters encoding to \fBexplicit\fR: -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-ec_param_enc explicit \-out keyout.pem -.Ve -.PP -To change the \s-1EC\s0 point conversion form to \fBcompressed\fR: -.PP -.Vb 1 -\& openssl pkey \-in key.pem \-ec_conv_form compressed \-out keyout.pem -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-pkcs8\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-pkeyparam.1ossl b/openssl-install/share/man/man1/openssl-pkeyparam.1ossl deleted file mode 100644 index ea9cf23c..00000000 --- a/openssl-install/share/man/man1/openssl-pkeyparam.1ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PKEYPARAM 1ossl" -.TH OPENSSL-PKEYPARAM 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-pkeyparam \- public key algorithm parameter processing command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBpkeyparam\fR -[\fB\-help\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-text\fR] -[\fB\-noout\fR] -[\fB\-check\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes public key algorithm parameters. -They can be checked for correctness and their components printed out. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read parameters from or standard input if -this option is not specified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write parameters to or standard output if -this option is not specified. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the parameters in plain text in addition to the encoded version. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -Do not output the encoded version of the parameters. -.IP "\fB\-check\fR" 4 -.IX Item "-check" -This option checks the correctness of parameters. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Print out text version of parameters: -.PP -.Vb 1 -\& openssl pkeyparam \-in param.pem \-text -.Ve -.SH "NOTES" -.IX Header "NOTES" -There are no \fB\-inform\fR or \fB\-outform\fR options for this command because only -\&\s-1PEM\s0 format is supported because the key type is determined by the \s-1PEM\s0 headers. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-pkcs8\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-pkeyutl.1ossl b/openssl-install/share/man/man1/openssl-pkeyutl.1ossl deleted file mode 100644 index d2e9ab67..00000000 --- a/openssl-install/share/man/man1/openssl-pkeyutl.1ossl +++ /dev/null @@ -1,615 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PKEYUTL 1ossl" -.TH OPENSSL-PKEYUTL 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-pkeyutl \- asymmetric key command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBpkeyutl\fR -[\fB\-help\fR] -[\fB\-in\fR \fIfile\fR] -[\fB\-rawin\fR] -[\fB\-digest\fR \fIalgorithm\fR] -[\fB\-out\fR \fIfile\fR] -[\fB\-secret\fR \fIfile\fR] -[\fB\-sigfile\fR \fIfile\fR] -[\fB\-inkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-pubin\fR] -[\fB\-certin\fR] -[\fB\-rev\fR] -[\fB\-sign\fR] -[\fB\-verify\fR] -[\fB\-verifyrecover\fR] -[\fB\-encrypt\fR] -[\fB\-decrypt\fR] -[\fB\-derive\fR] -[\fB\-peerkey\fR \fIfile\fR] -[\fB\-peerform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-encap\fR] -[\fB\-decap\fR] -[\fB\-kdf\fR \fIalgorithm\fR] -[\fB\-kdflen\fR \fIlength\fR] -[\fB\-kemop\fR \fIoperation\fR] -[\fB\-pkeyopt\fR \fIopt\fR:\fIvalue\fR] -[\fB\-pkeyopt_passin\fR \fIopt\fR[:\fIpassarg\fR]] -[\fB\-hexdump\fR] -[\fB\-asn1parse\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-engine_impl\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-config\fR \fIconfigfile\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command can be used to perform low-level operations -on asymmetric (public or private) keys using any supported algorithm. -.PP -By default the signing operation (see \fB\-sign\fR option) is assumed. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read data from or standard input -if this option is not specified. -.IP "\fB\-rawin\fR" 4 -.IX Item "-rawin" -This indicates that the signature or verification input data is raw data, -which is not hashed by any message digest algorithm. -Except with EdDSA, -the user can specify a digest algorithm by using the \fB\-digest\fR option. -For signature algorithms like \s-1RSA, DSA\s0 and \s-1ECDSA,\s0 -the default digest algorithm is \s-1SHA256.\s0 For \s-1SM2,\s0 it is \s-1SM3.\s0 -.Sp -This option can only be used with \fB\-sign\fR and \fB\-verify\fR. -For EdDSA (the Ed25519 and Ed448 algorithms) this option is required. -.IP "\fB\-digest\fR \fIalgorithm\fR" 4 -.IX Item "-digest algorithm" -This option can only be used with \fB\-sign\fR and \fB\-verify\fR. -It specifies the digest algorithm that is used to hash the input data -before signing or verifying it with the input key. This option could be omitted -if the signature algorithm does not require preprocessing the input through -a pluggable hash function before signing (for instance, EdDSA). If this option -is omitted but the signature algorithm requires one and the \fB\-rawin\fR option -is given, a default value will be used (see \fB\-rawin\fR for details). -If this option is present, then the \fB\-rawin\fR option is required. -.Sp -At this time, HashEdDSA (the ph or \*(L"prehash\*(R" variant of EdDSA) is not supported, -so the \fB\-digest\fR option cannot be used with EdDSA. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Specifies the output filename to write to or standard output by default. -.IP "\fB\-secret\fR \fIfilename\fR" 4 -.IX Item "-secret filename" -Specifies the output filename to write the secret to on \fI\-encap\fR. -.IP "\fB\-sigfile\fR \fIfile\fR" 4 -.IX Item "-sigfile file" -Signature file, required and allowed for \fB\-verify\fR operations only. -.IP "\fB\-inkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-inkey filename|uri" -The input key, by default it should be a private key. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The key format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The input key password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-pubin\fR" 4 -.IX Item "-pubin" -By default a private key is read from the key input. -With this option a public key is read instead. -If the input contains no public key but a private key, its public part is used. -.IP "\fB\-certin\fR" 4 -.IX Item "-certin" -The input is a certificate containing a public key. -.IP "\fB\-rev\fR" 4 -.IX Item "-rev" -Reverse the order of the input buffer. This is useful for some libraries -(such as CryptoAPI) which represent the buffer in little-endian format. -This cannot be used in conjunction with \fB\-rawin\fR. -.IP "\fB\-sign\fR" 4 -.IX Item "-sign" -Sign the input data and output the signed result. This requires a private key. -Using a message digest operation along with this is recommended, -when applicable, see the \fB\-rawin\fR and \fB\-digest\fR options for details. -Otherwise, the input data given with the \fB\-in\fR option is assumed to already -be a digest, but this may then require an additional \fB\-pkeyopt\fR \f(CW\*(C`digest:\*(C'\fR\fImd\fR -in some cases (e.g., \s-1RSA\s0 with the default PKCS#1 padding mode). -Even for other algorithms like \s-1ECDSA,\s0 where the additional \fB\-pkeyopt\fR option -does not affect signature output, it is recommended, as it enables -checking that the input length is consistent with the intended digest. -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verify the input data against the signature given with the \fB\-sigfile\fR option -and indicate if the verification succeeded or failed. -The input data given with the \fB\-in\fR option is assumed to be a hash value -unless the \fB\-rawin\fR option is specified or implied. -With raw data, when a digest algorithm is applicable, though it may be inferred -from the signature or take a default value, it should also be specified. -.IP "\fB\-verifyrecover\fR" 4 -.IX Item "-verifyrecover" -Verify the given signature and output the recovered data (signature payload). -For example, in case of \s-1RSA\s0 PKCS#1 the recovered data is the \fBEMSA\-PKCS\-v1_5\fR -\&\s-1DER\s0 encoding of the digest algorithm \s-1OID\s0 and value as specified in -\&\s-1RFC8017\s0 Section 9.2 . -.Sp -Note that here the input given with the \fB\-in\fR option is not a signature input -(as with the \fB\-sign\fR and \fB\-verify\fR options) but a signature output value, -typically produced using the \fB\-sign\fR option. -.Sp -This option is available only for use with \s-1RSA\s0 keys. -.IP "\fB\-encrypt\fR" 4 -.IX Item "-encrypt" -Encrypt the input data using a public key. -.IP "\fB\-decrypt\fR" 4 -.IX Item "-decrypt" -Decrypt the input data using a private key. -.IP "\fB\-derive\fR" 4 -.IX Item "-derive" -Derive a shared secret using own private (\s-1EC\s0)DH key and peer key. -.IP "\fB\-peerkey\fR \fIfile\fR" 4 -.IX Item "-peerkey file" -File containing the peer public or private (\s-1EC\s0)DH key -to use with the key derivation (agreement) operation. -Its type must match the type of the own private key given with \fB\-inkey\fR. -.IP "\fB\-peerform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-peerform DER|PEM|P12|ENGINE" -The peer key format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-encap\fR" 4 -.IX Item "-encap" -Encapsulate a generated secret using a private key. -The encapsulated result (binary data) is written to standard output by default, -or else to the file specified with \fI\-out\fR. -The \fI\-secret\fR option must also be provided to specify the output file for the -secret value generated in the encapsulation process. -.IP "\fB\-decap\fR" 4 -.IX Item "-decap" -Decapsulate the secret using a private key. -The result (binary data) is written to standard output by default, or else to -the file specified with \fI\-out\fR. -.IP "\fB\-kemop\fR \fIoperation\fR" 4 -.IX Item "-kemop operation" -This option is used for \fI\-encap\fR/\fI\-decap\fR commands and specifies the \s-1KEM\s0 -operation specific for the key algorithm when there is no default \s-1KEM\s0 -operation. -If the algorithm has the default \s-1KEM\s0 operation, this option can be omitted. -.Sp -See \fBEVP_PKEY_CTX_set_kem_op\fR\|(3) and algorithm-specific \s-1KEM\s0 documentation e.g. -\&\s-1\fBEVP_KEM\-RSA\s0\fR\|(7), \s-1\fBEVP_KEM\-EC\s0\fR\|(7), \s-1\fBEVP_KEM\-X25519\s0\fR\|(7), and -\&\s-1\fBEVP_KEM\-X448\s0\fR\|(7). -.IP "\fB\-kdf\fR \fIalgorithm\fR" 4 -.IX Item "-kdf algorithm" -Use key derivation function \fIalgorithm\fR. The supported algorithms are -at present \fB\s-1TLS1\-PRF\s0\fR and \fB\s-1HKDF\s0\fR. -Note: additional parameters and the \s-1KDF\s0 output length will normally have to be -set for this to work. -See \fBEVP_PKEY_CTX_set_hkdf_md\fR\|(3) and \fBEVP_PKEY_CTX_set_tls1_prf_md\fR\|(3) -for the supported string parameters of each algorithm. -.IP "\fB\-kdflen\fR \fIlength\fR" 4 -.IX Item "-kdflen length" -Set the output length for \s-1KDF.\s0 -.IP "\fB\-pkeyopt\fR \fIopt\fR:\fIvalue\fR" 4 -.IX Item "-pkeyopt opt:value" -Public key options specified as opt:value. See \s-1NOTES\s0 below for more details. -.IP "\fB\-pkeyopt_passin\fR \fIopt\fR[:\fIpassarg\fR]" 4 -.IX Item "-pkeyopt_passin opt[:passarg]" -Allows reading a public key option \fIopt\fR from stdin or a password source. -If only \fIopt\fR is specified, the user will be prompted to enter a password on -stdin. Alternatively, \fIpassarg\fR can be specified which can be any value -supported by \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-hexdump\fR" 4 -.IX Item "-hexdump" -hex dump the output data. -.IP "\fB\-asn1parse\fR" 4 -.IX Item "-asn1parse" -Parse the \s-1ASN.1\s0 output data to check its \s-1DER\s0 encoding and print any errors. -When combined with the \fB\-verifyrecover\fR option, this may be useful in case -an \s-1ASN.1\s0 DER-encoded structure had been signed directly (without hashing it) -and when checking a signature in PKCS#1 v1.5 format, which has a \s-1DER\s0 encoding. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-engine_impl\fR" 4 -.IX Item "-engine_impl" -When used with the \fB\-engine\fR option, it specifies to also use -engine \fIid\fR for crypto operations. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-config\fR \fIconfigfile\fR" 4 -.IX Item "-config configfile" -See \*(L"Configuration Option\*(R" in \fBopenssl\fR\|(1). -.SH "NOTES" -.IX Header "NOTES" -The operations and options supported vary according to the key algorithm -and its implementation. The OpenSSL operations and options are indicated below. -.PP -Unless otherwise mentioned, the \fB\-pkeyopt\fR option supports -for all public-key types the \f(CW\*(C`digest:\*(C'\fR\fIalg\fR argument, -which specifies the digest in use for the signing and verification operations. -The value \fIalg\fR should represent a digest name as used in the -\&\fBEVP_get_digestbyname()\fR function for example \fBsha256\fR. This value is not used to -hash the input data. It is used (by some algorithms) for sanity-checking the -lengths of data passed in and for creating the structures that make up the -signature (e.g., \fBDigestInfo\fR in \s-1RSASSA\s0 PKCS#1 v1.5 signatures). -.PP -For instance, -if the value of the \fB\-pkeyopt\fR option \f(CW\*(C`digest\*(C'\fR argument is \fBsha256\fR, -the signature or verification input should be the 32 bytes long binary value -of the \s-1SHA256\s0 hash function output. -.PP -Unless \fB\-rawin\fR is used or implied, this command does not hash the input data -but rather it will use the data directly as input to the signature algorithm. -Depending on the key type, signature type, and mode of padding, the maximum -sensible lengths of input data differ. With \s-1RSA\s0 the signed data cannot be longer -than the key modulus. In case of \s-1ECDSA\s0 and \s-1DSA\s0 the data should not be longer -than the field size, otherwise it will be silently truncated to the field size. -In any event the input size must not be larger than the largest supported digest -output size \fB\s-1EVP_MAX_MD_SIZE\s0\fR, which currently is 64 bytes. -.SH "RSA ALGORITHM" -.IX Header "RSA ALGORITHM" -The \s-1RSA\s0 algorithm generally supports the encrypt, decrypt, sign, -verify and verifyrecover operations. However, some padding modes -support only a subset of these operations. The following additional -\&\fBpkeyopt\fR values are supported: -.IP "\fBrsa_padding_mode:\fR\fImode\fR" 4 -.IX Item "rsa_padding_mode:mode" -This sets the \s-1RSA\s0 padding mode. Acceptable values for \fImode\fR are \fBpkcs1\fR for -PKCS#1 padding, \fBnone\fR for no padding, \fBoaep\fR -for \fB\s-1OAEP\s0\fR mode, \fBx931\fR for X9.31 mode and \fBpss\fR for \s-1PSS.\s0 -.Sp -In PKCS#1 padding, if the message digest is not set, then the supplied data is -signed or verified directly instead of using a \fBDigestInfo\fR structure. If a -digest is set, then the \fBDigestInfo\fR structure is used and its length -must correspond to the digest type. -.Sp -Note, for \fBpkcs1\fR padding, as a protection against the Bleichenbacher attack, -the decryption will not fail in case of padding check failures. Use \fBnone\fR -and manual inspection of the decrypted message to verify if the decrypted -value has correct PKCS#1 v1.5 padding. -.Sp -For \fBoaep\fR mode only encryption and decryption is supported. -.Sp -For \fBx931\fR if the digest type is set it is used to format the block data -otherwise the first byte is used to specify the X9.31 digest \s-1ID.\s0 Sign, -verify and verifyrecover are can be performed in this mode. -.Sp -For \fBpss\fR mode only sign and verify are supported and the digest type must be -specified. -.IP "\fBrsa_pss_saltlen:\fR\fIlen\fR" 4 -.IX Item "rsa_pss_saltlen:len" -For \fBpss\fR mode only this option specifies the salt length. Three special -values are supported: \fBdigest\fR sets the salt length to the digest length, -\&\fBmax\fR sets the salt length to the maximum permissible value. When verifying -\&\fBauto\fR causes the salt length to be automatically determined based on the -\&\fB\s-1PSS\s0\fR block structure. -.IP "\fBrsa_mgf1_md:\fR\fIdigest\fR" 4 -.IX Item "rsa_mgf1_md:digest" -For \s-1PSS\s0 and \s-1OAEP\s0 padding sets the \s-1MGF1\s0 digest. If the \s-1MGF1\s0 digest is not -explicitly set in \s-1PSS\s0 mode then the signing digest is used. -.IP "\fBrsa_oaep_md:\fR\fIdigest\fR" 4 -.IX Item "rsa_oaep_md:digest" -Sets the digest used for the \s-1OAEP\s0 hash function. If not explicitly set then -\&\s-1SHA256\s0 is used. -.IP "\fBrsa_pkcs1_implicit_rejection:\fR\fIflag\fR" 4 -.IX Item "rsa_pkcs1_implicit_rejection:flag" -Disables (when set to 0) or enables (when set to 1) the use of implicit -rejection with PKCS#1 v1.5 decryption. When enabled (the default), as a -protection against Bleichenbacher attack, the library will generate a -deterministic random plaintext that it will return to the caller in case -of padding check failure. -When disabled, it's the callers' responsibility to handle the returned -errors in a side-channel free manner. -.SH "RSA-PSS ALGORITHM" -.IX Header "RSA-PSS ALGORITHM" -The RSA-PSS algorithm is a restricted version of the \s-1RSA\s0 algorithm which only -supports the sign and verify operations with \s-1PSS\s0 padding. The following -additional \fB\-pkeyopt\fR values are supported: -.IP "\fBrsa_padding_mode:\fR\fImode\fR, \fBrsa_pss_saltlen:\fR\fIlen\fR, \fBrsa_mgf1_md:\fR\fIdigest\fR" 4 -.IX Item "rsa_padding_mode:mode, rsa_pss_saltlen:len, rsa_mgf1_md:digest" -These have the same meaning as the \fB\s-1RSA\s0\fR algorithm with some additional -restrictions. The padding mode can only be set to \fBpss\fR which is the -default value. -.Sp -If the key has parameter restrictions then the digest, \s-1MGF1\s0 -digest and salt length are set to the values specified in the parameters. -The digest and \s-1MG\s0 cannot be changed and the salt length cannot be set to a -value less than the minimum restriction. -.SH "DSA ALGORITHM" -.IX Header "DSA ALGORITHM" -The \s-1DSA\s0 algorithm supports signing and verification operations only. Currently -there are no additional \fB\-pkeyopt\fR options other than \fBdigest\fR. The \s-1SHA256\s0 -digest is assumed by default. -.SH "DH ALGORITHM" -.IX Header "DH ALGORITHM" -The \s-1DH\s0 algorithm only supports the derivation operation and no additional -\&\fB\-pkeyopt\fR options. -.SH "EC ALGORITHM" -.IX Header "EC ALGORITHM" -The \s-1EC\s0 algorithm supports sign, verify and derive operations. The sign and -verify operations use \s-1ECDSA\s0 and derive uses \s-1ECDH. SHA256\s0 is assumed by default -for the \fB\-pkeyopt\fR \fBdigest\fR option. -.SH "X25519 AND X448 ALGORITHMS" -.IX Header "X25519 AND X448 ALGORITHMS" -The X25519 and X448 algorithms support key derivation only. Currently there are -no additional options. -.SH "ED25519 AND ED448 ALGORITHMS" -.IX Header "ED25519 AND ED448 ALGORITHMS" -These algorithms only support signing and verifying. OpenSSL only implements the -\&\*(L"pure\*(R" variants of these algorithms so raw data can be passed directly to them -without hashing them first. OpenSSL only supports -\&\*(L"oneshot\*(R" operation with these algorithms. This means that the entire file to -be signed/verified must be read into memory before processing it. Signing or -Verifying very large files should be avoided. Additionally the size of the file -must be known for this to work. If the size of the file cannot be determined -(for example if the input is stdin) then the sign or verify operation will fail. -.SH "SM2" -.IX Header "SM2" -The \s-1SM2\s0 algorithm supports sign, verify, encrypt and decrypt operations. For -the sign and verify operations, \s-1SM2\s0 requires an Distinguishing \s-1ID\s0 string to -be passed in. The following \fB\-pkeyopt\fR value is supported: -.IP "\fBdistid:\fR\fIstring\fR" 4 -.IX Item "distid:string" -This sets the \s-1ID\s0 string used in \s-1SM2\s0 sign or verify operations. While verifying -an \s-1SM2\s0 signature, the \s-1ID\s0 string must be the same one used when signing the data. -Otherwise the verification will fail. -.IP "\fBhexdistid:\fR\fIhex_string\fR" 4 -.IX Item "hexdistid:hex_string" -This sets the \s-1ID\s0 string used in \s-1SM2\s0 sign or verify operations. While verifying -an \s-1SM2\s0 signature, the \s-1ID\s0 string must be the same one used when signing the data. -Otherwise the verification will fail. The \s-1ID\s0 string provided with this option -should be a valid hexadecimal value. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Sign some data using a private key: -.PP -.Vb 1 -\& openssl pkeyutl \-sign \-in file \-inkey key.pem \-out sig -.Ve -.PP -Recover the signed data (e.g. if an \s-1RSA\s0 key is used): -.PP -.Vb 1 -\& openssl pkeyutl \-verifyrecover \-in sig \-inkey key.pem -.Ve -.PP -Verify the signature (e.g. a \s-1DSA\s0 key): -.PP -.Vb 1 -\& openssl pkeyutl \-verify \-in file \-sigfile sig \-inkey key.pem -.Ve -.PP -Sign data using a message digest value (this is currently only valid for \s-1RSA\s0): -.PP -.Vb 1 -\& openssl pkeyutl \-sign \-in file \-inkey key.pem \-out sig \-pkeyopt digest:sha256 -.Ve -.PP -Derive a shared secret value: -.PP -.Vb 1 -\& openssl pkeyutl \-derive \-inkey key.pem \-peerkey pubkey.pem \-out secret -.Ve -.PP -Hexdump 48 bytes of \s-1TLS1 PRF\s0 using digest \fB\s-1SHA256\s0\fR and shared secret and -seed consisting of the single byte 0xFF: -.PP -.Vb 2 -\& openssl pkeyutl \-kdf TLS1\-PRF \-kdflen 48 \-pkeyopt md:SHA256 \e -\& \-pkeyopt hexsecret:ff \-pkeyopt hexseed:ff \-hexdump -.Ve -.PP -Derive a key using \fBscrypt\fR where the password is read from command line: -.PP -.Vb 2 -\& openssl pkeyutl \-kdf scrypt \-kdflen 16 \-pkeyopt_passin pass \e -\& \-pkeyopt hexsalt:aabbcc \-pkeyopt N:16384 \-pkeyopt r:8 \-pkeyopt p:1 -.Ve -.PP -Derive using the same algorithm, but read key from environment variable \s-1MYPASS:\s0 -.PP -.Vb 2 -\& openssl pkeyutl \-kdf scrypt \-kdflen 16 \-pkeyopt_passin pass:env:MYPASS \e -\& \-pkeyopt hexsalt:aabbcc \-pkeyopt N:16384 \-pkeyopt r:8 \-pkeyopt p:1 -.Ve -.PP -Sign some data using an \s-1\fBSM2\s0\fR\|(7) private key and a specific \s-1ID:\s0 -.PP -.Vb 2 -\& openssl pkeyutl \-sign \-in file \-inkey sm2.key \-out sig \-rawin \-digest sm3 \e -\& \-pkeyopt distid:someid -.Ve -.PP -Verify some data using an \s-1\fBSM2\s0\fR\|(7) certificate and a specific \s-1ID:\s0 -.PP -.Vb 2 -\& openssl pkeyutl \-verify \-certin \-in file \-inkey sm2.cert \-sigfile sig \e -\& \-rawin \-digest sm3 \-pkeyopt distid:someid -.Ve -.PP -Decrypt some data using a private key with \s-1OAEP\s0 padding using \s-1SHA256:\s0 -.PP -.Vb 2 -\& openssl pkeyutl \-decrypt \-in file \-inkey key.pem \-out secret \e -\& \-pkeyopt rsa_padding_mode:oaep \-pkeyopt rsa_oaep_md:sha256 -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-pkey\fR\|(1), -\&\fBopenssl\-rsautl\fR\|(1) -\&\fBopenssl\-dgst\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-kdf\fR\|(1) -\&\fBEVP_PKEY_CTX_set_hkdf_md\fR\|(3), -\&\fBEVP_PKEY_CTX_set_tls1_prf_md\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-prime.1ossl b/openssl-install/share/man/man1/openssl-prime.1ossl deleted file mode 100644 index d81bfddb..00000000 --- a/openssl-install/share/man/man1/openssl-prime.1ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-PRIME 1ossl" -.TH OPENSSL-PRIME 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-prime \- compute prime numbers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl prime\fR -[\fB\-help\fR] -[\fB\-hex\fR] -[\fB\-generate\fR] -[\fB\-bits\fR \fInum\fR] -[\fB\-safe\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-checks\fR \fInum\fR] -[\fInumber\fR ...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command checks if the specified numbers are prime. -.PP -If no numbers are given on the command line, the \fB\-generate\fR flag should -be used to generate primes according to the requirements specified by the -rest of the flags. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Display an option summary. -.IP "\fB\-hex\fR" 4 -.IX Item "-hex" -Generate hex output. -.IP "\fB\-generate\fR" 4 -.IX Item "-generate" -Generate a prime number. -.IP "\fB\-bits\fR \fInum\fR" 4 -.IX Item "-bits num" -Generate a prime with \fInum\fR bits. -.IP "\fB\-safe\fR" 4 -.IX Item "-safe" -When used with \fB\-generate\fR, generates a \*(L"safe\*(R" prime. If the number -generated is \fIn\fR, then check that \f(CW\*(C`(\f(CIn\f(CW\-1)/2\*(C'\fR is also prime. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-checks\fR \fInum\fR" 4 -.IX Item "-checks num" -This parameter is ignored. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-rand.1ossl b/openssl-install/share/man/man1/openssl-rand.1ossl deleted file mode 100644 index 162382b5..00000000 --- a/openssl-install/share/man/man1/openssl-rand.1ossl +++ /dev/null @@ -1,221 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-RAND 1ossl" -.TH OPENSSL-RAND 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-rand \- generate pseudo\-random bytes -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl rand\fR -[\fB\-help\fR] -[\fB\-out\fR \fIfile\fR] -[\fB\-base64\fR] -[\fB\-hex\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -\&\fInum\fR[K|M|G|T] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command generates \fInum\fR random bytes using a cryptographically -secure pseudo random number generator (\s-1CSPRNG\s0). A suffix [K|M|G|T] may be -appended to the num value to indicate the requested value be scaled as a -multiple of KiB/MiB/GiB/TiB respectively. Note that suffixes are case -sensitive, and that the suffixes represent binary multiples -(K = 1024 bytes, M = 1024*1024 bytes, etc). -.PP -The string 'max' may be substituted for a numerical value in num, to request the -maximum number of bytes the \s-1CSPRNG\s0 can produce per instantiation. Currently, -this is restricted to 2^61 bytes as per \s-1NIST SP 800\-90C.\s0 -.PP -The random bytes are generated using the \fBRAND_bytes\fR\|(3) function, -which provides a security level of 256 bits, provided it managed to -seed itself successfully from a trusted operating system entropy source. -Otherwise, the command will fail with a nonzero error code. -For more details, see \fBRAND_bytes\fR\|(3), \s-1\fBRAND\s0\fR\|(7), and \s-1\fBEVP_RAND\s0\fR\|(7). -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-out\fR \fIfile\fR" 4 -.IX Item "-out file" -Write to \fIfile\fR instead of standard output. -.IP "\fB\-base64\fR" 4 -.IX Item "-base64" -Perform base64 encoding on the output. -.IP "\fB\-hex\fR" 4 -.IX Item "-hex" -Show the output as a hex string. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBRAND_bytes\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7), -\&\s-1\fBEVP_RAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-rehash.1ossl b/openssl-install/share/man/man1/openssl-rehash.1ossl deleted file mode 100644 index de9c1c35..00000000 --- a/openssl-install/share/man/man1/openssl-rehash.1ossl +++ /dev/null @@ -1,281 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-REHASH 1ossl" -.TH OPENSSL-REHASH 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-rehash, c_rehash \- Create symbolic links to files named by the hash -values -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR -\&\fBrehash\fR -[\fB\-h\fR] -[\fB\-help\fR] -[\fB\-old\fR] -[\fB\-compat\fR] -[\fB\-n\fR] -[\fB\-v\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIdirectory\fR] ... -.PP -\&\fBc_rehash\fR -[\fB\-h\fR] -[\fB\-help\fR] -[\fB\-old\fR] -[\fB\-n\fR] -[\fB\-v\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIdirectory\fR] ... -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is generally equivalent to the external -script \fBc_rehash\fR, -except for minor differences noted below. -.PP -\&\fBopenssl rehash\fR scans directories and calculates a hash value of -each \fI.pem\fR, \fI.crt\fR, \fI.cer\fR, or \fI.crl\fR -file in the specified directory list and creates symbolic links -for each file, where the name of the link is the hash value. -(If the platform does not support symbolic links, a copy is made.) -This command is useful as many programs that use OpenSSL require -directories to be set up like this in order to find certificates. -.PP -If any directories are named on the command line, then those are -processed in turn. If not, then the \fB\s-1SSL_CERT_DIR\s0\fR environment variable -is consulted; this should be a colon-separated list of directories, -like the Unix \fB\s-1PATH\s0\fR variable. -If that is not set then the default directory (installation-specific -but often \fI/usr/local/ssl/certs\fR) is processed. -.PP -In order for a directory to be processed, the user must have write -permissions on that directory, otherwise an error will be generated. -.PP -The links created are of the form \fI\s-1HHHHHHHH.D\s0\fR, where each \fIH\fR -is a hexadecimal character and \fID\fR is a single decimal digit. -When a directory is processed, all links in it that have a name -in that syntax are first removed, even if they are being used for -some other purpose. -To skip the removal step, use the \fB\-n\fR flag. -Hashes for \s-1CRL\s0's look similar except the letter \fBr\fR appears after -the period, like this: \fI\s-1HHHHHHHH.\s0\fR\fBr\fR\fID\fR. -.PP -Multiple objects may have the same hash; they will be indicated by -incrementing the \fID\fR value. Duplicates are found by comparing the -full \s-1SHA\-1\s0 fingerprint. A warning will be displayed if a duplicate -is found. -.PP -A warning will also be displayed if there are files that -cannot be parsed as either a certificate or a \s-1CRL\s0 or if -more than one such object appears in the file. -.SS "Script Configuration" -.IX Subsection "Script Configuration" -The \fBc_rehash\fR script -uses the \fBopenssl\fR program to compute the hashes and -fingerprints. If not found in the user's \fB\s-1PATH\s0\fR, then set the -\&\fB\s-1OPENSSL\s0\fR environment variable to the full pathname. -Any program can be used, it will be invoked as follows for either -a certificate or \s-1CRL:\s0 -.PP -.Vb 2 -\& $OPENSSL x509 \-hash \-fingerprint \-noout \-in FILENAME -\& $OPENSSL crl \-hash \-fingerprint \-noout \-in FILENAME -.Ve -.PP -where \fI\s-1FILENAME\s0\fR is the filename. It must output the hash of the -file on the first line, and the fingerprint on the second, -optionally prefixed with some text and an equals sign. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR \fB\-h\fR" 4 -.IX Item "-help -h" -Display a brief usage message. -.IP "\fB\-old\fR" 4 -.IX Item "-old" -Use old-style hashing (\s-1MD5,\s0 as opposed to \s-1SHA\-1\s0) for generating -links to be used for releases before 1.0.0. -Note that current versions will not use the old style. -.IP "\fB\-n\fR" 4 -.IX Item "-n" -Do not remove existing links. -This is needed when keeping new and old-style links in the same directory. -.IP "\fB\-compat\fR" 4 -.IX Item "-compat" -Generate links for both old-style (\s-1MD5\s0) and new-style (\s-1SHA1\s0) hashing. -This allows releases before 1.0.0 to use these links along-side newer -releases. -.IP "\fB\-v\fR" 4 -.IX Item "-v" -Print messages about old links removed and new links created. -By default, this command only lists each directory as it is processed. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "ENVIRONMENT" -.IX Header "ENVIRONMENT" -.IP "\fB\s-1OPENSSL\s0\fR" 4 -.IX Item "OPENSSL" -The path to an executable to use to generate hashes and -fingerprints (see above). -.IP "\fB\s-1SSL_CERT_DIR\s0\fR" 4 -.IX Item "SSL_CERT_DIR" -Colon separated list of directories to operate on. -Ignored if directories are listed on the command line. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-crl\fR\|(1), -\&\fBopenssl\-x509\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-req.1ossl b/openssl-install/share/man/man1/openssl-req.1ossl deleted file mode 100644 index d8222bbb..00000000 --- a/openssl-install/share/man/man1/openssl-req.1ossl +++ /dev/null @@ -1,941 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-REQ 1ossl" -.TH OPENSSL-REQ 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-req \- PKCS#10 certificate request and certificate generating command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBreq\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-text\fR] -[\fB\-pubkey\fR] -[\fB\-noout\fR] -[\fB\-verify\fR] -[\fB\-modulus\fR] -[\fB\-new\fR] -[\fB\-newkey\fR \fIarg\fR] -[\fB\-pkeyopt\fR \fIopt\fR:\fIvalue\fR] -[\fB\-noenc\fR] -[\fB\-nodes\fR] -[\fB\-key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-keyout\fR \fIfilename\fR] -[\fB\-keygen_engine\fR \fIid\fR] -[\fB\-\f(BIdigest\fB\fR] -[\fB\-config\fR \fIfilename\fR] -[\fB\-section\fR \fIname\fR] -[\fB\-x509\fR] -[\fB\-x509v1\fR] -[\fB\-CA\fR \fIfilename\fR|\fIuri\fR] -[\fB\-CAkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-not_before\fR \fIdate\fR] -[\fB\-not_after\fR \fIdate\fR] -[\fB\-days\fR \fIn\fR] -[\fB\-set_serial\fR \fIn\fR] -[\fB\-newhdr\fR] -[\fB\-copy_extensions\fR \fIarg\fR] -[\fB\-extensions\fR \fIsection\fR] -[\fB\-reqexts\fR \fIsection\fR] -[\fB\-addext\fR \fIext\fR] -[\fB\-precert\fR] -[\fB\-utf8\fR] -[\fB\-reqopt\fR] -[\fB\-subject\fR] -[\fB\-subj\fR \fIarg\fR] -[\fB\-multivalue\-rdn\fR] -[\fB\-sigopt\fR \fInm\fR:\fIv\fR] -[\fB\-vfyopt\fR \fInm\fR:\fIv\fR] -[\fB\-batch\fR] -[\fB\-verbose\fR] -[\fB\-quiet\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command primarily creates and processes certificate requests (CSRs) -in PKCS#10 format. It can additionally create self-signed certificates -for use as root CAs for example. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The \s-1CSR\s0 input file format to use; by default \s-1PEM\s0 is tried first. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The output format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -The data is a PKCS#10 object. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read a request from. -This defaults to standard input unless \fB\-x509\fR or \fB\-CA\fR is specified. -A request is only read if the creation options -(\fB\-new\fR or \fB\-newkey\fR or \fB\-precert\fR) are not specified. -.IP "\fB\-sigopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-sigopt nm:v" -Pass options to the signature algorithm during sign operations. -Names and values of these options are algorithm-specific. -.IP "\fB\-vfyopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-vfyopt nm:v" -Pass options to the signature algorithm during verify operations. -Names and values of these options are algorithm-specific. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The password source for private key and certificate input. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passout arg" -The password source for the output file. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write to or standard output by default. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the certificate request in text form. -.IP "\fB\-subject\fR" 4 -.IX Item "-subject" -Prints out the certificate request subject -(or certificate subject if \fB\-x509\fR is in use). -.IP "\fB\-pubkey\fR" 4 -.IX Item "-pubkey" -Prints out the public key. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option prevents output of the encoded version of the certificate request. -.IP "\fB\-modulus\fR" 4 -.IX Item "-modulus" -Prints out the value of the modulus of the public key contained in the request. -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verifies the self-signature on the request. If the verification fails, -the program will immediately exit, i.e. further option processing -(e.g. \fB\-text\fR) is skipped. -.IP "\fB\-new\fR" 4 -.IX Item "-new" -This option generates a new certificate request. It will prompt -the user for the relevant field values. The actual fields -prompted for and their maximum and minimum sizes are specified -in the configuration file and any requested extensions. -.Sp -If the \fB\-key\fR option is not given it will generate a new private key -using information specified in the configuration file or given with -the \fB\-newkey\fR and \fB\-pkeyopt\fR options, -else by default an \s-1RSA\s0 key with 2048 bits length. -.IP "\fB\-newkey\fR \fIarg\fR" 4 -.IX Item "-newkey arg" -This option is used to generate a new private key unless \fB\-key\fR is given. -It is subsequently used as if it was given using the \fB\-key\fR option. -.Sp -This option implies the \fB\-new\fR flag to create a new certificate request -or a new certificate in case \fB\-x509\fR is used. -.Sp -The argument takes one of several forms. -.Sp -[\fBrsa:\fR]\fInbits\fR generates an \s-1RSA\s0 key \fInbits\fR in size. -If \fInbits\fR is omitted, i.e., \fB\-newkey\fR \fBrsa\fR is specified, -the default key size specified in the configuration file -with the \fBdefault_bits\fR option is used if present, else 2048. -.Sp -All other algorithms support the \fB\-newkey\fR \fIalgname\fR:\fIfile\fR form, where -\&\fIfile\fR is an algorithm parameter file, created with \f(CW\*(C`openssl genpkey \-genparam\*(C'\fR -or an X.509 certificate for a key with appropriate algorithm. -.Sp -\&\fBparam:\fR\fIfile\fR generates a key using the parameter file or certificate -\&\fIfile\fR, the algorithm is determined by the parameters. -.Sp -\&\fIalgname\fR[:\fIfile\fR] generates a key using the given algorithm \fIalgname\fR. -If a parameter file \fIfile\fR is given then the parameters specified there -are used, where the algorithm parameters must match \fIalgname\fR. -If algorithm parameters are not given, -any necessary parameters should be specified via the \fB\-pkeyopt\fR option. -.Sp -\&\fBdsa:\fR\fIfilename\fR generates a \s-1DSA\s0 key using the parameters -in the file \fIfilename\fR. \fBec:\fR\fIfilename\fR generates \s-1EC\s0 key (usable both with -\&\s-1ECDSA\s0 or \s-1ECDH\s0 algorithms), \fBgost2001:\fR\fIfilename\fR generates \s-1GOST R -34.10\-2001\s0 key (requires \fBgost\fR engine configured in the configuration -file). If just \fBgost2001\fR is specified a parameter set should be -specified by \fB\-pkeyopt\fR \fIparamset:X\fR -.IP "\fB\-pkeyopt\fR \fIopt\fR:\fIvalue\fR" 4 -.IX Item "-pkeyopt opt:value" -Set the public key algorithm option \fIopt\fR to \fIvalue\fR. The precise set of -options supported depends on the public key algorithm used and its -implementation. -See \*(L"\s-1KEY GENERATION OPTIONS\*(R"\s0 in \fBopenssl\-genpkey\fR\|(1) for more details. -.IP "\fB\-key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-key filename|uri" -This option provides the private key for signing a new certificate or -certificate request. -Unless \fB\-in\fR is given, the corresponding public key is placed in -the new certificate or certificate request, resulting in a self-signature. -.Sp -For certificate signing this option is overridden by the \fB\-CA\fR option. -.Sp -This option also accepts PKCS#8 format private keys for \s-1PEM\s0 format files. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The format of the private key; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-keyout\fR \fIfilename\fR" 4 -.IX Item "-keyout filename" -This gives the filename to write any private key to that has been newly created -or read from \fB\-key\fR. If neither the \fB\-keyout\fR option nor the \fB\-key\fR option -are given then the filename specified in the configuration file with the -\&\fBdefault_keyfile\fR option is used, if present. Thus, if you want to write the -private key and the \fB\-key\fR option is provided, you should provide the -\&\fB\-keyout\fR option explicitly. If a new key is generated and no filename is -specified the key is written to standard output. -.IP "\fB\-noenc\fR" 4 -.IX Item "-noenc" -If this option is specified then if a private key is created it -will not be encrypted. -.IP "\fB\-nodes\fR" 4 -.IX Item "-nodes" -This option is deprecated since OpenSSL 3.0; use \fB\-noenc\fR instead. -.IP "\fB\-\f(BIdigest\fB\fR" 4 -.IX Item "-digest" -This specifies the message digest to sign the request. -Any digest supported by the OpenSSL \fBdgst\fR command can be used. -This overrides the digest algorithm specified in -the configuration file. -.Sp -Some public key algorithms may override this choice. For instance, \s-1DSA\s0 -signatures always use \s-1SHA1, GOST R 34.10\s0 signatures always use -\&\s-1GOST R 34.11\-94\s0 (\fB\-md_gost94\fR), Ed25519 and Ed448 never use any digest. -.IP "\fB\-config\fR \fIfilename\fR" 4 -.IX Item "-config filename" -This allows an alternative configuration file to be specified. -Optional; for a description of the default value, -see \*(L"\s-1COMMAND SUMMARY\*(R"\s0 in \fBopenssl\fR\|(1). -.IP "\fB\-section\fR \fIname\fR" 4 -.IX Item "-section name" -Specifies the name of the section to use; the default is \fBreq\fR. -.IP "\fB\-subj\fR \fIarg\fR" 4 -.IX Item "-subj arg" -Sets subject name for new request or supersedes the subject name -when processing a certificate request. -.Sp -The arg must be formatted as \f(CW\*(C`/type0=value0/type1=value1/type2=...\*(C'\fR. -Special characters may be escaped by \f(CW\*(C`\e\*(C'\fR (backslash), whitespace is retained. -Empty values are permitted, but the corresponding type will not be included -in the request. -Giving a single \f(CW\*(C`/\*(C'\fR will lead to an empty sequence of RDNs (a NULL-DN). -Multi-valued RDNs can be formed by placing a \f(CW\*(C`+\*(C'\fR character instead of a \f(CW\*(C`/\*(C'\fR -between the AttributeValueAssertions (AVAs) that specify the members of the set. -Example: -.Sp -\&\f(CW\*(C`/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe\*(C'\fR -.IP "\fB\-multivalue\-rdn\fR" 4 -.IX Item "-multivalue-rdn" -This option has been deprecated and has no effect. -.IP "\fB\-x509\fR" 4 -.IX Item "-x509" -This option outputs a certificate instead of a certificate request. -This is typically used to generate test certificates. -It is implied by the \fB\-CA\fR option. -.Sp -This option implies the \fB\-new\fR flag if \fB\-in\fR is not given. -.Sp -If an existing request is specified with the \fB\-in\fR option, it is converted -to a certificate; otherwise a request is created from scratch. -.Sp -Unless specified using the \fB\-set_serial\fR option, -a large random number will be used for the serial number. -.Sp -Unless the \fB\-copy_extensions\fR option is used, -X.509 extensions are not copied from any provided request input file. -.Sp -X.509 extensions to be added can be specified in the configuration file, -possibly using the \fB\-config\fR and \fB\-extensions\fR options, -and/or using the \fB\-addext\fR option. -.Sp -Unless \fB\-x509v1\fR is given, generated certificates bear X.509 version 3. -Unless specified otherwise, -key identifier extensions are included as described in \fBx509v3_config\fR\|(5). -.IP "\fB\-x509v1\fR" 4 -.IX Item "-x509v1" -Request generation of certificates with X.509 version 1. -This implies \fB\-x509\fR. -If X.509 extensions are given, anyway X.509 version 3 is set. -.IP "\fB\-CA\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-CA filename|uri" -Specifies the \*(L"\s-1CA\*(R"\s0 certificate to be used for signing a new certificate -and implies use of \fB\-x509\fR. -When present, this behaves like a \*(L"micro \s-1CA\*(R"\s0 as follows: -The subject name of the \*(L"\s-1CA\*(R"\s0 certificate is placed as issuer name in the new -certificate, which is then signed using the \*(L"\s-1CA\*(R"\s0 key given as specified below. -.IP "\fB\-CAkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-CAkey filename|uri" -Sets the \*(L"\s-1CA\*(R"\s0 private key to sign a certificate with. -The private key must match the public key of the certificate given with \fB\-CA\fR. -If this option is not provided then the key must be present in the \fB\-CA\fR input. -.IP "\fB\-not_before\fR \fIdate\fR" 4 -.IX Item "-not_before date" -When \fB\-x509\fR is in use this allows the start date to be explicitly set, -otherwise it is ignored. The format of \fIdate\fR is \s-1YYMMDDHHMMSSZ\s0 (the -same as an \s-1ASN1\s0 UTCTime structure), or \s-1YYYYMMDDHHMMSSZ\s0 (the same as an -\&\s-1ASN1\s0 GeneralizedTime structure). In both formats, seconds \s-1SS\s0 and -timezone Z must be present. -Alternatively, you can also use \*(L"today\*(R". -.IP "\fB\-not_after\fR \fIdate\fR" 4 -.IX Item "-not_after date" -When \fB\-x509\fR is in use this allows the expiry date to be explicitly -set, otherwise it is ignored. The format of \fIdate\fR is \s-1YYMMDDHHMMSSZ\s0 -(the same as an \s-1ASN1\s0 UTCTime structure), or \s-1YYYYMMDDHHMMSSZ\s0 (the same as -an \s-1ASN1\s0 GeneralizedTime structure). In both formats, seconds \s-1SS\s0 and -timezone Z must be present. -Alternatively, you can also use \*(L"today\*(R". -.Sp -This overrides the \fB\-days\fR option. -.IP "\fB\-days\fR \fIn\fR" 4 -.IX Item "-days n" -When \fB\-x509\fR is in use this specifies the number of days from today to -certify the certificate for, otherwise it is ignored. \fIn\fR should -be a positive integer. The default is 30 days. -.Sp -Regardless of the option \fB\-not_before\fR, the days are always counted from -today. -When used together with the option \fB\-not_after\fR, the explicit expiry -date takes precedence. -.IP "\fB\-set_serial\fR \fIn\fR" 4 -.IX Item "-set_serial n" -Serial number to use when outputting a self-signed certificate. -This may be specified as a decimal value or a hex value if preceded by \f(CW\*(C`0x\*(C'\fR. -If not given, a large random number will be used. -.IP "\fB\-copy_extensions\fR \fIarg\fR" 4 -.IX Item "-copy_extensions arg" -Determines how X.509 extensions in certificate requests should be handled -when \fB\-x509\fR is in use. -If \fIarg\fR is \fBnone\fR or this option is not present then extensions are ignored. -If \fIarg\fR is \fBcopy\fR or \fBcopyall\fR then -all extensions in the request are copied to the certificate. -.Sp -The main use of this option is to allow a certificate request to supply -values for certain extensions such as subjectAltName. -.IP "\fB\-extensions\fR \fIsection\fR, \fB\-reqexts\fR \fIsection\fR" 4 -.IX Item "-extensions section, -reqexts section" -Can be used to override the name of the configuration file section -from which X.509 extensions are included -in the certificate (when \fB\-x509\fR is in use) or certificate request. -This allows several different sections to be used in the same configuration -file to specify requests for a variety of purposes. -.IP "\fB\-addext\fR \fIext\fR" 4 -.IX Item "-addext ext" -Add a specific extension to the certificate (if \fB\-x509\fR is in use) -or certificate request. The argument must have the form of -a \f(CW\*(C`key=value\*(C'\fR pair as it would appear in a config file. -.Sp -If an extension is added using this option that has the same \s-1OID\s0 as one -defined in the extension section of the config file, it overrides that one. -.Sp -This option can be given multiple times. -Doing so, the same key most not be given more than once. -.IP "\fB\-precert\fR" 4 -.IX Item "-precert" -A poison extension will be added to the certificate, making it a -\&\*(L"pre-certificate\*(R" (see \s-1RFC6962\s0). This can be submitted to Certificate -Transparency logs in order to obtain signed certificate timestamps (SCTs). -These SCTs can then be embedded into the pre-certificate as an extension, before -removing the poison and signing the certificate. -.Sp -This implies the \fB\-new\fR flag. -.IP "\fB\-utf8\fR" 4 -.IX Item "-utf8" -This option causes field values to be interpreted as \s-1UTF8\s0 strings, by -default they are interpreted as \s-1ASCII.\s0 This means that the field -values, whether prompted from a terminal or obtained from a -configuration file, must be valid \s-1UTF8\s0 strings. -.IP "\fB\-reqopt\fR \fIoption\fR" 4 -.IX Item "-reqopt option" -Customise the printing format used with \fB\-text\fR. The \fIoption\fR argument can be -a single option or multiple options separated by commas. -.Sp -See discussion of the \fB\-certopt\fR parameter in the \fBopenssl\-x509\fR\|(1) -command. -.IP "\fB\-newhdr\fR" 4 -.IX Item "-newhdr" -Adds the word \fB\s-1NEW\s0\fR to the \s-1PEM\s0 file header and footer lines on the outputted -request. Some software (Netscape certificate server) and some CAs need this. -.IP "\fB\-batch\fR" 4 -.IX Item "-batch" -Non-interactive mode. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Print extra details about the operations being performed. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Print fewer details about the operations being performed, which may be -handy during batch scripts or pipelines (specifically \*(L"progress dots\*(R" -during key generation are suppressed). -.IP "\fB\-keygen_engine\fR \fIid\fR" 4 -.IX Item "-keygen_engine id" -Specifies an engine (by its unique \fIid\fR string) which would be used -for key generation operations. -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -This specifies how the subject or issuer names are displayed. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "CONFIGURATION FILE FORMAT" -.IX Header "CONFIGURATION FILE FORMAT" -The configuration options are specified in the \fBreq\fR section of -the configuration file. An alternate name be specified by using the -\&\fB\-section\fR option. -As with all configuration files, if no -value is specified in the specific section then -the initial unnamed or \fBdefault\fR section is searched too. -.PP -The options available are described in detail below. -.IP "\fBinput_password\fR, \fBoutput_password\fR" 4 -.IX Item "input_password, output_password" -The passwords for the input private key file (if present) and -the output private key file (if one will be created). The -command line options \fBpassin\fR and \fBpassout\fR override the -configuration file values. -.IP "\fBdefault_bits\fR" 4 -.IX Item "default_bits" -Specifies the default key size in bits. -.Sp -This option is used in conjunction with the \fB\-new\fR option to generate -a new key. It can be overridden by specifying an explicit key size in -the \fB\-newkey\fR option. The smallest accepted key size is 512 bits. If -no key size is specified then 2048 bits is used. -.IP "\fBdefault_keyfile\fR" 4 -.IX Item "default_keyfile" -This is the default filename to write a private key to. If not -specified the key is written to standard output. This can be -overridden by the \fB\-keyout\fR option. -.IP "\fBoid_file\fR" 4 -.IX Item "oid_file" -This specifies a file containing additional \fB\s-1OBJECT IDENTIFIERS\s0\fR. -Each line of the file should consist of the numerical form of the -object identifier followed by whitespace then the short name followed -by whitespace and finally the long name. -.IP "\fBoid_section\fR" 4 -.IX Item "oid_section" -This specifies a section in the configuration file containing extra -object identifiers. Each line should consist of the short name of the -object identifier followed by \fB=\fR and the numerical form. The short -and long names are the same when this option is used. -.IP "\fB\s-1RANDFILE\s0\fR" 4 -.IX Item "RANDFILE" -At startup the specified file is loaded into the random number generator, -and at exit 256 bytes will be written to it. -It is used for private key generation. -.IP "\fBencrypt_key\fR" 4 -.IX Item "encrypt_key" -If this is set to \fBno\fR then if a private key is generated it is -\&\fBnot\fR encrypted. This is equivalent to the \fB\-noenc\fR command line -option. For compatibility \fBencrypt_rsa_key\fR is an equivalent option. -.IP "\fBdefault_md\fR" 4 -.IX Item "default_md" -This option specifies the digest algorithm to use. Any digest supported by the -OpenSSL \fBdgst\fR command can be used. This option can be overridden on the -command line. Certain signing algorithms (i.e. Ed25519 and Ed448) will ignore -any digest that has been set. -.IP "\fBstring_mask\fR" 4 -.IX Item "string_mask" -This option masks out the use of certain string types in certain -fields. Most users will not need to change this option. It can be set to -several values: -.RS 4 -.IP "\fButf8only\fR \- only UTF8Strings are used (this is the default value)" 4 -.IX Item "utf8only - only UTF8Strings are used (this is the default value)" -.PD 0 -.IP "\fBpkix\fR \- any string type except T61Strings" 4 -.IX Item "pkix - any string type except T61Strings" -.IP "\fBnombstr\fR \- any string type except BMPStrings and UTF8Strings" 4 -.IX Item "nombstr - any string type except BMPStrings and UTF8Strings" -.IP "\fBdefault\fR \- any kind of string type" 4 -.IX Item "default - any kind of string type" -.RE -.RS 4 -.PD -.Sp -Note that \fButf8only\fR is the \s-1PKIX\s0 recommendation in \s-1RFC2459\s0 after 2003, and the -default \fBstring_mask\fR; \fBdefault\fR is not the default option. The \fBnombstr\fR -value is a workaround for some software that has problems with variable-sized -BMPStrings and UTF8Strings. -.RE -.IP "\fBreq_extensions\fR" 4 -.IX Item "req_extensions" -This specifies the configuration file section containing a list of -extensions to add to the certificate request. It can be overridden -by the \fB\-reqexts\fR (or \fB\-extensions\fR) command line switch. See the -\&\fBx509v3_config\fR\|(5) manual page for details of the -extension section format. -.IP "\fBx509_extensions\fR" 4 -.IX Item "x509_extensions" -This specifies the configuration file section containing a list of -extensions to add to certificate generated when \fB\-x509\fR is in use. -It can be overridden by the \fB\-extensions\fR command line switch. -.IP "\fBprompt\fR" 4 -.IX Item "prompt" -If set to the value \fBno\fR this disables prompting of certificate fields -and just takes values from the config file directly. It also changes the -expected format of the \fBdistinguished_name\fR and \fBattributes\fR sections. -.IP "\fButf8\fR" 4 -.IX Item "utf8" -If set to the value \fByes\fR then field values to be interpreted as \s-1UTF8\s0 -strings, by default they are interpreted as \s-1ASCII.\s0 This means that -the field values, whether prompted from a terminal or obtained from a -configuration file, must be valid \s-1UTF8\s0 strings. -.IP "\fBattributes\fR" 4 -.IX Item "attributes" -This specifies the section containing any request attributes: its format -is the same as \fBdistinguished_name\fR. Typically these may contain the -challengePassword or unstructuredName types. They are currently ignored -by OpenSSL's request signing utilities but some CAs might want them. -.IP "\fBdistinguished_name\fR" 4 -.IX Item "distinguished_name" -This specifies the section containing the distinguished name fields to -prompt for when generating a certificate or certificate request. The format -is described in the next section. -.SH "DISTINGUISHED NAME AND ATTRIBUTE SECTION FORMAT" -.IX Header "DISTINGUISHED NAME AND ATTRIBUTE SECTION FORMAT" -There are two separate formats for the distinguished name and attribute -sections. If the \fBprompt\fR option is set to \fBno\fR then these sections -just consist of field names and values: for example, -.PP -.Vb 3 -\& CN=My Name -\& OU=My Organization -\& emailAddress=someone@somewhere.org -.Ve -.PP -This allows external programs (e.g. \s-1GUI\s0 based) to generate a template file with -all the field names and values and just pass it to this command. An example -of this kind of configuration file is contained in the \fB\s-1EXAMPLES\s0\fR section. -.PP -Alternatively if the \fBprompt\fR option is absent or not set to \fBno\fR then the -file contains field prompting information. It consists of lines of the form: -.PP -.Vb 4 -\& fieldName="prompt" -\& fieldName_default="default field value" -\& fieldName_min= 2 -\& fieldName_max= 4 -.Ve -.PP -\&\*(L"fieldName\*(R" is the field name being used, for example commonName (or \s-1CN\s0). -The \*(L"prompt\*(R" string is used to ask the user to enter the relevant -details. If the user enters nothing then the default value is used if no -default value is present then the field is omitted. A field can -still be omitted if a default value is present if the user just -enters the '.' character. -.PP -The number of characters entered must be between the fieldName_min and -fieldName_max limits: there may be additional restrictions based -on the field being used (for example countryName can only ever be -two characters long and must fit in a PrintableString). -.PP -Some fields (such as organizationName) can be used more than once -in a \s-1DN.\s0 This presents a problem because configuration files will -not recognize the same name occurring twice. To avoid this problem -if the fieldName contains some characters followed by a full stop -they will be ignored. So for example a second organizationName can -be input by calling it \*(L"1.organizationName\*(R". -.PP -The actual permitted field names are any object identifier short or -long names. These are compiled into OpenSSL and include the usual -values such as commonName, countryName, localityName, organizationName, -organizationalUnitName, stateOrProvinceName. Additionally emailAddress -is included as well as name, surname, givenName, initials, and dnQualifier. -.PP -Additional object identifiers can be defined with the \fBoid_file\fR or -\&\fBoid_section\fR options in the configuration file. Any additional fields -will be treated as though they were a DirectoryString. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Examine and verify certificate request: -.PP -.Vb 1 -\& openssl req \-in req.pem \-text \-verify \-noout -.Ve -.PP -Create a private key and then generate a certificate request from it: -.PP -.Vb 2 -\& openssl genrsa \-out key.pem 2048 -\& openssl req \-new \-key key.pem \-out req.pem -.Ve -.PP -The same but just using req: -.PP -.Vb 1 -\& openssl req \-newkey rsa:2048 \-keyout key.pem \-out req.pem -.Ve -.PP -Generate a self-signed root certificate: -.PP -.Vb 1 -\& openssl req \-x509 \-newkey rsa:2048 \-keyout key.pem \-out req.pem -.Ve -.PP -Create an \s-1SM2\s0 private key and then generate a certificate request from it: -.PP -.Vb 2 -\& openssl ecparam \-genkey \-name SM2 \-out sm2.key -\& openssl req \-new \-key sm2.key \-out sm2.csr \-sm3 \-sigopt "distid:1234567812345678" -.Ve -.PP -Examine and verify an \s-1SM2\s0 certificate request: -.PP -.Vb 1 -\& openssl req \-verify \-in sm2.csr \-sm3 \-vfyopt "distid:1234567812345678" -.Ve -.PP -Example of a file pointed to by the \fBoid_file\fR option: -.PP -.Vb 2 -\& 1.2.3.4 shortName A longer Name -\& 1.2.3.6 otherName Other longer Name -.Ve -.PP -Example of a section pointed to by \fBoid_section\fR making use of variable -expansion: -.PP -.Vb 2 -\& testoid1=1.2.3.5 -\& testoid2=${testoid1}.6 -.Ve -.PP -Sample configuration file prompting for field values: -.PP -.Vb 6 -\& [ req ] -\& default_bits = 2048 -\& default_keyfile = privkey.pem -\& distinguished_name = req_distinguished_name -\& attributes = req_attributes -\& req_extensions = v3_ca -\& -\& dirstring_type = nombstr -\& -\& [ req_distinguished_name ] -\& countryName = Country Name (2 letter code) -\& countryName_default = AU -\& countryName_min = 2 -\& countryName_max = 2 -\& -\& localityName = Locality Name (eg, city) -\& -\& organizationalUnitName = Organizational Unit Name (eg, section) -\& -\& commonName = Common Name (eg, YOUR name) -\& commonName_max = 64 -\& -\& emailAddress = Email Address -\& emailAddress_max = 40 -\& -\& [ req_attributes ] -\& challengePassword = A challenge password -\& challengePassword_min = 4 -\& challengePassword_max = 20 -\& -\& [ v3_ca ] -\& -\& subjectKeyIdentifier=hash -\& authorityKeyIdentifier=keyid:always,issuer:always -\& basicConstraints = critical, CA:true -.Ve -.PP -Sample configuration containing all field values: -.PP -.Vb 7 -\& [ req ] -\& default_bits = 2048 -\& default_keyfile = keyfile.pem -\& distinguished_name = req_distinguished_name -\& attributes = req_attributes -\& prompt = no -\& output_password = mypass -\& -\& [ req_distinguished_name ] -\& C = GB -\& ST = Test State or Province -\& L = Test Locality -\& O = Organization Name -\& OU = Organizational Unit Name -\& CN = Common Name -\& emailAddress = test@email.address -\& -\& [ req_attributes ] -\& challengePassword = A challenge password -.Ve -.PP -Example of giving the most common attributes (subject and extensions) -on the command line: -.PP -.Vb 4 -\& openssl req \-new \-subj "/C=GB/CN=foo" \e -\& \-addext "subjectAltName = DNS:foo.co.uk" \e -\& \-addext "certificatePolicies = 1.2.3.4" \e -\& \-newkey rsa:2048 \-keyout key.pem \-out req.pem -.Ve -.SH "NOTES" -.IX Header "NOTES" -The certificate requests generated by \fBXenroll\fR with \s-1MSIE\s0 have extensions -added. It includes the \fBkeyUsage\fR extension which determines the type of -key (signature only or general purpose) and any additional OIDs entered -by the script in an \fBextendedKeyUsage\fR extension. -.SH "DIAGNOSTICS" -.IX Header "DIAGNOSTICS" -The following messages are frequently asked about: -.PP -.Vb 2 -\& Using configuration from /some/path/openssl.cnf -\& Unable to load config info -.Ve -.PP -This is followed some time later by: -.PP -.Vb 2 -\& unable to find \*(Aqdistinguished_name\*(Aq in config -\& problems making Certificate Request -.Ve -.PP -The first error message is the clue: it can't find the configuration -file! Certain operations (like examining a certificate request) don't -need a configuration file so its use isn't enforced. Generation of -certificates or requests however does need a configuration file. This -could be regarded as a bug. -.PP -Another puzzling message is this: -.PP -.Vb 2 -\& Attributes: -\& a0:00 -.Ve -.PP -this is displayed when no attributes are present and the request includes -the correct empty \fB\s-1SET OF\s0\fR structure (the \s-1DER\s0 encoding of which is 0xa0 -0x00). If you just see: -.PP -.Vb 1 -\& Attributes: -.Ve -.PP -then the \fB\s-1SET OF\s0\fR is missing and the encoding is technically invalid (but -it is tolerated). See the description of the command line option \fB\-asn1\-kludge\fR -for more information. -.SH "BUGS" -.IX Header "BUGS" -OpenSSL's handling of T61Strings (aka TeletexStrings) is broken: it effectively -treats them as \s-1ISO\-8859\-1\s0 (Latin 1), Netscape and \s-1MSIE\s0 have similar behaviour. -This can cause problems if you need characters that aren't available in -PrintableStrings and you don't want to or can't use BMPStrings. -.PP -As a consequence of the T61String handling the only correct way to represent -accented characters in OpenSSL is to use a BMPString: unfortunately Netscape -currently chokes on these. If you have to use accented characters with Netscape -and \s-1MSIE\s0 then you currently need to use the invalid T61String form. -.PP -The current prompting is not very friendly. It doesn't allow you to confirm what -you've just entered. Other things like extensions in certificate requests are -statically defined in the configuration file. Some of these: like an email -address in subjectAltName should be input by the user. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -\&\fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1), -\&\fBconfig\fR\|(5), -\&\fBx509v3_config\fR\|(5) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-section\fR option was added in OpenSSL 3.0.0. -.PP -The \fB\-multivalue\-rdn\fR option has become obsolete in OpenSSL 3.0.0 and -has no effect. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -The <\-nodes> option was deprecated in OpenSSL 3.0, too; use \fB\-noenc\fR instead. -.PP -The \fB\-reqexts\fR option has been made an alias of \fB\-extensions\fR in OpenSSL 3.2. -.PP -Since OpenSSL 3.2, -generated certificates bear X.509 version 3 unless \fB\-x509v1\fR is given, -and key identifier extensions are included by default. -.PP -Since OpenSSL 3.3, the \fB\-verify\fR option will exit with 1 on failure. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-rsa.1ossl b/openssl-install/share/man/man1/openssl-rsa.1ossl deleted file mode 100644 index 12e26b77..00000000 --- a/openssl-install/share/man/man1/openssl-rsa.1ossl +++ /dev/null @@ -1,341 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-RSA 1ossl" -.TH OPENSSL-RSA 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-rsa \- RSA key processing command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBrsa\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-in\fR \fIfilename\fR|\fIuri\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-aes128\fR] -[\fB\-aes192\fR] -[\fB\-aes256\fR] -[\fB\-aria128\fR] -[\fB\-aria192\fR] -[\fB\-aria256\fR] -[\fB\-camellia128\fR] -[\fB\-camellia192\fR] -[\fB\-camellia256\fR] -[\fB\-des\fR] -[\fB\-des3\fR] -[\fB\-idea\fR] -[\fB\-text\fR] -[\fB\-noout\fR] -[\fB\-modulus\fR] -[\fB\-traditional\fR] -[\fB\-check\fR] -[\fB\-pubin\fR] -[\fB\-pubout\fR] -[\fB\-RSAPublicKey_in\fR] -[\fB\-RSAPublicKey_out\fR] -[\fB\-pvk\-strong\fR] -[\fB\-pvk\-weak\fR] -[\fB\-pvk\-none\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes \s-1RSA\s0 keys. They can be converted between -various forms and their components printed out. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-inform DER|PEM|P12|ENGINE" -The key input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The key output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-traditional\fR" 4 -.IX Item "-traditional" -When writing a private key, use the traditional PKCS#1 format -instead of the PKCS#8 format. -.IP "\fB\-in\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-in filename|uri" -This specifies the input to read a key from or standard input if this -option is not specified. If the key is encrypted a pass phrase will be -prompted for. -.IP "\fB\-passin\fR \fIarg\fR, \fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passin arg, -passout arg" -The password source for the input and output file. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write a key to or standard output if this -option is not specified. If any encryption options are set then a pass phrase -will be prompted for. The output filename should \fBnot\fR be the same as the input -filename. -.IP "\fB\-aes128\fR, \fB\-aes192\fR, \fB\-aes256\fR, \fB\-aria128\fR, \fB\-aria192\fR, \fB\-aria256\fR, \fB\-camellia128\fR, \fB\-camellia192\fR, \fB\-camellia256\fR, \fB\-des\fR, \fB\-des3\fR, \fB\-idea\fR" 4 -.IX Item "-aes128, -aes192, -aes256, -aria128, -aria192, -aria256, -camellia128, -camellia192, -camellia256, -des, -des3, -idea" -These options encrypt the private key with the specified -cipher before outputting it. A pass phrase is prompted for. -If none of these options is specified the key is written in plain text. This -means that this command can be used to remove the pass phrase from a key -by not giving any encryption option is given, or to add or change the pass -phrase by setting them. -These options can only be used with \s-1PEM\s0 format output files. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the various public or private key components in -plain text in addition to the encoded version. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option prevents output of the encoded version of the key. -.IP "\fB\-modulus\fR" 4 -.IX Item "-modulus" -This option prints out the value of the modulus of the key. -.IP "\fB\-check\fR" 4 -.IX Item "-check" -This option checks the consistency of an \s-1RSA\s0 private key. -.IP "\fB\-pubin\fR" 4 -.IX Item "-pubin" -By default a private key is read from the input. -With this option a public key is read instead. -If the input contains no public key but a private key, its public part is used. -.IP "\fB\-pubout\fR" 4 -.IX Item "-pubout" -By default a private key is output: with this option a public -key will be output instead. This option is automatically set if -the input is a public key. -.IP "\fB\-RSAPublicKey_in\fR, \fB\-RSAPublicKey_out\fR" 4 -.IX Item "-RSAPublicKey_in, -RSAPublicKey_out" -Like \fB\-pubin\fR and \fB\-pubout\fR except \fBRSAPublicKey\fR format is used instead. -.IP "\fB\-pvk\-strong\fR" 4 -.IX Item "-pvk-strong" -Enable 'Strong' \s-1PVK\s0 encoding level (default). -.IP "\fB\-pvk\-weak\fR" 4 -.IX Item "-pvk-weak" -Enable 'Weak' \s-1PVK\s0 encoding level. -.IP "\fB\-pvk\-none\fR" 4 -.IX Item "-pvk-none" -Don't enforce \s-1PVK\s0 encoding. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -The \fBopenssl\-pkey\fR\|(1) command is capable of performing all the operations -this command can, as well as supporting other public key types. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The documentation for the \fBopenssl\-pkey\fR\|(1) command contains examples -equivalent to the ones listed here. -.PP -To remove the pass phrase on an \s-1RSA\s0 private key: -.PP -.Vb 1 -\& openssl rsa \-in key.pem \-out keyout.pem -.Ve -.PP -To encrypt a private key using triple \s-1DES:\s0 -.PP -.Vb 1 -\& openssl rsa \-in key.pem \-des3 \-out keyout.pem -.Ve -.PP -To convert a private key from \s-1PEM\s0 to \s-1DER\s0 format: -.PP -.Vb 1 -\& openssl rsa \-in key.pem \-outform DER \-out keyout.der -.Ve -.PP -To print out the components of a private key to standard output: -.PP -.Vb 1 -\& openssl rsa \-in key.pem \-text \-noout -.Ve -.PP -To just output the public part of a private key: -.PP -.Vb 1 -\& openssl rsa \-in key.pem \-pubout \-out pubkey.pem -.Ve -.PP -Output the public part of a private key in \fBRSAPublicKey\fR format: -.PP -.Vb 1 -\& openssl rsa \-in key.pem \-RSAPublicKey_out \-out pubkey.pem -.Ve -.SH "BUGS" -.IX Header "BUGS" -There should be an option that automatically handles \fI.key\fR files, -without having to manually edit them. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkey\fR\|(1), -\&\fBopenssl\-pkcs8\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-rsautl.1ossl b/openssl-install/share/man/man1/openssl-rsautl.1ossl deleted file mode 100644 index 507fc574..00000000 --- a/openssl-install/share/man/man1/openssl-rsautl.1ossl +++ /dev/null @@ -1,387 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-RSAUTL 1ossl" -.TH OPENSSL-RSAUTL 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-rsautl \- RSA command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBrsautl\fR -[\fB\-help\fR] -[\fB\-in\fR \fIfile\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-rev\fR] -[\fB\-out\fR \fIfile\fR] -[\fB\-inkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-pubin\fR] -[\fB\-certin\fR] -[\fB\-sign\fR] -[\fB\-verify\fR] -[\fB\-encrypt\fR] -[\fB\-decrypt\fR] -[\fB\-pkcs\fR] -[\fB\-x931\fR] -[\fB\-oaep\fR] -[\fB\-raw\fR] -[\fB\-hexdump\fR] -[\fB\-asn1parse\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command has been deprecated. -The \fBopenssl\-pkeyutl\fR\|(1) command should be used instead. -.PP -This command can be used to sign, verify, encrypt and decrypt -data using the \s-1RSA\s0 algorithm. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read data from or standard input -if this option is not specified. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The passphrase used in the output file. -See see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-rev\fR" 4 -.IX Item "-rev" -Reverse the order of the input. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Specifies the output filename to write to or standard output by -default. -.IP "\fB\-inkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-inkey filename|uri" -The input key, by default it should be an \s-1RSA\s0 private key. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The key format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-pubin\fR" 4 -.IX Item "-pubin" -By default a private key is read from the key input. -With this option a public key is read instead. -If the input contains no public key but a private key, its public part is used. -.IP "\fB\-certin\fR" 4 -.IX Item "-certin" -The input is a certificate containing an \s-1RSA\s0 public key. -.IP "\fB\-sign\fR" 4 -.IX Item "-sign" -Sign the input data and output the signed result. This requires -an \s-1RSA\s0 private key. -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verify the input data and output the recovered data. -.IP "\fB\-encrypt\fR" 4 -.IX Item "-encrypt" -Encrypt the input data using an \s-1RSA\s0 public key. -.IP "\fB\-decrypt\fR" 4 -.IX Item "-decrypt" -Decrypt the input data using an \s-1RSA\s0 private key. -.IP "\fB\-pkcs\fR, \fB\-oaep\fR, \fB\-x931\fR, \fB\-raw\fR" 4 -.IX Item "-pkcs, -oaep, -x931, -raw" -The padding to use: PKCS#1 v1.5 (the default), PKCS#1 \s-1OAEP, -ANSI X9.31,\s0 or no padding, respectively. -For signatures, only \fB\-pkcs\fR and \fB\-raw\fR can be used. -.Sp -Note: because of protection against Bleichenbacher attacks, decryption -using PKCS#1 v1.5 mode will not return errors in case padding check failed. -Use \fB\-raw\fR and inspect the returned value manually to check if the -padding is correct. -.IP "\fB\-hexdump\fR" 4 -.IX Item "-hexdump" -Hex dump the output data. -.IP "\fB\-asn1parse\fR" 4 -.IX Item "-asn1parse" -Parse the \s-1ASN.1\s0 output data, this is useful when combined with the -\&\fB\-verify\fR option. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -Since this command uses the \s-1RSA\s0 algorithm directly, it can only be -used to sign or verify small pieces of data. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Examples equivalent to these can be found in the documentation for the -non-deprecated \fBopenssl\-pkeyutl\fR\|(1) command. -.PP -Sign some data using a private key: -.PP -.Vb 1 -\& openssl rsautl \-sign \-in file \-inkey key.pem \-out sig -.Ve -.PP -Recover the signed data -.PP -.Vb 1 -\& openssl rsautl \-verify \-in sig \-inkey key.pem -.Ve -.PP -Examine the raw signed data: -.PP -.Vb 1 -\& openssl rsautl \-verify \-in sig \-inkey key.pem \-raw \-hexdump -\& -\& 0000 \- 00 01 ff ff ff ff ff ff\-ff ff ff ff ff ff ff ff ................ -\& 0010 \- ff ff ff ff ff ff ff ff\-ff ff ff ff ff ff ff ff ................ -\& 0020 \- ff ff ff ff ff ff ff ff\-ff ff ff ff ff ff ff ff ................ -\& 0030 \- ff ff ff ff ff ff ff ff\-ff ff ff ff ff ff ff ff ................ -\& 0040 \- ff ff ff ff ff ff ff ff\-ff ff ff ff ff ff ff ff ................ -\& 0050 \- ff ff ff ff ff ff ff ff\-ff ff ff ff ff ff ff ff ................ -\& 0060 \- ff ff ff ff ff ff ff ff\-ff ff ff ff ff ff ff ff ................ -\& 0070 \- ff ff ff ff 00 68 65 6c\-6c 6f 20 77 6f 72 6c 64 .....hello world -.Ve -.PP -The PKCS#1 block formatting is evident from this. If this was done using -encrypt and decrypt the block would have been of type 2 (the second byte) -and random padding data visible instead of the 0xff bytes. -.PP -It is possible to analyse the signature of certificates using this -command in conjunction with \fBopenssl\-asn1parse\fR\|(1). Consider the self signed -example in \fIcerts/pca\-cert.pem\fR. Running \fBopenssl\-asn1parse\fR\|(1) as follows -yields: -.PP -.Vb 1 -\& openssl asn1parse \-in pca\-cert.pem -\& -\& 0:d=0 hl=4 l= 742 cons: SEQUENCE -\& 4:d=1 hl=4 l= 591 cons: SEQUENCE -\& 8:d=2 hl=2 l= 3 cons: cont [ 0 ] -\& 10:d=3 hl=2 l= 1 prim: INTEGER :02 -\& 13:d=2 hl=2 l= 1 prim: INTEGER :00 -\& 16:d=2 hl=2 l= 13 cons: SEQUENCE -\& 18:d=3 hl=2 l= 9 prim: OBJECT :md5WithRSAEncryption -\& 29:d=3 hl=2 l= 0 prim: NULL -\& 31:d=2 hl=2 l= 92 cons: SEQUENCE -\& 33:d=3 hl=2 l= 11 cons: SET -\& 35:d=4 hl=2 l= 9 cons: SEQUENCE -\& 37:d=5 hl=2 l= 3 prim: OBJECT :countryName -\& 42:d=5 hl=2 l= 2 prim: PRINTABLESTRING :AU -\& .... -\& 599:d=1 hl=2 l= 13 cons: SEQUENCE -\& 601:d=2 hl=2 l= 9 prim: OBJECT :md5WithRSAEncryption -\& 612:d=2 hl=2 l= 0 prim: NULL -\& 614:d=1 hl=3 l= 129 prim: BIT STRING -.Ve -.PP -The final \s-1BIT STRING\s0 contains the actual signature. It can be extracted with: -.PP -.Vb 1 -\& openssl asn1parse \-in pca\-cert.pem \-out sig \-noout \-strparse 614 -.Ve -.PP -The certificate public key can be extracted with: -.PP -.Vb 1 -\& openssl x509 \-in test/testx509.pem \-pubkey \-noout >pubkey.pem -.Ve -.PP -The signature can be analysed with: -.PP -.Vb 1 -\& openssl rsautl \-in sig \-verify \-asn1parse \-inkey pubkey.pem \-pubin -\& -\& 0:d=0 hl=2 l= 32 cons: SEQUENCE -\& 2:d=1 hl=2 l= 12 cons: SEQUENCE -\& 4:d=2 hl=2 l= 8 prim: OBJECT :md5 -\& 14:d=2 hl=2 l= 0 prim: NULL -\& 16:d=1 hl=2 l= 16 prim: OCTET STRING -\& 0000 \- f3 46 9e aa 1a 4a 73 c9\-37 ea 93 00 48 25 08 b5 .F...Js.7...H%.. -.Ve -.PP -This is the parsed version of an \s-1ASN1\s0 DigestInfo structure. It can be seen that -the digest used was md5. The actual part of the certificate that was signed can -be extracted with: -.PP -.Vb 1 -\& openssl asn1parse \-in pca\-cert.pem \-out tbs \-noout \-strparse 4 -.Ve -.PP -and its digest computed with: -.PP -.Vb 2 -\& openssl md5 \-c tbs -\& MD5(tbs)= f3:46:9e:aa:1a:4a:73:c9:37:ea:93:00:48:25:08:b5 -.Ve -.PP -which it can be seen agrees with the recovered value above. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-pkeyutl\fR\|(1), -\&\fBopenssl\-dgst\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -This command was deprecated in OpenSSL 3.0. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-s_client.1ossl b/openssl-install/share/man/man1/openssl-s_client.1ossl deleted file mode 100644 index 4b76ddf8..00000000 --- a/openssl-install/share/man/man1/openssl-s_client.1ossl +++ /dev/null @@ -1,1219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-S_CLIENT 1ossl" -.TH OPENSSL-S_CLIENT 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-s_client \- SSL/TLS client program -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBs_client\fR -[\fB\-help\fR] -[\fB\-ssl_config\fR \fIsection\fR] -[\fB\-connect\fR \fIhost\fR:\fIport\fR] -[\fB\-host\fR \fIhostname\fR] -[\fB\-port\fR \fIport\fR] -[\fB\-bind\fR \fIhost\fR:\fIport\fR] -[\fB\-proxy\fR \fIhost\fR:\fIport\fR] -[\fB\-proxy_user\fR \fIuserid\fR] -[\fB\-proxy_pass\fR \fIarg\fR] -[\fB\-unix\fR \fIpath\fR] -[\fB\-4\fR] -[\fB\-6\fR] -[\fB\-quic\fR] -[\fB\-servername\fR \fIname\fR] -[\fB\-noservername\fR] -[\fB\-verify\fR \fIdepth\fR] -[\fB\-verify_return_error\fR] -[\fB\-verify_quiet\fR] -[\fB\-verifyCAfile\fR \fIfilename\fR] -[\fB\-verifyCApath\fR \fIdir\fR] -[\fB\-verifyCAstore\fR \fIuri\fR] -[\fB\-cert\fR \fIfilename\fR] -[\fB\-certform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR] -[\fB\-cert_chain\fR \fIfilename\fR] -[\fB\-build_chain\fR] -[\fB\-CRL\fR \fIfilename\fR] -[\fB\-CRLform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-crl_download\fR] -[\fB\-key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-pass\fR \fIarg\fR] -[\fB\-chainCAfile\fR \fIfilename\fR] -[\fB\-chainCApath\fR \fIdirectory\fR] -[\fB\-chainCAstore\fR \fIuri\fR] -[\fB\-requestCAfile\fR \fIfilename\fR] -[\fB\-dane_tlsa_domain\fR \fIdomain\fR] -[\fB\-dane_tlsa_rrdata\fR \fIrrdata\fR] -[\fB\-dane_ee_no_namechecks\fR] -[\fB\-reconnect\fR] -[\fB\-showcerts\fR] -[\fB\-prexit\fR] -[\fB\-no\-interactive\fR] -[\fB\-debug\fR] -[\fB\-trace\fR] -[\fB\-nocommands\fR] -[\fB\-adv\fR] -[\fB\-security_debug\fR] -[\fB\-security_debug_verbose\fR] -[\fB\-msg\fR] -[\fB\-timeout\fR] -[\fB\-mtu\fR \fIsize\fR] -[\fB\-no_etm\fR] -[\fB\-no_ems\fR] -[\fB\-keymatexport\fR \fIlabel\fR] -[\fB\-keymatexportlen\fR \fIlen\fR] -[\fB\-msgfile\fR \fIfilename\fR] -[\fB\-nbio_test\fR] -[\fB\-state\fR] -[\fB\-nbio\fR] -[\fB\-crlf\fR] -[\fB\-ign_eof\fR] -[\fB\-no_ign_eof\fR] -[\fB\-psk_identity\fR \fIidentity\fR] -[\fB\-psk\fR \fIkey\fR] -[\fB\-psk_session\fR \fIfile\fR] -[\fB\-quiet\fR] -[\fB\-sctp\fR] -[\fB\-sctp_label_bug\fR] -[\fB\-fallback_scsv\fR] -[\fB\-async\fR] -[\fB\-maxfraglen\fR \fIlen\fR] -[\fB\-max_send_frag\fR] -[\fB\-split_send_frag\fR] -[\fB\-max_pipelines\fR] -[\fB\-read_buf\fR] -[\fB\-ignore_unexpected_eof\fR] -[\fB\-bugs\fR] -[\fB\-no_tx_cert_comp\fR] -[\fB\-no_rx_cert_comp\fR] -[\fB\-comp\fR] -[\fB\-no_comp\fR] -[\fB\-brief\fR] -[\fB\-legacy_server_connect\fR] -[\fB\-no_legacy_server_connect\fR] -[\fB\-allow_no_dhe_kex\fR] -[\fB\-prefer_no_dhe_kex\fR] -[\fB\-sigalgs\fR \fIsigalglist\fR] -[\fB\-curves\fR \fIcurvelist\fR] -[\fB\-cipher\fR \fIcipherlist\fR] -[\fB\-ciphersuites\fR \fIval\fR] -[\fB\-serverpref\fR] -[\fB\-starttls\fR \fIprotocol\fR] -[\fB\-name\fR \fIhostname\fR] -[\fB\-xmpphost\fR \fIhostname\fR] -[\fB\-name\fR \fIhostname\fR] -[\fB\-tlsextdebug\fR] -[\fB\-no_ticket\fR] -[\fB\-sess_out\fR \fIfilename\fR] -[\fB\-serverinfo\fR \fItypes\fR] -[\fB\-sess_in\fR \fIfilename\fR] -[\fB\-serverinfo\fR \fItypes\fR] -[\fB\-status\fR] -[\fB\-alpn\fR \fIprotocols\fR] -[\fB\-nextprotoneg\fR \fIprotocols\fR] -[\fB\-ct\fR] -[\fB\-noct\fR] -[\fB\-ctlogfile\fR] -[\fB\-keylogfile\fR \fIfile\fR] -[\fB\-early_data\fR \fIfile\fR] -[\fB\-enable_pha\fR] -[\fB\-use_srtp\fR \fIvalue\fR] -[\fB\-srpuser\fR \fIvalue\fR] -[\fB\-srppass\fR \fIvalue\fR] -[\fB\-srp_lateuser\fR] -[\fB\-srp_moregroups\fR] -[\fB\-srp_strength\fR \fInumber\fR] -[\fB\-ktls\fR] -[\fB\-tfo\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-no_ssl3\fR] -[\fB\-no_tls1\fR] -[\fB\-no_tls1_1\fR] -[\fB\-no_tls1_2\fR] -[\fB\-no_tls1_3\fR] -[\fB\-ssl3\fR] -[\fB\-tls1\fR] -[\fB\-tls1_1\fR] -[\fB\-tls1_2\fR] -[\fB\-tls1_3\fR] -[\fB\-dtls\fR] -[\fB\-dtls1\fR] -[\fB\-dtls1_2\fR] -[\fB\-xkey\fR \fIinfile\fR] -[\fB\-xcert\fR \fIfile\fR] -[\fB\-xchain\fR \fIfile\fR] -[\fB\-xchain_build\fR \fIfile\fR] -[\fB\-xcertform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR]> -[\fB\-xkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR]> -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-bugs\fR] -[\fB\-no_comp\fR] -[\fB\-comp\fR] -[\fB\-no_ticket\fR] -[\fB\-serverpref\fR] -[\fB\-client_renegotiation\fR] -[\fB\-legacy_renegotiation\fR] -[\fB\-no_renegotiation\fR] -[\fB\-no_resumption_on_reneg\fR] -[\fB\-legacy_server_connect\fR] -[\fB\-no_legacy_server_connect\fR] -[\fB\-no_etm\fR] -[\fB\-allow_no_dhe_kex\fR] -[\fB\-prefer_no_dhe_kex\fR] -[\fB\-prioritize_chacha\fR] -[\fB\-strict\fR] -[\fB\-sigalgs\fR \fIalgs\fR] -[\fB\-client_sigalgs\fR \fIalgs\fR] -[\fB\-groups\fR \fIgroups\fR] -[\fB\-curves\fR \fIcurves\fR] -[\fB\-named_curve\fR \fIcurve\fR] -[\fB\-cipher\fR \fIciphers\fR] -[\fB\-ciphersuites\fR \fI1.3ciphers\fR] -[\fB\-min_protocol\fR \fIminprot\fR] -[\fB\-max_protocol\fR \fImaxprot\fR] -[\fB\-record_padding\fR \fIpadding\fR] -[\fB\-debug_broken_protocol\fR] -[\fB\-no_middlebox\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-ssl_client_engine\fR \fIid\fR] -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -[\fB\-enable_server_rpk\fR] -[\fB\-enable_client_rpk\fR] -[\fIhost\fR:\fIport\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command implements a generic \s-1SSL/TLS\s0 client which -connects to a remote host using \s-1SSL/TLS.\s0 It is a \fIvery\fR useful diagnostic -tool for \s-1SSL\s0 servers. -.SH "OPTIONS" -.IX Header "OPTIONS" -In addition to the options below, this command also supports the -common and client only options documented -in the \*(L"Supported Command Line Commands\*(R" section of the \fBSSL_CONF_cmd\fR\|(3) -manual page. -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-ssl_config\fR \fIsection\fR" 4 -.IX Item "-ssl_config section" -Use the specified section of the configuration file to configure the \fB\s-1SSL_CTX\s0\fR object. -.IP "\fB\-connect\fR \fIhost\fR:\fIport\fR" 4 -.IX Item "-connect host:port" -This specifies the host and optional port to connect to. It is possible to -select the host and port using the optional target positional argument instead. -If neither this nor the target positional argument are specified then an attempt -is made to connect to the local host on port 4433. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -.IP "\fB\-host\fR \fIhostname\fR" 4 -.IX Item "-host hostname" -Host to connect to; use \fB\-connect\fR instead. -.IP "\fB\-port\fR \fIport\fR" 4 -.IX Item "-port port" -Connect to the specified port; use \fB\-connect\fR instead. -.IP "\fB\-bind\fR \fIhost\fR:\fIport\fR" 4 -.IX Item "-bind host:port" -This specifies the host address and or port to bind as the source for the -connection. For Unix-domain sockets the port is ignored and the host is -used as the source socket address. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -.IP "\fB\-proxy\fR \fIhost\fR:\fIport\fR" 4 -.IX Item "-proxy host:port" -When used with the \fB\-connect\fR flag, the program uses the host and port -specified with this flag and issues an \s-1HTTP CONNECT\s0 command to connect -to the desired server. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -.IP "\fB\-proxy_user\fR \fIuserid\fR" 4 -.IX Item "-proxy_user userid" -When used with the \fB\-proxy\fR flag, the program will attempt to authenticate -with the specified proxy using basic (base64) authentication. -\&\s-1NB:\s0 Basic authentication is insecure; the credentials are sent to the proxy -in easily reversible base64 encoding before any \s-1TLS/SSL\s0 session is established. -Therefore, these credentials are easily recovered by anyone able to sniff/trace -the network. Use with caution. -.IP "\fB\-proxy_pass\fR \fIarg\fR" 4 -.IX Item "-proxy_pass arg" -The proxy password source, used with the \fB\-proxy_user\fR flag. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-unix\fR \fIpath\fR" 4 -.IX Item "-unix path" -Connect over the specified Unix-domain socket. -.IP "\fB\-4\fR" 4 -.IX Item "-4" -Use IPv4 only. -.IP "\fB\-6\fR" 4 -.IX Item "-6" -Use IPv6 only. -.IP "\fB\-quic\fR" 4 -.IX Item "-quic" -Connect using the \s-1QUIC\s0 protocol. If specified then the \fB\-alpn\fR option must also -be provided. -.IP "\fB\-servername\fR \fIname\fR" 4 -.IX Item "-servername name" -Set the \s-1TLS SNI\s0 (Server Name Indication) extension in the ClientHello message to -the given value. -If \fB\-servername\fR is not provided, the \s-1TLS SNI\s0 extension will be populated with -the name given to \fB\-connect\fR if it follows a \s-1DNS\s0 name format. If \fB\-connect\fR is -not provided either, the \s-1SNI\s0 is set to \*(L"localhost\*(R". -This is the default since OpenSSL 1.1.1. -.Sp -Even though \s-1SNI\s0 should normally be a \s-1DNS\s0 name and not an \s-1IP\s0 address, if -\&\fB\-servername\fR is provided then that name will be sent, regardless of whether -it is a \s-1DNS\s0 name or not. -.Sp -This option cannot be used in conjunction with \fB\-noservername\fR. -.IP "\fB\-noservername\fR" 4 -.IX Item "-noservername" -Suppresses sending of the \s-1SNI\s0 (Server Name Indication) extension in the -ClientHello message. Cannot be used in conjunction with the \fB\-servername\fR or -\&\fB\-dane_tlsa_domain\fR options. -.IP "\fB\-cert\fR \fIfilename\fR" 4 -.IX Item "-cert filename" -The client certificate to use, if one is requested by the server. -The default is not to use a certificate. -.Sp -The chain for the client certificate may be specified using \fB\-cert_chain\fR. -.IP "\fB\-certform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR" 4 -.IX Item "-certform DER|PEM|P12" -The client certificate file format to use; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-cert_chain\fR" 4 -.IX Item "-cert_chain" -A file or \s-1URI\s0 of untrusted certificates to use when attempting to build the -certificate chain related to the certificate specified via the \fB\-cert\fR option. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-build_chain\fR" 4 -.IX Item "-build_chain" -Specify whether the application should build the client certificate chain to be -provided to the server. -.IP "\fB\-CRL\fR \fIfilename\fR" 4 -.IX Item "-CRL filename" -\&\s-1CRL\s0 file to use to check the server's certificate. -.IP "\fB\-CRLform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-CRLform DER|PEM" -The \s-1CRL\s0 file format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-crl_download\fR" 4 -.IX Item "-crl_download" -Download \s-1CRL\s0 from distribution points in the certificate. Note that this option -is ignored if \fB\-crl_check\fR option is not provided. Note that the maximum size -of \s-1CRL\s0 is limited by \fBX509_CRL_load_http\fR\|(3) function. -.IP "\fB\-key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-key filename|uri" -The client private key to use. -If not specified then the certificate file will be used to read also the key. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The key format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-pass\fR \fIarg\fR" 4 -.IX Item "-pass arg" -the private key and certificate file password source. -For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-verify\fR \fIdepth\fR" 4 -.IX Item "-verify depth" -The verify depth to use. This specifies the maximum length of the -server certificate chain and turns on server certificate verification. -Unless the \fB\-verify_return_error\fR option is given, -the verify operation continues after errors so all the problems -with a certificate chain can be seen. As a side effect the connection -will never fail due to a server certificate verify failure. -.Sp -By default, validation of server certificates and their chain -is done w.r.t. the (D)TLS Server (\f(CW\*(C`sslserver\*(C'\fR) purpose. -For details see \*(L"Certificate Extensions\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.IP "\fB\-verify_return_error\fR" 4 -.IX Item "-verify_return_error" -Turns on server certificate verification, like with \fB\-verify\fR, -but returns verification errors instead of continuing. -This will typically abort the handshake with a fatal error. -.IP "\fB\-verify_quiet\fR" 4 -.IX Item "-verify_quiet" -Limit verify output to only errors. -.IP "\fB\-verifyCAfile\fR \fIfilename\fR" 4 -.IX Item "-verifyCAfile filename" -A file in \s-1PEM\s0 format containing trusted certificates to use -for verifying the server's certificate. -.IP "\fB\-verifyCApath\fR \fIdir\fR" 4 -.IX Item "-verifyCApath dir" -A directory containing trusted certificates to use -for verifying the server's certificate. -This directory must be in \*(L"hash format\*(R", -see \fBopenssl\-verify\fR\|(1) for more information. -.IP "\fB\-verifyCAstore\fR \fIuri\fR" 4 -.IX Item "-verifyCAstore uri" -The \s-1URI\s0 of a store containing trusted certificates to use -for verifying the server's certificate. -.IP "\fB\-chainCAfile\fR \fIfile\fR" 4 -.IX Item "-chainCAfile file" -A file in \s-1PEM\s0 format containing trusted certificates to use -when attempting to build the client certificate chain. -.IP "\fB\-chainCApath\fR \fIdirectory\fR" 4 -.IX Item "-chainCApath directory" -A directory containing trusted certificates to use -for building the client certificate chain provided to the server. -This directory must be in \*(L"hash format\*(R", -see \fBopenssl\-verify\fR\|(1) for more information. -.IP "\fB\-chainCAstore\fR \fIuri\fR" 4 -.IX Item "-chainCAstore uri" -The \s-1URI\s0 of a store containing trusted certificates to use -when attempting to build the client certificate chain. -The \s-1URI\s0 may indicate a single certificate, as well as a collection of them. -With URIs in the \f(CW\*(C`file:\*(C'\fR scheme, this acts as \fB\-chainCAfile\fR or -\&\fB\-chainCApath\fR, depending on if the \s-1URI\s0 indicates a directory or a -single file. -See \fBossl_store\-file\fR\|(7) for more information on the \f(CW\*(C`file:\*(C'\fR scheme. -.IP "\fB\-requestCAfile\fR \fIfile\fR" 4 -.IX Item "-requestCAfile file" -A file containing a list of certificates whose subject names will be sent -to the server in the \fBcertificate_authorities\fR extension. Only supported -for \s-1TLS 1.3\s0 -.IP "\fB\-dane_tlsa_domain\fR \fIdomain\fR" 4 -.IX Item "-dane_tlsa_domain domain" -Enable \s-1RFC6698/RFC7671 DANE TLSA\s0 authentication and specify the -\&\s-1TLSA\s0 base domain which becomes the default \s-1SNI\s0 hint and the primary -reference identifier for hostname checks. This must be used in -combination with at least one instance of the \fB\-dane_tlsa_rrdata\fR -option below. -.Sp -When \s-1DANE\s0 authentication succeeds, the diagnostic output will include -the lowest (closest to 0) depth at which a \s-1TLSA\s0 record authenticated -a chain certificate. When that \s-1TLSA\s0 record is a \*(L"2 1 0\*(R" trust -anchor public key that signed (rather than matched) the top-most -certificate of the chain, the result is reported as \*(L"\s-1TA\s0 public key -verified\*(R". Otherwise, either the \s-1TLSA\s0 record \*(L"matched \s-1TA\s0 certificate\*(R" -at a positive depth or else \*(L"matched \s-1EE\s0 certificate\*(R" at depth 0. -.IP "\fB\-dane_tlsa_rrdata\fR \fIrrdata\fR" 4 -.IX Item "-dane_tlsa_rrdata rrdata" -Use one or more times to specify the \s-1RRDATA\s0 fields of the \s-1DANE TLSA\s0 -RRset associated with the target service. The \fIrrdata\fR value is -specified in \*(L"presentation form\*(R", that is four whitespace separated -fields that specify the usage, selector, matching type and associated -data, with the last of these encoded in hexadecimal. Optional -whitespace is ignored in the associated data field. For example: -.Sp -.Vb 12 -\& $ openssl s_client \-brief \-starttls smtp \e -\& \-connect smtp.example.com:25 \e -\& \-dane_tlsa_domain smtp.example.com \e -\& \-dane_tlsa_rrdata "2 1 1 -\& B111DD8A1C2091A89BD4FD60C57F0716CCE50FEEFF8137CDBEE0326E 02CF362B" \e -\& \-dane_tlsa_rrdata "2 1 1 -\& 60B87575447DCBA2A36B7D11AC09FB24A9DB406FEE12D2CC90180517 616E8A18" -\& ... -\& Verification: OK -\& Verified peername: smtp.example.com -\& DANE TLSA 2 1 1 ...ee12d2cc90180517616e8a18 matched TA certificate at depth 1 -\& ... -.Ve -.IP "\fB\-dane_ee_no_namechecks\fR" 4 -.IX Item "-dane_ee_no_namechecks" -This disables server name checks when authenticating via \s-1\fBDANE\-EE\s0\fR\|(3) \s-1TLSA\s0 -records. -For some applications, primarily web browsers, it is not safe to disable name -checks due to \*(L"unknown key share\*(R" attacks, in which a malicious server can -convince a client that a connection to a victim server is instead a secure -connection to the malicious server. -The malicious server may then be able to violate cross-origin scripting -restrictions. -Thus, despite the text of \s-1RFC7671,\s0 name checks are by default enabled for -\&\s-1\fBDANE\-EE\s0\fR\|(3) \s-1TLSA\s0 records, and can be disabled in applications where it is safe -to do so. -In particular, \s-1SMTP\s0 and \s-1XMPP\s0 clients should set this option as \s-1SRV\s0 and \s-1MX\s0 -records already make it possible for a remote domain to redirect client -connections to any server of its choice, and in any case \s-1SMTP\s0 and \s-1XMPP\s0 clients -do not execute scripts downloaded from remote servers. -.IP "\fB\-reconnect\fR" 4 -.IX Item "-reconnect" -Reconnects to the same server 5 times using the same session \s-1ID,\s0 this can -be used as a test that session caching is working. -.IP "\fB\-showcerts\fR" 4 -.IX Item "-showcerts" -Displays the server certificate list as sent by the server: it only consists of -certificates the server has sent (in the order the server has sent them). It is -\&\fBnot\fR a verified chain. -.IP "\fB\-prexit\fR" 4 -.IX Item "-prexit" -Print session information when the program exits. This will always attempt -to print out information even if the connection fails. Normally information -will only be printed out once if the connection succeeds. This option is useful -because the cipher in use may be renegotiated or the connection may fail -because a client certificate is required or is requested only after an -attempt is made to access a certain \s-1URL.\s0 Note: the output produced by this -option is not always accurate because a connection might never have been -established. -.IP "\fB\-no\-interactive\fR" 4 -.IX Item "-no-interactive" -This flag can be used to run the client in a non-interactive mode. -.IP "\fB\-state\fR" 4 -.IX Item "-state" -Prints out the \s-1SSL\s0 session states. -.IP "\fB\-debug\fR" 4 -.IX Item "-debug" -Print extensive debugging information including a hex dump of all traffic. -.IP "\fB\-nocommands\fR" 4 -.IX Item "-nocommands" -Do not use interactive command letters. -.IP "\fB\-adv\fR" 4 -.IX Item "-adv" -Use advanced command mode. -.IP "\fB\-security_debug\fR" 4 -.IX Item "-security_debug" -Enable security debug messages. -.IP "\fB\-security_debug_verbose\fR" 4 -.IX Item "-security_debug_verbose" -Output more security debug output. -.IP "\fB\-msg\fR" 4 -.IX Item "-msg" -Show protocol messages. -.IP "\fB\-timeout\fR" 4 -.IX Item "-timeout" -Enable send/receive timeout on \s-1DTLS\s0 connections. -.IP "\fB\-mtu\fR \fIsize\fR" 4 -.IX Item "-mtu size" -Set \s-1MTU\s0 of the link layer to the specified size. -.IP "\fB\-no_etm\fR" 4 -.IX Item "-no_etm" -Disable Encrypt-then-MAC negotiation. -.IP "\fB\-no_ems\fR" 4 -.IX Item "-no_ems" -Disable Extended master secret negotiation. -.IP "\fB\-keymatexport\fR \fIlabel\fR" 4 -.IX Item "-keymatexport label" -Export keying material using the specified label. -.IP "\fB\-keymatexportlen\fR \fIlen\fR" 4 -.IX Item "-keymatexportlen len" -Export the specified number of bytes of keying material; default is 20. -.Sp -Show all protocol messages with hex dump. -.IP "\fB\-trace\fR" 4 -.IX Item "-trace" -Show verbose trace output of protocol messages. -.IP "\fB\-msgfile\fR \fIfilename\fR" 4 -.IX Item "-msgfile filename" -File to send output of \fB\-msg\fR or \fB\-trace\fR to, default standard output. -.IP "\fB\-nbio_test\fR" 4 -.IX Item "-nbio_test" -Tests nonblocking I/O -.IP "\fB\-nbio\fR" 4 -.IX Item "-nbio" -Turns on nonblocking I/O -.IP "\fB\-crlf\fR" 4 -.IX Item "-crlf" -This option translated a line feed from the terminal into \s-1CR+LF\s0 as required -by some servers. -.IP "\fB\-ign_eof\fR" 4 -.IX Item "-ign_eof" -Inhibit shutting down the connection when end of file is reached in the -input. This implicitly turns on \fB\-nocommands\fR as well. -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Inhibit printing of session and certificate information. This implicitly -turns on \fB\-ign_eof\fR and \fB\-nocommands\fR as well. -.IP "\fB\-no_ign_eof\fR" 4 -.IX Item "-no_ign_eof" -Shut down the connection when end of file is reached in the input. -Can be used to override the implicit \fB\-ign_eof\fR after \fB\-quiet\fR. -.IP "\fB\-psk_identity\fR \fIidentity\fR" 4 -.IX Item "-psk_identity identity" -Use the \s-1PSK\s0 identity \fIidentity\fR when using a \s-1PSK\s0 cipher suite. -The default value is \*(L"Client_identity\*(R" (without the quotes). -.IP "\fB\-psk\fR \fIkey\fR" 4 -.IX Item "-psk key" -Use the \s-1PSK\s0 key \fIkey\fR when using a \s-1PSK\s0 cipher suite. The key is -given as a hexadecimal number without leading 0x, for example \-psk -1a2b3c4d. -This option must be provided in order to use a \s-1PSK\s0 cipher. -.IP "\fB\-psk_session\fR \fIfile\fR" 4 -.IX Item "-psk_session file" -Use the pem encoded \s-1SSL_SESSION\s0 data stored in \fIfile\fR as the basis of a \s-1PSK.\s0 -Note that this will only work if TLSv1.3 is negotiated. -.IP "\fB\-sctp\fR" 4 -.IX Item "-sctp" -Use \s-1SCTP\s0 for the transport protocol instead of \s-1UDP\s0 in \s-1DTLS.\s0 Must be used in -conjunction with \fB\-dtls\fR, \fB\-dtls1\fR or \fB\-dtls1_2\fR. This option is only -available where OpenSSL has support for \s-1SCTP\s0 enabled. -.IP "\fB\-sctp_label_bug\fR" 4 -.IX Item "-sctp_label_bug" -Use the incorrect behaviour of older OpenSSL implementations when computing -endpoint-pair shared secrets for \s-1DTLS/SCTP.\s0 This allows communication with -older broken implementations but breaks interoperability with correct -implementations. Must be used in conjunction with \fB\-sctp\fR. This option is only -available where OpenSSL has support for \s-1SCTP\s0 enabled. -.IP "\fB\-fallback_scsv\fR" 4 -.IX Item "-fallback_scsv" -Send \s-1TLS_FALLBACK_SCSV\s0 in the ClientHello. -.IP "\fB\-async\fR" 4 -.IX Item "-async" -Switch on asynchronous mode. Cryptographic operations will be performed -asynchronously. This will only have an effect if an asynchronous capable engine -is also used via the \fB\-engine\fR option. For test purposes the dummy async engine -(dasync) can be used (if available). -.IP "\fB\-maxfraglen\fR \fIlen\fR" 4 -.IX Item "-maxfraglen len" -Enable Maximum Fragment Length Negotiation; allowed values are -\&\f(CW512\fR, \f(CW1024\fR, \f(CW2048\fR, and \f(CW4096\fR. -.IP "\fB\-max_send_frag\fR \fIint\fR" 4 -.IX Item "-max_send_frag int" -The maximum size of data fragment to send. -See \fBSSL_CTX_set_max_send_fragment\fR\|(3) for further information. -.IP "\fB\-split_send_frag\fR \fIint\fR" 4 -.IX Item "-split_send_frag int" -The size used to split data for encrypt pipelines. If more data is written in -one go than this value then it will be split into multiple pipelines, up to the -maximum number of pipelines defined by max_pipelines. This only has an effect if -a suitable cipher suite has been negotiated, an engine that supports pipelining -has been loaded, and max_pipelines is greater than 1. See -\&\fBSSL_CTX_set_split_send_fragment\fR\|(3) for further information. -.IP "\fB\-max_pipelines\fR \fIint\fR" 4 -.IX Item "-max_pipelines int" -The maximum number of encrypt/decrypt pipelines to be used. This will only have -an effect if an engine has been loaded that supports pipelining (e.g. the dasync -engine) and a suitable cipher suite has been negotiated. The default value is 1. -See \fBSSL_CTX_set_max_pipelines\fR\|(3) for further information. -.IP "\fB\-read_buf\fR \fIint\fR" 4 -.IX Item "-read_buf int" -The default read buffer size to be used for connections. This will only have an -effect if the buffer size is larger than the size that would otherwise be used -and pipelining is in use (see \fBSSL_CTX_set_default_read_buffer_len\fR\|(3) for -further information). -.IP "\fB\-ignore_unexpected_eof\fR" 4 -.IX Item "-ignore_unexpected_eof" -Some \s-1TLS\s0 implementations do not send the mandatory close_notify alert on -shutdown. If the application tries to wait for the close_notify alert but the -peer closes the connection without sending it, an error is generated. When this -option is enabled the peer does not need to send the close_notify alert and a -closed connection will be treated as if the close_notify alert was received. -For more information on shutting down a connection, see \fBSSL_shutdown\fR\|(3). -.IP "\fB\-bugs\fR" 4 -.IX Item "-bugs" -There are several known bugs in \s-1SSL\s0 and \s-1TLS\s0 implementations. Adding this -option enables various workarounds. -.IP "\fB\-no_tx_cert_comp\fR" 4 -.IX Item "-no_tx_cert_comp" -Disables support for sending TLSv1.3 compressed certificates. -.IP "\fB\-no_rx_cert_comp\fR" 4 -.IX Item "-no_rx_cert_comp" -Disables support for receiving TLSv1.3 compressed certificate. -.IP "\fB\-comp\fR" 4 -.IX Item "-comp" -Enables support for \s-1SSL/TLS\s0 compression. -This option was introduced in OpenSSL 1.1.0. -\&\s-1TLS\s0 compression is not recommended and is off by default as of -OpenSSL 1.1.0. \s-1TLS\s0 compression can only be used in security level 1 or -lower. From OpenSSL 3.2.0 and above the default security level is 2, so this -option will have no effect without also changing the security level. Use the -\&\fB\-cipher\fR option to change the security level. See \fBopenssl\-ciphers\fR\|(1) for -more information. -.IP "\fB\-no_comp\fR" 4 -.IX Item "-no_comp" -Disables support for \s-1SSL/TLS\s0 compression. -\&\s-1TLS\s0 compression is not recommended and is off by default as of -OpenSSL 1.1.0. -.IP "\fB\-brief\fR" 4 -.IX Item "-brief" -Only provide a brief summary of connection parameters instead of the -normal verbose output. -.IP "\fB\-sigalgs\fR \fIsigalglist\fR" 4 -.IX Item "-sigalgs sigalglist" -Specifies the list of signature algorithms that are sent by the client. -The server selects one entry in the list based on its preferences. -For example strings, see \fBSSL_CTX_set1_sigalgs\fR\|(3) -.IP "\fB\-curves\fR \fIcurvelist\fR" 4 -.IX Item "-curves curvelist" -Specifies the list of supported curves to be sent by the client. The curve is -ultimately selected by the server. -.Sp -The list of all supported groups includes named \s-1EC\s0 parameters as well as X25519 -and X448 or \s-1FFDHE\s0 groups, and may also include groups implemented in 3rd\-party -providers. For a list of named \s-1EC\s0 parameters, use: -.Sp -.Vb 1 -\& $ openssl ecparam \-list_curves -.Ve -.IP "\fB\-cipher\fR \fIcipherlist\fR" 4 -.IX Item "-cipher cipherlist" -This allows the TLSv1.2 and below cipher list sent by the client to be modified. -This list will be combined with any TLSv1.3 ciphersuites that have been -configured. Although the server determines which ciphersuite is used it should -take the first supported cipher in the list sent by the client. See -\&\fBopenssl\-ciphers\fR\|(1) for more information. -.IP "\fB\-ciphersuites\fR \fIval\fR" 4 -.IX Item "-ciphersuites val" -This allows the TLSv1.3 ciphersuites sent by the client to be modified. This -list will be combined with any TLSv1.2 and below ciphersuites that have been -configured. Although the server determines which cipher suite is used it should -take the first supported cipher in the list sent by the client. See -\&\fBopenssl\-ciphers\fR\|(1) for more information. The format for this list is a simple -colon (\*(L":\*(R") separated list of TLSv1.3 ciphersuite names. -.IP "\fB\-starttls\fR \fIprotocol\fR" 4 -.IX Item "-starttls protocol" -Send the protocol-specific message(s) to switch to \s-1TLS\s0 for communication. -\&\fIprotocol\fR is a keyword for the intended protocol. Currently, the only -supported keywords are \*(L"smtp\*(R", \*(L"pop3\*(R", \*(L"imap\*(R", \*(L"ftp\*(R", \*(L"xmpp\*(R", \*(L"xmpp-server\*(R", -\&\*(L"irc\*(R", \*(L"postgres\*(R", \*(L"mysql\*(R", \*(L"lmtp\*(R", \*(L"nntp\*(R", \*(L"sieve\*(R" and \*(L"ldap\*(R". -.IP "\fB\-xmpphost\fR \fIhostname\fR" 4 -.IX Item "-xmpphost hostname" -This option, when used with \*(L"\-starttls xmpp\*(R" or \*(L"\-starttls xmpp-server\*(R", -specifies the host for the \*(L"to\*(R" attribute of the stream element. -If this option is not specified, then the host specified with \*(L"\-connect\*(R" -will be used. -.Sp -This option is an alias of the \fB\-name\fR option for \*(L"xmpp\*(R" and \*(L"xmpp-server\*(R". -.IP "\fB\-name\fR \fIhostname\fR" 4 -.IX Item "-name hostname" -This option is used to specify hostname information for various protocols -used with \fB\-starttls\fR option. Currently only \*(L"xmpp\*(R", \*(L"xmpp-server\*(R", -\&\*(L"smtp\*(R" and \*(L"lmtp\*(R" can utilize this \fB\-name\fR option. -.Sp -If this option is used with \*(L"\-starttls xmpp\*(R" or \*(L"\-starttls xmpp-server\*(R", -if specifies the host for the \*(L"to\*(R" attribute of the stream element. If this -option is not specified, then the host specified with \*(L"\-connect\*(R" will be used. -.Sp -If this option is used with \*(L"\-starttls lmtp\*(R" or \*(L"\-starttls smtp\*(R", it specifies -the name to use in the \*(L"\s-1LMTP LHLO\*(R"\s0 or \*(L"\s-1SMTP EHLO\*(R"\s0 message, respectively. If -this option is not specified, then \*(L"mail.example.com\*(R" will be used. -.IP "\fB\-tlsextdebug\fR" 4 -.IX Item "-tlsextdebug" -Print out a hex dump of any \s-1TLS\s0 extensions received from the server. -.IP "\fB\-no_ticket\fR" 4 -.IX Item "-no_ticket" -Disable RFC4507bis session ticket support. -.IP "\fB\-sess_out\fR \fIfilename\fR" 4 -.IX Item "-sess_out filename" -Output \s-1SSL\s0 session to \fIfilename\fR. -.IP "\fB\-sess_in\fR \fIfilename\fR" 4 -.IX Item "-sess_in filename" -Load \s-1SSL\s0 session from \fIfilename\fR. The client will attempt to resume a -connection from this session. -.IP "\fB\-serverinfo\fR \fItypes\fR" 4 -.IX Item "-serverinfo types" -A list of comma-separated \s-1TLS\s0 Extension Types (numbers between 0 and -65535). Each type will be sent as an empty ClientHello \s-1TLS\s0 Extension. -The server's response (if any) will be encoded and displayed as a \s-1PEM\s0 -file. -.IP "\fB\-status\fR" 4 -.IX Item "-status" -Sends a certificate status request to the server (\s-1OCSP\s0 stapling). The server -response (if any) is printed out. -.IP "\fB\-alpn\fR \fIprotocols\fR, \fB\-nextprotoneg\fR \fIprotocols\fR" 4 -.IX Item "-alpn protocols, -nextprotoneg protocols" -These flags enable the Enable the Application-Layer Protocol Negotiation -or Next Protocol Negotiation (\s-1NPN\s0) extension, respectively. \s-1ALPN\s0 is the -\&\s-1IETF\s0 standard and replaces \s-1NPN.\s0 -The \fIprotocols\fR list is a comma-separated list of protocol names that -the client should advertise support for. The list should contain the most -desirable protocols first. Protocol names are printable \s-1ASCII\s0 strings, -for example \*(L"http/1.1\*(R" or \*(L"spdy/3\*(R". -An empty list of protocols is treated specially and will cause the -client to advertise support for the \s-1TLS\s0 extension but disconnect just -after receiving ServerHello with a list of server supported protocols. -The flag \fB\-nextprotoneg\fR cannot be specified if \fB\-tls1_3\fR is used. -.IP "\fB\-ct\fR, \fB\-noct\fR" 4 -.IX Item "-ct, -noct" -Use one of these two options to control whether Certificate Transparency (\s-1CT\s0) -is enabled (\fB\-ct\fR) or disabled (\fB\-noct\fR). -If \s-1CT\s0 is enabled, signed certificate timestamps (SCTs) will be requested from -the server and reported at handshake completion. -.Sp -Enabling \s-1CT\s0 also enables \s-1OCSP\s0 stapling, as this is one possible delivery method -for SCTs. -.IP "\fB\-ctlogfile\fR" 4 -.IX Item "-ctlogfile" -A file containing a list of known Certificate Transparency logs. See -\&\fBSSL_CTX_set_ctlog_list_file\fR\|(3) for the expected file format. -.IP "\fB\-keylogfile\fR \fIfile\fR" 4 -.IX Item "-keylogfile file" -Appends \s-1TLS\s0 secrets to the specified keylog file such that external programs -(like Wireshark) can decrypt \s-1TLS\s0 connections. -.IP "\fB\-early_data\fR \fIfile\fR" 4 -.IX Item "-early_data file" -Reads the contents of the specified file and attempts to send it as early data -to the server. This will only work with resumed sessions that support early -data and when the server accepts the early data. -.IP "\fB\-enable_pha\fR" 4 -.IX Item "-enable_pha" -For TLSv1.3 only, send the Post-Handshake Authentication extension. This will -happen whether or not a certificate has been provided via \fB\-cert\fR. -.IP "\fB\-use_srtp\fR \fIvalue\fR" 4 -.IX Item "-use_srtp value" -Offer \s-1SRTP\s0 key management, where \fBvalue\fR is a colon-separated profile list. -.IP "\fB\-srpuser\fR \fIvalue\fR" 4 -.IX Item "-srpuser value" -Set the \s-1SRP\s0 username to the specified value. This option is deprecated. -.IP "\fB\-srppass\fR \fIvalue\fR" 4 -.IX Item "-srppass value" -Set the \s-1SRP\s0 password to the specified value. This option is deprecated. -.IP "\fB\-srp_lateuser\fR" 4 -.IX Item "-srp_lateuser" -\&\s-1SRP\s0 username for the second ClientHello message. This option is deprecated. -.IP "\fB\-srp_moregroups\fR This option is deprecated." 4 -.IX Item "-srp_moregroups This option is deprecated." -Tolerate other than the known \fBg\fR and \fBN\fR values. -.IP "\fB\-srp_strength\fR \fInumber\fR" 4 -.IX Item "-srp_strength number" -Set the minimal acceptable length, in bits, for \fBN\fR. This option is -deprecated. -.IP "\fB\-ktls\fR" 4 -.IX Item "-ktls" -Enable Kernel \s-1TLS\s0 for sending and receiving. -This option was introduced in OpenSSL 3.2.0. -Kernel \s-1TLS\s0 is off by default as of OpenSSL 3.2.0. -.IP "\fB\-tfo\fR" 4 -.IX Item "-tfo" -Enable creation of connections via \s-1TCP\s0 fast open (\s-1RFC7413\s0). -.IP "\fB\-no_ssl3\fR, \fB\-no_tls1\fR, \fB\-no_tls1_1\fR, \fB\-no_tls1_2\fR, \fB\-no_tls1_3\fR, \fB\-ssl3\fR, \fB\-tls1\fR, \fB\-tls1_1\fR, \fB\-tls1_2\fR, \fB\-tls1_3\fR" 4 -.IX Item "-no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3, -ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3" -See \*(L"\s-1TLS\s0 Version Options\*(R" in \fBopenssl\fR\|(1). -.IP "\fB\-dtls\fR, \fB\-dtls1\fR, \fB\-dtls1_2\fR" 4 -.IX Item "-dtls, -dtls1, -dtls1_2" -These specify the use of \s-1DTLS\s0 instead of \s-1TLS.\s0 -See \*(L"\s-1TLS\s0 Version Options\*(R" in \fBopenssl\fR\|(1). -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -This specifies how the subject or issuer names are displayed. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-xkey\fR \fIinfile\fR, \fB\-xcert\fR \fIfile\fR, \fB\-xchain\fR \fIfile\fR, \fB\-xchain_build\fR \fIfile\fR, \fB\-xcertform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR, \fB\-xkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-xkey infile, -xcert file, -xchain file, -xchain_build file, -xcertform DER|PEM, -xkeyform DER|PEM" -Set extended certificate verification options. -See \*(L"Extended Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-bugs\fR, \fB\-comp\fR, \fB\-no_comp\fR, \fB\-no_ticket\fR, \fB\-serverpref\fR, \fB\-client_renegotiation\fR, \fB\-legacy_renegotiation\fR, \fB\-no_renegotiation\fR, \fB\-no_resumption_on_reneg\fR, \fB\-legacy_server_connect\fR, \fB\-no_legacy_server_connect\fR, \fB\-no_etm\fR \fB\-allow_no_dhe_kex\fR, \fB\-prefer_no_dhe_kex\fR, \fB\-prioritize_chacha\fR, \fB\-strict\fR, \fB\-sigalgs\fR \fIalgs\fR, \fB\-client_sigalgs\fR \fIalgs\fR, \fB\-groups\fR \fIgroups\fR, \fB\-curves\fR \fIcurves\fR, \fB\-named_curve\fR \fIcurve\fR, \fB\-cipher\fR \fIciphers\fR, \fB\-ciphersuites\fR \fI1.3ciphers\fR, \fB\-min_protocol\fR \fIminprot\fR, \fB\-max_protocol\fR \fImaxprot\fR, \fB\-record_padding\fR \fIpadding\fR, \fB\-debug_broken_protocol\fR, \fB\-no_middlebox\fR" 4 -.IX Item "-bugs, -comp, -no_comp, -no_ticket, -serverpref, -client_renegotiation, -legacy_renegotiation, -no_renegotiation, -no_resumption_on_reneg, -legacy_server_connect, -no_legacy_server_connect, -no_etm -allow_no_dhe_kex, -prefer_no_dhe_kex, -prioritize_chacha, -strict, -sigalgs algs, -client_sigalgs algs, -groups groups, -curves curves, -named_curve curve, -cipher ciphers, -ciphersuites 1.3ciphers, -min_protocol minprot, -max_protocol maxprot, -record_padding padding, -debug_broken_protocol, -no_middlebox" -See \*(L"\s-1SUPPORTED COMMAND LINE COMMANDS\*(R"\s0 in \fBSSL_CONF_cmd\fR\|(3) for details. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-ssl_client_engine\fR \fIid\fR" 4 -.IX Item "-ssl_client_engine id" -Specify engine to be used for client certificate operations. -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.Sp -Verification errors are displayed, for debugging, but the command will -proceed unless the \fB\-verify_return_error\fR option is used. -.IP "\fB\-enable_server_rpk\fR" 4 -.IX Item "-enable_server_rpk" -Enable support for receiving raw public keys (\s-1RFC7250\s0) from the server. -Use of X.509 certificates by the server becomes optional, and servers that -support raw public keys may elect to use them. -Servers that don't support raw public keys or prefer to use X.509 -certificates can still elect to send X.509 certificates as usual. -.IP "\fB\-enable_client_rpk\fR" 4 -.IX Item "-enable_client_rpk" -Enable support for sending raw public keys (\s-1RFC7250\s0) to the server. -A raw public key will be sent by the client, if solicited by the server, -provided a suitable key and public certificate pair is configured. -Some servers may nevertheless not request any client credentials, -or may request a certificate. -.IP "\fIhost\fR:\fIport\fR" 4 -.IX Item "host:port" -Rather than providing \fB\-connect\fR, the target host and optional port may -be provided as a single positional argument after all options. If neither this -nor \fB\-connect\fR are provided, falls back to attempting to connect to -\&\fIlocalhost\fR on port \fI4433\fR. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -.SH "CONNECTED COMMANDS (BASIC)" -.IX Header "CONNECTED COMMANDS (BASIC)" -If a connection is established with an \s-1SSL/TLS\s0 server then any data received -from the server is displayed and any key presses will be sent to the -server. If end of file is reached then the connection will be closed down. -.PP -When used interactively (which means neither \fB\-quiet\fR nor \fB\-ign_eof\fR have been -given), and neither of \fB\-adv\fR or \fB\-nocommands\fR are given then \*(L"Basic\*(R" command -mode is entered. In this mode certain commands are recognized which perform -special operations. These commands are a letter which must appear at the start -of a line. All further data after the initial letter on the line is ignored. -The commands are listed below. -.IP "\fBQ\fR" 4 -.IX Item "Q" -End the current \s-1SSL\s0 connection and exit. -.IP "\fBR\fR" 4 -.IX Item "R" -Renegotiate the \s-1SSL\s0 session (TLSv1.2 and below only). -.IP "\fBC\fR" 4 -.IX Item "C" -Attempt to reconnect to the server using a resumption handshake. -.IP "\fBk\fR" 4 -.IX Item "k" -Send a key update message to the server (TLSv1.3 only) -.IP "\fBK\fR" 4 -.IX Item "K" -Send a key update message to the server and request one back (TLSv1.3 only) -.SH "CONNECTED COMMANDS (ADVANCED)" -.IX Header "CONNECTED COMMANDS (ADVANCED)" -If \fB\-adv\fR has been given then \*(L"advanced\*(R" command mode is entered. As with basic -mode, if a connection is established with an \s-1SSL/TLS\s0 server then any data -received from the server is displayed and any key presses will be sent to the -server. If end of file is reached then the connection will be closed down. -.PP -Special commands can be supplied by enclosing them in braces, e.g. \*(L"{help}\*(R" or -\&\*(L"{quit}\*(R". These commands can appear anywhere in the text entered into s_client, -but they are not sent to the server. Some commands can take an argument by -ending the command name with \*(L":\*(R" and then providing the argument, e.g. -\&\*(L"{keyup:req}\*(R". Some commands are only available when certain protocol versions -have been negotiated. -.PP -If a newline appears at the end of a line entered into s_client then this is -also sent to the server. If a command appears on a line on its own with no other -text on the same line, then the newline is suppressed and not sent to the -server. -.PP -The following commands are recognised. -.IP "\fBhelp\fR" 4 -.IX Item "help" -Prints out summary help text about the available commands. -.IP "\fBquit\fR" 4 -.IX Item "quit" -Close the connection to the peer -.IP "\fBreconnect\fR" 4 -.IX Item "reconnect" -Reconnect to the peer and attempt a resumption handshake -.IP "\fBkeyup\fR" 4 -.IX Item "keyup" -Send a Key Update message. TLSv1.3 only. This command takes an optional -argument. If the argument \*(L"req\*(R" is supplied then the peer is also requested to -update its keys. Otherwise if \*(L"noreq\*(R" is supplied the peer is not requested -to update its keys. The default is \*(L"req\*(R". -.IP "\fBreneg\fR" 4 -.IX Item "reneg" -Initiate a renegotiation with the server. (D)TLSv1.2 or below only. -.IP "\fBfin\fR" 4 -.IX Item "fin" -Indicate \s-1FIN\s0 on the current stream. \s-1QUIC\s0 only. Once \s-1FIN\s0 has been sent any -further text entered for this stream is ignored. -.SH "NOTES" -.IX Header "NOTES" -This command can be used to debug \s-1SSL\s0 servers. To connect to an \s-1SSL HTTP\s0 -server the command: -.PP -.Vb 1 -\& openssl s_client \-connect servername:443 -.Ve -.PP -would typically be used (https uses port 443). If the connection succeeds -then an \s-1HTTP\s0 command can be given such as \*(L"\s-1GET /\*(R"\s0 to retrieve a web page. -.PP -If the handshake fails then there are several possible causes, if it is -nothing obvious like no client certificate then the \fB\-bugs\fR, -\&\fB\-ssl3\fR, \fB\-tls1\fR, \fB\-no_ssl3\fR, \fB\-no_tls1\fR options can be tried -in case it is a buggy server. In particular you should play with these -options \fBbefore\fR submitting a bug report to an OpenSSL mailing list. -.PP -A frequent problem when attempting to get client certificates working -is that a web client complains it has no certificates or gives an empty -list to choose from. This is normally because the server is not sending -the clients certificate authority in its \*(L"acceptable \s-1CA\s0 list\*(R" when it -requests a certificate. By using this command, the \s-1CA\s0 list can be viewed -and checked. However, some servers only request client authentication -after a specific \s-1URL\s0 is requested. To obtain the list in this case it -is necessary to use the \fB\-prexit\fR option and send an \s-1HTTP\s0 request -for an appropriate page. -.PP -If a certificate is specified on the command line using the \fB\-cert\fR -option it will not be used unless the server specifically requests -a client certificate. Therefore, merely including a client certificate -on the command line is no guarantee that the certificate works. -.PP -If there are problems verifying a server certificate then the -\&\fB\-showcerts\fR option can be used to show all the certificates sent by the -server. -.PP -This command is a test tool and is designed to continue the -handshake after any certificate verification errors. As a result it will -accept any certificate chain (trusted or not) sent by the peer. Non-test -applications should \fBnot\fR do this as it makes them vulnerable to a \s-1MITM\s0 -attack. This behaviour can be changed by with the \fB\-verify_return_error\fR -option: any verify errors are then returned aborting the handshake. -.PP -The \fB\-bind\fR option may be useful if the server or a firewall requires -connections to come from some particular address and or port. -.SS "Note on Non-Interactive Use" -.IX Subsection "Note on Non-Interactive Use" -When \fBs_client\fR is run in a non-interactive environment (e.g., a cron job or -a script without a valid \fIstdin\fR), it may close the connection prematurely, -especially with \s-1TLS 1.3.\s0 To prevent this, you can use the \fB\-ign_eof\fR flag, -which keeps \fBs_client\fR running even after reaching \s-1EOF\s0 from \fIstdin\fR. -.PP -For example: -.PP -.Vb 3 -\& openssl s_client \-connect :443 \-tls1_3 -\& \-sess_out /path/to/tls_session_params_file -\& \-ign_eof :25 :25 -\& \-starttls smtp \-brief \-ign_eof -.Ve -.PP -Similarly, for \s-1HTTP/1.1\s0 connections, including a `Connection: close` header -ensures the server closes the connection after responding: -.PP -.Vb 2 -\& printf \*(AqGET / HTTP/1.1\er\enHost: \er\enConnection: close\er\en\er\en\*(Aq -\& | openssl s_client \-connect :443 \-brief -.Ve -.PP -These approaches help manage the connection closure gracefully and prevent -hangs caused by the server waiting for the client to initiate the disconnect. -.SH "BUGS" -.IX Header "BUGS" -Because this program has a lot of options and also because some of the -techniques used are rather old, the C source for this command is rather -hard to read and not a model of how things should be done. -A typical \s-1SSL\s0 client program would be much simpler. -.PP -The \fB\-prexit\fR option is a bit of a hack. We should really report -information whenever a session is renegotiated. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-sess_id\fR\|(1), -\&\fBopenssl\-s_server\fR\|(1), -\&\fBopenssl\-ciphers\fR\|(1), -\&\fBSSL_CONF_cmd\fR\|(3), -\&\fBSSL_CTX_set_max_send_fragment\fR\|(3), -\&\fBSSL_CTX_set_split_send_fragment\fR\|(3), -\&\fBSSL_CTX_set_max_pipelines\fR\|(3), -\&\fBossl_store\-file\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-no_alt_chains\fR option was added in OpenSSL 1.1.0. -The \fB\-name\fR option was added in OpenSSL 1.1.1. -.PP -The \fB\-certform\fR option has become obsolete in OpenSSL 3.0.0 and has no effect. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The -\&\fB\-enable_client_rpk\fR, -\&\fB\-enable_server_rpk\fR, -\&\fB\-no_rx_cert_comp\fR, -\&\fB\-no_tx_cert_comp\fR, -and \fB\-tfo\fR -options were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-s_server.1ossl b/openssl-install/share/man/man1/openssl-s_server.1ossl deleted file mode 100644 index 10435ab0..00000000 --- a/openssl-install/share/man/man1/openssl-s_server.1ossl +++ /dev/null @@ -1,1124 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-S_SERVER 1ossl" -.TH OPENSSL-S_SERVER 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-s_server \- SSL/TLS server program -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBs_server\fR -[\fB\-help\fR] -[\fB\-port\fR \fI+int\fR] -[\fB\-accept\fR \fIval\fR] -[\fB\-unix\fR \fIval\fR] -[\fB\-4\fR] -[\fB\-6\fR] -[\fB\-unlink\fR] -[\fB\-context\fR \fIval\fR] -[\fB\-verify\fR \fIint\fR] -[\fB\-Verify\fR \fIint\fR] -[\fB\-cert\fR \fIinfile\fR] -[\fB\-cert2\fR \fIinfile\fR] -[\fB\-certform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR] -[\fB\-cert_chain\fR \fIinfile\fR] -[\fB\-build_chain\fR] -[\fB\-serverinfo\fR \fIval\fR] -[\fB\-key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-key2\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-pass\fR \fIval\fR] -[\fB\-dcert\fR \fIinfile\fR] -[\fB\-dcertform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR] -[\fB\-dcert_chain\fR \fIinfile\fR] -[\fB\-dkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-dkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-dpass\fR \fIval\fR] -[\fB\-nbio_test\fR] -[\fB\-crlf\fR] -[\fB\-debug\fR] -[\fB\-msg\fR] -[\fB\-msgfile\fR \fIoutfile\fR] -[\fB\-state\fR] -[\fB\-nocert\fR] -[\fB\-quiet\fR] -[\fB\-no_resume_ephemeral\fR] -[\fB\-www\fR] -[\fB\-WWW\fR] -[\fB\-http_server_binmode\fR] -[\fB\-no_ca_names\fR] -[\fB\-ignore_unexpected_eof\fR] -[\fB\-servername\fR] -[\fB\-servername_fatal\fR] -[\fB\-tlsextdebug\fR] -[\fB\-HTTP\fR] -[\fB\-id_prefix\fR \fIval\fR] -[\fB\-keymatexport\fR \fIval\fR] -[\fB\-keymatexportlen\fR \fI+int\fR] -[\fB\-CRL\fR \fIinfile\fR] -[\fB\-CRLform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-crl_download\fR] -[\fB\-chainCAfile\fR \fIinfile\fR] -[\fB\-chainCApath\fR \fIdir\fR] -[\fB\-chainCAstore\fR \fIuri\fR] -[\fB\-verifyCAfile\fR \fIinfile\fR] -[\fB\-verifyCApath\fR \fIdir\fR] -[\fB\-verifyCAstore\fR \fIuri\fR] -[\fB\-no_cache\fR] -[\fB\-ext_cache\fR] -[\fB\-verify_return_error\fR] -[\fB\-verify_quiet\fR] -[\fB\-ign_eof\fR] -[\fB\-no_ign_eof\fR] -[\fB\-no_etm\fR] -[\fB\-no_ems\fR] -[\fB\-status\fR] -[\fB\-status_verbose\fR] -[\fB\-status_timeout\fR \fIint\fR] -[\fB\-proxy\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR] -[\fB\-no_proxy\fR \fIaddresses\fR] -[\fB\-status_url\fR \fIval\fR] -[\fB\-status_file\fR \fIinfile\fR] -[\fB\-ssl_config\fR \fIval\fR] -[\fB\-trace\fR] -[\fB\-security_debug\fR] -[\fB\-security_debug_verbose\fR] -[\fB\-brief\fR] -[\fB\-rev\fR] -[\fB\-async\fR] -[\fB\-max_send_frag\fR \fI+int\fR] -[\fB\-split_send_frag\fR \fI+int\fR] -[\fB\-max_pipelines\fR \fI+int\fR] -[\fB\-naccept\fR \fI+int\fR] -[\fB\-read_buf\fR \fI+int\fR] -[\fB\-bugs\fR] -[\fB\-no_tx_cert_comp\fR] -[\fB\-no_rx_cert_comp\fR] -[\fB\-no_comp\fR] -[\fB\-comp\fR] -[\fB\-no_ticket\fR] -[\fB\-serverpref\fR] -[\fB\-legacy_renegotiation\fR] -[\fB\-no_renegotiation\fR] -[\fB\-no_resumption_on_reneg\fR] -[\fB\-allow_no_dhe_kex\fR] -[\fB\-prefer_no_dhe_kex\fR] -[\fB\-prioritize_chacha\fR] -[\fB\-strict\fR] -[\fB\-sigalgs\fR \fIval\fR] -[\fB\-client_sigalgs\fR \fIval\fR] -[\fB\-groups\fR \fIval\fR] -[\fB\-curves\fR \fIval\fR] -[\fB\-named_curve\fR \fIval\fR] -[\fB\-cipher\fR \fIval\fR] -[\fB\-ciphersuites\fR \fIval\fR] -[\fB\-dhparam\fR \fIinfile\fR] -[\fB\-record_padding\fR \fIval\fR] -[\fB\-debug_broken_protocol\fR] -[\fB\-nbio\fR] -[\fB\-psk_identity\fR \fIval\fR] -[\fB\-psk_hint\fR \fIval\fR] -[\fB\-psk\fR \fIval\fR] -[\fB\-psk_session\fR \fIfile\fR] -[\fB\-srpvfile\fR \fIinfile\fR] -[\fB\-srpuserseed\fR \fIval\fR] -[\fB\-timeout\fR] -[\fB\-mtu\fR \fI+int\fR] -[\fB\-listen\fR] -[\fB\-sctp\fR] -[\fB\-sctp_label_bug\fR] -[\fB\-use_srtp\fR \fIval\fR] -[\fB\-no_dhe\fR] -[\fB\-nextprotoneg\fR \fIval\fR] -[\fB\-alpn\fR \fIval\fR] -[\fB\-ktls\fR] -[\fB\-sendfile\fR] -[\fB\-zerocopy_sendfile\fR] -[\fB\-keylogfile\fR \fIoutfile\fR] -[\fB\-recv_max_early_data\fR \fIint\fR] -[\fB\-max_early_data\fR \fIint\fR] -[\fB\-early_data\fR] -[\fB\-stateless\fR] -[\fB\-anti_replay\fR] -[\fB\-no_anti_replay\fR] -[\fB\-num_tickets\fR] -[\fB\-tfo\fR] -[\fB\-cert_comp\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-no_ssl3\fR] -[\fB\-no_tls1\fR] -[\fB\-no_tls1_1\fR] -[\fB\-no_tls1_2\fR] -[\fB\-no_tls1_3\fR] -[\fB\-ssl3\fR] -[\fB\-tls1\fR] -[\fB\-tls1_1\fR] -[\fB\-tls1_2\fR] -[\fB\-tls1_3\fR] -[\fB\-dtls\fR] -[\fB\-dtls1\fR] -[\fB\-dtls1_2\fR] -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -[\fB\-bugs\fR] -[\fB\-no_comp\fR] -[\fB\-comp\fR] -[\fB\-no_ticket\fR] -[\fB\-serverpref\fR] -[\fB\-client_renegotiation\fR] -[\fB\-legacy_renegotiation\fR] -[\fB\-no_renegotiation\fR] -[\fB\-no_resumption_on_reneg\fR] -[\fB\-legacy_server_connect\fR] -[\fB\-no_legacy_server_connect\fR] -[\fB\-no_etm\fR] -[\fB\-allow_no_dhe_kex\fR] -[\fB\-prefer_no_dhe_kex\fR] -[\fB\-prioritize_chacha\fR] -[\fB\-strict\fR] -[\fB\-sigalgs\fR \fIalgs\fR] -[\fB\-client_sigalgs\fR \fIalgs\fR] -[\fB\-groups\fR \fIgroups\fR] -[\fB\-curves\fR \fIcurves\fR] -[\fB\-named_curve\fR \fIcurve\fR] -[\fB\-cipher\fR \fIciphers\fR] -[\fB\-ciphersuites\fR \fI1.3ciphers\fR] -[\fB\-min_protocol\fR \fIminprot\fR] -[\fB\-max_protocol\fR \fImaxprot\fR] -[\fB\-record_padding\fR \fIpadding\fR] -[\fB\-debug_broken_protocol\fR] -[\fB\-no_middlebox\fR] -[\fB\-xkey\fR \fIinfile\fR] -[\fB\-xcert\fR \fIfile\fR] -[\fB\-xchain\fR \fIfile\fR] -[\fB\-xchain_build\fR \fIfile\fR] -[\fB\-xcertform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR]> -[\fB\-xkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR]> -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-enable_server_rpk\fR] -[\fB\-enable_client_rpk\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command implements a generic \s-1SSL/TLS\s0 server which -listens for connections on a given port using \s-1SSL/TLS.\s0 -.SH "OPTIONS" -.IX Header "OPTIONS" -In addition to the options below, this command also supports -the common and server only options documented -\&\*(L"Supported Command Line Commands\*(R" in \fBSSL_CONF_cmd\fR\|(3) -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-port\fR \fI+int\fR" 4 -.IX Item "-port +int" -The \s-1TCP\s0 port to listen on for connections. If not specified 4433 is used. -.IP "\fB\-accept\fR \fIval\fR" 4 -.IX Item "-accept val" -The optional \s-1TCP\s0 host and port to listen on for connections. If not specified, *:4433 is used. -.IP "\fB\-unix\fR \fIval\fR" 4 -.IX Item "-unix val" -Unix domain socket to accept on. -.IP "\fB\-4\fR" 4 -.IX Item "-4" -Use IPv4 only. -.IP "\fB\-6\fR" 4 -.IX Item "-6" -Use IPv6 only. -.IP "\fB\-unlink\fR" 4 -.IX Item "-unlink" -For \-unix, unlink any existing socket first. -.IP "\fB\-context\fR \fIval\fR" 4 -.IX Item "-context val" -Sets the \s-1SSL\s0 context id. It can be given any string value. If this option -is not present a default value will be used. -.IP "\fB\-verify\fR \fIint\fR, \fB\-Verify\fR \fIint\fR" 4 -.IX Item "-verify int, -Verify int" -The verify depth to use. This specifies the maximum length of the -client certificate chain and makes the server request a certificate from -the client. With the \fB\-verify\fR option a certificate is requested but the -client does not have to send one, with the \fB\-Verify\fR option the client -must supply a certificate or an error occurs. -.Sp -If the cipher suite cannot request a client certificate (for example an -anonymous cipher suite or \s-1PSK\s0) this option has no effect. -.Sp -By default, validation of any supplied client certificate and its chain -is done w.r.t. the (D)TLS Client (\f(CW\*(C`sslclient\*(C'\fR) purpose. -For details see \*(L"Certificate Extensions\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.IP "\fB\-cert\fR \fIinfile\fR" 4 -.IX Item "-cert infile" -The certificate to use, most servers cipher suites require the use of a -certificate and some require a certificate with a certain public key type: -for example the \s-1DSS\s0 cipher suites require a certificate containing a \s-1DSS\s0 -(\s-1DSA\s0) key. If not specified then the filename \fIserver.pem\fR will be used. -.IP "\fB\-cert2\fR \fIinfile\fR" 4 -.IX Item "-cert2 infile" -The certificate file to use for servername; default is \f(CW\*(C`server2.pem\*(C'\fR. -.IP "\fB\-certform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR" 4 -.IX Item "-certform DER|PEM|P12" -The server certificate file format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-cert_chain\fR" 4 -.IX Item "-cert_chain" -A file or \s-1URI\s0 of untrusted certificates to use when attempting to build the -certificate chain related to the certificate specified via the \fB\-cert\fR option. -These untrusted certificates are sent to clients and used for generating -certificate status (aka \s-1OCSP\s0 stapling) requests. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-build_chain\fR" 4 -.IX Item "-build_chain" -Specify whether the application should build the server certificate chain to be -provided to the client. -.IP "\fB\-serverinfo\fR \fIval\fR" 4 -.IX Item "-serverinfo val" -A file containing one or more blocks of \s-1PEM\s0 data. Each \s-1PEM\s0 block -must encode a \s-1TLS\s0 ServerHello extension (2 bytes type, 2 bytes length, -followed by \*(L"length\*(R" bytes of extension data). If the client sends -an empty \s-1TLS\s0 ClientHello extension matching the type, the corresponding -ServerHello extension will be returned. -.IP "\fB\-key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-key filename|uri" -The private key to use. If not specified then the certificate file will -be used. -.IP "\fB\-key2\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-key2 filename|uri" -The private Key file to use for servername if not given via \fB\-cert2\fR. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The key format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-pass\fR \fIval\fR" 4 -.IX Item "-pass val" -The private key and certificate file password source. -For more information about the format of \fIval\fR, -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-dcert\fR \fIinfile\fR, \fB\-dkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-dcert infile, -dkey filename|uri" -Specify an additional certificate and private key, these behave in the -same manner as the \fB\-cert\fR and \fB\-key\fR options except there is no default -if they are not specified (no additional certificate and key is used). As -noted above some cipher suites require a certificate containing a key of -a certain type. Some cipher suites need a certificate carrying an \s-1RSA\s0 key -and some a \s-1DSS\s0 (\s-1DSA\s0) key. By using \s-1RSA\s0 and \s-1DSS\s0 certificates and keys -a server can support clients which only support \s-1RSA\s0 or \s-1DSS\s0 cipher suites -by using an appropriate certificate. -.IP "\fB\-dcert_chain\fR" 4 -.IX Item "-dcert_chain" -A file or \s-1URI\s0 of untrusted certificates to use when attempting to build the -server certificate chain when a certificate specified via the \fB\-dcert\fR option -is in use. -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-dcertform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR" 4 -.IX Item "-dcertform DER|PEM|P12" -The format of the additional certificate file; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-dkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-dkeyform DER|PEM|P12|ENGINE" -The format of the additional private key; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-dpass\fR \fIval\fR" 4 -.IX Item "-dpass val" -The passphrase for the additional private key and certificate. -For more information about the format of \fIval\fR, -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-nbio_test\fR" 4 -.IX Item "-nbio_test" -Tests non blocking I/O. -.IP "\fB\-crlf\fR" 4 -.IX Item "-crlf" -This option translated a line feed from the terminal into \s-1CR+LF.\s0 -.IP "\fB\-debug\fR" 4 -.IX Item "-debug" -Print extensive debugging information including a hex dump of all traffic. -.IP "\fB\-security_debug\fR" 4 -.IX Item "-security_debug" -Print output from \s-1SSL/TLS\s0 security framework. -.IP "\fB\-security_debug_verbose\fR" 4 -.IX Item "-security_debug_verbose" -Print more output from \s-1SSL/TLS\s0 security framework -.IP "\fB\-msg\fR" 4 -.IX Item "-msg" -Show all protocol messages with hex dump. -.IP "\fB\-msgfile\fR \fIoutfile\fR" 4 -.IX Item "-msgfile outfile" -File to send output of \fB\-msg\fR or \fB\-trace\fR to, default standard output. -.IP "\fB\-state\fR" 4 -.IX Item "-state" -Prints the \s-1SSL\s0 session states. -.IP "\fB\-CRL\fR \fIinfile\fR" 4 -.IX Item "-CRL infile" -The \s-1CRL\s0 file to use. -.IP "\fB\-CRLform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-CRLform DER|PEM" -The \s-1CRL\s0 file format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-crl_download\fR" 4 -.IX Item "-crl_download" -Download CRLs from distribution points given in \s-1CDP\s0 extensions of certificates -.IP "\fB\-verifyCAfile\fR \fIfilename\fR" 4 -.IX Item "-verifyCAfile filename" -A file in \s-1PEM\s0 format \s-1CA\s0 containing trusted certificates to use -for verifying client certificates. -.IP "\fB\-verifyCApath\fR \fIdir\fR" 4 -.IX Item "-verifyCApath dir" -A directory containing trusted certificates to use -for verifying client certificates. -This directory must be in \*(L"hash format\*(R", -see \fBopenssl\-verify\fR\|(1) for more information. -.IP "\fB\-verifyCAstore\fR \fIuri\fR" 4 -.IX Item "-verifyCAstore uri" -The \s-1URI\s0 of a store containing trusted certificates to use -for verifying client certificates. -.IP "\fB\-chainCAfile\fR \fIfile\fR" 4 -.IX Item "-chainCAfile file" -A file in \s-1PEM\s0 format containing trusted certificates to use -when attempting to build the server certificate chain. -.IP "\fB\-chainCApath\fR \fIdir\fR" 4 -.IX Item "-chainCApath dir" -A directory containing trusted certificates to use -for building the server certificate chain provided to the client. -This directory must be in \*(L"hash format\*(R", -see \fBopenssl\-verify\fR\|(1) for more information. -.IP "\fB\-chainCAstore\fR \fIuri\fR" 4 -.IX Item "-chainCAstore uri" -The \s-1URI\s0 of a store containing trusted certificates to use -for building the server certificate chain provided to the client. -The \s-1URI\s0 may indicate a single certificate, as well as a collection of them. -With URIs in the \f(CW\*(C`file:\*(C'\fR scheme, this acts as \fB\-chainCAfile\fR or -\&\fB\-chainCApath\fR, depending on if the \s-1URI\s0 indicates a directory or a -single file. -See \fBossl_store\-file\fR\|(7) for more information on the \f(CW\*(C`file:\*(C'\fR scheme. -.IP "\fB\-nocert\fR" 4 -.IX Item "-nocert" -If this option is set then no certificate is used. This restricts the -cipher suites available to the anonymous ones (currently just anonymous -\&\s-1DH\s0). -.IP "\fB\-quiet\fR" 4 -.IX Item "-quiet" -Inhibit printing of session and certificate information. -.IP "\fB\-no_resume_ephemeral\fR" 4 -.IX Item "-no_resume_ephemeral" -Disable caching and tickets if ephemeral (\s-1EC\s0)DH is used. -.IP "\fB\-tlsextdebug\fR" 4 -.IX Item "-tlsextdebug" -Print a hex dump of any \s-1TLS\s0 extensions received from the server. -.IP "\fB\-www\fR" 4 -.IX Item "-www" -Sends a status message back to the client when it connects. This includes -information about the ciphers used and various session parameters. -The output is in \s-1HTML\s0 format so this option can be used with a web browser. -The special \s-1URL\s0 \f(CW\*(C`/renegcert\*(C'\fR turns on client cert validation, and \f(CW\*(C`/reneg\*(C'\fR -tells the server to request renegotiation. -The \fB\-early_data\fR option cannot be used with this option. -.IP "\fB\-WWW\fR, \fB\-HTTP\fR" 4 -.IX Item "-WWW, -HTTP" -Emulates a simple web server. Pages will be resolved relative to the -current directory, for example if the \s-1URL\s0 \f(CW\*(C`https://myhost/page.html\*(C'\fR is -requested the file \fI./page.html\fR will be sent. -If the \fB\-HTTP\fR flag is used, the files are sent directly, and should contain -any \s-1HTTP\s0 response headers (including status response line). -If the \fB\-WWW\fR option is used, -the response headers are generated by the server, and the file extension is -examined to determine the \fBContent-Type\fR header. -Extensions of \f(CW\*(C`html\*(C'\fR, \f(CW\*(C`htm\*(C'\fR, and \f(CW\*(C`php\*(C'\fR are \f(CW\*(C`text/html\*(C'\fR and all others are -\&\f(CW\*(C`text/plain\*(C'\fR. -In addition, the special \s-1URL\s0 \f(CW\*(C`/stats\*(C'\fR will return status -information like the \fB\-www\fR option. -Neither of these options can be used in conjunction with \fB\-early_data\fR. -.IP "\fB\-http_server_binmode\fR" 4 -.IX Item "-http_server_binmode" -When acting as web-server (using option \fB\-WWW\fR or \fB\-HTTP\fR) open files requested -by the client in binary mode. -.IP "\fB\-no_ca_names\fR" 4 -.IX Item "-no_ca_names" -Disable \s-1TLS\s0 Extension \s-1CA\s0 Names. You may want to disable it for security reasons -or for compatibility with some Windows \s-1TLS\s0 implementations crashing when this -extension is larger than 1024 bytes. -.IP "\fB\-ignore_unexpected_eof\fR" 4 -.IX Item "-ignore_unexpected_eof" -Some \s-1TLS\s0 implementations do not send the mandatory close_notify alert on -shutdown. If the application tries to wait for the close_notify alert but the -peer closes the connection without sending it, an error is generated. When this -option is enabled the peer does not need to send the close_notify alert and a -closed connection will be treated as if the close_notify alert was received. -For more information on shutting down a connection, see \fBSSL_shutdown\fR\|(3). -.IP "\fB\-servername\fR" 4 -.IX Item "-servername" -Servername for HostName \s-1TLS\s0 extension. -.IP "\fB\-servername_fatal\fR" 4 -.IX Item "-servername_fatal" -On servername mismatch send fatal alert (default: warning alert). -.IP "\fB\-id_prefix\fR \fIval\fR" 4 -.IX Item "-id_prefix val" -Generate \s-1SSL/TLS\s0 session IDs prefixed by \fIval\fR. This is mostly useful -for testing any \s-1SSL/TLS\s0 code (e.g. proxies) that wish to deal with multiple -servers, when each of which might be generating a unique range of session -IDs (e.g. with a certain prefix). -.IP "\fB\-keymatexport\fR" 4 -.IX Item "-keymatexport" -Export keying material using label. -.IP "\fB\-keymatexportlen\fR" 4 -.IX Item "-keymatexportlen" -Export the given number of bytes of keying material; default 20. -.IP "\fB\-no_cache\fR" 4 -.IX Item "-no_cache" -Disable session cache. -.IP "\fB\-ext_cache\fR." 4 -.IX Item "-ext_cache." -Disable internal cache, set up and use external cache. -.IP "\fB\-verify_return_error\fR" 4 -.IX Item "-verify_return_error" -Verification errors normally just print a message but allow the -connection to continue, for debugging purposes. -If this option is used, then verification errors close the connection. -.IP "\fB\-verify_quiet\fR" 4 -.IX Item "-verify_quiet" -No verify output except verify errors. -.IP "\fB\-ign_eof\fR" 4 -.IX Item "-ign_eof" -Ignore input \s-1EOF\s0 (default: when \fB\-quiet\fR). -.IP "\fB\-no_ign_eof\fR" 4 -.IX Item "-no_ign_eof" -Do not ignore input \s-1EOF.\s0 -.IP "\fB\-no_etm\fR" 4 -.IX Item "-no_etm" -Disable Encrypt-then-MAC negotiation. -.IP "\fB\-no_ems\fR" 4 -.IX Item "-no_ems" -Disable Extended master secret negotiation. -.IP "\fB\-status\fR" 4 -.IX Item "-status" -Enables certificate status request support (aka \s-1OCSP\s0 stapling). -.IP "\fB\-status_verbose\fR" 4 -.IX Item "-status_verbose" -Enables certificate status request support (aka \s-1OCSP\s0 stapling) and gives -a verbose printout of the \s-1OCSP\s0 response. -Use the \fB\-cert_chain\fR option to specify the certificate of the server's -certificate signer that is required for certificate status requests. -.IP "\fB\-status_timeout\fR \fIint\fR" 4 -.IX Item "-status_timeout int" -Sets the timeout for \s-1OCSP\s0 response to \fIint\fR seconds. -.IP "\fB\-proxy\fR \fI[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\fR" 4 -.IX Item "-proxy [http[s]://][userinfo@]host[:port][/path][?query][#fragment]" -The \s-1HTTP\s0(S) proxy server to use for reaching the \s-1OCSP\s0 server unless \fB\-no_proxy\fR -applies, see below. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -The proxy port defaults to 80 or 443 if the scheme is \f(CW\*(C`https\*(C'\fR; apart from that -the optional \f(CW\*(C`http://\*(C'\fR or \f(CW\*(C`https://\*(C'\fR prefix is ignored, -as well as any userinfo, path, query, and fragment components. -Defaults to the environment variable \f(CW\*(C`http_proxy\*(C'\fR if set, else \f(CW\*(C`HTTP_PROXY\*(C'\fR -in case no \s-1TLS\s0 is used, otherwise \f(CW\*(C`https_proxy\*(C'\fR if set, else \f(CW\*(C`HTTPS_PROXY\*(C'\fR. -.IP "\fB\-no_proxy\fR \fIaddresses\fR" 4 -.IX Item "-no_proxy addresses" -List of \s-1IP\s0 addresses and/or \s-1DNS\s0 names of servers -not to use an \s-1HTTP\s0(S) proxy for, separated by commas and/or whitespace -(where in the latter case the whole argument must be enclosed in \*(L"...\*(R"). -Default is from the environment variable \f(CW\*(C`no_proxy\*(C'\fR if set, else \f(CW\*(C`NO_PROXY\*(C'\fR. -.IP "\fB\-status_url\fR \fIval\fR" 4 -.IX Item "-status_url val" -Sets a fallback responder \s-1URL\s0 to use if no responder \s-1URL\s0 is present in the -server certificate. Without this option an error is returned if the server -certificate does not contain a responder address. -The optional userinfo and fragment \s-1URL\s0 components are ignored. -Any given query component is handled as part of the path component. -.IP "\fB\-status_file\fR \fIinfile\fR" 4 -.IX Item "-status_file infile" -Overrides any \s-1OCSP\s0 responder URLs from the certificate and always provides the -\&\s-1OCSP\s0 Response stored in the file. The file must be in \s-1DER\s0 format. -.IP "\fB\-ssl_config\fR \fIval\fR" 4 -.IX Item "-ssl_config val" -Configure \s-1SSL_CTX\s0 using the given configuration value. -.IP "\fB\-trace\fR" 4 -.IX Item "-trace" -Show verbose trace output of protocol messages. -.IP "\fB\-brief\fR" 4 -.IX Item "-brief" -Provide a brief summary of connection parameters instead of the normal verbose -output. -.IP "\fB\-rev\fR" 4 -.IX Item "-rev" -Simple echo server that sends back received text reversed. Also sets \fB\-brief\fR. -Cannot be used in conjunction with \fB\-early_data\fR. -.IP "\fB\-async\fR" 4 -.IX Item "-async" -Switch on asynchronous mode. Cryptographic operations will be performed -asynchronously. This will only have an effect if an asynchronous capable engine -is also used via the \fB\-engine\fR option. For test purposes the dummy async engine -(dasync) can be used (if available). -.IP "\fB\-max_send_frag\fR \fI+int\fR" 4 -.IX Item "-max_send_frag +int" -The maximum size of data fragment to send. -See \fBSSL_CTX_set_max_send_fragment\fR\|(3) for further information. -.IP "\fB\-split_send_frag\fR \fI+int\fR" 4 -.IX Item "-split_send_frag +int" -The size used to split data for encrypt pipelines. If more data is written in -one go than this value then it will be split into multiple pipelines, up to the -maximum number of pipelines defined by max_pipelines. This only has an effect if -a suitable cipher suite has been negotiated, an engine that supports pipelining -has been loaded, and max_pipelines is greater than 1. See -\&\fBSSL_CTX_set_split_send_fragment\fR\|(3) for further information. -.IP "\fB\-max_pipelines\fR \fI+int\fR" 4 -.IX Item "-max_pipelines +int" -The maximum number of encrypt/decrypt pipelines to be used. This will only have -an effect if an engine has been loaded that supports pipelining (e.g. the dasync -engine) and a suitable cipher suite has been negotiated. The default value is 1. -See \fBSSL_CTX_set_max_pipelines\fR\|(3) for further information. -.IP "\fB\-naccept\fR \fI+int\fR" 4 -.IX Item "-naccept +int" -The server will exit after receiving the specified number of connections, -default unlimited. -.IP "\fB\-read_buf\fR \fI+int\fR" 4 -.IX Item "-read_buf +int" -The default read buffer size to be used for connections. This will only have an -effect if the buffer size is larger than the size that would otherwise be used -and pipelining is in use (see \fBSSL_CTX_set_default_read_buffer_len\fR\|(3) for -further information). -.IP "\fB\-bugs\fR" 4 -.IX Item "-bugs" -There are several known bugs in \s-1SSL\s0 and \s-1TLS\s0 implementations. Adding this -option enables various workarounds. -.IP "\fB\-no_tx_cert_comp\fR" 4 -.IX Item "-no_tx_cert_comp" -Disables support for sending TLSv1.3 compressed certificates. -.IP "\fB\-no_rx_cert_comp\fR" 4 -.IX Item "-no_rx_cert_comp" -Disables support for receiving TLSv1.3 compressed certificates. -.IP "\fB\-no_comp\fR" 4 -.IX Item "-no_comp" -Disable negotiation of \s-1TLS\s0 compression. -\&\s-1TLS\s0 compression is not recommended and is off by default as of -OpenSSL 1.1.0. -.IP "\fB\-comp\fR" 4 -.IX Item "-comp" -Enables support for \s-1SSL/TLS\s0 compression. -This option was introduced in OpenSSL 1.1.0. -\&\s-1TLS\s0 compression is not recommended and is off by default as of -OpenSSL 1.1.0. \s-1TLS\s0 compression can only be used in security level 1 or -lower. From OpenSSL 3.2.0 and above the default security level is 2, so this -option will have no effect without also changing the security level. Use the -\&\fB\-cipher\fR option to change the security level. See \fBopenssl\-ciphers\fR\|(1) for -more information. -.IP "\fB\-no_ticket\fR" 4 -.IX Item "-no_ticket" -Disable RFC4507bis session ticket support. This option has no effect if TLSv1.3 -is negotiated. See \fB\-num_tickets\fR. -.IP "\fB\-num_tickets\fR" 4 -.IX Item "-num_tickets" -Control the number of tickets that will be sent to the client after a full -handshake in TLSv1.3. The default number of tickets is 2. This option does not -affect the number of tickets sent after a resumption handshake. -.IP "\fB\-serverpref\fR" 4 -.IX Item "-serverpref" -Use the server's cipher preferences, rather than the client's preferences. -.IP "\fB\-prioritize_chacha\fR" 4 -.IX Item "-prioritize_chacha" -Prioritize ChaCha ciphers when preferred by clients. Requires \fB\-serverpref\fR. -.IP "\fB\-no_resumption_on_reneg\fR" 4 -.IX Item "-no_resumption_on_reneg" -Set the \fB\s-1SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION\s0\fR option. -.IP "\fB\-client_sigalgs\fR \fIval\fR" 4 -.IX Item "-client_sigalgs val" -Signature algorithms to support for client certificate authentication -(colon-separated list). -.IP "\fB\-named_curve\fR \fIval\fR" 4 -.IX Item "-named_curve val" -Specifies the elliptic curve to use. \s-1NOTE:\s0 this is single curve, not a list. -.Sp -The list of all supported groups includes named \s-1EC\s0 parameters as well as X25519 -and X448 or \s-1FFDHE\s0 groups, and may also include groups implemented in 3rd\-party -providers. For a list of named \s-1EC\s0 parameters, use: -.Sp -.Vb 1 -\& $ openssl ecparam \-list_curves -.Ve -.IP "\fB\-cipher\fR \fIval\fR" 4 -.IX Item "-cipher val" -This allows the list of TLSv1.2 and below ciphersuites used by the server to be -modified. This list is combined with any TLSv1.3 ciphersuites that have been -configured. When the client sends a list of supported ciphers the first client -cipher also included in the server list is used. Because the client specifies -the preference order, the order of the server cipherlist is irrelevant. See -\&\fBopenssl\-ciphers\fR\|(1) for more information. -.IP "\fB\-ciphersuites\fR \fIval\fR" 4 -.IX Item "-ciphersuites val" -This allows the list of TLSv1.3 ciphersuites used by the server to be modified. -This list is combined with any TLSv1.2 and below ciphersuites that have been -configured. When the client sends a list of supported ciphers the first client -cipher also included in the server list is used. Because the client specifies -the preference order, the order of the server cipherlist is irrelevant. See -\&\fBopenssl\-ciphers\fR\|(1) command for more information. The format for this list is -a simple colon (\*(L":\*(R") separated list of TLSv1.3 ciphersuite names. -.IP "\fB\-dhparam\fR \fIinfile\fR" 4 -.IX Item "-dhparam infile" -The \s-1DH\s0 parameter file to use. The ephemeral \s-1DH\s0 cipher suites generate keys -using a set of \s-1DH\s0 parameters. If not specified then an attempt is made to -load the parameters from the server certificate file. -If this fails then a static set of parameters hard coded into this command -will be used. -.IP "\fB\-nbio\fR" 4 -.IX Item "-nbio" -Turns on non blocking I/O. -.IP "\fB\-timeout\fR" 4 -.IX Item "-timeout" -Enable timeouts. -.IP "\fB\-mtu\fR" 4 -.IX Item "-mtu" -Set link-layer \s-1MTU.\s0 -.IP "\fB\-psk_identity\fR \fIval\fR" 4 -.IX Item "-psk_identity val" -Expect the client to send \s-1PSK\s0 identity \fIval\fR when using a \s-1PSK\s0 -cipher suite, and warn if they do not. By default, the expected \s-1PSK\s0 -identity is the string \*(L"Client_identity\*(R". -.IP "\fB\-psk_hint\fR \fIval\fR" 4 -.IX Item "-psk_hint val" -Use the \s-1PSK\s0 identity hint \fIval\fR when using a \s-1PSK\s0 cipher suite. -.IP "\fB\-psk\fR \fIval\fR" 4 -.IX Item "-psk val" -Use the \s-1PSK\s0 key \fIval\fR when using a \s-1PSK\s0 cipher suite. The key is -given as a hexadecimal number without leading 0x, for example \-psk -1a2b3c4d. -This option must be provided in order to use a \s-1PSK\s0 cipher. -.IP "\fB\-psk_session\fR \fIfile\fR" 4 -.IX Item "-psk_session file" -Use the pem encoded \s-1SSL_SESSION\s0 data stored in \fIfile\fR as the basis of a \s-1PSK.\s0 -Note that this will only work if TLSv1.3 is negotiated. -.IP "\fB\-srpvfile\fR" 4 -.IX Item "-srpvfile" -The verifier file for \s-1SRP.\s0 -This option is deprecated. -.IP "\fB\-srpuserseed\fR" 4 -.IX Item "-srpuserseed" -A seed string for a default user salt. -This option is deprecated. -.IP "\fB\-listen\fR" 4 -.IX Item "-listen" -This option can only be used in conjunction with one of the \s-1DTLS\s0 options above. -With this option, this command will listen on a \s-1UDP\s0 port for incoming -connections. -Any ClientHellos that arrive will be checked to see if they have a cookie in -them or not. -Any without a cookie will be responded to with a HelloVerifyRequest. -If a ClientHello with a cookie is received then this command will -connect to that peer and complete the handshake. -.IP "\fB\-sctp\fR" 4 -.IX Item "-sctp" -Use \s-1SCTP\s0 for the transport protocol instead of \s-1UDP\s0 in \s-1DTLS.\s0 Must be used in -conjunction with \fB\-dtls\fR, \fB\-dtls1\fR or \fB\-dtls1_2\fR. This option is only -available where OpenSSL has support for \s-1SCTP\s0 enabled. -.IP "\fB\-sctp_label_bug\fR" 4 -.IX Item "-sctp_label_bug" -Use the incorrect behaviour of older OpenSSL implementations when computing -endpoint-pair shared secrets for \s-1DTLS/SCTP.\s0 This allows communication with -older broken implementations but breaks interoperability with correct -implementations. Must be used in conjunction with \fB\-sctp\fR. This option is only -available where OpenSSL has support for \s-1SCTP\s0 enabled. -.IP "\fB\-use_srtp\fR" 4 -.IX Item "-use_srtp" -Offer \s-1SRTP\s0 key management with a colon-separated profile list. -.IP "\fB\-no_dhe\fR" 4 -.IX Item "-no_dhe" -If this option is set then no \s-1DH\s0 parameters will be loaded effectively -disabling the ephemeral \s-1DH\s0 cipher suites. -.IP "\fB\-alpn\fR \fIval\fR, \fB\-nextprotoneg\fR \fIval\fR" 4 -.IX Item "-alpn val, -nextprotoneg val" -These flags enable the Application-Layer Protocol Negotiation -or Next Protocol Negotiation (\s-1NPN\s0) extension, respectively. \s-1ALPN\s0 is the -\&\s-1IETF\s0 standard and replaces \s-1NPN.\s0 -The \fIval\fR list is a comma-separated list of supported protocol -names. The list should contain the most desirable protocols first. -Protocol names are printable \s-1ASCII\s0 strings, for example \*(L"http/1.1\*(R" or -\&\*(L"spdy/3\*(R". -The flag \fB\-nextprotoneg\fR cannot be specified if \fB\-tls1_3\fR is used. -.IP "\fB\-ktls\fR" 4 -.IX Item "-ktls" -Enable Kernel \s-1TLS\s0 for sending and receiving. -This option was introduced in OpenSSL 3.2.0. -Kernel \s-1TLS\s0 is off by default as of OpenSSL 3.2.0. -.IP "\fB\-sendfile\fR" 4 -.IX Item "-sendfile" -If this option is set and \s-1KTLS\s0 is enabled, \fBSSL_sendfile()\fR will be used -instead of \fBBIO_write()\fR to send the \s-1HTTP\s0 response requested by a client. -This option is only valid when \fB\-ktls\fR along with \fB\-WWW\fR or \fB\-HTTP\fR -are specified. -.IP "\fB\-zerocopy_sendfile\fR" 4 -.IX Item "-zerocopy_sendfile" -If this option is set, \fBSSL_sendfile()\fR will use the zerocopy \s-1TX\s0 mode, which gives -a performance boost when used with \s-1KTLS\s0 hardware offload. Note that invalid -\&\s-1TLS\s0 records might be transmitted if the file is changed while being sent. -This option depends on \fB\-sendfile\fR; when used alone, \fB\-sendfile\fR is implied, -and a warning is shown. Note that \s-1KTLS\s0 sendfile on FreeBSD always runs in the -zerocopy mode. -.IP "\fB\-keylogfile\fR \fIoutfile\fR" 4 -.IX Item "-keylogfile outfile" -Appends \s-1TLS\s0 secrets to the specified keylog file such that external programs -(like Wireshark) can decrypt \s-1TLS\s0 connections. -.IP "\fB\-max_early_data\fR \fIint\fR" 4 -.IX Item "-max_early_data int" -Change the default maximum early data bytes that are specified for new sessions -and any incoming early data (when used in conjunction with the \fB\-early_data\fR -flag). The default value is approximately 16k. The argument must be an integer -greater than or equal to 0. -.IP "\fB\-recv_max_early_data\fR \fIint\fR" 4 -.IX Item "-recv_max_early_data int" -Specify the hard limit on the maximum number of early data bytes that will -be accepted. -.IP "\fB\-early_data\fR" 4 -.IX Item "-early_data" -Accept early data where possible. Cannot be used in conjunction with \fB\-www\fR, -\&\fB\-WWW\fR, \fB\-HTTP\fR or \fB\-rev\fR. -.IP "\fB\-stateless\fR" 4 -.IX Item "-stateless" -Require TLSv1.3 cookies. -.IP "\fB\-anti_replay\fR, \fB\-no_anti_replay\fR" 4 -.IX Item "-anti_replay, -no_anti_replay" -Switches replay protection on or off, respectively. Replay protection is on by -default unless overridden by a configuration file. When it is on, OpenSSL will -automatically detect if a session ticket has been used more than once, TLSv1.3 -has been negotiated, and early data is enabled on the server. A full handshake -is forced if a session ticket is used a second or subsequent time. Any early -data that was sent will be rejected. -.IP "\fB\-tfo\fR" 4 -.IX Item "-tfo" -Enable acceptance of \s-1TCP\s0 Fast Open (\s-1RFC7413\s0) connections. -.IP "\fB\-cert_comp\fR" 4 -.IX Item "-cert_comp" -Pre-compresses certificates (\s-1RFC8879\s0) that will be sent during the handshake. -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -This specifies how the subject or issuer names are displayed. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-no_ssl3\fR, \fB\-no_tls1\fR, \fB\-no_tls1_1\fR, \fB\-no_tls1_2\fR, \fB\-no_tls1_3\fR, \fB\-ssl3\fR, \fB\-tls1\fR, \fB\-tls1_1\fR, \fB\-tls1_2\fR, \fB\-tls1_3\fR" 4 -.IX Item "-no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3, -ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3" -See \*(L"\s-1TLS\s0 Version Options\*(R" in \fBopenssl\fR\|(1). -.IP "\fB\-dtls\fR, \fB\-dtls1\fR, \fB\-dtls1_2\fR" 4 -.IX Item "-dtls, -dtls1, -dtls1_2" -These specify the use of \s-1DTLS\s0 instead of \s-1TLS.\s0 -See \*(L"\s-1TLS\s0 Version Options\*(R" in \fBopenssl\fR\|(1). -.IP "\fB\-bugs\fR, \fB\-comp\fR, \fB\-no_comp\fR, \fB\-no_ticket\fR, \fB\-serverpref\fR, \fB\-client_renegotiation\fR, \fB\-legacy_renegotiation\fR, \fB\-no_renegotiation\fR, \fB\-no_resumption_on_reneg\fR, \fB\-legacy_server_connect\fR, \fB\-no_legacy_server_connect\fR, \fB\-no_etm\fR \fB\-allow_no_dhe_kex\fR, \fB\-prefer_no_dhe_kex\fR, \fB\-prioritize_chacha\fR, \fB\-strict\fR, \fB\-sigalgs\fR \fIalgs\fR, \fB\-client_sigalgs\fR \fIalgs\fR, \fB\-groups\fR \fIgroups\fR, \fB\-curves\fR \fIcurves\fR, \fB\-named_curve\fR \fIcurve\fR, \fB\-cipher\fR \fIciphers\fR, \fB\-ciphersuites\fR \fI1.3ciphers\fR, \fB\-min_protocol\fR \fIminprot\fR, \fB\-max_protocol\fR \fImaxprot\fR, \fB\-record_padding\fR \fIpadding\fR, \fB\-debug_broken_protocol\fR, \fB\-no_middlebox\fR" 4 -.IX Item "-bugs, -comp, -no_comp, -no_ticket, -serverpref, -client_renegotiation, -legacy_renegotiation, -no_renegotiation, -no_resumption_on_reneg, -legacy_server_connect, -no_legacy_server_connect, -no_etm -allow_no_dhe_kex, -prefer_no_dhe_kex, -prioritize_chacha, -strict, -sigalgs algs, -client_sigalgs algs, -groups groups, -curves curves, -named_curve curve, -cipher ciphers, -ciphersuites 1.3ciphers, -min_protocol minprot, -max_protocol maxprot, -record_padding padding, -debug_broken_protocol, -no_middlebox" -See \*(L"\s-1SUPPORTED COMMAND LINE COMMANDS\*(R"\s0 in \fBSSL_CONF_cmd\fR\|(3) for details. -.IP "\fB\-xkey\fR \fIinfile\fR, \fB\-xcert\fR \fIfile\fR, \fB\-xchain\fR \fIfile\fR, \fB\-xchain_build\fR \fIfile\fR, \fB\-xcertform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR, \fB\-xkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-xkey infile, -xcert file, -xchain file, -xchain_build file, -xcertform DER|PEM, -xkeyform DER|PEM" -Set extended certificate verification options. -See \*(L"Extended Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.Sp -If the server requests a client certificate, then -verification errors are displayed, for debugging, but the command will -proceed unless the \fB\-verify_return_error\fR option is used. -.IP "\fB\-enable_server_rpk\fR" 4 -.IX Item "-enable_server_rpk" -Enable support for sending raw public keys (\s-1RFC7250\s0) to the client. -A raw public key will be sent by the server, if solicited by the client, -provided a suitable key and public certificate pair is configured. -Clients that don't support raw public keys or prefer to use X.509 -certificates can still elect to receive X.509 certificates as usual. -.Sp -Raw public keys are extracted from the configured certificate/private key. -.IP "\fB\-enable_client_rpk\fR" 4 -.IX Item "-enable_client_rpk" -Enable support for receiving raw public keys (\s-1RFC7250\s0) from the client. -Use of X.509 certificates by the client becomes optional, and clients that -support raw public keys may elect to use them. -Clients that don't support raw public keys or prefer to use X.509 -certificates can still elect to send X.509 certificates as usual. -.Sp -Raw public keys are extracted from the configured certificate/private key. -.SH "CONNECTED COMMANDS" -.IX Header "CONNECTED COMMANDS" -If a connection request is established with an \s-1SSL\s0 client and neither the -\&\fB\-www\fR nor the \fB\-WWW\fR option has been used then normally any data received -from the client is displayed and any key presses will be sent to the client. -.PP -Certain commands are also recognized which perform special operations. These -commands are a letter which must appear at the start of a line. They are listed -below. -.IP "\fBq\fR" 4 -.IX Item "q" -End the current \s-1SSL\s0 connection but still accept new connections. -.IP "\fBQ\fR" 4 -.IX Item "Q" -End the current \s-1SSL\s0 connection and exit. -.IP "\fBr\fR" 4 -.IX Item "r" -Renegotiate the \s-1SSL\s0 session (TLSv1.2 and below only). -.IP "\fBR\fR" 4 -.IX Item "R" -Renegotiate the \s-1SSL\s0 session and request a client certificate (TLSv1.2 and below -only). -.IP "\fBP\fR" 4 -.IX Item "P" -Send some plain text down the underlying \s-1TCP\s0 connection: this should -cause the client to disconnect due to a protocol violation. -.IP "\fBS\fR" 4 -.IX Item "S" -Print out some session cache status information. -.IP "\fBk\fR" 4 -.IX Item "k" -Send a key update message to the client (TLSv1.3 only) -.IP "\fBK\fR" 4 -.IX Item "K" -Send a key update message to the client and request one back (TLSv1.3 only) -.IP "\fBc\fR" 4 -.IX Item "c" -Send a certificate request to the client (TLSv1.3 only) -.SH "NOTES" -.IX Header "NOTES" -This command can be used to debug \s-1SSL\s0 clients. To accept connections -from a web browser the command: -.PP -.Vb 1 -\& openssl s_server \-accept 443 \-www -.Ve -.PP -can be used for example. -.PP -Although specifying an empty list of CAs when requesting a client certificate -is strictly speaking a protocol violation, some \s-1SSL\s0 clients interpret this to -mean any \s-1CA\s0 is acceptable. This is useful for debugging purposes. -.PP -The session parameters can printed out using the \fBopenssl\-sess_id\fR\|(1) command. -.SH "BUGS" -.IX Header "BUGS" -Because this program has a lot of options and also because some of the -techniques used are rather old, the C source for this command is rather -hard to read and not a model of how things should be done. -A typical \s-1SSL\s0 server program would be much simpler. -.PP -The output of common ciphers is wrong: it just gives the list of ciphers that -OpenSSL recognizes and the client supports. -.PP -There should be a way for this command to print out details -of any unknown cipher suites a client says it supports. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-sess_id\fR\|(1), -\&\fBopenssl\-s_client\fR\|(1), -\&\fBopenssl\-ciphers\fR\|(1), -\&\fBSSL_CONF_cmd\fR\|(3), -\&\fBSSL_CTX_set_max_send_fragment\fR\|(3), -\&\fBSSL_CTX_set_split_send_fragment\fR\|(3), -\&\fBSSL_CTX_set_max_pipelines\fR\|(3), -\&\fBossl_store\-file\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \-no_alt_chains option was added in OpenSSL 1.1.0. -.PP -The -\&\-allow\-no\-dhe\-kex and \-prioritize_chacha options were added in OpenSSL 1.1.1. -.PP -The \fB\-srpvfile\fR, \fB\-srpuserseed\fR, and \fB\-engine\fR -option were deprecated in OpenSSL 3.0. -.PP -The -\&\fB\-enable_client_rpk\fR, -\&\fB\-enable_server_rpk\fR, -\&\fB\-no_rx_cert_comp\fR, -\&\fB\-no_tx_cert_comp\fR, -and \fB\-tfo\fR -options were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-s_time.1ossl b/openssl-install/share/man/man1/openssl-s_time.1ossl deleted file mode 100644 index 7300cd75..00000000 --- a/openssl-install/share/man/man1/openssl-s_time.1ossl +++ /dev/null @@ -1,327 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-S_TIME 1ossl" -.TH OPENSSL-S_TIME 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-s_time \- SSL/TLS performance timing program -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBs_time\fR -[\fB\-help\fR] -[\fB\-connect\fR \fIhost\fR:\fIport\fR] -[\fB\-www\fR \fIpage\fR] -[\fB\-cert\fR \fIfilename\fR] -[\fB\-key\fR \fIfilename\fR] -[\fB\-reuse\fR] -[\fB\-new\fR] -[\fB\-verify\fR \fIdepth\fR] -[\fB\-time\fR \fIseconds\fR] -[\fB\-ssl3\fR] -[\fB\-tls1\fR] -[\fB\-tls1_1\fR] -[\fB\-tls1_2\fR] -[\fB\-tls1_3\fR] -[\fB\-bugs\fR] -[\fB\-cipher\fR \fIcipherlist\fR] -[\fB\-ciphersuites\fR \fIval\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-cafile\fR \fIfile\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command implements a generic \s-1SSL/TLS\s0 client which -connects to a remote host using \s-1SSL/TLS.\s0 It can request a page from the server -and includes the time to transfer the payload data in its timing measurements. -It measures the number of connections within a given timeframe, the amount of -data transferred (if any), and calculates the average time spent for one -connection. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-connect\fR \fIhost\fR:\fIport\fR" 4 -.IX Item "-connect host:port" -This specifies the host and optional port to connect to. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -.IP "\fB\-www\fR \fIpage\fR" 4 -.IX Item "-www page" -This specifies the page to \s-1GET\s0 from the server. A value of '/' gets the -\&\fIindex.html\fR page. If this parameter is not specified, then this command -will only perform the handshake to establish \s-1SSL\s0 connections but not transfer -any payload data. -.IP "\fB\-cert\fR \fIcertname\fR" 4 -.IX Item "-cert certname" -The certificate to use, if one is requested by the server. The default is -not to use a certificate. The file is in \s-1PEM\s0 format. -.IP "\fB\-key\fR \fIkeyfile\fR" 4 -.IX Item "-key keyfile" -The private key to use. If not specified then the certificate file will -be used. The file is in \s-1PEM\s0 format. -.IP "\fB\-verify\fR \fIdepth\fR" 4 -.IX Item "-verify depth" -The verify depth to use. This specifies the maximum length of the -server certificate chain and turns on server certificate verification. -Currently the verify operation continues after errors so all the problems -with a certificate chain can be seen. As a side effect the connection -will never fail due to a server certificate verify failure. -.IP "\fB\-new\fR" 4 -.IX Item "-new" -Performs the timing test using a new session \s-1ID\s0 for each connection. -If neither \fB\-new\fR nor \fB\-reuse\fR are specified, they are both on by default -and executed in sequence. -.IP "\fB\-reuse\fR" 4 -.IX Item "-reuse" -Performs the timing test using the same session \s-1ID\s0; this can be used as a test -that session caching is working. If neither \fB\-new\fR nor \fB\-reuse\fR are -specified, they are both on by default and executed in sequence. -.IP "\fB\-bugs\fR" 4 -.IX Item "-bugs" -There are several known bugs in \s-1SSL\s0 and \s-1TLS\s0 implementations. Adding this -option enables various workarounds. -.IP "\fB\-cipher\fR \fIcipherlist\fR" 4 -.IX Item "-cipher cipherlist" -This allows the TLSv1.2 and below cipher list sent by the client to be modified. -This list will be combined with any TLSv1.3 ciphersuites that have been -configured. Although the server determines which cipher suite is used it should -take the first supported cipher in the list sent by the client. See -\&\fBopenssl\-ciphers\fR\|(1) for more information. -.IP "\fB\-ciphersuites\fR \fIval\fR" 4 -.IX Item "-ciphersuites val" -This allows the TLSv1.3 ciphersuites sent by the client to be modified. This -list will be combined with any TLSv1.2 and below ciphersuites that have been -configured. Although the server determines which cipher suite is used it should -take the first supported cipher in the list sent by the client. See -\&\fBopenssl\-ciphers\fR\|(1) for more information. The format for this list is a -simple colon (\*(L":\*(R") separated list of TLSv1.3 ciphersuite names. -.IP "\fB\-time\fR \fIlength\fR" 4 -.IX Item "-time length" -Specifies how long (in seconds) this command should establish connections -and optionally transfer payload data from a server. Server and client -performance and the link speed determine how many connections it -can establish. -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -This specifies how the subject or issuer names are displayed. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-cafile\fR \fIfile\fR" 4 -.IX Item "-cafile file" -This is an obsolete synonym for \fB\-CAfile\fR. -.IP "\fB\-ssl3\fR, \fB\-tls1\fR, \fB\-tls1_1\fR, \fB\-tls1_2\fR, \fB\-tls1_3\fR" 4 -.IX Item "-ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3" -See \*(L"\s-1TLS\s0 Version Options\*(R" in \fBopenssl\fR\|(1). -.SH "NOTES" -.IX Header "NOTES" -This command can be used to measure the performance of an \s-1SSL\s0 connection. -To connect to an \s-1SSL HTTP\s0 server and get the default page the command -.PP -.Vb 1 -\& openssl s_time \-connect servername:443 \-www / \-CApath yourdir \-CAfile yourfile.pem \-cipher commoncipher [\-ssl3] -.Ve -.PP -would typically be used (https uses port 443). \fIcommoncipher\fR is a cipher to -which both client and server can agree, see the \fBopenssl\-ciphers\fR\|(1) command -for details. -.PP -If the handshake fails then there are several possible causes, if it is -nothing obvious like no client certificate then the \fB\-bugs\fR and -\&\fB\-ssl3\fR options can be tried -in case it is a buggy server. In particular you should play with these -options \fBbefore\fR submitting a bug report to an OpenSSL mailing list. -.PP -A frequent problem when attempting to get client certificates working -is that a web client complains it has no certificates or gives an empty -list to choose from. This is normally because the server is not sending -the clients certificate authority in its \*(L"acceptable \s-1CA\s0 list\*(R" when it -requests a certificate. By using \fBopenssl\-s_client\fR\|(1) the \s-1CA\s0 list can be -viewed and checked. However, some servers only request client authentication -after a specific \s-1URL\s0 is requested. To obtain the list in this case it -is necessary to use the \fB\-prexit\fR option of \fBopenssl\-s_client\fR\|(1) and -send an \s-1HTTP\s0 request for an appropriate page. -.PP -If a certificate is specified on the command line using the \fB\-cert\fR -option it will not be used unless the server specifically requests -a client certificate. Therefore, merely including a client certificate -on the command line is no guarantee that the certificate works. -.SH "BUGS" -.IX Header "BUGS" -Because this program does not have all the options of the -\&\fBopenssl\-s_client\fR\|(1) program to turn protocols on and off, you may not -be able to measure the performance of all protocols with all servers. -.PP -The \fB\-verify\fR option should really exit if the server verification -fails. -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-cafile\fR option was deprecated in OpenSSL 3.0. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-s_client\fR\|(1), -\&\fBopenssl\-s_server\fR\|(1), -\&\fBopenssl\-ciphers\fR\|(1), -\&\fBossl_store\-file\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-sess_id.1ossl b/openssl-install/share/man/man1/openssl-sess_id.1ossl deleted file mode 100644 index 0ad61a50..00000000 --- a/openssl-install/share/man/man1/openssl-sess_id.1ossl +++ /dev/null @@ -1,267 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-SESS_ID 1ossl" -.TH OPENSSL-SESS_ID 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-sess_id \- SSL/TLS session handling command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBsess_id\fR -[\fB\-help\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1NSS\s0\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-text\fR] -[\fB\-cert\fR] -[\fB\-noout\fR] -[\fB\-context\fR \fI\s-1ID\s0\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes the encoded version of the \s-1SSL\s0 session -structure and optionally prints out \s-1SSL\s0 session details (for example -the \s-1SSL\s0 session master key) in human readable format. Since this is a -diagnostic tool that needs some knowledge of the \s-1SSL\s0 protocol to use -properly, most users will not need to use it. -.PP -The precise format of the data can vary across OpenSSL versions and -is not documented. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR, \fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1NSS\s0\fR" 4 -.IX Item "-inform DER|PEM, -outform DER|PEM|NSS" -The input and output formats; the default is \s-1PEM.\s0 -See \fBopenssl\-format\-options\fR\|(1) for details. -.Sp -For \fB\s-1NSS\s0\fR output, the session \s-1ID\s0 and master key are reported in \s-1NSS\s0 \*(L"keylog\*(R" -format. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read session information from or standard -input by default. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write session information to or standard -output if this option is not specified. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the various public or private key components in -plain text in addition to the encoded version. -.IP "\fB\-cert\fR" 4 -.IX Item "-cert" -If a certificate is present in the session it will be output using this option, -if the \fB\-text\fR option is also present then it will be printed out in text form. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option prevents output of the encoded version of the session. -.IP "\fB\-context\fR \fI\s-1ID\s0\fR" 4 -.IX Item "-context ID" -This option can set the session id so the output session information uses the -supplied \s-1ID.\s0 The \s-1ID\s0 can be any string of characters. This option won't normally -be used. -.SH "OUTPUT" -.IX Header "OUTPUT" -Typical output: -.PP -.Vb 10 -\& SSL\-Session: -\& Protocol : TLSv1 -\& Cipher : 0016 -\& Session\-ID: 871E62626C554CE95488823752CBD5F3673A3EF3DCE9C67BD916C809914B40ED -\& Session\-ID\-ctx: 01000000 -\& Master\-Key: A7CEFC571974BE02CAC305269DC59F76EA9F0B180CB6642697A68251F2D2BB57E51DBBB4C7885573192AE9AEE220FACD -\& Key\-Arg : None -\& Start Time: 948459261 -\& Timeout : 300 (sec) -\& Verify return code 0 (ok) -.Ve -.PP -These are described below in more detail. -.IP "\fBProtocol\fR" 4 -.IX Item "Protocol" -This is the protocol in use TLSv1.3, TLSv1.2, TLSv1.1, TLSv1 or SSLv3. -.IP "\fBCipher\fR" 4 -.IX Item "Cipher" -The cipher used this is the actual raw \s-1SSL\s0 or \s-1TLS\s0 cipher code, see the \s-1SSL\s0 -or \s-1TLS\s0 specifications for more information. -.IP "\fBSession-ID\fR" 4 -.IX Item "Session-ID" -The \s-1SSL\s0 session \s-1ID\s0 in hex format. -.IP "\fBSession-ID-ctx\fR" 4 -.IX Item "Session-ID-ctx" -The session \s-1ID\s0 context in hex format. -.IP "\fBMaster-Key\fR" 4 -.IX Item "Master-Key" -This is the \s-1SSL\s0 session master key. -.IP "\fBStart Time\fR" 4 -.IX Item "Start Time" -This is the session start time represented as an integer in standard -Unix format. -.IP "\fBTimeout\fR" 4 -.IX Item "Timeout" -The timeout in seconds. -.IP "\fBVerify return code\fR" 4 -.IX Item "Verify return code" -This is the return code when an \s-1SSL\s0 client certificate is verified. -.SH "NOTES" -.IX Header "NOTES" -Since the \s-1SSL\s0 session output contains the master key it is -possible to read the contents of an encrypted session using this -information. Therefore, appropriate security precautions should be taken if -the information is being output by a \*(L"real\*(R" application. This is however -strongly discouraged and should only be used for debugging purposes. -.SH "BUGS" -.IX Header "BUGS" -The cipher and start time should be printed out in human readable form. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-ciphers\fR\|(1), -\&\fBopenssl\-s_server\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-smime.1ossl b/openssl-install/share/man/man1/openssl-smime.1ossl deleted file mode 100644 index c1de061b..00000000 --- a/openssl-install/share/man/man1/openssl-smime.1ossl +++ /dev/null @@ -1,642 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-SMIME 1ossl" -.TH OPENSSL-SMIME 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-smime \- S/MIME command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBsmime\fR -[\fB\-help\fR] -[\fB\-encrypt\fR] -[\fB\-decrypt\fR] -[\fB\-sign\fR] -[\fB\-resign\fR] -[\fB\-verify\fR] -[\fB\-pk7out\fR] -[\fB\-binary\fR] -[\fB\-crlfeol\fR] -[\fB\-\f(BIcipher\fB\fR] -[\fB\-in\fR \fIfile\fR] -[\fB\-certfile\fR \fIfile\fR] -[\fB\-signer\fR \fIfile\fR] -[\fB\-nointern\fR] -[\fB\-noverify\fR] -[\fB\-nochain\fR] -[\fB\-nosigs\fR] -[\fB\-nocerts\fR] -[\fB\-noattr\fR] -[\fB\-nodetach\fR] -[\fB\-nosmimecap\fR] -[\fB\-recip\fR \fI file\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-inkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-out\fR \fIfile\fR] -[\fB\-content\fR \fIfile\fR] -[\fB\-to\fR \fIaddr\fR] -[\fB\-from\fR \fIad\fR] -[\fB\-subject\fR \fIs\fR] -[\fB\-text\fR] -[\fB\-indef\fR] -[\fB\-noindef\fR] -[\fB\-stream\fR] -[\fB\-md\fR \fIdigest\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-config\fR \fIconfigfile\fR] -\&\fIrecipcert\fR ... -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command handles S/MIME mail. It can encrypt, decrypt, sign -and verify S/MIME messages. -.SH "OPTIONS" -.IX Header "OPTIONS" -There are six operation options that set the type of operation to be performed: -\&\fB\-encrypt\fR, \fB\-decrypt\fR, \fB\-sign\fR, \fB\-resign\fR, \fB\-verify\fR, and \fB\-pk7out\fR. -These are mutually exclusive. -The meaning of the other options varies according to the operation type. -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-encrypt\fR" 4 -.IX Item "-encrypt" -Encrypt mail for the given recipient certificates. Input file is the message -to be encrypted. The output file is the encrypted mail in \s-1MIME\s0 format. -.Sp -Note that no revocation check is done for the recipient cert, so if that -key has been compromised, others may be able to decrypt the text. -.IP "\fB\-decrypt\fR" 4 -.IX Item "-decrypt" -Decrypt mail using the supplied certificate and private key. Expects an -encrypted mail message in \s-1MIME\s0 format for the input file. The decrypted mail -is written to the output file. -.IP "\fB\-sign\fR" 4 -.IX Item "-sign" -Sign mail using the supplied certificate and private key. Input file is -the message to be signed. The signed message in \s-1MIME\s0 format is written -to the output file. -.IP "\fB\-resign\fR" 4 -.IX Item "-resign" -Resign a message: take an existing message and one or more new signers. -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verify signed mail. Expects a signed mail message on input and outputs -the signed data. Both clear text and opaque signing is supported. -.IP "\fB\-pk7out\fR" 4 -.IX Item "-pk7out" -Takes an input message and writes out a \s-1PEM\s0 encoded PKCS#7 structure. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -The input message to be encrypted or signed or the \s-1MIME\s0 message to -be decrypted or verified. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -The message text that has been decrypted or verified or the output \s-1MIME\s0 -format message that has been signed or verified. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR" 4 -.IX Item "-inform DER|PEM|SMIME" -The input format of the PKCS#7 (S/MIME) structure (if one is being read); -the default is \fB\s-1SMIME\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fB\s-1SMIME\s0\fR" 4 -.IX Item "-outform DER|PEM|SMIME" -The output format of the PKCS#7 (S/MIME) structure (if one is being written); -the default is \fB\s-1SMIME\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The key format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-stream\fR, \fB\-indef\fR, \fB\-noindef\fR" 4 -.IX Item "-stream, -indef, -noindef" -The \fB\-stream\fR and \fB\-indef\fR options are equivalent and enable streaming I/O -for encoding operations. This permits single pass processing of data without -the need to hold the entire contents in memory, potentially supporting very -large files. Streaming is automatically set for S/MIME signing with detached -data if the output format is \fB\s-1SMIME\s0\fR it is currently off by default for all -other operations. -.IP "\fB\-noindef\fR" 4 -.IX Item "-noindef" -Disable streaming I/O where it would produce and indefinite length constructed -encoding. This option currently has no effect. In future streaming will be -enabled by default on all relevant operations and this option will disable it. -.IP "\fB\-content\fR \fIfilename\fR" 4 -.IX Item "-content filename" -This specifies a file containing the detached content, this is only -useful with the \fB\-verify\fR command. This is only usable if the PKCS#7 -structure is using the detached signature form where the content is -not included. This option will override any content if the input format -is S/MIME and it uses the multipart/signed \s-1MIME\s0 content type. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -This option adds plain text (text/plain) \s-1MIME\s0 headers to the supplied -message if encrypting or signing. If decrypting or verifying it strips -off text headers: if the decrypted or verified message is not of \s-1MIME\s0 -type text/plain then an error occurs. -.IP "\fB\-md\fR \fIdigest\fR" 4 -.IX Item "-md digest" -Digest algorithm to use when signing or resigning. If not present then the -default digest algorithm for the signing key will be used (usually \s-1SHA1\s0). -.IP "\fB\-\f(BIcipher\fB\fR" 4 -.IX Item "-cipher" -The encryption algorithm to use. For example \s-1DES\s0 (56 bits) \- \fB\-des\fR, -triple \s-1DES\s0 (168 bits) \- \fB\-des3\fR, -\&\fBEVP_get_cipherbyname()\fR function) can also be used preceded by a dash, for -example \fB\-aes\-128\-cbc\fR. See \fBopenssl\-enc\fR\|(1) for list of ciphers -supported by your version of OpenSSL. -.Sp -If not specified triple \s-1DES\s0 is used. Only used with \fB\-encrypt\fR. -.IP "\fB\-nointern\fR" 4 -.IX Item "-nointern" -When verifying a message normally certificates (if any) included in -the message are searched for the signing certificate. With this option -only the certificates specified in the \fB\-certfile\fR option are used. -The supplied certificates can still be used as untrusted CAs however. -.IP "\fB\-noverify\fR" 4 -.IX Item "-noverify" -Do not verify the signers certificate of a signed message. -.IP "\fB\-nochain\fR" 4 -.IX Item "-nochain" -Do not do chain verification of signers certificates; that is, do not -use the certificates in the signed message as untrusted CAs. -.IP "\fB\-nosigs\fR" 4 -.IX Item "-nosigs" -Don't try to verify the signatures on the message. -.IP "\fB\-nocerts\fR" 4 -.IX Item "-nocerts" -When signing a message, the signer's certificate is normally included. -With this option it is excluded. This will reduce the size of the -signed message, but the verifier must have a copy of the signers certificate -available locally (passed using the \fB\-certfile\fR option for example). -.IP "\fB\-noattr\fR" 4 -.IX Item "-noattr" -Normally, when a message is signed, a set of attributes are included which -include the signing time and supported symmetric algorithms. With this -option they are not included. -.IP "\fB\-nodetach\fR" 4 -.IX Item "-nodetach" -When signing a message use opaque signing. This form is more resistant -to translation by mail relays but it cannot be read by mail agents that -do not support S/MIME. Without this option cleartext signing with -the \s-1MIME\s0 type multipart/signed is used. -.IP "\fB\-nosmimecap\fR" 4 -.IX Item "-nosmimecap" -When signing a message, do not include the \fBSMIMECapabilities\fR attribute. -.IP "\fB\-binary\fR" 4 -.IX Item "-binary" -Normally the input message is converted to \*(L"canonical\*(R" format which is -effectively using \s-1CR\s0 and \s-1LF\s0 as end of line: as required by the S/MIME -specification. When this option is present no translation occurs. This -is useful when handling binary data which may not be in \s-1MIME\s0 format. -.IP "\fB\-crlfeol\fR" 4 -.IX Item "-crlfeol" -Normally the output file uses a single \fB\s-1LF\s0\fR as end of line. When this -option is present \fB\s-1CRLF\s0\fR is used instead. -.IP "\fB\-certfile\fR \fIfile\fR" 4 -.IX Item "-certfile file" -Allows additional certificates to be specified. When signing these will -be included with the message. When verifying, these will be searched for -signer certificates and will be used for chain building. -.Sp -The input can be in \s-1PEM, DER,\s0 or PKCS#12 format. -.IP "\fB\-signer\fR \fIfile\fR" 4 -.IX Item "-signer file" -A signing certificate when signing or resigning a message, this option can be -used multiple times if more than one signer is required. If a message is being -verified then the signers certificates will be written to this file if the -verification was successful. -.IP "\fB\-recip\fR \fIfile\fR" 4 -.IX Item "-recip file" -The recipients certificate when decrypting a message. This certificate -must match one of the recipients of the message or an error occurs. -.IP "\fB\-inkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-inkey filename|uri" -The private key to use when signing or decrypting. This must match the -corresponding certificate. If this option is not specified then the -private key must be included in the certificate file specified with -the \fB\-recip\fR or \fB\-signer\fR file. When signing this option can be used -multiple times to specify successive keys. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The private key password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-to\fR, \fB\-from\fR, \fB\-subject\fR" 4 -.IX Item "-to, -from, -subject" -The relevant mail headers. These are included outside the signed -portion of a message so they may be included manually. If signing -then many S/MIME mail clients check the signers certificate's email -address matches that specified in the From: address. -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.Sp -Any verification errors cause the command to exit. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-config\fR \fIconfigfile\fR" 4 -.IX Item "-config configfile" -See \*(L"Configuration Option\*(R" in \fBopenssl\fR\|(1). -.IP "\fIrecipcert\fR ..." 4 -.IX Item "recipcert ..." -One or more certificates of message recipients, used when encrypting -a message. -.SH "NOTES" -.IX Header "NOTES" -The \s-1MIME\s0 message must be sent without any blank lines between the -headers and the output. Some mail programs will automatically add -a blank line. Piping the mail directly to sendmail is one way to -achieve the correct format. -.PP -The supplied message to be signed or encrypted must include the -necessary \s-1MIME\s0 headers or many S/MIME clients won't display it -properly (if at all). You can use the \fB\-text\fR option to automatically -add plain text headers. -.PP -A \*(L"signed and encrypted\*(R" message is one where a signed message is -then encrypted. This can be produced by encrypting an already signed -message: see the examples section. -.PP -This version of the program only allows one signer per message but it -will verify multiple signers on received messages. Some S/MIME clients -choke if a message contains multiple signers. It is possible to sign -messages \*(L"in parallel\*(R" by signing an already signed message. -.PP -The options \fB\-encrypt\fR and \fB\-decrypt\fR reflect common usage in S/MIME -clients. Strictly speaking these process PKCS#7 enveloped data: PKCS#7 -encrypted data is used for other purposes. -.PP -The \fB\-resign\fR option uses an existing message digest when adding a new -signer. This means that attributes must be present in at least one existing -signer using the same message digest or this operation will fail. -.PP -The \fB\-stream\fR and \fB\-indef\fR options enable streaming I/O support. -As a result the encoding is \s-1BER\s0 using indefinite length constructed encoding -and no longer \s-1DER.\s0 Streaming is supported for the \fB\-encrypt\fR operation and the -\&\fB\-sign\fR operation if the content is not detached. -.PP -Streaming is always used for the \fB\-sign\fR operation with detached data but -since the content is no longer part of the PKCS#7 structure the encoding -remains \s-1DER.\s0 -.SH "EXIT CODES" -.IX Header "EXIT CODES" -.IP "0" 4 -The operation was completely successfully. -.IP "1" 4 -.IX Item "1" -An error occurred parsing the command options. -.IP "2" 4 -.IX Item "2" -One of the input files could not be read. -.IP "3" 4 -.IX Item "3" -An error occurred creating the PKCS#7 file or when reading the \s-1MIME\s0 -message. -.IP "4" 4 -.IX Item "4" -An error occurred decrypting or verifying the message. -.IP "5" 4 -.IX Item "5" -The message was verified correctly but an error occurred writing out -the signers certificates. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a cleartext signed message: -.PP -.Vb 2 -\& openssl smime \-sign \-in message.txt \-text \-out mail.msg \e -\& \-signer mycert.pem -.Ve -.PP -Create an opaque signed message: -.PP -.Vb 2 -\& openssl smime \-sign \-in message.txt \-text \-out mail.msg \-nodetach \e -\& \-signer mycert.pem -.Ve -.PP -Create a signed message, include some additional certificates and -read the private key from another file: -.PP -.Vb 2 -\& openssl smime \-sign \-in in.txt \-text \-out mail.msg \e -\& \-signer mycert.pem \-inkey mykey.pem \-certfile mycerts.pem -.Ve -.PP -Create a signed message with two signers: -.PP -.Vb 2 -\& openssl smime \-sign \-in message.txt \-text \-out mail.msg \e -\& \-signer mycert.pem \-signer othercert.pem -.Ve -.PP -Send a signed message under Unix directly to sendmail, including headers: -.PP -.Vb 3 -\& openssl smime \-sign \-in in.txt \-text \-signer mycert.pem \e -\& \-from steve@openssl.org \-to someone@somewhere \e -\& \-subject "Signed message" | sendmail someone@somewhere -.Ve -.PP -Verify a message and extract the signer's certificate if successful: -.PP -.Vb 1 -\& openssl smime \-verify \-in mail.msg \-signer user.pem \-out signedtext.txt -.Ve -.PP -Send encrypted mail using triple \s-1DES:\s0 -.PP -.Vb 3 -\& openssl smime \-encrypt \-in in.txt \-out mail.msg \-from steve@openssl.org \e -\& \-to someone@somewhere \-subject "Encrypted message" \e -\& \-des3 user.pem -.Ve -.PP -Sign and encrypt mail: -.PP -.Vb 4 -\& openssl smime \-sign \-in ml.txt \-signer my.pem \-text \e -\& | openssl smime \-encrypt \-out mail.msg \e -\& \-from steve@openssl.org \-to someone@somewhere \e -\& \-subject "Signed and Encrypted message" \-des3 user.pem -.Ve -.PP -Note: the encryption command does not include the \fB\-text\fR option because the -message being encrypted already has \s-1MIME\s0 headers. -.PP -Decrypt mail: -.PP -.Vb 1 -\& openssl smime \-decrypt \-in mail.msg \-recip mycert.pem \-inkey key.pem -.Ve -.PP -The output from Netscape form signing is a PKCS#7 structure with the -detached signature format. You can use this program to verify the -signature by line wrapping the base64 encoded structure and surrounding -it with: -.PP -.Vb 2 -\& \-\-\-\-\-BEGIN PKCS7\-\-\-\-\- -\& \-\-\-\-\-END PKCS7\-\-\-\-\- -.Ve -.PP -and using the command: -.PP -.Vb 1 -\& openssl smime \-verify \-inform PEM \-in signature.pem \-content content.txt -.Ve -.PP -Alternatively you can base64 decode the signature and use: -.PP -.Vb 1 -\& openssl smime \-verify \-inform DER \-in signature.der \-content content.txt -.Ve -.PP -Create an encrypted message using 128 bit Camellia: -.PP -.Vb 1 -\& openssl smime \-encrypt \-in plain.txt \-camellia128 \-out mail.msg cert.pem -.Ve -.PP -Add a signer to an existing message: -.PP -.Vb 1 -\& openssl smime \-resign \-in mail.msg \-signer newsign.pem \-out mail2.msg -.Ve -.SH "BUGS" -.IX Header "BUGS" -The \s-1MIME\s0 parser isn't very clever: it seems to handle most messages that I've -thrown at it but it may choke on others. -.PP -The code currently will only write out the signer's certificate to a file: if -the signer has a separate encryption certificate this must be manually -extracted. There should be some heuristic that determines the correct -encryption certificate. -.PP -Ideally a database should be maintained of a certificates for each email -address. -.PP -The code doesn't currently take note of the permitted symmetric encryption -algorithms as supplied in the SMIMECapabilities signed attribute. This means the -user has to manually include the correct encryption algorithm. It should store -the list of permitted ciphers in a database and only use those. -.PP -No revocation checking is done on the signer's certificate. -.PP -The current code can only handle S/MIME v2 messages, the more complex S/MIME v3 -structures may cause parsing errors. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\-file\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The use of multiple \fB\-signer\fR options and the \fB\-resign\fR command were first -added in OpenSSL 1.0.0 -.PP -The \-no_alt_chains option was added in OpenSSL 1.1.0. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-speed.1ossl b/openssl-install/share/man/man1/openssl-speed.1ossl deleted file mode 100644 index c36a2449..00000000 --- a/openssl-install/share/man/man1/openssl-speed.1ossl +++ /dev/null @@ -1,297 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-SPEED 1ossl" -.TH OPENSSL-SPEED 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-speed \- test library performance -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl speed\fR -[\fB\-help\fR] -[\fB\-config\fR \fIfilename\fR] -[\fB\-elapsed\fR] -[\fB\-evp\fR \fIalgo\fR] -[\fB\-hmac\fR \fIalgo\fR] -[\fB\-cmac\fR \fIalgo\fR] -[\fB\-mb\fR] -[\fB\-aead\fR] -[\fB\-kem\-algorithms\fR] -[\fB\-signature\-algorithms\fR] -[\fB\-multi\fR \fInum\fR] -[\fB\-async_jobs\fR \fInum\fR] -[\fB\-misalign\fR \fInum\fR] -[\fB\-decrypt\fR] -[\fB\-primes\fR \fInum\fR] -[\fB\-seconds\fR \fInum\fR] -[\fB\-bytes\fR \fInum\fR] -[\fB\-mr\fR] -[\fB\-mlock\fR] -[\fB\-testmode\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fIalgorithm\fR ...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to test the performance of cryptographic algorithms. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-config\fR \fIfilename\fR" 4 -.IX Item "-config filename" -Specifies the configuration file to use. -Optional; for a description of the default value, -see \*(L"\s-1COMMAND SUMMARY\*(R"\s0 in \fBopenssl\fR\|(1). -.IP "\fB\-elapsed\fR" 4 -.IX Item "-elapsed" -When calculating operations\- or bytes-per-second, use wall-clock time -instead of \s-1CPU\s0 user time as divisor. It can be useful when testing speed -of hardware engines. -.IP "\fB\-evp\fR \fIalgo\fR" 4 -.IX Item "-evp algo" -Use the specified cipher or message digest algorithm via the \s-1EVP\s0 interface. -If \fIalgo\fR is an \s-1AEAD\s0 cipher, then you can pass \fB\-aead\fR to benchmark a -TLS-like sequence. And if \fIalgo\fR is a multi-buffer capable cipher, e.g. -aes\-128\-cbc\-hmac\-sha1, then \fB\-mb\fR will time multi-buffer operation. -.Sp -To see the algorithms supported with this option, use -\&\f(CW\*(C`openssl list \-digest\-algorithms\*(C'\fR or \f(CW\*(C`openssl list \-cipher\-algorithms\*(C'\fR -command. -.IP "\fB\-multi\fR \fInum\fR" 4 -.IX Item "-multi num" -Run multiple operations in parallel. -.IP "\fB\-async_jobs\fR \fInum\fR" 4 -.IX Item "-async_jobs num" -Enable async mode and start specified number of jobs. -.IP "\fB\-misalign\fR \fInum\fR" 4 -.IX Item "-misalign num" -Misalign the buffers by the specified number of bytes. -.IP "\fB\-hmac\fR \fIdigest\fR" 4 -.IX Item "-hmac digest" -Time the \s-1HMAC\s0 algorithm using the specified message digest. -.IP "\fB\-cmac\fR \fIcipher\fR" 4 -.IX Item "-cmac cipher" -Time the \s-1CMAC\s0 algorithm using the specified cipher e.g. -\&\f(CW\*(C`openssl speed \-cmac aes128\*(C'\fR. -.IP "\fB\-decrypt\fR" 4 -.IX Item "-decrypt" -Time the decryption instead of encryption. Affects only the \s-1EVP\s0 testing. -.IP "\fB\-mb\fR" 4 -.IX Item "-mb" -Enable multi-block mode on EVP-named cipher. -.IP "\fB\-aead\fR" 4 -.IX Item "-aead" -Benchmark EVP-named \s-1AEAD\s0 cipher in TLS-like sequence. -.IP "\fB\-kem\-algorithms\fR" 4 -.IX Item "-kem-algorithms" -Benchmark \s-1KEM\s0 algorithms: key generation, encapsulation, decapsulation. -.IP "\fB\-signature\-algorithms\fR" 4 -.IX Item "-signature-algorithms" -Benchmark signature algorithms: key generation, signature, verification. -.IP "\fB\-primes\fR \fInum\fR" 4 -.IX Item "-primes num" -Generate a \fInum\fR\-prime \s-1RSA\s0 key and use it to run the benchmarks. This option -is only effective if \s-1RSA\s0 algorithm is specified to test. -.IP "\fB\-seconds\fR \fInum\fR" 4 -.IX Item "-seconds num" -Run benchmarks for \fInum\fR seconds. -.IP "\fB\-bytes\fR \fInum\fR" 4 -.IX Item "-bytes num" -Run benchmarks on \fInum\fR\-byte buffers. Affects ciphers, digests and the \s-1CSPRNG.\s0 -The limit on the size of the buffer is \s-1INT_MAX\s0 \- 64 bytes, which for a 32\-bit -int would be 2147483583 bytes. -.IP "\fB\-mr\fR" 4 -.IX Item "-mr" -Produce the summary in a mechanical, machine-readable, format. -.IP "\fB\-mlock\fR" 4 -.IX Item "-mlock" -Lock memory into \s-1RAM\s0 for more deterministic measurements. -.IP "\fB\-testmode\fR" 4 -.IX Item "-testmode" -Runs the speed command in testmode. Runs only 1 iteration of each algorithm test -regardless of any \fB\-seconds\fR value. In the event that any operation fails then -the speed command will return with a failure result. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fIalgorithm\fR ..." 4 -.IX Item "algorithm ..." -If any \fIalgorithm\fR is given, then those algorithms are tested, otherwise a -pre-compiled grand selection is tested. -.SH "BUGS" -.IX Header "BUGS" -The \fIalgorithm\fR can be selected only from a pre-compiled subset of things -that the \f(CW\*(C`openssl speed\*(C'\fR command knows about. To test any additional digest -or cipher algorithm supported by OpenSSL use the \f(CW\*(C`\-evp\*(C'\fR option. -.PP -There is no way to test the speed of any additional public key algorithms -supported by third party providers with the \f(CW\*(C`openssl speed\*(C'\fR command. -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -\&\s-1DSA512\s0 was removed in OpenSSL 3.2. -.PP -The \fB\-testmode\fR option was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-spkac.1ossl b/openssl-install/share/man/man1/openssl-spkac.1ossl deleted file mode 100644 index 6e1c18bc..00000000 --- a/openssl-install/share/man/man1/openssl-spkac.1ossl +++ /dev/null @@ -1,295 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-SPKAC 1ossl" -.TH OPENSSL-SPKAC 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-spkac \- SPKAC printing and generating command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBspkac\fR -[\fB\-help\fR] -[\fB\-in\fR \fIfilename\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-digest\fR \fIdigest\fR] -[\fB\-key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-challenge\fR \fIstring\fR] -[\fB\-pubkey\fR] -[\fB\-spkac\fR \fIspkacname\fR] -[\fB\-spksect\fR \fIsection\fR] -[\fB\-noout\fR] -[\fB\-verify\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command processes Netscape signed public key and challenge -(\s-1SPKAC\s0) files. It can print out their contents, verify the signature and -produce its own SPKACs from a supplied private key. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-in\fR \fIfilename\fR" 4 -.IX Item "-in filename" -This specifies the input filename to read from or standard input if this -option is not specified. Ignored if the \fB\-key\fR option is used. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -Specifies the output filename to write to or standard output by -default. -.IP "\fB\-digest\fR \fIdigest\fR" 4 -.IX Item "-digest digest" -Use the specified \fIdigest\fR to sign a created \s-1SPKAC\s0 file. -The default digest algorithm is \s-1MD5.\s0 -.IP "\fB\-key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-key filename|uri" -Create an \s-1SPKAC\s0 file using the private key specified by \fIfilename\fR or \fIuri\fR. -The \fB\-in\fR, \fB\-noout\fR, \fB\-spksect\fR and \fB\-verify\fR options are ignored if -present. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The key format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The input file password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-challenge\fR \fIstring\fR" 4 -.IX Item "-challenge string" -Specifies the challenge string if an \s-1SPKAC\s0 is being created. -.IP "\fB\-spkac\fR \fIspkacname\fR" 4 -.IX Item "-spkac spkacname" -Allows an alternative name form the variable containing the -\&\s-1SPKAC.\s0 The default is \*(L"\s-1SPKAC\*(R".\s0 This option affects both -generated and input \s-1SPKAC\s0 files. -.IP "\fB\-spksect\fR \fIsection\fR" 4 -.IX Item "-spksect section" -Allows an alternative name form the section containing the -\&\s-1SPKAC.\s0 The default is the default section. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -Don't output the text version of the \s-1SPKAC\s0 (not used if an -\&\s-1SPKAC\s0 is being created). -.IP "\fB\-pubkey\fR" 4 -.IX Item "-pubkey" -Output the public key of an \s-1SPKAC\s0 (not used if an \s-1SPKAC\s0 is -being created). -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verifies the digital signature on the supplied \s-1SPKAC.\s0 -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Print out the contents of an \s-1SPKAC:\s0 -.PP -.Vb 1 -\& openssl spkac \-in spkac.cnf -.Ve -.PP -Verify the signature of an \s-1SPKAC:\s0 -.PP -.Vb 1 -\& openssl spkac \-in spkac.cnf \-noout \-verify -.Ve -.PP -Create an \s-1SPKAC\s0 using the challenge string \*(L"hello\*(R": -.PP -.Vb 1 -\& openssl spkac \-key key.pem \-challenge hello \-out spkac.cnf -.Ve -.PP -Example of an \s-1SPKAC,\s0 (long lines split up for clarity): -.PP -.Vb 6 -\& SPKAC=MIG5MGUwXDANBgkqhkiG9w0BAQEFAANLADBIAkEA\e -\& 1cCoq2Wa3Ixs47uI7FPVwHVIPDx5yso105Y6zpozam135a\e -\& 8R0CpoRvkkigIyXfcCjiVi5oWk+6FfPaD03uPFoQIDAQAB\e -\& FgVoZWxsbzANBgkqhkiG9w0BAQQFAANBAFpQtY/FojdwkJ\e -\& h1bEIYuc2EeM2KHTWPEepWYeawvHD0gQ3DngSC75YCWnnD\e -\& dq+NQ3F+X4deMx9AaEglZtULwV4= -.Ve -.SH "NOTES" -.IX Header "NOTES" -A created \s-1SPKAC\s0 with suitable \s-1DN\s0 components appended can be fed to -\&\fBopenssl\-ca\fR\|(1). -.PP -SPKACs are typically generated by Netscape when a form is submitted -containing the \fB\s-1KEYGEN\s0\fR tag as part of the certificate enrollment -process. -.PP -The challenge string permits a primitive form of proof of possession -of private key. By checking the \s-1SPKAC\s0 signature and a random challenge -string some guarantee is given that the user knows the private key -corresponding to the public key being certified. This is important in -some applications. Without this it is possible for a previous \s-1SPKAC\s0 -to be used in a \*(L"replay attack\*(R". -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-ca\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-digest\fR option was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-srp.1ossl b/openssl-install/share/man/man1/openssl-srp.1ossl deleted file mode 100644 index 2186594c..00000000 --- a/openssl-install/share/man/man1/openssl-srp.1ossl +++ /dev/null @@ -1,249 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-SRP 1ossl" -.TH OPENSSL-SRP 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-srp \- maintain SRP password file -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl srp\fR -[\fB\-help\fR] -[\fB\-verbose\fR] -[\fB\-add\fR] -[\fB\-modify\fR] -[\fB\-delete\fR] -[\fB\-list\fR] -[\fB\-name\fR \fIsection\fR] -[\fB\-srpvfile\fR \fIfile\fR] -[\fB\-gn\fR \fIidentifier\fR] -[\fB\-userinfo\fR \fItext\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-passout\fR \fIarg\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-config\fR \fIconfigfile\fR] -[\fIuser\fR ...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is deprecated. It is used to maintain an \s-1SRP\s0 (secure remote -password) file. At most one of the \fB\-add\fR, \fB\-modify\fR, \fB\-delete\fR, and \fB\-list\fR -options can be specified. -These options take zero or more usernames as parameters and perform the -appropriate operation on the \s-1SRP\s0 file. -For \fB\-list\fR, if no \fIuser\fR is given then all users are displayed. -.PP -The configuration file to use, and the section within the file, can be -specified with the \fB\-config\fR and \fB\-name\fR flags, respectively. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Display an option summary. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Generate verbose output while processing. -.IP "\fB\-add\fR" 4 -.IX Item "-add" -Add a user and \s-1SRP\s0 verifier. -.IP "\fB\-modify\fR" 4 -.IX Item "-modify" -Modify the \s-1SRP\s0 verifier of an existing user. -.IP "\fB\-delete\fR" 4 -.IX Item "-delete" -Delete user from verifier file. -.IP "\fB\-list\fR" 4 -.IX Item "-list" -List users. -.IP "\fB\-name\fR" 4 -.IX Item "-name" -The particular \s-1SRP\s0 definition to use. -.IP "\fB\-srpvfile\fR \fIfile\fR" 4 -.IX Item "-srpvfile file" -If the config file is not specified, -\&\fB\-srpvfile\fR can be used to specify the file to operate on. -.IP "\fB\-gn\fR" 4 -.IX Item "-gn" -Specifies the \fBg\fR and \fBN\fR values, using one of -the strengths defined in \s-1IETF RFC 5054.\s0 -.IP "\fB\-userinfo\fR" 4 -.IX Item "-userinfo" -specifies additional information to add when -adding or modifying a user. -.IP "\fB\-passin\fR \fIarg\fR, \fB\-passout\fR \fIarg\fR" 4 -.IX Item "-passin arg, -passout arg" -The password source for the input and output file. -For more information about the format of \fBarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-config\fR \fIconfigfile\fR" 4 -.IX Item "-config configfile" -See \*(L"Configuration Option\*(R" in \fBopenssl\fR\|(1). -.Sp -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-storeutl.1ossl b/openssl-install/share/man/man1/openssl-storeutl.1ossl deleted file mode 100644 index c38f58ee..00000000 --- a/openssl-install/share/man/man1/openssl-storeutl.1ossl +++ /dev/null @@ -1,274 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-STOREUTL 1ossl" -.TH OPENSSL-STOREUTL 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-storeutl \- STORE command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBstoreutl\fR -[\fB\-help\fR] -[\fB\-out\fR \fIfile\fR] -[\fB\-noout\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-text\fR \fIarg\fR] -[\fB\-r\fR] -[\fB\-certs\fR] -[\fB\-keys\fR] -[\fB\-crls\fR] -[\fB\-subject\fR \fIarg\fR] -[\fB\-issuer\fR \fIarg\fR] -[\fB\-serial\fR \fIarg\fR] -[\fB\-alias\fR \fIarg\fR] -[\fB\-fingerprint\fR \fIarg\fR] -[\fB\-\f(BIdigest\fB\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -\&\fIuri\fR -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command can be used to display the contents (after -decryption as the case may be) fetched from the given \s-1URI.\s0 -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -specifies the output filename to write to or standard output by -default. -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -this option prevents output of the \s-1PEM\s0 data. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -the key password source. For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the objects in text form, similarly to the \fB\-text\fR output from -\&\fBopenssl\-x509\fR\|(1), \fBopenssl\-pkey\fR\|(1), etc. -.IP "\fB\-r\fR" 4 -.IX Item "-r" -Fetch objects recursively when possible. -.IP "\fB\-certs\fR" 4 -.IX Item "-certs" -.PD 0 -.IP "\fB\-keys\fR" 4 -.IX Item "-keys" -.IP "\fB\-crls\fR" 4 -.IX Item "-crls" -.PD -Only select the certificates, keys or CRLs from the given \s-1URI.\s0 -However, if this \s-1URI\s0 would return a set of names (URIs), those are always -returned. -.Sp -Note that all options must be given before the \fIuri\fR argument. -.Sp -Note \fI\-keys\fR selects exclusively private keys, there is no selector for public -keys only. -.IP "\fB\-subject\fR \fIarg\fR" 4 -.IX Item "-subject arg" -Search for an object having the subject name \fIarg\fR. -.Sp -The arg must be formatted as \f(CW\*(C`/type0=value0/type1=value1/type2=...\*(C'\fR. -Special characters may be escaped by \f(CW\*(C`\e\*(C'\fR (backslash), whitespace is retained. -Empty values are permitted but are ignored for the search. That is, -a search with an empty value will have the same effect as not specifying -the type at all. -Giving a single \f(CW\*(C`/\*(C'\fR will lead to an empty sequence of RDNs (a NULL-DN). -Multi-valued RDNs can be formed by placing a \f(CW\*(C`+\*(C'\fR character instead of a \f(CW\*(C`/\*(C'\fR -between the AttributeValueAssertions (AVAs) that specify the members of the set. -.Sp -Example: -.Sp -\&\f(CW\*(C`/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe\*(C'\fR -.IP "\fB\-issuer\fR \fIarg\fR" 4 -.IX Item "-issuer arg" -.PD 0 -.IP "\fB\-serial\fR \fIarg\fR" 4 -.IX Item "-serial arg" -.PD -Search for an object having the given issuer name and serial number. -These two options \fImust\fR be used together. -The issuer arg must be formatted as \f(CW\*(C`/type0=value0/type1=value1/type2=...\*(C'\fR, -characters may be escaped by \e (backslash), no spaces are skipped. -The serial arg may be specified as a decimal value or a hex value if preceded -by \f(CW\*(C`0x\*(C'\fR. -.IP "\fB\-alias\fR \fIarg\fR" 4 -.IX Item "-alias arg" -Search for an object having the given alias. -.IP "\fB\-fingerprint\fR \fIarg\fR" 4 -.IX Item "-fingerprint arg" -Search for an object having the given fingerprint. -.IP "\fB\-\f(BIdigest\fB\fR" 4 -.IX Item "-digest" -The digest that was used to compute the fingerprint given with \fB\-fingerprint\fR. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -This command was added in OpenSSL 1.1.1. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-ts.1ossl b/openssl-install/share/man/man1/openssl-ts.1ossl deleted file mode 100644 index 8372dee1..00000000 --- a/openssl-install/share/man/man1/openssl-ts.1ossl +++ /dev/null @@ -1,766 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-TS 1ossl" -.TH OPENSSL-TS 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-ts \- Time Stamping Authority command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBts\fR -\&\fB\-help\fR -.PP -\&\fBopenssl\fR \fBts\fR -\&\fB\-query\fR -[\fB\-config\fR \fIconfigfile\fR] -[\fB\-data\fR \fIfile_to_hash\fR] -[\fB\-digest\fR \fIdigest_bytes\fR] -[\fB\-\f(BIdigest\fB\fR] -[\fB\-tspolicy\fR \fIobject_id\fR] -[\fB\-no_nonce\fR] -[\fB\-cert\fR] -[\fB\-in\fR \fIrequest.tsq\fR] -[\fB\-out\fR \fIrequest.tsq\fR] -[\fB\-text\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.PP -\&\fBopenssl\fR \fBts\fR -\&\fB\-reply\fR -[\fB\-config\fR \fIconfigfile\fR] -[\fB\-section\fR \fItsa_section\fR] -[\fB\-queryfile\fR \fIrequest.tsq\fR] -[\fB\-passin\fR \fIpassword_src\fR] -[\fB\-signer\fR \fItsa_cert.pem\fR] -[\fB\-inkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-\f(BIdigest\fB\fR] -[\fB\-chain\fR \fIcerts_file.pem\fR] -[\fB\-tspolicy\fR \fIobject_id\fR] -[\fB\-in\fR \fIresponse.tsr\fR] -[\fB\-token_in\fR] -[\fB\-out\fR \fIresponse.tsr\fR] -[\fB\-token_out\fR] -[\fB\-text\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.PP -\&\fBopenssl\fR \fBts\fR -\&\fB\-verify\fR -[\fB\-data\fR \fIfile_to_hash\fR] -[\fB\-digest\fR \fIdigest_bytes\fR] -[\fB\-queryfile\fR \fIrequest.tsq\fR] -[\fB\-in\fR \fIresponse.tsr\fR] -[\fB\-token_in\fR] -[\fB\-untrusted\fR \fIfiles\fR|\fIuris\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is a basic Time Stamping Authority (\s-1TSA\s0) client and -server application as specified in \s-1RFC 3161\s0 (Time-Stamp Protocol, \s-1TSP\s0). A -\&\s-1TSA\s0 can be part of a \s-1PKI\s0 deployment and its role is to provide long -term proof of the existence of a certain datum before a particular -time. Here is a brief description of the protocol: -.IP "1." 4 -The \s-1TSA\s0 client computes a one-way hash value for a data file and sends -the hash to the \s-1TSA.\s0 -.IP "2." 4 -The \s-1TSA\s0 attaches the current date and time to the received hash value, -signs them and sends the timestamp token back to the client. By -creating this token the \s-1TSA\s0 certifies the existence of the original -data file at the time of response generation. -.IP "3." 4 -The \s-1TSA\s0 client receives the timestamp token and verifies the -signature on it. It also checks if the token contains the same hash -value that it had sent to the \s-1TSA.\s0 -.PP -There is one \s-1DER\s0 encoded protocol data unit defined for transporting a -timestamp request to the \s-1TSA\s0 and one for sending the timestamp response -back to the client. This command has three main functions: -creating a timestamp request based on a data file, -creating a timestamp response based on a request, verifying if a -response corresponds to a particular request or a data file. -.PP -There is no support for sending the requests/responses automatically -over \s-1HTTP\s0 or \s-1TCP\s0 yet as suggested in \s-1RFC 3161.\s0 The users must send the -requests either by ftp or e\-mail. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-query\fR" 4 -.IX Item "-query" -Generate a \s-1TS\s0 query. For details see \*(L"Timestamp Request generation\*(R". -.IP "\fB\-reply\fR" 4 -.IX Item "-reply" -Generate a \s-1TS\s0 reply. For details see \*(L"Timestamp Response generation\*(R". -.IP "\fB\-verify\fR" 4 -.IX Item "-verify" -Verify a \s-1TS\s0 response. For details see \*(L"Timestamp Response verification\*(R". -.SS "Timestamp Request generation" -.IX Subsection "Timestamp Request generation" -The \fB\-query\fR command can be used for creating and printing a timestamp -request with the following options: -.IP "\fB\-config\fR \fIconfigfile\fR" 4 -.IX Item "-config configfile" -The configuration file to use. -Optional; for a description of the default value, -see \*(L"\s-1COMMAND SUMMARY\*(R"\s0 in \fBopenssl\fR\|(1). -.IP "\fB\-data\fR \fIfile_to_hash\fR" 4 -.IX Item "-data file_to_hash" -The data file for which the timestamp request needs to be -created. stdin is the default if neither the \fB\-data\fR nor the \fB\-digest\fR -parameter is specified. (Optional) -.IP "\fB\-digest\fR \fIdigest_bytes\fR" 4 -.IX Item "-digest digest_bytes" -It is possible to specify the message imprint explicitly without the data -file. The imprint must be specified in a hexadecimal format, two characters -per byte, the bytes optionally separated by colons (e.g. 1A:F6:01:... or -1AF601...). The number of bytes must match the message digest algorithm -in use. (Optional) -.IP "\fB\-\f(BIdigest\fB\fR" 4 -.IX Item "-digest" -The message digest to apply to the data file. -Any digest supported by the \fBopenssl\-dgst\fR\|(1) command can be used. -The default is \s-1SHA\-256.\s0 (Optional) -.IP "\fB\-tspolicy\fR \fIobject_id\fR" 4 -.IX Item "-tspolicy object_id" -The policy that the client expects the \s-1TSA\s0 to use for creating the -timestamp token. Either the dotted \s-1OID\s0 notation or \s-1OID\s0 names defined -in the config file can be used. If no policy is requested the \s-1TSA\s0 will -use its own default policy. (Optional) -.IP "\fB\-no_nonce\fR" 4 -.IX Item "-no_nonce" -No nonce is specified in the request if this option is -given. Otherwise, a 64\-bit long pseudo-random nonce is -included in the request. It is recommended to use a nonce to -protect against replay attacks. (Optional) -.IP "\fB\-cert\fR" 4 -.IX Item "-cert" -The \s-1TSA\s0 is expected to include its signing certificate in the -response. (Optional) -.IP "\fB\-in\fR \fIrequest.tsq\fR" 4 -.IX Item "-in request.tsq" -This option specifies a previously created timestamp request in \s-1DER\s0 -format that will be printed into the output file. Useful when you need -to examine the content of a request in human-readable -format. (Optional) -.IP "\fB\-out\fR \fIrequest.tsq\fR" 4 -.IX Item "-out request.tsq" -Name of the output file to which the request will be written. Default -is stdout. (Optional) -.IP "\fB\-text\fR" 4 -.IX Item "-text" -If this option is specified the output is human-readable text format -instead of \s-1DER.\s0 (Optional) -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.SS "Timestamp Response generation" -.IX Subsection "Timestamp Response generation" -A timestamp response (TimeStampResp) consists of a response status -and the timestamp token itself (ContentInfo), if the token generation was -successful. The \fB\-reply\fR command is for creating a timestamp -response or timestamp token based on a request and printing the -response/token in human-readable format. If \fB\-token_out\fR is not -specified the output is always a timestamp response (TimeStampResp), -otherwise it is a timestamp token (ContentInfo). -.IP "\fB\-config\fR \fIconfigfile\fR" 4 -.IX Item "-config configfile" -The configuration file to use. -Optional; for a description of the default value, -see \*(L"\s-1COMMAND SUMMARY\*(R"\s0 in \fBopenssl\fR\|(1). -See \*(L"\s-1CONFIGURATION FILE OPTIONS\*(R"\s0 for configurable variables. -.IP "\fB\-section\fR \fItsa_section\fR" 4 -.IX Item "-section tsa_section" -The name of the config file section containing the settings for the -response generation. If not specified the default \s-1TSA\s0 section is -used, see \*(L"\s-1CONFIGURATION FILE OPTIONS\*(R"\s0 for details. (Optional) -.IP "\fB\-queryfile\fR \fIrequest.tsq\fR" 4 -.IX Item "-queryfile request.tsq" -The name of the file containing a \s-1DER\s0 encoded timestamp request. (Optional) -.IP "\fB\-passin\fR \fIpassword_src\fR" 4 -.IX Item "-passin password_src" -Specifies the password source for the private key of the \s-1TSA.\s0 See -description in \fBopenssl\fR\|(1). (Optional) -.IP "\fB\-signer\fR \fItsa_cert.pem\fR" 4 -.IX Item "-signer tsa_cert.pem" -The signer certificate of the \s-1TSA\s0 in \s-1PEM\s0 format. The \s-1TSA\s0 signing -certificate must have exactly one extended key usage assigned to it: -timeStamping. The extended key usage must also be critical, otherwise -the certificate is going to be refused. Overrides the \fBsigner_cert\fR -variable of the config file. (Optional) -.IP "\fB\-inkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-inkey filename|uri" -The signer private key of the \s-1TSA\s0 in \s-1PEM\s0 format. Overrides the -\&\fBsigner_key\fR config file option. (Optional) -.IP "\fB\-\f(BIdigest\fB\fR" 4 -.IX Item "-digest" -Signing digest to use. Overrides the \fBsigner_digest\fR config file -option. (Mandatory unless specified in the config file) -.IP "\fB\-chain\fR \fIcerts_file.pem\fR" 4 -.IX Item "-chain certs_file.pem" -The collection of certificates in \s-1PEM\s0 format that will all -be included in the response in addition to the signer certificate if -the \fB\-cert\fR option was used for the request. This file is supposed to -contain the certificate chain for the signer certificate from its -issuer upwards. The \fB\-reply\fR command does not build a certificate -chain automatically. (Optional) -.IP "\fB\-tspolicy\fR \fIobject_id\fR" 4 -.IX Item "-tspolicy object_id" -The default policy to use for the response unless the client -explicitly requires a particular \s-1TSA\s0 policy. The \s-1OID\s0 can be specified -either in dotted notation or with its name. Overrides the -\&\fBdefault_policy\fR config file option. (Optional) -.IP "\fB\-in\fR \fIresponse.tsr\fR" 4 -.IX Item "-in response.tsr" -Specifies a previously created timestamp response or timestamp token -(if \fB\-token_in\fR is also specified) in \s-1DER\s0 format that will be written -to the output file. This option does not require a request, it is -useful e.g. when you need to examine the content of a response or -token or you want to extract the timestamp token from a response. If -the input is a token and the output is a timestamp response a default -\&'granted' status info is added to the token. (Optional) -.IP "\fB\-token_in\fR" 4 -.IX Item "-token_in" -This flag can be used together with the \fB\-in\fR option and indicates -that the input is a \s-1DER\s0 encoded timestamp token (ContentInfo) instead -of a timestamp response (TimeStampResp). (Optional) -.IP "\fB\-out\fR \fIresponse.tsr\fR" 4 -.IX Item "-out response.tsr" -The response is written to this file. The format and content of the -file depends on other options (see \fB\-text\fR, \fB\-token_out\fR). The default is -stdout. (Optional) -.IP "\fB\-token_out\fR" 4 -.IX Item "-token_out" -The output is a timestamp token (ContentInfo) instead of timestamp -response (TimeStampResp). (Optional) -.IP "\fB\-text\fR" 4 -.IX Item "-text" -If this option is specified the output is human-readable text format -instead of \s-1DER.\s0 (Optional) -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SS "Timestamp Response verification" -.IX Subsection "Timestamp Response verification" -The \fB\-verify\fR command is for verifying if a timestamp response or -timestamp token is valid and matches a particular timestamp request or -data file. The \fB\-verify\fR command does not use the configuration file. -.IP "\fB\-data\fR \fIfile_to_hash\fR" 4 -.IX Item "-data file_to_hash" -The response or token must be verified against file_to_hash. The file -is hashed with the message digest algorithm specified in the token. -The \fB\-digest\fR and \fB\-queryfile\fR options must not be specified with this one. -(Optional) -.IP "\fB\-digest\fR \fIdigest_bytes\fR" 4 -.IX Item "-digest digest_bytes" -The response or token must be verified against the message digest specified -with this option. The number of bytes must match the message digest algorithm -specified in the token. The \fB\-data\fR and \fB\-queryfile\fR options must not be -specified with this one. (Optional) -.IP "\fB\-queryfile\fR \fIrequest.tsq\fR" 4 -.IX Item "-queryfile request.tsq" -The original timestamp request in \s-1DER\s0 format. The \fB\-data\fR and \fB\-digest\fR -options must not be specified with this one. (Optional) -.IP "\fB\-in\fR \fIresponse.tsr\fR" 4 -.IX Item "-in response.tsr" -The timestamp response that needs to be verified in \s-1DER\s0 format. (Mandatory) -.IP "\fB\-token_in\fR" 4 -.IX Item "-token_in" -This flag can be used together with the \fB\-in\fR option and indicates -that the input is a \s-1DER\s0 encoded timestamp token (ContentInfo) instead -of a timestamp response (TimeStampResp). (Optional) -.IP "\fB\-untrusted\fR \fIfiles\fR|\fIuris\fR" 4 -.IX Item "-untrusted files|uris" -A set of additional untrusted certificates which may be -needed when building the certificate chain for the \s-1TSA\s0's signing certificate. -These do not need to contain the \s-1TSA\s0 signing certificate and intermediate \s-1CA\s0 -certificates as far as the response already includes them. -(Optional) -.Sp -Multiple sources may be given, separated by commas and/or whitespace. -Each file may contain multiple certificates. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-CAstore\fR \fIuri\fR" 4 -.IX Item "-CAfile file, -CApath dir, -CAstore uri" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -At least one of \fB\-CAfile\fR, \fB\-CApath\fR or \fB\-CAstore\fR must be specified. -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.Sp -Any verification errors cause the command to exit. -.SH "CONFIGURATION FILE OPTIONS" -.IX Header "CONFIGURATION FILE OPTIONS" -The \fB\-query\fR and \fB\-reply\fR commands make use of a configuration file. -See \fBconfig\fR\|(5) -for a general description of the syntax of the config file. The -\&\fB\-query\fR command uses only the symbolic \s-1OID\s0 names section -and it can work without it. However, the \fB\-reply\fR command needs the -config file for its operation. -.PP -When there is a command line switch equivalent of a variable the -switch always overrides the settings in the config file. -.IP "\fBtsa\fR section, \fBdefault_tsa\fR" 4 -.IX Item "tsa section, default_tsa" -This is the main section and it specifies the name of another section -that contains all the options for the \fB\-reply\fR command. This default -section can be overridden with the \fB\-section\fR command line switch. (Optional) -.IP "\fBoid_file\fR" 4 -.IX Item "oid_file" -This specifies a file containing additional \fB\s-1OBJECT IDENTIFIERS\s0\fR. -Each line of the file should consist of the numerical form of the -object identifier followed by whitespace then the short name followed -by whitespace and finally the long name. (Optional) -.IP "\fBoid_section\fR" 4 -.IX Item "oid_section" -This specifies a section in the configuration file containing extra -object identifiers. Each line should consist of the short name of the -object identifier followed by \fB=\fR and the numerical form. The short -and long names are the same when this option is used. (Optional) -.IP "\fB\s-1RANDFILE\s0\fR" 4 -.IX Item "RANDFILE" -At startup the specified file is loaded into the random number generator, -and at exit 256 bytes will be written to it. (Note: Using a \s-1RANDFILE\s0 is -not necessary anymore, see the \*(L"\s-1HISTORY\*(R"\s0 section. -.IP "\fBserial\fR" 4 -.IX Item "serial" -The name of the file containing the hexadecimal serial number of the -last timestamp response created. This number is incremented by 1 for -each response. If the file does not exist at the time of response -generation a new file is created with serial number 1. (Mandatory) -.IP "\fBcrypto_device\fR" 4 -.IX Item "crypto_device" -Specifies the OpenSSL engine that will be set as the default for -all available algorithms. The default value is built-in, you can specify -any other engines supported by OpenSSL (e.g. use chil for the NCipher \s-1HSM\s0). -(Optional) -.IP "\fBsigner_cert\fR" 4 -.IX Item "signer_cert" -\&\s-1TSA\s0 signing certificate in \s-1PEM\s0 format. The same as the \fB\-signer\fR -command line option. (Optional) -.IP "\fBcerts\fR" 4 -.IX Item "certs" -A file containing a set of \s-1PEM\s0 encoded certificates that need to be -included in the response. The same as the \fB\-chain\fR command line -option. (Optional) -.IP "\fBsigner_key\fR" 4 -.IX Item "signer_key" -The private key of the \s-1TSA\s0 in \s-1PEM\s0 format. The same as the \fB\-inkey\fR -command line option. (Optional) -.IP "\fBsigner_digest\fR" 4 -.IX Item "signer_digest" -Signing digest to use. The same as the -\&\fB\-\f(BIdigest\fB\fR command line option. (Mandatory unless specified on the command -line) -.IP "\fBdefault_policy\fR" 4 -.IX Item "default_policy" -The default policy to use when the request does not mandate any -policy. The same as the \fB\-tspolicy\fR command line option. (Optional) -.IP "\fBother_policies\fR" 4 -.IX Item "other_policies" -Comma separated list of policies that are also acceptable by the \s-1TSA\s0 -and used only if the request explicitly specifies one of them. (Optional) -.IP "\fBdigests\fR" 4 -.IX Item "digests" -The list of message digest algorithms that the \s-1TSA\s0 accepts. At least -one algorithm must be specified. (Mandatory) -.IP "\fBaccuracy\fR" 4 -.IX Item "accuracy" -The accuracy of the time source of the \s-1TSA\s0 in seconds, milliseconds -and microseconds. E.g. secs:1, millisecs:500, microsecs:100. If any of -the components is missing zero is assumed for that field. (Optional) -.IP "\fBclock_precision_digits\fR" 4 -.IX Item "clock_precision_digits" -Specifies the maximum number of digits, which represent the fraction of -seconds, that need to be included in the time field. The trailing zeros -must be removed from the time, so there might actually be fewer digits, -or no fraction of seconds at all. Supported only on \s-1UNIX\s0 platforms. -The maximum value is 6, default is 0. -(Optional) -.IP "\fBordering\fR" 4 -.IX Item "ordering" -If this option is yes the responses generated by this \s-1TSA\s0 can always -be ordered, even if the time difference between two responses is less -than the sum of their accuracies. Default is no. (Optional) -.IP "\fBtsa_name\fR" 4 -.IX Item "tsa_name" -Set this option to yes if the subject name of the \s-1TSA\s0 must be included in -the \s-1TSA\s0 name field of the response. Default is no. (Optional) -.IP "\fBess_cert_id_chain\fR" 4 -.IX Item "ess_cert_id_chain" -The SignedData objects created by the \s-1TSA\s0 always contain the -certificate identifier of the signing certificate in a signed -attribute (see \s-1RFC 2634,\s0 Enhanced Security Services). -If this variable is set to no, only this signing certificate identifier -is included in the SigningCertificate signed attribute. -If this variable is set to yes and the \fBcerts\fR variable or the \fB\-chain\fR option -is specified then the certificate identifiers of the chain will also -be included, where the \fB\-chain\fR option overrides the \fBcerts\fR variable. -Default is no. (Optional) -.IP "\fBess_cert_id_alg\fR" 4 -.IX Item "ess_cert_id_alg" -This option specifies the hash function to be used to calculate the \s-1TSA\s0's -public key certificate identifier. Default is sha256. (Optional) -.SH "EXAMPLES" -.IX Header "EXAMPLES" -All the examples below presume that \fB\s-1OPENSSL_CONF\s0\fR is set to a proper -configuration file, e.g. the example configuration file -\&\fIopenssl/apps/openssl.cnf\fR will do. -.SS "Timestamp Request" -.IX Subsection "Timestamp Request" -To create a timestamp request for \fIdesign1.txt\fR with \s-1SHA\-256\s0 digest, -without nonce and policy, and without requirement for a certificate -in the response: -.PP -.Vb 2 -\& openssl ts \-query \-data design1.txt \-no_nonce \e -\& \-out design1.tsq -.Ve -.PP -To create a similar timestamp request with specifying the message imprint -explicitly: -.PP -.Vb 2 -\& openssl ts \-query \-digest b7e5d3f93198b38379852f2c04e78d73abdd0f4b \e -\& \-no_nonce \-out design1.tsq -.Ve -.PP -To print the content of the previous request in human readable format: -.PP -.Vb 1 -\& openssl ts \-query \-in design1.tsq \-text -.Ve -.PP -To create a timestamp request which includes the \s-1SHA\-512\s0 digest -of \fIdesign2.txt\fR, requests the signer certificate and nonce, and -specifies a policy id (assuming the tsa_policy1 name is defined in the -\&\s-1OID\s0 section of the config file): -.PP -.Vb 2 -\& openssl ts \-query \-data design2.txt \-sha512 \e -\& \-tspolicy tsa_policy1 \-cert \-out design2.tsq -.Ve -.SS "Timestamp Response" -.IX Subsection "Timestamp Response" -Before generating a response a signing certificate must be created for -the \s-1TSA\s0 that contains the \fBtimeStamping\fR critical extended key usage extension -without any other key usage extensions. You can add this line to the -user certificate section of the config file to generate a proper certificate; -.PP -.Vb 1 -\& extendedKeyUsage = critical,timeStamping -.Ve -.PP -See \fBopenssl\-req\fR\|(1), \fBopenssl\-ca\fR\|(1), and \fBopenssl\-x509\fR\|(1) for -instructions. The examples below assume that \fIcacert.pem\fR contains the -certificate of the \s-1CA,\s0 \fItsacert.pem\fR is the signing certificate issued -by \fIcacert.pem\fR and \fItsakey.pem\fR is the private key of the \s-1TSA.\s0 -.PP -To create a timestamp response for a request: -.PP -.Vb 2 -\& openssl ts \-reply \-queryfile design1.tsq \-inkey tsakey.pem \e -\& \-signer tsacert.pem \-out design1.tsr -.Ve -.PP -If you want to use the settings in the config file you could just write: -.PP -.Vb 1 -\& openssl ts \-reply \-queryfile design1.tsq \-out design1.tsr -.Ve -.PP -To print a timestamp reply to stdout in human readable format: -.PP -.Vb 1 -\& openssl ts \-reply \-in design1.tsr \-text -.Ve -.PP -To create a timestamp token instead of timestamp response: -.PP -.Vb 1 -\& openssl ts \-reply \-queryfile design1.tsq \-out design1_token.der \-token_out -.Ve -.PP -To print a timestamp token to stdout in human readable format: -.PP -.Vb 1 -\& openssl ts \-reply \-in design1_token.der \-token_in \-text \-token_out -.Ve -.PP -To extract the timestamp token from a response: -.PP -.Vb 1 -\& openssl ts \-reply \-in design1.tsr \-out design1_token.der \-token_out -.Ve -.PP -To add 'granted' status info to a timestamp token thereby creating a -valid response: -.PP -.Vb 1 -\& openssl ts \-reply \-in design1_token.der \-token_in \-out design1.tsr -.Ve -.SS "Timestamp Verification" -.IX Subsection "Timestamp Verification" -To verify a timestamp reply against a request: -.PP -.Vb 2 -\& openssl ts \-verify \-queryfile design1.tsq \-in design1.tsr \e -\& \-CAfile cacert.pem \-untrusted tsacert.pem -.Ve -.PP -To verify a timestamp reply that includes the certificate chain: -.PP -.Vb 2 -\& openssl ts \-verify \-queryfile design2.tsq \-in design2.tsr \e -\& \-CAfile cacert.pem -.Ve -.PP -To verify a timestamp token against the original data file: -.PP -.Vb 2 -\& openssl ts \-verify \-data design2.txt \-in design2.tsr \e -\& \-CAfile cacert.pem -.Ve -.PP -To verify a timestamp token against a message imprint: -.PP -.Vb 2 -\& openssl ts \-verify \-digest b7e5d3f93198b38379852f2c04e78d73abdd0f4b \e -\& \-in design2.tsr \-CAfile cacert.pem -.Ve -.PP -You could also look at the 'test' directory for more examples. -.SH "BUGS" -.IX Header "BUGS" -.IP "\(bu" 2 -No support for timestamps over \s-1SMTP,\s0 though it is quite easy -to implement an automatic e\-mail based \s-1TSA\s0 with \fBprocmail\fR\|(1) -and \fBperl\fR\|(1). \s-1HTTP\s0 server support is provided in the form of -a separate apache module. \s-1HTTP\s0 client support is provided by -\&\fBtsget\fR\|(1). Pure \s-1TCP/IP\s0 protocol is not supported. -.IP "\(bu" 2 -The file containing the last serial number of the \s-1TSA\s0 is not -locked when being read or written. This is a problem if more than one -instance of \fBopenssl\fR\|(1) is trying to create a timestamp -response at the same time. This is not an issue when using the apache -server module, it does proper locking. -.IP "\(bu" 2 -Look for the \s-1FIXME\s0 word in the source files. -.IP "\(bu" 2 -The source code should really be reviewed by somebody else, too. -.IP "\(bu" 2 -More testing is needed, I have done only some basic tests (see -test/testtsa). -.SH "HISTORY" -.IX Header "HISTORY" -OpenSSL 1.1.1 introduced a new random generator (\s-1CSPRNG\s0) with an improved -seeding mechanism. The new seeding mechanism makes it unnecessary to -define a \s-1RANDFILE\s0 for saving and restoring randomness. This option is -retained mainly for compatibility reasons. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBtsget\fR\|(1), -\&\fBopenssl\-req\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -\&\fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBconfig\fR\|(5), -\&\fBossl_store\-file\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-verification-options.1ossl b/openssl-install/share/man/man1/openssl-verification-options.1ossl deleted file mode 100644 index 87101cb0..00000000 --- a/openssl-install/share/man/man1/openssl-verification-options.1ossl +++ /dev/null @@ -1,768 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-VERIFICATION-OPTIONS 1ossl" -.TH OPENSSL-VERIFICATION-OPTIONS 1ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-verification\-options \- generic X.509 certificate verification options -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR -\&\fIcommand\fR -[ \fIoptions\fR ... ] -[ \fIparameters\fR ... ] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -There are many situations where X.509 certificates are verified -within the OpenSSL libraries and in various OpenSSL commands. -.PP -Certificate verification is implemented by \fBX509_verify_cert\fR\|(3). -It is a complicated process consisting of a number of steps -and depending on numerous options. -The most important of them are detailed in the following sections. -.PP -In a nutshell, a valid chain of certificates needs to be built up and verified -starting from the \fItarget certificate\fR that is to be verified -and ending in a certificate that due to some policy is trusted. -Certificate validation can be performed in the context of a \fIpurpose\fR, which -is a high-level specification of the intended use of the target certificate, -such as \f(CW\*(C`sslserver\*(C'\fR for \s-1TLS\s0 servers, or (by default) for any purpose. -.PP -The details of how each OpenSSL command handles errors -are documented on the specific command page. -.PP -\&\s-1DANE\s0 support is documented in \fBopenssl\-s_client\fR\|(1), -\&\fBSSL_CTX_dane_enable\fR\|(3), \fBSSL_set1_host\fR\|(3), -\&\fBX509_VERIFY_PARAM_set_flags\fR\|(3), and \fBX509_check_host\fR\|(3). -.SS "Trust Anchors" -.IX Subsection "Trust Anchors" -In general, according to \s-1RFC 4158\s0 and \s-1RFC 5280,\s0 a \fItrust anchor\fR is -any public key and related subject distinguished name (\s-1DN\s0) that -for some reason is considered trusted -and thus is acceptable as the root of a chain of certificates. -.PP -In practice, trust anchors are given in the form of certificates, -where their essential fields are the public key and the subject \s-1DN.\s0 -In addition to the requirements in \s-1RFC 5280,\s0 -OpenSSL checks the validity period of such certificates -and makes use of some further fields. -In particular, the subject key identifier extension, if present, -is used for matching trust anchors during chain building. -.PP -In the most simple and common case, trust anchors are by default -all self-signed \*(L"root\*(R" \s-1CA\s0 certificates that are placed in the \fItrust store\fR, -which is a collection of certificates that are trusted for certain uses. -This is akin to what is used in the trust stores of Mozilla Firefox, -or Apple's and Microsoft's certificate stores, ... -.PP -From the OpenSSL perspective, a trust anchor is a certificate -that should be augmented with an explicit designation for which -uses of a target certificate the certificate may serve as a trust anchor. -In \s-1PEM\s0 encoding, this is indicated by the \f(CW\*(C`TRUSTED CERTIFICATE\*(C'\fR string. -Such a designation provides a set of positive trust attributes -explicitly stating trust for the listed purposes -and/or a set of negative trust attributes -explicitly rejecting the use for the listed purposes. -The purposes are encoded using the values defined for the extended key usages -(EKUs) that may be given in X.509 extensions of end-entity certificates. -See also the \*(L"Extended Key Usage\*(R" section below. -.PP -The currently recognized uses are -\&\fBclientAuth\fR (\s-1SSL\s0 client use), \fBserverAuth\fR (\s-1SSL\s0 server use), -\&\fBemailProtection\fR (S/MIME email use), \fBcodeSigning\fR (object signer use), -\&\fBOCSPSigning\fR (\s-1OCSP\s0 responder use), \fB\s-1OCSP\s0\fR (\s-1OCSP\s0 request use), -\&\fBtimeStamping\fR (\s-1TSA\s0 server use), and \fBanyExtendedKeyUsage\fR. -As of OpenSSL 1.1.0, the last of these blocks all uses when rejected or -enables all uses when trusted. -.PP -A certificate, which may be \s-1CA\s0 certificate or an end-entity certificate, -is considered a trust anchor for the given use -if and only if all the following conditions hold: -.IP "\(bu" 4 -It is an an element of the trust store. -.IP "\(bu" 4 -It does not have a negative trust attribute rejecting the given use. -.IP "\(bu" 4 -It has a positive trust attribute accepting the given use -or (by default) one of the following compatibility conditions apply: -It is self-signed or the \fB\-partial_chain\fR option is given -(which corresponds to the \fBX509_V_FLAG_PARTIAL_CHAIN\fR flag being set). -.SS "Certification Path Building" -.IX Subsection "Certification Path Building" -First, a certificate chain is built up starting from the target certificate -and ending in a trust anchor. -.PP -The chain is built up iteratively, looking up in turn -a certificate with suitable key usage that -matches as an issuer of the current \*(L"subject\*(R" certificate as described below. -If there is such a certificate, the first one found that is currently valid -is taken, otherwise the one that expired most recently of all such certificates. -For efficiency, no backtracking is performed, thus -any further candidate issuer certificates that would match equally are ignored. -.PP -When a self-signed certificate has been added, chain construction stops. -In this case it must fully match a trust anchor, otherwise chain building fails. -.PP -A candidate issuer certificate matches a subject certificate -if all of the following conditions hold: -.IP "\(bu" 4 -Its subject name matches the issuer name of the subject certificate. -.IP "\(bu" 4 -If the subject certificate has an authority key identifier extension, -each of its sub-fields equals the corresponding subject key identifier, serial -number, and issuer field of the candidate issuer certificate, -as far as the respective fields are present in both certificates. -.IP "\(bu" 4 -The certificate signature algorithm used to sign the subject certificate -is supported and -equals the public key algorithm of the candidate issuer certificate. -.PP -The lookup first searches for issuer certificates in the trust store. -If it does not find a match there it consults -the list of untrusted (\*(L"intermediate\*(R" \s-1CA\s0) certificates, if provided. -.SS "Certification Path Validation" -.IX Subsection "Certification Path Validation" -When the certificate chain building process was successful -the chain components and their links are checked thoroughly. -.PP -The first step is to check that each certificate is well-formed. -Part of these checks are enabled only if the \fB\-x509_strict\fR option is given. -.PP -The second step is to check the X.509v3 extensions of every certificate -for consistency with the intended specific purpose, if any. -If the \fB\-purpose\fR option is not given then no such checks are done except for -\&\s-1CMS\s0 signature checking, where by default \f(CW\*(C`smimesign\*(C'\fR is checked, and \s-1SSL/\s0(D)TLS -connection setup, where by default \f(CW\*(C`sslserver\*(C'\fR or \f(CW\*(C`sslclient\*(C'\fR are checked. -The X.509v3 extensions of the target or \*(L"leaf\*(R" certificate -must be compatible with the specified purpose. -All other certificates down the chain are checked to be valid \s-1CA\s0 certificates, -and possibly also further non-standard checks are performed. -The precise extensions required are described in detail -in the \*(L"Certificate Extensions\*(R" section below. -.PP -The third step is to check the trust settings on the last certificate -(which typically is a self-signed root \s-1CA\s0 certificate). -It must be trusted for the given use. -For compatibility with previous versions of OpenSSL, a self-signed certificate -with no trust attributes is considered to be valid for all uses. -.PP -The fourth, and final, step is to check the validity of the certificate chain. -For each element in the chain, including the root \s-1CA\s0 certificate, -the validity period as specified by the \f(CW\*(C`notBefore\*(C'\fR and \f(CW\*(C`notAfter\*(C'\fR fields -is checked against the current system time. -The \fB\-attime\fR flag may be used to use a reference time other than \*(L"now.\*(R" -The certificate signature is checked as well -(except for the signature of the typically self-signed root \s-1CA\s0 certificate, -which is verified only if the \fB\-check_ss_sig\fR option is given). -When verifying a certificate signature -the keyUsage extension (if present) of the candidate issuer certificate -is checked to permit digitalSignature for signing proxy certificates -or to permit keyCertSign for signing other certificates, respectively. -If all operations complete successfully then certificate is considered -valid. If any operation fails then the certificate is not valid. -.SH "OPTIONS" -.IX Header "OPTIONS" -.SS "Trusted Certificate Options" -.IX Subsection "Trusted Certificate Options" -The following options specify how to supply the certificates -that can be used as trust anchors for certain uses. -As mentioned, a collection of such certificates is called a \fItrust store\fR. -.PP -Note that OpenSSL does not provide a default set of trust anchors. Many -Linux distributions include a system default and configure OpenSSL to point -to that. Mozilla maintains an influential trust store that can be found at -. -.PP -The certificates to add to the trust store -can be specified using following options. -.IP "\fB\-CAfile\fR \fIfile\fR" 4 -.IX Item "-CAfile file" -Load the specified file which contains a trusted certificate in \s-1DER\s0 format -or potentially several of them in case the input is in \s-1PEM\s0 format. -PEM-encoded certificates may also have trust attributes set. -.IP "\fB\-no\-CAfile\fR" 4 -.IX Item "-no-CAfile" -Do not load the default file of trusted certificates. -.IP "\fB\-CApath\fR \fIdir\fR" 4 -.IX Item "-CApath dir" -Use the specified directory as a collection of trusted certificates, -i.e., a trust store. -Files should be named with the hash value of the X.509 SubjectName of each -certificate. This is so that the library can extract the IssuerName, -hash it, and directly lookup the file to get the issuer certificate. -See \fBopenssl\-rehash\fR\|(1) for information on creating this type of directory. -.IP "\fB\-no\-CApath\fR" 4 -.IX Item "-no-CApath" -Do not use the default directory of trusted certificates. -.IP "\fB\-CAstore\fR \fIuri\fR" 4 -.IX Item "-CAstore uri" -Use \fIuri\fR as a store of \s-1CA\s0 certificates. -The \s-1URI\s0 may indicate a single certificate, as well as a collection of them. -With URIs in the \f(CW\*(C`file:\*(C'\fR scheme, this acts as \fB\-CAfile\fR or -\&\fB\-CApath\fR, depending on if the \s-1URI\s0 indicates a single file or -directory. -See \fBossl_store\-file\fR\|(7) for more information on the \f(CW\*(C`file:\*(C'\fR scheme. -.Sp -These certificates are also used when building the server certificate -chain (for example with \fBopenssl\-s_server\fR\|(1)) or client certificate -chain (for example with \fBopenssl\-s_time\fR\|(1)). -.IP "\fB\-no\-CAstore\fR" 4 -.IX Item "-no-CAstore" -Do not use the default store of trusted \s-1CA\s0 certificates. -.SS "Verification Options" -.IX Subsection "Verification Options" -The certificate verification can be fine-tuned with the following flags. -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Print extra information about the operations being performed. -.IP "\fB\-attime\fR \fItimestamp\fR" 4 -.IX Item "-attime timestamp" -Perform validation checks using time specified by \fItimestamp\fR and not -current system time. \fItimestamp\fR is the number of seconds since -January 1, 1970 (i.e., the Unix Epoch). -.IP "\fB\-no_check_time\fR" 4 -.IX Item "-no_check_time" -This option suppresses checking the validity period of certificates and CRLs -against the current time. If option \fB\-attime\fR is used to specify -a verification time, the check is not suppressed. -.IP "\fB\-x509_strict\fR" 4 -.IX Item "-x509_strict" -This disables non-compliant workarounds for broken certificates. -Thus errors are thrown on certificates not compliant with \s-1RFC 5280.\s0 -.Sp -When this option is set, -among others, the following certificate well-formedness conditions are checked: -.RS 4 -.IP "\(bu" 4 -The basicConstraints of \s-1CA\s0 certificates must be marked critical. -.IP "\(bu" 4 -\&\s-1CA\s0 certificates must explicitly include the keyUsage extension. -.IP "\(bu" 4 -If a pathlenConstraint is given the key usage keyCertSign must be allowed. -.IP "\(bu" 4 -The pathlenConstraint must not be given for non-CA certificates. -.IP "\(bu" 4 -The issuer name of any certificate must not be empty. -.IP "\(bu" 4 -The subject name of \s-1CA\s0 certs, certs with keyUsage crlSign, and certs -without subjectAlternativeName must not be empty. -.IP "\(bu" 4 -If a subjectAlternativeName extension is given it must not be empty. -.IP "\(bu" 4 -The signatureAlgorithm field and the cert signature must be consistent. -.IP "\(bu" 4 -Any given authorityKeyIdentifier and any given subjectKeyIdentifier -must not be marked critical. -.IP "\(bu" 4 -The authorityKeyIdentifier must be given for X.509v3 certs unless they -are self-signed. -.IP "\(bu" 4 -The subjectKeyIdentifier must be given for all X.509v3 \s-1CA\s0 certs. -.RE -.RS 4 -.RE -.IP "\fB\-ignore_critical\fR" 4 -.IX Item "-ignore_critical" -Normally if an unhandled critical extension is present that is not -supported by OpenSSL the certificate is rejected (as required by \s-1RFC5280\s0). -If this option is set critical extensions are ignored. -.IP "\fB\-issuer_checks\fR" 4 -.IX Item "-issuer_checks" -Ignored. -.IP "\fB\-crl_check\fR" 4 -.IX Item "-crl_check" -Checks end entity certificate validity by attempting to look up a valid \s-1CRL.\s0 -If a valid \s-1CRL\s0 cannot be found an error occurs. -.IP "\fB\-crl_check_all\fR" 4 -.IX Item "-crl_check_all" -Checks the validity of \fBall\fR certificates in the chain by attempting -to look up valid CRLs. -.IP "\fB\-use_deltas\fR" 4 -.IX Item "-use_deltas" -Enable support for delta CRLs. -.IP "\fB\-extended_crl\fR" 4 -.IX Item "-extended_crl" -Enable extended \s-1CRL\s0 features such as indirect CRLs and alternate \s-1CRL\s0 -signing keys. -.IP "\fB\-suiteB_128_only\fR, \fB\-suiteB_128\fR, \fB\-suiteB_192\fR" 4 -.IX Item "-suiteB_128_only, -suiteB_128, -suiteB_192" -Enable the Suite B mode operation at 128 bit Level of Security, 128 bit or -192 bit, or only 192 bit Level of Security respectively. -See \s-1RFC6460\s0 for details. In particular the supported signature algorithms are -reduced to support only \s-1ECDSA\s0 and \s-1SHA256\s0 or \s-1SHA384\s0 and only the elliptic curves -P\-256 and P\-384. -.IP "\fB\-auth_level\fR \fIlevel\fR" 4 -.IX Item "-auth_level level" -Set the certificate chain authentication security level to \fIlevel\fR. -The authentication security level determines the acceptable signature and -public key strength when verifying certificate chains. For a certificate -chain to validate, the public keys of all the certificates must meet the -specified security \fIlevel\fR. The signature algorithm security level is -enforced for all the certificates in the chain except for the chain's -\&\fItrust anchor\fR, which is either directly trusted or validated by means -other than its signature. See \fBSSL_CTX_set_security_level\fR\|(3) for the -definitions of the available levels. The default security level is \-1, -or \*(L"not set\*(R". At security level 0 or lower all algorithms are acceptable. -Security level 1 requires at least 80\-bit\-equivalent security and is broadly -interoperable, though it will, for example, reject \s-1MD5\s0 signatures or \s-1RSA\s0 -keys shorter than 1024 bits. -.IP "\fB\-partial_chain\fR" 4 -.IX Item "-partial_chain" -Allow verification to succeed if an incomplete chain can be built. -That is, a chain ending in a certificate that normally would not be trusted -(because it has no matching positive trust attributes and is not self-signed) -but is an element of the trust store. -This certificate may be self-issued or belong to an intermediate \s-1CA.\s0 -.IP "\fB\-check_ss_sig\fR" 4 -.IX Item "-check_ss_sig" -Verify the signature of -the last certificate in a chain if the certificate is supposedly self-signed. -This is prohibited and will result in an error if it is a non-conforming \s-1CA\s0 -certificate with key usage restrictions not including the keyCertSign bit. -This verification is disabled by default because it doesn't add any security. -.IP "\fB\-allow_proxy_certs\fR" 4 -.IX Item "-allow_proxy_certs" -Allow the verification of proxy certificates. -.IP "\fB\-trusted_first\fR" 4 -.IX Item "-trusted_first" -As of OpenSSL 1.1.0 this option is on by default and cannot be disabled. -.Sp -When constructing the certificate chain, the trusted certificates specified -via \fB\-CAfile\fR, \fB\-CApath\fR, \fB\-CAstore\fR or \fB\-trusted\fR are always used -before any certificates specified via \fB\-untrusted\fR. -.IP "\fB\-no_alt_chains\fR" 4 -.IX Item "-no_alt_chains" -As of OpenSSL 1.1.0, since \fB\-trusted_first\fR always on, this option has no -effect. -.IP "\fB\-trusted\fR \fIfile\fR" 4 -.IX Item "-trusted file" -Parse \fIfile\fR as a set of one or more certificates. -Each of them qualifies as trusted if has a suitable positive trust attribute -or it is self-signed or the \fB\-partial_chain\fR option is specified. -This option implies the \fB\-no\-CAfile\fR, \fB\-no\-CApath\fR, and \fB\-no\-CAstore\fR options -and it cannot be used with the \fB\-CAfile\fR, \fB\-CApath\fR or \fB\-CAstore\fR options, so -only certificates specified using the \fB\-trusted\fR option are trust anchors. -This option may be used multiple times. -.IP "\fB\-untrusted\fR \fIfile\fR" 4 -.IX Item "-untrusted file" -Parse \fIfile\fR as a set of one or more certificates. -All certificates (typically of intermediate CAs) are considered untrusted -and may be used to -construct a certificate chain from the target certificate to a trust anchor. -This option may be used multiple times. -.IP "\fB\-policy\fR \fIarg\fR" 4 -.IX Item "-policy arg" -Enable policy processing and add \fIarg\fR to the user-initial-policy-set (see -\&\s-1RFC5280\s0). The policy \fIarg\fR can be an object name or an \s-1OID\s0 in numeric form. -This argument can appear more than once. -.IP "\fB\-explicit_policy\fR" 4 -.IX Item "-explicit_policy" -Set policy variable require-explicit-policy (see \s-1RFC5280\s0). -.IP "\fB\-policy_check\fR" 4 -.IX Item "-policy_check" -Enables certificate policy processing. -.IP "\fB\-policy_print\fR" 4 -.IX Item "-policy_print" -Print out diagnostics related to policy processing. -.IP "\fB\-inhibit_any\fR" 4 -.IX Item "-inhibit_any" -Set policy variable inhibit-any-policy (see \s-1RFC5280\s0). -.IP "\fB\-inhibit_map\fR" 4 -.IX Item "-inhibit_map" -Set policy variable inhibit-policy-mapping (see \s-1RFC5280\s0). -.IP "\fB\-purpose\fR \fIpurpose\fR" 4 -.IX Item "-purpose purpose" -A high-level specification of the intended use of the target certificate. -Currently predefined purposes are \f(CW\*(C`sslclient\*(C'\fR, \f(CW\*(C`sslserver\*(C'\fR, \f(CW\*(C`nssslserver\*(C'\fR, -\&\f(CW\*(C`smimesign\*(C'\fR, \f(CW\*(C`smimeencrypt\*(C'\fR, \f(CW\*(C`crlsign\*(C'\fR, \f(CW\*(C`ocsphelper\*(C'\fR, \f(CW\*(C`timestampsign\*(C'\fR, -\&\f(CW\*(C`codesign\*(C'\fR and \f(CW\*(C`any\*(C'\fR. -If peer certificate verification is enabled, by default the \s-1TLS\s0 implementation -and thus the commands \fBopenssl\-s_client\fR\|(1) and \fBopenssl\-s_server\fR\|(1) -check for consistency with -\&\s-1TLS\s0 server (\f(CW\*(C`sslserver\*(C'\fR) or \s-1TLS\s0 client use (\f(CW\*(C`sslclient\*(C'\fR), respectively. -By default, \s-1CMS\s0 signature validation, which can be done via \fBopenssl\-cms\fR\|(1), -checks for consistency with S/MIME signing use (\f(CW\*(C`smimesign\*(C'\fR). -.Sp -While \s-1IETF RFC 5280\s0 says that \fBid-kp-serverAuth\fR and \fBid-kp-clientAuth\fR -are only for \s-1WWW\s0 use, in practice they are used for all kinds of \s-1TLS\s0 clients -and servers, and this is what OpenSSL assumes as well. -.IP "\fB\-verify_depth\fR \fInum\fR" 4 -.IX Item "-verify_depth num" -Limit the certificate chain to \fInum\fR intermediate \s-1CA\s0 certificates. -A maximal depth chain can have up to \fInum\fR+2 certificates, since neither the -end-entity certificate nor the trust-anchor certificate count against the -\&\fB\-verify_depth\fR limit. -.IP "\fB\-verify_email\fR \fIemail\fR" 4 -.IX Item "-verify_email email" -Verify if \fIemail\fR matches the email address in Subject Alternative Name or -the email in the subject Distinguished Name. -.IP "\fB\-verify_hostname\fR \fIhostname\fR" 4 -.IX Item "-verify_hostname hostname" -Verify if \fIhostname\fR matches \s-1DNS\s0 name in Subject Alternative Name or -Common Name in the subject certificate. -.IP "\fB\-verify_ip\fR \fIip\fR" 4 -.IX Item "-verify_ip ip" -Verify if \fIip\fR matches the \s-1IP\s0 address in Subject Alternative Name of -the subject certificate. -.IP "\fB\-verify_name\fR \fIname\fR" 4 -.IX Item "-verify_name name" -Use a set of verification parameters, also known as verification method, -identified by \fIname\fR. The currently predefined methods are named \f(CW\*(C`ssl_client\*(C'\fR, -\&\f(CW\*(C`ssl_server\*(C'\fR, \f(CW\*(C`smime_sign\*(C'\fR with alias \f(CW\*(C`pkcs7\*(C'\fR, \f(CW\*(C`code_sign\*(C'\fR, and \f(CW\*(C`default\*(C'\fR. -These mimic the combinations of purpose and trust settings used in \s-1SSL/\s0(D)TLS, -\&\s-1CMS/PKCS7\s0 (including S/MIME), and code signing. -.Sp -The verification parameters include the trust model, various flags that can -partly be set also via other command-line options, and the verification purpose, -which in turn implies certificate key usage and extended key usage requirements. -.Sp -The trust model determines which auxiliary trust or reject OIDs are applicable -to verifying the given certificate chain. -They can be given using the \fB\-addtrust\fR and \fB\-addreject\fR options -for \fBopenssl\-x509\fR\|(1). -.SS "Extended Verification Options" -.IX Subsection "Extended Verification Options" -Sometimes there may be more than one certificate chain leading to an -end-entity certificate. -This usually happens when a root or intermediate \s-1CA\s0 signs a certificate -for another a \s-1CA\s0 in other organization. -Another reason is when a \s-1CA\s0 might have intermediates that use two different -signature formats, such as a \s-1SHA\-1\s0 and a \s-1SHA\-256\s0 digest. -.PP -The following options can be used to provide data that will allow the -OpenSSL command to generate an alternative chain. -.IP "\fB\-xkey\fR \fIinfile\fR, \fB\-xcert\fR \fIinfile\fR, \fB\-xchain\fR" 4 -.IX Item "-xkey infile, -xcert infile, -xchain" -Specify an extra certificate, private key and certificate chain. These behave -in the same manner as the \fB\-cert\fR, \fB\-key\fR and \fB\-cert_chain\fR options. When -specified, the callback returning the first valid chain will be in use by the -client. -.IP "\fB\-xchain_build\fR" 4 -.IX Item "-xchain_build" -Specify whether the application should build the certificate chain to be -provided to the server for the extra certificates via the \fB\-xkey\fR, -\&\fB\-xcert\fR, and \fB\-xchain\fR options. -.IP "\fB\-xcertform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR" 4 -.IX Item "-xcertform DER|PEM|P12" -The input format for the extra certificate. -This option has no effect and is retained for backward compatibility only. -.IP "\fB\-xkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR" 4 -.IX Item "-xkeyform DER|PEM|P12" -The input format for the extra key. -This option has no effect and is retained for backward compatibility only. -.SS "Certificate Extensions" -.IX Subsection "Certificate Extensions" -Options like \fB\-purpose\fR and \fB\-verify_name\fR trigger the processing of specific -certificate extensions, which determine what certificates can be used for. -.PP -\fIBasic Constraints\fR -.IX Subsection "Basic Constraints" -.PP -The basicConstraints extension \s-1CA\s0 flag is used to determine whether the -certificate can be used as a \s-1CA.\s0 If the \s-1CA\s0 flag is true then it is a \s-1CA,\s0 -if the \s-1CA\s0 flag is false then it is not a \s-1CA.\s0 \fBAll\fR CAs should have the -\&\s-1CA\s0 flag set to true. -.PP -If the basicConstraints extension is absent, -which includes the case that it is an X.509v1 certificate, -then the certificate is considered to be a \*(L"possible \s-1CA\*(R"\s0 and -other extensions are checked according to the intended use of the certificate. -The treatment of certificates without basicConstraints as a \s-1CA\s0 -is presently supported, but this could change in the future. -.PP -\fIKey Usage\fR -.IX Subsection "Key Usage" -.PP -If the keyUsage extension is present then additional restraints are -made on the uses of the certificate. A \s-1CA\s0 certificate \fBmust\fR have the -keyCertSign bit set if the keyUsage extension is present. -.PP -\fIExtended Key Usage\fR -.IX Subsection "Extended Key Usage" -.PP -The extKeyUsage (\s-1EKU\s0) extension places additional restrictions on -certificate use. If this extension is present (whether critical or not) -in an end-entity certficiate, the key is allowed only for the uses specified, -while the special \s-1EKU\s0 \fBanyExtendedKeyUsage\fR allows for all uses. -.PP -Note that according to \s-1RFC 5280\s0 section 4.2.1.12, -the Extended Key Usage extension will appear only in end-entity certificates, -and consequently the standard certification path validation described -in its section 6 does not include \s-1EKU\s0 checks for \s-1CA\s0 certificates. -The CA/Browser Forum requires for \s-1TLS\s0 server, S/MIME, and code signing use -the presence of respective EKUs in subordinate \s-1CA\s0 certificates (while excluding -them for root \s-1CA\s0 certificates), while taking over from \s-1RFC 5280\s0 -the certificate validity concept and certificate path validation. -.PP -For historic reasons, OpenSSL has its own way of interpreting and checking -\&\s-1EKU\s0 extensions on \s-1CA\s0 certificates, which may change in the future. -It does not require the presence of \s-1EKU\s0 extensions in \s-1CA\s0 certificates, -but in case the verification purpose is -\&\f(CW\*(C`sslclient\*(C'\fR, \f(CW\*(C`nssslserver\*(C'\fR, \f(CW\*(C`sslserver\*(C'\fR, \f(CW\*(C`smimesign\*(C'\fR, or \f(CW\*(C`smimeencrypt\*(C'\fR, -it checks that any present \s-1EKU\s0 extension (that does not contain -\&\fBanyExtendedKeyUsage\fR) contains the respective \s-1EKU\s0 as detailed below. -Moreover, it does these checks even for trust anchor certificates. -.PP -\fIChecks Implied by Specific Predefined Policies\fR -.IX Subsection "Checks Implied by Specific Predefined Policies" -.PP -A specific description of each check is given below. The comments about -basicConstraints and keyUsage and X.509v1 certificates above apply to \fBall\fR -\&\s-1CA\s0 certificates. -.ie n .IP "\fB(D)TLS Client\fR (""sslclient"")" 4 -.el .IP "\fB(D)TLS Client\fR (\f(CWsslclient\fR)" 4 -.IX Item "(D)TLS Client (sslclient)" -Any given extended key usage extension must allow for \f(CW\*(C`clientAuth\*(C'\fR -(\*(L"\s-1TLS WWW\s0 client authentication\*(R"). -.Sp -For target certificates, -the key usage must allow for \f(CW\*(C`digitalSignature\*(C'\fR and/or \f(CW\*(C`keyAgreement\*(C'\fR. -The Netscape certificate type must be absent or have the \s-1SSL\s0 client bit set. -.Sp -For all other certificates the normal \s-1CA\s0 checks apply. In addition, -the Netscape certificate type must be absent or have the \s-1SSL CA\s0 bit set. -This is used as a workaround if the basicConstraints extension is absent. -.ie n .IP "\fB(D)TLS Server\fR (""sslserver"")" 4 -.el .IP "\fB(D)TLS Server\fR (\f(CWsslserver\fR)" 4 -.IX Item "(D)TLS Server (sslserver)" -Any given extended key usage extension must allow for \f(CW\*(C`serverAuth\*(C'\fR -(\*(L"\s-1TLS WWW\s0 server authentication\*(R") and/or include one of the \s-1SGC\s0 OIDs. -.Sp -For target certificates, the key usage must -allow for \f(CW\*(C`digitalSignature\*(C'\fR, \f(CW\*(C`keyEncipherment\*(C'\fR, and/or \f(CW\*(C`keyAgreement\*(C'\fR. -The Netscape certificate type must be absent or have the \s-1SSL\s0 server bit set. -.Sp -For all other certificates the normal \s-1CA\s0 checks apply. In addition, -the Netscape certificate type must be absent or have the \s-1SSL CA\s0 bit set. -This is used as a workaround if the basicConstraints extension is absent. -.ie n .IP "\fBNetscape \s-1SSL\s0 Server\fR (""nssslserver"")" 4 -.el .IP "\fBNetscape \s-1SSL\s0 Server\fR (\f(CWnssslserver\fR)" 4 -.IX Item "Netscape SSL Server (nssslserver)" -In addition to what has been described for \fBsslserver\fR, for a Netscape -\&\s-1SSL\s0 client to connect to an \s-1SSL\s0 server, its \s-1EE\s0 certficate must have the -\&\fBkeyEncipherment\fR bit set if the keyUsage extension is present. This isn't -always valid because some cipher suites use the key for digital signing. -Otherwise it is the same as a normal \s-1SSL\s0 server. -.IP "\fBCommon S/MIME Checks\fR" 4 -.IX Item "Common S/MIME Checks" -Any given extended key usage extension must allow for \f(CW\*(C`emailProtection\*(C'\fR. -.Sp -For target certificates, -the Netscape certificate type must be absent or should have the S/MIME bit set. -If the S/MIME bit is not set in the Netscape certificate type -then the \s-1SSL\s0 client bit is tolerated as an alternative but a warning is shown. -This is because some Verisign certificates don't set the S/MIME bit. -.Sp -For all other certificates the normal \s-1CA\s0 checks apply. In addition, -the Netscape certificate type must be absent or have the S/MIME \s-1CA\s0 bit set. -This is used as a workaround if the basicConstraints extension is absent. -.ie n .IP "\fBS/MIME Signing\fR (""smimesign"")" 4 -.el .IP "\fBS/MIME Signing\fR (\f(CWsmimesign\fR)" 4 -.IX Item "S/MIME Signing (smimesign)" -In addition to the common S/MIME checks, for target certficiates -the key usage must allow for \f(CW\*(C`digitalSignature\*(C'\fR and/or \fBnonRepudiation\fR. -.ie n .IP "\fBS/MIME Encryption\fR (""smimeencrypt"")" 4 -.el .IP "\fBS/MIME Encryption\fR (\f(CWsmimeencrypt\fR)" 4 -.IX Item "S/MIME Encryption (smimeencrypt)" -In addition to the common S/MIME checks, for target certficiates -the key usage must allow for \f(CW\*(C`keyEncipherment\*(C'\fR. -.ie n .IP "\fB\s-1CRL\s0 Signing\fR (""crlsign"")" 4 -.el .IP "\fB\s-1CRL\s0 Signing\fR (\f(CWcrlsign\fR)" 4 -.IX Item "CRL Signing (crlsign)" -For target certificates, the key usage must allow for \f(CW\*(C`cRLSign\*(C'\fR. -.Sp -For all other certifcates the normal \s-1CA\s0 checks apply. -Except in this case the basicConstraints extension must be present. -.ie n .IP "\fB\s-1OCSP\s0 Helper\fR (""ocsphelper"")" 4 -.el .IP "\fB\s-1OCSP\s0 Helper\fR (\f(CWocsphelper\fR)" 4 -.IX Item "OCSP Helper (ocsphelper)" -For target certificates, no checks are performed at this stage, -but special checks apply; see \fBOCSP_basic_verify\fR\|(3). -.Sp -For all other certifcates the normal \s-1CA\s0 checks apply. -.ie n .IP "\fBTimestamp Signing\fR (""timestampsign"")" 4 -.el .IP "\fBTimestamp Signing\fR (\f(CWtimestampsign\fR)" 4 -.IX Item "Timestamp Signing (timestampsign)" -For target certificates, if the key usage extension is present, it must include -\&\f(CW\*(C`digitalSignature\*(C'\fR and/or \f(CW\*(C`nonRepudiation\*(C'\fR and must not include other bits. -The \s-1EKU\s0 extension must be present and contain \f(CW\*(C`timeStamping\*(C'\fR only. -Moreover, it must be marked as critical. -.Sp -For all other certifcates the normal \s-1CA\s0 checks apply. -.ie n .IP "\fBCode Signing\fR (""codesign"")" 4 -.el .IP "\fBCode Signing\fR (\f(CWcodesign\fR)" 4 -.IX Item "Code Signing (codesign)" -For target certificates, -the key usage extension must be present and marked critical and -include , but must not include \f(CW\*(C`keyCertSign\*(C'\fR nor \f(CW\*(C`cRLSign\*(C'\fR. -The \s-1EKU\s0 extension must be present and contain \f(CW\*(C`codeSign\*(C'\fR, -but must not include \f(CW\*(C`anyExtendedKeyUsage\*(C'\fR nor \f(CW\*(C`serverAuth\*(C'\fR. -.Sp -For all other certifcates the normal \s-1CA\s0 checks apply. -.SH "BUGS" -.IX Header "BUGS" -The issuer checks still suffer from limitations in the underlying X509_LOOKUP -\&\s-1API.\s0 One consequence of this is that trusted certificates with matching -subject name must appear in a file (as specified by the \fB\-CAfile\fR option), -a directory (as specified by \fB\-CApath\fR), -or a store (as specified by \fB\-CAstore\fR). -If there are multiple such matches, possibly in multiple locations, -only the first one (in the mentioned order of locations) is recognised. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_verify_cert\fR\|(3), -\&\fBOCSP_basic_verify\fR\|(3), -\&\fBopenssl\-verify\fR\|(1), -\&\fBopenssl\-ocsp\fR\|(1), -\&\fBopenssl\-ts\fR\|(1), -\&\fBopenssl\-s_client\fR\|(1), -\&\fBopenssl\-s_server\fR\|(1), -\&\fBopenssl\-smime\fR\|(1), -\&\fBopenssl\-cmp\fR\|(1), -\&\fBopenssl\-cms\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The checks enabled by \fB\-x509_strict\fR have been extended in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-verify.1ossl b/openssl-install/share/man/man1/openssl-verify.1ossl deleted file mode 100644 index 39aca984..00000000 --- a/openssl-install/share/man/man1/openssl-verify.1ossl +++ /dev/null @@ -1,316 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-VERIFY 1ossl" -.TH OPENSSL-VERIFY 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-verify \- certificate verification command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBverify\fR -[\fB\-help\fR] -[\fB\-CRLfile\fR \fIfilename\fR|\fIuri\fR] -[\fB\-crl_download\fR] -[\fB\-show_chain\fR] -[\fB\-verbose\fR] -[\fB\-trusted\fR \fIfilename\fR|\fIuri\fR] -[\fB\-untrusted\fR \fIfilename\fR|\fIuri\fR] -[\fB\-vfyopt\fR \fInm\fR:\fIv\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-CAfile\fR \fIfile\fR] -[\fB\-no\-CAfile\fR] -[\fB\-CApath\fR \fIdir\fR] -[\fB\-no\-CApath\fR] -[\fB\-CAstore\fR \fIuri\fR] -[\fB\-no\-CAstore\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-allow_proxy_certs\fR] -[\fB\-attime\fR \fItimestamp\fR] -[\fB\-no_check_time\fR] -[\fB\-check_ss_sig\fR] -[\fB\-crl_check\fR] -[\fB\-crl_check_all\fR] -[\fB\-explicit_policy\fR] -[\fB\-extended_crl\fR] -[\fB\-ignore_critical\fR] -[\fB\-inhibit_any\fR] -[\fB\-inhibit_map\fR] -[\fB\-partial_chain\fR] -[\fB\-policy\fR \fIarg\fR] -[\fB\-policy_check\fR] -[\fB\-policy_print\fR] -[\fB\-purpose\fR \fIpurpose\fR] -[\fB\-suiteB_128\fR] -[\fB\-suiteB_128_only\fR] -[\fB\-suiteB_192\fR] -[\fB\-trusted_first\fR] -[\fB\-no_alt_chains\fR] -[\fB\-use_deltas\fR] -[\fB\-auth_level\fR \fInum\fR] -[\fB\-verify_depth\fR \fInum\fR] -[\fB\-verify_email\fR \fIemail\fR] -[\fB\-verify_hostname\fR \fIhostname\fR] -[\fB\-verify_ip\fR \fIip\fR] -[\fB\-verify_name\fR \fIname\fR] -[\fB\-x509_strict\fR] -[\fB\-issuer_checks\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -[\fB\-\-\fR] -[\fIcertificate\fR ...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command verifies certificate chains. If a certificate chain has multiple -problems, this program attempts to display all of them. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-CRLfile\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-CRLfile filename|uri" -The file or \s-1URI\s0 should contain one or more CRLs in \s-1PEM\s0 or \s-1DER\s0 format. -This option can be specified more than once to include CRLs from multiple -sources. -.IP "\fB\-crl_download\fR" 4 -.IX Item "-crl_download" -Attempt to download \s-1CRL\s0 information for certificates via their \s-1CDP\s0 entries. -.IP "\fB\-show_chain\fR" 4 -.IX Item "-show_chain" -Display information about the certificate chain that has been built (if -successful). Certificates in the chain that came from the untrusted list will be -flagged as \*(L"untrusted\*(R". -.IP "\fB\-verbose\fR" 4 -.IX Item "-verbose" -Print extra information about the operations being performed. -.IP "\fB\-trusted\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-trusted filename|uri" -A file or \s-1URI\s0 of (more or less) trusted certificates. -See \fBopenssl\-verification\-options\fR\|(1) for more information on trust settings. -.Sp -This option can be specified more than once to load certificates from multiple -sources. -.IP "\fB\-untrusted\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-untrusted filename|uri" -A file or \s-1URI\s0 of untrusted certificates to use for chain building. -This option can be specified more than once to load certificates from multiple -sources. -.IP "\fB\-vfyopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-vfyopt nm:v" -Pass options to the signature algorithm during verify operations. -Names and values of these options are algorithm-specific. -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -This specifies how the subject or issuer names are displayed. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.Sp -To load certificates or CRLs that require engine support, specify the -\&\fB\-engine\fR option before any of the -\&\fB\-trusted\fR, \fB\-untrusted\fR or \fB\-CRLfile\fR options. -.IP "\fB\-CAfile\fR \fIfile\fR, \fB\-no\-CAfile\fR, \fB\-CApath\fR \fIdir\fR, \fB\-no\-CApath\fR, \fB\-CAstore\fR \fIuri\fR, \fB\-no\-CAstore\fR" 4 -.IX Item "-CAfile file, -no-CAfile, -CApath dir, -no-CApath, -CAstore uri, -no-CAstore" -See \*(L"Trusted Certificate Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-allow_proxy_certs\fR, \fB\-attime\fR, \fB\-no_check_time\fR, \fB\-check_ss_sig\fR, \fB\-crl_check\fR, \fB\-crl_check_all\fR, \fB\-explicit_policy\fR, \fB\-extended_crl\fR, \fB\-ignore_critical\fR, \fB\-inhibit_any\fR, \fB\-inhibit_map\fR, \fB\-no_alt_chains\fR, \fB\-partial_chain\fR, \fB\-policy\fR, \fB\-policy_check\fR, \fB\-policy_print\fR, \fB\-purpose\fR, \fB\-suiteB_128\fR, \fB\-suiteB_128_only\fR, \fB\-suiteB_192\fR, \fB\-trusted_first\fR, \fB\-use_deltas\fR, \fB\-auth_level\fR, \fB\-verify_depth\fR, \fB\-verify_email\fR, \fB\-verify_hostname\fR, \fB\-verify_ip\fR, \fB\-verify_name\fR, \fB\-x509_strict\fR \fB\-issuer_checks\fR" 4 -.IX Item "-allow_proxy_certs, -attime, -no_check_time, -check_ss_sig, -crl_check, -crl_check_all, -explicit_policy, -extended_crl, -ignore_critical, -inhibit_any, -inhibit_map, -no_alt_chains, -partial_chain, -policy, -policy_check, -policy_print, -purpose, -suiteB_128, -suiteB_128_only, -suiteB_192, -trusted_first, -use_deltas, -auth_level, -verify_depth, -verify_email, -verify_hostname, -verify_ip, -verify_name, -x509_strict -issuer_checks" -Set various options of certificate chain verification. -See \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1) for details. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.IP "\fB\-\-\fR" 4 -.IX Item "--" -Indicates the last option. All arguments following this are assumed to be -certificate files. This is useful if the first certificate filename begins -with a \fB\-\fR. -.IP "\fIcertificate\fR ..." 4 -.IX Item "certificate ..." -One or more target certificates to verify, one per file. If no certificates are -given, this command will attempt to read a single certificate from standard -input. -.SH "DIAGNOSTICS" -.IX Header "DIAGNOSTICS" -When a verify operation fails the output messages can be somewhat cryptic. The -general form of the error message is: -.PP -.Vb 2 -\& server.pem: /C=AU/ST=Queensland/O=CryptSoft Pty Ltd/CN=Test CA (1024 bit) -\& error 24 at 1 depth lookup:invalid CA certificate -.Ve -.PP -The first line contains the name of the certificate being verified followed by -the subject name of the certificate. The second line contains the error number -and the depth. The depth is number of the certificate being verified when a -problem was detected starting with zero for the target (\*(L"leaf\*(R") certificate -itself then 1 for the \s-1CA\s0 that signed the target certificate and so on. -Finally a textual version of the error number is presented. -.PP -A list of the error codes and messages can be found in -\&\fBX509_STORE_CTX_get_error\fR\|(3); the full list is defined in the header file -\&\fI\fR. -.PP -This command ignores many errors, in order to allow all the problems with a -certificate chain to be determined. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-verification\-options\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -\&\fBossl_store\-file\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\-show_chain\fR option was added in OpenSSL 1.1.0. -.PP -The \fB\-engine option\fR was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-version.1ossl b/openssl-install/share/man/man1/openssl-version.1ossl deleted file mode 100644 index f77414c6..00000000 --- a/openssl-install/share/man/man1/openssl-version.1ossl +++ /dev/null @@ -1,231 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-VERSION 1ossl" -.TH OPENSSL-VERSION 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-version \- print OpenSSL version information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl version\fR -[\fB\-help\fR] -[\fB\-a\fR] -[\fB\-v\fR] -[\fB\-b\fR] -[\fB\-o\fR] -[\fB\-f\fR] -[\fB\-p\fR] -[\fB\-d\fR] -[\fB\-e\fR] -[\fB\-m\fR] -[\fB\-r\fR] -[\fB\-c\fR] -[\fB\-w\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is used to print out version information about OpenSSL. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-a\fR" 4 -.IX Item "-a" -All information, this is the same as setting all the other flags. -.IP "\fB\-v\fR" 4 -.IX Item "-v" -The current OpenSSL version. -.IP "\fB\-b\fR" 4 -.IX Item "-b" -The date the current version of OpenSSL was built. -.IP "\fB\-o\fR" 4 -.IX Item "-o" -Option information: various options set when the library was built. -.IP "\fB\-f\fR" 4 -.IX Item "-f" -Compilation flags. -.IP "\fB\-p\fR" 4 -.IX Item "-p" -Platform setting. -.IP "\fB\-d\fR" 4 -.IX Item "-d" -\&\s-1OPENSSLDIR\s0 setting. -.IP "\fB\-e\fR" 4 -.IX Item "-e" -\&\s-1ENGINESDIR\s0 settings. -.IP "\fB\-m\fR" 4 -.IX Item "-m" -\&\s-1MODULESDIR\s0 settings. -.IP "\fB\-r\fR" 4 -.IX Item "-r" -The random number generator source settings. -.IP "\fB\-c\fR" 4 -.IX Item "-c" -The OpenSSL \s-1CPU\s0 settings info. -.IP "\fB\-w\fR" 4 -.IX Item "-w" -The OpenSSL \fB\s-1OSSL_WINCTX\s0\fR build time variable, if set. -Used for computing Windows registry key names. This option is unavailable on -non-Windows platforms. -.SH "HISTORY" -.IX Header "HISTORY" -In OpenSSL versions prior to 3.4, OpenSSL had a limitation regarding the -\&\fB\s-1OPENSSLDIR\s0\fR, \fB\s-1MODULESDIR\s0\fR and \fB\s-1ENGINESDIR\s0\fR build time macros. These macros -were defined at build time, and represented filesystem paths. This is common -practice on unix like systems, as there was an expectation that a given build -would be installed to a pre-determined location. On Windows however, there is -no such expectation, as libraries can be installed to arbitrary locations. -\&\fB\s-1OSSL_WINCTX\s0\fR was introduced as a new build time variable to define a set of -registry keys identified by the name openssl\-\-, in which the - value is derived from the version string in the openssl source, and -the extension is derived from the \fB\s-1OSSL_WINCTX\s0\fR variable. The values of -\&\fB\s-1OPENSSLDIR\s0\fR, \fB\s-1ENGINESDIR\s0\fR and \fB\s-1MODULESDIR\s0\fR can be set to various paths -underneath this key to break the requirement to predict the installation path at -build time. -.SH "NOTES" -.IX Header "NOTES" -The output of \f(CW\*(C`openssl version \-a\*(C'\fR would typically be used when sending -in a bug report. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl-x509.1ossl b/openssl-install/share/man/man1/openssl-x509.1ossl deleted file mode 100644 index 47d173f1..00000000 --- a/openssl-install/share/man/man1/openssl-x509.1ossl +++ /dev/null @@ -1,891 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-X509 1ossl" -.TH OPENSSL-X509 1ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-x509 \- Certificate display and signing command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR \fBx509\fR -[\fB\-help\fR] -[\fB\-in\fR \fIfilename\fR|\fIuri\fR] -[\fB\-passin\fR \fIarg\fR] -[\fB\-new\fR] -[\fB\-x509toreq\fR] -[\fB\-req\fR] -[\fB\-copy_extensions\fR \fIarg\fR] -[\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-vfyopt\fR \fInm\fR:\fIv\fR] -[\fB\-key\fR \fIfilename\fR|\fIuri\fR] -[\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-signkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-out\fR \fIfilename\fR] -[\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR] -[\fB\-nocert\fR] -[\fB\-noout\fR] -[\fB\-dateopt\fR] -[\fB\-text\fR] -[\fB\-certopt\fR \fIoption\fR] -[\fB\-fingerprint\fR] -[\fB\-alias\fR] -[\fB\-serial\fR] -[\fB\-startdate\fR] -[\fB\-enddate\fR] -[\fB\-dates\fR] -[\fB\-subject\fR] -[\fB\-issuer\fR] -[\fB\-nameopt\fR \fIoption\fR] -[\fB\-email\fR] -[\fB\-hash\fR] -[\fB\-subject_hash\fR] -[\fB\-subject_hash_old\fR] -[\fB\-issuer_hash\fR] -[\fB\-issuer_hash_old\fR] -[\fB\-ext\fR \fIextensions\fR] -[\fB\-ocspid\fR] -[\fB\-ocsp_uri\fR] -[\fB\-purpose\fR] -[\fB\-pubkey\fR] -[\fB\-modulus\fR] -[\fB\-checkend\fR \fInum\fR] -[\fB\-checkhost\fR \fIhost\fR] -[\fB\-checkemail\fR \fIhost\fR] -[\fB\-checkip\fR \fIipaddr\fR] -[\fB\-set_serial\fR \fIn\fR] -[\fB\-next_serial\fR] -[\fB\-not_before\fR \fIdate\fR] -[\fB\-not_after\fR \fIdate\fR] -[\fB\-days\fR \fIarg\fR] -[\fB\-preserve_dates\fR] -[\fB\-set_issuer\fR \fIarg\fR] -[\fB\-set_subject\fR \fIarg\fR] -[\fB\-subj\fR \fIarg\fR] -[\fB\-force_pubkey\fR \fIfilename\fR] -[\fB\-clrext\fR] -[\fB\-extfile\fR \fIfilename\fR] -[\fB\-extensions\fR \fIsection\fR] -[\fB\-sigopt\fR \fInm\fR:\fIv\fR] -[\fB\-badsig\fR] -[\fB\-\f(BIdigest\fB\fR] -[\fB\-CA\fR \fIfilename\fR|\fIuri\fR] -[\fB\-CAform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR] -[\fB\-CAkey\fR \fIfilename\fR|\fIuri\fR] -[\fB\-CAkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR] -[\fB\-CAserial\fR \fIfilename\fR] -[\fB\-CAcreateserial\fR] -[\fB\-trustout\fR] -[\fB\-setalias\fR \fIarg\fR] -[\fB\-clrtrust\fR] -[\fB\-addtrust\fR \fIarg\fR] -[\fB\-clrreject\fR] -[\fB\-addreject\fR \fIarg\fR] -[\fB\-rand\fR \fIfiles\fR] -[\fB\-writerand\fR \fIfile\fR] -[\fB\-engine\fR \fIid\fR] -[\fB\-provider\fR \fIname\fR] -[\fB\-provider\-path\fR \fIpath\fR] -[\fB\-propquery\fR \fIpropq\fR] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command is a multi-purposes certificate handling command. -It can be used to print certificate information, -convert certificates to various forms, edit certificate trust settings, -generate certificates from scratch or from certification requests -and then self-signing them or signing them like a \*(L"micro \s-1CA\*(R".\s0 -.PP -Generated certificates bear X.509 version 3. -Unless specified otherwise, -key identifier extensions are included as described in \fBx509v3_config\fR\|(5). -.PP -Since there are a large number of options they will split up into -various sections. -.SH "OPTIONS" -.IX Header "OPTIONS" -.SS "Input, Output, and General Purpose Options" -.IX Subsection "Input, Output, and General Purpose Options" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Print out a usage message. -.IP "\fB\-in\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-in filename|uri" -This specifies the input to read a certificate from -or the input file for reading a certificate request if the \fB\-req\fR flag is used. -In both cases this defaults to standard input. -.Sp -This option cannot be combined with the \fB\-new\fR flag. -.IP "\fB\-passin\fR \fIarg\fR" 4 -.IX Item "-passin arg" -The key and certificate file password source. -For more information about the format of \fIarg\fR -see \fBopenssl\-passphrase\-options\fR\|(1). -.IP "\fB\-new\fR" 4 -.IX Item "-new" -Generate a certificate from scratch, not using an input certificate -or certificate request. -So this excludes the \fB\-in\fR and \fB\-req\fR options. -Instead, the \fB\-set_subject\fR option needs to be given. -The public key to include can be given with the \fB\-force_pubkey\fR option -and defaults to the key given with the \fB\-key\fR (or \fB\-signkey\fR) option, -which implies self-signature. -.IP "\fB\-x509toreq\fR" 4 -.IX Item "-x509toreq" -Output a PKCS#10 certificate request (rather than a certificate). -The \fB\-key\fR (or \fB\-signkey\fR) option must be used to provide the private key for -self-signing; the corresponding public key is placed in the subjectPKInfo field. -.Sp -X.509 extensions included in a certificate input are not copied by default. -X.509 extensions to be added can be specified using the \fB\-extfile\fR option. -.IP "\fB\-req\fR" 4 -.IX Item "-req" -By default a certificate is expected on input. -With this option a PKCS#10 certificate request is expected instead, -which must be correctly self-signed. -.Sp -X.509 extensions included in the request are not copied by default. -X.509 extensions to be added can be specified using the \fB\-extfile\fR option. -.IP "\fB\-copy_extensions\fR \fIarg\fR" 4 -.IX Item "-copy_extensions arg" -Determines how to handle X.509 extensions -when converting from a certificate to a request using the \fB\-x509toreq\fR option -or converting from a request to a certificate using the \fB\-req\fR option. -If \fIarg\fR is \fBnone\fR or this option is not present then extensions are ignored. -If \fIarg\fR is \fBcopy\fR or \fBcopyall\fR then all extensions are copied, -except that subject identifier and authority key identifier extensions -are not taken over when producing a certificate request. -.Sp -The \fB\-ext\fR option can be used to further restrict which extensions to copy. -.IP "\fB\-inform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-inform DER|PEM" -The input file format to use; by default \s-1PEM\s0 is tried first. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-vfyopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-vfyopt nm:v" -Pass options to the signature algorithm during verify operations. -Names and values of these options are algorithm-specific. -.IP "\fB\-key\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-key filename|uri" -This option provides the private key for signing a new certificate or -certificate request. -Unless \fB\-force_pubkey\fR is given, the corresponding public key is placed in -the new certificate or certificate request, resulting in a self-signature. -.Sp -This option cannot be used in conjunction with the \fB\-CA\fR option. -.Sp -It sets the issuer name to the subject name (i.e., makes it self-issued). -Unless the \fB\-preserve_dates\fR option is supplied, -it sets the validity start date to the current time -and the end date to a value determined by the \fB\-days\fR option. -Start date and end date can also be explicitly supplied with options -\&\fB\-not_before\fR and \fB\-not_after\fR. -.IP "\fB\-signkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-signkey filename|uri" -This option is an alias of \fB\-key\fR. -.IP "\fB\-keyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-keyform DER|PEM|P12|ENGINE" -The key input format; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-out\fR \fIfilename\fR" 4 -.IX Item "-out filename" -This specifies the output filename to write to or standard output by default. -.IP "\fB\-outform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR" 4 -.IX Item "-outform DER|PEM" -The output format; the default is \fB\s-1PEM\s0\fR. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-nocert\fR" 4 -.IX Item "-nocert" -Do not output a certificate (except for printing as requested by below options). -.IP "\fB\-noout\fR" 4 -.IX Item "-noout" -This option prevents output except for printing as requested by below options. -.SS "Certificate Printing Options" -.IX Subsection "Certificate Printing Options" -Note: the \fB\-alias\fR and \fB\-purpose\fR options are also printing options -but are described in the \*(L"Trust Settings\*(R" section. -.IP "\fB\-dateopt\fR" 4 -.IX Item "-dateopt" -Specify the date output format. Values are: rfc_822 and iso_8601. -Defaults to rfc_822. -.IP "\fB\-text\fR" 4 -.IX Item "-text" -Prints out the certificate in text form. Full details are printed including the -public key, signature algorithms, issuer and subject names, serial number -any extensions present and any trust settings. -.IP "\fB\-certopt\fR \fIoption\fR" 4 -.IX Item "-certopt option" -Customise the print format used with \fB\-text\fR. The \fIoption\fR argument -can be a single option or multiple options separated by commas. -The \fB\-certopt\fR switch may be also be used more than once to set multiple -options. See the \*(L"Text Printing Flags\*(R" section for more information. -.IP "\fB\-fingerprint\fR" 4 -.IX Item "-fingerprint" -Calculates and prints the digest of the \s-1DER\s0 encoded version of the entire -certificate (see digest options). -This is commonly called a \*(L"fingerprint\*(R". Because of the nature of message -digests, the fingerprint of a certificate is unique to that certificate and -two certificates with the same fingerprint can be considered to be the same. -.IP "\fB\-alias\fR" 4 -.IX Item "-alias" -Prints the certificate \*(L"alias\*(R" (nickname), if any. -.IP "\fB\-serial\fR" 4 -.IX Item "-serial" -Prints the certificate serial number. -.IP "\fB\-startdate\fR" 4 -.IX Item "-startdate" -Prints out the start date of the certificate, that is the notBefore date. -.IP "\fB\-enddate\fR" 4 -.IX Item "-enddate" -Prints out the expiry date of the certificate, that is the notAfter date. -.IP "\fB\-dates\fR" 4 -.IX Item "-dates" -Prints out the start and expiry dates of a certificate. -.IP "\fB\-subject\fR" 4 -.IX Item "-subject" -Prints the subject name. -.IP "\fB\-issuer\fR" 4 -.IX Item "-issuer" -Prints the issuer name. -.IP "\fB\-nameopt\fR \fIoption\fR" 4 -.IX Item "-nameopt option" -This specifies how the subject or issuer names are displayed. -See \fBopenssl\-namedisplay\-options\fR\|(1) for details. -.IP "\fB\-email\fR" 4 -.IX Item "-email" -Prints the email address(es) if any. -.IP "\fB\-hash\fR" 4 -.IX Item "-hash" -Synonym for \*(L"\-subject_hash\*(R" for backward compatibility reasons. -.IP "\fB\-subject_hash\fR" 4 -.IX Item "-subject_hash" -Prints the \*(L"hash\*(R" of the certificate subject name. This is used in OpenSSL to -form an index to allow certificates in a directory to be looked up by subject -name. -.IP "\fB\-subject_hash_old\fR" 4 -.IX Item "-subject_hash_old" -Prints the \*(L"hash\*(R" of the certificate subject name using the older algorithm -as used by OpenSSL before version 1.0.0. -.IP "\fB\-issuer_hash\fR" 4 -.IX Item "-issuer_hash" -Prints the \*(L"hash\*(R" of the certificate issuer name. -.IP "\fB\-issuer_hash_old\fR" 4 -.IX Item "-issuer_hash_old" -Prints the \*(L"hash\*(R" of the certificate issuer name using the older algorithm -as used by OpenSSL before version 1.0.0. -.IP "\fB\-ext\fR \fIextensions\fR" 4 -.IX Item "-ext extensions" -Prints out the certificate extensions in text form. -Can also be used to restrict which extensions to copy. -Extensions are specified -with a comma separated string, e.g., \*(L"subjectAltName, subjectKeyIdentifier\*(R". -See the \fBx509v3_config\fR\|(5) manual page for the extension names. -.IP "\fB\-ocspid\fR" 4 -.IX Item "-ocspid" -Prints the \s-1OCSP\s0 hash values for the subject name and public key. -.IP "\fB\-ocsp_uri\fR" 4 -.IX Item "-ocsp_uri" -Prints the \s-1OCSP\s0 responder address(es) if any. -.IP "\fB\-purpose\fR" 4 -.IX Item "-purpose" -This option performs tests on the certificate extensions and outputs -the results. For a more complete description see -\&\*(L"Certificate Extensions\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.IP "\fB\-pubkey\fR" 4 -.IX Item "-pubkey" -Prints the certificate's SubjectPublicKeyInfo block in \s-1PEM\s0 format. -.IP "\fB\-modulus\fR" 4 -.IX Item "-modulus" -This option prints out the value of the modulus of the public key -contained in the certificate. -.SS "Certificate Checking Options" -.IX Subsection "Certificate Checking Options" -.IP "\fB\-checkend\fR \fIarg\fR" 4 -.IX Item "-checkend arg" -Checks if the certificate expires within the next \fIarg\fR seconds and exits -nonzero if yes it will expire or zero if not. -.IP "\fB\-checkhost\fR \fIhost\fR" 4 -.IX Item "-checkhost host" -Check that the certificate matches the specified host. -.IP "\fB\-checkemail\fR \fIemail\fR" 4 -.IX Item "-checkemail email" -Check that the certificate matches the specified email address. -.IP "\fB\-checkip\fR \fIipaddr\fR" 4 -.IX Item "-checkip ipaddr" -Check that the certificate matches the specified \s-1IP\s0 address. -.SS "Certificate Output Options" -.IX Subsection "Certificate Output Options" -.IP "\fB\-set_serial\fR \fIn\fR" 4 -.IX Item "-set_serial n" -Specifies the serial number to use. -This option can be used with the \fB\-key\fR, \fB\-signkey\fR, or \fB\-CA\fR options. -If used in conjunction with the \fB\-CA\fR option -the serial number file (as specified by the \fB\-CAserial\fR option) is not used. -.Sp -The serial number can be decimal or hex (if preceded by \f(CW\*(C`0x\*(C'\fR). -.IP "\fB\-next_serial\fR" 4 -.IX Item "-next_serial" -Set the serial to be one more than the number in the certificate. -.IP "\fB\-not_before\fR \fIdate\fR" 4 -.IX Item "-not_before date" -This allows the start date to be explicitly set. The format of the -date is \s-1YYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 UTCTime structure), or -\&\s-1YYYYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 GeneralizedTime structure). In -both formats, seconds \s-1SS\s0 and timezone Z must be present. -Alternatively, you can also use \*(L"today\*(R". -.Sp -Cannot be used together with the \fB\-preserve_dates\fR option. -.IP "\fB\-not_after\fR \fIdate\fR" 4 -.IX Item "-not_after date" -This allows the expiry date to be explicitly set. The format of the -date is \s-1YYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 UTCTime structure), or -\&\s-1YYYYMMDDHHMMSSZ\s0 (the same as an \s-1ASN1\s0 GeneralizedTime structure). In -both formats, seconds \s-1SS\s0 and timezone Z must be present. -Alternatively, you can also use \*(L"today\*(R". -.Sp -Cannot be used together with the \fB\-preserve_dates\fR option. -This overrides the option \fB\-days\fR. -.IP "\fB\-days\fR \fIarg\fR" 4 -.IX Item "-days arg" -Specifies the number of days from today until a newly generated certificate expires. -The default is 30. -.Sp -Cannot be used together with the option \fB\-preserve_dates\fR. -If option \fB\-not_after\fR is set, the explicit expiry date takes precedence. -.IP "\fB\-preserve_dates\fR" 4 -.IX Item "-preserve_dates" -When signing a certificate, preserve \*(L"notBefore\*(R" and \*(L"notAfter\*(R" dates of any -input certificate instead of adjusting them to current time and duration. -Cannot be used together with the options \fB\-days\fR, \fB\-not_before\fR and \fB\-not_after\fR. -.IP "\fB\-set_issuer\fR \fIarg\fR" 4 -.IX Item "-set_issuer arg" -When a certificate is created set its issuer name to the given value. -.Sp -See \fB\-set_subject\fR on how the arg must be formatted. -.IP "\fB\-set_subject\fR \fIarg\fR" 4 -.IX Item "-set_subject arg" -When a certificate is created set its subject name to the given value. -When the certificate is self-signed the issuer name is set to the same value, -unless the \fB\-set_issuer\fR option is given. -.Sp -The arg must be formatted as \f(CW\*(C`/type0=value0/type1=value1/type2=...\*(C'\fR. -Special characters may be escaped by \f(CW\*(C`\e\*(C'\fR (backslash), whitespace is retained. -Empty values are permitted, but the corresponding type will not be included -in the certificate. -Giving a single \f(CW\*(C`/\*(C'\fR will lead to an empty sequence of RDNs (a NULL-DN). -Multi-valued RDNs can be formed by placing a \f(CW\*(C`+\*(C'\fR character instead of a \f(CW\*(C`/\*(C'\fR -between the AttributeValueAssertions (AVAs) that specify the members of the set. -Example: -.Sp -\&\f(CW\*(C`/DC=org/DC=OpenSSL/DC=users/UID=123456+CN=John Doe\*(C'\fR -.Sp -This option can be used with the \fB\-new\fR and \fB\-force_pubkey\fR options to create -a new certificate without providing an input certificate or certificate request. -.IP "\fB\-subj\fR \fIarg\fR" 4 -.IX Item "-subj arg" -This option is an alias of \fB\-set_subject\fR. -.IP "\fB\-force_pubkey\fR \fIfilename\fR" 4 -.IX Item "-force_pubkey filename" -When a new certificate or certificate request is created -set its public key to the given key -instead of the key contained in the input -or given with the \fB\-key\fR (or \fB\-signkey\fR) option. -If the input contains no public key but a private key, its public part is used. -.Sp -This option can be used in conjunction with b<\-new> and \fB\-set_subject\fR -to directly generate a certificate containing any desired public key. -.Sp -This option is also useful for creating self-issued certificates that are not -self-signed, for instance when the key cannot be used for signing, such as \s-1DH.\s0 -.IP "\fB\-clrext\fR" 4 -.IX Item "-clrext" -When transforming a certificate to a new certificate -by default all certificate extensions are retained. -.Sp -When transforming a certificate or certificate request, -the \fB\-clrext\fR option prevents taking over any extensions from the source. -In any case, when producing a certificate request, -neither subject identifier nor authority key identifier extensions are included. -.IP "\fB\-extfile\fR \fIfilename\fR" 4 -.IX Item "-extfile filename" -Configuration file containing certificate and request X.509 extensions to add. -.IP "\fB\-extensions\fR \fIsection\fR" 4 -.IX Item "-extensions section" -The section in the extfile to add X.509 extensions from. -If this option is not -specified then the extensions should either be contained in the unnamed -(default) section or the default section should contain a variable called -\&\*(L"extensions\*(R" which contains the section to use. -.Sp -See the \fBx509v3_config\fR\|(5) manual page for details of the -extension section format. -.Sp -Unless specified otherwise, -key identifier extensions are included as described in \fBx509v3_config\fR\|(5). -.IP "\fB\-sigopt\fR \fInm\fR:\fIv\fR" 4 -.IX Item "-sigopt nm:v" -Pass options to the signature algorithm during sign operations. -This option may be given multiple times. -Names and values provided using this option are algorithm-specific. -.IP "\fB\-badsig\fR" 4 -.IX Item "-badsig" -Corrupt the signature before writing it; this can be useful -for testing. -.IP "\fB\-\f(BIdigest\fB\fR" 4 -.IX Item "-digest" -The digest to use. -This affects any signing or printing option that uses a message -digest, such as the \fB\-fingerprint\fR, \fB\-key\fR, and \fB\-CA\fR options. -Any digest supported by the \fBopenssl\-dgst\fR\|(1) command can be used. -If not specified then \s-1SHA1\s0 is used with \fB\-fingerprint\fR or -the default digest for the signing algorithm is used, typically \s-1SHA256.\s0 -.SS "Micro-CA Options" -.IX Subsection "Micro-CA Options" -.IP "\fB\-CA\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-CA filename|uri" -Specifies the \*(L"\s-1CA\*(R"\s0 certificate to be used for signing. -When present, this behaves like a \*(L"micro \s-1CA\*(R"\s0 as follows: -The subject name of the \*(L"\s-1CA\*(R"\s0 certificate is placed as issuer name in the new -certificate, which is then signed using the \*(L"\s-1CA\*(R"\s0 key given as detailed below. -.Sp -This option cannot be used in conjunction with \fB\-key\fR (or \fB\-signkey\fR). -This option is normally combined with the \fB\-req\fR option referencing a \s-1CSR.\s0 -Without the \fB\-req\fR option the input must be an existing certificate -unless the \fB\-new\fR option is given, which generates a certificate from scratch. -.IP "\fB\-CAform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR," 4 -.IX Item "-CAform DER|PEM|P12," -The format for the \s-1CA\s0 certificate; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-CAkey\fR \fIfilename\fR|\fIuri\fR" 4 -.IX Item "-CAkey filename|uri" -Sets the \s-1CA\s0 private key to sign a certificate with. -The private key must match the public key of the certificate given with \fB\-CA\fR. -If this option is not provided then the key must be present in the \fB\-CA\fR input. -.IP "\fB\-CAkeyform\fR \fB\s-1DER\s0\fR|\fB\s-1PEM\s0\fR|\fBP12\fR|\fB\s-1ENGINE\s0\fR" 4 -.IX Item "-CAkeyform DER|PEM|P12|ENGINE" -The format for the \s-1CA\s0 key; unspecified by default. -See \fBopenssl\-format\-options\fR\|(1) for details. -.IP "\fB\-CAserial\fR \fIfilename\fR" 4 -.IX Item "-CAserial filename" -Sets the \s-1CA\s0 serial number file to use. -.Sp -When creating a certificate with this option and with the \fB\-CA\fR option, -the certificate serial number is stored in the given file. -This file consists of one line containing -an even number of hex digits with the serial number used last time. -After reading this number, it is incremented and used, and the file is updated. -.Sp -The default filename consists of the \s-1CA\s0 certificate file base name with -\&\fI.srl\fR appended. For example if the \s-1CA\s0 certificate file is called -\&\fImycacert.pem\fR it expects to find a serial number file called -\&\fImycacert.srl\fR. -.Sp -If the \fB\-CA\fR option is specified and neither <\-CAserial> or <\-CAcreateserial> -is given and the default serial number file does not exist, -a random number is generated; this is the recommended practice. -.IP "\fB\-CAcreateserial\fR" 4 -.IX Item "-CAcreateserial" -With this option and the \fB\-CA\fR option -the \s-1CA\s0 serial number file is created if it does not exist. -A random number is generated, used for the certificate, -and saved into the serial number file determined as described above. -.SS "Trust Settings" -.IX Subsection "Trust Settings" -A \fBtrusted certificate\fR is an ordinary certificate which has several -additional pieces of information attached to it such as the permitted -and prohibited uses of the certificate and possibly an \*(L"alias\*(R" (nickname). -.PP -Normally when a certificate is being verified at least one certificate -must be \*(L"trusted\*(R". By default a trusted certificate must be stored -locally and must be a root \s-1CA:\s0 any certificate chain ending in this \s-1CA\s0 -is then usable for any purpose. -.PP -Trust settings currently are only used with a root \s-1CA.\s0 -They allow a finer control over the purposes the root \s-1CA\s0 can be used for. -For example, a \s-1CA\s0 may be trusted for \s-1SSL\s0 client but not \s-1SSL\s0 server use. -.PP -See \fBopenssl\-verification\-options\fR\|(1) for more information -on the meaning of trust settings. -.PP -Future versions of OpenSSL will recognize trust settings on any -certificate: not just root CAs. -.IP "\fB\-trustout\fR" 4 -.IX Item "-trustout" -Mark any certificate \s-1PEM\s0 output as certificate rather than ordinary. -An ordinary or trusted certificate can be input but by default an ordinary -certificate is output and any trust settings are discarded. -With the \fB\-trustout\fR option a trusted certificate is output. A trusted -certificate is automatically output if any trust settings are modified. -.IP "\fB\-setalias\fR \fIarg\fR" 4 -.IX Item "-setalias arg" -Sets the \*(L"alias\*(R" of the certificate. This will allow the certificate -to be referred to using a nickname for example \*(L"Steve's Certificate\*(R". -.IP "\fB\-clrtrust\fR" 4 -.IX Item "-clrtrust" -Clears all the permitted or trusted uses of the certificate. -.IP "\fB\-addtrust\fR \fIarg\fR" 4 -.IX Item "-addtrust arg" -Adds a trusted certificate use. -Any object name can be used here but currently only \fBclientAuth\fR, -\&\fBserverAuth\fR, \fBemailProtection\fR, and \fBanyExtendedKeyUsage\fR are defined. -As of OpenSSL 1.1.0, the last of these blocks all purposes when rejected or -enables all purposes when trusted. -Other OpenSSL applications may define additional uses. -.IP "\fB\-clrreject\fR" 4 -.IX Item "-clrreject" -Clears all the prohibited or rejected uses of the certificate. -.IP "\fB\-addreject\fR \fIarg\fR" 4 -.IX Item "-addreject arg" -Adds a prohibited trust anchor purpose. -It accepts the same values as the \fB\-addtrust\fR option. -.SS "Generic options" -.IX Subsection "Generic options" -.IP "\fB\-rand\fR \fIfiles\fR, \fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-rand files, -writerand file" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for details. -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -See \*(L"Engine Options\*(R" in \fBopenssl\fR\|(1). -This option is deprecated. -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -.PD 0 -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -.PD -See \*(L"Provider Options\*(R" in \fBopenssl\fR\|(1), \fBprovider\fR\|(7), and \fBproperty\fR\|(7). -.SS "Text Printing Flags" -.IX Subsection "Text Printing Flags" -As well as customising the name printing format, it is also possible to -customise the actual fields printed using the \fBcertopt\fR option when -the \fBtext\fR option is present. The default behaviour is to print all fields. -.IP "\fBcompatible\fR" 4 -.IX Item "compatible" -Use the old format. This is equivalent to specifying no printing options at all. -.IP "\fBno_header\fR" 4 -.IX Item "no_header" -Don't print header information: that is the lines saying \*(L"Certificate\*(R" -and \*(L"Data\*(R". -.IP "\fBno_version\fR" 4 -.IX Item "no_version" -Don't print out the version number. -.IP "\fBno_serial\fR" 4 -.IX Item "no_serial" -Don't print out the serial number. -.IP "\fBno_signame\fR" 4 -.IX Item "no_signame" -Don't print out the signature algorithm used. -.IP "\fBno_validity\fR" 4 -.IX Item "no_validity" -Don't print the validity, that is the \fBnotBefore\fR and \fBnotAfter\fR fields. -.IP "\fBno_subject\fR" 4 -.IX Item "no_subject" -Don't print out the subject name. -.IP "\fBno_issuer\fR" 4 -.IX Item "no_issuer" -Don't print out the issuer name. -.IP "\fBno_pubkey\fR" 4 -.IX Item "no_pubkey" -Don't print out the public key. -.IP "\fBno_sigdump\fR" 4 -.IX Item "no_sigdump" -Don't give a hexadecimal dump of the certificate signature. -.IP "\fBno_aux\fR" 4 -.IX Item "no_aux" -Don't print out certificate trust information. -.IP "\fBno_extensions\fR" 4 -.IX Item "no_extensions" -Don't print out any X509V3 extensions. -.IP "\fBext_default\fR" 4 -.IX Item "ext_default" -Retain default extension behaviour: attempt to print out unsupported -certificate extensions. -.IP "\fBext_error\fR" 4 -.IX Item "ext_error" -Print an error message for unsupported certificate extensions. -.IP "\fBext_parse\fR" 4 -.IX Item "ext_parse" -\&\s-1ASN1\s0 parse unsupported extensions. -.IP "\fBext_dump\fR" 4 -.IX Item "ext_dump" -Hex dump unsupported extensions. -.IP "\fBca_default\fR" 4 -.IX Item "ca_default" -The value used by \fBopenssl\-ca\fR\|(1), equivalent to \fBno_issuer\fR, \fBno_pubkey\fR, -\&\fBno_header\fR, and \fBno_version\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Note: in these examples the '\e' means the example should be all on one -line. -.PP -Print the contents of a certificate: -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-noout \-text -.Ve -.PP -Print the \*(L"Subject Alternative Name\*(R" extension of a certificate: -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-noout \-ext subjectAltName -.Ve -.PP -Print more extensions of a certificate: -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-noout \-ext subjectAltName,nsCertType -.Ve -.PP -Print the certificate serial number: -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-noout \-serial -.Ve -.PP -Print the certificate subject name: -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-noout \-subject -.Ve -.PP -Print the certificate subject name in \s-1RFC2253\s0 form: -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-noout \-subject \-nameopt RFC2253 -.Ve -.PP -Print the certificate subject name in oneline form on a terminal -supporting \s-1UTF8:\s0 -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-noout \-subject \-nameopt oneline,\-esc_msb -.Ve -.PP -Print the certificate \s-1SHA1\s0 fingerprint: -.PP -.Vb 1 -\& openssl x509 \-sha1 \-in cert.pem \-noout \-fingerprint -.Ve -.PP -Convert a certificate from \s-1PEM\s0 to \s-1DER\s0 format: -.PP -.Vb 1 -\& openssl x509 \-in cert.pem \-inform PEM \-out cert.der \-outform DER -.Ve -.PP -Convert a certificate to a certificate request: -.PP -.Vb 1 -\& openssl x509 \-x509toreq \-in cert.pem \-out req.pem \-key key.pem -.Ve -.PP -Convert a certificate request into a self-signed certificate using -extensions for a \s-1CA:\s0 -.PP -.Vb 2 -\& openssl x509 \-req \-in careq.pem \-extfile openssl.cnf \-extensions v3_ca \e -\& \-key key.pem \-out cacert.pem -.Ve -.PP -Sign a certificate request using the \s-1CA\s0 certificate above and add user -certificate extensions: -.PP -.Vb 2 -\& openssl x509 \-req \-in req.pem \-extfile openssl.cnf \-extensions v3_usr \e -\& \-CA cacert.pem \-CAkey key.pem \-CAcreateserial -.Ve -.PP -Set a certificate to be trusted for \s-1SSL\s0 client use and change set its alias to -\&\*(L"Steve's Class 1 \s-1CA\*(R"\s0 -.PP -.Vb 2 -\& openssl x509 \-in cert.pem \-addtrust clientAuth \e -\& \-setalias "Steve\*(Aqs Class 1 CA" \-out trust.pem -.Ve -.SH "NOTES" -.IX Header "NOTES" -The conversion to \s-1UTF8\s0 format used with the name options assumes that -T61Strings use the \s-1ISO8859\-1\s0 character set. This is wrong but Netscape -and \s-1MSIE\s0 do this as do many certificates. So although this is incorrect -it is more likely to print the majority of certificates correctly. -.PP -The \fB\-email\fR option searches the subject name and the subject alternative -name extension. Only unique email addresses will be printed out: it will -not print the same address more than once. -.SH "BUGS" -.IX Header "BUGS" -It is possible to produce invalid certificates or requests by specifying the -wrong private key, using unsuitable X.509 extensions, -or using inconsistent options in some cases: these should be checked. -.PP -There should be options to explicitly set such things as start and end -dates rather than an offset from the current time. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-req\fR\|(1), -\&\fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1), -\&\fBopenssl\-verify\fR\|(1), -\&\fBx509v3_config\fR\|(5) -.SH "HISTORY" -.IX Header "HISTORY" -The hash algorithm used in the \fB\-subject_hash\fR and \fB\-issuer_hash\fR options -before OpenSSL 1.0.0 was based on the deprecated \s-1MD5\s0 algorithm and the encoding -of the distinguished name. In OpenSSL 1.0.0 and later it is based on a canonical -version of the \s-1DN\s0 using \s-1SHA1.\s0 This means that any directories using the old -form must have their links rebuilt using \fBopenssl\-rehash\fR\|(1) or similar. -.PP -The \fB\-signkey\fR option has been renamed to \fB\-key\fR in OpenSSL 3.0, -keeping the old name as an alias. -.PP -The \fB\-engine\fR option was deprecated in OpenSSL 3.0. -.PP -The \fB\-C\fR option was removed in OpenSSL 3.0. -.PP -Since OpenSSL 3.2, generated certificates bear X.509 version 3, -and key identifier extensions are included by default. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/openssl.1ossl b/openssl-install/share/man/man1/openssl.1ossl deleted file mode 100644 index c2d7b2c6..00000000 --- a/openssl-install/share/man/man1/openssl.1ossl +++ /dev/null @@ -1,775 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL 1ossl" -.TH OPENSSL 1ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl \- OpenSSL command line program -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBopenssl\fR -\&\fIcommand\fR -[ \fIoptions\fR ... ] -[ \fIparameters\fR ... ] -.PP -\&\fBopenssl\fR \fBno\-\fR\fI\s-1XXX\s0\fR [ \fIoptions\fR ] -.PP -\&\fBopenssl\fR \fB\-help\fR | \fB\-version\fR -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL is a cryptography toolkit implementing the Secure Sockets Layer (\s-1SSL\s0) -and Transport Layer Security (\s-1TLS\s0) network protocols and related -cryptography standards required by them. -.PP -The \fBopenssl\fR program is a command line program for using the various -cryptography functions of OpenSSL's \fBcrypto\fR library from the shell. -It can be used for -.PP -.Vb 8 -\& o Creation and management of private keys, public keys and parameters -\& o Public key cryptographic operations -\& o Creation of X.509 certificates, CSRs and CRLs -\& o Calculation of Message Digests and Message Authentication Codes -\& o Encryption and Decryption with Ciphers -\& o SSL/TLS Client and Server Tests -\& o Handling of S/MIME signed or encrypted mail -\& o Timestamp requests, generation and verification -.Ve -.SH "COMMAND SUMMARY" -.IX Header "COMMAND SUMMARY" -The \fBopenssl\fR program provides a rich variety of commands (\fIcommand\fR in -the \*(L"\s-1SYNOPSIS\*(R"\s0 above). -Each command can have many options and argument parameters, shown above as -\&\fIoptions\fR and \fIparameters\fR. -.PP -Detailed documentation and use cases for most standard subcommands are available -(e.g., \fBopenssl\-x509\fR\|(1)). The subcommand \fBopenssl\-list\fR\|(1) may be used to list -subcommands. -.PP -The command \fBno\-\fR\fI\s-1XXX\s0\fR tests whether a command of the -specified name is available. If no command named \fI\s-1XXX\s0\fR exists, it -returns 0 (success) and prints \fBno\-\fR\fI\s-1XXX\s0\fR; otherwise it returns 1 -and prints \fI\s-1XXX\s0\fR. In both cases, the output goes to \fBstdout\fR and -nothing is printed to \fBstderr\fR. Additional command line arguments -are always ignored. Since for each cipher there is a command of the -same name, this provides an easy way for shell scripts to test for the -availability of ciphers in the \fBopenssl\fR program. (\fBno\-\fR\fI\s-1XXX\s0\fR is -not able to detect pseudo-commands such as \fBquit\fR, -\&\fBlist\fR, or \fBno\-\fR\fI\s-1XXX\s0\fR itself.) -.SS "Configuration Option" -.IX Subsection "Configuration Option" -Many commands use an external configuration file for some or all of their -arguments and have a \fB\-config\fR option to specify that file. -The default name of the file is \fIopenssl.cnf\fR in the default certificate -storage area, which can be determined from the \fBopenssl\-version\fR\|(1) -command using the \fB\-d\fR or \fB\-a\fR option. -The environment variable \fB\s-1OPENSSL_CONF\s0\fR can be used to specify a different -file location or to disable loading a configuration (using the empty string). -.PP -Among others, the configuration file can be used to load modules -and to specify parameters for generating certificates and random numbers. -See \fBconfig\fR\|(5) for details. -.SS "Standard Commands" -.IX Subsection "Standard Commands" -.IP "\fBasn1parse\fR" 4 -.IX Item "asn1parse" -Parse an \s-1ASN.1\s0 sequence. -.IP "\fBca\fR" 4 -.IX Item "ca" -Certificate Authority (\s-1CA\s0) Management. -.IP "\fBciphers\fR" 4 -.IX Item "ciphers" -Cipher Suite Description Determination. -.IP "\fBcms\fR" 4 -.IX Item "cms" -\&\s-1CMS\s0 (Cryptographic Message Syntax) command. -.IP "\fBcrl\fR" 4 -.IX Item "crl" -Certificate Revocation List (\s-1CRL\s0) Management. -.IP "\fBcrl2pkcs7\fR" 4 -.IX Item "crl2pkcs7" -\&\s-1CRL\s0 to PKCS#7 Conversion. -.IP "\fBdgst\fR" 4 -.IX Item "dgst" -Message Digest calculation. \s-1MAC\s0 calculations are superseded by -\&\fBopenssl\-mac\fR\|(1). -.IP "\fBdhparam\fR" 4 -.IX Item "dhparam" -Generation and Management of Diffie-Hellman Parameters. Superseded by -\&\fBopenssl\-genpkey\fR\|(1) and \fBopenssl\-pkeyparam\fR\|(1). -.IP "\fBdsa\fR" 4 -.IX Item "dsa" -\&\s-1DSA\s0 Data Management. -.IP "\fBdsaparam\fR" 4 -.IX Item "dsaparam" -\&\s-1DSA\s0 Parameter Generation and Management. Superseded by -\&\fBopenssl\-genpkey\fR\|(1) and \fBopenssl\-pkeyparam\fR\|(1). -.IP "\fBec\fR" 4 -.IX Item "ec" -\&\s-1EC\s0 (Elliptic curve) key processing. -.IP "\fBecparam\fR" 4 -.IX Item "ecparam" -\&\s-1EC\s0 parameter manipulation and generation. -.IP "\fBenc\fR" 4 -.IX Item "enc" -Encryption, decryption, and encoding. -.IP "\fBengine\fR" 4 -.IX Item "engine" -Engine (loadable module) information and manipulation. -.IP "\fBerrstr\fR" 4 -.IX Item "errstr" -Error Number to Error String Conversion. -.IP "\fBfipsinstall\fR" 4 -.IX Item "fipsinstall" -\&\s-1FIPS\s0 configuration installation. -.IP "\fBgendsa\fR" 4 -.IX Item "gendsa" -Generation of \s-1DSA\s0 Private Key from Parameters. Superseded by -\&\fBopenssl\-genpkey\fR\|(1) and \fBopenssl\-pkey\fR\|(1). -.IP "\fBgenpkey\fR" 4 -.IX Item "genpkey" -Generation of Private Key or Parameters. -.IP "\fBgenrsa\fR" 4 -.IX Item "genrsa" -Generation of \s-1RSA\s0 Private Key. Superseded by \fBopenssl\-genpkey\fR\|(1). -.IP "\fBhelp\fR" 4 -.IX Item "help" -Display information about a command's options. -.IP "\fBinfo\fR" 4 -.IX Item "info" -Display diverse information built into the OpenSSL libraries. -.IP "\fBkdf\fR" 4 -.IX Item "kdf" -Key Derivation Functions. -.IP "\fBlist\fR" 4 -.IX Item "list" -List algorithms and features. -.IP "\fBmac\fR" 4 -.IX Item "mac" -Message Authentication Code Calculation. -.IP "\fBnseq\fR" 4 -.IX Item "nseq" -Create or examine a Netscape certificate sequence. -.IP "\fBocsp\fR" 4 -.IX Item "ocsp" -Online Certificate Status Protocol command. -.IP "\fBpasswd\fR" 4 -.IX Item "passwd" -Generation of hashed passwords. -.IP "\fBpkcs12\fR" 4 -.IX Item "pkcs12" -PKCS#12 Data Management. -.IP "\fBpkcs7\fR" 4 -.IX Item "pkcs7" -PKCS#7 Data Management. -.IP "\fBpkcs8\fR" 4 -.IX Item "pkcs8" -PKCS#8 format private key conversion command. -.IP "\fBpkey\fR" 4 -.IX Item "pkey" -Public and private key management. -.IP "\fBpkeyparam\fR" 4 -.IX Item "pkeyparam" -Public key algorithm parameter management. -.IP "\fBpkeyutl\fR" 4 -.IX Item "pkeyutl" -Public key algorithm cryptographic operation command. -.IP "\fBprime\fR" 4 -.IX Item "prime" -Compute prime numbers. -.IP "\fBrand\fR" 4 -.IX Item "rand" -Generate pseudo-random bytes. -.IP "\fBrehash\fR" 4 -.IX Item "rehash" -Create symbolic links to certificate and \s-1CRL\s0 files named by the hash values. -.IP "\fBreq\fR" 4 -.IX Item "req" -PKCS#10 X.509 Certificate Signing Request (\s-1CSR\s0) Management. -.IP "\fBrsa\fR" 4 -.IX Item "rsa" -\&\s-1RSA\s0 key management. -.IP "\fBrsautl\fR" 4 -.IX Item "rsautl" -\&\s-1RSA\s0 command for signing, verification, encryption, and decryption. Superseded -by \fBopenssl\-pkeyutl\fR\|(1). -.IP "\fBs_client\fR" 4 -.IX Item "s_client" -This implements a generic \s-1SSL/TLS\s0 client which can establish a transparent -connection to a remote server speaking \s-1SSL/TLS.\s0 It's intended for testing -purposes only and provides only rudimentary interface functionality but -internally uses mostly all functionality of the OpenSSL \fBssl\fR library. -.IP "\fBs_server\fR" 4 -.IX Item "s_server" -This implements a generic \s-1SSL/TLS\s0 server which accepts connections from remote -clients speaking \s-1SSL/TLS.\s0 It's intended for testing purposes only and provides -only rudimentary interface functionality but internally uses mostly all -functionality of the OpenSSL \fBssl\fR library. It provides both an own command -line oriented protocol for testing \s-1SSL\s0 functions and a simple \s-1HTTP\s0 response -facility to emulate an SSL/TLS\-aware webserver. -.IP "\fBs_time\fR" 4 -.IX Item "s_time" -\&\s-1SSL\s0 Connection Timer. -.IP "\fBsess_id\fR" 4 -.IX Item "sess_id" -\&\s-1SSL\s0 Session Data Management. -.IP "\fBsmime\fR" 4 -.IX Item "smime" -S/MIME mail processing. -.IP "\fBspeed\fR" 4 -.IX Item "speed" -Algorithm Speed Measurement. -.IP "\fBspkac\fR" 4 -.IX Item "spkac" -\&\s-1SPKAC\s0 printing and generating command. -.IP "\fBsrp\fR" 4 -.IX Item "srp" -Maintain \s-1SRP\s0 password file. This command is deprecated. -.IP "\fBstoreutl\fR" 4 -.IX Item "storeutl" -Command to list and display certificates, keys, CRLs, etc. -.IP "\fBts\fR" 4 -.IX Item "ts" -Time Stamping Authority command. -.IP "\fBverify\fR" 4 -.IX Item "verify" -X.509 Certificate Verification. -See also the \fBopenssl\-verification\-options\fR\|(1) manual page. -.IP "\fBversion\fR" 4 -.IX Item "version" -OpenSSL Version Information. -.IP "\fBx509\fR" 4 -.IX Item "x509" -X.509 Certificate Data Management. -.SS "Message Digest Commands" -.IX Subsection "Message Digest Commands" -.IP "\fBblake2b512\fR" 4 -.IX Item "blake2b512" -BLAKE2b\-512 Digest -.IP "\fBblake2s256\fR" 4 -.IX Item "blake2s256" -BLAKE2s\-256 Digest -.IP "\fBmd2\fR" 4 -.IX Item "md2" -\&\s-1MD2\s0 Digest -.IP "\fBmd4\fR" 4 -.IX Item "md4" -\&\s-1MD4\s0 Digest -.IP "\fBmd5\fR" 4 -.IX Item "md5" -\&\s-1MD5\s0 Digest -.IP "\fBmdc2\fR" 4 -.IX Item "mdc2" -\&\s-1MDC2\s0 Digest -.IP "\fBrmd160\fR" 4 -.IX Item "rmd160" -\&\s-1RMD\-160\s0 Digest -.IP "\fBsha1\fR" 4 -.IX Item "sha1" -\&\s-1SHA\-1\s0 Digest -.IP "\fBsha224\fR" 4 -.IX Item "sha224" -\&\s-1SHA\-2 224\s0 Digest -.IP "\fBsha256\fR" 4 -.IX Item "sha256" -\&\s-1SHA\-2 256\s0 Digest -.IP "\fBsha384\fR" 4 -.IX Item "sha384" -\&\s-1SHA\-2 384\s0 Digest -.IP "\fBsha512\fR" 4 -.IX Item "sha512" -\&\s-1SHA\-2 512\s0 Digest -.IP "\fBsha3\-224\fR" 4 -.IX Item "sha3-224" -\&\s-1SHA\-3 224\s0 Digest -.IP "\fBsha3\-256\fR" 4 -.IX Item "sha3-256" -\&\s-1SHA\-3 256\s0 Digest -.IP "\fBsha3\-384\fR" 4 -.IX Item "sha3-384" -\&\s-1SHA\-3 384\s0 Digest -.IP "\fBsha3\-512\fR" 4 -.IX Item "sha3-512" -\&\s-1SHA\-3 512\s0 Digest -.IP "\fBkeccak\-224\fR" 4 -.IX Item "keccak-224" -\&\s-1KECCAK 224\s0 Digest -.IP "\fBkeccak\-256\fR" 4 -.IX Item "keccak-256" -\&\s-1KECCAK 256\s0 Digest -.IP "\fBkeccak\-384\fR" 4 -.IX Item "keccak-384" -\&\s-1KECCAK 384\s0 Digest -.IP "\fBkeccak\-512\fR" 4 -.IX Item "keccak-512" -\&\s-1KECCAK 512\s0 Digest -.IP "\fBshake128\fR" 4 -.IX Item "shake128" -\&\s-1SHA\-3 SHAKE128\s0 Digest -.IP "\fBshake256\fR" 4 -.IX Item "shake256" -\&\s-1SHA\-3 SHAKE256\s0 Digest -.IP "\fBsm3\fR" 4 -.IX Item "sm3" -\&\s-1SM3\s0 Digest -.SS "Encryption, Decryption, and Encoding Commands" -.IX Subsection "Encryption, Decryption, and Encoding Commands" -The following aliases provide convenient access to the most used encodings -and ciphers. -.PP -Depending on how OpenSSL was configured and built, not all ciphers listed -here may be present. See \fBopenssl\-enc\fR\|(1) for more information. -.IP "\fBaes128\fR, \fBaes\-128\-cbc\fR, \fBaes\-128\-cfb\fR, \fBaes\-128\-ctr\fR, \fBaes\-128\-ecb\fR, \fBaes\-128\-ofb\fR" 4 -.IX Item "aes128, aes-128-cbc, aes-128-cfb, aes-128-ctr, aes-128-ecb, aes-128-ofb" -\&\s-1AES\-128\s0 Cipher -.IP "\fBaes192\fR, \fBaes\-192\-cbc\fR, \fBaes\-192\-cfb\fR, \fBaes\-192\-ctr\fR, \fBaes\-192\-ecb\fR, \fBaes\-192\-ofb\fR" 4 -.IX Item "aes192, aes-192-cbc, aes-192-cfb, aes-192-ctr, aes-192-ecb, aes-192-ofb" -\&\s-1AES\-192\s0 Cipher -.IP "\fBaes256\fR, \fBaes\-256\-cbc\fR, \fBaes\-256\-cfb\fR, \fBaes\-256\-ctr\fR, \fBaes\-256\-ecb\fR, \fBaes\-256\-ofb\fR" 4 -.IX Item "aes256, aes-256-cbc, aes-256-cfb, aes-256-ctr, aes-256-ecb, aes-256-ofb" -\&\s-1AES\-256\s0 Cipher -.IP "\fBaria128\fR, \fBaria\-128\-cbc\fR, \fBaria\-128\-cfb\fR, \fBaria\-128\-ctr\fR, \fBaria\-128\-ecb\fR, \fBaria\-128\-ofb\fR" 4 -.IX Item "aria128, aria-128-cbc, aria-128-cfb, aria-128-ctr, aria-128-ecb, aria-128-ofb" -Aria\-128 Cipher -.IP "\fBaria192\fR, \fBaria\-192\-cbc\fR, \fBaria\-192\-cfb\fR, \fBaria\-192\-ctr\fR, \fBaria\-192\-ecb\fR, \fBaria\-192\-ofb\fR" 4 -.IX Item "aria192, aria-192-cbc, aria-192-cfb, aria-192-ctr, aria-192-ecb, aria-192-ofb" -Aria\-192 Cipher -.IP "\fBaria256\fR, \fBaria\-256\-cbc\fR, \fBaria\-256\-cfb\fR, \fBaria\-256\-ctr\fR, \fBaria\-256\-ecb\fR, \fBaria\-256\-ofb\fR" 4 -.IX Item "aria256, aria-256-cbc, aria-256-cfb, aria-256-ctr, aria-256-ecb, aria-256-ofb" -Aria\-256 Cipher -.IP "\fBbase64\fR" 4 -.IX Item "base64" -Base64 Encoding -.IP "\fBbf\fR, \fBbf-cbc\fR, \fBbf-cfb\fR, \fBbf-ecb\fR, \fBbf-ofb\fR" 4 -.IX Item "bf, bf-cbc, bf-cfb, bf-ecb, bf-ofb" -Blowfish Cipher -.IP "\fBcamellia128\fR, \fBcamellia\-128\-cbc\fR, \fBcamellia\-128\-cfb\fR, \fBcamellia\-128\-ctr\fR, \fBcamellia\-128\-ecb\fR, \fBcamellia\-128\-ofb\fR" 4 -.IX Item "camellia128, camellia-128-cbc, camellia-128-cfb, camellia-128-ctr, camellia-128-ecb, camellia-128-ofb" -Camellia\-128 Cipher -.IP "\fBcamellia192\fR, \fBcamellia\-192\-cbc\fR, \fBcamellia\-192\-cfb\fR, \fBcamellia\-192\-ctr\fR, \fBcamellia\-192\-ecb\fR, \fBcamellia\-192\-ofb\fR" 4 -.IX Item "camellia192, camellia-192-cbc, camellia-192-cfb, camellia-192-ctr, camellia-192-ecb, camellia-192-ofb" -Camellia\-192 Cipher -.IP "\fBcamellia256\fR, \fBcamellia\-256\-cbc\fR, \fBcamellia\-256\-cfb\fR, \fBcamellia\-256\-ctr\fR, \fBcamellia\-256\-ecb\fR, \fBcamellia\-256\-ofb\fR" 4 -.IX Item "camellia256, camellia-256-cbc, camellia-256-cfb, camellia-256-ctr, camellia-256-ecb, camellia-256-ofb" -Camellia\-256 Cipher -.IP "\fBcast\fR, \fBcast-cbc\fR" 4 -.IX Item "cast, cast-cbc" -\&\s-1CAST\s0 Cipher -.IP "\fBcast5\-cbc\fR, \fBcast5\-cfb\fR, \fBcast5\-ecb\fR, \fBcast5\-ofb\fR" 4 -.IX Item "cast5-cbc, cast5-cfb, cast5-ecb, cast5-ofb" -\&\s-1CAST5\s0 Cipher -.IP "\fBchacha20\fR" 4 -.IX Item "chacha20" -Chacha20 Cipher -.IP "\fBdes\fR, \fBdes-cbc\fR, \fBdes-cfb\fR, \fBdes-ecb\fR, \fBdes-ede\fR, \fBdes-ede-cbc\fR, \fBdes-ede-cfb\fR, \fBdes-ede-ofb\fR, \fBdes-ofb\fR" 4 -.IX Item "des, des-cbc, des-cfb, des-ecb, des-ede, des-ede-cbc, des-ede-cfb, des-ede-ofb, des-ofb" -\&\s-1DES\s0 Cipher -.IP "\fBdes3\fR, \fBdesx\fR, \fBdes\-ede3\fR, \fBdes\-ede3\-cbc\fR, \fBdes\-ede3\-cfb\fR, \fBdes\-ede3\-ofb\fR" 4 -.IX Item "des3, desx, des-ede3, des-ede3-cbc, des-ede3-cfb, des-ede3-ofb" -Triple-DES Cipher -.IP "\fBidea\fR, \fBidea-cbc\fR, \fBidea-cfb\fR, \fBidea-ecb\fR, \fBidea-ofb\fR" 4 -.IX Item "idea, idea-cbc, idea-cfb, idea-ecb, idea-ofb" -\&\s-1IDEA\s0 Cipher -.IP "\fBrc2\fR, \fBrc2\-cbc\fR, \fBrc2\-cfb\fR, \fBrc2\-ecb\fR, \fBrc2\-ofb\fR" 4 -.IX Item "rc2, rc2-cbc, rc2-cfb, rc2-ecb, rc2-ofb" -\&\s-1RC2\s0 Cipher -.IP "\fBrc4\fR" 4 -.IX Item "rc4" -\&\s-1RC4\s0 Cipher -.IP "\fBrc5\fR, \fBrc5\-cbc\fR, \fBrc5\-cfb\fR, \fBrc5\-ecb\fR, \fBrc5\-ofb\fR" 4 -.IX Item "rc5, rc5-cbc, rc5-cfb, rc5-ecb, rc5-ofb" -\&\s-1RC5\s0 Cipher -.IP "\fBseed\fR, \fBseed-cbc\fR, \fBseed-cfb\fR, \fBseed-ecb\fR, \fBseed-ofb\fR" 4 -.IX Item "seed, seed-cbc, seed-cfb, seed-ecb, seed-ofb" -\&\s-1SEED\s0 Cipher -.IP "\fBsm4\fR, \fBsm4\-cbc\fR, \fBsm4\-cfb\fR, \fBsm4\-ctr\fR, \fBsm4\-ecb\fR, \fBsm4\-ofb\fR" 4 -.IX Item "sm4, sm4-cbc, sm4-cfb, sm4-ctr, sm4-ecb, sm4-ofb" -\&\s-1SM4\s0 Cipher -.SH "OPTIONS" -.IX Header "OPTIONS" -Details of which options are available depend on the specific command. -This section describes some common options with common behavior. -.SS "Program Options" -.IX Subsection "Program Options" -These options can be specified without a command specified to get help -or version information. -.IP "\fB\-help\fR" 4 -.IX Item "-help" -Provides a terse summary of all options. -For more detailed information, each command supports a \fB\-help\fR option. -Accepts \fB\-\-help\fR as well. -.IP "\fB\-version\fR" 4 -.IX Item "-version" -Provides a terse summary of the \fBopenssl\fR program version. -For more detailed information see \fBopenssl\-version\fR\|(1). -Accepts \fB\-\-version\fR as well. -.SS "Common Options" -.IX Subsection "Common Options" -.IP "\fB\-help\fR" 4 -.IX Item "-help" -If an option takes an argument, the \*(L"type\*(R" of argument is also given. -.IP "\fB\-\-\fR" 4 -.IX Item "--" -This terminates the list of options. It is mostly useful if any filename -parameters start with a minus sign: -.Sp -.Vb 1 -\& openssl verify [flags...] \-\- \-cert1.pem... -.Ve -.SS "Format Options" -.IX Subsection "Format Options" -See \fBopenssl\-format\-options\fR\|(1) for manual page. -.SS "Pass Phrase Options" -.IX Subsection "Pass Phrase Options" -See the \fBopenssl\-passphrase\-options\fR\|(1) manual page. -.SS "Random State Options" -.IX Subsection "Random State Options" -Prior to OpenSSL 1.1.1, it was common for applications to store information -about the state of the random-number generator in a file that was loaded -at startup and rewritten upon exit. On modern operating systems, this is -generally no longer necessary as OpenSSL will seed itself from a trusted -entropy source provided by the operating system. These flags are still -supported for special platforms or circumstances that might require them. -.PP -It is generally an error to use the same seed file more than once and -every use of \fB\-rand\fR should be paired with \fB\-writerand\fR. -.IP "\fB\-rand\fR \fIfiles\fR" 4 -.IX Item "-rand files" -A file or files containing random data used to seed the random number -generator. -Multiple files can be specified separated by an OS-dependent character. -The separator is \f(CW\*(C`;\*(C'\fR for MS-Windows, \f(CW\*(C`,\*(C'\fR for OpenVMS, and \f(CW\*(C`:\*(C'\fR for -all others. Another way to specify multiple files is to repeat this flag -with different filenames. -.IP "\fB\-writerand\fR \fIfile\fR" 4 -.IX Item "-writerand file" -Writes the seed data to the specified \fIfile\fR upon exit. -This file can be used in a subsequent command invocation. -.SS "Certificate Verification Options" -.IX Subsection "Certificate Verification Options" -See the \fBopenssl\-verification\-options\fR\|(1) manual page. -.SS "Name Format Options" -.IX Subsection "Name Format Options" -See the \fBopenssl\-namedisplay\-options\fR\|(1) manual page. -.SS "\s-1TLS\s0 Version Options" -.IX Subsection "TLS Version Options" -Several commands use \s-1SSL, TLS,\s0 or \s-1DTLS.\s0 By default, the commands use \s-1TLS\s0 and -clients will offer the lowest and highest protocol version they support, -and servers will pick the highest version that the client offers that is also -supported by the server. -.PP -The options below can be used to limit which protocol versions are used, -and whether \s-1TCP\s0 (\s-1SSL\s0 and \s-1TLS\s0) or \s-1UDP\s0 (\s-1DTLS\s0) is used. -Note that not all protocols and flags may be available, depending on how -OpenSSL was built. -.IP "\fB\-ssl3\fR, \fB\-tls1\fR, \fB\-tls1_1\fR, \fB\-tls1_2\fR, \fB\-tls1_3\fR, \fB\-no_ssl3\fR, \fB\-no_tls1\fR, \fB\-no_tls1_1\fR, \fB\-no_tls1_2\fR, \fB\-no_tls1_3\fR" 4 -.IX Item "-ssl3, -tls1, -tls1_1, -tls1_2, -tls1_3, -no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3" -These options require or disable the use of the specified \s-1SSL\s0 or \s-1TLS\s0 protocols. -When a specific \s-1TLS\s0 version is required, only that version will be offered or -accepted. -Only one specific protocol can be given and it cannot be combined with any of -the \fBno_\fR options. -The \fBno_*\fR options do not work with \fBs_time\fR and \fBciphers\fR commands but work with -\&\fBs_client\fR and \fBs_server\fR commands. -.IP "\fB\-dtls\fR, \fB\-dtls1\fR, \fB\-dtls1_2\fR" 4 -.IX Item "-dtls, -dtls1, -dtls1_2" -These options specify to use \s-1DTLS\s0 instead of \s-1TLS.\s0 -With \fB\-dtls\fR, clients will negotiate any supported \s-1DTLS\s0 protocol version. -Use the \fB\-dtls1\fR or \fB\-dtls1_2\fR options to support only \s-1DTLS1.0\s0 or \s-1DTLS1.2,\s0 -respectively. -.SS "Engine Options" -.IX Subsection "Engine Options" -.IP "\fB\-engine\fR \fIid\fR" 4 -.IX Item "-engine id" -Load the engine identified by \fIid\fR and use all the methods it implements -(algorithms, key storage, etc.), unless specified otherwise in the -command-specific documentation or it is configured to do so, as described in -\&\*(L"Engine Configuration\*(R" in \fBconfig\fR\|(5). -.Sp -The engine will be used for key ids specified with \fB\-key\fR and similar -options when an option like \fB\-keyform engine\fR is given. -.Sp -A special case is the \f(CW\*(C`loader_attic\*(C'\fR engine, which -is meant just for internal OpenSSL testing purposes and -supports loading keys, parameters, certificates, and CRLs from files. -When this engine is used, files with such credentials are read via this engine. -Using the \f(CW\*(C`file:\*(C'\fR schema is optional; a plain file (path) name will do. -.PP -Options specifying keys, like \fB\-key\fR and similar, can use the generic -OpenSSL engine key loading \s-1URI\s0 scheme \f(CW\*(C`org.openssl.engine:\*(C'\fR to retrieve -private keys and public keys. The \s-1URI\s0 syntax is as follows, in simplified -form: -.PP -.Vb 1 -\& org.openssl.engine:{engineid}:{keyid} -.Ve -.PP -Where \f(CW\*(C`{engineid}\*(C'\fR is the identity/name of the engine, and \f(CW\*(C`{keyid}\*(C'\fR is a -key identifier that's acceptable by that engine. For example, when using an -engine that interfaces against a PKCS#11 implementation, the generic key \s-1URI\s0 -would be something like this (this happens to be an example for the PKCS#11 -engine that's part of OpenSC): -.PP -.Vb 1 -\& \-key org.openssl.engine:pkcs11:label_some\-private\-key -.Ve -.PP -As a third possibility, for engines and providers that have implemented -their own \s-1\fBOSSL_STORE_LOADER\s0\fR\|(3), \f(CW\*(C`org.openssl.engine:\*(C'\fR should not be -necessary. For a PKCS#11 implementation that has implemented such a loader, -the PKCS#11 \s-1URI\s0 as defined in \s-1RFC 7512\s0 should be possible to use directly: -.PP -.Vb 1 -\& \-key pkcs11:object=some\-private\-key;pin\-value=1234 -.Ve -.SS "Provider Options" -.IX Subsection "Provider Options" -.IP "\fB\-provider\fR \fIname\fR" 4 -.IX Item "-provider name" -Load and initialize the provider identified by \fIname\fR. The \fIname\fR -can be also a path to the provider module. In that case the provider name -will be the specified path and not just the provider module name. -Interpretation of relative paths is platform specific. The configured -\&\*(L"\s-1MODULESDIR\*(R"\s0 path, \fB\s-1OPENSSL_MODULES\s0\fR environment variable, or the path -specified by \fB\-provider\-path\fR is prepended to relative paths. -See \fBprovider\fR\|(7) for a more detailed description. -.IP "\fB\-provider\-path\fR \fIpath\fR" 4 -.IX Item "-provider-path path" -Specifies the search path that is to be used for looking for providers. -Equivalently, the \fB\s-1OPENSSL_MODULES\s0\fR environment variable may be set. -.IP "\fB\-propquery\fR \fIpropq\fR" 4 -.IX Item "-propquery propq" -Specifies the \fIproperty query clause\fR to be used when fetching algorithms -from the loaded providers. -See \fBproperty\fR\|(7) for a more detailed description. -.SH "ENVIRONMENT" -.IX Header "ENVIRONMENT" -The OpenSSL libraries can take some configuration parameters from the -environment. -.PP -For information about all environment variables used by the OpenSSL libraries, -such as \fB\s-1OPENSSL_CONF\s0\fR, \fB\s-1OPENSSL_MODULES\s0\fR, and \fB\s-1OPENSSL_TRACE\s0\fR, -see \fBopenssl\-env\fR\|(7). -.PP -For information about the use of environment variables in configuration, -see \*(L"\s-1ENVIRONMENT\*(R"\s0 in \fBconfig\fR\|(5). -.PP -For information about specific commands, see \fBopenssl\-engine\fR\|(1), -\&\fBopenssl\-rehash\fR\|(1), and \fBtsget\fR\|(1). -.PP -For information about querying or specifying \s-1CPU\s0 architecture flags, see -\&\fBOPENSSL_ia32cap\fR\|(3), \fBOPENSSL_s390xcap\fR\|(3) and \fBOPENSSL_riscvcap\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-asn1parse\fR\|(1), -\&\fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-ciphers\fR\|(1), -\&\fBopenssl\-cms\fR\|(1), -\&\fBopenssl\-crl\fR\|(1), -\&\fBopenssl\-crl2pkcs7\fR\|(1), -\&\fBopenssl\-dgst\fR\|(1), -\&\fBopenssl\-dhparam\fR\|(1), -\&\fBopenssl\-dsa\fR\|(1), -\&\fBopenssl\-dsaparam\fR\|(1), -\&\fBopenssl\-ec\fR\|(1), -\&\fBopenssl\-ecparam\fR\|(1), -\&\fBopenssl\-enc\fR\|(1), -\&\fBopenssl\-engine\fR\|(1), -\&\fBopenssl\-errstr\fR\|(1), -\&\fBopenssl\-gendsa\fR\|(1), -\&\fBopenssl\-genpkey\fR\|(1), -\&\fBopenssl\-genrsa\fR\|(1), -\&\fBopenssl\-kdf\fR\|(1), -\&\fBopenssl\-list\fR\|(1), -\&\fBopenssl\-mac\fR\|(1), -\&\fBopenssl\-nseq\fR\|(1), -\&\fBopenssl\-ocsp\fR\|(1), -\&\fBopenssl\-passwd\fR\|(1), -\&\fBopenssl\-pkcs12\fR\|(1), -\&\fBopenssl\-pkcs7\fR\|(1), -\&\fBopenssl\-pkcs8\fR\|(1), -\&\fBopenssl\-pkey\fR\|(1), -\&\fBopenssl\-pkeyparam\fR\|(1), -\&\fBopenssl\-pkeyutl\fR\|(1), -\&\fBopenssl\-prime\fR\|(1), -\&\fBopenssl\-rand\fR\|(1), -\&\fBopenssl\-rehash\fR\|(1), -\&\fBopenssl\-req\fR\|(1), -\&\fBopenssl\-rsa\fR\|(1), -\&\fBopenssl\-rsautl\fR\|(1), -\&\fBopenssl\-s_client\fR\|(1), -\&\fBopenssl\-s_server\fR\|(1), -\&\fBopenssl\-s_time\fR\|(1), -\&\fBopenssl\-sess_id\fR\|(1), -\&\fBopenssl\-smime\fR\|(1), -\&\fBopenssl\-speed\fR\|(1), -\&\fBopenssl\-spkac\fR\|(1), -\&\fBopenssl\-srp\fR\|(1), -\&\fBopenssl\-storeutl\fR\|(1), -\&\fBopenssl\-ts\fR\|(1), -\&\fBopenssl\-verify\fR\|(1), -\&\fBopenssl\-version\fR\|(1), -\&\fBopenssl\-x509\fR\|(1), -\&\fBconfig\fR\|(5), -\&\fBcrypto\fR\|(7), -\&\fBopenssl\-env\fR\|(7). -\&\fBssl\fR\|(7), -\&\fBx509v3_config\fR\|(5) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBlist\fR \-\fI\s-1XXX\s0\fR\fB\-algorithms\fR options were added in OpenSSL 1.0.0; -For notes on the availability of other commands, see their individual -manual pages. -.PP -The \fB\-issuer_checks\fR option is deprecated as of OpenSSL 1.1.0 and -is silently ignored. -.PP -The \fB\-xcertform\fR and \fB\-xkeyform\fR options -are obsolete since OpenSSL 3.0 and have no effect. -.PP -The interactive mode, which could be invoked by running \f(CW\*(C`openssl\*(C'\fR -with no further arguments, was removed in OpenSSL 3.0, and running -that program with no arguments is now equivalent to \f(CW\*(C`openssl help\*(C'\fR. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/passwd.1ossl b/openssl-install/share/man/man1/passwd.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/passwd.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/pkcs12.1ossl b/openssl-install/share/man/man1/pkcs12.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/pkcs12.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/pkcs7.1ossl b/openssl-install/share/man/man1/pkcs7.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/pkcs7.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/pkcs8.1ossl b/openssl-install/share/man/man1/pkcs8.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/pkcs8.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/pkey.1ossl b/openssl-install/share/man/man1/pkey.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/pkey.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/pkeyparam.1ossl b/openssl-install/share/man/man1/pkeyparam.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/pkeyparam.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/pkeyutl.1ossl b/openssl-install/share/man/man1/pkeyutl.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/pkeyutl.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/prime.1ossl b/openssl-install/share/man/man1/prime.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/prime.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/rand.1ossl b/openssl-install/share/man/man1/rand.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/rand.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/rehash.1ossl b/openssl-install/share/man/man1/rehash.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/rehash.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/req.1ossl b/openssl-install/share/man/man1/req.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/req.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/rsa.1ossl b/openssl-install/share/man/man1/rsa.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/rsa.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/rsautl.1ossl b/openssl-install/share/man/man1/rsautl.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/rsautl.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/s_client.1ossl b/openssl-install/share/man/man1/s_client.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/s_client.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/s_server.1ossl b/openssl-install/share/man/man1/s_server.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/s_server.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/s_time.1ossl b/openssl-install/share/man/man1/s_time.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/s_time.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/sess_id.1ossl b/openssl-install/share/man/man1/sess_id.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/sess_id.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/smime.1ossl b/openssl-install/share/man/man1/smime.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/smime.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/speed.1ossl b/openssl-install/share/man/man1/speed.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/speed.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/spkac.1ossl b/openssl-install/share/man/man1/spkac.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/spkac.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/srp.1ossl b/openssl-install/share/man/man1/srp.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/srp.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/storeutl.1ossl b/openssl-install/share/man/man1/storeutl.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/storeutl.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/ts.1ossl b/openssl-install/share/man/man1/ts.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/ts.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/tsget.1ossl b/openssl-install/share/man/man1/tsget.1ossl deleted file mode 100644 index ce18868c..00000000 --- a/openssl-install/share/man/man1/tsget.1ossl +++ /dev/null @@ -1,324 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "TSGET 1ossl" -.TH TSGET 1ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -tsget \- Time Stamping HTTP/HTTPS client -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -\&\fBtsget\fR -\&\fB\-h\fR \fIserver_url\fR -[\fB\-e\fR \fIextension\fR] -[\fB\-o\fR \fIoutput\fR] -[\fB\-v\fR] -[\fB\-d\fR] -[\fB\-k\fR \fIprivate_key.pem\fR] -[\fB\-p\fR \fIkey_password\fR] -[\fB\-c\fR \fIclient_cert.pem\fR] -[\fB\-C\fR \fICA_certs.pem\fR] -[\fB\-P\fR \fICA_path\fR] -[\fB\-r\fR \fIfiles\fR] -[\fB\-g\fR \fIEGD_socket\fR] -[\fIrequest\fR ...] -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This command can be used for sending a timestamp request, as specified -in \s-1RFC 3161,\s0 to a timestamp server over \s-1HTTP\s0 or \s-1HTTPS\s0 and storing the -timestamp response in a file. It cannot be used for creating the requests -and verifying responses, you have to use \fBopenssl\-ts\fR\|(1) to do that. This -command can send several requests to the server without closing the \s-1TCP\s0 -connection if more than one requests are specified on the command line. -.PP -This command sends the following \s-1HTTP\s0 request for each timestamp request: -.PP -.Vb 7 -\& POST url HTTP/1.1 -\& User\-Agent: OpenTSA tsget.pl/ -\& Host: : -\& Pragma: no\-cache -\& Content\-Type: application/timestamp\-query -\& Accept: application/timestamp\-reply -\& Content\-Length: length of body -\& -\& ...binary request specified by the user... -.Ve -.PP -It expects a response of type application/timestamp\-reply, which is -written to a file without any interpretation. -.SH "OPTIONS" -.IX Header "OPTIONS" -.IP "\fB\-h\fR \fIserver_url\fR" 4 -.IX Item "-h server_url" -The \s-1URL\s0 of the \s-1HTTP/HTTPS\s0 server listening for timestamp requests. -.IP "\fB\-e\fR \fIextension\fR" 4 -.IX Item "-e extension" -If the \fB\-o\fR option is not given this argument specifies the extension of the -output files. The base name of the output file will be the same as those of -the input files. Default extension is \fI.tsr\fR. (Optional) -.IP "\fB\-o\fR \fIoutput\fR" 4 -.IX Item "-o output" -This option can be specified only when just one request is sent to the -server. The timestamp response will be written to the given output file. '\-' -means standard output. In case of multiple timestamp requests or the absence -of this argument the names of the output files will be derived from the names -of the input files and the default or specified extension argument. (Optional) -.IP "\fB\-v\fR" 4 -.IX Item "-v" -The name of the currently processed request is printed on standard -error. (Optional) -.IP "\fB\-d\fR" 4 -.IX Item "-d" -Switches on verbose mode for the underlying perl module WWW::Curl::Easy. -You can see detailed debug messages for the connection. (Optional) -.IP "\fB\-k\fR \fIprivate_key.pem\fR" 4 -.IX Item "-k private_key.pem" -(\s-1HTTPS\s0) In case of certificate-based client authentication over \s-1HTTPS\s0 -\&\fIprivate_key.pem\fR must contain the private key of the user. The private key -file can optionally be protected by a passphrase. The \fB\-c\fR option must also -be specified. (Optional) -.IP "\fB\-p\fR \fIkey_password\fR" 4 -.IX Item "-p key_password" -(\s-1HTTPS\s0) Specifies the passphrase for the private key specified by the \fB\-k\fR -argument. If this option is omitted and the key is passphrase protected, -it will be prompted for. (Optional) -.IP "\fB\-c\fR \fIclient_cert.pem\fR" 4 -.IX Item "-c client_cert.pem" -(\s-1HTTPS\s0) In case of certificate-based client authentication over \s-1HTTPS\s0 -\&\fIclient_cert.pem\fR must contain the X.509 certificate of the user. The \fB\-k\fR -option must also be specified. If this option is not specified no -certificate-based client authentication will take place. (Optional) -.IP "\fB\-C\fR \fICA_certs.pem\fR" 4 -.IX Item "-C CA_certs.pem" -(\s-1HTTPS\s0) The trusted \s-1CA\s0 certificate store. The certificate chain of the peer's -certificate must include one of the \s-1CA\s0 certificates specified in this file. -Either option \fB\-C\fR or option \fB\-P\fR must be given in case of \s-1HTTPS.\s0 (Optional) -.IP "\fB\-P\fR \fICA_path\fR" 4 -.IX Item "-P CA_path" -(\s-1HTTPS\s0) The path containing the trusted \s-1CA\s0 certificates to verify the peer's -certificate. The directory must be prepared with \fBopenssl\-rehash\fR\|(1). Either -option \fB\-C\fR or option \fB\-P\fR must be given in case of \s-1HTTPS.\s0 (Optional) -.IP "\fB\-r\fR \fIfiles\fR" 4 -.IX Item "-r files" -See \*(L"Random State Options\*(R" in \fBopenssl\fR\|(1) for more information. -.IP "\fB\-g\fR \fIEGD_socket\fR" 4 -.IX Item "-g EGD_socket" -The name of an \s-1EGD\s0 socket to get random data from. (Optional) -.IP "\fIrequest\fR ..." 4 -.IX Item "request ..." -List of files containing \s-1RFC 3161\s0 DER-encoded timestamp requests. If no -requests are specified only one request will be sent to the server and it will -be read from the standard input. -(Optional) -.SH "ENVIRONMENT VARIABLES" -.IX Header "ENVIRONMENT VARIABLES" -The \fB\s-1TSGET\s0\fR environment variable can optionally contain default -arguments. The content of this variable is added to the list of command line -arguments. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The examples below presume that \fIfile1.tsq\fR and \fIfile2.tsq\fR contain valid -timestamp requests, tsa.opentsa.org listens at port 8080 for \s-1HTTP\s0 requests -and at port 8443 for \s-1HTTPS\s0 requests, the \s-1TSA\s0 service is available at the /tsa -absolute path. -.PP -Get a timestamp response for \fIfile1.tsq\fR over \s-1HTTP,\s0 output is written to -\&\fIfile1.tsr\fR: -.PP -.Vb 1 -\& tsget \-h http://tsa.opentsa.org:8080/tsa file1.tsq -.Ve -.PP -Get a timestamp response for \fIfile1.tsq\fR and \fIfile2.tsq\fR over \s-1HTTP\s0 showing -progress, output is written to \fIfile1.reply\fR and \fIfile2.reply\fR respectively: -.PP -.Vb 2 -\& tsget \-h http://tsa.opentsa.org:8080/tsa \-v \-e .reply \e -\& file1.tsq file2.tsq -.Ve -.PP -Create a timestamp request, write it to \fIfile3.tsq\fR, send it to the server and -write the response to \fIfile3.tsr\fR: -.PP -.Vb 3 -\& openssl ts \-query \-data file3.txt \-cert | tee file3.tsq \e -\& | tsget \-h http://tsa.opentsa.org:8080/tsa \e -\& \-o file3.tsr -.Ve -.PP -Get a timestamp response for \fIfile1.tsq\fR over \s-1HTTPS\s0 without client -authentication: -.PP -.Vb 2 -\& tsget \-h https://tsa.opentsa.org:8443/tsa \e -\& \-C cacerts.pem file1.tsq -.Ve -.PP -Get a timestamp response for \fIfile1.tsq\fR over \s-1HTTPS\s0 with certificate-based -client authentication (it will ask for the passphrase if \fIclient_key.pem\fR is -protected): -.PP -.Vb 2 -\& tsget \-h https://tsa.opentsa.org:8443/tsa \-C cacerts.pem \e -\& \-k client_key.pem \-c client_cert.pem file1.tsq -.Ve -.PP -You can shorten the previous command line if you make use of the \fB\s-1TSGET\s0\fR -environment variable. The following commands do the same as the previous -example: -.PP -.Vb 4 -\& TSGET=\*(Aq\-h https://tsa.opentsa.org:8443/tsa \-C cacerts.pem \e -\& \-k client_key.pem \-c client_cert.pem\*(Aq -\& export TSGET -\& tsget file1.tsq -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), -\&\fBopenssl\-ts\fR\|(1), -WWW::Curl::Easy, - -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man1/verify.1ossl b/openssl-install/share/man/man1/verify.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/verify.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/version.1ossl b/openssl-install/share/man/man1/version.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/version.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man1/x509.1ossl b/openssl-install/share/man/man1/x509.1ossl deleted file mode 120000 index 6dc9ff24..00000000 --- a/openssl-install/share/man/man1/x509.1ossl +++ /dev/null @@ -1 +0,0 @@ -openssl-cmds.1ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ACCESS_DESCRIPTION_free.3ossl b/openssl-install/share/man/man3/ACCESS_DESCRIPTION_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ACCESS_DESCRIPTION_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ACCESS_DESCRIPTION_new.3ossl b/openssl-install/share/man/man3/ACCESS_DESCRIPTION_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ACCESS_DESCRIPTION_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS.3ossl b/openssl-install/share/man/man3/ADMISSIONS.3ossl deleted file mode 100644 index 970f12a0..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS.3ossl +++ /dev/null @@ -1,311 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ADMISSIONS 3ossl" -.TH ADMISSIONS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ADMISSIONS, -ADMISSIONS_get0_admissionAuthority, -ADMISSIONS_get0_namingAuthority, -ADMISSIONS_get0_professionInfos, -ADMISSIONS_set0_admissionAuthority, -ADMISSIONS_set0_namingAuthority, -ADMISSIONS_set0_professionInfos, -ADMISSION_SYNTAX, -ADMISSION_SYNTAX_get0_admissionAuthority, -ADMISSION_SYNTAX_get0_contentsOfAdmissions, -ADMISSION_SYNTAX_set0_admissionAuthority, -ADMISSION_SYNTAX_set0_contentsOfAdmissions, -NAMING_AUTHORITY, -NAMING_AUTHORITY_get0_authorityId, -NAMING_AUTHORITY_get0_authorityURL, -NAMING_AUTHORITY_get0_authorityText, -NAMING_AUTHORITY_set0_authorityId, -NAMING_AUTHORITY_set0_authorityURL, -NAMING_AUTHORITY_set0_authorityText, -PROFESSION_INFO, -PROFESSION_INFOS, -PROFESSION_INFO_get0_addProfessionInfo, -PROFESSION_INFO_get0_namingAuthority, -PROFESSION_INFO_get0_professionItems, -PROFESSION_INFO_get0_professionOIDs, -PROFESSION_INFO_get0_registrationNumber, -PROFESSION_INFO_set0_addProfessionInfo, -PROFESSION_INFO_set0_namingAuthority, -PROFESSION_INFO_set0_professionItems, -PROFESSION_INFO_set0_professionOIDs, -PROFESSION_INFO_set0_registrationNumber -\&\- Accessors and settors for ADMISSION_SYNTAX -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 5 -\& typedef struct NamingAuthority_st NAMING_AUTHORITY; -\& typedef struct ProfessionInfo_st PROFESSION_INFO; -\& typedef STACK_OF(PROFESSION_INFO) PROFESSION_INFOS; -\& typedef struct Admissions_st ADMISSIONS; -\& typedef struct AdmissionSyntax_st ADMISSION_SYNTAX; -\& -\& const ASN1_OBJECT *NAMING_AUTHORITY_get0_authorityId( -\& const NAMING_AUTHORITY *n); -\& void NAMING_AUTHORITY_set0_authorityId(NAMING_AUTHORITY *n, -\& ASN1_OBJECT* namingAuthorityId); -\& const ASN1_IA5STRING *NAMING_AUTHORITY_get0_authorityURL( -\& const NAMING_AUTHORITY *n); -\& void NAMING_AUTHORITY_set0_authorityURL(NAMING_AUTHORITY *n, -\& ASN1_IA5STRING* namingAuthorityUrl); -\& const ASN1_STRING *NAMING_AUTHORITY_get0_authorityText( -\& const NAMING_AUTHORITY *n); -\& void NAMING_AUTHORITY_set0_authorityText(NAMING_AUTHORITY *n, -\& ASN1_STRING* namingAuthorityText); -\& -\& const GENERAL_NAME *ADMISSION_SYNTAX_get0_admissionAuthority( -\& const ADMISSION_SYNTAX *as); -\& void ADMISSION_SYNTAX_set0_admissionAuthority( -\& ADMISSION_SYNTAX *as, GENERAL_NAME *aa); -\& const STACK_OF(ADMISSIONS) *ADMISSION_SYNTAX_get0_contentsOfAdmissions( -\& const ADMISSION_SYNTAX *as); -\& void ADMISSION_SYNTAX_set0_contentsOfAdmissions( -\& ADMISSION_SYNTAX *as, STACK_OF(ADMISSIONS) *a); -\& -\& const GENERAL_NAME *ADMISSIONS_get0_admissionAuthority(const ADMISSIONS *a); -\& void ADMISSIONS_set0_admissionAuthority(ADMISSIONS *a, GENERAL_NAME *aa); -\& const NAMING_AUTHORITY *ADMISSIONS_get0_namingAuthority(const ADMISSIONS *a); -\& void ADMISSIONS_set0_namingAuthority(ADMISSIONS *a, NAMING_AUTHORITY *na); -\& const PROFESSION_INFOS *ADMISSIONS_get0_professionInfos(const ADMISSIONS *a); -\& void ADMISSIONS_set0_professionInfos(ADMISSIONS *a, PROFESSION_INFOS *pi); -\& -\& const ASN1_OCTET_STRING *PROFESSION_INFO_get0_addProfessionInfo( -\& const PROFESSION_INFO *pi); -\& void PROFESSION_INFO_set0_addProfessionInfo( -\& PROFESSION_INFO *pi, ASN1_OCTET_STRING *aos); -\& const NAMING_AUTHORITY *PROFESSION_INFO_get0_namingAuthority( -\& const PROFESSION_INFO *pi); -\& void PROFESSION_INFO_set0_namingAuthority( -\& PROFESSION_INFO *pi, NAMING_AUTHORITY *na); -\& const STACK_OF(ASN1_STRING) *PROFESSION_INFO_get0_professionItems( -\& const PROFESSION_INFO *pi); -\& void PROFESSION_INFO_set0_professionItems( -\& PROFESSION_INFO *pi, STACK_OF(ASN1_STRING) *as); -\& const STACK_OF(ASN1_OBJECT) *PROFESSION_INFO_get0_professionOIDs( -\& const PROFESSION_INFO *pi); -\& void PROFESSION_INFO_set0_professionOIDs( -\& PROFESSION_INFO *pi, STACK_OF(ASN1_OBJECT) *po); -\& const ASN1_PRINTABLESTRING *PROFESSION_INFO_get0_registrationNumber( -\& const PROFESSION_INFO *pi); -\& void PROFESSION_INFO_set0_registrationNumber( -\& PROFESSION_INFO *pi, ASN1_PRINTABLESTRING *rn); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1PROFESSION_INFOS\s0\fR, \fB\s-1ADMISSION_SYNTAX\s0\fR, \fB\s-1ADMISSIONS\s0\fR, and -\&\fB\s-1PROFESSION_INFO\s0\fR types are opaque structures representing the -analogous types defined in the Common \s-1PKI\s0 Specification published -by . -Knowledge of those structures and their semantics is assumed. -.PP -The conventional routines to convert between \s-1DER\s0 and the local format -are described in \fBd2i_X509\fR\|(3). -The conventional routines to allocate and free the types are defined -in \fBX509_dup\fR\|(3). -.PP -The \fB\s-1PROFESSION_INFOS\s0\fR type is a stack of \fB\s-1PROFESSION_INFO\s0\fR; see -\&\s-1\fBDEFINE_STACK_OF\s0\fR\|(3) for details. -.PP -The \fB\s-1NAMING_AUTHORITY\s0\fR type has an authority \s-1ID\s0 and \s-1URL,\s0 and text fields. -The \fBNAMING_AUTHORITY_get0_authorityId()\fR, -\&\fBNAMING_AUTHORITY_get0_get0_authorityURL()\fR, and -\&\fBNAMING_AUTHORITY_get0_get0_authorityText()\fR, functions return pointers -to those values within the object. -The \fBNAMING_AUTHORITY_set0_authorityId()\fR, -\&\fBNAMING_AUTHORITY_set0_get0_authorityURL()\fR, and -\&\fBNAMING_AUTHORITY_set0_get0_authorityText()\fR, -functions free any existing value and set the pointer to the specified value. -.PP -The \fB\s-1ADMISSION_SYNTAX\s0\fR type has an authority name and a stack of -\&\fB\s-1ADMISSION\s0\fR objects. -The \fBADMISSION_SYNTAX_get0_admissionAuthority()\fR -and \fBADMISSION_SYNTAX_get0_contentsOfAdmissions()\fR functions return pointers -to those values within the object. -The -\&\fBADMISSION_SYNTAX_set0_admissionAuthority()\fR and -\&\fBADMISSION_SYNTAX_set0_contentsOfAdmissions()\fR -functions free any existing value and set the pointer to the specified value. -.PP -The \fB\s-1ADMISSION\s0\fR type has an authority name, authority object, and a -stack of \fB\s-1PROFESSION_INFO\s0\fR items. -The \fBADMISSIONS_get0_admissionAuthority()\fR, \fBADMISSIONS_get0_namingAuthority()\fR, -and \fBADMISSIONS_get0_professionInfos()\fR -functions return pointers to those values within the object. -The -\&\fBADMISSIONS_set0_admissionAuthority()\fR, -\&\fBADMISSIONS_set0_namingAuthority()\fR, and -\&\fBADMISSIONS_set0_professionInfos()\fR -functions free any existing value and set the pointer to the specified value. -.PP -The \fB\s-1PROFESSION_INFO\s0\fR type has a name authority, stacks of -profession Items and OIDs, a registration number, and additional -profession info. -The functions \fBPROFESSION_INFO_get0_addProfessionInfo()\fR, -\&\fBPROFESSION_INFO_get0_namingAuthority()\fR, \fBPROFESSION_INFO_get0_professionItems()\fR, -\&\fBPROFESSION_INFO_get0_professionOIDs()\fR, and -\&\fBPROFESSION_INFO_get0_registrationNumber()\fR -functions return pointers to those values within the object. -The -\&\fBPROFESSION_INFO_set0_addProfessionInfo()\fR, -\&\fBPROFESSION_INFO_set0_namingAuthority()\fR, -\&\fBPROFESSION_INFO_set0_professionItems()\fR, -\&\fBPROFESSION_INFO_set0_professionOIDs()\fR, and -\&\fBPROFESSION_INFO_set0_registrationNumber()\fR -functions free any existing value and set the pointer to the specified value. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Described above. -Note that all of the \fIget0\fR functions return a pointer to the internal data -structure and must not be freed. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_dup\fR\|(3), -\&\fBd2i_X509\fR\|(3), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ADMISSIONS_free.3ossl b/openssl-install/share/man/man3/ADMISSIONS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS_get0_admissionAuthority.3ossl b/openssl-install/share/man/man3/ADMISSIONS_get0_admissionAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_get0_admissionAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS_get0_namingAuthority.3ossl b/openssl-install/share/man/man3/ADMISSIONS_get0_namingAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_get0_namingAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS_get0_professionInfos.3ossl b/openssl-install/share/man/man3/ADMISSIONS_get0_professionInfos.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_get0_professionInfos.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS_new.3ossl b/openssl-install/share/man/man3/ADMISSIONS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS_set0_admissionAuthority.3ossl b/openssl-install/share/man/man3/ADMISSIONS_set0_admissionAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_set0_admissionAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS_set0_namingAuthority.3ossl b/openssl-install/share/man/man3/ADMISSIONS_set0_namingAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_set0_namingAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSIONS_set0_professionInfos.3ossl b/openssl-install/share/man/man3/ADMISSIONS_set0_professionInfos.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSIONS_set0_professionInfos.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSION_SYNTAX.3ossl b/openssl-install/share/man/man3/ADMISSION_SYNTAX.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSION_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSION_SYNTAX_free.3ossl b/openssl-install/share/man/man3/ADMISSION_SYNTAX_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ADMISSION_SYNTAX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_admissionAuthority.3ossl b/openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_admissionAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_admissionAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_contentsOfAdmissions.3ossl b/openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_contentsOfAdmissions.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSION_SYNTAX_get0_contentsOfAdmissions.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSION_SYNTAX_new.3ossl b/openssl-install/share/man/man3/ADMISSION_SYNTAX_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ADMISSION_SYNTAX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_admissionAuthority.3ossl b/openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_admissionAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_admissionAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_contentsOfAdmissions.3ossl b/openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_contentsOfAdmissions.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/ADMISSION_SYNTAX_set0_contentsOfAdmissions.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASIdOrRange_free.3ossl b/openssl-install/share/man/man3/ASIdOrRange_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASIdOrRange_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASIdOrRange_new.3ossl b/openssl-install/share/man/man3/ASIdOrRange_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASIdOrRange_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASIdentifierChoice_free.3ossl b/openssl-install/share/man/man3/ASIdentifierChoice_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASIdentifierChoice_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASIdentifierChoice_new.3ossl b/openssl-install/share/man/man3/ASIdentifierChoice_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASIdentifierChoice_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASIdentifiers_free.3ossl b/openssl-install/share/man/man3/ASIdentifiers_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASIdentifiers_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASIdentifiers_new.3ossl b/openssl-install/share/man/man3/ASIdentifiers_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASIdentifiers_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_AUX.3ossl b/openssl-install/share/man/man3/ASN1_AUX.3ossl deleted file mode 120000 index ec226b0c..00000000 --- a/openssl-install/share/man/man3/ASN1_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_aux_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ENUMERATED_get.3ossl b/openssl-install/share/man/man3/ASN1_ENUMERATED_get.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_ENUMERATED_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ENUMERATED_get_int64.3ossl b/openssl-install/share/man/man3/ASN1_ENUMERATED_get_int64.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_ENUMERATED_get_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ENUMERATED_set.3ossl b/openssl-install/share/man/man3/ASN1_ENUMERATED_set.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_ENUMERATED_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ENUMERATED_set_int64.3ossl b/openssl-install/share/man/man3/ASN1_ENUMERATED_set_int64.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_ENUMERATED_set_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ENUMERATED_to_BN.3ossl b/openssl-install/share/man/man3/ASN1_ENUMERATED_to_BN.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_ENUMERATED_to_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_EXTERN_FUNCS.3ossl b/openssl-install/share/man/man3/ASN1_EXTERN_FUNCS.3ossl deleted file mode 100644 index 69d28d7b..00000000 --- a/openssl-install/share/man/man3/ASN1_EXTERN_FUNCS.3ossl +++ /dev/null @@ -1,299 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_EXTERN_FUNCS 3ossl" -.TH ASN1_EXTERN_FUNCS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_EXTERN_FUNCS, ASN1_ex_d2i, ASN1_ex_d2i_ex, ASN1_ex_i2d, ASN1_ex_new_func, -ASN1_ex_new_ex_func, ASN1_ex_free_func, ASN1_ex_print_func, -IMPLEMENT_EXTERN_ASN1 -\&\- ASN.1 external function support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int ASN1_ex_d2i(ASN1_VALUE **pval, const unsigned char **in, long len, -\& const ASN1_ITEM *it, int tag, int aclass, char opt, -\& ASN1_TLC *ctx); -\& typedef int ASN1_ex_d2i_ex(ASN1_VALUE **pval, const unsigned char **in, long len, -\& const ASN1_ITEM *it, int tag, int aclass, char opt, -\& ASN1_TLC *ctx, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& typedef int ASN1_ex_i2d(const ASN1_VALUE **pval, unsigned char **out, -\& const ASN1_ITEM *it, int tag, int aclass); -\& typedef int ASN1_ex_new_func(ASN1_VALUE **pval, const ASN1_ITEM *it); -\& typedef int ASN1_ex_new_ex_func(ASN1_VALUE **pval, const ASN1_ITEM *it, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& typedef void ASN1_ex_free_func(ASN1_VALUE **pval, const ASN1_ITEM *it); -\& typedef int ASN1_ex_print_func(BIO *out, const ASN1_VALUE **pval, -\& int indent, const char *fname, -\& const ASN1_PCTX *pctx); -\& -\& struct ASN1_EXTERN_FUNCS_st { -\& void *app_data; -\& ASN1_ex_new_func *asn1_ex_new; -\& ASN1_ex_free_func *asn1_ex_free; -\& ASN1_ex_free_func *asn1_ex_clear; -\& ASN1_ex_d2i *asn1_ex_d2i; -\& ASN1_ex_i2d *asn1_ex_i2d; -\& ASN1_ex_print_func *asn1_ex_print; -\& ASN1_ex_new_ex_func *asn1_ex_new_ex; -\& ASN1_ex_d2i_ex *asn1_ex_d2i_ex; -\& }; -\& typedef struct ASN1_EXTERN_FUNCS_st ASN1_EXTERN_FUNCS; -\& -\& #define IMPLEMENT_EXTERN_ASN1(sname, tag, fptrs) -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1ASN.1\s0 data structures templates are typically defined in OpenSSL using a series -of macros such as \s-1\fBASN1_SEQUENCE\s0()\fR, \s-1\fBASN1_SEQUENCE_END\s0()\fR and so on. Instead -templates can also be defined based entirely on external functions. These -external functions are called to perform operations such as creating a new -\&\fB\s-1ASN1_VALUE\s0\fR or converting an \fB\s-1ASN1_VALUE\s0\fR to or from \s-1DER\s0 encoding. -.PP -The macro \s-1\fBIMPLEMENT_EXTERN_ASN1\s0()\fR can be used to create such an externally -defined structure. The name of the structure should be supplied in the \fIsname\fR -parameter. The tag for the structure (e.g. typically \fBV_ASN1_SEQUENCE\fR) should -be supplied in the \fItag\fR parameter. Finally a pointer to an -\&\fB\s-1ASN1_EXTERN_FUNCS\s0\fR structure should be supplied in the \fIfptrs\fR parameter. -.PP -The \fB\s-1ASN1_EXTERN_FUNCS\s0\fR structure has the following entries. -.IP "\fIapp_data\fR" 4 -.IX Item "app_data" -A pointer to arbitrary application specific data. -.IP "\fIasn1_ex_new\fR" 4 -.IX Item "asn1_ex_new" -A \*(L"new\*(R" function responsible for constructing a new \fB\s-1ASN1_VALUE\s0\fR object. The -newly constructed value should be stored in \fI*pval\fR. The \fIit\fR parameter is a -pointer to the \fB\s-1ASN1_ITEM\s0\fR template object created via the -\&\s-1\fBIMPLEMENT_EXTERN_ASN1\s0()\fR macro. -.Sp -Returns a positive value on success or 0 on error. -.IP "\fIasn1_ex_free\fR" 4 -.IX Item "asn1_ex_free" -A \*(L"free\*(R" function responsible for freeing the \fB\s-1ASN1_VALUE\s0\fR passed in \fI*pval\fR -that was previously allocated via a \*(L"new\*(R" function. The \fIit\fR parameter is a -pointer to the \fB\s-1ASN1_ITEM\s0\fR template object created via the -\&\s-1\fBIMPLEMENT_EXTERN_ASN1\s0()\fR macro. -.IP "\fIasn1_ex_clear\fR" 4 -.IX Item "asn1_ex_clear" -A \*(L"clear\*(R" function responsible for clearing any data in the \fB\s-1ASN1_VALUE\s0\fR passed -in \fI*pval\fR and making it suitable for reuse. The \fIit\fR parameter is a pointer -to the \fB\s-1ASN1_ITEM\s0\fR template object created via the \s-1\fBIMPLEMENT_EXTERN_ASN1\s0()\fR -macro. -.IP "\fIasn1_ex_d2i\fR" 4 -.IX Item "asn1_ex_d2i" -A \*(L"d2i\*(R" function responsible for converting \s-1DER\s0 data with the tag \fItag\fR and -class \fIclass\fR into an \fB\s-1ASN1_VALUE\s0\fR. If \fI*pval\fR is non-NULL then the -\&\fB\s-1ASN_VALUE\s0\fR it points to should be reused. Otherwise a new \fB\s-1ASN1_VALUE\s0\fR -should be allocated and stored in \fI*pval\fR. \fI*in\fR points to the \s-1DER\s0 data to be -decoded and \fIlen\fR is the length of that data. After decoding \fI*in\fR should be -updated to point at the next byte after the decoded data. If the \fB\s-1ASN1_VALUE\s0\fR -is considered optional in this context then \fIopt\fR will be nonzero. Otherwise -it will be zero. The \fIit\fR parameter is a pointer to the \fB\s-1ASN1_ITEM\s0\fR template -object created via the \s-1\fBIMPLEMENT_EXTERN_ASN1\s0()\fR macro. A pointer to the current -\&\fB\s-1ASN1_TLC\s0\fR context (which may be required for other \s-1ASN1\s0 function calls) is -passed in the \fIctx\fR parameter. -.Sp -The \fIasn1_ex_d2i\fR entry may be \s-1NULL\s0 if \fIasn1_ex_d2i_ex\fR has been specified -instead. -.Sp -Returns <= 0 on error or a positive value on success. -.IP "\fIasn1_ex_i2d\fR" 4 -.IX Item "asn1_ex_i2d" -An \*(L"i2d\*(R" function responsible for converting an \fB\s-1ASN1_VALUE\s0\fR into \s-1DER\s0 encoding. -On entry \fI*pval\fR will contain the \fB\s-1ASN1_VALUE\s0\fR to be encoded. If default -tagging is to be used then \fItag\fR will be \-1 on entry. Otherwise if implicit -tagging should be used then \fItag\fR and \fIaclass\fR will be the tag and associated -class. -.Sp -If \fIout\fR is not \s-1NULL\s0 then this function should write the \s-1DER\s0 encoded data to -the buffer in \fI*out\fR, and then increment \fI*out\fR to point to immediately after -the data just written. -.Sp -If \fIout\fR is \s-1NULL\s0 then no data should be written but the length calculated and -returned as if it were. -.Sp -The \fIasn1_ex_i2d\fR entry may be \s-1NULL\s0 if \fIasn1_ex_i2d_ex\fR has been specified -instead. -.Sp -The return value should be negative if a fatal error occurred, or 0 if a -non-fatal error occurred. Otherwise it should return the length of the encoded -data. -.IP "\fIasn1_ex_print\fR" 4 -.IX Item "asn1_ex_print" -A \*(L"print\*(R" function. \fIout\fR is the \s-1BIO\s0 to print the output to. \fI*pval\fR is the -\&\fB\s-1ASN1_VALUE\s0\fR to be printed. \fIindent\fR is the number of spaces of indenting to -be printed before any data is printed. \fIfname\fR is currently unused and is -always "". \fIpctx\fR is a pointer to the \fB\s-1ASN1_PCTX\s0\fR for the print operation. -.Sp -Returns 0 on error or a positive value on success. If the return value is 2 then -an additional newline will be printed after the data printed by this function. -.IP "\fIasn1_ex_new_ex\fR" 4 -.IX Item "asn1_ex_new_ex" -This is the same as \fIasn1_ex_new\fR except that it is additionally passed the -\&\s-1OSSL_LIB_CTX\s0 to be used in \fIlibctx\fR and any property query string to be used -for algorithm fetching in the \fIpropq\fR parameter. See -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further details. If \fIasn1_ex_new_ex\fR is -non \s-1NULL,\s0 then it will always be called in preference to \fIasn1_ex_new\fR. -.IP "\fIasn1_ex_d2i_ex\fR" 4 -.IX Item "asn1_ex_d2i_ex" -This is the same as \fIasn1_ex_d2i\fR except that it is additionally passed the -\&\s-1OSSL_LIB_CTX\s0 to be used in \fIlibctx\fR and any property query string to be used -for algorithm fetching in the \fIpropq\fR parameter. See -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further details. If \fIasn1_ex_d2i_ex\fR is -non \s-1NULL,\s0 then it will always be called in preference to \fIasn1_ex_d2i\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Return values for the various callbacks are as described above. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBASN1_item_new_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fIasn1_ex_new_ex\fR and \fIasn1_ex_d2i_ex\fR callbacks were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_adj.3ossl b/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_adj.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_adj.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_check.3ossl b/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_check.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_dup.3ossl b/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_dup.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_print.3ossl b/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_print.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set.3ossl b/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set_string.3ossl b/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set_string.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_GENERALIZEDTIME_set_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_free.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_free.3ossl deleted file mode 120000 index bfa4b3d0..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_get.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_get.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_get_int64.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_get_int64.3ossl deleted file mode 100644 index 7beb4fbe..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_get_int64.3ossl +++ /dev/null @@ -1,262 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_INTEGER_GET_INT64 3ossl" -.TH ASN1_INTEGER_GET_INT64 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_INTEGER_get_uint64, ASN1_INTEGER_set_uint64, -ASN1_INTEGER_get_int64, ASN1_INTEGER_get, ASN1_INTEGER_set_int64, ASN1_INTEGER_set, BN_to_ASN1_INTEGER, ASN1_INTEGER_to_BN, ASN1_ENUMERATED_get_int64, ASN1_ENUMERATED_get, ASN1_ENUMERATED_set_int64, ASN1_ENUMERATED_set, BN_to_ASN1_ENUMERATED, ASN1_ENUMERATED_to_BN -\&\- ASN.1 INTEGER and ENUMERATED utilities -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ASN1_INTEGER_get_int64(int64_t *pr, const ASN1_INTEGER *a); -\& long ASN1_INTEGER_get(const ASN1_INTEGER *a); -\& -\& int ASN1_INTEGER_set_int64(ASN1_INTEGER *a, int64_t r); -\& int ASN1_INTEGER_set(ASN1_INTEGER *a, long v); -\& -\& int ASN1_INTEGER_get_uint64(uint64_t *pr, const ASN1_INTEGER *a); -\& int ASN1_INTEGER_set_uint64(ASN1_INTEGER *a, uint64_t r); -\& -\& ASN1_INTEGER *BN_to_ASN1_INTEGER(const BIGNUM *bn, ASN1_INTEGER *ai); -\& BIGNUM *ASN1_INTEGER_to_BN(const ASN1_INTEGER *ai, BIGNUM *bn); -\& -\& int ASN1_ENUMERATED_get_int64(int64_t *pr, const ASN1_ENUMERATED *a); -\& long ASN1_ENUMERATED_get(const ASN1_ENUMERATED *a); -\& -\& int ASN1_ENUMERATED_set_int64(ASN1_ENUMERATED *a, int64_t r); -\& int ASN1_ENUMERATED_set(ASN1_ENUMERATED *a, long v); -\& -\& ASN1_ENUMERATED *BN_to_ASN1_ENUMERATED(const BIGNUM *bn, ASN1_ENUMERATED *ai); -\& BIGNUM *ASN1_ENUMERATED_to_BN(const ASN1_ENUMERATED *ai, BIGNUM *bn); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions convert to and from \fB\s-1ASN1_INTEGER\s0\fR and \fB\s-1ASN1_ENUMERATED\s0\fR -structures. -.PP -\&\fBASN1_INTEGER_get_int64()\fR converts an \fB\s-1ASN1_INTEGER\s0\fR into an \fBint64_t\fR type -If successful it returns 1 and sets \fI*pr\fR to the value of \fIa\fR. If it fails -(due to invalid type or the value being too big to fit into an \fBint64_t\fR type) -it returns 0. -.PP -\&\fBASN1_INTEGER_get_uint64()\fR is similar to \fBASN1_INTEGER_get_int64_t()\fR except it -converts to a \fBuint64_t\fR type and an error is returned if the passed integer -is negative. -.PP -\&\fBASN1_INTEGER_get()\fR also returns the value of \fIa\fR but it returns 0 if \fIa\fR is -\&\s-1NULL\s0 and \-1 on error (which is ambiguous because \-1 is a legitimate value for -an \fB\s-1ASN1_INTEGER\s0\fR). New applications should use \fBASN1_INTEGER_get_int64()\fR -instead. -.PP -\&\fBASN1_INTEGER_set_int64()\fR sets the value of \fB\s-1ASN1_INTEGER\s0\fR \fIa\fR to the -\&\fBint64_t\fR value \fIr\fR. -.PP -\&\fBASN1_INTEGER_set_uint64()\fR sets the value of \fB\s-1ASN1_INTEGER\s0\fR \fIa\fR to the -\&\fBuint64_t\fR value \fIr\fR. -.PP -\&\fBASN1_INTEGER_set()\fR sets the value of \fB\s-1ASN1_INTEGER\s0\fR \fIa\fR to the \fIlong\fR value -\&\fIv\fR. -.PP -\&\fBBN_to_ASN1_INTEGER()\fR converts \fB\s-1BIGNUM\s0\fR \fIbn\fR to an \fB\s-1ASN1_INTEGER\s0\fR. If \fIai\fR -is \s-1NULL\s0 a new \fB\s-1ASN1_INTEGER\s0\fR structure is returned. If \fIai\fR is not \s-1NULL\s0 then -the existing structure will be used instead. -.PP -\&\fBASN1_INTEGER_to_BN()\fR converts \s-1ASN1_INTEGER\s0 \fIai\fR into a \fB\s-1BIGNUM\s0\fR. If \fIbn\fR is -\&\s-1NULL\s0 a new \fB\s-1BIGNUM\s0\fR structure is returned. If \fIbn\fR is not \s-1NULL\s0 then the -existing structure will be used instead. -.PP -\&\fBASN1_ENUMERATED_get_int64()\fR, \fBASN1_ENUMERATED_set_int64()\fR, -\&\fBASN1_ENUMERATED_set()\fR, \fBBN_to_ASN1_ENUMERATED()\fR and \fBASN1_ENUMERATED_to_BN()\fR -behave in an identical way to their \s-1ASN1_INTEGER\s0 counterparts except they -operate on an \fB\s-1ASN1_ENUMERATED\s0\fR value. -.PP -\&\fBASN1_ENUMERATED_get()\fR returns the value of \fIa\fR in a similar way to -\&\fBASN1_INTEGER_get()\fR but it returns \fB0xffffffffL\fR if the value of \fIa\fR will not -fit in a long type. New applications should use \fBASN1_ENUMERATED_get_int64()\fR -instead. -.SH "NOTES" -.IX Header "NOTES" -In general an \fB\s-1ASN1_INTEGER\s0\fR or \fB\s-1ASN1_ENUMERATED\s0\fR type can contain an -integer of almost arbitrary size and so cannot always be represented by a C -\&\fBint64_t\fR type. However, in many cases (for example version numbers) they -represent small integers which can be more easily manipulated if converted to -an appropriate C integer type. -.SH "BUGS" -.IX Header "BUGS" -The ambiguous return values of \fBASN1_INTEGER_get()\fR and \fBASN1_ENUMERATED_get()\fR -mean these functions should be avoided if possible. They are retained for -compatibility. Normally the ambiguous return values are not legitimate -values for the fields they represent. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_INTEGER_set_int64()\fR, \fBASN1_INTEGER_set()\fR, \fBASN1_ENUMERATED_set_int64()\fR and -\&\fBASN1_ENUMERATED_set()\fR return 1 for success and 0 for failure. They will only -fail if a memory allocation error occurs. -.PP -\&\fBASN1_INTEGER_get_int64()\fR and \fBASN1_ENUMERATED_get_int64()\fR return 1 for success -and 0 for failure. They will fail if the passed type is incorrect (this will -only happen if there is a programming error) or if the value exceeds the range -of an \fBint64_t\fR type. -.PP -\&\fBBN_to_ASN1_INTEGER()\fR and \fBBN_to_ASN1_ENUMERATED()\fR return an \fB\s-1ASN1_INTEGER\s0\fR or -\&\fB\s-1ASN1_ENUMERATED\s0\fR structure respectively or \s-1NULL\s0 if an error occurs. They will -only fail due to a memory allocation error. -.PP -\&\fBASN1_INTEGER_to_BN()\fR and \fBASN1_ENUMERATED_to_BN()\fR return a \fB\s-1BIGNUM\s0\fR structure -of \s-1NULL\s0 if an error occurs. They can fail if the passed type is incorrect -(due to programming error) or due to a memory allocation failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBASN1_INTEGER_set_int64()\fR, \fBASN1_INTEGER_get_int64()\fR, -\&\fBASN1_ENUMERATED_set_int64()\fR and \fBASN1_ENUMERATED_get_int64()\fR -were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_get_uint64.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_get_uint64.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_get_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_new.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_new.3ossl deleted file mode 100644 index d1080c18..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_new.3ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_INTEGER_NEW 3ossl" -.TH ASN1_INTEGER_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_INTEGER_new, ASN1_INTEGER_free \- ASN1_INTEGER allocation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_INTEGER *ASN1_INTEGER_new(void); -\& void ASN1_INTEGER_free(ASN1_INTEGER *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBASN1_INTEGER_new()\fR returns an allocated \fB\s-1ASN1_INTEGER\s0\fR structure. -.PP -\&\fBASN1_INTEGER_free()\fR frees up a single \fB\s-1ASN1_INTEGER\s0\fR object. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fB\s-1ASN1_INTEGER\s0\fR structure representing the \s-1ASN.1 INTEGER\s0 type -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_INTEGER_new()\fR return a valid \fB\s-1ASN1_INTEGER\s0\fR structure or \s-1NULL\s0 -if an error occurred. -.PP -\&\fBASN1_INTEGER_free()\fR does not return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_set.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_set.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_set_int64.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_set_int64.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_set_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_set_uint64.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_set_uint64.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_set_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_INTEGER_to_BN.3ossl b/openssl-install/share/man/man3/ASN1_INTEGER_to_BN.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/ASN1_INTEGER_to_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ITEM.3ossl b/openssl-install/share/man/man3/ASN1_ITEM.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASN1_ITEM.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ITEM_get.3ossl b/openssl-install/share/man/man3/ASN1_ITEM_get.3ossl deleted file mode 120000 index 1dc0a786..00000000 --- a/openssl-install/share/man/man3/ASN1_ITEM_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_ITEM_lookup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ITEM_lookup.3ossl b/openssl-install/share/man/man3/ASN1_ITEM_lookup.3ossl deleted file mode 100644 index a37af337..00000000 --- a/openssl-install/share/man/man3/ASN1_ITEM_lookup.3ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_ITEM_LOOKUP 3ossl" -.TH ASN1_ITEM_LOOKUP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_ITEM_lookup, ASN1_ITEM_get \- lookup ASN.1 structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const ASN1_ITEM *ASN1_ITEM_lookup(const char *name); -\& const ASN1_ITEM *ASN1_ITEM_get(size_t i); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBASN1_ITEM_lookup()\fR returns the \fB\s-1ASN1_ITEM\s0\fR named \fIname\fR. -.PP -\&\fBASN1_ITEM_get()\fR returns the \fB\s-1ASN1_ITEM\s0\fR with index \fIi\fR. This function -returns \s-1NULL\s0 if the index \fIi\fR is out of range. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_ITEM_lookup()\fR and \fBASN1_ITEM_get()\fR return a valid \fB\s-1ASN1_ITEM\s0\fR structure -or \s-1NULL\s0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_OBJECT_free.3ossl b/openssl-install/share/man/man3/ASN1_OBJECT_free.3ossl deleted file mode 120000 index 50fc77ee..00000000 --- a/openssl-install/share/man/man3/ASN1_OBJECT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_OBJECT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_OBJECT_new.3ossl b/openssl-install/share/man/man3/ASN1_OBJECT_new.3ossl deleted file mode 100644 index 1304774f..00000000 --- a/openssl-install/share/man/man3/ASN1_OBJECT_new.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_OBJECT_NEW 3ossl" -.TH ASN1_OBJECT_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_OBJECT_new, ASN1_OBJECT_free \- object allocation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_OBJECT *ASN1_OBJECT_new(void); -\& void ASN1_OBJECT_free(ASN1_OBJECT *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1ASN1_OBJECT\s0\fR allocation routines, allocate and free an -\&\fB\s-1ASN1_OBJECT\s0\fR structure, which represents an \s-1ASN1 OBJECT IDENTIFIER.\s0 -.PP -\&\fBASN1_OBJECT_new()\fR allocates and initializes an \fB\s-1ASN1_OBJECT\s0\fR structure. -.PP -\&\fBASN1_OBJECT_free()\fR frees up the \fB\s-1ASN1_OBJECT\s0\fR structure \fIa\fR. -If \fIa\fR is \s-1NULL,\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -Although \fBASN1_OBJECT_new()\fR allocates a new \fB\s-1ASN1_OBJECT\s0\fR structure it -is almost never used in applications. The \s-1ASN1\s0 object utility functions -such as \fBOBJ_nid2obj()\fR are used instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBASN1_OBJECT_new()\fR returns \s-1NULL\s0 and sets an error -code that can be obtained by \fBERR_get_error\fR\|(3). -Otherwise it returns a pointer to the newly allocated structure. -.PP -\&\fBASN1_OBJECT_free()\fR returns no value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBd2i_ASN1_OBJECT\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_PRINT_ARG.3ossl b/openssl-install/share/man/man3/ASN1_PRINT_ARG.3ossl deleted file mode 120000 index ec226b0c..00000000 --- a/openssl-install/share/man/man3/ASN1_PRINT_ARG.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_aux_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STREAM_ARG.3ossl b/openssl-install/share/man/man3/ASN1_STREAM_ARG.3ossl deleted file mode 120000 index ec226b0c..00000000 --- a/openssl-install/share/man/man3/ASN1_STREAM_ARG.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_aux_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_TABLE.3ossl b/openssl-install/share/man/man3/ASN1_STRING_TABLE.3ossl deleted file mode 120000 index aef77654..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_TABLE.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_TABLE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_TABLE_add.3ossl b/openssl-install/share/man/man3/ASN1_STRING_TABLE_add.3ossl deleted file mode 100644 index 0fab1e47..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_TABLE_add.3ossl +++ /dev/null @@ -1,196 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_STRING_TABLE_ADD 3ossl" -.TH ASN1_STRING_TABLE_ADD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_STRING_TABLE, ASN1_STRING_TABLE_add, ASN1_STRING_TABLE_get, -ASN1_STRING_TABLE_cleanup \- ASN1_STRING_TABLE manipulation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct asn1_string_table_st ASN1_STRING_TABLE; -\& -\& int ASN1_STRING_TABLE_add(int nid, long minsize, long maxsize, -\& unsigned long mask, unsigned long flags); -\& ASN1_STRING_TABLE *ASN1_STRING_TABLE_get(int nid); -\& void ASN1_STRING_TABLE_cleanup(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -.SS "Types" -.IX Subsection "Types" -\&\fB\s-1ASN1_STRING_TABLE\s0\fR is a table which holds string information -(basically minimum size, maximum size, type and etc) for a \s-1NID\s0 object. -.SS "Functions" -.IX Subsection "Functions" -\&\fBASN1_STRING_TABLE_add()\fR adds a new \fB\s-1ASN1_STRING_TABLE\s0\fR item into the -local \s-1ASN1\s0 string table based on the \fInid\fR along with other parameters. -.PP -If the item is already in the table, fields of \fB\s-1ASN1_STRING_TABLE\s0\fR are -updated (depending on the values of those parameters, e.g., \fIminsize\fR -and \fImaxsize\fR >= 0, \fImask\fR and \fIflags\fR != 0). If the \fInid\fR is standard, -a copy of the standard \fB\s-1ASN1_STRING_TABLE\s0\fR is created and updated with -other parameters. -.PP -\&\fBASN1_STRING_TABLE_get()\fR searches for an \fB\s-1ASN1_STRING_TABLE\s0\fR item based -on \fInid\fR. It will search the local table first, then the standard one. -.PP -\&\fBASN1_STRING_TABLE_cleanup()\fR frees all \fB\s-1ASN1_STRING_TABLE\s0\fR items added -by \fBASN1_STRING_TABLE_add()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_STRING_TABLE_add()\fR returns 1 on success, 0 if an error occurred. -.PP -\&\fBASN1_STRING_TABLE_get()\fR returns a valid \fB\s-1ASN1_STRING_TABLE\s0\fR structure -or \s-1NULL\s0 if nothing is found. -.PP -\&\fBASN1_STRING_TABLE_cleanup()\fR does not return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_STRING_TABLE_cleanup.3ossl b/openssl-install/share/man/man3/ASN1_STRING_TABLE_cleanup.3ossl deleted file mode 120000 index aef77654..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_TABLE_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_TABLE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_TABLE_get.3ossl b/openssl-install/share/man/man3/ASN1_STRING_TABLE_get.3ossl deleted file mode 120000 index aef77654..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_TABLE_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_TABLE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_cmp.3ossl b/openssl-install/share/man/man3/ASN1_STRING_cmp.3ossl deleted file mode 120000 index 76e51eff..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_length.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_data.3ossl b/openssl-install/share/man/man3/ASN1_STRING_data.3ossl deleted file mode 120000 index 76e51eff..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_length.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_dup.3ossl b/openssl-install/share/man/man3/ASN1_STRING_dup.3ossl deleted file mode 120000 index 76e51eff..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_length.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_free.3ossl b/openssl-install/share/man/man3/ASN1_STRING_free.3ossl deleted file mode 120000 index bfd2aea3..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_get0_data.3ossl b/openssl-install/share/man/man3/ASN1_STRING_get0_data.3ossl deleted file mode 120000 index 76e51eff..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_get0_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_length.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_length.3ossl b/openssl-install/share/man/man3/ASN1_STRING_length.3ossl deleted file mode 100644 index 99f77c9a..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_length.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_STRING_LENGTH 3ossl" -.TH ASN1_STRING_LENGTH 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_STRING_dup, ASN1_STRING_cmp, ASN1_STRING_set, ASN1_STRING_length, -ASN1_STRING_type, ASN1_STRING_get0_data, ASN1_STRING_data, -ASN1_STRING_to_UTF8 \- ASN1_STRING utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ASN1_STRING_length(ASN1_STRING *x); -\& const unsigned char *ASN1_STRING_get0_data(const ASN1_STRING *x); -\& unsigned char *ASN1_STRING_data(ASN1_STRING *x); -\& -\& ASN1_STRING *ASN1_STRING_dup(const ASN1_STRING *a); -\& -\& int ASN1_STRING_cmp(ASN1_STRING *a, ASN1_STRING *b); -\& -\& int ASN1_STRING_set(ASN1_STRING *str, const void *data, int len); -\& -\& int ASN1_STRING_type(const ASN1_STRING *x); -\& -\& int ASN1_STRING_to_UTF8(unsigned char **out, const ASN1_STRING *in); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions allow an \fB\s-1ASN1_STRING\s0\fR structure to be manipulated. -.PP -\&\fBASN1_STRING_length()\fR returns the length of the content of \fIx\fR. -.PP -\&\fBASN1_STRING_get0_data()\fR returns an internal pointer to the data of \fIx\fR. -Since this is an internal pointer it should \fBnot\fR be freed or -modified in any way. -.PP -\&\fBASN1_STRING_data()\fR is similar to \fBASN1_STRING_get0_data()\fR except the -returned value is not constant. This function is deprecated: -applications should use \fBASN1_STRING_get0_data()\fR instead. -.PP -\&\fBASN1_STRING_dup()\fR returns a copy of the structure \fIa\fR. -.PP -\&\fBASN1_STRING_cmp()\fR compares \fIa\fR and \fIb\fR returning 0 if the two -are identical. The string types and content are compared. -.PP -\&\fBASN1_STRING_set()\fR sets the data of string \fIstr\fR to the buffer -\&\fIdata\fR or length \fIlen\fR. The supplied data is copied. If \fIlen\fR -is \-1 then the length is determined by strlen(data). -.PP -\&\fBASN1_STRING_type()\fR returns the type of \fIx\fR, using standard constants -such as \fBV_ASN1_OCTET_STRING\fR. -.PP -\&\fBASN1_STRING_to_UTF8()\fR converts the string \fIin\fR to \s-1UTF8\s0 format, the -converted data is allocated in a buffer in \fI*out\fR. The length of -\&\fIout\fR is returned or a negative error code. The buffer \fI*out\fR -should be freed using \fBOPENSSL_free()\fR. -.SH "NOTES" -.IX Header "NOTES" -Almost all \s-1ASN1\s0 types in OpenSSL are represented as an \fB\s-1ASN1_STRING\s0\fR -structure. Other types such as \fB\s-1ASN1_OCTET_STRING\s0\fR are simply typedef'ed -to \fB\s-1ASN1_STRING\s0\fR and the functions call the \fB\s-1ASN1_STRING\s0\fR equivalents. -\&\fB\s-1ASN1_STRING\s0\fR is also used for some \fB\s-1CHOICE\s0\fR types which consist -entirely of primitive string types such as \fBDirectoryString\fR and -\&\fBTime\fR. -.PP -These functions should \fBnot\fR be used to examine or modify \fB\s-1ASN1_INTEGER\s0\fR -or \fB\s-1ASN1_ENUMERATED\s0\fR types: the relevant \fB\s-1INTEGER\s0\fR or \fB\s-1ENUMERATED\s0\fR -utility functions should be used instead. -.PP -In general it cannot be assumed that the data returned by \fBASN1_STRING_data()\fR -is null terminated or does not contain embedded nulls. The actual format -of the data will depend on the actual string type itself: for example -for an IA5String the data will be \s-1ASCII,\s0 for a BMPString two bytes per -character in big endian format, and for a UTF8String it will be in \s-1UTF8\s0 format. -.PP -Similar care should be take to ensure the data is in the correct format -when calling \fBASN1_STRING_set()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_STRING_length()\fR returns the length of the content of \fIx\fR. -.PP -\&\fBASN1_STRING_get0_data()\fR and \fBASN1_STRING_data()\fR return an internal pointer to -the data of \fIx\fR. -.PP -\&\fBASN1_STRING_dup()\fR returns a valid \fB\s-1ASN1_STRING\s0\fR structure or \s-1NULL\s0 if an -error occurred. -.PP -\&\fBASN1_STRING_cmp()\fR returns an integer greater than, equal to, or less than 0, -according to whether \fIa\fR is greater than, equal to, or less than \fIb\fR. -.PP -\&\fBASN1_STRING_set()\fR returns 1 on success or 0 on error. -.PP -\&\fBASN1_STRING_type()\fR returns the type of \fIx\fR. -.PP -\&\fBASN1_STRING_to_UTF8()\fR returns the number of bytes in output string \fIout\fR or a -negative value if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_STRING_new.3ossl b/openssl-install/share/man/man3/ASN1_STRING_new.3ossl deleted file mode 100644 index a9bc04de..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_new.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_STRING_NEW 3ossl" -.TH ASN1_STRING_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_STRING_new, ASN1_STRING_type_new, ASN1_STRING_free \- -ASN1_STRING allocation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_STRING *ASN1_STRING_new(void); -\& ASN1_STRING *ASN1_STRING_type_new(int type); -\& void ASN1_STRING_free(ASN1_STRING *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBASN1_STRING_new()\fR returns an allocated \fB\s-1ASN1_STRING\s0\fR structure. Its type -is undefined. -.PP -\&\fBASN1_STRING_type_new()\fR returns an allocated \fB\s-1ASN1_STRING\s0\fR structure of -type \fItype\fR. -.PP -\&\fBASN1_STRING_free()\fR frees up \fIa\fR. -If \fIa\fR is \s-1NULL\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -Other string types call the \fB\s-1ASN1_STRING\s0\fR functions. For example -\&\fBASN1_OCTET_STRING_new()\fR calls ASN1_STRING_type_new(V_ASN1_OCTET_STRING). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_STRING_new()\fR and \fBASN1_STRING_type_new()\fR return a valid -\&\fB\s-1ASN1_STRING\s0\fR structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBASN1_STRING_free()\fR does not return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_STRING_print.3ossl b/openssl-install/share/man/man3/ASN1_STRING_print.3ossl deleted file mode 120000 index 13c0091e..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_print_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_print_ex.3ossl b/openssl-install/share/man/man3/ASN1_STRING_print_ex.3ossl deleted file mode 100644 index 6142de34..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_print_ex.3ossl +++ /dev/null @@ -1,246 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_STRING_PRINT_EX 3ossl" -.TH ASN1_STRING_PRINT_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_tag2str, ASN1_STRING_print_ex, ASN1_STRING_print_ex_fp, ASN1_STRING_print -\&\- ASN1_STRING output routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ASN1_STRING_print_ex(BIO *out, const ASN1_STRING *str, unsigned long flags); -\& int ASN1_STRING_print_ex_fp(FILE *fp, const ASN1_STRING *str, unsigned long flags); -\& int ASN1_STRING_print(BIO *out, const ASN1_STRING *str); -\& -\& const char *ASN1_tag2str(int tag); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions output an \fB\s-1ASN1_STRING\s0\fR structure. \fB\s-1ASN1_STRING\s0\fR is used to -represent all the \s-1ASN1\s0 string types. -.PP -\&\fBASN1_STRING_print_ex()\fR outputs \fIstr\fR to \fIout\fR, the format is determined by -the options \fIflags\fR. \fBASN1_STRING_print_ex_fp()\fR is identical except it outputs -to \fIfp\fR instead. -.PP -\&\fBASN1_STRING_print()\fR prints \fIstr\fR to \fIout\fR but using a different format to -\&\fBASN1_STRING_print_ex()\fR. It replaces unprintable characters (other than \s-1CR, LF\s0) -with '.'. -.PP -\&\fBASN1_tag2str()\fR returns a human-readable name of the specified \s-1ASN.1\s0 \fItag\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\fBASN1_STRING_print()\fR is a deprecated function which should be avoided; use -\&\fBASN1_STRING_print_ex()\fR instead. -.PP -Although there are a large number of options frequently \fB\s-1ASN1_STRFLGS_RFC2253\s0\fR is -suitable, or on \s-1UTF8\s0 terminals \fB\s-1ASN1_STRFLGS_RFC2253 &\s0 ~ASN1_STRFLGS_ESC_MSB\fR. -.PP -The complete set of supported options for \fIflags\fR is listed below. -.PP -Various characters can be escaped. If \fB\s-1ASN1_STRFLGS_ESC_2253\s0\fR is set the characters -determined by \s-1RFC2253\s0 are escaped. If \fB\s-1ASN1_STRFLGS_ESC_CTRL\s0\fR is set control -characters are escaped. If \fB\s-1ASN1_STRFLGS_ESC_MSB\s0\fR is set characters with the -\&\s-1MSB\s0 set are escaped: this option should \fBnot\fR be used if the terminal correctly -interprets \s-1UTF8\s0 sequences. -.PP -Escaping takes several forms. -.PP -If the character being escaped is a 16 bit character then the form \*(L"\eUXXXX\*(R" is used -using exactly four characters for the hex representation. If it is 32 bits then -\&\*(L"\eWXXXXXXXX\*(R" is used using eight characters of its hex representation. These forms -will only be used if \s-1UTF8\s0 conversion is not set (see below). -.PP -Printable characters are normally escaped using the backslash '\e' character. If -\&\fB\s-1ASN1_STRFLGS_ESC_QUOTE\s0\fR is set then the whole string is instead surrounded by -double quote characters: this is arguably more readable than the backslash -notation. Other characters use the \*(L"\eXX\*(R" using exactly two characters of the hex -representation. -.PP -If \fB\s-1ASN1_STRFLGS_UTF8_CONVERT\s0\fR is set then characters are converted to \s-1UTF8\s0 -format first. If the terminal supports the display of \s-1UTF8\s0 sequences then this -option will correctly display multi byte characters. -.PP -If \fB\s-1ASN1_STRFLGS_IGNORE_TYPE\s0\fR is set then the string type is not interpreted at -all: everything is assumed to be one byte per character. This is primarily for -debugging purposes and can result in confusing output in multi character strings. -.PP -If \fB\s-1ASN1_STRFLGS_SHOW_TYPE\s0\fR is set then the string type itself is printed out -before its value (for example \*(L"\s-1BMPSTRING\*(R"\s0), this actually uses \fBASN1_tag2str()\fR. -.PP -The content of a string instead of being interpreted can be \*(L"dumped\*(R": this just -outputs the value of the string using the form #XXXX using hex format for each -octet. -.PP -If \fB\s-1ASN1_STRFLGS_DUMP_ALL\s0\fR is set then any type is dumped. -.PP -Normally non character string types (such as \s-1OCTET STRING\s0) are assumed to be -one byte per character, if \fB\s-1ASN1_STRFLGS_DUMP_UNKNOWN\s0\fR is set then they will -be dumped instead. -.PP -When a type is dumped normally just the content octets are printed, if -\&\fB\s-1ASN1_STRFLGS_DUMP_DER\s0\fR is set then the complete encoding is dumped -instead (including tag and length octets). -.PP -\&\fB\s-1ASN1_STRFLGS_RFC2253\s0\fR includes all the flags required by \s-1RFC2253.\s0 It is -equivalent to: - \s-1ASN1_STRFLGS_ESC_2253\s0 | \s-1ASN1_STRFLGS_ESC_CTRL\s0 | \s-1ASN1_STRFLGS_ESC_MSB\s0 | - \s-1ASN1_STRFLGS_UTF8_CONVERT\s0 | \s-1ASN1_STRFLGS_DUMP_UNKNOWN ASN1_STRFLGS_DUMP_DER\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_STRING_print_ex()\fR and \fBASN1_STRING_print_ex_fp()\fR return the number of -characters written or \-1 if an error occurred. -.PP -\&\fBASN1_STRING_print()\fR returns 1 on success or 0 on error. -.PP -\&\fBASN1_tag2str()\fR returns a human-readable name of the specified \s-1ASN.1\s0 \fItag\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBASN1_tag2str\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_STRING_print_ex_fp.3ossl b/openssl-install/share/man/man3/ASN1_STRING_print_ex_fp.3ossl deleted file mode 120000 index 13c0091e..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_print_ex_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_print_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_set.3ossl b/openssl-install/share/man/man3/ASN1_STRING_set.3ossl deleted file mode 120000 index 76e51eff..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_length.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_to_UTF8.3ossl b/openssl-install/share/man/man3/ASN1_STRING_to_UTF8.3ossl deleted file mode 120000 index 76e51eff..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_to_UTF8.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_length.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_type.3ossl b/openssl-install/share/man/man3/ASN1_STRING_type.3ossl deleted file mode 120000 index 76e51eff..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_length.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_STRING_type_new.3ossl b/openssl-install/share/man/man3/ASN1_STRING_type_new.3ossl deleted file mode 120000 index bfd2aea3..00000000 --- a/openssl-install/share/man/man3/ASN1_STRING_type_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_adj.3ossl b/openssl-install/share/man/man3/ASN1_TIME_adj.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_adj.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_check.3ossl b/openssl-install/share/man/man3/ASN1_TIME_check.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_cmp_time_t.3ossl b/openssl-install/share/man/man3/ASN1_TIME_cmp_time_t.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_cmp_time_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_compare.3ossl b/openssl-install/share/man/man3/ASN1_TIME_compare.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_compare.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_diff.3ossl b/openssl-install/share/man/man3/ASN1_TIME_diff.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_diff.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_dup.3ossl b/openssl-install/share/man/man3/ASN1_TIME_dup.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_normalize.3ossl b/openssl-install/share/man/man3/ASN1_TIME_normalize.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_normalize.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_print.3ossl b/openssl-install/share/man/man3/ASN1_TIME_print.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_print_ex.3ossl b/openssl-install/share/man/man3/ASN1_TIME_print_ex.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_print_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_set.3ossl b/openssl-install/share/man/man3/ASN1_TIME_set.3ossl deleted file mode 100644 index 2ae03818..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_set.3ossl +++ /dev/null @@ -1,419 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_TIME_SET 3ossl" -.TH ASN1_TIME_SET 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_TIME_set, ASN1_UTCTIME_set, ASN1_GENERALIZEDTIME_set, -ASN1_TIME_adj, ASN1_UTCTIME_adj, ASN1_GENERALIZEDTIME_adj, -ASN1_TIME_check, ASN1_UTCTIME_check, ASN1_GENERALIZEDTIME_check, -ASN1_TIME_set_string, ASN1_UTCTIME_set_string, ASN1_GENERALIZEDTIME_set_string, -ASN1_TIME_set_string_X509, -ASN1_TIME_normalize, -ASN1_TIME_to_tm, -ASN1_TIME_print, ASN1_TIME_print_ex, ASN1_UTCTIME_print, ASN1_GENERALIZEDTIME_print, -ASN1_TIME_diff, -ASN1_TIME_cmp_time_t, ASN1_UTCTIME_cmp_time_t, -ASN1_TIME_compare, -ASN1_TIME_to_generalizedtime, -ASN1_TIME_dup, ASN1_UTCTIME_dup, ASN1_GENERALIZEDTIME_dup \- ASN.1 Time functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 4 -\& ASN1_TIME *ASN1_TIME_set(ASN1_TIME *s, time_t t); -\& ASN1_UTCTIME *ASN1_UTCTIME_set(ASN1_UTCTIME *s, time_t t); -\& ASN1_GENERALIZEDTIME *ASN1_GENERALIZEDTIME_set(ASN1_GENERALIZEDTIME *s, -\& time_t t); -\& -\& ASN1_TIME *ASN1_TIME_adj(ASN1_TIME *s, time_t t, int offset_day, -\& long offset_sec); -\& ASN1_UTCTIME *ASN1_UTCTIME_adj(ASN1_UTCTIME *s, time_t t, -\& int offset_day, long offset_sec); -\& ASN1_GENERALIZEDTIME *ASN1_GENERALIZEDTIME_adj(ASN1_GENERALIZEDTIME *s, -\& time_t t, int offset_day, -\& long offset_sec); -\& -\& int ASN1_TIME_set_string(ASN1_TIME *s, const char *str); -\& int ASN1_TIME_set_string_X509(ASN1_TIME *s, const char *str); -\& int ASN1_UTCTIME_set_string(ASN1_UTCTIME *s, const char *str); -\& int ASN1_GENERALIZEDTIME_set_string(ASN1_GENERALIZEDTIME *s, -\& const char *str); -\& -\& int ASN1_TIME_normalize(ASN1_TIME *s); -\& -\& int ASN1_TIME_check(const ASN1_TIME *t); -\& int ASN1_UTCTIME_check(const ASN1_UTCTIME *t); -\& int ASN1_GENERALIZEDTIME_check(const ASN1_GENERALIZEDTIME *t); -\& -\& int ASN1_TIME_print(BIO *b, const ASN1_TIME *s); -\& int ASN1_TIME_print_ex(BIO *bp, const ASN1_TIME *tm, unsigned long flags); -\& int ASN1_UTCTIME_print(BIO *b, const ASN1_UTCTIME *s); -\& int ASN1_GENERALIZEDTIME_print(BIO *b, const ASN1_GENERALIZEDTIME *s); -\& -\& int ASN1_TIME_to_tm(const ASN1_TIME *s, struct tm *tm); -\& int ASN1_TIME_diff(int *pday, int *psec, const ASN1_TIME *from, -\& const ASN1_TIME *to); -\& -\& int ASN1_TIME_cmp_time_t(const ASN1_TIME *s, time_t t); -\& int ASN1_UTCTIME_cmp_time_t(const ASN1_UTCTIME *s, time_t t); -\& -\& int ASN1_TIME_compare(const ASN1_TIME *a, const ASN1_TIME *b); -\& -\& ASN1_GENERALIZEDTIME *ASN1_TIME_to_generalizedtime(ASN1_TIME *t, -\& ASN1_GENERALIZEDTIME **out); -\& -\& ASN1_TIME *ASN1_TIME_dup(const ASN1_TIME *t); -\& ASN1_UTCTIME *ASN1_UTCTIME_dup(const ASN1_UTCTIME *t); -\& ASN1_GENERALIZEDTIME *ASN1_GENERALIZEDTIME_dup(const ASN1_GENERALIZEDTIME *t); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBASN1_TIME_set()\fR, \fBASN1_UTCTIME_set()\fR and \fBASN1_GENERALIZEDTIME_set()\fR -functions set the structure \fIs\fR to the time represented by the time_t -value \fIt\fR. If \fIs\fR is \s-1NULL\s0 a new time structure is allocated and returned. -.PP -The \fBASN1_TIME_adj()\fR, \fBASN1_UTCTIME_adj()\fR and \fBASN1_GENERALIZEDTIME_adj()\fR -functions set the time structure \fIs\fR to the time represented -by the time \fIoffset_day\fR and \fIoffset_sec\fR after the time_t value \fIt\fR. -The values of \fIoffset_day\fR or \fIoffset_sec\fR can be negative to set a -time before \fIt\fR. The \fIoffset_sec\fR value can also exceed the number of -seconds in a day. If \fIs\fR is \s-1NULL\s0 a new structure is allocated -and returned. -.PP -The \fBASN1_TIME_set_string()\fR, \fBASN1_UTCTIME_set_string()\fR and -\&\fBASN1_GENERALIZEDTIME_set_string()\fR functions set the time structure \fIs\fR -to the time represented by string \fIstr\fR which must be in appropriate \s-1ASN.1\s0 -time format (for example \s-1YYMMDDHHMMSSZ\s0 or \s-1YYYYMMDDHHMMSSZ\s0). If \fIs\fR is \s-1NULL\s0 -this function performs a format check on \fIstr\fR only. The string \fIstr\fR -is copied into \fIs\fR. -.PP -\&\fBASN1_TIME_set_string_X509()\fR sets \fB\s-1ASN1_TIME\s0\fR structure \fIs\fR to the time -represented by string \fIstr\fR which must be in appropriate time format -that \s-1RFC 5280\s0 requires, which means it only allows \s-1YYMMDDHHMMSSZ\s0 and -\&\s-1YYYYMMDDHHMMSSZ\s0 (leap second is rejected), all other \s-1ASN.1\s0 time format -are not allowed. If \fIs\fR is \s-1NULL\s0 this function performs a format check -on \fIstr\fR only. -.PP -The \fBASN1_TIME_normalize()\fR function converts an \fB\s-1ASN1_GENERALIZEDTIME\s0\fR or -\&\fB\s-1ASN1_UTCTIME\s0\fR into a time value that can be used in a certificate. It -should be used after the \fBASN1_TIME_set_string()\fR functions and before -\&\fBASN1_TIME_print()\fR functions to get consistent (i.e. \s-1GMT\s0) results. -.PP -The \fBASN1_TIME_check()\fR, \fBASN1_UTCTIME_check()\fR and \fBASN1_GENERALIZEDTIME_check()\fR -functions check the syntax of the time structure \fIs\fR. -.PP -The \fBASN1_TIME_print()\fR, \fBASN1_UTCTIME_print()\fR and \fBASN1_GENERALIZEDTIME_print()\fR -functions print the time structure \fIs\fR to \s-1BIO\s0 \fIb\fR in human readable -format. It will be of the format \s-1MMM DD\s0 HH:MM:SS[.s*] \s-1YYYY GMT,\s0 for example -\&\*(L"Feb 3 00:55:52 2015 \s-1GMT\*(R",\s0 which does not include a newline. -If the time structure has invalid format it prints out \*(L"Bad time value\*(R" and -returns an error. The output for generalized time may include a fractional part -following the second. -.PP -\&\fBASN1_TIME_print_ex()\fR provides \fIflags\fR to specify the output format of the -datetime. This can be either \fB\s-1ASN1_DTFLGS_RFC822\s0\fR or \fB\s-1ASN1_DTFLGS_ISO8601\s0\fR. -.PP -\&\fBASN1_TIME_to_tm()\fR converts the time \fIs\fR to the standard \fItm\fR structure. -If \fIs\fR is \s-1NULL,\s0 then the current time is converted. The output time is \s-1GMT.\s0 -The \fItm_sec\fR, \fItm_min\fR, \fItm_hour\fR, \fItm_mday\fR, \fItm_wday\fR, \fItm_yday\fR, -\&\fItm_mon\fR and \fItm_year\fR fields of \fItm\fR structure are set to proper values, -whereas all other fields are set to 0. If \fItm\fR is \s-1NULL\s0 this function performs -a format check on \fIs\fR only. If \fIs\fR is in Generalized format with fractional -seconds, e.g. \s-1YYYYMMDDHHMMSS.SSSZ,\s0 the fractional seconds will be lost while -converting \fIs\fR to \fItm\fR structure. -.PP -\&\fBASN1_TIME_diff()\fR sets \fI*pday\fR and \fI*psec\fR to the time difference between -\&\fIfrom\fR and \fIto\fR. If \fIto\fR represents a time later than \fIfrom\fR then -one or both (depending on the time difference) of \fI*pday\fR and \fI*psec\fR -will be positive. If \fIto\fR represents a time earlier than \fIfrom\fR then -one or both of \fI*pday\fR and \fI*psec\fR will be negative. If \fIto\fR and \fIfrom\fR -represent the same time then \fI*pday\fR and \fI*psec\fR will both be zero. -If both \fI*pday\fR and \fI*psec\fR are nonzero they will always have the same -sign. The value of \fI*psec\fR will always be less than the number of seconds -in a day. If \fIfrom\fR or \fIto\fR is \s-1NULL\s0 the current time is used. -.PP -The \fBASN1_TIME_cmp_time_t()\fR and \fBASN1_UTCTIME_cmp_time_t()\fR functions compare -the two times represented by the time structure \fIs\fR and the time_t \fIt\fR. -.PP -The \fBASN1_TIME_compare()\fR function compares the two times represented by the -time structures \fIa\fR and \fIb\fR. -.PP -The \fBASN1_TIME_to_generalizedtime()\fR function converts an \fB\s-1ASN1_TIME\s0\fR to an -\&\fB\s-1ASN1_GENERALIZEDTIME\s0\fR, regardless of year. If either \fIout\fR or -\&\fI*out\fR are \s-1NULL,\s0 then a new object is allocated and must be freed after use. -.PP -The \fBASN1_TIME_dup()\fR, \fBASN1_UTCTIME_dup()\fR and \fBASN1_GENERALIZEDTIME_dup()\fR functions -duplicate the time structure \fIt\fR and return the duplicated result -correspondingly. -.SH "NOTES" -.IX Header "NOTES" -The \fB\s-1ASN1_TIME\s0\fR structure corresponds to the \s-1ASN.1\s0 structure \fBTime\fR -defined in \s-1RFC5280\s0 et al. The time setting functions obey the rules outlined -in \s-1RFC5280:\s0 if the date can be represented by UTCTime it is used, else -GeneralizedTime is used. -.PP -The \fB\s-1ASN1_TIME\s0\fR, \fB\s-1ASN1_UTCTIME\s0\fR and \fB\s-1ASN1_GENERALIZEDTIME\s0\fR structures are -represented as an \fB\s-1ASN1_STRING\s0\fR internally and can be freed up using -\&\fBASN1_STRING_free()\fR. -.PP -The \fB\s-1ASN1_TIME\s0\fR structure can represent years from 0000 to 9999 but no attempt -is made to correct ancient calendar changes (for example from Julian to -Gregorian calendars). -.PP -\&\fB\s-1ASN1_UTCTIME\s0\fR is limited to a year range of 1950 through 2049. -.PP -Some applications add offset times directly to a time_t value and pass the -results to \fBASN1_TIME_set()\fR (or equivalent). This can cause problems as the -time_t value can overflow on some systems resulting in unexpected results. -New applications should use \fBASN1_TIME_adj()\fR instead and pass the offset value -in the \fIoffset_sec\fR and \fIoffset_day\fR parameters instead of directly -manipulating a time_t value. -.PP -\&\fBASN1_TIME_adj()\fR may change the type from \fB\s-1ASN1_GENERALIZEDTIME\s0\fR to -\&\fB\s-1ASN1_UTCTIME\s0\fR, or vice versa, based on the resulting year. -\&\fBASN1_GENERALIZEDTIME_adj()\fR and \fBASN1_UTCTIME_adj()\fR will not modify the type -of the return structure. -.PP -It is recommended that functions starting with \fB\s-1ASN1_TIME\s0\fR be used instead of -those starting with \fB\s-1ASN1_UTCTIME\s0\fR or \fB\s-1ASN1_GENERALIZEDTIME\s0\fR. The functions -starting with \fB\s-1ASN1_UTCTIME\s0\fR and \fB\s-1ASN1_GENERALIZEDTIME\s0\fR act only on that -specific time format. The functions starting with \fB\s-1ASN1_TIME\s0\fR will operate on -either format. -.PP -Users familiar with \s-1RFC822\s0 should note that when specifying the flag -\&\fB\s-1ASN1_DTFLGS_RFC822\s0\fR the year will be formatted as documented above, -i.e., using 4 digits, not 2 as specified in \s-1RFC822.\s0 -.SH "BUGS" -.IX Header "BUGS" -\&\fBASN1_TIME_print()\fR, \fBASN1_UTCTIME_print()\fR and \fBASN1_GENERALIZEDTIME_print()\fR do -not print out the timezone: it either prints out \*(L"\s-1GMT\*(R"\s0 or nothing. But all -certificates complying with \s-1RFC5280\s0 et al use \s-1GMT\s0 anyway. -.PP -\&\fBASN1_TIME_print()\fR, \fBASN1_TIME_print_ex()\fR, \fBASN1_UTCTIME_print()\fR and -\&\fBASN1_GENERALIZEDTIME_print()\fR do not distinguish if they fail because -of an I/O error or invalid time format. -.PP -Use the \fBASN1_TIME_normalize()\fR function to normalize the time value before -printing to get \s-1GMT\s0 results. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_TIME_set()\fR, \fBASN1_UTCTIME_set()\fR, \fBASN1_GENERALIZEDTIME_set()\fR, -\&\fBASN1_TIME_adj()\fR, \fBASN1_UTCTIME_adj()\fR and \fBASN1_GENERALIZEDTIME_set()\fR return -a pointer to a time structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBASN1_TIME_set_string()\fR, \fBASN1_UTCTIME_set_string()\fR, -\&\fBASN1_GENERALIZEDTIME_set_string()\fR and \fBASN1_TIME_set_string_X509()\fR return -1 if the time value is successfully set and 0 otherwise. -.PP -\&\fBASN1_TIME_normalize()\fR returns 1 on success, and 0 on error. -.PP -\&\fBASN1_TIME_check()\fR, ASN1_UTCTIME_check and \fBASN1_GENERALIZEDTIME_check()\fR return 1 -if the structure is syntactically correct and 0 otherwise. -.PP -\&\fBASN1_TIME_print()\fR, \fBASN1_UTCTIME_print()\fR and \fBASN1_GENERALIZEDTIME_print()\fR -return 1 if the time is successfully printed out and -0 if an I/O error occurred an error occurred (I/O error or invalid time format). -.PP -\&\fBASN1_TIME_to_tm()\fR returns 1 if the time is successfully parsed and 0 if an -error occurred (invalid time format). -.PP -\&\fBASN1_TIME_diff()\fR returns 1 for success and 0 for failure. It can fail if the -passed-in time structure has invalid syntax, for example. -.PP -\&\fBASN1_TIME_cmp_time_t()\fR and \fBASN1_UTCTIME_cmp_time_t()\fR return \-1 if \fIs\fR is -before \fIt\fR, 0 if \fIs\fR equals \fIt\fR, or 1 if \fIs\fR is after \fIt\fR. \-2 is returned -on error. -.PP -\&\fBASN1_TIME_compare()\fR returns \-1 if \fIa\fR is before \fIb\fR, 0 if \fIa\fR equals \fIb\fR, -or 1 if \fIa\fR is after \fIb\fR. \-2 is returned on error. -.PP -\&\fBASN1_TIME_to_generalizedtime()\fR returns a pointer to the appropriate time -structure on success or \s-1NULL\s0 if an error occurred. -.PP -\&\fBASN1_TIME_dup()\fR, \fBASN1_UTCTIME_dup()\fR and \fBASN1_GENERALIZEDTIME_dup()\fR return a -pointer to a time structure or \s-1NULL\s0 if an error occurred. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Set a time structure to one hour after the current time and print it out: -.PP -.Vb 2 -\& #include -\& #include -\& -\& ASN1_TIME *tm; -\& time_t t; -\& BIO *b; -\& -\& t = time(NULL); -\& tm = ASN1_TIME_adj(NULL, t, 0, 60 * 60); -\& b = BIO_new_fp(stdout, BIO_NOCLOSE); -\& ASN1_TIME_print(b, tm); -\& ASN1_STRING_free(tm); -\& BIO_free(b); -.Ve -.PP -Determine if one time is later or sooner than the current time: -.PP -.Vb 1 -\& int day, sec; -\& -\& if (!ASN1_TIME_diff(&day, &sec, NULL, to)) -\& /* Invalid time format */ -\& -\& if (day > 0 || sec > 0) -\& printf("Later\en"); -\& else if (day < 0 || sec < 0) -\& printf("Sooner\en"); -\& else -\& printf("Same\en"); -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -The \fBASN1_TIME_to_tm()\fR function was added in OpenSSL 1.1.1. -The \fBASN1_TIME_set_string_X509()\fR function was added in OpenSSL 1.1.1. -The \fBASN1_TIME_normalize()\fR function was added in OpenSSL 1.1.1. -The \fBASN1_TIME_cmp_time_t()\fR function was added in OpenSSL 1.1.1. -The \fBASN1_TIME_compare()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_TIME_set_string.3ossl b/openssl-install/share/man/man3/ASN1_TIME_set_string.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_set_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_set_string_X509.3ossl b/openssl-install/share/man/man3/ASN1_TIME_set_string_X509.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_set_string_X509.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_to_generalizedtime.3ossl b/openssl-install/share/man/man3/ASN1_TIME_to_generalizedtime.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_to_generalizedtime.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TIME_to_tm.3ossl b/openssl-install/share/man/man3/ASN1_TIME_to_tm.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_TIME_to_tm.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TYPE_cmp.3ossl b/openssl-install/share/man/man3/ASN1_TYPE_cmp.3ossl deleted file mode 120000 index 8503b83f..00000000 --- a/openssl-install/share/man/man3/ASN1_TYPE_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TYPE_get.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TYPE_get.3ossl b/openssl-install/share/man/man3/ASN1_TYPE_get.3ossl deleted file mode 100644 index e4ecf69e..00000000 --- a/openssl-install/share/man/man3/ASN1_TYPE_get.3ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_TYPE_GET 3ossl" -.TH ASN1_TYPE_GET 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_TYPE_get, ASN1_TYPE_set, ASN1_TYPE_set1, ASN1_TYPE_cmp, ASN1_TYPE_unpack_sequence, ASN1_TYPE_pack_sequence \- ASN1_TYPE utility -functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ASN1_TYPE_get(const ASN1_TYPE *a); -\& void ASN1_TYPE_set(ASN1_TYPE *a, int type, void *value); -\& int ASN1_TYPE_set1(ASN1_TYPE *a, int type, const void *value); -\& int ASN1_TYPE_cmp(const ASN1_TYPE *a, const ASN1_TYPE *b); -\& -\& void *ASN1_TYPE_unpack_sequence(const ASN1_ITEM *it, const ASN1_TYPE *t); -\& ASN1_TYPE *ASN1_TYPE_pack_sequence(const ASN1_ITEM *it, void *s, -\& ASN1_TYPE **t); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions allow an \fB\s-1ASN1_TYPE\s0\fR structure to be manipulated. The -\&\fB\s-1ASN1_TYPE\s0\fR structure can contain any \s-1ASN.1\s0 type or constructed type -such as a \s-1SEQUENCE:\s0 it is effectively equivalent to the \s-1ASN.1 ANY\s0 type. -.PP -\&\fBASN1_TYPE_get()\fR returns the type of \fIa\fR or 0 if it fails. -.PP -\&\fBASN1_TYPE_set()\fR sets the value of \fIa\fR to \fItype\fR and \fIvalue\fR. This -function uses the pointer \fIvalue\fR internally so it must \fBnot\fR be freed -up after the call. -.PP -\&\fBASN1_TYPE_set1()\fR sets the value of \fIa\fR to \fItype\fR a copy of \fIvalue\fR. -.PP -\&\fBASN1_TYPE_cmp()\fR compares \s-1ASN.1\s0 types \fIa\fR and \fIb\fR and returns 0 if -they are identical and nonzero otherwise. -.PP -\&\fBASN1_TYPE_unpack_sequence()\fR attempts to parse the \s-1SEQUENCE\s0 present in -\&\fIt\fR using the \s-1ASN.1\s0 structure \fIit\fR. If successful it returns a pointer -to the \s-1ASN.1\s0 structure corresponding to \fIit\fR which must be freed by the -caller. If it fails it return \s-1NULL.\s0 -.PP -\&\fBASN1_TYPE_pack_sequence()\fR attempts to encode the \s-1ASN.1\s0 structure \fIs\fR -corresponding to \fIit\fR into an \fB\s-1ASN1_TYPE\s0\fR. If successful the encoded -\&\fB\s-1ASN1_TYPE\s0\fR is returned. If \fIt\fR and \fI*t\fR are not \s-1NULL\s0 the encoded type -is written to \fIt\fR overwriting any existing data. If \fIt\fR is not \s-1NULL\s0 -but \fI*t\fR is \s-1NULL\s0 the returned \fB\s-1ASN1_TYPE\s0\fR is written to \fI*t\fR. -.SH "NOTES" -.IX Header "NOTES" -The type and meaning of the \fIvalue\fR parameter for \fBASN1_TYPE_set()\fR and -\&\fBASN1_TYPE_set1()\fR is determined by the \fItype\fR parameter. -If \fItype\fR is \fBV_ASN1_NULL\fR \fIvalue\fR is ignored. If \fItype\fR is -\&\fBV_ASN1_BOOLEAN\fR -then the boolean is set to \s-1TRUE\s0 if \fIvalue\fR is not \s-1NULL.\s0 If \fItype\fR is -\&\fBV_ASN1_OBJECT\fR then value is an \fB\s-1ASN1_OBJECT\s0\fR structure. Otherwise \fItype\fR -is and \fB\s-1ASN1_STRING\s0\fR structure. If \fItype\fR corresponds to a primitive type -(or a string type) then the contents of the \fB\s-1ASN1_STRING\s0\fR contain the content -octets of the type. If \fItype\fR corresponds to a constructed type or -a tagged type (\fBV_ASN1_SEQUENCE\fR, \fBV_ASN1_SET\fR or \fBV_ASN1_OTHER\fR) then the -\&\fB\s-1ASN1_STRING\s0\fR contains the entire \s-1ASN.1\s0 encoding verbatim (including tag and -length octets). -.PP -\&\fBASN1_TYPE_cmp()\fR may not return zero if two types are equivalent but have -different encodings. For example the single content octet of the boolean \s-1TRUE\s0 -value under \s-1BER\s0 can have any nonzero encoding but \fBASN1_TYPE_cmp()\fR will -only return zero if the values are the same. -.PP -If either or both of the parameters passed to \fBASN1_TYPE_cmp()\fR is \s-1NULL\s0 the -return value is nonzero. Technically if both parameters are \s-1NULL\s0 the two -types could be absent \s-1OPTIONAL\s0 fields and so should match, however, passing -\&\s-1NULL\s0 values could also indicate a programming error (for example an -unparsable type which returns \s-1NULL\s0) for types which do \fBnot\fR match. So -applications should handle the case of two absent values separately. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_TYPE_get()\fR returns the type of the \fB\s-1ASN1_TYPE\s0\fR argument. -.PP -\&\fBASN1_TYPE_set()\fR does not return a value. -.PP -\&\fBASN1_TYPE_set1()\fR returns 1 for success and 0 for failure. -.PP -\&\fBASN1_TYPE_cmp()\fR returns 0 if the types are identical and nonzero otherwise. -.PP -\&\fBASN1_TYPE_unpack_sequence()\fR returns a pointer to an \s-1ASN.1\s0 structure or -\&\s-1NULL\s0 on failure. -.PP -\&\fBASN1_TYPE_pack_sequence()\fR return an \fB\s-1ASN1_TYPE\s0\fR structure if it succeeds or -\&\s-1NULL\s0 on failure. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_TYPE_pack_sequence.3ossl b/openssl-install/share/man/man3/ASN1_TYPE_pack_sequence.3ossl deleted file mode 120000 index 8503b83f..00000000 --- a/openssl-install/share/man/man3/ASN1_TYPE_pack_sequence.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TYPE_get.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TYPE_set.3ossl b/openssl-install/share/man/man3/ASN1_TYPE_set.3ossl deleted file mode 120000 index 8503b83f..00000000 --- a/openssl-install/share/man/man3/ASN1_TYPE_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TYPE_get.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TYPE_set1.3ossl b/openssl-install/share/man/man3/ASN1_TYPE_set1.3ossl deleted file mode 120000 index 8503b83f..00000000 --- a/openssl-install/share/man/man3/ASN1_TYPE_set1.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TYPE_get.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_TYPE_unpack_sequence.3ossl b/openssl-install/share/man/man3/ASN1_TYPE_unpack_sequence.3ossl deleted file mode 120000 index 8503b83f..00000000 --- a/openssl-install/share/man/man3/ASN1_TYPE_unpack_sequence.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TYPE_get.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_UTCTIME_adj.3ossl b/openssl-install/share/man/man3/ASN1_UTCTIME_adj.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_UTCTIME_adj.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_UTCTIME_check.3ossl b/openssl-install/share/man/man3/ASN1_UTCTIME_check.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_UTCTIME_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_UTCTIME_cmp_time_t.3ossl b/openssl-install/share/man/man3/ASN1_UTCTIME_cmp_time_t.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_UTCTIME_cmp_time_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_UTCTIME_dup.3ossl b/openssl-install/share/man/man3/ASN1_UTCTIME_dup.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_UTCTIME_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_UTCTIME_print.3ossl b/openssl-install/share/man/man3/ASN1_UTCTIME_print.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_UTCTIME_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_UTCTIME_set.3ossl b/openssl-install/share/man/man3/ASN1_UTCTIME_set.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_UTCTIME_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_UTCTIME_set_string.3ossl b/openssl-install/share/man/man3/ASN1_UTCTIME_set_string.3ossl deleted file mode 120000 index e98f8e4a..00000000 --- a/openssl-install/share/man/man3/ASN1_UTCTIME_set_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_TIME_set.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_add_oid_module.3ossl b/openssl-install/share/man/man3/ASN1_add_oid_module.3ossl deleted file mode 120000 index 5fd046e1..00000000 --- a/openssl-install/share/man/man3/ASN1_add_oid_module.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_load_builtin_modules.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_aux_cb.3ossl b/openssl-install/share/man/man3/ASN1_aux_cb.3ossl deleted file mode 100644 index 7d419060..00000000 --- a/openssl-install/share/man/man3/ASN1_aux_cb.3ossl +++ /dev/null @@ -1,368 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_AUX_CB 3ossl" -.TH ASN1_AUX_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_AUX, ASN1_PRINT_ARG, ASN1_STREAM_ARG, ASN1_aux_cb, ASN1_aux_const_cb -\&\- ASN.1 auxiliary data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& struct ASN1_AUX_st { -\& void *app_data; -\& int flags; -\& int ref_offset; /* Offset of reference value */ -\& int ref_lock; /* Offset to an CRYPTO_RWLOCK */ -\& ASN1_aux_cb *asn1_cb; -\& int enc_offset; /* Offset of ASN1_ENCODING structure */ -\& ASN1_aux_const_cb *asn1_const_cb; /* for ASN1_OP_I2D_ and ASN1_OP_PRINT_ */ -\& }; -\& typedef struct ASN1_AUX_st ASN1_AUX; -\& -\& struct ASN1_PRINT_ARG_st { -\& BIO *out; -\& int indent; -\& const ASN1_PCTX *pctx; -\& }; -\& typedef struct ASN1_PRINT_ARG_st ASN1_PRINT_ARG; -\& -\& struct ASN1_STREAM_ARG_st { -\& BIO *out; -\& BIO *ndef_bio; -\& unsigned char **boundary; -\& }; -\& typedef struct ASN1_STREAM_ARG_st ASN1_STREAM_ARG; -\& -\& typedef int ASN1_aux_cb(int operation, ASN1_VALUE **in, const ASN1_ITEM *it, -\& void *exarg); -\& typedef int ASN1_aux_const_cb(int operation, const ASN1_VALUE **in, -\& const ASN1_ITEM *it, void *exarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1ASN.1\s0 data structures can be associated with an \fB\s-1ASN1_AUX\s0\fR object to supply -additional information about the \s-1ASN.1\s0 structure. An \fB\s-1ASN1_AUX\s0\fR structure is -associated with the structure during the definition of the \s-1ASN.1\s0 template. For -example an \fB\s-1ASN1_AUX\s0\fR structure will be associated by using one of the various -\&\s-1ASN.1\s0 template definition macros that supply auxiliary information such as -\&\fBASN1_SEQUENCE_enc()\fR, \fBASN1_SEQUENCE_ref()\fR, \fBASN1_SEQUENCE_cb_const_cb()\fR, -\&\fBASN1_SEQUENCE_const_cb()\fR, \fBASN1_SEQUENCE_cb()\fR or \fBASN1_NDEF_SEQUENCE_cb()\fR. -.PP -An \fB\s-1ASN1_AUX\s0\fR structure contains the following information. -.IP "\fIapp_data\fR" 4 -.IX Item "app_data" -Arbitrary application data -.IP "\fIflags\fR" 4 -.IX Item "flags" -Flags which indicate the auxiliarly functionality supported. -.Sp -The \fB\s-1ASN1_AFLG_REFCOUNT\s0\fR flag indicates that objects support reference counting. -.Sp -The \fB\s-1ASN1_AFLG_ENCODING\s0\fR flag indicates that the original encoding of the -object will be saved. -.Sp -The \fB\s-1ASN1_AFLG_BROKEN\s0\fR flag is a work around for broken encoders where the -sequence length value may not be correct. This should generally not be used. -.Sp -The \fB\s-1ASN1_AFLG_CONST_CB\s0\fR flag indicates that the \*(L"const\*(R" form of the -\&\fB\s-1ASN1_AUX\s0\fR callback should be used in preference to the non-const form. -.IP "\fIref_offset\fR" 4 -.IX Item "ref_offset" -If the \fB\s-1ASN1_AFLG_REFCOUNT\s0\fR flag is set then this value is assumed to be an -offset into the \fB\s-1ASN1_VALUE\s0\fR structure where a \fB\s-1CRYPTO_REF_COUNT\s0\fR may be -found for the purposes of reference counting. -.IP "\fIref_lock\fR" 4 -.IX Item "ref_lock" -If the \fB\s-1ASN1_AFLG_REFCOUNT\s0\fR flag is set then this value is assumed to be an -offset into the \fB\s-1ASN1_VALUE\s0\fR structure where a \fB\s-1CRYPTO_RWLOCK\s0\fR may be -found for the purposes of reference counting. -.IP "\fIasn1_cb\fR" 4 -.IX Item "asn1_cb" -A callback that will be invoked at various points during the processing of -the \fB\s-1ASN1_VALUE\s0\fR. See below for further details. -.IP "\fIenc_offset\fR" 4 -.IX Item "enc_offset" -Offset into the \fB\s-1ASN1_VALUE\s0\fR object where the original encoding of the object -will be saved if the \fB\s-1ASN1_AFLG_ENCODING\s0\fR flag has been set. -.IP "\fIasn1_const_cb\fR" 4 -.IX Item "asn1_const_cb" -A callback that will be invoked at various points during the processing of -the \fB\s-1ASN1_VALUE\s0\fR. This is used in preference to the \fIasn1_cb\fR callback if -the \fB\s-1ASN1_AFLG_CONST_CB\s0\fR flag is set. See below for further details. -.PP -During the processing of an \fB\s-1ASN1_VALUE\s0\fR object the callbacks set via -\&\fIasn1_cb\fR or \fIasn1_const_cb\fR will be invoked as a result of various events -indicated via the \fIoperation\fR parameter. The value of \fI*in\fR will be the -\&\fB\s-1ASN1_VALUE\s0\fR object being processed based on the template in \fIit\fR. An -additional operation specific parameter may be passed in \fIexarg\fR. The currently -supported operations are as follows. The callbacks should return a positive -value on success or zero on error, unless otherwise noted below. -.IP "\fB\s-1ASN1_OP_NEW_PRE\s0\fR" 4 -.IX Item "ASN1_OP_NEW_PRE" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -prior to an \fB\s-1ASN1_VALUE\s0\fR object being allocated. The callback may allocate the -\&\fB\s-1ASN1_VALUE\s0\fR itself and store it in \fI*pval\fR. If it does so it should return 2 -from the callback. On error it should return 0. -.IP "\fB\s-1ASN1_OP_NEW_POST\s0\fR" 4 -.IX Item "ASN1_OP_NEW_POST" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -after an \fB\s-1ASN1_VALUE\s0\fR object has been allocated. The allocated object is in -\&\fI*pval\fR. -.IP "\fB\s-1ASN1_OP_FREE_PRE\s0\fR" 4 -.IX Item "ASN1_OP_FREE_PRE" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -immediately before an \fB\s-1ASN1_VALUE\s0\fR is freed. If the callback originally -constructed the \fB\s-1ASN1_VALUE\s0\fR via \fB\s-1ASN1_OP_NEW_PRE\s0\fR then it should free it at -this point and return 2 from the callback. Otherwise it should return 1 for -success or 0 on error. -.IP "\fB\s-1ASN1_OP_FREE_POST\s0\fR" 4 -.IX Item "ASN1_OP_FREE_POST" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -immediately after \fB\s-1ASN1_VALUE\s0\fR sub-structures are freed. -.IP "\fB\s-1ASN1_OP_D2I_PRE\s0\fR" 4 -.IX Item "ASN1_OP_D2I_PRE" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -immediately before a \*(L"d2i\*(R" operation for the \fB\s-1ASN1_VALUE\s0\fR. -.IP "\fB\s-1ASN1_OP_D2I_POST\s0\fR" 4 -.IX Item "ASN1_OP_D2I_POST" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -immediately after a \*(L"d2i\*(R" operation for the \fB\s-1ASN1_VALUE\s0\fR. -.IP "\fB\s-1ASN1_OP_I2D_PRE\s0\fR" 4 -.IX Item "ASN1_OP_I2D_PRE" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -immediately before a \*(L"i2d\*(R" operation for the \fB\s-1ASN1_VALUE\s0\fR. -.IP "\fB\s-1ASN1_OP_I2D_POST\s0\fR" 4 -.IX Item "ASN1_OP_I2D_POST" -Invoked when processing a \fB\s-1CHOICE\s0\fR, \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure -immediately after a \*(L"i2d\*(R" operation for the \fB\s-1ASN1_VALUE\s0\fR. -.IP "\fB\s-1ASN1_OP_PRINT_PRE\s0\fR" 4 -.IX Item "ASN1_OP_PRINT_PRE" -Invoked when processing a \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure immediately -before printing the \fB\s-1ASN1_VALUE\s0\fR. The \fIexarg\fR argument will be a pointer to an -\&\fB\s-1ASN1_PRINT_ARG\s0\fR structure (see below). -.IP "\fB\s-1ASN1_OP_PRINT_POST\s0\fR" 4 -.IX Item "ASN1_OP_PRINT_POST" -Invoked when processing a \fB\s-1SEQUENCE\s0\fR or \fB\s-1NDEF_SEQUENCE\s0\fR structure immediately -after printing the \fB\s-1ASN1_VALUE\s0\fR. The \fIexarg\fR argument will be a pointer to an -\&\fB\s-1ASN1_PRINT_ARG\s0\fR structure (see below). -.IP "\fB\s-1ASN1_OP_STREAM_PRE\s0\fR" 4 -.IX Item "ASN1_OP_STREAM_PRE" -Invoked immediately prior to streaming the \fB\s-1ASN1_VALUE\s0\fR data using indefinite -length encoding. The \fIexarg\fR argument will be a pointer to a \fB\s-1ASN1_STREAM_ARG\s0\fR -structure (see below). -.IP "\fB\s-1ASN1_OP_STREAM_POST\s0\fR" 4 -.IX Item "ASN1_OP_STREAM_POST" -Invoked immediately after streaming the \fB\s-1ASN1_VALUE\s0\fR data using indefinite -length encoding. The \fIexarg\fR argument will be a pointer to a \fB\s-1ASN1_STREAM_ARG\s0\fR -structure (see below). -.IP "\fB\s-1ASN1_OP_DETACHED_PRE\s0\fR" 4 -.IX Item "ASN1_OP_DETACHED_PRE" -Invoked immediately prior to processing the \fB\s-1ASN1_VALUE\s0\fR data as a \*(L"detached\*(R" -value (as used in \s-1CMS\s0 and \s-1PKCS7\s0). The \fIexarg\fR argument will be a pointer to a -\&\fB\s-1ASN1_STREAM_ARG\s0\fR structure (see below). -.IP "\fB\s-1ASN1_OP_DETACHED_POST\s0\fR" 4 -.IX Item "ASN1_OP_DETACHED_POST" -Invoked immediately after processing the \fB\s-1ASN1_VALUE\s0\fR data as a \*(L"detached\*(R" -value (as used in \s-1CMS\s0 and \s-1PKCS7\s0). The \fIexarg\fR argument will be a pointer to a -\&\fB\s-1ASN1_STREAM_ARG\s0\fR structure (see below). -.IP "\fB\s-1ASN1_OP_DUP_PRE\s0\fR" 4 -.IX Item "ASN1_OP_DUP_PRE" -Invoked immediate prior to an \s-1ASN1_VALUE\s0 being duplicated via a call to -\&\fBASN1_item_dup()\fR. -.IP "\fB\s-1ASN1_OP_DUP_POST\s0\fR" 4 -.IX Item "ASN1_OP_DUP_POST" -Invoked immediate after to an \s-1ASN1_VALUE\s0 has been duplicated via a call to -\&\fBASN1_item_dup()\fR. -.IP "\fB\s-1ASN1_OP_GET0_LIBCTX\s0\fR" 4 -.IX Item "ASN1_OP_GET0_LIBCTX" -Invoked in order to obtain the \fB\s-1OSSL_LIB_CTX\s0\fR associated with an \fB\s-1ASN1_VALUE\s0\fR -if any. A pointer to an \fB\s-1OSSL_LIB_CTX\s0\fR should be stored in \fI*exarg\fR if such -a value exists. -.IP "\fB\s-1ASN1_OP_GET0_PROPQ\s0\fR" 4 -.IX Item "ASN1_OP_GET0_PROPQ" -Invoked in order to obtain the property query string associated with an -\&\fB\s-1ASN1_VALUE\s0\fR if any. A pointer to the property query string should be stored in -\&\fI*exarg\fR if such a value exists. -.PP -An \fB\s-1ASN1_PRINT_ARG\s0\fR object is used during processing of \fB\s-1ASN1_OP_PRINT_PRE\s0\fR -and \fB\s-1ASN1_OP_PRINT_POST\s0\fR callback operations. It contains the following -information. -.IP "\fIout\fR" 4 -.IX Item "out" -The \fB\s-1BIO\s0\fR being used to print the data out. -.IP "\fIndef_bio\fR" 4 -.IX Item "ndef_bio" -The current number of indent spaces that should be used for printing this data. -.IP "\fIpctx\fR" 4 -.IX Item "pctx" -The context for the \fB\s-1ASN1_PCTX\s0\fR operation. -.PP -An \fB\s-1ASN1_STREAM_ARG\s0\fR object is used during processing of \fB\s-1ASN1_OP_STREAM_PRE\s0\fR, -\&\fB\s-1ASN1_OP_STREAM_POST\s0\fR, \fB\s-1ASN1_OP_DETACHED_PRE\s0\fR and \fB\s-1ASN1_OP_DETACHED_POST\s0\fR -callback operations. It contains the following information. -.IP "\fIout\fR" 4 -.IX Item "out" -The \fB\s-1BIO\s0\fR to stream through -.IP "\fIndef_bio\fR" 4 -.IX Item "ndef_bio" -The \fB\s-1BIO\s0\fR with filters appended -.IP "\fIboundary\fR" 4 -.IX Item "boundary" -The streaming I/O boundary. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The callbacks return 0 on error and a positive value on success. Some operations -require specific positive success values as noted above. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBASN1_item_new_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBASN1_aux_const_cb()\fR callback and the \fB\s-1ASN1_OP_GET0_LIBCTX\s0\fR and -\&\fB\s-1ASN1_OP_GET0_PROPQ\s0\fR operation types were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_aux_const_cb.3ossl b/openssl-install/share/man/man3/ASN1_aux_const_cb.3ossl deleted file mode 120000 index ec226b0c..00000000 --- a/openssl-install/share/man/man3/ASN1_aux_const_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_aux_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ex_d2i.3ossl b/openssl-install/share/man/man3/ASN1_ex_d2i.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/ASN1_ex_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ex_d2i_ex.3ossl b/openssl-install/share/man/man3/ASN1_ex_d2i_ex.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/ASN1_ex_d2i_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ex_free_func.3ossl b/openssl-install/share/man/man3/ASN1_ex_free_func.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/ASN1_ex_free_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ex_i2d.3ossl b/openssl-install/share/man/man3/ASN1_ex_i2d.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/ASN1_ex_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ex_new_ex_func.3ossl b/openssl-install/share/man/man3/ASN1_ex_new_ex_func.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/ASN1_ex_new_ex_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ex_new_func.3ossl b/openssl-install/share/man/man3/ASN1_ex_new_func.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/ASN1_ex_new_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_ex_print_func.3ossl b/openssl-install/share/man/man3/ASN1_ex_print_func.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/ASN1_ex_print_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_generate_nconf.3ossl b/openssl-install/share/man/man3/ASN1_generate_nconf.3ossl deleted file mode 100644 index 1955d9be..00000000 --- a/openssl-install/share/man/man3/ASN1_generate_nconf.3ossl +++ /dev/null @@ -1,382 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_GENERATE_NCONF 3ossl" -.TH ASN1_GENERATE_NCONF 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_generate_nconf, ASN1_generate_v3 \- ASN1 string generation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_TYPE *ASN1_generate_nconf(const char *str, CONF *nconf); -\& ASN1_TYPE *ASN1_generate_v3(const char *str, X509V3_CTX *cnf); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions generate the \s-1ASN1\s0 encoding of a string -in an \fB\s-1ASN1_TYPE\s0\fR structure. -.PP -\&\fIstr\fR contains the string to encode. \fInconf\fR or \fIcnf\fR contains -the optional configuration information where additional strings -will be read from. \fInconf\fR will typically come from a config -file whereas \fIcnf\fR is obtained from an \fBX509V3_CTX\fR structure, -which will typically be used by X509 v3 certificate extension -functions. \fIcnf\fR or \fInconf\fR can be set to \s-1NULL\s0 if no additional -configuration will be used. -.SH "GENERATION STRING FORMAT" -.IX Header "GENERATION STRING FORMAT" -The actual data encoded is determined by the string \fIstr\fR and -the configuration information. The general format of the string -is: -.IP "[\fImodifier\fR,]\fItype\fR[:\fIvalue\fR]" 4 -.IX Item "[modifier,]type[:value]" -.PP -That is zero or more comma separated modifiers followed by a type -followed by an optional colon and a value. The formats of \fItype\fR, -\&\fIvalue\fR and \fImodifier\fR are explained below. -.SS "Supported Types" -.IX Subsection "Supported Types" -The supported types are listed below. -Case is not significant in the type names. -Unless otherwise specified only the \fB\s-1ASCII\s0\fR format is permissible. -.IP "\fB\s-1BOOLEAN\s0\fR, \fB\s-1BOOL\s0\fR" 4 -.IX Item "BOOLEAN, BOOL" -This encodes a boolean type. The \fIvalue\fR string is mandatory and -should be \fB\s-1TRUE\s0\fR or \fB\s-1FALSE\s0\fR. Additionally \fB\s-1TRUE\s0\fR, \fBtrue\fR, \fBY\fR, -\&\fBy\fR, \fB\s-1YES\s0\fR, \fByes\fR, \fB\s-1FALSE\s0\fR, \fBfalse\fR, \fBN\fR, \fBn\fR, \fB\s-1NO\s0\fR and \fBno\fR -are acceptable. -.IP "\fB\s-1NULL\s0\fR" 4 -.IX Item "NULL" -Encode the \fB\s-1NULL\s0\fR type, the \fIvalue\fR string must not be present. -.IP "\fB\s-1INTEGER\s0\fR, \fB\s-1INT\s0\fR" 4 -.IX Item "INTEGER, INT" -Encodes an \s-1ASN1\s0 \fB\s-1INTEGER\s0\fR type. The \fIvalue\fR string represents -the value of the integer, it can be prefaced by a minus sign and -is normally interpreted as a decimal value unless the prefix \fB0x\fR -is included. -.IP "\fB\s-1ENUMERATED\s0\fR, \fB\s-1ENUM\s0\fR" 4 -.IX Item "ENUMERATED, ENUM" -Encodes the \s-1ASN1\s0 \fB\s-1ENUMERATED\s0\fR type, it is otherwise identical to -\&\fB\s-1INTEGER\s0\fR. -.IP "\fB\s-1OBJECT\s0\fR, \fB\s-1OID\s0\fR" 4 -.IX Item "OBJECT, OID" -Encodes an \s-1ASN1\s0 \fB\s-1OBJECT IDENTIFIER\s0\fR, the \fIvalue\fR string can be -a short name, a long name or numerical format. -.IP "\fB\s-1UTCTIME\s0\fR, \fB\s-1UTC\s0\fR" 4 -.IX Item "UTCTIME, UTC" -Encodes an \s-1ASN1\s0 \fBUTCTime\fR structure, the value should be in -the format \fB\s-1YYMMDDHHMMSSZ\s0\fR. -.IP "\fB\s-1GENERALIZEDTIME\s0\fR, \fB\s-1GENTIME\s0\fR" 4 -.IX Item "GENERALIZEDTIME, GENTIME" -Encodes an \s-1ASN1\s0 \fBGeneralizedTime\fR structure, the value should be in -the format \fB\s-1YYYYMMDDHHMMSSZ\s0\fR. -.IP "\fB\s-1OCTETSTRING\s0\fR, \fB\s-1OCT\s0\fR" 4 -.IX Item "OCTETSTRING, OCT" -Encodes an \s-1ASN1\s0 \fB\s-1OCTET STRING\s0\fR. \fIvalue\fR represents the contents -of this structure, the format strings \fB\s-1ASCII\s0\fR and \fB\s-1HEX\s0\fR can be -used to specify the format of \fIvalue\fR. -.IP "\fB\s-1BITSTRING\s0\fR, \fB\s-1BITSTR\s0\fR" 4 -.IX Item "BITSTRING, BITSTR" -Encodes an \s-1ASN1\s0 \fB\s-1BIT STRING\s0\fR. \fIvalue\fR represents the contents -of this structure, the format strings \fB\s-1ASCII\s0\fR, \fB\s-1HEX\s0\fR and \fB\s-1BITLIST\s0\fR -can be used to specify the format of \fIvalue\fR. -.Sp -If the format is anything other than \fB\s-1BITLIST\s0\fR the number of unused -bits is set to zero. -.IP "\fB\s-1UNIVERSALSTRING\s0\fR, \fB\s-1UNIV\s0\fR, \fB\s-1IA5\s0\fR, \fB\s-1IA5STRING\s0\fR, \fB\s-1UTF8\s0\fR, \fBUTF8String\fR, \fB\s-1BMP\s0\fR, \fB\s-1BMPSTRING\s0\fR, \fB\s-1VISIBLESTRING\s0\fR, \fB\s-1VISIBLE\s0\fR, \fB\s-1PRINTABLESTRING\s0\fR, \fB\s-1PRINTABLE\s0\fR, \fBT61\fR, \fBT61STRING\fR, \fB\s-1TELETEXSTRING\s0\fR, \fBGeneralString\fR, \fB\s-1NUMERICSTRING\s0\fR, \fB\s-1NUMERIC\s0\fR" 4 -.IX Item "UNIVERSALSTRING, UNIV, IA5, IA5STRING, UTF8, UTF8String, BMP, BMPSTRING, VISIBLESTRING, VISIBLE, PRINTABLESTRING, PRINTABLE, T61, T61STRING, TELETEXSTRING, GeneralString, NUMERICSTRING, NUMERIC" -These encode the corresponding string types. \fIvalue\fR represents the -contents of this structure. The format can be \fB\s-1ASCII\s0\fR or \fB\s-1UTF8\s0\fR. -.IP "\fB\s-1SEQUENCE\s0\fR, \fB\s-1SEQ\s0\fR, \fB\s-1SET\s0\fR" 4 -.IX Item "SEQUENCE, SEQ, SET" -Formats the result as an \s-1ASN1\s0 \fB\s-1SEQUENCE\s0\fR or \fB\s-1SET\s0\fR type. \fIvalue\fR -should be a section name which will contain the contents. The -field names in the section are ignored and the values are in the -generated string format. If \fIvalue\fR is absent then an empty \s-1SEQUENCE\s0 -will be encoded. -.SS "Modifiers" -.IX Subsection "Modifiers" -Modifiers affect the following structure, they can be used to -add \s-1EXPLICIT\s0 or \s-1IMPLICIT\s0 tagging, add wrappers or to change -the string format of the final type and value. The supported -formats are documented below. -.IP "\fB\s-1EXPLICIT\s0\fR, \fB\s-1EXP\s0\fR" 4 -.IX Item "EXPLICIT, EXP" -Add an explicit tag to the following structure. This string -should be followed by a colon and the tag value to use as a -decimal value. -.Sp -By following the number with \fBU\fR, \fBA\fR, \fBP\fR or \fBC\fR \s-1UNIVERSAL, -APPLICATION, PRIVATE\s0 or \s-1CONTEXT SPECIFIC\s0 tagging can be used, -the default is \s-1CONTEXT SPECIFIC.\s0 -.IP "\fB\s-1IMPLICIT\s0\fR, \fB\s-1IMP\s0\fR" 4 -.IX Item "IMPLICIT, IMP" -This is the same as \fB\s-1EXPLICIT\s0\fR except \s-1IMPLICIT\s0 tagging is used -instead. -.IP "\fB\s-1OCTWRAP\s0\fR, \fB\s-1SEQWRAP\s0\fR, \fB\s-1SETWRAP\s0\fR, \fB\s-1BITWRAP\s0\fR" 4 -.IX Item "OCTWRAP, SEQWRAP, SETWRAP, BITWRAP" -The following structure is surrounded by an \s-1OCTET STRING,\s0 a \s-1SEQUENCE,\s0 -a \s-1SET\s0 or a \s-1BIT STRING\s0 respectively. For a \s-1BIT STRING\s0 the number of unused -bits is set to zero. -.IP "\fB\s-1FORMAT\s0\fR" 4 -.IX Item "FORMAT" -This specifies the format of the ultimate value. It should be followed -by a colon and one of the strings \fB\s-1ASCII\s0\fR, \fB\s-1UTF8\s0\fR, \fB\s-1HEX\s0\fR or \fB\s-1BITLIST\s0\fR. -.Sp -If no format specifier is included then \fB\s-1ASCII\s0\fR is used. If \fB\s-1UTF8\s0\fR is -specified then the value string must be a valid \fB\s-1UTF8\s0\fR string. For \fB\s-1HEX\s0\fR the -output must be a set of hex digits. \fB\s-1BITLIST\s0\fR (which is only valid for a \s-1BIT -STRING\s0) is a comma separated list of the indices of the set bits, all other -bits are zero. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_generate_nconf()\fR and \fBASN1_generate_v3()\fR return the encoded -data as an \fB\s-1ASN1_TYPE\s0\fR structure or \s-1NULL\s0 if an error occurred. -.PP -The error codes that can be obtained by \fBERR_get_error\fR\|(3). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -A simple IA5String: -.PP -.Vb 1 -\& IA5STRING:Hello World -.Ve -.PP -An IA5String explicitly tagged: -.PP -.Vb 1 -\& EXPLICIT:0,IA5STRING:Hello World -.Ve -.PP -An IA5String explicitly tagged using \s-1APPLICATION\s0 tagging: -.PP -.Vb 1 -\& EXPLICIT:0A,IA5STRING:Hello World -.Ve -.PP -A \s-1BITSTRING\s0 with bits 1 and 5 set and all others zero: -.PP -.Vb 1 -\& FORMAT:BITLIST,BITSTRING:1,5 -.Ve -.PP -A more complex example using a config file to produce a -\&\s-1SEQUENCE\s0 consisting of a \s-1BOOL\s0 an \s-1OID\s0 and a UTF8String: -.PP -.Vb 1 -\& asn1 = SEQUENCE:seq_section -\& -\& [seq_section] -\& -\& field1 = BOOLEAN:TRUE -\& field2 = OID:commonName -\& field3 = UTF8:Third field -.Ve -.PP -This example produces an RSAPrivateKey structure, this is the -key contained in the file client.pem in all OpenSSL distributions -(note: the field names such as 'coeff' are ignored and are present just -for clarity): -.PP -.Vb 3 -\& asn1=SEQUENCE:private_key -\& [private_key] -\& version=INTEGER:0 -\& -\& n=INTEGER:0xBB6FE79432CC6EA2D8F970675A5A87BFBE1AFF0BE63E879F2AFFB93644\e -\& D4D2C6D000430DEC66ABF47829E74B8C5108623A1C0EE8BE217B3AD8D36D5EB4FCA1D9 -\& -\& e=INTEGER:0x010001 -\& -\& d=INTEGER:0x6F05EAD2F27FFAEC84BEC360C4B928FD5F3A9865D0FCAAD291E2A52F4A\e -\& F810DC6373278C006A0ABBA27DC8C63BF97F7E666E27C5284D7D3B1FFFE16B7A87B51D -\& -\& p=INTEGER:0xF3929B9435608F8A22C208D86795271D54EBDFB09DDEF539AB083DA912\e -\& D4BD57 -\& -\& q=INTEGER:0xC50016F89DFF2561347ED1186A46E150E28BF2D0F539A1594BBD7FE467\e -\& 46EC4F -\& -\& exp1=INTEGER:0x9E7D4326C924AFC1DEA40B45650134966D6F9DFA3A7F9D698CD4ABEA\e -\& 9C0A39B9 -\& -\& exp2=INTEGER:0xBA84003BB95355AFB7C50DF140C60513D0BA51D637272E355E397779\e -\& E7B2458F -\& -\& coeff=INTEGER:0x30B9E4F2AFA5AC679F920FC83F1F2DF1BAF1779CF989447FABC2F5\e -\& 628657053A -.Ve -.PP -This example is the corresponding public key in a SubjectPublicKeyInfo -structure: -.PP -.Vb 2 -\& # Start with a SEQUENCE -\& asn1=SEQUENCE:pubkeyinfo -\& -\& # pubkeyinfo contains an algorithm identifier and the public key wrapped -\& # in a BIT STRING -\& [pubkeyinfo] -\& algorithm=SEQUENCE:rsa_alg -\& pubkey=BITWRAP,SEQUENCE:rsapubkey -\& -\& # algorithm ID for RSA is just an OID and a NULL -\& [rsa_alg] -\& algorithm=OID:rsaEncryption -\& parameter=NULL -\& -\& # Actual public key: modulus and exponent -\& [rsapubkey] -\& n=INTEGER:0xBB6FE79432CC6EA2D8F970675A5A87BFBE1AFF0BE63E879F2AFFB93644\e -\& D4D2C6D000430DEC66ABF47829E74B8C5108623A1C0EE8BE217B3AD8D36D5EB4FCA1D9 -\& -\& e=INTEGER:0x010001 -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_generate_v3.3ossl b/openssl-install/share/man/man3/ASN1_generate_v3.3ossl deleted file mode 120000 index ec28895d..00000000 --- a/openssl-install/share/man/man3/ASN1_generate_v3.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_generate_nconf.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_d2i.3ossl b/openssl-install/share/man/man3/ASN1_item_d2i.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_d2i_bio.3ossl b/openssl-install/share/man/man3/ASN1_item_d2i_bio.3ossl deleted file mode 100644 index 2c93136d..00000000 --- a/openssl-install/share/man/man3/ASN1_item_d2i_bio.3ossl +++ /dev/null @@ -1,247 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_ITEM_D2I_BIO 3ossl" -.TH ASN1_ITEM_D2I_BIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_item_d2i_ex, ASN1_item_d2i, ASN1_item_d2i_bio_ex, ASN1_item_d2i_bio, -ASN1_item_d2i_fp_ex, ASN1_item_d2i_fp, ASN1_item_i2d_mem_bio, -ASN1_item_pack, ASN1_item_unpack_ex, ASN1_item_unpack -\&\- decode and encode DER\-encoded ASN.1 structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_VALUE *ASN1_item_d2i_ex(ASN1_VALUE **pval, const unsigned char **in, -\& long len, const ASN1_ITEM *it, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& ASN1_VALUE *ASN1_item_d2i(ASN1_VALUE **pval, const unsigned char **in, -\& long len, const ASN1_ITEM *it); -\& -\& void *ASN1_item_d2i_bio_ex(const ASN1_ITEM *it, BIO *in, void *x, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& void *ASN1_item_d2i_bio(const ASN1_ITEM *it, BIO *in, void *x); -\& -\& void *ASN1_item_d2i_fp_ex(const ASN1_ITEM *it, FILE *in, void *x, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& void *ASN1_item_d2i_fp(const ASN1_ITEM *it, FILE *in, void *x); -\& -\& BIO *ASN1_item_i2d_mem_bio(const ASN1_ITEM *it, const ASN1_VALUE *val); -\& -\& ASN1_STRING *ASN1_item_pack(void *obj, const ASN1_ITEM *it, ASN1_STRING **oct); -\& -\& void *ASN1_item_unpack(const ASN1_STRING *oct, const ASN1_ITEM *it); -\& -\& void *ASN1_item_unpack_ex(const ASN1_STRING *oct, const ASN1_ITEM *it, -\& OSSL_LIB_CTX *libctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBASN1_item_d2i_ex()\fR decodes the contents of the data stored in \fI*in\fR of length -\&\fIlen\fR which must be a DER-encoded \s-1ASN.1\s0 structure, using the \s-1ASN.1\s0 template -\&\fIit\fR. It places the result in \fI*pval\fR unless \fIpval\fR is \s-1NULL.\s0 If \fI*pval\fR is -non-NULL on entry then the \fB\s-1ASN1_VALUE\s0\fR present there will be reused. Otherwise -a new \fB\s-1ASN1_VALUE\s0\fR will be allocated. If any algorithm fetches are required -during the process then they will use the \fB\s-1OSSL_LIB_CTX\s0\fRprovided in the -\&\fIlibctx\fR parameter and the property query string in \fIpropq\fR. See -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for more information about algorithm fetching. -On exit \fI*in\fR will be updated to point to the next byte in the buffer after the -decoded structure. -.PP -\&\fBASN1_item_d2i()\fR is the same as \fBASN1_item_d2i_ex()\fR except that the default -\&\s-1OSSL_LIB_CTX\s0 is used (i.e. \s-1NULL\s0) and with a \s-1NULL\s0 property query string. -.PP -\&\fBASN1_item_d2i_bio_ex()\fR decodes the contents of its input \s-1BIO\s0 \fIin\fR, -which must be a DER-encoded \s-1ASN.1\s0 structure, using the \s-1ASN.1\s0 template \fIit\fR -and places the result in \fI*pval\fR unless \fIpval\fR is \s-1NULL.\s0 -If \fIin\fR is \s-1NULL\s0 it returns \s-1NULL,\s0 else a pointer to the parsed structure. If any -algorithm fetches are required during the process then they will use the -\&\fB\s-1OSSL_LIB_CTX\s0\fR provided in the \fIlibctx\fR parameter and the property query -string in \fIpropq\fR. See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for more information -about algorithm fetching. -.PP -\&\fBASN1_item_d2i_bio()\fR is the same as \fBASN1_item_d2i_bio_ex()\fR except that the -default \fB\s-1OSSL_LIB_CTX\s0\fR is used (i.e. \s-1NULL\s0) and with a \s-1NULL\s0 property query -string. -.PP -\&\fBASN1_item_d2i_fp_ex()\fR is the same as \fBASN1_item_d2i_bio_ex()\fR except that a \s-1FILE\s0 -pointer is provided instead of a \s-1BIO.\s0 -.PP -\&\fBASN1_item_d2i_fp()\fR is the same as \fBASN1_item_d2i_fp_ex()\fR except that the -default \fB\s-1OSSL_LIB_CTX\s0\fR is used (i.e. \s-1NULL\s0) and with a \s-1NULL\s0 property query -string. -.PP -\&\fBASN1_item_i2d_mem_bio()\fR encodes the given \s-1ASN.1\s0 value \fIval\fR -using the \s-1ASN.1\s0 template \fIit\fR and returns the result in a memory \s-1BIO.\s0 -.PP -\&\fBASN1_item_pack()\fR encodes the given \s-1ASN.1\s0 value in \fIobj\fR using the -\&\s-1ASN.1\s0 template \fIit\fR and returns an \fB\s-1ASN1_STRING\s0\fR object. If the passed in -\&\fI*oct\fR is not \s-1NULL\s0 then this is used to store the returned result, otherwise -a new \fB\s-1ASN1_STRING\s0\fR object is created. If \fIoct\fR is not \s-1NULL\s0 and \fI*oct\fR is \s-1NULL\s0 -then the returned return is also set into \fI*oct\fR. If there is an error the optional -passed in \fB\s-1ASN1_STRING\s0\fR will not be freed, but the previous value may be cleared when -ASN1_STRING_set0(*oct, \s-1NULL, 0\s0) is called internally. -.PP -\&\fBASN1_item_unpack()\fR uses \fBASN1_item_d2i()\fR to decode the DER-encoded \fB\s-1ASN1_STRING\s0\fR -\&\fIoct\fR using the \s-1ASN.1\s0 template \fIit\fR. -.PP -\&\fBASN1_item_unpack_ex()\fR is similar to \fBASN1_item_unpack()\fR, but uses \fBASN1_item_d2i_ex()\fR so -that the \fIlibctx\fR and \fIpropq\fR can be used when doing algorithm fetching. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_item_d2i_bio()\fR, \fBASN1_item_unpack_ex()\fR and \fBASN1_item_unpack()\fR return a pointer to -an \fB\s-1ASN1_VALUE\s0\fR or \s-1NULL\s0 on error. -.PP -\&\fBASN1_item_i2d_mem_bio()\fR returns a pointer to a memory \s-1BIO\s0 or \s-1NULL\s0 on error. -.PP -\&\fBASN1_item_pack()\fR returns a pointer to an \fB\s-1ASN1_STRING\s0\fR or \s-1NULL\s0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBASN1_item_d2i_ex()\fR, \fBASN1_item_d2i_bio_ex()\fR, \fBASN1_item_d2i_fp_ex()\fR -and \fBASN1_item_i2d_mem_bio()\fR were added in OpenSSL 3.0. -.PP -The function \fBASN1_item_unpack_ex()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_item_d2i_bio_ex.3ossl b/openssl-install/share/man/man3/ASN1_item_d2i_bio_ex.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_d2i_bio_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_d2i_ex.3ossl b/openssl-install/share/man/man3/ASN1_item_d2i_ex.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_d2i_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_d2i_fp.3ossl b/openssl-install/share/man/man3/ASN1_item_d2i_fp.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_d2i_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_d2i_fp_ex.3ossl b/openssl-install/share/man/man3/ASN1_item_d2i_fp_ex.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_d2i_fp_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_i2d_mem_bio.3ossl b/openssl-install/share/man/man3/ASN1_item_i2d_mem_bio.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_i2d_mem_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_new.3ossl b/openssl-install/share/man/man3/ASN1_item_new.3ossl deleted file mode 100644 index f0011911..00000000 --- a/openssl-install/share/man/man3/ASN1_item_new.3ossl +++ /dev/null @@ -1,177 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_ITEM_NEW 3ossl" -.TH ASN1_ITEM_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_item_new_ex, ASN1_item_new -\&\- create new ASN.1 values -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_VALUE *ASN1_item_new_ex(const ASN1_ITEM *it, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& ASN1_VALUE *ASN1_item_new(const ASN1_ITEM *it); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBASN1_item_new_ex()\fR creates a new \fB\s-1ASN1_VALUE\s0\fR structure based on the -\&\fB\s-1ASN1_ITEM\s0\fR template given in the \fIit\fR parameter. If any algorithm fetches are -required during the process then they will use the \fB\s-1OSSL_LIB_CTX\s0\fR provided in -the \fIlibctx\fR parameter and the property query string in \fIpropq\fR. See -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for more information about algorithm fetching. -.PP -\&\fBASN1_item_new()\fR is the same as \fBASN1_item_new_ex()\fR except that the default -\&\fB\s-1OSSL_LIB_CTX\s0\fR is used (i.e. \s-1NULL\s0) and with a \s-1NULL\s0 property query string. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASN1_item_new_ex()\fR and \fBASN1_item_new()\fR return a pointer to the newly created -\&\fB\s-1ASN1_VALUE\s0\fR or \s-1NULL\s0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBASN1_item_new_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_item_new_ex.3ossl b/openssl-install/share/man/man3/ASN1_item_new_ex.3ossl deleted file mode 120000 index 449c1f15..00000000 --- a/openssl-install/share/man/man3/ASN1_item_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_pack.3ossl b/openssl-install/share/man/man3/ASN1_item_pack.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_pack.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_sign.3ossl b/openssl-install/share/man/man3/ASN1_item_sign.3ossl deleted file mode 100644 index 19e7d824..00000000 --- a/openssl-install/share/man/man3/ASN1_item_sign.3ossl +++ /dev/null @@ -1,357 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASN1_ITEM_SIGN 3ossl" -.TH ASN1_ITEM_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASN1_item_sign, ASN1_item_sign_ex, ASN1_item_sign_ctx, -ASN1_item_verify, ASN1_item_verify_ex, ASN1_item_verify_ctx \- -ASN1 sign and verify -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ASN1_item_sign_ex(const ASN1_ITEM *it, X509_ALGOR *algor1, -\& X509_ALGOR *algor2, ASN1_BIT_STRING *signature, -\& const void *data, const ASN1_OCTET_STRING *id, -\& EVP_PKEY *pkey, const EVP_MD *md, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& -\& int ASN1_item_sign(const ASN1_ITEM *it, X509_ALGOR *algor1, X509_ALGOR *algor2, -\& ASN1_BIT_STRING *signature, const void *data, -\& EVP_PKEY *pkey, const EVP_MD *md); -\& -\& int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1, -\& X509_ALGOR *algor2, ASN1_BIT_STRING *signature, -\& const void *data, EVP_MD_CTX *ctx); -\& -\& int ASN1_item_verify_ex(const ASN1_ITEM *it, const X509_ALGOR *alg, -\& const ASN1_BIT_STRING *signature, const void *data, -\& const ASN1_OCTET_STRING *id, EVP_PKEY *pkey, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& -\& int ASN1_item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg, -\& const ASN1_BIT_STRING *signature, const void *data, -\& EVP_PKEY *pkey); -\& -\& int ASN1_item_verify_ctx(const ASN1_ITEM *it, const X509_ALGOR *alg, -\& const ASN1_BIT_STRING *signature, const void *data, -\& EVP_MD_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBASN1_item_sign_ex()\fR is used to sign arbitrary \s-1ASN1\s0 data using a data object -\&\fIdata\fR, the \s-1ASN.1\s0 structure \fIit\fR, private key \fIpkey\fR and message digest \fImd\fR. -The data that is signed is formed by taking the data object in \fIdata\fR and -converting it to der format using the \s-1ASN.1\s0 structure \fIit\fR. -The \fIdata\fR that will be signed, and a structure containing the signature may -both have a copy of the \fBX509_ALGOR\fR. The \fBASN1_item_sign_ex()\fR function will -write the correct \fBX509_ALGOR\fR to the structs based on the algorithms and -parameters that have been set up. If one of \fIalgor1\fR or \fIalgor2\fR points to the -\&\fBX509_ALGOR\fR of the \fIdata\fR to be signed, then that \fBX509_ALGOR\fR will first be -written before the signature is generated. -Examples of valid values that can be used by the \s-1ASN.1\s0 structure \fIit\fR are -ASN1_ITEM_rptr(X509_CINF), ASN1_ITEM_rptr(X509_REQ_INFO) and -ASN1_ITEM_rptr(X509_CRL_INFO). -The \fB\s-1OSSL_LIB_CTX\s0\fR specified in \fIlibctx\fR and the property query string -specified in \fIprops\fR are used when searching for algorithms in providers. -The generated signature is set into \fIsignature\fR. -The optional parameter \fIid\fR can be \s-1NULL,\s0 but can be set for special key types. -See \fBEVP_PKEY_CTX_set1_id()\fR for further info. The output parameters and -\&\fIalgor2\fR are ignored if they are \s-1NULL.\s0 -.PP -\&\fBASN1_item_sign()\fR is similar to \fBASN1_item_sign_ex()\fR but uses default values of -\&\s-1NULL\s0 for the \fIid\fR, \fIlibctx\fR and \fIpropq\fR. -.PP -\&\fBASN1_item_sign_ctx()\fR is similar to \fBASN1_item_sign()\fR but uses the parameters -contained in digest context \fIctx\fR. -.PP -\&\fBASN1_item_verify_ex()\fR is used to verify the signature \fIsignature\fR of internal -data \fIdata\fR using the public key \fIpkey\fR and algorithm identifier \fIalg\fR. -The data that is verified is formed by taking the data object in \fIdata\fR and -converting it to der format using the \s-1ASN.1\s0 structure \fIit\fR. -The \fB\s-1OSSL_LIB_CTX\s0\fR specified in \fIlibctx\fR and the property query string -specified in \fIprops\fR are used when searching for algorithms in providers. -The optional parameter \fIid\fR can be \s-1NULL,\s0 but can be set for special key types. -See \fBEVP_PKEY_CTX_set1_id()\fR for further info. -.PP -\&\fBASN1_item_verify()\fR is similar to \fBASN1_item_verify_ex()\fR but uses default values of -\&\s-1NULL\s0 for the \fIid\fR, \fIlibctx\fR and \fIpropq\fR. -.PP -\&\fBASN1_item_verify_ctx()\fR is similar to \fBASN1_item_verify()\fR but uses the parameters -contained in digest context \fIctx\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All sign functions return the size of the signature in bytes for success and -zero for failure. -.PP -All verify functions return 1 if the signature is valid and 0 if the signature -check fails. If the signature could not be checked at all because it was -ill-formed or some other error occurred then \-1 is returned. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -In the following example a 'MyObject' object is signed using the key contained -in an \s-1EVP_MD_CTX.\s0 The signature is written to MyObject.signature. The object is -then output in \s-1DER\s0 format and then loaded back in and verified. -.PP -.Vb 2 -\& #include -\& #include -\& -\& /* An object used to store the ASN1 data fields that will be signed */ -\& typedef struct MySignInfoObject_st -\& { -\& ASN1_INTEGER *version; -\& X509_ALGOR sig_alg; -\& } MySignInfoObject; -\& -\& DECLARE_ASN1_FUNCTIONS(MySignInfoObject) -\& /* -\& * A higher level object containing the ASN1 fields, signature alg and -\& * output signature. -\& */ -\& typedef struct MyObject_st -\& { -\& MySignInfoObject info; -\& X509_ALGOR sig_alg; -\& ASN1_BIT_STRING *signature; -\& } MyObject; -\& -\& DECLARE_ASN1_FUNCTIONS(MyObject) -\& -\& /* The ASN1 definition of MySignInfoObject */ -\& ASN1_SEQUENCE_cb(MySignInfoObject, NULL) = { -\& ASN1_SIMPLE(MySignInfoObject, version, ASN1_INTEGER) -\& ASN1_EMBED(MySignInfoObject, sig_alg, X509_ALGOR), -\& } ASN1_SEQUENCE_END_cb(MySignInfoObject, MySignInfoObject) -\& -\& /* new, free, d2i & i2d functions for MySignInfoObject */ -\& IMPLEMENT_ASN1_FUNCTIONS(MySignInfoObject) -\& -\& /* The ASN1 definition of MyObject */ -\& ASN1_SEQUENCE_cb(MyObject, NULL) = { -\& ASN1_EMBED(MyObject, info, MySignInfoObject), -\& ASN1_EMBED(MyObject, sig_alg, X509_ALGOR), -\& ASN1_SIMPLE(MyObject, signature, ASN1_BIT_STRING) -\& } ASN1_SEQUENCE_END_cb(MyObject, MyObject) -\& -\& /* new, free, d2i & i2d functions for MyObject */ -\& IMPLEMENT_ASN1_FUNCTIONS(MyObject) -\& -\& int test_asn1_item_sign_verify(const char *mdname, EVP_PKEY *pkey, long version) -\& { -\& int ret = 0; -\& unsigned char *obj_der = NULL; -\& const unsigned char *p = NULL; -\& MyObject *obj = NULL, *loaded_obj = NULL; -\& const ASN1_ITEM *it = ASN1_ITEM_rptr(MySignInfoObject); -\& EVP_MD_CTX *sctx = NULL, *vctx = NULL; -\& int len; -\& -\& /* Create MyObject and set its version */ -\& obj = MyObject_new(); -\& if (obj == NULL) -\& goto err; -\& if (!ASN1_INTEGER_set(obj\->info.version, version)) -\& goto err; -\& -\& /* Set the key and digest used for signing */ -\& sctx = EVP_MD_CTX_new(); -\& if (sctx == NULL -\& || !EVP_DigestSignInit_ex(sctx, NULL, mdname, NULL, NULL, pkey)) -\& goto err; -\& -\& /* -\& * it contains the mapping between ASN.1 data and an object MySignInfoObject -\& * obj\->info is the \*(AqMySignInfoObject\*(Aq object that will be -\& * converted into DER data and then signed. -\& * obj\->signature will contain the output signature. -\& * obj\->sig_alg is filled with the private key\*(Aqs signing algorithm id. -\& * obj\->info.sig_alg is another copy of the signing algorithm id that sits -\& * within MyObject. -\& */ -\& len = ASN1_item_sign_ctx(it, &obj\->sig_alg, &obj\->info.sig_alg, -\& obj\->signature, &obj\->info, sctx); -\& if (len <= 0 -\& || X509_ALGOR_cmp(&obj\->sig_alg, &obj\->info.sig_alg) != 0) -\& goto err; -\& -\& /* Output MyObject in der form */ -\& len = i2d_MyObject(obj, &obj_der); -\& if (len <= 0) -\& goto err; -\& -\& /* Set the key and digest used for verifying */ -\& vctx = EVP_MD_CTX_new(); -\& if (vctx == NULL -\& || !EVP_DigestVerifyInit_ex(vctx, NULL, mdname, NULL, NULL, pkey)) -\& goto err; -\& -\& /* Load the der data back into an object */ -\& p = obj_der; -\& loaded_obj = d2i_MyObject(NULL, &p, len); -\& if (loaded_obj == NULL) -\& goto err; -\& /* Verify the loaded object */ -\& ret = ASN1_item_verify_ctx(it, &loaded_obj\->sig_alg, loaded_obj\->signature, -\& &loaded_obj\->info, vctx); -\&err: -\& OPENSSL_free(obj_der); -\& MyObject_free(loaded_obj); -\& MyObject_free(obj); -\& EVP_MD_CTX_free(sctx); -\& EVP_MD_CTX_free(vctx); -\& return ret; -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_sign\fR\|(3), -\&\fBX509_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBASN1_item_sign_ex()\fR and \fBASN1_item_verify_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASN1_item_sign_ctx.3ossl b/openssl-install/share/man/man3/ASN1_item_sign_ctx.3ossl deleted file mode 120000 index b0bea0a3..00000000 --- a/openssl-install/share/man/man3/ASN1_item_sign_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_sign_ex.3ossl b/openssl-install/share/man/man3/ASN1_item_sign_ex.3ossl deleted file mode 120000 index b0bea0a3..00000000 --- a/openssl-install/share/man/man3/ASN1_item_sign_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_unpack.3ossl b/openssl-install/share/man/man3/ASN1_item_unpack.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_unpack.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_unpack_ex.3ossl b/openssl-install/share/man/man3/ASN1_item_unpack_ex.3ossl deleted file mode 120000 index f8402a68..00000000 --- a/openssl-install/share/man/man3/ASN1_item_unpack_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_d2i_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_verify.3ossl b/openssl-install/share/man/man3/ASN1_item_verify.3ossl deleted file mode 120000 index b0bea0a3..00000000 --- a/openssl-install/share/man/man3/ASN1_item_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_verify_ctx.3ossl b/openssl-install/share/man/man3/ASN1_item_verify_ctx.3ossl deleted file mode 120000 index b0bea0a3..00000000 --- a/openssl-install/share/man/man3/ASN1_item_verify_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_item_verify_ex.3ossl b/openssl-install/share/man/man3/ASN1_item_verify_ex.3ossl deleted file mode 120000 index b0bea0a3..00000000 --- a/openssl-install/share/man/man3/ASN1_item_verify_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_item_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASN1_tag2str.3ossl b/openssl-install/share/man/man3/ASN1_tag2str.3ossl deleted file mode 120000 index 13c0091e..00000000 --- a/openssl-install/share/man/man3/ASN1_tag2str.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_STRING_print_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASRange_free.3ossl b/openssl-install/share/man/man3/ASRange_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASRange_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASRange_new.3ossl b/openssl-install/share/man/man3/ASRange_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ASRange_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_STATUS_EAGAIN.3ossl b/openssl-install/share/man/man3/ASYNC_STATUS_EAGAIN.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_STATUS_EAGAIN.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_STATUS_ERR.3ossl b/openssl-install/share/man/man3/ASYNC_STATUS_ERR.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_STATUS_ERR.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_STATUS_OK.3ossl b/openssl-install/share/man/man3/ASYNC_STATUS_OK.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_STATUS_OK.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_STATUS_UNSUPPORTED.3ossl b/openssl-install/share/man/man3/ASYNC_STATUS_UNSUPPORTED.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_STATUS_UNSUPPORTED.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_clear_fd.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_clear_fd.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_clear_fd.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_free.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_free.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_all_fds.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_all_fds.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_all_fds.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_callback.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_callback.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_changed_fds.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_changed_fds.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_changed_fds.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_fd.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_fd.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_fd.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_status.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_status.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_get_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_new.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_new.3ossl deleted file mode 100644 index b5d35398..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_new.3ossl +++ /dev/null @@ -1,349 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASYNC_WAIT_CTX_NEW 3ossl" -.TH ASYNC_WAIT_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASYNC_WAIT_CTX_new, ASYNC_WAIT_CTX_free, ASYNC_WAIT_CTX_set_wait_fd, -ASYNC_WAIT_CTX_get_fd, ASYNC_WAIT_CTX_get_all_fds, -ASYNC_WAIT_CTX_get_changed_fds, ASYNC_WAIT_CTX_clear_fd, -ASYNC_WAIT_CTX_set_callback, ASYNC_WAIT_CTX_get_callback, -ASYNC_WAIT_CTX_set_status, ASYNC_WAIT_CTX_get_status, ASYNC_callback_fn, -ASYNC_STATUS_UNSUPPORTED, ASYNC_STATUS_ERR, ASYNC_STATUS_OK, -ASYNC_STATUS_EAGAIN -\&\- functions to manage waiting for asynchronous jobs to complete -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define ASYNC_STATUS_UNSUPPORTED 0 -\& #define ASYNC_STATUS_ERR 1 -\& #define ASYNC_STATUS_OK 2 -\& #define ASYNC_STATUS_EAGAIN 3 -\& typedef int (*ASYNC_callback_fn)(void *arg); -\& ASYNC_WAIT_CTX *ASYNC_WAIT_CTX_new(void); -\& void ASYNC_WAIT_CTX_free(ASYNC_WAIT_CTX *ctx); -\& int ASYNC_WAIT_CTX_set_wait_fd(ASYNC_WAIT_CTX *ctx, const void *key, -\& OSSL_ASYNC_FD fd, -\& void *custom_data, -\& void (*cleanup)(ASYNC_WAIT_CTX *, const void *, -\& OSSL_ASYNC_FD, void *)); -\& int ASYNC_WAIT_CTX_get_fd(ASYNC_WAIT_CTX *ctx, const void *key, -\& OSSL_ASYNC_FD *fd, void **custom_data); -\& int ASYNC_WAIT_CTX_get_all_fds(ASYNC_WAIT_CTX *ctx, OSSL_ASYNC_FD *fd, -\& size_t *numfds); -\& int ASYNC_WAIT_CTX_get_changed_fds(ASYNC_WAIT_CTX *ctx, OSSL_ASYNC_FD *addfd, -\& size_t *numaddfds, OSSL_ASYNC_FD *delfd, -\& size_t *numdelfds); -\& int ASYNC_WAIT_CTX_clear_fd(ASYNC_WAIT_CTX *ctx, const void *key); -\& int ASYNC_WAIT_CTX_set_callback(ASYNC_WAIT_CTX *ctx, -\& ASYNC_callback_fn callback, -\& void *callback_arg); -\& int ASYNC_WAIT_CTX_get_callback(ASYNC_WAIT_CTX *ctx, -\& ASYNC_callback_fn *callback, -\& void **callback_arg); -\& int ASYNC_WAIT_CTX_set_status(ASYNC_WAIT_CTX *ctx, int status); -\& int ASYNC_WAIT_CTX_get_status(ASYNC_WAIT_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -For an overview of how asynchronous operations are implemented in OpenSSL see -\&\fBASYNC_start_job\fR\|(3). An \fB\s-1ASYNC_WAIT_CTX\s0\fR object represents an asynchronous -\&\*(L"session\*(R", i.e. a related set of crypto operations. For example in \s-1SSL\s0 terms -this would have a one-to-one correspondence with an \s-1SSL\s0 connection. -.PP -Application code must create an \fB\s-1ASYNC_WAIT_CTX\s0\fR using the \fBASYNC_WAIT_CTX_new()\fR -function prior to calling \fBASYNC_start_job()\fR (see \fBASYNC_start_job\fR\|(3)). When -the job is started it is associated with the \fB\s-1ASYNC_WAIT_CTX\s0\fR for the duration -of that job. An \fB\s-1ASYNC_WAIT_CTX\s0\fR should only be used for one \fB\s-1ASYNC_JOB\s0\fR at -any one time, but can be reused after an \fB\s-1ASYNC_JOB\s0\fR has finished for a -subsequent \fB\s-1ASYNC_JOB\s0\fR. When the session is complete (e.g. the \s-1SSL\s0 connection -is closed), application code cleans up with \fBASYNC_WAIT_CTX_free()\fR. -.PP -\&\fB\s-1ASYNC_WAIT_CTX\s0\fRs can have \*(L"wait\*(R" file descriptors associated with them. -Calling \fBASYNC_WAIT_CTX_get_all_fds()\fR and passing in a pointer to an -\&\fB\s-1ASYNC_WAIT_CTX\s0\fR in the \fIctx\fR parameter will return the wait file descriptors -associated with that job in \fI*fd\fR. The number of file descriptors returned will -be stored in \fI*numfds\fR. It is the caller's responsibility to ensure that -sufficient memory has been allocated in \fI*fd\fR to receive all the file -descriptors. Calling \fBASYNC_WAIT_CTX_get_all_fds()\fR with a \s-1NULL\s0 \fIfd\fR value will -return no file descriptors but will still populate \fI*numfds\fR. Therefore, -application code is typically expected to call this function twice: once to get -the number of fds, and then again when sufficient memory has been allocated. If -only one asynchronous engine is being used then normally this call will only -ever return one fd. If multiple asynchronous engines are being used then more -could be returned. -.PP -The function \fBASYNC_WAIT_CTX_get_changed_fds()\fR can be used to detect if any fds -have changed since the last call time \fBASYNC_start_job()\fR returned \fB\s-1ASYNC_PAUSE\s0\fR -(or since the \fB\s-1ASYNC_WAIT_CTX\s0\fR was created if no \fB\s-1ASYNC_PAUSE\s0\fR result has -been received). The \fInumaddfds\fR and \fInumdelfds\fR parameters will be populated -with the number of fds added or deleted respectively. \fI*addfd\fR and \fI*delfd\fR -will be populated with the list of added and deleted fds respectively. Similarly -to \fBASYNC_WAIT_CTX_get_all_fds()\fR either of these can be \s-1NULL,\s0 but if they are not -\&\s-1NULL\s0 then the caller is responsible for ensuring sufficient memory is allocated. -.PP -Implementers of async aware code (e.g. engines) are encouraged to return a -stable fd for the lifetime of the \fB\s-1ASYNC_WAIT_CTX\s0\fR in order to reduce the -\&\*(L"churn\*(R" of regularly changing fds \- although no guarantees of this are provided -to applications. -.PP -Applications can wait for the file descriptor to be ready for \*(L"read\*(R" using a -system function call such as select or poll (being ready for \*(L"read\*(R" indicates -that the job should be resumed). If no file descriptor is made available then an -application will have to periodically \*(L"poll\*(R" the job by attempting to restart it -to see if it is ready to continue. -.PP -Async aware code (e.g. engines) can get the current \fB\s-1ASYNC_WAIT_CTX\s0\fR from the -job via \fBASYNC_get_wait_ctx\fR\|(3) and provide a file descriptor to use for -waiting on by calling \fBASYNC_WAIT_CTX_set_wait_fd()\fR. Typically this would be done -by an engine immediately prior to calling \fBASYNC_pause_job()\fR and not by end user -code. An existing association with a file descriptor can be obtained using -\&\fBASYNC_WAIT_CTX_get_fd()\fR and cleared using \fBASYNC_WAIT_CTX_clear_fd()\fR. Both of -these functions requires a \fIkey\fR value which is unique to the async aware -code. This could be any unique value but a good candidate might be the -\&\fB\s-1ENGINE\s0 *\fR for the engine. The \fIcustom_data\fR parameter can be any value, and -will be returned in a subsequent call to \fBASYNC_WAIT_CTX_get_fd()\fR. The -\&\fBASYNC_WAIT_CTX_set_wait_fd()\fR function also expects a pointer to a \*(L"cleanup\*(R" -routine. This can be \s-1NULL\s0 but if provided will automatically get called when -the \fB\s-1ASYNC_WAIT_CTX\s0\fR is freed, and gives the engine the opportunity to close -the fd or any other resources. Note: The \*(L"cleanup\*(R" routine does not get called -if the fd is cleared directly via a call to \fBASYNC_WAIT_CTX_clear_fd()\fR. -.PP -An example of typical usage might be an async capable engine. User code would -initiate cryptographic operations. The engine would initiate those operations -asynchronously and then call \fBASYNC_WAIT_CTX_set_wait_fd()\fR followed by -\&\fBASYNC_pause_job()\fR to return control to the user code. The user code can then -perform other tasks or wait for the job to be ready by calling \*(L"select\*(R" or other -similar function on the wait file descriptor. The engine can signal to the user -code that the job should be resumed by making the wait file descriptor -\&\*(L"readable\*(R". Once resumed the engine should clear the wake signal on the wait -file descriptor. -.PP -As well as a file descriptor, user code may also be notified via a callback. The -callback and data pointers are stored within the \fB\s-1ASYNC_WAIT_CTX\s0\fR along with an -additional status field that can be used for the notification of retries from an -engine. This additional method can be used when the user thinks that a file -descriptor is too costly in terms of \s-1CPU\s0 cycles or in some context where a file -descriptor is not appropriate. -.PP -\&\fBASYNC_WAIT_CTX_set_callback()\fR sets the callback and the callback argument. The -callback will be called to notify user code when an engine completes a -cryptography operation. It is a requirement that the callback function is small -and nonblocking as it will be run in the context of a polling mechanism or an -interrupt. -.PP -\&\fBASYNC_WAIT_CTX_get_callback()\fR returns the callback set in the \fB\s-1ASYNC_WAIT_CTX\s0\fR -structure. -.PP -\&\fBASYNC_WAIT_CTX_set_status()\fR allows an engine to set the current engine status. -The possible status values are the following: -.IP "\fB\s-1ASYNC_STATUS_UNSUPPORTED\s0\fR" 4 -.IX Item "ASYNC_STATUS_UNSUPPORTED" -The engine does not support the callback mechanism. This is the default value. -The engine must call \fBASYNC_WAIT_CTX_set_status()\fR to set the status to some value -other than \fB\s-1ASYNC_STATUS_UNSUPPORTED\s0\fR if it intends to enable the callback -mechanism. -.IP "\fB\s-1ASYNC_STATUS_ERR\s0\fR" 4 -.IX Item "ASYNC_STATUS_ERR" -The engine has a fatal problem with this request. The user code should clean up -this session. -.IP "\fB\s-1ASYNC_STATUS_OK\s0\fR" 4 -.IX Item "ASYNC_STATUS_OK" -The request has been successfully submitted. -.IP "\fB\s-1ASYNC_STATUS_EAGAIN\s0\fR" 4 -.IX Item "ASYNC_STATUS_EAGAIN" -The engine has some problem which will be recovered soon, such as a buffer is -full, so user code should resume the job. -.PP -\&\fBASYNC_WAIT_CTX_get_status()\fR allows user code to obtain the current status value. -If the status is any value other than \fB\s-1ASYNC_STATUS_OK\s0\fR then the user code -should not expect to receive a callback from the engine even if one has been -set. -.PP -An example of the usage of the callback method might be the following. User -code would initiate cryptographic operations, and the engine code would dispatch -this operation to hardware, and if the dispatch is successful, then the engine -code would call \fBASYNC_pause_job()\fR to return control to the user code. After -that, user code can perform other tasks. When the hardware completes the -operation, normally it is detected by a polling function or an interrupt, as the -user code set a callback by calling \fBASYNC_WAIT_CTX_set_callback()\fR previously, -then the registered callback will be called. -.PP -\&\fBASYNC_WAIT_CTX_free()\fR frees up a single \fB\s-1ASYNC_WAIT_CTX\s0\fR object. -If the argument is \s-1NULL,\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBASYNC_WAIT_CTX_new()\fR returns a pointer to the newly allocated \fB\s-1ASYNC_WAIT_CTX\s0\fR -or \s-1NULL\s0 on error. -.PP -ASYNC_WAIT_CTX_set_wait_fd, ASYNC_WAIT_CTX_get_fd, ASYNC_WAIT_CTX_get_all_fds, -ASYNC_WAIT_CTX_get_changed_fds, ASYNC_WAIT_CTX_clear_fd, -ASYNC_WAIT_CTX_set_callback, ASYNC_WAIT_CTX_get_callback and -ASYNC_WAIT_CTX_set_status all return 1 on success or 0 on error. -\&\fBASYNC_WAIT_CTX_get_status()\fR returns the engine status. -.SH "NOTES" -.IX Header "NOTES" -On Windows platforms the \fI\fR header is dependent on some -of the types customarily made available by including \fI\fR. The -application developer is likely to require control over when the latter -is included, commonly as one of the first included headers. Therefore, -it is defined as an application developer's responsibility to include -\&\fI\fR prior to \fI\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBASYNC_start_job\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBASYNC_WAIT_CTX_new()\fR, \fBASYNC_WAIT_CTX_free()\fR, \fBASYNC_WAIT_CTX_set_wait_fd()\fR, -\&\fBASYNC_WAIT_CTX_get_fd()\fR, \fBASYNC_WAIT_CTX_get_all_fds()\fR, -\&\fBASYNC_WAIT_CTX_get_changed_fds()\fR and \fBASYNC_WAIT_CTX_clear_fd()\fR -were added in OpenSSL 1.1.0. -.PP -\&\fBASYNC_WAIT_CTX_set_callback()\fR, \fBASYNC_WAIT_CTX_get_callback()\fR, -\&\fBASYNC_WAIT_CTX_set_status()\fR, and \fBASYNC_WAIT_CTX_get_status()\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_callback.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_callback.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_status.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_status.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_wait_fd.3ossl b/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_wait_fd.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_WAIT_CTX_set_wait_fd.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_block_pause.3ossl b/openssl-install/share/man/man3/ASYNC_block_pause.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_block_pause.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_callback_fn.3ossl b/openssl-install/share/man/man3/ASYNC_callback_fn.3ossl deleted file mode 120000 index fcfae748..00000000 --- a/openssl-install/share/man/man3/ASYNC_callback_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_WAIT_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_cleanup_thread.3ossl b/openssl-install/share/man/man3/ASYNC_cleanup_thread.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_cleanup_thread.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_get_current_job.3ossl b/openssl-install/share/man/man3/ASYNC_get_current_job.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_get_current_job.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_get_mem_functions.3ossl b/openssl-install/share/man/man3/ASYNC_get_mem_functions.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_get_mem_functions.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_get_wait_ctx.3ossl b/openssl-install/share/man/man3/ASYNC_get_wait_ctx.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_get_wait_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_init_thread.3ossl b/openssl-install/share/man/man3/ASYNC_init_thread.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_init_thread.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_is_capable.3ossl b/openssl-install/share/man/man3/ASYNC_is_capable.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_is_capable.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_pause_job.3ossl b/openssl-install/share/man/man3/ASYNC_pause_job.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_pause_job.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_set_mem_functions.3ossl b/openssl-install/share/man/man3/ASYNC_set_mem_functions.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_set_mem_functions.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_stack_alloc_fn.3ossl b/openssl-install/share/man/man3/ASYNC_stack_alloc_fn.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_stack_alloc_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_stack_free_fn.3ossl b/openssl-install/share/man/man3/ASYNC_stack_free_fn.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_stack_free_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ASYNC_start_job.3ossl b/openssl-install/share/man/man3/ASYNC_start_job.3ossl deleted file mode 100644 index 5d087600..00000000 --- a/openssl-install/share/man/man3/ASYNC_start_job.3ossl +++ /dev/null @@ -1,501 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ASYNC_START_JOB 3ossl" -.TH ASYNC_START_JOB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ASYNC_get_wait_ctx, -ASYNC_init_thread, ASYNC_cleanup_thread, ASYNC_start_job, ASYNC_pause_job, -ASYNC_get_current_job, ASYNC_block_pause, ASYNC_unblock_pause, ASYNC_is_capable, -ASYNC_stack_alloc_fn, ASYNC_stack_free_fn, ASYNC_set_mem_functions, ASYNC_get_mem_functions -\&\- asynchronous job management functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ASYNC_init_thread(size_t max_size, size_t init_size); -\& void ASYNC_cleanup_thread(void); -\& -\& int ASYNC_start_job(ASYNC_JOB **job, ASYNC_WAIT_CTX *ctx, int *ret, -\& int (*func)(void *), void *args, size_t size); -\& int ASYNC_pause_job(void); -\& -\& ASYNC_JOB *ASYNC_get_current_job(void); -\& ASYNC_WAIT_CTX *ASYNC_get_wait_ctx(ASYNC_JOB *job); -\& void ASYNC_block_pause(void); -\& void ASYNC_unblock_pause(void); -\& -\& int ASYNC_is_capable(void); -\& -\& typedef void *(*ASYNC_stack_alloc_fn)(size_t *num); -\& typedef void (*ASYNC_stack_free_fn)(void *addr); -\& int ASYNC_set_mem_functions(ASYNC_stack_alloc_fn alloc_fn, -\& ASYNC_stack_free_fn free_fn); -\& void ASYNC_get_mem_functions(ASYNC_stack_alloc_fn *alloc_fn, -\& ASYNC_stack_free_fn *free_fn); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL implements asynchronous capabilities through an \fB\s-1ASYNC_JOB\s0\fR. This -represents code that can be started and executes until some event occurs. At -that point the code can be paused and control returns to user code until some -subsequent event indicates that the job can be resumed. It's OpenSSL -specific implementation of cooperative multitasking. -.PP -The creation of an \fB\s-1ASYNC_JOB\s0\fR is a relatively expensive operation. Therefore, -for efficiency reasons, jobs can be created up front and reused many times. They -are held in a pool until they are needed, at which point they are removed from -the pool, used, and then returned to the pool when the job completes. If the -user application is multi-threaded, then \fBASYNC_init_thread()\fR may be called for -each thread that will initiate asynchronous jobs. Before -user code exits per-thread resources need to be cleaned up. This will normally -occur automatically (see \fBOPENSSL_init_crypto\fR\|(3)) but may be explicitly -initiated by using \fBASYNC_cleanup_thread()\fR. No asynchronous jobs must be -outstanding for the thread when \fBASYNC_cleanup_thread()\fR is called. Failing to -ensure this will result in memory leaks. -.PP -The \fImax_size\fR argument limits the number of \fB\s-1ASYNC_JOB\s0\fRs that will be held in -the pool. If \fImax_size\fR is set to 0 then no upper limit is set. When an -\&\fB\s-1ASYNC_JOB\s0\fR is needed but there are none available in the pool already then one -will be automatically created, as long as the total of \fB\s-1ASYNC_JOB\s0\fRs managed by -the pool does not exceed \fImax_size\fR. When the pool is first initialised -\&\fIinit_size\fR \fB\s-1ASYNC_JOB\s0\fRs will be created immediately. If \fBASYNC_init_thread()\fR -is not called before the pool is first used then it will be called automatically -with a \fImax_size\fR of 0 (no upper limit) and an \fIinit_size\fR of 0 (no -\&\fB\s-1ASYNC_JOB\s0\fRs created up front). -.PP -An asynchronous job is started by calling the \fBASYNC_start_job()\fR function. -Initially \fI*job\fR should be \s-1NULL.\s0 \fIctx\fR should point to an \fB\s-1ASYNC_WAIT_CTX\s0\fR -object created through the \fBASYNC_WAIT_CTX_new\fR\|(3) function. \fIret\fR should -point to a location where the return value of the asynchronous function should -be stored on completion of the job. \fIfunc\fR represents the function that should -be started asynchronously. The data pointed to by \fIargs\fR and of size \fIsize\fR -will be copied and then passed as an argument to \fIfunc\fR when the job starts. -ASYNC_start_job will return one of the following values: -.IP "\fB\s-1ASYNC_ERR\s0\fR" 4 -.IX Item "ASYNC_ERR" -An error occurred trying to start the job. Check the OpenSSL error queue (e.g. -see \fBERR_print_errors\fR\|(3)) for more details. -.IP "\fB\s-1ASYNC_NO_JOBS\s0\fR" 4 -.IX Item "ASYNC_NO_JOBS" -There are no jobs currently available in the pool. This call can be retried -again at a later time. -.IP "\fB\s-1ASYNC_PAUSE\s0\fR" 4 -.IX Item "ASYNC_PAUSE" -The job was successfully started but was \*(L"paused\*(R" before it completed (see -\&\fBASYNC_pause_job()\fR below). A handle to the job is placed in \fI*job\fR. Other work -can be performed (if desired) and the job restarted at a later time. To restart -a job call \fBASYNC_start_job()\fR again passing the job handle in \fI*job\fR. The -\&\fIfunc\fR, \fIargs\fR and \fIsize\fR parameters will be ignored when restarting a job. -When restarting a job \fBASYNC_start_job()\fR \fBmust\fR be called from the same thread -that the job was originally started from. \fB\s-1ASYNC_WAIT_CTX\s0\fR is used to -know when a job is ready to be restarted. -.IP "\fB\s-1ASYNC_FINISH\s0\fR" 4 -.IX Item "ASYNC_FINISH" -The job completed. \fI*job\fR will be \s-1NULL\s0 and the return value from \fIfunc\fR will -be placed in \fI*ret\fR. -.PP -At any one time there can be a maximum of one job actively running per thread -(you can have many that are paused). \fBASYNC_get_current_job()\fR can be used to get -a pointer to the currently executing \fB\s-1ASYNC_JOB\s0\fR. If no job is currently -executing then this will return \s-1NULL.\s0 -.PP -If executing within the context of a job (i.e. having been called directly or -indirectly by the function \*(L"func\*(R" passed as an argument to \fBASYNC_start_job()\fR) -then \fBASYNC_pause_job()\fR will immediately return control to the calling -application with \fB\s-1ASYNC_PAUSE\s0\fR returned from the \fBASYNC_start_job()\fR call. A -subsequent call to ASYNC_start_job passing in the relevant \fB\s-1ASYNC_JOB\s0\fR in the -\&\fI*job\fR parameter will resume execution from the \fBASYNC_pause_job()\fR call. If -\&\fBASYNC_pause_job()\fR is called whilst not within the context of a job then no -action is taken and \fBASYNC_pause_job()\fR returns immediately. -.PP -\&\fBASYNC_get_wait_ctx()\fR can be used to get a pointer to the \fB\s-1ASYNC_WAIT_CTX\s0\fR -for the \fIjob\fR (see \fBASYNC_WAIT_CTX_new\fR\|(3)). -\&\fB\s-1ASYNC_WAIT_CTX\s0\fRs contain two different ways to notify -applications that a job is ready to be resumed. One is a \*(L"wait\*(R" file -descriptor, and the other is a \*(L"callback\*(R" mechanism. -.PP -The \*(L"wait\*(R" file descriptor associated with \fB\s-1ASYNC_WAIT_CTX\s0\fR is used for -applications to wait for the file descriptor to be ready for \*(L"read\*(R" using a -system function call such as \fBselect\fR\|(2) or \fBpoll\fR\|(2) (being ready for \*(L"read\*(R" -indicates -that the job should be resumed). If no file descriptor is made available then -an application will have to periodically \*(L"poll\*(R" the job by attempting to restart -it to see if it is ready to continue. -.PP -\&\fB\s-1ASYNC_WAIT_CTX\s0\fRs also have a \*(L"callback\*(R" mechanism to notify applications. The -callback is set by an application, and it will be automatically called when an -engine completes a cryptography operation, so that the application can resume -the paused work flow without polling. An engine could be written to look whether -the callback has been set. If it has then it would use the callback mechanism -in preference to the file descriptor notifications. If a callback is not set -then the engine may use file descriptor based notifications. Please note that -not all engines may support the callback mechanism, so the callback may not be -used even if it has been set. See \fBASYNC_WAIT_CTX_new()\fR for more details. -.PP -The \fBASYNC_block_pause()\fR function will prevent the currently active job from -pausing. The block will remain in place until a subsequent call to -\&\fBASYNC_unblock_pause()\fR. These functions can be nested, e.g. if you call -\&\fBASYNC_block_pause()\fR twice then you must call \fBASYNC_unblock_pause()\fR twice in -order to re-enable pausing. If these functions are called while there is no -currently active job then they have no effect. This functionality can be useful -to avoid deadlock scenarios. For example during the execution of an \fB\s-1ASYNC_JOB\s0\fR -an application acquires a lock. It then calls some cryptographic function which -invokes \fBASYNC_pause_job()\fR. This returns control back to the code that created -the \fB\s-1ASYNC_JOB\s0\fR. If that code then attempts to acquire the same lock before -resuming the original job then a deadlock can occur. By calling -\&\fBASYNC_block_pause()\fR immediately after acquiring the lock and -\&\fBASYNC_unblock_pause()\fR immediately before releasing it then this situation cannot -occur. -.PP -Some platforms cannot support async operations. The \fBASYNC_is_capable()\fR function -can be used to detect whether the current platform is async capable or not. -.PP -Custom memory allocation functions are supported for the \s-1POSIX\s0 platform. -Custom memory allocation functions allow alternative methods of allocating -stack memory such as mmap, or using stack memory from the current thread. -Using an ASYNC_stack_alloc_fn callback also allows manipulation of the stack -size, which defaults to 32k. -The stack size can be altered by allocating a stack of a size different to -the requested size, and passing back the new stack size in the callback's \fI*num\fR -parameter. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -ASYNC_init_thread returns 1 on success or 0 otherwise. -.PP -ASYNC_start_job returns one of \fB\s-1ASYNC_ERR\s0\fR, \fB\s-1ASYNC_NO_JOBS\s0\fR, \fB\s-1ASYNC_PAUSE\s0\fR or -\&\fB\s-1ASYNC_FINISH\s0\fR as described above. -.PP -ASYNC_pause_job returns 0 if an error occurred or 1 on success. If called when -not within the context of an \fB\s-1ASYNC_JOB\s0\fR then this is counted as success so 1 -is returned. -.PP -ASYNC_get_current_job returns a pointer to the currently executing \fB\s-1ASYNC_JOB\s0\fR -or \s-1NULL\s0 if not within the context of a job. -.PP -\&\fBASYNC_get_wait_ctx()\fR returns a pointer to the \fB\s-1ASYNC_WAIT_CTX\s0\fR for the job. -.PP -\&\fBASYNC_is_capable()\fR returns 1 if the current platform is async capable or 0 -otherwise. -.PP -ASYNC_set_mem_functions returns 1 if custom stack allocators are supported by -the current platform and no allocations have already occurred or 0 otherwise. -.SH "NOTES" -.IX Header "NOTES" -On Windows platforms the \fI\fR header is dependent on some -of the types customarily made available by including \fI\fR. The -application developer is likely to require control over when the latter -is included, commonly as one of the first included headers. Therefore, -it is defined as an application developer's responsibility to include -\&\fI\fR prior to \fI\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following example demonstrates how to use most of the core async APIs: -.PP -.Vb 7 -\& #ifdef _WIN32 -\& # include -\& #endif -\& #include -\& #include -\& #include -\& #include -\& -\& int unique = 0; -\& -\& void cleanup(ASYNC_WAIT_CTX *ctx, const void *key, OSSL_ASYNC_FD r, void *vw) -\& { -\& OSSL_ASYNC_FD *w = (OSSL_ASYNC_FD *)vw; -\& -\& close(r); -\& close(*w); -\& OPENSSL_free(w); -\& } -\& -\& int jobfunc(void *arg) -\& { -\& ASYNC_JOB *currjob; -\& unsigned char *msg; -\& int pipefds[2] = {0, 0}; -\& OSSL_ASYNC_FD *wptr; -\& char buf = \*(AqX\*(Aq; -\& -\& currjob = ASYNC_get_current_job(); -\& if (currjob != NULL) { -\& printf("Executing within a job\en"); -\& } else { -\& printf("Not executing within a job \- should not happen\en"); -\& return 0; -\& } -\& -\& msg = (unsigned char *)arg; -\& printf("Passed in message is: %s\en", msg); -\& -\& /* -\& * Create a way to inform the calling thread when this job is ready -\& * to resume, in this example we\*(Aqre using file descriptors. -\& * For offloading the task to an asynchronous ENGINE it\*(Aqs not necessary, -\& * the ENGINE should handle that internally. -\& */ -\& -\& if (pipe(pipefds) != 0) { -\& printf("Failed to create pipe\en"); -\& return 0; -\& } -\& wptr = OPENSSL_malloc(sizeof(OSSL_ASYNC_FD)); -\& if (wptr == NULL) { -\& printf("Failed to malloc\en"); -\& return 0; -\& } -\& *wptr = pipefds[1]; -\& ASYNC_WAIT_CTX_set_wait_fd(ASYNC_get_wait_ctx(currjob), &unique, -\& pipefds[0], wptr, cleanup); -\& -\& /* -\& * Normally some external event (like a network read being ready, -\& * disk access being finished, or some hardware offload operation -\& * completing) would cause this to happen at some -\& * later point \- but we do it here for demo purposes, i.e. -\& * immediately signalling that the job is ready to be woken up after -\& * we return to main via ASYNC_pause_job(). -\& */ -\& write(pipefds[1], &buf, 1); -\& -\& /* -\& * Return control back to main just before calling a blocking -\& * method. The main thread will wait until pipefds[0] is ready -\& * for reading before returning control to this thread. -\& */ -\& ASYNC_pause_job(); -\& -\& /* Perform the blocking call (it won\*(Aqt block with this example code) */ -\& read(pipefds[0], &buf, 1); -\& -\& printf ("Resumed the job after a pause\en"); -\& -\& return 1; -\& } -\& -\& int main(void) -\& { -\& ASYNC_JOB *job = NULL; -\& ASYNC_WAIT_CTX *ctx = NULL; -\& int ret; -\& OSSL_ASYNC_FD waitfd; -\& fd_set waitfdset; -\& size_t numfds; -\& unsigned char msg[13] = "Hello world!"; -\& -\& printf("Starting...\en"); -\& -\& ctx = ASYNC_WAIT_CTX_new(); -\& if (ctx == NULL) { -\& printf("Failed to create ASYNC_WAIT_CTX\en"); -\& abort(); -\& } -\& -\& for (;;) { -\& switch (ASYNC_start_job(&job, ctx, &ret, jobfunc, msg, sizeof(msg))) { -\& case ASYNC_ERR: -\& case ASYNC_NO_JOBS: -\& printf("An error occurred\en"); -\& goto end; -\& case ASYNC_PAUSE: -\& printf("Job was paused\en"); -\& break; -\& case ASYNC_FINISH: -\& printf("Job finished with return value %d\en", ret); -\& goto end; -\& } -\& -\& /* Get the file descriptor we can use to wait for the job -\& * to be ready to be woken up -\& */ -\& printf("Waiting for the job to be woken up\en"); -\& -\& if (!ASYNC_WAIT_CTX_get_all_fds(ctx, NULL, &numfds) -\& || numfds > 1) { -\& printf("Unexpected number of fds\en"); -\& abort(); -\& } -\& ASYNC_WAIT_CTX_get_all_fds(ctx, &waitfd, &numfds); -\& FD_ZERO(&waitfdset); -\& FD_SET(waitfd, &waitfdset); -\& -\& /* Wait for the job to be ready for wakeup */ -\& select(waitfd + 1, &waitfdset, NULL, NULL, NULL); -\& } -\& -\& end: -\& ASYNC_WAIT_CTX_free(ctx); -\& printf("Finishing\en"); -\& -\& return 0; -\& } -.Ve -.PP -The expected output from executing the above example program is: -.PP -.Vb 8 -\& Starting... -\& Executing within a job -\& Passed in message is: Hello world! -\& Job was paused -\& Waiting for the job to be woken up -\& Resumed the job after a pause -\& Job finished with return value 1 -\& Finishing -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBERR_print_errors\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -ASYNC_init_thread, ASYNC_cleanup_thread, -ASYNC_start_job, ASYNC_pause_job, ASYNC_get_current_job, \fBASYNC_get_wait_ctx()\fR, -\&\fBASYNC_block_pause()\fR, \fBASYNC_unblock_pause()\fR and \fBASYNC_is_capable()\fR were first -added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ASYNC_unblock_pause.3ossl b/openssl-install/share/man/man3/ASYNC_unblock_pause.3ossl deleted file mode 120000 index 0ecffbee..00000000 --- a/openssl-install/share/man/man3/ASYNC_unblock_pause.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASYNC_start_job.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_free.3ossl b/openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_new.3ossl b/openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/AUTHORITY_INFO_ACCESS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/AUTHORITY_KEYID_free.3ossl b/openssl-install/share/man/man3/AUTHORITY_KEYID_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/AUTHORITY_KEYID_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/AUTHORITY_KEYID_new.3ossl b/openssl-install/share/man/man3/AUTHORITY_KEYID_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/AUTHORITY_KEYID_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BASIC_CONSTRAINTS_free.3ossl b/openssl-install/share/man/man3/BASIC_CONSTRAINTS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/BASIC_CONSTRAINTS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BASIC_CONSTRAINTS_new.3ossl b/openssl-install/share/man/man3/BASIC_CONSTRAINTS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/BASIC_CONSTRAINTS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BF_cbc_encrypt.3ossl b/openssl-install/share/man/man3/BF_cbc_encrypt.3ossl deleted file mode 120000 index 74111896..00000000 --- a/openssl-install/share/man/man3/BF_cbc_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -BF_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BF_cfb64_encrypt.3ossl b/openssl-install/share/man/man3/BF_cfb64_encrypt.3ossl deleted file mode 120000 index 74111896..00000000 --- a/openssl-install/share/man/man3/BF_cfb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -BF_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BF_decrypt.3ossl b/openssl-install/share/man/man3/BF_decrypt.3ossl deleted file mode 120000 index 74111896..00000000 --- a/openssl-install/share/man/man3/BF_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -BF_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BF_ecb_encrypt.3ossl b/openssl-install/share/man/man3/BF_ecb_encrypt.3ossl deleted file mode 120000 index 74111896..00000000 --- a/openssl-install/share/man/man3/BF_ecb_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -BF_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BF_encrypt.3ossl b/openssl-install/share/man/man3/BF_encrypt.3ossl deleted file mode 100644 index c8503df3..00000000 --- a/openssl-install/share/man/man3/BF_encrypt.3ossl +++ /dev/null @@ -1,263 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BF_ENCRYPT 3ossl" -.TH BF_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BF_set_key, BF_encrypt, BF_decrypt, BF_ecb_encrypt, BF_cbc_encrypt, -BF_cfb64_encrypt, BF_ofb64_encrypt, BF_options \- Blowfish encryption -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void BF_set_key(BF_KEY *key, int len, const unsigned char *data); -\& -\& void BF_ecb_encrypt(const unsigned char *in, unsigned char *out, -\& BF_KEY *key, int enc); -\& void BF_cbc_encrypt(const unsigned char *in, unsigned char *out, -\& long length, BF_KEY *schedule, -\& unsigned char *ivec, int enc); -\& void BF_cfb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, BF_KEY *schedule, -\& unsigned char *ivec, int *num, int enc); -\& void BF_ofb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, BF_KEY *schedule, -\& unsigned char *ivec, int *num); -\& const char *BF_options(void); -\& -\& void BF_encrypt(BF_LONG *data, const BF_KEY *key); -\& void BF_decrypt(BF_LONG *data, const BF_KEY *key); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. Applications should -instead use \fBEVP_EncryptInit_ex\fR\|(3), \fBEVP_EncryptUpdate\fR\|(3) and -\&\fBEVP_EncryptFinal_ex\fR\|(3) or the equivalently named decrypt functions. -.PP -This library implements the Blowfish cipher, which was invented and described -by Counterpane (see http://www.counterpane.com/blowfish.html ). -.PP -Blowfish is a block cipher that operates on 64 bit (8 byte) blocks of data. -It uses a variable size key, but typically, 128 bit (16 byte) keys are -considered good for strong encryption. Blowfish can be used in the same -modes as \s-1DES\s0 (see \fBdes_modes\fR\|(7)). Blowfish is currently one -of the faster block ciphers. It is quite a bit faster than \s-1DES,\s0 and much -faster than \s-1IDEA\s0 or \s-1RC2.\s0 -.PP -Blowfish consists of a key setup phase and the actual encryption or decryption -phase. -.PP -\&\fBBF_set_key()\fR sets up the \fB\s-1BF_KEY\s0\fR \fBkey\fR using the \fBlen\fR bytes long key -at \fBdata\fR. -.PP -\&\fBBF_ecb_encrypt()\fR is the basic Blowfish encryption and decryption function. -It encrypts or decrypts the first 64 bits of \fBin\fR using the key \fBkey\fR, -putting the result in \fBout\fR. \fBenc\fR decides if encryption (\fB\s-1BF_ENCRYPT\s0\fR) -or decryption (\fB\s-1BF_DECRYPT\s0\fR) shall be performed. The vector pointed at by -\&\fBin\fR and \fBout\fR must be 64 bits in length, no less. If they are larger, -everything after the first 64 bits is ignored. -.PP -The mode functions \fBBF_cbc_encrypt()\fR, \fBBF_cfb64_encrypt()\fR and \fBBF_ofb64_encrypt()\fR -all operate on variable length data. They all take an initialization vector -\&\fBivec\fR which needs to be passed along into the next call of the same function -for the same message. \fBivec\fR may be initialized with anything, but the -recipient needs to know what it was initialized with, or it won't be able -to decrypt. Some programs and protocols simplify this, like \s-1SSH,\s0 where -\&\fBivec\fR is simply initialized to zero. -\&\fBBF_cbc_encrypt()\fR operates on data that is a multiple of 8 bytes long, while -\&\fBBF_cfb64_encrypt()\fR and \fBBF_ofb64_encrypt()\fR are used to encrypt a variable -number of bytes (the amount does not have to be an exact multiple of 8). The -purpose of the latter two is to simulate stream ciphers, and therefore, they -need the parameter \fBnum\fR, which is a pointer to an integer where the current -offset in \fBivec\fR is stored between calls. This integer must be initialized -to zero when \fBivec\fR is initialized. -.PP -\&\fBBF_cbc_encrypt()\fR is the Cipher Block Chaining function for Blowfish. It -encrypts or decrypts the 64 bits chunks of \fBin\fR using the key \fBschedule\fR, -putting the result in \fBout\fR. \fBenc\fR decides if encryption (\s-1BF_ENCRYPT\s0) or -decryption (\s-1BF_DECRYPT\s0) shall be performed. \fBivec\fR must point at an 8 byte -long initialization vector. -.PP -\&\fBBF_cfb64_encrypt()\fR is the \s-1CFB\s0 mode for Blowfish with 64 bit feedback. -It encrypts or decrypts the bytes in \fBin\fR using the key \fBschedule\fR, -putting the result in \fBout\fR. \fBenc\fR decides if encryption (\fB\s-1BF_ENCRYPT\s0\fR) -or decryption (\fB\s-1BF_DECRYPT\s0\fR) shall be performed. \fBivec\fR must point at an -8 byte long initialization vector. \fBnum\fR must point at an integer which must -be initially zero. -.PP -\&\fBBF_ofb64_encrypt()\fR is the \s-1OFB\s0 mode for Blowfish with 64 bit feedback. -It uses the same parameters as \fBBF_cfb64_encrypt()\fR, which must be initialized -the same way. -.PP -\&\fBBF_encrypt()\fR and \fBBF_decrypt()\fR are the lowest level functions for Blowfish -encryption. They encrypt/decrypt the first 64 bits of the vector pointed by -\&\fBdata\fR, using the key \fBkey\fR. These functions should not be used unless you -implement 'modes' of Blowfish. The alternative is to use \fBBF_ecb_encrypt()\fR. -If you still want to use these functions, you should be aware that they take -each 32\-bit chunk in host-byte order, which is little-endian on little-endian -platforms and big-endian on big-endian ones. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -None of the functions presented here return any value. -.SH "NOTE" -.IX Header "NOTE" -Applications should use the higher level functions -\&\fBEVP_EncryptInit\fR\|(3) etc. instead of calling these -functions directly. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBdes_modes\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BF_ofb64_encrypt.3ossl b/openssl-install/share/man/man3/BF_ofb64_encrypt.3ossl deleted file mode 120000 index 74111896..00000000 --- a/openssl-install/share/man/man3/BF_ofb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -BF_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BF_options.3ossl b/openssl-install/share/man/man3/BF_options.3ossl deleted file mode 120000 index 74111896..00000000 --- a/openssl-install/share/man/man3/BF_options.3ossl +++ /dev/null @@ -1 +0,0 @@ -BF_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BF_set_key.3ossl b/openssl-install/share/man/man3/BF_set_key.3ossl deleted file mode 120000 index 74111896..00000000 --- a/openssl-install/share/man/man3/BF_set_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -BF_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR.3ossl b/openssl-install/share/man/man3/BIO_ADDR.3ossl deleted file mode 100644 index 3e175bf9..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR.3ossl +++ /dev/null @@ -1,271 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_ADDR 3ossl" -.TH BIO_ADDR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_ADDR, BIO_ADDR_new, BIO_ADDR_copy, BIO_ADDR_dup, BIO_ADDR_clear, -BIO_ADDR_free, BIO_ADDR_rawmake, -BIO_ADDR_family, BIO_ADDR_rawaddress, BIO_ADDR_rawport, -BIO_ADDR_hostname_string, BIO_ADDR_service_string, -BIO_ADDR_path_string \- BIO_ADDR routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& typedef union bio_addr_st BIO_ADDR; -\& -\& BIO_ADDR *BIO_ADDR_new(void); -\& int BIO_ADDR_copy(BIO_ADDR *dst, const BIO_ADDR *src); -\& BIO_ADDR *BIO_ADDR_dup(const BIO_ADDR *ap); -\& void BIO_ADDR_free(BIO_ADDR *ap); -\& void BIO_ADDR_clear(BIO_ADDR *ap); -\& int BIO_ADDR_rawmake(BIO_ADDR *ap, int family, -\& const void *where, size_t wherelen, unsigned short port); -\& int BIO_ADDR_family(const BIO_ADDR *ap); -\& int BIO_ADDR_rawaddress(const BIO_ADDR *ap, void *p, size_t *l); -\& unsigned short BIO_ADDR_rawport(const BIO_ADDR *ap); -\& char *BIO_ADDR_hostname_string(const BIO_ADDR *ap, int numeric); -\& char *BIO_ADDR_service_string(const BIO_ADDR *ap, int numeric); -\& char *BIO_ADDR_path_string(const BIO_ADDR *ap); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1BIO_ADDR\s0\fR type is a wrapper around all types of socket -addresses that OpenSSL deals with, currently transparently -supporting \s-1AF_INET, AF_INET6\s0 and \s-1AF_UNIX\s0 according to what's -available on the platform at hand. -.PP -\&\fBBIO_ADDR_new()\fR creates a new unfilled \fB\s-1BIO_ADDR\s0\fR, to be used -with routines that will fill it with information, such as -\&\fBBIO_accept_ex()\fR. -.PP -\&\fBBIO_ADDR_copy()\fR copies the contents of \fBsrc\fR into \fBdst\fR. Neither \fBsrc\fR or -\&\fBdst\fR can be \s-1NULL.\s0 -.PP -\&\fBBIO_ADDR_dup()\fR creates a new \fB\s-1BIO_ADDR\s0\fR, with a copy of the -address data in \fBap\fR. -.PP -\&\fBBIO_ADDR_free()\fR frees a \fB\s-1BIO_ADDR\s0\fR created with \fBBIO_ADDR_new()\fR -or \fBBIO_ADDR_dup()\fR. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBBIO_ADDR_clear()\fR clears any data held within the provided \fB\s-1BIO_ADDR\s0\fR and sets -it back to an uninitialised state. -.PP -\&\fBBIO_ADDR_rawmake()\fR takes a protocol \fBfamily\fR, a byte array of -size \fBwherelen\fR with an address in network byte order pointed at -by \fBwhere\fR and a port number in network byte order in \fBport\fR (except -for the \fB\s-1AF_UNIX\s0\fR protocol family, where \fBport\fR is meaningless and -therefore ignored) and populates the given \fB\s-1BIO_ADDR\s0\fR with them. -In case this creates a \fB\s-1AF_UNIX\s0\fR \fB\s-1BIO_ADDR\s0\fR, \fBwherelen\fR is expected -to be the length of the path string (not including the terminating -\&\s-1NUL,\s0 such as the result of a call to \fBstrlen()\fR). -Read on about the addresses in \*(L"\s-1RAW ADDRESSES\*(R"\s0 below. -.PP -\&\fBBIO_ADDR_family()\fR returns the protocol family of the given -\&\fB\s-1BIO_ADDR\s0\fR. The possible non-error results are one of the -constants \s-1AF_INET, AF_INET6\s0 and \s-1AF_UNIX.\s0 It will also return \s-1AF_UNSPEC\s0 if the -\&\s-1BIO_ADDR\s0 has not been initialised. -.PP -\&\fBBIO_ADDR_rawaddress()\fR will write the raw address of the given -\&\fB\s-1BIO_ADDR\s0\fR in the area pointed at by \fBp\fR if \fBp\fR is non-NULL, -and will set \fB*l\fR to be the amount of bytes the raw address -takes up if \fBl\fR is non-NULL. -A technique to only find out the size of the address is a call -with \fBp\fR set to \fB\s-1NULL\s0\fR. The raw address will be in network byte -order, most significant byte first. -In case this is a \fB\s-1AF_UNIX\s0\fR \fB\s-1BIO_ADDR\s0\fR, \fBl\fR gets the length of the -path string (not including the terminating \s-1NUL,\s0 such as the result of -a call to \fBstrlen()\fR). -Read on about the addresses in \*(L"\s-1RAW ADDRESSES\*(R"\s0 below. -.PP -\&\fBBIO_ADDR_rawport()\fR returns the raw port of the given \fB\s-1BIO_ADDR\s0\fR. -The raw port will be in network byte order. -.PP -\&\fBBIO_ADDR_hostname_string()\fR returns a character string with the -hostname of the given \fB\s-1BIO_ADDR\s0\fR. If \fBnumeric\fR is 1, the string -will contain the numerical form of the address. This only works for -\&\fB\s-1BIO_ADDR\s0\fR of the protocol families \s-1AF_INET\s0 and \s-1AF_INET6.\s0 The -returned string has been allocated on the heap and must be freed -with \fBOPENSSL_free()\fR. -.PP -\&\fBBIO_ADDR_service_string()\fR returns a character string with the -service name of the port of the given \fB\s-1BIO_ADDR\s0\fR. If \fBnumeric\fR -is 1, the string will contain the port number. This only works -for \fB\s-1BIO_ADDR\s0\fR of the protocol families \s-1AF_INET\s0 and \s-1AF_INET6.\s0 The -returned string has been allocated on the heap and must be freed -with \fBOPENSSL_free()\fR. -.PP -\&\fBBIO_ADDR_path_string()\fR returns a character string with the path -of the given \fB\s-1BIO_ADDR\s0\fR. This only works for \fB\s-1BIO_ADDR\s0\fR of the -protocol family \s-1AF_UNIX.\s0 The returned string has been allocated -on the heap and must be freed with \fBOPENSSL_free()\fR. -.SH "RAW ADDRESSES" -.IX Header "RAW ADDRESSES" -Both \fBBIO_ADDR_rawmake()\fR and \fBBIO_ADDR_rawaddress()\fR take a pointer to a -network byte order address of a specific site. Internally, those are -treated as a pointer to \fBstruct in_addr\fR (for \fB\s-1AF_INET\s0\fR), \fBstruct -in6_addr\fR (for \fB\s-1AF_INET6\s0\fR) or \fBchar *\fR (for \fB\s-1AF_UNIX\s0\fR), all -depending on the protocol family the address is for. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The string producing functions \fBBIO_ADDR_hostname_string()\fR, -\&\fBBIO_ADDR_service_string()\fR and \fBBIO_ADDR_path_string()\fR will -return \fB\s-1NULL\s0\fR on error and leave an error indication on the -OpenSSL error stack. -.PP -\&\fBBIO_ADDR_copy()\fR returns 1 on success or 0 on error. -.PP -All other functions described here return 0 or \fB\s-1NULL\s0\fR when the -information they should return isn't available. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_connect\fR\|(3), \fBBIO_s_connect\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_ADDR_copy()\fR and \fBBIO_ADDR_dup()\fR were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_ADDRINFO.3ossl b/openssl-install/share/man/man3/BIO_ADDRINFO.3ossl deleted file mode 100644 index 7a495fab..00000000 --- a/openssl-install/share/man/man3/BIO_ADDRINFO.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_ADDRINFO 3ossl" -.TH BIO_ADDRINFO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_lookup_type, -BIO_ADDRINFO, BIO_ADDRINFO_next, BIO_ADDRINFO_free, -BIO_ADDRINFO_family, BIO_ADDRINFO_socktype, BIO_ADDRINFO_protocol, -BIO_ADDRINFO_address, -BIO_lookup_ex, -BIO_lookup -\&\- BIO_ADDRINFO type and routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& typedef union bio_addrinfo_st BIO_ADDRINFO; -\& -\& enum BIO_lookup_type { -\& BIO_LOOKUP_CLIENT, BIO_LOOKUP_SERVER -\& }; -\& -\& int BIO_lookup_ex(const char *host, const char *service, int lookup_type, -\& int family, int socktype, int protocol, BIO_ADDRINFO **res); -\& int BIO_lookup(const char *host, const char *service, -\& enum BIO_lookup_type lookup_type, -\& int family, int socktype, BIO_ADDRINFO **res); -\& -\& const BIO_ADDRINFO *BIO_ADDRINFO_next(const BIO_ADDRINFO *bai); -\& int BIO_ADDRINFO_family(const BIO_ADDRINFO *bai); -\& int BIO_ADDRINFO_socktype(const BIO_ADDRINFO *bai); -\& int BIO_ADDRINFO_protocol(const BIO_ADDRINFO *bai); -\& const BIO_ADDR *BIO_ADDRINFO_address(const BIO_ADDRINFO *bai); -\& void BIO_ADDRINFO_free(BIO_ADDRINFO *bai); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1BIO_ADDRINFO\s0\fR type is a wrapper for address information -types provided on your platform. -.PP -\&\fB\s-1BIO_ADDRINFO\s0\fR normally forms a chain of several that can be -picked at one by one. -.PP -\&\fBBIO_lookup_ex()\fR looks up a specified \fBhost\fR and \fBservice\fR, and -uses \fBlookup_type\fR to determine what the default address should -be if \fBhost\fR is \fB\s-1NULL\s0\fR. \fBfamily\fR, \fBsocktype\fR and \fBprotocol\fR are used to -determine what protocol family, socket type and protocol should be used for -the lookup. \fBfamily\fR can be any of \s-1AF_INET, AF_INET6, AF_UNIX\s0 and -\&\s-1AF_UNSPEC.\s0 \fBsocktype\fR can be \s-1SOCK_STREAM, SOCK_DGRAM\s0 or 0. Specifying 0 -indicates that any type can be used. \fBprotocol\fR specifies a protocol such as -\&\s-1IPPROTO_TCP, IPPROTO_UDP\s0 or \s-1IPPORTO_SCTP.\s0 If set to 0 than any protocol can be -used. \fBres\fR points at a pointer to hold the start of a \fB\s-1BIO_ADDRINFO\s0\fR -chain. -.PP -For the family \fB\s-1AF_UNIX\s0\fR, \fBBIO_lookup_ex()\fR will ignore the \fBservice\fR -parameter and expects the \fBhost\fR parameter to hold the path to the socket file. -.PP -\&\fBBIO_lookup()\fR does the same as \fBBIO_lookup_ex()\fR but does not provide the ability -to select based on the protocol (any protocol may be returned). -.PP -\&\fBBIO_ADDRINFO_family()\fR returns the family of the given -\&\fB\s-1BIO_ADDRINFO\s0\fR. The result will be one of the constants -\&\s-1AF_INET, AF_INET6\s0 and \s-1AF_UNIX.\s0 -.PP -\&\fBBIO_ADDRINFO_socktype()\fR returns the socket type of the given -\&\fB\s-1BIO_ADDRINFO\s0\fR. The result will be one of the constants -\&\s-1SOCK_STREAM\s0 and \s-1SOCK_DGRAM.\s0 -.PP -\&\fBBIO_ADDRINFO_protocol()\fR returns the protocol id of the given -\&\fB\s-1BIO_ADDRINFO\s0\fR. The result will be one of the constants -\&\s-1IPPROTO_TCP\s0 and \s-1IPPROTO_UDP.\s0 -.PP -\&\fBBIO_ADDRINFO_address()\fR returns the underlying \fB\s-1BIO_ADDR\s0\fR -of the given \fB\s-1BIO_ADDRINFO\s0\fR. -.PP -\&\fBBIO_ADDRINFO_next()\fR returns the next \fB\s-1BIO_ADDRINFO\s0\fR in the chain -from the given one. -.PP -\&\fBBIO_ADDRINFO_free()\fR frees the chain of \fB\s-1BIO_ADDRINFO\s0\fR starting -with the given one. If the argument is \s-1NULL,\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_lookup_ex()\fR and \fBBIO_lookup()\fR return 1 on success and 0 when an error -occurred, and will leave an error indication on the OpenSSL error stack in that -case. -.PP -All other functions described here return 0 or \fB\s-1NULL\s0\fR when the -information they should return isn't available. -.SH "NOTES" -.IX Header "NOTES" -The \fBBIO_lookup_ex()\fR implementation uses the platform provided \fBgetaddrinfo()\fR -function. On Linux it is known that specifying 0 for the protocol will not -return any \s-1SCTP\s0 based addresses when calling \fBgetaddrinfo()\fR. Therefore, if an \s-1SCTP\s0 -address is required then the \fBprotocol\fR parameter to \fBBIO_lookup_ex()\fR should be -explicitly set to \s-1IPPROTO_SCTP.\s0 The same may be true on other platforms. -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBIO_lookup_ex()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_ADDRINFO_address.3ossl b/openssl-install/share/man/man3/BIO_ADDRINFO_address.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_ADDRINFO_address.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDRINFO_family.3ossl b/openssl-install/share/man/man3/BIO_ADDRINFO_family.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_ADDRINFO_family.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDRINFO_free.3ossl b/openssl-install/share/man/man3/BIO_ADDRINFO_free.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_ADDRINFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDRINFO_next.3ossl b/openssl-install/share/man/man3/BIO_ADDRINFO_next.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_ADDRINFO_next.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDRINFO_protocol.3ossl b/openssl-install/share/man/man3/BIO_ADDRINFO_protocol.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_ADDRINFO_protocol.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDRINFO_socktype.3ossl b/openssl-install/share/man/man3/BIO_ADDRINFO_socktype.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_ADDRINFO_socktype.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_clear.3ossl b/openssl-install/share/man/man3/BIO_ADDR_clear.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_clear.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_copy.3ossl b/openssl-install/share/man/man3/BIO_ADDR_copy.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_dup.3ossl b/openssl-install/share/man/man3/BIO_ADDR_dup.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_family.3ossl b/openssl-install/share/man/man3/BIO_ADDR_family.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_family.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_free.3ossl b/openssl-install/share/man/man3/BIO_ADDR_free.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_hostname_string.3ossl b/openssl-install/share/man/man3/BIO_ADDR_hostname_string.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_hostname_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_new.3ossl b/openssl-install/share/man/man3/BIO_ADDR_new.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_path_string.3ossl b/openssl-install/share/man/man3/BIO_ADDR_path_string.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_path_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_rawaddress.3ossl b/openssl-install/share/man/man3/BIO_ADDR_rawaddress.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_rawaddress.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_rawmake.3ossl b/openssl-install/share/man/man3/BIO_ADDR_rawmake.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_rawmake.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_rawport.3ossl b/openssl-install/share/man/man3/BIO_ADDR_rawport.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_rawport.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ADDR_service_string.3ossl b/openssl-install/share/man/man3/BIO_ADDR_service_string.3ossl deleted file mode 120000 index cf4df41b..00000000 --- a/openssl-install/share/man/man3/BIO_ADDR_service_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDR.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_accept_ex.3ossl b/openssl-install/share/man/man3/BIO_accept_ex.3ossl deleted file mode 120000 index 10175c59..00000000 --- a/openssl-install/share/man/man3/BIO_accept_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_append_filename.3ossl b/openssl-install/share/man/man3/BIO_append_filename.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_append_filename.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_bind.3ossl b/openssl-install/share/man/man3/BIO_bind.3ossl deleted file mode 120000 index 10175c59..00000000 --- a/openssl-install/share/man/man3/BIO_bind.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_callback_ctrl.3ossl b/openssl-install/share/man/man3/BIO_callback_ctrl.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_callback_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_callback_fn.3ossl b/openssl-install/share/man/man3/BIO_callback_fn.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_callback_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_callback_fn_ex.3ossl b/openssl-install/share/man/man3/BIO_callback_fn_ex.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_callback_fn_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_closesocket.3ossl b/openssl-install/share/man/man3/BIO_closesocket.3ossl deleted file mode 120000 index 10175c59..00000000 --- a/openssl-install/share/man/man3/BIO_closesocket.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_connect.3ossl b/openssl-install/share/man/man3/BIO_connect.3ossl deleted file mode 100644 index 72ec1c5c..00000000 --- a/openssl-install/share/man/man3/BIO_connect.3ossl +++ /dev/null @@ -1,249 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_CONNECT 3ossl" -.TH BIO_CONNECT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_socket, BIO_bind, BIO_connect, BIO_listen, BIO_accept_ex, BIO_closesocket \- BIO -socket communication setup routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BIO_socket(int domain, int socktype, int protocol, int options); -\& int BIO_bind(int sock, const BIO_ADDR *addr, int options); -\& int BIO_connect(int sock, const BIO_ADDR *addr, int options); -\& int BIO_listen(int sock, const BIO_ADDR *addr, int options); -\& int BIO_accept_ex(int accept_sock, BIO_ADDR *peer, int options); -\& int BIO_closesocket(int sock); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_socket()\fR creates a socket in the domain \fBdomain\fR, of type -\&\fBsocktype\fR and \fBprotocol\fR. Socket \fBoptions\fR are currently unused, -but is present for future use. -.PP -\&\fBBIO_bind()\fR binds the source address and service to a socket and -may be useful before calling \fBBIO_connect()\fR. The options may include -\&\fB\s-1BIO_SOCK_REUSEADDR\s0\fR, which is described in \*(L"\s-1FLAGS\*(R"\s0 below. -.PP -\&\fBBIO_connect()\fR connects \fBsock\fR to the address and service given by -\&\fBaddr\fR. Connection \fBoptions\fR may be zero or any combination of -\&\fB\s-1BIO_SOCK_KEEPALIVE\s0\fR, \fB\s-1BIO_SOCK_NONBLOCK\s0\fR and \fB\s-1BIO_SOCK_NODELAY\s0\fR. -The flags are described in \*(L"\s-1FLAGS\*(R"\s0 below. -.PP -\&\fBBIO_listen()\fR has \fBsock\fR start listening on the address and service -given by \fBaddr\fR. Connection \fBoptions\fR may be zero or any -combination of \fB\s-1BIO_SOCK_KEEPALIVE\s0\fR, \fB\s-1BIO_SOCK_NONBLOCK\s0\fR, -\&\fB\s-1BIO_SOCK_NODELAY\s0\fR, \fB\s-1BIO_SOCK_REUSEADDR\s0\fR and \fB\s-1BIO_SOCK_V6_ONLY\s0\fR. -The flags are described in \*(L"\s-1FLAGS\*(R"\s0 below. -.PP -\&\fBBIO_accept_ex()\fR waits for an incoming connections on the given -socket \fBaccept_sock\fR. When it gets a connection, the address and -port of the peer gets stored in \fBpeer\fR if that one is non-NULL. -Accept \fBoptions\fR may be zero or \fB\s-1BIO_SOCK_NONBLOCK\s0\fR, and is applied -on the accepted socket. The flags are described in \*(L"\s-1FLAGS\*(R"\s0 below. -.PP -\&\fBBIO_closesocket()\fR closes \fBsock\fR. -.SH "FLAGS" -.IX Header "FLAGS" -.IP "\s-1BIO_SOCK_KEEPALIVE\s0" 4 -.IX Item "BIO_SOCK_KEEPALIVE" -Enables regular sending of keep-alive messages. -.IP "\s-1BIO_SOCK_NONBLOCK\s0" 4 -.IX Item "BIO_SOCK_NONBLOCK" -Sets the socket to nonblocking mode. -.IP "\s-1BIO_SOCK_NODELAY\s0" 4 -.IX Item "BIO_SOCK_NODELAY" -Corresponds to \fB\s-1TCP_NODELAY\s0\fR, and disables the Nagle algorithm. With -this set, any data will be sent as soon as possible instead of being -buffered until there's enough for the socket to send out in one go. -.IP "\s-1BIO_SOCK_REUSEADDR\s0" 4 -.IX Item "BIO_SOCK_REUSEADDR" -Try to reuse the address and port combination for a recently closed -port. -.IP "\s-1BIO_SOCK_V6_ONLY\s0" 4 -.IX Item "BIO_SOCK_V6_ONLY" -When creating an IPv6 socket, make it only listen for IPv6 addresses -and not IPv4 addresses mapped to IPv6. -.IP "\s-1BIO_SOCK_TFO\s0" 4 -.IX Item "BIO_SOCK_TFO" -Enables \s-1TCP\s0 Fast Open on the socket. Uses appropriate APIs on -supported operating systems, including Linux, macOS and FreeBSD. Can -be used with \fBBIO_connect()\fR, \fBBIO_set_conn_mode()\fR, \fBBIO_set_bind_mode()\fR, -and \fBBIO_listen()\fR. -On Linux kernels before 4.14, use \fBBIO_set_conn_address()\fR to specify -the peer address before starting the \s-1TLS\s0 handshake. -.PP -These flags are bit flags, so they are to be combined with the -\&\f(CW\*(C`|\*(C'\fR operator, for example: -.PP -.Vb 1 -\& BIO_connect(sock, addr, BIO_SOCK_KEEPALIVE | BIO_SOCK_NONBLOCK); -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_socket()\fR returns the socket number on success or \fB\s-1INVALID_SOCKET\s0\fR -(\-1) on error. When an error has occurred, the OpenSSL error stack -will hold the error data and errno has the system error. -.PP -\&\fBBIO_bind()\fR, \fBBIO_connect()\fR and \fBBIO_listen()\fR return 1 on success or 0 on error. -When an error has occurred, the OpenSSL error stack will hold the error -data and errno has the system error. -.PP -\&\fBBIO_accept_ex()\fR returns the accepted socket on success or -\&\fB\s-1INVALID_SOCKET\s0\fR (\-1) on error. When an error has occurred, the -OpenSSL error stack will hold the error data and errno has the system -error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBBIO_ADDR\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_gethostname()\fR, \fBBIO_get_port()\fR, \fBBIO_get_host_ip()\fR, -\&\fBBIO_get_accept_socket()\fR and \fBBIO_accept()\fR were deprecated in OpenSSL 1.1.0. -Use the functions described above instead. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_ctrl.3ossl b/openssl-install/share/man/man3/BIO_ctrl.3ossl deleted file mode 100644 index cb3dec72..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl.3ossl +++ /dev/null @@ -1,321 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_CTRL 3ossl" -.TH BIO_CTRL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_ctrl, BIO_callback_ctrl, BIO_ptr_ctrl, BIO_int_ctrl, BIO_reset, -BIO_seek, BIO_tell, BIO_flush, BIO_eof, BIO_set_close, BIO_get_close, -BIO_pending, BIO_wpending, BIO_ctrl_pending, BIO_ctrl_wpending, -BIO_get_info_callback, BIO_set_info_callback, BIO_info_cb, BIO_get_ktls_send, -BIO_get_ktls_recv, BIO_set_conn_mode, BIO_get_conn_mode, BIO_set_tfo -\&\- BIO control operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int BIO_info_cb(BIO *b, int state, int res); -\& -\& long BIO_ctrl(BIO *bp, int cmd, long larg, void *parg); -\& long BIO_callback_ctrl(BIO *b, int cmd, BIO_info_cb *cb); -\& void *BIO_ptr_ctrl(BIO *bp, int cmd, long larg); -\& long BIO_int_ctrl(BIO *bp, int cmd, long larg, int iarg); -\& -\& int BIO_reset(BIO *b); -\& int BIO_seek(BIO *b, int ofs); -\& int BIO_tell(BIO *b); -\& int BIO_flush(BIO *b); -\& int BIO_eof(BIO *b); -\& int BIO_set_close(BIO *b, long flag); -\& int BIO_get_close(BIO *b); -\& int BIO_pending(BIO *b); -\& int BIO_wpending(BIO *b); -\& size_t BIO_ctrl_pending(BIO *b); -\& size_t BIO_ctrl_wpending(BIO *b); -\& -\& int BIO_get_info_callback(BIO *b, BIO_info_cb **cbp); -\& int BIO_set_info_callback(BIO *b, BIO_info_cb *cb); -\& -\& int BIO_get_ktls_send(BIO *b); -\& int BIO_get_ktls_recv(BIO *b); -\& -\& int BIO_set_conn_mode(BIO *b, int mode); -\& int BIO_get_conn_mode(BIO *b); -\& -\& int BIO_set_tfo(BIO *b, int onoff); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_ctrl()\fR, \fBBIO_callback_ctrl()\fR, \fBBIO_ptr_ctrl()\fR and \fBBIO_int_ctrl()\fR -are \s-1BIO\s0 \*(L"control\*(R" operations taking arguments of various types. -These functions are not normally called directly, various macros -are used instead. The standard macros are described below, macros -specific to a particular type of \s-1BIO\s0 are described in the specific -BIOs manual page as well as any special features of the standard -calls. -.PP -\&\fBBIO_reset()\fR typically resets a \s-1BIO\s0 to some initial state, in the case -of file related BIOs for example it rewinds the file pointer to the -start of the file. -.PP -\&\fBBIO_seek()\fR resets a file related \s-1BIO\s0's (that is file descriptor and -\&\s-1FILE\s0 BIOs) file position pointer to \fBofs\fR bytes from start of file. -.PP -\&\fBBIO_tell()\fR returns the current file position of a file related \s-1BIO.\s0 -.PP -\&\fBBIO_flush()\fR normally writes out any internally buffered data, in some -cases it is used to signal \s-1EOF\s0 and that no more data will be written. -.PP -\&\fBBIO_eof()\fR returns 1 if the \s-1BIO\s0 has read \s-1EOF,\s0 the precise meaning of -\&\*(L"\s-1EOF\*(R"\s0 varies according to the \s-1BIO\s0 type. -.PP -\&\fBBIO_set_close()\fR sets the \s-1BIO\s0 \fBb\fR close flag to \fBflag\fR. \fBflag\fR can -take the value \s-1BIO_CLOSE\s0 or \s-1BIO_NOCLOSE.\s0 Typically \s-1BIO_CLOSE\s0 is used -in a source/sink \s-1BIO\s0 to indicate that the underlying I/O stream should -be closed when the \s-1BIO\s0 is freed. -.PP -\&\fBBIO_get_close()\fR returns the BIOs close flag. -.PP -\&\fBBIO_pending()\fR, \fBBIO_ctrl_pending()\fR, \fBBIO_wpending()\fR and \fBBIO_ctrl_wpending()\fR -return the number of pending characters in the BIOs read and write buffers. -Not all BIOs support these calls. \fBBIO_ctrl_pending()\fR and \fBBIO_ctrl_wpending()\fR -return a size_t type and are functions, \fBBIO_pending()\fR and \fBBIO_wpending()\fR are -macros which call \fBBIO_ctrl()\fR. -.PP -\&\fBBIO_get_ktls_send()\fR returns 1 if the \s-1BIO\s0 is using the Kernel \s-1TLS\s0 data-path for -sending. Otherwise, it returns zero. -\&\fBBIO_get_ktls_recv()\fR returns 1 if the \s-1BIO\s0 is using the Kernel \s-1TLS\s0 data-path for -receiving. Otherwise, it returns zero. -.PP -\&\fBBIO_get_conn_mode()\fR returns the \s-1BIO\s0 connection mode. \fBBIO_set_conn_mode()\fR sets -the \s-1BIO\s0 connection mode. -.PP -\&\fBBIO_set_tfo()\fR disables \s-1TCP\s0 Fast Open when \fBonoff\fR is 0, and enables \s-1TCP\s0 Fast -Open when \fBonoff\fR is nonzero. Setting the value to 1 is equivalent to setting -\&\fB\s-1BIO_SOCK_TFO\s0\fR in \fBBIO_set_conn_mode()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_reset()\fR normally returns 1 for success and <=0 for failure. File -BIOs are an exception, they return 0 for success and \-1 for failure. -.PP -\&\fBBIO_seek()\fR and \fBBIO_tell()\fR both return the current file position on success -and \-1 for failure, except file BIOs which for \fBBIO_seek()\fR always return 0 -for success and \-1 for failure. -.PP -\&\fBBIO_flush()\fR returns 1 for success and <=0 for failure. -.PP -\&\fBBIO_eof()\fR returns 1 if \s-1EOF\s0 has been reached, 0 if not, or negative values for failure. -.PP -\&\fBBIO_set_close()\fR returns 1 on success or <=0 for failure. -.PP -\&\fBBIO_get_close()\fR returns the close flag value: \s-1BIO_CLOSE\s0 or \s-1BIO_NOCLOSE.\s0 It also -returns other negative values if an error occurs. -.PP -\&\fBBIO_pending()\fR, \fBBIO_ctrl_pending()\fR, \fBBIO_wpending()\fR and \fBBIO_ctrl_wpending()\fR -return the amount of pending data. \fBBIO_pending()\fR and \fBBIO_wpending()\fR return -negative value or 0 on error. \fBBIO_ctrl_pending()\fR and \fBBIO_ctrl_wpending()\fR return -0 on error. -.PP -\&\fBBIO_get_ktls_send()\fR returns 1 if the \s-1BIO\s0 is using the Kernel \s-1TLS\s0 data-path for -sending. Otherwise, it returns zero. -\&\fBBIO_get_ktls_recv()\fR returns 1 if the \s-1BIO\s0 is using the Kernel \s-1TLS\s0 data-path for -receiving. Otherwise, it returns zero. -.PP -\&\fBBIO_set_conn_mode()\fR returns 1 for success and 0 for failure. \fBBIO_get_conn_mode()\fR -returns the current connection mode. Which may contain the bitwise-or of the -following flags: -.PP -.Vb 6 -\& BIO_SOCK_REUSEADDR -\& BIO_SOCK_V6_ONLY -\& BIO_SOCK_KEEPALIVE -\& BIO_SOCK_NONBLOCK -\& BIO_SOCK_NODELAY -\& BIO_SOCK_TFO -.Ve -.PP -\&\fBBIO_set_tfo()\fR returns 1 for success, and 0 for failure. -.SH "NOTES" -.IX Header "NOTES" -\&\fBBIO_flush()\fR, because it can write data may return 0 or \-1 indicating -that the call should be retried later in a similar manner to \fBBIO_write_ex()\fR. -The \fBBIO_should_retry()\fR call should be used and appropriate action taken -is the call fails. -.PP -The return values of \fBBIO_pending()\fR and \fBBIO_wpending()\fR may not reliably -determine the amount of pending data in all cases. For example in the -case of a file \s-1BIO\s0 some data may be available in the \s-1FILE\s0 structures -internal buffers but it is not possible to determine this in a -portably way. For other types of \s-1BIO\s0 they may not be supported. -.PP -Filter BIOs if they do not internally handle a particular \fBBIO_ctrl()\fR -operation usually pass the operation to the next \s-1BIO\s0 in the chain. -This often means there is no need to locate the required \s-1BIO\s0 for -a particular operation, it can be called on a chain and it will -be automatically passed to the relevant \s-1BIO.\s0 However, this can cause -unexpected results: for example no current filter BIOs implement -\&\fBBIO_seek()\fR, but this may still succeed if the chain ends in a \s-1FILE\s0 -or file descriptor \s-1BIO.\s0 -.PP -Source/sink BIOs return an 0 if they do not recognize the \fBBIO_ctrl()\fR -operation. -.SH "BUGS" -.IX Header "BUGS" -Some of the return values are ambiguous and care should be taken. In -particular a return value of 0 can be returned if an operation is not -supported, if an error occurred, if \s-1EOF\s0 has not been reached and in -the case of \fBBIO_seek()\fR on a file \s-1BIO\s0 for a successful operation. -.PP -In older versions of OpenSSL the \fBBIO_ctrl_pending()\fR and -\&\fBBIO_ctrl_wpending()\fR could return values greater than \s-1INT_MAX\s0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBIO_get_ktls_send()\fR and \fBBIO_get_ktls_recv()\fR macros were added in -OpenSSL 3.0. They were modified to never return \-1 in OpenSSL 3.0.4. -.PP -The \fBBIO_get_conn_mode()\fR, \fBBIO_set_conn_mode()\fR and \fBBIO_set_tfo()\fR functions -were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_ctrl_dgram_connect.3ossl b/openssl-install/share/man/man3/BIO_ctrl_dgram_connect.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl_dgram_connect.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ctrl_get_read_request.3ossl b/openssl-install/share/man/man3/BIO_ctrl_get_read_request.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl_get_read_request.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ctrl_get_write_guarantee.3ossl b/openssl-install/share/man/man3/BIO_ctrl_get_write_guarantee.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl_get_write_guarantee.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ctrl_pending.3ossl b/openssl-install/share/man/man3/BIO_ctrl_pending.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl_pending.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ctrl_reset_read_request.3ossl b/openssl-install/share/man/man3/BIO_ctrl_reset_read_request.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl_reset_read_request.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ctrl_set_connected.3ossl b/openssl-install/share/man/man3/BIO_ctrl_set_connected.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl_set_connected.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ctrl_wpending.3ossl b/openssl-install/share/man/man3/BIO_ctrl_wpending.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_ctrl_wpending.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_debug_callback.3ossl b/openssl-install/share/man/man3/BIO_debug_callback.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_debug_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_debug_callback_ex.3ossl b/openssl-install/share/man/man3/BIO_debug_callback_ex.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_debug_callback_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_destroy_bio_pair.3ossl b/openssl-install/share/man/man3/BIO_destroy_bio_pair.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_destroy_bio_pair.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_detect_peer_addr.3ossl b/openssl-install/share/man/man3/BIO_dgram_detect_peer_addr.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_detect_peer_addr.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_caps.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_caps.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_caps.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_effective_caps.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_effective_caps.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_effective_caps.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_local_addr_cap.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_local_addr_cap.3ossl deleted file mode 120000 index 28a49405..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_local_addr_cap.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_sendmmsg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_local_addr_enable.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_local_addr_enable.3ossl deleted file mode 120000 index 28a49405..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_local_addr_enable.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_sendmmsg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_mtu.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_mtu.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_mtu.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_mtu_overhead.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_mtu_overhead.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_mtu_overhead.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_no_trunc.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_no_trunc.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_no_trunc.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_get_peer.3ossl b/openssl-install/share/man/man3/BIO_dgram_get_peer.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_get_peer.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_recv_timedout.3ossl b/openssl-install/share/man/man3/BIO_dgram_recv_timedout.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_recv_timedout.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_send_timedout.3ossl b/openssl-install/share/man/man3/BIO_dgram_send_timedout.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_send_timedout.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_set_caps.3ossl b/openssl-install/share/man/man3/BIO_dgram_set_caps.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_set_caps.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_set_local_addr_enable.3ossl b/openssl-install/share/man/man3/BIO_dgram_set_local_addr_enable.3ossl deleted file mode 120000 index 28a49405..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_set_local_addr_enable.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_sendmmsg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_set_mtu.3ossl b/openssl-install/share/man/man3/BIO_dgram_set_mtu.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_set_mtu.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_set_no_trunc.3ossl b/openssl-install/share/man/man3/BIO_dgram_set_no_trunc.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_set_no_trunc.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_dgram_set_peer.3ossl b/openssl-install/share/man/man3/BIO_dgram_set_peer.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_dgram_set_peer.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_do_accept.3ossl b/openssl-install/share/man/man3/BIO_do_accept.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_do_accept.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_do_connect.3ossl b/openssl-install/share/man/man3/BIO_do_connect.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_do_connect.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_do_connect_retry.3ossl b/openssl-install/share/man/man3/BIO_do_connect_retry.3ossl deleted file mode 120000 index 32dfdab8..00000000 --- a/openssl-install/share/man/man3/BIO_do_connect_retry.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_socket_wait.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_do_handshake.3ossl b/openssl-install/share/man/man3/BIO_do_handshake.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_do_handshake.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_eof.3ossl b/openssl-install/share/man/man3/BIO_eof.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_eof.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_err_is_non_fatal.3ossl b/openssl-install/share/man/man3/BIO_err_is_non_fatal.3ossl deleted file mode 120000 index 28a49405..00000000 --- a/openssl-install/share/man/man3/BIO_err_is_non_fatal.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_sendmmsg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_f_base64.3ossl b/openssl-install/share/man/man3/BIO_f_base64.3ossl deleted file mode 100644 index 7d8008ac..00000000 --- a/openssl-install/share/man/man3/BIO_f_base64.3ossl +++ /dev/null @@ -1,267 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_BASE64 3ossl" -.TH BIO_F_BASE64 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_f_base64 \- base64 BIO filter -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& const BIO_METHOD *BIO_f_base64(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_base64()\fR returns the base64 \s-1BIO\s0 method. This is a filter -\&\s-1BIO\s0 that base64 encodes any data written through it and decodes -any data read through it. -.PP -Base64 BIOs do not support \fBBIO_gets()\fR or \fBBIO_puts()\fR. -.PP -For writing, by default output is divided to lines of length 64 -characters and there is a newline at the end of output. -This behavior can be changed with \fB\s-1BIO_FLAGS_BASE64_NO_NL\s0\fR flag. -.PP -For reading, the first line of base64 content should be at most 1024 bytes long -including newline unless the flag \fB\s-1BIO_FLAGS_BASE64_NO_NL\s0\fR is set. -Subsequent input lines can be of any length (i.e., newlines may appear anywhere -in the input) and a newline at the end of input is not needed. -.PP -Also when reading, unless the flag \fB\s-1BIO_FLAGS_BASE64_NO_NL\s0\fR is set, initial -lines that contain non\-base64 content (whitespace is tolerated and ignored) are -skipped, as are lines longer than 1024 bytes. -Decoding starts with the first line that is shorter than 1024 bytes (including -the newline) and consists of only (at least one) valid base64 characters plus -optional whitespace. -Decoding stops when base64 padding is encountered, a soft end-of-input -character (\fB\-\fR, see \fBEVP_DecodeUpdate\fR\|(3)) occurs as the first byte after a -complete group of 4 valid base64 characters is decoded, or when an error occurs -(e.g. due to input characters other than valid base64 or whitespace). -.PP -If decoding stops as a result of an error, the first \fBBIO_read\fR\|(3) that -returns no decoded data will typically return a negative result, rather -than 0 (which indicates normal end of input). -However, a negative return value can also occur if the underlying \s-1BIO\s0 -supports retries, see \fBBIO_should_read\fR\|(3) and \fBBIO_set_mem_eof_return\fR\|(3). -.PP -\&\fBBIO_flush()\fR on a base64 \s-1BIO\s0 that is being written through is -used to signal that no more data is to be encoded: this is used -to flush the final block through the \s-1BIO.\s0 -.PP -The flag \fB\s-1BIO_FLAGS_BASE64_NO_NL\s0\fR can be set with \fBBIO_set_flags()\fR. -For writing, it causes all data to be written on one line without -newline at the end. -For reading, it removes all expectations on newlines in the input data. -.SH "NOTES" -.IX Header "NOTES" -Because of the format of base64 encoding the end of the encoded -block cannot always be reliably determined. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_base64()\fR returns the base64 \s-1BIO\s0 method. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Base64 encode the string \*(L"Hello World\en\*(R" and write the result -to standard output: -.PP -.Vb 2 -\& BIO *bio, *b64; -\& char message[] = "Hello World \en"; -\& -\& b64 = BIO_new(BIO_f_base64()); -\& bio = BIO_new_fp(stdout, BIO_NOCLOSE); -\& BIO_push(b64, bio); -\& BIO_write(b64, message, strlen(message)); -\& BIO_flush(b64); -\& -\& BIO_free_all(b64); -.Ve -.PP -Read base64 encoded data from standard input and write the decoded -data to standard output: -.PP -.Vb 3 -\& BIO *bio, *b64, *bio_out; -\& char inbuf[512]; -\& int inlen; -\& -\& b64 = BIO_new(BIO_f_base64()); -\& bio = BIO_new_fp(stdin, BIO_NOCLOSE); -\& bio_out = BIO_new_fp(stdout, BIO_NOCLOSE); -\& BIO_push(b64, bio); -\& while ((inlen = BIO_read(b64, inbuf, 512)) > 0) -\& BIO_write(bio_out, inbuf, inlen); -\& -\& BIO_flush(bio_out); -\& BIO_free_all(b64); -.Ve -.SH "BUGS" -.IX Header "BUGS" -The hyphen character (\fB\-\fR) is treated as an ad hoc soft end-of-input -character when it occurs at the start of a base64 group of 4 encoded -characters. -.PP -This heuristic works to detect the ends of base64 blocks in \s-1PEM\s0 or -multi-part \s-1MIME,\s0 provided there are no stray hyphens in the middle -input. -But it is just a heuristic, and sufficiently unusual input could produce -unexpected results. -.PP -There should perhaps be some way of specifying a test that the \s-1BIO\s0 can perform -to reliably determine \s-1EOF\s0 (for example a \s-1MIME\s0 boundary). -.PP -It may be possible for \fBBIO_read\fR\|(3) to return zero, rather than \-1, even if -an error has been detected, more tests are needed to cover all the potential -error paths. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_read\fR\|(3), -\&\fBBIO_should_read\fR\|(3), -\&\fBBIO_set_mem_eof_return\fR\|(3), -\&\fBEVP_DecodeUpdate\fR\|(3). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_brotli.3ossl b/openssl-install/share/man/man3/BIO_f_brotli.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/BIO_f_brotli.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_f_buffer.3ossl b/openssl-install/share/man/man3/BIO_f_buffer.3ossl deleted file mode 100644 index 09e64071..00000000 --- a/openssl-install/share/man/man3/BIO_f_buffer.3ossl +++ /dev/null @@ -1,234 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_BUFFER 3ossl" -.TH BIO_F_BUFFER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_get_buffer_num_lines, -BIO_set_read_buffer_size, -BIO_set_write_buffer_size, -BIO_set_buffer_size, -BIO_set_buffer_read_data, -BIO_f_buffer -\&\- buffering BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_f_buffer(void); -\& -\& long BIO_get_buffer_num_lines(BIO *b); -\& long BIO_set_read_buffer_size(BIO *b, long size); -\& long BIO_set_write_buffer_size(BIO *b, long size); -\& long BIO_set_buffer_size(BIO *b, long size); -\& long BIO_set_buffer_read_data(BIO *b, void *buf, long num); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_buffer()\fR returns the buffering \s-1BIO\s0 method. -.PP -Data written to a buffering \s-1BIO\s0 is buffered and periodically written -to the next \s-1BIO\s0 in the chain. Data read from a buffering \s-1BIO\s0 comes from -an internal buffer which is filled from the next \s-1BIO\s0 in the chain. -Both \fBBIO_gets()\fR and \fBBIO_puts()\fR are supported. -.PP -Calling \fBBIO_reset()\fR on a buffering \s-1BIO\s0 clears any buffered data. -.PP -\&\fBBIO_get_buffer_num_lines()\fR returns the number of lines currently buffered. -.PP -\&\fBBIO_set_read_buffer_size()\fR, \fBBIO_set_write_buffer_size()\fR and \fBBIO_set_buffer_size()\fR -set the read, write or both read and write buffer sizes to \fBsize\fR. The initial -buffer size is \s-1DEFAULT_BUFFER_SIZE,\s0 currently 4096. Any attempt to reduce the -buffer size below \s-1DEFAULT_BUFFER_SIZE\s0 is ignored. Any buffered data is cleared -when the buffer is resized. -.PP -\&\fBBIO_set_buffer_read_data()\fR clears the read buffer and fills it with \fBnum\fR -bytes of \fBbuf\fR. If \fBnum\fR is larger than the current buffer size the buffer -is expanded. -.SH "NOTES" -.IX Header "NOTES" -These functions, other than \fBBIO_f_buffer()\fR, are implemented as macros. -.PP -Buffering BIOs implement \fBBIO_read_ex()\fR and \fBBIO_gets()\fR by using -\&\fBBIO_read_ex()\fR operations on the next \s-1BIO\s0 in the chain and storing the -result in an internal buffer, from which bytes are given back to the -caller as appropriate for the call; a \fBBIO_gets()\fR is guaranteed to give -the caller a whole line, and \fBBIO_read_ex()\fR is guaranteed to give the -caller the number of bytes it asks for, unless there's an error or end -of communication is reached in the next \s-1BIO.\s0 By prepending a -buffering \s-1BIO\s0 to a chain it is therefore possible to provide -\&\fBBIO_gets()\fR or exact size \fBBIO_read_ex()\fR functionality if the following -BIOs do not support it. -.PP -Do not add more than one \fBBIO_f_buffer()\fR to a \s-1BIO\s0 chain. The result of -doing so will force a full read of the size of the internal buffer of -the top \fBBIO_f_buffer()\fR, which is 4 KiB at a minimum. -.PP -Data is only written to the next \s-1BIO\s0 in the chain when the write buffer fills -or when \fBBIO_flush()\fR is called. It is therefore important to call \fBBIO_flush()\fR -whenever any pending data should be written such as when removing a buffering -\&\s-1BIO\s0 using \fBBIO_pop()\fR. \fBBIO_flush()\fR may need to be retried if the ultimate -source/sink \s-1BIO\s0 is non blocking. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_buffer()\fR returns the buffering \s-1BIO\s0 method. -.PP -\&\fBBIO_get_buffer_num_lines()\fR returns the number of lines buffered (may be 0) or -a negative value in case of errors. -.PP -\&\fBBIO_set_read_buffer_size()\fR, \fBBIO_set_write_buffer_size()\fR and \fBBIO_set_buffer_size()\fR -return 1 if the buffer was successfully resized or <=0 for failure. -.PP -\&\fBBIO_set_buffer_read_data()\fR returns 1 if the data was set correctly or <=0 if -there was an error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7), -\&\fBBIO_reset\fR\|(3), -\&\fBBIO_flush\fR\|(3), -\&\fBBIO_pop\fR\|(3), -\&\fBBIO_ctrl\fR\|(3). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_cipher.3ossl b/openssl-install/share/man/man3/BIO_f_cipher.3ossl deleted file mode 100644 index 364b6adb..00000000 --- a/openssl-install/share/man/man3/BIO_f_cipher.3ossl +++ /dev/null @@ -1,211 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_CIPHER 3ossl" -.TH BIO_F_CIPHER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_f_cipher, BIO_set_cipher, BIO_get_cipher_status, BIO_get_cipher_ctx \- cipher BIO filter -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& const BIO_METHOD *BIO_f_cipher(void); -\& int BIO_set_cipher(BIO *b, const EVP_CIPHER *cipher, -\& const unsigned char *key, const unsigned char *iv, int enc); -\& int BIO_get_cipher_status(BIO *b); -\& int BIO_get_cipher_ctx(BIO *b, EVP_CIPHER_CTX **pctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_cipher()\fR returns the cipher \s-1BIO\s0 method. This is a filter -\&\s-1BIO\s0 that encrypts any data written through it, and decrypts any data -read from it. It is a \s-1BIO\s0 wrapper for the cipher routines -\&\fBEVP_CipherInit()\fR, \fBEVP_CipherUpdate()\fR and \fBEVP_CipherFinal()\fR. -.PP -Cipher BIOs do not support \fBBIO_gets()\fR or \fBBIO_puts()\fR. -.PP -\&\fBBIO_flush()\fR on an encryption \s-1BIO\s0 that is being written through is -used to signal that no more data is to be encrypted: this is used -to flush and possibly pad the final block through the \s-1BIO.\s0 -.PP -\&\fBBIO_set_cipher()\fR sets the cipher of \s-1BIO\s0 \fBb\fR to \fBcipher\fR using key \fBkey\fR -and \s-1IV\s0 \fBiv\fR. \fBenc\fR should be set to 1 for encryption and zero for -decryption. -.PP -When reading from an encryption \s-1BIO\s0 the final block is automatically -decrypted and checked when \s-1EOF\s0 is detected. \fBBIO_get_cipher_status()\fR -is a \fBBIO_ctrl()\fR macro which can be called to determine whether the -decryption operation was successful. -.PP -\&\fBBIO_get_cipher_ctx()\fR is a \fBBIO_ctrl()\fR macro which retrieves the internal -\&\s-1BIO\s0 cipher context. The retrieved context can be used in conjunction -with the standard cipher routines to set it up. This is useful when -\&\fBBIO_set_cipher()\fR is not flexible enough for the applications needs. -.SH "NOTES" -.IX Header "NOTES" -When encrypting \fBBIO_flush()\fR \fBmust\fR be called to flush the final block -through the \s-1BIO.\s0 If it is not then the final block will fail a subsequent -decrypt. -.PP -When decrypting an error on the final block is signaled by a zero -return value from the read operation. A successful decrypt followed -by \s-1EOF\s0 will also return zero for the final read. \fBBIO_get_cipher_status()\fR -should be called to determine if the decrypt was successful. -.PP -As always, if \fBBIO_gets()\fR or \fBBIO_puts()\fR support is needed then it can -be achieved by preceding the cipher \s-1BIO\s0 with a buffering \s-1BIO.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_cipher()\fR returns the cipher \s-1BIO\s0 method. -.PP -\&\fBBIO_set_cipher()\fR returns 1 for success and 0 for failure. -.PP -\&\fBBIO_get_cipher_status()\fR returns 1 for a successful decrypt and <=0 -for failure. -.PP -\&\fBBIO_get_cipher_ctx()\fR returns 1 for success and <=0 for failure. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_md.3ossl b/openssl-install/share/man/man3/BIO_f_md.3ossl deleted file mode 100644 index 3eb0ac44..00000000 --- a/openssl-install/share/man/man3/BIO_f_md.3ossl +++ /dev/null @@ -1,295 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_MD 3ossl" -.TH BIO_F_MD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_f_md, BIO_set_md, BIO_get_md, BIO_get_md_ctx \- message digest BIO filter -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& const BIO_METHOD *BIO_f_md(void); -\& int BIO_set_md(BIO *b, EVP_MD *md); -\& int BIO_get_md(BIO *b, EVP_MD **mdp); -\& int BIO_get_md_ctx(BIO *b, EVP_MD_CTX **mdcp); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_md()\fR returns the message digest \s-1BIO\s0 method. This is a filter -\&\s-1BIO\s0 that digests any data passed through it. It is a \s-1BIO\s0 wrapper -for the digest routines \fBEVP_DigestInit()\fR, \fBEVP_DigestUpdate()\fR -and \fBEVP_DigestFinal()\fR. -.PP -Any data written or read through a digest \s-1BIO\s0 using \fBBIO_read_ex()\fR and -\&\fBBIO_write_ex()\fR is digested. -.PP -\&\fBBIO_gets()\fR, if its \fBsize\fR parameter is large enough finishes the -digest calculation and returns the digest value. \fBBIO_puts()\fR is -not supported. -.PP -\&\fBBIO_reset()\fR reinitialises a digest \s-1BIO.\s0 -.PP -\&\fBBIO_set_md()\fR sets the message digest of \s-1BIO\s0 \fBb\fR to \fBmd\fR: this -must be called to initialize a digest \s-1BIO\s0 before any data is -passed through it. It is a \fBBIO_ctrl()\fR macro. -.PP -\&\fBBIO_get_md()\fR places a pointer to the digest BIOs digest method -in \fBmdp\fR. It is a \fBBIO_ctrl()\fR macro. -.PP -\&\fBBIO_get_md_ctx()\fR returns the digest BIOs context into \fBmdcp\fR. -.SH "NOTES" -.IX Header "NOTES" -The context returned by \fBBIO_get_md_ctx()\fR can be used in calls -to \fBEVP_DigestFinal()\fR and also the signature routines \fBEVP_SignFinal()\fR -and \fBEVP_VerifyFinal()\fR. -.PP -The context returned by \fBBIO_get_md_ctx()\fR is an internal context -structure. Changes made to this context will affect the digest -\&\s-1BIO\s0 itself and the context pointer will become invalid when the digest -\&\s-1BIO\s0 is freed. -.PP -After the digest has been retrieved from a digest \s-1BIO\s0 it must be -reinitialized by calling \fBBIO_reset()\fR, or \fBBIO_set_md()\fR before any more -data is passed through it. -.PP -If an application needs to call \fBBIO_gets()\fR or \fBBIO_puts()\fR through -a chain containing digest BIOs then this can be done by prepending -a buffering \s-1BIO.\s0 -.PP -Calling \fBBIO_get_md_ctx()\fR will return the context and initialize the \s-1BIO\s0 -state. This allows applications to initialize the context externally -if the standard calls such as \fBBIO_set_md()\fR are not sufficiently flexible. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_md()\fR returns the digest \s-1BIO\s0 method. -.PP -\&\fBBIO_set_md()\fR, \fBBIO_get_md()\fR and \fBBIO_md_ctx()\fR return 1 for success and -<=0 for failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following example creates a \s-1BIO\s0 chain containing an \s-1SHA1\s0 and \s-1MD5\s0 -digest \s-1BIO\s0 and passes the string \*(L"Hello World\*(R" through it. Error -checking has been omitted for clarity. -.PP -.Vb 2 -\& BIO *bio, *mdtmp; -\& char message[] = "Hello World"; -\& -\& bio = BIO_new(BIO_s_null()); -\& mdtmp = BIO_new(BIO_f_md()); -\& BIO_set_md(mdtmp, EVP_sha1()); -\& /* -\& * For BIO_push() we want to append the sink BIO and keep a note of -\& * the start of the chain. -\& */ -\& bio = BIO_push(mdtmp, bio); -\& mdtmp = BIO_new(BIO_f_md()); -\& BIO_set_md(mdtmp, EVP_md5()); -\& bio = BIO_push(mdtmp, bio); -\& /* Note: mdtmp can now be discarded */ -\& BIO_write(bio, message, strlen(message)); -.Ve -.PP -The next example digests data by reading through a chain instead: -.PP -.Vb 3 -\& BIO *bio, *mdtmp; -\& char buf[1024]; -\& int rdlen; -\& -\& bio = BIO_new_file(file, "rb"); -\& mdtmp = BIO_new(BIO_f_md()); -\& BIO_set_md(mdtmp, EVP_sha1()); -\& bio = BIO_push(mdtmp, bio); -\& mdtmp = BIO_new(BIO_f_md()); -\& BIO_set_md(mdtmp, EVP_md5()); -\& bio = BIO_push(mdtmp, bio); -\& do { -\& rdlen = BIO_read(bio, buf, sizeof(buf)); -\& /* Might want to do something with the data here */ -\& } while (rdlen > 0); -.Ve -.PP -This next example retrieves the message digests from a \s-1BIO\s0 chain and -outputs them. This could be used with the examples above. -.PP -.Vb 4 -\& BIO *mdtmp; -\& unsigned char mdbuf[EVP_MAX_MD_SIZE]; -\& int mdlen; -\& int i; -\& -\& mdtmp = bio; /* Assume bio has previously been set up */ -\& do { -\& EVP_MD *md; -\& -\& mdtmp = BIO_find_type(mdtmp, BIO_TYPE_MD); -\& if (!mdtmp) -\& break; -\& BIO_get_md(mdtmp, &md); -\& printf("%s digest", OBJ_nid2sn(EVP_MD_get_type(md))); -\& mdlen = BIO_gets(mdtmp, mdbuf, EVP_MAX_MD_SIZE); -\& for (i = 0; i < mdlen; i++) printf(":%02X", mdbuf[i]); -\& printf("\en"); -\& mdtmp = BIO_next(mdtmp); -\& } while (mdtmp); -\& -\& BIO_free_all(bio); -.Ve -.SH "BUGS" -.IX Header "BUGS" -The lack of support for \fBBIO_puts()\fR and the non standard behaviour of -\&\fBBIO_gets()\fR could be regarded as anomalous. It could be argued that \fBBIO_gets()\fR -and \fBBIO_puts()\fR should be passed to the next \s-1BIO\s0 in the chain and digest -the data passed through and that digests should be retrieved using a -separate \fBBIO_ctrl()\fR call. -.SH "HISTORY" -.IX Header "HISTORY" -Before OpenSSL 1.0.0., the call to \fBBIO_get_md_ctx()\fR would only work if the -\&\s-1BIO\s0 was initialized first. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_null.3ossl b/openssl-install/share/man/man3/BIO_f_null.3ossl deleted file mode 100644 index c9ee5f23..00000000 --- a/openssl-install/share/man/man3/BIO_f_null.3ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_NULL 3ossl" -.TH BIO_F_NULL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_f_null \- null filter -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_f_null(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_null()\fR returns the null filter \s-1BIO\s0 method. This is a filter \s-1BIO\s0 -that does nothing. -.PP -All requests to a null filter \s-1BIO\s0 are passed through to the next \s-1BIO\s0 in -the chain: this means that a \s-1BIO\s0 chain containing a null filter \s-1BIO\s0 -behaves just as though the \s-1BIO\s0 was not there. -.SH "NOTES" -.IX Header "NOTES" -As may be apparent a null filter \s-1BIO\s0 is not particularly useful. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_null()\fR returns the null filter \s-1BIO\s0 method. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_prefix.3ossl b/openssl-install/share/man/man3/BIO_f_prefix.3ossl deleted file mode 100644 index 9bc5c29e..00000000 --- a/openssl-install/share/man/man3/BIO_f_prefix.3ossl +++ /dev/null @@ -1,201 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_PREFIX 3ossl" -.TH BIO_F_PREFIX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_f_prefix, BIO_set_prefix, BIO_set_indent, BIO_get_indent -\&\- prefix BIO filter -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_f_prefix(void); -\& long BIO_set_prefix(BIO *b, const char *prefix); -\& long BIO_set_indent(BIO *b, long indent); -\& long BIO_get_indent(BIO *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_cipher()\fR returns the prefix \s-1BIO\s0 method. This is a filter for -text output, where each line gets automatically prefixed and indented -according to user input. -.PP -The prefix and the indentation are combined. For each line of output -going through this filter, the prefix is output first, then the amount -of additional spaces indicated by the indentation, and then the line -itself. -.PP -By default, there is no prefix, and indentation is set to 0. -.PP -\&\fBBIO_set_prefix()\fR sets the prefix to be used for future lines of -text, using \fIprefix\fR. \fIprefix\fR may be \s-1NULL,\s0 signifying that there -should be no prefix. If \fIprefix\fR isn't \s-1NULL,\s0 this function makes a -copy of it. -.PP -\&\fBBIO_set_indent()\fR sets the indentation to be used for future lines of -text, using \fIindent\fR. Negative values are not allowed. -.PP -\&\fBBIO_get_indent()\fR gets the current indentation. -.SH "NOTES" -.IX Header "NOTES" -\&\fBBIO_set_prefix()\fR, \fBBIO_set_indent()\fR and \fBBIO_get_indent()\fR are -implemented as macros. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_prefix()\fR returns the prefix \s-1BIO\s0 method. -.PP -\&\fBBIO_set_prefix()\fR returns 1 if the prefix was correctly set, or <=0 on -failure. -.PP -\&\fBBIO_set_indent()\fR returns 1 if the prefix was correctly set, or <=0 on -failure. -.PP -\&\fBBIO_get_indent()\fR returns the current indentation, or a negative value for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_readbuffer.3ossl b/openssl-install/share/man/man3/BIO_f_readbuffer.3ossl deleted file mode 100644 index 1f7545a7..00000000 --- a/openssl-install/share/man/man3/BIO_f_readbuffer.3ossl +++ /dev/null @@ -1,192 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_READBUFFER 3ossl" -.TH BIO_F_READBUFFER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_f_readbuffer -\&\- read only buffering BIO that supports BIO_tell() and BIO_seek() -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_f_readbuffer(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_readbuffer()\fR returns the read buffering \s-1BIO\s0 method. -.PP -This \s-1BIO\s0 filter can be inserted on top of \s-1BIO\s0's that do not support \fBBIO_tell()\fR -or \fBBIO_seek()\fR (e.g. A file \s-1BIO\s0 that uses stdin). -.PP -Data read from a read buffering \s-1BIO\s0 comes from an internal buffer which is -filled from the next \s-1BIO\s0 in the chain. -.PP -\&\fBBIO_gets()\fR is supported for read buffering BIOs. -Writing data to a read buffering \s-1BIO\s0 is not supported. -.PP -Calling \fBBIO_reset()\fR on a read buffering \s-1BIO\s0 does not clear any buffered data. -.SH "NOTES" -.IX Header "NOTES" -Read buffering BIOs implement \fBBIO_read_ex()\fR by using \fBBIO_read_ex()\fR operations -on the next \s-1BIO\s0 (e.g. a file \s-1BIO\s0) in the chain and storing the result in an -internal buffer, from which bytes are given back to the caller as appropriate -for the call. \fBBIO_read_ex()\fR is guaranteed to give the caller the number of bytes -it asks for, unless there's an error or end of communication is reached in the -next \s-1BIO.\s0 The internal buffer can grow to cache the entire contents of the next -\&\s-1BIO\s0 in the chain. \fBBIO_seek()\fR uses the internal buffer, so that it can only seek -into data that is already read. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_readbuffer()\fR returns the read buffering \s-1BIO\s0 method. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7), -\&\fBBIO_read\fR\|(3), -\&\fBBIO_gets\fR\|(3), -\&\fBBIO_reset\fR\|(3), -\&\fBBIO_ctrl\fR\|(3). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_ssl.3ossl b/openssl-install/share/man/man3/BIO_f_ssl.3ossl deleted file mode 100644 index dde781fd..00000000 --- a/openssl-install/share/man/man3/BIO_f_ssl.3ossl +++ /dev/null @@ -1,446 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_F_SSL 3ossl" -.TH BIO_F_SSL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_do_handshake, -BIO_f_ssl, BIO_set_ssl, BIO_get_ssl, BIO_set_ssl_mode, -BIO_set_ssl_renegotiate_bytes, -BIO_get_num_renegotiates, BIO_set_ssl_renegotiate_timeout, BIO_new_ssl, -BIO_new_ssl_connect, BIO_new_buffer_ssl_connect, BIO_ssl_copy_session_id, -BIO_ssl_shutdown \- SSL BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& const BIO_METHOD *BIO_f_ssl(void); -\& -\& long BIO_set_ssl(BIO *b, SSL *ssl, long c); -\& long BIO_get_ssl(BIO *b, SSL **sslp); -\& long BIO_set_ssl_mode(BIO *b, long client); -\& long BIO_set_ssl_renegotiate_bytes(BIO *b, long num); -\& long BIO_set_ssl_renegotiate_timeout(BIO *b, long seconds); -\& long BIO_get_num_renegotiates(BIO *b); -\& -\& BIO *BIO_new_ssl(SSL_CTX *ctx, int client); -\& BIO *BIO_new_ssl_connect(SSL_CTX *ctx); -\& BIO *BIO_new_buffer_ssl_connect(SSL_CTX *ctx); -\& int BIO_ssl_copy_session_id(BIO *to, BIO *from); -\& void BIO_ssl_shutdown(BIO *bio); -\& -\& long BIO_do_handshake(BIO *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_f_ssl()\fR returns the \s-1SSL BIO\s0 method. This is a filter \s-1BIO\s0 which -is a wrapper round the OpenSSL \s-1SSL\s0 routines adding a \s-1BIO\s0 \*(L"flavour\*(R" to -\&\s-1SSL I/O.\s0 -.PP -I/O performed on an \s-1SSL BIO\s0 communicates using the \s-1SSL\s0 protocol with -the SSLs read and write BIOs. If an \s-1SSL\s0 connection is not established -then an attempt is made to establish one on the first I/O call. -.PP -If a \s-1BIO\s0 is appended to an \s-1SSL BIO\s0 using \fBBIO_push()\fR it is automatically -used as the \s-1SSL\s0 BIOs read and write BIOs. -.PP -Calling \fBBIO_reset()\fR on an \s-1SSL BIO\s0 closes down any current \s-1SSL\s0 connection -by calling \fBSSL_shutdown()\fR. \fBBIO_reset()\fR is then sent to the next \s-1BIO\s0 in -the chain: this will typically disconnect the underlying transport. -The \s-1SSL BIO\s0 is then reset to the initial accept or connect state. -.PP -If the close flag is set when an \s-1SSL BIO\s0 is freed then the internal -\&\s-1SSL\s0 structure is also freed using \fBSSL_free()\fR. -.PP -\&\fBBIO_set_ssl()\fR sets the internal \s-1SSL\s0 pointer of \s-1SSL BIO\s0 \fBb\fR to \fBssl\fR using -the close flag \fBc\fR. -.PP -\&\fBBIO_get_ssl()\fR retrieves the \s-1SSL\s0 pointer of \s-1SSL BIO\s0 \fBb\fR, it can then be -manipulated using the standard \s-1SSL\s0 library functions. -.PP -\&\fBBIO_set_ssl_mode()\fR sets the \s-1SSL BIO\s0 mode to \fBclient\fR. If \fBclient\fR -is 1 client mode is set. If \fBclient\fR is 0 server mode is set. -.PP -\&\fBBIO_set_ssl_renegotiate_bytes()\fR sets the renegotiate byte count of \s-1SSL BIO\s0 \fBb\fR -to \fBnum\fR. When set after every \fBnum\fR bytes of I/O (read and write) -the \s-1SSL\s0 session is automatically renegotiated. \fBnum\fR must be at -least 512 bytes. -.PP -\&\fBBIO_set_ssl_renegotiate_timeout()\fR sets the renegotiate timeout of \s-1SSL BIO\s0 \fBb\fR -to \fBseconds\fR. -When the renegotiate timeout elapses the session is automatically renegotiated. -.PP -\&\fBBIO_get_num_renegotiates()\fR returns the total number of session -renegotiations due to I/O or timeout of \s-1SSL BIO\s0 \fBb\fR. -.PP -\&\fBBIO_new_ssl()\fR allocates an \s-1SSL BIO\s0 using \s-1SSL_CTX\s0 \fBctx\fR and using -client mode if \fBclient\fR is non zero. -.PP -\&\fBBIO_new_ssl_connect()\fR creates a new \s-1BIO\s0 chain consisting of an -\&\s-1SSL BIO\s0 (using \fBctx\fR) followed by a connect \s-1BIO.\s0 -.PP -\&\fBBIO_new_buffer_ssl_connect()\fR creates a new \s-1BIO\s0 chain consisting -of a buffering \s-1BIO,\s0 an \s-1SSL BIO\s0 (using \fBctx\fR), and a connect \s-1BIO.\s0 -.PP -\&\fBBIO_ssl_copy_session_id()\fR copies an \s-1SSL\s0 session id between -\&\s-1BIO\s0 chains \fBfrom\fR and \fBto\fR. It does this by locating the -\&\s-1SSL\s0 BIOs in each chain and calling \fBSSL_copy_session_id()\fR on -the internal \s-1SSL\s0 pointer. -.PP -\&\fBBIO_ssl_shutdown()\fR closes down an \s-1SSL\s0 connection on \s-1BIO\s0 -chain \fBbio\fR. It does this by locating the \s-1SSL BIO\s0 in the -chain and calling \fBSSL_shutdown()\fR on its internal \s-1SSL\s0 -pointer. -.PP -\&\fBBIO_do_handshake()\fR attempts to complete an \s-1SSL\s0 handshake on the -supplied \s-1BIO\s0 and establish the \s-1SSL\s0 connection. -For non-SSL BIOs the connection is done typically at \s-1TCP\s0 level. -If domain name resolution yields multiple \s-1IP\s0 addresses all of them are tried -after \fBconnect()\fR failures. -The function returns 1 if the connection was established successfully. -A zero or negative value is returned if the connection could not be established. -The call \fBBIO_should_retry()\fR should be used for nonblocking connect BIOs -to determine if the call should be retried. -If a connection has already been established this call has no effect. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1SSL\s0 BIOs are exceptional in that if the underlying transport -is non blocking they can still request a retry in exceptional -circumstances. Specifically this will happen if a session -renegotiation takes place during a \fBBIO_read_ex()\fR operation, one -case where this happens is when step up occurs. -.PP -The \s-1SSL\s0 flag \s-1SSL_AUTO_RETRY\s0 can be -set to disable this behaviour. That is when this flag is set -an \s-1SSL BIO\s0 using a blocking transport will never request a -retry. -.PP -Since unknown \fBBIO_ctrl()\fR operations are sent through filter -BIOs the servers name and port can be set using \fBBIO_set_host()\fR -on the \s-1BIO\s0 returned by \fBBIO_new_ssl_connect()\fR without having -to locate the connect \s-1BIO\s0 first. -.PP -Applications do not have to call \fBBIO_do_handshake()\fR but may wish -to do so to separate the handshake process from other I/O -processing. -.PP -\&\fBBIO_set_ssl()\fR, \fBBIO_get_ssl()\fR, \fBBIO_set_ssl_mode()\fR, -\&\fBBIO_set_ssl_renegotiate_bytes()\fR, \fBBIO_set_ssl_renegotiate_timeout()\fR, -\&\fBBIO_get_num_renegotiates()\fR, and \fBBIO_do_handshake()\fR are implemented as macros. -.PP -\&\fBBIO_ssl_copy_session_id()\fR is not currently supported on \s-1QUIC SSL\s0 objects and -fails if called on such an object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_f_ssl()\fR returns the \s-1SSL\s0 \fB\s-1BIO_METHOD\s0\fR structure. -.PP -\&\fBBIO_set_ssl()\fR, \fBBIO_get_ssl()\fR, \fBBIO_set_ssl_mode()\fR, \fBBIO_set_ssl_renegotiate_bytes()\fR, -\&\fBBIO_set_ssl_renegotiate_timeout()\fR and \fBBIO_get_num_renegotiates()\fR return 1 on -success or a value which is less than or equal to 0 if an error occurred. -.PP -\&\fBBIO_new_ssl()\fR, \fBBIO_new_ssl_connect()\fR and \fBBIO_new_buffer_ssl_connect()\fR return -a valid \fB\s-1BIO\s0\fR structure on success or \fB\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBBIO_ssl_copy_session_id()\fR returns 1 on success or 0 on error, or if called -on a \s-1QUIC SSL\s0 object. -.PP -\&\fBBIO_do_handshake()\fR returns 1 if the connection was established successfully. -A zero or negative value is returned if the connection could not be established. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This \s-1SSL/TLS\s0 client example attempts to retrieve a page from an -\&\s-1SSL/TLS\s0 web server. The I/O routines are identical to those of the -unencrypted example in \fBBIO_s_connect\fR\|(3). -.PP -.Vb 5 -\& BIO *sbio, *out; -\& int len; -\& char tmpbuf[1024]; -\& SSL_CTX *ctx; -\& SSL *ssl; -\& -\& /* XXX Seed the PRNG if needed. */ -\& -\& ctx = SSL_CTX_new(TLS_client_method()); -\& -\& /* XXX Set verify paths and mode here. */ -\& -\& sbio = BIO_new_ssl_connect(ctx); -\& BIO_get_ssl(sbio, &ssl); -\& if (ssl == NULL) { -\& fprintf(stderr, "Can\*(Aqt locate SSL pointer\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& -\& /* XXX We might want to do other things with ssl here */ -\& -\& /* An empty host part means the loopback address */ -\& BIO_set_conn_hostname(sbio, ":https"); -\& -\& out = BIO_new_fp(stdout, BIO_NOCLOSE); -\& if (BIO_do_connect(sbio) <= 0) { -\& fprintf(stderr, "Error connecting to server\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& -\& /* XXX Could examine ssl here to get connection info */ -\& -\& BIO_puts(sbio, "GET / HTTP/1.0\en\en"); -\& for (;;) { -\& len = BIO_read(sbio, tmpbuf, 1024); -\& if (len <= 0) -\& break; -\& BIO_write(out, tmpbuf, len); -\& } -\& BIO_free_all(sbio); -\& BIO_free(out); -.Ve -.PP -Here is a simple server example. It makes use of a buffering -\&\s-1BIO\s0 to allow lines to be read from the \s-1SSL BIO\s0 using BIO_gets. -It creates a pseudo web page containing the actual request from -a client and also echoes the request to standard output. -.PP -.Vb 5 -\& BIO *sbio, *bbio, *acpt, *out; -\& int len; -\& char tmpbuf[1024]; -\& SSL_CTX *ctx; -\& SSL *ssl; -\& -\& /* XXX Seed the PRNG if needed. */ -\& -\& ctx = SSL_CTX_new(TLS_server_method()); -\& if (!SSL_CTX_use_certificate_file(ctx, "server.pem", SSL_FILETYPE_PEM) -\& || !SSL_CTX_use_PrivateKey_file(ctx, "server.pem", SSL_FILETYPE_PEM) -\& || !SSL_CTX_check_private_key(ctx)) { -\& fprintf(stderr, "Error setting up SSL_CTX\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& -\& /* XXX Other things like set verify locations, EDH temp callbacks. */ -\& -\& /* New SSL BIO setup as server */ -\& sbio = BIO_new_ssl(ctx, 0); -\& BIO_get_ssl(sbio, &ssl); -\& if (ssl == NULL) { -\& fprintf(stderr, "Can\*(Aqt locate SSL pointer\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& -\& bbio = BIO_new(BIO_f_buffer()); -\& sbio = BIO_push(bbio, sbio); -\& acpt = BIO_new_accept("4433"); -\& -\& /* -\& * By doing this when a new connection is established -\& * we automatically have sbio inserted into it. The -\& * BIO chain is now \*(Aqswallowed\*(Aq by the accept BIO and -\& * will be freed when the accept BIO is freed. -\& */ -\& BIO_set_accept_bios(acpt, sbio); -\& out = BIO_new_fp(stdout, BIO_NOCLOSE); -\& -\& /* First call to BIO_do_accept() sets up accept BIO */ -\& if (BIO_do_accept(acpt) <= 0) { -\& fprintf(stderr, "Error setting up accept BIO\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -.Ve -.PP -/* Second call to \fBBIO_do_accept()\fR waits for incoming connection */ - if (BIO_do_accept(acpt) <= 0) { - fprintf(stderr, \*(L"Error accepting connection\en\*(R"); - ERR_print_errors_fp(stderr); - \fBexit\fR\|(1); - } -.PP -.Vb 3 -\& /* We only want one connection so remove and free accept BIO */ -\& sbio = BIO_pop(acpt); -\& BIO_free_all(acpt); -\& -\& if (BIO_do_handshake(sbio) <= 0) { -\& fprintf(stderr, "Error in SSL handshake\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& -\& BIO_puts(sbio, "HTTP/1.0 200 OK\er\enContent\-type: text/plain\er\en\er\en"); -\& BIO_puts(sbio, "\er\enConnection Established\er\enRequest headers:\er\en"); -\& BIO_puts(sbio, "\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\er\en"); -\& -\& for (;;) { -\& len = BIO_gets(sbio, tmpbuf, 1024); -\& if (len <= 0) -\& break; -\& BIO_write(sbio, tmpbuf, len); -\& BIO_write(out, tmpbuf, len); -\& /* Look for blank line signifying end of headers*/ -\& if (tmpbuf[0] == \*(Aq\er\*(Aq || tmpbuf[0] == \*(Aq\en\*(Aq) -\& break; -\& } -\& -\& BIO_puts(sbio, "\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\er\en"); -\& BIO_puts(sbio, "\er\en"); -\& BIO_flush(sbio); -\& BIO_free_all(sbio); -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -In OpenSSL before 1.0.0 the \fBBIO_pop()\fR call was handled incorrectly, -the I/O \s-1BIO\s0 reference count was incorrectly incremented (instead of -decremented) and dissociated with the \s-1SSL BIO\s0 even if the \s-1SSL BIO\s0 was not -explicitly being popped (e.g. a pop higher up the chain). Applications which -included workarounds for this bug (e.g. freeing BIOs more than once) should -be modified to handle this fix or they may free up an already freed \s-1BIO.\s0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_f_zlib.3ossl b/openssl-install/share/man/man3/BIO_f_zlib.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/BIO_f_zlib.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_f_zstd.3ossl b/openssl-install/share/man/man3/BIO_f_zstd.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/BIO_f_zstd.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_find_type.3ossl b/openssl-install/share/man/man3/BIO_find_type.3ossl deleted file mode 100644 index d0546b29..00000000 --- a/openssl-install/share/man/man3/BIO_find_type.3ossl +++ /dev/null @@ -1,203 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_FIND_TYPE 3ossl" -.TH BIO_FIND_TYPE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_find_type, BIO_next, BIO_method_type \- BIO chain traversal -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIO *BIO_find_type(BIO *b, int bio_type); -\& BIO *BIO_next(BIO *b); -\& int BIO_method_type(const BIO *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBBIO_find_type()\fR searches for a \fB\s-1BIO\s0\fR of a given type in a chain, starting -at \fB\s-1BIO\s0\fR \fIb\fR. If \fItype\fR is a specific type (such as \fB\s-1BIO_TYPE_MEM\s0\fR) then a -search is made for a \fB\s-1BIO\s0\fR of that type. If \fItype\fR is a general type (such as -\&\fB\s-1BIO_TYPE_SOURCE_SINK\s0\fR) then the next matching \fB\s-1BIO\s0\fR of the given general type is -searched for. \fBBIO_find_type()\fR returns the next matching \fB\s-1BIO\s0\fR or \s-1NULL\s0 if none is -found. If \fItype\fR is \fB\s-1BIO_TYPE_NONE\s0\fR it will not find a match. -.PP -The following general types are defined: -\&\fB\s-1BIO_TYPE_DESCRIPTOR\s0\fR, \fB\s-1BIO_TYPE_FILTER\s0\fR, and \fB\s-1BIO_TYPE_SOURCE_SINK\s0\fR. -.PP -For a list of the specific types, see the \fI\fR header file. -.PP -\&\fBBIO_next()\fR returns the next \s-1BIO\s0 in a chain. It can be used to traverse all BIOs -in a chain or used in conjunction with \fBBIO_find_type()\fR to find all BIOs of a -certain type. -.PP -\&\fBBIO_method_type()\fR returns the type of a \s-1BIO.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_find_type()\fR returns a matching \s-1BIO\s0 or \s-1NULL\s0 for no match. -.PP -\&\fBBIO_next()\fR returns the next \s-1BIO\s0 in a chain. -.PP -\&\fBBIO_method_type()\fR returns the type of the \s-1BIO\s0 \fIb\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Traverse a chain looking for digest BIOs: -.PP -.Vb 1 -\& BIO *btmp; -\& -\& btmp = in_bio; /* in_bio is chain to search through */ -\& do { -\& btmp = BIO_find_type(btmp, BIO_TYPE_MD); -\& if (btmp == NULL) -\& break; /* Not found */ -\& /* btmp is a digest BIO, do something with it ...*/ -\& ... -\& -\& btmp = BIO_next(btmp); -\& } while (btmp); -.Ve -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_flush.3ossl b/openssl-install/share/man/man3/BIO_flush.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_flush.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_free.3ossl b/openssl-install/share/man/man3/BIO_free.3ossl deleted file mode 120000 index 9126d49b..00000000 --- a/openssl-install/share/man/man3/BIO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_free_all.3ossl b/openssl-install/share/man/man3/BIO_free_all.3ossl deleted file mode 120000 index 9126d49b..00000000 --- a/openssl-install/share/man/man3/BIO_free_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get0_dgram_bio.3ossl b/openssl-install/share/man/man3/BIO_get0_dgram_bio.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_get0_dgram_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_accept_ip_family.3ossl b/openssl-install/share/man/man3/BIO_get_accept_ip_family.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_get_accept_ip_family.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_accept_name.3ossl b/openssl-install/share/man/man3/BIO_get_accept_name.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_get_accept_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_accept_port.3ossl b/openssl-install/share/man/man3/BIO_get_accept_port.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_get_accept_port.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_app_data.3ossl b/openssl-install/share/man/man3/BIO_get_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/BIO_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_bind_mode.3ossl b/openssl-install/share/man/man3/BIO_get_bind_mode.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_get_bind_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_buffer_num_lines.3ossl b/openssl-install/share/man/man3/BIO_get_buffer_num_lines.3ossl deleted file mode 120000 index ad4704f1..00000000 --- a/openssl-install/share/man/man3/BIO_get_buffer_num_lines.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_buffer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_callback.3ossl b/openssl-install/share/man/man3/BIO_get_callback.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_get_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_callback_arg.3ossl b/openssl-install/share/man/man3/BIO_get_callback_arg.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_get_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_callback_ex.3ossl b/openssl-install/share/man/man3/BIO_get_callback_ex.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_get_callback_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_cipher_ctx.3ossl b/openssl-install/share/man/man3/BIO_get_cipher_ctx.3ossl deleted file mode 120000 index 15f4e6f1..00000000 --- a/openssl-install/share/man/man3/BIO_get_cipher_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_cipher_status.3ossl b/openssl-install/share/man/man3/BIO_get_cipher_status.3ossl deleted file mode 120000 index 15f4e6f1..00000000 --- a/openssl-install/share/man/man3/BIO_get_cipher_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_close.3ossl b/openssl-install/share/man/man3/BIO_get_close.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_get_close.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_conn_address.3ossl b/openssl-install/share/man/man3/BIO_get_conn_address.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_get_conn_address.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_conn_hostname.3ossl b/openssl-install/share/man/man3/BIO_get_conn_hostname.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_get_conn_hostname.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_conn_ip_family.3ossl b/openssl-install/share/man/man3/BIO_get_conn_ip_family.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_get_conn_ip_family.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_conn_mode.3ossl b/openssl-install/share/man/man3/BIO_get_conn_mode.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_get_conn_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_conn_port.3ossl b/openssl-install/share/man/man3/BIO_get_conn_port.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_get_conn_port.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_data.3ossl b/openssl-install/share/man/man3/BIO_get_data.3ossl deleted file mode 100644 index 533bf895..00000000 --- a/openssl-install/share/man/man3/BIO_get_data.3ossl +++ /dev/null @@ -1,196 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_GET_DATA 3ossl" -.TH BIO_GET_DATA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_set_data, BIO_get_data, BIO_set_init, BIO_get_init, BIO_set_shutdown, -BIO_get_shutdown \- functions for managing BIO state information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void BIO_set_data(BIO *a, void *ptr); -\& void *BIO_get_data(BIO *a); -\& void BIO_set_init(BIO *a, int init); -\& int BIO_get_init(BIO *a); -\& void BIO_set_shutdown(BIO *a, int shut); -\& int BIO_get_shutdown(BIO *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are mainly useful when implementing a custom \s-1BIO.\s0 -.PP -The \fBBIO_set_data()\fR function associates the custom data pointed to by \fBptr\fR with -the \s-1BIO.\s0 This data can subsequently be retrieved via a call to \fBBIO_get_data()\fR. -This can be used by custom BIOs for storing implementation specific information. -.PP -The \fBBIO_set_init()\fR function sets the value of the \s-1BIO\s0's \*(L"init\*(R" flag to indicate -whether initialisation has been completed for this \s-1BIO\s0 or not. A nonzero value -indicates that initialisation is complete, whilst zero indicates that it is not. -Often initialisation will complete during initial construction of the \s-1BIO.\s0 For -some BIOs however, initialisation may not complete until after additional steps -have occurred (for example through calling custom ctrls). The \fBBIO_get_init()\fR -function returns the value of the \*(L"init\*(R" flag. -.PP -The \fBBIO_set_shutdown()\fR and \fBBIO_get_shutdown()\fR functions set and get the state of -this \s-1BIO\s0's shutdown (i.e. \s-1BIO_CLOSE\s0) flag. If set then the underlying resource -is also closed when the \s-1BIO\s0 is freed. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_get_data()\fR returns a pointer to the implementation specific custom data -associated with this \s-1BIO,\s0 or \s-1NULL\s0 if none has been set. -.PP -\&\fBBIO_get_init()\fR returns the state of the \s-1BIO\s0's init flag. -.PP -\&\fBBIO_get_shutdown()\fR returns the stat of the \s-1BIO\s0's shutdown (i.e. \s-1BIO_CLOSE\s0) flag. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7), \fBBIO_meth_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_get_ex_data.3ossl b/openssl-install/share/man/man3/BIO_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/BIO_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_ex_new_index.3ossl b/openssl-install/share/man/man3/BIO_get_ex_new_index.3ossl deleted file mode 100644 index 8bb830db..00000000 --- a/openssl-install/share/man/man3/BIO_get_ex_new_index.3ossl +++ /dev/null @@ -1,266 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_GET_EX_NEW_INDEX 3ossl" -.TH BIO_GET_EX_NEW_INDEX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_get_ex_new_index, BIO_set_ex_data, BIO_get_ex_data, -BIO_set_app_data, BIO_get_app_data, -DH_get_ex_new_index, DH_set_ex_data, DH_get_ex_data, -DSA_get_ex_new_index, DSA_set_ex_data, DSA_get_ex_data, -EC_KEY_get_ex_new_index, EC_KEY_set_ex_data, EC_KEY_get_ex_data, -ENGINE_get_ex_new_index, ENGINE_set_ex_data, ENGINE_get_ex_data, -EVP_PKEY_get_ex_new_index, EVP_PKEY_set_ex_data, EVP_PKEY_get_ex_data, -RSA_get_ex_new_index, RSA_set_ex_data, RSA_get_ex_data, -RSA_set_app_data, RSA_get_app_data, -SSL_get_ex_new_index, SSL_set_ex_data, SSL_get_ex_data, -SSL_set_app_data, SSL_get_app_data, -SSL_CTX_get_ex_new_index, SSL_CTX_set_ex_data, SSL_CTX_get_ex_data, -SSL_CTX_set_app_data, SSL_CTX_get_app_data, -SSL_SESSION_get_ex_new_index, SSL_SESSION_set_ex_data, SSL_SESSION_get_ex_data, -SSL_SESSION_set_app_data, SSL_SESSION_get_app_data, -UI_get_ex_new_index, UI_set_ex_data, UI_get_ex_data, -UI_set_app_data, UI_get_app_data, -X509_STORE_CTX_get_ex_new_index, X509_STORE_CTX_set_ex_data, X509_STORE_CTX_get_ex_data, -X509_STORE_CTX_set_app_data, X509_STORE_CTX_get_app_data, -X509_STORE_get_ex_new_index, X509_STORE_set_ex_data, X509_STORE_get_ex_data, -X509_get_ex_new_index, X509_set_ex_data, X509_get_ex_data -\&\- application\-specific data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int TYPE_get_ex_new_index(long argl, void *argp, -\& CRYPTO_EX_new *new_func, -\& CRYPTO_EX_dup *dup_func, -\& CRYPTO_EX_free *free_func); -\& -\& int TYPE_set_ex_data(TYPE *d, int idx, void *arg); -\& -\& void *TYPE_get_ex_data(const TYPE *d, int idx); -\& -\& #define TYPE_set_app_data(TYPE *d, void *arg) -\& #define TYPE_get_app_data(TYPE *d) -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& int DH_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func, -\& CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func); -\& int DH_set_ex_data(DH *type, int idx, void *arg); -\& void *DH_get_ex_data(DH *type, int idx); -\& int DSA_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func, -\& CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func); -\& int DSA_set_ex_data(DSA *type, int idx, void *arg); -\& void *DSA_get_ex_data(DSA *type, int idx); -\& int EC_KEY_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func, -\& CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func); -\& int EC_KEY_set_ex_data(EC_KEY *type, int idx, void *arg); -\& void *EC_KEY_get_ex_data(EC_KEY *type, int idx); -\& int RSA_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func, -\& CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func); -\& int RSA_set_ex_data(RSA *type, int idx, void *arg); -\& void *RSA_get_ex_data(RSA *type, int idx); -\& int RSA_set_app_data(RSA *type, void *arg); -\& void *RSA_get_app_data(RSA *type); -\& int ENGINE_get_ex_new_index(long argl, void *argp, CRYPTO_EX_new *new_func, -\& CRYPTO_EX_dup *dup_func, CRYPTO_EX_free *free_func); -\& int ENGINE_set_ex_data(ENGINE *type, int idx, void *arg); -\& void *ENGINE_get_ex_data(ENGINE *type, int idx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -In the description here, \fI\s-1TYPE\s0\fR is used a placeholder -for any of the OpenSSL datatypes listed in \fBCRYPTO_get_ex_new_index\fR\|(3). -.PP -All functions with a \fI\s-1TYPE\s0\fR of \fB\s-1DH\s0\fR, \fB\s-1DSA\s0\fR, \fB\s-1RSA\s0\fR and \fB\s-1EC_KEY\s0\fR are deprecated. -Applications should instead use \fBEVP_PKEY_set_ex_data()\fR, -\&\fBEVP_PKEY_get_ex_data()\fR and \fBEVP_PKEY_get_ex_new_index()\fR. -.PP -All functions with a \fI\s-1TYPE\s0\fR of \fB\s-1ENGINE\s0\fR are deprecated. -Applications using engines should be replaced by providers. -.PP -These functions handle application-specific data for OpenSSL data -structures. -.PP -\&\fBTYPE_get_ex_new_index()\fR is a macro that calls \fBCRYPTO_get_ex_new_index()\fR -with the correct \fBindex\fR value. -.PP -\&\fBTYPE_set_ex_data()\fR is a function that calls \fBCRYPTO_set_ex_data()\fR with -an offset into the opaque exdata part of the \s-1TYPE\s0 object. -.PP -\&\fBTYPE_get_ex_data()\fR is a function that calls \fBCRYPTO_get_ex_data()\fR with -an offset into the opaque exdata part of the \s-1TYPE\s0 object. -.PP -For compatibility with previous releases, the exdata index of zero is -reserved for \*(L"application data.\*(R" There are two convenience functions for -this. -\&\fBTYPE_set_app_data()\fR is a macro that invokes \fBTYPE_set_ex_data()\fR with -\&\fBidx\fR set to zero. -\&\fBTYPE_get_app_data()\fR is a macro that invokes \fBTYPE_get_ex_data()\fR with -\&\fBidx\fR set to zero. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBTYPE_get_ex_new_index()\fR returns a new index on success or \-1 on error. -.PP -\&\fBTYPE_set_ex_data()\fR returns 1 on success or 0 on error. -.PP -\&\fBTYPE_get_ex_data()\fR returns the application data or \s-1NULL\s0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBCRYPTO_get_ex_new_index\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBDH_get_ex_new_index()\fR, \fBDH_set_ex_data()\fR, \fBDH_get_ex_data()\fR, -\&\fBDSA_get_ex_new_index()\fR, \fBDSA_set_ex_data()\fR, \fBDSA_get_ex_data()\fR, -\&\fBEC_KEY_get_ex_new_index()\fR, \fBEC_KEY_set_ex_data()\fR, \fBEC_KEY_get_ex_data()\fR, -\&\fBENGINE_get_ex_new_index()\fR, \fBENGINE_set_ex_data()\fR, \fBENGINE_get_ex_data()\fR, -\&\fBRSA_get_ex_new_index()\fR, \fBRSA_set_ex_data()\fR, \fBRSA_get_ex_data()\fR, -\&\fBRSA_set_app_data()\fR and \fBRSA_get_app_data()\fR were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_get_fd.3ossl b/openssl-install/share/man/man3/BIO_get_fd.3ossl deleted file mode 120000 index 91a83843..00000000 --- a/openssl-install/share/man/man3/BIO_get_fd.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_fd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_fp.3ossl b/openssl-install/share/man/man3/BIO_get_fp.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_get_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_indent.3ossl b/openssl-install/share/man/man3/BIO_get_indent.3ossl deleted file mode 120000 index 324d0806..00000000 --- a/openssl-install/share/man/man3/BIO_get_indent.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_prefix.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_info_callback.3ossl b/openssl-install/share/man/man3/BIO_get_info_callback.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_get_info_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_init.3ossl b/openssl-install/share/man/man3/BIO_get_init.3ossl deleted file mode 120000 index d0d51f6b..00000000 --- a/openssl-install/share/man/man3/BIO_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_ktls_recv.3ossl b/openssl-install/share/man/man3/BIO_get_ktls_recv.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_get_ktls_recv.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_ktls_send.3ossl b/openssl-install/share/man/man3/BIO_get_ktls_send.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_get_ktls_send.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_line.3ossl b/openssl-install/share/man/man3/BIO_get_line.3ossl deleted file mode 120000 index 688d3c98..00000000 --- a/openssl-install/share/man/man3/BIO_get_line.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_md.3ossl b/openssl-install/share/man/man3/BIO_get_md.3ossl deleted file mode 120000 index 1b4ea909..00000000 --- a/openssl-install/share/man/man3/BIO_get_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_md_ctx.3ossl b/openssl-install/share/man/man3/BIO_get_md_ctx.3ossl deleted file mode 120000 index 1b4ea909..00000000 --- a/openssl-install/share/man/man3/BIO_get_md_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_mem_data.3ossl b/openssl-install/share/man/man3/BIO_get_mem_data.3ossl deleted file mode 120000 index e9853704..00000000 --- a/openssl-install/share/man/man3/BIO_get_mem_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_mem.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_mem_ptr.3ossl b/openssl-install/share/man/man3/BIO_get_mem_ptr.3ossl deleted file mode 120000 index e9853704..00000000 --- a/openssl-install/share/man/man3/BIO_get_mem_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_mem.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_new_index.3ossl b/openssl-install/share/man/man3/BIO_get_new_index.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_get_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_num_renegotiates.3ossl b/openssl-install/share/man/man3/BIO_get_num_renegotiates.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_get_num_renegotiates.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_peer_name.3ossl b/openssl-install/share/man/man3/BIO_get_peer_name.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_get_peer_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_peer_port.3ossl b/openssl-install/share/man/man3/BIO_get_peer_port.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_get_peer_port.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_read_request.3ossl b/openssl-install/share/man/man3/BIO_get_read_request.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_get_read_request.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_retry_BIO.3ossl b/openssl-install/share/man/man3/BIO_get_retry_BIO.3ossl deleted file mode 120000 index d31b1c24..00000000 --- a/openssl-install/share/man/man3/BIO_get_retry_BIO.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_should_retry.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_retry_reason.3ossl b/openssl-install/share/man/man3/BIO_get_retry_reason.3ossl deleted file mode 120000 index d31b1c24..00000000 --- a/openssl-install/share/man/man3/BIO_get_retry_reason.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_should_retry.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_rpoll_descriptor.3ossl b/openssl-install/share/man/man3/BIO_get_rpoll_descriptor.3ossl deleted file mode 100644 index 30d8edfd..00000000 --- a/openssl-install/share/man/man3/BIO_get_rpoll_descriptor.3ossl +++ /dev/null @@ -1,236 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_GET_RPOLL_DESCRIPTOR 3ossl" -.TH BIO_GET_RPOLL_DESCRIPTOR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_get_rpoll_descriptor, BIO_get_wpoll_descriptor \- obtain a structure which -can be used to determine when a BIO object can next be read or written -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct bio_poll_descriptor_st { -\& uint32_t type; -\& union { -\& int fd; -\& void *custom; -\& uintptr_t custom_ui; -\& } value; -\& } BIO_POLL_DESCRIPTOR; -\& -\& int BIO_get_rpoll_descriptor(BIO *b, BIO_POLL_DESCRIPTOR *desc); -\& int BIO_get_wpoll_descriptor(BIO *b, BIO_POLL_DESCRIPTOR *desc); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_get_rpoll_descriptor()\fR and \fBBIO_get_wpoll_descriptor()\fR, on success, fill -\&\fI*desc\fR with a poll descriptor. A poll descriptor is a tagged union structure -which represents some kind of \s-1OS\s0 or non-OS resource which can be used to -synchronise on I/O availability events. -.PP -\&\fBBIO_get_rpoll_descriptor()\fR outputs a descriptor which can be used to determine -when the \s-1BIO\s0 can (potentially) next be read, and \fBBIO_get_wpoll_descriptor()\fR -outputs a descriptor which can be used to determine when the \s-1BIO\s0 can -(potentially) next be written. -.PP -It is permissible for \fBBIO_get_rpoll_descriptor()\fR and \fBBIO_get_wpoll_descriptor()\fR -to output the same descriptor. -.PP -Poll descriptors can represent different kinds of information. A typical kind of -resource which might be represented by a poll descriptor is an \s-1OS\s0 file -descriptor which can be used with APIs such as \fBselect()\fR. -.PP -The kinds of poll descriptor defined by OpenSSL are: -.IP "\s-1BIO_POLL_DESCRIPTOR_TYPE_NONE\s0" 4 -.IX Item "BIO_POLL_DESCRIPTOR_TYPE_NONE" -Represents the absence of a valid poll descriptor. It may be used by -\&\fBBIO_get_rpoll_descriptor()\fR or \fBBIO_get_wpoll_descriptor()\fR to indicate that the -\&\s-1BIO\s0 is not pollable for readability or writeability respectively. -.Sp -For this type, no field within the \fIvalue\fR field of the \fB\s-1BIO_POLL_DESCRIPTOR\s0\fR -is valid. -.IP "\s-1BIO_POLL_DESCRIPTOR_TYPE_SOCK_FD\s0" 4 -.IX Item "BIO_POLL_DESCRIPTOR_TYPE_SOCK_FD" -The poll descriptor represents an \s-1OS\s0 socket resource. The field \fIvalue.fd\fR -in the \fB\s-1BIO_POLL_DESCRIPTOR\s0\fR is valid if it is not set to \-1. -.Sp -The resource is whatever kind of handle is used by a given \s-1OS\s0 to represent -sockets, which may vary by \s-1OS.\s0 For example, on Windows, the value is a \fB\s-1SOCKET\s0\fR -for use with the Winsock \s-1API.\s0 On POSIX-like platforms, it is a file descriptor. -.Sp -Where a poll descriptor of this type is output by \fBBIO_get_rpoll_descriptor()\fR, it -should be polled for readability to determine when the \s-1BIO\s0 might next be able to -successfully complete a \fBBIO_read()\fR operation; likewise, where a poll descriptor -of this type is output by \fBBIO_get_wpoll_descriptor()\fR, it should be polled for -writeability to determine when the \s-1BIO\s0 might next be able to successfully -complete a \fBBIO_write()\fR operation. -.IP "\s-1BIO_POLL_DESCRIPTOR_CUSTOM_START\s0" 4 -.IX Item "BIO_POLL_DESCRIPTOR_CUSTOM_START" -Type values beginning with this value (inclusive) are reserved for application -allocation for custom poll descriptor types. Any of the definitions in the union -field \fIvalue\fR can be used by the application arbitrarily as opaque values. -.PP -Because poll descriptors are a tagged union structure, they can represent -different kinds of information. New types of poll descriptor may be defined, -including by applications, according to their needs. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions \fBBIO_get_rpoll_descriptor()\fR and \fBBIO_get_wpoll_descriptor()\fR return 1 -on success and 0 on failure. -.PP -These functions are permitted to succeed and initialise \fI*desc\fR with a poll -descriptor of type \fB\s-1BIO_POLL_DESCRIPTOR_TYPE_NONE\s0\fR to indicate that the \s-1BIO\s0 is -not pollable for readability or writeability respectively. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_handle_events\fR\|(3), \fBSSL_get_event_timeout\fR\|(3), \fBSSL_get_rpoll_descriptor\fR\|(3), -\&\fBSSL_get_wpoll_descriptor\fR\|(3), \fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_get_rpoll_descriptor()\fR and \fBSSL_get_wpoll_descriptor()\fR functions were -added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_get_shutdown.3ossl b/openssl-install/share/man/man3/BIO_get_shutdown.3ossl deleted file mode 120000 index d0d51f6b..00000000 --- a/openssl-install/share/man/man3/BIO_get_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_sock_type.3ossl b/openssl-install/share/man/man3/BIO_get_sock_type.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_get_sock_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_ssl.3ossl b/openssl-install/share/man/man3/BIO_get_ssl.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_get_ssl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_wpoll_descriptor.3ossl b/openssl-install/share/man/man3/BIO_get_wpoll_descriptor.3ossl deleted file mode 120000 index caedce07..00000000 --- a/openssl-install/share/man/man3/BIO_get_wpoll_descriptor.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_rpoll_descriptor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_write_buf_size.3ossl b/openssl-install/share/man/man3/BIO_get_write_buf_size.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_get_write_buf_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_get_write_guarantee.3ossl b/openssl-install/share/man/man3/BIO_get_write_guarantee.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_get_write_guarantee.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_gets.3ossl b/openssl-install/share/man/man3/BIO_gets.3ossl deleted file mode 120000 index 688d3c98..00000000 --- a/openssl-install/share/man/man3/BIO_gets.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_hostserv_priorities.3ossl b/openssl-install/share/man/man3/BIO_hostserv_priorities.3ossl deleted file mode 120000 index 2c85270a..00000000 --- a/openssl-install/share/man/man3/BIO_hostserv_priorities.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_parse_hostserv.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_info_cb.3ossl b/openssl-install/share/man/man3/BIO_info_cb.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_info_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_int_ctrl.3ossl b/openssl-install/share/man/man3/BIO_int_ctrl.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_int_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_listen.3ossl b/openssl-install/share/man/man3/BIO_listen.3ossl deleted file mode 120000 index 10175c59..00000000 --- a/openssl-install/share/man/man3/BIO_listen.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_lookup.3ossl b/openssl-install/share/man/man3/BIO_lookup.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_lookup.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_lookup_ex.3ossl b/openssl-install/share/man/man3/BIO_lookup_ex.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_lookup_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_lookup_type.3ossl b/openssl-install/share/man/man3/BIO_lookup_type.3ossl deleted file mode 120000 index a69ada76..00000000 --- a/openssl-install/share/man/man3/BIO_lookup_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ADDRINFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_make_bio_pair.3ossl b/openssl-install/share/man/man3/BIO_make_bio_pair.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_make_bio_pair.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_free.3ossl b/openssl-install/share/man/man3/BIO_meth_free.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_callback_ctrl.3ossl b/openssl-install/share/man/man3/BIO_meth_get_callback_ctrl.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_callback_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_create.3ossl b/openssl-install/share/man/man3/BIO_meth_get_create.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_ctrl.3ossl b/openssl-install/share/man/man3/BIO_meth_get_ctrl.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_destroy.3ossl b/openssl-install/share/man/man3/BIO_meth_get_destroy.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_destroy.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_gets.3ossl b/openssl-install/share/man/man3/BIO_meth_get_gets.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_gets.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_puts.3ossl b/openssl-install/share/man/man3/BIO_meth_get_puts.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_puts.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_read.3ossl b/openssl-install/share/man/man3/BIO_meth_get_read.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_read.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_read_ex.3ossl b/openssl-install/share/man/man3/BIO_meth_get_read_ex.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_read_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_recvmmsg.3ossl b/openssl-install/share/man/man3/BIO_meth_get_recvmmsg.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_recvmmsg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_sendmmsg.3ossl b/openssl-install/share/man/man3/BIO_meth_get_sendmmsg.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_sendmmsg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_write.3ossl b/openssl-install/share/man/man3/BIO_meth_get_write.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_write.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_get_write_ex.3ossl b/openssl-install/share/man/man3/BIO_meth_get_write_ex.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_get_write_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_new.3ossl b/openssl-install/share/man/man3/BIO_meth_new.3ossl deleted file mode 100644 index b9a398e1..00000000 --- a/openssl-install/share/man/man3/BIO_meth_new.3ossl +++ /dev/null @@ -1,326 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_METH_NEW 3ossl" -.TH BIO_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_get_new_index, -BIO_meth_new, BIO_meth_free, BIO_meth_get_read_ex, BIO_meth_set_read_ex, -BIO_meth_get_write_ex, BIO_meth_set_write_ex, BIO_meth_get_write, -BIO_meth_set_write, BIO_meth_get_read, BIO_meth_set_read, BIO_meth_get_puts, -BIO_meth_set_puts, BIO_meth_get_gets, BIO_meth_set_gets, BIO_meth_get_ctrl, -BIO_meth_set_ctrl, BIO_meth_get_create, BIO_meth_set_create, -BIO_meth_get_destroy, BIO_meth_set_destroy, BIO_meth_get_callback_ctrl, -BIO_meth_set_callback_ctrl, BIO_meth_set_sendmmsg, BIO_meth_get_sendmmsg, -BIO_meth_set_recvmmsg, BIO_meth_get_recvmmsg \- Routines to build up BIO methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BIO_get_new_index(void); -\& -\& BIO_METHOD *BIO_meth_new(int type, const char *name); -\& -\& void BIO_meth_free(BIO_METHOD *biom); -\& -\& int (*BIO_meth_get_write_ex(const BIO_METHOD *biom))(BIO *, const char *, size_t, -\& size_t *); -\& int (*BIO_meth_get_write(const BIO_METHOD *biom))(BIO *, const char *, int); -\& int BIO_meth_set_write_ex(BIO_METHOD *biom, -\& int (*bwrite)(BIO *, const char *, size_t, size_t *)); -\& int BIO_meth_set_write(BIO_METHOD *biom, -\& int (*write)(BIO *, const char *, int)); -\& -\& int (*BIO_meth_get_read_ex(const BIO_METHOD *biom))(BIO *, char *, size_t, size_t *); -\& int (*BIO_meth_get_read(const BIO_METHOD *biom))(BIO *, char *, int); -\& int BIO_meth_set_read_ex(BIO_METHOD *biom, -\& int (*bread)(BIO *, char *, size_t, size_t *)); -\& int BIO_meth_set_read(BIO_METHOD *biom, int (*read)(BIO *, char *, int)); -\& -\& int (*BIO_meth_get_puts(const BIO_METHOD *biom))(BIO *, const char *); -\& int BIO_meth_set_puts(BIO_METHOD *biom, int (*puts)(BIO *, const char *)); -\& -\& int (*BIO_meth_get_gets(const BIO_METHOD *biom))(BIO *, char *, int); -\& int BIO_meth_set_gets(BIO_METHOD *biom, -\& int (*gets)(BIO *, char *, int)); -\& -\& long (*BIO_meth_get_ctrl(const BIO_METHOD *biom))(BIO *, int, long, void *); -\& int BIO_meth_set_ctrl(BIO_METHOD *biom, -\& long (*ctrl)(BIO *, int, long, void *)); -\& -\& int (*BIO_meth_get_create(const BIO_METHOD *bion))(BIO *); -\& int BIO_meth_set_create(BIO_METHOD *biom, int (*create)(BIO *)); -\& -\& int (*BIO_meth_get_destroy(const BIO_METHOD *biom))(BIO *); -\& int BIO_meth_set_destroy(BIO_METHOD *biom, int (*destroy)(BIO *)); -\& -\& long (*BIO_meth_get_callback_ctrl(const BIO_METHOD *biom))(BIO *, int, BIO_info_cb *); -\& int BIO_meth_set_callback_ctrl(BIO_METHOD *biom, -\& long (*callback_ctrl)(BIO *, int, BIO_info_cb *)); -\& -\& ossl_ssize_t (*BIO_meth_get_sendmmsg(const BIO_METHOD *biom))(BIO *, -\& BIO_MSG *, -\& size_t, -\& size_t, -\& uint64_t); -\& int BIO_meth_set_sendmmsg(BIO_METHOD *biom, -\& ossl_ssize_t (*f) (BIO *, BIO_MSG *, size_t, -\& size_t, uint64_t)); -\& -\& ossl_ssize_t (*BIO_meth_get_recvmmsg(const BIO_METHOD *biom))(BIO *, -\& BIO_MSG *, -\& size_t, -\& size_t, -\& uint64_t); -\& int BIO_meth_set_recvmmsg(BIO_METHOD *biom, -\& ossl_ssize_t (*f) (BIO *, BIO_MSG *, size_t, -\& size_t, uint64_t)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1BIO_METHOD\s0\fR type is a structure used for the implementation of new \s-1BIO\s0 -types. It provides a set of functions used by OpenSSL for the implementation -of the various \s-1BIO\s0 capabilities. See the \fBbio\fR\|(7) page for more information. -.PP -\&\fBBIO_meth_new()\fR creates a new \fB\s-1BIO_METHOD\s0\fR structure that contains a type -identifier \fItype\fR and a string that represents its \fBname\fR. -\&\fBtype\fR can be set to either \fB\s-1BIO_TYPE_NONE\s0\fR or via \fBBIO_get_new_index()\fR if -a unique type is required for searching (See \fBBIO_find_type\fR\|(3)) -.PP -Note that \fBBIO_get_new_index()\fR can only be used 127 times before it returns an -error. -.PP -The set of -standard OpenSSL provided \s-1BIO\s0 types is provided in \fI\fR. -Some examples include \fB\s-1BIO_TYPE_BUFFER\s0\fR and \fB\s-1BIO_TYPE_CIPHER\s0\fR. Filter BIOs -should have a type which have the \*(L"filter\*(R" bit set (\fB\s-1BIO_TYPE_FILTER\s0\fR). -Source/sink BIOs should have the \*(L"source/sink\*(R" bit set (\fB\s-1BIO_TYPE_SOURCE_SINK\s0\fR). -File descriptor based BIOs (e.g. socket, fd, connect, accept etc) should -additionally have the \*(L"descriptor\*(R" bit set (\fB\s-1BIO_TYPE_DESCRIPTOR\s0\fR). See the -\&\fBBIO_find_type\fR\|(3) page for more information. -.PP -\&\fBBIO_meth_free()\fR destroys a \fB\s-1BIO_METHOD\s0\fR structure and frees up any memory -associated with it. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBBIO_meth_get_write_ex()\fR and \fBBIO_meth_set_write_ex()\fR get and set the function -used for writing arbitrary length data to the \s-1BIO\s0 respectively. This function -will be called in response to the application calling \fBBIO_write_ex()\fR or -\&\fBBIO_write()\fR. The parameters for the function have the same meaning as for -\&\fBBIO_write_ex()\fR. Older code may call \fBBIO_meth_get_write()\fR and -\&\fBBIO_meth_set_write()\fR instead. Applications should not call both -\&\fBBIO_meth_set_write_ex()\fR and \fBBIO_meth_set_write()\fR or call \fBBIO_meth_get_write()\fR -when the function was set with \fBBIO_meth_set_write_ex()\fR. -.PP -\&\fBBIO_meth_get_read_ex()\fR and \fBBIO_meth_set_read_ex()\fR get and set the function used -for reading arbitrary length data from the \s-1BIO\s0 respectively. This function will -be called in response to the application calling \fBBIO_read_ex()\fR or \fBBIO_read()\fR. -The parameters for the function have the same meaning as for \fBBIO_read_ex()\fR. -Older code may call \fBBIO_meth_get_read()\fR and \fBBIO_meth_set_read()\fR instead. -Applications should not call both \fBBIO_meth_set_read_ex()\fR and \fBBIO_meth_set_read()\fR -or call \fBBIO_meth_get_read()\fR when the function was set with -\&\fBBIO_meth_set_read_ex()\fR. -.PP -\&\fBBIO_meth_get_puts()\fR and \fBBIO_meth_set_puts()\fR get and set the function used for -writing a \s-1NULL\s0 terminated string to the \s-1BIO\s0 respectively. This function will be -called in response to the application calling \fBBIO_puts()\fR. The parameters for -the function have the same meaning as for \fBBIO_puts()\fR. -.PP -\&\fBBIO_meth_get_gets()\fR and \fBBIO_meth_set_gets()\fR get and set the function typically -used for reading a line of data from the \s-1BIO\s0 respectively (see the \fBBIO_gets\fR\|(3) -page for more information). This function will be called in response to the -application calling \fBBIO_gets()\fR. The parameters for the function have the same -meaning as for \fBBIO_gets()\fR. -.PP -\&\fBBIO_meth_get_ctrl()\fR and \fBBIO_meth_set_ctrl()\fR get and set the function used for -processing ctrl messages in the \s-1BIO\s0 respectively. See the \fBBIO_ctrl\fR\|(3) page for -more information. This function will be called in response to the application -calling \fBBIO_ctrl()\fR. The parameters for the function have the same meaning as for -\&\fBBIO_ctrl()\fR. -.PP -\&\fBBIO_meth_get_create()\fR and \fBBIO_meth_set_create()\fR get and set the function used -for creating a new instance of the \s-1BIO\s0 respectively. This function will be -called in response to the application calling \fBBIO_new()\fR and passing -in a pointer to the current \s-1BIO_METHOD.\s0 The \fBBIO_new()\fR function will allocate the -memory for the new \s-1BIO,\s0 and a pointer to this newly allocated structure will -be passed as a parameter to the function. If a create function is set, -\&\fBBIO_new()\fR will not mark the \s-1BIO\s0 as initialised on allocation. -\&\fBBIO_set_init\fR\|(3) must then be called either by the create function, or later, -by a \s-1BIO\s0 ctrl function, once \s-1BIO\s0 initialisation is complete. -.PP -\&\fBBIO_meth_get_destroy()\fR and \fBBIO_meth_set_destroy()\fR get and set the function used -for destroying an instance of a \s-1BIO\s0 respectively. This function will be -called in response to the application calling \fBBIO_free()\fR. A pointer to the \s-1BIO\s0 -to be destroyed is passed as a parameter. The destroy function should be used -for \s-1BIO\s0 specific clean up. The memory for the \s-1BIO\s0 itself should not be freed by -this function. -.PP -\&\fBBIO_meth_get_callback_ctrl()\fR and \fBBIO_meth_set_callback_ctrl()\fR get and set the -function used for processing callback ctrl messages in the \s-1BIO\s0 respectively. See -the \fBBIO_callback_ctrl\fR\|(3) page for more information. This function will be called -in response to the application calling \fBBIO_callback_ctrl()\fR. The parameters for -the function have the same meaning as for \fBBIO_callback_ctrl()\fR. -.PP -\&\fBBIO_meth_get_sendmmsg()\fR, \fBBIO_meth_set_sendmmsg()\fR, \fBBIO_meth_get_recvmmsg()\fR and -\&\fBBIO_meth_set_recvmmsg()\fR get and set the functions used for handling -\&\fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR calls respectively. See \fBBIO_sendmmsg\fR\|(3) for -more information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_get_new_index()\fR returns the new \s-1BIO\s0 type value or \-1 if an error occurred. -.PP -BIO_meth_new(int type, const char *name) returns a valid \fB\s-1BIO_METHOD\s0\fR or \s-1NULL\s0 -if an error occurred. -.PP -The \fBBIO_meth_set\fR functions return 1 on success or 0 on error. -.PP -The \fBBIO_meth_get\fR functions return the corresponding function pointers. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7), \fBBIO_find_type\fR\|(3), \fBBIO_ctrl\fR\|(3), \fBBIO_read_ex\fR\|(3), \fBBIO_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_meth_set_callback_ctrl.3ossl b/openssl-install/share/man/man3/BIO_meth_set_callback_ctrl.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_callback_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_create.3ossl b/openssl-install/share/man/man3/BIO_meth_set_create.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_ctrl.3ossl b/openssl-install/share/man/man3/BIO_meth_set_ctrl.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_destroy.3ossl b/openssl-install/share/man/man3/BIO_meth_set_destroy.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_destroy.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_gets.3ossl b/openssl-install/share/man/man3/BIO_meth_set_gets.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_gets.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_puts.3ossl b/openssl-install/share/man/man3/BIO_meth_set_puts.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_puts.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_read.3ossl b/openssl-install/share/man/man3/BIO_meth_set_read.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_read.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_read_ex.3ossl b/openssl-install/share/man/man3/BIO_meth_set_read_ex.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_read_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_recvmmsg.3ossl b/openssl-install/share/man/man3/BIO_meth_set_recvmmsg.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_recvmmsg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_sendmmsg.3ossl b/openssl-install/share/man/man3/BIO_meth_set_sendmmsg.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_sendmmsg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_write.3ossl b/openssl-install/share/man/man3/BIO_meth_set_write.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_write.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_meth_set_write_ex.3ossl b/openssl-install/share/man/man3/BIO_meth_set_write_ex.3ossl deleted file mode 120000 index a4c29b4e..00000000 --- a/openssl-install/share/man/man3/BIO_meth_set_write_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_method_type.3ossl b/openssl-install/share/man/man3/BIO_method_type.3ossl deleted file mode 120000 index 5f983bf4..00000000 --- a/openssl-install/share/man/man3/BIO_method_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_find_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new.3ossl b/openssl-install/share/man/man3/BIO_new.3ossl deleted file mode 100644 index c7c7f3dd..00000000 --- a/openssl-install/share/man/man3/BIO_new.3ossl +++ /dev/null @@ -1,211 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_NEW 3ossl" -.TH BIO_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_new_ex, BIO_new, BIO_up_ref, BIO_free, BIO_vfree, BIO_free_all -\&\- BIO allocation and freeing functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIO *BIO_new_ex(OSSL_LIB_CTX *libctx, const BIO_METHOD *type); -\& BIO *BIO_new(const BIO_METHOD *type); -\& int BIO_up_ref(BIO *a); -\& int BIO_free(BIO *a); -\& void BIO_vfree(BIO *a); -\& void BIO_free_all(BIO *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBBIO_new_ex()\fR function returns a new \s-1BIO\s0 using method \fBtype\fR associated with -the library context \fIlibctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)). The library context may be -\&\s-1NULL\s0 to indicate the default library context. -.PP -The \fBBIO_new()\fR is the same as \fBBIO_new_ex()\fR except the default library context is -always used. -.PP -\&\fBBIO_up_ref()\fR increments the reference count associated with the \s-1BIO\s0 object. -.PP -\&\fBBIO_free()\fR frees up a single \s-1BIO,\s0 \fBBIO_vfree()\fR also frees up a single \s-1BIO\s0 -but it does not return a value. -If \fBa\fR is \s-1NULL\s0 nothing is done. -Calling \fBBIO_free()\fR may also have some effect -on the underlying I/O structure, for example it may close the file being -referred to under certain circumstances. For more details see the individual -\&\s-1BIO_METHOD\s0 descriptions. -.PP -\&\fBBIO_free_all()\fR frees up an entire \s-1BIO\s0 chain, it does not halt if an error -occurs freeing up an individual \s-1BIO\s0 in the chain. -If \fBa\fR is \s-1NULL\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_new_ex()\fR and \fBBIO_new()\fR return a newly created \s-1BIO\s0 or \s-1NULL\s0 if the call fails. -.PP -\&\fBBIO_up_ref()\fR and \fBBIO_free()\fR return 1 for success and 0 for failure. -.PP -\&\fBBIO_free_all()\fR and \fBBIO_vfree()\fR do not return values. -.SH "NOTES" -.IX Header "NOTES" -If \fBBIO_free()\fR is called on a \s-1BIO\s0 chain it will only free one \s-1BIO\s0 resulting -in a memory leak. -.PP -Calling \fBBIO_free_all()\fR on a single \s-1BIO\s0 has the same effect as calling \fBBIO_free()\fR -on it other than the discarded return value. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_set()\fR was removed in OpenSSL 1.1.0 as \s-1BIO\s0 type is now opaque. -.PP -\&\fBBIO_new_ex()\fR was added in OpenSSL 3.0. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a memory \s-1BIO:\s0 -.PP -.Vb 1 -\& BIO *mem = BIO_new(BIO_s_mem()); -.Ve -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_new_CMS.3ossl b/openssl-install/share/man/man3/BIO_new_CMS.3ossl deleted file mode 100644 index 0492fb74..00000000 --- a/openssl-install/share/man/man3/BIO_new_CMS.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_NEW_CMS 3ossl" -.TH BIO_NEW_CMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_new_CMS \- CMS streaming filter BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIO *BIO_new_CMS(BIO *out, CMS_ContentInfo *cms); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_new_CMS()\fR returns a streaming filter \s-1BIO\s0 chain based on \fBcms\fR. The output -of the filter is written to \fBout\fR. Any data written to the chain is -automatically translated to a \s-1BER\s0 format \s-1CMS\s0 structure of the appropriate type. -.SH "NOTES" -.IX Header "NOTES" -The chain returned by this function behaves like a standard filter \s-1BIO.\s0 It -supports non blocking I/O. Content is processed and streamed on the fly and not -all held in memory at once: so it is possible to encode very large structures. -After all content has been written through the chain \fBBIO_flush()\fR must be called -to finalise the structure. -.PP -The \fB\s-1CMS_STREAM\s0\fR flag must be included in the corresponding \fBflags\fR -parameter of the \fBcms\fR creation function. -.PP -If an application wishes to write additional data to \fBout\fR BIOs should be -removed from the chain using \fBBIO_pop()\fR and freed with \fBBIO_free()\fR until \fBout\fR -is reached. If no additional data needs to be written \fBBIO_free_all()\fR can be -called to free up the whole chain. -.PP -Any content written through the filter is used verbatim: no canonical -translation is performed. -.PP -It is possible to chain multiple BIOs to, for example, create a triple wrapped -signed, enveloped, signed structure. In this case it is the applications -responsibility to set the inner content type of any outer CMS_ContentInfo -structures. -.PP -Large numbers of small writes through the chain should be avoided as this will -produce an output consisting of lots of \s-1OCTET STRING\s0 structures. Prepending -a \fBBIO_f_buffer()\fR buffering \s-1BIO\s0 will prevent this. -.SH "BUGS" -.IX Header "BUGS" -There is currently no corresponding inverse \s-1BIO:\s0 i.e. one which can decode -a \s-1CMS\s0 structure on the fly. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_new_CMS()\fR returns a \s-1BIO\s0 chain when successful or \s-1NULL\s0 if an error -occurred. The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3), -\&\fBCMS_encrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBIO_new_CMS()\fR function was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_new_accept.3ossl b/openssl-install/share/man/man3/BIO_new_accept.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_new_accept.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_bio_dgram_pair.3ossl b/openssl-install/share/man/man3/BIO_new_bio_dgram_pair.3ossl deleted file mode 120000 index 18214fef..00000000 --- a/openssl-install/share/man/man3/BIO_new_bio_dgram_pair.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_dgram_pair.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_bio_pair.3ossl b/openssl-install/share/man/man3/BIO_new_bio_pair.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_new_bio_pair.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_buffer_ssl_connect.3ossl b/openssl-install/share/man/man3/BIO_new_buffer_ssl_connect.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_new_buffer_ssl_connect.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_connect.3ossl b/openssl-install/share/man/man3/BIO_new_connect.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_new_connect.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_dgram.3ossl b/openssl-install/share/man/man3/BIO_new_dgram.3ossl deleted file mode 120000 index c95fac58..00000000 --- a/openssl-install/share/man/man3/BIO_new_dgram.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_datagram.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_ex.3ossl b/openssl-install/share/man/man3/BIO_new_ex.3ossl deleted file mode 120000 index 9126d49b..00000000 --- a/openssl-install/share/man/man3/BIO_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_fd.3ossl b/openssl-install/share/man/man3/BIO_new_fd.3ossl deleted file mode 120000 index 91a83843..00000000 --- a/openssl-install/share/man/man3/BIO_new_fd.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_fd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_file.3ossl b/openssl-install/share/man/man3/BIO_new_file.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_new_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_fp.3ossl b/openssl-install/share/man/man3/BIO_new_fp.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_new_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_from_core_bio.3ossl b/openssl-install/share/man/man3/BIO_new_from_core_bio.3ossl deleted file mode 120000 index e07d279b..00000000 --- a/openssl-install/share/man/man3/BIO_new_from_core_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_core.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_mem_buf.3ossl b/openssl-install/share/man/man3/BIO_new_mem_buf.3ossl deleted file mode 120000 index e9853704..00000000 --- a/openssl-install/share/man/man3/BIO_new_mem_buf.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_mem.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_socket.3ossl b/openssl-install/share/man/man3/BIO_new_socket.3ossl deleted file mode 120000 index 473f5f6a..00000000 --- a/openssl-install/share/man/man3/BIO_new_socket.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_socket.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_ssl.3ossl b/openssl-install/share/man/man3/BIO_new_ssl.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_new_ssl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_new_ssl_connect.3ossl b/openssl-install/share/man/man3/BIO_new_ssl_connect.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_new_ssl_connect.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_next.3ossl b/openssl-install/share/man/man3/BIO_next.3ossl deleted file mode 120000 index 5f983bf4..00000000 --- a/openssl-install/share/man/man3/BIO_next.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_find_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_parse_hostserv.3ossl b/openssl-install/share/man/man3/BIO_parse_hostserv.3ossl deleted file mode 100644 index d7df4416..00000000 --- a/openssl-install/share/man/man3/BIO_parse_hostserv.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_PARSE_HOSTSERV 3ossl" -.TH BIO_PARSE_HOSTSERV 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_hostserv_priorities, -BIO_parse_hostserv -\&\- utility routines to parse a standard host and service string -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& enum BIO_hostserv_priorities { -\& BIO_PARSE_PRIO_HOST, BIO_PARSE_PRIO_SERV -\& }; -\& int BIO_parse_hostserv(const char *hostserv, char **host, char **service, -\& enum BIO_hostserv_priorities hostserv_prio); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_parse_hostserv()\fR will parse the information given in \fBhostserv\fR, -create strings with the hostname and service name and give those -back via \fBhost\fR and \fBservice\fR. Those will need to be freed after -they are used. \fBhostserv_prio\fR helps determine if \fBhostserv\fR shall -be interpreted primarily as a hostname or a service name in ambiguous -cases. -.PP -The syntax the \fBBIO_parse_hostserv()\fR recognises is: -.PP -.Vb 7 -\& host + \*(Aq:\*(Aq + service -\& host + \*(Aq:\*(Aq + \*(Aq*\*(Aq -\& host + \*(Aq:\*(Aq -\& \*(Aq:\*(Aq + service -\& \*(Aq*\*(Aq + \*(Aq:\*(Aq + service -\& host -\& service -.Ve -.PP -The host part can be a name or an \s-1IP\s0 address. If it's a IPv6 -address, it \s-1MUST\s0 be enclosed in brackets, such as '[::1]'. -.PP -The service part can be a service name or its port number. A service name -will be mapped to a port number using the system function \fBgetservbyname()\fR. -.PP -The returned values will depend on the given \fBhostserv\fR string -and \fBhostserv_prio\fR, as follows: -.PP -.Vb 5 -\& host + \*(Aq:\*(Aq + service => *host = "host", *service = "service" -\& host + \*(Aq:\*(Aq + \*(Aq*\*(Aq => *host = "host", *service = NULL -\& host + \*(Aq:\*(Aq => *host = "host", *service = NULL -\& \*(Aq:\*(Aq + service => *host = NULL, *service = "service" -\& \*(Aq*\*(Aq + \*(Aq:\*(Aq + service => *host = NULL, *service = "service" -\& -\& in case no \*(Aq:\*(Aq is present in the string, the result depends on -\& hostserv_prio, as follows: -\& -\& when hostserv_prio == BIO_PARSE_PRIO_HOST -\& host => *host = "host", *service untouched -\& -\& when hostserv_prio == BIO_PARSE_PRIO_SERV -\& service => *host untouched, *service = "service" -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_parse_hostserv()\fR returns 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBBIO_ADDRINFO\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_pending.3ossl b/openssl-install/share/man/man3/BIO_pending.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_pending.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_pop.3ossl b/openssl-install/share/man/man3/BIO_pop.3ossl deleted file mode 120000 index e6369f56..00000000 --- a/openssl-install/share/man/man3/BIO_pop.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_push.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_printf.3ossl b/openssl-install/share/man/man3/BIO_printf.3ossl deleted file mode 100644 index 4dce9bdf..00000000 --- a/openssl-install/share/man/man3/BIO_printf.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_PRINTF 3ossl" -.TH BIO_PRINTF 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_printf, BIO_vprintf, BIO_snprintf, BIO_vsnprintf -\&\- formatted output to a BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BIO_printf(BIO *bio, const char *format, ...); -\& int BIO_vprintf(BIO *bio, const char *format, va_list args); -\& -\& int BIO_snprintf(char *buf, size_t n, const char *format, ...); -\& int BIO_vsnprintf(char *buf, size_t n, const char *format, va_list args); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_printf()\fR is similar to the standard C \fBprintf()\fR function, except that -the output is sent to the specified \s-1BIO,\s0 \fIbio\fR, rather than standard -output. All common format specifiers are supported. -.PP -\&\fBBIO_vprintf()\fR is similar to the \fBvprintf()\fR function found on many platforms, -the output is sent to the specified \s-1BIO,\s0 \fIbio\fR, rather than standard -output. All common format specifiers are supported. The argument -list \fIargs\fR is a stdarg argument list. -.PP -\&\fBBIO_snprintf()\fR is for platforms that do not have the common \fBsnprintf()\fR -function. It is like \fBsprintf()\fR except that the size parameter, \fIn\fR, -specifies the size of the output buffer. -.PP -\&\fBBIO_vsnprintf()\fR is to \fBBIO_snprintf()\fR as \fBBIO_vprintf()\fR is to \fBBIO_printf()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return the number of bytes written, or \-1 on error. -For \fBBIO_snprintf()\fR and \fBBIO_vsnprintf()\fR this includes when the output -buffer is too small. -.SH "NOTES" -.IX Header "NOTES" -Except when \fIn\fR is 0, both \fBBIO_snprintf()\fR and \fBBIO_vsnprintf()\fR always -terminate their output with \f(CW\*(Aq\e0\*(Aq\fR. This includes cases where \-1 is -returned, such as when there is insufficient space to output the whole -string. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_ptr_ctrl.3ossl b/openssl-install/share/man/man3/BIO_ptr_ctrl.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_ptr_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_push.3ossl b/openssl-install/share/man/man3/BIO_push.3ossl deleted file mode 100644 index 27c1d8c8..00000000 --- a/openssl-install/share/man/man3/BIO_push.3ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_PUSH 3ossl" -.TH BIO_PUSH 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_push, BIO_pop, BIO_set_next \- add and remove BIOs from a chain -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIO *BIO_push(BIO *b, BIO *next); -\& BIO *BIO_pop(BIO *b); -\& void BIO_set_next(BIO *b, BIO *next); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_push()\fR pushes \fIb\fR on \fInext\fR. -If \fIb\fR is \s-1NULL\s0 the function does nothing and returns \fInext\fR. -Otherwise it prepends \fIb\fR, which may be a single \s-1BIO\s0 or a chain of BIOs, -to \fInext\fR (unless \fInext\fR is \s-1NULL\s0). -It then makes a control call on \fIb\fR and returns \fIb\fR. -.PP -\&\fBBIO_pop()\fR removes the \s-1BIO\s0 \fIb\fR from any chain is is part of. -If \fIb\fR is \s-1NULL\s0 the function does nothing and returns \s-1NULL.\s0 -Otherwise it makes a control call on \fIb\fR and -returns the next \s-1BIO\s0 in the chain, or \s-1NULL\s0 if there is no next \s-1BIO.\s0 -The removed \s-1BIO\s0 becomes a single \s-1BIO\s0 with no association with -the original chain, it can thus be freed or be made part of a different chain. -.PP -\&\fBBIO_set_next()\fR replaces the existing next \s-1BIO\s0 in a chain with the \s-1BIO\s0 pointed to -by \fInext\fR. The new chain may include some of the same BIOs from the old chain -or it may be completely different. -.SH "NOTES" -.IX Header "NOTES" -The names of these functions are perhaps a little misleading. \fBBIO_push()\fR -joins two \s-1BIO\s0 chains whereas \fBBIO_pop()\fR deletes a single \s-1BIO\s0 from a chain, -the deleted \s-1BIO\s0 does not need to be at the end of a chain. -.PP -The process of calling \fBBIO_push()\fR and \fBBIO_pop()\fR on a \s-1BIO\s0 may have additional -consequences (a control call is made to the affected BIOs). -Any effects will be noted in the descriptions of individual BIOs. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_push()\fR returns the head of the chain, -which usually is \fIb\fR, or \fInext\fR if \fIb\fR is \s-1NULL.\s0 -.PP -\&\fBBIO_pop()\fR returns the next \s-1BIO\s0 in the chain, -or \s-1NULL\s0 if there is no next \s-1BIO.\s0 -.SH "EXAMPLES" -.IX Header "EXAMPLES" -For these examples suppose \fImd1\fR and \fImd2\fR are digest BIOs, -\&\fIb64\fR is a base64 \s-1BIO\s0 and \fIf\fR is a file \s-1BIO.\s0 -.PP -If the call: -.PP -.Vb 1 -\& BIO_push(b64, f); -.Ve -.PP -is made then the new chain will be \fIb64\-f\fR. After making the calls -.PP -.Vb 2 -\& BIO_push(md2, b64); -\& BIO_push(md1, md2); -.Ve -.PP -the new chain is \fImd1\-md2\-b64\-f\fR. Data written to \fImd1\fR will be digested -by \fImd1\fR and \fImd2\fR, base64 encoded, and finally written to \fIf\fR. -.PP -It should be noted that reading causes data to pass in the reverse -direction, that is data is read from \fIf\fR, base64 decoded, -and digested by \fImd2\fR and then \fImd1\fR. -.PP -The call: -.PP -.Vb 1 -\& BIO_pop(md2); -.Ve -.PP -will return \fIb64\fR and the new chain will be \fImd1\-b64\-f\fR. -Data can be written to and read from \fImd1\fR as before, -except that \fImd2\fR will no more be applied. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBIO_set_next()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_puts.3ossl b/openssl-install/share/man/man3/BIO_puts.3ossl deleted file mode 120000 index 688d3c98..00000000 --- a/openssl-install/share/man/man3/BIO_puts.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_read.3ossl b/openssl-install/share/man/man3/BIO_read.3ossl deleted file mode 100644 index 4f452723..00000000 --- a/openssl-install/share/man/man3/BIO_read.3ossl +++ /dev/null @@ -1,259 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_READ 3ossl" -.TH BIO_READ 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_read_ex, BIO_write_ex, BIO_read, BIO_write, -BIO_gets, BIO_get_line, BIO_puts -\&\- BIO I/O functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BIO_read_ex(BIO *b, void *data, size_t dlen, size_t *readbytes); -\& int BIO_write_ex(BIO *b, const void *data, size_t dlen, size_t *written); -\& -\& int BIO_read(BIO *b, void *data, int dlen); -\& int BIO_gets(BIO *b, char *buf, int size); -\& int BIO_get_line(BIO *b, char *buf, int size); -\& int BIO_write(BIO *b, const void *data, int dlen); -\& int BIO_puts(BIO *b, const char *buf); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_read_ex()\fR attempts to read \fIdlen\fR bytes from \s-1BIO\s0 \fIb\fR and places the data -in \fIdata\fR. If any bytes were successfully read then the number of bytes read is -stored in \fI*readbytes\fR. -.PP -\&\fBBIO_write_ex()\fR attempts to write \fIdlen\fR bytes from \fIdata\fR to \s-1BIO\s0 \fIb\fR. -If successful then the number of bytes written is stored in \fI*written\fR -unless \fIwritten\fR is \s-1NULL.\s0 -.PP -\&\fBBIO_read()\fR attempts to read \fIlen\fR bytes from \s-1BIO\s0 \fIb\fR and places -the data in \fIbuf\fR. -.PP -\&\fBBIO_gets()\fR performs the BIOs \*(L"gets\*(R" operation and places the data -in \fIbuf\fR. Usually this operation will attempt to read a line of data -from the \s-1BIO\s0 of maximum length \fIsize\-1\fR. There are exceptions to this, -however; for example, \fBBIO_gets()\fR on a digest \s-1BIO\s0 will calculate and -return the digest and other BIOs may not support \fBBIO_gets()\fR at all. -The returned string is always NUL-terminated and the '\en' is preserved -if present in the input data. -On binary input there may be \s-1NUL\s0 characters within the string; -in this case the return value (if nonnegative) may give an incorrect length. -.PP -\&\fBBIO_get_line()\fR attempts to read from \s-1BIO\s0 \fIb\fR a line of data up to the next '\en' -or the maximum length \fIsize\-1\fR is reached and places the data in \fIbuf\fR. -The returned string is always NUL-terminated and the '\en' is preserved -if present in the input data. -On binary input there may be \s-1NUL\s0 characters within the string; -in this case the return value (if nonnegative) gives the actual length read. -For implementing this, unfortunately the data needs to be read byte-by-byte. -.PP -\&\fBBIO_write()\fR attempts to write \fIlen\fR bytes from \fIbuf\fR to \s-1BIO\s0 \fIb\fR. -.PP -\&\fBBIO_puts()\fR attempts to write a NUL-terminated string \fIbuf\fR to \s-1BIO\s0 \fIb\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_read_ex()\fR returns 1 if data was successfully read, and 0 otherwise. -.PP -\&\fBBIO_write_ex()\fR returns 1 if no error was encountered writing data, 0 otherwise. -Requesting to write 0 bytes is not considered an error. -.PP -\&\fBBIO_write()\fR returns \-2 if the \*(L"write\*(R" operation is not implemented by the \s-1BIO\s0 -or \-1 on other errors. -Otherwise it returns the number of bytes written. -This may be 0 if the \s-1BIO\s0 \fIb\fR is \s-1NULL\s0 or \fIdlen <= 0\fR. -.PP -\&\fBBIO_gets()\fR returns \-2 if the \*(L"gets\*(R" operation is not implemented by the \s-1BIO\s0 -or \-1 on other errors. -Otherwise it typically returns the amount of data read, -but depending on the implementation it may return only the length up to -the first \s-1NUL\s0 character contained in the data read. -In any case the trailing \s-1NUL\s0 that is added after the data read -is not included in the length returned. -.PP -All other functions return either the amount of data successfully read or -written (if the return value is positive) or that no data was successfully -read or written if the result is 0 or \-1. If the return value is \-2 then -the operation is not implemented in the specific \s-1BIO\s0 type. -.SH "NOTES" -.IX Header "NOTES" -A 0 or \-1 return is not necessarily an indication of an error. In -particular when the source/sink is nonblocking or of a certain type -it may merely be an indication that no data is currently available and that -the application should retry the operation later. -.PP -One technique sometimes used with blocking sockets is to use a system call -(such as \fBselect()\fR, \fBpoll()\fR or equivalent) to determine when data is available -and then call \fBread()\fR to read the data. The equivalent with BIOs (that is call -\&\fBselect()\fR on the underlying I/O structure and then call \fBBIO_read()\fR to -read the data) should \fBnot\fR be used because a single call to \fBBIO_read()\fR -can cause several reads (and writes in the case of \s-1SSL\s0 BIOs) on the underlying -I/O structure and may block as a result. Instead \fBselect()\fR (or equivalent) -should be combined with non blocking I/O so successive reads will request -a retry instead of blocking. -.PP -See \fBBIO_should_retry\fR\|(3) for details of how to -determine the cause of a retry and other I/O issues. -.PP -If the \*(L"gets\*(R" method is not supported by a \s-1BIO\s0 then \fBBIO_get_line()\fR can be used. -It is also possible to make \fBBIO_gets()\fR usable even if the \*(L"gets\*(R" method is not -supported by adding a buffering \s-1BIO\s0 \fBBIO_f_buffer\fR\|(3) to the chain. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_should_retry\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_gets()\fR on 1.1.0 and older when called on \fBBIO_fd()\fR based \s-1BIO\s0 did not -keep the '\en' at the end of the line in the buffer. -.PP -\&\fBBIO_get_line()\fR was added in OpenSSL 3.0. -.PP -\&\fBBIO_write_ex()\fR returns 1 if the size of the data to write is 0 and the -\&\fIwritten\fR parameter of the function can be \s-1NULL\s0 since OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_read_ex.3ossl b/openssl-install/share/man/man3/BIO_read_ex.3ossl deleted file mode 120000 index 688d3c98..00000000 --- a/openssl-install/share/man/man3/BIO_read_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_read_filename.3ossl b/openssl-install/share/man/man3/BIO_read_filename.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_read_filename.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_recvmmsg.3ossl b/openssl-install/share/man/man3/BIO_recvmmsg.3ossl deleted file mode 120000 index 28a49405..00000000 --- a/openssl-install/share/man/man3/BIO_recvmmsg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_sendmmsg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_reset.3ossl b/openssl-install/share/man/man3/BIO_reset.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_reset.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_retry_type.3ossl b/openssl-install/share/man/man3/BIO_retry_type.3ossl deleted file mode 120000 index d31b1c24..00000000 --- a/openssl-install/share/man/man3/BIO_retry_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_should_retry.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_rw_filename.3ossl b/openssl-install/share/man/man3/BIO_rw_filename.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_rw_filename.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_s_accept.3ossl b/openssl-install/share/man/man3/BIO_s_accept.3ossl deleted file mode 100644 index e02c407e..00000000 --- a/openssl-install/share/man/man3/BIO_s_accept.3ossl +++ /dev/null @@ -1,388 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_ACCEPT 3ossl" -.TH BIO_S_ACCEPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_accept, BIO_set_accept_name, BIO_set_accept_port, BIO_get_accept_name, -BIO_get_accept_port, BIO_new_accept, BIO_set_nbio_accept, BIO_set_tfo_accept, BIO_set_accept_bios, -BIO_get_peer_name, BIO_get_peer_port, -BIO_get_accept_ip_family, BIO_set_accept_ip_family, -BIO_set_bind_mode, BIO_get_bind_mode, BIO_do_accept \- accept BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_accept(void); -\& -\& long BIO_set_accept_name(BIO *b, char *name); -\& char *BIO_get_accept_name(BIO *b); -\& -\& long BIO_set_accept_port(BIO *b, char *port); -\& char *BIO_get_accept_port(BIO *b); -\& -\& BIO *BIO_new_accept(char *host_port); -\& -\& long BIO_set_nbio_accept(BIO *b, int n); -\& long BIO_set_tfo_accept(BIO *b, int n); -\& long BIO_set_accept_bios(BIO *b, char *bio); -\& -\& char *BIO_get_peer_name(BIO *b); -\& char *BIO_get_peer_port(BIO *b); -\& long BIO_get_accept_ip_family(BIO *b); -\& long BIO_set_accept_ip_family(BIO *b, long family); -\& -\& long BIO_set_bind_mode(BIO *b, long mode); -\& long BIO_get_bind_mode(BIO *b); -\& -\& int BIO_do_accept(BIO *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_accept()\fR returns the accept \s-1BIO\s0 method. This is a wrapper -round the platform's \s-1TCP/IP\s0 socket accept routines. -.PP -Using accept BIOs, \s-1TCP/IP\s0 connections can be accepted and data -transferred using only \s-1BIO\s0 routines. In this way any platform -specific operations are hidden by the \s-1BIO\s0 abstraction. -.PP -Read and write operations on an accept \s-1BIO\s0 will perform I/O -on the underlying connection. If no connection is established -and the port (see below) is set up properly then the \s-1BIO\s0 -waits for an incoming connection. -.PP -Accept BIOs support \fBBIO_puts()\fR but not \fBBIO_gets()\fR. -.PP -If the close flag is set on an accept \s-1BIO\s0 then any active -connection on that chain is shutdown and the socket closed when -the \s-1BIO\s0 is freed. -.PP -Calling \fBBIO_reset()\fR on an accept \s-1BIO\s0 will close any active -connection and reset the \s-1BIO\s0 into a state where it awaits another -incoming connection. -.PP -\&\fBBIO_get_fd()\fR and \fBBIO_set_fd()\fR can be called to retrieve or set -the accept socket. See \fBBIO_s_fd\fR\|(3) -.PP -\&\fBBIO_set_accept_name()\fR uses the string \fBname\fR to set the accept -name. The name is represented as a string of the form \*(L"host:port\*(R", -where \*(L"host\*(R" is the interface to use and \*(L"port\*(R" is the port. -The host can be \*(L"*\*(R" or empty which is interpreted as meaning -any interface. If the host is an IPv6 address, it has to be -enclosed in brackets, for example \*(L"[::1]:https\*(R". \*(L"port\*(R" has the -same syntax as the port specified in \fBBIO_set_conn_port()\fR for -connect BIOs, that is it can be a numerical port string or a -string to lookup using \fBgetservbyname()\fR and a string table. -.PP -\&\fBBIO_set_accept_port()\fR uses the string \fBport\fR to set the accept -port of \s-1BIO\s0 \fIb\fR. \*(L"port\*(R" has the same syntax as the port specified in -\&\fBBIO_set_conn_port()\fR for connect BIOs, that is it can be a numerical -port string or a string to lookup using \fBgetservbyname()\fR and a string -table. -If the given port is \f(CW0\fR then a random available port is chosen. -It may be queried using \fBBIO_sock_info()\fR and \fBBIO_ADDR_service_string\fR\|(3). -.PP -\&\fBBIO_new_accept()\fR combines \fBBIO_new()\fR and \fBBIO_set_accept_name()\fR into -a single call: that is it creates a new accept \s-1BIO\s0 with port -\&\fBhost_port\fR. -.PP -\&\fBBIO_set_nbio_accept()\fR sets the accept socket to blocking mode -(the default) if \fBn\fR is 0 or non blocking mode if \fBn\fR is 1. -.PP -\&\fBBIO_set_tfo_accept()\fR enables \s-1TCP\s0 Fast Open on the accept socket -if \fBn\fR is 1 or disables \s-1TCP\s0 Fast Open if \fBn\fR is 0 (the default). -Setting the value to 1 is equivalent to setting \fB\s-1BIO_SOCK_TFO\s0\fR -in \fBBIO_set_bind_mode()\fR. -.PP -\&\fBBIO_set_accept_bios()\fR can be used to set a chain of BIOs which -will be duplicated and prepended to the chain when an incoming -connection is received. This is useful if, for example, a -buffering or \s-1SSL BIO\s0 is required for each connection. The -chain of BIOs must not be freed after this call, they will -be automatically freed when the accept \s-1BIO\s0 is freed. -.PP -\&\fBBIO_get_accept_ip_family()\fR returns the \s-1IP\s0 family accepted by the \s-1BIO\s0 \fIb\fR, -which may be \fB\s-1BIO_FAMILY_IPV4\s0\fR, \fB\s-1BIO_FAMILY_IPV6\s0\fR, or \fB\s-1BIO_FAMILY_IPANY\s0\fR. -.PP -\&\fBBIO_set_accept_ip_family()\fR sets the \s-1IP\s0 family \fIfamily\fR accepted by \s-1BIO\s0 \fIb\fR. -The default is \fB\s-1BIO_FAMILY_IPANY\s0\fR. -.PP -\&\fBBIO_set_bind_mode()\fR and \fBBIO_get_bind_mode()\fR set and retrieve -the current bind mode. If \fB\s-1BIO_BIND_NORMAL\s0\fR (the default) is set -then another socket cannot be bound to the same port. If -\&\fB\s-1BIO_BIND_REUSEADDR\s0\fR is set then other sockets can bind to the -same port. If \fB\s-1BIO_BIND_REUSEADDR_IF_UNUSED\s0\fR is set then and -attempt is first made to use \s-1BIO_BIN_NORMAL,\s0 if this fails -and the port is not in use then a second attempt is made -using \fB\s-1BIO_BIND_REUSEADDR\s0\fR. If \fB\s-1BIO_SOCK_TFO\s0\fR is set, then -the socket will be configured to accept \s-1TCP\s0 Fast Open -connections. -.PP -\&\fBBIO_do_accept()\fR serves two functions. When it is first -called, after the accept \s-1BIO\s0 has been setup, it will attempt -to create the accept socket and bind an address to it. Second -and subsequent calls to \fBBIO_do_accept()\fR will await an incoming -connection, or request a retry in non blocking mode. -.SH "NOTES" -.IX Header "NOTES" -When an accept \s-1BIO\s0 is at the end of a chain it will await an -incoming connection before processing I/O calls. When an accept -\&\s-1BIO\s0 is not at then end of a chain it passes I/O calls to the next -\&\s-1BIO\s0 in the chain. -.PP -When a connection is established a new socket \s-1BIO\s0 is created for -the connection and appended to the chain. That is the chain is now -accept\->socket. This effectively means that attempting I/O on -an initial accept socket will await an incoming connection then -perform I/O on it. -.PP -If any additional BIOs have been set using \fBBIO_set_accept_bios()\fR -then they are placed between the socket and the accept \s-1BIO,\s0 -that is the chain will be accept\->otherbios\->socket. -.PP -If a server wishes to process multiple connections (as is normally -the case) then the accept \s-1BIO\s0 must be made available for further -incoming connections. This can be done by waiting for a connection and -then calling: -.PP -.Vb 1 -\& connection = BIO_pop(accept); -.Ve -.PP -After this call \fBconnection\fR will contain a \s-1BIO\s0 for the recently -established connection and \fBaccept\fR will now be a single \s-1BIO\s0 -again which can be used to await further incoming connections. -If no further connections will be accepted the \fBaccept\fR can -be freed using \fBBIO_free()\fR. -.PP -If only a single connection will be processed it is possible to -perform I/O using the accept \s-1BIO\s0 itself. This is often undesirable -however because the accept \s-1BIO\s0 will still accept additional incoming -connections. This can be resolved by using \fBBIO_pop()\fR (see above) -and freeing up the accept \s-1BIO\s0 after the initial connection. -.PP -If the underlying accept socket is nonblocking and \fBBIO_do_accept()\fR is -called to await an incoming connection it is possible for -\&\fBBIO_should_io_special()\fR with the reason \s-1BIO_RR_ACCEPT.\s0 If this happens -then it is an indication that an accept attempt would block: the application -should take appropriate action to wait until the underlying socket has -accepted a connection and retry the call. -.PP -\&\fBBIO_set_accept_name()\fR, \fBBIO_get_accept_name()\fR, \fBBIO_set_accept_port()\fR, -\&\fBBIO_get_accept_port()\fR, \fBBIO_set_nbio_accept()\fR, \fBBIO_set_accept_bios()\fR, -\&\fBBIO_get_peer_name()\fR, \fBBIO_get_peer_port()\fR, -\&\fBBIO_get_accept_ip_family()\fR, \fBBIO_set_accept_ip_family()\fR, -\&\fBBIO_set_bind_mode()\fR, \fBBIO_get_bind_mode()\fR and \fBBIO_do_accept()\fR are macros. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_do_accept()\fR, -\&\fBBIO_set_accept_name()\fR, \fBBIO_set_accept_port()\fR, \fBBIO_set_nbio_accept()\fR, -\&\fBBIO_set_accept_bios()\fR, \fBBIO_set_accept_ip_family()\fR, and \fBBIO_set_bind_mode()\fR -return 1 for success and <= 0 for failure. -.PP -\&\fBBIO_get_accept_name()\fR returns the accept name or \s-1NULL\s0 on error. -\&\fBBIO_get_peer_name()\fR returns the peer name or \s-1NULL\s0 on error. -.PP -\&\fBBIO_get_accept_port()\fR returns the accept port as a string or \s-1NULL\s0 on error. -\&\fBBIO_get_peer_port()\fR returns the peer port as a string or \s-1NULL\s0 on error. -\&\fBBIO_get_accept_ip_family()\fR returns the \s-1IP\s0 family or <= 0 on error. -.PP -\&\fBBIO_get_bind_mode()\fR returns the set of \fB\s-1BIO_BIND\s0\fR flags, or <= 0 on failure. -.PP -\&\fBBIO_new_accept()\fR returns a \s-1BIO\s0 or \s-1NULL\s0 on error. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example accepts two connections on port 4444, sends messages -down each and finally closes both down. -.PP -.Vb 1 -\& BIO *abio, *cbio, *cbio2; -\& -\& /* First call to BIO_do_accept() sets up accept BIO */ -\& abio = BIO_new_accept("4444"); -\& if (BIO_do_accept(abio) <= 0) { -\& fprintf(stderr, "Error setting up accept\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& -\& /* Wait for incoming connection */ -\& if (BIO_do_accept(abio) <= 0) { -\& fprintf(stderr, "Error accepting connection\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& fprintf(stderr, "Connection 1 established\en"); -\& -\& /* Retrieve BIO for connection */ -\& cbio = BIO_pop(abio); -\& BIO_puts(cbio, "Connection 1: Sending out Data on initial connection\en"); -\& fprintf(stderr, "Sent out data on connection 1\en"); -\& -\& /* Wait for another connection */ -\& if (BIO_do_accept(abio) <= 0) { -\& fprintf(stderr, "Error accepting connection\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& fprintf(stderr, "Connection 2 established\en"); -\& -\& /* Close accept BIO to refuse further connections */ -\& cbio2 = BIO_pop(abio); -\& BIO_free(abio); -\& BIO_puts(cbio2, "Connection 2: Sending out Data on second\en"); -\& fprintf(stderr, "Sent out data on connection 2\en"); -\& -\& BIO_puts(cbio, "Connection 1: Second connection established\en"); -\& -\& /* Close the two established connections */ -\& BIO_free(cbio); -\& BIO_free(cbio2); -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_set_tfo_accept()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_bio.3ossl b/openssl-install/share/man/man3/BIO_s_bio.3ossl deleted file mode 100644 index 3bb8dc39..00000000 --- a/openssl-install/share/man/man3/BIO_s_bio.3ossl +++ /dev/null @@ -1,332 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_BIO 3ossl" -.TH BIO_S_BIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_bio, BIO_make_bio_pair, BIO_destroy_bio_pair, BIO_shutdown_wr, -BIO_set_write_buf_size, BIO_get_write_buf_size, BIO_new_bio_pair, -BIO_get_write_guarantee, BIO_ctrl_get_write_guarantee, BIO_get_read_request, -BIO_ctrl_get_read_request, BIO_ctrl_reset_read_request \- BIO pair BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_bio(void); -\& -\& int BIO_make_bio_pair(BIO *b1, BIO *b2); -\& int BIO_destroy_bio_pair(BIO *b); -\& int BIO_shutdown_wr(BIO *b); -\& -\& int BIO_set_write_buf_size(BIO *b, long size); -\& size_t BIO_get_write_buf_size(BIO *b, long size); -\& -\& int BIO_new_bio_pair(BIO **bio1, size_t writebuf1, BIO **bio2, size_t writebuf2); -\& -\& int BIO_get_write_guarantee(BIO *b); -\& size_t BIO_ctrl_get_write_guarantee(BIO *b); -\& int BIO_get_read_request(BIO *b); -\& size_t BIO_ctrl_get_read_request(BIO *b); -\& int BIO_ctrl_reset_read_request(BIO *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_bio()\fR returns the method for a \s-1BIO\s0 pair. A \s-1BIO\s0 pair is a pair of source/sink -BIOs where data written to either half of the pair is buffered and can be read from -the other half. Both halves must usually by handled by the same application thread -since no locking is done on the internal data structures. -.PP -Since \s-1BIO\s0 chains typically end in a source/sink \s-1BIO\s0 it is possible to make this -one half of a \s-1BIO\s0 pair and have all the data processed by the chain under application -control. -.PP -One typical use of \s-1BIO\s0 pairs is to place \s-1TLS/SSL I/O\s0 under application control, this -can be used when the application wishes to use a non standard transport for -\&\s-1TLS/SSL\s0 or the normal socket routines are inappropriate. -.PP -Calls to \fBBIO_read_ex()\fR will read data from the buffer or request a retry if no -data is available. -.PP -Calls to \fBBIO_write_ex()\fR will place data in the buffer or request a retry if the -buffer is full. -.PP -The standard calls \fBBIO_ctrl_pending()\fR and \fBBIO_ctrl_wpending()\fR can be used to -determine the amount of pending data in the read or write buffer. -.PP -\&\fBBIO_reset()\fR clears any data in the write buffer. -.PP -\&\fBBIO_make_bio_pair()\fR joins two separate BIOs into a connected pair. -.PP -\&\fBBIO_destroy_pair()\fR destroys the association between two connected BIOs. Freeing -up any half of the pair will automatically destroy the association. -.PP -\&\fBBIO_shutdown_wr()\fR is used to close down a \s-1BIO\s0 \fBb\fR. After this call no further -writes on \s-1BIO\s0 \fBb\fR are allowed (they will return an error). Reads on the other -half of the pair will return any pending data or \s-1EOF\s0 when all pending data has -been read. -.PP -\&\fBBIO_set_write_buf_size()\fR sets the write buffer size of \s-1BIO\s0 \fBb\fR to \fBsize\fR. -If the size is not initialized a default value is used. This is currently -17K, sufficient for a maximum size \s-1TLS\s0 record. -.PP -\&\fBBIO_get_write_buf_size()\fR returns the size of the write buffer. -.PP -\&\fBBIO_new_bio_pair()\fR combines the calls to \fBBIO_new()\fR, \fBBIO_make_bio_pair()\fR and -\&\fBBIO_set_write_buf_size()\fR to create a connected pair of BIOs \fBbio1\fR, \fBbio2\fR -with write buffer sizes \fBwritebuf1\fR and \fBwritebuf2\fR. If either size is -zero then the default size is used. \fBBIO_new_bio_pair()\fR does not check whether -\&\fBbio1\fR or \fBbio2\fR do point to some other \s-1BIO,\s0 the values are overwritten, -\&\fBBIO_free()\fR is not called. -.PP -\&\fBBIO_get_write_guarantee()\fR and \fBBIO_ctrl_get_write_guarantee()\fR return the maximum -length of data that can be currently written to the \s-1BIO.\s0 Writes larger than this -value will return a value from \fBBIO_write_ex()\fR less than the amount requested or -if the buffer is full request a retry. \fBBIO_ctrl_get_write_guarantee()\fR is a -function whereas \fBBIO_get_write_guarantee()\fR is a macro. -.PP -\&\fBBIO_get_read_request()\fR and \fBBIO_ctrl_get_read_request()\fR return the -amount of data requested, or the buffer size if it is less, if the -last read attempt at the other half of the \s-1BIO\s0 pair failed due to an -empty buffer. This can be used to determine how much data should be -written to the \s-1BIO\s0 so the next read will succeed: this is most useful -in \s-1TLS/SSL\s0 applications where the amount of data read is usually -meaningful rather than just a buffer size. After a successful read -this call will return zero. It also will return zero once new data -has been written satisfying the read request or part of it. -Note that \fBBIO_get_read_request()\fR never returns an amount larger -than that returned by \fBBIO_get_write_guarantee()\fR. -.PP -\&\fBBIO_ctrl_reset_read_request()\fR can also be used to reset the value returned by -\&\fBBIO_get_read_request()\fR to zero. -.SH "NOTES" -.IX Header "NOTES" -Both halves of a \s-1BIO\s0 pair should be freed. That is even if one half is implicit -freed due to a \fBBIO_free_all()\fR or \fBSSL_free()\fR call the other half needs to be freed. -.PP -When used in bidirectional applications (such as \s-1TLS/SSL\s0) care should be taken to -flush any data in the write buffer. This can be done by calling \fBBIO_pending()\fR -on the other half of the pair and, if any data is pending, reading it and sending -it to the underlying transport. This must be done before any normal processing -(such as calling \fBselect()\fR ) due to a request and \fBBIO_should_read()\fR being true. -.PP -To see why this is important consider a case where a request is sent using -\&\fBBIO_write_ex()\fR and a response read with \fBBIO_read_ex()\fR, this can occur during an -\&\s-1TLS/SSL\s0 handshake for example. \fBBIO_write_ex()\fR will succeed and place data in the -write buffer. \fBBIO_read_ex()\fR will initially fail and \fBBIO_should_read()\fR will be -true. If the application then waits for data to be available on the underlying -transport before flushing the write buffer it will never succeed because the -request was never sent! -.PP -\&\fBBIO_eof()\fR is true if no data is in the peer \s-1BIO\s0 and the peer \s-1BIO\s0 has been -shutdown. -.PP -\&\fBBIO_make_bio_pair()\fR, \fBBIO_destroy_bio_pair()\fR, \fBBIO_shutdown_wr()\fR, -\&\fBBIO_set_write_buf_size()\fR, \fBBIO_get_write_buf_size()\fR, -\&\fBBIO_get_write_guarantee()\fR, and \fBBIO_get_read_request()\fR are implemented -as macros. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_new_bio_pair()\fR returns 1 on success, with the new BIOs available in -\&\fBbio1\fR and \fBbio2\fR, or 0 on failure, with \s-1NULL\s0 pointers stored into the -locations for \fBbio1\fR and \fBbio2\fR. Check the error stack for more information. -.PP -[\s-1XXXXX:\s0 More return values need to be added here] -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The \s-1BIO\s0 pair can be used to have full control over the network access of an -application. The application can call \fBselect()\fR on the socket as required -without having to go through the SSL-interface. -.PP -.Vb 1 -\& BIO *internal_bio, *network_bio; -\& -\& ... -\& BIO_new_bio_pair(&internal_bio, 0, &network_bio, 0); -\& SSL_set_bio(ssl, internal_bio, internal_bio); -\& SSL_operations(); /* e.g. SSL_read and SSL_write */ -\& ... -\& -\& application | TLS\-engine -\& | | -\& +\-\-\-\-\-\-\-\-\-\-> SSL_operations() -\& | /\e || -\& | || \e/ -\& | BIO\-pair (internal_bio) -\& | BIO\-pair (network_bio) -\& | || /\e -\& | \e/ || -\& +\-\-\-\-\-\-\-\-\-\-\-< BIO_operations() -\& | | -\& | | -\& socket -\& -\& ... -\& SSL_free(ssl); /* implicitly frees internal_bio */ -\& BIO_free(network_bio); -\& ... -.Ve -.PP -As the \s-1BIO\s0 pair will only buffer the data and never directly access the -connection, it behaves nonblocking and will return as soon as the write -buffer is full or the read buffer is drained. Then the application has to -flush the write buffer and/or fill the read buffer. -.PP -Use the \fBBIO_ctrl_pending()\fR, to find out whether data is buffered in the \s-1BIO\s0 -and must be transferred to the network. Use \fBBIO_ctrl_get_read_request()\fR to -find out, how many bytes must be written into the buffer before the -\&\fBSSL_operation()\fR can successfully be continued. -.SH "WARNINGS" -.IX Header "WARNINGS" -As the data is buffered, \fBSSL_operation()\fR may return with an \s-1ERROR_SSL_WANT_READ\s0 -condition, but there is still data in the write buffer. An application must -not rely on the error value of \fBSSL_operation()\fR but must assure that the -write buffer is always flushed first. Otherwise a deadlock may occur as -the peer might be waiting for the data before being able to continue. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_set_bio\fR\|(3), \fBssl\fR\|(7), \fBbio\fR\|(7), -\&\fBBIO_should_retry\fR\|(3), \fBBIO_read_ex\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_connect.3ossl b/openssl-install/share/man/man3/BIO_s_connect.3ossl deleted file mode 100644 index a5efa334..00000000 --- a/openssl-install/share/man/man3/BIO_s_connect.3ossl +++ /dev/null @@ -1,366 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_CONNECT 3ossl" -.TH BIO_S_CONNECT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_connect, BIO_new_connect, -BIO_set_conn_hostname, BIO_set_conn_port, -BIO_set_conn_address, BIO_set_conn_ip_family, -BIO_get_conn_hostname, BIO_get_conn_port, -BIO_get_conn_address, BIO_get_conn_ip_family, -BIO_set_nbio, BIO_set_sock_type, BIO_get_sock_type, BIO_get0_dgram_bio, -BIO_do_connect \- connect BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_connect(void); -\& -\& BIO *BIO_new_connect(const char *name); -\& -\& long BIO_set_conn_hostname(BIO *b, char *name); -\& long BIO_set_conn_port(BIO *b, char *port); -\& long BIO_set_conn_address(BIO *b, BIO_ADDR *addr); -\& long BIO_set_conn_ip_family(BIO *b, long family); -\& const char *BIO_get_conn_hostname(BIO *b); -\& const char *BIO_get_conn_port(BIO *b); -\& const BIO_ADDR *BIO_get_conn_address(BIO *b); -\& const long BIO_get_conn_ip_family(BIO *b); -\& -\& long BIO_set_nbio(BIO *b, long n); -\& -\& int BIO_set_sock_type(BIO *b, int sock_type); -\& int BIO_get_sock_type(BIO *b); -\& int BIO_get0_dgram_bio(BIO *B, BIO **dgram_bio); -\& -\& long BIO_do_connect(BIO *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_connect()\fR returns the connect \s-1BIO\s0 method. This is a wrapper -round the platform's \s-1TCP/IP\s0 socket connection routines. -.PP -Using connect BIOs, \s-1TCP/IP\s0 connections can be made and data -transferred using only \s-1BIO\s0 routines. In this way any platform -specific operations are hidden by the \s-1BIO\s0 abstraction. -.PP -Read and write operations on a connect \s-1BIO\s0 will perform I/O -on the underlying connection. If no connection is established -and the port and hostname (see below) is set up properly then -a connection is established first. -.PP -Connect BIOs support \fBBIO_puts()\fR and \fBBIO_gets()\fR. -.PP -If the close flag is set on a connect \s-1BIO\s0 then any active -connection is shutdown and the socket closed when the \s-1BIO\s0 -is freed. -.PP -Calling \fBBIO_reset()\fR on a connect \s-1BIO\s0 will close any active -connection and reset the \s-1BIO\s0 into a state where it can connect -to the same host again. -.PP -\&\fBBIO_new_connect()\fR combines \fBBIO_new()\fR and \fBBIO_set_conn_hostname()\fR into -a single call: that is it creates a new connect \s-1BIO\s0 with hostname \fBname\fR. -.PP -\&\fBBIO_set_conn_hostname()\fR uses the string \fBname\fR to set the hostname. -The hostname can be an \s-1IP\s0 address; if the address is an IPv6 one, it -must be enclosed in brackets \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -The hostname can also include the port in the form hostname:port; -see \fBBIO_parse_hostserv\fR\|(3) and \fBBIO_set_conn_port()\fR for details. -.PP -\&\fBBIO_set_conn_port()\fR sets the port to \fBport\fR. \fBport\fR can be the -numerical form or a service string such as \*(L"http\*(R", which -will be mapped to a port number using the system function \fBgetservbyname()\fR. -.PP -\&\fBBIO_set_conn_address()\fR sets the address and port information using -a \s-1\fBBIO_ADDR\s0\fR\|(3ssl). -.PP -\&\fBBIO_set_conn_ip_family()\fR sets the \s-1IP\s0 family. -.PP -\&\fBBIO_get_conn_hostname()\fR returns the hostname of the connect \s-1BIO\s0 or -\&\s-1NULL\s0 if the \s-1BIO\s0 is initialized but no hostname is set. -This return value is an internal pointer which should not be modified. -.PP -\&\fBBIO_get_conn_port()\fR returns the port as a string. -This return value is an internal pointer which should not be modified. -.PP -\&\fBBIO_get_conn_address()\fR returns the address information as a \s-1BIO_ADDR.\s0 -This return value is an internal pointer which should not be modified. -.PP -\&\fBBIO_get_conn_ip_family()\fR returns the \s-1IP\s0 family of the connect \s-1BIO.\s0 -.PP -\&\fBBIO_set_nbio()\fR sets the non blocking I/O flag to \fBn\fR. If \fBn\fR is -zero then blocking I/O is set. If \fBn\fR is 1 then non blocking I/O -is set. Blocking I/O is the default. The call to \fBBIO_set_nbio()\fR -should be made before the connection is established because -non blocking I/O is set during the connect process. -.PP -\&\fBBIO_do_connect()\fR attempts to connect the supplied \s-1BIO.\s0 -This performs an \s-1SSL/TLS\s0 handshake as far as supported by the \s-1BIO.\s0 -For non-SSL BIOs the connection is done typically at \s-1TCP\s0 level. -If domain name resolution yields multiple \s-1IP\s0 addresses all of them are tried -after \fBconnect()\fR failures. -The function returns 1 if the connection was established successfully. -A zero or negative value is returned if the connection could not be established. -The call \fBBIO_should_retry()\fR should be used for non blocking connect BIOs -to determine if the call should be retried. -If a connection has already been established this call has no effect. -.PP -\&\fBBIO_set_sock_type()\fR can be used to set a socket type value as would be passed in -a call to \fBsocket\fR\|(2). The only currently supported values are \fB\s-1SOCK_STREAM\s0\fR (the -default) and \fB\s-1SOCK_DGRAM\s0\fR. If \fB\s-1SOCK_DGRAM\s0\fR is configured, the connection -created is a \s-1UDP\s0 datagram socket handled via \fBBIO_s_datagram\fR\|(3). -I/O calls such as \fBBIO_read\fR\|(3) and \fBBIO_write\fR\|(3) are forwarded transparently -to an internal \fBBIO_s_datagram\fR\|(3) instance. The created \fBBIO_s_datagram\fR\|(3) -instance can be retrieved using \fBBIO_get0_dgram_bio()\fR if desired, which writes -a pointer to the \fBBIO_s_datagram\fR\|(3) instance to \fI*dgram_bio\fR. The lifetime -of the internal \fBBIO_s_datagram\fR\|(3) is managed by \fBBIO_s_connect()\fR and does not -need to be freed by the caller. -.PP -\&\fBBIO_get_sock_type()\fR retrieves the value set using \fBBIO_set_sock_type()\fR. -.SH "NOTES" -.IX Header "NOTES" -If blocking I/O is set then a non positive return value from any -I/O call is caused by an error condition, although a zero return -will normally mean that the connection was closed. -.PP -If the port name is supplied as part of the hostname then this will -override any value set with \fBBIO_set_conn_port()\fR. This may be undesirable -if the application does not wish to allow connection to arbitrary -ports. This can be avoided by checking for the presence of the ':' -character in the passed hostname and either indicating an error or -truncating the string at that point. -.PP -The values returned by \fBBIO_get_conn_hostname()\fR, \fBBIO_get_conn_address()\fR, -and \fBBIO_get_conn_port()\fR are updated when a connection attempt is made. -Before any connection attempt the values returned are those set by the -application itself. -.PP -Applications do not have to call \fBBIO_do_connect()\fR but may wish to do -so to separate the connection process from other I/O processing. -.PP -If non blocking I/O is set then retries will be requested as appropriate. -.PP -It addition to \fBBIO_should_read()\fR and \fBBIO_should_write()\fR it is also -possible for \fBBIO_should_io_special()\fR to be true during the initial -connection process with the reason \s-1BIO_RR_CONNECT.\s0 If this is returned -then this is an indication that a connection attempt would block, -the application should then take appropriate action to wait until -the underlying socket has connected and retry the call. -.PP -\&\fBBIO_set_conn_hostname()\fR, \fBBIO_set_conn_port()\fR, \fBBIO_get_conn_hostname()\fR, -\&\fBBIO_set_conn_address()\fR, \fBBIO_get_conn_port()\fR, \fBBIO_get_conn_address()\fR, -\&\fBBIO_set_conn_ip_family()\fR, \fBBIO_get_conn_ip_family()\fR, -\&\fBBIO_set_nbio()\fR, and \fBBIO_do_connect()\fR are macros. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_connect()\fR returns the connect \s-1BIO\s0 method. -.PP -\&\fBBIO_set_conn_address()\fR, \fBBIO_set_conn_port()\fR, and \fBBIO_set_conn_ip_family()\fR -return 1 or <=0 if an error occurs. -.PP -\&\fBBIO_set_conn_hostname()\fR returns 1 on success and <=0 on failure. -.PP -\&\fBBIO_get_conn_address()\fR returns the address information or \s-1NULL\s0 if none -was set. -.PP -\&\fBBIO_get_conn_hostname()\fR returns the connected hostname or \s-1NULL\s0 if -none was set. -.PP -\&\fBBIO_get_conn_ip_family()\fR returns the address family or \-1 if none was set. -.PP -\&\fBBIO_get_conn_port()\fR returns a string representing the connected -port or \s-1NULL\s0 if not set. -.PP -\&\fBBIO_set_nbio()\fR returns 1 or <=0 if an error occurs. -.PP -\&\fBBIO_do_connect()\fR returns 1 if the connection was successfully -established and <=0 if the connection failed. -.PP -\&\fBBIO_set_sock_type()\fR returns 1 on success or 0 on failure. -.PP -\&\fBBIO_get_sock_type()\fR returns a socket type or 0 if the call is not supported. -.PP -\&\fBBIO_get0_dgram_bio()\fR returns 1 on success or 0 on failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This is example connects to a webserver on the local host and attempts -to retrieve a page and copy the result to standard output. -.PP -.Vb 3 -\& BIO *cbio, *out; -\& int len; -\& char tmpbuf[1024]; -\& -\& cbio = BIO_new_connect("localhost:http"); -\& out = BIO_new_fp(stdout, BIO_NOCLOSE); -\& if (BIO_do_connect(cbio) <= 0) { -\& fprintf(stderr, "Error connecting to server\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -\& BIO_puts(cbio, "GET / HTTP/1.0\en\en"); -\& for (;;) { -\& len = BIO_read(cbio, tmpbuf, 1024); -\& if (len <= 0) -\& break; -\& BIO_write(out, tmpbuf, len); -\& } -\& BIO_free(cbio); -\& BIO_free(out); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBBIO_ADDR\s0\fR\|(3), \fBBIO_parse_hostserv\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_set_conn_int_port()\fR, \fBBIO_get_conn_int_port()\fR, \fBBIO_set_conn_ip()\fR, and \fBBIO_get_conn_ip()\fR -were removed in OpenSSL 1.1.0. -Use \fBBIO_set_conn_address()\fR and \fBBIO_get_conn_address()\fR instead. -.PP -Connect BIOs support \fBBIO_gets()\fR since OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_core.3ossl b/openssl-install/share/man/man3/BIO_s_core.3ossl deleted file mode 100644 index 3bf8b5af..00000000 --- a/openssl-install/share/man/man3/BIO_s_core.3ossl +++ /dev/null @@ -1,205 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_CORE 3ossl" -.TH BIO_S_CORE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_core, BIO_new_from_core_bio \- OSSL_CORE_BIO functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_core(void); -\& -\& BIO *BIO_new_from_core_bio(OSSL_LIB_CTX *libctx, OSSL_CORE_BIO *corebio); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_core()\fR returns the core \s-1BIO\s0 method function. -.PP -A core \s-1BIO\s0 is treated as source/sink \s-1BIO\s0 which communicates to some external -\&\s-1BIO.\s0 This is primarily useful to provider authors. A number of calls from -libcrypto into a provider supply an \s-1OSSL_CORE_BIO\s0 parameter. This represents -a \s-1BIO\s0 within libcrypto, but cannot be used directly by a provider. Instead it -should be wrapped using a \fBBIO_s_core()\fR. -.PP -Once a \s-1BIO\s0 is constructed based on \fBBIO_s_core()\fR, the associated \s-1OSSL_CORE_BIO\s0 -object should be set on it using \fBBIO_set_data\fR\|(3). Note that the \s-1BIO\s0 will only -operate correctly if it is associated with a library context constructed using -\&\fBOSSL_LIB_CTX_new_from_dispatch\fR\|(3). To associate the \s-1BIO\s0 with a library context -construct it using \fBBIO_new_ex\fR\|(3). -.PP -\&\fBBIO_new_from_core_bio()\fR is a convenience function that constructs a new \s-1BIO\s0 -based on \fBBIO_s_core()\fR and that is associated with the given library context. It -then also sets the \s-1OSSL_CORE_BIO\s0 object on the \s-1BIO\s0 using \fBBIO_set_data\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_core()\fR return a core \s-1BIO\s0 \fB\s-1BIO_METHOD\s0\fR structure. -.PP -\&\fBBIO_new_from_core_bio()\fR returns a \s-1BIO\s0 structure on success or \s-1NULL\s0 on failure. -A failure will most commonly be because the library context was not constructed -using \fBOSSL_LIB_CTX_new_from_dispatch\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_s_core()\fR and \fBBIO_new_from_core_bio()\fR were added in OpenSSL 3.0. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a core \s-1BIO\s0 and write some data to it: -.PP -.Vb 2 -\& int some_function(OSSL_LIB_CTX *libctx, OSSL_CORE_BIO *corebio) { -\& BIO *cbio = BIO_new_from_core_bio(libctx, corebio); -\& -\& if (cbio == NULL) -\& return 0; -\& -\& BIO_puts(cbio, "Hello World\en"); -\& -\& BIO_free(cbio); -\& return 1; -\& } -.Ve -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_datagram.3ossl b/openssl-install/share/man/man3/BIO_s_datagram.3ossl deleted file mode 100644 index 6194de4f..00000000 --- a/openssl-install/share/man/man3/BIO_s_datagram.3ossl +++ /dev/null @@ -1,367 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_DATAGRAM 3ossl" -.TH BIO_S_DATAGRAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_datagram, BIO_new_dgram, -BIO_ctrl_dgram_connect, -BIO_ctrl_set_connected, -BIO_dgram_recv_timedout, -BIO_dgram_send_timedout, -BIO_dgram_get_peer, -BIO_dgram_set_peer, -BIO_dgram_detect_peer_addr, -BIO_dgram_get_mtu_overhead \- Network BIO with datagram semantics -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIO_METHOD *BIO_s_datagram(void); -\& BIO *BIO_new_dgram(int fd, int close_flag); -\& -\& int BIO_ctrl_dgram_connect(BIO *bio, const BIO_ADDR *peer); -\& int BIO_ctrl_set_connected(BIO *bio, const BIO_ADDR *peer); -\& int BIO_dgram_recv_timedout(BIO *bio); -\& int BIO_dgram_send_timedout(BIO *bio); -\& int BIO_dgram_get_peer(BIO *bio, BIO_ADDR *peer); -\& int BIO_dgram_set_peer(BIO *bio, const BIO_ADDR *peer); -\& int BIO_dgram_get_mtu_overhead(BIO *bio); -\& int BIO_dgram_detect_peer_addr(BIO *bio, BIO_ADDR *peer); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_datagram()\fR is a \s-1BIO\s0 implementation designed for use with network sockets -which provide datagram semantics, such as \s-1UDP\s0 sockets. It is suitable for use -with DTLSv1 or \s-1QUIC.\s0 -.PP -Because \fBBIO_s_datagram()\fR has datagram semantics, a single \fBBIO_write()\fR call sends -a single datagram and a single \fBBIO_read()\fR call receives a single datagram. If -the size of the buffer passed to \fBBIO_read()\fR is inadequate, the datagram is -silently truncated. -.PP -For a memory-based \s-1BIO\s0 which provides datagram semantics identical to those of -\&\fBBIO_s_datagram()\fR, see \fBBIO_s_dgram_pair\fR\|(3). -.PP -This \s-1BIO\s0 supports the \fBBIO_sendmmsg\fR\|(3) and \fBBIO_recvmmsg\fR\|(3) functions. -.PP -When using \fBBIO_s_datagram()\fR, it is important to note that: -.IP "\(bu" 4 -This \s-1BIO\s0 can be used with either a connected or unconnected network socket. A -connected socket is a network socket which has had \fBBIO_connect\fR\|(3) or a -similar OS-specific function called on it. Such a socket can only receive -datagrams from the specified peer. Any other socket is an unconnected socket and -can receive datagrams from any host. -.IP "\(bu" 4 -Despite their naming, -neither \fBBIO_ctrl_dgram_connect()\fR nor \fBBIO_ctrl_set_connected()\fR cause a socket -to become connected. These controls are provided to indicate to the \s-1BIO\s0 how -the underlying socket is configured and how it is to be used; see below. -.IP "\(bu" 4 -Use of \fBBIO_s_datagram()\fR with an unconnected network socket is hazardous hecause -any successful call to \fBBIO_read()\fR results in the peer address used for any -subsequent call to \fBBIO_write()\fR being set to the source address of the datagram -received by that call to \fBBIO_read()\fR. Thus, unless the caller calls -\&\fBBIO_dgram_set_peer()\fR immediately prior to every call to \fBBIO_write()\fR, or never -calls \fBBIO_read()\fR, any host on the network may cause future datagrams written to -be redirected to that host. Therefore, it is recommended that users either use -\&\fBBIO_s_dgram()\fR only with a connected socket, or, if using \fBBIO_s_dgram()\fR with an -unconnected socket, to use the \fBBIO_sendmmsg\fR\|(3) and \fBBIO_recvmmsg\fR\|(3) methods -only and forego use of \fBBIO_read\fR\|(3) and \fBBIO_write\fR\|(3). An exception is where -\&\fBDTLSv1_listen\fR\|(3) must be used; see \fBDTLSv1_listen\fR\|(3) for further -discussion. -.IP "\(bu" 4 -Unlike \fBBIO_read\fR\|(3) and \fBBIO_write\fR\|(3), the \fBBIO_sendmmsg\fR\|(3) and -\&\fBBIO_recvmmsg\fR\|(3) methods are stateless and do not cause the internal state of -the \fBBIO_s_datagram()\fR to change. -.PP -Various controls are available for configuring the \fBBIO_s_datagram()\fR using -\&\fBBIO_ctrl\fR\|(3): -.IP "BIO_ctrl_dgram_connect (\s-1BIO_CTRL_DGRAM_CONNECT\s0)" 4 -.IX Item "BIO_ctrl_dgram_connect (BIO_CTRL_DGRAM_CONNECT)" -This is equivalent to calling \fBBIO_dgram_set_peer\fR\|(3). -.Sp -Despite its name, this function does not cause the underlying socket to become -connected. -.IP "BIO_ctrl_set_connected (\s-1BIO_CTRL_SET_CONNECTED\s0)" 4 -.IX Item "BIO_ctrl_set_connected (BIO_CTRL_SET_CONNECTED)" -This informs the \fBBIO_s_datagram()\fR whether the underlying socket has been -connected, and therefore how the \fBBIO_s_datagram()\fR should attempt to use the -socket. -.Sp -If the \fIpeer\fR argument is non-NULL, \fBBIO_s_datagram()\fR assumes that the -underlying socket has been connected and will attempt to use the socket using \s-1OS\s0 -APIs which do not specify peer addresses (for example, \fBsend\fR\|(3) and \fBrecv\fR\|(3) or -similar). The \fIpeer\fR argument should specify the peer address to which the socket -is connected. -.Sp -If the \fIpeer\fR argument is \s-1NULL,\s0 \fBBIO_s_datagram()\fR assumes that the underlying -socket is not connected and will attempt to use the socket using an \s-1OS\s0 APIs -which specify peer addresses (for example, \fBsendto\fR\|(3) and \fBrecvfrom\fR\|(3)). -.Sp -This control does not affect the operation of \fBBIO_sendmmsg\fR\|(3) or -\&\fBBIO_recvmmsg\fR\|(3). -.IP "BIO_dgram_get_peer (\s-1BIO_CTRL_DGRAM_GET_PEER\s0)" 4 -.IX Item "BIO_dgram_get_peer (BIO_CTRL_DGRAM_GET_PEER)" -This outputs a \fB\s-1BIO_ADDR\s0\fR which specifies one of the following values, -whichever happened most recently: -.RS 4 -.IP "\(bu" 4 -The peer address last passed to \fBBIO_dgram_set_peer()\fR, \fBBIO_ctrl_dgram_connect()\fR -or \fBBIO_ctrl_set_connected()\fR. -.IP "\(bu" 4 -The peer address of the datagram last received by a call to \fBBIO_read()\fR. -.RE -.RS 4 -.RE -.IP "BIO_dgram_set_peer (\s-1BIO_CTRL_DGRAM_SET_PEER\s0)" 4 -.IX Item "BIO_dgram_set_peer (BIO_CTRL_DGRAM_SET_PEER)" -Sets the peer address to be used for subsequent writes to this \s-1BIO.\s0 -.Sp -Warning: When used with an unconnected network socket, the value set may be -modified by future calls to \fBBIO_read\fR\|(3), making use of \fBBIO_s_datagram()\fR -hazardous when used with unconnected network sockets; see above. -.Sp -This does not affect the operation of \fBBIO_sendmmsg\fR\|(3). -\&\fBBIO_recvmmsg\fR\|(3) does not affect the value set by \fBBIO_dgram_set_peer()\fR. -.IP "BIO_dgram_detect_peer_addr (\s-1BIO_CTRL_DGRAM_DETECT_PEER_ADDR\s0)" 4 -.IX Item "BIO_dgram_detect_peer_addr (BIO_CTRL_DGRAM_DETECT_PEER_ADDR)" -This is similar to \fBBIO_dgram_get_peer()\fR except that if the peer address has not -been set on the \s-1BIO\s0 object, an \s-1OS\s0 call such as \fBgetpeername\fR\|(2) will be attempted -to try and autodetect the peer address to which the underlying socket is -connected. Other BIOs may also implement this control if they are capable of -sensing a peer address, without necessarily also implementing -\&\fBBIO_dgram_set_peer()\fR and \fBBIO_dgram_get_peer()\fR. -.IP "BIO_dgram_recv_timeout (\s-1BIO_CTRL_DGRAM_GET_RECV_TIMER_EXP\s0)" 4 -.IX Item "BIO_dgram_recv_timeout (BIO_CTRL_DGRAM_GET_RECV_TIMER_EXP)" -Returns 1 if the last I/O operation performed on the \s-1BIO\s0 (for example, via a -call to \fBBIO_read\fR\|(3)) may have been caused by a receive timeout. -.IP "BIO_dgram_send_timedout (\s-1BIO_CTRL_DGRAM_GET_SEND_TIMER_EXP\s0)" 4 -.IX Item "BIO_dgram_send_timedout (BIO_CTRL_DGRAM_GET_SEND_TIMER_EXP)" -Returns 1 if the last I/O operation performed on the \s-1BIO\s0 (for example, via a -call to \fBBIO_write\fR\|(3)) may have been caused by a send timeout. -.IP "BIO_dgram_get_mtu_overhead (\s-1BIO_CTRL_DGRAM_GET_MTU_OVERHEAD\s0)" 4 -.IX Item "BIO_dgram_get_mtu_overhead (BIO_CTRL_DGRAM_GET_MTU_OVERHEAD)" -Returns a quantity in bytes which is a rough estimate of the number of bytes of -overhead which should typically be added to a datagram payload size in order to -estimate the final size of the Layer 3 (e.g. \s-1IP\s0) packet which will contain the -datagram. In most cases, the maximum datagram payload size which can be -transmitted can be determined by determining the link \s-1MTU\s0 in bytes and -subtracting the value returned by this call. -.Sp -The value returned by this call depends on the network layer protocol being -used. -.Sp -The value returned is not fully reliable because datagram overheads can be -higher in atypical network configurations, for example where IPv6 extension -headers or IPv4 options are used. -.IP "\s-1BIO_CTRL_DGRAM_SET_DONT_FRAG\s0" 4 -.IX Item "BIO_CTRL_DGRAM_SET_DONT_FRAG" -If \fInum\fR is nonzero, configures the underlying network socket to enable Don't -Fragment mode, in which datagrams will be set with the \s-1IP\s0 Don't Fragment (\s-1DF\s0) -bit set. If \fInum\fR is zero, Don't Fragment mode is disabled. -.IP "\s-1BIO_CTRL_DGRAM_QUERY_MTU\s0" 4 -.IX Item "BIO_CTRL_DGRAM_QUERY_MTU" -Queries the \s-1OS\s0 for its assessment of the Path \s-1MTU\s0 for the destination to which -the underlying network socket, and returns that Path \s-1MTU\s0 in bytes. This control -can only be used with a connected socket. -.Sp -This is not supported on all platforms and depends on \s-1OS\s0 support being -available. Returns 0 on failure. -.IP "\s-1BIO_CTRL_DGRAM_MTU_DISCOVER\s0" 4 -.IX Item "BIO_CTRL_DGRAM_MTU_DISCOVER" -This control requests that Path \s-1MTU\s0 discovery be enabled on the underlying -network socket. -.IP "\s-1BIO_CTRL_DGRAM_GET_FALLBACK_MTU\s0" 4 -.IX Item "BIO_CTRL_DGRAM_GET_FALLBACK_MTU" -Returns the estimated minimum size of datagram payload which should always be -supported on the \s-1BIO.\s0 This size is determined by the minimum \s-1MTU\s0 required to be -supported by the applicable underlying network layer. Use of datagrams of this -size may lead to suboptimal performance, but should be routable in all -circumstances. The value returned is the datagram payload size in bytes and does -not include the size of layer 3 or layer 4 protocol headers. -.IP "\s-1BIO_CTRL_DGRAM_MTU_EXCEEDED\s0" 4 -.IX Item "BIO_CTRL_DGRAM_MTU_EXCEEDED" -Returns 1 if the last attempted write to the \s-1BIO\s0 failed due to the size of the -attempted write exceeding the applicable \s-1MTU.\s0 -.IP "\s-1BIO_CTRL_DGRAM_SET_NEXT_TIMEOUT\s0" 4 -.IX Item "BIO_CTRL_DGRAM_SET_NEXT_TIMEOUT" -Accepts a pointer to a \fBstruct timeval\fR. If the time specified is zero, -disables receive timeouts. Otherwise, configures the specified time interval as -the receive timeout for the socket for the purposes of future \fBBIO_read\fR\|(3) -calls. -.IP "\s-1BIO_CTRL_DGRAM_SET_PEEK_MODE\s0" 4 -.IX Item "BIO_CTRL_DGRAM_SET_PEEK_MODE" -If \fBnum\fR is nonzero, enables peek mode; otherwise, disables peek mode. Where -peek mode is enabled, calls to \fBBIO_read\fR\|(3) read datagrams from the underlying -network socket in peek mode, meaning that a future call to \fBBIO_read\fR\|(3) will -yield the same datagram until peek mode is disabled. -.Sp -\&\fBBIO_recvmmsg\fR\|(3) is not affected by this control. -.PP -\&\fBBIO_new_dgram()\fR is a helper function which instantiates a \fBBIO_s_datagram()\fR and -sets the \s-1BIO\s0 to use the socket given in \fIfd\fR by calling \fBBIO_set_fd()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_datagram()\fR returns a \s-1BIO\s0 method. -.PP -\&\fBBIO_new_dgram()\fR returns a \s-1BIO\s0 on success and \s-1NULL\s0 on failure. -.PP -\&\fBBIO_ctrl_dgram_connect()\fR, \fBBIO_ctrl_set_connected()\fR and \fBBIO_dgram_set_peer()\fR -return 1 on success and 0 on failure. -.PP -\&\fBBIO_dgram_get_peer()\fR and \fBBIO_dgram_detect_peer_addr()\fR return 0 on failure and -the number of bytes for the outputted address representation (a positive value) -on success. -.PP -\&\fBBIO_dgram_recv_timedout()\fR and \fBBIO_dgram_send_timedout()\fR return 0 or 1 depending -on the circumstance; see discussion above. -.PP -\&\fBBIO_dgram_get_mtu_overhead()\fR returns a value in bytes. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_sendmmsg\fR\|(3), \fBBIO_s_dgram_pair\fR\|(3), \fBDTLSv1_listen\fR\|(3), \fBbio\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_dgram_mem.3ossl b/openssl-install/share/man/man3/BIO_s_dgram_mem.3ossl deleted file mode 120000 index e9853704..00000000 --- a/openssl-install/share/man/man3/BIO_s_dgram_mem.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_mem.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_s_dgram_pair.3ossl b/openssl-install/share/man/man3/BIO_s_dgram_pair.3ossl deleted file mode 100644 index 92180982..00000000 --- a/openssl-install/share/man/man3/BIO_s_dgram_pair.3ossl +++ /dev/null @@ -1,343 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_DGRAM_PAIR 3ossl" -.TH BIO_S_DGRAM_PAIR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_dgram_pair, BIO_new_bio_dgram_pair, BIO_dgram_set_no_trunc, -BIO_dgram_get_no_trunc, BIO_dgram_get_effective_caps, BIO_dgram_get_caps, -BIO_dgram_set_caps, BIO_dgram_set_mtu, BIO_dgram_get_mtu \- datagram pair BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_dgram_pair(void); -\& -\& int BIO_new_bio_dgram_pair(BIO **bio1, size_t writebuf1, -\& BIO **bio2, size_t writebuf2); -\& int BIO_dgram_set_no_trunc(BIO *bio, int enable); -\& int BIO_dgram_get_no_trunc(BIO *bio); -\& uint32_t BIO_dgram_get_effective_caps(BIO *bio); -\& uint32_t BIO_dgram_get_caps(BIO *bio); -\& int BIO_dgram_set_caps(BIO *bio, uint32_t caps); -\& int BIO_dgram_set_mtu(BIO *bio, unsigned int mtu); -\& unsigned int BIO_dgram_get_mtu(BIO *bio); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_dgram_pair()\fR returns the method for a \s-1BIO\s0 datagram pair. A \s-1BIO\s0 datagram -pair is similar to a \s-1BIO\s0 pair (see \fBBIO_s_bio\fR\|(3)) but has datagram semantics. -Broadly, this means that the length of the buffer passed to a write call will -match that retrieved by a read call. If the buffer passed to a read call is too -short, the datagram is truncated or the read fails, depending on how the \s-1BIO\s0 is -configured. -.PP -The \s-1BIO\s0 datagram pair attaches certain metadata to each write, such as source -and destination addresses. This information may be retrieved on read. -.PP -A typical application of a \s-1BIO\s0 datagram pair is to allow an application to keep -all datagram network I/O requested by libssl under application control. -.PP -The \s-1BIO\s0 datagram pair is designed to support multithreaded use where certain -restrictions are observed; see \s-1THREADING.\s0 -.PP -The \s-1BIO\s0 datagram pair allows each half of a pair to signal to the other half -whether they support certain capabilities; see \s-1CAPABILITY INDICATION.\s0 -.PP -\&\fBBIO_new_bio_dgram_pair()\fR combines the calls to \fBBIO_new\fR\|(3), -\&\fBBIO_make_bio_pair\fR\|(3) and \fBBIO_set_write_buf_size\fR\|(3) to create a connected -pair of BIOs \fBbio1\fR, \fBbio2\fR with write buffer sizes \fBwritebuf1\fR and -\&\fBwritebuf2\fR. If either size is zero then the default size is used. -.PP -\&\fBBIO_make_bio_pair\fR\|(3) may be used to join two datagram pair BIOs into a pair. -The two BIOs must both use the method returned by \fBBIO_s_dgram_pair()\fR and neither -of the BIOs may currently be associated in a pair. -.PP -\&\fBBIO_destroy_bio_pair\fR\|(3) destroys the association between two connected BIOs. -Freeing either half of the pair will automatically destroy the association. -.PP -\&\fBBIO_reset\fR\|(3) clears any data in the write buffer of the given \s-1BIO.\s0 This means -that the opposite \s-1BIO\s0 in the pair will no longer have any data waiting to be -read. -.PP -The \s-1BIO\s0 maintains a fixed size internal write buffer. When the buffer is full, -further writes will fail until the buffer is drained via calls to -\&\fBBIO_read\fR\|(3). The size of the buffer can be changed using -\&\fBBIO_set_write_buf_size\fR\|(3) and queried using \fBBIO_get_write_buf_size\fR\|(3). -.PP -Note that the write buffer is partially consumed by metadata stored internally -which is attached to each datagram, such as source and destination addresses. -The size of this overhead is undefined and may change between releases. -.PP -The standard \fBBIO_ctrl_pending\fR\|(3) call has modified behaviour and returns the -size of the next datagram waiting to be read in bytes. An application can use -this function to ensure it provides an adequate buffer to a subsequent read -call. If no datagram is waiting to be read, zero is returned. -.PP -This \s-1BIO\s0 does not support sending or receiving zero-length datagrams. Passing a -zero-length buffer to BIO_write is treated as a no-op. -.PP -\&\fBBIO_eof\fR\|(3) returns 1 only if the given \s-1BIO\s0 datagram pair \s-1BIO\s0 is not currently -connected to a peer \s-1BIO.\s0 -.PP -\&\fBBIO_get_write_guarantee\fR\|(3) and \fBBIO_ctrl_get_write_guarantee\fR\|(3) return how -large a datagram the next call to \fBBIO_write\fR\|(3) can accept. If there is not -enough space in the write buffer to accept another datagram equal in size to the -configured \s-1MTU,\s0 zero is returned (see below). This is intended to avoid a -situation where an application attempts to read a datagram from a network -intending to write it to a \s-1BIO\s0 datagram pair, but where the received datagram -ends up being too large to write to the \s-1BIO\s0 datagram pair. -.PP -\&\fBBIO_dgram_set_no_trunc()\fR and \fBBIO_ctrl_get_no_trunc()\fR set and retrieve the -truncation mode for the given half of a \s-1BIO\s0 datagram pair. When no-truncate mode -is enabled, \fBBIO_read()\fR will fail if the buffer provided is inadequate to hold -the next datagram to be read. If no-truncate mode is disabled (the default), the -datagram will be silently truncated. This default behaviour maintains -compatibility with the semantics of the Berkeley sockets \s-1API.\s0 -.PP -\&\fBBIO_dgram_set_mtu()\fR and \fBBIO_dgram_get_mtu()\fR may be used to set an informational -\&\s-1MTU\s0 value on the \s-1BIO\s0 datagram pair. If \fBBIO_dgram_set_mtu()\fR is used on a \s-1BIO\s0 -which is currently part of a \s-1BIO\s0 datagram pair, the \s-1MTU\s0 value is set on both -halves of the pair. The value does not affect the operation of the \s-1BIO\s0 datagram -pair (except for \fBBIO_get_write_guarantee()\fR; see above) but may be used by other -code to determine a requested \s-1MTU.\s0 When a \s-1BIO\s0 datagram pair \s-1BIO\s0 is created, the -\&\s-1MTU\s0 is set to an unspecified but valid value. -.PP -\&\fBBIO_flush\fR\|(3) is a no-op. -.SH "NOTES" -.IX Header "NOTES" -The halves of a \s-1BIO\s0 datagram pair have independent lifetimes and must be -separately freed. -.SH "THREADING" -.IX Header "THREADING" -\&\fBBIO_recvmmsg\fR\|(3), \fBBIO_sendmmsg\fR\|(3), \fBBIO_read\fR\|(3), \fBBIO_write\fR\|(3), -\&\fBBIO_pending\fR\|(3), \fBBIO_get_write_guarantee\fR\|(3) and \fBBIO_flush\fR\|(3) may be used -by multiple threads simultaneously on the same \s-1BIO\s0 datagram pair. Specific -\&\fBBIO_ctrl\fR\|(3) operations (namely \s-1BIO_CTRL_PENDING, BIO_CTRL_FLUSH\s0 and -\&\s-1BIO_C_GET_WRITE_GUARANTEE\s0) may also be used. Invoking any other \s-1BIO\s0 call, or any -other \fBBIO_ctrl\fR\|(3) operation, on either half of a \s-1BIO\s0 datagram pair while any -other \s-1BIO\s0 call is also in progress to either half of the same \s-1BIO\s0 datagram pair -results in undefined behaviour. -.SH "CAPABILITY INDICATION" -.IX Header "CAPABILITY INDICATION" -The \s-1BIO\s0 datagram pair can be used to enqueue datagrams which have source and -destination addresses attached. It is important that the component consuming one -side of a \s-1BIO\s0 datagram pair understand whether the other side of the pair will -honour any source and destination addresses it attaches to each datagram. For -example, if datagrams are queued with destination addresses set but simply read -by simple calls to \fBBIO_read\fR\|(3), the destination addresses will be discarded. -.PP -Each half of a \s-1BIO\s0 datagram pair can have capability flags set on it which -indicate whether source and destination addresses will be honoured by the reader -and whether they will be provided by the writer. These capability flags should -be set via a call to \fBBIO_dgram_set_caps()\fR, and these capabilities will be -reflected in the value returned by \fBBIO_dgram_get_effective_caps()\fR on the -opposite \s-1BIO.\s0 If necessary, the capability value previously set can be retrieved -using \fBBIO_dgram_get_caps()\fR. Note that \fBBIO_dgram_set_caps()\fR on a given \s-1BIO\s0 -controls the capabilities advertised to the peer, and -\&\fBBIO_dgram_get_effective_caps()\fR on a given \s-1BIO\s0 determines the capabilities -advertised by the peer of that \s-1BIO.\s0 -.PP -The following capabilities are available: -.IP "\fB\s-1BIO_DGRAM_CAP_HANDLES_SRC_ADDR\s0\fR" 4 -.IX Item "BIO_DGRAM_CAP_HANDLES_SRC_ADDR" -The user of the datagram pair \s-1BIO\s0 promises to honour source addresses provided -with datagrams written to the \s-1BIO\s0 pair. -.IP "\fB\s-1BIO_DGRAM_CAP_HANDLES_DST_ADDR\s0\fR" 4 -.IX Item "BIO_DGRAM_CAP_HANDLES_DST_ADDR" -The user of the datagram pair \s-1BIO\s0 promises to honour destination addresses provided -with datagrams written to the \s-1BIO\s0 pair. -.IP "\fB\s-1BIO_DGRAM_CAP_PROVIDES_SRC_ADDR\s0\fR" 4 -.IX Item "BIO_DGRAM_CAP_PROVIDES_SRC_ADDR" -The user of the datagram pair \s-1BIO\s0 advertises the fact that it will provide source -addressing information with future writes to the \s-1BIO\s0 pair, where available. -.IP "\fB\s-1BIO_DGRAM_CAP_PROVIDES_DST_ADDR\s0\fR" 4 -.IX Item "BIO_DGRAM_CAP_PROVIDES_DST_ADDR" -The user of the datagram pair \s-1BIO\s0 advertises the fact that it will provide -destination addressing information with future writes to the \s-1BIO\s0 pair, where -available. -.PP -If a caller attempts to specify a destination address (for example, using -\&\fBBIO_sendmmsg\fR\|(3)) and the peer has not advertised the -\&\fB\s-1BIO_DGRAM_CAP_HANDLES_DST_ADDR\s0\fR capability, the operation fails. Thus, -capability negotiation is mandatory. -.PP -If a caller attempts to specify a source address when writing, or requests a -destination address when receiving, and local address support has not been -enabled, the operation fails; see \fBBIO_dgram_set_local_addr_enable\fR\|(3). -.PP -If a caller attempts to enable local address support using -\&\fBBIO_dgram_set_local_addr_enable\fR\|(3) and \fBBIO_dgram_get_local_addr_cap\fR\|(3) -does not return 1 (meaning that the peer has not advertised both the -\&\fB\s-1BIO_DGRAM_CAP_HANDLES_SRC_ADDR\s0\fR and the \fB\s-1BIO_DGRAM_CAP_PROVIDES_DST_ADDR\s0\fR -capability), the operation fails. -.PP -\&\fB\s-1BIO_DGRAM_CAP_PROVIDES_SRC_ADDR\s0\fR and \fB\s-1BIO_DGRAM_CAP_PROVIDES_DST_ADDR\s0\fR -indicate that the application using that half of a \s-1BIO\s0 datagram pair promises to -provide source and destination addresses respectively when writing datagrams to -that half of the \s-1BIO\s0 datagram pair. However, these capability flags do not -affect the behaviour of the \s-1BIO\s0 datagram pair. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_new_bio_dgram_pair()\fR returns 1 on success, with the new BIOs available in -\&\fBbio1\fR and \fBbio2\fR, or 0 on failure, with \s-1NULL\s0 pointers stored into the -locations for \fBbio1\fR and \fBbio2\fR. Check the error stack for more information. -.PP -\&\fBBIO_dgram_set_no_trunc()\fR, \fBBIO_dgram_set_caps()\fR and \fBBIO_dgram_set_mtu()\fR return 1 -on success and 0 on failure. -.PP -\&\fBBIO_dgram_get_no_trunc()\fR returns 1 if no-truncate mode is enabled on a \s-1BIO,\s0 or 0 -if no-truncate mode is not enabled or not supported on a given \s-1BIO.\s0 -.PP -\&\fBBIO_dgram_get_effective_caps()\fR and \fBBIO_dgram_get_caps()\fR return zero if no -capabilities are supported. -.PP -\&\fBBIO_dgram_get_mtu()\fR returns the \s-1MTU\s0 value configured on the \s-1BIO,\s0 or zero if the -operation is not supported. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_s_bio\fR\|(3), \fBbio\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_fd.3ossl b/openssl-install/share/man/man3/BIO_s_fd.3ossl deleted file mode 100644 index 7cd14318..00000000 --- a/openssl-install/share/man/man3/BIO_s_fd.3ossl +++ /dev/null @@ -1,230 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_FD 3ossl" -.TH BIO_S_FD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_fd, BIO_set_fd, BIO_get_fd, BIO_new_fd \- file descriptor BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_fd(void); -\& -\& int BIO_set_fd(BIO *b, int fd, int c); -\& int BIO_get_fd(BIO *b, int *c); -\& -\& BIO *BIO_new_fd(int fd, int close_flag); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_fd()\fR returns the file descriptor \s-1BIO\s0 method. This is a wrapper -round the platforms file descriptor routines such as \fBread()\fR and \fBwrite()\fR. -.PP -\&\fBBIO_read_ex()\fR and \fBBIO_write_ex()\fR read or write the underlying descriptor. -\&\fBBIO_puts()\fR is supported but \fBBIO_gets()\fR is not. -.PP -If the close flag is set then \fBclose()\fR is called on the underlying -file descriptor when the \s-1BIO\s0 is freed. -.PP -\&\fBBIO_reset()\fR attempts to change the file pointer to the start of file -such as by using \fBlseek(fd, 0, 0)\fR. -.PP -\&\fBBIO_seek()\fR sets the file pointer to position \fBofs\fR from start of file -such as by using \fBlseek(fd, ofs, 0)\fR. -.PP -\&\fBBIO_tell()\fR returns the current file position such as by calling -\&\fBlseek(fd, 0, 1)\fR. -.PP -\&\fBBIO_set_fd()\fR sets the file descriptor of \s-1BIO\s0 \fBb\fR to \fBfd\fR and the close -flag to \fBc\fR. -.PP -\&\fBBIO_get_fd()\fR places the file descriptor of \s-1BIO\s0 \fBb\fR in \fBc\fR if it is not \s-1NULL.\s0 -It also returns the file descriptor. -.PP -\&\fBBIO_new_fd()\fR returns a file descriptor \s-1BIO\s0 using \fBfd\fR and \fBclose_flag\fR. -.SH "NOTES" -.IX Header "NOTES" -The behaviour of \fBBIO_read_ex()\fR and \fBBIO_write_ex()\fR depends on the behavior of the -platforms \fBread()\fR and \fBwrite()\fR calls on the descriptor. If the underlying -file descriptor is in a non blocking mode then the \s-1BIO\s0 will behave in the -manner described in the \fBBIO_read_ex\fR\|(3) and \fBBIO_should_retry\fR\|(3) -manual pages. -.PP -File descriptor BIOs should not be used for socket I/O. Use socket BIOs -instead. -.PP -\&\fBBIO_set_fd()\fR and \fBBIO_get_fd()\fR are implemented as macros. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_fd()\fR returns the file descriptor \s-1BIO\s0 method. -.PP -\&\fBBIO_set_fd()\fR returns 1 on success or <=0 for failure. -.PP -\&\fBBIO_get_fd()\fR returns the file descriptor or \-1 if the \s-1BIO\s0 has not -been initialized. It also returns zero and negative values if other error occurs. -.PP -\&\fBBIO_new_fd()\fR returns the newly allocated \s-1BIO\s0 or \s-1NULL\s0 is an error -occurred. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This is a file descriptor \s-1BIO\s0 version of \*(L"Hello World\*(R": -.PP -.Vb 1 -\& BIO *out; -\& -\& out = BIO_new_fd(fileno(stdout), BIO_NOCLOSE); -\& BIO_printf(out, "Hello World\en"); -\& BIO_free(out); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_seek\fR\|(3), \fBBIO_tell\fR\|(3), -\&\fBBIO_reset\fR\|(3), \fBBIO_read_ex\fR\|(3), -\&\fBBIO_write_ex\fR\|(3), \fBBIO_puts\fR\|(3), -\&\fBBIO_gets\fR\|(3), \fBBIO_printf\fR\|(3), -\&\fBBIO_set_close\fR\|(3), \fBBIO_get_close\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_file.3ossl b/openssl-install/share/man/man3/BIO_s_file.3ossl deleted file mode 100644 index 9d624617..00000000 --- a/openssl-install/share/man/man3/BIO_s_file.3ossl +++ /dev/null @@ -1,304 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_FILE 3ossl" -.TH BIO_S_FILE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_file, BIO_new_file, BIO_new_fp, BIO_set_fp, BIO_get_fp, -BIO_read_filename, BIO_write_filename, BIO_append_filename, -BIO_rw_filename \- FILE bio -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_file(void); -\& BIO *BIO_new_file(const char *filename, const char *mode); -\& BIO *BIO_new_fp(FILE *stream, int flags); -\& -\& BIO_set_fp(BIO *b, FILE *fp, int flags); -\& BIO_get_fp(BIO *b, FILE **fpp); -\& -\& int BIO_read_filename(BIO *b, char *name); -\& int BIO_write_filename(BIO *b, char *name); -\& int BIO_append_filename(BIO *b, char *name); -\& int BIO_rw_filename(BIO *b, char *name); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_file()\fR returns the \s-1BIO\s0 file method. As its name implies it -is a wrapper round the stdio \s-1FILE\s0 structure and it is a -source/sink \s-1BIO.\s0 -.PP -Calls to \fBBIO_read_ex()\fR and \fBBIO_write_ex()\fR read and write data to the -underlying stream. \fBBIO_gets()\fR and \fBBIO_puts()\fR are supported on file BIOs. -.PP -\&\fBBIO_flush()\fR on a file \s-1BIO\s0 calls the \fBfflush()\fR function on the wrapped -stream. -.PP -\&\fBBIO_reset()\fR attempts to change the file pointer to the start of file -using fseek(stream, 0, 0). -.PP -\&\fBBIO_seek()\fR sets the file pointer to position \fBofs\fR from start of file -using fseek(stream, ofs, 0). -.PP -\&\fBBIO_eof()\fR calls \fBfeof()\fR. -.PP -Setting the \s-1BIO_CLOSE\s0 flag calls \fBfclose()\fR on the stream when the \s-1BIO\s0 -is freed. -.PP -\&\fBBIO_new_file()\fR creates a new file \s-1BIO\s0 with mode \fBmode\fR the meaning -of \fBmode\fR is the same as the stdio function \fBfopen()\fR. The \s-1BIO_CLOSE\s0 -flag is set on the returned \s-1BIO.\s0 -.PP -\&\fBBIO_new_fp()\fR creates a file \s-1BIO\s0 wrapping \fBstream\fR. Flags can be: -\&\s-1BIO_CLOSE, BIO_NOCLOSE\s0 (the close flag) \s-1BIO_FP_TEXT\s0 (sets the underlying -stream to text mode, default is binary: this only has any effect under -Win32). -.PP -\&\fBBIO_set_fp()\fR sets the fp of a file \s-1BIO\s0 to \fBfp\fR. \fBflags\fR has the same -meaning as in \fBBIO_new_fp()\fR, it is a macro. -.PP -\&\fBBIO_get_fp()\fR retrieves the fp of a file \s-1BIO,\s0 it is a macro. -.PP -\&\fBBIO_seek()\fR is a macro that sets the position pointer to \fBoffset\fR bytes -from the start of file. -.PP -\&\fBBIO_tell()\fR returns the value of the position pointer. -.PP -\&\fBBIO_read_filename()\fR, \fBBIO_write_filename()\fR, \fBBIO_append_filename()\fR and -\&\fBBIO_rw_filename()\fR set the file \s-1BIO\s0 \fBb\fR to use file \fBname\fR for -reading, writing, append or read write respectively. -.SH "NOTES" -.IX Header "NOTES" -When wrapping stdout, stdin or stderr the underlying stream should not -normally be closed so the \s-1BIO_NOCLOSE\s0 flag should be set. -.PP -Because the file \s-1BIO\s0 calls the underlying stdio functions any quirks -in stdio behaviour will be mirrored by the corresponding \s-1BIO.\s0 -.PP -On Windows BIO_new_files reserves for the filename argument to be -\&\s-1UTF\-8\s0 encoded. In other words if you have to make it work in multi\- -lingual environment, encode filenames in \s-1UTF\-8.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_file()\fR returns the file \s-1BIO\s0 method. -.PP -\&\fBBIO_new_file()\fR and \fBBIO_new_fp()\fR return a file \s-1BIO\s0 or \s-1NULL\s0 if an error -occurred. -.PP -\&\fBBIO_set_fp()\fR and \fBBIO_get_fp()\fR return 1 for success or <=0 for failure -(although the current implementation never return 0). -.PP -\&\fBBIO_seek()\fR returns 0 for success or negative values for failure. -.PP -\&\fBBIO_tell()\fR returns the current file position or negative values for failure. -.PP -\&\fBBIO_read_filename()\fR, \fBBIO_write_filename()\fR, \fBBIO_append_filename()\fR and -\&\fBBIO_rw_filename()\fR return 1 for success or <=0 for failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -File \s-1BIO\s0 \*(L"hello world\*(R": -.PP -.Vb 1 -\& BIO *bio_out; -\& -\& bio_out = BIO_new_fp(stdout, BIO_NOCLOSE); -\& BIO_printf(bio_out, "Hello World\en"); -.Ve -.PP -Alternative technique: -.PP -.Vb 1 -\& BIO *bio_out; -\& -\& bio_out = BIO_new(BIO_s_file()); -\& if (bio_out == NULL) -\& /* Error */ -\& if (BIO_set_fp(bio_out, stdout, BIO_NOCLOSE) <= 0) -\& /* Error */ -\& BIO_printf(bio_out, "Hello World\en"); -.Ve -.PP -Write to a file: -.PP -.Vb 1 -\& BIO *out; -\& -\& out = BIO_new_file("filename.txt", "w"); -\& if (!out) -\& /* Error */ -\& BIO_printf(out, "Hello World\en"); -\& BIO_free(out); -.Ve -.PP -Alternative technique: -.PP -.Vb 1 -\& BIO *out; -\& -\& out = BIO_new(BIO_s_file()); -\& if (out == NULL) -\& /* Error */ -\& if (BIO_write_filename(out, "filename.txt") <= 0) -\& /* Error */ -\& BIO_printf(out, "Hello World\en"); -\& BIO_free(out); -.Ve -.SH "BUGS" -.IX Header "BUGS" -\&\fBBIO_reset()\fR and \fBBIO_seek()\fR are implemented using \fBfseek()\fR on the underlying -stream. The return value for \fBfseek()\fR is 0 for success or \-1 if an error -occurred this differs from other types of \s-1BIO\s0 which will typically return -1 for success and a non positive value if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_seek\fR\|(3), \fBBIO_tell\fR\|(3), -\&\fBBIO_reset\fR\|(3), \fBBIO_flush\fR\|(3), -\&\fBBIO_read_ex\fR\|(3), -\&\fBBIO_write_ex\fR\|(3), \fBBIO_puts\fR\|(3), -\&\fBBIO_gets\fR\|(3), \fBBIO_printf\fR\|(3), -\&\fBBIO_set_close\fR\|(3), \fBBIO_get_close\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_mem.3ossl b/openssl-install/share/man/man3/BIO_s_mem.3ossl deleted file mode 100644 index 60858b03..00000000 --- a/openssl-install/share/man/man3/BIO_s_mem.3ossl +++ /dev/null @@ -1,351 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_MEM 3ossl" -.TH BIO_S_MEM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_secmem, BIO_s_dgram_mem, -BIO_s_mem, BIO_set_mem_eof_return, BIO_get_mem_data, BIO_set_mem_buf, -BIO_get_mem_ptr, BIO_new_mem_buf \- memory BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_mem(void); -\& const BIO_METHOD *BIO_s_dgram_mem(void); -\& const BIO_METHOD *BIO_s_secmem(void); -\& -\& BIO_set_mem_eof_return(BIO *b, int v); -\& long BIO_get_mem_data(BIO *b, char **pp); -\& BIO_set_mem_buf(BIO *b, BUF_MEM *bm, int c); -\& BIO_get_mem_ptr(BIO *b, BUF_MEM **pp); -\& -\& BIO *BIO_new_mem_buf(const void *buf, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_mem()\fR returns the memory \s-1BIO\s0 method function. -.PP -A memory \s-1BIO\s0 is a source/sink \s-1BIO\s0 which uses memory for its I/O. Data -written to a memory \s-1BIO\s0 is stored in a \s-1BUF_MEM\s0 structure which is extended -as appropriate to accommodate the stored data. -.PP -\&\fBBIO_s_secmem()\fR is like \fBBIO_s_mem()\fR except that the secure heap is used -for buffer storage. -.PP -\&\fBBIO_s_dgram_mem()\fR is a memory \s-1BIO\s0 that respects datagram semantics. A single -call to \fBBIO_write\fR\|(3) will write a single datagram to the memory \s-1BIO. A\s0 -subsequent call to \fBBIO_read\fR\|(3) will read the data in that datagram. The -\&\fBBIO_read\fR\|(3) call will never return more data than was written in the original -\&\fBBIO_write\fR\|(3) call even if there were subsequent \fBBIO_write\fR\|(3) calls that -wrote more datagrams. Each successive call to \fBBIO_read\fR\|(3) will read the next -datagram. If a \fBBIO_read\fR\|(3) call supplies a read buffer that is smaller than -the size of the datagram, then the read buffer will be completely filled and the -remaining data from the datagram will be discarded. -.PP -It is not possible to write a zero length datagram. Calling \fBBIO_write\fR\|(3) in -this case will return 0 and no datagrams will be written. Calling \fBBIO_read\fR\|(3) -when there are no datagrams in the \s-1BIO\s0 to read will return a negative result and -the \*(L"retry\*(R" flags will be set (i.e. calling \fBBIO_should_retry\fR\|(3) will return -true). A datagram mem \s-1BIO\s0 will never return true from \fBBIO_eof\fR\|(3). -.PP -Any data written to a memory \s-1BIO\s0 can be recalled by reading from it. -Unless the memory \s-1BIO\s0 is read only any data read from it is deleted from -the \s-1BIO.\s0 -.PP -Memory BIOs except \fBBIO_s_dgram_mem()\fR support \fBBIO_gets()\fR and \fBBIO_puts()\fR. -.PP -\&\fBBIO_s_dgram_mem()\fR supports \fBBIO_sendmmsg\fR\|(3) and \fBBIO_recvmmsg\fR\|(3) calls -and calls related to \fB\s-1BIO_ADDR\s0\fR and \s-1MTU\s0 handling similarly to the -\&\fBBIO_s_dgram_pair\fR\|(3). -.PP -If the \s-1BIO_CLOSE\s0 flag is set when a memory \s-1BIO\s0 is freed then the underlying -\&\s-1BUF_MEM\s0 structure is also freed. -.PP -Calling \fBBIO_reset()\fR on a read write memory \s-1BIO\s0 clears any data in it if the -flag \s-1BIO_FLAGS_NONCLEAR_RST\s0 is not set, otherwise it just restores the read -pointer to the state it was just after the last write was performed and the -data can be read again. On a read only \s-1BIO\s0 it similarly restores the \s-1BIO\s0 to -its original state and the read only data can be read again. -.PP -\&\fBBIO_eof()\fR is true if no data is in the \s-1BIO.\s0 -.PP -\&\fBBIO_ctrl_pending()\fR returns the number of bytes currently stored. -.PP -\&\fBBIO_set_mem_eof_return()\fR sets the behaviour of memory \s-1BIO\s0 \fBb\fR when it is -empty. If the \fBv\fR is zero then an empty memory \s-1BIO\s0 will return \s-1EOF\s0 (that is -it will return zero and BIO_should_retry(b) will be false. If \fBv\fR is non -zero then it will return \fBv\fR when it is empty and it will set the read retry -flag (that is BIO_read_retry(b) is true). To avoid ambiguity with a normal -positive return value \fBv\fR should be set to a negative value, typically \-1. -Calling this macro will fail for datagram mem BIOs. -.PP -\&\fBBIO_get_mem_data()\fR sets *\fBpp\fR to a pointer to the start of the memory BIOs data -and returns the total amount of data available. It is implemented as a macro. -Note the pointer returned by this call is informative, no transfer of ownership -of this memory is implied. See notes on \fBBIO_set_close()\fR. -.PP -\&\fBBIO_set_mem_buf()\fR sets the internal \s-1BUF_MEM\s0 structure to \fBbm\fR and sets the -close flag to \fBc\fR, that is \fBc\fR should be either \s-1BIO_CLOSE\s0 or \s-1BIO_NOCLOSE.\s0 -It is a macro. -.PP -\&\fBBIO_get_mem_ptr()\fR places the underlying \s-1BUF_MEM\s0 structure in *\fBpp\fR. It is -a macro. -.PP -\&\fBBIO_new_mem_buf()\fR creates a memory \s-1BIO\s0 using \fBlen\fR bytes of data at \fBbuf\fR, -if \fBlen\fR is \-1 then the \fBbuf\fR is assumed to be nul terminated and its -length is determined by \fBstrlen\fR. The \s-1BIO\s0 is set to a read only state and -as a result cannot be written to. This is useful when some data needs to be -made available from a static area of memory in the form of a \s-1BIO.\s0 The -supplied data is read directly from the supplied buffer: it is \fBnot\fR copied -first, so the supplied area of memory must be unchanged until the \s-1BIO\s0 is freed. -.PP -All of the five functions described above return an error with -\&\fBBIO_s_dgram_mem()\fR. -.SH "NOTES" -.IX Header "NOTES" -Writes to memory BIOs will always succeed if memory is available: that is -their size can grow indefinitely. An exception is \fBBIO_s_dgram_mem()\fR when -\&\fBBIO_set_write_buf_size\fR\|(3) is called on it. In such case the write buffer -size will be fixed and any writes that would overflow the buffer will return -an error. -.PP -Every write after partial read (not all data in the memory buffer was read) -to a read write memory \s-1BIO\s0 will have to move the unread data with an internal -copy operation, if a \s-1BIO\s0 contains a lot of data and it is read in small -chunks intertwined with writes the operation can be very slow. Adding -a buffering \s-1BIO\s0 to the chain can speed up the process. -.PP -Calling \fBBIO_set_mem_buf()\fR on a secmem or dgram \s-1BIO\s0 will give undefined results, -including perhaps a program crash. -.PP -Switching a memory \s-1BIO\s0 from read write to read only is not supported and -can give undefined results including a program crash. There are two notable -exceptions to the rule. The first one is to assign a static memory buffer -immediately after \s-1BIO\s0 creation and set the \s-1BIO\s0 as read only. -.PP -The other supported sequence is to start with a read write \s-1BIO\s0 then temporarily -switch it to read only and call \fBBIO_reset()\fR on the read only \s-1BIO\s0 immediately -before switching it back to read write. Before the \s-1BIO\s0 is freed it must be -switched back to the read write mode. -.PP -Calling \fBBIO_get_mem_ptr()\fR on read only \s-1BIO\s0 will return a \s-1BUF_MEM\s0 that -contains only the remaining data to be read. If the close status of the -\&\s-1BIO\s0 is set to \s-1BIO_NOCLOSE,\s0 before freeing the \s-1BUF_MEM\s0 the data pointer -in it must be set to \s-1NULL\s0 as the data pointer does not point to an -allocated memory. -.PP -Calling \fBBIO_reset()\fR on a read write memory \s-1BIO\s0 with \s-1BIO_FLAGS_NONCLEAR_RST\s0 -flag set can have unexpected outcome when the reads and writes to the -\&\s-1BIO\s0 are intertwined. As documented above the \s-1BIO\s0 will be reset to the -state after the last completed write operation. The effects of reads -preceding that write operation cannot be undone. -.PP -Calling \fBBIO_get_mem_ptr()\fR prior to a \fBBIO_reset()\fR call with -\&\s-1BIO_FLAGS_NONCLEAR_RST\s0 set has the same effect as a write operation. -.PP -Calling \fBBIO_set_close()\fR with \s-1BIO_NOCLOSE\s0 orphans the \s-1BUF_MEM\s0 internal to the -\&\s-1BIO,\s0 _not_ its actual data buffer. See the examples section for the proper -method for claiming ownership of the data pointer for a deferred free operation. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_mem()\fR, \fBBIO_s_dgram_mem()\fR and \fBBIO_s_secmem()\fR return a valid memory -\&\fB\s-1BIO_METHOD\s0\fR structure. -.PP -\&\fBBIO_set_mem_eof_return()\fR, \fBBIO_set_mem_buf()\fR and \fBBIO_get_mem_ptr()\fR -return 1 on success or a value which is less than or equal to 0 if an error occurred. -.PP -\&\fBBIO_get_mem_data()\fR returns the total number of bytes available on success, -0 if b is \s-1NULL,\s0 or a negative value in case of other errors. -.PP -\&\fBBIO_new_mem_buf()\fR returns a valid \fB\s-1BIO\s0\fR structure on success or \s-1NULL\s0 on error. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a memory \s-1BIO\s0 and write some data to it: -.PP -.Vb 1 -\& BIO *mem = BIO_new(BIO_s_mem()); -\& -\& BIO_puts(mem, "Hello World\en"); -.Ve -.PP -Create a read only memory \s-1BIO:\s0 -.PP -.Vb 2 -\& char data[] = "Hello World"; -\& BIO *mem = BIO_new_mem_buf(data, \-1); -.Ve -.PP -Extract the \s-1BUF_MEM\s0 structure from a memory \s-1BIO\s0 and then free up the \s-1BIO:\s0 -.PP -.Vb 1 -\& BUF_MEM *bptr; -\& -\& BIO_get_mem_ptr(mem, &bptr); -\& BIO_set_close(mem, BIO_NOCLOSE); /* So BIO_free() leaves BUF_MEM alone */ -\& BIO_free(mem); -.Ve -.PP -Extract the \s-1BUF_MEM\s0 ptr, claim ownership of the internal data and free the \s-1BIO\s0 -and \s-1BUF_MEM\s0 structure: -.PP -.Vb 2 -\& BUF_MEM *bptr; -\& char *data; -\& -\& BIO_get_mem_data(bio, &data); -\& BIO_get_mem_ptr(bio, &bptr); -\& BIO_set_close(mem, BIO_NOCLOSE); /* So BIO_free orphans BUF_MEM */ -\& BIO_free(bio); -\& bptr\->data = NULL; /* Tell BUF_MEM to orphan data */ -\& BUF_MEM_free(bptr); -\& ... -\& free(data); -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_s_dgram_mem()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_null.3ossl b/openssl-install/share/man/man3/BIO_s_null.3ossl deleted file mode 100644 index ee0bc6ca..00000000 --- a/openssl-install/share/man/man3/BIO_s_null.3ossl +++ /dev/null @@ -1,176 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_NULL 3ossl" -.TH BIO_S_NULL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_null \- null data sink -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_null(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_null()\fR returns the null sink \s-1BIO\s0 method. Data written to -the null sink is discarded, reads return \s-1EOF.\s0 -.SH "NOTES" -.IX Header "NOTES" -A null sink \s-1BIO\s0 behaves in a similar manner to the Unix /dev/null -device. -.PP -A null bio can be placed on the end of a chain to discard any data -passed through it. -.PP -A null sink is useful if, for example, an application wishes to digest some -data by writing through a digest bio but not send the digested data anywhere. -Since a \s-1BIO\s0 chain must normally include a source/sink \s-1BIO\s0 this can be achieved -by adding a null sink \s-1BIO\s0 to the end of the chain -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_null()\fR returns the null sink \s-1BIO\s0 method. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_s_secmem.3ossl b/openssl-install/share/man/man3/BIO_s_secmem.3ossl deleted file mode 120000 index e9853704..00000000 --- a/openssl-install/share/man/man3/BIO_s_secmem.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_mem.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_s_socket.3ossl b/openssl-install/share/man/man3/BIO_s_socket.3ossl deleted file mode 100644 index 75d0ac64..00000000 --- a/openssl-install/share/man/man3/BIO_s_socket.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_S_SOCKET 3ossl" -.TH BIO_S_SOCKET 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_s_socket, BIO_new_socket \- socket BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIO_METHOD *BIO_s_socket(void); -\& -\& BIO *BIO_new_socket(int sock, int close_flag); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_s_socket()\fR returns the socket \s-1BIO\s0 method. This is a wrapper -round the platform's socket routines. -.PP -\&\fBBIO_read_ex()\fR and \fBBIO_write_ex()\fR read or write the underlying socket. -\&\fBBIO_puts()\fR is supported but \fBBIO_gets()\fR is not. -.PP -If the close flag is set then the socket is shut down and closed -when the \s-1BIO\s0 is freed. -.PP -\&\fBBIO_new_socket()\fR returns a socket \s-1BIO\s0 using \fBsock\fR and \fBclose_flag\fR. -.SH "NOTES" -.IX Header "NOTES" -Socket BIOs also support any relevant functionality of file descriptor -BIOs. -.PP -The reason for having separate file descriptor and socket BIOs is that on some -platforms sockets are not file descriptors and use distinct I/O routines, -Windows is one such platform. Any code mixing the two will not work on -all platforms. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_s_socket()\fR returns the socket \s-1BIO\s0 method. -.PP -\&\fBBIO_new_socket()\fR returns the newly allocated \s-1BIO\s0 or \s-1NULL\s0 is an error -occurred. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_seek.3ossl b/openssl-install/share/man/man3/BIO_seek.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_seek.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_sendmmsg.3ossl b/openssl-install/share/man/man3/BIO_sendmmsg.3ossl deleted file mode 100644 index ce44d784..00000000 --- a/openssl-install/share/man/man3/BIO_sendmmsg.3ossl +++ /dev/null @@ -1,350 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_SENDMMSG 3ossl" -.TH BIO_SENDMMSG 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_sendmmsg, BIO_recvmmsg, BIO_dgram_set_local_addr_enable, -BIO_dgram_get_local_addr_enable, BIO_dgram_get_local_addr_cap, -BIO_err_is_non_fatal \- send and receive multiple datagrams in a single call -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct bio_msg_st { -\& void *data; -\& size_t data_len; -\& BIO_ADDR *peer, *local; -\& uint64_t flags; -\& } BIO_MSG; -\& -\& int BIO_sendmmsg(BIO *b, BIO_MSG *msg, -\& size_t stride, size_t num_msg, uint64_t flags, -\& size_t *msgs_processed); -\& int BIO_recvmmsg(BIO *b, BIO_MSG *msg, -\& size_t stride, size_t num_msg, uint64_t flags, -\& size_t *msgs_processed); -\& -\& int BIO_dgram_set_local_addr_enable(BIO *b, int enable); -\& int BIO_dgram_get_local_addr_enable(BIO *b, int *enable); -\& int BIO_dgram_get_local_addr_cap(BIO *b); -\& int BIO_err_is_non_fatal(unsigned int errcode); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR functions can be used to send and receive -multiple messages in a single call to a \s-1BIO.\s0 They are analogous to \fBsendmmsg\fR\|(2) -and \fBrecvmmsg\fR\|(2) on operating systems which provide those functions. -.PP -The \fB\s-1BIO_MSG\s0\fR structure provides a subset of the functionality of the \fBstruct -msghdr\fR structure defined by \s-1POSIX.\s0 These functions accept an array of -\&\fB\s-1BIO_MSG\s0\fR structures. On any particular invocation, these functions may process -all of the passed structures, some of them, or none of them. This is indicated -by the value stored in \fI*msgs_processed\fR, which expresses the number of -messages processed. -.PP -The caller should set the \fIdata\fR member of a \fB\s-1BIO_MSG\s0\fR to a buffer containing -the data to send, or to be filled with a received message. \fIdata_len\fR should be -set to the size of the buffer in bytes. If the given \fB\s-1BIO_MSG\s0\fR is processed (in -other words, if the integer returned by the function is greater than or equal to -that \fB\s-1BIO_MSG\s0\fR's array index), \fIdata_len\fR will be modified to specify the -actual amount of data sent or received. -.PP -The \fIflags\fR field of a \fB\s-1BIO_MSG\s0\fR provides input per-message flags to the -invocation. If the invocation processes that \fB\s-1BIO_MSG\s0\fR, the \fIflags\fR field is -written with output per-message flags, or zero if no such flags are applicable. -.PP -Currently, no input or output per-message flags are defined and this field -should be set to zero before calling \fBBIO_sendmmsg()\fR or \fBBIO_recvmmsg()\fR. -.PP -The \fIflags\fR argument to \fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR provides global -flags which affect the entire invocation. No global flags are currently -defined and this argument should be set to zero. -.PP -When these functions are used to send and receive datagrams, the \fIpeer\fR field -of a \fB\s-1BIO_MSG\s0\fR allows the destination address of sent datagrams to be specified -on a per-datagram basis, and the source address of received datagrams to be -determined. The \fIpeer\fR field should be set to point to a \fB\s-1BIO_ADDR\s0\fR, which -will be read by \fBBIO_sendmmsg()\fR and used as the destination address for sent -datagrams, and written by \fBBIO_recvmmsg()\fR with the source address of received -datagrams. -.PP -Similarly, the \fIlocal\fR field of a \fB\s-1BIO_MSG\s0\fR allows the source address of sent -datagrams to be specified on a per-datagram basis, and the destination address -of received datagrams to be determined. Unlike \fIpeer\fR, support for \fIlocal\fR -must be explicitly enabled on a \fB\s-1BIO\s0\fR before it can be used; see -\&\fBBIO_dgram_set_local_addr_enable()\fR. If \fIlocal\fR is non-NULL in a \fB\s-1BIO_MSG\s0\fR and -support for \fIlocal\fR has not been enabled, processing of that \fB\s-1BIO_MSG\s0\fR fails. -.PP -\&\fIpeer\fR and \fIlocal\fR should be set to \s-1NULL\s0 if they are not required. Support for -\&\fIlocal\fR may not be available on all platforms; on these platforms, these -functions always fail if \fIlocal\fR is non-NULL. -.PP -If \fIlocal\fR is specified and local address support is enabled, but the operating -system does not report a local address for a specific received message, the -\&\fB\s-1BIO_ADDR\s0\fR it points to will be cleared (address family set to \f(CW\*(C`AF_UNSPEC\*(C'\fR). -This is known to happen on Windows when a packet is received which was sent by -the local system, regardless of whether the packet's destination address was the -loopback address or the \s-1IP\s0 address of a local non-loopback interface. This is -also known to happen on macOS in some circumstances, such as for packets sent -before local address support was enabled for a receiving socket. These are -OS-specific limitations. As such, users of this \s-1API\s0 using local address support -should expect to sometimes receive a cleared local \fB\s-1BIO_ADDR\s0\fR instead of the -correct value. -.PP -The \fIstride\fR argument must be set to \f(CW\*(C`sizeof(BIO_MSG)\*(C'\fR. This argument -facilitates backwards compatibility if fields are added to \fB\s-1BIO_MSG\s0\fR. Callers -must zero-initialize \fB\s-1BIO_MSG\s0\fR. -.PP -\&\fInum_msg\fR should be sent to the maximum number of messages to send or receive, -which is also the length of the array pointed to by \fImsg\fR. -.PP -\&\fImsgs_processed\fR must be non-NULL and points to an integer written with the -number of messages successfully processed; see the \s-1RETURN VALUES\s0 section for -further discussion. -.PP -Unlike most \s-1BIO\s0 functions, these functions explicitly support multi-threaded -use. Multiple concurrent writers and multiple concurrent readers of the same \s-1BIO\s0 -are permitted in any combination. As such, these functions do not clear, set, or -otherwise modify \s-1BIO\s0 retry flags. The return value must be used to determine -whether an operation should be retried; see below. -.PP -The support for concurrent use extends to \fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR -only, and no other function may be called on a given \s-1BIO\s0 while any call to -\&\fBBIO_sendmmsg()\fR or \fBBIO_recvmmsg()\fR is in progress, or vice versa. -.PP -\&\fBBIO_dgram_set_local_addr_enable()\fR and \fBBIO_dgram_get_local_addr_enable()\fR control -whether local address support is enabled. To enable local address support, call -\&\fBBIO_dgram_set_local_addr_enable()\fR with an argument of 1. The call will fail if -local address support is not available for the platform. -\&\fBBIO_dgram_get_local_addr_enable()\fR retrieves the value set by -\&\fBBIO_dgram_set_local_addr_enable()\fR. -.PP -\&\fBBIO_dgram_get_local_addr_cap()\fR determines if the \fB\s-1BIO\s0\fR is capable of supporting -local addresses. -.PP -\&\fBBIO_err_is_non_fatal()\fR determines if a packed error code represents an error -which is transient in nature. -.SH "NOTES" -.IX Header "NOTES" -Some implementations of the \fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR \s-1BIO\s0 methods might -always process at most one message at a time, for example when OS-level -functionality to transmit or receive multiple messages at a time is not -available. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -On success, the functions \fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR return 1 and write -the number of messages successfully processed (which need not be nonzero) to -\&\fImsgs_processed\fR. Where a positive value n is written to \fImsgs_processed\fR, all -entries in the \fB\s-1BIO_MSG\s0\fR array from 0 through n\-1 inclusive have their -\&\fIdata_len\fR and \fIflags\fR fields updated with the results of the operation on -that message. If the call was to \fBBIO_recvmmsg()\fR and the \fIpeer\fR or \fIlocal\fR -fields of that message are non-NULL, the \fB\s-1BIO_ADDR\s0\fR structures they point to -are written with the relevant address. -.PP -On failure, the functions \fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR return 0 and write -zero to \fImsgs_processed\fR. Thus \fImsgs_processed\fR is always written regardless -of the outcome of the function call. -.PP -If \fBBIO_sendmmsg()\fR and \fBBIO_recvmmsg()\fR fail, they always raise an \fB\s-1ERR_LIB_BIO\s0\fR -error using \fBERR_raise\fR\|(3). Any error may be raised, but the following in -particular may be noted: -.IP "\fB\s-1BIO_R_LOCAL_ADDR_NOT_AVAILABLE\s0\fR" 2 -.IX Item "BIO_R_LOCAL_ADDR_NOT_AVAILABLE" -The \fIlocal\fR field was set to a non-NULL value, but local address support is not -available or not enabled on the \s-1BIO.\s0 -.IP "\fB\s-1BIO_R_PEER_ADDR_NOT_AVAILABLE\s0\fR" 2 -.IX Item "BIO_R_PEER_ADDR_NOT_AVAILABLE" -The \fIpeer\fR field was set to a non-NULL value, but peer address support is not -available on the \s-1BIO.\s0 -.IP "\fB\s-1BIO_R_UNSUPPORTED_METHOD\s0\fR" 2 -.IX Item "BIO_R_UNSUPPORTED_METHOD" -The \fBBIO_sendmmsg()\fR or \fBBIO_recvmmsg()\fR method is not supported on the \s-1BIO.\s0 -.IP "\fB\s-1BIO_R_NON_FATAL\s0\fR" 2 -.IX Item "BIO_R_NON_FATAL" -The call failed due to a transient, non-fatal error (for example, because the -\&\s-1BIO\s0 is in nonblocking mode and the call would otherwise have blocked). -.Sp -Implementations of this interface which do not make system calls and thereby -pass through system error codes using \fB\s-1ERR_LIB_SYS\s0\fR (for example, memory-based -implementations) should issue this reason code to indicate a transient failure. -However, users of this interface should not test for this reason code directly, -as there are multiple possible packed error codes representing a transient -failure; use \fBBIO_err_is_non_fatal()\fR instead (discussed below). -.IP "Socket errors" 2 -.IX Item "Socket errors" -OS-level socket errors are reported using an error with library code -\&\fB\s-1ERR_LIB_SYS\s0\fR; for a packed error code \fBerrcode\fR where -\&\f(CW\*(C`ERR_SYSTEM_ERROR(errcode) == 1\*(C'\fR, the OS-level socket error code can be -retrieved using \f(CW\*(C`ERR_GET_REASON(errcode)\*(C'\fR. The packed error code can be -retrieved by calling \fBERR_peek_last_error\fR\|(3) after the call to \fBBIO_sendmmsg()\fR -or \fBBIO_recvmmsg()\fR returns 0. -.IP "Non-fatal errors" 2 -.IX Item "Non-fatal errors" -Whether an error is transient can be determined by passing the packed error code -to \fBBIO_err_is_non_fatal()\fR. Callers should do this instead of testing the reason -code directly, as there are many possible error codes which can indicate a -transient error, many of which are system specific. -.PP -Third parties implementing custom BIOs supporting the \fBBIO_sendmmsg()\fR or -\&\fBBIO_recvmmsg()\fR methods should note that it is a required part of the \s-1API\s0 -contract that an error is always raised when either of these functions return 0. -.PP -\&\fBBIO_dgram_set_local_addr_enable()\fR returns 1 if local address support was -successfully enabled or disabled and 0 otherwise. -.PP -\&\fBBIO_dgram_get_local_addr_enable()\fR returns 1 if the local address support enable -flag was successfully retrieved. -.PP -\&\fBBIO_dgram_get_local_addr_cap()\fR returns 1 if the \fB\s-1BIO\s0\fR can support local -addresses. -.PP -\&\fBBIO_err_is_non_fatal()\fR returns 1 if the passed packed error code represents an -error which is transient in nature. -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_set_accept_bios.3ossl b/openssl-install/share/man/man3/BIO_set_accept_bios.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_set_accept_bios.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_accept_ip_family.3ossl b/openssl-install/share/man/man3/BIO_set_accept_ip_family.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_set_accept_ip_family.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_accept_name.3ossl b/openssl-install/share/man/man3/BIO_set_accept_name.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_set_accept_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_accept_port.3ossl b/openssl-install/share/man/man3/BIO_set_accept_port.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_set_accept_port.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_app_data.3ossl b/openssl-install/share/man/man3/BIO_set_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/BIO_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_bind_mode.3ossl b/openssl-install/share/man/man3/BIO_set_bind_mode.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_set_bind_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_buffer_read_data.3ossl b/openssl-install/share/man/man3/BIO_set_buffer_read_data.3ossl deleted file mode 120000 index ad4704f1..00000000 --- a/openssl-install/share/man/man3/BIO_set_buffer_read_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_buffer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_buffer_size.3ossl b/openssl-install/share/man/man3/BIO_set_buffer_size.3ossl deleted file mode 120000 index ad4704f1..00000000 --- a/openssl-install/share/man/man3/BIO_set_buffer_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_buffer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_callback.3ossl b/openssl-install/share/man/man3/BIO_set_callback.3ossl deleted file mode 100644 index 7876f846..00000000 --- a/openssl-install/share/man/man3/BIO_set_callback.3ossl +++ /dev/null @@ -1,453 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_SET_CALLBACK 3ossl" -.TH BIO_SET_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_set_callback_ex, BIO_get_callback_ex, BIO_set_callback, BIO_get_callback, -BIO_set_callback_arg, BIO_get_callback_arg, BIO_debug_callback, -BIO_debug_callback_ex, BIO_callback_fn_ex, BIO_callback_fn -\&\- BIO callback functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef long (*BIO_callback_fn_ex)(BIO *b, int oper, const char *argp, -\& size_t len, int argi, -\& long argl, int ret, size_t *processed); -\& -\& void BIO_set_callback_ex(BIO *b, BIO_callback_fn_ex callback); -\& BIO_callback_fn_ex BIO_get_callback_ex(const BIO *b); -\& -\& void BIO_set_callback_arg(BIO *b, char *arg); -\& char *BIO_get_callback_arg(const BIO *b); -\& -\& long BIO_debug_callback_ex(BIO *bio, int oper, const char *argp, size_t len, -\& int argi, long argl, int ret, size_t *processed); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 6 -\& typedef long (*BIO_callback_fn)(BIO *b, int oper, const char *argp, int argi, -\& long argl, long ret); -\& void BIO_set_callback(BIO *b, BIO_callback_fn cb); -\& BIO_callback_fn BIO_get_callback(const BIO *b); -\& long BIO_debug_callback(BIO *bio, int cmd, const char *argp, int argi, -\& long argl, long ret); -\& -\& typedef struct bio_mmsg_cb_args_st { -\& BIO_MSG *msg; -\& size_t stride, num_msg; -\& uint64_t flags; -\& size_t *msgs_processed; -\& } BIO_MMSG_CB_ARGS; -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_set_callback_ex()\fR and \fBBIO_get_callback_ex()\fR set and retrieve the \s-1BIO\s0 -callback. The callback is called during most high-level \s-1BIO\s0 operations. It can -be used for debugging purposes to trace operations on a \s-1BIO\s0 or to modify its -operation. -.PP -\&\fBBIO_set_callback()\fR and \fBBIO_get_callback()\fR set and retrieve the old format \s-1BIO\s0 -callback. New code should not use these functions, but they are retained for -backwards compatibility. Any callback set via \fBBIO_set_callback_ex()\fR will get -called in preference to any set by \fBBIO_set_callback()\fR. -.PP -\&\fBBIO_set_callback_arg()\fR and \fBBIO_get_callback_arg()\fR are macros which can be -used to set and retrieve an argument for use in the callback. -.PP -\&\fBBIO_debug_callback_ex()\fR is a standard debugging callback which prints -out information relating to each \s-1BIO\s0 operation. If the callback -argument is set it is interpreted as a \s-1BIO\s0 to send the information -to, otherwise stderr is used. The \fBBIO_debug_callback()\fR function is the -deprecated version of the same callback for use with the old callback -format \fBBIO_set_callback()\fR function. -.PP -BIO_callback_fn_ex is the type of the callback function and BIO_callback_fn -is the type of the old format callback function. The meaning of each argument -is described below: -.IP "\fBb\fR" 4 -.IX Item "b" -The \s-1BIO\s0 the callback is attached to is passed in \fBb\fR. -.IP "\fBoper\fR" 4 -.IX Item "oper" -\&\fBoper\fR is set to the operation being performed. For some operations -the callback is called twice, once before and once after the actual -operation, the latter case has \fBoper\fR or'ed with \s-1BIO_CB_RETURN.\s0 -.IP "\fBlen\fR" 4 -.IX Item "len" -The length of the data requested to be read or written. This is only useful if -\&\fBoper\fR is \s-1BIO_CB_READ, BIO_CB_WRITE\s0 or \s-1BIO_CB_GETS.\s0 -.IP "\fBargp\fR \fBargi\fR \fBargl\fR" 4 -.IX Item "argp argi argl" -The meaning of the arguments \fBargp\fR, \fBargi\fR and \fBargl\fR depends on -the value of \fBoper\fR, that is the operation being performed. -.IP "\fBprocessed\fR" 4 -.IX Item "processed" -\&\fBprocessed\fR is a pointer to a location which will be updated with the amount of -data that was actually read or written. Only used for \s-1BIO_CB_READ, BIO_CB_WRITE, -BIO_CB_GETS\s0 and \s-1BIO_CB_PUTS.\s0 -.IP "\fBret\fR" 4 -.IX Item "ret" -\&\fBret\fR is the return value that would be returned to the -application if no callback were present. The actual value returned -is the return value of the callback itself. In the case of callbacks -called before the actual \s-1BIO\s0 operation 1 is placed in \fBret\fR, if -the return value is not positive it will be immediately returned to -the application and the \s-1BIO\s0 operation will not be performed. -.PP -The callback should normally simply return \fBret\fR when it has -finished processing, unless it specifically wishes to modify the -value returned to the application. -.SH "CALLBACK OPERATIONS" -.IX Header "CALLBACK OPERATIONS" -In the notes below, \fBcallback\fR defers to the actual callback -function that is called. -.IP "\fBBIO_free(b)\fR" 4 -.IX Item "BIO_free(b)" -.Vb 1 -\& callback_ex(b, BIO_CB_FREE, NULL, 0, 0, 0L, 1L, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_FREE, NULL, 0L, 0L, 1L) -.Ve -.Sp -is called before the free operation. -.IP "\fBBIO_read_ex(b, data, dlen, readbytes)\fR" 4 -.IX Item "BIO_read_ex(b, data, dlen, readbytes)" -.Vb 1 -\& callback_ex(b, BIO_CB_READ, data, dlen, 0, 0L, 1L, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_READ, data, dlen, 0L, 1L) -.Ve -.Sp -is called before the read and -.Sp -.Vb 2 -\& callback_ex(b, BIO_CB_READ | BIO_CB_RETURN, data, dlen, 0, 0L, retvalue, -\& &readbytes) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_READ|BIO_CB_RETURN, data, dlen, 0L, retvalue) -.Ve -.Sp -after. -.IP "\fBBIO_write(b, data, dlen, written)\fR" 4 -.IX Item "BIO_write(b, data, dlen, written)" -.Vb 1 -\& callback_ex(b, BIO_CB_WRITE, data, dlen, 0, 0L, 1L, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_WRITE, datat, dlen, 0L, 1L) -.Ve -.Sp -is called before the write and -.Sp -.Vb 2 -\& callback_ex(b, BIO_CB_WRITE | BIO_CB_RETURN, data, dlen, 0, 0L, retvalue, -\& &written) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_WRITE|BIO_CB_RETURN, data, dlen, 0L, retvalue) -.Ve -.Sp -after. -.IP "\fBBIO_gets(b, buf, size)\fR" 4 -.IX Item "BIO_gets(b, buf, size)" -.Vb 1 -\& callback_ex(b, BIO_CB_GETS, buf, size, 0, 0L, 1, NULL, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_GETS, buf, size, 0L, 1L) -.Ve -.Sp -is called before the operation and -.Sp -.Vb 2 -\& callback_ex(b, BIO_CB_GETS | BIO_CB_RETURN, buf, size, 0, 0L, retvalue, -\& &readbytes) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_GETS|BIO_CB_RETURN, buf, size, 0L, retvalue) -.Ve -.Sp -after. -.IP "\fBBIO_puts(b, buf)\fR" 4 -.IX Item "BIO_puts(b, buf)" -.Vb 1 -\& callback_ex(b, BIO_CB_PUTS, buf, 0, 0, 0L, 1L, NULL); -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_PUTS, buf, 0, 0L, 1L) -.Ve -.Sp -is called before the operation and -.Sp -.Vb 1 -\& callback_ex(b, BIO_CB_PUTS | BIO_CB_RETURN, buf, 0, 0, 0L, retvalue, &written) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_PUTS|BIO_CB_RETURN, buf, 0, 0L, retvalue) -.Ve -.Sp -after. -.IP "\fBBIO_ctrl(\s-1BIO\s0 *b, int cmd, long larg, void *parg)\fR" 4 -.IX Item "BIO_ctrl(BIO *b, int cmd, long larg, void *parg)" -.Vb 1 -\& callback_ex(b, BIO_CB_CTRL, parg, 0, cmd, larg, 1L, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_CTRL, parg, cmd, larg, 1L) -.Ve -.Sp -is called before the call and -.Sp -.Vb 1 -\& callback_ex(b, BIO_CB_CTRL | BIO_CB_RETURN, parg, 0, cmd, larg, ret, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_CTRL|BIO_CB_RETURN, parg, cmd, larg, ret) -.Ve -.Sp -after. -.Sp -Note: \fBcmd\fR == \fB\s-1BIO_CTRL_SET_CALLBACK\s0\fR is special, because \fBparg\fR is not the -argument of type \fBBIO_info_cb\fR itself. In this case \fBparg\fR is a pointer to -the actual call parameter, see \fBBIO_callback_ctrl\fR. -.IP "\fBBIO_sendmmsg(\s-1BIO\s0 *b, \s-1BIO_MSG\s0 *msg, size_t stride, size_t num_msg, uint64_t flags, size_t *msgs_processed)\fR" 4 -.IX Item "BIO_sendmmsg(BIO *b, BIO_MSG *msg, size_t stride, size_t num_msg, uint64_t flags, size_t *msgs_processed)" -.Vb 1 -\& callback_ex(b, BIO_CB_SENDMMSG, args, 0, 0, 0, 1, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_SENDMMSG, args, 0, 0, 1) -.Ve -.Sp -is called before the call and -.Sp -.Vb 1 -\& callback_ex(b, BIO_CB_SENDMMSG | BIO_CB_RETURN, args, ret, 0, 0, ret, NULL) -.Ve -.Sp -or -.Sp -.Vb 1 -\& callback(b, BIO_CB_SENDMMSG | BIO_CB_RETURN, args, ret, 0, 0, ret) -.Ve -.Sp -after. -.Sp -\&\fBargs\fR is a pointer to a \fB\s-1BIO_MMSG_CB_ARGS\s0\fR structure containing the arguments -passed to \fBBIO_sendmmsg()\fR. \fBret\fR is the return value of the \fBBIO_sendmmsg()\fR call. -The return value of \fBBIO_sendmmsg()\fR is altered to the value returned by the -\&\fB\s-1BIO_CB_SENDMMSG\s0 | \s-1BIO_CB_RETURN\s0\fR call. -.IP "\fBBIO_recvmmsg(\s-1BIO\s0 *b, \s-1BIO_MSG\s0 *msg, size_t stride, size_t num_msg, uint64_t flags, size_t *msgs_processed)\fR" 4 -.IX Item "BIO_recvmmsg(BIO *b, BIO_MSG *msg, size_t stride, size_t num_msg, uint64_t flags, size_t *msgs_processed)" -See the documentation for \fBBIO_sendmmsg()\fR. \fBBIO_recvmmsg()\fR works identically -except that \fB\s-1BIO_CB_RECVMMSG\s0\fR is used instead of \fB\s-1BIO_CB_SENDMMSG\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_get_callback_ex()\fR and \fBBIO_get_callback()\fR return the callback function -previously set by a call to \fBBIO_set_callback_ex()\fR and \fBBIO_set_callback()\fR -respectively. -.PP -\&\fBBIO_get_callback_arg()\fR returns a \fBchar\fR pointer to the value previously set -via a call to \fBBIO_set_callback_arg()\fR. -.PP -\&\fBBIO_debug_callback()\fR returns 1 or \fBret\fR if it's called after specific \s-1BIO\s0 -operations. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The \fBBIO_debug_callback_ex()\fR function is an example, its source is -in crypto/bio/bio_cb.c -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBIO_debug_callback_ex()\fR function was added in OpenSSL 3.0. -.PP -\&\fBBIO_set_callback()\fR, \fBBIO_get_callback()\fR, and \fBBIO_debug_callback()\fR were -deprecated in OpenSSL 3.0. Use the non-deprecated _ex functions instead. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_set_callback_arg.3ossl b/openssl-install/share/man/man3/BIO_set_callback_arg.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_set_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_callback_ex.3ossl b/openssl-install/share/man/man3/BIO_set_callback_ex.3ossl deleted file mode 120000 index decefafe..00000000 --- a/openssl-install/share/man/man3/BIO_set_callback_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_cipher.3ossl b/openssl-install/share/man/man3/BIO_set_cipher.3ossl deleted file mode 120000 index 15f4e6f1..00000000 --- a/openssl-install/share/man/man3/BIO_set_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_close.3ossl b/openssl-install/share/man/man3/BIO_set_close.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_set_close.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_conn_address.3ossl b/openssl-install/share/man/man3/BIO_set_conn_address.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_set_conn_address.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_conn_hostname.3ossl b/openssl-install/share/man/man3/BIO_set_conn_hostname.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_set_conn_hostname.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_conn_ip_family.3ossl b/openssl-install/share/man/man3/BIO_set_conn_ip_family.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_set_conn_ip_family.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_conn_mode.3ossl b/openssl-install/share/man/man3/BIO_set_conn_mode.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_set_conn_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_conn_port.3ossl b/openssl-install/share/man/man3/BIO_set_conn_port.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_set_conn_port.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_data.3ossl b/openssl-install/share/man/man3/BIO_set_data.3ossl deleted file mode 120000 index d0d51f6b..00000000 --- a/openssl-install/share/man/man3/BIO_set_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_ex_data.3ossl b/openssl-install/share/man/man3/BIO_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/BIO_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_fd.3ossl b/openssl-install/share/man/man3/BIO_set_fd.3ossl deleted file mode 120000 index 91a83843..00000000 --- a/openssl-install/share/man/man3/BIO_set_fd.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_fd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_fp.3ossl b/openssl-install/share/man/man3/BIO_set_fp.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_set_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_indent.3ossl b/openssl-install/share/man/man3/BIO_set_indent.3ossl deleted file mode 120000 index 324d0806..00000000 --- a/openssl-install/share/man/man3/BIO_set_indent.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_prefix.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_info_callback.3ossl b/openssl-install/share/man/man3/BIO_set_info_callback.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_set_info_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_init.3ossl b/openssl-install/share/man/man3/BIO_set_init.3ossl deleted file mode 120000 index d0d51f6b..00000000 --- a/openssl-install/share/man/man3/BIO_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_md.3ossl b/openssl-install/share/man/man3/BIO_set_md.3ossl deleted file mode 120000 index 1b4ea909..00000000 --- a/openssl-install/share/man/man3/BIO_set_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_mem_buf.3ossl b/openssl-install/share/man/man3/BIO_set_mem_buf.3ossl deleted file mode 120000 index e9853704..00000000 --- a/openssl-install/share/man/man3/BIO_set_mem_buf.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_mem.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_mem_eof_return.3ossl b/openssl-install/share/man/man3/BIO_set_mem_eof_return.3ossl deleted file mode 120000 index e9853704..00000000 --- a/openssl-install/share/man/man3/BIO_set_mem_eof_return.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_mem.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_nbio.3ossl b/openssl-install/share/man/man3/BIO_set_nbio.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_set_nbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_nbio_accept.3ossl b/openssl-install/share/man/man3/BIO_set_nbio_accept.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_set_nbio_accept.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_next.3ossl b/openssl-install/share/man/man3/BIO_set_next.3ossl deleted file mode 120000 index e6369f56..00000000 --- a/openssl-install/share/man/man3/BIO_set_next.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_push.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_prefix.3ossl b/openssl-install/share/man/man3/BIO_set_prefix.3ossl deleted file mode 120000 index 324d0806..00000000 --- a/openssl-install/share/man/man3/BIO_set_prefix.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_prefix.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_read_buffer_size.3ossl b/openssl-install/share/man/man3/BIO_set_read_buffer_size.3ossl deleted file mode 120000 index ad4704f1..00000000 --- a/openssl-install/share/man/man3/BIO_set_read_buffer_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_buffer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_retry_reason.3ossl b/openssl-install/share/man/man3/BIO_set_retry_reason.3ossl deleted file mode 120000 index d31b1c24..00000000 --- a/openssl-install/share/man/man3/BIO_set_retry_reason.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_should_retry.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_shutdown.3ossl b/openssl-install/share/man/man3/BIO_set_shutdown.3ossl deleted file mode 120000 index d0d51f6b..00000000 --- a/openssl-install/share/man/man3/BIO_set_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_sock_type.3ossl b/openssl-install/share/man/man3/BIO_set_sock_type.3ossl deleted file mode 120000 index a2c979c4..00000000 --- a/openssl-install/share/man/man3/BIO_set_sock_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_ssl.3ossl b/openssl-install/share/man/man3/BIO_set_ssl.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_set_ssl.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_ssl_mode.3ossl b/openssl-install/share/man/man3/BIO_set_ssl_mode.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_set_ssl_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_ssl_renegotiate_bytes.3ossl b/openssl-install/share/man/man3/BIO_set_ssl_renegotiate_bytes.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_set_ssl_renegotiate_bytes.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_ssl_renegotiate_timeout.3ossl b/openssl-install/share/man/man3/BIO_set_ssl_renegotiate_timeout.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_set_ssl_renegotiate_timeout.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_tfo.3ossl b/openssl-install/share/man/man3/BIO_set_tfo.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_set_tfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_tfo_accept.3ossl b/openssl-install/share/man/man3/BIO_set_tfo_accept.3ossl deleted file mode 120000 index 270988b0..00000000 --- a/openssl-install/share/man/man3/BIO_set_tfo_accept.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_accept.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_write_buf_size.3ossl b/openssl-install/share/man/man3/BIO_set_write_buf_size.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_set_write_buf_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_set_write_buffer_size.3ossl b/openssl-install/share/man/man3/BIO_set_write_buffer_size.3ossl deleted file mode 120000 index ad4704f1..00000000 --- a/openssl-install/share/man/man3/BIO_set_write_buffer_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_buffer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_should_io_special.3ossl b/openssl-install/share/man/man3/BIO_should_io_special.3ossl deleted file mode 120000 index d31b1c24..00000000 --- a/openssl-install/share/man/man3/BIO_should_io_special.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_should_retry.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_should_read.3ossl b/openssl-install/share/man/man3/BIO_should_read.3ossl deleted file mode 120000 index d31b1c24..00000000 --- a/openssl-install/share/man/man3/BIO_should_read.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_should_retry.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_should_retry.3ossl b/openssl-install/share/man/man3/BIO_should_retry.3ossl deleted file mode 100644 index 1e2c1aa7..00000000 --- a/openssl-install/share/man/man3/BIO_should_retry.3ossl +++ /dev/null @@ -1,276 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_SHOULD_RETRY 3ossl" -.TH BIO_SHOULD_RETRY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_should_read, BIO_should_write, -BIO_should_io_special, BIO_retry_type, BIO_should_retry, -BIO_get_retry_BIO, BIO_get_retry_reason, BIO_set_retry_reason \- BIO retry -functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BIO_should_read(BIO *b); -\& int BIO_should_write(BIO *b); -\& int BIO_should_io_special(iBIO *b); -\& int BIO_retry_type(BIO *b); -\& int BIO_should_retry(BIO *b); -\& -\& BIO *BIO_get_retry_BIO(BIO *bio, int *reason); -\& int BIO_get_retry_reason(BIO *bio); -\& void BIO_set_retry_reason(BIO *bio, int reason); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions determine why a \s-1BIO\s0 is not able to read or write data. -They will typically be called after a failed \fBBIO_read_ex()\fR or \fBBIO_write_ex()\fR -call. -.PP -\&\fBBIO_should_retry()\fR is true if the call that produced this condition -should then be retried at a later time. -.PP -If \fBBIO_should_retry()\fR is false then the cause is an error condition. -.PP -\&\fBBIO_should_read()\fR is true if the cause of the condition is that the \s-1BIO\s0 -has insufficient data to return. Check for readability and/or retry the -last operation. -.PP -\&\fBBIO_should_write()\fR is true if the cause of the condition is that the \s-1BIO\s0 -has pending data to write. Check for writability and/or retry the -last operation. -.PP -\&\fBBIO_should_io_special()\fR is true if some \*(L"special\*(R" condition, that is a -reason other than reading or writing is the cause of the condition. -.PP -\&\fBBIO_retry_type()\fR returns a mask of the cause of a retry condition -consisting of the values \fB\s-1BIO_FLAGS_READ\s0\fR, \fB\s-1BIO_FLAGS_WRITE\s0\fR, -\&\fB\s-1BIO_FLAGS_IO_SPECIAL\s0\fR though current \s-1BIO\s0 types will only set one of -these. -.PP -\&\fBBIO_get_retry_BIO()\fR determines the precise reason for the special -condition, it returns the \s-1BIO\s0 that caused this condition and if -\&\fBreason\fR is not \s-1NULL\s0 it contains the reason code. The meaning of -the reason code and the action that should be taken depends on -the type of \s-1BIO\s0 that resulted in this condition. -.PP -\&\fBBIO_get_retry_reason()\fR returns the reason for a special condition if -passed the relevant \s-1BIO,\s0 for example as returned by \fBBIO_get_retry_BIO()\fR. -.PP -\&\fBBIO_set_retry_reason()\fR sets the retry reason for a special condition for a given -\&\s-1BIO.\s0 This would usually only be called by \s-1BIO\s0 implementations. -.SH "NOTES" -.IX Header "NOTES" -\&\fBBIO_should_read()\fR, \fBBIO_should_write()\fR, \fBBIO_should_io_special()\fR, -\&\fBBIO_retry_type()\fR, and \fBBIO_should_retry()\fR, are implemented as macros. -.PP -If \fBBIO_should_retry()\fR returns false then the precise \*(L"error condition\*(R" -depends on the \s-1BIO\s0 type that caused it and the return code of the \s-1BIO\s0 -operation. For example if a call to \fBBIO_read_ex()\fR on a socket \s-1BIO\s0 returns -0 and \fBBIO_should_retry()\fR is false then the cause will be that the -connection closed. A similar condition on a file \s-1BIO\s0 will mean that it -has reached \s-1EOF.\s0 Some \s-1BIO\s0 types may place additional information on -the error queue. For more details see the individual \s-1BIO\s0 type manual -pages. -.PP -If the underlying I/O structure is in a blocking mode almost all current -\&\s-1BIO\s0 types will not request a retry, because the underlying I/O -calls will not. If the application knows that the \s-1BIO\s0 type will never -signal a retry then it need not call \fBBIO_should_retry()\fR after a failed -\&\s-1BIO I/O\s0 call. This is typically done with file BIOs. -.PP -\&\s-1SSL\s0 BIOs are the only current exception to this rule: they can request a -retry even if the underlying I/O structure is blocking, if a handshake -occurs during a call to \fBBIO_read()\fR. An application can retry the failed -call immediately or avoid this situation by setting \s-1SSL_MODE_AUTO_RETRY\s0 -on the underlying \s-1SSL\s0 structure. -.PP -While an application may retry a failed non blocking call immediately -this is likely to be very inefficient because the call will fail -repeatedly until data can be processed or is available. An application -will normally wait until the necessary condition is satisfied. How -this is done depends on the underlying I/O structure. -.PP -For example if the cause is ultimately a socket and \fBBIO_should_read()\fR -is true then a call to \fBselect()\fR may be made to wait until data is -available and then retry the \s-1BIO\s0 operation. By combining the retry -conditions of several non blocking BIOs in a single \fBselect()\fR call -it is possible to service several BIOs in a single thread, though -the performance may be poor if \s-1SSL\s0 BIOs are present because long delays -can occur during the initial handshake process. -.PP -It is possible for a \s-1BIO\s0 to block indefinitely if the underlying I/O -structure cannot process or return any data. This depends on the behaviour of -the platforms I/O functions. This is often not desirable: one solution -is to use non blocking I/O and use a timeout on the \fBselect()\fR (or -equivalent) call. -.SH "BUGS" -.IX Header "BUGS" -The OpenSSL \s-1ASN1\s0 functions cannot gracefully deal with non blocking I/O: -that is they cannot retry after a partial read or write. This is usually -worked around by only passing the relevant data to \s-1ASN1\s0 functions when -the entire structure can be read or written. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_should_read()\fR, \fBBIO_should_write()\fR, \fBBIO_should_io_special()\fR, and -\&\fBBIO_should_retry()\fR return either 1 or 0 based on the actual conditions -of the \fB\s-1BIO\s0\fR. -.PP -\&\fBBIO_retry_type()\fR returns a flag combination presenting the cause of a retry -condition or false if there is no retry condition. -.PP -\&\fBBIO_get_retry_BIO()\fR returns a valid \fB\s-1BIO\s0\fR structure. -.PP -\&\fBBIO_get_retry_reason()\fR returns the reason for a special condition. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBIO_get_retry_reason()\fR and \fBBIO_set_retry_reason()\fR functions were added in -OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_should_write.3ossl b/openssl-install/share/man/man3/BIO_should_write.3ossl deleted file mode 120000 index d31b1c24..00000000 --- a/openssl-install/share/man/man3/BIO_should_write.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_should_retry.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_shutdown_wr.3ossl b/openssl-install/share/man/man3/BIO_shutdown_wr.3ossl deleted file mode 120000 index f079f5ea..00000000 --- a/openssl-install/share/man/man3/BIO_shutdown_wr.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_snprintf.3ossl b/openssl-install/share/man/man3/BIO_snprintf.3ossl deleted file mode 120000 index a68b8001..00000000 --- a/openssl-install/share/man/man3/BIO_snprintf.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_printf.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_socket.3ossl b/openssl-install/share/man/man3/BIO_socket.3ossl deleted file mode 120000 index 10175c59..00000000 --- a/openssl-install/share/man/man3/BIO_socket.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_connect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_socket_wait.3ossl b/openssl-install/share/man/man3/BIO_socket_wait.3ossl deleted file mode 100644 index 7b78b1ef..00000000 --- a/openssl-install/share/man/man3/BIO_socket_wait.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO_SOCKET_WAIT 3ossl" -.TH BIO_SOCKET_WAIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BIO_socket_wait, -BIO_wait, -BIO_do_connect_retry -\&\- BIO connection utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #ifndef OPENSSL_NO_SOCK -\& int BIO_socket_wait(int fd, int for_read, time_t max_time); -\& #endif -\& int BIO_wait(BIO *bio, time_t max_time, unsigned int nap_milliseconds); -\& int BIO_do_connect_retry(BIO *bio, int timeout, int nap_milliseconds); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBIO_socket_wait()\fR waits on the socket \fBfd\fR for reading if \fBfor_read\fR is not 0, -else for writing, at most until \fBmax_time\fR. -It succeeds immediately if \fBmax_time\fR == 0 (which means no timeout given). -.PP -\&\fBBIO_wait()\fR waits at most until \fBmax_time\fR on the given (typically socket-based) -\&\fBbio\fR, for reading if \fBbio\fR is supposed to read, else for writing. -It is used by \fBBIO_do_connect_retry()\fR and can be used together \fBBIO_read\fR\|(3). -It succeeds immediately if \fBmax_time\fR == 0 (which means no timeout given). -If sockets are not available it supports polling by succeeding after sleeping -at most the given \fBnap_milliseconds\fR in order to avoid a tight busy loop. -Via \fBnap_milliseconds\fR the caller determines the polling granularity. -.PP -\&\fBBIO_do_connect_retry()\fR connects via the given \fBbio\fR. -It retries \fBBIO_do_connect()\fR as far as needed to reach a definite outcome, -i.e., connection succeeded, timeout has been reached, or an error occurred. -For nonblocking and potentially even non-socket BIOs it polls -every \fBnap_milliseconds\fR and sleeps in between using \fBBIO_wait()\fR. -If \fBnap_milliseconds\fR is < 0 then a default value of 100 ms is used. -If the \fBtimeout\fR parameter is > 0 this indicates the maximum number of seconds -to wait until the connection is established or a definite error occurred. -A value of 0 enables waiting indefinitely (i.e, no timeout), -while a value < 0 means that \fBBIO_do_connect()\fR is tried only once. -The function may, directly or indirectly, invoke \fBERR_clear_error()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBIO_socket_wait()\fR, \fBBIO_wait()\fR, and \fBBIO_do_connect_retry()\fR -return \-1 on error, 0 on timeout, and 1 on success. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_do_connect\fR\|(3), \fBBIO_read\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBIO_socket_wait()\fR, \fBBIO_wait()\fR, and \fBBIO_do_connect_retry()\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BIO_ssl_copy_session_id.3ossl b/openssl-install/share/man/man3/BIO_ssl_copy_session_id.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_ssl_copy_session_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_ssl_shutdown.3ossl b/openssl-install/share/man/man3/BIO_ssl_shutdown.3ossl deleted file mode 120000 index b2cef1e9..00000000 --- a/openssl-install/share/man/man3/BIO_ssl_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_f_ssl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_tell.3ossl b/openssl-install/share/man/man3/BIO_tell.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_tell.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_up_ref.3ossl b/openssl-install/share/man/man3/BIO_up_ref.3ossl deleted file mode 120000 index 9126d49b..00000000 --- a/openssl-install/share/man/man3/BIO_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_vfree.3ossl b/openssl-install/share/man/man3/BIO_vfree.3ossl deleted file mode 120000 index 9126d49b..00000000 --- a/openssl-install/share/man/man3/BIO_vfree.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_vprintf.3ossl b/openssl-install/share/man/man3/BIO_vprintf.3ossl deleted file mode 120000 index a68b8001..00000000 --- a/openssl-install/share/man/man3/BIO_vprintf.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_printf.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_vsnprintf.3ossl b/openssl-install/share/man/man3/BIO_vsnprintf.3ossl deleted file mode 120000 index a68b8001..00000000 --- a/openssl-install/share/man/man3/BIO_vsnprintf.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_printf.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_wait.3ossl b/openssl-install/share/man/man3/BIO_wait.3ossl deleted file mode 120000 index 32dfdab8..00000000 --- a/openssl-install/share/man/man3/BIO_wait.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_socket_wait.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_wpending.3ossl b/openssl-install/share/man/man3/BIO_wpending.3ossl deleted file mode 120000 index 52a9b459..00000000 --- a/openssl-install/share/man/man3/BIO_wpending.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_write.3ossl b/openssl-install/share/man/man3/BIO_write.3ossl deleted file mode 120000 index 688d3c98..00000000 --- a/openssl-install/share/man/man3/BIO_write.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_write_ex.3ossl b/openssl-install/share/man/man3/BIO_write_ex.3ossl deleted file mode 120000 index 688d3c98..00000000 --- a/openssl-install/share/man/man3/BIO_write_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BIO_write_filename.3ossl b/openssl-install/share/man/man3/BIO_write_filename.3ossl deleted file mode 120000 index 931738ba..00000000 --- a/openssl-install/share/man/man3/BIO_write_filename.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_s_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_convert.3ossl b/openssl-install/share/man/man3/BN_BLINDING_convert.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_convert.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_convert_ex.3ossl b/openssl-install/share/man/man3/BN_BLINDING_convert_ex.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_convert_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_create_param.3ossl b/openssl-install/share/man/man3/BN_BLINDING_create_param.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_create_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_free.3ossl b/openssl-install/share/man/man3/BN_BLINDING_free.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_get_flags.3ossl b/openssl-install/share/man/man3/BN_BLINDING_get_flags.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_invert.3ossl b/openssl-install/share/man/man3/BN_BLINDING_invert.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_invert.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_invert_ex.3ossl b/openssl-install/share/man/man3/BN_BLINDING_invert_ex.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_invert_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_is_current_thread.3ossl b/openssl-install/share/man/man3/BN_BLINDING_is_current_thread.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_is_current_thread.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_lock.3ossl b/openssl-install/share/man/man3/BN_BLINDING_lock.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_lock.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_new.3ossl b/openssl-install/share/man/man3/BN_BLINDING_new.3ossl deleted file mode 100644 index f6780e2c..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_new.3ossl +++ /dev/null @@ -1,258 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_BLINDING_NEW 3ossl" -.TH BN_BLINDING_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_BLINDING_new, BN_BLINDING_free, BN_BLINDING_update, BN_BLINDING_convert, -BN_BLINDING_invert, BN_BLINDING_convert_ex, BN_BLINDING_invert_ex, -BN_BLINDING_is_current_thread, BN_BLINDING_set_current_thread, -BN_BLINDING_lock, BN_BLINDING_unlock, BN_BLINDING_get_flags, -BN_BLINDING_set_flags, BN_BLINDING_create_param \- blinding related BIGNUM functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BN_BLINDING *BN_BLINDING_new(const BIGNUM *A, const BIGNUM *Ai, -\& BIGNUM *mod); -\& void BN_BLINDING_free(BN_BLINDING *b); -\& int BN_BLINDING_update(BN_BLINDING *b, BN_CTX *ctx); -\& int BN_BLINDING_convert(BIGNUM *n, BN_BLINDING *b, BN_CTX *ctx); -\& int BN_BLINDING_invert(BIGNUM *n, BN_BLINDING *b, BN_CTX *ctx); -\& int BN_BLINDING_convert_ex(BIGNUM *n, BIGNUM *r, BN_BLINDING *b, -\& BN_CTX *ctx); -\& int BN_BLINDING_invert_ex(BIGNUM *n, const BIGNUM *r, BN_BLINDING *b, -\& BN_CTX *ctx); -\& int BN_BLINDING_is_current_thread(BN_BLINDING *b); -\& void BN_BLINDING_set_current_thread(BN_BLINDING *b); -\& int BN_BLINDING_lock(BN_BLINDING *b); -\& int BN_BLINDING_unlock(BN_BLINDING *b); -\& unsigned long BN_BLINDING_get_flags(const BN_BLINDING *b); -\& void BN_BLINDING_set_flags(BN_BLINDING *b, unsigned long flags); -\& BN_BLINDING *BN_BLINDING_create_param(BN_BLINDING *b, -\& const BIGNUM *e, BIGNUM *m, BN_CTX *ctx, -\& int (*bn_mod_exp)(BIGNUM *r, -\& const BIGNUM *a, -\& const BIGNUM *p, -\& const BIGNUM *m, -\& BN_CTX *ctx, -\& BN_MONT_CTX *m_ctx), -\& BN_MONT_CTX *m_ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_BLINDING_new()\fR allocates a new \fB\s-1BN_BLINDING\s0\fR structure and copies -the \fBA\fR and \fBAi\fR values into the newly created \fB\s-1BN_BLINDING\s0\fR object. -.PP -\&\fBBN_BLINDING_free()\fR frees the \fB\s-1BN_BLINDING\s0\fR structure. -If \fBb\fR is \s-1NULL,\s0 nothing is done. -.PP -\&\fBBN_BLINDING_update()\fR updates the \fB\s-1BN_BLINDING\s0\fR parameters by squaring -the \fBA\fR and \fBAi\fR or, after specific number of uses and if the -necessary parameters are set, by re-creating the blinding parameters. -.PP -\&\fBBN_BLINDING_convert_ex()\fR multiplies \fBn\fR with the blinding factor \fBA\fR. -If \fBr\fR is not \s-1NULL\s0 a copy the inverse blinding factor \fBAi\fR will be -returned in \fBr\fR (this is useful if a \fB\s-1RSA\s0\fR object is shared among -several threads). \fBBN_BLINDING_invert_ex()\fR multiplies \fBn\fR with the -inverse blinding factor \fBAi\fR. If \fBr\fR is not \s-1NULL\s0 it will be used as -the inverse blinding. -.PP -\&\fBBN_BLINDING_convert()\fR and \fBBN_BLINDING_invert()\fR are wrapper -functions for \fBBN_BLINDING_convert_ex()\fR and \fBBN_BLINDING_invert_ex()\fR -with \fBr\fR set to \s-1NULL.\s0 -.PP -\&\fBBN_BLINDING_is_current_thread()\fR returns whether the \fB\s-1BN_BLINDING\s0\fR -structure is owned by the current thread. This is to help users -provide proper locking if needed for multi-threaded use. -.PP -\&\fBBN_BLINDING_set_current_thread()\fR sets the current thread as the -owner of the \fB\s-1BN_BLINDING\s0\fR structure. -.PP -\&\fBBN_BLINDING_lock()\fR locks the \fB\s-1BN_BLINDING\s0\fR structure. -.PP -\&\fBBN_BLINDING_unlock()\fR unlocks the \fB\s-1BN_BLINDING\s0\fR structure. -.PP -\&\fBBN_BLINDING_get_flags()\fR returns the \s-1BN_BLINDING\s0 flags. Currently -there are two supported flags: \fB\s-1BN_BLINDING_NO_UPDATE\s0\fR and -\&\fB\s-1BN_BLINDING_NO_RECREATE\s0\fR. \fB\s-1BN_BLINDING_NO_UPDATE\s0\fR inhibits the -automatic update of the \fB\s-1BN_BLINDING\s0\fR parameters after each use -and \fB\s-1BN_BLINDING_NO_RECREATE\s0\fR inhibits the automatic re-creation -of the \fB\s-1BN_BLINDING\s0\fR parameters after a fixed number of uses (currently -32). In newly allocated \fB\s-1BN_BLINDING\s0\fR objects no flags are set. -\&\fBBN_BLINDING_set_flags()\fR sets the \fB\s-1BN_BLINDING\s0\fR parameters flags. -.PP -\&\fBBN_BLINDING_create_param()\fR creates new \fB\s-1BN_BLINDING\s0\fR parameters -using the exponent \fBe\fR and the modulus \fBm\fR. \fBbn_mod_exp\fR and -\&\fBm_ctx\fR can be used to pass special functions for exponentiation -(normally \fBBN_mod_exp_mont()\fR and \fB\s-1BN_MONT_CTX\s0\fR). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_BLINDING_new()\fR returns the newly allocated \fB\s-1BN_BLINDING\s0\fR structure -or \s-1NULL\s0 in case of an error. -.PP -\&\fBBN_BLINDING_update()\fR, \fBBN_BLINDING_convert()\fR, \fBBN_BLINDING_invert()\fR, -\&\fBBN_BLINDING_convert_ex()\fR and \fBBN_BLINDING_invert_ex()\fR return 1 on -success and 0 if an error occurred. -.PP -\&\fBBN_BLINDING_is_current_thread()\fR returns 1 if the current thread owns -the \fB\s-1BN_BLINDING\s0\fR object, 0 otherwise. -.PP -\&\fBBN_BLINDING_set_current_thread()\fR doesn't return anything. -.PP -\&\fBBN_BLINDING_lock()\fR, \fBBN_BLINDING_unlock()\fR return 1 if the operation -succeeded or 0 on error. -.PP -\&\fBBN_BLINDING_get_flags()\fR returns the currently set \fB\s-1BN_BLINDING\s0\fR flags -(a \fBunsigned long\fR value). -.PP -\&\fBBN_BLINDING_create_param()\fR returns the newly created \fB\s-1BN_BLINDING\s0\fR -parameters or \s-1NULL\s0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBN_BLINDING_thread_id()\fR was first introduced in OpenSSL 1.0.0, and it -deprecates \fBBN_BLINDING_set_thread_id()\fR and \fBBN_BLINDING_get_thread_id()\fR. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2005\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_BLINDING_set_current_thread.3ossl b/openssl-install/share/man/man3/BN_BLINDING_set_current_thread.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_set_current_thread.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_set_flags.3ossl b/openssl-install/share/man/man3/BN_BLINDING_set_flags.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_unlock.3ossl b/openssl-install/share/man/man3/BN_BLINDING_unlock.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_unlock.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_BLINDING_update.3ossl b/openssl-install/share/man/man3/BN_BLINDING_update.3ossl deleted file mode 120000 index 20e602d5..00000000 --- a/openssl-install/share/man/man3/BN_BLINDING_update.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_BLINDING_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_CTX_end.3ossl b/openssl-install/share/man/man3/BN_CTX_end.3ossl deleted file mode 120000 index 37d60084..00000000 --- a/openssl-install/share/man/man3/BN_CTX_end.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_CTX_start.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_CTX_free.3ossl b/openssl-install/share/man/man3/BN_CTX_free.3ossl deleted file mode 120000 index bf57cc8b..00000000 --- a/openssl-install/share/man/man3/BN_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_CTX_get.3ossl b/openssl-install/share/man/man3/BN_CTX_get.3ossl deleted file mode 120000 index 37d60084..00000000 --- a/openssl-install/share/man/man3/BN_CTX_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_CTX_start.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_CTX_new.3ossl b/openssl-install/share/man/man3/BN_CTX_new.3ossl deleted file mode 100644 index e66d61d1..00000000 --- a/openssl-install/share/man/man3/BN_CTX_new.3ossl +++ /dev/null @@ -1,223 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_CTX_NEW 3ossl" -.TH BN_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_CTX_new_ex, BN_CTX_new, BN_CTX_secure_new_ex, BN_CTX_secure_new, BN_CTX_free -\&\- allocate and free BN_CTX structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BN_CTX *BN_CTX_new_ex(OSSL_LIB_CTX *ctx); -\& BN_CTX *BN_CTX_new(void); -\& -\& BN_CTX *BN_CTX_secure_new_ex(OSSL_LIB_CTX *ctx); -\& BN_CTX *BN_CTX_secure_new(void); -\& -\& void BN_CTX_free(BN_CTX *c); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A \fB\s-1BN_CTX\s0\fR is a structure that holds \fB\s-1BIGNUM\s0\fR temporary variables used by -library functions. Since dynamic memory allocation to create \fB\s-1BIGNUM\s0\fRs -is rather expensive when used in conjunction with repeated subroutine -calls, the \fB\s-1BN_CTX\s0\fR structure is used. -.PP -\&\fBBN_CTX_new_ex()\fR allocates and initializes a \fB\s-1BN_CTX\s0\fR structure for the given -library context \fBctx\fR. The value may be \s-1NULL\s0 in which case the default -library context will be used. \fBBN_CTX_new()\fR is the same as \fBBN_CTX_new_ex()\fR except -that the default library context is always used. -.PP -\&\fBBN_CTX_secure_new_ex()\fR allocates and initializes a \fB\s-1BN_CTX\s0\fR structure -but uses the secure heap (see \fBCRYPTO_secure_malloc\fR\|(3)) to hold the -\&\fB\s-1BIGNUM\s0\fRs for the given library context \fBctx\fR. The value may be \s-1NULL\s0 in -which case the default library context will be used. \fBBN_CTX_secure_new()\fR is the -same as \fBBN_CTX_secure_new_ex()\fR except that the default library context is always -used. -.PP -\&\fBBN_CTX_free()\fR frees the components of the \fB\s-1BN_CTX\s0\fR and the structure itself. -Since \fBBN_CTX_start()\fR is required in order to obtain \fB\s-1BIGNUM\s0\fRs from the -\&\fB\s-1BN_CTX\s0\fR, in most cases \fBBN_CTX_end()\fR must be called before the \fB\s-1BN_CTX\s0\fR may -be freed by \fBBN_CTX_free()\fR. If \fBc\fR is \s-1NULL,\s0 nothing is done. -.PP -A given \fB\s-1BN_CTX\s0\fR must only be used by a single thread of execution. No -locking is performed, and the internal pool allocator will not properly handle -multiple threads of execution. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_CTX_new()\fR and \fBBN_CTX_secure_new()\fR return a pointer to the \fB\s-1BN_CTX\s0\fR. -If the allocation fails, -they return \fB\s-1NULL\s0\fR and sets an error code that can be obtained by -\&\fBERR_get_error\fR\|(3). -.PP -\&\fBBN_CTX_free()\fR has no return values. -.SH "REMOVED FUNCTIONALITY" -.IX Header "REMOVED FUNCTIONALITY" -.Vb 1 -\& void BN_CTX_init(BN_CTX *c); -.Ve -.PP -\&\fBBN_CTX_init()\fR is no longer available as of OpenSSL 1.1.0. Applications should -replace use of BN_CTX_init with BN_CTX_new instead: -.PP -.Vb 6 -\& BN_CTX *ctx; -\& ctx = BN_CTX_new(); -\& if (!ctx) -\& /* error */ -\& ... -\& BN_CTX_free(ctx); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_add\fR\|(3), -\&\fBBN_CTX_start\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBN_CTX_init()\fR was removed in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_CTX_new_ex.3ossl b/openssl-install/share/man/man3/BN_CTX_new_ex.3ossl deleted file mode 120000 index bf57cc8b..00000000 --- a/openssl-install/share/man/man3/BN_CTX_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_CTX_secure_new.3ossl b/openssl-install/share/man/man3/BN_CTX_secure_new.3ossl deleted file mode 120000 index bf57cc8b..00000000 --- a/openssl-install/share/man/man3/BN_CTX_secure_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_CTX_secure_new_ex.3ossl b/openssl-install/share/man/man3/BN_CTX_secure_new_ex.3ossl deleted file mode 120000 index bf57cc8b..00000000 --- a/openssl-install/share/man/man3/BN_CTX_secure_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_CTX_start.3ossl b/openssl-install/share/man/man3/BN_CTX_start.3ossl deleted file mode 100644 index 1c4da268..00000000 --- a/openssl-install/share/man/man3/BN_CTX_start.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_CTX_START 3ossl" -.TH BN_CTX_START 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_CTX_start, BN_CTX_get, BN_CTX_end \- use temporary BIGNUM variables -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void BN_CTX_start(BN_CTX *ctx); -\& -\& BIGNUM *BN_CTX_get(BN_CTX *ctx); -\& -\& void BN_CTX_end(BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are used to obtain temporary \fB\s-1BIGNUM\s0\fR variables from -a \fB\s-1BN_CTX\s0\fR (which can been created by using \fBBN_CTX_new\fR\|(3)) -in order to save the overhead of repeatedly creating and -freeing \fB\s-1BIGNUM\s0\fRs in functions that are called from inside a loop. -.PP -A function must call \fBBN_CTX_start()\fR first. Then, \fBBN_CTX_get()\fR may be -called repeatedly to obtain temporary \fB\s-1BIGNUM\s0\fRs. All \fBBN_CTX_get()\fR -calls must be made before calling any other functions that use the -\&\fBctx\fR as an argument. -.PP -Finally, \fBBN_CTX_end()\fR must be called before returning from the function. -If \fBctx\fR is \s-1NULL,\s0 nothing is done. -When \fBBN_CTX_end()\fR is called, the \fB\s-1BIGNUM\s0\fR pointers obtained from -\&\fBBN_CTX_get()\fR become invalid. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_CTX_start()\fR and \fBBN_CTX_end()\fR return no values. -.PP -\&\fBBN_CTX_get()\fR returns a pointer to the \fB\s-1BIGNUM\s0\fR, or \fB\s-1NULL\s0\fR on error. -Once \fBBN_CTX_get()\fR has failed, the subsequent calls will return \fB\s-1NULL\s0\fR -as well, so it is sufficient to check the return value of the last -\&\fBBN_CTX_get()\fR call. In case of an error, an error code is set, which -can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBN_CTX_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_GENCB_call.3ossl b/openssl-install/share/man/man3/BN_GENCB_call.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_GENCB_call.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_GENCB_free.3ossl b/openssl-install/share/man/man3/BN_GENCB_free.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_GENCB_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_GENCB_get_arg.3ossl b/openssl-install/share/man/man3/BN_GENCB_get_arg.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_GENCB_get_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_GENCB_new.3ossl b/openssl-install/share/man/man3/BN_GENCB_new.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_GENCB_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_GENCB_set.3ossl b/openssl-install/share/man/man3/BN_GENCB_set.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_GENCB_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_GENCB_set_old.3ossl b/openssl-install/share/man/man3/BN_GENCB_set_old.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_GENCB_set_old.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_MONT_CTX_copy.3ossl b/openssl-install/share/man/man3/BN_MONT_CTX_copy.3ossl deleted file mode 120000 index 09d3a815..00000000 --- a/openssl-install/share/man/man3/BN_MONT_CTX_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_montgomery.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_MONT_CTX_free.3ossl b/openssl-install/share/man/man3/BN_MONT_CTX_free.3ossl deleted file mode 120000 index 09d3a815..00000000 --- a/openssl-install/share/man/man3/BN_MONT_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_montgomery.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_MONT_CTX_new.3ossl b/openssl-install/share/man/man3/BN_MONT_CTX_new.3ossl deleted file mode 120000 index 09d3a815..00000000 --- a/openssl-install/share/man/man3/BN_MONT_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_montgomery.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_MONT_CTX_set.3ossl b/openssl-install/share/man/man3/BN_MONT_CTX_set.3ossl deleted file mode 120000 index 09d3a815..00000000 --- a/openssl-install/share/man/man3/BN_MONT_CTX_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_montgomery.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_RECP_CTX_free.3ossl b/openssl-install/share/man/man3/BN_RECP_CTX_free.3ossl deleted file mode 120000 index 2e40b44b..00000000 --- a/openssl-install/share/man/man3/BN_RECP_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_reciprocal.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_RECP_CTX_new.3ossl b/openssl-install/share/man/man3/BN_RECP_CTX_new.3ossl deleted file mode 120000 index 2e40b44b..00000000 --- a/openssl-install/share/man/man3/BN_RECP_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_reciprocal.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_RECP_CTX_set.3ossl b/openssl-install/share/man/man3/BN_RECP_CTX_set.3ossl deleted file mode 120000 index 2e40b44b..00000000 --- a/openssl-install/share/man/man3/BN_RECP_CTX_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_reciprocal.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_abs_is_word.3ossl b/openssl-install/share/man/man3/BN_abs_is_word.3ossl deleted file mode 120000 index 64c2f2ba..00000000 --- a/openssl-install/share/man/man3/BN_abs_is_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_add.3ossl b/openssl-install/share/man/man3/BN_add.3ossl deleted file mode 100644 index 9463e892..00000000 --- a/openssl-install/share/man/man3/BN_add.3ossl +++ /dev/null @@ -1,276 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_ADD 3ossl" -.TH BN_ADD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_add, BN_sub, BN_mul, BN_sqr, BN_div, BN_mod, BN_nnmod, BN_mod_add, -BN_mod_sub, BN_mod_mul, BN_mod_sqr, BN_mod_sqrt, BN_exp, BN_mod_exp, BN_gcd \- -arithmetic operations on BIGNUMs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b); -\& -\& int BN_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b); -\& -\& int BN_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx); -\& -\& int BN_sqr(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx); -\& -\& int BN_div(BIGNUM *dv, BIGNUM *rem, const BIGNUM *a, const BIGNUM *d, -\& BN_CTX *ctx); -\& -\& int BN_mod(BIGNUM *rem, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx); -\& -\& int BN_nnmod(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx); -\& -\& int BN_mod_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m, -\& BN_CTX *ctx); -\& -\& int BN_mod_sub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m, -\& BN_CTX *ctx); -\& -\& int BN_mod_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m, -\& BN_CTX *ctx); -\& -\& int BN_mod_sqr(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx); -\& -\& BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx); -\& -\& int BN_exp(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx); -\& -\& int BN_mod_exp(BIGNUM *r, const BIGNUM *a, const BIGNUM *p, -\& const BIGNUM *m, BN_CTX *ctx); -\& -\& int BN_gcd(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_add()\fR adds \fIa\fR and \fIb\fR and places the result in \fIr\fR (\f(CW\*(C`r=a+b\*(C'\fR). -\&\fIr\fR may be the same \fB\s-1BIGNUM\s0\fR as \fIa\fR or \fIb\fR. -.PP -\&\fBBN_sub()\fR subtracts \fIb\fR from \fIa\fR and places the result in \fIr\fR (\f(CW\*(C`r=a\-b\*(C'\fR). -\&\fIr\fR may be the same \fB\s-1BIGNUM\s0\fR as \fIa\fR or \fIb\fR. -.PP -\&\fBBN_mul()\fR multiplies \fIa\fR and \fIb\fR and places the result in \fIr\fR (\f(CW\*(C`r=a*b\*(C'\fR). -\&\fIr\fR may be the same \fB\s-1BIGNUM\s0\fR as \fIa\fR or \fIb\fR. -For multiplication by powers of 2, use \fBBN_lshift\fR\|(3). -.PP -\&\fBBN_sqr()\fR takes the square of \fIa\fR and places the result in \fIr\fR -(\f(CW\*(C`r=a^2\*(C'\fR). \fIr\fR and \fIa\fR may be the same \fB\s-1BIGNUM\s0\fR. -This function is faster than BN_mul(r,a,a). -.PP -\&\fBBN_div()\fR divides \fIa\fR by \fId\fR and places the result in \fIdv\fR and the -remainder in \fIrem\fR (\f(CW\*(C`dv=a/d, rem=a%d\*(C'\fR). Either of \fIdv\fR and \fIrem\fR may -be \fB\s-1NULL\s0\fR, in which case the respective value is not returned. -The result is rounded towards zero; thus if \fIa\fR is negative, the -remainder will be zero or negative. -For division by powers of 2, use \fBBN_rshift\fR\|(3). -.PP -\&\fBBN_mod()\fR corresponds to \fBBN_div()\fR with \fIdv\fR set to \fB\s-1NULL\s0\fR. -.PP -\&\fBBN_nnmod()\fR reduces \fIa\fR modulo \fIm\fR and places the nonnegative -remainder in \fIr\fR. -.PP -\&\fBBN_mod_add()\fR adds \fIa\fR to \fIb\fR modulo \fIm\fR and places the nonnegative -result in \fIr\fR. -.PP -\&\fBBN_mod_sub()\fR subtracts \fIb\fR from \fIa\fR modulo \fIm\fR and places the -nonnegative result in \fIr\fR. -.PP -\&\fBBN_mod_mul()\fR multiplies \fIa\fR by \fIb\fR and finds the nonnegative -remainder respective to modulus \fIm\fR (\f(CW\*(C`r=(a*b) mod m\*(C'\fR). \fIr\fR may be -the same \fB\s-1BIGNUM\s0\fR as \fIa\fR or \fIb\fR. For more efficient algorithms for -repeated computations using the same modulus, see -\&\fBBN_mod_mul_montgomery\fR\|(3) and -\&\fBBN_mod_mul_reciprocal\fR\|(3). -.PP -\&\fBBN_mod_sqr()\fR takes the square of \fIa\fR modulo \fBm\fR and places the -result in \fIr\fR. -.PP -\&\fBBN_mod_sqrt()\fR returns the modular square root of \fIa\fR such that -\&\f(CW\*(C`in^2 = a (mod p)\*(C'\fR. The modulus \fIp\fR must be a -prime, otherwise an error or an incorrect \*(L"result\*(R" will be returned. -The result is stored into \fIin\fR which can be \s-1NULL.\s0 The result will be -newly allocated in that case. -.PP -\&\fBBN_exp()\fR raises \fIa\fR to the \fIp\fR\-th power and places the result in \fIr\fR -(\f(CW\*(C`r=a^p\*(C'\fR). This function is faster than repeated applications of -\&\fBBN_mul()\fR. -.PP -\&\fBBN_mod_exp()\fR computes \fIa\fR to the \fIp\fR\-th power modulo \fIm\fR (\f(CW\*(C`r=a^p % -m\*(C'\fR). This function uses less time and space than \fBBN_exp()\fR. Do not call this -function when \fBm\fR is even and any of the parameters have the -\&\fB\s-1BN_FLG_CONSTTIME\s0\fR flag set. -.PP -\&\fBBN_gcd()\fR computes the greatest common divisor of \fIa\fR and \fIb\fR and -places the result in \fIr\fR. \fIr\fR may be the same \fB\s-1BIGNUM\s0\fR as \fIa\fR or -\&\fIb\fR. -.PP -For all functions, \fIctx\fR is a previously allocated \fB\s-1BN_CTX\s0\fR used for -temporary variables; see \fBBN_CTX_new\fR\|(3). -.PP -Unless noted otherwise, the result \fB\s-1BIGNUM\s0\fR must be different from -the arguments. -.SH "NOTES" -.IX Header "NOTES" -For modular operations such as \fBBN_nnmod()\fR or \fBBN_mod_exp()\fR it is an error -to use the same \fB\s-1BIGNUM\s0\fR object for the modulus as for the output. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBBN_mod_sqrt()\fR returns the result (possibly incorrect if \fIp\fR is -not a prime), or \s-1NULL.\s0 -.PP -For all remaining functions, 1 is returned for success, 0 on error. The return -value should always be checked (e.g., \f(CW\*(C`if (!BN_add(r,a,b)) goto err;\*(C'\fR). -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_CTX_new\fR\|(3), -\&\fBBN_add_word\fR\|(3), \fBBN_set_bit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_add_word.3ossl b/openssl-install/share/man/man3/BN_add_word.3ossl deleted file mode 100644 index 1d755dfa..00000000 --- a/openssl-install/share/man/man3/BN_add_word.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_ADD_WORD 3ossl" -.TH BN_ADD_WORD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_add_word, BN_sub_word, BN_mul_word, BN_div_word, BN_mod_word \- arithmetic -functions on BIGNUMs with integers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_add_word(BIGNUM *a, BN_ULONG w); -\& -\& int BN_sub_word(BIGNUM *a, BN_ULONG w); -\& -\& int BN_mul_word(BIGNUM *a, BN_ULONG w); -\& -\& BN_ULONG BN_div_word(BIGNUM *a, BN_ULONG w); -\& -\& BN_ULONG BN_mod_word(const BIGNUM *a, BN_ULONG w); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions perform arithmetic operations on BIGNUMs with unsigned -integers. They are much more efficient than the normal \s-1BIGNUM\s0 -arithmetic operations. -.PP -\&\fBBN_add_word()\fR adds \fBw\fR to \fBa\fR (\f(CW\*(C`a+=w\*(C'\fR). -.PP -\&\fBBN_sub_word()\fR subtracts \fBw\fR from \fBa\fR (\f(CW\*(C`a\-=w\*(C'\fR). -.PP -\&\fBBN_mul_word()\fR multiplies \fBa\fR and \fBw\fR (\f(CW\*(C`a*=w\*(C'\fR). -.PP -\&\fBBN_div_word()\fR divides \fBa\fR by \fBw\fR (\f(CW\*(C`a/=w\*(C'\fR) and returns the remainder. -.PP -\&\fBBN_mod_word()\fR returns the remainder of \fBa\fR divided by \fBw\fR (\f(CW\*(C`a%w\*(C'\fR). -.PP -For \fBBN_div_word()\fR and \fBBN_mod_word()\fR, \fBw\fR must not be 0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_add_word()\fR, \fBBN_sub_word()\fR and \fBBN_mul_word()\fR return 1 for success, 0 -on error. The error codes can be obtained by \fBERR_get_error\fR\|(3). -.PP -\&\fBBN_mod_word()\fR and \fBBN_div_word()\fR return \fBa\fR%\fBw\fR on success and -\&\fB(\s-1BN_ULONG\s0)\-1\fR if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_add\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_are_coprime.3ossl b/openssl-install/share/man/man3/BN_are_coprime.3ossl deleted file mode 120000 index 64c2f2ba..00000000 --- a/openssl-install/share/man/man3/BN_are_coprime.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_bin2bn.3ossl b/openssl-install/share/man/man3/BN_bin2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_bin2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_bn2bin.3ossl b/openssl-install/share/man/man3/BN_bn2bin.3ossl deleted file mode 100644 index 6b0e3021..00000000 --- a/openssl-install/share/man/man3/BN_bn2bin.3ossl +++ /dev/null @@ -1,281 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_BN2BIN 3ossl" -.TH BN_BN2BIN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_bn2binpad, BN_signed_bn2bin, BN_bn2bin, BN_bin2bn, BN_signed_bin2bn, -BN_bn2lebinpad, BN_signed_bn2lebin, BN_lebin2bn, BN_signed_lebin2bn, -BN_bn2nativepad, BN_signed_bn2native, BN_native2bn, BN_signed_native2bn, -BN_bn2hex, BN_bn2dec, BN_hex2bn, BN_dec2bn, -BN_print, BN_print_fp, BN_bn2mpi, BN_mpi2bn \- format conversions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_bn2bin(const BIGNUM *a, unsigned char *to); -\& int BN_bn2binpad(const BIGNUM *a, unsigned char *to, int tolen); -\& int BN_signed_bn2bin(const BIGNUM *a, unsigned char *to, int tolen); -\& BIGNUM *BN_bin2bn(const unsigned char *s, int len, BIGNUM *ret); -\& BIGNUM *BN_signed_bin2bn(const unsigned char *s, int len, BIGNUM *ret); -\& -\& int BN_bn2lebinpad(const BIGNUM *a, unsigned char *to, int tolen); -\& int BN_signed_bn2lebin(const BIGNUM *a, unsigned char *to, int tolen); -\& BIGNUM *BN_lebin2bn(const unsigned char *s, int len, BIGNUM *ret); -\& BIGNUM *BN_signed_lebin2bn(const unsigned char *s, int len, BIGNUM *ret); -\& -\& int BN_bn2nativepad(const BIGNUM *a, unsigned char *to, int tolen); -\& int BN_signed_bn2native(const BIGNUM *a, unsigned char *to, int tolen); -\& BIGNUM *BN_native2bn(const unsigned char *s, int len, BIGNUM *ret); -\& BIGNUM *BN_signed_native2bn(const unsigned char *s, int len, BIGNUM *ret); -\& -\& char *BN_bn2hex(const BIGNUM *a); -\& char *BN_bn2dec(const BIGNUM *a); -\& int BN_hex2bn(BIGNUM **a, const char *str); -\& int BN_dec2bn(BIGNUM **a, const char *str); -\& -\& int BN_print(BIO *fp, const BIGNUM *a); -\& int BN_print_fp(FILE *fp, const BIGNUM *a); -\& -\& int BN_bn2mpi(const BIGNUM *a, unsigned char *to); -\& BIGNUM *BN_mpi2bn(unsigned char *s, int len, BIGNUM *ret); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_bn2bin()\fR converts the absolute value of \fBa\fR into big-endian form -and stores it at \fBto\fR. \fBto\fR must point to BN_num_bytes(\fBa\fR) bytes of -memory. -.PP -\&\fBBN_bn2binpad()\fR also converts the absolute value of \fBa\fR into big-endian form -and stores it at \fBto\fR. \fBtolen\fR indicates the length of the output buffer -\&\fBto\fR. The result is padded with zeros if necessary. If \fBtolen\fR is less than -BN_num_bytes(\fBa\fR) an error is returned. -.PP -\&\fBBN_signed_bn2bin()\fR converts the value of \fBa\fR into big-endian signed 2's -complements form and stores it at \fBto\fR. \fBtolen\fR indicates the length of -the output buffer \fBto\fR. The result is signed extended (padded with 0x00 -for positive numbers or with 0xff for negative numbers) if necessary. -If \fBtolen\fR is smaller than the necessary size (which may be -\&\f(CW\*(C`), an error is returned. -.PP -\&\fBBN_bin2bn()\fR converts the positive integer in big-endian form of length -\&\fBlen\fR at \fBs\fR into a \fB\s-1BIGNUM\s0\fR and places it in \fBret\fR. If \fBret\fR is -\&\s-1NULL,\s0 a new \fB\s-1BIGNUM\s0\fR is created. -.PP -\&\fBBN_signed_bin2bn()\fR converts the integer in big-endian signed 2's complement -form of length \fBlen\fR at \fBs\fR into a \fB\s-1BIGNUM\s0\fR and places it in \fBret\fR. If -\&\fBret\fR is \s-1NULL,\s0 a new \fB\s-1BIGNUM\s0\fR is created. -.PP -\&\fBBN_bn2lebinpad()\fR, \fBBN_signed_bn2lebin()\fR and \fBBN_lebin2bn()\fR are identical to -\&\fBBN_bn2binpad()\fR, \fBBN_signed_bn2bin()\fR and \fBBN_bin2bn()\fR except the buffer is in -little-endian format. -.PP -\&\fBBN_bn2nativepad()\fR, \fBBN_signed_bn2native()\fR and \fBBN_native2bn()\fR are identical -to \fBBN_bn2binpad()\fR, \fBBN_signed_bn2bin()\fR and \fBBN_bin2bn()\fR except the buffer is -in native format, i.e. most significant byte first on big-endian platforms, -and least significant byte first on little-endian platforms. -.PP -\&\fBBN_bn2hex()\fR and \fBBN_bn2dec()\fR return printable strings containing the -hexadecimal and decimal encoding of \fBa\fR respectively. For negative -numbers, the string is prefaced with a leading '\-'. The string must be -freed later using \fBOPENSSL_free()\fR. -.PP -\&\fBBN_hex2bn()\fR takes as many characters as possible from the string \fBstr\fR, -including the leading character '\-' which means negative, to form a valid -hexadecimal number representation and converts them to a \fB\s-1BIGNUM\s0\fR and -stores it in **\fBa\fR. If *\fBa\fR is \s-1NULL,\s0 a new \fB\s-1BIGNUM\s0\fR is created. If -\&\fBa\fR is \s-1NULL,\s0 it only computes the length of valid representation. -A \*(L"negative zero\*(R" is converted to zero. -\&\fBBN_dec2bn()\fR is the same using the decimal system. -.PP -\&\fBBN_print()\fR and \fBBN_print_fp()\fR write the hexadecimal encoding of \fBa\fR, -with a leading '\-' for negative numbers, to the \fB\s-1BIO\s0\fR or \fB\s-1FILE\s0\fR -\&\fBfp\fR. -.PP -\&\fBBN_bn2mpi()\fR and \fBBN_mpi2bn()\fR convert \fB\s-1BIGNUM\s0\fRs from and to a format -that consists of the number's length in bytes represented as a 4\-byte -big-endian number, and the number itself in big-endian format, where -the most significant bit signals a negative number (the representation -of numbers with the \s-1MSB\s0 set is prefixed with null byte). -.PP -\&\fBBN_bn2mpi()\fR stores the representation of \fBa\fR at \fBto\fR, where \fBto\fR -must be large enough to hold the result. The size can be determined by -calling BN_bn2mpi(\fBa\fR, \s-1NULL\s0). -.PP -\&\fBBN_mpi2bn()\fR converts the \fBlen\fR bytes long representation at \fBs\fR to -a \fB\s-1BIGNUM\s0\fR and stores it at \fBret\fR, or in a newly allocated \fB\s-1BIGNUM\s0\fR -if \fBret\fR is \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_bn2bin()\fR returns the length of the big-endian number placed at \fBto\fR. -\&\fBBN_bin2bn()\fR returns the \fB\s-1BIGNUM\s0\fR, \s-1NULL\s0 on error. -.PP -\&\fBBN_bn2binpad()\fR, \fBBN_signed_bn2bin()\fR, \fBBN_bn2lebinpad()\fR, \fBBN_signed_bn2lebin()\fR, -\&\fBBN_bn2nativepad()\fR, and_signed \fBBN_bn2native()\fR return the number of bytes -written or \-1 if the supplied buffer is too small. -.PP -\&\fBBN_bn2hex()\fR and \fBBN_bn2dec()\fR return a NUL-terminated string, or \s-1NULL\s0 -on error. \fBBN_hex2bn()\fR and \fBBN_dec2bn()\fR return the number of characters -used in parsing, or 0 on error, in which -case no new \fB\s-1BIGNUM\s0\fR will be created. -.PP -\&\fBBN_print_fp()\fR and \fBBN_print()\fR return 1 on success, 0 on write errors. -.PP -\&\fBBN_bn2mpi()\fR returns the length of the representation. \fBBN_mpi2bn()\fR -returns the \fB\s-1BIGNUM\s0\fR, and \s-1NULL\s0 on error. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_zero\fR\|(3), -\&\fBASN1_INTEGER_to_BN\fR\|(3), -\&\fBBN_num_bytes\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBBN_signed_bin2bn()\fR, \fBBN_signed_bn2bin()\fR, \fBBN_signed_lebin2bn()\fR, -\&\fBBN_signed_bn2lebin()\fR, \fBBN_signed_native2bn()\fR, \fBBN_signed_bn2native()\fR -were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_bn2binpad.3ossl b/openssl-install/share/man/man3/BN_bn2binpad.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_bn2binpad.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_bn2dec.3ossl b/openssl-install/share/man/man3/BN_bn2dec.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_bn2dec.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_bn2hex.3ossl b/openssl-install/share/man/man3/BN_bn2hex.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_bn2hex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_bn2lebinpad.3ossl b/openssl-install/share/man/man3/BN_bn2lebinpad.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_bn2lebinpad.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_bn2mpi.3ossl b/openssl-install/share/man/man3/BN_bn2mpi.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_bn2mpi.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_bn2nativepad.3ossl b/openssl-install/share/man/man3/BN_bn2nativepad.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_bn2nativepad.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_check_prime.3ossl b/openssl-install/share/man/man3/BN_check_prime.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_check_prime.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_clear.3ossl b/openssl-install/share/man/man3/BN_clear.3ossl deleted file mode 120000 index 77082279..00000000 --- a/openssl-install/share/man/man3/BN_clear.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_clear_bit.3ossl b/openssl-install/share/man/man3/BN_clear_bit.3ossl deleted file mode 120000 index 75dc02ad..00000000 --- a/openssl-install/share/man/man3/BN_clear_bit.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_set_bit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_clear_free.3ossl b/openssl-install/share/man/man3/BN_clear_free.3ossl deleted file mode 120000 index 77082279..00000000 --- a/openssl-install/share/man/man3/BN_clear_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_cmp.3ossl b/openssl-install/share/man/man3/BN_cmp.3ossl deleted file mode 100644 index ebf790c9..00000000 --- a/openssl-install/share/man/man3/BN_cmp.3ossl +++ /dev/null @@ -1,196 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_CMP 3ossl" -.TH BN_CMP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_cmp, BN_ucmp, BN_is_zero, BN_is_one, BN_is_word, BN_abs_is_word, BN_is_odd, BN_are_coprime -\&\- BIGNUM comparison and test functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_cmp(const BIGNUM *a, const BIGNUM *b); -\& int BN_ucmp(const BIGNUM *a, const BIGNUM *b); -\& -\& int BN_is_zero(const BIGNUM *a); -\& int BN_is_one(const BIGNUM *a); -\& int BN_is_word(const BIGNUM *a, const BN_ULONG w); -\& int BN_abs_is_word(const BIGNUM *a, const BN_ULONG w); -\& int BN_is_odd(const BIGNUM *a); -\& -\& int BN_are_coprime(BIGNUM *a, const BIGNUM *b, BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_cmp()\fR compares the numbers \fIa\fR and \fIb\fR. \fBBN_ucmp()\fR compares their -absolute values. -.PP -\&\fBBN_is_zero()\fR, \fBBN_is_one()\fR, \fBBN_is_word()\fR and \fBBN_abs_is_word()\fR test if -\&\fIa\fR equals 0, 1, \fIw\fR, or |\fIw\fR| respectively. -\&\fBBN_is_odd()\fR tests if \fIa\fR is odd. -.PP -\&\fBBN_are_coprime()\fR determines if \fBa\fR and \fBb\fR are coprime. -\&\fBctx\fR is used internally for storing temporary variables. -The values of \fBa\fR and \fBb\fR and \fBctx\fR must not be \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_cmp()\fR returns \-1 if \fIa\fR < \fIb\fR, 0 if \fIa\fR == \fIb\fR and 1 if -\&\fIa\fR > \fIb\fR. \fBBN_ucmp()\fR is the same using the absolute values -of \fIa\fR and \fIb\fR. -.PP -\&\fBBN_is_zero()\fR, \fBBN_is_one()\fR \fBBN_is_word()\fR, \fBBN_abs_is_word()\fR and -\&\fBBN_is_odd()\fR return 1 if the condition is true, 0 otherwise. -.PP -\&\fBBN_are_coprime()\fR returns 1 if the \fB\s-1BIGNUM\s0\fR's are coprime, otherwise it -returns 0. -.SH "HISTORY" -.IX Header "HISTORY" -Prior to OpenSSL 1.1.0, \fBBN_is_zero()\fR, \fBBN_is_one()\fR, \fBBN_is_word()\fR, -\&\fBBN_abs_is_word()\fR and \fBBN_is_odd()\fR were macros. -.PP -The function \fBBN_are_coprime()\fR was added in OpenSSL 3.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_copy.3ossl b/openssl-install/share/man/man3/BN_copy.3ossl deleted file mode 100644 index f6092886..00000000 --- a/openssl-install/share/man/man3/BN_copy.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_COPY 3ossl" -.TH BN_COPY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_copy, BN_dup, BN_with_flags \- copy BIGNUMs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIGNUM *BN_copy(BIGNUM *to, const BIGNUM *from); -\& -\& BIGNUM *BN_dup(const BIGNUM *from); -\& -\& void BN_with_flags(BIGNUM *dest, const BIGNUM *b, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_copy()\fR copies \fBfrom\fR to \fBto\fR. \fBBN_dup()\fR creates a new \fB\s-1BIGNUM\s0\fR -containing the value \fBfrom\fR. -.PP -BN_with_flags creates a \fBtemporary\fR shallow copy of \fBb\fR in \fBdest\fR. It places -significant restrictions on the copied data. Applications that do no adhere to -these restrictions may encounter unexpected side effects or crashes. For that -reason use of this function is discouraged. Any flags provided in \fBflags\fR will -be set in \fBdest\fR in addition to any flags already set in \fBb\fR. For example this -might commonly be used to create a temporary copy of a \s-1BIGNUM\s0 with the -\&\fB\s-1BN_FLG_CONSTTIME\s0\fR flag set for constant time operations. The temporary copy in -\&\fBdest\fR will share some internal state with \fBb\fR. For this reason the following -restrictions apply to the use of \fBdest\fR: -.IP "\(bu" 2 -\&\fBdest\fR should be a newly allocated \s-1BIGNUM\s0 obtained via a call to \fBBN_new()\fR. It -should not have been used for other purposes or initialised in any way. -.IP "\(bu" 2 -\&\fBdest\fR must only be used in \*(L"read-only\*(R" operations, i.e. typically those -functions where the relevant parameter is declared \*(L"const\*(R". -.IP "\(bu" 2 -\&\fBdest\fR must be used and freed before any further subsequent use of \fBb\fR -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_copy()\fR returns \fBto\fR on success, \s-1NULL\s0 on error. \fBBN_dup()\fR returns -the new \fB\s-1BIGNUM\s0\fR, and \s-1NULL\s0 on error. The error codes can be obtained -by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_dec2bn.3ossl b/openssl-install/share/man/man3/BN_dec2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_dec2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_div.3ossl b/openssl-install/share/man/man3/BN_div.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_div.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_div_recp.3ossl b/openssl-install/share/man/man3/BN_div_recp.3ossl deleted file mode 120000 index 2e40b44b..00000000 --- a/openssl-install/share/man/man3/BN_div_recp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_reciprocal.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_div_word.3ossl b/openssl-install/share/man/man3/BN_div_word.3ossl deleted file mode 120000 index 570c6e7c..00000000 --- a/openssl-install/share/man/man3/BN_div_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add_word.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_dup.3ossl b/openssl-install/share/man/man3/BN_dup.3ossl deleted file mode 120000 index 111f9a92..00000000 --- a/openssl-install/share/man/man3/BN_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_exp.3ossl b/openssl-install/share/man/man3/BN_exp.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_free.3ossl b/openssl-install/share/man/man3/BN_free.3ossl deleted file mode 120000 index 77082279..00000000 --- a/openssl-install/share/man/man3/BN_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_from_montgomery.3ossl b/openssl-install/share/man/man3/BN_from_montgomery.3ossl deleted file mode 120000 index 09d3a815..00000000 --- a/openssl-install/share/man/man3/BN_from_montgomery.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_montgomery.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_gcd.3ossl b/openssl-install/share/man/man3/BN_gcd.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_gcd.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_generate_prime.3ossl b/openssl-install/share/man/man3/BN_generate_prime.3ossl deleted file mode 100644 index c0bc36c6..00000000 --- a/openssl-install/share/man/man3/BN_generate_prime.3ossl +++ /dev/null @@ -1,382 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_GENERATE_PRIME 3ossl" -.TH BN_GENERATE_PRIME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_generate_prime_ex2, BN_generate_prime_ex, BN_is_prime_ex, BN_check_prime, -BN_is_prime_fasttest_ex, BN_GENCB_call, BN_GENCB_new, BN_GENCB_free, -BN_GENCB_set_old, BN_GENCB_set, BN_GENCB_get_arg, BN_generate_prime, -BN_is_prime, BN_is_prime_fasttest \- generate primes and test for primality -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_generate_prime_ex2(BIGNUM *ret, int bits, int safe, -\& const BIGNUM *add, const BIGNUM *rem, BN_GENCB *cb, -\& BN_CTX *ctx); -\& -\& int BN_generate_prime_ex(BIGNUM *ret, int bits, int safe, const BIGNUM *add, -\& const BIGNUM *rem, BN_GENCB *cb); -\& -\& int BN_check_prime(const BIGNUM *p, BN_CTX *ctx, BN_GENCB *cb); -\& -\& int BN_GENCB_call(BN_GENCB *cb, int a, int b); -\& -\& BN_GENCB *BN_GENCB_new(void); -\& -\& void BN_GENCB_free(BN_GENCB *cb); -\& -\& void BN_GENCB_set_old(BN_GENCB *gencb, -\& void (*callback)(int, int, void *), void *cb_arg); -\& -\& void BN_GENCB_set(BN_GENCB *gencb, -\& int (*callback)(int, int, BN_GENCB *), void *cb_arg); -\& -\& void *BN_GENCB_get_arg(BN_GENCB *cb); -.Ve -.PP -The following functions have been deprecated since OpenSSL 0.9.8, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& BIGNUM *BN_generate_prime(BIGNUM *ret, int num, int safe, BIGNUM *add, -\& BIGNUM *rem, void (*callback)(int, int, void *), -\& void *cb_arg); -\& -\& int BN_is_prime(const BIGNUM *p, int nchecks, -\& void (*callback)(int, int, void *), BN_CTX *ctx, void *cb_arg); -\& -\& int BN_is_prime_fasttest(const BIGNUM *p, int nchecks, -\& void (*callback)(int, int, void *), BN_CTX *ctx, -\& void *cb_arg, int do_trial_division); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int BN_is_prime_ex(const BIGNUM *p, int nchecks, BN_CTX *ctx, BN_GENCB *cb); -\& -\& int BN_is_prime_fasttest_ex(const BIGNUM *p, int nchecks, BN_CTX *ctx, -\& int do_trial_division, BN_GENCB *cb); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_generate_prime_ex2()\fR generates a pseudo-random prime number of -at least bit length \fBbits\fR using the \s-1BN_CTX\s0 provided in \fBctx\fR. The value of -\&\fBctx\fR must not be \s-1NULL.\s0 -.PP -The returned number is probably prime with a negligible error. -The maximum error rate is 2^\-128. -It's 2^\-287 for a 512 bit prime, 2^\-435 for a 1024 bit prime, -2^\-648 for a 2048 bit prime, and lower than 2^\-882 for primes larger -than 2048 bit. -.PP -If \fBadd\fR is \fB\s-1NULL\s0\fR the returned prime number will have exact bit -length \fBbits\fR with the top most two bits set. -.PP -If \fBret\fR is not \fB\s-1NULL\s0\fR, it will be used to store the number. -.PP -If \fBcb\fR is not \fB\s-1NULL\s0\fR, it is used as follows: -.IP "\(bu" 2 -\&\fBBN_GENCB_call(cb, 0, i)\fR is called after generating the i\-th -potential prime number. -.IP "\(bu" 2 -While the number is being tested for primality, -\&\fBBN_GENCB_call(cb, 1, j)\fR is called as described below. -.IP "\(bu" 2 -When a prime has been found, \fBBN_GENCB_call(cb, 2, i)\fR is called. -.IP "\(bu" 2 -The callers of \fBBN_generate_prime_ex()\fR may call \fBBN_GENCB_call(cb, i, j)\fR with -other values as described in their respective man pages; see \*(L"\s-1SEE ALSO\*(R"\s0. -.PP -The prime may have to fulfill additional requirements for use in -Diffie-Hellman key exchange: -.PP -If \fBadd\fR is not \fB\s-1NULL\s0\fR, the prime will fulfill the condition p % \fBadd\fR -== \fBrem\fR (p % \fBadd\fR == 1 if \fBrem\fR == \fB\s-1NULL\s0\fR) in order to suit a given -generator. -.PP -If \fBsafe\fR is true, it will be a safe prime (i.e. a prime p so -that (p\-1)/2 is also prime). If \fBsafe\fR is true, and \fBrem\fR == \fB\s-1NULL\s0\fR -the condition will be p % \fBadd\fR == 3. -It is recommended that \fBadd\fR is a multiple of 4. -.PP -The random generator must be seeded prior to calling \fBBN_generate_prime_ex()\fR. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -The random number generator configured for the \s-1OSSL_LIB_CTX\s0 associated with -\&\fBctx\fR will be used. -.PP -\&\fBBN_generate_prime_ex()\fR is the same as \fBBN_generate_prime_ex2()\fR except that no -\&\fBctx\fR parameter is passed. -In this case the random number generator associated with the default \s-1OSSL_LIB_CTX\s0 -will be used. -.PP -\&\fBBN_check_prime()\fR, \fBBN_is_prime_ex()\fR, \fBBN_is_prime_fasttest_ex()\fR, \fBBN_is_prime()\fR -and \fBBN_is_prime_fasttest()\fR test if the number \fBp\fR is prime. -The functions tests until one of the tests shows that \fBp\fR is composite, -or all the tests passed. -If \fBp\fR passes all these tests, it is considered a probable prime. -.PP -The test performed on \fBp\fR are trial division by a number of small primes -and rounds of the of the Miller-Rabin probabilistic primality test. -.PP -The functions do at least 64 rounds of the Miller-Rabin test giving a maximum -false positive rate of 2^\-128. -If the size of \fBp\fR is more than 2048 bits, they do at least 128 rounds -giving a maximum false positive rate of 2^\-256. -.PP -If \fBnchecks\fR is larger than the minimum above (64 or 128), \fBnchecks\fR -rounds of the Miller-Rabin test will be done. -.PP -If \fBdo_trial_division\fR set to \fB0\fR, the trial division will be skipped. -\&\fBBN_is_prime_ex()\fR and \fBBN_is_prime()\fR always skip the trial division. -.PP -\&\fBBN_is_prime_ex()\fR, \fBBN_is_prime_fasttest_ex()\fR, \fBBN_is_prime()\fR -and \fBBN_is_prime_fasttest()\fR are deprecated. -.PP -\&\fBBN_is_prime_fasttest()\fR and \fBBN_is_prime()\fR behave just like -\&\fBBN_is_prime_fasttest_ex()\fR and \fBBN_is_prime_ex()\fR respectively, but with the old -style call back. -.PP -\&\fBctx\fR is a preallocated \fB\s-1BN_CTX\s0\fR (to save the overhead of allocating and -freeing the structure in a loop), or \fB\s-1NULL\s0\fR. -.PP -If the trial division is done, and no divisors are found and \fBcb\fR -is not \fB\s-1NULL\s0\fR, \fBBN_GENCB_call(cb, 1, \-1)\fR is called. -.PP -After each round of the Miller-Rabin probabilistic primality test, -if \fBcb\fR is not \fB\s-1NULL\s0\fR, \fBBN_GENCB_call(cb, 1, j)\fR is called -with \fBj\fR the iteration (j = 0, 1, ...). -.PP -\&\fBBN_GENCB_call()\fR calls the callback function held in the \fB\s-1BN_GENCB\s0\fR structure -and passes the ints \fBa\fR and \fBb\fR as arguments. There are two types of -\&\fB\s-1BN_GENCB\s0\fR structure that are supported: \*(L"new\*(R" style and \*(L"old\*(R" style. New -programs should prefer the \*(L"new\*(R" style, whilst the \*(L"old\*(R" style is provided -for backwards compatibility purposes. -.PP -A \fB\s-1BN_GENCB\s0\fR structure should be created through a call to \fBBN_GENCB_new()\fR, -and freed through a call to \fBBN_GENCB_free()\fR. If the argument is \s-1NULL,\s0 -nothing is done. -.PP -For \*(L"new\*(R" style callbacks a \s-1BN_GENCB\s0 structure should be initialised with a -call to \fBBN_GENCB_set()\fR, where \fBgencb\fR is a \fB\s-1BN_GENCB\s0 *\fR, \fBcallback\fR is of -type \fBint (*callback)(int, int, \s-1BN_GENCB\s0 *)\fR and \fBcb_arg\fR is a \fBvoid *\fR. -\&\*(L"Old\*(R" style callbacks are the same except they are initialised with a call -to \fBBN_GENCB_set_old()\fR and \fBcallback\fR is of type -\&\fBvoid (*callback)(int, int, void *)\fR. -.PP -A callback is invoked through a call to \fBBN_GENCB_call\fR. This will check -the type of the callback and will invoke \fBcallback(a, b, gencb)\fR for new -style callbacks or \fBcallback(a, b, cb_arg)\fR for old style. -.PP -It is possible to obtain the argument associated with a \s-1BN_GENCB\s0 structure -(set via a call to BN_GENCB_set or BN_GENCB_set_old) using BN_GENCB_get_arg. -.PP -\&\fBBN_generate_prime()\fR (deprecated) works in the same way as -\&\fBBN_generate_prime_ex()\fR but expects an old-style callback function -directly in the \fBcallback\fR parameter, and an argument to pass to it in -the \fBcb_arg\fR. \fBBN_is_prime()\fR and \fBBN_is_prime_fasttest()\fR -can similarly be compared to \fBBN_is_prime_ex()\fR and -\&\fBBN_is_prime_fasttest_ex()\fR, respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_generate_prime_ex()\fR return 1 on success or 0 on error. -.PP -\&\fBBN_is_prime_ex()\fR, \fBBN_is_prime_fasttest_ex()\fR, \fBBN_is_prime()\fR, -\&\fBBN_is_prime_fasttest()\fR and BN_check_prime return 0 if the number is composite, -1 if it is prime with an error probability of less than 0.25^\fBnchecks\fR, and -\&\-1 on error. -.PP -\&\fBBN_generate_prime()\fR returns the prime number on success, \fB\s-1NULL\s0\fR otherwise. -.PP -BN_GENCB_new returns a pointer to a \s-1BN_GENCB\s0 structure on success, or \fB\s-1NULL\s0\fR -otherwise. -.PP -BN_GENCB_get_arg returns the argument previously associated with a \s-1BN_GENCB\s0 -structure. -.PP -Callback functions should return 1 on success or 0 on error. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "REMOVED FUNCTIONALITY" -.IX Header "REMOVED FUNCTIONALITY" -As of OpenSSL 1.1.0 it is no longer possible to create a \s-1BN_GENCB\s0 structure -directly, as in: -.PP -.Vb 1 -\& BN_GENCB callback; -.Ve -.PP -Instead applications should create a \s-1BN_GENCB\s0 structure using BN_GENCB_new: -.PP -.Vb 6 -\& BN_GENCB *callback; -\& callback = BN_GENCB_new(); -\& if (!callback) -\& /* error */ -\& ... -\& BN_GENCB_free(callback); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_generate_parameters\fR\|(3), \fBDSA_generate_parameters\fR\|(3), -\&\fBRSA_generate_key\fR\|(3), \fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBN_is_prime_ex()\fR and \fBBN_is_prime_fasttest_ex()\fR functions were -deprecated in OpenSSL 3.0. -.PP -The \fBBN_GENCB_new()\fR, \fBBN_GENCB_free()\fR, -and \fBBN_GENCB_get_arg()\fR functions were added in OpenSSL 1.1.0. -.PP -\&\fBBN_check_prime()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_generate_prime_ex.3ossl b/openssl-install/share/man/man3/BN_generate_prime_ex.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_generate_prime_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_generate_prime_ex2.3ossl b/openssl-install/share/man/man3/BN_generate_prime_ex2.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_generate_prime_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get0_nist_prime_192.3ossl b/openssl-install/share/man/man3/BN_get0_nist_prime_192.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get0_nist_prime_192.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get0_nist_prime_224.3ossl b/openssl-install/share/man/man3/BN_get0_nist_prime_224.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get0_nist_prime_224.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get0_nist_prime_256.3ossl b/openssl-install/share/man/man3/BN_get0_nist_prime_256.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get0_nist_prime_256.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get0_nist_prime_384.3ossl b/openssl-install/share/man/man3/BN_get0_nist_prime_384.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get0_nist_prime_384.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get0_nist_prime_521.3ossl b/openssl-install/share/man/man3/BN_get0_nist_prime_521.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get0_nist_prime_521.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc2409_prime_1024.3ossl b/openssl-install/share/man/man3/BN_get_rfc2409_prime_1024.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc2409_prime_1024.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc2409_prime_768.3ossl b/openssl-install/share/man/man3/BN_get_rfc2409_prime_768.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc2409_prime_768.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc3526_prime_1536.3ossl b/openssl-install/share/man/man3/BN_get_rfc3526_prime_1536.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc3526_prime_1536.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc3526_prime_2048.3ossl b/openssl-install/share/man/man3/BN_get_rfc3526_prime_2048.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc3526_prime_2048.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc3526_prime_3072.3ossl b/openssl-install/share/man/man3/BN_get_rfc3526_prime_3072.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc3526_prime_3072.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc3526_prime_4096.3ossl b/openssl-install/share/man/man3/BN_get_rfc3526_prime_4096.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc3526_prime_4096.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc3526_prime_6144.3ossl b/openssl-install/share/man/man3/BN_get_rfc3526_prime_6144.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc3526_prime_6144.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_rfc3526_prime_8192.3ossl b/openssl-install/share/man/man3/BN_get_rfc3526_prime_8192.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/BN_get_rfc3526_prime_8192.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_get_word.3ossl b/openssl-install/share/man/man3/BN_get_word.3ossl deleted file mode 120000 index 13fb4113..00000000 --- a/openssl-install/share/man/man3/BN_get_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_zero.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_hex2bn.3ossl b/openssl-install/share/man/man3/BN_hex2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_hex2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_bit_set.3ossl b/openssl-install/share/man/man3/BN_is_bit_set.3ossl deleted file mode 120000 index 75dc02ad..00000000 --- a/openssl-install/share/man/man3/BN_is_bit_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_set_bit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_odd.3ossl b/openssl-install/share/man/man3/BN_is_odd.3ossl deleted file mode 120000 index 64c2f2ba..00000000 --- a/openssl-install/share/man/man3/BN_is_odd.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_one.3ossl b/openssl-install/share/man/man3/BN_is_one.3ossl deleted file mode 120000 index 64c2f2ba..00000000 --- a/openssl-install/share/man/man3/BN_is_one.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_prime.3ossl b/openssl-install/share/man/man3/BN_is_prime.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_is_prime.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_prime_ex.3ossl b/openssl-install/share/man/man3/BN_is_prime_ex.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_is_prime_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_prime_fasttest.3ossl b/openssl-install/share/man/man3/BN_is_prime_fasttest.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_is_prime_fasttest.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_prime_fasttest_ex.3ossl b/openssl-install/share/man/man3/BN_is_prime_fasttest_ex.3ossl deleted file mode 120000 index 1d522c46..00000000 --- a/openssl-install/share/man/man3/BN_is_prime_fasttest_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_generate_prime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_word.3ossl b/openssl-install/share/man/man3/BN_is_word.3ossl deleted file mode 120000 index 64c2f2ba..00000000 --- a/openssl-install/share/man/man3/BN_is_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_is_zero.3ossl b/openssl-install/share/man/man3/BN_is_zero.3ossl deleted file mode 120000 index 64c2f2ba..00000000 --- a/openssl-install/share/man/man3/BN_is_zero.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_lebin2bn.3ossl b/openssl-install/share/man/man3/BN_lebin2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_lebin2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_lshift.3ossl b/openssl-install/share/man/man3/BN_lshift.3ossl deleted file mode 120000 index 75dc02ad..00000000 --- a/openssl-install/share/man/man3/BN_lshift.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_set_bit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_lshift1.3ossl b/openssl-install/share/man/man3/BN_lshift1.3ossl deleted file mode 120000 index 75dc02ad..00000000 --- a/openssl-install/share/man/man3/BN_lshift1.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_set_bit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mask_bits.3ossl b/openssl-install/share/man/man3/BN_mask_bits.3ossl deleted file mode 120000 index 75dc02ad..00000000 --- a/openssl-install/share/man/man3/BN_mask_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_set_bit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod.3ossl b/openssl-install/share/man/man3/BN_mod.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mod.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_add.3ossl b/openssl-install/share/man/man3/BN_mod_add.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mod_add.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_exp.3ossl b/openssl-install/share/man/man3/BN_mod_exp.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_exp_mont.3ossl b/openssl-install/share/man/man3/BN_mod_exp_mont.3ossl deleted file mode 100644 index 248b7a9e..00000000 --- a/openssl-install/share/man/man3/BN_mod_exp_mont.3ossl +++ /dev/null @@ -1,197 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_MOD_EXP_MONT 3ossl" -.TH BN_MOD_EXP_MONT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_mod_exp_mont, BN_mod_exp_mont_consttime, BN_mod_exp_mont_consttime_x2 \- -Montgomery exponentiation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_mod_exp_mont(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p, -\& const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *in_mont); -\& -\& int BN_mod_exp_mont_consttime(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p, -\& const BIGNUM *m, BN_CTX *ctx, -\& BN_MONT_CTX *in_mont); -\& -\& int BN_mod_exp_mont_consttime_x2(BIGNUM *rr1, const BIGNUM *a1, -\& const BIGNUM *p1, const BIGNUM *m1, -\& BN_MONT_CTX *in_mont1, BIGNUM *rr2, -\& const BIGNUM *a2, const BIGNUM *p2, -\& const BIGNUM *m2, BN_MONT_CTX *in_mont2, -\& BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_mod_exp_mont()\fR computes \fIa\fR to the \fIp\fR\-th power modulo \fIm\fR (\f(CW\*(C`rr=a^p % m\*(C'\fR) -using Montgomery multiplication. \fIin_mont\fR is a Montgomery context and can be -\&\s-1NULL.\s0 In the case \fIin_mont\fR is \s-1NULL,\s0 it will be initialized within the -function, so you can save time on initialization if you provide it in advance. -.PP -\&\fBBN_mod_exp_mont_consttime()\fR computes \fIa\fR to the \fIp\fR\-th power modulo \fIm\fR -(\f(CW\*(C`rr=a^p % m\*(C'\fR) using Montgomery multiplication. It is a variant of -\&\fBBN_mod_exp_mont\fR\|(3) that uses fixed windows and the special precomputation -memory layout to limit data-dependency to a minimum to protect secret exponents. -It is called automatically when \fBBN_mod_exp_mont\fR\|(3) is called with parameters -\&\fIa\fR, \fIp\fR, \fIm\fR, any of which have \fB\s-1BN_FLG_CONSTTIME\s0\fR flag. -.PP -\&\fBBN_mod_exp_mont_consttime_x2()\fR computes two independent exponentiations \fIa1\fR to -the \fIp1\fR\-th power modulo \fIm1\fR (\f(CW\*(C`rr1=a1^p1 % m1\*(C'\fR) and \fIa2\fR to the \fIp2\fR\-th -power modulo \fIm2\fR (\f(CW\*(C`rr2=a2^p2 % m2\*(C'\fR) using Montgomery multiplication. For some -fixed and equal modulus sizes \fIm1\fR and \fIm2\fR it uses optimizations that allow -to speedup two exponentiations. In all other cases the function reduces to two -calls of \fBBN_mod_exp_mont_consttime\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -For all functions 1 is returned for success, 0 on error. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_mod_exp_mont\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_mod_exp_mont_consttime.3ossl b/openssl-install/share/man/man3/BN_mod_exp_mont_consttime.3ossl deleted file mode 120000 index e71ba5e9..00000000 --- a/openssl-install/share/man/man3/BN_mod_exp_mont_consttime.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_exp_mont.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_exp_mont_consttime_x2.3ossl b/openssl-install/share/man/man3/BN_mod_exp_mont_consttime_x2.3ossl deleted file mode 120000 index e71ba5e9..00000000 --- a/openssl-install/share/man/man3/BN_mod_exp_mont_consttime_x2.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_exp_mont.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_inverse.3ossl b/openssl-install/share/man/man3/BN_mod_inverse.3ossl deleted file mode 100644 index 1319c08a..00000000 --- a/openssl-install/share/man/man3/BN_mod_inverse.3ossl +++ /dev/null @@ -1,176 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_MOD_INVERSE 3ossl" -.TH BN_MOD_INVERSE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_mod_inverse \- compute inverse modulo n -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIGNUM *BN_mod_inverse(BIGNUM *r, BIGNUM *a, const BIGNUM *n, -\& BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_mod_inverse()\fR computes the inverse of \fBa\fR modulo \fBn\fR -places the result in \fBr\fR (\f(CW\*(C`(a*r)%n==1\*(C'\fR). If \fBr\fR is \s-1NULL,\s0 -a new \fB\s-1BIGNUM\s0\fR is created. -.PP -\&\fBctx\fR is a previously allocated \fB\s-1BN_CTX\s0\fR used for temporary -variables. \fBr\fR may be the same \fB\s-1BIGNUM\s0\fR as \fBa\fR. -.SH "NOTES" -.IX Header "NOTES" -It is an error to use the same \fB\s-1BIGNUM\s0\fR as \fBn\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_mod_inverse()\fR returns the \fB\s-1BIGNUM\s0\fR containing the inverse, and -\&\s-1NULL\s0 on error. The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_add\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_mod_mul.3ossl b/openssl-install/share/man/man3/BN_mod_mul.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mod_mul.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_mul_montgomery.3ossl b/openssl-install/share/man/man3/BN_mod_mul_montgomery.3ossl deleted file mode 100644 index 76323634..00000000 --- a/openssl-install/share/man/man3/BN_mod_mul_montgomery.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_MOD_MUL_MONTGOMERY 3ossl" -.TH BN_MOD_MUL_MONTGOMERY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_mod_mul_montgomery, BN_MONT_CTX_new, -BN_MONT_CTX_free, BN_MONT_CTX_set, BN_MONT_CTX_copy, -BN_from_montgomery, BN_to_montgomery \- Montgomery multiplication -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BN_MONT_CTX *BN_MONT_CTX_new(void); -\& void BN_MONT_CTX_free(BN_MONT_CTX *mont); -\& -\& int BN_MONT_CTX_set(BN_MONT_CTX *mont, const BIGNUM *m, BN_CTX *ctx); -\& BN_MONT_CTX *BN_MONT_CTX_copy(BN_MONT_CTX *to, BN_MONT_CTX *from); -\& -\& int BN_mod_mul_montgomery(BIGNUM *r, BIGNUM *a, BIGNUM *b, -\& BN_MONT_CTX *mont, BN_CTX *ctx); -\& -\& int BN_from_montgomery(BIGNUM *r, BIGNUM *a, BN_MONT_CTX *mont, -\& BN_CTX *ctx); -\& -\& int BN_to_montgomery(BIGNUM *r, BIGNUM *a, BN_MONT_CTX *mont, -\& BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions implement Montgomery multiplication. They are used -automatically when \fBBN_mod_exp\fR\|(3) is called with suitable input, -but they may be useful when several operations are to be performed -using the same modulus. -.PP -\&\fBBN_MONT_CTX_new()\fR allocates and initializes a \fB\s-1BN_MONT_CTX\s0\fR structure. -.PP -\&\fBBN_MONT_CTX_set()\fR sets up the \fImont\fR structure from the modulus \fIm\fR -by precomputing its inverse and a value R. -.PP -\&\fBBN_MONT_CTX_copy()\fR copies the \fB\s-1BN_MONT_CTX\s0\fR \fIfrom\fR to \fIto\fR. -.PP -\&\fBBN_MONT_CTX_free()\fR frees the components of the \fB\s-1BN_MONT_CTX\s0\fR, and, if -it was created by \fBBN_MONT_CTX_new()\fR, also the structure itself. -If \fBmont\fR is \s-1NULL,\s0 nothing is done. -.PP -\&\fBBN_mod_mul_montgomery()\fR computes Mont(\fIa\fR,\fIb\fR):=\fIa\fR*\fIb\fR*R^\-1 and places -the result in \fIr\fR. -.PP -\&\fBBN_from_montgomery()\fR performs the Montgomery reduction \fIr\fR = \fIa\fR*R^\-1. -.PP -\&\fBBN_to_montgomery()\fR computes Mont(\fIa\fR,R^2), i.e. \fIa\fR*R. -Note that \fIa\fR must be nonnegative and smaller than the modulus. -.PP -For all functions, \fIctx\fR is a previously allocated \fB\s-1BN_CTX\s0\fR used for -temporary variables. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_MONT_CTX_new()\fR returns the newly allocated \fB\s-1BN_MONT_CTX\s0\fR, and \s-1NULL\s0 -on error. -.PP -\&\fBBN_MONT_CTX_free()\fR has no return value. -.PP -For the other functions, 1 is returned for success, 0 on error. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "WARNINGS" -.IX Header "WARNINGS" -The inputs must be reduced modulo \fBm\fR, otherwise the result will be -outside the expected range. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_add\fR\|(3), -\&\fBBN_CTX_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBN_MONT_CTX_init()\fR was removed in OpenSSL 1.1.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_mod_mul_reciprocal.3ossl b/openssl-install/share/man/man3/BN_mod_mul_reciprocal.3ossl deleted file mode 100644 index d268c55d..00000000 --- a/openssl-install/share/man/man3/BN_mod_mul_reciprocal.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_MOD_MUL_RECIPROCAL 3ossl" -.TH BN_MOD_MUL_RECIPROCAL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_mod_mul_reciprocal, BN_div_recp, BN_RECP_CTX_new, -BN_RECP_CTX_free, BN_RECP_CTX_set \- modular multiplication using -reciprocal -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BN_RECP_CTX *BN_RECP_CTX_new(void); -\& void BN_RECP_CTX_free(BN_RECP_CTX *recp); -\& -\& int BN_RECP_CTX_set(BN_RECP_CTX *recp, const BIGNUM *m, BN_CTX *ctx); -\& -\& int BN_div_recp(BIGNUM *dv, BIGNUM *rem, const BIGNUM *a, BN_RECP_CTX *recp, -\& BN_CTX *ctx); -\& -\& int BN_mod_mul_reciprocal(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, -\& BN_RECP_CTX *recp, BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_mod_mul_reciprocal()\fR can be used to perform an efficient -\&\fBBN_mod_mul\fR\|(3) operation when the operation will be performed -repeatedly with the same modulus. It computes \fBr\fR=(\fBa\fR*\fBb\fR)%\fBm\fR -using \fBrecp\fR=1/\fBm\fR, which is set as described below. \fBctx\fR is a -previously allocated \fB\s-1BN_CTX\s0\fR used for temporary variables. -.PP -\&\fBBN_RECP_CTX_new()\fR allocates and initializes a \fB\s-1BN_RECP\s0\fR structure. -.PP -\&\fBBN_RECP_CTX_free()\fR frees the components of the \fB\s-1BN_RECP\s0\fR, and, if it -was created by \fBBN_RECP_CTX_new()\fR, also the structure itself. -If \fBrecp\fR is \s-1NULL,\s0 nothing is done. -.PP -\&\fBBN_RECP_CTX_set()\fR stores \fBm\fR in \fBrecp\fR and sets it up for computing -1/\fBm\fR and shifting it left by BN_num_bits(\fBm\fR)+1 to make it an -integer. The result and the number of bits it was shifted left will -later be stored in \fBrecp\fR. -.PP -\&\fBBN_div_recp()\fR divides \fBa\fR by \fBm\fR using \fBrecp\fR. It places the quotient -in \fBdv\fR and the remainder in \fBrem\fR. -.PP -The \fB\s-1BN_RECP_CTX\s0\fR structure cannot be shared between threads. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_RECP_CTX_new()\fR returns the newly allocated \fB\s-1BN_RECP_CTX\s0\fR, and \s-1NULL\s0 -on error. -.PP -\&\fBBN_RECP_CTX_free()\fR has no return value. -.PP -For the other functions, 1 is returned for success, 0 on error. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBBN_add\fR\|(3), -\&\fBBN_CTX_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBN_RECP_CTX_init()\fR was removed in OpenSSL 1.1.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_mod_sqr.3ossl b/openssl-install/share/man/man3/BN_mod_sqr.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mod_sqr.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_sqrt.3ossl b/openssl-install/share/man/man3/BN_mod_sqrt.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mod_sqrt.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_sub.3ossl b/openssl-install/share/man/man3/BN_mod_sub.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mod_sub.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mod_word.3ossl b/openssl-install/share/man/man3/BN_mod_word.3ossl deleted file mode 120000 index 570c6e7c..00000000 --- a/openssl-install/share/man/man3/BN_mod_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add_word.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mpi2bn.3ossl b/openssl-install/share/man/man3/BN_mpi2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_mpi2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mul.3ossl b/openssl-install/share/man/man3/BN_mul.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_mul.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_mul_word.3ossl b/openssl-install/share/man/man3/BN_mul_word.3ossl deleted file mode 120000 index 570c6e7c..00000000 --- a/openssl-install/share/man/man3/BN_mul_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add_word.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_native2bn.3ossl b/openssl-install/share/man/man3/BN_native2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_native2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_new.3ossl b/openssl-install/share/man/man3/BN_new.3ossl deleted file mode 100644 index 26bf74ad..00000000 --- a/openssl-install/share/man/man3/BN_new.3ossl +++ /dev/null @@ -1,195 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_NEW 3ossl" -.TH BN_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_new, BN_secure_new, BN_clear, BN_free, BN_clear_free \- allocate and free BIGNUMs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIGNUM *BN_new(void); -\& -\& BIGNUM *BN_secure_new(void); -\& -\& void BN_clear(BIGNUM *a); -\& -\& void BN_free(BIGNUM *a); -\& -\& void BN_clear_free(BIGNUM *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_new()\fR allocates and initializes a \fB\s-1BIGNUM\s0\fR structure. -\&\fBBN_secure_new()\fR does the same except that the secure heap -\&\fBOPENSSL_secure_malloc\fR\|(3) is used to store the value. -.PP -\&\fBBN_clear()\fR is used to destroy sensitive data such as keys when they -are no longer needed. It erases the memory used by \fBa\fR and sets it -to the value 0. -If \fBa\fR is \s-1NULL,\s0 nothing is done. -.PP -\&\fBBN_free()\fR frees the components of the \fB\s-1BIGNUM\s0\fR, and if it was created -by \fBBN_new()\fR, also the structure itself. \fBBN_clear_free()\fR additionally -overwrites the data before the memory is returned to the system. -If \fBa\fR is \s-1NULL,\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_new()\fR and \fBBN_secure_new()\fR -return a pointer to the \fB\s-1BIGNUM\s0\fR initialised to the value 0. -If the allocation fails, -they return \fB\s-1NULL\s0\fR and set an error code that can be obtained -by \fBERR_get_error\fR\|(3). -.PP -\&\fBBN_clear()\fR, \fBBN_free()\fR and \fBBN_clear_free()\fR have no return values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBOPENSSL_secure_malloc\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBBN_init()\fR was removed in OpenSSL 1.1.0; use \fBBN_new()\fR instead. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_nnmod.3ossl b/openssl-install/share/man/man3/BN_nnmod.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_nnmod.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_num_bits.3ossl b/openssl-install/share/man/man3/BN_num_bits.3ossl deleted file mode 120000 index 9a9e5d0f..00000000 --- a/openssl-install/share/man/man3/BN_num_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_num_bytes.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_num_bits_word.3ossl b/openssl-install/share/man/man3/BN_num_bits_word.3ossl deleted file mode 120000 index 9a9e5d0f..00000000 --- a/openssl-install/share/man/man3/BN_num_bits_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_num_bytes.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_num_bytes.3ossl b/openssl-install/share/man/man3/BN_num_bytes.3ossl deleted file mode 100644 index 57eff26f..00000000 --- a/openssl-install/share/man/man3/BN_num_bytes.3ossl +++ /dev/null @@ -1,192 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_NUM_BYTES 3ossl" -.TH BN_NUM_BYTES 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_num_bits, BN_num_bytes, BN_num_bits_word \- get BIGNUM size -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_num_bytes(const BIGNUM *a); -\& -\& int BN_num_bits(const BIGNUM *a); -\& -\& int BN_num_bits_word(BN_ULONG w); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_num_bytes()\fR returns the size of a \fB\s-1BIGNUM\s0\fR in bytes. -.PP -\&\fBBN_num_bits_word()\fR returns the number of significant bits in a word. -If we take 0x00000432 as an example, it returns 11, not 16, not 32. -Basically, except for a zero, it returns \fIfloor(log2(w))+1\fR. -.PP -\&\fBBN_num_bits()\fR returns the number of significant bits in a \fB\s-1BIGNUM\s0\fR, -following the same principle as \fBBN_num_bits_word()\fR. -.PP -\&\fBBN_num_bytes()\fR is a macro. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The size. -.SH "NOTES" -.IX Header "NOTES" -Some have tried using \fBBN_num_bits()\fR on individual numbers in \s-1RSA\s0 keys, -\&\s-1DH\s0 keys and \s-1DSA\s0 keys, and found that they don't always come up with -the number of bits they expected (something like 512, 1024, 2048, -\&...). This is because generating a number with some specific number -of bits doesn't always set the highest bits, thereby making the number -of \fIsignificant\fR bits a little lower. If you want to know the \*(L"key -size\*(R" of such a key, either use functions like \fBRSA_size()\fR, \fBDH_size()\fR -and \fBDSA_size()\fR, or use \fBBN_num_bytes()\fR and multiply with 8 (although -there's no real guarantee that will match the \*(L"key size\*(R", just a lot -more probability). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_size\fR\|(3), \fBDSA_size\fR\|(3), -\&\fBRSA_size\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_one.3ossl b/openssl-install/share/man/man3/BN_one.3ossl deleted file mode 120000 index 13fb4113..00000000 --- a/openssl-install/share/man/man3/BN_one.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_zero.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_print.3ossl b/openssl-install/share/man/man3/BN_print.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_print_fp.3ossl b/openssl-install/share/man/man3/BN_print_fp.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_print_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_priv_rand.3ossl b/openssl-install/share/man/man3/BN_priv_rand.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_priv_rand.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_priv_rand_ex.3ossl b/openssl-install/share/man/man3/BN_priv_rand_ex.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_priv_rand_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_priv_rand_range.3ossl b/openssl-install/share/man/man3/BN_priv_rand_range.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_priv_rand_range.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_priv_rand_range_ex.3ossl b/openssl-install/share/man/man3/BN_priv_rand_range_ex.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_priv_rand_range_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_pseudo_rand.3ossl b/openssl-install/share/man/man3/BN_pseudo_rand.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_pseudo_rand.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_pseudo_rand_range.3ossl b/openssl-install/share/man/man3/BN_pseudo_rand_range.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_pseudo_rand_range.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_rand.3ossl b/openssl-install/share/man/man3/BN_rand.3ossl deleted file mode 100644 index 1bd4d22c..00000000 --- a/openssl-install/share/man/man3/BN_rand.3ossl +++ /dev/null @@ -1,252 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_RAND 3ossl" -.TH BN_RAND 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_rand_ex, BN_rand, BN_priv_rand_ex, BN_priv_rand, BN_pseudo_rand, -BN_rand_range_ex, BN_rand_range, BN_priv_rand_range_ex, BN_priv_rand_range, -BN_pseudo_rand_range -\&\- generate pseudo\-random number -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_rand_ex(BIGNUM *rnd, int bits, int top, int bottom, -\& unsigned int strength, BN_CTX *ctx); -\& int BN_rand(BIGNUM *rnd, int bits, int top, int bottom); -\& -\& int BN_priv_rand_ex(BIGNUM *rnd, int bits, int top, int bottom, -\& unsigned int strength, BN_CTX *ctx); -\& int BN_priv_rand(BIGNUM *rnd, int bits, int top, int bottom); -\& -\& int BN_rand_range_ex(BIGNUM *rnd, const BIGNUM *range, unsigned int strength, -\& BN_CTX *ctx); -\& int BN_rand_range(BIGNUM *rnd, const BIGNUM *range); -\& -\& int BN_priv_rand_range_ex(BIGNUM *rnd, const BIGNUM *range, unsigned int strength, -\& BN_CTX *ctx); -\& int BN_priv_rand_range(BIGNUM *rnd, const BIGNUM *range); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int BN_pseudo_rand(BIGNUM *rnd, int bits, int top, int bottom); -\& int BN_pseudo_rand_range(BIGNUM *rnd, const BIGNUM *range); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_rand_ex()\fR generates a cryptographically strong pseudo-random -number of \fIbits\fR in length and security strength at least \fIstrength\fR bits -using the random number generator for the library context associated with -\&\fIctx\fR. The function stores the generated data in \fIrnd\fR. The parameter \fIctx\fR -may be \s-1NULL\s0 in which case the default library context is used. -If \fIbits\fR is less than zero, or too small to -accommodate the requirements specified by the \fItop\fR and \fIbottom\fR -parameters, an error is returned. -The \fItop\fR parameters specifies -requirements on the most significant bit of the generated number. -If it is \fB\s-1BN_RAND_TOP_ANY\s0\fR, there is no constraint. -If it is \fB\s-1BN_RAND_TOP_ONE\s0\fR, the top bit must be one. -If it is \fB\s-1BN_RAND_TOP_TWO\s0\fR, the two most significant bits of -the number will be set to 1, so that the product of two such random -numbers will always have 2*\fIbits\fR length. -If \fIbottom\fR is \fB\s-1BN_RAND_BOTTOM_ODD\s0\fR, the number will be odd; if it -is \fB\s-1BN_RAND_BOTTOM_ANY\s0\fR it can be odd or even. -If \fIbits\fR is 1 then \fItop\fR cannot also be \fB\s-1BN_RAND_TOP_TWO\s0\fR. -.PP -\&\fBBN_rand()\fR is the same as \fBBN_rand_ex()\fR except that the default library context -is always used. -.PP -\&\fBBN_rand_range_ex()\fR generates a cryptographically strong pseudo-random -number \fIrnd\fR, of security strength at least \fIstrength\fR bits, -in the range 0 <= \fIrnd\fR < \fIrange\fR using the random number -generator for the library context associated with \fIctx\fR. The parameter \fIctx\fR -may be \s-1NULL\s0 in which case the default library context is used. -.PP -\&\fBBN_rand_range()\fR is the same as \fBBN_rand_range_ex()\fR except that the default -library context is always used. -.PP -\&\fBBN_priv_rand_ex()\fR, \fBBN_priv_rand()\fR, \fBBN_priv_rand_rand_ex()\fR and -\&\fBBN_priv_rand_range()\fR have the same semantics as \fBBN_rand_ex()\fR, \fBBN_rand()\fR, -\&\fBBN_rand_range_ex()\fR and \fBBN_rand_range()\fR respectively. They are intended to be -used for generating values that should remain private, and mirror the -same difference between \fBRAND_bytes\fR\|(3) and \fBRAND_priv_bytes\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -Always check the error return value of these functions and do not take -randomness for granted: an error occurs if the \s-1CSPRNG\s0 has not been -seeded with enough randomness to ensure an unpredictable byte sequence. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions return 1 on success, 0 on error. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBRAND_add\fR\|(3), -\&\fBRAND_bytes\fR\|(3), -\&\fBRAND_priv_bytes\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7), -\&\s-1\fBEVP_RAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -.IP "\(bu" 2 -Starting with OpenSSL release 1.1.0, \fBBN_pseudo_rand()\fR has been identical -to \fBBN_rand()\fR and \fBBN_pseudo_rand_range()\fR has been identical to -\&\fBBN_rand_range()\fR. -The \fBBN_pseudo_rand()\fR and \fBBN_pseudo_rand_range()\fR functions were -deprecated in OpenSSL 3.0. -.IP "\(bu" 2 -The \fBBN_priv_rand()\fR and \fBBN_priv_rand_range()\fR functions were added in -OpenSSL 1.1.1. -.IP "\(bu" 2 -The \fBBN_rand_ex()\fR, \fBBN_priv_rand_ex()\fR, \fBBN_rand_range_ex()\fR and -\&\fBBN_priv_rand_range_ex()\fR functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_rand_ex.3ossl b/openssl-install/share/man/man3/BN_rand_ex.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_rand_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_rand_range.3ossl b/openssl-install/share/man/man3/BN_rand_range.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_rand_range.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_rand_range_ex.3ossl b/openssl-install/share/man/man3/BN_rand_range_ex.3ossl deleted file mode 120000 index 565ccf39..00000000 --- a/openssl-install/share/man/man3/BN_rand_range_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_rand.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_rshift.3ossl b/openssl-install/share/man/man3/BN_rshift.3ossl deleted file mode 120000 index 75dc02ad..00000000 --- a/openssl-install/share/man/man3/BN_rshift.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_set_bit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_rshift1.3ossl b/openssl-install/share/man/man3/BN_rshift1.3ossl deleted file mode 120000 index 75dc02ad..00000000 --- a/openssl-install/share/man/man3/BN_rshift1.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_set_bit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_secure_new.3ossl b/openssl-install/share/man/man3/BN_secure_new.3ossl deleted file mode 120000 index 77082279..00000000 --- a/openssl-install/share/man/man3/BN_secure_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_security_bits.3ossl b/openssl-install/share/man/man3/BN_security_bits.3ossl deleted file mode 100644 index f3ea0a2e..00000000 --- a/openssl-install/share/man/man3/BN_security_bits.3ossl +++ /dev/null @@ -1,181 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_SECURITY_BITS 3ossl" -.TH BN_SECURITY_BITS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_security_bits \- returns bits of security based on given numbers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_security_bits(int L, int N); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_security_bits()\fR returns the number of bits of security provided by a -specific algorithm and a particular key size. The bits of security is -defined in \s-1NIST SP800\-57.\s0 Currently, \fBBN_security_bits()\fR support two types -of asymmetric algorithms: the \s-1FFC\s0 (Finite Field Cryptography) and \s-1IFC\s0 -(Integer Factorization Cryptography). For \s-1FFC,\s0 e.g., \s-1DSA\s0 and \s-1DH,\s0 both -parameters \fBL\fR and \fBN\fR are used to decide the bits of security, where -\&\fBL\fR is the size of the public key and \fBN\fR is the size of the private -key. For \s-1IFC,\s0 e.g., \s-1RSA,\s0 only \fBL\fR is used and it's commonly considered -to be the key size (modulus). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Number of security bits. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1ECC\s0 (Elliptic Curve Cryptography) is not covered by the \fBBN_security_bits()\fR -function. The symmetric algorithms are not covered neither. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_security_bits\fR\|(3), \fBDSA_security_bits\fR\|(3), \fBRSA_security_bits\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBN_security_bits()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_set_bit.3ossl b/openssl-install/share/man/man3/BN_set_bit.3ossl deleted file mode 100644 index 682a8b51..00000000 --- a/openssl-install/share/man/man3/BN_set_bit.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_SET_BIT 3ossl" -.TH BN_SET_BIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_set_bit, BN_clear_bit, BN_is_bit_set, BN_mask_bits, BN_lshift, -BN_lshift1, BN_rshift, BN_rshift1 \- bit operations on BIGNUMs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int BN_set_bit(BIGNUM *a, int n); -\& int BN_clear_bit(BIGNUM *a, int n); -\& -\& int BN_is_bit_set(const BIGNUM *a, int n); -\& -\& int BN_mask_bits(BIGNUM *a, int n); -\& -\& int BN_lshift(BIGNUM *r, const BIGNUM *a, int n); -\& int BN_lshift1(BIGNUM *r, BIGNUM *a); -\& -\& int BN_rshift(BIGNUM *r, BIGNUM *a, int n); -\& int BN_rshift1(BIGNUM *r, BIGNUM *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_set_bit()\fR sets bit \fBn\fR in \fBa\fR to 1 (\f(CW\*(C`a|=(1<. diff --git a/openssl-install/share/man/man3/BN_set_word.3ossl b/openssl-install/share/man/man3/BN_set_word.3ossl deleted file mode 120000 index 13fb4113..00000000 --- a/openssl-install/share/man/man3/BN_set_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_zero.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_signed_bin2bn.3ossl b/openssl-install/share/man/man3/BN_signed_bin2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_signed_bin2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_signed_bn2bin.3ossl b/openssl-install/share/man/man3/BN_signed_bn2bin.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_signed_bn2bin.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_signed_bn2lebin.3ossl b/openssl-install/share/man/man3/BN_signed_bn2lebin.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_signed_bn2lebin.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_signed_bn2native.3ossl b/openssl-install/share/man/man3/BN_signed_bn2native.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_signed_bn2native.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_signed_lebin2bn.3ossl b/openssl-install/share/man/man3/BN_signed_lebin2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_signed_lebin2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_signed_native2bn.3ossl b/openssl-install/share/man/man3/BN_signed_native2bn.3ossl deleted file mode 120000 index 369956e3..00000000 --- a/openssl-install/share/man/man3/BN_signed_native2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_bn2bin.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_sqr.3ossl b/openssl-install/share/man/man3/BN_sqr.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_sqr.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_sub.3ossl b/openssl-install/share/man/man3/BN_sub.3ossl deleted file mode 120000 index a2617d7b..00000000 --- a/openssl-install/share/man/man3/BN_sub.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_sub_word.3ossl b/openssl-install/share/man/man3/BN_sub_word.3ossl deleted file mode 120000 index 570c6e7c..00000000 --- a/openssl-install/share/man/man3/BN_sub_word.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_add_word.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_swap.3ossl b/openssl-install/share/man/man3/BN_swap.3ossl deleted file mode 100644 index 9151ac33..00000000 --- a/openssl-install/share/man/man3/BN_swap.3ossl +++ /dev/null @@ -1,163 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_SWAP 3ossl" -.TH BN_SWAP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_swap \- exchange BIGNUMs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void BN_swap(BIGNUM *a, BIGNUM *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBBN_swap()\fR exchanges the values of \fIa\fR and \fIb\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_swap()\fR does not return a value. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BN_to_ASN1_ENUMERATED.3ossl b/openssl-install/share/man/man3/BN_to_ASN1_ENUMERATED.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/BN_to_ASN1_ENUMERATED.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_to_ASN1_INTEGER.3ossl b/openssl-install/share/man/man3/BN_to_ASN1_INTEGER.3ossl deleted file mode 120000 index e531919d..00000000 --- a/openssl-install/share/man/man3/BN_to_ASN1_INTEGER.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_INTEGER_get_int64.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_to_montgomery.3ossl b/openssl-install/share/man/man3/BN_to_montgomery.3ossl deleted file mode 120000 index 09d3a815..00000000 --- a/openssl-install/share/man/man3/BN_to_montgomery.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_mod_mul_montgomery.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_ucmp.3ossl b/openssl-install/share/man/man3/BN_ucmp.3ossl deleted file mode 120000 index 64c2f2ba..00000000 --- a/openssl-install/share/man/man3/BN_ucmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_value_one.3ossl b/openssl-install/share/man/man3/BN_value_one.3ossl deleted file mode 120000 index 13fb4113..00000000 --- a/openssl-install/share/man/man3/BN_value_one.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_zero.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_with_flags.3ossl b/openssl-install/share/man/man3/BN_with_flags.3ossl deleted file mode 120000 index 111f9a92..00000000 --- a/openssl-install/share/man/man3/BN_with_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -BN_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BN_zero.3ossl b/openssl-install/share/man/man3/BN_zero.3ossl deleted file mode 100644 index 9fd4758a..00000000 --- a/openssl-install/share/man/man3/BN_zero.3ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BN_ZERO 3ossl" -.TH BN_ZERO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BN_zero, BN_one, BN_value_one, BN_set_word, BN_get_word \- BIGNUM assignment -operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void BN_zero(BIGNUM *a); -\& int BN_one(BIGNUM *a); -\& -\& const BIGNUM *BN_value_one(void); -\& -\& int BN_set_word(BIGNUM *a, BN_ULONG w); -\& unsigned BN_ULONG BN_get_word(BIGNUM *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1BN_ULONG\s0\fR is a macro that will be an unsigned integral type optimized -for the most efficient implementation on the local platform. -.PP -\&\fBBN_zero()\fR, \fBBN_one()\fR and \fBBN_set_word()\fR set \fBa\fR to the values 0, 1 and -\&\fBw\fR respectively. \fBBN_zero()\fR and \fBBN_one()\fR are macros. -.PP -\&\fBBN_value_one()\fR returns a \fB\s-1BIGNUM\s0\fR constant of value 1. This constant -is useful for use in comparisons and assignment. -.PP -\&\fBBN_get_word()\fR returns \fBa\fR, if it can be represented as a \fB\s-1BN_ULONG\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBN_get_word()\fR returns the value \fBa\fR, or all-bits-set if \fBa\fR cannot -be represented as a single integer. -.PP -\&\fBBN_one()\fR and \fBBN_set_word()\fR return 1 on success, 0 otherwise. -\&\fBBN_value_one()\fR returns the constant. -\&\fBBN_zero()\fR never fails and returns no value. -.SH "BUGS" -.IX Header "BUGS" -If a \fB\s-1BIGNUM\s0\fR is equal to the value of all-bits-set, it will collide -with the error condition returned by \fBBN_get_word()\fR which uses that -as an error value. -.PP -\&\fB\s-1BN_ULONG\s0\fR should probably be a typedef. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBN_bn2bin\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -In OpenSSL 0.9.8, \fBBN_zero()\fR was changed to not return a value; previous -versions returned an int. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BUF_MEM_free.3ossl b/openssl-install/share/man/man3/BUF_MEM_free.3ossl deleted file mode 120000 index 44870cce..00000000 --- a/openssl-install/share/man/man3/BUF_MEM_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -BUF_MEM_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BUF_MEM_grow.3ossl b/openssl-install/share/man/man3/BUF_MEM_grow.3ossl deleted file mode 120000 index 44870cce..00000000 --- a/openssl-install/share/man/man3/BUF_MEM_grow.3ossl +++ /dev/null @@ -1 +0,0 @@ -BUF_MEM_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BUF_MEM_grow_clean.3ossl b/openssl-install/share/man/man3/BUF_MEM_grow_clean.3ossl deleted file mode 120000 index 44870cce..00000000 --- a/openssl-install/share/man/man3/BUF_MEM_grow_clean.3ossl +++ /dev/null @@ -1 +0,0 @@ -BUF_MEM_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BUF_MEM_new.3ossl b/openssl-install/share/man/man3/BUF_MEM_new.3ossl deleted file mode 100644 index 0783eaba..00000000 --- a/openssl-install/share/man/man3/BUF_MEM_new.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BUF_MEM_NEW 3ossl" -.TH BUF_MEM_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -BUF_MEM_new, BUF_MEM_new_ex, BUF_MEM_free, BUF_MEM_grow, -BUF_MEM_grow_clean, BUF_reverse -\&\- simple character array structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BUF_MEM *BUF_MEM_new(void); -\& -\& BUF_MEM *BUF_MEM_new_ex(unsigned long flags); -\& -\& void BUF_MEM_free(BUF_MEM *a); -\& -\& int BUF_MEM_grow(BUF_MEM *str, int len); -\& size_t BUF_MEM_grow_clean(BUF_MEM *str, size_t len); -\& -\& void BUF_reverse(unsigned char *out, const unsigned char *in, size_t size); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The buffer library handles simple character arrays. Buffers are used for -various purposes in the library, most notably memory BIOs. -.PP -\&\fBBUF_MEM_new()\fR allocates a new buffer of zero size. -.PP -\&\fBBUF_MEM_new_ex()\fR allocates a buffer with the specified flags. -The flag \fB\s-1BUF_MEM_FLAG_SECURE\s0\fR specifies that the \fBdata\fR pointer -should be allocated on the secure heap; see \fBCRYPTO_secure_malloc\fR\|(3). -.PP -\&\fBBUF_MEM_free()\fR frees up an already existing buffer. The data is zeroed -before freeing up in case the buffer contains sensitive data. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBBUF_MEM_grow()\fR changes the size of an already existing buffer to -\&\fBlen\fR. Any data already in the buffer is preserved if it increases in -size. -.PP -\&\fBBUF_MEM_grow_clean()\fR is similar to \fBBUF_MEM_grow()\fR but it sets any free'd -or additionally-allocated memory to zero. -.PP -\&\fBBUF_reverse()\fR reverses \fBsize\fR bytes at \fBin\fR into \fBout\fR. If \fBin\fR -is \s-1NULL,\s0 the array is reversed in-place. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBBUF_MEM_new()\fR returns the buffer or \s-1NULL\s0 on error. -.PP -\&\fBBUF_MEM_free()\fR has no return value. -.PP -\&\fBBUF_MEM_grow()\fR and \fBBUF_MEM_grow_clean()\fR return -zero on error or the new size (i.e., \fBlen\fR). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7), -\&\fBCRYPTO_secure_malloc\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The \fBBUF_MEM_new_ex()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/BUF_MEM_new_ex.3ossl b/openssl-install/share/man/man3/BUF_MEM_new_ex.3ossl deleted file mode 120000 index 44870cce..00000000 --- a/openssl-install/share/man/man3/BUF_MEM_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -BUF_MEM_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/BUF_reverse.3ossl b/openssl-install/share/man/man3/BUF_reverse.3ossl deleted file mode 120000 index 44870cce..00000000 --- a/openssl-install/share/man/man3/BUF_reverse.3ossl +++ /dev/null @@ -1 +0,0 @@ -BUF_MEM_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CERTIFICATEPOLICIES_free.3ossl b/openssl-install/share/man/man3/CERTIFICATEPOLICIES_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CERTIFICATEPOLICIES_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CERTIFICATEPOLICIES_new.3ossl b/openssl-install/share/man/man3/CERTIFICATEPOLICIES_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CERTIFICATEPOLICIES_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_CTX.3ossl b/openssl-install/share/man/man3/CMAC_CTX.3ossl deleted file mode 100644 index fb8886fc..00000000 --- a/openssl-install/share/man/man3/CMAC_CTX.3ossl +++ /dev/null @@ -1,246 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMAC_CTX 3ossl" -.TH CMAC_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMAC_CTX, CMAC_CTX_new, CMAC_CTX_cleanup, CMAC_CTX_free, -CMAC_CTX_get0_cipher_ctx, CMAC_CTX_copy, CMAC_Init, CMAC_Update, CMAC_Final, -CMAC_resume -\&\- create cipher\-based message authentication codes -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -disabled entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version -value, see \fBopenssl_user_macros\fR\|(7). -.PP -.Vb 1 -\& typedef struct CMAC_CTX_st CMAC_CTX; -\& -\& CMAC_CTX *CMAC_CTX_new(void); -\& void CMAC_CTX_cleanup(CMAC_CTX *ctx); -\& void CMAC_CTX_free(CMAC_CTX *ctx); -\& EVP_CIPHER_CTX *CMAC_CTX_get0_cipher_ctx(CMAC_CTX *ctx); -\& int CMAC_CTX_copy(CMAC_CTX *out, const CMAC_CTX *in); -\& int CMAC_Init(CMAC_CTX *ctx, const void *key, size_t keylen, -\& const EVP_CIPHER *cipher, ENGINE *impl); -\& int CMAC_Update(CMAC_CTX *ctx, const void *data, size_t dlen); -\& int CMAC_Final(CMAC_CTX *ctx, unsigned char *out, size_t *poutlen); -\& int CMAC_resume(CMAC_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The low-level \s-1MAC\s0 functions documented on this page are deprecated. -Applications should use the new \s-1\fBEVP_MAC\s0\fR\|(3) interface. -Specifically, utilize the following functions for \s-1MAC\s0 operations: -.IP "\fBEVP_MAC_CTX_new\fR\|(3) to create a new \s-1MAC\s0 context." 4 -.IX Item "EVP_MAC_CTX_new to create a new MAC context." -.PD 0 -.IP "\fBEVP_MAC_CTX_free\fR\|(3) to free the \s-1MAC\s0 context." 4 -.IX Item "EVP_MAC_CTX_free to free the MAC context." -.IP "\fBEVP_MAC_init\fR\|(3) to initialize the \s-1MAC\s0 context." 4 -.IX Item "EVP_MAC_init to initialize the MAC context." -.IP "\fBEVP_MAC_update\fR\|(3) to update the \s-1MAC\s0 with data." 4 -.IX Item "EVP_MAC_update to update the MAC with data." -.IP "\fBEVP_MAC_final\fR\|(3) to finalize the \s-1MAC\s0 and retrieve the output." 4 -.IX Item "EVP_MAC_final to finalize the MAC and retrieve the output." -.PD -.PP -Alternatively, for a single-step \s-1MAC\s0 computation, use the \fBEVP_Q_mac\fR\|(3) -function. -.PP -The \fB\s-1CMAC_CTX\s0\fR type is a structure used for the provision of \s-1CMAC\s0 -(Cipher-based Message Authentication Code) operations. -.PP -\&\fBCMAC_CTX_new()\fR creates a new \fB\s-1CMAC_CTX\s0\fR structure and returns a pointer to it. -.PP -\&\fBCMAC_CTX_cleanup()\fR resets the \fB\s-1CMAC_CTX\s0\fR structure, clearing any internal data -but not freeing the structure itself. -.PP -\&\fBCMAC_CTX_free()\fR frees the \fB\s-1CMAC_CTX\s0\fR structure and any associated resources. -If the argument is \s-1NULL,\s0 no action is taken. -.PP -\&\fBCMAC_CTX_get0_cipher_ctx()\fR returns a pointer to the internal \fB\s-1EVP_CIPHER_CTX\s0\fR -structure within the \fB\s-1CMAC_CTX\s0\fR. -.PP -\&\fBCMAC_CTX_copy()\fR copies the state from one \fB\s-1CMAC_CTX\s0\fR structure to another. -.PP -\&\fBCMAC_Init()\fR initializes the \fB\s-1CMAC_CTX\s0\fR structure for a new \s-1CMAC\s0 calculation -with the specified key, key length, and cipher type. -Optionally, an \fB\s-1ENGINE\s0\fR can be provided. -.PP -\&\fBCMAC_Update()\fR processes data to be included in the \s-1CMAC\s0 calculation. -This function can be called multiple times to update the context with -additional data. -.PP -\&\fBCMAC_Final()\fR finalizes the \s-1CMAC\s0 calculation and retrieves the resulting -\&\s-1MAC\s0 value. The output is stored in the provided buffer, and the length is -stored in the variable pointed to by \fIpoutlen\fR. To determine the required -buffer size, call with \fIout\fR set to \s-1NULL,\s0 which stores only the length in -\&\fIpoutlen\fR. Allocate a buffer of this size and call \fBCMAC_Final()\fR again with -the allocated buffer to retrieve the \s-1MAC.\s0 -.PP -\&\fBCMAC_resume()\fR resumes a previously finalized \s-1CMAC\s0 calculation, allowing -additional data to be processed and a new \s-1MAC\s0 to be generated. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMAC_CTX_new()\fR returns a pointer to a new \fB\s-1CMAC_CTX\s0\fR structure or \s-1NULL\s0 if -an error occurs. -.PP -\&\fBCMAC_CTX_get0_cipher_ctx()\fR returns a pointer to the internal -\&\fB\s-1EVP_CIPHER_CTX\s0\fR structure, or \s-1NULL\s0 if an error occurs. -.PP -\&\fBCMAC_CTX_copy()\fR, \fBCMAC_Init()\fR, \fBCMAC_Update()\fR, \fBCMAC_Final()\fR and \fBCMAC_resume()\fR -return 1 for success or 0 if an error occurs. -.SH "HISTORY" -.IX Header "HISTORY" -All functions described here were deprecated in OpenSSL 3.0. For replacements, -see \fBEVP_MAC_CTX_new\fR\|(3), \fBEVP_MAC_CTX_free\fR\|(3), \fBEVP_MAC_init\fR\|(3), -\&\fBEVP_MAC_update\fR\|(3), and \fBEVP_MAC_final\fR\|(3). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMAC_CTX_cleanup.3ossl b/openssl-install/share/man/man3/CMAC_CTX_cleanup.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_CTX_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_CTX_copy.3ossl b/openssl-install/share/man/man3/CMAC_CTX_copy.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_CTX_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_CTX_free.3ossl b/openssl-install/share/man/man3/CMAC_CTX_free.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_CTX_get0_cipher_ctx.3ossl b/openssl-install/share/man/man3/CMAC_CTX_get0_cipher_ctx.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_CTX_get0_cipher_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_CTX_new.3ossl b/openssl-install/share/man/man3/CMAC_CTX_new.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_Final.3ossl b/openssl-install/share/man/man3/CMAC_Final.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_Init.3ossl b/openssl-install/share/man/man3/CMAC_Init.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_Update.3ossl b/openssl-install/share/man/man3/CMAC_Update.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMAC_resume.3ossl b/openssl-install/share/man/man3/CMAC_resume.3ossl deleted file mode 120000 index 599df427..00000000 --- a/openssl-install/share/man/man3/CMAC_resume.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMAC_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_AuthEnvelopedData_create.3ossl b/openssl-install/share/man/man3/CMS_AuthEnvelopedData_create.3ossl deleted file mode 120000 index 92e7d6df..00000000 --- a/openssl-install/share/man/man3/CMS_AuthEnvelopedData_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_EnvelopedData_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_AuthEnvelopedData_create_ex.3ossl b/openssl-install/share/man/man3/CMS_AuthEnvelopedData_create_ex.3ossl deleted file mode 120000 index 92e7d6df..00000000 --- a/openssl-install/share/man/man3/CMS_AuthEnvelopedData_create_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_EnvelopedData_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ContentInfo_free.3ossl b/openssl-install/share/man/man3/CMS_ContentInfo_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_ContentInfo_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ContentInfo_new.3ossl b/openssl-install/share/man/man3/CMS_ContentInfo_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_ContentInfo_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ContentInfo_new_ex.3ossl b/openssl-install/share/man/man3/CMS_ContentInfo_new_ex.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_ContentInfo_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ContentInfo_print_ctx.3ossl b/openssl-install/share/man/man3/CMS_ContentInfo_print_ctx.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_ContentInfo_print_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_EncryptedData_decrypt.3ossl b/openssl-install/share/man/man3/CMS_EncryptedData_decrypt.3ossl deleted file mode 100644 index 971a76ec..00000000 --- a/openssl-install/share/man/man3/CMS_EncryptedData_decrypt.3ossl +++ /dev/null @@ -1,199 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_ENCRYPTEDDATA_DECRYPT 3ossl" -.TH CMS_ENCRYPTEDDATA_DECRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_EncryptedData_decrypt, CMS_EnvelopedData_decrypt -\&\- Decrypt CMS EncryptedData or EnvelopedData -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_EncryptedData_decrypt(CMS_ContentInfo *cms, -\& const unsigned char *key, size_t keylen, -\& BIO *dcont, BIO *out, unsigned int flags); -\& -\& BIO *CMS_EnvelopedData_decrypt(CMS_EnvelopedData *env, BIO *detached_data, -\& EVP_PKEY *pkey, X509 *cert, -\& ASN1_OCTET_STRING *secret, unsigned int flags, -\& OSSL_LIB_CTX *libctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_EncryptedData_decrypt()\fR decrypts a \fIcms\fR EncryptedData object using the -symmetric \fIkey\fR of size \fIkeylen\fR bytes. \fIout\fR is a \s-1BIO\s0 to write the content -to and \fIflags\fR is an optional set of flags. -\&\fIdcont\fR is used in the rare case where the encrypted content is detached. It -will normally be set to \s-1NULL.\s0 -.PP -The following flags can be passed in the \fIflags\fR parameter. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \f(CW\*(C`text/plain\*(C'\fR are deleted -from the content. If the content is not of type \f(CW\*(C`text/plain\*(C'\fR then an error is -returned. -.PP -\&\fBCMS_EnvelopedData_decrypt()\fR decrypts, similarly to \fBCMS_decrypt\fR\|(3), -a \s-1CMS\s0 EnvelopedData object \fIenv\fR using the symmetric key \fIsecret\fR if it -is not \s-1NULL,\s0 otherwise the private key of the recipient \fIpkey\fR. -If \fIpkey\fR is given, it is recommended to provide also the associated -certificate in \fIcert\fR \- see \fBCMS_decrypt\fR\|(3) and the \s-1NOTES\s0 on \fIcert\fR there. -The optional parameters \fIflags\fR and \fIdcont\fR are used as described above. -The optional parameters library context \fIlibctx\fR and property query \fIpropq\fR -are used when retrieving algorithms from providers. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_EncryptedData_decrypt()\fR returns 0 if an error occurred otherwise returns 1. -.PP -\&\fBCMS_EnvelopedData_decrypt()\fR returns \s-1NULL\s0 if an error occurred, -otherwise a \s-1BIO\s0 containing the decypted content. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_EncryptedData_encrypt\fR\|(3), \fBCMS_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCMS_EnvelopedData_decrypt()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_EncryptedData_encrypt.3ossl b/openssl-install/share/man/man3/CMS_EncryptedData_encrypt.3ossl deleted file mode 100644 index ee977b41..00000000 --- a/openssl-install/share/man/man3/CMS_EncryptedData_encrypt.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_ENCRYPTEDDATA_ENCRYPT 3ossl" -.TH CMS_ENCRYPTEDDATA_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_EncryptedData_encrypt_ex, CMS_EncryptedData_encrypt -\&\- Create CMS EncryptedData -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *CMS_EncryptedData_encrypt_ex(BIO *in, -\& const EVP_CIPHER *cipher, -\& const unsigned char *key, -\& size_t keylen, -\& unsigned int flags, -\& OSSL_LIB_CTX *ctx, -\& const char *propq); -\& -\& CMS_ContentInfo *CMS_EncryptedData_encrypt(BIO *in, -\& const EVP_CIPHER *cipher, const unsigned char *key, size_t keylen, -\& unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_EncryptedData_encrypt_ex()\fR creates a \fBCMS_ContentInfo\fR structure -with a type \fBNID_pkcs7_encrypted\fR. \fIin\fR is a \s-1BIO\s0 containing the data to -encrypt using \fIcipher\fR and the encryption key \fIkey\fR of size \fIkeylen\fR bytes. -The library context \fIlibctx\fR and the property query \fIpropq\fR are used when -retrieving algorithms from providers. \fIflags\fR is a set of optional flags. -.PP -The \fIflags\fR field supports the options \fB\s-1CMS_DETACHED\s0\fR, \fB\s-1CMS_STREAM\s0\fR and -\&\fB\s-1CMS_PARTIAL\s0\fR. Internally \fBCMS_final()\fR is called unless \fB\s-1CMS_STREAM\s0\fR and/or -\&\fB\s-1CMS_PARTIAL\s0\fR is specified. -.PP -The algorithm passed in the \fIcipher\fR parameter must support \s-1ASN1\s0 encoding of -its parameters. -.PP -The \fBCMS_ContentInfo\fR structure can be freed using \fBCMS_ContentInfo_free\fR\|(3). -.PP -\&\fBCMS_EncryptedData_encrypt()\fR is similar to \fBCMS_EncryptedData_encrypt_ex()\fR -but uses default values of \s-1NULL\s0 for the library context \fIlibctx\fR and the -property query \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBCMS_EncryptedData_encrypt_ex()\fR and -\&\fBCMS_EncryptedData_encrypt()\fR return \s-1NULL\s0 and set an error code that can be -obtained by \fBERR_get_error\fR\|(3). Otherwise they return a pointer to the newly -allocated structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_final\fR\|(3), \fBCMS_EncryptedData_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBCMS_EncryptedData_encrypt_ex()\fR method was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_EncryptedData_encrypt_ex.3ossl b/openssl-install/share/man/man3/CMS_EncryptedData_encrypt_ex.3ossl deleted file mode 120000 index c355dcb1..00000000 --- a/openssl-install/share/man/man3/CMS_EncryptedData_encrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_EncryptedData_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_EnvelopedData_create.3ossl b/openssl-install/share/man/man3/CMS_EnvelopedData_create.3ossl deleted file mode 100644 index 5efe96ed..00000000 --- a/openssl-install/share/man/man3/CMS_EnvelopedData_create.3ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_ENVELOPEDDATA_CREATE 3ossl" -.TH CMS_ENVELOPEDDATA_CREATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_EnvelopedData_create_ex, CMS_EnvelopedData_create, -CMS_AuthEnvelopedData_create, CMS_AuthEnvelopedData_create_ex -\&\- Create CMS envelope -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo * -\& CMS_EnvelopedData_create_ex(const EVP_CIPHER *cipher, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& CMS_ContentInfo *CMS_EnvelopedData_create(const EVP_CIPHER *cipher); -\& -\& CMS_ContentInfo * -\& CMS_AuthEnvelopedData_create_ex(const EVP_CIPHER *cipher, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& CMS_ContentInfo *CMS_AuthEnvelopedData_create(const EVP_CIPHER *cipher); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_EnvelopedData_create_ex()\fR creates a \fBCMS_ContentInfo\fR structure -with a type \fBNID_pkcs7_enveloped\fR. \fIcipher\fR is the symmetric cipher to use. -The library context \fIlibctx\fR and the property query \fIpropq\fR are used when -retrieving algorithms from providers. -.PP -\&\fBCMS_AuthEnvelopedData_create_ex()\fR creates a \fBCMS_ContentInfo\fR -structure with a type \fBNID_id_smime_ct_authEnvelopedData\fR. \fBcipher\fR is the -symmetric \s-1AEAD\s0 cipher to use. Currently only \s-1AES\s0 variants with \s-1GCM\s0 mode are -supported. The library context \fIlibctx\fR and the property query \fIpropq\fR are -used when retrieving algorithms from providers. -.PP -The algorithm passed in the \fIcipher\fR parameter must support \s-1ASN1\s0 encoding of -its parameters. -.PP -The recipients can be added later using \fBCMS_add1_recipient_cert\fR\|(3) or -\&\fBCMS_add0_recipient_key\fR\|(3). -.PP -The \fBCMS_ContentInfo\fR structure needs to be finalized using \fBCMS_final\fR\|(3) -and then freed using \fBCMS_ContentInfo_free\fR\|(3). -.PP -\&\fBCMS_EnvelopedData_create()\fR and \fBCMS_AuthEnvelopedData_create()\fR are similar to -\&\fBCMS_EnvelopedData_create_ex()\fR and \fBCMS_AuthEnvelopedData_create_ex()\fR -but use default values of \s-1NULL\s0 for -the library context \fIlibctx\fR and the property query \fIpropq\fR. -.SH "NOTES" -.IX Header "NOTES" -Although \fBCMS_EnvelopedData_create_ex()\fR, and \fBCMS_EnvelopedData_create()\fR, -\&\fBCMS_AuthEnvelopedData_create_ex()\fR, and \fBCMS_AuthEnvelopedData_create()\fR allocate -a new \fBCMS_ContentInfo\fR structure, they are not usually used in applications. -The wrappers \fBCMS_encrypt\fR\|(3) and \fBCMS_decrypt\fR\|(3) are often used instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBCMS_EnvelopedData_create_ex()\fR, -\&\fBCMS_EnvelopedData_create()\fR, \fBCMS_AuthEnvelopedData_create_ex()\fR, and -\&\fBCMS_AuthEnvelopedData_create()\fR return \s-1NULL\s0 and set an error code that can be -obtained by \fBERR_get_error\fR\|(3). Otherwise they return a pointer to the newly -allocated structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_encrypt\fR\|(3), \fBCMS_decrypt\fR\|(3), \fBCMS_final\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBCMS_EnvelopedData_create_ex()\fR method was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_EnvelopedData_create_ex.3ossl b/openssl-install/share/man/man3/CMS_EnvelopedData_create_ex.3ossl deleted file mode 120000 index 92e7d6df..00000000 --- a/openssl-install/share/man/man3/CMS_EnvelopedData_create_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_EnvelopedData_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_EnvelopedData_decrypt.3ossl b/openssl-install/share/man/man3/CMS_EnvelopedData_decrypt.3ossl deleted file mode 120000 index b5d6b675..00000000 --- a/openssl-install/share/man/man3/CMS_EnvelopedData_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_EncryptedData_decrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_EnvelopedData_it.3ossl b/openssl-install/share/man/man3/CMS_EnvelopedData_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_EnvelopedData_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ReceiptRequest_create0.3ossl b/openssl-install/share/man/man3/CMS_ReceiptRequest_create0.3ossl deleted file mode 120000 index 83f2cab3..00000000 --- a/openssl-install/share/man/man3/CMS_ReceiptRequest_create0.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get1_ReceiptRequest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ReceiptRequest_create0_ex.3ossl b/openssl-install/share/man/man3/CMS_ReceiptRequest_create0_ex.3ossl deleted file mode 120000 index 83f2cab3..00000000 --- a/openssl-install/share/man/man3/CMS_ReceiptRequest_create0_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get1_ReceiptRequest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ReceiptRequest_free.3ossl b/openssl-install/share/man/man3/CMS_ReceiptRequest_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_ReceiptRequest_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ReceiptRequest_get0_values.3ossl b/openssl-install/share/man/man3/CMS_ReceiptRequest_get0_values.3ossl deleted file mode 120000 index 83f2cab3..00000000 --- a/openssl-install/share/man/man3/CMS_ReceiptRequest_get0_values.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get1_ReceiptRequest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_ReceiptRequest_new.3ossl b/openssl-install/share/man/man3/CMS_ReceiptRequest_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_ReceiptRequest_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_decrypt.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_decrypt.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_encrypt.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_encrypt.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey_and_peer.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey_and_peer.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_kari_set0_pkey_and_peer.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_kekri_get0_id.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_kekri_get0_id.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_kekri_get0_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_kekri_id_cmp.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_kekri_id_cmp.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_kekri_id_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_ktri_cert_cmp.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_ktri_cert_cmp.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_ktri_cert_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_ktri_get0_signer_id.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_ktri_get0_signer_id.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_ktri_get0_signer_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_set0_key.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_set0_key.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_set0_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_set0_pkey.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_set0_pkey.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_set0_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_RecipientInfo_type.3ossl b/openssl-install/share/man/man3/CMS_RecipientInfo_type.3ossl deleted file mode 120000 index 81c4b672..00000000 --- a/openssl-install/share/man/man3/CMS_RecipientInfo_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_RecipientInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignedData_free.3ossl b/openssl-install/share/man/man3/CMS_SignedData_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_SignedData_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignedData_new.3ossl b/openssl-install/share/man/man3/CMS_SignedData_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CMS_SignedData_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignedData_verify.3ossl b/openssl-install/share/man/man3/CMS_SignedData_verify.3ossl deleted file mode 120000 index 323b8d52..00000000 --- a/openssl-install/share/man/man3/CMS_SignedData_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignerInfo_cert_cmp.3ossl b/openssl-install/share/man/man3/CMS_SignerInfo_cert_cmp.3ossl deleted file mode 120000 index 0983bbfa..00000000 --- a/openssl-install/share/man/man3/CMS_SignerInfo_cert_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_SignerInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignerInfo_get0_signature.3ossl b/openssl-install/share/man/man3/CMS_SignerInfo_get0_signature.3ossl deleted file mode 120000 index 0983bbfa..00000000 --- a/openssl-install/share/man/man3/CMS_SignerInfo_get0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_SignerInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignerInfo_get0_signer_id.3ossl b/openssl-install/share/man/man3/CMS_SignerInfo_get0_signer_id.3ossl deleted file mode 120000 index 0983bbfa..00000000 --- a/openssl-install/share/man/man3/CMS_SignerInfo_get0_signer_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_SignerInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignerInfo_set1_signer_cert.3ossl b/openssl-install/share/man/man3/CMS_SignerInfo_set1_signer_cert.3ossl deleted file mode 120000 index 0983bbfa..00000000 --- a/openssl-install/share/man/man3/CMS_SignerInfo_set1_signer_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_SignerInfos.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_SignerInfo_sign.3ossl b/openssl-install/share/man/man3/CMS_SignerInfo_sign.3ossl deleted file mode 120000 index 9fdd6f67..00000000 --- a/openssl-install/share/man/man3/CMS_SignerInfo_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add1_signer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_add0_cert.3ossl b/openssl-install/share/man/man3/CMS_add0_cert.3ossl deleted file mode 100644 index 915ffb31..00000000 --- a/openssl-install/share/man/man3/CMS_add0_cert.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_ADD0_CERT 3ossl" -.TH CMS_ADD0_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_add0_cert, CMS_add1_cert, CMS_get1_certs, -CMS_add0_crl, CMS_add1_crl, CMS_get1_crls -\&\- CMS certificate and CRL utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_add0_cert(CMS_ContentInfo *cms, X509 *cert); -\& int CMS_add1_cert(CMS_ContentInfo *cms, X509 *cert); -\& STACK_OF(X509) *CMS_get1_certs(CMS_ContentInfo *cms); -\& -\& int CMS_add0_crl(CMS_ContentInfo *cms, X509_CRL *crl); -\& int CMS_add1_crl(CMS_ContentInfo *cms, X509_CRL *crl); -\& STACK_OF(X509_CRL) *CMS_get1_crls(CMS_ContentInfo *cms); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_add0_cert()\fR and \fBCMS_add1_cert()\fR add certificate \fIcert\fR to \fIcms\fR -unless it is already present. -This is used by \fBCMS_sign_ex\fR\|(3) and \fBCMS_sign\fR\|(3) and may be used before -calling \fBCMS_verify\fR\|(3) to help chain building in certificate validation. -As the 0 implies, \fBCMS_add0_cert()\fR adds \fIcert\fR internally to \fIcms\fR -and on success it must not be freed up by the caller. -In contrast, the caller of \fBCMS_add1_cert()\fR must free \fIcert\fR. -\&\fIcms\fR must be of type signed data or (authenticated) enveloped data. -For signed data, such a certificate can be used when signing or verifying -to fill in the signer certificate or to provide an extra \s-1CA\s0 certificate -that may be needed for chain building in certificate validation. -.PP -\&\fBCMS_get1_certs()\fR returns all certificates in \fIcms\fR. -.PP -\&\fBCMS_add0_crl()\fR and \fBCMS_add1_crl()\fR add \s-1CRL\s0 \fIcrl\fR to \fIcms\fR. -\&\fIcms\fR must be of type signed data or (authenticated) enveloped data. -For signed data, such a \s-1CRL\s0 may be used in certificate validation -with \fBCMS_verify\fR\|(3). -It may be given both for inclusion when signing a \s-1CMS\s0 message -and when verifying a signed \s-1CMS\s0 message. -.PP -\&\fBCMS_get1_crls()\fR returns all CRLs in \fIcms\fR. -.SH "NOTES" -.IX Header "NOTES" -The CMS_ContentInfo structure \fIcms\fR must be of type signed data or enveloped -data or authenticated enveloped data or an error will be returned. -.PP -For signed data, certificates and CRLs are added to the \fIcertificates\fR and -\&\fIcrls\fR fields of SignedData structure. -For enveloped data they are added to \fBOriginatorInfo\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_add0_cert()\fR, \fBCMS_add1_cert()\fR and \fBCMS_add0_crl()\fR and \fBCMS_add1_crl()\fR return -1 for success and 0 for failure. -.PP -\&\fBCMS_get1_certs()\fR and \fBCMS_get1_crls()\fR return the \s-1STACK\s0 of certificates or CRLs -or \s-1NULL\s0 if there are none or an error occurs. -Besides out-of-memory, the only error which will occur -in practice is if the \fIcms\fR type is invalid. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBCMS_sign\fR\|(3), \fBCMS_sign_ex\fR\|(3), \fBCMS_verify\fR\|(3), -\&\fBCMS_encrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCMS_add0_cert()\fR and \fBCMS_add1_cert()\fR have been changed in OpenSSL 3.2 -not to throw an error if a certificate to be added is already present. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_add0_crl.3ossl b/openssl-install/share/man/man3/CMS_add0_crl.3ossl deleted file mode 120000 index 6347d625..00000000 --- a/openssl-install/share/man/man3/CMS_add0_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add0_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_add0_recipient_key.3ossl b/openssl-install/share/man/man3/CMS_add0_recipient_key.3ossl deleted file mode 120000 index b8f08811..00000000 --- a/openssl-install/share/man/man3/CMS_add0_recipient_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add1_recipient_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_add1_ReceiptRequest.3ossl b/openssl-install/share/man/man3/CMS_add1_ReceiptRequest.3ossl deleted file mode 120000 index 83f2cab3..00000000 --- a/openssl-install/share/man/man3/CMS_add1_ReceiptRequest.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get1_ReceiptRequest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_add1_cert.3ossl b/openssl-install/share/man/man3/CMS_add1_cert.3ossl deleted file mode 120000 index 6347d625..00000000 --- a/openssl-install/share/man/man3/CMS_add1_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add0_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_add1_crl.3ossl b/openssl-install/share/man/man3/CMS_add1_crl.3ossl deleted file mode 120000 index 6347d625..00000000 --- a/openssl-install/share/man/man3/CMS_add1_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add0_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_add1_recipient.3ossl b/openssl-install/share/man/man3/CMS_add1_recipient.3ossl deleted file mode 120000 index b8f08811..00000000 --- a/openssl-install/share/man/man3/CMS_add1_recipient.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add1_recipient_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_add1_recipient_cert.3ossl b/openssl-install/share/man/man3/CMS_add1_recipient_cert.3ossl deleted file mode 100644 index 96a64067..00000000 --- a/openssl-install/share/man/man3/CMS_add1_recipient_cert.3ossl +++ /dev/null @@ -1,216 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_ADD1_RECIPIENT_CERT 3ossl" -.TH CMS_ADD1_RECIPIENT_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_add1_recipient, CMS_add1_recipient_cert, CMS_add0_recipient_key \- add recipients to a CMS enveloped data structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_RecipientInfo *CMS_add1_recipient(CMS_ContentInfo *cms, X509 *recip, -\& EVP_PKEY *originatorPrivKey, -\& X509 *originator, unsigned int flags); -\& -\& CMS_RecipientInfo *CMS_add1_recipient_cert(CMS_ContentInfo *cms, -\& X509 *recip, unsigned int flags); -\& -\& CMS_RecipientInfo *CMS_add0_recipient_key(CMS_ContentInfo *cms, int nid, -\& unsigned char *key, size_t keylen, -\& unsigned char *id, size_t idlen, -\& ASN1_GENERALIZEDTIME *date, -\& ASN1_OBJECT *otherTypeId, -\& ASN1_TYPE *otherType); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_add1_recipient()\fR adds recipient \fBrecip\fR and provides the originator pkey -\&\fBoriginatorPrivKey\fR and originator certificate \fBoriginator\fR to CMS_ContentInfo. -The originator-related fields are relevant only in case when the keyAgreement -method of providing of the shared key is in use. -.PP -\&\fBCMS_add1_recipient_cert()\fR adds recipient \fBrecip\fR to CMS_ContentInfo enveloped -data structure \fBcms\fR as a KeyTransRecipientInfo structure. -.PP -\&\fBCMS_add0_recipient_key()\fR adds symmetric key \fBkey\fR of length \fBkeylen\fR using -wrapping algorithm \fBnid\fR, identifier \fBid\fR of length \fBidlen\fR and optional -values \fBdate\fR, \fBotherTypeId\fR and \fBotherType\fR to CMS_ContentInfo enveloped -data structure \fBcms\fR as a KEKRecipientInfo structure. -.PP -The CMS_ContentInfo structure should be obtained from an initial call to -\&\fBCMS_encrypt()\fR with the flag \fB\s-1CMS_PARTIAL\s0\fR set. -.SH "NOTES" -.IX Header "NOTES" -The main purpose of this function is to provide finer control over a \s-1CMS\s0 -enveloped data structure where the simpler \fBCMS_encrypt()\fR function defaults are -not appropriate. For example if one or more KEKRecipientInfo structures -need to be added. New attributes can also be added using the returned -CMS_RecipientInfo structure and the \s-1CMS\s0 attribute utility functions. -.PP -OpenSSL will by default identify recipient certificates using issuer name -and serial number. If \fB\s-1CMS_USE_KEYID\s0\fR is set it will use the subject key -identifier value instead. An error occurs if all recipient certificates do not -have a subject key identifier extension. -.PP -Currently only \s-1AES\s0 based key wrapping algorithms are supported for \fBnid\fR, -specifically: NID_id_aes128_wrap, NID_id_aes192_wrap and NID_id_aes256_wrap. -If \fBnid\fR is set to \fBNID_undef\fR then an \s-1AES\s0 wrap algorithm will be used -consistent with \fBkeylen\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_add1_recipient_cert()\fR and \fBCMS_add0_recipient_key()\fR return an internal -pointer to the CMS_RecipientInfo structure just added or \s-1NULL\s0 if an error -occurs. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_decrypt\fR\|(3), -\&\fBCMS_final\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCMS_add1_recipient_cert\fR and \fBCMS_add0_recipient_key\fR were added in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_add1_signer.3ossl b/openssl-install/share/man/man3/CMS_add1_signer.3ossl deleted file mode 100644 index d0d1fdc4..00000000 --- a/openssl-install/share/man/man3/CMS_add1_signer.3ossl +++ /dev/null @@ -1,240 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_ADD1_SIGNER 3ossl" -.TH CMS_ADD1_SIGNER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_add1_signer, CMS_SignerInfo_sign \- add a signer to a CMS_ContentInfo signed data structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_SignerInfo *CMS_add1_signer(CMS_ContentInfo *cms, X509 *signcert, -\& EVP_PKEY *pkey, const EVP_MD *md, -\& unsigned int flags); -\& -\& int CMS_SignerInfo_sign(CMS_SignerInfo *si); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_add1_signer()\fR adds a signer with certificate \fBsigncert\fR and private -key \fBpkey\fR using message digest \fBmd\fR to CMS_ContentInfo SignedData -structure \fBcms\fR. -.PP -The CMS_ContentInfo structure should be obtained from an initial call to -\&\fBCMS_sign()\fR with the flag \fB\s-1CMS_PARTIAL\s0\fR set or in the case or re-signing a -valid CMS_ContentInfo SignedData structure. -.PP -If the \fBmd\fR parameter is \fB\s-1NULL\s0\fR then the default digest for the public -key algorithm will be used. -.PP -Unless the \fB\s-1CMS_REUSE_DIGEST\s0\fR flag is set the returned CMS_ContentInfo -structure is not complete and must be finalized either by streaming (if -applicable) or a call to \fBCMS_final()\fR. -.PP -The \fBCMS_SignerInfo_sign()\fR function explicitly signs a CMS_SignerInfo -structure, its main use is when the \fB\s-1CMS_REUSE_DIGEST\s0\fR and \fB\s-1CMS_PARTIAL\s0\fR flags -are both set. -.SH "NOTES" -.IX Header "NOTES" -The main purpose of \fBCMS_add1_signer()\fR is to provide finer control -over a \s-1CMS\s0 signed data structure where the simpler \fBCMS_sign()\fR function defaults -are not appropriate. For example if multiple signers or non default digest -algorithms are needed. New attributes can also be added using the returned -CMS_SignerInfo structure and the \s-1CMS\s0 attribute utility functions or the -\&\s-1CMS\s0 signed receipt request functions. -.PP -Any of the following flags (ored together) can be passed in the \fBflags\fR -parameter. -.PP -If \fB\s-1CMS_REUSE_DIGEST\s0\fR is set then an attempt is made to copy the content -digest value from the CMS_ContentInfo structure: to add a signer to an existing -structure. An error occurs if a matching digest value cannot be found to copy. -The returned CMS_ContentInfo structure will be valid and finalized when this -flag is set. -.PP -If \fB\s-1CMS_PARTIAL\s0\fR is set in addition to \fB\s-1CMS_REUSE_DIGEST\s0\fR then the -CMS_SignerInfo structure will not be finalized so additional attributes -can be added. In this case an explicit call to \fBCMS_SignerInfo_sign()\fR is -needed to finalize it. -.PP -If \fB\s-1CMS_NOCERTS\s0\fR is set the signer's certificate will not be included in the -CMS_ContentInfo structure, the signer's certificate must still be supplied in -the \fBsigncert\fR parameter though. This can reduce the size of the signature if -the signers certificate can be obtained by other means: for example a -previously signed message. -.PP -The SignedData structure includes several \s-1CMS\s0 signedAttributes including the -signing time, the \s-1CMS\s0 content type and the supported list of ciphers in an -SMIMECapabilities attribute. If \fB\s-1CMS_NOATTR\s0\fR is set then no signedAttributes -will be used. If \fB\s-1CMS_NOSMIMECAP\s0\fR is set then just the SMIMECapabilities are -omitted. -.PP -OpenSSL will by default identify signing certificates using issuer name -and serial number. If \fB\s-1CMS_USE_KEYID\s0\fR is set it will use the subject key -identifier value instead. An error occurs if the signing certificate does not -have a subject key identifier extension. -.PP -If present the SMIMECapabilities attribute indicates support for the following -algorithms in preference order: 256 bit \s-1AES,\s0 Gost R3411\-94, Gost 28147\-89, 192 -bit \s-1AES, 128\s0 bit \s-1AES,\s0 triple \s-1DES, 128\s0 bit \s-1RC2, 64\s0 bit \s-1RC2, DES\s0 and 40 bit \s-1RC2.\s0 -If any of these algorithms is not available then it will not be included: for example the \s-1GOST\s0 algorithms will not be included if the \s-1GOST ENGINE\s0 is -not loaded. -.PP -\&\fBCMS_add1_signer()\fR returns an internal pointer to the CMS_SignerInfo -structure just added, this can be used to set additional attributes -before it is finalized. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_add1_signer()\fR returns an internal pointer to the CMS_SignerInfo -structure just added or \s-1NULL\s0 if an error occurs. -.PP -\&\fBCMS_SignerInfo_sign()\fR returns 1 on success, 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3), -\&\fBCMS_final\fR\|(3), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2014\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_compress.3ossl b/openssl-install/share/man/man3/CMS_compress.3ossl deleted file mode 100644 index ad3f11e8..00000000 --- a/openssl-install/share/man/man3/CMS_compress.3ossl +++ /dev/null @@ -1,208 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_COMPRESS 3ossl" -.TH CMS_COMPRESS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_compress \- create a CMS CompressedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *CMS_compress(BIO *in, int comp_nid, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_compress()\fR creates and returns a \s-1CMS\s0 CompressedData structure. \fBcomp_nid\fR -is the compression algorithm to use or \fBNID_undef\fR to use the default -algorithm (zlib compression). \fBin\fR is the content to be compressed. -\&\fBflags\fR is an optional set of flags. -.PP -The only currently supported compression algorithm is zlib using the \s-1NID\s0 -NID_zlib_compression. -.PP -If zlib support is not compiled into OpenSSL then \fBCMS_compress()\fR will return -an error. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are -prepended to the data. -.PP -Normally the supplied content is translated into \s-1MIME\s0 canonical format (as -required by the S/MIME specifications) if \fB\s-1CMS_BINARY\s0\fR is set no translation -occurs. This option should be used if the supplied data is in binary format -otherwise the translation will corrupt it. If \fB\s-1CMS_BINARY\s0\fR is set then -\&\fB\s-1CMS_TEXT\s0\fR is ignored. -.PP -If the \fB\s-1CMS_STREAM\s0\fR flag is set a partial \fBCMS_ContentInfo\fR structure is -returned suitable for streaming I/O: no data is read from the \s-1BIO\s0 \fBin\fR. -.PP -The compressed data is included in the CMS_ContentInfo structure, unless -\&\fB\s-1CMS_DETACHED\s0\fR is set in which case it is omitted. This is rarely used in -practice and is not supported by \fBSMIME_write_CMS()\fR. -.PP -If the flag \fB\s-1CMS_STREAM\s0\fR is set the returned \fBCMS_ContentInfo\fR structure is -\&\fBnot\fR complete and outputting its contents via a function that does not -properly finalize the \fBCMS_ContentInfo\fR structure will give unpredictable -results. -.PP -Several functions including \fBSMIME_write_CMS()\fR, \fBi2d_CMS_bio_stream()\fR, -\&\fBPEM_write_bio_CMS_stream()\fR finalize the structure. Alternatively finalization -can be performed by obtaining the streaming \s-1ASN1\s0 \fB\s-1BIO\s0\fR directly using -\&\fBBIO_new_CMS()\fR. -.PP -Additional compression parameters such as the zlib compression level cannot -currently be set. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_compress()\fR returns either a CMS_ContentInfo structure or \s-1NULL\s0 if an error -occurred. The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_uncompress\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\s-1CMS_STREAM\s0\fR flag was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_data_create.3ossl b/openssl-install/share/man/man3/CMS_data_create.3ossl deleted file mode 100644 index e67a84cd..00000000 --- a/openssl-install/share/man/man3/CMS_data_create.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_DATA_CREATE 3ossl" -.TH CMS_DATA_CREATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_data_create_ex, CMS_data_create -\&\- Create CMS Data object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *CMS_data_create_ex(BIO *in, unsigned int flags, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& CMS_ContentInfo *CMS_data_create(BIO *in, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_data_create_ex()\fR creates a \fBCMS_ContentInfo\fR structure -with a type \fBNID_pkcs7_data\fR. The data is supplied via the \fIin\fR \s-1BIO.\s0 -The library context \fIlibctx\fR and the property query \fIpropq\fR are used when -retrieving algorithms from providers. The \fIflags\fR field supports the -\&\fB\s-1CMS_STREAM\s0\fR flag. Internally \fBCMS_final()\fR is called unless \fB\s-1CMS_STREAM\s0\fR is -specified. -.PP -The \fBCMS_ContentInfo\fR structure can be freed using \fBCMS_ContentInfo_free\fR\|(3). -.PP -\&\fBCMS_data_create()\fR is similar to \fBCMS_data_create_ex()\fR -but uses default values of \s-1NULL\s0 for the library context \fIlibctx\fR and the -property query \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBCMS_data_create_ex()\fR and \fBCMS_data_create()\fR -return \s-1NULL\s0 and set an error code that can be obtained by \fBERR_get_error\fR\|(3). -Otherwise they return a pointer to the newly allocated structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_final\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBCMS_data_create_ex()\fR method was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_data_create_ex.3ossl b/openssl-install/share/man/man3/CMS_data_create_ex.3ossl deleted file mode 120000 index c1357d4a..00000000 --- a/openssl-install/share/man/man3/CMS_data_create_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_data_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_decrypt.3ossl b/openssl-install/share/man/man3/CMS_decrypt.3ossl deleted file mode 100644 index 90073774..00000000 --- a/openssl-install/share/man/man3/CMS_decrypt.3ossl +++ /dev/null @@ -1,251 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_DECRYPT 3ossl" -.TH CMS_DECRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_decrypt, CMS_decrypt_set1_pkey_and_peer, -CMS_decrypt_set1_pkey, CMS_decrypt_set1_password -\&\- decrypt content from a CMS envelopedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_decrypt(CMS_ContentInfo *cms, EVP_PKEY *pkey, X509 *cert, -\& BIO *dcont, BIO *out, unsigned int flags); -\& int CMS_decrypt_set1_pkey_and_peer(CMS_ContentInfo *cms, -\& EVP_PKEY *pk, X509 *cert, X509 *peer); -\& int CMS_decrypt_set1_pkey(CMS_ContentInfo *cms, EVP_PKEY *pk, X509 *cert); -\& int CMS_decrypt_set1_password(CMS_ContentInfo *cms, -\& unsigned char *pass, ossl_ssize_t passlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_decrypt()\fR extracts the decrypted content from a \s-1CMS\s0 EnvelopedData -or AuthEnvelopedData structure. -It uses \fBCMS_decrypt_set1_pkey()\fR to decrypt the content -with the recipient private key \fIpkey\fR if \fIpkey\fR is not \s-1NULL.\s0 -In this case, the associated certificate is recommended to provide in \fIcert\fR \- -see the \s-1NOTES\s0 below. -\&\fIout\fR is a \s-1BIO\s0 to write the content to and -\&\fIflags\fR is an optional set of flags. -If \fIpkey\fR is \s-1NULL\s0 the function assumes that decryption was already done -(e.g., using \fBCMS_decrypt_set1_pkey()\fR or \fBCMS_decrypt_set1_password()\fR) and just -provides the content unless \fIcert\fR, \fIdcont\fR, and \fIout\fR are \s-1NULL\s0 as well. -The \fIdcont\fR parameter is used in the rare case where the encrypted content -is detached. It will normally be set to \s-1NULL.\s0 -.PP -\&\fBCMS_decrypt_set1_pkey_and_peer()\fR decrypts the CMS_ContentInfo structure \fIcms\fR -using the private key \fIpkey\fR, the corresponding certificate \fIcert\fR, which is -recommended but may be \s-1NULL,\s0 and the (optional) originator certificate \fIpeer\fR. -On success, it also records in \fIcms\fR the decryption key \fIpkey\fR, and then -should be followed by \f(CW\*(C`CMS_decrypt(cms, NULL, NULL, dcont, out, flags)\*(C'\fR. -This call deallocates any decryption key stored in \fIcms\fR. -.PP -\&\fBCMS_decrypt_set1_pkey()\fR is the same as -\&\fBCMS_decrypt_set1_pkey_and_peer()\fR with \fIpeer\fR being \s-1NULL.\s0 -.PP -\&\fBCMS_decrypt_set1_password()\fR decrypts the CMS_ContentInfo structure \fIcms\fR -using the secret \fIpass\fR of length \fIpasslen\fR. -On success, it also records in \fIcms\fR the decryption key used, and then -should be followed by \f(CW\*(C`CMS_decrypt(cms, NULL, NULL, dcont, out, flags)\*(C'\fR. -This call deallocates any decryption key stored in \fIcms\fR. -.SH "NOTES" -.IX Header "NOTES" -Although the recipients certificate is not needed to decrypt the data it is -needed to locate the appropriate (of possible several) recipients in the \s-1CMS\s0 -structure. -.PP -If \fIcert\fR is set to \s-1NULL\s0 all possible recipients are tried. This case however -is problematic. To thwart the \s-1MMA\s0 attack (Bleichenbacher's attack on -\&\s-1PKCS\s0 #1 v1.5 \s-1RSA\s0 padding) all recipients are tried whether they succeed or -not. If no recipient succeeds then a random symmetric key is used to decrypt -the content: this will typically output garbage and may (but is not guaranteed -to) ultimately return a padding error only. If \fBCMS_decrypt()\fR just returned an -error when all recipient encrypted keys failed to decrypt an attacker could -use this in a timing attack. If the special flag \fB\s-1CMS_DEBUG_DECRYPT\s0\fR is set -then the above behaviour is modified and an error \fBis\fR returned if no -recipient encrypted key can be decrypted \fBwithout\fR generating a random -content encryption key. Applications should use this flag with -\&\fBextreme caution\fR especially in automated gateways as it can leave them -open to attack. -.PP -It is possible to determine the correct recipient key by other means (for -example looking them up in a database) and setting them in the \s-1CMS\s0 structure -in advance using the \s-1CMS\s0 utility functions such as \fBCMS_set1_pkey()\fR, -or use \fBCMS_decrypt_set1_password()\fR if the recipient has a symmetric key. -In these cases both \fIcert\fR and \fIpkey\fR should be set to \s-1NULL.\s0 -.PP -To process KEKRecipientInfo types \fBCMS_set1_key()\fR or \fBCMS_RecipientInfo_set0_key()\fR -and \fBCMS_RecipientInfo_decrypt()\fR should be called before \fBCMS_decrypt()\fR and -\&\fIcert\fR and \fIpkey\fR set to \s-1NULL.\s0 -.PP -The following flags can be passed in the \fIflags\fR parameter. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \f(CW\*(C`text/plain\*(C'\fR are deleted -from the content. If the content is not of type \f(CW\*(C`text/plain\*(C'\fR then an error is -returned. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_decrypt()\fR, \fBCMS_decrypt_set1_pkey_and_peer()\fR, -\&\fBCMS_decrypt_set1_pkey()\fR, and \fBCMS_decrypt_set1_password()\fR -return either 1 for success or 0 for failure. -The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "BUGS" -.IX Header "BUGS" -The \fBset1_\fR part of these function names is misleading -and should better read: \fBwith_\fR. -.PP -The lack of single pass processing and the need to hold all data in memory as -mentioned in \fBCMS_verify()\fR also applies to \fBCMS_decrypt()\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_encrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCMS_decrypt_set1_pkey_and_peer()\fR and \fBCMS_decrypt_set1_password()\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_decrypt_set1_password.3ossl b/openssl-install/share/man/man3/CMS_decrypt_set1_password.3ossl deleted file mode 120000 index 6726bb78..00000000 --- a/openssl-install/share/man/man3/CMS_decrypt_set1_password.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_decrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_decrypt_set1_pkey.3ossl b/openssl-install/share/man/man3/CMS_decrypt_set1_pkey.3ossl deleted file mode 120000 index 6726bb78..00000000 --- a/openssl-install/share/man/man3/CMS_decrypt_set1_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_decrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_decrypt_set1_pkey_and_peer.3ossl b/openssl-install/share/man/man3/CMS_decrypt_set1_pkey_and_peer.3ossl deleted file mode 120000 index 6726bb78..00000000 --- a/openssl-install/share/man/man3/CMS_decrypt_set1_pkey_and_peer.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_decrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_digest_create.3ossl b/openssl-install/share/man/man3/CMS_digest_create.3ossl deleted file mode 100644 index fd0426e4..00000000 --- a/openssl-install/share/man/man3/CMS_digest_create.3ossl +++ /dev/null @@ -1,188 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_DIGEST_CREATE 3ossl" -.TH CMS_DIGEST_CREATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_digest_create_ex, CMS_digest_create -\&\- Create CMS DigestedData object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *CMS_digest_create_ex(BIO *in, const EVP_MD *md, -\& unsigned int flags, OSSL_LIB_CTX *ctx, -\& const char *propq); -\& -\& CMS_ContentInfo *CMS_digest_create(BIO *in, const EVP_MD *md, -\& unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_digest_create_ex()\fR creates a \fBCMS_ContentInfo\fR structure -with a type \fBNID_pkcs7_digest\fR. The data supplied via the \fIin\fR \s-1BIO\s0 is digested -using \fImd\fR. The library context \fIlibctx\fR and the property query \fIpropq\fR are -used when retrieving algorithms from providers. -The \fIflags\fR field supports the \fB\s-1CMS_DETACHED\s0\fR and \fB\s-1CMS_STREAM\s0\fR flags, -Internally \fBCMS_final()\fR is called unless \fB\s-1CMS_STREAM\s0\fR is specified. -.PP -The \fBCMS_ContentInfo\fR structure can be freed using \fBCMS_ContentInfo_free\fR\|(3). -.PP -\&\fBCMS_digest_create()\fR is similar to \fBCMS_digest_create_ex()\fR -but uses default values of \s-1NULL\s0 for the library context \fIlibctx\fR and the -property query \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBCMS_digest_create_ex()\fR and \fBCMS_digest_create()\fR -return \s-1NULL\s0 and set an error code that can be obtained by \fBERR_get_error\fR\|(3). -Otherwise they return a pointer to the newly allocated structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_final\fR\|(3)> -.SH "HISTORY" -.IX Header "HISTORY" -The \fBCMS_digest_create_ex()\fR method was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_digest_create_ex.3ossl b/openssl-install/share/man/man3/CMS_digest_create_ex.3ossl deleted file mode 120000 index 563a53cc..00000000 --- a/openssl-install/share/man/man3/CMS_digest_create_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_digest_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_encrypt.3ossl b/openssl-install/share/man/man3/CMS_encrypt.3ossl deleted file mode 100644 index 855df2f5..00000000 --- a/openssl-install/share/man/man3/CMS_encrypt.3ossl +++ /dev/null @@ -1,245 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_ENCRYPT 3ossl" -.TH CMS_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_encrypt_ex, CMS_encrypt \- create a CMS envelopedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *CMS_encrypt_ex(STACK_OF(X509) *certs, BIO *in, -\& const EVP_CIPHER *cipher, unsigned int flags, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& CMS_ContentInfo *CMS_encrypt(STACK_OF(X509) *certs, BIO *in, -\& const EVP_CIPHER *cipher, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_encrypt_ex()\fR creates and returns a \s-1CMS\s0 EnvelopedData or -AuthEnvelopedData structure. \fIcerts\fR is a list of recipient certificates. -\&\fIin\fR is the content to be encrypted. \fIcipher\fR is the symmetric cipher to use. -\&\fIflags\fR is an optional set of flags. The library context \fIlibctx\fR and the -property query \fIpropq\fR are used internally when retrieving algorithms from -providers. -.PP -Only certificates carrying \s-1RSA,\s0 Diffie-Hellman or \s-1EC\s0 keys are supported by this -function. -.PP -\&\fBEVP_des_ede3_cbc()\fR (triple \s-1DES\s0) is the algorithm of choice for S/MIME use -because most clients will support it. -.PP -The algorithm passed in the \fBcipher\fR parameter must support \s-1ASN1\s0 encoding of -its parameters. If the cipher mode is \s-1GCM,\s0 then an AuthEnvelopedData structure -containing \s-1MAC\s0 is used. Otherwise an EnvelopedData structure is used. Currently -the \s-1AES\s0 variants with \s-1GCM\s0 mode are the only supported \s-1AEAD\s0 algorithms. -.PP -Many browsers implement a \*(L"sign and encrypt\*(R" option which is simply an S/MIME -envelopedData containing an S/MIME signed message. This can be readily produced -by storing the S/MIME signed message in a memory \s-1BIO\s0 and passing it to -\&\fBCMS_encrypt()\fR. -.PP -The following flags can be passed in the \fBflags\fR parameter. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are -prepended to the data. -.PP -Normally the supplied content is translated into \s-1MIME\s0 canonical format (as -required by the S/MIME specifications) if \fB\s-1CMS_BINARY\s0\fR is set no translation -occurs. This option should be used if the supplied data is in binary format -otherwise the translation will corrupt it. If \fB\s-1CMS_BINARY\s0\fR is set then -\&\fB\s-1CMS_TEXT\s0\fR is ignored. -.PP -OpenSSL will by default identify recipient certificates using issuer name -and serial number. If \fB\s-1CMS_USE_KEYID\s0\fR is set it will use the subject key -identifier value instead. An error occurs if all recipient certificates do not -have a subject key identifier extension. -.PP -If the \fB\s-1CMS_STREAM\s0\fR flag is set a partial \fBCMS_ContentInfo\fR structure is -returned suitable for streaming I/O: no data is read from the \s-1BIO\s0 \fBin\fR. -.PP -If the \fB\s-1CMS_PARTIAL\s0\fR flag is set a partial \fBCMS_ContentInfo\fR structure is -returned to which additional recipients and attributes can be added before -finalization. -.PP -The data being encrypted is included in the CMS_ContentInfo structure, unless -\&\fB\s-1CMS_DETACHED\s0\fR is set in which case it is omitted. This is rarely used in -practice and is not supported by \fBSMIME_write_CMS()\fR. -.PP -If the flag \fB\s-1CMS_STREAM\s0\fR is set the returned \fBCMS_ContentInfo\fR structure is -\&\fBnot\fR complete and outputting its contents via a function that does not -properly finalize the \fBCMS_ContentInfo\fR structure will give unpredictable -results. -.PP -Several functions including \fBSMIME_write_CMS()\fR, \fBi2d_CMS_bio_stream()\fR, -\&\fBPEM_write_bio_CMS_stream()\fR finalize the structure. Alternatively finalization -can be performed by obtaining the streaming \s-1ASN1\s0 \fB\s-1BIO\s0\fR directly using -\&\fBBIO_new_CMS()\fR. -.PP -The recipients specified in \fBcerts\fR use a \s-1CMS\s0 KeyTransRecipientInfo info -structure. KEKRecipientInfo is also supported using the flag \fB\s-1CMS_PARTIAL\s0\fR -and \fBCMS_add0_recipient_key()\fR. -.PP -The parameter \fBcerts\fR may be \s-1NULL\s0 if \fB\s-1CMS_PARTIAL\s0\fR is set and recipients -added later using \fBCMS_add1_recipient_cert()\fR or \fBCMS_add0_recipient_key()\fR. -.PP -\&\fBCMS_encrypt()\fR is similar to \fBCMS_encrypt_ex()\fR but uses default values -of \s-1NULL\s0 for the library context \fIlibctx\fR and the property query \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_encrypt_ex()\fR and \fBCMS_encrypt()\fR return either a CMS_ContentInfo -structure or \s-1NULL\s0 if an error occurred. The error can be obtained from -\&\fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBCMS_encrypt_ex()\fR was added in OpenSSL 3.0. -.PP -The \fB\s-1CMS_STREAM\s0\fR flag was first supported in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_encrypt_ex.3ossl b/openssl-install/share/man/man3/CMS_encrypt_ex.3ossl deleted file mode 120000 index d2b5fa55..00000000 --- a/openssl-install/share/man/man3/CMS_encrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_final.3ossl b/openssl-install/share/man/man3/CMS_final.3ossl deleted file mode 100644 index bc914305..00000000 --- a/openssl-install/share/man/man3/CMS_final.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_FINAL 3ossl" -.TH CMS_FINAL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_final, CMS_final_digest \- finalise a CMS_ContentInfo structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_final(CMS_ContentInfo *cms, BIO *data, BIO *dcont, unsigned int flags); -\& int CMS_final_digest(CMS_ContentInfo *cms, const unsigned char *md, -\& unsigned int mdlen, BIO *dcont, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_final()\fR finalises the structure \fBcms\fR. Its purpose is to perform any -operations necessary on \fBcms\fR (digest computation for example) and set the -appropriate fields. The parameter \fBdata\fR contains the content to be -processed. The \fBdcont\fR parameter contains a \s-1BIO\s0 to write content to after -processing: this is only used with detached data and will usually be set to -\&\s-1NULL.\s0 -.PP -\&\fBCMS_final_digest()\fR finalises the structure \fBcms\fR using a pre-computed digest, -rather than computing the digest from the original data. -.SH "NOTES" -.IX Header "NOTES" -These functions will normally be called when the \fB\s-1CMS_PARTIAL\s0\fR flag is used. It -should only be used when streaming is not performed because the streaming -I/O functions perform finalisation operations internally. -.PP -To sign a pre-computed digest, \fBCMS_sign\fR\|(3) or \fBCMS_sign_ex()\fR is called -with the \fBdata\fR parameter set to \s-1NULL\s0 before the \s-1CMS\s0 structure is finalised -with the digest provided to \fBCMS_final_digest()\fR in binary form. -When signing a pre-computed digest, the security relies on the digest and its -computation from the original message being trusted. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_final()\fR and \fBCMS_final_digest()\fR return 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3), -\&\fBCMS_encrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCMS_final_digest()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_final_digest.3ossl b/openssl-install/share/man/man3/CMS_final_digest.3ossl deleted file mode 120000 index dcfdf7a9..00000000 --- a/openssl-install/share/man/man3/CMS_final_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_final.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_get0_RecipientInfos.3ossl b/openssl-install/share/man/man3/CMS_get0_RecipientInfos.3ossl deleted file mode 100644 index 5b8dc981..00000000 --- a/openssl-install/share/man/man3/CMS_get0_RecipientInfos.3ossl +++ /dev/null @@ -1,285 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_GET0_RECIPIENTINFOS 3ossl" -.TH CMS_GET0_RECIPIENTINFOS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_get0_RecipientInfos, CMS_RecipientInfo_type, -CMS_RecipientInfo_ktri_get0_signer_id, CMS_RecipientInfo_ktri_cert_cmp, -CMS_RecipientInfo_set0_pkey, CMS_RecipientInfo_kekri_get0_id, -CMS_RecipientInfo_kari_set0_pkey_and_peer, -CMS_RecipientInfo_kari_set0_pkey, -CMS_RecipientInfo_kekri_id_cmp, CMS_RecipientInfo_set0_key, -CMS_RecipientInfo_decrypt, CMS_RecipientInfo_encrypt -\&\- CMS envelopedData RecipientInfo routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(CMS_RecipientInfo) *CMS_get0_RecipientInfos(CMS_ContentInfo *cms); -\& int CMS_RecipientInfo_type(CMS_RecipientInfo *ri); -\& -\& int CMS_RecipientInfo_ktri_get0_signer_id(CMS_RecipientInfo *ri, -\& ASN1_OCTET_STRING **keyid, -\& X509_NAME **issuer, -\& ASN1_INTEGER **sno); -\& int CMS_RecipientInfo_ktri_cert_cmp(CMS_RecipientInfo *ri, X509 *cert); -\& int CMS_RecipientInfo_set0_pkey(CMS_RecipientInfo *ri, EVP_PKEY *pkey); -\& int CMS_RecipientInfo_kari_set0_pkey_and_peer(CMS_RecipientInfo *ri, -\& EVP_PKEY *pk, X509 *peer); -\& int CMS_RecipientInfo_kari_set0_pkey(CMS_RecipientInfo *ri, EVP_PKEY *pk); -\& int CMS_RecipientInfo_kekri_get0_id(CMS_RecipientInfo *ri, X509_ALGOR **palg, -\& ASN1_OCTET_STRING **pid, -\& ASN1_GENERALIZEDTIME **pdate, -\& ASN1_OBJECT **potherid, -\& ASN1_TYPE **pothertype); -\& int CMS_RecipientInfo_kekri_id_cmp(CMS_RecipientInfo *ri, -\& const unsigned char *id, size_t idlen); -\& int CMS_RecipientInfo_set0_key(CMS_RecipientInfo *ri, -\& unsigned char *key, size_t keylen); -\& -\& int CMS_RecipientInfo_decrypt(CMS_ContentInfo *cms, CMS_RecipientInfo *ri); -\& int CMS_RecipientInfo_encrypt(CMS_ContentInfo *cms, CMS_RecipientInfo *ri); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBCMS_get0_RecipientInfos()\fR returns all the CMS_RecipientInfo -structures associated with a \s-1CMS\s0 EnvelopedData structure. -.PP -\&\fBCMS_RecipientInfo_type()\fR returns the type of CMS_RecipientInfo structure \fBri\fR. -It will currently return \s-1CMS_RECIPINFO_TRANS, CMS_RECIPINFO_AGREE, -CMS_RECIPINFO_KEK, CMS_RECIPINFO_PASS,\s0 or \s-1CMS_RECIPINFO_OTHER.\s0 -.PP -\&\fBCMS_RecipientInfo_ktri_get0_signer_id()\fR retrieves the certificate recipient -identifier associated with a specific CMS_RecipientInfo structure \fBri\fR, which -must be of type \s-1CMS_RECIPINFO_TRANS.\s0 Either the keyidentifier will be set in -\&\fBkeyid\fR or \fBboth\fR issuer name and serial number in \fBissuer\fR and \fBsno\fR. -.PP -\&\fBCMS_RecipientInfo_ktri_cert_cmp()\fR compares the certificate \fBcert\fR against the -CMS_RecipientInfo structure \fBri\fR, which must be of type \s-1CMS_RECIPINFO_TRANS.\s0 -It returns zero if the comparison is successful and non zero if not. -.PP -\&\fBCMS_RecipientInfo_set0_pkey()\fR associates the private key \fBpkey\fR with -the CMS_RecipientInfo structure \fBri\fR, which must be of type -\&\s-1CMS_RECIPINFO_TRANS.\s0 -.PP -\&\fBCMS_RecipientInfo_kari_set0_pkey_and_peer()\fR associates the private key \fBpkey\fR -and peer certificate \fBpeer\fR with the CMS_RecipientInfo structure \fBri\fR, which -must be of type \s-1CMS_RECIPINFO_AGREE.\s0 -.PP -\&\fBCMS_RecipientInfo_kari_set0_pkey()\fR associates the private key \fBpkey\fR with the -CMS_RecipientInfo structure \fBri\fR, which must be of type \s-1CMS_RECIPINFO_AGREE.\s0 -.PP -\&\fBCMS_RecipientInfo_kekri_get0_id()\fR retrieves the key information from the -CMS_RecipientInfo structure \fBri\fR which must be of type \s-1CMS_RECIPINFO_KEK.\s0 Any -of the remaining parameters can be \s-1NULL\s0 if the application is not interested in -the value of a field. Where a field is optional and absent \s-1NULL\s0 will be written -to the corresponding parameter. The keyEncryptionAlgorithm field is written to -\&\fBpalg\fR, the \fBkeyIdentifier\fR field is written to \fBpid\fR, the \fBdate\fR field if -present is written to \fBpdate\fR, if the \fBother\fR field is present the components -\&\fBkeyAttrId\fR and \fBkeyAttr\fR are written to parameters \fBpotherid\fR and -\&\fBpothertype\fR. -.PP -\&\fBCMS_RecipientInfo_kekri_id_cmp()\fR compares the \s-1ID\s0 in the \fBid\fR and \fBidlen\fR -parameters against the \fBkeyIdentifier\fR CMS_RecipientInfo structure \fBri\fR, -which must be of type \s-1CMS_RECIPINFO_KEK.\s0 It returns zero if the comparison is -successful and non zero if not. -.PP -\&\fBCMS_RecipientInfo_set0_key()\fR associates the symmetric key \fBkey\fR of length -\&\fBkeylen\fR with the CMS_RecipientInfo structure \fBri\fR, which must be of type -\&\s-1CMS_RECIPINFO_KEK.\s0 -.PP -\&\fBCMS_RecipientInfo_decrypt()\fR attempts to decrypt CMS_RecipientInfo structure -\&\fBri\fR in structure \fBcms\fR. A key must have been associated with the structure -first. -.PP -\&\fBCMS_RecipientInfo_encrypt()\fR attempts to encrypt CMS_RecipientInfo structure -\&\fBri\fR in structure \fBcms\fR. A key must have been associated with the structure -first and the content encryption key must be available: for example by a -previous call to \fBCMS_RecipientInfo_decrypt()\fR. -.SH "NOTES" -.IX Header "NOTES" -The main purpose of these functions is to enable an application to lookup -recipient keys using any appropriate technique when the simpler method -of \fBCMS_decrypt()\fR is not appropriate. -.PP -In typical usage and application will retrieve all CMS_RecipientInfo structures -using \fBCMS_get0_RecipientInfos()\fR and check the type of each using -\&\fBCMS_RecipientInfo_type()\fR. Depending on the type the CMS_RecipientInfo structure -can be ignored or its key identifier data retrieved using an appropriate -function. Then if the corresponding secret or private key can be obtained by -any appropriate means it can then associated with the structure and -\&\fBCMS_RecipientInfo_decrypt()\fR called. If successful \fBCMS_decrypt()\fR can be called -with a \s-1NULL\s0 key to decrypt the enveloped content. -.PP -The \fBCMS_RecipientInfo_encrypt()\fR can be used to add a new recipient to an -existing enveloped data structure. Typically an application will first decrypt -an appropriate CMS_RecipientInfo structure to make the content encrypt key -available, it will then add a new recipient using a function such as -\&\fBCMS_add1_recipient_cert()\fR and finally encrypt the content encryption key -using \fBCMS_RecipientInfo_encrypt()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_get0_RecipientInfos()\fR returns all CMS_RecipientInfo structures, or \s-1NULL\s0 if -an error occurs. -.PP -\&\fBCMS_RecipientInfo_ktri_get0_signer_id()\fR, \fBCMS_RecipientInfo_set0_pkey()\fR, -\&\fBCMS_RecipientInfo_kekri_get0_id()\fR, \fBCMS_RecipientInfo_set0_key()\fR and -\&\fBCMS_RecipientInfo_decrypt()\fR return 1 for success or 0 if an error occurs. -\&\fBCMS_RecipientInfo_encrypt()\fR return 1 for success or 0 if an error occurs. -.PP -\&\fBCMS_RecipientInfo_ktri_cert_cmp()\fR and \fBCMS_RecipientInfo_kekri_cmp()\fR return 0 -for a successful comparison and non zero otherwise. -.PP -Any error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCMS_RecipientInfo_kari_set0_pkey_and_peer\fR and \fBCMS_RecipientInfo_kari_set0_pkey\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_get0_SignerInfos.3ossl b/openssl-install/share/man/man3/CMS_get0_SignerInfos.3ossl deleted file mode 100644 index 801f4ebc..00000000 --- a/openssl-install/share/man/man3/CMS_get0_SignerInfos.3ossl +++ /dev/null @@ -1,221 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_GET0_SIGNERINFOS 3ossl" -.TH CMS_GET0_SIGNERINFOS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_SignerInfo_set1_signer_cert, -CMS_get0_SignerInfos, CMS_SignerInfo_get0_signer_id, -CMS_SignerInfo_get0_signature, CMS_SignerInfo_cert_cmp -\&\- CMS signedData signer functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(CMS_SignerInfo) *CMS_get0_SignerInfos(CMS_ContentInfo *cms); -\& -\& int CMS_SignerInfo_get0_signer_id(CMS_SignerInfo *si, ASN1_OCTET_STRING **keyid, -\& X509_NAME **issuer, ASN1_INTEGER **sno); -\& ASN1_OCTET_STRING *CMS_SignerInfo_get0_signature(CMS_SignerInfo *si); -\& int CMS_SignerInfo_cert_cmp(CMS_SignerInfo *si, X509 *cert); -\& void CMS_SignerInfo_set1_signer_cert(CMS_SignerInfo *si, X509 *signer); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBCMS_get0_SignerInfos()\fR returns all the CMS_SignerInfo structures -associated with a \s-1CMS\s0 signedData structure. -.PP -\&\fBCMS_SignerInfo_get0_signer_id()\fR retrieves the certificate signer identifier -associated with a specific CMS_SignerInfo structure \fBsi\fR. Either the -keyidentifier will be set in \fBkeyid\fR or \fBboth\fR issuer name and serial number -in \fBissuer\fR and \fBsno\fR. -.PP -\&\fBCMS_SignerInfo_get0_signature()\fR retrieves the signature associated with -\&\fBsi\fR in a pointer to an \s-1ASN1_OCTET_STRING\s0 structure. This pointer returned -corresponds to the internal signature value if \fBsi\fR so it may be read or -modified. -.PP -\&\fBCMS_SignerInfo_cert_cmp()\fR compares the certificate \fBcert\fR against the signer -identifier \fBsi\fR. It returns zero if the comparison is successful and non zero -if not. -.PP -\&\fBCMS_SignerInfo_set1_signer_cert()\fR sets the signers certificate of \fBsi\fR to -\&\fBsigner\fR. -.SH "NOTES" -.IX Header "NOTES" -The main purpose of these functions is to enable an application to lookup -signers certificates using any appropriate technique when the simpler method -of \fBCMS_verify()\fR is not appropriate. -.PP -In typical usage and application will retrieve all CMS_SignerInfo structures -using \fBCMS_get0_SignerInfo()\fR and retrieve the identifier information using -\&\s-1CMS.\s0 It will then obtain the signer certificate by some unspecified means -(or return and error if it cannot be found) and set it using -\&\fBCMS_SignerInfo_set1_signer_cert()\fR. -.PP -Once all signer certificates have been set \fBCMS_verify()\fR can be used. -.PP -Although \fBCMS_get0_SignerInfos()\fR can return \s-1NULL\s0 if an error occurs \fBor\fR if -there are no signers this is not a problem in practice because the only -error which can occur is if the \fBcms\fR structure is not of type signedData -due to application error. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_get0_SignerInfos()\fR returns all CMS_SignerInfo structures, or \s-1NULL\s0 there -are no signers or an error occurs. -.PP -\&\fBCMS_SignerInfo_get0_signer_id()\fR returns 1 for success and 0 for failure. -.PP -\&\fBCMS_SignerInfo_cert_cmp()\fR returns 0 for a successful comparison and non -zero otherwise. -.PP -\&\fBCMS_SignerInfo_set1_signer_cert()\fR does not return a value. -.PP -Any error can be obtained from \fBERR_get_error\fR\|(3) -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_verify\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_get0_content.3ossl b/openssl-install/share/man/man3/CMS_get0_content.3ossl deleted file mode 120000 index e55fd595..00000000 --- a/openssl-install/share/man/man3/CMS_get0_content.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_get0_eContentType.3ossl b/openssl-install/share/man/man3/CMS_get0_eContentType.3ossl deleted file mode 120000 index e55fd595..00000000 --- a/openssl-install/share/man/man3/CMS_get0_eContentType.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_get0_signers.3ossl b/openssl-install/share/man/man3/CMS_get0_signers.3ossl deleted file mode 120000 index 323b8d52..00000000 --- a/openssl-install/share/man/man3/CMS_get0_signers.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_get0_type.3ossl b/openssl-install/share/man/man3/CMS_get0_type.3ossl deleted file mode 100644 index 6ae39caf..00000000 --- a/openssl-install/share/man/man3/CMS_get0_type.3ossl +++ /dev/null @@ -1,218 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_GET0_TYPE 3ossl" -.TH CMS_GET0_TYPE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_get0_type, CMS_set1_eContentType, CMS_get0_eContentType, CMS_get0_content \- get and set CMS content types and content -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const ASN1_OBJECT *CMS_get0_type(const CMS_ContentInfo *cms); -\& int CMS_set1_eContentType(CMS_ContentInfo *cms, const ASN1_OBJECT *oid); -\& const ASN1_OBJECT *CMS_get0_eContentType(CMS_ContentInfo *cms); -\& ASN1_OCTET_STRING **CMS_get0_content(CMS_ContentInfo *cms); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_get0_type()\fR returns the content type of a CMS_ContentInfo structure as -an \s-1ASN1_OBJECT\s0 pointer. An application can then decide how to process the -CMS_ContentInfo structure based on this value. -.PP -\&\fBCMS_set1_eContentType()\fR sets the embedded content type of a CMS_ContentInfo -structure. It should be called with \s-1CMS\s0 functions (such as \fBCMS_sign\fR\|(3), -\&\fBCMS_encrypt\fR\|(3)) -with the \fB\s-1CMS_PARTIAL\s0\fR -flag and \fBbefore\fR the structure is finalised, otherwise the results are -undefined. -.PP -\&\s-1ASN1_OBJECT\s0 *\fBCMS_get0_eContentType()\fR returns a pointer to the embedded -content type. -.PP -\&\fBCMS_get0_content()\fR returns a pointer to the \fB\s-1ASN1_OCTET_STRING\s0\fR pointer -containing the embedded content. -.SH "NOTES" -.IX Header "NOTES" -As the \fB0\fR implies \fBCMS_get0_type()\fR, \fBCMS_get0_eContentType()\fR and -\&\fBCMS_get0_content()\fR return internal pointers which should \fBnot\fR be freed up. -\&\fBCMS_set1_eContentType()\fR copies the supplied \s-1OID\s0 and it \fBshould\fR be freed up -after use. -.PP -The \fB\s-1ASN1_OBJECT\s0\fR values returned can be converted to an integer \fB\s-1NID\s0\fR value -using \fBOBJ_obj2nid()\fR. For the currently supported content types the following -values are returned: -.PP -.Vb 6 -\& NID_pkcs7_data -\& NID_pkcs7_signed -\& NID_pkcs7_digest -\& NID_id_smime_ct_compressedData: -\& NID_pkcs7_encrypted -\& NID_pkcs7_enveloped -.Ve -.PP -The return value of \fBCMS_get0_content()\fR is a pointer to the \fB\s-1ASN1_OCTET_STRING\s0\fR -content pointer. That means that for example: -.PP -.Vb 1 -\& ASN1_OCTET_STRING **pconf = CMS_get0_content(cms); -.Ve -.PP -\&\fB*pconf\fR could be \s-1NULL\s0 if there is no embedded content. Applications can -access, modify or create the embedded content in a \fBCMS_ContentInfo\fR structure -using this function. Applications usually will not need to modify the -embedded content as it is normally set by higher level functions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_get0_type()\fR and \fBCMS_get0_eContentType()\fR return an \s-1ASN1_OBJECT\s0 structure. -.PP -\&\fBCMS_set1_eContentType()\fR returns 1 for success or 0 if an error occurred. The -error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_get1_ReceiptRequest.3ossl b/openssl-install/share/man/man3/CMS_get1_ReceiptRequest.3ossl deleted file mode 100644 index 44aa0c61..00000000 --- a/openssl-install/share/man/man3/CMS_get1_ReceiptRequest.3ossl +++ /dev/null @@ -1,222 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_GET1_RECEIPTREQUEST 3ossl" -.TH CMS_GET1_RECEIPTREQUEST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_ReceiptRequest_create0_ex, CMS_ReceiptRequest_create0, -CMS_add1_ReceiptRequest, CMS_get1_ReceiptRequest, CMS_ReceiptRequest_get0_values -\&\- CMS signed receipt request functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ReceiptRequest *CMS_ReceiptRequest_create0_ex( -\& unsigned char *id, int idlen, int allorfirst, -\& STACK_OF(GENERAL_NAMES) *receiptList, STACK_OF(GENERAL_NAMES) *receiptsTo, -\& OSSL_LIB_CTX *libctx); -\& CMS_ReceiptRequest *CMS_ReceiptRequest_create0( -\& unsigned char *id, int idlen, int allorfirst, -\& STACK_OF(GENERAL_NAMES) *receiptList, STACK_OF(GENERAL_NAMES) *receiptsTo); -\& int CMS_add1_ReceiptRequest(CMS_SignerInfo *si, CMS_ReceiptRequest *rr); -\& int CMS_get1_ReceiptRequest(CMS_SignerInfo *si, CMS_ReceiptRequest **prr); -\& void CMS_ReceiptRequest_get0_values(CMS_ReceiptRequest *rr, ASN1_STRING **pcid, -\& int *pallorfirst, -\& STACK_OF(GENERAL_NAMES) **plist, -\& STACK_OF(GENERAL_NAMES) **prto); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_ReceiptRequest_create0_ex()\fR creates a signed receipt request -structure. The \fBsignedContentIdentifier\fR field is set using \fIid\fR and \fIidlen\fR, -or it is set to 32 bytes of pseudo random data if \fIid\fR is \s-1NULL.\s0 -If \fIreceiptList\fR is \s-1NULL\s0 the allOrFirstTier option in \fIreceiptsFrom\fR is used -and set to the value of the \fIallorfirst\fR parameter. If \fIreceiptList\fR is not -\&\s-1NULL\s0 the \fIreceiptList\fR option in \fIreceiptsFrom\fR is used. The \fIreceiptsTo\fR -parameter specifies the \fIreceiptsTo\fR field value. The library context \fIlibctx\fR -is used to find the public random generator. -.PP -\&\fBCMS_ReceiptRequest_create0()\fR is similar to -\&\fBCMS_ReceiptRequest_create0_ex()\fR but uses default values of \s-1NULL\s0 for the -library context \fIlibctx\fR. -.PP -The \fBCMS_add1_ReceiptRequest()\fR function adds a signed receipt request \fBrr\fR -to SignerInfo structure \fBsi\fR. -.PP -int \fBCMS_get1_ReceiptRequest()\fR looks for a signed receipt request in \fBsi\fR, if -any is found it is decoded and written to \fBprr\fR. -.PP -\&\fBCMS_ReceiptRequest_get0_values()\fR retrieves the values of a receipt request. -The signedContentIdentifier is copied to \fBpcid\fR. If the \fBallOrFirstTier\fR -option of \fBreceiptsFrom\fR is used its value is copied to \fBpallorfirst\fR -otherwise the \fBreceiptList\fR field is copied to \fBplist\fR. The \fBreceiptsTo\fR -parameter is copied to \fBprto\fR. -.SH "NOTES" -.IX Header "NOTES" -For more details of the meaning of the fields see \s-1RFC2634.\s0 -.PP -The contents of a signed receipt should only be considered meaningful if the -corresponding CMS_ContentInfo structure can be successfully verified using -\&\fBCMS_verify()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_ReceiptRequest_create0_ex()\fR and \fBCMS_ReceiptRequest_create0()\fR return -a signed receipt request structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBCMS_add1_ReceiptRequest()\fR returns 1 for success or 0 if an error occurred. -.PP -\&\fBCMS_get1_ReceiptRequest()\fR returns 1 is a signed receipt request is found and -decoded. It returns 0 if a signed receipt request is not present and \-1 if -it is present but malformed. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3), -\&\fBCMS_sign_receipt\fR\|(3), \fBCMS_verify\fR\|(3) -\&\fBCMS_verify_receipt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBCMS_ReceiptRequest_create0_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_get1_certs.3ossl b/openssl-install/share/man/man3/CMS_get1_certs.3ossl deleted file mode 120000 index 6347d625..00000000 --- a/openssl-install/share/man/man3/CMS_get1_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add0_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_get1_crls.3ossl b/openssl-install/share/man/man3/CMS_get1_crls.3ossl deleted file mode 120000 index 6347d625..00000000 --- a/openssl-install/share/man/man3/CMS_get1_crls.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_add0_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_set1_eContentType.3ossl b/openssl-install/share/man/man3/CMS_set1_eContentType.3ossl deleted file mode 120000 index e55fd595..00000000 --- a/openssl-install/share/man/man3/CMS_set1_eContentType.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_get0_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_sign.3ossl b/openssl-install/share/man/man3/CMS_sign.3ossl deleted file mode 100644 index 19022355..00000000 --- a/openssl-install/share/man/man3/CMS_sign.3ossl +++ /dev/null @@ -1,274 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_SIGN 3ossl" -.TH CMS_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_sign, CMS_sign_ex \- create a CMS SignedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *CMS_sign_ex(X509 *signcert, EVP_PKEY *pkey, -\& STACK_OF(X509) *certs, BIO *data, -\& unsigned int flags, OSSL_LIB_CTX *ctx, -\& const char *propq); -\& CMS_ContentInfo *CMS_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, -\& BIO *data, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_sign_ex()\fR creates and returns a \s-1CMS\s0 SignedData structure. -\&\fIsigncert\fR is the certificate to sign with, \fIpkey\fR is the corresponding -private key. \fIcerts\fR is an optional additional set of certificates to include -in the \s-1CMS\s0 structure (for example any intermediate CAs in the chain). The -library context \fIlibctx\fR and the property query \fIpropq\fR are used when -retrieving algorithms from providers. Any or all of these parameters can be -\&\fB\s-1NULL\s0\fR, see \fB\s-1NOTES\s0\fR below. -.PP -The data to be signed is read from \s-1BIO\s0 \fBdata\fR. -.PP -\&\fBflags\fR is an optional set of flags. -.PP -\&\fBCMS_sign()\fR is similar to \fBCMS_sign_ex()\fR but uses default values of \s-1NULL\s0 -for the library context \fIlibctx\fR and the property query \fIpropq\fR. -.SH "NOTES" -.IX Header "NOTES" -Any of the following flags (ored together) can be passed in the \fBflags\fR -parameter. -.PP -Many S/MIME clients expect the signed content to include valid \s-1MIME\s0 headers. If -the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are prepended -to the data. -.PP -If \fB\s-1CMS_NOCERTS\s0\fR is set the signer's certificate will not be included in the -CMS_ContentInfo structure, the signer's certificate must still be supplied in -the \fBsigncert\fR parameter though. This can reduce the size of the signature if -the signers certificate can be obtained by other means: for example a -previously signed message. -.PP -The data being signed is included in the CMS_ContentInfo structure, unless -\&\fB\s-1CMS_DETACHED\s0\fR is set in which case it is omitted. This is used for -CMS_ContentInfo detached signatures which are used in S/MIME plaintext signed -messages for example. -.PP -Normally the supplied content is translated into \s-1MIME\s0 canonical format (as -required by the S/MIME specifications) if \fB\s-1CMS_BINARY\s0\fR is set no translation -occurs. This option should be used if the supplied data is in binary format -otherwise the translation will corrupt it. -.PP -The SignedData structure includes several \s-1CMS\s0 signedAttributes including the -signing time, the \s-1CMS\s0 content type and the supported list of ciphers in an -SMIMECapabilities attribute. If \fB\s-1CMS_NOATTR\s0\fR is set then no signedAttributes -will be used. If \fB\s-1CMS_NOSMIMECAP\s0\fR is set then just the SMIMECapabilities are -omitted. -.PP -If present the SMIMECapabilities attribute indicates support for the following -algorithms in preference order: 256 bit \s-1AES,\s0 Gost R3411\-94, Gost 28147\-89, 192 -bit \s-1AES, 128\s0 bit \s-1AES,\s0 triple \s-1DES, 128\s0 bit \s-1RC2, 64\s0 bit \s-1RC2, DES\s0 and 40 bit \s-1RC2.\s0 -If any of these algorithms is not available then it will not be included: -for example the \s-1GOST\s0 algorithms will not be included if the \s-1GOST ENGINE\s0 is -not loaded. -.PP -OpenSSL will by default identify signing certificates using issuer name -and serial number. If \fB\s-1CMS_USE_KEYID\s0\fR is set it will use the subject key -identifier value instead. An error occurs if the signing certificate does not -have a subject key identifier extension. -.PP -If the flags \fB\s-1CMS_STREAM\s0\fR is set then the returned \fBCMS_ContentInfo\fR -structure is just initialized ready to perform the signing operation. The -signing is however \fBnot\fR performed and the data to be signed is not read from -the \fBdata\fR parameter. Signing is deferred until after the data has been -written. In this way data can be signed in a single pass. -.PP -If the \fB\s-1CMS_PARTIAL\s0\fR flag is set a partial \fBCMS_ContentInfo\fR structure is -output to which additional signers and capabilities can be added before -finalization. -.PP -If the flag \fB\s-1CMS_STREAM\s0\fR is set the returned \fBCMS_ContentInfo\fR structure is -\&\fBnot\fR complete and outputting its contents via a function that does not -properly finalize the \fBCMS_ContentInfo\fR structure will give unpredictable -results. -.PP -Several functions including \fBSMIME_write_CMS()\fR, \fBi2d_CMS_bio_stream()\fR, -\&\fBPEM_write_bio_CMS_stream()\fR finalize the structure. Alternatively finalization -can be performed by obtaining the streaming \s-1ASN1\s0 \fB\s-1BIO\s0\fR directly using -\&\fBBIO_new_CMS()\fR. -.PP -If a signer is specified it will use the default digest for the signing -algorithm. This is \fB\s-1SHA256\s0\fR for both \s-1RSA\s0 and \s-1DSA\s0 keys. -.PP -If \fBsigncert\fR and \fBpkey\fR are \s-1NULL\s0 then a certificates only \s-1CMS\s0 structure is -output. -.PP -The function \fBCMS_sign()\fR is a basic \s-1CMS\s0 signing function whose output will be -suitable for many purposes. For finer control of the output format the -\&\fBcerts\fR, \fBsigncert\fR and \fBpkey\fR parameters can all be \fB\s-1NULL\s0\fR and the -\&\fB\s-1CMS_PARTIAL\s0\fR flag set. Then one or more signers can be added using the -function \fBCMS_add1_signer()\fR, non default digests can be used and custom -attributes added. \fBCMS_final()\fR must then be called to finalize the -structure if streaming is not enabled. -.SH "BUGS" -.IX Header "BUGS" -Some attributes such as counter signatures are not supported. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_sign_ex()\fR and \fBCMS_sign()\fR return either a valid CMS_ContentInfo -structure or \s-1NULL\s0 if an error occurred. The error can be obtained from -\&\fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\s-1CMS_STREAM\s0\fR flag is only supported for detached data in OpenSSL 0.9.8, -it is supported for embedded data in OpenSSL 1.0.0 and later. -.PP -The \fBCMS_sign_ex()\fR method was added in OpenSSL 3.0. -.PP -Since OpenSSL 3.2, \fBCMS_sign_ex()\fR and \fBCMS_sign()\fR ignore any duplicate -certificates in their \fIcerts\fR argument and no longer throw an error for them. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_sign_ex.3ossl b/openssl-install/share/man/man3/CMS_sign_ex.3ossl deleted file mode 120000 index 7cdbe190..00000000 --- a/openssl-install/share/man/man3/CMS_sign_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_sign_receipt.3ossl b/openssl-install/share/man/man3/CMS_sign_receipt.3ossl deleted file mode 100644 index d37cf7ce..00000000 --- a/openssl-install/share/man/man3/CMS_sign_receipt.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_SIGN_RECEIPT 3ossl" -.TH CMS_SIGN_RECEIPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_sign_receipt \- create a CMS signed receipt -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, X509 *signcert, -\& EVP_PKEY *pkey, STACK_OF(X509) *certs, -\& unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_sign_receipt()\fR creates and returns a \s-1CMS\s0 signed receipt structure. \fBsi\fR is -the \fBCMS_SignerInfo\fR structure containing the signed receipt request. -\&\fBsigncert\fR is the certificate to sign with, \fBpkey\fR is the corresponding -private key. \fBcerts\fR is an optional additional set of certificates to include -in the \s-1CMS\s0 structure (for example any intermediate CAs in the chain). -.PP -\&\fBflags\fR is an optional set of flags. -.SH "NOTES" -.IX Header "NOTES" -This functions behaves in a similar way to \fBCMS_sign()\fR except the flag values -\&\fB\s-1CMS_DETACHED\s0\fR, \fB\s-1CMS_BINARY\s0\fR, \fB\s-1CMS_NOATTR\s0\fR, \fB\s-1CMS_TEXT\s0\fR and \fB\s-1CMS_STREAM\s0\fR -are not supported since they do not make sense in the context of signed -receipts. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_sign_receipt()\fR returns either a valid CMS_ContentInfo structure or \s-1NULL\s0 if -an error occurred. The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBCMS_verify_receipt\fR\|(3), -\&\fBCMS_sign\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_signed_add1_attr.3ossl b/openssl-install/share/man/man3/CMS_signed_add1_attr.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_add1_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/CMS_signed_add1_attr_by_NID.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_add1_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_add1_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/CMS_signed_add1_attr_by_OBJ.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_add1_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_add1_attr_by_txt.3ossl b/openssl-install/share/man/man3/CMS_signed_add1_attr_by_txt.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_add1_attr_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_delete_attr.3ossl b/openssl-install/share/man/man3/CMS_signed_delete_attr.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_delete_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_get0_data_by_OBJ.3ossl b/openssl-install/share/man/man3/CMS_signed_get0_data_by_OBJ.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_get0_data_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_get_attr.3ossl b/openssl-install/share/man/man3/CMS_signed_get_attr.3ossl deleted file mode 100644 index 90626bb3..00000000 --- a/openssl-install/share/man/man3/CMS_signed_get_attr.3ossl +++ /dev/null @@ -1,338 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_SIGNED_GET_ATTR 3ossl" -.TH CMS_SIGNED_GET_ATTR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_signed_get_attr_count, -CMS_signed_get_attr_by_NID, CMS_signed_get_attr_by_OBJ, CMS_signed_get_attr, -CMS_signed_delete_attr, -CMS_signed_add1_attr, CMS_signed_add1_attr_by_OBJ, -CMS_signed_add1_attr_by_NID, CMS_signed_add1_attr_by_txt, -CMS_signed_get0_data_by_OBJ, -CMS_unsigned_get_attr_count, -CMS_unsigned_get_attr_by_NID, CMS_unsigned_get_attr_by_OBJ, -CMS_unsigned_get_attr, CMS_unsigned_delete_attr, -CMS_unsigned_add1_attr, CMS_unsigned_add1_attr_by_OBJ, -CMS_unsigned_add1_attr_by_NID, CMS_unsigned_add1_attr_by_txt, -CMS_unsigned_get0_data_by_OBJ -\&\- CMS signed and unsigned attribute functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_signed_get_attr_count(const CMS_SignerInfo *si); -\& int CMS_signed_get_attr_by_NID(const CMS_SignerInfo *si, int nid, -\& int lastpos); -\& int CMS_signed_get_attr_by_OBJ(const CMS_SignerInfo *si, const ASN1_OBJECT *obj, -\& int lastpos); -\& X509_ATTRIBUTE *CMS_signed_get_attr(const CMS_SignerInfo *si, int loc); -\& X509_ATTRIBUTE *CMS_signed_delete_attr(CMS_SignerInfo *si, int loc); -\& int CMS_signed_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr); -\& int CMS_signed_add1_attr_by_OBJ(CMS_SignerInfo *si, -\& const ASN1_OBJECT *obj, int type, -\& const void *bytes, int len); -\& int CMS_signed_add1_attr_by_NID(CMS_SignerInfo *si, -\& int nid, int type, -\& const void *bytes, int len); -\& int CMS_signed_add1_attr_by_txt(CMS_SignerInfo *si, -\& const char *attrname, int type, -\& const void *bytes, int len); -\& void *CMS_signed_get0_data_by_OBJ(const CMS_SignerInfo *si, -\& const ASN1_OBJECT *oid, -\& int lastpos, int type); -\& -\& int CMS_unsigned_get_attr_count(const CMS_SignerInfo *si); -\& int CMS_unsigned_get_attr_by_NID(const CMS_SignerInfo *si, int nid, -\& int lastpos); -\& int CMS_unsigned_get_attr_by_OBJ(const CMS_SignerInfo *si, -\& const ASN1_OBJECT *obj, int lastpos); -\& X509_ATTRIBUTE *CMS_unsigned_get_attr(const CMS_SignerInfo *si, int loc); -\& X509_ATTRIBUTE *CMS_unsigned_delete_attr(CMS_SignerInfo *si, int loc); -\& int CMS_unsigned_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr); -\& int CMS_unsigned_add1_attr_by_OBJ(CMS_SignerInfo *si, -\& const ASN1_OBJECT *obj, int type, -\& const void *bytes, int len); -\& int CMS_unsigned_add1_attr_by_NID(CMS_SignerInfo *si, -\& int nid, int type, -\& const void *bytes, int len); -\& int CMS_unsigned_add1_attr_by_txt(CMS_SignerInfo *si, -\& const char *attrname, int type, -\& const void *bytes, int len); -\& void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid, -\& int lastpos, int type); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -CMS_signerInfo contains separate attribute lists for signed and unsigned -attributes. Each \fBCMS_signed_XXX()\fR function is used for signed attributes, and -each \fBCMS_unsigned_XXX()\fR function is used for unsigned attributes. -Since the \fBCMS_unsigned_XXX()\fR functions work in the same way as the -\&\fBCMS_signed_XXX()\fR equivalents, only the \fBCMS_signed_XXX()\fR functions are -described below. -.PP -\&\fBCMS_signed_get_attr_by_OBJ()\fR finds the location of the first matching object -\&\fIobj\fR in the SignerInfo's \fIsi\fR signed attribute list. The search starts at the -position after \fIlastpos\fR. If the returned value is positive then it can be used -on the next call to \fBCMS_signed_get_attr_by_OBJ()\fR as the value of \fIlastpos\fR in -order to iterate through the remaining attributes. \fIlastpos\fR can be set to any -negative value on the first call, in order to start searching from the start of -the signed attribute list. -.PP -\&\fBCMS_signed_get_attr_by_NID()\fR is similar to \fBCMS_signed_get_attr_by_OBJ()\fR except -that it passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBCMS_signed_get_attr()\fR returns the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in the -\&\fIsi\fR signed attribute list. \fIloc\fR should be in the range from 0 to -\&\fBCMS_signed_get_attr_count()\fR \- 1. -.PP -\&\fBCMS_signed_delete_attr()\fR removes the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in -the \fIsi\fR signed attribute list. An error occurs if the \fIsi\fR attribute list -is \s-1NULL.\s0 -.PP -\&\fBCMS_signed_add1_attr()\fR pushes a copy of the passed in \fBX509_ATTRIBUTE\fR object -to the \fIsi\fR signed attribute list. A new signed attribute list is created if -required. An error occurs if \fIattr\fR is \s-1NULL.\s0 -.PP -\&\fBCMS_signed_add1_attr_by_OBJ()\fR creates a new signed \fBX509_ATTRIBUTE\fR using -\&\fBX509_ATTRIBUTE_set1_object()\fR and \fBX509_ATTRIBUTE_set1_data()\fR to assign a new -\&\fIobj\fR with type \fItype\fR and data \fIbytes\fR of length \fIlen\fR and then pushes it -to the \fIkey\fR object's attribute list. -.PP -\&\fBCMS_signed_add1_attr_by_NID()\fR is similar to \fBCMS_signed_add1_attr_by_OBJ()\fR except -that it passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBCMS_signed_add1_attr_by_txt()\fR is similar to \fBCMS_signed_add1_attr_by_OBJ()\fR -except that it passes a name \fIattrname\fR associated with the object. -See for a list of SN_* names. -.PP -\&\fBCMS_signed_get0_data_by_OBJ()\fR finds the first attribute in a \fIsi\fR signed -attributes list that matches the \fIobj\fR starting at index \fIlastpos\fR -and returns the data retrieved from the found attributes first \fB\s-1ASN1_TYPE\s0\fR -object. An error will occur if the attribute type \fItype\fR does not match the -type of the \fB\s-1ASN1_TYPE\s0\fR object \s-1OR\s0 if \fItype\fR is either \fBV_ASN1_BOOLEAN\fR or -\&\fBV_ASN1_NULL\fR \s-1OR\s0 the attribute is not found. -If \fIlastpos\fR is less than \-1 then an error will occur if there are multiple -objects in the signed attribute list that match \fIobj\fR. -If \fIlastpos\fR is less than \-2 then an error will occur if there is more than -one \fB\s-1ASN1_TYPE\s0\fR object in the found signed attribute. -.PP -Refer to \fBX509_ATTRIBUTE\fR\|(3) for information related to attributes. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBCMS_unsigned_XXX()\fR functions return values are similar to those of the -equivalent \fBCMS_signed_XXX()\fR functions. -.PP -\&\fBCMS_signed_get_attr_count()\fR returns the number of signed attributes in the -SignerInfo \fIsi\fR, or \-1 if the signed attribute list is \s-1NULL.\s0 -.PP -\&\fBCMS_signed_get_attr_by_OBJ()\fR returns \-1 if either the signed attribute list of -\&\fIsi\fR is empty \s-1OR\s0 if \fIobj\fR is not found, otherwise it returns the location of -the \fIobj\fR in the SignerInfo's \fIsi\fR signed attribute list. -.PP -\&\fBCMS_signed_get_attr_by_NID()\fR is similar to \fBCMS_signed_get_attr_by_OBJ()\fR except -that it returns \-2 if the \fInid\fR is not known by OpenSSL. -.PP -\&\fBCMS_signed_get_attr()\fR returns either a signed \fBX509_ATTRIBUTE\fR or \s-1NULL\s0 on error. -.PP -\&\fBCMS_signed_delete_attr()\fR returns either the removed signed \fBX509_ATTRIBUTE\fR or -\&\s-1NULL\s0 if there is a error. -.PP -\&\fBCMS_signed_add1_attr()\fR, \fBCMS_signed_add1_attr_by_OBJ()\fR, -\&\fBCMS_signed_add1_attr_by_NID()\fR, \fBCMS_signed_add1_attr_by_txt()\fR, -return 1 on success or 0 on error. -.PP -\&\fBCMS_signed_get0_data_by_OBJ()\fR returns the data retrieved from the found -signed attributes first \fB\s-1ASN1_TYPE\s0\fR object, or \s-1NULL\s0 if an error occurs. -.SH "NOTES" -.IX Header "NOTES" -Some attributes are added automatically during the signing process. -.PP -Calling \fBCMS_SignerInfo_sign()\fR adds the NID_pkcs9_signingTime signed -attribute. -.PP -Calling \fBCMS_final()\fR, \fBCMS_final_digest()\fR or \fBCMS_dataFinal()\fR adds the -NID_pkcs9_messageDigest signed attribute. -.PP -The NID_pkcs9_contentType signed attribute is always added if the -NID_pkcs9_signingTime attribute is added. -.PP -Calling \fBCMS_sign_ex()\fR, \fBCMS_sign_receipt()\fR or \fBCMS_add1_signer()\fR may add -attributes depending on the flags parameter. See \fBCMS_add1_signer\fR\|(3) for -more information. -.PP -OpenSSL applies special rules for the following attribute NIDs: -.IP "\s-1CMS\s0 Signed Attributes" 4 -.IX Item "CMS Signed Attributes" -NID_pkcs9_contentType -NID_pkcs9_messageDigest -NID_pkcs9_signingTime -.IP "\s-1ESS\s0 Signed Attributes" 4 -.IX Item "ESS Signed Attributes" -NID_id_smime_aa_signingCertificate -NID_id_smime_aa_signingCertificateV2 -NID_id_smime_aa_receiptRequest -.IP "\s-1CMS\s0 Unsigned Attributes" 4 -.IX Item "CMS Unsigned Attributes" -NID_pkcs9_countersignature -.PP -\&\fBCMS_signed_add1_attr()\fR, \fBCMS_signed_add1_attr_by_OBJ()\fR, -\&\fBCMS_signed_add1_attr_by_NID()\fR, \fBCMS_signed_add1_attr_by_txt()\fR -and the equivalent \fBCMS_unsigned_add1_attrXXX()\fR functions allow -duplicate attributes to be added. The attribute rules are not checked -during these function calls, and are deferred until the sign or verify process -(i.e. during calls to any of \fBCMS_sign_ex()\fR, \fBCMS_sign()\fR, \fBCMS_sign_receipt()\fR, -\&\fBCMS_add1_signer()\fR, \fBCMS_Final()\fR, \fBCMS_dataFinal()\fR, \fBCMS_final_digest()\fR, -\&\fBCMS_verify()\fR, \fBCMS_verify_receipt()\fR or \fBCMS_SignedData_verify()\fR). -.PP -For \s-1CMS\s0 attribute rules see \s-1RFC 5652\s0 Section 11. -For \s-1ESS\s0 attribute rules see \s-1RFC 2634\s0 Section 1.3.4 and \s-1RFC 5035\s0 Section 5.4. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_ATTRIBUTE\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_signed_get_attr_by_NID.3ossl b/openssl-install/share/man/man3/CMS_signed_get_attr_by_NID.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_get_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_get_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/CMS_signed_get_attr_by_OBJ.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_get_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_signed_get_attr_count.3ossl b/openssl-install/share/man/man3/CMS_signed_get_attr_count.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_signed_get_attr_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_uncompress.3ossl b/openssl-install/share/man/man3/CMS_uncompress.3ossl deleted file mode 100644 index f624f552..00000000 --- a/openssl-install/share/man/man3/CMS_uncompress.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_UNCOMPRESS 3ossl" -.TH CMS_UNCOMPRESS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_uncompress \- uncompress a CMS CompressedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_uncompress(CMS_ContentInfo *cms, BIO *dcont, BIO *out, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_uncompress()\fR extracts and uncompresses the content from a \s-1CMS\s0 -CompressedData structure \fBcms\fR. \fBdata\fR is a \s-1BIO\s0 to write the content to and -\&\fBflags\fR is an optional set of flags. -.PP -The \fBdcont\fR parameter is used in the rare case where the compressed content -is detached. It will normally be set to \s-1NULL.\s0 -.SH "NOTES" -.IX Header "NOTES" -The only currently supported compression algorithm is zlib: if the structure -indicates the use of any other algorithm an error is returned. -.PP -If zlib support is not compiled into OpenSSL then \fBCMS_uncompress()\fR will always -return an error. -.PP -The following flags can be passed in the \fBflags\fR parameter. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are deleted -from the content. If the content is not of type \fBtext/plain\fR then an error is -returned. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_uncompress()\fR returns either 1 for success or 0 for failure. The error can -be obtained from \fBERR_get_error\fR\|(3) -.SH "BUGS" -.IX Header "BUGS" -The lack of single pass processing and the need to hold all data in memory as -mentioned in \fBCMS_verify()\fR also applies to \fBCMS_decompress()\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_compress\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_unsigned_add1_attr.3ossl b/openssl-install/share/man/man3/CMS_unsigned_add1_attr.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_add1_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_NID.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_OBJ.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_txt.3ossl b/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_txt.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_add1_attr_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_delete_attr.3ossl b/openssl-install/share/man/man3/CMS_unsigned_delete_attr.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_delete_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_get0_data_by_OBJ.3ossl b/openssl-install/share/man/man3/CMS_unsigned_get0_data_by_OBJ.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_get0_data_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_get_attr.3ossl b/openssl-install/share/man/man3/CMS_unsigned_get_attr.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_get_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_get_attr_by_NID.3ossl b/openssl-install/share/man/man3/CMS_unsigned_get_attr_by_NID.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_get_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_get_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/CMS_unsigned_get_attr_by_OBJ.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_get_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_unsigned_get_attr_count.3ossl b/openssl-install/share/man/man3/CMS_unsigned_get_attr_count.3ossl deleted file mode 120000 index 9b1498ee..00000000 --- a/openssl-install/share/man/man3/CMS_unsigned_get_attr_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -CMS_signed_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CMS_verify.3ossl b/openssl-install/share/man/man3/CMS_verify.3ossl deleted file mode 100644 index 6247fe1b..00000000 --- a/openssl-install/share/man/man3/CMS_verify.3ossl +++ /dev/null @@ -1,300 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_VERIFY 3ossl" -.TH CMS_VERIFY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_verify, CMS_SignedData_verify, -CMS_get0_signers \- verify a CMS SignedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, X509_STORE *store, -\& BIO *detached_data, BIO *out, unsigned int flags); -\& BIO *CMS_SignedData_verify(CMS_SignedData *sd, BIO *detached_data, -\& STACK_OF(X509) *scerts, X509_STORE *store, -\& STACK_OF(X509) *extra, STACK_OF(X509_CRL) *crls, -\& unsigned int flags, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& -\& STACK_OF(X509) *CMS_get0_signers(CMS_ContentInfo *cms); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_verify()\fR is very similar to \fBPKCS7_verify\fR\|(3). It verifies a -\&\fB\s-1CMS\s0 SignedData\fR structure contained in a structure of type \fBCMS_ContentInfo\fR. -\&\fIcms\fR points to the \fBCMS_ContentInfo\fR structure to verify. -The optional \fIcerts\fR parameter refers to a set of certificates -in which to search for signing certificates. -It is also used -as a source of untrusted intermediate \s-1CA\s0 certificates for chain building. -\&\fIcms\fR may contain extra untrusted \s-1CA\s0 certificates that may be used for -chain building as well as CRLs that may be used for certificate validation. -\&\fIstore\fR may be \s-1NULL\s0 or point to -the trusted certificate store to use for chain verification. -\&\fIdetached_data\fR refers to the signed data if the content is detached from \fIcms\fR. -Otherwise \fIdetached_data\fR should be \s-1NULL\s0 and the signed data must be in \fIcms\fR. -The content is written to the \s-1BIO\s0 \fIout\fR unless it is \s-1NULL.\s0 -\&\fIflags\fR is an optional set of flags, which can be used to modify the operation. -.PP -\&\fBCMS_SignedData_verify()\fR is like \fBCMS_verify()\fR except that -it operates on \fB\s-1CMS\s0 SignedData\fR input in the \fIsd\fR argument, -it has some additional parameters described next, -and on success it returns the verified content as a memory \s-1BIO.\s0 -The optional \fIextra\fR parameter may be used to provide untrusted \s-1CA\s0 -certificates that may be helpful for chain building in certificate validation. -This list of certificates must not contain duplicates. -The optional \fIcrls\fR parameter may be used to provide extra CRLs. -Also the list of CRLs must not contain duplicates. -The optional parameters library context \fIlibctx\fR and property query \fIpropq\fR -are used when retrieving algorithms from providers. -.PP -\&\fBCMS_get0_signers()\fR retrieves the signing certificate(s) from \fIcms\fR; it may only -be called after a successful \fBCMS_verify()\fR or \fBCMS_SignedData_verify()\fR operation. -.SH "VERIFY PROCESS" -.IX Header "VERIFY PROCESS" -Normally the verify process proceeds as follows. -.PP -Initially some sanity checks are performed on \fIcms\fR. The type of \fIcms\fR must -be SignedData. There must be at least one signature on the data and if -the content is detached \fIdetached_data\fR cannot be \s-1NULL.\s0 -.PP -An attempt is made to locate all the signing certificate(s), first looking in -the \fIcerts\fR parameter (if it is not \s-1NULL\s0) and then looking in any -certificates contained in the \fIcms\fR structure unless \fB\s-1CMS_NOINTERN\s0\fR is set. -If any signing certificate cannot be located the operation fails. -.PP -Each signing certificate is chain verified using the \fIsmimesign\fR purpose and -using the trusted certificate store \fIstore\fR if supplied. -Any internal certificates in the message, which may have been added using -\&\fBCMS_add1_cert\fR\|(3), are used as untrusted CAs. -If \s-1CRL\s0 checking is enabled in \fIstore\fR and \fB\s-1CMS_NOCRL\s0\fR is not set, -any internal CRLs, which may have been added using \fBCMS_add1_crl\fR\|(3), -are used in addition to attempting to look them up in \fIstore\fR. -If \fIstore\fR is not \s-1NULL\s0 and any chain verify fails an error code is returned. -.PP -Finally the signed content is read (and written to \fIout\fR unless it is \s-1NULL\s0) -and the signature is checked. -.PP -If all signatures verify correctly then the function is successful. -.PP -Any of the following flags (ored together) can be passed in the \fIflags\fR -parameter to change the default verify behaviour. -.PP -If \fB\s-1CMS_NOINTERN\s0\fR is set the certificates in the message itself are not -searched when locating the signing certificate(s). -This means that all the signing certificates must be in the \fIcerts\fR parameter. -.PP -If \fB\s-1CMS_NOCRL\s0\fR is set and \s-1CRL\s0 checking is enabled in \fIstore\fR then any -CRLs in the message itself and provided via the \fIcrls\fR parameter are ignored. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \f(CW\*(C`text/plain\*(C'\fR are deleted -from the content. If the content is not of type \f(CW\*(C`text/plain\*(C'\fR then an error is -returned. -.PP -If \fB\s-1CMS_NO_SIGNER_CERT_VERIFY\s0\fR is set the signing certificates are not -chain verified, unless \fB\s-1CMS_CADES\s0\fR flag is also set. -.PP -If \fB\s-1CMS_NO_ATTR_VERIFY\s0\fR is set the signed attributes signature is not -verified, unless \s-1CMS_CADES\s0 flag is also set. -.PP -If \fB\s-1CMS_CADES\s0\fR is set, each signer certificate is checked against the -\&\s-1ESS\s0 signingCertificate or \s-1ESS\s0 signingCertificateV2 extension -that is required in the signed attributes of the signature. -.PP -If \fB\s-1CMS_NO_CONTENT_VERIFY\s0\fR is set then the content digest is not checked. -.SH "NOTES" -.IX Header "NOTES" -One application of \fB\s-1CMS_NOINTERN\s0\fR is to only accept messages signed by -a small number of certificates. The acceptable certificates would be passed -in the \fIcerts\fR parameter. In this case if the signer certificate is not one -of the certificates supplied in \fIcerts\fR then the verify will fail because the -signer cannot be found. -.PP -In some cases the standard techniques for looking up and validating -certificates are not appropriate: for example an application may wish to -lookup certificates in a database or perform customised verification. This -can be achieved by setting and verifying the signer certificates manually -using the signed data utility functions. -.PP -Care should be taken when modifying the default verify behaviour, for example -setting \fB\s-1CMS_NO_CONTENT_VERIFY\s0\fR will totally disable all content verification -and any modified content will be considered valid. This combination is however -useful if one merely wishes to write the content to \fIout\fR and its validity -is not considered important. -.PP -Chain verification should arguably be performed using the signing time rather -than the current time. However, since the signing time is supplied by the -signer it cannot be trusted without additional evidence (such as a trusted -timestamp). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_verify()\fR returns 1 for a successful verification and 0 if an error occurred. -.PP -\&\fBCMS_SignedData_verify()\fR returns a memory \s-1BIO\s0 containing the verified content, -or \s-1NULL\s0 on error. -.PP -\&\fBCMS_get0_signers()\fR returns all signers or \s-1NULL\s0 if an error occurred. -.PP -The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "BUGS" -.IX Header "BUGS" -The trusted certificate store is not searched for the signing certificate. -This is primarily due to the inadequacies of the current \fBX509_STORE\fR -functionality. -.PP -The lack of single pass processing means that the signed content must all -be held in memory if it is not detached. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS7_verify\fR\|(3), \fBCMS_add1_cert\fR\|(3), \fBCMS_add1_crl\fR\|(3), -\&\fBOSSL_ESS_check_signing_certs\fR\|(3), -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCMS_SignedData_verify()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CMS_verify_receipt.3ossl b/openssl-install/share/man/man3/CMS_verify_receipt.3ossl deleted file mode 100644 index 24ee270b..00000000 --- a/openssl-install/share/man/man3/CMS_verify_receipt.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CMS_VERIFY_RECEIPT 3ossl" -.TH CMS_VERIFY_RECEIPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CMS_verify_receipt \- verify a CMS signed receipt -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms, -\& STACK_OF(X509) *certs, X509_STORE *store, -\& unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCMS_verify_receipt()\fR verifies a \s-1CMS\s0 signed receipt. \fBrcms\fR is the signed -receipt to verify. \fBocms\fR is the original SignedData structure containing the -receipt request. \fBcerts\fR is a set of certificates in which to search for the -signing certificate. \fBstore\fR is a trusted certificate store (used for chain -verification). -.PP -\&\fBflags\fR is an optional set of flags, which can be used to modify the verify -operation. -.SH "NOTES" -.IX Header "NOTES" -This functions behaves in a similar way to \fBCMS_verify()\fR except the flag values -\&\fB\s-1CMS_DETACHED\s0\fR, \fB\s-1CMS_BINARY\s0\fR, \fB\s-1CMS_TEXT\s0\fR and \fB\s-1CMS_STREAM\s0\fR are not -supported since they do not make sense in the context of signed receipts. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCMS_verify_receipt()\fR returns 1 for a successful verification and zero if an -error occurred. -.PP -The error can be obtained from \fBERR_get_error\fR\|(3) -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBCMS_sign_receipt\fR\|(3), -\&\fBCMS_verify\fR\|(3), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/COMP_CTX_free.3ossl b/openssl-install/share/man/man3/COMP_CTX_free.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_CTX_get_method.3ossl b/openssl-install/share/man/man3/COMP_CTX_get_method.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_CTX_get_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_CTX_get_type.3ossl b/openssl-install/share/man/man3/COMP_CTX_get_type.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_CTX_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_CTX_new.3ossl b/openssl-install/share/man/man3/COMP_CTX_new.3ossl deleted file mode 100644 index 1f4b64f9..00000000 --- a/openssl-install/share/man/man3/COMP_CTX_new.3ossl +++ /dev/null @@ -1,298 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "COMP_CTX_NEW 3ossl" -.TH COMP_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -COMP_CTX_new, -COMP_CTX_get_method, -COMP_CTX_get_type, -COMP_get_type, -COMP_get_name, -COMP_CTX_free, -COMP_compress_block, -COMP_expand_block, -COMP_zlib, -COMP_zlib_oneshot, -COMP_brotli, -COMP_brotli_oneshot, -COMP_zstd, -COMP_zstd_oneshot, -BIO_f_zlib, -BIO_f_brotli, -BIO_f_zstd -\&\- Compression support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& COMP_CTX *COMP_CTX_new(COMP_METHOD *meth); -\& void COMP_CTX_free(COMP_CTX *ctx); -\& const COMP_METHOD *COMP_CTX_get_method(const COMP_CTX *ctx); -\& int COMP_CTX_get_type(const COMP_CTX* comp); -\& int COMP_get_type(const COMP_METHOD *meth); -\& const char *COMP_get_name(const COMP_METHOD *meth); -\& -\& int COMP_compress_block(COMP_CTX *ctx, unsigned char *out, int olen, -\& unsigned char *in, int ilen); -\& int COMP_expand_block(COMP_CTX *ctx, unsigned char *out, int olen, -\& unsigned char *in, int ilen); -\& -\& COMP_METHOD *COMP_zlib(void); -\& COMP_METHOD *COMP_zlib_oneshot(void); -\& COMP_METHOD *COMP_brotli(void); -\& COMP_METHOD *COMP_brotli_oneshot(void); -\& COMP_METHOD *COMP_zstd(void); -\& COMP_METHOD *COMP_zstd_oneshot(void); -\& -\& const BIO_METHOD *BIO_f_zlib(void); -\& const BIO_METHOD *BIO_f_brotli(void); -\& const BIO_METHOD *BIO_f_zstd(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions provide compression support for OpenSSL. Compression is used within -the OpenSSL library to support \s-1TLS\s0 record and certificate compression. -.PP -\&\fBCOMP_CTX_new()\fR is used to create a new \fB\s-1COMP_CTX\s0\fR structure used to compress data. -.PP -\&\fBCOMP_CTX_free()\fR is used to free the returned \fB\s-1COMP_CTX\s0\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBCOMP_CTX_get_method()\fR returns the \fB\s-1COMP_METHOD\s0\fR of the given \fIctx\fR. -.PP -\&\fBCOMP_CTX_get_type()\fR and \fBCOMP_get_type()\fR return the \s-1NID\s0 for the \fB\s-1COMP_CTX\s0\fR and -\&\fB\s-1COMP_METHOD\s0\fR, respectively. \fBCOMP_get_name()\fR returns the name of the algorithm -of the given \fB\s-1COMP_METHOD\s0\fR. -.PP -\&\fBCOMP_compress_block()\fR compresses b bytes from the buffer \fIin\fR into the -buffer b of size \fIolen\fR using the algorithm specified by \fIctx\fR. -.PP -\&\fBCOMP_expand_block()\fR expands \fIilen\fR bytes from the buffer \fIin\fR into the -buffer \fIout\fR of size \fIolen\fR using the algorithm specified by \fIctx\fR. -.PP -Methods (\fB\s-1COMP_METHOD\s0\fR) may be specified by one of these functions. These functions -will be available even if their corresponding compression algorithm is not configured -into the OpenSSL library. In such a case, \s-1NULL\s0 will be returned. -.IP "\(bu" 4 -\&\fBCOMP_zlib()\fR returns a \fB\s-1COMP_METHOD\s0\fR for stream-based \s-1ZLIB\s0 compression. -.IP "\(bu" 4 -\&\fBCOMP_zlib_oneshot()\fR returns a \fB\s-1COMP_METHOD\s0\fR for one-shot \s-1ZLIB\s0 compression. -.IP "\(bu" 4 -\&\fBCOMP_brotli()\fR returns a \fB\s-1COMP_METHOD\s0\fR for stream-based Brotli compression. -.IP "\(bu" 4 -\&\fBCOMP_brotli_oneshot()\fR returns a \fB\s-1COMP_METHOD\s0\fR for one-shot Brotli compression. -.IP "\(bu" 4 -\&\fBCOMP_zstd()\fR returns a \fB\s-1COMP_METHOD\s0\fR for stream-based Zstandard compression. -.IP "\(bu" 4 -\&\fBCOMP_zstd_oneshot()\fR returns a \fB\s-1COMP_METHOD\s0\fR for one-shot Zstandard compression. -.PP -\&\fBBIO_f_zlib()\fR, \fBBIO_f_brotli()\fR \fBBIO_f_zstd()\fR each return a \fB\s-1BIO_METHOD\s0\fR that may be used to -create a \fB\s-1BIO\s0\fR via \fB\fBBIO_new\fB\|(3)\fR to read and write compressed files or streams. -The functions are only available if the corresponding algorithm is compiled into -the OpenSSL library. \s-1NULL\s0 may be returned if the algorithm fails to load dynamically. -.SH "NOTES" -.IX Header "NOTES" -While compressing non-compressible data, the output may be larger than the -input. Care should be taken to size output buffers appropriate for both -compression and expansion. -.PP -Compression support and compression algorithms must be enabled and built into -the library before use. Refer to the \s-1INSTALL\s0.md file when configuring OpenSSL. -.PP -\&\s-1ZLIB\s0 may be found at -.PP -Brotli may be found at . -.PP -Zstandard may be found at . -.PP -Compression of \s-1SSL/TLS\s0 records is not recommended, as it has been -shown to lead to the \s-1CRIME\s0 attack . -It is disabled by default, and may be enabled by clearing the -\&\s-1SSL_OP_NO_COMPRESSION\s0 option and setting the security level as appropriate. -See the documentation for the \fBSSL_CTX_set_options\fR\|(3) and -\&\fBSSL_set_options\fR\|(3) functions. -.PP -Compression is also used to support certificate compression as described -in \s-1RFC8879\s0 . -It may be disabled via the \s-1SSL_OP_NO_TX_CERTIFICATE_COMPRESSION\s0 and -\&\s-1SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\s0 options of the -\&\fBSSL_CTX_set_options\fR\|(3) or \fBSSL_set_options\fR\|(3) functions. -.PP -\&\fBCOMP_zlib()\fR, \fBCOMP_brotli()\fR and \fBCOMP_zstd()\fR are stream-based compression methods. -Internal state (including compression dictionary) is maintained between calls. -If an error is returned, the stream is corrupted, and should be closed. -.PP -\&\fBCOMP_zlib_oneshot()\fR, \fBCOMP_brotli_oneshot()\fR and \fBCOMP_zstd_oneshot()\fR are not stream-based. These -methods do not maintain state between calls. An error in one call does not affect -future calls. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCOMP_CTX_new()\fR returns a \fB\s-1COMP_CTX\s0\fR on success, or \s-1NULL\s0 on failure. -.PP -\&\fBCOMP_CTX_get_method()\fR, \fBCOMP_zlib()\fR, \fBCOMP_zlib_oneshot()\fR, \fBCOMP_brotli()\fR, \fBCOMP_brotli_oneshot()\fR, -\&\fBCOMP_zstd()\fR, and \fBCOMP_zstd_oneshot()\fR return a \fB\s-1COMP_METHOD\s0\fR on success, -or \s-1NULL\s0 on failure. -.PP -\&\fBCOMP_CTX_get_type()\fR and \fBCOMP_get_type()\fR return a \s-1NID\s0 value. On failure, -NID_undef is returned. -.PP -\&\fBCOMP_compress_block()\fR and \fBCOMP_expand_block()\fR return the number of -bytes stored in the output buffer \fIout\fR. This may be 0. On failure, -\&\-1 is returned. -.PP -\&\fBCOMP_get_name()\fR returns a \fBconst char *\fR that must not be freed -on success, or \s-1NULL\s0 on failure. -.PP -\&\fBBIO_f_zlib()\fR, \fBBIO_f_brotli()\fR and \fBBIO_f_zstd()\fR return \s-1NULL\s0 on error, and -a \fB\s-1BIO_METHOD\s0\fR on success. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_new\fR\|(3), \fBSSL_CTX_set_options\fR\|(3), \fBSSL_set_options\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -Brotli and Zstandard functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/COMP_brotli.3ossl b/openssl-install/share/man/man3/COMP_brotli.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_brotli.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_brotli_oneshot.3ossl b/openssl-install/share/man/man3/COMP_brotli_oneshot.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_brotli_oneshot.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_compress_block.3ossl b/openssl-install/share/man/man3/COMP_compress_block.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_compress_block.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_expand_block.3ossl b/openssl-install/share/man/man3/COMP_expand_block.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_expand_block.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_get_name.3ossl b/openssl-install/share/man/man3/COMP_get_name.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_get_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_get_type.3ossl b/openssl-install/share/man/man3/COMP_get_type.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_zlib.3ossl b/openssl-install/share/man/man3/COMP_zlib.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_zlib.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_zlib_oneshot.3ossl b/openssl-install/share/man/man3/COMP_zlib_oneshot.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_zlib_oneshot.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_zstd.3ossl b/openssl-install/share/man/man3/COMP_zstd.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_zstd.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/COMP_zstd_oneshot.3ossl b/openssl-install/share/man/man3/COMP_zstd_oneshot.3ossl deleted file mode 120000 index f0e4fbfc..00000000 --- a/openssl-install/share/man/man3/COMP_zstd_oneshot.3ossl +++ /dev/null @@ -1 +0,0 @@ -COMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CONF_get1_default_config_file.3ossl b/openssl-install/share/man/man3/CONF_get1_default_config_file.3ossl deleted file mode 120000 index 24e577eb..00000000 --- a/openssl-install/share/man/man3/CONF_get1_default_config_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -CONF_modules_load_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CONF_modules_finish.3ossl b/openssl-install/share/man/man3/CONF_modules_finish.3ossl deleted file mode 120000 index c3bc6c50..00000000 --- a/openssl-install/share/man/man3/CONF_modules_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -CONF_modules_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CONF_modules_free.3ossl b/openssl-install/share/man/man3/CONF_modules_free.3ossl deleted file mode 100644 index 1729ca85..00000000 --- a/openssl-install/share/man/man3/CONF_modules_free.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CONF_MODULES_FREE 3ossl" -.TH CONF_MODULES_FREE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CONF_modules_free, CONF_modules_finish, CONF_modules_unload \- -OpenSSL configuration cleanup functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void CONF_modules_finish(void); -\& void CONF_modules_unload(int all); -.Ve -.PP -The following functions have been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void CONF_modules_free(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCONF_modules_free()\fR closes down and frees up all memory allocated by all -configuration modules. Normally, in versions of OpenSSL prior to 1.1.0, -applications called -\&\fBCONF_modules_free()\fR at exit to tidy up any configuration performed. -.PP -\&\fBCONF_modules_finish()\fR calls each configuration modules \fBfinish\fR handler -to free up any configuration that module may have performed. -.PP -\&\fBCONF_modules_unload()\fR finishes and unloads configuration modules. If -\&\fBall\fR is set to \fB0\fR only modules loaded from DSOs will be unloads. If -\&\fBall\fR is \fB1\fR all modules, including built-in modules will be unloaded. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -None of the functions return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBconfig\fR\|(5), \fBOPENSSL_config\fR\|(3), -\&\fBCONF_modules_load_file_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCONF_modules_free()\fR was deprecated in OpenSSL 1.1.0; do not use it. -For more information see \fBOPENSSL_init_crypto\fR\|(3). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CONF_modules_load.3ossl b/openssl-install/share/man/man3/CONF_modules_load.3ossl deleted file mode 120000 index 24e577eb..00000000 --- a/openssl-install/share/man/man3/CONF_modules_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -CONF_modules_load_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CONF_modules_load_file.3ossl b/openssl-install/share/man/man3/CONF_modules_load_file.3ossl deleted file mode 100644 index 54f71fc0..00000000 --- a/openssl-install/share/man/man3/CONF_modules_load_file.3ossl +++ /dev/null @@ -1,302 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CONF_MODULES_LOAD_FILE 3ossl" -.TH CONF_MODULES_LOAD_FILE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CONF_get1_default_config_file, -CONF_modules_load_file_ex, CONF_modules_load_file, CONF_modules_load -\&\- OpenSSL configuration functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& char *CONF_get1_default_config_file(void); -\& int CONF_modules_load_file_ex(OSSL_LIB_CTX *libctx, const char *filename, -\& const char *appname, unsigned long flags); -\& int CONF_modules_load_file(const char *filename, const char *appname, -\& unsigned long flags); -\& int CONF_modules_load(const CONF *cnf, const char *appname, -\& unsigned long flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBCONF_get1_default_config_file()\fR determines the default -configuration file pathname as follows. -If the \fB\s-1OPENSSL_CONF\s0\fR environment variable is set its value is returned. -Else the function returns the path obtained using -\&\fBX509_get_default_cert_area\fR\|(3) with the filename \f(CW"openssl.cnf"\fR appended. -The caller is responsible for freeing any string returned. -.PP -The function \fBCONF_modules_load_file_ex()\fR configures OpenSSL using -library context \fBlibctx\fR file \fBfilename\fR and application name \fBappname\fR. -If \fBfilename\fR is \s-1NULL\s0 the standard OpenSSL configuration file is used -as determined by calling \fBCONF_get1_default_config_file()\fR. -If \fBappname\fR is \s-1NULL\s0 the standard OpenSSL application name \fBopenssl_conf\fR is -used. -The behaviour can be customized using \fBflags\fR. Note that, the error suppressing -can be overridden by \fBconfig_diagnostics\fR as described in \fBconfig\fR\|(5). -.PP -\&\fBCONF_modules_load_file()\fR is the same as \fBCONF_modules_load_file_ex()\fR but -has a \s-1NULL\s0 library context. -.PP -\&\fBCONF_modules_load()\fR is identical to \fBCONF_modules_load_file()\fR except it -reads configuration information from \fBcnf\fR. -.SH "NOTES" -.IX Header "NOTES" -The following \fBflags\fR are currently recognized: -.PP -If \fB\s-1CONF_MFLAGS_IGNORE_ERRORS\s0\fR is set errors returned by individual -configuration modules are ignored. If not set the first module error is -considered fatal and no further modules are loaded. -.PP -Normally any modules errors will add error information to the error queue. If -\&\fB\s-1CONF_MFLAGS_SILENT\s0\fR is set no error information is added. -.PP -If \fB\s-1CONF_MFLAGS_IGNORE_RETURN_CODES\s0\fR is set the function unconditionally -returns success. -This is used by default in \fBOPENSSL_init_crypto\fR\|(3) to ignore any errors in -the default system-wide configuration file, as having all OpenSSL applications -fail to start when there are potentially minor issues in the file is too risky. -Applications calling \fBCONF_modules_load_file_ex\fR explicitly should not -generally set this flag. -.PP -If \fB\s-1CONF_MFLAGS_NO_DSO\s0\fR is set configuration module loading from DSOs is -disabled. -.PP -\&\fB\s-1CONF_MFLAGS_IGNORE_MISSING_FILE\s0\fR if set will make \fBCONF_load_modules_file()\fR -ignore missing configuration files. Normally a missing configuration file -return an error. -.PP -\&\fB\s-1CONF_MFLAGS_DEFAULT_SECTION\s0\fR if set and \fBappname\fR is not \s-1NULL\s0 will use the -default section pointed to by \fBopenssl_conf\fR if \fBappname\fR does not exist. -.PP -By using \fBCONF_modules_load_file_ex()\fR with appropriate flags an -application can customise application configuration to best suit its needs. -In some cases the use of a configuration file is optional and its absence is not -an error: in this case \fB\s-1CONF_MFLAGS_IGNORE_MISSING_FILE\s0\fR would be set. -.PP -Errors during configuration may also be handled differently by different -applications. For example in some cases an error may simply print out a warning -message and the application continue. In other cases an application might -consider a configuration file error as fatal and exit immediately. -.PP -Applications can use the \fBCONF_modules_load()\fR function if they wish to load a -configuration file themselves and have finer control over how errors are -treated. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return 1 for success and a zero or negative value for -failure. If module errors are not ignored the return code will reflect the -return value of the failing module (this will always be zero or negative). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Load a configuration file and print out any errors and exit (missing file -considered fatal): -.PP -.Vb 5 -\& if (CONF_modules_load_file_ex(libctx, NULL, NULL, 0) <= 0) { -\& fprintf(stderr, "FATAL: error loading configuration file\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -.Ve -.PP -Load default configuration file using the section indicated by \*(L"myapp\*(R", -tolerate missing files, but exit on other errors: -.PP -.Vb 6 -\& if (CONF_modules_load_file_ex(NULL, NULL, "myapp", -\& CONF_MFLAGS_IGNORE_MISSING_FILE) <= 0) { -\& fprintf(stderr, "FATAL: error loading configuration file\en"); -\& ERR_print_errors_fp(stderr); -\& exit(1); -\& } -.Ve -.PP -Load custom configuration file and section, only print warnings on error, -missing configuration file ignored: -.PP -.Vb 5 -\& if (CONF_modules_load_file_ex(NULL, "/something/app.cnf", "myapp", -\& CONF_MFLAGS_IGNORE_MISSING_FILE) <= 0) { -\& fprintf(stderr, "WARNING: error loading configuration file\en"); -\& ERR_print_errors_fp(stderr); -\& } -.Ve -.PP -Load and parse configuration file manually, custom error handling: -.PP -.Vb 3 -\& FILE *fp; -\& CONF *cnf = NULL; -\& long eline; -\& -\& fp = fopen("/somepath/app.cnf", "r"); -\& if (fp == NULL) { -\& fprintf(stderr, "Error opening configuration file\en"); -\& /* Other missing configuration file behaviour */ -\& } else { -\& cnf = NCONF_new_ex(libctx, NULL); -\& if (NCONF_load_fp(cnf, fp, &eline) == 0) { -\& fprintf(stderr, "Error on line %ld of configuration file\en", eline); -\& ERR_print_errors_fp(stderr); -\& /* Other malformed configuration file behaviour */ -\& } else if (CONF_modules_load(cnf, "appname", 0) <= 0) { -\& fprintf(stderr, "Error configuring application\en"); -\& ERR_print_errors_fp(stderr); -\& /* Other configuration error behaviour */ -\& } -\& fclose(fp); -\& NCONF_free(cnf); -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBconfig\fR\|(5), -\&\fBOPENSSL_config\fR\|(3), -\&\fBNCONF_new_ex\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CONF_modules_load_file_ex.3ossl b/openssl-install/share/man/man3/CONF_modules_load_file_ex.3ossl deleted file mode 120000 index 24e577eb..00000000 --- a/openssl-install/share/man/man3/CONF_modules_load_file_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CONF_modules_load_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CONF_modules_unload.3ossl b/openssl-install/share/man/man3/CONF_modules_unload.3ossl deleted file mode 120000 index c3bc6c50..00000000 --- a/openssl-install/share/man/man3/CONF_modules_unload.3ossl +++ /dev/null @@ -1 +0,0 @@ -CONF_modules_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRL_DIST_POINTS_free.3ossl b/openssl-install/share/man/man3/CRL_DIST_POINTS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CRL_DIST_POINTS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRL_DIST_POINTS_new.3ossl b/openssl-install/share/man/man3/CRL_DIST_POINTS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/CRL_DIST_POINTS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_EX_dup.3ossl b/openssl-install/share/man/man3/CRYPTO_EX_dup.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_EX_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_EX_free.3ossl b/openssl-install/share/man/man3/CRYPTO_EX_free.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_EX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_EX_new.3ossl b/openssl-install/share/man/man3/CRYPTO_EX_new.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_EX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_THREAD_lock_free.3ossl b/openssl-install/share/man/man3/CRYPTO_THREAD_lock_free.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_THREAD_lock_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_THREAD_lock_new.3ossl b/openssl-install/share/man/man3/CRYPTO_THREAD_lock_new.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_THREAD_lock_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_THREAD_read_lock.3ossl b/openssl-install/share/man/man3/CRYPTO_THREAD_read_lock.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_THREAD_read_lock.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_THREAD_run_once.3ossl b/openssl-install/share/man/man3/CRYPTO_THREAD_run_once.3ossl deleted file mode 100644 index 8cbcbeb5..00000000 --- a/openssl-install/share/man/man3/CRYPTO_THREAD_run_once.3ossl +++ /dev/null @@ -1,380 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CRYPTO_THREAD_RUN_ONCE 3ossl" -.TH CRYPTO_THREAD_RUN_ONCE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CRYPTO_THREAD_run_once, -CRYPTO_THREAD_lock_new, CRYPTO_THREAD_read_lock, CRYPTO_THREAD_write_lock, -CRYPTO_THREAD_unlock, CRYPTO_THREAD_lock_free, -CRYPTO_atomic_add, CRYPTO_atomic_add64, CRYPTO_atomic_and, CRYPTO_atomic_or, -CRYPTO_atomic_load, CRYPTO_atomic_store, CRYPTO_atomic_load_int, -OSSL_set_max_threads, OSSL_get_max_threads, -OSSL_get_thread_support_flags, OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL, -OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN \- OpenSSL thread support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CRYPTO_ONCE CRYPTO_ONCE_STATIC_INIT; -\& int CRYPTO_THREAD_run_once(CRYPTO_ONCE *once, void (*init)(void)); -\& -\& CRYPTO_RWLOCK *CRYPTO_THREAD_lock_new(void); -\& int CRYPTO_THREAD_read_lock(CRYPTO_RWLOCK *lock); -\& int CRYPTO_THREAD_write_lock(CRYPTO_RWLOCK *lock); -\& int CRYPTO_THREAD_unlock(CRYPTO_RWLOCK *lock); -\& void CRYPTO_THREAD_lock_free(CRYPTO_RWLOCK *lock); -\& -\& int CRYPTO_atomic_add(int *val, int amount, int *ret, CRYPTO_RWLOCK *lock); -\& int CRYPTO_atomic_add64(uint64_t *val, uint64_t op, uint64_t *ret, -\& CRYPTO_RWLOCK *lock); -\& int CRYPTO_atomic_and(uint64_t *val, uint64_t op, uint64_t *ret, -\& CRYPTO_RWLOCK *lock); -\& int CRYPTO_atomic_or(uint64_t *val, uint64_t op, uint64_t *ret, -\& CRYPTO_RWLOCK *lock); -\& int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock); -\& int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock); -\& int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock); -\& -\& int OSSL_set_max_threads(OSSL_LIB_CTX *ctx, uint64_t max_threads); -\& uint64_t OSSL_get_max_threads(OSSL_LIB_CTX *ctx); -\& uint32_t OSSL_get_thread_support_flags(void); -\& -\& #define OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL -\& #define OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL can be safely used in multi-threaded applications provided that -support for the underlying \s-1OS\s0 threading \s-1API\s0 is built-in. Currently, OpenSSL -supports the pthread and Windows APIs. OpenSSL can also be built without -any multi-threading support, for example on platforms that don't provide -any threading support or that provide a threading \s-1API\s0 that is not yet -supported by OpenSSL. -.PP -The following multi-threading function are provided: -.IP "\(bu" 2 -\&\fBCRYPTO_THREAD_run_once()\fR can be used to perform one-time initialization. -The \fIonce\fR argument must be a pointer to a static object of type -\&\fB\s-1CRYPTO_ONCE\s0\fR that was statically initialized to the value -\&\fB\s-1CRYPTO_ONCE_STATIC_INIT\s0\fR. -The \fIinit\fR argument is a pointer to a function that performs the desired -exactly once initialization. -In particular, this can be used to allocate locks in a thread-safe manner, -which can then be used with the locking functions below. -.IP "\(bu" 2 -\&\fBCRYPTO_THREAD_lock_new()\fR allocates, initializes and returns a new read/write -lock. -.IP "\(bu" 2 -\&\fBCRYPTO_THREAD_read_lock()\fR locks the provided \fIlock\fR for reading. -.IP "\(bu" 2 -\&\fBCRYPTO_THREAD_write_lock()\fR locks the provided \fIlock\fR for writing. -.IP "\(bu" 2 -\&\fBCRYPTO_THREAD_unlock()\fR unlocks the previously locked \fIlock\fR. -.IP "\(bu" 2 -\&\fBCRYPTO_THREAD_lock_free()\fR frees the provided \fIlock\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.IP "\(bu" 2 -\&\fBCRYPTO_atomic_add()\fR atomically adds \fIamount\fR to \fI*val\fR and returns the -result of the operation in \fI*ret\fR. \fIlock\fR will be locked, unless atomic -operations are supported on the specific platform. Because of this, if a -variable is modified by \fBCRYPTO_atomic_add()\fR then \fBCRYPTO_atomic_add()\fR must -be the only way that the variable is modified. If atomic operations are not -supported and \fIlock\fR is \s-1NULL,\s0 then the function will fail. -.IP "\(bu" 2 -\&\fBCRYPTO_atomic_add64()\fR atomically adds \fIop\fR to \fI*val\fR and returns the -result of the operation in \fI*ret\fR. \fIlock\fR will be locked, unless atomic -operations are supported on the specific platform. Because of this, if a -variable is modified by \fBCRYPTO_atomic_add64()\fR then \fBCRYPTO_atomic_add64()\fR must -be the only way that the variable is modified. If atomic operations are not -supported and \fIlock\fR is \s-1NULL,\s0 then the function will fail. -.IP "\(bu" 2 -\&\fBCRYPTO_atomic_and()\fR performs an atomic bitwise and of \fIop\fR and \fI*val\fR and stores -the result back in \fI*val\fR. It also returns the result of the operation in -\&\fI*ret\fR. \fIlock\fR will be locked, unless atomic operations are supported on the -specific platform. Because of this, if a variable is modified by -\&\fBCRYPTO_atomic_and()\fR or read by \fBCRYPTO_atomic_load()\fR then \fBCRYPTO_atomic_and()\fR must -be the only way that the variable is modified. If atomic operations are not -supported and \fIlock\fR is \s-1NULL,\s0 then the function will fail. -.IP "\(bu" 2 -\&\fBCRYPTO_atomic_or()\fR performs an atomic bitwise or of \fIop\fR and \fI*val\fR and stores -the result back in \fI*val\fR. It also returns the result of the operation in -\&\fI*ret\fR. \fIlock\fR will be locked, unless atomic operations are supported on the -specific platform. Because of this, if a variable is modified by -\&\fBCRYPTO_atomic_or()\fR or read by \fBCRYPTO_atomic_load()\fR then \fBCRYPTO_atomic_or()\fR must -be the only way that the variable is modified. If atomic operations are not -supported and \fIlock\fR is \s-1NULL,\s0 then the function will fail. -.IP "\(bu" 2 -\&\fBCRYPTO_atomic_load()\fR atomically loads the contents of \fI*val\fR into \fI*ret\fR. -\&\fIlock\fR will be locked, unless atomic operations are supported on the specific -platform. Because of this, if a variable is modified by \fBCRYPTO_atomic_or()\fR or -read by \fBCRYPTO_atomic_load()\fR then \fBCRYPTO_atomic_load()\fR must be the only way that -the variable is read. If atomic operations are not supported and \fIlock\fR is -\&\s-1NULL,\s0 then the function will fail. -.IP "\(bu" 2 -\&\fBCRYPTO_atomic_store()\fR atomically stores the contents of \fIval\fR into \fI*dst\fR. -\&\fIlock\fR will be locked, unless atomic operations are supported on the specific -platform. -.IP "\(bu" 2 -\&\fBCRYPTO_atomic_load_int()\fR works identically to \fBCRYPTO_atomic_load()\fR but operates -on an \fIint\fR value instead of a \fIuint64_t\fR value. -.IP "\(bu" 2 -\&\fBOSSL_set_max_threads()\fR sets the maximum number of threads to be used by the -thread pool. If the argument is 0, thread pooling is disabled. OpenSSL will -not create any threads and existing threads in the thread pool will be torn -down. The maximum thread count is a limit, not a target. Threads will not be -spawned unless (and until) there is demand. Thread polling is disabled by -default. To enable threading you must call \fBOSSL_set_max_threads()\fR explicitly. -Under no circumstances is this done for you. -.IP "\(bu" 2 -\&\fBOSSL_get_thread_support_flags()\fR determines what thread pool functionality -OpenSSL is compiled with and is able to support in the current run time -environment. \fB\s-1OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL\s0\fR indicates that the base -thread pool functionality is available, and -\&\fB\s-1OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN\s0\fR indicates that the default thread pool -model is available. The default thread pool model is currently the only model -available, therefore both of these flags must be set for thread pool -functionality to be used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCRYPTO_THREAD_run_once()\fR returns 1 on success, or 0 on error. -.PP -\&\fBCRYPTO_THREAD_lock_new()\fR returns the allocated lock, or \s-1NULL\s0 on error. -.PP -\&\fBCRYPTO_THREAD_lock_free()\fR returns no value. -.PP -\&\fBOSSL_set_max_threads()\fR returns 1 on success and 0 on failure. Returns failure -if OpenSSL-managed thread pooling is not supported (for example, if it is not -supported on the current platform, or because OpenSSL is not built with the -necessary support). -.PP -\&\fBOSSL_get_max_threads()\fR returns the maximum number of threads currently allowed -to be used by the thread pool. If thread pooling is disabled or not available, -returns 0. -.PP -\&\fBOSSL_get_thread_support_flags()\fR returns zero or more \fB\s-1OSSL_THREAD_SUPPORT_FLAG\s0\fR -values. -.PP -The other functions return 1 on success, or 0 on error. -.SH "NOTES" -.IX Header "NOTES" -On Windows platforms the CRYPTO_THREAD_* types and functions in the -\&\fI\fR header are dependent on some of the types -customarily made available by including \fI\fR. The application -developer is likely to require control over when the latter is included, -commonly as one of the first included headers. Therefore, it is defined as an -application developer's responsibility to include \fI\fR prior to -\&\fI\fR where use of CRYPTO_THREAD_* types and functions is -required. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -You can find out if OpenSSL was configured with thread support: -.PP -.Vb 6 -\& #include -\& #if defined(OPENSSL_THREADS) -\& /* thread support enabled */ -\& #else -\& /* no thread support */ -\& #endif -.Ve -.PP -This example safely initializes and uses a lock. -.PP -.Vb 4 -\& #ifdef _WIN32 -\& # include -\& #endif -\& #include -\& -\& static CRYPTO_ONCE once = CRYPTO_ONCE_STATIC_INIT; -\& static CRYPTO_RWLOCK *lock; -\& -\& static void myinit(void) -\& { -\& lock = CRYPTO_THREAD_lock_new(); -\& } -\& -\& static int mylock(void) -\& { -\& if (!CRYPTO_THREAD_run_once(&once, void init) || lock == NULL) -\& return 0; -\& return CRYPTO_THREAD_write_lock(lock); -\& } -\& -\& static int myunlock(void) -\& { -\& return CRYPTO_THREAD_unlock(lock); -\& } -\& -\& int serialized(void) -\& { -\& int ret = 0; -\& -\& if (!mylock()) { -\& /* Do not unlock unless the lock was successfully acquired. */ -\& return 0; -\& } -\& -\& /* Your code here, do not return without releasing the lock! */ -\& ret = ... ; -\& myunlock(); -\& return ret; -\& } -.Ve -.PP -Finalization of locks is an advanced topic, not covered in this example. -This can only be done at process exit or when a dynamically loaded library is -no longer in use and is unloaded. -The simplest solution is to just \*(L"leak\*(R" the lock in applications and not -repeatedly load/unload shared libraries that allocate locks. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBopenssl\-threads\fR\|(7). -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCRYPTO_atomic_store()\fR was added in OpenSSL 3.4.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CRYPTO_THREAD_unlock.3ossl b/openssl-install/share/man/man3/CRYPTO_THREAD_unlock.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_THREAD_unlock.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_THREAD_write_lock.3ossl b/openssl-install/share/man/man3/CRYPTO_THREAD_write_lock.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_THREAD_write_lock.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_aligned_alloc.3ossl b/openssl-install/share/man/man3/CRYPTO_aligned_alloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_aligned_alloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_alloc_ex_data.3ossl b/openssl-install/share/man/man3/CRYPTO_alloc_ex_data.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_alloc_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_atomic_add.3ossl b/openssl-install/share/man/man3/CRYPTO_atomic_add.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_atomic_add.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_atomic_add64.3ossl b/openssl-install/share/man/man3/CRYPTO_atomic_add64.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_atomic_add64.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_atomic_and.3ossl b/openssl-install/share/man/man3/CRYPTO_atomic_and.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_atomic_and.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_atomic_load.3ossl b/openssl-install/share/man/man3/CRYPTO_atomic_load.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_atomic_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_atomic_load_int.3ossl b/openssl-install/share/man/man3/CRYPTO_atomic_load_int.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_atomic_load_int.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_atomic_or.3ossl b/openssl-install/share/man/man3/CRYPTO_atomic_or.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_atomic_or.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_atomic_store.3ossl b/openssl-install/share/man/man3/CRYPTO_atomic_store.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/CRYPTO_atomic_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_clear_free.3ossl b/openssl-install/share/man/man3/CRYPTO_clear_free.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_clear_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_clear_realloc.3ossl b/openssl-install/share/man/man3/CRYPTO_clear_realloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_clear_realloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_free.3ossl b/openssl-install/share/man/man3/CRYPTO_free.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_free_ex_data.3ossl b/openssl-install/share/man/man3/CRYPTO_free_ex_data.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_free_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_free_ex_index.3ossl b/openssl-install/share/man/man3/CRYPTO_free_ex_index.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_free_ex_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_free_fn.3ossl b/openssl-install/share/man/man3/CRYPTO_free_fn.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_free_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_get_alloc_counts.3ossl b/openssl-install/share/man/man3/CRYPTO_get_alloc_counts.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_get_alloc_counts.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_get_ex_data.3ossl b/openssl-install/share/man/man3/CRYPTO_get_ex_data.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_get_ex_new_index.3ossl b/openssl-install/share/man/man3/CRYPTO_get_ex_new_index.3ossl deleted file mode 100644 index 270de475..00000000 --- a/openssl-install/share/man/man3/CRYPTO_get_ex_new_index.3ossl +++ /dev/null @@ -1,313 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CRYPTO_GET_EX_NEW_INDEX 3ossl" -.TH CRYPTO_GET_EX_NEW_INDEX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CRYPTO_EX_new, CRYPTO_EX_free, CRYPTO_EX_dup, -CRYPTO_free_ex_index, CRYPTO_get_ex_new_index, -CRYPTO_alloc_ex_data, CRYPTO_set_ex_data, CRYPTO_get_ex_data, -CRYPTO_free_ex_data, CRYPTO_new_ex_data -\&\- functions supporting application\-specific data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CRYPTO_get_ex_new_index(int class_index, -\& long argl, void *argp, -\& CRYPTO_EX_new *new_func, -\& CRYPTO_EX_dup *dup_func, -\& CRYPTO_EX_free *free_func); -\& -\& typedef void CRYPTO_EX_new(void *parent, void *ptr, CRYPTO_EX_DATA *ad, -\& int idx, long argl, void *argp); -\& typedef void CRYPTO_EX_free(void *parent, void *ptr, CRYPTO_EX_DATA *ad, -\& int idx, long argl, void *argp); -\& typedef int CRYPTO_EX_dup(CRYPTO_EX_DATA *to, const CRYPTO_EX_DATA *from, -\& void **from_d, int idx, long argl, void *argp); -\& -\& int CRYPTO_new_ex_data(int class_index, void *obj, CRYPTO_EX_DATA *ad); -\& -\& int CRYPTO_alloc_ex_data(int class_index, void *obj, CRYPTO_EX_DATA *ad, -\& int idx); -\& -\& int CRYPTO_set_ex_data(CRYPTO_EX_DATA *r, int idx, void *arg); -\& -\& void *CRYPTO_get_ex_data(const CRYPTO_EX_DATA *r, int idx); -\& -\& void CRYPTO_free_ex_data(int class_index, void *obj, CRYPTO_EX_DATA *r); -\& -\& int CRYPTO_free_ex_index(int class_index, int idx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Several OpenSSL structures can have application-specific data attached to them, -known as \*(L"exdata.\*(R" -The specific structures are: -.PP -.Vb 10 -\& BIO -\& DH -\& DSA -\& EC_KEY -\& ENGINE -\& EVP_PKEY -\& RSA -\& SSL -\& SSL_CTX -\& SSL_SESSION -\& UI -\& UI_METHOD -\& X509 -\& X509_STORE -\& X509_STORE_CTX -.Ve -.PP -In addition, the \fB\s-1APP\s0\fR name is reserved for use by application code. -.PP -Each is identified by an \fBCRYPTO_EX_INDEX_xxx\fR define in the header file -\&\fI\fR. In addition, \fB\s-1CRYPTO_EX_INDEX_APP\s0\fR is reserved for -applications to use this facility for their own structures. -.PP -The \s-1API\s0 described here is used by OpenSSL to manipulate exdata for specific -structures. Since the application data can be anything at all it is passed -and retrieved as a \fBvoid *\fR type. -.PP -The \fB\s-1CRYPTO_EX_DATA\s0\fR type is opaque. To initialize the exdata part of -a structure, call \fBCRYPTO_new_ex_data()\fR. This is only necessary for -\&\fB\s-1CRYPTO_EX_INDEX_APP\s0\fR objects. -.PP -Exdata types are identified by an \fBindex\fR, an integer guaranteed to be -unique within structures for the lifetime of the program. Applications -using exdata typically call \fBCRYPTO_get_ex_new_index\fR at startup, and -store the result in a global variable, or write a wrapper function to -provide lazy evaluation. The \fBclass_index\fR should be one of the -\&\fBCRYPTO_EX_INDEX_xxx\fR values. The \fBargl\fR and \fBargp\fR parameters are saved -to be passed to the callbacks but are otherwise not used. In order to -transparently manipulate exdata, three callbacks must be provided. The -semantics of those callbacks are described below. -.PP -When copying or releasing objects with exdata, the callback functions -are called in increasing order of their \fBindex\fR value. -.PP -If a dynamic library can be unloaded, it should call \fBCRYPTO_free_ex_index()\fR -when this is done. -This will replace the callbacks with no-ops -so that applications don't crash. Any existing exdata will be leaked. -.PP -To set or get the exdata on an object, the appropriate type-specific -routine must be used. This is because the containing structure is opaque -and the \fB\s-1CRYPTO_EX_DATA\s0\fR field is not accessible. In both \s-1API\s0's, the -\&\fBidx\fR parameter should be an already-created index value. -.PP -When setting exdata, the pointer specified with a particular index is saved, -and returned on a subsequent \*(L"get\*(R" call. If the application is going to -release the data, it must make sure to set a \fB\s-1NULL\s0\fR value at the index, -to avoid likely double-free crashes. -.PP -The function \fBCRYPTO_free_ex_data\fR is used to free all exdata attached -to a structure. The appropriate type-specific routine must be used. -The \fBclass_index\fR identifies the structure type, the \fBobj\fR is -a pointer to the actual structure, and \fBr\fR is a pointer to the -structure's exdata field. -.SS "Callback Functions" -.IX Subsection "Callback Functions" -This section describes how the callback functions are used. Applications -that are defining their own exdata using \fB\s-1CYPRTO_EX_INDEX_APP\s0\fR must -call them as described here. -.PP -When a structure is initially allocated (such as \fBRSA_new()\fR) then the -\&\fBnew_func()\fR is called for every defined index. There is no requirement -that the entire parent, or containing, structure has been set up. -The \fBnew_func()\fR is typically used only to allocate memory to store the -exdata, and perhaps an \*(L"initialized\*(R" flag within that memory. -The exdata value may be allocated later on with \fBCRYPTO_alloc_ex_data()\fR, -or may be set by calling \fBCRYPTO_set_ex_data()\fR. -.PP -When a structure is free'd (such as \fBSSL_CTX_free()\fR) then the -\&\fBfree_func()\fR is called for every defined index. Again, the state of the -parent structure is not guaranteed. The \fBfree_func()\fR may be called with a -\&\s-1NULL\s0 pointer. -.PP -Both \fBnew_func()\fR and \fBfree_func()\fR take the same parameters. -The \fBparent\fR is the pointer to the structure that contains the exdata. -The \fBptr\fR is the current exdata item; for \fBnew_func()\fR this will typically -be \s-1NULL.\s0 The \fBr\fR parameter is a pointer to the exdata field of the object. -The \fBidx\fR is the index and is the value returned when the callbacks were -initially registered via \fBCRYPTO_get_ex_new_index()\fR and can be used if -the same callback handles different types of exdata. -.PP -\&\fBdup_func()\fR is called when a structure is being copied. This is only done -for \fB\s-1SSL\s0\fR, \fB\s-1SSL_SESSION\s0\fR, \fB\s-1EC_KEY\s0\fR objects and \fB\s-1BIO\s0\fR chains via -\&\fBBIO_dup_chain()\fR. The \fBto\fR and \fBfrom\fR parameters -are pointers to the destination and source \fB\s-1CRYPTO_EX_DATA\s0\fR structures, -respectively. The \fB*from_d\fR parameter is a pointer to the source exdata. -When the \fBdup_func()\fR returns, the value in \fB*from_d\fR is copied to the -destination ex_data. If the pointer contained in \fB*pptr\fR is not modified -by the \fBdup_func()\fR, then both \fBto\fR and \fBfrom\fR will point to the same data. -The \fBidx\fR, \fBargl\fR and \fBargp\fR parameters are as described for the other -two callbacks. If the \fBdup_func()\fR returns \fB0\fR the whole \fBCRYPTO_dup_ex_data()\fR -will fail. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCRYPTO_get_ex_new_index()\fR returns a new index or \-1 on failure. -.PP -\&\fBCRYPTO_free_ex_index()\fR, \fBCRYPTO_alloc_ex_data()\fR and \fBCRYPTO_set_ex_data()\fR -return 1 on success or 0 on failure. -.PP -\&\fBCRYPTO_get_ex_data()\fR returns the application data or \s-1NULL\s0 on failure; -note that \s-1NULL\s0 may be a valid value. -.PP -\&\fBdup_func()\fR should return 0 for failure and 1 for success. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBCRYPTO_alloc_ex_data()\fR was added in OpenSSL 3.0. -.PP -The signature of the \fBdup_func()\fR callback was changed in OpenSSL 3.0 to use the -type \fBvoid **\fR for \fBfrom_d\fR. Previously this parameter was of type \fBvoid *\fR. -.PP -Support for \s-1ENGINE\s0 \*(L"exdata\*(R" was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CRYPTO_get_mem_functions.3ossl b/openssl-install/share/man/man3/CRYPTO_get_mem_functions.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_get_mem_functions.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_malloc.3ossl b/openssl-install/share/man/man3/CRYPTO_malloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_malloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_malloc_fn.3ossl b/openssl-install/share/man/man3/CRYPTO_malloc_fn.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_malloc_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_mem_ctrl.3ossl b/openssl-install/share/man/man3/CRYPTO_mem_ctrl.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_mem_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_mem_debug_pop.3ossl b/openssl-install/share/man/man3/CRYPTO_mem_debug_pop.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_mem_debug_pop.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_mem_debug_push.3ossl b/openssl-install/share/man/man3/CRYPTO_mem_debug_push.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_mem_debug_push.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_mem_leaks.3ossl b/openssl-install/share/man/man3/CRYPTO_mem_leaks.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_mem_leaks.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_mem_leaks_cb.3ossl b/openssl-install/share/man/man3/CRYPTO_mem_leaks_cb.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_mem_leaks_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_mem_leaks_fp.3ossl b/openssl-install/share/man/man3/CRYPTO_mem_leaks_fp.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_mem_leaks_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_memcmp.3ossl b/openssl-install/share/man/man3/CRYPTO_memcmp.3ossl deleted file mode 100644 index c1e6b87b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_memcmp.3ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CRYPTO_MEMCMP 3ossl" -.TH CRYPTO_MEMCMP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CRYPTO_memcmp \- Constant time memory comparison -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CRYPTO_memcmp(const void *a, const void *b, size_t len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The CRYPTO_memcmp function compares the \fBlen\fR bytes pointed to by \fBa\fR and \fBb\fR -for equality. -It takes an amount of time dependent on \fBlen\fR, but independent of the -contents of the memory regions pointed to by \fBa\fR and \fBb\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCRYPTO_memcmp()\fR returns 0 if the memory regions are equal and nonzero -otherwise. -.SH "NOTES" -.IX Header "NOTES" -Unlike \fBmemcmp\fR\|(2), this function cannot be used to order the two memory regions -as the return value when they differ is undefined, other than being nonzero. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CRYPTO_new_ex_data.3ossl b/openssl-install/share/man/man3/CRYPTO_new_ex_data.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_new_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_realloc.3ossl b/openssl-install/share/man/man3/CRYPTO_realloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_realloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_realloc_fn.3ossl b/openssl-install/share/man/man3/CRYPTO_realloc_fn.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_realloc_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_allocated.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_allocated.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_allocated.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_clear_free.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_clear_free.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_clear_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_free.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_free.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_malloc.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_malloc.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_malloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_malloc_done.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_malloc_done.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_malloc_done.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_malloc_init.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_malloc_init.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_malloc_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_malloc_initialized.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_malloc_initialized.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_malloc_initialized.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_used.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_used.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_used.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_secure_zalloc.3ossl b/openssl-install/share/man/man3/CRYPTO_secure_zalloc.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/CRYPTO_secure_zalloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_set_ex_data.3ossl b/openssl-install/share/man/man3/CRYPTO_set_ex_data.3ossl deleted file mode 120000 index 3053260b..00000000 --- a/openssl-install/share/man/man3/CRYPTO_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_set_mem_debug.3ossl b/openssl-install/share/man/man3/CRYPTO_set_mem_debug.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_set_mem_debug.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_set_mem_functions.3ossl b/openssl-install/share/man/man3/CRYPTO_set_mem_functions.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_set_mem_functions.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_strdup.3ossl b/openssl-install/share/man/man3/CRYPTO_strdup.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_strdup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_strndup.3ossl b/openssl-install/share/man/man3/CRYPTO_strndup.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_strndup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CRYPTO_zalloc.3ossl b/openssl-install/share/man/man3/CRYPTO_zalloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/CRYPTO_zalloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_STORE_free.3ossl b/openssl-install/share/man/man3/CTLOG_STORE_free.3ossl deleted file mode 120000 index 5dcc6385..00000000 --- a/openssl-install/share/man/man3/CTLOG_STORE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_STORE_get0_log_by_id.3ossl b/openssl-install/share/man/man3/CTLOG_STORE_get0_log_by_id.3ossl deleted file mode 100644 index 57948a06..00000000 --- a/openssl-install/share/man/man3/CTLOG_STORE_get0_log_by_id.3ossl +++ /dev/null @@ -1,180 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CTLOG_STORE_GET0_LOG_BY_ID 3ossl" -.TH CTLOG_STORE_GET0_LOG_BY_ID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CTLOG_STORE_get0_log_by_id \- -Get a Certificate Transparency log from a CTLOG_STORE -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const CTLOG *CTLOG_STORE_get0_log_by_id(const CTLOG_STORE *store, -\& const uint8_t *log_id, -\& size_t log_id_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A Signed Certificate Timestamp (\s-1SCT\s0) identifies the Certificate Transparency -(\s-1CT\s0) log that issued it using the log's LogID (see \s-1RFC 6962,\s0 Section 3.2). -Therefore, it is useful to be able to look up more information about a log -(e.g. its public key) using this LogID. -.PP -\&\fBCTLOG_STORE_get0_log_by_id()\fR provides a way to do this. It will find a \s-1CTLOG\s0 -in a \s-1CTLOG_STORE\s0 that has a given LogID. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCTLOG_STORE_get0_log_by_id\fR returns a \s-1CTLOG\s0 with the given LogID, if it -exists in the given \s-1CTLOG_STORE,\s0 otherwise it returns \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7), -\&\fBCTLOG_STORE_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBCTLOG_STORE_get0_log_by_id()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CTLOG_STORE_load_default_file.3ossl b/openssl-install/share/man/man3/CTLOG_STORE_load_default_file.3ossl deleted file mode 120000 index 5dcc6385..00000000 --- a/openssl-install/share/man/man3/CTLOG_STORE_load_default_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_STORE_load_file.3ossl b/openssl-install/share/man/man3/CTLOG_STORE_load_file.3ossl deleted file mode 120000 index 5dcc6385..00000000 --- a/openssl-install/share/man/man3/CTLOG_STORE_load_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_STORE_new.3ossl b/openssl-install/share/man/man3/CTLOG_STORE_new.3ossl deleted file mode 100644 index e13789b4..00000000 --- a/openssl-install/share/man/man3/CTLOG_STORE_new.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CTLOG_STORE_NEW 3ossl" -.TH CTLOG_STORE_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CTLOG_STORE_new_ex, -CTLOG_STORE_new, CTLOG_STORE_free, -CTLOG_STORE_load_default_file, CTLOG_STORE_load_file \- -Create and populate a Certificate Transparency log list -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CTLOG_STORE *CTLOG_STORE_new_ex(OSSL_LIB_CTX *libctx, const char *propq); -\& CTLOG_STORE *CTLOG_STORE_new(void); -\& void CTLOG_STORE_free(CTLOG_STORE *store); -\& -\& int CTLOG_STORE_load_default_file(CTLOG_STORE *store); -\& int CTLOG_STORE_load_file(CTLOG_STORE *store, const char *file); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A \s-1CTLOG_STORE\s0 is a container for a list of CTLOGs (Certificate Transparency -logs). The list can be loaded from one or more files and then searched by LogID -(see \s-1RFC 6962,\s0 Section 3.2, for the definition of a LogID). -.PP -\&\fBCTLOG_STORE_new_ex()\fR creates an empty list of \s-1CT\s0 logs associated with -the library context \fIlibctx\fR and the property query string \fIpropq\fR. -.PP -\&\fBCTLOG_STORE_new()\fR does the same thing as \fBCTLOG_STORE_new_ex()\fR but with -the default library context and property query string. -.PP -The \s-1CTLOG_STORE\s0 is then populated by \fBCTLOG_STORE_load_default_file()\fR or -\&\fBCTLOG_STORE_load_file()\fR. \fBCTLOG_STORE_load_default_file()\fR loads from the default -file, which is named \fIct_log_list.cnf\fR in \s-1OPENSSLDIR\s0 (see the output of -\&\fBopenssl\-version\fR\|(1)). This can be overridden using an environment variable -named \fB\s-1CTLOG_FILE\s0\fR. \fBCTLOG_STORE_load_file()\fR loads from a caller-specified file -path instead. Both of these functions append any loaded \s-1CT\s0 logs to the -\&\s-1CTLOG_STORE.\s0 -.PP -The expected format of the file is: -.PP -.Vb 1 -\& enabled_logs=foo,bar -\& -\& [foo] -\& description = Log 1 -\& key = -\& -\& [bar] -\& description = Log 2 -\& key = -.Ve -.PP -Once a \s-1CTLOG_STORE\s0 is no longer required, it should be passed to -\&\fBCTLOG_STORE_free()\fR. This will delete all of the CTLOGs stored within, along -with the \s-1CTLOG_STORE\s0 itself. If the argument is \s-1NULL,\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -If there are any invalid \s-1CT\s0 logs in a file, they are skipped and the remaining -valid logs will still be added to the \s-1CTLOG_STORE. A CT\s0 log will be considered -invalid if it is missing a \*(L"key\*(R" or \*(L"description\*(R" field. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Both \fBCTLOG_STORE_load_default_file\fR and \fBCTLOG_STORE_load_file\fR return 1 if -all \s-1CT\s0 logs in the file are successfully parsed and loaded, 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7), -\&\fBCTLOG_STORE_get0_log_by_id\fR\|(3), -\&\fBSSL_CTX_set_ctlog_list_file\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -CTLOG_STORE_new_ex was added in OpenSSL 3.0. All other functions were -added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CTLOG_STORE_new_ex.3ossl b/openssl-install/share/man/man3/CTLOG_STORE_new_ex.3ossl deleted file mode 120000 index 5dcc6385..00000000 --- a/openssl-install/share/man/man3/CTLOG_STORE_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_free.3ossl b/openssl-install/share/man/man3/CTLOG_free.3ossl deleted file mode 120000 index 03f96640..00000000 --- a/openssl-install/share/man/man3/CTLOG_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_get0_log_id.3ossl b/openssl-install/share/man/man3/CTLOG_get0_log_id.3ossl deleted file mode 120000 index 03f96640..00000000 --- a/openssl-install/share/man/man3/CTLOG_get0_log_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_get0_name.3ossl b/openssl-install/share/man/man3/CTLOG_get0_name.3ossl deleted file mode 120000 index 03f96640..00000000 --- a/openssl-install/share/man/man3/CTLOG_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_get0_public_key.3ossl b/openssl-install/share/man/man3/CTLOG_get0_public_key.3ossl deleted file mode 120000 index 03f96640..00000000 --- a/openssl-install/share/man/man3/CTLOG_get0_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_new.3ossl b/openssl-install/share/man/man3/CTLOG_new.3ossl deleted file mode 100644 index 189aad58..00000000 --- a/openssl-install/share/man/man3/CTLOG_new.3ossl +++ /dev/null @@ -1,221 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CTLOG_NEW 3ossl" -.TH CTLOG_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CTLOG_new_ex, CTLOG_new, CTLOG_new_from_base64, -CTLOG_new_from_base64_ex, CTLOG_free, -CTLOG_get0_name, CTLOG_get0_log_id, CTLOG_get0_public_key \- -encapsulates information about a Certificate Transparency log -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CTLOG *CTLOG_new_ex(EVP_PKEY *public_key, const char *name, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& CTLOG *CTLOG_new(EVP_PKEY *public_key, const char *name); -\& -\& int CTLOG_new_from_base64_ex(CTLOG **ct_log, const char *pkey_base64, -\& const char *name, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int CTLOG_new_from_base64(CTLOG ** ct_log, -\& const char *pkey_base64, const char *name); -\& void CTLOG_free(CTLOG *log); -\& const char *CTLOG_get0_name(const CTLOG *log); -\& void CTLOG_get0_log_id(const CTLOG *log, const uint8_t **log_id, -\& size_t *log_id_len); -\& EVP_PKEY *CTLOG_get0_public_key(const CTLOG *log); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBCTLOG_new_ex()\fR returns a new \s-1CTLOG\s0 that represents the Certificate -Transparency (\s-1CT\s0) log with the given public key and associates it with the -library context \fIlibctx\fR and property query string \fIpropq\fR. A name must also -be provided that can be used to help users identify this log. Ownership of the -public key is transferred. -.PP -\&\fBCTLOG_new()\fR does the same thing as \fBCTLOG_new_ex()\fR but with the default -library context and the default property query string. -.PP -\&\fBCTLOG_new_from_base64_ex()\fR also creates a new \s-1CTLOG,\s0 but takes the -public key in base64\-encoded \s-1DER\s0 form and sets the ct_log pointer to point to -the new \s-1CTLOG.\s0 The base64 will be decoded and the public key parsed. The \s-1CTLOG\s0 -will be associated with the given library context \fIlibctx\fR and property query -string \fIpropq\fR. -.PP -\&\fBCTLOG_new_from_base64()\fR does the same thing as -\&\fBCTLOG_new_from_base64_ex()\fR except that the default library context and -property query string are used. -.PP -Regardless of whether \fBCTLOG_new()\fR or \fBCTLOG_new_from_base64()\fR is used, it is the -caller's responsibility to pass the \s-1CTLOG\s0 to \fBCTLOG_free()\fR once it is no longer -needed. This will delete it and, if created by \fBCTLOG_new()\fR, the \s-1EVP_PKEY\s0 that -was passed to it. If the argument to \fBCTLOG_free()\fR is \s-1NULL,\s0 nothing is done. -.PP -\&\fBCTLOG_get0_name()\fR returns the name of the log, as provided when the \s-1CTLOG\s0 was -created. Ownership of the string remains with the \s-1CTLOG.\s0 -.PP -\&\fBCTLOG_get0_log_id()\fR sets *log_id to point to a string containing that log's -LogID (see \s-1RFC 6962\s0). It sets *log_id_len to the length of that LogID. For a -v1 \s-1CT\s0 log, the LogID will be a \s-1SHA\-256\s0 hash (i.e. 32 bytes long). Ownership of -the string remains with the \s-1CTLOG.\s0 -.PP -\&\fBCTLOG_get0_public_key()\fR returns the public key of the \s-1CT\s0 log. Ownership of the -\&\s-1EVP_PKEY\s0 remains with the \s-1CTLOG.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCTLOG_new()\fR will return \s-1NULL\s0 if an error occurs. -.PP -\&\fBCTLOG_new_from_base64()\fR will return 1 on success, 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBCTLOG_new_ex()\fR and \fBCTLOG_new_from_base64_ex()\fR -were added in OpenSSL 3.0. All other functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CTLOG_new_ex.3ossl b/openssl-install/share/man/man3/CTLOG_new_ex.3ossl deleted file mode 120000 index 03f96640..00000000 --- a/openssl-install/share/man/man3/CTLOG_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_new_from_base64.3ossl b/openssl-install/share/man/man3/CTLOG_new_from_base64.3ossl deleted file mode 120000 index 03f96640..00000000 --- a/openssl-install/share/man/man3/CTLOG_new_from_base64.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CTLOG_new_from_base64_ex.3ossl b/openssl-install/share/man/man3/CTLOG_new_from_base64_ex.3ossl deleted file mode 120000 index 03f96640..00000000 --- a/openssl-install/share/man/man3/CTLOG_new_from_base64_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CTLOG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_free.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_free.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_cert.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_cert.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_issuer.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_issuer.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_log_store.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_log_store.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get0_log_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get_time.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get_time.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_get_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new.3ossl deleted file mode 100644 index da116fd1..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new.3ossl +++ /dev/null @@ -1,247 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CT_POLICY_EVAL_CTX_NEW 3ossl" -.TH CT_POLICY_EVAL_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CT_POLICY_EVAL_CTX_new_ex, -CT_POLICY_EVAL_CTX_new, CT_POLICY_EVAL_CTX_free, -CT_POLICY_EVAL_CTX_get0_cert, CT_POLICY_EVAL_CTX_set1_cert, -CT_POLICY_EVAL_CTX_get0_issuer, CT_POLICY_EVAL_CTX_set1_issuer, -CT_POLICY_EVAL_CTX_get0_log_store, CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE, -CT_POLICY_EVAL_CTX_get_time, CT_POLICY_EVAL_CTX_set_time \- -Encapsulates the data required to evaluate whether SCTs meet a Certificate Transparency policy -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CT_POLICY_EVAL_CTX *CT_POLICY_EVAL_CTX_new_ex(OSSL_LIB_CTX *libctx, -\& const char *propq); -\& CT_POLICY_EVAL_CTX *CT_POLICY_EVAL_CTX_new(void); -\& void CT_POLICY_EVAL_CTX_free(CT_POLICY_EVAL_CTX *ctx); -\& X509* CT_POLICY_EVAL_CTX_get0_cert(const CT_POLICY_EVAL_CTX *ctx); -\& int CT_POLICY_EVAL_CTX_set1_cert(CT_POLICY_EVAL_CTX *ctx, X509 *cert); -\& X509* CT_POLICY_EVAL_CTX_get0_issuer(const CT_POLICY_EVAL_CTX *ctx); -\& int CT_POLICY_EVAL_CTX_set1_issuer(CT_POLICY_EVAL_CTX *ctx, X509 *issuer); -\& const CTLOG_STORE *CT_POLICY_EVAL_CTX_get0_log_store(const CT_POLICY_EVAL_CTX *ctx); -\& void CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE(CT_POLICY_EVAL_CTX *ctx, -\& CTLOG_STORE *log_store); -\& uint64_t CT_POLICY_EVAL_CTX_get_time(const CT_POLICY_EVAL_CTX *ctx); -\& void CT_POLICY_EVAL_CTX_set_time(CT_POLICY_EVAL_CTX *ctx, uint64_t time_in_ms); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A \fB\s-1CT_POLICY_EVAL_CTX\s0\fR is used by functions that evaluate whether Signed -Certificate Timestamps (SCTs) fulfil a Certificate Transparency (\s-1CT\s0) policy. -This policy may be, for example, that at least one valid \s-1SCT\s0 is available. To -determine this, an \s-1SCT\s0's timestamp and signature must be verified. -This requires: -.IP "\(bu" 2 -the public key of the log that issued the \s-1SCT\s0 -.IP "\(bu" 2 -the certificate that the \s-1SCT\s0 was issued for -.IP "\(bu" 2 -the issuer certificate (if the \s-1SCT\s0 was issued for a pre-certificate) -.IP "\(bu" 2 -the current time -.PP -The above requirements are met using the setters described below. -.PP -\&\fBCT_POLICY_EVAL_CTX_new_ex()\fR creates an empty policy evaluation context -and associates it with the given library context \fIlibctx\fR and property query -string \fIpropq\fR. -.PP -\&\fBCT_POLICY_EVAL_CTX_new()\fR does the same thing as -\&\fBCT_POLICY_EVAL_CTX_new_ex()\fR except that it uses the default library -context and property query string. -.PP -The \s-1CT_POLICY_EVAL_CTX\s0 should then be populated using: -.IP "\(bu" 2 -\&\fBCT_POLICY_EVAL_CTX_set1_cert()\fR to provide the certificate the SCTs were issued for -.Sp -Increments the reference count of the certificate. -.IP "\(bu" 2 -\&\fBCT_POLICY_EVAL_CTX_set1_issuer()\fR to provide the issuer certificate -.Sp -Increments the reference count of the certificate. -.IP "\(bu" 2 -\&\fBCT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE()\fR to provide a list of logs that are trusted as sources of SCTs -.Sp -Holds a pointer to the \s-1CTLOG_STORE,\s0 so the \s-1CTLOG_STORE\s0 must outlive the -\&\s-1CT_POLICY_EVAL_CTX.\s0 -.IP "\(bu" 2 -\&\fBCT_POLICY_EVAL_CTX_set_time()\fR to set the time SCTs should be compared with to determine if they are valid -.Sp -The \s-1SCT\s0 timestamp will be compared to this time to check whether the \s-1SCT\s0 was -issued in the future. \s-1RFC6962\s0 states that \*(L"\s-1TLS\s0 clients \s-1MUST\s0 reject SCTs whose -timestamp is in the future\*(R". By default, this will be set to 5 minutes in the -future (e.g. (\fBtime()\fR + 300) * 1000), to allow for clock drift. -.Sp -The time should be in milliseconds since the Unix Epoch. -.PP -Each setter has a matching getter for accessing the current value. -.PP -When no longer required, the \fB\s-1CT_POLICY_EVAL_CTX\s0\fR should be passed to -\&\fBCT_POLICY_EVAL_CTX_free()\fR to delete it. If the argument to -\&\fBCT_POLICY_EVAL_CTX_free()\fR is \s-1NULL,\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -The issuer certificate only needs to be provided if at least one of the SCTs -was issued for a pre-certificate. This will be the case for SCTs embedded in a -certificate (i.e. those in an X.509 extension), but may not be the case for SCTs -found in the \s-1TLS SCT\s0 extension or \s-1OCSP\s0 response. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCT_POLICY_EVAL_CTX_new_ex()\fR and \fBCT_POLICY_EVAL_CTX_new()\fR will return -\&\s-1NULL\s0 if malloc fails. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -CT_POLICY_EVAL_CTX_new_ex was added in OpenSSL 3.0. All other -functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new_ex.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new_ex.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_cert.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_cert.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_issuer.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_issuer.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set1_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_time.3ossl b/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_time.3ossl deleted file mode 120000 index 004d684a..00000000 --- a/openssl-install/share/man/man3/CT_POLICY_EVAL_CTX_set_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -CT_POLICY_EVAL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DECLARE_ASN1_FUNCTIONS.3ossl b/openssl-install/share/man/man3/DECLARE_ASN1_FUNCTIONS.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DECLARE_ASN1_FUNCTIONS.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DECLARE_PEM_rw.3ossl b/openssl-install/share/man/man3/DECLARE_PEM_rw.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/DECLARE_PEM_rw.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DEFINE_LHASH_OF.3ossl b/openssl-install/share/man/man3/DEFINE_LHASH_OF.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/DEFINE_LHASH_OF.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DEFINE_LHASH_OF_EX.3ossl b/openssl-install/share/man/man3/DEFINE_LHASH_OF_EX.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/DEFINE_LHASH_OF_EX.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF.3ossl b/openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF_CONST.3ossl b/openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF_CONST.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/DEFINE_SPECIAL_STACK_OF_CONST.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DEFINE_STACK_OF.3ossl b/openssl-install/share/man/man3/DEFINE_STACK_OF.3ossl deleted file mode 100644 index 0f234f77..00000000 --- a/openssl-install/share/man/man3/DEFINE_STACK_OF.3ossl +++ /dev/null @@ -1,448 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DEFINE_STACK_OF 3ossl" -.TH DEFINE_STACK_OF 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DEFINE_STACK_OF, DEFINE_STACK_OF_CONST, DEFINE_SPECIAL_STACK_OF, -DEFINE_SPECIAL_STACK_OF_CONST, -sk_TYPE_num, sk_TYPE_value, sk_TYPE_new, sk_TYPE_new_null, -sk_TYPE_reserve, sk_TYPE_free, sk_TYPE_zero, sk_TYPE_delete, -sk_TYPE_delete_ptr, sk_TYPE_push, sk_TYPE_unshift, sk_TYPE_pop, -sk_TYPE_shift, sk_TYPE_pop_free, sk_TYPE_insert, sk_TYPE_set, -sk_TYPE_find, sk_TYPE_find_ex, sk_TYPE_find_all, sk_TYPE_sort, -sk_TYPE_is_sorted, sk_TYPE_dup, sk_TYPE_deep_copy, sk_TYPE_set_cmp_func, -sk_TYPE_new_reserve, -OPENSSL_sk_deep_copy, OPENSSL_sk_delete, OPENSSL_sk_delete_ptr, -OPENSSL_sk_dup, OPENSSL_sk_find, OPENSSL_sk_find_ex, OPENSSL_sk_find_all, -OPENSSL_sk_free, OPENSSL_sk_insert, OPENSSL_sk_is_sorted, OPENSSL_sk_new, -OPENSSL_sk_new_null, OPENSSL_sk_new_reserve, OPENSSL_sk_num, OPENSSL_sk_pop, -OPENSSL_sk_pop_free, OPENSSL_sk_push, OPENSSL_sk_reserve, OPENSSL_sk_set, -OPENSSL_sk_set_cmp_func, OPENSSL_sk_shift, OPENSSL_sk_sort, -OPENSSL_sk_unshift, OPENSSL_sk_value, OPENSSL_sk_zero -\&\- stack container -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(TYPE) -\& DEFINE_STACK_OF(TYPE) -\& DEFINE_STACK_OF_CONST(TYPE) -\& DEFINE_SPECIAL_STACK_OF(FUNCTYPE, TYPE) -\& DEFINE_SPECIAL_STACK_OF_CONST(FUNCTYPE, TYPE) -\& -\& typedef int (*sk_TYPE_compfunc)(const TYPE *const *a, const TYPE *const *b); -\& typedef TYPE * (*sk_TYPE_copyfunc)(const TYPE *a); -\& typedef void (*sk_TYPE_freefunc)(TYPE *a); -\& -\& int sk_TYPE_num(const STACK_OF(TYPE) *sk); -\& TYPE *sk_TYPE_value(const STACK_OF(TYPE) *sk, int idx); -\& STACK_OF(TYPE) *sk_TYPE_new(sk_TYPE_compfunc compare); -\& STACK_OF(TYPE) *sk_TYPE_new_null(void); -\& int sk_TYPE_reserve(STACK_OF(TYPE) *sk, int n); -\& void sk_TYPE_free(STACK_OF(TYPE) *sk); -\& void sk_TYPE_zero(STACK_OF(TYPE) *sk); -\& TYPE *sk_TYPE_delete(STACK_OF(TYPE) *sk, int i); -\& TYPE *sk_TYPE_delete_ptr(STACK_OF(TYPE) *sk, TYPE *ptr); -\& int sk_TYPE_push(STACK_OF(TYPE) *sk, const TYPE *ptr); -\& int sk_TYPE_unshift(STACK_OF(TYPE) *sk, const TYPE *ptr); -\& TYPE *sk_TYPE_pop(STACK_OF(TYPE) *sk); -\& TYPE *sk_TYPE_shift(STACK_OF(TYPE) *sk); -\& void sk_TYPE_pop_free(STACK_OF(TYPE) *sk, sk_TYPE_freefunc freefunc); -\& int sk_TYPE_insert(STACK_OF(TYPE) *sk, TYPE *ptr, int idx); -\& TYPE *sk_TYPE_set(STACK_OF(TYPE) *sk, int idx, const TYPE *ptr); -\& int sk_TYPE_find(STACK_OF(TYPE) *sk, TYPE *ptr); -\& int sk_TYPE_find_ex(STACK_OF(TYPE) *sk, TYPE *ptr); -\& int sk_TYPE_find_all(STACK_OF(TYPE) *sk, TYPE *ptr, int *pnum); -\& void sk_TYPE_sort(const STACK_OF(TYPE) *sk); -\& int sk_TYPE_is_sorted(const STACK_OF(TYPE) *sk); -\& STACK_OF(TYPE) *sk_TYPE_dup(const STACK_OF(TYPE) *sk); -\& STACK_OF(TYPE) *sk_TYPE_deep_copy(const STACK_OF(TYPE) *sk, -\& sk_TYPE_copyfunc copyfunc, -\& sk_TYPE_freefunc freefunc); -\& sk_TYPE_compfunc (*sk_TYPE_set_cmp_func(STACK_OF(TYPE) *sk, -\& sk_TYPE_compfunc compare)); -\& STACK_OF(TYPE) *sk_TYPE_new_reserve(sk_TYPE_compfunc compare, int n); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Applications can create and use their own stacks by placing any of the macros -described below in a header file. These macros define typesafe inline -functions that wrap around the utility \fBOPENSSL_sk_\fR \s-1API.\s0 -In the description here, \fB\f(BI\s-1TYPE\s0\fB\fR is used -as a placeholder for any of the OpenSSL datatypes, such as \fBX509\fR. -.PP -The \s-1\fBSTACK_OF\s0()\fR macro returns the name for a stack of the specified \fB\f(BI\s-1TYPE\s0\fB\fR. -This is an opaque pointer to a structure declaration. -This can be used in every header file that references the stack. -There are several \fB\s-1DEFINE...\s0\fR macros that create static inline functions -for all of the functions described on this page. -This should normally be used in one source file, and the stack manipulation -is wrapped with application-specific functions. -.PP -\&\s-1\fBDEFINE_STACK_OF\s0()\fR creates set of functions for a stack of \fB\f(BI\s-1TYPE\s0\fB\fR elements. -The type is referenced by -\&\fB\s-1STACK_OF\s0\fR(\fB\f(BI\s-1TYPE\s0\fB\fR) and each function name begins with \fBsk_\f(BI\s-1TYPE\s0\fB_\fR. -\&\s-1\fBDEFINE_STACK_OF_CONST\s0()\fR is identical to \s-1\fBDEFINE_STACK_OF\s0()\fR except -each element is constant. -.PP -.Vb 4 -\& /* DEFINE_STACK_OF(TYPE) */ -\& TYPE *sk_TYPE_value(STACK_OF(TYPE) *sk, int idx); -\& /* DEFINE_STACK_OF_CONST(TYPE) */ -\& const TYPE *sk_TYPE_value(STACK_OF(TYPE) *sk, int idx); -.Ve -.PP -\&\s-1\fBDEFINE_SPECIAL_STACK_OF\s0()\fR and \s-1\fBDEFINE_SPECIAL_STACK_OF_CONST\s0()\fR are similar -except \fB\s-1FUNCNAME\s0\fR is used in the function names: -.PP -.Vb 4 -\& /* DEFINE_SPECIAL_STACK_OF(TYPE, FUNCNAME) */ -\& TYPE *sk_FUNCNAME_value(STACK_OF(TYPE) *sk, int idx); -\& /* DEFINE_SPECIAL_STACK_OF(TYPE, FUNCNAME) */ -\& const TYPE *sk_FUNCNAME_value(STACK_OF(TYPE) *sk, int idx); -.Ve -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_num\fR() returns the number of elements in \fIsk\fR or \-1 if \fIsk\fR is -\&\s-1NULL.\s0 -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_value\fR() returns element \fIidx\fR in \fIsk\fR, where \fIidx\fR starts at -zero. If \fIidx\fR is out of range then \s-1NULL\s0 is returned. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_new\fR() allocates a new empty stack using comparison function -\&\fIcompare\fR. If \fIcompare\fR is \s-1NULL\s0 then no comparison function is used. This -function is equivalent to \fBsk_\f(BI\s-1TYPE\s0\fB_new_reserve\fR(\fIcompare\fR, 0). -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_new_null\fR() allocates a new empty stack with no comparison -function. This function is equivalent to \fBsk_\f(BI\s-1TYPE\s0\fB_new_reserve\fR(\s-1NULL, 0\s0). -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_reserve\fR() allocates additional memory in the \fIsk\fR structure -such that the next \fIn\fR calls to \fBsk_\f(BI\s-1TYPE\s0\fB_insert\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_push\fR() -or \fBsk_\f(BI\s-1TYPE\s0\fB_unshift\fR() will not fail or cause memory to be allocated -or reallocated. If \fIn\fR is zero, any excess space allocated in the -\&\fIsk\fR structure is freed. On error \fIsk\fR is unchanged. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_new_reserve\fR() allocates a new stack. The new stack will have -additional memory allocated to hold \fIn\fR elements if \fIn\fR is positive. -The next \fIn\fR calls to \fBsk_\f(BI\s-1TYPE\s0\fB_insert\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_push\fR() or -\&\fBsk_\f(BI\s-1TYPE\s0\fB_unshift\fR() will not fail or cause memory to be allocated or -reallocated. If \fIn\fR is zero or less than zero, no memory is allocated. -\&\fBsk_\f(BI\s-1TYPE\s0\fB_new_reserve\fR() also sets the comparison function \fIcompare\fR -to the newly created stack. If \fIcompare\fR is \s-1NULL\s0 then no comparison -function is used. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_set_cmp_func\fR() sets the comparison function of \fIsk\fR to -\&\fIcompare\fR. The previous comparison function is returned or \s-1NULL\s0 if there -was no previous comparison function. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_free\fR() frees up the \fIsk\fR structure. It does \fInot\fR free up any -elements of \fIsk\fR. After this call \fIsk\fR is no longer valid. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_zero\fR() sets the number of elements in \fIsk\fR to zero. It does not -free \fIsk\fR so after this call \fIsk\fR is still valid. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_pop_free\fR() frees up all elements of \fIsk\fR and \fIsk\fR itself. The -free function \fBfreefunc()\fR is called on each element to free it. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_delete\fR() deletes element \fIi\fR from \fIsk\fR. It returns the deleted -element or \s-1NULL\s0 if \fIi\fR is out of range. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_delete_ptr\fR() deletes element matching \fIptr\fR from \fIsk\fR. It -returns the deleted element or \s-1NULL\s0 if no element matching \fIptr\fR was found. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_insert\fR() inserts \fIptr\fR into \fIsk\fR at position \fIidx\fR. Any -existing elements at or after \fIidx\fR are moved downwards. If \fIidx\fR is out -of range the new element is appended to \fIsk\fR. \fBsk_\f(BI\s-1TYPE\s0\fB_insert\fR() either -returns the number of elements in \fIsk\fR after the new element is inserted or -zero if an error (such as memory allocation failure) occurred. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_push\fR() appends \fIptr\fR to \fIsk\fR it is equivalent to: -.PP -.Vb 1 -\& sk_TYPE_insert(sk, ptr, \-1); -.Ve -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_unshift\fR() inserts \fIptr\fR at the start of \fIsk\fR it is equivalent -to: -.PP -.Vb 1 -\& sk_TYPE_insert(sk, ptr, 0); -.Ve -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_pop\fR() returns and removes the last element from \fIsk\fR. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_shift\fR() returns and removes the first element from \fIsk\fR. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_set\fR() sets element \fIidx\fR of \fIsk\fR to \fIptr\fR replacing the current -element. The new element value is returned or \s-1NULL\s0 if an error occurred: -this will only happen if \fIsk\fR is \s-1NULL\s0 or \fIidx\fR is out of range. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_find\fR() searches \fIsk\fR for the element \fIptr\fR. In the case -where no comparison function has been specified, the function performs -a linear search for a pointer equal to \fIptr\fR. The index of the first -matching element is returned or \fB\-1\fR if there is no match. In the case -where a comparison function has been specified, \fIsk\fR is sorted and -\&\fBsk_\f(BI\s-1TYPE\s0\fB_find\fR() returns the index of a matching element or \fB\-1\fR if there -is no match. Note that, in this case the comparison function will usually -compare the values pointed to rather than the pointers themselves and -the order of elements in \fIsk\fR can change. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_find_ex\fR() operates like \fBsk_\f(BI\s-1TYPE\s0\fB_find\fR() except when a -comparison function has been specified and no matching element is found. -Instead of returning \fB\-1\fR, \fBsk_\f(BI\s-1TYPE\s0\fB_find_ex\fR() returns the index of the -element either before or after the location where \fIptr\fR would be if it were -present in \fIsk\fR. The function also does not guarantee that the first matching -element in the sorted stack is returned. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_find_all\fR() operates like \fBsk_\f(BI\s-1TYPE\s0\fB_find\fR() but it also -sets the \fI*pnum\fR to number of matching elements in the stack. In case -no comparison function has been specified the \fI*pnum\fR will be always set -to 1 if matching element was found, 0 otherwise. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_sort\fR() sorts \fIsk\fR using the supplied comparison function. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_is_sorted\fR() returns \fB1\fR if \fIsk\fR is sorted and \fB0\fR otherwise. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_dup\fR() returns a shallow copy of \fIsk\fR -or an empty stack if the passed stack is \s-1NULL.\s0 -Note the pointers in the copy are identical to the original. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_deep_copy\fR() returns a new stack where each element has been -copied or an empty stack if the passed stack is \s-1NULL.\s0 -Copying is performed by the supplied \fBcopyfunc()\fR and freeing by \fBfreefunc()\fR. -The function \fBfreefunc()\fR is only called if an error occurs. -.SH "NOTES" -.IX Header "NOTES" -Care should be taken when accessing stacks in multi-threaded environments. -Any operation which increases the size of a stack such as \fBsk_\f(BI\s-1TYPE\s0\fB_insert\fR() -or \fBsk_\f(BI\s-1TYPE\s0\fB_push\fR() can \*(L"grow\*(R" the size of an internal array and cause race -conditions if the same stack is accessed in a different thread. Operations such -as \fBsk_\f(BI\s-1TYPE\s0\fB_find\fR() and \fBsk_\f(BI\s-1TYPE\s0\fB_sort\fR() can also reorder the stack. -.PP -Any comparison function supplied should use a metric suitable -for use in a binary search operation. That is it should return zero, a -positive or negative value if \fIa\fR is equal to, greater than -or less than \fIb\fR respectively. -.PP -Care should be taken when checking the return values of the functions -\&\fBsk_\f(BI\s-1TYPE\s0\fB_find\fR() and \fBsk_\f(BI\s-1TYPE\s0\fB_find_ex\fR(). They return an index to the -matching element. In particular \fB0\fR indicates a matching first element. -A failed search is indicated by a \fB\-1\fR return value. -.PP -\&\s-1\fBSTACK_OF\s0()\fR, \s-1\fBDEFINE_STACK_OF\s0()\fR, \s-1\fBDEFINE_STACK_OF_CONST\s0()\fR, and -\&\s-1\fBDEFINE_SPECIAL_STACK_OF\s0()\fR are implemented as macros. -.PP -It is not an error to call \fBsk_\f(BI\s-1TYPE\s0\fB_num\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_value\fR(), -\&\fBsk_\f(BI\s-1TYPE\s0\fB_free\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_zero\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_pop_free\fR(), -\&\fBsk_\f(BI\s-1TYPE\s0\fB_delete\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_delete_ptr\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_pop\fR(), -\&\fBsk_\f(BI\s-1TYPE\s0\fB_shift\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_find\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_find_ex\fR(), -and \fBsk_\f(BI\s-1TYPE\s0\fB_find_all\fR() on a \s-1NULL\s0 stack, empty stack, or with -an invalid index. An error is not raised in these conditions. -.PP -The underlying utility \fBOPENSSL_sk_\fR \s-1API\s0 should not be used directly. -It defines these functions: \fBOPENSSL_sk_deep_copy()\fR, -\&\fBOPENSSL_sk_delete()\fR, \fBOPENSSL_sk_delete_ptr()\fR, \fBOPENSSL_sk_dup()\fR, -\&\fBOPENSSL_sk_find()\fR, \fBOPENSSL_sk_find_ex()\fR, \fBOPENSSL_sk_find_all()\fR, -\&\fBOPENSSL_sk_free()\fR, \fBOPENSSL_sk_insert()\fR, \fBOPENSSL_sk_is_sorted()\fR, -\&\fBOPENSSL_sk_new()\fR, \fBOPENSSL_sk_new_null()\fR, \fBOPENSSL_sk_new_reserve()\fR, -\&\fBOPENSSL_sk_num()\fR, \fBOPENSSL_sk_pop()\fR, \fBOPENSSL_sk_pop_free()\fR, \fBOPENSSL_sk_push()\fR, -\&\fBOPENSSL_sk_reserve()\fR, \fBOPENSSL_sk_set()\fR, \fBOPENSSL_sk_set_cmp_func()\fR, -\&\fBOPENSSL_sk_shift()\fR, \fBOPENSSL_sk_sort()\fR, \fBOPENSSL_sk_unshift()\fR, -\&\fBOPENSSL_sk_value()\fR, \fBOPENSSL_sk_zero()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBsk_\f(BI\s-1TYPE\s0\fB_num\fR() returns the number of elements in the stack or \fB\-1\fR if the -passed stack is \s-1NULL.\s0 -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_value\fR() returns a pointer to a stack element or \s-1NULL\s0 if the -index is out of range. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_new\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_new_null\fR() and \fBsk_\f(BI\s-1TYPE\s0\fB_new_reserve\fR() -return an empty stack or \s-1NULL\s0 if an error occurs. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_reserve\fR() returns \fB1\fR on successful allocation of the required -memory or \fB0\fR on error. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_set_cmp_func\fR() returns the old comparison function or \s-1NULL\s0 if -there was no old comparison function. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_free\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_zero\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_pop_free\fR() and -\&\fBsk_\f(BI\s-1TYPE\s0\fB_sort\fR() do not return values. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_pop\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_shift\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_delete\fR() and -\&\fBsk_\f(BI\s-1TYPE\s0\fB_delete_ptr\fR() return a pointer to the deleted element or \s-1NULL\s0 -on error. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_insert\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_push\fR() and \fBsk_\f(BI\s-1TYPE\s0\fB_unshift\fR() return -the total number of elements in the stack and 0 if an error occurred. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_set\fR() returns a pointer to the replacement element or \s-1NULL\s0 on -error. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_find\fR() and \fBsk_\f(BI\s-1TYPE\s0\fB_find_ex\fR() return an index to the found -element or \fB\-1\fR on error. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_is_sorted\fR() returns \fB1\fR if the stack is sorted and \fB0\fR if it is -not. -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_dup\fR() and \fBsk_\f(BI\s-1TYPE\s0\fB_deep_copy\fR() return a pointer to the copy -of the stack or \s-1NULL\s0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -Before OpenSSL 1.1.0, this was implemented via macros and not inline functions -and was not a public \s-1API.\s0 -.PP -\&\fBsk_\f(BI\s-1TYPE\s0\fB_reserve\fR() and \fBsk_\f(BI\s-1TYPE\s0\fB_new_reserve\fR() were added in OpenSSL -1.1.1. -.PP -From OpenSSL 3.2.0, the \fBsk_\f(BI\s-1TYPE\s0\fB_find\fR(), \fBsk_\f(BI\s-1TYPE\s0\fB_find_ex\fR() -and \fBsk_\f(BI\s-1TYPE\s0\fB_find_all\fR() calls are read-only and do not sort the -stack. To avoid any performance implications this change introduces, -\&\fBsk_\f(BI\s-1TYPE\s0\fB_sort\fR() should be called before these find operations. -.PP -Before OpenSSL 3.3.0 \fBsk_\f(BI\s-1TYPE\s0\fB_push\fR() returned \-1 if \fIsk\fR was \s-1NULL.\s0 It -was changed to return 0 in this condition as for other errors. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DEFINE_STACK_OF_CONST.3ossl b/openssl-install/share/man/man3/DEFINE_STACK_OF_CONST.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/DEFINE_STACK_OF_CONST.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_cbc_cksum.3ossl b/openssl-install/share/man/man3/DES_cbc_cksum.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_cbc_cksum.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_cfb64_encrypt.3ossl b/openssl-install/share/man/man3/DES_cfb64_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_cfb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_cfb_encrypt.3ossl b/openssl-install/share/man/man3/DES_cfb_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_cfb_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_crypt.3ossl b/openssl-install/share/man/man3/DES_crypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_crypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ecb2_encrypt.3ossl b/openssl-install/share/man/man3/DES_ecb2_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ecb2_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ecb3_encrypt.3ossl b/openssl-install/share/man/man3/DES_ecb3_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ecb3_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ecb_encrypt.3ossl b/openssl-install/share/man/man3/DES_ecb_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ecb_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ede2_cbc_encrypt.3ossl b/openssl-install/share/man/man3/DES_ede2_cbc_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ede2_cbc_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ede2_cfb64_encrypt.3ossl b/openssl-install/share/man/man3/DES_ede2_cfb64_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ede2_cfb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ede2_ofb64_encrypt.3ossl b/openssl-install/share/man/man3/DES_ede2_ofb64_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ede2_ofb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ede3_cbc_encrypt.3ossl b/openssl-install/share/man/man3/DES_ede3_cbc_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ede3_cbc_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ede3_cfb64_encrypt.3ossl b/openssl-install/share/man/man3/DES_ede3_cfb64_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ede3_cfb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ede3_ofb64_encrypt.3ossl b/openssl-install/share/man/man3/DES_ede3_ofb64_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ede3_ofb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_fcrypt.3ossl b/openssl-install/share/man/man3/DES_fcrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_fcrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_is_weak_key.3ossl b/openssl-install/share/man/man3/DES_is_weak_key.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_is_weak_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_key_sched.3ossl b/openssl-install/share/man/man3/DES_key_sched.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_key_sched.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ncbc_encrypt.3ossl b/openssl-install/share/man/man3/DES_ncbc_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ncbc_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ofb64_encrypt.3ossl b/openssl-install/share/man/man3/DES_ofb64_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ofb64_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_ofb_encrypt.3ossl b/openssl-install/share/man/man3/DES_ofb_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_ofb_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_pcbc_encrypt.3ossl b/openssl-install/share/man/man3/DES_pcbc_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_pcbc_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_quad_cksum.3ossl b/openssl-install/share/man/man3/DES_quad_cksum.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_quad_cksum.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_random_key.3ossl b/openssl-install/share/man/man3/DES_random_key.3ossl deleted file mode 100644 index 19597ca8..00000000 --- a/openssl-install/share/man/man3/DES_random_key.3ossl +++ /dev/null @@ -1,464 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DES_RANDOM_KEY 3ossl" -.TH DES_RANDOM_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DES_random_key, DES_set_key, DES_key_sched, DES_set_key_checked, -DES_set_key_unchecked, DES_set_odd_parity, DES_is_weak_key, -DES_ecb_encrypt, DES_ecb2_encrypt, DES_ecb3_encrypt, DES_ncbc_encrypt, -DES_cfb_encrypt, DES_ofb_encrypt, DES_pcbc_encrypt, DES_cfb64_encrypt, -DES_ofb64_encrypt, DES_xcbc_encrypt, DES_ede2_cbc_encrypt, -DES_ede2_cfb64_encrypt, DES_ede2_ofb64_encrypt, DES_ede3_cbc_encrypt, -DES_ede3_cfb64_encrypt, DES_ede3_ofb64_encrypt, -DES_cbc_cksum, DES_quad_cksum, DES_string_to_key, DES_string_to_2keys, -DES_fcrypt, DES_crypt \- DES encryption -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void DES_random_key(DES_cblock *ret); -\& -\& int DES_set_key(const_DES_cblock *key, DES_key_schedule *schedule); -\& int DES_key_sched(const_DES_cblock *key, DES_key_schedule *schedule); -\& int DES_set_key_checked(const_DES_cblock *key, DES_key_schedule *schedule); -\& void DES_set_key_unchecked(const_DES_cblock *key, DES_key_schedule *schedule); -\& -\& void DES_set_odd_parity(DES_cblock *key); -\& int DES_is_weak_key(const_DES_cblock *key); -\& -\& void DES_ecb_encrypt(const_DES_cblock *input, DES_cblock *output, -\& DES_key_schedule *ks, int enc); -\& void DES_ecb2_encrypt(const_DES_cblock *input, DES_cblock *output, -\& DES_key_schedule *ks1, DES_key_schedule *ks2, int enc); -\& void DES_ecb3_encrypt(const_DES_cblock *input, DES_cblock *output, -\& DES_key_schedule *ks1, DES_key_schedule *ks2, -\& DES_key_schedule *ks3, int enc); -\& -\& void DES_ncbc_encrypt(const unsigned char *input, unsigned char *output, -\& long length, DES_key_schedule *schedule, DES_cblock *ivec, -\& int enc); -\& void DES_cfb_encrypt(const unsigned char *in, unsigned char *out, -\& int numbits, long length, DES_key_schedule *schedule, -\& DES_cblock *ivec, int enc); -\& void DES_ofb_encrypt(const unsigned char *in, unsigned char *out, -\& int numbits, long length, DES_key_schedule *schedule, -\& DES_cblock *ivec); -\& void DES_pcbc_encrypt(const unsigned char *input, unsigned char *output, -\& long length, DES_key_schedule *schedule, DES_cblock *ivec, -\& int enc); -\& void DES_cfb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, DES_key_schedule *schedule, DES_cblock *ivec, -\& int *num, int enc); -\& void DES_ofb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, DES_key_schedule *schedule, DES_cblock *ivec, -\& int *num); -\& -\& void DES_xcbc_encrypt(const unsigned char *input, unsigned char *output, -\& long length, DES_key_schedule *schedule, DES_cblock *ivec, -\& const_DES_cblock *inw, const_DES_cblock *outw, int enc); -\& -\& void DES_ede2_cbc_encrypt(const unsigned char *input, unsigned char *output, -\& long length, DES_key_schedule *ks1, -\& DES_key_schedule *ks2, DES_cblock *ivec, int enc); -\& void DES_ede2_cfb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, DES_key_schedule *ks1, -\& DES_key_schedule *ks2, DES_cblock *ivec, -\& int *num, int enc); -\& void DES_ede2_ofb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, DES_key_schedule *ks1, -\& DES_key_schedule *ks2, DES_cblock *ivec, int *num); -\& -\& void DES_ede3_cbc_encrypt(const unsigned char *input, unsigned char *output, -\& long length, DES_key_schedule *ks1, -\& DES_key_schedule *ks2, DES_key_schedule *ks3, -\& DES_cblock *ivec, int enc); -\& void DES_ede3_cfb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, DES_key_schedule *ks1, -\& DES_key_schedule *ks2, DES_key_schedule *ks3, -\& DES_cblock *ivec, int *num, int enc); -\& void DES_ede3_ofb64_encrypt(const unsigned char *in, unsigned char *out, -\& long length, DES_key_schedule *ks1, -\& DES_key_schedule *ks2, DES_key_schedule *ks3, -\& DES_cblock *ivec, int *num); -\& -\& DES_LONG DES_cbc_cksum(const unsigned char *input, DES_cblock *output, -\& long length, DES_key_schedule *schedule, -\& const_DES_cblock *ivec); -\& DES_LONG DES_quad_cksum(const unsigned char *input, DES_cblock output[], -\& long length, int out_count, DES_cblock *seed); -\& void DES_string_to_key(const char *str, DES_cblock *key); -\& void DES_string_to_2keys(const char *str, DES_cblock *key1, DES_cblock *key2); -\& -\& char *DES_fcrypt(const char *buf, const char *salt, char *ret); -\& char *DES_crypt(const char *buf, const char *salt); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. Applications should -instead use \fBEVP_EncryptInit_ex\fR\|(3), \fBEVP_EncryptUpdate\fR\|(3) and -\&\fBEVP_EncryptFinal_ex\fR\|(3) or the equivalently named decrypt functions. -.PP -This library contains a fast implementation of the \s-1DES\s0 encryption -algorithm. -.PP -There are two phases to the use of \s-1DES\s0 encryption. The first is the -generation of a \fIDES_key_schedule\fR from a key, the second is the -actual encryption. A \s-1DES\s0 key is of type \fIDES_cblock\fR. This type -consists of 8 bytes with odd parity. The least significant bit in -each byte is the parity bit. The key schedule is an expanded form of -the key; it is used to speed the encryption process. -.PP -\&\fBDES_random_key()\fR generates a random key. The random generator must be -seeded when calling this function. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -If the function fails, 0 is returned. -.PP -Before a \s-1DES\s0 key can be used, it must be converted into the -architecture dependent \fIDES_key_schedule\fR via the -\&\fBDES_set_key_checked()\fR or \fBDES_set_key_unchecked()\fR function. -.PP -\&\fBDES_set_key_checked()\fR will check that the key passed is of odd parity -and is not a weak or semi-weak key. If the parity is wrong, then \-1 -is returned. If the key is a weak key, then \-2 is returned. If an -error is returned, the key schedule is not generated. -.PP -\&\fBDES_set_key()\fR works like \fBDES_set_key_checked()\fR and remains for -backward compatibility. -.PP -\&\fBDES_set_odd_parity()\fR sets the parity of the passed \fIkey\fR to odd. -.PP -\&\fBDES_is_weak_key()\fR returns 1 if the passed key is a weak key, 0 if it -is ok. -.PP -The following routines mostly operate on an input and output stream of -\&\fIDES_cblock\fRs. -.PP -\&\fBDES_ecb_encrypt()\fR is the basic \s-1DES\s0 encryption routine that encrypts or -decrypts a single 8\-byte \fIDES_cblock\fR in \fIelectronic code book\fR -(\s-1ECB\s0) mode. It always transforms the input data, pointed to by -\&\fIinput\fR, into the output data, pointed to by the \fIoutput\fR argument. -If the \fIencrypt\fR argument is nonzero (\s-1DES_ENCRYPT\s0), the \fIinput\fR -(cleartext) is encrypted in to the \fIoutput\fR (ciphertext) using the -key_schedule specified by the \fIschedule\fR argument, previously set via -\&\fIDES_set_key\fR. If \fIencrypt\fR is zero (\s-1DES_DECRYPT\s0), the \fIinput\fR (now -ciphertext) is decrypted into the \fIoutput\fR (now cleartext). Input -and output may overlap. \fBDES_ecb_encrypt()\fR does not return a value. -.PP -\&\fBDES_ecb3_encrypt()\fR encrypts/decrypts the \fIinput\fR block by using -three-key Triple-DES encryption in \s-1ECB\s0 mode. This involves encrypting -the input with \fIks1\fR, decrypting with the key schedule \fIks2\fR, and -then encrypting with \fIks3\fR. This routine greatly reduces the chances -of brute force breaking of \s-1DES\s0 and has the advantage of if \fIks1\fR, -\&\fIks2\fR and \fIks3\fR are the same, it is equivalent to just encryption -using \s-1ECB\s0 mode and \fIks1\fR as the key. -.PP -The macro \fBDES_ecb2_encrypt()\fR is provided to perform two-key Triple-DES -encryption by using \fIks1\fR for the final encryption. -.PP -\&\fBDES_ncbc_encrypt()\fR encrypts/decrypts using the \fIcipher-block-chaining\fR -(\s-1CBC\s0) mode of \s-1DES.\s0 If the \fIencrypt\fR argument is nonzero, the -routine cipher-block-chain encrypts the cleartext data pointed to by -the \fIinput\fR argument into the ciphertext pointed to by the \fIoutput\fR -argument, using the key schedule provided by the \fIschedule\fR argument, -and initialization vector provided by the \fIivec\fR argument. If the -\&\fIlength\fR argument is not an integral multiple of eight bytes, the -last block is copied to a temporary area and zero filled. The output -is always an integral multiple of eight bytes. -.PP -\&\fBDES_xcbc_encrypt()\fR is \s-1RSA\s0's \s-1DESX\s0 mode of \s-1DES.\s0 It uses \fIinw\fR and -\&\fIoutw\fR to 'whiten' the encryption. \fIinw\fR and \fIoutw\fR are secret -(unlike the iv) and are as such, part of the key. So the key is sort -of 24 bytes. This is much better than \s-1CBC DES.\s0 -.PP -\&\fBDES_ede3_cbc_encrypt()\fR implements outer triple \s-1CBC DES\s0 encryption with -three keys. This means that each \s-1DES\s0 operation inside the \s-1CBC\s0 mode is -\&\f(CW\*(C`C=E(ks3,D(ks2,E(ks1,M)))\*(C'\fR. This mode is used by \s-1SSL.\s0 -.PP -The \fBDES_ede2_cbc_encrypt()\fR macro implements two-key Triple-DES by -reusing \fIks1\fR for the final encryption. \f(CW\*(C`C=E(ks1,D(ks2,E(ks1,M)))\*(C'\fR. -This form of Triple-DES is used by the \s-1RSAREF\s0 library. -.PP -\&\fBDES_pcbc_encrypt()\fR encrypts/decrypts using the propagating cipher block -chaining mode used by Kerberos v4. Its parameters are the same as -\&\fBDES_ncbc_encrypt()\fR. -.PP -\&\fBDES_cfb_encrypt()\fR encrypts/decrypts using cipher feedback mode. This -method takes an array of characters as input and outputs an array of -characters. It does not require any padding to 8 character groups. -Note: the \fIivec\fR variable is changed and the new changed value needs to -be passed to the next call to this function. Since this function runs -a complete \s-1DES ECB\s0 encryption per \fInumbits\fR, this function is only -suggested for use when sending a small number of characters. -.PP -\&\fBDES_cfb64_encrypt()\fR -implements \s-1CFB\s0 mode of \s-1DES\s0 with 64\-bit feedback. Why is this -useful you ask? Because this routine will allow you to encrypt an -arbitrary number of bytes, without 8 byte padding. Each call to this -routine will encrypt the input bytes to output and then update ivec -and num. num contains 'how far' we are though ivec. If this does -not make much sense, read more about \s-1CFB\s0 mode of \s-1DES.\s0 -.PP -\&\fBDES_ede3_cfb64_encrypt()\fR and \fBDES_ede2_cfb64_encrypt()\fR is the same as -\&\fBDES_cfb64_encrypt()\fR except that Triple-DES is used. -.PP -\&\fBDES_ofb_encrypt()\fR encrypts using output feedback mode. This method -takes an array of characters as input and outputs an array of -characters. It does not require any padding to 8 character groups. -Note: the \fIivec\fR variable is changed and the new changed value needs to -be passed to the next call to this function. Since this function runs -a complete \s-1DES ECB\s0 encryption per \fInumbits\fR, this function is only -suggested for use when sending a small number of characters. -.PP -\&\fBDES_ofb64_encrypt()\fR is the same as \fBDES_cfb64_encrypt()\fR using Output -Feed Back mode. -.PP -\&\fBDES_ede3_ofb64_encrypt()\fR and \fBDES_ede2_ofb64_encrypt()\fR is the same as -\&\fBDES_ofb64_encrypt()\fR, using Triple-DES. -.PP -The following functions are included in the \s-1DES\s0 library for -compatibility with the \s-1MIT\s0 Kerberos library. -.PP -\&\fBDES_cbc_cksum()\fR produces an 8 byte checksum based on the input stream -(via \s-1CBC\s0 encryption). The last 4 bytes of the checksum are returned -and the complete 8 bytes are placed in \fIoutput\fR. This function is -used by Kerberos v4. Other applications should use -\&\fBEVP_DigestInit\fR\|(3) etc. instead. -.PP -\&\fBDES_quad_cksum()\fR is a Kerberos v4 function. It returns a 4 byte -checksum from the input bytes. The algorithm can be iterated over the -input, depending on \fIout_count\fR, 1, 2, 3 or 4 times. If \fIoutput\fR is -non-NULL, the 8 bytes generated by each pass are written into -\&\fIoutput\fR. -.PP -The following are DES-based transformations: -.PP -\&\fBDES_fcrypt()\fR is a fast version of the Unix \fBcrypt\fR\|(3) function. This -version takes only a small amount of space relative to other fast -\&\fBcrypt()\fR implementations. This is different to the normal \fBcrypt()\fR in -that the third parameter is the buffer that the return value is -written into. It needs to be at least 14 bytes long. This function -is thread safe, unlike the normal \fBcrypt()\fR. -.PP -\&\fBDES_crypt()\fR is a faster replacement for the normal system \fBcrypt()\fR. -This function calls \fBDES_fcrypt()\fR with a static array passed as the -third parameter. This mostly emulates the normal non-thread-safe semantics -of \fBcrypt\fR\|(3). -The \fBsalt\fR must be two \s-1ASCII\s0 characters. -.PP -The values returned by \fBDES_fcrypt()\fR and \fBDES_crypt()\fR are terminated by \s-1NUL\s0 -character. -.PP -\&\fBDES_enc_write()\fR writes \fIlen\fR bytes to file descriptor \fIfd\fR from -buffer \fIbuf\fR. The data is encrypted via \fIpcbc_encrypt\fR (default) -using \fIsched\fR for the key and \fIiv\fR as a starting vector. The actual -data send down \fIfd\fR consists of 4 bytes (in network byte order) -containing the length of the following encrypted data. The encrypted -data then follows, padded with random data out to a multiple of 8 -bytes. -.SH "BUGS" -.IX Header "BUGS" -\&\fBDES_cbc_encrypt()\fR does not modify \fBivec\fR; use \fBDES_ncbc_encrypt()\fR -instead. -.PP -\&\fBDES_cfb_encrypt()\fR and \fBDES_ofb_encrypt()\fR operates on input of 8 bits. -What this means is that if you set numbits to 12, and length to 2, the -first 12 bits will come from the 1st input byte and the low half of -the second input byte. The second 12 bits will have the low 8 bits -taken from the 3rd input byte and the top 4 bits taken from the 4th -input byte. The same holds for output. This function has been -implemented this way because most people will be using a multiple of 8 -and because once you get into pulling bytes input bytes apart things -get ugly! -.PP -\&\fBDES_string_to_key()\fR is available for backward compatibility with the -\&\s-1MIT\s0 library. New applications should use a cryptographic hash function. -The same applies for \fBDES_string_to_2key()\fR. -.SH "NOTES" -.IX Header "NOTES" -The \fBdes\fR library was written to be source code compatible with -the \s-1MIT\s0 Kerberos library. -.PP -Applications should use the higher level functions -\&\fBEVP_EncryptInit\fR\|(3) etc. instead of calling these -functions directly. -.PP -Single-key \s-1DES\s0 is insecure due to its short key size. \s-1ECB\s0 mode is -not suitable for most applications; see \fBdes_modes\fR\|(7). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDES_set_key()\fR, \fBDES_key_sched()\fR, and \fBDES_set_key_checked()\fR -return 0 on success or negative values on error. -.PP -\&\fBDES_is_weak_key()\fR returns 1 if the passed key is a weak key, 0 if it -is ok. -.PP -\&\fBDES_cbc_cksum()\fR and \fBDES_quad_cksum()\fR return 4\-byte integer representing the -last 4 bytes of the checksum of the input. -.PP -\&\fBDES_fcrypt()\fR returns a pointer to the caller-provided buffer and \fBDES_crypt()\fR \- -to a static buffer on success; otherwise they return \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBdes_modes\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -The requirement that the \fBsalt\fR parameter to \fBDES_crypt()\fR and \fBDES_fcrypt()\fR -be two \s-1ASCII\s0 characters was first enforced in -OpenSSL 1.1.0. Previous versions tried to use the letter uppercase \fBA\fR -if both character were not present, and could crash when given non-ASCII -on some platforms. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DES_set_key.3ossl b/openssl-install/share/man/man3/DES_set_key.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_set_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_set_key_checked.3ossl b/openssl-install/share/man/man3/DES_set_key_checked.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_set_key_checked.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_set_key_unchecked.3ossl b/openssl-install/share/man/man3/DES_set_key_unchecked.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_set_key_unchecked.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_set_odd_parity.3ossl b/openssl-install/share/man/man3/DES_set_odd_parity.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_set_odd_parity.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_string_to_2keys.3ossl b/openssl-install/share/man/man3/DES_string_to_2keys.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_string_to_2keys.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_string_to_key.3ossl b/openssl-install/share/man/man3/DES_string_to_key.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_string_to_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DES_xcbc_encrypt.3ossl b/openssl-install/share/man/man3/DES_xcbc_encrypt.3ossl deleted file mode 120000 index b58b36df..00000000 --- a/openssl-install/share/man/man3/DES_xcbc_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -DES_random_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_OpenSSL.3ossl b/openssl-install/share/man/man3/DH_OpenSSL.3ossl deleted file mode 120000 index 2611dc87..00000000 --- a/openssl-install/share/man/man3/DH_OpenSSL.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_bits.3ossl b/openssl-install/share/man/man3/DH_bits.3ossl deleted file mode 120000 index c8821495..00000000 --- a/openssl-install/share/man/man3/DH_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_check.3ossl b/openssl-install/share/man/man3/DH_check.3ossl deleted file mode 120000 index bc001523..00000000 --- a/openssl-install/share/man/man3/DH_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_check_ex.3ossl b/openssl-install/share/man/man3/DH_check_ex.3ossl deleted file mode 120000 index bc001523..00000000 --- a/openssl-install/share/man/man3/DH_check_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_check_params.3ossl b/openssl-install/share/man/man3/DH_check_params.3ossl deleted file mode 120000 index bc001523..00000000 --- a/openssl-install/share/man/man3/DH_check_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_check_params_ex.3ossl b/openssl-install/share/man/man3/DH_check_params_ex.3ossl deleted file mode 120000 index bc001523..00000000 --- a/openssl-install/share/man/man3/DH_check_params_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_check_pub_key_ex.3ossl b/openssl-install/share/man/man3/DH_check_pub_key_ex.3ossl deleted file mode 120000 index bc001523..00000000 --- a/openssl-install/share/man/man3/DH_check_pub_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_clear_flags.3ossl b/openssl-install/share/man/man3/DH_clear_flags.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_compute_key.3ossl b/openssl-install/share/man/man3/DH_compute_key.3ossl deleted file mode 120000 index 894c4131..00000000 --- a/openssl-install/share/man/man3/DH_compute_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_compute_key_padded.3ossl b/openssl-install/share/man/man3/DH_compute_key_padded.3ossl deleted file mode 120000 index 894c4131..00000000 --- a/openssl-install/share/man/man3/DH_compute_key_padded.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_free.3ossl b/openssl-install/share/man/man3/DH_free.3ossl deleted file mode 120000 index 5e9fdd82..00000000 --- a/openssl-install/share/man/man3/DH_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_generate_key.3ossl b/openssl-install/share/man/man3/DH_generate_key.3ossl deleted file mode 100644 index e90ccd33..00000000 --- a/openssl-install/share/man/man3/DH_generate_key.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_GENERATE_KEY 3ossl" -.TH DH_GENERATE_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_generate_key, DH_compute_key, DH_compute_key_padded \- perform -Diffie\-Hellman key exchange -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int DH_generate_key(DH *dh); -\& -\& int DH_compute_key(unsigned char *key, const BIGNUM *pub_key, DH *dh); -\& -\& int DH_compute_key_padded(unsigned char *key, const BIGNUM *pub_key, DH *dh); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_derive_init\fR\|(3) -and \fBEVP_PKEY_derive\fR\|(3). -.PP -\&\fBDH_generate_key()\fR performs the first step of a Diffie-Hellman key -exchange by generating private and public \s-1DH\s0 values. By calling -\&\fBDH_compute_key()\fR or \fBDH_compute_key_padded()\fR, these are combined with -the other party's public value to compute the shared key. -.PP -\&\fBDH_generate_key()\fR expects \fBdh\fR to contain the shared parameters -\&\fBdh\->p\fR and \fBdh\->g\fR. It generates a random private \s-1DH\s0 value -unless \fBdh\->priv_key\fR is already set, and computes the -corresponding public value \fBdh\->pub_key\fR, which can then be -published. -.PP -\&\fBDH_compute_key()\fR computes the shared secret from the private \s-1DH\s0 value -in \fBdh\fR and the other party's public value in \fBpub_key\fR and stores -it in \fBkey\fR. \fBkey\fR must point to \fBDH_size(dh)\fR bytes of memory. -The padding style is \s-1RFC 5246\s0 (8.1.2) that strips leading zero bytes. -It is not constant time due to the leading zero bytes being stripped. -The return value should be considered public. -.PP -\&\fBDH_compute_key_padded()\fR is similar but stores a fixed number of bytes. -The padding style is \s-1NIST SP 800\-56A\s0 (C.1) that retains leading zero bytes. -It is constant time due to the leading zero bytes being retained. -The return value should be considered public. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDH_generate_key()\fR returns 1 on success, 0 otherwise. -.PP -\&\fBDH_compute_key()\fR returns the size of the shared secret on success, \-1 -on error. -.PP -\&\fBDH_compute_key_padded()\fR returns \fBDH_size(dh)\fR on success, \-1 on error. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_derive\fR\|(3), -\&\fBDH_new\fR\|(3), \fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), \fBDH_size\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBDH_compute_key_padded()\fR was added in OpenSSL 1.0.2. -.PP -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_generate_parameters.3ossl b/openssl-install/share/man/man3/DH_generate_parameters.3ossl deleted file mode 100644 index e3b22d74..00000000 --- a/openssl-install/share/man/man3/DH_generate_parameters.3ossl +++ /dev/null @@ -1,290 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_GENERATE_PARAMETERS 3ossl" -.TH DH_GENERATE_PARAMETERS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_generate_parameters_ex, DH_generate_parameters, -DH_check, DH_check_params, -DH_check_ex, DH_check_params_ex, DH_check_pub_key_ex -\&\- generate and check Diffie\-Hellman -parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int DH_generate_parameters_ex(DH *dh, int prime_len, int generator, BN_GENCB *cb); -\& -\& int DH_check(DH *dh, int *codes); -\& int DH_check_params(DH *dh, int *codes); -\& -\& int DH_check_ex(const DH *dh); -\& int DH_check_params_ex(const DH *dh); -\& int DH_check_pub_key_ex(const DH *dh, const BIGNUM *pub_key); -.Ve -.PP -The following functions have been deprecated since OpenSSL 0.9.8, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& DH *DH_generate_parameters(int prime_len, int generator, -\& void (*callback)(int, int, void *), void *cb_arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_check\fR\|(3), -\&\fBEVP_PKEY_public_check\fR\|(3), \fBEVP_PKEY_private_check\fR\|(3) and -\&\fBEVP_PKEY_param_check\fR\|(3). -.PP -\&\fBDH_generate_parameters_ex()\fR generates Diffie-Hellman parameters that can -be shared among a group of users, and stores them in the provided \fB\s-1DH\s0\fR -structure. The pseudo-random number generator must be -seeded before calling it. -The parameters generated by \fBDH_generate_parameters_ex()\fR should not be used in -signature schemes. -.PP -\&\fBprime_len\fR is the length in bits of the safe prime to be generated. -\&\fBgenerator\fR is a small number > 1, typically 2 or 5. -.PP -A callback function may be used to provide feedback about the progress -of the key generation. If \fBcb\fR is not \fB\s-1NULL\s0\fR, it will be -called as described in \fBBN_generate_prime\fR\|(3) while a random prime -number is generated, and when a prime has been found, \fBBN_GENCB_call(cb, 3, 0)\fR -is called. See \fBBN_generate_prime_ex\fR\|(3) for information on -the \fBBN_GENCB_call()\fR function. -.PP -\&\fBDH_generate_parameters()\fR is similar to \fBDH_generate_prime_ex()\fR but -expects an old-style callback function; see -\&\fBBN_generate_prime\fR\|(3) for information on the old-style callback. -.PP -\&\fBDH_check_params()\fR confirms that the \fBp\fR and \fBg\fR are likely enough to -be valid. -This is a lightweight check, if a more thorough check is needed, use -\&\fBDH_check()\fR. -The value of \fB*codes\fR is updated with any problems found. -If \fB*codes\fR is zero then no problems were found, otherwise the -following bits may be set: -.IP "\s-1DH_CHECK_P_NOT_PRIME\s0" 4 -.IX Item "DH_CHECK_P_NOT_PRIME" -The parameter \fBp\fR has been determined to not being an odd prime. -Note that the lack of this bit doesn't guarantee that \fBp\fR is a -prime. -.IP "\s-1DH_NOT_SUITABLE_GENERATOR\s0" 4 -.IX Item "DH_NOT_SUITABLE_GENERATOR" -The generator \fBg\fR is not suitable. -Note that the lack of this bit doesn't guarantee that \fBg\fR is -suitable, unless \fBp\fR is known to be a strong prime. -.IP "\s-1DH_MODULUS_TOO_SMALL\s0" 4 -.IX Item "DH_MODULUS_TOO_SMALL" -The modulus is too small. -.IP "\s-1DH_MODULUS_TOO_LARGE\s0" 4 -.IX Item "DH_MODULUS_TOO_LARGE" -The modulus is too large. -.PP -\&\fBDH_check()\fR confirms that the Diffie-Hellman parameters \fBdh\fR are valid. The -value of \fB*codes\fR is updated with any problems found. If \fB*codes\fR is zero then -no problems were found, otherwise the following bits may be set: -.IP "\s-1DH_CHECK_P_NOT_PRIME\s0" 4 -.IX Item "DH_CHECK_P_NOT_PRIME" -The parameter \fBp\fR is not prime. -.IP "\s-1DH_CHECK_P_NOT_SAFE_PRIME\s0" 4 -.IX Item "DH_CHECK_P_NOT_SAFE_PRIME" -The parameter \fBp\fR is not a safe prime and no \fBq\fR value is present. -.IP "\s-1DH_UNABLE_TO_CHECK_GENERATOR\s0" 4 -.IX Item "DH_UNABLE_TO_CHECK_GENERATOR" -The generator \fBg\fR cannot be checked for suitability. -.IP "\s-1DH_NOT_SUITABLE_GENERATOR\s0" 4 -.IX Item "DH_NOT_SUITABLE_GENERATOR" -The generator \fBg\fR is not suitable. -.IP "\s-1DH_CHECK_Q_NOT_PRIME\s0" 4 -.IX Item "DH_CHECK_Q_NOT_PRIME" -The parameter \fBq\fR is not prime. -.IP "\s-1DH_CHECK_INVALID_Q_VALUE\s0" 4 -.IX Item "DH_CHECK_INVALID_Q_VALUE" -The parameter \fBq\fR is invalid. -.IP "\s-1DH_CHECK_INVALID_J_VALUE\s0" 4 -.IX Item "DH_CHECK_INVALID_J_VALUE" -The parameter \fBj\fR is invalid. -.PP -If 0 is returned or \fB*codes\fR is set to a nonzero value the supplied -parameters should not be used for Diffie-Hellman operations otherwise -the security properties of the key exchange are not guaranteed. -.PP -\&\fBDH_check_ex()\fR, \fBDH_check_params()\fR and \fBDH_check_pub_key_ex()\fR are similar to -\&\fBDH_check()\fR and \fBDH_check_params()\fR respectively, but the error reasons are added -to the thread's error queue instead of provided as return values from the -function. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDH_generate_parameters_ex()\fR, \fBDH_check()\fR and \fBDH_check_params()\fR return 1 -if the check could be performed, 0 otherwise. -.PP -\&\fBDH_generate_parameters()\fR returns a pointer to the \s-1DH\s0 structure or \s-1NULL\s0 if -the parameter generation fails. -.PP -\&\fBDH_check_ex()\fR, \fBDH_check_params()\fR and \fBDH_check_pub_key_ex()\fR return 1 if the -check is successful, 0 for failed. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_new\fR\|(3), \fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), -\&\fBDH_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -\&\fBDH_generate_parameters()\fR was deprecated in OpenSSL 0.9.8; use -\&\fBDH_generate_parameters_ex()\fR instead. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_generate_parameters_ex.3ossl b/openssl-install/share/man/man3/DH_generate_parameters_ex.3ossl deleted file mode 120000 index bc001523..00000000 --- a/openssl-install/share/man/man3/DH_generate_parameters_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_generate_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get0_engine.3ossl b/openssl-install/share/man/man3/DH_get0_engine.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get0_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get0_g.3ossl b/openssl-install/share/man/man3/DH_get0_g.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get0_g.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get0_key.3ossl b/openssl-install/share/man/man3/DH_get0_key.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get0_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get0_p.3ossl b/openssl-install/share/man/man3/DH_get0_p.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get0_p.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get0_pqg.3ossl b/openssl-install/share/man/man3/DH_get0_pqg.3ossl deleted file mode 100644 index af3720dc..00000000 --- a/openssl-install/share/man/man3/DH_get0_pqg.3ossl +++ /dev/null @@ -1,283 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_GET0_PQG 3ossl" -.TH DH_GET0_PQG 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_get0_pqg, DH_set0_pqg, DH_get0_key, DH_set0_key, -DH_get0_p, DH_get0_q, DH_get0_g, -DH_get0_priv_key, DH_get0_pub_key, -DH_clear_flags, DH_test_flags, DH_set_flags, DH_get0_engine, -DH_get_length, DH_set_length \- Routines for getting and setting data in a DH object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& void DH_get0_pqg(const DH *dh, -\& const BIGNUM **p, const BIGNUM **q, const BIGNUM **g); -\& int DH_set0_pqg(DH *dh, BIGNUM *p, BIGNUM *q, BIGNUM *g); -\& void DH_get0_key(const DH *dh, -\& const BIGNUM **pub_key, const BIGNUM **priv_key); -\& int DH_set0_key(DH *dh, BIGNUM *pub_key, BIGNUM *priv_key); -\& const BIGNUM *DH_get0_p(const DH *dh); -\& const BIGNUM *DH_get0_q(const DH *dh); -\& const BIGNUM *DH_get0_g(const DH *dh); -\& const BIGNUM *DH_get0_priv_key(const DH *dh); -\& const BIGNUM *DH_get0_pub_key(const DH *dh); -\& void DH_clear_flags(DH *dh, int flags); -\& int DH_test_flags(const DH *dh, int flags); -\& void DH_set_flags(DH *dh, int flags); -\& -\& long DH_get_length(const DH *dh); -\& int DH_set_length(DH *dh, long length); -\& -\& ENGINE *DH_get0_engine(DH *d); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_get_bn_param\fR\|(3) for any methods that -return a \fB\s-1BIGNUM\s0\fR. Refer to \s-1\fBEVP_PKEY\-DH\s0\fR\|(7) for more information. -.PP -A \s-1DH\s0 object contains the parameters \fIp\fR, \fIq\fR and \fIg\fR. Note that the \fIq\fR -parameter is optional. It also contains a public key (\fIpub_key\fR) and -(optionally) a private key (\fIpriv_key\fR). -.PP -The \fIp\fR, \fIq\fR and \fIg\fR parameters can be obtained by calling \fBDH_get0_pqg()\fR. -If the parameters have not yet been set then \fI*p\fR, \fI*q\fR and \fI*g\fR will be set -to \s-1NULL.\s0 Otherwise they are set to pointers to their respective values. These -point directly to the internal representations of the values and therefore -should not be freed directly. -Any of the out parameters \fIp\fR, \fIq\fR, and \fIg\fR can be \s-1NULL,\s0 in which case no -value will be returned for that parameter. -.PP -The \fIp\fR, \fIq\fR and \fIg\fR values can be set by calling \fBDH_set0_pqg()\fR and passing -the new values for \fIp\fR, \fIq\fR and \fIg\fR as parameters to the function. Calling -this function transfers the memory management of the values to the \s-1DH\s0 object, -and therefore the values that have been passed in should not be freed directly -after this function has been called. The \fIq\fR parameter may be \s-1NULL.\s0 -\&\fBDH_set0_pqg()\fR also checks if the parameters associated with \fIp\fR and \fIg\fR and -optionally \fIq\fR are associated with known safe prime groups. If it is a safe -prime group then the value of \fIq\fR will be set to q = (p \- 1) / 2 if \fIq\fR is -\&\s-1NULL.\s0 The optional length parameter will be set to BN_num_bits(\fIq\fR) if \fIq\fR -is not \s-1NULL.\s0 -.PP -To get the public and private key values use the \fBDH_get0_key()\fR function. A -pointer to the public key will be stored in \fI*pub_key\fR, and a pointer to the -private key will be stored in \fI*priv_key\fR. Either may be \s-1NULL\s0 if they have not -been set yet, although if the private key has been set then the public key must -be. The values point to the internal representation of the public key and -private key values. This memory should not be freed directly. -Any of the out parameters \fIpub_key\fR and \fIpriv_key\fR can be \s-1NULL,\s0 in which case -no value will be returned for that parameter. -.PP -The public and private key values can be set using \fBDH_set0_key()\fR. Either -parameter may be \s-1NULL,\s0 which means the corresponding \s-1DH\s0 field is left -untouched. As with \fBDH_set0_pqg()\fR this function transfers the memory management -of the key values to the \s-1DH\s0 object, and therefore they should not be freed -directly after this function has been called. -.PP -Any of the values \fIp\fR, \fIq\fR, \fIg\fR, \fIpriv_key\fR, and \fIpub_key\fR can also be -retrieved separately by the corresponding function \fBDH_get0_p()\fR, \fBDH_get0_q()\fR, -\&\fBDH_get0_g()\fR, \fBDH_get0_priv_key()\fR, and \fBDH_get0_pub_key()\fR, respectively. -.PP -\&\fBDH_set_flags()\fR sets the flags in the \fIflags\fR parameter on the \s-1DH\s0 object. -Multiple flags can be passed in one go (bitwise ORed together). Any flags that -are already set are left set. \fBDH_test_flags()\fR tests to see whether the flags -passed in the \fIflags\fR parameter are currently set in the \s-1DH\s0 object. Multiple -flags can be tested in one go. All flags that are currently set are returned, or -zero if none of the flags are set. \fBDH_clear_flags()\fR clears the specified flags -within the \s-1DH\s0 object. -.PP -\&\fBDH_get0_engine()\fR returns a handle to the \s-1ENGINE\s0 that has been set for this \s-1DH\s0 -object, or \s-1NULL\s0 if no such \s-1ENGINE\s0 has been set. This function is deprecated. All -engines should be replaced by providers. -.PP -The \fBDH_get_length()\fR and \fBDH_set_length()\fR functions get and set the optional -length parameter associated with this \s-1DH\s0 object. If the length is nonzero then -it is used, otherwise it is ignored. The \fIlength\fR parameter indicates the -length of the secret exponent (private key) in bits. For safe prime groups the optional length parameter \fIlength\fR can be -set to a value greater or equal to 2 * maximum_target_security_strength(BN_num_bits(\fIp\fR)) -as listed in SP800\-56Ar3 Table(s) 25 & 26. -These functions are deprecated and should be replaced with -\&\fBEVP_PKEY_CTX_set_params()\fR and \fBEVP_PKEY_get_int_param()\fR using the parameter key -\&\fB\s-1OSSL_PKEY_PARAM_DH_PRIV_LEN\s0\fR as described in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -Values retrieved with \fBDH_get0_key()\fR are owned by the \s-1DH\s0 object used -in the call and may therefore \fInot\fR be passed to \fBDH_set0_key()\fR. If -needed, duplicate the received value using \fBBN_dup()\fR and pass the -duplicate. The same applies to \fBDH_get0_pqg()\fR and \fBDH_set0_pqg()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDH_set0_pqg()\fR and \fBDH_set0_key()\fR return 1 on success or 0 on failure. -.PP -\&\fBDH_get0_p()\fR, \fBDH_get0_q()\fR, \fBDH_get0_g()\fR, \fBDH_get0_priv_key()\fR, and \fBDH_get0_pub_key()\fR -return the respective value, or \s-1NULL\s0 if it is unset. -.PP -\&\fBDH_test_flags()\fR returns the current state of the flags in the \s-1DH\s0 object. -.PP -\&\fBDH_get0_engine()\fR returns the \s-1ENGINE\s0 set for the \s-1DH\s0 object or \s-1NULL\s0 if no \s-1ENGINE\s0 -has been set. -.PP -\&\fBDH_get_length()\fR returns the length of the secret exponent (private key) in bits, -or zero if no such length has been explicitly set. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_new\fR\|(3), \fBDH_new\fR\|(3), \fBDH_generate_parameters\fR\|(3), \fBDH_generate_key\fR\|(3), -\&\fBDH_set_method\fR\|(3), \fBDH_size\fR\|(3), \fBDH_meth_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 1.1.0. -.PP -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_get0_priv_key.3ossl b/openssl-install/share/man/man3/DH_get0_priv_key.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get0_priv_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get0_pub_key.3ossl b/openssl-install/share/man/man3/DH_get0_pub_key.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get0_pub_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get0_q.3ossl b/openssl-install/share/man/man3/DH_get0_q.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get0_q.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get_1024_160.3ossl b/openssl-install/share/man/man3/DH_get_1024_160.3ossl deleted file mode 100644 index af899c3a..00000000 --- a/openssl-install/share/man/man3/DH_get_1024_160.3ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_GET_1024_160 3ossl" -.TH DH_GET_1024_160 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_get_1024_160, -DH_get_2048_224, -DH_get_2048_256, -BN_get0_nist_prime_192, -BN_get0_nist_prime_224, -BN_get0_nist_prime_256, -BN_get0_nist_prime_384, -BN_get0_nist_prime_521, -BN_get_rfc2409_prime_768, -BN_get_rfc2409_prime_1024, -BN_get_rfc3526_prime_1536, -BN_get_rfc3526_prime_2048, -BN_get_rfc3526_prime_3072, -BN_get_rfc3526_prime_4096, -BN_get_rfc3526_prime_6144, -BN_get_rfc3526_prime_8192 -\&\- Create standardized public primes or DH pairs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const BIGNUM *BN_get0_nist_prime_192(void); -\& const BIGNUM *BN_get0_nist_prime_224(void); -\& const BIGNUM *BN_get0_nist_prime_256(void); -\& const BIGNUM *BN_get0_nist_prime_384(void); -\& const BIGNUM *BN_get0_nist_prime_521(void); -\& -\& BIGNUM *BN_get_rfc2409_prime_768(BIGNUM *bn); -\& BIGNUM *BN_get_rfc2409_prime_1024(BIGNUM *bn); -\& BIGNUM *BN_get_rfc3526_prime_1536(BIGNUM *bn); -\& BIGNUM *BN_get_rfc3526_prime_2048(BIGNUM *bn); -\& BIGNUM *BN_get_rfc3526_prime_3072(BIGNUM *bn); -\& BIGNUM *BN_get_rfc3526_prime_4096(BIGNUM *bn); -\& BIGNUM *BN_get_rfc3526_prime_6144(BIGNUM *bn); -\& BIGNUM *BN_get_rfc3526_prime_8192(BIGNUM *bn); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #include -\& -\& DH *DH_get_1024_160(void); -\& DH *DH_get_2048_224(void); -\& DH *DH_get_2048_256(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBDH_get_1024_160()\fR, \fBDH_get_2048_224()\fR, and \fBDH_get_2048_256()\fR each return -a \s-1DH\s0 object for the \s-1IETF RFC 5114\s0 value. These functions are deprecated. -Applications should instead use \fBEVP_PKEY_CTX_set_dh_rfc5114()\fR and -\&\fBEVP_PKEY_CTX_set_dhx_rfc5114()\fR as described in \fBEVP_PKEY_CTX_ctrl\fR\|(3) or -by setting the \fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR as specified in -\&\*(L"\s-1DH\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7)) to one of \*(L"dh_1024_160\*(R", \*(L"dh_2048_224\*(R" or -\&\*(L"dh_2048_256\*(R". -.PP -\&\fBBN_get0_nist_prime_192()\fR, \fBBN_get0_nist_prime_224()\fR, \fBBN_get0_nist_prime_256()\fR, -\&\fBBN_get0_nist_prime_384()\fR, and \fBBN_get0_nist_prime_521()\fR functions return -a \s-1BIGNUM\s0 for the specific \s-1NIST\s0 prime curve (e.g., P\-256). -.PP -\&\fBBN_get_rfc2409_prime_768()\fR, \fBBN_get_rfc2409_prime_1024()\fR, -\&\fBBN_get_rfc3526_prime_1536()\fR, \fBBN_get_rfc3526_prime_2048()\fR, -\&\fBBN_get_rfc3526_prime_3072()\fR, \fBBN_get_rfc3526_prime_4096()\fR, -\&\fBBN_get_rfc3526_prime_6144()\fR, and \fBBN_get_rfc3526_prime_8192()\fR functions -return a \s-1BIGNUM\s0 for the specified size from \s-1IETF RFC 2409.\s0 If \fBbn\fR -is not \s-1NULL,\s0 the \s-1BIGNUM\s0 will be set into that location as well. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Defined above. -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBDH_get_1024_160()\fR, \fBDH_get_2048_224()\fR and \fBDH_get_2048_256()\fR were -deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_get_2048_224.3ossl b/openssl-install/share/man/man3/DH_get_2048_224.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/DH_get_2048_224.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get_2048_256.3ossl b/openssl-install/share/man/man3/DH_get_2048_256.3ossl deleted file mode 120000 index 6fb9f6c0..00000000 --- a/openssl-install/share/man/man3/DH_get_2048_256.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get_1024_160.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get_default_method.3ossl b/openssl-install/share/man/man3/DH_get_default_method.3ossl deleted file mode 120000 index 2611dc87..00000000 --- a/openssl-install/share/man/man3/DH_get_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get_ex_data.3ossl b/openssl-install/share/man/man3/DH_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/DH_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get_ex_new_index.3ossl b/openssl-install/share/man/man3/DH_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/DH_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get_length.3ossl b/openssl-install/share/man/man3/DH_get_length.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_get_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_get_nid.3ossl b/openssl-install/share/man/man3/DH_get_nid.3ossl deleted file mode 120000 index 885a063b..00000000 --- a/openssl-install/share/man/man3/DH_get_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_new_by_nid.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_dup.3ossl b/openssl-install/share/man/man3/DH_meth_dup.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_free.3ossl b/openssl-install/share/man/man3/DH_meth_free.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get0_app_data.3ossl b/openssl-install/share/man/man3/DH_meth_get0_app_data.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get0_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get0_name.3ossl b/openssl-install/share/man/man3/DH_meth_get0_name.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get_bn_mod_exp.3ossl b/openssl-install/share/man/man3/DH_meth_get_bn_mod_exp.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get_bn_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get_compute_key.3ossl b/openssl-install/share/man/man3/DH_meth_get_compute_key.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get_compute_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get_finish.3ossl b/openssl-install/share/man/man3/DH_meth_get_finish.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get_flags.3ossl b/openssl-install/share/man/man3/DH_meth_get_flags.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get_generate_key.3ossl b/openssl-install/share/man/man3/DH_meth_get_generate_key.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get_generate_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get_generate_params.3ossl b/openssl-install/share/man/man3/DH_meth_get_generate_params.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get_generate_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_get_init.3ossl b/openssl-install/share/man/man3/DH_meth_get_init.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_new.3ossl b/openssl-install/share/man/man3/DH_meth_new.3ossl deleted file mode 100644 index bced9630..00000000 --- a/openssl-install/share/man/man3/DH_meth_new.3ossl +++ /dev/null @@ -1,311 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_METH_NEW 3ossl" -.TH DH_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_meth_new, DH_meth_free, DH_meth_dup, DH_meth_get0_name, DH_meth_set1_name, -DH_meth_get_flags, DH_meth_set_flags, DH_meth_get0_app_data, -DH_meth_set0_app_data, DH_meth_get_generate_key, DH_meth_set_generate_key, -DH_meth_get_compute_key, DH_meth_set_compute_key, DH_meth_get_bn_mod_exp, -DH_meth_set_bn_mod_exp, DH_meth_get_init, DH_meth_set_init, DH_meth_get_finish, -DH_meth_set_finish, DH_meth_get_generate_params, -DH_meth_set_generate_params \- Routines to build up DH methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& DH_METHOD *DH_meth_new(const char *name, int flags); -\& -\& void DH_meth_free(DH_METHOD *dhm); -\& -\& DH_METHOD *DH_meth_dup(const DH_METHOD *dhm); -\& -\& const char *DH_meth_get0_name(const DH_METHOD *dhm); -\& int DH_meth_set1_name(DH_METHOD *dhm, const char *name); -\& -\& int DH_meth_get_flags(const DH_METHOD *dhm); -\& int DH_meth_set_flags(DH_METHOD *dhm, int flags); -\& -\& void *DH_meth_get0_app_data(const DH_METHOD *dhm); -\& int DH_meth_set0_app_data(DH_METHOD *dhm, void *app_data); -\& -\& int (*DH_meth_get_generate_key(const DH_METHOD *dhm))(DH *); -\& int DH_meth_set_generate_key(DH_METHOD *dhm, int (*generate_key)(DH *)); -\& -\& int (*DH_meth_get_compute_key(const DH_METHOD *dhm)) -\& (unsigned char *key, const BIGNUM *pub_key, DH *dh); -\& int DH_meth_set_compute_key(DH_METHOD *dhm, -\& int (*compute_key)(unsigned char *key, const BIGNUM *pub_key, DH *dh)); -\& -\& int (*DH_meth_get_bn_mod_exp(const DH_METHOD *dhm)) -\& (const DH *dh, BIGNUM *r, const BIGNUM *a, const BIGNUM *p, -\& const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *m_ctx); -\& int DH_meth_set_bn_mod_exp(DH_METHOD *dhm, -\& int (*bn_mod_exp)(const DH *dh, BIGNUM *r, const BIGNUM *a, -\& const BIGNUM *p, const BIGNUM *m, BN_CTX *ctx, -\& BN_MONT_CTX *m_ctx)); -\& -\& int (*DH_meth_get_init(const DH_METHOD *dhm))(DH *); -\& int DH_meth_set_init(DH_METHOD *dhm, int (*init)(DH *)); -\& -\& int (*DH_meth_get_finish(const DH_METHOD *dhm))(DH *); -\& int DH_meth_set_finish(DH_METHOD *dhm, int (*finish)(DH *)); -\& -\& int (*DH_meth_get_generate_params(const DH_METHOD *dhm)) -\& (DH *, int, int, BN_GENCB *); -\& int DH_meth_set_generate_params(DH_METHOD *dhm, -\& int (*generate_params)(DH *, int, int, BN_GENCB *)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the provider APIs. -.PP -The \fB\s-1DH_METHOD\s0\fR type is a structure used for the provision of custom \s-1DH\s0 -implementations. It provides a set of functions used by OpenSSL for the -implementation of the various \s-1DH\s0 capabilities. -.PP -\&\fBDH_meth_new()\fR creates a new \fB\s-1DH_METHOD\s0\fR structure. It should be given a -unique \fBname\fR and a set of \fBflags\fR. The \fBname\fR should be a \s-1NULL\s0 terminated -string, which will be duplicated and stored in the \fB\s-1DH_METHOD\s0\fR object. It is -the callers responsibility to free the original string. The flags will be used -during the construction of a new \fB\s-1DH\s0\fR object based on this \fB\s-1DH_METHOD\s0\fR. Any -new \fB\s-1DH\s0\fR object will have those flags set by default. -.PP -\&\fBDH_meth_dup()\fR creates a duplicate copy of the \fB\s-1DH_METHOD\s0\fR object passed as a -parameter. This might be useful for creating a new \fB\s-1DH_METHOD\s0\fR based on an -existing one, but with some differences. -.PP -\&\fBDH_meth_free()\fR destroys a \fB\s-1DH_METHOD\s0\fR structure and frees up any memory -associated with it. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBDH_meth_get0_name()\fR will return a pointer to the name of this \s-1DH_METHOD.\s0 This -is a pointer to the internal name string and so should not be freed by the -caller. \fBDH_meth_set1_name()\fR sets the name of the \s-1DH_METHOD\s0 to \fBname\fR. The -string is duplicated and the copy is stored in the \s-1DH_METHOD\s0 structure, so the -caller remains responsible for freeing the memory associated with the name. -.PP -\&\fBDH_meth_get_flags()\fR returns the current value of the flags associated with this -\&\s-1DH_METHOD.\s0 \fBDH_meth_set_flags()\fR provides the ability to set these flags. -.PP -The functions \fBDH_meth_get0_app_data()\fR and \fBDH_meth_set0_app_data()\fR provide the -ability to associate implementation specific data with the \s-1DH_METHOD.\s0 It is -the application's responsibility to free this data before the \s-1DH_METHOD\s0 is -freed via a call to \fBDH_meth_free()\fR. -.PP -\&\fBDH_meth_get_generate_key()\fR and \fBDH_meth_set_generate_key()\fR get and set the -function used for generating a new \s-1DH\s0 key pair respectively. This function will -be called in response to the application calling \fBDH_generate_key()\fR. The -parameter for the function has the same meaning as for \fBDH_generate_key()\fR. -.PP -\&\fBDH_meth_get_compute_key()\fR and \fBDH_meth_set_compute_key()\fR get and set the -function used for computing a new \s-1DH\s0 shared secret respectively. This function -will be called in response to the application calling \fBDH_compute_key()\fR. The -parameters for the function have the same meaning as for \fBDH_compute_key()\fR. -.PP -\&\fBDH_meth_get_bn_mod_exp()\fR and \fBDH_meth_set_bn_mod_exp()\fR get and set the function -used for computing the following value: -.PP -.Vb 1 -\& r = a ^ p mod m -.Ve -.PP -This function will be called by the default OpenSSL function for -\&\fBDH_generate_key()\fR. The result is stored in the \fBr\fR parameter. This function -may be \s-1NULL\s0 unless using the default generate key function, in which case it -must be present. -.PP -\&\fBDH_meth_get_init()\fR and \fBDH_meth_set_init()\fR get and set the function used -for creating a new \s-1DH\s0 instance respectively. This function will be -called in response to the application calling \fBDH_new()\fR (if the current default -\&\s-1DH_METHOD\s0 is this one) or \fBDH_new_method()\fR. The \fBDH_new()\fR and \fBDH_new_method()\fR -functions will allocate the memory for the new \s-1DH\s0 object, and a pointer to this -newly allocated structure will be passed as a parameter to the function. This -function may be \s-1NULL.\s0 -.PP -\&\fBDH_meth_get_finish()\fR and \fBDH_meth_set_finish()\fR get and set the function used -for destroying an instance of a \s-1DH\s0 object respectively. This function will be -called in response to the application calling \fBDH_free()\fR. A pointer to the \s-1DH\s0 -to be destroyed is passed as a parameter. The destroy function should be used -for \s-1DH\s0 implementation specific clean up. The memory for the \s-1DH\s0 itself should -not be freed by this function. This function may be \s-1NULL.\s0 -.PP -\&\fBDH_meth_get_generate_params()\fR and \fBDH_meth_set_generate_params()\fR get and set the -function used for generating \s-1DH\s0 parameters respectively. This function will be -called in response to the application calling \fBDH_generate_parameters_ex()\fR (or -\&\fBDH_generate_parameters()\fR). The parameters for the function have the same -meaning as for \fBDH_generate_parameters_ex()\fR. This function may be \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDH_meth_new()\fR and \fBDH_meth_dup()\fR return the newly allocated \s-1DH_METHOD\s0 object -or \s-1NULL\s0 on failure. -.PP -\&\fBDH_meth_get0_name()\fR and \fBDH_meth_get_flags()\fR return the name and flags -associated with the \s-1DH_METHOD\s0 respectively. -.PP -All other DH_meth_get_*() functions return the appropriate function pointer -that has been set in the \s-1DH_METHOD,\s0 or \s-1NULL\s0 if no such pointer has yet been -set. -.PP -\&\fBDH_meth_set1_name()\fR and all DH_meth_set_*() functions return 1 on success or -0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_new\fR\|(3), \fBDH_new\fR\|(3), \fBDH_generate_parameters\fR\|(3), \fBDH_generate_key\fR\|(3), -\&\fBDH_set_method\fR\|(3), \fBDH_size\fR\|(3), \fBDH_get0_pqg\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -The functions described here were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_meth_set0_app_data.3ossl b/openssl-install/share/man/man3/DH_meth_set0_app_data.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set0_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set1_name.3ossl b/openssl-install/share/man/man3/DH_meth_set1_name.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set1_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set_bn_mod_exp.3ossl b/openssl-install/share/man/man3/DH_meth_set_bn_mod_exp.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set_bn_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set_compute_key.3ossl b/openssl-install/share/man/man3/DH_meth_set_compute_key.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set_compute_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set_finish.3ossl b/openssl-install/share/man/man3/DH_meth_set_finish.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set_flags.3ossl b/openssl-install/share/man/man3/DH_meth_set_flags.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set_generate_key.3ossl b/openssl-install/share/man/man3/DH_meth_set_generate_key.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set_generate_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set_generate_params.3ossl b/openssl-install/share/man/man3/DH_meth_set_generate_params.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set_generate_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_meth_set_init.3ossl b/openssl-install/share/man/man3/DH_meth_set_init.3ossl deleted file mode 120000 index e63ddb08..00000000 --- a/openssl-install/share/man/man3/DH_meth_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_new.3ossl b/openssl-install/share/man/man3/DH_new.3ossl deleted file mode 100644 index 1428c8b7..00000000 --- a/openssl-install/share/man/man3/DH_new.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_NEW 3ossl" -.TH DH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_new, DH_free \- allocate and free DH objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& DH* DH_new(void); -\& -\& void DH_free(DH *dh); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBDH_new()\fR allocates and initializes a \fB\s-1DH\s0\fR structure. -.PP -\&\fBDH_free()\fR frees the \fB\s-1DH\s0\fR structure and its components. The values are -erased before the memory is returned to the system. -If \fBdh\fR is \s-1NULL\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBDH_new()\fR returns \fB\s-1NULL\s0\fR and sets an error -code that can be obtained by \fBERR_get_error\fR\|(3). Otherwise it returns -a pointer to the newly allocated structure. -.PP -\&\fBDH_free()\fR returns no value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_new\fR\|(3), \fBERR_get_error\fR\|(3), -\&\fBDH_generate_parameters\fR\|(3), -\&\fBDH_generate_key\fR\|(3), -\&\s-1\fBEVP_PKEY\-DH\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -For replacement see \s-1\fBEVP_PKEY\-DH\s0\fR\|(7). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_new_by_nid.3ossl b/openssl-install/share/man/man3/DH_new_by_nid.3ossl deleted file mode 100644 index 5ad40396..00000000 --- a/openssl-install/share/man/man3/DH_new_by_nid.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_NEW_BY_NID 3ossl" -.TH DH_NEW_BY_NID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_new_by_nid, DH_get_nid \- create or get DH named parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& DH *DH_new_by_nid(int nid); -\& -\& int DH_get_nid(const DH *dh); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBDH_new_by_nid()\fR creates and returns a \s-1DH\s0 structure containing named parameters -\&\fBnid\fR. Currently \fBnid\fR must be \fBNID_ffdhe2048\fR, \fBNID_ffdhe3072\fR, -\&\fBNID_ffdhe4096\fR, \fBNID_ffdhe6144\fR, \fBNID_ffdhe8192\fR, -\&\fBNID_modp_1536\fR, \fBNID_modp_2048\fR, \fBNID_modp_3072\fR, -\&\fBNID_modp_4096\fR, \fBNID_modp_6144\fR or \fBNID_modp_8192\fR. -.PP -\&\fBDH_get_nid()\fR determines if the parameters contained in \fBdh\fR match -any named safe prime group. It returns the \s-1NID\s0 corresponding to the matching -parameters or \fBNID_undef\fR if there is no match. -This function is deprecated. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDH_new_by_nid()\fR returns a set of \s-1DH\s0 parameters or \fB\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBDH_get_nid()\fR returns the \s-1NID\s0 of the matching set of parameters for p and g -and optionally q, otherwise it returns \fBNID_undef\fR if there is no match. -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_new_method.3ossl b/openssl-install/share/man/man3/DH_new_method.3ossl deleted file mode 120000 index 2611dc87..00000000 --- a/openssl-install/share/man/man3/DH_new_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_security_bits.3ossl b/openssl-install/share/man/man3/DH_security_bits.3ossl deleted file mode 120000 index c8821495..00000000 --- a/openssl-install/share/man/man3/DH_security_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_set0_key.3ossl b/openssl-install/share/man/man3/DH_set0_key.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_set0_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_set0_pqg.3ossl b/openssl-install/share/man/man3/DH_set0_pqg.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_set0_pqg.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_set_default_method.3ossl b/openssl-install/share/man/man3/DH_set_default_method.3ossl deleted file mode 120000 index 2611dc87..00000000 --- a/openssl-install/share/man/man3/DH_set_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_set_ex_data.3ossl b/openssl-install/share/man/man3/DH_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/DH_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_set_flags.3ossl b/openssl-install/share/man/man3/DH_set_flags.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_set_length.3ossl b/openssl-install/share/man/man3/DH_set_length.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_set_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DH_set_method.3ossl b/openssl-install/share/man/man3/DH_set_method.3ossl deleted file mode 100644 index 4c386770..00000000 --- a/openssl-install/share/man/man3/DH_set_method.3ossl +++ /dev/null @@ -1,232 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_SET_METHOD 3ossl" -.TH DH_SET_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_set_default_method, DH_get_default_method, -DH_set_method, DH_new_method, DH_OpenSSL \- select DH method -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void DH_set_default_method(const DH_METHOD *meth); -\& -\& const DH_METHOD *DH_get_default_method(void); -\& -\& int DH_set_method(DH *dh, const DH_METHOD *meth); -\& -\& DH *DH_new_method(ENGINE *engine); -\& -\& const DH_METHOD *DH_OpenSSL(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the provider APIs. -.PP -A \fB\s-1DH_METHOD\s0\fR specifies the functions that OpenSSL uses for Diffie-Hellman -operations. By modifying the method, alternative implementations -such as hardware accelerators may be used. \s-1IMPORTANT:\s0 See the \s-1NOTES\s0 section for -important information about how these \s-1DH API\s0 functions are affected by the use -of \fB\s-1ENGINE\s0\fR \s-1API\s0 calls. -.PP -Initially, the default \s-1DH_METHOD\s0 is the OpenSSL internal implementation, as -returned by \fBDH_OpenSSL()\fR. -.PP -\&\fBDH_set_default_method()\fR makes \fBmeth\fR the default method for all \s-1DH\s0 -structures created later. -\&\fB\s-1NB\s0\fR: This is true only whilst no \s-1ENGINE\s0 has been set -as a default for \s-1DH,\s0 so this function is no longer recommended. -This function is not thread-safe and should not be called at the same time -as other OpenSSL functions. -.PP -\&\fBDH_get_default_method()\fR returns a pointer to the current default \s-1DH_METHOD.\s0 -However, the meaningfulness of this result is dependent on whether the \s-1ENGINE -API\s0 is being used, so this function is no longer recommended. -.PP -\&\fBDH_set_method()\fR selects \fBmeth\fR to perform all operations using the key \fBdh\fR. -This will replace the \s-1DH_METHOD\s0 used by the \s-1DH\s0 key and if the previous method -was supplied by an \s-1ENGINE,\s0 the handle to that \s-1ENGINE\s0 will be released during the -change. It is possible to have \s-1DH\s0 keys that only work with certain \s-1DH_METHOD\s0 -implementations (e.g. from an \s-1ENGINE\s0 module that supports embedded -hardware-protected keys), and in such cases attempting to change the \s-1DH_METHOD\s0 -for the key can have unexpected results. -.PP -\&\fBDH_new_method()\fR allocates and initializes a \s-1DH\s0 structure so that \fBengine\fR will -be used for the \s-1DH\s0 operations. If \fBengine\fR is \s-1NULL,\s0 the default \s-1ENGINE\s0 for \s-1DH\s0 -operations is used, and if no default \s-1ENGINE\s0 is set, the \s-1DH_METHOD\s0 controlled by -\&\fBDH_set_default_method()\fR is used. -.PP -A new \s-1DH_METHOD\s0 object may be constructed using \fBDH_meth_new()\fR (see -\&\fBDH_meth_new\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDH_OpenSSL()\fR and \fBDH_get_default_method()\fR return pointers to the respective -\&\fB\s-1DH_METHOD\s0\fRs. -.PP -\&\fBDH_set_default_method()\fR returns no value. -.PP -\&\fBDH_set_method()\fR returns nonzero if the provided \fBmeth\fR was successfully set as -the method for \fBdh\fR (including unloading the \s-1ENGINE\s0 handle if the previous -method was supplied by an \s-1ENGINE\s0). -.PP -\&\fBDH_new_method()\fR returns \s-1NULL\s0 and sets an error code that can be obtained by -\&\fBERR_get_error\fR\|(3) if the allocation fails. Otherwise it -returns a pointer to the newly allocated structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_new\fR\|(3), \fBDH_new\fR\|(3), \fBDH_meth_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_size.3ossl b/openssl-install/share/man/man3/DH_size.3ossl deleted file mode 100644 index d1957ab5..00000000 --- a/openssl-install/share/man/man3/DH_size.3ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DH_SIZE 3ossl" -.TH DH_SIZE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DH_size, DH_bits, DH_security_bits \- get Diffie\-Hellman prime size and -security bits -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int DH_bits(const DH *dh); -\& -\& int DH_size(const DH *dh); -\& -\& int DH_security_bits(const DH *dh); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_get_bits\fR\|(3), -\&\fBEVP_PKEY_get_security_bits\fR\|(3) and \fBEVP_PKEY_get_size\fR\|(3). -.PP -\&\fBDH_bits()\fR returns the number of significant bits. -.PP -\&\fBdh\fR and \fBdh\->p\fR must not be \fB\s-1NULL\s0\fR. -.PP -\&\fBDH_size()\fR returns the Diffie-Hellman prime size in bytes. It can be used -to determine how much memory must be allocated for the shared secret -computed by \fBDH_compute_key\fR\|(3). -.PP -\&\fBDH_security_bits()\fR returns the number of security bits of the given \fBdh\fR -key. See \fBBN_security_bits\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDH_bits()\fR returns the number of bits in the key, or \-1 if -\&\fBdh\fR doesn't hold any key parameters. -.PP -\&\fBDH_size()\fR returns the prime size of Diffie-Hellman in bytes, or \-1 if -\&\fBdh\fR doesn't hold any key parameters. -.PP -\&\fBDH_security_bits()\fR returns the number of security bits, or \-1 if -\&\fBdh\fR doesn't hold any key parameters. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_get_bits\fR\|(3), -\&\fBDH_new\fR\|(3), \fBDH_generate_key\fR\|(3), -\&\fBBN_num_bits\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DH_test_flags.3ossl b/openssl-install/share/man/man3/DH_test_flags.3ossl deleted file mode 120000 index a661aa4c..00000000 --- a/openssl-install/share/man/man3/DH_test_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DH_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DHparams_print.3ossl b/openssl-install/share/man/man3/DHparams_print.3ossl deleted file mode 120000 index f53ff3b2..00000000 --- a/openssl-install/share/man/man3/DHparams_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DHparams_print_fp.3ossl b/openssl-install/share/man/man3/DHparams_print_fp.3ossl deleted file mode 120000 index f53ff3b2..00000000 --- a/openssl-install/share/man/man3/DHparams_print_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DIRECTORYSTRING_free.3ossl b/openssl-install/share/man/man3/DIRECTORYSTRING_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DIRECTORYSTRING_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DIRECTORYSTRING_new.3ossl b/openssl-install/share/man/man3/DIRECTORYSTRING_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DIRECTORYSTRING_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DISPLAYTEXT_free.3ossl b/openssl-install/share/man/man3/DISPLAYTEXT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DISPLAYTEXT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DISPLAYTEXT_new.3ossl b/openssl-install/share/man/man3/DISPLAYTEXT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DISPLAYTEXT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DIST_POINT_NAME_dup.3ossl b/openssl-install/share/man/man3/DIST_POINT_NAME_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DIST_POINT_NAME_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DIST_POINT_NAME_free.3ossl b/openssl-install/share/man/man3/DIST_POINT_NAME_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DIST_POINT_NAME_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DIST_POINT_NAME_new.3ossl b/openssl-install/share/man/man3/DIST_POINT_NAME_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DIST_POINT_NAME_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DIST_POINT_free.3ossl b/openssl-install/share/man/man3/DIST_POINT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DIST_POINT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DIST_POINT_new.3ossl b/openssl-install/share/man/man3/DIST_POINT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DIST_POINT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_OpenSSL.3ossl b/openssl-install/share/man/man3/DSA_OpenSSL.3ossl deleted file mode 120000 index ecd3ad8b..00000000 --- a/openssl-install/share/man/man3/DSA_OpenSSL.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_SIG_free.3ossl b/openssl-install/share/man/man3/DSA_SIG_free.3ossl deleted file mode 120000 index d4d981ae..00000000 --- a/openssl-install/share/man/man3/DSA_SIG_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_SIG_get0.3ossl b/openssl-install/share/man/man3/DSA_SIG_get0.3ossl deleted file mode 120000 index d4d981ae..00000000 --- a/openssl-install/share/man/man3/DSA_SIG_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_SIG_new.3ossl b/openssl-install/share/man/man3/DSA_SIG_new.3ossl deleted file mode 100644 index 2e567007..00000000 --- a/openssl-install/share/man/man3/DSA_SIG_new.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_SIG_NEW 3ossl" -.TH DSA_SIG_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_SIG_get0, DSA_SIG_set0, -DSA_SIG_new, DSA_SIG_free \- allocate and free DSA signature objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& DSA_SIG *DSA_SIG_new(void); -\& void DSA_SIG_free(DSA_SIG *a); -\& void DSA_SIG_get0(const DSA_SIG *sig, const BIGNUM **pr, const BIGNUM **ps); -\& int DSA_SIG_set0(DSA_SIG *sig, BIGNUM *r, BIGNUM *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBDSA_SIG_new()\fR allocates an empty \fB\s-1DSA_SIG\s0\fR structure. -.PP -\&\fBDSA_SIG_free()\fR frees the \fB\s-1DSA_SIG\s0\fR structure and its components. The -values are erased before the memory is returned to the system. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBDSA_SIG_get0()\fR returns internal pointers to the \fBr\fR and \fBs\fR values contained -in \fBsig\fR. -.PP -The \fBr\fR and \fBs\fR values can be set by calling \fBDSA_SIG_set0()\fR and passing the -new values for \fBr\fR and \fBs\fR as parameters to the function. Calling this -function transfers the memory management of the values to the \s-1DSA_SIG\s0 object, -and therefore the values that have been passed in should not be freed directly -after this function has been called. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBDSA_SIG_new()\fR returns \fB\s-1NULL\s0\fR and sets an -error code that can be obtained by -\&\fBERR_get_error\fR\|(3). Otherwise it returns a pointer -to the newly allocated structure. -.PP -\&\fBDSA_SIG_free()\fR returns no value. -.PP -\&\fBDSA_SIG_set0()\fR returns 1 on success or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_new\fR\|(3), \fBEVP_PKEY_free\fR\|(3), \fBEVP_PKEY_get_bn_param\fR\|(3), -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_SIG_set0.3ossl b/openssl-install/share/man/man3/DSA_SIG_set0.3ossl deleted file mode 120000 index d4d981ae..00000000 --- a/openssl-install/share/man/man3/DSA_SIG_set0.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_bits.3ossl b/openssl-install/share/man/man3/DSA_bits.3ossl deleted file mode 120000 index fb300282..00000000 --- a/openssl-install/share/man/man3/DSA_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_clear_flags.3ossl b/openssl-install/share/man/man3/DSA_clear_flags.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_do_sign.3ossl b/openssl-install/share/man/man3/DSA_do_sign.3ossl deleted file mode 100644 index f0ed9661..00000000 --- a/openssl-install/share/man/man3/DSA_do_sign.3ossl +++ /dev/null @@ -1,197 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_DO_SIGN 3ossl" -.TH DSA_DO_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_do_sign, DSA_do_verify \- raw DSA signature operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& DSA_SIG *DSA_do_sign(const unsigned char *dgst, int dlen, DSA *dsa); -\& -\& int DSA_do_verify(const unsigned char *dgst, int dgst_len, -\& DSA_SIG *sig, DSA *dsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_sign_init\fR\|(3), \fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify_init\fR\|(3) and \fBEVP_PKEY_verify\fR\|(3). -.PP -\&\fBDSA_do_sign()\fR computes a digital signature on the \fBlen\fR byte message -digest \fBdgst\fR using the private key \fBdsa\fR and returns it in a -newly allocated \fB\s-1DSA_SIG\s0\fR structure. -.PP -\&\fBDSA_sign_setup\fR\|(3) may be used to precompute part -of the signing operation in case signature generation is -time-critical. -.PP -\&\fBDSA_do_verify()\fR verifies that the signature \fBsig\fR matches a given -message digest \fBdgst\fR of size \fBlen\fR. \fBdsa\fR is the signer's public -key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_do_sign()\fR returns the signature, \s-1NULL\s0 on error. \fBDSA_do_verify()\fR -returns 1 for a valid signature, 0 for an incorrect signature and \-1 -on error. The error codes can be obtained by -\&\fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDSA_new\fR\|(3), \fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), -\&\fBDSA_SIG_new\fR\|(3), -\&\fBDSA_sign\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_do_verify.3ossl b/openssl-install/share/man/man3/DSA_do_verify.3ossl deleted file mode 120000 index 3fa20e73..00000000 --- a/openssl-install/share/man/man3/DSA_do_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_do_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_dup_DH.3ossl b/openssl-install/share/man/man3/DSA_dup_DH.3ossl deleted file mode 100644 index a1868d6b..00000000 --- a/openssl-install/share/man/man3/DSA_dup_DH.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_DUP_DH 3ossl" -.TH DSA_DUP_DH 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_dup_DH \- create a DH structure out of DSA structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& DH *DSA_dup_DH(const DSA *r); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function described on this page is deprecated. There is no direct -replacement, applications should use the \s-1EVP_PKEY\s0 APIs for Diffie-Hellman -operations. -.PP -\&\fBDSA_dup_DH()\fR duplicates \s-1DSA\s0 parameters/keys as \s-1DH\s0 parameters/keys. q -is lost during that conversion, but the resulting \s-1DH\s0 parameters -contain its length. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_dup_DH()\fR returns the new \fB\s-1DH\s0\fR structure, and \s-1NULL\s0 on error. The -error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "NOTE" -.IX Header "NOTE" -Be careful to avoid small subgroup attacks when using this. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDH_new\fR\|(3), \fBDSA_new\fR\|(3), \fBERR_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This function was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_free.3ossl b/openssl-install/share/man/man3/DSA_free.3ossl deleted file mode 120000 index b494733a..00000000 --- a/openssl-install/share/man/man3/DSA_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_generate_key.3ossl b/openssl-install/share/man/man3/DSA_generate_key.3ossl deleted file mode 100644 index e0267846..00000000 --- a/openssl-install/share/man/man3/DSA_generate_key.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_GENERATE_KEY 3ossl" -.TH DSA_GENERATE_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_generate_key \- generate DSA key pair -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int DSA_generate_key(DSA *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_keygen_init\fR\|(3) and -\&\fBEVP_PKEY_keygen\fR\|(3) as described in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7). -.PP -\&\fBDSA_generate_key()\fR expects \fBa\fR to contain \s-1DSA\s0 parameters. It generates -a new key pair and stores it in \fBa\->pub_key\fR and \fBa\->priv_key\fR. -.PP -The random generator must be seeded prior to calling \fBDSA_generate_key()\fR. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_generate_key()\fR returns 1 on success, 0 otherwise. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDSA_new\fR\|(3), \fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), -\&\fBDSA_generate_parameters_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This function was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_generate_parameters.3ossl b/openssl-install/share/man/man3/DSA_generate_parameters.3ossl deleted file mode 100644 index 2819fe6c..00000000 --- a/openssl-install/share/man/man3/DSA_generate_parameters.3ossl +++ /dev/null @@ -1,252 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_GENERATE_PARAMETERS 3ossl" -.TH DSA_GENERATE_PARAMETERS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_generate_parameters_ex, DSA_generate_parameters \- generate DSA parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& int DSA_generate_parameters_ex(DSA *dsa, int bits, -\& const unsigned char *seed, int seed_len, -\& int *counter_ret, unsigned long *h_ret, -\& BN_GENCB *cb); -.Ve -.PP -The following functions have been deprecated since OpenSSL 0.9.8, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& DSA *DSA_generate_parameters(int bits, unsigned char *seed, int seed_len, -\& int *counter_ret, unsigned long *h_ret, -\& void (*callback)(int, int, void *), void *cb_arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_paramgen_init\fR\|(3) and -\&\fBEVP_PKEY_keygen\fR\|(3) as described in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7). -.PP -\&\fBDSA_generate_parameters_ex()\fR generates primes p and q and a generator g -for use in the \s-1DSA\s0 and stores the result in \fBdsa\fR. -.PP -\&\fBbits\fR is the length of the prime p to be generated. -For lengths under 2048 bits, the length of q is 160 bits; for lengths -greater than or equal to 2048 bits, the length of q is set to 256 bits. -.PP -If \fBseed\fR is \s-1NULL,\s0 the primes will be generated at random. -If \fBseed_len\fR is less than the length of q, an error is returned. -.PP -\&\fBDSA_generate_parameters_ex()\fR places the iteration count in -*\fBcounter_ret\fR and a counter used for finding a generator in -*\fBh_ret\fR, unless these are \fB\s-1NULL\s0\fR. -.PP -A callback function may be used to provide feedback about the progress -of the key generation. If \fBcb\fR is not \fB\s-1NULL\s0\fR, it will be -called as shown below. For information on the \s-1BN_GENCB\s0 structure and the -BN_GENCB_call function discussed below, refer to -\&\fBBN_generate_prime\fR\|(3). -.PP -\&\fBDSA_generate_parameters()\fR is similar to \fBDSA_generate_parameters_ex()\fR but -expects an old-style callback function; see -\&\fBBN_generate_prime\fR\|(3) for information on the old-style callback. -.IP "\(bu" 2 -When a candidate for q is generated, \fBBN_GENCB_call(cb, 0, m++)\fR is called -(m is 0 for the first candidate). -.IP "\(bu" 2 -When a candidate for q has passed a test by trial division, -\&\fBBN_GENCB_call(cb, 1, \-1)\fR is called. -While a candidate for q is tested by Miller-Rabin primality tests, -\&\fBBN_GENCB_call(cb, 1, i)\fR is called in the outer loop -(once for each witness that confirms that the candidate may be prime); -i is the loop counter (starting at 0). -.IP "\(bu" 2 -When a prime q has been found, \fBBN_GENCB_call(cb, 2, 0)\fR and -\&\fBBN_GENCB_call(cb, 3, 0)\fR are called. -.IP "\(bu" 2 -Before a candidate for p (other than the first) is generated and tested, -\&\fBBN_GENCB_call(cb, 0, counter)\fR is called. -.IP "\(bu" 2 -When a candidate for p has passed the test by trial division, -\&\fBBN_GENCB_call(cb, 1, \-1)\fR is called. -While it is tested by the Miller-Rabin primality test, -\&\fBBN_GENCB_call(cb, 1, i)\fR is called in the outer loop -(once for each witness that confirms that the candidate may be prime). -i is the loop counter (starting at 0). -.IP "\(bu" 2 -When p has been found, \fBBN_GENCB_call(cb, 2, 1)\fR is called. -.IP "\(bu" 2 -When the generator has been found, \fBBN_GENCB_call(cb, 3, 1)\fR is called. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_generate_parameters_ex()\fR returns a 1 on success, or 0 otherwise. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.PP -\&\fBDSA_generate_parameters()\fR returns a pointer to the \s-1DSA\s0 structure or -\&\fB\s-1NULL\s0\fR if the parameter generation fails. -.SH "BUGS" -.IX Header "BUGS" -Seed lengths greater than 20 are not supported. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDSA_new\fR\|(3), \fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), -\&\fBDSA_free\fR\|(3), \fBBN_generate_prime\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBDSA_generate_parameters_ex()\fR was deprecated in OpenSSL 3.0. -.PP -\&\fBDSA_generate_parameters()\fR was deprecated in OpenSSL 0.9.8; use -\&\fBDSA_generate_parameters_ex()\fR instead. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_generate_parameters_ex.3ossl b/openssl-install/share/man/man3/DSA_generate_parameters_ex.3ossl deleted file mode 120000 index 103ca785..00000000 --- a/openssl-install/share/man/man3/DSA_generate_parameters_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_generate_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get0_engine.3ossl b/openssl-install/share/man/man3/DSA_get0_engine.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_get0_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get0_g.3ossl b/openssl-install/share/man/man3/DSA_get0_g.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_get0_g.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get0_key.3ossl b/openssl-install/share/man/man3/DSA_get0_key.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_get0_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get0_p.3ossl b/openssl-install/share/man/man3/DSA_get0_p.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_get0_p.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get0_pqg.3ossl b/openssl-install/share/man/man3/DSA_get0_pqg.3ossl deleted file mode 100644 index 2f1e3c42..00000000 --- a/openssl-install/share/man/man3/DSA_get0_pqg.3ossl +++ /dev/null @@ -1,255 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_GET0_PQG 3ossl" -.TH DSA_GET0_PQG 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_get0_pqg, DSA_set0_pqg, DSA_get0_key, DSA_set0_key, -DSA_get0_p, DSA_get0_q, DSA_get0_g, -DSA_get0_pub_key, DSA_get0_priv_key, -DSA_clear_flags, DSA_test_flags, DSA_set_flags, -DSA_get0_engine \- Routines for getting and -setting data in a DSA object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& void DSA_get0_pqg(const DSA *d, -\& const BIGNUM **p, const BIGNUM **q, const BIGNUM **g); -\& int DSA_set0_pqg(DSA *d, BIGNUM *p, BIGNUM *q, BIGNUM *g); -\& void DSA_get0_key(const DSA *d, -\& const BIGNUM **pub_key, const BIGNUM **priv_key); -\& int DSA_set0_key(DSA *d, BIGNUM *pub_key, BIGNUM *priv_key); -\& const BIGNUM *DSA_get0_p(const DSA *d); -\& const BIGNUM *DSA_get0_q(const DSA *d); -\& const BIGNUM *DSA_get0_g(const DSA *d); -\& const BIGNUM *DSA_get0_pub_key(const DSA *d); -\& const BIGNUM *DSA_get0_priv_key(const DSA *d); -\& void DSA_clear_flags(DSA *d, int flags); -\& int DSA_test_flags(const DSA *d, int flags); -\& void DSA_set_flags(DSA *d, int flags); -\& ENGINE *DSA_get0_engine(DSA *d); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_get_bn_param\fR\|(3). -.PP -A \s-1DSA\s0 object contains the parameters \fBp\fR, \fBq\fR and \fBg\fR. It also contains a -public key (\fBpub_key\fR) and (optionally) a private key (\fBpriv_key\fR). -.PP -The \fBp\fR, \fBq\fR and \fBg\fR parameters can be obtained by calling \fBDSA_get0_pqg()\fR. -If the parameters have not yet been set then \fB*p\fR, \fB*q\fR and \fB*g\fR will be set -to \s-1NULL.\s0 Otherwise they are set to pointers to their respective values. These -point directly to the internal representations of the values and therefore -should not be freed directly. -.PP -The \fBp\fR, \fBq\fR and \fBg\fR values can be set by calling \fBDSA_set0_pqg()\fR and passing -the new values for \fBp\fR, \fBq\fR and \fBg\fR as parameters to the function. Calling -this function transfers the memory management of the values to the \s-1DSA\s0 object, -and therefore the values that have been passed in should not be freed directly -after this function has been called. -.PP -To get the public and private key values use the \fBDSA_get0_key()\fR function. A -pointer to the public key will be stored in \fB*pub_key\fR, and a pointer to the -private key will be stored in \fB*priv_key\fR. Either may be \s-1NULL\s0 if they have not -been set yet, although if the private key has been set then the public key must -be. The values point to the internal representation of the public key and -private key values. This memory should not be freed directly. -.PP -The public and private key values can be set using \fBDSA_set0_key()\fR. The public -key must be non-NULL the first time this function is called on a given \s-1DSA\s0 -object. The private key may be \s-1NULL.\s0 On subsequent calls, either may be \s-1NULL,\s0 -which means the corresponding \s-1DSA\s0 field is left untouched. As for \fBDSA_set0_pqg()\fR -this function transfers the memory management of the key values to the \s-1DSA\s0 -object, and therefore they should not be freed directly after this function has -been called. -.PP -Any of the values \fBp\fR, \fBq\fR, \fBg\fR, \fBpriv_key\fR, and \fBpub_key\fR can also be -retrieved separately by the corresponding function \fBDSA_get0_p()\fR, \fBDSA_get0_q()\fR, -\&\fBDSA_get0_g()\fR, \fBDSA_get0_priv_key()\fR, and \fBDSA_get0_pub_key()\fR, respectively. -.PP -\&\fBDSA_set_flags()\fR sets the flags in the \fBflags\fR parameter on the \s-1DSA\s0 object. -Multiple flags can be passed in one go (bitwise ORed together). Any flags that -are already set are left set. \fBDSA_test_flags()\fR tests to see whether the flags -passed in the \fBflags\fR parameter are currently set in the \s-1DSA\s0 object. Multiple -flags can be tested in one go. All flags that are currently set are returned, or -zero if none of the flags are set. \fBDSA_clear_flags()\fR clears the specified flags -within the \s-1DSA\s0 object. -.PP -\&\fBDSA_get0_engine()\fR returns a handle to the \s-1ENGINE\s0 that has been set for this \s-1DSA\s0 -object, or \s-1NULL\s0 if no such \s-1ENGINE\s0 has been set. -.SH "NOTES" -.IX Header "NOTES" -Values retrieved with \fBDSA_get0_key()\fR are owned by the \s-1DSA\s0 object used -in the call and may therefore \fInot\fR be passed to \fBDSA_set0_key()\fR. If -needed, duplicate the received value using \fBBN_dup()\fR and pass the -duplicate. The same applies to \fBDSA_get0_pqg()\fR and \fBDSA_set0_pqg()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_set0_pqg()\fR and \fBDSA_set0_key()\fR return 1 on success or 0 on failure. -.PP -\&\fBDSA_test_flags()\fR returns the current state of the flags in the \s-1DSA\s0 object. -.PP -\&\fBDSA_get0_engine()\fR returns the \s-1ENGINE\s0 set for the \s-1DSA\s0 object or \s-1NULL\s0 if no \s-1ENGINE\s0 -has been set. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_get_bn_param\fR\|(3), -\&\fBDSA_new\fR\|(3), \fBDSA_new\fR\|(3), \fBDSA_generate_parameters\fR\|(3), \fBDSA_generate_key\fR\|(3), -\&\fBDSA_dup_DH\fR\|(3), \fBDSA_do_sign\fR\|(3), \fBDSA_set_method\fR\|(3), \fBDSA_SIG_new\fR\|(3), -\&\fBDSA_sign\fR\|(3), \fBDSA_size\fR\|(3), \fBDSA_meth_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 1.1.0 and deprecated in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_get0_priv_key.3ossl b/openssl-install/share/man/man3/DSA_get0_priv_key.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_get0_priv_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get0_pub_key.3ossl b/openssl-install/share/man/man3/DSA_get0_pub_key.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_get0_pub_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get0_q.3ossl b/openssl-install/share/man/man3/DSA_get0_q.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_get0_q.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get_default_method.3ossl b/openssl-install/share/man/man3/DSA_get_default_method.3ossl deleted file mode 120000 index ecd3ad8b..00000000 --- a/openssl-install/share/man/man3/DSA_get_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get_ex_data.3ossl b/openssl-install/share/man/man3/DSA_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/DSA_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_get_ex_new_index.3ossl b/openssl-install/share/man/man3/DSA_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/DSA_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_dup.3ossl b/openssl-install/share/man/man3/DSA_meth_dup.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_free.3ossl b/openssl-install/share/man/man3/DSA_meth_free.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get0_app_data.3ossl b/openssl-install/share/man/man3/DSA_meth_get0_app_data.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get0_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get0_name.3ossl b/openssl-install/share/man/man3/DSA_meth_get0_name.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_bn_mod_exp.3ossl b/openssl-install/share/man/man3/DSA_meth_get_bn_mod_exp.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_bn_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_finish.3ossl b/openssl-install/share/man/man3/DSA_meth_get_finish.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_flags.3ossl b/openssl-install/share/man/man3/DSA_meth_get_flags.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_init.3ossl b/openssl-install/share/man/man3/DSA_meth_get_init.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_keygen.3ossl b/openssl-install/share/man/man3/DSA_meth_get_keygen.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_mod_exp.3ossl b/openssl-install/share/man/man3/DSA_meth_get_mod_exp.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_paramgen.3ossl b/openssl-install/share/man/man3/DSA_meth_get_paramgen.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_paramgen.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_sign.3ossl b/openssl-install/share/man/man3/DSA_meth_get_sign.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_sign_setup.3ossl b/openssl-install/share/man/man3/DSA_meth_get_sign_setup.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_sign_setup.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_get_verify.3ossl b/openssl-install/share/man/man3/DSA_meth_get_verify.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_get_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_new.3ossl b/openssl-install/share/man/man3/DSA_meth_new.3ossl deleted file mode 100644 index 98d6d221..00000000 --- a/openssl-install/share/man/man3/DSA_meth_new.3ossl +++ /dev/null @@ -1,361 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_METH_NEW 3ossl" -.TH DSA_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_meth_new, DSA_meth_free, DSA_meth_dup, DSA_meth_get0_name, -DSA_meth_set1_name, DSA_meth_get_flags, DSA_meth_set_flags, -DSA_meth_get0_app_data, DSA_meth_set0_app_data, DSA_meth_get_sign, -DSA_meth_set_sign, DSA_meth_get_sign_setup, DSA_meth_set_sign_setup, -DSA_meth_get_verify, DSA_meth_set_verify, DSA_meth_get_mod_exp, -DSA_meth_set_mod_exp, DSA_meth_get_bn_mod_exp, DSA_meth_set_bn_mod_exp, -DSA_meth_get_init, DSA_meth_set_init, DSA_meth_get_finish, DSA_meth_set_finish, -DSA_meth_get_paramgen, DSA_meth_set_paramgen, DSA_meth_get_keygen, -DSA_meth_set_keygen \- Routines to build up DSA methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& DSA_METHOD *DSA_meth_new(const char *name, int flags); -\& -\& void DSA_meth_free(DSA_METHOD *dsam); -\& -\& DSA_METHOD *DSA_meth_dup(const DSA_METHOD *meth); -\& -\& const char *DSA_meth_get0_name(const DSA_METHOD *dsam); -\& int DSA_meth_set1_name(DSA_METHOD *dsam, const char *name); -\& -\& int DSA_meth_get_flags(const DSA_METHOD *dsam); -\& int DSA_meth_set_flags(DSA_METHOD *dsam, int flags); -\& -\& void *DSA_meth_get0_app_data(const DSA_METHOD *dsam); -\& int DSA_meth_set0_app_data(DSA_METHOD *dsam, void *app_data); -\& -\& DSA_SIG *(*DSA_meth_get_sign(const DSA_METHOD *dsam))(const unsigned char *, -\& int, DSA *); -\& int DSA_meth_set_sign(DSA_METHOD *dsam, DSA_SIG *(*sign)(const unsigned char *, -\& int, DSA *)); -\& -\& int (*DSA_meth_get_sign_setup(const DSA_METHOD *dsam))(DSA *, BN_CTX *,$ -\& BIGNUM **, BIGNUM **); -\& int DSA_meth_set_sign_setup(DSA_METHOD *dsam, int (*sign_setup)(DSA *, BN_CTX *, -\& BIGNUM **, BIGNUM **)); -\& -\& int (*DSA_meth_get_verify(const DSA_METHOD *dsam))(const unsigned char *, -\& int, DSA_SIG *, DSA *); -\& int DSA_meth_set_verify(DSA_METHOD *dsam, int (*verify)(const unsigned char *, -\& int, DSA_SIG *, DSA *)); -\& -\& int (*DSA_meth_get_mod_exp(const DSA_METHOD *dsam))(DSA *dsa, BIGNUM *rr, BIGNUM *a1, -\& BIGNUM *p1, BIGNUM *a2, BIGNUM *p2, -\& BIGNUM *m, BN_CTX *ctx, -\& BN_MONT_CTX *in_mont); -\& int DSA_meth_set_mod_exp(DSA_METHOD *dsam, int (*mod_exp)(DSA *dsa, BIGNUM *rr, -\& BIGNUM *a1, BIGNUM *p1, -\& BIGNUM *a2, BIGNUM *p2, -\& BIGNUM *m, BN_CTX *ctx, -\& BN_MONT_CTX *mont)); -\& -\& int (*DSA_meth_get_bn_mod_exp(const DSA_METHOD *dsam))(DSA *dsa, BIGNUM *r, BIGNUM *a, -\& const BIGNUM *p, const BIGNUM *m, -\& BN_CTX *ctx, BN_MONT_CTX *mont); -\& int DSA_meth_set_bn_mod_exp(DSA_METHOD *dsam, int (*bn_mod_exp)(DSA *dsa, -\& BIGNUM *r, -\& BIGNUM *a, -\& const BIGNUM *p, -\& const BIGNUM *m, -\& BN_CTX *ctx, -\& BN_MONT_CTX *mont)); -\& -\& int (*DSA_meth_get_init(const DSA_METHOD *dsam))(DSA *); -\& int DSA_meth_set_init(DSA_METHOD *dsam, int (*init)(DSA *)); -\& -\& int (*DSA_meth_get_finish(const DSA_METHOD *dsam))(DSA *); -\& int DSA_meth_set_finish(DSA_METHOD *dsam, int (*finish)(DSA *)); -\& -\& int (*DSA_meth_get_paramgen(const DSA_METHOD *dsam))(DSA *, int, -\& const unsigned char *, -\& int, int *, unsigned long *, -\& BN_GENCB *); -\& int DSA_meth_set_paramgen(DSA_METHOD *dsam, -\& int (*paramgen)(DSA *, int, const unsigned char *, -\& int, int *, unsigned long *, BN_GENCB *)); -\& -\& int (*DSA_meth_get_keygen(const DSA_METHOD *dsam))(DSA *); -\& int DSA_meth_set_keygen(DSA_METHOD *dsam, int (*keygen)(DSA *)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications and extension implementations should instead use the -\&\s-1OSSL_PROVIDER\s0 APIs. -.PP -The \fB\s-1DSA_METHOD\s0\fR type is a structure used for the provision of custom \s-1DSA\s0 -implementations. It provides a set of functions used by OpenSSL for the -implementation of the various \s-1DSA\s0 capabilities. -.PP -\&\fBDSA_meth_new()\fR creates a new \fB\s-1DSA_METHOD\s0\fR structure. It should be given a -unique \fBname\fR and a set of \fBflags\fR. The \fBname\fR should be a \s-1NULL\s0 terminated -string, which will be duplicated and stored in the \fB\s-1DSA_METHOD\s0\fR object. It is -the callers responsibility to free the original string. The flags will be used -during the construction of a new \fB\s-1DSA\s0\fR object based on this \fB\s-1DSA_METHOD\s0\fR. Any -new \fB\s-1DSA\s0\fR object will have those flags set by default. -.PP -\&\fBDSA_meth_dup()\fR creates a duplicate copy of the \fB\s-1DSA_METHOD\s0\fR object passed as a -parameter. This might be useful for creating a new \fB\s-1DSA_METHOD\s0\fR based on an -existing one, but with some differences. -.PP -\&\fBDSA_meth_free()\fR destroys a \fB\s-1DSA_METHOD\s0\fR structure and frees up any memory -associated with it. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBDSA_meth_get0_name()\fR will return a pointer to the name of this \s-1DSA_METHOD.\s0 This -is a pointer to the internal name string and so should not be freed by the -caller. \fBDSA_meth_set1_name()\fR sets the name of the \s-1DSA_METHOD\s0 to \fBname\fR. The -string is duplicated and the copy is stored in the \s-1DSA_METHOD\s0 structure, so the -caller remains responsible for freeing the memory associated with the name. -.PP -\&\fBDSA_meth_get_flags()\fR returns the current value of the flags associated with this -\&\s-1DSA_METHOD.\s0 \fBDSA_meth_set_flags()\fR provides the ability to set these flags. -.PP -The functions \fBDSA_meth_get0_app_data()\fR and \fBDSA_meth_set0_app_data()\fR provide the -ability to associate implementation specific data with the \s-1DSA_METHOD.\s0 It is -the application's responsibility to free this data before the \s-1DSA_METHOD\s0 is -freed via a call to \fBDSA_meth_free()\fR. -.PP -\&\fBDSA_meth_get_sign()\fR and \fBDSA_meth_set_sign()\fR get and set the function used for -creating a \s-1DSA\s0 signature respectively. This function will be -called in response to the application calling \fBDSA_do_sign()\fR (or \fBDSA_sign()\fR). The -parameters for the function have the same meaning as for \fBDSA_do_sign()\fR. -.PP -\&\fBDSA_meth_get_sign_setup()\fR and \fBDSA_meth_set_sign_setup()\fR get and set the function -used for precalculating the \s-1DSA\s0 signature values \fBk^\-1\fR and \fBr\fR. This function -will be called in response to the application calling \fBDSA_sign_setup()\fR. The -parameters for the function have the same meaning as for \fBDSA_sign_setup()\fR. -.PP -\&\fBDSA_meth_get_verify()\fR and \fBDSA_meth_set_verify()\fR get and set the function used -for verifying a \s-1DSA\s0 signature respectively. This function will be called in -response to the application calling \fBDSA_do_verify()\fR (or \fBDSA_verify()\fR). The -parameters for the function have the same meaning as for \fBDSA_do_verify()\fR. -.PP -\&\fBDSA_meth_get_mod_exp()\fR and \fBDSA_meth_set_mod_exp()\fR get and set the function used -for computing the following value: -.PP -.Vb 1 -\& rr = a1^p1 * a2^p2 mod m -.Ve -.PP -This function will be called by the default OpenSSL method during verification -of a \s-1DSA\s0 signature. The result is stored in the \fBrr\fR parameter. This function -may be \s-1NULL.\s0 -.PP -\&\fBDSA_meth_get_bn_mod_exp()\fR and \fBDSA_meth_set_bn_mod_exp()\fR get and set the function -used for computing the following value: -.PP -.Vb 1 -\& r = a ^ p mod m -.Ve -.PP -This function will be called by the default OpenSSL function for -\&\fBDSA_sign_setup()\fR. The result is stored in the \fBr\fR parameter. This function -may be \s-1NULL.\s0 -.PP -\&\fBDSA_meth_get_init()\fR and \fBDSA_meth_set_init()\fR get and set the function used -for creating a new \s-1DSA\s0 instance respectively. This function will be -called in response to the application calling \fBDSA_new()\fR (if the current default -\&\s-1DSA_METHOD\s0 is this one) or \fBDSA_new_method()\fR. The \fBDSA_new()\fR and \fBDSA_new_method()\fR -functions will allocate the memory for the new \s-1DSA\s0 object, and a pointer to this -newly allocated structure will be passed as a parameter to the function. This -function may be \s-1NULL.\s0 -.PP -\&\fBDSA_meth_get_finish()\fR and \fBDSA_meth_set_finish()\fR get and set the function used -for destroying an instance of a \s-1DSA\s0 object respectively. This function will be -called in response to the application calling \fBDSA_free()\fR. A pointer to the \s-1DSA\s0 -to be destroyed is passed as a parameter. The destroy function should be used -for \s-1DSA\s0 implementation specific clean up. The memory for the \s-1DSA\s0 itself should -not be freed by this function. This function may be \s-1NULL.\s0 -.PP -\&\fBDSA_meth_get_paramgen()\fR and \fBDSA_meth_set_paramgen()\fR get and set the function -used for generating \s-1DSA\s0 parameters respectively. This function will be called in -response to the application calling \fBDSA_generate_parameters_ex()\fR (or -\&\fBDSA_generate_parameters()\fR). The parameters for the function have the same -meaning as for \fBDSA_generate_parameters_ex()\fR. -.PP -\&\fBDSA_meth_get_keygen()\fR and \fBDSA_meth_set_keygen()\fR get and set the function -used for generating a new \s-1DSA\s0 key pair respectively. This function will be -called in response to the application calling \fBDSA_generate_key()\fR. The parameter -for the function has the same meaning as for \fBDSA_generate_key()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_meth_new()\fR and \fBDSA_meth_dup()\fR return the newly allocated \s-1DSA_METHOD\s0 object -or \s-1NULL\s0 on failure. -.PP -\&\fBDSA_meth_get0_name()\fR and \fBDSA_meth_get_flags()\fR return the name and flags -associated with the \s-1DSA_METHOD\s0 respectively. -.PP -All other DSA_meth_get_*() functions return the appropriate function pointer -that has been set in the \s-1DSA_METHOD,\s0 or \s-1NULL\s0 if no such pointer has yet been -set. -.PP -\&\fBDSA_meth_set1_name()\fR and all DSA_meth_set_*() functions return 1 on success or -0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDSA_new\fR\|(3), \fBDSA_new\fR\|(3), \fBDSA_generate_parameters\fR\|(3), \fBDSA_generate_key\fR\|(3), -\&\fBDSA_dup_DH\fR\|(3), \fBDSA_do_sign\fR\|(3), \fBDSA_set_method\fR\|(3), \fBDSA_SIG_new\fR\|(3), -\&\fBDSA_sign\fR\|(3), \fBDSA_size\fR\|(3), \fBDSA_get0_pqg\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were deprecated in OpenSSL 3.0. -.PP -The functions described here were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_meth_set0_app_data.3ossl b/openssl-install/share/man/man3/DSA_meth_set0_app_data.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set0_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set1_name.3ossl b/openssl-install/share/man/man3/DSA_meth_set1_name.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set1_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_bn_mod_exp.3ossl b/openssl-install/share/man/man3/DSA_meth_set_bn_mod_exp.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_bn_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_finish.3ossl b/openssl-install/share/man/man3/DSA_meth_set_finish.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_flags.3ossl b/openssl-install/share/man/man3/DSA_meth_set_flags.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_init.3ossl b/openssl-install/share/man/man3/DSA_meth_set_init.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_keygen.3ossl b/openssl-install/share/man/man3/DSA_meth_set_keygen.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_mod_exp.3ossl b/openssl-install/share/man/man3/DSA_meth_set_mod_exp.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_paramgen.3ossl b/openssl-install/share/man/man3/DSA_meth_set_paramgen.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_paramgen.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_sign.3ossl b/openssl-install/share/man/man3/DSA_meth_set_sign.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_sign_setup.3ossl b/openssl-install/share/man/man3/DSA_meth_set_sign_setup.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_sign_setup.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_meth_set_verify.3ossl b/openssl-install/share/man/man3/DSA_meth_set_verify.3ossl deleted file mode 120000 index 1d262e28..00000000 --- a/openssl-install/share/man/man3/DSA_meth_set_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_new.3ossl b/openssl-install/share/man/man3/DSA_new.3ossl deleted file mode 100644 index 12515183..00000000 --- a/openssl-install/share/man/man3/DSA_new.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_NEW 3ossl" -.TH DSA_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_new, DSA_free \- allocate and free DSA objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& DSA* DSA_new(void); -\& -\& void DSA_free(DSA *dsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_new\fR\|(3) and \fBEVP_PKEY_free\fR\|(3). -.PP -\&\fBDSA_new()\fR allocates and initializes a \fB\s-1DSA\s0\fR structure. It is equivalent to -calling DSA_new_method(\s-1NULL\s0). -.PP -\&\fBDSA_free()\fR frees the \fB\s-1DSA\s0\fR structure and its components. The values are -erased before the memory is returned to the system. -If \fBdsa\fR is \s-1NULL\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBDSA_new()\fR returns \fB\s-1NULL\s0\fR and sets an error -code that can be obtained by -\&\fBERR_get_error\fR\|(3). Otherwise it returns a pointer -to the newly allocated structure. -.PP -\&\fBDSA_free()\fR returns no value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_new\fR\|(3), \fBEVP_PKEY_free\fR\|(3), -\&\fBDSA_new\fR\|(3), \fBERR_get_error\fR\|(3), -\&\fBDSA_generate_parameters\fR\|(3), -\&\fBDSA_generate_key\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_new_method.3ossl b/openssl-install/share/man/man3/DSA_new_method.3ossl deleted file mode 120000 index ecd3ad8b..00000000 --- a/openssl-install/share/man/man3/DSA_new_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_print.3ossl b/openssl-install/share/man/man3/DSA_print.3ossl deleted file mode 120000 index f53ff3b2..00000000 --- a/openssl-install/share/man/man3/DSA_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_print_fp.3ossl b/openssl-install/share/man/man3/DSA_print_fp.3ossl deleted file mode 120000 index f53ff3b2..00000000 --- a/openssl-install/share/man/man3/DSA_print_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_security_bits.3ossl b/openssl-install/share/man/man3/DSA_security_bits.3ossl deleted file mode 120000 index fb300282..00000000 --- a/openssl-install/share/man/man3/DSA_security_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_set0_key.3ossl b/openssl-install/share/man/man3/DSA_set0_key.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_set0_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_set0_pqg.3ossl b/openssl-install/share/man/man3/DSA_set0_pqg.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_set0_pqg.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_set_default_method.3ossl b/openssl-install/share/man/man3/DSA_set_default_method.3ossl deleted file mode 120000 index ecd3ad8b..00000000 --- a/openssl-install/share/man/man3/DSA_set_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_set_ex_data.3ossl b/openssl-install/share/man/man3/DSA_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/DSA_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_set_flags.3ossl b/openssl-install/share/man/man3/DSA_set_flags.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_set_method.3ossl b/openssl-install/share/man/man3/DSA_set_method.3ossl deleted file mode 100644 index eca70303..00000000 --- a/openssl-install/share/man/man3/DSA_set_method.3ossl +++ /dev/null @@ -1,232 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_SET_METHOD 3ossl" -.TH DSA_SET_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_set_default_method, DSA_get_default_method, -DSA_set_method, DSA_new_method, DSA_OpenSSL \- select DSA method -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void DSA_set_default_method(const DSA_METHOD *meth); -\& -\& const DSA_METHOD *DSA_get_default_method(void); -\& -\& int DSA_set_method(DSA *dsa, const DSA_METHOD *meth); -\& -\& DSA *DSA_new_method(ENGINE *engine); -\& -\& const DSA_METHOD *DSA_OpenSSL(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should providers instead of method overrides. -.PP -A \fB\s-1DSA_METHOD\s0\fR specifies the functions that OpenSSL uses for \s-1DSA\s0 -operations. By modifying the method, alternative implementations -such as hardware accelerators may be used. \s-1IMPORTANT:\s0 See the \s-1NOTES\s0 section for -important information about how these \s-1DSA API\s0 functions are affected by the use -of \fB\s-1ENGINE\s0\fR \s-1API\s0 calls. -.PP -Initially, the default \s-1DSA_METHOD\s0 is the OpenSSL internal implementation, -as returned by \fBDSA_OpenSSL()\fR. -.PP -\&\fBDSA_set_default_method()\fR makes \fBmeth\fR the default method for all \s-1DSA\s0 -structures created later. -\&\fB\s-1NB\s0\fR: This is true only whilst no \s-1ENGINE\s0 has -been set as a default for \s-1DSA,\s0 so this function is no longer recommended. -This function is not thread-safe and should not be called at the same time -as other OpenSSL functions. -.PP -\&\fBDSA_get_default_method()\fR returns a pointer to the current default -\&\s-1DSA_METHOD.\s0 However, the meaningfulness of this result is dependent on -whether the \s-1ENGINE API\s0 is being used, so this function is no longer -recommended. -.PP -\&\fBDSA_set_method()\fR selects \fBmeth\fR to perform all operations using the key -\&\fBrsa\fR. This will replace the \s-1DSA_METHOD\s0 used by the \s-1DSA\s0 key and if the -previous method was supplied by an \s-1ENGINE,\s0 the handle to that \s-1ENGINE\s0 will -be released during the change. It is possible to have \s-1DSA\s0 keys that only -work with certain \s-1DSA_METHOD\s0 implementations (e.g. from an \s-1ENGINE\s0 module -that supports embedded hardware-protected keys), and in such cases -attempting to change the \s-1DSA_METHOD\s0 for the key can have unexpected -results. See \fBDSA_meth_new\fR\|(3) for information on constructing custom \s-1DSA_METHOD\s0 -objects; -.PP -\&\fBDSA_new_method()\fR allocates and initializes a \s-1DSA\s0 structure so that \fBengine\fR -will be used for the \s-1DSA\s0 operations. If \fBengine\fR is \s-1NULL,\s0 the default engine -for \s-1DSA\s0 operations is used, and if no default \s-1ENGINE\s0 is set, the \s-1DSA_METHOD\s0 -controlled by \fBDSA_set_default_method()\fR is used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_OpenSSL()\fR and \fBDSA_get_default_method()\fR return pointers to the respective -\&\fB\s-1DSA_METHOD\s0\fRs. -.PP -\&\fBDSA_set_default_method()\fR returns no value. -.PP -\&\fBDSA_set_method()\fR returns nonzero if the provided \fBmeth\fR was successfully set as -the method for \fBdsa\fR (including unloading the \s-1ENGINE\s0 handle if the previous -method was supplied by an \s-1ENGINE\s0). -.PP -\&\fBDSA_new_method()\fR returns \s-1NULL\s0 and sets an error code that can be -obtained by \fBERR_get_error\fR\|(3) if the allocation -fails. Otherwise it returns a pointer to the newly allocated structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDSA_new\fR\|(3), \fBDSA_new\fR\|(3), \fBDSA_meth_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_sign.3ossl b/openssl-install/share/man/man3/DSA_sign.3ossl deleted file mode 100644 index d4436208..00000000 --- a/openssl-install/share/man/man3/DSA_sign.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_SIGN 3ossl" -.TH DSA_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_sign, DSA_sign_setup, DSA_verify \- DSA signatures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int DSA_sign(int type, const unsigned char *dgst, int len, -\& unsigned char *sigret, unsigned int *siglen, DSA *dsa); -\& -\& int DSA_sign_setup(DSA *dsa, BN_CTX *ctx, BIGNUM **kinvp, BIGNUM **rp); -\& -\& int DSA_verify(int type, const unsigned char *dgst, int len, -\& unsigned char *sigbuf, int siglen, DSA *dsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_sign_init\fR\|(3), \fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify_init\fR\|(3) and \fBEVP_PKEY_verify\fR\|(3). -.PP -\&\fBDSA_sign()\fR computes a digital signature on the \fBlen\fR byte message -digest \fBdgst\fR using the private key \fBdsa\fR and places its \s-1ASN.1 DER\s0 -encoding at \fBsigret\fR. The length of the signature is places in -*\fBsiglen\fR. \fBsigret\fR must point to DSA_size(\fBdsa\fR) bytes of memory. -.PP -\&\fBDSA_sign_setup()\fR is defined only for backward binary compatibility and -should not be used. -Since OpenSSL 1.1.0 the \s-1DSA\s0 type is opaque and the output of -\&\fBDSA_sign_setup()\fR cannot be used anyway: calling this function will only -cause overhead, and does not affect the actual signature -(pre\-)computation. -.PP -\&\fBDSA_verify()\fR verifies that the signature \fBsigbuf\fR of size \fBsiglen\fR -matches a given message digest \fBdgst\fR of size \fBlen\fR. -\&\fBdsa\fR is the signer's public key. -.PP -The \fBtype\fR parameter is ignored. -.PP -The random generator must be seeded when \fBDSA_sign()\fR (or \fBDSA_sign_setup()\fR) -is called. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_sign()\fR and \fBDSA_sign_setup()\fR return 1 on success, 0 on error. -\&\fBDSA_verify()\fR returns 1 for a valid signature, 0 for an incorrect -signature and \-1 on error. The error codes can be obtained by -\&\fBERR_get_error\fR\|(3). -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1US\s0 Federal Information Processing Standard \s-1FIPS186\-4\s0 (Digital Signature -Standard, \s-1DSS\s0), \s-1ANSI X9.30\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDSA_new\fR\|(3), \fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), -\&\fBDSA_do_sign\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_sign_setup.3ossl b/openssl-install/share/man/man3/DSA_sign_setup.3ossl deleted file mode 120000 index ef9e04ac..00000000 --- a/openssl-install/share/man/man3/DSA_sign_setup.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_size.3ossl b/openssl-install/share/man/man3/DSA_size.3ossl deleted file mode 100644 index e602b6ec..00000000 --- a/openssl-install/share/man/man3/DSA_size.3ossl +++ /dev/null @@ -1,201 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DSA_SIZE 3ossl" -.TH DSA_SIZE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DSA_size, DSA_bits, DSA_security_bits \- get DSA signature size, key bits or security bits -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int DSA_bits(const DSA *dsa); -\& -\& int DSA_size(const DSA *dsa); -\& -\& int DSA_security_bits(const DSA *dsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_get_bits\fR\|(3), -\&\fBEVP_PKEY_get_security_bits\fR\|(3) and \fBEVP_PKEY_get_size\fR\|(3). -.PP -\&\fBDSA_bits()\fR returns the number of bits in key \fIdsa\fR: this is the number -of bits in the \fIp\fR parameter. -.PP -\&\fBDSA_size()\fR returns the maximum size of an \s-1ASN.1\s0 encoded \s-1DSA\s0 signature -for key \fIdsa\fR in bytes. It can be used to determine how much memory must -be allocated for a \s-1DSA\s0 signature. -.PP -\&\fBDSA_security_bits()\fR returns the number of security bits of the given \fIdsa\fR -key. See \fBBN_security_bits\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSA_security_bits()\fR returns the number of security bits in the key, or \-1 if -\&\fIdsa\fR doesn't hold any key parameters. -.PP -\&\fBDSA_bits()\fR returns the number of bits in the key, or \-1 if \fIdsa\fR doesn't -hold any key parameters. -.PP -\&\fBDSA_size()\fR returns the signature size in bytes, or \-1 if \fIdsa\fR doesn't -hold any key parameters. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_get_bits\fR\|(3), -\&\fBEVP_PKEY_get_security_bits\fR\|(3), -\&\fBEVP_PKEY_get_size\fR\|(3), -\&\fBDSA_new\fR\|(3), \fBDSA_sign\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DSA_test_flags.3ossl b/openssl-install/share/man/man3/DSA_test_flags.3ossl deleted file mode 120000 index 5c6e6694..00000000 --- a/openssl-install/share/man/man3/DSA_test_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_get0_pqg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSA_verify.3ossl b/openssl-install/share/man/man3/DSA_verify.3ossl deleted file mode 120000 index ef9e04ac..00000000 --- a/openssl-install/share/man/man3/DSA_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -DSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSAparams_dup.3ossl b/openssl-install/share/man/man3/DSAparams_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/DSAparams_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSAparams_print.3ossl b/openssl-install/share/man/man3/DSAparams_print.3ossl deleted file mode 120000 index f53ff3b2..00000000 --- a/openssl-install/share/man/man3/DSAparams_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DSAparams_print_fp.3ossl b/openssl-install/share/man/man3/DSAparams_print_fp.3ossl deleted file mode 120000 index f53ff3b2..00000000 --- a/openssl-install/share/man/man3/DSAparams_print_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLS_client_method.3ossl b/openssl-install/share/man/man3/DTLS_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLS_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLS_get_data_mtu.3ossl b/openssl-install/share/man/man3/DTLS_get_data_mtu.3ossl deleted file mode 100644 index c077b9a9..00000000 --- a/openssl-install/share/man/man3/DTLS_get_data_mtu.3ossl +++ /dev/null @@ -1,168 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DTLS_GET_DATA_MTU 3ossl" -.TH DTLS_GET_DATA_MTU 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DTLS_get_data_mtu \- Get maximum data payload size -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& size_t DTLS_get_data_mtu(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This function obtains the maximum data payload size for the established -\&\s-1DTLS\s0 connection \fBssl\fR, based on the \s-1DTLS\s0 record \s-1MTU\s0 and the overhead -of the \s-1DTLS\s0 record header, encryption and authentication currently in use. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns the maximum data payload size on success, or 0 on failure. -.SH "HISTORY" -.IX Header "HISTORY" -The \fBDTLS_get_data_mtu()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DTLS_method.3ossl b/openssl-install/share/man/man3/DTLS_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLS_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLS_server_method.3ossl b/openssl-install/share/man/man3/DTLS_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLS_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLS_set_timer_cb.3ossl b/openssl-install/share/man/man3/DTLS_set_timer_cb.3ossl deleted file mode 100644 index f42f3517..00000000 --- a/openssl-install/share/man/man3/DTLS_set_timer_cb.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DTLS_SET_TIMER_CB 3ossl" -.TH DTLS_SET_TIMER_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DTLS_timer_cb, -DTLS_set_timer_cb -\&\- Set callback for controlling DTLS timer duration -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef unsigned int (*DTLS_timer_cb)(SSL *s, unsigned int timer_us); -\& -\& void DTLS_set_timer_cb(SSL *s, DTLS_timer_cb cb); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This function sets an optional callback function for controlling the -timeout interval on the \s-1DTLS\s0 protocol. The callback function will be -called by \s-1DTLS\s0 for every new \s-1DTLS\s0 packet that is sent. -.PP -The callback should return the timeout interval in micro seconds. -.PP -The \fItimer_us\fR parameter of the callback is the last set timeout -interval returned. On the first invocation of the callback, -this value will be 0. -.PP -At the beginning of the connection, if no timeout callback has been -set via \fBDTLS_set_timer_cb()\fR, the default timeout value is 1 second. -For all subsequent timeouts, the default behavior is to double the -duration up to a maximum of 1 minute. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns void. -.SH "HISTORY" -.IX Header "HISTORY" -The \fBDTLS_set_timer_cb()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DTLS_timer_cb.3ossl b/openssl-install/share/man/man3/DTLS_timer_cb.3ossl deleted file mode 120000 index dac2ba8b..00000000 --- a/openssl-install/share/man/man3/DTLS_timer_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -DTLS_set_timer_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLSv1_2_client_method.3ossl b/openssl-install/share/man/man3/DTLSv1_2_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLSv1_2_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLSv1_2_method.3ossl b/openssl-install/share/man/man3/DTLSv1_2_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLSv1_2_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLSv1_2_server_method.3ossl b/openssl-install/share/man/man3/DTLSv1_2_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLSv1_2_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLSv1_client_method.3ossl b/openssl-install/share/man/man3/DTLSv1_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLSv1_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLSv1_get_timeout.3ossl b/openssl-install/share/man/man3/DTLSv1_get_timeout.3ossl deleted file mode 100644 index f4650bb4..00000000 --- a/openssl-install/share/man/man3/DTLSv1_get_timeout.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DTLSV1_GET_TIMEOUT 3ossl" -.TH DTLSV1_GET_TIMEOUT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DTLSv1_get_timeout \- determine when a DTLS or QUIC SSL object next needs a -timeout event to be handled -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int DTLSv1_get_timeout(SSL *s, struct timeval *tv); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBDTLSv1_get_timeout()\fR can be used on a \s-1DTLS\s0 or \s-1QUIC SSL\s0 object to determine when -the \s-1SSL\s0 object next needs to perform internal processing due to the passage of -time. -.PP -Calling \fBDTLSv1_get_timeout()\fR results in \fI*tv\fR being written with an amount of -time left before the \s-1SSL\s0 object needs have \fBDTLSv1_handle_timeout()\fR called on it. -If the \s-1SSL\s0 object needs to be ticked immediately, \fI*tv\fR is zeroed and the -function succeeds, returning 1. If no timeout is currently active, this function -returns 0. -.PP -This function is only applicable to \s-1DTLS\s0 and \s-1QUIC\s0 objects. It fails if called on -any other kind of \s-1SSL\s0 object. -.PP -Note that the value output by a call to \fBDTLSv1_get_timeout()\fR may change as a -result of other calls to the \s-1SSL\s0 object. -.PP -Once the timeout expires, \fBDTLSv1_handle_timeout()\fR should be called to handle any -internal processing which is due; for more information, see -\&\fBDTLSv1_handle_timeout\fR\|(3). -.PP -\&\fBSSL_get_event_timeout\fR\|(3) supersedes all use cases for this this function and -may be used instead of it. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -On success, writes a duration to \fI*tv\fR and returns 1. -.PP -Returns 0 on failure, or if no timeout is currently active. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDTLSv1_handle_timeout\fR\|(3), \fBSSL_get_event_timeout\fR\|(3), \fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DTLSv1_handle_timeout.3ossl b/openssl-install/share/man/man3/DTLSv1_handle_timeout.3ossl deleted file mode 100644 index cd1802f3..00000000 --- a/openssl-install/share/man/man3/DTLSv1_handle_timeout.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DTLSV1_HANDLE_TIMEOUT 3ossl" -.TH DTLSV1_HANDLE_TIMEOUT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DTLSv1_handle_timeout \- handle a pending timeout event for a DTLS or QUIC SSL -object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int DTLSv1_handle_timeout(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBDTLSv1_handle_timeout()\fR handles any timeout events which have become pending -on a \s-1DTLS\s0 or \s-1QUIC SSL\s0 object. -.PP -Use \fBDTLSv1_get_timeout\fR\|(3) or \fBSSL_get_event_timeout\fR\|(3) to determine -when to call \fBDTLSv1_handle_timeout()\fR. -.PP -This function is only applicable to \s-1DTLS\s0 or \s-1QUIC SSL\s0 objects. It returns 0 if -called on any other kind of \s-1SSL\s0 object. -.PP -\&\fBSSL_handle_events\fR\|(3) supersedes all use cases for this function and may -be used instead of it. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 if there was a pending timeout event and it was handled successfully. -.PP -Returns 0 if there was no pending timeout event, or if the \s-1SSL\s0 object is not a -\&\s-1DTLS\s0 or \s-1QUIC\s0 object. -.PP -Returns \-1 if there was a pending timeout event but it could not be handled -successfully. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBDTLSv1_get_timeout\fR\|(3), \fBSSL_handle_events\fR\|(3), \fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DTLSv1_listen.3ossl b/openssl-install/share/man/man3/DTLSv1_listen.3ossl deleted file mode 100644 index 8a50f194..00000000 --- a/openssl-install/share/man/man3/DTLSv1_listen.3ossl +++ /dev/null @@ -1,286 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DTLSV1_LISTEN 3ossl" -.TH DTLSV1_LISTEN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_stateless, -DTLSv1_listen -\&\- Statelessly listen for incoming connections -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_stateless(SSL *s); -\& int DTLSv1_listen(SSL *ssl, BIO_ADDR *peer); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_stateless()\fR statelessly listens for new incoming TLSv1.3 connections. -\&\fBDTLSv1_listen()\fR statelessly listens for new incoming \s-1DTLS\s0 connections. If a -ClientHello is received that does not contain a cookie, then they respond with a -request for a new ClientHello that does contain a cookie. If a ClientHello is -received with a cookie that is verified then the function returns in order to -enable the handshake to be completed (for example by using \fBSSL_accept()\fR). -.SH "NOTES" -.IX Header "NOTES" -Some transport protocols (such as \s-1UDP\s0) can be susceptible to amplification -attacks. Unlike \s-1TCP\s0 there is no initial connection setup in \s-1UDP\s0 that -validates that the client can actually receive messages on its advertised source -address. An attacker could forge its source \s-1IP\s0 address and then send handshake -initiation messages to the server. The server would then send its response to -the forged source \s-1IP.\s0 If the response messages are larger than the original -message then the amplification attack has succeeded. -.PP -If \s-1DTLS\s0 is used over \s-1UDP\s0 (or any datagram based protocol that does not validate -the source \s-1IP\s0) then it is susceptible to this type of attack. TLSv1.3 is -designed to operate over a stream-based transport protocol (such as \s-1TCP\s0). -If \s-1TCP\s0 is being used then there is no need to use \fBSSL_stateless()\fR. However, some -stream-based transport protocols (e.g. \s-1QUIC\s0) may not validate the source -address. In this case a TLSv1.3 application would be susceptible to this attack. -.PP -As a countermeasure to this issue TLSv1.3 and \s-1DTLS\s0 include a stateless cookie -mechanism. The idea is that when a client attempts to connect to a server it -sends a ClientHello message. The server responds with a HelloRetryRequest (in -TLSv1.3) or a HelloVerifyRequest (in \s-1DTLS\s0) which contains a unique cookie. The -client then resends the ClientHello, but this time includes the cookie in the -message thus proving that the client is capable of receiving messages sent to -that address. All of this can be done by the server without allocating any -state, and thus without consuming expensive resources. -.PP -OpenSSL implements this capability via the \fBSSL_stateless()\fR and \fBDTLSv1_listen()\fR -functions. The \fBssl\fR parameter should be a newly allocated \s-1SSL\s0 object with its -read and write BIOs set, in the same way as might be done for a call to -\&\fBSSL_accept()\fR. Typically, for \s-1DTLS,\s0 the read \s-1BIO\s0 will be in an \*(L"unconnected\*(R" -state and thus capable of receiving messages from any peer. -.PP -When a ClientHello is received that contains a cookie that has been verified, -then these functions will return with the \fBssl\fR parameter updated into a state -where the handshake can be continued by a call to (for example) \fBSSL_accept()\fR. -Additionally, for \fBDTLSv1_listen()\fR, the \fB\s-1BIO_ADDR\s0\fR pointed to by \fBpeer\fR will be -filled in with details of the peer that sent the ClientHello. If the underlying -\&\s-1BIO\s0 is unable to obtain the \fB\s-1BIO_ADDR\s0\fR of the peer (for example because the \s-1BIO\s0 -does not support this), then \fB*peer\fR will be cleared and the family set to -\&\s-1AF_UNSPEC.\s0 Typically user code is expected to \*(L"connect\*(R" the underlying socket to -the peer and continue the handshake in a connected state. -.PP -Warning: It is essential that the calling code connects the underlying socket to -the peer after making use of \fBDTLSv1_listen()\fR. In the typical case where -\&\fBBIO_s_datagram\fR\|(3) is used, the peer address is updated when receiving a -datagram on an unconnected socket. If the socket is not connected, it can -receive datagrams from any host on the network, which will cause subsequent -outgoing datagrams transmitted by \s-1DTLS\s0 to be transmitted to that host. In other -words, failing to call \fBBIO_connect()\fR or a similar OS-specific function on a -socket means that any host on the network can cause outgoing \s-1DTLS\s0 traffic to be -redirected to it by sending a datagram to the socket in question. This does not -break the cryptographic protections of \s-1DTLS\s0 but may facilitate a -denial-of-service attack or allow unencrypted information in the \s-1DTLS\s0 handshake -to be learned by an attacker. This is due to the historical design of -\&\fBBIO_s_datagram\fR\|(3); see \fBBIO_s_datagram\fR\|(3) for details on this issue. -.PP -Once a socket has been connected, \fBBIO_ctrl_set_connected\fR\|(3) should be used to -inform the \s-1BIO\s0 that the socket is to be used in connected mode. -.PP -Prior to calling \fBDTLSv1_listen()\fR user code must ensure that cookie generation -and verification callbacks have been set up using -\&\fBSSL_CTX_set_cookie_generate_cb\fR\|(3) and \fBSSL_CTX_set_cookie_verify_cb\fR\|(3) -respectively. For \fBSSL_stateless()\fR, \fBSSL_CTX_set_stateless_cookie_generate_cb\fR\|(3) -and \fBSSL_CTX_set_stateless_cookie_verify_cb\fR\|(3) must be used instead. -.PP -Since \fBDTLSv1_listen()\fR operates entirely statelessly whilst processing incoming -ClientHellos it is unable to process fragmented messages (since this would -require the allocation of state). An implication of this is that \fBDTLSv1_listen()\fR -\&\fBonly\fR supports ClientHellos that fit inside a single datagram. -.PP -For \fBSSL_stateless()\fR if an entire ClientHello message cannot be read without the -\&\*(L"read\*(R" \s-1BIO\s0 becoming empty then the \fBSSL_stateless()\fR call will fail. It is the -application's responsibility to ensure that data read from the \*(L"read\*(R" \s-1BIO\s0 during -a single \fBSSL_stateless()\fR call is all from the same peer. -.PP -\&\fBSSL_stateless()\fR will fail (with a 0 return value) if some \s-1TLS\s0 version less than -TLSv1.3 is used. -.PP -Both \fBSSL_stateless()\fR and \fBDTLSv1_listen()\fR will clear the error queue when they -start. -.PP -\&\fBSSL_stateless()\fR cannot be used with \s-1QUIC SSL\s0 objects and returns an error if -called on such an object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -For \fBSSL_stateless()\fR a return value of 1 indicates success and the \fBssl\fR object -will be set up ready to continue the handshake. A return value of 0 or \-1 -indicates failure. If the value is 0 then a HelloRetryRequest was sent. A value -of \-1 indicates any other error. User code may retry the \fBSSL_stateless()\fR call. -.PP -For \fBDTLSv1_listen()\fR a return value of >= 1 indicates success. The \fBssl\fR object -will be set up ready to continue the handshake. the \fBpeer\fR value will also be -filled in. -.PP -A return value of 0 indicates a non-fatal error. This could (for -example) be because of nonblocking \s-1IO,\s0 or some invalid message having been -received from a peer. Errors may be placed on the OpenSSL error queue with -further information if appropriate. Typically user code is expected to retry the -call to \fBDTLSv1_listen()\fR in the event of a non-fatal error. -.PP -A return value of <0 indicates a fatal error. This could (for example) be -because of a failure to allocate sufficient memory for the operation. -.PP -For \fBDTLSv1_listen()\fR, prior to OpenSSL 1.1.0, fatal and non-fatal errors both -produce return codes <= 0 (in typical implementations user code treats all -errors as non-fatal), whilst return codes >0 indicate success. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_set_cookie_generate_cb\fR\|(3), \fBSSL_CTX_set_cookie_verify_cb\fR\|(3), -\&\fBSSL_CTX_set_stateless_cookie_generate_cb\fR\|(3), -\&\fBSSL_CTX_set_stateless_cookie_verify_cb\fR\|(3), \fBSSL_get_error\fR\|(3), -\&\fBSSL_accept\fR\|(3), \fBssl\fR\|(7), \fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_stateless()\fR function was added in OpenSSL 1.1.1. -.PP -The \fBDTLSv1_listen()\fR return codes were clarified in OpenSSL 1.1.0. -The type of \*(L"peer\*(R" also changed in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/DTLSv1_method.3ossl b/openssl-install/share/man/man3/DTLSv1_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLSv1_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/DTLSv1_server_method.3ossl b/openssl-install/share/man/man3/DTLSv1_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/DTLSv1_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_SIG_free.3ossl b/openssl-install/share/man/man3/ECDSA_SIG_free.3ossl deleted file mode 120000 index dd22a746..00000000 --- a/openssl-install/share/man/man3/ECDSA_SIG_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_SIG_get0.3ossl b/openssl-install/share/man/man3/ECDSA_SIG_get0.3ossl deleted file mode 120000 index dd22a746..00000000 --- a/openssl-install/share/man/man3/ECDSA_SIG_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_SIG_get0_r.3ossl b/openssl-install/share/man/man3/ECDSA_SIG_get0_r.3ossl deleted file mode 120000 index dd22a746..00000000 --- a/openssl-install/share/man/man3/ECDSA_SIG_get0_r.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_SIG_get0_s.3ossl b/openssl-install/share/man/man3/ECDSA_SIG_get0_s.3ossl deleted file mode 120000 index dd22a746..00000000 --- a/openssl-install/share/man/man3/ECDSA_SIG_get0_s.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_SIG_new.3ossl b/openssl-install/share/man/man3/ECDSA_SIG_new.3ossl deleted file mode 100644 index 19432c46..00000000 --- a/openssl-install/share/man/man3/ECDSA_SIG_new.3ossl +++ /dev/null @@ -1,281 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ECDSA_SIG_NEW 3ossl" -.TH ECDSA_SIG_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ECDSA_SIG_new, ECDSA_SIG_free, -ECDSA_SIG_get0, ECDSA_SIG_get0_r, ECDSA_SIG_get0_s, ECDSA_SIG_set0 -\&\- Functions for creating, destroying and manipulating ECDSA_SIG objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ECDSA_SIG *ECDSA_SIG_new(void); -\& void ECDSA_SIG_free(ECDSA_SIG *sig); -\& void ECDSA_SIG_get0(const ECDSA_SIG *sig, const BIGNUM **pr, const BIGNUM **ps); -\& const BIGNUM *ECDSA_SIG_get0_r(const ECDSA_SIG *sig); -\& const BIGNUM *ECDSA_SIG_get0_s(const ECDSA_SIG *sig); -\& int ECDSA_SIG_set0(ECDSA_SIG *sig, BIGNUM *r, BIGNUM *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1ECDSA_SIG\s0\fR is an opaque structure consisting of two BIGNUMs for the -\&\fIr\fR and \fIs\fR value of an Elliptic Curve Digital Signature Algorithm (\s-1ECDSA\s0) signature -(see \s-1FIPS186\-4\s0 or X9.62). -The \fB\s-1ECDSA_SIG\s0\fR object was mainly used by the deprecated low level functions described in -\&\fBECDSA_sign\fR\|(3), it is still required in order to be able to set or get the values of -\&\fIr\fR and \fIs\fR into or from a signature. This is mainly used for testing purposes as shown -in the \*(L"\s-1EXAMPLES\*(R"\s0. -.PP -\&\fBECDSA_SIG_new()\fR allocates an empty \fB\s-1ECDSA_SIG\s0\fR structure. -Note: before OpenSSL 1.1.0, the \fIr\fR and \fIs\fR components were initialised. -.PP -\&\fBECDSA_SIG_free()\fR frees the \fB\s-1ECDSA_SIG\s0\fR structure \fIsig\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBECDSA_SIG_get0()\fR returns internal pointers the \fIr\fR and \fIs\fR values contained -in \fIsig\fR and stores them in \fI*pr\fR and \fI*ps\fR, respectively. -The pointer \fIpr\fR or \fIps\fR can be \s-1NULL,\s0 in which case the corresponding value -is not returned. -.PP -The values \fIr\fR, \fIs\fR can also be retrieved separately by the corresponding -function \fBECDSA_SIG_get0_r()\fR and \fBECDSA_SIG_get0_s()\fR, respectively. -.PP -Non-NULL \fIr\fR and \fIs\fR values can be set on the \fIsig\fR by calling -\&\fBECDSA_SIG_set0()\fR. Calling this function transfers the memory management of the -values to the \fB\s-1ECDSA_SIG\s0\fR object, and therefore the values that have been -passed in should not be freed by the caller. -.PP -See \fBi2d_ECDSA_SIG\fR\|(3) and \fBd2i_ECDSA_SIG\fR\|(3) for information about encoding -and decoding \s-1ECDSA\s0 signatures to/from \s-1DER.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBECDSA_SIG_new()\fR returns \s-1NULL\s0 if the allocation fails. -.PP -\&\fBECDSA_SIG_set0()\fR returns 1 on success or 0 on failure. -.PP -\&\fBECDSA_SIG_get0_r()\fR and \fBECDSA_SIG_get0_s()\fR return the corresponding value, -or \s-1NULL\s0 if it is unset. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Extract signature \fIr\fR and \fIs\fR values from a \s-1ECDSA\s0 \fIsignature\fR -of size \fIsignaturelen\fR: -.PP -.Vb 2 -\& ECDSA_SIG *obj; -\& const BIGNUM *r, *s; -\& -\& /* Load a signature into the ECDSA_SIG object */ -\& obj = d2i_ECDSA_SIG(NULL, &signature, signaturelen); -\& if (obj == NULL) -\& /* error */ -\& -\& r = ECDSA_SIG_get0_r(obj); -\& s = ECDSA_SIG_get0_s(obj); -\& if (r == NULL || s == NULL) -\& /* error */ -\& -\& /* Use BN_bn2binpad() here to convert to r and s into byte arrays */ -\& -\& /* -\& * Do not try to access I or I after calling ECDSA_SIG_free(), -\& * as they are both freed by this call. -\& */ -\& ECDSA_SIG_free(obj); -.Ve -.PP -Convert \fIr\fR and \fIs\fR byte arrays into an \s-1ECDSA_SIG\s0 \fIsignature\fR of -size \fIsignaturelen\fR: -.PP -.Vb 4 -\& ECDSA_SIG *obj = NULL; -\& unsigned char *signature = NULL; -\& size_t signaturelen; -\& BIGNUM *rbn = NULL, *sbn = NULL; -\& -\& obj = ECDSA_SIG_new(); -\& if (obj == NULL) -\& /* error */ -\& rbn = BN_bin2bn(r, rlen, NULL); -\& sbn = BN_bin2bn(s, slen, NULL); -\& if (rbn == NULL || sbn == NULL) -\& /* error */ -\& -\& if (!ECDSA_SIG_set0(obj, rbn, sbn)) -\& /* error */ -\& /* Set these to NULL since they are now owned by obj */ -\& rbn = sbn = NULL; -\& -\& signaturelen = i2d_ECDSA_SIG(obj, &signature); -\& if (signaturelen <= 0) -\& /* error */ -\& -\& /* -\& * This signature could now be passed to L -\& * or L -\& */ -\& -\& BN_free(rbn); -\& BN_free(sbn); -\& OPENSSL_free(signature); -\& ECDSA_SIG_free(obj); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ANSI X9.62, -US\s0 Federal Information Processing Standard \s-1FIPS186\-4\s0 -(Digital Signature Standard, \s-1DSS\s0) -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEC_KEY_new\fR\|(3), -\&\fBEVP_DigestSignInit\fR\|(3), -\&\fBEVP_DigestVerifyInit\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3) -\&\fBi2d_ECDSA_SIG\fR\|(3), -\&\fBd2i_ECDSA_SIG\fR\|(3), -\&\fBECDSA_sign\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ECDSA_SIG_set0.3ossl b/openssl-install/share/man/man3/ECDSA_SIG_set0.3ossl deleted file mode 120000 index dd22a746..00000000 --- a/openssl-install/share/man/man3/ECDSA_SIG_set0.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_SIG_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_do_sign.3ossl b/openssl-install/share/man/man3/ECDSA_do_sign.3ossl deleted file mode 120000 index a01845fb..00000000 --- a/openssl-install/share/man/man3/ECDSA_do_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_do_sign_ex.3ossl b/openssl-install/share/man/man3/ECDSA_do_sign_ex.3ossl deleted file mode 120000 index a01845fb..00000000 --- a/openssl-install/share/man/man3/ECDSA_do_sign_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_do_verify.3ossl b/openssl-install/share/man/man3/ECDSA_do_verify.3ossl deleted file mode 120000 index a01845fb..00000000 --- a/openssl-install/share/man/man3/ECDSA_do_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_sign.3ossl b/openssl-install/share/man/man3/ECDSA_sign.3ossl deleted file mode 100644 index 64781f1b..00000000 --- a/openssl-install/share/man/man3/ECDSA_sign.3ossl +++ /dev/null @@ -1,329 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ECDSA_SIGN 3ossl" -.TH ECDSA_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ECDSA_size, ECDSA_sign, ECDSA_do_sign, -ECDSA_verify, ECDSA_do_verify, ECDSA_sign_setup, ECDSA_sign_ex, -ECDSA_do_sign_ex \- deprecated low\-level elliptic curve digital signature algorithm -(ECDSA) functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int ECDSA_size(const EC_KEY *eckey); -\& -\& int ECDSA_sign(int type, const unsigned char *dgst, int dgstlen, -\& unsigned char *sig, unsigned int *siglen, EC_KEY *eckey); -\& ECDSA_SIG *ECDSA_do_sign(const unsigned char *dgst, int dgst_len, -\& EC_KEY *eckey); -\& -\& int ECDSA_verify(int type, const unsigned char *dgst, int dgstlen, -\& const unsigned char *sig, int siglen, EC_KEY *eckey); -\& int ECDSA_do_verify(const unsigned char *dgst, int dgst_len, -\& const ECDSA_SIG *sig, EC_KEY* eckey); -\& -\& ECDSA_SIG *ECDSA_do_sign_ex(const unsigned char *dgst, int dgstlen, -\& const BIGNUM *kinv, const BIGNUM *rp, -\& EC_KEY *eckey); -\& int ECDSA_sign_setup(EC_KEY *eckey, BN_CTX *ctx, BIGNUM **kinv, BIGNUM **rp); -\& int ECDSA_sign_ex(int type, const unsigned char *dgst, int dgstlen, -\& unsigned char *sig, unsigned int *siglen, -\& const BIGNUM *kinv, const BIGNUM *rp, EC_KEY *eckey); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -See \fBECDSA_SIG_new\fR\|(3) for a description of the \fB\s-1ECDSA_SIG\s0\fR object. -.PP -See \fBi2d_ECDSA_SIG\fR\|(3) and \fBd2i_ECDSA_SIG\fR\|(3) for information about encoding -and decoding \s-1ECDSA\s0 signatures to/from \s-1DER.\s0 -.PP -All of the functions described below are deprecated. Applications should -use the higher level \fB\s-1EVP\s0\fR interface such as \fBEVP_DigestSignInit\fR\|(3) -or \fBEVP_DigestVerifyInit\fR\|(3) instead. -.PP -\&\fBECDSA_size()\fR returns the maximum length of a \s-1DER\s0 encoded \s-1ECDSA\s0 signature -created with the private \s-1EC\s0 key \fIeckey\fR. To obtain the actual signature -size use \fBEVP_PKEY_sign\fR\|(3) with a \s-1NULL\s0 \fIsig\fR parameter. -.PP -\&\fBECDSA_sign()\fR computes a digital signature of the \fIdgstlen\fR bytes hash value -\&\fIdgst\fR using the private \s-1EC\s0 key \fIeckey\fR. The \s-1DER\s0 encoded signatures is -stored in \fIsig\fR and its length is returned in \fIsiglen\fR. Note: \fIsig\fR must -point to ECDSA_size(eckey) bytes of memory. The parameter \fItype\fR is currently -ignored. \fBECDSA_sign()\fR is wrapper function for \fBECDSA_sign_ex()\fR with \fIkinv\fR -and \fIrp\fR set to \s-1NULL.\s0 -.PP -\&\fBECDSA_do_sign()\fR is similar to \fBECDSA_sign()\fR except the signature is returned -as a newly allocated \fB\s-1ECDSA_SIG\s0\fR structure (or \s-1NULL\s0 on error). \fBECDSA_do_sign()\fR -is a wrapper function for \fBECDSA_do_sign_ex()\fR with \fIkinv\fR and \fIrp\fR set to -\&\s-1NULL.\s0 -.PP -\&\fBECDSA_verify()\fR verifies that the signature in \fIsig\fR of size \fIsiglen\fR is a -valid \s-1ECDSA\s0 signature of the hash value \fIdgst\fR of size \fIdgstlen\fR using the -public key \fIeckey\fR. The parameter \fItype\fR is ignored. -.PP -\&\fBECDSA_do_verify()\fR is similar to \fBECDSA_verify()\fR except the signature is -presented in the form of a pointer to an \fB\s-1ECDSA_SIG\s0\fR structure. -.PP -The remaining functions utilise the internal \fIkinv\fR and \fIr\fR values used -during signature computation. Most applications will never need to call these -and some external \s-1ECDSA ENGINE\s0 implementations may not support them at all if -either \fIkinv\fR or \fIr\fR is not \s-1NULL.\s0 -.PP -\&\fBECDSA_sign_setup()\fR may be used to precompute parts of the signing operation. -\&\fIeckey\fR is the private \s-1EC\s0 key and \fIctx\fR is a pointer to \fB\s-1BN_CTX\s0\fR structure -(or \s-1NULL\s0). The precomputed values or returned in \fIkinv\fR and \fIrp\fR and can be -used in a later call to \fBECDSA_sign_ex()\fR or \fBECDSA_do_sign_ex()\fR. -.PP -\&\fBECDSA_sign_ex()\fR computes a digital signature of the \fIdgstlen\fR bytes hash value -\&\fIdgst\fR using the private \s-1EC\s0 key \fIeckey\fR and the optional pre-computed values -\&\fIkinv\fR and \fIrp\fR. The \s-1DER\s0 encoded signature is stored in \fIsig\fR and its -length is returned in \fIsiglen\fR. Note: \fIsig\fR must point to ECDSA_size(eckey) -bytes of memory. The parameter \fItype\fR is ignored. -.PP -\&\fBECDSA_do_sign_ex()\fR is similar to \fBECDSA_sign_ex()\fR except the signature is -returned as a newly allocated \fB\s-1ECDSA_SIG\s0\fR structure (or \s-1NULL\s0 on error). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBECDSA_size()\fR returns the maximum length signature or 0 on error. -.PP -\&\fBECDSA_sign()\fR, \fBECDSA_sign_ex()\fR and \fBECDSA_sign_setup()\fR return 1 if successful -or 0 on error. -.PP -\&\fBECDSA_do_sign()\fR and \fBECDSA_do_sign_ex()\fR return a pointer to an allocated -\&\fB\s-1ECDSA_SIG\s0\fR structure or \s-1NULL\s0 on error. -.PP -\&\fBECDSA_verify()\fR and \fBECDSA_do_verify()\fR return 1 for a valid -signature, 0 for an invalid signature and \-1 on error. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Creating an \s-1ECDSA\s0 signature of a given \s-1SHA\-256\s0 hash value using the -named curve prime256v1 (aka P\-256). -This example uses deprecated functionality. See \*(L"\s-1DESCRIPTION\*(R"\s0. -.PP -First step: create an \s-1EC_KEY\s0 object (note: this part is \fBnot\fR \s-1ECDSA\s0 -specific) -.PP -.Vb 3 -\& int ret; -\& ECDSA_SIG *sig; -\& EC_KEY *eckey; -\& -\& eckey = EC_KEY_new_by_curve_name(NID_X9_62_prime256v1); -\& if (eckey == NULL) -\& /* error */ -\& if (EC_KEY_generate_key(eckey) == 0) -\& /* error */ -.Ve -.PP -Second step: compute the \s-1ECDSA\s0 signature of a \s-1SHA\-256\s0 hash value -using \fBECDSA_do_sign()\fR: -.PP -.Vb 3 -\& sig = ECDSA_do_sign(digest, 32, eckey); -\& if (sig == NULL) -\& /* error */ -.Ve -.PP -or using \fBECDSA_sign()\fR: -.PP -.Vb 2 -\& unsigned char *buffer, *pp; -\& int buf_len; -\& -\& buf_len = ECDSA_size(eckey); -\& buffer = OPENSSL_malloc(buf_len); -\& pp = buffer; -\& if (ECDSA_sign(0, dgst, dgstlen, pp, &buf_len, eckey) == 0) -\& /* error */ -.Ve -.PP -Third step: verify the created \s-1ECDSA\s0 signature using \fBECDSA_do_verify()\fR: -.PP -.Vb 1 -\& ret = ECDSA_do_verify(digest, 32, sig, eckey); -.Ve -.PP -or using \fBECDSA_verify()\fR: -.PP -.Vb 1 -\& ret = ECDSA_verify(0, digest, 32, buffer, buf_len, eckey); -.Ve -.PP -and finally evaluate the return value: -.PP -.Vb 6 -\& if (ret == 1) -\& /* signature ok */ -\& else if (ret == 0) -\& /* incorrect signature */ -\& else -\& /* error */ -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ANSI X9.62, US\s0 Federal Information Processing Standard \s-1FIPS186\-2\s0 -(Digital Signature Standard, \s-1DSS\s0) -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEC_KEY_new\fR\|(3), -\&\fBEVP_DigestSignInit\fR\|(3), -\&\fBEVP_DigestVerifyInit\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3) -\&\fBi2d_ECDSA_SIG\fR\|(3), -\&\fBd2i_ECDSA_SIG\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All functionality described here was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ECDSA_sign_ex.3ossl b/openssl-install/share/man/man3/ECDSA_sign_ex.3ossl deleted file mode 120000 index a01845fb..00000000 --- a/openssl-install/share/man/man3/ECDSA_sign_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_sign_setup.3ossl b/openssl-install/share/man/man3/ECDSA_sign_setup.3ossl deleted file mode 120000 index a01845fb..00000000 --- a/openssl-install/share/man/man3/ECDSA_sign_setup.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_size.3ossl b/openssl-install/share/man/man3/ECDSA_size.3ossl deleted file mode 120000 index a01845fb..00000000 --- a/openssl-install/share/man/man3/ECDSA_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECDSA_verify.3ossl b/openssl-install/share/man/man3/ECDSA_verify.3ossl deleted file mode 120000 index a01845fb..00000000 --- a/openssl-install/share/man/man3/ECDSA_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECDSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECPARAMETERS_free.3ossl b/openssl-install/share/man/man3/ECPARAMETERS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ECPARAMETERS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECPARAMETERS_new.3ossl b/openssl-install/share/man/man3/ECPARAMETERS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ECPARAMETERS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECPKPARAMETERS_free.3ossl b/openssl-install/share/man/man3/ECPKPARAMETERS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ECPKPARAMETERS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECPKPARAMETERS_new.3ossl b/openssl-install/share/man/man3/ECPKPARAMETERS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ECPKPARAMETERS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ECPKParameters_print.3ossl b/openssl-install/share/man/man3/ECPKParameters_print.3ossl deleted file mode 100644 index d9ae68a7..00000000 --- a/openssl-install/share/man/man3/ECPKParameters_print.3ossl +++ /dev/null @@ -1,188 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ECPKPARAMETERS_PRINT 3ossl" -.TH ECPKPARAMETERS_PRINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ECPKParameters_print, ECPKParameters_print_fp \- Functions for decoding and -encoding ASN1 representations of elliptic curve entities -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int ECPKParameters_print(BIO *bp, const EC_GROUP *x, int off); -\& int ECPKParameters_print_fp(FILE *fp, const EC_GROUP *x, int off); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_print_params\fR\|(3) -.PP -The ECPKParameters represent the public parameters for an -\&\fB\s-1EC_GROUP\s0\fR structure, which represents a curve. -.PP -The \fBECPKParameters_print()\fR and \fBECPKParameters_print_fp()\fR functions print -a human-readable output of the public parameters of the \s-1EC_GROUP\s0 to \fBbp\fR -or \fBfp\fR. The output lines are indented by \fBoff\fR spaces. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBECPKParameters_print()\fR and \fBECPKParameters_print_fp()\fR -return 1 for success and 0 if an error occurs. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBEC_GROUP_new\fR\|(3), \fBEC_GROUP_copy\fR\|(3), -\&\fBEC_POINT_new\fR\|(3), \fBEC_POINT_add\fR\|(3), \fBEC_KEY_new\fR\|(3), -\&\fBEC_GFp_simple_method\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ECPKParameters_print_fp.3ossl b/openssl-install/share/man/man3/ECPKParameters_print_fp.3ossl deleted file mode 120000 index 8c4cccae..00000000 --- a/openssl-install/share/man/man3/ECPKParameters_print_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -ECPKParameters_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GF2m_simple_method.3ossl b/openssl-install/share/man/man3/EC_GF2m_simple_method.3ossl deleted file mode 120000 index e61b62fe..00000000 --- a/openssl-install/share/man/man3/EC_GF2m_simple_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GFp_simple_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GFp_mont_method.3ossl b/openssl-install/share/man/man3/EC_GFp_mont_method.3ossl deleted file mode 120000 index e61b62fe..00000000 --- a/openssl-install/share/man/man3/EC_GFp_mont_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GFp_simple_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GFp_nist_method.3ossl b/openssl-install/share/man/man3/EC_GFp_nist_method.3ossl deleted file mode 120000 index e61b62fe..00000000 --- a/openssl-install/share/man/man3/EC_GFp_nist_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GFp_simple_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GFp_nistp224_method.3ossl b/openssl-install/share/man/man3/EC_GFp_nistp224_method.3ossl deleted file mode 120000 index e61b62fe..00000000 --- a/openssl-install/share/man/man3/EC_GFp_nistp224_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GFp_simple_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GFp_nistp256_method.3ossl b/openssl-install/share/man/man3/EC_GFp_nistp256_method.3ossl deleted file mode 120000 index e61b62fe..00000000 --- a/openssl-install/share/man/man3/EC_GFp_nistp256_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GFp_simple_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GFp_nistp521_method.3ossl b/openssl-install/share/man/man3/EC_GFp_nistp521_method.3ossl deleted file mode 120000 index e61b62fe..00000000 --- a/openssl-install/share/man/man3/EC_GFp_nistp521_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GFp_simple_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GFp_simple_method.3ossl b/openssl-install/share/man/man3/EC_GFp_simple_method.3ossl deleted file mode 100644 index 5abe341c..00000000 --- a/openssl-install/share/man/man3/EC_GFp_simple_method.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EC_GFP_SIMPLE_METHOD 3ossl" -.TH EC_GFP_SIMPLE_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EC_GFp_simple_method, EC_GFp_mont_method, EC_GFp_nist_method, EC_GFp_nistp224_method, EC_GFp_nistp256_method, EC_GFp_nistp521_method, EC_GF2m_simple_method, EC_METHOD_get_field_type \- Functions for obtaining EC_METHOD objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 6 -\& const EC_METHOD *EC_GFp_simple_method(void); -\& const EC_METHOD *EC_GFp_mont_method(void); -\& const EC_METHOD *EC_GFp_nist_method(void); -\& const EC_METHOD *EC_GFp_nistp224_method(void); -\& const EC_METHOD *EC_GFp_nistp256_method(void); -\& const EC_METHOD *EC_GFp_nistp521_method(void); -\& -\& const EC_METHOD *EC_GF2m_simple_method(void); -\& -\& int EC_METHOD_get_field_type(const EC_METHOD *meth); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All const \s-1EC_METHOD\s0 *EC_GF* functions were deprecated in OpenSSL 3.0, since -\&\s-1EC_METHOD\s0 is no longer a public concept. -.PP -The Elliptic Curve library provides a number of different implementations through a single common interface. -When constructing a curve using EC_GROUP_new (see \fBEC_GROUP_new\fR\|(3)) an -implementation method must be provided. The functions described here all return a const pointer to an -\&\fB\s-1EC_METHOD\s0\fR structure that can be passed to \s-1EC_GROUP_NEW.\s0 It is important that the correct implementation -type for the form of curve selected is used. -.PP -For F2^m curves there is only one implementation choice, i.e. EC_GF2_simple_method. -.PP -For Fp curves the lowest common denominator implementation is the EC_GFp_simple_method implementation. All -other implementations are based on this one. EC_GFp_mont_method builds on EC_GFp_simple_method but adds the -use of montgomery multiplication (see \fBBN_mod_mul_montgomery\fR\|(3)). EC_GFp_nist_method -offers an implementation optimised for use with \s-1NIST\s0 recommended curves (\s-1NIST\s0 curves are available through -EC_GROUP_new_by_curve_name as described in \fBEC_GROUP_new\fR\|(3)). -.PP -The functions EC_GFp_nistp224_method, EC_GFp_nistp256_method and EC_GFp_nistp521_method offer 64 bit -optimised implementations for the \s-1NIST P224, P256\s0 and P521 curves respectively. Note, however, that these -implementations are not available on all platforms. -.PP -\&\fBEC_METHOD_get_field_type()\fR was deprecated in OpenSSL 3.0. -Applications should use \fBEC_GROUP_get_field_type()\fR as a replacement (see \fBEC_GROUP_copy\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All EC_GFp* functions and EC_GF2m_simple_method always return a const pointer to an \s-1EC_METHOD\s0 structure. -.PP -EC_METHOD_get_field_type returns an integer that identifies the type of field the \s-1EC_METHOD\s0 structure supports. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBEC_GROUP_new\fR\|(3), \fBEC_GROUP_copy\fR\|(3), -\&\fBEC_POINT_new\fR\|(3), \fBEC_POINT_add\fR\|(3), \fBEC_KEY_new\fR\|(3), -\&\fBd2i_ECPKParameters\fR\|(3), -\&\fBBN_mod_mul_montgomery\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEC_GFp_simple_method()\fR, EC_GFp_mont_method(void), -\&\fBEC_GFp_nist_method()\fR, \fBEC_GFp_nistp224_method()\fR, -\&\fBEC_GFp_nistp256_method()\fR, \fBEC_GFp_nistp521_method()\fR, -\&\fBEC_GF2m_simple_method()\fR, and \fBEC_METHOD_get_field_type()\fR -were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EC_GROUP_check.3ossl b/openssl-install/share/man/man3/EC_GROUP_check.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_check_discriminant.3ossl b/openssl-install/share/man/man3/EC_GROUP_check_discriminant.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_check_discriminant.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_check_named_curve.3ossl b/openssl-install/share/man/man3/EC_GROUP_check_named_curve.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_check_named_curve.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_clear_free.3ossl b/openssl-install/share/man/man3/EC_GROUP_clear_free.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_clear_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_cmp.3ossl b/openssl-install/share/man/man3/EC_GROUP_cmp.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_copy.3ossl b/openssl-install/share/man/man3/EC_GROUP_copy.3ossl deleted file mode 100644 index 9a6176cd..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_copy.3ossl +++ /dev/null @@ -1,397 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EC_GROUP_COPY 3ossl" -.TH EC_GROUP_COPY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EC_GROUP_get0_order, EC_GROUP_order_bits, EC_GROUP_get0_cofactor, -EC_GROUP_copy, EC_GROUP_dup, EC_GROUP_method_of, EC_GROUP_set_generator, -EC_GROUP_get0_generator, EC_GROUP_get_order, EC_GROUP_get_cofactor, -EC_GROUP_set_curve_name, EC_GROUP_get_curve_name, EC_GROUP_set_asn1_flag, -EC_GROUP_get_asn1_flag, EC_GROUP_set_point_conversion_form, -EC_GROUP_get_point_conversion_form, EC_GROUP_get0_seed, -EC_GROUP_get_seed_len, EC_GROUP_set_seed, EC_GROUP_get_degree, -EC_GROUP_check, EC_GROUP_check_named_curve, -EC_GROUP_check_discriminant, EC_GROUP_cmp, -EC_GROUP_get_basis_type, EC_GROUP_get_trinomial_basis, -EC_GROUP_get_pentanomial_basis, EC_GROUP_get0_field, -EC_GROUP_get_field_type -\&\- Functions for manipulating EC_GROUP objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EC_GROUP_copy(EC_GROUP *dst, const EC_GROUP *src); -\& EC_GROUP *EC_GROUP_dup(const EC_GROUP *src); -\& -\& int EC_GROUP_set_generator(EC_GROUP *group, const EC_POINT *generator, -\& const BIGNUM *order, const BIGNUM *cofactor); -\& const EC_POINT *EC_GROUP_get0_generator(const EC_GROUP *group); -\& -\& int EC_GROUP_get_order(const EC_GROUP *group, BIGNUM *order, BN_CTX *ctx); -\& const BIGNUM *EC_GROUP_get0_order(const EC_GROUP *group); -\& int EC_GROUP_order_bits(const EC_GROUP *group); -\& int EC_GROUP_get_cofactor(const EC_GROUP *group, BIGNUM *cofactor, BN_CTX *ctx); -\& const BIGNUM *EC_GROUP_get0_cofactor(const EC_GROUP *group); -\& const BIGNUM *EC_GROUP_get0_field(const EC_GROUP *group); -\& -\& void EC_GROUP_set_curve_name(EC_GROUP *group, int nid); -\& int EC_GROUP_get_curve_name(const EC_GROUP *group); -\& -\& void EC_GROUP_set_asn1_flag(EC_GROUP *group, int flag); -\& int EC_GROUP_get_asn1_flag(const EC_GROUP *group); -\& -\& void EC_GROUP_set_point_conversion_form(EC_GROUP *group, point_conversion_form_t form); -\& point_conversion_form_t EC_GROUP_get_point_conversion_form(const EC_GROUP *group); -\& -\& unsigned char *EC_GROUP_get0_seed(const EC_GROUP *group); -\& size_t EC_GROUP_get_seed_len(const EC_GROUP *group); -\& size_t EC_GROUP_set_seed(EC_GROUP *group, const unsigned char *, size_t len); -\& -\& int EC_GROUP_get_degree(const EC_GROUP *group); -\& -\& int EC_GROUP_check(const EC_GROUP *group, BN_CTX *ctx); -\& int EC_GROUP_check_named_curve(const EC_GROUP *group, int nist_only, -\& BN_CTX *ctx); -\& -\& int EC_GROUP_check_discriminant(const EC_GROUP *group, BN_CTX *ctx); -\& -\& int EC_GROUP_cmp(const EC_GROUP *a, const EC_GROUP *b, BN_CTX *ctx); -\& -\& int EC_GROUP_get_basis_type(const EC_GROUP *group); -\& int EC_GROUP_get_trinomial_basis(const EC_GROUP *group, unsigned int *k); -\& int EC_GROUP_get_pentanomial_basis(const EC_GROUP *group, unsigned int *k1, -\& unsigned int *k2, unsigned int *k3); -\& -\& int EC_GROUP_get_field_type(const EC_GROUP *group); -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& const EC_METHOD *EC_GROUP_method_of(const EC_GROUP *group); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEC_GROUP_copy()\fR copies the curve \fBsrc\fR into \fBdst\fR. Both \fBsrc\fR and \fBdst\fR must use the same \s-1EC_METHOD.\s0 -.PP -\&\fBEC_GROUP_dup()\fR creates a new \s-1EC_GROUP\s0 object and copies the content from \fBsrc\fR to the newly created -\&\s-1EC_GROUP\s0 object. -.PP -\&\fBEC_GROUP_method_of()\fR obtains the \s-1EC_METHOD\s0 of \fBgroup\fR. -This function was deprecated in OpenSSL 3.0, since \s-1EC_METHOD\s0 is no longer a public concept. -.PP -\&\fBEC_GROUP_set_generator()\fR sets curve parameters that must be agreed by all participants using the curve. These -parameters include the \fBgenerator\fR, the \fBorder\fR and the \fBcofactor\fR. The \fBgenerator\fR is a well defined point on the -curve chosen for cryptographic operations. Integers used for point multiplications will be between 0 and -n\-1 where n is the \fBorder\fR. The \fBorder\fR multiplied by the \fBcofactor\fR gives the number of points on the curve. -.PP -\&\fBEC_GROUP_get0_generator()\fR returns the generator for the identified \fBgroup\fR. -.PP -\&\fBEC_GROUP_get_order()\fR retrieves the order of \fBgroup\fR and copies its value into -\&\fBorder\fR. It fails in case \fBgroup\fR is not fully initialized (i.e., its order -is not set or set to zero). -.PP -\&\fBEC_GROUP_get_cofactor()\fR retrieves the cofactor of \fBgroup\fR and copies its value -into \fBcofactor\fR. It fails in case \fBgroup\fR is not fully initialized or if the -cofactor is not set (or set to zero). -.PP -The functions \fBEC_GROUP_set_curve_name()\fR and \fBEC_GROUP_get_curve_name()\fR, set and get the \s-1NID\s0 for the curve respectively -(see \fBEC_GROUP_new\fR\|(3)). If a curve does not have a \s-1NID\s0 associated with it, then EC_GROUP_get_curve_name -will return NID_undef. -.PP -The asn1_flag value is used to determine whether the curve encoding uses -explicit parameters or a named curve using an \s-1ASN1 OID:\s0 many applications only -support the latter form. If asn1_flag is \fB\s-1OPENSSL_EC_NAMED_CURVE\s0\fR then the -named curve form is used and the parameters must have a corresponding -named curve \s-1NID\s0 set. If asn1_flags is \fB\s-1OPENSSL_EC_EXPLICIT_CURVE\s0\fR the -parameters are explicitly encoded. The functions \fBEC_GROUP_get_asn1_flag()\fR and -\&\fBEC_GROUP_set_asn1_flag()\fR get and set the status of the asn1_flag for the curve. -Note: \fB\s-1OPENSSL_EC_EXPLICIT_CURVE\s0\fR was added in OpenSSL 1.1.0, for -previous versions of OpenSSL the value 0 must be used instead. Before OpenSSL -1.1.0 the default form was to use explicit parameters (meaning that -applications would have to explicitly set the named curve form) in OpenSSL -1.1.0 and later the named curve form is the default. -.PP -The point_conversion_form for a curve controls how \s-1EC_POINT\s0 data is encoded as \s-1ASN1\s0 as defined in X9.62 (\s-1ECDSA\s0). -point_conversion_form_t is an enum defined as follows: -.PP -.Vb 10 -\& typedef enum { -\& /** the point is encoded as z||x, where the octet z specifies -\& * which solution of the quadratic equation y is */ -\& POINT_CONVERSION_COMPRESSED = 2, -\& /** the point is encoded as z||x||y, where z is the octet 0x04 */ -\& POINT_CONVERSION_UNCOMPRESSED = 4, -\& /** the point is encoded as z||x||y, where the octet z specifies -\& * which solution of the quadratic equation y is */ -\& POINT_CONVERSION_HYBRID = 6 -\& } point_conversion_form_t; -.Ve -.PP -For \s-1POINT_CONVERSION_UNCOMPRESSED\s0 the point is encoded as an octet signifying the \s-1UNCOMPRESSED\s0 form has been used followed by -the octets for x, followed by the octets for y. -.PP -For any given x coordinate for a point on a curve it is possible to derive two possible y values. For -\&\s-1POINT_CONVERSION_COMPRESSED\s0 the point is encoded as an octet signifying that the \s-1COMPRESSED\s0 form has been used \s-1AND\s0 which of -the two possible solutions for y has been used, followed by the octets for x. -.PP -For \s-1POINT_CONVERSION_HYBRID\s0 the point is encoded as an octet signifying the \s-1HYBRID\s0 form has been used \s-1AND\s0 which of the two -possible solutions for y has been used, followed by the octets for x, followed by the octets for y. -.PP -The functions \fBEC_GROUP_set_point_conversion_form()\fR and \fBEC_GROUP_get_point_conversion_form()\fR, set and get the point_conversion_form -for the curve respectively. -.PP -\&\s-1ANSI X9.62\s0 (\s-1ECDSA\s0 standard) defines a method of generating the curve parameter b from a random number. This provides advantages -in that a parameter obtained in this way is highly unlikely to be susceptible to special purpose attacks, or have any trapdoors in it. -If the seed is present for a curve then the b parameter was generated in a verifiable fashion using that seed. The OpenSSL \s-1EC\s0 library -does not use this seed value but does enable you to inspect it using \fBEC_GROUP_get0_seed()\fR. This returns a pointer to a memory block -containing the seed that was used. The length of the memory block can be obtained using \fBEC_GROUP_get_seed_len()\fR. A number of the -built-in curves within the library provide seed values that can be obtained. It is also possible to set a custom seed using -\&\fBEC_GROUP_set_seed()\fR and passing a pointer to a memory block, along with the length of the seed. Again, the \s-1EC\s0 library will not use -this seed value, although it will be preserved in any \s-1ASN1\s0 based communications. -.PP -\&\fBEC_GROUP_get_degree()\fR gets the degree of the field. -For Fp fields this will be the number of bits in p. -For F2^m fields this will be the value m. -.PP -\&\fBEC_GROUP_get_field_type()\fR identifies what type of field the \s-1EC_GROUP\s0 structure supports, -which will be either F2^m or Fp. -.PP -The function \fBEC_GROUP_check_discriminant()\fR calculates the discriminant for the curve and verifies that it is valid. -For a curve defined over Fp the discriminant is given by the formula 4*a^3 + 27*b^2 whilst for F2^m curves the discriminant is -simply b. In either case for the curve to be valid the discriminant must be non zero. -.PP -The function \fBEC_GROUP_check()\fR behaves in the following way: -For the OpenSSL default provider it performs a number of checks on a curve to verify that it is valid. Checks performed include -verifying that the discriminant is non zero; that a generator has been defined; that the generator is on the curve and has -the correct order. For the OpenSSL \s-1FIPS\s0 provider it uses \fBEC_GROUP_check_named_curve()\fR to conform to SP800\-56Ar3. -.PP -The function \fBEC_GROUP_check_named_curve()\fR determines if the group's domain parameters match one of the built-in curves supported by the library. -The curve name is returned as a \fB\s-1NID\s0\fR if it matches. If the group's domain parameters have been modified then no match will be found. -If the curve name of the given group is \fBNID_undef\fR (e.g. it has been created by using explicit parameters with no curve name), -then this method can be used to lookup the name of the curve that matches the group domain parameters. The built-in curves contain -aliases, so that multiple \s-1NID\s0's can map to the same domain parameters. For such curves it is unspecified which of the aliases will be -returned if the curve name of the given group is NID_undef. -If \fBnist_only\fR is 1 it will only look for \s-1NIST\s0 approved curves, otherwise it searches all built-in curves. -This function may be passed a \s-1BN_CTX\s0 object in the \fBctx\fR parameter. -The \fBctx\fR parameter may be \s-1NULL.\s0 -.PP -\&\fBEC_GROUP_cmp()\fR compares \fBa\fR and \fBb\fR to determine whether they represent the same curve or not. -.PP -The functions \fBEC_GROUP_get_basis_type()\fR, \fBEC_GROUP_get_trinomial_basis()\fR and \fBEC_GROUP_get_pentanomial_basis()\fR should only be called for curves -defined over an F2^m field. Addition and multiplication operations within an F2^m field are performed using an irreducible polynomial -function f(x). This function is either a trinomial of the form: -.PP -f(x) = x^m + x^k + 1 with m > k >= 1 -.PP -or a pentanomial of the form: -.PP -f(x) = x^m + x^k3 + x^k2 + x^k1 + 1 with m > k3 > k2 > k1 >= 1 -.PP -The function \fBEC_GROUP_get_basis_type()\fR returns a \s-1NID\s0 identifying whether a trinomial or pentanomial is in use for the field. The -function \fBEC_GROUP_get_trinomial_basis()\fR must only be called where f(x) is of the trinomial form, and returns the value of \fBk\fR. Similarly -the function \fBEC_GROUP_get_pentanomial_basis()\fR must only be called where f(x) is of the pentanomial form, and returns the values of \fBk1\fR, -\&\fBk2\fR and \fBk3\fR respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following functions return 1 on success or 0 on error: \fBEC_GROUP_copy()\fR, \fBEC_GROUP_set_generator()\fR, \fBEC_GROUP_check()\fR, -\&\fBEC_GROUP_check_discriminant()\fR, \fBEC_GROUP_get_trinomial_basis()\fR and \fBEC_GROUP_get_pentanomial_basis()\fR. -.PP -\&\fBEC_GROUP_dup()\fR returns a pointer to the duplicated curve, or \s-1NULL\s0 on error. -.PP -\&\fBEC_GROUP_method_of()\fR returns the \s-1EC_METHOD\s0 implementation in use for the given curve or \s-1NULL\s0 on error. -.PP -\&\fBEC_GROUP_get0_generator()\fR returns the generator for the given curve or \s-1NULL\s0 on error. -.PP -\&\fBEC_GROUP_get_order()\fR returns 0 if the order is not set (or set to zero) for -\&\fBgroup\fR or if copying into \fBorder\fR fails, 1 otherwise. -.PP -\&\fBEC_GROUP_get_cofactor()\fR returns 0 if the cofactor is not set (or is set to zero) for \fBgroup\fR or if copying into \fBcofactor\fR fails, 1 otherwise. -.PP -\&\fBEC_GROUP_get_curve_name()\fR returns the curve name (\s-1NID\s0) for \fBgroup\fR or will return NID_undef if no curve name is associated. -.PP -\&\fBEC_GROUP_get_asn1_flag()\fR returns the \s-1ASN1\s0 flag for the specified \fBgroup\fR . -.PP -\&\fBEC_GROUP_get_point_conversion_form()\fR returns the point_conversion_form for \fBgroup\fR. -.PP -\&\fBEC_GROUP_get_degree()\fR returns the degree for \fBgroup\fR or 0 if the operation is not supported by the underlying group implementation. -.PP -\&\fBEC_GROUP_get_field_type()\fR returns either \fBNID_X9_62_prime_field\fR for prime curves -or \fBNID_X9_62_characteristic_two_field\fR for binary curves; -these values are defined in the \fI\fR header file. -.PP -\&\fBEC_GROUP_check_named_curve()\fR returns the nid of the matching named curve, otherwise it returns 0 for no match, or \-1 on error. -.PP -\&\fBEC_GROUP_get0_order()\fR returns an internal pointer to the group order. -\&\fBEC_GROUP_order_bits()\fR returns the number of bits in the group order. -\&\fBEC_GROUP_get0_cofactor()\fR returns an internal pointer to the group cofactor. -\&\fBEC_GROUP_get0_field()\fR returns an internal pointer to the group field. For curves over \s-1GF\s0(p), this is the modulus; for curves -over \s-1GF\s0(2^m), this is the irreducible polynomial defining the field. -.PP -\&\fBEC_GROUP_get0_seed()\fR returns a pointer to the seed that was used to generate the parameter b, or \s-1NULL\s0 if the seed is not -specified. \fBEC_GROUP_get_seed_len()\fR returns the length of the seed or 0 if the seed is not specified. -.PP -\&\fBEC_GROUP_set_seed()\fR returns the length of the seed that has been set. If the supplied seed is \s-1NULL,\s0 or the supplied seed length is -0, the return value will be 1. On error 0 is returned. -.PP -\&\fBEC_GROUP_cmp()\fR returns 0 if the curves are equal, 1 if they are not equal, or \-1 on error. -.PP -\&\fBEC_GROUP_get_basis_type()\fR returns the values NID_X9_62_tpBasis or NID_X9_62_ppBasis (as defined in \fI\fR) for a -trinomial or pentanomial respectively. Alternatively in the event of an error a 0 is returned. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBEC_GROUP_new\fR\|(3), -\&\fBEC_POINT_new\fR\|(3), \fBEC_POINT_add\fR\|(3), \fBEC_KEY_new\fR\|(3), -\&\fBEC_GFp_simple_method\fR\|(3), \fBd2i_ECPKParameters\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEC_GROUP_method_of()\fR was deprecated in OpenSSL 3.0. -\&\fBEC_GROUP_get0_field()\fR, \fBEC_GROUP_check_named_curve()\fR and \fBEC_GROUP_get_field_type()\fR were added in OpenSSL 3.0. -\&\fBEC_GROUP_get0_order()\fR, \fBEC_GROUP_order_bits()\fR and \fBEC_GROUP_get0_cofactor()\fR were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EC_GROUP_dup.3ossl b/openssl-install/share/man/man3/EC_GROUP_dup.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_free.3ossl b/openssl-install/share/man/man3/EC_GROUP_free.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get0_cofactor.3ossl b/openssl-install/share/man/man3/EC_GROUP_get0_cofactor.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get0_cofactor.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get0_field.3ossl b/openssl-install/share/man/man3/EC_GROUP_get0_field.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get0_field.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get0_generator.3ossl b/openssl-install/share/man/man3/EC_GROUP_get0_generator.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get0_generator.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get0_order.3ossl b/openssl-install/share/man/man3/EC_GROUP_get0_order.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get0_order.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get0_seed.3ossl b/openssl-install/share/man/man3/EC_GROUP_get0_seed.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get0_seed.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_asn1_flag.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_asn1_flag.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_asn1_flag.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_basis_type.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_basis_type.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_basis_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_cofactor.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_cofactor.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_cofactor.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_curve.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_curve.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_curve.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_curve_GF2m.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_curve_GF2m.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_curve_GF2m.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_curve_GFp.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_curve_GFp.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_curve_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_curve_name.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_curve_name.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_curve_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_degree.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_degree.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_degree.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_ecparameters.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_ecparameters.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_ecparameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_ecpkparameters.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_ecpkparameters.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_ecpkparameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_field_type.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_field_type.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_field_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_order.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_order.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_order.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_pentanomial_basis.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_pentanomial_basis.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_pentanomial_basis.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_point_conversion_form.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_point_conversion_form.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_point_conversion_form.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_seed_len.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_seed_len.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_seed_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_get_trinomial_basis.3ossl b/openssl-install/share/man/man3/EC_GROUP_get_trinomial_basis.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_get_trinomial_basis.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_have_precompute_mult.3ossl b/openssl-install/share/man/man3/EC_GROUP_have_precompute_mult.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_have_precompute_mult.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_method_of.3ossl b/openssl-install/share/man/man3/EC_GROUP_method_of.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_method_of.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_new.3ossl b/openssl-install/share/man/man3/EC_GROUP_new.3ossl deleted file mode 100644 index 27bbfbcc..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new.3ossl +++ /dev/null @@ -1,376 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EC_GROUP_NEW 3ossl" -.TH EC_GROUP_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EC_GROUP_get_ecparameters, -EC_GROUP_get_ecpkparameters, -EC_GROUP_new_from_params, -EC_GROUP_to_params, -EC_GROUP_new_from_ecparameters, -EC_GROUP_new_from_ecpkparameters, -EC_GROUP_new, -EC_GROUP_free, -EC_GROUP_clear_free, -EC_GROUP_new_curve_GFp, -EC_GROUP_new_curve_GF2m, -EC_GROUP_new_by_curve_name_ex, -EC_GROUP_new_by_curve_name, -EC_GROUP_set_curve, -EC_GROUP_get_curve, -EC_GROUP_set_curve_GFp, -EC_GROUP_get_curve_GFp, -EC_GROUP_set_curve_GF2m, -EC_GROUP_get_curve_GF2m, -EC_get_builtin_curves, -OSSL_EC_curve_nid2name \- -Functions for creating and destroying EC_GROUP objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EC_GROUP *EC_GROUP_new_from_params(const OSSL_PARAM params[], -\& OSSL_LIB_CTX *libctx, const char *propq); -\& OSSL_PARAM *EC_GROUP_to_params(const EC_GROUP *group, OSSL_LIB_CTX *libctx, -\& const char *propq, BN_CTX *bnctx); -\& EC_GROUP *EC_GROUP_new_from_ecparameters(const ECPARAMETERS *params); -\& EC_GROUP *EC_GROUP_new_from_ecpkparameters(const ECPKPARAMETERS *params); -\& void EC_GROUP_free(EC_GROUP *group); -\& -\& EC_GROUP *EC_GROUP_new_curve_GFp(const BIGNUM *p, const BIGNUM *a, -\& const BIGNUM *b, BN_CTX *ctx); -\& EC_GROUP *EC_GROUP_new_curve_GF2m(const BIGNUM *p, const BIGNUM *a, -\& const BIGNUM *b, BN_CTX *ctx); -\& EC_GROUP *EC_GROUP_new_by_curve_name_ex(OSSL_LIB_CTX *libctx, const char *propq, -\& int nid); -\& EC_GROUP *EC_GROUP_new_by_curve_name(int nid); -\& -\& int EC_GROUP_set_curve(EC_GROUP *group, const BIGNUM *p, const BIGNUM *a, -\& const BIGNUM *b, BN_CTX *ctx); -\& int EC_GROUP_get_curve(const EC_GROUP *group, BIGNUM *p, BIGNUM *a, BIGNUM *b, -\& BN_CTX *ctx); -\& -\& ECPARAMETERS *EC_GROUP_get_ecparameters(const EC_GROUP *group, -\& ECPARAMETERS *params); -\& ECPKPARAMETERS *EC_GROUP_get_ecpkparameters(const EC_GROUP *group, -\& ECPKPARAMETERS *params); -\& -\& size_t EC_get_builtin_curves(EC_builtin_curve *r, size_t nitems); -\& const char *OSSL_EC_curve_nid2name(int nid); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& EC_GROUP *EC_GROUP_new(const EC_METHOD *meth); -\& void EC_GROUP_clear_free(EC_GROUP *group); -\& -\& int EC_GROUP_set_curve_GFp(EC_GROUP *group, const BIGNUM *p, -\& const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx); -\& int EC_GROUP_get_curve_GFp(const EC_GROUP *group, BIGNUM *p, -\& BIGNUM *a, BIGNUM *b, BN_CTX *ctx); -\& int EC_GROUP_set_curve_GF2m(EC_GROUP *group, const BIGNUM *p, -\& const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx); -\& int EC_GROUP_get_curve_GF2m(const EC_GROUP *group, BIGNUM *p, -\& BIGNUM *a, BIGNUM *b, BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Within the library there are two forms of elliptic curve that are of interest. -The first form is those defined over the prime field Fp. The elements of Fp are -the integers 0 to p\-1, where p is a prime number. This gives us a revised -elliptic curve equation as follows: -.PP -y^2 mod p = x^3 +ax + b mod p -.PP -The second form is those defined over a binary field F2^m where the elements of -the field are integers of length at most m bits. For this form the elliptic -curve equation is modified to: -.PP -y^2 + xy = x^3 + ax^2 + b (where b != 0) -.PP -Operations in a binary field are performed relative to an -\&\fBirreducible polynomial\fR. All such curves with OpenSSL use a trinomial or a -pentanomial for this parameter. -.PP -Although deprecated since OpenSSL 3.0 and should no longer be used, -a new curve can be constructed by calling \fBEC_GROUP_new()\fR, using the -implementation provided by \fImeth\fR (see \fBEC_GFp_simple_method\fR\|(3)) and -associated with the library context \fIctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)). -The \fIctx\fR parameter may be \s-1NULL\s0 in which case the default library context is -used. -It is then necessary to call \fBEC_GROUP_set_curve()\fR to set the curve parameters. -Applications should instead use one of the other EC_GROUP_new_* constructors. -.PP -\&\fBEC_GROUP_new_from_params()\fR creates a group with parameters specified by \fIparams\fR. -The library context \fIlibctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) and property query string -\&\fIpropq\fR are used to fetch algorithms from providers. -\&\fIparams\fR may be either a list of explicit params or a named group, -The values for \fIctx\fR and \fIpropq\fR may be \s-1NULL.\s0 -The \fIparams\fR that can be used are described in -\&\fB\s-1EVP_PKEY\-EC\s0\fR(7). -.PP -EC_GROUP_to_params creates an \s-1OSSL_PARAM\s0 array with the corresponding parameters -describing the given \s-1EC_GROUP.\s0 The resulting parameters may contain parameters -describing a named or explicit curve depending on the \s-1EC_GROUP.\s0 -The library context \fIlibctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) and property query string -\&\fIpropq\fR are used to fetch algorithms from providers. -\&\fIbnctx\fR is an optional preallocated \s-1BN_CTX\s0 (to save the overhead of allocating -and freeing the structure in a loop). -The values for \fIlibctx\fR, \fIpropq\fR and \fIbnctx\fR may be \s-1NULL.\s0 -The caller is responsible for freeing the \s-1OSSL_PARAM\s0 pointer returned. -.PP -\&\fBEC_GROUP_new_from_ecparameters()\fR will create a group from the -specified \fIparams\fR and -\&\fBEC_GROUP_new_from_ecpkparameters()\fR will create a group from the specific \s-1PK\s0 -\&\fIparams\fR. -.PP -\&\fBEC_GROUP_set_curve()\fR sets the curve parameters \fIp\fR, \fIa\fR and \fIb\fR. For a curve -over Fp \fIp\fR is the prime for the field. For a curve over F2^m \fIp\fR represents -the irreducible polynomial \- each bit represents a term in the polynomial. -Therefore, there will either be three or five bits set dependent on whether the -polynomial is a trinomial or a pentanomial. -In either case, \fIa\fR and \fIb\fR represents the coefficients a and b from the -relevant equation introduced above. -.PP -\&\fBEC_group_get_curve()\fR obtains the previously set curve parameters. -.PP -\&\fBEC_GROUP_set_curve_GFp()\fR and \fBEC_GROUP_set_curve_GF2m()\fR are synonyms for -\&\fBEC_GROUP_set_curve()\fR. They are defined for backwards compatibility only and -should not be used. -.PP -\&\fBEC_GROUP_get_curve_GFp()\fR and \fBEC_GROUP_get_curve_GF2m()\fR are synonyms for -\&\fBEC_GROUP_get_curve()\fR. They are defined for backwards compatibility only and -should not be used. -.PP -The functions \fBEC_GROUP_new_curve_GFp()\fR and \fBEC_GROUP_new_curve_GF2m()\fR are -shortcuts for calling \fBEC_GROUP_new()\fR and then the \fBEC_GROUP_set_curve()\fR function. -An appropriate default implementation method will be used. -.PP -Whilst the library can be used to create any curve using the functions described -above, there are also a number of predefined curves that are available. In order -to obtain a list of all of the predefined curves, call the function -\&\fBEC_get_builtin_curves()\fR. The parameter \fIr\fR should be an array of -EC_builtin_curve structures of size \fInitems\fR. The function will populate the -\&\fIr\fR array with information about the built-in curves. If \fInitems\fR is less than -the total number of curves available, then the first \fInitems\fR curves will be -returned. Otherwise the total number of curves will be provided. The return -value is the total number of curves available (whether that number has been -populated in \fIr\fR or not). Passing a \s-1NULL\s0 \fIr\fR, or setting \fInitems\fR to 0 will -do nothing other than return the total number of curves available. -The EC_builtin_curve structure is defined as follows: -.PP -.Vb 4 -\& typedef struct { -\& int nid; -\& const char *comment; -\& } EC_builtin_curve; -.Ve -.PP -Each EC_builtin_curve item has a unique integer id (\fInid\fR), and a human -readable comment string describing the curve. -.PP -In order to construct a built-in curve use the function -\&\fBEC_GROUP_new_by_curve_name_ex()\fR and provide the \fInid\fR of the curve to -be constructed, the associated library context to be used in \fIctx\fR (see -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) and any property query string in \fIpropq\fR. The \fIctx\fR value -may be \s-1NULL\s0 in which case the default library context is used. The \fIpropq\fR -value may also be \s-1NULL.\s0 -.PP -\&\fBEC_GROUP_new_by_curve_name()\fR is the same as -\&\fBEC_GROUP_new_by_curve_name_ex()\fR except that the default library context -is always used along with a \s-1NULL\s0 property query string. -.PP -\&\fBEC_GROUP_free()\fR frees the memory associated with the \s-1EC_GROUP.\s0 -If \fIgroup\fR is \s-1NULL\s0 nothing is done. -.PP -\&\fBEC_GROUP_clear_free()\fR is deprecated: it was meant to destroy any sensitive data -held within the \s-1EC_GROUP\s0 and then free its memory, but since all the data stored -in the \s-1EC_GROUP\s0 is public anyway, this function is unnecessary. -Its use can be safely replaced with \fBEC_GROUP_free()\fR. -If \fIgroup\fR is \s-1NULL\s0 nothing is done. -.PP -\&\fBOSSL_EC_curve_nid2name()\fR converts a curve \fInid\fR into the corresponding name. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All EC_GROUP_new* functions return a pointer to the newly constructed group, or -\&\s-1NULL\s0 on error. -.PP -\&\fBEC_get_builtin_curves()\fR returns the number of built-in curves that are -available. -.PP -\&\fBEC_GROUP_set_curve_GFp()\fR, \fBEC_GROUP_get_curve_GFp()\fR, \fBEC_GROUP_set_curve_GF2m()\fR, -\&\fBEC_GROUP_get_curve_GF2m()\fR return 1 on success or 0 on error. -.PP -\&\fBOSSL_EC_curve_nid2name()\fR returns a character string constant, or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBEC_GROUP_copy\fR\|(3), -\&\fBEC_POINT_new\fR\|(3), \fBEC_POINT_add\fR\|(3), \fBEC_KEY_new\fR\|(3), -\&\fBEC_GFp_simple_method\fR\|(3), \fBd2i_ECPKParameters\fR\|(3), -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3), \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -.IP "\(bu" 2 -\&\fBEC_GROUP_new()\fR was deprecated in OpenSSL 3.0. -.Sp -\&\fBEC_GROUP_new_by_curve_name_ex()\fR and \fBEC_GROUP_new_from_params()\fR were -added in OpenSSL 3.0. -.IP "\(bu" 2 -\&\fBEC_GROUP_clear_free()\fR was deprecated in OpenSSL 3.0; use \fBEC_GROUP_free()\fR -instead. -.IP "\(bu" 2 - -.Sp -.Vb 3 -\& EC_GROUP_set_curve_GFp(), EC_GROUP_get_curve_GFp(), -\& EC_GROUP_set_curve_GF2m() and EC_GROUP_get_curve_GF2m() were deprecated in -\& OpenSSL 3.0; use EC_GROUP_set_curve() and EC_GROUP_get_curve() instead. -.Ve -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EC_GROUP_new_by_curve_name.3ossl b/openssl-install/share/man/man3/EC_GROUP_new_by_curve_name.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new_by_curve_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_new_by_curve_name_ex.3ossl b/openssl-install/share/man/man3/EC_GROUP_new_by_curve_name_ex.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new_by_curve_name_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_new_curve_GF2m.3ossl b/openssl-install/share/man/man3/EC_GROUP_new_curve_GF2m.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new_curve_GF2m.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_new_curve_GFp.3ossl b/openssl-install/share/man/man3/EC_GROUP_new_curve_GFp.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new_curve_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_new_from_ecparameters.3ossl b/openssl-install/share/man/man3/EC_GROUP_new_from_ecparameters.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new_from_ecparameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_new_from_ecpkparameters.3ossl b/openssl-install/share/man/man3/EC_GROUP_new_from_ecpkparameters.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new_from_ecpkparameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_new_from_params.3ossl b/openssl-install/share/man/man3/EC_GROUP_new_from_params.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_new_from_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_order_bits.3ossl b/openssl-install/share/man/man3/EC_GROUP_order_bits.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_order_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_precompute_mult.3ossl b/openssl-install/share/man/man3/EC_GROUP_precompute_mult.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_precompute_mult.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_asn1_flag.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_asn1_flag.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_asn1_flag.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_curve.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_curve.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_curve.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_curve_GF2m.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_curve_GF2m.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_curve_GF2m.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_curve_GFp.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_curve_GFp.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_curve_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_curve_name.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_curve_name.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_curve_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_generator.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_generator.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_generator.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_point_conversion_form.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_point_conversion_form.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_point_conversion_form.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_set_seed.3ossl b/openssl-install/share/man/man3/EC_GROUP_set_seed.3ossl deleted file mode 120000 index 8ecbfaec..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_set_seed.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_copy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_GROUP_to_params.3ossl b/openssl-install/share/man/man3/EC_GROUP_to_params.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_GROUP_to_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_check_key.3ossl b/openssl-install/share/man/man3/EC_KEY_check_key.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_check_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_clear_flags.3ossl b/openssl-install/share/man/man3/EC_KEY_clear_flags.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_copy.3ossl b/openssl-install/share/man/man3/EC_KEY_copy.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_decoded_from_explicit_params.3ossl b/openssl-install/share/man/man3/EC_KEY_decoded_from_explicit_params.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_decoded_from_explicit_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_dup.3ossl b/openssl-install/share/man/man3/EC_KEY_dup.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_free.3ossl b/openssl-install/share/man/man3/EC_KEY_free.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_generate_key.3ossl b/openssl-install/share/man/man3/EC_KEY_generate_key.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_generate_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get0_engine.3ossl b/openssl-install/share/man/man3/EC_KEY_get0_engine.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get0_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get0_group.3ossl b/openssl-install/share/man/man3/EC_KEY_get0_group.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get0_group.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get0_private_key.3ossl b/openssl-install/share/man/man3/EC_KEY_get0_private_key.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get0_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get0_public_key.3ossl b/openssl-install/share/man/man3/EC_KEY_get0_public_key.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get0_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get_conv_form.3ossl b/openssl-install/share/man/man3/EC_KEY_get_conv_form.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get_conv_form.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get_enc_flags.3ossl b/openssl-install/share/man/man3/EC_KEY_get_enc_flags.3ossl deleted file mode 100644 index a65500c3..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get_enc_flags.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EC_KEY_GET_ENC_FLAGS 3ossl" -.TH EC_KEY_GET_ENC_FLAGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EC_KEY_get_enc_flags, EC_KEY_set_enc_flags -\&\- Get and set flags for encoding EC_KEY structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned int EC_KEY_get_enc_flags(const EC_KEY *key); -\& void EC_KEY_set_enc_flags(EC_KEY *eckey, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The format of the external representation of the public key written by -\&\fBi2d_ECPrivateKey()\fR (such as whether it is stored in a compressed form or not) is -described by the point_conversion_form. See \fBEC_GROUP_copy\fR\|(3) -for a description of point_conversion_form. -.PP -When reading a private key encoded without an associated public key (e.g. if -\&\s-1EC_PKEY_NO_PUBKEY\s0 has been used \- see below), then \fBd2i_ECPrivateKey()\fR generates -the missing public key automatically. Private keys encoded without parameters -(e.g. if \s-1EC_PKEY_NO_PARAMETERS\s0 has been used \- see below) cannot be loaded using -\&\fBd2i_ECPrivateKey()\fR. -.PP -The functions \fBEC_KEY_get_enc_flags()\fR and \fBEC_KEY_set_enc_flags()\fR get and set the -value of the encoding flags for the \fBkey\fR. There are two encoding flags -currently defined \- \s-1EC_PKEY_NO_PARAMETERS\s0 and \s-1EC_PKEY_NO_PUBKEY.\s0 These flags -define the behaviour of how the \fBkey\fR is converted into \s-1ASN1\s0 in a call to -\&\fBi2d_ECPrivateKey()\fR. If \s-1EC_PKEY_NO_PARAMETERS\s0 is set then the public parameters for -the curve are not encoded along with the private key. If \s-1EC_PKEY_NO_PUBKEY\s0 is -set then the public key is not encoded along with the private key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEC_KEY_get_enc_flags()\fR returns the value of the current encoding flags for the -\&\s-1EC_KEY.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBEC_GROUP_new\fR\|(3), -\&\fBEC_GROUP_copy\fR\|(3), \fBEC_POINT_new\fR\|(3), -\&\fBEC_POINT_add\fR\|(3), -\&\fBEC_GFp_simple_method\fR\|(3), -\&\fBd2i_ECPKParameters\fR\|(3), -\&\fBd2i_ECPrivateKey\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EC_KEY_get_ex_data.3ossl b/openssl-install/share/man/man3/EC_KEY_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get_ex_new_index.3ossl b/openssl-install/share/man/man3/EC_KEY_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get_flags.3ossl b/openssl-install/share/man/man3/EC_KEY_get_flags.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_get_method.3ossl b/openssl-install/share/man/man3/EC_KEY_get_method.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_get_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_key2buf.3ossl b/openssl-install/share/man/man3/EC_KEY_key2buf.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_key2buf.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_new.3ossl b/openssl-install/share/man/man3/EC_KEY_new.3ossl deleted file mode 100644 index 932b8b84..00000000 --- a/openssl-install/share/man/man3/EC_KEY_new.3ossl +++ /dev/null @@ -1,378 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EC_KEY_NEW 3ossl" -.TH EC_KEY_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_EC_gen, -EC_KEY_get_method, EC_KEY_set_method, EC_KEY_new_ex, -EC_KEY_new, EC_KEY_get_flags, EC_KEY_set_flags, EC_KEY_clear_flags, -EC_KEY_new_by_curve_name_ex, EC_KEY_new_by_curve_name, EC_KEY_free, -EC_KEY_copy, EC_KEY_dup, EC_KEY_up_ref, EC_KEY_get0_engine, -EC_KEY_get0_group, EC_KEY_set_group, EC_KEY_get0_private_key, -EC_KEY_set_private_key, EC_KEY_get0_public_key, EC_KEY_set_public_key, -EC_KEY_get_conv_form, -EC_KEY_set_conv_form, EC_KEY_set_asn1_flag, -EC_KEY_decoded_from_explicit_params, EC_KEY_precompute_mult, -EC_KEY_generate_key, EC_KEY_check_key, EC_KEY_set_public_key_affine_coordinates, -EC_KEY_oct2key, EC_KEY_key2buf, EC_KEY_oct2priv, EC_KEY_priv2oct, -EC_KEY_priv2buf \- Functions for creating, destroying and manipulating -EC_KEY objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *EVP_EC_gen(const char *curve); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& EC_KEY *EC_KEY_new_ex(OSSL_LIB_CTX *ctx, const char *propq); -\& EC_KEY *EC_KEY_new(void); -\& int EC_KEY_get_flags(const EC_KEY *key); -\& void EC_KEY_set_flags(EC_KEY *key, int flags); -\& void EC_KEY_clear_flags(EC_KEY *key, int flags); -\& EC_KEY *EC_KEY_new_by_curve_name_ex(OSSL_LIB_CTX *ctx, const char *propq, -\& int nid); -\& EC_KEY *EC_KEY_new_by_curve_name(int nid); -\& void EC_KEY_free(EC_KEY *key); -\& EC_KEY *EC_KEY_copy(EC_KEY *dst, const EC_KEY *src); -\& EC_KEY *EC_KEY_dup(const EC_KEY *src); -\& int EC_KEY_up_ref(EC_KEY *key); -\& ENGINE *EC_KEY_get0_engine(const EC_KEY *eckey); -\& const EC_GROUP *EC_KEY_get0_group(const EC_KEY *key); -\& int EC_KEY_set_group(EC_KEY *key, const EC_GROUP *group); -\& const BIGNUM *EC_KEY_get0_private_key(const EC_KEY *key); -\& int EC_KEY_set_private_key(EC_KEY *key, const BIGNUM *priv_key); -\& const EC_POINT *EC_KEY_get0_public_key(const EC_KEY *key); -\& int EC_KEY_set_public_key(EC_KEY *key, const EC_POINT *pub); -\& point_conversion_form_t EC_KEY_get_conv_form(const EC_KEY *key); -\& void EC_KEY_set_conv_form(EC_KEY *eckey, point_conversion_form_t cform); -\& void EC_KEY_set_asn1_flag(EC_KEY *eckey, int asn1_flag); -\& int EC_KEY_decoded_from_explicit_params(const EC_KEY *key); -\& int EC_KEY_generate_key(EC_KEY *key); -\& int EC_KEY_check_key(const EC_KEY *key); -\& int EC_KEY_set_public_key_affine_coordinates(EC_KEY *key, BIGNUM *x, BIGNUM *y); -\& const EC_KEY_METHOD *EC_KEY_get_method(const EC_KEY *key); -\& int EC_KEY_set_method(EC_KEY *key, const EC_KEY_METHOD *meth); -\& -\& int EC_KEY_oct2key(EC_KEY *eckey, const unsigned char *buf, size_t len, BN_CTX *ctx); -\& size_t EC_KEY_key2buf(const EC_KEY *eckey, point_conversion_form_t form, -\& unsigned char **pbuf, BN_CTX *ctx); -\& -\& int EC_KEY_oct2priv(EC_KEY *eckey, const unsigned char *buf, size_t len); -\& size_t EC_KEY_priv2oct(const EC_KEY *eckey, unsigned char *buf, size_t len); -\& -\& size_t EC_KEY_priv2buf(const EC_KEY *eckey, unsigned char **pbuf); -\& int EC_KEY_precompute_mult(EC_KEY *key, BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_EC_gen()\fR generates a new \s-1EC\s0 key pair on the given \fIcurve\fR. -.PP -All of the functions described below are deprecated. -Applications should instead use \fBEVP_EC_gen()\fR, \fBEVP_PKEY_Q_keygen\fR\|(3), or -\&\fBEVP_PKEY_keygen_init\fR\|(3) and \fBEVP_PKEY_keygen\fR\|(3). -.PP -An \s-1EC_KEY\s0 represents a public key and, optionally, the associated private -key. -A new \s-1EC_KEY\s0 with no associated curve can be constructed by calling -\&\fBEC_KEY_new_ex()\fR and specifying the associated library context in \fIctx\fR -(see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) and property query string \fIpropq\fR. -The \fIctx\fR parameter may be \s-1NULL\s0 in which case the default library context is -used. -The reference count for the newly created \s-1EC_KEY\s0 is initially -set to 1. -A curve can be associated with the \s-1EC_KEY\s0 by calling -\&\fBEC_KEY_set_group()\fR. -.PP -\&\fBEC_KEY_new()\fR is the same as \fBEC_KEY_new_ex()\fR except that the default library -context is always used. -.PP -Alternatively a new \s-1EC_KEY\s0 can be constructed by calling -\&\fBEC_KEY_new_by_curve_name_ex()\fR and supplying the nid of the associated -curve, the library context to be used \fIctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) and any -property query string \fIpropq\fR. -The \fIctx\fR parameter may be \s-1NULL\s0 in which case the default library context is -used. The \fIpropq\fR value may also be \s-1NULL.\s0 -See \fBEC_GROUP_new\fR\|(3) for a description of curve names. -This function simply wraps calls to \fBEC_KEY_new_ex()\fR and -\&\fBEC_GROUP_new_by_curve_name_ex()\fR. -.PP -\&\fBEC_KEY_new_by_curve_name()\fR is the same as \fBEC_KEY_new_by_curve_name_ex()\fR -except that the default library context is always used and a \s-1NULL\s0 property query -string. -.PP -Calling \fBEC_KEY_free()\fR decrements the reference count for the \s-1EC_KEY\s0 object, -and if it has dropped to zero then frees the memory associated with it. If -\&\fIkey\fR is \s-1NULL\s0 nothing is done. -.PP -\&\fBEC_KEY_copy()\fR copies the contents of the \s-1EC_KEY\s0 in \fIsrc\fR into \fIdest\fR. -.PP -\&\fBEC_KEY_dup()\fR creates a new \s-1EC_KEY\s0 object and copies \fIec_key\fR into it. -.PP -\&\fBEC_KEY_up_ref()\fR increments the reference count associated with the \s-1EC_KEY\s0 -object. -.PP -\&\fBEC_KEY_get0_engine()\fR returns a handle to the \s-1ENGINE\s0 that has been set for -this \s-1EC_KEY\s0 object. -.PP -\&\fBEC_KEY_generate_key()\fR generates a new public and private key for the supplied -\&\fIeckey\fR object. \fIeckey\fR must have an \s-1EC_GROUP\s0 object associated with it -before calling this function. The private key is a random integer (0 < priv_key -< order, where \fIorder\fR is the order of the \s-1EC_GROUP\s0 object). The public key is -an \s-1EC_POINT\s0 on the curve calculated by multiplying the generator for the -curve by the private key. -.PP -\&\fBEC_KEY_check_key()\fR performs various sanity checks on the \s-1EC_KEY\s0 object to -confirm that it is valid. -.PP -\&\fBEC_KEY_set_public_key_affine_coordinates()\fR sets the public key for \fIkey\fR based -on its affine coordinates; i.e., it constructs an \s-1EC_POINT\s0 object based on -the supplied \fIx\fR and \fIy\fR values and sets the public key to be this -\&\s-1EC_POINT.\s0 It also performs certain sanity checks on the key to confirm -that it is valid. -.PP -The functions \fBEC_KEY_get0_group()\fR, \fBEC_KEY_set_group()\fR, -\&\fBEC_KEY_get0_private_key()\fR, \fBEC_KEY_set_private_key()\fR, \fBEC_KEY_get0_public_key()\fR, -and \fBEC_KEY_set_public_key()\fR get and set the \s-1EC_GROUP\s0 object, the private key, -and the \s-1EC_POINT\s0 public key for the \fBkey\fR respectively. The function -\&\fBEC_KEY_set_private_key()\fR accepts \s-1NULL\s0 as the priv_key argument to securely clear -the private key component from the \s-1EC_KEY.\s0 -.PP -The functions \fBEC_KEY_get_conv_form()\fR and \fBEC_KEY_set_conv_form()\fR get and set the -point_conversion_form for the \fIkey\fR. For a description of -point_conversion_forms please see \fBEC_POINT_new\fR\|(3). -.PP -\&\fBEC_KEY_set_flags()\fR sets the flags in the \fIflags\fR parameter on the \s-1EC_KEY\s0 -object. Any flags that are already set are left set. The flags currently -defined are \s-1EC_FLAG_NON_FIPS_ALLOW\s0 and \s-1EC_FLAG_FIPS_CHECKED.\s0 In -addition there is the flag \s-1EC_FLAG_COFACTOR_ECDH\s0 which is specific to \s-1ECDH.\s0 -\&\fBEC_KEY_get_flags()\fR returns the current flags that are set for this \s-1EC_KEY.\s0 -\&\fBEC_KEY_clear_flags()\fR clears the flags indicated by the \fIflags\fR parameter; all -other flags are left in their existing state. -.PP -\&\fBEC_KEY_set_asn1_flag()\fR sets the asn1_flag on the underlying \s-1EC_GROUP\s0 object -(if set). Refer to \fBEC_GROUP_copy\fR\|(3) for further information on the -asn1_flag. -.PP -\&\fBEC_KEY_decoded_from_explicit_params()\fR returns 1 if the group of the \fIkey\fR was -decoded from data with explicitly encoded group parameters, \-1 if the \fIkey\fR -is \s-1NULL\s0 or the group parameters are missing, and 0 otherwise. -.PP -\&\fBEC_KEY_precompute_mult()\fR stores multiples of the underlying \s-1EC_GROUP\s0 generator -for faster point multiplication. See also \fBEC_POINT_add\fR\|(3). -Modern versions should instead switch to named curves which OpenSSL has -hardcoded lookup tables for. -.PP -\&\fBEC_KEY_oct2key()\fR and \fBEC_KEY_key2buf()\fR are identical to the functions -\&\fBEC_POINT_oct2point()\fR and \fBEC_POINT_point2buf()\fR except they use the public key -\&\s-1EC_POINT\s0 in \fIeckey\fR. -.PP -\&\fBEC_KEY_oct2priv()\fR and \fBEC_KEY_priv2oct()\fR convert between the private key -component of \fIeckey\fR and octet form. The octet form consists of the content -octets of the \fIprivateKey\fR \s-1OCTET STRING\s0 in an \fIECPrivateKey\fR \s-1ASN.1\s0 structure. -.PP -The function \fBEC_KEY_priv2oct()\fR must be supplied with a buffer long enough to -store the octet form. The return value provides the number of octets stored. -Calling the function with a \s-1NULL\s0 buffer will not perform the conversion but -will just return the required buffer length. -.PP -The function \fBEC_KEY_priv2buf()\fR allocates a buffer of suitable length and writes -an \s-1EC_KEY\s0 to it in octet format. The allocated buffer is written to \fI*pbuf\fR -and its length is returned. The caller must free up the allocated buffer with a -call to \fBOPENSSL_free()\fR. Since the allocated buffer value is written to \fI*pbuf\fR -the \fIpbuf\fR parameter \fB\s-1MUST NOT\s0\fR be \fB\s-1NULL\s0\fR. -.PP -\&\fBEC_KEY_priv2buf()\fR converts an \s-1EC_KEY\s0 private key into an allocated buffer. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEC_KEY_new_ex()\fR, \fBEC_KEY_new()\fR, \fBEC_KEY_new_by_curve_name_ex()\fR, -\&\fBEC_KEY_new_by_curve_name()\fR and \fBEC_KEY_dup()\fR return a pointer to the newly -created \s-1EC_KEY\s0 object, or \s-1NULL\s0 on error. -.PP -\&\fBEC_KEY_get_flags()\fR returns the flags associated with the \s-1EC_KEY\s0 object as an -integer. -.PP -\&\fBEC_KEY_copy()\fR returns a pointer to the destination key, or \s-1NULL\s0 on error. -.PP -\&\fBEC_KEY_get0_engine()\fR returns a pointer to an \s-1ENGINE,\s0 or \s-1NULL\s0 if it wasn't set. -.PP -\&\fBEC_KEY_up_ref()\fR, \fBEC_KEY_set_group()\fR, \fBEC_KEY_set_public_key()\fR, -\&\fBEC_KEY_precompute_mult()\fR, \fBEC_KEY_generate_key()\fR, \fBEC_KEY_check_key()\fR, -\&\fBEC_KEY_set_public_key_affine_coordinates()\fR, \fBEC_KEY_oct2key()\fR and -\&\fBEC_KEY_oct2priv()\fR return 1 on success or 0 on error. -.PP -\&\fBEC_KEY_set_private_key()\fR returns 1 on success or 0 on error except when the -priv_key argument is \s-1NULL,\s0 in that case it returns 0, for legacy compatibility, -and should not be treated as an error. -.PP -\&\fBEC_KEY_get0_group()\fR returns the \s-1EC_GROUP\s0 associated with the \s-1EC_KEY.\s0 -.PP -\&\fBEC_KEY_get0_private_key()\fR returns the private key associated with the \s-1EC_KEY.\s0 -.PP -\&\fBEC_KEY_get_conv_form()\fR return the point_conversion_form for the \s-1EC_KEY.\s0 -.PP -\&\fBEC_KEY_key2buf()\fR, \fBEC_KEY_priv2oct()\fR and \fBEC_KEY_priv2buf()\fR return the length -of the buffer or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_Q_keygen\fR\|(3) -\&\fBcrypto\fR\|(7), \fBEC_GROUP_new\fR\|(3), -\&\fBEC_GROUP_copy\fR\|(3), \fBEC_POINT_new\fR\|(3), -\&\fBEC_POINT_add\fR\|(3), -\&\fBEC_GFp_simple_method\fR\|(3), -\&\fBd2i_ECPKParameters\fR\|(3), -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_EC_gen()\fR was added in OpenSSL 3.0. -All other functions described here were deprecated in OpenSSL 3.0. -For replacement see \s-1\fBEVP_PKEY\-EC\s0\fR\|(7). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EC_KEY_new_by_curve_name.3ossl b/openssl-install/share/man/man3/EC_KEY_new_by_curve_name.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_new_by_curve_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_new_by_curve_name_ex.3ossl b/openssl-install/share/man/man3/EC_KEY_new_by_curve_name_ex.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_new_by_curve_name_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_new_ex.3ossl b/openssl-install/share/man/man3/EC_KEY_new_ex.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_oct2key.3ossl b/openssl-install/share/man/man3/EC_KEY_oct2key.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_oct2key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_oct2priv.3ossl b/openssl-install/share/man/man3/EC_KEY_oct2priv.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_oct2priv.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_precompute_mult.3ossl b/openssl-install/share/man/man3/EC_KEY_precompute_mult.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_precompute_mult.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_priv2buf.3ossl b/openssl-install/share/man/man3/EC_KEY_priv2buf.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_priv2buf.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_priv2oct.3ossl b/openssl-install/share/man/man3/EC_KEY_priv2oct.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_priv2oct.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_asn1_flag.3ossl b/openssl-install/share/man/man3/EC_KEY_set_asn1_flag.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_asn1_flag.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_conv_form.3ossl b/openssl-install/share/man/man3/EC_KEY_set_conv_form.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_conv_form.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_enc_flags.3ossl b/openssl-install/share/man/man3/EC_KEY_set_enc_flags.3ossl deleted file mode 120000 index 6cbc931c..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_enc_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_get_enc_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_ex_data.3ossl b/openssl-install/share/man/man3/EC_KEY_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_flags.3ossl b/openssl-install/share/man/man3/EC_KEY_set_flags.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_group.3ossl b/openssl-install/share/man/man3/EC_KEY_set_group.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_group.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_method.3ossl b/openssl-install/share/man/man3/EC_KEY_set_method.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_private_key.3ossl b/openssl-install/share/man/man3/EC_KEY_set_private_key.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_public_key.3ossl b/openssl-install/share/man/man3/EC_KEY_set_public_key.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_set_public_key_affine_coordinates.3ossl b/openssl-install/share/man/man3/EC_KEY_set_public_key_affine_coordinates.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_set_public_key_affine_coordinates.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_KEY_up_ref.3ossl b/openssl-install/share/man/man3/EC_KEY_up_ref.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EC_KEY_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_METHOD_get_field_type.3ossl b/openssl-install/share/man/man3/EC_METHOD_get_field_type.3ossl deleted file mode 120000 index e61b62fe..00000000 --- a/openssl-install/share/man/man3/EC_METHOD_get_field_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GFp_simple_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_add.3ossl b/openssl-install/share/man/man3/EC_POINT_add.3ossl deleted file mode 100644 index bb390976..00000000 --- a/openssl-install/share/man/man3/EC_POINT_add.3ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EC_POINT_ADD 3ossl" -.TH EC_POINT_ADD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EC_POINT_add, EC_POINT_dbl, EC_POINT_invert, EC_POINT_is_at_infinity, EC_POINT_is_on_curve, EC_POINT_cmp, EC_POINT_make_affine, EC_POINTs_make_affine, EC_POINTs_mul, EC_POINT_mul, EC_GROUP_precompute_mult, EC_GROUP_have_precompute_mult \- Functions for performing mathematical operations and tests on EC_POINT objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EC_POINT_add(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a, -\& const EC_POINT *b, BN_CTX *ctx); -\& int EC_POINT_dbl(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a, BN_CTX *ctx); -\& int EC_POINT_invert(const EC_GROUP *group, EC_POINT *a, BN_CTX *ctx); -\& int EC_POINT_is_at_infinity(const EC_GROUP *group, const EC_POINT *p); -\& int EC_POINT_is_on_curve(const EC_GROUP *group, const EC_POINT *point, BN_CTX *ctx); -\& int EC_POINT_cmp(const EC_GROUP *group, const EC_POINT *a, const EC_POINT *b, BN_CTX *ctx); -\& int EC_POINT_mul(const EC_GROUP *group, EC_POINT *r, const BIGNUM *n, -\& const EC_POINT *q, const BIGNUM *m, BN_CTX *ctx); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 7 -\& int EC_POINT_make_affine(const EC_GROUP *group, EC_POINT *point, BN_CTX *ctx); -\& int EC_POINTs_make_affine(const EC_GROUP *group, size_t num, -\& EC_POINT *points[], BN_CTX *ctx); -\& int EC_POINTs_mul(const EC_GROUP *group, EC_POINT *r, const BIGNUM *n, size_t num, -\& const EC_POINT *p[], const BIGNUM *m[], BN_CTX *ctx); -\& int EC_GROUP_precompute_mult(EC_GROUP *group, BN_CTX *ctx); -\& int EC_GROUP_have_precompute_mult(const EC_GROUP *group); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -EC_POINT_add adds the two points \fBa\fR and \fBb\fR and places the result in \fBr\fR. Similarly EC_POINT_dbl doubles the point \fBa\fR and places the -result in \fBr\fR. In both cases it is valid for \fBr\fR to be one of \fBa\fR or \fBb\fR. -.PP -EC_POINT_invert calculates the inverse of the supplied point \fBa\fR. The result is placed back in \fBa\fR. -.PP -The function EC_POINT_is_at_infinity tests whether the supplied point is at infinity or not. -.PP -EC_POINT_is_on_curve tests whether the supplied point is on the curve or not. -.PP -EC_POINT_cmp compares the two supplied points and tests whether or not they are equal. -.PP -The functions EC_POINT_make_affine and EC_POINTs_make_affine force the internal representation of the \s-1EC_POINT\s0(s) into the affine -coordinate system. In the case of EC_POINTs_make_affine the value \fBnum\fR provides the number of points in the array \fBpoints\fR to be -forced. These functions were deprecated in OpenSSL 3.0 and should no longer be used. -Modern versions automatically perform this conversion when needed. -.PP -EC_POINT_mul calculates the value generator * \fBn\fR + \fBq\fR * \fBm\fR and stores the result in \fBr\fR. -The value \fBn\fR may be \s-1NULL\s0 in which case the result is just \fBq\fR * \fBm\fR (variable point multiplication). Alternatively, both \fBq\fR and \fBm\fR may be \s-1NULL,\s0 and \fBn\fR non-NULL, in which case the result is just generator * \fBn\fR (fixed point multiplication). -When performing a single fixed or variable point multiplication, the underlying implementation uses a constant time algorithm, when the input scalar (either \fBn\fR or \fBm\fR) is in the range [0, ec_group_order). -.PP -Although deprecated in OpenSSL 3.0 and should no longer be used, -EC_POINTs_mul calculates the value generator * \fBn\fR + \fBq[0]\fR * \fBm[0]\fR + ... + \fBq[num\-1]\fR * \fBm[num\-1]\fR. As for EC_POINT_mul the value \fBn\fR may be \s-1NULL\s0 or \fBnum\fR may be zero. -When performing a fixed point multiplication (\fBn\fR is non-NULL and \fBnum\fR is 0) or a variable point multiplication (\fBn\fR is \s-1NULL\s0 and \fBnum\fR is 1), the underlying implementation uses a constant time algorithm, when the input scalar (either \fBn\fR or \fBm[0]\fR) is in the range [0, ec_group_order). -Modern versions should instead use \fBEC_POINT_mul()\fR, combined (if needed) with \fBEC_POINT_add()\fR in such rare circumstances. -.PP -The function EC_GROUP_precompute_mult stores multiples of the generator for faster point multiplication, whilst -EC_GROUP_have_precompute_mult tests whether precomputation has already been done. See \fBEC_GROUP_copy\fR\|(3) for information -about the generator. Precomputation functionality was deprecated in OpenSSL 3.0. -Users of \fBEC_GROUP_precompute_mult()\fR and \fBEC_GROUP_have_precompute_mult()\fR should -switch to named curves which OpenSSL has hardcoded lookup tables for. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following functions return 1 on success or 0 on error: EC_POINT_add, EC_POINT_dbl, EC_POINT_invert, EC_POINT_make_affine, -EC_POINTs_make_affine, EC_POINTs_make_affine, EC_POINT_mul, EC_POINTs_mul and EC_GROUP_precompute_mult. -.PP -EC_POINT_is_at_infinity returns 1 if the point is at infinity, or 0 otherwise. -.PP -EC_POINT_is_on_curve returns 1 if the point is on the curve, 0 if not, or \-1 on error. -.PP -EC_POINT_cmp returns 1 if the points are not equal, 0 if they are, or \-1 on error. -.PP -EC_GROUP_have_precompute_mult return 1 if a precomputation has been done, or 0 if not. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBEC_GROUP_new\fR\|(3), \fBEC_GROUP_copy\fR\|(3), -\&\fBEC_POINT_new\fR\|(3), \fBEC_KEY_new\fR\|(3), -\&\fBEC_GFp_simple_method\fR\|(3), \fBd2i_ECPKParameters\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEC_POINT_make_affine()\fR, \fBEC_POINTs_make_affine()\fR, \fBEC_POINTs_mul()\fR, -\&\fBEC_GROUP_precompute_mult()\fR, and \fBEC_GROUP_have_precompute_mult()\fR -were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EC_POINT_bn2point.3ossl b/openssl-install/share/man/man3/EC_POINT_bn2point.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_bn2point.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_clear_free.3ossl b/openssl-install/share/man/man3/EC_POINT_clear_free.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_clear_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_cmp.3ossl b/openssl-install/share/man/man3/EC_POINT_cmp.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINT_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_copy.3ossl b/openssl-install/share/man/man3/EC_POINT_copy.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_dbl.3ossl b/openssl-install/share/man/man3/EC_POINT_dbl.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINT_dbl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_dup.3ossl b/openssl-install/share/man/man3/EC_POINT_dup.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_free.3ossl b/openssl-install/share/man/man3/EC_POINT_free.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_get_Jprojective_coordinates_GFp.3ossl b/openssl-install/share/man/man3/EC_POINT_get_Jprojective_coordinates_GFp.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_get_Jprojective_coordinates_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates.3ossl b/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GF2m.3ossl b/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GF2m.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GF2m.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GFp.3ossl b/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GFp.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_get_affine_coordinates_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_hex2point.3ossl b/openssl-install/share/man/man3/EC_POINT_hex2point.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_hex2point.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_invert.3ossl b/openssl-install/share/man/man3/EC_POINT_invert.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINT_invert.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_is_at_infinity.3ossl b/openssl-install/share/man/man3/EC_POINT_is_at_infinity.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINT_is_at_infinity.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_is_on_curve.3ossl b/openssl-install/share/man/man3/EC_POINT_is_on_curve.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINT_is_on_curve.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_make_affine.3ossl b/openssl-install/share/man/man3/EC_POINT_make_affine.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINT_make_affine.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_method_of.3ossl b/openssl-install/share/man/man3/EC_POINT_method_of.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_method_of.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_mul.3ossl b/openssl-install/share/man/man3/EC_POINT_mul.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINT_mul.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_new.3ossl b/openssl-install/share/man/man3/EC_POINT_new.3ossl deleted file mode 100644 index 1b6bb650..00000000 --- a/openssl-install/share/man/man3/EC_POINT_new.3ossl +++ /dev/null @@ -1,411 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EC_POINT_NEW 3ossl" -.TH EC_POINT_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EC_POINT_set_Jprojective_coordinates_GFp, -EC_POINT_point2buf, -EC_POINT_new, -EC_POINT_free, -EC_POINT_clear_free, -EC_POINT_copy, -EC_POINT_dup, -EC_POINT_method_of, -EC_POINT_set_to_infinity, -EC_POINT_get_Jprojective_coordinates_GFp, -EC_POINT_set_affine_coordinates, -EC_POINT_get_affine_coordinates, -EC_POINT_set_compressed_coordinates, -EC_POINT_set_affine_coordinates_GFp, -EC_POINT_get_affine_coordinates_GFp, -EC_POINT_set_compressed_coordinates_GFp, -EC_POINT_set_affine_coordinates_GF2m, -EC_POINT_get_affine_coordinates_GF2m, -EC_POINT_set_compressed_coordinates_GF2m, -EC_POINT_point2oct, -EC_POINT_oct2point, -EC_POINT_point2bn, -EC_POINT_bn2point, -EC_POINT_point2hex, -EC_POINT_hex2point -\&\- Functions for creating, destroying and manipulating EC_POINT objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EC_POINT *EC_POINT_new(const EC_GROUP *group); -\& void EC_POINT_free(EC_POINT *point); -\& void EC_POINT_clear_free(EC_POINT *point); -\& int EC_POINT_copy(EC_POINT *dst, const EC_POINT *src); -\& EC_POINT *EC_POINT_dup(const EC_POINT *src, const EC_GROUP *group); -\& int EC_POINT_set_to_infinity(const EC_GROUP *group, EC_POINT *point); -\& int EC_POINT_set_affine_coordinates(const EC_GROUP *group, EC_POINT *p, -\& const BIGNUM *x, const BIGNUM *y, -\& BN_CTX *ctx); -\& int EC_POINT_get_affine_coordinates(const EC_GROUP *group, const EC_POINT *p, -\& BIGNUM *x, BIGNUM *y, BN_CTX *ctx); -\& int EC_POINT_set_compressed_coordinates(const EC_GROUP *group, EC_POINT *p, -\& const BIGNUM *x, int y_bit, -\& BN_CTX *ctx); -\& size_t EC_POINT_point2oct(const EC_GROUP *group, const EC_POINT *p, -\& point_conversion_form_t form, -\& unsigned char *buf, size_t len, BN_CTX *ctx); -\& size_t EC_POINT_point2buf(const EC_GROUP *group, const EC_POINT *point, -\& point_conversion_form_t form, -\& unsigned char **pbuf, BN_CTX *ctx); -\& int EC_POINT_oct2point(const EC_GROUP *group, EC_POINT *p, -\& const unsigned char *buf, size_t len, BN_CTX *ctx); -\& char *EC_POINT_point2hex(const EC_GROUP *group, const EC_POINT *p, -\& point_conversion_form_t form, BN_CTX *ctx); -\& EC_POINT *EC_POINT_hex2point(const EC_GROUP *group, const char *hex, -\& EC_POINT *p, BN_CTX *ctx); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& const EC_METHOD *EC_POINT_method_of(const EC_POINT *point); -\& int EC_POINT_set_Jprojective_coordinates_GFp(const EC_GROUP *group, -\& EC_POINT *p, -\& const BIGNUM *x, const BIGNUM *y, -\& const BIGNUM *z, BN_CTX *ctx); -\& int EC_POINT_get_Jprojective_coordinates_GFp(const EC_GROUP *group, -\& const EC_POINT *p, -\& BIGNUM *x, BIGNUM *y, BIGNUM *z, -\& BN_CTX *ctx); -\& int EC_POINT_set_affine_coordinates_GFp(const EC_GROUP *group, EC_POINT *p, -\& const BIGNUM *x, const BIGNUM *y, -\& BN_CTX *ctx); -\& int EC_POINT_get_affine_coordinates_GFp(const EC_GROUP *group, -\& const EC_POINT *p, -\& BIGNUM *x, BIGNUM *y, BN_CTX *ctx); -\& int EC_POINT_set_compressed_coordinates_GFp(const EC_GROUP *group, -\& EC_POINT *p, -\& const BIGNUM *x, int y_bit, -\& BN_CTX *ctx); -\& int EC_POINT_set_affine_coordinates_GF2m(const EC_GROUP *group, EC_POINT *p, -\& const BIGNUM *x, const BIGNUM *y, -\& BN_CTX *ctx); -\& int EC_POINT_get_affine_coordinates_GF2m(const EC_GROUP *group, -\& const EC_POINT *p, -\& BIGNUM *x, BIGNUM *y, BN_CTX *ctx); -\& int EC_POINT_set_compressed_coordinates_GF2m(const EC_GROUP *group, -\& EC_POINT *p, -\& const BIGNUM *x, int y_bit, -\& BN_CTX *ctx); -\& BIGNUM *EC_POINT_point2bn(const EC_GROUP *group, const EC_POINT *p, -\& point_conversion_form_t form, BIGNUM *bn, -\& BN_CTX *ctx); -\& EC_POINT *EC_POINT_bn2point(const EC_GROUP *group, const BIGNUM *bn, -\& EC_POINT *p, BN_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -An \fB\s-1EC_POINT\s0\fR structure represents a point on a curve. A new point is -constructed by calling the function \fBEC_POINT_new()\fR and providing the -\&\fBgroup\fR object that the point relates to. -.PP -\&\fBEC_POINT_free()\fR frees the memory associated with the \fB\s-1EC_POINT\s0\fR. -if \fBpoint\fR is \s-1NULL\s0 nothing is done. -.PP -\&\fBEC_POINT_clear_free()\fR destroys any sensitive data held within the \s-1EC_POINT\s0 and -then frees its memory. If \fBpoint\fR is \s-1NULL\s0 nothing is done. -.PP -\&\fBEC_POINT_copy()\fR copies the point \fBsrc\fR into \fBdst\fR. Both \fBsrc\fR and \fBdst\fR -must use the same \fB\s-1EC_METHOD\s0\fR. -.PP -\&\fBEC_POINT_dup()\fR creates a new \fB\s-1EC_POINT\s0\fR object and copies the content from -\&\fBsrc\fR to the newly created \fB\s-1EC_POINT\s0\fR object. -.PP -\&\fBEC_POINT_method_of()\fR obtains the \fB\s-1EC_METHOD\s0\fR associated with \fBpoint\fR. -This function was deprecated in OpenSSL 3.0, since \s-1EC_METHOD\s0 is no longer a -public concept. -.PP -A valid point on a curve is the special point at infinity. A point is set to -be at infinity by calling \fBEC_POINT_set_to_infinity()\fR. -.PP -The affine coordinates for a point describe a point in terms of its x and y -position. The function \fBEC_POINT_set_affine_coordinates()\fR sets the \fBx\fR and \fBy\fR -coordinates for the point \fBp\fR defined over the curve given in \fBgroup\fR. The -function \fBEC_POINT_get_affine_coordinates()\fR sets \fBx\fR and \fBy\fR, either of which -may be \s-1NULL,\s0 to the corresponding coordinates of \fBp\fR. -.PP -The functions \fBEC_POINT_set_affine_coordinates_GFp()\fR and -\&\fBEC_POINT_set_affine_coordinates_GF2m()\fR are synonyms for -\&\fBEC_POINT_set_affine_coordinates()\fR. They are defined for backwards compatibility -only and should not be used. -.PP -The functions \fBEC_POINT_get_affine_coordinates_GFp()\fR and -\&\fBEC_POINT_get_affine_coordinates_GF2m()\fR are synonyms for -\&\fBEC_POINT_get_affine_coordinates()\fR. They are defined for backwards compatibility -only and should not be used. -.PP -As well as the affine coordinates, a point can alternatively be described in -terms of its Jacobian projective coordinates (for Fp curves only). Jacobian -projective coordinates are expressed as three values x, y and z. Working in -this coordinate system provides more efficient point multiplication -operations. A mapping exists between Jacobian projective coordinates and -affine coordinates. A Jacobian projective coordinate (x, y, z) can be written -as an affine coordinate as (x/(z^2), y/(z^3)). Conversion to Jacobian -projective from affine coordinates is simple. The coordinate (x, y) is mapped -to (x, y, 1). Although deprecated in OpenSSL 3.0 and should no longer be used, -to set or get the projective coordinates in older versions use -\&\fBEC_POINT_set_Jprojective_coordinates_GFp()\fR and -\&\fBEC_POINT_get_Jprojective_coordinates_GFp()\fR respectively. -Modern versions should instead use \fBEC_POINT_set_affine_coordinates()\fR and -\&\fBEC_POINT_get_affine_coordinates()\fR, performing the conversion manually using the -above maps in such rare circumstances. -.PP -Points can also be described in terms of their compressed coordinates. For a -point (x, y), for any given value for x such that the point is on the curve -there will only ever be two possible values for y. Therefore, a point can be set -using the \fBEC_POINT_set_compressed_coordinates()\fR function where \fBx\fR is the x -coordinate and \fBy_bit\fR is a value 0 or 1 to identify which of the two -possible values for y should be used. -.PP -The functions \fBEC_POINT_set_compressed_coordinates_GFp()\fR and -\&\fBEC_POINT_set_compressed_coordinates_GF2m()\fR are synonyms for -\&\fBEC_POINT_set_compressed_coordinates()\fR. They are defined for backwards -compatibility only and should not be used. -.PP -In addition \fB\s-1EC_POINT\s0\fR can be converted to and from various external -representations. The octet form is the binary encoding of the \fBECPoint\fR -structure (as defined in \s-1RFC5480\s0 and used in certificates and \s-1TLS\s0 records): -only the content octets are present, the \fB\s-1OCTET STRING\s0\fR tag and length are -not included. \fB\s-1BIGNUM\s0\fR form is the octet form interpreted as a big endian -integer converted to a \fB\s-1BIGNUM\s0\fR structure. Hexadecimal form is the octet -form converted to a \s-1NULL\s0 terminated character string where each character -is one of the printable values 0\-9 or A\-F (or a\-f). -.PP -The functions \fBEC_POINT_point2oct()\fR, \fBEC_POINT_oct2point()\fR, \fBEC_POINT_point2bn()\fR, -\&\fBEC_POINT_bn2point()\fR, \fBEC_POINT_point2hex()\fR and \fBEC_POINT_hex2point()\fR convert from -and to EC_POINTs for the formats: octet, \s-1BIGNUM\s0 and hexadecimal respectively. -.PP -The function \fBEC_POINT_point2oct()\fR encodes the given curve point \fBp\fR as an -octet string into the buffer \fBbuf\fR of size \fBlen\fR, using the specified -conversion form \fBform\fR. -The encoding conforms with Sec. 2.3.3 of the \s-1SECG SEC 1\s0 (\*(L"Elliptic Curve -Cryptography\*(R") standard. -Similarly the function \fBEC_POINT_oct2point()\fR decodes a curve point into \fBp\fR from -the octet string contained in the given buffer \fBbuf\fR of size \fBlen\fR, conforming -to Sec. 2.3.4 of the \s-1SECG SEC 1\s0 (\*(L"Elliptic Curve Cryptography\*(R") standard. -.PP -The functions \fBEC_POINT_point2hex()\fR and \fBEC_POINT_point2bn()\fR convert a point \fBp\fR, -respectively, to the hexadecimal or \s-1BIGNUM\s0 representation of the same -encoding of the function \fBEC_POINT_point2oct()\fR. -Vice versa, similarly to the function \fBEC_POINT_oct2point()\fR, the functions -\&\fBEC_POINT_hex2point()\fR and \fBEC_POINT_point2bn()\fR decode the hexadecimal or -\&\s-1BIGNUM\s0 representation into the \s-1EC_POINT\s0 \fBp\fR. -.PP -Notice that, according to the standard, the octet string encoding of the point -at infinity for a given curve is fixed to a single octet of value zero and that, -vice versa, a single octet of size zero is decoded as the point at infinity. -.PP -The function \fBEC_POINT_point2oct()\fR must be supplied with a buffer long enough to -store the octet form. The return value provides the number of octets stored. -Calling the function with a \s-1NULL\s0 buffer will not perform the conversion but -will still return the required buffer length. -.PP -The function \fBEC_POINT_point2buf()\fR allocates a buffer of suitable length and -writes an \s-1EC_POINT\s0 to it in octet format. The allocated buffer is written to -\&\fB*pbuf\fR and its length is returned. The caller must free up the allocated -buffer with a call to \fBOPENSSL_free()\fR. Since the allocated buffer value is -written to \fB*pbuf\fR the \fBpbuf\fR parameter \fB\s-1MUST NOT\s0\fR be \fB\s-1NULL\s0\fR. -.PP -The function \fBEC_POINT_point2hex()\fR will allocate sufficient memory to store the -hexadecimal string. It is the caller's responsibility to free this memory with -a subsequent call to \fBOPENSSL_free()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEC_POINT_new()\fR and \fBEC_POINT_dup()\fR return the newly allocated \s-1EC_POINT\s0 or \s-1NULL\s0 -on error. -.PP -The following functions return 1 on success or 0 on error: \fBEC_POINT_copy()\fR, -\&\fBEC_POINT_set_to_infinity()\fR, \fBEC_POINT_set_Jprojective_coordinates_GFp()\fR, -\&\fBEC_POINT_get_Jprojective_coordinates_GFp()\fR, -\&\fBEC_POINT_set_affine_coordinates_GFp()\fR, \fBEC_POINT_get_affine_coordinates_GFp()\fR, -\&\fBEC_POINT_set_compressed_coordinates_GFp()\fR, -\&\fBEC_POINT_set_affine_coordinates_GF2m()\fR, \fBEC_POINT_get_affine_coordinates_GF2m()\fR, -\&\fBEC_POINT_set_compressed_coordinates_GF2m()\fR and \fBEC_POINT_oct2point()\fR. -.PP -EC_POINT_method_of returns the \s-1EC_METHOD\s0 associated with the supplied \s-1EC_POINT.\s0 -.PP -\&\fBEC_POINT_point2oct()\fR and \fBEC_POINT_point2buf()\fR return the length of the required -buffer or 0 on error. -.PP -\&\fBEC_POINT_point2bn()\fR returns the pointer to the \s-1BIGNUM\s0 supplied, or \s-1NULL\s0 on -error. -.PP -\&\fBEC_POINT_bn2point()\fR returns the pointer to the \s-1EC_POINT\s0 supplied, or \s-1NULL\s0 on -error. -.PP -\&\fBEC_POINT_point2hex()\fR returns a pointer to the hex string, or \s-1NULL\s0 on error. -.PP -\&\fBEC_POINT_hex2point()\fR returns the pointer to the \s-1EC_POINT\s0 supplied, or \s-1NULL\s0 on -error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBEC_GROUP_new\fR\|(3), \fBEC_GROUP_copy\fR\|(3), -\&\fBEC_POINT_add\fR\|(3), \fBEC_KEY_new\fR\|(3), -\&\fBEC_GFp_simple_method\fR\|(3), \fBd2i_ECPKParameters\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEC_POINT_method_of()\fR, -\&\fBEC_POINT_set_Jprojective_coordinates_GFp()\fR, -\&\fBEC_POINT_get_Jprojective_coordinates_GFp()\fR, -\&\fBEC_POINT_set_affine_coordinates_GFp()\fR, \fBEC_POINT_get_affine_coordinates_GFp()\fR, -\&\fBEC_POINT_set_compressed_coordinates_GFp()\fR, -\&\fBEC_POINT_set_affine_coordinates_GF2m()\fR, \fBEC_POINT_get_affine_coordinates_GF2m()\fR, -\&\fBEC_POINT_set_compressed_coordinates_GF2m()\fR, -\&\fBEC_POINT_point2bn()\fR, and \fBEC_POINT_bn2point()\fR were deprecated in OpenSSL 3.0. -.PP -\&\fBEC_POINT_set_affine_coordinates\fR, \fBEC_POINT_get_affine_coordinates\fR, -and \fBEC_POINT_set_compressed_coordinates\fR were -added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EC_POINT_oct2point.3ossl b/openssl-install/share/man/man3/EC_POINT_oct2point.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_oct2point.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_point2bn.3ossl b/openssl-install/share/man/man3/EC_POINT_point2bn.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_point2bn.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_point2buf.3ossl b/openssl-install/share/man/man3/EC_POINT_point2buf.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_point2buf.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_point2hex.3ossl b/openssl-install/share/man/man3/EC_POINT_point2hex.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_point2hex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_point2oct.3ossl b/openssl-install/share/man/man3/EC_POINT_point2oct.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_point2oct.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_Jprojective_coordinates_GFp.3ossl b/openssl-install/share/man/man3/EC_POINT_set_Jprojective_coordinates_GFp.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_Jprojective_coordinates_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates.3ossl b/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GF2m.3ossl b/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GF2m.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GF2m.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GFp.3ossl b/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GFp.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_affine_coordinates_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates.3ossl b/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GF2m.3ossl b/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GF2m.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GF2m.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GFp.3ossl b/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GFp.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_compressed_coordinates_GFp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINT_set_to_infinity.3ossl b/openssl-install/share/man/man3/EC_POINT_set_to_infinity.3ossl deleted file mode 120000 index 090f1175..00000000 --- a/openssl-install/share/man/man3/EC_POINT_set_to_infinity.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINTs_make_affine.3ossl b/openssl-install/share/man/man3/EC_POINTs_make_affine.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINTs_make_affine.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_POINTs_mul.3ossl b/openssl-install/share/man/man3/EC_POINTs_mul.3ossl deleted file mode 120000 index fb229834..00000000 --- a/openssl-install/share/man/man3/EC_POINTs_mul.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_POINT_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EC_get_builtin_curves.3ossl b/openssl-install/share/man/man3/EC_get_builtin_curves.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/EC_get_builtin_curves.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EDIPARTYNAME_free.3ossl b/openssl-install/share/man/man3/EDIPARTYNAME_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/EDIPARTYNAME_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EDIPARTYNAME_new.3ossl b/openssl-install/share/man/man3/EDIPARTYNAME_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/EDIPARTYNAME_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_add.3ossl b/openssl-install/share/man/man3/ENGINE_add.3ossl deleted file mode 100644 index 89a970a9..00000000 --- a/openssl-install/share/man/man3/ENGINE_add.3ossl +++ /dev/null @@ -1,816 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ENGINE_ADD 3ossl" -.TH ENGINE_ADD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ENGINE_get_DH, ENGINE_get_DSA, -ENGINE_by_id, ENGINE_get_cipher_engine, ENGINE_get_default_DH, -ENGINE_get_default_DSA, -ENGINE_get_default_RAND, -ENGINE_get_default_RSA, ENGINE_get_digest_engine, ENGINE_get_first, -ENGINE_get_last, ENGINE_get_next, ENGINE_get_prev, ENGINE_new, -ENGINE_get_ciphers, ENGINE_get_ctrl_function, ENGINE_get_digests, -ENGINE_get_destroy_function, ENGINE_get_finish_function, -ENGINE_get_init_function, ENGINE_get_load_privkey_function, -ENGINE_get_load_pubkey_function, ENGINE_load_private_key, -ENGINE_load_public_key, ENGINE_get_RAND, ENGINE_get_RSA, ENGINE_get_id, -ENGINE_get_name, ENGINE_get_cmd_defns, ENGINE_get_cipher, -ENGINE_get_digest, ENGINE_add, ENGINE_cmd_is_executable, -ENGINE_ctrl, ENGINE_ctrl_cmd, ENGINE_ctrl_cmd_string, -ENGINE_finish, ENGINE_free, ENGINE_get_flags, ENGINE_init, -ENGINE_register_DH, ENGINE_register_DSA, -ENGINE_register_RAND, ENGINE_register_RSA, -ENGINE_register_all_complete, ENGINE_register_ciphers, -ENGINE_register_complete, ENGINE_register_digests, ENGINE_remove, -ENGINE_set_DH, ENGINE_set_DSA, -ENGINE_set_RAND, ENGINE_set_RSA, ENGINE_set_ciphers, -ENGINE_set_cmd_defns, ENGINE_set_ctrl_function, ENGINE_set_default, -ENGINE_set_default_DH, ENGINE_set_default_DSA, -ENGINE_set_default_RAND, ENGINE_set_default_RSA, -ENGINE_set_default_ciphers, ENGINE_set_default_digests, -ENGINE_set_default_string, ENGINE_set_destroy_function, -ENGINE_set_digests, ENGINE_set_finish_function, ENGINE_set_flags, -ENGINE_set_id, ENGINE_set_init_function, ENGINE_set_load_privkey_function, -ENGINE_set_load_pubkey_function, ENGINE_set_name, ENGINE_up_ref, -ENGINE_get_table_flags, ENGINE_cleanup, -ENGINE_load_builtin_engines, ENGINE_register_all_DH, -ENGINE_register_all_DSA, -ENGINE_register_all_RAND, -ENGINE_register_all_RSA, ENGINE_register_all_ciphers, -ENGINE_register_all_digests, ENGINE_set_table_flags, ENGINE_unregister_DH, -ENGINE_unregister_DSA, -ENGINE_unregister_RAND, ENGINE_unregister_RSA, ENGINE_unregister_ciphers, -ENGINE_unregister_digests -\&\- ENGINE cryptographic module support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& ENGINE *ENGINE_get_first(void); -\& ENGINE *ENGINE_get_last(void); -\& ENGINE *ENGINE_get_next(ENGINE *e); -\& ENGINE *ENGINE_get_prev(ENGINE *e); -\& -\& int ENGINE_add(ENGINE *e); -\& int ENGINE_remove(ENGINE *e); -\& -\& ENGINE *ENGINE_by_id(const char *id); -\& -\& int ENGINE_init(ENGINE *e); -\& int ENGINE_finish(ENGINE *e); -\& -\& void ENGINE_load_builtin_engines(void); -\& -\& ENGINE *ENGINE_get_default_RSA(void); -\& ENGINE *ENGINE_get_default_DSA(void); -\& ENGINE *ENGINE_get_default_DH(void); -\& ENGINE *ENGINE_get_default_RAND(void); -\& ENGINE *ENGINE_get_cipher_engine(int nid); -\& ENGINE *ENGINE_get_digest_engine(int nid); -\& -\& int ENGINE_set_default_RSA(ENGINE *e); -\& int ENGINE_set_default_DSA(ENGINE *e); -\& int ENGINE_set_default_DH(ENGINE *e); -\& int ENGINE_set_default_RAND(ENGINE *e); -\& int ENGINE_set_default_ciphers(ENGINE *e); -\& int ENGINE_set_default_digests(ENGINE *e); -\& int ENGINE_set_default_string(ENGINE *e, const char *list); -\& -\& int ENGINE_set_default(ENGINE *e, unsigned int flags); -\& -\& unsigned int ENGINE_get_table_flags(void); -\& void ENGINE_set_table_flags(unsigned int flags); -\& -\& int ENGINE_register_RSA(ENGINE *e); -\& void ENGINE_unregister_RSA(ENGINE *e); -\& void ENGINE_register_all_RSA(void); -\& int ENGINE_register_DSA(ENGINE *e); -\& void ENGINE_unregister_DSA(ENGINE *e); -\& void ENGINE_register_all_DSA(void); -\& int ENGINE_register_DH(ENGINE *e); -\& void ENGINE_unregister_DH(ENGINE *e); -\& void ENGINE_register_all_DH(void); -\& int ENGINE_register_RAND(ENGINE *e); -\& void ENGINE_unregister_RAND(ENGINE *e); -\& void ENGINE_register_all_RAND(void); -\& int ENGINE_register_ciphers(ENGINE *e); -\& void ENGINE_unregister_ciphers(ENGINE *e); -\& void ENGINE_register_all_ciphers(void); -\& int ENGINE_register_digests(ENGINE *e); -\& void ENGINE_unregister_digests(ENGINE *e); -\& void ENGINE_register_all_digests(void); -\& int ENGINE_register_complete(ENGINE *e); -\& int ENGINE_register_all_complete(void); -\& -\& int ENGINE_ctrl(ENGINE *e, int cmd, long i, void *p, void (*f)(void)); -\& int ENGINE_cmd_is_executable(ENGINE *e, int cmd); -\& int ENGINE_ctrl_cmd(ENGINE *e, const char *cmd_name, -\& long i, void *p, void (*f)(void), int cmd_optional); -\& int ENGINE_ctrl_cmd_string(ENGINE *e, const char *cmd_name, const char *arg, -\& int cmd_optional); -\& -\& ENGINE *ENGINE_new(void); -\& int ENGINE_free(ENGINE *e); -\& int ENGINE_up_ref(ENGINE *e); -\& -\& int ENGINE_set_id(ENGINE *e, const char *id); -\& int ENGINE_set_name(ENGINE *e, const char *name); -\& int ENGINE_set_RSA(ENGINE *e, const RSA_METHOD *rsa_meth); -\& int ENGINE_set_DSA(ENGINE *e, const DSA_METHOD *dsa_meth); -\& int ENGINE_set_DH(ENGINE *e, const DH_METHOD *dh_meth); -\& int ENGINE_set_RAND(ENGINE *e, const RAND_METHOD *rand_meth); -\& int ENGINE_set_destroy_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR destroy_f); -\& int ENGINE_set_init_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR init_f); -\& int ENGINE_set_finish_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR finish_f); -\& int ENGINE_set_ctrl_function(ENGINE *e, ENGINE_CTRL_FUNC_PTR ctrl_f); -\& int ENGINE_set_load_privkey_function(ENGINE *e, ENGINE_LOAD_KEY_PTR loadpriv_f); -\& int ENGINE_set_load_pubkey_function(ENGINE *e, ENGINE_LOAD_KEY_PTR loadpub_f); -\& int ENGINE_set_ciphers(ENGINE *e, ENGINE_CIPHERS_PTR f); -\& int ENGINE_set_digests(ENGINE *e, ENGINE_DIGESTS_PTR f); -\& int ENGINE_set_flags(ENGINE *e, int flags); -\& int ENGINE_set_cmd_defns(ENGINE *e, const ENGINE_CMD_DEFN *defns); -\& -\& const char *ENGINE_get_id(const ENGINE *e); -\& const char *ENGINE_get_name(const ENGINE *e); -\& const RSA_METHOD *ENGINE_get_RSA(const ENGINE *e); -\& const DSA_METHOD *ENGINE_get_DSA(const ENGINE *e); -\& const DH_METHOD *ENGINE_get_DH(const ENGINE *e); -\& const RAND_METHOD *ENGINE_get_RAND(const ENGINE *e); -\& ENGINE_GEN_INT_FUNC_PTR ENGINE_get_destroy_function(const ENGINE *e); -\& ENGINE_GEN_INT_FUNC_PTR ENGINE_get_init_function(const ENGINE *e); -\& ENGINE_GEN_INT_FUNC_PTR ENGINE_get_finish_function(const ENGINE *e); -\& ENGINE_CTRL_FUNC_PTR ENGINE_get_ctrl_function(const ENGINE *e); -\& ENGINE_LOAD_KEY_PTR ENGINE_get_load_privkey_function(const ENGINE *e); -\& ENGINE_LOAD_KEY_PTR ENGINE_get_load_pubkey_function(const ENGINE *e); -\& ENGINE_CIPHERS_PTR ENGINE_get_ciphers(const ENGINE *e); -\& ENGINE_DIGESTS_PTR ENGINE_get_digests(const ENGINE *e); -\& const EVP_CIPHER *ENGINE_get_cipher(ENGINE *e, int nid); -\& const EVP_MD *ENGINE_get_digest(ENGINE *e, int nid); -\& int ENGINE_get_flags(const ENGINE *e); -\& const ENGINE_CMD_DEFN *ENGINE_get_cmd_defns(const ENGINE *e); -\& -\& EVP_PKEY *ENGINE_load_private_key(ENGINE *e, const char *key_id, -\& UI_METHOD *ui_method, void *callback_data); -\& EVP_PKEY *ENGINE_load_public_key(ENGINE *e, const char *key_id, -\& UI_METHOD *ui_method, void *callback_data); -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void ENGINE_cleanup(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the provider APIs. -.PP -These functions create, manipulate, and use cryptographic modules in the -form of \fB\s-1ENGINE\s0\fR objects. These objects act as containers for -implementations of cryptographic algorithms, and support a -reference-counted mechanism to allow them to be dynamically loaded in and -out of the running application. -.PP -The cryptographic functionality that can be provided by an \fB\s-1ENGINE\s0\fR -implementation includes the following abstractions; -.PP -.Vb 6 -\& RSA_METHOD \- for providing alternative RSA implementations -\& DSA_METHOD, DH_METHOD, RAND_METHOD, ECDH_METHOD, ECDSA_METHOD, -\& \- similarly for other OpenSSL APIs -\& EVP_CIPHER \- potentially multiple cipher algorithms (indexed by \*(Aqnid\*(Aq) -\& EVP_DIGEST \- potentially multiple hash algorithms (indexed by \*(Aqnid\*(Aq) -\& key\-loading \- loading public and/or private EVP_PKEY keys -.Ve -.SS "Reference counting and handles" -.IX Subsection "Reference counting and handles" -Due to the modular nature of the \s-1ENGINE API,\s0 pointers to ENGINEs need to be -treated as handles \- i.e. not only as pointers, but also as references to -the underlying \s-1ENGINE\s0 object. Ie. one should obtain a new reference when -making copies of an \s-1ENGINE\s0 pointer if the copies will be used (and -released) independently. -.PP -\&\s-1ENGINE\s0 objects have two levels of reference-counting to match the way in -which the objects are used. At the most basic level, each \s-1ENGINE\s0 pointer is -inherently a \fBstructural\fR reference \- a structural reference is required -to use the pointer value at all, as this kind of reference is a guarantee -that the structure can not be deallocated until the reference is released. -.PP -However, a structural reference provides no guarantee that the \s-1ENGINE\s0 is -initialised and able to use any of its cryptographic -implementations. Indeed it's quite possible that most ENGINEs will not -initialise at all in typical environments, as ENGINEs are typically used to -support specialised hardware. To use an \s-1ENGINE\s0's functionality, you need a -\&\fBfunctional\fR reference. This kind of reference can be considered a -specialised form of structural reference, because each functional reference -implicitly contains a structural reference as well \- however to avoid -difficult-to-find programming bugs, it is recommended to treat the two -kinds of reference independently. If you have a functional reference to an -\&\s-1ENGINE,\s0 you have a guarantee that the \s-1ENGINE\s0 has been initialised and -is ready to perform cryptographic operations, and will remain initialised -until after you have released your reference. -.PP -\&\fIStructural references\fR -.PP -This basic type of reference is used for instantiating new ENGINEs, -iterating across OpenSSL's internal linked-list of loaded -ENGINEs, reading information about an \s-1ENGINE,\s0 etc. Essentially a structural -reference is sufficient if you only need to query or manipulate the data of -an \s-1ENGINE\s0 implementation rather than use its functionality. -.PP -The \fBENGINE_new()\fR function returns a structural reference to a new (empty) -\&\s-1ENGINE\s0 object. There are other \s-1ENGINE API\s0 functions that return structural -references such as; \fBENGINE_by_id()\fR, \fBENGINE_get_first()\fR, \fBENGINE_get_last()\fR, -\&\fBENGINE_get_next()\fR, \fBENGINE_get_prev()\fR. All structural references should be -released by a corresponding to call to the \fBENGINE_free()\fR function \- the -\&\s-1ENGINE\s0 object itself will only actually be cleaned up and deallocated when -the last structural reference is released. If the argument to \fBENGINE_free()\fR -is \s-1NULL,\s0 nothing is done. -.PP -It should also be noted that many \s-1ENGINE API\s0 function calls that accept a -structural reference will internally obtain another reference \- typically -this happens whenever the supplied \s-1ENGINE\s0 will be needed by OpenSSL after -the function has returned. Eg. the function to add a new \s-1ENGINE\s0 to -OpenSSL's internal list is \fBENGINE_add()\fR \- if this function returns success, -then OpenSSL will have stored a new structural reference internally so the -caller is still responsible for freeing their own reference with -\&\fBENGINE_free()\fR when they are finished with it. In a similar way, some -functions will automatically release the structural reference passed to it -if part of the function's job is to do so. Eg. the \fBENGINE_get_next()\fR and -\&\fBENGINE_get_prev()\fR functions are used for iterating across the internal -\&\s-1ENGINE\s0 list \- they will return a new structural reference to the next (or -previous) \s-1ENGINE\s0 in the list or \s-1NULL\s0 if at the end (or beginning) of the -list, but in either case the structural reference passed to the function is -released on behalf of the caller. -.PP -To clarify a particular function's handling of references, one should -always consult that function's documentation \*(L"man\*(R" page, or failing that -the \fI\fR header file includes some hints. -.PP -\&\fIFunctional references\fR -.PP -As mentioned, functional references exist when the cryptographic -functionality of an \s-1ENGINE\s0 is required to be available. A functional -reference can be obtained in one of two ways; from an existing structural -reference to the required \s-1ENGINE,\s0 or by asking OpenSSL for the default -operational \s-1ENGINE\s0 for a given cryptographic purpose. -.PP -To obtain a functional reference from an existing structural reference, -call the \fBENGINE_init()\fR function. This returns zero if the \s-1ENGINE\s0 was not -already operational and couldn't be successfully initialised (e.g. lack of -system drivers, no special hardware attached, etc), otherwise it will -return nonzero to indicate that the \s-1ENGINE\s0 is now operational and will -have allocated a new \fBfunctional\fR reference to the \s-1ENGINE.\s0 All functional -references are released by calling \fBENGINE_finish()\fR (which removes the -implicit structural reference as well). -.PP -The second way to get a functional reference is by asking OpenSSL for a -default implementation for a given task, e.g. by \fBENGINE_get_default_RSA()\fR, -\&\fBENGINE_get_default_cipher_engine()\fR, etc. These are discussed in the next -section, though they are not usually required by application programmers as -they are used automatically when creating and using the relevant -algorithm-specific types in OpenSSL, such as \s-1RSA, DSA, EVP_CIPHER_CTX,\s0 etc. -.SS "Default implementations" -.IX Subsection "Default implementations" -For each supported abstraction, the \s-1ENGINE\s0 code maintains an internal table -of state to control which implementations are available for a given -abstraction and which should be used by default. These implementations are -registered in the tables and indexed by an 'nid' value, because -abstractions like \s-1EVP_CIPHER\s0 and \s-1EVP_DIGEST\s0 support many distinct -algorithms and modes, and ENGINEs can support arbitrarily many of them. -In the case of other abstractions like \s-1RSA, DSA,\s0 etc, there is only one -\&\*(L"algorithm\*(R" so all implementations implicitly register using the same 'nid' -index. -.PP -When a default \s-1ENGINE\s0 is requested for a given abstraction/algorithm/mode, (e.g. -when calling RSA_new_method(\s-1NULL\s0)), a \*(L"get_default\*(R" call will be made to the -\&\s-1ENGINE\s0 subsystem to process the corresponding state table and return a -functional reference to an initialised \s-1ENGINE\s0 whose implementation should be -used. If no \s-1ENGINE\s0 should (or can) be used, it will return \s-1NULL\s0 and the caller -will operate with a \s-1NULL ENGINE\s0 handle \- this usually equates to using the -conventional software implementation. In the latter case, OpenSSL will from -then on behave the way it used to before the \s-1ENGINE API\s0 existed. -.PP -Each state table has a flag to note whether it has processed this -\&\*(L"get_default\*(R" query since the table was last modified, because to process -this question it must iterate across all the registered ENGINEs in the -table trying to initialise each of them in turn, in case one of them is -operational. If it returns a functional reference to an \s-1ENGINE,\s0 it will -also cache another reference to speed up processing future queries (without -needing to iterate across the table). Likewise, it will cache a \s-1NULL\s0 -response if no \s-1ENGINE\s0 was available so that future queries won't repeat the -same iteration unless the state table changes. This behaviour can also be -changed; if the \s-1ENGINE_TABLE_FLAG_NOINIT\s0 flag is set (using -\&\fBENGINE_set_table_flags()\fR), no attempted initialisations will take place, -instead the only way for the state table to return a non-NULL \s-1ENGINE\s0 to the -\&\*(L"get_default\*(R" query will be if one is expressly set in the table. Eg. -\&\fBENGINE_set_default_RSA()\fR does the same job as \fBENGINE_register_RSA()\fR except -that it also sets the state table's cached response for the \*(L"get_default\*(R" -query. In the case of abstractions like \s-1EVP_CIPHER,\s0 where implementations are -indexed by 'nid', these flags and cached-responses are distinct for each 'nid' -value. -.SS "Application requirements" -.IX Subsection "Application requirements" -This section will explain the basic things an application programmer should -support to make the most useful elements of the \s-1ENGINE\s0 functionality -available to the user. The first thing to consider is whether the -programmer wishes to make alternative \s-1ENGINE\s0 modules available to the -application and user. OpenSSL maintains an internal linked list of -\&\*(L"visible\*(R" ENGINEs from which it has to operate \- at start-up, this list is -empty and in fact if an application does not call any \s-1ENGINE API\s0 calls and -it uses static linking against openssl, then the resulting application -binary will not contain any alternative \s-1ENGINE\s0 code at all. So the first -consideration is whether any/all available \s-1ENGINE\s0 implementations should be -made visible to OpenSSL \- this is controlled by calling the various \*(L"load\*(R" -functions. -.PP -The fact that ENGINEs are made visible to OpenSSL (and thus are linked into -the program and loaded into memory at run-time) does not mean they are -\&\*(L"registered\*(R" or called into use by OpenSSL automatically \- that behaviour -is something for the application to control. Some applications -will want to allow the user to specify exactly which \s-1ENGINE\s0 they want used -if any is to be used at all. Others may prefer to load all support and have -OpenSSL automatically use at run-time any \s-1ENGINE\s0 that is able to -successfully initialise \- i.e. to assume that this corresponds to -acceleration hardware attached to the machine or some such thing. There are -probably numerous other ways in which applications may prefer to handle -things, so we will simply illustrate the consequences as they apply to a -couple of simple cases and leave developers to consider these and the -source code to openssl's built-in utilities as guides. -.PP -If no \s-1ENGINE API\s0 functions are called within an application, then OpenSSL -will not allocate any internal resources. Prior to OpenSSL 1.1.0, however, -if any ENGINEs are loaded, even if not registered or used, it was necessary to -call \fBENGINE_cleanup()\fR before the program exits. -.PP -\&\fIUsing a specific \s-1ENGINE\s0 implementation\fR -.PP -Here we'll assume an application has been configured by its user or admin -to want to use the \*(L"\s-1ACME\*(R" ENGINE\s0 if it is available in the version of -OpenSSL the application was compiled with. If it is available, it should be -used by default for all \s-1RSA, DSA,\s0 and symmetric cipher operations, otherwise -OpenSSL should use its built-in software as per usual. The following code -illustrates how to approach this; -.PP -.Vb 10 -\& ENGINE *e; -\& const char *engine_id = "ACME"; -\& ENGINE_load_builtin_engines(); -\& e = ENGINE_by_id(engine_id); -\& if (!e) -\& /* the engine isn\*(Aqt available */ -\& return; -\& if (!ENGINE_init(e)) { -\& /* the engine couldn\*(Aqt initialise, release \*(Aqe\*(Aq */ -\& ENGINE_free(e); -\& return; -\& } -\& if (!ENGINE_set_default_RSA(e)) -\& /* -\& * This should only happen when \*(Aqe\*(Aq can\*(Aqt initialise, but the previous -\& * statement suggests it did. -\& */ -\& abort(); -\& ENGINE_set_default_DSA(e); -\& ENGINE_set_default_ciphers(e); -\& /* Release the functional reference from ENGINE_init() */ -\& ENGINE_finish(e); -\& /* Release the structural reference from ENGINE_by_id() */ -\& ENGINE_free(e); -.Ve -.PP -\&\fIAutomatically using built-in \s-1ENGINE\s0 implementations\fR -.PP -Here we'll assume we want to load and register all \s-1ENGINE\s0 implementations -bundled with OpenSSL, such that for any cryptographic algorithm required by -OpenSSL \- if there is an \s-1ENGINE\s0 that implements it and can be initialised, -it should be used. The following code illustrates how this can work; -.PP -.Vb 4 -\& /* Load all bundled ENGINEs into memory and make them visible */ -\& ENGINE_load_builtin_engines(); -\& /* Register all of them for every algorithm they collectively implement */ -\& ENGINE_register_all_complete(); -.Ve -.PP -That's all that's required. Eg. the next time OpenSSL tries to set up an -\&\s-1RSA\s0 key, any bundled ENGINEs that implement \s-1RSA_METHOD\s0 will be passed to -\&\fBENGINE_init()\fR and if any of those succeed, that \s-1ENGINE\s0 will be set as the -default for \s-1RSA\s0 use from then on. -.SS "Advanced configuration support" -.IX Subsection "Advanced configuration support" -There is a mechanism supported by the \s-1ENGINE\s0 framework that allows each -\&\s-1ENGINE\s0 implementation to define an arbitrary set of configuration -\&\*(L"commands\*(R" and expose them to OpenSSL and any applications based on -OpenSSL. This mechanism is entirely based on the use of name-value pairs -and assumes \s-1ASCII\s0 input (no unicode or \s-1UTF\s0 for now!), so it is ideal if -applications want to provide a transparent way for users to provide -arbitrary configuration \*(L"directives\*(R" directly to such ENGINEs. It is also -possible for the application to dynamically interrogate the loaded \s-1ENGINE\s0 -implementations for the names, descriptions, and input flags of their -available \*(L"control commands\*(R", providing a more flexible configuration -scheme. However, if the user is expected to know which \s-1ENGINE\s0 device he/she -is using (in the case of specialised hardware, this goes without saying) -then applications may not need to concern themselves with discovering the -supported control commands and simply prefer to pass settings into ENGINEs -exactly as they are provided by the user. -.PP -Before illustrating how control commands work, it is worth mentioning what -they are typically used for. Broadly speaking there are two uses for -control commands; the first is to provide the necessary details to the -implementation (which may know nothing at all specific to the host system) -so that it can be initialised for use. This could include the path to any -driver or config files it needs to load, required network addresses, -smart-card identifiers, passwords to initialise protected devices, -logging information, etc etc. This class of commands typically needs to be -passed to an \s-1ENGINE\s0 \fBbefore\fR attempting to initialise it, i.e. before -calling \fBENGINE_init()\fR. The other class of commands consist of settings or -operations that tweak certain behaviour or cause certain operations to take -place, and these commands may work either before or after \fBENGINE_init()\fR, or -in some cases both. \s-1ENGINE\s0 implementations should provide indications of -this in the descriptions attached to built-in control commands and/or in -external product documentation. -.PP -\&\fIIssuing control commands to an \s-1ENGINE\s0\fR -.PP -Let's illustrate by example; a function for which the caller supplies the -name of the \s-1ENGINE\s0 it wishes to use, a table of string-pairs for use before -initialisation, and another table for use after initialisation. Note that -the string-pairs used for control commands consist of a command \*(L"name\*(R" -followed by the command \*(L"parameter\*(R" \- the parameter could be \s-1NULL\s0 in some -cases but the name can not. This function should initialise the \s-1ENGINE\s0 -(issuing the \*(L"pre\*(R" commands beforehand and the \*(L"post\*(R" commands afterwards) -and set it as the default for everything except \s-1RAND\s0 and then return a -boolean success or failure. -.PP -.Vb 10 -\& int generic_load_engine_fn(const char *engine_id, -\& const char **pre_cmds, int pre_num, -\& const char **post_cmds, int post_num) -\& { -\& ENGINE *e = ENGINE_by_id(engine_id); -\& if (!e) return 0; -\& while (pre_num\-\-) { -\& if (!ENGINE_ctrl_cmd_string(e, pre_cmds[0], pre_cmds[1], 0)) { -\& fprintf(stderr, "Failed command (%s \- %s:%s)\en", engine_id, -\& pre_cmds[0], pre_cmds[1] ? pre_cmds[1] : "(NULL)"); -\& ENGINE_free(e); -\& return 0; -\& } -\& pre_cmds += 2; -\& } -\& if (!ENGINE_init(e)) { -\& fprintf(stderr, "Failed initialisation\en"); -\& ENGINE_free(e); -\& return 0; -\& } -\& /* -\& * ENGINE_init() returned a functional reference, so free the structural -\& * reference from ENGINE_by_id(). -\& */ -\& ENGINE_free(e); -\& while (post_num\-\-) { -\& if (!ENGINE_ctrl_cmd_string(e, post_cmds[0], post_cmds[1], 0)) { -\& fprintf(stderr, "Failed command (%s \- %s:%s)\en", engine_id, -\& post_cmds[0], post_cmds[1] ? post_cmds[1] : "(NULL)"); -\& ENGINE_finish(e); -\& return 0; -\& } -\& post_cmds += 2; -\& } -\& ENGINE_set_default(e, ENGINE_METHOD_ALL & ~ENGINE_METHOD_RAND); -\& /* Success */ -\& return 1; -\& } -.Ve -.PP -Note that \fBENGINE_ctrl_cmd_string()\fR accepts a boolean argument that can -relax the semantics of the function \- if set nonzero it will only return -failure if the \s-1ENGINE\s0 supported the given command name but failed while -executing it, if the \s-1ENGINE\s0 doesn't support the command name it will simply -return success without doing anything. In this case we assume the user is -only supplying commands specific to the given \s-1ENGINE\s0 so we set this to -\&\s-1FALSE.\s0 -.PP -\&\fIDiscovering supported control commands\fR -.PP -It is possible to discover at run-time the names, numerical-ids, descriptions -and input parameters of the control commands supported by an \s-1ENGINE\s0 using a -structural reference. Note that some control commands are defined by OpenSSL -itself and it will intercept and handle these control commands on behalf of the -\&\s-1ENGINE,\s0 i.e. the \s-1ENGINE\s0's \fBctrl()\fR handler is not used for the control command. -\&\fI\fR defines an index, \s-1ENGINE_CMD_BASE,\s0 that all control -commands implemented by ENGINEs should be numbered from. Any command value -lower than this symbol is considered a \*(L"generic\*(R" command is handled directly -by the OpenSSL core routines. -.PP -It is using these \*(L"core\*(R" control commands that one can discover the control -commands implemented by a given \s-1ENGINE,\s0 specifically the commands: -.PP -.Vb 9 -\& ENGINE_HAS_CTRL_FUNCTION -\& ENGINE_CTRL_GET_FIRST_CMD_TYPE -\& ENGINE_CTRL_GET_NEXT_CMD_TYPE -\& ENGINE_CTRL_GET_CMD_FROM_NAME -\& ENGINE_CTRL_GET_NAME_LEN_FROM_CMD -\& ENGINE_CTRL_GET_NAME_FROM_CMD -\& ENGINE_CTRL_GET_DESC_LEN_FROM_CMD -\& ENGINE_CTRL_GET_DESC_FROM_CMD -\& ENGINE_CTRL_GET_CMD_FLAGS -.Ve -.PP -Whilst these commands are automatically processed by the OpenSSL framework code, -they use various properties exposed by each \s-1ENGINE\s0 to process these -queries. An \s-1ENGINE\s0 has 3 properties it exposes that can affect how this behaves; -it can supply a \fBctrl()\fR handler, it can specify \s-1ENGINE_FLAGS_MANUAL_CMD_CTRL\s0 in -the \s-1ENGINE\s0's flags, and it can expose an array of control command descriptions. -If an \s-1ENGINE\s0 specifies the \s-1ENGINE_FLAGS_MANUAL_CMD_CTRL\s0 flag, then it will -simply pass all these \*(L"core\*(R" control commands directly to the \s-1ENGINE\s0's \fBctrl()\fR -handler (and thus, it must have supplied one), so it is up to the \s-1ENGINE\s0 to -reply to these \*(L"discovery\*(R" commands itself. If that flag is not set, then the -OpenSSL framework code will work with the following rules: -.PP -.Vb 9 -\& if no ctrl() handler supplied; -\& ENGINE_HAS_CTRL_FUNCTION returns FALSE (zero), -\& all other commands fail. -\& if a ctrl() handler was supplied but no array of control commands; -\& ENGINE_HAS_CTRL_FUNCTION returns TRUE, -\& all other commands fail. -\& if a ctrl() handler and array of control commands was supplied; -\& ENGINE_HAS_CTRL_FUNCTION returns TRUE, -\& all other commands proceed processing ... -.Ve -.PP -If the \s-1ENGINE\s0's array of control commands is empty then all other commands will -fail, otherwise; \s-1ENGINE_CTRL_GET_FIRST_CMD_TYPE\s0 returns the identifier of -the first command supported by the \s-1ENGINE, ENGINE_GET_NEXT_CMD_TYPE\s0 takes the -identifier of a command supported by the \s-1ENGINE\s0 and returns the next command -identifier or fails if there are no more, \s-1ENGINE_CMD_FROM_NAME\s0 takes a string -name for a command and returns the corresponding identifier or fails if no such -command name exists, and the remaining commands take a command identifier and -return properties of the corresponding commands. All except -\&\s-1ENGINE_CTRL_GET_FLAGS\s0 return the string length of a command name or description, -or populate a supplied character buffer with a copy of the command name or -description. \s-1ENGINE_CTRL_GET_FLAGS\s0 returns a bitwise-OR'd mask of the following -possible values: -.PP -.Vb 4 -\& ENGINE_CMD_FLAG_NUMERIC -\& ENGINE_CMD_FLAG_STRING -\& ENGINE_CMD_FLAG_NO_INPUT -\& ENGINE_CMD_FLAG_INTERNAL -.Ve -.PP -If the \s-1ENGINE_CMD_FLAG_INTERNAL\s0 flag is set, then any other flags are purely -informational to the caller \- this flag will prevent the command being usable -for any higher-level \s-1ENGINE\s0 functions such as \fBENGINE_ctrl_cmd_string()\fR. -\&\*(L"\s-1INTERNAL\*(R"\s0 commands are not intended to be exposed to text-based configuration -by applications, administrations, users, etc. These can support arbitrary -operations via \fBENGINE_ctrl()\fR, including passing to and/or from the control -commands data of any arbitrary type. These commands are supported in the -discovery mechanisms simply to allow applications to determine if an \s-1ENGINE\s0 -supports certain specific commands it might want to use (e.g. application \*(L"foo\*(R" -might query various ENGINEs to see if they implement \*(L"\s-1FOO_GET_VENDOR_LOGO_GIF\*(R"\s0 \- -and \s-1ENGINE\s0 could therefore decide whether or not to support this \*(L"foo\*(R"\-specific -extension). -.SH "ENVIRONMENT" -.IX Header "ENVIRONMENT" -.IP "\fB\s-1OPENSSL_ENGINES\s0\fR" 4 -.IX Item "OPENSSL_ENGINES" -The path to the engines directory. -Ignored in set-user-ID and set-group-ID programs. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBENGINE_get_first()\fR, \fBENGINE_get_last()\fR, \fBENGINE_get_next()\fR and \fBENGINE_get_prev()\fR -return a valid \fB\s-1ENGINE\s0\fR structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBENGINE_add()\fR and \fBENGINE_remove()\fR return 1 on success or 0 on error. -.PP -\&\fBENGINE_by_id()\fR returns a valid \fB\s-1ENGINE\s0\fR structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBENGINE_init()\fR and \fBENGINE_finish()\fR return 1 on success or 0 on error. -.PP -All \fBENGINE_get_default_TYPE()\fR functions, \fBENGINE_get_cipher_engine()\fR and -\&\fBENGINE_get_digest_engine()\fR return a valid \fB\s-1ENGINE\s0\fR structure on success or \s-1NULL\s0 -if an error occurred. -.PP -All \fBENGINE_set_default_TYPE()\fR functions return 1 on success or 0 on error. -.PP -\&\fBENGINE_set_default()\fR returns 1 on success or 0 on error. -.PP -\&\fBENGINE_get_table_flags()\fR returns an unsigned integer value representing the -global table flags which are used to control the registration behaviour of -\&\fB\s-1ENGINE\s0\fR implementations. -.PP -All \fBENGINE_register_TYPE()\fR functions return 1 on success or 0 on error. -.PP -\&\fBENGINE_register_complete()\fR and \fBENGINE_register_all_complete()\fR always return 1. -.PP -\&\fBENGINE_ctrl()\fR returns a positive value on success or others on error. -.PP -\&\fBENGINE_cmd_is_executable()\fR returns 1 if \fBcmd\fR is executable or 0 otherwise. -.PP -\&\fBENGINE_ctrl_cmd()\fR and \fBENGINE_ctrl_cmd_string()\fR return 1 on success or 0 on error. -.PP -\&\fBENGINE_new()\fR returns a valid \fB\s-1ENGINE\s0\fR structure on success or \s-1NULL\s0 if an error -occurred. -.PP -\&\fBENGINE_free()\fR always returns 1. -.PP -\&\fBENGINE_up_ref()\fR returns 1 on success or 0 on error. -.PP -\&\fBENGINE_set_id()\fR and \fBENGINE_set_name()\fR return 1 on success or 0 on error. -.PP -All other \fBENGINE_set_*\fR functions return 1 on success or 0 on error. -.PP -\&\fBENGINE_get_id()\fR and \fBENGINE_get_name()\fR return a string representing the identifier -and the name of the \s-1ENGINE\s0 \fBe\fR respectively. -.PP -\&\fBENGINE_get_RSA()\fR, \fBENGINE_get_DSA()\fR, \fBENGINE_get_DH()\fR and \fBENGINE_get_RAND()\fR -return corresponding method structures for each algorithms. -.PP -\&\fBENGINE_get_destroy_function()\fR, \fBENGINE_get_init_function()\fR, -\&\fBENGINE_get_finish_function()\fR, \fBENGINE_get_ctrl_function()\fR, -\&\fBENGINE_get_load_privkey_function()\fR, \fBENGINE_get_load_pubkey_function()\fR, -\&\fBENGINE_get_ciphers()\fR and \fBENGINE_get_digests()\fR return corresponding function -pointers of the callbacks. -.PP -\&\fBENGINE_get_cipher()\fR returns a valid \fB\s-1EVP_CIPHER\s0\fR structure on success or \s-1NULL\s0 -if an error occurred. -.PP -\&\fBENGINE_get_digest()\fR returns a valid \fB\s-1EVP_MD\s0\fR structure on success or \s-1NULL\s0 if an -error occurred. -.PP -\&\fBENGINE_get_flags()\fR returns an integer representing the \s-1ENGINE\s0 flags which are -used to control various behaviours of an \s-1ENGINE.\s0 -.PP -\&\fBENGINE_get_cmd_defns()\fR returns an \fB\s-1ENGINE_CMD_DEFN\s0\fR structure or \s-1NULL\s0 if it's -not set. -.PP -\&\fBENGINE_load_private_key()\fR and \fBENGINE_load_public_key()\fR return a valid \fB\s-1EVP_PKEY\s0\fR -structure on success or \s-1NULL\s0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOPENSSL_init_crypto\fR\|(3), \fBRSA_new_method\fR\|(3), \fBDSA_new\fR\|(3), \fBDH_new\fR\|(3), -\&\fBRAND_bytes\fR\|(3), \fBconfig\fR\|(5) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -\&\fBENGINE_cleanup()\fR was deprecated in OpenSSL 1.1.0 by the automatic cleanup -done by \fBOPENSSL_cleanup()\fR -and should not be used. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ENGINE_add_conf_module.3ossl b/openssl-install/share/man/man3/ENGINE_add_conf_module.3ossl deleted file mode 120000 index 5fd046e1..00000000 --- a/openssl-install/share/man/man3/ENGINE_add_conf_module.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_load_builtin_modules.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_by_id.3ossl b/openssl-install/share/man/man3/ENGINE_by_id.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_by_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_cleanup.3ossl b/openssl-install/share/man/man3/ENGINE_cleanup.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_cmd_is_executable.3ossl b/openssl-install/share/man/man3/ENGINE_cmd_is_executable.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_cmd_is_executable.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_ctrl.3ossl b/openssl-install/share/man/man3/ENGINE_ctrl.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_ctrl_cmd.3ossl b/openssl-install/share/man/man3/ENGINE_ctrl_cmd.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_ctrl_cmd.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_ctrl_cmd_string.3ossl b/openssl-install/share/man/man3/ENGINE_ctrl_cmd_string.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_ctrl_cmd_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_finish.3ossl b/openssl-install/share/man/man3/ENGINE_finish.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_free.3ossl b/openssl-install/share/man/man3/ENGINE_free.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_DH.3ossl b/openssl-install/share/man/man3/ENGINE_get_DH.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_DSA.3ossl b/openssl-install/share/man/man3/ENGINE_get_DSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_RAND.3ossl b/openssl-install/share/man/man3/ENGINE_get_RAND.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_RAND.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_RSA.3ossl b/openssl-install/share/man/man3/ENGINE_get_RSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_cipher.3ossl b/openssl-install/share/man/man3/ENGINE_get_cipher.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_cipher_engine.3ossl b/openssl-install/share/man/man3/ENGINE_get_cipher_engine.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_cipher_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_ciphers.3ossl b/openssl-install/share/man/man3/ENGINE_get_ciphers.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_cmd_defns.3ossl b/openssl-install/share/man/man3/ENGINE_get_cmd_defns.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_cmd_defns.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_ctrl_function.3ossl b/openssl-install/share/man/man3/ENGINE_get_ctrl_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_ctrl_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_default_DH.3ossl b/openssl-install/share/man/man3/ENGINE_get_default_DH.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_default_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_default_DSA.3ossl b/openssl-install/share/man/man3/ENGINE_get_default_DSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_default_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_default_RAND.3ossl b/openssl-install/share/man/man3/ENGINE_get_default_RAND.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_default_RAND.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_default_RSA.3ossl b/openssl-install/share/man/man3/ENGINE_get_default_RSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_default_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_destroy_function.3ossl b/openssl-install/share/man/man3/ENGINE_get_destroy_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_destroy_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_digest.3ossl b/openssl-install/share/man/man3/ENGINE_get_digest.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_digest_engine.3ossl b/openssl-install/share/man/man3/ENGINE_get_digest_engine.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_digest_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_digests.3ossl b/openssl-install/share/man/man3/ENGINE_get_digests.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_digests.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_ex_data.3ossl b/openssl-install/share/man/man3/ENGINE_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_ex_new_index.3ossl b/openssl-install/share/man/man3/ENGINE_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_finish_function.3ossl b/openssl-install/share/man/man3/ENGINE_get_finish_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_finish_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_first.3ossl b/openssl-install/share/man/man3/ENGINE_get_first.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_first.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_flags.3ossl b/openssl-install/share/man/man3/ENGINE_get_flags.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_id.3ossl b/openssl-install/share/man/man3/ENGINE_get_id.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_init_function.3ossl b/openssl-install/share/man/man3/ENGINE_get_init_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_init_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_last.3ossl b/openssl-install/share/man/man3/ENGINE_get_last.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_last.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_load_privkey_function.3ossl b/openssl-install/share/man/man3/ENGINE_get_load_privkey_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_load_privkey_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_load_pubkey_function.3ossl b/openssl-install/share/man/man3/ENGINE_get_load_pubkey_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_load_pubkey_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_name.3ossl b/openssl-install/share/man/man3/ENGINE_get_name.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_next.3ossl b/openssl-install/share/man/man3/ENGINE_get_next.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_next.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_prev.3ossl b/openssl-install/share/man/man3/ENGINE_get_prev.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_prev.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_get_table_flags.3ossl b/openssl-install/share/man/man3/ENGINE_get_table_flags.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_get_table_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_init.3ossl b/openssl-install/share/man/man3/ENGINE_init.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_load_builtin_engines.3ossl b/openssl-install/share/man/man3/ENGINE_load_builtin_engines.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_load_builtin_engines.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_load_private_key.3ossl b/openssl-install/share/man/man3/ENGINE_load_private_key.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_load_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_load_public_key.3ossl b/openssl-install/share/man/man3/ENGINE_load_public_key.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_load_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_new.3ossl b/openssl-install/share/man/man3/ENGINE_new.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_DH.3ossl b/openssl-install/share/man/man3/ENGINE_register_DH.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_DSA.3ossl b/openssl-install/share/man/man3/ENGINE_register_DSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_RAND.3ossl b/openssl-install/share/man/man3/ENGINE_register_RAND.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_RAND.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_RSA.3ossl b/openssl-install/share/man/man3/ENGINE_register_RSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_all_DH.3ossl b/openssl-install/share/man/man3/ENGINE_register_all_DH.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_all_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_all_DSA.3ossl b/openssl-install/share/man/man3/ENGINE_register_all_DSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_all_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_all_RAND.3ossl b/openssl-install/share/man/man3/ENGINE_register_all_RAND.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_all_RAND.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_all_RSA.3ossl b/openssl-install/share/man/man3/ENGINE_register_all_RSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_all_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_all_ciphers.3ossl b/openssl-install/share/man/man3/ENGINE_register_all_ciphers.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_all_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_all_complete.3ossl b/openssl-install/share/man/man3/ENGINE_register_all_complete.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_all_complete.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_all_digests.3ossl b/openssl-install/share/man/man3/ENGINE_register_all_digests.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_all_digests.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_ciphers.3ossl b/openssl-install/share/man/man3/ENGINE_register_ciphers.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_complete.3ossl b/openssl-install/share/man/man3/ENGINE_register_complete.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_complete.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_register_digests.3ossl b/openssl-install/share/man/man3/ENGINE_register_digests.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_register_digests.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_remove.3ossl b/openssl-install/share/man/man3/ENGINE_remove.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_remove.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_DH.3ossl b/openssl-install/share/man/man3/ENGINE_set_DH.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_DSA.3ossl b/openssl-install/share/man/man3/ENGINE_set_DSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_RAND.3ossl b/openssl-install/share/man/man3/ENGINE_set_RAND.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_RAND.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_RSA.3ossl b/openssl-install/share/man/man3/ENGINE_set_RSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_ciphers.3ossl b/openssl-install/share/man/man3/ENGINE_set_ciphers.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_cmd_defns.3ossl b/openssl-install/share/man/man3/ENGINE_set_cmd_defns.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_cmd_defns.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_ctrl_function.3ossl b/openssl-install/share/man/man3/ENGINE_set_ctrl_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_ctrl_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default.3ossl b/openssl-install/share/man/man3/ENGINE_set_default.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default_DH.3ossl b/openssl-install/share/man/man3/ENGINE_set_default_DH.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default_DSA.3ossl b/openssl-install/share/man/man3/ENGINE_set_default_DSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default_RAND.3ossl b/openssl-install/share/man/man3/ENGINE_set_default_RAND.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default_RAND.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default_RSA.3ossl b/openssl-install/share/man/man3/ENGINE_set_default_RSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default_ciphers.3ossl b/openssl-install/share/man/man3/ENGINE_set_default_ciphers.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default_digests.3ossl b/openssl-install/share/man/man3/ENGINE_set_default_digests.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default_digests.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_default_string.3ossl b/openssl-install/share/man/man3/ENGINE_set_default_string.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_default_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_destroy_function.3ossl b/openssl-install/share/man/man3/ENGINE_set_destroy_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_destroy_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_digests.3ossl b/openssl-install/share/man/man3/ENGINE_set_digests.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_digests.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_ex_data.3ossl b/openssl-install/share/man/man3/ENGINE_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_finish_function.3ossl b/openssl-install/share/man/man3/ENGINE_set_finish_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_finish_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_flags.3ossl b/openssl-install/share/man/man3/ENGINE_set_flags.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_id.3ossl b/openssl-install/share/man/man3/ENGINE_set_id.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_init_function.3ossl b/openssl-install/share/man/man3/ENGINE_set_init_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_init_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_load_privkey_function.3ossl b/openssl-install/share/man/man3/ENGINE_set_load_privkey_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_load_privkey_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_load_pubkey_function.3ossl b/openssl-install/share/man/man3/ENGINE_set_load_pubkey_function.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_load_pubkey_function.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_name.3ossl b/openssl-install/share/man/man3/ENGINE_set_name.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_set_table_flags.3ossl b/openssl-install/share/man/man3/ENGINE_set_table_flags.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_set_table_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_unregister_DH.3ossl b/openssl-install/share/man/man3/ENGINE_unregister_DH.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_unregister_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_unregister_DSA.3ossl b/openssl-install/share/man/man3/ENGINE_unregister_DSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_unregister_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_unregister_RAND.3ossl b/openssl-install/share/man/man3/ENGINE_unregister_RAND.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_unregister_RAND.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_unregister_RSA.3ossl b/openssl-install/share/man/man3/ENGINE_unregister_RSA.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_unregister_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_unregister_ciphers.3ossl b/openssl-install/share/man/man3/ENGINE_unregister_ciphers.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_unregister_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_unregister_digests.3ossl b/openssl-install/share/man/man3/ENGINE_unregister_digests.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_unregister_digests.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ENGINE_up_ref.3ossl b/openssl-install/share/man/man3/ENGINE_up_ref.3ossl deleted file mode 120000 index 7b4e06e9..00000000 --- a/openssl-install/share/man/man3/ENGINE_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -ENGINE_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_FATAL_ERROR.3ossl b/openssl-install/share/man/man3/ERR_FATAL_ERROR.3ossl deleted file mode 120000 index 7b593d49..00000000 --- a/openssl-install/share/man/man3/ERR_FATAL_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_GET_LIB.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_GET_LIB.3ossl b/openssl-install/share/man/man3/ERR_GET_LIB.3ossl deleted file mode 100644 index 7c37c954..00000000 --- a/openssl-install/share/man/man3/ERR_GET_LIB.3ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_GET_LIB 3ossl" -.TH ERR_GET_LIB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_GET_LIB, ERR_GET_REASON, ERR_FATAL_ERROR -\&\- get information from error codes -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ERR_GET_LIB(unsigned long e); -\& -\& int ERR_GET_REASON(unsigned long e); -\& -\& int ERR_FATAL_ERROR(unsigned long e); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The error code returned by \fBERR_get_error()\fR consists of a library -number and reason code. \s-1\fBERR_GET_LIB\s0()\fR -and \s-1\fBERR_GET_REASON\s0()\fR can be used to extract these. -.PP -\&\s-1\fBERR_FATAL_ERROR\s0()\fR indicates whether a given error code is a fatal error. -.PP -The library number describes where the error -occurred, the reason code is the information about what went wrong. -.PP -Each sub-library of OpenSSL has a unique library number; the -reason code is unique within each sub-library. Note that different -libraries may use the same value to signal different reasons. -.PP -\&\fB\s-1ERR_R_...\s0\fR reason codes such as \fB\s-1ERR_R_MALLOC_FAILURE\s0\fR are globally -unique. However, when checking for sub-library specific reason codes, -be sure to also compare the library number. -.PP -\&\s-1\fBERR_GET_LIB\s0()\fR, \s-1\fBERR_GET_REASON\s0()\fR, and \s-1\fBERR_FATAL_ERROR\s0()\fR are macros. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The library number, reason code, and whether the error -is fatal, respectively. -Starting with OpenSSL 3.0.0, the function code is always set to zero. -.SH "NOTES" -.IX Header "NOTES" -Applications should not make control flow decisions based on specific error -codes. Error codes are subject to change at any time (even in patch releases of -OpenSSL). A particular error code can only be considered meaningful for control -flow decisions if it is explicitly documented as such. New failure codes may -still appear at any time. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\s-1\fBERR_GET_LIB\s0()\fR and \s-1\fBERR_GET_REASON\s0()\fR are available in all versions of OpenSSL. -.PP -\&\s-1\fBERR_GET_FUNC\s0()\fR was removed in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_GET_REASON.3ossl b/openssl-install/share/man/man3/ERR_GET_REASON.3ossl deleted file mode 120000 index 7b593d49..00000000 --- a/openssl-install/share/man/man3/ERR_GET_REASON.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_GET_LIB.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_PACK.3ossl b/openssl-install/share/man/man3/ERR_PACK.3ossl deleted file mode 120000 index dc8a6d87..00000000 --- a/openssl-install/share/man/man3/ERR_PACK.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_load_strings.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_add_error_data.3ossl b/openssl-install/share/man/man3/ERR_add_error_data.3ossl deleted file mode 120000 index 3f08ecc2..00000000 --- a/openssl-install/share/man/man3/ERR_add_error_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_put_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_add_error_mem_bio.3ossl b/openssl-install/share/man/man3/ERR_add_error_mem_bio.3ossl deleted file mode 120000 index 3f08ecc2..00000000 --- a/openssl-install/share/man/man3/ERR_add_error_mem_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_put_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_add_error_txt.3ossl b/openssl-install/share/man/man3/ERR_add_error_txt.3ossl deleted file mode 120000 index 3f08ecc2..00000000 --- a/openssl-install/share/man/man3/ERR_add_error_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_put_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_add_error_vdata.3ossl b/openssl-install/share/man/man3/ERR_add_error_vdata.3ossl deleted file mode 120000 index 3f08ecc2..00000000 --- a/openssl-install/share/man/man3/ERR_add_error_vdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_put_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_clear_error.3ossl b/openssl-install/share/man/man3/ERR_clear_error.3ossl deleted file mode 100644 index 7803caed..00000000 --- a/openssl-install/share/man/man3/ERR_clear_error.3ossl +++ /dev/null @@ -1,166 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_CLEAR_ERROR 3ossl" -.TH ERR_CLEAR_ERROR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_clear_error \- clear the error queue -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void ERR_clear_error(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_clear_error()\fR empties the current thread's error queue. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_clear_error()\fR has no return value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_clear_last_mark.3ossl b/openssl-install/share/man/man3/ERR_clear_last_mark.3ossl deleted file mode 120000 index 466cbc90..00000000 --- a/openssl-install/share/man/man3/ERR_clear_last_mark.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_set_mark.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_count_to_mark.3ossl b/openssl-install/share/man/man3/ERR_count_to_mark.3ossl deleted file mode 120000 index 466cbc90..00000000 --- a/openssl-install/share/man/man3/ERR_count_to_mark.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_set_mark.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_error_string.3ossl b/openssl-install/share/man/man3/ERR_error_string.3ossl deleted file mode 100644 index fd144487..00000000 --- a/openssl-install/share/man/man3/ERR_error_string.3ossl +++ /dev/null @@ -1,216 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_ERROR_STRING 3ossl" -.TH ERR_ERROR_STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_error_string, ERR_error_string_n, ERR_lib_error_string, -ERR_func_error_string, ERR_reason_error_string \- obtain human\-readable -error message -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& char *ERR_error_string(unsigned long e, char *buf); -\& void ERR_error_string_n(unsigned long e, char *buf, size_t len); -\& -\& const char *ERR_lib_error_string(unsigned long e); -\& const char *ERR_reason_error_string(unsigned long e); -.Ve -.PP -Deprecated in OpenSSL 3.0: -.PP -.Vb 1 -\& const char *ERR_func_error_string(unsigned long e); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_error_string()\fR generates a human-readable string representing the -error code \fIe\fR, and places it at \fIbuf\fR. \fIbuf\fR must be at least 256 -bytes long. If \fIbuf\fR is \fB\s-1NULL\s0\fR, the error string is placed in a -static buffer. -Note that this function is not thread-safe and does no checks on the size -of the buffer; use \fBERR_error_string_n()\fR instead. -.PP -\&\fBERR_error_string_n()\fR is a variant of \fBERR_error_string()\fR that writes -at most \fIlen\fR characters (including the terminating 0) -and truncates the string if necessary. -For \fBERR_error_string_n()\fR, \fIbuf\fR may not be \fB\s-1NULL\s0\fR. -.PP -The string will have the following format: -.PP -.Vb 1 -\& error:[error code]:[library name]::[reason string] -.Ve -.PP -\&\fIerror code\fR is an 8 digit hexadecimal number, \fIlibrary name\fR and -\&\fIreason string\fR are \s-1ASCII\s0 text. -.PP -\&\fBERR_lib_error_string()\fR and \fBERR_reason_error_string()\fR return the library -name and reason string respectively. -.PP -If there is no text string registered for the given error code, -the error string will contain the numeric code. -.PP -\&\fBERR_print_errors\fR\|(3) can be used to print -all error codes currently in the queue. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_error_string()\fR returns a pointer to a static buffer containing the -string if \fIbuf\fR \fB== \s-1NULL\s0\fR, \fIbuf\fR otherwise. -.PP -\&\fBERR_lib_error_string()\fR and \fBERR_reason_error_string()\fR return the strings, -and \fB\s-1NULL\s0\fR if none is registered for the error code. -.PP -\&\fBERR_func_error_string()\fR returns \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBERR_print_errors\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBERR_func_error_string()\fR became deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_error_string_n.3ossl b/openssl-install/share/man/man3/ERR_error_string_n.3ossl deleted file mode 120000 index 15dc281a..00000000 --- a/openssl-install/share/man/man3/ERR_error_string_n.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_error_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_free_strings.3ossl b/openssl-install/share/man/man3/ERR_free_strings.3ossl deleted file mode 120000 index 04b9ca0f..00000000 --- a/openssl-install/share/man/man3/ERR_free_strings.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_load_crypto_strings.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_func_error_string.3ossl b/openssl-install/share/man/man3/ERR_func_error_string.3ossl deleted file mode 120000 index 15dc281a..00000000 --- a/openssl-install/share/man/man3/ERR_func_error_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_error_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_get_error.3ossl b/openssl-install/share/man/man3/ERR_get_error.3ossl deleted file mode 100644 index 585334ab..00000000 --- a/openssl-install/share/man/man3/ERR_get_error.3ossl +++ /dev/null @@ -1,274 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_GET_ERROR 3ossl" -.TH ERR_GET_ERROR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_get_error, ERR_peek_error, ERR_peek_last_error, -ERR_get_error_line, ERR_peek_error_line, ERR_peek_last_error_line, -ERR_peek_error_func, ERR_peek_last_error_func, -ERR_peek_error_data, ERR_peek_last_error_data, -ERR_get_error_all, ERR_peek_error_all, ERR_peek_last_error_all, -ERR_get_error_line_data, ERR_peek_error_line_data, ERR_peek_last_error_line_data -\&\- obtain error code and data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned long ERR_get_error(void); -\& unsigned long ERR_peek_error(void); -\& unsigned long ERR_peek_last_error(void); -\& -\& unsigned long ERR_peek_error_line(const char **file, int *line); -\& unsigned long ERR_peek_last_error_line(const char **file, int *line); -\& -\& unsigned long ERR_peek_error_func(const char **func); -\& unsigned long ERR_peek_last_error_func(const char **func); -\& -\& unsigned long ERR_peek_error_data(const char **data, int *flags); -\& unsigned long ERR_peek_last_error_data(const char **data, int *flags); -\& -\& unsigned long ERR_get_error_all(const char **file, int *line, -\& const char **func, -\& const char **data, int *flags); -\& unsigned long ERR_peek_error_all(const char **file, int *line, -\& const char **func, -\& const char **data, int *flags); -\& unsigned long ERR_peek_last_error_all(const char **file, int *line, -\& const char *func, -\& const char **data, int *flags); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 7 -\& unsigned long ERR_get_error_line(const char **file, int *line); -\& unsigned long ERR_get_error_line_data(const char **file, int *line, -\& const char **data, int *flags); -\& unsigned long ERR_peek_error_line_data(const char **file, int *line, -\& const char **data, int *flags); -\& unsigned long ERR_peek_last_error_line_data(const char **file, int *line, -\& const char **data, int *flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_get_error()\fR returns the earliest error code from the thread's error -queue and removes the entry. This function can be called repeatedly -until there are no more error codes to return. -.PP -\&\fBERR_peek_error()\fR returns the earliest error code from the thread's -error queue without modifying it. -.PP -\&\fBERR_peek_last_error()\fR returns the latest error code from the thread's -error queue without modifying it. -.PP -See \s-1\fBERR_GET_LIB\s0\fR\|(3) for obtaining further specific information -such as the reason of the error, -and \fBERR_error_string\fR\|(3) for human-readable error messages. -.PP -\&\fBERR_get_error_all()\fR is the same as \fBERR_get_error()\fR, but on success it -additionally stores the filename, line number and function where the error -occurred in *\fIfile\fR, *\fIline\fR and *\fIfunc\fR, and also extra text and flags -in *\fIdata\fR, *\fIflags\fR. If any of those parameters are \s-1NULL,\s0 it will not -be changed. -An unset filename is indicated as "\*(L", i.e. an empty string. -An unset line number is indicated as 0. -An unset function name is indicated as \*(R"", i.e. an empty string. -.PP -A pointer returned this way by these functions and the ones below -is valid until the respective entry is overwritten in the error queue. -.PP -\&\fBERR_peek_error_line()\fR and \fBERR_peek_last_error_line()\fR are the same as -\&\fBERR_peek_error()\fR and \fBERR_peek_last_error()\fR, but on success they additionally -store the filename and line number where the error occurred in *\fIfile\fR and -*\fIline\fR, as far as they are not \s-1NULL.\s0 -An unset filename is indicated as "", i.e., an empty string. -An unset line number is indicated as 0. -.PP -\&\fBERR_peek_error_func()\fR and \fBERR_peek_last_error_func()\fR are the same as -\&\fBERR_peek_error()\fR and \fBERR_peek_last_error()\fR, but on success they additionally -store the name of the function where the error occurred in *\fIfunc\fR, unless -it is \s-1NULL.\s0 -An unset function name is indicated as "". -.PP -\&\fBERR_peek_error_data()\fR and \fBERR_peek_last_error_data()\fR are the same as -\&\fBERR_peek_error()\fR and \fBERR_peek_last_error()\fR, but on success they additionally -store additional data and flags associated with the error code in *\fIdata\fR -and *\fIflags\fR, as far as they are not \s-1NULL.\s0 -Unset data is indicated as "". -In this case the value given for the flag is irrelevant (and equals 0). -*\fIdata\fR contains a string if *\fIflags\fR&\fB\s-1ERR_TXT_STRING\s0\fR is true. -.PP -\&\fBERR_peek_error_all()\fR and \fBERR_peek_last_error_all()\fR are combinations of all -of the above. -.PP -\&\fBERR_get_error_line()\fR, \fBERR_get_error_line_data()\fR, \fBERR_peek_error_line_data()\fR -and \fBERR_peek_last_error_line_data()\fR are older variants of \fBERR_get_error_all()\fR, -\&\fBERR_peek_error_all()\fR and \fBERR_peek_last_error_all()\fR, and may give confusing -results. They should no longer be used and are therefore deprecated. -.PP -An application \fB\s-1MUST NOT\s0\fR free the *\fIdata\fR pointer (or any other pointers -returned by these functions) with \fBOPENSSL_free()\fR as freeing is handled -automatically by the error library. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The error code, or 0 if there is no error in the queue. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_error_string\fR\|(3), -\&\s-1\fBERR_GET_LIB\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBERR_peek_error_func()\fR, \fBERR_peek_last_error_func()\fR, -\&\fBERR_peek_error_data()\fR, \fBERR_peek_last_error_data()\fR, -\&\fBERR_peek_error_all()\fR and \fBERR_peek_last_error_all()\fR -were added in OpenSSL 3.0. -.PP -\&\fBERR_get_error_line()\fR, \fBERR_get_error_line_data()\fR, \fBERR_peek_error_line_data()\fR -and \fBERR_peek_last_error_line_data()\fR became deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_get_error_all.3ossl b/openssl-install/share/man/man3/ERR_get_error_all.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_get_error_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_get_error_line.3ossl b/openssl-install/share/man/man3/ERR_get_error_line.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_get_error_line.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_get_error_line_data.3ossl b/openssl-install/share/man/man3/ERR_get_error_line_data.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_get_error_line_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_get_next_error_library.3ossl b/openssl-install/share/man/man3/ERR_get_next_error_library.3ossl deleted file mode 120000 index dc8a6d87..00000000 --- a/openssl-install/share/man/man3/ERR_get_next_error_library.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_load_strings.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_lib_error_string.3ossl b/openssl-install/share/man/man3/ERR_lib_error_string.3ossl deleted file mode 120000 index 15dc281a..00000000 --- a/openssl-install/share/man/man3/ERR_lib_error_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_error_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_load_crypto_strings.3ossl b/openssl-install/share/man/man3/ERR_load_crypto_strings.3ossl deleted file mode 100644 index d09d46c3..00000000 --- a/openssl-install/share/man/man3/ERR_load_crypto_strings.3ossl +++ /dev/null @@ -1,187 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_LOAD_CRYPTO_STRINGS 3ossl" -.TH ERR_LOAD_CRYPTO_STRINGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_load_crypto_strings, SSL_load_error_strings, ERR_free_strings \- -load and free error strings -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -The following functions have been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #include -\& -\& void ERR_load_crypto_strings(void); -\& void ERR_free_strings(void); -\& -\& #include -\& -\& void SSL_load_error_strings(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_load_crypto_strings()\fR registers the error strings for all -\&\fBlibcrypto\fR functions. \fBSSL_load_error_strings()\fR does the same, -but also registers the \fBlibssl\fR error strings. -.PP -In versions prior to OpenSSL 1.1.0, -\&\fBERR_free_strings()\fR releases any resources created by the above functions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_load_crypto_strings()\fR, \fBSSL_load_error_strings()\fR and -\&\fBERR_free_strings()\fR return no values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_error_string\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBERR_load_crypto_strings()\fR, \fBSSL_load_error_strings()\fR, and -\&\fBERR_free_strings()\fR functions were deprecated in OpenSSL 1.1.0 by -\&\fBOPENSSL_init_crypto()\fR and \fBOPENSSL_init_ssl()\fR and should not be used. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_load_strings.3ossl b/openssl-install/share/man/man3/ERR_load_strings.3ossl deleted file mode 100644 index 7d1b59fb..00000000 --- a/openssl-install/share/man/man3/ERR_load_strings.3ossl +++ /dev/null @@ -1,192 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_LOAD_STRINGS 3ossl" -.TH ERR_LOAD_STRINGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_load_strings, ERR_PACK, ERR_get_next_error_library \- load -arbitrary error strings -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ERR_load_strings(int lib, ERR_STRING_DATA *str); -\& -\& int ERR_get_next_error_library(void); -\& -\& unsigned long ERR_PACK(int lib, int func, int reason); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_load_strings()\fR registers error strings for library number \fBlib\fR. -.PP -\&\fBstr\fR is an array of error string data: -.PP -.Vb 5 -\& typedef struct ERR_string_data_st -\& { -\& unsigned long error; -\& char *string; -\& } ERR_STRING_DATA; -.Ve -.PP -The error code is generated from the library number and a function and -reason code: \fBerror\fR = \s-1ERR_PACK\s0(\fBlib\fR, \fBfunc\fR, \fBreason\fR). -\&\s-1\fBERR_PACK\s0()\fR is a macro. -.PP -The last entry in the array is {0,0}. -.PP -\&\fBERR_get_next_error_library()\fR can be used to assign library numbers -to user libraries at run time. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_load_strings()\fR returns 1 for success and 0 for failure. \s-1\fBERR_PACK\s0()\fR returns the error code. -\&\fBERR_get_next_error_library()\fR returns zero on failure, otherwise a new -library number. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_load_strings\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_new.3ossl b/openssl-install/share/man/man3/ERR_new.3ossl deleted file mode 100644 index fe511573..00000000 --- a/openssl-install/share/man/man3/ERR_new.3ossl +++ /dev/null @@ -1,209 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_NEW 3ossl" -.TH ERR_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_new, ERR_set_debug, ERR_set_error, ERR_vset_error -\&\- Error recording building blocks -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void ERR_new(void); -\& void ERR_set_debug(const char *file, int line, const char *func); -\& void ERR_set_error(int lib, int reason, const char *fmt, ...); -\& void ERR_vset_error(int lib, int reason, const char *fmt, va_list args); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions described here are generally not used directly, but -rather through macros such as \fBERR_raise\fR\|(3). -They can still be useful for anyone that wants to make their own -macros. -.PP -\&\fBERR_new()\fR allocates a new slot in the thread's error queue. -.PP -\&\fBERR_set_debug()\fR sets the debug information related to the current -error in the thread's error queue. -The values that can be given are the filename \fIfile\fR, line in the -file \fIline\fR and the name of the function \fIfunc\fR where the error -occurred. -The names must be constant, this function will only save away the -pointers, not copy the strings. -.PP -\&\fBERR_set_error()\fR sets the error information, which are the library -number \fIlib\fR and the reason code \fIreason\fR, and additional data as a -format string \fIfmt\fR and an arbitrary number of arguments. -The additional data is processed with \fBBIO_snprintf\fR\|(3) to form the -additional data string, which is allocated and store in the error -record. -.PP -\&\fBERR_vset_error()\fR works like \fBERR_set_error()\fR, but takes a \fBva_list\fR -argument instead of a variable number of arguments. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -ERR_new, ERR_set_debug, ERR_set_error and ERR_vset_error -do not return any values. -.SH "NOTES" -.IX Header "NOTES" -The library number is unique to each unit that records errors. -OpenSSL has a number of preallocated ones for its own uses, but -others may allocate their own library number dynamically with -\&\fBERR_get_next_error_library\fR\|(3). -.PP -Reason codes are unique within each library, and may have an -associated set of strings as a short description of the reason. -For dynamically allocated library numbers, reason strings are recorded -with \fBERR_load_strings\fR\|(3). -.PP -Provider authors are supplied with core versions of these functions, -see \fBprovider\-base\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_raise\fR\|(3), \fBERR_get_next_error_library\fR\|(3), -\&\fBERR_load_strings\fR\|(3), \fBBIO_snprintf\fR\|(3), \fBprovider\-base\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_peek_error.3ossl b/openssl-install/share/man/man3/ERR_peek_error.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_error_all.3ossl b/openssl-install/share/man/man3/ERR_peek_error_all.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_error_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_error_data.3ossl b/openssl-install/share/man/man3/ERR_peek_error_data.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_error_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_error_func.3ossl b/openssl-install/share/man/man3/ERR_peek_error_func.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_error_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_error_line.3ossl b/openssl-install/share/man/man3/ERR_peek_error_line.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_error_line.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_error_line_data.3ossl b/openssl-install/share/man/man3/ERR_peek_error_line_data.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_error_line_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_last_error.3ossl b/openssl-install/share/man/man3/ERR_peek_last_error.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_last_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_last_error_all.3ossl b/openssl-install/share/man/man3/ERR_peek_last_error_all.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_last_error_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_last_error_data.3ossl b/openssl-install/share/man/man3/ERR_peek_last_error_data.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_last_error_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_last_error_func.3ossl b/openssl-install/share/man/man3/ERR_peek_last_error_func.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_last_error_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_last_error_line.3ossl b/openssl-install/share/man/man3/ERR_peek_last_error_line.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_last_error_line.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_peek_last_error_line_data.3ossl b/openssl-install/share/man/man3/ERR_peek_last_error_line_data.3ossl deleted file mode 120000 index 27e80052..00000000 --- a/openssl-install/share/man/man3/ERR_peek_last_error_line_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_pop.3ossl b/openssl-install/share/man/man3/ERR_pop.3ossl deleted file mode 120000 index 466cbc90..00000000 --- a/openssl-install/share/man/man3/ERR_pop.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_set_mark.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_pop_to_mark.3ossl b/openssl-install/share/man/man3/ERR_pop_to_mark.3ossl deleted file mode 120000 index 466cbc90..00000000 --- a/openssl-install/share/man/man3/ERR_pop_to_mark.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_set_mark.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_print_errors.3ossl b/openssl-install/share/man/man3/ERR_print_errors.3ossl deleted file mode 100644 index 1c96375a..00000000 --- a/openssl-install/share/man/man3/ERR_print_errors.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_PRINT_ERRORS 3ossl" -.TH ERR_PRINT_ERRORS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_print_errors, ERR_print_errors_fp, ERR_print_errors_cb -\&\- print error messages -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void ERR_print_errors(BIO *bp); -\& void ERR_print_errors_fp(FILE *fp); -\& void ERR_print_errors_cb(int (*cb)(const char *str, size_t len, void *u), -\& void *u); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_print_errors()\fR is a convenience function that prints the error -strings for all errors that OpenSSL has recorded to \fBbp\fR, thus -emptying the error queue. -.PP -\&\fBERR_print_errors_fp()\fR is the same, except that the output goes to a -\&\fB\s-1FILE\s0\fR. -.PP -\&\fBERR_print_errors_cb()\fR is the same, except that the callback function, -\&\fBcb\fR, is called for each error line with the string, length, and userdata -\&\fBu\fR as the callback parameters. -.PP -The error strings will have the following format: -.PP -.Vb 1 -\& [pid]:error:[error code]:[library name]:[function name]:[reason string]:[filename]:[line]:[optional text message] -.Ve -.PP -\&\fIerror code\fR is an 8 digit hexadecimal number. \fIlibrary name\fR, -\&\fIfunction name\fR and \fIreason string\fR are \s-1ASCII\s0 text, as is \fIoptional -text message\fR if one was set for the respective error code. -.PP -If there is no text string registered for the given error code, -the error string will contain the numeric code. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_print_errors()\fR and \fBERR_print_errors_fp()\fR return no values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_error_string\fR\|(3), -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_print_errors_cb.3ossl b/openssl-install/share/man/man3/ERR_print_errors_cb.3ossl deleted file mode 120000 index f145b7de..00000000 --- a/openssl-install/share/man/man3/ERR_print_errors_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_print_errors.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_print_errors_fp.3ossl b/openssl-install/share/man/man3/ERR_print_errors_fp.3ossl deleted file mode 120000 index f145b7de..00000000 --- a/openssl-install/share/man/man3/ERR_print_errors_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_print_errors.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_put_error.3ossl b/openssl-install/share/man/man3/ERR_put_error.3ossl deleted file mode 100644 index ff86f5c4..00000000 --- a/openssl-install/share/man/man3/ERR_put_error.3ossl +++ /dev/null @@ -1,299 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_PUT_ERROR 3ossl" -.TH ERR_PUT_ERROR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_raise, ERR_raise_data, -ERR_put_error, ERR_add_error_data, ERR_add_error_vdata, -ERR_add_error_txt, ERR_add_error_mem_bio -\&\- record an error -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void ERR_raise(int lib, int reason); -\& void ERR_raise_data(int lib, int reason, const char *fmt, ...); -\& -\& void ERR_add_error_data(int num, ...); -\& void ERR_add_error_vdata(int num, va_list arg); -\& void ERR_add_error_txt(const char *sep, const char *txt); -\& void ERR_add_error_mem_bio(const char *sep, BIO *bio); -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void ERR_put_error(int lib, int func, int reason, const char *file, int line); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_raise()\fR adds a new error to the thread's error queue. The -error occurred in the library \fBlib\fR for the reason given by the -\&\fBreason\fR code. Furthermore, the name of the file, the line, and name -of the function where the error occurred is saved with the error -record. -.PP -\&\fBERR_raise_data()\fR does the same thing as \fBERR_raise()\fR, but also lets the -caller specify additional information as a format string \fBfmt\fR and an -arbitrary number of values, which are processed with \fBBIO_snprintf\fR\|(3). -.PP -\&\fBERR_put_error()\fR adds an error code to the thread's error queue. It -signals that the error of reason code \fBreason\fR occurred in function -\&\fBfunc\fR of library \fBlib\fR, in line number \fBline\fR of \fBfile\fR. -This function is usually called by a macro. -.PP -\&\fBERR_add_error_data()\fR associates the concatenation of its \fBnum\fR string -arguments as additional data with the error code added last. -\&\fBERR_add_error_vdata()\fR is similar except the argument is a \fBva_list\fR. -Multiple calls to these functions append to the current top of the error queue. -The total length of the string data per error is limited to 4096 characters. -.PP -\&\fBERR_add_error_txt()\fR appends the given text string as additional data to the -last error queue entry, after inserting the optional separator string if it is -not \s-1NULL\s0 and the top error entry does not yet have additional data. -In case the separator is at the end of the text it is not appended to the data. -The \fBsep\fR argument may be for instance \*(L"\en\*(R" to insert a line break when needed. -If the associated data would become more than 4096 characters long -(which is the limit given above) -it is split over sufficiently many new copies of the last error queue entry. -.PP -\&\fBERR_add_error_mem_bio()\fR is the same as \fBERR_add_error_txt()\fR except that -the text string is taken from the given memory \s-1BIO.\s0 -It appends '\e0' to the \s-1BIO\s0 contents if not already NUL-terminated. -.PP -\&\fBERR_load_strings\fR\|(3) can be used to register -error strings so that the application can a generate human-readable -error messages for the error code. -.SS "Reporting errors" -.IX Subsection "Reporting errors" -\fIOpenSSL library reports\fR -.IX Subsection "OpenSSL library reports" -.PP -Each OpenSSL sub-library has library code \fB\s-1ERR_LIB_XXX\s0\fR and has its own set -of reason codes \fB\s-1XXX_R_...\s0\fR. These are both passed in combination to -\&\fBERR_raise()\fR and \fBERR_raise_data()\fR, and the combination ultimately produces -the correct error text for the reported error. -.PP -All these macros and the numbers they have as values are specific to -OpenSSL's libraries. OpenSSL reason codes normally consist of textual error -descriptions. For example, the function \fBssl3_read_bytes()\fR reports a -\&\*(L"handshake failure\*(R" as follows: -.PP -.Vb 1 -\& ERR_raise(ERR_LIB_SSL, SSL_R_SSL_HANDSHAKE_FAILURE); -.Ve -.PP -There are two exceptions: -.IP "\fB\s-1ERR_LIB_SYS\s0\fR" 4 -.IX Item "ERR_LIB_SYS" -This \*(L"library code\*(R" indicates that a system error is being reported. In -this case, the reason code given to \fBERR_raise()\fR and \fBERR_raise_data()\fR \fImust\fR -be \fBerrno\fR\|(3). -.Sp -.Vb 1 -\& ERR_raise(ERR_LIB_SYS, errno); -.Ve -.IP "\fB\s-1ERR_R_XXX\s0\fR" 4 -.IX Item "ERR_R_XXX" -This set of error codes is considered global, and may be used in combination -with any sub-library code. -.Sp -.Vb 1 -\& ERR_raise(ERR_LIB_RSA, ERR_R_PASSED_INVALID_ARGUMENT); -.Ve -.PP -\fIOther pieces of software\fR -.IX Subsection "Other pieces of software" -.PP -Other pieces of software that may want to use OpenSSL's error reporting -system, such as engines or applications, must normally get their own -numbers. -.IP "\(bu" 4 -To get a \*(L"library\*(R" code, call \fBERR_get_next_error_library\fR\|(3); this gives -the calling code a dynamic number, usable for the duration of the process. -.IP "\(bu" 4 -Reason codes for each such \*(L"library\*(R" are determined or generated by the -authors of that code. They must be numbers in the range 1 to 524287 (in -other words, they must be nonzero unsigned 18 bit integers). -.PP -The exceptions mentioned in \*(L"OpenSSL library reports\*(R" above are valid for -other pieces of software, i.e. they may use \fB\s-1ERR_LIB_SYS\s0\fR to report system -errors: -.PP -.Vb 1 -\& ERR_raise(ERR_LIB_SYS, errno); -.Ve -.PP -\&... and they may use \fB\s-1ERR_R_XXX\s0\fR macros together with their own \*(L"library\*(R" -code. -.PP -.Vb 1 -\& int app_lib_code = ERR_get_next_error_library(); -\& -\& /* ... */ -\& -\& ERR_raise(app_lib_code, ERR_R_PASSED_INVALID_ARGUMENT); -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_raise()\fR, \fBERR_raise_data()\fR, \fBERR_put_error()\fR, -\&\fBERR_add_error_data()\fR, \fBERR_add_error_vdata()\fR -\&\fBERR_add_error_txt()\fR, and \fBERR_add_error_mem_bio()\fR -return no values. -.SH "NOTES" -.IX Header "NOTES" -\&\fBERR_raise()\fR, \fBERR_raise()\fR and \fBERR_put_error()\fR are implemented as macros. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_load_strings\fR\|(3), \fBERR_get_next_error_library\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -ERR_raise, ERR_raise_data, \fBERR_add_error_txt()\fR and \fBERR_add_error_mem_bio()\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_raise.3ossl b/openssl-install/share/man/man3/ERR_raise.3ossl deleted file mode 120000 index 3f08ecc2..00000000 --- a/openssl-install/share/man/man3/ERR_raise.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_put_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_raise_data.3ossl b/openssl-install/share/man/man3/ERR_raise_data.3ossl deleted file mode 120000 index 3f08ecc2..00000000 --- a/openssl-install/share/man/man3/ERR_raise_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_put_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_reason_error_string.3ossl b/openssl-install/share/man/man3/ERR_reason_error_string.3ossl deleted file mode 120000 index 15dc281a..00000000 --- a/openssl-install/share/man/man3/ERR_reason_error_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_error_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_remove_state.3ossl b/openssl-install/share/man/man3/ERR_remove_state.3ossl deleted file mode 100644 index 24c3f8c8..00000000 --- a/openssl-install/share/man/man3/ERR_remove_state.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_REMOVE_STATE 3ossl" -.TH ERR_REMOVE_STATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_remove_thread_state, ERR_remove_state \- DEPRECATED -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -The following function has been deprecated since OpenSSL 1.0.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void ERR_remove_state(unsigned long tid); -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void ERR_remove_thread_state(void *tid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_remove_state()\fR frees the error queue associated with the specified -thread, identified by \fBtid\fR. -\&\fBERR_remove_thread_state()\fR does the same thing, except the identifier is -an opaque pointer. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_remove_state()\fR and \fBERR_remove_thread_state()\fR return no value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -L\fBOPENSSL_init_crypto\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBERR_remove_state()\fR was deprecated in OpenSSL 1.0.0 and -\&\fBERR_remove_thread_state()\fR was deprecated in OpenSSL 1.1.0; these functions -and should not be used. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_remove_thread_state.3ossl b/openssl-install/share/man/man3/ERR_remove_thread_state.3ossl deleted file mode 120000 index 7e9b9b11..00000000 --- a/openssl-install/share/man/man3/ERR_remove_thread_state.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_remove_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_set_debug.3ossl b/openssl-install/share/man/man3/ERR_set_debug.3ossl deleted file mode 120000 index 14ce8371..00000000 --- a/openssl-install/share/man/man3/ERR_set_debug.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_set_error.3ossl b/openssl-install/share/man/man3/ERR_set_error.3ossl deleted file mode 120000 index 14ce8371..00000000 --- a/openssl-install/share/man/man3/ERR_set_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ERR_set_mark.3ossl b/openssl-install/share/man/man3/ERR_set_mark.3ossl deleted file mode 100644 index 194f8878..00000000 --- a/openssl-install/share/man/man3/ERR_set_mark.3ossl +++ /dev/null @@ -1,192 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "ERR_SET_MARK 3ossl" -.TH ERR_SET_MARK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ERR_set_mark, ERR_clear_last_mark, ERR_pop_to_mark, ERR_count_to_mark, ERR_pop \- -set mark, clear mark, pop errors until mark and pop last error -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int ERR_set_mark(void); -\& int ERR_pop_to_mark(void); -\& int ERR_clear_last_mark(void); -\& int ERR_count_to_mark(void); -\& int ERR_pop(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBERR_set_mark()\fR sets a mark on the current topmost error record if there -is one. -.PP -\&\fBERR_pop_to_mark()\fR will pop the top of the error stack until a mark is found. -The mark is then removed. If there is no mark, the whole stack is removed. -.PP -\&\fBERR_clear_last_mark()\fR removes the last mark added if there is one. -.PP -\&\fBERR_count_to_mark()\fR returns the number of entries on the error stack above the -most recently marked entry, not including that entry. If there is no mark in the -error stack, the number of entries in the error stack is returned. -.PP -\&\fBERR_pop()\fR unconditionally pops a single error entry from the top of the error -stack (which is the entry obtainable via \fBERR_peek_last_error\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBERR_set_mark()\fR returns 0 if the error stack is empty, otherwise 1. -.PP -\&\fBERR_clear_last_mark()\fR and \fBERR_pop_to_mark()\fR return 0 if there was no mark in the -error stack, which implies that the stack became empty, otherwise 1. -.PP -\&\fBERR_count_to_mark()\fR returns the number of error stack entries found above the -most recent mark, if any, or the total number of error stack entries. -.PP -\&\fBERR_pop()\fR returns 1 if an error was popped or 0 if the error stack was empty. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBERR_pop()\fR was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2003\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/ERR_vset_error.3ossl b/openssl-install/share/man/man3/ERR_vset_error.3ossl deleted file mode 120000 index 14ce8371..00000000 --- a/openssl-install/share/man/man3/ERR_vset_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_CERT_ID_V2_dup.3ossl b/openssl-install/share/man/man3/ESS_CERT_ID_V2_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_CERT_ID_V2_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_CERT_ID_V2_free.3ossl b/openssl-install/share/man/man3/ESS_CERT_ID_V2_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_CERT_ID_V2_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_CERT_ID_V2_new.3ossl b/openssl-install/share/man/man3/ESS_CERT_ID_V2_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_CERT_ID_V2_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_CERT_ID_dup.3ossl b/openssl-install/share/man/man3/ESS_CERT_ID_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_CERT_ID_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_CERT_ID_free.3ossl b/openssl-install/share/man/man3/ESS_CERT_ID_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_CERT_ID_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_CERT_ID_new.3ossl b/openssl-install/share/man/man3/ESS_CERT_ID_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_CERT_ID_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_dup.3ossl b/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_free.3ossl b/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_new.3ossl b/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_ISSUER_SERIAL_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_dup.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_free.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_it.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_new.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_V2_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_dup.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_free.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_it.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ESS_SIGNING_CERT_new.3ossl b/openssl-install/share/man/man3/ESS_SIGNING_CERT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ESS_SIGNING_CERT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_do_all_provided.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_fetch.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_fetch.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_free.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_free.3ossl deleted file mode 100644 index b6cc781d..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_free.3ossl +++ /dev/null @@ -1,243 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_ASYM_CIPHER_FREE 3ossl" -.TH EVP_ASYM_CIPHER_FREE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_ASYM_CIPHER_fetch, EVP_ASYM_CIPHER_free, EVP_ASYM_CIPHER_up_ref, -EVP_ASYM_CIPHER_is_a, EVP_ASYM_CIPHER_get0_provider, -EVP_ASYM_CIPHER_do_all_provided, EVP_ASYM_CIPHER_names_do_all, -EVP_ASYM_CIPHER_get0_name, EVP_ASYM_CIPHER_get0_description, -EVP_ASYM_CIPHER_gettable_ctx_params, EVP_ASYM_CIPHER_settable_ctx_params -\&\- Functions to manage EVP_ASYM_CIPHER algorithm objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_ASYM_CIPHER *EVP_ASYM_CIPHER_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, -\& const char *properties); -\& void EVP_ASYM_CIPHER_free(EVP_ASYM_CIPHER *cipher); -\& int EVP_ASYM_CIPHER_up_ref(EVP_ASYM_CIPHER *cipher); -\& const char *EVP_ASYM_CIPHER_get0_name(const EVP_ASYM_CIPHER *cipher); -\& int EVP_ASYM_CIPHER_is_a(const EVP_ASYM_CIPHER *cipher, const char *name); -\& OSSL_PROVIDER *EVP_ASYM_CIPHER_get0_provider(const EVP_ASYM_CIPHER *cipher); -\& void EVP_ASYM_CIPHER_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_ASYM_CIPHER *cipher, -\& void *arg), -\& void *arg); -\& int EVP_ASYM_CIPHER_names_do_all(const EVP_ASYM_CIPHER *cipher, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const char *EVP_ASYM_CIPHER_get0_description(const EVP_ASYM_CIPHER *cipher); -\& const OSSL_PARAM *EVP_ASYM_CIPHER_gettable_ctx_params(const EVP_ASYM_CIPHER *cip); -\& const OSSL_PARAM *EVP_ASYM_CIPHER_settable_ctx_params(const EVP_ASYM_CIPHER *cip); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_ASYM_CIPHER_fetch()\fR fetches the implementation for the given -\&\fBalgorithm\fR from any provider offering it, within the criteria given -by the \fBproperties\fR and in the scope of the given library context \fBctx\fR (see -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3)). The algorithm will be one offering functions for performing -asymmetric cipher related tasks such as asymmetric encryption and decryption. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.PP -The returned value must eventually be freed with \fBEVP_ASYM_CIPHER_free()\fR. -.PP -\&\fBEVP_ASYM_CIPHER_free()\fR decrements the reference count for the \fB\s-1EVP_ASYM_CIPHER\s0\fR -structure. Typically this structure will have been obtained from an earlier call -to \fBEVP_ASYM_CIPHER_fetch()\fR. If the reference count drops to 0 then the -structure is freed. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_ASYM_CIPHER_up_ref()\fR increments the reference count for an -\&\fB\s-1EVP_ASYM_CIPHER\s0\fR structure. -.PP -\&\fBEVP_ASYM_CIPHER_is_a()\fR returns 1 if \fIcipher\fR is an implementation of an -algorithm that's identifiable with \fIname\fR, otherwise 0. -.PP -\&\fBEVP_ASYM_CIPHER_get0_provider()\fR returns the provider that \fIcipher\fR was -fetched from. -.PP -\&\fBEVP_ASYM_CIPHER_do_all_provided()\fR traverses all EVP_ASYM_CIPHERs implemented by -all activated providers in the given library context \fIlibctx\fR, and for each of -the implementations, calls the given function \fIfn\fR with the implementation -method and the given \fIarg\fR as argument. -.PP -\&\fBEVP_ASYM_CIPHER_get0_name()\fR returns the algorithm name from the provided -implementation for the given \fIcipher\fR. Note that the \fIcipher\fR may have -multiple synonyms associated with it. In this case the first name from the -algorithm definition is returned. Ownership of the returned string is retained -by the \fIcipher\fR object and should not be freed by the caller. -.PP -\&\fBEVP_ASYM_CIPHER_names_do_all()\fR traverses all names for \fIcipher\fR, and calls -\&\fIfn\fR with each name and \fIdata\fR. -.PP -\&\fBEVP_ASYM_CIPHER_get0_description()\fR returns a description of the \fIcipher\fR, -meant for display and human consumption. The description is at the -discretion of the \fIcipher\fR implementation. -.PP -\&\fBEVP_ASYM_CIPHER_gettable_ctx_params()\fR and \fBEVP_ASYM_CIPHER_settable_ctx_params()\fR -return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the names and types of key -parameters that can be retrieved or set by a key encryption algorithm using -\&\fBEVP_PKEY_CTX_get_params\fR\|(3) and \fBEVP_PKEY_CTX_set_params\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_ASYM_CIPHER_fetch()\fR returns a pointer to an \fB\s-1EVP_ASYM_CIPHER\s0\fR for success -or \fB\s-1NULL\s0\fR for failure. -.PP -\&\fBEVP_ASYM_CIPHER_up_ref()\fR returns 1 for success or 0 otherwise. -.PP -\&\fBEVP_ASYM_CIPHER_names_do_all()\fR returns 1 if the callback was called for all -names. A return value of 0 means that the callback was not called for any names. -.PP -\&\fBEVP_ASYM_CIPHER_gettable_ctx_params()\fR and \fBEVP_ASYM_CIPHER_settable_ctx_params()\fR -return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7), \s-1\fBOSSL_PROVIDER\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_description.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_description.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_name.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_name.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_provider.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_gettable_ctx_params.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_is_a.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_is_a.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_names_do_all.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_settable_ctx_params.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_up_ref.3ossl b/openssl-install/share/man/man3/EVP_ASYM_CIPHER_up_ref.3ossl deleted file mode 120000 index b62419c4..00000000 --- a/openssl-install/share/man/man3/EVP_ASYM_CIPHER_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_ASYM_CIPHER_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_BytesToKey.3ossl b/openssl-install/share/man/man3/EVP_BytesToKey.3ossl deleted file mode 100644 index f57877b4..00000000 --- a/openssl-install/share/man/man3/EVP_BytesToKey.3ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_BYTESTOKEY 3ossl" -.TH EVP_BYTESTOKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_BytesToKey \- password based encryption routine -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_BytesToKey(const EVP_CIPHER *type, const EVP_MD *md, -\& const unsigned char *salt, -\& const unsigned char *data, int datal, int count, -\& unsigned char *key, unsigned char *iv); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_BytesToKey()\fR derives a key and \s-1IV\s0 from various parameters. \fBtype\fR is -the cipher to derive the key and \s-1IV\s0 for. \fBmd\fR is the message digest to use. -The \fBsalt\fR parameter is used as a salt in the derivation: it should point to -an 8 byte buffer or \s-1NULL\s0 if no salt is used. \fBdata\fR is a buffer containing -\&\fBdatal\fR bytes which is used to derive the keying data. \fBcount\fR is the -iteration count to use. The derived key and \s-1IV\s0 will be written to \fBkey\fR -and \fBiv\fR respectively. -.SH "NOTES" -.IX Header "NOTES" -A typical application of this function is to derive keying material for an -encryption algorithm from a password in the \fBdata\fR parameter. -.PP -Increasing the \fBcount\fR parameter slows down the algorithm which makes it -harder for an attacker to perform a brute force attack using a large number -of candidate passwords. -.PP -If the total key and \s-1IV\s0 length is less than the digest length and -\&\fB\s-1MD5\s0\fR is used then the derivation algorithm is compatible with PKCS#5 v1.5 -otherwise a non standard extension is used to derive the extra data. -.PP -Newer applications should use a more modern algorithm such as \s-1PBKDF2\s0 as -defined in PKCS#5v2.1 and provided by \s-1PKCS5_PBKDF2_HMAC.\s0 -.SH "KEY DERIVATION ALGORITHM" -.IX Header "KEY DERIVATION ALGORITHM" -The key and \s-1IV\s0 is derived by concatenating D_1, D_2, etc until -enough data is available for the key and \s-1IV.\s0 D_i is defined as: -.PP -.Vb 1 -\& D_i = HASH^count(D_(i\-1) || data || salt) -.Ve -.PP -where || denotes concatenation, D_0 is empty, \s-1HASH\s0 is the digest -algorithm in use, HASH^1(data) is simply \s-1HASH\s0(data), HASH^2(data) -is \s-1HASH\s0(\s-1HASH\s0(data)) and so on. -.PP -The initial bytes are used for the key and the subsequent bytes for -the \s-1IV.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If \fBdata\fR is \s-1NULL,\s0 then \fBEVP_BytesToKey()\fR returns the number of bytes -needed to store the derived key. -Otherwise, \fBEVP_BytesToKey()\fR returns the size of the derived key in bytes, -or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), \fBRAND_bytes\fR\|(3), -\&\s-1\fBPKCS5_PBKDF2_HMAC\s0\fR\|(3), -\&\fBEVP_EncryptInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_block_size.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_block_size.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_cipher.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_cipher.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_clear_flags.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_clear_flags.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_copy.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_copy.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_ctrl.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_ctrl.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_dup.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_dup.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_encrypting.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_encrypting.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_encrypting.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_flags.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_flags.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_free.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_free.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_cipher.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_cipher.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_name.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_name.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get1_cipher.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get1_cipher.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get1_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor.3ossl deleted file mode 120000 index 4ab4a12c..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get_algor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor_params.3ossl deleted file mode 120000 index 4ab4a12c..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_algor_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get_algor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_app_data.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_app_data.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_block_size.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_block_size.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_cipher_data.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_cipher_data.3ossl deleted file mode 100644 index e51e8d2f..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_cipher_data.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER_CTX_GET_CIPHER_DATA 3ossl" -.TH EVP_CIPHER_CTX_GET_CIPHER_DATA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER_CTX_get_cipher_data, EVP_CIPHER_CTX_set_cipher_data \- Routines to -inspect and modify EVP_CIPHER_CTX objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void *EVP_CIPHER_CTX_get_cipher_data(const EVP_CIPHER_CTX *ctx); -\& void *EVP_CIPHER_CTX_set_cipher_data(EVP_CIPHER_CTX *ctx, void *cipher_data); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_CIPHER_CTX_get_cipher_data()\fR function returns a pointer to the cipher -data relevant to \s-1EVP_CIPHER_CTX.\s0 The contents of this data is specific to the -particular implementation of the cipher. For example this data can be used by -engines to store engine specific information. The data is automatically -allocated and freed by OpenSSL, so applications and engines should not normally -free this directly (but see below). -.PP -The \fBEVP_CIPHER_CTX_set_cipher_data()\fR function allows an application or engine to -replace the cipher data with new data. A pointer to any existing cipher data is -returned from this function. If the old data is no longer required then it -should be freed through a call to \fBOPENSSL_free()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBEVP_CIPHER_CTX_get_cipher_data()\fR function returns a pointer to the current -cipher data for the \s-1EVP_CIPHER_CTX.\s0 -.PP -The \fBEVP_CIPHER_CTX_set_cipher_data()\fR function returns a pointer to the old -cipher data for the \s-1EVP_CIPHER_CTX.\s0 -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_CIPHER_CTX_get_cipher_data()\fR and \fBEVP_CIPHER_CTX_set_cipher_data()\fR -functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_iv_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_iv_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_iv_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_key_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_key_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_key_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_mode.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_mode.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_nid.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_nid.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_num.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_num.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_original_iv.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_original_iv.3ossl deleted file mode 100644 index 375587a4..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_original_iv.3ossl +++ /dev/null @@ -1,208 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER_CTX_GET_ORIGINAL_IV 3ossl" -.TH EVP_CIPHER_CTX_GET_ORIGINAL_IV 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER_CTX_get_original_iv, EVP_CIPHER_CTX_get_updated_iv, -EVP_CIPHER_CTX_iv, EVP_CIPHER_CTX_original_iv, -EVP_CIPHER_CTX_iv_noconst \- Routines to inspect EVP_CIPHER_CTX IV data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_CIPHER_CTX_get_original_iv(EVP_CIPHER_CTX *ctx, void *buf, size_t len); -\& int EVP_CIPHER_CTX_get_updated_iv(EVP_CIPHER_CTX *ctx, void *buf, size_t len); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& const unsigned char *EVP_CIPHER_CTX_iv(const EVP_CIPHER_CTX *ctx); -\& const unsigned char *EVP_CIPHER_CTX_original_iv(const EVP_CIPHER_CTX *ctx); -\& unsigned char *EVP_CIPHER_CTX_iv_noconst(EVP_CIPHER_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_CIPHER_CTX_get_original_iv()\fR and \fBEVP_CIPHER_CTX_get_updated_iv()\fR copy -initialization vector (\s-1IV\s0) information from the \fB\s-1EVP_CIPHER_CTX\s0\fR into the -caller-supplied buffer. \fBEVP_CIPHER_CTX_get_iv_length\fR\|(3) can be used to -determine an appropriate buffer size, and if the supplied buffer is too small, -an error will be returned (and no data copied). -\&\fBEVP_CIPHER_CTX_get_original_iv()\fR accesses the (\*(L"original\*(R") \s-1IV\s0 that was -supplied when the \fB\s-1EVP_CIPHER_CTX\s0\fR was initialized, and -\&\fBEVP_CIPHER_CTX_get_updated_iv()\fR accesses the current \*(L"\s-1IV\s0 state\*(R" -of the cipher, which is updated during cipher operation for certain cipher modes -(e.g., \s-1CBC\s0 and \s-1OFB\s0). -.PP -The functions \fBEVP_CIPHER_CTX_iv()\fR, \fBEVP_CIPHER_CTX_original_iv()\fR, and -\&\fBEVP_CIPHER_CTX_iv_noconst()\fR are deprecated functions that provide similar (at -a conceptual level) functionality. \fBEVP_CIPHER_CTX_iv()\fR returns a pointer to -the beginning of the \*(L"\s-1IV\s0 state\*(R" as maintained internally in the -\&\fB\s-1EVP_CIPHER_CTX\s0\fR; \fBEVP_CIPHER_CTX_original_iv()\fR returns a pointer to the -beginning of the (\*(L"original\*(R") \s-1IV,\s0 as maintained by the \fB\s-1EVP_CIPHER_CTX\s0\fR, that -was provided when the \fB\s-1EVP_CIPHER_CTX\s0\fR was initialized; and -\&\fBEVP_CIPHER_CTX_get_iv_noconst()\fR is the same as \fBEVP_CIPHER_CTX_iv()\fR but has a -different return type for the pointer. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_CIPHER_CTX_get_original_iv()\fR and \fBEVP_CIPHER_CTX_get_updated_iv()\fR return 1 -on success and 0 on failure. -.PP -The functions \fBEVP_CIPHER_CTX_iv()\fR, \fBEVP_CIPHER_CTX_original_iv()\fR, and -\&\fBEVP_CIPHER_CTX_iv_noconst()\fR return a pointer to an \s-1IV\s0 as an array of bytes on -success, and \s-1NULL\s0 on failure. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_CIPHER_CTX_get_original_iv()\fR and \fBEVP_CIPHER_CTX_get_updated_iv()\fR were added -in OpenSSL 3.0.0. -.PP -\&\fBEVP_CIPHER_CTX_iv()\fR, \fBEVP_CIPHER_CTX_original_iv()\fR, and -\&\fBEVP_CIPHER_CTX_iv_noconst()\fR were added in OpenSSL 1.1.0, and were deprecated -in OpenSSL 3.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_tag_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_tag_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_tag_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_type.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_type.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_updated_iv.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_updated_iv.3ossl deleted file mode 120000 index 3d0606b1..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_get_updated_iv.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_CTX_get_original_iv.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_gettable_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_is_encrypting.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_is_encrypting.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_is_encrypting.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv.3ossl deleted file mode 120000 index 3d0606b1..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_CTX_get_original_iv.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_noconst.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_noconst.3ossl deleted file mode 120000 index 3d0606b1..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_iv_noconst.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_CTX_get_original_iv.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_key_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_key_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_key_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_mode.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_mode.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_new.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_new.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_nid.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_nid.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_num.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_num.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_original_iv.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_original_iv.3ossl deleted file mode 120000 index 3d0606b1..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_original_iv.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_CTX_get_original_iv.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_reset.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_reset.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_reset.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_algor_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_algor_params.3ossl deleted file mode 120000 index 4ab4a12c..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_algor_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get_algor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_app_data.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_app_data.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_cipher_data.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_cipher_data.3ossl deleted file mode 120000 index b3a667e3..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_cipher_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_CTX_get_cipher_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_flags.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_flags.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_key_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_key_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_key_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_num.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_num.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_padding.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_padding.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_padding.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_settable_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_settable_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_tag_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_tag_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_tag_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_test_flags.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_test_flags.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_test_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_CTX_type.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_CTX_type.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_CTX_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_asn1_to_param.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_asn1_to_param.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_asn1_to_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_block_size.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_block_size.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_do_all_provided.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_fetch.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_fetch.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_flags.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_flags.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_free.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_free.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get0_description.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get0_description.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get0_name.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get0_name.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get0_provider.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_block_size.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_block_size.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_flags.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_flags.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_iv_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_iv_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_iv_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_key_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_key_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_key_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_mode.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_mode.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_nid.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_nid.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_get_type.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_get_type.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_gettable_ctx_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_gettable_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_is_a.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_is_a.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_iv_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_iv_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_iv_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_key_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_key_length.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_key_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_dup.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_dup.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_free.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_free.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_cleanup.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_get_cleanup.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_ctrl.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_get_ctrl.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_do_cipher.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_get_do_cipher.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_do_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_get_asn1_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_get_get_asn1_params.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_get_asn1_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_init.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_get_init.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_set_asn1_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_get_set_asn1_params.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_get_set_asn1_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_new.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_new.3ossl deleted file mode 100644 index 8d839659..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_new.3ossl +++ /dev/null @@ -1,371 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER_METH_NEW 3ossl" -.TH EVP_CIPHER_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER_meth_new, EVP_CIPHER_meth_dup, EVP_CIPHER_meth_free, -EVP_CIPHER_meth_set_iv_length, EVP_CIPHER_meth_set_flags, -EVP_CIPHER_meth_set_impl_ctx_size, EVP_CIPHER_meth_set_init, -EVP_CIPHER_meth_set_do_cipher, EVP_CIPHER_meth_set_cleanup, -EVP_CIPHER_meth_set_set_asn1_params, EVP_CIPHER_meth_set_get_asn1_params, -EVP_CIPHER_meth_set_ctrl, EVP_CIPHER_meth_get_init, -EVP_CIPHER_meth_get_do_cipher, EVP_CIPHER_meth_get_cleanup, -EVP_CIPHER_meth_get_set_asn1_params, EVP_CIPHER_meth_get_get_asn1_params, -EVP_CIPHER_meth_get_ctrl -\&\- Routines to build up EVP_CIPHER methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& EVP_CIPHER *EVP_CIPHER_meth_new(int cipher_type, int block_size, int key_len); -\& EVP_CIPHER *EVP_CIPHER_meth_dup(const EVP_CIPHER *cipher); -\& void EVP_CIPHER_meth_free(EVP_CIPHER *cipher); -\& -\& int EVP_CIPHER_meth_set_iv_length(EVP_CIPHER *cipher, int iv_len); -\& int EVP_CIPHER_meth_set_flags(EVP_CIPHER *cipher, unsigned long flags); -\& int EVP_CIPHER_meth_set_impl_ctx_size(EVP_CIPHER *cipher, int ctx_size); -\& int EVP_CIPHER_meth_set_init(EVP_CIPHER *cipher, -\& int (*init)(EVP_CIPHER_CTX *ctx, -\& const unsigned char *key, -\& const unsigned char *iv, -\& int enc)); -\& int EVP_CIPHER_meth_set_do_cipher(EVP_CIPHER *cipher, -\& int (*do_cipher)(EVP_CIPHER_CTX *ctx, -\& unsigned char *out, -\& const unsigned char *in, -\& size_t inl)); -\& int EVP_CIPHER_meth_set_cleanup(EVP_CIPHER *cipher, -\& int (*cleanup)(EVP_CIPHER_CTX *)); -\& int EVP_CIPHER_meth_set_set_asn1_params(EVP_CIPHER *cipher, -\& int (*set_asn1_parameters)(EVP_CIPHER_CTX *, -\& ASN1_TYPE *)); -\& int EVP_CIPHER_meth_set_get_asn1_params(EVP_CIPHER *cipher, -\& int (*get_asn1_parameters)(EVP_CIPHER_CTX *, -\& ASN1_TYPE *)); -\& int EVP_CIPHER_meth_set_ctrl(EVP_CIPHER *cipher, -\& int (*ctrl)(EVP_CIPHER_CTX *, int type, -\& int arg, void *ptr)); -\& -\& int (*EVP_CIPHER_meth_get_init(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx, -\& const unsigned char *key, -\& const unsigned char *iv, -\& int enc); -\& int (*EVP_CIPHER_meth_get_do_cipher(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx, -\& unsigned char *out, -\& const unsigned char *in, -\& size_t inl); -\& int (*EVP_CIPHER_meth_get_cleanup(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *); -\& int (*EVP_CIPHER_meth_get_set_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, -\& ASN1_TYPE *); -\& int (*EVP_CIPHER_meth_get_get_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, -\& ASN1_TYPE *); -\& int (*EVP_CIPHER_meth_get_ctrl(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, -\& int type, int arg, -\& void *ptr); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the \s-1OSSL_PROVIDER\s0 APIs. -.PP -The \fB\s-1EVP_CIPHER\s0\fR type is a structure for symmetric cipher method -implementation. -.PP -\&\fBEVP_CIPHER_meth_new()\fR creates a new \fB\s-1EVP_CIPHER\s0\fR structure. -.PP -\&\fBEVP_CIPHER_meth_dup()\fR creates a copy of \fBcipher\fR. -.PP -\&\fBEVP_CIPHER_meth_free()\fR destroys a \fB\s-1EVP_CIPHER\s0\fR structure. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_CIPHER_meth_set_iv_length()\fR sets the length of the \s-1IV.\s0 -This is only needed when the implemented cipher mode requires it. -.PP -\&\fBEVP_CIPHER_meth_set_flags()\fR sets the flags to describe optional -behaviours in the particular \fBcipher\fR. -With the exception of cipher modes, of which only one may be present, -several flags can be or'd together. -The available flags are: -.IP "\s-1EVP_CIPH_STREAM_CIPHER, EVP_CIPH_ECB_MODE EVP_CIPH_CBC_MODE, EVP_CIPH_CFB_MODE, EVP_CIPH_OFB_MODE, EVP_CIPH_CTR_MODE, EVP_CIPH_GCM_MODE, EVP_CIPH_CCM_MODE, EVP_CIPH_XTS_MODE, EVP_CIPH_WRAP_MODE, EVP_CIPH_OCB_MODE, EVP_CIPH_SIV_MODE\s0" 4 -.IX Item "EVP_CIPH_STREAM_CIPHER, EVP_CIPH_ECB_MODE EVP_CIPH_CBC_MODE, EVP_CIPH_CFB_MODE, EVP_CIPH_OFB_MODE, EVP_CIPH_CTR_MODE, EVP_CIPH_GCM_MODE, EVP_CIPH_CCM_MODE, EVP_CIPH_XTS_MODE, EVP_CIPH_WRAP_MODE, EVP_CIPH_OCB_MODE, EVP_CIPH_SIV_MODE" -The cipher mode. -.IP "\s-1EVP_CIPH_VARIABLE_LENGTH\s0" 4 -.IX Item "EVP_CIPH_VARIABLE_LENGTH" -This cipher is of variable length. -.IP "\s-1EVP_CIPH_CUSTOM_IV\s0" 4 -.IX Item "EVP_CIPH_CUSTOM_IV" -Storing and initialising the \s-1IV\s0 is left entirely to the -implementation. -.IP "\s-1EVP_CIPH_ALWAYS_CALL_INIT\s0" 4 -.IX Item "EVP_CIPH_ALWAYS_CALL_INIT" -Set this if the implementation's \fBinit()\fR function should be called even -if \fBkey\fR is \fB\s-1NULL\s0\fR. -.IP "\s-1EVP_CIPH_CTRL_INIT\s0" 4 -.IX Item "EVP_CIPH_CTRL_INIT" -Set this to have the implementation's \fBctrl()\fR function called with -command code \fB\s-1EVP_CTRL_INIT\s0\fR early in its setup. -.IP "\s-1EVP_CIPH_CUSTOM_KEY_LENGTH\s0" 4 -.IX Item "EVP_CIPH_CUSTOM_KEY_LENGTH" -Checking and setting the key length after creating the \fB\s-1EVP_CIPHER\s0\fR -is left to the implementation. -Whenever someone uses \fBEVP_CIPHER_CTX_set_key_length()\fR on a -\&\fB\s-1EVP_CIPHER\s0\fR with this flag set, the implementation's \fBctrl()\fR function -will be called with the control code \fB\s-1EVP_CTRL_SET_KEY_LENGTH\s0\fR and -the key length in \fBarg\fR. -.IP "\s-1EVP_CIPH_NO_PADDING\s0" 4 -.IX Item "EVP_CIPH_NO_PADDING" -Don't use standard block padding. -.IP "\s-1EVP_CIPH_RAND_KEY\s0" 4 -.IX Item "EVP_CIPH_RAND_KEY" -Making a key with random content is left to the implementation. -This is done by calling the implementation's \fBctrl()\fR function with the -control code \fB\s-1EVP_CTRL_RAND_KEY\s0\fR and the pointer to the key memory -storage in \fBptr\fR. -.IP "\s-1EVP_CIPH_CUSTOM_COPY\s0" 4 -.IX Item "EVP_CIPH_CUSTOM_COPY" -Set this to have the implementation's \fBctrl()\fR function called with -command code \fB\s-1EVP_CTRL_COPY\s0\fR at the end of \fBEVP_CIPHER_CTX_copy()\fR. -The intended use is for further things to deal with after the -implementation specific data block has been copied. -The destination \fB\s-1EVP_CIPHER_CTX\s0\fR is passed to the control with the -\&\fBptr\fR parameter. -The implementation specific data block is reached with -\&\fBEVP_CIPHER_CTX_get_cipher_data()\fR. -.IP "\s-1EVP_CIPH_FLAG_DEFAULT_ASN1\s0" 4 -.IX Item "EVP_CIPH_FLAG_DEFAULT_ASN1" -Use the default \s-1EVP\s0 routines to pass \s-1IV\s0 to and from \s-1ASN.1.\s0 -.IP "\s-1EVP_CIPH_FLAG_LENGTH_BITS\s0" 4 -.IX Item "EVP_CIPH_FLAG_LENGTH_BITS" -Signals that the length of the input buffer for encryption / -decryption is to be understood as the number of bits instead of -bytes for this implementation. -This is only useful for \s-1CFB1\s0 ciphers. -.IP "\s-1EVP_CIPH_FLAG_CTS\s0" 4 -.IX Item "EVP_CIPH_FLAG_CTS" -Indicates that the cipher uses ciphertext stealing. This is currently -used to indicate that the cipher is a one shot that only allows a single call to -\&\fBEVP_CipherUpdate()\fR. -.IP "\s-1EVP_CIPH_FLAG_CUSTOM_CIPHER\s0" 4 -.IX Item "EVP_CIPH_FLAG_CUSTOM_CIPHER" -This indicates that the implementation takes care of everything, -including padding, buffering and finalization. -The \s-1EVP\s0 routines will simply give them control and do nothing more. -.IP "\s-1EVP_CIPH_FLAG_AEAD_CIPHER\s0" 4 -.IX Item "EVP_CIPH_FLAG_AEAD_CIPHER" -This indicates that this is an \s-1AEAD\s0 cipher implementation. -.IP "\s-1EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK\s0" 4 -.IX Item "EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK" -Allow interleaving of crypto blocks, a particular optimization only applicable -to certain \s-1TLS\s0 ciphers. -.PP -\&\fBEVP_CIPHER_meth_set_impl_ctx_size()\fR sets the size of the \s-1EVP_CIPHER\s0's -implementation context so that it can be automatically allocated. -.PP -\&\fBEVP_CIPHER_meth_set_init()\fR sets the cipher init function for -\&\fBcipher\fR. -The cipher init function is called by \fBEVP_CipherInit()\fR, -\&\fBEVP_CipherInit_ex()\fR, \fBEVP_EncryptInit()\fR, \fBEVP_EncryptInit_ex()\fR, -\&\fBEVP_DecryptInit()\fR, \fBEVP_DecryptInit_ex()\fR. -.PP -\&\fBEVP_CIPHER_meth_set_do_cipher()\fR sets the cipher function for -\&\fBcipher\fR. -The cipher function is called by \fBEVP_CipherUpdate()\fR, -\&\fBEVP_EncryptUpdate()\fR, \fBEVP_DecryptUpdate()\fR, \fBEVP_CipherFinal()\fR, -\&\fBEVP_EncryptFinal()\fR, \fBEVP_EncryptFinal_ex()\fR, \fBEVP_DecryptFinal()\fR and -\&\fBEVP_DecryptFinal_ex()\fR. -.PP -\&\fBEVP_CIPHER_meth_set_cleanup()\fR sets the function for \fBcipher\fR to do -extra cleanup before the method's private data structure is cleaned -out and freed. -Note that the cleanup function is passed a \fB\s-1EVP_CIPHER_CTX\s0 *\fR, the -private data structure is then available with -\&\fBEVP_CIPHER_CTX_get_cipher_data()\fR. -This cleanup function is called by \fBEVP_CIPHER_CTX_reset()\fR and -\&\fBEVP_CIPHER_CTX_free()\fR. -.PP -\&\fBEVP_CIPHER_meth_set_set_asn1_params()\fR sets the function for \fBcipher\fR -to set the AlgorithmIdentifier \*(L"parameter\*(R" based on the passed cipher. -This function is called by \fBEVP_CIPHER_param_to_asn1()\fR. -\&\fBEVP_CIPHER_meth_set_get_asn1_params()\fR sets the function for \fBcipher\fR -that sets the cipher parameters based on an \s-1ASN.1\s0 AlgorithmIdentifier -\&\*(L"parameter\*(R". -Both these functions are needed when there is a need for custom data -(more or other than the cipher \s-1IV\s0). -They are called by \fBEVP_CIPHER_param_to_asn1()\fR and -\&\fBEVP_CIPHER_asn1_to_param()\fR respectively if defined. -.PP -\&\fBEVP_CIPHER_meth_set_ctrl()\fR sets the control function for \fBcipher\fR. -.PP -\&\fBEVP_CIPHER_meth_get_init()\fR, \fBEVP_CIPHER_meth_get_do_cipher()\fR, -\&\fBEVP_CIPHER_meth_get_cleanup()\fR, \fBEVP_CIPHER_meth_get_set_asn1_params()\fR, -\&\fBEVP_CIPHER_meth_get_get_asn1_params()\fR and \fBEVP_CIPHER_meth_get_ctrl()\fR -are all used to retrieve the method data given with the -EVP_CIPHER_meth_set_*() functions above. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_CIPHER_meth_new()\fR and \fBEVP_CIPHER_meth_dup()\fR return a pointer to a -newly created \fB\s-1EVP_CIPHER\s0\fR, or \s-1NULL\s0 on failure. -All EVP_CIPHER_meth_set_*() functions return 1. -All EVP_CIPHER_meth_get_*() functions return pointers to their -respective \fBcipher\fR function. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_EncryptInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -The functions described here were added in OpenSSL 1.1.0. -The \fB\s-1EVP_CIPHER\s0\fR structure created with these functions became reference -counted in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_cleanup.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_cleanup.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_ctrl.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_ctrl.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_do_cipher.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_do_cipher.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_do_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_flags.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_flags.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_get_asn1_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_get_asn1_params.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_get_asn1_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_impl_ctx_size.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_impl_ctx_size.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_impl_ctx_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_init.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_init.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_iv_length.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_iv_length.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_iv_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_set_asn1_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_meth_set_set_asn1_params.3ossl deleted file mode 120000 index 347ed301..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_meth_set_set_asn1_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_CIPHER_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_mode.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_mode.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_name.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_name.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_names_do_all.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_nid.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_nid.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_param_to_asn1.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_param_to_asn1.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_param_to_asn1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_settable_ctx_params.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_type.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_type.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CIPHER_up_ref.3ossl b/openssl-install/share/man/man3/EVP_CIPHER_up_ref.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CIPHER_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_Cipher.3ossl b/openssl-install/share/man/man3/EVP_Cipher.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_Cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CipherFinal.3ossl b/openssl-install/share/man/man3/EVP_CipherFinal.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CipherFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CipherFinal_ex.3ossl b/openssl-install/share/man/man3/EVP_CipherFinal_ex.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CipherFinal_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CipherInit.3ossl b/openssl-install/share/man/man3/EVP_CipherInit.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CipherInit.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CipherInit_ex.3ossl b/openssl-install/share/man/man3/EVP_CipherInit_ex.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CipherInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CipherInit_ex2.3ossl b/openssl-install/share/man/man3/EVP_CipherInit_ex2.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CipherInit_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_CipherUpdate.3ossl b/openssl-install/share/man/man3/EVP_CipherUpdate.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_CipherUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecodeBlock.3ossl b/openssl-install/share/man/man3/EVP_DecodeBlock.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_DecodeBlock.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecodeFinal.3ossl b/openssl-install/share/man/man3/EVP_DecodeFinal.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_DecodeFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecodeInit.3ossl b/openssl-install/share/man/man3/EVP_DecodeInit.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_DecodeInit.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecodeUpdate.3ossl b/openssl-install/share/man/man3/EVP_DecodeUpdate.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_DecodeUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecryptFinal.3ossl b/openssl-install/share/man/man3/EVP_DecryptFinal.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_DecryptFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecryptFinal_ex.3ossl b/openssl-install/share/man/man3/EVP_DecryptFinal_ex.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_DecryptFinal_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecryptInit.3ossl b/openssl-install/share/man/man3/EVP_DecryptInit.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_DecryptInit.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecryptInit_ex.3ossl b/openssl-install/share/man/man3/EVP_DecryptInit_ex.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_DecryptInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecryptInit_ex2.3ossl b/openssl-install/share/man/man3/EVP_DecryptInit_ex2.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_DecryptInit_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DecryptUpdate.3ossl b/openssl-install/share/man/man3/EVP_DecryptUpdate.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_DecryptUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_Digest.3ossl b/openssl-install/share/man/man3/EVP_Digest.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_Digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestFinal.3ossl b/openssl-install/share/man/man3/EVP_DigestFinal.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_DigestFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestFinalXOF.3ossl b/openssl-install/share/man/man3/EVP_DigestFinalXOF.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_DigestFinalXOF.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestFinal_ex.3ossl b/openssl-install/share/man/man3/EVP_DigestFinal_ex.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_DigestFinal_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestInit.3ossl b/openssl-install/share/man/man3/EVP_DigestInit.3ossl deleted file mode 100644 index 74b3fe59..00000000 --- a/openssl-install/share/man/man3/EVP_DigestInit.3ossl +++ /dev/null @@ -1,880 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_DIGESTINIT 3ossl" -.TH EVP_DIGESTINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD_fetch, EVP_MD_up_ref, EVP_MD_free, -EVP_MD_get_params, EVP_MD_gettable_params, -EVP_MD_CTX_new, EVP_MD_CTX_reset, EVP_MD_CTX_free, EVP_MD_CTX_dup, -EVP_MD_CTX_copy, EVP_MD_CTX_copy_ex, EVP_MD_CTX_ctrl, -EVP_MD_CTX_set_params, EVP_MD_CTX_get_params, -EVP_MD_settable_ctx_params, EVP_MD_gettable_ctx_params, -EVP_MD_CTX_settable_params, EVP_MD_CTX_gettable_params, -EVP_MD_CTX_set_flags, EVP_MD_CTX_clear_flags, EVP_MD_CTX_test_flags, -EVP_Q_digest, EVP_Digest, EVP_DigestInit_ex2, EVP_DigestInit_ex, EVP_DigestInit, -EVP_DigestUpdate, EVP_DigestFinal_ex, EVP_DigestFinalXOF, EVP_DigestFinal, -EVP_DigestSqueeze, -EVP_MD_is_a, EVP_MD_get0_name, EVP_MD_get0_description, -EVP_MD_names_do_all, EVP_MD_get0_provider, EVP_MD_get_type, -EVP_MD_get_pkey_type, EVP_MD_get_size, EVP_MD_get_block_size, EVP_MD_get_flags, -EVP_MD_CTX_get0_name, EVP_MD_CTX_md, EVP_MD_CTX_get0_md, EVP_MD_CTX_get1_md, -EVP_MD_CTX_get_type, EVP_MD_CTX_get_size_ex, EVP_MD_CTX_get_block_size, -EVP_MD_CTX_get0_md_data, EVP_MD_CTX_update_fn, EVP_MD_CTX_set_update_fn, -EVP_md_null, -EVP_get_digestbyname, EVP_get_digestbynid, EVP_get_digestbyobj, -EVP_MD_CTX_get_pkey_ctx, EVP_MD_CTX_set_pkey_ctx, -EVP_MD_do_all_provided, -EVP_MD_type, EVP_MD_nid, EVP_MD_name, EVP_MD_pkey_type, EVP_MD_size, -EVP_MD_block_size, EVP_MD_flags, EVP_MD_xof, -EVP_MD_CTX_size, EVP_MD_CTX_get_size, EVP_MD_CTX_block_size, -EVP_MD_CTX_type, EVP_MD_CTX_pkey_ctx, EVP_MD_CTX_md_data -\&\- EVP digest routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_MD *EVP_MD_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, -\& const char *properties); -\& int EVP_MD_up_ref(EVP_MD *md); -\& void EVP_MD_free(EVP_MD *md); -\& int EVP_MD_get_params(const EVP_MD *digest, OSSL_PARAM params[]); -\& const OSSL_PARAM *EVP_MD_gettable_params(const EVP_MD *digest); -\& EVP_MD_CTX *EVP_MD_CTX_new(void); -\& int EVP_MD_CTX_reset(EVP_MD_CTX *ctx); -\& void EVP_MD_CTX_free(EVP_MD_CTX *ctx); -\& void EVP_MD_CTX_ctrl(EVP_MD_CTX *ctx, int cmd, int p1, void* p2); -\& int EVP_MD_CTX_get_params(EVP_MD_CTX *ctx, OSSL_PARAM params[]); -\& int EVP_MD_CTX_set_params(EVP_MD_CTX *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *EVP_MD_settable_ctx_params(const EVP_MD *md); -\& const OSSL_PARAM *EVP_MD_gettable_ctx_params(const EVP_MD *md); -\& const OSSL_PARAM *EVP_MD_CTX_settable_params(EVP_MD_CTX *ctx); -\& const OSSL_PARAM *EVP_MD_CTX_gettable_params(EVP_MD_CTX *ctx); -\& void EVP_MD_CTX_set_flags(EVP_MD_CTX *ctx, int flags); -\& void EVP_MD_CTX_clear_flags(EVP_MD_CTX *ctx, int flags); -\& int EVP_MD_CTX_test_flags(const EVP_MD_CTX *ctx, int flags); -\& -\& int EVP_Q_digest(OSSL_LIB_CTX *libctx, const char *name, const char *propq, -\& const void *data, size_t datalen, -\& unsigned char *md, size_t *mdlen); -\& int EVP_Digest(const void *data, size_t count, unsigned char *md, -\& unsigned int *size, const EVP_MD *type, ENGINE *impl); -\& int EVP_DigestInit_ex2(EVP_MD_CTX *ctx, const EVP_MD *type, -\& const OSSL_PARAM params[]); -\& int EVP_DigestInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl); -\& int EVP_DigestUpdate(EVP_MD_CTX *ctx, const void *d, size_t cnt); -\& int EVP_DigestFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s); -\& int EVP_DigestFinalXOF(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen); -\& int EVP_DigestSqueeze(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen); -\& -\& EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in); -\& int EVP_MD_CTX_copy_ex(EVP_MD_CTX *out, const EVP_MD_CTX *in); -\& -\& int EVP_DigestInit(EVP_MD_CTX *ctx, const EVP_MD *type); -\& int EVP_DigestFinal(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s); -\& -\& int EVP_MD_CTX_copy(EVP_MD_CTX *out, EVP_MD_CTX *in); -\& -\& const char *EVP_MD_get0_name(const EVP_MD *md); -\& const char *EVP_MD_get0_description(const EVP_MD *md); -\& int EVP_MD_is_a(const EVP_MD *md, const char *name); -\& int EVP_MD_names_do_all(const EVP_MD *md, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const OSSL_PROVIDER *EVP_MD_get0_provider(const EVP_MD *md); -\& int EVP_MD_get_type(const EVP_MD *md); -\& int EVP_MD_get_pkey_type(const EVP_MD *md); -\& int EVP_MD_get_size(const EVP_MD *md); -\& int EVP_MD_get_block_size(const EVP_MD *md); -\& unsigned long EVP_MD_get_flags(const EVP_MD *md); -\& int EVP_MD_xof(const EVP_MD *md); -\& -\& const EVP_MD *EVP_MD_CTX_get0_md(const EVP_MD_CTX *ctx); -\& EVP_MD *EVP_MD_CTX_get1_md(EVP_MD_CTX *ctx); -\& const char *EVP_MD_CTX_get0_name(const EVP_MD_CTX *ctx); -\& int EVP_MD_CTX_get_size_ex(const EVP_MD_CTX *ctx); -\& int EVP_MD_CTX_get_block_size(const EVP_MD_CTX *ctx); -\& int EVP_MD_CTX_get_type(const EVP_MD_CTX *ctx); -\& void *EVP_MD_CTX_get0_md_data(const EVP_MD_CTX *ctx); -\& -\& const EVP_MD *EVP_md_null(void); -\& -\& const EVP_MD *EVP_get_digestbyname(const char *name); -\& const EVP_MD *EVP_get_digestbynid(int type); -\& const EVP_MD *EVP_get_digestbyobj(const ASN1_OBJECT *o); -\& -\& EVP_PKEY_CTX *EVP_MD_CTX_get_pkey_ctx(const EVP_MD_CTX *ctx); -\& void EVP_MD_CTX_set_pkey_ctx(EVP_MD_CTX *ctx, EVP_PKEY_CTX *pctx); -\& -\& void EVP_MD_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_MD *mac, void *arg), -\& void *arg); -\& -\& #define EVP_MD_type EVP_MD_get_type -\& #define EVP_MD_nid EVP_MD_get_type -\& #define EVP_MD_name EVP_MD_get0_name -\& #define EVP_MD_pkey_type EVP_MD_get_pkey_type -\& #define EVP_MD_size EVP_MD_get_size -\& #define EVP_MD_block_size EVP_MD_get_block_size -\& #define EVP_MD_flags EVP_MD_get_flags -\& #define EVP_MD_CTX_get_size EVP_MD_CTX_get_size_ex -\& #define EVP_MD_CTX_size EVP_MD_CTX_get_size_ex -\& #define EVP_MD_CTX_block_size EVP_MD_CTX_get_block_size -\& #define EVP_MD_CTX_type EVP_MD_CTX_get_type -\& #define EVP_MD_CTX_pkey_ctx EVP_MD_CTX_get_pkey_ctx -\& #define EVP_MD_CTX_md_data EVP_MD_CTX_get0_md_data -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& const EVP_MD *EVP_MD_CTX_md(const EVP_MD_CTX *ctx); -\& -\& int (*EVP_MD_CTX_update_fn(EVP_MD_CTX *ctx))(EVP_MD_CTX *ctx, -\& const void *data, size_t count); -\& -\& void EVP_MD_CTX_set_update_fn(EVP_MD_CTX *ctx, -\& int (*update)(EVP_MD_CTX *ctx, -\& const void *data, size_t count)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 digest routines are a high-level interface to message digests, and -Extendable Output Functions (\s-1XOF\s0). -.PP -The \fB\s-1EVP_MD\s0\fR type is a structure for digest method implementation. -.PP -Each Message digest algorithm (such as \s-1SHA256\s0) produces a fixed size output -length which is returned when \fBEVP_DigestFinal_ex()\fR is called. -Extendable Output Functions (\s-1XOF\s0) such as \s-1SHAKE256\s0 have a variable sized output -length \fIoutlen\fR which can be used with either \fBEVP_DigestFinalXOF()\fR or -\&\fBEVP_DigestSqueeze()\fR. \fBEVP_DigestFinal_ex()\fR may also be used for an \s-1XOF,\s0 but the -\&\*(L"xoflen\*(R" must be set beforehand (See \*(L"\s-1PARAMETERS\*(R"\s0). -Note that \fBEVP_MD_get_size()\fR and \fBEVP_MD_CTX_get_size_ex()\fR behave differently for -an \s-1XOF.\s0 -.IP "\fBEVP_MD_fetch()\fR" 4 -.IX Item "EVP_MD_fetch()" -Fetches the digest implementation for the given \fIalgorithm\fR from any -provider offering it, within the criteria given by the \fIproperties\fR. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.Sp -The returned value must eventually be freed with \fBEVP_MD_free()\fR. -.Sp -Fetched \fB\s-1EVP_MD\s0\fR structures are reference counted. -.IP "\fBEVP_MD_up_ref()\fR" 4 -.IX Item "EVP_MD_up_ref()" -Increments the reference count for an \fB\s-1EVP_MD\s0\fR structure. -.IP "\fBEVP_MD_free()\fR" 4 -.IX Item "EVP_MD_free()" -Decrements the reference count for the fetched \fB\s-1EVP_MD\s0\fR structure. -If the reference count drops to 0 then the structure is freed. -If the argument is \s-1NULL,\s0 nothing is done. -.IP "\fBEVP_MD_CTX_new()\fR" 4 -.IX Item "EVP_MD_CTX_new()" -Allocates and returns a digest context. -.IP "\fBEVP_MD_CTX_reset()\fR" 4 -.IX Item "EVP_MD_CTX_reset()" -Resets the digest context \fIctx\fR. This can be used to reuse an already -existing context. -.IP "\fBEVP_MD_CTX_free()\fR" 4 -.IX Item "EVP_MD_CTX_free()" -Cleans up digest context \fIctx\fR and frees up the space allocated to it. -If the argument is \s-1NULL,\s0 nothing is done. -.IP "\fBEVP_MD_CTX_ctrl()\fR" 4 -.IX Item "EVP_MD_CTX_ctrl()" -\&\fIThis is a legacy method. \f(BIEVP_MD_CTX_set_params()\fI and \f(BIEVP_MD_CTX_get_params()\fI -is the mechanism that should be used to set and get parameters that are used by -providers.\fR -.Sp -Performs digest-specific control actions on context \fIctx\fR. The control command -is indicated in \fIcmd\fR and any additional arguments in \fIp1\fR and \fIp2\fR. -\&\fBEVP_MD_CTX_ctrl()\fR must be called after \fBEVP_DigestInit_ex2()\fR. Other restrictions -may apply depending on the control type and digest implementation. -.Sp -If this function happens to be used with a fetched \fB\s-1EVP_MD\s0\fR, it will -translate the controls that are known to OpenSSL into \s-1\fBOSSL_PARAM\s0\fR\|(3) -parameters with keys defined by OpenSSL and call \fBEVP_MD_CTX_get_params()\fR or -\&\fBEVP_MD_CTX_set_params()\fR as is appropriate for each control command. -.Sp -See \*(L"\s-1CONTROLS\*(R"\s0 below for more information, including what translations are -being done. -.IP "\fBEVP_MD_get_params()\fR" 4 -.IX Item "EVP_MD_get_params()" -Retrieves the requested list of \fIparams\fR from a \s-1MD\s0 \fImd\fR. -See \*(L"\s-1PARAMETERS\*(R"\s0 below for more information. -.IP "\fBEVP_MD_CTX_get_params()\fR" 4 -.IX Item "EVP_MD_CTX_get_params()" -Retrieves the requested list of \fIparams\fR from a \s-1MD\s0 context \fIctx\fR. -See \*(L"\s-1PARAMETERS\*(R"\s0 below for more information. -.IP "\fBEVP_MD_CTX_set_params()\fR" 4 -.IX Item "EVP_MD_CTX_set_params()" -Sets the list of \fIparams\fR into a \s-1MD\s0 context \fIctx\fR. -See \*(L"\s-1PARAMETERS\*(R"\s0 below for more information. -.IP "\fBEVP_MD_gettable_params()\fR" 4 -.IX Item "EVP_MD_gettable_params()" -Get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the retrievable parameters -that can be used with \fBEVP_MD_get_params()\fR. -.IP "\fBEVP_MD_gettable_ctx_params()\fR, \fBEVP_MD_CTX_gettable_params()\fR" 4 -.IX Item "EVP_MD_gettable_ctx_params(), EVP_MD_CTX_gettable_params()" -Get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the retrievable parameters -that can be used with \fBEVP_MD_CTX_get_params()\fR. \fBEVP_MD_gettable_ctx_params()\fR -returns the parameters that can be retrieved from the algorithm, whereas -\&\fBEVP_MD_CTX_gettable_params()\fR returns the parameters that can be retrieved -in the context's current state. -.IP "\fBEVP_MD_settable_ctx_params()\fR, \fBEVP_MD_CTX_settable_params()\fR" 4 -.IX Item "EVP_MD_settable_ctx_params(), EVP_MD_CTX_settable_params()" -Get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the settable parameters -that can be used with \fBEVP_MD_CTX_set_params()\fR. \fBEVP_MD_settable_ctx_params()\fR -returns the parameters that can be set from the algorithm, whereas -\&\fBEVP_MD_CTX_settable_params()\fR returns the parameters that can be set in the -context's current state. -.IP "\fBEVP_MD_CTX_set_flags()\fR, \fBEVP_MD_CTX_clear_flags()\fR, \fBEVP_MD_CTX_test_flags()\fR" 4 -.IX Item "EVP_MD_CTX_set_flags(), EVP_MD_CTX_clear_flags(), EVP_MD_CTX_test_flags()" -Sets, clears and tests \fIctx\fR flags. See \*(L"\s-1FLAGS\*(R"\s0 below for more information. -.IP "\fBEVP_Q_digest()\fR is a quick one-shot digest function." 4 -.IX Item "EVP_Q_digest() is a quick one-shot digest function." -It hashes \fIdatalen\fR bytes of data at \fIdata\fR using the digest algorithm -\&\fIname\fR, which is fetched using the optional \fIlibctx\fR and \fIpropq\fR parameters. -The digest value is placed in \fImd\fR and its length is written at \fImdlen\fR -if the pointer is not \s-1NULL.\s0 At most \fB\s-1EVP_MAX_MD_SIZE\s0\fR bytes will be written. -.IP "\fBEVP_Digest()\fR" 4 -.IX Item "EVP_Digest()" -A wrapper around the Digest Init_ex, Update and Final_ex functions. -Hashes \fIcount\fR bytes of data at \fIdata\fR using a digest \fItype\fR from \s-1ENGINE\s0 -\&\fIimpl\fR. The digest value is placed in \fImd\fR and its length is written at \fIsize\fR -if the pointer is not \s-1NULL.\s0 At most \fB\s-1EVP_MAX_MD_SIZE\s0\fR bytes will be written. -If \fIimpl\fR is \s-1NULL\s0 the default implementation of digest \fItype\fR is used. -.IP "\fBEVP_DigestInit_ex2()\fR" 4 -.IX Item "EVP_DigestInit_ex2()" -Sets up digest context \fIctx\fR to use a digest \fItype\fR. -\&\fItype\fR is typically supplied by a function such as \fBEVP_sha1()\fR, or a -value explicitly fetched with \fBEVP_MD_fetch()\fR. -.Sp -The parameters \fBparams\fR are set on the context after initialisation. -.Sp -The \fItype\fR parameter can be \s-1NULL\s0 if \fIctx\fR has been already initialized -with another \fBEVP_DigestInit_ex()\fR call and has not been reset with -\&\fBEVP_MD_CTX_reset()\fR. -.IP "\fBEVP_DigestInit_ex()\fR" 4 -.IX Item "EVP_DigestInit_ex()" -Sets up digest context \fIctx\fR to use a digest \fItype\fR. -\&\fItype\fR is typically supplied by a function such as \fBEVP_sha1()\fR, or a -value explicitly fetched with \fBEVP_MD_fetch()\fR. -.Sp -If \fIimpl\fR is non-NULL, its implementation of the digest \fItype\fR is used if -there is one, and if not, the default implementation is used. -.Sp -The \fItype\fR parameter can be \s-1NULL\s0 if \fIctx\fR has been already initialized -with another \fBEVP_DigestInit_ex()\fR call and has not been reset with -\&\fBEVP_MD_CTX_reset()\fR. -.IP "\fBEVP_DigestUpdate()\fR" 4 -.IX Item "EVP_DigestUpdate()" -Hashes \fIcnt\fR bytes of data at \fId\fR into the digest context \fIctx\fR. This -function can be called several times on the same \fIctx\fR to hash additional -data. -.IP "\fBEVP_DigestFinal_ex()\fR" 4 -.IX Item "EVP_DigestFinal_ex()" -Retrieves the digest value from \fIctx\fR and places it in \fImd\fR. If the \fIs\fR -parameter is not \s-1NULL\s0 then the number of bytes of data written (i.e. the -length of the digest) will be written to the integer at \fIs\fR, at most -\&\fB\s-1EVP_MAX_MD_SIZE\s0\fR bytes will be written unless the digest implementation -allows changing the digest size and it is set to a larger value by the -application. After calling \fBEVP_DigestFinal_ex()\fR no additional calls to -\&\fBEVP_DigestUpdate()\fR can be made, but \fBEVP_DigestInit_ex2()\fR can be called to -initialize a new digest operation. -.IP "\fBEVP_DigestFinalXOF()\fR" 4 -.IX Item "EVP_DigestFinalXOF()" -Interfaces to extendable-output functions, XOFs, such as \s-1SHAKE128\s0 and \s-1SHAKE256.\s0 -It retrieves the digest value from \fIctx\fR and places it in \fIoutlen\fR\-sized \fIout\fR. -After calling this function no additional calls to \fBEVP_DigestUpdate()\fR can be -made, but \fBEVP_DigestInit_ex2()\fR can be called to initialize a new operation. -\&\fBEVP_DigestFinalXOF()\fR may only be called once -.IP "\fBEVP_DigestSqueeze()\fR" 4 -.IX Item "EVP_DigestSqueeze()" -Similar to \fBEVP_DigestFinalXOF()\fR but allows multiple calls to be made to -squeeze variable length output data. -\&\fBEVP_DigestFinalXOF()\fR should not be called after this. -.IP "\fBEVP_MD_CTX_dup()\fR" 4 -.IX Item "EVP_MD_CTX_dup()" -Can be used to duplicate the message digest state from \fIin\fR. This is useful -to avoid multiple \fBEVP_MD_fetch()\fR calls or if large amounts of data are to be -hashed which only differ in the last few bytes. -.IP "\fBEVP_MD_CTX_copy_ex()\fR" 4 -.IX Item "EVP_MD_CTX_copy_ex()" -Can be used to copy the message digest state from \fIin\fR to \fIout\fR. This is -useful if large amounts of data are to be hashed which only differ in the last -few bytes. -.IP "\fBEVP_DigestInit()\fR" 4 -.IX Item "EVP_DigestInit()" -Behaves in the same way as \fBEVP_DigestInit_ex2()\fR except it doesn't set any -parameters and calls \fBEVP_MD_CTX_reset()\fR so it cannot be used with an \fItype\fR -of \s-1NULL.\s0 -.IP "\fBEVP_DigestFinal()\fR" 4 -.IX Item "EVP_DigestFinal()" -Similar to \fBEVP_DigestFinal_ex()\fR except after computing the digest -the digest context \fIctx\fR is automatically cleaned up with \fBEVP_MD_CTX_reset()\fR. -.IP "\fBEVP_MD_CTX_copy()\fR" 4 -.IX Item "EVP_MD_CTX_copy()" -Similar to \fBEVP_MD_CTX_copy_ex()\fR except the destination \fIout\fR does not have to -be initialized. -.IP "\fBEVP_MD_is_a()\fR" 4 -.IX Item "EVP_MD_is_a()" -Returns 1 if \fImd\fR is an implementation of an algorithm that's -identifiable with \fIname\fR, otherwise 0. -.Sp -If \fImd\fR is a legacy digest (it's the return value from the likes of -\&\fBEVP_sha256()\fR rather than the result of an \fBEVP_MD_fetch()\fR), only cipher -names registered with the default library context (see -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) will be considered. -.IP "\fBEVP_MD_xof()\fR" 4 -.IX Item "EVP_MD_xof()" -Returns 1 if \fImd\fR is an Extendable-output Function (\s-1XOF\s0) otherwise it returns -0. \s-1SHAKE128\s0 and \s-1SHAKE256\s0 are \s-1XOF\s0 functions. -It returns 0 for \s-1BLAKE2B\s0 algorithms. -.IP "\fBEVP_MD_get0_name()\fR, \fBEVP_MD_CTX_get0_name()\fR" 4 -.IX Item "EVP_MD_get0_name(), EVP_MD_CTX_get0_name()" -Return the name of the given message digest. For fetched message -digests with multiple names, only one of them is returned; it's -recommended to use \fBEVP_MD_names_do_all()\fR instead. -.IP "\fBEVP_MD_names_do_all()\fR" 4 -.IX Item "EVP_MD_names_do_all()" -Traverses all names for the \fImd\fR, and calls \fIfn\fR with each name and -\&\fIdata\fR. This is only useful with fetched \fB\s-1EVP_MD\s0\fRs. -.IP "\fBEVP_MD_get0_description()\fR" 4 -.IX Item "EVP_MD_get0_description()" -Returns a description of the digest, meant for display and human consumption. -The description is at the discretion of the digest implementation. -.IP "\fBEVP_MD_get0_provider()\fR" 4 -.IX Item "EVP_MD_get0_provider()" -Returns an \fB\s-1OSSL_PROVIDER\s0\fR pointer to the provider that implements the given -\&\fB\s-1EVP_MD\s0\fR. -.IP "\fBEVP_MD_get_size()\fR" 4 -.IX Item "EVP_MD_get_size()" -Return the size of the message digest when passed an \fB\s-1EVP_MD\s0\fR, i.e. the size of -the hash. A negative value or 0 can occur for invalid size. -For an \s-1XOF\s0 with no default size this returns 0. -.IP "\fBEVP_MD_CTX_get_size_ex()\fR, \fBEVP_MD_CTX_get_size()\fR" 4 -.IX Item "EVP_MD_CTX_get_size_ex(), EVP_MD_CTX_get_size()" -For a normal digest this is the same as \fBEVP_MD_get_size()\fR. -For an \s-1XOF\s0 this returns the \*(L"xoflen\*(R" if it has been set, otherwise it returns 0. -.IP "\fBEVP_MD_get_block_size()\fR, \fBEVP_MD_CTX_get_block_size()\fR" 4 -.IX Item "EVP_MD_get_block_size(), EVP_MD_CTX_get_block_size()" -Return the block size of the message digest when passed an \fB\s-1EVP_MD\s0\fR or an -\&\fB\s-1EVP_MD_CTX\s0\fR structure. -.IP "\fBEVP_MD_get_type()\fR, \fBEVP_MD_CTX_get_type()\fR" 4 -.IX Item "EVP_MD_get_type(), EVP_MD_CTX_get_type()" -Return the \s-1NID\s0 of the \s-1OBJECT IDENTIFIER\s0 representing the given message digest -when passed an \fB\s-1EVP_MD\s0\fR structure. For example, \f(CW\*(C`EVP_MD_get_type(EVP_sha1())\*(C'\fR -returns \fBNID_sha1\fR. This function is normally used when setting \s-1ASN1\s0 OIDs. -.IP "\fBEVP_MD_CTX_get0_md_data()\fR" 4 -.IX Item "EVP_MD_CTX_get0_md_data()" -Return the digest method private data for the passed \fB\s-1EVP_MD_CTX\s0\fR. -The space is allocated by OpenSSL and has the size originally set with -\&\fBEVP_MD_meth_set_app_datasize()\fR. -.IP "\fBEVP_MD_CTX_get0_md()\fR, \fBEVP_MD_CTX_get1_md()\fR" 4 -.IX Item "EVP_MD_CTX_get0_md(), EVP_MD_CTX_get1_md()" -\&\fBEVP_MD_CTX_get0_md()\fR returns -the \fB\s-1EVP_MD\s0\fR structure corresponding to the passed \fB\s-1EVP_MD_CTX\s0\fR. This -will be the same \fB\s-1EVP_MD\s0\fR object originally passed to \fBEVP_DigestInit_ex2()\fR (or -other similar function) when the \s-1EVP_MD_CTX\s0 was first initialised. Note that -where explicit fetch is in use (see \fBEVP_MD_fetch\fR\|(3)) the value returned from -this function will not have its reference count incremented and therefore it -should not be used after the \s-1EVP_MD_CTX\s0 is freed. -\&\fBEVP_MD_CTX_get1_md()\fR is the same except the ownership is passed to the -caller and is from the passed \fB\s-1EVP_MD_CTX\s0\fR. -.IP "\fBEVP_MD_CTX_set_update_fn()\fR" 4 -.IX Item "EVP_MD_CTX_set_update_fn()" -Sets the update function for \fIctx\fR to \fIupdate\fR. -This is the function that is called by \fBEVP_DigestUpdate()\fR. If not set, the -update function from the \fB\s-1EVP_MD\s0\fR type specified at initialization is used. -.IP "\fBEVP_MD_CTX_update_fn()\fR" 4 -.IX Item "EVP_MD_CTX_update_fn()" -Returns the update function for \fIctx\fR. -.IP "\fBEVP_MD_get_flags()\fR" 4 -.IX Item "EVP_MD_get_flags()" -Returns the \fImd\fR flags. Note that these are different from the \fB\s-1EVP_MD_CTX\s0\fR -ones. See \fBEVP_MD_meth_set_flags\fR\|(3) for more information. -.IP "\fBEVP_MD_get_pkey_type()\fR" 4 -.IX Item "EVP_MD_get_pkey_type()" -Returns the \s-1NID\s0 of the public key signing algorithm associated with this -digest. For example \fBEVP_sha1()\fR is associated with \s-1RSA\s0 so this will return -\&\fBNID_sha1WithRSAEncryption\fR. Since digests and signature algorithms are no -longer linked this function is only retained for compatibility reasons. -.IP "\fBEVP_md_null()\fR" 4 -.IX Item "EVP_md_null()" -A \*(L"null\*(R" message digest that does nothing: i.e. the hash it returns is of zero -length. -.IP "\fBEVP_get_digestbyname()\fR, \fBEVP_get_digestbynid()\fR, \fBEVP_get_digestbyobj()\fR" 4 -.IX Item "EVP_get_digestbyname(), EVP_get_digestbynid(), EVP_get_digestbyobj()" -Returns an \fB\s-1EVP_MD\s0\fR structure when passed a digest name, a digest \fB\s-1NID\s0\fR or an -\&\fB\s-1ASN1_OBJECT\s0\fR structure respectively. -.Sp -The \fBEVP_get_digestbyname()\fR function is present for backwards compatibility with -OpenSSL prior to version 3 and is different to the \fBEVP_MD_fetch()\fR function -since it does not attempt to \*(L"fetch\*(R" an implementation of the cipher. -Additionally, it only knows about digests that are built-in to OpenSSL and have -an associated \s-1NID.\s0 Similarly \fBEVP_get_digestbynid()\fR and \fBEVP_get_digestbyobj()\fR -also return objects without an associated implementation. -.Sp -When the digest objects returned by these functions are used (such as in a call -to \fBEVP_DigestInit_ex()\fR) an implementation of the digest will be implicitly -fetched from the loaded providers. This fetch could fail if no suitable -implementation is available. Use \fBEVP_MD_fetch()\fR instead to explicitly fetch -the algorithm and an associated implementation from a provider. -.Sp -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for more information about fetching. -.Sp -The digest objects returned from these functions do not need to be freed with -\&\fBEVP_MD_free()\fR. -.IP "\fBEVP_MD_CTX_get_pkey_ctx()\fR" 4 -.IX Item "EVP_MD_CTX_get_pkey_ctx()" -Returns the \fB\s-1EVP_PKEY_CTX\s0\fR assigned to \fIctx\fR. The returned pointer should not -be freed by the caller. -.IP "\fBEVP_MD_CTX_set_pkey_ctx()\fR" 4 -.IX Item "EVP_MD_CTX_set_pkey_ctx()" -Assigns an \fB\s-1EVP_PKEY_CTX\s0\fR to \fB\s-1EVP_MD_CTX\s0\fR. This is usually used to provide -a customized \fB\s-1EVP_PKEY_CTX\s0\fR to \fBEVP_DigestSignInit\fR\|(3) or -\&\fBEVP_DigestVerifyInit\fR\|(3). The \fIpctx\fR passed to this function should be freed -by the caller. A \s-1NULL\s0 \fIpctx\fR pointer is also allowed to clear the \fB\s-1EVP_PKEY_CTX\s0\fR -assigned to \fIctx\fR. In such case, freeing the cleared \fB\s-1EVP_PKEY_CTX\s0\fR or not -depends on how the \fB\s-1EVP_PKEY_CTX\s0\fR is created. -.IP "\fBEVP_MD_do_all_provided()\fR" 4 -.IX Item "EVP_MD_do_all_provided()" -Traverses all messages digests implemented by all activated providers -in the given library context \fIlibctx\fR, and for each of the implementations, -calls the given function \fIfn\fR with the implementation method and the given -\&\fIarg\fR as argument. -.SH "PARAMETERS" -.IX Header "PARAMETERS" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for information about passing parameters. -.PP -\&\fBEVP_MD_CTX_set_params()\fR and \fBEVP_MD_CTX_get_params()\fR can be used with the -following \s-1OSSL_PARAM\s0 keys: -.ie n .IP """xoflen"" (\fB\s-1OSSL_DIGEST_PARAM_XOFLEN\s0\fR) " 4 -.el .IP "``xoflen'' (\fB\s-1OSSL_DIGEST_PARAM_XOFLEN\s0\fR) " 4 -.IX Item "xoflen (OSSL_DIGEST_PARAM_XOFLEN) " -Sets or gets the digest length for extendable output functions. -The value should not exceed what can be given using a \fBsize_t\fR. -It may be used by \s-1SHAKE\-128\s0 and \s-1SHAKE\-256\s0 to set the -output length used by \fBEVP_DigestFinal_ex()\fR and \fBEVP_DigestFinal()\fR. -.ie n .IP """size"" (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_DIGEST_PARAM_SIZE) " -Sets or gets a fixed digest length. -The value should not exceed what can be given using a \fBsize_t\fR. -It may be used by \s-1BLAKE2B\-512\s0 to set the output length used by -\&\fBEVP_DigestFinal_ex()\fR and \fBEVP_DigestFinal()\fR. -.PP -\&\fBEVP_MD_CTX_set_params()\fR can be used with the following \s-1OSSL_PARAM\s0 keys: -.ie n .IP """pad-type"" (\fB\s-1OSSL_DIGEST_PARAM_PAD_TYPE\s0\fR) " 4 -.el .IP "``pad-type'' (\fB\s-1OSSL_DIGEST_PARAM_PAD_TYPE\s0\fR) " 4 -.IX Item "pad-type (OSSL_DIGEST_PARAM_PAD_TYPE) " -Sets the padding type. -It is used by the \s-1MDC2\s0 algorithm. -.PP -\&\fBEVP_MD_CTX_get_params()\fR can be used with the following \s-1OSSL_PARAM\s0 keys: -.ie n .IP """micalg"" (\fB\s-1OSSL_DIGEST_PARAM_MICALG\s0\fR) <\s-1UTF8\s0 string>." 4 -.el .IP "``micalg'' (\fB\s-1OSSL_DIGEST_PARAM_MICALG\s0\fR) <\s-1UTF8\s0 string>." 4 -.IX Item "micalg (OSSL_DIGEST_PARAM_MICALG) ." -Gets the digest Message Integrity Check algorithm string. This is used when -creating S/MIME multipart/signed messages, as specified in \s-1RFC 3851.\s0 -It may be used by external engines or providers. -.SH "CONTROLS" -.IX Header "CONTROLS" -\&\fBEVP_MD_CTX_ctrl()\fR can be used to send the following standard controls: -.IP "\s-1EVP_MD_CTRL_MICALG\s0" 4 -.IX Item "EVP_MD_CTRL_MICALG" -Gets the digest Message Integrity Check algorithm string. This is used when -creating S/MIME multipart/signed messages, as specified in \s-1RFC 3851.\s0 -The string value is written to \fIp2\fR. -.Sp -When used with a fetched \fB\s-1EVP_MD\s0\fR, \fBEVP_MD_CTX_get_params()\fR gets called with -an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"micalg\*(R" (\fB\s-1OSSL_DIGEST_PARAM_MICALG\s0\fR). -.IP "\s-1EVP_MD_CTRL_XOF_LEN\s0" 4 -.IX Item "EVP_MD_CTRL_XOF_LEN" -This control sets the digest length for extendable output functions to \fIp1\fR. -Sending this control directly should not be necessary, the use of -\&\fBEVP_DigestFinalXOF()\fR is preferred. -Currently used by \s-1SHAKE\s0 algorithms. -.Sp -When used with a fetched \fB\s-1EVP_MD\s0\fR, \fBEVP_MD_CTX_get_params()\fR gets called with -an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"xoflen\*(R" (\fB\s-1OSSL_DIGEST_PARAM_XOFLEN\s0\fR). -.SH "FLAGS" -.IX Header "FLAGS" -\&\fBEVP_MD_CTX_set_flags()\fR, \fBEVP_MD_CTX_clear_flags()\fR and \fBEVP_MD_CTX_test_flags()\fR -can be used the manipulate and test these \fB\s-1EVP_MD_CTX\s0\fR flags: -.IP "\s-1EVP_MD_CTX_FLAG_ONESHOT\s0" 4 -.IX Item "EVP_MD_CTX_FLAG_ONESHOT" -This flag instructs the digest to optimize for one update only, if possible. -.IP "\s-1EVP_MD_CTX_FLAG_CLEANED\s0" 4 -.IX Item "EVP_MD_CTX_FLAG_CLEANED" -This flag is for internal use only and \fImust not\fR be used in user code. -.IP "\s-1EVP_MD_CTX_FLAG_REUSE\s0" 4 -.IX Item "EVP_MD_CTX_FLAG_REUSE" -This flag is for internal use only and \fImust not\fR be used in user code. -.IP "\s-1EVP_MD_CTX_FLAG_NO_INIT\s0" 4 -.IX Item "EVP_MD_CTX_FLAG_NO_INIT" -This flag instructs \fBEVP_DigestInit()\fR and similar not to initialise the -implementation specific data. -.IP "\s-1EVP_MD_CTX_FLAG_FINALISE\s0" 4 -.IX Item "EVP_MD_CTX_FLAG_FINALISE" -Some functions such as EVP_DigestSign only finalise copies of internal -contexts so additional data can be included after the finalisation call. -This is inefficient if this functionality is not required, and can be -disabled with this flag. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -.IP "\fBEVP_MD_fetch()\fR" 4 -.IX Item "EVP_MD_fetch()" -Returns a pointer to a \fB\s-1EVP_MD\s0\fR for success or \s-1NULL\s0 for failure. -.IP "\fBEVP_MD_up_ref()\fR" 4 -.IX Item "EVP_MD_up_ref()" -Returns 1 for success or 0 for failure. -.IP "\fBEVP_Q_digest()\fR, \fBEVP_Digest()\fR, \fBEVP_DigestInit_ex2()\fR, \fBEVP_DigestInit_ex()\fR, \fBEVP_DigestInit()\fR, \fBEVP_DigestUpdate()\fR, \fBEVP_DigestFinal_ex()\fR, \fBEVP_DigestFinalXOF()\fR, and \fBEVP_DigestFinal()\fR" 4 -.IX Item "EVP_Q_digest(), EVP_Digest(), EVP_DigestInit_ex2(), EVP_DigestInit_ex(), EVP_DigestInit(), EVP_DigestUpdate(), EVP_DigestFinal_ex(), EVP_DigestFinalXOF(), and EVP_DigestFinal()" -return 1 for -success and 0 for failure. -.IP "\fBEVP_MD_CTX_ctrl()\fR" 4 -.IX Item "EVP_MD_CTX_ctrl()" -Returns 1 if successful or 0 for failure. -.IP "\fBEVP_MD_CTX_set_params()\fR, \fBEVP_MD_CTX_get_params()\fR" 4 -.IX Item "EVP_MD_CTX_set_params(), EVP_MD_CTX_get_params()" -Returns 1 if successful or 0 for failure. -.IP "\fBEVP_MD_CTX_settable_params()\fR, \fBEVP_MD_CTX_gettable_params()\fR" 4 -.IX Item "EVP_MD_CTX_settable_params(), EVP_MD_CTX_gettable_params()" -Return an array of constant \s-1\fBOSSL_PARAM\s0\fR\|(3)s, or \s-1NULL\s0 if there is none -to get. -.IP "\fBEVP_MD_CTX_dup()\fR" 4 -.IX Item "EVP_MD_CTX_dup()" -Returns a new \s-1EVP_MD_CTX\s0 if successful or \s-1NULL\s0 on failure. -.IP "\fBEVP_MD_CTX_copy_ex()\fR" 4 -.IX Item "EVP_MD_CTX_copy_ex()" -Returns 1 if successful or 0 for failure. -.IP "\fBEVP_MD_get_type()\fR, \fBEVP_MD_get_pkey_type()\fR" 4 -.IX Item "EVP_MD_get_type(), EVP_MD_get_pkey_type()" -Returns the \s-1NID\s0 of the corresponding \s-1OBJECT IDENTIFIER\s0 or NID_undef if none -exists. -.IP "\fBEVP_MD_get_size()\fR, \fBEVP_MD_get_block_size()\fR, \fBEVP_MD_CTX_get_size()\fR, \fBEVP_MD_CTX_get_block_size()\fR" 4 -.IX Item "EVP_MD_get_size(), EVP_MD_get_block_size(), EVP_MD_CTX_get_size(), EVP_MD_CTX_get_block_size()" -Returns the digest or block size in bytes or \-1 for failure. -.IP "\fBEVP_md_null()\fR" 4 -.IX Item "EVP_md_null()" -Returns a pointer to the \fB\s-1EVP_MD\s0\fR structure of the \*(L"null\*(R" message digest. -.IP "\fBEVP_get_digestbyname()\fR, \fBEVP_get_digestbynid()\fR, \fBEVP_get_digestbyobj()\fR" 4 -.IX Item "EVP_get_digestbyname(), EVP_get_digestbynid(), EVP_get_digestbyobj()" -Returns either an \fB\s-1EVP_MD\s0\fR structure or \s-1NULL\s0 if an error occurs. -.IP "\fBEVP_MD_CTX_set_pkey_ctx()\fR" 4 -.IX Item "EVP_MD_CTX_set_pkey_ctx()" -This function has no return value. -.IP "\fBEVP_MD_names_do_all()\fR" 4 -.IX Item "EVP_MD_names_do_all()" -Returns 1 if the callback was called for all names. A return value of 0 means -that the callback was not called for any names. -.SH "NOTES" -.IX Header "NOTES" -The \fB\s-1EVP\s0\fR interface to message digests should almost always be used in -preference to the low-level interfaces. This is because the code then becomes -transparent to the digest used and much more flexible. -.PP -New applications should use the \s-1SHA\-2\s0 (such as \fBEVP_sha256\fR\|(3)) or the \s-1SHA\-3\s0 -digest algorithms (such as \fBEVP_sha3_512\fR\|(3)). The other digest algorithms -are still in common use. -.PP -For most applications the \fIimpl\fR parameter to \fBEVP_DigestInit_ex()\fR will be -set to \s-1NULL\s0 to use the default digest implementation. -.PP -Ignoring failure returns of \fBEVP_DigestInit_ex()\fR, \fBEVP_DigestInit_ex2()\fR, or -\&\fBEVP_DigestInit()\fR can lead to undefined behavior on subsequent calls -updating or finalizing the \fB\s-1EVP_MD_CTX\s0\fR such as the \fBEVP_DigestUpdate()\fR or -\&\fBEVP_DigestFinal()\fR functions. The only valid calls on the \fB\s-1EVP_MD_CTX\s0\fR -when initialization fails are calls that attempt another initialization of -the context or release the context. -.PP -The functions \fBEVP_DigestInit()\fR, \fBEVP_DigestFinal()\fR and \fBEVP_MD_CTX_copy()\fR are -obsolete but are retained to maintain compatibility with existing code. New -applications should use \fBEVP_DigestInit_ex()\fR, \fBEVP_DigestFinal_ex()\fR and -\&\fBEVP_MD_CTX_copy_ex()\fR because they can efficiently reuse a digest context -instead of initializing and cleaning it up on each call and allow non default -implementations of digests to be specified. -.PP -If digest contexts are not cleaned up after use, -memory leaks will occur. -.PP -\&\fBEVP_MD_CTX_get0_name()\fR, \fBEVP_MD_CTX_get_size()\fR, \fBEVP_MD_CTX_get_block_size()\fR, -\&\fBEVP_MD_CTX_get_type()\fR, \fBEVP_get_digestbynid()\fR and \fBEVP_get_digestbyobj()\fR are -defined as macros. -.PP -\&\fBEVP_MD_CTX_ctrl()\fR sends commands to message digests for additional configuration -or control. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example digests the data \*(L"Test Message\en\*(R" and \*(L"Hello World\en\*(R", using the -digest name passed on the command line. -.PP -.Vb 3 -\& #include -\& #include -\& #include -\& -\& int main(int argc, char *argv[]) -\& { -\& EVP_MD_CTX *mdctx; -\& const EVP_MD *md; -\& char mess1[] = "Test Message\en"; -\& char mess2[] = "Hello World\en"; -\& unsigned char md_value[EVP_MAX_MD_SIZE]; -\& unsigned int md_len, i; -\& -\& if (argv[1] == NULL) { -\& printf("Usage: mdtest digestname\en"); -\& exit(1); -\& } -\& -\& md = EVP_get_digestbyname(argv[1]); -\& if (md == NULL) { -\& printf("Unknown message digest %s\en", argv[1]); -\& exit(1); -\& } -\& -\& mdctx = EVP_MD_CTX_new(); -\& if (!EVP_DigestInit_ex2(mdctx, md, NULL)) { -\& printf("Message digest initialization failed.\en"); -\& EVP_MD_CTX_free(mdctx); -\& exit(1); -\& } -\& if (!EVP_DigestUpdate(mdctx, mess1, strlen(mess1))) { -\& printf("Message digest update failed.\en"); -\& EVP_MD_CTX_free(mdctx); -\& exit(1); -\& } -\& if (!EVP_DigestUpdate(mdctx, mess2, strlen(mess2))) { -\& printf("Message digest update failed.\en"); -\& EVP_MD_CTX_free(mdctx); -\& exit(1); -\& } -\& if (!EVP_DigestFinal_ex(mdctx, md_value, &md_len)) { -\& printf("Message digest finalization failed.\en"); -\& EVP_MD_CTX_free(mdctx); -\& exit(1); -\& } -\& EVP_MD_CTX_free(mdctx); -\& -\& printf("Digest is: "); -\& for (i = 0; i < md_len; i++) -\& printf("%02x", md_value[i]); -\& printf("\en"); -\& -\& exit(0); -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_meth_new\fR\|(3), -\&\fBopenssl\-dgst\fR\|(1), -\&\fBevp\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\s0\fR\|(3), -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), -\&\fBproperty\fR\|(7), -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7), -\&\fBprovider\-digest\fR\|(7), -\&\fBlife_cycle\-digest\fR\|(7) -.PP -The full list of digest algorithms are provided below. -.PP -\&\fBEVP_blake2b512\fR\|(3), -\&\fBEVP_md2\fR\|(3), -\&\fBEVP_md4\fR\|(3), -\&\fBEVP_md5\fR\|(3), -\&\fBEVP_mdc2\fR\|(3), -\&\fBEVP_ripemd160\fR\|(3), -\&\fBEVP_sha1\fR\|(3), -\&\fBEVP_sha224\fR\|(3), -\&\fBEVP_sha3_224\fR\|(3), -\&\fBEVP_sm3\fR\|(3), -\&\fBEVP_whirlpool\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_MD_CTX_create()\fR and \fBEVP_MD_CTX_destroy()\fR functions were renamed to -\&\fBEVP_MD_CTX_new()\fR and \fBEVP_MD_CTX_free()\fR in OpenSSL 1.1.0, respectively. -.PP -The link between digests and signing algorithms was fixed in OpenSSL 1.0 and -later, so now \fBEVP_sha1()\fR can be used with \s-1RSA\s0 and \s-1DSA.\s0 -.PP -The \fBEVP_dss1()\fR function was removed in OpenSSL 1.1.0. -.PP -The \fBEVP_MD_CTX_set_pkey_ctx()\fR function was added in OpenSSL 1.1.1. -.PP -The \fBEVP_Q_digest()\fR, \fBEVP_DigestInit_ex2()\fR, -\&\fBEVP_MD_fetch()\fR, \fBEVP_MD_free()\fR, \fBEVP_MD_up_ref()\fR, -\&\fBEVP_MD_get_params()\fR, \fBEVP_MD_CTX_set_params()\fR, \fBEVP_MD_CTX_get_params()\fR, -\&\fBEVP_MD_gettable_params()\fR, \fBEVP_MD_gettable_ctx_params()\fR, -\&\fBEVP_MD_settable_ctx_params()\fR, \fBEVP_MD_CTX_settable_params()\fR and -\&\fBEVP_MD_CTX_gettable_params()\fR functions were added in OpenSSL 3.0. -.PP -The \fBEVP_MD_type()\fR, \fBEVP_MD_nid()\fR, \fBEVP_MD_name()\fR, \fBEVP_MD_pkey_type()\fR, -\&\fBEVP_MD_size()\fR, \fBEVP_MD_block_size()\fR, \fBEVP_MD_flags()\fR, \fBEVP_MD_CTX_size()\fR, -\&\fBEVP_MD_CTX_block_size()\fR, \fBEVP_MD_CTX_type()\fR, and \fBEVP_MD_CTX_md_data()\fR -functions were renamed to include \f(CW\*(C`get\*(C'\fR or \f(CW\*(C`get0\*(C'\fR in their names in -OpenSSL 3.0, respectively. The old names are kept as non-deprecated -alias macros. -.PP -The \fBEVP_MD_CTX_md()\fR function was deprecated in OpenSSL 3.0; use -\&\fBEVP_MD_CTX_get0_md()\fR instead. -\&\fBEVP_MD_CTX_update_fn()\fR and \fBEVP_MD_CTX_set_update_fn()\fR were deprecated -in OpenSSL 3.0. -.PP -The \fBEVP_MD_CTX_dup()\fR function was added in OpenSSL 3.1. -.PP -The \fBEVP_DigestSqueeze()\fR function was added in OpenSSL 3.3. -.PP -The \fBEVP_MD_CTX_get_size_ex()\fR and \fBEVP_xof()\fR functions were added in OpenSSL 3.4. -The macros \fBEVP_MD_CTX_get_size()\fR and EVP_MD_CTX_size were changed in OpenSSL 3.4 -to be aliases for \fBEVP_MD_CTX_get_size_ex()\fR, previously they were aliases for -EVP_MD_get_size which returned a constant value. This is required for \s-1XOF\s0 -digests since they do not have a fixed size. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_DigestInit_ex.3ossl b/openssl-install/share/man/man3/EVP_DigestInit_ex.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_DigestInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestInit_ex2.3ossl b/openssl-install/share/man/man3/EVP_DigestInit_ex2.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_DigestInit_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestSign.3ossl b/openssl-install/share/man/man3/EVP_DigestSign.3ossl deleted file mode 120000 index b350ff88..00000000 --- a/openssl-install/share/man/man3/EVP_DigestSign.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestSignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestSignFinal.3ossl b/openssl-install/share/man/man3/EVP_DigestSignFinal.3ossl deleted file mode 120000 index b350ff88..00000000 --- a/openssl-install/share/man/man3/EVP_DigestSignFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestSignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestSignInit.3ossl b/openssl-install/share/man/man3/EVP_DigestSignInit.3ossl deleted file mode 100644 index 6e7b0def..00000000 --- a/openssl-install/share/man/man3/EVP_DigestSignInit.3ossl +++ /dev/null @@ -1,339 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_DIGESTSIGNINIT 3ossl" -.TH EVP_DIGESTSIGNINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_DigestSignInit_ex, EVP_DigestSignInit, EVP_DigestSignUpdate, -EVP_DigestSignFinal, EVP_DigestSign \- EVP signing functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_DigestSignInit_ex(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx, -\& const char *mdname, OSSL_LIB_CTX *libctx, -\& const char *props, EVP_PKEY *pkey, -\& const OSSL_PARAM params[]); -\& int EVP_DigestSignInit(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx, -\& const EVP_MD *type, ENGINE *e, EVP_PKEY *pkey); -\& int EVP_DigestSignUpdate(EVP_MD_CTX *ctx, const void *d, size_t cnt); -\& int EVP_DigestSignFinal(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen); -\& -\& int EVP_DigestSign(EVP_MD_CTX *ctx, unsigned char *sig, -\& size_t *siglen, const unsigned char *tbs, -\& size_t tbslen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 signature routines are a high-level interface to digital signatures. -Input data is digested first before the signing takes place. -.PP -\&\fBEVP_DigestSignInit_ex()\fR sets up signing context \fIctx\fR to use a digest -with the name \fImdname\fR and private key \fIpkey\fR. The name of the digest to be -used is passed to the provider of the signature algorithm in use. How that -provider interprets the digest name is provider specific. The provider may -implement that digest directly itself or it may (optionally) choose to fetch it -(which could result in a digest from a different provider being selected). If the -provider supports fetching the digest then it may use the \fIprops\fR argument for -the properties to be used during the fetch. Finally, the passed parameters -\&\fIparams\fR, if not \s-1NULL,\s0 are set on the context before returning. -.PP -The \fIpkey\fR algorithm is used to fetch a \fB\s-1EVP_SIGNATURE\s0\fR method implicitly, to -be used for the actual signing. See \*(L"Implicit fetch\*(R" in \fBprovider\fR\|(7) for -more information about implicit fetches. -.PP -The OpenSSL default and legacy providers support fetching digests and can fetch -those digests from any available provider. The OpenSSL \s-1FIPS\s0 provider also -supports fetching digests but will only fetch digests that are themselves -implemented inside the \s-1FIPS\s0 provider. -.PP -\&\fIctx\fR must be created with \fBEVP_MD_CTX_new()\fR before calling this function. If -\&\fIpctx\fR is not \s-1NULL,\s0 the \s-1EVP_PKEY_CTX\s0 of the signing operation will be written -to \fI*pctx\fR: this can be used to set alternative signing options. Note that any -existing value in \fI*pctx\fR is overwritten. The \s-1EVP_PKEY_CTX\s0 value returned must -not be freed directly by the application if \fIctx\fR is not assigned an -\&\s-1EVP_PKEY_CTX\s0 value before being passed to \fBEVP_DigestSignInit_ex()\fR -(which means the \s-1EVP_PKEY_CTX\s0 is created inside \fBEVP_DigestSignInit_ex()\fR -and it will be freed automatically when the \s-1EVP_MD_CTX\s0 is freed). If the -\&\s-1EVP_PKEY_CTX\s0 to be used is created by EVP_DigestSignInit_ex then it -will use the \fB\s-1OSSL_LIB_CTX\s0\fR specified in \fIlibctx\fR and the property query string -specified in \fIprops\fR. -.PP -The digest \fImdname\fR may be \s-1NULL\s0 if the signing algorithm supports it. The -\&\fIprops\fR argument can always be \s-1NULL.\s0 -.PP -No \fB\s-1EVP_PKEY_CTX\s0\fR will be created by \fBEVP_DigestSignInit_ex()\fR if the -passed \fIctx\fR has already been assigned one via \fBEVP_MD_CTX_set_pkey_ctx\fR\|(3). -See also \s-1\fBSM2\s0\fR\|(7). -.PP -Only \s-1EVP_PKEY\s0 types that support signing can be used with these functions. This -includes \s-1MAC\s0 algorithms where the \s-1MAC\s0 generation is considered as a form of -\&\*(L"signing\*(R". Built-in \s-1EVP_PKEY\s0 types supported by these functions are \s-1CMAC,\s0 -Poly1305, \s-1DSA, ECDSA, HMAC, RSA,\s0 SipHash, Ed25519 and Ed448. -.PP -Not all digests can be used for all key types. The following combinations apply. -.IP "\s-1DSA\s0" 4 -.IX Item "DSA" -Supports \s-1SHA1, SHA224, SHA256, SHA384\s0 and \s-1SHA512\s0 -.IP "\s-1ECDSA\s0" 4 -.IX Item "ECDSA" -Supports \s-1SHA1, SHA224, SHA256, SHA384, SHA512\s0 and \s-1SM3\s0 -.IP "\s-1RSA\s0 with no padding" 4 -.IX Item "RSA with no padding" -Supports no digests (the digest \fItype\fR must be \s-1NULL\s0) -.IP "\s-1RSA\s0 with X931 padding" 4 -.IX Item "RSA with X931 padding" -Supports \s-1SHA1, SHA256, SHA384\s0 and \s-1SHA512\s0 -.IP "All other \s-1RSA\s0 padding types" 4 -.IX Item "All other RSA padding types" -Support \s-1SHA1, SHA224, SHA256, SHA384, SHA512, MD5, MD5_SHA1, MD2, MD4, MDC2, -SHA3\-224, SHA3\-256, SHA3\-384, SHA3\-512\s0 -.IP "Ed25519 and Ed448" 4 -.IX Item "Ed25519 and Ed448" -Support no digests (the digest \fItype\fR must be \s-1NULL\s0) -.IP "\s-1HMAC\s0" 4 -.IX Item "HMAC" -Supports any digest -.IP "\s-1CMAC,\s0 Poly1305 and SipHash" 4 -.IX Item "CMAC, Poly1305 and SipHash" -Will ignore any digest provided. -.PP -If RSA-PSS is used and restrictions apply then the digest must match. -.PP -\&\fBEVP_DigestSignInit()\fR works in the same way as \fBEVP_DigestSignInit_ex()\fR -except that the \fImdname\fR parameter will be inferred from the supplied -digest \fItype\fR, and \fIprops\fR will be \s-1NULL.\s0 Where supplied the \s-1ENGINE\s0 \fIe\fR will -be used for the signing and digest algorithm implementations. \fIe\fR may be \s-1NULL.\s0 -.PP -\&\fBEVP_DigestSignUpdate()\fR hashes \fIcnt\fR bytes of data at \fId\fR into the -signature context \fIctx\fR. This function can be called several times on the -same \fIctx\fR to include additional data. -.PP -Unless \fIsig\fR is \s-1NULL\s0 \fBEVP_DigestSignFinal()\fR signs the data in \fIctx\fR -and places the signature in \fIsig\fR. -Otherwise the maximum necessary size of the output buffer is written to -the \fIsiglen\fR parameter. If \fIsig\fR is not \s-1NULL\s0 then before the call the -\&\fIsiglen\fR parameter should contain the length of the \fIsig\fR buffer. If the -call is successful the signature is written to \fIsig\fR and the amount of data -written to \fIsiglen\fR. -.PP -\&\fBEVP_DigestSign()\fR is similar to a single call to \fBEVP_DigestSignUpdate()\fR and -\&\fBEVP_DigestSignFinal()\fR. -Unless \fIsig\fR is \s-1NULL,\s0 \fBEVP_DigestSign()\fR signs the data \fItbs\fR of length \fItbslen\fR -bytes and places the signature in a buffer \fIsig\fR of size \fIsiglen\fR. -If \fIsig\fR is \s-1NULL,\s0 the maximum necessary size of the signature buffer is written -to the \fIsiglen\fR parameter. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_DigestSignInit()\fR, \fBEVP_DigestSignUpdate()\fR, \fBEVP_DigestSignFinal()\fR and -\&\fBEVP_DigestSign()\fR return 1 for success and 0 for failure. -.PP -The error codes can be obtained from \fBERR_get_error\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The \fB\s-1EVP\s0\fR interface to digital signatures should almost always be used in -preference to the low-level interfaces. This is because the code then becomes -transparent to the algorithm used and much more flexible. -.PP -\&\fBEVP_DigestSign()\fR is a one shot operation which signs a single block of data -in one function. For algorithms that support streaming it is equivalent to -calling \fBEVP_DigestSignUpdate()\fR and \fBEVP_DigestSignFinal()\fR. For algorithms which -do not support streaming (e.g. PureEdDSA) it is the only way to sign data. -.PP -In previous versions of OpenSSL there was a link between message digest types -and public key algorithms. This meant that \*(L"clone\*(R" digests such as \fBEVP_dss1()\fR -needed to be used to sign using \s-1SHA1\s0 and \s-1DSA.\s0 This is no longer necessary and -the use of clone digest is now discouraged. -.PP -For some key types and parameters the random number generator must be seeded. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.PP -The call to \fBEVP_DigestSignFinal()\fR internally finalizes a copy of the digest -context. This means that calls to \fBEVP_DigestSignUpdate()\fR and -\&\fBEVP_DigestSignFinal()\fR can be called later to digest and sign additional data. -Applications may disable this behavior by setting the \s-1EVP_MD_CTX_FLAG_FINALISE\s0 -context flag via \fBEVP_MD_CTX_set_flags\fR\|(3). -.PP -Note that not all providers support continuation, in case the selected -provider does not allow to duplicate contexts \fBEVP_DigestSignFinal()\fR will -finalize the digest context and attempting to process additional data via -\&\fBEVP_DigestSignUpdate()\fR will result in an error. -.PP -\&\fBEVP_DigestSignInit()\fR and \fBEVP_DigestSignInit_ex()\fR functions can be called -multiple times on a context and the parameters set by previous calls should be -preserved if the \fIpkey\fR parameter is \s-1NULL.\s0 The call then just resets the state -of the \fIctx\fR. -.PP -\&\fBEVP_DigestSign()\fR can not be called again, once a signature is generated (by -passing \fIsig\fR as non \s-1NULL\s0), unless the \fB\s-1EVP_MD_CTX\s0\fR is reinitialised by -calling \fBEVP_DigestSignInit_ex()\fR. -.PP -Ignoring failure returns of \fBEVP_DigestSignInit()\fR and \fBEVP_DigestSignInit_ex()\fR -functions can lead to subsequent undefined behavior when calling -\&\fBEVP_DigestSignUpdate()\fR, \fBEVP_DigestSignFinal()\fR, or \fBEVP_DigestSign()\fR. -.PP -The use of \fBEVP_PKEY_get_size()\fR with these functions is discouraged because some -signature operations may have a signature length which depends on the -parameters set. As a result \fBEVP_PKEY_get_size()\fR would have to return a value -which indicates the maximum possible signature for any set of parameters. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestVerifyInit\fR\|(3), -\&\fBEVP_DigestInit\fR\|(3), -\&\fBevp\fR\|(7), \s-1\fBHMAC\s0\fR\|(3), \s-1\fBMD2\s0\fR\|(3), -\&\s-1\fBMD5\s0\fR\|(3), \s-1\fBMDC2\s0\fR\|(3), \s-1\fBRIPEMD160\s0\fR\|(3), -\&\s-1\fBSHA1\s0\fR\|(3), \fBopenssl\-dgst\fR\|(1), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_DigestSignInit()\fR, \fBEVP_DigestSignUpdate()\fR and \fBEVP_DigestSignFinal()\fR -were added in OpenSSL 1.0.0. -.PP -\&\fBEVP_DigestSignInit_ex()\fR was added in OpenSSL 3.0. -.PP -\&\fBEVP_DigestSignUpdate()\fR was converted from a macro to a function in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_DigestSignInit_ex.3ossl b/openssl-install/share/man/man3/EVP_DigestSignInit_ex.3ossl deleted file mode 120000 index b350ff88..00000000 --- a/openssl-install/share/man/man3/EVP_DigestSignInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestSignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestSignUpdate.3ossl b/openssl-install/share/man/man3/EVP_DigestSignUpdate.3ossl deleted file mode 120000 index b350ff88..00000000 --- a/openssl-install/share/man/man3/EVP_DigestSignUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestSignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestSqueeze.3ossl b/openssl-install/share/man/man3/EVP_DigestSqueeze.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_DigestSqueeze.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestUpdate.3ossl b/openssl-install/share/man/man3/EVP_DigestUpdate.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_DigestUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestVerify.3ossl b/openssl-install/share/man/man3/EVP_DigestVerify.3ossl deleted file mode 120000 index e23b24b0..00000000 --- a/openssl-install/share/man/man3/EVP_DigestVerify.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestVerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestVerifyFinal.3ossl b/openssl-install/share/man/man3/EVP_DigestVerifyFinal.3ossl deleted file mode 120000 index e23b24b0..00000000 --- a/openssl-install/share/man/man3/EVP_DigestVerifyFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestVerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestVerifyInit.3ossl b/openssl-install/share/man/man3/EVP_DigestVerifyInit.3ossl deleted file mode 100644 index d3ae68c7..00000000 --- a/openssl-install/share/man/man3/EVP_DigestVerifyInit.3ossl +++ /dev/null @@ -1,324 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_DIGESTVERIFYINIT 3ossl" -.TH EVP_DIGESTVERIFYINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_DigestVerifyInit_ex, EVP_DigestVerifyInit, EVP_DigestVerifyUpdate, -EVP_DigestVerifyFinal, EVP_DigestVerify \- EVP signature verification functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_DigestVerifyInit_ex(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx, -\& const char *mdname, OSSL_LIB_CTX *libctx, -\& const char *props, EVP_PKEY *pkey, -\& const OSSL_PARAM params[]); -\& int EVP_DigestVerifyInit(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx, -\& const EVP_MD *type, ENGINE *e, EVP_PKEY *pkey); -\& int EVP_DigestVerifyUpdate(EVP_MD_CTX *ctx, const void *d, size_t cnt); -\& int EVP_DigestVerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sig, -\& size_t siglen); -\& int EVP_DigestVerify(EVP_MD_CTX *ctx, const unsigned char *sig, -\& size_t siglen, const unsigned char *tbs, size_t tbslen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 signature routines are a high-level interface to digital signatures. -Input data is digested first before the signature verification takes place. -.PP -\&\fBEVP_DigestVerifyInit_ex()\fR sets up verification context \fBctx\fR to use a -digest with the name \fBmdname\fR and public key \fBpkey\fR. The name of the digest to -be used is passed to the provider of the signature algorithm in use. How that -provider interprets the digest name is provider specific. The provider may -implement that digest directly itself or it may (optionally) choose to fetch it -(which could result in a digest from a different provider being selected). If -the provider supports fetching the digest then it may use the \fBprops\fR argument -for the properties to be used during the fetch. Finally, the passed parameters -\&\fIparams\fR, if not \s-1NULL,\s0 are set on the context before returning. -.PP -The \fIpkey\fR algorithm is used to fetch a \fB\s-1EVP_SIGNATURE\s0\fR method implicitly, to -be used for the actual signing. See \*(L"Implicit fetch\*(R" in \fBprovider\fR\|(7) for -more information about implicit fetches. -.PP -The OpenSSL default and legacy providers support fetching digests and can fetch -those digests from any available provider. The OpenSSL \s-1FIPS\s0 provider also -supports fetching digests but will only fetch digests that are themselves -implemented inside the \s-1FIPS\s0 provider. -.PP -\&\fBctx\fR must be created with \fBEVP_MD_CTX_new()\fR before calling this function. If -\&\fBpctx\fR is not \s-1NULL,\s0 the \s-1EVP_PKEY_CTX\s0 of the verification operation will be -written to \fB*pctx\fR: this can be used to set alternative verification options. -Note that any existing value in \fB*pctx\fR is overwritten. The \s-1EVP_PKEY_CTX\s0 value -returned must not be freed directly by the application if \fBctx\fR is not assigned -an \s-1EVP_PKEY_CTX\s0 value before being passed to \fBEVP_DigestVerifyInit_ex()\fR -(which means the \s-1EVP_PKEY_CTX\s0 is created inside -\&\fBEVP_DigestVerifyInit_ex()\fR and it will be freed automatically when the -\&\s-1EVP_MD_CTX\s0 is freed). If the \s-1EVP_PKEY_CTX\s0 to be used is created by -EVP_DigestVerifyInit_ex then it will use the \fB\s-1OSSL_LIB_CTX\s0\fR specified -in \fIlibctx\fR and the property query string specified in \fIprops\fR. -.PP -No \fB\s-1EVP_PKEY_CTX\s0\fR will be created by \fBEVP_DigestVerifyInit_ex()\fR if the -passed \fBctx\fR has already been assigned one via \fBEVP_MD_CTX_set_pkey_ctx\fR\|(3). -See also \s-1\fBSM2\s0\fR\|(7). -.PP -Not all digests can be used for all key types. The following combinations apply. -.IP "\s-1DSA\s0" 4 -.IX Item "DSA" -Supports \s-1SHA1, SHA224, SHA256, SHA384\s0 and \s-1SHA512\s0 -.IP "\s-1ECDSA\s0" 4 -.IX Item "ECDSA" -Supports \s-1SHA1, SHA224, SHA256, SHA384, SHA512\s0 and \s-1SM3\s0 -.IP "\s-1RSA\s0 with no padding" 4 -.IX Item "RSA with no padding" -Supports no digests (the digest \fBtype\fR must be \s-1NULL\s0) -.IP "\s-1RSA\s0 with X931 padding" 4 -.IX Item "RSA with X931 padding" -Supports \s-1SHA1, SHA256, SHA384\s0 and \s-1SHA512\s0 -.IP "All other \s-1RSA\s0 padding types" 4 -.IX Item "All other RSA padding types" -Support \s-1SHA1, SHA224, SHA256, SHA384, SHA512, MD5, MD5_SHA1, MD2, MD4, MDC2, -SHA3\-224, SHA3\-256, SHA3\-384, SHA3\-512\s0 -.IP "Ed25519 and Ed448" 4 -.IX Item "Ed25519 and Ed448" -Support no digests (the digest \fBtype\fR must be \s-1NULL\s0) -.IP "\s-1HMAC\s0" 4 -.IX Item "HMAC" -Supports any digest -.IP "\s-1CMAC,\s0 Poly1305 and Siphash" 4 -.IX Item "CMAC, Poly1305 and Siphash" -Will ignore any digest provided. -.PP -If RSA-PSS is used and restrictions apply then the digest must match. -.PP -\&\fBEVP_DigestVerifyInit()\fR works in the same way as -\&\fBEVP_DigestVerifyInit_ex()\fR except that the \fBmdname\fR parameter will be -inferred from the supplied digest \fBtype\fR, and \fBprops\fR will be \s-1NULL.\s0 Where -supplied the \s-1ENGINE\s0 \fBe\fR will be used for the signature verification and digest -algorithm implementations. \fBe\fR may be \s-1NULL.\s0 -.PP -\&\fBEVP_DigestVerifyUpdate()\fR hashes \fBcnt\fR bytes of data at \fBd\fR into the -verification context \fBctx\fR. This function can be called several times on the -same \fBctx\fR to include additional data. -.PP -\&\fBEVP_DigestVerifyFinal()\fR verifies the data in \fBctx\fR against the signature in -\&\fBsig\fR of length \fBsiglen\fR. -.PP -\&\fBEVP_DigestVerify()\fR verifies \fBtbslen\fR bytes at \fBtbs\fR against the signature -in \fBsig\fR of length \fBsiglen\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_DigestVerifyInit()\fR and \fBEVP_DigestVerifyUpdate()\fR return 1 for success and 0 -for failure. -.PP -\&\fBEVP_DigestVerifyFinal()\fR and \fBEVP_DigestVerify()\fR return 1 for success; any other -value indicates failure. A return value of zero indicates that the signature -did not verify successfully (that is, \fBtbs\fR did not match the original data or -the signature had an invalid form), while other values indicate a more serious -error (and sometimes also indicate an invalid signature form). -.PP -The error codes can be obtained from \fBERR_get_error\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The \fB\s-1EVP\s0\fR interface to digital signatures should almost always be used in -preference to the low-level interfaces. This is because the code then becomes -transparent to the algorithm used and much more flexible. -.PP -\&\fBEVP_DigestVerify()\fR is a one shot operation which verifies a single block of -data in one function. For algorithms that support streaming it is equivalent -to calling \fBEVP_DigestVerifyUpdate()\fR and \fBEVP_DigestVerifyFinal()\fR. For -algorithms which do not support streaming (e.g. PureEdDSA) it is the only way -to verify data. -.PP -In previous versions of OpenSSL there was a link between message digest types -and public key algorithms. This meant that \*(L"clone\*(R" digests such as \fBEVP_dss1()\fR -needed to be used to sign using \s-1SHA1\s0 and \s-1DSA.\s0 This is no longer necessary and -the use of clone digest is now discouraged. -.PP -For some key types and parameters the random number generator must be seeded. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.PP -The call to \fBEVP_DigestVerifyFinal()\fR internally finalizes a copy of the digest -context. This means that \fBEVP_VerifyUpdate()\fR and \fBEVP_VerifyFinal()\fR can -be called later to digest and verify additional data. Applications may disable -this behavior by setting the \s-1EVP_MD_CTX_FLAG_FINALISE\s0 context flag via -\&\fBEVP_MD_CTX_set_flags\fR\|(3). -.PP -Note that not all providers support continuation, in case the selected -provider does not allow to duplicate contexts \fBEVP_DigestVerifyFinal()\fR will -finalize the digest context and attempting to process additional data via -\&\fBEVP_DigestVerifyUpdate()\fR will result in an error. -.PP -\&\fBEVP_DigestVerifyInit()\fR and \fBEVP_DigestVerifyInit_ex()\fR functions can be called -multiple times on a context and the parameters set by previous calls should be -preserved if the \fIpkey\fR parameter is \s-1NULL.\s0 The call then just resets the state -of the \fIctx\fR. -.PP -\&\fBEVP_DigestVerify()\fR can only be called once, and cannot be used again without -reinitialising the \fB\s-1EVP_MD_CTX\s0\fR by calling \fBEVP_DigestVerifyInit_ex()\fR. -.PP -Ignoring failure returns of \fBEVP_DigestVerifyInit()\fR and \fBEVP_DigestVerifyInit_ex()\fR -functions can lead to subsequent undefined behavior when calling -\&\fBEVP_DigestVerifyUpdate()\fR, \fBEVP_DigestVerifyFinal()\fR, or \fBEVP_DigestVerify()\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestSignInit\fR\|(3), -\&\fBEVP_DigestInit\fR\|(3), -\&\fBevp\fR\|(7), \s-1\fBHMAC\s0\fR\|(3), \s-1\fBMD2\s0\fR\|(3), -\&\s-1\fBMD5\s0\fR\|(3), \s-1\fBMDC2\s0\fR\|(3), \s-1\fBRIPEMD160\s0\fR\|(3), -\&\s-1\fBSHA1\s0\fR\|(3), \fBopenssl\-dgst\fR\|(1), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_DigestVerifyInit()\fR, \fBEVP_DigestVerifyUpdate()\fR and \fBEVP_DigestVerifyFinal()\fR -were added in OpenSSL 1.0.0. -.PP -\&\fBEVP_DigestVerifyInit_ex()\fR was added in OpenSSL 3.0. -.PP -\&\fBEVP_DigestVerifyUpdate()\fR was converted from a macro to a function in OpenSSL -3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_DigestVerifyInit_ex.3ossl b/openssl-install/share/man/man3/EVP_DigestVerifyInit_ex.3ossl deleted file mode 120000 index e23b24b0..00000000 --- a/openssl-install/share/man/man3/EVP_DigestVerifyInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestVerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_DigestVerifyUpdate.3ossl b/openssl-install/share/man/man3/EVP_DigestVerifyUpdate.3ossl deleted file mode 120000 index e23b24b0..00000000 --- a/openssl-install/share/man/man3/EVP_DigestVerifyUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestVerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EC_gen.3ossl b/openssl-install/share/man/man3/EVP_EC_gen.3ossl deleted file mode 120000 index 6f99b819..00000000 --- a/openssl-install/share/man/man3/EVP_EC_gen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_KEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ENCODE_CTX_copy.3ossl b/openssl-install/share/man/man3/EVP_ENCODE_CTX_copy.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_ENCODE_CTX_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ENCODE_CTX_free.3ossl b/openssl-install/share/man/man3/EVP_ENCODE_CTX_free.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_ENCODE_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ENCODE_CTX_new.3ossl b/openssl-install/share/man/man3/EVP_ENCODE_CTX_new.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_ENCODE_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ENCODE_CTX_num.3ossl b/openssl-install/share/man/man3/EVP_ENCODE_CTX_num.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_ENCODE_CTX_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncodeBlock.3ossl b/openssl-install/share/man/man3/EVP_EncodeBlock.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_EncodeBlock.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncodeFinal.3ossl b/openssl-install/share/man/man3/EVP_EncodeFinal.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_EncodeFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncodeInit.3ossl b/openssl-install/share/man/man3/EVP_EncodeInit.3ossl deleted file mode 100644 index fb9b20e9..00000000 --- a/openssl-install/share/man/man3/EVP_EncodeInit.3ossl +++ /dev/null @@ -1,320 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_ENCODEINIT 3ossl" -.TH EVP_ENCODEINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_ENCODE_CTX_new, EVP_ENCODE_CTX_free, EVP_ENCODE_CTX_copy, -EVP_ENCODE_CTX_num, EVP_EncodeInit, EVP_EncodeUpdate, EVP_EncodeFinal, -EVP_EncodeBlock, EVP_DecodeInit, EVP_DecodeUpdate, EVP_DecodeFinal, -EVP_DecodeBlock \- EVP base64 encode/decode routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_ENCODE_CTX *EVP_ENCODE_CTX_new(void); -\& void EVP_ENCODE_CTX_free(EVP_ENCODE_CTX *ctx); -\& int EVP_ENCODE_CTX_copy(EVP_ENCODE_CTX *dctx, EVP_ENCODE_CTX *sctx); -\& int EVP_ENCODE_CTX_num(EVP_ENCODE_CTX *ctx); -\& void EVP_EncodeInit(EVP_ENCODE_CTX *ctx); -\& int EVP_EncodeUpdate(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl, -\& const unsigned char *in, int inl); -\& void EVP_EncodeFinal(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl); -\& int EVP_EncodeBlock(unsigned char *t, const unsigned char *f, int n); -\& -\& void EVP_DecodeInit(EVP_ENCODE_CTX *ctx); -\& int EVP_DecodeUpdate(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl, -\& const unsigned char *in, int inl); -\& int EVP_DecodeFinal(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl); -\& int EVP_DecodeBlock(unsigned char *t, const unsigned char *f, int n); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 encode routines provide a high-level interface to base64 encoding and -decoding. -Base64 encoding converts binary data into a printable form that uses -the characters A\-Z, a\-z, 0\-9, \*(L"+\*(R" and \*(L"/\*(R" to represent the data. For every 3 -bytes of binary data provided 4 bytes of base64 encoded data will be produced -plus some occasional newlines (see below). If the input data length is not a -multiple of 3 then the output data will be padded at the end using the \*(L"=\*(R" -character. -.PP -\&\fBEVP_ENCODE_CTX_new()\fR allocates, initializes and returns a context to be used for -the encode/decode functions. -.PP -\&\fBEVP_ENCODE_CTX_free()\fR cleans up an encode/decode context \fBctx\fR and frees up the -space allocated to it. If the argument is \s-1NULL,\s0 nothing is done. -.PP -Encoding of binary data is performed in blocks of 48 input bytes (or less for -the final block). -For each 48 byte input block encoded 64 bytes of base64 data -is output plus an additional newline character (i.e. 65 bytes in total). The -final block (which may be less than 48 bytes) will output 4 bytes for every 3 -bytes of input. If the data length is not divisible by 3 then a full 4 bytes is -still output for the final 1 or 2 bytes of input. Similarly a newline character -will also be output. -.PP -\&\fBEVP_EncodeInit()\fR initialises \fBctx\fR for the start of a new encoding operation. -.PP -\&\fBEVP_EncodeUpdate()\fR encode \fBinl\fR bytes of data found in the buffer pointed to by -\&\fBin\fR. The output is stored in the buffer \fBout\fR and the number of bytes output -is stored in \fB*outl\fR. It is the caller's responsibility to ensure that the -buffer at \fBout\fR is sufficiently large to accommodate the output data. Only full -blocks of data (48 bytes) will be immediately processed and output by this -function. Any remainder is held in the \fBctx\fR object and will be processed by a -subsequent call to \fBEVP_EncodeUpdate()\fR or \fBEVP_EncodeFinal()\fR. To calculate the -required size of the output buffer add together the value of \fBinl\fR with the -amount of unprocessed data held in \fBctx\fR and divide the result by 48 (ignore -any remainder). This gives the number of blocks of data that will be processed. -Ensure the output buffer contains 65 bytes of storage for each block, plus an -additional byte for a \s-1NUL\s0 terminator. \fBEVP_EncodeUpdate()\fR may be called -repeatedly to process large amounts of input data. In the event of an error -\&\fBEVP_EncodeUpdate()\fR will set \fB*outl\fR to 0 and return 0. On success 1 will be -returned. -.PP -\&\fBEVP_EncodeFinal()\fR must be called at the end of an encoding operation. It will -process any partial block of data remaining in the \fBctx\fR object. The output -data will be stored in \fBout\fR and the length of the data written will be stored -in \fB*outl\fR. It is the caller's responsibility to ensure that \fBout\fR is -sufficiently large to accommodate the output data which will never be more than -65 bytes plus an additional \s-1NUL\s0 terminator (i.e. 66 bytes in total). -.PP -\&\fBEVP_ENCODE_CTX_copy()\fR can be used to copy a context \fBsctx\fR to a context -\&\fBdctx\fR. \fBdctx\fR must be initialized before calling this function. -.PP -\&\fBEVP_ENCODE_CTX_num()\fR will return the number of as yet unprocessed bytes still to -be encoded or decoded that are pending in the \fBctx\fR object. -.PP -\&\fBEVP_EncodeBlock()\fR encodes a full block of input data in \fBf\fR and of length -\&\fBn\fR and stores it in \fBt\fR. For every 3 bytes of input provided 4 bytes of -output data will be produced. If \fBn\fR is not divisible by 3 then the block is -encoded as a final block of data and the output is padded such that it is always -divisible by 4. Additionally a \s-1NUL\s0 terminator character will be added. For -example if 16 bytes of input data is provided then 24 bytes of encoded data is -created plus 1 byte for a \s-1NUL\s0 terminator (i.e. 25 bytes in total). The length of -the data generated \fIwithout\fR the \s-1NUL\s0 terminator is returned from the function. -.PP -\&\fBEVP_DecodeInit()\fR initialises \fBctx\fR for the start of a new decoding operation. -.PP -\&\fBEVP_DecodeUpdate()\fR decodes \fBinl\fR characters of data found in the buffer -pointed to by \fBin\fR. -The output is stored in the buffer \fBout\fR and the number of bytes output is -stored in \fB*outl\fR. -It is the caller's responsibility to ensure that the buffer at \fBout\fR is -sufficiently large to accommodate the output data. -This function will attempt to decode as much data as possible in chunks of up -to 80 base64 characters at a time. -Residual input shorter than the internal chunk size will be buffered in \fBctx\fR -if its length is not a multiple of 4 (including any padding), to be processed -in future calls to \fBEVP_DecodeUpdate()\fR or \fBEVP_DecodeFinal()\fR. -If the final chunk length is a multiple of 4, it is decoded immediately and -not buffered. -.PP -Any whitespace, newline or carriage return characters are ignored. -For compatibility with \fB\s-1PEM\s0\fR, the \fB\-\fR (hyphen) character is treated as a soft -end-of-input, subsequent bytes are not buffered, and the return value will be -0 to indicate that the end of the base64 input has been detected. -The soft end-of-input, if present, \s-1MUST\s0 occur after a multiple of 4 valid base64 -input bytes. -The soft end-of-input condition is not remembered in \fBctx\fR, it is up to the -caller to avoid further calls to \fBEVP_DecodeUpdate()\fR after a 0 or negative -(error) return. -.PP -If any invalid base64 characters are encountered or if the base64 padding -character (\fB=\fR) is encountered in the middle of the data then -\&\fBEVP_DecodeUpdate()\fR returns \-1 to indicate an error. -A return value of 0 or 1 indicates successful processing of the data. -A return value of 0 additionally indicates that the last 4 bytes processed -ended with base64 padding (\fB=\fR), or that the next 4 byte group starts with the -soft end-of-input (\fB\-\fR) character, and therefore no more input data is -expected to be processed. -.PP -For every 4 valid base64 bytes processed (ignoring whitespace, carriage returns -and line feeds), 3 bytes of binary output data will be produced (except at the -end of data terminated with one or two padding characters). -.PP -\&\fBEVP_DecodeFinal()\fR should be called at the end of a decoding operation, -but it will never decode additional data. If there is no residual data -it will return 1 to indicate success. If there is residual data, its -length is not a multiple of 4, i.e. it was not properly padded, \-1 is -is returned in that case to indicate an error. -.PP -\&\fBEVP_DecodeBlock()\fR will decode the block of \fBn\fR characters of base64 data -contained in \fBf\fR and store the result in \fBt\fR. -Any leading whitespace will be trimmed as will any trailing whitespace, -newlines, carriage returns or \s-1EOF\s0 characters. -Internal whitespace \s-1MUST NOT\s0 be present. -After trimming the data in \fBf\fR \s-1MUST\s0 consist entirely of valid base64 -characters or padding (only at the tail of the input) and its length \s-1MUST\s0 be -divisible by 4. -For every 4 input bytes exactly 3 output bytes will be produced. -Padding bytes (\fB=\fR) (even if internal) are decoded to 6 zero bits, the caller -is responsible for taking trailing padding into account, by ignoring as many -bytes at the tail of the returned output. -\&\fBEVP_DecodeBlock()\fR will return the length of the data decoded or \-1 on error. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_ENCODE_CTX_new()\fR returns a pointer to the newly allocated \s-1EVP_ENCODE_CTX\s0 -object or \s-1NULL\s0 on error. -.PP -\&\fBEVP_ENCODE_CTX_num()\fR returns the number of bytes pending encoding or decoding in -\&\fBctx\fR. -.PP -\&\fBEVP_EncodeUpdate()\fR returns 0 on error or 1 on success. -.PP -\&\fBEVP_EncodeBlock()\fR returns the number of bytes encoded excluding the \s-1NUL\s0 -terminator. -.PP -\&\fBEVP_DecodeUpdate()\fR returns \-1 on error and 0 or 1 on success. If 0 is returned -then no more non-padding base64 characters are expected. -.PP -\&\fBEVP_DecodeFinal()\fR returns \-1 on error or 1 on success. -.PP -\&\fBEVP_DecodeBlock()\fR returns the length of the data decoded or \-1 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_EncodeUpdate.3ossl b/openssl-install/share/man/man3/EVP_EncodeUpdate.3ossl deleted file mode 120000 index 7ede2660..00000000 --- a/openssl-install/share/man/man3/EVP_EncodeUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncodeInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncryptFinal.3ossl b/openssl-install/share/man/man3/EVP_EncryptFinal.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_EncryptFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncryptFinal_ex.3ossl b/openssl-install/share/man/man3/EVP_EncryptFinal_ex.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_EncryptFinal_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncryptInit.3ossl b/openssl-install/share/man/man3/EVP_EncryptInit.3ossl deleted file mode 100644 index c193c96e..00000000 --- a/openssl-install/share/man/man3/EVP_EncryptInit.3ossl +++ /dev/null @@ -1,1852 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_ENCRYPTINIT 3ossl" -.TH EVP_ENCRYPTINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER_fetch, -EVP_CIPHER_up_ref, -EVP_CIPHER_free, -EVP_CIPHER_CTX_new, -EVP_CIPHER_CTX_reset, -EVP_CIPHER_CTX_free, -EVP_CIPHER_CTX_dup, -EVP_CIPHER_CTX_copy, -EVP_EncryptInit_ex, -EVP_EncryptInit_ex2, -EVP_EncryptUpdate, -EVP_EncryptFinal_ex, -EVP_DecryptInit_ex, -EVP_DecryptInit_ex2, -EVP_DecryptUpdate, -EVP_DecryptFinal_ex, -EVP_CipherInit_ex, -EVP_CipherInit_ex2, -EVP_CipherUpdate, -EVP_CipherFinal_ex, -EVP_CIPHER_CTX_set_key_length, -EVP_CIPHER_CTX_ctrl, -EVP_EncryptInit, -EVP_EncryptFinal, -EVP_DecryptInit, -EVP_DecryptFinal, -EVP_CipherInit, -EVP_CipherFinal, -EVP_Cipher, -EVP_get_cipherbyname, -EVP_get_cipherbynid, -EVP_get_cipherbyobj, -EVP_CIPHER_is_a, -EVP_CIPHER_get0_name, -EVP_CIPHER_get0_description, -EVP_CIPHER_names_do_all, -EVP_CIPHER_get0_provider, -EVP_CIPHER_get_nid, -EVP_CIPHER_get_params, -EVP_CIPHER_gettable_params, -EVP_CIPHER_get_block_size, -EVP_CIPHER_get_key_length, -EVP_CIPHER_get_iv_length, -EVP_CIPHER_get_flags, -EVP_CIPHER_get_mode, -EVP_CIPHER_get_type, -EVP_CIPHER_CTX_cipher, -EVP_CIPHER_CTX_get0_cipher, -EVP_CIPHER_CTX_get1_cipher, -EVP_CIPHER_CTX_get0_name, -EVP_CIPHER_CTX_get_nid, -EVP_CIPHER_CTX_get_params, -EVP_CIPHER_gettable_ctx_params, -EVP_CIPHER_CTX_gettable_params, -EVP_CIPHER_CTX_set_params, -EVP_CIPHER_settable_ctx_params, -EVP_CIPHER_CTX_settable_params, -EVP_CIPHER_CTX_get_block_size, -EVP_CIPHER_CTX_get_key_length, -EVP_CIPHER_CTX_get_iv_length, -EVP_CIPHER_CTX_get_tag_length, -EVP_CIPHER_CTX_get_app_data, -EVP_CIPHER_CTX_set_app_data, -EVP_CIPHER_CTX_flags, -EVP_CIPHER_CTX_set_flags, -EVP_CIPHER_CTX_clear_flags, -EVP_CIPHER_CTX_test_flags, -EVP_CIPHER_CTX_get_type, -EVP_CIPHER_CTX_get_mode, -EVP_CIPHER_CTX_get_num, -EVP_CIPHER_CTX_set_num, -EVP_CIPHER_CTX_is_encrypting, -EVP_CIPHER_param_to_asn1, -EVP_CIPHER_asn1_to_param, -EVP_CIPHER_CTX_set_padding, -EVP_enc_null, -EVP_CIPHER_do_all_provided, -EVP_CIPHER_nid, -EVP_CIPHER_name, -EVP_CIPHER_block_size, -EVP_CIPHER_key_length, -EVP_CIPHER_iv_length, -EVP_CIPHER_flags, -EVP_CIPHER_mode, -EVP_CIPHER_type, -EVP_CIPHER_CTX_encrypting, -EVP_CIPHER_CTX_nid, -EVP_CIPHER_CTX_block_size, -EVP_CIPHER_CTX_key_length, -EVP_CIPHER_CTX_iv_length, -EVP_CIPHER_CTX_tag_length, -EVP_CIPHER_CTX_num, -EVP_CIPHER_CTX_type, -EVP_CIPHER_CTX_mode -\&\- EVP cipher routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_CIPHER *EVP_CIPHER_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, -\& const char *properties); -\& int EVP_CIPHER_up_ref(EVP_CIPHER *cipher); -\& void EVP_CIPHER_free(EVP_CIPHER *cipher); -\& EVP_CIPHER_CTX *EVP_CIPHER_CTX_new(void); -\& int EVP_CIPHER_CTX_reset(EVP_CIPHER_CTX *ctx); -\& void EVP_CIPHER_CTX_free(EVP_CIPHER_CTX *ctx); -\& EVP_CIPHER_CTX *EVP_CIPHER_CTX_dup(const EVP_CIPHER_CTX *in); -\& int EVP_CIPHER_CTX_copy(EVP_CIPHER_CTX *out, const EVP_CIPHER_CTX *in); -\& -\& int EVP_EncryptInit_ex(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& ENGINE *impl, const unsigned char *key, const unsigned char *iv); -\& int EVP_EncryptInit_ex2(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& const unsigned char *key, const unsigned char *iv, -\& const OSSL_PARAM params[]); -\& int EVP_EncryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, -\& int *outl, const unsigned char *in, int inl); -\& int EVP_EncryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl); -\& -\& int EVP_DecryptInit_ex(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& ENGINE *impl, const unsigned char *key, const unsigned char *iv); -\& int EVP_DecryptInit_ex2(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& const unsigned char *key, const unsigned char *iv, -\& const OSSL_PARAM params[]); -\& int EVP_DecryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, -\& int *outl, const unsigned char *in, int inl); -\& int EVP_DecryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl); -\& -\& int EVP_CipherInit_ex(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& ENGINE *impl, const unsigned char *key, const unsigned char *iv, int enc); -\& int EVP_CipherInit_ex2(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& const unsigned char *key, const unsigned char *iv, -\& int enc, const OSSL_PARAM params[]); -\& int EVP_CipherUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, -\& int *outl, const unsigned char *in, int inl); -\& int EVP_CipherFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl); -\& -\& int EVP_EncryptInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& const unsigned char *key, const unsigned char *iv); -\& int EVP_EncryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl); -\& -\& int EVP_DecryptInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& const unsigned char *key, const unsigned char *iv); -\& int EVP_DecryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl); -\& -\& int EVP_CipherInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& const unsigned char *key, const unsigned char *iv, int enc); -\& int EVP_CipherFinal(EVP_CIPHER_CTX *ctx, unsigned char *outm, int *outl); -\& -\& int EVP_Cipher(EVP_CIPHER_CTX *ctx, unsigned char *out, -\& const unsigned char *in, unsigned int inl); -\& -\& int EVP_CIPHER_CTX_set_padding(EVP_CIPHER_CTX *x, int padding); -\& int EVP_CIPHER_CTX_set_key_length(EVP_CIPHER_CTX *x, int keylen); -\& int EVP_CIPHER_CTX_ctrl(EVP_CIPHER_CTX *ctx, int cmd, int p1, void *p2); -\& int EVP_CIPHER_CTX_rand_key(EVP_CIPHER_CTX *ctx, unsigned char *key); -\& void EVP_CIPHER_CTX_set_flags(EVP_CIPHER_CTX *ctx, int flags); -\& void EVP_CIPHER_CTX_clear_flags(EVP_CIPHER_CTX *ctx, int flags); -\& int EVP_CIPHER_CTX_test_flags(const EVP_CIPHER_CTX *ctx, int flags); -\& -\& const EVP_CIPHER *EVP_get_cipherbyname(const char *name); -\& const EVP_CIPHER *EVP_get_cipherbynid(int nid); -\& const EVP_CIPHER *EVP_get_cipherbyobj(const ASN1_OBJECT *a); -\& -\& int EVP_CIPHER_get_nid(const EVP_CIPHER *e); -\& int EVP_CIPHER_is_a(const EVP_CIPHER *cipher, const char *name); -\& int EVP_CIPHER_names_do_all(const EVP_CIPHER *cipher, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const char *EVP_CIPHER_get0_name(const EVP_CIPHER *cipher); -\& const char *EVP_CIPHER_get0_description(const EVP_CIPHER *cipher); -\& const OSSL_PROVIDER *EVP_CIPHER_get0_provider(const EVP_CIPHER *cipher); -\& int EVP_CIPHER_get_block_size(const EVP_CIPHER *e); -\& int EVP_CIPHER_get_key_length(const EVP_CIPHER *e); -\& int EVP_CIPHER_get_iv_length(const EVP_CIPHER *e); -\& unsigned long EVP_CIPHER_get_flags(const EVP_CIPHER *e); -\& unsigned long EVP_CIPHER_get_mode(const EVP_CIPHER *e); -\& int EVP_CIPHER_get_type(const EVP_CIPHER *cipher); -\& -\& const EVP_CIPHER *EVP_CIPHER_CTX_get0_cipher(const EVP_CIPHER_CTX *ctx); -\& EVP_CIPHER *EVP_CIPHER_CTX_get1_cipher(const EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_get_nid(const EVP_CIPHER_CTX *ctx); -\& const char *EVP_CIPHER_CTX_get0_name(const EVP_CIPHER_CTX *ctx); -\& -\& int EVP_CIPHER_get_params(EVP_CIPHER *cipher, OSSL_PARAM params[]); -\& int EVP_CIPHER_CTX_set_params(EVP_CIPHER_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_CIPHER_CTX_get_params(EVP_CIPHER_CTX *ctx, OSSL_PARAM params[]); -\& const OSSL_PARAM *EVP_CIPHER_gettable_params(const EVP_CIPHER *cipher); -\& const OSSL_PARAM *EVP_CIPHER_settable_ctx_params(const EVP_CIPHER *cipher); -\& const OSSL_PARAM *EVP_CIPHER_gettable_ctx_params(const EVP_CIPHER *cipher); -\& const OSSL_PARAM *EVP_CIPHER_CTX_settable_params(EVP_CIPHER_CTX *ctx); -\& const OSSL_PARAM *EVP_CIPHER_CTX_gettable_params(EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_get_block_size(const EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_get_key_length(const EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_get_iv_length(const EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_get_tag_length(const EVP_CIPHER_CTX *ctx); -\& void *EVP_CIPHER_CTX_get_app_data(const EVP_CIPHER_CTX *ctx); -\& void EVP_CIPHER_CTX_set_app_data(const EVP_CIPHER_CTX *ctx, void *data); -\& int EVP_CIPHER_CTX_get_type(const EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_get_mode(const EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_get_num(const EVP_CIPHER_CTX *ctx); -\& int EVP_CIPHER_CTX_set_num(EVP_CIPHER_CTX *ctx, int num); -\& int EVP_CIPHER_CTX_is_encrypting(const EVP_CIPHER_CTX *ctx); -\& -\& int EVP_CIPHER_param_to_asn1(EVP_CIPHER_CTX *c, ASN1_TYPE *type); -\& int EVP_CIPHER_asn1_to_param(EVP_CIPHER_CTX *c, ASN1_TYPE *type); -\& -\& void EVP_CIPHER_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_CIPHER *cipher, void *arg), -\& void *arg); -\& -\& #define EVP_CIPHER_nid EVP_CIPHER_get_nid -\& #define EVP_CIPHER_name EVP_CIPHER_get0_name -\& #define EVP_CIPHER_block_size EVP_CIPHER_get_block_size -\& #define EVP_CIPHER_key_length EVP_CIPHER_get_key_length -\& #define EVP_CIPHER_iv_length EVP_CIPHER_get_iv_length -\& #define EVP_CIPHER_flags EVP_CIPHER_get_flags -\& #define EVP_CIPHER_mode EVP_CIPHER_get_mode -\& #define EVP_CIPHER_type EVP_CIPHER_get_type -\& #define EVP_CIPHER_CTX_encrypting EVP_CIPHER_CTX_is_encrypting -\& #define EVP_CIPHER_CTX_nid EVP_CIPHER_CTX_get_nid -\& #define EVP_CIPHER_CTX_block_size EVP_CIPHER_CTX_get_block_size -\& #define EVP_CIPHER_CTX_key_length EVP_CIPHER_CTX_get_key_length -\& #define EVP_CIPHER_CTX_iv_length EVP_CIPHER_CTX_get_iv_length -\& #define EVP_CIPHER_CTX_tag_length EVP_CIPHER_CTX_get_tag_length -\& #define EVP_CIPHER_CTX_num EVP_CIPHER_CTX_get_num -\& #define EVP_CIPHER_CTX_type EVP_CIPHER_CTX_get_type -\& #define EVP_CIPHER_CTX_mode EVP_CIPHER_CTX_get_mode -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& const EVP_CIPHER *EVP_CIPHER_CTX_cipher(const EVP_CIPHER_CTX *ctx); -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int EVP_CIPHER_CTX_flags(const EVP_CIPHER_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 cipher routines are a high-level interface to certain -symmetric ciphers. -.PP -The \fB\s-1EVP_CIPHER\s0\fR type is a structure for cipher method implementation. -.IP "\fBEVP_CIPHER_fetch()\fR" 4 -.IX Item "EVP_CIPHER_fetch()" -Fetches the cipher implementation for the given \fIalgorithm\fR from any provider -offering it, within the criteria given by the \fIproperties\fR. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.Sp -The returned value must eventually be freed with \fBEVP_CIPHER_free()\fR. -.Sp -Fetched \fB\s-1EVP_CIPHER\s0\fR structures are reference counted. -.IP "\fBEVP_CIPHER_up_ref()\fR" 4 -.IX Item "EVP_CIPHER_up_ref()" -Increments the reference count for an \fB\s-1EVP_CIPHER\s0\fR structure. -.IP "\fBEVP_CIPHER_free()\fR" 4 -.IX Item "EVP_CIPHER_free()" -Decrements the reference count for the fetched \fB\s-1EVP_CIPHER\s0\fR structure. -If the reference count drops to 0 then the structure is freed. -If the argument is \s-1NULL,\s0 nothing is done. -.IP "\fBEVP_CIPHER_CTX_new()\fR" 4 -.IX Item "EVP_CIPHER_CTX_new()" -Allocates and returns a cipher context. -.IP "\fBEVP_CIPHER_CTX_free()\fR" 4 -.IX Item "EVP_CIPHER_CTX_free()" -Clears all information from a cipher context and frees any allocated memory -associated with it, including \fIctx\fR itself. This function should be called -after all operations using a cipher are complete so sensitive information does -not remain in memory. If the argument is \s-1NULL,\s0 nothing is done. -.IP "\fBEVP_CIPHER_CTX_dup()\fR" 4 -.IX Item "EVP_CIPHER_CTX_dup()" -Can be used to duplicate the cipher state from \fIin\fR. This is useful -to avoid multiple \fBEVP_CIPHER_fetch()\fR calls or if large amounts of data are to be -fed which only differ in the last few bytes. -.IP "\fBEVP_CIPHER_CTX_copy()\fR" 4 -.IX Item "EVP_CIPHER_CTX_copy()" -Can be used to copy the cipher state from \fIin\fR to \fIout\fR. -.IP "\fBEVP_CIPHER_CTX_ctrl()\fR" 4 -.IX Item "EVP_CIPHER_CTX_ctrl()" -\&\fIThis is a legacy method.\fR \fBEVP_CIPHER_CTX_set_params()\fR and -\&\fBEVP_CIPHER_CTX_get_params()\fR is the mechanism that should be used to set and get -parameters that are used by providers. -.Sp -Performs cipher-specific control actions on context \fIctx\fR. The control command -is indicated in \fIcmd\fR and any additional arguments in \fIp1\fR and \fIp2\fR. -\&\fBEVP_CIPHER_CTX_ctrl()\fR must be called after \fBEVP_CipherInit_ex2()\fR. Other restrictions -may apply depending on the control type and cipher implementation. -.Sp -If this function happens to be used with a fetched \fB\s-1EVP_CIPHER\s0\fR, it will -translate the controls that are known to OpenSSL into \s-1\fBOSSL_PARAM\s0\fR\|(3) -parameters with keys defined by OpenSSL and call \fBEVP_CIPHER_CTX_get_params()\fR or -\&\fBEVP_CIPHER_CTX_set_params()\fR as is appropriate for each control command. -.Sp -See \*(L"\s-1CONTROLS\*(R"\s0 below for more information, including what translations are -being done. -.IP "\fBEVP_CIPHER_get_params()\fR" 4 -.IX Item "EVP_CIPHER_get_params()" -Retrieves the requested list of algorithm \fIparams\fR from a \s-1CIPHER\s0 \fIcipher\fR. -See \*(L"\s-1PARAMETERS\*(R"\s0 below for more information. -.IP "\fBEVP_CIPHER_CTX_get_params()\fR" 4 -.IX Item "EVP_CIPHER_CTX_get_params()" -Retrieves the requested list of \fIparams\fR from \s-1CIPHER\s0 context \fIctx\fR. -See \*(L"\s-1PARAMETERS\*(R"\s0 below for more information. -.IP "\fBEVP_CIPHER_CTX_set_params()\fR" 4 -.IX Item "EVP_CIPHER_CTX_set_params()" -Sets the list of \fIparams\fR into a \s-1CIPHER\s0 context \fIctx\fR. -See \*(L"\s-1PARAMETERS\*(R"\s0 below for more information. -.IP "\fBEVP_CIPHER_gettable_params()\fR" 4 -.IX Item "EVP_CIPHER_gettable_params()" -Get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the retrievable parameters -that can be used with \fBEVP_CIPHER_get_params()\fR. -.IP "\fBEVP_CIPHER_gettable_ctx_params()\fR and \fBEVP_CIPHER_CTX_gettable_params()\fR" 4 -.IX Item "EVP_CIPHER_gettable_ctx_params() and EVP_CIPHER_CTX_gettable_params()" -Get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the retrievable parameters -that can be used with \fBEVP_CIPHER_CTX_get_params()\fR. -\&\fBEVP_CIPHER_gettable_ctx_params()\fR returns the parameters that can be retrieved -from the algorithm, whereas \fBEVP_CIPHER_CTX_gettable_params()\fR returns the -parameters that can be retrieved in the context's current state. -.IP "\fBEVP_CIPHER_settable_ctx_params()\fR and \fBEVP_CIPHER_CTX_settable_params()\fR" 4 -.IX Item "EVP_CIPHER_settable_ctx_params() and EVP_CIPHER_CTX_settable_params()" -Get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the settable parameters -that can be used with \fBEVP_CIPHER_CTX_set_params()\fR. -\&\fBEVP_CIPHER_settable_ctx_params()\fR returns the parameters that can be set from the -algorithm, whereas \fBEVP_CIPHER_CTX_settable_params()\fR returns the parameters that -can be set in the context's current state. -.IP "\fBEVP_EncryptInit_ex2()\fR" 4 -.IX Item "EVP_EncryptInit_ex2()" -Sets up cipher context \fIctx\fR for encryption with cipher \fItype\fR. \fItype\fR is -typically supplied by calling \fBEVP_CIPHER_fetch()\fR. \fItype\fR may also be set -using legacy functions such as \fBEVP_aes_256_cbc()\fR, but this is not recommended -for new applications. \fIkey\fR is the symmetric key to use and \fIiv\fR is the \s-1IV\s0 to -use (if necessary), the actual number of bytes used for the key and \s-1IV\s0 depends -on the cipher. The parameters \fIparams\fR will be set on the context after -initialisation. It is possible to set all parameters to \s-1NULL\s0 except \fItype\fR in -an initial call and supply the remaining parameters in subsequent calls, all of -which have \fItype\fR set to \s-1NULL.\s0 This is done when the default cipher parameters -are not appropriate. -For \fB\s-1EVP_CIPH_GCM_MODE\s0\fR the \s-1IV\s0 will be generated internally if it is not -specified. -.IP "\fBEVP_EncryptInit_ex()\fR" 4 -.IX Item "EVP_EncryptInit_ex()" -This legacy function is similar to \fBEVP_EncryptInit_ex2()\fR when \fIimpl\fR is \s-1NULL.\s0 -The implementation of the \fItype\fR from the \fIimpl\fR engine will be used if it -exists. -.IP "\fBEVP_EncryptUpdate()\fR" 4 -.IX Item "EVP_EncryptUpdate()" -Encrypts \fIinl\fR bytes from the buffer \fIin\fR and writes the encrypted version to -\&\fIout\fR. The pointers \fIout\fR and \fIin\fR may point to the same location, in which -case the encryption will be done in-place. However, in-place encryption is -guaranteed to work only if the encryption context (\fIctx\fR) has processed data in -multiples of the block size. If the context contains an incomplete data block -from previous operations, in-place encryption will fail. -.Sp -If \fIout\fR and \fIin\fR point to different locations, the two buffers must be -disjoint, otherwise the operation might fail or the outcome might be undefined. -.Sp -This function can be called multiple times to encrypt successive blocks -of data. The amount of data written depends on the block alignment of the -encrypted data. -For most ciphers and modes, the amount of data written can be anything -from zero bytes to (inl + cipher_block_size \- 1) bytes. -For wrap cipher modes, the amount of data written can be anything -from zero bytes to (inl + cipher_block_size) bytes. -For stream ciphers, the amount of data written can be anything from zero -bytes to inl bytes. -Thus, the buffer pointed to by \fIout\fR must contain sufficient room for the -operation being performed. -The actual number of bytes written is placed in \fIoutl\fR. -.Sp -If padding is enabled (the default) then \fBEVP_EncryptFinal_ex()\fR encrypts -the \*(L"final\*(R" data, that is any data that remains in a partial block. -It uses standard block padding (aka \s-1PKCS\s0 padding) as described in -the \s-1NOTES\s0 section, below. The encrypted -final data is written to \fIout\fR which should have sufficient space for -one cipher block. The number of bytes written is placed in \fIoutl\fR. After -this function is called the encryption operation is finished and no further -calls to \fBEVP_EncryptUpdate()\fR should be made. -.Sp -If padding is disabled then \fBEVP_EncryptFinal_ex()\fR will not encrypt any more -data and it will return an error if any data remains in a partial block: -that is if the total data length is not a multiple of the block size. -.IP "\fBEVP_DecryptInit_ex2()\fR, \fBEVP_DecryptInit_ex()\fR, \fBEVP_DecryptUpdate()\fR and \fBEVP_DecryptFinal_ex()\fR" 4 -.IX Item "EVP_DecryptInit_ex2(), EVP_DecryptInit_ex(), EVP_DecryptUpdate() and EVP_DecryptFinal_ex()" -These functions are the corresponding decryption operations. -\&\fBEVP_DecryptFinal()\fR will return an error code if padding is enabled and the -final block is not correctly formatted. The parameters and restrictions are -identical to the encryption operations except that if padding is enabled the -decrypted data buffer \fIout\fR passed to \fBEVP_DecryptUpdate()\fR should have -sufficient room for (\fIinl\fR + cipher_block_size) bytes unless the cipher block -size is 1 in which case \fIinl\fR bytes is sufficient. -.IP "\fBEVP_CipherInit_ex2()\fR, \fBEVP_CipherInit_ex()\fR, \fBEVP_CipherUpdate()\fR and \fBEVP_CipherFinal_ex()\fR" 4 -.IX Item "EVP_CipherInit_ex2(), EVP_CipherInit_ex(), EVP_CipherUpdate() and EVP_CipherFinal_ex()" -These functions can be used for decryption or encryption. The operation -performed depends on the value of the \fIenc\fR parameter. It should be set to 1 -for encryption, 0 for decryption and \-1 to leave the value unchanged -(the actual value of 'enc' being supplied in a previous call). -.IP "\fBEVP_CIPHER_CTX_reset()\fR" 4 -.IX Item "EVP_CIPHER_CTX_reset()" -Clears all information from a cipher context and free up any allocated memory -associated with it, except the \fIctx\fR itself. This function should be called -anytime \fIctx\fR is reused by another -\&\fBEVP_CipherInit()\fR / \fBEVP_CipherUpdate()\fR / \fBEVP_CipherFinal()\fR series of calls. -.IP "\fBEVP_EncryptInit()\fR, \fBEVP_DecryptInit()\fR and \fBEVP_CipherInit()\fR" 4 -.IX Item "EVP_EncryptInit(), EVP_DecryptInit() and EVP_CipherInit()" -Behave in a similar way to \fBEVP_EncryptInit_ex()\fR, \fBEVP_DecryptInit_ex()\fR and -\&\fBEVP_CipherInit_ex()\fR except if the \fItype\fR is not a fetched cipher they use the -default implementation of the \fItype\fR. -.IP "\fBEVP_EncryptFinal()\fR, \fBEVP_DecryptFinal()\fR and \fBEVP_CipherFinal()\fR" 4 -.IX Item "EVP_EncryptFinal(), EVP_DecryptFinal() and EVP_CipherFinal()" -Identical to \fBEVP_EncryptFinal_ex()\fR, \fBEVP_DecryptFinal_ex()\fR and -\&\fBEVP_CipherFinal_ex()\fR. In previous releases they also cleaned up -the \fIctx\fR, but this is no longer done and \fBEVP_CIPHER_CTX_cleanup()\fR -must be called to free any context resources. -.IP "\fBEVP_Cipher()\fR" 4 -.IX Item "EVP_Cipher()" -Encrypts or decrypts a maximum \fIinl\fR amount of bytes from \fIin\fR and leaves the -result in \fIout\fR. -.Sp -For legacy ciphers \- If the cipher doesn't have the flag -\&\fB\s-1EVP_CIPH_FLAG_CUSTOM_CIPHER\s0\fR set, then \fIinl\fR must be a multiple of -\&\fBEVP_CIPHER_get_block_size()\fR. If it isn't, the result is undefined. If the cipher -has that flag set, then \fIinl\fR can be any size. -.Sp -Due to the constraints of the \s-1API\s0 contract of this function it shouldn't be used -in applications, please consider using \fBEVP_CipherUpdate()\fR and -\&\fBEVP_CipherFinal_ex()\fR instead. -.IP "\fBEVP_get_cipherbyname()\fR, \fBEVP_get_cipherbynid()\fR and \fBEVP_get_cipherbyobj()\fR" 4 -.IX Item "EVP_get_cipherbyname(), EVP_get_cipherbynid() and EVP_get_cipherbyobj()" -Returns an \fB\s-1EVP_CIPHER\s0\fR structure when passed a cipher name, a cipher \fB\s-1NID\s0\fR or -an \fB\s-1ASN1_OBJECT\s0\fR structure respectively. -.Sp -\&\fBEVP_get_cipherbyname()\fR will return \s-1NULL\s0 for algorithms such as \*(L"\s-1AES\-128\-SIV\*(R", -\&\*(L"AES\-128\-CBC\-CTS\*(R"\s0 and \*(L"\s-1CAMELLIA\-128\-CBC\-CTS\*(R"\s0 which were previously only -accessible via low level interfaces. -.Sp -The \fBEVP_get_cipherbyname()\fR function is present for backwards compatibility with -OpenSSL prior to version 3 and is different to the \fBEVP_CIPHER_fetch()\fR function -since it does not attempt to \*(L"fetch\*(R" an implementation of the cipher. -Additionally, it only knows about ciphers that are built-in to OpenSSL and have -an associated \s-1NID.\s0 Similarly \fBEVP_get_cipherbynid()\fR and \fBEVP_get_cipherbyobj()\fR -also return objects without an associated implementation. -.Sp -When the cipher objects returned by these functions are used (such as in a call -to \fBEVP_EncryptInit_ex()\fR) an implementation of the cipher will be implicitly -fetched from the loaded providers. This fetch could fail if no suitable -implementation is available. Use \fBEVP_CIPHER_fetch()\fR instead to explicitly fetch -the algorithm and an associated implementation from a provider. -.Sp -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for more information about fetching. -.Sp -The cipher objects returned from these functions do not need to be freed with -\&\fBEVP_CIPHER_free()\fR. -.IP "\fBEVP_CIPHER_get_nid()\fR and \fBEVP_CIPHER_CTX_get_nid()\fR" 4 -.IX Item "EVP_CIPHER_get_nid() and EVP_CIPHER_CTX_get_nid()" -Return the \s-1NID\s0 of a cipher when passed an \fB\s-1EVP_CIPHER\s0\fR or \fB\s-1EVP_CIPHER_CTX\s0\fR -structure. The actual \s-1NID\s0 value is an internal value which may not have a -corresponding \s-1OBJECT IDENTIFIER.\s0 NID_undef is returned in the event that the -nid is unknown or if the cipher has not been properly initialized via a call to -\&\fBEVP_CipherInit\fR. -.IP "\fBEVP_CIPHER_CTX_set_flags()\fR, \fBEVP_CIPHER_CTX_clear_flags()\fR and \fBEVP_CIPHER_CTX_test_flags()\fR" 4 -.IX Item "EVP_CIPHER_CTX_set_flags(), EVP_CIPHER_CTX_clear_flags() and EVP_CIPHER_CTX_test_flags()" -Sets, clears and tests \fIctx\fR flags. See \*(L"\s-1FLAGS\*(R"\s0 below for more information. -.Sp -For provided ciphers \fBEVP_CIPHER_CTX_set_flags()\fR should be called only after the -fetched cipher has been assigned to the \fIctx\fR. It is recommended to use -\&\*(L"\s-1PARAMETERS\*(R"\s0 instead. -.IP "\fBEVP_CIPHER_CTX_set_padding()\fR" 4 -.IX Item "EVP_CIPHER_CTX_set_padding()" -Enables or disables padding. This function should be called after the context -is set up for encryption or decryption with \fBEVP_EncryptInit_ex2()\fR, -\&\fBEVP_DecryptInit_ex2()\fR or \fBEVP_CipherInit_ex2()\fR. By default encryption operations -are padded using standard block padding and the padding is checked and removed -when decrypting. If the \fIpad\fR parameter is zero then no padding is -performed, the total amount of data encrypted or decrypted must then -be a multiple of the block size or an error will occur. -.IP "\fBEVP_CIPHER_get_key_length()\fR and \fBEVP_CIPHER_CTX_get_key_length()\fR" 4 -.IX Item "EVP_CIPHER_get_key_length() and EVP_CIPHER_CTX_get_key_length()" -Return the key length of a cipher when passed an \fB\s-1EVP_CIPHER\s0\fR or -\&\fB\s-1EVP_CIPHER_CTX\s0\fR structure. The constant \fB\s-1EVP_MAX_KEY_LENGTH\s0\fR is the maximum -key length for all ciphers. Note: although \fBEVP_CIPHER_get_key_length()\fR is fixed for -a given cipher, the value of \fBEVP_CIPHER_CTX_get_key_length()\fR may be different for -variable key length ciphers. -.IP "\fBEVP_CIPHER_CTX_set_key_length()\fR" 4 -.IX Item "EVP_CIPHER_CTX_set_key_length()" -Sets the key length of the cipher context. -If the cipher is a fixed length cipher then attempting to set the key -length to any value other than the fixed value is an error. -.IP "\fBEVP_CIPHER_get_iv_length()\fR and \fBEVP_CIPHER_CTX_get_iv_length()\fR" 4 -.IX Item "EVP_CIPHER_get_iv_length() and EVP_CIPHER_CTX_get_iv_length()" -Return the \s-1IV\s0 length of a cipher when passed an \fB\s-1EVP_CIPHER\s0\fR or -\&\fB\s-1EVP_CIPHER_CTX\s0\fR. It will return zero if the cipher does not use an \s-1IV,\s0 if -the cipher has not yet been initialized within the \fB\s-1EVP_CIPHER_CTX\s0\fR, or if the -passed cipher is \s-1NULL.\s0 The constant \fB\s-1EVP_MAX_IV_LENGTH\s0\fR is the maximum \s-1IV\s0 -length for all ciphers. -.IP "\fBEVP_CIPHER_CTX_get_tag_length()\fR" 4 -.IX Item "EVP_CIPHER_CTX_get_tag_length()" -Returns the tag length of an \s-1AEAD\s0 cipher when passed a \fB\s-1EVP_CIPHER_CTX\s0\fR. It will -return zero if the cipher does not support a tag. It returns a default value if -the tag length has not been set. -.IP "\fBEVP_CIPHER_get_block_size()\fR and \fBEVP_CIPHER_CTX_get_block_size()\fR" 4 -.IX Item "EVP_CIPHER_get_block_size() and EVP_CIPHER_CTX_get_block_size()" -Return the block size of a cipher when passed an \fB\s-1EVP_CIPHER\s0\fR or -\&\fB\s-1EVP_CIPHER_CTX\s0\fR structure. The constant \fB\s-1EVP_MAX_BLOCK_LENGTH\s0\fR is also the -maximum block length for all ciphers. A value of 0 is returned if the cipher -has not been properly initialized with a call to \fBEVP_CipherInit\fR. -.IP "\fBEVP_CIPHER_get_type()\fR and \fBEVP_CIPHER_CTX_get_type()\fR" 4 -.IX Item "EVP_CIPHER_get_type() and EVP_CIPHER_CTX_get_type()" -Return the type of the passed cipher or context. This \*(L"type\*(R" is the actual \s-1NID\s0 -of the cipher \s-1OBJECT IDENTIFIER\s0 and as such it ignores the cipher parameters -(40 bit \s-1RC2\s0 and 128 bit \s-1RC2\s0 have the same \s-1NID\s0). If the cipher does not have an -object identifier or does not have \s-1ASN1\s0 support this function will return -\&\fBNID_undef\fR. -.IP "\fBEVP_CIPHER_is_a()\fR" 4 -.IX Item "EVP_CIPHER_is_a()" -Returns 1 if \fIcipher\fR is an implementation of an algorithm that's identifiable -with \fIname\fR, otherwise 0. If \fIcipher\fR is a legacy cipher (it's the return -value from the likes of \fBEVP_aes128()\fR rather than the result of an -\&\fBEVP_CIPHER_fetch()\fR), only cipher names registered with the default library -context (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) will be considered. -.IP "\fBEVP_CIPHER_get0_name()\fR and \fBEVP_CIPHER_CTX_get0_name()\fR" 4 -.IX Item "EVP_CIPHER_get0_name() and EVP_CIPHER_CTX_get0_name()" -Return the name of the passed cipher or context. For fetched ciphers with -multiple names, only one of them is returned. See also \fBEVP_CIPHER_names_do_all()\fR. -.IP "\fBEVP_CIPHER_names_do_all()\fR" 4 -.IX Item "EVP_CIPHER_names_do_all()" -Traverses all names for the \fIcipher\fR, and calls \fIfn\fR with each name and -\&\fIdata\fR. This is only useful with fetched \fB\s-1EVP_CIPHER\s0\fRs. -.IP "\fBEVP_CIPHER_get0_description()\fR" 4 -.IX Item "EVP_CIPHER_get0_description()" -Returns a description of the cipher, meant for display and human consumption. -The description is at the discretion of the cipher implementation. -.IP "\fBEVP_CIPHER_get0_provider()\fR" 4 -.IX Item "EVP_CIPHER_get0_provider()" -Returns an \fB\s-1OSSL_PROVIDER\s0\fR pointer to the provider that implements the given -\&\fB\s-1EVP_CIPHER\s0\fR. -.IP "\fBEVP_CIPHER_CTX_get0_cipher()\fR" 4 -.IX Item "EVP_CIPHER_CTX_get0_cipher()" -Returns the \fB\s-1EVP_CIPHER\s0\fR structure when passed an \fB\s-1EVP_CIPHER_CTX\s0\fR structure. -\&\fBEVP_CIPHER_CTX_get1_cipher()\fR is the same except the ownership is passed to -the caller. Both functions return \s-1NULL\s0 on error. -.IP "\fBEVP_CIPHER_get_mode()\fR and \fBEVP_CIPHER_CTX_get_mode()\fR" 4 -.IX Item "EVP_CIPHER_get_mode() and EVP_CIPHER_CTX_get_mode()" -Return the block cipher mode: -\&\s-1EVP_CIPH_ECB_MODE, EVP_CIPH_CBC_MODE, EVP_CIPH_CFB_MODE, EVP_CIPH_OFB_MODE, -EVP_CIPH_CTR_MODE, EVP_CIPH_GCM_MODE, EVP_CIPH_CCM_MODE, EVP_CIPH_XTS_MODE, -EVP_CIPH_WRAP_MODE, EVP_CIPH_OCB_MODE\s0 or \s-1EVP_CIPH_SIV_MODE.\s0 -If the cipher is a stream cipher then \s-1EVP_CIPH_STREAM_CIPHER\s0 is returned. -.IP "\fBEVP_CIPHER_get_flags()\fR" 4 -.IX Item "EVP_CIPHER_get_flags()" -Returns any flags associated with the cipher. See \*(L"\s-1FLAGS\*(R"\s0 -for a list of currently defined flags. -.IP "\fBEVP_CIPHER_CTX_get_num()\fR and \fBEVP_CIPHER_CTX_set_num()\fR" 4 -.IX Item "EVP_CIPHER_CTX_get_num() and EVP_CIPHER_CTX_set_num()" -Gets or sets the cipher specific \*(L"num\*(R" parameter for the associated \fIctx\fR. -Built-in ciphers typically use this to track how much of the current underlying block -has been \*(L"used\*(R" already. -.IP "\fBEVP_CIPHER_CTX_is_encrypting()\fR" 4 -.IX Item "EVP_CIPHER_CTX_is_encrypting()" -Reports whether the \fIctx\fR is being used for encryption or decryption. -.IP "\fBEVP_CIPHER_CTX_flags()\fR" 4 -.IX Item "EVP_CIPHER_CTX_flags()" -A deprecated macro calling \f(CW\*(C`EVP_CIPHER_get_flags(EVP_CIPHER_CTX_get0_cipher(ctx))\*(C'\fR. -Do not use. -.IP "\fBEVP_CIPHER_param_to_asn1()\fR" 4 -.IX Item "EVP_CIPHER_param_to_asn1()" -Sets the AlgorithmIdentifier \*(L"parameter\*(R" based on the passed cipher. This will -typically include any parameters and an \s-1IV.\s0 The cipher \s-1IV\s0 (if any) must be set -when this call is made. This call should be made before the cipher is actually -\&\*(L"used\*(R" (before any \fBEVP_EncryptUpdate()\fR, \fBEVP_DecryptUpdate()\fR calls for example). -This function may fail if the cipher does not have any \s-1ASN1\s0 support, or if an -uninitialized cipher is passed to it. -.IP "\fBEVP_CIPHER_asn1_to_param()\fR" 4 -.IX Item "EVP_CIPHER_asn1_to_param()" -Sets the cipher parameters based on an \s-1ASN1\s0 AlgorithmIdentifier \*(L"parameter\*(R". -The precise effect depends on the cipher. In the case of \fB\s-1RC2\s0\fR, for example, -it will set the \s-1IV\s0 and effective key length. -This function should be called after the base cipher type is set but before -the key is set. For example \fBEVP_CipherInit()\fR will be called with the \s-1IV\s0 and -key set to \s-1NULL,\s0 \fBEVP_CIPHER_asn1_to_param()\fR will be called and finally -\&\fBEVP_CipherInit()\fR again with all parameters except the key set to \s-1NULL.\s0 It is -possible for this function to fail if the cipher does not have any \s-1ASN1\s0 support -or the parameters cannot be set (for example the \s-1RC2\s0 effective key length -is not supported. -.IP "\fBEVP_CIPHER_CTX_rand_key()\fR" 4 -.IX Item "EVP_CIPHER_CTX_rand_key()" -Generates a random key of the appropriate length based on the cipher context. -The \fB\s-1EVP_CIPHER\s0\fR can provide its own random key generation routine to support -keys of a specific form. \fIkey\fR must point to a buffer at least as big as the -value returned by \fBEVP_CIPHER_CTX_get_key_length()\fR. -.IP "\fBEVP_CIPHER_do_all_provided()\fR" 4 -.IX Item "EVP_CIPHER_do_all_provided()" -Traverses all ciphers implemented by all activated providers in the given -library context \fIlibctx\fR, and for each of the implementations, calls the given -function \fIfn\fR with the implementation method and the given \fIarg\fR as argument. -.SH "PARAMETERS" -.IX Header "PARAMETERS" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for information about passing parameters. -.SS "Gettable \s-1EVP_CIPHER\s0 parameters" -.IX Subsection "Gettable EVP_CIPHER parameters" -When \fBEVP_CIPHER_fetch()\fR is called it internally calls \fBEVP_CIPHER_get_params()\fR -and caches the results. -.PP -\&\fBEVP_CIPHER_get_params()\fR can be used with the following \s-1\fBOSSL_PARAM\s0\fR\|(3) keys: -.ie n .IP """mode"" (\fB\s-1OSSL_CIPHER_PARAM_MODE\s0\fR) " 4 -.el .IP "``mode'' (\fB\s-1OSSL_CIPHER_PARAM_MODE\s0\fR) " 4 -.IX Item "mode (OSSL_CIPHER_PARAM_MODE) " -Gets the mode for the associated cipher algorithm \fIcipher\fR. -See \*(L"\fBEVP_CIPHER_get_mode()\fR and \fBEVP_CIPHER_CTX_get_mode()\fR\*(R" for a list of valid modes. -Use \fBEVP_CIPHER_get_mode()\fR to retrieve the cached value. -.ie n .IP """keylen"" (\fB\s-1OSSL_CIPHER_PARAM_KEYLEN\s0\fR) " 4 -.el .IP "``keylen'' (\fB\s-1OSSL_CIPHER_PARAM_KEYLEN\s0\fR) " 4 -.IX Item "keylen (OSSL_CIPHER_PARAM_KEYLEN) " -Gets the key length for the associated cipher algorithm \fIcipher\fR. -Use \fBEVP_CIPHER_get_key_length()\fR to retrieve the cached value. -.ie n .IP """ivlen"" (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR) " 4 -.el .IP "``ivlen'' (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR) " 4 -.IX Item "ivlen (OSSL_CIPHER_PARAM_IVLEN) " -Gets the \s-1IV\s0 length for the associated cipher algorithm \fIcipher\fR. -Use \fBEVP_CIPHER_get_iv_length()\fR to retrieve the cached value. -.ie n .IP """blocksize"" (\fB\s-1OSSL_CIPHER_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``blocksize'' (\fB\s-1OSSL_CIPHER_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "blocksize (OSSL_CIPHER_PARAM_BLOCK_SIZE) " -Gets the block size for the associated cipher algorithm \fIcipher\fR. -The block size should be 1 for stream ciphers. -Note that the block size for a cipher may be different to the block size for -the underlying encryption/decryption primitive. -For example \s-1AES\s0 in \s-1CTR\s0 mode has a block size of 1 (because it operates like a -stream cipher), even though \s-1AES\s0 has a block size of 16. -Use \fBEVP_CIPHER_get_block_size()\fR to retrieve the cached value. -.ie n .IP """aead"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD\s0\fR) " 4 -.el .IP "``aead'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD\s0\fR) " 4 -.IX Item "aead (OSSL_CIPHER_PARAM_AEAD) " -Gets 1 if this is an \s-1AEAD\s0 cipher algorithm, otherwise it gets 0. -Use (EVP_CIPHER_get_flags(cipher) & \s-1EVP_CIPH_FLAG_AEAD_CIPHER\s0) to retrieve the -cached value. -.ie n .IP """custom-iv"" (\fB\s-1OSSL_CIPHER_PARAM_CUSTOM_IV\s0\fR) " 4 -.el .IP "``custom-iv'' (\fB\s-1OSSL_CIPHER_PARAM_CUSTOM_IV\s0\fR) " 4 -.IX Item "custom-iv (OSSL_CIPHER_PARAM_CUSTOM_IV) " -Gets 1 if the cipher algorithm \fIcipher\fR has a custom \s-1IV,\s0 otherwise it gets 0. -Storing and initializing the \s-1IV\s0 is left entirely to the implementation, if a -custom \s-1IV\s0 is used. -Use (EVP_CIPHER_get_flags(cipher) & \s-1EVP_CIPH_CUSTOM_IV\s0) to retrieve the -cached value. -.ie n .IP """cts"" (\fB\s-1OSSL_CIPHER_PARAM_CTS\s0\fR) " 4 -.el .IP "``cts'' (\fB\s-1OSSL_CIPHER_PARAM_CTS\s0\fR) " 4 -.IX Item "cts (OSSL_CIPHER_PARAM_CTS) " -Gets 1 if the cipher algorithm \fIcipher\fR uses ciphertext stealing, -otherwise it gets 0. -This is currently used to indicate that the cipher is a one shot that only -allows a single call to \fBEVP_CipherUpdate()\fR. -Use (EVP_CIPHER_get_flags(cipher) & \s-1EVP_CIPH_FLAG_CTS\s0) to retrieve the -cached value. -.ie n .IP """tls-multi"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK\s0\fR) " 4 -.el .IP "``tls-multi'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK\s0\fR) " 4 -.IX Item "tls-multi (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK) " -Gets 1 if the cipher algorithm \fIcipher\fR supports interleaving of crypto blocks, -otherwise it gets 0. The interleaving is an optimization only applicable to certain -\&\s-1TLS\s0 ciphers. -Use (EVP_CIPHER_get_flags(cipher) & \s-1EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK\s0) to retrieve the -cached value. -.ie n .IP """has-randkey"" (\fB\s-1OSSL_CIPHER_PARAM_HAS_RANDKEY\s0\fR) " 4 -.el .IP "``has-randkey'' (\fB\s-1OSSL_CIPHER_PARAM_HAS_RANDKEY\s0\fR) " 4 -.IX Item "has-randkey (OSSL_CIPHER_PARAM_HAS_RANDKEY) " -Gets 1 if the cipher algorithm \fIcipher\fR supports the gettable \s-1EVP_CIPHER_CTX\s0 -parameter \fB\s-1OSSL_CIPHER_PARAM_RANDOM_KEY\s0\fR. Only \s-1DES\s0 and 3DES set this to 1, -all other OpenSSL ciphers return 0. -.ie n .IP """decrypt-only"" (\fB\s-1OSSL_CIPHER_PARAM_DECRYPT_ONLY\s0) " 4 -.el .IP "``padding'' (\fB\s-1OSSL_CIPHER_PARAM_PADDING\s0\fR) " 4 -.IX Item "padding (OSSL_CIPHER_PARAM_PADDING) " -Gets or sets the padding mode for the cipher context \fIctx\fR. -Padding is enabled if the value is 1, and disabled if the value is 0. -See also \fBEVP_CIPHER_CTX_set_padding()\fR. -.ie n .IP """num"" (\fB\s-1OSSL_CIPHER_PARAM_NUM\s0\fR) " 4 -.el .IP "``num'' (\fB\s-1OSSL_CIPHER_PARAM_NUM\s0\fR) " 4 -.IX Item "num (OSSL_CIPHER_PARAM_NUM) " -Gets or sets the cipher specific \*(L"num\*(R" parameter for the cipher context \fIctx\fR. -Built-in ciphers typically use this to track how much of the current underlying -block has been \*(L"used\*(R" already. -See also \fBEVP_CIPHER_CTX_get_num()\fR and \fBEVP_CIPHER_CTX_set_num()\fR. -.ie n .IP """keylen"" (\fB\s-1OSSL_CIPHER_PARAM_KEYLEN\s0\fR) " 4 -.el .IP "``keylen'' (\fB\s-1OSSL_CIPHER_PARAM_KEYLEN\s0\fR) " 4 -.IX Item "keylen (OSSL_CIPHER_PARAM_KEYLEN) " -Gets or sets the key length for the cipher context \fIctx\fR. -The length of the \*(L"keylen\*(R" parameter should not exceed that of a \fBsize_t\fR. -See also \fBEVP_CIPHER_CTX_get_key_length()\fR and \fBEVP_CIPHER_CTX_set_key_length()\fR. -.ie n .IP """tag"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TAG\s0\fR) " 4 -.el .IP "``tag'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TAG\s0\fR) " 4 -.IX Item "tag (OSSL_CIPHER_PARAM_AEAD_TAG) " -Gets or sets the \s-1AEAD\s0 tag for the associated cipher context \fIctx\fR. -See \*(L"\s-1AEAD\s0 Interface\*(R" in \fBEVP_EncryptInit\fR\|(3). -.ie n .IP """keybits"" (\fB\s-1OSSL_CIPHER_PARAM_RC2_KEYBITS\s0\fR) " 4 -.el .IP "``keybits'' (\fB\s-1OSSL_CIPHER_PARAM_RC2_KEYBITS\s0\fR) " 4 -.IX Item "keybits (OSSL_CIPHER_PARAM_RC2_KEYBITS) " -Gets or sets the effective keybits used for a \s-1RC2\s0 cipher. -The length of the \*(L"keybits\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """rounds"" (\fB\s-1OSSL_CIPHER_PARAM_ROUNDS\s0\fR) " 4 -.el .IP "``rounds'' (\fB\s-1OSSL_CIPHER_PARAM_ROUNDS\s0\fR) " 4 -.IX Item "rounds (OSSL_CIPHER_PARAM_ROUNDS) " -Gets or sets the number of rounds to be used for a cipher. -This is used by the \s-1RC5\s0 cipher. -.ie n .IP """algorithm-id"" (\fB\s-1OSSL_CIPHER_PARAM_ALGORITHM_ID\s0\fR) " 4 -.el .IP "``algorithm-id'' (\fB\s-1OSSL_CIPHER_PARAM_ALGORITHM_ID\s0\fR) " 4 -.IX Item "algorithm-id (OSSL_CIPHER_PARAM_ALGORITHM_ID) " -Used to get the \s-1DER\s0 encoded AlgorithmIdentifier from the cipher -implementation. Functions like \fBEVP_PKEY_CTX_get_algor\fR\|(3) use this -parameter. -.ie n .IP """algorithm-id-params"" (\fB\s-1OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS\s0\fR) " 4 -.el .IP "``algorithm-id-params'' (\fB\s-1OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS\s0\fR) " 4 -.IX Item "algorithm-id-params (OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS) " -Used to pass the \s-1DER\s0 encoded AlgorithmIdentifier parameter to or from -the cipher implementation. -Functions like \fBEVP_CIPHER_CTX_set_algor_params\fR\|(3) and -\&\fBEVP_CIPHER_CTX_get_algor_params\fR\|(3) use this parameter. -.ie n .IP """alg_id_params"" (\fB\s-1OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS_OLD\s0\fR) " 4 -.el .IP "``alg_id_params'' (\fB\s-1OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS_OLD\s0\fR) " 4 -.IX Item "alg_id_params (OSSL_CIPHER_PARAM_ALGORITHM_ID_PARAMS_OLD) " -An deprecated alias for \*(L"algorithm-id-params\*(R", only used by -\&\fBEVP_CIPHER_param_to_asn1\fR\|(3) and \fBEVP_CIPHER_asn1_to_param\fR\|(3). -.ie n .IP """cts_mode"" (\fB\s-1OSSL_CIPHER_PARAM_CTS_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cts_mode'' (\fB\s-1OSSL_CIPHER_PARAM_CTS_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cts_mode (OSSL_CIPHER_PARAM_CTS_MODE) " -Gets or sets the cipher text stealing mode. For all modes the output size is the -same as the input size. The input length must be greater than or equal to the -block size. (The block size for \s-1AES\s0 and \s-1CAMELLIA\s0 is 16 bytes). -.Sp -Valid values for the mode are: -.RS 4 -.ie n .IP """\s-1CS1""\s0" 4 -.el .IP "``\s-1CS1''\s0" 4 -.IX Item "CS1" -The \s-1NIST\s0 variant of cipher text stealing. -For input lengths that are multiples of the block size it is equivalent to -using a \*(L"AES-XXX-CBC\*(R" or \*(L"CAMELLIA-XXX-CBC\*(R" cipher otherwise the second last -cipher text block is a partial block. -.ie n .IP """\s-1CS2""\s0" 4 -.el .IP "``\s-1CS2''\s0" 4 -.IX Item "CS2" -For input lengths that are multiples of the block size it is equivalent to -using a \*(L"AES-XXX-CBC\*(R" or \*(L"CAMELLIA-XXX-CBC\*(R" cipher, otherwise it is the same as -\&\*(L"\s-1CS3\*(R"\s0 mode. -.ie n .IP """\s-1CS3""\s0" 4 -.el .IP "``\s-1CS3''\s0" 4 -.IX Item "CS3" -The Kerberos5 variant of cipher text stealing which always swaps the last -cipher text block with the previous block (which may be a partial or full block -depending on the input length). If the input length is exactly one full block -then this is equivalent to using a \*(L"AES-XXX-CBC\*(R" or \*(L"CAMELLIA-XXX-CBC\*(R" cipher. -.RE -.RS 4 -.Sp -The default is \*(L"\s-1CS1\*(R".\s0 -This is only supported for \*(L"\s-1AES\-128\-CBC\-CTS\*(R", \*(L"AES\-192\-CBC\-CTS\*(R", \*(L"AES\-256\-CBC\-CTS\*(R", -\&\*(L"CAMELLIA\-128\-CBC\-CTS\*(R", \*(L"CAMELLIA\-192\-CBC\-CTS\*(R"\s0 and \*(L"\s-1CAMELLIA\-256\-CBC\-CTS\*(R".\s0 -.RE -.ie n .IP """tls1multi_interleave"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE\s0\fR) " 4 -.el .IP "``tls1multi_interleave'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE\s0\fR) " 4 -.IX Item "tls1multi_interleave (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE) " -Sets or gets the number of records being sent in one go for a tls1 multiblock -cipher operation (either 4 or 8 records). -.SS "Gettable \s-1EVP_CIPHER_CTX\s0 parameters" -.IX Subsection "Gettable EVP_CIPHER_CTX parameters" -The following \s-1\fBOSSL_PARAM\s0\fR\|(3) keys can be used with \fBEVP_CIPHER_CTX_get_params()\fR: -.ie n .IP """ivlen"" (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR and <\fB\s-1OSSL_CIPHER_PARAM_AEAD_IVLEN\s0\fR) " 4 -.el .IP "``ivlen'' (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR and <\fB\s-1OSSL_CIPHER_PARAM_AEAD_IVLEN\s0\fR) " 4 -.IX Item "ivlen (OSSL_CIPHER_PARAM_IVLEN and " -Gets the \s-1IV\s0 length for the cipher context \fIctx\fR. -The length of the \*(L"ivlen\*(R" parameter should not exceed that of a \fBsize_t\fR. -See also \fBEVP_CIPHER_CTX_get_iv_length()\fR. -.ie n .IP """iv"" (\fB\s-1OSSL_CIPHER_PARAM_IV\s0\fR) " 4 -.el .IP "``iv'' (\fB\s-1OSSL_CIPHER_PARAM_IV\s0\fR) " 4 -.IX Item "iv (OSSL_CIPHER_PARAM_IV) " -Gets the \s-1IV\s0 used to initialize the associated cipher context \fIctx\fR. -See also \fBEVP_CIPHER_CTX_get_original_iv()\fR. -.ie n .IP """updated-iv"" (\fB\s-1OSSL_CIPHER_PARAM_UPDATED_IV\s0\fR) " 4 -.el .IP "``updated-iv'' (\fB\s-1OSSL_CIPHER_PARAM_UPDATED_IV\s0\fR) " 4 -.IX Item "updated-iv (OSSL_CIPHER_PARAM_UPDATED_IV) " -Gets the updated pseudo-IV state for the associated cipher context, e.g., -the previous ciphertext block for \s-1CBC\s0 mode or the iteratively encrypted \s-1IV\s0 -value for \s-1OFB\s0 mode. Note that octet pointer access is deprecated and is -provided only for backwards compatibility with historical libcrypto APIs. -See also \fBEVP_CIPHER_CTX_get_updated_iv()\fR. -.ie n .IP """randkey"" (\fB\s-1OSSL_CIPHER_PARAM_RANDOM_KEY\s0\fR) " 4 -.el .IP "``randkey'' (\fB\s-1OSSL_CIPHER_PARAM_RANDOM_KEY\s0\fR) " 4 -.IX Item "randkey (OSSL_CIPHER_PARAM_RANDOM_KEY) " -Gets an implementation specific randomly generated key for the associated -cipher context \fIctx\fR. This is currently only supported by \s-1DES\s0 and 3DES (which set -the key to odd parity). -.ie n .IP """taglen"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TAGLEN\s0\fR) " 4 -.el .IP "``taglen'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TAGLEN\s0\fR) " 4 -.IX Item "taglen (OSSL_CIPHER_PARAM_AEAD_TAGLEN) " -Gets the tag length to be used for an \s-1AEAD\s0 cipher for the associated cipher -context \fIctx\fR. It gets a default value if it has not been set. -The length of the \*(L"taglen\*(R" parameter should not exceed that of a \fBsize_t\fR. -See also \fBEVP_CIPHER_CTX_get_tag_length()\fR. -.ie n .IP """tlsaadpad"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_AAD_PAD\s0\fR) " 4 -.el .IP "``tlsaadpad'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_AAD_PAD\s0\fR) " 4 -.IX Item "tlsaadpad (OSSL_CIPHER_PARAM_AEAD_TLS1_AAD_PAD) " -Gets the length of the tag that will be added to a \s-1TLS\s0 record for the \s-1AEAD\s0 -tag for the associated cipher context \fIctx\fR. -The length of the \*(L"tlsaadpad\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """tlsivgen"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_GET_IV_GEN\s0\fR) " 4 -.el .IP "``tlsivgen'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_GET_IV_GEN\s0\fR) " 4 -.IX Item "tlsivgen (OSSL_CIPHER_PARAM_AEAD_TLS1_GET_IV_GEN) " -Gets the invocation field generated for encryption. -Can only be called after \*(L"tlsivfixed\*(R" is set. -This is only used for \s-1GCM\s0 mode. -.ie n .IP """tls1multi_enclen"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_LEN\s0\fR) " 4 -.el .IP "``tls1multi_enclen'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_LEN\s0\fR) " 4 -.IX Item "tls1multi_enclen (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_LEN) " -Get the total length of the record returned from the \*(L"tls1multi_enc\*(R" operation. -.ie n .IP """tls1multi_maxbufsz"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_BUFSIZE\s0\fR) " 4 -.el .IP "``tls1multi_maxbufsz'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_BUFSIZE\s0\fR) " 4 -.IX Item "tls1multi_maxbufsz (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_BUFSIZE) " -Gets the maximum record length for a \s-1TLS1\s0 multiblock cipher operation. -The length of the \*(L"tls1multi_maxbufsz\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """tls1multi_aadpacklen"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD_PACKLEN\s0\fR) " 4 -.el .IP "``tls1multi_aadpacklen'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD_PACKLEN\s0\fR) " 4 -.IX Item "tls1multi_aadpacklen (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD_PACKLEN) " -Gets the result of running the \*(L"tls1multi_aad\*(R" operation. -.ie n .IP """tls-mac"" (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC\s0\fR) " 4 -.el .IP "``tls-mac'' (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC\s0\fR) " 4 -.IX Item "tls-mac (OSSL_CIPHER_PARAM_TLS_MAC) " -Used to pass the \s-1TLS MAC\s0 data. -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) " -This option is used by the OpenSSL \s-1FIPS\s0 provider. -.Sp -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling a cipher final operation such as -\&\fBEVP_EncryptFinal_ex()\fR. It may return 0 if the \*(L"encrypt-check\*(R" option is set to 0. -.ie n .IP """iv-generated"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_IV_GENERATED\s0\fR) " 4 -.el .IP "``iv-generated'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_IV_GENERATED\s0\fR) " 4 -.IX Item "iv-generated (OSSL_CIPHER_PARAM_AEAD_IV_GENERATED) " -An indicator that returns 1 if an \s-1IV\s0 was generated internally during encryption, -or O otherwise. -This may be used by \s-1GCM\s0 ciphers after calling a cipher final operation such -as \fBEVP_EncryptFinal_ex()\fR. -\&\s-1GCM\s0 should generate an \s-1IV\s0 internally if the \s-1IV\s0 is not specified during a -cipher initialisation call such as \fBEVP_CipherInit_ex()\fR. -See \s-1FIPS 140\-3 IG C.H\s0 for information related to \s-1IV\s0 requirements. -.SS "Settable \s-1EVP_CIPHER_CTX\s0 parameters" -.IX Subsection "Settable EVP_CIPHER_CTX parameters" -The following \s-1\fBOSSL_PARAM\s0\fR\|(3) keys can be used with \fBEVP_CIPHER_CTX_set_params()\fR: -.ie n .IP """mackey"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_MAC_KEY\s0\fR) " 4 -.el .IP "``mackey'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_MAC_KEY\s0\fR) " 4 -.IX Item "mackey (OSSL_CIPHER_PARAM_AEAD_MAC_KEY) " -Sets the \s-1MAC\s0 key used by composite \s-1AEAD\s0 ciphers such as \s-1AES\-CBC\-HMAC\-SHA256.\s0 -.ie n .IP """speed"" (\fB\s-1OSSL_CIPHER_PARAM_SPEED\s0\fR) " 4 -.el .IP "``speed'' (\fB\s-1OSSL_CIPHER_PARAM_SPEED\s0\fR) " 4 -.IX Item "speed (OSSL_CIPHER_PARAM_SPEED) " -Sets the speed option for the associated cipher context. This is only supported -by \s-1AES SIV\s0 ciphers which disallow multiple operations by default. -Setting \*(L"speed\*(R" to 1 allows another encrypt or decrypt operation to be -performed. This is used for performance testing. -.ie n .IP """use-bits"" (\fB\s-1OSSL_CIPHER_PARAM_USE_BITS\s0\fR) " 4 -.el .IP "``use-bits'' (\fB\s-1OSSL_CIPHER_PARAM_USE_BITS\s0\fR) " 4 -.IX Item "use-bits (OSSL_CIPHER_PARAM_USE_BITS) " -Determines if the input length \fIinl\fR passed to \fBEVP_EncryptUpdate()\fR, -\&\fBEVP_DecryptUpdate()\fR and \fBEVP_CipherUpdate()\fR is the number of bits or number of bytes. -Setting \*(L"use-bits\*(R" to 1 uses bits. The default is in bytes. -This is only used for \fB\s-1CFB1\s0\fR ciphers. -.Sp -This can be set using EVP_CIPHER_CTX_set_flags(ctx, \s-1EVP_CIPH_FLAG_LENGTH_BITS\s0). -.ie n .IP """tls-version"" (\fB\s-1OSSL_CIPHER_PARAM_TLS_VERSION\s0\fR) " 4 -.el .IP "``tls-version'' (\fB\s-1OSSL_CIPHER_PARAM_TLS_VERSION\s0\fR) " 4 -.IX Item "tls-version (OSSL_CIPHER_PARAM_TLS_VERSION) " -Sets the \s-1TLS\s0 version. -.ie n .IP """tls-mac-size"" (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC_SIZE\s0\fR) " 4 -.el .IP "``tls-mac-size'' (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC_SIZE\s0\fR) " 4 -.IX Item "tls-mac-size (OSSL_CIPHER_PARAM_TLS_MAC_SIZE) " -Set the \s-1TLS MAC\s0 size. -.ie n .IP """tlsaad"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_AAD\s0\fR) " 4 -.el .IP "``tlsaad'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_AAD\s0\fR) " 4 -.IX Item "tlsaad (OSSL_CIPHER_PARAM_AEAD_TLS1_AAD) " -Sets TLSv1.2 \s-1AAD\s0 information for the associated cipher context \fIctx\fR. -TLSv1.2 \s-1AAD\s0 information is always 13 bytes in length and is as defined for the -\&\*(L"additional_data\*(R" field described in section 6.2.3.3 of \s-1RFC5246.\s0 -.ie n .IP """tlsivfixed"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_IV_FIXED\s0\fR) " 4 -.el .IP "``tlsivfixed'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_IV_FIXED\s0\fR) " 4 -.IX Item "tlsivfixed (OSSL_CIPHER_PARAM_AEAD_TLS1_IV_FIXED) " -Sets the fixed portion of an \s-1IV\s0 for an \s-1AEAD\s0 cipher used in a \s-1TLS\s0 record -encryption/ decryption for the associated cipher context. -\&\s-1TLS\s0 record encryption/decryption always occurs \*(L"in place\*(R" so that the input and -output buffers are always the same memory location. -\&\s-1AEAD\s0 IVs in TLSv1.2 consist of an implicit \*(L"fixed\*(R" part and an explicit part -that varies with every record. -Setting a \s-1TLS\s0 fixed \s-1IV\s0 changes a cipher to encrypt/decrypt \s-1TLS\s0 records. -\&\s-1TLS\s0 records are encrypted/decrypted using a single OSSL_FUNC_cipher_cipher call per -record. -For a record decryption the first bytes of the input buffer will be the explicit -part of the \s-1IV\s0 and the final bytes of the input buffer will be the \s-1AEAD\s0 tag. -The length of the explicit part of the \s-1IV\s0 and the tag length will depend on the -cipher in use and will be defined in the \s-1RFC\s0 for the relevant ciphersuite. -In order to allow for \*(L"in place\*(R" decryption the plaintext output should be -written to the same location in the output buffer that the ciphertext payload -was read from, i.e. immediately after the explicit \s-1IV.\s0 -.Sp -When encrypting a record the first bytes of the input buffer should be empty to -allow space for the explicit \s-1IV,\s0 as will the final bytes where the tag will -be written. -The length of the input buffer will include the length of the explicit \s-1IV,\s0 the -payload, and the tag bytes. -The cipher implementation should generate the explicit \s-1IV\s0 and write it to the -beginning of the output buffer, do \*(L"in place\*(R" encryption of the payload and -write that to the output buffer, and finally add the tag onto the end of the -output buffer. -.Sp -Whether encrypting or decrypting the value written to \fI*outl\fR in the -OSSL_FUNC_cipher_cipher call should be the length of the payload excluding the explicit -\&\s-1IV\s0 length and the tag length. -.ie n .IP """tlsivinv"" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_SET_IV_INV\s0\fR) " 4 -.el .IP "``tlsivinv'' (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_SET_IV_INV\s0\fR) " 4 -.IX Item "tlsivinv (OSSL_CIPHER_PARAM_AEAD_TLS1_SET_IV_INV) " -Sets the invocation field used for decryption. -Can only be called after \*(L"tlsivfixed\*(R" is set. -This is only used for \s-1GCM\s0 mode. -.ie n .IP """tls1multi_enc"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC\s0\fR) " 4 -.el .IP "``tls1multi_enc'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC\s0\fR) " 4 -.IX Item "tls1multi_enc (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC) " -Triggers a multiblock \s-1TLS1\s0 encrypt operation for a \s-1TLS1\s0 aware cipher that -supports sending 4 or 8 records in one go. -The cipher performs both the \s-1MAC\s0 and encrypt stages and constructs the record -headers itself. -\&\*(L"tls1multi_enc\*(R" supplies the output buffer for the encrypt operation, -\&\*(L"tls1multi_encin\*(R" & \*(L"tls1multi_interleave\*(R" must also be set in order to supply -values to the encrypt operation. -.ie n .IP """tls1multi_encin"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_IN\s0\fR) " 4 -.el .IP "``tls1multi_encin'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_IN\s0\fR) " 4 -.IX Item "tls1multi_encin (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_IN) " -Supplies the data to encrypt for a \s-1TLS1\s0 multiblock cipher operation. -.ie n .IP """tls1multi_maxsndfrag"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_SEND_FRAGMENT\s0\fR) " 4 -.el .IP "``tls1multi_maxsndfrag'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_SEND_FRAGMENT\s0\fR) " 4 -.IX Item "tls1multi_maxsndfrag (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_SEND_FRAGMENT) " -Sets the maximum send fragment size for a \s-1TLS1\s0 multiblock cipher operation. -It must be set before using \*(L"tls1multi_maxbufsz\*(R". -The length of the \*(L"tls1multi_maxsndfrag\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """tls1multi_aad"" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD\s0\fR) " 4 -.el .IP "``tls1multi_aad'' (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD\s0\fR) " 4 -.IX Item "tls1multi_aad (OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD) " -Sets the authenticated additional data used by a \s-1TLS1\s0 multiblock cipher operation. -The supplied data consists of 13 bytes of record data containing: -Bytes 0\-7: The sequence number of the first record -Byte 8: The record type -Byte 9\-10: The protocol version -Byte 11\-12: Input length (Always 0) -.Sp -\&\*(L"tls1multi_interleave\*(R" must also be set for this operation. -.ie n .IP """xts_standard"" (\fB\s-1OSSL_CIPHER_PARAM_XTS_STANDARD\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``xts_standard'' (\fB\s-1OSSL_CIPHER_PARAM_XTS_STANDARD\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "xts_standard (OSSL_CIPHER_PARAM_XTS_STANDARD) " -Sets the \s-1XTS\s0 standard to use with \s-1SM4\-XTS\s0 algorithm. \s-1XTS\s0 mode has two -implementations, one is standardized in \s-1IEEE\s0 Std. 1619\-2007 and has -been widely used (e.g., \s-1XTS AES\s0), the other is proposed recently -(\s-1GB/T 17964\-2021\s0 implemented in May 2022) and is currently only used -in \s-1SM4.\s0 -.Sp -The main difference between them is the multiplication by the -primitive element X to calculate the tweak values. The \s-1IEEE\s0 -Std 1619\-2007 noted that the multiplication \*(L"is a left shift of each -byte by one bit with carry propagating from one byte to the next -one\*(R", which means that in each byte, the leftmost bit is the most -significant bit. But in \s-1GB/T 17964\-2021,\s0 the rightmost bit is the -most significant bit, thus the multiplication becomes a right shift -of each byte by one bit with carry propagating from one byte to the -next one. -.Sp -Valid values for the mode are: -.RS 4 -.ie n .IP """\s-1GB""\s0" 4 -.el .IP "``\s-1GB''\s0" 4 -.IX Item "GB" -The \s-1GB/T 17964\-2021\s0 variant of \s-1SM4\-XTS\s0 algorithm. -.ie n .IP """\s-1IEEE""\s0" 4 -.el .IP "``\s-1IEEE''\s0" 4 -.IX Item "IEEE" -The \s-1IEEE\s0 Std. 1619\-2007 variant of \s-1SM4\-XTS\s0 algorithm. -.RE -.RS 4 -.Sp -The default value is \*(L"\s-1GB\*(R".\s0 -.RE -.ie n .IP """encrypt-check"" (\fB\s-1OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK\s0\fR) " 4 -.el .IP "``encrypt-check'' (\fB\s-1OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK\s0\fR) " 4 -.IX Item "encrypt-check (OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK) " -This option is used by the OpenSSL \s-1FIPS\s0 provider. -.Sp -If required this parameter should be set early via an cipher encrypt init -function such as \fBEVP_EncryptInit_ex2()\fR. -The default value of 1 causes an error when an encryption operation is triggered. -Setting this to 0 will ignore the error and set the approved \*(L"fips-indicator\*(R" to -0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "CONTROLS" -.IX Header "CONTROLS" -The Mappings from \fBEVP_CIPHER_CTX_ctrl()\fR identifiers to \s-1PARAMETERS\s0 are listed -in the following section. See the \*(L"\s-1PARAMETERS\*(R"\s0 section for more details. -.PP -\&\fBEVP_CIPHER_CTX_ctrl()\fR can be used to send the following standard controls: -.IP "\s-1EVP_CTRL_AEAD_SET_IVLEN\s0 and \s-1EVP_CTRL_GET_IVLEN\s0" 4 -.IX Item "EVP_CTRL_AEAD_SET_IVLEN and EVP_CTRL_GET_IVLEN" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR and -\&\fBEVP_CIPHER_CTX_get_params()\fR get called with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the -key \*(L"ivlen\*(R" (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR). -.IP "\s-1EVP_CTRL_AEAD_SET_IV_FIXED\s0" 4 -.IX Item "EVP_CTRL_AEAD_SET_IV_FIXED" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"tlsivfixed\*(R" -(\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_IV_FIXED\s0\fR). -.IP "\s-1EVP_CTRL_AEAD_SET_MAC_KEY\s0" 4 -.IX Item "EVP_CTRL_AEAD_SET_MAC_KEY" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"mackey\*(R" -(\fB\s-1OSSL_CIPHER_PARAM_AEAD_MAC_KEY\s0\fR). -.IP "\s-1EVP_CTRL_AEAD_SET_TAG\s0 and \s-1EVP_CTRL_AEAD_GET_TAG\s0" 4 -.IX Item "EVP_CTRL_AEAD_SET_TAG and EVP_CTRL_AEAD_GET_TAG" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR and -\&\fBEVP_CIPHER_CTX_get_params()\fR get called with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the -key \*(L"tag\*(R" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TAG\s0\fR). -.IP "\s-1EVP_CTRL_CCM_SET_L\s0" 4 -.IX Item "EVP_CTRL_CCM_SET_L" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"ivlen\*(R" (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR) -with a value of (15 \- L) -.IP "\s-1EVP_CTRL_COPY\s0" 4 -.IX Item "EVP_CTRL_COPY" -There is no \s-1OSSL_PARAM\s0 mapping for this. Use \fBEVP_CIPHER_CTX_copy()\fR instead. -.IP "\s-1EVP_CTRL_GCM_SET_IV_INV\s0" 4 -.IX Item "EVP_CTRL_GCM_SET_IV_INV" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"tlsivinv\*(R" -(\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_SET_IV_INV\s0\fR). -.IP "\s-1EVP_CTRL_RAND_KEY\s0" 4 -.IX Item "EVP_CTRL_RAND_KEY" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"randkey\*(R" -(\fB\s-1OSSL_CIPHER_PARAM_RANDOM_KEY\s0\fR). -.IP "\s-1EVP_CTRL_SET_KEY_LENGTH\s0" 4 -.IX Item "EVP_CTRL_SET_KEY_LENGTH" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"keylen\*(R" (\fB\s-1OSSL_CIPHER_PARAM_KEYLEN\s0\fR). -.IP "\s-1EVP_CTRL_SET_RC2_KEY_BITS\s0 and \s-1EVP_CTRL_GET_RC2_KEY_BITS\s0" 4 -.IX Item "EVP_CTRL_SET_RC2_KEY_BITS and EVP_CTRL_GET_RC2_KEY_BITS" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR and -\&\fBEVP_CIPHER_CTX_get_params()\fR get called with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the -key \*(L"keybits\*(R" (\fB\s-1OSSL_CIPHER_PARAM_RC2_KEYBITS\s0\fR). -.IP "\s-1EVP_CTRL_SET_RC5_ROUNDS\s0 and \s-1EVP_CTRL_GET_RC5_ROUNDS\s0" 4 -.IX Item "EVP_CTRL_SET_RC5_ROUNDS and EVP_CTRL_GET_RC5_ROUNDS" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR and -\&\fBEVP_CIPHER_CTX_get_params()\fR get called with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the -key \*(L"rounds\*(R" (\fB\s-1OSSL_CIPHER_PARAM_ROUNDS\s0\fR). -.IP "\s-1EVP_CTRL_SET_SPEED\s0" 4 -.IX Item "EVP_CTRL_SET_SPEED" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key \*(L"speed\*(R" (\fB\s-1OSSL_CIPHER_PARAM_SPEED\s0\fR). -.IP "\s-1EVP_CTRL_GCM_IV_GEN\s0" 4 -.IX Item "EVP_CTRL_GCM_IV_GEN" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_get_params()\fR gets called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key -\&\*(L"tlsivgen\*(R" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_GET_IV_GEN\s0\fR). -.IP "\s-1EVP_CTRL_AEAD_TLS1_AAD\s0" 4 -.IX Item "EVP_CTRL_AEAD_TLS1_AAD" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR get called -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the key -\&\*(L"tlsaad\*(R" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_AAD\s0\fR) -followed by \fBEVP_CIPHER_CTX_get_params()\fR with a key of -\&\*(L"tlsaadpad\*(R" (\fB\s-1OSSL_CIPHER_PARAM_AEAD_TLS1_AAD_PAD\s0\fR). -.IP "\s-1EVP_CTRL_TLS1_1_MULTIBLOCK_MAX_BUFSIZE\s0" 4 -.IX Item "EVP_CTRL_TLS1_1_MULTIBLOCK_MAX_BUFSIZE" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, -\&\fBEVP_CIPHER_CTX_set_params()\fR gets called with an \s-1\fBOSSL_PARAM\s0\fR\|(3) item with the -key \s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_SEND_FRAGMENT\s0 -followed by \fBEVP_CIPHER_CTX_get_params()\fR with a key of -\&\*(L"tls1multi_maxbufsz\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_MAX_BUFSIZE\s0\fR). -.IP "\s-1EVP_CTRL_TLS1_1_MULTIBLOCK_AAD\s0" 4 -.IX Item "EVP_CTRL_TLS1_1_MULTIBLOCK_AAD" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with \s-1\fBOSSL_PARAM\s0\fR\|(3) items with the keys -\&\*(L"tls1multi_aad\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD\s0\fR) and -\&\*(L"tls1multi_interleave\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE\s0\fR) -followed by \fBEVP_CIPHER_CTX_get_params()\fR with keys of -\&\*(L"tls1multi_aadpacklen\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_AAD_PACKLEN\s0\fR) and -\&\*(L"tls1multi_interleave\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE\s0\fR). -.IP "\s-1EVP_CTRL_TLS1_1_MULTIBLOCK_ENCRYPT\s0" 4 -.IX Item "EVP_CTRL_TLS1_1_MULTIBLOCK_ENCRYPT" -When used with a fetched \fB\s-1EVP_CIPHER\s0\fR, \fBEVP_CIPHER_CTX_set_params()\fR gets called -with \s-1\fBOSSL_PARAM\s0\fR\|(3) items with the keys -\&\*(L"tls1multi_enc\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC\s0\fR), -\&\*(L"tls1multi_encin\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_IN\s0\fR) and -\&\*(L"tls1multi_interleave\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_INTERLEAVE\s0\fR), -followed by \fBEVP_CIPHER_CTX_get_params()\fR with a key of -\&\*(L"tls1multi_enclen\*(R" (\fB\s-1OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK_ENC_LEN\s0\fR). -.SH "FLAGS" -.IX Header "FLAGS" -\&\fBEVP_CIPHER_CTX_set_flags()\fR, \fBEVP_CIPHER_CTX_clear_flags()\fR and \fBEVP_CIPHER_CTX_test_flags()\fR. -can be used to manipulate and test these \fB\s-1EVP_CIPHER_CTX\s0\fR flags: -.IP "\s-1EVP_CIPH_NO_PADDING\s0" 4 -.IX Item "EVP_CIPH_NO_PADDING" -Used by \fBEVP_CIPHER_CTX_set_padding()\fR. -.Sp -See also \*(L"Gettable and Settable \s-1EVP_CIPHER_CTX\s0 parameters\*(R" \*(L"padding\*(R" -.IP "\s-1EVP_CIPH_FLAG_LENGTH_BITS\s0" 4 -.IX Item "EVP_CIPH_FLAG_LENGTH_BITS" -See \*(L"Settable \s-1EVP_CIPHER_CTX\s0 parameters\*(R" \*(L"use-bits\*(R". -.IP "\s-1EVP_CIPHER_CTX_FLAG_WRAP_ALLOW\s0" 4 -.IX Item "EVP_CIPHER_CTX_FLAG_WRAP_ALLOW" -Used for Legacy purposes only. This flag needed to be set to indicate the -cipher handled wrapping. -.PP -\&\fBEVP_CIPHER_flags()\fR uses the following flags that -have mappings to \*(L"Gettable \s-1EVP_CIPHER\s0 parameters\*(R": -.IP "\s-1EVP_CIPH_FLAG_AEAD_CIPHER\s0" 4 -.IX Item "EVP_CIPH_FLAG_AEAD_CIPHER" -See \*(L"Gettable \s-1EVP_CIPHER\s0 parameters\*(R" \*(L"aead\*(R". -.IP "\s-1EVP_CIPH_CUSTOM_IV\s0" 4 -.IX Item "EVP_CIPH_CUSTOM_IV" -See \*(L"Gettable \s-1EVP_CIPHER\s0 parameters\*(R" \*(L"custom-iv\*(R". -.IP "\s-1EVP_CIPH_FLAG_CTS\s0" 4 -.IX Item "EVP_CIPH_FLAG_CTS" -See \*(L"Gettable \s-1EVP_CIPHER\s0 parameters\*(R" \*(L"cts\*(R". -.IP "\s-1EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK\s0;" 4 -.IX Item "EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK;" -See \*(L"Gettable \s-1EVP_CIPHER\s0 parameters\*(R" \*(L"tls-multi\*(R". -.IP "\s-1EVP_CIPH_RAND_KEY\s0" 4 -.IX Item "EVP_CIPH_RAND_KEY" -See \*(L"Gettable \s-1EVP_CIPHER\s0 parameters\*(R" \*(L"has-randkey\*(R". -.PP -\&\fBEVP_CIPHER_flags()\fR uses the following flags for legacy purposes only: -.IP "\s-1EVP_CIPH_VARIABLE_LENGTH\s0" 4 -.IX Item "EVP_CIPH_VARIABLE_LENGTH" -.PD 0 -.IP "\s-1EVP_CIPH_FLAG_CUSTOM_CIPHER\s0" 4 -.IX Item "EVP_CIPH_FLAG_CUSTOM_CIPHER" -.IP "\s-1EVP_CIPH_ALWAYS_CALL_INIT\s0" 4 -.IX Item "EVP_CIPH_ALWAYS_CALL_INIT" -.IP "\s-1EVP_CIPH_CTRL_INIT\s0" 4 -.IX Item "EVP_CIPH_CTRL_INIT" -.IP "\s-1EVP_CIPH_CUSTOM_KEY_LENGTH\s0" 4 -.IX Item "EVP_CIPH_CUSTOM_KEY_LENGTH" -.IP "\s-1EVP_CIPH_CUSTOM_COPY\s0" 4 -.IX Item "EVP_CIPH_CUSTOM_COPY" -.IP "\s-1EVP_CIPH_FLAG_DEFAULT_ASN1\s0" 4 -.IX Item "EVP_CIPH_FLAG_DEFAULT_ASN1" -.PD -See \fBEVP_CIPHER_meth_set_flags\fR\|(3) for further information related to the above -flags. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_CIPHER_fetch()\fR returns a pointer to a \fB\s-1EVP_CIPHER\s0\fR for success -and \fB\s-1NULL\s0\fR for failure. -.PP -\&\fBEVP_CIPHER_up_ref()\fR returns 1 for success or 0 otherwise. -.PP -\&\fBEVP_CIPHER_CTX_new()\fR returns a pointer to a newly created -\&\fB\s-1EVP_CIPHER_CTX\s0\fR for success and \fB\s-1NULL\s0\fR for failure. -.PP -\&\fBEVP_CIPHER_CTX_dup()\fR returns a new \s-1EVP_CIPHER_CTX\s0 if successful or \s-1NULL\s0 on failure. -.PP -\&\fBEVP_CIPHER_CTX_copy()\fR returns 1 if successful or 0 for failure. -.PP -\&\fBEVP_EncryptInit_ex2()\fR, \fBEVP_EncryptUpdate()\fR and \fBEVP_EncryptFinal_ex()\fR -return 1 for success and 0 for failure. -.PP -\&\fBEVP_DecryptInit_ex2()\fR and \fBEVP_DecryptUpdate()\fR return 1 for success and 0 for failure. -\&\fBEVP_DecryptFinal_ex()\fR returns 0 if the decrypt failed or 1 for success. -.PP -\&\fBEVP_CipherInit_ex2()\fR and \fBEVP_CipherUpdate()\fR return 1 for success and 0 for -failure. -\&\fBEVP_CipherFinal_ex()\fR returns 0 for an encryption/decryption failure or 1 for -success. -.PP -\&\fBEVP_Cipher()\fR returns 1 on success and <= 0 on failure, if the flag -\&\fB\s-1EVP_CIPH_FLAG_CUSTOM_CIPHER\s0\fR is not set for the cipher, or if the cipher has -not been initialized via a call to \fBEVP_CipherInit_ex2\fR. -\&\fBEVP_Cipher()\fR returns the number of bytes written to \fIout\fR for -encryption/decryption, or the number of bytes authenticated in a call specifying -\&\s-1AAD\s0 for an \s-1AEAD\s0 cipher, if the flag \fB\s-1EVP_CIPH_FLAG_CUSTOM_CIPHER\s0\fR is set for -the cipher. -.PP -\&\fBEVP_CIPHER_CTX_reset()\fR returns 1 for success and 0 for failure. -.PP -\&\fBEVP_get_cipherbyname()\fR, \fBEVP_get_cipherbynid()\fR and \fBEVP_get_cipherbyobj()\fR -return an \fB\s-1EVP_CIPHER\s0\fR structure or \s-1NULL\s0 on error. -.PP -\&\fBEVP_CIPHER_get_nid()\fR and \fBEVP_CIPHER_CTX_get_nid()\fR return a \s-1NID.\s0 -.PP -\&\fBEVP_CIPHER_get_block_size()\fR and \fBEVP_CIPHER_CTX_get_block_size()\fR return the -block size, or 0 on error. -.PP -\&\fBEVP_CIPHER_get_key_length()\fR and \fBEVP_CIPHER_CTX_get_key_length()\fR return the key -length. -.PP -\&\fBEVP_CIPHER_CTX_set_padding()\fR always returns 1. -.PP -\&\fBEVP_CIPHER_get_iv_length()\fR and \fBEVP_CIPHER_CTX_get_iv_length()\fR return the \s-1IV\s0 -length, zero if the cipher does not use an \s-1IV\s0 and a negative value on error. -.PP -\&\fBEVP_CIPHER_CTX_get_tag_length()\fR return the tag length or zero if the cipher -does not use a tag. -.PP -\&\fBEVP_CIPHER_get_type()\fR and \fBEVP_CIPHER_CTX_get_type()\fR return the \s-1NID\s0 of the -cipher's \s-1OBJECT IDENTIFIER\s0 or NID_undef if it has no defined -\&\s-1OBJECT IDENTIFIER.\s0 -.PP -\&\fBEVP_CIPHER_CTX_cipher()\fR returns an \fB\s-1EVP_CIPHER\s0\fR structure. -.PP -\&\fBEVP_CIPHER_CTX_get_num()\fR returns a nonnegative num value or -\&\fB\s-1EVP_CTRL_RET_UNSUPPORTED\s0\fR if the implementation does not support the call -or on any other error. -.PP -\&\fBEVP_CIPHER_CTX_set_num()\fR returns 1 on success and 0 if the implementation -does not support the call or on any other error. -.PP -\&\fBEVP_CIPHER_CTX_is_encrypting()\fR returns 1 if the \fIctx\fR is set up for encryption -0 otherwise. -.PP -\&\fBEVP_CIPHER_param_to_asn1()\fR and \fBEVP_CIPHER_asn1_to_param()\fR return greater -than zero for success and zero or a negative number on failure. -.PP -\&\fBEVP_CIPHER_CTX_rand_key()\fR returns 1 for success and zero or a negative number -for failure. -.PP -\&\fBEVP_CIPHER_names_do_all()\fR returns 1 if the callback was called for all names. -A return value of 0 means that the callback was not called for any names. -.SH "CIPHER LISTING" -.IX Header "CIPHER LISTING" -All algorithms have a fixed key length unless otherwise stated. -.PP -Refer to \*(L"\s-1SEE ALSO\*(R"\s0 for the full list of ciphers available through the \s-1EVP\s0 -interface. -.IP "\fBEVP_enc_null()\fR" 4 -.IX Item "EVP_enc_null()" -Null cipher: does nothing. -.SH "AEAD INTERFACE" -.IX Header "AEAD INTERFACE" -The \s-1EVP\s0 interface for Authenticated Encryption with Associated Data (\s-1AEAD\s0) -modes are subtly altered and several additional \fIctrl\fR operations are supported -depending on the mode specified. -.PP -To specify additional authenticated data (\s-1AAD\s0), a call to \fBEVP_CipherUpdate()\fR, -\&\fBEVP_EncryptUpdate()\fR or \fBEVP_DecryptUpdate()\fR should be made with the output -parameter \fIout\fR set to \fB\s-1NULL\s0\fR. In this case, on success, the parameter -\&\fIoutl\fR is set to the number of bytes authenticated. -.PP -When decrypting, the return value of \fBEVP_DecryptFinal()\fR or \fBEVP_CipherFinal()\fR -indicates whether the operation was successful. If it does not indicate success, -the authentication operation has failed and any output data \fB\s-1MUST NOT\s0\fR be used -as it is corrupted. -.PP -Please note that the number of authenticated bytes returned by -\&\fBEVP_CipherUpdate()\fR depends on the cipher used. Stream ciphers, such as ChaCha20 -or ciphers in \s-1GCM\s0 mode, can handle 1 byte at a time, resulting in an effective -\&\*(L"block\*(R" size of 1. Conversely, ciphers in \s-1OCB\s0 mode must process data one block -at a time, and the block size is returned. -.PP -Regardless of the returned size, it is safe to pass unpadded data to an -\&\fBEVP_CipherUpdate()\fR call in a single operation. -.SS "\s-1GCM\s0 and \s-1OCB\s0 Modes" -.IX Subsection "GCM and OCB Modes" -The following \fIctrl\fRs are supported in \s-1GCM\s0 and \s-1OCB\s0 modes. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_SET_IVLEN,\s0 ivlen, \s-1NULL\s0)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, ivlen, NULL)" -Sets the \s-1IV\s0 length. This call can only be made before specifying an \s-1IV.\s0 If -not called a default \s-1IV\s0 length is used. -.Sp -For \s-1GCM AES\s0 and \s-1OCB AES\s0 the default is 12 (i.e. 96 bits). For \s-1OCB\s0 mode the -maximum is 15. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_GET_TAG,\s0 taglen, tag)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, taglen, tag)" -Writes \f(CW\*(C`taglen\*(C'\fR bytes of the tag value to the buffer indicated by \f(CW\*(C`tag\*(C'\fR. -This call can only be made when encrypting data and \fBafter\fR all data has been -processed (e.g. after an \fBEVP_EncryptFinal()\fR call). -.Sp -For \s-1OCB,\s0 \f(CW\*(C`taglen\*(C'\fR must either be 16 or the value previously set via -\&\fB\s-1EVP_CTRL_AEAD_SET_TAG\s0\fR. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_SET_TAG,\s0 taglen, tag)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag)" -When decrypting, this call sets the expected tag to \f(CW\*(C`taglen\*(C'\fR bytes from \f(CW\*(C`tag\*(C'\fR. -\&\f(CW\*(C`taglen\*(C'\fR must be between 1 and 16 inclusive. -The tag must be set prior to any call to \fBEVP_DecryptFinal()\fR or -\&\fBEVP_DecryptFinal_ex()\fR. -.Sp -For \s-1GCM,\s0 this call is only valid when decrypting data. -.Sp -For \s-1OCB,\s0 this call is valid when decrypting data to set the expected tag, -and when encrypting to set the desired tag length. -.Sp -In \s-1OCB\s0 mode, calling this with \f(CW\*(C`tag\*(C'\fR set to \f(CW\*(C`NULL\*(C'\fR sets the tag length. -The tag length can only be set before specifying an \s-1IV.\s0 If this is not called -prior to setting the \s-1IV,\s0 then a default tag length is used. -.Sp -For \s-1OCB AES,\s0 the default tag length is 16 (i.e. 128 bits). It is also the -maximum tag length for \s-1OCB.\s0 -.SS "\s-1CCM\s0 Mode" -.IX Subsection "CCM Mode" -The \s-1EVP\s0 interface for \s-1CCM\s0 mode is similar to that of the \s-1GCM\s0 mode but with a -few additional requirements and different \fIctrl\fR values. -.PP -For \s-1CCM\s0 mode, the total plaintext or ciphertext length \fB\s-1MUST\s0\fR be passed to -\&\fBEVP_CipherUpdate()\fR, \fBEVP_EncryptUpdate()\fR or \fBEVP_DecryptUpdate()\fR with the output -and input parameters (\fIin\fR and \fIout\fR) set to \fB\s-1NULL\s0\fR and the length passed in -the \fIinl\fR parameter. -.PP -The following \fIctrl\fRs are supported in \s-1CCM\s0 mode. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_SET_TAG,\s0 taglen, tag)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag)" -This call is made to set the expected \fB\s-1CCM\s0\fR tag value when decrypting or -the length of the tag (with the \f(CW\*(C`tag\*(C'\fR parameter set to \s-1NULL\s0) when encrypting. -The tag length is often referred to as \fBM\fR. If not set a default value is -used (12 for \s-1AES\s0). When decrypting, the tag needs to be set before passing -in data to be decrypted, but as in \s-1GCM\s0 and \s-1OCB\s0 mode, it can be set after -passing additional authenticated data (see \*(L"\s-1AEAD INTERFACE\*(R"\s0). -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_CCM_SET_L,\s0 ivlen, \s-1NULL\s0)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_CCM_SET_L, ivlen, NULL)" -Sets the \s-1CCM\s0 \fBL\fR value. If not set a default is used (8 for \s-1AES\s0). -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_SET_IVLEN,\s0 ivlen, \s-1NULL\s0)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, ivlen, NULL)" -Sets the \s-1CCM\s0 nonce (\s-1IV\s0) length. This call can only be made before specifying a -nonce value. The nonce length is given by \fB15 \- L\fR so it is 7 by default for -\&\s-1AES.\s0 -.SS "\s-1SIV\s0 Mode" -.IX Subsection "SIV Mode" -Both the AES-SIV and AES-GCM-SIV ciphers fall under this mode. -.PP -For \s-1SIV\s0 mode ciphers the behaviour of the \s-1EVP\s0 interface is subtly -altered and several additional ctrl operations are supported. -.PP -To specify any additional authenticated data (\s-1AAD\s0) and/or a Nonce, a call to -\&\fBEVP_CipherUpdate()\fR, \fBEVP_EncryptUpdate()\fR or \fBEVP_DecryptUpdate()\fR should be made -with the output parameter \fIout\fR set to \fB\s-1NULL\s0\fR. -.PP -\&\s-1RFC5297\s0 states that the Nonce is the last piece of \s-1AAD\s0 before the actual -encrypt/decrypt takes place. The \s-1API\s0 does not differentiate the Nonce from -other \s-1AAD.\s0 -.PP -When decrypting the return value of \fBEVP_DecryptFinal()\fR or \fBEVP_CipherFinal()\fR -indicates if the operation was successful. If it does not indicate success -the authentication operation has failed and any output data \fB\s-1MUST NOT\s0\fR -be used as it is corrupted. -.PP -The \s-1API\s0 does not store the \s-1SIV\s0 (Synthetic Initialization Vector) in -the cipher text. Instead, it is stored as the tag within the \s-1EVP_CIPHER_CTX.\s0 -The \s-1SIV\s0 must be retrieved from the context after encryption, and set into -the context before decryption. -.PP -This differs from \s-1RFC5297\s0 in that the cipher output from encryption, and -the cipher input to decryption, does not contain the \s-1SIV.\s0 This also means -that the plain text and cipher text lengths are identical. -.PP -The following ctrls are supported in \s-1SIV\s0 mode, and are used to get and set -the Synthetic Initialization Vector: -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_GET_TAG,\s0 taglen, tag);" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, taglen, tag);" -Writes \fItaglen\fR bytes of the tag value (the Synthetic Initialization Vector) -to the buffer indicated by \fItag\fR. This call can only be made when encrypting -data and \fBafter\fR all data has been processed (e.g. after an \fBEVP_EncryptFinal()\fR -call). For \s-1SIV\s0 mode the taglen must be 16. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_SET_TAG,\s0 taglen, tag);" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag);" -Sets the expected tag (the Synthetic Initialization Vector) to \fItaglen\fR -bytes from \fItag\fR. This call is only legal when decrypting data and must be -made \fBbefore\fR any data is processed (e.g. before any \fBEVP_DecryptUpdate()\fR -calls). For \s-1SIV\s0 mode the taglen must be 16. -.PP -\&\s-1SIV\s0 mode makes two passes over the input data, thus, only one call to -\&\fBEVP_CipherUpdate()\fR, \fBEVP_EncryptUpdate()\fR or \fBEVP_DecryptUpdate()\fR should be made -with \fIout\fR set to a non\-\fB\s-1NULL\s0\fR value. A call to \fBEVP_DecryptFinal()\fR or -\&\fBEVP_CipherFinal()\fR is not required, but will indicate if the update -operation succeeded. -.SS "ChaCha20\-Poly1305" -.IX Subsection "ChaCha20-Poly1305" -The following \fIctrl\fRs are supported for the ChaCha20\-Poly1305 \s-1AEAD\s0 algorithm. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_SET_IVLEN,\s0 ivlen, \s-1NULL\s0)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, ivlen, NULL)" -Sets the nonce length. This call is now redundant since the only valid value -is the default length of 12 (i.e. 96 bits). -Prior to OpenSSL 3.0 a nonce of less than 12 bytes could be used to automatically -pad the iv with leading 0 bytes to make it 12 bytes in length. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_GET_TAG,\s0 taglen, tag)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, taglen, tag)" -Writes \f(CW\*(C`taglen\*(C'\fR bytes of the tag value to the buffer indicated by \f(CW\*(C`tag\*(C'\fR. -This call can only be made when encrypting data and \fBafter\fR all data has been -processed (e.g. after an \fBEVP_EncryptFinal()\fR call). -.Sp -\&\f(CW\*(C`taglen\*(C'\fR specified here must be 16 (\fB\s-1POLY1305_BLOCK_SIZE\s0\fR, i.e. 128\-bits) or -less. -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_AEAD_SET_TAG,\s0 taglen, tag)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, taglen, tag)" -Sets the expected tag to \f(CW\*(C`taglen\*(C'\fR bytes from \f(CW\*(C`tag\*(C'\fR. -The tag length can only be set before specifying an \s-1IV.\s0 -\&\f(CW\*(C`taglen\*(C'\fR must be between 1 and 16 (\fB\s-1POLY1305_BLOCK_SIZE\s0\fR) inclusive. -This call is only valid when decrypting data. -.SH "NOTES" -.IX Header "NOTES" -Where possible the \fB\s-1EVP\s0\fR interface to symmetric ciphers should be used in -preference to the low-level interfaces. This is because the code then becomes -transparent to the cipher used and much more flexible. Additionally, the -\&\fB\s-1EVP\s0\fR interface will ensure the use of platform specific cryptographic -acceleration such as AES-NI (the low-level interfaces do not provide the -guarantee). -.PP -\&\s-1PKCS\s0 padding works by adding \fBn\fR padding bytes of value \fBn\fR to make the total -length of the encrypted data a multiple of the block size. Padding is always -added so if the data is already a multiple of the block size \fBn\fR will equal -the block size. For example if the block size is 8 and 11 bytes are to be -encrypted then 5 padding bytes of value 5 will be added. -.PP -When decrypting the final block is checked to see if it has the correct form. -.PP -Although the decryption operation can produce an error if padding is enabled, -it is not a strong test that the input data or key is correct. A random block -has better than 1 in 256 chance of being of the correct format and problems with -the input data earlier on will not produce a final decrypt error. -.PP -If padding is disabled then the decryption operation will always succeed if -the total amount of data decrypted is a multiple of the block size. -.PP -The functions \fBEVP_EncryptInit()\fR, \fBEVP_EncryptInit_ex()\fR, -\&\fBEVP_EncryptFinal()\fR, \fBEVP_DecryptInit()\fR, \fBEVP_DecryptInit_ex()\fR, -\&\fBEVP_CipherInit()\fR, \fBEVP_CipherInit_ex()\fR and \fBEVP_CipherFinal()\fR are obsolete -but are retained for compatibility with existing code. New code should -use \fBEVP_EncryptInit_ex2()\fR, \fBEVP_EncryptFinal_ex()\fR, \fBEVP_DecryptInit_ex2()\fR, -\&\fBEVP_DecryptFinal_ex()\fR, \fBEVP_CipherInit_ex2()\fR and \fBEVP_CipherFinal_ex()\fR -because they can reuse an existing context without allocating and freeing -it up on each call. -.PP -There are some differences between functions \fBEVP_CipherInit()\fR and -\&\fBEVP_CipherInit_ex()\fR, significant in some circumstances. \fBEVP_CipherInit()\fR fills -the passed context object with zeros. As a consequence, \fBEVP_CipherInit()\fR does -not allow step-by-step initialization of the ctx when the \fIkey\fR and \fIiv\fR are -passed in separate calls. It also means that the flags set for the \s-1CTX\s0 are -removed, and it is especially important for the -\&\fB\s-1EVP_CIPHER_CTX_FLAG_WRAP_ALLOW\s0\fR flag treated specially in -\&\fBEVP_CipherInit_ex()\fR. -.PP -Ignoring failure returns of the \fB\s-1EVP_CIPHER_CTX\s0\fR initialization functions can -lead to subsequent undefined behavior when calling the functions that update or -finalize the context. The only valid calls on the \fB\s-1EVP_CIPHER_CTX\s0\fR when -initialization fails are calls that attempt another initialization of the -context or release the context. -.PP -\&\fBEVP_get_cipherbynid()\fR, and \fBEVP_get_cipherbyobj()\fR are implemented as macros. -.SH "BUGS" -.IX Header "BUGS" -\&\fB\s-1EVP_MAX_KEY_LENGTH\s0\fR and \fB\s-1EVP_MAX_IV_LENGTH\s0\fR only refer to the internal -ciphers with default key lengths. If custom ciphers exceed these values the -results are unpredictable. This is because it has become standard practice to -define a generic key as a fixed unsigned char array containing -\&\fB\s-1EVP_MAX_KEY_LENGTH\s0\fR bytes. -.PP -The \s-1ASN1\s0 code is incomplete (and sometimes inaccurate) it has only been tested -for certain common S/MIME ciphers (\s-1RC2, DES,\s0 triple \s-1DES\s0) in \s-1CBC\s0 mode. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Encrypt a string using \s-1IDEA:\s0 -.PP -.Vb 10 -\& int do_crypt(char *outfile) -\& { -\& unsigned char outbuf[1024]; -\& int outlen, tmplen; -\& /* -\& * Bogus key and IV: we\*(Aqd normally set these from -\& * another source. -\& */ -\& unsigned char key[] = {0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15}; -\& unsigned char iv[] = {1,2,3,4,5,6,7,8}; -\& char intext[] = "Some Crypto Text"; -\& EVP_CIPHER_CTX *ctx; -\& FILE *out; -\& -\& ctx = EVP_CIPHER_CTX_new(); -\& if (!EVP_EncryptInit_ex2(ctx, EVP_idea_cbc(), key, iv, NULL)) { -\& /* Error */ -\& EVP_CIPHER_CTX_free(ctx); -\& return 0; -\& } -\& -\& if (!EVP_EncryptUpdate(ctx, outbuf, &outlen, intext, strlen(intext))) { -\& /* Error */ -\& EVP_CIPHER_CTX_free(ctx); -\& return 0; -\& } -\& /* -\& * Buffer passed to EVP_EncryptFinal() must be after data just -\& * encrypted to avoid overwriting it. -\& */ -\& if (!EVP_EncryptFinal_ex(ctx, outbuf + outlen, &tmplen)) { -\& /* Error */ -\& EVP_CIPHER_CTX_free(ctx); -\& return 0; -\& } -\& outlen += tmplen; -\& EVP_CIPHER_CTX_free(ctx); -\& /* -\& * Need binary mode for fopen because encrypted data is -\& * binary data. Also cannot use strlen() on it because -\& * it won\*(Aqt be NUL terminated and may contain embedded -\& * NULs. -\& */ -\& out = fopen(outfile, "wb"); -\& if (out == NULL) { -\& /* Error */ -\& return 0; -\& } -\& fwrite(outbuf, 1, outlen, out); -\& fclose(out); -\& return 1; -\& } -.Ve -.PP -The ciphertext from the above example can be decrypted using the \fBopenssl\fR -utility with the command line (shown on two lines for clarity): -.PP -.Vb 2 -\& openssl idea \-d \e -\& \-K 000102030405060708090A0B0C0D0E0F \-iv 0102030405060708 = 16. -\& */ -\& int ret = 0, encrypt = 1, outlen, len; -\& EVP_CIPHER_CTX *ctx = NULL; -\& EVP_CIPHER *cipher = NULL; -\& OSSL_PARAM params[2]; -\& -\& ctx = EVP_CIPHER_CTX_new(); -\& cipher = EVP_CIPHER_fetch(NULL, "AES\-256\-CBC\-CTS", NULL); -\& if (ctx == NULL || cipher == NULL) -\& goto err; -\& -\& /* -\& * The default is "CS1" so this is not really needed, -\& * but would be needed to set either "CS2" or "CS3". -\& */ -\& params[0] = OSSL_PARAM_construct_utf8_string(OSSL_CIPHER_PARAM_CTS_MODE, -\& "CS1", 0); -\& params[1] = OSSL_PARAM_construct_end(); -\& -\& if (!EVP_CipherInit_ex2(ctx, cipher, key, iv, encrypt, params)) -\& goto err; -\& -\& /* NOTE: CTS mode does not support multiple calls to EVP_CipherUpdate() */ -\& if (!EVP_CipherUpdate(ctx, out, &outlen, msg, msg_len)) -\& goto err; -\& if (!EVP_CipherFinal_ex(ctx, out + outlen, &len)) -\& goto err; -\& ret = 1; -\& err: -\& EVP_CIPHER_free(cipher); -\& EVP_CIPHER_CTX_free(ctx); -\& return ret; -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBproperty\fR\|(7), -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7), -\&\fBprovider\-cipher\fR\|(7), -\&\fBlife_cycle\-cipher\fR\|(7) -.PP -Supported ciphers are listed in: -.PP -\&\fBEVP_aes_128_gcm\fR\|(3), -\&\fBEVP_aria_128_gcm\fR\|(3), -\&\fBEVP_bf_cbc\fR\|(3), -\&\fBEVP_camellia_128_ecb\fR\|(3), -\&\fBEVP_cast5_cbc\fR\|(3), -\&\fBEVP_chacha20\fR\|(3), -\&\fBEVP_des_cbc\fR\|(3), -\&\fBEVP_desx_cbc\fR\|(3), -\&\fBEVP_idea_cbc\fR\|(3), -\&\fBEVP_rc2_cbc\fR\|(3), -\&\fBEVP_rc4\fR\|(3), -\&\fBEVP_rc5_32_12_16_cbc\fR\|(3), -\&\fBEVP_seed_cbc\fR\|(3), -\&\fBEVP_sm4_cbc\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -Support for \s-1OCB\s0 mode was added in OpenSSL 1.1.0. -.PP -\&\fB\s-1EVP_CIPHER_CTX\s0\fR was made opaque in OpenSSL 1.1.0. As a result, -\&\fBEVP_CIPHER_CTX_reset()\fR appeared and \fBEVP_CIPHER_CTX_cleanup()\fR -disappeared. \fBEVP_CIPHER_CTX_init()\fR remains as an alias for -\&\fBEVP_CIPHER_CTX_reset()\fR. -.PP -The \fBEVP_CIPHER_CTX_cipher()\fR function was deprecated in OpenSSL 3.0; use -\&\fBEVP_CIPHER_CTX_get0_cipher()\fR instead. -.PP -The \fBEVP_EncryptInit_ex2()\fR, \fBEVP_DecryptInit_ex2()\fR, \fBEVP_CipherInit_ex2()\fR, -\&\fBEVP_CIPHER_fetch()\fR, \fBEVP_CIPHER_free()\fR, \fBEVP_CIPHER_up_ref()\fR, -\&\fBEVP_CIPHER_CTX_get0_cipher()\fR, \fBEVP_CIPHER_CTX_get1_cipher()\fR, -\&\fBEVP_CIPHER_get_params()\fR, \fBEVP_CIPHER_CTX_set_params()\fR, -\&\fBEVP_CIPHER_CTX_get_params()\fR, \fBEVP_CIPHER_gettable_params()\fR, -\&\fBEVP_CIPHER_settable_ctx_params()\fR, \fBEVP_CIPHER_gettable_ctx_params()\fR, -\&\fBEVP_CIPHER_CTX_settable_params()\fR and \fBEVP_CIPHER_CTX_gettable_params()\fR -functions were added in 3.0. -.PP -The \fBEVP_CIPHER_nid()\fR, \fBEVP_CIPHER_name()\fR, \fBEVP_CIPHER_block_size()\fR, -\&\fBEVP_CIPHER_key_length()\fR, \fBEVP_CIPHER_iv_length()\fR, \fBEVP_CIPHER_flags()\fR, -\&\fBEVP_CIPHER_mode()\fR, \fBEVP_CIPHER_type()\fR, \fBEVP_CIPHER_CTX_nid()\fR, -\&\fBEVP_CIPHER_CTX_block_size()\fR, \fBEVP_CIPHER_CTX_key_length()\fR, -\&\fBEVP_CIPHER_CTX_iv_length()\fR, \fBEVP_CIPHER_CTX_tag_length()\fR, -\&\fBEVP_CIPHER_CTX_num()\fR, \fBEVP_CIPHER_CTX_type()\fR, and \fBEVP_CIPHER_CTX_mode()\fR -functions were renamed to include \f(CW\*(C`get\*(C'\fR or \f(CW\*(C`get0\*(C'\fR in their names in -OpenSSL 3.0, respectively. The old names are kept as non-deprecated -alias macros. -.PP -The \fBEVP_CIPHER_CTX_encrypting()\fR function was renamed to -\&\fBEVP_CIPHER_CTX_is_encrypting()\fR in OpenSSL 3.0. The old name is kept as -non-deprecated alias macro. -.PP -The \fBEVP_CIPHER_CTX_flags()\fR macro was deprecated in OpenSSL 1.1.0. -.PP -\&\fBEVP_CIPHER_CTX_dup()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_EncryptInit_ex.3ossl b/openssl-install/share/man/man3/EVP_EncryptInit_ex.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_EncryptInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncryptInit_ex2.3ossl b/openssl-install/share/man/man3/EVP_EncryptInit_ex2.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_EncryptInit_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_EncryptUpdate.3ossl b/openssl-install/share/man/man3/EVP_EncryptUpdate.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_EncryptUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF.3ossl b/openssl-install/share/man/man3/EVP_KDF.3ossl deleted file mode 100644 index 28ede018..00000000 --- a/openssl-install/share/man/man3/EVP_KDF.3ossl +++ /dev/null @@ -1,439 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF 3ossl" -.TH EVP_KDF 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF, EVP_KDF_fetch, EVP_KDF_free, EVP_KDF_up_ref, -EVP_KDF_CTX, EVP_KDF_CTX_new, EVP_KDF_CTX_free, EVP_KDF_CTX_dup, -EVP_KDF_CTX_reset, EVP_KDF_derive, -EVP_KDF_CTX_get_kdf_size, -EVP_KDF_get0_provider, EVP_KDF_CTX_kdf, EVP_KDF_is_a, -EVP_KDF_get0_name, EVP_KDF_names_do_all, EVP_KDF_get0_description, -EVP_KDF_CTX_get_params, EVP_KDF_CTX_set_params, EVP_KDF_do_all_provided, -EVP_KDF_get_params, EVP_KDF_gettable_params, -EVP_KDF_gettable_ctx_params, EVP_KDF_settable_ctx_params, -EVP_KDF_CTX_gettable_params, EVP_KDF_CTX_settable_params \- EVP KDF routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct evp_kdf_st EVP_KDF; -\& typedef struct evp_kdf_ctx_st EVP_KDF_CTX; -\& -\& EVP_KDF_CTX *EVP_KDF_CTX_new(EVP_KDF *kdf); -\& const EVP_KDF *EVP_KDF_CTX_kdf(EVP_KDF_CTX *ctx); -\& void EVP_KDF_CTX_free(EVP_KDF_CTX *ctx); -\& EVP_KDF_CTX *EVP_KDF_CTX_dup(const EVP_KDF_CTX *src); -\& void EVP_KDF_CTX_reset(EVP_KDF_CTX *ctx); -\& size_t EVP_KDF_CTX_get_kdf_size(EVP_KDF_CTX *ctx); -\& int EVP_KDF_derive(EVP_KDF_CTX *ctx, unsigned char *key, size_t keylen, -\& const OSSL_PARAM params[]); -\& int EVP_KDF_up_ref(EVP_KDF *kdf); -\& void EVP_KDF_free(EVP_KDF *kdf); -\& EVP_KDF *EVP_KDF_fetch(OSSL_LIB_CTX *libctx, const char *algorithm, -\& const char *properties); -\& int EVP_KDF_is_a(const EVP_KDF *kdf, const char *name); -\& const char *EVP_KDF_get0_name(const EVP_KDF *kdf); -\& const char *EVP_KDF_get0_description(const EVP_KDF *kdf); -\& const OSSL_PROVIDER *EVP_KDF_get0_provider(const EVP_KDF *kdf); -\& void EVP_KDF_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_KDF *kdf, void *arg), -\& void *arg); -\& int EVP_KDF_names_do_all(const EVP_KDF *kdf, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& int EVP_KDF_get_params(EVP_KDF *kdf, OSSL_PARAM params[]); -\& int EVP_KDF_CTX_get_params(EVP_KDF_CTX *ctx, OSSL_PARAM params[]); -\& int EVP_KDF_CTX_set_params(EVP_KDF_CTX *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *EVP_KDF_gettable_params(const EVP_KDF *kdf); -\& const OSSL_PARAM *EVP_KDF_gettable_ctx_params(const EVP_KDF *kdf); -\& const OSSL_PARAM *EVP_KDF_settable_ctx_params(const EVP_KDF *kdf); -\& const OSSL_PARAM *EVP_KDF_CTX_gettable_params(const EVP_KDF *kdf); -\& const OSSL_PARAM *EVP_KDF_CTX_settable_params(const EVP_KDF *kdf); -\& const OSSL_PROVIDER *EVP_KDF_get0_provider(const EVP_KDF *kdf); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP KDF\s0 routines are a high-level interface to Key Derivation Function -algorithms and should be used instead of algorithm-specific functions. -.PP -After creating a \fB\s-1EVP_KDF_CTX\s0\fR for the required algorithm using -\&\fBEVP_KDF_CTX_new()\fR, inputs to the algorithm are supplied either by -passing them as part of the \fBEVP_KDF_derive()\fR call or using calls -to \fBEVP_KDF_CTX_set_params()\fR before calling \fBEVP_KDF_derive()\fR to derive -the key. -.SS "Types" -.IX Subsection "Types" -\&\fB\s-1EVP_KDF\s0\fR is a type that holds the implementation of a \s-1KDF.\s0 -.PP -\&\fB\s-1EVP_KDF_CTX\s0\fR is a context type that holds the algorithm inputs. -.SS "Algorithm implementation fetching" -.IX Subsection "Algorithm implementation fetching" -\&\fBEVP_KDF_fetch()\fR fetches an implementation of a \s-1KDF\s0 \fIalgorithm\fR, given -a library context \fIlibctx\fR and a set of \fIproperties\fR. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.PP -See \*(L"Key Derivation Function (\s-1KDF\s0)\*(R" in \fBOSSL_PROVIDER\-default\fR\|(7) for the lists of -algorithms supported by the default provider. -.PP -The returned value must eventually be freed with -\&\fBEVP_KDF_free\fR\|(3). -.PP -\&\fBEVP_KDF_up_ref()\fR increments the reference count of an already fetched -\&\s-1KDF.\s0 -.PP -\&\fBEVP_KDF_free()\fR frees a fetched algorithm. -\&\s-1NULL\s0 is a valid parameter, for which this function is a no-op. -.SS "Context manipulation functions" -.IX Subsection "Context manipulation functions" -\&\fBEVP_KDF_CTX_new()\fR creates a new context for the \s-1KDF\s0 implementation \fIkdf\fR. -.PP -\&\fBEVP_KDF_CTX_free()\fR frees up the context \fIctx\fR. If \fIctx\fR is \s-1NULL,\s0 nothing -is done. -.PP -\&\fBEVP_KDF_CTX_kdf()\fR returns the \fB\s-1EVP_KDF\s0\fR associated with the context -\&\fIctx\fR. -.SS "Computing functions" -.IX Subsection "Computing functions" -\&\fBEVP_KDF_CTX_reset()\fR resets the context to the default state as if the context -had just been created. -.PP -\&\fBEVP_KDF_derive()\fR processes any parameters in \fIParams\fR and then derives -\&\fIkeylen\fR bytes of key material and places it in the \fIkey\fR buffer. -If the algorithm produces a fixed amount of output then an error will -occur unless the \fIkeylen\fR parameter is equal to that output size, -as returned by \fBEVP_KDF_CTX_get_kdf_size()\fR. -.PP -\&\fBEVP_KDF_get_params()\fR retrieves details about the implementation -\&\fIkdf\fR. -The set of parameters given with \fIparams\fR determine exactly what -parameters should be retrieved. -Note that a parameter that is unknown in the underlying context is -simply ignored. -.PP -\&\fBEVP_KDF_CTX_get_params()\fR retrieves chosen parameters, given the -context \fIctx\fR and its underlying context. -The set of parameters given with \fIparams\fR determine exactly what -parameters should be retrieved. -Note that a parameter that is unknown in the underlying context is -simply ignored. -.PP -\&\fBEVP_KDF_CTX_set_params()\fR passes chosen parameters to the underlying -context, given a context \fIctx\fR. -The set of parameters given with \fIparams\fR determine exactly what -parameters are passed down. -Note that a parameter that is unknown in the underlying context is -simply ignored. -Also, what happens when a needed parameter isn't passed down is -defined by the implementation. -.PP -\&\fBEVP_KDF_gettable_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes -the retrievable and settable parameters. \fBEVP_KDF_gettable_params()\fR -returns parameters that can be used with \fBEVP_KDF_get_params()\fR. -.PP -\&\fBEVP_KDF_gettable_ctx_params()\fR and \fBEVP_KDF_CTX_gettable_params()\fR -return constant \s-1\fBOSSL_PARAM\s0\fR\|(3) arrays that describe the retrievable -parameters that can be used with \fBEVP_KDF_CTX_get_params()\fR. -\&\fBEVP_KDF_gettable_ctx_params()\fR returns the parameters that can be retrieved -from the algorithm, whereas \fBEVP_KDF_CTX_gettable_params()\fR returns -the parameters that can be retrieved in the context's current state. -.PP -\&\fBEVP_KDF_settable_ctx_params()\fR and \fBEVP_KDF_CTX_settable_params()\fR return -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) arrays that describe the settable parameters that -can be used with \fBEVP_KDF_CTX_set_params()\fR. \fBEVP_KDF_settable_ctx_params()\fR -returns the parameters that can be retrieved from the algorithm, -whereas \fBEVP_KDF_CTX_settable_params()\fR returns the parameters that can -be retrieved in the context's current state. -.SS "Information functions" -.IX Subsection "Information functions" -\&\fBEVP_KDF_CTX_get_kdf_size()\fR returns the output size if the algorithm produces a fixed amount -of output and \fB\s-1SIZE_MAX\s0\fR otherwise. If an error occurs then 0 is returned. -For some algorithms an error may result if input parameters necessary to -calculate a fixed output size have not yet been supplied. -.PP -\&\fBEVP_KDF_is_a()\fR returns 1 if \fIkdf\fR is an implementation of an -algorithm that's identifiable with \fIname\fR, otherwise 0. -.PP -\&\fBEVP_KDF_get0_provider()\fR returns the provider that holds the implementation -of the given \fIkdf\fR. -.PP -\&\fBEVP_KDF_do_all_provided()\fR traverses all \s-1KDF\s0 implemented by all activated -providers in the given library context \fIlibctx\fR, and for each of the -implementations, calls the given function \fIfn\fR with the implementation method -and the given \fIarg\fR as argument. -.PP -\&\fBEVP_KDF_get0_name()\fR return the name of the given \s-1KDF.\s0 For fetched KDFs -with multiple names, only one of them is returned; it's -recommended to use \fBEVP_KDF_names_do_all()\fR instead. -.PP -\&\fBEVP_KDF_names_do_all()\fR traverses all names for \fIkdf\fR, and calls -\&\fIfn\fR with each name and \fIdata\fR. -.PP -\&\fBEVP_KDF_get0_description()\fR returns a description of the \fIkdf\fR, meant for -display and human consumption. The description is at the discretion of -the \fIkdf\fR implementation. -.SH "PARAMETERS" -.IX Header "PARAMETERS" -The standard parameter names are: -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -Some \s-1KDF\s0 implementations require a password. -For those \s-1KDF\s0 implementations that support it, this parameter sets the password. -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -Some \s-1KDF\s0 implementations can take a non-secret unique cryptographic salt. -For those \s-1KDF\s0 implementations that support it, this parameter sets the salt. -.Sp -The default value, if any, is implementation dependent. -.ie n .IP """iter"" (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.el .IP "``iter'' (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.IX Item "iter (OSSL_KDF_PARAM_ITER) " -Some \s-1KDF\s0 implementations require an iteration count. -For those \s-1KDF\s0 implementations that support it, this parameter sets the -iteration count. -.Sp -The default value, if any, is implementation dependent. -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """mac"" (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mac'' (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mac (OSSL_KDF_PARAM_MAC) " -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.ie n .IP """cipher"" (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_KDF_PARAM_CIPHER) " -.PD -For \s-1KDF\s0 implementations that use an underlying computation \s-1MAC,\s0 digest or -cipher, these parameters set what the algorithm should be. -.Sp -The value is always the name of the intended algorithm, -or the properties. -.Sp -Note that not all algorithms may support all possible underlying -implementations. -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -Some \s-1KDF\s0 implementations require a key. -For those \s-1KDF\s0 implementations that support it, this octet string parameter -sets the key. -.ie n .IP """info"" (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.el .IP "``info'' (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.IX Item "info (OSSL_KDF_PARAM_INFO) " -Some \s-1KDF\s0 implementations, such as \s-1\fBEVP_KDF\-HKDF\s0\fR\|(7), take an 'info' parameter -for binding the derived key material -to application\- and context-specific information. -This parameter sets the info, fixed info, other info or shared info argument. -You can specify this parameter multiple times, and each instance will -be concatenated to form the final value. -.ie n .IP """maclen"" (\fB\s-1OSSL_KDF_PARAM_MAC_SIZE\s0\fR) " 4 -.el .IP "``maclen'' (\fB\s-1OSSL_KDF_PARAM_MAC_SIZE\s0\fR) " 4 -.IX Item "maclen (OSSL_KDF_PARAM_MAC_SIZE) " -Used by implementations that use a \s-1MAC\s0 with a variable output size (\s-1KMAC\s0). -For those \s-1KDF\s0 implementations that support it, this parameter -sets the \s-1MAC\s0 output size. -.Sp -The default value, if any, is implementation dependent. -The length must never exceed what can be given with a \fBsize_t\fR. -.ie n .IP """maxmem_bytes"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_MAXMEM\s0\fR) " 4 -.el .IP "``maxmem_bytes'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_MAXMEM\s0\fR) " 4 -.IX Item "maxmem_bytes (OSSL_KDF_PARAM_SCRYPT_MAXMEM) " -Memory-hard password-based \s-1KDF\s0 algorithms, such as scrypt, use an amount of -memory that depends on the load factors provided as input. -For those \s-1KDF\s0 implementations that support it, this \fBuint64_t\fR parameter sets -an upper limit on the amount of memory that may be consumed while performing -a key derivation. -If this memory usage limit is exceeded because the load factors are chosen -too high, the key derivation will fail. -.Sp -The default value is implementation dependent. -The memory size must never exceed what can be given with a \fBsize_t\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_KDF_fetch()\fR returns a pointer to a newly fetched \fB\s-1EVP_KDF\s0\fR, or -\&\s-1NULL\s0 if allocation failed. -.PP -\&\fBEVP_KDF_get0_provider()\fR returns a pointer to the provider for the \s-1KDF,\s0 or -\&\s-1NULL\s0 on error. -.PP -\&\fBEVP_KDF_up_ref()\fR returns 1 on success, 0 on error. -.PP -\&\fBEVP_KDF_CTX_new()\fR returns either the newly allocated -\&\fB\s-1EVP_KDF_CTX\s0\fR structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBEVP_KDF_CTX_free()\fR and \fBEVP_KDF_CTX_reset()\fR do not return a value. -.PP -\&\fBEVP_KDF_CTX_get_kdf_size()\fR returns the output size. \fB\s-1SIZE_MAX\s0\fR is returned to indicate -that the algorithm produces a variable amount of output; 0 to indicate failure. -.PP -\&\fBEVP_KDF_get0_name()\fR returns the name of the \s-1KDF,\s0 or \s-1NULL\s0 on error. -.PP -\&\fBEVP_KDF_names_do_all()\fR returns 1 if the callback was called for all names. A -return value of 0 means that the callback was not called for any names. -.PP -The remaining functions return 1 for success and 0 or a negative value for -failure. In particular, a return value of \-2 indicates the operation is not -supported by the \s-1KDF\s0 algorithm. -.SH "NOTES" -.IX Header "NOTES" -The \s-1KDF\s0 life-cycle is described in \fBlife_cycle\-kdf\fR\|(7). In the future, -the transitions described there will be enforced. When this is done, it will -not be considered a breaking change to the \s-1API.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\*(L"Key Derivation Function (\s-1KDF\s0)\*(R" in \fBOSSL_PROVIDER\-default\fR\|(7), -\&\fBlife_cycle\-kdf\fR\|(7). -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_dup.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_dup.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_free.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_free.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_get_kdf_size.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_get_kdf_size.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_get_kdf_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_get_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_get_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_gettable_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_kdf.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_kdf.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_kdf.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_new.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_new.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_reset.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_reset.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_reset.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_set_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_set_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_CTX_settable_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_CTX_settable_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_CTX_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_derive.3ossl b/openssl-install/share/man/man3/EVP_KDF_derive.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_derive.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_KDF_do_all_provided.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_fetch.3ossl b/openssl-install/share/man/man3/EVP_KDF_fetch.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_free.3ossl b/openssl-install/share/man/man3/EVP_KDF_free.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_get0_description.3ossl b/openssl-install/share/man/man3/EVP_KDF_get0_description.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_get0_name.3ossl b/openssl-install/share/man/man3/EVP_KDF_get0_name.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_KDF_get0_provider.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_get_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_get_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_gettable_ctx_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_gettable_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_is_a.3ossl b/openssl-install/share/man/man3/EVP_KDF_is_a.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_KDF_names_do_all.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_KDF_settable_ctx_params.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KDF_up_ref.3ossl b/openssl-install/share/man/man3/EVP_KDF_up_ref.3ossl deleted file mode 120000 index ad467465..00000000 --- a/openssl-install/share/man/man3/EVP_KDF_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KDF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_KEM_do_all_provided.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_fetch.3ossl b/openssl-install/share/man/man3/EVP_KEM_fetch.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_free.3ossl b/openssl-install/share/man/man3/EVP_KEM_free.3ossl deleted file mode 100644 index d94831a5..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_free.3ossl +++ /dev/null @@ -1,237 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEM_FREE 3ossl" -.TH EVP_KEM_FREE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEM_fetch, EVP_KEM_free, EVP_KEM_up_ref, -EVP_KEM_get0_name, EVP_KEM_is_a, EVP_KEM_get0_provider, -EVP_KEM_do_all_provided, EVP_KEM_names_do_all, EVP_KEM_get0_description, -EVP_KEM_gettable_ctx_params, EVP_KEM_settable_ctx_params -\&\- Functions to manage EVP_KEM algorithm objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_KEM *EVP_KEM_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, -\& const char *properties); -\& void EVP_KEM_free(EVP_KEM *kem); -\& int EVP_KEM_up_ref(EVP_KEM *kem); -\& const char *EVP_KEM_get0_name(const EVP_KEM *kem); -\& int EVP_KEM_is_a(const EVP_KEM *kem, const char *name); -\& OSSL_PROVIDER *EVP_KEM_get0_provider(const EVP_KEM *kem); -\& void EVP_KEM_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_KEM *kem, void *arg), void *arg); -\& int EVP_KEM_names_do_all(const EVP_KEM *kem, -\& void (*fn)(const char *name, void *data), void *data); -\& const char *EVP_KEM_get0_description(const EVP_KEM *kem); -\& const OSSL_PARAM *EVP_KEM_gettable_ctx_params(const EVP_KEM *kem); -\& const OSSL_PARAM *EVP_KEM_settable_ctx_params(const EVP_KEM *kem); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_KEM_fetch()\fR fetches the implementation for the given \fBalgorithm\fR from any -provider offering it, within the criteria given by the \fBproperties\fR and in the -scope of the given library context \fBctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)). The algorithm -will be one offering functions for performing asymmetric kem related tasks such -as key encapsulation and decapsulation. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.PP -The returned value must eventually be freed with \fBEVP_KEM_free()\fR. -.PP -\&\fBEVP_KEM_free()\fR decrements the reference count for the \fB\s-1EVP_KEM\s0\fR structure. -Typically this structure will have been obtained from an earlier call to -\&\fBEVP_KEM_fetch()\fR. If the reference count drops to 0 then the structure is freed. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_KEM_up_ref()\fR increments the reference count for an \fB\s-1EVP_KEM\s0\fR structure. -.PP -\&\fBEVP_KEM_is_a()\fR returns 1 if \fIkem\fR is an implementation of an -algorithm that's identifiable with \fIname\fR, otherwise 0. -.PP -\&\fBEVP_KEM_get0_provider()\fR returns the provider that \fIkem\fR was fetched from. -.PP -\&\fBEVP_KEM_do_all_provided()\fR traverses all EVP_KEMs implemented by all activated -providers in the given library context \fIlibctx\fR, and for each of the -implementations, calls the given function \fIfn\fR with the implementation method -and the given \fIarg\fR as argument. -.PP -\&\fBEVP_KEM_get0_name()\fR returns the algorithm name from the provided -implementation for the given \fIkem\fR. Note that the \fIkem\fR may have -multiple synonyms associated with it. In this case the first name from the -algorithm definition is returned. Ownership of the returned string is retained -by the \fIkem\fR object and should not be freed by the caller. -.PP -\&\fBEVP_KEM_names_do_all()\fR traverses all names for \fIkem\fR, and calls \fIfn\fR with -each name and \fIdata\fR. -.PP -\&\fBEVP_KEM_get0_description()\fR returns a description of the \fIkem\fR, meant for -display and human consumption. The description is at the discretion of -the \fIkem\fR implementation. -.PP -\&\fBEVP_KEM_gettable_ctx_params()\fR and \fBEVP_KEM_settable_ctx_params()\fR return -a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the names and types of key -parameters that can be retrieved or set by a key encapsulation algorithm using -\&\fBEVP_PKEY_CTX_get_params\fR\|(3) and \fBEVP_PKEY_CTX_set_params\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_KEM_fetch()\fR returns a pointer to an \fB\s-1EVP_KEM\s0\fR for success or \fB\s-1NULL\s0\fR for -failure. -.PP -\&\fBEVP_KEM_up_ref()\fR returns 1 for success or 0 otherwise. -.PP -\&\fBEVP_KEM_names_do_all()\fR returns 1 if the callback was called for all names. A -return value of 0 means that the callback was not called for any names. -.PP -\&\fBEVP_KEM_gettable_ctx_params()\fR and \fBEVP_KEM_settable_ctx_params()\fR return -a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7), \s-1\fBOSSL_PROVIDER\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_KEM_get0_description.3ossl b/openssl-install/share/man/man3/EVP_KEM_get0_description.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_get0_name.3ossl b/openssl-install/share/man/man3/EVP_KEM_get0_name.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_KEM_get0_provider.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_KEM_gettable_ctx_params.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_is_a.3ossl b/openssl-install/share/man/man3/EVP_KEM_is_a.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_KEM_names_do_all.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_KEM_settable_ctx_params.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEM_up_ref.3ossl b/openssl-install/share/man/man3/EVP_KEM_up_ref.3ossl deleted file mode 120000 index 98f3ca3e..00000000 --- a/openssl-install/share/man/man3/EVP_KEM_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_do_all_provided.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_fetch.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_fetch.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_free.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_free.3ossl deleted file mode 100644 index 189f0a9e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_free.3ossl +++ /dev/null @@ -1,242 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEYEXCH_FREE 3ossl" -.TH EVP_KEYEXCH_FREE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEYEXCH_fetch, EVP_KEYEXCH_free, EVP_KEYEXCH_up_ref, -EVP_KEYEXCH_get0_provider, EVP_KEYEXCH_is_a, EVP_KEYEXCH_do_all_provided, -EVP_KEYEXCH_names_do_all, EVP_KEYEXCH_get0_name, EVP_KEYEXCH_get0_description, -EVP_KEYEXCH_gettable_ctx_params, EVP_KEYEXCH_settable_ctx_params -\&\- Functions to manage EVP_KEYEXCH algorithm objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_KEYEXCH *EVP_KEYEXCH_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, -\& const char *properties); -\& void EVP_KEYEXCH_free(EVP_KEYEXCH *exchange); -\& int EVP_KEYEXCH_up_ref(EVP_KEYEXCH *exchange); -\& OSSL_PROVIDER *EVP_KEYEXCH_get0_provider(const EVP_KEYEXCH *exchange); -\& int EVP_KEYEXCH_is_a(const EVP_KEYEXCH *exchange, const char *name); -\& const char *EVP_KEYEXCH_get0_name(const EVP_KEYEXCH *exchange); -\& void EVP_KEYEXCH_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_KEYEXCH *exchange, void *arg), -\& void *arg); -\& int EVP_KEYEXCH_names_do_all(const EVP_KEYEXCH *exchange, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const char *EVP_KEYEXCH_get0_description(const EVP_KEYEXCH *keyexch); -\& const OSSL_PARAM *EVP_KEYEXCH_gettable_ctx_params(const EVP_KEYEXCH *keyexch); -\& const OSSL_PARAM *EVP_KEYEXCH_settable_ctx_params(const EVP_KEYEXCH *keyexch); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_KEYEXCH_fetch()\fR fetches the key exchange implementation for the given -\&\fIalgorithm\fR from any provider offering it, within the criteria given -by the \fIproperties\fR. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.PP -The returned value must eventually be freed with \fBEVP_KEYEXCH_free()\fR. -.PP -\&\fBEVP_KEYEXCH_free()\fR decrements the reference count for the \fB\s-1EVP_KEYEXCH\s0\fR -structure. Typically this structure will have been obtained from an earlier call -to \fBEVP_KEYEXCH_fetch()\fR. If the reference count drops to 0 then the -structure is freed. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_KEYEXCH_up_ref()\fR increments the reference count for an \fB\s-1EVP_KEYEXCH\s0\fR -structure. -.PP -\&\fBEVP_KEYEXCH_get0_provider()\fR returns the provider that \fIexchange\fR was -fetched from. -.PP -\&\fBEVP_KEYEXCH_is_a()\fR checks if \fIexchange\fR is an implementation of an -algorithm that's identifiable with \fIname\fR. -.PP -\&\fBEVP_KEYEXCH_get0_name()\fR returns the algorithm name from the provided -implementation for the given \fIexchange\fR. Note that the \fIexchange\fR may have -multiple synonyms associated with it. In this case the first name from the -algorithm definition is returned. Ownership of the returned string is retained -by the \fIexchange\fR object and should not be freed by the caller. -.PP -\&\fBEVP_KEYEXCH_names_do_all()\fR traverses all names for the \fIexchange\fR, and -calls \fIfn\fR with each name and \fIdata\fR. -.PP -\&\fBEVP_KEYEXCH_get0_description()\fR returns a description of the \fIkeyexch\fR, meant -for display and human consumption. The description is at the discretion of -the \fIkeyexch\fR implementation. -.PP -\&\fBEVP_KEYEXCH_do_all_provided()\fR traverses all key exchange implementations by -all activated providers in the library context \fIlibctx\fR, and for each -of the implementations, calls \fIfn\fR with the implementation method and -\&\fIdata\fR as arguments. -.PP -\&\fBEVP_KEYEXCH_gettable_ctx_params()\fR and \fBEVP_KEYEXCH_settable_ctx_params()\fR return -a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the names and types of key -parameters that can be retrieved or set by a key exchange algorithm using -\&\fBEVP_PKEY_CTX_get_params\fR\|(3) and \fBEVP_PKEY_CTX_set_params\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_KEYEXCH_fetch()\fR returns a pointer to a \fB\s-1EVP_KEYEXCH\s0\fR for success -or \s-1NULL\s0 for failure. -.PP -\&\fBEVP_KEYEXCH_up_ref()\fR returns 1 for success or 0 otherwise. -.PP -\&\fBEVP_KEYEXCH_names_do_all()\fR returns 1 if the callback was called for all -names. A return value of 0 means that the callback was not called for any names. -.PP -\&\fBEVP_KEYEXCH_is_a()\fR returns 1 of \fIexchange\fR was identifiable, -otherwise 0. -.PP -\&\fBEVP_KEYEXCH_gettable_ctx_params()\fR and \fBEVP_KEYEXCH_settable_ctx_params()\fR return -a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7), \s-1\fBOSSL_PROVIDER\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_get0_description.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_get0_description.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_get0_name.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_get0_name.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_get0_provider.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_gettable_ctx_params.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_is_a.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_is_a.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_names_do_all.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_settable_ctx_params.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYEXCH_up_ref.3ossl b/openssl-install/share/man/man3/EVP_KEYEXCH_up_ref.3ossl deleted file mode 120000 index 0060bf4e..00000000 --- a/openssl-install/share/man/man3/EVP_KEYEXCH_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT.3ossl deleted file mode 100644 index 3e889ea9..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT.3ossl +++ /dev/null @@ -1,285 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEYMGMT 3ossl" -.TH EVP_KEYMGMT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEYMGMT, -EVP_KEYMGMT_fetch, -EVP_KEYMGMT_up_ref, -EVP_KEYMGMT_free, -EVP_KEYMGMT_get0_provider, -EVP_KEYMGMT_is_a, -EVP_KEYMGMT_get0_description, -EVP_KEYMGMT_get0_name, -EVP_KEYMGMT_do_all_provided, -EVP_KEYMGMT_names_do_all, -EVP_KEYMGMT_gettable_params, -EVP_KEYMGMT_settable_params, -EVP_KEYMGMT_gen_gettable_params, -EVP_KEYMGMT_gen_settable_params -\&\- EVP key management routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct evp_keymgmt_st EVP_KEYMGMT; -\& -\& EVP_KEYMGMT *EVP_KEYMGMT_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, -\& const char *properties); -\& int EVP_KEYMGMT_up_ref(EVP_KEYMGMT *keymgmt); -\& void EVP_KEYMGMT_free(EVP_KEYMGMT *keymgmt); -\& const OSSL_PROVIDER *EVP_KEYMGMT_get0_provider(const EVP_KEYMGMT *keymgmt); -\& int EVP_KEYMGMT_is_a(const EVP_KEYMGMT *keymgmt, const char *name); -\& const char *EVP_KEYMGMT_get0_name(const EVP_KEYMGMT *keymgmt); -\& const char *EVP_KEYMGMT_get0_description(const EVP_KEYMGMT *keymgmt); -\& -\& void EVP_KEYMGMT_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_KEYMGMT *keymgmt, void *arg), -\& void *arg); -\& int EVP_KEYMGMT_names_do_all(const EVP_KEYMGMT *keymgmt, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const OSSL_PARAM *EVP_KEYMGMT_gettable_params(const EVP_KEYMGMT *keymgmt); -\& const OSSL_PARAM *EVP_KEYMGMT_settable_params(const EVP_KEYMGMT *keymgmt); -\& const OSSL_PARAM *EVP_KEYMGMT_gen_settable_params(const EVP_KEYMGMT *keymgmt); -\& const OSSL_PARAM *EVP_KEYMGMT_gen_gettable_params(const EVP_KEYMGMT *keymgmt); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1EVP_KEYMGMT\s0\fR is a method object that represents key management -implementations for different cryptographic algorithms. -This method object provides functionality to have providers import key -material from the outside, as well as export key material to the -outside. -Most of the functionality can only be used internally and has no -public interface, this object is simply passed into other functions -when needed. -.PP -\&\fBEVP_KEYMGMT_fetch()\fR looks for an algorithm within the provider that -has been loaded into the \fB\s-1OSSL_LIB_CTX\s0\fR given by \fIctx\fR, having the -name given by \fIalgorithm\fR and the properties given by \fIproperties\fR. -.PP -\&\fBEVP_KEYMGMT_up_ref()\fR increments the reference count for the given -\&\fB\s-1EVP_KEYMGMT\s0\fR \fIkeymgmt\fR. -.PP -\&\fBEVP_KEYMGMT_free()\fR decrements the reference count for the given -\&\fB\s-1EVP_KEYMGMT\s0\fR \fIkeymgmt\fR, and when the count reaches zero, frees it. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_KEYMGMT_get0_provider()\fR returns the provider that has this particular -implementation. -.PP -\&\fBEVP_KEYMGMT_is_a()\fR checks if \fIkeymgmt\fR is an implementation of an -algorithm that's identifiable with \fIname\fR. -.PP -\&\fBEVP_KEYMGMT_get0_name()\fR returns the algorithm name from the provided -implementation for the given \fIkeymgmt\fR. Note that the \fIkeymgmt\fR may have -multiple synonyms associated with it. In this case the first name from the -algorithm definition is returned. Ownership of the returned string is -retained by the \fIkeymgmt\fR object and should not be freed by the caller. -.PP -\&\fBEVP_KEYMGMT_names_do_all()\fR traverses all names for the \fIkeymgmt\fR, and -calls \fIfn\fR with each name and \fIdata\fR. -.PP -\&\fBEVP_KEYMGMT_get0_description()\fR returns a description of the \fIkeymgmt\fR, meant -for display and human consumption. The description is at the discretion -of the \fIkeymgmt\fR implementation. -.PP -\&\fBEVP_KEYMGMT_do_all_provided()\fR traverses all key keymgmt implementations by -all activated providers in the library context \fIlibctx\fR, and for each -of the implementations, calls \fIfn\fR with the implementation method and -\&\fIdata\fR as arguments. -.PP -\&\fBEVP_KEYMGMT_gettable_params()\fR and \fBEVP_KEYMGMT_settable_params()\fR return a -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the names and types of key -parameters that can be retrieved or set. -\&\fBEVP_KEYMGMT_gettable_params()\fR is used by \fBEVP_PKEY_gettable_params\fR\|(3). -.PP -\&\fBEVP_KEYMGMT_gen_gettable_params()\fR and \fBEVP_KEYMGMT_gen_settable_params()\fR return a -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the names and types of key -generation parameters that can be retrieved or set via -\&\fBEVP_PKEY_CTX_get_params\fR\|(3) or \fBEVP_PKEY_CTX_set_params\fR\|(3) respectively. -.SH "NOTES" -.IX Header "NOTES" -\&\fBEVP_KEYMGMT_fetch()\fR may be called implicitly by other fetching -functions, using the same library context and properties. -Any other \s-1API\s0 that uses keys will typically do this. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_KEYMGMT_fetch()\fR returns a pointer to the key management -implementation represented by an \s-1EVP_KEYMGMT\s0 object, or \s-1NULL\s0 on -error. -.PP -\&\fBEVP_KEYMGMT_up_ref()\fR returns 1 on success, or 0 on error. -.PP -\&\fBEVP_KEYMGMT_names_do_all()\fR returns 1 if the callback was called for all -names. A return value of 0 means that the callback was not called for any names. -.PP -\&\fBEVP_KEYMGMT_free()\fR doesn't return any value. -.PP -\&\fBEVP_KEYMGMT_get0_provider()\fR returns a pointer to a provider object, or \s-1NULL\s0 -on error. -.PP -\&\fBEVP_KEYMGMT_is_a()\fR returns 1 of \fIkeymgmt\fR was identifiable, -otherwise 0. -.PP -\&\fBEVP_KEYMGMT_get0_name()\fR returns the algorithm name, or \s-1NULL\s0 on error. -.PP -\&\fBEVP_KEYMGMT_get0_description()\fR returns a pointer to a description, or \s-1NULL\s0 if -there isn't one. -.PP -\&\fBEVP_KEYMGMT_gettable_params()\fR, \fBEVP_KEYMGMT_settable_params()\fR, -\&\fBEVP_KEYMGMT_gen_gettable_params()\fR and \fBEVP_KEYMGMT_gen_settable_params()\fR -return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_fetch\fR\|(3), \s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBEVP_KEYMGMT_gen_gettable_params()\fR was added in OpenSSL 3.4.0 -All other functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_do_all_provided.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_fetch.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_fetch.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_free.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_free.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_gen_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_gen_gettable_params.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_gen_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_gen_settable_params.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_gen_settable_params.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_gen_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_get0_description.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_get0_description.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_get0_name.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_get0_name.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_get0_provider.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_gettable_params.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_is_a.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_is_a.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_names_do_all.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_settable_params.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_settable_params.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_KEYMGMT_up_ref.3ossl b/openssl-install/share/man/man3/EVP_KEYMGMT_up_ref.3ossl deleted file mode 120000 index c66df96b..00000000 --- a/openssl-install/share/man/man3/EVP_KEYMGMT_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYMGMT.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC.3ossl b/openssl-install/share/man/man3/EVP_MAC.3ossl deleted file mode 100644 index 591b36c1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC.3ossl +++ /dev/null @@ -1,630 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC 3ossl" -.TH EVP_MAC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC, EVP_MAC_fetch, EVP_MAC_up_ref, EVP_MAC_free, EVP_MAC_is_a, -EVP_MAC_get0_name, EVP_MAC_names_do_all, EVP_MAC_get0_description, -EVP_MAC_get0_provider, EVP_MAC_get_params, EVP_MAC_gettable_params, -EVP_MAC_CTX, EVP_MAC_CTX_new, EVP_MAC_CTX_free, EVP_MAC_CTX_dup, -EVP_MAC_CTX_get0_mac, EVP_MAC_CTX_get_params, EVP_MAC_CTX_set_params, -EVP_MAC_CTX_get_mac_size, EVP_MAC_CTX_get_block_size, EVP_Q_mac, -EVP_MAC_init, EVP_MAC_update, EVP_MAC_final, EVP_MAC_finalXOF, -EVP_MAC_gettable_ctx_params, EVP_MAC_settable_ctx_params, -EVP_MAC_CTX_gettable_params, EVP_MAC_CTX_settable_params, -EVP_MAC_do_all_provided \- EVP MAC routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct evp_mac_st EVP_MAC; -\& typedef struct evp_mac_ctx_st EVP_MAC_CTX; -\& -\& EVP_MAC *EVP_MAC_fetch(OSSL_LIB_CTX *libctx, const char *algorithm, -\& const char *properties); -\& int EVP_MAC_up_ref(EVP_MAC *mac); -\& void EVP_MAC_free(EVP_MAC *mac); -\& int EVP_MAC_is_a(const EVP_MAC *mac, const char *name); -\& const char *EVP_MAC_get0_name(const EVP_MAC *mac); -\& int EVP_MAC_names_do_all(const EVP_MAC *mac, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const char *EVP_MAC_get0_description(const EVP_MAC *mac); -\& const OSSL_PROVIDER *EVP_MAC_get0_provider(const EVP_MAC *mac); -\& int EVP_MAC_get_params(EVP_MAC *mac, OSSL_PARAM params[]); -\& -\& EVP_MAC_CTX *EVP_MAC_CTX_new(EVP_MAC *mac); -\& void EVP_MAC_CTX_free(EVP_MAC_CTX *ctx); -\& EVP_MAC_CTX *EVP_MAC_CTX_dup(const EVP_MAC_CTX *src); -\& EVP_MAC *EVP_MAC_CTX_get0_mac(EVP_MAC_CTX *ctx); -\& int EVP_MAC_CTX_get_params(EVP_MAC_CTX *ctx, OSSL_PARAM params[]); -\& int EVP_MAC_CTX_set_params(EVP_MAC_CTX *ctx, const OSSL_PARAM params[]); -\& -\& size_t EVP_MAC_CTX_get_mac_size(EVP_MAC_CTX *ctx); -\& size_t EVP_MAC_CTX_get_block_size(EVP_MAC_CTX *ctx); -\& unsigned char *EVP_Q_mac(OSSL_LIB_CTX *libctx, const char *name, const char *propq, -\& const char *subalg, const OSSL_PARAM *params, -\& const void *key, size_t keylen, -\& const unsigned char *data, size_t datalen, -\& unsigned char *out, size_t outsize, size_t *outlen); -\& int EVP_MAC_init(EVP_MAC_CTX *ctx, const unsigned char *key, size_t keylen, -\& const OSSL_PARAM params[]); -\& int EVP_MAC_update(EVP_MAC_CTX *ctx, const unsigned char *data, size_t datalen); -\& int EVP_MAC_final(EVP_MAC_CTX *ctx, -\& unsigned char *out, size_t *outl, size_t outsize); -\& int EVP_MAC_finalXOF(EVP_MAC_CTX *ctx, unsigned char *out, size_t outsize); -\& -\& const OSSL_PARAM *EVP_MAC_gettable_params(const EVP_MAC *mac); -\& const OSSL_PARAM *EVP_MAC_gettable_ctx_params(const EVP_MAC *mac); -\& const OSSL_PARAM *EVP_MAC_settable_ctx_params(const EVP_MAC *mac); -\& const OSSL_PARAM *EVP_MAC_CTX_gettable_params(EVP_MAC_CTX *ctx); -\& const OSSL_PARAM *EVP_MAC_CTX_settable_params(EVP_MAC_CTX *ctx); -\& -\& void EVP_MAC_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_MAC *mac, void *arg), -\& void *arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These types and functions help the application to calculate MACs of -different types and with different underlying algorithms if there are -any. -.PP -MACs are a bit complex insofar that some of them use other algorithms -for actual computation. \s-1HMAC\s0 uses a digest, and \s-1CMAC\s0 uses a cipher. -Therefore, there are sometimes two contexts to keep track of, one for -the \s-1MAC\s0 algorithm itself and one for the underlying computation -algorithm if there is one. -.PP -To make things less ambiguous, this manual talks about a \*(L"context\*(R" or -\&\*(L"\s-1MAC\s0 context\*(R", which is to denote the \s-1MAC\s0 level context, and about a -\&\*(L"underlying context\*(R", or \*(L"computation context\*(R", which is to denote the -context for the underlying computation algorithm if there is one. -.SS "Types" -.IX Subsection "Types" -\&\fB\s-1EVP_MAC\s0\fR is a type that holds the implementation of a \s-1MAC.\s0 -.PP -\&\fB\s-1EVP_MAC_CTX\s0\fR is a context type that holds internal \s-1MAC\s0 information -as well as a reference to a computation context, for those MACs that -rely on an underlying computation algorithm. -.SS "Algorithm implementation fetching" -.IX Subsection "Algorithm implementation fetching" -\&\fBEVP_MAC_fetch()\fR fetches an implementation of a \s-1MAC\s0 \fIalgorithm\fR, given -a library context \fIlibctx\fR and a set of \fIproperties\fR. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.PP -See \*(L"Message Authentication Code (\s-1MAC\s0)\*(R" in \fBOSSL_PROVIDER\-default\fR\|(7) for the list -of algorithms supported by the default provider. -.PP -The returned value must eventually be freed with -\&\fBEVP_MAC_free\fR\|(3). -.PP -\&\fBEVP_MAC_up_ref()\fR increments the reference count of an already fetched -\&\s-1MAC.\s0 -.PP -\&\fBEVP_MAC_free()\fR frees a fetched algorithm. -\&\s-1NULL\s0 is a valid parameter, for which this function is a no-op. -.SS "Context manipulation functions" -.IX Subsection "Context manipulation functions" -\&\fBEVP_MAC_CTX_new()\fR creates a new context for the \s-1MAC\s0 type \fImac\fR. -The created context can then be used with most other functions -described here. -.PP -\&\fBEVP_MAC_CTX_free()\fR frees the contents of the context, including an -underlying context if there is one, as well as the context itself. -\&\s-1NULL\s0 is a valid parameter, for which this function is a no-op. -.PP -\&\fBEVP_MAC_CTX_dup()\fR duplicates the \fIsrc\fR context and returns a newly allocated -context. -.PP -\&\fBEVP_MAC_CTX_get0_mac()\fR returns the \fB\s-1EVP_MAC\s0\fR associated with the context -\&\fIctx\fR. -.SS "Computing functions" -.IX Subsection "Computing functions" -\&\fBEVP_Q_mac()\fR computes the message authentication code -of \fIdata\fR with length \fIdatalen\fR -using the \s-1MAC\s0 algorithm \fIname\fR and the key \fIkey\fR with length \fIkeylen\fR. -The \s-1MAC\s0 algorithm is fetched using any given \fIlibctx\fR and property query -string \fIpropq\fR. It takes parameters \fIsubalg\fR and further \fIparams\fR, -both of which may be \s-1NULL\s0 if not needed. -If \fIout\fR is not \s-1NULL,\s0 it places the result in the memory pointed at by \fIout\fR, -but only if \fIoutsize\fR is sufficient (otherwise no computation is made). -If \fIout\fR is \s-1NULL,\s0 it allocates and uses a buffer of suitable length, -which will be returned on success and must be freed by the caller. -In either case, also on error, -it assigns the number of bytes written to \fI*outlen\fR unless \fIoutlen\fR is \s-1NULL.\s0 -.PP -\&\fBEVP_MAC_init()\fR sets up the underlying context \fIctx\fR with information given -via the \fIkey\fR and \fIparams\fR arguments. The \s-1MAC\s0 \fIkey\fR has a length of -\&\fIkeylen\fR and the parameters in \fIparams\fR are processed before setting -the key. If \fIkey\fR is \s-1NULL,\s0 the key must be set via \fIparams\fR either -as part of this call or separately using \fBEVP_MAC_CTX_set_params()\fR. -Providing non-NULL \fIparams\fR to this function is equivalent to calling -\&\fBEVP_MAC_CTX_set_params()\fR with those \fIparams\fR for the same \fIctx\fR beforehand. -Note: There are additional requirements for some \s-1MAC\s0 algorithms during -re-initalization (i.e. calling \fBEVP_MAC_init()\fR on an \s-1EVP_MAC\s0 after \fBEVP_MAC_final()\fR -has been called on the same object). See the \s-1NOTES\s0 section below. -.PP -\&\fBEVP_MAC_init()\fR should be called before \fBEVP_MAC_update()\fR and \fBEVP_MAC_final()\fR. -.PP -\&\fBEVP_MAC_update()\fR adds \fIdatalen\fR bytes from \fIdata\fR to the \s-1MAC\s0 input. -.PP -\&\fBEVP_MAC_final()\fR does the final computation and stores the result in -the memory pointed at by \fIout\fR of size \fIoutsize\fR, and sets the number -of bytes written in \fI*outl\fR at. -If \fIout\fR is \s-1NULL\s0 or \fIoutsize\fR is too small, then no computation -is made. -To figure out what the output length will be and allocate space for it -dynamically, simply call with \fIout\fR being \s-1NULL\s0 and \fIoutl\fR -pointing at a valid location, then allocate space and make a second -call with \fIout\fR pointing at the allocated space. -.PP -\&\fBEVP_MAC_finalXOF()\fR does the final computation for an \s-1XOF\s0 based \s-1MAC\s0 and stores -the result in the memory pointed at by \fIout\fR of size \fIoutsize\fR. -.PP -\&\fBEVP_MAC_get_params()\fR retrieves details about the implementation -\&\fImac\fR. -The set of parameters given with \fIparams\fR determine exactly what -parameters should be retrieved. -Note that a parameter that is unknown in the underlying context is -simply ignored. -.PP -\&\fBEVP_MAC_CTX_get_params()\fR retrieves chosen parameters, given the -context \fIctx\fR and its underlying context. -The set of parameters given with \fIparams\fR determine exactly what -parameters should be retrieved. -Note that a parameter that is unknown in the underlying context is -simply ignored. -.PP -\&\fBEVP_MAC_CTX_set_params()\fR passes chosen parameters to the underlying -context, given a context \fIctx\fR. -The set of parameters given with \fIparams\fR determine exactly what -parameters are passed down. -If \fIparams\fR are \s-1NULL,\s0 the underlying context should do nothing and return 1. -Note that a parameter that is unknown in the underlying context is -simply ignored. -Also, what happens when a needed parameter isn't passed down is -defined by the implementation. -.PP -\&\fBEVP_MAC_gettable_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes -the retrievable and settable parameters. \fBEVP_MAC_gettable_params()\fR -returns parameters that can be used with \fBEVP_MAC_get_params()\fR. -.PP -\&\fBEVP_MAC_gettable_ctx_params()\fR and \fBEVP_MAC_CTX_gettable_params()\fR -return constant \s-1\fBOSSL_PARAM\s0\fR\|(3) arrays that describe the retrievable -parameters that can be used with \fBEVP_MAC_CTX_get_params()\fR. -\&\fBEVP_MAC_gettable_ctx_params()\fR returns the parameters that can be retrieved -from the algorithm, whereas \fBEVP_MAC_CTX_gettable_params()\fR returns -the parameters that can be retrieved in the context's current state. -.PP -\&\fBEVP_MAC_settable_ctx_params()\fR and \fBEVP_MAC_CTX_settable_params()\fR return -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) arrays that describe the settable parameters that -can be used with \fBEVP_MAC_CTX_set_params()\fR. \fBEVP_MAC_settable_ctx_params()\fR -returns the parameters that can be retrieved from the algorithm, -whereas \fBEVP_MAC_CTX_settable_params()\fR returns the parameters that can -be retrieved in the context's current state. -.SS "Information functions" -.IX Subsection "Information functions" -\&\fBEVP_MAC_CTX_get_mac_size()\fR returns the \s-1MAC\s0 output size for the given context. -.PP -\&\fBEVP_MAC_CTX_get_block_size()\fR returns the \s-1MAC\s0 block size for the given context. -Not all \s-1MAC\s0 algorithms support this. -.PP -\&\fBEVP_MAC_is_a()\fR checks if the given \fImac\fR is an implementation of an -algorithm that's identifiable with \fIname\fR. -.PP -\&\fBEVP_MAC_get0_provider()\fR returns the provider that holds the implementation -of the given \fImac\fR. -.PP -\&\fBEVP_MAC_do_all_provided()\fR traverses all \s-1MAC\s0 implemented by all activated -providers in the given library context \fIlibctx\fR, and for each of the -implementations, calls the given function \fIfn\fR with the implementation method -and the given \fIarg\fR as argument. -.PP -\&\fBEVP_MAC_get0_name()\fR return the name of the given \s-1MAC.\s0 For fetched MACs -with multiple names, only one of them is returned; it's -recommended to use \fBEVP_MAC_names_do_all()\fR instead. -.PP -\&\fBEVP_MAC_names_do_all()\fR traverses all names for \fImac\fR, and calls -\&\fIfn\fR with each name and \fIdata\fR. -.PP -\&\fBEVP_MAC_get0_description()\fR returns a description of the \fImac\fR, meant -for display and human consumption. The description is at the discretion -of the mac implementation. -.SH "PARAMETERS" -.IX Header "PARAMETERS" -Parameters are identified by name as strings, and have an expected -data type and maximum size. -OpenSSL has a set of macros for parameter names it expects to see in -its own \s-1MAC\s0 implementations. -Here, we show all three, the OpenSSL macro for the parameter name, the -name in string form, and a type description. -.PP -The standard parameter names are: -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Its value is the \s-1MAC\s0 key as an array of bytes. -.Sp -For MACs that use an underlying computation algorithm, the algorithm -must be set first, see parameter names \*(L"algorithm\*(R" below. -.ie n .IP """iv"" (\fB\s-1OSSL_MAC_PARAM_IV\s0\fR) " 4 -.el .IP "``iv'' (\fB\s-1OSSL_MAC_PARAM_IV\s0\fR) " 4 -.IX Item "iv (OSSL_MAC_PARAM_IV) " -Some \s-1MAC\s0 implementations (\s-1GMAC\s0) require an \s-1IV,\s0 this parameter sets the \s-1IV.\s0 -.ie n .IP """custom"" (\fB\s-1OSSL_MAC_PARAM_CUSTOM\s0\fR) " 4 -.el .IP "``custom'' (\fB\s-1OSSL_MAC_PARAM_CUSTOM\s0\fR) " 4 -.IX Item "custom (OSSL_MAC_PARAM_CUSTOM) " -Some \s-1MAC\s0 implementations (\s-1KMAC, BLAKE2\s0) accept a Customization String, -this parameter sets the Customization String. The default value is the -empty string. -.ie n .IP """salt"" (\fB\s-1OSSL_MAC_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_MAC_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_MAC_PARAM_SALT) " -This option is used by \s-1BLAKE2 MAC.\s0 -.ie n .IP """xof"" (\fB\s-1OSSL_MAC_PARAM_XOF\s0\fR) " 4 -.el .IP "``xof'' (\fB\s-1OSSL_MAC_PARAM_XOF\s0\fR) " 4 -.IX Item "xof (OSSL_MAC_PARAM_XOF) " -It's a simple flag, the value 0 or 1 are expected. -.Sp -This option is used by \s-1KMAC.\s0 -.ie n .IP """digest-noinit"" (\fB\s-1OSSL_MAC_PARAM_DIGEST_NOINIT\s0\fR) " 4 -.el .IP "``digest-noinit'' (\fB\s-1OSSL_MAC_PARAM_DIGEST_NOINIT\s0\fR) " 4 -.IX Item "digest-noinit (OSSL_MAC_PARAM_DIGEST_NOINIT) " -A simple flag to set the \s-1MAC\s0 digest to not initialise the -implementation specific data. The value 0 or 1 is expected. -.Sp -This option is deprecated and will be removed in a future release. -The option may be set, but is ignored. -.ie n .IP """digest-oneshot"" (\fB\s-1OSSL_MAC_PARAM_DIGEST_ONESHOT\s0\fR) " 4 -.el .IP "``digest-oneshot'' (\fB\s-1OSSL_MAC_PARAM_DIGEST_ONESHOT\s0\fR) " 4 -.IX Item "digest-oneshot (OSSL_MAC_PARAM_DIGEST_ONESHOT) " -A simple flag to set the \s-1MAC\s0 digest to be a oneshot operation. -The value 0 or 1 is expected. -.Sp -This option is deprecated and will be removed in a future release. -The option may be set, but is ignored. -.ie n .IP """properties"" (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_MAC_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_MAC_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_MAC_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_MAC_PARAM_DIGEST) " -.ie n .IP """cipher"" (\fB\s-1OSSL_MAC_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_MAC_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_MAC_PARAM_CIPHER) " -.PD -For \s-1MAC\s0 implementations that use an underlying computation cipher or -digest, these parameters set what the algorithm should be. -.Sp -The value is always the name of the intended algorithm, -or the properties. -.Sp -Note that not all algorithms may support all digests. -\&\s-1HMAC\s0 does not support variable output length digests such as \s-1SHAKE128\s0 -or \s-1SHAKE256.\s0 -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -For \s-1MAC\s0 implementations that support it, set the output size that -\&\fBEVP_MAC_final()\fR should produce. -The allowed sizes vary between \s-1MAC\s0 implementations, but must never exceed -what can be given with a \fBsize_t\fR. -.ie n .IP """tls-data-size"" (\fB\s-1OSSL_MAC_PARAM_TLS_DATA_SIZE\s0\fR) " 4 -.el .IP "``tls-data-size'' (\fB\s-1OSSL_MAC_PARAM_TLS_DATA_SIZE\s0\fR) " 4 -.IX Item "tls-data-size (OSSL_MAC_PARAM_TLS_DATA_SIZE) " -This parameter is only supported by \s-1HMAC.\s0 If set then special handling is -activated for calculating the \s-1MAC\s0 of a received mac-then-encrypt \s-1TLS\s0 record -where variable length record padding has been used (as in the case of \s-1CBC\s0 mode -ciphersuites). The value represents the total length of the record that is -having the \s-1MAC\s0 calculated including the received \s-1MAC\s0 and the record padding. -.Sp -When used EVP_MAC_update must be called precisely twice. The first time with -the 13 bytes of \s-1TLS\s0 \*(L"header\*(R" data, and the second time with the entire record -including the \s-1MAC\s0 itself and any padding. The entire record length must equal -the value passed in the \*(L"tls-data-size\*(R" parameter. The length passed in the -\&\fBdatalen\fR parameter to \fBEVP_MAC_update()\fR should be equal to the length of the -record after the \s-1MAC\s0 and any padding has been removed. -.PP -All these parameters should be used before the calls to any of -\&\fBEVP_MAC_init()\fR, \fBEVP_MAC_update()\fR and \fBEVP_MAC_final()\fR for a full -computation. -Anything else may give undefined results. -.SH "NOTES" -.IX Header "NOTES" -The \s-1MAC\s0 life-cycle is described in \fBlife_cycle\-mac\fR\|(7). In the future, -the transitions described there will be enforced. When this is done, it will -not be considered a breaking change to the \s-1API.\s0 -.PP -The usage of the parameter names \*(L"custom\*(R", \*(L"iv\*(R" and \*(L"salt\*(R" correspond to -the names used in the standard where the algorithm was defined. -.PP -Some \s-1MAC\s0 algorithms store internal state that cannot be extracted during -re-initalization. For example \s-1GMAC\s0 cannot extract an \fB\s-1IV\s0\fR from the -underlying \s-1CIPHER\s0 context, and so calling \fBEVP_MAC_init()\fR on an \s-1EVP_MAC\s0 object -after \fBEVP_MAC_final()\fR has been called cannot reset its cipher state to what it -was when the \fB\s-1IV\s0\fR was initially generated. For such instances, an -\&\fB\s-1OSSL_MAC_PARAM_IV\s0\fR parameter must be passed with each call to \fBEVP_MAC_init()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_MAC_fetch()\fR returns a pointer to a newly fetched \fB\s-1EVP_MAC\s0\fR, or -\&\s-1NULL\s0 if allocation failed. -.PP -\&\fBEVP_MAC_up_ref()\fR returns 1 on success, 0 on error. -.PP -\&\fBEVP_MAC_names_do_all()\fR returns 1 if the callback was called for all names. A -return value of 0 means that the callback was not called for any names. -.PP -\&\fBEVP_MAC_free()\fR returns nothing at all. -.PP -\&\fBEVP_MAC_is_a()\fR returns 1 if the given method can be identified with -the given name, otherwise 0. -.PP -\&\fBEVP_MAC_get0_name()\fR returns a name of the \s-1MAC,\s0 or \s-1NULL\s0 on error. -.PP -\&\fBEVP_MAC_get0_provider()\fR returns a pointer to the provider for the \s-1MAC,\s0 or -\&\s-1NULL\s0 on error. -.PP -\&\fBEVP_MAC_CTX_new()\fR and \fBEVP_MAC_CTX_dup()\fR return a pointer to a newly -created \s-1EVP_MAC_CTX,\s0 or \s-1NULL\s0 if allocation failed. -.PP -\&\fBEVP_MAC_CTX_free()\fR returns nothing at all. -.PP -\&\fBEVP_MAC_CTX_get_params()\fR and \fBEVP_MAC_CTX_set_params()\fR return 1 on -success, 0 on error. -.PP -\&\fBEVP_Q_mac()\fR returns a pointer to the computed \s-1MAC\s0 value, or \s-1NULL\s0 on error. -.PP -\&\fBEVP_MAC_init()\fR, \fBEVP_MAC_update()\fR, \fBEVP_MAC_final()\fR, and \fBEVP_MAC_finalXOF()\fR -return 1 on success, 0 on error. -.PP -\&\fBEVP_MAC_CTX_get_mac_size()\fR returns the expected output size, or 0 if it isn't -set. If it isn't set, a call to \fBEVP_MAC_init()\fR will set it. -.PP -\&\fBEVP_MAC_CTX_get_block_size()\fR returns the block size, or 0 if it isn't set. -If it isn't set, a call to \fBEVP_MAC_init()\fR will set it. -.PP -\&\fBEVP_MAC_do_all_provided()\fR returns nothing at all. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 5 -\& #include -\& #include -\& #include -\& #include -\& #include -\& -\& #include -\& #include -\& #include -\& -\& int main() { -\& EVP_MAC *mac = EVP_MAC_fetch(NULL, getenv("MY_MAC"), NULL); -\& const char *cipher = getenv("MY_MAC_CIPHER"); -\& const char *digest = getenv("MY_MAC_DIGEST"); -\& const char *key = getenv("MY_KEY"); -\& EVP_MAC_CTX *ctx = NULL; -\& -\& unsigned char buf[4096]; -\& size_t read_l; -\& size_t final_l; -\& -\& size_t i; -\& -\& OSSL_PARAM params[3]; -\& size_t params_n = 0; -\& -\& if (cipher != NULL) -\& params[params_n++] = -\& OSSL_PARAM_construct_utf8_string("cipher", (char*)cipher, 0); -\& if (digest != NULL) -\& params[params_n++] = -\& OSSL_PARAM_construct_utf8_string("digest", (char*)digest, 0); -\& params[params_n] = OSSL_PARAM_construct_end(); -\& -\& if (mac == NULL -\& || key == NULL -\& || (ctx = EVP_MAC_CTX_new(mac)) == NULL -\& || !EVP_MAC_init(ctx, (const unsigned char *)key, strlen(key), -\& params)) -\& goto err; -\& -\& while ( (read_l = read(STDIN_FILENO, buf, sizeof(buf))) > 0) { -\& if (!EVP_MAC_update(ctx, buf, read_l)) -\& goto err; -\& } -\& -\& if (!EVP_MAC_final(ctx, buf, &final_l, sizeof(buf))) -\& goto err; -\& -\& printf("Result: "); -\& for (i = 0; i < final_l; i++) -\& printf("%02X", buf[i]); -\& printf("\en"); -\& -\& EVP_MAC_CTX_free(ctx); -\& EVP_MAC_free(mac); -\& exit(0); -\& -\& err: -\& EVP_MAC_CTX_free(ctx); -\& EVP_MAC_free(mac); -\& fprintf(stderr, "Something went wrong\en"); -\& ERR_print_errors_fp(stderr); -\& exit (1); -\& } -.Ve -.PP -A run of this program, called with correct environment variables, can -look like this: -.PP -.Vb 3 -\& $ MY_MAC=cmac MY_KEY=secret0123456789 MY_MAC_CIPHER=aes\-128\-cbc \e -\& LD_LIBRARY_PATH=. ./foo < foo.c -\& Result: C5C06683CD9DDEF904D754505C560A4E -.Ve -.PP -(in this example, that program was stored in \fIfoo.c\fR and compiled to -\&\fI./foo\fR) -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBproperty\fR\|(7) -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), -\&\s-1\fBEVP_MAC\-BLAKE2\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-CMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-GMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-HMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-KMAC\s0\fR\|(7), -\&\fBEVP_MAC\-Siphash\fR\|(7), -\&\fBEVP_MAC\-Poly1305\fR\|(7), -\&\fBprovider\-mac\fR\|(7), -\&\fBlife_cycle\-mac\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_dup.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_dup.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_free.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_free.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_get0_mac.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_get0_mac.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_get0_mac.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_get_block_size.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_get_block_size.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_get_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_get_mac_size.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_get_mac_size.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_get_mac_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_get_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_get_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_gettable_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_new.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_new.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_set_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_set_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_CTX_settable_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_CTX_settable_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_CTX_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_MAC_do_all_provided.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_fetch.3ossl b/openssl-install/share/man/man3/EVP_MAC_fetch.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_final.3ossl b/openssl-install/share/man/man3/EVP_MAC_final.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_final.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_finalXOF.3ossl b/openssl-install/share/man/man3/EVP_MAC_finalXOF.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_finalXOF.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_free.3ossl b/openssl-install/share/man/man3/EVP_MAC_free.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_get0_description.3ossl b/openssl-install/share/man/man3/EVP_MAC_get0_description.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_get0_name.3ossl b/openssl-install/share/man/man3/EVP_MAC_get0_name.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_MAC_get0_provider.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_get_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_get_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_gettable_ctx_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_gettable_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_init.3ossl b/openssl-install/share/man/man3/EVP_MAC_init.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_is_a.3ossl b/openssl-install/share/man/man3/EVP_MAC_is_a.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_MAC_names_do_all.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_MAC_settable_ctx_params.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_up_ref.3ossl b/openssl-install/share/man/man3/EVP_MAC_up_ref.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MAC_update.3ossl b/openssl-install/share/man/man3/EVP_MAC_update.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_MAC_update.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_block_size.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_block_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_clear_flags.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_clear_flags.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_copy.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_copy.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_copy_ex.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_copy_ex.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_copy_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_ctrl.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_ctrl.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_dup.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_dup.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_free.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_free.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get0_md.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get0_md.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get0_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get0_md_data.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get0_md_data.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get0_md_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get0_name.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get0_name.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get1_md.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get1_md.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get1_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get_block_size.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get_block_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get_params.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get_pkey_ctx.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get_pkey_ctx.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get_pkey_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get_size.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get_size_ex.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get_size_ex.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get_size_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_get_type.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_get_type.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_gettable_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_md.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_md.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_md_data.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_md_data.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_md_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_new.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_new.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_pkey_ctx.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_pkey_ctx.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_pkey_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_reset.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_reset.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_reset.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_set_flags.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_set_flags.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_set_params.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_set_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_set_pkey_ctx.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_set_pkey_ctx.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_set_pkey_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_set_update_fn.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_set_update_fn.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_set_update_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_settable_params.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_settable_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_size.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_test_flags.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_test_flags.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_test_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_type.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_type.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_CTX_update_fn.3ossl b/openssl-install/share/man/man3/EVP_MD_CTX_update_fn.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_CTX_update_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_block_size.3ossl b/openssl-install/share/man/man3/EVP_MD_block_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_MD_do_all_provided.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_fetch.3ossl b/openssl-install/share/man/man3/EVP_MD_fetch.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_flags.3ossl b/openssl-install/share/man/man3/EVP_MD_flags.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_free.3ossl b/openssl-install/share/man/man3/EVP_MD_free.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get0_description.3ossl b/openssl-install/share/man/man3/EVP_MD_get0_description.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get0_name.3ossl b/openssl-install/share/man/man3/EVP_MD_get0_name.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_MD_get0_provider.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get_block_size.3ossl b/openssl-install/share/man/man3/EVP_MD_get_block_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get_block_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get_flags.3ossl b/openssl-install/share/man/man3/EVP_MD_get_flags.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get_params.3ossl b/openssl-install/share/man/man3/EVP_MD_get_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get_pkey_type.3ossl b/openssl-install/share/man/man3/EVP_MD_get_pkey_type.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get_pkey_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get_size.3ossl b/openssl-install/share/man/man3/EVP_MD_get_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_get_type.3ossl b/openssl-install/share/man/man3/EVP_MD_get_type.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_MD_gettable_ctx_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_MD_gettable_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_is_a.3ossl b/openssl-install/share/man/man3/EVP_MD_is_a.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_dup.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_dup.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_free.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_free.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_app_datasize.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_app_datasize.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_app_datasize.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_cleanup.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_cleanup.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_copy.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_copy.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_ctrl.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_ctrl.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_final.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_final.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_final.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_flags.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_flags.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_init.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_init.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_input_blocksize.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_input_blocksize.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_input_blocksize.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_result_size.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_result_size.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_result_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_get_update.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_get_update.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_get_update.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_new.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_new.3ossl deleted file mode 100644 index 3930193f..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_new.3ossl +++ /dev/null @@ -1,328 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD_METH_NEW 3ossl" -.TH EVP_MD_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD_meth_new, EVP_MD_meth_dup, EVP_MD_meth_free, -EVP_MD_meth_set_input_blocksize, -EVP_MD_meth_set_result_size, EVP_MD_meth_set_app_datasize, -EVP_MD_meth_set_flags, EVP_MD_meth_set_init, EVP_MD_meth_set_update, -EVP_MD_meth_set_final, EVP_MD_meth_set_copy, EVP_MD_meth_set_cleanup, -EVP_MD_meth_set_ctrl, EVP_MD_meth_get_input_blocksize, -EVP_MD_meth_get_result_size, EVP_MD_meth_get_app_datasize, -EVP_MD_meth_get_flags, EVP_MD_meth_get_init, EVP_MD_meth_get_update, -EVP_MD_meth_get_final, EVP_MD_meth_get_copy, EVP_MD_meth_get_cleanup, -EVP_MD_meth_get_ctrl -\&\- Routines to build up legacy EVP_MD methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& EVP_MD *EVP_MD_meth_new(int md_type, int pkey_type); -\& void EVP_MD_meth_free(EVP_MD *md); -\& EVP_MD *EVP_MD_meth_dup(const EVP_MD *md); -\& -\& int EVP_MD_meth_set_input_blocksize(EVP_MD *md, int blocksize); -\& int EVP_MD_meth_set_result_size(EVP_MD *md, int resultsize); -\& int EVP_MD_meth_set_app_datasize(EVP_MD *md, int datasize); -\& int EVP_MD_meth_set_flags(EVP_MD *md, unsigned long flags); -\& int EVP_MD_meth_set_init(EVP_MD *md, int (*init)(EVP_MD_CTX *ctx)); -\& int EVP_MD_meth_set_update(EVP_MD *md, int (*update)(EVP_MD_CTX *ctx, -\& const void *data, -\& size_t count)); -\& int EVP_MD_meth_set_final(EVP_MD *md, int (*final)(EVP_MD_CTX *ctx, -\& unsigned char *md)); -\& int EVP_MD_meth_set_copy(EVP_MD *md, int (*copy)(EVP_MD_CTX *to, -\& const EVP_MD_CTX *from)); -\& int EVP_MD_meth_set_cleanup(EVP_MD *md, int (*cleanup)(EVP_MD_CTX *ctx)); -\& int EVP_MD_meth_set_ctrl(EVP_MD *md, int (*ctrl)(EVP_MD_CTX *ctx, int cmd, -\& int p1, void *p2)); -\& -\& int EVP_MD_meth_get_input_blocksize(const EVP_MD *md); -\& int EVP_MD_meth_get_result_size(const EVP_MD *md); -\& int EVP_MD_meth_get_app_datasize(const EVP_MD *md); -\& unsigned long EVP_MD_meth_get_flags(const EVP_MD *md); -\& int (*EVP_MD_meth_get_init(const EVP_MD *md))(EVP_MD_CTX *ctx); -\& int (*EVP_MD_meth_get_update(const EVP_MD *md))(EVP_MD_CTX *ctx, -\& const void *data, -\& size_t count); -\& int (*EVP_MD_meth_get_final(const EVP_MD *md))(EVP_MD_CTX *ctx, -\& unsigned char *md); -\& int (*EVP_MD_meth_get_copy(const EVP_MD *md))(EVP_MD_CTX *to, -\& const EVP_MD_CTX *from); -\& int (*EVP_MD_meth_get_cleanup(const EVP_MD *md))(EVP_MD_CTX *ctx); -\& int (*EVP_MD_meth_get_ctrl(const EVP_MD *md))(EVP_MD_CTX *ctx, int cmd, -\& int p1, void *p2); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the \s-1OSSL_PROVIDER\s0 APIs. -.PP -The \fB\s-1EVP_MD\s0\fR type is a structure for digest method implementation. -It can also have associated public/private key signing and verifying -routines. -.PP -\&\fBEVP_MD_meth_new()\fR creates a new \fB\s-1EVP_MD\s0\fR structure. -These \fB\s-1EVP_MD\s0\fR structures are reference counted. -.PP -\&\fBEVP_MD_meth_dup()\fR creates a copy of \fBmd\fR. -.PP -\&\fBEVP_MD_meth_free()\fR decrements the reference count for the \fB\s-1EVP_MD\s0\fR structure. -If the reference count drops to 0 then the structure is freed. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_MD_meth_set_input_blocksize()\fR sets the internal input block size -for the method \fBmd\fR to \fBblocksize\fR bytes. -.PP -\&\fBEVP_MD_meth_set_result_size()\fR sets the size of the result that the -digest method in \fBmd\fR is expected to produce to \fBresultsize\fR bytes. -.PP -The digest method may have its own private data, which OpenSSL will -allocate for it. \fBEVP_MD_meth_set_app_datasize()\fR should be used to -set the size for it to \fBdatasize\fR. -.PP -\&\fBEVP_MD_meth_set_flags()\fR sets the flags to describe optional -behaviours in the particular \fBmd\fR. Several flags can be or'd -together. The available flags are: -.IP "\s-1EVP_MD_FLAG_ONESHOT\s0" 4 -.IX Item "EVP_MD_FLAG_ONESHOT" -This digest method can only handle one block of input. -.IP "\s-1EVP_MD_FLAG_XOF\s0" 4 -.IX Item "EVP_MD_FLAG_XOF" -This digest method is an extensible-output function (\s-1XOF\s0) and supports -the \fB\s-1EVP_MD_CTRL_XOF_LEN\s0\fR control. -.IP "\s-1EVP_MD_FLAG_DIGALGID_NULL\s0" 4 -.IX Item "EVP_MD_FLAG_DIGALGID_NULL" -When setting up a DigestAlgorithmIdentifier, this flag will have the -parameter set to \s-1NULL\s0 by default. Use this for PKCS#1. \fINote: if -combined with \s-1EVP_MD_FLAG_DIGALGID_ABSENT,\s0 the latter will override.\fR -.IP "\s-1EVP_MD_FLAG_DIGALGID_ABSENT\s0" 4 -.IX Item "EVP_MD_FLAG_DIGALGID_ABSENT" -When setting up a DigestAlgorithmIdentifier, this flag will have the -parameter be left absent by default. \fINote: if combined with -\&\s-1EVP_MD_FLAG_DIGALGID_NULL,\s0 the latter will be overridden.\fR -.IP "\s-1EVP_MD_FLAG_DIGALGID_CUSTOM\s0" 4 -.IX Item "EVP_MD_FLAG_DIGALGID_CUSTOM" -Custom DigestAlgorithmIdentifier handling via ctrl, with -\&\fB\s-1EVP_MD_FLAG_DIGALGID_ABSENT\s0\fR as default. \fINote: if combined with -\&\s-1EVP_MD_FLAG_DIGALGID_NULL,\s0 the latter will be overridden.\fR -Currently unused. -.IP "\s-1EVP_MD_FLAG_FIPS\s0" 4 -.IX Item "EVP_MD_FLAG_FIPS" -This digest method is suitable for use in \s-1FIPS\s0 mode. -Currently unused. -.PP -\&\fBEVP_MD_meth_set_init()\fR sets the digest init function for \fBmd\fR. -The digest init function is called by \fBEVP_Digest()\fR, \fBEVP_DigestInit()\fR, -\&\fBEVP_DigestInit_ex()\fR, EVP_SignInit, \fBEVP_SignInit_ex()\fR, \fBEVP_VerifyInit()\fR -and \fBEVP_VerifyInit_ex()\fR. -.PP -\&\fBEVP_MD_meth_set_update()\fR sets the digest update function for \fBmd\fR. -The digest update function is called by \fBEVP_Digest()\fR, \fBEVP_DigestUpdate()\fR and -\&\fBEVP_SignUpdate()\fR. -.PP -\&\fBEVP_MD_meth_set_final()\fR sets the digest final function for \fBmd\fR. -The digest final function is called by \fBEVP_Digest()\fR, \fBEVP_DigestFinal()\fR, -\&\fBEVP_DigestFinal_ex()\fR, \fBEVP_SignFinal()\fR and \fBEVP_VerifyFinal()\fR. -.PP -\&\fBEVP_MD_meth_set_copy()\fR sets the function for \fBmd\fR to do extra -computations after the method's private data structure has been copied -from one \fB\s-1EVP_MD_CTX\s0\fR to another. If all that's needed is to copy -the data, there is no need for this copy function. -Note that the copy function is passed two \fB\s-1EVP_MD_CTX\s0 *\fR, the private -data structure is then available with \fBEVP_MD_CTX_get0_md_data()\fR. -This copy function is called by \fBEVP_MD_CTX_copy()\fR and -\&\fBEVP_MD_CTX_copy_ex()\fR. -.PP -\&\fBEVP_MD_meth_set_cleanup()\fR sets the function for \fBmd\fR to do extra -cleanup before the method's private data structure is cleaned out and -freed. -Note that the cleanup function is passed a \fB\s-1EVP_MD_CTX\s0 *\fR, the -private data structure is then available with \fBEVP_MD_CTX_get0_md_data()\fR. -This cleanup function is called by \fBEVP_MD_CTX_reset()\fR and -\&\fBEVP_MD_CTX_free()\fR. -.PP -\&\fBEVP_MD_meth_set_ctrl()\fR sets the control function for \fBmd\fR. -See \fBEVP_MD_CTX_ctrl\fR\|(3) for the available controls. -.PP -\&\fBEVP_MD_meth_get_input_blocksize()\fR, \fBEVP_MD_meth_get_result_size()\fR, -\&\fBEVP_MD_meth_get_app_datasize()\fR, \fBEVP_MD_meth_get_flags()\fR, -\&\fBEVP_MD_meth_get_init()\fR, \fBEVP_MD_meth_get_update()\fR, -\&\fBEVP_MD_meth_get_final()\fR, \fBEVP_MD_meth_get_copy()\fR, -\&\fBEVP_MD_meth_get_cleanup()\fR and \fBEVP_MD_meth_get_ctrl()\fR are all used -to retrieve the method data given with the EVP_MD_meth_set_*() -functions above. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_MD_meth_new()\fR and \fBEVP_MD_meth_dup()\fR return a pointer to a newly -created \fB\s-1EVP_MD\s0\fR, or \s-1NULL\s0 on failure. -All EVP_MD_meth_set_*() functions return 1. -\&\fBEVP_MD_get_input_blocksize()\fR, \fBEVP_MD_meth_get_result_size()\fR, -\&\fBEVP_MD_meth_get_app_datasize()\fR and \fBEVP_MD_meth_get_flags()\fR return the -indicated sizes or flags. -All other EVP_CIPHER_meth_get_*() functions return pointers to their -respective \fBmd\fR function. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestInit\fR\|(3), \fBEVP_SignInit\fR\|(3), \fBEVP_VerifyInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -The \fB\s-1EVP_MD\s0\fR structure was openly available in OpenSSL before version -1.1. -The functions described here were added in OpenSSL 1.1. -The \fB\s-1EVP_MD\s0\fR structure created with these functions became reference -counted in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_app_datasize.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_app_datasize.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_app_datasize.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_cleanup.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_cleanup.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_copy.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_copy.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_ctrl.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_ctrl.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_final.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_final.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_final.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_flags.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_flags.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_init.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_init.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_input_blocksize.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_input_blocksize.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_input_blocksize.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_result_size.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_result_size.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_result_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_meth_set_update.3ossl b/openssl-install/share/man/man3/EVP_MD_meth_set_update.3ossl deleted file mode 120000 index c97cdc36..00000000 --- a/openssl-install/share/man/man3/EVP_MD_meth_set_update.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_name.3ossl b/openssl-install/share/man/man3/EVP_MD_name.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_MD_names_do_all.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_nid.3ossl b/openssl-install/share/man/man3/EVP_MD_nid.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_pkey_type.3ossl b/openssl-install/share/man/man3/EVP_MD_pkey_type.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_pkey_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_MD_settable_ctx_params.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_size.3ossl b/openssl-install/share/man/man3/EVP_MD_size.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_type.3ossl b/openssl-install/share/man/man3/EVP_MD_type.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_up_ref.3ossl b/openssl-install/share/man/man3/EVP_MD_up_ref.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_MD_xof.3ossl b/openssl-install/share/man/man3/EVP_MD_xof.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_MD_xof.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_OpenFinal.3ossl b/openssl-install/share/man/man3/EVP_OpenFinal.3ossl deleted file mode 120000 index c2405833..00000000 --- a/openssl-install/share/man/man3/EVP_OpenFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_OpenInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_OpenInit.3ossl b/openssl-install/share/man/man3/EVP_OpenInit.3ossl deleted file mode 100644 index 78ffd5fd..00000000 --- a/openssl-install/share/man/man3/EVP_OpenInit.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_OPENINIT 3ossl" -.TH EVP_OPENINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_OpenInit, EVP_OpenUpdate, EVP_OpenFinal \- EVP envelope decryption -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_OpenInit(EVP_CIPHER_CTX *ctx, EVP_CIPHER *type, unsigned char *ek, -\& int ekl, unsigned char *iv, EVP_PKEY *priv); -\& int EVP_OpenUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, -\& int *outl, unsigned char *in, int inl); -\& int EVP_OpenFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 envelope routines are a high-level interface to envelope -decryption. They decrypt a public key encrypted symmetric key and -then decrypt data using it. -.PP -\&\fBEVP_OpenInit()\fR initializes a cipher context \fBctx\fR for decryption -with cipher \fBtype\fR. It decrypts the encrypted symmetric key of length -\&\fBekl\fR bytes passed in the \fBek\fR parameter using the private key \fBpriv\fR. -The \s-1IV\s0 is supplied in the \fBiv\fR parameter. -.PP -\&\fBEVP_OpenUpdate()\fR and \fBEVP_OpenFinal()\fR have exactly the same properties -as the \fBEVP_DecryptUpdate()\fR and \fBEVP_DecryptFinal()\fR routines, as -documented on the \fBEVP_EncryptInit\fR\|(3) manual -page. -.SH "NOTES" -.IX Header "NOTES" -It is possible to call \fBEVP_OpenInit()\fR twice in the same way as -\&\fBEVP_DecryptInit()\fR. The first call should have \fBpriv\fR set to \s-1NULL\s0 -and (after setting any cipher parameters) it should be called again -with \fBtype\fR set to \s-1NULL.\s0 -.PP -If the cipher passed in the \fBtype\fR parameter is a variable length -cipher then the key length will be set to the value of the recovered -key length. If the cipher is a fixed length cipher then the recovered -key length must match the fixed cipher length. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_OpenInit()\fR returns 0 on error or a non zero integer (actually the -recovered secret key size) if successful. -.PP -\&\fBEVP_OpenUpdate()\fR returns 1 for success or 0 for failure. -.PP -\&\fBEVP_OpenFinal()\fR returns 0 if the decrypt failed or 1 for success. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), \fBRAND_bytes\fR\|(3), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_SealInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_OpenUpdate.3ossl b/openssl-install/share/man/man3/EVP_OpenUpdate.3ossl deleted file mode 120000 index c2405833..00000000 --- a/openssl-install/share/man/man3/EVP_OpenUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_OpenInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PBE_CipherInit.3ossl b/openssl-install/share/man/man3/EVP_PBE_CipherInit.3ossl deleted file mode 100644 index d1629964..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_CipherInit.3ossl +++ /dev/null @@ -1,229 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PBE_CIPHERINIT 3ossl" -.TH EVP_PBE_CIPHERINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PBE_CipherInit, EVP_PBE_CipherInit_ex, -EVP_PBE_find, EVP_PBE_find_ex, -EVP_PBE_alg_add_type, EVP_PBE_alg_add \- Password based encryption routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PBE_CipherInit(ASN1_OBJECT *pbe_obj, const char *pass, int passlen, -\& ASN1_TYPE *param, EVP_CIPHER_CTX *ctx, int en_de); -\& int EVP_PBE_CipherInit_ex(ASN1_OBJECT *pbe_obj, const char *pass, int passlen, -\& ASN1_TYPE *param, EVP_CIPHER_CTX *ctx, int en_de, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& -\& int EVP_PBE_find(int type, int pbe_nid, int *pcnid, int *pmnid, -\& EVP_PBE_KEYGEN **pkeygen); -\& int EVP_PBE_find_ex(int type, int pbe_nid, int *pcnid, int *pmnid, -\& EVP_PBE_KEYGEN **pkeygen, EVP_PBE_KEYGEN_EX **keygen_ex); -\& -\& int EVP_PBE_alg_add_type(int pbe_type, int pbe_nid, int cipher_nid, -\& int md_nid, EVP_PBE_KEYGEN *keygen); -\& int EVP_PBE_alg_add(int nid, const EVP_CIPHER *cipher, const EVP_MD *md, -\& EVP_PBE_KEYGEN *keygen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -.SS "\s-1PBE\s0 operations" -.IX Subsection "PBE operations" -\&\fBEVP_PBE_CipherInit()\fR and \fBEVP_PBE_CipherInit_ex()\fR initialise an \fB\s-1EVP_CIPHER_CTX\s0\fR -\&\fIctx\fR for encryption (\fIen_de\fR=1) or decryption (\fIen_de\fR=0) using the password -\&\fIpass\fR of length \fIpasslen\fR. The \s-1PBE\s0 algorithm type and parameters are extracted -from an \s-1OID\s0 \fIpbe_obj\fR and parameters \fIparam\fR. -.PP -\&\fBEVP_PBE_CipherInit_ex()\fR also allows the application to specify a library context -\&\fIlibctx\fR and property query \fIpropq\fR to select appropriate algorithm -implementations. -.SS "\s-1PBE\s0 algorithm search" -.IX Subsection "PBE algorithm search" -\&\fBEVP_PBE_find()\fR and \fBEVP_PBE_find_ex()\fR search for a matching algorithm using two parameters: -.PP -1. An algorithm type \fItype\fR which can be: -.IP "\(bu" 4 -\&\s-1EVP_PBE_TYPE_OUTER\s0 \- A \s-1PBE\s0 algorithm -.IP "\(bu" 4 -\&\s-1EVP_PBE_TYPE_PRF\s0 \- A pseudo-random function -.IP "\(bu" 4 -\&\s-1EVP_PBE_TYPE_KDF\s0 \- A key derivation function -.PP -2. A \fIpbe_nid\fR which can represent the algorithm identifier with parameters e.g. -\&\fBNID_pbeWithSHA1AndRC2_CBC\fR or an algorithm class e.g. \fBNID_pbes2\fR. -.PP -They return the algorithm's cipher \s-1ID\s0 \fIpcnid\fR, digest \s-1ID\s0 \fIpmnid\fR and a key -generation function for the algorithm \fIpkeygen\fR. \fBEVP_PBE_CipherInit_ex()\fR also -returns an extended key generation function \fIkeygen_ex\fR which takes a library -context and property query. -.PP -If a \s-1NULL\s0 is supplied for any of \fIpcnid\fR, \fIpmnid\fR, \fIpkeygen\fR or \fIpkeygen_ex\fR -then this parameter is not returned. -.SS "\s-1PBE\s0 algorithm add" -.IX Subsection "PBE algorithm add" -\&\fBEVP_PBE_alg_add_type()\fR and \fBEVP_PBE_alg_add()\fR add an algorithm to the list -of known algorithms. Their parameters have the same meaning as for -\&\fBEVP_PBE_find()\fR and \fBEVP_PBE_find_ex()\fR functions. -.SH "NOTES" -.IX Header "NOTES" -The arguments \fIpbe_obj\fR and \fIparam\fR to \fBEVP_PBE_CipherInit()\fR and \fBEVP_PBE_CipherInit_ex()\fR -together form an \fBX509_ALGOR\fR and can often be extracted directly from this structure. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Return value is 1 for success and 0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS5_PBE_keyivgen\fR\|(3), -\&\fBPKCS12_PBE_keyivgen_ex\fR\|(3), -\&\fBPKCS5_v2_PBE_keyivgen_ex\fR\|(3), -\&\fBPKCS12_pbe_crypt_ex\fR\|(3), -\&\fBPKCS12_create_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_PBE_CipherInit_ex()\fR and \fBEVP_PBE_find_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PBE_CipherInit_ex.3ossl b/openssl-install/share/man/man3/EVP_PBE_CipherInit_ex.3ossl deleted file mode 120000 index a94ee5ef..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_CipherInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PBE_CipherInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PBE_alg_add.3ossl b/openssl-install/share/man/man3/EVP_PBE_alg_add.3ossl deleted file mode 120000 index a94ee5ef..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_alg_add.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PBE_CipherInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PBE_alg_add_type.3ossl b/openssl-install/share/man/man3/EVP_PBE_alg_add_type.3ossl deleted file mode 120000 index a94ee5ef..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_alg_add_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PBE_CipherInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PBE_find.3ossl b/openssl-install/share/man/man3/EVP_PBE_find.3ossl deleted file mode 120000 index a94ee5ef..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PBE_CipherInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PBE_find_ex.3ossl b/openssl-install/share/man/man3/EVP_PBE_find_ex.3ossl deleted file mode 120000 index a94ee5ef..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_find_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PBE_CipherInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PBE_scrypt.3ossl b/openssl-install/share/man/man3/EVP_PBE_scrypt.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_scrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PBE_scrypt_ex.3ossl b/openssl-install/share/man/man3/EVP_PBE_scrypt_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/EVP_PBE_scrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKCS82PKEY.3ossl b/openssl-install/share/man/man3/EVP_PKCS82PKEY.3ossl deleted file mode 120000 index 8ea28937..00000000 --- a/openssl-install/share/man/man3/EVP_PKCS82PKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY2PKCS8.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKCS82PKEY_ex.3ossl b/openssl-install/share/man/man3/EVP_PKCS82PKEY_ex.3ossl deleted file mode 120000 index 8ea28937..00000000 --- a/openssl-install/share/man/man3/EVP_PKCS82PKEY_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY2PKCS8.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY.3ossl b/openssl-install/share/man/man3/EVP_PKEY.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY2PKCS8.3ossl b/openssl-install/share/man/man3/EVP_PKEY2PKCS8.3ossl deleted file mode 100644 index 77173552..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY2PKCS8.3ossl +++ /dev/null @@ -1,179 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY2PKCS8 3ossl" -.TH EVP_PKEY2PKCS8 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY2PKCS8, EVP_PKCS82PKEY_ex, EVP_PKCS82PKEY -\&\- Convert a private key to/from PKCS8 -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS8_PRIV_KEY_INFO *EVP_PKEY2PKCS8(const EVP_PKEY *pkey); -\& EVP_PKEY *EVP_PKCS82PKEY(const PKCS8_PRIV_KEY_INFO *p8); -\& EVP_PKEY *EVP_PKCS82PKEY_ex(const PKCS8_PRIV_KEY_INFO *p8, OSSL_LIB_CTX *libctx, -\& const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1\fBEVP_PKEY2PKCS8\s0()\fR converts a private key \fIpkey\fR into a returned \s-1PKCS8\s0 object. -.PP -\&\fBEVP_PKCS82PKEY_ex()\fR converts a \s-1PKCS8\s0 object \fIp8\fR into a returned private key. -It uses \fIlibctx\fR and \fIpropq\fR when fetching algorithms. -.PP -\&\s-1\fBEVP_PKCS82PKEY\s0()\fR is similar to \fBEVP_PKCS82PKEY_ex()\fR but uses default values of -\&\s-1NULL\s0 for the \fIlibctx\fR and \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1\fBEVP_PKEY2PKCS8\s0()\fR returns a \s-1PKCS8\s0 object on success. -\&\s-1\fBEVP_PKCS82PKEY\s0()\fR and \fBEVP_PKCS82PKEY_ex()\fR return a private key on success. -.PP -All functions return \s-1NULL\s0 if the operation fails. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS8_pkey_add1_attr\fR\|(3), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_ASN1_METHOD.3ossl b/openssl-install/share/man/man3/EVP_PKEY_ASN1_METHOD.3ossl deleted file mode 100644 index 68f76479..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_ASN1_METHOD.3ossl +++ /dev/null @@ -1,592 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_ASN1_METHOD 3ossl" -.TH EVP_PKEY_ASN1_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_ASN1_METHOD, -EVP_PKEY_asn1_new, -EVP_PKEY_asn1_copy, -EVP_PKEY_asn1_free, -EVP_PKEY_asn1_add0, -EVP_PKEY_asn1_add_alias, -EVP_PKEY_asn1_set_public, -EVP_PKEY_asn1_set_private, -EVP_PKEY_asn1_set_param, -EVP_PKEY_asn1_set_free, -EVP_PKEY_asn1_set_ctrl, -EVP_PKEY_asn1_set_item, -EVP_PKEY_asn1_set_siginf, -EVP_PKEY_asn1_set_check, -EVP_PKEY_asn1_set_public_check, -EVP_PKEY_asn1_set_param_check, -EVP_PKEY_asn1_set_security_bits, -EVP_PKEY_asn1_set_set_priv_key, -EVP_PKEY_asn1_set_set_pub_key, -EVP_PKEY_asn1_set_get_priv_key, -EVP_PKEY_asn1_set_get_pub_key, -EVP_PKEY_get0_asn1 -\&\- manipulating and registering EVP_PKEY_ASN1_METHOD structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct evp_pkey_asn1_method_st EVP_PKEY_ASN1_METHOD; -\& -\& EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_new(int id, int flags, -\& const char *pem_str, -\& const char *info); -\& void EVP_PKEY_asn1_copy(EVP_PKEY_ASN1_METHOD *dst, -\& const EVP_PKEY_ASN1_METHOD *src); -\& void EVP_PKEY_asn1_free(EVP_PKEY_ASN1_METHOD *ameth); -\& int EVP_PKEY_asn1_add0(const EVP_PKEY_ASN1_METHOD *ameth); -\& int EVP_PKEY_asn1_add_alias(int to, int from); -\& -\& void EVP_PKEY_asn1_set_public(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*pub_decode) (EVP_PKEY *pk, -\& const X509_PUBKEY *pub), -\& int (*pub_encode) (X509_PUBKEY *pub, -\& const EVP_PKEY *pk), -\& int (*pub_cmp) (const EVP_PKEY *a, -\& const EVP_PKEY *b), -\& int (*pub_print) (BIO *out, -\& const EVP_PKEY *pkey, -\& int indent, ASN1_PCTX *pctx), -\& int (*pkey_size) (const EVP_PKEY *pk), -\& int (*pkey_bits) (const EVP_PKEY *pk)); -\& void EVP_PKEY_asn1_set_private(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*priv_decode) (EVP_PKEY *pk, -\& const PKCS8_PRIV_KEY_INFO -\& *p8inf), -\& int (*priv_encode) (PKCS8_PRIV_KEY_INFO *p8, -\& const EVP_PKEY *pk), -\& int (*priv_print) (BIO *out, -\& const EVP_PKEY *pkey, -\& int indent, -\& ASN1_PCTX *pctx)); -\& void EVP_PKEY_asn1_set_param(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*param_decode) (EVP_PKEY *pkey, -\& const unsigned char **pder, -\& int derlen), -\& int (*param_encode) (const EVP_PKEY *pkey, -\& unsigned char **pder), -\& int (*param_missing) (const EVP_PKEY *pk), -\& int (*param_copy) (EVP_PKEY *to, -\& const EVP_PKEY *from), -\& int (*param_cmp) (const EVP_PKEY *a, -\& const EVP_PKEY *b), -\& int (*param_print) (BIO *out, -\& const EVP_PKEY *pkey, -\& int indent, -\& ASN1_PCTX *pctx)); -\& -\& void EVP_PKEY_asn1_set_free(EVP_PKEY_ASN1_METHOD *ameth, -\& void (*pkey_free) (EVP_PKEY *pkey)); -\& void EVP_PKEY_asn1_set_ctrl(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*pkey_ctrl) (EVP_PKEY *pkey, int op, -\& long arg1, void *arg2)); -\& void EVP_PKEY_asn1_set_item(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*item_verify) (EVP_MD_CTX *ctx, -\& const ASN1_ITEM *it, -\& void *asn, -\& X509_ALGOR *a, -\& ASN1_BIT_STRING *sig, -\& EVP_PKEY *pkey), -\& int (*item_sign) (EVP_MD_CTX *ctx, -\& const ASN1_ITEM *it, -\& void *asn, -\& X509_ALGOR *alg1, -\& X509_ALGOR *alg2, -\& ASN1_BIT_STRING *sig)); -\& -\& void EVP_PKEY_asn1_set_siginf(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*siginf_set) (X509_SIG_INFO *siginf, -\& const X509_ALGOR *alg, -\& const ASN1_STRING *sig)); -\& -\& void EVP_PKEY_asn1_set_check(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*pkey_check) (const EVP_PKEY *pk)); -\& -\& void EVP_PKEY_asn1_set_public_check(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*pkey_pub_check) (const EVP_PKEY *pk)); -\& -\& void EVP_PKEY_asn1_set_param_check(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*pkey_param_check) (const EVP_PKEY *pk)); -\& -\& void EVP_PKEY_asn1_set_security_bits(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*pkey_security_bits) (const EVP_PKEY -\& *pk)); -\& -\& void EVP_PKEY_asn1_set_set_priv_key(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*set_priv_key) (EVP_PKEY *pk, -\& const unsigned char -\& *priv, -\& size_t len)); -\& -\& void EVP_PKEY_asn1_set_set_pub_key(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*set_pub_key) (EVP_PKEY *pk, -\& const unsigned char *pub, -\& size_t len)); -\& -\& void EVP_PKEY_asn1_set_get_priv_key(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*get_priv_key) (const EVP_PKEY *pk, -\& unsigned char *priv, -\& size_t *len)); -\& -\& void EVP_PKEY_asn1_set_get_pub_key(EVP_PKEY_ASN1_METHOD *ameth, -\& int (*get_pub_key) (const EVP_PKEY *pk, -\& unsigned char *pub, -\& size_t *len)); -\& -\& const EVP_PKEY_ASN1_METHOD *EVP_PKEY_get0_asn1(const EVP_PKEY *pkey); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR is a structure which holds a set of \s-1ASN.1\s0 -conversion, printing and information methods for a specific public key -algorithm. -.PP -There are two places where the \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR objects are -stored: one is a built-in array representing the standard methods for -different algorithms, and the other one is a stack of user-defined -application-specific methods, which can be manipulated by using -\&\fBEVP_PKEY_asn1_add0\fR\|(3). -.SS "Methods" -.IX Subsection "Methods" -The methods are the underlying implementations of a particular public -key algorithm present by the \fB\s-1EVP_PKEY\s0\fR object. -.PP -.Vb 5 -\& int (*pub_decode) (EVP_PKEY *pk, const X509_PUBKEY *pub); -\& int (*pub_encode) (X509_PUBKEY *pub, const EVP_PKEY *pk); -\& int (*pub_cmp) (const EVP_PKEY *a, const EVP_PKEY *b); -\& int (*pub_print) (BIO *out, const EVP_PKEY *pkey, int indent, -\& ASN1_PCTX *pctx); -.Ve -.PP -The \fBpub_decode()\fR and \fBpub_encode()\fR methods are called to decode / -encode \fBX509_PUBKEY\fR \s-1ASN.1\s0 parameters to / from \fBpk\fR. -They \s-1MUST\s0 return 0 on error, 1 on success. -They're called by \fBX509_PUBKEY_get0\fR\|(3) and \fBX509_PUBKEY_set\fR\|(3). -.PP -The \fBpub_cmp()\fR method is called when two public keys are to be -compared. -It \s-1MUST\s0 return 1 when the keys are equal, 0 otherwise. -It's called by \fBEVP_PKEY_eq\fR\|(3). -.PP -The \fBpub_print()\fR method is called to print a public key in humanly -readable text to \fBout\fR, indented \fBindent\fR spaces. -It \s-1MUST\s0 return 0 on error, 1 on success. -It's called by \fBEVP_PKEY_print_public\fR\|(3). -.PP -.Vb 4 -\& int (*priv_decode) (EVP_PKEY *pk, const PKCS8_PRIV_KEY_INFO *p8inf); -\& int (*priv_encode) (PKCS8_PRIV_KEY_INFO *p8, const EVP_PKEY *pk); -\& int (*priv_print) (BIO *out, const EVP_PKEY *pkey, int indent, -\& ASN1_PCTX *pctx); -.Ve -.PP -The \fBpriv_decode()\fR and \fBpriv_encode()\fR methods are called to decode / -encode \fB\s-1PKCS8_PRIV_KEY_INFO\s0\fR form private key to / from \fBpk\fR. -They \s-1MUST\s0 return 0 on error, 1 on success. -They're called by \s-1\fBEVP_PKCS82PKEY\s0\fR\|(3) and \s-1\fBEVP_PKEY2PKCS8\s0\fR\|(3). -.PP -The \fBpriv_print()\fR method is called to print a private key in humanly -readable text to \fBout\fR, indented \fBindent\fR spaces. -It \s-1MUST\s0 return 0 on error, 1 on success. -It's called by \fBEVP_PKEY_print_private\fR\|(3). -.PP -.Vb 3 -\& int (*pkey_size) (const EVP_PKEY *pk); -\& int (*pkey_bits) (const EVP_PKEY *pk); -\& int (*pkey_security_bits) (const EVP_PKEY *pk); -.Ve -.PP -The \fBpkey_size()\fR method returns the key size in bytes. -It's called by \fBEVP_PKEY_get_size\fR\|(3). -.PP -The \fBpkey_bits()\fR method returns the key size in bits. -It's called by \fBEVP_PKEY_get_bits\fR\|(3). -.PP -.Vb 8 -\& int (*param_decode) (EVP_PKEY *pkey, -\& const unsigned char **pder, int derlen); -\& int (*param_encode) (const EVP_PKEY *pkey, unsigned char **pder); -\& int (*param_missing) (const EVP_PKEY *pk); -\& int (*param_copy) (EVP_PKEY *to, const EVP_PKEY *from); -\& int (*param_cmp) (const EVP_PKEY *a, const EVP_PKEY *b); -\& int (*param_print) (BIO *out, const EVP_PKEY *pkey, int indent, -\& ASN1_PCTX *pctx); -.Ve -.PP -The \fBparam_decode()\fR and \fBparam_encode()\fR methods are called to decode / -encode \s-1DER\s0 formatted parameters to / from \fBpk\fR. -They \s-1MUST\s0 return 0 on error, 1 on success. -They're called by \fBPEM_read_bio_Parameters\fR\|(3) and the \fBfile:\fR -\&\s-1\fBOSSL_STORE_LOADER\s0\fR\|(3). -.PP -The \fBparam_missing()\fR method returns 0 if a key parameter is missing, -otherwise 1. -It's called by \fBEVP_PKEY_missing_parameters\fR\|(3). -.PP -The \fBparam_copy()\fR method copies key parameters from \fBfrom\fR to \fBto\fR. -It \s-1MUST\s0 return 0 on error, 1 on success. -It's called by \fBEVP_PKEY_copy_parameters\fR\|(3). -.PP -The \fBparam_cmp()\fR method compares the parameters of keys \fBa\fR and \fBb\fR. -It \s-1MUST\s0 return 1 when the keys are equal, 0 when not equal, or a -negative number on error. -It's called by \fBEVP_PKEY_parameters_eq\fR\|(3). -.PP -The \fBparam_print()\fR method prints the private key parameters in humanly -readable text to \fBout\fR, indented \fBindent\fR spaces. -It \s-1MUST\s0 return 0 on error, 1 on success. -It's called by \fBEVP_PKEY_print_params\fR\|(3). -.PP -.Vb 3 -\& int (*sig_print) (BIO *out, -\& const X509_ALGOR *sigalg, const ASN1_STRING *sig, -\& int indent, ASN1_PCTX *pctx); -.Ve -.PP -The \fBsig_print()\fR method prints a signature in humanly readable text to -\&\fBout\fR, indented \fBindent\fR spaces. -\&\fBsigalg\fR contains the exact signature algorithm. -If the signature in \fBsig\fR doesn't correspond to what this method -expects, \fBX509_signature_dump()\fR must be used as a last resort. -It \s-1MUST\s0 return 0 on error, 1 on success. -It's called by \fBX509_signature_print\fR\|(3). -.PP -.Vb 1 -\& void (*pkey_free) (EVP_PKEY *pkey); -.Ve -.PP -The \fBpkey_free()\fR method helps freeing the internals of \fBpkey\fR. -It's called by \fBEVP_PKEY_free\fR\|(3), \fBEVP_PKEY_set_type\fR\|(3), -\&\fBEVP_PKEY_set_type_str\fR\|(3), and \fBEVP_PKEY_assign\fR\|(3). -.PP -.Vb 1 -\& int (*pkey_ctrl) (EVP_PKEY *pkey, int op, long arg1, void *arg2); -.Ve -.PP -The \fBpkey_ctrl()\fR method adds extra algorithm specific control. -It's called by \fBEVP_PKEY_get_default_digest_nid\fR\|(3), -\&\fBEVP_PKEY_set1_encoded_public_key\fR\|(3), -\&\fBEVP_PKEY_get1_encoded_public_key\fR\|(3), \fBPKCS7_SIGNER_INFO_set\fR\|(3), -\&\fBPKCS7_RECIP_INFO_set\fR\|(3), ... -.PP -.Vb 3 -\& int (*old_priv_decode) (EVP_PKEY *pkey, -\& const unsigned char **pder, int derlen); -\& int (*old_priv_encode) (const EVP_PKEY *pkey, unsigned char **pder); -.Ve -.PP -The \fBold_priv_decode()\fR and \fBold_priv_encode()\fR methods decode / encode -they private key \fBpkey\fR from / to a \s-1DER\s0 formatted array. -These are exclusively used to help decoding / encoding older (pre -PKCS#8) \s-1PEM\s0 formatted encrypted private keys. -\&\fBold_priv_decode()\fR \s-1MUST\s0 return 0 on error, 1 on success. -\&\fBold_priv_encode()\fR \s-1MUST\s0 the return same kind of values as -\&\fBi2d_PrivateKey()\fR. -They're called by \fBd2i_PrivateKey\fR\|(3) and \fBi2d_PrivateKey\fR\|(3). -.PP -.Vb 5 -\& int (*item_verify) (EVP_MD_CTX *ctx, const ASN1_ITEM *it, void *asn, -\& X509_ALGOR *a, ASN1_BIT_STRING *sig, EVP_PKEY *pkey); -\& int (*item_sign) (EVP_MD_CTX *ctx, const ASN1_ITEM *it, void *asn, -\& X509_ALGOR *alg1, X509_ALGOR *alg2, -\& ASN1_BIT_STRING *sig); -.Ve -.PP -The \fBitem_sign()\fR and \fBitem_verify()\fR methods make it possible to have -algorithm specific signatures and verification of them. -.PP -\&\fBitem_sign()\fR \s-1MUST\s0 return one of: -.IP "<=0" 4 -.IX Item "<=0" -error -.IP "1" 4 -.IX Item "1" -\&\fBitem_sign()\fR did everything, OpenSSL internals just needs to pass the -signature length back. -.IP "2" 4 -.IX Item "2" -\&\fBitem_sign()\fR did nothing, OpenSSL internal standard routines are -expected to continue with the default signature production. -.IP "3" 4 -.IX Item "3" -\&\fBitem_sign()\fR set the algorithm identifier \fBalgor1\fR and \fBalgor2\fR, -OpenSSL internals should just sign using those algorithms. -.PP -\&\fBitem_verify()\fR \s-1MUST\s0 return one of: -.IP "<=0" 4 -.IX Item "<=0" -error -.IP "1" 4 -.IX Item "1" -\&\fBitem_sign()\fR did everything, OpenSSL internals just needs to pass the -signature length back. -.IP "2" 4 -.IX Item "2" -\&\fBitem_sign()\fR did nothing, OpenSSL internal standard routines are -expected to continue with the default signature production. -.PP -\&\fBitem_verify()\fR and \fBitem_sign()\fR are called by \fBASN1_item_verify\fR\|(3) and -\&\fBASN1_item_sign\fR\|(3), and by extension, \fBX509_verify\fR\|(3), -\&\fBX509_REQ_verify\fR\|(3), \fBX509_sign\fR\|(3), \fBX509_REQ_sign\fR\|(3), ... -.PP -.Vb 2 -\& int (*siginf_set) (X509_SIG_INFO *siginf, const X509_ALGOR *alg, -\& const ASN1_STRING *sig); -.Ve -.PP -The \fBsiginf_set()\fR method is used to set custom \fBX509_SIG_INFO\fR -parameters. -It \s-1MUST\s0 return 0 on error, or 1 on success. -It's called as part of \fBX509_check_purpose\fR\|(3), \fBX509_check_ca\fR\|(3) -and \fBX509_check_issued\fR\|(3). -.PP -.Vb 3 -\& int (*pkey_check) (const EVP_PKEY *pk); -\& int (*pkey_public_check) (const EVP_PKEY *pk); -\& int (*pkey_param_check) (const EVP_PKEY *pk); -.Ve -.PP -The \fBpkey_check()\fR, \fBpkey_public_check()\fR and \fBpkey_param_check()\fR methods are used -to check the validity of \fBpk\fR for key-pair, public component and parameters, -respectively. -They \s-1MUST\s0 return 0 for an invalid key, or 1 for a valid key. -They are called by \fBEVP_PKEY_check\fR\|(3), \fBEVP_PKEY_public_check\fR\|(3) and -\&\fBEVP_PKEY_param_check\fR\|(3) respectively. -.PP -.Vb 2 -\& int (*set_priv_key) (EVP_PKEY *pk, const unsigned char *priv, size_t len); -\& int (*set_pub_key) (EVP_PKEY *pk, const unsigned char *pub, size_t len); -.Ve -.PP -The \fBset_priv_key()\fR and \fBset_pub_key()\fR methods are used to set the raw private and -public key data for an \s-1EVP_PKEY.\s0 They \s-1MUST\s0 return 0 on error, or 1 on success. -They are called by \fBEVP_PKEY_new_raw_private_key\fR\|(3), and -\&\fBEVP_PKEY_new_raw_public_key\fR\|(3) respectively. -.PP -.Vb 2 -\& size_t (*dirty) (const EVP_PKEY *pk); -\& void *(*export_to) (const EVP_PKEY *pk, EVP_KEYMGMT *keymgmt); -.Ve -.PP -\&\fBdirty_cnt()\fR returns the internal key's dirty count. -This can be used to synchronise different copies of the same keys. -.PP -The \fBexport_to()\fR method exports the key material from the given key to -a provider, through the \s-1\fBEVP_KEYMGMT\s0\fR\|(3) interface, if that provider -supports importing key material. -.SS "Functions" -.IX Subsection "Functions" -\&\fBEVP_PKEY_asn1_new()\fR creates and returns a new \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR -object, and associates the given \fBid\fR, \fBflags\fR, \fBpem_str\fR and -\&\fBinfo\fR. -\&\fBid\fR is a \s-1NID,\s0 \fBpem_str\fR is the \s-1PEM\s0 type string, \fBinfo\fR is a -descriptive string. -The following \fBflags\fR are supported: -.PP -.Vb 1 -\& ASN1_PKEY_SIGPARAM_NULL -.Ve -.PP -If \fB\s-1ASN1_PKEY_SIGPARAM_NULL\s0\fR is set, then the signature algorithm -parameters are given the type \fBV_ASN1_NULL\fR by default, otherwise -they will be given the type \fBV_ASN1_UNDEF\fR (i.e. the parameter is -omitted). -See \fBX509_ALGOR_set0\fR\|(3) for more information. -.PP -\&\fBEVP_PKEY_asn1_copy()\fR copies an \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR object from -\&\fBsrc\fR to \fBdst\fR. -This function is not thread safe, it's recommended to only use this -when initializing the application. -.PP -\&\fBEVP_PKEY_asn1_free()\fR frees an existing \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR pointed -by \fBameth\fR. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_PKEY_asn1_add0()\fR adds \fBameth\fR to the user defined stack of -methods unless another \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR with the same \s-1NID\s0 is -already there. -This function is not thread safe, it's recommended to only use this -when initializing the application. -.PP -\&\fBEVP_PKEY_asn1_add_alias()\fR creates an alias with the \s-1NID\s0 \fBto\fR for the -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR with \s-1NID\s0 \fBfrom\fR unless another -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR with the same \s-1NID\s0 is already added. -This function is not thread safe, it's recommended to only use this -when initializing the application. -.PP -\&\fBEVP_PKEY_asn1_set_public()\fR, \fBEVP_PKEY_asn1_set_private()\fR, -\&\fBEVP_PKEY_asn1_set_param()\fR, \fBEVP_PKEY_asn1_set_free()\fR, -\&\fBEVP_PKEY_asn1_set_ctrl()\fR, \fBEVP_PKEY_asn1_set_item()\fR, -\&\fBEVP_PKEY_asn1_set_siginf()\fR, \fBEVP_PKEY_asn1_set_check()\fR, -\&\fBEVP_PKEY_asn1_set_public_check()\fR, \fBEVP_PKEY_asn1_set_param_check()\fR, -\&\fBEVP_PKEY_asn1_set_security_bits()\fR, \fBEVP_PKEY_asn1_set_set_priv_key()\fR, -\&\fBEVP_PKEY_asn1_set_set_pub_key()\fR, \fBEVP_PKEY_asn1_set_get_priv_key()\fR and -\&\fBEVP_PKEY_asn1_set_get_pub_key()\fR set the diverse methods of the given -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR object. -.PP -\&\fBEVP_PKEY_get0_asn1()\fR finds the \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR associated -with the key \fBpkey\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_asn1_new()\fR returns \s-1NULL\s0 on error, or a pointer to an -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR object otherwise. -.PP -\&\fBEVP_PKEY_asn1_add0()\fR and \fBEVP_PKEY_asn1_add_alias()\fR return 0 on error, -or 1 on success. -.PP -\&\fBEVP_PKEY_get0_asn1()\fR returns \s-1NULL\s0 on error, or a pointer to a constant -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR object otherwise. -.SH "HISTORY" -.IX Header "HISTORY" -The signature of the \fIpub_decode\fR functional argument of -\&\fBEVP_PKEY_asn1_set_public()\fR has changed in OpenSSL 3.0 so its \fIpub\fR -parameter is now constified. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_add1_hkdf_info.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_add1_hkdf_info.3ossl deleted file mode 120000 index 7a8f3fab..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_add1_hkdf_info.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_hkdf_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_add1_tls1_prf_seed.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_add1_tls1_prf_seed.3ossl deleted file mode 120000 index 908a3430..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_add1_tls1_prf_seed.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_tls1_prf_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl.3ossl deleted file mode 100644 index ad76110f..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl.3ossl +++ /dev/null @@ -1,818 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_CTRL 3ossl" -.TH EVP_PKEY_CTX_CTRL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_ctrl, -EVP_PKEY_CTX_ctrl_str, -EVP_PKEY_CTX_ctrl_uint64, -EVP_PKEY_CTX_md, -EVP_PKEY_CTX_set_signature_md, -EVP_PKEY_CTX_get_signature_md, -EVP_PKEY_CTX_set_mac_key, -EVP_PKEY_CTX_set_group_name, -EVP_PKEY_CTX_get_group_name, -EVP_PKEY_CTX_set_rsa_padding, -EVP_PKEY_CTX_get_rsa_padding, -EVP_PKEY_CTX_set_rsa_pss_saltlen, -EVP_PKEY_CTX_get_rsa_pss_saltlen, -EVP_PKEY_CTX_set_rsa_keygen_bits, -EVP_PKEY_CTX_set_rsa_keygen_pubexp, -EVP_PKEY_CTX_set1_rsa_keygen_pubexp, -EVP_PKEY_CTX_set_rsa_keygen_primes, -EVP_PKEY_CTX_set_rsa_mgf1_md_name, -EVP_PKEY_CTX_set_rsa_mgf1_md, -EVP_PKEY_CTX_get_rsa_mgf1_md, -EVP_PKEY_CTX_get_rsa_mgf1_md_name, -EVP_PKEY_CTX_set_rsa_oaep_md_name, -EVP_PKEY_CTX_set_rsa_oaep_md, -EVP_PKEY_CTX_get_rsa_oaep_md, -EVP_PKEY_CTX_get_rsa_oaep_md_name, -EVP_PKEY_CTX_set0_rsa_oaep_label, -EVP_PKEY_CTX_get0_rsa_oaep_label, -EVP_PKEY_CTX_set_dsa_paramgen_bits, -EVP_PKEY_CTX_set_dsa_paramgen_q_bits, -EVP_PKEY_CTX_set_dsa_paramgen_md, -EVP_PKEY_CTX_set_dsa_paramgen_md_props, -EVP_PKEY_CTX_set_dsa_paramgen_gindex, -EVP_PKEY_CTX_set_dsa_paramgen_type, -EVP_PKEY_CTX_set_dsa_paramgen_seed, -EVP_PKEY_CTX_set_dh_paramgen_prime_len, -EVP_PKEY_CTX_set_dh_paramgen_subprime_len, -EVP_PKEY_CTX_set_dh_paramgen_generator, -EVP_PKEY_CTX_set_dh_paramgen_type, -EVP_PKEY_CTX_set_dh_paramgen_gindex, -EVP_PKEY_CTX_set_dh_paramgen_seed, -EVP_PKEY_CTX_set_dh_rfc5114, -EVP_PKEY_CTX_set_dhx_rfc5114, -EVP_PKEY_CTX_set_dh_pad, -EVP_PKEY_CTX_set_dh_nid, -EVP_PKEY_CTX_set_dh_kdf_type, -EVP_PKEY_CTX_get_dh_kdf_type, -EVP_PKEY_CTX_set0_dh_kdf_oid, -EVP_PKEY_CTX_get0_dh_kdf_oid, -EVP_PKEY_CTX_set_dh_kdf_md, -EVP_PKEY_CTX_get_dh_kdf_md, -EVP_PKEY_CTX_set_dh_kdf_outlen, -EVP_PKEY_CTX_get_dh_kdf_outlen, -EVP_PKEY_CTX_set0_dh_kdf_ukm, -EVP_PKEY_CTX_get0_dh_kdf_ukm, -EVP_PKEY_CTX_set_ec_paramgen_curve_nid, -EVP_PKEY_CTX_set_ec_param_enc, -EVP_PKEY_CTX_set_ecdh_cofactor_mode, -EVP_PKEY_CTX_get_ecdh_cofactor_mode, -EVP_PKEY_CTX_set_ecdh_kdf_type, -EVP_PKEY_CTX_get_ecdh_kdf_type, -EVP_PKEY_CTX_set_ecdh_kdf_md, -EVP_PKEY_CTX_get_ecdh_kdf_md, -EVP_PKEY_CTX_set_ecdh_kdf_outlen, -EVP_PKEY_CTX_get_ecdh_kdf_outlen, -EVP_PKEY_CTX_set0_ecdh_kdf_ukm, -EVP_PKEY_CTX_get0_ecdh_kdf_ukm, -EVP_PKEY_CTX_set1_id, EVP_PKEY_CTX_get1_id, EVP_PKEY_CTX_get1_id_len, -EVP_PKEY_CTX_set_kem_op -\&\- algorithm specific control operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_ctrl(EVP_PKEY_CTX *ctx, int keytype, int optype, -\& int cmd, int p1, void *p2); -\& int EVP_PKEY_CTX_ctrl_uint64(EVP_PKEY_CTX *ctx, int keytype, int optype, -\& int cmd, uint64_t value); -\& int EVP_PKEY_CTX_ctrl_str(EVP_PKEY_CTX *ctx, const char *type, -\& const char *value); -\& -\& int EVP_PKEY_CTX_md(EVP_PKEY_CTX *ctx, int optype, int cmd, const char *md); -\& -\& int EVP_PKEY_CTX_set_signature_md(EVP_PKEY_CTX *ctx, const EVP_MD *md); -\& int EVP_PKEY_CTX_get_signature_md(EVP_PKEY_CTX *ctx, const EVP_MD **pmd); -\& -\& int EVP_PKEY_CTX_set_mac_key(EVP_PKEY_CTX *ctx, const unsigned char *key, -\& int len); -\& int EVP_PKEY_CTX_set_group_name(EVP_PKEY_CTX *ctx, const char *name); -\& int EVP_PKEY_CTX_get_group_name(EVP_PKEY_CTX *ctx, char *name, size_t namelen); -\& -\& int EVP_PKEY_CTX_set_kem_op(EVP_PKEY_CTX *ctx, const char *op); -\& -\& #include -\& -\& int EVP_PKEY_CTX_set_rsa_padding(EVP_PKEY_CTX *ctx, int pad); -\& int EVP_PKEY_CTX_get_rsa_padding(EVP_PKEY_CTX *ctx, int *pad); -\& int EVP_PKEY_CTX_set_rsa_pss_saltlen(EVP_PKEY_CTX *ctx, int saltlen); -\& int EVP_PKEY_CTX_get_rsa_pss_saltlen(EVP_PKEY_CTX *ctx, int *saltlen); -\& int EVP_PKEY_CTX_set_rsa_keygen_bits(EVP_PKEY_CTX *ctx, int mbits); -\& int EVP_PKEY_CTX_set1_rsa_keygen_pubexp(EVP_PKEY_CTX *ctx, BIGNUM *pubexp); -\& int EVP_PKEY_CTX_set_rsa_keygen_primes(EVP_PKEY_CTX *ctx, int primes); -\& int EVP_PKEY_CTX_set_rsa_mgf1_md_name(EVP_PKEY_CTX *ctx, const char *mdname, -\& const char *mdprops); -\& int EVP_PKEY_CTX_set_rsa_mgf1_md(EVP_PKEY_CTX *ctx, const EVP_MD *md); -\& int EVP_PKEY_CTX_get_rsa_mgf1_md(EVP_PKEY_CTX *ctx, const EVP_MD **md); -\& int EVP_PKEY_CTX_get_rsa_mgf1_md_name(EVP_PKEY_CTX *ctx, char *name, -\& size_t namelen); -\& int EVP_PKEY_CTX_set_rsa_oaep_md_name(EVP_PKEY_CTX *ctx, const char *mdname, -\& const char *mdprops); -\& int EVP_PKEY_CTX_set_rsa_oaep_md(EVP_PKEY_CTX *ctx, const EVP_MD *md); -\& int EVP_PKEY_CTX_get_rsa_oaep_md(EVP_PKEY_CTX *ctx, const EVP_MD **md); -\& int EVP_PKEY_CTX_get_rsa_oaep_md_name(EVP_PKEY_CTX *ctx, char *name, -\& size_t namelen); -\& int EVP_PKEY_CTX_set0_rsa_oaep_label(EVP_PKEY_CTX *ctx, void *label, -\& int len); -\& int EVP_PKEY_CTX_get0_rsa_oaep_label(EVP_PKEY_CTX *ctx, unsigned char **label); -\& -\& #include -\& -\& int EVP_PKEY_CTX_set_dsa_paramgen_bits(EVP_PKEY_CTX *ctx, int nbits); -\& int EVP_PKEY_CTX_set_dsa_paramgen_q_bits(EVP_PKEY_CTX *ctx, int qbits); -\& int EVP_PKEY_CTX_set_dsa_paramgen_md(EVP_PKEY_CTX *ctx, const EVP_MD *md); -\& int EVP_PKEY_CTX_set_dsa_paramgen_md_props(EVP_PKEY_CTX *ctx, -\& const char *md_name, -\& const char *md_properties); -\& int EVP_PKEY_CTX_set_dsa_paramgen_type(EVP_PKEY_CTX *ctx, const char *name); -\& int EVP_PKEY_CTX_set_dsa_paramgen_gindex(EVP_PKEY_CTX *ctx, int gindex); -\& int EVP_PKEY_CTX_set_dsa_paramgen_seed(EVP_PKEY_CTX *ctx, -\& const unsigned char *seed, -\& size_t seedlen); -\& -\& #include -\& -\& int EVP_PKEY_CTX_set_dh_paramgen_prime_len(EVP_PKEY_CTX *ctx, int len); -\& int EVP_PKEY_CTX_set_dh_paramgen_subprime_len(EVP_PKEY_CTX *ctx, int len); -\& int EVP_PKEY_CTX_set_dh_paramgen_generator(EVP_PKEY_CTX *ctx, int gen); -\& int EVP_PKEY_CTX_set_dh_paramgen_type(EVP_PKEY_CTX *ctx, int type); -\& int EVP_PKEY_CTX_set_dh_pad(EVP_PKEY_CTX *ctx, int pad); -\& int EVP_PKEY_CTX_set_dh_nid(EVP_PKEY_CTX *ctx, int nid); -\& int EVP_PKEY_CTX_set_dh_rfc5114(EVP_PKEY_CTX *ctx, int rfc5114); -\& int EVP_PKEY_CTX_set_dhx_rfc5114(EVP_PKEY_CTX *ctx, int rfc5114); -\& int EVP_PKEY_CTX_set_dh_paramgen_gindex(EVP_PKEY_CTX *ctx, int gindex); -\& int EVP_PKEY_CTX_set_dh_paramgen_seed(EVP_PKEY_CTX *ctx, -\& const unsigned char *seed, -\& size_t seedlen); -\& int EVP_PKEY_CTX_set_dh_kdf_type(EVP_PKEY_CTX *ctx, int kdf); -\& int EVP_PKEY_CTX_get_dh_kdf_type(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_CTX_set0_dh_kdf_oid(EVP_PKEY_CTX *ctx, ASN1_OBJECT *oid); -\& int EVP_PKEY_CTX_get0_dh_kdf_oid(EVP_PKEY_CTX *ctx, ASN1_OBJECT **oid); -\& int EVP_PKEY_CTX_set_dh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD *md); -\& int EVP_PKEY_CTX_get_dh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD **md); -\& int EVP_PKEY_CTX_set_dh_kdf_outlen(EVP_PKEY_CTX *ctx, int len); -\& int EVP_PKEY_CTX_get_dh_kdf_outlen(EVP_PKEY_CTX *ctx, int *len); -\& int EVP_PKEY_CTX_set0_dh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char *ukm, int len); -\& -\& #include -\& -\& int EVP_PKEY_CTX_set_ec_paramgen_curve_nid(EVP_PKEY_CTX *ctx, int nid); -\& int EVP_PKEY_CTX_set_ec_param_enc(EVP_PKEY_CTX *ctx, int param_enc); -\& int EVP_PKEY_CTX_set_ecdh_cofactor_mode(EVP_PKEY_CTX *ctx, int cofactor_mode); -\& int EVP_PKEY_CTX_get_ecdh_cofactor_mode(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_CTX_set_ecdh_kdf_type(EVP_PKEY_CTX *ctx, int kdf); -\& int EVP_PKEY_CTX_get_ecdh_kdf_type(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_CTX_set_ecdh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD *md); -\& int EVP_PKEY_CTX_get_ecdh_kdf_md(EVP_PKEY_CTX *ctx, const EVP_MD **md); -\& int EVP_PKEY_CTX_set_ecdh_kdf_outlen(EVP_PKEY_CTX *ctx, int len); -\& int EVP_PKEY_CTX_get_ecdh_kdf_outlen(EVP_PKEY_CTX *ctx, int *len); -\& int EVP_PKEY_CTX_set0_ecdh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char *ukm, int len); -\& -\& int EVP_PKEY_CTX_set1_id(EVP_PKEY_CTX *ctx, void *id, size_t id_len); -\& int EVP_PKEY_CTX_get1_id(EVP_PKEY_CTX *ctx, void *id); -\& int EVP_PKEY_CTX_get1_id_len(EVP_PKEY_CTX *ctx, size_t *id_len); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_set_rsa_keygen_pubexp(EVP_PKEY_CTX *ctx, BIGNUM *pubexp); -\& -\& #include -\& -\& int EVP_PKEY_CTX_get0_dh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char **ukm); -\& -\& #include -\& -\& int EVP_PKEY_CTX_get0_ecdh_kdf_ukm(EVP_PKEY_CTX *ctx, unsigned char **ukm); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_CTX_ctrl()\fR sends a control operation to the context \fIctx\fR. The key -type used must match \fIkeytype\fR if it is not \-1. The parameter \fIoptype\fR is a -mask indicating which operations the control can be applied to. -The control command is indicated in \fIcmd\fR and any additional arguments in -\&\fIp1\fR and \fIp2\fR. -.PP -For \fIcmd\fR = \fB\s-1EVP_PKEY_CTRL_SET_MAC_KEY\s0\fR, \fIp1\fR is the length of the \s-1MAC\s0 key, -and \fIp2\fR is the \s-1MAC\s0 key. This is used by Poly1305, SipHash, \s-1HMAC\s0 and \s-1CMAC.\s0 -.PP -Applications will not normally call \fBEVP_PKEY_CTX_ctrl()\fR directly but will -instead call one of the algorithm specific functions below. -.PP -\&\fBEVP_PKEY_CTX_ctrl_uint64()\fR is a wrapper that directly passes a -uint64 value as \fIp2\fR to \fBEVP_PKEY_CTX_ctrl()\fR. -.PP -\&\fBEVP_PKEY_CTX_ctrl_str()\fR allows an application to send an algorithm -specific control operation to a context \fIctx\fR in string form. This is -intended to be used for options specified on the command line or in text -files. The commands supported are documented in the openssl utility -command line pages for the option \fI\-pkeyopt\fR which is supported by the -\&\fIpkeyutl\fR, \fIgenpkey\fR and \fIreq\fR commands. -.PP -\&\fBEVP_PKEY_CTX_md()\fR sends a message digest control operation to the context -\&\fIctx\fR. The message digest is specified by its name \fImd\fR. -.PP -\&\fBEVP_PKEY_CTX_set_signature_md()\fR sets the message digest type used -in a signature. It can be used in the \s-1RSA, DSA\s0 and \s-1ECDSA\s0 algorithms. -.PP -\&\fBEVP_PKEY_CTX_get_signature_md()\fRgets the message digest type used -in a signature. It can be used in the \s-1RSA, DSA\s0 and \s-1ECDSA\s0 algorithms. -.PP -Key generation typically involves setting up parameters to be used and -generating the private and public key data. Some algorithm implementations -allow private key data to be set explicitly using \fBEVP_PKEY_CTX_set_mac_key()\fR. -In this case key generation is simply the process of setting up the -parameters for the key and then setting the raw key data to the value explicitly. -Normally applications would call \fBEVP_PKEY_new_raw_private_key\fR\|(3) or similar -functions instead. -.PP -\&\fBEVP_PKEY_CTX_set_mac_key()\fR can be used with any of the algorithms supported by -the \fBEVP_PKEY_new_raw_private_key\fR\|(3) function. -.PP -\&\fBEVP_PKEY_CTX_set_group_name()\fR sets the group name to \fIname\fR for parameter and -key generation. For example for \s-1EC\s0 keys this will set the curve name and for -\&\s-1DH\s0 keys it will set the name of the finite field group. -.PP -\&\fBEVP_PKEY_CTX_get_group_name()\fR finds the group name that's currently -set with \fIctx\fR, and writes it to the location that \fIname\fR points at, as long -as its size \fInamelen\fR is large enough to store that name, including a -terminating \s-1NUL\s0 byte. -.SS "\s-1RSA\s0 parameters" -.IX Subsection "RSA parameters" -\&\fBEVP_PKEY_CTX_set_rsa_padding()\fR sets the \s-1RSA\s0 padding mode for \fIctx\fR. -The \fIpad\fR parameter can take the value \fB\s-1RSA_PKCS1_PADDING\s0\fR for PKCS#1 -padding, \fB\s-1RSA_NO_PADDING\s0\fR for -no padding, \fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR for \s-1OAEP\s0 padding (encrypt and -decrypt only), \fB\s-1RSA_X931_PADDING\s0\fR for X9.31 padding (signature operations -only), \fB\s-1RSA_PKCS1_PSS_PADDING\s0\fR (sign and verify only) and -\&\fB\s-1RSA_PKCS1_WITH_TLS_PADDING\s0\fR for \s-1TLS RSA\s0 ClientKeyExchange message padding -(decryption only). -.PP -Two \s-1RSA\s0 padding modes behave differently if \fBEVP_PKEY_CTX_set_signature_md()\fR -is used. If this function is called for PKCS#1 padding the plaintext buffer is -an actual digest value and is encapsulated in a DigestInfo structure according -to PKCS#1 when signing and this structure is expected (and stripped off) when -verifying. If this control is not used with \s-1RSA\s0 and PKCS#1 padding then the -supplied data is used directly and not encapsulated. In the case of X9.31 -padding for \s-1RSA\s0 the algorithm identifier byte is added or checked and removed -if this control is called. If it is not called then the first byte of the plaintext -buffer is expected to be the algorithm identifier byte. -.PP -\&\fBEVP_PKEY_CTX_get_rsa_padding()\fR gets the \s-1RSA\s0 padding mode for \fIctx\fR. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_pss_saltlen()\fR sets the \s-1RSA PSS\s0 salt length to \fIsaltlen\fR. -As its name implies it is only supported for \s-1PSS\s0 padding. If this function is -not called then the salt length is maximized up to the digest length when -signing and auto detection when verifying. Four special values are supported: -.IP "\fB\s-1RSA_PSS_SALTLEN_DIGEST\s0\fR" 4 -.IX Item "RSA_PSS_SALTLEN_DIGEST" -sets the salt length to the digest length. -.IP "\fB\s-1RSA_PSS_SALTLEN_MAX\s0\fR" 4 -.IX Item "RSA_PSS_SALTLEN_MAX" -sets the salt length to the maximum permissible value. -.IP "\fB\s-1RSA_PSS_SALTLEN_AUTO\s0\fR" 4 -.IX Item "RSA_PSS_SALTLEN_AUTO" -causes the salt length to be automatically determined based on the -\&\fB\s-1PSS\s0\fR block structure when verifying. When signing, it has the same -meaning as \fB\s-1RSA_PSS_SALTLEN_MAX\s0\fR. -.IP "\fB\s-1RSA_PSS_SALTLEN_AUTO_DIGEST_MAX\s0\fR" 4 -.IX Item "RSA_PSS_SALTLEN_AUTO_DIGEST_MAX" -causes the salt length to be automatically determined based on the \fB\s-1PSS\s0\fR block -structure when verifying, like \fB\s-1RSA_PSS_SALTLEN_AUTO\s0\fR. When signing, the salt -length is maximized up to a maximum of the digest length to comply with \s-1FIPS -186\-4\s0 section 5.5. -.PP -\&\fBEVP_PKEY_CTX_get_rsa_pss_saltlen()\fR gets the \s-1RSA PSS\s0 salt length for \fIctx\fR. -The padding mode must already have been set to \fB\s-1RSA_PKCS1_PSS_PADDING\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_keygen_bits()\fR sets the \s-1RSA\s0 key length for -\&\s-1RSA\s0 key generation to \fIbits\fR. If not specified 2048 bits is used. -.PP -\&\fBEVP_PKEY_CTX_set1_rsa_keygen_pubexp()\fR sets the public exponent value for \s-1RSA\s0 key -generation to the value stored in \fIpubexp\fR. Currently it should be an odd -integer. In accordance with the OpenSSL naming convention, the \fIpubexp\fR pointer -must be freed independently of the \s-1EVP_PKEY_CTX\s0 (ie, it is internally copied). -If not specified 65537 is used. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_keygen_pubexp()\fR does the same as -\&\fBEVP_PKEY_CTX_set1_rsa_keygen_pubexp()\fR except that there is no internal copy and -therefore \fIpubexp\fR should not be modified or freed after the call. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_keygen_primes()\fR sets the number of primes for -\&\s-1RSA\s0 key generation to \fIprimes\fR. If not specified 2 is used. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_mgf1_md_name()\fR sets the \s-1MGF1\s0 digest for \s-1RSA\s0 -padding schemes to the digest named \fImdname\fR. If the \s-1RSA\s0 algorithm -implementation for the selected provider supports it then the digest will be -fetched using the properties \fImdprops\fR. If not explicitly set the signing -digest is used. The padding mode must have been set to \fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR -or \fB\s-1RSA_PKCS1_PSS_PADDING\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_mgf1_md()\fR does the same as -\&\fBEVP_PKEY_CTX_set_rsa_mgf1_md_name()\fR except that the name of the digest is -inferred from the supplied \fImd\fR and it is not possible to specify any -properties. -.PP -\&\fBEVP_PKEY_CTX_get_rsa_mgf1_md_name()\fR gets the name of the \s-1MGF1\s0 -digest algorithm for \fIctx\fR. If not explicitly set the signing digest is used. -The padding mode must have been set to \fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR or -\&\fB\s-1RSA_PKCS1_PSS_PADDING\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_get_rsa_mgf1_md()\fR does the same as -\&\fBEVP_PKEY_CTX_get_rsa_mgf1_md_name()\fR except that it returns a pointer to an -\&\s-1EVP_MD\s0 object instead. Note that only known, built-in \s-1EVP_MD\s0 objects will be -returned. The \s-1EVP_MD\s0 object may be \s-1NULL\s0 if the digest is not one of these (such -as a digest only implemented in a third party provider). -.PP -\&\fBEVP_PKEY_CTX_set_rsa_oaep_md_name()\fR sets the message digest type -used in \s-1RSA OAEP\s0 to the digest named \fImdname\fR. If the \s-1RSA\s0 algorithm -implementation for the selected provider supports it then the digest will be -fetched using the properties \fImdprops\fR. The padding mode must have been set to -\&\fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_oaep_md()\fR does the same as -\&\fBEVP_PKEY_CTX_set_rsa_oaep_md_name()\fR except that the name of the digest is -inferred from the supplied \fImd\fR and it is not possible to specify any -properties. -.PP -\&\fBEVP_PKEY_CTX_get_rsa_oaep_md_name()\fR gets the message digest -algorithm name used in \s-1RSA OAEP\s0 and stores it in the buffer \fIname\fR which is of -size \fInamelen\fR. The padding mode must have been set to -\&\fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR. The buffer should be sufficiently large for any -expected digest algorithm names or the function will fail. -.PP -\&\fBEVP_PKEY_CTX_get_rsa_oaep_md()\fR does the same as -\&\fBEVP_PKEY_CTX_get_rsa_oaep_md_name()\fR except that it returns a pointer to an -\&\s-1EVP_MD\s0 object instead. Note that only known, built-in \s-1EVP_MD\s0 objects will be -returned. The \s-1EVP_MD\s0 object may be \s-1NULL\s0 if the digest is not one of these (such -as a digest only implemented in a third party provider). -.PP -\&\fBEVP_PKEY_CTX_set0_rsa_oaep_label()\fR sets the \s-1RSA OAEP\s0 label to binary data -\&\fIlabel\fR and its length in bytes to \fIlen\fR. If \fIlabel\fR is \s-1NULL\s0 or \fIlen\fR is 0, -the label is cleared. The library takes ownership of the label so the -caller should not free the original memory pointed to by \fIlabel\fR. -The padding mode must have been set to \fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_get0_rsa_oaep_label()\fR gets the \s-1RSA OAEP\s0 label to -\&\fIlabel\fR. The return value is the label length. The padding mode -must have been set to \fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR. The resulting pointer is owned -by the library and should not be freed by the caller. -.PP -\&\fB\s-1RSA_PKCS1_WITH_TLS_PADDING\s0\fR is used when decrypting an \s-1RSA\s0 encrypted \s-1TLS\s0 -pre-master secret in a \s-1TLS\s0 ClientKeyExchange message. It is the same as -\&\s-1RSA_PKCS1_PADDING\s0 except that it additionally verifies that the result is the -correct length and the first two bytes are the protocol version initially -requested by the client. If the encrypted content is publicly invalid then the -decryption will fail. However, if the padding checks fail then decryption will -still appear to succeed but a random \s-1TLS\s0 premaster secret will be returned -instead. This padding mode accepts two parameters which can be set using the -\&\fBEVP_PKEY_CTX_set_params\fR\|(3) function. These are -\&\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0 and -\&\s-1OSSL_ASYM_CIPHER_PARAM_TLS_NEGOTIATED_VERSION,\s0 both of which are expected to be -unsigned integers. Normally only the first of these will be set and represents -the \s-1TLS\s0 protocol version that was first requested by the client (e.g. 0x0303 for -TLSv1.2, 0x0302 for TLSv1.1 etc). Historically some buggy clients would use the -negotiated protocol version instead of the protocol version first requested. If -this behaviour should be tolerated then -\&\s-1OSSL_ASYM_CIPHER_PARAM_TLS_NEGOTIATED_VERSION\s0 should be set to the actual -negotiated protocol version. Otherwise it should be left unset. -.PP -Similarly to the \fB\s-1RSA_PKCS1_WITH_TLS_PADDING\s0\fR above, since OpenSSL version -3.2.0, the use of \fB\s-1RSA_PKCS1_PADDING\s0\fR will return a randomly generated message -instead of padding errors in case padding checks fail. Applications that -want to remain secure while using earlier versions of OpenSSL, or a provider -that doesn't implement the implicit rejection mechanism, still need to -handle both the error code from the \s-1RSA\s0 decryption operation and the -returned message in a side channel secure manner. -This protection against Bleichenbacher attacks can be disabled by setting -\&\fB\s-1OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION\s0\fR (an unsigned integer) to 0. -.SS "\s-1DSA\s0 parameters" -.IX Subsection "DSA parameters" -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_bits()\fR sets the number of bits used for \s-1DSA\s0 -parameter generation to \fBnbits\fR. If not specified, 2048 is used. -.PP -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_q_bits()\fR sets the number of bits in the subprime -parameter \fIq\fR for \s-1DSA\s0 parameter generation to \fIqbits\fR. If not specified, 224 -is used. If a digest function is specified below, this parameter is ignored and -instead, the number of bits in \fIq\fR matches the size of the digest. -.PP -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_md()\fR sets the digest function used for \s-1DSA\s0 -parameter generation to \fImd\fR. If not specified, one of \s-1SHA\-1, SHA\-224,\s0 or -\&\s-1SHA\-256\s0 is selected to match the bit length of \fIq\fR above. -.PP -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_md_props()\fR sets the digest function used for \s-1DSA\s0 -parameter generation using \fImd_name\fR and \fImd_properties\fR to retrieve the -digest from a provider. -If not specified, \fImd_name\fR will be set to one of \s-1SHA\-1, SHA\-224,\s0 or -\&\s-1SHA\-256\s0 depending on the bit length of \fIq\fR above. \fImd_properties\fR is a -property query string that has a default value of '' if not specified. -.PP -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_gindex()\fR sets the \fIgindex\fR used by the generator -G. The default value is \-1 which uses unverifiable g, otherwise a positive value -uses verifiable g. This value must be saved if key validation of g is required, -since it is not part of a persisted key. -.PP -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_seed()\fR sets the \fIseed\fR to use for generation -rather than using a randomly generated value for the seed. This is useful for -testing purposes only and can fail if the seed does not produce primes for both -p & q on its first iteration. This value must be saved if key validation of -p, q, and verifiable g are required, since it is not part of a persisted key. -.PP -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_type()\fR sets the generation type to use \s-1FIPS186\-4\s0 -generation if \fIname\fR is \*(L"fips186_4\*(R", or \s-1FIPS186\-2\s0 generation if \fIname\fR is -\&\*(L"fips186_2\*(R". The default value for the default provider is \*(L"fips186_2\*(R". The -default value for the \s-1FIPS\s0 provider is \*(L"fips186_4\*(R". -.SS "\s-1DH\s0 parameters" -.IX Subsection "DH parameters" -\&\fBEVP_PKEY_CTX_set_dh_paramgen_prime_len()\fR sets the length of the \s-1DH\s0 prime -parameter \fIp\fR for \s-1DH\s0 parameter generation. If this function is not called then -2048 is used. Only accepts lengths greater than or equal to 256. -.PP -\&\fBEVP_PKEY_CTX_set_dh_paramgen_subprime_len()\fR sets the length of the \s-1DH\s0 -optional subprime parameter \fIq\fR for \s-1DH\s0 parameter generation. The default is -256 if the prime is at least 2048 bits long or 160 otherwise. The \s-1DH\s0 paramgen -type must have been set to \*(L"fips186_4\*(R". -.PP -\&\fBEVP_PKEY_CTX_set_dh_paramgen_generator()\fR sets \s-1DH\s0 generator to \fIgen\fR for \s-1DH\s0 -parameter generation. If not specified 2 is used. -.PP -\&\fBEVP_PKEY_CTX_set_dh_paramgen_type()\fR sets the key type for \s-1DH\s0 parameter -generation. The supported parameters are: -.IP "\fB\s-1DH_PARAMGEN_TYPE_GROUP\s0\fR" 4 -.IX Item "DH_PARAMGEN_TYPE_GROUP" -Use a named group. If only the safe prime parameter \fIp\fR is set this can be -used to select a ffdhe safe prime group of the correct size. -.IP "\fB\s-1DH_PARAMGEN_TYPE_FIPS_186_4\s0\fR" 4 -.IX Item "DH_PARAMGEN_TYPE_FIPS_186_4" -\&\s-1FIPS186\-4 FFC\s0 parameter generator. -.IP "\fB\s-1DH_PARAMGEN_TYPE_FIPS_186_2\s0\fR" 4 -.IX Item "DH_PARAMGEN_TYPE_FIPS_186_2" -\&\s-1FIPS186\-2 FFC\s0 parameter generator (X9.42 \s-1DH\s0). -.IP "\fB\s-1DH_PARAMGEN_TYPE_GENERATOR\s0\fR" 4 -.IX Item "DH_PARAMGEN_TYPE_GENERATOR" -Uses a safe prime generator g (PKCS#3 format). -.PP -The default in the default provider is \fB\s-1DH_PARAMGEN_TYPE_GENERATOR\s0\fR for the -\&\*(L"\s-1DH\*(R"\s0 keytype, and \fB\s-1DH_PARAMGEN_TYPE_FIPS_186_2\s0\fR for the \*(L"\s-1DHX\*(R"\s0 keytype. In the -\&\s-1FIPS\s0 provider the default value is \fB\s-1DH_PARAMGEN_TYPE_GROUP\s0\fR for the \*(L"\s-1DH\*(R"\s0 -keytype and <\fB\s-1DH_PARAMGEN_TYPE_FIPS_186_4\s0\fR for the \*(L"\s-1DHX\*(R"\s0 keytype. -.PP -\&\fBEVP_PKEY_CTX_set_dh_paramgen_gindex()\fR sets the \fIgindex\fR used by the generator G. -The default value is \-1 which uses unverifiable g, otherwise a positive value -uses verifiable g. This value must be saved if key validation of g is required, -since it is not part of a persisted key. -.PP -\&\fBEVP_PKEY_CTX_set_dh_paramgen_seed()\fR sets the \fIseed\fR to use for generation -rather than using a randomly generated value for the seed. This is useful for -testing purposes only and can fail if the seed does not produce primes for both -p & q on its first iteration. This value must be saved if key validation of p, q, -and verifiable g are required, since it is not part of a persisted key. -.PP -\&\fBEVP_PKEY_CTX_set_dh_pad()\fR sets the \s-1DH\s0 padding mode. -If \fIpad\fR is 1 the shared secret is padded with zeros up to the size of the \s-1DH\s0 -prime \fIp\fR. -If \fIpad\fR is zero (the default) then no padding is performed. -.PP -\&\fBEVP_PKEY_CTX_set_dh_nid()\fR sets the \s-1DH\s0 parameters to values corresponding to -\&\fInid\fR as defined in \s-1RFC7919\s0 or \s-1RFC3526.\s0 The \fInid\fR parameter must be -\&\fBNID_ffdhe2048\fR, \fBNID_ffdhe3072\fR, \fBNID_ffdhe4096\fR, \fBNID_ffdhe6144\fR, -\&\fBNID_ffdhe8192\fR, \fBNID_modp_1536\fR, \fBNID_modp_2048\fR, \fBNID_modp_3072\fR, -\&\fBNID_modp_4096\fR, \fBNID_modp_6144\fR, \fBNID_modp_8192\fR or \fBNID_undef\fR to clear -the stored value. This function can be called during parameter or key generation. -The nid parameter and the rfc5114 parameter are mutually exclusive. -.PP -\&\fBEVP_PKEY_CTX_set_dh_rfc5114()\fR and \fBEVP_PKEY_CTX_set_dhx_rfc5114()\fR both set the -\&\s-1DH\s0 parameters to the values defined in \s-1RFC5114.\s0 The \fIrfc5114\fR parameter must -be 1, 2 or 3 corresponding to \s-1RFC5114\s0 sections 2.1, 2.2 and 2.3. or 0 to clear -the stored value. This macro can be called during parameter generation. The -\&\fIctx\fR must have a key type of \fB\s-1EVP_PKEY_DHX\s0\fR. -The rfc5114 parameter and the nid parameter are mutually exclusive. -.SS "\s-1DH\s0 key derivation function parameters" -.IX Subsection "DH key derivation function parameters" -Note that all of the following functions require that the \fIctx\fR parameter has -a private key type of \fB\s-1EVP_PKEY_DHX\s0\fR. When using key derivation, the output of -\&\fBEVP_PKEY_derive()\fR is the output of the \s-1KDF\s0 instead of the \s-1DH\s0 shared secret. -The \s-1KDF\s0 output is typically used as a Key Encryption Key (\s-1KEK\s0) that in turn -encrypts a Content Encryption Key (\s-1CEK\s0). -.PP -\&\fBEVP_PKEY_CTX_set_dh_kdf_type()\fR sets the key derivation function type to \fIkdf\fR -for \s-1DH\s0 key derivation. Possible values are \fB\s-1EVP_PKEY_DH_KDF_NONE\s0\fR and -\&\fB\s-1EVP_PKEY_DH_KDF_X9_42\s0\fR which uses the key derivation specified in \s-1RFC2631\s0 -(based on the keying algorithm described in X9.42). When using key derivation, -the \fIkdf_oid\fR, \fIkdf_md\fR and \fIkdf_outlen\fR parameters must also be specified. -.PP -\&\fBEVP_PKEY_CTX_get_dh_kdf_type()\fR gets the key derivation function type for \fIctx\fR -used for \s-1DH\s0 key derivation. Possible values are \fB\s-1EVP_PKEY_DH_KDF_NONE\s0\fR and -\&\fB\s-1EVP_PKEY_DH_KDF_X9_42\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_set0_dh_kdf_oid()\fR sets the key derivation function object -identifier to \fIoid\fR for \s-1DH\s0 key derivation. This \s-1OID\s0 should identify the -algorithm to be used with the Content Encryption Key. -The library takes ownership of the object identifier so the caller should not -free the original memory pointed to by \fIoid\fR. -.PP -\&\fBEVP_PKEY_CTX_get0_dh_kdf_oid()\fR gets the key derivation function oid for \fIctx\fR -used for \s-1DH\s0 key derivation. The resulting pointer is owned by the library and -should not be freed by the caller. -.PP -\&\fBEVP_PKEY_CTX_set_dh_kdf_md()\fR sets the key derivation function message digest to -\&\fImd\fR for \s-1DH\s0 key derivation. Note that \s-1RFC2631\s0 specifies that this digest should -be \s-1SHA1\s0 but OpenSSL tolerates other digests. -.PP -\&\fBEVP_PKEY_CTX_get_dh_kdf_md()\fR gets the key derivation function message digest for -\&\fIctx\fR used for \s-1DH\s0 key derivation. -.PP -\&\fBEVP_PKEY_CTX_set_dh_kdf_outlen()\fR sets the key derivation function output length -to \fIlen\fR for \s-1DH\s0 key derivation. -.PP -\&\fBEVP_PKEY_CTX_get_dh_kdf_outlen()\fR gets the key derivation function output length -for \fIctx\fR used for \s-1DH\s0 key derivation. -.PP -\&\fBEVP_PKEY_CTX_set0_dh_kdf_ukm()\fR sets the user key material to \fIukm\fR and its -length to \fIlen\fR for \s-1DH\s0 key derivation. This parameter is optional and -corresponds to the partyAInfo field in \s-1RFC2631\s0 terms. The specification -requires that it is 512 bits long but this is not enforced by OpenSSL. -The library takes ownership of the user key material so the caller should not -free the original memory pointed to by \fIukm\fR. -.PP -\&\fBEVP_PKEY_CTX_get0_dh_kdf_ukm()\fR gets the user key material for \fIctx\fR. -The return value is the user key material length. The resulting pointer is owned -by the library and should not be freed by the caller. -.SS "\s-1EC\s0 parameters" -.IX Subsection "EC parameters" -Use \fBEVP_PKEY_CTX_set_group_name()\fR (described above) to set the curve name to -\&\fIname\fR for parameter and key generation. -.PP -\&\fBEVP_PKEY_CTX_set_ec_paramgen_curve_nid()\fR does the same as -\&\fBEVP_PKEY_CTX_set_group_name()\fR, but is specific to \s-1EC\s0 and uses a \fInid\fR rather -than a name string. -.PP -For \s-1EC\s0 parameter generation, one of \fBEVP_PKEY_CTX_set_group_name()\fR -or \fBEVP_PKEY_CTX_set_ec_paramgen_curve_nid()\fR must be called or an error occurs -because there is no default curve. -These function can also be called to set the curve explicitly when -generating an \s-1EC\s0 key. -.PP -\&\fBEVP_PKEY_CTX_get_group_name()\fR (described above) can be used to obtain the curve -name that's currently set with \fIctx\fR. -.PP -\&\fBEVP_PKEY_CTX_set_ec_param_enc()\fR sets the \s-1EC\s0 parameter encoding to \fIparam_enc\fR -when generating \s-1EC\s0 parameters or an \s-1EC\s0 key. The encoding can be -\&\fB\s-1OPENSSL_EC_EXPLICIT_CURVE\s0\fR for explicit parameters (the default in versions -of OpenSSL before 1.1.0) or \fB\s-1OPENSSL_EC_NAMED_CURVE\s0\fR to use named curve form. -For maximum compatibility the named curve form should be used. Note: the -\&\fB\s-1OPENSSL_EC_NAMED_CURVE\s0\fR value was added in OpenSSL 1.1.0; previous -versions should use 0 instead. -.SS "\s-1ECDH\s0 parameters" -.IX Subsection "ECDH parameters" -\&\fBEVP_PKEY_CTX_set_ecdh_cofactor_mode()\fR sets the cofactor mode to \fIcofactor_mode\fR -for \s-1ECDH\s0 key derivation. Possible values are 1 to enable cofactor -key derivation, 0 to disable it and \-1 to clear the stored cofactor mode and -fallback to the private key cofactor mode. -.PP -\&\fBEVP_PKEY_CTX_get_ecdh_cofactor_mode()\fR returns the cofactor mode for \fIctx\fR used -for \s-1ECDH\s0 key derivation. Possible values are 1 when cofactor key derivation is -enabled and 0 otherwise. -.SS "\s-1ECDH\s0 key derivation function parameters" -.IX Subsection "ECDH key derivation function parameters" -\&\fBEVP_PKEY_CTX_set_ecdh_kdf_type()\fR sets the key derivation function type to -\&\fIkdf\fR for \s-1ECDH\s0 key derivation. Possible values are \fB\s-1EVP_PKEY_ECDH_KDF_NONE\s0\fR -and \fB\s-1EVP_PKEY_ECDH_KDF_X9_63\s0\fR which uses the key derivation specified in X9.63. -When using key derivation, the \fIkdf_md\fR and \fIkdf_outlen\fR parameters must -also be specified. -.PP -\&\fBEVP_PKEY_CTX_get_ecdh_kdf_type()\fR returns the key derivation function type for -\&\fIctx\fR used for \s-1ECDH\s0 key derivation. Possible values are -\&\fB\s-1EVP_PKEY_ECDH_KDF_NONE\s0\fR and \fB\s-1EVP_PKEY_ECDH_KDF_X9_63\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_set_ecdh_kdf_md()\fR sets the key derivation function message digest -to \fImd\fR for \s-1ECDH\s0 key derivation. Note that X9.63 specifies that this digest -should be \s-1SHA1\s0 but OpenSSL tolerates other digests. -.PP -\&\fBEVP_PKEY_CTX_get_ecdh_kdf_md()\fR gets the key derivation function message digest -for \fIctx\fR used for \s-1ECDH\s0 key derivation. -.PP -\&\fBEVP_PKEY_CTX_set_ecdh_kdf_outlen()\fR sets the key derivation function output -length to \fIlen\fR for \s-1ECDH\s0 key derivation. -.PP -\&\fBEVP_PKEY_CTX_get_ecdh_kdf_outlen()\fR gets the key derivation function output -length for \fIctx\fR used for \s-1ECDH\s0 key derivation. -.PP -\&\fBEVP_PKEY_CTX_set0_ecdh_kdf_ukm()\fR sets the user key material to \fIukm\fR for \s-1ECDH\s0 -key derivation. This parameter is optional and corresponds to the shared info in -X9.63 terms. The library takes ownership of the user key material so the caller -should not free the original memory pointed to by \fIukm\fR. -.PP -\&\fBEVP_PKEY_CTX_get0_ecdh_kdf_ukm()\fR gets the user key material for \fIctx\fR. -The return value is the user key material length. The resulting pointer is owned -by the library and should not be freed by the caller. -.SS "Other parameters" -.IX Subsection "Other parameters" -\&\fBEVP_PKEY_CTX_set1_id()\fR, \fBEVP_PKEY_CTX_get1_id()\fR and \fBEVP_PKEY_CTX_get1_id_len()\fR -are used to manipulate the special identifier field for specific signature -algorithms such as \s-1SM2.\s0 The \fBEVP_PKEY_CTX_set1_id()\fR sets an \s-1ID\s0 pointed by \fIid\fR with -the length \fIid_len\fR to the library. The library takes a copy of the id so that -the caller can safely free the original memory pointed to by \fIid\fR. -\&\fBEVP_PKEY_CTX_get1_id_len()\fR returns the length of the \s-1ID\s0 set via a previous call -to \fBEVP_PKEY_CTX_set1_id()\fR. The length is usually used to allocate adequate -memory for further calls to \fBEVP_PKEY_CTX_get1_id()\fR. \fBEVP_PKEY_CTX_get1_id()\fR -returns the previously set \s-1ID\s0 value to caller in \fIid\fR. The caller should -allocate adequate memory space for the \fIid\fR before calling \fBEVP_PKEY_CTX_get1_id()\fR. -.PP -\&\fBEVP_PKEY_CTX_set_kem_op()\fR sets the \s-1KEM\s0 operation to run. This can be set after -\&\fBEVP_PKEY_encapsulate_init()\fR or \fBEVP_PKEY_decapsulate_init()\fR to select the kem -operation. For the key types that support encapsulation and don't have the -default operation, e.g. \s-1RSA,\s0 this function must be called before -\&\fBEVP_PKEY_encapsulate()\fR or \fBEVP_PKEY_decapsulate()\fR. The supported values for the -built-in algorithms are enumerated in \s-1\fBEVP_KEM\-RSA\s0\fR\|(7), \s-1\fBEVP_KEM\-EC\s0\fR\|(7), -\&\s-1\fBEVP_KEM\-X25519\s0\fR\|(7), and \s-1\fBEVP_KEM\-X448\s0\fR\|(7). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All other functions described on this page return a positive value for success -and 0 or a negative value for failure. In particular a return value of \-2 -indicates the operation is not supported by the public key algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_params\fR\|(3), -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3), -\&\fBEVP_PKEY_keygen\fR\|(3) -\&\fBEVP_PKEY_encapsulate\fR\|(3) -\&\fBEVP_PKEY_decapsulate\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_PKEY_CTX_get_rsa_oaep_md_name()\fR, \fBEVP_PKEY_CTX_get_rsa_mgf1_md_name()\fR, -\&\fBEVP_PKEY_CTX_set_rsa_mgf1_md_name()\fR, \fBEVP_PKEY_CTX_set_rsa_oaep_md_name()\fR, -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_md_props()\fR, \fBEVP_PKEY_CTX_set_dsa_paramgen_gindex()\fR, -\&\fBEVP_PKEY_CTX_set_dsa_paramgen_type()\fR, \fBEVP_PKEY_CTX_set_dsa_paramgen_seed()\fR, -\&\fBEVP_PKEY_CTX_set_group_name()\fR and \fBEVP_PKEY_CTX_get_group_name()\fR -were added in OpenSSL 3.0. -.PP -The \fBEVP_PKEY_CTX_set1_id()\fR, \fBEVP_PKEY_CTX_get1_id()\fR and -\&\fBEVP_PKEY_CTX_get1_id_len()\fR macros were added in 1.1.1, other functions were -added in OpenSSL 1.0.0. -.PP -In OpenSSL 1.1.1 and below the functions were mostly macros. -From OpenSSL 3.0 they are all functions. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_keygen_pubexp()\fR, \fBEVP_PKEY_CTX_get0_dh_kdf_ukm()\fR, -and \fBEVP_PKEY_CTX_get0_ecdh_kdf_ukm()\fR were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_str.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_str.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_str.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_uint64.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_uint64.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_ctrl_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_dup.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_dup.3ossl deleted file mode 120000 index 70da0c9a..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_free.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_free.3ossl deleted file mode 120000 index 70da0c9a..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_oid.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_oid.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_oid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_ukm.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_ukm.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_dh_kdf_ukm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_ecdh_kdf_ukm.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_ecdh_kdf_ukm.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_ecdh_kdf_ukm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_libctx.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_libctx.3ossl deleted file mode 100644 index 08959aa5..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_libctx.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_GET0_LIBCTX 3ossl" -.TH EVP_PKEY_CTX_GET0_LIBCTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_get0_libctx, -EVP_PKEY_CTX_get0_propq, -EVP_PKEY_CTX_get0_provider -\&\- functions for getting diverse information from an EVP_PKEY_CTX -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_LIB_CTX *EVP_PKEY_CTX_get0_libctx(EVP_PKEY_CTX *ctx); -\& const char *EVP_PKEY_CTX_get0_propq(const EVP_PKEY_CTX *ctx); -\& const OSSL_PROVIDER *EVP_PKEY_CTX_get0_provider(const EVP_PKEY_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_CTX_get0_libctx()\fR and \fBEVP_PKEY_CTX_get0_propq()\fR obtain the -\&\s-1OSSL_LIB_CTX\s0 and property query string values respectively that were -associated with the \s-1EVP_PKEY_CTX\s0 when it was constructed. -.PP -\&\fBEVP_PKEY_CTX_get0_provider()\fR returns the provider associated with the -ongoing \fB\s-1EVP_PKEY_CTX\s0\fR operation. If the operation is performed by -en \fB\s-1ENGINE\s0\fR, this function returns \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_CTX_get0_libctx()\fR and \fBEVP_PKEY_CTX_get0_propq()\fR functions return the -\&\s-1OSSL_LIB_CTX\s0 and property query string associated with the \s-1EVP_PKEY_CTX\s0 or \s-1NULL\s0 -if they are not set. The returned values should not be freed by the caller. -.PP -\&\fBEVP_PKEY_CTX_get0_provider()\fR returns a provider if an operation performed by -a provider is ongoing, otherwise \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_peerkey.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_peerkey.3ossl deleted file mode 120000 index 59224010..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_peerkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get0_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_pkey.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_pkey.3ossl deleted file mode 100644 index 531291ff..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_pkey.3ossl +++ /dev/null @@ -1,188 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_GET0_PKEY 3ossl" -.TH EVP_PKEY_CTX_GET0_PKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_get0_pkey, -EVP_PKEY_CTX_get0_peerkey -\&\- functions for accessing the EVP_PKEY associated with an EVP_PKEY_CTX -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *EVP_PKEY_CTX_get0_pkey(EVP_PKEY_CTX *ctx); -\& EVP_PKEY *EVP_PKEY_CTX_get0_peerkey(EVP_PKEY_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_CTX_get0_pkey()\fR is used to access the \fB\s-1EVP_PKEY\s0\fR -associated with the given \fB\s-1EVP_PKEY_CTX\s0\fR \fIctx\fR. -The \fB\s-1EVP_PKEY\s0\fR obtained is the one used for creating the \fB\s-1EVP_PKEY_CTX\s0\fR -using either \fBEVP_PKEY_CTX_new\fR\|(3) or \fBEVP_PKEY_CTX_new_from_pkey\fR\|(3). -.PP -\&\fBEVP_PKEY_CTX_get0_peerkey()\fR is used to access the peer \fB\s-1EVP_PKEY\s0\fR -associated with the given \fB\s-1EVP_PKEY_CTX\s0\fR \fIctx\fR. -The peer \fB\s-1EVP_PKEY\s0\fR obtained is the one set using -either \fBEVP_PKEY_derive_set_peer\fR\|(3) or \fBEVP_PKEY_derive_set_peer_ex\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_CTX_get0_pkey()\fR returns the \fB\s-1EVP_PKEY\s0\fR associated with the -\&\s-1EVP_PKEY_CTX\s0 or \s-1NULL\s0 if it is not set. -.PP -\&\fBEVP_PKEY_CTX_get0_peerkey()\fR returns the peer \fB\s-1EVP_PKEY\s0\fR associated with the -\&\s-1EVP_PKEY_CTX\s0 or \s-1NULL\s0 if it is not set. -.PP -The returned \s-1EVP_PKEY\s0 objects are owned by the \s-1EVP_PKEY_CTX,\s0 -and therefore should not explicitly be freed by the caller. -.PP -These functions do not affect the \s-1EVP_PKEY\s0 reference count. -They merely act as getter functions, and should be treated as such. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), \fBEVP_PKEY_CTX_new_from_pkey\fR\|(3), -\&\fBEVP_PKEY_derive_set_peer\fR\|(3), \fBEVP_PKEY_derive_set_peer_ex\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). -You may not use this file except in compliance with the License. -You can obtain a copy in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_propq.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_propq.3ossl deleted file mode 120000 index d94ef73e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_propq.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get0_libctx.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_provider.3ossl deleted file mode 120000 index d94ef73e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get0_libctx.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_rsa_oaep_label.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_rsa_oaep_label.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get0_rsa_oaep_label.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id_len.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id_len.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get1_id_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor.3ossl deleted file mode 100644 index 06bb75d4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor.3ossl +++ /dev/null @@ -1,195 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_GET_ALGOR 3ossl" -.TH EVP_PKEY_CTX_GET_ALGOR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER_CTX_get_algor, -EVP_CIPHER_CTX_get_algor_params, -EVP_CIPHER_CTX_set_algor_params, -EVP_PKEY_CTX_get_algor, -EVP_PKEY_CTX_get_algor_params, -EVP_PKEY_CTX_set_algor_params -\&\- pass AlgorithmIdentifier and its params to/from algorithm implementations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 3 -\& int EVP_TYPE_CTX_get_algor(EVP_TYPE_CTX *ctx, X509_ALGOR **alg); -\& int EVP_TYPE_CTX_get_algor_params(EVP_TYPE_CTX *ctx, X509_ALGOR *alg); -\& int EVP_TYPE_CTX_set_algor_params(EVP_TYPE_CTX *ctx, const X509_ALGOR *alg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -In the description here and the \*(L"\s-1SYNOPSIS\*(R"\s0 above, \fB\f(BI\s-1TYPE\s0\fB\fR is used as a -placeholder for any \s-1EVP\s0 operation type. -.PP -\&\fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB_CTX_get_algor\fR() attempts to retrieve a complete -AlgorithmIdentifier from the \fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB\fR implementation, and populates -\&\fI*alg\fR with it. -If \fIalg\fR is \s-1NULL,\s0 calling this function will serve to see if calling this -function is supported at all by the \fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB\fR implementation. -If \fI*alg\fR is \s-1NULL,\s0 space will be allocated automatically, and assigned to -\&\fI*alg\fR. -.PP -\&\fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB_CTX_get_algor_params\fR() attempts to retrieve the \fIparameters\fR -part of an AlgorithmIdentifier from the \fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB\fR implementation, and -populates \fIalg\-\fRparameters> with it. -If \fIalg\fR is \s-1NULL,\s0 calling this function will serve to see if calling this -function is supported at all by the \fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB\fR implementation. -If \fIalg\->parameters\fR is \s-1NULL,\s0 space will be allocated automatically, and -assigned to \fIalg\->parameters\fR. -If \fIalg\->parameters\fR is not \s-1NULL,\s0 its previous contents will be overwritten -with the retrieved AlgorithmIdentifier parameters. Beware! -.PP -\&\fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB_CTX_set_algor_params\fR() attempts to pass \fIalg\->parameters\fR -to the \fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB\fR implementation. -If \fIalg\fR is \s-1NULL,\s0 calling this function will serve to see if calling this -function is supported at all by the \fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB\fR implementation. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return 1 for success, and 0 or a negative number if an error -occurs. In particular, \-2 is returned when the function isn't supported by -the \fB\s-1EVP_\s0\f(BI\s-1TYPE\s0\fB\fR implementation. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor_params.3ossl deleted file mode 120000 index 4ab4a12c..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_algor_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get_algor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_app_data.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_app_data.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_cb.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_cb.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_outlen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_outlen.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_outlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_type.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_dh_kdf_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_cofactor_mode.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_cofactor_mode.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_cofactor_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_outlen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_outlen.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_outlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_type.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_ecdh_kdf_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_group_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_group_name.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_group_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_keygen_info.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_keygen_info.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_keygen_info.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_params.3ossl deleted file mode 120000 index d5e1e4c8..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md_name.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_mgf1_md_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md_name.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_oaep_md_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_padding.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_padding.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_padding.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_pss_saltlen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_pss_saltlen.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_rsa_pss_saltlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_signature_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_get_signature_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_get_signature_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_gettable_params.3ossl deleted file mode 120000 index d5e1e4c8..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_is_a.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_is_a.3ossl deleted file mode 120000 index 70da0c9a..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_new.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_new.3ossl deleted file mode 100644 index f7fb23fe..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_new.3ossl +++ /dev/null @@ -1,258 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_NEW 3ossl" -.TH EVP_PKEY_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_new, EVP_PKEY_CTX_new_id, EVP_PKEY_CTX_new_from_name, -EVP_PKEY_CTX_new_from_pkey, EVP_PKEY_CTX_dup, EVP_PKEY_CTX_free, -EVP_PKEY_CTX_is_a -\&\- public key algorithm context functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY_CTX *EVP_PKEY_CTX_new(EVP_PKEY *pkey, ENGINE *e); -\& EVP_PKEY_CTX *EVP_PKEY_CTX_new_id(int id, ENGINE *e); -\& EVP_PKEY_CTX *EVP_PKEY_CTX_new_from_name(OSSL_LIB_CTX *libctx, -\& const char *name, -\& const char *propquery); -\& EVP_PKEY_CTX *EVP_PKEY_CTX_new_from_pkey(OSSL_LIB_CTX *libctx, -\& EVP_PKEY *pkey, -\& const char *propquery); -\& EVP_PKEY_CTX *EVP_PKEY_CTX_dup(const EVP_PKEY_CTX *ctx); -\& void EVP_PKEY_CTX_free(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_CTX_is_a(EVP_PKEY_CTX *ctx, const char *keytype); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_PKEY_CTX_new()\fR function allocates public key algorithm context using -the \fIpkey\fR key type and \s-1ENGINE\s0 \fIe\fR. -.PP -The \fBEVP_PKEY_CTX_new_id()\fR function allocates public key algorithm context -using the key type specified by \fIid\fR and \s-1ENGINE\s0 \fIe\fR. -.PP -The \fBEVP_PKEY_CTX_new_from_name()\fR function allocates a public key algorithm -context using the library context \fIlibctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)), the -key type specified by \fIname\fR and the property query \fIpropquery\fR. None -of the arguments are duplicated, so they must remain unchanged for the -lifetime of the returned \fB\s-1EVP_PKEY_CTX\s0\fR or of any of its duplicates. Read -further about the possible names in \*(L"\s-1NOTES\*(R"\s0 below. -.PP -The \fBEVP_PKEY_CTX_new_from_pkey()\fR function allocates a public key algorithm -context using the library context \fIlibctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) and the -algorithm specified by \fIpkey\fR and the property query \fIpropquery\fR. None of the -arguments are duplicated, so they must remain unchanged for the lifetime of the -returned \fB\s-1EVP_PKEY_CTX\s0\fR or any of its duplicates. -.PP -\&\fBEVP_PKEY_CTX_new_id()\fR and \fBEVP_PKEY_CTX_new_from_name()\fR are normally -used when no \fB\s-1EVP_PKEY\s0\fR structure is associated with the operations, -for example during parameter generation or key generation for some -algorithms. -.PP -\&\fBEVP_PKEY_CTX_dup()\fR duplicates the context \fIctx\fR. -It is not supported for a keygen operation. -It is however possible to duplicate a context freshly created via any of the -above \f(CW\*(C`new\*(C'\fR functions, provided \fBEVP_PKEY_keygen_init\fR\|(3) has not yet been -called on the source context, and then use the copy for key generation. -.PP -\&\fBEVP_PKEY_CTX_free()\fR frees up the context \fIctx\fR. -If \fIctx\fR is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_PKEY_is_a()\fR checks if the key type associated with \fIctx\fR is \fIkeytype\fR. -.SH "NOTES" -.IX Header "NOTES" -.SS "On \fB\s-1EVP_PKEY_CTX\s0\fP" -.IX Subsection "On EVP_PKEY_CTX" -The \fB\s-1EVP_PKEY_CTX\s0\fR structure is an opaque public key algorithm context used -by the OpenSSL high-level public key \s-1API.\s0 Contexts \fB\s-1MUST NOT\s0\fR be shared between -threads: that is it is not permissible to use the same context simultaneously -in two threads. -.SS "On Key Types" -.IX Subsection "On Key Types" -We mention \*(L"key type\*(R" in this manual, which is the same -as \*(L"algorithm\*(R" in most cases, allowing either term to be used -interchangeably. There are algorithms where the \fIkey type\fR and the -\&\fIalgorithm\fR of the operations that use the keys are not the same, -such as \s-1EC\s0 keys being used for \s-1ECDSA\s0 and \s-1ECDH\s0 operations. -.PP -Key types are given in two different manners: -.IP "Legacy \s-1NID\s0 or \s-1EVP_PKEY\s0 type" 4 -.IX Item "Legacy NID or EVP_PKEY type" -This is the \fIid\fR used with \fBEVP_PKEY_CTX_new_id()\fR. -.Sp -These are \fB\s-1EVP_PKEY_RSA\s0\fR, \fB\s-1EVP_PKEY_RSA_PSS\s0\fR, \fB\s-1EVP_PKEY_DSA\s0\fR, -\&\fB\s-1EVP_PKEY_DH\s0\fR, \fB\s-1EVP_PKEY_EC\s0\fR, \fB\s-1EVP_PKEY_SM2\s0\fR, \fB\s-1EVP_PKEY_X25519\s0\fR, -\&\fB\s-1EVP_PKEY_X448\s0\fR, and are used by legacy methods. -.IP "Name strings" 4 -.IX Item "Name strings" -This is the \fIname\fR used with \fBEVP_PKEY_CTX_new_from_name()\fR. -.Sp -These are names like \*(L"\s-1RSA\*(R", \*(L"DSA\*(R",\s0 and what's available depends on what -providers are currently accessible. -.Sp -The OpenSSL providers offer a set of key types available this way, please -see \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) and \fBOSSL_PROVIDER\-default\fR\|(7) and related -documentation for more information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_CTX_new()\fR, \fBEVP_PKEY_CTX_new_id()\fR and \fBEVP_PKEY_CTX_dup()\fR return either -the newly allocated \fB\s-1EVP_PKEY_CTX\s0\fR structure or \fB\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBEVP_PKEY_CTX_free()\fR does not return a value. -.PP -\&\fBEVP_PKEY_CTX_is_a()\fR returns 1 for true and 0 for false. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_CTX_new()\fR, \fBEVP_PKEY_CTX_new_id()\fR, \fBEVP_PKEY_CTX_dup()\fR and -\&\fBEVP_PKEY_CTX_free()\fR functions were added in OpenSSL 1.0.0. -.PP -The \fBEVP_PKEY_CTX_new_from_name()\fR and \fBEVP_PKEY_CTX_new_from_pkey()\fR functions were -added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_name.3ossl deleted file mode 120000 index 70da0c9a..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_pkey.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_pkey.3ossl deleted file mode 120000 index 70da0c9a..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_new_from_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_new_id.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_new_id.3ossl deleted file mode 120000 index 70da0c9a..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_new_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_oid.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_oid.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_oid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_ukm.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_ukm.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_dh_kdf_ukm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_ecdh_kdf_ukm.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_ecdh_kdf_ukm.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_ecdh_kdf_ukm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_rsa_oaep_label.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_rsa_oaep_label.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set0_rsa_oaep_label.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_key.3ossl deleted file mode 120000 index 7a8f3fab..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_hkdf_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_salt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_salt.3ossl deleted file mode 120000 index 7a8f3fab..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_hkdf_salt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_hkdf_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_id.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_id.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_pbe_pass.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_pbe_pass.3ossl deleted file mode 100644 index 1c33343d..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_pbe_pass.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_SET1_PBE_PASS 3ossl" -.TH EVP_PKEY_CTX_SET1_PBE_PASS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_set1_pbe_pass -\&\- generic KDF support functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_set1_pbe_pass(EVP_PKEY_CTX *pctx, unsigned char *pass, -\& int passlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are generic support functions for all \s-1KDF\s0 algorithms. -.PP -\&\fBEVP_PKEY_CTX_set1_pbe_pass()\fR sets the password to the \fBpasslen\fR first -bytes from \fBpass\fR. -.SH "STRING CTRLS" -.IX Header "STRING CTRLS" -There is also support for string based control operations via -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3). -The \fBpassword\fR can be directly specified using the \fBtype\fR parameter -\&\*(L"pass\*(R" or given in hex encoding using the \*(L"hexpass\*(R" parameter. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 for success and 0 or a negative value for failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_PKEY_CTX_set1_pbe_pass()\fR was converted from a macro to a function in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_rsa_keygen_pubexp.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_rsa_keygen_pubexp.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_rsa_keygen_pubexp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_scrypt_salt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_scrypt_salt.3ossl deleted file mode 120000 index 2cd3b0b4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_scrypt_salt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_scrypt_N.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_tls1_prf_secret.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_tls1_prf_secret.3ossl deleted file mode 120000 index 908a3430..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set1_tls1_prf_secret.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_tls1_prf_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_algor_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_algor_params.3ossl deleted file mode 120000 index 4ab4a12c..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_algor_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_get_algor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_app_data.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_app_data.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_cb.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_cb.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_outlen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_outlen.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_outlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_type.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_kdf_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_nid.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_nid.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_pad.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_pad.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_pad.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_generator.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_generator.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_generator.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_gindex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_gindex.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_gindex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_prime_len.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_prime_len.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_prime_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_seed.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_seed.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_seed.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_subprime_len.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_subprime_len.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_subprime_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_type.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_paramgen_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_rfc5114.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_rfc5114.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dh_rfc5114.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dhx_rfc5114.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dhx_rfc5114.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dhx_rfc5114.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_bits.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_gindex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_gindex.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_gindex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md_props.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md_props.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_md_props.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_q_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_q_bits.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_q_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_seed.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_seed.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_seed.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_type.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_dsa_paramgen_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_param_enc.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_param_enc.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_param_enc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_paramgen_curve_nid.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_paramgen_curve_nid.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ec_paramgen_curve_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_cofactor_mode.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_cofactor_mode.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_cofactor_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_outlen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_outlen.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_outlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_type.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_ecdh_kdf_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_group_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_group_name.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_group_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_md.3ossl deleted file mode 100644 index 178235b6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_md.3ossl +++ /dev/null @@ -1,293 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_SET_HKDF_MD 3ossl" -.TH EVP_PKEY_CTX_SET_HKDF_MD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_set_hkdf_md, EVP_PKEY_CTX_set1_hkdf_salt, -EVP_PKEY_CTX_set1_hkdf_key, EVP_PKEY_CTX_add1_hkdf_info, -EVP_PKEY_CTX_set_hkdf_mode \- -HMAC\-based Extract\-and\-Expand key derivation algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_set_hkdf_mode(EVP_PKEY_CTX *pctx, int mode); -\& -\& int EVP_PKEY_CTX_set_hkdf_md(EVP_PKEY_CTX *pctx, const EVP_MD *md); -\& -\& int EVP_PKEY_CTX_set1_hkdf_salt(EVP_PKEY_CTX *pctx, unsigned char *salt, -\& int saltlen); -\& -\& int EVP_PKEY_CTX_set1_hkdf_key(EVP_PKEY_CTX *pctx, unsigned char *key, -\& int keylen); -\& -\& int EVP_PKEY_CTX_add1_hkdf_info(EVP_PKEY_CTX *pctx, unsigned char *info, -\& int infolen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP_PKEY_HKDF\s0 algorithm implements the \s-1HKDF\s0 key derivation function. -\&\s-1HKDF\s0 follows the \*(L"extract-then-expand\*(R" paradigm, where the \s-1KDF\s0 logically -consists of two modules. The first stage takes the input keying material -and \*(L"extracts\*(R" from it a fixed-length pseudorandom key K. The second stage -\&\*(L"expands\*(R" the key K into several additional pseudorandom keys (the output -of the \s-1KDF\s0). -.PP -\&\fBEVP_PKEY_CTX_set_hkdf_mode()\fR sets the mode for the \s-1HKDF\s0 operation. There -are three modes that are currently defined: -.IP "\s-1EVP_PKEY_HKDEF_MODE_EXTRACT_AND_EXPAND\s0" 4 -.IX Item "EVP_PKEY_HKDEF_MODE_EXTRACT_AND_EXPAND" -This is the default mode. Calling \fBEVP_PKEY_derive\fR\|(3) on an \s-1EVP_PKEY_CTX\s0 set -up for \s-1HKDF\s0 will perform an extract followed by an expand operation in one go. -The derived key returned will be the result after the expand operation. The -intermediate fixed-length pseudorandom key K is not returned. -.Sp -In this mode the digest, key, salt and info values must be set before a key is -derived or an error occurs. -.IP "\s-1EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY\s0" 4 -.IX Item "EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY" -In this mode calling \fBEVP_PKEY_derive\fR\|(3) will just perform the extract -operation. The value returned will be the intermediate fixed-length pseudorandom -key K. -.Sp -The digest, key and salt values must be set before a key is derived or an -error occurs. -.IP "\s-1EVP_PKEY_HKDEF_MODE_EXPAND_ONLY\s0" 4 -.IX Item "EVP_PKEY_HKDEF_MODE_EXPAND_ONLY" -In this mode calling \fBEVP_PKEY_derive\fR\|(3) will just perform the expand -operation. The input key should be set to the intermediate fixed-length -pseudorandom key K returned from a previous extract operation. -.Sp -The digest, key and info values must be set before a key is derived or an -error occurs. -.PP -\&\fBEVP_PKEY_CTX_set_hkdf_md()\fR sets the message digest associated with the \s-1HKDF.\s0 -.PP -\&\fBEVP_PKEY_CTX_set1_hkdf_salt()\fR sets the salt to \fBsaltlen\fR bytes of the -buffer \fBsalt\fR. Any existing value is replaced. -.PP -\&\fBEVP_PKEY_CTX_set1_hkdf_key()\fR sets the key to \fBkeylen\fR bytes of the buffer -\&\fBkey\fR. Any existing value is replaced. -.PP -\&\fBEVP_PKEY_CTX_add1_hkdf_info()\fR sets the info value to \fBinfolen\fR bytes of the -buffer \fBinfo\fR. If a value is already set, it is appended to the existing -value. -.SH "STRING CTRLS" -.IX Header "STRING CTRLS" -\&\s-1HKDF\s0 also supports string based control operations via -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3). -The \fBtype\fR parameter \*(L"md\*(R" uses the supplied \fBvalue\fR as the name of the digest -algorithm to use. -The \fBtype\fR parameter \*(L"mode\*(R" uses the values \*(L"\s-1EXTRACT_AND_EXPAND\*(R", -\&\*(L"EXTRACT_ONLY\*(R"\s0 and \*(L"\s-1EXPAND_ONLY\*(R"\s0 to determine the mode to use. -The \fBtype\fR parameters \*(L"salt\*(R", \*(L"key\*(R" and \*(L"info\*(R" use the supplied \fBvalue\fR -parameter as a \fBseed\fR, \fBkey\fR or \fBinfo\fR value. -The names \*(L"hexsalt\*(R", \*(L"hexkey\*(R" and \*(L"hexinfo\*(R" are similar except they take a hex -string which is converted to binary. -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1HKDF\s0 can be obtained by calling: -.PP -.Vb 1 -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); -.Ve -.PP -The total length of the info buffer cannot exceed 2048 bytes in length: this -should be more than enough for any normal use of \s-1HKDF.\s0 -.PP -The output length of an \s-1HKDF\s0 expand operation is specified via the length -parameter to the \fBEVP_PKEY_derive\fR\|(3) function. -Since the \s-1HKDF\s0 output length is variable, passing a \fB\s-1NULL\s0\fR buffer as a means -to obtain the requisite length is not meaningful with \s-1HKDF\s0 in any mode that -performs an expand operation. Instead, the caller must allocate a buffer of the -desired length, and pass that buffer to \fBEVP_PKEY_derive\fR\|(3) along with (a -pointer initialized to) the desired length. Passing a \fB\s-1NULL\s0\fR buffer to obtain -the length is allowed when using \s-1EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY.\s0 -.PP -Optimised versions of \s-1HKDF\s0 can be implemented in an \s-1ENGINE.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 for success and 0 or a negative value for failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 10 bytes using \s-1SHA\-256\s0 with the secret key \*(L"secret\*(R", -salt value \*(L"salt\*(R" and info value \*(L"label\*(R": -.PP -.Vb 4 -\& EVP_PKEY_CTX *pctx; -\& unsigned char out[10]; -\& size_t outlen = sizeof(out); -\& pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_HKDF, NULL); -\& -\& if (EVP_PKEY_derive_init(pctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_hkdf_md(pctx, EVP_sha256()) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set1_hkdf_salt(pctx, "salt", 4) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set1_hkdf_key(pctx, "secret", 6) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_add1_hkdf_info(pctx, "label", 5) <= 0) -\& /* Error */ -\& if (EVP_PKEY_derive(pctx, out, &outlen) <= 0) -\& /* Error */ -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 5869\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of the functions described here were converted from macros to functions in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_mode.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_mode.3ossl deleted file mode 120000 index 7a8f3fab..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_hkdf_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_hkdf_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_kem_op.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_kem_op.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_kem_op.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_mac_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_mac_key.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_mac_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_params.3ossl deleted file mode 100644 index e002dc00..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_params.3ossl +++ /dev/null @@ -1,226 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_SET_PARAMS 3ossl" -.TH EVP_PKEY_CTX_SET_PARAMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_set_params, -EVP_PKEY_CTX_settable_params, -EVP_PKEY_CTX_get_params, -EVP_PKEY_CTX_gettable_params -\&\- provider parameter passing operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_set_params(EVP_PKEY_CTX *ctx, const OSSL_PARAM *params); -\& const OSSL_PARAM *EVP_PKEY_CTX_settable_params(const EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_CTX_get_params(EVP_PKEY_CTX *ctx, OSSL_PARAM *params); -\& const OSSL_PARAM *EVP_PKEY_CTX_gettable_params(const EVP_PKEY_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_PKEY_CTX_get_params()\fR and \fBEVP_PKEY_CTX_set_params()\fR functions allow -transfer of arbitrary key parameters to and from providers. -Not all parameters may be supported by all providers. -See \s-1\fBOSSL_PROVIDER\s0\fR\|(3) for more information on providers. -The \fIparams\fR field is a pointer to a list of \fB\s-1OSSL_PARAM\s0\fR structures, -terminated with a \s-1\fBOSSL_PARAM_END\s0\fR\|(3) struct. -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for information about passing parameters. -These functions must only be called after the \s-1EVP_PKEY_CTX\s0 has been initialised -for use in an operation. -These methods replace the \fBEVP_PKEY_CTX_ctrl()\fR mechanism. (EVP_PKEY_CTX_ctrl now -calls these methods internally to interact with providers). -.PP -\&\fBEVP_PKEY_CTX_gettable_params()\fR and \fBEVP_PKEY_CTX_settable_params()\fR get a -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the gettable and -settable parameters for the current algorithm implementation, i.e. parameters -that can be used with \fBEVP_PKEY_CTX_get_params()\fR and \fBEVP_PKEY_CTX_set_params()\fR -respectively. -These functions must only be called after the \s-1EVP_PKEY_CTX\s0 has been initialised -for use in an operation. -.SS "Parameters" -.IX Subsection "Parameters" -Examples of \s-1EVP_PKEY\s0 parameters include the following: -.PP -\&\*(L"Common parameters\*(R" in \fBprovider\-keymgmt\fR\|(7) -\&\*(L"Key Exchange parameters\*(R" in \fBprovider\-keyexch\fR\|(7) -\&\*(L"Signature parameters\*(R" in \fBprovider\-signature\fR\|(7) -.PP -\&\*(L"Common \s-1RSA\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7) -\&\*(L"\s-1RSA\s0 key generation parameters\*(R" in \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7) -\&\*(L"\s-1FFC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7) -\&\*(L"\s-1FFC\s0 key generation parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7) -\&\*(L"\s-1DSA\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7) -\&\*(L"\s-1DSA\s0 key generation parameters\*(R" in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7) -\&\*(L"\s-1DH\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7) -\&\*(L"\s-1DH\s0 key generation parameters\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7) -\&\*(L"Common \s-1EC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) -\&\*(L"Common X25519, X448, \s-1ED25519\s0 and \s-1ED448\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7) -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_CTX_set_params()\fR returns 1 for success or 0 otherwise. -\&\fBEVP_PKEY_CTX_settable_params()\fR returns an \s-1OSSL_PARAM\s0 array on success or \s-1NULL\s0 on -error. -It may also return \s-1NULL\s0 if there are no settable parameters available. -.PP -All other functions and macros described on this page return a positive value -for success and 0 or a negative value for failure. In particular a return value -of \-2 indicates the operation is not supported by the public key algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3), -\&\fBEVP_PKEY_keygen\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_bits.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_primes.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_primes.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_primes.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_pubexp.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_pubexp.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_keygen_pubexp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md_name.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_mgf1_md_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md_name.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_oaep_md_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_padding.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_padding.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_padding.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl deleted file mode 100644 index 4f850fe7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl +++ /dev/null @@ -1,236 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_SET_RSA_PSS_KEYGEN_MD 3ossl" -.TH EVP_PKEY_CTX_SET_RSA_PSS_KEYGEN_MD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_set_rsa_pss_keygen_md, -EVP_PKEY_CTX_set_rsa_pss_keygen_md_name, -EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md, -EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name, -EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen -\&\- EVP_PKEY RSA\-PSS algorithm support functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_set_rsa_pss_keygen_md(EVP_PKEY_CTX *pctx, -\& const EVP_MD *md); -\& int EVP_PKEY_CTX_set_rsa_pss_keygen_md_name(EVP_PKEY_CTX *ctx, -\& const char *mdname, -\& const char *mdprops); -\& int EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md(EVP_PKEY_CTX *pctx, -\& const EVP_MD *md); -\& int EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name(EVP_PKEY_CTX *pctx, -\& const char *mdname); -\& int EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen(EVP_PKEY_CTX *pctx, -\& int saltlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These are the functions that implement \s-1\fBRSA\-PSS\s0\fR\|(7). -.SS "Signing and Verification" -.IX Subsection "Signing and Verification" -The macro \fBEVP_PKEY_CTX_set_rsa_padding()\fR is supported but an error is -returned if an attempt is made to set the padding mode to anything other -than \fB\s-1PSS\s0\fR. It is otherwise similar to the \fB\s-1RSA\s0\fR version. -.PP -The \fBEVP_PKEY_CTX_set_rsa_pss_saltlen()\fR macro is used to set the salt length. -If the key has usage restrictions then an error is returned if an attempt is -made to set the salt length below the minimum value. It is otherwise similar -to the \fB\s-1RSA\s0\fR operation except detection of the salt length (using -\&\s-1RSA_PSS_SALTLEN_AUTO\s0) is not supported for verification if the key has -usage restrictions. -.PP -The \fBEVP_PKEY_CTX_set_signature_md\fR\|(3) and \fBEVP_PKEY_CTX_set_rsa_mgf1_md\fR\|(3) -functions are used to set the digest and \s-1MGF1\s0 algorithms respectively. If the -key has usage restrictions then an error is returned if an attempt is made to -set the digest to anything other than the restricted value. Otherwise these are -similar to the \fB\s-1RSA\s0\fR versions. -.SS "Key Generation" -.IX Subsection "Key Generation" -As with \s-1RSA\s0 key generation the \fBEVP_PKEY_CTX_set_rsa_keygen_bits()\fR -and \fBEVP_PKEY_CTX_set_rsa_keygen_pubexp()\fR macros are supported for RSA-PSS: -they have exactly the same meaning as for the \s-1RSA\s0 algorithm. -.PP -Optional parameter restrictions can be specified when generating a \s-1PSS\s0 key. -If any restrictions are set (using the macros described below) then \fBall\fR -parameters are restricted. For example, setting a minimum salt length also -restricts the digest and \s-1MGF1\s0 algorithms. If any restrictions are in place -then they are reflected in the corresponding parameters of the public key -when (for example) a certificate request is signed. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_md()\fR restricts the digest algorithm the -generated key can use to \fImd\fR. -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_md_name()\fR does the same thing, but -passes the algorithm by name rather than by \fB\s-1EVP_MD\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md()\fR restricts the \s-1MGF1\s0 algorithm the -generated key can use to \fImd\fR. -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name()\fR does the same thing, but -passes the algorithm by name rather than by \fB\s-1EVP_MD\s0\fR. -.PP -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_saltlen()\fR restricts the minimum salt length -to \fIsaltlen\fR. -.SH "NOTES" -.IX Header "NOTES" -A context for the \fBRSA-PSS\fR algorithm can be obtained by calling: -.PP -.Vb 1 -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_RSA_PSS, NULL); -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 for success and 0 or a negative value for failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBRSA\-PSS\s0\fR\|(7), -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md_name.3ossl deleted file mode 120000 index 5f2f9ab3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md.3ossl deleted file mode 120000 index 5f2f9ab3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name.3ossl deleted file mode 120000 index 5f2f9ab3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen.3ossl deleted file mode 120000 index 5f2f9ab3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_rsa_pss_keygen_md.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_saltlen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_saltlen.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_rsa_pss_saltlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_N.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_N.3ossl deleted file mode 100644 index 0e289939..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_N.3ossl +++ /dev/null @@ -1,221 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_SET_SCRYPT_N 3ossl" -.TH EVP_PKEY_CTX_SET_SCRYPT_N 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_set1_scrypt_salt, -EVP_PKEY_CTX_set_scrypt_N, -EVP_PKEY_CTX_set_scrypt_r, -EVP_PKEY_CTX_set_scrypt_p, -EVP_PKEY_CTX_set_scrypt_maxmem_bytes -\&\- EVP_PKEY scrypt KDF support functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_set1_scrypt_salt(EVP_PKEY_CTX *pctx, unsigned char *salt, -\& int saltlen); -\& -\& int EVP_PKEY_CTX_set_scrypt_N(EVP_PKEY_CTX *pctx, uint64_t N); -\& -\& int EVP_PKEY_CTX_set_scrypt_r(EVP_PKEY_CTX *pctx, uint64_t r); -\& -\& int EVP_PKEY_CTX_set_scrypt_p(EVP_PKEY_CTX *pctx, uint64_t p); -\& -\& int EVP_PKEY_CTX_set_scrypt_maxmem_bytes(EVP_PKEY_CTX *pctx, -\& uint64_t maxmem); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are used to set up the necessary data to use the -scrypt \s-1KDF.\s0 -For more information on scrypt, see \s-1\fBEVP_KDF\-SCRYPT\s0\fR\|(7). -.PP -\&\fBEVP_PKEY_CTX_set1_scrypt_salt()\fR sets the \fBsaltlen\fR bytes long salt -value. -.PP -\&\fBEVP_PKEY_CTX_set_scrypt_N()\fR, \fBEVP_PKEY_CTX_set_scrypt_r()\fR and -\&\fBEVP_PKEY_CTX_set_scrypt_p()\fR configure the work factors N, r and p. -.PP -\&\fBEVP_PKEY_CTX_set_scrypt_maxmem_bytes()\fR sets how much \s-1RAM\s0 key -derivation may maximally use, given in bytes. -If \s-1RAM\s0 is exceeded because the load factors are chosen too high, the -key derivation will fail. -.SH "STRING CTRLS" -.IX Header "STRING CTRLS" -scrypt also supports string based control operations via -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3). -Similarly, the \fBsalt\fR can either be specified using the \fBtype\fR -parameter \*(L"salt\*(R" or in hex encoding by using the \*(L"hexsalt\*(R" parameter. -The work factors \fBN\fR, \fBr\fR and \fBp\fR as well as \fBmaxmem_bytes\fR can be -set by using the parameters \*(L"N\*(R", \*(L"r\*(R", \*(L"p\*(R" and \*(L"maxmem_bytes\*(R", -respectively. -.SH "NOTES" -.IX Header "NOTES" -There is a newer generic \s-1API\s0 for KDFs, \s-1\fBEVP_KDF\s0\fR\|(3), which is -preferred over the \s-1EVP_PKEY\s0 method. -.PP -The scrypt \s-1KDF\s0 also uses \fBEVP_PKEY_CTX_set1_pbe_pass()\fR as well as -the value from the string controls \*(L"pass\*(R" and \*(L"hexpass\*(R". -See \fBEVP_PKEY_CTX_set1_pbe_pass\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 for success and 0 or a negative value for -failure. -In particular a return value of \-2 indicates the operation is not -supported by the public key algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3) -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of the functions described here were converted from macros to functions in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_maxmem_bytes.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_maxmem_bytes.3ossl deleted file mode 120000 index 2cd3b0b4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_maxmem_bytes.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_scrypt_N.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_p.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_p.3ossl deleted file mode 120000 index 2cd3b0b4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_p.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_scrypt_N.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_r.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_r.3ossl deleted file mode 120000 index 2cd3b0b4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_scrypt_r.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_scrypt_N.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature.3ossl deleted file mode 120000 index 341edffb..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature_md.3ossl deleted file mode 120000 index c003742b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_signature_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3ossl deleted file mode 100644 index 12b7bbef..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CTX_SET_TLS1_PRF_MD 3ossl" -.TH EVP_PKEY_CTX_SET_TLS1_PRF_MD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_CTX_set_tls1_prf_md, -EVP_PKEY_CTX_set1_tls1_prf_secret, EVP_PKEY_CTX_add1_tls1_prf_seed \- -TLS PRF key derivation algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_CTX_set_tls1_prf_md(EVP_PKEY_CTX *pctx, const EVP_MD *md); -\& int EVP_PKEY_CTX_set1_tls1_prf_secret(EVP_PKEY_CTX *pctx, -\& unsigned char *sec, int seclen); -\& int EVP_PKEY_CTX_add1_tls1_prf_seed(EVP_PKEY_CTX *pctx, -\& unsigned char *seed, int seedlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1EVP_PKEY_TLS1_PRF\s0\fR algorithm implements the \s-1PRF\s0 key derivation function for -\&\s-1TLS.\s0 It has no associated private key and only implements key derivation -using \fBEVP_PKEY_derive\fR\|(3). -.PP -\&\fBEVP_PKEY_set_tls1_prf_md()\fR sets the message digest associated with the -\&\s-1TLS PRF.\s0 \fBEVP_md5_sha1()\fR is treated as a special case which uses the \s-1PRF\s0 -algorithm using both \fB\s-1MD5\s0\fR and \fB\s-1SHA1\s0\fR as used in \s-1TLS 1.0\s0 and 1.1. -.PP -\&\fBEVP_PKEY_CTX_set_tls1_prf_secret()\fR sets the secret value of the \s-1TLS PRF\s0 -to \fBseclen\fR bytes of the buffer \fBsec\fR. Any existing secret value is replaced -and any seed is reset. -.PP -\&\fBEVP_PKEY_CTX_add1_tls1_prf_seed()\fR sets the seed to \fBseedlen\fR bytes of \fBseed\fR. -If a seed is already set it is appended to the existing value. -.SH "STRING CTRLS" -.IX Header "STRING CTRLS" -The \s-1TLS PRF\s0 also supports string based control operations using -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3). -The \fBtype\fR parameter \*(L"md\*(R" uses the supplied \fBvalue\fR as the name of the digest -algorithm to use. -The \fBtype\fR parameters \*(L"secret\*(R" and \*(L"seed\*(R" use the supplied \fBvalue\fR parameter -as a secret or seed value. -The names \*(L"hexsecret\*(R" and \*(L"hexseed\*(R" are similar except they take a hex string -which is converted to binary. -.SH "NOTES" -.IX Header "NOTES" -A context for the \s-1TLS PRF\s0 can be obtained by calling: -.PP -.Vb 1 -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_TLS1_PRF, NULL); -.Ve -.PP -The digest, secret value and seed must be set before a key is derived or an -error occurs. -.PP -The total length of all seeds cannot exceed 1024 bytes in length: this should -be more than enough for any normal use of the \s-1TLS PRF.\s0 -.PP -The output length of the \s-1PRF\s0 is specified by the length parameter in the -\&\fBEVP_PKEY_derive()\fR function. Since the output length is variable, setting -the buffer to \fB\s-1NULL\s0\fR is not meaningful for the \s-1TLS PRF.\s0 -.PP -Optimised versions of the \s-1TLS PRF\s0 can be implemented in an \s-1ENGINE.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 for success and 0 or a negative value for failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 10 bytes using \s-1SHA\-256\s0 with the secret key \*(L"secret\*(R" -and seed value \*(L"seed\*(R": -.PP -.Vb 3 -\& EVP_PKEY_CTX *pctx; -\& unsigned char out[10]; -\& size_t outlen = sizeof(out); -\& -\& pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_TLS1_PRF, NULL); -\& if (EVP_PKEY_derive_init(pctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_tls1_prf_md(pctx, EVP_sha256()) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set1_tls1_prf_secret(pctx, "secret", 6) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_add1_tls1_prf_seed(pctx, "seed", 4) <= 0) -\& /* Error */ -\& if (EVP_PKEY_derive(pctx, out, &outlen) <= 0) -\& /* Error */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of the functions described here were converted from macros to functions in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_CTX_settable_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_CTX_settable_params.3ossl deleted file mode 120000 index d5e1e4c8..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_CTX_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_CTX_set_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_METHOD.3ossl b/openssl-install/share/man/man3/EVP_PKEY_METHOD.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_METHOD.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_Q_keygen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_Q_keygen.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_Q_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_add1_attr.3ossl b/openssl-install/share/man/man3/EVP_PKEY_add1_attr.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_add1_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_NID.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_OBJ.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_txt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_txt.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_add1_attr_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_add0.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_add0.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_add0.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_add_alias.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_add_alias.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_add_alias.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_copy.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_copy.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_find.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_find.3ossl deleted file mode 120000 index 1387b4d8..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_asn1_get_count.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_find_str.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_find_str.3ossl deleted file mode 120000 index 1387b4d8..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_find_str.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_asn1_get_count.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_free.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_free.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_get0.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_get0.3ossl deleted file mode 120000 index 1387b4d8..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_asn1_get_count.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_get0_info.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_get0_info.3ossl deleted file mode 120000 index 1387b4d8..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_get0_info.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_asn1_get_count.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_get_count.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_get_count.3ossl deleted file mode 100644 index a6c5b75c..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_get_count.3ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_ASN1_GET_COUNT 3ossl" -.TH EVP_PKEY_ASN1_GET_COUNT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_asn1_find, -EVP_PKEY_asn1_find_str, -EVP_PKEY_asn1_get_count, -EVP_PKEY_asn1_get0, -EVP_PKEY_asn1_get0_info -\&\- enumerate public key ASN.1 methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_asn1_get_count(void); -\& const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_get0(int idx); -\& const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find(ENGINE **pe, int type); -\& const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find_str(ENGINE **pe, -\& const char *str, int len); -\& int EVP_PKEY_asn1_get0_info(int *ppkey_id, int *pkey_base_id, -\& int *ppkey_flags, const char **pinfo, -\& const char **ppem_str, -\& const EVP_PKEY_ASN1_METHOD *ameth); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_asn1_count()\fR returns a count of the number of public key -\&\s-1ASN.1\s0 methods available: it includes standard methods and any methods -added by the application. -.PP -\&\fBEVP_PKEY_asn1_get0()\fR returns the public key \s-1ASN.1\s0 method \fBidx\fR. -The value of \fBidx\fR must be between zero and \fBEVP_PKEY_asn1_get_count()\fR -\&\- 1. -.PP -\&\fBEVP_PKEY_asn1_find()\fR looks up the \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR with \s-1NID\s0 -\&\fBtype\fR. -If \fBpe\fR isn't \fB\s-1NULL\s0\fR, then it will look up an engine implementing a -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR for the \s-1NID\s0 \fBtype\fR and return that instead, -and also set \fB*pe\fR to point at the engine that implements it. -.PP -\&\fBEVP_PKEY_asn1_find_str()\fR looks up the \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR with \s-1PEM\s0 -type string \fBstr\fR. -Just like \fBEVP_PKEY_asn1_find()\fR, if \fBpe\fR isn't \fB\s-1NULL\s0\fR, then it will -look up an engine implementing a \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR for the \s-1NID\s0 -\&\fBtype\fR and return that instead, and also set \fB*pe\fR to point at the -engine that implements it. -.PP -\&\fBEVP_PKEY_asn1_get0_info()\fR returns the public key \s-1ID,\s0 base public key -\&\s-1ID\s0 (both NIDs), any flags, the method description and \s-1PEM\s0 type string -associated with the public key \s-1ASN.1\s0 method \fB*ameth\fR. -.PP -\&\fBEVP_PKEY_asn1_count()\fR, \fBEVP_PKEY_asn1_get0()\fR, \fBEVP_PKEY_asn1_find()\fR and -\&\fBEVP_PKEY_asn1_find_str()\fR are not thread safe, but as long as all -\&\fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR objects are added before the application gets -threaded, using them is safe. See \fBEVP_PKEY_asn1_add0\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_asn1_count()\fR returns the number of available public key methods. -.PP -\&\fBEVP_PKEY_asn1_get0()\fR return a public key method or \fB\s-1NULL\s0\fR if \fBidx\fR is -out of range. -.PP -\&\fBEVP_PKEY_asn1_get0_info()\fR returns 0 on failure, 1 on success. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_asn1_new\fR\|(3), \fBEVP_PKEY_asn1_add0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_new.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_new.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_check.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_ctrl.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_ctrl.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_free.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_free.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_priv_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_priv_key.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_priv_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_pub_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_pub_key.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_get_pub_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_item.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_item.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_item.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_param.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_param_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_param_check.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_param_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_private.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_private.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_private.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_public.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_public.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_public.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_public_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_public_check.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_public_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_security_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_security_bits.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_security_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_priv_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_priv_key.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_priv_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_pub_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_pub_key.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_set_pub_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_siginf.3ossl b/openssl-install/share/man/man3/EVP_PKEY_asn1_set_siginf.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_asn1_set_siginf.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_assign_DH.3ossl b/openssl-install/share/man/man3/EVP_PKEY_assign_DH.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_assign_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_assign_DSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_assign_DSA.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_assign_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_assign_EC_KEY.3ossl b/openssl-install/share/man/man3/EVP_PKEY_assign_EC_KEY.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_assign_EC_KEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_assign_POLY1305.3ossl b/openssl-install/share/man/man3/EVP_PKEY_assign_POLY1305.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_assign_POLY1305.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_assign_RSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_assign_RSA.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_assign_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_assign_SIPHASH.3ossl b/openssl-install/share/man/man3/EVP_PKEY_assign_SIPHASH.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_assign_SIPHASH.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_auth_decapsulate_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_auth_decapsulate_init.3ossl deleted file mode 120000 index 51692ff1..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_auth_decapsulate_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_decapsulate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_auth_encapsulate_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_auth_encapsulate_init.3ossl deleted file mode 120000 index ca8beb26..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_auth_encapsulate_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_encapsulate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_base_id.3ossl b/openssl-install/share/man/man3/EVP_PKEY_base_id.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_base_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_bits.3ossl deleted file mode 120000 index 16e1e92b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_can_sign.3ossl b/openssl-install/share/man/man3/EVP_PKEY_can_sign.3ossl deleted file mode 120000 index 21a9674e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_can_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_is_a.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_check.3ossl deleted file mode 100644 index ac6af037..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_check.3ossl +++ /dev/null @@ -1,231 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_CHECK 3ossl" -.TH EVP_PKEY_CHECK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_check, EVP_PKEY_param_check, EVP_PKEY_param_check_quick, -EVP_PKEY_public_check, EVP_PKEY_public_check_quick, EVP_PKEY_private_check, -EVP_PKEY_pairwise_check -\&\- key and parameter validation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_check(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_param_check(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_param_check_quick(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_public_check(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_public_check_quick(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_private_check(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_pairwise_check(EVP_PKEY_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_param_check()\fR validates the parameters component of the key -given by \fBctx\fR. This check will always succeed for key types that do not have -parameters. -.PP -\&\fBEVP_PKEY_param_check_quick()\fR validates the parameters component of the key -given by \fBctx\fR like \fBEVP_PKEY_param_check()\fR does. However some algorithm -implementations may offer a quicker form of validation that omits some checks in -order to perform a lightweight sanity check of the key. If a quicker form is not -provided then this function call does the same thing as \fBEVP_PKEY_param_check()\fR. -.PP -\&\fBEVP_PKEY_public_check()\fR validates the public component of the key given by \fBctx\fR. -.PP -\&\fBEVP_PKEY_public_check_quick()\fR validates the public component of the key -given by \fBctx\fR like \fBEVP_PKEY_public_check()\fR does. However some algorithm -implementations may offer a quicker form of validation that omits some checks in -order to perform a lightweight sanity check of the key. If a quicker form is not -provided then this function call does the same thing as \fBEVP_PKEY_public_check()\fR. -.PP -\&\fBEVP_PKEY_private_check()\fR validates the private component of the key given by \fBctx\fR. -.PP -\&\fBEVP_PKEY_pairwise_check()\fR validates that the public and private components have -the correct mathematical relationship to each other for the key given by \fBctx\fR. -.PP -\&\fBEVP_PKEY_check()\fR is an alias for the \fBEVP_PKEY_pairwise_check()\fR function. -.SH "NOTES" -.IX Header "NOTES" -Key validation used by the OpenSSL \s-1FIPS\s0 provider complies with the rules -within \s-1SP800\-56A\s0 and \s-1SP800\-56B.\s0 For backwards compatibility reasons the OpenSSL -default provider may use checks that are not as restrictive for certain key types. -For further information see \*(L"\s-1DSA\s0 key validation\*(R" in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), -\&\*(L"\s-1DH\s0 key validation\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7), \*(L"\s-1EC\s0 key validation\*(R" in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) and -\&\*(L"\s-1RSA\s0 key validation\*(R" in \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7). -.PP -Refer to \s-1SP800\-56A\s0 and \s-1SP800\-56B\s0 for rules relating to when these functions -should be called during key establishment. -It is not necessary to call these functions after locally calling an approved key -generation method, but may be required for assurance purposes when receiving -keys from a third party. -.PP -The \fBEVP_PKEY_pairwise_check()\fR and \fBEVP_PKEY_private_check()\fR might not be bounded -by any key size limits as private keys are not expected to be supplied by -attackers. For that reason they might take an unbounded time if run on -arbitrarily large keys. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return 1 for success or others for failure. -They return \-2 if the operation is not supported for the specific algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_fromdata\fR\|(3), -\&\s-1\fBEVP_PKEY\-DH\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-FFC\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-EC\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-RSA\s0\fR\|(7), -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_PKEY_check()\fR, \fBEVP_PKEY_public_check()\fR and \fBEVP_PKEY_param_check()\fR were added -in OpenSSL 1.1.1. -.PP -\&\fBEVP_PKEY_param_check_quick()\fR, \fBEVP_PKEY_public_check_quick()\fR, -\&\fBEVP_PKEY_private_check()\fR and \fBEVP_PKEY_pairwise_check()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_cmp.3ossl b/openssl-install/share/man/man3/EVP_PKEY_cmp.3ossl deleted file mode 120000 index 9da46e99..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_copy_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_cmp_parameters.3ossl b/openssl-install/share/man/man3/EVP_PKEY_cmp_parameters.3ossl deleted file mode 120000 index 9da46e99..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_cmp_parameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_copy_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_copy_parameters.3ossl b/openssl-install/share/man/man3/EVP_PKEY_copy_parameters.3ossl deleted file mode 100644 index d58101c1..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_copy_parameters.3ossl +++ /dev/null @@ -1,236 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_COPY_PARAMETERS 3ossl" -.TH EVP_PKEY_COPY_PARAMETERS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_missing_parameters, EVP_PKEY_copy_parameters, EVP_PKEY_parameters_eq, -EVP_PKEY_cmp_parameters, EVP_PKEY_eq, -EVP_PKEY_cmp \- public key parameter and comparison functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_missing_parameters(const EVP_PKEY *pkey); -\& int EVP_PKEY_copy_parameters(EVP_PKEY *to, const EVP_PKEY *from); -\& -\& int EVP_PKEY_parameters_eq(const EVP_PKEY *a, const EVP_PKEY *b); -\& int EVP_PKEY_eq(const EVP_PKEY *a, const EVP_PKEY *b); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int EVP_PKEY_cmp_parameters(const EVP_PKEY *a, const EVP_PKEY *b); -\& int EVP_PKEY_cmp(const EVP_PKEY *a, const EVP_PKEY *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBEVP_PKEY_missing_parameters()\fR returns 1 if the public key -parameters of \fBpkey\fR are missing and 0 if they are present or the algorithm -doesn't use parameters. -.PP -The function \fBEVP_PKEY_copy_parameters()\fR copies the parameters from key -\&\fBfrom\fR to key \fBto\fR. An error is returned if the parameters are missing in -\&\fBfrom\fR or present in both \fBfrom\fR and \fBto\fR and mismatch. If the parameters -in \fBfrom\fR and \fBto\fR are both present and match this function has no effect. -.PP -The function \fBEVP_PKEY_parameters_eq()\fR checks the parameters of keys -\&\fBa\fR and \fBb\fR for equality. -.PP -The function \fBEVP_PKEY_eq()\fR checks the keys \fBa\fR and \fBb\fR for equality, -including their parameters if they are available. -.SH "NOTES" -.IX Header "NOTES" -The main purpose of the functions \fBEVP_PKEY_missing_parameters()\fR and -\&\fBEVP_PKEY_copy_parameters()\fR is to handle public keys in certificates where the -parameters are sometimes omitted from a public key if they are inherited from -the \s-1CA\s0 that signed it. -.PP -The deprecated functions \fBEVP_PKEY_cmp()\fR and \fBEVP_PKEY_cmp_parameters()\fR differ in -their return values compared to other \fB_cmp()\fR functions. They are aliases for -\&\fBEVP_PKEY_eq()\fR and \fBEVP_PKEY_parameters_eq()\fR. -.PP -The function \fBEVP_PKEY_cmp()\fR previously only checked the key parameters -(if there are any) and the public key, assuming that there always was -a public key and that private key equality could be derived from that. -Because it's no longer assumed that the private key in an \s-1\fBEVP_PKEY\s0\fR\|(3) is -always accompanied by a public key, the comparison can not rely on public -key comparison alone. -.PP -Instead, \fBEVP_PKEY_eq()\fR (and therefore also \fBEVP_PKEY_cmp()\fR) now compares: -.IP "1." 4 -the key parameters (if there are any) -.IP "2." 4 -the public keys or the private keys of the two \fB\s-1EVP_PKEY\s0\fRs, depending on -what they both contain. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The function \fBEVP_PKEY_missing_parameters()\fR returns 1 if the public key -parameters of \fBpkey\fR are missing and 0 if they are present or the algorithm -doesn't use parameters. -.PP -These functions \fBEVP_PKEY_copy_parameters()\fR returns 1 for success and 0 for -failure. -.PP -The functions \fBEVP_PKEY_cmp_parameters()\fR, \fBEVP_PKEY_parameters_eq()\fR, -\&\fBEVP_PKEY_cmp()\fR and \fBEVP_PKEY_eq()\fR return 1 if their -inputs match, 0 if they don't match, \-1 if the key types are different and -\&\-2 if the operation is not supported. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_keygen\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_cmp()\fR and \fBEVP_PKEY_cmp_parameters()\fR functions were deprecated in -OpenSSL 3.0. -.PP -The \fBEVP_PKEY_eq()\fR and \fBEVP_PKEY_parameters_eq()\fR were added in OpenSSL 3.0 to -replace \fBEVP_PKEY_cmp()\fR and \fBEVP_PKEY_cmp_parameters()\fR. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_decapsulate.3ossl b/openssl-install/share/man/man3/EVP_PKEY_decapsulate.3ossl deleted file mode 100644 index 818fac56..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_decapsulate.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_DECAPSULATE 3ossl" -.TH EVP_PKEY_DECAPSULATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_decapsulate_init, EVP_PKEY_auth_decapsulate_init, EVP_PKEY_decapsulate -\&\- Key decapsulation using a KEM algorithm with a private key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_decapsulate_init(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_PKEY_auth_decapsulate_init(EVP_PKEY_CTX *ctx, EVP_PKEY *authpub, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_decapsulate(EVP_PKEY_CTX *ctx, -\& unsigned char *unwrapped, size_t *unwrappedlen, -\& const unsigned char *wrapped, size_t wrappedlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_PKEY_decapsulate_init()\fR function initializes a private key algorithm -context \fIctx\fR for a decapsulation operation and then sets the \fIparams\fR -on the context in the same way as calling \fBEVP_PKEY_CTX_set_params\fR\|(3). -Note that \fIctx\fR usually is produced using \fBEVP_PKEY_CTX_new_from_pkey\fR\|(3), -specifying the private key to use. -.PP -The \fBEVP_PKEY_auth_decapsulate_init()\fR function is similar to -\&\fBEVP_PKEY_decapsulate_init()\fR but also passes an \fIauthpub\fR authentication public -key that is used during decapsulation. -.PP -The \fBEVP_PKEY_decapsulate()\fR function performs a private key decapsulation -operation using \fIctx\fR. The data to be decapsulated is specified using the -\&\fIwrapped\fR and \fIwrappedlen\fR parameters. -If \fIunwrapped\fR is \s-1NULL\s0 then the size of the output secret buffer -is written to \fI*unwrappedlen\fR. If \fIunwrapped\fR is not \s-1NULL\s0 and the -call is successful then the decapsulated secret data is written to \fIunwrapped\fR -and the amount of data written to \fI*unwrappedlen\fR. Note that, if \fIunwrappedlen\fR -is not \s-1NULL\s0 in this call, the value it points to must be initialised to the length of -\&\fIunwrapped\fR, so that the call can validate it is of sufficient size to hold the -result of the operation. -.SH "NOTES" -.IX Header "NOTES" -After the call to \fBEVP_PKEY_decapsulate_init()\fR algorithm-specific parameters -for the operation may be set or modified using \fBEVP_PKEY_CTX_set_params\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_decapsulate_init()\fR, \fBEVP_PKEY_auth_decapsulate_init()\fR and -\&\fBEVP_PKEY_decapsulate()\fR return 1 for success and 0 or a negative value for -failure. In particular a return value of \-2 indicates the operation is not -supported by the private key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Decapsulate data using \s-1RSA:\s0 -.PP -.Vb 1 -\& #include -\& -\& /* -\& * NB: assumes rsa_priv_key is an RSA private key, -\& * and that in, inlen are already set up to contain encapsulated data. -\& */ -\& -\& EVP_PKEY_CTX *ctx = NULL; -\& size_t secretlen = 0; -\& unsigned char *secret = NULL;; -\& -\& ctx = EVP_PKEY_CTX_new_from_pkey(libctx, rsa_priv_key, NULL); -\& if (ctx == NULL) -\& /* Error */ -\& if (EVP_PKEY_decapsulate_init(ctx, NULL) <= 0) -\& /* Error */ -\& -\& /* Set the mode \- only \*(AqRSASVE\*(Aq is currently supported */ -\& if (EVP_PKEY_CTX_set_kem_op(ctx, "RSASVE") <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_decapsulate(ctx, NULL, &secretlen, in, inlen) <= 0) -\& /* Error */ -\& -\& secret = OPENSSL_malloc(secretlen); -\& if (secret == NULL) -\& /* malloc failure */ -\& -\& /* Decapsulated secret data is secretlen bytes long */ -\& if (EVP_PKEY_decapsulate(ctx, secret, &secretlen, in, inlen) <= 0) -\& /* Error */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new_from_pkey\fR\|(3), -\&\fBEVP_PKEY_encapsulate\fR\|(3), -\&\s-1\fBEVP_KEM\-RSA\s0\fR\|(7), \s-1\fBEVP_KEM\-X25519\s0\fR\|(7), \s-1\fBEVP_KEM\-EC\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBEVP_PKEY_decapsulate_init()\fR and \fBEVP_PKEY_decapsulate()\fR were added -in OpenSSL 3.0. -.PP -The function \fBEVP_PKEY_auth_decapsulate_init()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_decapsulate_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_decapsulate_init.3ossl deleted file mode 120000 index 51692ff1..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_decapsulate_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_decapsulate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_decrypt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_decrypt.3ossl deleted file mode 100644 index c2185e43..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_decrypt.3ossl +++ /dev/null @@ -1,266 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_DECRYPT 3ossl" -.TH EVP_PKEY_DECRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_decrypt_init, EVP_PKEY_decrypt_init_ex, -EVP_PKEY_decrypt \- decrypt using a public key algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_decrypt_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_decrypt_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_PKEY_decrypt(EVP_PKEY_CTX *ctx, -\& unsigned char *out, size_t *outlen, -\& const unsigned char *in, size_t inlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_PKEY_decrypt_init()\fR function initializes a public key algorithm -context using key \fIpkey\fR for a decryption operation. -.PP -The \fBEVP_PKEY_decrypt_init_ex()\fR function initializes a public key algorithm -context using key \fIpkey\fR for a decryption operation and sets the -algorithm specific \fIparams\fR. -.PP -The \fBEVP_PKEY_decrypt()\fR function performs a public key decryption operation -using \fIctx\fR. The data to be decrypted is specified using the \fIin\fR and -\&\fIinlen\fR parameters. If \fIout\fR is \s-1NULL\s0 then the minimum required size of -the output buffer is written to the \fI*outlen\fR parameter. -.PP -If \fIout\fR is not \s-1NULL\s0 then before the call the \fI*outlen\fR parameter must -contain the length of the \fIout\fR buffer. If the call is successful the -decrypted data is written to \fIout\fR and the amount of the decrypted data -written to \fI*outlen\fR, otherwise an error is returned. -.SH "NOTES" -.IX Header "NOTES" -After the call to \fBEVP_PKEY_decrypt_init()\fR algorithm specific control -operations can be performed to set any appropriate parameters for the -operation. These operations can be included in the \fBEVP_PKEY_decrypt_init_ex()\fR -call. -.PP -The function \fBEVP_PKEY_decrypt()\fR can be called more than once on the same -context if several operations are performed using the same parameters. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_decrypt_init()\fR, \fBEVP_PKEY_decrypt_init_ex()\fR and \fBEVP_PKEY_decrypt()\fR -return 1 for success and 0 or a negative value for failure. In particular a -return value of \-2 indicates the operation is not supported by the public key -algorithm. -.SH "WARNINGS" -.IX Header "WARNINGS" -In OpenSSL versions before 3.2.0, when used in PKCS#1 v1.5 padding, -both the return value from the \fBEVP_PKEY_decrypt()\fR and the \fBoutlen\fR provided -information useful in mounting a Bleichenbacher attack against the -used private key. They had to be processed in a side-channel free way. -.PP -Since version 3.2.0, the \fBEVP_PKEY_decrypt()\fR method when used with PKCS#1 -v1.5 padding as implemented in the \fBdefault\fR provider implements -the implicit rejection mechanism (see -\&\fB\s-1OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION\s0\fR in \fBprovider\-asym_cipher\fR\|(7)). -That means it doesn't return an error when it detects an error in padding, -instead it returns a pseudo-randomly generated message, removing the need -of side-channel secure code from applications using OpenSSL. -If OpenSSL is configured to use a provider that doesn't implement implicit -rejection, the code still needs to handle the returned values -using side-channel free code. -Side-channel free handling of the error stack can be performed using -either a pair of unconditional \fBERR_set_mark\fR\|(3) and \fBERR_pop_to_mark\fR\|(3) -calls or by using the \fBERR_clear_error\fR\|(3) call. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Decrypt data using \s-1OAEP\s0 (for \s-1RSA\s0 keys): -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& ENGINE *eng; -\& unsigned char *out, *in; -\& size_t outlen, inlen; -\& EVP_PKEY *key; -\& -\& /* -\& * NB: assumes key, eng, in, inlen are already set up -\& * and that key is an RSA private key -\& */ -\& ctx = EVP_PKEY_CTX_new(key, eng); -\& if (!ctx) -\& /* Error occurred */ -\& if (EVP_PKEY_decrypt_init(ctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_OAEP_PADDING) <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_decrypt(ctx, NULL, &outlen, in, inlen) <= 0) -\& /* Error */ -\& -\& out = OPENSSL_malloc(outlen); -\& -\& if (!out) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_decrypt(ctx, out, &outlen, in, inlen) <= 0) -\& /* Error */ -\& -\& /* Decrypted data is outlen bytes written to buffer out */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_decrypt_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_decrypt_init.3ossl deleted file mode 120000 index a2316bf4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_decrypt_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_decrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_decrypt_init_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_decrypt_init_ex.3ossl deleted file mode 120000 index a2316bf4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_decrypt_init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_decrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_delete_attr.3ossl b/openssl-install/share/man/man3/EVP_PKEY_delete_attr.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_delete_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_derive.3ossl b/openssl-install/share/man/man3/EVP_PKEY_derive.3ossl deleted file mode 100644 index 57a133b4..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_derive.3ossl +++ /dev/null @@ -1,255 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_DERIVE 3ossl" -.TH EVP_PKEY_DERIVE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_derive_init, EVP_PKEY_derive_init_ex, -EVP_PKEY_derive_set_peer_ex, EVP_PKEY_derive_set_peer, EVP_PKEY_derive -\&\- derive public key algorithm shared secret -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_derive_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_derive_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_PKEY_derive_set_peer_ex(EVP_PKEY_CTX *ctx, EVP_PKEY *peer, -\& int validate_peer); -\& int EVP_PKEY_derive_set_peer(EVP_PKEY_CTX *ctx, EVP_PKEY *peer); -\& int EVP_PKEY_derive(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_derive_init()\fR initializes a public key algorithm context \fIctx\fR for -shared secret derivation using the algorithm given when the context was created -using \fBEVP_PKEY_CTX_new\fR\|(3) or variants thereof. The algorithm is used to -fetch a \fB\s-1EVP_KEYEXCH\s0\fR method implicitly, see \*(L"Implicit fetch\*(R" in \fBprovider\fR\|(7) for -more information about implicit fetches. -.PP -\&\fBEVP_PKEY_derive_init_ex()\fR is the same as \fBEVP_PKEY_derive_init()\fR but additionally -sets the passed parameters \fIparams\fR on the context before returning. -.PP -\&\fBEVP_PKEY_derive_set_peer_ex()\fR sets the peer key: this will normally -be a public key. The \fIvalidate_peer\fR will validate the public key if this value -is non zero. -.PP -\&\fBEVP_PKEY_derive_set_peer()\fR is similar to \fBEVP_PKEY_derive_set_peer_ex()\fR with -\&\fIvalidate_peer\fR set to 1. -.PP -\&\fBEVP_PKEY_derive()\fR derives a shared secret using \fIctx\fR. -If \fIkey\fR is \s-1NULL\s0 then the maximum size of the output buffer is written to the -\&\fIkeylen\fR parameter. If \fIkey\fR is not \s-1NULL\s0 then before the call the \fIkeylen\fR -parameter should contain the length of the \fIkey\fR buffer, if the call is -successful the shared secret is written to \fIkey\fR and the amount of data -written to \fIkeylen\fR. -.SH "NOTES" -.IX Header "NOTES" -After the call to \fBEVP_PKEY_derive_init()\fR, algorithm -specific control operations can be performed to set any appropriate parameters -for the operation. -.PP -The function \fBEVP_PKEY_derive()\fR can be called more than once on the same -context if several operations are performed using the same parameters. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_derive_init()\fR and \fBEVP_PKEY_derive()\fR return 1 -for success and 0 or a negative value for failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Derive shared secret (for example \s-1DH\s0 or \s-1EC\s0 keys): -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& ENGINE *eng; -\& unsigned char *skey; -\& size_t skeylen; -\& EVP_PKEY *pkey, *peerkey; -\& /* NB: assumes pkey, eng, peerkey have been already set up */ -\& -\& ctx = EVP_PKEY_CTX_new(pkey, eng); -\& if (!ctx) -\& /* Error occurred */ -\& if (EVP_PKEY_derive_init(ctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_derive_set_peer(ctx, peerkey) <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_derive(ctx, NULL, &skeylen) <= 0) -\& /* Error */ -\& -\& skey = OPENSSL_malloc(skeylen); -\& -\& if (!skey) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_derive(ctx, skey, &skeylen) <= 0) -\& /* Error */ -\& -\& /* Shared secret is skey bytes written to buffer skey */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_KEYEXCH_fetch\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_derive_init()\fR, \fBEVP_PKEY_derive_set_peer()\fR and \fBEVP_PKEY_derive()\fR -functions were originally added in OpenSSL 1.0.0. -.PP -The \fBEVP_PKEY_derive_init_ex()\fR and \fBEVP_PKEY_derive_set_peer_ex()\fR functions were -added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_derive_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_derive_init.3ossl deleted file mode 120000 index 631db418..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_derive_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_derive.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_derive_init_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_derive_init_ex.3ossl deleted file mode 120000 index 631db418..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_derive_init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_derive.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_derive_set_peer.3ossl b/openssl-install/share/man/man3/EVP_PKEY_derive_set_peer.3ossl deleted file mode 120000 index 631db418..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_derive_set_peer.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_derive.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_derive_set_peer_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_derive_set_peer_ex.3ossl deleted file mode 120000 index 631db418..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_derive_set_peer_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_derive.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_digestsign_supports_digest.3ossl b/openssl-install/share/man/man3/EVP_PKEY_digestsign_supports_digest.3ossl deleted file mode 100644 index 5f9be42c..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_digestsign_supports_digest.3ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_DIGESTSIGN_SUPPORTS_DIGEST 3ossl" -.TH EVP_PKEY_DIGESTSIGN_SUPPORTS_DIGEST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_digestsign_supports_digest \- indicate support for signature digest -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 3 -\& #include -\& int EVP_PKEY_digestsign_supports_digest(EVP_PKEY *pkey, OSSL_LIB_CTX *libctx, -\& const char *name, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_PKEY_digestsign_supports_digest()\fR function queries whether the message -digest \fIname\fR is supported for public key signature operations associated with -key \fIpkey\fR. The query is done within an optional library context \fIlibctx\fR and -with an optional property query \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBEVP_PKEY_digestsign_supports_digest()\fR function returns 1 if the message -digest algorithm identified by \fIname\fR can be used for public key signature -operations associated with key \fIpkey\fR and 0 if it cannot be used. It returns -a negative value for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestSignInit_ex\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_digestsign_supports_digest()\fR function was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_dup.3ossl b/openssl-install/share/man/man3/EVP_PKEY_dup.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_encapsulate.3ossl b/openssl-install/share/man/man3/EVP_PKEY_encapsulate.3ossl deleted file mode 100644 index aafd15dd..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_encapsulate.3ossl +++ /dev/null @@ -1,253 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_ENCAPSULATE 3ossl" -.TH EVP_PKEY_ENCAPSULATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_encapsulate_init, EVP_PKEY_auth_encapsulate_init, EVP_PKEY_encapsulate -\&\- Key encapsulation using a KEM algorithm with a public key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_encapsulate_init(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_PKEY_auth_encapsulate_init(EVP_PKEY_CTX *ctx, EVP_PKEY *authpriv, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_encapsulate(EVP_PKEY_CTX *ctx, -\& unsigned char *wrappedkey, size_t *wrappedkeylen, -\& unsigned char *genkey, size_t *genkeylen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_PKEY_encapsulate_init()\fR function initializes a public key algorithm -context \fIctx\fR for an encapsulation operation and then sets the \fIparams\fR -on the context in the same way as calling \fBEVP_PKEY_CTX_set_params\fR\|(3). -Note that \fIctx\fR is usually is produced using \fBEVP_PKEY_CTX_new_from_pkey\fR\|(3), -specifying the public key to use. -.PP -The \fBEVP_PKEY_auth_encapsulate_init()\fR function is similar to -\&\fBEVP_PKEY_encapsulate_init()\fR but also passes an \fIauthpriv\fR authentication private -key that is used during encapsulation. -.PP -The \fBEVP_PKEY_encapsulate()\fR function performs a public key encapsulation -operation using \fIctx\fR. -The symmetric secret generated in \fIgenkey\fR can be used as key material. -The ciphertext in \fIwrappedkey\fR is its encapsulated form, which can be sent -to another party, who can use \fBEVP_PKEY_decapsulate\fR\|(3) to retrieve it -using their private key. -If \fIwrappedkey\fR is \s-1NULL\s0 then the maximum size of the output buffer -is written to the \fI*wrappedkeylen\fR parameter unless \fIwrappedkeylen\fR is \s-1NULL\s0 -and the maximum size of the generated key buffer is written to \fI*genkeylen\fR -unless \fIgenkeylen\fR is \s-1NULL.\s0 -If \fIwrappedkey\fR is not \s-1NULL\s0 and the call is successful then the -internally generated key is written to \fIgenkey\fR and its size is written to -\&\fI*genkeylen\fR. The encapsulated version of the generated key is written to -\&\fIwrappedkey\fR and its size is written to \fI*wrappedkeylen\fR. Note that if -\&\fIwrappedlen\fR is not \s-1NULL,\s0 then the value it points to must initially hold the size of -the \fIunwrapped\fR buffer so that its size can be validated by the call, ensuring -it is large enough to hold the result written to \fIwrapped\fR. -.SH "NOTES" -.IX Header "NOTES" -After the call to \fBEVP_PKEY_encapsulate_init()\fR algorithm-specific parameters -for the operation may be set or modified using \fBEVP_PKEY_CTX_set_params\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_encapsulate_init()\fR, \fBEVP_PKEY_auth_encapsulate_init()\fR and -\&\fBEVP_PKEY_encapsulate()\fR return 1 for success and 0 or a negative value for -failure. In particular a return value of \-2 indicates the operation is not -supported by the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Encapsulate an \s-1RSASVE\s0 key (for \s-1RSA\s0 keys). -.PP -.Vb 1 -\& #include -\& -\& /* -\& * NB: assumes rsa_pub_key is an public key of another party. -\& */ -\& -\& EVP_PKEY_CTX *ctx = NULL; -\& size_t secretlen = 0, outlen = 0; -\& unsigned char *out = NULL, *secret = NULL; -\& -\& ctx = EVP_PKEY_CTX_new_from_pkey(libctx, rsa_pub_key, NULL); -\& if (ctx == NULL) -\& /* Error */ -\& if (EVP_PKEY_encapsulate_init(ctx, NULL) <= 0) -\& /* Error */ -\& -\& /* Set the mode \- only \*(AqRSASVE\*(Aq is currently supported */ -\& if (EVP_PKEY_CTX_set_kem_op(ctx, "RSASVE") <= 0) -\& /* Error */ -\& /* Determine buffer length */ -\& if (EVP_PKEY_encapsulate(ctx, NULL, &outlen, NULL, &secretlen) <= 0) -\& /* Error */ -\& -\& out = OPENSSL_malloc(outlen); -\& secret = OPENSSL_malloc(secretlen); -\& if (out == NULL || secret == NULL) -\& /* malloc failure */ -\& -\& /* -\& * The generated \*(Aqsecret\*(Aq can be used as key material. -\& * The encapsulated \*(Aqout\*(Aq can be sent to another party who can -\& * decapsulate it using their private key to retrieve the \*(Aqsecret\*(Aq. -\& */ -\& if (EVP_PKEY_encapsulate(ctx, out, &outlen, secret, &secretlen) <= 0) -\& /* Error */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new_from_pkey\fR\|(3), -\&\fBEVP_PKEY_decapsulate\fR\|(3), -\&\s-1\fBEVP_KEM\-RSA\s0\fR\|(7), \s-1\fBEVP_KEM\-X25519\s0\fR\|(7), \s-1\fBEVP_KEM\-EC\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -These functions \fBEVP_PKEY_encapsulate_init()\fR and \fBEVP_PKEY_encapsulate()\fR were -added in OpenSSL 3.0. -The function \fBEVP_PKEY_auth_encapsulate_init()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_encapsulate_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_encapsulate_init.3ossl deleted file mode 120000 index ca8beb26..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_encapsulate_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_encapsulate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_encrypt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_encrypt.3ossl deleted file mode 100644 index bef3bd29..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_encrypt.3ossl +++ /dev/null @@ -1,249 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_ENCRYPT 3ossl" -.TH EVP_PKEY_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_encrypt_init_ex, -EVP_PKEY_encrypt_init, EVP_PKEY_encrypt \- encrypt using a public key algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_encrypt_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_encrypt_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_PKEY_encrypt(EVP_PKEY_CTX *ctx, -\& unsigned char *out, size_t *outlen, -\& const unsigned char *in, size_t inlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEVP_PKEY_encrypt_init()\fR function initializes a public key algorithm -context using key \fBpkey\fR for an encryption operation. -.PP -The \fBEVP_PKEY_encrypt_init_ex()\fR function initializes a public key algorithm -context using key \fBpkey\fR for an encryption operation and sets the -algorithm specific \fBparams\fR. -.PP -The \fBEVP_PKEY_encrypt()\fR function performs a public key encryption operation -using \fBctx\fR. The data to be encrypted is specified using the \fBin\fR and -\&\fBinlen\fR parameters. If \fBout\fR is \fB\s-1NULL\s0\fR then the maximum size of the output -buffer is written to the \fBoutlen\fR parameter. If \fBout\fR is not \fB\s-1NULL\s0\fR then -before the call the \fBoutlen\fR parameter should contain the length of the -\&\fBout\fR buffer, if the call is successful the encrypted data is written to -\&\fBout\fR and the amount of data written to \fBoutlen\fR. -.SH "NOTES" -.IX Header "NOTES" -After the call to \fBEVP_PKEY_encrypt_init()\fR algorithm specific control -operations can be performed to set any appropriate parameters for the -operation. These operations can be included in the \fBEVP_PKEY_encrypt_init_ex()\fR -call. -.PP -The function \fBEVP_PKEY_encrypt()\fR can be called more than once on the same -context if several operations are performed using the same parameters. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_encrypt_init()\fR, \fBEVP_PKEY_encrypt_init_ex()\fR and \fBEVP_PKEY_encrypt()\fR -return 1 for success and 0 or a negative value for failure. In particular a -return value of \-2 indicates the operation is not supported by the public key -algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Encrypt data using \s-1OAEP\s0 (for \s-1RSA\s0 keys). See also \fBPEM_read_PUBKEY\fR\|(3) or -\&\fBd2i_X509\fR\|(3) for means to load a public key. You may also simply -set 'eng = \s-1NULL\s0;' to start with the default OpenSSL \s-1RSA\s0 implementation: -.PP -.Vb 3 -\& #include -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& ENGINE *eng; -\& unsigned char *out, *in; -\& size_t outlen, inlen; -\& EVP_PKEY *key; -\& -\& /* -\& * NB: assumes eng, key, in, inlen are already set up, -\& * and that key is an RSA public key -\& */ -\& ctx = EVP_PKEY_CTX_new(key, eng); -\& if (!ctx) -\& /* Error occurred */ -\& if (EVP_PKEY_encrypt_init(ctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_OAEP_PADDING) <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_encrypt(ctx, NULL, &outlen, in, inlen) <= 0) -\& /* Error */ -\& -\& out = OPENSSL_malloc(outlen); -\& -\& if (!out) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_encrypt(ctx, out, &outlen, in, inlen) <= 0) -\& /* Error */ -\& -\& /* Encrypted data is outlen bytes written to buffer out */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBENGINE_by_id\fR\|(3), -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_encrypt_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_encrypt_init.3ossl deleted file mode 120000 index 618c0afe..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_encrypt_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_encrypt_init_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_encrypt_init_ex.3ossl deleted file mode 120000 index 618c0afe..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_encrypt_init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_eq.3ossl b/openssl-install/share/man/man3/EVP_PKEY_eq.3ossl deleted file mode 120000 index 9da46e99..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_eq.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_copy_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_export.3ossl b/openssl-install/share/man/man3/EVP_PKEY_export.3ossl deleted file mode 120000 index 33ba37a6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_export.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_todata.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_free.3ossl b/openssl-install/share/man/man3/EVP_PKEY_free.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_fromdata.3ossl b/openssl-install/share/man/man3/EVP_PKEY_fromdata.3ossl deleted file mode 100644 index c5dd5695..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_fromdata.3ossl +++ /dev/null @@ -1,392 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_FROMDATA 3ossl" -.TH EVP_PKEY_FROMDATA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_fromdata_init, EVP_PKEY_fromdata, EVP_PKEY_fromdata_settable -\&\- functions to create keys and key parameters from user data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_fromdata_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_fromdata(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey, int selection, -\& OSSL_PARAM params[]); -\& const OSSL_PARAM *EVP_PKEY_fromdata_settable(EVP_PKEY_CTX *ctx, int selection); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions described here are used to create new keys from user -provided key data, such as \fIn\fR, \fIe\fR and \fId\fR for a minimal \s-1RSA\s0 -keypair. -.PP -These functions use an \fB\s-1EVP_PKEY_CTX\s0\fR context, which should primarily -be created with \fBEVP_PKEY_CTX_new_from_name\fR\|(3) or -\&\fBEVP_PKEY_CTX_new_id\fR\|(3). -.PP -The exact key data that the user can pass depends on the key type. -These are passed as an \s-1\fBOSSL_PARAM\s0\fR\|(3) array. -.PP -\&\fBEVP_PKEY_fromdata_init()\fR initializes a public key algorithm context -for creating a key or key parameters from user data. -.PP -\&\fBEVP_PKEY_fromdata()\fR creates the structure to store a key or key parameters, -given data from \fIparams\fR, \fIselection\fR and a context that's been initialized -with \fBEVP_PKEY_fromdata_init()\fR. The result is written to \fI*ppkey\fR. -\&\fIselection\fR is described in \*(L"Selections\*(R". -The parameters that can be used for various types of key are as described by the -diverse \*(L"Common parameters\*(R" sections of the -\&\fB\s-1EVP_PKEY\-RSA\s0\fR(7), -\&\fB\s-1EVP_PKEY\-DSA\s0\fR(7), -\&\fB\s-1EVP_PKEY\-DH\s0\fR(7), -\&\fB\s-1EVP_PKEY\-EC\s0\fR(7), -\&\fB\s-1EVP_PKEY\-ED448\s0\fR(7), -\&\fB\s-1EVP_PKEY\-X25519\s0\fR(7), -\&\fB\s-1EVP_PKEY\-X448\s0\fR(7), -and \fB\s-1EVP_PKEY\-ED25519\s0\fR(7) pages. -.PP -\&\fBEVP_PKEY_fromdata_settable()\fR gets a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes -the settable parameters that can be used with \fBEVP_PKEY_fromdata()\fR. -\&\fIselection\fR is described in \*(L"Selections\*(R". -.PP -Parameters in the \fIparams\fR array that are not among the settable parameters -for the given \fIselection\fR are ignored. -.SS "Selections" -.IX Subsection "Selections" -The following constants can be used for \fIselection\fR: -.IP "\fB\s-1EVP_PKEY_KEY_PARAMETERS\s0\fR" 4 -.IX Item "EVP_PKEY_KEY_PARAMETERS" -Only key parameters will be selected. -.IP "\fB\s-1EVP_PKEY_PUBLIC_KEY\s0\fR" 4 -.IX Item "EVP_PKEY_PUBLIC_KEY" -Only public key components will be selected. This includes optional key -parameters. -.IP "\fB\s-1EVP_PKEY_KEYPAIR\s0\fR" 4 -.IX Item "EVP_PKEY_KEYPAIR" -Any keypair components will be selected. This includes the private key, -public key and key parameters. -.SH "NOTES" -.IX Header "NOTES" -These functions only work with key management methods coming from a provider. -This is the mirror function to \fBEVP_PKEY_todata\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_fromdata_init()\fR and \fBEVP_PKEY_fromdata()\fR return 1 for success and 0 or -a negative value for failure. In particular a return value of \-2 indicates the -operation is not supported by the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -These examples are very terse for the sake of staying on topic, which -is the \fBEVP_PKEY_fromdata()\fR set of functions. In real applications, -BIGNUMs would be handled and converted to byte arrays with -\&\fBBN_bn2nativepad()\fR, but that's off topic here. -.SS "Creating an \s-1RSA\s0 keypair using raw key data" -.IX Subsection "Creating an RSA keypair using raw key data" -.Vb 1 -\& #include -\& -\& /* -\& * These are extremely small to make this example simple. A real -\& * and secure application will not use such small numbers. A real -\& * and secure application is expected to use BIGNUMs, and to build -\& * this array dynamically. -\& */ -\& unsigned long rsa_n = 0xbc747fc5; -\& unsigned long rsa_e = 0x10001; -\& unsigned long rsa_d = 0x7b133399; -\& OSSL_PARAM params[] = { -\& OSSL_PARAM_ulong("n", &rsa_n), -\& OSSL_PARAM_ulong("e", &rsa_e), -\& OSSL_PARAM_ulong("d", &rsa_d), -\& OSSL_PARAM_END -\& }; -\& -\& int main() -\& { -\& EVP_PKEY_CTX *ctx = EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL); -\& EVP_PKEY *pkey = NULL; -\& -\& if (ctx == NULL -\& || EVP_PKEY_fromdata_init(ctx) <= 0 -\& || EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEYPAIR, params) <= 0) -\& exit(1); -\& -\& /* Do what you want with |pkey| */ -\& } -.Ve -.SS "Creating an \s-1ECC\s0 keypair using raw key data" -.IX Subsection "Creating an ECC keypair using raw key data" -.Vb 3 -\& #include -\& #include -\& #include -\& -\& /* -\& * Fixed data to represent the private and public key. -\& */ -\& const unsigned char priv_data[] = { -\& 0xb9, 0x2f, 0x3c, 0xe6, 0x2f, 0xfb, 0x45, 0x68, -\& 0x39, 0x96, 0xf0, 0x2a, 0xaf, 0x6c, 0xda, 0xf2, -\& 0x89, 0x8a, 0x27, 0xbf, 0x39, 0x9b, 0x7e, 0x54, -\& 0x21, 0xc2, 0xa1, 0xe5, 0x36, 0x12, 0x48, 0x5d -\& }; -\& /* UNCOMPRESSED FORMAT */ -\& const unsigned char pub_data[] = { -\& POINT_CONVERSION_UNCOMPRESSED, -\& 0xcf, 0x20, 0xfb, 0x9a, 0x1d, 0x11, 0x6c, 0x5e, -\& 0x9f, 0xec, 0x38, 0x87, 0x6c, 0x1d, 0x2f, 0x58, -\& 0x47, 0xab, 0xa3, 0x9b, 0x79, 0x23, 0xe6, 0xeb, -\& 0x94, 0x6f, 0x97, 0xdb, 0xa3, 0x7d, 0xbd, 0xe5, -\& 0x26, 0xca, 0x07, 0x17, 0x8d, 0x26, 0x75, 0xff, -\& 0xcb, 0x8e, 0xb6, 0x84, 0xd0, 0x24, 0x02, 0x25, -\& 0x8f, 0xb9, 0x33, 0x6e, 0xcf, 0x12, 0x16, 0x2f, -\& 0x5c, 0xcd, 0x86, 0x71, 0xa8, 0xbf, 0x1a, 0x47 -\& }; -\& -\& int main() -\& { -\& EVP_PKEY_CTX *ctx; -\& EVP_PKEY *pkey = NULL; -\& BIGNUM *priv; -\& OSSL_PARAM_BLD *param_bld; -\& OSSL_PARAM *params = NULL; -\& int exitcode = 0; -\& -\& priv = BN_bin2bn(priv_data, sizeof(priv_data), NULL); -\& -\& param_bld = OSSL_PARAM_BLD_new(); -\& if (priv != NULL && param_bld != NULL -\& && OSSL_PARAM_BLD_push_utf8_string(param_bld, "group", -\& "prime256v1", 0) -\& && OSSL_PARAM_BLD_push_BN(param_bld, "priv", priv) -\& && OSSL_PARAM_BLD_push_octet_string(param_bld, "pub", -\& pub_data, sizeof(pub_data))) -\& params = OSSL_PARAM_BLD_to_param(param_bld); -\& -\& ctx = EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL); -\& if (ctx == NULL -\& || params == NULL -\& || EVP_PKEY_fromdata_init(ctx) <= 0 -\& || EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEYPAIR, params) <= 0) { -\& exitcode = 1; -\& } else { -\& /* Do what you want with |pkey| */ -\& } -\& -\& EVP_PKEY_free(pkey); -\& EVP_PKEY_CTX_free(ctx); -\& OSSL_PARAM_free(params); -\& OSSL_PARAM_BLD_free(param_bld); -\& BN_free(priv); -\& -\& exit(exitcode); -\& } -.Ve -.SS "Finding out params for an unknown key type" -.IX Subsection "Finding out params for an unknown key type" -.Vb 2 -\& #include -\& #include -\& -\& /* Program expects a key type as first argument */ -\& int main(int argc, char *argv[]) -\& { -\& EVP_PKEY_CTX *ctx = EVP_PKEY_CTX_new_from_name(NULL, argv[1], NULL); -\& const OSSL_PARAM *settable_params = NULL; -\& -\& if (ctx == NULL) -\& exit(1); -\& settable_params = EVP_PKEY_fromdata_settable(ctx, EVP_PKEY_KEYPAIR); -\& if (settable_params == NULL) -\& exit(1); -\& -\& for (; settable_params\->key != NULL; settable_params++) { -\& const char *datatype = NULL; -\& -\& switch (settable_params\->data_type) { -\& case OSSL_PARAM_INTEGER: -\& datatype = "integer"; -\& break; -\& case OSSL_PARAM_UNSIGNED_INTEGER: -\& datatype = "unsigned integer"; -\& break; -\& case OSSL_PARAM_UTF8_STRING: -\& datatype = "printable string (utf\-8 encoding expected)"; -\& break; -\& case OSSL_PARAM_UTF8_PTR: -\& datatype = "printable string pointer (utf\-8 encoding expected)"; -\& break; -\& case OSSL_PARAM_OCTET_STRING: -\& datatype = "octet string"; -\& break; -\& case OSSL_PARAM_OCTET_PTR: -\& datatype = "octet string pointer"; -\& break; -\& } -\& printf("%s : %s ", settable_params\->key, datatype); -\& if (settable_params\->data_size == 0) -\& printf("(unlimited size)\en"); -\& else -\& printf("(maximum size %zu)\en", settable_params\->data_size); -\& } -\& } -.Ve -.PP -The descriptor \s-1\fBOSSL_PARAM\s0\fR\|(3) returned by -\&\fBEVP_PKEY_fromdata_settable()\fR may also be used programmatically, for -example with \fBOSSL_PARAM_allocate_from_text\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), \fBprovider\fR\|(7), \fBEVP_PKEY_gettable_params\fR\|(3), -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), \fBEVP_PKEY_todata\fR\|(3), -\&\s-1\fBEVP_PKEY\-RSA\s0\fR\|(7), \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), \s-1\fBEVP_PKEY\-DH\s0\fR\|(7), \s-1\fBEVP_PKEY\-EC\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-ED448\s0\fR\|(7), \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7), \s-1\fBEVP_PKEY\-X448\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-ED25519\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_fromdata_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_fromdata_init.3ossl deleted file mode 120000 index 540d68f1..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_fromdata_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_fromdata.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_fromdata_settable.3ossl b/openssl-install/share/man/man3/EVP_PKEY_fromdata_settable.3ossl deleted file mode 120000 index 540d68f1..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_fromdata_settable.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_fromdata.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_gen_cb.3ossl b/openssl-install/share/man/man3/EVP_PKEY_gen_cb.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_gen_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_generate.3ossl b/openssl-install/share/man/man3/EVP_PKEY_generate.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_generate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_DH.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_DH.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_DSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_DSA.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_EC_KEY.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_EC_KEY.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_EC_KEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_RSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_RSA.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_asn1.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_asn1.3ossl deleted file mode 120000 index f72ab9ad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_asn1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_ASN1_METHOD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_description.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_description.3ossl deleted file mode 120000 index 21a9674e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_is_a.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_engine.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_engine.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_hmac.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_hmac.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_hmac.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_poly1305.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_poly1305.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_poly1305.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_provider.3ossl deleted file mode 120000 index 21a9674e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_is_a.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_siphash.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_siphash.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_siphash.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get0_type_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get0_type_name.3ossl deleted file mode 120000 index 21a9674e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get0_type_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_is_a.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get1_DH.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get1_DH.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get1_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get1_DSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get1_DSA.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get1_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get1_EC_KEY.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get1_EC_KEY.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get1_EC_KEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get1_RSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get1_RSA.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get1_RSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get1_encoded_public_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get1_encoded_public_key.3ossl deleted file mode 120000 index ac899e51..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get1_encoded_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_encoded_public_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get1_tls_encodedpoint.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get1_tls_encodedpoint.3ossl deleted file mode 120000 index ac899e51..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get1_tls_encodedpoint.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_encoded_public_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_attr.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_attr.3ossl deleted file mode 100644 index d258e53e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_attr.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_GET_ATTR 3ossl" -.TH EVP_PKEY_GET_ATTR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_get_attr, -EVP_PKEY_get_attr_count, -EVP_PKEY_get_attr_by_NID, EVP_PKEY_get_attr_by_OBJ, -EVP_PKEY_delete_attr, -EVP_PKEY_add1_attr, -EVP_PKEY_add1_attr_by_OBJ, EVP_PKEY_add1_attr_by_NID, EVP_PKEY_add1_attr_by_txt -\&\- EVP_PKEY X509_ATTRIBUTE functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_get_attr_count(const EVP_PKEY *key); -\& int EVP_PKEY_get_attr_by_NID(const EVP_PKEY *key, int nid, int lastpos); -\& int EVP_PKEY_get_attr_by_OBJ(const EVP_PKEY *key, const ASN1_OBJECT *obj, -\& int lastpos); -\& X509_ATTRIBUTE *EVP_PKEY_get_attr(const EVP_PKEY *key, int loc); -\& X509_ATTRIBUTE *EVP_PKEY_delete_attr(EVP_PKEY *key, int loc); -\& int EVP_PKEY_add1_attr(EVP_PKEY *key, X509_ATTRIBUTE *attr); -\& int EVP_PKEY_add1_attr_by_OBJ(EVP_PKEY *key, -\& const ASN1_OBJECT *obj, int type, -\& const unsigned char *bytes, int len); -\& int EVP_PKEY_add1_attr_by_NID(EVP_PKEY *key, -\& int nid, int type, -\& const unsigned char *bytes, int len); -\& int EVP_PKEY_add1_attr_by_txt(EVP_PKEY *key, -\& const char *attrname, int type, -\& const unsigned char *bytes, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are used by \fB\s-1PKCS12\s0\fR. -.PP -\&\fBEVP_PKEY_get_attr_by_OBJ()\fR finds the location of the first matching object \fIobj\fR -in the \fIkey\fR attribute list. The search starts at the position after \fIlastpos\fR. -If the returned value is positive then it can be used on the next call to -\&\fBEVP_PKEY_get_attr_by_OBJ()\fR as the value of \fIlastpos\fR in order to iterate through -the remaining attributes. \fIlastpos\fR can be set to any negative value on the -first call, in order to start searching from the start of the attribute list. -.PP -\&\fBEVP_PKEY_get_attr_by_NID()\fR is similar to \fBEVP_PKEY_get_attr_by_OBJ()\fR except that -it passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBEVP_PKEY_get_attr()\fR returns the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in the -\&\fIkey\fR attribute list. \fIloc\fR should be in the range from 0 to -\&\fBEVP_PKEY_get_attr_count()\fR \- 1. -.PP -\&\fBEVP_PKEY_delete_attr()\fR removes the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in -the \fIkey\fR attribute list. -.PP -\&\fBEVP_PKEY_add1_attr()\fR pushes a copy of the passed in \fBX509_ATTRIBUTE\fR object -to the \fIkey\fR attribute list. A new \fIkey\fR attribute list is created if required. -An error occurs if either \fIattr\fR is \s-1NULL,\s0 or the attribute already exists. -.PP -\&\fBEVP_PKEY_add1_attr_by_OBJ()\fR creates a new \fBX509_ATTRIBUTE\fR using -\&\fBX509_ATTRIBUTE_set1_object()\fR and \fBX509_ATTRIBUTE_set1_data()\fR to assign a new -\&\fIobj\fR with type \fItype\fR and data \fIbytes\fR of length \fIlen\fR and then pushes it -to the \fIkey\fR object's attribute list. If \fIobj\fR already exists in the attribute -list then an error occurs. -.PP -\&\fBEVP_PKEY_add1_attr_by_NID()\fR is similar to \fBEVP_PKEY_add1_attr_by_OBJ()\fR except -that it passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBEVP_PKEY_add1_attr_by_txt()\fR is similar to \fBEVP_PKEY_add1_attr_by_OBJ()\fR except -that it passes a name \fIattrname\fR associated with the object. -See for a list of SN_* names. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_get_attr_count()\fR returns the number of attributes in the \fIkey\fR object -attribute list or \-1 if the attribute list is \s-1NULL.\s0 -.PP -\&\fBEVP_PKEY_get_attr_by_OBJ()\fR returns \-1 if either the list is empty \s-1OR\s0 the object -is not found, otherwise it returns the location of the object in the list. -.PP -\&\fBEVP_PKEY_get_attr_by_NID()\fR is similar to \fBEVP_PKEY_get_attr_by_OBJ()\fR, except that -it returns \-2 if the \fInid\fR is not known by OpenSSL. -.PP -\&\fBEVP_PKEY_get_attr()\fR returns either a \fBX509_ATTRIBUTE\fR or \s-1NULL\s0 if there is a -error. -.PP -\&\fBEVP_PKEY_delete_attr()\fR returns either the removed \fBX509_ATTRIBUTE\fR or \s-1NULL\s0 if -there is a error. -.PP -\&\fBEVP_PKEY_add1_attr()\fR, \fBEVP_PKEY_add1_attr_by_OBJ()\fR, \fBEVP_PKEY_add1_attr_by_NID()\fR -and \fBEVP_PKEY_add1_attr_by_txt()\fR return 1 on success or 0 otherwise. -.SH "NOTES" -.IX Header "NOTES" -A \fB\s-1EVP_PKEY\s0\fR object's attribute list is initially \s-1NULL.\s0 All the above functions -listed will return an error unless \fBEVP_PKEY_add1_attr()\fR is called. -All functions listed assume that the \fIkey\fR is not \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_ATTRIBUTE\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_attr_by_NID.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_attr_by_NID.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_attr_by_OBJ.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_attr_count.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_attr_count.3ossl deleted file mode 120000 index 329872e2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_attr_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_base_id.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_base_id.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_base_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_bits.3ossl deleted file mode 120000 index 16e1e92b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_bn_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_bn_param.3ossl deleted file mode 120000 index 06acdfaf..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_bn_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_gettable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_default_digest_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_default_digest_name.3ossl deleted file mode 120000 index 54ab021d..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_default_digest_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_default_digest_nid.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_default_digest_nid.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_default_digest_nid.3ossl deleted file mode 100644 index db4be539..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_default_digest_nid.3ossl +++ /dev/null @@ -1,197 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_GET_DEFAULT_DIGEST_NID 3ossl" -.TH EVP_PKEY_GET_DEFAULT_DIGEST_NID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_get_default_digest_nid, EVP_PKEY_get_default_digest_name -\&\- get default signature digest -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_get_default_digest_name(EVP_PKEY *pkey, -\& char *mdname, size_t mdname_sz); -\& int EVP_PKEY_get_default_digest_nid(EVP_PKEY *pkey, int *pnid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_get_default_digest_name()\fR fills in the default message digest -name for the public key signature operations associated with key -\&\fIpkey\fR into \fImdname\fR, up to at most \fImdname_sz\fR bytes including the -ending \s-1NUL\s0 byte. The name could be \f(CW"UNDEF"\fR, signifying that a digest -must (for return value 2) or may (for return value 1) be left unspecified. -.PP -\&\fBEVP_PKEY_get_default_digest_nid()\fR sets \fIpnid\fR to the default message -digest \s-1NID\s0 for the public key signature operations associated with key -\&\fIpkey\fR. Note that some signature algorithms (i.e. Ed25519 and Ed448) -do not use a digest during signing. In this case \fIpnid\fR will be set -to NID_undef. This function is only reliable for legacy keys, which -are keys with a \fB\s-1EVP_PKEY_ASN1_METHOD\s0\fR; these keys have typically -been loaded from engines, or created with \fBEVP_PKEY_assign_RSA\fR\|(3) or -similar. -.SH "NOTES" -.IX Header "NOTES" -For all current standard OpenSSL public key algorithms \s-1SHA256\s0 is returned. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_get_default_digest_name()\fR and \fBEVP_PKEY_get_default_digest_nid()\fR -both return 1 if the message digest is advisory (that is other digests -can be used) and 2 if it is mandatory (other digests can not be used). -They return 0 or a negative value for failure. In particular a return -value of \-2 indicates the operation is not supported by the public key -algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_digestsign_supports_digest\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -This function was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_ec_point_conv_form.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_ec_point_conv_form.3ossl deleted file mode 120000 index 490c88ac..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_ec_point_conv_form.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_field_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_ex_data.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_ex_new_index.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_field_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_field_type.3ossl deleted file mode 100644 index dd8ed69c..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_field_type.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_GET_FIELD_TYPE 3ossl" -.TH EVP_PKEY_GET_FIELD_TYPE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_get_field_type, EVP_PKEY_get_ec_point_conv_form \- get field type -or point conversion form of a key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_get_field_type(const EVP_PKEY *pkey); -\& int EVP_PKEY_get_ec_point_conv_form(const EVP_PKEY *pkey); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_get_field_type()\fR returns the field type \s-1NID\s0 of the \fIpkey\fR, if -\&\fIpkey\fR's key type supports it. The types currently supported -by the built-in OpenSSL providers are either \fBNID_X9_62_prime_field\fR -for prime curves or \fBNID_X9_62_characteristic_two_field\fR for binary curves; -these values are defined in the \fI\fR header file. -.PP -\&\fBEVP_PKEY_get_ec_point_conv_form()\fR returns the point conversion format -of the \fIpkey\fR, if \fIpkey\fR's key type supports it. -.SH "NOTES" -.IX Header "NOTES" -Among the standard OpenSSL key types, this is only supported for \s-1EC\s0 and -\&\s-1SM2\s0 keys. Other providers may support this for additional key types. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_get_field_type()\fR returns the field type \s-1NID\s0 or 0 on error. -.PP -\&\fBEVP_PKEY_get_ec_point_conv_form()\fR returns the point conversion format number -(see \fBEC_GROUP_copy\fR\|(3)) or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEC_GROUP_copy\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_group_name.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_group_name.3ossl deleted file mode 100644 index 4d463a76..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_group_name.3ossl +++ /dev/null @@ -1,177 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_GET_GROUP_NAME 3ossl" -.TH EVP_PKEY_GET_GROUP_NAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_get_group_name \- get group name of a key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_get_group_name(EVP_PKEY *pkey, char *gname, size_t gname_sz, -\& size_t *gname_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_get_group_name()\fR fills in the group name of the \fIpkey\fR into -\&\fIgname\fR, up to at most \fIgname_sz\fR bytes including the ending \s-1NUL\s0 byte -and assigns \fI*gname_len\fR the actual length of the name not including -the \s-1NUL\s0 byte, if \fIpkey\fR's key type supports it. -\&\fIgname\fR as well as \fIgname_len\fR may individually be \s-1NULL,\s0 and won't be -filled in or assigned in that case. -.SH "NOTES" -.IX Header "NOTES" -Among the standard OpenSSL key types, this is only supported for \s-1DH, EC\s0 and -\&\s-1SM2\s0 keys. Other providers may support this for additional key types. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_get_group_name()\fR returns 1 if the group name could be filled in, -otherwise 0. -.SH "HISTORY" -.IX Header "HISTORY" -This function was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_id.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_id.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_int_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_int_param.3ossl deleted file mode 120000 index 06acdfaf..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_int_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_gettable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_octet_string_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_octet_string_param.3ossl deleted file mode 120000 index 06acdfaf..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_octet_string_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_gettable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_params.3ossl deleted file mode 120000 index 06acdfaf..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_gettable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_raw_private_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_raw_private_key.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_raw_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_raw_public_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_raw_public_key.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_raw_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_security_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_security_bits.3ossl deleted file mode 120000 index 16e1e92b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_security_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_size.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_size.3ossl deleted file mode 100644 index 2cef37e5..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_size.3ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_GET_SIZE 3ossl" -.TH EVP_PKEY_GET_SIZE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_get_size, EVP_PKEY_get_bits, EVP_PKEY_get_security_bits, -EVP_PKEY_bits, EVP_PKEY_security_bits, EVP_PKEY_size -\&\- EVP_PKEY information functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_get_size(const EVP_PKEY *pkey); -\& int EVP_PKEY_get_bits(const EVP_PKEY *pkey); -\& int EVP_PKEY_get_security_bits(const EVP_PKEY *pkey); -\& -\& #define EVP_PKEY_bits EVP_PKEY_get_bits -\& #define EVP_PKEY_security_bits EVP_PKEY_get_security_bits -\& #define EVP_PKEY_size EVP_PKEY_get_size -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_get_size()\fR returns the maximum suitable size for the output -buffers for almost all operations that can be done with \fIpkey\fR. -This corresponds to the provider parameter \fB\s-1OSSL_PKEY_PARAM_MAX_SIZE\s0\fR. -The primary documented use is with \fBEVP_SignFinal\fR\|(3) and -\&\fBEVP_SealInit\fR\|(3), but it isn't limited there. The returned size is -also large enough for the output buffer of \fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), \fBEVP_PKEY_decrypt\fR\|(3), \fBEVP_PKEY_derive\fR\|(3). -.PP -It must be stressed that, unless the documentation for the operation -that's being performed says otherwise, the size returned by -\&\fBEVP_PKEY_get_size()\fR is only preliminary and not exact, so the final -contents of the target buffer may be smaller. It is therefore crucial -to take note of the size given back by the function that performs the -operation, such as \fBEVP_PKEY_sign\fR\|(3) (the \fIsiglen\fR argument will -receive that length), to avoid bugs. -.PP -\&\fBEVP_PKEY_get_bits()\fR returns the cryptographic length of the cryptosystem -to which the key in \fIpkey\fR belongs, in bits. Note that the definition -of cryptographic length is specific to the key cryptosystem. -This length corresponds to the provider parameter \fB\s-1OSSL_PKEY_PARAM_BITS\s0\fR. -.PP -\&\fBEVP_PKEY_get_security_bits()\fR returns the number of security bits of the given -\&\fIpkey\fR, bits of security is defined in \s-1NIST SP800\-57.\s0 -This corresponds to the provider parameter \fB\s-1OSSL_PKEY_PARAM_SECURITY_BITS\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_get_size()\fR, \fBEVP_PKEY_get_bits()\fR and \fBEVP_PKEY_get_security_bits()\fR -return a positive number, or 0 if this size isn't available. -.SH "NOTES" -.IX Header "NOTES" -Most functions that have an output buffer and are mentioned with -\&\fBEVP_PKEY_get_size()\fR have a functionality where you can pass \s-1NULL\s0 for the -buffer and still pass a pointer to an integer and get the exact size -that this function call delivers in the context that it's called in. -This allows those functions to be called twice, once to find out the -exact buffer size, then allocate the buffer in between, and call that -function again actually output the data. For those functions, it -isn't strictly necessary to call \fBEVP_PKEY_get_size()\fR to find out the -buffer size, but may be useful in cases where it's desirable to know -the upper limit in advance. -.PP -It should also be especially noted that \fBEVP_PKEY_get_size()\fR shouldn't be -used to get the output size for \fBEVP_DigestSignFinal()\fR, according to -\&\*(L"\s-1NOTES\*(R"\s0 in \fBEVP_DigestSignFinal\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-keymgmt\fR\|(7), -\&\fBEVP_SignFinal\fR\|(3), -\&\fBEVP_SealInit\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_bits()\fR, \fBEVP_PKEY_security_bits()\fR, and \fBEVP_PKEY_size()\fR functions -were renamed to include \f(CW\*(C`get\*(C'\fR in their names in OpenSSL 3.0, respectively. -The old names are kept as non-deprecated alias macros. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_size_t_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_size_t_param.3ossl deleted file mode 120000 index 06acdfaf..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_size_t_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_gettable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_get_utf8_string_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_get_utf8_string_param.3ossl deleted file mode 120000 index 06acdfaf..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_get_utf8_string_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_gettable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_gettable_params.3ossl deleted file mode 100644 index f69733ce..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_gettable_params.3ossl +++ /dev/null @@ -1,266 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_GETTABLE_PARAMS 3ossl" -.TH EVP_PKEY_GETTABLE_PARAMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_gettable_params, EVP_PKEY_get_params, -EVP_PKEY_get_int_param, EVP_PKEY_get_size_t_param, -EVP_PKEY_get_bn_param, EVP_PKEY_get_utf8_string_param, -EVP_PKEY_get_octet_string_param -\&\- retrieve key parameters from a key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const OSSL_PARAM *EVP_PKEY_gettable_params(EVP_PKEY *pkey); -\& int EVP_PKEY_get_params(const EVP_PKEY *pkey, OSSL_PARAM params[]); -\& int EVP_PKEY_get_int_param(const EVP_PKEY *pkey, const char *key_name, -\& int *out); -\& int EVP_PKEY_get_size_t_param(const EVP_PKEY *pkey, const char *key_name, -\& size_t *out); -\& int EVP_PKEY_get_bn_param(const EVP_PKEY *pkey, const char *key_name, -\& BIGNUM **bn); -\& int EVP_PKEY_get_utf8_string_param(const EVP_PKEY *pkey, const char *key_name, -\& char *str, size_t max_buf_sz, -\& size_t *out_len); -\& int EVP_PKEY_get_octet_string_param(const EVP_PKEY *pkey, const char *key_name, -\& unsigned char *buf, size_t max_buf_sz, -\& size_t *out_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for information about parameters. -.PP -\&\fBEVP_PKEY_get_params()\fR retrieves parameters from the key \fIpkey\fR, according to -the contents of \fIparams\fR. -.PP -\&\fBEVP_PKEY_gettable_params()\fR returns a constant list of \fIparams\fR indicating -the names and types of key parameters that can be retrieved. -.PP -An \s-1\fBOSSL_PARAM\s0\fR\|(3) of type \fB\s-1OSSL_PARAM_INTEGER\s0\fR or -\&\fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR is of arbitrary length. Such a parameter can be -obtained using any of the functions \fBEVP_PKEY_get_int_param()\fR, -\&\fBEVP_PKEY_get_size_t_param()\fR or \fBEVP_PKEY_get_bn_param()\fR. Attempting to -obtain an integer value that does not fit into a native C \fBint\fR type will cause -\&\fBEVP_PKEY_get_int_param()\fR to fail. Similarly attempting to obtain an integer -value that is negative or does not fit into a native C \fBsize_t\fR type using -\&\fBEVP_PKEY_get_size_t_param()\fR will also fail. -.PP -\&\fBEVP_PKEY_get_int_param()\fR retrieves a key \fIpkey\fR integer value \fI*out\fR -associated with a name of \fIkey_name\fR if it fits into \f(CW\*(C`int\*(C'\fR type. For -parameters that do not fit into \f(CW\*(C`int\*(C'\fR use \fBEVP_PKEY_get_bn_param()\fR. -.PP -\&\fBEVP_PKEY_get_size_t_param()\fR retrieves a key \fIpkey\fR size_t value \fI*out\fR -associated with a name of \fIkey_name\fR if it fits into \f(CW\*(C`size_t\*(C'\fR type. For -parameters that do not fit into \f(CW\*(C`size_t\*(C'\fR use \fBEVP_PKEY_get_bn_param()\fR. -.PP -\&\fBEVP_PKEY_get_bn_param()\fR retrieves a key \fIpkey\fR \s-1BIGNUM\s0 value \fI**bn\fR -associated with a name of \fIkey_name\fR. If \fI*bn\fR is \s-1NULL\s0 then the \s-1BIGNUM\s0 -is allocated by the method. -.PP -\&\fBEVP_PKEY_get_utf8_string_param()\fR get a key \fIpkey\fR \s-1UTF8\s0 string value into a -buffer \fIstr\fR of maximum size \fImax_buf_sz\fR associated with a name of -\&\fIkey_name\fR. The maximum size must be large enough to accommodate the string -value including a terminating \s-1NUL\s0 byte, or this function will fail. -If \fIout_len\fR is not \s-1NULL,\s0 \fI*out_len\fR is set to the length of the string -not including the terminating \s-1NUL\s0 byte. The required buffer size not including -the terminating \s-1NUL\s0 byte can be obtained from \fI*out_len\fR by calling the -function with \fIstr\fR set to \s-1NULL.\s0 -.PP -\&\fBEVP_PKEY_get_octet_string_param()\fR get a key \fIpkey\fR's octet string value into a -buffer \fIbuf\fR of maximum size \fImax_buf_sz\fR associated with a name of \fIkey_name\fR. -If \fIout_len\fR is not \s-1NULL,\s0 \fI*out_len\fR is set to the length of the contents. -The required buffer size can be obtained from \fI*out_len\fR by calling the -function with \fIbuf\fR set to \s-1NULL.\s0 -.SH "NOTES" -.IX Header "NOTES" -These functions only work for \fB\s-1EVP_PKEY\s0\fRs that contain a provider side key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_gettable_params()\fR returns \s-1NULL\s0 on error or if it is not supported. -.PP -All other methods return 1 if a value associated with the key's \fIkey_name\fR was -successfully returned, or 0 if there was an error. -An error may be returned by methods \fBEVP_PKEY_get_utf8_string_param()\fR and -\&\fBEVP_PKEY_get_octet_string_param()\fR if \fImax_buf_sz\fR is not big enough to hold the -value. If \fIout_len\fR is not \s-1NULL,\s0 \fI*out_len\fR will be assigned the required -buffer size to hold the value. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 1 -\& #include -\& -\& char curve_name[64]; -\& unsigned char pub[256]; -\& BIGNUM *bn_priv = NULL; -\& -\& /* -\& * NB: assumes \*(Aqkey\*(Aq is set up before the next step. In this example the key -\& * is an EC key. -\& */ -\& -\& if (!EVP_PKEY_get_utf8_string_param(key, OSSL_PKEY_PARAM_GROUP_NAME, -\& curve_name, sizeof(curve_name), &len)) { -\& /* Error */ -\& } -\& if (!EVP_PKEY_get_octet_string_param(key, OSSL_PKEY_PARAM_PUB_KEY, -\& pub, sizeof(pub), &len)) { -\& /* Error */ -\& } -\& if (!EVP_PKEY_get_bn_param(key, OSSL_PKEY_PARAM_PRIV_KEY, &bn_priv)) { -\& /* Error */ -\& } -\& -\& BN_clear_free(bn_priv); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), \fBprovider\-keymgmt\fR\|(7), \s-1\fBOSSL_PARAM\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_id.3ossl b/openssl-install/share/man/man3/EVP_PKEY_id.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_is_a.3ossl b/openssl-install/share/man/man3/EVP_PKEY_is_a.3ossl deleted file mode 100644 index 185047a2..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_is_a.3ossl +++ /dev/null @@ -1,247 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_IS_A 3ossl" -.TH EVP_PKEY_IS_A 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_is_a, EVP_PKEY_can_sign, EVP_PKEY_type_names_do_all, -EVP_PKEY_get0_type_name, EVP_PKEY_get0_description, EVP_PKEY_get0_provider -\&\- key type and capabilities functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_is_a(const EVP_PKEY *pkey, const char *name); -\& int EVP_PKEY_can_sign(const EVP_PKEY *pkey); -\& int EVP_PKEY_type_names_do_all(const EVP_PKEY *pkey, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const char *EVP_PKEY_get0_type_name(const EVP_PKEY *key); -\& const char *EVP_PKEY_get0_description(const EVP_PKEY *key); -\& const OSSL_PROVIDER *EVP_PKEY_get0_provider(const EVP_PKEY *key); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_is_a()\fR checks if the key type of \fIpkey\fR is \fIname\fR. -.PP -\&\fBEVP_PKEY_can_sign()\fR checks if the functionality for the key type of -\&\fIpkey\fR supports signing. No other check is done, such as whether -\&\fIpkey\fR contains a private key. -.PP -\&\fBEVP_PKEY_type_names_do_all()\fR traverses all names for \fIpkey\fR's key type, and -calls \fIfn\fR with each name and \fIdata\fR. For example, an \s-1RSA\s0 \fB\s-1EVP_PKEY\s0\fR may -be named both \f(CW\*(C`RSA\*(C'\fR and \f(CW\*(C`rsaEncryption\*(C'\fR. -The order of the names depends on the provider implementation that holds -the key. -.PP -\&\fBEVP_PKEY_get0_type_name()\fR returns the first key type name that is found -for the given \fIpkey\fR. Note that the \fIpkey\fR may have multiple synonyms -associated with it. In this case it depends on the provider implementation -that holds the key which one will be returned. -Ownership of the returned string is retained by the \fIpkey\fR object and should -not be freed by the caller. -.PP -\&\fBEVP_PKEY_get0_description()\fR returns a description of the type of \fB\s-1EVP_PKEY\s0\fR, -meant for display and human consumption. The description is at the -discretion of the key type implementation. -.PP -\&\fBEVP_PKEY_get0_provider()\fR returns the provider of the \fB\s-1EVP_PKEY\s0\fR's -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_is_a()\fR returns 1 if \fIpkey\fR has the key type \fIname\fR, -otherwise 0. -.PP -\&\fBEVP_PKEY_can_sign()\fR returns 1 if the \fIpkey\fR key type functionality -supports signing, otherwise 0. -.PP -\&\fBEVP_PKEY_get0_type_name()\fR returns the name that is found or \s-1NULL\s0 on error. -.PP -\&\fBEVP_PKEY_get0_description()\fR returns the description if found or \s-1NULL\s0 if not. -.PP -\&\fBEVP_PKEY_get0_provider()\fR returns the provider if found or \s-1NULL\s0 if not. -.PP -\&\fBEVP_PKEY_type_names_do_all()\fR returns 1 if the callback was called for all -names. A return value of 0 means that the callback was not called for any -names. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.SS "\fBEVP_PKEY_is_a()\fP" -.IX Subsection "EVP_PKEY_is_a()" -The loaded providers and what key types they support will ultimately -determine what \fIname\fR is possible to use with \fBEVP_PKEY_is_a()\fR. We do know -that the default provider supports \s-1RSA, DH, DSA\s0 and \s-1EC\s0 keys, so we can use -this as an crude example: -.PP -.Vb 1 -\& #include -\& -\& ... -\& /* |pkey| is an EVP_PKEY* */ -\& if (EVP_PKEY_is_a(pkey, "RSA")) { -\& BIGNUM *modulus = NULL; -\& if (EVP_PKEY_get_bn_param(pkey, "n", &modulus)) -\& /* do whatever with the modulus */ -\& BN_free(modulus); -\& } -.Ve -.SS "\fBEVP_PKEY_can_sign()\fP" -.IX Subsection "EVP_PKEY_can_sign()" -.Vb 1 -\& #include -\& -\& ... -\& /* |pkey| is an EVP_PKEY* */ -\& if (!EVP_PKEY_can_sign(pkey)) { -\& fprintf(stderr, "Not a signing key!"); -\& exit(1); -\& } -\& /* Sign something... */ -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_keygen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_keygen.3ossl deleted file mode 100644 index ea40131c..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_keygen.3ossl +++ /dev/null @@ -1,371 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_KEYGEN 3ossl" -.TH EVP_PKEY_KEYGEN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_Q_keygen, -EVP_PKEY_keygen_init, EVP_PKEY_paramgen_init, EVP_PKEY_generate, -EVP_PKEY_CTX_set_cb, EVP_PKEY_CTX_get_cb, -EVP_PKEY_CTX_get_keygen_info, EVP_PKEY_CTX_set_app_data, -EVP_PKEY_CTX_get_app_data, -EVP_PKEY_gen_cb, -EVP_PKEY_paramgen, EVP_PKEY_keygen -\&\- key and parameter generation and check functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *EVP_PKEY_Q_keygen(OSSL_LIB_CTX *libctx, const char *propq, -\& const char *type, ...); -\& -\& int EVP_PKEY_keygen_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_paramgen_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_generate(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey); -\& int EVP_PKEY_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey); -\& int EVP_PKEY_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey); -\& -\& typedef int EVP_PKEY_gen_cb(EVP_PKEY_CTX *ctx); -\& -\& void EVP_PKEY_CTX_set_cb(EVP_PKEY_CTX *ctx, EVP_PKEY_gen_cb *cb); -\& EVP_PKEY_gen_cb *EVP_PKEY_CTX_get_cb(EVP_PKEY_CTX *ctx); -\& -\& int EVP_PKEY_CTX_get_keygen_info(EVP_PKEY_CTX *ctx, int idx); -\& -\& void EVP_PKEY_CTX_set_app_data(EVP_PKEY_CTX *ctx, void *data); -\& void *EVP_PKEY_CTX_get_app_data(EVP_PKEY_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Generating keys is sometimes straight forward, just generate the key's -numbers and be done with it. However, there are certain key types that need -key parameters, often called domain parameters but not necessarily limited -to that, that also need to be generated. In addition to this, the caller -may want to set user provided generation parameters that further affect key -parameter or key generation, such as the desired key size. -.PP -To flexibly allow all that's just been described, key parameter and key -generation is divided into an initialization of a key algorithm context, -functions to set user provided parameters, and finally the key parameter or -key generation function itself. -.PP -The key algorithm context must be created using \fBEVP_PKEY_CTX_new\fR\|(3) or -variants thereof, see that manual for details. -.PP -\&\fBEVP_PKEY_keygen_init()\fR initializes a public key algorithm context \fIctx\fR -for a key generation operation. -.PP -\&\fBEVP_PKEY_paramgen_init()\fR is similar to \fBEVP_PKEY_keygen_init()\fR except key -parameters are generated. -.PP -After initialization, generation parameters may be provided with -\&\fBEVP_PKEY_CTX_ctrl\fR\|(3) or \fBEVP_PKEY_CTX_set_params\fR\|(3), or any other -function described in those manuals. -.PP -\&\fBEVP_PKEY_generate()\fR performs the generation operation, the resulting key -parameters or key are written to \fI*ppkey\fR. If \fI*ppkey\fR is \s-1NULL\s0 when this -function is called, it will be allocated, and should be freed by the caller -when no longer useful, using \fBEVP_PKEY_free\fR\|(3). -.PP -\&\fBEVP_PKEY_paramgen()\fR and \fBEVP_PKEY_keygen()\fR do exactly the same thing as -\&\fBEVP_PKEY_generate()\fR, after checking that the corresponding \fBEVP_PKEY_paramgen_init()\fR -or \fBEVP_PKEY_keygen_init()\fR was used to initialize \fIctx\fR. -These are older functions that are kept for backward compatibility. -It is safe to use \fBEVP_PKEY_generate()\fR instead. -.PP -The function \fBEVP_PKEY_set_cb()\fR sets the key or parameter generation callback -to \fIcb\fR. The function \fBEVP_PKEY_CTX_get_cb()\fR returns the key or parameter -generation callback. -.PP -The function \fBEVP_PKEY_CTX_get_keygen_info()\fR returns parameters associated -with the generation operation. If \fIidx\fR is \-1 the total number of -parameters available is returned. Any non negative value returns the value of -that parameter. \fBEVP_PKEY_CTX_gen_keygen_info()\fR with a nonnegative value for -\&\fIidx\fR should only be called within the generation callback. -.PP -If the callback returns 0 then the key generation operation is aborted and an -error occurs. This might occur during a time consuming operation where -a user clicks on a \*(L"cancel\*(R" button. -.PP -The functions \fBEVP_PKEY_CTX_set_app_data()\fR and \fBEVP_PKEY_CTX_get_app_data()\fR set -and retrieve an opaque pointer. This can be used to set some application -defined value which can be retrieved in the callback: for example a handle -which is used to update a \*(L"progress dialog\*(R". -.PP -\&\fBEVP_PKEY_Q_keygen()\fR abstracts from the explicit use of \fB\s-1EVP_PKEY_CTX\s0\fR while -providing a 'quick' but limited way of generating a new asymmetric key pair. -It provides shorthands for simple and common cases of key generation. -As usual, the library context \fIlibctx\fR and property query \fIpropq\fR -can be given for fetching algorithms from providers. -If \fItype\fR is \f(CW\*(C`RSA\*(C'\fR, -a \fBsize_t\fR parameter must be given to specify the size of the \s-1RSA\s0 key. -If \fItype\fR is \f(CW\*(C`EC\*(C'\fR, -a string parameter must be given to specify the name of the \s-1EC\s0 curve. -If \fItype\fR is \f(CW\*(C`X25519\*(C'\fR, \f(CW\*(C`X448\*(C'\fR, \f(CW\*(C`ED25519\*(C'\fR, \f(CW\*(C`ED448\*(C'\fR, or \f(CW\*(C`SM2\*(C'\fR -no further parameter is needed. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_keygen_init()\fR, \fBEVP_PKEY_paramgen_init()\fR, \fBEVP_PKEY_keygen()\fR and -\&\fBEVP_PKEY_paramgen()\fR return 1 for success and 0 or a negative value for failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.PP -\&\fBEVP_PKEY_Q_keygen()\fR returns an \fB\s-1EVP_PKEY\s0\fR, or \s-1NULL\s0 on failure. -.SH "NOTES" -.IX Header "NOTES" -After the call to \fBEVP_PKEY_keygen_init()\fR or \fBEVP_PKEY_paramgen_init()\fR algorithm -specific control operations can be performed to set any appropriate parameters -for the operation. -.PP -The functions \fBEVP_PKEY_keygen()\fR and \fBEVP_PKEY_paramgen()\fR can be called more than -once on the same context if several operations are performed using the same -parameters. -.PP -The meaning of the parameters passed to the callback will depend on the -algorithm and the specific implementation of the algorithm. Some might not -give any useful information at all during key or parameter generation. Others -might not even call the callback. -.PP -The operation performed by key or parameter generation depends on the algorithm -used. In some cases (e.g. \s-1EC\s0 with a supplied named curve) the \*(L"generation\*(R" -option merely sets the appropriate fields in an \s-1EVP_PKEY\s0 structure. -.PP -In OpenSSL an \s-1EVP_PKEY\s0 structure containing a private key also contains the -public key components and parameters (if any). An OpenSSL private key is -equivalent to what some libraries call a \*(L"key pair\*(R". A private key can be used -in functions which require the use of a public key or parameters. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Generate a 2048 bit \s-1RSA\s0 key: -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& EVP_PKEY *pkey = NULL; -\& -\& ctx = EVP_PKEY_CTX_new_id(EVP_PKEY_RSA, NULL); -\& if (!ctx) -\& /* Error occurred */ -\& if (EVP_PKEY_keygen_init(ctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_rsa_keygen_bits(ctx, 2048) <= 0) -\& /* Error */ -\& -\& /* Generate key */ -\& if (EVP_PKEY_keygen(ctx, &pkey) <= 0) -\& /* Error */ -.Ve -.PP -Generate a key from a set of parameters: -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& ENGINE *eng; -\& EVP_PKEY *pkey = NULL, *param; -\& -\& /* Assumed param, eng are set up already */ -\& ctx = EVP_PKEY_CTX_new(param, eng); -\& if (!ctx) -\& /* Error occurred */ -\& if (EVP_PKEY_keygen_init(ctx) <= 0) -\& /* Error */ -\& -\& /* Generate key */ -\& if (EVP_PKEY_keygen(ctx, &pkey) <= 0) -\& /* Error */ -.Ve -.PP -Example of generation callback for OpenSSL public key implementations: -.PP -.Vb 1 -\& /* Application data is a BIO to output status to */ -\& -\& EVP_PKEY_CTX_set_app_data(ctx, status_bio); -\& -\& static int genpkey_cb(EVP_PKEY_CTX *ctx) -\& { -\& char c = \*(Aq*\*(Aq; -\& BIO *b = EVP_PKEY_CTX_get_app_data(ctx); -\& int p = EVP_PKEY_CTX_get_keygen_info(ctx, 0); -\& -\& if (p == 0) -\& c = \*(Aq.\*(Aq; -\& if (p == 1) -\& c = \*(Aq+\*(Aq; -\& if (p == 2) -\& c = \*(Aq*\*(Aq; -\& if (p == 3) -\& c = \*(Aq\en\*(Aq; -\& BIO_write(b, &c, 1); -\& (void)BIO_flush(b); -\& return 1; -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_RSA_gen\fR\|(3), \fBEVP_EC_gen\fR\|(3), -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_PKEY_keygen_init()\fR, int \fBEVP_PKEY_paramgen_init()\fR, \fBEVP_PKEY_keygen()\fR, -\&\fBEVP_PKEY_paramgen()\fR, \fBEVP_PKEY_gen_cb()\fR, \fBEVP_PKEY_CTX_set_cb()\fR, -\&\fBEVP_PKEY_CTX_get_cb()\fR, \fBEVP_PKEY_CTX_get_keygen_info()\fR, -\&\fBEVP_PKEY_CTX_set_app_data()\fR and \fBEVP_PKEY_CTX_get_app_data()\fR were added in -OpenSSL 1.0.0. -.PP -\&\fBEVP_PKEY_Q_keygen()\fR and \fBEVP_PKEY_generate()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_keygen_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_keygen_init.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_keygen_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_add0.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_add0.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_add0.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_copy.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_copy.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_find.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_find.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_free.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_free.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get0.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get0.3ossl deleted file mode 120000 index 889b49aa..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_get_count.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get0_info.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get0_info.3ossl deleted file mode 120000 index 889b49aa..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get0_info.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_get_count.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_check.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_cleanup.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_cleanup.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_copy.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_copy.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_count.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_count.3ossl deleted file mode 100644 index aa8ce4e5..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_count.3ossl +++ /dev/null @@ -1,194 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_METH_GET_COUNT 3ossl" -.TH EVP_PKEY_METH_GET_COUNT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_meth_get_count, EVP_PKEY_meth_get0, EVP_PKEY_meth_get0_info \- enumerate public key methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& size_t EVP_PKEY_meth_get_count(void); -\& const EVP_PKEY_METHOD *EVP_PKEY_meth_get0(size_t idx); -\& void EVP_PKEY_meth_get0_info(int *ppkey_id, int *pflags, -\& const EVP_PKEY_METHOD *meth); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the \s-1OSSL_PROVIDER\s0 APIs. -.PP -\&\fBEVP_PKEY_meth_count()\fR returns a count of the number of public key methods -available: it includes standard methods and any methods added by the -application. -.PP -\&\fBEVP_PKEY_meth_get0()\fR returns the public key method \fBidx\fR. The value of \fBidx\fR -must be between zero and \fBEVP_PKEY_meth_get_count()\fR \- 1. -.PP -\&\fBEVP_PKEY_meth_get0_info()\fR returns the public key \s-1ID\s0 (a \s-1NID\s0) and any flags -associated with the public key method \fB*meth\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_meth_count()\fR returns the number of available public key methods. -.PP -\&\fBEVP_PKEY_meth_get0()\fR return a public key method or \fB\s-1NULL\s0\fR if \fBidx\fR is -out of range. -.PP -\&\fBEVP_PKEY_meth_get0_info()\fR does not return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_ctrl.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_ctrl.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_decrypt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_decrypt.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_derive.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_derive.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_derive.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_digest_custom.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_digest_custom.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_digest_custom.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_digestsign.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_digestsign.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_digestsign.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_digestverify.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_digestverify.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_digestverify.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_encrypt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_encrypt.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_init.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_keygen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_keygen.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_param_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_param_check.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_param_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_paramgen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_paramgen.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_paramgen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_public_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_public_check.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_public_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_sign.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_sign.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_signctx.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_signctx.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_signctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_verify.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_verify.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_verify_recover.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_verify_recover.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_verify_recover.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_get_verifyctx.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_get_verifyctx.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_get_verifyctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_new.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_new.3ossl deleted file mode 100644 index c1815779..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_new.3ossl +++ /dev/null @@ -1,630 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_METH_NEW 3ossl" -.TH EVP_PKEY_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_meth_new, EVP_PKEY_meth_free, EVP_PKEY_meth_copy, EVP_PKEY_meth_find, -EVP_PKEY_meth_add0, EVP_PKEY_METHOD, -EVP_PKEY_meth_set_init, EVP_PKEY_meth_set_copy, EVP_PKEY_meth_set_cleanup, -EVP_PKEY_meth_set_paramgen, EVP_PKEY_meth_set_keygen, EVP_PKEY_meth_set_sign, -EVP_PKEY_meth_set_verify, EVP_PKEY_meth_set_verify_recover, EVP_PKEY_meth_set_signctx, -EVP_PKEY_meth_set_verifyctx, EVP_PKEY_meth_set_encrypt, EVP_PKEY_meth_set_decrypt, -EVP_PKEY_meth_set_derive, EVP_PKEY_meth_set_ctrl, -EVP_PKEY_meth_set_digestsign, EVP_PKEY_meth_set_digestverify, -EVP_PKEY_meth_set_check, -EVP_PKEY_meth_set_public_check, EVP_PKEY_meth_set_param_check, -EVP_PKEY_meth_set_digest_custom, -EVP_PKEY_meth_get_init, EVP_PKEY_meth_get_copy, EVP_PKEY_meth_get_cleanup, -EVP_PKEY_meth_get_paramgen, EVP_PKEY_meth_get_keygen, EVP_PKEY_meth_get_sign, -EVP_PKEY_meth_get_verify, EVP_PKEY_meth_get_verify_recover, EVP_PKEY_meth_get_signctx, -EVP_PKEY_meth_get_verifyctx, EVP_PKEY_meth_get_encrypt, EVP_PKEY_meth_get_decrypt, -EVP_PKEY_meth_get_derive, EVP_PKEY_meth_get_ctrl, -EVP_PKEY_meth_get_digestsign, EVP_PKEY_meth_get_digestverify, -EVP_PKEY_meth_get_check, -EVP_PKEY_meth_get_public_check, EVP_PKEY_meth_get_param_check, -EVP_PKEY_meth_get_digest_custom, -EVP_PKEY_meth_remove -\&\- manipulating EVP_PKEY_METHOD structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& typedef struct evp_pkey_method_st EVP_PKEY_METHOD; -\& -\& EVP_PKEY_METHOD *EVP_PKEY_meth_new(int id, int flags); -\& void EVP_PKEY_meth_free(EVP_PKEY_METHOD *pmeth); -\& void EVP_PKEY_meth_copy(EVP_PKEY_METHOD *dst, const EVP_PKEY_METHOD *src); -\& const EVP_PKEY_METHOD *EVP_PKEY_meth_find(int type); -\& int EVP_PKEY_meth_add0(const EVP_PKEY_METHOD *pmeth); -\& int EVP_PKEY_meth_remove(const EVP_PKEY_METHOD *pmeth); -\& -\& void EVP_PKEY_meth_set_init(EVP_PKEY_METHOD *pmeth, -\& int (*init) (EVP_PKEY_CTX *ctx)); -\& void EVP_PKEY_meth_set_copy(EVP_PKEY_METHOD *pmeth, -\& int (*copy) (EVP_PKEY_CTX *dst, -\& const EVP_PKEY_CTX *src)); -\& void EVP_PKEY_meth_set_cleanup(EVP_PKEY_METHOD *pmeth, -\& void (*cleanup) (EVP_PKEY_CTX *ctx)); -\& void EVP_PKEY_meth_set_paramgen(EVP_PKEY_METHOD *pmeth, -\& int (*paramgen_init) (EVP_PKEY_CTX *ctx), -\& int (*paramgen) (EVP_PKEY_CTX *ctx, -\& EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_set_keygen(EVP_PKEY_METHOD *pmeth, -\& int (*keygen_init) (EVP_PKEY_CTX *ctx), -\& int (*keygen) (EVP_PKEY_CTX *ctx, -\& EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_set_sign(EVP_PKEY_METHOD *pmeth, -\& int (*sign_init) (EVP_PKEY_CTX *ctx), -\& int (*sign) (EVP_PKEY_CTX *ctx, -\& unsigned char *sig, size_t *siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_set_verify(EVP_PKEY_METHOD *pmeth, -\& int (*verify_init) (EVP_PKEY_CTX *ctx), -\& int (*verify) (EVP_PKEY_CTX *ctx, -\& const unsigned char *sig, -\& size_t siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_set_verify_recover(EVP_PKEY_METHOD *pmeth, -\& int (*verify_recover_init) (EVP_PKEY_CTX -\& *ctx), -\& int (*verify_recover) (EVP_PKEY_CTX -\& *ctx, -\& unsigned char -\& *sig, -\& size_t *siglen, -\& const unsigned -\& char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_set_signctx(EVP_PKEY_METHOD *pmeth, -\& int (*signctx_init) (EVP_PKEY_CTX *ctx, -\& EVP_MD_CTX *mctx), -\& int (*signctx) (EVP_PKEY_CTX *ctx, -\& unsigned char *sig, -\& size_t *siglen, -\& EVP_MD_CTX *mctx)); -\& void EVP_PKEY_meth_set_verifyctx(EVP_PKEY_METHOD *pmeth, -\& int (*verifyctx_init) (EVP_PKEY_CTX *ctx, -\& EVP_MD_CTX *mctx), -\& int (*verifyctx) (EVP_PKEY_CTX *ctx, -\& const unsigned char *sig, -\& int siglen, -\& EVP_MD_CTX *mctx)); -\& void EVP_PKEY_meth_set_encrypt(EVP_PKEY_METHOD *pmeth, -\& int (*encrypt_init) (EVP_PKEY_CTX *ctx), -\& int (*encryptfn) (EVP_PKEY_CTX *ctx, -\& unsigned char *out, -\& size_t *outlen, -\& const unsigned char *in, -\& size_t inlen)); -\& void EVP_PKEY_meth_set_decrypt(EVP_PKEY_METHOD *pmeth, -\& int (*decrypt_init) (EVP_PKEY_CTX *ctx), -\& int (*decrypt) (EVP_PKEY_CTX *ctx, -\& unsigned char *out, -\& size_t *outlen, -\& const unsigned char *in, -\& size_t inlen)); -\& void EVP_PKEY_meth_set_derive(EVP_PKEY_METHOD *pmeth, -\& int (*derive_init) (EVP_PKEY_CTX *ctx), -\& int (*derive) (EVP_PKEY_CTX *ctx, -\& unsigned char *key, -\& size_t *keylen)); -\& void EVP_PKEY_meth_set_ctrl(EVP_PKEY_METHOD *pmeth, -\& int (*ctrl) (EVP_PKEY_CTX *ctx, int type, int p1, -\& void *p2), -\& int (*ctrl_str) (EVP_PKEY_CTX *ctx, -\& const char *type, -\& const char *value)); -\& void EVP_PKEY_meth_set_digestsign(EVP_PKEY_METHOD *pmeth, -\& int (*digestsign) (EVP_MD_CTX *ctx, -\& unsigned char *sig, -\& size_t *siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_set_digestverify(EVP_PKEY_METHOD *pmeth, -\& int (*digestverify) (EVP_MD_CTX *ctx, -\& const unsigned char *sig, -\& size_t siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_set_check(EVP_PKEY_METHOD *pmeth, -\& int (*check) (EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_set_public_check(EVP_PKEY_METHOD *pmeth, -\& int (*check) (EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_set_param_check(EVP_PKEY_METHOD *pmeth, -\& int (*check) (EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_set_digest_custom(EVP_PKEY_METHOD *pmeth, -\& int (*digest_custom) (EVP_PKEY_CTX *ctx, -\& EVP_MD_CTX *mctx)); -\& -\& void EVP_PKEY_meth_get_init(const EVP_PKEY_METHOD *pmeth, -\& int (**pinit) (EVP_PKEY_CTX *ctx)); -\& void EVP_PKEY_meth_get_copy(const EVP_PKEY_METHOD *pmeth, -\& int (**pcopy) (EVP_PKEY_CTX *dst, -\& EVP_PKEY_CTX *src)); -\& void EVP_PKEY_meth_get_cleanup(const EVP_PKEY_METHOD *pmeth, -\& void (**pcleanup) (EVP_PKEY_CTX *ctx)); -\& void EVP_PKEY_meth_get_paramgen(const EVP_PKEY_METHOD *pmeth, -\& int (**pparamgen_init) (EVP_PKEY_CTX *ctx), -\& int (**pparamgen) (EVP_PKEY_CTX *ctx, -\& EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_get_keygen(const EVP_PKEY_METHOD *pmeth, -\& int (**pkeygen_init) (EVP_PKEY_CTX *ctx), -\& int (**pkeygen) (EVP_PKEY_CTX *ctx, -\& EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_get_sign(const EVP_PKEY_METHOD *pmeth, -\& int (**psign_init) (EVP_PKEY_CTX *ctx), -\& int (**psign) (EVP_PKEY_CTX *ctx, -\& unsigned char *sig, size_t *siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_get_verify(const EVP_PKEY_METHOD *pmeth, -\& int (**pverify_init) (EVP_PKEY_CTX *ctx), -\& int (**pverify) (EVP_PKEY_CTX *ctx, -\& const unsigned char *sig, -\& size_t siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_get_verify_recover(const EVP_PKEY_METHOD *pmeth, -\& int (**pverify_recover_init) (EVP_PKEY_CTX -\& *ctx), -\& int (**pverify_recover) (EVP_PKEY_CTX -\& *ctx, -\& unsigned char -\& *sig, -\& size_t *siglen, -\& const unsigned -\& char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_get_signctx(const EVP_PKEY_METHOD *pmeth, -\& int (**psignctx_init) (EVP_PKEY_CTX *ctx, -\& EVP_MD_CTX *mctx), -\& int (**psignctx) (EVP_PKEY_CTX *ctx, -\& unsigned char *sig, -\& size_t *siglen, -\& EVP_MD_CTX *mctx)); -\& void EVP_PKEY_meth_get_verifyctx(const EVP_PKEY_METHOD *pmeth, -\& int (**pverifyctx_init) (EVP_PKEY_CTX *ctx, -\& EVP_MD_CTX *mctx), -\& int (**pverifyctx) (EVP_PKEY_CTX *ctx, -\& const unsigned char *sig, -\& int siglen, -\& EVP_MD_CTX *mctx)); -\& void EVP_PKEY_meth_get_encrypt(const EVP_PKEY_METHOD *pmeth, -\& int (**pencrypt_init) (EVP_PKEY_CTX *ctx), -\& int (**pencryptfn) (EVP_PKEY_CTX *ctx, -\& unsigned char *out, -\& size_t *outlen, -\& const unsigned char *in, -\& size_t inlen)); -\& void EVP_PKEY_meth_get_decrypt(const EVP_PKEY_METHOD *pmeth, -\& int (**pdecrypt_init) (EVP_PKEY_CTX *ctx), -\& int (**pdecrypt) (EVP_PKEY_CTX *ctx, -\& unsigned char *out, -\& size_t *outlen, -\& const unsigned char *in, -\& size_t inlen)); -\& void EVP_PKEY_meth_get_derive(const EVP_PKEY_METHOD *pmeth, -\& int (**pderive_init) (EVP_PKEY_CTX *ctx), -\& int (**pderive) (EVP_PKEY_CTX *ctx, -\& unsigned char *key, -\& size_t *keylen)); -\& void EVP_PKEY_meth_get_ctrl(const EVP_PKEY_METHOD *pmeth, -\& int (**pctrl) (EVP_PKEY_CTX *ctx, int type, int p1, -\& void *p2), -\& int (**pctrl_str) (EVP_PKEY_CTX *ctx, -\& const char *type, -\& const char *value)); -\& void EVP_PKEY_meth_get_digestsign(const EVP_PKEY_METHOD *pmeth, -\& int (**digestsign) (EVP_MD_CTX *ctx, -\& unsigned char *sig, -\& size_t *siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_get_digestverify(const EVP_PKEY_METHOD *pmeth, -\& int (**digestverify) (EVP_MD_CTX *ctx, -\& const unsigned char *sig, -\& size_t siglen, -\& const unsigned char *tbs, -\& size_t tbslen)); -\& void EVP_PKEY_meth_get_check(const EVP_PKEY_METHOD *pmeth, -\& int (**pcheck) (EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_get_public_check(const EVP_PKEY_METHOD *pmeth, -\& int (**pcheck) (EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_get_param_check(const EVP_PKEY_METHOD *pmeth, -\& int (**pcheck) (EVP_PKEY *pkey)); -\& void EVP_PKEY_meth_get_digest_custom(const EVP_PKEY_METHOD *pmeth, -\& int (**pdigest_custom) (EVP_PKEY_CTX *ctx, -\& EVP_MD_CTX *mctx)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the \s-1OSSL_PROVIDER\s0 APIs. -.PP -\&\fB\s-1EVP_PKEY_METHOD\s0\fR is a structure which holds a set of methods for a -specific public key cryptographic algorithm. Those methods are usually -used to perform different jobs, such as generating a key, signing or -verifying, encrypting or decrypting, etc. -.PP -There are two places where the \fB\s-1EVP_PKEY_METHOD\s0\fR objects are stored: one -is a built-in static array representing the standard methods for different -algorithms, and the other one is a stack of user-defined application-specific -methods, which can be manipulated by using \fBEVP_PKEY_meth_add0\fR\|(3). -.PP -The \fB\s-1EVP_PKEY_METHOD\s0\fR objects are usually referenced by \fB\s-1EVP_PKEY_CTX\s0\fR -objects. -.SS "Methods" -.IX Subsection "Methods" -The methods are the underlying implementations of a particular public key -algorithm present by the \fB\s-1EVP_PKEY_CTX\s0\fR object. -.PP -.Vb 3 -\& int (*init) (EVP_PKEY_CTX *ctx); -\& int (*copy) (EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src); -\& void (*cleanup) (EVP_PKEY_CTX *ctx); -.Ve -.PP -The \fBinit()\fR method is called to initialize algorithm-specific data when a new -\&\fB\s-1EVP_PKEY_CTX\s0\fR is created. As opposed to \fBinit()\fR, the \fBcleanup()\fR method is called -when an \fB\s-1EVP_PKEY_CTX\s0\fR is freed. The \fBcopy()\fR method is called when an \fB\s-1EVP_PKEY_CTX\s0\fR -is being duplicated. Refer to \fBEVP_PKEY_CTX_new\fR\|(3), \fBEVP_PKEY_CTX_new_id\fR\|(3), -\&\fBEVP_PKEY_CTX_free\fR\|(3) and \fBEVP_PKEY_CTX_dup\fR\|(3). -.PP -.Vb 2 -\& int (*paramgen_init) (EVP_PKEY_CTX *ctx); -\& int (*paramgen) (EVP_PKEY_CTX *ctx, EVP_PKEY *pkey); -.Ve -.PP -The \fBparamgen_init()\fR and \fBparamgen()\fR methods deal with key parameter generation. -They are called by \fBEVP_PKEY_paramgen_init\fR\|(3) and \fBEVP_PKEY_paramgen\fR\|(3) to -handle the parameter generation process. -.PP -.Vb 2 -\& int (*keygen_init) (EVP_PKEY_CTX *ctx); -\& int (*keygen) (EVP_PKEY_CTX *ctx, EVP_PKEY *pkey); -.Ve -.PP -The \fBkeygen_init()\fR and \fBkeygen()\fR methods are used to generate the actual key for -the specified algorithm. They are called by \fBEVP_PKEY_keygen_init\fR\|(3) and -\&\fBEVP_PKEY_keygen\fR\|(3). -.PP -.Vb 3 -\& int (*sign_init) (EVP_PKEY_CTX *ctx); -\& int (*sign) (EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, -\& const unsigned char *tbs, size_t tbslen); -.Ve -.PP -The \fBsign_init()\fR and \fBsign()\fR methods are used to generate the signature of a -piece of data using a private key. They are called by \fBEVP_PKEY_sign_init\fR\|(3) -and \fBEVP_PKEY_sign\fR\|(3). -.PP -.Vb 4 -\& int (*verify_init) (EVP_PKEY_CTX *ctx); -\& int (*verify) (EVP_PKEY_CTX *ctx, -\& const unsigned char *sig, size_t siglen, -\& const unsigned char *tbs, size_t tbslen); -.Ve -.PP -The \fBverify_init()\fR and \fBverify()\fR methods are used to verify whether a signature is -valid. They are called by \fBEVP_PKEY_verify_init\fR\|(3) and \fBEVP_PKEY_verify\fR\|(3). -.PP -.Vb 4 -\& int (*verify_recover_init) (EVP_PKEY_CTX *ctx); -\& int (*verify_recover) (EVP_PKEY_CTX *ctx, -\& unsigned char *rout, size_t *routlen, -\& const unsigned char *sig, size_t siglen); -.Ve -.PP -The \fBverify_recover_init()\fR and \fBverify_recover()\fR methods are used to verify a -signature and then recover the digest from the signature (for instance, a -signature that was generated by \s-1RSA\s0 signing algorithm). They are called by -\&\fBEVP_PKEY_verify_recover_init\fR\|(3) and \fBEVP_PKEY_verify_recover\fR\|(3). -.PP -.Vb 3 -\& int (*signctx_init) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); -\& int (*signctx) (EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, -\& EVP_MD_CTX *mctx); -.Ve -.PP -The \fBsignctx_init()\fR and \fBsignctx()\fR methods are used to sign a digest present by -a \fB\s-1EVP_MD_CTX\s0\fR object. They are called by the EVP_DigestSign functions. See -\&\fBEVP_DigestSignInit\fR\|(3) for details. -.PP -.Vb 3 -\& int (*verifyctx_init) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); -\& int (*verifyctx) (EVP_PKEY_CTX *ctx, const unsigned char *sig, int siglen, -\& EVP_MD_CTX *mctx); -.Ve -.PP -The \fBverifyctx_init()\fR and \fBverifyctx()\fR methods are used to verify a signature -against the data in a \fB\s-1EVP_MD_CTX\s0\fR object. They are called by the various -EVP_DigestVerify functions. See \fBEVP_DigestVerifyInit\fR\|(3) for details. -.PP -.Vb 3 -\& int (*encrypt_init) (EVP_PKEY_CTX *ctx); -\& int (*encrypt) (EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, -\& const unsigned char *in, size_t inlen); -.Ve -.PP -The \fBencrypt_init()\fR and \fBencrypt()\fR methods are used to encrypt a piece of data. -They are called by \fBEVP_PKEY_encrypt_init\fR\|(3) and \fBEVP_PKEY_encrypt\fR\|(3). -.PP -.Vb 3 -\& int (*decrypt_init) (EVP_PKEY_CTX *ctx); -\& int (*decrypt) (EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, -\& const unsigned char *in, size_t inlen); -.Ve -.PP -The \fBdecrypt_init()\fR and \fBdecrypt()\fR methods are used to decrypt a piece of data. -They are called by \fBEVP_PKEY_decrypt_init\fR\|(3) and \fBEVP_PKEY_decrypt\fR\|(3). -.PP -.Vb 2 -\& int (*derive_init) (EVP_PKEY_CTX *ctx); -\& int (*derive) (EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen); -.Ve -.PP -The \fBderive_init()\fR and \fBderive()\fR methods are used to derive the shared secret -from a public key algorithm (for instance, the \s-1DH\s0 algorithm). They are called by -\&\fBEVP_PKEY_derive_init\fR\|(3) and \fBEVP_PKEY_derive\fR\|(3). -.PP -.Vb 2 -\& int (*ctrl) (EVP_PKEY_CTX *ctx, int type, int p1, void *p2); -\& int (*ctrl_str) (EVP_PKEY_CTX *ctx, const char *type, const char *value); -.Ve -.PP -The \fBctrl()\fR and \fBctrl_str()\fR methods are used to adjust algorithm-specific -settings. See \fBEVP_PKEY_CTX_ctrl\fR\|(3) and related functions for details. -.PP -.Vb 5 -\& int (*digestsign) (EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen, -\& const unsigned char *tbs, size_t tbslen); -\& int (*digestverify) (EVP_MD_CTX *ctx, const unsigned char *sig, -\& size_t siglen, const unsigned char *tbs, -\& size_t tbslen); -.Ve -.PP -The \fBdigestsign()\fR and \fBdigestverify()\fR methods are used to generate or verify -a signature in a one-shot mode. They could be called by \fBEVP_DigestSign\fR\|(3) -and \fBEVP_DigestVerify\fR\|(3). -.PP -.Vb 3 -\& int (*check) (EVP_PKEY *pkey); -\& int (*public_check) (EVP_PKEY *pkey); -\& int (*param_check) (EVP_PKEY *pkey); -.Ve -.PP -The \fBcheck()\fR, \fBpublic_check()\fR and \fBparam_check()\fR methods are used to validate a -key-pair, the public component and parameters respectively for a given \fBpkey\fR. -They could be called by \fBEVP_PKEY_check\fR\|(3), \fBEVP_PKEY_public_check\fR\|(3) and -\&\fBEVP_PKEY_param_check\fR\|(3) respectively. -.PP -.Vb 1 -\& int (*digest_custom) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); -.Ve -.PP -The \fBdigest_custom()\fR method is used to generate customized digest content before -the real message is passed to functions like \fBEVP_DigestSignUpdate\fR\|(3) or -\&\fBEVP_DigestVerifyInit\fR\|(3). This is usually required by some public key -signature algorithms like \s-1SM2\s0 which requires a hashed prefix to the message to -be signed. The \fBdigest_custom()\fR function will be called by \fBEVP_DigestSignInit\fR\|(3) -and \fBEVP_DigestVerifyInit\fR\|(3). -.SS "Functions" -.IX Subsection "Functions" -\&\fBEVP_PKEY_meth_new()\fR creates and returns a new \fB\s-1EVP_PKEY_METHOD\s0\fR object, -and associates the given \fBid\fR and \fBflags\fR. The following flags are -supported: -.PP -.Vb 2 -\& EVP_PKEY_FLAG_AUTOARGLEN -\& EVP_PKEY_FLAG_SIGCTX_CUSTOM -.Ve -.PP -If an \fB\s-1EVP_PKEY_METHOD\s0\fR is set with the \fB\s-1EVP_PKEY_FLAG_AUTOARGLEN\s0\fR flag, the -maximum size of the output buffer will be automatically calculated or checked -in corresponding \s-1EVP\s0 methods by the \s-1EVP\s0 framework. Thus the implementations of -these methods don't need to care about handling the case of returning output -buffer size by themselves. For details on the output buffer size, refer to -\&\fBEVP_PKEY_sign\fR\|(3). -.PP -The \fB\s-1EVP_PKEY_FLAG_SIGCTX_CUSTOM\s0\fR is used to indicate the \fBsignctx()\fR method -of an \fB\s-1EVP_PKEY_METHOD\s0\fR is always called by the \s-1EVP\s0 framework while doing a -digest signing operation by calling \fBEVP_DigestSignFinal\fR\|(3). -.PP -\&\fBEVP_PKEY_meth_free()\fR frees an existing \fB\s-1EVP_PKEY_METHOD\s0\fR pointed by -\&\fBpmeth\fR. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_PKEY_meth_copy()\fR copies an \fB\s-1EVP_PKEY_METHOD\s0\fR object from \fBsrc\fR -to \fBdst\fR. -.PP -\&\fBEVP_PKEY_meth_find()\fR finds an \fB\s-1EVP_PKEY_METHOD\s0\fR object with the \fBid\fR. -This function first searches through the user-defined method objects and -then the built-in objects. -.PP -\&\fBEVP_PKEY_meth_add0()\fR adds \fBpmeth\fR to the user defined stack of methods. -.PP -\&\fBEVP_PKEY_meth_remove()\fR removes an \fB\s-1EVP_PKEY_METHOD\s0\fR object added by -\&\fBEVP_PKEY_meth_add0()\fR. -.PP -The EVP_PKEY_meth_set functions set the corresponding fields of -\&\fB\s-1EVP_PKEY_METHOD\s0\fR structure with the arguments passed. -.PP -The EVP_PKEY_meth_get functions get the corresponding fields of -\&\fB\s-1EVP_PKEY_METHOD\s0\fR structure to the arguments provided. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_meth_new()\fR returns a pointer to a new \fB\s-1EVP_PKEY_METHOD\s0\fR -object or returns \s-1NULL\s0 on error. -.PP -\&\fBEVP_PKEY_meth_free()\fR and \fBEVP_PKEY_meth_copy()\fR do not return values. -.PP -\&\fBEVP_PKEY_meth_find()\fR returns a pointer to the found \fB\s-1EVP_PKEY_METHOD\s0\fR -object or returns \s-1NULL\s0 if not found. -.PP -\&\fBEVP_PKEY_meth_add0()\fR returns 1 if method is added successfully or 0 -if an error occurred. -.PP -\&\fBEVP_PKEY_meth_remove()\fR returns 1 if method is removed successfully or -0 if an error occurred. -.PP -All EVP_PKEY_meth_set and EVP_PKEY_meth_get functions have no return -values. For the 'get' functions, function pointers are returned by -arguments. -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -The signature of the \fIcopy\fR functional argument of \fBEVP_PKEY_meth_set_copy()\fR -has changed in OpenSSL 3.0 so its \fIsrc\fR parameter is now constified. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_remove.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_remove.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_remove.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_check.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_cleanup.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_cleanup.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_copy.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_copy.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_ctrl.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_ctrl.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_decrypt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_decrypt.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_derive.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_derive.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_derive.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_digest_custom.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_digest_custom.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_digest_custom.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_digestsign.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_digestsign.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_digestsign.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_digestverify.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_digestverify.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_digestverify.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_encrypt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_encrypt.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_init.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_keygen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_keygen.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_param_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_param_check.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_param_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_paramgen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_paramgen.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_paramgen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_public_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_public_check.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_public_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_sign.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_sign.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_signctx.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_signctx.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_signctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_verify.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_verify.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_verify_recover.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_verify_recover.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_verify_recover.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_meth_set_verifyctx.3ossl b/openssl-install/share/man/man3/EVP_PKEY_meth_set_verifyctx.3ossl deleted file mode 120000 index b86efa86..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_meth_set_verifyctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_missing_parameters.3ossl b/openssl-install/share/man/man3/EVP_PKEY_missing_parameters.3ossl deleted file mode 120000 index 9da46e99..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_missing_parameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_copy_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_new.3ossl b/openssl-install/share/man/man3/EVP_PKEY_new.3ossl deleted file mode 100644 index 68baedad..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_new.3ossl +++ /dev/null @@ -1,350 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_NEW 3ossl" -.TH EVP_PKEY_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY, -EVP_PKEY_new, -EVP_PKEY_up_ref, -EVP_PKEY_dup, -EVP_PKEY_free, -EVP_PKEY_new_raw_private_key_ex, -EVP_PKEY_new_raw_private_key, -EVP_PKEY_new_raw_public_key_ex, -EVP_PKEY_new_raw_public_key, -EVP_PKEY_new_CMAC_key, -EVP_PKEY_new_mac_key, -EVP_PKEY_get_raw_private_key, -EVP_PKEY_get_raw_public_key -\&\- public/private key allocation and raw key handling functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef evp_pkey_st EVP_PKEY; -\& -\& EVP_PKEY *EVP_PKEY_new(void); -\& int EVP_PKEY_up_ref(EVP_PKEY *key); -\& EVP_PKEY *EVP_PKEY_dup(EVP_PKEY *key); -\& void EVP_PKEY_free(EVP_PKEY *key); -\& -\& EVP_PKEY *EVP_PKEY_new_raw_private_key_ex(OSSL_LIB_CTX *libctx, -\& const char *keytype, -\& const char *propq, -\& const unsigned char *key, -\& size_t keylen); -\& EVP_PKEY *EVP_PKEY_new_raw_private_key(int type, ENGINE *e, -\& const unsigned char *key, size_t keylen); -\& EVP_PKEY *EVP_PKEY_new_raw_public_key_ex(OSSL_LIB_CTX *libctx, -\& const char *keytype, -\& const char *propq, -\& const unsigned char *key, -\& size_t keylen); -\& EVP_PKEY *EVP_PKEY_new_raw_public_key(int type, ENGINE *e, -\& const unsigned char *key, size_t keylen); -\& EVP_PKEY *EVP_PKEY_new_mac_key(int type, ENGINE *e, const unsigned char *key, -\& int keylen); -\& -\& int EVP_PKEY_get_raw_private_key(const EVP_PKEY *pkey, unsigned char *priv, -\& size_t *len); -\& int EVP_PKEY_get_raw_public_key(const EVP_PKEY *pkey, unsigned char *pub, -\& size_t *len); -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& EVP_PKEY *EVP_PKEY_new_CMAC_key(ENGINE *e, const unsigned char *priv, -\& size_t len, const EVP_CIPHER *cipher); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1EVP_PKEY\s0\fR is a generic structure to hold diverse types of asymmetric keys -(also known as \*(L"key pairs\*(R"), and can be used for diverse operations, like -signing, verifying signatures, key derivation, etc. The asymmetric keys -themselves are often referred to as the \*(L"internal key\*(R", and are handled by -backends, such as providers (through \s-1\fBEVP_KEYMGMT\s0\fR\|(3)) or \fB\s-1ENGINE\s0\fRs. -.PP -Conceptually, an \fB\s-1EVP_PKEY\s0\fR internal key may hold a private key, a public -key, or both (a keypair), and along with those, key parameters if the key type -requires them. The presence of these components determine what operations can -be made; for example, signing normally requires the presence of a private key, -and verifying normally requires the presence of a public key. -.PP -\&\fB\s-1EVP_PKEY\s0\fR has also been used for \s-1MAC\s0 algorithm that were conceived as -producing signatures, although not being public key algorithms; \*(L"\s-1POLY1305\*(R", -\&\*(L"SIPHASH\*(R", \*(L"HMAC\*(R", \*(L"CMAC\*(R".\s0 This usage is considered legacy and is discouraged -in favor of the \s-1\fBEVP_MAC\s0\fR\|(3) \s-1API.\s0 -.PP -The \fBEVP_PKEY_new()\fR function allocates an empty \fB\s-1EVP_PKEY\s0\fR structure which is -used by OpenSSL to store public and private keys. The reference count is set to -\&\fB1\fR. -.PP -\&\fBEVP_PKEY_up_ref()\fR increments the reference count of \fIkey\fR. -.PP -\&\fBEVP_PKEY_dup()\fR duplicates the \fIkey\fR. The \fIkey\fR must not be \s-1ENGINE\s0 based or -a raw key, otherwise the duplication will fail. -.PP -\&\fBEVP_PKEY_free()\fR decrements the reference count of \fIkey\fR and, if the reference -count is zero, frees it up. If \fIkey\fR is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_PKEY_new_raw_private_key_ex()\fR allocates a new \fB\s-1EVP_PKEY\s0\fR. Unless an -engine should be used for the key type, a provider for the key is found using -the library context \fIlibctx\fR and the property query string \fIpropq\fR. The -\&\fIkeytype\fR argument indicates what kind of key this is. The value should be a -string for a public key algorithm that supports raw private keys, i.e one of -\&\*(L"X25519\*(R", \*(L"\s-1ED25519\*(R", \*(L"X448\*(R"\s0 or \*(L"\s-1ED448\*(R".\s0 \fIkey\fR points to the raw private key -data for this \fB\s-1EVP_PKEY\s0\fR which should be of length \fIkeylen\fR. The length -should be appropriate for the type of the key. The public key data will be -automatically derived from the given private key data (if appropriate for the -algorithm type). -.PP -\&\fBEVP_PKEY_new_raw_private_key()\fR does the same as -\&\fBEVP_PKEY_new_raw_private_key_ex()\fR except that the default library context and -default property query are used instead. If \fIe\fR is non-NULL then the new -\&\fB\s-1EVP_PKEY\s0\fR structure is associated with the engine \fIe\fR. The \fItype\fR argument -indicates what kind of key this is. The value should be a \s-1NID\s0 for a public key -algorithm that supports raw private keys, i.e. one of \fB\s-1EVP_PKEY_X25519\s0\fR, -\&\fB\s-1EVP_PKEY_ED25519\s0\fR, \fB\s-1EVP_PKEY_X448\s0\fR or \fB\s-1EVP_PKEY_ED448\s0\fR. -.PP -\&\fBEVP_PKEY_new_raw_private_key_ex()\fR and \fBEVP_PKEY_new_raw_private_key()\fR may also -be used with most MACs implemented as public key algorithms, so key types such -as \*(L"\s-1HMAC\*(R", \*(L"POLY1305\*(R", \*(L"SIPHASH\*(R",\s0 or their \s-1NID\s0 form \fB\s-1EVP_PKEY_POLY1305\s0\fR, -\&\fB\s-1EVP_PKEY_SIPHASH\s0\fR, \fB\s-1EVP_PKEY_HMAC\s0\fR are also accepted. This usage is, -as mentioned above, discouraged in favor of the \s-1\fBEVP_MAC\s0\fR\|(3) \s-1API.\s0 -.PP -\&\fBEVP_PKEY_new_raw_public_key_ex()\fR works in the same way as -\&\fBEVP_PKEY_new_raw_private_key_ex()\fR except that \fIkey\fR points to the raw -public key data. The \fB\s-1EVP_PKEY\s0\fR structure will be initialised without any -private key information. Algorithm types that support raw public keys are -\&\*(L"X25519\*(R", \*(L"\s-1ED25519\*(R", \*(L"X448\*(R"\s0 or \*(L"\s-1ED448\*(R".\s0 -.PP -\&\fBEVP_PKEY_new_raw_public_key()\fR works in the same way as -\&\fBEVP_PKEY_new_raw_private_key()\fR except that \fIkey\fR points to the raw public key -data. The \fB\s-1EVP_PKEY\s0\fR structure will be initialised without any private key -information. Algorithm types that support raw public keys are -\&\fB\s-1EVP_PKEY_X25519\s0\fR, \fB\s-1EVP_PKEY_ED25519\s0\fR, \fB\s-1EVP_PKEY_X448\s0\fR or \fB\s-1EVP_PKEY_ED448\s0\fR. -.PP -\&\fBEVP_PKEY_new_mac_key()\fR works in the same way as \fBEVP_PKEY_new_raw_private_key()\fR. -New applications should use \fBEVP_PKEY_new_raw_private_key()\fR instead. -.PP -\&\fBEVP_PKEY_get_raw_private_key()\fR fills the buffer provided by \fIpriv\fR with raw -private key data. The size of the \fIpriv\fR buffer should be in \fI*len\fR on entry -to the function, and on exit \fI*len\fR is updated with the number of bytes -actually written. If the buffer \fIpriv\fR is \s-1NULL\s0 then \fI*len\fR is populated with -the number of bytes required to hold the key. The calling application is -responsible for ensuring that the buffer is large enough to receive the private -key data. This function only works for algorithms that support raw private keys. -Currently this is: \fB\s-1EVP_PKEY_HMAC\s0\fR, \fB\s-1EVP_PKEY_POLY1305\s0\fR, \fB\s-1EVP_PKEY_SIPHASH\s0\fR, -\&\fB\s-1EVP_PKEY_X25519\s0\fR, \fB\s-1EVP_PKEY_ED25519\s0\fR, \fB\s-1EVP_PKEY_X448\s0\fR or \fB\s-1EVP_PKEY_ED448\s0\fR. -.PP -\&\fBEVP_PKEY_get_raw_public_key()\fR fills the buffer provided by \fIpub\fR with raw -public key data. The size of the \fIpub\fR buffer should be in \fI*len\fR on entry -to the function, and on exit \fI*len\fR is updated with the number of bytes -actually written. If the buffer \fIpub\fR is \s-1NULL\s0 then \fI*len\fR is populated with -the number of bytes required to hold the key. The calling application is -responsible for ensuring that the buffer is large enough to receive the public -key data. This function only works for algorithms that support raw public keys. -Currently this is: \fB\s-1EVP_PKEY_X25519\s0\fR, \fB\s-1EVP_PKEY_ED25519\s0\fR, \fB\s-1EVP_PKEY_X448\s0\fR or -\&\fB\s-1EVP_PKEY_ED448\s0\fR. -.PP -\&\fBEVP_PKEY_new_CMAC_key()\fR works in the same way as \fBEVP_PKEY_new_raw_private_key()\fR -except it is only for the \fB\s-1EVP_PKEY_CMAC\s0\fR algorithm type. In addition to the -raw private key data, it also takes a cipher algorithm to be used during -creation of a \s-1CMAC\s0 in the \fBcipher\fR argument. The cipher should be a standard -encryption-only cipher. For example \s-1AEAD\s0 and \s-1XTS\s0 ciphers should not be used. -.PP -Applications should use the \s-1\fBEVP_MAC\s0\fR\|(3) \s-1API\s0 instead -and set the \fB\s-1OSSL_MAC_PARAM_CIPHER\s0\fR parameter on the \fB\s-1EVP_MAC_CTX\s0\fR object -with the name of the cipher being used. -.SH "NOTES" -.IX Header "NOTES" -The \fB\s-1EVP_PKEY\s0\fR structure is used by various OpenSSL functions which require a -general private key without reference to any particular algorithm. -.PP -The structure returned by \fBEVP_PKEY_new()\fR is empty. To add a private or public -key to this empty structure use the appropriate functions described in -\&\fBEVP_PKEY_set1_RSA\fR\|(3), \fBEVP_PKEY_set1_DSA\fR\|(3), \fBEVP_PKEY_set1_DH\fR\|(3) or -\&\fBEVP_PKEY_set1_EC_KEY\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_new()\fR, \fBEVP_PKEY_new_raw_private_key()\fR, \fBEVP_PKEY_new_raw_public_key()\fR, -\&\fBEVP_PKEY_new_CMAC_key()\fR and \fBEVP_PKEY_new_mac_key()\fR return either the newly -allocated \fB\s-1EVP_PKEY\s0\fR structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBEVP_PKEY_dup()\fR returns the key duplicate or \s-1NULL\s0 if an error occurred. -.PP -\&\fBEVP_PKEY_up_ref()\fR, \fBEVP_PKEY_get_raw_private_key()\fR and -\&\fBEVP_PKEY_get_raw_public_key()\fR return 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_set1_RSA\fR\|(3), \fBEVP_PKEY_set1_DSA\fR\|(3), \fBEVP_PKEY_set1_DH\fR\|(3) or -\&\fBEVP_PKEY_set1_EC_KEY\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The -\&\fBEVP_PKEY_new()\fR and \fBEVP_PKEY_free()\fR functions exist in all versions of OpenSSL. -.PP -The \fBEVP_PKEY_up_ref()\fR function was added in OpenSSL 1.1.0. -.PP -The -\&\fBEVP_PKEY_new_raw_private_key()\fR, \fBEVP_PKEY_new_raw_public_key()\fR, -\&\fBEVP_PKEY_new_CMAC_key()\fR, \fBEVP_PKEY_new_raw_private_key()\fR and -\&\fBEVP_PKEY_get_raw_public_key()\fR functions were added in OpenSSL 1.1.1. -.PP -The \fBEVP_PKEY_dup()\fR, \fBEVP_PKEY_new_raw_private_key_ex()\fR, and -\&\fBEVP_PKEY_new_raw_public_key_ex()\fR -functions were added in OpenSSL 3.0. -.PP -The \fBEVP_PKEY_new_CMAC_key()\fR was deprecated in OpenSSL 3.0. -.PP -The documentation of \fB\s-1EVP_PKEY\s0\fR was amended in OpenSSL 3.0 to allow there to -be the private part of the keypair without the public part, where this was -previously implied to be disallowed. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_new_CMAC_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_new_CMAC_key.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_new_CMAC_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_new_mac_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_new_mac_key.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_new_mac_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key_ex.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_new_raw_private_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key_ex.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_new_raw_public_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_pairwise_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_pairwise_check.3ossl deleted file mode 120000 index 45eb2158..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_pairwise_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_check.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_param_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_param_check.3ossl deleted file mode 120000 index 45eb2158..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_param_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_check.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_param_check_quick.3ossl b/openssl-install/share/man/man3/EVP_PKEY_param_check_quick.3ossl deleted file mode 120000 index 45eb2158..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_param_check_quick.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_check.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_parameters_eq.3ossl b/openssl-install/share/man/man3/EVP_PKEY_parameters_eq.3ossl deleted file mode 120000 index 9da46e99..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_parameters_eq.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_copy_parameters.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_paramgen.3ossl b/openssl-install/share/man/man3/EVP_PKEY_paramgen.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_paramgen.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_paramgen_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_paramgen_init.3ossl deleted file mode 120000 index 908f5ac7..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_paramgen_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_keygen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_print_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_print_params.3ossl deleted file mode 120000 index 9a16d2ff..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_print_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_print_private.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_print_params_fp.3ossl b/openssl-install/share/man/man3/EVP_PKEY_print_params_fp.3ossl deleted file mode 120000 index 9a16d2ff..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_print_params_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_print_private.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_print_private.3ossl b/openssl-install/share/man/man3/EVP_PKEY_print_private.3ossl deleted file mode 100644 index ea6c8540..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_print_private.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_PRINT_PRIVATE 3ossl" -.TH EVP_PKEY_PRINT_PRIVATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_print_public, EVP_PKEY_print_private, EVP_PKEY_print_params, -EVP_PKEY_print_public_fp, EVP_PKEY_print_private_fp, -EVP_PKEY_print_params_fp \- public key algorithm printing routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_print_public(BIO *out, const EVP_PKEY *pkey, -\& int indent, ASN1_PCTX *pctx); -\& int EVP_PKEY_print_public_fp(FILE *fp, const EVP_PKEY *pkey, -\& int indent, ASN1_PCTX *pctx); -\& int EVP_PKEY_print_private(BIO *out, const EVP_PKEY *pkey, -\& int indent, ASN1_PCTX *pctx); -\& int EVP_PKEY_print_private_fp(FILE *fp, const EVP_PKEY *pkey, -\& int indent, ASN1_PCTX *pctx); -\& int EVP_PKEY_print_params(BIO *out, const EVP_PKEY *pkey, -\& int indent, ASN1_PCTX *pctx); -\& int EVP_PKEY_print_params_fp(FILE *fp, const EVP_PKEY *pkey, -\& int indent, ASN1_PCTX *pctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions \fBEVP_PKEY_print_public()\fR, \fBEVP_PKEY_print_private()\fR and -\&\fBEVP_PKEY_print_params()\fR print out the public, private or parameter components -of key \fIpkey\fR respectively. The key is sent to \fB\s-1BIO\s0\fR \fIout\fR in human readable -form. The parameter \fIindent\fR indicates how far the printout should be indented. -.PP -The \fIpctx\fR parameter allows the print output to be finely tuned by using -\&\s-1ASN1\s0 printing options. If \fIpctx\fR is set to \s-1NULL\s0 then default values will -be used. -.PP -The functions \fBEVP_PKEY_print_public_fp()\fR, \fBEVP_PKEY_print_private_fp()\fR and -\&\fBEVP_PKEY_print_params_fp()\fR do the same as the \fB\s-1BIO\s0\fR based functions -but use \fB\s-1FILE\s0\fR \fIfp\fR instead. -.SH "NOTES" -.IX Header "NOTES" -Currently no public key algorithms include any options in the \fIpctx\fR parameter. -.PP -If the key does not include all the components indicated by the function then -only those contained in the key will be printed. For example passing a public -key to \fBEVP_PKEY_print_private()\fR will only print the public components. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions all return 1 for success and 0 or a negative value for failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_keygen\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBEVP_PKEY_print_public()\fR, \fBEVP_PKEY_print_private()\fR, -and \fBEVP_PKEY_print_params()\fR were added in OpenSSL 1.0.0. -.PP -The functions \fBEVP_PKEY_print_public_fp()\fR, \fBEVP_PKEY_print_private_fp()\fR, -and \fBEVP_PKEY_print_params_fp()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_print_private_fp.3ossl b/openssl-install/share/man/man3/EVP_PKEY_print_private_fp.3ossl deleted file mode 120000 index 9a16d2ff..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_print_private_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_print_private.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_print_public.3ossl b/openssl-install/share/man/man3/EVP_PKEY_print_public.3ossl deleted file mode 120000 index 9a16d2ff..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_print_public.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_print_private.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_print_public_fp.3ossl b/openssl-install/share/man/man3/EVP_PKEY_print_public_fp.3ossl deleted file mode 120000 index 9a16d2ff..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_print_public_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_print_private.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_private_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_private_check.3ossl deleted file mode 120000 index 45eb2158..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_private_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_check.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_public_check.3ossl b/openssl-install/share/man/man3/EVP_PKEY_public_check.3ossl deleted file mode 120000 index 45eb2158..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_public_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_check.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_public_check_quick.3ossl b/openssl-install/share/man/man3/EVP_PKEY_public_check_quick.3ossl deleted file mode 120000 index 45eb2158..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_public_check_quick.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_check.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_security_bits.3ossl b/openssl-install/share/man/man3/EVP_PKEY_security_bits.3ossl deleted file mode 120000 index 16e1e92b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_security_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set1_DH.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set1_DH.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set1_DH.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set1_DSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set1_DSA.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set1_DSA.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set1_EC_KEY.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set1_EC_KEY.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set1_EC_KEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set1_RSA.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set1_RSA.3ossl deleted file mode 100644 index 39fa4943..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set1_RSA.3ossl +++ /dev/null @@ -1,369 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_SET1_RSA 3ossl" -.TH EVP_PKEY_SET1_RSA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_set1_RSA, EVP_PKEY_set1_DSA, EVP_PKEY_set1_DH, EVP_PKEY_set1_EC_KEY, -EVP_PKEY_get1_RSA, EVP_PKEY_get1_DSA, EVP_PKEY_get1_DH, EVP_PKEY_get1_EC_KEY, -EVP_PKEY_get0_RSA, EVP_PKEY_get0_DSA, EVP_PKEY_get0_DH, EVP_PKEY_get0_EC_KEY, -EVP_PKEY_assign_RSA, EVP_PKEY_assign_DSA, EVP_PKEY_assign_DH, -EVP_PKEY_assign_EC_KEY, EVP_PKEY_assign_POLY1305, EVP_PKEY_assign_SIPHASH, -EVP_PKEY_get0_hmac, EVP_PKEY_get0_poly1305, EVP_PKEY_get0_siphash, -EVP_PKEY_get0, EVP_PKEY_type, EVP_PKEY_get_id, EVP_PKEY_get_base_id, -EVP_PKEY_set1_engine, EVP_PKEY_get0_engine, -EVP_PKEY_id, EVP_PKEY_base_id \- -EVP_PKEY assignment functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_get_id(const EVP_PKEY *pkey); -\& int EVP_PKEY_get_base_id(const EVP_PKEY *pkey); -\& int EVP_PKEY_type(int type); -\& -\& #define EVP_PKEY_id EVP_PKEY_get_id -\& #define EVP_PKEY_base_id EVP_PKEY_get_base_id -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& int EVP_PKEY_set1_RSA(EVP_PKEY *pkey, RSA *key); -\& int EVP_PKEY_set1_DSA(EVP_PKEY *pkey, DSA *key); -\& int EVP_PKEY_set1_DH(EVP_PKEY *pkey, DH *key); -\& int EVP_PKEY_set1_EC_KEY(EVP_PKEY *pkey, EC_KEY *key); -\& -\& RSA *EVP_PKEY_get1_RSA(EVP_PKEY *pkey); -\& DSA *EVP_PKEY_get1_DSA(EVP_PKEY *pkey); -\& DH *EVP_PKEY_get1_DH(EVP_PKEY *pkey); -\& EC_KEY *EVP_PKEY_get1_EC_KEY(EVP_PKEY *pkey); -\& -\& const unsigned char *EVP_PKEY_get0_hmac(const EVP_PKEY *pkey, size_t *len); -\& const unsigned char *EVP_PKEY_get0_poly1305(const EVP_PKEY *pkey, size_t *len); -\& const unsigned char *EVP_PKEY_get0_siphash(const EVP_PKEY *pkey, size_t *len); -\& const RSA *EVP_PKEY_get0_RSA(const EVP_PKEY *pkey); -\& const DSA *EVP_PKEY_get0_DSA(const EVP_PKEY *pkey); -\& const DH *EVP_PKEY_get0_DH(const EVP_PKEY *pkey); -\& const EC_KEY *EVP_PKEY_get0_EC_KEY(const EVP_PKEY *pkey); -\& void *EVP_PKEY_get0(const EVP_PKEY *pkey); -\& -\& int EVP_PKEY_assign_RSA(EVP_PKEY *pkey, RSA *key); -\& int EVP_PKEY_assign_DSA(EVP_PKEY *pkey, DSA *key); -\& int EVP_PKEY_assign_DH(EVP_PKEY *pkey, DH *key); -\& int EVP_PKEY_assign_EC_KEY(EVP_PKEY *pkey, EC_KEY *key); -\& int EVP_PKEY_assign_POLY1305(EVP_PKEY *pkey, ASN1_OCTET_STRING *key); -\& int EVP_PKEY_assign_SIPHASH(EVP_PKEY *pkey, ASN1_OCTET_STRING *key); -\& -\& ENGINE *EVP_PKEY_get0_engine(const EVP_PKEY *pkey); -\& int EVP_PKEY_set1_engine(EVP_PKEY *pkey, ENGINE *engine); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_get_base_id()\fR returns the type of \fIpkey\fR. For example -an \s-1RSA\s0 key will return \fB\s-1EVP_PKEY_RSA\s0\fR. -.PP -\&\fBEVP_PKEY_get_id()\fR returns the actual \s-1NID\s0 associated with \fIpkey\fR -only if the \fIpkey\fR type isn't implemented just in a \fBprovider\fR\|(7). -Historically keys using the same algorithm could use different NIDs. -For example an \s-1RSA\s0 key could use the NIDs corresponding to -the NIDs \fBNID_rsaEncryption\fR (equivalent to \fB\s-1EVP_PKEY_RSA\s0\fR) or -\&\fBNID_rsa\fR (equivalent to \fB\s-1EVP_PKEY_RSA2\s0\fR). The use of -alternative non-standard NIDs is now rare so \fB\s-1EVP_PKEY_RSA2\s0\fR et al are not -often seen in practice. -\&\fBEVP_PKEY_get_id()\fR returns \-1 (\fB\s-1EVP_PKEY_KEYMGMT\s0\fR) if the \fIpkey\fR is -only implemented in a \fBprovider\fR\|(7). -.PP -\&\fBEVP_PKEY_type()\fR returns the underlying type of the \s-1NID\s0 \fItype\fR. For example -EVP_PKEY_type(\s-1EVP_PKEY_RSA2\s0) will return \fB\s-1EVP_PKEY_RSA\s0\fR. -.PP -\&\fBEVP_PKEY_set1_RSA()\fR, \fBEVP_PKEY_set1_DSA()\fR, \fBEVP_PKEY_set1_DH()\fR and -\&\fBEVP_PKEY_set1_EC_KEY()\fR set the key referenced by \fIpkey\fR to \fIkey\fR. These -functions are deprecated. Applications should instead use -\&\fBEVP_PKEY_fromdata\fR\|(3). -.PP -\&\fBEVP_PKEY_assign_RSA()\fR, \fBEVP_PKEY_assign_DSA()\fR, \fBEVP_PKEY_assign_DH()\fR, -\&\fBEVP_PKEY_assign_EC_KEY()\fR, \fBEVP_PKEY_assign_POLY1305()\fR and -\&\fBEVP_PKEY_assign_SIPHASH()\fR set the referenced key to \fIkey\fR however these use -the supplied \fIkey\fR internally and so \fIkey\fR will be freed when the parent -\&\fIpkey\fR is freed. These macros are deprecated. Applications should instead read -an \s-1EVP_PKEY\s0 directly using the \s-1OSSL_DECODER\s0 APIs (see -\&\fBOSSL_DECODER_CTX_new_for_pkey\fR\|(3)), or construct an \s-1EVP_PKEY\s0 from data using -\&\fBEVP_PKEY_fromdata\fR\|(3). -.PP -\&\fBEVP_PKEY_get1_RSA()\fR, \fBEVP_PKEY_get1_DSA()\fR, \fBEVP_PKEY_get1_DH()\fR and -\&\fBEVP_PKEY_get1_EC_KEY()\fR return the referenced key in \fIpkey\fR or \s-1NULL\s0 if the -key is not of the correct type. The returned key must be freed after use. -These functions are deprecated. Applications should instead use the \s-1EVP_PKEY\s0 -directly where possible. If access to the low level key parameters is required -then applications should use \fBEVP_PKEY_get_params\fR\|(3) and other similar -functions. To write an \s-1EVP_PKEY\s0 out use the \s-1OSSL_ENCODER\s0 APIs (see -\&\fBOSSL_ENCODER_CTX_new_for_pkey\fR\|(3)). -.PP -\&\fBEVP_PKEY_get0_hmac()\fR, \fBEVP_PKEY_get0_poly1305()\fR, \fBEVP_PKEY_get0_siphash()\fR, -\&\fBEVP_PKEY_get0_RSA()\fR, \fBEVP_PKEY_get0_DSA()\fR, \fBEVP_PKEY_get0_DH()\fR and -\&\fBEVP_PKEY_get0_EC_KEY()\fR return the referenced key in \fIpkey\fR or \s-1NULL\s0 if the -key is not of the correct type. The reference count of the returned key is -\&\fBnot\fR incremented and so the key must not be freed after use. These functions -are deprecated. Applications should instead use the \s-1EVP_PKEY\s0 directly where -possible. If access to the low level key parameters is required then -applications should use \fBEVP_PKEY_get_params\fR\|(3) and other similar functions. -To write an \s-1EVP_PKEY\s0 out use the \s-1OSSL_ENCODER\s0 APIs (see -\&\fBOSSL_ENCODER_CTX_new_for_pkey\fR\|(3)). \fBEVP_PKEY_get0()\fR returns a pointer to the -legacy key or \s-1NULL\s0 if the key is not legacy. -.PP -Note that if an \s-1EVP_PKEY\s0 was not constructed using one of the deprecated -functions such as \fBEVP_PKEY_set1_RSA()\fR, \fBEVP_PKEY_set1_DSA()\fR, \fBEVP_PKEY_set1_DH()\fR -or \fBEVP_PKEY_set1_EC_KEY()\fR, or via the similarly named \fBEVP_PKEY_assign\fR macros -described above then the internal key will be managed by a provider (see -\&\fBprovider\fR\|(7)). In that case the key returned by \fBEVP_PKEY_get1_RSA()\fR, -\&\fBEVP_PKEY_get1_DSA()\fR, \fBEVP_PKEY_get1_DH()\fR, \fBEVP_PKEY_get1_EC_KEY()\fR, -\&\fBEVP_PKEY_get0_hmac()\fR, \fBEVP_PKEY_get0_poly1305()\fR, \fBEVP_PKEY_get0_siphash()\fR, -\&\fBEVP_PKEY_get0_RSA()\fR, \fBEVP_PKEY_get0_DSA()\fR, \fBEVP_PKEY_get0_DH()\fR or -\&\fBEVP_PKEY_get0_EC_KEY()\fR will be a cached copy of the provider's key. Subsequent -updates to the provider's key will not be reflected back in the cached copy, and -updates made by an application to the returned key will not be reflected back in -the provider's key. Subsequent calls to \fBEVP_PKEY_get1_RSA()\fR, -\&\fBEVP_PKEY_get1_DSA()\fR, \fBEVP_PKEY_get1_DH()\fR and \fBEVP_PKEY_get1_EC_KEY()\fR will always -return the cached copy returned by the first call. -.PP -\&\fBEVP_PKEY_get0_engine()\fR returns a reference to the \s-1ENGINE\s0 handling \fIpkey\fR. This -function is deprecated. Applications should use providers instead of engines -(see \fBprovider\fR\|(7) for details). -.PP -\&\fBEVP_PKEY_set1_engine()\fR sets the \s-1ENGINE\s0 handling \fIpkey\fR to \fIengine\fR. It -must be called after the key algorithm and components are set up. -If \fIengine\fR does not include an \fB\s-1EVP_PKEY_METHOD\s0\fR for \fIpkey\fR an -error occurs. This function is deprecated. Applications should use providers -instead of engines (see \fBprovider\fR\|(7) for details). -.SH "WARNINGS" -.IX Header "WARNINGS" -The following functions are only reliable with \fB\s-1EVP_PKEY\s0\fRs that have -been assigned an internal key with EVP_PKEY_assign_*(): -.PP -\&\fBEVP_PKEY_get_id()\fR, \fBEVP_PKEY_get_base_id()\fR, \fBEVP_PKEY_type()\fR -.PP -For \s-1EVP_PKEY\s0 key type checking purposes, \fBEVP_PKEY_is_a\fR\|(3) is more generic. -.PP -For purposes of retrieving the name of the \fB\s-1EVP_PKEY\s0\fR the function -\&\fBEVP_PKEY_get0_type_name\fR\|(3) is more generally useful. -.PP -The keys returned from the functions \fBEVP_PKEY_get0_RSA()\fR, \fBEVP_PKEY_get0_DSA()\fR, -\&\fBEVP_PKEY_get0_DH()\fR and \fBEVP_PKEY_get0_EC_KEY()\fR were changed to have a \*(L"const\*(R" -return type in OpenSSL 3.0. As described above the keys returned may be cached -copies of the key held in a provider. Due to this, and unlike in earlier -versions of OpenSSL, they should be considered read-only copies of the key. -Updates to these keys will not be reflected back in the provider side key. The -\&\fBEVP_PKEY_get1_RSA()\fR, \fBEVP_PKEY_get1_DSA()\fR, \fBEVP_PKEY_get1_DH()\fR and -\&\fBEVP_PKEY_get1_EC_KEY()\fR functions were not changed to have a \*(L"const\*(R" return type -in order that applications can \*(L"free\*(R" the return value. However applications -should still consider them as read-only copies. -.SH "NOTES" -.IX Header "NOTES" -In accordance with the OpenSSL naming convention the key obtained -from or assigned to the \fIpkey\fR using the \fB1\fR functions must be -freed as well as \fIpkey\fR. -.PP -\&\fBEVP_PKEY_assign_RSA()\fR, \fBEVP_PKEY_assign_DSA()\fR, \fBEVP_PKEY_assign_DH()\fR, -\&\fBEVP_PKEY_assign_EC_KEY()\fR, \fBEVP_PKEY_assign_POLY1305()\fR -and \fBEVP_PKEY_assign_SIPHASH()\fR are implemented as macros. -.PP -\&\fBEVP_PKEY_assign_EC_KEY()\fR looks at the curve name id to determine if -the passed \fB\s-1EC_KEY\s0\fR is an \s-1\fBSM2\s0\fR\|(7) key, and will set the \fB\s-1EVP_PKEY\s0\fR -type to \fB\s-1EVP_PKEY_SM2\s0\fR in that case, instead of \fB\s-1EVP_PKEY_EC\s0\fR. -.PP -Most applications wishing to know a key type will simply call -\&\fBEVP_PKEY_get_base_id()\fR and will not care about the actual type: -which will be identical in almost all cases. -.PP -Previous versions of this document suggested using EVP_PKEY_type(pkey\->type) -to determine the type of a key. Since \fB\s-1EVP_PKEY\s0\fR is now opaque this -is no longer possible: the equivalent is EVP_PKEY_get_base_id(pkey). -.PP -\&\fBEVP_PKEY_set1_engine()\fR is typically used by an \s-1ENGINE\s0 returning an \s-1HSM\s0 -key as part of its routine to load a private key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_set1_RSA()\fR, \fBEVP_PKEY_set1_DSA()\fR, \fBEVP_PKEY_set1_DH()\fR and -\&\fBEVP_PKEY_set1_EC_KEY()\fR return 1 for success or 0 for failure. -.PP -\&\fBEVP_PKEY_get1_RSA()\fR, \fBEVP_PKEY_get1_DSA()\fR, \fBEVP_PKEY_get1_DH()\fR and -\&\fBEVP_PKEY_get1_EC_KEY()\fR return the referenced key or \s-1NULL\s0 if -an error occurred. -.PP -\&\fBEVP_PKEY_assign_RSA()\fR, \fBEVP_PKEY_assign_DSA()\fR, \fBEVP_PKEY_assign_DH()\fR, -\&\fBEVP_PKEY_assign_EC_KEY()\fR, \fBEVP_PKEY_assign_POLY1305()\fR -and \fBEVP_PKEY_assign_SIPHASH()\fR return 1 for success and 0 for failure. -.PP -\&\fBEVP_PKEY_get_base_id()\fR, \fBEVP_PKEY_get_id()\fR and \fBEVP_PKEY_type()\fR return a key -type or \fBNID_undef\fR (equivalently \fB\s-1EVP_PKEY_NONE\s0\fR) on error. -.PP -\&\fBEVP_PKEY_set1_engine()\fR returns 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_new\fR\|(3), \s-1\fBSM2\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_id()\fR and \fBEVP_PKEY_base_id()\fR functions were renamed to -include \f(CW\*(C`get\*(C'\fR in their names in OpenSSL 3.0, respectively. The old names -are kept as non-deprecated alias macros. -.PP -EVP_PKEY_set1_RSA, EVP_PKEY_set1_DSA, EVP_PKEY_set1_DH, EVP_PKEY_set1_EC_KEY, -EVP_PKEY_get1_RSA, EVP_PKEY_get1_DSA, EVP_PKEY_get1_DH, EVP_PKEY_get1_EC_KEY, -EVP_PKEY_get0_RSA, EVP_PKEY_get0_DSA, EVP_PKEY_get0_DH, EVP_PKEY_get0_EC_KEY, -EVP_PKEY_assign_RSA, EVP_PKEY_assign_DSA, EVP_PKEY_assign_DH, -EVP_PKEY_assign_EC_KEY, EVP_PKEY_assign_POLY1305, EVP_PKEY_assign_SIPHASH, -EVP_PKEY_get0_hmac, EVP_PKEY_get0_poly1305, EVP_PKEY_get0_siphash, -EVP_PKEY_set1_engine and EVP_PKEY_get0_engine were deprecated in OpenSSL 3.0. -.PP -The return value from EVP_PKEY_get0_RSA, EVP_PKEY_get0_DSA, EVP_PKEY_get0_DH, -EVP_PKEY_get0_EC_KEY were made const in OpenSSL 3.0. -.PP -The function \fBEVP_PKEY_set_alias_type()\fR was previously documented on this page. -It was removed in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_set1_encoded_public_key.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set1_encoded_public_key.3ossl deleted file mode 100644 index 5e1992da..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set1_encoded_public_key.3ossl +++ /dev/null @@ -1,274 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_SET1_ENCODED_PUBLIC_KEY 3ossl" -.TH EVP_PKEY_SET1_ENCODED_PUBLIC_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_set1_encoded_public_key, EVP_PKEY_get1_encoded_public_key, -EVP_PKEY_set1_tls_encodedpoint, EVP_PKEY_get1_tls_encodedpoint -\&\- functions to set and get public key data within an EVP_PKEY -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_set1_encoded_public_key(EVP_PKEY *pkey, -\& const unsigned char *pub, size_t publen); -\& -\& size_t EVP_PKEY_get1_encoded_public_key(EVP_PKEY *pkey, unsigned char **ppub); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int EVP_PKEY_set1_tls_encodedpoint(EVP_PKEY *pkey, -\& const unsigned char *pt, size_t ptlen); -\& -\& size_t EVP_PKEY_get1_tls_encodedpoint(EVP_PKEY *pkey, unsigned char **ppt); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_set1_encoded_public_key()\fR can be used to set the public key value -within an existing \s-1EVP_PKEY\s0 object. For the built-in OpenSSL algorithms this -currently only works for those that support key exchange. Parameters are not -set as part of this operation, so typically an application will create an -\&\s-1EVP_PKEY\s0 first, set the parameters on it, and then call this function. -For example setting the parameters might be done using -\&\fBEVP_PKEY_copy_parameters\fR\|(3). -.PP -The format for the encoded public key will depend on the algorithm in use. For -\&\s-1DH\s0 it should be encoded as a positive integer in big-endian form. For \s-1EC\s0 is -should be a point conforming to Sec. 2.3.4 of the \s-1SECG SEC 1\s0 (\*(L"Elliptic -Curve Cryptography\*(R") standard. For X25519 and X448 it should be encoded in a -format as defined by \s-1RFC7748.\s0 -.PP -The key to be updated is supplied in \fBpkey\fR. The buffer containing the encoded -key is pointed to be \fBpub\fR. The length of the buffer is supplied in \fBpublen\fR. -.PP -\&\fBEVP_PKEY_get1_encoded_public_key()\fR does the equivalent operation except that -the encoded public key is returned to the application. The key containing the -public key data is supplied in \fBpkey\fR. A buffer containing the encoded key will -be allocated and stored in \fB*ppub\fR. The length of the encoded public key is -returned by the function. The application is responsible for freeing the -allocated buffer. -.PP -The macro \fBEVP_PKEY_set1_tls_encodedpoint()\fR is deprecated and simply calls -\&\fBEVP_PKEY_set1_encoded_public_key()\fR with all the same arguments. New applications -should use \fBEVP_PKEY_set1_encoded_public_key()\fR instead. -.PP -The macro \fBEVP_PKEY_get1_tls_encodedpoint()\fR is deprecated and simply calls -\&\fBEVP_PKEY_get1_encoded_public_key()\fR with all the same arguments. New applications -should use \fBEVP_PKEY_get1_encoded_public_key()\fR instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_set1_encoded_public_key()\fR returns 1 for success and 0 or a negative -value for failure. -.PP -\&\fBEVP_PKEY_get1_encoded_public_key()\fR returns the length of the encoded key or 0 for failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -See \fBEVP_PKEY_derive_init\fR\|(3) and \fBEVP_PKEY_derive\fR\|(3) for information about -performing a key exchange operation. -.SS "Set up a peer's \s-1EVP_PKEY\s0 ready for a key exchange operation" -.IX Subsection "Set up a peer's EVP_PKEY ready for a key exchange operation" -.Vb 1 -\& #include -\& -\& int exchange(EVP_PKEY *ourkey, unsigned char *peer_pub, size_t peer_pub_len) -\& { -\& EVP_PKEY *peerkey = EVP_PKEY_new(); -\& -\& if (peerkey == NULL || EVP_PKEY_copy_parameters(peerkey, ourkey) <= 0) -\& return 0; -\& -\& if (EVP_PKEY_set1_encoded_public_key(peerkey, peer_pub, -\& peer_pub_len) <= 0) -\& return 0; -\& -\& /* Do the key exchange here */ -\& -\& EVP_PKEY_free(peerkey); -\& -\& return 1; -\& } -.Ve -.SS "Get an encoded public key to send to a peer" -.IX Subsection "Get an encoded public key to send to a peer" -.Vb 1 -\& #include -\& -\& int get_encoded_pub_key(EVP_PKEY *ourkey) -\& { -\& unsigned char *pubkey; -\& size_t pubkey_len; -\& -\& pubkey_len = EVP_PKEY_get1_encoded_public_key(ourkey, &pubkey); -\& if (pubkey_len == 0) -\& return 0; -\& -\& /* -\& * Send the encoded public key stored in the buffer at "pubkey" and of -\& * length pubkey_len, to the peer. -\& */ -\& -\& OPENSSL_free(pubkey); -\& return 1; -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_new\fR\|(3), \fBEVP_PKEY_copy_parameters\fR\|(3), -\&\fBEVP_PKEY_derive_init\fR\|(3), \fBEVP_PKEY_derive\fR\|(3), -\&\s-1\fBEVP_PKEY\-DH\s0\fR\|(7), \s-1\fBEVP_PKEY\-EC\s0\fR\|(7), \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7), \s-1\fBEVP_PKEY\-X448\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_PKEY_set1_encoded_public_key()\fR and \fBEVP_PKEY_get1_encoded_public_key()\fR were -added in OpenSSL 3.0. -.PP -\&\fBEVP_PKEY_set1_tls_encodedpoint()\fR and \fBEVP_PKEY_get1_tls_encodedpoint()\fR were -deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_set1_engine.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set1_engine.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set1_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set1_tls_encodedpoint.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set1_tls_encodedpoint.3ossl deleted file mode 120000 index ac899e51..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set1_tls_encodedpoint.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_encoded_public_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_bn_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_bn_param.3ossl deleted file mode 120000 index 14dc8464..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_bn_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_settable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_ex_data.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_int_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_int_param.3ossl deleted file mode 120000 index 14dc8464..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_int_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_settable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_octet_string_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_octet_string_param.3ossl deleted file mode 120000 index 14dc8464..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_octet_string_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_settable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_params.3ossl deleted file mode 120000 index 14dc8464..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_settable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_size_t_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_size_t_param.3ossl deleted file mode 120000 index 14dc8464..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_size_t_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_settable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_type.3ossl deleted file mode 100644 index 21f996f3..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_type.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_SET_TYPE 3ossl" -.TH EVP_PKEY_SET_TYPE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_set_type, EVP_PKEY_set_type_str, EVP_PKEY_set_type_by_keymgmt -\&\- functions to change the EVP_PKEY type -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_set_type(EVP_PKEY *pkey, int type); -\& int EVP_PKEY_set_type_str(EVP_PKEY *pkey, const char *str, int len); -\& int EVP_PKEY_set_type_by_keymgmt(EVP_PKEY *pkey, EVP_KEYMGMT *keymgmt); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All the functions described here behave the same in so far that they -clear all the previous key data and methods from \fIpkey\fR, and reset it -to be of the type of key given by the different arguments. If -\&\fIpkey\fR is \s-1NULL,\s0 these functions will still return the same return -values as if it wasn't. -.PP -\&\fBEVP_PKEY_set_type()\fR initialises \fIpkey\fR to contain an internal legacy -key. When doing this, it finds a \s-1\fBEVP_PKEY_ASN1_METHOD\s0\fR\|(3) -corresponding to \fItype\fR, and associates \fIpkey\fR with the findings. -It is an error if no \s-1\fBEVP_PKEY_ASN1_METHOD\s0\fR\|(3) could be found for -\&\fItype\fR. -.PP -\&\fBEVP_PKEY_set_type_str()\fR initialises \fIpkey\fR to contain an internal legacy -key. When doing this, it finds a \s-1\fBEVP_PKEY_ASN1_METHOD\s0\fR\|(3) -corresponding to \fIstr\fR that has then length \fIlen\fR, and associates -\&\fIpkey\fR with the findings. -It is an error if no \s-1\fBEVP_PKEY_ASN1_METHOD\s0\fR\|(3) could be found for -\&\fItype\fR. -.PP -For both \fBEVP_PKEY_set_type()\fR and \fBEVP_PKEY_set_type_str()\fR, \fIpkey\fR gets -a numeric type, which can be retrieved with \fBEVP_PKEY_get_id\fR\|(3). This -numeric type is taken from the \s-1\fBEVP_PKEY_ASN1_METHOD\s0\fR\|(3) that was -found, and is equal to or closely related to \fItype\fR in the case of -\&\fBEVP_PKEY_set_type()\fR, or related to \fIstr\fR in the case of -\&\fBEVP_PKEY_set_type_str()\fR. -.PP -\&\fBEVP_PKEY_set_type_by_keymgmt()\fR initialises \fIpkey\fR to contain an -internal provider side key. When doing this, it associates \fIpkey\fR -with \fIkeymgmt\fR. For keys initialised like this, the numeric type -retrieved with \fBEVP_PKEY_get_id\fR\|(3) will always be \fB\s-1EVP_PKEY_NONE\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions described here return 1 if successful, or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_assign\fR\|(3), \fBEVP_PKEY_get_id\fR\|(3), \fBEVP_PKEY_get0_RSA\fR\|(3), -\&\fBEVP_PKEY_copy_parameters\fR\|(3), \s-1\fBEVP_PKEY_ASN1_METHOD\s0\fR\|(3), -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_type_by_keymgmt.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_type_by_keymgmt.3ossl deleted file mode 120000 index 286e6e47..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_type_by_keymgmt.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_type_str.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_type_str.3ossl deleted file mode 120000 index 286e6e47..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_type_str.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_set_utf8_string_param.3ossl b/openssl-install/share/man/man3/EVP_PKEY_set_utf8_string_param.3ossl deleted file mode 120000 index 14dc8464..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_set_utf8_string_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_settable_params.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_settable_params.3ossl b/openssl-install/share/man/man3/EVP_PKEY_settable_params.3ossl deleted file mode 100644 index ab970d81..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_settable_params.3ossl +++ /dev/null @@ -1,211 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_SETTABLE_PARAMS 3ossl" -.TH EVP_PKEY_SETTABLE_PARAMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_settable_params, EVP_PKEY_set_params, -EVP_PKEY_set_int_param, EVP_PKEY_set_size_t_param, EVP_PKEY_set_bn_param, -EVP_PKEY_set_utf8_string_param, EVP_PKEY_set_octet_string_param -\&\- set key parameters into a key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const OSSL_PARAM *EVP_PKEY_settable_params(const EVP_PKEY *pkey); -\& int EVP_PKEY_set_params(EVP_PKEY *pkey, OSSL_PARAM params[]); -\& int EVP_PKEY_set_int_param(EVP_PKEY *pkey, const char *key_name, int in); -\& int EVP_PKEY_set_size_t_param(EVP_PKEY *pkey, const char *key_name, size_t in); -\& int EVP_PKEY_set_bn_param(EVP_PKEY *pkey, const char *key_name, -\& const BIGNUM *bn); -\& int EVP_PKEY_set_utf8_string_param(EVP_PKEY *pkey, const char *key_name, -\& const char *str); -\& int EVP_PKEY_set_octet_string_param(EVP_PKEY *pkey, const char *key_name, -\& const unsigned char *buf, size_t bsize); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions can be used to set additional parameters into an existing -\&\fB\s-1EVP_PKEY\s0\fR. -.PP -\&\fBEVP_PKEY_set_params()\fR sets one or more \fIparams\fR into a \fIpkey\fR. -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for information about parameters. -.PP -\&\fBEVP_PKEY_settable_params()\fR returns a constant list of \fIparams\fR indicating -the names and types of key parameters that can be set. -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for information about parameters. -.PP -\&\fBEVP_PKEY_set_int_param()\fR sets an integer value \fIin\fR into a key \fIpkey\fR for the -associated field \fIkey_name\fR. -.PP -\&\fBEVP_PKEY_set_size_t_param()\fR sets an size_t value \fIin\fR into a key \fIpkey\fR for -the associated field \fIkey_name\fR. -.PP -\&\fBEVP_PKEY_set_bn_param()\fR sets the \s-1BIGNUM\s0 value \fIbn\fR into a key \fIpkey\fR for the -associated field \fIkey_name\fR. -.PP -\&\fBEVP_PKEY_set_utf8_string_param()\fR sets the \s-1UTF8\s0 string \fIstr\fR into a key \fIpkey\fR -for the associated field \fIkey_name\fR. -.PP -\&\fBEVP_PKEY_set_octet_string_param()\fR sets the octet string value \fIbuf\fR with a -size \fIbsize\fR into a key \fIpkey\fR for the associated field \fIkey_name\fR. -.SH "NOTES" -.IX Header "NOTES" -These functions only work for \fB\s-1EVP_PKEY\s0\fRs that contain a provider side key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_settable_params()\fR returns \s-1NULL\s0 on error or if it is not supported, -.PP -All other methods return 1 if a value was successfully set, or 0 if -there was an error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_gettable_params\fR\|(3), -\&\fBEVP_PKEY_CTX_new\fR\|(3), \fBprovider\-keymgmt\fR\|(7), \s-1\fBOSSL_PARAM\s0\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_sign.3ossl b/openssl-install/share/man/man3/EVP_PKEY_sign.3ossl deleted file mode 100644 index 014fa060..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_sign.3ossl +++ /dev/null @@ -1,484 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_SIGN 3ossl" -.TH EVP_PKEY_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_sign_init, EVP_PKEY_sign_init_ex, EVP_PKEY_sign_init_ex2, -EVP_PKEY_sign, EVP_PKEY_sign_message_init, EVP_PKEY_sign_message_update, -EVP_PKEY_sign_message_final \- sign using a public key algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_sign_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_sign_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_PKEY_sign_init_ex2(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_sign_message_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_sign_message_update(EVP_PKEY_CTX *ctx, -\& unsigned char *in, size_t inlen); -\& int EVP_PKEY_sign_message_final(EVP_PKEY_CTX *ctx, unsigned char *sig, -\& size_t *siglen, size_t sigsize); -\& int EVP_PKEY_sign(EVP_PKEY_CTX *ctx, -\& unsigned char *sig, size_t *siglen, -\& const unsigned char *tbs, size_t tbslen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_sign_init()\fR initializes a public key algorithm context \fIctx\fR for -signing using the algorithm given when the context was created -using \fBEVP_PKEY_CTX_new\fR\|(3) or variants thereof. The algorithm is used to -fetch a \fB\s-1EVP_SIGNATURE\s0\fR method implicitly, see \*(L"Implicit fetch\*(R" in \fBprovider\fR\|(7) -for more information about implicit fetches. -.PP -\&\fBEVP_PKEY_sign_init_ex()\fR is the same as \fBEVP_PKEY_sign_init()\fR but additionally -sets the passed parameters \fIparams\fR on the context before returning. -.PP -\&\fBEVP_PKEY_sign_init_ex2()\fR initializes a public key algorithm context \fIctx\fR for -signing a pre-computed message digest using the algorithm given by \fIalgo\fR and -the key given through \fBEVP_PKEY_CTX_new\fR\|(3) or \fBEVP_PKEY_CTX_new_from_pkey\fR\|(3). -A context \fIctx\fR without a pre-loaded key cannot be used with this function. -This function provides almost the same functionality as \fBEVP_PKEY_sign_init_ex()\fR, -but is uniquely intended to be used with a pre-computed messsage digest, and -allows pre-determining the exact conditions for that message digest, if a -composite signature algorithm (such as \s-1RSA\-SHA256\s0) was fetched. -Following a call to this function, setting parameters that modifies the digest -implementation or padding is not normally supported. -.PP -\&\fBEVP_PKEY_sign_message_init()\fR initializes a public key algorithm context \fIctx\fR -for signing an unlimited size message using the algorithm given by \fIalgo\fR and -the key given through \fBEVP_PKEY_CTX_new\fR\|(3) or \fBEVP_PKEY_CTX_new_from_pkey\fR\|(3). -Passing the message is supported both in a one-shot fashion using -\&\fBEVP_PKEY_sign()\fR, and through the combination of \fBEVP_PKEY_sign_message_update()\fR -and \fBEVP_PKEY_sign_message_final()\fR. -This function enables using algorithms that can process input of arbitrary -length, such as \s-1ED25519, RSA\-SHA256\s0 and similar. -.PP -\&\fBEVP_PKEY_sign_message_update()\fR adds \fIinlen\fR bytes from \fIin\fR to the data to be -processed for signature. The signature algorithm specification and -implementation determine how the input bytes are processed and if there's a -limit on the total size of the input. See \*(L"\s-1NOTES\*(R"\s0 below for a deeper -explanation. -.PP -\&\fBEVP_PKEY_sign_message_final()\fR signs the processed data and places the data in -\&\fIsig\fR, and the number of signature bytes in \fI*siglen\fR, if the number of -bytes doesn't surpass the size given by \fIsigsize\fR. -\&\fIsig\fR may be \s-1NULL,\s0 and in that case, only \fI*siglen\fR is updated with the -number of signature bytes. -.PP -\&\fBEVP_PKEY_sign()\fR is a one-shot function that can be used with all the init -functions above. -When initialization was done with \fBEVP_PKEY_sign_init()\fR, \fBEVP_PKEY_sign_init_ex()\fR -or \fBEVP_PKEY_sign_init_ex2()\fR, the data specified by \fItbs\fR and \fItbslen\fR is -signed after appropriate padding. -When initialization was done with \fBEVP_PKEY_sign_message_init()\fR, the data -specified by \fItbs\fR and \fItbslen\fR is digested by the implied message digest -algorithm, and the result is signed after appropriate padding. -If \fIsig\fR is \s-1NULL\s0 then the maximum size of the output buffer is written to the -\&\fIsiglen\fR parameter. -If \fIsig\fR is not \s-1NULL,\s0 then before the call the \fIsiglen\fR parameter should -contain the length of the \fIsig\fR buffer, and if the call is successful the -signature is written to \fIsig\fR and the amount of data written to \fIsiglen\fR. -.SH "NOTES" -.IX Header "NOTES" -.SS "General" -.IX Subsection "General" -Some signature implementations only accumulate the input data and do no -further processing before signing it (they expect the input to be a digest), -while others compress the data, typically by internally producing a digest, -and signing the result. -Some of them support both modes of operation at the same time. -The caller is expected to know how the chosen algorithm is supposed to behave -and under what conditions. -.PP -For example, an \s-1RSA\s0 implementation can be expected to only expect a message -digest as input, while \s-1ED25519\s0 can be expected to process the input with a hash, -i.e. to produce the message digest internally, and while \s-1RSA\-SHA256\s0 can be -expected to handle either mode of operation, depending on if the operation was -initialized with \fBEVP_PKEY_sign_init_ex2()\fR or with \fBEVP_PKEY_sign_message_init()\fR. -.PP -Similarly, an \s-1RSA\s0 implementation usually expects additional details to be set, -like the message digest algorithm that the input is supposed to be digested -with, as well as the padding mode (see \fBEVP_PKEY_CTX_set_signature_md\fR\|(3) and -\&\fBEVP_PKEY_CTX_set_rsa_padding\fR\|(3) and similar others), while an \s-1RSA\-SHA256\s0 -implementation usually has these details pre-set and immutable. -.PP -The functions described here can't be used to combine separate algorithms. In -particular, neither \fBEVP_PKEY_CTX_set_signature_md\fR\|(3) nor the \fB\s-1OSSL_PARAM\s0\fR -parameter \*(L"digest\*(R" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) can be used to combine a -signature algorithm with a hash algorithm to process the input. In other -words, it's not possible to specify a \fIctx\fR pre-loaded with an \s-1RSA\s0 pkey, or -an \fIalgo\fR that fetched \f(CW\*(C`RSA\*(C'\fR and try to specify \s-1SHA256\s0 separately to get the -functionality of \s-1RSA\-SHA256.\s0 If combining algorithms in that manner is -desired, please use \fBEVP_DigestSignInit\fR\|(3) and associated functions. -.SS "Performing multiple signatures" -.IX Subsection "Performing multiple signatures" -When initialized using \fBEVP_PKEY_sign_init_ex()\fR or \fBEVP_PKEY_sign_init_ex2()\fR, -\&\fBEVP_PKEY_sign()\fR can be called more than once on the same context to have -several one-shot operations performed using the same parameters. -.PP -When initialized using \fBEVP_PKEY_sign_message_init()\fR, it's not possible to -call \fBEVP_PKEY_sign()\fR multiple times. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return 1 for success and 0 or a negative value for failure. -.PP -In particular, \fBEVP_PKEY_sign_init()\fR and its other variants may return \-2 to -indicate that the operation is not supported by the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.SS "\s-1RSA\s0 with PKCS#1 padding for \s-1SHA256\s0" -.IX Subsection "RSA with PKCS#1 padding for SHA256" -Sign data using \s-1RSA\s0 with PKCS#1 padding and a \s-1SHA256\s0 digest as input: -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& /* md is a SHA\-256 digest in this example. */ -\& unsigned char *md, *sig; -\& size_t mdlen = 32, siglen; -\& EVP_PKEY *signing_key; -\& -\& /* -\& * NB: assumes signing_key and md are set up before the next -\& * step. signing_key must be an RSA private key and md must -\& * point to the SHA\-256 digest to be signed. -\& */ -\& ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */); -\& if (ctx == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_sign_init(ctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_PADDING) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_signature_md(ctx, EVP_sha256()) <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_sign(ctx, NULL, &siglen, md, mdlen) <= 0) -\& /* Error */ -\& -\& sig = OPENSSL_malloc(siglen); -\& -\& if (sig == NULL) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_sign(ctx, sig, &siglen, md, mdlen) <= 0) -\& /* Error */ -\& -\& /* Signature is siglen bytes written to buffer sig */ -.Ve -.SS "\s-1RSA\-SHA256\s0 with a pre-computed digest" -.IX Subsection "RSA-SHA256 with a pre-computed digest" -Sign a digest with \s-1RSA\-SHA256\s0 using one-shot functions. To be noted is that -\&\s-1RSA\-SHA256\s0 is assumed to be an implementation of \f(CW\*(C`sha256WithRSAEncryption\*(C'\fR, -for which the padding is pre-determined to be \fB\s-1RSA_PKCS1_PADDING\s0\fR, and the -input digest is assumed to have been computed using \s-1SHA256.\s0 -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& /* md is a SHA\-256 digest in this example. */ -\& unsigned char *md, *sig; -\& size_t mdlen = 32, siglen; -\& EVP_PKEY *signing_key; -\& -\& /* -\& * NB: assumes signing_key and md are set up before the next -\& * step. signing_key must be an RSA private key and md must -\& * point to the SHA\-256 digest to be signed. -\& */ -\& ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */); -\& alg = EVP_SIGNATURE_fetch(NULL, "RSA\-SHA256", NULL); -\& -\& if (ctx == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_sign_init_ex2(ctx, alg, NULL) <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_sign(ctx, NULL, &siglen, md, mdlen) <= 0) -\& /* Error */ -\& -\& sig = OPENSSL_malloc(siglen); -\& -\& if (sig == NULL) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_sign(ctx, sig, &siglen, md, mdlen) <= 0) -\& /* Error */ -\& -\& /* Signature is siglen bytes written to buffer sig */ -.Ve -.SS "\s-1RSA\-SHA256,\s0 one-shot" -.IX Subsection "RSA-SHA256, one-shot" -Sign a document with \s-1RSA\-SHA256\s0 using one-shot functions. -To be noted is that \s-1RSA\-SHA256\s0 is assumed to be an implementation of -\&\f(CW\*(C`sha256WithRSAEncryption\*(C'\fR, for which the padding is pre-determined to be -\&\fB\s-1RSA_PKCS1_PADDING\s0\fR. -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& /* in is the input in this example. */ -\& unsigned char *in, *sig; -\& /* inlen is the length of the input in this example. */ -\& size_t inlen, siglen; -\& EVP_PKEY *signing_key; -\& EVP_SIGNATURE *alg; -\& -\& /* -\& * NB: assumes signing_key, in and inlen are set up before -\& * the next step. signing_key must be an RSA private key, -\& * in must point to data to be digested and signed, and -\& * inlen must be the size of the data in bytes. -\& */ -\& ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */); -\& alg = EVP_SIGNATURE_fetch(NULL, "RSA\-SHA256", NULL); -\& -\& if (ctx == NULL || alg == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_sign_message_init(ctx, alg, NULL) <= 0) -\& /* Error */ -\& -\& /* Determine sig buffer length */ -\& if (EVP_PKEY_sign(ctx, NULL, &siglen, in, inlen) <= 0) -\& /* Error */ -\& -\& sig = OPENSSL_malloc(siglen); -\& -\& if (sig == NULL) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_sign(ctx, sig, &siglen, in, inlen) <= 0) -\& /* Error */ -\& -\& /* Signature is siglen bytes written to buffer sig */ -.Ve -.SS "\s-1RSA\-SHA256,\s0 using update and final" -.IX Subsection "RSA-SHA256, using update and final" -This is the same as the previous example, but allowing stream-like -functionality. -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& /* in is the input in this example. */ -\& unsigned char *in, *sig; -\& /* inlen is the length of the input in this example. */ -\& size_t inlen, siglen; -\& EVP_PKEY *signing_key; -\& EVP_SIGNATURE *alg; -\& -\& /* -\& * NB: assumes signing_key, in and inlen are set up before -\& * the next step. signing_key must be an RSA private key, -\& * in must point to data to be digested and signed, and -\& * inlen must be the size of the data in bytes. -\& */ -\& ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */); -\& alg = EVP_SIGNATURE_fetch(NULL, "RSA\-SHA256", NULL); -\& -\& if (ctx == NULL || alg == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_sign_message_init(ctx, alg, NULL) <= 0) -\& /* Error */ -\& -\& while (inlen > 0) { -\& if (EVP_PKEY_sign_message_update(ctx, in, inlen)) <= 0) -\& /* Error */ -\& if (inlen > 256) { -\& inlen \-= 256; -\& in += 256; -\& } else { -\& inlen = 0; -\& } -\& } -\& -\& /* Determine sig buffer length */ -\& if (EVP_PKEY_sign_message_final(ctx, NULL, &siglen) <= 0) -\& /* Error */ -\& -\& sig = OPENSSL_malloc(siglen); -\& -\& if (sig == NULL) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_sign_message_final(ctx, sig, &siglen) <= 0) -\& /* Error */ -\& -\& /* Signature is siglen bytes written to buffer sig */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_CTX_ctrl\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_sign_init()\fR and \fBEVP_PKEY_sign()\fR functions were added in -OpenSSL 1.0.0. -.PP -The \fBEVP_PKEY_sign_init_ex()\fR function was added in OpenSSL 3.0. -.PP -The \fBEVP_PKEY_sign_init_ex2()\fR, \fBEVP_PKEY_sign_message_init()\fR, -\&\fBEVP_PKEY_sign_message_update()\fR and \fBEVP_PKEY_sign_message_final()\fR functions -where added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_sign_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_sign_init.3ossl deleted file mode 120000 index 415596e6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_sign_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_sign_init_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_sign_init_ex.3ossl deleted file mode 120000 index 415596e6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_sign_init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_sign_init_ex2.3ossl b/openssl-install/share/man/man3/EVP_PKEY_sign_init_ex2.3ossl deleted file mode 120000 index 415596e6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_sign_init_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_sign_message_final.3ossl b/openssl-install/share/man/man3/EVP_PKEY_sign_message_final.3ossl deleted file mode 120000 index 415596e6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_sign_message_final.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_sign_message_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_sign_message_init.3ossl deleted file mode 120000 index 415596e6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_sign_message_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_sign_message_update.3ossl b/openssl-install/share/man/man3/EVP_PKEY_sign_message_update.3ossl deleted file mode 120000 index 415596e6..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_sign_message_update.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_size.3ossl b/openssl-install/share/man/man3/EVP_PKEY_size.3ossl deleted file mode 120000 index 16e1e92b..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_get_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_todata.3ossl b/openssl-install/share/man/man3/EVP_PKEY_todata.3ossl deleted file mode 100644 index 8cbb185d..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_todata.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_TODATA 3ossl" -.TH EVP_PKEY_TODATA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_todata, EVP_PKEY_export -\&\- functions to return keys as an array of key parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_todata(const EVP_PKEY *pkey, int selection, OSSL_PARAM **params); -\& int EVP_PKEY_export(const EVP_PKEY *pkey, int selection, -\& OSSL_CALLBACK *export_cb, void *export_cbarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions described here are used to extract \fB\s-1EVP_PKEY\s0\fR key values as an -array of \s-1\fBOSSL_PARAM\s0\fR\|(3). -.PP -\&\fBEVP_PKEY_todata()\fR extracts values from a key \fIpkey\fR using the \fIselection\fR. -\&\fIselection\fR is described in \*(L"Selections\*(R" in \fBEVP_PKEY_fromdata\fR\|(3). -\&\fBOSSL_PARAM_free\fR\|(3) should be used to free the returned parameters in -\&\fI*params\fR. -.PP -\&\fBEVP_PKEY_export()\fR is similar to \fBEVP_PKEY_todata()\fR but uses a callback -\&\fIexport_cb\fR that gets passed the value of \fIexport_cbarg\fR. -See \fBopenssl\-core.h\fR\|(7) for more information about the callback. Note that the -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) array that is passed to the callback is not persistent after the -callback returns. The user must preserve the items of interest, or use -\&\fBEVP_PKEY_todata()\fR if persistence is required. -.SH "NOTES" -.IX Header "NOTES" -These functions only work with key management methods coming from a provider. -This is the mirror function to \fBEVP_PKEY_fromdata\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_todata()\fR and \fBEVP_PKEY_export()\fR return 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), \fBopenssl\-core.h\fR\|(7), -\&\fBEVP_PKEY_fromdata\fR\|(3), -\&\s-1\fBEVP_PKEY\-RSA\s0\fR\|(7), \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), \s-1\fBEVP_PKEY\-DH\s0\fR\|(7), \s-1\fBEVP_PKEY\-EC\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-ED448\s0\fR\|(7), \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7), \s-1\fBEVP_PKEY\-X448\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-ED25519\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_type.3ossl b/openssl-install/share/man/man3/EVP_PKEY_type.3ossl deleted file mode 120000 index 3a831f55..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_set1_RSA.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_type_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_PKEY_type_names_do_all.3ossl deleted file mode 120000 index 21a9674e..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_type_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_is_a.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_up_ref.3ossl b/openssl-install/share/man/man3/EVP_PKEY_up_ref.3ossl deleted file mode 120000 index 3fd44f13..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify.3ossl deleted file mode 100644 index 1d7f0291..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify.3ossl +++ /dev/null @@ -1,473 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_VERIFY 3ossl" -.TH EVP_PKEY_VERIFY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_verify_init, EVP_PKEY_verify_init_ex, EVP_PKEY_verify_init_ex2, -EVP_PKEY_verify, EVP_PKEY_verify_message_init, EVP_PKEY_verify_message_update, -EVP_PKEY_verify_message_final, EVP_PKEY_CTX_set_signature \- signature -verification using a public key algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_verify_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_verify_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[]); -\& int EVP_PKEY_verify_init_ex2(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_verify_message_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_CTX_set_signature(EVP_PKEY_CTX *pctx, -\& const unsigned char *sig, size_t siglen); -\& int EVP_PKEY_verify_message_update(EVP_PKEY_CTX *ctx, -\& unsigned char *in, size_t inlen); -\& int EVP_PKEY_verify_message_final(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_verify(EVP_PKEY_CTX *ctx, -\& const unsigned char *sig, size_t siglen, -\& const unsigned char *tbs, size_t tbslen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_verify_init()\fR initializes a public key algorithm context \fIctx\fR for -verification using the algorithm given when the context was created -using \fBEVP_PKEY_CTX_new\fR\|(3) or variants thereof. The algorithm is used to -fetch a \fB\s-1EVP_SIGNATURE\s0\fR method implicitly, see \*(L"Implicit fetch\*(R" in \fBprovider\fR\|(7) -for more information about implicit fetches. -.PP -\&\fBEVP_PKEY_verify_init_ex()\fR is the same as \fBEVP_PKEY_verify_init()\fR but additionally -sets the passed parameters \fIparams\fR on the context before returning. -.PP -\&\fBEVP_PKEY_verify_init_ex2()\fR is the same as \fBEVP_PKEY_verify_init_ex()\fR, but works -with an explicitly fetched \fB\s-1EVP_SIGNATURE\s0\fR \fIalgo\fR. -A context \fIctx\fR without a pre-loaded key cannot be used with this function. -Depending on what algorithm was fetched, certain details revolving around the -treatment of the input to \fBEVP_PKEY_verify()\fR may be pre-determined, and in that -case, those details may normally not be changed. -See \*(L"\s-1NOTES\*(R"\s0 below for a deeper explanation. -.PP -\&\fBEVP_PKEY_verify_message_init()\fR initializes a public key algorithm context -\&\fIctx\fR for verifying an unlimited size message using the algorithm given by -\&\fIalgo\fR and the key given through \fBEVP_PKEY_CTX_new\fR\|(3) or -\&\fBEVP_PKEY_CTX_new_from_pkey\fR\|(3). -Passing the message is supported both in a one-shot fashion using -\&\fBEVP_PKEY_verify()\fR, and through the combination of \fBEVP_PKEY_verify_update()\fR and -\&\fBEVP_PKEY_verify_final()\fR. -This function enables using algorithms that can process input of arbitrary -length, such as \s-1ED25519, RSA\-SHA256\s0 and similar. -.PP -\&\fBEVP_PKEY_CTX_set_signature()\fR specifies the \fIsiglen\fR bytes long signature -\&\fIsig\fR to be verified against by \fBEVP_PKEY_verify_final()\fR. -It \fImust\fR be used together with \fBEVP_PKEY_verify_update()\fR and -\&\fBEVP_PKEY_verify_final()\fR. -See \*(L"\s-1NOTES\*(R"\s0 below for a deeper explanation. -.PP -\&\fBEVP_PKEY_verify_update()\fR adds \fIinlen\fR bytes from \fIin\fR to the data to be -processed for verification. The signature algorithm specification and -implementation determine how the input bytes are processed and if there's a -limit on the total size of the input. See \*(L"\s-1NOTES\*(R"\s0 below for a deeper -explanation. -.PP -\&\fBEVP_PKEY_verify_final()\fR verifies the processed data, given only \fIctx\fR. -The signature to verify against must have been given with -\&\fBEVP_PKEY_CTX_set_signature()\fR. -.PP -\&\fBEVP_PKEY_verify()\fR is a one-shot function that performs the same thing as -\&\fBEVP_PKEY_CTX_set_signature()\fR call with \fIsig\fR and \fIsiglen\fR as parameters, -followed by a single \fBEVP_PKEY_verify_update()\fR call with \fItbs\fR and \fItbslen\fR, -followed by \fBEVP_PKEY_verify_final()\fR call. -.SH "NOTES" -.IX Header "NOTES" -.SS "General" -.IX Subsection "General" -Some signature implementations only accumulate the input data and do no -further processing before verifying it (they expect the input to be a digest), -while others compress the data, typically by internally producing a digest, -and signing the result, which is then verified against a given signature. -Some of them support both modes of operation at the same time. -The caller is expected to know how the chosen algorithm is supposed to behave -and under what conditions. -.PP -For example, an \s-1RSA\s0 implementation can be expected to only expect a digest as -input, while \s-1ED25519\s0 can be expected to process the input with a hash, i.e. -to produce the digest internally, and while \s-1RSA\-SHA256\s0 can be expected to -handle either mode of operation, depending on if the operation was initialized -with \fBEVP_PKEY_verify_init_ex2()\fR or with \fBEVP_PKEY_verify_message_init()\fR. -.PP -Similarly, an \s-1RSA\s0 implementation usually expects additional details to be set, -like the message digest algorithm that the input is supposed to be digested -with, as well as the padding mode (see \fBEVP_PKEY_CTX_set_signature_md\fR\|(3) and -\&\fBEVP_PKEY_CTX_set_rsa_padding\fR\|(3) and similar others), while an \s-1RSA\-SHA256\s0 -implementation usually has these details pre-set and immutable. -.PP -The functions described here can't be used to combine separate algorithms. In -particular, neither \fBEVP_PKEY_CTX_set_signature_md\fR\|(3) nor the \fB\s-1OSSL_PARAM\s0\fR -parameter \*(L"digest\*(R" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) can be used to combine a -signature algorithm with a hash algorithm to process the input. In other -words, it's not possible to specify a \fIctx\fR pre-loaded with an \s-1RSA\s0 pkey, or -an \fIalgo\fR that fetched \f(CW\*(C`RSA\*(C'\fR and try to specify \s-1SHA256\s0 separately to get the -functionality of \s-1RSA\-SHA256.\s0 If combining algorithms in that manner is -desired, please use \fBEVP_DigestVerifyInit\fR\|(3) and associated functions, or -\&\fBEVP_VerifyInit\fR\|(3) and associated functions. -.SS "Performing multiple verifications" -.IX Subsection "Performing multiple verifications" -When initialized using \fBEVP_PKEY_verify_init_ex()\fR or \fBEVP_PKEY_verify_init_ex2()\fR, -\&\fBEVP_PKEY_verify()\fR can be called more than once on the same context to have -several one-shot operations performed using the same parameters. -.PP -When initialized using \fBEVP_PKEY_verify_message_init()\fR, it's not possible to -call \fBEVP_PKEY_verify()\fR multiple times. -.SS "On \fBEVP_PKEY_CTX_set_signature()\fP" -.IX Subsection "On EVP_PKEY_CTX_set_signature()" -Some signature algorithms (such as \s-1LMS\s0) require the signature verification -data be specified before verifying the message. -Other algorithms allow the signature to be specified late. -To allow either way (which may depend on the application's flow of input), the -signature to be verified against \fImust\fR be specified using this function when -using \fBEVP_PKEY_verify_message_update()\fR and \fBEVP_PKEY_verify_message_final()\fR to -perform the verification. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return 1 for success and 0 or a negative value for failure. -However, unlike other functions, the return value 0 from \fBEVP_PKEY_verify()\fR, -\&\fBEVP_PKEY_verify_recover()\fR and \fBEVP_PKEY_verify_message_final()\fR only indicates -that the signature did not verify successfully (that is tbs did not match the -original data or the signature was of invalid form) it is not an indication of -a more serious error. -.PP -A negative value indicates an error other that signature verification failure. -In particular a return value of \-2 indicates the operation is not supported by -the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.SS "\s-1RSA\s0 with PKCS#1 padding for \s-1SHA256\s0" -.IX Subsection "RSA with PKCS#1 padding for SHA256" -Verify signature using PKCS#1 padding and a \s-1SHA256\s0 digest as input: -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& unsigned char *md, *sig; -\& size_t mdlen, siglen; -\& EVP_PKEY *verify_key; -\& -\& /* -\& * NB: assumes verify_key, sig, siglen md and mdlen are already set up -\& * and that verify_key is an RSA public key -\& */ -\& ctx = EVP_PKEY_CTX_new(verify_key, NULL /* no engine */); -\& if (ctx == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_verify_init(ctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_PADDING) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_signature_md(ctx, EVP_sha256()) <= 0) -\& /* Error */ -\& -\& /* Perform operation */ -\& ret = EVP_PKEY_verify(ctx, sig, siglen, md, mdlen); -\& -\& /* -\& * ret == 1 indicates success, 0 verify failure and < 0 for some -\& * other error. -\& */ -.Ve -.SS "\s-1RSA\-SHA256\s0 with a pre-computed digest" -.IX Subsection "RSA-SHA256 with a pre-computed digest" -Verify a digest with \s-1RSA\-SHA256\s0 using one-shot functions. To be noted is that -\&\s-1RSA\-SHA256\s0 is assumed to be an implementation of \f(CW\*(C`sha256WithRSAEncryption\*(C'\fR, -for which the padding is pre-determined to be \fB\s-1RSA_PKCS1_PADDING\s0\fR, and the -input digest is assumed to have been computed using \s-1SHA256.\s0 -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& /* md is a SHA\-256 digest in this example. */ -\& unsigned char *md, *sig; -\& size_t mdlen = 32, siglen; -\& EVP_PKEY *signing_key; -\& -\& /* -\& * NB: assumes verify_key, sig, siglen, md and mdlen are already set up -\& * and that verify_key is an RSA public key -\& */ -\& ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */); -\& alg = EVP_SIGNATURE_fetch(NULL, "RSA\-SHA256", NULL); -\& -\& if (ctx == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_verify_init_ex2(ctx, alg, NULL) <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_verify(ctx, sig, siglen, md, mdlen) <= 0) -\& /* Error or signature doesn\*(Aqt verify */ -\& -\& /* Perform operation */ -\& ret = EVP_PKEY_verify(ctx, sig, siglen, md, mdlen); -\& -\& /* -\& * ret == 1 indicates success, 0 verify failure and < 0 for some -\& * other error. -\& */ -.Ve -.SS "\s-1RSA\-SHA256,\s0 one-shot" -.IX Subsection "RSA-SHA256, one-shot" -Verify a document with \s-1RSA\-SHA256\s0 using one-shot functions. -To be noted is that \s-1RSA\-SHA256\s0 is assumed to be an implementation of -\&\f(CW\*(C`sha256WithRSAEncryption\*(C'\fR, for which the padding is pre-determined to be -\&\fB\s-1RSA_PKCS1_PADDING\s0\fR. -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& /* in the input in this example. */ -\& unsigned char *in, *sig; -\& /* inlen is the length of the input in this example. */ -\& size_t inlen, siglen; -\& EVP_PKEY *signing_key; -\& EVP_SIGNATURE *alg; -\& -\& /* -\& * NB: assumes signing_key, in and inlen are set up before -\& * the next step. signing_key must be an RSA private key, -\& * in must point to data to be digested and signed, and -\& * inlen must be the size of the data in bytes. -\& */ -\& ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */); -\& alg = EVP_SIGNATURE_fetch(NULL, "RSA\-SHA256", NULL); -\& -\& if (ctx == NULL || alg == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_verify_message_init(ctx, alg, NULL) <= 0) -\& /* Error */ -\& -\& /* Perform operation */ -\& ret = EVP_PKEY_verify(ctx, sig, siglen, in, inlen); -\& -\& /* -\& * ret == 1 indicates success, 0 verify failure and < 0 for some -\& * other error. -\& */ -.Ve -.SS "\s-1RSA\-SHA256,\s0 using update and final" -.IX Subsection "RSA-SHA256, using update and final" -This is the same as the previous example, but allowing stream-like -functionality. -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& /* in is the input in this example. */ -\& unsigned char *in, *sig; -\& /* inlen is the length of the input in this example. */ -\& size_t inlen, siglen; -\& EVP_PKEY *signing_key; -\& EVP_SIGNATURE *alg; -\& -\& /* -\& * NB: assumes signing_key, in and inlen are set up before -\& * the next step. signing_key must be an RSA private key, -\& * in must point to data to be digested and signed, and -\& * inlen must be the size of the data in bytes. -\& */ -\& ctx = EVP_PKEY_CTX_new(signing_key, NULL /* no engine */); -\& alg = EVP_SIGNATURE_fetch(NULL, "RSA\-SHA256", NULL); -\& -\& if (ctx == NULL || alg == NULL) -\& /* Error occurred */ -\& if (EVP_PKEY_verify_message_init(ctx, alg, NULL) <= 0) -\& /* Error */ -\& -\& /* We have the signature, specify it early */ -\& EVP_PKEY_CTX_set_signature(ctx, sig, siglen); -\& -\& /* Perform operation */ -\& while (inlen > 0) { -\& if (EVP_PKEY_verify_message_update(ctx, in, inlen)) <= 0) -\& /* Error */ -\& if (inlen > 256) { -\& inlen \-= 256; -\& in += 256; -\& } else { -\& inlen = 0; -\& } -\& } -\& ret = EVP_PKEY_verify_message_final(ctx); -\& -\& /* -\& * ret == 1 indicates success, 0 verify failure and < 0 for some -\& * other error. -\& */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_verify_init()\fR and \fBEVP_PKEY_verify()\fR functions were added in -OpenSSL 1.0.0. -.PP -The \fBEVP_PKEY_verify_init_ex()\fR function was added in OpenSSL 3.0. -.PP -The \fBEVP_PKEY_verify_init_ex2()\fR, \fBEVP_PKEY_verify_message_init()\fR, -\&\fBEVP_PKEY_verify_message_update()\fR, \fBEVP_PKEY_verify_message_final()\fR and -\&\fBEVP_PKEY_CTX_set_signature()\fR functions where added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_init.3ossl deleted file mode 120000 index 341edffb..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_init_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_init_ex.3ossl deleted file mode 120000 index 341edffb..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_init_ex2.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_init_ex2.3ossl deleted file mode 120000 index 341edffb..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_init_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_message_final.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_message_final.3ossl deleted file mode 120000 index 341edffb..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_message_final.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_message_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_message_init.3ossl deleted file mode 120000 index 341edffb..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_message_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_message_update.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_message_update.3ossl deleted file mode 120000 index 341edffb..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_message_update.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_recover.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_recover.3ossl deleted file mode 100644 index f9042396..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_recover.3ossl +++ /dev/null @@ -1,273 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY_VERIFY_RECOVER 3ossl" -.TH EVP_PKEY_VERIFY_RECOVER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY_verify_recover_init, EVP_PKEY_verify_recover_init_ex, -EVP_PKEY_verify_recover_init_ex2, EVP_PKEY_verify_recover -\&\- recover signature using a public key algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_PKEY_verify_recover_init(EVP_PKEY_CTX *ctx); -\& int EVP_PKEY_verify_recover_init_ex(EVP_PKEY_CTX *ctx, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_verify_recover_init_ex2(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *algo, -\& const OSSL_PARAM params[]); -\& int EVP_PKEY_verify_recover(EVP_PKEY_CTX *ctx, -\& unsigned char *rout, size_t *routlen, -\& const unsigned char *sig, size_t siglen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_PKEY_verify_recover_init()\fR initializes a public key algorithm context -\&\fIctx\fR for signing using the algorithm given when the context was created -using \fBEVP_PKEY_CTX_new\fR\|(3) or variants thereof. The algorithm is used to -fetch a \fB\s-1EVP_SIGNATURE\s0\fR method implicitly, see \*(L"Implicit fetch\*(R" in \fBprovider\fR\|(7) -for more information about implicit fetches. -.PP -\&\fBEVP_PKEY_verify_recover_init_ex()\fR is the same as -\&\fBEVP_PKEY_verify_recover_init()\fR but additionally sets the passed parameters -\&\fIparams\fR on the context before returning. -.PP -\&\fBEVP_PKEY_verify_recover_init_ex2()\fR is the same as \fBEVP_PKEY_verify_recover_init_ex()\fR, -but works with an explicitly fetched \fB\s-1EVP_SIGNATURE\s0\fR \fIalgo\fR. -A context \fIctx\fR without a pre-loaded key cannot be used with this function. -Depending on what algorithm was fetched, certain details revolving around the -treatment of the input to \fBEVP_PKEY_verify()\fR may be pre-determined, and in that -case, those details may normally not be changed. -See \*(L"\s-1NOTES\*(R"\s0 below for a deeper explanation. -.PP -The \fBEVP_PKEY_verify_recover()\fR function recovers signed data -using \fIctx\fR. The signature is specified using the \fIsig\fR and -\&\fIsiglen\fR parameters. If \fIrout\fR is \s-1NULL\s0 then the maximum size of the output -buffer is written to the \fIroutlen\fR parameter. If \fIrout\fR is not \s-1NULL\s0 then -before the call the \fIroutlen\fR parameter should contain the length of the -\&\fIrout\fR buffer, if the call is successful recovered data is written to -\&\fIrout\fR and the amount of data written to \fIroutlen\fR. -.SH "NOTES" -.IX Header "NOTES" -Normally an application is only interested in whether a signature verification -operation is successful in those cases the \fBEVP_verify()\fR function should be -used. -.PP -Sometimes however it is useful to obtain the data originally signed using a -signing operation. Only certain public key algorithms can recover a signature -in this way (for example \s-1RSA\s0 in \s-1PKCS\s0 padding mode). -.PP -After the call to \fBEVP_PKEY_verify_recover_init()\fR algorithm specific control -operations can be performed to set any appropriate parameters for the -operation. -.PP -After the call to \fBEVP_PKEY_verify_recover_init_ex2()\fR, algorithm specific control -operations may not be needed if the chosen algorithm implies that those controls -pre-set (and immutable). -.PP -The function \fBEVP_PKEY_verify_recover()\fR can be called more than once on the same -context if several operations are performed using the same parameters. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_PKEY_verify_recover_init()\fR and \fBEVP_PKEY_verify_recover()\fR return 1 for success -and 0 or a negative value for failure. In particular a return value of \-2 -indicates the operation is not supported by the public key algorithm. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Recover digest originally signed using PKCS#1 and \s-1SHA256\s0 digest: -.PP -.Vb 2 -\& #include -\& #include -\& -\& EVP_PKEY_CTX *ctx; -\& unsigned char *rout, *sig; -\& size_t routlen, siglen; -\& EVP_PKEY *verify_key; -\& -\& /* -\& * NB: assumes verify_key, sig and siglen are already set up -\& * and that verify_key is an RSA public key -\& */ -\& ctx = EVP_PKEY_CTX_new(verify_key, NULL /* no engine */); -\& if (!ctx) -\& /* Error occurred */ -\& if (EVP_PKEY_verify_recover_init(ctx) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_PADDING) <= 0) -\& /* Error */ -\& if (EVP_PKEY_CTX_set_signature_md(ctx, EVP_sha256()) <= 0) -\& /* Error */ -\& -\& /* Determine buffer length */ -\& if (EVP_PKEY_verify_recover(ctx, NULL, &routlen, sig, siglen) <= 0) -\& /* Error */ -\& -\& rout = OPENSSL_malloc(routlen); -\& -\& if (!rout) -\& /* malloc failure */ -\& -\& if (EVP_PKEY_verify_recover(ctx, rout, &routlen, sig, siglen) <= 0) -\& /* Error */ -\& -\& /* Recovered data is routlen bytes written to buffer rout */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBEVP_PKEY_verify_recover_init()\fR and \fBEVP_PKEY_verify_recover()\fR -functions were added in OpenSSL 1.0.0. -.PP -The \fBEVP_PKEY_verify_recover_init_ex()\fR function was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init.3ossl deleted file mode 120000 index 73d46a98..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify_recover.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex.3ossl deleted file mode 120000 index 73d46a98..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify_recover.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex2.3ossl b/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex2.3ossl deleted file mode 120000 index 73d46a98..00000000 --- a/openssl-install/share/man/man3/EVP_PKEY_verify_recover_init_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY_verify_recover.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_Q_digest.3ossl b/openssl-install/share/man/man3/EVP_Q_digest.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_Q_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_Q_mac.3ossl b/openssl-install/share/man/man3/EVP_Q_mac.3ossl deleted file mode 120000 index 7bd844e1..00000000 --- a/openssl-install/share/man/man3/EVP_Q_mac.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND.3ossl b/openssl-install/share/man/man3/EVP_RAND.3ossl deleted file mode 100644 index 1ecd9be6..00000000 --- a/openssl-install/share/man/man3/EVP_RAND.3ossl +++ /dev/null @@ -1,544 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND 3ossl" -.TH EVP_RAND 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND, EVP_RAND_fetch, EVP_RAND_free, EVP_RAND_up_ref, EVP_RAND_CTX, -EVP_RAND_CTX_new, EVP_RAND_CTX_free, EVP_RAND_CTX_up_ref, EVP_RAND_instantiate, -EVP_RAND_uninstantiate, EVP_RAND_generate, EVP_RAND_reseed, EVP_RAND_nonce, -EVP_RAND_enable_locking, EVP_RAND_verify_zeroization, EVP_RAND_get_strength, -EVP_RAND_get_state, -EVP_RAND_get0_provider, EVP_RAND_CTX_get0_rand, EVP_RAND_is_a, -EVP_RAND_get0_name, EVP_RAND_names_do_all, -EVP_RAND_get0_description, -EVP_RAND_CTX_get_params, -EVP_RAND_CTX_set_params, EVP_RAND_do_all_provided, EVP_RAND_get_params, -EVP_RAND_gettable_ctx_params, EVP_RAND_settable_ctx_params, -EVP_RAND_CTX_gettable_params, EVP_RAND_CTX_settable_params, -EVP_RAND_gettable_params, EVP_RAND_STATE_UNINITIALISED, EVP_RAND_STATE_READY, -EVP_RAND_STATE_ERROR \- EVP RAND routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct evp_rand_st EVP_RAND; -\& typedef struct evp_rand_ctx_st EVP_RAND_CTX; -\& -\& EVP_RAND *EVP_RAND_fetch(OSSL_LIB_CTX *libctx, const char *algorithm, -\& const char *properties); -\& int EVP_RAND_up_ref(EVP_RAND *rand); -\& void EVP_RAND_free(EVP_RAND *rand); -\& EVP_RAND_CTX *EVP_RAND_CTX_new(EVP_RAND *rand, EVP_RAND_CTX *parent); -\& void EVP_RAND_CTX_free(EVP_RAND_CTX *ctx); -\& int EVP_RAND_CTX_up_ref(EVP_RAND_CTX *ctx); -\& EVP_RAND *EVP_RAND_CTX_get0_rand(EVP_RAND_CTX *ctx); -\& int EVP_RAND_get_params(EVP_RAND *rand, OSSL_PARAM params[]); -\& int EVP_RAND_CTX_get_params(EVP_RAND_CTX *ctx, OSSL_PARAM params[]); -\& int EVP_RAND_CTX_set_params(EVP_RAND_CTX *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *EVP_RAND_gettable_params(const EVP_RAND *rand); -\& const OSSL_PARAM *EVP_RAND_gettable_ctx_params(const EVP_RAND *rand); -\& const OSSL_PARAM *EVP_RAND_settable_ctx_params(const EVP_RAND *rand); -\& const OSSL_PARAM *EVP_RAND_CTX_gettable_params(EVP_RAND_CTX *ctx); -\& const OSSL_PARAM *EVP_RAND_CTX_settable_params(EVP_RAND_CTX *ctx); -\& const char *EVP_RAND_get0_name(const EVP_RAND *rand); -\& const char *EVP_RAND_get0_description(const EVP_RAND *rand); -\& int EVP_RAND_is_a(const EVP_RAND *rand, const char *name); -\& const OSSL_PROVIDER *EVP_RAND_get0_provider(const EVP_RAND *rand); -\& void EVP_RAND_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_RAND *rand, void *arg), -\& void *arg); -\& int EVP_RAND_names_do_all(const EVP_RAND *rand, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& -\& int EVP_RAND_instantiate(EVP_RAND_CTX *ctx, unsigned int strength, -\& int prediction_resistance, -\& const unsigned char *pstr, size_t pstr_len, -\& const OSSL_PARAM params[]); -\& int EVP_RAND_uninstantiate(EVP_RAND_CTX *ctx); -\& int EVP_RAND_generate(EVP_RAND_CTX *ctx, unsigned char *out, size_t outlen, -\& unsigned int strength, int prediction_resistance, -\& const unsigned char *addin, size_t addin_len); -\& int EVP_RAND_reseed(EVP_RAND_CTX *ctx, int prediction_resistance, -\& const unsigned char *ent, size_t ent_len, -\& const unsigned char *addin, size_t addin_len); -\& int EVP_RAND_nonce(EVP_RAND_CTX *ctx, unsigned char *out, size_t outlen); -\& int EVP_RAND_enable_locking(EVP_RAND_CTX *ctx); -\& int EVP_RAND_verify_zeroization(EVP_RAND_CTX *ctx); -\& unsigned int EVP_RAND_get_strength(EVP_RAND_CTX *ctx); -\& int EVP_RAND_get_state(EVP_RAND_CTX *ctx); -\& -\& #define EVP_RAND_STATE_UNINITIALISED 0 -\& #define EVP_RAND_STATE_READY 1 -\& #define EVP_RAND_STATE_ERROR 2 -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP RAND\s0 routines are a high-level interface to random number generators -both deterministic and not. -If you just want to generate random bytes then you don't need to use -these functions: just call \fBRAND_bytes()\fR or \fBRAND_priv_bytes()\fR. -If you want to do more, these calls should be used instead of the older -\&\s-1RAND\s0 and \s-1RAND_DRBG\s0 functions. -.PP -After creating a \fB\s-1EVP_RAND_CTX\s0\fR for the required algorithm using -\&\fBEVP_RAND_CTX_new()\fR, inputs to the algorithm are supplied either by -passing them as part of the \fBEVP_RAND_instantiate()\fR call or using calls to -\&\fBEVP_RAND_CTX_set_params()\fR before calling \fBEVP_RAND_instantiate()\fR. Finally, -call \fBEVP_RAND_generate()\fR to produce cryptographically secure random bytes. -.SS "Types" -.IX Subsection "Types" -\&\fB\s-1EVP_RAND\s0\fR is a type that holds the implementation of a \s-1RAND.\s0 -.PP -\&\fB\s-1EVP_RAND_CTX\s0\fR is a context type that holds the algorithm inputs. -\&\fB\s-1EVP_RAND_CTX\s0\fR structures are reference counted. -.SS "Algorithm implementation fetching" -.IX Subsection "Algorithm implementation fetching" -\&\fBEVP_RAND_fetch()\fR fetches an implementation of a \s-1RAND\s0 \fIalgorithm\fR, given -a library context \fIlibctx\fR and a set of \fIproperties\fR. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.PP -The returned value must eventually be freed with -\&\fBEVP_RAND_free\fR\|(3). -.PP -\&\fBEVP_RAND_up_ref()\fR increments the reference count of an already fetched -\&\s-1RAND.\s0 -.PP -\&\fBEVP_RAND_free()\fR frees a fetched algorithm. -\&\s-1NULL\s0 is a valid parameter, for which this function is a no-op. -.SS "Context manipulation functions" -.IX Subsection "Context manipulation functions" -\&\fBEVP_RAND_CTX_new()\fR creates a new context for the \s-1RAND\s0 implementation \fIrand\fR. -If not \s-1NULL,\s0 \fIparent\fR specifies the seed source for this implementation. -Not all random number generators need to have a seed source specified. -If a parent is required, a \s-1NULL\s0 \fIparent\fR will utilise the operating -system entropy sources. -It is recommended to minimise the number of random number generators that -rely on the operating system for their randomness because this is often scarce. -.PP -\&\fBEVP_RAND_CTX_free()\fR frees up the context \fIctx\fR. If \fIctx\fR is \s-1NULL,\s0 nothing -is done. -.PP -\&\fBEVP_RAND_CTX_get0_rand()\fR returns the \fB\s-1EVP_RAND\s0\fR associated with the context -\&\fIctx\fR. -.SS "Random Number Generator Functions" -.IX Subsection "Random Number Generator Functions" -\&\fBEVP_RAND_instantiate()\fR processes any parameters in \fIparams\fR and -then instantiates the \s-1RAND\s0 \fIctx\fR with a minimum security strength -of and personalisation string \fIpstr\fR of length . -If \fIprediction_resistance\fR is specified, fresh entropy from a live source -will be sought. This call operates as per \s-1NIST SP 800\-90A\s0 and \s-1SP 800\-90C.\s0 -.PP -\&\fBEVP_RAND_uninstantiate()\fR uninstantiates the \s-1RAND\s0 \fIctx\fR as per -\&\s-1NIST SP 800\-90A\s0 and \s-1SP 800\-90C.\s0 Subsequent to this call, the \s-1RAND\s0 cannot -be used to generate bytes. It can only be freed or instantiated again. -.PP -\&\fBEVP_RAND_generate()\fR produces random bytes from the \s-1RAND\s0 \fIctx\fR with the -additional input \fIaddin\fR of length \fIaddin_len\fR. The bytes -produced will meet the security \fIstrength\fR. -If \fIprediction_resistance\fR is specified, fresh entropy from a live source -will be sought. This call operates as per \s-1NIST SP 800\-90A\s0 and \s-1SP 800\-90C.\s0 -.PP -\&\fBEVP_RAND_reseed()\fR reseeds the \s-1RAND\s0 with new entropy. -Entropy \fIent\fR of length \fIent_len\fR bytes can be supplied as can additional -input \fIaddin\fR of length \fIaddin_len\fR bytes. In the \s-1FIPS\s0 provider, both are -treated as additional input as per \s-1NIST\s0 SP\-800\-90Ar1, Sections 9.1 and 9.2. -Additional seed material is also drawn from the \s-1RAND\s0's parent or the -operating system. If \fIprediction_resistance\fR is specified, fresh entropy -from a live source will be sought. This call operates as per \s-1NIST SP 800\-90A\s0 -and \s-1SP 800\-90C.\s0 -.PP -\&\fBEVP_RAND_nonce()\fR creates a nonce in \fIout\fR of length \fIoutlen\fR -bytes from the \s-1RAND\s0 \fIctx\fR. -.PP -\&\fBEVP_RAND_enable_locking()\fR enables locking for the \s-1RAND\s0 \fIctx\fR and all of -its parents. After this \fIctx\fR will operate in a thread safe manner, albeit -more slowly. This function is not itself thread safe if called with the same -\&\fIctx\fR from multiple threads. Typically locking should be enabled before a -\&\fIctx\fR is shared across multiple threads. -.PP -\&\fBEVP_RAND_get_params()\fR retrieves details about the implementation -\&\fIrand\fR. -The set of parameters given with \fIparams\fR determine exactly what -parameters should be retrieved. -Note that a parameter that is unknown in the underlying context is -simply ignored. -.PP -\&\fBEVP_RAND_CTX_get_params()\fR retrieves chosen parameters, given the -context \fIctx\fR and its underlying context. -The set of parameters given with \fIparams\fR determine exactly what -parameters should be retrieved. -Note that a parameter that is unknown in the underlying context is -simply ignored. -.PP -\&\fBEVP_RAND_CTX_set_params()\fR passes chosen parameters to the underlying -context, given a context \fIctx\fR. -The set of parameters given with \fIparams\fR determine exactly what -parameters are passed down. -Note that a parameter that is unknown in the underlying context is -simply ignored. -Also, what happens when a needed parameter isn't passed down is -defined by the implementation. -.PP -\&\fBEVP_RAND_gettable_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes -the retrievable and settable parameters. \fBEVP_RAND_gettable_params()\fR returns -parameters that can be used with \fBEVP_RAND_get_params()\fR. -.PP -\&\fBEVP_RAND_gettable_ctx_params()\fR and \fBEVP_RAND_CTX_gettable_params()\fR return -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) arrays that describe the retrievable parameters that -can be used with \fBEVP_RAND_CTX_get_params()\fR. \fBEVP_RAND_gettable_ctx_params()\fR -returns the parameters that can be retrieved from the algorithm, whereas -\&\fBEVP_RAND_CTX_gettable_params()\fR returns the parameters that can be retrieved -in the context's current state. -.PP -\&\fBEVP_RAND_settable_ctx_params()\fR and \fBEVP_RAND_CTX_settable_params()\fR return -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) arrays that describe the settable parameters that -can be used with \fBEVP_RAND_CTX_set_params()\fR. \fBEVP_RAND_settable_ctx_params()\fR -returns the parameters that can be retrieved from the algorithm, whereas -\&\fBEVP_RAND_CTX_settable_params()\fR returns the parameters that can be retrieved -in the context's current state. -.SS "Information functions" -.IX Subsection "Information functions" -\&\fBEVP_RAND_get_strength()\fR returns the security strength of the \s-1RAND\s0 \fIctx\fR. -.PP -\&\fBEVP_RAND_get_state()\fR returns the current state of the \s-1RAND\s0 \fIctx\fR. -States defined by the OpenSSL RNGs are: -.IP "\(bu" 4 -\&\s-1EVP_RAND_STATE_UNINITIALISED:\s0 this \s-1RNG\s0 is currently uninitialised. -The instantiate call will change this to the ready state. -.IP "\(bu" 4 -\&\s-1EVP_RAND_STATE_READY:\s0 this \s-1RNG\s0 is currently ready to generate output. -.IP "\(bu" 4 -\&\s-1EVP_RAND_STATE_ERROR:\s0 this \s-1RNG\s0 is in an error state. -.PP -\&\fBEVP_RAND_is_a()\fR returns 1 if \fIrand\fR is an implementation of an -algorithm that's identifiable with \fIname\fR, otherwise 0. -.PP -\&\fBEVP_RAND_get0_provider()\fR returns the provider that holds the implementation -of the given \fIrand\fR. -.PP -\&\fBEVP_RAND_do_all_provided()\fR traverses all \s-1RAND\s0 implemented by all activated -providers in the given library context \fIlibctx\fR, and for each of the -implementations, calls the given function \fIfn\fR with the implementation method -and the given \fIarg\fR as argument. -.PP -\&\fBEVP_RAND_get0_name()\fR returns the canonical name of \fIrand\fR. -.PP -\&\fBEVP_RAND_names_do_all()\fR traverses all names for \fIrand\fR, and calls -\&\fIfn\fR with each name and \fIdata\fR. -.PP -\&\fBEVP_RAND_get0_description()\fR returns a description of the rand, meant for -display and human consumption. The description is at the discretion of -the rand implementation. -.PP -\&\fBEVP_RAND_verify_zeroization()\fR confirms if the internal \s-1DRBG\s0 state is -currently zeroed. This is used by the \s-1FIPS\s0 provider to support the mandatory -self tests. -.SH "PARAMETERS" -.IX Header "PARAMETERS" -The standard parameter names are: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -Returns the state of the random number generator. -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -Returns the bit strength of the random number generator. -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This option is used by the OpenSSL \s-1FIPS\s0 provider and is not supported -by all \s-1EVP_RAND\s0 sources. -.PP -For rands that are also deterministic random bit generators (DRBGs), these -additional parameters are recognised. Not all -parameters are relevant to, or are understood by all \s-1DRBG\s0 rands: -.ie n .IP """reseed_requests"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``reseed_requests'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "reseed_requests (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -Reads or set the number of generate requests before reseeding the -associated \s-1RAND\s0 ctx. -.ie n .IP """reseed_time_interval"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.el .IP "``reseed_time_interval'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.IX Item "reseed_time_interval (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) " -Reads or set the number of elapsed seconds before reseeding the -associated \s-1RAND\s0 ctx. -.ie n .IP """max_request"" (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.IX Item "max_request (OSSL_RAND_PARAM_MAX_REQUEST) " -Specifies the maximum number of bytes that can be generated in a single -call to OSSL_FUNC_rand_generate. -.ie n .IP """min_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.el .IP "``min_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.IX Item "min_entropylen (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) " -.PD 0 -.ie n .IP """max_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.el .IP "``max_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.IX Item "max_entropylen (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) " -.PD -Specify the minimum and maximum number of bytes of random material that -can be used to seed the \s-1DRBG.\s0 -.ie n .IP """min_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.el .IP "``min_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.IX Item "min_noncelen (OSSL_DRBG_PARAM_MIN_NONCELEN) " -.PD 0 -.ie n .IP """max_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.el .IP "``max_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.IX Item "max_noncelen (OSSL_DRBG_PARAM_MAX_NONCELEN) " -.PD -Specify the minimum and maximum number of bytes of nonce that can be used to -seed the \s-1DRBG.\s0 -.ie n .IP """max_perslen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.el .IP "``max_perslen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.IX Item "max_perslen (OSSL_DRBG_PARAM_MAX_PERSLEN) " -.PD 0 -.ie n .IP """max_adinlen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.el .IP "``max_adinlen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.IX Item "max_adinlen (OSSL_DRBG_PARAM_MAX_ADINLEN) " -.PD -Specify the minimum and maximum number of bytes of personalisation string -that can be used with the \s-1DRBG.\s0 -.ie n .IP """reseed_counter"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.el .IP "``reseed_counter'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.IX Item "reseed_counter (OSSL_DRBG_PARAM_RESEED_COUNTER) " -Specifies the number of times the \s-1DRBG\s0 has been seeded or reseeded. -.ie n .IP """properties"" (\fB\s-1OSSL_RAND_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_RAND_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_RAND_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """mac"" (\fB\s-1OSSL_RAND_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mac'' (\fB\s-1OSSL_RAND_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mac (OSSL_RAND_PARAM_MAC) " -.ie n .IP """digest"" (\fB\s-1OSSL_RAND_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_RAND_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_RAND_PARAM_DIGEST) " -.ie n .IP """cipher"" (\fB\s-1OSSL_RAND_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_RAND_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_RAND_PARAM_CIPHER) " -.PD -For \s-1RAND\s0 implementations that use an underlying computation \s-1MAC,\s0 digest or -cipher, these parameters set what the algorithm should be. -.Sp -The value is always the name of the intended algorithm, -or the properties in the case of \fB\s-1OSSL_RAND_PARAM_PROPERTIES\s0\fR. -.SH "NOTES" -.IX Header "NOTES" -The use of a nonzero value for the \fIprediction_resistance\fR argument to -\&\fBEVP_RAND_instantiate()\fR, \fBEVP_RAND_generate()\fR or \fBEVP_RAND_reseed()\fR should -be used sparingly. In the default setup, this will cause all public and -private DRBGs to be reseeded on next use. Since, by default, public and -private DRBGs are allocated on a per thread basis, this can result in -significant overhead for highly multi-threaded applications. For normal -use-cases, the default \*(L"reseed_requests\*(R" and \*(L"reseed_time_interval\*(R" -thresholds ensure sufficient prediction resistance over time and you -can reduce those values if you think they are too high. Explicitly -requesting prediction resistance is intended for more special use-cases -like generating long-term secrets. -.PP -An \fB\s-1EVP_RAND_CTX\s0\fR needs to have locking enabled if it acts as the parent of -more than one child and the children can be accessed concurrently. This must -be done by explicitly calling \fBEVP_RAND_enable_locking()\fR. -.PP -The \s-1RAND\s0 life-cycle is described in \fBlife_cycle\-rand\fR\|(7). In the future, -the transitions described there will be enforced. When this is done, it will -not be considered a breaking change to the \s-1API.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_RAND_fetch()\fR returns a pointer to a newly fetched \fB\s-1EVP_RAND\s0\fR, or -\&\s-1NULL\s0 if allocation failed. -.PP -\&\fBEVP_RAND_get0_provider()\fR returns a pointer to the provider for the \s-1RAND,\s0 or -\&\s-1NULL\s0 on error. -.PP -\&\fBEVP_RAND_CTX_get0_rand()\fR returns a pointer to the \fB\s-1EVP_RAND\s0\fR associated -with the context. -.PP -\&\fBEVP_RAND_get0_name()\fR returns the name of the random number generation -algorithm. -.PP -\&\fBEVP_RAND_up_ref()\fR returns 1 on success, 0 on error. -.PP -\&\fBEVP_RAND_names_do_all()\fR returns 1 if the callback was called for all names. A -return value of 0 means that the callback was not called for any names. -.PP -\&\fBEVP_RAND_CTX_new()\fR returns either the newly allocated -\&\fB\s-1EVP_RAND_CTX\s0\fR structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBEVP_RAND_CTX_free()\fR does not return a value. -.PP -\&\fBEVP_RAND_CTX_up_ref()\fR returns 1 on success, 0 on error. -.PP -\&\fBEVP_RAND_nonce()\fR returns 1 on success, 0 on error. -.PP -\&\fBEVP_RAND_get_strength()\fR returns the strength of the random number generator -in bits. -.PP -\&\fBEVP_RAND_gettable_params()\fR, \fBEVP_RAND_gettable_ctx_params()\fR and -\&\fBEVP_RAND_settable_ctx_params()\fR return an array of OSSL_PARAMs. -.PP -\&\fBEVP_RAND_verify_zeroization()\fR returns 1 if the internal \s-1DRBG\s0 state is -currently zeroed, and 0 if not. -.PP -The remaining functions return 1 for success and 0 or a negative value for -failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRAND_bytes\fR\|(3), -\&\s-1\fBEVP_RAND\-CTR\-DRBG\s0\fR\|(7), -\&\s-1\fBEVP_RAND\-HASH\-DRBG\s0\fR\|(7), -\&\s-1\fBEVP_RAND\-HMAC\-DRBG\s0\fR\|(7), -\&\s-1\fBEVP_RAND\-TEST\-RAND\s0\fR\|(7), -\&\fBprovider\-rand\fR\|(7), -\&\fBlife_cycle\-rand\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_RAND_CTX_up_ref()\fR was added in OpenSSL 3.1. -.PP -The remaining functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_free.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_free.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_get0_rand.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_get0_rand.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_get0_rand.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_get_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_get_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_gettable_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_new.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_new.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_set_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_set_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_settable_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_settable_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_settable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_CTX_up_ref.3ossl b/openssl-install/share/man/man3/EVP_RAND_CTX_up_ref.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_CTX_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_STATE_ERROR.3ossl b/openssl-install/share/man/man3/EVP_RAND_STATE_ERROR.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_STATE_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_STATE_READY.3ossl b/openssl-install/share/man/man3/EVP_RAND_STATE_READY.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_STATE_READY.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_STATE_UNINITIALISED.3ossl b/openssl-install/share/man/man3/EVP_RAND_STATE_UNINITIALISED.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_STATE_UNINITIALISED.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_RAND_do_all_provided.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_enable_locking.3ossl b/openssl-install/share/man/man3/EVP_RAND_enable_locking.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_enable_locking.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_fetch.3ossl b/openssl-install/share/man/man3/EVP_RAND_fetch.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_free.3ossl b/openssl-install/share/man/man3/EVP_RAND_free.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_generate.3ossl b/openssl-install/share/man/man3/EVP_RAND_generate.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_generate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_get0_description.3ossl b/openssl-install/share/man/man3/EVP_RAND_get0_description.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_get0_name.3ossl b/openssl-install/share/man/man3/EVP_RAND_get0_name.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_RAND_get0_provider.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_get_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_get_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_get_state.3ossl b/openssl-install/share/man/man3/EVP_RAND_get_state.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_get_state.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_get_strength.3ossl b/openssl-install/share/man/man3/EVP_RAND_get_strength.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_get_strength.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_gettable_ctx_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_gettable_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_gettable_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_instantiate.3ossl b/openssl-install/share/man/man3/EVP_RAND_instantiate.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_instantiate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_is_a.3ossl b/openssl-install/share/man/man3/EVP_RAND_is_a.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_RAND_names_do_all.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_nonce.3ossl b/openssl-install/share/man/man3/EVP_RAND_nonce.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_nonce.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_reseed.3ossl b/openssl-install/share/man/man3/EVP_RAND_reseed.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_reseed.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_RAND_settable_ctx_params.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_uninstantiate.3ossl b/openssl-install/share/man/man3/EVP_RAND_uninstantiate.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_uninstantiate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_up_ref.3ossl b/openssl-install/share/man/man3/EVP_RAND_up_ref.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RAND_verify_zeroization.3ossl b/openssl-install/share/man/man3/EVP_RAND_verify_zeroization.3ossl deleted file mode 120000 index f1eb7a21..00000000 --- a/openssl-install/share/man/man3/EVP_RAND_verify_zeroization.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_RAND.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_RSA_gen.3ossl b/openssl-install/share/man/man3/EVP_RSA_gen.3ossl deleted file mode 120000 index 5316c699..00000000 --- a/openssl-install/share/man/man3/EVP_RSA_gen.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_generate_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE.3ossl deleted file mode 100644 index 952f1356..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE.3ossl +++ /dev/null @@ -1,247 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SIGNATURE 3ossl" -.TH EVP_SIGNATURE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SIGNATURE, -EVP_SIGNATURE_fetch, EVP_SIGNATURE_free, EVP_SIGNATURE_up_ref, -EVP_SIGNATURE_is_a, EVP_SIGNATURE_get0_provider, -EVP_SIGNATURE_do_all_provided, EVP_SIGNATURE_names_do_all, -EVP_SIGNATURE_get0_name, EVP_SIGNATURE_get0_description, -EVP_SIGNATURE_gettable_ctx_params, EVP_SIGNATURE_settable_ctx_params -\&\- Functions to manage EVP_SIGNATURE algorithm objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct evp_signature_st EVP_SIGNATURE; -\& -\& EVP_SIGNATURE *EVP_SIGNATURE_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, -\& const char *properties); -\& void EVP_SIGNATURE_free(EVP_SIGNATURE *signature); -\& int EVP_SIGNATURE_up_ref(EVP_SIGNATURE *signature); -\& const char *EVP_SIGNATURE_get0_name(const EVP_SIGNATURE *signature); -\& int EVP_SIGNATURE_is_a(const EVP_SIGNATURE *signature, const char *name); -\& OSSL_PROVIDER *EVP_SIGNATURE_get0_provider(const EVP_SIGNATURE *signature); -\& void EVP_SIGNATURE_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(EVP_SIGNATURE *signature, -\& void *arg), -\& void *arg); -\& int EVP_SIGNATURE_names_do_all(const EVP_SIGNATURE *signature, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const char *EVP_SIGNATURE_get0_name(const EVP_SIGNATURE *signature); -\& const char *EVP_SIGNATURE_get0_description(const EVP_SIGNATURE *signature); -\& const OSSL_PARAM *EVP_SIGNATURE_gettable_ctx_params(const EVP_SIGNATURE *sig); -\& const OSSL_PARAM *EVP_SIGNATURE_settable_ctx_params(const EVP_SIGNATURE *sig); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_SIGNATURE_fetch()\fR fetches the implementation for the given -\&\fBalgorithm\fR from any provider offering it, within the criteria given -by the \fBproperties\fR. -The algorithm will be one offering functions for performing signature related -tasks such as signing and verifying. -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -.PP -The returned value must eventually be freed with \fBEVP_SIGNATURE_free()\fR. -.PP -\&\fBEVP_SIGNATURE_free()\fR decrements the reference count for the \fB\s-1EVP_SIGNATURE\s0\fR -structure. Typically this structure will have been obtained from an earlier call -to \fBEVP_SIGNATURE_fetch()\fR. If the reference count drops to 0 then the -structure is freed. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBEVP_SIGNATURE_up_ref()\fR increments the reference count for an \fB\s-1EVP_SIGNATURE\s0\fR -structure. -.PP -\&\fBEVP_SIGNATURE_is_a()\fR returns 1 if \fIsignature\fR is an implementation of an -algorithm that's identifiable with \fIname\fR, otherwise 0. -.PP -\&\fBEVP_SIGNATURE_get0_provider()\fR returns the provider that \fIsignature\fR was -fetched from. -.PP -\&\fBEVP_SIGNATURE_do_all_provided()\fR traverses all \s-1SIGNATURE\s0 implemented by all -activated providers in the given library context \fIlibctx\fR, and for each of the -implementations, calls the given function \fIfn\fR with the implementation method -and the given \fIarg\fR as argument. -.PP -\&\fBEVP_SIGNATURE_get0_name()\fR returns the algorithm name from the provided -implementation for the given \fIsignature\fR. Note that the \fIsignature\fR may have -multiple synonyms associated with it. In this case the first name from the -algorithm definition is returned. Ownership of the returned string is retained -by the \fIsignature\fR object and should not be freed by the caller. -.PP -\&\fBEVP_SIGNATURE_names_do_all()\fR traverses all names for \fIsignature\fR, and calls -\&\fIfn\fR with each name and \fIdata\fR. -.PP -\&\fBEVP_SIGNATURE_get0_description()\fR returns a description of the \fIsignature\fR, -meant for display and human consumption. The description is at the -discretion of the \fIsignature\fR implementation. -.PP -\&\fBEVP_SIGNATURE_gettable_ctx_params()\fR and \fBEVP_SIGNATURE_settable_ctx_params()\fR -return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the names and types of key -parameters that can be retrieved or set by a signature algorithm using -\&\fBEVP_PKEY_CTX_get_params\fR\|(3) and \fBEVP_PKEY_CTX_set_params\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_SIGNATURE_fetch()\fR returns a pointer to an \fB\s-1EVP_SIGNATURE\s0\fR for success -or \fB\s-1NULL\s0\fR for failure. -.PP -\&\fBEVP_SIGNATURE_up_ref()\fR returns 1 for success or 0 otherwise. -.PP -\&\fBEVP_SIGNATURE_names_do_all()\fR returns 1 if the callback was called for all names. -A return value of 0 means that the callback was not called for any names. -.PP -\&\fBEVP_SIGNATURE_gettable_ctx_params()\fR and \fBEVP_SIGNATURE_settable_ctx_params()\fR -return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7), \s-1\fBOSSL_PROVIDER\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_do_all_provided.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_do_all_provided.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_fetch.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_fetch.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_free.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_free.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_get0_description.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_get0_description.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_get0_name.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_get0_name.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_get0_provider.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_get0_provider.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_gettable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_gettable_ctx_params.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_gettable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_is_a.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_is_a.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_names_do_all.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_names_do_all.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_settable_ctx_params.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_settable_ctx_params.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SIGNATURE_up_ref.3ossl b/openssl-install/share/man/man3/EVP_SIGNATURE_up_ref.3ossl deleted file mode 120000 index 9afc17d4..00000000 --- a/openssl-install/share/man/man3/EVP_SIGNATURE_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SealFinal.3ossl b/openssl-install/share/man/man3/EVP_SealFinal.3ossl deleted file mode 120000 index 579d422a..00000000 --- a/openssl-install/share/man/man3/EVP_SealFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SealInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SealInit.3ossl b/openssl-install/share/man/man3/EVP_SealInit.3ossl deleted file mode 100644 index 7534418b..00000000 --- a/openssl-install/share/man/man3/EVP_SealInit.3ossl +++ /dev/null @@ -1,223 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SEALINIT 3ossl" -.TH EVP_SEALINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SealInit, EVP_SealUpdate, EVP_SealFinal \- EVP envelope encryption -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_SealInit(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *type, -\& unsigned char **ek, int *ekl, unsigned char *iv, -\& EVP_PKEY **pubk, int npubk); -\& int EVP_SealUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, -\& int *outl, unsigned char *in, int inl); -\& int EVP_SealFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 envelope routines are a high-level interface to envelope -encryption. They generate a random key and \s-1IV\s0 (if required) then -\&\*(L"envelope\*(R" it by using public key encryption. Data can then be -encrypted using this key. -.PP -\&\fBEVP_SealInit()\fR initializes a cipher context \fBctx\fR for encryption -with cipher \fBtype\fR using a random secret key and \s-1IV.\s0 \fBtype\fR is normally -supplied by a function such as \fBEVP_aes_256_cbc()\fR. The secret key is encrypted -using one or more public keys, this allows the same encrypted data to be -decrypted using any of the corresponding private keys. \fBek\fR is an array of -buffers where the public key encrypted secret key will be written, each buffer -must contain enough room for the corresponding encrypted key: that is -\&\fBek[i]\fR must have room for \fBEVP_PKEY_get_size(pubk[i])\fR bytes. The actual -size of each encrypted secret key is written to the array \fBekl\fR. \fBpubk\fR is -an array of \fBnpubk\fR public keys. -.PP -The \fBiv\fR parameter is a buffer where the generated \s-1IV\s0 is written to. It must -contain enough room for the corresponding cipher's \s-1IV,\s0 as determined by (for -example) EVP_CIPHER_get_iv_length(type). -.PP -If the cipher does not require an \s-1IV\s0 then the \fBiv\fR parameter is ignored -and can be \fB\s-1NULL\s0\fR. -.PP -\&\fBEVP_SealUpdate()\fR and \fBEVP_SealFinal()\fR have exactly the same properties -as the \fBEVP_EncryptUpdate()\fR and \fBEVP_EncryptFinal()\fR routines, as -documented on the \fBEVP_EncryptInit\fR\|(3) manual -page. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_SealInit()\fR returns 0 on error or \fBnpubk\fR if successful. -.PP -\&\fBEVP_SealUpdate()\fR and \fBEVP_SealFinal()\fR return 1 for success and 0 for -failure. -.SH "NOTES" -.IX Header "NOTES" -Because a random secret key is generated the random number generator -must be seeded when \fBEVP_SealInit()\fR is called. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.PP -The public key must be \s-1RSA\s0 because it is the only OpenSSL public key -algorithm that supports key transport. -.PP -Envelope encryption is the usual method of using public key encryption -on large amounts of data, this is because public key encryption is slow -but symmetric encryption is fast. So symmetric encryption is used for -bulk encryption and the small random symmetric key used is transferred -using public key encryption. -.PP -It is possible to call \fBEVP_SealInit()\fR twice in the same way as -\&\fBEVP_EncryptInit()\fR. The first call should have \fBnpubk\fR set to 0 -and (after setting any cipher parameters) it should be called again -with \fBtype\fR set to \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), \fBRAND_bytes\fR\|(3), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_OpenInit\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_SealUpdate.3ossl b/openssl-install/share/man/man3/EVP_SealUpdate.3ossl deleted file mode 120000 index 579d422a..00000000 --- a/openssl-install/share/man/man3/EVP_SealUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SealInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SignFinal.3ossl b/openssl-install/share/man/man3/EVP_SignFinal.3ossl deleted file mode 120000 index 50abdfb4..00000000 --- a/openssl-install/share/man/man3/EVP_SignFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SignFinal_ex.3ossl b/openssl-install/share/man/man3/EVP_SignFinal_ex.3ossl deleted file mode 120000 index 50abdfb4..00000000 --- a/openssl-install/share/man/man3/EVP_SignFinal_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SignInit.3ossl b/openssl-install/share/man/man3/EVP_SignInit.3ossl deleted file mode 100644 index 46fec541..00000000 --- a/openssl-install/share/man/man3/EVP_SignInit.3ossl +++ /dev/null @@ -1,248 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SIGNINIT 3ossl" -.TH EVP_SIGNINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SignInit, EVP_SignInit_ex, EVP_SignUpdate, -EVP_SignFinal_ex, EVP_SignFinal -\&\- EVP signing functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_SignInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl); -\& int EVP_SignUpdate(EVP_MD_CTX *ctx, const void *d, unsigned int cnt); -\& int EVP_SignFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s, -\& EVP_PKEY *pkey, OSSL_LIB_CTX *libctx, const char *propq); -\& int EVP_SignFinal(EVP_MD_CTX *ctx, unsigned char *sig, unsigned int *s, -\& EVP_PKEY *pkey); -\& -\& void EVP_SignInit(EVP_MD_CTX *ctx, const EVP_MD *type); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 signature routines are a high-level interface to digital -signatures. -.PP -\&\fBEVP_SignInit_ex()\fR sets up signing context \fIctx\fR to use digest -\&\fItype\fR from \fB\s-1ENGINE\s0\fR \fIimpl\fR. \fIctx\fR must be created with -\&\fBEVP_MD_CTX_new()\fR before calling this function. -.PP -\&\fBEVP_SignUpdate()\fR hashes \fIcnt\fR bytes of data at \fId\fR into the -signature context \fIctx\fR. This function can be called several times on the -same \fIctx\fR to include additional data. -.PP -\&\fBEVP_SignFinal_ex()\fR signs the data in \fIctx\fR using the private key -\&\fIpkey\fR and places the signature in \fIsig\fR. The library context \fIlibctx\fR and -property query \fIpropq\fR are used when creating a context to use with the key -\&\fIpkey\fR. \fIsig\fR must be at least \f(CW\*(C`EVP_PKEY_get_size(pkey)\*(C'\fR bytes in size. -\&\fIs\fR is an \s-1OUT\s0 parameter, and not used as an \s-1IN\s0 parameter. -The number of bytes of data written (i.e. the length of the signature) -will be written to the integer at \fIs\fR, at most \f(CW\*(C`EVP_PKEY_get_size(pkey)\*(C'\fR -bytes will be written. -.PP -\&\fBEVP_SignFinal()\fR is similar to \fBEVP_SignFinal_ex()\fR but uses default -values of \s-1NULL\s0 for the library context \fIlibctx\fR and the property query \fIpropq\fR. -.PP -\&\fBEVP_SignInit()\fR initializes a signing context \fIctx\fR to use the default -implementation of digest \fItype\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_SignInit_ex()\fR, \fBEVP_SignUpdate()\fR, \fBEVP_SignFinal_ex()\fR and -\&\fBEVP_SignFinal()\fR return 1 for success and 0 for failure. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The \fB\s-1EVP\s0\fR interface to digital signatures should almost always be used in -preference to the low-level interfaces. This is because the code then becomes -transparent to the algorithm used and much more flexible. -.PP -When signing with some private key types the random number generator must -be seeded. If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails -due to external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.PP -The call to \fBEVP_SignFinal()\fR internally finalizes a copy of the digest context. -This means that calls to \fBEVP_SignUpdate()\fR and \fBEVP_SignFinal()\fR can be called -later to digest and sign additional data.cApplications may disable this -behavior by setting the \s-1EVP_MD_CTX_FLAG_FINALISE\s0 context flag via -\&\fBEVP_MD_CTX_set_flags\fR\|(3). -.PP -Since only a copy of the digest context is ever finalized the context must -be cleaned up after use by calling \fBEVP_MD_CTX_free()\fR or a memory leak -will occur. -.PP -Note that not all providers support continuation, in case the selected -provider does not allow to duplicate contexts \fBEVP_SignFinal()\fR will -finalize the digest context and attempting to process additional data via -\&\fBEVP_SignUpdate()\fR will result in an error. -.SH "BUGS" -.IX Header "BUGS" -Older versions of this documentation wrongly stated that calls to -\&\fBEVP_SignUpdate()\fR could not be made after calling \fBEVP_SignFinal()\fR. -.PP -Since the private key is passed in the call to \fBEVP_SignFinal()\fR any error -relating to the private key (for example an unsuitable key and digest -combination) will not be indicated until after potentially large amounts of -data have been passed through \fBEVP_SignUpdate()\fR. -.PP -It is not possible to change the signing parameters using these function. -.PP -The previous two bugs are fixed in the newer EVP_DigestSign*() functions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_get_size\fR\|(3), \fBEVP_PKEY_get_bits\fR\|(3), -\&\fBEVP_PKEY_get_security_bits\fR\|(3), -\&\fBEVP_VerifyInit\fR\|(3), -\&\fBEVP_DigestInit\fR\|(3), -\&\fBevp\fR\|(7), \s-1\fBHMAC\s0\fR\|(3), \s-1\fBMD2\s0\fR\|(3), -\&\s-1\fBMD5\s0\fR\|(3), \s-1\fBMDC2\s0\fR\|(3), \s-1\fBRIPEMD160\s0\fR\|(3), -\&\s-1\fBSHA1\s0\fR\|(3), \fBopenssl\-dgst\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBEVP_SignFinal_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_SignInit_ex.3ossl b/openssl-install/share/man/man3/EVP_SignInit_ex.3ossl deleted file mode 120000 index 50abdfb4..00000000 --- a/openssl-install/share/man/man3/EVP_SignInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_SignUpdate.3ossl b/openssl-install/share/man/man3/EVP_SignUpdate.3ossl deleted file mode 120000 index 50abdfb4..00000000 --- a/openssl-install/share/man/man3/EVP_SignUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SignInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_VerifyFinal.3ossl b/openssl-install/share/man/man3/EVP_VerifyFinal.3ossl deleted file mode 120000 index 7cf7968e..00000000 --- a/openssl-install/share/man/man3/EVP_VerifyFinal.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_VerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_VerifyFinal_ex.3ossl b/openssl-install/share/man/man3/EVP_VerifyFinal_ex.3ossl deleted file mode 120000 index 7cf7968e..00000000 --- a/openssl-install/share/man/man3/EVP_VerifyFinal_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_VerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_VerifyInit.3ossl b/openssl-install/share/man/man3/EVP_VerifyInit.3ossl deleted file mode 100644 index dc5c405c..00000000 --- a/openssl-install/share/man/man3/EVP_VerifyInit.3ossl +++ /dev/null @@ -1,243 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_VERIFYINIT 3ossl" -.TH EVP_VERIFYINIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_VerifyInit_ex, -EVP_VerifyInit, EVP_VerifyUpdate, EVP_VerifyFinal_ex, EVP_VerifyFinal -\&\- EVP signature verification functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_VerifyInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl); -\& int EVP_VerifyUpdate(EVP_MD_CTX *ctx, const void *d, unsigned int cnt); -\& int EVP_VerifyFinal_ex(EVP_MD_CTX *ctx, const unsigned char *sigbuf, -\& unsigned int siglen, EVP_PKEY *pkey, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int EVP_VerifyFinal(EVP_MD_CTX *ctx, unsigned char *sigbuf, unsigned int siglen, -\& EVP_PKEY *pkey); -\& -\& int EVP_VerifyInit(EVP_MD_CTX *ctx, const EVP_MD *type); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 signature verification routines are a high-level interface to digital -signatures. -.PP -\&\fBEVP_VerifyInit_ex()\fR sets up verification context \fIctx\fR to use digest -\&\fItype\fR from \s-1ENGINE\s0 \fIimpl\fR. \fIctx\fR must be created by calling -\&\fBEVP_MD_CTX_new()\fR before calling this function. -.PP -\&\fBEVP_VerifyUpdate()\fR hashes \fIcnt\fR bytes of data at \fId\fR into the -verification context \fIctx\fR. This function can be called several times on the -same \fIctx\fR to include additional data. -.PP -\&\fBEVP_VerifyFinal_ex()\fR verifies the data in \fIctx\fR using the public key -\&\fIpkey\fR and \fIsiglen\fR bytes in \fIsigbuf\fR. -The library context \fIlibctx\fR and property query \fIpropq\fR are used when creating -a context to use with the key \fIpkey\fR. -.PP -\&\fBEVP_VerifyFinal()\fR is similar to \fBEVP_VerifyFinal_ex()\fR but uses default -values of \s-1NULL\s0 for the library context \fIlibctx\fR and the property query \fIpropq\fR. -.PP -\&\fBEVP_VerifyInit()\fR initializes verification context \fIctx\fR to use the default -implementation of digest \fItype\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_VerifyInit_ex()\fR and \fBEVP_VerifyUpdate()\fR return 1 for success and 0 for -failure. -.PP -\&\fBEVP_VerifyFinal_ex()\fR and \fBEVP_VerifyFinal()\fR return 1 for a correct -signature, 0 for failure and a negative value if some other error occurred. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The \fB\s-1EVP\s0\fR interface to digital signatures should almost always be used in -preference to the low-level interfaces. This is because the code then becomes -transparent to the algorithm used and much more flexible. -.PP -The call to \fBEVP_VerifyFinal()\fR internally finalizes a copy of the digest context. -This means that calls to \fBEVP_VerifyUpdate()\fR and \fBEVP_VerifyFinal()\fR can be called -later to digest and verify additional data. Applications may disable this -behavior by setting the \s-1EVP_MD_CTX_FLAG_FINALISE\s0 context flag via -\&\fBEVP_MD_CTX_set_flags\fR\|(3). -.PP -Since only a copy of the digest context is ever finalized the context must -be cleaned up after use by calling \fBEVP_MD_CTX_free()\fR or a memory leak -will occur. -.PP -Note that not all providers support continuation, in case the selected -provider does not allow to duplicate contexts \fBEVP_VerifyFinal()\fR will -finalize the digest context and attempting to process additional data via -\&\fBEVP_VerifyUpdate()\fR will result in an error. -.SH "BUGS" -.IX Header "BUGS" -Older versions of this documentation wrongly stated that calls to -\&\fBEVP_VerifyUpdate()\fR could not be made after calling \fBEVP_VerifyFinal()\fR. -.PP -Since the public key is passed in the call to \fBEVP_SignFinal()\fR any error -relating to the private key (for example an unsuitable key and digest -combination) will not be indicated until after potentially large amounts of -data have been passed through \fBEVP_SignUpdate()\fR. -.PP -It is not possible to change the signing parameters using these function. -.PP -The previous two bugs are fixed in the newer EVP_DigestVerify*() function. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_SignInit\fR\|(3), -\&\fBEVP_DigestInit\fR\|(3), -\&\fBevp\fR\|(7), \s-1\fBHMAC\s0\fR\|(3), \s-1\fBMD2\s0\fR\|(3), -\&\s-1\fBMD5\s0\fR\|(3), \s-1\fBMDC2\s0\fR\|(3), \s-1\fBRIPEMD160\s0\fR\|(3), -\&\s-1\fBSHA1\s0\fR\|(3), \fBopenssl\-dgst\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBEVP_VerifyFinal_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_VerifyInit_ex.3ossl b/openssl-install/share/man/man3/EVP_VerifyInit_ex.3ossl deleted file mode 120000 index 7cf7968e..00000000 --- a/openssl-install/share/man/man3/EVP_VerifyInit_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_VerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_VerifyUpdate.3ossl b/openssl-install/share/man/man3/EVP_VerifyUpdate.3ossl deleted file mode 120000 index 7cf7968e..00000000 --- a/openssl-install/share/man/man3/EVP_VerifyUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_VerifyInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_cbc.3ossl b/openssl-install/share/man/man3/EVP_aes_128_cbc.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha1.3ossl b/openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha1.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha256.3ossl b/openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha256.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_cbc_hmac_sha256.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_ccm.3ossl b/openssl-install/share/man/man3/EVP_aes_128_ccm.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_ccm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_cfb.3ossl b/openssl-install/share/man/man3/EVP_aes_128_cfb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_cfb1.3ossl b/openssl-install/share/man/man3/EVP_aes_128_cfb1.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_cfb128.3ossl b/openssl-install/share/man/man3/EVP_aes_128_cfb128.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_cfb8.3ossl b/openssl-install/share/man/man3/EVP_aes_128_cfb8.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_ctr.3ossl b/openssl-install/share/man/man3/EVP_aes_128_ctr.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_ecb.3ossl b/openssl-install/share/man/man3/EVP_aes_128_ecb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_gcm.3ossl b/openssl-install/share/man/man3/EVP_aes_128_gcm.3ossl deleted file mode 100644 index 93763341..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_gcm.3ossl +++ /dev/null @@ -1,274 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_AES_128_GCM 3ossl" -.TH EVP_AES_128_GCM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_aes_128_cbc, -EVP_aes_192_cbc, -EVP_aes_256_cbc, -EVP_aes_128_cfb, -EVP_aes_192_cfb, -EVP_aes_256_cfb, -EVP_aes_128_cfb1, -EVP_aes_192_cfb1, -EVP_aes_256_cfb1, -EVP_aes_128_cfb8, -EVP_aes_192_cfb8, -EVP_aes_256_cfb8, -EVP_aes_128_cfb128, -EVP_aes_192_cfb128, -EVP_aes_256_cfb128, -EVP_aes_128_ctr, -EVP_aes_192_ctr, -EVP_aes_256_ctr, -EVP_aes_128_ecb, -EVP_aes_192_ecb, -EVP_aes_256_ecb, -EVP_aes_128_ofb, -EVP_aes_192_ofb, -EVP_aes_256_ofb, -EVP_aes_128_cbc_hmac_sha1, -EVP_aes_256_cbc_hmac_sha1, -EVP_aes_128_cbc_hmac_sha256, -EVP_aes_256_cbc_hmac_sha256, -EVP_aes_128_ccm, -EVP_aes_192_ccm, -EVP_aes_256_ccm, -EVP_aes_128_gcm, -EVP_aes_192_gcm, -EVP_aes_256_gcm, -EVP_aes_128_ocb, -EVP_aes_192_ocb, -EVP_aes_256_ocb, -EVP_aes_128_wrap, -EVP_aes_192_wrap, -EVP_aes_256_wrap, -EVP_aes_128_wrap_pad, -EVP_aes_192_wrap_pad, -EVP_aes_256_wrap_pad, -EVP_aes_128_xts, -EVP_aes_256_xts -\&\- EVP AES cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_ciphername(void) -.Ve -.PP -\&\fIEVP_ciphername\fR is used a placeholder for any of the described cipher -functions, such as \fIEVP_aes_128_cbc\fR. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1AES\s0 encryption algorithm for \s-1EVP.\s0 -.IP "\fBEVP_aes_128_cbc()\fR, \fBEVP_aes_192_cbc()\fR, \fBEVP_aes_256_cbc()\fR, \fBEVP_aes_128_cfb()\fR, \fBEVP_aes_192_cfb()\fR, \fBEVP_aes_256_cfb()\fR, \fBEVP_aes_128_cfb1()\fR, \fBEVP_aes_192_cfb1()\fR, \fBEVP_aes_256_cfb1()\fR, \fBEVP_aes_128_cfb8()\fR, \fBEVP_aes_192_cfb8()\fR, \fBEVP_aes_256_cfb8()\fR, \fBEVP_aes_128_cfb128()\fR, \fBEVP_aes_192_cfb128()\fR, \fBEVP_aes_256_cfb128()\fR, \fBEVP_aes_128_ctr()\fR, \fBEVP_aes_192_ctr()\fR, \fBEVP_aes_256_ctr()\fR, \fBEVP_aes_128_ecb()\fR, \fBEVP_aes_192_ecb()\fR, \fBEVP_aes_256_ecb()\fR, \fBEVP_aes_128_ofb()\fR, \fBEVP_aes_192_ofb()\fR, \fBEVP_aes_256_ofb()\fR" 4 -.IX Item "EVP_aes_128_cbc(), EVP_aes_192_cbc(), EVP_aes_256_cbc(), EVP_aes_128_cfb(), EVP_aes_192_cfb(), EVP_aes_256_cfb(), EVP_aes_128_cfb1(), EVP_aes_192_cfb1(), EVP_aes_256_cfb1(), EVP_aes_128_cfb8(), EVP_aes_192_cfb8(), EVP_aes_256_cfb8(), EVP_aes_128_cfb128(), EVP_aes_192_cfb128(), EVP_aes_256_cfb128(), EVP_aes_128_ctr(), EVP_aes_192_ctr(), EVP_aes_256_ctr(), EVP_aes_128_ecb(), EVP_aes_192_ecb(), EVP_aes_256_ecb(), EVP_aes_128_ofb(), EVP_aes_192_ofb(), EVP_aes_256_ofb()" -\&\s-1AES\s0 for 128, 192 and 256 bit keys in the following modes: \s-1CBC, CFB\s0 with 128\-bit -shift, \s-1CFB\s0 with 1\-bit shift, \s-1CFB\s0 with 8\-bit shift, \s-1CTR, ECB,\s0 and \s-1OFB.\s0 -.IP "\fBEVP_aes_128_cbc_hmac_sha1()\fR, \fBEVP_aes_256_cbc_hmac_sha1()\fR" 4 -.IX Item "EVP_aes_128_cbc_hmac_sha1(), EVP_aes_256_cbc_hmac_sha1()" -Authenticated encryption with \s-1AES\s0 in \s-1CBC\s0 mode using \s-1SHA\-1\s0 as \s-1HMAC,\s0 with keys of -128 and 256 bits length respectively. The authentication tag is 160 bits long. -.Sp -\&\s-1WARNING:\s0 this is not intended for usage outside of \s-1TLS\s0 and requires calling of -some undocumented ctrl functions. These ciphers do not conform to the \s-1EVP AEAD\s0 -interface. -.IP "\fBEVP_aes_128_cbc_hmac_sha256()\fR, \fBEVP_aes_256_cbc_hmac_sha256()\fR" 4 -.IX Item "EVP_aes_128_cbc_hmac_sha256(), EVP_aes_256_cbc_hmac_sha256()" -Authenticated encryption with \s-1AES\s0 in \s-1CBC\s0 mode using \s-1SHA256\s0 (\s-1SHA\-2,\s0 256\-bits) as -\&\s-1HMAC,\s0 with keys of 128 and 256 bits length respectively. The authentication tag -is 256 bits long. -.Sp -\&\s-1WARNING:\s0 this is not intended for usage outside of \s-1TLS\s0 and requires calling of -some undocumented ctrl functions. These ciphers do not conform to the \s-1EVP AEAD\s0 -interface. -.IP "\fBEVP_aes_128_ccm()\fR, \fBEVP_aes_192_ccm()\fR, \fBEVP_aes_256_ccm()\fR, \fBEVP_aes_128_gcm()\fR, \fBEVP_aes_192_gcm()\fR, \fBEVP_aes_256_gcm()\fR, \fBEVP_aes_128_ocb()\fR, \fBEVP_aes_192_ocb()\fR, \fBEVP_aes_256_ocb()\fR" 4 -.IX Item "EVP_aes_128_ccm(), EVP_aes_192_ccm(), EVP_aes_256_ccm(), EVP_aes_128_gcm(), EVP_aes_192_gcm(), EVP_aes_256_gcm(), EVP_aes_128_ocb(), EVP_aes_192_ocb(), EVP_aes_256_ocb()" -\&\s-1AES\s0 for 128, 192 and 256 bit keys in CBC-MAC Mode (\s-1CCM\s0), Galois Counter Mode -(\s-1GCM\s0) and \s-1OCB\s0 Mode respectively. These ciphers require additional control -operations to function correctly, see the \*(L"\s-1AEAD\s0 Interface\*(R" in \fBEVP_EncryptInit\fR\|(3) -section for details. -.IP "\fBEVP_aes_128_wrap()\fR, \fBEVP_aes_192_wrap()\fR, \fBEVP_aes_256_wrap()\fR, \fBEVP_aes_128_wrap_pad()\fR, \fBEVP_aes_192_wrap_pad()\fR, \fBEVP_aes_256_wrap_pad()\fR" 4 -.IX Item "EVP_aes_128_wrap(), EVP_aes_192_wrap(), EVP_aes_256_wrap(), EVP_aes_128_wrap_pad(), EVP_aes_192_wrap_pad(), EVP_aes_256_wrap_pad()" -\&\s-1AES\s0 key wrap with 128, 192 and 256 bit keys, as according to \s-1RFC 3394\s0 section -2.2.1 (\*(L"wrap\*(R") and \s-1RFC 5649\s0 section 4.1 (\*(L"wrap with padding\*(R") respectively. -.IP "\fBEVP_aes_128_xts()\fR, \fBEVP_aes_256_xts()\fR" 4 -.IX Item "EVP_aes_128_xts(), EVP_aes_256_xts()" -\&\s-1AES XTS\s0 mode (XTS-AES) is standardized in \s-1IEEE\s0 Std. 1619\-2007 and described in \s-1NIST -SP 800\-38E.\s0 The \s-1XTS\s0 (XEX-based tweaked-codebook mode with ciphertext stealing) -mode was designed by Prof. Phillip Rogaway of University of California, Davis, -intended for encrypting data on a storage device. -.Sp -XTS-AES provides confidentiality but not authentication of data. It also -requires a key of double-length for protection of a certain key size. -In particular, \s-1XTS\-AES\-128\s0 (\fBEVP_aes_128_xts\fR) takes input of a 256\-bit key to -achieve \s-1AES\s0 128\-bit security, and \s-1XTS\-AES\-256\s0 (\fBEVP_aes_256_xts\fR) takes input -of a 512\-bit key to achieve \s-1AES\s0 256\-bit security. -.Sp -The \s-1XTS\s0 implementation in OpenSSL does not support streaming. That is there must -only be one \fBEVP_EncryptUpdate\fR\|(3) call per \fBEVP_EncryptInit_ex\fR\|(3) call (and -similarly with the \*(L"Decrypt\*(R" functions). -.Sp -The \fIiv\fR parameter to \fBEVP_EncryptInit_ex\fR\|(3) or \fBEVP_DecryptInit_ex\fR\|(3) is -the \s-1XTS\s0 \*(L"tweak\*(R" value. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-AES\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_aes_128_ocb.3ossl b/openssl-install/share/man/man3/EVP_aes_128_ocb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_ocb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_ofb.3ossl b/openssl-install/share/man/man3/EVP_aes_128_ofb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_wrap.3ossl b/openssl-install/share/man/man3/EVP_aes_128_wrap.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_wrap.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_wrap_pad.3ossl b/openssl-install/share/man/man3/EVP_aes_128_wrap_pad.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_wrap_pad.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_128_xts.3ossl b/openssl-install/share/man/man3/EVP_aes_128_xts.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_128_xts.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_cbc.3ossl b/openssl-install/share/man/man3/EVP_aes_192_cbc.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_ccm.3ossl b/openssl-install/share/man/man3/EVP_aes_192_ccm.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_ccm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_cfb.3ossl b/openssl-install/share/man/man3/EVP_aes_192_cfb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_cfb1.3ossl b/openssl-install/share/man/man3/EVP_aes_192_cfb1.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_cfb128.3ossl b/openssl-install/share/man/man3/EVP_aes_192_cfb128.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_cfb8.3ossl b/openssl-install/share/man/man3/EVP_aes_192_cfb8.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_ctr.3ossl b/openssl-install/share/man/man3/EVP_aes_192_ctr.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_ecb.3ossl b/openssl-install/share/man/man3/EVP_aes_192_ecb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_gcm.3ossl b/openssl-install/share/man/man3/EVP_aes_192_gcm.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_gcm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_ocb.3ossl b/openssl-install/share/man/man3/EVP_aes_192_ocb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_ocb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_ofb.3ossl b/openssl-install/share/man/man3/EVP_aes_192_ofb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_wrap.3ossl b/openssl-install/share/man/man3/EVP_aes_192_wrap.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_wrap.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_192_wrap_pad.3ossl b/openssl-install/share/man/man3/EVP_aes_192_wrap_pad.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_192_wrap_pad.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_cbc.3ossl b/openssl-install/share/man/man3/EVP_aes_256_cbc.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha1.3ossl b/openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha1.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha256.3ossl b/openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha256.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_cbc_hmac_sha256.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_ccm.3ossl b/openssl-install/share/man/man3/EVP_aes_256_ccm.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_ccm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_cfb.3ossl b/openssl-install/share/man/man3/EVP_aes_256_cfb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_cfb1.3ossl b/openssl-install/share/man/man3/EVP_aes_256_cfb1.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_cfb128.3ossl b/openssl-install/share/man/man3/EVP_aes_256_cfb128.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_cfb8.3ossl b/openssl-install/share/man/man3/EVP_aes_256_cfb8.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_ctr.3ossl b/openssl-install/share/man/man3/EVP_aes_256_ctr.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_ecb.3ossl b/openssl-install/share/man/man3/EVP_aes_256_ecb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_gcm.3ossl b/openssl-install/share/man/man3/EVP_aes_256_gcm.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_gcm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_ocb.3ossl b/openssl-install/share/man/man3/EVP_aes_256_ocb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_ocb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_ofb.3ossl b/openssl-install/share/man/man3/EVP_aes_256_ofb.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_wrap.3ossl b/openssl-install/share/man/man3/EVP_aes_256_wrap.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_wrap.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_wrap_pad.3ossl b/openssl-install/share/man/man3/EVP_aes_256_wrap_pad.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_wrap_pad.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aes_256_xts.3ossl b/openssl-install/share/man/man3/EVP_aes_256_xts.3ossl deleted file mode 120000 index f995a493..00000000 --- a/openssl-install/share/man/man3/EVP_aes_256_xts.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aes_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_cbc.3ossl b/openssl-install/share/man/man3/EVP_aria_128_cbc.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_ccm.3ossl b/openssl-install/share/man/man3/EVP_aria_128_ccm.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_ccm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_cfb.3ossl b/openssl-install/share/man/man3/EVP_aria_128_cfb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_cfb1.3ossl b/openssl-install/share/man/man3/EVP_aria_128_cfb1.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_cfb128.3ossl b/openssl-install/share/man/man3/EVP_aria_128_cfb128.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_cfb8.3ossl b/openssl-install/share/man/man3/EVP_aria_128_cfb8.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_ctr.3ossl b/openssl-install/share/man/man3/EVP_aria_128_ctr.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_ecb.3ossl b/openssl-install/share/man/man3/EVP_aria_128_ecb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_128_gcm.3ossl b/openssl-install/share/man/man3/EVP_aria_128_gcm.3ossl deleted file mode 100644 index f9c6b808..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_gcm.3ossl +++ /dev/null @@ -1,218 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_ARIA_128_GCM 3ossl" -.TH EVP_ARIA_128_GCM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_aria_128_cbc, -EVP_aria_192_cbc, -EVP_aria_256_cbc, -EVP_aria_128_cfb, -EVP_aria_192_cfb, -EVP_aria_256_cfb, -EVP_aria_128_cfb1, -EVP_aria_192_cfb1, -EVP_aria_256_cfb1, -EVP_aria_128_cfb8, -EVP_aria_192_cfb8, -EVP_aria_256_cfb8, -EVP_aria_128_cfb128, -EVP_aria_192_cfb128, -EVP_aria_256_cfb128, -EVP_aria_128_ctr, -EVP_aria_192_ctr, -EVP_aria_256_ctr, -EVP_aria_128_ecb, -EVP_aria_192_ecb, -EVP_aria_256_ecb, -EVP_aria_128_ofb, -EVP_aria_192_ofb, -EVP_aria_256_ofb, -EVP_aria_128_ccm, -EVP_aria_192_ccm, -EVP_aria_256_ccm, -EVP_aria_128_gcm, -EVP_aria_192_gcm, -EVP_aria_256_gcm, -\&\- EVP ARIA cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_ciphername(void) -.Ve -.PP -\&\fIEVP_ciphername\fR is used a placeholder for any of the described cipher -functions, such as \fIEVP_aria_128_cbc\fR. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1ARIA\s0 encryption algorithm for \s-1EVP.\s0 -.IP "\fBEVP_aria_128_cbc()\fR, \fBEVP_aria_192_cbc()\fR, \fBEVP_aria_256_cbc()\fR, \fBEVP_aria_128_cfb()\fR, \fBEVP_aria_192_cfb()\fR, \fBEVP_aria_256_cfb()\fR, \fBEVP_aria_128_cfb1()\fR, \fBEVP_aria_192_cfb1()\fR, \fBEVP_aria_256_cfb1()\fR, \fBEVP_aria_128_cfb8()\fR, \fBEVP_aria_192_cfb8()\fR, \fBEVP_aria_256_cfb8()\fR, \fBEVP_aria_128_cfb128()\fR, \fBEVP_aria_192_cfb128()\fR, \fBEVP_aria_256_cfb128()\fR, \fBEVP_aria_128_ctr()\fR, \fBEVP_aria_192_ctr()\fR, \fBEVP_aria_256_ctr()\fR, \fBEVP_aria_128_ecb()\fR, \fBEVP_aria_192_ecb()\fR, \fBEVP_aria_256_ecb()\fR, \fBEVP_aria_128_ofb()\fR, \fBEVP_aria_192_ofb()\fR, \fBEVP_aria_256_ofb()\fR" 4 -.IX Item "EVP_aria_128_cbc(), EVP_aria_192_cbc(), EVP_aria_256_cbc(), EVP_aria_128_cfb(), EVP_aria_192_cfb(), EVP_aria_256_cfb(), EVP_aria_128_cfb1(), EVP_aria_192_cfb1(), EVP_aria_256_cfb1(), EVP_aria_128_cfb8(), EVP_aria_192_cfb8(), EVP_aria_256_cfb8(), EVP_aria_128_cfb128(), EVP_aria_192_cfb128(), EVP_aria_256_cfb128(), EVP_aria_128_ctr(), EVP_aria_192_ctr(), EVP_aria_256_ctr(), EVP_aria_128_ecb(), EVP_aria_192_ecb(), EVP_aria_256_ecb(), EVP_aria_128_ofb(), EVP_aria_192_ofb(), EVP_aria_256_ofb()" -\&\s-1ARIA\s0 for 128, 192 and 256 bit keys in the following modes: \s-1CBC, CFB\s0 with -128\-bit shift, \s-1CFB\s0 with 1\-bit shift, \s-1CFB\s0 with 8\-bit shift, \s-1CTR, ECB\s0 and \s-1OFB.\s0 -.IP "\fBEVP_aria_128_ccm()\fR, \fBEVP_aria_192_ccm()\fR, \fBEVP_aria_256_ccm()\fR, \fBEVP_aria_128_gcm()\fR, \fBEVP_aria_192_gcm()\fR, \fBEVP_aria_256_gcm()\fR," 4 -.IX Item "EVP_aria_128_ccm(), EVP_aria_192_ccm(), EVP_aria_256_ccm(), EVP_aria_128_gcm(), EVP_aria_192_gcm(), EVP_aria_256_gcm()," -\&\s-1ARIA\s0 for 128, 192 and 256 bit keys in CBC-MAC Mode (\s-1CCM\s0) and Galois Counter -Mode (\s-1GCM\s0). These ciphers require additional control operations to function -correctly, see the \*(L"\s-1AEAD\s0 Interface\*(R" in \fBEVP_EncryptInit\fR\|(3) section for details. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-ARIA\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_aria_128_ofb.3ossl b/openssl-install/share/man/man3/EVP_aria_128_ofb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_128_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_cbc.3ossl b/openssl-install/share/man/man3/EVP_aria_192_cbc.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_ccm.3ossl b/openssl-install/share/man/man3/EVP_aria_192_ccm.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_ccm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_cfb.3ossl b/openssl-install/share/man/man3/EVP_aria_192_cfb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_cfb1.3ossl b/openssl-install/share/man/man3/EVP_aria_192_cfb1.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_cfb128.3ossl b/openssl-install/share/man/man3/EVP_aria_192_cfb128.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_cfb8.3ossl b/openssl-install/share/man/man3/EVP_aria_192_cfb8.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_ctr.3ossl b/openssl-install/share/man/man3/EVP_aria_192_ctr.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_ecb.3ossl b/openssl-install/share/man/man3/EVP_aria_192_ecb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_gcm.3ossl b/openssl-install/share/man/man3/EVP_aria_192_gcm.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_gcm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_192_ofb.3ossl b/openssl-install/share/man/man3/EVP_aria_192_ofb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_192_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_cbc.3ossl b/openssl-install/share/man/man3/EVP_aria_256_cbc.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_ccm.3ossl b/openssl-install/share/man/man3/EVP_aria_256_ccm.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_ccm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_cfb.3ossl b/openssl-install/share/man/man3/EVP_aria_256_cfb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_cfb1.3ossl b/openssl-install/share/man/man3/EVP_aria_256_cfb1.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_cfb128.3ossl b/openssl-install/share/man/man3/EVP_aria_256_cfb128.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_cfb8.3ossl b/openssl-install/share/man/man3/EVP_aria_256_cfb8.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_ctr.3ossl b/openssl-install/share/man/man3/EVP_aria_256_ctr.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_ecb.3ossl b/openssl-install/share/man/man3/EVP_aria_256_ecb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_gcm.3ossl b/openssl-install/share/man/man3/EVP_aria_256_gcm.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_gcm.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_aria_256_ofb.3ossl b/openssl-install/share/man/man3/EVP_aria_256_ofb.3ossl deleted file mode 120000 index 75dd83db..00000000 --- a/openssl-install/share/man/man3/EVP_aria_256_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_aria_128_gcm.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_bf_cbc.3ossl b/openssl-install/share/man/man3/EVP_bf_cbc.3ossl deleted file mode 100644 index afce4cb2..00000000 --- a/openssl-install/share/man/man3/EVP_bf_cbc.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_BF_CBC 3ossl" -.TH EVP_BF_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_bf_cbc, -EVP_bf_cfb, -EVP_bf_cfb64, -EVP_bf_ecb, -EVP_bf_ofb -\&\- EVP Blowfish cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_bf_cbc(void); -\& const EVP_CIPHER *EVP_bf_cfb(void); -\& const EVP_CIPHER *EVP_bf_cfb64(void); -\& const EVP_CIPHER *EVP_bf_ecb(void); -\& const EVP_CIPHER *EVP_bf_ofb(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The Blowfish encryption algorithm for \s-1EVP.\s0 -.PP -This is a variable key length cipher. -.IP "\fBEVP_bf_cbc()\fR, \fBEVP_bf_cfb()\fR, \fBEVP_bf_cfb64()\fR, \fBEVP_bf_ecb()\fR, \fBEVP_bf_ofb()\fR" 4 -.IX Item "EVP_bf_cbc(), EVP_bf_cfb(), EVP_bf_cfb64(), EVP_bf_ecb(), EVP_bf_ofb()" -Blowfish encryption algorithm in \s-1CBC, CFB, ECB\s0 and \s-1OFB\s0 modes respectively. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-BLOWFISH\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_bf_cfb.3ossl b/openssl-install/share/man/man3/EVP_bf_cfb.3ossl deleted file mode 120000 index f8b28131..00000000 --- a/openssl-install/share/man/man3/EVP_bf_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_bf_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_bf_cfb64.3ossl b/openssl-install/share/man/man3/EVP_bf_cfb64.3ossl deleted file mode 120000 index f8b28131..00000000 --- a/openssl-install/share/man/man3/EVP_bf_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_bf_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_bf_ecb.3ossl b/openssl-install/share/man/man3/EVP_bf_ecb.3ossl deleted file mode 120000 index f8b28131..00000000 --- a/openssl-install/share/man/man3/EVP_bf_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_bf_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_bf_ofb.3ossl b/openssl-install/share/man/man3/EVP_bf_ofb.3ossl deleted file mode 120000 index f8b28131..00000000 --- a/openssl-install/share/man/man3/EVP_bf_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_bf_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_blake2b512.3ossl b/openssl-install/share/man/man3/EVP_blake2b512.3ossl deleted file mode 100644 index f8bbb073..00000000 --- a/openssl-install/share/man/man3/EVP_blake2b512.3ossl +++ /dev/null @@ -1,192 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_BLAKE2B512 3ossl" -.TH EVP_BLAKE2B512 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_blake2b512, -EVP_blake2s256 -\&\- BLAKE2 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_blake2b512(void); -\& const EVP_MD *EVP_blake2s256(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1BLAKE2\s0 is an improved version of \s-1BLAKE,\s0 which was submitted to the \s-1NIST SHA\-3\s0 -algorithm competition. The BLAKE2s and BLAKE2b algorithms are described in -\&\s-1RFC 7693.\s0 -.IP "\fBEVP_blake2s256()\fR" 4 -.IX Item "EVP_blake2s256()" -The BLAKE2s algorithm that produces a 256\-bit output from a given input. -.IP "\fBEVP_blake2b512()\fR" 4 -.IX Item "EVP_blake2b512()" -The BLAKE2b algorithm that produces a 512\-bit output from a given input. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-BLAKE2\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.PP -Both algorithms support a variable-length digest, -but this is only available through \s-1\fBEVP_MD\-BLAKE2\s0\fR\|(7). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 7693.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_blake2s256.3ossl b/openssl-install/share/man/man3/EVP_blake2s256.3ossl deleted file mode 120000 index 5073438d..00000000 --- a/openssl-install/share/man/man3/EVP_blake2s256.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_blake2b512.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_128_cbc.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_cbc.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_128_cfb.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_cfb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_128_cfb1.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_cfb1.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_128_cfb128.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_cfb128.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_128_cfb8.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_cfb8.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_128_ctr.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_ctr.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_128_ecb.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_ecb.3ossl deleted file mode 100644 index 61b3cb0c..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_ecb.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CAMELLIA_128_ECB 3ossl" -.TH EVP_CAMELLIA_128_ECB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_camellia_128_cbc, -EVP_camellia_192_cbc, -EVP_camellia_256_cbc, -EVP_camellia_128_cfb, -EVP_camellia_192_cfb, -EVP_camellia_256_cfb, -EVP_camellia_128_cfb1, -EVP_camellia_192_cfb1, -EVP_camellia_256_cfb1, -EVP_camellia_128_cfb8, -EVP_camellia_192_cfb8, -EVP_camellia_256_cfb8, -EVP_camellia_128_cfb128, -EVP_camellia_192_cfb128, -EVP_camellia_256_cfb128, -EVP_camellia_128_ctr, -EVP_camellia_192_ctr, -EVP_camellia_256_ctr, -EVP_camellia_128_ecb, -EVP_camellia_192_ecb, -EVP_camellia_256_ecb, -EVP_camellia_128_ofb, -EVP_camellia_192_ofb, -EVP_camellia_256_ofb -\&\- EVP Camellia cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_ciphername(void) -.Ve -.PP -\&\fIEVP_ciphername\fR is used a placeholder for any of the described cipher -functions, such as \fIEVP_camellia_128_cbc\fR. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The Camellia encryption algorithm for \s-1EVP.\s0 -.IP "\fBEVP_camellia_128_cbc()\fR, \fBEVP_camellia_192_cbc()\fR, \fBEVP_camellia_256_cbc()\fR, \fBEVP_camellia_128_cfb()\fR, \fBEVP_camellia_192_cfb()\fR, \fBEVP_camellia_256_cfb()\fR, \fBEVP_camellia_128_cfb1()\fR, \fBEVP_camellia_192_cfb1()\fR, \fBEVP_camellia_256_cfb1()\fR, \fBEVP_camellia_128_cfb8()\fR, \fBEVP_camellia_192_cfb8()\fR, \fBEVP_camellia_256_cfb8()\fR, \fBEVP_camellia_128_cfb128()\fR, \fBEVP_camellia_192_cfb128()\fR, \fBEVP_camellia_256_cfb128()\fR, \fBEVP_camellia_128_ctr()\fR, \fBEVP_camellia_192_ctr()\fR, \fBEVP_camellia_256_ctr()\fR, \fBEVP_camellia_128_ecb()\fR, \fBEVP_camellia_192_ecb()\fR, \fBEVP_camellia_256_ecb()\fR, \fBEVP_camellia_128_ofb()\fR, \fBEVP_camellia_192_ofb()\fR, \fBEVP_camellia_256_ofb()\fR" 4 -.IX Item "EVP_camellia_128_cbc(), EVP_camellia_192_cbc(), EVP_camellia_256_cbc(), EVP_camellia_128_cfb(), EVP_camellia_192_cfb(), EVP_camellia_256_cfb(), EVP_camellia_128_cfb1(), EVP_camellia_192_cfb1(), EVP_camellia_256_cfb1(), EVP_camellia_128_cfb8(), EVP_camellia_192_cfb8(), EVP_camellia_256_cfb8(), EVP_camellia_128_cfb128(), EVP_camellia_192_cfb128(), EVP_camellia_256_cfb128(), EVP_camellia_128_ctr(), EVP_camellia_192_ctr(), EVP_camellia_256_ctr(), EVP_camellia_128_ecb(), EVP_camellia_192_ecb(), EVP_camellia_256_ecb(), EVP_camellia_128_ofb(), EVP_camellia_192_ofb(), EVP_camellia_256_ofb()" -Camellia for 128, 192 and 256 bit keys in the following modes: \s-1CBC, CFB\s0 with -128\-bit shift, \s-1CFB\s0 with 1\-bit shift, \s-1CFB\s0 with 8\-bit shift, \s-1CTR, ECB\s0 and \s-1OFB.\s0 -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-CAMELLIA\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_camellia_128_ofb.3ossl b/openssl-install/share/man/man3/EVP_camellia_128_ofb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_128_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_cbc.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_cbc.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_cfb.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_cfb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_cfb1.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_cfb1.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_cfb128.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_cfb128.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_cfb8.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_cfb8.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_ctr.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_ctr.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_ecb.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_ecb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_192_ofb.3ossl b/openssl-install/share/man/man3/EVP_camellia_192_ofb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_192_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_cbc.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_cbc.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_cfb.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_cfb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_cfb1.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_cfb1.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_cfb128.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_cfb128.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_cfb8.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_cfb8.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_ctr.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_ctr.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_ecb.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_ecb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_camellia_256_ofb.3ossl b/openssl-install/share/man/man3/EVP_camellia_256_ofb.3ossl deleted file mode 120000 index ef705e4a..00000000 --- a/openssl-install/share/man/man3/EVP_camellia_256_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_camellia_128_ecb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_cast5_cbc.3ossl b/openssl-install/share/man/man3/EVP_cast5_cbc.3ossl deleted file mode 100644 index d9be69d7..00000000 --- a/openssl-install/share/man/man3/EVP_cast5_cbc.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CAST5_CBC 3ossl" -.TH EVP_CAST5_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_cast5_cbc, -EVP_cast5_cfb, -EVP_cast5_cfb64, -EVP_cast5_ecb, -EVP_cast5_ofb -\&\- EVP CAST cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_cast5_cbc(void); -\& const EVP_CIPHER *EVP_cast5_cfb(void); -\& const EVP_CIPHER *EVP_cast5_cfb64(void); -\& const EVP_CIPHER *EVP_cast5_ecb(void); -\& const EVP_CIPHER *EVP_cast5_ofb(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1CAST\s0 encryption algorithm for \s-1EVP.\s0 -.PP -This is a variable key length cipher. -.IP "\fBEVP_cast5_cbc()\fR, \fBEVP_cast5_ecb()\fR, \fBEVP_cast5_cfb()\fR, \fBEVP_cast5_cfb64()\fR, \fBEVP_cast5_ofb()\fR" 4 -.IX Item "EVP_cast5_cbc(), EVP_cast5_ecb(), EVP_cast5_cfb(), EVP_cast5_cfb64(), EVP_cast5_ofb()" -\&\s-1CAST\s0 encryption algorithm in \s-1CBC, ECB, CFB\s0 and \s-1OFB\s0 modes respectively. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-CAST\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_cast5_cfb.3ossl b/openssl-install/share/man/man3/EVP_cast5_cfb.3ossl deleted file mode 120000 index 48c68193..00000000 --- a/openssl-install/share/man/man3/EVP_cast5_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_cast5_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_cast5_cfb64.3ossl b/openssl-install/share/man/man3/EVP_cast5_cfb64.3ossl deleted file mode 120000 index 48c68193..00000000 --- a/openssl-install/share/man/man3/EVP_cast5_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_cast5_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_cast5_ecb.3ossl b/openssl-install/share/man/man3/EVP_cast5_ecb.3ossl deleted file mode 120000 index 48c68193..00000000 --- a/openssl-install/share/man/man3/EVP_cast5_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_cast5_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_cast5_ofb.3ossl b/openssl-install/share/man/man3/EVP_cast5_ofb.3ossl deleted file mode 120000 index 48c68193..00000000 --- a/openssl-install/share/man/man3/EVP_cast5_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_cast5_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_chacha20.3ossl b/openssl-install/share/man/man3/EVP_chacha20.3ossl deleted file mode 100644 index 3709e67f..00000000 --- a/openssl-install/share/man/man3/EVP_chacha20.3ossl +++ /dev/null @@ -1,199 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CHACHA20 3ossl" -.TH EVP_CHACHA20 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_chacha20, -EVP_chacha20_poly1305 -\&\- EVP ChaCha20 stream cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_chacha20(void); -\& const EVP_CIPHER *EVP_chacha20_poly1305(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The ChaCha20 stream cipher for \s-1EVP.\s0 -.IP "\fBEVP_chacha20()\fR" 4 -.IX Item "EVP_chacha20()" -The ChaCha20 stream cipher. The key length is 256 bits, the \s-1IV\s0 is 128 bits long. -The first 64 bits consists of a counter in little-endian order followed by a 64 -bit nonce. For example a nonce of: -.Sp -0000000000000002 -.Sp -With an initial counter of 42 (2a in hex) would be expressed as: -.Sp -2a000000000000000000000000000002 -.IP "\fBEVP_chacha20_poly1305()\fR" 4 -.IX Item "EVP_chacha20_poly1305()" -Authenticated encryption with ChaCha20\-Poly1305. Like \fBEVP_chacha20()\fR, the key -is 256 bits and the \s-1IV\s0 is 96 bits. This supports additional authenticated data -(\s-1AAD\s0) and produces a 128\-bit authentication tag. See the -\&\*(L"\s-1AEAD\s0 Interface\*(R" in \fBEVP_EncryptInit\fR\|(3) section for more information. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-CHACHA\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.PP -\&\s-1RFC 7539\s0 -uses a 32 bit counter and a 96 bit nonce for the \s-1IV.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_chacha20_poly1305.3ossl b/openssl-install/share/man/man3/EVP_chacha20_poly1305.3ossl deleted file mode 120000 index a50d355a..00000000 --- a/openssl-install/share/man/man3/EVP_chacha20_poly1305.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_chacha20.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_cleanup.3ossl b/openssl-install/share/man/man3/EVP_cleanup.3ossl deleted file mode 120000 index 741d473b..00000000 --- a/openssl-install/share/man/man3/EVP_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_add_all_algorithms.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_default_properties_enable_fips.3ossl b/openssl-install/share/man/man3/EVP_default_properties_enable_fips.3ossl deleted file mode 120000 index 1f943191..00000000 --- a/openssl-install/share/man/man3/EVP_default_properties_enable_fips.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_set_default_properties.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_default_properties_is_fips_enabled.3ossl b/openssl-install/share/man/man3/EVP_default_properties_is_fips_enabled.3ossl deleted file mode 120000 index 1f943191..00000000 --- a/openssl-install/share/man/man3/EVP_default_properties_is_fips_enabled.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_set_default_properties.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_cbc.3ossl b/openssl-install/share/man/man3/EVP_des_cbc.3ossl deleted file mode 100644 index fb801917..00000000 --- a/openssl-install/share/man/man3/EVP_des_cbc.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_DES_CBC 3ossl" -.TH EVP_DES_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_des_cbc, -EVP_des_cfb, -EVP_des_cfb1, -EVP_des_cfb8, -EVP_des_cfb64, -EVP_des_ecb, -EVP_des_ofb, -EVP_des_ede, -EVP_des_ede_cbc, -EVP_des_ede_cfb, -EVP_des_ede_cfb64, -EVP_des_ede_ecb, -EVP_des_ede_ofb, -EVP_des_ede3, -EVP_des_ede3_cbc, -EVP_des_ede3_cfb, -EVP_des_ede3_cfb1, -EVP_des_ede3_cfb8, -EVP_des_ede3_cfb64, -EVP_des_ede3_ecb, -EVP_des_ede3_ofb, -EVP_des_ede3_wrap -\&\- EVP DES cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_ciphername(void) -.Ve -.PP -\&\fIEVP_ciphername\fR is used a placeholder for any of the described cipher -functions, such as \fIEVP_des_cbc\fR. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1DES\s0 encryption algorithm for \s-1EVP.\s0 -.IP "\fBEVP_des_cbc()\fR, \fBEVP_des_ecb()\fR, \fBEVP_des_cfb()\fR, \fBEVP_des_cfb1()\fR, \fBEVP_des_cfb8()\fR, \fBEVP_des_cfb64()\fR, \fBEVP_des_ofb()\fR" 4 -.IX Item "EVP_des_cbc(), EVP_des_ecb(), EVP_des_cfb(), EVP_des_cfb1(), EVP_des_cfb8(), EVP_des_cfb64(), EVP_des_ofb()" -\&\s-1DES\s0 in \s-1CBC, ECB, CFB\s0 with 64\-bit shift, \s-1CFB\s0 with 1\-bit shift, \s-1CFB\s0 with 8\-bit -shift and \s-1OFB\s0 modes. -.Sp -None of these algorithms are provided by the OpenSSL default provider. -To use them it is necessary to load either the OpenSSL legacy provider or another -implementation. -.IP "\fBEVP_des_ede()\fR, \fBEVP_des_ede_cbc()\fR, \fBEVP_des_ede_cfb()\fR, \fBEVP_des_ede_cfb64()\fR, \fBEVP_des_ede_ecb()\fR, \fBEVP_des_ede_ofb()\fR" 4 -.IX Item "EVP_des_ede(), EVP_des_ede_cbc(), EVP_des_ede_cfb(), EVP_des_ede_cfb64(), EVP_des_ede_ecb(), EVP_des_ede_ofb()" -Two key triple \s-1DES\s0 in \s-1ECB, CBC, CFB\s0 with 64\-bit shift and \s-1OFB\s0 modes. -.IP "\fBEVP_des_ede3()\fR, \fBEVP_des_ede3_cbc()\fR, \fBEVP_des_ede3_cfb()\fR, \fBEVP_des_ede3_cfb1()\fR, \fBEVP_des_ede3_cfb8()\fR, \fBEVP_des_ede3_cfb64()\fR, \fBEVP_des_ede3_ecb()\fR, \fBEVP_des_ede3_ofb()\fR" 4 -.IX Item "EVP_des_ede3(), EVP_des_ede3_cbc(), EVP_des_ede3_cfb(), EVP_des_ede3_cfb1(), EVP_des_ede3_cfb8(), EVP_des_ede3_cfb64(), EVP_des_ede3_ecb(), EVP_des_ede3_ofb()" -Three-key triple \s-1DES\s0 in \s-1ECB, CBC, CFB\s0 with 64\-bit shift, \s-1CFB\s0 with 1\-bit shift, -\&\s-1CFB\s0 with 8\-bit shift and \s-1OFB\s0 modes. -.IP "\fBEVP_des_ede3_wrap()\fR" 4 -.IX Item "EVP_des_ede3_wrap()" -Triple-DES key wrap according to \s-1RFC 3217\s0 Section 3. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-DES\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_des_cfb.3ossl b/openssl-install/share/man/man3/EVP_des_cfb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_cfb1.3ossl b/openssl-install/share/man/man3/EVP_des_cfb1.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_cfb64.3ossl b/openssl-install/share/man/man3/EVP_des_cfb64.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_cfb8.3ossl b/openssl-install/share/man/man3/EVP_des_cfb8.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ecb.3ossl b/openssl-install/share/man/man3/EVP_des_ecb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede.3ossl b/openssl-install/share/man/man3/EVP_des_ede.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3.3ossl b/openssl-install/share/man/man3/EVP_des_ede3.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_cbc.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_cbc.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_cfb.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_cfb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_cfb1.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_cfb1.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_cfb1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_cfb64.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_cfb64.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_cfb8.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_cfb8.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_cfb8.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_ecb.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_ecb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_ofb.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_ofb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede3_wrap.3ossl b/openssl-install/share/man/man3/EVP_des_ede3_wrap.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede3_wrap.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede_cbc.3ossl b/openssl-install/share/man/man3/EVP_des_ede_cbc.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede_cfb.3ossl b/openssl-install/share/man/man3/EVP_des_ede_cfb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede_cfb64.3ossl b/openssl-install/share/man/man3/EVP_des_ede_cfb64.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede_ecb.3ossl b/openssl-install/share/man/man3/EVP_des_ede_ecb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ede_ofb.3ossl b/openssl-install/share/man/man3/EVP_des_ede_ofb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ede_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_des_ofb.3ossl b/openssl-install/share/man/man3/EVP_des_ofb.3ossl deleted file mode 120000 index 3ae88873..00000000 --- a/openssl-install/share/man/man3/EVP_des_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_des_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_desx_cbc.3ossl b/openssl-install/share/man/man3/EVP_desx_cbc.3ossl deleted file mode 100644 index 3cf0cc37..00000000 --- a/openssl-install/share/man/man3/EVP_desx_cbc.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_DESX_CBC 3ossl" -.TH EVP_DESX_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_desx_cbc -\&\- EVP DES\-X cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_desx_cbc(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The DES-X encryption algorithm for \s-1EVP.\s0 -.PP -All modes below use a key length of 128 bits and acts on blocks of 128\-bits. -.IP "\fBEVP_desx_cbc()\fR" 4 -.IX Item "EVP_desx_cbc()" -The DES-X algorithm in \s-1CBC\s0 mode. -.Sp -This algorithm is not provided by the OpenSSL default provider. -To use it is necessary to load either the OpenSSL legacy provider or another -implementation. -.PP -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-DES\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_enc_null.3ossl b/openssl-install/share/man/man3/EVP_enc_null.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_enc_null.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_get_cipherbyname.3ossl b/openssl-install/share/man/man3/EVP_get_cipherbyname.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_get_cipherbyname.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_get_cipherbynid.3ossl b/openssl-install/share/man/man3/EVP_get_cipherbynid.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_get_cipherbynid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_get_cipherbyobj.3ossl b/openssl-install/share/man/man3/EVP_get_cipherbyobj.3ossl deleted file mode 120000 index efefb3dd..00000000 --- a/openssl-install/share/man/man3/EVP_get_cipherbyobj.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_EncryptInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_get_digestbyname.3ossl b/openssl-install/share/man/man3/EVP_get_digestbyname.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_get_digestbyname.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_get_digestbynid.3ossl b/openssl-install/share/man/man3/EVP_get_digestbynid.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_get_digestbynid.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_get_digestbyobj.3ossl b/openssl-install/share/man/man3/EVP_get_digestbyobj.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_get_digestbyobj.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_idea_cbc.3ossl b/openssl-install/share/man/man3/EVP_idea_cbc.3ossl deleted file mode 100644 index f835e18d..00000000 --- a/openssl-install/share/man/man3/EVP_idea_cbc.3ossl +++ /dev/null @@ -1,188 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_IDEA_CBC 3ossl" -.TH EVP_IDEA_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_idea_cbc, -EVP_idea_cfb, -EVP_idea_cfb64, -EVP_idea_ecb, -EVP_idea_ofb -\&\- EVP IDEA cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_idea_cbc(void); -\& const EVP_CIPHER *EVP_idea_cfb(void); -\& const EVP_CIPHER *EVP_idea_cfb64(void); -\& const EVP_CIPHER *EVP_idea_ecb(void); -\& const EVP_CIPHER *EVP_idea_ofb(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1IDEA\s0 encryption algorithm for \s-1EVP.\s0 -.IP "\fBEVP_idea_cbc()\fR, \fBEVP_idea_cfb()\fR, \fBEVP_idea_cfb64()\fR, \fBEVP_idea_ecb()\fR, \fBEVP_idea_ofb()\fR" 4 -.IX Item "EVP_idea_cbc(), EVP_idea_cfb(), EVP_idea_cfb64(), EVP_idea_ecb(), EVP_idea_ofb()" -The \s-1IDEA\s0 encryption algorithm in \s-1CBC, CFB, ECB\s0 and \s-1OFB\s0 modes respectively. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-IDEA\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_idea_cfb.3ossl b/openssl-install/share/man/man3/EVP_idea_cfb.3ossl deleted file mode 120000 index a61ae8cd..00000000 --- a/openssl-install/share/man/man3/EVP_idea_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_idea_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_idea_cfb64.3ossl b/openssl-install/share/man/man3/EVP_idea_cfb64.3ossl deleted file mode 120000 index a61ae8cd..00000000 --- a/openssl-install/share/man/man3/EVP_idea_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_idea_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_idea_ecb.3ossl b/openssl-install/share/man/man3/EVP_idea_ecb.3ossl deleted file mode 120000 index a61ae8cd..00000000 --- a/openssl-install/share/man/man3/EVP_idea_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_idea_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_idea_ofb.3ossl b/openssl-install/share/man/man3/EVP_idea_ofb.3ossl deleted file mode 120000 index a61ae8cd..00000000 --- a/openssl-install/share/man/man3/EVP_idea_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_idea_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_md2.3ossl b/openssl-install/share/man/man3/EVP_md2.3ossl deleted file mode 100644 index d80e4b50..00000000 --- a/openssl-install/share/man/man3/EVP_md2.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD2 3ossl" -.TH EVP_MD2 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_md2 -\&\- MD2 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_md2(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1MD2\s0 is a cryptographic hash function standardized in \s-1RFC 1319\s0 and designed by -Ronald Rivest. This implementation is only available with the legacy provider. -.IP "\fBEVP_md2()\fR" 4 -.IX Item "EVP_md2()" -The \s-1MD2\s0 algorithm which produces a 128\-bit output from a given input. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-MD2\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 1319.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBprovider\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_md4.3ossl b/openssl-install/share/man/man3/EVP_md4.3ossl deleted file mode 100644 index f394fc41..00000000 --- a/openssl-install/share/man/man3/EVP_md4.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD4 3ossl" -.TH EVP_MD4 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_md4 -\&\- MD4 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_md4(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1MD4\s0 is a cryptographic hash function standardized in \s-1RFC 1320\s0 and designed by -Ronald Rivest, first published in 1990. This implementation is only available -with the legacy provider. -.IP "\fBEVP_md4()\fR" 4 -.IX Item "EVP_md4()" -The \s-1MD4\s0 algorithm which produces a 128\-bit output from a given input. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-MD4\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 1320.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBprovider\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_md5.3ossl b/openssl-install/share/man/man3/EVP_md5.3ossl deleted file mode 100644 index 09bd8c33..00000000 --- a/openssl-install/share/man/man3/EVP_md5.3ossl +++ /dev/null @@ -1,194 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD5 3ossl" -.TH EVP_MD5 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_md5, -EVP_md5_sha1 -\&\- MD5 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_md5(void); -\& const EVP_MD *EVP_md5_sha1(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1MD5\s0 is a cryptographic hash function standardized in \s-1RFC 1321\s0 and designed by -Ronald Rivest. -.PP -The \s-1CMU\s0 Software Engineering Institute considers \s-1MD5\s0 unsuitable for further -use since its security has been severely compromised. -.IP "\fBEVP_md5()\fR" 4 -.IX Item "EVP_md5()" -The \s-1MD5\s0 algorithm which produces a 128\-bit output from a given input. -.IP "\fBEVP_md5_sha1()\fR" 4 -.IX Item "EVP_md5_sha1()" -A hash algorithm of \s-1SSL\s0 v3 that combines \s-1MD5\s0 with \s-1SHA\-1\s0 as described in \s-1RFC -6101.\s0 -.Sp -\&\s-1WARNING:\s0 this algorithm is not intended for non-SSL usage. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-MD5\s0\fR\|(7) or \s-1\fBEVP_MD\-MD5\-SHA1\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 1321.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_md5_sha1.3ossl b/openssl-install/share/man/man3/EVP_md5_sha1.3ossl deleted file mode 120000 index 24ecc4a8..00000000 --- a/openssl-install/share/man/man3/EVP_md5_sha1.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_md5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_md_null.3ossl b/openssl-install/share/man/man3/EVP_md_null.3ossl deleted file mode 120000 index b09b8c57..00000000 --- a/openssl-install/share/man/man3/EVP_md_null.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_DigestInit.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_mdc2.3ossl b/openssl-install/share/man/man3/EVP_mdc2.3ossl deleted file mode 100644 index 107691b7..00000000 --- a/openssl-install/share/man/man3/EVP_mdc2.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MDC2 3ossl" -.TH EVP_MDC2 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_mdc2 -\&\- MDC\-2 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_mdc2(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1MDC\-2\s0 (Modification Detection Code 2 or Meyer-Schilling) is a cryptographic -hash function based on a block cipher. This implementation is only available -with the legacy provider. -.IP "\fBEVP_mdc2()\fR" 4 -.IX Item "EVP_mdc2()" -The \s-1MDC\-2DES\s0 algorithm of using \s-1MDC\-2\s0 with the \s-1DES\s0 block cipher. It produces a -128\-bit output from a given input. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-MDC2\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ISO/IEC 10118\-2:2000\s0 Hash-Function 2, with \s-1DES\s0 as the underlying block cipher. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBprovider\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_rc2_40_cbc.3ossl b/openssl-install/share/man/man3/EVP_rc2_40_cbc.3ossl deleted file mode 120000 index a106f493..00000000 --- a/openssl-install/share/man/man3/EVP_rc2_40_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc2_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc2_64_cbc.3ossl b/openssl-install/share/man/man3/EVP_rc2_64_cbc.3ossl deleted file mode 120000 index a106f493..00000000 --- a/openssl-install/share/man/man3/EVP_rc2_64_cbc.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc2_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc2_cbc.3ossl b/openssl-install/share/man/man3/EVP_rc2_cbc.3ossl deleted file mode 100644 index 8c5963d9..00000000 --- a/openssl-install/share/man/man3/EVP_rc2_cbc.3ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RC2_CBC 3ossl" -.TH EVP_RC2_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_rc2_cbc, -EVP_rc2_cfb, -EVP_rc2_cfb64, -EVP_rc2_ecb, -EVP_rc2_ofb, -EVP_rc2_40_cbc, -EVP_rc2_64_cbc -\&\- EVP RC2 cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_rc2_cbc(void); -\& const EVP_CIPHER *EVP_rc2_cfb(void); -\& const EVP_CIPHER *EVP_rc2_cfb64(void); -\& const EVP_CIPHER *EVP_rc2_ecb(void); -\& const EVP_CIPHER *EVP_rc2_ofb(void); -\& const EVP_CIPHER *EVP_rc2_40_cbc(void); -\& const EVP_CIPHER *EVP_rc2_64_cbc(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1RC2\s0 encryption algorithm for \s-1EVP.\s0 -.IP "\fBEVP_rc2_cbc()\fR, \fBEVP_rc2_cfb()\fR, \fBEVP_rc2_cfb64()\fR, \fBEVP_rc2_ecb()\fR, \fBEVP_rc2_ofb()\fR" 4 -.IX Item "EVP_rc2_cbc(), EVP_rc2_cfb(), EVP_rc2_cfb64(), EVP_rc2_ecb(), EVP_rc2_ofb()" -\&\s-1RC2\s0 encryption algorithm in \s-1CBC, CFB, ECB\s0 and \s-1OFB\s0 modes respectively. This is a -variable key length cipher with an additional parameter called \*(L"effective key -bits\*(R" or \*(L"effective key length\*(R". By default both are set to 128 bits. -.IP "\fBEVP_rc2_40_cbc()\fR, \fBEVP_rc2_64_cbc()\fR" 4 -.IX Item "EVP_rc2_40_cbc(), EVP_rc2_64_cbc()" -\&\s-1RC2\s0 algorithm in \s-1CBC\s0 mode with a default key length and effective key length of -40 and 64 bits. -.Sp -\&\s-1WARNING:\s0 these functions are obsolete. Their usage should be replaced with the -\&\fBEVP_rc2_cbc()\fR, \fBEVP_CIPHER_CTX_set_key_length()\fR and \fBEVP_CIPHER_CTX_ctrl()\fR -functions to set the key length and effective key length. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-RC2\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_rc2_cfb.3ossl b/openssl-install/share/man/man3/EVP_rc2_cfb.3ossl deleted file mode 120000 index a106f493..00000000 --- a/openssl-install/share/man/man3/EVP_rc2_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc2_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc2_cfb64.3ossl b/openssl-install/share/man/man3/EVP_rc2_cfb64.3ossl deleted file mode 120000 index a106f493..00000000 --- a/openssl-install/share/man/man3/EVP_rc2_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc2_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc2_ecb.3ossl b/openssl-install/share/man/man3/EVP_rc2_ecb.3ossl deleted file mode 120000 index a106f493..00000000 --- a/openssl-install/share/man/man3/EVP_rc2_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc2_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc2_ofb.3ossl b/openssl-install/share/man/man3/EVP_rc2_ofb.3ossl deleted file mode 120000 index a106f493..00000000 --- a/openssl-install/share/man/man3/EVP_rc2_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc2_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc4.3ossl b/openssl-install/share/man/man3/EVP_rc4.3ossl deleted file mode 100644 index e3f53d05..00000000 --- a/openssl-install/share/man/man3/EVP_rc4.3ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RC4 3ossl" -.TH EVP_RC4 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_rc4, -EVP_rc4_40, -EVP_rc4_hmac_md5 -\&\- EVP RC4 stream cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_rc4(void); -\& const EVP_CIPHER *EVP_rc4_40(void); -\& const EVP_CIPHER *EVP_rc4_hmac_md5(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1RC4\s0 stream cipher for \s-1EVP.\s0 -.IP "\fBEVP_rc4()\fR" 4 -.IX Item "EVP_rc4()" -\&\s-1RC4\s0 stream cipher. This is a variable key length cipher with a default key -length of 128 bits. -.IP "\fBEVP_rc4_40()\fR" 4 -.IX Item "EVP_rc4_40()" -\&\s-1RC4\s0 stream cipher with 40 bit key length. -.Sp -\&\s-1WARNING:\s0 this function is obsolete. Its usage should be replaced with the -\&\fBEVP_rc4()\fR and the \fBEVP_CIPHER_CTX_set_key_length()\fR functions. -.IP "\fBEVP_rc4_hmac_md5()\fR" 4 -.IX Item "EVP_rc4_hmac_md5()" -Authenticated encryption with the \s-1RC4\s0 stream cipher with \s-1MD5\s0 as \s-1HMAC.\s0 -.Sp -\&\s-1WARNING:\s0 this is not intended for usage outside of \s-1TLS\s0 and requires calling of -some undocumented ctrl functions. These ciphers do not conform to the \s-1EVP AEAD\s0 -interface. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-RC4\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_rc4_40.3ossl b/openssl-install/share/man/man3/EVP_rc4_40.3ossl deleted file mode 120000 index 1c745d65..00000000 --- a/openssl-install/share/man/man3/EVP_rc4_40.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc4.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc4_hmac_md5.3ossl b/openssl-install/share/man/man3/EVP_rc4_hmac_md5.3ossl deleted file mode 120000 index 1c745d65..00000000 --- a/openssl-install/share/man/man3/EVP_rc4_hmac_md5.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc4.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc5_32_12_16_cbc.3ossl b/openssl-install/share/man/man3/EVP_rc5_32_12_16_cbc.3ossl deleted file mode 100644 index bd6ea5d9..00000000 --- a/openssl-install/share/man/man3/EVP_rc5_32_12_16_cbc.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RC5_32_12_16_CBC 3ossl" -.TH EVP_RC5_32_12_16_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_rc5_32_12_16_cbc, -EVP_rc5_32_12_16_cfb, -EVP_rc5_32_12_16_cfb64, -EVP_rc5_32_12_16_ecb, -EVP_rc5_32_12_16_ofb -\&\- EVP RC5 cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_rc5_32_12_16_cbc(void); -\& const EVP_CIPHER *EVP_rc5_32_12_16_cfb(void); -\& const EVP_CIPHER *EVP_rc5_32_12_16_cfb64(void); -\& const EVP_CIPHER *EVP_rc5_32_12_16_ecb(void); -\& const EVP_CIPHER *EVP_rc5_32_12_16_ofb(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1RC5\s0 encryption algorithm for \s-1EVP.\s0 -.IP "\fBEVP_rc5_32_12_16_cbc()\fR, \fBEVP_rc5_32_12_16_cfb()\fR, \fBEVP_rc5_32_12_16_cfb64()\fR, \fBEVP_rc5_32_12_16_ecb()\fR, \fBEVP_rc5_32_12_16_ofb()\fR" 4 -.IX Item "EVP_rc5_32_12_16_cbc(), EVP_rc5_32_12_16_cfb(), EVP_rc5_32_12_16_cfb64(), EVP_rc5_32_12_16_ecb(), EVP_rc5_32_12_16_ofb()" -\&\s-1RC5\s0 encryption algorithm in \s-1CBC, CFB, ECB\s0 and \s-1OFB\s0 modes respectively. This is a -variable key length cipher with an additional \*(L"number of rounds\*(R" parameter. By -default the key length is set to 128 bits and 12 rounds. Alternative key lengths -can be set using \fBEVP_CIPHER_CTX_set_key_length\fR\|(3). The maximum key length is -2040 bits. -.Sp -The following rc5 specific \fIctrl\fRs are supported (see -\&\fBEVP_CIPHER_CTX_ctrl\fR\|(3)). -.RS 4 -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_SET_RC5_ROUNDS,\s0 rounds, \s-1NULL\s0)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_SET_RC5_ROUNDS, rounds, NULL)" -Sets the number of rounds to \fBrounds\fR. This must be one of \s-1RC5_8_ROUNDS, -RC5_12_ROUNDS\s0 or \s-1RC5_16_ROUNDS.\s0 -.IP "EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CTRL_GET_RC5_ROUNDS, 0,\s0 &rounds)" 4 -.IX Item "EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_GET_RC5_ROUNDS, 0, &rounds)" -Stores the number of rounds currently configured in \fB*rounds\fR where \fB*rounds\fR -is an int. -.RE -.RS 4 -.RE -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-RC5\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb.3ossl b/openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb.3ossl deleted file mode 120000 index 4f58f696..00000000 --- a/openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc5_32_12_16_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb64.3ossl b/openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb64.3ossl deleted file mode 120000 index 4f58f696..00000000 --- a/openssl-install/share/man/man3/EVP_rc5_32_12_16_cfb64.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc5_32_12_16_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc5_32_12_16_ecb.3ossl b/openssl-install/share/man/man3/EVP_rc5_32_12_16_ecb.3ossl deleted file mode 120000 index 4f58f696..00000000 --- a/openssl-install/share/man/man3/EVP_rc5_32_12_16_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc5_32_12_16_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_rc5_32_12_16_ofb.3ossl b/openssl-install/share/man/man3/EVP_rc5_32_12_16_ofb.3ossl deleted file mode 120000 index 4f58f696..00000000 --- a/openssl-install/share/man/man3/EVP_rc5_32_12_16_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_rc5_32_12_16_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_ripemd160.3ossl b/openssl-install/share/man/man3/EVP_ripemd160.3ossl deleted file mode 100644 index 2597485b..00000000 --- a/openssl-install/share/man/man3/EVP_ripemd160.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RIPEMD160 3ossl" -.TH EVP_RIPEMD160 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_ripemd160 -\&\- RIPEMD160 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_ripemd160(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1RIPEMD\-160\s0 is a cryptographic hash function first published in 1996 belonging -to the \s-1RIPEMD\s0 family (\s-1RACE\s0 Integrity Primitives Evaluation Message Digest). -This implementation is only available with the legacy provider. -.IP "\fBEVP_ripemd160()\fR" 4 -.IX Item "EVP_ripemd160()" -The \s-1RIPEMD\-160\s0 algorithm which produces a 160\-bit output from a given input. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-RIPEMD160\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ISO/IEC 10118\-3:2016\s0 Dedicated Hash-Function 1 (\s-1RIPEMD\-160\s0). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBprovider\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_seed_cbc.3ossl b/openssl-install/share/man/man3/EVP_seed_cbc.3ossl deleted file mode 100644 index 53f2f15a..00000000 --- a/openssl-install/share/man/man3/EVP_seed_cbc.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SEED_CBC 3ossl" -.TH EVP_SEED_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_seed_cbc, -EVP_seed_cfb, -EVP_seed_cfb128, -EVP_seed_ecb, -EVP_seed_ofb -\&\- EVP SEED cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_seed_cbc(void); -\& const EVP_CIPHER *EVP_seed_cfb(void); -\& const EVP_CIPHER *EVP_seed_cfb128(void); -\& const EVP_CIPHER *EVP_seed_ecb(void); -\& const EVP_CIPHER *EVP_seed_ofb(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1SEED\s0 encryption algorithm for \s-1EVP.\s0 -.PP -All modes below use a key length of 128 bits and acts on blocks of 128\-bits. -.IP "\fBEVP_seed_cbc()\fR, \fBEVP_seed_cfb()\fR, \fBEVP_seed_cfb128()\fR, \fBEVP_seed_ecb()\fR, \fBEVP_seed_ofb()\fR" 4 -.IX Item "EVP_seed_cbc(), EVP_seed_cfb(), EVP_seed_cfb128(), EVP_seed_ecb(), EVP_seed_ofb()" -The \s-1SEED\s0 encryption algorithm in \s-1CBC, CFB, ECB\s0 and \s-1OFB\s0 modes respectively. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-SEED\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return an \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_seed_cfb.3ossl b/openssl-install/share/man/man3/EVP_seed_cfb.3ossl deleted file mode 120000 index 4e9ed04f..00000000 --- a/openssl-install/share/man/man3/EVP_seed_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_seed_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_seed_cfb128.3ossl b/openssl-install/share/man/man3/EVP_seed_cfb128.3ossl deleted file mode 120000 index 4e9ed04f..00000000 --- a/openssl-install/share/man/man3/EVP_seed_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_seed_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_seed_ecb.3ossl b/openssl-install/share/man/man3/EVP_seed_ecb.3ossl deleted file mode 120000 index 4e9ed04f..00000000 --- a/openssl-install/share/man/man3/EVP_seed_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_seed_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_seed_ofb.3ossl b/openssl-install/share/man/man3/EVP_seed_ofb.3ossl deleted file mode 120000 index 4e9ed04f..00000000 --- a/openssl-install/share/man/man3/EVP_seed_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_seed_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_set_default_properties.3ossl b/openssl-install/share/man/man3/EVP_set_default_properties.3ossl deleted file mode 100644 index 49eb3176..00000000 --- a/openssl-install/share/man/man3/EVP_set_default_properties.3ossl +++ /dev/null @@ -1,201 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SET_DEFAULT_PROPERTIES 3ossl" -.TH EVP_SET_DEFAULT_PROPERTIES 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_set_default_properties, EVP_default_properties_enable_fips, -EVP_default_properties_is_fips_enabled -\&\- Set default properties for future algorithm fetches -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int EVP_set_default_properties(OSSL_LIB_CTX *libctx, const char *propq); -\& int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable); -\& int EVP_default_properties_is_fips_enabled(OSSL_LIB_CTX *libctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_set_default_properties()\fR sets the default properties for all -future \s-1EVP\s0 algorithm fetches, implicit as well as explicit. See -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for information about implicit and explicit -fetching. -.PP -EVP_set_default_properties stores the properties given with the string -\&\fIpropq\fR among the \s-1EVP\s0 data that's been stored in the library context -given with \fIlibctx\fR (\s-1NULL\s0 signifies the default library context). -.PP -Any previous default property for the specified library context will -be dropped. -.PP -\&\fBEVP_default_properties_enable_fips()\fR sets the 'fips=yes' to be a default property -if \fIenable\fR is non zero, otherwise it clears 'fips' from the default property -query for the given \fIlibctx\fR. It merges the fips default property query with any -existing query strings that have been set via \fBEVP_set_default_properties()\fR. -.PP -\&\fBEVP_default_properties_is_fips_enabled()\fR indicates if 'fips=yes' is a default -property for the given \fIlibctx\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\fBEVP_set_default_properties()\fR and \fBEVP_default_properties_enable_fips()\fR are not -thread safe. They are intended to be called only during the initialisation -phase of a \fIlibctx\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_set_default_properties()\fR and \fBEVP_default_properties_enable_fips()\fR return 1 -on success, or 0 on failure. An error is placed on the error stack if a -failure occurs. -.PP -\&\fBEVP_default_properties_is_fips_enabled()\fR returns 1 if the 'fips=yes' default -property is set for the given \fIlibctx\fR, otherwise it returns 0. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_fetch\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_sha1.3ossl b/openssl-install/share/man/man3/EVP_sha1.3ossl deleted file mode 100644 index 5d9f70a2..00000000 --- a/openssl-install/share/man/man3/EVP_sha1.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SHA1 3ossl" -.TH EVP_SHA1 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_sha1 -\&\- SHA\-1 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_sha1(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1SHA\-1\s0 (Secure Hash Algorithm 1) is a cryptographic hash function standardized -in \s-1NIST FIPS 180\-4.\s0 The algorithm was designed by the United States National -Security Agency and initially published in 1995. -.IP "\fBEVP_sha1()\fR" 4 -.IX Item "EVP_sha1()" -The \s-1SHA\-1\s0 algorithm which produces a 160\-bit output from a given input. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-SHA1\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST FIPS 180\-4.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_sha224.3ossl b/openssl-install/share/man/man3/EVP_sha224.3ossl deleted file mode 100644 index 16649f9a..00000000 --- a/openssl-install/share/man/man3/EVP_sha224.3ossl +++ /dev/null @@ -1,199 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SHA224 3ossl" -.TH EVP_SHA224 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_sha224, -EVP_sha256, -EVP_sha512_224, -EVP_sha512_256, -EVP_sha384, -EVP_sha512 -\&\- SHA\-2 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_sha224(void); -\& const EVP_MD *EVP_sha256(void); -\& const EVP_MD *EVP_sha512_224(void); -\& const EVP_MD *EVP_sha512_256(void); -\& const EVP_MD *EVP_sha384(void); -\& const EVP_MD *EVP_sha512(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1SHA\-2\s0 (Secure Hash Algorithm 2) is a family of cryptographic hash functions -standardized in \s-1NIST FIPS 180\-4,\s0 first published in 2001. -.IP "\fBEVP_sha224()\fR, \fBEVP_sha256()\fR, EVP_sha512_224, EVP_sha512_256, \fBEVP_sha384()\fR, \fBEVP_sha512()\fR" 4 -.IX Item "EVP_sha224(), EVP_sha256(), EVP_sha512_224, EVP_sha512_256, EVP_sha384(), EVP_sha512()" -The \s-1SHA\-2 SHA\-224, SHA\-256, SHA\-512/224, SHA512/256, SHA\-384\s0 and \s-1SHA\-512\s0 -algorithms, which generate 224, 256, 224, 256, 384 and 512 bits -respectively of output from a given input. -.Sp -The two algorithms: \s-1SHA\-512/224\s0 and \s-1SHA512/256\s0 are truncated forms of the -\&\s-1SHA\-512\s0 algorithm. They are distinct from \s-1SHA\-224\s0 and \s-1SHA\-256\s0 even though -their outputs are of the same size. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-SHA2\s0\fR\|(7)instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST FIPS 180\-4.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_sha256.3ossl b/openssl-install/share/man/man3/EVP_sha256.3ossl deleted file mode 120000 index 3a1ee65d..00000000 --- a/openssl-install/share/man/man3/EVP_sha256.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sha384.3ossl b/openssl-install/share/man/man3/EVP_sha384.3ossl deleted file mode 120000 index 3a1ee65d..00000000 --- a/openssl-install/share/man/man3/EVP_sha384.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sha3_224.3ossl b/openssl-install/share/man/man3/EVP_sha3_224.3ossl deleted file mode 100644 index 8b5d674f..00000000 --- a/openssl-install/share/man/man3/EVP_sha3_224.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SHA3_224 3ossl" -.TH EVP_SHA3_224 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_sha3_224, -EVP_sha3_256, -EVP_sha3_384, -EVP_sha3_512, -EVP_shake128, -EVP_shake256 -\&\- SHA\-3 For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_sha3_224(void); -\& const EVP_MD *EVP_sha3_256(void); -\& const EVP_MD *EVP_sha3_384(void); -\& const EVP_MD *EVP_sha3_512(void); -\& -\& const EVP_MD *EVP_shake128(void); -\& const EVP_MD *EVP_shake256(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1SHA\-3\s0 (Secure Hash Algorithm 3) is a family of cryptographic hash functions -standardized in \s-1NIST FIPS 202,\s0 first published in 2015. It is based on the -Keccak algorithm. -.IP "\fBEVP_sha3_224()\fR, \fBEVP_sha3_256()\fR, \fBEVP_sha3_384()\fR, \fBEVP_sha3_512()\fR" 4 -.IX Item "EVP_sha3_224(), EVP_sha3_256(), EVP_sha3_384(), EVP_sha3_512()" -The \s-1SHA\-3 SHA\-3\-224, SHA\-3\-256, SHA\-3\-384,\s0 and \s-1SHA\-3\-512\s0 algorithms -respectively. They produce 224, 256, 384 and 512 bits of output from a given -input. -.IP "\fBEVP_shake128()\fR, \fBEVP_shake256()\fR" 4 -.IX Item "EVP_shake128(), EVP_shake256()" -The \s-1SHAKE\-128\s0 and \s-1SHAKE\-256\s0 Extendable Output Functions (\s-1XOF\s0) that can generate -a variable hash length. -.Sp -Specifically, \fBEVP_shake128\fR provides an overall security of 128 bits, while -\&\fBEVP_shake256\fR provides that of 256 bits. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-SHA3\s0\fR\|(7) or \s-1\fBEVP_MD\-SHAKE\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST FIPS 202.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_sha3_256.3ossl b/openssl-install/share/man/man3/EVP_sha3_256.3ossl deleted file mode 120000 index 77e161b4..00000000 --- a/openssl-install/share/man/man3/EVP_sha3_256.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha3_224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sha3_384.3ossl b/openssl-install/share/man/man3/EVP_sha3_384.3ossl deleted file mode 120000 index 77e161b4..00000000 --- a/openssl-install/share/man/man3/EVP_sha3_384.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha3_224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sha3_512.3ossl b/openssl-install/share/man/man3/EVP_sha3_512.3ossl deleted file mode 120000 index 77e161b4..00000000 --- a/openssl-install/share/man/man3/EVP_sha3_512.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha3_224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sha512.3ossl b/openssl-install/share/man/man3/EVP_sha512.3ossl deleted file mode 120000 index 3a1ee65d..00000000 --- a/openssl-install/share/man/man3/EVP_sha512.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sha512_224.3ossl b/openssl-install/share/man/man3/EVP_sha512_224.3ossl deleted file mode 120000 index 3a1ee65d..00000000 --- a/openssl-install/share/man/man3/EVP_sha512_224.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sha512_256.3ossl b/openssl-install/share/man/man3/EVP_sha512_256.3ossl deleted file mode 120000 index 3a1ee65d..00000000 --- a/openssl-install/share/man/man3/EVP_sha512_256.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_shake128.3ossl b/openssl-install/share/man/man3/EVP_shake128.3ossl deleted file mode 120000 index 77e161b4..00000000 --- a/openssl-install/share/man/man3/EVP_shake128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha3_224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_shake256.3ossl b/openssl-install/share/man/man3/EVP_shake256.3ossl deleted file mode 120000 index 77e161b4..00000000 --- a/openssl-install/share/man/man3/EVP_shake256.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sha3_224.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sm3.3ossl b/openssl-install/share/man/man3/EVP_sm3.3ossl deleted file mode 100644 index 48fe899d..00000000 --- a/openssl-install/share/man/man3/EVP_sm3.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SM3 3ossl" -.TH EVP_SM3 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_sm3 -\&\- SM3 for EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_sm3(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1SM3\s0 is a cryptographic hash function with a 256\-bit output, defined in \s-1GB/T -32905\-2016.\s0 -.IP "\fBEVP_sm3()\fR" 4 -.IX Item "EVP_sm3()" -The \s-1SM3\s0 hash function. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-SM3\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1GB/T 32905\-2016\s0 and \s-1GM/T 0004\-2012.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -Copyright 2017 Ribose Inc. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_sm4_cbc.3ossl b/openssl-install/share/man/man3/EVP_sm4_cbc.3ossl deleted file mode 100644 index efdac048..00000000 --- a/openssl-install/share/man/man3/EVP_sm4_cbc.3ossl +++ /dev/null @@ -1,194 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SM4_CBC 3ossl" -.TH EVP_SM4_CBC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_sm4_cbc, -EVP_sm4_ecb, -EVP_sm4_cfb, -EVP_sm4_cfb128, -EVP_sm4_ofb, -EVP_sm4_ctr -\&\- EVP SM4 cipher -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_CIPHER *EVP_sm4_cbc(void); -\& const EVP_CIPHER *EVP_sm4_ecb(void); -\& const EVP_CIPHER *EVP_sm4_cfb(void); -\& const EVP_CIPHER *EVP_sm4_cfb128(void); -\& const EVP_CIPHER *EVP_sm4_ofb(void); -\& const EVP_CIPHER *EVP_sm4_ctr(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1SM4\s0 blockcipher (\s-1GB/T 32907\-2016\s0) for \s-1EVP.\s0 -.PP -All modes below use a key length of 128 bits and acts on blocks of 128 bits. -.IP "\fBEVP_sm4_cbc()\fR, \fBEVP_sm4_ecb()\fR, \fBEVP_sm4_cfb()\fR, \fBEVP_sm4_cfb128()\fR, \fBEVP_sm4_ofb()\fR, \fBEVP_sm4_ctr()\fR" 4 -.IX Item "EVP_sm4_cbc(), EVP_sm4_ecb(), EVP_sm4_cfb(), EVP_sm4_cfb128(), EVP_sm4_ofb(), EVP_sm4_ctr()" -The \s-1SM4\s0 blockcipher with a 128\-bit key in \s-1CBC, ECB, CFB, OFB\s0 and \s-1CTR\s0 modes -respectively. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling these functions multiple times and should consider using -\&\fBEVP_CIPHER_fetch\fR\|(3) with \s-1\fBEVP_CIPHER\-SM4\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_CIPHER\s0\fR structure that contains the -implementation of the symmetric cipher. See \fBEVP_CIPHER_meth_new\fR\|(3) for -details of the \fB\s-1EVP_CIPHER\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -Copyright 2017 Ribose Inc. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EVP_sm4_cfb.3ossl b/openssl-install/share/man/man3/EVP_sm4_cfb.3ossl deleted file mode 120000 index 78358485..00000000 --- a/openssl-install/share/man/man3/EVP_sm4_cfb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sm4_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sm4_cfb128.3ossl b/openssl-install/share/man/man3/EVP_sm4_cfb128.3ossl deleted file mode 120000 index 78358485..00000000 --- a/openssl-install/share/man/man3/EVP_sm4_cfb128.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sm4_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sm4_ctr.3ossl b/openssl-install/share/man/man3/EVP_sm4_ctr.3ossl deleted file mode 120000 index 78358485..00000000 --- a/openssl-install/share/man/man3/EVP_sm4_ctr.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sm4_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sm4_ecb.3ossl b/openssl-install/share/man/man3/EVP_sm4_ecb.3ossl deleted file mode 120000 index 78358485..00000000 --- a/openssl-install/share/man/man3/EVP_sm4_ecb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sm4_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_sm4_ofb.3ossl b/openssl-install/share/man/man3/EVP_sm4_ofb.3ossl deleted file mode 120000 index 78358485..00000000 --- a/openssl-install/share/man/man3/EVP_sm4_ofb.3ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_sm4_cbc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EVP_whirlpool.3ossl b/openssl-install/share/man/man3/EVP_whirlpool.3ossl deleted file mode 100644 index ffe82599..00000000 --- a/openssl-install/share/man/man3/EVP_whirlpool.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_WHIRLPOOL 3ossl" -.TH EVP_WHIRLPOOL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_whirlpool -\&\- WHIRLPOOL For EVP -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const EVP_MD *EVP_whirlpool(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1WHIRLPOOL\s0 is a cryptographic hash function standardized in \s-1ISO/IEC 10118\-3:2004\s0 -designed by Vincent Rijmen and Paulo S. L. M. Barreto. This implementation is -only available with the legacy provider. -.IP "\fBEVP_whirlpool()\fR" 4 -.IX Item "EVP_whirlpool()" -The \s-1WHIRLPOOL\s0 algorithm that produces a message digest of 512\-bits from a given -input. -.SH "NOTES" -.IX Header "NOTES" -Developers should be aware of the negative performance implications of -calling this function multiple times and should consider using -\&\fBEVP_MD_fetch\fR\|(3) with \s-1\fBEVP_MD\-WHIRLPOOL\s0\fR\|(7) instead. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return a \fB\s-1EVP_MD\s0\fR structure that contains the -implementation of the message digest. See \fBEVP_MD_meth_new\fR\|(3) for -details of the \fB\s-1EVP_MD\s0\fR structure. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ISO/IEC 10118\-3:2004.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBprovider\fR\|(7), -\&\fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/EXTENDED_KEY_USAGE_free.3ossl b/openssl-install/share/man/man3/EXTENDED_KEY_USAGE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/EXTENDED_KEY_USAGE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EXTENDED_KEY_USAGE_new.3ossl b/openssl-install/share/man/man3/EXTENDED_KEY_USAGE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/EXTENDED_KEY_USAGE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/EXT_UTF8STRING.3ossl b/openssl-install/share/man/man3/EXT_UTF8STRING.3ossl deleted file mode 120000 index 57a93e37..00000000 --- a/openssl-install/share/man/man3/EXT_UTF8STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CORE_MAKE_FUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_NAME.3ossl b/openssl-install/share/man/man3/GENERAL_NAME.3ossl deleted file mode 100644 index 0f876827..00000000 --- a/openssl-install/share/man/man3/GENERAL_NAME.3ossl +++ /dev/null @@ -1,173 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "GENERAL_NAME 3ossl" -.TH GENERAL_NAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -GENERAL_NAME, -GENERAL_NAME_set1_X509_NAME -\&\- GENERAL_NAME method routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct GENERAL_NAME_st GENERAL_NAME; -\& -\& int GENERAL_NAME_set1_X509_NAME(GENERAL_NAME **tgt, const X509_NAME *src); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBGENERAL_NAME_set1_X509_NAME()\fR creates a new \s-1GENERAL_NAME\s0 of type \s-1GEN_DIRNAME\s0 -and populates it based on provided X509_NAME \fIsrc\fR which can be \s-1NULL.\s0 -\&\fItgt\fR must not be \s-1NULL.\s0 If successful, \fI*tgt\fR will be set to point -to the newly created \s-1GENERAL_NAME.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBGENERAL_NAME_set1_X509_NAME()\fR return 1 on success, 0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBGENERAL_NAME_set1_X509_NAME()\fR was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/GENERAL_NAMES_free.3ossl b/openssl-install/share/man/man3/GENERAL_NAMES_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/GENERAL_NAMES_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_NAMES_new.3ossl b/openssl-install/share/man/man3/GENERAL_NAMES_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/GENERAL_NAMES_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_NAME_dup.3ossl b/openssl-install/share/man/man3/GENERAL_NAME_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/GENERAL_NAME_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_NAME_free.3ossl b/openssl-install/share/man/man3/GENERAL_NAME_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/GENERAL_NAME_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_NAME_new.3ossl b/openssl-install/share/man/man3/GENERAL_NAME_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/GENERAL_NAME_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_NAME_set1_X509_NAME.3ossl b/openssl-install/share/man/man3/GENERAL_NAME_set1_X509_NAME.3ossl deleted file mode 120000 index 37e118f3..00000000 --- a/openssl-install/share/man/man3/GENERAL_NAME_set1_X509_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -GENERAL_NAME.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_SUBTREE_free.3ossl b/openssl-install/share/man/man3/GENERAL_SUBTREE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/GENERAL_SUBTREE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GENERAL_SUBTREE_new.3ossl b/openssl-install/share/man/man3/GENERAL_SUBTREE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/GENERAL_SUBTREE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/GEN_SESSION_CB.3ossl b/openssl-install/share/man/man3/GEN_SESSION_CB.3ossl deleted file mode 120000 index 625534b5..00000000 --- a/openssl-install/share/man/man3/GEN_SESSION_CB.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_generate_session_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC.3ossl b/openssl-install/share/man/man3/HMAC.3ossl deleted file mode 100644 index 580a4fb4..00000000 --- a/openssl-install/share/man/man3/HMAC.3ossl +++ /dev/null @@ -1,307 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "HMAC 3ossl" -.TH HMAC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -HMAC, -HMAC_CTX_new, -HMAC_CTX_reset, -HMAC_CTX_free, -HMAC_Init, -HMAC_Init_ex, -HMAC_Update, -HMAC_Final, -HMAC_CTX_copy, -HMAC_CTX_set_flags, -HMAC_CTX_get_md, -HMAC_size -\&\- HMAC message authentication code -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned char *HMAC(const EVP_MD *evp_md, const void *key, int key_len, -\& const unsigned char *data, size_t data_len, -\& unsigned char *md, unsigned int *md_len); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& HMAC_CTX *HMAC_CTX_new(void); -\& int HMAC_CTX_reset(HMAC_CTX *ctx); -\& -\& int HMAC_Init_ex(HMAC_CTX *ctx, const void *key, int key_len, -\& const EVP_MD *md, ENGINE *impl); -\& int HMAC_Update(HMAC_CTX *ctx, const unsigned char *data, size_t len); -\& int HMAC_Final(HMAC_CTX *ctx, unsigned char *md, unsigned int *len); -\& -\& void HMAC_CTX_free(HMAC_CTX *ctx); -\& -\& int HMAC_CTX_copy(HMAC_CTX *dctx, HMAC_CTX *sctx); -\& void HMAC_CTX_set_flags(HMAC_CTX *ctx, unsigned long flags); -\& const EVP_MD *HMAC_CTX_get_md(const HMAC_CTX *ctx); -\& -\& size_t HMAC_size(const HMAC_CTX *e); -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int HMAC_Init(HMAC_CTX *ctx, const void *key, int key_len, -\& const EVP_MD *md); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1HMAC\s0 is a \s-1MAC\s0 (message authentication code), i.e. a keyed hash -function used for message authentication, which is based on a hash -function. -.PP -\&\s-1\fBHMAC\s0()\fR computes the message authentication code of the \fIdata_len\fR bytes at -\&\fIdata\fR using the hash function \fIevp_md\fR and the key \fIkey\fR which is -\&\fIkey_len\fR bytes long. The \fIkey\fR may also be \s-1NULL\s0 with \fIkey_len\fR being 0. -.PP -It places the result in \fImd\fR (which must have space for the output of -the hash function, which is no more than \fB\s-1EVP_MAX_MD_SIZE\s0\fR bytes). -If \fImd\fR is \s-1NULL,\s0 the digest is placed in a static array. The size of -the output is placed in \fImd_len\fR, unless it is \s-1NULL.\s0 Note: passing a \s-1NULL\s0 -value for \fImd\fR to use the static array is not thread safe. -.PP -\&\fIevp_md\fR is a message digest such as \fBEVP_sha1()\fR, \fBEVP_ripemd160()\fR etc. -\&\s-1HMAC\s0 does not support variable output length digests such as \fBEVP_shake128()\fR and -\&\fBEVP_shake256()\fR. -.PP -\&\s-1\fBHMAC\s0()\fR uses the default \fB\s-1OSSL_LIB_CTX\s0\fR. -Use \fBEVP_Q_mac\fR\|(3) instead if a library context is required. -.PP -All of the functions described below are deprecated. -Applications should instead use \fBEVP_MAC_CTX_new\fR\|(3), \fBEVP_MAC_CTX_free\fR\|(3), -\&\fBEVP_MAC_init\fR\|(3), \fBEVP_MAC_update\fR\|(3) and \fBEVP_MAC_final\fR\|(3) -or the 'quick' single-shot \s-1MAC\s0 function \fBEVP_Q_mac\fR\|(3). -.PP -\&\fBHMAC_CTX_new()\fR creates a new \s-1HMAC_CTX\s0 in heap memory. -.PP -\&\fBHMAC_CTX_reset()\fR clears an existing \fB\s-1HMAC_CTX\s0\fR and associated -resources, making it suitable for new computations as if it was newly -created with \fBHMAC_CTX_new()\fR. -.PP -\&\fBHMAC_CTX_free()\fR erases the key and other data from the \fB\s-1HMAC_CTX\s0\fR, -releases any associated resources and finally frees the \fB\s-1HMAC_CTX\s0\fR -itself. If the argument is \s-1NULL,\s0 nothing is done. -.PP -The following functions may be used if the message is not completely -stored in memory: -.PP -\&\fBHMAC_Init_ex()\fR initializes or reuses a \fB\s-1HMAC_CTX\s0\fR structure to use the hash -function \fIevp_md\fR and key \fIkey\fR. If both are \s-1NULL,\s0 or if \fIkey\fR is \s-1NULL\s0 -and \fIevp_md\fR is the same as the previous call, then the -existing key is -reused. \fIctx\fR must have been created with \fBHMAC_CTX_new()\fR before the first use -of an \fB\s-1HMAC_CTX\s0\fR in this function. -.PP -If \fBHMAC_Init_ex()\fR is called with \fIkey\fR \s-1NULL\s0 and \fIevp_md\fR is not the -same as the previous digest used by \fIctx\fR then an error is returned -because reuse of an existing key with a different digest is not supported. -.PP -\&\fBHMAC_Init()\fR initializes a \fB\s-1HMAC_CTX\s0\fR structure to use the hash -function \fIevp_md\fR and the key \fIkey\fR which is \fIkey_len\fR bytes -long. -.PP -\&\fBHMAC_Update()\fR can be called repeatedly with chunks of the message to -be authenticated (\fIlen\fR bytes at \fIdata\fR). -.PP -\&\fBHMAC_Final()\fR places the message authentication code in \fImd\fR, which -must have space for the hash function output. -.PP -\&\fBHMAC_CTX_copy()\fR copies all of the internal state from \fIsctx\fR into \fIdctx\fR. -.PP -\&\fBHMAC_CTX_set_flags()\fR applies the specified flags to the internal EVP_MD_CTXs. -These flags have the same meaning as for \fBEVP_MD_CTX_set_flags\fR\|(3). -.PP -\&\fBHMAC_CTX_get_md()\fR returns the \s-1EVP_MD\s0 that has previously been set for the -supplied \s-1HMAC_CTX.\s0 -.PP -\&\fBHMAC_size()\fR returns the length in bytes of the underlying hash function output. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1\fBHMAC\s0()\fR returns a pointer to the message authentication code or \s-1NULL\s0 if -an error occurred. -.PP -\&\fBHMAC_CTX_new()\fR returns a pointer to a new \fB\s-1HMAC_CTX\s0\fR on success or -\&\s-1NULL\s0 if an error occurred. -.PP -\&\fBHMAC_CTX_reset()\fR, \fBHMAC_Init_ex()\fR, \fBHMAC_Update()\fR, \fBHMAC_Final()\fR and -\&\fBHMAC_CTX_copy()\fR return 1 for success or 0 if an error occurred. -.PP -\&\fBHMAC_CTX_get_md()\fR return the \s-1EVP_MD\s0 previously set for the supplied \s-1HMAC_CTX\s0 or -\&\s-1NULL\s0 if no \s-1EVP_MD\s0 has been set. -.PP -\&\fBHMAC_size()\fR returns the length in bytes of the underlying hash function output -or zero on error. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 2104\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBSHA1\s0\fR\|(3), \fBEVP_Q_mac\fR\|(3), \fBevp\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All functions except for \s-1\fBHMAC\s0()\fR were deprecated in OpenSSL 3.0. -.PP -\&\fBHMAC_CTX_init()\fR was replaced with \fBHMAC_CTX_reset()\fR in OpenSSL 1.1.0. -.PP -\&\fBHMAC_CTX_cleanup()\fR existed in OpenSSL before version 1.1.0. -.PP -\&\fBHMAC_CTX_new()\fR, \fBHMAC_CTX_free()\fR and \fBHMAC_CTX_get_md()\fR are new in OpenSSL 1.1.0. -.PP -\&\fBHMAC_Init_ex()\fR, \fBHMAC_Update()\fR and \fBHMAC_Final()\fR did not return values in -OpenSSL before version 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/HMAC_CTX_copy.3ossl b/openssl-install/share/man/man3/HMAC_CTX_copy.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_CTX_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_CTX_free.3ossl b/openssl-install/share/man/man3/HMAC_CTX_free.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_CTX_get_md.3ossl b/openssl-install/share/man/man3/HMAC_CTX_get_md.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_CTX_get_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_CTX_new.3ossl b/openssl-install/share/man/man3/HMAC_CTX_new.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_CTX_reset.3ossl b/openssl-install/share/man/man3/HMAC_CTX_reset.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_CTX_reset.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_CTX_set_flags.3ossl b/openssl-install/share/man/man3/HMAC_CTX_set_flags.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_CTX_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_Final.3ossl b/openssl-install/share/man/man3/HMAC_Final.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_Init.3ossl b/openssl-install/share/man/man3/HMAC_Init.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_Init_ex.3ossl b/openssl-install/share/man/man3/HMAC_Init_ex.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_Init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_Update.3ossl b/openssl-install/share/man/man3/HMAC_Update.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/HMAC_size.3ossl b/openssl-install/share/man/man3/HMAC_size.3ossl deleted file mode 120000 index 2f064693..00000000 --- a/openssl-install/share/man/man3/HMAC_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IMPLEMENT_ASN1_FUNCTIONS.3ossl b/openssl-install/share/man/man3/IMPLEMENT_ASN1_FUNCTIONS.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IMPLEMENT_ASN1_FUNCTIONS.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IMPLEMENT_EXTERN_ASN1.3ossl b/openssl-install/share/man/man3/IMPLEMENT_EXTERN_ASN1.3ossl deleted file mode 120000 index d1a649b1..00000000 --- a/openssl-install/share/man/man3/IMPLEMENT_EXTERN_ASN1.3ossl +++ /dev/null @@ -1 +0,0 @@ -ASN1_EXTERN_FUNCS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IMPLEMENT_LHASH_COMP_FN.3ossl b/openssl-install/share/man/man3/IMPLEMENT_LHASH_COMP_FN.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/IMPLEMENT_LHASH_COMP_FN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IMPLEMENT_LHASH_HASH_FN.3ossl b/openssl-install/share/man/man3/IMPLEMENT_LHASH_HASH_FN.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/IMPLEMENT_LHASH_HASH_FN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressChoice_free.3ossl b/openssl-install/share/man/man3/IPAddressChoice_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressChoice_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressChoice_new.3ossl b/openssl-install/share/man/man3/IPAddressChoice_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressChoice_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressFamily_free.3ossl b/openssl-install/share/man/man3/IPAddressFamily_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressFamily_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressFamily_new.3ossl b/openssl-install/share/man/man3/IPAddressFamily_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressFamily_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressOrRange_free.3ossl b/openssl-install/share/man/man3/IPAddressOrRange_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressOrRange_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressOrRange_new.3ossl b/openssl-install/share/man/man3/IPAddressOrRange_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressOrRange_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressRange_free.3ossl b/openssl-install/share/man/man3/IPAddressRange_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressRange_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/IPAddressRange_new.3ossl b/openssl-install/share/man/man3/IPAddressRange_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/IPAddressRange_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_free.3ossl b/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_it.3ossl b/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_new.3ossl b/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ISSUER_SIGN_TOOL_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ISSUING_DIST_POINT_free.3ossl b/openssl-install/share/man/man3/ISSUING_DIST_POINT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ISSUING_DIST_POINT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ISSUING_DIST_POINT_it.3ossl b/openssl-install/share/man/man3/ISSUING_DIST_POINT_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ISSUING_DIST_POINT_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ISSUING_DIST_POINT_new.3ossl b/openssl-install/share/man/man3/ISSUING_DIST_POINT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/ISSUING_DIST_POINT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/LHASH.3ossl b/openssl-install/share/man/man3/LHASH.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/LHASH.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/LHASH_DOALL_ARG_FN_TYPE.3ossl b/openssl-install/share/man/man3/LHASH_DOALL_ARG_FN_TYPE.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/LHASH_DOALL_ARG_FN_TYPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/LHASH_OF.3ossl b/openssl-install/share/man/man3/LHASH_OF.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/LHASH_OF.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD2.3ossl b/openssl-install/share/man/man3/MD2.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD2.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD2_Final.3ossl b/openssl-install/share/man/man3/MD2_Final.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD2_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD2_Init.3ossl b/openssl-install/share/man/man3/MD2_Init.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD2_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD2_Update.3ossl b/openssl-install/share/man/man3/MD2_Update.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD2_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD4.3ossl b/openssl-install/share/man/man3/MD4.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD4.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD4_Final.3ossl b/openssl-install/share/man/man3/MD4_Final.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD4_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD4_Init.3ossl b/openssl-install/share/man/man3/MD4_Init.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD4_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD4_Update.3ossl b/openssl-install/share/man/man3/MD4_Update.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD4_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD5.3ossl b/openssl-install/share/man/man3/MD5.3ossl deleted file mode 100644 index 8197cec1..00000000 --- a/openssl-install/share/man/man3/MD5.3ossl +++ /dev/null @@ -1,246 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "MD5 3ossl" -.TH MD5 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -MD2, MD4, MD5, MD2_Init, MD2_Update, MD2_Final, MD4_Init, MD4_Update, -MD4_Final, MD5_Init, MD5_Update, MD5_Final \- MD2, MD4, and MD5 hash functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #include -\& -\& unsigned char *MD2(const unsigned char *d, unsigned long n, unsigned char *md); -\& -\& int MD2_Init(MD2_CTX *c); -\& int MD2_Update(MD2_CTX *c, const unsigned char *data, unsigned long len); -\& int MD2_Final(unsigned char *md, MD2_CTX *c); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #include -\& -\& unsigned char *MD4(const unsigned char *d, unsigned long n, unsigned char *md); -\& -\& int MD4_Init(MD4_CTX *c); -\& int MD4_Update(MD4_CTX *c, const void *data, unsigned long len); -\& int MD4_Final(unsigned char *md, MD4_CTX *c); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #include -\& -\& unsigned char *MD5(const unsigned char *d, unsigned long n, unsigned char *md); -\& -\& int MD5_Init(MD5_CTX *c); -\& int MD5_Update(MD5_CTX *c, const void *data, unsigned long len); -\& int MD5_Final(unsigned char *md, MD5_CTX *c); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_DigestInit_ex\fR\|(3), \fBEVP_DigestUpdate\fR\|(3) -and \fBEVP_DigestFinal_ex\fR\|(3). -.PP -\&\s-1MD2, MD4,\s0 and \s-1MD5\s0 are cryptographic hash functions with a 128 bit output. -.PP -\&\s-1\fBMD2\s0()\fR, \s-1\fBMD4\s0()\fR, and \s-1\fBMD5\s0()\fR compute the \s-1MD2, MD4,\s0 and \s-1MD5\s0 message digest -of the \fBn\fR bytes at \fBd\fR and place it in \fBmd\fR (which must have space -for \s-1MD2_DIGEST_LENGTH\s0 == \s-1MD4_DIGEST_LENGTH\s0 == \s-1MD5_DIGEST_LENGTH\s0 == 16 -bytes of output). If \fBmd\fR is \s-1NULL,\s0 the digest is placed in a static -array. -.PP -The following functions may be used if the message is not completely -stored in memory: -.PP -\&\fBMD2_Init()\fR initializes a \fB\s-1MD2_CTX\s0\fR structure. -.PP -\&\fBMD2_Update()\fR can be called repeatedly with chunks of the message to -be hashed (\fBlen\fR bytes at \fBdata\fR). -.PP -\&\fBMD2_Final()\fR places the message digest in \fBmd\fR, which must have space -for \s-1MD2_DIGEST_LENGTH\s0 == 16 bytes of output, and erases the \fB\s-1MD2_CTX\s0\fR. -.PP -\&\fBMD4_Init()\fR, \fBMD4_Update()\fR, \fBMD4_Final()\fR, \fBMD5_Init()\fR, \fBMD5_Update()\fR, and -\&\fBMD5_Final()\fR are analogous using an \fB\s-1MD4_CTX\s0\fR and \fB\s-1MD5_CTX\s0\fR structure. -.PP -Applications should use the higher level functions -\&\fBEVP_DigestInit\fR\|(3) -etc. instead of calling the hash functions directly. -.SH "NOTE" -.IX Header "NOTE" -\&\s-1MD2, MD4,\s0 and \s-1MD5\s0 are recommended only for compatibility with existing -applications. In new applications, hashes from the \s-1SHA\-2\s0 or \s-1SHA\-3\s0 family -should be preferred. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1\fBMD2\s0()\fR, \s-1\fBMD4\s0()\fR, and \s-1\fBMD5\s0()\fR return pointers to the hash value. -.PP -\&\fBMD2_Init()\fR, \fBMD2_Update()\fR, \fBMD2_Final()\fR, \fBMD4_Init()\fR, \fBMD4_Update()\fR, -\&\fBMD4_Final()\fR, \fBMD5_Init()\fR, \fBMD5_Update()\fR, and \fBMD5_Final()\fR return 1 for -success, 0 otherwise. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 1319, RFC 1320, RFC 1321\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestInit\fR\|(3), \s-1\fBEVP_MD\-SHA2\s0\fR\|(7), \s-1\fBEVP_MD\-SHA3\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/MD5_Final.3ossl b/openssl-install/share/man/man3/MD5_Final.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD5_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD5_Init.3ossl b/openssl-install/share/man/man3/MD5_Init.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD5_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MD5_Update.3ossl b/openssl-install/share/man/man3/MD5_Update.3ossl deleted file mode 120000 index 5c6aed13..00000000 --- a/openssl-install/share/man/man3/MD5_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -MD5.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MDC2.3ossl b/openssl-install/share/man/man3/MDC2.3ossl deleted file mode 120000 index ae2afbf2..00000000 --- a/openssl-install/share/man/man3/MDC2.3ossl +++ /dev/null @@ -1 +0,0 @@ -MDC2_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MDC2_Final.3ossl b/openssl-install/share/man/man3/MDC2_Final.3ossl deleted file mode 120000 index ae2afbf2..00000000 --- a/openssl-install/share/man/man3/MDC2_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -MDC2_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/MDC2_Init.3ossl b/openssl-install/share/man/man3/MDC2_Init.3ossl deleted file mode 100644 index 4bb35be7..00000000 --- a/openssl-install/share/man/man3/MDC2_Init.3ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "MDC2_INIT 3ossl" -.TH MDC2_INIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -MDC2, MDC2_Init, MDC2_Update, MDC2_Final \- MDC2 hash function -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& unsigned char *MDC2(const unsigned char *d, unsigned long n, -\& unsigned char *md); -\& -\& int MDC2_Init(MDC2_CTX *c); -\& int MDC2_Update(MDC2_CTX *c, const unsigned char *data, -\& unsigned long len); -\& int MDC2_Final(unsigned char *md, MDC2_CTX *c); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_DigestInit_ex\fR\|(3), \fBEVP_DigestUpdate\fR\|(3) -and \fBEVP_DigestFinal_ex\fR\|(3). -.PP -\&\s-1MDC2\s0 is a method to construct hash functions with 128 bit output from -block ciphers. These functions are an implementation of \s-1MDC2\s0 with -\&\s-1DES.\s0 -.PP -\&\s-1\fBMDC2\s0()\fR computes the \s-1MDC2\s0 message digest of the \fBn\fR -bytes at \fBd\fR and places it in \fBmd\fR (which must have space for -\&\s-1MDC2_DIGEST_LENGTH\s0 == 16 bytes of output). If \fBmd\fR is \s-1NULL,\s0 the digest -is placed in a static array. -.PP -The following functions may be used if the message is not completely -stored in memory: -.PP -\&\fBMDC2_Init()\fR initializes a \fB\s-1MDC2_CTX\s0\fR structure. -.PP -\&\fBMDC2_Update()\fR can be called repeatedly with chunks of the message to -be hashed (\fBlen\fR bytes at \fBdata\fR). -.PP -\&\fBMDC2_Final()\fR places the message digest in \fBmd\fR, which must have space -for \s-1MDC2_DIGEST_LENGTH\s0 == 16 bytes of output, and erases the \fB\s-1MDC2_CTX\s0\fR. -.PP -Applications should use the higher level functions -\&\fBEVP_DigestInit\fR\|(3) etc. instead of calling the -hash functions directly. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1\fBMDC2\s0()\fR returns a pointer to the hash value. -.PP -\&\fBMDC2_Init()\fR, \fBMDC2_Update()\fR and \fBMDC2_Final()\fR return 1 for success, 0 otherwise. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ISO/IEC 10118\-2:2000\s0 Hash-Function 2, with \s-1DES\s0 as the underlying block cipher. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/MDC2_Update.3ossl b/openssl-install/share/man/man3/MDC2_Update.3ossl deleted file mode 120000 index ae2afbf2..00000000 --- a/openssl-install/share/man/man3/MDC2_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -MDC2_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAME_CONSTRAINTS_free.3ossl b/openssl-install/share/man/man3/NAME_CONSTRAINTS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NAME_CONSTRAINTS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAME_CONSTRAINTS_new.3ossl b/openssl-install/share/man/man3/NAME_CONSTRAINTS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NAME_CONSTRAINTS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_free.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityId.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityId.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityId.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityText.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityText.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityText.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityURL.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityURL.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_get0_authorityURL.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_new.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityId.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityId.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityId.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityText.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityText.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityText.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityURL.3ossl b/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityURL.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/NAMING_AUTHORITY_set0_authorityURL.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_default.3ossl b/openssl-install/share/man/man3/NCONF_default.3ossl deleted file mode 120000 index 4d280a2d..00000000 --- a/openssl-install/share/man/man3/NCONF_default.3ossl +++ /dev/null @@ -1 +0,0 @@ -NCONF_new_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_free.3ossl b/openssl-install/share/man/man3/NCONF_free.3ossl deleted file mode 120000 index 4d280a2d..00000000 --- a/openssl-install/share/man/man3/NCONF_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -NCONF_new_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_get0_libctx.3ossl b/openssl-install/share/man/man3/NCONF_get0_libctx.3ossl deleted file mode 120000 index 4d280a2d..00000000 --- a/openssl-install/share/man/man3/NCONF_get0_libctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -NCONF_new_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_get_section.3ossl b/openssl-install/share/man/man3/NCONF_get_section.3ossl deleted file mode 120000 index 4d280a2d..00000000 --- a/openssl-install/share/man/man3/NCONF_get_section.3ossl +++ /dev/null @@ -1 +0,0 @@ -NCONF_new_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_get_section_names.3ossl b/openssl-install/share/man/man3/NCONF_get_section_names.3ossl deleted file mode 120000 index 4d280a2d..00000000 --- a/openssl-install/share/man/man3/NCONF_get_section_names.3ossl +++ /dev/null @@ -1 +0,0 @@ -NCONF_new_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_load.3ossl b/openssl-install/share/man/man3/NCONF_load.3ossl deleted file mode 120000 index 4d280a2d..00000000 --- a/openssl-install/share/man/man3/NCONF_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -NCONF_new_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_new.3ossl b/openssl-install/share/man/man3/NCONF_new.3ossl deleted file mode 120000 index 4d280a2d..00000000 --- a/openssl-install/share/man/man3/NCONF_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -NCONF_new_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NCONF_new_ex.3ossl b/openssl-install/share/man/man3/NCONF_new_ex.3ossl deleted file mode 100644 index b9c5b462..00000000 --- a/openssl-install/share/man/man3/NCONF_new_ex.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "NCONF_NEW_EX 3ossl" -.TH NCONF_NEW_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -NCONF_new_ex, NCONF_new, NCONF_free, NCONF_default, NCONF_load, -NCONF_get0_libctx, NCONF_get_section, NCONF_get_section_names -\&\- functionality to Load and parse configuration files manually -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct { -\& char *section; -\& char *name; -\& char *value; -\& } CONF_VALUE; -\& -\& CONF *NCONF_new_ex(OSSL_LIB_CTX *libctx, CONF_METHOD *meth); -\& CONF *NCONF_new(CONF_METHOD *meth); -\& void NCONF_free(CONF *conf); -\& CONF_METHOD *NCONF_default(void); -\& int NCONF_load(CONF *conf, const char *file, long *eline); -\& OSSL_LIB_CTX *NCONF_get0_libctx(const CONF *conf); -\& -\& STACK_OF(CONF_VALUE) *NCONF_get_section(const CONF *conf, const char *name); -\& STACK_OF(OPENSSL_CSTRING) *NCONF_get_section_names(const CONF *conf); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBNCONF_new_ex()\fR creates a new \s-1CONF\s0 object in heap memory and assigns to -it a context \fIlibctx\fR that can be used during loading. If the method table -\&\fImeth\fR is set to \s-1NULL\s0 then the default value of \fBNCONF_default()\fR is used. -.PP -\&\fBNCONF_new()\fR is similar to \fBNCONF_new_ex()\fR but sets the \fIlibctx\fR to \s-1NULL.\s0 -.PP -\&\fBNCONF_free()\fR frees the data associated with \fIconf\fR and then frees the \fIconf\fR -object. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBNCONF_load()\fR parses the file named \fIfilename\fR and adds the values found to -\&\fIconf\fR. If an error occurs \fIfile\fR and \fIeline\fR list the file and line that -the load failed on if they are not \s-1NULL.\s0 -.PP -\&\fBNCONF_default()\fR gets the default method table for processing a configuration file. -.PP -\&\fBNCONF_get0_libctx()\fR gets the library context associated with the \fIconf\fR -parameter. -.PP -\&\fBNCONF_get_section_names()\fR gets the names of the sections associated with -the \fIconf\fR as \fB\s-1STACK_OF\s0(\s-1OPENSSL_CSTRING\s0)\fR strings. The individual strings -are associated with the \fIconf\fR and will be invalid after \fIconf\fR is -freed. The returned stack must be freed with \fBsk_OPENSSL_CSTRING_free()\fR. -.PP -\&\fBNCONF_get_section()\fR gets the config values associated with the \fIconf\fR from -the config section \fIname\fR as \fB\s-1STACK_OF\s0(\s-1CONF_VALUE\s0)\fR structures. The returned -stack is associated with the \fIconf\fR and will be invalid after \fIconf\fR -is freed. It must not be freed by the caller. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBNCONF_load()\fR returns 1 on success or 0 on error. -.PP -\&\fBNCONF_new_ex()\fR and \fBNCONF_new()\fR return a newly created \fI\s-1CONF\s0\fR object -or \s-1NULL\s0 if an error occurs. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBCONF_modules_load_file\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBNCONF_new_ex()\fR, \fBNCONF_get0_libctx()\fR, and \fBNCONF_get_section_names()\fR were added -in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_free.3ossl b/openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_new.3ossl b/openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NETSCAPE_CERT_SEQUENCE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NETSCAPE_SPKAC_free.3ossl b/openssl-install/share/man/man3/NETSCAPE_SPKAC_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NETSCAPE_SPKAC_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NETSCAPE_SPKAC_new.3ossl b/openssl-install/share/man/man3/NETSCAPE_SPKAC_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NETSCAPE_SPKAC_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NETSCAPE_SPKI_free.3ossl b/openssl-install/share/man/man3/NETSCAPE_SPKI_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NETSCAPE_SPKI_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NETSCAPE_SPKI_new.3ossl b/openssl-install/share/man/man3/NETSCAPE_SPKI_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NETSCAPE_SPKI_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NOTICEREF_free.3ossl b/openssl-install/share/man/man3/NOTICEREF_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NOTICEREF_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/NOTICEREF_new.3ossl b/openssl-install/share/man/man3/NOTICEREF_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/NOTICEREF_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_add_sigid.3ossl b/openssl-install/share/man/man3/OBJ_add_sigid.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_add_sigid.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_cleanup.3ossl b/openssl-install/share/man/man3/OBJ_cleanup.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_cmp.3ossl b/openssl-install/share/man/man3/OBJ_cmp.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_create.3ossl b/openssl-install/share/man/man3/OBJ_create.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_dup.3ossl b/openssl-install/share/man/man3/OBJ_dup.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_get0_data.3ossl b/openssl-install/share/man/man3/OBJ_get0_data.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_get0_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_length.3ossl b/openssl-install/share/man/man3/OBJ_length.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_ln2nid.3ossl b/openssl-install/share/man/man3/OBJ_ln2nid.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_ln2nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_nid2ln.3ossl b/openssl-install/share/man/man3/OBJ_nid2ln.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_nid2ln.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_nid2obj.3ossl b/openssl-install/share/man/man3/OBJ_nid2obj.3ossl deleted file mode 100644 index 22b92057..00000000 --- a/openssl-install/share/man/man3/OBJ_nid2obj.3ossl +++ /dev/null @@ -1,345 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OBJ_NID2OBJ 3ossl" -.TH OBJ_NID2OBJ 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -i2t_ASN1_OBJECT, -OBJ_length, OBJ_get0_data, OBJ_nid2obj, OBJ_nid2ln, -OBJ_nid2sn, OBJ_obj2nid, OBJ_txt2nid, OBJ_ln2nid, OBJ_sn2nid, OBJ_cmp, -OBJ_dup, OBJ_txt2obj, OBJ_obj2txt, OBJ_create, OBJ_cleanup, OBJ_add_sigid -\&\- ASN1 object utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_OBJECT *OBJ_nid2obj(int n); -\& const char *OBJ_nid2ln(int n); -\& const char *OBJ_nid2sn(int n); -\& -\& int OBJ_obj2nid(const ASN1_OBJECT *o); -\& int OBJ_ln2nid(const char *ln); -\& int OBJ_sn2nid(const char *sn); -\& -\& int OBJ_txt2nid(const char *s); -\& -\& ASN1_OBJECT *OBJ_txt2obj(const char *s, int no_name); -\& int OBJ_obj2txt(char *buf, int buf_len, const ASN1_OBJECT *a, int no_name); -\& -\& int i2t_ASN1_OBJECT(char *buf, int buf_len, const ASN1_OBJECT *a); -\& -\& int OBJ_cmp(const ASN1_OBJECT *a, const ASN1_OBJECT *b); -\& ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o); -\& -\& int OBJ_create(const char *oid, const char *sn, const char *ln); -\& -\& size_t OBJ_length(const ASN1_OBJECT *obj); -\& const unsigned char *OBJ_get0_data(const ASN1_OBJECT *obj); -\& -\& int OBJ_add_sigid(int signid, int dig_id, int pkey_id); -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void OBJ_cleanup(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1ASN1\s0 object utility functions process \s-1ASN1_OBJECT\s0 structures which are -a representation of the \s-1ASN1 OBJECT IDENTIFIER\s0 (\s-1OID\s0) type. -For convenience, OIDs are usually represented in source code as numeric -identifiers, or \fB\s-1NID\s0\fRs. OpenSSL has an internal table of OIDs that -are generated when the library is built, and their corresponding NIDs -are available as defined constants. For the functions below, application -code should treat all returned values \*(-- OIDs, NIDs, or names \*(-- as -constants. -.PP -\&\fBOBJ_nid2obj()\fR, \fBOBJ_nid2ln()\fR and \fBOBJ_nid2sn()\fR convert the \s-1NID\s0 \fIn\fR to -an \s-1ASN1_OBJECT\s0 structure, its long name and its short name respectively, -or \fB\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBOBJ_obj2nid()\fR, \fBOBJ_ln2nid()\fR, \fBOBJ_sn2nid()\fR return the corresponding \s-1NID\s0 -for the object \fIo\fR, the long name \fIln\fR or the short name \fIsn\fR respectively -or NID_undef if an error occurred. -.PP -\&\fBOBJ_txt2nid()\fR returns \s-1NID\s0 corresponding to text string \fIs\fR. \fIs\fR can be -a long name, a short name or the numerical representation of an object. -.PP -\&\fBOBJ_txt2obj()\fR converts the text string \fIs\fR into an \s-1ASN1_OBJECT\s0 structure. -If \fIno_name\fR is 0 then long names and short names will be interpreted -as well as numerical forms. If \fIno_name\fR is 1 only the numerical form -is acceptable. -.PP -\&\fBOBJ_obj2txt()\fR converts the \fB\s-1ASN1_OBJECT\s0\fR \fIa\fR into a textual representation. -Unless \fIbuf\fR is \s-1NULL,\s0 -the representation is written as a NUL-terminated string to \fIbuf\fR, where -at most \fIbuf_len\fR bytes are written, truncating the result if necessary. -In any case it returns the total string length, excluding the \s-1NUL\s0 character, -required for non-truncated representation, or \-1 on error. -If \fIno_name\fR is 0 then if the object has a long or short name -then that will be used, otherwise the numerical form will be used. -If \fIno_name\fR is 1 then the numerical form will always be used. -.PP -\&\fBi2t_ASN1_OBJECT()\fR is the same as \fBOBJ_obj2txt()\fR with the \fIno_name\fR set to zero. -.PP -\&\fBOBJ_cmp()\fR compares \fIa\fR to \fIb\fR. If the two are identical 0 is returned. -.PP -\&\fBOBJ_dup()\fR returns a copy of \fIo\fR. -.PP -\&\fBOBJ_create()\fR adds a new object to the internal table. \fIoid\fR is the -numerical form of the object, \fIsn\fR the short name and \fIln\fR the -long name. A new \s-1NID\s0 is returned for the created object in case of -success and NID_undef in case of failure. Any of \fIoid\fR, \fIsn\fR and -\&\fIln\fR may be \s-1NULL,\s0 but not all at once. -.PP -\&\fBOBJ_length()\fR returns the size of the content octets of \fIobj\fR. -.PP -\&\fBOBJ_get0_data()\fR returns a pointer to the content octets of \fIobj\fR. -The returned pointer is an internal pointer which \fBmust not\fR be freed. -.PP -\&\fBOBJ_add_sigid()\fR creates a new composite \*(L"Signature Algorithm\*(R" that associates a -given \s-1NID\s0 with two other NIDs \- one representing the underlying signature -algorithm and the other representing a digest algorithm to be used in -conjunction with it. \fIsignid\fR represents the \s-1NID\s0 for the composite \*(L"Signature -Algorithm\*(R", \fIdig_id\fR is the \s-1NID\s0 for the digest algorithm and \fIpkey_id\fR is the -\&\s-1NID\s0 for the underlying signature algorithm. As there are signature algorithms -that do not require a digest, NID_undef is a valid \fIdig_id\fR. -.PP -\&\fBOBJ_cleanup()\fR releases any resources allocated by creating new objects. -.SH "NOTES" -.IX Header "NOTES" -Objects in OpenSSL can have a short name, a long name and a numerical -identifier (\s-1NID\s0) associated with them. A standard set of objects is -represented in an internal table. The appropriate values are defined -in the header file \fBobjects.h\fR. -.PP -For example the \s-1OID\s0 for commonName has the following definitions: -.PP -.Vb 3 -\& #define SN_commonName "CN" -\& #define LN_commonName "commonName" -\& #define NID_commonName 13 -.Ve -.PP -New objects can be added by calling \fBOBJ_create()\fR. -.PP -Table objects have certain advantages over other objects: for example -their NIDs can be used in a C language switch statement. They are -also static constant structures which are shared: that is there -is only a single constant structure for each table object. -.PP -Objects which are not in the table have the \s-1NID\s0 value NID_undef. -.PP -Objects do not need to be in the internal tables to be processed, -the functions \fBOBJ_txt2obj()\fR and \fBOBJ_obj2txt()\fR can process the numerical -form of an \s-1OID.\s0 -.PP -Some objects are used to represent algorithms which do not have a -corresponding \s-1ASN.1 OBJECT IDENTIFIER\s0 encoding (for example no \s-1OID\s0 currently -exists for a particular algorithm). As a result they \fBcannot\fR be encoded or -decoded as part of \s-1ASN.1\s0 structures. Applications can determine if there -is a corresponding \s-1OBJECT IDENTIFIER\s0 by checking \fBOBJ_length()\fR is not zero. -.PP -These functions cannot return \fBconst\fR because an \fB\s-1ASN1_OBJECT\s0\fR can -represent both an internal, constant, \s-1OID\s0 and a dynamically-created one. -The latter cannot be constant because it needs to be freed after use. -.PP -These functions were not thread safe in OpenSSL 3.0 and before. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOBJ_nid2obj()\fR returns an \fB\s-1ASN1_OBJECT\s0\fR structure or \fB\s-1NULL\s0\fR is an -error occurred. -.PP -\&\fBOBJ_nid2ln()\fR and \fBOBJ_nid2sn()\fR returns a valid string or \fB\s-1NULL\s0\fR -on error. -.PP -\&\fBOBJ_obj2nid()\fR, \fBOBJ_ln2nid()\fR, \fBOBJ_sn2nid()\fR and \fBOBJ_txt2nid()\fR return -a \s-1NID\s0 or \fBNID_undef\fR on error. -.PP -\&\fBOBJ_add_sigid()\fR returns 1 on success or 0 on error. -.PP -\&\fBi2t_ASN1_OBJECT()\fR an \fBOBJ_obj2txt()\fR return \-1 on error. -On success, they return the length of the string written to \fIbuf\fR if \fIbuf\fR is -not \s-1NULL\s0 and \fIbuf_len\fR is big enough, otherwise the total string length. -Note that this does not count the trailing \s-1NUL\s0 character. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create an object for \fBcommonName\fR: -.PP -.Vb 1 -\& ASN1_OBJECT *o = OBJ_nid2obj(NID_commonName); -.Ve -.PP -Check if an object is \fBcommonName\fR -.PP -.Vb 2 -\& if (OBJ_obj2nid(obj) == NID_commonName) -\& /* Do something */ -.Ve -.PP -Create a new \s-1NID\s0 and initialize an object from it: -.PP -.Vb 2 -\& int new_nid = OBJ_create("1.2.3.4", "NewOID", "New Object Identifier"); -\& ASN1_OBJECT *obj = OBJ_nid2obj(new_nid); -.Ve -.PP -Create a new object directly: -.PP -.Vb 1 -\& obj = OBJ_txt2obj("1.2.3.4", 1); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOBJ_cleanup()\fR was deprecated in OpenSSL 1.1.0 by \fBOPENSSL_init_crypto\fR\|(3) -and should not be used. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OBJ_nid2sn.3ossl b/openssl-install/share/man/man3/OBJ_nid2sn.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_nid2sn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_obj2nid.3ossl b/openssl-install/share/man/man3/OBJ_obj2nid.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_obj2nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_obj2txt.3ossl b/openssl-install/share/man/man3/OBJ_obj2txt.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_obj2txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_sn2nid.3ossl b/openssl-install/share/man/man3/OBJ_sn2nid.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_sn2nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_txt2nid.3ossl b/openssl-install/share/man/man3/OBJ_txt2nid.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_txt2nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OBJ_txt2obj.3ossl b/openssl-install/share/man/man3/OBJ_txt2obj.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/OBJ_txt2obj.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_BASICRESP_free.3ossl b/openssl-install/share/man/man3/OCSP_BASICRESP_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_BASICRESP_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_BASICRESP_new.3ossl b/openssl-install/share/man/man3/OCSP_BASICRESP_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_BASICRESP_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_CERTID_dup.3ossl b/openssl-install/share/man/man3/OCSP_CERTID_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_CERTID_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_CERTID_free.3ossl b/openssl-install/share/man/man3/OCSP_CERTID_free.3ossl deleted file mode 120000 index 9eb2d6a3..00000000 --- a/openssl-install/share/man/man3/OCSP_CERTID_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_cert_to_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_CERTID_new.3ossl b/openssl-install/share/man/man3/OCSP_CERTID_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_CERTID_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_CERTSTATUS_free.3ossl b/openssl-install/share/man/man3/OCSP_CERTSTATUS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_CERTSTATUS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_CERTSTATUS_new.3ossl b/openssl-install/share/man/man3/OCSP_CERTSTATUS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_CERTSTATUS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_CRLID_free.3ossl b/openssl-install/share/man/man3/OCSP_CRLID_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_CRLID_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_CRLID_new.3ossl b/openssl-install/share/man/man3/OCSP_CRLID_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_CRLID_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_ONEREQ_free.3ossl b/openssl-install/share/man/man3/OCSP_ONEREQ_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_ONEREQ_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_ONEREQ_new.3ossl b/openssl-install/share/man/man3/OCSP_ONEREQ_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_ONEREQ_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQINFO_free.3ossl b/openssl-install/share/man/man3/OCSP_REQINFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_REQINFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQINFO_new.3ossl b/openssl-install/share/man/man3/OCSP_REQINFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_REQINFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQUEST_free.3ossl b/openssl-install/share/man/man3/OCSP_REQUEST_free.3ossl deleted file mode 120000 index 9422ed41..00000000 --- a/openssl-install/share/man/man3/OCSP_REQUEST_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_REQUEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQUEST_new.3ossl b/openssl-install/share/man/man3/OCSP_REQUEST_new.3ossl deleted file mode 100644 index 0b298009..00000000 --- a/openssl-install/share/man/man3/OCSP_REQUEST_new.3ossl +++ /dev/null @@ -1,251 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OCSP_REQUEST_NEW 3ossl" -.TH OCSP_REQUEST_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OCSP_REQUEST_new, OCSP_REQUEST_free, OCSP_request_add0_id, OCSP_request_sign, -OCSP_request_add1_cert, OCSP_request_onereq_count, -OCSP_request_onereq_get0 \- OCSP request functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OCSP_REQUEST *OCSP_REQUEST_new(void); -\& void OCSP_REQUEST_free(OCSP_REQUEST *req); -\& -\& OCSP_ONEREQ *OCSP_request_add0_id(OCSP_REQUEST *req, OCSP_CERTID *cid); -\& -\& int OCSP_request_sign(OCSP_REQUEST *req, -\& X509 *signer, EVP_PKEY *key, const EVP_MD *dgst, -\& STACK_OF(X509) *certs, unsigned long flags); -\& -\& int OCSP_request_add1_cert(OCSP_REQUEST *req, X509 *cert); -\& -\& int OCSP_request_onereq_count(OCSP_REQUEST *req); -\& OCSP_ONEREQ *OCSP_request_onereq_get0(OCSP_REQUEST *req, int i); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOCSP_REQUEST_new()\fR allocates and returns an empty \fB\s-1OCSP_REQUEST\s0\fR structure. -.PP -\&\fBOCSP_REQUEST_free()\fR frees up the request structure \fBreq\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOCSP_request_add0_id()\fR adds certificate \s-1ID\s0 \fBcid\fR to \fBreq\fR. It returns -the \fB\s-1OCSP_ONEREQ\s0\fR structure added so an application can add additional -extensions to the request. The \fBid\fR parameter \fB\s-1MUST NOT\s0\fR be freed up after -the operation. -.PP -\&\fBOCSP_request_sign()\fR signs \s-1OCSP\s0 request \fBreq\fR using certificate -\&\fBsigner\fR, private key \fBkey\fR, digest \fBdgst\fR and additional certificates -\&\fBcerts\fR. If the \fBflags\fR option \fB\s-1OCSP_NOCERTS\s0\fR is set then no certificates -will be included in the request. -.PP -\&\fBOCSP_request_add1_cert()\fR adds certificate \fBcert\fR to request \fBreq\fR. The -application is responsible for freeing up \fBcert\fR after use. -.PP -\&\fBOCSP_request_onereq_count()\fR returns the total number of \fB\s-1OCSP_ONEREQ\s0\fR -structures in \fBreq\fR. -.PP -\&\fBOCSP_request_onereq_get0()\fR returns an internal pointer to the \fB\s-1OCSP_ONEREQ\s0\fR -contained in \fBreq\fR of index \fBi\fR. The index value \fBi\fR runs from 0 to -OCSP_request_onereq_count(req) \- 1. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOCSP_REQUEST_new()\fR returns an empty \fB\s-1OCSP_REQUEST\s0\fR structure or \fB\s-1NULL\s0\fR if -an error occurred. -.PP -\&\fBOCSP_request_add0_id()\fR returns the \fB\s-1OCSP_ONEREQ\s0\fR structure containing \fBcid\fR -or \fB\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBOCSP_request_sign()\fR and \fBOCSP_request_add1_cert()\fR return 1 for success and 0 -for failure. -.PP -\&\fBOCSP_request_onereq_count()\fR returns the total number of \fB\s-1OCSP_ONEREQ\s0\fR -structures in \fBreq\fR and \-1 on error. -.PP -\&\fBOCSP_request_onereq_get0()\fR returns a pointer to an \fB\s-1OCSP_ONEREQ\s0\fR structure -or \fB\s-1NULL\s0\fR if the index value is out or range. -.SH "NOTES" -.IX Header "NOTES" -An \s-1OCSP\s0 request structure contains one or more \fB\s-1OCSP_ONEREQ\s0\fR structures -corresponding to each certificate. -.PP -\&\fBOCSP_request_onereq_count()\fR and \fBOCSP_request_onereq_get0()\fR are mainly used by -\&\s-1OCSP\s0 responders. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create an \fB\s-1OCSP_REQUEST\s0\fR structure for certificate \fBcert\fR with issuer -\&\fBissuer\fR: -.PP -.Vb 2 -\& OCSP_REQUEST *req; -\& OCSP_ID *cid; -\& -\& req = OCSP_REQUEST_new(); -\& if (req == NULL) -\& /* error */ -\& cid = OCSP_cert_to_id(EVP_sha1(), cert, issuer); -\& if (cid == NULL) -\& /* error */ -\& -\& if (OCSP_REQUEST_add0_id(req, cid) == NULL) -\& /* error */ -\& -\& /* Do something with req, e.g. query responder */ -\& -\& OCSP_REQUEST_free(req); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), -\&\fBOCSP_cert_to_id\fR\|(3), -\&\fBOCSP_request_add1_nonce\fR\|(3), -\&\fBOCSP_resp_find_status\fR\|(3), -\&\fBOCSP_response_status\fR\|(3), -\&\fBOCSP_sendreq_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OCSP_REQ_CTX.3ossl b/openssl-install/share/man/man3/OCSP_REQ_CTX.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_REQ_CTX.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQ_CTX_add1_header.3ossl b/openssl-install/share/man/man3/OCSP_REQ_CTX_add1_header.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_REQ_CTX_add1_header.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQ_CTX_free.3ossl b/openssl-install/share/man/man3/OCSP_REQ_CTX_free.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_REQ_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQ_CTX_i2d.3ossl b/openssl-install/share/man/man3/OCSP_REQ_CTX_i2d.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_REQ_CTX_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REQ_CTX_set1_req.3ossl b/openssl-install/share/man/man3/OCSP_REQ_CTX_set1_req.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_REQ_CTX_set1_req.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPBYTES_free.3ossl b/openssl-install/share/man/man3/OCSP_RESPBYTES_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPBYTES_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPBYTES_new.3ossl b/openssl-install/share/man/man3/OCSP_RESPBYTES_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPBYTES_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPDATA_free.3ossl b/openssl-install/share/man/man3/OCSP_RESPDATA_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPDATA_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPDATA_new.3ossl b/openssl-install/share/man/man3/OCSP_RESPDATA_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPDATA_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPID_free.3ossl b/openssl-install/share/man/man3/OCSP_RESPID_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPID_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPID_match.3ossl b/openssl-install/share/man/man3/OCSP_RESPID_match.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPID_match.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPID_match_ex.3ossl b/openssl-install/share/man/man3/OCSP_RESPID_match_ex.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPID_match_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPID_new.3ossl b/openssl-install/share/man/man3/OCSP_RESPID_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPID_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPID_set_by_key.3ossl b/openssl-install/share/man/man3/OCSP_RESPID_set_by_key.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPID_set_by_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPID_set_by_key_ex.3ossl b/openssl-install/share/man/man3/OCSP_RESPID_set_by_key_ex.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPID_set_by_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPID_set_by_name.3ossl b/openssl-install/share/man/man3/OCSP_RESPID_set_by_name.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPID_set_by_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPONSE_free.3ossl b/openssl-install/share/man/man3/OCSP_RESPONSE_free.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPONSE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_RESPONSE_new.3ossl b/openssl-install/share/man/man3/OCSP_RESPONSE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_RESPONSE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REVOKEDINFO_free.3ossl b/openssl-install/share/man/man3/OCSP_REVOKEDINFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_REVOKEDINFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_REVOKEDINFO_new.3ossl b/openssl-install/share/man/man3/OCSP_REVOKEDINFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_REVOKEDINFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_SERVICELOC_free.3ossl b/openssl-install/share/man/man3/OCSP_SERVICELOC_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_SERVICELOC_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_SERVICELOC_new.3ossl b/openssl-install/share/man/man3/OCSP_SERVICELOC_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_SERVICELOC_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_SIGNATURE_free.3ossl b/openssl-install/share/man/man3/OCSP_SIGNATURE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_SIGNATURE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_SIGNATURE_new.3ossl b/openssl-install/share/man/man3/OCSP_SIGNATURE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_SIGNATURE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_SINGLERESP_free.3ossl b/openssl-install/share/man/man3/OCSP_SINGLERESP_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_SINGLERESP_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_SINGLERESP_new.3ossl b/openssl-install/share/man/man3/OCSP_SINGLERESP_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OCSP_SINGLERESP_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_basic_add1_nonce.3ossl b/openssl-install/share/man/man3/OCSP_basic_add1_nonce.3ossl deleted file mode 120000 index e5d4a48a..00000000 --- a/openssl-install/share/man/man3/OCSP_basic_add1_nonce.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_request_add1_nonce.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_basic_sign.3ossl b/openssl-install/share/man/man3/OCSP_basic_sign.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_basic_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_basic_sign_ctx.3ossl b/openssl-install/share/man/man3/OCSP_basic_sign_ctx.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_basic_sign_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_basic_verify.3ossl b/openssl-install/share/man/man3/OCSP_basic_verify.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_basic_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_cert_id_new.3ossl b/openssl-install/share/man/man3/OCSP_cert_id_new.3ossl deleted file mode 120000 index 9eb2d6a3..00000000 --- a/openssl-install/share/man/man3/OCSP_cert_id_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_cert_to_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_cert_to_id.3ossl b/openssl-install/share/man/man3/OCSP_cert_to_id.3ossl deleted file mode 100644 index e7309f99..00000000 --- a/openssl-install/share/man/man3/OCSP_cert_to_id.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OCSP_CERT_TO_ID 3ossl" -.TH OCSP_CERT_TO_ID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OCSP_cert_to_id, OCSP_cert_id_new, OCSP_CERTID_free, OCSP_id_issuer_cmp, -OCSP_id_cmp, OCSP_id_get0_info \- OCSP certificate ID utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OCSP_CERTID *OCSP_cert_to_id(const EVP_MD *dgst, -\& X509 *subject, X509 *issuer); -\& -\& OCSP_CERTID *OCSP_cert_id_new(const EVP_MD *dgst, -\& X509_NAME *issuerName, -\& ASN1_BIT_STRING *issuerKey, -\& ASN1_INTEGER *serialNumber); -\& -\& void OCSP_CERTID_free(OCSP_CERTID *id); -\& -\& int OCSP_id_issuer_cmp(const OCSP_CERTID *a, const OCSP_CERTID *b); -\& int OCSP_id_cmp(const OCSP_CERTID *a, const OCSP_CERTID *b); -\& -\& int OCSP_id_get0_info(ASN1_OCTET_STRING **piNameHash, ASN1_OBJECT **pmd, -\& ASN1_OCTET_STRING **pikeyHash, -\& ASN1_INTEGER **pserial, OCSP_CERTID *cid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOCSP_cert_to_id()\fR creates and returns a new \fB\s-1OCSP_CERTID\s0\fR structure using -message digest \fBdgst\fR for certificate \fBsubject\fR with issuer \fBissuer\fR. If -\&\fBdgst\fR is \fB\s-1NULL\s0\fR then \s-1SHA1\s0 is used. -.PP -\&\fBOCSP_cert_id_new()\fR creates and returns a new \fB\s-1OCSP_CERTID\s0\fR using \fBdgst\fR and -issuer name \fBissuerName\fR, issuer key hash \fBissuerKey\fR and serial number -\&\fBserialNumber\fR. -.PP -\&\fBOCSP_CERTID_free()\fR frees up \fBid\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOCSP_id_cmp()\fR compares \fB\s-1OCSP_CERTID\s0\fR \fBa\fR and \fBb\fR. -.PP -\&\fBOCSP_id_issuer_cmp()\fR compares only the issuer name of \fB\s-1OCSP_CERTID\s0\fR \fBa\fR and \fBb\fR. -.PP -\&\fBOCSP_id_get0_info()\fR returns the issuer name hash, hash \s-1OID,\s0 issuer key hash and -serial number contained in \fBcid\fR. If any of the values are not required the -corresponding parameter can be set to \fB\s-1NULL\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOCSP_cert_to_id()\fR and \fBOCSP_cert_id_new()\fR return either a pointer to a valid -\&\fB\s-1OCSP_CERTID\s0\fR structure or \fB\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBOCSP_id_cmp()\fR and \fBOCSP_id_issuer_cmp()\fR returns zero for a match and nonzero -otherwise. -.PP -\&\fBOCSP_CERTID_free()\fR does not return a value. -.PP -\&\fBOCSP_id_get0_info()\fR returns 1 for success and 0 for failure. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1OCSP\s0 clients will typically only use \fBOCSP_cert_to_id()\fR or \fBOCSP_cert_id_new()\fR: -the other functions are used by responder applications. -.PP -The values returned by \fBOCSP_id_get0_info()\fR are internal pointers and \fB\s-1MUST -NOT\s0\fR be freed up by an application: they will be freed when the corresponding -\&\fB\s-1OCSP_CERTID\s0\fR structure is freed. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), -\&\fBOCSP_request_add1_nonce\fR\|(3), -\&\fBOCSP_REQUEST_new\fR\|(3), -\&\fBOCSP_resp_find_status\fR\|(3), -\&\fBOCSP_response_status\fR\|(3), -\&\fBOCSP_sendreq_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OCSP_check_nonce.3ossl b/openssl-install/share/man/man3/OCSP_check_nonce.3ossl deleted file mode 120000 index e5d4a48a..00000000 --- a/openssl-install/share/man/man3/OCSP_check_nonce.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_request_add1_nonce.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_check_validity.3ossl b/openssl-install/share/man/man3/OCSP_check_validity.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_check_validity.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_copy_nonce.3ossl b/openssl-install/share/man/man3/OCSP_copy_nonce.3ossl deleted file mode 120000 index e5d4a48a..00000000 --- a/openssl-install/share/man/man3/OCSP_copy_nonce.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_request_add1_nonce.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_id_cmp.3ossl b/openssl-install/share/man/man3/OCSP_id_cmp.3ossl deleted file mode 120000 index 9eb2d6a3..00000000 --- a/openssl-install/share/man/man3/OCSP_id_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_cert_to_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_id_get0_info.3ossl b/openssl-install/share/man/man3/OCSP_id_get0_info.3ossl deleted file mode 120000 index 9eb2d6a3..00000000 --- a/openssl-install/share/man/man3/OCSP_id_get0_info.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_cert_to_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_id_issuer_cmp.3ossl b/openssl-install/share/man/man3/OCSP_id_issuer_cmp.3ossl deleted file mode 120000 index 9eb2d6a3..00000000 --- a/openssl-install/share/man/man3/OCSP_id_issuer_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_cert_to_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_parse_url.3ossl b/openssl-install/share/man/man3/OCSP_parse_url.3ossl deleted file mode 120000 index 0a203382..00000000 --- a/openssl-install/share/man/man3/OCSP_parse_url.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_parse_url.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_request_add0_id.3ossl b/openssl-install/share/man/man3/OCSP_request_add0_id.3ossl deleted file mode 120000 index 9422ed41..00000000 --- a/openssl-install/share/man/man3/OCSP_request_add0_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_REQUEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_request_add1_cert.3ossl b/openssl-install/share/man/man3/OCSP_request_add1_cert.3ossl deleted file mode 120000 index 9422ed41..00000000 --- a/openssl-install/share/man/man3/OCSP_request_add1_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_REQUEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_request_add1_nonce.3ossl b/openssl-install/share/man/man3/OCSP_request_add1_nonce.3ossl deleted file mode 100644 index 909ffb61..00000000 --- a/openssl-install/share/man/man3/OCSP_request_add1_nonce.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OCSP_REQUEST_ADD1_NONCE 3ossl" -.TH OCSP_REQUEST_ADD1_NONCE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OCSP_request_add1_nonce, OCSP_basic_add1_nonce, OCSP_check_nonce, OCSP_copy_nonce \- OCSP nonce functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OCSP_request_add1_nonce(OCSP_REQUEST *req, unsigned char *val, int len); -\& int OCSP_basic_add1_nonce(OCSP_BASICRESP *resp, unsigned char *val, int len); -\& int OCSP_copy_nonce(OCSP_BASICRESP *resp, OCSP_REQUEST *req); -\& int OCSP_check_nonce(OCSP_REQUEST *req, OCSP_BASICRESP *resp); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOCSP_request_add1_nonce()\fR adds a nonce of value \fBval\fR and length \fBlen\fR to -\&\s-1OCSP\s0 request \fBreq\fR. If \fBval\fR is \fB\s-1NULL\s0\fR a random nonce is used. If \fBlen\fR -is zero or negative a default length will be used (currently 16 bytes). -.PP -\&\fBOCSP_basic_add1_nonce()\fR is identical to \fBOCSP_request_add1_nonce()\fR except -it adds a nonce to \s-1OCSP\s0 basic response \fBresp\fR. -.PP -\&\fBOCSP_check_nonce()\fR compares the nonce value in \fBreq\fR and \fBresp\fR. -.PP -\&\fBOCSP_copy_nonce()\fR copies any nonce value present in \fBreq\fR to \fBresp\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOCSP_request_add1_nonce()\fR and \fBOCSP_basic_add1_nonce()\fR return 1 for success -and 0 for failure. -.PP -\&\fBOCSP_copy_nonce()\fR returns 1 if a nonce was successfully copied, 2 if no nonce -was present in \fBreq\fR and 0 if an error occurred. -.PP -\&\fBOCSP_check_nonce()\fR returns the result of the nonce comparison between \fBreq\fR -and \fBresp\fR. The return value indicates the result of the comparison. If -nonces are present and equal 1 is returned. If the nonces are absent 2 is -returned. If a nonce is present in the response only 3 is returned. If nonces -are present and unequal 0 is returned. If the nonce is present in the request -only then \-1 is returned. -.SH "NOTES" -.IX Header "NOTES" -For most purposes the nonce value in a request is set to a random value so -the \fBval\fR parameter in \fBOCSP_request_add1_nonce()\fR is usually \s-1NULL.\s0 -.PP -An \s-1OCSP\s0 nonce is typically added to an \s-1OCSP\s0 request to thwart replay attacks -by checking the same nonce value appears in the response. -.PP -Some responders may include a nonce in all responses even if one is not -supplied. -.PP -Some responders cache \s-1OCSP\s0 responses and do not sign each response for -performance reasons. As a result they do not support nonces. -.PP -The return values of \fBOCSP_check_nonce()\fR can be checked to cover each case. A -positive return value effectively indicates success: nonces are both present -and match, both absent or present in the response only. A nonzero return -additionally covers the case where the nonce is present in the request only: -this will happen if the responder doesn't support nonces. A zero return value -indicates present and mismatched nonces: this should be treated as an error -condition. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), -\&\fBOCSP_cert_to_id\fR\|(3), -\&\fBOCSP_REQUEST_new\fR\|(3), -\&\fBOCSP_resp_find_status\fR\|(3), -\&\fBOCSP_response_status\fR\|(3), -\&\fBOCSP_sendreq_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OCSP_request_onereq_count.3ossl b/openssl-install/share/man/man3/OCSP_request_onereq_count.3ossl deleted file mode 120000 index 9422ed41..00000000 --- a/openssl-install/share/man/man3/OCSP_request_onereq_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_REQUEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_request_onereq_get0.3ossl b/openssl-install/share/man/man3/OCSP_request_onereq_get0.3ossl deleted file mode 120000 index 9422ed41..00000000 --- a/openssl-install/share/man/man3/OCSP_request_onereq_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_REQUEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_request_sign.3ossl b/openssl-install/share/man/man3/OCSP_request_sign.3ossl deleted file mode 120000 index 9422ed41..00000000 --- a/openssl-install/share/man/man3/OCSP_request_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_REQUEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_count.3ossl b/openssl-install/share/man/man3/OCSP_resp_count.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_find.3ossl b/openssl-install/share/man/man3/OCSP_resp_find.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_find_status.3ossl b/openssl-install/share/man/man3/OCSP_resp_find_status.3ossl deleted file mode 100644 index 2d91c725..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_find_status.3ossl +++ /dev/null @@ -1,351 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OCSP_RESP_FIND_STATUS 3ossl" -.TH OCSP_RESP_FIND_STATUS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OCSP_resp_find_status, OCSP_resp_count, -OCSP_resp_get0, OCSP_resp_find, OCSP_single_get0_status, -OCSP_resp_get0_produced_at, OCSP_resp_get0_signature, -OCSP_resp_get0_tbs_sigalg, OCSP_resp_get0_respdata, -OCSP_resp_get0_certs, OCSP_resp_get0_signer, -OCSP_resp_get0_id, OCSP_resp_get1_id, -OCSP_check_validity, OCSP_basic_verify -\&\- OCSP response utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OCSP_resp_find_status(OCSP_BASICRESP *bs, OCSP_CERTID *id, int *status, -\& int *reason, -\& ASN1_GENERALIZEDTIME **revtime, -\& ASN1_GENERALIZEDTIME **thisupd, -\& ASN1_GENERALIZEDTIME **nextupd); -\& -\& int OCSP_resp_count(OCSP_BASICRESP *bs); -\& OCSP_SINGLERESP *OCSP_resp_get0(OCSP_BASICRESP *bs, int idx); -\& int OCSP_resp_find(OCSP_BASICRESP *bs, OCSP_CERTID *id, int last); -\& int OCSP_single_get0_status(OCSP_SINGLERESP *single, int *reason, -\& ASN1_GENERALIZEDTIME **revtime, -\& ASN1_GENERALIZEDTIME **thisupd, -\& ASN1_GENERALIZEDTIME **nextupd); -\& -\& const ASN1_GENERALIZEDTIME *OCSP_resp_get0_produced_at( -\& const OCSP_BASICRESP* single); -\& -\& const ASN1_OCTET_STRING *OCSP_resp_get0_signature(const OCSP_BASICRESP *bs); -\& const X509_ALGOR *OCSP_resp_get0_tbs_sigalg(const OCSP_BASICRESP *bs); -\& const OCSP_RESPDATA *OCSP_resp_get0_respdata(const OCSP_BASICRESP *bs); -\& const STACK_OF(X509) *OCSP_resp_get0_certs(const OCSP_BASICRESP *bs); -\& -\& int OCSP_resp_get0_signer(OCSP_BASICRESP *bs, X509 **signer, -\& STACK_OF(X509) *extra_certs); -\& -\& int OCSP_resp_get0_id(const OCSP_BASICRESP *bs, -\& const ASN1_OCTET_STRING **pid, -\& const X509_NAME **pname); -\& int OCSP_resp_get1_id(const OCSP_BASICRESP *bs, -\& ASN1_OCTET_STRING **pid, -\& X509_NAME **pname); -\& -\& int OCSP_check_validity(ASN1_GENERALIZEDTIME *thisupd, -\& ASN1_GENERALIZEDTIME *nextupd, -\& long sec, long maxsec); -\& -\& int OCSP_basic_verify(OCSP_BASICRESP *bs, STACK_OF(X509) *certs, -\& X509_STORE *st, unsigned long flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOCSP_resp_find_status()\fR searches \fIbs\fR for an \s-1OCSP\s0 response for \fIid\fR. If it is -successful the fields of the response are returned in \fI*status\fR, \fI*reason\fR, -\&\fI*revtime\fR, \fI*thisupd\fR and \fI*nextupd\fR. The \fI*status\fR value will be one of -\&\fBV_OCSP_CERTSTATUS_GOOD\fR, \fBV_OCSP_CERTSTATUS_REVOKED\fR or -\&\fBV_OCSP_CERTSTATUS_UNKNOWN\fR. The \fI*reason\fR and \fI*revtime\fR fields are only -set if the status is \fBV_OCSP_CERTSTATUS_REVOKED\fR. If set the \fI*reason\fR field -will be set to the revocation reason which will be one of -\&\fB\s-1OCSP_REVOKED_STATUS_NOSTATUS\s0\fR, \fB\s-1OCSP_REVOKED_STATUS_UNSPECIFIED\s0\fR, -\&\fB\s-1OCSP_REVOKED_STATUS_KEYCOMPROMISE\s0\fR, \fB\s-1OCSP_REVOKED_STATUS_CACOMPROMISE\s0\fR, -\&\fB\s-1OCSP_REVOKED_STATUS_AFFILIATIONCHANGED\s0\fR, \fB\s-1OCSP_REVOKED_STATUS_SUPERSEDED\s0\fR, -\&\fB\s-1OCSP_REVOKED_STATUS_CESSATIONOFOPERATION\s0\fR, -\&\fB\s-1OCSP_REVOKED_STATUS_CERTIFICATEHOLD\s0\fR or \fB\s-1OCSP_REVOKED_STATUS_REMOVEFROMCRL\s0\fR. -.PP -\&\fBOCSP_resp_count()\fR returns the number of \fB\s-1OCSP_SINGLERESP\s0\fR structures in \fIbs\fR. -.PP -\&\fBOCSP_resp_get0()\fR returns the \fB\s-1OCSP_SINGLERESP\s0\fR structure in \fIbs\fR corresponding -to index \fIidx\fR, where \fIidx\fR runs from 0 to OCSP_resp_count(bs) \- 1. -.PP -\&\fBOCSP_resp_find()\fR searches \fIbs\fR for \fIid\fR and returns the index of the first -matching entry after \fIlast\fR or starting from the beginning if \fIlast\fR is \-1. -.PP -\&\fBOCSP_single_get0_status()\fR extracts the fields of \fIsingle\fR in \fI*reason\fR, -\&\fI*revtime\fR, \fI*thisupd\fR and \fI*nextupd\fR. -.PP -\&\fBOCSP_resp_get0_produced_at()\fR extracts the \fBproducedAt\fR field from the -single response \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_signature()\fR returns the signature from \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_tbs_sigalg()\fR returns the \fBsignatureAlgorithm\fR from \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_respdata()\fR returns the \fBtbsResponseData\fR from \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_certs()\fR returns any certificates included in \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_signer()\fR attempts to retrieve the certificate that directly -signed \fIbs\fR. The \s-1OCSP\s0 protocol does not require that this certificate -is included in the \fBcerts\fR field of the response, so additional certificates -can be supplied via the \fIextra_certs\fR if the certificates that may have -signed the response are known via some out-of-band mechanism. -.PP -\&\fBOCSP_resp_get0_id()\fR gets the responder id of \fIbs\fR. If the responder \s-1ID\s0 is -a name then <*pname> is set to the name and \fI*pid\fR is set to \s-1NULL.\s0 If the -responder \s-1ID\s0 is by key \s-1ID\s0 then \fI*pid\fR is set to the key \s-1ID\s0 and \fI*pname\fR -is set to \s-1NULL.\s0 -.PP -\&\fBOCSP_resp_get1_id()\fR is the same as \fBOCSP_resp_get0_id()\fR -but leaves ownership of \fI*pid\fR and \fI*pname\fR with the caller, -who is responsible for freeing them unless the function returns 0. -.PP -\&\fBOCSP_check_validity()\fR checks the validity of its \fIthisupd\fR and \fInextupd\fR -arguments, which will be typically obtained from \fBOCSP_resp_find_status()\fR or -\&\fBOCSP_single_get0_status()\fR. If \fIsec\fR is nonzero it indicates how many seconds -leeway should be allowed in the check. If \fImaxsec\fR is positive it indicates -the maximum age of \fIthisupd\fR in seconds. -.PP -\&\fBOCSP_basic_verify()\fR checks that the basic response message \fIbs\fR is correctly -signed and that the signer certificate can be validated. It takes \fIst\fR as -the trusted store and \fIcerts\fR as a set of untrusted intermediate certificates. -The function first tries to find the signer certificate of the response -in \fIcerts\fR. It then searches the certificates the responder may have included -in \fIbs\fR unless \fIflags\fR contains \fB\s-1OCSP_NOINTERN\s0\fR. -It fails if the signer certificate cannot be found. -Next, unless \fIflags\fR contains \fB\s-1OCSP_NOSIGS\s0\fR, the function checks -the signature of \fIbs\fR and fails on error. Then the function already returns -success if \fIflags\fR contains \fB\s-1OCSP_NOVERIFY\s0\fR or if the signer certificate -was found in \fIcerts\fR and \fIflags\fR contains \fB\s-1OCSP_TRUSTOTHER\s0\fR. -Otherwise the function continues by validating the signer certificate. -If \fIflags\fR contains \fB\s-1OCSP_PARTIAL_CHAIN\s0\fR it takes intermediate \s-1CA\s0 -certificates in \fIst\fR as trust anchors. -For more details, see the description of \fBX509_V_FLAG_PARTIAL_CHAIN\fR -in \*(L"\s-1VERIFICATION FLAGS\*(R"\s0 in \fBX509_VERIFY_PARAM_set_flags\fR\|(3). -If \fIflags\fR contains \fB\s-1OCSP_NOCHAIN\s0\fR it ignores all certificates in \fIcerts\fR -and in \fIbs\fR, else it takes them as untrusted intermediate \s-1CA\s0 certificates -and uses them for constructing the validation path for the signer certificate. -Certificate revocation status checks using CRLs is disabled during path validation -if the signer certificate contains the \fBid-pkix-ocsp-no-check\fR extension. -After successful path -validation the function returns success if the \fB\s-1OCSP_NOCHECKS\s0\fR flag is set. -Otherwise it verifies that the signer certificate meets the \s-1OCSP\s0 issuer -criteria including potential delegation. If this does not succeed and the -\&\fB\s-1OCSP_NOEXPLICIT\s0\fR flag is not set the function checks for explicit -trust for \s-1OCSP\s0 signing in the root \s-1CA\s0 certificate. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOCSP_resp_find_status()\fR returns 1 if \fIid\fR is found in \fIbs\fR and 0 otherwise. -.PP -\&\fBOCSP_resp_count()\fR returns the total number of \fB\s-1OCSP_SINGLERESP\s0\fR fields in \fIbs\fR -or \-1 on error. -.PP -\&\fBOCSP_resp_get0()\fR returns a pointer to an \fB\s-1OCSP_SINGLERESP\s0\fR structure or -\&\s-1NULL\s0 on error, such as \fIidx\fR being out of range. -.PP -\&\fBOCSP_resp_find()\fR returns the index of \fIid\fR in \fIbs\fR (which may be 0) -or \-1 on error, such as when \fIid\fR was not found. -.PP -\&\fBOCSP_single_get0_status()\fR returns the status of \fIsingle\fR or \-1 if an error -occurred. -.PP -\&\fBOCSP_resp_get0_produced_at()\fR returns the \fBproducedAt\fR field from \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_signature()\fR returns the signature from \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_tbs_sigalg()\fR returns the \fBsignatureAlgorithm\fR field from \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_respdata()\fR returns the \fBtbsResponseData\fR field from \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_certs()\fR returns any certificates included in \fIbs\fR. -.PP -\&\fBOCSP_resp_get0_signer()\fR returns 1 if the signing certificate was located, -or 0 if not found or on error. -.PP -\&\fBOCSP_resp_get0_id()\fR and \fBOCSP_resp_get1_id()\fR return 1 on success, 0 on failure. -.PP -\&\fBOCSP_check_validity()\fR returns 1 if \fIthisupd\fR and \fInextupd\fR are valid time -values and the current time + \fIsec\fR is not before \fIthisupd\fR and, -if \fImaxsec\fR >= 0, the current time \- \fImaxsec\fR is not past \fInextupd\fR. -Otherwise it returns 0 to indicate an error. -.PP -\&\fBOCSP_basic_verify()\fR returns 1 on success, 0 on verification not successful, -or \-1 on a fatal error such as malloc failure. -.SH "NOTES" -.IX Header "NOTES" -Applications will typically call \fBOCSP_resp_find_status()\fR using the certificate -\&\s-1ID\s0 of interest and then check its validity using \fBOCSP_check_validity()\fR. They -can then take appropriate action based on the status of the certificate. -.PP -An \s-1OCSP\s0 response for a certificate contains \fBthisUpdate\fR and \fBnextUpdate\fR -fields. Normally the current time should be between these two values. To -account for clock skew the \fImaxsec\fR field can be set to nonzero in -\&\fBOCSP_check_validity()\fR. Some responders do not set the \fBnextUpdate\fR field, this -would otherwise mean an ancient response would be considered valid: the -\&\fImaxsec\fR parameter to \fBOCSP_check_validity()\fR can be used to limit the permitted -age of responses. -.PP -The values written to \fI*revtime\fR, \fI*thisupd\fR and \fI*nextupd\fR by -\&\fBOCSP_resp_find_status()\fR and \fBOCSP_single_get0_status()\fR are internal pointers -which \s-1MUST NOT\s0 be freed up by the calling application. Any or all of these -parameters can be set to \s-1NULL\s0 if their value is not required. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), -\&\fBOCSP_cert_to_id\fR\|(3), -\&\fBOCSP_request_add1_nonce\fR\|(3), -\&\fBOCSP_REQUEST_new\fR\|(3), -\&\fBOCSP_response_status\fR\|(3), -\&\fBOCSP_sendreq_new\fR\|(3), -\&\fBX509_VERIFY_PARAM_set_flags\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OCSP_resp_get0.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get0_certs.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0_certs.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get0_id.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0_id.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get0_produced_at.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0_produced_at.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0_produced_at.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get0_respdata.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0_respdata.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0_respdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get0_signature.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0_signature.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get0_signer.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0_signer.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0_signer.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get0_tbs_sigalg.3ossl b/openssl-install/share/man/man3/OCSP_resp_get0_tbs_sigalg.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get0_tbs_sigalg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_resp_get1_id.3ossl b/openssl-install/share/man/man3/OCSP_resp_get1_id.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_resp_get1_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_response_create.3ossl b/openssl-install/share/man/man3/OCSP_response_create.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_response_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_response_get1_basic.3ossl b/openssl-install/share/man/man3/OCSP_response_get1_basic.3ossl deleted file mode 120000 index 5ccbe606..00000000 --- a/openssl-install/share/man/man3/OCSP_response_get1_basic.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_response_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_response_status.3ossl b/openssl-install/share/man/man3/OCSP_response_status.3ossl deleted file mode 100644 index 132d9a00..00000000 --- a/openssl-install/share/man/man3/OCSP_response_status.3ossl +++ /dev/null @@ -1,264 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OCSP_RESPONSE_STATUS 3ossl" -.TH OCSP_RESPONSE_STATUS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OCSP_response_status, OCSP_response_get1_basic, OCSP_response_create, -OCSP_RESPONSE_free, OCSP_RESPID_set_by_name, -OCSP_RESPID_set_by_key_ex, OCSP_RESPID_set_by_key, OCSP_RESPID_match_ex, -OCSP_RESPID_match, OCSP_basic_sign, OCSP_basic_sign_ctx -\&\- OCSP response functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OCSP_response_status(OCSP_RESPONSE *resp); -\& OCSP_BASICRESP *OCSP_response_get1_basic(OCSP_RESPONSE *resp); -\& OCSP_RESPONSE *OCSP_response_create(int status, OCSP_BASICRESP *bs); -\& void OCSP_RESPONSE_free(OCSP_RESPONSE *resp); -\& -\& int OCSP_RESPID_set_by_name(OCSP_RESPID *respid, X509 *cert); -\& int OCSP_RESPID_set_by_key_ex(OCSP_RESPID *respid, X509 *cert, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int OCSP_RESPID_set_by_key(OCSP_RESPID *respid, X509 *cert); -\& int OCSP_RESPID_match_ex(OCSP_RESPID *respid, X509 *cert, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int OCSP_RESPID_match(OCSP_RESPID *respid, X509 *cert); -\& -\& int OCSP_basic_sign(OCSP_BASICRESP *brsp, X509 *signer, EVP_PKEY *key, -\& const EVP_MD *dgst, STACK_OF(X509) *certs, -\& unsigned long flags); -\& int OCSP_basic_sign_ctx(OCSP_BASICRESP *brsp, X509 *signer, EVP_MD_CTX *ctx, -\& STACK_OF(X509) *certs, unsigned long flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOCSP_response_status()\fR returns the \s-1OCSP\s0 response status of \fIresp\fR. It returns -one of the values: \fI\s-1OCSP_RESPONSE_STATUS_SUCCESSFUL\s0\fR, -\&\fI\s-1OCSP_RESPONSE_STATUS_MALFORMEDREQUEST\s0\fR, -\&\fI\s-1OCSP_RESPONSE_STATUS_INTERNALERROR\s0\fR, \fI\s-1OCSP_RESPONSE_STATUS_TRYLATER\s0\fR -\&\fI\s-1OCSP_RESPONSE_STATUS_SIGREQUIRED\s0\fR, or \fI\s-1OCSP_RESPONSE_STATUS_UNAUTHORIZED\s0\fR. -.PP -\&\fBOCSP_response_get1_basic()\fR decodes and returns the \fI\s-1OCSP_BASICRESP\s0\fR structure -contained in \fIresp\fR. -.PP -\&\fBOCSP_response_create()\fR creates and returns an \fI\s-1OCSP_RESPONSE\s0\fR structure for -\&\fIstatus\fR and optionally including basic response \fIbs\fR. -.PP -\&\fBOCSP_RESPONSE_free()\fR frees up \s-1OCSP\s0 response \fIresp\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOCSP_RESPID_set_by_name()\fR sets the name of the \s-1OCSP_RESPID\s0 to be the same as the -subject name in the supplied X509 certificate \fIcert\fR for the \s-1OCSP\s0 responder. -.PP -\&\fBOCSP_RESPID_set_by_key_ex()\fR sets the key of the \s-1OCSP_RESPID\s0 to be the same as the -key in the supplied X509 certificate \fIcert\fR for the \s-1OCSP\s0 responder. The key is -stored as a \s-1SHA1\s0 hash. To calculate the hash the \s-1SHA1\s0 algorithm is fetched using -the library ctx \fIlibctx\fR and the property query string \fIpropq\fR (see -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information). -.PP -\&\fBOCSP_RESPID_set_by_key()\fR does the same as \fBOCSP_RESPID_set_by_key_ex()\fR except -that the default library context is used with an empty property query string. -.PP -Note that an \s-1OCSP_RESPID\s0 can only have one of the name, or the key set. Calling -\&\fBOCSP_RESPID_set_by_name()\fR or \fBOCSP_RESPID_set_by_key()\fR will clear any existing -setting. -.PP -\&\fBOCSP_RESPID_match_ex()\fR tests whether the \s-1OCSP_RESPID\s0 given in \fIrespid\fR matches -with the X509 certificate \fIcert\fR based on the \s-1SHA1\s0 hash. To calculate the hash -the \s-1SHA1\s0 algorithm is fetched using the library ctx \fIlibctx\fR and the property -query string \fIpropq\fR (see \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further -information). -.PP -\&\fBOCSP_RESPID_match()\fR does the same as \fBOCSP_RESPID_match_ex()\fR except that the -default library context is used with an empty property query string. -.PP -\&\fBOCSP_basic_sign()\fR signs \s-1OCSP\s0 response \fIbrsp\fR using certificate \fIsigner\fR, private key -\&\fIkey\fR, digest \fIdgst\fR and additional certificates \fIcerts\fR. If the \fIflags\fR option -\&\fI\s-1OCSP_NOCERTS\s0\fR is set then no certificates will be included in the response. If the -\&\fIflags\fR option \fI\s-1OCSP_RESPID_KEY\s0\fR is set then the responder is identified by key \s-1ID\s0 -rather than by name. \fBOCSP_basic_sign_ctx()\fR also signs \s-1OCSP\s0 response \fIbrsp\fR but -uses the parameters contained in digest context \fIctx\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOCSP_RESPONSE_status()\fR returns a status value. -.PP -\&\fBOCSP_response_get1_basic()\fR returns an \fI\s-1OCSP_BASICRESP\s0\fR structure pointer or -\&\fI\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBOCSP_response_create()\fR returns an \fI\s-1OCSP_RESPONSE\s0\fR structure pointer or \fI\s-1NULL\s0\fR -if an error occurred. -.PP -\&\fBOCSP_RESPONSE_free()\fR does not return a value. -.PP -\&\fBOCSP_RESPID_set_by_name()\fR, \fBOCSP_RESPID_set_by_key()\fR, \fBOCSP_basic_sign()\fR, and -\&\fBOCSP_basic_sign_ctx()\fR return 1 on success or 0 -on failure. -.PP -\&\fBOCSP_RESPID_match()\fR returns 1 if the \s-1OCSP_RESPID\s0 and the X509 certificate match -or 0 otherwise. -.SH "NOTES" -.IX Header "NOTES" -\&\fBOCSP_response_get1_basic()\fR is only called if the status of a response is -\&\fI\s-1OCSP_RESPONSE_STATUS_SUCCESSFUL\s0\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7) -\&\fBOCSP_cert_to_id\fR\|(3) -\&\fBOCSP_request_add1_nonce\fR\|(3) -\&\fBOCSP_REQUEST_new\fR\|(3) -\&\fBOCSP_resp_find_status\fR\|(3) -\&\fBOCSP_sendreq_new\fR\|(3) -\&\fBOCSP_RESPID_new\fR\|(3) -\&\fBOCSP_RESPID_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBOCSP_RESPID_set_by_name()\fR, \fBOCSP_RESPID_set_by_key()\fR and \fBOCSP_RESPID_match()\fR -functions were added in OpenSSL 1.1.0a. -.PP -The \fBOCSP_basic_sign_ctx()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OCSP_sendreq_bio.3ossl b/openssl-install/share/man/man3/OCSP_sendreq_bio.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_sendreq_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_sendreq_nbio.3ossl b/openssl-install/share/man/man3/OCSP_sendreq_nbio.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_sendreq_nbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_sendreq_new.3ossl b/openssl-install/share/man/man3/OCSP_sendreq_new.3ossl deleted file mode 100644 index e33924e4..00000000 --- a/openssl-install/share/man/man3/OCSP_sendreq_new.3ossl +++ /dev/null @@ -1,262 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OCSP_SENDREQ_NEW 3ossl" -.TH OCSP_SENDREQ_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OCSP_REQ_CTX, -OCSP_sendreq_new, -OCSP_sendreq_nbio, -OCSP_sendreq_bio, -OCSP_REQ_CTX_i2d, -OCSP_REQ_CTX_add1_header, -OCSP_REQ_CTX_free, -OCSP_set_max_response_length, -OCSP_REQ_CTX_set1_req -\&\- OCSP responder query functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_HTTP_REQ_CTX *OCSP_sendreq_new(BIO *io, const char *path, -\& const OCSP_REQUEST *req, int buf_size); -\& OCSP_RESPONSE *OCSP_sendreq_bio(BIO *io, const char *path, OCSP_REQUEST *req); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 8 -\& typedef OSSL_HTTP_REQ_CTX OCSP_REQ_CTX; -\& int OCSP_sendreq_nbio(OCSP_RESPONSE **presp, OSSL_HTTP_REQ_CTX *rctx); -\& int OCSP_REQ_CTX_i2d(OCSP_REQ_CT *rctx, const ASN1_ITEM *it, ASN1_VALUE *req); -\& int OCSP_REQ_CTX_add1_header(OCSP_REQ_CT *rctx, -\& const char *name, const char *value); -\& void OCSP_REQ_CTX_free(OCSP_REQ_CTX *rctx); -\& void OCSP_set_max_response_length(OCSP_REQ_CT *rctx, unsigned long len); -\& int OCSP_REQ_CTX_set1_req(OCSP_REQ_CTX *rctx, const OCSP_REQUEST *req); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions perform an \s-1OCSP POST\s0 request / response transfer over \s-1HTTP,\s0 -using the \s-1HTTP\s0 request functions described in \s-1\fBOSSL_HTTP_REQ_CTX\s0\fR\|(3). -.PP -The function \fBOCSP_sendreq_new()\fR builds a complete \fB\s-1OSSL_HTTP_REQ_CTX\s0\fR structure -with the \fB\s-1BIO\s0\fR \fIio\fR to be used for requests and response, the \s-1URL\s0 path \fIpath\fR, -optionally the \s-1OCSP\s0 request \fIreq\fR, and a response header maximum line length -of \fIbuf_size\fR. If \fIbuf_size\fR is zero a default value of 4KiB is used. -The \fIreq\fR may be set to \s-1NULL\s0 and provided later using \fBOCSP_REQ_CTX_set1_req()\fR -or \fBOSSL_HTTP_REQ_CTX_set1_req\fR\|(3). -The \fIio\fR and \fIpath\fR arguments to \fBOCSP_sendreq_new()\fR correspond to the -components of the \s-1URL.\s0 -For example if the responder \s-1URL\s0 is \f(CW\*(C`http://example.com/ocspreq\*(C'\fR the \s-1BIO\s0 -\&\fIio\fR should haven been connected to host \f(CW\*(C`example.com\*(C'\fR on port 80 and \fIpath\fR -should be set to \f(CW\*(C`/ocspreq\*(C'\fR. -.PP -\&\fBOCSP_sendreq_nbio()\fR attempts to send the request prepared in \fIrctx\fR -and to gather the response via \s-1HTTP,\s0 using the \s-1BIO\s0 \fIio\fR and \fIpath\fR -that were given when calling \fBOCSP_sendreq_new()\fR. -If the operation gets completed it assigns the response, -a pointer to a \fB\s-1OCSP_RESPONSE\s0\fR structure, in \fI*presp\fR. -The function may need to be called again if its result is \-1, which indicates -\&\fBBIO_should_retry\fR\|(3). In such a case it is advisable to sleep a little in -between, using \fBBIO_wait\fR\|(3) on the read \s-1BIO\s0 to prevent a busy loop. -.PP -\&\fBOCSP_sendreq_bio()\fR combines \fBOCSP_sendreq_new()\fR with as many calls of -\&\fBOCSP_sendreq_nbio()\fR as needed and then \fBOCSP_REQ_CTX_free()\fR, with a -response header maximum line length 4k. It waits indefinitely on a response. -It does not support setting a timeout or adding headers and is retained -for compatibility; use \fBOSSL_HTTP_transfer\fR\|(3) instead. -.PP -OCSP_REQ_CTX_i2d(rctx, it, req) is equivalent to the following: -.PP -.Vb 1 -\& OSSL_HTTP_REQ_CTX_set1_req(rctx, "application/ocsp\-request", it, req) -.Ve -.PP -OCSP_REQ_CTX_set1_req(rctx, req) is equivalent to the following: -.PP -.Vb 3 -\& OSSL_HTTP_REQ_CTX_set1_req(rctx, "application/ocsp\-request", -\& ASN1_ITEM_rptr(OCSP_REQUEST), -\& (const ASN1_VALUE *)req) -.Ve -.PP -The deprecated type and the remaining deprecated functions -have been superseded by the following equivalents: -\&\fB\s-1OCSP_REQ_CTX\s0\fR by \s-1\fBOSSL_HTTP_REQ_CTX\s0\fR\|(3), -\&\fBOCSP_REQ_CTX_add1_header()\fR by \fBOSSL_HTTP_REQ_CTX_add1_header\fR\|(3), -\&\fBOCSP_REQ_CTX_free()\fR by \fBOSSL_HTTP_REQ_CTX_free\fR\|(3), and -\&\fBOCSP_set_max_response_length()\fR by -\&\fBOSSL_HTTP_REQ_CTX_set_max_response_length\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOCSP_sendreq_new()\fR returns a valid \fB\s-1OSSL_HTTP_REQ_CTX\s0\fR structure or \s-1NULL\s0 -if an error occurred. -.PP -\&\fBOCSP_sendreq_nbio()\fR returns 1 for success, 0 on error, \-1 if retry is needed. -.PP -\&\fBOCSP_sendreq_bio()\fR returns the \fB\s-1OCSP_RESPONSE\s0\fR structure sent by the -responder or \s-1NULL\s0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_HTTP_REQ_CTX\s0\fR\|(3), \fBOSSL_HTTP_transfer\fR\|(3), -\&\fBOCSP_cert_to_id\fR\|(3), -\&\fBOCSP_request_add1_nonce\fR\|(3), -\&\fBOCSP_REQUEST_new\fR\|(3), -\&\fBOCSP_resp_find_status\fR\|(3), -\&\fBOCSP_response_status\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fB\s-1OCSP_REQ_CTX\s0\fR, -\&\fBOCSP_REQ_CTX_i2d()\fR, -\&\fBOCSP_REQ_CTX_add1_header()\fR, -\&\fBOCSP_REQ_CTX_free()\fR, -\&\fBOCSP_set_max_response_length()\fR, -and \fBOCSP_REQ_CTX_set1_req()\fR -were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OCSP_set_max_response_length.3ossl b/openssl-install/share/man/man3/OCSP_set_max_response_length.3ossl deleted file mode 120000 index 89ebfeb1..00000000 --- a/openssl-install/share/man/man3/OCSP_set_max_response_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_sendreq_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OCSP_single_get0_status.3ossl b/openssl-install/share/man/man3/OCSP_single_get0_status.3ossl deleted file mode 120000 index 173c00bf..00000000 --- a/openssl-install/share/man/man3/OCSP_single_get0_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -OCSP_resp_find_status.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_Applink.3ossl b/openssl-install/share/man/man3/OPENSSL_Applink.3ossl deleted file mode 100644 index a83d1654..00000000 --- a/openssl-install/share/man/man3/OPENSSL_Applink.3ossl +++ /dev/null @@ -1,168 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_APPLINK 3ossl" -.TH OPENSSL_APPLINK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_Applink \- glue between OpenSSL BIO and Win32 compiler run\-time -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& _\|_declspec(dllexport) void **OPENSSL_Applink(); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OPENSSL_Applink is application-side interface which provides a glue -between OpenSSL \s-1BIO\s0 layer and Win32 compiler run-time environment. -Even though it appears at application side, it's essentially OpenSSL -private interface. For this reason application developers are not -expected to implement it, but to compile provided module with -compiler of their choice and link it into the target application. -The referred module is available as \fIapplink.c\fR, located alongside -the public header files (only on the platforms where applicable). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Not available. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_FILE.3ossl b/openssl-install/share/man/man3/OPENSSL_FILE.3ossl deleted file mode 100644 index e1743289..00000000 --- a/openssl-install/share/man/man3/OPENSSL_FILE.3ossl +++ /dev/null @@ -1,187 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_FILE 3ossl" -.TH OPENSSL_FILE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_FILE, OPENSSL_LINE, OPENSSL_FUNC, -OPENSSL_MSTR, OPENSSL_MSTR_HELPER -\&\- generic C programming utility macros -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define OPENSSL_FILE /* typically: _\|_FILE_\|_ */ -\& #define OPENSSL_LINE /* typically: _\|_LINE_\|_ */ -\& #define OPENSSL_FUNC /* typically: _\|_func_\|_ */ -\& -\& #define OPENSSL_MSTR_HELPER(x) #x -\& #define OPENSSL_MSTR(x) OPENSSL_MSTR_HELPER(x) -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The macros \fB\s-1OPENSSL_FILE\s0\fR and \fB\s-1OPENSSL_LINE\s0\fR -typically yield the current filename and line number during C compilation. -When \fB\s-1OPENSSL_NO_FILENAMES\s0\fR is defined they yield \fB""\fR and \fB0\fR, respectively. -.PP -The macro \fB\s-1OPENSSL_FUNC\s0\fR attempts to yield the name of the C function -currently being compiled, as far as language and compiler versions allow. -Otherwise, it yields \*(L"(unknown function)\*(R". -.PP -The macro \fB\s-1OPENSSL_MSTR\s0\fR yields the expansion of the macro given as argument, -which is useful for concatenation with string constants. -The macro \fB\s-1OPENSSL_MSTR_HELPER\s0\fR is an auxiliary macro for this purpose. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -see above -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fB\s-1OPENSSL_FUNC\s0\fR, \fB\s-1OPENSSL_MSTR\s0\fR, and \fB\s-1OPENSSL_MSTR_HELPER\s0\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_FUNC.3ossl b/openssl-install/share/man/man3/OPENSSL_FUNC.3ossl deleted file mode 120000 index 4cf5726f..00000000 --- a/openssl-install/share/man/man3/OPENSSL_FUNC.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_FILE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_INIT_free.3ossl b/openssl-install/share/man/man3/OPENSSL_INIT_free.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_INIT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_INIT_new.3ossl b/openssl-install/share/man/man3/OPENSSL_INIT_new.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_INIT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_INIT_set_config_appname.3ossl b/openssl-install/share/man/man3/OPENSSL_INIT_set_config_appname.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_INIT_set_config_appname.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_INIT_set_config_file_flags.3ossl b/openssl-install/share/man/man3/OPENSSL_INIT_set_config_file_flags.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_INIT_set_config_file_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_INIT_set_config_filename.3ossl b/openssl-install/share/man/man3/OPENSSL_INIT_set_config_filename.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_INIT_set_config_filename.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_COMPFUNC.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_COMPFUNC.3ossl deleted file mode 100644 index 7b1f3685..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_COMPFUNC.3ossl +++ /dev/null @@ -1,475 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_LH_COMPFUNC 3ossl" -.TH OPENSSL_LH_COMPFUNC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -LHASH, LHASH_OF, DEFINE_LHASH_OF_EX, DEFINE_LHASH_OF, -OPENSSL_LH_COMPFUNC, OPENSSL_LH_HASHFUNC, OPENSSL_LH_DOALL_FUNC, -LHASH_DOALL_ARG_FN_TYPE, -IMPLEMENT_LHASH_HASH_FN, IMPLEMENT_LHASH_COMP_FN, -lh_TYPE_new, lh_TYPE_free, lh_TYPE_flush, -lh_TYPE_insert, lh_TYPE_delete, lh_TYPE_retrieve, -lh_TYPE_doall, lh_TYPE_doall_arg, lh_TYPE_num_items, lh_TYPE_get_down_load, -lh_TYPE_set_down_load, lh_TYPE_error, -OPENSSL_LH_new, OPENSSL_LH_free, OPENSSL_LH_flush, -OPENSSL_LH_insert, OPENSSL_LH_delete, OPENSSL_LH_retrieve, -OPENSSL_LH_doall, OPENSSL_LH_doall_arg, OPENSSL_LH_doall_arg_thunk, -OPENSSL_LH_set_thunks, OPENSSL_LH_num_items, -OPENSSL_LH_get_down_load, OPENSSL_LH_set_down_load, OPENSSL_LH_error -\&\- dynamic hash table -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& LHASH_OF(TYPE) -\& -\& DEFINE_LHASH_OF_EX(TYPE); -\& -\& LHASH_OF(TYPE) *lh_TYPE_new(OPENSSL_LH_HASHFUNC hash, OPENSSL_LH_COMPFUNC compare); -\& void lh_TYPE_free(LHASH_OF(TYPE) *table); -\& void lh_TYPE_flush(LHASH_OF(TYPE) *table); -\& OPENSSL_LHASH *OPENSSL_LH_set_thunks(OPENSSL_LHASH *lh, -\& OPENSSL_LH_HASHFUNCTHUNK hw, -\& OPENSSL_LH_COMPFUNCTHUNK cw, -\& OPENSSL_LH_DOALL_FUNC_THUNK daw, -\& OPENSSL_LH_DOALL_FUNCARG_THUNK daaw) -\& -\& TYPE *lh_TYPE_insert(LHASH_OF(TYPE) *table, TYPE *data); -\& TYPE *lh_TYPE_delete(LHASH_OF(TYPE) *table, TYPE *data); -\& TYPE *lh_TYPE_retrieve(LHASH_OF(TYPE) *table, TYPE *data); -\& -\& void lh_TYPE_doall(LHASH_OF(TYPE) *table, OPENSSL_LH_DOALL_FUNC func); -\& void lh_TYPE_doall_arg(LHASH_OF(TYPE) *table, OPENSSL_LH_DOALL_FUNCARG func, -\& TYPE *arg); -\& void OPENSSL_LH_doall_arg_thunk(OPENSSL_LHASH *lh, -\& OPENSSL_LH_DOALL_FUNCARG_THUNK daaw, -\& OPENSSL_LH_DOALL_FUNCARG fn, void *arg) -\& -\& unsigned long lh_TYPE_num_items(OPENSSL_LHASH *lh); -\& unsigned long lh_TYPE_get_down_load(OPENSSL_LHASH *lh); -\& void lh_TYPE_set_down_load(OPENSSL_LHASH *lh, unsigned long dl); -\& -\& int lh_TYPE_error(LHASH_OF(TYPE) *table); -\& -\& typedef int (*OPENSSL_LH_COMPFUNC)(const void *, const void *); -\& typedef unsigned long (*OPENSSL_LH_HASHFUNC)(const void *); -\& typedef void (*OPENSSL_LH_DOALL_FUNC)(const void *); -\& typedef void (*LHASH_DOALL_ARG_FN_TYPE)(const void *, const void *); -\& -\& OPENSSL_LHASH *OPENSSL_LH_new(OPENSSL_LH_HASHFUNC h, OPENSSL_LH_COMPFUNC c); -\& void OPENSSL_LH_free(OPENSSL_LHASH *lh); -\& void OPENSSL_LH_flush(OPENSSL_LHASH *lh); -\& -\& void *OPENSSL_LH_insert(OPENSSL_LHASH *lh, void *data); -\& void *OPENSSL_LH_delete(OPENSSL_LHASH *lh, const void *data); -\& void *OPENSSL_LH_retrieve(OPENSSL_LHASH *lh, const void *data); -\& -\& void OPENSSL_LH_doall(OPENSSL_LHASH *lh, OPENSSL_LH_DOALL_FUNC func); -\& void OPENSSL_LH_doall_arg(OPENSSL_LHASH *lh, OPENSSL_LH_DOALL_FUNCARG func, void *arg); -\& -\& unsigned long OPENSSL_LH_num_items(OPENSSL_LHASH *lh); -\& unsigned long OPENSSL_LH_get_down_load(OPENSSL_LHASH *lh); -\& void OPENSSL_LH_set_down_load(OPENSSL_LHASH *lh, unsigned long dl); -\& -\& int OPENSSL_LH_error(OPENSSL_LHASH *lh); -\& -\& #define LH_LOAD_MULT /* integer constant */ -.Ve -.PP -The following macro is deprecated: -.PP -.Vb 1 -\& DEFINE_LHASH_OF(TYPE); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This library implements type-checked dynamic hash tables. The hash -table entries can be arbitrary structures. Usually they consist of key -and value fields. In the description here, \fB\f(BI\s-1TYPE\s0\fB\fR is used a placeholder -for any of the OpenSSL datatypes, such as \fI\s-1SSL_SESSION\s0\fR. -.PP -To define a new type-checked dynamic hash table, use \fB\s-1DEFINE_LHASH_OF_EX\s0\fR(). -\&\fB\s-1DEFINE_LHASH_OF\s0\fR() was previously used for this purpose, but is now -deprecated. The \fB\s-1DEFINE_LHASH_OF_EX\s0\fR() macro provides all functionality of -\&\fB\s-1DEFINE_LHASH_OF\s0\fR() except for certain deprecated statistics functions (see -\&\fBOPENSSL_LH_stats\fR\|(3)). -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_new\fR() creates a new \fB\s-1LHASH_OF\s0\fR(\fB\f(BI\s-1TYPE\s0\fB\fR) structure to store -arbitrary data entries, and specifies the 'hash' and 'compare' -callbacks to be used in organising the table's entries. The \fIhash\fR -callback takes a pointer to a table entry as its argument and returns -an unsigned long hash value for its key field. The hash value is -normally truncated to a power of 2, so make sure that your hash -function returns well mixed low order bits. The \fIcompare\fR callback -takes two arguments (pointers to two hash table entries), and returns -0 if their keys are equal, nonzero otherwise. -.PP -If your hash table -will contain items of some particular type and the \fIhash\fR and -\&\fIcompare\fR callbacks hash/compare these types, then the -\&\fB\s-1IMPLEMENT_LHASH_HASH_FN\s0\fR and \fB\s-1IMPLEMENT_LHASH_COMP_FN\s0\fR macros can be -used to create callback wrappers of the prototypes required by -\&\fBlh_\f(BI\s-1TYPE\s0\fB_new\fR() as shown in this example: -.PP -.Vb 11 -\& /* -\& * Implement the hash and compare functions; "stuff" can be any word. -\& */ -\& static unsigned long stuff_hash(const TYPE *a) -\& { -\& ... -\& } -\& static int stuff_cmp(const TYPE *a, const TYPE *b) -\& { -\& ... -\& } -\& -\& /* -\& * Implement the wrapper functions. -\& */ -\& static IMPLEMENT_LHASH_HASH_FN(stuff, TYPE) -\& static IMPLEMENT_LHASH_COMP_FN(stuff, TYPE) -.Ve -.PP -If the type is going to be used in several places, the following macros -can be used in a common header file to declare the function wrappers: -.PP -.Vb 2 -\& DECLARE_LHASH_HASH_FN(stuff, TYPE) -\& DECLARE_LHASH_COMP_FN(stuff, TYPE) -.Ve -.PP -Then a hash table of \fB\f(BI\s-1TYPE\s0\fB\fR objects can be created using this: -.PP -.Vb 1 -\& LHASH_OF(TYPE) *htable; -\& -\& htable = B_new>(LHASH_HASH_FN(stuff), LHASH_COMP_FN(stuff)); -.Ve -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_free\fR() frees the \fB\s-1LHASH_OF\s0\fR(\fB\f(BI\s-1TYPE\s0\fB\fR) structure -\&\fItable\fR. Allocated hash table entries will not be freed; consider -using \fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() to deallocate any remaining entries in the -hash table (see below). If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_flush\fR() empties the \fB\s-1LHASH_OF\s0\fR(\fB\f(BI\s-1TYPE\s0\fB\fR) structure \fItable\fR. New -entries can be added to the flushed table. Allocated hash table entries -will not be freed; consider using \fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() to deallocate any -remaining entries in the hash table (see below). -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_insert\fR() inserts the structure pointed to by \fIdata\fR into -\&\fItable\fR. If there already is an entry with the same key, the old -value is replaced. Note that \fBlh_\f(BI\s-1TYPE\s0\fB_insert\fR() stores pointers, the -data are not copied. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_delete\fR() deletes an entry from \fItable\fR. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_retrieve\fR() looks up an entry in \fItable\fR. Normally, \fIdata\fR -is a structure with the key field(s) set; the function will return a -pointer to a fully populated structure. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() will, for every entry in the hash table, call -\&\fIfunc\fR with the data item as its parameter. -For example: -.PP -.Vb 2 -\& /* Cleans up resources belonging to \*(Aqa\*(Aq (this is implemented elsewhere) */ -\& void TYPE_cleanup_doall(TYPE *a); -\& -\& /* Implement a prototype\-compatible wrapper for "TYPE_cleanup" */ -\& IMPLEMENT_LHASH_DOALL_FN(TYPE_cleanup, TYPE) -\& -\& /* Call "TYPE_cleanup" against all items in a hash table. */ -\& lh_TYPE_doall(hashtable, LHASH_DOALL_FN(TYPE_cleanup)); -\& -\& /* Then the hash table itself can be deallocated */ -\& lh_TYPE_free(hashtable); -.Ve -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_doall_arg\fR() is the same as \fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() except that -\&\fIfunc\fR will be called with \fIarg\fR as the second argument and \fIfunc\fR -should be of type \fB\s-1LHASH_DOALL_ARG_FN\s0\fR(\fB\f(BI\s-1TYPE\s0\fB\fR) (a callback prototype -that is passed both the table entry and an extra argument). As with -\&\fBlh_doall()\fR, you can instead choose to declare your callback with a -prototype matching the types you are dealing with and use the -declare/implement macros to create compatible wrappers that cast -variables before calling your type-specific callbacks. An example of -this is demonstrated here (printing all hash table entries to a \s-1BIO\s0 -that is provided by the caller): -.PP -.Vb 2 -\& /* Prints item \*(Aqa\*(Aq to \*(Aqoutput_bio\*(Aq (this is implemented elsewhere) */ -\& void TYPE_print_doall_arg(const TYPE *a, BIO *output_bio); -\& -\& /* Implement a prototype\-compatible wrapper for "TYPE_print" */ -\& static IMPLEMENT_LHASH_DOALL_ARG_FN(TYPE, const TYPE, BIO) -\& -\& /* Print out the entire hashtable to a particular BIO */ -\& lh_TYPE_doall_arg(hashtable, LHASH_DOALL_ARG_FN(TYPE_print), BIO, -\& logging_bio); -.Ve -.PP -Note that it is by default \fBnot\fR safe to use \fBlh_\f(BI\s-1TYPE\s0\fB_delete\fR() inside a -callback passed to \fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() or \fBlh_\f(BI\s-1TYPE\s0\fB_doall_arg\fR(). The -reason for this is that deleting an item from the hash table may result in the -hash table being contracted to a smaller size and rehashed. -\&\fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() and \fBlh_\f(BI\s-1TYPE\s0\fB_doall_arg\fR() are unsafe and will exhibit -undefined behaviour under these conditions, as these functions assume the hash -table size and bucket pointers do not change during the call. -.PP -If it is desired to use \fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() or \fBlh_\f(BI\s-1TYPE\s0\fB_doall_arg\fR() with -\&\fBlh_\f(BI\s-1TYPE\s0\fB_delete\fR(), it is essential that you call -\&\fBlh_\f(BI\s-1TYPE\s0\fB_set_down_load\fR() with a \fIdown_load\fR argument of 0 first. This -disables hash table contraction and guarantees that it will be safe to delete -items from a hash table during a call to \fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() or -\&\fBlh_\f(BI\s-1TYPE\s0\fB_doall_arg\fR(). -.PP -It is never safe to call \fBlh_\f(BI\s-1TYPE\s0\fB_insert\fR() during a call to -\&\fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() or \fBlh_\f(BI\s-1TYPE\s0\fB_doall_arg\fR(). -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_error\fR() can be used to determine if an error occurred in the last -operation. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_num_items\fR() returns the number of items in the hash table. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_get_down_load\fR() and \fBlh_\f(BI\s-1TYPE\s0\fB_set_down_load\fR() get and set the -factor used to determine when the hash table is contracted. The factor is the -load factor at or below which hash table contraction will occur, multiplied by -\&\fB\s-1LH_LOAD_MULT\s0\fR, where the load factor is the number of items divided by the -number of nodes. Setting this value to 0 disables hash table contraction. -.PP -\&\fBOPENSSL_LH_new()\fR is the same as the \fBlh_\f(BI\s-1TYPE\s0\fB_new\fR() except that it is not -type specific. So instead of returning an \fB\s-1LHASH_OF\s0(\f(BI\s-1TYPE\s0\fB)\fR value it returns -a \fBvoid *\fR. In the same way the functions \fBOPENSSL_LH_free()\fR, -\&\fBOPENSSL_LH_flush()\fR, \fBOPENSSL_LH_insert()\fR, \fBOPENSSL_LH_delete()\fR, -\&\fBOPENSSL_LH_retrieve()\fR, \fBOPENSSL_LH_doall()\fR, \fBOPENSSL_LH_doall_arg()\fR, -\&\fBOPENSSL_LH_num_items()\fR, \fBOPENSSL_LH_get_down_load()\fR, \fBOPENSSL_LH_set_down_load()\fR -and \fBOPENSSL_LH_error()\fR are equivalent to the similarly named \fBlh_\f(BI\s-1TYPE\s0\fB\fR -functions except that they return or use a \fBvoid *\fR where the equivalent -\&\fBlh_\f(BI\s-1TYPE\s0\fB\fR function returns or uses a \fB\f(BI\s-1TYPE\s0\fB *\fR or \fB\s-1LHASH_OF\s0(\f(BI\s-1TYPE\s0\fB) *\fR. -\&\fBlh_\f(BI\s-1TYPE\s0\fB\fR functions are implemented as type checked wrappers around the -\&\fB\s-1OPENSSL_LH\s0\fR functions. Most applications should not call the \fB\s-1OPENSSL_LH\s0\fR -functions directly. -.PP -\&\fBOPENSSL_LH_set_thunks()\fR and \fBOPENSSL_LH_doall_arg_thunk()\fR, while public by -necessity, are actually internal functions and should not be used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBlh_\f(BI\s-1TYPE\s0\fB_new\fR() and \fBOPENSSL_LH_new()\fR return \s-1NULL\s0 on error, otherwise a -pointer to the new \fB\s-1LHASH\s0\fR structure. -.PP -When a hash table entry is replaced, \fBlh_\f(BI\s-1TYPE\s0\fB_insert\fR() or -\&\fBOPENSSL_LH_insert()\fR return the value being replaced. \s-1NULL\s0 is returned on normal -operation and on error. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_delete\fR() and \fBOPENSSL_LH_delete()\fR return the entry being deleted. -\&\s-1NULL\s0 is returned if there is no such value in the hash table. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_retrieve\fR() and \fBOPENSSL_LH_retrieve()\fR return the hash table entry -if it has been found, \s-1NULL\s0 otherwise. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_error\fR() and \fBOPENSSL_LH_error()\fR return 1 if an error occurred in -the last operation, 0 otherwise. It's meaningful only after non-retrieve -operations. -.PP -\&\fBlh_\f(BI\s-1TYPE\s0\fB_free\fR(), \fBOPENSSL_LH_free()\fR, \fBlh_\f(BI\s-1TYPE\s0\fB_flush\fR(), -\&\fBOPENSSL_LH_flush()\fR, \fBlh_\f(BI\s-1TYPE\s0\fB_doall\fR() \fBOPENSSL_LH_doall()\fR, -\&\fBlh_\f(BI\s-1TYPE\s0\fB_doall_arg\fR() and \fBOPENSSL_LH_doall_arg()\fR return no values. -.SH "NOTE" -.IX Header "NOTE" -The \s-1LHASH\s0 code is not thread safe. All updating operations, as well as -\&\fBlh_\f(BI\s-1TYPE\s0\fB_error\fR() or \fBOPENSSL_LH_error()\fR calls must be performed under -a write lock. All retrieve operations should be performed under a read lock, -\&\fIunless\fR accurate usage statistics are desired. In which case, a write lock -should be used for retrieve operations as well. For output of the usage -statistics, using the functions from \fBOPENSSL_LH_stats\fR\|(3), a read lock -suffices. -.PP -The \s-1LHASH\s0 code regards table entries as constant data. As such, it -internally represents \fBlh_insert()\fR'd items with a \*(L"const void *\*(R" -pointer type. This is why callbacks such as those used by \fBlh_doall()\fR -and \fBlh_doall_arg()\fR declare their prototypes with \*(L"const\*(R", even for the -parameters that pass back the table items' data pointers \- for -consistency, user-provided data is \*(L"const\*(R" at all times as far as the -\&\s-1LHASH\s0 code is concerned. However, as callers are themselves providing -these pointers, they can choose whether they too should be treating -all such parameters as constant. -.PP -As an example, a hash table may be maintained by code that, for -reasons of encapsulation, has only \*(L"const\*(R" access to the data being -indexed in the hash table (i.e. it is returned as \*(L"const\*(R" from -elsewhere in their code) \- in this case the \s-1LHASH\s0 prototypes are -appropriate as-is. Conversely, if the caller is responsible for the -life-time of the data in question, then they may well wish to make -modifications to table item passed back in the \fBlh_doall()\fR or -\&\fBlh_doall_arg()\fR callbacks (see the \*(L"TYPE_cleanup\*(R" example above). If -so, the caller can either cast the \*(L"const\*(R" away (if they're providing -the raw callbacks themselves) or use the macros to declare/implement -the wrapper functions without \*(L"const\*(R" types. -.PP -Callers that only have \*(L"const\*(R" access to data they're indexing in a -table, yet declare callbacks without constant types (or cast the -\&\*(L"const\*(R" away themselves), are therefore creating their own risks/bugs -without being encouraged to do so by the \s-1API.\s0 On a related note, -those auditing code should pay special attention to any instances of -DECLARE/IMPLEMENT_LHASH_DOALL_[\s-1ARG_\s0]_FN macros that provide types -without any \*(L"const\*(R" qualifiers. -.SH "BUGS" -.IX Header "BUGS" -\&\fBlh_\f(BI\s-1TYPE\s0\fB_insert\fR() and \fBOPENSSL_LH_insert()\fR return \s-1NULL\s0 both for success -and error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOPENSSL_LH_stats\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -In OpenSSL 1.0.0, the lhash interface was revamped for better -type checking. -.PP -In OpenSSL 3.1, \fB\s-1DEFINE_LHASH_OF_EX\s0\fR() was introduced and \fB\s-1DEFINE_LHASH_OF\s0\fR() -was deprecated. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_LH_DOALL_FUNC.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_DOALL_FUNC.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_DOALL_FUNC.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_HASHFUNC.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_HASHFUNC.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_HASHFUNC.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_delete.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_delete.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_delete.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_doall.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_doall.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_doall.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_doall_arg.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_doall_arg.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_doall_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_doall_arg_thunk.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_doall_arg_thunk.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_doall_arg_thunk.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_error.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_error.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_flush.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_flush.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_flush.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_free.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_free.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_get_down_load.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_get_down_load.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_get_down_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_insert.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_insert.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_insert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_new.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_new.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_node_stats.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_node_stats.3ossl deleted file mode 120000 index bda15ed4..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_node_stats.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_stats.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_node_stats_bio.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_node_stats_bio.3ossl deleted file mode 120000 index bda15ed4..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_node_stats_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_stats.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats.3ossl deleted file mode 120000 index bda15ed4..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_stats.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats_bio.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats_bio.3ossl deleted file mode 120000 index bda15ed4..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_node_usage_stats_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_stats.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_num_items.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_num_items.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_num_items.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_retrieve.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_retrieve.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_retrieve.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_set_down_load.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_set_down_load.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_set_down_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_set_thunks.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_set_thunks.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_set_thunks.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LH_stats.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_stats.3ossl deleted file mode 100644 index 5f478b00..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_stats.3ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_LH_STATS 3ossl" -.TH OPENSSL_LH_STATS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_LH_stats, OPENSSL_LH_node_stats, OPENSSL_LH_node_usage_stats, -OPENSSL_LH_stats_bio, -OPENSSL_LH_node_stats_bio, OPENSSL_LH_node_usage_stats_bio \- LHASH statistics -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.1, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& void OPENSSL_LH_node_stats(LHASH *table, FILE *out); -\& void OPENSSL_LH_node_usage_stats(LHASH *table, FILE *out); -\& -\& void OPENSSL_LH_node_stats_bio(LHASH *table, BIO *out); -\& void OPENSSL_LH_node_usage_stats_bio(LHASH *table, BIO *out); -\& -\& void OPENSSL_LH_stats(LHASH *table, FILE *out); -\& void OPENSSL_LH_stats_bio(LHASH *table, BIO *out); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1LHASH\s0\fR structure records statistics about most aspects of -accessing the hash table. -.PP -\&\fBOPENSSL_LH_stats()\fR prints out statistics on the size of the hash table and how -many entries are in it. For historical reasons, this function also outputs a -number of additional statistics, but the tracking of these statistics is no -longer supported and these statistics are always reported as zero. -.PP -\&\fBOPENSSL_LH_node_stats()\fR prints the number of entries for each 'bucket' in the -hash table. -.PP -\&\fBOPENSSL_LH_node_usage_stats()\fR prints out a short summary of the state of the -hash table. It prints the 'load' and the 'actual load'. The load is -the average number of data items per 'bucket' in the hash table. The -\&'actual load' is the average number of items per 'bucket', but only -for buckets which contain entries. So the 'actual load' is the -average number of searches that will need to find an item in the hash -table, while the 'load' is the average number that will be done to -record a miss. -.PP -\&\fBOPENSSL_LH_stats_bio()\fR, \fBOPENSSL_LH_node_stats_bio()\fR and \fBOPENSSL_LH_node_usage_stats_bio()\fR -are the same as the above, except that the output goes to a \fB\s-1BIO\s0\fR. -.PP -These functions are deprecated and should no longer be used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions do not return values. -.SH "NOTE" -.IX Header "NOTE" -These calls should be made under a read lock. Refer to -\&\*(L"\s-1NOTE\*(R"\s0 in \s-1\fBOPENSSL_LH_COMPFUNC\s0\fR\|(3) for more details about the locks required -when using the \s-1LHASH\s0 data structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBbio\fR\|(7), \s-1\fBOPENSSL_LH_COMPFUNC\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were deprecated in version 3.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_LH_stats_bio.3ossl b/openssl-install/share/man/man3/OPENSSL_LH_stats_bio.3ossl deleted file mode 120000 index bda15ed4..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LH_stats_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_stats.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_LINE.3ossl b/openssl-install/share/man/man3/OPENSSL_LINE.3ossl deleted file mode 120000 index 4cf5726f..00000000 --- a/openssl-install/share/man/man3/OPENSSL_LINE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_FILE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_MALLOC_FAILURES.3ossl b/openssl-install/share/man/man3/OPENSSL_MALLOC_FAILURES.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_MALLOC_FAILURES.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_MALLOC_FD.3ossl b/openssl-install/share/man/man3/OPENSSL_MALLOC_FD.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_MALLOC_FD.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_MSTR.3ossl b/openssl-install/share/man/man3/OPENSSL_MSTR.3ossl deleted file mode 120000 index 4cf5726f..00000000 --- a/openssl-install/share/man/man3/OPENSSL_MSTR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_FILE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_MSTR_HELPER.3ossl b/openssl-install/share/man/man3/OPENSSL_MSTR_HELPER.3ossl deleted file mode 120000 index 4cf5726f..00000000 --- a/openssl-install/share/man/man3/OPENSSL_MSTR_HELPER.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_FILE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_BUILD_METADATA.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_BUILD_METADATA.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_BUILD_METADATA.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_MAJOR.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_MAJOR.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_MAJOR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_MINOR.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_MINOR.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_MINOR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_NUMBER.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_NUMBER.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_NUMBER.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_PATCH.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_PATCH.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_PATCH.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_PREREQ.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_PREREQ.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_PREREQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_PRE_RELEASE.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_PRE_RELEASE.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_PRE_RELEASE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_VERSION_TEXT.3ossl b/openssl-install/share/man/man3/OPENSSL_VERSION_TEXT.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_VERSION_TEXT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_aligned_alloc.3ossl b/openssl-install/share/man/man3/OPENSSL_aligned_alloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_aligned_alloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_atexit.3ossl b/openssl-install/share/man/man3/OPENSSL_atexit.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_atexit.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_buf2hexstr.3ossl b/openssl-install/share/man/man3/OPENSSL_buf2hexstr.3ossl deleted file mode 120000 index 3007f330..00000000 --- a/openssl-install/share/man/man3/OPENSSL_buf2hexstr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_hexchar2int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_buf2hexstr_ex.3ossl b/openssl-install/share/man/man3/OPENSSL_buf2hexstr_ex.3ossl deleted file mode 120000 index 3007f330..00000000 --- a/openssl-install/share/man/man3/OPENSSL_buf2hexstr_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_hexchar2int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_cipher_name.3ossl b/openssl-install/share/man/man3/OPENSSL_cipher_name.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/OPENSSL_cipher_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_cleanse.3ossl b/openssl-install/share/man/man3/OPENSSL_cleanse.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_cleanse.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_cleanup.3ossl b/openssl-install/share/man/man3/OPENSSL_cleanup.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_clear_free.3ossl b/openssl-install/share/man/man3/OPENSSL_clear_free.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_clear_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_clear_realloc.3ossl b/openssl-install/share/man/man3/OPENSSL_clear_realloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_clear_realloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_config.3ossl b/openssl-install/share/man/man3/OPENSSL_config.3ossl deleted file mode 100644 index f017e0b1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_config.3ossl +++ /dev/null @@ -1,214 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_CONFIG 3ossl" -.TH OPENSSL_CONFIG 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_config, OPENSSL_no_config \- simple OpenSSL configuration functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& void OPENSSL_config(const char *appname); -\& void OPENSSL_no_config(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOPENSSL_config()\fR configures OpenSSL using the standard \fBopenssl.cnf\fR and -reads from the application section \fBappname\fR. If \fBappname\fR is \s-1NULL\s0 then -the default section, \fBopenssl_conf\fR, will be used. -Errors are silently ignored. -Multiple calls have no effect. -.PP -\&\fBOPENSSL_no_config()\fR disables configuration. If called before \fBOPENSSL_config()\fR -no configuration takes place. -.PP -If the application is built with \fB\s-1OPENSSL_LOAD_CONF\s0\fR defined, then a -call to \fBOpenSSL_add_all_algorithms()\fR will implicitly call \fBOPENSSL_config()\fR -first. -.SH "NOTES" -.IX Header "NOTES" -The \fBOPENSSL_config()\fR function is designed to be a very simple \*(L"call it and -forget it\*(R" function. -It is however \fBmuch\fR better than nothing. Applications which need finer -control over their configuration functionality should use the configuration -functions such as \fBCONF_modules_load()\fR directly. This function is deprecated -and its use should be avoided. -Applications should instead call \fBCONF_modules_load()\fR during -initialization (that is before starting any threads). -.PP -There are several reasons why calling the OpenSSL configuration routines is -advisable. For example, to load dynamic ENGINEs from shared libraries (DSOs). -However, very few applications currently support the control interface and so -very few can load and use dynamic ENGINEs. Equally in future more sophisticated -ENGINEs will require certain control operations to customize them. If an -application calls \fBOPENSSL_config()\fR it doesn't need to know or care about -\&\s-1ENGINE\s0 control operations because they can be performed by editing a -configuration file. -.SH "ENVIRONMENT" -.IX Header "ENVIRONMENT" -.IP "\fB\s-1OPENSSL_CONF\s0\fR" 4 -.IX Item "OPENSSL_CONF" -The path to the config file. -Ignored in set-user-ID and set-group-ID programs. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Neither \fBOPENSSL_config()\fR nor \fBOPENSSL_no_config()\fR return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBconfig\fR\|(5), -\&\fBCONF_modules_load_file\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBOPENSSL_no_config()\fR and \fBOPENSSL_config()\fR functions were -deprecated in OpenSSL 1.1.0 by \fBOPENSSL_init_crypto()\fR. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_fork_child.3ossl b/openssl-install/share/man/man3/OPENSSL_fork_child.3ossl deleted file mode 120000 index 806c9662..00000000 --- a/openssl-install/share/man/man3/OPENSSL_fork_child.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_fork_prepare.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_fork_parent.3ossl b/openssl-install/share/man/man3/OPENSSL_fork_parent.3ossl deleted file mode 120000 index 806c9662..00000000 --- a/openssl-install/share/man/man3/OPENSSL_fork_parent.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_fork_prepare.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_fork_prepare.3ossl b/openssl-install/share/man/man3/OPENSSL_fork_prepare.3ossl deleted file mode 100644 index fdd4bb5c..00000000 --- a/openssl-install/share/man/man3/OPENSSL_fork_prepare.3ossl +++ /dev/null @@ -1,203 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_FORK_PREPARE 3ossl" -.TH OPENSSL_FORK_PREPARE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_fork_prepare, -OPENSSL_fork_parent, -OPENSSL_fork_child -\&\- OpenSSL fork handlers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& void OPENSSL_fork_prepare(void); -\& void OPENSSL_fork_parent(void); -\& void OPENSSL_fork_child(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These methods are currently unused, and as such, no replacement methods are -required or planned. -.PP -OpenSSL has state that should be reset when a process forks. For example, -the entropy pool used to generate random numbers (and therefore encryption -keys) should not be shared across multiple programs. -The \fBOPENSSL_fork_prepare()\fR, \fBOPENSSL_fork_parent()\fR, and \fBOPENSSL_fork_child()\fR -functions are used to reset this internal state. -.PP -Platforms without \fBfork\fR\|(2) will probably not need to use these functions. -Platforms with \fBfork\fR\|(2) but without \fBpthread_atfork\fR\|(3) will probably need -to call them manually, as described in the following paragraph. Platforms -such as Linux that have both functions will normally not need to call these -functions as the OpenSSL library will do so automatically. -.PP -\&\fBOPENSSL_init_crypto\fR\|(3) will register these functions with the appropriate -handler, when the \fB\s-1OPENSSL_INIT_ATFORK\s0\fR flag is used. For other -applications, these functions can be called directly. They should be used -according to the calling sequence described by the \fBpthread_atfork\fR\|(3) -documentation, which is summarized here. \fBOPENSSL_fork_prepare()\fR should -be called before a \fBfork()\fR is done. After the \fBfork()\fR returns, the parent -process should call \fBOPENSSL_fork_parent()\fR and the child process should -call \fBOPENSSL_fork_child()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOPENSSL_fork_prepare()\fR, \fBOPENSSL_fork_parent()\fR and \fBOPENSSL_fork_child()\fR do not -return values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOPENSSL_init_crypto\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_free.3ossl b/openssl-install/share/man/man3/OPENSSL_free.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_gmtime.3ossl b/openssl-install/share/man/man3/OPENSSL_gmtime.3ossl deleted file mode 100644 index abbdc99b..00000000 --- a/openssl-install/share/man/man3/OPENSSL_gmtime.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_GMTIME 3ossl" -.TH OPENSSL_GMTIME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_gmtime, -OPENSSL_gmtime_adj, -OPENSSL_gmtime_diff \- platform\-agnostic OpenSSL time routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& struct tm *OPENSSL_gmtime(const time_t *timer, struct tm *result); -\& int OPENSSL_gmtime_adj(struct tm *tm, int offset_day, long offset_sec); -\& int OPENSSL_gmtime_diff(int *pday, int *psec, -\& const struct tm *from, const struct tm *to); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOPENSSL_gmtime()\fR returns the \s-1UTC\s0 time specified by \fItimer\fR into the provided -\&\fIresult\fR argument. -.PP -\&\fBOPENSSL_gmtime_adj()\fR adds the offsets in \fIoffset_day\fR and \fIoffset_sec\fR to \fItm\fR. -.PP -\&\fBOPENSSL_gmtime_diff()\fR calculates the difference between \fIfrom\fR and \fIto\fR. -.SH "NOTES" -.IX Header "NOTES" -It is an error to call \fBOPENSSL_gmtime()\fR with \fIresult\fR equal to \s-1NULL.\s0 The -contents of the time_t given by \fItimer\fR are stored into the \fIresult\fR. Calling -with \fItimer\fR equal to \s-1NULL\s0 means use the current time. -.PP -\&\fBOPENSSL_gmtime_adj()\fR converts \fItm\fR into a days and seconds value, adds the -offsets, then converts back into a \fIstruct tm\fR specified by \fItm\fR. Leap seconds -are not considered. -.PP -\&\fBOPENSSL_gmtime_diff()\fR calculates the difference between the two \fIstruct tm\fR -structures \fIfrom\fR and \fIto\fR. The difference in days is placed into \fI*pday\fR, -the remaining seconds are placed to \fI*psec\fR. The value in \fI*psec\fR will be less -than the number of seconds per day (3600). Leap seconds are not considered. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOPENSSL_gmtime()\fR returns \s-1NULL\s0 on error, or \fIresult\fR on success. -.PP -\&\fBOPENSSL_gmtime_adj()\fR and \fBOPENSSL_gmtime_diff()\fR return 0 on error, and 1 on success. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOPENSSL_gmtime()\fR, \fBOPENSSL_gmtime_adj()\fR and \fBOPENSSL_gmtime_diff()\fR have been -in OpenSSL since 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_gmtime_adj.3ossl b/openssl-install/share/man/man3/OPENSSL_gmtime_adj.3ossl deleted file mode 120000 index dd2193e0..00000000 --- a/openssl-install/share/man/man3/OPENSSL_gmtime_adj.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_gmtime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_gmtime_diff.3ossl b/openssl-install/share/man/man3/OPENSSL_gmtime_diff.3ossl deleted file mode 120000 index dd2193e0..00000000 --- a/openssl-install/share/man/man3/OPENSSL_gmtime_diff.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_gmtime.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_hexchar2int.3ossl b/openssl-install/share/man/man3/OPENSSL_hexchar2int.3ossl deleted file mode 100644 index 0ca00003..00000000 --- a/openssl-install/share/man/man3/OPENSSL_hexchar2int.3ossl +++ /dev/null @@ -1,214 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_HEXCHAR2INT 3ossl" -.TH OPENSSL_HEXCHAR2INT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_hexchar2int, -OPENSSL_hexstr2buf_ex, OPENSSL_hexstr2buf, -OPENSSL_buf2hexstr_ex, OPENSSL_buf2hexstr -\&\- Hex encoding and decoding functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OPENSSL_hexchar2int(unsigned char c); -\& int OPENSSL_hexstr2buf_ex(unsigned char *buf, size_t buf_n, long *buflen, -\& const char *str, const char sep); -\& unsigned char *OPENSSL_hexstr2buf(const char *str, long *len); -\& int OPENSSL_buf2hexstr_ex(char *str, size_t str_n, size_t *strlength, -\& const unsigned char *buf, long buflen, -\& const char sep); -\& char *OPENSSL_buf2hexstr(const unsigned char *buf, long buflen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOPENSSL_hexchar2int()\fR converts a hexadecimal character to its numeric -equivalent. -.PP -\&\fBOPENSSL_hexstr2buf_ex()\fR decodes the hex string \fBstr\fR and places the -resulting string of bytes in the given \fIbuf\fR. -The character \fIsep\fR is the separator between the bytes, setting this to '\e0' -means that there is no separator. -\&\fIbuf_n\fR gives the size of the buffer. -If \fIbuflen\fR is not \s-1NULL,\s0 it is filled in with the result length. -To find out how large the result will be, call this function with \s-1NULL\s0 -for \fIbuf\fR. -Colons between two-character hex \*(L"bytes\*(R" are accepted and ignored. -An odd number of hex digits is an error. -.PP -\&\fBOPENSSL_hexstr2buf()\fR does the same thing as \fBOPENSSL_hexstr2buf_ex()\fR, -but allocates the space for the result, and returns the result. It uses a -default separator of ':'. -The memory is allocated by calling \fBOPENSSL_malloc()\fR and should be -released by calling \fBOPENSSL_free()\fR. -.PP -\&\fBOPENSSL_buf2hexstr_ex()\fR encodes the contents of the given \fIbuf\fR with -length \fIbuflen\fR and places the resulting hexadecimal character string -in the given \fIstr\fR. -The character \fIsep\fR is the separator between the bytes, setting this to '\e0' -means that there is no separator. -\&\fIstr_n\fR gives the size of the of the string buffer. -If \fIstrlength\fR is not \s-1NULL,\s0 it is filled in with the result length. -To find out how large the result will be, call this function with \s-1NULL\s0 -for \fIstr\fR. -.PP -\&\fBOPENSSL_buf2hexstr()\fR does the same thing as \fBOPENSSL_buf2hexstr_ex()\fR, -but allocates the space for the result, and returns the result. It uses a -default separator of ':'. -The memory is allocated by calling \fBOPENSSL_malloc()\fR and should be -released by calling \fBOPENSSL_free()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -OPENSSL_hexchar2int returns the value of a decoded hex character, -or \-1 on error. -.PP -\&\fBOPENSSL_buf2hexstr()\fR and \fBOPENSSL_hexstr2buf()\fR -return a pointer to allocated memory, or \s-1NULL\s0 on error. -.PP -\&\fBOPENSSL_buf2hexstr_ex()\fR and \fBOPENSSL_hexstr2buf_ex()\fR return 1 on -success, or 0 on error. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_hexstr2buf.3ossl b/openssl-install/share/man/man3/OPENSSL_hexstr2buf.3ossl deleted file mode 120000 index 3007f330..00000000 --- a/openssl-install/share/man/man3/OPENSSL_hexstr2buf.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_hexchar2int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_hexstr2buf_ex.3ossl b/openssl-install/share/man/man3/OPENSSL_hexstr2buf_ex.3ossl deleted file mode 120000 index 3007f330..00000000 --- a/openssl-install/share/man/man3/OPENSSL_hexstr2buf_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_hexchar2int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_ia32cap.3ossl b/openssl-install/share/man/man3/OPENSSL_ia32cap.3ossl deleted file mode 100644 index eb0b0bc9..00000000 --- a/openssl-install/share/man/man3/OPENSSL_ia32cap.3ossl +++ /dev/null @@ -1,264 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_IA32CAP 3ossl" -.TH OPENSSL_IA32CAP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_ia32cap \- the x86[_64] processor capabilities vector -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& env OPENSSL_ia32cap=... -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL supports a range of x86[_64] instruction set extensions. These -extensions are denoted by individual bits in capability vector returned -by processor in \s-1EDX:ECX\s0 register pair after executing \s-1CPUID\s0 instruction -with EAX=1 input value (see Intel Application Note #241618). This vector -is copied to memory upon toolkit initialization and used to choose -between different code paths to provide optimal performance across wide -range of processors. For the moment of this writing following bits are -significant: -.IP "bit #4 denoting presence of Time-Stamp Counter." 4 -.IX Item "bit #4 denoting presence of Time-Stamp Counter." -.PD 0 -.IP "bit #19 denoting availability of \s-1CLFLUSH\s0 instruction;" 4 -.IX Item "bit #19 denoting availability of CLFLUSH instruction;" -.IP "bit #20, reserved by Intel, is used to choose among \s-1RC4\s0 code paths;" 4 -.IX Item "bit #20, reserved by Intel, is used to choose among RC4 code paths;" -.IP "bit #23 denoting \s-1MMX\s0 support;" 4 -.IX Item "bit #23 denoting MMX support;" -.IP "bit #24, \s-1FXSR\s0 bit, denoting availability of \s-1XMM\s0 registers;" 4 -.IX Item "bit #24, FXSR bit, denoting availability of XMM registers;" -.IP "bit #25 denoting \s-1SSE\s0 support;" 4 -.IX Item "bit #25 denoting SSE support;" -.IP "bit #26 denoting \s-1SSE2\s0 support;" 4 -.IX Item "bit #26 denoting SSE2 support;" -.IP "bit #28 denoting Hyperthreading, which is used to distinguish cores with shared cache;" 4 -.IX Item "bit #28 denoting Hyperthreading, which is used to distinguish cores with shared cache;" -.IP "bit #30, reserved by Intel, denotes specifically Intel CPUs;" 4 -.IX Item "bit #30, reserved by Intel, denotes specifically Intel CPUs;" -.IP "bit #33 denoting availability of \s-1PCLMULQDQ\s0 instruction;" 4 -.IX Item "bit #33 denoting availability of PCLMULQDQ instruction;" -.IP "bit #41 denoting \s-1SSSE3,\s0 Supplemental \s-1SSE3,\s0 support;" 4 -.IX Item "bit #41 denoting SSSE3, Supplemental SSE3, support;" -.IP "bit #43 denoting \s-1AMD XOP\s0 support (forced to zero on non-AMD CPUs);" 4 -.IX Item "bit #43 denoting AMD XOP support (forced to zero on non-AMD CPUs);" -.IP "bit #54 denoting availability of \s-1MOVBE\s0 instruction;" 4 -.IX Item "bit #54 denoting availability of MOVBE instruction;" -.IP "bit #57 denoting AES-NI instruction set extension;" 4 -.IX Item "bit #57 denoting AES-NI instruction set extension;" -.IP "bit #58, \s-1XSAVE\s0 bit, lack of which in combination with \s-1MOVBE\s0 is used to identify Atom Silvermont core;" 4 -.IX Item "bit #58, XSAVE bit, lack of which in combination with MOVBE is used to identify Atom Silvermont core;" -.IP "bit #59, \s-1OSXSAVE\s0 bit, denoting availability of \s-1YMM\s0 registers;" 4 -.IX Item "bit #59, OSXSAVE bit, denoting availability of YMM registers;" -.IP "bit #60 denoting \s-1AVX\s0 extension;" 4 -.IX Item "bit #60 denoting AVX extension;" -.IP "bit #62 denoting availability of \s-1RDRAND\s0 instruction;" 4 -.IX Item "bit #62 denoting availability of RDRAND instruction;" -.PD -.PP -For example, in 32\-bit application context clearing bit #26 at run-time -disables high-performance \s-1SSE2\s0 code present in the crypto library, while -clearing bit #24 disables \s-1SSE2\s0 code operating on 128\-bit \s-1XMM\s0 register -bank. You might have to do the latter if target OpenSSL application is -executed on \s-1SSE2\s0 capable \s-1CPU,\s0 but under control of \s-1OS\s0 that does not -enable \s-1XMM\s0 registers. Historically address of the capability vector copy -was exposed to application through \fBOPENSSL_ia32cap_loc()\fR, but not -anymore. Now the only way to affect the capability detection is to set -\&\fBOPENSSL_ia32cap\fR environment variable prior target application start. To -give a specific example, on Intel P4 processor -\&\f(CW\*(C`env OPENSSL_ia32cap=0x16980010 apps/openssl\*(C'\fR, or better yet -\&\f(CW\*(C`env OPENSSL_ia32cap=~0x1000000 apps/openssl\*(C'\fR would achieve the desired -effect. Alternatively you can reconfigure the toolkit with no\-sse2 -option and recompile. -.PP -Less intuitive is clearing bit #28, or ~0x10000000 in the \*(L"environment -variable\*(R" terms. The truth is that it's not copied from \s-1CPUID\s0 output -verbatim, but is adjusted to reflect whether or not the data cache is -actually shared between logical cores. This in turn affects the decision -on whether or not expensive countermeasures against cache-timing attacks -are applied, most notably in \s-1AES\s0 assembler module. -.PP -The capability vector is further extended with \s-1EBX\s0 value returned by -\&\s-1CPUID\s0 with EAX=7 and ECX=0 as input. Following bits are significant: -.IP "bit #64+3 denoting availability of \s-1BMI1\s0 instructions, e.g. \s-1ANDN\s0;" 4 -.IX Item "bit #64+3 denoting availability of BMI1 instructions, e.g. ANDN;" -.PD 0 -.IP "bit #64+5 denoting availability of \s-1AVX2\s0 instructions;" 4 -.IX Item "bit #64+5 denoting availability of AVX2 instructions;" -.IP "bit #64+8 denoting availability of \s-1BMI2\s0 instructions, e.g. \s-1MULX\s0 and \s-1RORX\s0;" 4 -.IX Item "bit #64+8 denoting availability of BMI2 instructions, e.g. MULX and RORX;" -.IP "bit #64+16 denoting availability of \s-1AVX512F\s0 extension;" 4 -.IX Item "bit #64+16 denoting availability of AVX512F extension;" -.IP "bit #64+17 denoting availability of \s-1AVX512DQ\s0 extension;" 4 -.IX Item "bit #64+17 denoting availability of AVX512DQ extension;" -.IP "bit #64+18 denoting availability of \s-1RDSEED\s0 instruction;" 4 -.IX Item "bit #64+18 denoting availability of RDSEED instruction;" -.IP "bit #64+19 denoting availability of \s-1ADCX\s0 and \s-1ADOX\s0 instructions;" 4 -.IX Item "bit #64+19 denoting availability of ADCX and ADOX instructions;" -.IP "bit #64+21 denoting availability of VPMADD52[\s-1LH\s0]UQ instructions, aka \s-1AVX512IFMA\s0 extension;" 4 -.IX Item "bit #64+21 denoting availability of VPMADD52[LH]UQ instructions, aka AVX512IFMA extension;" -.IP "bit #64+29 denoting availability of \s-1SHA\s0 extension;" 4 -.IX Item "bit #64+29 denoting availability of SHA extension;" -.IP "bit #64+30 denoting availability of \s-1AVX512BW\s0 extension;" 4 -.IX Item "bit #64+30 denoting availability of AVX512BW extension;" -.IP "bit #64+31 denoting availability of \s-1AVX512VL\s0 extension;" 4 -.IX Item "bit #64+31 denoting availability of AVX512VL extension;" -.IP "bit #64+41 denoting availability of \s-1VAES\s0 extension;" 4 -.IX Item "bit #64+41 denoting availability of VAES extension;" -.IP "bit #64+42 denoting availability of \s-1VPCLMULQDQ\s0 extension;" 4 -.IX Item "bit #64+42 denoting availability of VPCLMULQDQ extension;" -.PD -.PP -To control this extended capability word use \f(CW\*(C`:\*(C'\fR as delimiter when -setting up \fBOPENSSL_ia32cap\fR environment variable. For example assigning -\&\f(CW\*(C`:~0x20\*(C'\fR would disable \s-1AVX2\s0 code paths, and \f(CW\*(C`:0\*(C'\fR \- all post-AVX -extensions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Not available. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_info.3ossl b/openssl-install/share/man/man3/OPENSSL_info.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_info.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_init_crypto.3ossl b/openssl-install/share/man/man3/OPENSSL_init_crypto.3ossl deleted file mode 100644 index 3abb1a94..00000000 --- a/openssl-install/share/man/man3/OPENSSL_init_crypto.3ossl +++ /dev/null @@ -1,409 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_INIT_CRYPTO 3ossl" -.TH OPENSSL_INIT_CRYPTO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_INIT_new, OPENSSL_INIT_set_config_filename, -OPENSSL_INIT_set_config_appname, OPENSSL_INIT_set_config_file_flags, -OPENSSL_INIT_free, OPENSSL_init_crypto, OPENSSL_cleanup, OPENSSL_atexit, -OPENSSL_thread_stop_ex, OPENSSL_thread_stop \- OpenSSL initialisation -and deinitialisation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void OPENSSL_cleanup(void); -\& int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings); -\& int OPENSSL_atexit(void (*handler)(void)); -\& void OPENSSL_thread_stop_ex(OSSL_LIB_CTX *ctx); -\& void OPENSSL_thread_stop(void); -\& -\& OPENSSL_INIT_SETTINGS *OPENSSL_INIT_new(void); -\& int OPENSSL_INIT_set_config_filename(OPENSSL_INIT_SETTINGS *init, -\& const char* filename); -\& int OPENSSL_INIT_set_config_file_flags(OPENSSL_INIT_SETTINGS *init, -\& unsigned long flags); -\& int OPENSSL_INIT_set_config_appname(OPENSSL_INIT_SETTINGS *init, -\& const char* name); -\& void OPENSSL_INIT_free(OPENSSL_INIT_SETTINGS *init); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -During normal operation OpenSSL (libcrypto) will allocate various resources at -start up that must, subsequently, be freed on close down of the library. -Additionally some resources are allocated on a per thread basis (if the -application is multi-threaded), and these resources must be freed prior to the -thread closing. -.PP -As of version 1.1.0 OpenSSL will automatically allocate all resources that it -needs so no explicit initialisation is required. Similarly it will also -automatically deinitialise as required. -.PP -However, there may be situations when explicit initialisation is desirable or -needed, for example when some nondefault initialisation is required. The -function \fBOPENSSL_init_crypto()\fR can be used for this purpose for -libcrypto (see also \fBOPENSSL_init_ssl\fR\|(3) for the libssl -equivalent). -.PP -Numerous internal OpenSSL functions call \fBOPENSSL_init_crypto()\fR. -Therefore, in order to perform nondefault initialisation, -\&\fBOPENSSL_init_crypto()\fR \s-1MUST\s0 be called by application code prior to -any other OpenSSL function calls. -.PP -The \fBopts\fR parameter specifies which aspects of libcrypto should be -initialised. Valid options are: -.IP "\s-1OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS\s0" 4 -.IX Item "OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS" -Suppress automatic loading of the libcrypto error strings. This option is -not a default option. Once selected subsequent calls to -\&\fBOPENSSL_init_crypto()\fR with the option -\&\fB\s-1OPENSSL_INIT_LOAD_CRYPTO_STRINGS\s0\fR will be ignored. -.IP "\s-1OPENSSL_INIT_LOAD_CRYPTO_STRINGS\s0" 4 -.IX Item "OPENSSL_INIT_LOAD_CRYPTO_STRINGS" -Automatic loading of the libcrypto error strings. With this option the -library will automatically load the libcrypto error strings. -This option is a default option. Once selected subsequent calls to -\&\fBOPENSSL_init_crypto()\fR with the option -\&\fB\s-1OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS\s0\fR will be ignored. -.IP "\s-1OPENSSL_INIT_ADD_ALL_CIPHERS\s0" 4 -.IX Item "OPENSSL_INIT_ADD_ALL_CIPHERS" -With this option the library will automatically load and make available all -libcrypto ciphers. This option is a default option. Once selected subsequent -calls to \fBOPENSSL_init_crypto()\fR with the option -\&\fB\s-1OPENSSL_INIT_NO_ADD_ALL_CIPHERS\s0\fR will be ignored. -.IP "\s-1OPENSSL_INIT_ADD_ALL_DIGESTS\s0" 4 -.IX Item "OPENSSL_INIT_ADD_ALL_DIGESTS" -With this option the library will automatically load and make available all -libcrypto digests. This option is a default option. Once selected subsequent -calls to \fBOPENSSL_init_crypto()\fR with the option -\&\fB\s-1OPENSSL_INIT_NO_ADD_ALL_DIGESTS\s0\fR will be ignored. -.IP "\s-1OPENSSL_INIT_NO_ADD_ALL_CIPHERS\s0" 4 -.IX Item "OPENSSL_INIT_NO_ADD_ALL_CIPHERS" -With this option the library will suppress automatic loading of libcrypto -ciphers. This option is not a default option. Once selected subsequent -calls to \fBOPENSSL_init_crypto()\fR with the option -\&\fB\s-1OPENSSL_INIT_ADD_ALL_CIPHERS\s0\fR will be ignored. -.IP "\s-1OPENSSL_INIT_NO_ADD_ALL_DIGESTS\s0" 4 -.IX Item "OPENSSL_INIT_NO_ADD_ALL_DIGESTS" -With this option the library will suppress automatic loading of libcrypto -digests. This option is not a default option. Once selected subsequent -calls to \fBOPENSSL_init_crypto()\fR with the option -\&\fB\s-1OPENSSL_INIT_ADD_ALL_DIGESTS\s0\fR will be ignored. -.IP "\s-1OPENSSL_INIT_LOAD_CONFIG\s0" 4 -.IX Item "OPENSSL_INIT_LOAD_CONFIG" -With this option an OpenSSL configuration file will be automatically loaded and -used by calling \fBOPENSSL_config()\fR. This is a default option. -Note that in OpenSSL 1.1.1 this was the default for libssl but not for -libcrypto (see \fBOPENSSL_init_ssl\fR\|(3) for further details about libssl -initialisation). -In OpenSSL 1.1.0 this was a nondefault option for both libssl and libcrypto. -See the description of \fBOPENSSL_INIT_new()\fR, below. -.IP "\s-1OPENSSL_INIT_NO_LOAD_CONFIG\s0" 4 -.IX Item "OPENSSL_INIT_NO_LOAD_CONFIG" -With this option the loading of OpenSSL configuration files will be suppressed. -It is the equivalent of calling \fBOPENSSL_no_config()\fR. This is not a default -option. -.IP "\s-1OPENSSL_INIT_ASYNC\s0" 4 -.IX Item "OPENSSL_INIT_ASYNC" -With this option the library with automatically initialise the libcrypto async -sub-library (see \fBASYNC_start_job\fR\|(3)). This is a default option. -.IP "\s-1OPENSSL_INIT_ENGINE_RDRAND\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_RDRAND" -With this option the library will automatically load and initialise the -\&\s-1RDRAND\s0 engine (if available). This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ENGINE_DYNAMIC\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_DYNAMIC" -With this option the library will automatically load and initialise the -dynamic engine. This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ENGINE_OPENSSL\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_OPENSSL" -With this option the library will automatically load and initialise the -openssl engine. This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ENGINE_CRYPTODEV\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_CRYPTODEV" -With this option the library will automatically load and initialise the -cryptodev engine (if available). This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ENGINE_CAPI\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_CAPI" -With this option the library will automatically load and initialise the -\&\s-1CAPI\s0 engine (if available). This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ENGINE_PADLOCK\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_PADLOCK" -With this option the library will automatically load and initialise the -padlock engine (if available). This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ENGINE_AFALG\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_AFALG" -With this option the library will automatically load and initialise the -\&\s-1AFALG\s0 engine. This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ENGINE_ALL_BUILTIN\s0" 4 -.IX Item "OPENSSL_INIT_ENGINE_ALL_BUILTIN" -With this option the library will automatically load and initialise all the -built in engines listed above with the exception of the openssl and afalg -engines. This not a default option and is deprecated -in OpenSSL 3.0. -.IP "\s-1OPENSSL_INIT_ATFORK\s0" 4 -.IX Item "OPENSSL_INIT_ATFORK" -With this option the library will register its fork handlers. -See \fBOPENSSL_fork_prepare\fR\|(3) for details. -.IP "\s-1OPENSSL_INIT_NO_ATEXIT\s0" 4 -.IX Item "OPENSSL_INIT_NO_ATEXIT" -By default OpenSSL will attempt to clean itself up when the process exits via an -\&\*(L"atexit\*(R" handler. Using this option suppresses that behaviour. This means that -the application will have to clean up OpenSSL explicitly using -\&\fBOPENSSL_cleanup()\fR. -.PP -Multiple options may be combined together in a single call to -\&\fBOPENSSL_init_crypto()\fR. For example: -.PP -.Vb 2 -\& OPENSSL_init_crypto(OPENSSL_INIT_NO_ADD_ALL_CIPHERS -\& | OPENSSL_INIT_NO_ADD_ALL_DIGESTS, NULL); -.Ve -.PP -The \fBOPENSSL_cleanup()\fR function deinitialises OpenSSL (both libcrypto -and libssl). All resources allocated by OpenSSL are freed. Typically there -should be no need to call this function directly as it is initiated -automatically on application exit. This is done via the standard C library -\&\fBatexit()\fR function. In the event that the application will close in a manner -that will not call the registered \fBatexit()\fR handlers then the application should -call \fBOPENSSL_cleanup()\fR directly. Developers of libraries using OpenSSL -are discouraged from calling this function and should instead, typically, rely -on auto-deinitialisation. This is to avoid error conditions where both an -application and a library it depends on both use OpenSSL, and the library -deinitialises it before the application has finished using it. -.PP -Once \fBOPENSSL_cleanup()\fR has been called the library cannot be reinitialised. -Attempts to call \fBOPENSSL_init_crypto()\fR will fail and an \s-1ERR_R_INIT_FAIL\s0 error -will be added to the error stack. Note that because initialisation has failed -OpenSSL error strings will not be available, only an error code. This code can -be put through the openssl errstr command line application to produce a human -readable error (see \fBopenssl\-errstr\fR\|(1)). -.PP -The \fBOPENSSL_atexit()\fR function enables the registration of a -function to be called during \fBOPENSSL_cleanup()\fR. Stop handlers are -called after deinitialisation of resources local to a thread, but before other -process wide resources are freed. In the event that multiple stop handlers are -registered, no guarantees are made about the order of execution. -.PP -The \fBOPENSSL_thread_stop_ex()\fR function deallocates resources associated -with the current thread for the given \s-1OSSL_LIB_CTX\s0 \fBctx\fR. The \fBctx\fR parameter -can be \s-1NULL\s0 in which case the default \s-1OSSL_LIB_CTX\s0 is used. -.PP -Typically, this function will be called automatically by the library when -the thread exits as long as the \s-1OSSL_LIB_CTX\s0 has not been freed before the thread -exits. If \fBOSSL_LIB_CTX_free()\fR is called OPENSSL_thread_stop_ex will be called -automatically for the current thread (but not any other threads that may have -used this \s-1OSSL_LIB_CTX\s0). -.PP -OPENSSL_thread_stop_ex should be called on all threads that will exit after the -\&\s-1OSSL_LIB_CTX\s0 is freed. -Typically this is not necessary for the default \s-1OSSL_LIB_CTX\s0 (because all -resources are cleaned up on library exit) except if thread local resources -should be freed before library exit, or under the circumstances described in -the \s-1NOTES\s0 section below. -.PP -\&\fBOPENSSL_thread_stop()\fR is the same as \fBOPENSSL_thread_stop_ex()\fR except that the -default \s-1OSSL_LIB_CTX\s0 is always used. -.PP -The \fB\s-1OPENSSL_INIT_LOAD_CONFIG\s0\fR flag will load a configuration file, as with -\&\fBCONF_modules_load_file\fR\|(3) with \s-1NULL\s0 filename and application name and the -\&\fB\s-1CONF_MFLAGS_IGNORE_MISSING_FILE\s0\fR, \fB\s-1CONF_MFLAGS_IGNORE_RETURN_CODES\s0\fR and -\&\fB\s-1CONF_MFLAGS_DEFAULT_SECTION\s0\fR flags. -The filename, application name, and flags can be customized by providing a -non-null \fB\s-1OPENSSL_INIT_SETTINGS\s0\fR object. -The object can be allocated via \fB\fBOPENSSL_INIT_new()\fB\fR. -The \fB\fBOPENSSL_INIT_set_config_filename()\fB\fR function can be used to specify a -nondefault filename, which is copied and need not refer to persistent storage. -Similarly, \fBOPENSSL_INIT_set_config_appname()\fR can be used to specify a -nondefault application name. -Finally, OPENSSL_INIT_set_file_flags can be used to specify nondefault flags. -If the \fB\s-1CONF_MFLAGS_IGNORE_RETURN_CODES\s0\fR flag is not included, any errors in -the configuration file will cause an error return from \fBOPENSSL_init_crypto\fR -or indirectly \fBOPENSSL_init_ssl\fR\|(3). -The object can be released with \fBOPENSSL_INIT_free()\fR when done. -If the argument to \fBOPENSSL_INIT_free()\fR is \s-1NULL,\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -Resources local to a thread are deallocated automatically when the thread exits -(e.g. in a pthreads environment, when \fBpthread_exit()\fR is called). On Windows -platforms this is done in response to a \s-1DLL_THREAD_DETACH\s0 message being sent to -the libcrypto32.dll entry point. Some windows functions may cause threads to exit -without sending this message (for example \fBExitProcess()\fR). If the application -uses such functions, then the application must free up OpenSSL resources -directly via a call to \fBOPENSSL_thread_stop()\fR on each thread. Similarly this -message will also not be sent if OpenSSL is linked statically, and therefore -applications using static linking should also call \fBOPENSSL_thread_stop()\fR on each -thread. Additionally if OpenSSL is loaded dynamically via \fBLoadLibrary()\fR and the -threads are not destroyed until after \fBFreeLibrary()\fR is called then each thread -should call \fBOPENSSL_thread_stop()\fR prior to the \fBFreeLibrary()\fR call. -.PP -On Linux/Unix where OpenSSL has been loaded via \fBdlopen()\fR and the application is -multi-threaded and if \fBdlclose()\fR is subsequently called prior to the threads -being destroyed then OpenSSL will not be able to deallocate resources associated -with those threads. The application should either call \fBOPENSSL_thread_stop()\fR on -each thread prior to the \fBdlclose()\fR call, or alternatively the original \fBdlopen()\fR -call should use the \s-1RTLD_NODELETE\s0 flag (where available on the platform). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions OPENSSL_init_crypto, \fBOPENSSL_atexit()\fR and -\&\fBOPENSSL_INIT_set_config_appname()\fR return 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOPENSSL_init_ssl\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBOPENSSL_init_crypto()\fR, \fBOPENSSL_cleanup()\fR, \fBOPENSSL_atexit()\fR, -\&\fBOPENSSL_thread_stop()\fR, \fBOPENSSL_INIT_new()\fR, \fBOPENSSL_INIT_set_config_appname()\fR -and \fBOPENSSL_INIT_free()\fR functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_init_ssl.3ossl b/openssl-install/share/man/man3/OPENSSL_init_ssl.3ossl deleted file mode 100644 index 835242b3..00000000 --- a/openssl-install/share/man/man3/OPENSSL_init_ssl.3ossl +++ /dev/null @@ -1,209 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_INIT_SSL 3ossl" -.TH OPENSSL_INIT_SSL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_init_ssl \- OpenSSL (libssl and libcrypto) initialisation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OPENSSL_init_ssl(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -During normal operation OpenSSL (libssl and libcrypto) will allocate various -resources at start up that must, subsequently, be freed on close down of the -library. Additionally some resources are allocated on a per thread basis (if the -application is multi-threaded), and these resources must be freed prior to the -thread closing. -.PP -As of version 1.1.0 OpenSSL will automatically allocate all resources that it -needs so no explicit initialisation is required. Similarly it will also -automatically deinitialise as required. -.PP -However, there may be situations when explicit initialisation is desirable or -needed, for example when some nondefault initialisation is required. The -function \fBOPENSSL_init_ssl()\fR can be used for this purpose. Calling -this function will explicitly initialise \s-1BOTH\s0 libcrypto and libssl. To -explicitly initialise \s-1ONLY\s0 libcrypto see the -\&\fBOPENSSL_init_crypto\fR\|(3) function. -.PP -Numerous internal OpenSSL functions call \fBOPENSSL_init_ssl()\fR. -Therefore, in order to perform nondefault initialisation, -\&\fBOPENSSL_init_ssl()\fR \s-1MUST\s0 be called by application code prior to -any other OpenSSL function calls. -.PP -The \fBopts\fR parameter specifies which aspects of libssl and libcrypto should be -initialised. Valid options for libcrypto are described on the -\&\fBOPENSSL_init_crypto\fR\|(3) page. In addition to any libcrypto -specific option the following libssl options can also be used: -.IP "\s-1OPENSSL_INIT_NO_LOAD_SSL_STRINGS\s0" 4 -.IX Item "OPENSSL_INIT_NO_LOAD_SSL_STRINGS" -Suppress automatic loading of the libssl error strings. This option is -not a default option. Once selected subsequent calls to -\&\fBOPENSSL_init_ssl()\fR with the option -\&\fB\s-1OPENSSL_INIT_LOAD_SSL_STRINGS\s0\fR will be ignored. -.IP "\s-1OPENSSL_INIT_LOAD_SSL_STRINGS\s0" 4 -.IX Item "OPENSSL_INIT_LOAD_SSL_STRINGS" -Automatic loading of the libssl error strings. This option is a -default option. Once selected subsequent calls to -\&\fBOPENSSL_init_ssl()\fR with the option -\&\fB\s-1OPENSSL_INIT_LOAD_SSL_STRINGS\s0\fR will be ignored. -.PP -\&\fBOPENSSL_init_ssl()\fR takes a \fBsettings\fR parameter which can be used to -set parameter values. See \fBOPENSSL_init_crypto\fR\|(3) for details. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The function \fBOPENSSL_init_ssl()\fR returns 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOPENSSL_init_crypto\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBOPENSSL_init_ssl()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_instrument_bus.3ossl b/openssl-install/share/man/man3/OPENSSL_instrument_bus.3ossl deleted file mode 100644 index 83004ed1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_instrument_bus.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_INSTRUMENT_BUS 3ossl" -.TH OPENSSL_INSTRUMENT_BUS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_instrument_bus, OPENSSL_instrument_bus2 \- instrument references to memory bus -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 4 -\& #ifdef OPENSSL_CPUID_OBJ -\& size_t OPENSSL_instrument_bus(unsigned int *vector, size_t num); -\& size_t OPENSSL_instrument_bus2(unsigned int *vector, size_t num, size_t max); -\& #endif -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -It was empirically found that timings of references to primary memory -are subject to irregular, apparently non-deterministic variations. The -subroutines in question instrument these references for purposes of -gathering randomness for random number generator. In order to make it -bus-bound a 'flush cache line' instruction is used between probes. In -addition probes are added to \fBvector\fR elements in atomic or -interlocked manner, which should contribute additional noise on -multi-processor systems. This also means that \fBvector[num]\fR should be -zeroed upon invocation (if you want to retrieve actual probe values). -.PP -\&\fBOPENSSL_instrument_bus()\fR performs \fBnum\fR probes and records the number of -oscillator cycles every probe took. -.PP -\&\fBOPENSSL_instrument_bus2()\fR on the other hand \fBaccumulates\fR consecutive -probes with the same value, i.e. in a way it records duration of -periods when probe values appeared deterministic. The subroutine -performs at most \fBmax\fR probes in attempt to fill the \fBvector[num]\fR, -with \fBmax\fR value of 0 meaning \*(L"as many as it takes.\*(R" -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Return value of 0 indicates that \s-1CPU\s0 is not capable of performing the -benchmark, either because oscillator counter or 'flush cache line' is -not available on current platform. For reference, on x86 'flush cache -line' was introduced with the \s-1SSE2\s0 extensions. -.PP -Otherwise number of recorded values is returned. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2011\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_instrument_bus2.3ossl b/openssl-install/share/man/man3/OPENSSL_instrument_bus2.3ossl deleted file mode 120000 index 422f64b7..00000000 --- a/openssl-install/share/man/man3/OPENSSL_instrument_bus2.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_instrument_bus.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_load_builtin_modules.3ossl b/openssl-install/share/man/man3/OPENSSL_load_builtin_modules.3ossl deleted file mode 100644 index 5b6bf06c..00000000 --- a/openssl-install/share/man/man3/OPENSSL_load_builtin_modules.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_LOAD_BUILTIN_MODULES 3ossl" -.TH OPENSSL_LOAD_BUILTIN_MODULES 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_load_builtin_modules, ASN1_add_oid_module, ENGINE_add_conf_module \- add standard configuration modules -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void OPENSSL_load_builtin_modules(void); -\& void ASN1_add_oid_module(void); -\& void ENGINE_add_conf_module(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBOPENSSL_load_builtin_modules()\fR adds all the standard OpenSSL -configuration modules to the internal list. They can then be used by the -OpenSSL configuration code. -.PP -\&\fBASN1_add_oid_module()\fR adds just the \s-1ASN1 OBJECT\s0 module. -.PP -\&\fBENGINE_add_conf_module()\fR adds just the \s-1ENGINE\s0 configuration module. -.SH "NOTES" -.IX Header "NOTES" -If the simple configuration function \fBOPENSSL_config()\fR is called then -\&\fBOPENSSL_load_builtin_modules()\fR is called automatically. -.PP -Applications which use the configuration functions directly will need to -call \fBOPENSSL_load_builtin_modules()\fR themselves \fIbefore\fR any other -configuration code. -.PP -Applications should call \fBOPENSSL_load_builtin_modules()\fR to load all -configuration modules instead of adding modules selectively: otherwise -functionality may be missing from the application if an when new -modules are added. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -None of the functions return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBconfig\fR\|(5), \fBOPENSSL_config\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBENGINE_add_conf_module()\fR was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_malloc.3ossl b/openssl-install/share/man/man3/OPENSSL_malloc.3ossl deleted file mode 100644 index f0f0f803..00000000 --- a/openssl-install/share/man/man3/OPENSSL_malloc.3ossl +++ /dev/null @@ -1,390 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_MALLOC 3ossl" -.TH OPENSSL_MALLOC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_malloc_init, -OPENSSL_malloc, OPENSSL_aligned_alloc, OPENSSL_zalloc, OPENSSL_realloc, -OPENSSL_free, OPENSSL_clear_realloc, OPENSSL_clear_free, OPENSSL_cleanse, -CRYPTO_malloc, CRYPTO_aligned_alloc, CRYPTO_zalloc, CRYPTO_realloc, CRYPTO_free, -OPENSSL_strdup, OPENSSL_strndup, -OPENSSL_memdup, OPENSSL_strlcpy, OPENSSL_strlcat, OPENSSL_strtoul, -CRYPTO_strdup, CRYPTO_strndup, -OPENSSL_mem_debug_push, OPENSSL_mem_debug_pop, -CRYPTO_mem_debug_push, CRYPTO_mem_debug_pop, -CRYPTO_clear_realloc, CRYPTO_clear_free, -CRYPTO_malloc_fn, CRYPTO_realloc_fn, CRYPTO_free_fn, -CRYPTO_get_mem_functions, CRYPTO_set_mem_functions, -CRYPTO_get_alloc_counts, -CRYPTO_set_mem_debug, CRYPTO_mem_ctrl, -CRYPTO_mem_leaks, CRYPTO_mem_leaks_fp, CRYPTO_mem_leaks_cb, -OPENSSL_MALLOC_FAILURES, -OPENSSL_MALLOC_FD -\&\- Memory allocation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OPENSSL_malloc_init(void); -\& -\& void *OPENSSL_malloc(size_t num); -\& void *OPENSSL_aligned_alloc(size_t num, size_t alignment, void **freeptr); -\& void *OPENSSL_zalloc(size_t num); -\& void *OPENSSL_realloc(void *addr, size_t num); -\& void OPENSSL_free(void *addr); -\& char *OPENSSL_strdup(const char *str); -\& char *OPENSSL_strndup(const char *str, size_t s); -\& size_t OPENSSL_strlcat(char *dst, const char *src, size_t size); -\& size_t OPENSSL_strlcpy(char *dst, const char *src, size_t size); -\& int OPENSSL_strtoul(char *src, char **endptr, int base, unsigned long *num); -\& void *OPENSSL_memdup(void *data, size_t s); -\& void *OPENSSL_clear_realloc(void *p, size_t old_len, size_t num); -\& void OPENSSL_clear_free(void *str, size_t num); -\& void OPENSSL_cleanse(void *ptr, size_t len); -\& -\& void *CRYPTO_malloc(size_t num, const char *file, int line); -\& void *CRYPTO_aligned_alloc(size_t num, size_t align, void **freeptr, -\& const char *file, int line); -\& void *CRYPTO_zalloc(size_t num, const char *file, int line); -\& void *CRYPTO_realloc(void *p, size_t num, const char *file, int line); -\& void CRYPTO_free(void *str, const char *, int); -\& char *CRYPTO_strdup(const char *p, const char *file, int line); -\& char *CRYPTO_strndup(const char *p, size_t num, const char *file, int line); -\& void *CRYPTO_clear_realloc(void *p, size_t old_len, size_t num, -\& const char *file, int line); -\& void CRYPTO_clear_free(void *str, size_t num, const char *, int); -\& -\& typedef void *(*CRYPTO_malloc_fn)(size_t num, const char *file, int line); -\& typedef void *(*CRYPTO_realloc_fn)(void *addr, size_t num, const char *file, -\& int line); -\& typedef void (*CRYPTO_free_fn)(void *addr, const char *file, int line); -\& void CRYPTO_get_mem_functions(CRYPTO_malloc_fn *malloc_fn, -\& CRYPTO_realloc_fn *realloc_fn, -\& CRYPTO_free_fn *free_fn); -\& int CRYPTO_set_mem_functions(CRYPTO_malloc_fn malloc_fn, -\& CRYPTO_realloc_fn realloc_fn, -\& CRYPTO_free_fn free_fn); -\& -\& void CRYPTO_get_alloc_counts(int *mcount, int *rcount, int *fcount); -\& -\& env OPENSSL_MALLOC_FAILURES=... -\& env OPENSSL_MALLOC_FD=... -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& int CRYPTO_mem_leaks(BIO *b); -\& int CRYPTO_mem_leaks_fp(FILE *fp); -\& int CRYPTO_mem_leaks_cb(int (*cb)(const char *str, size_t len, void *u), -\& void *u); -\& -\& int CRYPTO_set_mem_debug(int onoff); -\& int CRYPTO_mem_ctrl(int mode); -\& int OPENSSL_mem_debug_push(const char *info); -\& int OPENSSL_mem_debug_pop(void); -\& int CRYPTO_mem_debug_push(const char *info, const char *file, int line); -\& int CRYPTO_mem_debug_pop(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL memory allocation is handled by the \fBOPENSSL_xxx\fR \s-1API.\s0 These are -generally macro's that add the standard C \fB_\|_FILE_\|_\fR and \fB_\|_LINE_\|_\fR -parameters and call a lower-level \fBCRYPTO_xxx\fR \s-1API.\s0 -Some functions do not add those parameters, but exist for consistency. -.PP -\&\fBOPENSSL_malloc_init()\fR does nothing and does not need to be called. It is -included for compatibility with older versions of OpenSSL. -.PP -\&\fBOPENSSL_malloc()\fR, \fBOPENSSL_realloc()\fR, and \fBOPENSSL_free()\fR are like the -C \fBmalloc()\fR, \fBrealloc()\fR, and \fBfree()\fR functions. -\&\fBOPENSSL_zalloc()\fR calls \fBmemset()\fR to zero the memory before returning. -.PP -\&\fBOPENSSL_aligned_alloc()\fR operates just as OPENSSL_malloc does, but it -allows for the caller to specify an alignment value, for instances in -which the default alignment of malloc is insufficient for the callers -needs. Note, the alignment value must be a power of 2, and the size -specified must be a multiple of the alignment. -\&\s-1NOTE:\s0 The call to \fBOPENSSL_aligned_alloc()\fR accepts a 3rd argument, \fIfreeptr\fR -which must point to a void pointer. On some platforms, there is no available -library call to obtain memory allocations greater than what malloc provides. In -this case, OPENSSL_aligned_alloc implements its own alignment routine, -allocating additional memory and offsetting the returned pointer to be on the -requested alignment boundary. In order to safely free allocations made by this -method, the caller must return the value in the \fIfreeptr\fR variable, rather than -the returned pointer. -.PP -\&\fBOPENSSL_clear_realloc()\fR and \fBOPENSSL_clear_free()\fR should be used -when the buffer at \fBaddr\fR holds sensitive information. -The old buffer is filled with zero's by calling \fBOPENSSL_cleanse()\fR -before ultimately calling \fBOPENSSL_free()\fR. If the argument to \fBOPENSSL_free()\fR is -\&\s-1NULL,\s0 nothing is done. -.PP -\&\fBOPENSSL_cleanse()\fR fills \fBptr\fR of size \fBlen\fR with a string of 0's. -Use \fBOPENSSL_cleanse()\fR with care if the memory is a mapping of a file. -If the storage controller uses write compression, then it's possible -that sensitive tail bytes will survive zeroization because the block of -zeros will be compressed. If the storage controller uses wear leveling, -then the old sensitive data will not be overwritten; rather, a block of -0's will be written at a new physical location. -.PP -\&\fBOPENSSL_strdup()\fR, \fBOPENSSL_strndup()\fR and \fBOPENSSL_memdup()\fR are like the -equivalent C functions, except that memory is allocated by calling the -\&\fBOPENSSL_malloc()\fR and should be released by calling \fBOPENSSL_free()\fR. -.PP -\&\fBOPENSSL_strlcpy()\fR, -\&\fBOPENSSL_strlcat()\fR and \fBOPENSSL_strnlen()\fR are equivalents of the common C -library functions and are provided for portability. -.PP -\&\fBOPENSSL_strtoul()\fR is a wrapper around the \s-1POSIX\s0 function strtoul, with the same -behaviors listed in the \s-1POSIX\s0 documentation, with the additional behavior that -it validates the input \fIstr\fR and \fInum\fR parameters for not being \s-1NULL,\s0 and confirms -that at least a single byte of input has been consumed in the translation, -returning an error in the event that no bytes were consumed. -.PP -If no allocations have been done, it is possible to \*(L"swap out\*(R" the default -implementations for \fBOPENSSL_malloc()\fR, \fBOPENSSL_realloc()\fR and \fBOPENSSL_free()\fR -and replace them with alternate versions. -\&\fBCRYPTO_get_mem_functions()\fR function fills in the given arguments with the -function pointers for the current implementations. -With \fBCRYPTO_set_mem_functions()\fR, you can specify a different set of functions. -If any of \fBmalloc_fn\fR, \fBrealloc_fn\fR, or \fBfree_fn\fR are \s-1NULL,\s0 then -the function is not changed. -While it's permitted to swap out only a few and not all the functions -with \fBCRYPTO_set_mem_functions()\fR, it's recommended to swap them all out -at once. -.PP -If the library is built with the \f(CW\*(C`crypto\-mdebug\*(C'\fR option, then one -function, \fBCRYPTO_get_alloc_counts()\fR, and two additional environment -variables, \fB\s-1OPENSSL_MALLOC_FAILURES\s0\fR and \fB\s-1OPENSSL_MALLOC_FD\s0\fR, -are available. -.PP -The function \fBCRYPTO_get_alloc_counts()\fR fills in the number of times -each of \fBCRYPTO_malloc()\fR, \fBCRYPTO_realloc()\fR, and \fBCRYPTO_free()\fR have been -called, into the values pointed to by \fBmcount\fR, \fBrcount\fR, and \fBfcount\fR, -respectively. If a pointer is \s-1NULL,\s0 then the corresponding count is not stored. -.PP -The variable -\&\fB\s-1OPENSSL_MALLOC_FAILURES\s0\fR controls how often allocations should fail. -It is a set of fields separated by semicolons, which each field is a count -(defaulting to zero) and an optional atsign and percentage (defaulting -to 100). If the count is zero, then it lasts forever. For example, -\&\f(CW\*(C`100;@25\*(C'\fR or \f(CW\*(C`100@0;0@25\*(C'\fR means the first 100 allocations pass, then all -other allocations (until the program exits or crashes) have a 25% chance of -failing. -.PP -If the variable \fB\s-1OPENSSL_MALLOC_FD\s0\fR is parsed as a positive integer, then -it is taken as an open file descriptor. This is used in conjunction with -\&\fB\s-1OPENSSL_MALLOC_FAILURES\s0\fR described above. For every allocation it will log -details about how many allocations there have been so far, what percentage -chance there is for this allocation failing, and whether it has actually failed. -The following example in classic shell syntax shows how to use this (will not -work on all platforms): -.PP -.Vb 5 -\& OPENSSL_MALLOC_FAILURES=\*(Aq200;@10\*(Aq -\& export OPENSSL_MALLOC_FAILURES -\& OPENSSL_MALLOC_FD=3 -\& export OPENSSL_MALLOC_FD -\& ...app invocation... 3>/tmp/log$$ -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOPENSSL_malloc_init()\fR, \fBOPENSSL_free()\fR, \fBOPENSSL_clear_free()\fR -\&\fBCRYPTO_free()\fR, \fBCRYPTO_clear_free()\fR and \fBCRYPTO_get_mem_functions()\fR -return no value. -.PP -\&\fBOPENSSL_malloc()\fR, \fBOPENSSL_aligned_alloc()\fR, \fBOPENSSL_zalloc()\fR, \fBOPENSSL_realloc()\fR, -\&\fBOPENSSL_clear_realloc()\fR, -\&\fBCRYPTO_malloc()\fR, \fBCRYPTO_zalloc()\fR, \fBCRYPTO_realloc()\fR, -\&\fBCRYPTO_clear_realloc()\fR, -\&\fBOPENSSL_strdup()\fR, and \fBOPENSSL_strndup()\fR -return a pointer to allocated memory or \s-1NULL\s0 on error. -.PP -\&\fBCRYPTO_set_mem_functions()\fR returns 1 on success or 0 on failure (almost -always because allocations have already happened). -.PP -\&\fBCRYPTO_mem_leaks()\fR, \fBCRYPTO_mem_leaks_fp()\fR, \fBCRYPTO_mem_leaks_cb()\fR, -\&\fBCRYPTO_set_mem_debug()\fR, and \fBCRYPTO_mem_ctrl()\fR are deprecated and are no-ops that -always return \-1. -\&\fBOPENSSL_mem_debug_push()\fR, \fBOPENSSL_mem_debug_pop()\fR, -\&\fBCRYPTO_mem_debug_push()\fR, and \fBCRYPTO_mem_debug_pop()\fR -are deprecated and are no-ops that always return 0. -.PP -\&\fBOPENSSL_strtoul()\fR returns 1 on success and 0 in the event that an error has -occurred. Specifically, 0 is returned in the following events: -.IP "\(bu" 4 -If the underlying call to strtoul returned a non zero errno value -.IP "\(bu" 4 -If the translation did not consume the entire input string, and the passed -endptr value was \s-1NULL\s0 -.IP "\(bu" 4 -If no characters were consumed in the translation -.PP -Note that a success condition does not imply that the expected -translation has been performed. For instance calling -.PP -.Vb 1 -\& OPENSSL_strtoul("0x12345", &endptr, 10, &num); -.Ve -.PP -will result in a successful translation with num having the value 0, and -*endptr = 'x'. Be sure to validate how much data was consumed when calling this -function. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOPENSSL_mem_debug_push()\fR, \fBOPENSSL_mem_debug_pop()\fR, -\&\fBCRYPTO_mem_debug_push()\fR, \fBCRYPTO_mem_debug_pop()\fR, -\&\fBCRYPTO_mem_leaks()\fR, \fBCRYPTO_mem_leaks_fp()\fR, -\&\fBCRYPTO_mem_leaks_cb()\fR, \fBCRYPTO_set_mem_debug()\fR, \fBCRYPTO_mem_ctrl()\fR -were deprecated in OpenSSL 3.0. -The memory-leak checking has been deprecated in OpenSSL 3.0 in favor of -clang's memory and leak sanitizer. -\&\fBOPENSSL_aligned_alloc()\fR, \fBCRYPTO_aligned_alloc()\fR were added in OpenSSL 3.4.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_malloc_init.3ossl b/openssl-install/share/man/man3/OPENSSL_malloc_init.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_malloc_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_mem_debug_pop.3ossl b/openssl-install/share/man/man3/OPENSSL_mem_debug_pop.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_mem_debug_pop.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_mem_debug_push.3ossl b/openssl-install/share/man/man3/OPENSSL_mem_debug_push.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_mem_debug_push.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_memdup.3ossl b/openssl-install/share/man/man3/OPENSSL_memdup.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_memdup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_no_config.3ossl b/openssl-install/share/man/man3/OPENSSL_no_config.3ossl deleted file mode 120000 index e935b946..00000000 --- a/openssl-install/share/man/man3/OPENSSL_no_config.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_config.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_realloc.3ossl b/openssl-install/share/man/man3/OPENSSL_realloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_realloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_riscvcap.3ossl b/openssl-install/share/man/man3/OPENSSL_riscvcap.3ossl deleted file mode 100644 index 6c29ee59..00000000 --- a/openssl-install/share/man/man3/OPENSSL_riscvcap.3ossl +++ /dev/null @@ -1,323 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_RISCVCAP 3ossl" -.TH OPENSSL_RISCVCAP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_riscvcap \- the RISC\-V processor capabilities vector -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& env OPENSSL_riscvcap=... -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -libcrypto supports RISC-V instruction set extensions. These -extensions are denoted by individual extension names in the capabilities -vector. For Linux platform, when libcrypto is initialized, the results -returned by the RISC-V Hardware Probing syscall (hwprobe) are stored -in the vector. Otherwise all capabilities are disabled. -.PP -To override the set of instructions available to an application, you can -set the \fBOPENSSL_riscvcap\fR environment variable before you start the -application. -.PP -The environment variable is similar to the RISC-V \s-1ISA\s0 string defined in the -RISC-V Instruction Set Manual. It is case insensitive. Though due to the limit -of the environment variable parser inside libcrypto, an extension must be -prefixed with an underscore to make it recognizable. This also applies to the -Vector extension. -.PP -.Vb 1 -\& OPENSSL_riscvcap="rv64gc_v_zba_zbb_zbs..." -.Ve -.PP -Note that extension implication is currently not implemented. -For example, when \*(L"rv64gc_b\*(R" is provided as the environment variable, -zba/zbb/zbs would not be implied in the capability vector. -.PP -Currently only these extensions are recognized: -.IP "\s-1ZBA\s0" 4 -.IX Item "ZBA" -Address Generation -.Sp -Could be detected using hwprobe for Linux kernel >= 6.5 -.IP "\s-1ZBB\s0" 4 -.IX Item "ZBB" -Basic bit-manipulation -.Sp -Could be detected using hwprobe for Linux kernel >= 6.5 -.IP "\s-1ZBC\s0" 4 -.IX Item "ZBC" -Carry-less multiplication -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZBS\s0" 4 -.IX Item "ZBS" -Single-bit instructions -.Sp -Could be detected using hwprobe for Linux kernel >= 6.5 -.IP "\s-1ZBKB\s0" 4 -.IX Item "ZBKB" -Bit-manipulation for Cryptography -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZBKC\s0" 4 -.IX Item "ZBKC" -Carry-less multiplication for Cryptography -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZBKX\s0" 4 -.IX Item "ZBKX" -Crossbar permutations -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZKND\s0" 4 -.IX Item "ZKND" -\&\s-1NIST\s0 Suite: \s-1AES\s0 Decryption -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZKNE\s0" 4 -.IX Item "ZKNE" -\&\s-1NIST\s0 Suite: \s-1AES\s0 Encryption -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZKNH\s0" 4 -.IX Item "ZKNH" -\&\s-1NIST\s0 Suite: Hash Function Instructions -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZKSED\s0" 4 -.IX Item "ZKSED" -ShangMi Suite: \s-1SM4\s0 Block Cipher Instructions -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZKSH\s0" 4 -.IX Item "ZKSH" -ShangMi Suite: \s-1SM3\s0 Hash Function Instructions -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZKR\s0" 4 -.IX Item "ZKR" -Entropy Source Extension -.IP "\s-1ZKT\s0" 4 -.IX Item "ZKT" -Data Independent Execution Latency -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "V" 4 -.IX Item "V" -Vector Extension for Application Processors -.Sp -Could be detected using hwprobe for Linux kernel >= 6.5 -.IP "\s-1ZVBB\s0" 4 -.IX Item "ZVBB" -Vector Basic Bit-manipulation -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVBC\s0" 4 -.IX Item "ZVBC" -Vector Carryless Multiplication -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVKB\s0" 4 -.IX Item "ZVKB" -Vector Cryptography Bit-manipulation -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVKG\s0" 4 -.IX Item "ZVKG" -Vector \s-1GCM/GMAC\s0 -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVKNED\s0" 4 -.IX Item "ZVKNED" -\&\s-1NIST\s0 Suite: Vector \s-1AES\s0 Block Cipher -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVKNHA\s0" 4 -.IX Item "ZVKNHA" -\&\s-1NIST\s0 Suite: Vector \s-1SHA\-2\s0 Secure Hash -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVKNHB\s0" 4 -.IX Item "ZVKNHB" -\&\s-1NIST\s0 Suite: Vector \s-1SHA\-2\s0 Secure Hash -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVKSED\s0" 4 -.IX Item "ZVKSED" -ShangMi Suite: \s-1SM4\s0 Block Cipher -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.IP "\s-1ZVKSH\s0" 4 -.IX Item "ZVKSH" -ShangMi Suite: \s-1SM3\s0 Secure Hash -.Sp -Could be detected using hwprobe for Linux kernel >= 6.8 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Not available. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Check currently detected capabilities -.PP -.Vb 2 -\& $ openssl info \-cpusettings -\& OPENSSL_riscvcap=ZBA_ZBB_ZBC_ZBS_V -.Ve -.PP -Disables all instruction set extensions: -.PP -.Vb 1 -\& OPENSSL_riscvcap="rv64gc" -.Ve -.PP -Only enable the vector extension: -.PP -.Vb 1 -\& OPENSSL_riscvcap="rv64gc_v" -.Ve -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_s390xcap.3ossl b/openssl-install/share/man/man3/OPENSSL_s390xcap.3ossl deleted file mode 100644 index bf6e240e..00000000 --- a/openssl-install/share/man/man3/OPENSSL_s390xcap.3ossl +++ /dev/null @@ -1,344 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_S390XCAP 3ossl" -.TH OPENSSL_S390XCAP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_s390xcap \- the IBM z processor capabilities vector -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& env OPENSSL_s390xcap=... -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -libcrypto supports z/Architecture instruction set extensions. These -extensions are denoted by individual bits in the capabilities vector. -When libcrypto is initialized, the bits returned by the \s-1STFLE\s0 instruction -and by the \s-1QUERY\s0 functions are stored in the vector. -.PP -To change the set of instructions available to an application, you can -set the \fBOPENSSL_s390xcap\fR environment variable before you start the -application. After initialization, the capability vector is ANDed bitwise -with a mask which is derived from the environment variable. -.PP -The environment variable is a semicolon-separated list of tokens which is -processed from left to right (whitespace is ignored): -.PP -.Vb 1 -\& OPENSSL_s390xcap=";;..." -.Ve -.PP -There are four types of tokens: -.IP "" 4 -.IX Item "" -The name of a processor generation. A bit in the environment variable's -mask is set to one if and only if the specified processor generation -implements the corresponding instruction set extension. Possible values -are \fBz900\fR, \fBz990\fR, \fBz9\fR, \fBz10\fR, \fBz196\fR, \fBzEC12\fR, \fBz13\fR, \fBz14\fR, -\&\fBz15\fR, and \fBz16\fR. -.IP "::" 4 -.IX Item "::" -The name of an instruction followed by two 64\-bit masks. The part of the -environment variable's mask corresponding to the specified instruction is -set to the specified 128\-bit mask. Possible values are \fBkimd\fR, \fBklmd\fR, -\&\fBkm\fR, \fBkmc\fR, \fBkmac\fR, \fBkmctr\fR, \fBkmo\fR, \fBkmf\fR, \fBprno\fR, \fBkma\fR, \fBpcc\fR -and \fBkdsa\fR. -.IP "stfle:::" 4 -.IX Item "stfle:::" -Store-facility-list-extended (stfle) followed by three 64\-bit masks. The -part of the environment variable's mask corresponding to the stfle -instruction is set to the specified 192\-bit mask. -.IP "nocex" 4 -.IX Item "nocex" -Deactivate modular exponentiation and \s-1CRT\s0 operation offloading to -Crypto Express Adapters. -.PP -The 64\-bit masks are specified in hexadecimal notation. The 0x prefix is -optional. Prefix a mask with a tilde, \f(CW\*(C`~\*(C'\fR, to denote a bitwise \s-1NOT\s0 operation. -.PP -The following is a list of significant bits for each instruction. Colon -rows separate the individual 64\-bit masks. The bit numbers in the first -column are consistent with [1], that is, 0 denotes the leftmost bit and -the numbering is continuous across 64\-bit mask boundaries. -.PP -.Vb 1 -\& Bit Mask Facility/Function -\& -\& stfle: -\& # 17 1<<46 message\-security assist -\& # 25 1<<38 store\-clock\-fast facility -\& : -\& # 76 1<<51 message\-security assist extension 3 -\& # 77 1<<50 message\-security assist extension 4 -\& # 86 1<<41 message\-security\-assist extension 12 -\& : -\& #129 1<<62 vector facility -\& #134 1<<57 vector packed decimal facility -\& #135 1<<56 vector enhancements facility 1 -\& #146 1<<45 message\-security assist extension 8 -\& #155 1<<36 message\-security assist extension 9 -\& -\& kimd : -\& # 1 1<<62 KIMD\-SHA\-1 -\& # 2 1<<61 KIMD\-SHA\-256 -\& # 3 1<<60 KIMD\-SHA\-512 -\& # 32 1<<31 KIMD\-SHA3\-224 -\& # 33 1<<30 KIMD\-SHA3\-256 -\& # 34 1<<29 KIMD\-SHA3\-384 -\& # 35 1<<28 KIMD\-SHA3\-512 -\& # 36 1<<27 KIMD\-SHAKE\-128 -\& # 37 1<<26 KIMD\-SHAKE\-256 -\& : -\& # 65 1<<62 KIMD\-GHASH -\& -\& klmd : -\& # 32 1<<31 KLMD\-SHA3\-224 -\& # 33 1<<30 KLMD\-SHA3\-256 -\& # 34 1<<29 KLMD\-SHA3\-384 -\& # 35 1<<28 KLMD\-SHA3\-512 -\& # 36 1<<27 KLMD\-SHAKE\-128 -\& # 37 1<<26 KLMD\-SHAKE\-256 -\& : -\& -\& km : -\& # 18 1<<45 KM\-AES\-128 -\& # 19 1<<44 KM\-AES\-192 -\& # 20 1<<43 KM\-AES\-256 -\& # 50 1<<13 KM\-XTS\-AES\-128 -\& # 52 1<<11 KM\-XTS\-AES\-256 -\& : -\& # 82 1<<45 KM\-XTS\-AES\-128\-MSA10 -\& # 84 1<<43 KM\-XTS\-AES\-256\-MSA10 -\& -\& kmc : -\& # 18 1<<45 KMC\-AES\-128 -\& # 19 1<<44 KMC\-AES\-192 -\& # 20 1<<43 KMC\-AES\-256 -\& : -\& -\& kmac : -\& # 18 1<<45 KMAC\-AES\-128 -\& # 19 1<<44 KMAC\-AES\-192 -\& # 20 1<<43 KMAC\-AES\-256 -\& : -\& # 112 1<<15 KMAC\-SHA\-224 -\& # 113 1<<14 KMAC\-SHA\-256 -\& # 114 1<<13 KMAC\-SHA\-384 -\& # 115 1<<12 KMAC\-SHA\-512 -\& -\& kmctr: -\& : -\& -\& kmo : -\& # 18 1<<45 KMO\-AES\-128 -\& # 19 1<<44 KMO\-AES\-192 -\& # 20 1<<43 KMO\-AES\-256 -\& : -\& -\& kmf : -\& # 18 1<<45 KMF\-AES\-128 -\& # 19 1<<44 KMF\-AES\-192 -\& # 20 1<<43 KMF\-AES\-256 -\& : -\& -\& prno : -\& : -\& -\& kma : -\& # 18 1<<45 KMA\-GCM\-AES\-128 -\& # 19 1<<44 KMA\-GCM\-AES\-192 -\& # 20 1<<43 KMA\-GCM\-AES\-256 -\& : -\& -\& pcc : -\& : -\& # 64 1<<63 PCC\-Scalar\-Multiply\-P256 -\& # 65 1<<62 PCC\-Scalar\-Multiply\-P384 -\& # 66 1<<61 PCC\-Scalar\-Multiply\-P521 -\& # 72 1<<55 PCC\-Scalar\-Multiply\-Ed25519 -\& # 73 1<<54 PCC\-Scalar\-Multiply\-Ed448 -\& # 80 1<<47 PCC\-Scalar\-Multiply\-X25519 -\& # 81 1<<46 PCC\-Scalar\-Multiply\-X448 -\& -\& kdsa : -\& # 1 1<<62 KDSA\-ECDSA\-Verify\-P256 -\& # 2 1<<61 KDSA\-ECDSA\-Verify\-P384 -\& # 3 1<<60 KDSA\-ECDSA\-Verify\-P521 -\& # 9 1<<54 KDSA\-ECDSA\-Sign\-P256 -\& # 10 1<<53 KDSA\-ECDSA\-Sign\-P384 -\& # 11 1<<52 KDSA\-ECDSA\-Sign\-P521 -\& # 32 1<<31 KDSA\-EdDSA\-Verify\-Ed25519 -\& # 36 1<<27 KDSA\-EdDSA\-Verify\-Ed448 -\& # 40 1<<23 KDSA\-EdDSA\-Sign\-Ed25519 -\& # 44 1<<19 KDSA\-EdDSA\-Sign\-Ed448 -\& : -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Not available. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Disables all instruction set extensions which the z196 processor does not implement: -.PP -.Vb 1 -\& OPENSSL_s390xcap="z196" -.Ve -.PP -Disables the vector facility: -.PP -.Vb 1 -\& OPENSSL_s390xcap="stfle:~0:~0:~0x4000000000000000" -.Ve -.PP -Disables the KM-XTS-AES and the KIMD-SHAKE function codes: -.PP -.Vb 1 -\& OPENSSL_s390xcap="km:~0x2800:~0;kimd:~0xc000000:~0" -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -[1] z/Architecture Principles of Operation, \s-1SA22\-7832\-12\s0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_secure_actual_size.3ossl b/openssl-install/share/man/man3/OPENSSL_secure_actual_size.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/OPENSSL_secure_actual_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_secure_clear_free.3ossl b/openssl-install/share/man/man3/OPENSSL_secure_clear_free.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/OPENSSL_secure_clear_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_secure_free.3ossl b/openssl-install/share/man/man3/OPENSSL_secure_free.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/OPENSSL_secure_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_secure_malloc.3ossl b/openssl-install/share/man/man3/OPENSSL_secure_malloc.3ossl deleted file mode 100644 index 9d81c298..00000000 --- a/openssl-install/share/man/man3/OPENSSL_secure_malloc.3ossl +++ /dev/null @@ -1,276 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_SECURE_MALLOC 3ossl" -.TH OPENSSL_SECURE_MALLOC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -CRYPTO_secure_malloc_init, CRYPTO_secure_malloc_initialized, -CRYPTO_secure_malloc_done, OPENSSL_secure_malloc, CRYPTO_secure_malloc, -OPENSSL_secure_zalloc, CRYPTO_secure_zalloc, OPENSSL_secure_free, -CRYPTO_secure_free, OPENSSL_secure_clear_free, -CRYPTO_secure_clear_free, OPENSSL_secure_actual_size, -CRYPTO_secure_allocated, -CRYPTO_secure_used \- secure heap storage -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int CRYPTO_secure_malloc_init(size_t size, size_t minsize); -\& -\& int CRYPTO_secure_malloc_initialized(); -\& -\& int CRYPTO_secure_malloc_done(); -\& -\& void *OPENSSL_secure_malloc(size_t num); -\& void *CRYPTO_secure_malloc(size_t num, const char *file, int line); -\& -\& void *OPENSSL_secure_zalloc(size_t num); -\& void *CRYPTO_secure_zalloc(size_t num, const char *file, int line); -\& -\& void OPENSSL_secure_free(void* ptr); -\& void CRYPTO_secure_free(void *ptr, const char *, int); -\& -\& void OPENSSL_secure_clear_free(void* ptr, size_t num); -\& void CRYPTO_secure_clear_free(void *ptr, size_t num, const char *, int); -\& -\& size_t OPENSSL_secure_actual_size(const void *ptr); -\& -\& int CRYPTO_secure_allocated(const void *ptr); -\& size_t CRYPTO_secure_used(); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -In order to help protect applications (particularly long-running servers) -from pointer overruns or underruns that could return arbitrary data from -the program's dynamic memory area, where keys and other sensitive -information might be stored, OpenSSL supports the concept of a \*(L"secure heap.\*(R" -The level and type of security guarantees depend on the operating system. -It is a good idea to review the code and see if it addresses your -threat model and concerns. -.PP -If a secure heap is used, then private key \fB\s-1BIGNUM\s0\fR values are stored there. -This protects long-term storage of private keys, but will not necessarily -put all intermediate values and computations there. -.PP -\&\fBCRYPTO_secure_malloc_init()\fR creates the secure heap, with the specified -\&\f(CW\*(C`size\*(C'\fR in bytes. The \f(CW\*(C`minsize\*(C'\fR parameter is the minimum size to -allocate from the heap or zero to use a reasonable default value. -Both \f(CW\*(C`size\*(C'\fR and, if specified, \f(CW\*(C`minsize\*(C'\fR must be a power of two and -\&\f(CW\*(C`minsize\*(C'\fR should generally be small, for example 16 or 32. -\&\f(CW\*(C`minsize\*(C'\fR must be less than a quarter of \f(CW\*(C`size\*(C'\fR in any case. -.PP -\&\fBCRYPTO_secure_malloc_initialized()\fR indicates whether or not the secure -heap as been initialized and is available. -.PP -\&\fBCRYPTO_secure_malloc_done()\fR releases the heap and makes the memory unavailable -to the process if all secure memory has been freed. -It can take noticeably long to complete. -.PP -\&\fBOPENSSL_secure_malloc()\fR allocates \f(CW\*(C`num\*(C'\fR bytes from the heap. -If \fBCRYPTO_secure_malloc_init()\fR is not called, this is equivalent to -calling \fBOPENSSL_malloc()\fR. -It is a macro that expands to -\&\fBCRYPTO_secure_malloc()\fR and adds the \f(CW\*(C`_\|_FILE_\|_\*(C'\fR and \f(CW\*(C`_\|_LINE_\|_\*(C'\fR parameters. -.PP -\&\fBOPENSSL_secure_zalloc()\fR and \fBCRYPTO_secure_zalloc()\fR are like -\&\fBOPENSSL_secure_malloc()\fR and \fBCRYPTO_secure_malloc()\fR, respectively, -except that they call \fBmemset()\fR to zero the memory before returning. -.PP -\&\fBOPENSSL_secure_free()\fR releases the memory at \f(CW\*(C`ptr\*(C'\fR back to the heap. -It must be called with a value previously obtained from -\&\fBOPENSSL_secure_malloc()\fR. -If \fBCRYPTO_secure_malloc_init()\fR is not called, this is equivalent to -calling \fBOPENSSL_free()\fR. -It exists for consistency with \fBOPENSSL_secure_malloc()\fR , and -is a macro that expands to \fBCRYPTO_secure_free()\fR and adds the \f(CW\*(C`_\|_FILE_\|_\*(C'\fR -and \f(CW\*(C`_\|_LINE_\|_\*(C'\fR parameters.. If the argument to \fBOPENSSL_secure_free()\fR -is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOPENSSL_secure_clear_free()\fR is similar to \fBOPENSSL_secure_free()\fR except -that it has an additional \f(CW\*(C`num\*(C'\fR parameter which is used to clear -the memory if it was not allocated from the secure heap. -If \fBCRYPTO_secure_malloc_init()\fR is not called, this is equivalent to -calling \fBOPENSSL_clear_free()\fR. If the argument to \fBOPENSSL_secure_clear_free()\fR -is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOPENSSL_secure_actual_size()\fR tells the actual size allocated to the -pointer; implementations may allocate more space than initially -requested, in order to \*(L"round up\*(R" and reduce secure heap fragmentation. -.PP -\&\fBOPENSSL_secure_allocated()\fR tells if a pointer is allocated in the secure heap. -.PP -\&\fBCRYPTO_secure_used()\fR returns the number of bytes allocated in the -secure heap. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBCRYPTO_secure_malloc_init()\fR returns 0 on failure, 1 if successful, -and 2 if successful but the heap could not be protected by memory -mapping. -.PP -\&\fBCRYPTO_secure_malloc_initialized()\fR returns 1 if the secure heap is -available (that is, if \fBCRYPTO_secure_malloc_init()\fR has been called, -but \fBCRYPTO_secure_malloc_done()\fR has not been called or failed) or 0 if not. -.PP -\&\fBOPENSSL_secure_malloc()\fR and \fBOPENSSL_secure_zalloc()\fR return a pointer into -the secure heap of the requested size, or \f(CW\*(C`NULL\*(C'\fR if memory could not be -allocated. -.PP -\&\fBCRYPTO_secure_allocated()\fR returns 1 if the pointer is in the secure heap, or 0 if not. -.PP -\&\fBCRYPTO_secure_malloc_done()\fR returns 1 if the secure memory area is released, or 0 if not. -.PP -\&\fBOPENSSL_secure_free()\fR and \fBOPENSSL_secure_clear_free()\fR return no values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOPENSSL_malloc\fR\|(3), -\&\fBBN_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBOPENSSL_secure_clear_free()\fR function was added in OpenSSL 1.1.0g. -.PP -The second argument to \fBCRYPTO_secure_malloc_init()\fR was changed from an \fBint\fR to -a \fBsize_t\fR in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_secure_zalloc.3ossl b/openssl-install/share/man/man3/OPENSSL_secure_zalloc.3ossl deleted file mode 120000 index 7a877887..00000000 --- a/openssl-install/share/man/man3/OPENSSL_secure_zalloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_secure_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_deep_copy.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_deep_copy.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_deep_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_delete.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_delete.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_delete.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_delete_ptr.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_delete_ptr.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_delete_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_dup.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_dup.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_find.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_find.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_find_all.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_find_all.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_find_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_find_ex.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_find_ex.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_find_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_free.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_free.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_insert.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_insert.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_insert.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_is_sorted.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_is_sorted.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_is_sorted.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_new.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_new.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_new_null.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_new_null.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_new_null.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_new_reserve.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_new_reserve.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_new_reserve.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_num.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_num.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_pop.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_pop.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_pop.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_pop_free.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_pop_free.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_pop_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_push.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_push.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_push.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_reserve.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_reserve.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_reserve.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_set.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_set.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_set_cmp_func.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_set_cmp_func.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_set_cmp_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_shift.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_shift.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_shift.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_sort.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_sort.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_sort.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_unshift.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_unshift.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_unshift.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_value.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_value.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_value.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_sk_zero.3ossl b/openssl-install/share/man/man3/OPENSSL_sk_zero.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/OPENSSL_sk_zero.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_strcasecmp.3ossl b/openssl-install/share/man/man3/OPENSSL_strcasecmp.3ossl deleted file mode 100644 index 70a90035..00000000 --- a/openssl-install/share/man/man3/OPENSSL_strcasecmp.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_STRCASECMP 3ossl" -.TH OPENSSL_STRCASECMP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_strcasecmp, OPENSSL_strncasecmp \- compare two strings ignoring case -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OPENSSL_strcasecmp(const char *s1, const char *s2); -\& int OPENSSL_strncasecmp(const char *s1, const char *s2, size_t n); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The OPENSSL_strcasecmp function performs a byte-by-byte comparison of the strings -\&\fBs1\fR and \fBs2\fR, ignoring the case of the characters. -.PP -The OPENSSL_strncasecmp function is similar, except that it compares no more than -\&\fBn\fR bytes of \fBs1\fR and \fBs2\fR. -.PP -In POSIX-compatible system and on Windows these functions use \*(L"C\*(R" locale for -case insensitive. Otherwise the comparison is done in current locale. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Both functions return an integer less than, equal to, or greater than zero if -s1 is found, respectively, to be less than, to match, or be greater than s2. -.SH "NOTES" -.IX Header "NOTES" -OpenSSL extensively uses case insensitive comparison of \s-1ASCII\s0 strings. Though -OpenSSL itself is locale-agnostic, the applications using OpenSSL libraries may -unpredictably suffer when they use localization (e.g. Turkish locale is -well-known with a specific I/i cases). These functions use C locale for string -comparison. -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OPENSSL_strdup.3ossl b/openssl-install/share/man/man3/OPENSSL_strdup.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_strdup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_strlcat.3ossl b/openssl-install/share/man/man3/OPENSSL_strlcat.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_strlcat.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_strlcpy.3ossl b/openssl-install/share/man/man3/OPENSSL_strlcpy.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_strlcpy.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_strncasecmp.3ossl b/openssl-install/share/man/man3/OPENSSL_strncasecmp.3ossl deleted file mode 120000 index 08153c11..00000000 --- a/openssl-install/share/man/man3/OPENSSL_strncasecmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_strcasecmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_strndup.3ossl b/openssl-install/share/man/man3/OPENSSL_strndup.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_strndup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_strtoul.3ossl b/openssl-install/share/man/man3/OPENSSL_strtoul.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_strtoul.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_thread_stop.3ossl b/openssl-install/share/man/man3/OPENSSL_thread_stop.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_thread_stop.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_thread_stop_ex.3ossl b/openssl-install/share/man/man3/OPENSSL_thread_stop_ex.3ossl deleted file mode 120000 index a05c22d5..00000000 --- a/openssl-install/share/man/man3/OPENSSL_thread_stop_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_init_crypto.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_version_build_metadata.3ossl b/openssl-install/share/man/man3/OPENSSL_version_build_metadata.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_version_build_metadata.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_version_major.3ossl b/openssl-install/share/man/man3/OPENSSL_version_major.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_version_major.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_version_minor.3ossl b/openssl-install/share/man/man3/OPENSSL_version_minor.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_version_minor.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_version_patch.3ossl b/openssl-install/share/man/man3/OPENSSL_version_patch.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_version_patch.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_version_pre_release.3ossl b/openssl-install/share/man/man3/OPENSSL_version_pre_release.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OPENSSL_version_pre_release.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OPENSSL_zalloc.3ossl b/openssl-install/share/man/man3/OPENSSL_zalloc.3ossl deleted file mode 120000 index e0ba6ca1..00000000 --- a/openssl-install/share/man/man3/OPENSSL_zalloc.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_malloc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ALGORITHM.3ossl b/openssl-install/share/man/man3/OSSL_ALGORITHM.3ossl deleted file mode 100644 index 3b003eba..00000000 --- a/openssl-install/share/man/man3/OSSL_ALGORITHM.3ossl +++ /dev/null @@ -1,260 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ALGORITHM 3ossl" -.TH OSSL_ALGORITHM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ALGORITHM \- OpenSSL Core type to define a fetchable algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_algorithm_st OSSL_ALGORITHM; -\& struct ossl_algorithm_st { -\& const char *algorithm_names; /* key */ -\& const char *property_definition; /* key */ -\& const OSSL_DISPATCH *implementation; -\& const char *algorithm_description; -\& }; -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1OSSL_ALGORITHM\s0\fR type is a \fIpublic structure\fR that describes an -algorithm that a \fBprovider\fR\|(7) provides. Arrays of this type are returned -by providers on demand from the OpenSSL libraries to describe what -algorithms the providers provide implementations of, and with what -properties. -.PP -Arrays of this type must be terminated with a tuple where \fIalgorithm_names\fR -is \s-1NULL.\s0 -.PP -This type of array is typically returned by the provider's operation querying -function, further described in \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7). -.SS "\fB\s-1OSSL_ALGORITHM\s0\fP fields" -.IX Subsection "OSSL_ALGORITHM fields" -.IP "\fIalgorithm_names\fR" 4 -.IX Item "algorithm_names" -This string is a colon separated set of names / identities, and is used by -the appropriate fetching functionality (such as \fBEVP_CIPHER_fetch\fR\|(3), -\&\fBEVP_MD_fetch\fR\|(3), etc) to find the desired algorithm. -.Sp -Multiple names / identities allow a specific algorithm implementation to be -fetched multiple ways. For example, the \s-1RSA\s0 algorithm has the following -known identities: -.RS 4 -.IP "\(bu" 4 -\&\f(CW\*(C`RSA\*(C'\fR -.IP "\(bu" 4 -\&\f(CW\*(C`rsaEncryption\*(C'\fR -.Sp -This is the name of the algorithm's \s-1OBJECT IDENTIFIER\s0 (\s-1OID\s0), as given by the -PKCS#1 \s-1RFC\s0's \s-1ASN.1\s0 module -.IP "\(bu" 4 -\&\f(CW1.2.840.113549.1.1.1\fR -.Sp -This is the \s-1OID\s0 itself for \f(CW\*(C`rsaEncryption\*(C'\fR, in canonical decimal text form. -.RE -.RS 4 -.Sp -The resulting \fIalgorithm_names\fR string would look like this: -.Sp -.Vb 1 -\& "RSA:rsaEncryption:1.2.840.113549.1.1.1" -.Ve -.Sp -The OpenSSL libraries use the first of the algorithm names as the main -or canonical name, on a per algorithm implementation basis. -.Sp -See the notes \*(L"On the subject of algorithm names\*(R" below for a more in -depth discussion on \fIalgorithm_names\fR and how that may interact with -applications and libraries, including OpenSSL's. -.RE -.IP "\fIproperty_definition\fR" 4 -.IX Item "property_definition" -This string defines a set of properties associated with a particular -algorithm implementation, and is used by the appropriate fetching -functionality (such as \fBEVP_CIPHER_fetch\fR\|(3), \fBEVP_MD_fetch\fR\|(3), etc) for -a finer grained lookup of an algorithm implementation, which is useful in -case multiple implementations of the same algorithm are available. -.Sp -See \fBproperty\fR\|(7) for a further description of the contents of this -string. -.IP "\fIimplementation\fR" 4 -.IX Item "implementation" -Pointer to an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) array, containing pointers to the -functions of a particular algorithm implementation. -.IP "\fIalgorithm_description\fR" 4 -.IX Item "algorithm_description" -A string with a short human-readable description of the algorithm. -.SH "NOTES" -.IX Header "NOTES" -.SS "On the subject of algorithm names" -.IX Subsection "On the subject of algorithm names" -Providers may find the need to register \s-1ASN.1\s0 OIDs for algorithms using -\&\fBOBJ_create\fR\|(3) (via the \fBcore_obj_create\fR upcall described in -\&\fBprovider\-base\fR\|(7), because some application or library \*(-- possibly still -the OpenSSL libraries, even \*(-- use NIDs to look up algorithms. -.PP -In that scenario, you must make sure that the corresponding \fB\s-1OSSL_ALGORITHM\s0\fR's -\&\fIalgorithm_names\fR includes both the short and the long name. -.PP -Most of the time, registering \s-1ASN.1\s0 OIDs like this shouldn't be necessary, -and applications and libraries are encouraged to use \fBOBJ_obj2txt\fR\|(3) to -get a text representation of the \s-1OID,\s0 which may be a long or short name for -OIDs that are registered, or the \s-1OID\s0 itself in canonical decimal text form -if not (or if \fBOBJ_obj2txt\fR\|(3) is called with \fIno_name\fR = 1). -.PP -It's recommended to make sure that the corresponding \fB\s-1OSSL_ALGORITHM\s0\fR's -\&\fIalgorithm_names\fR include known names as well as the \s-1OID\s0 itself in -canonical decimal text form. That should cover all scenarios. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBprovider\-base\fR\|(7), \fBopenssl\-core.h\fR\|(7), -\&\fBopenssl\-core_dispatch.h\fR\|(7), \s-1\fBOSSL_DISPATCH\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fB\s-1OSSL_ALGORITHM\s0\fR was added in OpenSSL 3.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_free.3ossl b/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_it.3ossl b/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_new.3ossl b/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_ATTRIBUTES_SYNTAX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_free.3ossl b/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_it.3ossl b/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_new.3ossl b/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_BASIC_ATTR_CONSTRAINTS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CALLBACK.3ossl b/openssl-install/share/man/man3/OSSL_CALLBACK.3ossl deleted file mode 100644 index 37cf90f2..00000000 --- a/openssl-install/share/man/man3/OSSL_CALLBACK.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CALLBACK 3ossl" -.TH OSSL_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CALLBACK, OSSL_PASSPHRASE_CALLBACK \- OpenSSL Core type to define callbacks -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 6 -\& #include -\& typedef int (OSSL_CALLBACK)(const OSSL_PARAM params[], void *arg); -\& typedef int (OSSL_PASSPHRASE_CALLBACK)(char *pass, size_t pass_size, -\& size_t *pass_len, -\& const OSSL_PARAM params[], -\& void *arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -For certain events or activities, provider functionality may need help from -the application or the calling OpenSSL libraries themselves. For example, -user input or direct (possibly optional) user output could be implemented -this way. -.PP -Callback functions themselves are always provided by or through the calling -OpenSSL libraries, along with a generic pointer to data \fIarg\fR. As far as -the function receiving the pointer to the function pointer and \fIarg\fR is -concerned, the data that \fIarg\fR points at is opaque, and the pointer should -simply be passed back to the callback function when it's called. -.IP "\fB\s-1OSSL_CALLBACK\s0\fR" 4 -.IX Item "OSSL_CALLBACK" -This is a generic callback function. When calling this callback function, -the caller is expected to build an \s-1\fBOSSL_PARAM\s0\fR\|(3) array of data it wants or -is expected to pass back, and pass that as \fIparams\fR, as well as the opaque -data pointer it received, as \fIarg\fR. -.IP "\fB\s-1OSSL_PASSPHRASE_CALLBACK\s0\fR" 4 -.IX Item "OSSL_PASSPHRASE_CALLBACK" -This is a specialised callback function, used specifically to prompt the -user for a passphrase. When calling this callback function, a buffer to -store the pass phrase needs to be given with \fIpass\fR, and its size with -\&\fIpass_size\fR. The length of the prompted pass phrase will be given back in -\&\fI*pass_len\fR. -.Sp -Additional parameters can be passed with the \s-1\fBOSSL_PARAM\s0\fR\|(3) array \fIparams\fR, -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core.h\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The types described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAVS.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAVS.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAVS.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAVS_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAVS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAVS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAVS_it.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAVS_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAVS_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAVS_new.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAVS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAVS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_create.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_create.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_free.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_algId.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_algId.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_algId.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_type.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_type.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_value.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_value.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get0_value.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get_rsaKeyLen.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_get_rsaKeyLen.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_get_rsaKeyLen.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_new_algId.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_new_algId.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_new_algId.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_new_rsaKeyLen.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_new_rsaKeyLen.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_new_rsaKeyLen.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_push1.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_push1.3ossl deleted file mode 120000 index ed5cb357..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_push1.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ATAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ATAV_set0.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ATAV_set0.3ossl deleted file mode 100644 index 31318df3..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ATAV_set0.3ossl +++ /dev/null @@ -1,248 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_ATAV_SET0 3ossl" -.TH OSSL_CMP_ATAV_SET0 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_ATAV, -OSSL_CMP_ATAV_create, -OSSL_CMP_ATAV_set0, -OSSL_CMP_ATAV_get0_type, -OSSL_CMP_ATAV_get0_value, -OSSL_CMP_ATAV_new_algId, -OSSL_CMP_ATAV_get0_algId, -OSSL_CMP_ATAV_new_rsaKeyLen, -OSSL_CMP_ATAV_get_rsaKeyLen, -OSSL_CMP_ATAVS, -OSSL_CMP_ATAV_push1, -OSSL_CMP_ATAV_free -\&\- OSSL_CMP_ATAV utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef OSSL_CRMF_ATTRIBUTETYPEANDVALUE OSSL_CMP_ATAV; -\& OSSL_CMP_ATAV *OSSL_CMP_ATAV_create(ASN1_OBJECT *type, ASN1_TYPE *value); -\& void OSSL_CMP_ATAV_set0(OSSL_CMP_ATAV *atav, ASN1_OBJECT *type, -\& ASN1_TYPE *value); -\& ASN1_OBJECT *OSSL_CMP_ATAV_get0_type(const OSSL_CMP_ATAV *atav); -\& ASN1_TYPE *OSSL_CMP_ATAV_get0_value(const OSSL_CMP_ATAV *atav); -\& -\& OSSL_CMP_ATAV *OSSL_CMP_ATAV_new_algId(const X509_ALGOR *alg); -\& X509_ALGOR *OSSL_CMP_ATAV_get0_algId(const OSSL_CMP_ATAV *atav); -\& OSSL_CMP_ATAV *OSSL_CMP_ATAV_new_rsaKeyLen(int len); -\& int OSSL_CMP_ATAV_get_rsaKeyLen(const OSSL_CMP_ATAV *atav); -\& -\& typedef STACK_OF(OSSL_CRMF_ATTRIBUTETYPEANDVALUE) OSSL_CMP_ATAVS; -\& int OSSL_CMP_ATAV_push1(OSSL_CMP_ATAVS **sk_p, const OSSL_CMP_ATAV *atav); -\& void OSSL_CMP_ATAV_free(OSSL_CMP_ATAV *atav); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_CMP_ATAV\s0\fR is a short hand of \fB\s-1OSSL_CRMF_ATTRIBUTETYPEANDVALUE\s0\fR, -defined in \s-1RFC 4211\s0 Appendix B. -It is typically used in CertRequest structures, -but also in CertReqTemplateContent structures for key specifications. -.PP -\&\fBOSSL_CMP_ATAV_create()\fR creates a new \fB\s-1OSSL_CMP_ATAV\s0\fR structure and fills it in. -It combines \fBOSSL_CMP_ATAV_new()\fR and \fBOSSL_CMP_ATAV_set0()\fR. -.PP -\&\fBOSSL_CMP_ATAV_set0()\fR sets the \fIatav\fR with an infoType of \fItype\fR and an -infoValue of \fIvalue\fR. -The pointers \fItype\fR and \fIvalue\fR may be \s-1NULL,\s0 otherwise -they must \fBnot\fR be freed up after the call because their ownership -is transferred to \fIatav\fR. The \fIitav\fR pointer must not be \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ATAV_get0_type()\fR returns a direct pointer to the infoType -in the \fIatav\fR unless it is \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ATAV_get0_value()\fR returns a direct pointer to the infoValue -in the \fIatav\fR as generic \fB\s-1ASN1_TYPE\s0\fR pointer unless \fIatav\fR is \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ATAV_new_algId()\fR creates a new \fB\s-1OSSL_CMP_ATAV\s0\fR structure of type -\&\fBalgId\fR and fills it in with a copy of the given \fIalg\fR. -.PP -\&\fBOSSL_CMP_ATAV_get0_algId()\fR returns -a direct pointer to the algId infoValue in the \fIatav\fR of type \fBX509_ALGOR\fR -or \s-1NULL\s0 if \fIatav\fR is \s-1NULL\s0 or does not contain an algId. -.PP -\&\fBOSSL_CMP_ATAV_new_rsaKeyLen()\fR creates a new \fB\s-1OSSL_CMP_ATAV\s0\fR structure of type -\&\fBrsaKeyLen\fR and fills it in with the given \fIlen\fR, which must be positive. -.PP -\&\fBOSSL_CMP_ATAV_get_rsaKeyLen()\fR returns -the \s-1RSA\s0 key length in rsaKeyLen infoValue in the \fIatav\fR, -\&\-1 if \fIatav\fR is \s-1NULL\s0 or does not contain an rsaKeyLen or cannot be parsed, -or \-2 if the value is less than 1 or is greater than \s-1INT_MAX.\s0 -.PP -\&\fBOSSL_CMP_ATAV_push1()\fR pushes a copy of \fIatav\fR to the stack of \fB\s-1OSSL_CMP_ATAV\s0\fR -pointed to by \fI*sk_p\fR. It creates a new stack if \fI*sk_p\fR points to \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ATAV_free()\fR deallocates \fIatav\fR. It is defined as a macro. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210. CRMF\s0 is defined in \s-1RFC 4211.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_ATAV_create()\fR, -\&\fBOSSL_CMP_ATAV_new_algId()\fR, and \fBOSSL_CMP_ATAV_new_rsaKeyLen()\fR -return a pointer to the \s-1ATAV\s0 structure on success, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_ATAV_set0()\fR and \fBOSSL_CMP_ATAV_free()\fR do not return a value. -.PP -\&\fBOSSL_CMP_ATAV_get0_type()\fR, \fBOSSL_CMP_ATAV_get0_value()\fR, and -\&\fBOSSL_CMP_ATAV_get0_algId()\fR -return the respective pointer or \s-1NULL\s0 if their input is \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ATAV_get_rsaKeyLen()\fR return a key length in bits or < 0 on error. -.PP -\&\fBOSSL_CMP_ATAV_push1()\fR returns 1 on success, 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_ITAV_new0_certReqTemplate\fR\|(3), \fBASN1_TYPE_set\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fB\s-1OSSL_CMP_ATAV\s0\fR type and related functions were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_CR.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CR.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_create.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_create.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_get0.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_get0.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_new1.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_new1.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CRLSTATUS_new1.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_build_cert_chain.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_build_cert_chain.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_build_cert_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_free.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_geninfo_ITAVs.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_geninfo_ITAVs.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_geninfo_ITAVs.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_libctx.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_libctx.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_libctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newCert.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newCert.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newCert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newPkey.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newPkey.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_newPkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_propq.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_propq.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_propq.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_statusString.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_statusString.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_statusString.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trusted.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trusted.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trusted.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trustedStore.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trustedStore.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_trustedStore.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_untrusted.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_untrusted.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_untrusted.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_validatedSrvCert.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_validatedSrvCert.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get0_validatedSrvCert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_caPubs.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_caPubs.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_caPubs.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_extraCertsIn.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_extraCertsIn.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_extraCertsIn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_newChain.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_newChain.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get1_newChain.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_certConf_cb_arg.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get_certConf_cb_arg.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_certConf_cb_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_failInfoCode.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get_failInfoCode.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_failInfoCode.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_http_cb_arg.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get_http_cb_arg.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_http_cb_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_option.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get_option.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_option.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_status.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get_status.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_transfer_cb_arg.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_get_transfer_cb_arg.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_get_transfer_cb_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_new.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_new.3ossl deleted file mode 100644 index cbf24237..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_new.3ossl +++ /dev/null @@ -1,1039 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_CTX_NEW 3ossl" -.TH OSSL_CMP_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_CTX_new, -OSSL_CMP_CTX_free, -OSSL_CMP_CTX_reinit, -OSSL_CMP_CTX_get0_libctx, OSSL_CMP_CTX_get0_propq, -OSSL_CMP_CTX_set_option, -OSSL_CMP_CTX_get_option, -OSSL_CMP_CTX_set_log_cb, -OSSL_CMP_CTX_set_log_verbosity, -OSSL_CMP_CTX_print_errors, -OSSL_CMP_CTX_set1_serverPath, -OSSL_CMP_CTX_set1_server, -OSSL_CMP_CTX_set_serverPort, -OSSL_CMP_CTX_set1_proxy, -OSSL_CMP_CTX_set1_no_proxy, -OSSL_CMP_CTX_set_http_cb, -OSSL_CMP_CTX_set_http_cb_arg, -OSSL_CMP_CTX_get_http_cb_arg, -OSSL_CMP_transfer_cb_t, -OSSL_CMP_CTX_set_transfer_cb, -OSSL_CMP_CTX_set_transfer_cb_arg, -OSSL_CMP_CTX_get_transfer_cb_arg, -OSSL_CMP_CTX_set1_srvCert, -OSSL_CMP_CTX_set1_expected_sender, -OSSL_CMP_CTX_set0_trusted, -OSSL_CMP_CTX_set0_trustedStore, -OSSL_CMP_CTX_get0_trusted, -OSSL_CMP_CTX_get0_trustedStore, -OSSL_CMP_CTX_set1_untrusted, -OSSL_CMP_CTX_get0_untrusted, -OSSL_CMP_CTX_set1_cert, -OSSL_CMP_CTX_build_cert_chain, -OSSL_CMP_CTX_set1_pkey, -OSSL_CMP_CTX_set1_referenceValue, -OSSL_CMP_CTX_set1_secretValue, -OSSL_CMP_CTX_set1_recipient, -OSSL_CMP_CTX_push0_geninfo_ITAV, -OSSL_CMP_CTX_reset_geninfo_ITAVs, -OSSL_CMP_CTX_get0_geninfo_ITAVs, -OSSL_CMP_CTX_set1_extraCertsOut, -OSSL_CMP_CTX_set0_newPkey, -OSSL_CMP_CTX_get0_newPkey, -OSSL_CMP_CTX_set1_issuer, -OSSL_CMP_CTX_set1_serialNumber, -OSSL_CMP_CTX_set1_subjectName, -OSSL_CMP_CTX_push1_subjectAltName, -OSSL_CMP_CTX_set0_reqExtensions, -OSSL_CMP_CTX_reqExtensions_have_SAN, -OSSL_CMP_CTX_push0_policy, -OSSL_CMP_CTX_set1_oldCert, -OSSL_CMP_CTX_set1_p10CSR, -OSSL_CMP_CTX_push0_genm_ITAV, -OSSL_CMP_certConf_cb_t, -OSSL_CMP_certConf_cb, -OSSL_CMP_CTX_set_certConf_cb, -OSSL_CMP_CTX_set_certConf_cb_arg, -OSSL_CMP_CTX_get_certConf_cb_arg, -OSSL_CMP_CTX_get_status, -OSSL_CMP_CTX_get0_statusString, -OSSL_CMP_CTX_get_failInfoCode, -OSSL_CMP_CTX_get0_validatedSrvCert, -OSSL_CMP_CTX_get0_newCert, -OSSL_CMP_CTX_get1_newChain, -OSSL_CMP_CTX_get1_caPubs, -OSSL_CMP_CTX_get1_extraCertsIn, -OSSL_CMP_CTX_set1_transactionID, -OSSL_CMP_CTX_set1_senderNonce -\&\- functions for managing the CMP client context data structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CMP_CTX *OSSL_CMP_CTX_new(OSSL_LIB_CTX *libctx, const char *propq); -\& void OSSL_CMP_CTX_free(OSSL_CMP_CTX *ctx); -\& int OSSL_CMP_CTX_reinit(OSSL_CMP_CTX *ctx); -\& OSSL_LIB_CTX *OSSL_CMP_CTX_get0_libctx(const OSSL_CMP_CTX *ctx); -\& const char *OSSL_CMP_CTX_get0_propq(const OSSL_CMP_CTX *ctx); -\& int OSSL_CMP_CTX_set_option(OSSL_CMP_CTX *ctx, int opt, int val); -\& int OSSL_CMP_CTX_get_option(const OSSL_CMP_CTX *ctx, int opt); -\& -\& /* logging and error reporting: */ -\& int OSSL_CMP_CTX_set_log_cb(OSSL_CMP_CTX *ctx, OSSL_CMP_log_cb_t cb); -\& #define OSSL_CMP_CTX_set_log_verbosity(ctx, level) -\& void OSSL_CMP_CTX_print_errors(const OSSL_CMP_CTX *ctx); -\& -\& /* message transfer: */ -\& int OSSL_CMP_CTX_set1_serverPath(OSSL_CMP_CTX *ctx, const char *path); -\& int OSSL_CMP_CTX_set1_server(OSSL_CMP_CTX *ctx, const char *address); -\& int OSSL_CMP_CTX_set_serverPort(OSSL_CMP_CTX *ctx, int port); -\& int OSSL_CMP_CTX_set1_proxy(OSSL_CMP_CTX *ctx, const char *name); -\& int OSSL_CMP_CTX_set1_no_proxy(OSSL_CMP_CTX *ctx, const char *names); -\& int OSSL_CMP_CTX_set_http_cb(OSSL_CMP_CTX *ctx, HTTP_bio_cb_t cb); -\& int OSSL_CMP_CTX_set_http_cb_arg(OSSL_CMP_CTX *ctx, void *arg); -\& void *OSSL_CMP_CTX_get_http_cb_arg(const OSSL_CMP_CTX *ctx); -\& typedef OSSL_CMP_MSG *(*OSSL_CMP_transfer_cb_t)(OSSL_CMP_CTX *ctx, -\& const OSSL_CMP_MSG *req); -\& int OSSL_CMP_CTX_set_transfer_cb(OSSL_CMP_CTX *ctx, -\& OSSL_CMP_transfer_cb_t cb); -\& int OSSL_CMP_CTX_set_transfer_cb_arg(OSSL_CMP_CTX *ctx, void *arg); -\& void *OSSL_CMP_CTX_get_transfer_cb_arg(const OSSL_CMP_CTX *ctx); -\& -\& /* server authentication: */ -\& int OSSL_CMP_CTX_set1_srvCert(OSSL_CMP_CTX *ctx, X509 *cert); -\& int OSSL_CMP_CTX_set1_expected_sender(OSSL_CMP_CTX *ctx, -\& const X509_NAME *name); -\& #define OSSL_CMP_CTX_set0_trusted OSSL_CMP_CTX_set0_trustedStore -\& int OSSL_CMP_CTX_set0_trustedStore(OSSL_CMP_CTX *ctx, X509_STORE *store); -\& #define OSSL_CMP_CTX_get0_trusted OSSL_CMP_CTX_get0_trustedStore -\& X509_STORE *OSSL_CMP_CTX_get0_trustedStore(const OSSL_CMP_CTX *ctx); -\& int OSSL_CMP_CTX_set1_untrusted(OSSL_CMP_CTX *ctx, STACK_OF(X509) *certs); -\& STACK_OF(X509) *OSSL_CMP_CTX_get0_untrusted(const OSSL_CMP_CTX *ctx); -\& -\& /* client authentication: */ -\& int OSSL_CMP_CTX_set1_cert(OSSL_CMP_CTX *ctx, X509 *cert); -\& int OSSL_CMP_CTX_build_cert_chain(OSSL_CMP_CTX *ctx, X509_STORE *own_trusted, -\& STACK_OF(X509) *candidates); -\& int OSSL_CMP_CTX_set1_pkey(OSSL_CMP_CTX *ctx, EVP_PKEY *pkey); -\& int OSSL_CMP_CTX_set1_referenceValue(OSSL_CMP_CTX *ctx, -\& const unsigned char *ref, int len); -\& int OSSL_CMP_CTX_set1_secretValue(OSSL_CMP_CTX *ctx, -\& const unsigned char *sec, int len); -\& -\& /* CMP message header and extra certificates: */ -\& int OSSL_CMP_CTX_set1_recipient(OSSL_CMP_CTX *ctx, const X509_NAME *name); -\& int OSSL_CMP_CTX_push0_geninfo_ITAV(OSSL_CMP_CTX *ctx, OSSL_CMP_ITAV *itav); -\& int OSSL_CMP_CTX_reset_geninfo_ITAVs(OSSL_CMP_CTX *ctx); -\& STACK_OF(OSSL_CMP_ITAV) -\& *OSSL_CMP_CTX_get0_geninfo_ITAVs(const OSSL_CMP_CTX *ctx); -\& int OSSL_CMP_CTX_set1_extraCertsOut(OSSL_CMP_CTX *ctx, -\& STACK_OF(X509) *extraCertsOut); -\& -\& /* certificate template: */ -\& int OSSL_CMP_CTX_set0_newPkey(OSSL_CMP_CTX *ctx, int priv, EVP_PKEY *pkey); -\& EVP_PKEY *OSSL_CMP_CTX_get0_newPkey(const OSSL_CMP_CTX *ctx, int priv); -\& int OSSL_CMP_CTX_set1_issuer(OSSL_CMP_CTX *ctx, const X509_NAME *name); -\& int OSSL_CMP_CTX_set1_serialNumber(OSSL_CMP_CTX *ctx, const ASN1_INTEGER *sn); -\& int OSSL_CMP_CTX_set1_subjectName(OSSL_CMP_CTX *ctx, const X509_NAME *name); -\& int OSSL_CMP_CTX_push1_subjectAltName(OSSL_CMP_CTX *ctx, -\& const GENERAL_NAME *name); -\& int OSSL_CMP_CTX_set0_reqExtensions(OSSL_CMP_CTX *ctx, X509_EXTENSIONS *exts); -\& int OSSL_CMP_CTX_reqExtensions_have_SAN(OSSL_CMP_CTX *ctx); -\& int OSSL_CMP_CTX_push0_policy(OSSL_CMP_CTX *ctx, POLICYINFO *pinfo); -\& int OSSL_CMP_CTX_set1_oldCert(OSSL_CMP_CTX *ctx, X509 *cert); -\& int OSSL_CMP_CTX_set1_p10CSR(OSSL_CMP_CTX *ctx, const X509_REQ *csr); -\& -\& /* misc body contents: */ -\& int OSSL_CMP_CTX_push0_genm_ITAV(OSSL_CMP_CTX *ctx, OSSL_CMP_ITAV *itav); -\& -\& /* certificate confirmation: */ -\& typedef int (*OSSL_CMP_certConf_cb_t)(OSSL_CMP_CTX *ctx, X509 *cert, -\& int fail_info, const char **txt); -\& int OSSL_CMP_certConf_cb(OSSL_CMP_CTX *ctx, X509 *cert, int fail_info, -\& const char **text); -\& int OSSL_CMP_CTX_set_certConf_cb(OSSL_CMP_CTX *ctx, OSSL_CMP_certConf_cb_t cb); -\& int OSSL_CMP_CTX_set_certConf_cb_arg(OSSL_CMP_CTX *ctx, void *arg); -\& void *OSSL_CMP_CTX_get_certConf_cb_arg(const OSSL_CMP_CTX *ctx); -\& -\& /* result fetching: */ -\& int OSSL_CMP_CTX_get_status(const OSSL_CMP_CTX *ctx); -\& OSSL_CMP_PKIFREETEXT *OSSL_CMP_CTX_get0_statusString(const OSSL_CMP_CTX *ctx); -\& int OSSL_CMP_CTX_get_failInfoCode(const OSSL_CMP_CTX *ctx); -\& -\& X509 *OSSL_CMP_CTX_get0_validatedSrvCert(const OSSL_CMP_CTX *ctx); -\& X509 *OSSL_CMP_CTX_get0_newCert(const OSSL_CMP_CTX *ctx); -\& STACK_OF(X509) *OSSL_CMP_CTX_get1_newChain(const OSSL_CMP_CTX *ctx); -\& STACK_OF(X509) *OSSL_CMP_CTX_get1_caPubs(const OSSL_CMP_CTX *ctx); -\& STACK_OF(X509) *OSSL_CMP_CTX_get1_extraCertsIn(const OSSL_CMP_CTX *ctx); -\& -\& /* for testing and debugging purposes: */ -\& int OSSL_CMP_CTX_set1_transactionID(OSSL_CMP_CTX *ctx, -\& const ASN1_OCTET_STRING *id); -\& int OSSL_CMP_CTX_set1_senderNonce(OSSL_CMP_CTX *ctx, -\& const ASN1_OCTET_STRING *nonce); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This is the context \s-1API\s0 for using \s-1CMP\s0 (Certificate Management Protocol) with -OpenSSL. -.PP -\&\fBOSSL_CMP_CTX_new()\fR allocates an \fB\s-1OSSL_CMP_CTX\s0\fR structure associated with -the library context \fIlibctx\fR and property query string \fIpropq\fR, -both of which may be \s-1NULL\s0 to select the defaults. -It initializes the remaining fields to their default values \- for instance, -the logging verbosity is set to \s-1OSSL_CMP_LOG_INFO,\s0 -the message timeout is set to 120 seconds, -and the proof-of-possession method is set to \s-1OSSL_CRMF_POPO_SIGNATURE.\s0 -.PP -\&\fBOSSL_CMP_CTX_free()\fR deallocates an \s-1OSSL_CMP_CTX\s0 structure. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_CMP_CTX_reinit()\fR prepares the given \fIctx\fR for a further transaction by -clearing the internal \s-1CMP\s0 transaction (aka session) status, PKIStatusInfo, -and any previous results (newCert, newChain, caPubs, and extraCertsIn) -from the last executed transaction. -It also clears any ITAVs that were added by \fBOSSL_CMP_CTX_push0_genm_ITAV()\fR. -All other field values (i.e., \s-1CMP\s0 options) are retained for potential reuse. -.PP -\&\fBOSSL_CMP_CTX_get0_libctx()\fR returns the \fIlibctx\fR argument that was used -when constructing \fIctx\fR with \fBOSSL_CMP_CTX_new()\fR, which may be \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_CTX_get0_propq()\fR returns the \fIpropq\fR argument that was used -when constructing \fIctx\fR with \fBOSSL_CMP_CTX_new()\fR, which may be \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_CTX_set_option()\fR sets the given value for the given option -(e.g., \s-1OSSL_CMP_OPT_IMPLICIT_CONFIRM\s0) in the given \s-1OSSL_CMP_CTX\s0 structure. -.PP -The following options can be set: -.IP "\fB\s-1OSSL_CMP_OPT_LOG_VERBOSITY\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_LOG_VERBOSITY" -.Vb 3 -\& The level of severity needed for actually outputting log messages -\& due to errors, warnings, general info, debugging, etc. -\& Default is OSSL_CMP_LOG_INFO. See also L. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_KEEP_ALIVE\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_KEEP_ALIVE" -.Vb 6 -\& If the given value is 0 then HTTP connections are not kept open -\& after receiving a response, which is the default behavior for HTTP 1.0. -\& If the value is 1 or 2 then persistent connections are requested. -\& If the value is 2 then persistent connections are required, -\& i.e., in case the server does not grant them an error occurs. -\& The default value is 1: prefer to keep the connection open. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_MSG_TIMEOUT\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_MSG_TIMEOUT" -.Vb 4 -\& Number of seconds a CMP request\-response message round trip -\& is allowed to take before a timeout error is returned. -\& A value <= 0 means no limitation (waiting indefinitely). -\& Default is to use the B setting. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_TOTAL_TIMEOUT\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_TOTAL_TIMEOUT" -.Vb 4 -\& Maximum total number of seconds a transaction may take, -\& including polling etc. -\& A value <= 0 means no limitation (waiting indefinitely). -\& Default is 0. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_USE_TLS\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_USE_TLS" -.Vb 8 -\& Use this option to indicate to the HTTP implementation -\& whether TLS is going to be used for the connection (resulting in HTTPS). -\& The value 1 indicates that TLS is used for client\-side HTTP connections, -\& which needs to be implemented via a callback function set by -\& OSSL_CMP_CTX_set_http_cb(). -\& The value 0 indicates that TLS is not used. -\& Default is \-1 for backward compatibility: TLS is used by the client side -\& if and only if OSSL_CMP_CTX_set_http_cb_arg() sets a non\-NULL I. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_VALIDITY_DAYS\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_VALIDITY_DAYS" -.Vb 1 -\& Number of days new certificates are asked to be valid for. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT" -.Vb 2 -\& Do not take default Subject Alternative Names -\& from the reference certificate. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_SUBJECTALTNAME_CRITICAL\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_SUBJECTALTNAME_CRITICAL" -.Vb 1 -\& Demand that the given Subject Alternative Names are flagged as critical. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_POLICIES_CRITICAL\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_POLICIES_CRITICAL" -.Vb 1 -\& Demand that the given policies are flagged as critical. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_POPO_METHOD\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_POPO_METHOD" -.Vb 1 -\& Select the proof of possession method to use. Possible values are: -\& -\& OSSL_CRMF_POPO_NONE \- ProofOfPossession field omitted -\& OSSL_CRMF_POPO_RAVERIFIED \- assert that the RA has already -\& verified the PoPo -\& OSSL_CRMF_POPO_SIGNATURE \- sign a value with private key, -\& which is the default. -\& OSSL_CRMF_POPO_KEYENC \- decrypt the encrypted certificate -\& ("indirect method") -\& -\& Note that a signature\-based POPO can only be produced if a private key -\& is provided as the newPkey or client\*(Aqs pkey component of the CMP context. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_DIGEST_ALGNID\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_DIGEST_ALGNID" -.Vb 3 -\& The NID of the digest algorithm to be used in RFC 4210\*(Aqs MSG_SIG_ALG -\& for signature\-based message protection and Proof\-of\-Possession (POPO). -\& Default is SHA256. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_OWF_ALGNID\s0\fR The \s-1NID\s0 of the digest algorithm to be used as one-way function (\s-1OWF\s0) for MAC-based message protection with password-based \s-1MAC\s0 (\s-1PBM\s0). See \s-1RFC 4210\s0 section 5.1.3.1 for details. Default is \s-1SHA256.\s0" 4 -.IX Item "OSSL_CMP_OPT_OWF_ALGNID The NID of the digest algorithm to be used as one-way function (OWF) for MAC-based message protection with password-based MAC (PBM). See RFC 4210 section 5.1.3.1 for details. Default is SHA256." -.PD 0 -.IP "\fB\s-1OSSL_CMP_OPT_MAC_ALGNID\s0\fR The \s-1NID\s0 of the \s-1MAC\s0 algorithm to be used for message protection with \s-1PBM.\s0 Default is \s-1HMAC\-SHA1\s0 as per \s-1RFC 4210.\s0" 4 -.IX Item "OSSL_CMP_OPT_MAC_ALGNID The NID of the MAC algorithm to be used for message protection with PBM. Default is HMAC-SHA1 as per RFC 4210." -.IP "\fB\s-1OSSL_CMP_OPT_REVOCATION_REASON\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_REVOCATION_REASON" -.PD -.Vb 2 -\& The reason code to be included in a Revocation Request (RR); -\& values: 0..10 (RFC 5210, 5.3.1) or \-1 for none, which is the default. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_IMPLICIT_CONFIRM\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_IMPLICIT_CONFIRM" -.Vb 4 -\& Request server to enable implicit confirm mode, where the client -\& does not need to send confirmation upon receiving the -\& certificate. If the server does not enable implicit confirmation -\& in the return message, then confirmation is sent anyway. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_DISABLE_CONFIRM\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_DISABLE_CONFIRM" -.Vb 5 -\& Do not confirm enrolled certificates, to cope with broken servers -\& not supporting implicit confirmation correctly. -\&B This setting leads to unspecified behavior and it is meant -\&exclusively to allow interoperability with server implementations violating -\&RFC 4210. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_UNPROTECTED_SEND\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_UNPROTECTED_SEND" -.Vb 1 -\& Send request or response messages without CMP\-level protection. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_UNPROTECTED_ERRORS\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_UNPROTECTED_ERRORS" -.Vb 7 -\& Accept unprotected error responses which are either explicitly -\& unprotected or where protection verification failed. Applies to regular -\& error messages as well as certificate responses (IP/CP/KUP) and -\& revocation responses (RP) with rejection. -\&B This setting leads to unspecified behavior and it is meant -\&exclusively to allow interoperability with server implementations violating -\&RFC 4210. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_IGNORE_KEYUSAGE\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_IGNORE_KEYUSAGE" -.Vb 3 -\& Ignore key usage restrictions in the signer\*(Aqs certificate when -\& validating signature\-based protection in received CMP messages. -\& Else, \*(AqdigitalSignature\*(Aq must be allowed by CMP signer certificates. -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR" -.Vb 3 -\& Allow retrieving a trust anchor from extraCerts and using that -\& to validate the certificate chain of an IP message. -\& This is a quirk option added to support 3GPP TS 33.310. -\& -\& Note that using this option is dangerous as the certificate obtained -\& this way has not been authenticated (at least not at CMP level). -\& Taking it over as a trust anchor implements trust\-on\-first\-use (TOFU). -.Ve -.IP "\fB\s-1OSSL_CMP_OPT_NO_CACHE_EXTRACERTS\s0\fR" 4 -.IX Item "OSSL_CMP_OPT_NO_CACHE_EXTRACERTS" -.Vb 2 -\& Do not cache certificates received in the extraCerts CMP message field. -\& Otherwise they are stored to potentially help validate further messages. -.Ve -.PP -\&\fBOSSL_CMP_CTX_get_option()\fR reads the current value of the given option -(e.g., \s-1OSSL_CMP_OPT_IMPLICIT_CONFIRM\s0) from the given \s-1OSSL_CMP_CTX\s0 structure. -.PP -\&\fBOSSL_CMP_CTX_set_log_cb()\fR sets in \fIctx\fR the callback function \fIcb\fR -for handling error queue entries and logging messages. -When \fIcb\fR is \s-1NULL\s0 errors are printed to \s-1STDERR\s0 (if available, else ignored) -any log messages are ignored. -Alternatively, \fBOSSL_CMP_log_open\fR\|(3) may be used to direct logging to \s-1STDOUT.\s0 -.PP -\&\fBOSSL_CMP_CTX_set_log_verbosity()\fR is a macro setting the -\&\s-1OSSL_CMP_OPT_LOG_VERBOSITY\s0 context option to the given level. -.PP -\&\fBOSSL_CMP_CTX_print_errors()\fR outputs any entries in the OpenSSL error queue. It -is similar to \fBERR_print_errors_cb\fR\|(3) but uses the \s-1CMP\s0 log callback function -if set in the \fIctx\fR for uniformity with \s-1CMP\s0 logging if given. Otherwise it uses -\&\fBERR_print_errors\fR\|(3) to print to \s-1STDERR\s0 (unless \s-1OPENSSL_NO_STDIO\s0 is defined). -.PP -\&\fBOSSL_CMP_CTX_set1_serverPath()\fR sets the \s-1HTTP\s0 path of the \s-1CMP\s0 server on the host, -also known as \*(L"\s-1CMP\s0 alias\*(R". -The default is \f(CW\*(C`/\*(C'\fR. -.PP -\&\fBOSSL_CMP_CTX_set1_server()\fR sets the given server \fIaddress\fR -(which may be a hostname or \s-1IP\s0 address or \s-1NULL\s0) in the given \fIctx\fR. -.PP -\&\fBOSSL_CMP_CTX_set_serverPort()\fR sets the port of the \s-1CMP\s0 server to connect to. -If not used or the \fIport\fR argument is 0 -the default port applies, which is 80 for \s-1HTTP\s0 and 443 for \s-1HTTPS.\s0 -.PP -\&\fBOSSL_CMP_CTX_set1_proxy()\fR sets the \s-1HTTP\s0 proxy to be used for connecting to -the given \s-1CMP\s0 server unless overruled by any \*(L"no_proxy\*(R" settings (see below). -If \s-1TLS\s0 is not used this defaults to the value of -the environment variable \f(CW\*(C`http_proxy\*(C'\fR if set, else \f(CW\*(C`HTTP_PROXY\*(C'\fR. -Otherwise defaults to the value of \f(CW\*(C`https_proxy\*(C'\fR if set, else \f(CW\*(C`HTTPS_PROXY\*(C'\fR. -An empty proxy string specifies not to use a proxy. -Otherwise the format is -\&\f(CW\*(C`[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\*(C'\fR, -where any given userinfo, path, query, and fragment is ignored. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -The default port number is 80, or 443 in case \f(CW\*(C`https:\*(C'\fR is given. -.PP -\&\fBOSSL_CMP_CTX_set1_no_proxy()\fR sets the list of server hostnames not to use -an \s-1HTTP\s0 proxy for. The names may be separated by commas and/or whitespace. -Defaults to the environment variable \f(CW\*(C`no_proxy\*(C'\fR if set, else \f(CW\*(C`NO_PROXY\*(C'\fR. -.PP -\&\fBOSSL_CMP_CTX_set_http_cb()\fR sets the optional \s-1BIO\s0 connect/disconnect callback -function, which has the prototype -.PP -.Vb 1 -\& typedef BIO *(*HTTP_bio_cb_t) (BIO *bio, void *arg, int connect, int detail); -.Ve -.PP -The callback may modify the \fIbio\fR provided by \fBOSSL_CMP_MSG_http_perform\fR\|(3) -as described for the \fIbio_update_fn\fR parameter of \fBOSSL_HTTP_open\fR\|(3). -The callback may make use of a custom defined argument \fIarg\fR, -as described for the \fIarg\fR parameter of \fBOSSL_HTTP_open\fR\|(3). -The argument is stored in the \s-1OSSL_CMP_CTX\s0 using \fBOSSL_CMP_CTX_set_http_cb_arg()\fR. -See also the \fB\s-1OSSL_CMP_OPT_USE_TLS\s0\fR option described above. -.PP -\&\fBOSSL_CMP_CTX_set_http_cb_arg()\fR sets the argument, respectively a pointer to -a structure containing arguments such as an \fB\s-1SSL_CTX\s0\fR structure, -optionally to be used by the http connect/disconnect callback function. -\&\fIarg\fR is not consumed, and it must therefore explicitly be freed when not -needed any more. \fIarg\fR may be \s-1NULL\s0 to clear the entry. -.PP -\&\fBOSSL_CMP_CTX_get_http_cb_arg()\fR gets the argument, respectively the pointer to a -structure containing arguments, previously set by -\&\fBOSSL_CMP_CTX_set_http_cb_arg()\fR or \s-1NULL\s0 if unset. -.PP -\&\fBOSSL_CMP_CTX_set_transfer_cb()\fR sets the message transfer callback function, -which has the type -.PP -.Vb 2 -\& typedef OSSL_CMP_MSG *(*OSSL_CMP_transfer_cb_t) (OSSL_CMP_CTX *ctx, -\& const OSSL_CMP_MSG *req); -.Ve -.PP -Default is \s-1NULL,\s0 which implies the use of \fBOSSL_CMP_MSG_http_perform\fR\|(3). -The callback should send the \s-1CMP\s0 request message it obtains via the \fIreq\fR -parameter and on success return the response, else it must return \s-1NULL.\s0 -The transfer callback may make use of a custom defined argument stored in -the ctx by means of \fBOSSL_CMP_CTX_set_transfer_cb_arg()\fR, which may be retrieved -again through \fBOSSL_CMP_CTX_get_transfer_cb_arg()\fR. -.PP -\&\fBOSSL_CMP_CTX_set_transfer_cb_arg()\fR sets an argument, respectively a pointer to a -structure containing arguments, optionally to be used by the transfer callback. -\&\fIarg\fR is not consumed, and it must therefore explicitly be freed when not -needed any more. \fIarg\fR may be \s-1NULL\s0 to clear the entry. -.PP -\&\fBOSSL_CMP_CTX_get_transfer_cb_arg()\fR gets the argument, respectively the pointer -to a structure containing arguments, previously set by -\&\fBOSSL_CMP_CTX_set_transfer_cb_arg()\fR or \s-1NULL\s0 if unset. -.PP -\&\fBOSSL_CMP_CTX_set1_srvCert()\fR sets the expected server cert in \fIctx\fR and trusts -it directly (even if it is expired) when verifying signed response messages. -This pins the accepted \s-1CMP\s0 server -and results in ignoring whatever may be set using \fBOSSL_CMP_CTX_set0_trusted()\fR. -Any previously set value is freed. -The \fIcert\fR argument may be \s-1NULL\s0 to clear the entry. -If set, the subject of the certificate is also used -as default value for the recipient of \s-1CMP\s0 requests -and as default value for the expected sender of \s-1CMP\s0 responses. -.PP -\&\fBOSSL_CMP_CTX_set1_expected_sender()\fR sets the Distinguished Name (\s-1DN\s0) -expected in the sender field of incoming \s-1CMP\s0 messages. -Defaults to the subject of the pinned server certificate, if any. -This can be used to make sure that only a particular entity is accepted as -\&\s-1CMP\s0 message signer, and attackers are not able to use arbitrary certificates -of a trusted \s-1PKI\s0 hierarchy to fraudulently pose as \s-1CMP\s0 server. -Note that this gives slightly more freedom than \fBOSSL_CMP_CTX_set1_srvCert()\fR, -which pins the server to the holder of a particular certificate, while the -expected sender name will continue to match after updates of the server cert. -.PP -\&\fBOSSL_CMP_CTX_set0_trusted()\fR is an alias of the original -\&\fBOSSL_CMP_CTX_set0_trustedStore()\fR. -It sets in the \s-1CMP\s0 context \fIctx\fR the certificate store of type X509_STORE -containing trusted certificates, typically of root CAs. -This is ignored when a certificate is pinned using \fBOSSL_CMP_CTX_set1_srvCert()\fR. -The store may also hold CRLs and a certificate verification callback function -used for signature-based peer authentication. -Any store entry already set before is freed. -When given a \s-1NULL\s0 parameter the entry is cleared. -.PP -\&\fBOSSL_CMP_CTX_get0_trusted()\fR is an alias of the original -\&\fBOSSL_CMP_CTX_get0_trustedStore()\fR. -It extracts from the \s-1CMP\s0 context \fIctx\fR the pointer to the currently set -certificate store containing trust anchors etc., or an empty store if unset. -.PP -\&\fBOSSL_CMP_CTX_set1_untrusted()\fR sets up a list of non-trusted certificates -of intermediate CAs that may be useful for path construction for the own \s-1CMP\s0 -signer certificate, for the own \s-1TLS\s0 certificate (if any), when verifying peer -\&\s-1CMP\s0 protection certificates, and when verifying newly enrolled certificates. -The reference counts of those certificates handled successfully are increased. -This list of untrusted certificates in \fIctx\fR will get augmented by extraCerts -in received \s-1CMP\s0 messages unless \fB\s-1OSSL_CMP_OPT_NO_CACHE_EXTRACERTS\s0\fR is set. -.PP -\&\fBOSSL_CMP_CTX_get0_untrusted()\fR returns a pointer to the -list of untrusted certs in \fIctx\fR, which may be empty if unset. -.PP -\&\fBOSSL_CMP_CTX_set1_cert()\fR sets the \s-1CMP\s0 \fIsigner certificate\fR, -also called \fIprotection certificate\fR, -related to the private key used for signature-based \s-1CMP\s0 message protection. -Therefore the public key of this \fIcert\fR must correspond to -the private key set before or thereafter via \fBOSSL_CMP_CTX_set1_pkey()\fR. -When using signature-based protection of \s-1CMP\s0 request messages -this \s-1CMP\s0 signer certificate will be included first in the extraCerts field. -It serves as fallback reference certificate, see \fBOSSL_CMP_CTX_set1_oldCert()\fR. -The subject of this \fIcert\fR will be used as the sender field of outgoing -messages, while the subject of any cert set via \fBOSSL_CMP_CTX_set1_oldCert()\fR, -the subject of any PKCS#10 \s-1CSR\s0 set via \fBOSSL_CMP_CTX_set1_p10CSR()\fR, -and any value set via \fBOSSL_CMP_CTX_set1_subjectName()\fR are used as fallback. -.PP -The \fIcert\fR argument may be \s-1NULL\s0 to clear the entry. -.PP -\&\fBOSSL_CMP_CTX_build_cert_chain()\fR builds a certificate chain for the \s-1CMP\s0 signer -certificate previously set in the \fIctx\fR. It adds the optional \fIcandidates\fR, -a list of intermediate \s-1CA\s0 certs that may already constitute the targeted chain, -to the untrusted certs that may already exist in the \fIctx\fR. -Then the function uses this augmented set of certs for chain construction. -If \fIown_trusted\fR is \s-1NULL\s0 it builds the chain as far down as possible and -ignores any verification errors. Else the \s-1CMP\s0 signer certificate must be -verifiable where the chain reaches a trust anchor contained in \fIown_trusted\fR. -On success the function stores the resulting chain in \fIctx\fR -for inclusion in the extraCerts field of signature-protected messages. -Calling this function is optional; by default a chain construction -is performed on demand that is equivalent to calling this function -with the \fIcandidates\fR and \fIown_trusted\fR arguments being \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_CTX_set1_pkey()\fR sets the client's private key corresponding to the -\&\s-1CMP\s0 signer certificate set via \fBOSSL_CMP_CTX_set1_cert()\fR. -This key is used create signature-based protection (protectionAlg = \s-1MSG_SIG_ALG\s0) -of outgoing messages -unless a symmetric secret has been set via \fBOSSL_CMP_CTX_set1_secretValue()\fR. -The \fIpkey\fR argument may be \s-1NULL\s0 to clear the entry. -.PP -\&\fBOSSL_CMP_CTX_set1_secretValue()\fR sets in \fIctx\fR the byte string \fIsec\fR of length -\&\fIlen\fR to use as pre-shared secret, or clears it if the \fIsec\fR argument is \s-1NULL.\s0 -If present, this secret is used to create MAC-based authentication and integrity -protection (rather than applying signature-based protection) -of outgoing messages and to verify authenticity and integrity of incoming -messages that have MAC-based protection (protectionAlg = \f(CW\*(C`MSG_MAC_ALG\*(C'\fR). -.PP -\&\fBOSSL_CMP_CTX_set1_referenceValue()\fR sets the given referenceValue \fIref\fR with -length \fIlen\fR in the given \fIctx\fR or clears it if the \fIref\fR argument is \s-1NULL.\s0 -According to \s-1RFC 4210\s0 section 5.1.1, if no value for the sender field in -\&\s-1CMP\s0 message headers can be determined (i.e., no \s-1CMP\s0 signer certificate -and no subject \s-1DN\s0 is set via \fBOSSL_CMP_CTX_set1_subjectName()\fR -then the sender field will contain the NULL-DN -and the senderKID field of the \s-1CMP\s0 message header must be set. -When signature-based protection is used the senderKID will be set to -the subjectKeyIdentifier of the \s-1CMP\s0 signer certificate as far as present. -If not present or when MAC-based protection is used -the \fIref\fR value is taken as the fallback value for the senderKID. -.PP -\&\fBOSSL_CMP_CTX_set1_recipient()\fR sets the recipient name that will be used in the -PKIHeader of \s-1CMP\s0 request messages, i.e. the X509 name of the (\s-1CA\s0) server. -.PP -The recipient field in the header of a \s-1CMP\s0 message is mandatory. -If not given explicitly the recipient is determined in the following order: -the subject of the \s-1CMP\s0 server certificate set using \fBOSSL_CMP_CTX_set1_srvCert()\fR, -the value set using \fBOSSL_CMP_CTX_set1_issuer()\fR, -the issuer of the certificate set using \fBOSSL_CMP_CTX_set1_oldCert()\fR, -the issuer of the \s-1CMP\s0 signer certificate, -as far as any of those is present, else the NULL-DN as last resort. -.PP -\&\fBOSSL_CMP_CTX_push0_geninfo_ITAV()\fR adds \fIitav\fR to the stack in the \fIctx\fR to be -added to the generalInfo field of the \s-1CMP\s0 PKIMessage header of a request -message sent with this context. -.PP -\&\fBOSSL_CMP_CTX_reset_geninfo_ITAVs()\fR -clears any ITAVs that were added by \fBOSSL_CMP_CTX_push0_geninfo_ITAV()\fR. -.PP -\&\fBOSSL_CMP_CTX_get0_geninfo_ITAVs()\fR returns the list of ITAVs set in \fIctx\fR -for inclusion in the generalInfo field of the \s-1CMP\s0 PKIMessage header of requests -or \s-1NULL\s0 if not set. -.PP -\&\fBOSSL_CMP_CTX_set1_extraCertsOut()\fR sets the stack of extraCerts that will be -sent to remote. -.PP -\&\fBOSSL_CMP_CTX_set0_newPkey()\fR can be used to explicitly set the given \s-1EVP_PKEY\s0 -structure as the private or public key to be certified in the \s-1CMP\s0 context. -The \fIpriv\fR parameter must be 0 if and only if the given key is a public key. -.PP -\&\fBOSSL_CMP_CTX_get0_newPkey()\fR gives the key to use for certificate enrollment -dependent on fields of the \s-1CMP\s0 context structure: -the newPkey (which may be a private or public key) if present, -else the public key in the p10CSR if present, else the client's private key. -If the \fIpriv\fR parameter is not 0 and the selected key does not have a -private component then \s-1NULL\s0 is returned. -.PP -\&\fBOSSL_CMP_CTX_set1_issuer()\fR sets the name of the intended issuer that -will be set in the CertTemplate, i.e., the X509 name of the \s-1CA\s0 server. -.PP -\&\fBOSSL_CMP_CTX_set1_serialNumber()\fR sets the serial number optionally used to -select the certificate to be revoked in Revocation Requests (\s-1RR\s0). -.PP -\&\fBOSSL_CMP_CTX_set1_subjectName()\fR sets the subject \s-1DN\s0 that will be used in -the CertTemplate structure when requesting a new cert. For Key Update Requests -(\s-1KUR\s0), it defaults to the subject \s-1DN\s0 of the reference certificate, -see \fBOSSL_CMP_CTX_set1_oldCert()\fR. This default is used for Initialization -Requests (\s-1IR\s0) and Certification Requests (\s-1CR\s0) only if no SANs are set. -The \fIsubjectName\fR is also used as fallback for the sender field -of outgoing \s-1CMP\s0 messages if no reference certificate is available. -.PP -\&\fBOSSL_CMP_CTX_push1_subjectAltName()\fR adds the given X509 name to the list of -alternate names on the certificate template request. This cannot be used if -any Subject Alternative Name extension is set via -\&\fBOSSL_CMP_CTX_set0_reqExtensions()\fR. -By default, unless \fB\s-1OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT\s0\fR has been set, -the Subject Alternative Names are copied from the reference certificate, -see \fBOSSL_CMP_CTX_set1_oldCert()\fR. -If set and the subject \s-1DN\s0 is not set with \fBOSSL_CMP_CTX_set1_subjectName()\fR then -the certificate template of an \s-1IR\s0 and \s-1CR\s0 will not be filled with the default -subject \s-1DN\s0 from the reference certificate. -If a subject \s-1DN\s0 is desired it needs to be set explicitly with -\&\fBOSSL_CMP_CTX_set1_subjectName()\fR. -.PP -\&\fBOSSL_CMP_CTX_set0_reqExtensions()\fR sets the X.509v3 extensions to be used in -\&\s-1IR/CR/KUR.\s0 -.PP -\&\fBOSSL_CMP_CTX_reqExtensions_have_SAN()\fR returns 1 if the context contains -a Subject Alternative Name extension, else 0 or \-1 on error. -.PP -\&\fBOSSL_CMP_CTX_push0_policy()\fR adds the certificate policy info object -to the X509_EXTENSIONS of the requested certificate template. -.PP -\&\fBOSSL_CMP_CTX_set1_oldCert()\fR sets the old certificate to be updated in -Key Update Requests (\s-1KUR\s0) or to be revoked in Revocation Requests (\s-1RR\s0). -For \s-1RR,\s0 this is ignored if an issuer name and a serial number are provided using -\&\fBOSSL_CMP_CTX_set1_issuer()\fR and \fBOSSL_CMP_CTX_set1_serialNumber()\fR, respectively. -For \s-1IR/CR/KUR\s0 this sets the \fIreference certificate\fR, -which otherwise defaults to the \s-1CMP\s0 signer certificate. -The \fIreference certificate\fR determined this way, if any, is used for providing -default public key, subject \s-1DN,\s0 Subject Alternative Names, and issuer \s-1DN\s0 entries -in the requested certificate template of \s-1IR/CR/KUR\s0 messages. -.PP -The subject of the reference certificate is used as the sender field value -in \s-1CMP\s0 message headers. -Its issuer is used as default recipient in \s-1CMP\s0 message headers. -.PP -\&\fBOSSL_CMP_CTX_set1_p10CSR()\fR sets the PKCS#10 \s-1CSR\s0 to use in P10CR messages. -If such a \s-1CSR\s0 is provided, its subject and public key fields are also -used as fallback values for the certificate template of \s-1IR/CR/KUR/RR\s0 messages, -and any extensions included are added to the template of \s-1IR/CR/KUR\s0 messages. -.PP -\&\fBOSSL_CMP_CTX_push0_genm_ITAV()\fR adds \fIitav\fR to the stack in the \fIctx\fR which -will be the body of a General Message sent with this context. -.PP -\&\fBOSSL_CMP_certConf_cb()\fR is the default certificate confirmation callback function. -If the callback argument is not \s-1NULL\s0 it must point to a trust store. -In this case the function checks that the newly enrolled certificate can be -verified using this trust store and untrusted certificates from the \fIctx\fR, -which have been augmented by the list of extraCerts received. -During this verification, any certificate status checking is disabled. -If the callback argument is \s-1NULL\s0 the function tries building an approximate -chain as far as possible using the same untrusted certificates from the \fIctx\fR, -and if this fails it takes the received extraCerts as fallback. -The resulting cert chain can be retrieved using \fBOSSL_CMP_CTX_get1_newChain()\fR. -This chain excludes the leaf certificate, i.e., the newly enrolled certificate. -Also the trust anchor (the root certificate) is not included. -.PP -\&\fBOSSL_CMP_CTX_set_certConf_cb()\fR sets the callback used for evaluating the newly -enrolled certificate before the library sends, depending on its result, -a positive or negative certConf message to the server. The callback has type -.PP -.Vb 2 -\& typedef int (*OSSL_CMP_certConf_cb_t) (OSSL_CMP_CTX *ctx, X509 *cert, -\& int fail_info, const char **txt); -.Ve -.PP -and should inspect the certificate it obtains via the \fIcert\fR parameter and may -overrule the pre-decision given in the \fIfail_info\fR and \fI*txt\fR parameters. -If it accepts the certificate it must return 0, indicating success. Else it must -return a bit field reflecting PKIFailureInfo with at least one failure bit and -may set the \fI*txt\fR output parameter to point to a string constant with more -detail. The transfer callback may make use of a custom defined argument stored -in the \fIctx\fR by means of \fBOSSL_CMP_CTX_set_certConf_cb_arg()\fR, which may be -retrieved again through \fBOSSL_CMP_CTX_get_certConf_cb_arg()\fR. -Typically, the callback will check at least that the certificate can be verified -using a set of trusted certificates. -It also could compare the subject \s-1DN\s0 and other fields of the newly -enrolled certificate with the certificate template of the request. -.PP -\&\fBOSSL_CMP_CTX_set_certConf_cb_arg()\fR sets an argument, respectively a pointer to a -structure containing arguments, optionally to be used by the certConf callback. -\&\fIarg\fR is not consumed, and it must therefore explicitly be freed when not -needed any more. \fIarg\fR may be \s-1NULL\s0 to clear the entry. -.PP -\&\fBOSSL_CMP_CTX_get_certConf_cb_arg()\fR gets the argument, respectively the pointer -to a structure containing arguments, previously set by -\&\fBOSSL_CMP_CTX_set_certConf_cb_arg()\fR, or \s-1NULL\s0 if unset. -.PP -\&\fBOSSL_CMP_CTX_get_status()\fR returns for client contexts the PKIstatus from -the last received CertRepMessage or Revocation Response or error message: -=item \fBOSSL_CMP_PKISTATUS_accepted\fR on successful receipt of a \s-1GENP\s0 message: -.IP "\fBOSSL_CMP_PKISTATUS_request\fR" 4 -.IX Item "OSSL_CMP_PKISTATUS_request" -if an \s-1IR/CR/KUR/RR/GENM\s0 request message could not be produced, -.IP "\fBOSSL_CMP_PKISTATUS_trans\fR" 4 -.IX Item "OSSL_CMP_PKISTATUS_trans" -on a transmission error or transaction error for this type of request, and -.IP "\fBOSSL_CMP_PKISTATUS_unspecified\fR" 4 -.IX Item "OSSL_CMP_PKISTATUS_unspecified" -if no such request was attempted or \fBOSSL_CMP_CTX_reinit()\fR has been called. -.PP -For server contexts it returns -\&\fBOSSL_CMP_PKISTATUS_trans\fR if a transaction is open, -otherwise \fBOSSL_CMP_PKISTATUS_unspecified\fR. -.PP -\&\fBOSSL_CMP_CTX_get0_statusString()\fR returns the statusString from the last received -CertRepMessage or Revocation Response or error message, or \s-1NULL\s0 if unset. -.PP -\&\fBOSSL_CMP_CTX_get_failInfoCode()\fR returns the error code from the failInfo field -of the last received CertRepMessage or Revocation Response or error message, -or \-1 if no such response was received or \fBOSSL_CMP_CTX_reinit()\fR has been called. -This is a bit field and the flags for it are specified in the header file -\&\fI\fR. -The flags start with \s-1OSSL_CMP_CTX_FAILINFO,\s0 for example: -OSSL_CMP_CTX_FAILINFO_badAlg. Returns \-1 if the failInfoCode field is unset. -.PP -\&\fBOSSL_CMP_CTX_get0_validatedSrvCert()\fR returns -the successfully validated certificate, if any, that the \s-1CMP\s0 server used -in the current transaction for signature-based response message protection, -or \s-1NULL\s0 if the server used MAC-based protection. -The value is relevant only at the end of a successful transaction. -It may be used to check the authorization of the server based on its cert. -.PP -\&\fBOSSL_CMP_CTX_get0_newCert()\fR returns the pointer to the newly obtained -certificate in case it is available, else \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_CTX_get1_newChain()\fR returns a pointer to a duplicate of the stack of -X.509 certificates computed by \fBOSSL_CMP_certConf_cb()\fR (if this function has -been called) on the last received certificate response message \s-1IP/CP/KUP.\s0 -.PP -\&\fBOSSL_CMP_CTX_get1_caPubs()\fR returns a pointer to a duplicate of the list of -X.509 certificates in the caPubs field of the last received certificate -response message (of type \s-1IP, CP,\s0 or \s-1KUP\s0), -or an empty stack if no caPubs have been received in the current transaction. -.PP -\&\fBOSSL_CMP_CTX_get1_extraCertsIn()\fR returns a pointer to a duplicate of the list -of X.509 certificates contained in the extraCerts field of the last received -response message (except for pollRep and PKIConf), or -an empty stack if no extraCerts have been received in the current transaction. -.PP -\&\fBOSSL_CMP_CTX_set1_transactionID()\fR sets the given transaction \s-1ID\s0 in the given -\&\s-1OSSL_CMP_CTX\s0 structure. -.PP -\&\fBOSSL_CMP_CTX_set1_senderNonce()\fR stores the last sent sender \fInonce\fR in -the \fIctx\fR. This will be used to validate the recipNonce in incoming messages. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210\s0 (and \s-1CRMF\s0 in \s-1RFC 4211\s0). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_CTX_free()\fR and \fBOSSL_CMP_CTX_print_errors()\fR do not return anything. -.PP -\&\fBOSSL_CMP_CTX_new()\fR, -\&\fBOSSL_CMP_CTX_get0_libctx()\fR, \fBOSSL_CMP_CTX_get0_propq()\fR, -\&\fBOSSL_CMP_CTX_get_http_cb_arg()\fR, -\&\fBOSSL_CMP_CTX_get_transfer_cb_arg()\fR, -\&\fBOSSL_CMP_CTX_get0_trusted()\fR, -\&\fBOSSL_CMP_CTX_get0_untrusted()\fR, -\&\fBOSSL_CMP_CTX_get0_geninfo_ITAVs()\fR, -\&\fBOSSL_CMP_CTX_get0_newPkey()\fR, -\&\fBOSSL_CMP_CTX_get_certConf_cb_arg()\fR, -\&\fBOSSL_CMP_CTX_get0_statusString()\fR, -\&\fBOSSL_CMP_CTX_get0_validatedSrvCert()\fR, -\&\fBOSSL_CMP_CTX_get0_newCert()\fR, -\&\fBOSSL_CMP_CTX_get0_newChain()\fR, -\&\fBOSSL_CMP_CTX_get1_caPubs()\fR, and -\&\fBOSSL_CMP_CTX_get1_extraCertsIn()\fR -return the intended pointer value as described above or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_CTX_get_option()\fR, -\&\fBOSSL_CMP_CTX_reqExtensions_have_SAN()\fR, -\&\fBOSSL_CMP_CTX_get_status()\fR, and -\&\fBOSSL_CMP_CTX_get_failInfoCode()\fR -return the intended value as described above or \-1 on error. -.PP -\&\fBOSSL_CMP_certConf_cb()\fR returns \fIfail_info\fR if it is not equal to 0, -else 0 on successful validation, -or else a bit field with the \fBOSSL_CMP_PKIFAILUREINFO_incorrectData\fR bit set. -.PP -All other functions, including \fBOSSL_CMP_CTX_reinit()\fR -and \fBOSSL_CMP_CTX_reset_geninfo_ITAVs()\fR, -return 1 on success, 0 on error. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following code omits error handling. -.PP -Set up a \s-1CMP\s0 client context for sending requests and verifying responses: -.PP -.Vb 5 -\& cmp_ctx = OSSL_CMP_CTX_new(); -\& OSSL_CMP_CTX_set1_server(cmp_ctx, name_or_address); -\& OSSL_CMP_CTX_set1_serverPort(cmp_ctx, port_string); -\& OSSL_CMP_CTX_set1_serverPath(cmp_ctx, path_or_alias); -\& OSSL_CMP_CTX_set0_trusted(cmp_ctx, ts); -.Ve -.PP -Set up symmetric credentials for MAC-based message protection such as \s-1PBM:\s0 -.PP -.Vb 2 -\& OSSL_CMP_CTX_set1_referenceValue(cmp_ctx, ref, ref_len); -\& OSSL_CMP_CTX_set1_secretValue(cmp_ctx, sec, sec_len); -.Ve -.PP -Set up the details for certificate requests: -.PP -.Vb 2 -\& OSSL_CMP_CTX_set1_subjectName(cmp_ctx, name); -\& OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, initialKey); -.Ve -.PP -Perform an Initialization Request transaction: -.PP -.Vb 1 -\& initialCert = OSSL_CMP_exec_IR_ses(cmp_ctx); -.Ve -.PP -Reset the transaction state of the \s-1CMP\s0 context and the credentials: -.PP -.Vb 3 -\& OSSL_CMP_CTX_reinit(cmp_ctx); -\& OSSL_CMP_CTX_set1_referenceValue(cmp_ctx, NULL, 0); -\& OSSL_CMP_CTX_set1_secretValue(cmp_ctx, NULL, 0); -.Ve -.PP -Perform a Certification Request transaction, making use of the new credentials: -.PP -.Vb 4 -\& OSSL_CMP_CTX_set1_cert(cmp_ctx, initialCert); -\& OSSL_CMP_CTX_set1_pkey(cmp_ctx, initialKey); -\& OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, curentKey); -\& currentCert = OSSL_CMP_exec_CR_ses(cmp_ctx); -.Ve -.PP -Perform a Key Update Request, signed using the cert (and key) to be updated: -.PP -.Vb 6 -\& OSSL_CMP_CTX_reinit(cmp_ctx); -\& OSSL_CMP_CTX_set1_cert(cmp_ctx, currentCert); -\& OSSL_CMP_CTX_set1_pkey(cmp_ctx, currentKey); -\& OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, updatedKey); -\& currentCert = OSSL_CMP_exec_KUR_ses(cmp_ctx); -\& currentKey = updatedKey; -.Ve -.PP -Perform a General Message transaction including, as an example, -the id-it-signKeyPairTypes \s-1OID\s0 and prints info on the General Response contents: -.PP -.Vb 1 -\& OSSL_CMP_CTX_reinit(cmp_ctx); -\& -\& ASN1_OBJECT *type = OBJ_txt2obj("1.3.6.1.5.5.7.4.2", 1); -\& OSSL_CMP_ITAV *itav = OSSL_CMP_ITAV_create(type, NULL); -\& OSSL_CMP_CTX_push0_genm_ITAV(cmp_ctx, itav); -\& -\& STACK_OF(OSSL_CMP_ITAV) *itavs; -\& itavs = OSSL_CMP_exec_GENM_ses(cmp_ctx); -\& print_itavs(itavs); -\& sk_OSSL_CMP_ITAV_pop_free(itavs, OSSL_CMP_ITAV_free); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_exec_IR_ses\fR\|(3), \fBOSSL_CMP_exec_CR_ses\fR\|(3), -\&\fBOSSL_CMP_exec_KUR_ses\fR\|(3), \fBOSSL_CMP_exec_GENM_ses\fR\|(3), -\&\fBOSSL_CMP_exec_certreq\fR\|(3), \fBOSSL_CMP_MSG_http_perform\fR\|(3), -\&\fBERR_print_errors_cb\fR\|(3), \fBOSSL_HTTP_open\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.PP -\&\fBOSSL_CMP_CTX_get0_trustedStore()\fR was renamed to \fBOSSL_CMP_CTX_get0_trusted()\fR and -\&\fBOSSL_CMP_CTX_set0_trustedStore()\fR was renamed to \fBOSSL_CMP_CTX_set0_trusted()\fR, -using macros, while keeping the old names for backward compatibility, -in OpenSSL 3.2. -.PP -\&\fBOSSL_CMP_CTX_reset_geninfo_ITAVs()\fR was added in OpenSSL 3.0.8. -.PP -\&\fBOSSL_CMP_CTX_set1_serialNumber()\fR, -\&\fBOSSL_CMP_CTX_get0_libctx()\fR, \fBOSSL_CMP_CTX_get0_propq()\fR, and -\&\fBOSSL_CMP_CTX_get0_validatedSrvCert()\fR were added in OpenSSL 3.2. -.PP -\&\fBOSSL_CMP_CTX_get0_geninfo_ITAVs()\fR was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_print_errors.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_print_errors.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_print_errors.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_geninfo_ITAV.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_geninfo_ITAV.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_geninfo_ITAV.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_genm_ITAV.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_genm_ITAV.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_genm_ITAV.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_policy.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_policy.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_push0_policy.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_push1_subjectAltName.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_push1_subjectAltName.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_push1_subjectAltName.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_reinit.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_reinit.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_reinit.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_reqExtensions_have_SAN.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_reqExtensions_have_SAN.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_reqExtensions_have_SAN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_reset_geninfo_ITAVs.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_reset_geninfo_ITAVs.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_reset_geninfo_ITAVs.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_server_perform.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_server_perform.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_server_perform.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_newPkey.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_newPkey.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_newPkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_reqExtensions.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_reqExtensions.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_reqExtensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trusted.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trusted.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trusted.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trustedStore.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trustedStore.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set0_trustedStore.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_cert.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_cert.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_expected_sender.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_expected_sender.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_expected_sender.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_extraCertsOut.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_extraCertsOut.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_extraCertsOut.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_issuer.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_issuer.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_no_proxy.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_no_proxy.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_no_proxy.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_oldCert.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_oldCert.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_oldCert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_p10CSR.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_p10CSR.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_p10CSR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_pkey.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_pkey.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_proxy.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_proxy.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_proxy.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_recipient.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_recipient.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_recipient.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_referenceValue.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_referenceValue.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_referenceValue.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_secretValue.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_secretValue.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_secretValue.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_senderNonce.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_senderNonce.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_senderNonce.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serialNumber.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serialNumber.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_server.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_server.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_server.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serverPath.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serverPath.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_serverPath.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_srvCert.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_srvCert.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_srvCert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_subjectName.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_subjectName.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_subjectName.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_transactionID.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_transactionID.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_transactionID.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_untrusted.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_untrusted.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set1_untrusted.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb_arg.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb_arg.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_certConf_cb_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb_arg.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb_arg.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_http_cb_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_cb.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_cb.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_verbosity.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_verbosity.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_log_verbosity.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_option.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_option.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_option.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_serverPort.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_serverPort.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_serverPort.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb_arg.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb_arg.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_set_transfer_cb_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_setup_CRM.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_setup_CRM.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_setup_CRM.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_CTX_snprint_PKIStatus.3ossl b/openssl-install/share/man/man3/OSSL_CMP_CTX_snprint_PKIStatus.3ossl deleted file mode 120000 index 62f2c527..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_CTX_snprint_PKIStatus.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_STATUSINFO_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_geninfo_ITAVs.3ossl b/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_geninfo_ITAVs.3ossl deleted file mode 120000 index 95dbc6dc..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_geninfo_ITAVs.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_HDR_get0_transactionID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_recipNonce.3ossl b/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_recipNonce.3ossl deleted file mode 120000 index 95dbc6dc..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_recipNonce.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_HDR_get0_transactionID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_transactionID.3ossl b/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_transactionID.3ossl deleted file mode 100644 index 6834ebae..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_HDR_get0_transactionID.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_HDR_GET0_TRANSACTIONID 3ossl" -.TH OSSL_CMP_HDR_GET0_TRANSACTIONID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_HDR_get0_transactionID, -OSSL_CMP_HDR_get0_recipNonce, -OSSL_CMP_HDR_get0_geninfo_ITAVs -\&\- functions manipulating CMP message headers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_OCTET_STRING *OSSL_CMP_HDR_get0_transactionID(const -\& OSSL_CMP_PKIHEADER *hdr); -\& ASN1_OCTET_STRING *OSSL_CMP_HDR_get0_recipNonce(const -\& OSSL_CMP_PKIHEADER *hdr); -\& STACK_OF(OSSL_CMP_ITAV) -\& *OSSL_CMP_HDR_get0_geninfo_ITAVs(const OSSL_CMP_PKIHEADER *hdr); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OSSL_CMP_HDR_get0_transactionID returns the transaction \s-1ID\s0 of the given -PKIHeader. -.PP -OSSL_CMP_HDR_get0_recipNonce returns the recipient nonce of the given PKIHeader. -.PP -\&\fBOSSL_CMP_HDR_get0_geninfo_ITAVs()\fR returns the list of ITAVs -in the generalInfo field of the given PKIHeader. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions return the intended pointer value as described above -or \s-1NULL\s0 if the respective entry does not exist and on error. -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.PP -\&\fBOSSL_CMP_HDR_get0_geninfo_ITAVs()\fR was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_IR.3ossl b/openssl-install/share/man/man3/OSSL_CMP_IR.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_IR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_create.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_create.3ossl deleted file mode 120000 index 43c4420b..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_dup.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_caCerts.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_caCerts.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_caCerts.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_certProfile.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_certProfile.3ossl deleted file mode 120000 index 43c4420b..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_certProfile.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crlStatusList.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crlStatusList.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crlStatusList.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crls.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crls.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_crls.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaCert.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaCert.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaCert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaKeyUpdate.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaKeyUpdate.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_rootCaKeyUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_type.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_type.3ossl deleted file mode 120000 index 43c4420b..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_value.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_value.3ossl deleted file mode 120000 index 43c4420b..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get0_value.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get1_certReqTemplate.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_get1_certReqTemplate.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_get1_certReqTemplate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certProfile.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certProfile.3ossl deleted file mode 120000 index 43c4420b..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certProfile.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certReqTemplate.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certReqTemplate.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_certReqTemplate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_crlStatusList.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_crlStatusList.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new0_crlStatusList.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_caCerts.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_caCerts.3ossl deleted file mode 100644 index 8ec65017..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_caCerts.3ossl +++ /dev/null @@ -1,345 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_ITAV_NEW_CACERTS 3ossl" -.TH OSSL_CMP_ITAV_NEW_CACERTS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_ITAV_new_caCerts, -OSSL_CMP_ITAV_get0_caCerts, -OSSL_CMP_ITAV_new_rootCaCert, -OSSL_CMP_ITAV_get0_rootCaCert, -OSSL_CMP_ITAV_new_rootCaKeyUpdate, -OSSL_CMP_ITAV_get0_rootCaKeyUpdate, -OSSL_CMP_CRLSTATUS_new1, -OSSL_CMP_CRLSTATUS_create, -OSSL_CMP_CRLSTATUS_get0, -OSSL_CMP_ITAV_new0_crlStatusList, -OSSL_CMP_ITAV_get0_crlStatusList, -OSSL_CMP_ITAV_new_crls, -OSSL_CMP_ITAV_get0_crls, -OSSL_CMP_ITAV_new0_certReqTemplate, -OSSL_CMP_ITAV_get1_certReqTemplate -\&\- CMP utility functions for handling specific genm and genp messages -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_caCerts(const STACK_OF(X509) *caCerts); -\& int OSSL_CMP_ITAV_get0_caCerts(const OSSL_CMP_ITAV *itav, STACK_OF(X509) **out); -\& -\& OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_rootCaCert(const X509 *rootCaCert); -\& int OSSL_CMP_ITAV_get0_rootCaCert(const OSSL_CMP_ITAV *itav, X509 **out); -\& OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_rootCaKeyUpdate(const X509 *newWithNew, -\& const X509 *newWithOld, -\& const X509 *oldWithNew); -\& int OSSL_CMP_ITAV_get0_rootCaKeyUpdate(const OSSL_CMP_ITAV *itav, -\& X509 **newWithNew, -\& X509 **newWithOld, -\& X509 **oldWithNew); -\& -\& OSSL_CMP_CRLSTATUS *OSSL_CMP_CRLSTATUS_new1(const DIST_POINT_NAME *dpn, -\& const GENERAL_NAMES *issuer, -\& const ASN1_TIME *thisUpdate); -\& OSSL_CMP_CRLSTATUS *OSSL_CMP_CRLSTATUS_create(const X509_CRL *crl, -\& const X509 *cert, int only_DN); -\& int OSSL_CMP_CRLSTATUS_get0(const OSSL_CMP_CRLSTATUS *crlstatus, -\& DIST_POINT_NAME **dpn, GENERAL_NAMES **issuer, -\& ASN1_TIME **thisUpdate); -\& OSSL_CMP_ITAV -\& *OSSL_CMP_ITAV_new0_crlStatusList(STACK_OF(OSSL_CMP_CRLSTATUS) *crlStatusList); -\& int OSSL_CMP_ITAV_get0_crlStatusList(const OSSL_CMP_ITAV *itav, -\& STACK_OF(OSSL_CMP_CRLSTATUS) **out); -\& OSSL_CMP_ITAV *OSSL_CMP_ITAV_new_crls(const X509_CRL *crl); -\& int OSSL_CMP_ITAV_get0_crls(const OSSL_CMP_ITAV *itav, STACK_OF(X509_CRL) **out); -\& OSSL_CMP_ITAV -\& *OSSL_CMP_ITAV_new0_certReqTemplate(OSSL_CRMF_CERTTEMPLATE *certTemplate, -\& OSSL_CMP_ATAVS *keySpec); -\& int OSSL_CMP_ITAV_get1_certReqTemplate(const OSSL_CMP_ITAV *itav, -\& OSSL_CRMF_CERTTEMPLATE **certTemplate, -\& OSSL_CMP_ATAVS **keySpec); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1ITAV\s0 is short for InfoTypeAndValue. -.PP -\&\fBOSSL_CMP_ITAV_new_caCerts()\fR creates an \fB\s-1OSSL_CMP_ITAV\s0\fR structure of type -\&\fBcaCerts\fR and fills it with a copy of the provided list of certificates. -The \fIcaCerts\fR argument may be \s-1NULL\s0 or contain any number of certificates. -.PP -\&\fBOSSL_CMP_ITAV_get0_caCerts()\fR requires that \fIitav\fR has type \fBcaCerts\fR. -It assigns \s-1NULL\s0 to \fI*out\fR if there are no \s-1CA\s0 certificates in \fIitav\fR, otherwise -the internal pointer of type \fB\s-1STACK_OF\s0(X509)\fR with the certificates present. -.PP -\&\fBOSSL_CMP_ITAV_new_rootCaCert()\fR creates a new \fB\s-1OSSL_CMP_ITAV\s0\fR structure -of type \fBrootCaCert\fR that includes the optionally given certificate. -.PP -\&\fBOSSL_CMP_ITAV_get0_rootCaCert()\fR requires that \fIitav\fR has type \fBrootCaCert\fR. -It assigns \s-1NULL\s0 to \fI*out\fR if no certificate is included in \fIitav\fR, otherwise -the internal pointer to the certificate contained in the infoValue field. -.PP -\&\fBOSSL_CMP_ITAV_new_rootCaKeyUpdate()\fR creates a new \fB\s-1OSSL_CMP_ITAV\s0\fR structure -of type \fBrootCaKeyUpdate\fR that includes an RootCaKeyUpdateContent structure -with the optional \fInewWithNew\fR, \fInewWithOld\fR, and \fIoldWithNew\fR certificates. -An RootCaKeyUpdateContent structure is included only if \fInewWithNew\fR -is not \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ITAV_get0_rootCaKeyUpdate()\fR requires that \fIitav\fR has infoType -\&\fBrootCaKeyUpdate\fR. -If an update of a root \s-1CA\s0 certificate is included, -it assigns to \fI*newWithNew\fR the internal pointer -to the certificate contained in the newWithNew infoValue sub-field of \fIitav\fR. -If \fInewWithOld\fR is not \s-1NULL,\s0 it assigns to \fI*newWithOld\fR the internal pointer -to the certificate contained in the newWithOld infoValue sub-field of \fIitav\fR. -If \fIoldWithNew\fR is not \s-1NULL,\s0 it assigns to \fI*oldWithNew\fR the internal pointer -to the certificate contained in the oldWithNew infoValue sub-field of \fIitav\fR. -Each of these pointers will be set to \s-1NULL\s0 if no root \s-1CA\s0 certificate update -is present or the respective sub-field is not included. -.PP -\&\fBOSSL_CMP_CRLSTATUS_new1()\fR allocates a new \fB\s-1OSSL_CMP_CRLSTATUS\s0\fR structure -that contains either a copy of the distribution point name \fIdpn\fR -or a copy of the certificate issuer \fIissuer\fR, while giving both is an error. -If given, a copy of the \s-1CRL\s0 issuance time \fIthisUpdate\fR is also included. -.PP -\&\fBOSSL_CMP_CRLSTATUS_create()\fR is a high-level variant of \fBOSSL_CMP_CRLSTATUS_new1()\fR. -It fills the thisUpdate field with a copy of the thisUpdate field of \fIcrl\fR if present. -It fills the CRLSource field with a copy of the first data item found using the \fIcrl\fR -and/or \fIcert\fR parameters as follows. -Any available distribution point name is preferred over issuer names. -Data from \fIcert\fR, if present, is preferred over data from \fIcrl\fR. -If no distribution point names are available, -candidate issuer names are taken from following sources, as far as present: -.IP "the list of distribution points in the first cRLDistributionPoints extension of \fIcert\fR," 4 -.IX Item "the list of distribution points in the first cRLDistributionPoints extension of cert," -.PD 0 -.IP "the issuer field of the authority key identifier of \fIcert\fR," 4 -.IX Item "the issuer field of the authority key identifier of cert," -.IP "the issuer \s-1DN\s0 of \fIcert\fR," 4 -.IX Item "the issuer DN of cert," -.IP "the issuer field of the authority key identifier of \fIcrl\fR, and" 4 -.IX Item "the issuer field of the authority key identifier of crl, and" -.IP "the issuer \s-1DN\s0 of \fIcrl\fR." 4 -.IX Item "the issuer DN of crl." -.PD -.PP -If is set, a candidate issuer name of type \fB\s-1GENERAL_NAMES\s0\fR is -accepted only if it contains exactly one general name of type directoryName. -.PP -\&\fBOSSL_CMP_CRLSTATUS_get0()\fR reads the fields of \fIcrlstatus\fR -and assigns them to \fI*dpn\fR, \fI*issuer\fR, and \fI*thisUpdate\fR. -\&\fI*thisUpdate\fR is assigned only if the \fIthisUpdate\fR argument is not \s-1NULL.\s0 -Depending on the choice present, either \fI*dpn\fR or \fI*issuer\fR will be \s-1NULL.\s0 -\&\fI*thisUpdate\fR can also be \s-1NULL\s0 if the field is not present. -.PP -\&\fBOSSL_CMP_ITAV_new0_crlStatusList()\fR creates a new \fB\s-1OSSL_CMP_ITAV\s0\fR structure of -type \fBcrlStatusList\fR that includes the optionally given list of -\&\s-1CRL\s0 status data, each of which is of type \fB\s-1OSSL_CMP_CRLSTATUS\s0\fR. -.PP -\&\fBOSSL_CMP_ITAV_get0_crlStatusList()\fR on success assigns to \fI*out\fR an internal -pointer to the list of \s-1CRL\s0 status data in the infoValue field of \fIitav\fR. -The pointer may be \s-1NULL\s0 if no \s-1CRL\s0 status data is included. -It is an error if the infoType of \fIitav\fR is not \fBcrlStatusList\fR. -.PP -\&\fBOSSL_CMP_ITAV_new_crls()\fR creates a new \fB\s-1OSSL_CMP_ITAV\s0\fR structure -of type \fBcrls\fR including an empty list of CRLs if the \fIcrl\fR argument is \s-1NULL\s0 -or including a singleton list a with copy of the provided \s-1CRL\s0 otherwise. -.PP -\&\fBOSSL_CMP_ITAV_get0_crls()\fR on success assigns to \fI*out\fR an internal pointer to -the list of CRLs contained in the infoValue field of \fIitav\fR. -The pointer may be \s-1NULL\s0 if no \s-1CRL\s0 is included. -It is an error if the infoType of \fIitav\fR is not \fBcrls\fR. -.PP -\&\fBOSSL_CMP_ITAV_new0_certReqTemplate()\fR creates an \fB\s-1OSSL_CMP_ITAV\s0\fR structure -of type \fBcertReqTemplate\fR. -If \fIcertTemplate\fR is \s-1NULL\s0 then also \fIkeySpec\fR must be \s-1NULL,\s0 -and the resulting \s-1ITAV\s0 can be used in a \fBgenm\fR message to obtain the -requirements a \s-1PKI\s0 has on the certificate template used to request certificates, -or in a \fBgenp\fR message stating that there are no such requirements. -Otherwise the resulting \s-1ITAV\s0 includes a CertReqTemplateValue structure -with \fIcertTemplate\fR of type \fB\s-1OSSL_CRMF_CERTTEMPLATE\s0\fR and an optional list -of key specifications \fIkeySpec\fR, each being of type \fB\s-1OSSL_CMP_ATAV\s0\fR, and -the resulting \s-1ATAV\s0 can be used in a \fBgenp\fR message to provide requirements. -.PP -\&\fBOSSL_CMP_ITAV_get1_certReqTemplate()\fR -requires that \fIitav\fR has type \fBcertReqTemplate\fR. -If assigns \s-1NULL\s0 to \fI*certTemplate\fR if no \fB\s-1OSSL_CRMF_CERTTEMPLATE\s0\fR structure -with a certificate template value is in \fIitav\fR, -otherwise a copy of the certTemplate field value. -If \fIkeySpec\fR is not \s-1NULL,\s0 it is assigned \s-1NULL\s0 -if the structure is not present in \fIitav\fR or the keySpec field is absent. -Otherwise, the function checks that all elements of keySpec field are of type -\&\fBalgId\fR or \fBrsaKeyLen\fR and assigns to \fI*keySpec\fR a copy of the keySpec field. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_ITAV_new_caCerts()\fR, \fBOSSL_CMP_ITAV_new_rootCaCert()\fR, -\&\fBOSSL_CMP_ITAV_new_rootCaKeyUpdate()\fR, \fBOSSL_CMP_CRLSTATUS_new1()\fR, -\&\fBOSSL_CMP_CRLSTATUS_create()\fR, \fBOSSL_CMP_ITAV_new0_crlStatusList()\fR, -\&\fBOSSL_CMP_ITAV_new_crls()\fR and \fBOSSL_CMP_ITAV_new0_certReqTemplate()\fR -return a pointer to the new \s-1ITAV\s0 structure on success, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_ITAV_get0_caCerts()\fR, \fBOSSL_CMP_ITAV_get0_rootCaCert()\fR, -\&\fBOSSL_CMP_ITAV_get0_rootCaKeyUpdate()\fR, \fBOSSL_CMP_CRLSTATUS_get0()\fR, -\&\fBOSSL_CMP_ITAV_get0_crlStatusList()\fR, \fBOSSL_CMP_ITAV_get0_crls()\fR -and \fBOSSL_CMP_ITAV_get1_certReqTemplate()\fR -return 1 on success, 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_ITAV_create\fR\|(3) and \fBOSSL_CMP_ITAV_get0_type\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_CMP_ITAV_new_caCerts()\fR, \fBOSSL_CMP_ITAV_get0_caCerts()\fR, -\&\fBOSSL_CMP_ITAV_new_rootCaCert()\fR, \fBOSSL_CMP_ITAV_get0_rootCaCert()\fR, -\&\fBOSSL_CMP_ITAV_new_rootCaKeyUpdate()\fR, and \fBOSSL_CMP_ITAV_get0_rootCaKeyUpdate()\fR -were added in OpenSSL 3.2. -.PP -\&\fBOSSL_CMP_CRLSTATUS_new1()\fR, \fBOSSL_CMP_CRLSTATUS_create()\fR, -\&\fBOSSL_CMP_CRLSTATUS_get0()\fR, \fBOSSL_CMP_ITAV_new0_crlStatusList()\fR, -\&\fBOSSL_CMP_ITAV_get0_crlStatusList()\fR, \fBOSSL_CMP_ITAV_new_crls()\fR, -\&\fBOSSL_CMP_ITAV_get0_crls()\fR, \fBOSSL_CMP_ITAV_new0_certReqTemplate()\fR -and \fBOSSL_CMP_ITAV_get1_certReqTemplate()\fR were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_crls.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_crls.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_crls.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaCert.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaCert.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaCert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaKeyUpdate.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaKeyUpdate.3ossl deleted file mode 120000 index 20225652..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_new_rootCaKeyUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_new_caCerts.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_push0_stack_item.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_push0_stack_item.3ossl deleted file mode 120000 index 43c4420b..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_push0_stack_item.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_ITAV_set0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_ITAV_set0.3ossl b/openssl-install/share/man/man3/OSSL_CMP_ITAV_set0.3ossl deleted file mode 100644 index d98e0e6b..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_ITAV_set0.3ossl +++ /dev/null @@ -1,264 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_ITAV_SET0 3ossl" -.TH OSSL_CMP_ITAV_SET0 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_ITAV_create, -OSSL_CMP_ITAV_set0, -OSSL_CMP_ITAV_get0_type, -OSSL_CMP_ITAV_get0_value, -OSSL_CMP_ITAV_push0_stack_item, -OSSL_CMP_ITAV_new0_certProfile, -OSSL_CMP_ITAV_get0_certProfile -\&\- OSSL_CMP_ITAV utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CMP_ITAV *OSSL_CMP_ITAV_create(ASN1_OBJECT *type, ASN1_TYPE *value); -\& void OSSL_CMP_ITAV_set0(OSSL_CMP_ITAV *itav, ASN1_OBJECT *type, -\& ASN1_TYPE *value); -\& ASN1_OBJECT *OSSL_CMP_ITAV_get0_type(const OSSL_CMP_ITAV *itav); -\& ASN1_TYPE *OSSL_CMP_ITAV_get0_value(const OSSL_CMP_ITAV *itav); -\& int OSSL_CMP_ITAV_push0_stack_item(STACK_OF(OSSL_CMP_ITAV) **itav_sk_p, -\& OSSL_CMP_ITAV *itav); -\& OSSL_CMP_ITAV -\& *OSSL_CMP_ITAV_new0_certProfile(STACK_OF(ASN1_UTF8STRING) *certProfile); -\& int OSSL_CMP_ITAV_get0_certProfile(const OSSL_CMP_ITAV *itav, -\& STACK_OF(ASN1_UTF8STRING) **out); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1ITAV\s0 is short for InfoTypeAndValue. This type is defined in \s-1RFC 4210\s0 -section 5.3.19 and Appendix F. It is used at various places in \s-1CMP\s0 messages, -e.g., in the generalInfo PKIHeader field, to hold a key-value pair. -.PP -\&\fBOSSL_CMP_ITAV_create()\fR creates a new \fB\s-1OSSL_CMP_ITAV\s0\fR structure and fills it in. -It combines \fBOSSL_CMP_ITAV_new()\fR and \fBOSSL_CMP_ITAV_set0()\fR. -.PP -\&\fBOSSL_CMP_ITAV_set0()\fR sets the \fIitav\fR with an infoType of \fItype\fR and an -infoValue of \fIvalue\fR. This function uses the pointers \fItype\fR and \fIvalue\fR -internally, so they must \fBnot\fR be freed up after the call. -.PP -\&\fBOSSL_CMP_ITAV_get0_type()\fR returns a direct pointer to the infoType in the -\&\fIitav\fR. -.PP -\&\fBOSSL_CMP_ITAV_get0_value()\fR returns a direct pointer to the infoValue in -the \fIitav\fR as generic \fB\s-1ASN1_TYPE\s0\fR pointer. -.PP -\&\fBOSSL_CMP_ITAV_push0_stack_item()\fR pushes \fIitav\fR to the stack pointed to -by \fI*itav_sk_p\fR. It creates a new stack if \fI*itav_sk_p\fR points to \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ITAV_new0_certProfile()\fR creates a new \fB\s-1OSSL_CMP_ITAV\s0\fR structure -of type \fBcertProfile\fR that includes the optionally given list of profile names. -On success, ownership of the list is with the new \fB\s-1OSSL_CMP_ITAV\s0\fR structure. -.PP -\&\fBOSSL_CMP_ITAV_get0_certProfile()\fR on success assigns to \fI*out\fR -an internal pointer to the -list of certificate profile names contained in the infoValue field of \fIitav\fR. -The pointer may be \s-1NULL\s0 if no profile name is included. -It is an error if the infoType of \fIitav\fR is not \fBcertProfile\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210\s0 and \s-1RFC 9480\s0 (and \s-1CRMF\s0 in \s-1RFC 4211\s0). -.PP -OIDs to use as types in \fB\s-1OSSL_CMP_ITAV\s0\fR can be found at -. -The respective OpenSSL NIDs, such as \fBNID_id_it_certProfile\fR, -are defined in the \fI\fR header file. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_ITAV_create()\fR and \fBOSSL_CMP_ITAV_new0_certProfile()\fR -return a pointer to an \s-1ITAV\s0 structure on success, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_ITAV_set0()\fR does not return a value. -.PP -\&\fBOSSL_CMP_ITAV_get0_type()\fR and \fBOSSL_CMP_ITAV_get0_value()\fR -return the respective pointer or \s-1NULL\s0 if their input is \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_ITAV_push0_stack_item()\fR and \fBOSSL_CMP_ITAV_get0_certProfile()\fR -return 1 on success, 0 on error. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following code creates and sets a structure representing a generic -InfoTypeAndValue sequence, using an \s-1OID\s0 created from text as type, and an -integer as value. Afterwards, it is pushed to the \fB\s-1OSSL_CMP_CTX\s0\fR to be later -included in the requests' PKIHeader's genInfo field. -.PP -.Vb 2 -\& ASN1_OBJECT *type = OBJ_txt2obj("1.2.3.4.5", 1); -\& if (type == NULL) ... -\& -\& ASN1_INTEGER *asn1int = ASN1_INTEGER_new(); -\& if (asn1int == NULL || !ASN1_INTEGER_set(asn1int, 12345)) ... -\& -\& ASN1_TYPE *val = ASN1_TYPE_new(); -\& if (val == NULL) ... -\& ASN1_TYPE_set(val, V_ASN1_INTEGER, asn1int); -\& -\& OSSL_CMP_ITAV *itav = OSSL_CMP_ITAV_create(type, val); -\& if (itav == NULL) ... -\& -\& if (!OSSL_CMP_CTX_push0_geninfo_ITAV(ctx, itav)) { -\& OSSL_CMP_ITAV_free(itav); /* also frees type and val */ -\& ... -\& } -\& -\& ... -\& -\& OSSL_CMP_CTX_free(ctx); /* also frees itav */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_CTX_new\fR\|(3), \fBOSSL_CMP_CTX_free\fR\|(3), \fBASN1_TYPE_set\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.PP -\&\fBOSSL_CMP_ITAV_new0_certProfile()\fR and \fBOSSL_CMP_ITAV_get0_certProfile()\fR -were added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_KUR.3ossl b/openssl-install/share/man/man3/OSSL_CMP_KUR.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_KUR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_ALERT.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_ALERT.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_ALERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_CRIT.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_CRIT.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_CRIT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_DEBUG.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_DEBUG.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_DEBUG.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_EMERG.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_EMERG.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_EMERG.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_ERR.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_ERR.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_ERR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_INFO.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_INFO.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_NOTICE.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_NOTICE.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_NOTICE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_TRACE.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_TRACE.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_TRACE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_LOG_WARNING.3ossl b/openssl-install/share/man/man3/OSSL_CMP_LOG_WARNING.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_LOG_WARNING.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_dup.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_get0_certreq_publickey.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_get0_certreq_publickey.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_get0_certreq_publickey.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_get0_header.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_get0_header.3ossl deleted file mode 100644 index 2ca08265..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_get0_header.3ossl +++ /dev/null @@ -1,287 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_MSG_GET0_HEADER 3ossl" -.TH OSSL_CMP_MSG_GET0_HEADER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_MSG_get0_header, -OSSL_CMP_MSG_get_bodytype, -OSSL_CMP_MSG_get0_certreq_publickey, -OSSL_CMP_MSG_update_transactionID, -OSSL_CMP_MSG_update_recipNonce, -OSSL_CMP_CTX_setup_CRM, -OSSL_CMP_MSG_read, -OSSL_CMP_MSG_write, -d2i_OSSL_CMP_MSG_bio, -i2d_OSSL_CMP_MSG_bio -\&\- function(s) manipulating CMP messages -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CMP_PKIHEADER *OSSL_CMP_MSG_get0_header(const OSSL_CMP_MSG *msg); -\& int OSSL_CMP_MSG_get_bodytype(const OSSL_CMP_MSG *msg); -\& X509_PUBKEY *OSSL_CMP_MSG_get0_certreq_publickey(const OSSL_CMP_MSG *msg); -\& int OSSL_CMP_MSG_update_transactionID(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg); -\& int OSSL_CMP_MSG_update_recipNonce(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg); -\& OSSL_CRMF_MSG *OSSL_CMP_CTX_setup_CRM(OSSL_CMP_CTX *ctx, int for_KUR, int rid); -\& OSSL_CMP_MSG *OSSL_CMP_MSG_read(const char *file, OSSL_LIB_CTX *libctx, const char *propq); -\& int OSSL_CMP_MSG_write(const char *file, const OSSL_CMP_MSG *msg); -\& OSSL_CMP_MSG *d2i_OSSL_CMP_MSG_bio(BIO *bio, OSSL_CMP_MSG **msg); -\& int i2d_OSSL_CMP_MSG_bio(BIO *bio, const OSSL_CMP_MSG *msg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_CMP_MSG_get0_header()\fR returns the header of the given \s-1CMP\s0 message. -.PP -\&\fBOSSL_CMP_MSG_get_bodytype()\fR returns the body type of the given \s-1CMP\s0 message. -.PP -\&\fBOSSL_CMP_MSG_get0_certreq_publickey()\fR expects that \fImsg\fR is a certificate request -message and returns the public key in its certificate template if present. -.PP -\&\fBOSSL_CMP_MSG_update_transactionID()\fR updates the transactionID field -in the header of the given message according to the \s-1CMP_CTX.\s0 -If \fIctx\fR does not contain a transaction \s-1ID,\s0 a fresh one is created before. -The message gets re-protected (if protecting requests is required). -.PP -\&\fBOSSL_CMP_MSG_update_recipNonce()\fR updates the recipNonce field -in the header of the given message according to the \s-1CMP_CTX.\s0 -The message gets re-protected (if protecting requests is required). -.PP -\&\fBOSSL_CMP_CTX_setup_CRM()\fR creates a \s-1CRMF\s0 certificate request message -from various information provided in the \s-1CMP\s0 context argument \fIctx\fR -for inclusion in a \s-1CMP\s0 request message based on details contained in \fIctx\fR. -The \fIrid\fR argument defines the request identifier to use, which typically is 0. -.PP -The subject \s-1DN\s0 included in the certificate template is -the first available value of these: -.IP "any subject name in \fIctx\fR set via \fBOSSL_CMP_CTX_set1_subjectName\fR\|(3) \- if it is the NULL-DN (i.e., any empty sequence of RDNs), no subject is included," 4 -.IX Item "any subject name in ctx set via OSSL_CMP_CTX_set1_subjectName - if it is the NULL-DN (i.e., any empty sequence of RDNs), no subject is included," -.PD 0 -.IP "the subject field of any PKCS#10 \s-1CSR\s0 set in \fIctx\fR via \fBOSSL_CMP_CTX_set1_p10CSR\fR\|(3)," 4 -.IX Item "the subject field of any PKCS#10 CSR set in ctx via OSSL_CMP_CTX_set1_p10CSR," -.IP "the subject field of any reference certificate given in \fIctx\fR (see \fBOSSL_CMP_CTX_set1_oldCert\fR\|(3)), but only if \fIfor_KUR\fR is nonzero or the \fIctx\fR does not include a Subject Alternative Name." 4 -.IX Item "the subject field of any reference certificate given in ctx (see OSSL_CMP_CTX_set1_oldCert), but only if for_KUR is nonzero or the ctx does not include a Subject Alternative Name." -.PD -.PP -The public key included is the first available value of these: -.IP "the public key derived from any key set via \fBOSSL_CMP_CTX_set0_newPkey\fR\|(3)," 4 -.IX Item "the public key derived from any key set via OSSL_CMP_CTX_set0_newPkey," -.PD 0 -.IP "the public key of any PKCS#10 \s-1CSR\s0 given in \fIctx\fR," 4 -.IX Item "the public key of any PKCS#10 CSR given in ctx," -.IP "the public key of any reference certificate given in \fIctx\fR (see \fBOSSL_CMP_CTX_set1_oldCert\fR\|(3))," 4 -.IX Item "the public key of any reference certificate given in ctx (see OSSL_CMP_CTX_set1_oldCert)," -.IP "the public key derived from any client's private key set via \fBOSSL_CMP_CTX_set1_pkey\fR\|(3)." 4 -.IX Item "the public key derived from any client's private key set via OSSL_CMP_CTX_set1_pkey." -.PD -.PP -The set of X.509 extensions to include is computed as follows. -If a PKCS#10 \s-1CSR\s0 is present in \fIctx\fR, default extensions are taken from there, -otherwise the empty set is taken as the initial value. -If there is a reference certificate in \fIctx\fR and contains Subject Alternative -Names (SANs) and \fB\s-1OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT\s0\fR is not set, -these override any SANs from the PKCS#10 \s-1CSR.\s0 -The extensions are further augmented or overridden by any extensions with the -same OIDs included in the \fIctx\fR via \fBOSSL_CMP_CTX_set0_reqExtensions\fR\|(3). -The SANs are further overridden by any SANs included in \fIctx\fR via -\&\fBOSSL_CMP_CTX_push1_subjectAltName\fR\|(3). -Finally, policies are overridden by any policies included in \fIctx\fR via -\&\fBOSSL_CMP_CTX_push0_policy\fR\|(3). -.PP -\&\fBOSSL_CMP_CTX_setup_CRM()\fR also sets the sets the regToken control \fBoldCertID\fR -for \s-1KUR\s0 messages using the issuer name and serial number of the reference -certificate, if present. -.PP -\&\fBOSSL_CMP_MSG_read()\fR loads a DER-encoded \s-1OSSL_CMP_MSG\s0 from \fIfile\fR. -.PP -\&\fBOSSL_CMP_MSG_write()\fR stores the given \s-1OSSL_CMP_MSG\s0 to \fIfile\fR in \s-1DER\s0 encoding. -.PP -\&\fBd2i_OSSL_CMP_MSG_bio()\fR parses an \s-1ASN\s0.1\-encoded \s-1OSSL_CMP_MSG\s0 from the \s-1BIO\s0 \fIbio\fR. -It assigns a pointer to the new structure to \fI*msg\fR if \fImsg\fR is not \s-1NULL.\s0 -.PP -\&\fBi2d_OSSL_CMP_MSG_bio()\fR writes the \s-1OSSL_CMP_MSG\s0 \fImsg\fR in \s-1ASN.1\s0 encoding -to \s-1BIO\s0 \fIbio\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_MSG_get0_header()\fR returns the intended pointer value as described above -or \s-1NULL\s0 if the respective entry does not exist and on error. -.PP -\&\fBOSSL_CMP_MSG_get_bodytype()\fR returns the body type or \-1 on error. -.PP -\&\fBOSSL_CMP_MSG_get0_certreq_publickey()\fR returns a public key or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_CTX_setup_CRM()\fR returns a pointer to a \fB\s-1OSSL_CRMF_MSG\s0\fR on success, -\&\s-1NULL\s0 on error. -.PP -\&\fBd2i_OSSL_CMP_MSG_bio()\fR returns the parsed message or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_MSG_read()\fR and \fBd2i_OSSL_CMP_MSG_bio()\fR -return the parsed \s-1CMP\s0 message or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_MSG_write()\fR returns the number of bytes successfully encoded or a -negative value if an error occurs. -.PP -\&\fBi2d_OSSL_CMP_MSG_bio()\fR, \fBOSSL_CMP_MSG_update_transactionID()\fR, -and \fBOSSL_CMP_MSG_update_recipNonce()\fR -return 1 on success, 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_CTX_set1_subjectName\fR\|(3), \fBOSSL_CMP_CTX_set1_p10CSR\fR\|(3), -\&\fBOSSL_CMP_CTX_set1_oldCert\fR\|(3), \fBOSSL_CMP_CTX_set0_newPkey\fR\|(3), -\&\fBOSSL_CMP_CTX_set1_pkey\fR\|(3), \fBOSSL_CMP_CTX_set0_reqExtensions\fR\|(3), -\&\fBOSSL_CMP_CTX_push1_subjectAltName\fR\|(3), \fBOSSL_CMP_CTX_push0_policy\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.PP -\&\fBOSSL_CMP_MSG_update_recipNonce()\fR was added in OpenSSL 3.0.9. -.PP -\&\fBOSSL_CMP_MSG_get0_certreq_publickey()\fR was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_get_bodytype.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_get_bodytype.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_get_bodytype.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_http_perform.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_http_perform.3ossl deleted file mode 100644 index 402668bd..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_http_perform.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_MSG_HTTP_PERFORM 3ossl" -.TH OSSL_CMP_MSG_HTTP_PERFORM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_MSG_http_perform -\&\- client\-side HTTP(S) transfer of a CMP request\-response pair -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CMP_MSG *OSSL_CMP_MSG_http_perform(OSSL_CMP_CTX *ctx, -\& const OSSL_CMP_MSG *req); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_CMP_MSG_http_perform()\fR sends the given PKIMessage \fIreq\fR -to the \s-1CMP\s0 server specified in \fIctx\fR via \fBOSSL_CMP_CTX_set1_server\fR\|(3) -and optionally \fBOSSL_CMP_CTX_set_serverPort\fR\|(3), using -any \*(L"\s-1CMP\s0 alias\*(R" optionally specified via \fBOSSL_CMP_CTX_set1_serverPath\fR\|(3). -The default port is 80 for \s-1HTTP\s0 and 443 for \s-1HTTPS\s0; the default path is \*(L"/\*(R". -On success the function returns the server's response PKIMessage. -.PP -The function makes use of any \s-1HTTP\s0 callback function -set via \fBOSSL_CMP_CTX_set_http_cb\fR\|(3). -It respects any timeout value set via \fBOSSL_CMP_CTX_set_option\fR\|(3) -with an \fB\s-1OSSL_CMP_OPT_MSG_TIMEOUT\s0\fR argument. -It also respects any \s-1HTTP\s0(S) proxy options set via \fBOSSL_CMP_CTX_set1_proxy\fR\|(3) -and \fBOSSL_CMP_CTX_set1_no_proxy\fR\|(3) and the respective environment variables. -Proxying plain \s-1HTTP\s0 is supported directly, -while using a proxy for \s-1HTTPS\s0 connections requires a suitable callback function -such as \fBOSSL_HTTP_proxy_connect\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210. -HTTP\s0 transfer for \s-1CMP\s0 is defined in \s-1RFC 6712.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_MSG_http_perform()\fR returns a \s-1CMP\s0 message on success, else \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_CTX_new\fR\|(3), \fBOSSL_HTTP_proxy_connect\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_it.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_read.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_read.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_read.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_update_recipNonce.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_update_recipNonce.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_update_recipNonce.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_update_transactionID.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_update_transactionID.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_update_transactionID.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_MSG_write.3ossl b/openssl-install/share/man/man3/OSSL_CMP_MSG_write.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_MSG_write.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_P10CR.3ossl b/openssl-install/share/man/man3/OSSL_CMP_P10CR.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_P10CR.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_it.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_new.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKIHEADER_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKISI_dup.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKISI_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKISI_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKISI_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKISI_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKISI_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKISI_it.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKISI_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKISI_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKISI_new.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKISI_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKISI_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_PKISTATUS_it.3ossl b/openssl-install/share/man/man3/OSSL_CMP_PKISTATUS_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_PKISTATUS_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_free.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_free.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_cmp_ctx.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_cmp_ctx.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_cmp_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_custom_ctx.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_custom_ctx.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_get0_custom_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init_trans.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init_trans.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_init_trans.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_new.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_new.3ossl deleted file mode 100644 index e116d3db..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_new.3ossl +++ /dev/null @@ -1,328 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_SRV_CTX_NEW 3ossl" -.TH OSSL_CMP_SRV_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_SRV_process_request, -OSSL_CMP_CTX_server_perform, -OSSL_CMP_SRV_CTX_new, -OSSL_CMP_SRV_CTX_free, -OSSL_CMP_SRV_cert_request_cb_t, -OSSL_CMP_SRV_rr_cb_t, -OSSL_CMP_SRV_certConf_cb_t, -OSSL_CMP_SRV_genm_cb_t, -OSSL_CMP_SRV_error_cb_t, -OSSL_CMP_SRV_pollReq_cb_t, -OSSL_CMP_SRV_CTX_init, -OSSL_CMP_SRV_delayed_delivery_cb_t, -OSSL_CMP_SRV_clean_transaction_cb_t, -OSSL_CMP_SRV_CTX_init_trans, -OSSL_CMP_SRV_CTX_get0_cmp_ctx, -OSSL_CMP_SRV_CTX_get0_custom_ctx, -OSSL_CMP_SRV_CTX_set_send_unprotected_errors, -OSSL_CMP_SRV_CTX_set_accept_unprotected, -OSSL_CMP_SRV_CTX_set_accept_raverified, -OSSL_CMP_SRV_CTX_set_grant_implicit_confirm -\&\- generic functions to set up and control a CMP server -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CMP_MSG *OSSL_CMP_SRV_process_request(OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req); -\& OSSL_CMP_MSG *OSSL_CMP_CTX_server_perform(OSSL_CMP_CTX *client_ctx, -\& const OSSL_CMP_MSG *req); -\& OSSL_CMP_SRV_CTX *OSSL_CMP_SRV_CTX_new(OSSL_LIB_CTX *libctx, const char *propq); -\& void OSSL_CMP_SRV_CTX_free(OSSL_CMP_SRV_CTX *srv_ctx); -\& -\& typedef OSSL_CMP_PKISI *(*OSSL_CMP_SRV_cert_request_cb_t)( -\& OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req, -\& int certReqId, -\& const OSSL_CRMF_MSG *crm, -\& const X509_REQ *p10cr, -\& X509 **certOut, -\& STACK_OF(X509) **chainOut, -\& STACK_OF(X509) **caPubs); -\& typedef OSSL_CMP_PKISI *(*OSSL_CMP_SRV_rr_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req, -\& const X509_NAME *issuer, -\& const ASN1_INTEGER *serial); -\& typedef int (*OSSL_CMP_SRV_genm_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req, -\& STACK_OF(OSSL_CMP_ITAV) *in, -\& STACK_OF(OSSL_CMP_ITAV) **out); -\& typedef void (*OSSL_CMP_SRV_error_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req, -\& const OSSL_CMP_PKISI *statusInfo, -\& const ASN1_INTEGER *errorCode, -\& const OSSL_CMP_PKIFREETEXT *errorDetails); -\& typedef int (*OSSL_CMP_SRV_certConf_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req, -\& int certReqId, -\& const ASN1_OCTET_STRING *certHash, -\& const OSSL_CMP_PKISI *si); -\& typedef int (*OSSL_CMP_SRV_pollReq_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req, -\& int certReqId, -\& OSSL_CMP_MSG **certReq, -\& int64_t *check_after); -\& int OSSL_CMP_SRV_CTX_init(OSSL_CMP_SRV_CTX *srv_ctx, void *custom_ctx, -\& OSSL_CMP_SRV_cert_request_cb_t process_cert_request, -\& OSSL_CMP_SRV_rr_cb_t process_rr, -\& OSSL_CMP_SRV_genm_cb_t process_genm, -\& OSSL_CMP_SRV_error_cb_t process_error, -\& OSSL_CMP_SRV_certConf_cb_t process_certConf, -\& OSSL_CMP_SRV_pollReq_cb_t process_pollReq); -\& typedef int (*OSSL_CMP_SRV_delayed_delivery_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, -\& const OSSL_CMP_MSG *req); -\& typedef int (*OSSL_CMP_SRV_clean_transaction_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, -\& const ASN1_OCTET_STRING *id); -\& int OSSL_CMP_SRV_CTX_init_trans(OSSL_CMP_SRV_CTX *srv_ctx, -\& OSSL_CMP_SRV_delayed_delivery_cb_t delay, -\& OSSL_CMP_SRV_clean_transaction_cb_t clean); -\& -\& OSSL_CMP_CTX *OSSL_CMP_SRV_CTX_get0_cmp_ctx(const OSSL_CMP_SRV_CTX *srv_ctx); -\& void *OSSL_CMP_SRV_CTX_get0_custom_ctx(const OSSL_CMP_SRV_CTX *srv_ctx); -\& -\& int OSSL_CMP_SRV_CTX_set_send_unprotected_errors(OSSL_CMP_SRV_CTX *srv_ctx, -\& int val); -\& int OSSL_CMP_SRV_CTX_set_accept_unprotected(OSSL_CMP_SRV_CTX *srv_ctx, int val); -\& int OSSL_CMP_SRV_CTX_set_accept_raverified(OSSL_CMP_SRV_CTX *srv_ctx, int val); -\& int OSSL_CMP_SRV_CTX_set_grant_implicit_confirm(OSSL_CMP_SRV_CTX *srv_ctx, -\& int val); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_CMP_SRV_process_request()\fR implements the generic aspects of a \s-1CMP\s0 server. -Its arguments are the \fB\s-1OSSL_CMP_SRV_CTX\s0\fR \fIsrv_ctx\fR and the \s-1CMP\s0 request message -\&\fIreq\fR. It does the typical generic checks on \fIreq\fR, calls -the respective callback function (if present) for more specific processing, -and then assembles a result message, which may be a \s-1CMP\s0 error message. -If after return of the function the expression -\&\fIOSSL_CMP_CTX_get_status(OSSL_CMP_SRV_CTX_get0_cmp_ctx(srv_ctx))\fR yields \-1 -then the function has closed the current transaction, -which may be due to normal successful end of the transaction or due to an error. -.PP -\&\fBOSSL_CMP_CTX_server_perform()\fR is an interface to -\&\fBOSSL_CMP_SRV_process_request()\fR that can be used by a \s-1CMP\s0 client -in the same way as \fBOSSL_CMP_MSG_http_perform\fR\|(3). -The \fB\s-1OSSL_CMP_SRV_CTX\s0\fR must be set as \fItransfer_cb_arg\fR of \fIclient_ctx\fR. -.PP -\&\fBOSSL_CMP_SRV_CTX_new()\fR creates and initializes an \fB\s-1OSSL_CMP_SRV_CTX\s0\fR structure -associated with the library context \fIlibctx\fR and property query string -\&\fIpropq\fR, both of which may be \s-1NULL\s0 to select the defaults. -.PP -\&\fBOSSL_CMP_SRV_CTX_free()\fR deletes the given \fIsrv_ctx\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_CMP_SRV_CTX_init()\fR sets in the given \fIsrv_ctx\fR a custom server context -pointer as well as callback functions performing the specific processing of \s-1CMP\s0 -certificate requests, revocation requests, certificate confirmation requests, -general messages, error messages, and poll requests. -All arguments except \fIsrv_ctx\fR may be \s-1NULL.\s0 -If a callback for some message type is not given this means that the respective -type of \s-1CMP\s0 message is not supported by the server. -.PP -\&\fBOSSL_CMP_SRV_CTX_init_trans()\fR sets in \fIsrv_ctx\fR the optional callback -functions for initiating delayed delivery and cleaning up a transaction. -If the function is \s-1NULL\s0 then delivery of responses is never delayed. -Otherwise \fIdelay\fR takes a custom server context and a request message as input. -It must return 1 if delivery of the respective response shall be delayed, -0 if not, and \-1 on error. -If the function is \s-1NULL\s0 then no specific cleanup is performed. -Otherwise \fIclean\fR takes a custom server context and a transaction \s-1ID\s0 pointer -as input, where the pointer is \s-1NULL\s0 in case a new transaction is being started -and otherwise provides the \s-1ID\s0 of the transaction being terminated. -The function should reset the respective portions of the state -and free related memory. -It must return 1 on success and 0 on error. -.PP -\&\fBOSSL_CMP_SRV_CTX_get0_cmp_ctx()\fR returns the \fB\s-1OSSL_CMP_CTX\s0\fR from the \fIsrv_ctx\fR. -.PP -\&\fBOSSL_CMP_SRV_CTX_get0_custom_ctx()\fR returns the custom server context from -\&\fIsrv_ctx\fR that has been set using \fBOSSL_CMP_SRV_CTX_init()\fR. -.PP -\&\fBOSSL_CMP_SRV_CTX_set_send_unprotected_errors()\fR enables sending error messages -and other forms of negative responses unprotected. -.PP -\&\fBOSSL_CMP_SRV_CTX_set_accept_unprotected()\fR enables acceptance of requests -without protection of with invalid protection. -.PP -\&\fBOSSL_CMP_SRV_CTX_set_accept_raverified()\fR enables acceptance of ir/cr/kur -messages with \s-1POPO\s0 'RAVerified'. -.PP -\&\fBOSSL_CMP_SRV_CTX_set_grant_implicit_confirm()\fR enables granting implicit -confirmation of newly enrolled certificates if requested. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210\s0 (and \s-1CRMF\s0 in \s-1RFC 4211\s0). -.PP -So far the \s-1CMP\s0 server implementation is limited to one request per \s-1CMP\s0 message -(and consequently to at most one response component per \s-1CMP\s0 message). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_SRV_CTX_new()\fR returns a \fB\s-1OSSL_CMP_SRV_CTX\s0\fR structure on success, -\&\s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_SRV_CTX_free()\fR does not return a value. -.PP -\&\fBOSSL_CMP_SRV_CTX_get0_cmp_ctx()\fR returns a \fB\s-1OSSL_CMP_CTX\s0\fR structure on success, -\&\s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_SRV_CTX_get0_custom_ctx()\fR returns the custom server context -that has been set using \fBOSSL_CMP_SRV_CTX_init()\fR. -.PP -All other functions return 1 on success, 0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.PP -\&\fBOSSL_CMP_SRV_CTX_init_trans()\fR -supporting delayed delivery of all types of response messages -was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_raverified.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_raverified.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_raverified.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_unprotected.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_unprotected.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_accept_unprotected.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_grant_implicit_confirm.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_grant_implicit_confirm.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_grant_implicit_confirm.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_send_unprotected_errors.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_send_unprotected_errors.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_CTX_set_send_unprotected_errors.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_certConf_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_certConf_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_certConf_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_cert_request_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_cert_request_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_cert_request_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_clean_transaction_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_clean_transaction_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_clean_transaction_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_delayed_delivery_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_delayed_delivery_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_delayed_delivery_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_error_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_error_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_error_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_genm_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_genm_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_genm_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_pollReq_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_pollReq_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_pollReq_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_process_request.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_process_request.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_process_request.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_SRV_rr_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_SRV_rr_cb_t.3ossl deleted file mode 120000 index aae98117..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_SRV_rr_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_SRV_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_STATUSINFO_new.3ossl b/openssl-install/share/man/man3/OSSL_CMP_STATUSINFO_new.3ossl deleted file mode 100644 index 6305929e..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_STATUSINFO_new.3ossl +++ /dev/null @@ -1,197 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_STATUSINFO_NEW 3ossl" -.TH OSSL_CMP_STATUSINFO_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_STATUSINFO_new, -OSSL_CMP_snprint_PKIStatusInfo, -OSSL_CMP_CTX_snprint_PKIStatus -\&\- function(s) for managing the CMP PKIStatus -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CMP_PKISI *OSSL_CMP_STATUSINFO_new(int status, int fail_info, -\& const char *text); -\& char *OSSL_CMP_snprint_PKIStatusInfo(const OSSL_CMP_PKISI *statusInfo, -\& char *buf, size_t bufsize); -\& char *OSSL_CMP_CTX_snprint_PKIStatus(const OSSL_CMP_CTX *ctx, char *buf, -\& size_t bufsize); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This is the PKIStatus \s-1API\s0 for using \s-1CMP\s0 (Certificate Management Protocol) with -OpenSSL. -.PP -\&\fBOSSL_CMP_STATUSINFO_new()\fR creates a new PKIStatusInfo structure -and fills in the given values. -It sets the status field to \fIstatus\fR, -copies \fItext\fR (unless it is \s-1NULL\s0) to statusString, -and interprets \fIfail_info\fR as bit pattern for the failInfo field. -.PP -\&\fBOSSL_CMP_snprint_PKIStatusInfo()\fR places a human-readable string -representing the given statusInfo -in the given buffer, with the given maximal length. -.PP -\&\fBOSSL_CMP_CTX_snprint_PKIStatus()\fR places a human-readable string -representing the PKIStatusInfo components of the \s-1CMP\s0 context \fIctx\fR -in the given buffer, with the given maximal length. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210\s0 (and \s-1CRMF\s0 in \s-1RFC 4211\s0). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_STATUSINFO_new()\fR -returns a pointer to the structure on success, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_CMP_snprint_PKIStatusInfo()\fR and -\&\fBOSSL_CMP_CTX_snprint_PKIStatus()\fR -return a copy of the buffer pointer containing the string or \s-1NULL\s0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_certConf_cb.3ossl b/openssl-install/share/man/man3/OSSL_CMP_certConf_cb.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_certConf_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_certConf_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_certConf_cb_t.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_certConf_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_exec_CR_ses.3ossl b/openssl-install/share/man/man3/OSSL_CMP_exec_CR_ses.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_exec_CR_ses.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_exec_GENM_ses.3ossl b/openssl-install/share/man/man3/OSSL_CMP_exec_GENM_ses.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_exec_GENM_ses.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_exec_IR_ses.3ossl b/openssl-install/share/man/man3/OSSL_CMP_exec_IR_ses.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_exec_IR_ses.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_exec_KUR_ses.3ossl b/openssl-install/share/man/man3/OSSL_CMP_exec_KUR_ses.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_exec_KUR_ses.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_exec_P10CR_ses.3ossl b/openssl-install/share/man/man3/OSSL_CMP_exec_P10CR_ses.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_exec_P10CR_ses.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_exec_RR_ses.3ossl b/openssl-install/share/man/man3/OSSL_CMP_exec_RR_ses.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_exec_RR_ses.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_exec_certreq.3ossl b/openssl-install/share/man/man3/OSSL_CMP_exec_certreq.3ossl deleted file mode 100644 index 0f0a46c0..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_exec_certreq.3ossl +++ /dev/null @@ -1,393 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_EXEC_CERTREQ 3ossl" -.TH OSSL_CMP_EXEC_CERTREQ 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_exec_certreq, -OSSL_CMP_exec_IR_ses, -OSSL_CMP_exec_CR_ses, -OSSL_CMP_exec_P10CR_ses, -OSSL_CMP_exec_KUR_ses, -OSSL_CMP_IR, -OSSL_CMP_CR, -OSSL_CMP_P10CR, -OSSL_CMP_KUR, -OSSL_CMP_try_certreq, -OSSL_CMP_exec_RR_ses, -OSSL_CMP_exec_GENM_ses, -OSSL_CMP_get1_caCerts, -OSSL_CMP_get1_rootCaKeyUpdate, -OSSL_CMP_get1_crlUpdate, -OSSL_CMP_get1_certReqTemplate -\&\- functions implementing CMP client transactions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509 *OSSL_CMP_exec_certreq(OSSL_CMP_CTX *ctx, int req_type, -\& const OSSL_CRMF_MSG *crm); -\& X509 *OSSL_CMP_exec_IR_ses(OSSL_CMP_CTX *ctx); -\& X509 *OSSL_CMP_exec_CR_ses(OSSL_CMP_CTX *ctx); -\& X509 *OSSL_CMP_exec_P10CR_ses(OSSL_CMP_CTX *ctx); -\& X509 *OSSL_CMP_exec_KUR_ses(OSSL_CMP_CTX *ctx); -\& #define OSSL_CMP_IR -\& #define OSSL_CMP_CR -\& #define OSSL_CMP_P10CR -\& #define OSSL_CMP_KUR -\& int OSSL_CMP_try_certreq(OSSL_CMP_CTX *ctx, int req_type, -\& const OSSL_CRMF_MSG *crm, int *checkAfter); -\& int OSSL_CMP_exec_RR_ses(OSSL_CMP_CTX *ctx); -\& -\& STACK_OF(OSSL_CMP_ITAV) *OSSL_CMP_exec_GENM_ses(OSSL_CMP_CTX *ctx); -\& int OSSL_CMP_get1_caCerts(OSSL_CMP_CTX *ctx, STACK_OF(X509) **out); -\& int OSSL_CMP_get1_rootCaKeyUpdate(OSSL_CMP_CTX *ctx, -\& const X509 *oldWithOld, X509 **newWithNew, -\& X509 **newWithOld, X509 **oldWithNew); -\& int OSSL_CMP_get1_crlUpdate(OSSL_CMP_CTX *ctx, const X509 *crlcert, -\& const X509_CRL *last_crl, -\& X509_CRL **crl); -\& int OSSL_CMP_get1_certReqTemplate(OSSL_CMP_CTX *ctx, -\& OSSL_CRMF_CERTTEMPLATE **certTemplate, -\& OSSL_CMP_ATAVS **keySpec); -\&=head1 DESCRIPTION -.Ve -.PP -This is the OpenSSL \s-1API\s0 for doing \s-1CMP\s0 (Certificate Management Protocol) -client-server transactions, i.e., sequences of \s-1CMP\s0 requests and responses. -.PP -All functions take a populated \s-1OSSL_CMP_CTX\s0 structure as their first argument. -Usually the server name, port, and path (\*(L"\s-1CMP\s0 alias\*(R") need to be set, as well as -credentials the client can use for authenticating itself to the server. -In order to authenticate the server the client typically needs a trust store. -The functions return their respective main results directly, while there are -also accessor functions for retrieving various results and status information -from the \fIctx\fR. See \fBOSSL_CMP_CTX_new\fR\|(3) etc. for details. -.PP -The default conveying protocol is \s-1HTTP.\s0 -Timeout values may be given per request-response pair and per transaction. -See \fBOSSL_CMP_MSG_http_perform\fR\|(3) for details. -.PP -\&\fBOSSL_CMP_exec_IR_ses()\fR requests an initial certificate from the given \s-1PKI.\s0 -.PP -\&\fBOSSL_CMP_exec_CR_ses()\fR requests an additional certificate. -.PP -\&\fBOSSL_CMP_exec_P10CR_ses()\fR conveys a legacy PKCS#10 \s-1CSR\s0 requesting a certificate. -.PP -\&\fBOSSL_CMP_exec_KUR_ses()\fR obtains an updated certificate. -.PP -These four types of certificate enrollment are implemented as macros -calling \fBOSSL_CMP_exec_certreq()\fR. -.PP -\&\fBOSSL_CMP_exec_certreq()\fR performs a certificate request of the type specified -by the \fIreq_type\fR parameter, which may be \s-1IR, CR, P10CR,\s0 or \s-1KUR.\s0 -For \s-1IR, CR,\s0 and \s-1KUR,\s0 the certificate template to be used in the request -may be supplied via the \fIcrm\fR parameter pointing to a \s-1CRMF\s0 structure. -Typically \fIcrm\fR is \s-1NULL,\s0 then the template ingredients are taken from \fIctx\fR -and need to be filled in using \fBOSSL_CMP_CTX_set1_subjectName\fR\|(3), -\&\fBOSSL_CMP_CTX_set0_newPkey\fR\|(3), \fBOSSL_CMP_CTX_set1_oldCert\fR\|(3), etc. -For P10CR, \fBOSSL_CMP_CTX_set1_p10CSR\fR\|(3) needs to be used instead. -The enrollment session may be blocked (with polling and sleeping in between) -until the server side can fully process and ultimately answer the request. -.PP -\&\fBOSSL_CMP_try_certreq()\fR is an alternative to the above functions that is -more flexible regarding what to do after receiving a checkAfter value. -When called for the first time (with no certificate request in progress for -the given \fIctx\fR) it starts a new transaction by sending a certificate request -constructed as stated above using the \fIreq_type\fR and optional \fIcrm\fR parameter. -Otherwise (when according to \fIctx\fR a 'waiting' status has been received before) -it continues polling for the pending request -unless the \fIreq_type\fR argument is < 0, which aborts the request. -If the requested certificate is available the function returns 1 and the -caller can use \fBOSSL_CMP_CTX_get0_newCert\fR\|(3) to retrieve the new certificate. -If no error occurred but no certificate is available yet then -\&\fBOSSL_CMP_try_certreq()\fR remembers in the \s-1CMP\s0 context that it should be retried -and returns \-1 after assigning the received checkAfter value -via the output pointer argument (unless it is \s-1NULL\s0). -The checkAfter value indicates the number of seconds the caller should let pass -before trying again. The caller is free to sleep for the given number of seconds -or for some other time and/or to do anything else before retrying by calling -\&\fBOSSL_CMP_try_certreq()\fR again with the same parameter values as before. -\&\fBOSSL_CMP_try_certreq()\fR then polls -to see whether meanwhile the requested certificate is available. -If the caller decides to abort the pending certificate request and provides -a negative value as the \fIreq_type\fR argument then \fBOSSL_CMP_try_certreq()\fR -aborts the \s-1CMP\s0 transaction by sending an error message to the server. -.PP -\&\fBOSSL_CMP_exec_RR_ses()\fR requests the revocation of the certificate -specified in the \fIctx\fR using the issuer \s-1DN\s0 and serial number set by -\&\fBOSSL_CMP_CTX_set1_issuer\fR\|(3) and \fBOSSL_CMP_CTX_set1_serialNumber\fR\|(3), respectively, -otherwise the issuer \s-1DN\s0 and serial number -of the certificate set by \fBOSSL_CMP_CTX_set1_oldCert\fR\|(3), -otherwise the subject \s-1DN\s0 and public key -of the certificate signing request set by \fBOSSL_CMP_CTX_set1_p10CSR\fR\|(3). -\&\s-1RFC 4210\s0 is vague in which PKIStatus should be returned by the server. -We take \*(L"accepted\*(R" and \*(L"grantedWithMods\*(R" as clear success and handle -\&\*(L"revocationWarning\*(R" and \*(L"revocationNotification\*(R" just as warnings because CAs -typically return them as an indication that the certificate was already revoked. -\&\*(L"rejection\*(R" is a clear error. The values \*(L"waiting\*(R" and \*(L"keyUpdateWarning\*(R" -make no sense for revocation and thus are treated as an error as well. -The revocation session may be blocked (with polling and sleeping in between) -until the server can fully process and ultimately answer the request. -.PP -\&\fBOSSL_CMP_exec_GENM_ses()\fR sends a genm general message containing the sequence of -infoType and infoValue pairs (InfoTypeAndValue; short: \fB\s-1ITAV\s0\fR) -optionally provided in the \fIctx\fR using \fBOSSL_CMP_CTX_push0_genm_ITAV\fR\|(3). -The message exchange may be blocked (with polling and sleeping in between) -until the server can fully process and ultimately answer the request. -On success the function records in \fIctx\fR status \fBOSSL_CMP_PKISTATUS_accepted\fR -and returns the list of \fB\s-1ITAV\s0\fRs received in a genp response message. -This can be used, for instance, -with infoType \f(CW\*(C`signKeyPairTypes\*(C'\fR to obtain the set of signature -algorithm identifiers that the \s-1CA\s0 will certify for subject public keys. -See \s-1RFC 4210\s0 section 5.3.19 and appendix E.5 for details. -Functions implementing more specific genm/genp exchanges are described next. -.PP -\&\fBOSSL_CMP_get1_caCerts()\fR uses a genm/genp message exchange with infoType caCerts -to obtain a list of \s-1CA\s0 certificates from the \s-1CMP\s0 server referenced by \fIctx\fR. -On success it assigns to \fI*out\fR the list of certificates received, -which must be freed by the caller. -\&\s-1NULL\s0 output means that no \s-1CA\s0 certificates were provided by the server. -.PP -\&\fBOSSL_CMP_get1_rootCaKeyUpdate()\fR uses a genm request message -with infoType rootCaCert to obtain from the \s-1CMP\s0 server referenced by \fIctx\fR -in a genp response message with infoType rootCaKeyUpdate any update of the -given root \s-1CA\s0 certificate \fIoldWithOld\fR and verifies it as far as possible. -See \s-1RFC 4210\s0 section 4.4 for details. -On success it assigns to \fI*newWithNew\fR the root certificate received. -When the \fInewWithOld\fR and \fIoldWithNew\fR output parameters are not \s-1NULL,\s0 -it assigns to them the corresponding transition certificates. -\&\s-1NULL\s0 means that the respective certificate was not provided by the server. -All certificates obtained this way must be freed by the caller. -.PP -\&\fB\s-1WARNING:\s0\fR -The \fInewWithNew\fR certificate is meant to be a certificate that will be trusted. -The trust placed in it cannot be stronger than the trust placed in -the \fIoldwithold\fR certificate if present, otherwise it cannot be stronger than -the weakest trust in any of the certificates in the trust store of \fIctx\fR. -.PP -\&\fBOSSL_CMP_get1_crlUpdate()\fR uses a genm request message with infoType crlStatusList -to obtain \s-1CRL\s0 from the \s-1CMP\s0 server referenced by \fIctx\fR in a genp response message -with infoType crls. It uses \fIlast_crl\fR and \fIcrlcert\fR to create -a request with a status field as described for \fBOSSL_CMP_CRLSTATUS_create\fR\|(3). -On success it assigns to \fI*crl\fR the \s-1CRL\s0 received. -\&\s-1NULL\s0 means that no \s-1CRL\s0 was provided by the server. -The \s-1CRL\s0 obtained this way must be freed by the caller. -.PP -\&\fBOSSL_CMP_get1_certReqTemplate()\fR uses a genm request message with -infoType certReqTemplate to obtain a certificate request template from the -\&\s-1CMP\s0 server referenced by \fIctx\fR. On success it assigns to \fI*certTemplate\fR -the certificate template received. \s-1NULL\s0 output means that no certificate -request template was provided by the server. -The optional \fIkeySpec\fR output parameter is assigned the key specification -if received, otherwise it set to \s-1NULL.\s0 -Both must be freed by the caller. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210\s0 (and \s-1CRMF\s0 in \s-1RFC 4211\s0). -.PP -The \s-1CMP\s0 client implementation is limited to one request per \s-1CMP\s0 message -(and consequently to at most one response component per \s-1CMP\s0 message). -.PP -When a client obtains from a \s-1CMP\s0 server \s-1CA\s0 certificates that it is going to -trust, for instance via the caPubs field of a certificate response or using -functions like \fBOSSL_CMP_get1_caCerts()\fR and \fBOSSL_CMP_get1_rootCaKeyUpdate()\fR, -authentication of the \s-1CMP\s0 server is particularly critical. -So special care must be taken setting up server authentication in \fIctx\fR -using functions such as -\&\fBOSSL_CMP_CTX_set0_trusted\fR\|(3) (for certificate-based authentication) or -\&\fBOSSL_CMP_CTX_set1_secretValue\fR\|(3) (for MAC-based protection). -If authentication is certificate-based, \fBOSSL_CMP_CTX_get0_validatedSrvCert\fR\|(3) -should be used to obtain the server validated certificate -and perform an authorization check based on it. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_exec_certreq()\fR, \fBOSSL_CMP_exec_IR_ses()\fR, \fBOSSL_CMP_exec_CR_ses()\fR, -\&\fBOSSL_CMP_exec_P10CR_ses()\fR, and \fBOSSL_CMP_exec_KUR_ses()\fR return a -pointer to the newly obtained X509 certificate on success, \s-1NULL\s0 on error. -This pointer will be freed implicitly by \fBOSSL_CMP_CTX_free()\fR or -\&\fBCSSL_CMP_CTX_reinit()\fR. -.PP -\&\fBOSSL_CMP_try_certreq()\fR returns 1 if the requested certificate is available -via \fBOSSL_CMP_CTX_get0_newCert\fR\|(3) -or on successfully aborting a pending certificate request, 0 on error, and \-1 -in case a 'waiting' status has been received and checkAfter value is available. -In the latter case \fBOSSL_CMP_CTX_get0_newCert\fR\|(3) yields \s-1NULL\s0 -and the output parameter \fIcheckAfter\fR has been used to -assign the received value unless \fIcheckAfter\fR is \s-1NULL.\s0 -.PP -\&\fBOSSL_CMP_exec_RR_ses()\fR, \fBOSSL_CMP_get1_caCerts()\fR, -\&\fBOSSL_CMP_get1_rootCaKeyUpdate()\fR, \fBOSSL_CMP_get1_crlUpdate()\fR -and \fBOSSL_CMP_get1_certReqTemplate()\fR -return 1 on success, 0 on error. -.PP -\&\fBOSSL_CMP_exec_GENM_ses()\fR returns \s-1NULL\s0 on error, -otherwise a pointer to the sequence of \fB\s-1ITAV\s0\fR received, which may be empty. -This pointer must be freed by the caller. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -See \s-1OSSL_CMP_CTX\s0 for examples on how to prepare the context for these -functions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_CTX_new\fR\|(3), \fBOSSL_CMP_CTX_free\fR\|(3), -\&\fBOSSL_CMP_CTX_set1_subjectName\fR\|(3), \fBOSSL_CMP_CTX_set0_newPkey\fR\|(3), -\&\fBOSSL_CMP_CTX_set1_p10CSR\fR\|(3), \fBOSSL_CMP_CTX_set1_oldCert\fR\|(3), -\&\fBOSSL_CMP_CTX_get0_newCert\fR\|(3), \fBOSSL_CMP_CTX_push0_genm_ITAV\fR\|(3), -\&\fBOSSL_CMP_MSG_http_perform\fR\|(3), \fBOSSL_CMP_CRLSTATUS_create\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.PP -\&\fBOSSL_CMP_get1_caCerts()\fR and \fBOSSL_CMP_get1_rootCaKeyUpdate()\fR -were added in OpenSSL 3.2. -.PP -Support for delayed delivery of all types of response messages -was added in OpenSSL 3.3. -.PP -\&\fBOSSL_CMP_get1_crlUpdate()\fR and \fBOSSL_CMP_get1_certReqTemplate()\fR -were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_get1_caCerts.3ossl b/openssl-install/share/man/man3/OSSL_CMP_get1_caCerts.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_get1_caCerts.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_get1_certReqTemplate.3ossl b/openssl-install/share/man/man3/OSSL_CMP_get1_certReqTemplate.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_get1_certReqTemplate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_get1_crlUpdate.3ossl b/openssl-install/share/man/man3/OSSL_CMP_get1_crlUpdate.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_get1_crlUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_get1_rootCaKeyUpdate.3ossl b/openssl-install/share/man/man3/OSSL_CMP_get1_rootCaKeyUpdate.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_get1_rootCaKeyUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_log_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_log_cb_t.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_log_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_log_close.3ossl b/openssl-install/share/man/man3/OSSL_CMP_log_close.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_log_close.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_log_open.3ossl b/openssl-install/share/man/man3/OSSL_CMP_log_open.3ossl deleted file mode 100644 index 8057cec9..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_log_open.3ossl +++ /dev/null @@ -1,258 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_LOG_OPEN 3ossl" -.TH OSSL_CMP_LOG_OPEN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_log_open, -OSSL_CMP_log_close, -OSSL_CMP_severity, -OSSL_CMP_LOG_EMERG, -OSSL_CMP_LOG_ALERT, -OSSL_CMP_LOG_CRIT, -OSSL_CMP_LOG_ERR, -OSSL_CMP_LOG_WARNING, -OSSL_CMP_LOG_NOTICE, -OSSL_CMP_LOG_INFO, -OSSL_CMP_LOG_DEBUG, -OSSL_CMP_LOG_TRACE, -.PP -OSSL_CMP_log_cb_t, -OSSL_CMP_print_to_bio, -OSSL_CMP_print_errors_cb -\&\- functions for logging and error reporting -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_CMP_log_open(void); -\& void OSSL_CMP_log_close(void); -\& -\& /* severity level declarations resemble those from syslog.h */ -\& typedef int OSSL_CMP_severity; -\& #define OSSL_CMP_LOG_EMERG 0 -\& #define OSSL_CMP_LOG_ALERT 1 -\& #define OSSL_CMP_LOG_CRIT 2 -\& #define OSSL_CMP_LOG_ERR 3 -\& #define OSSL_CMP_LOG_WARNING 4 -\& #define OSSL_CMP_LOG_NOTICE 5 -\& #define OSSL_CMP_LOG_INFO 6 -\& #define OSSL_CMP_LOG_DEBUG 7 -\& #define OSSL_CMP_LOG_TRACE 8 -\& -\& typedef int (*OSSL_CMP_log_cb_t)(const char *component, -\& const char *file, int line, -\& OSSL_CMP_severity level, const char *msg); -\& int OSSL_CMP_print_to_bio(BIO *bio, const char *component, const char *file, -\& int line, OSSL_CMP_severity level, const char *msg); -\& void OSSL_CMP_print_errors_cb(OSSL_CMP_log_cb_t log_fn); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The logging and error reporting facility described here contains -convenience functions for CMP-specific logging, -including a string prefix mirroring the severity levels of syslog.h, -and enhancements of the error queue mechanism needed for large diagnostic -messages produced by the \s-1CMP\s0 library in case of certificate validation failures. -.PP -When an interesting activity is performed or an error occurs, some detail -should be provided for user information, debugging, and auditing purposes. -A \s-1CMP\s0 application can obtain this information by providing a callback function -with the following type: -.PP -.Vb 3 -\& typedef int (*OSSL_CMP_log_cb_t)(const char *component, -\& const char *file, int line, -\& OSSL_CMP_severity level, const char *msg); -.Ve -.PP -The parameters may provide -some component info (which may be a module name and/or function name) or \s-1NULL,\s0 -a file pathname or \s-1NULL,\s0 -a line number or 0 indicating the source code location, -a severity level, and -a message string describing the nature of the event, terminated by '\en'. -.PP -Even when an activity is successful some warnings may be useful and some degree -of auditing may be required. Therefore, the logging facility supports a severity -level and the callback function has a \fIlevel\fR parameter indicating such a -level, such that error, warning, info, debug, etc. can be treated differently. -The callback is activated only when the severity level is sufficient according -to the current level of verbosity, which by default is \fB\s-1OSSL_CMP_LOG_INFO\s0\fR. -.PP -The callback function may itself do non-trivial tasks like writing to -a log file or remote stream, which in turn may fail. -Therefore, the function should return 1 on success and 0 on failure. -.PP -\&\fBOSSL_CMP_log_open()\fR initializes the CMP-specific logging facility to output -everything to \s-1STDOUT.\s0 It fails if the integrated tracing is disabled or \s-1STDIO\s0 -is not available. It may be called during application startup. -Alternatively, \fBOSSL_CMP_CTX_set_log_cb\fR\|(3) can be used for more flexibility. -As long as neither if the two is used any logging output is ignored. -.PP -\&\fBOSSL_CMP_log_close()\fR may be called when all activities are finished to flush -any pending CMP-specific log output and deallocate related resources. -It may be called multiple times. It does get called at OpenSSL shutdown. -.PP -\&\fBOSSL_CMP_print_to_bio()\fR prints the given component info, filename, line number, -severity level, and log message or error queue message to the given \fIbio\fR. -\&\fIcomponent\fR usually is a function or module name. -If it is \s-1NULL,\s0 empty, or \*(L"(unknown function)\*(R" then \*(L"\s-1CMP\*(R"\s0 is used as fallback. -.PP -\&\fBOSSL_CMP_print_errors_cb()\fR outputs any entries in the OpenSSL error queue. -It is similar to \fBERR_print_errors_cb\fR\|(3) but uses the \s-1CMP\s0 log callback -function \fIlog_fn\fR for uniformity with \s-1CMP\s0 logging if not \s-1NULL.\s0 Otherwise it -prints to \s-1STDERR\s0 using \fBOSSL_CMP_print_to_bio\fR\|(3) (unless \fB\s-1OPENSSL_NO_STDIO\s0\fR -is defined). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_log_close()\fR and \fBOSSL_CMP_print_errors_cb()\fR do not return anything. -.PP -All other functions return 1 on success, 0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CMP_print_errors_cb.3ossl b/openssl-install/share/man/man3/OSSL_CMP_print_errors_cb.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_print_errors_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_print_to_bio.3ossl b/openssl-install/share/man/man3/OSSL_CMP_print_to_bio.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_print_to_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_severity.3ossl b/openssl-install/share/man/man3/OSSL_CMP_severity.3ossl deleted file mode 120000 index 0f6a94cb..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_severity.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_log_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_snprint_PKIStatusInfo.3ossl b/openssl-install/share/man/man3/OSSL_CMP_snprint_PKIStatusInfo.3ossl deleted file mode 120000 index 62f2c527..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_snprint_PKIStatusInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_STATUSINFO_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_transfer_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_CMP_transfer_cb_t.3ossl deleted file mode 120000 index 3b0b76c7..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_transfer_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_try_certreq.3ossl b/openssl-install/share/man/man3/OSSL_CMP_try_certreq.3ossl deleted file mode 120000 index e06fb1ca..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_try_certreq.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_exec_certreq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_validate_cert_path.3ossl b/openssl-install/share/man/man3/OSSL_CMP_validate_cert_path.3ossl deleted file mode 120000 index 2afd0f9a..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_validate_cert_path.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_validate_msg.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CMP_validate_msg.3ossl b/openssl-install/share/man/man3/OSSL_CMP_validate_msg.3ossl deleted file mode 100644 index acf5e5cf..00000000 --- a/openssl-install/share/man/man3/OSSL_CMP_validate_msg.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CMP_VALIDATE_MSG 3ossl" -.TH OSSL_CMP_VALIDATE_MSG 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CMP_validate_msg, -OSSL_CMP_validate_cert_path -\&\- functions for verifying CMP message protection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 4 -\& #include -\& int OSSL_CMP_validate_msg(OSSL_CMP_CTX *ctx, OSSL_CMP_MSG *msg); -\& int OSSL_CMP_validate_cert_path(const OSSL_CMP_CTX *ctx, -\& X509_STORE *trusted_store, X509 *cert); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This is the \s-1API\s0 for validating the protection of \s-1CMP\s0 messages, -which includes validating \s-1CMP\s0 message sender certificates and their paths -while optionally checking the revocation status of the certificates(s). -.PP -\&\fBOSSL_CMP_validate_msg()\fR validates the protection of the given \fImsg\fR, -which must be signature-based or using password-based \s-1MAC\s0 (\s-1PBM\s0). -In the former case a suitable trust anchor must be given in the \s-1CMP\s0 context -\&\fIctx\fR, and in the latter case the matching secret must have been set there -using \fBOSSL_CMP_CTX_set1_secretValue\fR\|(3). -.PP -In case of signature algorithm, the certificate to use for the signature check -is preferably the one provided by a call to \fBOSSL_CMP_CTX_set1_srvCert\fR\|(3). -If no such sender cert has been pinned then candidate sender certificates are -taken from the list of certificates received in the \fImsg\fR extraCerts, then any -certificates provided before via \fBOSSL_CMP_CTX_set1_untrusted\fR\|(3), and -then all trusted certificates provided via \fBOSSL_CMP_CTX_set0_trusted\fR\|(3). -A candidate certificate is acceptable only if it is currently valid -(or the trust store contains a verification callback that overrides the verdict -that the certificate is expired or not yet valid), its subject \s-1DN\s0 matches -the \fImsg\fR sender \s-1DN\s0 (as far as present), and its subject key identifier -is present and matches the senderKID (as far as the latter is present). -Each acceptable cert is tried in the given order to see if the message -signature check succeeds and the cert and its path can be verified -using any trust store set via \fBOSSL_CMP_CTX_set0_trusted\fR\|(3). -.PP -If the option \s-1OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR\s0 was set by calling -\&\fBOSSL_CMP_CTX_set_option\fR\|(3), for an Initialization Response (\s-1IP\s0) message -any self-issued certificate from the \fImsg\fR extraCerts field may be used -as a trust anchor for the path verification of an 'acceptable' cert if it can be -used also to validate the issued certificate returned in the \s-1IP\s0 message. This is -according to \s-1TS 33.310\s0 [Network Domain Security (\s-1NDS\s0); Authentication Framework -(\s-1AF\s0)] document specified by The 3rd Generation Partnership Project (3GPP). -Note that using this option is dangerous as the certificate obtained this way -has not been authenticated (at least not at \s-1CMP\s0 level). -Taking it over as a trust anchor implements trust-on-first-use (\s-1TOFU\s0). -.PP -Any cert that has been found as described above is cached and tried first when -validating the signatures of subsequent messages in the same transaction. -.PP -\&\fBOSSL_CMP_validate_cert_path()\fR attempts to validate the given certificate and its -path using the given store of trusted certs (possibly including CRLs and a cert -verification callback) and non-trusted intermediate certs from the \fIctx\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1CMP\s0 is defined in \s-1RFC 4210\s0 (and \s-1CRMF\s0 in \s-1RFC 4211\s0). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CMP_validate_msg()\fR and \fBOSSL_CMP_validate_cert_path()\fR -return 1 on success, 0 on error or validation failed. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_CMP_CTX_new\fR\|(3), \fBOSSL_CMP_exec_certreq\fR\|(3), -\&\fBOSSL_CMP_CTX_set1_secretValue\fR\|(3), \fBOSSL_CMP_CTX_set1_srvCert\fR\|(3), -\&\fBOSSL_CMP_CTX_set1_untrusted\fR\|(3), \fBOSSL_CMP_CTX_set0_trusted\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CMP\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CORE_MAKE_FUNC.3ossl b/openssl-install/share/man/man3/OSSL_CORE_MAKE_FUNC.3ossl deleted file mode 100644 index d188b40a..00000000 --- a/openssl-install/share/man/man3/OSSL_CORE_MAKE_FUNC.3ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CORE_MAKE_FUNC 3ossl" -.TH OSSL_CORE_MAKE_FUNC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CORE_MAKE_FUNC, -SSL_OP_BIT, -EXT_UTF8STRING -\&\- OpenSSL reserved symbols -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define OSSL_CORE_MAKE_FUNC(type,name,args) -\& #define SSL_OP_BIT(n) -\& #define EXT_UTF8STRING(nid) -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -There are certain macros that may appear in OpenSSL header files that are -reserved for internal use. They should not be used by applications or assumed -to exist. -.PP -All the macros listed in the synopsis above are reserved. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Not applicable. -.SH "HISTORY" -.IX Header "HISTORY" -The macros described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_dup.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTID_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTID_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_gen.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTID_gen.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_gen.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_issuer.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_issuer.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_serialNumber.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_serialNumber.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_get0_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTID_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTID_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTID_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_dup.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_fill.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_fill.3ossl deleted file mode 120000 index 2c667cb6..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_fill.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set0_validity.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_extensions.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_extensions.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_issuer.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_issuer.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_publicKey.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_publicKey.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_publicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_serialNumber.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_serialNumber.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_subject.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_subject.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_get0_subject.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_CERTTEMPLATE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_ENCRYPTEDVALUE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSGS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSGS_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSGS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_verify_popo.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSGS_verify_popo.3ossl deleted file mode 120000 index 2c667cb6..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSGS_verify_popo.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set0_validity.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_create_popo.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_create_popo.3ossl deleted file mode 120000 index 2c667cb6..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_create_popo.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set0_validity.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_dup.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_authenticator.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_authenticator.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_authenticator.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_oldCertID.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_oldCertID.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_oldCertID.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_regToken.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_regToken.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regCtrl_regToken.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_certReq.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_certReq.3ossl deleted file mode 120000 index c5f291b7..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_certReq.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_utf8Pairs.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_utf8Pairs.3ossl deleted file mode 120000 index c5f291b7..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_regInfo_utf8Pairs.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_tmpl.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_tmpl.3ossl deleted file mode 100644 index b7dd3dd3..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get0_tmpl.3ossl +++ /dev/null @@ -1,235 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CRMF_MSG_GET0_TMPL 3ossl" -.TH OSSL_CRMF_MSG_GET0_TMPL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CRMF_MSG_get0_tmpl, -OSSL_CRMF_CERTTEMPLATE_get0_publicKey, -OSSL_CRMF_CERTTEMPLATE_get0_subject, -OSSL_CRMF_CERTTEMPLATE_get0_issuer, -OSSL_CRMF_CERTTEMPLATE_get0_serialNumber, -OSSL_CRMF_CERTTEMPLATE_get0_extensions, -OSSL_CRMF_CERTID_get0_serialNumber, -OSSL_CRMF_CERTID_get0_issuer, -OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert, -OSSL_CRMF_MSG_get_certReqId -\&\- functions reading from CRMF CertReqMsg structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_CRMF_CERTTEMPLATE *OSSL_CRMF_MSG_get0_tmpl(const OSSL_CRMF_MSG *crm); -\& X509_PUBKEY -\& *OSSL_CRMF_CERTTEMPLATE_get0_publicKey(const OSSL_CRMF_CERTTEMPLATE *tmpl); -\& const X509_NAME -\& *OSSL_CRMF_CERTTEMPLATE_get0_subject(const OSSL_CRMF_CERTTEMPLATE *tmpl); -\& const X509_NAME -\& *OSSL_CRMF_CERTTEMPLATE_get0_issuer(const OSSL_CRMF_CERTTEMPLATE *tmpl); -\& const ASN1_INTEGER -\& *OSSL_CRMF_CERTTEMPLATE_get0_serialNumber(const OSSL_CRMF_CERTTEMPLATE *tmpl); -\& X509_EXTENSIONS -\& *OSSL_CRMF_CERTTEMPLATE_get0_extensions(const OSSL_CRMF_CERTTEMPLATE *tmpl); -\& -\& const ASN1_INTEGER -\& *OSSL_CRMF_CERTID_get0_serialNumber(const OSSL_CRMF_CERTID *cid); -\& const X509_NAME *OSSL_CRMF_CERTID_get0_issuer(const OSSL_CRMF_CERTID *cid); -\& -\& X509 -\& *OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert(const OSSL_CRMF_ENCRYPTEDVALUE *ecert, -\& OSSL_LIB_CTX *libctx, const char *propq, -\& EVP_PKEY *pkey); -\& -\& int OSSL_CRMF_MSG_get_certReqId(const OSSL_CRMF_MSG *crm); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_CRMF_MSG_get0_tmpl()\fR retrieves the certificate template of \fIcrm\fR. -.PP -\&\fBOSSL_CRMF_CERTTEMPLATE_get0_publicKey()\fR retrieves the public key of the -given certificate template \fItmpl\fR. -.PP -\&\fBOSSL_CRMF_CERTTEMPLATE_get0_subject()\fR retrieves the subject name of the -given certificate template \fItmpl\fR. -.PP -\&\fBOSSL_CRMF_CERTTEMPLATE_get0_issuer()\fR retrieves the issuer name of the -given certificate template \fItmpl\fR. -.PP -\&\fBOSSL_CRMF_CERTTEMPLATE_get0_serialNumber()\fR retrieves the serialNumber of the -given certificate template \fItmpl\fR. -.PP -\&\fBOSSL_CRMF_CERTTEMPLATE_get0_extensions()\fR retrieves the X.509 extensions -of the given certificate template \fItmpl\fR, or \s-1NULL\s0 if not present. -.PP -OSSL_CRMF_CERTID_get0_serialNumber retrieves the serialNumber -of the given CertId \fIcid\fR. -.PP -OSSL_CRMF_CERTID_get0_issuer retrieves the issuer name -of the given CertId \fIcid\fR, which must be of \s-1ASN.1\s0 type \s-1GEN_DIRNAME.\s0 -.PP -\&\fBOSSL_CRMF_ENCRYPTEDVALUE_get1_encCert()\fR decrypts the certificate in the given -encryptedValue \fIecert\fR, using the private key \fIpkey\fR, library context -\&\fIlibctx\fR and property query string \fIpropq\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)). -This is needed for the indirect \s-1POPO\s0 method as in \s-1RFC 4210\s0 section 5.2.8.2. -The function returns the decrypted certificate as a copy, leaving its ownership -with the caller, who is responsible for freeing it. -.PP -\&\fBOSSL_CRMF_MSG_get_certReqId()\fR retrieves the certReqId of \fIcrm\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CRMF_MSG_get_certReqId()\fR returns the certificate request \s-1ID\s0 as a -nonnegative integer or \-1 on error. -.PP -All other functions return a pointer with the intended result or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1RFC 4211\s0 -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CRMF\s0 support was added in OpenSSL 3.0. -.PP -\&\fBOSSL_CRMF_CERTTEMPLATE_get0_publicKey()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get_certReqId.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_get_certReqId.3ossl deleted file mode 120000 index b05faabc..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_get_certReqId.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_get0_tmpl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_push0_extension.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_push0_extension.3ossl deleted file mode 120000 index 2c667cb6..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_push0_extension.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set0_validity.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_SinglePubInfo.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_SinglePubInfo.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_SinglePubInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_extensions.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_extensions.3ossl deleted file mode 120000 index 2c667cb6..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set0_validity.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_validity.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_validity.3ossl deleted file mode 100644 index e2d3d6f0..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set0_validity.3ossl +++ /dev/null @@ -1,247 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CRMF_MSG_SET0_VALIDITY 3ossl" -.TH OSSL_CRMF_MSG_SET0_VALIDITY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CRMF_MSG_set0_validity, -OSSL_CRMF_MSG_set_certReqId, -OSSL_CRMF_CERTTEMPLATE_fill, -OSSL_CRMF_MSG_set0_extensions, -OSSL_CRMF_MSG_push0_extension, -OSSL_CRMF_MSG_create_popo, -OSSL_CRMF_MSGS_verify_popo -\&\- functions populating and verifying CRMF CertReqMsg structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_CRMF_MSG_set0_validity(OSSL_CRMF_MSG *crm, -\& ASN1_TIME *notBefore, ASN1_TIME *notAfter); -\& -\& int OSSL_CRMF_MSG_set_certReqId(OSSL_CRMF_MSG *crm, int rid); -\& -\& int OSSL_CRMF_CERTTEMPLATE_fill(OSSL_CRMF_CERTTEMPLATE *tmpl, -\& EVP_PKEY *pubkey, -\& const X509_NAME *subject, -\& const X509_NAME *issuer, -\& const ASN1_INTEGER *serial); -\& -\& int OSSL_CRMF_MSG_set0_extensions(OSSL_CRMF_MSG *crm, X509_EXTENSIONS *exts); -\& -\& int OSSL_CRMF_MSG_push0_extension(OSSL_CRMF_MSG *crm, X509_EXTENSION *ext); -\& -\& int OSSL_CRMF_MSG_create_popo(int meth, OSSL_CRMF_MSG *crm, -\& EVP_PKEY *pkey, const EVP_MD *digest, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& -\& int OSSL_CRMF_MSGS_verify_popo(const OSSL_CRMF_MSGS *reqs, -\& int rid, int acceptRAVerified, -\& OSSL_LIB_CTX *libctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_CRMF_MSG_set0_validity()\fR sets the \fInotBefore\fR and \fInotAfter\fR fields -as validity constraints in the certTemplate of \fIcrm\fR. -Any of the \fInotBefore\fR and \fInotAfter\fR parameters may be \s-1NULL,\s0 -which means no constraint for the respective field. -On success ownership of \fInotBefore\fR and \fInotAfter\fR is transferred to \fIcrm\fR. -.PP -\&\fBOSSL_CRMF_MSG_set_certReqId()\fR sets \fIrid\fR as the certReqId of \fIcrm\fR. -.PP -\&\fBOSSL_CRMF_CERTTEMPLATE_fill()\fR sets those fields of the certTemplate \fItmpl\fR -for which non-NULL values are provided: \fIpubkey\fR, \fIsubject\fR, \fIissuer\fR, -and/or \fIserial\fR. -X.509 extensions may be set using \fBOSSL_CRMF_MSG_set0_extensions()\fR. -On success the reference counter of the \fIpubkey\fR (if given) is incremented, -while the \fIsubject\fR, \fIissuer\fR, and \fIserial\fR structures (if given) are copied. -.PP -\&\fBOSSL_CRMF_MSG_set0_extensions()\fR sets \fIexts\fR as the extensions in the -certTemplate of \fIcrm\fR. Frees any pre-existing ones and consumes \fIexts\fR. -.PP -\&\fBOSSL_CRMF_MSG_push0_extension()\fR pushes the X509 extension \fIext\fR to the -extensions in the certTemplate of \fIcrm\fR. Consumes \fIext\fR. -.PP -\&\fBOSSL_CRMF_MSG_create_popo()\fR creates and sets the Proof-of-Possession (\s-1POPO\s0) -according to the method \fImeth\fR in \fIcrm\fR. -The library context \fIlibctx\fR and property query string \fIpropq\fR, -may be \s-1NULL\s0 to select the defaults. -In case the method is \s-1OSSL_CRMF_POPO_SIGNATURE\s0 the \s-1POPO\s0 is calculated -using the private key \fIpkey\fR and the digest method \fIdigest\fR, -where the \fIdigest\fR argument is ignored if \fIpkey\fR is of a type (such as -Ed25519 and Ed448) that is implicitly associated with a digest algorithm. -.PP -\&\fImeth\fR can be one of the following: -.IP "\(bu" 8 -\&\s-1OSSL_CRMF_POPO_NONE\s0 \- \s-1RFC 4211,\s0 section 4, \s-1POP\s0 field omitted. -\&\s-1CA/RA\s0 uses out-of-band method to verify \s-1POP.\s0 Note that servers may fail in this -case, resulting for instance in \s-1HTTP\s0 error code 500 (Internal error). -.IP "\(bu" 8 -\&\s-1OSSL_CRMF_POPO_RAVERIFIED\s0 \- \s-1RFC 4211,\s0 section 4, explicit indication -that the \s-1RA\s0 has already verified the \s-1POP.\s0 -.IP "\(bu" 8 -\&\s-1OSSL_CRMF_POPO_SIGNATURE\s0 \- \s-1RFC 4211,\s0 section 4.1, only case 3 supported -so far. -.IP "\(bu" 8 -\&\s-1OSSL_CRMF_POPO_KEYENC\s0 \- \s-1RFC 4211,\s0 section 4.2, only indirect method -(subsequentMessage/enccert) supported, -challenge-response exchange (challengeResp) not yet supported. -.IP "\(bu" 8 -\&\s-1OSSL_CRMF_POPO_KEYAGREE\s0 \- \s-1RFC 4211,\s0 section 4.3, not yet supported. -.PP -OSSL_CRMF_MSGS_verify_popo verifies the Proof-of-Possession of the request with -the given \fIrid\fR in the list of \fIreqs\fR. Optionally accepts RAVerified. It can -make use of the library context \fIlibctx\fR and property query string \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return 1 on success, 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1RFC 4211\s0 -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CRMF\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_authenticator.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_authenticator.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_authenticator.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_oldCertID.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_oldCertID.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_oldCertID.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl deleted file mode 100644 index 163fec64..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl +++ /dev/null @@ -1,261 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CRMF_MSG_SET1_REGCTRL_REGTOKEN 3ossl" -.TH OSSL_CRMF_MSG_SET1_REGCTRL_REGTOKEN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CRMF_MSG_get0_regCtrl_regToken, -OSSL_CRMF_MSG_set1_regCtrl_regToken, -OSSL_CRMF_MSG_get0_regCtrl_authenticator, -OSSL_CRMF_MSG_set1_regCtrl_authenticator, -OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo, -OSSL_CRMF_MSG_set0_SinglePubInfo, -OSSL_CRMF_MSG_set_PKIPublicationInfo_action, -OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo, -OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo, -OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey, -OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey, -OSSL_CRMF_MSG_get0_regCtrl_oldCertID, -OSSL_CRMF_MSG_set1_regCtrl_oldCertID, -OSSL_CRMF_CERTID_gen -\&\- functions getting or setting CRMF Registration Controls -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_UTF8STRING -\& *OSSL_CRMF_MSG_get0_regCtrl_regToken(const OSSL_CRMF_MSG *msg); -\& int OSSL_CRMF_MSG_set1_regCtrl_regToken(OSSL_CRMF_MSG *msg, -\& const ASN1_UTF8STRING *tok); -\& ASN1_UTF8STRING -\& *OSSL_CRMF_MSG_get0_regCtrl_authenticator(const OSSL_CRMF_MSG *msg); -\& int OSSL_CRMF_MSG_set1_regCtrl_authenticator(OSSL_CRMF_MSG *msg, -\& const ASN1_UTF8STRING *auth); -\& int OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo( -\& OSSL_CRMF_PKIPUBLICATIONINFO *pi, -\& OSSL_CRMF_SINGLEPUBINFO *spi); -\& int OSSL_CRMF_MSG_set0_SinglePubInfo(OSSL_CRMF_SINGLEPUBINFO *spi, -\& int method, GENERAL_NAME *nm); -\& int OSSL_CRMF_MSG_set_PKIPublicationInfo_action( -\& OSSL_CRMF_PKIPUBLICATIONINFO *pi, int action); -\& OSSL_CRMF_PKIPUBLICATIONINFO -\& *OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo(const OSSL_CRMF_MSG *msg); -\& int OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo(OSSL_CRMF_MSG *msg, -\& const OSSL_CRMF_PKIPUBLICATIONINFO *pi); -\& X509_PUBKEY -\& *OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey(const OSSL_CRMF_MSG *msg); -\& int OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey(OSSL_CRMF_MSG *msg, -\& const X509_PUBKEY *pubkey); -\& OSSL_CRMF_CERTID -\& *OSSL_CRMF_MSG_get0_regCtrl_oldCertID(const OSSL_CRMF_MSG *msg); -\& int OSSL_CRMF_MSG_set1_regCtrl_oldCertID(OSSL_CRMF_MSG *msg, -\& const OSSL_CRMF_CERTID *cid); -\& OSSL_CRMF_CERTID *OSSL_CRMF_CERTID_gen(const X509_NAME *issuer, -\& const ASN1_INTEGER *serial); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Each of the \fBOSSL_CRMF_MSG_get0_regCtrl_X()\fR functions -returns the respective control X in the given \fImsg\fR, if present. -.PP -\&\fBOSSL_CRMF_MSG_set1_regCtrl_regToken()\fR sets the regToken control in the given -\&\fImsg\fR copying the given \fItok\fR as value. See \s-1RFC 4211,\s0 section 6.1. -.PP -\&\fBOSSL_CRMF_MSG_set1_regCtrl_authenticator()\fR sets the authenticator control in -the given \fImsg\fR copying the given \fIauth\fR as value. See \s-1RFC 4211,\s0 section 6.2. -.PP -\&\fBOSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo()\fR pushes the given \fIspi\fR -to \fIsi\fR. Consumes the \fIspi\fR pointer. -.PP -\&\fBOSSL_CRMF_MSG_set0_SinglePubInfo()\fR sets in the given SinglePubInfo \fIspi\fR -the \fImethod\fR and publication location, in the form of a GeneralName, \fInm\fR. -The publication location is optional, and therefore \fInm\fR may be \s-1NULL.\s0 -The function consumes the \fInm\fR pointer if present. -Available methods are: - # define \s-1OSSL_CRMF_PUB_METHOD_DONTCARE 0\s0 - # define \s-1OSSL_CRMF_PUB_METHOD_X500\s0 1 - # define \s-1OSSL_CRMF_PUB_METHOD_WEB\s0 2 - # define \s-1OSSL_CRMF_PUB_METHOD_LDAP\s0 3 -.PP -\&\fBOSSL_CRMF_MSG_set_PKIPublicationInfo_action()\fR sets the action in the given \fIpi\fR -using the given \fIaction\fR as value. See \s-1RFC 4211,\s0 section 6.3. -Available actions are: - # define \s-1OSSL_CRMF_PUB_ACTION_DONTPUBLISH\s0 0 - # define \s-1OSSL_CRMF_PUB_ACTION_PLEASEPUBLISH 1\s0 -.PP -\&\fBOSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo()\fR sets the pkiPublicationInfo -control in the given \fImsg\fR copying the given \fItok\fR as value. See \s-1RFC 4211,\s0 -section 6.3. -.PP -\&\fBOSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey()\fR sets the protocolEncrKey control in -the given \fImsg\fR copying the given \fIpubkey\fR as value. See \s-1RFC 4211\s0 section 6.6. -.PP -\&\fBOSSL_CRMF_MSG_set1_regCtrl_oldCertID()\fR sets the \fBoldCertID\fR regToken control in -the given \fImsg\fR copying the given \fIcid\fR as value. See \s-1RFC 4211,\s0 section 6.5. -.PP -OSSL_CRMF_CERTID_gen produces an OSSL_CRMF_CERTID_gen structure copying the -given \fIissuer\fR name and \fIserial\fR number. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All OSSL_CRMF_MSG_get0_*() functions -return the respective pointer value or \s-1NULL\s0 if not present and on error. -.PP -All OSSL_CRMF_MSG_set1_*() functions return 1 on success, 0 on error. -.PP -\&\fBOSSL_CRMF_CERTID_gen()\fR returns a pointer to the resulting structure -or \s-1NULL\s0 on error. -.SH "NOTES" -.IX Header "NOTES" -A function \fBOSSL_CRMF_MSG_set1_regCtrl_pkiArchiveOptions()\fR for setting an -Archive Options Control is not yet implemented due to missing features to -create the needed \s-1OSSL_CRMF_PKIARCHIVEOPTINS\s0 content. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1RFC 4211\s0 -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CRMF\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl deleted file mode 100644 index e0828eb6..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CRMF_MSG_SET1_REGINFO_CERTREQ 3ossl" -.TH OSSL_CRMF_MSG_SET1_REGINFO_CERTREQ 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CRMF_MSG_get0_regInfo_utf8Pairs, -OSSL_CRMF_MSG_set1_regInfo_utf8Pairs, -OSSL_CRMF_MSG_get0_regInfo_certReq, -OSSL_CRMF_MSG_set1_regInfo_certReq -\&\- functions getting or setting CRMF Registration Info -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_UTF8STRING -\& *OSSL_CRMF_MSG_get0_regInfo_utf8Pairs(const OSSL_CRMF_MSG *msg); -\& int OSSL_CRMF_MSG_set1_regInfo_utf8Pairs(OSSL_CRMF_MSG *msg, -\& const ASN1_UTF8STRING *utf8pairs); -\& OSSL_CRMF_CERTREQUEST -\& *OSSL_CRMF_MSG_get0_regInfo_certReq(const OSSL_CRMF_MSG *msg); -\& int OSSL_CRMF_MSG_set1_regInfo_certReq(OSSL_CRMF_MSG *msg, -\& const OSSL_CRMF_CERTREQUEST *cr); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_CRMF_MSG_get0_regInfo_utf8Pairs()\fR returns the first utf8Pairs regInfo -in the given \fImsg\fR, if present. -.PP -\&\fBOSSL_CRMF_MSG_set1_regInfo_utf8Pairs()\fR adds a copy of the given \fIutf8pairs\fR -value as utf8Pairs regInfo to the given \fImsg\fR. See \s-1RFC 4211\s0 section 7.1. -.PP -\&\fBOSSL_CRMF_MSG_get0_regInfo_certReq()\fR returns the first certReq regInfo -in the given \fImsg\fR, if present. -.PP -\&\fBOSSL_CRMF_MSG_set1_regInfo_certReq()\fR adds a copy of the given \fIcr\fR value -as certReq regInfo to the given \fImsg\fR. See \s-1RFC 4211\s0 section 7.2. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All get0_*() functions return the respective pointer value, \s-1NULL\s0 if not present. -.PP -All set1_*() functions return 1 on success, 0 on error. -.SH "NOTES" -.IX Header "NOTES" -Calling the set1_*() functions multiple times -adds multiple instances of the respective -control to the regInfo structure of the given \fImsg\fR. While \s-1RFC 4211\s0 expects -multiple utf8Pairs in one regInfo structure, it does not allow multiple certReq. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1RFC 4211\s0 -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CRMF\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_utf8Pairs.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_utf8Pairs.3ossl deleted file mode 120000 index c5f291b7..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set1_regInfo_utf8Pairs.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regInfo_certReq.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set_PKIPublicationInfo_action.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set_PKIPublicationInfo_action.3ossl deleted file mode 120000 index 7ca31fcd..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set_PKIPublicationInfo_action.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set1_regCtrl_regToken.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set_certReqId.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_MSG_set_certReqId.3ossl deleted file mode 120000 index 2c667cb6..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_MSG_set_certReqId.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_MSG_set0_validity.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_PBMPARAMETER_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_PKIPUBLICATIONINFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_free.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_it.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_SINGLEPUBINFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_pbm_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_pbm_new.3ossl deleted file mode 120000 index 3861e0cf..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_pbm_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CRMF_pbmp_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_CRMF_pbmp_new.3ossl b/openssl-install/share/man/man3/OSSL_CRMF_pbmp_new.3ossl deleted file mode 100644 index a320e648..00000000 --- a/openssl-install/share/man/man3/OSSL_CRMF_pbmp_new.3ossl +++ /dev/null @@ -1,223 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_CRMF_PBMP_NEW 3ossl" -.TH OSSL_CRMF_PBMP_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_CRMF_pbm_new, -OSSL_CRMF_pbmp_new -\&\- functions for producing Password\-Based MAC (PBM) -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_CRMF_pbm_new(OSSL_LIB_CTX *libctx, const char *propq, -\& const OSSL_CRMF_PBMPARAMETER *pbmp, -\& const unsigned char *msg, size_t msglen, -\& const unsigned char *sec, size_t seclen, -\& unsigned char **mac, size_t *maclen); -\& -\& OSSL_CRMF_PBMPARAMETER *OSSL_CRMF_pbmp_new(OSSL_LIB_CTX *libctx, size_t saltlen, -\& int owfnid, size_t itercnt, -\& int macnid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_CRMF_pbm_new()\fR generates a \s-1PBM\s0 (Password-Based \s-1MAC\s0) based on given \s-1PBM\s0 -parameters \fIpbmp\fR, message \fImsg\fR, and secret \fIsec\fR, along with the respective -lengths \fImsglen\fR and \fIseclen\fR. -The optional library context \fIlibctx\fR and \fIpropq\fR parameters may be used -to influence the selection of the \s-1MAC\s0 algorithm referenced in the \fIpbmp\fR; -see \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further information. -On success writes the address of the newly -allocated \s-1MAC\s0 via the \fImac\fR reference parameter and writes the length via the -\&\fImaclen\fR reference parameter unless it its \s-1NULL.\s0 -.PP -\&\fBOSSL_CRMF_pbmp_new()\fR initializes and returns a new \fBPBMParameter\fR structure -with a new random salt of given length \fIsaltlen\fR, -\&\s-1OWF\s0 (one-way function) \s-1NID\s0 \fIowfnid\fR, \s-1OWF\s0 iteration count \fIitercnt\fR, -and \s-1MAC NID\s0 \fImacnid\fR. -The library context \fIlibctx\fR parameter may be used to select the provider -for the random number generation (\s-1DRBG\s0) and may be \s-1NULL\s0 for the default. -.SH "NOTES" -.IX Header "NOTES" -The algorithms for the \s-1OWF\s0 (one-way function) and for the \s-1MAC\s0 (message -authentication code) may be any with a \s-1NID\s0 defined in \fI\fR. -As specified by \s-1RFC 4210,\s0 these should include NID_hmac_sha1. -.PP -\&\s-1RFC 4210\s0 recommends that the salt \s-1SHOULD\s0 be at least 8 bytes (64 bits) long, -where 16 bytes is common. -.PP -The iteration count must be at least 100, as stipulated by \s-1RFC 4211,\s0 and is -limited to at most 100000 to avoid DoS through manipulated or otherwise -malformed input. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_CRMF_pbm_new()\fR returns 1 on success, 0 on error. -.PP -\&\fBOSSL_CRMF_pbmp_new()\fR returns a new and initialized \s-1OSSL_CRMF_PBMPARAMETER\s0 -structure, or \s-1NULL\s0 on error. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 5 -\& OSSL_CRMF_PBMPARAMETER *pbm = NULL; -\& unsigned char *msg = "Hello"; -\& unsigned char *sec = "SeCrEt"; -\& unsigned char *mac = NULL; -\& size_t maclen; -\& -\& if ((pbm = OSSL_CRMF_pbmp_new(16, NID_sha256, 500, NID_hmac_sha1) == NULL)) -\& goto err; -\& if (!OSSL_CRMF_pbm_new(pbm, msg, 5, sec, 6, &mac, &maclen)) -\& goto err; -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1RFC 4211\s0 section 4.4 -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL \s-1CRMF\s0 support was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_DECODER.3ossl b/openssl-install/share/man/man3/OSSL_DECODER.3ossl deleted file mode 100644 index 9f65cc51..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER.3ossl +++ /dev/null @@ -1,322 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_DECODER 3ossl" -.TH OSSL_DECODER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_DECODER, -OSSL_DECODER_fetch, -OSSL_DECODER_up_ref, -OSSL_DECODER_free, -OSSL_DECODER_get0_provider, -OSSL_DECODER_get0_properties, -OSSL_DECODER_is_a, -OSSL_DECODER_get0_name, -OSSL_DECODER_get0_description, -OSSL_DECODER_do_all_provided, -OSSL_DECODER_names_do_all, -OSSL_DECODER_gettable_params, -OSSL_DECODER_get_params -\&\- Decoder method routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_decoder_st OSSL_DECODER; -\& -\& OSSL_DECODER *OSSL_DECODER_fetch(OSSL_LIB_CTX *ctx, const char *name, -\& const char *properties); -\& int OSSL_DECODER_up_ref(OSSL_DECODER *decoder); -\& void OSSL_DECODER_free(OSSL_DECODER *decoder); -\& const OSSL_PROVIDER *OSSL_DECODER_get0_provider(const OSSL_DECODER *decoder); -\& const char *OSSL_DECODER_get0_properties(const OSSL_DECODER *decoder); -\& int OSSL_DECODER_is_a(const OSSL_DECODER *decoder, const char *name); -\& const char *OSSL_DECODER_get0_name(const OSSL_DECODER *decoder); -\& const char *OSSL_DECODER_get0_description(const OSSL_DECODER *decoder); -\& void OSSL_DECODER_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(OSSL_DECODER *decoder, void *arg), -\& void *arg); -\& int OSSL_DECODER_names_do_all(const OSSL_DECODER *decoder, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const OSSL_PARAM *OSSL_DECODER_gettable_params(OSSL_DECODER *decoder); -\& int OSSL_DECODER_get_params(OSSL_DECODER_CTX *ctx, const OSSL_PARAM params[]); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_DECODER\s0\fR is a method for decoders, which know how to -decode encoded data into an object of some type that the rest -of OpenSSL knows how to handle. -.PP -\&\fBOSSL_DECODER_fetch()\fR looks for an algorithm within the provider that -has been loaded into the \fB\s-1OSSL_LIB_CTX\s0\fR given by \fIctx\fR, having the -name given by \fIname\fR and the properties given by \fIproperties\fR. -The \fIname\fR determines what type of object the fetched decoder -method is expected to be able to decode, and the properties are -used to determine the expected output type. -For known properties and the values they may have, please have a look -in \*(L"Names and properties\*(R" in \fBprovider\-encoder\fR\|(7). -.PP -\&\fBOSSL_DECODER_up_ref()\fR increments the reference count for the given -\&\fIdecoder\fR. -.PP -\&\fBOSSL_DECODER_free()\fR decrements the reference count for the given -\&\fIdecoder\fR, and when the count reaches zero, frees it. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_DECODER_get0_provider()\fR returns the provider of the given -\&\fIdecoder\fR. -.PP -\&\fBOSSL_DECODER_get0_properties()\fR returns the property definition associated -with the given \fIdecoder\fR. -.PP -\&\fBOSSL_DECODER_is_a()\fR checks if \fIdecoder\fR is an implementation -of an algorithm that's identifiable with \fIname\fR. -.PP -\&\fBOSSL_DECODER_get0_name()\fR returns the name used to fetch the given \fIdecoder\fR. -.PP -\&\fBOSSL_DECODER_get0_description()\fR returns a description of the \fIdecoder\fR, meant -for display and human consumption. The description is at the discretion -of the \fIdecoder\fR implementation. -.PP -\&\fBOSSL_DECODER_names_do_all()\fR traverses all names for the given -\&\fIdecoder\fR, and calls \fIfn\fR with each name and \fIdata\fR as arguments. -.PP -\&\fBOSSL_DECODER_do_all_provided()\fR traverses all decoder -implementations by all activated providers in the library context -\&\fIlibctx\fR, and for each of the implementations, calls \fIfn\fR with the -implementation method and \fIarg\fR as arguments. -.PP -\&\fBOSSL_DECODER_gettable_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) -array of parameter descriptors. -.PP -\&\fBOSSL_DECODER_get_params()\fR attempts to get parameters specified -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) array \fIparams\fR. Parameters that the -implementation doesn't recognise should be ignored. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_DECODER_fetch()\fR returns a pointer to an \s-1OSSL_DECODER\s0 object, -or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_DECODER_up_ref()\fR returns 1 on success, or 0 on error. -.PP -\&\fBOSSL_DECODER_free()\fR doesn't return any value. -.PP -\&\fBOSSL_DECODER_get0_provider()\fR returns a pointer to a provider object, or -\&\s-1NULL\s0 on error. -.PP -\&\fBOSSL_DECODER_get0_properties()\fR returns a pointer to a property -definition string, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_DECODER_is_a()\fR returns 1 if \fIdecoder\fR was identifiable, -otherwise 0. -.PP -\&\fBOSSL_DECODER_get0_name()\fR returns the algorithm name from the provided -implementation for the given \fIdecoder\fR. Note that the \fIdecoder\fR may have -multiple synonyms associated with it. In this case the first name from the -algorithm definition is returned. Ownership of the returned string is retained -by the \fIdecoder\fR object and should not be freed by the caller. -.PP -\&\fBOSSL_DECODER_get0_description()\fR returns a pointer to a description, or \s-1NULL\s0 if -there isn't one. -.PP -\&\fBOSSL_DECODER_names_do_all()\fR returns 1 if the callback was called for all -names. A return value of 0 means that the callback was not called for any names. -.SH "NOTES" -.IX Header "NOTES" -\&\fBOSSL_DECODER_fetch()\fR may be called implicitly by other fetching -functions, using the same library context and properties. -Any other \s-1API\s0 that uses keys will typically do this. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To list all decoders in a provider to a bio_out: -.PP -.Vb 3 -\& static void collect_decoders(OSSL_DECODER *decoder, void *stack) -\& { -\& STACK_OF(OSSL_DECODER) *decoder_stack = stack; -\& -\& sk_OSSL_DECODER_push(decoder_stack, decoder); -\& OSSL_DECODER_up_ref(decoder); -\& } -\& -\& void print_name(const char *name, void *vdata) -\& { -\& BIO *bio = vdata; -\& -\& BIO_printf(bio, "%s ", name); -\& } -\& -\& -\& STACK_OF(OSSL_DECODER) *decoders; -\& int i; -\& -\& decoders = sk_OSSL_DECODER_new_null(); -\& -\& BIO_printf(bio_out, "DECODERs provided by %s:\en", provider); -\& OSSL_DECODER_do_all_provided(NULL, collect_decoders, -\& decoders); -\& -\& for (i = 0; i < sk_OSSL_DECODER_num(decoders); i++) { -\& OSSL_DECODER *decoder = sk_OSSL_DECODER_value(decoders, i); -\& -\& if (strcmp(OSSL_PROVIDER_get0_name(OSSL_DECODER_get0_provider(decoder)), -\& provider) != 0) -\& continue; -\& -\& if (OSSL_DECODER_names_do_all(decoder, print_name, bio_out)) -\& BIO_printf(bio_out, "\en"); -\& } -\& sk_OSSL_DECODER_pop_free(decoders, OSSL_DECODER_free); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_DECODER_CTX\s0\fR\|(3), \fBOSSL_DECODER_from_bio\fR\|(3), -\&\fBOSSL_DECODER_CTX_new_for_pkey\fR\|(3), \s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CLEANUP.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CLEANUP.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CLEANUP.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CONSTRUCT.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CONSTRUCT.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CONSTRUCT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX.3ossl deleted file mode 100644 index d5866a07..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX.3ossl +++ /dev/null @@ -1,382 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_DECODER_CTX 3ossl" -.TH OSSL_DECODER_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_DECODER_CTX, -OSSL_DECODER_CTX_new, -OSSL_DECODER_settable_ctx_params, -OSSL_DECODER_CTX_set_params, -OSSL_DECODER_CTX_free, -OSSL_DECODER_CTX_set_selection, -OSSL_DECODER_CTX_set_input_type, -OSSL_DECODER_CTX_set_input_structure, -OSSL_DECODER_CTX_add_decoder, -OSSL_DECODER_CTX_add_extra, -OSSL_DECODER_CTX_get_num_decoders, -OSSL_DECODER_INSTANCE, -OSSL_DECODER_CONSTRUCT, -OSSL_DECODER_CLEANUP, -OSSL_DECODER_CTX_set_construct, -OSSL_DECODER_CTX_set_construct_data, -OSSL_DECODER_CTX_set_cleanup, -OSSL_DECODER_CTX_get_construct, -OSSL_DECODER_CTX_get_construct_data, -OSSL_DECODER_CTX_get_cleanup, -OSSL_DECODER_export, -OSSL_DECODER_INSTANCE_get_decoder, -OSSL_DECODER_INSTANCE_get_decoder_ctx, -OSSL_DECODER_INSTANCE_get_input_type, -OSSL_DECODER_INSTANCE_get_input_structure -\&\- Decoder context routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_decoder_ctx_st OSSL_DECODER_CTX; -\& -\& OSSL_DECODER_CTX *OSSL_DECODER_CTX_new(void); -\& const OSSL_PARAM *OSSL_DECODER_settable_ctx_params(OSSL_DECODER *decoder); -\& int OSSL_DECODER_CTX_set_params(OSSL_DECODER_CTX *ctx, -\& const OSSL_PARAM params[]); -\& void OSSL_DECODER_CTX_free(OSSL_DECODER_CTX *ctx); -\& -\& int OSSL_DECODER_CTX_set_selection(OSSL_DECODER_CTX *ctx, int selection); -\& int OSSL_DECODER_CTX_set_input_type(OSSL_DECODER_CTX *ctx, -\& const char *input_type); -\& int OSSL_DECODER_CTX_set_input_structure(OSSL_DECODER_CTX *ctx, -\& const char *input_structure); -\& int OSSL_DECODER_CTX_add_decoder(OSSL_DECODER_CTX *ctx, OSSL_DECODER *decoder); -\& int OSSL_DECODER_CTX_add_extra(OSSL_DECODER_CTX *ctx, -\& OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int OSSL_DECODER_CTX_get_num_decoders(OSSL_DECODER_CTX *ctx); -\& -\& typedef struct ossl_decoder_instance_st OSSL_DECODER_INSTANCE; -\& OSSL_DECODER * -\& OSSL_DECODER_INSTANCE_get_decoder(OSSL_DECODER_INSTANCE *decoder_inst); -\& void * -\& OSSL_DECODER_INSTANCE_get_decoder_ctx(OSSL_DECODER_INSTANCE *decoder_inst); -\& const char * -\& OSSL_DECODER_INSTANCE_get_input_type(OSSL_DECODER_INSTANCE *decoder_inst); -\& OSSL_DECODER_INSTANCE_get_input_structure(OSSL_DECODER_INSTANCE *decoder_inst, -\& int *was_set); -\& -\& typedef int OSSL_DECODER_CONSTRUCT(OSSL_DECODER_INSTANCE *decoder_inst, -\& const OSSL_PARAM *object, -\& void *construct_data); -\& typedef void OSSL_DECODER_CLEANUP(void *construct_data); -\& -\& int OSSL_DECODER_CTX_set_construct(OSSL_DECODER_CTX *ctx, -\& OSSL_DECODER_CONSTRUCT *construct); -\& int OSSL_DECODER_CTX_set_construct_data(OSSL_DECODER_CTX *ctx, -\& void *construct_data); -\& int OSSL_DECODER_CTX_set_cleanup(OSSL_DECODER_CTX *ctx, -\& OSSL_DECODER_CLEANUP *cleanup); -\& OSSL_DECODER_CONSTRUCT *OSSL_DECODER_CTX_get_construct(OSSL_DECODER_CTX *ctx); -\& void *OSSL_DECODER_CTX_get_construct_data(OSSL_DECODER_CTX *ctx); -\& OSSL_DECODER_CLEANUP *OSSL_DECODER_CTX_get_cleanup(OSSL_DECODER_CTX *ctx); -\& -\& int OSSL_DECODER_export(OSSL_DECODER_INSTANCE *decoder_inst, -\& void *reference, size_t reference_sz, -\& OSSL_CALLBACK *export_cb, void *export_cbarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1OSSL_DECODER_CTX\s0\fR holds data about multiple decoders, as needed to -figure out what the input data is and to attempt to unpack it into one of -several possible related results. This also includes chaining decoders, so -the output from one can become the input for another. This allows having -generic format decoders such as \s-1PEM\s0 to \s-1DER,\s0 as well as more specialized -decoders like \s-1DER\s0 to \s-1RSA.\s0 -.PP -The chains may be limited by specifying an input type, which is considered a -starting point. This is both considered by \fBOSSL_DECODER_CTX_add_extra()\fR, -which will stop adding one more decoder implementations when it has already -added those that take the specified input type, and functions like -\&\fBOSSL_DECODER_from_bio\fR\|(3), which will only start the decoding process with -the decoder implementations that take that input type. For example, if the -input type is set to \f(CW\*(C`DER\*(C'\fR, a \s-1PEM\s0 to \s-1DER\s0 decoder will be ignored. -.PP -The input type can also be \s-1NULL,\s0 which means that the caller doesn't know -what type of input they have. In this case, \fBOSSL_DECODER_from_bio()\fR will -simply try with one decoder implementation after the other, and thereby -discover what kind of input the caller gave it. -.PP -For every decoding done, even an intermediary one, a constructor provided by -the caller is called to attempt to construct an appropriate type / structure -that the caller knows how to handle from the current decoding result. -The constructor is set with \fBOSSL_DECODER_CTX_set_construct()\fR. -.PP -\&\fB\s-1OSSL_DECODER_INSTANCE\s0\fR is an opaque structure that contains data about the -decoder that was just used, and that may be useful for the constructor. -There are some functions to extract data from this type, described further -down. -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_DECODER_CTX_new()\fR creates a new empty \fB\s-1OSSL_DECODER_CTX\s0\fR. -.PP -\&\fBOSSL_DECODER_settable_ctx_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) array of -parameter descriptors. -.PP -\&\fBOSSL_DECODER_CTX_set_params()\fR attempts to set parameters specified with an -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) array \fIparams\fR. These parameters are passed to all -decoders that have been added to the \fIctx\fR so far. Parameters that an -implementation doesn't recognise should be ignored by it. -.PP -\&\fBOSSL_DECODER_CTX_free()\fR frees the given context \fIctx\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_DECODER_CTX_add_decoder()\fR populates the \fB\s-1OSSL_DECODER_CTX\s0\fR \fIctx\fR with -a decoder, to be used to attempt to decode some encoded input. -.PP -\&\fBOSSL_DECODER_CTX_add_extra()\fR finds decoders that generate input for already -added decoders, and adds them as well. This is used to build decoder -chains. -.PP -\&\fBOSSL_DECODER_CTX_set_input_type()\fR sets the starting input type. This limits -the decoder chains to be considered, as explained in the general description -above. -.PP -\&\fBOSSL_DECODER_CTX_set_input_structure()\fR sets the name of the structure that -the input is expected to have. This may be used to determines what decoder -implementations may be used. \s-1NULL\s0 is a valid input structure, when it's not -relevant, or when the decoder implementations are expected to figure it out. -.PP -\&\fBOSSL_DECODER_CTX_get_num_decoders()\fR gets the number of decoders currently -added to the context \fIctx\fR. -.PP -\&\fBOSSL_DECODER_CTX_set_construct()\fR sets the constructor \fIconstruct\fR. -.PP -\&\fBOSSL_DECODER_CTX_set_construct_data()\fR sets the constructor data that is -passed to the constructor every time it's called. -.PP -\&\fBOSSL_DECODER_CTX_set_cleanup()\fR sets the constructor data \fIcleanup\fR -function. This is called by \fBOSSL_DECODER_CTX_free\fR\|(3). -.PP -\&\fBOSSL_DECODER_CTX_get_construct()\fR, \fBOSSL_DECODER_CTX_get_construct_data()\fR and -\&\fBOSSL_DECODER_CTX_get_cleanup()\fR return the values that have been set by -\&\fBOSSL_DECODER_CTX_set_construct()\fR, \fBOSSL_DECODER_CTX_set_construct_data()\fR and -\&\fBOSSL_DECODER_CTX_set_cleanup()\fR respectively. -.PP -\&\fBOSSL_DECODER_export()\fR is a fallback function for constructors that cannot -use the data they get directly for diverse reasons. It takes the same -decode instance \fIdecoder_inst\fR that the constructor got and an object -\&\fIreference\fR, unpacks the object which it refers to, and exports it by -creating an \s-1\fBOSSL_PARAM\s0\fR\|(3) array that it then passes to \fIexport_cb\fR, -along with \fIexport_arg\fR. -.SS "Constructor" -.IX Subsection "Constructor" -A \fB\s-1OSSL_DECODER_CONSTRUCT\s0\fR gets the following arguments: -.IP "\fIdecoder_inst\fR" 4 -.IX Item "decoder_inst" -The \fB\s-1OSSL_DECODER_INSTANCE\s0\fR for the decoder from which the constructor gets -its data. -.IP "\fIobject\fR" 4 -.IX Item "object" -A provider-native object abstraction produced by the decoder. Further -information on the provider-native object abstraction can be found in -\&\fBprovider\-object\fR\|(7). -.IP "\fIconstruct_data\fR" 4 -.IX Item "construct_data" -The pointer that was set with \fBOSSL_DECODE_CTX_set_construct_data()\fR. -.PP -The constructor is expected to return 1 when the data it receives can be -constructed, otherwise 0. -.PP -These utility functions may be used by a constructor: -.PP -\&\fBOSSL_DECODER_INSTANCE_get_decoder()\fR can be used to get the decoder -implementation from a decoder instance \fIdecoder_inst\fR. -.PP -\&\fBOSSL_DECODER_INSTANCE_get_decoder_ctx()\fR can be used to get the decoder -implementation's provider context from a decoder instance \fIdecoder_inst\fR. -.PP -\&\fBOSSL_DECODER_INSTANCE_get_input_type()\fR can be used to get the decoder -implementation's input type from a decoder instance \fIdecoder_inst\fR. -.PP -\&\fBOSSL_DECODER_INSTANCE_get_input_structure()\fR can be used to get the input -structure for the decoder implementation from a decoder instance -\&\fIdecoder_inst\fR. -This may be \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_DECODER_CTX_new()\fR returns a pointer to a \fB\s-1OSSL_DECODER_CTX\s0\fR, or \s-1NULL\s0 -if the context structure couldn't be allocated. -.PP -\&\fBOSSL_DECODER_settable_ctx_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) array, or -\&\s-1NULL\s0 if none is available. -.PP -\&\fBOSSL_DECODER_CTX_set_params()\fR returns 1 if all recognised parameters were -valid, or 0 if one of them was invalid or caused some other failure in the -implementation. -.PP -\&\fBOSSL_DECODER_CTX_add_decoder()\fR, \fBOSSL_DECODER_CTX_add_extra()\fR, -\&\fBOSSL_DECODER_CTX_set_construct()\fR, \fBOSSL_DECODER_CTX_set_construct_data()\fR and -\&\fBOSSL_DECODER_CTX_set_cleanup()\fR return 1 on success, or 0 on failure. -.PP -\&\fBOSSL_DECODER_CTX_get_construct()\fR, \fBOSSL_DECODER_CTX_get_construct_data()\fR and -\&\fBOSSL_DECODER_CTX_get_cleanup()\fR return the current pointers to the -constructor, the constructor data and the cleanup functions, respectively. -.PP -\&\fBOSSL_DECODER_CTX_num_decoders()\fR returns the current number of decoders. It -returns 0 if \fIctx\fR is \s-1NULL.\s0 -.PP -\&\fBOSSL_DECODER_export()\fR returns 1 on success, or 0 on failure. -.PP -\&\fBOSSL_DECODER_INSTANCE_decoder()\fR returns an \fB\s-1OSSL_DECODER\s0\fR pointer on -success, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_DECODER_INSTANCE_decoder_ctx()\fR returns a provider context pointer on -success, or \s-1NULL\s0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_DECODER\s0\fR\|(3), \fBOSSL_DECODER_from_bio\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_add_decoder.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_add_decoder.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_add_decoder.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_add_extra.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_add_extra.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_add_extra.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_free.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_free.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_cleanup.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_cleanup.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct_data.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct_data.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_construct_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_num_decoders.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_num_decoders.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_get_num_decoders.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_new.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_new.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_new_for_pkey.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_new_for_pkey.3ossl deleted file mode 100644 index fdf969fc..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_new_for_pkey.3ossl +++ /dev/null @@ -1,273 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_DECODER_CTX_NEW_FOR_PKEY 3ossl" -.TH OSSL_DECODER_CTX_NEW_FOR_PKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_DECODER_CTX_new_for_pkey, -OSSL_DECODER_CTX_set_passphrase, -OSSL_DECODER_CTX_set_pem_password_cb, -OSSL_DECODER_CTX_set_passphrase_ui, -OSSL_DECODER_CTX_set_passphrase_cb -\&\- Decoder routines to decode EVP_PKEYs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_DECODER_CTX * -\& OSSL_DECODER_CTX_new_for_pkey(EVP_PKEY **pkey, -\& const char *input_type, -\& const char *input_struct, -\& const char *keytype, int selection, -\& OSSL_LIB_CTX *libctx, const char *propquery); -\& -\& int OSSL_DECODER_CTX_set_passphrase(OSSL_DECODER_CTX *ctx, -\& const unsigned char *kstr, -\& size_t klen); -\& int OSSL_DECODER_CTX_set_pem_password_cb(OSSL_DECODER_CTX *ctx, -\& pem_password_cb *cb, -\& void *cbarg); -\& int OSSL_DECODER_CTX_set_passphrase_ui(OSSL_DECODER_CTX *ctx, -\& const UI_METHOD *ui_method, -\& void *ui_data); -\& int OSSL_DECODER_CTX_set_passphrase_cb(OSSL_DECODER_CTX *ctx, -\& OSSL_PASSPHRASE_CALLBACK *cb, -\& void *cbarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_DECODER_CTX_new_for_pkey()\fR is a utility function that creates a -\&\fB\s-1OSSL_DECODER_CTX\s0\fR, finds all applicable decoder implementations and sets -them up, so all the caller has to do next is call functions like -\&\fBOSSL_DECODER_from_bio\fR\|(3). The caller may use the optional \fIinput_type\fR, -\&\fIinput_struct\fR, \fIkeytype\fR and \fIselection\fR to specify what the input is -expected to contain. The \fIpkey\fR must reference an \fB\s-1EVP_PKEY\s0 *\fR variable -that will be set to the newly created \fB\s-1EVP_PKEY\s0\fR on successful decoding. -The referenced variable must be initialized to \s-1NULL\s0 before calling the -function. -.PP -Internally \fBOSSL_DECODER_CTX_new_for_pkey()\fR searches for all available -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3) implementations, and then builds a list of all potential -decoder implementations that may be able to process the encoded input into -data suitable for \fB\s-1EVP_PKEY\s0\fRs. All these implementations are implicitly -fetched using \fIlibctx\fR and \fIpropquery\fR. -.PP -The search of decoder implementations can be limited with \fIinput_type\fR and -\&\fIinput_struct\fR which specifies a starting input type and input structure. -\&\s-1NULL\s0 is valid for both of them and signifies that the decoder implementations -will find out the input type on their own. -They are set with \fBOSSL_DECODER_CTX_set_input_type\fR\|(3) and -\&\fBOSSL_DECODER_CTX_set_input_structure\fR\|(3). -See \*(L"Input Types\*(R" and \*(L"Input Structures\*(R" below for further information. -.PP -The search of decoder implementations can also be limited with \fIkeytype\fR -and \fIselection\fR, which specifies the expected resulting keytype and contents. -\&\s-1NULL\s0 and zero are valid and signify that the decoder implementations will -find out the keytype and key contents on their own from the input they get. -.PP -If no suitable decoder implementation is found, -\&\fBOSSL_DECODER_CTX_new_for_pkey()\fR still creates a \fB\s-1OSSL_DECODER_CTX\s0\fR, but -with no associated decoder (\fBOSSL_DECODER_CTX_get_num_decoders\fR\|(3) returns -zero). This helps the caller to distinguish between an error when creating -the \fB\s-1OSSL_ENCODER_CTX\s0\fR and missing encoder implementation, and allows it to -act accordingly. -.PP -\&\fBOSSL_DECODER_CTX_set_passphrase()\fR gives the implementation a pass phrase to -use when decrypting the encoded private key. Alternatively, a pass phrase -callback may be specified with the following functions. -.PP -\&\fBOSSL_DECODER_CTX_set_pem_password_cb()\fR, \fBOSSL_DECODER_CTX_set_passphrase_ui()\fR -and \fBOSSL_DECODER_CTX_set_passphrase_cb()\fR set up a callback method that the -implementation can use to prompt for a pass phrase, giving the caller the -choice of preferred pass phrase callback form. These are called indirectly, -through an internal \s-1\fBOSSL_PASSPHRASE_CALLBACK\s0\fR\|(3) function. -.PP -The internal \s-1\fBOSSL_PASSPHRASE_CALLBACK\s0\fR\|(3) function caches the pass phrase, to -be reused in all decodings that are performed in the same decoding run (for -example, within one \fBOSSL_DECODER_from_bio\fR\|(3) call). -.SS "Input Types" -.IX Subsection "Input Types" -Available input types depend on the implementations that available providers -offer, and provider documentation should have the details. -.PP -Among the known input types that OpenSSL decoder implementations offer -for \fB\s-1EVP_PKEY\s0\fRs are \f(CW\*(C`DER\*(C'\fR, \f(CW\*(C`PEM\*(C'\fR, \f(CW\*(C`MSBLOB\*(C'\fR and \f(CW\*(C`PVK\*(C'\fR. -See \fBopenssl\-glossary\fR\|(7) for further information on what these input -types mean. -.SS "Input Structures" -.IX Subsection "Input Structures" -Available input structures depend on the implementations that available -providers offer, and provider documentation should have the details. -.PP -Among the known input structures that OpenSSL decoder implementations -offer for \fB\s-1EVP_PKEY\s0\fRs are \f(CW\*(C`pkcs8\*(C'\fR and \f(CW\*(C`SubjectPublicKeyInfo\*(C'\fR. -.PP -OpenSSL decoder implementations also support the input structure -\&\f(CW\*(C`type\-specific\*(C'\fR. This is the structure used for keys encoded -according to key type specific specifications. For example, \s-1RSA\s0 keys -encoded according to PKCS#1. -.SS "Selections" -.IX Subsection "Selections" -\&\fIselection\fR can be any one of the values described in -\&\*(L"Selections\*(R" in \fBEVP_PKEY_fromdata\fR\|(3). -Additionally \fIselection\fR can also be set to \fB0\fR to indicate that the code will -auto detect the selection. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_DECODER_CTX_new_for_pkey()\fR returns a pointer to a -\&\fB\s-1OSSL_DECODER_CTX\s0\fR, or \s-1NULL\s0 if it couldn't be created. -.PP -\&\fBOSSL_DECODER_CTX_set_passphrase()\fR, \fBOSSL_DECODER_CTX_set_pem_password_cb()\fR, -\&\fBOSSL_DECODER_CTX_set_passphrase_ui()\fR and -\&\fBOSSL_DECODER_CTX_set_passphrase_cb()\fR all return 1 on success, or 0 on -failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_DECODER\s0\fR\|(3), \s-1\fBOSSL_DECODER_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_cleanup.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_cleanup.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct_data.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct_data.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_construct_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_structure.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_structure.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_structure.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_type.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_type.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_input_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_params.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_params.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase.3ossl deleted file mode 120000 index 136fcea1..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_cb.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_cb.3ossl deleted file mode 120000 index 136fcea1..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_ui.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_ui.3ossl deleted file mode 120000 index 136fcea1..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_passphrase_ui.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_pem_password_cb.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_pem_password_cb.3ossl deleted file mode 120000 index 136fcea1..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_pem_password_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_selection.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_selection.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_CTX_set_selection.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder_ctx.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder_ctx.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_decoder_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_structure.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_structure.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_structure.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_type.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_type.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_INSTANCE_get_input_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_do_all_provided.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_do_all_provided.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_export.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_export.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_export.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_fetch.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_fetch.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_free.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_free.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_from_bio.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_from_bio.3ossl deleted file mode 100644 index bed14820..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_from_bio.3ossl +++ /dev/null @@ -1,249 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_DECODER_FROM_BIO 3ossl" -.TH OSSL_DECODER_FROM_BIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_DECODER_from_data, -OSSL_DECODER_from_bio, -OSSL_DECODER_from_fp -\&\- Routines to perform a decoding -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_DECODER_from_bio(OSSL_DECODER_CTX *ctx, BIO *in); -\& int OSSL_DECODER_from_fp(OSSL_DECODER_CTX *ctx, FILE *fp); -\& int OSSL_DECODER_from_data(OSSL_DECODER_CTX *ctx, const unsigned char **pdata, -\& size_t *pdata_len); -.Ve -.PP -Feature availability macros: -.IP "\fBOSSL_DECODER_from_fp()\fR is only available when \fB\s-1OPENSSL_NO_STDIO\s0\fR is undefined." 4 -.IX Item "OSSL_DECODER_from_fp() is only available when OPENSSL_NO_STDIO is undefined." -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_DECODER_from_data()\fR runs the decoding process for the context \fIctx\fR, -with input coming from \fI*pdata\fR, \fI*pdata_len\fR bytes long. Both \fI*pdata\fR -and \fI*pdata_len\fR must be non-NULL. When \fBOSSL_DECODER_from_data()\fR returns, -\&\fI*pdata\fR is updated to point at the location after what has been decoded, -and \fI*pdata_len\fR to have the number of remaining bytes. -.PP -\&\fBOSSL_DECODER_from_bio()\fR runs the decoding process for the context \fIctx\fR, -with the input coming from the \fB\s-1BIO\s0\fR \fIin\fR. Should it make a difference, -it's recommended to have the \s-1BIO\s0 set in binary mode rather than text mode. -.PP -\&\fBOSSL_DECODER_from_fp()\fR does the same thing as \fBOSSL_DECODER_from_bio()\fR, -except that the input is coming from the \fB\s-1FILE\s0\fR \fIfp\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_DECODER_from_bio()\fR, \fBOSSL_DECODER_from_data()\fR and \fBOSSL_DECODER_from_fp()\fR -return 1 on success, or 0 on failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To decode an \s-1RSA\s0 key encoded with \s-1PEM\s0 from a bio: -.PP -.Vb 6 -\& OSSL_DECODER_CTX *dctx; -\& EVP_PKEY *pkey = NULL; -\& const char *format = "PEM"; /* NULL for any format */ -\& const char *structure = NULL; /* any structure */ -\& const char *keytype = "RSA"; /* NULL for any key */ -\& const unsigned char *pass = "my password"; -\& -\& dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, format, structure, -\& keytype, -\& OSSL_KEYMGMT_SELECT_KEYPAIR, -\& NULL, NULL); -\& if (dctx == NULL) { -\& /* error: no suitable potential decoders found */ -\& } -\& if (pass != NULL) -\& OSSL_DECODER_CTX_set_passphrase(dctx, pass, strlen(pass)); -\& if (OSSL_DECODER_from_bio(dctx, bio)) { -\& /* pkey is created with the decoded data from the bio */ -\& } else { -\& /* decoding failure */ -\& } -\& OSSL_DECODER_CTX_free(dctx); -.Ve -.PP -To decode an \s-1EC\s0 key encoded with \s-1DER\s0 from a buffer: -.PP -.Vb 8 -\& OSSL_DECODER_CTX *dctx; -\& EVP_PKEY *pkey = NULL; -\& const char *format = "DER"; /* NULL for any format */ -\& const char *structure = NULL; /* any structure */ -\& const char *keytype = "EC"; /* NULL for any key */ -\& const unsigned char *pass = NULL -\& const unsigned char *data = buffer; -\& size_t datalen = sizeof(buffer); -\& -\& dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, format, structure, -\& keytype, -\& OSSL_KEYMGMT_SELECT_KEYPAIR -\& | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS, -\& NULL, NULL); -\& if (dctx == NULL) { -\& /* error: no suitable potential decoders found */ -\& } -\& if (pass != NULL) -\& OSSL_DECODER_CTX_set_passphrase(dctx, pass, strlen(pass)); -\& if (OSSL_DECODER_from_data(dctx, &data, &datalen)) { -\& /* pkey is created with the decoded data from the buffer */ -\& } else { -\& /* decoding failure */ -\& } -\& OSSL_DECODER_CTX_free(dctx); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_DECODER_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_DECODER_from_data.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_from_data.3ossl deleted file mode 120000 index 2d2efbc4..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_from_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_from_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_from_fp.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_from_fp.3ossl deleted file mode 120000 index 2d2efbc4..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_from_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_from_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_get0_description.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_get0_description.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_get0_name.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_get0_name.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_get0_properties.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_get0_properties.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_get0_properties.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_get0_provider.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_get0_provider.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_get_params.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_get_params.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_gettable_params.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_gettable_params.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_is_a.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_is_a.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_names_do_all.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_names_do_all.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_settable_ctx_params.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_settable_ctx_params.3ossl deleted file mode 120000 index f8d774e9..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DECODER_up_ref.3ossl b/openssl-install/share/man/man3/OSSL_DECODER_up_ref.3ossl deleted file mode 120000 index 91d35f8f..00000000 --- a/openssl-install/share/man/man3/OSSL_DECODER_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DECODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_DISPATCH.3ossl b/openssl-install/share/man/man3/OSSL_DISPATCH.3ossl deleted file mode 100644 index 5508479c..00000000 --- a/openssl-install/share/man/man3/OSSL_DISPATCH.3ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_DISPATCH 3ossl" -.TH OSSL_DISPATCH 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_DISPATCH, OSSL_DISPATCH_END \- OpenSSL Core type to define a dispatchable function table -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_dispatch_st OSSL_DISPATCH; -\& struct ossl_dispatch_st { -\& int function_id; -\& void (*function)(void); -\& }; -\& -\& #define OSSL_DISPATCH_END -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This type is a tuple of function identity and function pointer. -Arrays of this type are passed between the OpenSSL libraries and the -providers to describe what functionality one side provides to the other. -.PP -Arrays of this type must be terminated with the \s-1OSSL_DISPATCH_END\s0 macro. -.SS "\fB\s-1OSSL_DISPATCH\s0\fP fields" -.IX Subsection "OSSL_DISPATCH fields" -.IP "\fIfunction_id\fR" 4 -.IX Item "function_id" -OpenSSL defined function identity of the implemented function. -.IP "\fIfunction\fR" 4 -.IX Item "function" -Pointer to the implemented function itself. Despite the generic definition -of this field, the implemented function it points to must have a function -signature that corresponds to the \fIfunction_id\fR -.PP -Available function identities and corresponding function signatures are -defined in \fBopenssl\-core_dispatch.h\fR\|(7). -Furthermore, the chosen function identities and associated function -signature must be chosen specifically for the operation that it's intended -for, as determined by the intended \s-1\fBOSSL_ALGORITHM\s0\fR\|(3) array. -.PP -Any function identity not recognised by the recipient of this type -will be ignored. -This ensures that providers built with one OpenSSL version in mind -will work together with any other OpenSSL version that supports this -mechanism. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBopenssl\-core_dispatch.h\fR\|(7), \s-1\fBOSSL_ALGORITHM\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fB\s-1OSSL_DISPATCH\s0\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_DISPATCH_END.3ossl b/openssl-install/share/man/man3/OSSL_DISPATCH_END.3ossl deleted file mode 120000 index 161aa430..00000000 --- a/openssl-install/share/man/man3/OSSL_DISPATCH_END.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_DISPATCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_EC_curve_nid2name.3ossl b/openssl-install/share/man/man3/OSSL_EC_curve_nid2name.3ossl deleted file mode 120000 index 24d68265..00000000 --- a/openssl-install/share/man/man3/OSSL_EC_curve_nid2name.3ossl +++ /dev/null @@ -1 +0,0 @@ -EC_GROUP_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER.3ossl deleted file mode 100644 index 311dee5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER.3ossl +++ /dev/null @@ -1,276 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ENCODER 3ossl" -.TH OSSL_ENCODER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ENCODER, -OSSL_ENCODER_fetch, -OSSL_ENCODER_up_ref, -OSSL_ENCODER_free, -OSSL_ENCODER_get0_provider, -OSSL_ENCODER_get0_properties, -OSSL_ENCODER_is_a, -OSSL_ENCODER_get0_name, -OSSL_ENCODER_get0_description, -OSSL_ENCODER_do_all_provided, -OSSL_ENCODER_names_do_all, -OSSL_ENCODER_gettable_params, -OSSL_ENCODER_get_params -\&\- Encoder method routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_encoder_st OSSL_ENCODER; -\& -\& OSSL_ENCODER *OSSL_ENCODER_fetch(OSSL_LIB_CTX *ctx, const char *name, -\& const char *properties); -\& int OSSL_ENCODER_up_ref(OSSL_ENCODER *encoder); -\& void OSSL_ENCODER_free(OSSL_ENCODER *encoder); -\& const OSSL_PROVIDER *OSSL_ENCODER_get0_provider(const OSSL_ENCODER *encoder); -\& const char *OSSL_ENCODER_get0_properties(const OSSL_ENCODER *encoder); -\& int OSSL_ENCODER_is_a(const OSSL_ENCODER *encoder, const char *name); -\& const char *OSSL_ENCODER_get0_name(const OSSL_ENCODER *encoder); -\& const char *OSSL_ENCODER_get0_description(const OSSL_ENCODER *encoder); -\& void OSSL_ENCODER_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*fn)(OSSL_ENCODER *encoder, void *arg), -\& void *arg); -\& int OSSL_ENCODER_names_do_all(const OSSL_ENCODER *encoder, -\& void (*fn)(const char *name, void *data), -\& void *data); -\& const OSSL_PARAM *OSSL_ENCODER_gettable_params(OSSL_ENCODER *encoder); -\& int OSSL_ENCODER_get_params(OSSL_ENCODER_CTX *ctx, const OSSL_PARAM params[]); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_ENCODER\s0\fR is a method for encoders, which know how to -encode an object of some kind to a encoded form, such as \s-1PEM, -DER,\s0 or even human readable text. -.PP -\&\fBOSSL_ENCODER_fetch()\fR looks for an algorithm within the provider that -has been loaded into the \fB\s-1OSSL_LIB_CTX\s0\fR given by \fIctx\fR, having the -name given by \fIname\fR and the properties given by \fIproperties\fR. -The \fIname\fR determines what type of object the fetched encoder -method is expected to be able to encode, and the properties are -used to determine the expected output type. -For known properties and the values they may have, please have a look -in \*(L"Names and properties\*(R" in \fBprovider\-encoder\fR\|(7). -.PP -\&\fBOSSL_ENCODER_up_ref()\fR increments the reference count for the given -\&\fIencoder\fR. -.PP -\&\fBOSSL_ENCODER_free()\fR decrements the reference count for the given -\&\fIencoder\fR, and when the count reaches zero, frees it. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_ENCODER_get0_provider()\fR returns the provider of the given -\&\fIencoder\fR. -.PP -\&\fBOSSL_ENCODER_get0_properties()\fR returns the property definition associated -with the given \fIencoder\fR. -.PP -\&\fBOSSL_ENCODER_is_a()\fR checks if \fIencoder\fR is an implementation of an -algorithm that's identifiable with \fIname\fR. -.PP -\&\fBOSSL_ENCODER_get0_name()\fR returns the name used to fetch the given \fIencoder\fR. -.PP -\&\fBOSSL_ENCODER_get0_description()\fR returns a description of the \fIloader\fR, meant -for display and human consumption. The description is at the discretion of the -\&\fIloader\fR implementation. -.PP -\&\fBOSSL_ENCODER_names_do_all()\fR traverses all names for the given -\&\fIencoder\fR, and calls \fIfn\fR with each name and \fIdata\fR as arguments. -.PP -\&\fBOSSL_ENCODER_do_all_provided()\fR traverses all encoder -implementations by all activated providers in the library context -\&\fIlibctx\fR, and for each of the implementations, calls \fIfn\fR with the -implementation method and \fIarg\fR as arguments. -.PP -\&\fBOSSL_ENCODER_gettable_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) -array of parameter descriptors. -.PP -\&\fBOSSL_ENCODER_get_params()\fR attempts to get parameters specified -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) array \fIparams\fR. Parameters that the -implementation doesn't recognise should be ignored. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_ENCODER_fetch()\fR returns a pointer to the key management -implementation represented by an \s-1OSSL_ENCODER\s0 object, or \s-1NULL\s0 on -error. -.PP -\&\fBOSSL_ENCODER_up_ref()\fR returns 1 on success, or 0 on error. -.PP -\&\fBOSSL_ENCODER_free()\fR doesn't return any value. -.PP -\&\fBOSSL_ENCODER_get0_provider()\fR returns a pointer to a provider object, or -\&\s-1NULL\s0 on error. -.PP -\&\fBOSSL_ENCODER_get0_properties()\fR returns a pointer to a property -definition string, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_ENCODER_is_a()\fR returns 1 of \fIencoder\fR was identifiable, -otherwise 0. -.PP -\&\fBOSSL_ENCODER_get0_name()\fR returns the algorithm name from the provided -implementation for the given \fIencoder\fR. Note that the \fIencoder\fR may have -multiple synonyms associated with it. In this case the first name from the -algorithm definition is returned. Ownership of the returned string is retained -by the \fIencoder\fR object and should not be freed by the caller. -.PP -\&\fBOSSL_ENCODER_get0_description()\fR returns a pointer to a description, or \s-1NULL\s0 if -there isn't one. -.PP -\&\fBOSSL_ENCODER_names_do_all()\fR returns 1 if the callback was called for all -names. A return value of 0 means that the callback was not called for any names. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_ENCODER_CTX\s0\fR\|(3), \fBOSSL_ENCODER_to_bio\fR\|(3), -\&\fBOSSL_ENCODER_CTX_new_for_pkey\fR\|(3), \s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CLEANUP.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CLEANUP.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CLEANUP.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CONSTRUCT.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CONSTRUCT.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CONSTRUCT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX.3ossl deleted file mode 100644 index ab17d04a..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX.3ossl +++ /dev/null @@ -1,345 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ENCODER_CTX 3ossl" -.TH OSSL_ENCODER_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ENCODER_CTX, -OSSL_ENCODER_CTX_new, -OSSL_ENCODER_settable_ctx_params, -OSSL_ENCODER_CTX_set_params, -OSSL_ENCODER_CTX_free, -OSSL_ENCODER_CTX_set_selection, -OSSL_ENCODER_CTX_set_output_type, -OSSL_ENCODER_CTX_set_output_structure, -OSSL_ENCODER_CTX_add_encoder, -OSSL_ENCODER_CTX_add_extra, -OSSL_ENCODER_CTX_get_num_encoders, -OSSL_ENCODER_INSTANCE, -OSSL_ENCODER_INSTANCE_get_encoder, -OSSL_ENCODER_INSTANCE_get_encoder_ctx, -OSSL_ENCODER_INSTANCE_get_output_type, -OSSL_ENCODER_INSTANCE_get_output_structure, -OSSL_ENCODER_CONSTRUCT, -OSSL_ENCODER_CLEANUP, -OSSL_ENCODER_CTX_set_construct, -OSSL_ENCODER_CTX_set_construct_data, -OSSL_ENCODER_CTX_set_cleanup -\&\- Encoder context routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_encoder_ctx_st OSSL_ENCODER_CTX; -\& -\& OSSL_ENCODER_CTX *OSSL_ENCODER_CTX_new(); -\& const OSSL_PARAM *OSSL_ENCODER_settable_ctx_params(OSSL_ENCODER *encoder); -\& int OSSL_ENCODER_CTX_set_params(OSSL_ENCODER_CTX *ctx, -\& const OSSL_PARAM params[]); -\& void OSSL_ENCODER_CTX_free(OSSL_ENCODER_CTX *ctx); -\& -\& int OSSL_ENCODER_CTX_set_selection(OSSL_ENCODER_CTX *ctx, int selection); -\& int OSSL_ENCODER_CTX_set_output_type(OSSL_ENCODER_CTX *ctx, -\& const char *output_type); -\& int OSSL_ENCODER_CTX_set_output_structure(OSSL_ENCODER_CTX *ctx, -\& const char *output_structure); -\& -\& int OSSL_ENCODER_CTX_add_encoder(OSSL_ENCODER_CTX *ctx, OSSL_ENCODER *encoder); -\& int OSSL_ENCODER_CTX_add_extra(OSSL_ENCODER_CTX *ctx, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int OSSL_ENCODER_CTX_get_num_encoders(OSSL_ENCODER_CTX *ctx); -\& -\& typedef struct ossl_encoder_instance_st OSSL_ENCODER_INSTANCE; -\& OSSL_ENCODER * -\& OSSL_ENCODER_INSTANCE_get_encoder(OSSL_ENCODER_INSTANCE *encoder_inst); -\& void * -\& OSSL_ENCODER_INSTANCE_get_encoder_ctx(OSSL_ENCODER_INSTANCE *encoder_inst); -\& const char * -\& OSSL_ENCODER_INSTANCE_get_output_type(OSSL_ENCODER_INSTANCE *encoder_inst); -\& const char * -\& OSSL_ENCODER_INSTANCE_get_output_structure(OSSL_ENCODER_INSTANCE *encoder_inst); -\& -\& typedef const void *OSSL_ENCODER_CONSTRUCT(OSSL_ENCODER_INSTANCE *encoder_inst, -\& void *construct_data); -\& typedef void OSSL_ENCODER_CLEANUP(void *construct_data); -\& -\& int OSSL_ENCODER_CTX_set_construct(OSSL_ENCODER_CTX *ctx, -\& OSSL_ENCODER_CONSTRUCT *construct); -\& int OSSL_ENCODER_CTX_set_construct_data(OSSL_ENCODER_CTX *ctx, -\& void *construct_data); -\& int OSSL_ENCODER_CTX_set_cleanup(OSSL_ENCODER_CTX *ctx, -\& OSSL_ENCODER_CLEANUP *cleanup); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Encoding an input object to the desired encoding may be done with a chain of -encoder implementations, which means that the output from one encoder may be -the input for the next in the chain. The \fB\s-1OSSL_ENCODER_CTX\s0\fR holds all the -data about these encoders. This allows having generic format encoders such -as \s-1DER\s0 to \s-1PEM,\s0 as well as more specialized encoders like \s-1RSA\s0 to \s-1DER.\s0 -.PP -The final output type must be given, and a chain of encoders must end with -an implementation that produces that output type. -.PP -At the beginning of the encoding process, a constructor provided by the -caller is called to ensure that there is an appropriate provider-side object -to start with. -The constructor is set with \fBOSSL_ENCODER_CTX_set_construct()\fR. -.PP -\&\fB\s-1OSSL_ENCODER_INSTANCE\s0\fR is an opaque structure that contains data about the -encoder that is going to be used, and that may be useful for the -constructor. There are some functions to extract data from this type, -described in \*(L"Constructor\*(R" below. -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_ENCODER_CTX_new()\fR creates a \fB\s-1OSSL_ENCODER_CTX\s0\fR. -.PP -\&\fBOSSL_ENCODER_settable_ctx_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) -array of parameter descriptors. -.PP -\&\fBOSSL_ENCODER_CTX_set_params()\fR attempts to set parameters specified -with an \s-1\fBOSSL_PARAM\s0\fR\|(3) array \fIparams\fR. Parameters that the -implementation doesn't recognise should be ignored. -.PP -\&\fBOSSL_ENCODER_CTX_free()\fR frees the given context \fIctx\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_ENCODER_CTX_add_encoder()\fR populates the \fB\s-1OSSL_ENCODER_CTX\s0\fR -\&\fIctx\fR with a encoder, to be used to encode an input object. -.PP -\&\fBOSSL_ENCODER_CTX_add_extra()\fR finds encoders that further encodes output -from already added encoders, and adds them as well. This is used to build -encoder chains. -.PP -\&\fBOSSL_ENCODER_CTX_set_output_type()\fR sets the ending output type. This must -be specified, and determines if a complete encoder chain is available. -.PP -\&\fBOSSL_ENCODER_CTX_set_output_structure()\fR sets the desired output structure. -This may be used to determines what encoder implementations may be used. -Depending on the type of object being encoded, the output structure may -not be relevant. -.PP -\&\fBOSSL_ENCODER_CTX_get_num_encoders()\fR gets the number of encoders currently -added to the context \fIctx\fR. -.PP -\&\fBOSSL_ENCODER_CTX_set_construct()\fR sets the constructor \fIconstruct\fR. -.PP -\&\fBOSSL_ENCODER_CTX_set_construct_data()\fR sets the constructor data that is -passed to the constructor every time it's called. -.PP -\&\fBOSSL_ENCODER_CTX_set_cleanup()\fR sets the constructor data \fIcleanup\fR -function. This is called by \fBOSSL_ENCODER_CTX_free\fR\|(3). -.SS "Constructor" -.IX Subsection "Constructor" -A \fB\s-1OSSL_ENCODER_CONSTRUCT\s0\fR gets the following arguments: -.IP "\fIencoder_inst\fR" 4 -.IX Item "encoder_inst" -The \fB\s-1OSSL_ENCODER_INSTANCE\s0\fR for the encoder from which the constructor gets -its data. -.IP "\fIconstruct_data\fR" 4 -.IX Item "construct_data" -The pointer that was set with \fBOSSL_ENCODE_CTX_set_construct_data()\fR. -.PP -The constructor is expected to return a valid (non-NULL) pointer to a -provider-native object that can be used as first input of an encoding chain, -or \s-1NULL\s0 to indicate that an error has occurred. -.PP -These utility functions may be used by a constructor: -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_encoder()\fR can be used to get the encoder -implementation of the encoder instance \fIencoder_inst\fR. -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_encoder_ctx()\fR can be used to get the encoder -implementation's provider context of the encoder instance \fIencoder_inst\fR. -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_output_type()\fR can be used to get the output type -for the encoder implementation of the encoder instance \fIencoder_inst\fR. -This will never be \s-1NULL.\s0 -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_output_structure()\fR can be used to get the output -structure for the encoder implementation of the encoder instance -\&\fIencoder_inst\fR. -This may be \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_ENCODER_CTX_new()\fR returns a pointer to a \fB\s-1OSSL_ENCODER_CTX\s0\fR, or \s-1NULL\s0 -if the context structure couldn't be allocated. -.PP -\&\fBOSSL_ENCODER_settable_ctx_params()\fR returns an \s-1\fBOSSL_PARAM\s0\fR\|(3) array, or -\&\s-1NULL\s0 if none is available. -.PP -\&\fBOSSL_ENCODER_CTX_set_params()\fR returns 1 if all recognised parameters were -valid, or 0 if one of them was invalid or caused some other failure in the -implementation. -.PP -\&\fBOSSL_ENCODER_CTX_add_encoder()\fR, \fBOSSL_ENCODER_CTX_add_extra()\fR, -\&\fBOSSL_ENCODER_CTX_set_construct()\fR, \fBOSSL_ENCODER_CTX_set_construct_data()\fR and -\&\fBOSSL_ENCODER_CTX_set_cleanup()\fR return 1 on success, or 0 on failure. -.PP -\&\fBOSSL_ENCODER_CTX_get_num_encoders()\fR returns the current number of encoders. -It returns 0 if \fIctx\fR is \s-1NULL.\s0 -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_encoder()\fR returns an \fB\s-1OSSL_ENCODER\s0\fR pointer on -success, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_encoder_ctx()\fR returns a provider context pointer on -success, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_output_type()\fR returns a string with the name of the -input type, if relevant. \s-1NULL\s0 is a valid returned value. -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_output_type()\fR returns a string with the name of the -output type. -.PP -\&\fBOSSL_ENCODER_INSTANCE_get_output_structure()\fR returns a string with the name -of the output structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_ENCODER\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_encoder.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_encoder.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_encoder.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_extra.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_extra.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_add_extra.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_free.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_free.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_get_num_encoders.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_get_num_encoders.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_get_num_encoders.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_new.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_new.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_new_for_pkey.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_new_for_pkey.3ossl deleted file mode 100644 index 6aa207be..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_new_for_pkey.3ossl +++ /dev/null @@ -1,271 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ENCODER_CTX_NEW_FOR_PKEY 3ossl" -.TH OSSL_ENCODER_CTX_NEW_FOR_PKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ENCODER_CTX_new_for_pkey, -OSSL_ENCODER_CTX_set_cipher, -OSSL_ENCODER_CTX_set_passphrase, -OSSL_ENCODER_CTX_set_pem_password_cb, -OSSL_ENCODER_CTX_set_passphrase_cb, -OSSL_ENCODER_CTX_set_passphrase_ui -\&\- Encoder routines to encode EVP_PKEYs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_ENCODER_CTX * -\& OSSL_ENCODER_CTX_new_for_pkey(const EVP_PKEY *pkey, int selection, -\& const char *output_type, -\& const char *output_structure, -\& const char *propquery); -\& -\& int OSSL_ENCODER_CTX_set_cipher(OSSL_ENCODER_CTX *ctx, -\& const char *cipher_name, -\& const char *propquery); -\& int OSSL_ENCODER_CTX_set_passphrase(OSSL_ENCODER_CTX *ctx, -\& const unsigned char *kstr, -\& size_t klen); -\& int OSSL_ENCODER_CTX_set_pem_password_cb(OSSL_ENCODER_CTX *ctx, -\& pem_password_cb *cb, void *cbarg); -\& int OSSL_ENCODER_CTX_set_passphrase_ui(OSSL_ENCODER_CTX *ctx, -\& const UI_METHOD *ui_method, -\& void *ui_data); -\& int OSSL_ENCODER_CTX_set_passphrase_cb(OSSL_ENCODER_CTX *ctx, -\& OSSL_PASSPHRASE_CALLBACK *cb, -\& void *cbarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_ENCODER_CTX_new_for_pkey()\fR is a utility function that creates a -\&\fB\s-1OSSL_ENCODER_CTX\s0\fR, finds all applicable encoder implementations and sets -them up, so almost all the caller has to do next is call functions like -\&\fBOSSL_ENCODER_to_bio\fR\|(3). \fIoutput_type\fR determines the final output -encoding, and \fIselection\fR can be used to select what parts of the \fIpkey\fR -should be included in the output. \fIoutput_type\fR is further discussed in -\&\*(L"Output types\*(R" below, and \fIselection\fR is further described in -\&\*(L"Selections\*(R". -.PP -Internally, \fBOSSL_ENCODER_CTX_new_for_pkey()\fR uses the names from the -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3) implementation associated with \fIpkey\fR to build a list of -applicable encoder implementations that are used to process the \fIpkey\fR into -the encoding named by \fIoutput_type\fR, with the outermost structure named by -\&\fIoutput_structure\fR if that's relevant. All these implementations are -implicitly fetched, with \fIpropquery\fR for finer selection. -.PP -If no suitable encoder implementation is found, -\&\fBOSSL_ENCODER_CTX_new_for_pkey()\fR still creates a \fB\s-1OSSL_ENCODER_CTX\s0\fR, but -with no associated encoder (\fBOSSL_ENCODER_CTX_get_num_encoders\fR\|(3) returns -zero). This helps the caller to distinguish between an error when creating -the \fB\s-1OSSL_ENCODER_CTX\s0\fR and missing encoder implementation, and allows it to -act accordingly. -.PP -\&\fBOSSL_ENCODER_CTX_set_cipher()\fR tells the implementation what cipher -should be used to encrypt encoded keys. The cipher is given by -name \fIcipher_name\fR. The interpretation of that \fIcipher_name\fR is -implementation dependent. The implementation may implement the cipher -directly itself or by other implementations, or it may choose to fetch -it. If the implementation supports fetching the cipher, then it may -use \fIpropquery\fR as properties to be queried for when fetching. -\&\fIcipher_name\fR may also be \s-1NULL,\s0 which will result in unencrypted -encoding. -.PP -\&\fBOSSL_ENCODER_CTX_set_passphrase()\fR gives the implementation a -pass phrase to use when encrypting the encoded private key. -Alternatively, a pass phrase callback may be specified with the -following functions. -.PP -\&\fBOSSL_ENCODER_CTX_set_pem_password_cb()\fR, \fBOSSL_ENCODER_CTX_set_passphrase_ui()\fR -and \fBOSSL_ENCODER_CTX_set_passphrase_cb()\fR sets up a callback method that the -implementation can use to prompt for a pass phrase, giving the caller the -choice of preferred pass phrase callback form. These are called indirectly, -through an internal \s-1\fBOSSL_PASSPHRASE_CALLBACK\s0\fR\|(3) function. -.SS "Output types" -.IX Subsection "Output types" -The possible \fB\s-1EVP_PKEY\s0\fR output types depends on the available -implementations. -.PP -OpenSSL has built in implementations for the following output types: -.ie n .IP """TEXT""" 4 -.el .IP "\f(CWTEXT\fR" 4 -.IX Item "TEXT" -The output is a human readable description of the key. -\&\fBEVP_PKEY_print_private\fR\|(3), \fBEVP_PKEY_print_public\fR\|(3) and -\&\fBEVP_PKEY_print_params\fR\|(3) use this for their output. -.ie n .IP """DER""" 4 -.el .IP "\f(CWDER\fR" 4 -.IX Item "DER" -The output is the \s-1DER\s0 encoding of the \fIselection\fR of the \fIpkey\fR. -.ie n .IP """PEM""" 4 -.el .IP "\f(CWPEM\fR" 4 -.IX Item "PEM" -The output is the \fIselection\fR of the \fIpkey\fR in \s-1PEM\s0 format. -.SS "Selections" -.IX Subsection "Selections" -\&\fIselection\fR can be any one of the values described in -\&\*(L"Selections\*(R" in \fBEVP_PKEY_fromdata\fR\|(3). -.PP -These are only 'hints' since the encoder implementations are free to -determine what makes sense to include in the output, and this may depend on -the desired output. For example, an \s-1EC\s0 key in a PKCS#8 structure doesn't -usually include the public key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_ENCODER_CTX_new_for_pkey()\fR returns a pointer to an \fB\s-1OSSL_ENCODER_CTX\s0\fR, -or \s-1NULL\s0 if it couldn't be created. -.PP -\&\fBOSSL_ENCODER_CTX_set_cipher()\fR, \fBOSSL_ENCODER_CTX_set_passphrase()\fR, -\&\fBOSSL_ENCODER_CTX_set_pem_password_cb()\fR, \fBOSSL_ENCODER_CTX_set_passphrase_ui()\fR -and \fBOSSL_ENCODER_CTX_set_passphrase_cb()\fR all return 1 on success, or 0 on -failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_ENCODER\s0\fR\|(3), \s-1\fBOSSL_ENCODER_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cipher.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cipher.3ossl deleted file mode 120000 index 20ef0c51..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cleanup.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cleanup.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct_data.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct_data.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_construct_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_structure.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_structure.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_structure.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_type.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_type.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_output_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_params.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_params.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase.3ossl deleted file mode 120000 index 20ef0c51..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_cb.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_cb.3ossl deleted file mode 120000 index 20ef0c51..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_ui.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_ui.3ossl deleted file mode 120000 index 20ef0c51..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_passphrase_ui.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_pem_password_cb.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_pem_password_cb.3ossl deleted file mode 120000 index 20ef0c51..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_pem_password_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX_new_for_pkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_selection.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_selection.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_CTX_set_selection.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder_ctx.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder_ctx.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_encoder_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_structure.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_structure.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_structure.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_type.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_type.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_INSTANCE_get_output_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_do_all_provided.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_do_all_provided.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_fetch.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_fetch.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_free.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_free.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_get0_description.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_get0_description.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_get0_name.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_get0_name.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_get0_properties.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_get0_properties.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_get0_properties.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_get0_provider.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_get0_provider.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_get_params.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_get_params.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_gettable_params.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_gettable_params.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_is_a.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_is_a.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_names_do_all.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_names_do_all.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_settable_ctx_params.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_settable_ctx_params.3ossl deleted file mode 120000 index f8de3d5c..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_settable_ctx_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_to_bio.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_to_bio.3ossl deleted file mode 100644 index d9a55df8..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_to_bio.3ossl +++ /dev/null @@ -1,260 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ENCODER_TO_BIO 3ossl" -.TH OSSL_ENCODER_TO_BIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ENCODER_to_data, -OSSL_ENCODER_to_bio, -OSSL_ENCODER_to_fp -\&\- Routines to perform an encoding -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_ENCODER_to_data(OSSL_ENCODER_CTX *ctx, unsigned char **pdata, -\& size_t *pdata_len); -\& int OSSL_ENCODER_to_bio(OSSL_ENCODER_CTX *ctx, BIO *out); -\& int OSSL_ENCODER_to_fp(OSSL_ENCODER_CTX *ctx, FILE *fp); -.Ve -.PP -Feature availability macros: -.IP "\fBOSSL_ENCODER_to_fp()\fR is only available when \fB\s-1OPENSSL_NO_STDIO\s0\fR is undefined." 4 -.IX Item "OSSL_ENCODER_to_fp() is only available when OPENSSL_NO_STDIO is undefined." -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_ENCODER_to_data()\fR runs the encoding process for the context \fIctx\fR, -with the output going to the \fI*pdata\fR and \fI*pdata_len\fR. -If \fI*pdata\fR is \s-1NULL\s0 when \fBOSSL_ENCODER_to_data()\fR is called, a buffer will be -allocated using \fBOPENSSL_zalloc\fR\|(3), and \fI*pdata\fR will be set to point at -the start of that buffer, and \fI*pdata_len\fR will be assigned its length when -\&\fBOSSL_ENCODER_to_data()\fR returns. -If \fI*pdata\fR is non-NULL when \fBOSSL_ENCODER_to_data()\fR is called, \fI*pdata_len\fR -is assumed to have its size. In this case, \fI*pdata\fR will be set to point -after the encoded bytes, and \fI*pdata_len\fR will be assigned the number of -remaining bytes. -.PP -\&\fBOSSL_ENCODER_to_bio()\fR runs the encoding process for the context \fIctx\fR, with -the output going to the \fB\s-1BIO\s0\fR \fIout\fR. -.PP -\&\fBOSSL_ENCODER_to_fp()\fR does the same thing as \fBOSSL_ENCODER_to_bio()\fR, except -that the output is going to the \fB\s-1FILE\s0\fR \fIfp\fR. -.PP -For \fBOSSL_ENCODER_to_bio()\fR and \fBOSSL_ENCODER_to_fp()\fR, the application is -required to set up the \fB\s-1BIO\s0\fR or \fB\s-1FILE\s0\fR properly, for example to have -it in text or binary mode as is appropriate for the encoder output type. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_ENCODER_to_bio()\fR, \fBOSSL_ENCODER_to_fp()\fR and \fBOSSL_ENCODER_to_data()\fR -return 1 on success, or 0 on failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To encode a pkey as PKCS#8 with \s-1PEM\s0 format into a bio: -.PP -.Vb 4 -\& OSSL_ENCODER_CTX *ectx; -\& const char *format = "PEM"; -\& const char *structure = "PrivateKeyInfo"; /* PKCS#8 structure */ -\& const unsigned char *pass = "my password"; -\& -\& ectx = OSSL_ENCODER_CTX_new_for_pkey(pkey, -\& OSSL_KEYMGMT_SELECT_KEYPAIR -\& | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS, -\& format, structure, -\& NULL); -\& if (ectx == NULL) { -\& /* error: no suitable potential encoders found */ -\& } -\& if (pass != NULL) -\& OSSL_ENCODER_CTX_set_passphrase(ectx, pass, strlen(pass)); -\& if (OSSL_ENCODER_to_bio(ectx, bio)) { -\& /* pkey was successfully encoded into the bio */ -\& } else { -\& /* encoding failure */ -\& } -\& OSSL_ENCODER_CTX_free(ectx); -.Ve -.PP -To encode a pkey as PKCS#8 with \s-1DER\s0 format encrypted with -\&\s-1AES\-256\-CBC\s0 into a buffer: -.PP -.Vb 6 -\& OSSL_ENCODER_CTX *ectx; -\& const char *format = "DER"; -\& const char *structure = "PrivateKeyInfo"; /* PKCS#8 structure */ -\& const unsigned char *pass = "my password"; -\& unsigned char *data = NULL; -\& size_t datalen; -\& -\& ectx = OSSL_ENCODER_CTX_new_for_pkey(pkey, -\& OSSL_KEYMGMT_SELECT_KEYPAIR -\& | OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS, -\& format, structure, -\& NULL); -\& if (ectx == NULL) { -\& /* error: no suitable potential encoders found */ -\& } -\& if (pass != NULL) { -\& OSSL_ENCODER_CTX_set_passphrase(ectx, pass, strlen(pass)); -\& OSSL_ENCODER_CTX_set_cipher(ctx, "AES\-256\-CBC", NULL); -\& } -\& if (OSSL_ENCODER_to_data(ectx, &data, &datalen)) { -\& /* -\& * pkey was successfully encoded into a newly allocated -\& * data buffer -\& */ -\& } else { -\& /* encoding failure */ -\& } -\& OSSL_ENCODER_CTX_free(ectx); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_ENCODER_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_to_data.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_to_data.3ossl deleted file mode 120000 index d7c5b528..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_to_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_to_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_to_fp.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_to_fp.3ossl deleted file mode 120000 index d7c5b528..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_to_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER_to_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ENCODER_up_ref.3ossl b/openssl-install/share/man/man3/OSSL_ENCODER_up_ref.3ossl deleted file mode 120000 index b90524fe..00000000 --- a/openssl-install/share/man/man3/OSSL_ENCODER_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ENCODER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ERR_STATE_free.3ossl b/openssl-install/share/man/man3/OSSL_ERR_STATE_free.3ossl deleted file mode 120000 index ed998295..00000000 --- a/openssl-install/share/man/man3/OSSL_ERR_STATE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ERR_STATE_save.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ERR_STATE_new.3ossl b/openssl-install/share/man/man3/OSSL_ERR_STATE_new.3ossl deleted file mode 120000 index ed998295..00000000 --- a/openssl-install/share/man/man3/OSSL_ERR_STATE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ERR_STATE_save.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ERR_STATE_restore.3ossl b/openssl-install/share/man/man3/OSSL_ERR_STATE_restore.3ossl deleted file mode 120000 index ed998295..00000000 --- a/openssl-install/share/man/man3/OSSL_ERR_STATE_restore.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ERR_STATE_save.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ERR_STATE_save.3ossl b/openssl-install/share/man/man3/OSSL_ERR_STATE_save.3ossl deleted file mode 100644 index 2f740e27..00000000 --- a/openssl-install/share/man/man3/OSSL_ERR_STATE_save.3ossl +++ /dev/null @@ -1,217 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ERR_STATE_SAVE 3ossl" -.TH OSSL_ERR_STATE_SAVE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ERR_STATE_new, OSSL_ERR_STATE_save, OSSL_ERR_STATE_save_to_mark, -OSSL_ERR_STATE_restore, OSSL_ERR_STATE_free \- saving and restoring error state -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ERR_STATE *OSSL_ERR_STATE_new(void); -\& void OSSL_ERR_STATE_save(ERR_STATE *es); -\& void OSSL_ERR_STATE_save_to_mark(ERR_STATE *es); -\& void OSSL_ERR_STATE_restore(const ERR_STATE *es); -\& void OSSL_ERR_STATE_free(ERR_STATE *es); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions save and restore the error state from the thread -local error state to a preallocated error state structure. -.PP -\&\fBOSSL_ERR_STATE_new()\fR allocates an empty error state structure to -be used when saving and restoring thread error state. -.PP -\&\fBOSSL_ERR_STATE_save()\fR saves the thread error state to \fIes\fR. It -subsequently clears the thread error state. Any previously saved -state in \fIes\fR is cleared prior to saving the new state. -.PP -\&\fBOSSL_ERR_STATE_save_to_mark()\fR is similar to \fBOSSL_ERR_STATE_save()\fR but only saves -\&\s-1ERR\s0 entries up to the most recent mark on the \s-1ERR\s0 stack. These entries are moved -to \fIes\fR and removed from the thread error state. However, the most recent -marked \s-1ERR\s0 and any \s-1ERR\s0 state before it remains part of the thread error state -and is not moved to the \s-1ERR_STATE.\s0 The mark is not cleared and must be cleared -explicitly after a call to this function using \fBERR_pop_to_mark\fR\|(3) or -\&\fBERR_clear_last_mark\fR\|(3). (Since a call to \fBOSSL_ERR_STATE_save_to_mark()\fR leaves -the marked \s-1ERR\s0 as the top error, either of these functions will have the same -effect.) If there is no marked \s-1ERR\s0 in the thread local error state, all \s-1ERR\s0 -entries are copied and the effect is the same as for a call to -\&\fBOSSL_ERR_STATE_save()\fR. -.PP -\&\fBOSSL_ERR_STATE_restore()\fR adds all the error entries from the -saved state \fIes\fR to the thread error state. Existing entries in -the thread error state are not affected if there is enough space -for all the added entries. Any allocated data in the saved error -entries is duplicated on adding to the thread state. -.PP -\&\fBOSSL_ERR_STATE_free()\fR frees the saved error state \fIes\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_ERR_STATE_new()\fR returns a pointer to the allocated \s-1ERR_STATE\s0 -structure or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_ERR_STATE_save()\fR, \fBOSSL_ERR_STATE_save_to_mark()\fR, \fBOSSL_ERR_STATE_restore()\fR, -\&\fBOSSL_ERR_STATE_free()\fR do not return any values. -.SH "NOTES" -.IX Header "NOTES" -\&\fBOSSL_ERR_STATE_save()\fR and \fBOSSL_ERR_STATE_save_to_mark()\fR cannot fail as it takes -over any allocated data from the thread error state. -.PP -\&\fBOSSL_ERR_STATE_restore()\fR is a best effort function. The only failure -that can happen during its operation is when memory allocation fails. -Because it manipulates the thread error state it avoids raising memory -errors on such failure. At worst the restored error entries will be -missing the auxiliary error data. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_raise\fR\|(3), \fBERR_get_error\fR\|(3), \fBERR_clear_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ERR_STATE_save_to_mark.3ossl b/openssl-install/share/man/man3/OSSL_ERR_STATE_save_to_mark.3ossl deleted file mode 120000 index ed998295..00000000 --- a/openssl-install/share/man/man3/OSSL_ERR_STATE_save_to_mark.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ERR_STATE_save.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ESS_check_signing_certs.3ossl b/openssl-install/share/man/man3/OSSL_ESS_check_signing_certs.3ossl deleted file mode 100644 index a58de7df..00000000 --- a/openssl-install/share/man/man3/OSSL_ESS_check_signing_certs.3ossl +++ /dev/null @@ -1,218 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ESS_CHECK_SIGNING_CERTS 3ossl" -.TH OSSL_ESS_CHECK_SIGNING_CERTS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ESS_signing_cert_new_init, -OSSL_ESS_signing_cert_v2_new_init, -OSSL_ESS_check_signing_certs -\&\- Enhanced Security Services (ESS) functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ESS_SIGNING_CERT *OSSL_ESS_signing_cert_new_init(const X509 *signcert, -\& const STACK_OF(X509) *certs, -\& int set_issuer_serial); -\& ESS_SIGNING_CERT_V2 *OSSL_ESS_signing_cert_v2_new_init(const EVP_MD *hash_alg, -\& const X509 *signcert, -\& const -\& STACK_OF(X509) *certs, -\& int set_issuer_serial); -\& int OSSL_ESS_check_signing_certs(const ESS_SIGNING_CERT *ss, -\& const ESS_SIGNING_CERT_V2 *ssv2, -\& const STACK_OF(X509) *chain, -\& int require_signing_cert); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_ESS_signing_cert_new_init()\fR generates a new \fB\s-1ESS_SIGNING_CERT\s0\fR structure -referencing the given \fIsigncert\fR and any given further \fIcerts\fR -using their \s-1SHA\-1\s0 fingerprints. -If \fIset_issuer_serial\fR is nonzero then also the issuer and serial number -of \fIsigncert\fR are included in the \fB\s-1ESS_CERT_ID\s0\fR as the \fBissuerSerial\fR field. -For all members of \fIcerts\fR the \fBissuerSerial\fR field is always included. -.PP -\&\fBOSSL_ESS_signing_cert_v2_new_init()\fR is the same as -\&\fBOSSL_ESS_signing_cert_new_init()\fR except that it uses the given \fIhash_alg\fR and -generates a \fB\s-1ESS_SIGNING_CERT_V2\s0\fR structure with \fB\s-1ESS_CERT_ID_V2\s0\fR elements. -.PP -\&\fBOSSL_ESS_check_signing_certs()\fR checks if the validation chain \fIchain\fR contains -the certificates required by the identifiers given in \fIss\fR and/or \fIssv2\fR. -If \fIrequire_signing_cert\fR is nonzero, \fIss\fR or \fIssv2\fR must not be \s-1NULL.\s0 -If both \fIss\fR and \fIssv2\fR are not \s-1NULL,\s0 they are evaluated independently. -The list of certificate identifiers in \fIss\fR is of type \fB\s-1ESS_CERT_ID\s0\fR, -while the list contained in \fIssv2\fR is of type \fB\s-1ESS_CERT_ID_V2\s0\fR. -As far as these lists are present, they must be nonempty. -The certificate identified by their first entry must be the first element of -\&\fIchain\fR, i.e. the signer certificate. -Any further certificates referenced in the list must also be found in \fIchain\fR. -The matching is done using the given certificate hash algorithm and value. -In addition to the checks required by RFCs 2624 and 5035, -if the \fBissuerSerial\fR field is included in an \fBESSCertID\fR or \fBESSCertIDv2\fR -it must match the certificate issuer and serial number attributes. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1ESS\s0 has been defined in \s-1RFC 2634,\s0 which has been updated in \s-1RFC 5035\s0 -(\s-1ESS\s0 version 2) to support hash algorithms other than \s-1SHA\-1.\s0 -This is used for \s-1TSP\s0 (\s-1RFC 3161\s0) and CAdES-BES (informational \s-1RFC 5126\s0). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_ESS_signing_cert_new_init()\fR and \fBOSSL_ESS_signing_cert_v2_new_init()\fR -return a pointer to the new structure or \s-1NULL\s0 on malloc failure. -.PP -\&\fBOSSL_ESS_check_signing_certs()\fR returns 1 on success, -0 if a required certificate cannot be found, \-1 on other error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBTS_VERIFY_CTX_set_certs\fR\|(3), -\&\fBCMS_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_ESS_signing_cert_new_init()\fR, \fBOSSL_ESS_signing_cert_v2_new_init()\fR, and -\&\fBOSSL_ESS_check_signing_certs()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ESS_signing_cert_new_init.3ossl b/openssl-install/share/man/man3/OSSL_ESS_signing_cert_new_init.3ossl deleted file mode 120000 index e9114425..00000000 --- a/openssl-install/share/man/man3/OSSL_ESS_signing_cert_new_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ESS_check_signing_certs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ESS_signing_cert_v2_new_init.3ossl b/openssl-install/share/man/man3/OSSL_ESS_signing_cert_v2_new_init.3ossl deleted file mode 120000 index e9114425..00000000 --- a/openssl-install/share/man/man3/OSSL_ESS_signing_cert_v2_new_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_ESS_check_signing_certs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_GENERAL_NAMES_print.3ossl b/openssl-install/share/man/man3/OSSL_GENERAL_NAMES_print.3ossl deleted file mode 100644 index fed34e9c..00000000 --- a/openssl-install/share/man/man3/OSSL_GENERAL_NAMES_print.3ossl +++ /dev/null @@ -1,168 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_GENERAL_NAMES_PRINT 3ossl" -.TH OSSL_GENERAL_NAMES_PRINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_GENERAL_NAMES_print \- print GeneralNames in a human\-friendly, multi\-line -string -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_GENERAL_NAMES_print(BIO *out, GENERAL_NAMES *gens, int indent); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_GENERAL_NAMES_print()\fR prints a human readable version of the GeneralNames -\&\fIgens\fR to \s-1BIO\s0 \fIout\fR. Each line is indented by \fIindent\fR spaces. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_GENERAL_NAMES_print()\fR always returns 1. -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were all added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_free.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_free.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_get_seq.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_get_seq.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_get_seq.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_new.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_new.3ossl deleted file mode 100644 index d972c098..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_new.3ossl +++ /dev/null @@ -1,672 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_HPKE_CTX_NEW 3ossl" -.TH OSSL_HPKE_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_HPKE_CTX_new, OSSL_HPKE_CTX_free, -OSSL_HPKE_encap, OSSL_HPKE_decap, -OSSL_HPKE_seal, OSSL_HPKE_open, OSSL_HPKE_export, -OSSL_HPKE_suite_check, OSSL_HPKE_str2suite, -OSSL_HPKE_keygen, OSSL_HPKE_get_grease_value, -OSSL_HPKE_get_ciphertext_size, OSSL_HPKE_get_public_encap_size, -OSSL_HPKE_get_recommended_ikmelen, -OSSL_HPKE_CTX_set1_psk, OSSL_HPKE_CTX_set1_ikme, -OSSL_HPKE_CTX_set1_authpriv, OSSL_HPKE_CTX_set1_authpub, -OSSL_HPKE_CTX_get_seq, OSSL_HPKE_CTX_set_seq -\&\- Hybrid Public Key Encryption (HPKE) functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct { -\& uint16_t kem_id; -\& uint16_t kdf_id; -\& uint16_t aead_id; -\& } OSSL_HPKE_SUITE; -\& -\& OSSL_HPKE_CTX *OSSL_HPKE_CTX_new(int mode, OSSL_HPKE_SUITE suite, int role, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& void OSSL_HPKE_CTX_free(OSSL_HPKE_CTX *ctx); -\& -\& int OSSL_HPKE_encap(OSSL_HPKE_CTX *ctx, -\& unsigned char *enc, size_t *enclen, -\& const unsigned char *pub, size_t publen, -\& const unsigned char *info, size_t infolen); -\& int OSSL_HPKE_seal(OSSL_HPKE_CTX *ctx, -\& unsigned char *ct, size_t *ctlen, -\& const unsigned char *aad, size_t aadlen, -\& const unsigned char *pt, size_t ptlen); -\& -\& int OSSL_HPKE_keygen(OSSL_HPKE_SUITE suite, -\& unsigned char *pub, size_t *publen, EVP_PKEY **priv, -\& const unsigned char *ikm, size_t ikmlen, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int OSSL_HPKE_decap(OSSL_HPKE_CTX *ctx, -\& const unsigned char *enc, size_t enclen, -\& EVP_PKEY *recippriv, -\& const unsigned char *info, size_t infolen); -\& int OSSL_HPKE_open(OSSL_HPKE_CTX *ctx, -\& unsigned char *pt, size_t *ptlen, -\& const unsigned char *aad, size_t aadlen, -\& const unsigned char *ct, size_t ctlen); -\& -\& int OSSL_HPKE_export(OSSL_HPKE_CTX *ctx, -\& unsigned char *secret, size_t secretlen, -\& const unsigned char *label, size_t labellen); -\& -\& int OSSL_HPKE_CTX_set1_authpriv(OSSL_HPKE_CTX *ctx, EVP_PKEY *priv); -\& int OSSL_HPKE_CTX_set1_authpub(OSSL_HPKE_CTX *ctx, -\& unsigned char *pub, size_t publen); -\& int OSSL_HPKE_CTX_set1_psk(OSSL_HPKE_CTX *ctx, -\& const char *pskid, -\& const unsigned char *psk, size_t psklen); -\& -\& int OSSL_HPKE_CTX_get_seq(OSSL_HPKE_CTX *ctx, uint64_t *seq); -\& int OSSL_HPKE_CTX_set_seq(OSSL_HPKE_CTX *ctx, uint64_t seq); -\& -\& int OSSL_HPKE_CTX_set1_ikme(OSSL_HPKE_CTX *ctx, -\& const unsigned char *ikme, size_t ikmelen); -\& -\& int OSSL_HPKE_suite_check(OSSL_HPKE_SUITE suite); -\& int OSSL_HPKE_get_grease_value(const OSSL_HPKE_SUITE *suite_in, -\& OSSL_HPKE_SUITE *suite, -\& unsigned char *enc, size_t *enclen, -\& unsigned char *ct, size_t ctlen, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& -\& int OSSL_HPKE_str2suite(const char *str, OSSL_HPKE_SUITE *suite); -\& size_t OSSL_HPKE_get_ciphertext_size(OSSL_HPKE_SUITE suite, size_t clearlen); -\& size_t OSSL_HPKE_get_public_encap_size(OSSL_HPKE_SUITE suite); -\& size_t OSSL_HPKE_get_recommended_ikmelen(OSSL_HPKE_SUITE suite); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions provide an \s-1API\s0 for using the form of Hybrid Public Key -Encryption (\s-1HPKE\s0) defined in \s-1RFC9180.\s0 Understanding the \s-1HPKE\s0 specification -is likely required before using these APIs. \s-1HPKE\s0 is used by various -other \s-1IETF\s0 specifications, including the \s-1TLS\s0 Encrypted Client -Hello (\s-1ECH\s0) specification and others. -.PP -\&\s-1HPKE\s0 is a standardised, highly flexible construct for encrypting \*(L"to\*(R" a public -key that supports combinations of a key encapsulation method (\s-1KEM\s0), a key -derivation function (\s-1KDF\s0) and an authenticated encryption with additional data -(\s-1AEAD\s0) algorithm, with optional sender authentication. -.PP -The sender and a receiver here will generally be using some application or -protocol making use of \s-1HPKE.\s0 For example, with \s-1ECH,\s0 -the sender will be a browser and the receiver will be a web server. -.SS "Data Structures" -.IX Subsection "Data Structures" -\&\fB\s-1OSSL_HPKE_SUITE\s0\fR is a structure that holds identifiers for the algorithms -used for \s-1KEM, KDF\s0 and \s-1AEAD\s0 operations. -.PP -\&\fB\s-1OSSL_HPKE_CTX\s0\fR is a context that maintains internal state as \s-1HPKE\s0 -operations are carried out. Separate \fB\s-1OSSL_HPKE_CTX\s0\fR objects must be used for -the sender and receiver. Attempting to use a single context for both will -result in errors. -.SS "\s-1OSSL_HPKE_SUITE\s0 Identifiers" -.IX Subsection "OSSL_HPKE_SUITE Identifiers" -The identifiers used by \fB\s-1OSSL_HPKE_SUITE\s0\fR are: -.PP -The \s-1KEM\s0 identifier \fIkem_id\fR is one of the following: -.IP "0x10 \fB\s-1OSSL_HPKE_KEM_ID_P256\s0\fR" 4 -.IX Item "0x10 OSSL_HPKE_KEM_ID_P256" -.PD 0 -.IP "0x11 \fB\s-1OSSL_HPKE_KEM_ID_P384\s0\fR" 4 -.IX Item "0x11 OSSL_HPKE_KEM_ID_P384" -.IP "0x12 \fB\s-1OSSL_HPKE_KEM_ID_P521\s0\fR" 4 -.IX Item "0x12 OSSL_HPKE_KEM_ID_P521" -.IP "0x20 \fB\s-1OSSL_HPKE_KEM_ID_X25519\s0\fR" 4 -.IX Item "0x20 OSSL_HPKE_KEM_ID_X25519" -.IP "0x21 \fB\s-1OSSL_HPKE_KEM_ID_X448\s0\fR" 4 -.IX Item "0x21 OSSL_HPKE_KEM_ID_X448" -.PD -.PP -The \s-1KDF\s0 identifier \fIkdf_id\fR is one of the following: -.IP "0x01 \fB\s-1OSSL_HPKE_KDF_ID_HKDF_SHA256\s0\fR" 4 -.IX Item "0x01 OSSL_HPKE_KDF_ID_HKDF_SHA256" -.PD 0 -.IP "0x02 \fB\s-1OSSL_HPKE_KDF_ID_HKDF_SHA384\s0\fR" 4 -.IX Item "0x02 OSSL_HPKE_KDF_ID_HKDF_SHA384" -.IP "0x03 \fB\s-1OSSL_HPKE_KDF_ID_HKDF_SHA512\s0\fR" 4 -.IX Item "0x03 OSSL_HPKE_KDF_ID_HKDF_SHA512" -.PD -.PP -The \s-1AEAD\s0 identifier \fIaead_id\fR is one of the following: -.IP "0x01 \fB\s-1OSSL_HPKE_AEAD_ID_AES_GCM_128\s0\fR" 4 -.IX Item "0x01 OSSL_HPKE_AEAD_ID_AES_GCM_128" -.PD 0 -.IP "0x02 \fB\s-1OSSL_HPKE_AEAD_ID_AES_GCM_256\s0\fR" 4 -.IX Item "0x02 OSSL_HPKE_AEAD_ID_AES_GCM_256" -.IP "0x03 \fB\s-1OSSL_HPKE_AEAD_ID_CHACHA_POLY1305\s0\fR" 4 -.IX Item "0x03 OSSL_HPKE_AEAD_ID_CHACHA_POLY1305" -.IP "0xFFFF \fB\s-1OSSL_HPKE_AEAD_ID_EXPORTONLY\s0\fR" 4 -.IX Item "0xFFFF OSSL_HPKE_AEAD_ID_EXPORTONLY" -.PD -The last identifier above indicates that \s-1AEAD\s0 operations are not needed. -\&\fBOSSL_HPKE_export()\fR can be used, but \fBOSSL_HPKE_open()\fR and \fBOSSL_HPKE_seal()\fR will -return an error if called with a context using that \s-1AEAD\s0 identifier. -.SS "\s-1HPKE\s0 Modes" -.IX Subsection "HPKE Modes" -\&\s-1HPKE\s0 supports the following variants of Authentication using a mode Identifier: -.IP "\fB\s-1OSSL_HPKE_MODE_BASE\s0\fR, 0x00" 4 -.IX Item "OSSL_HPKE_MODE_BASE, 0x00" -Authentication is not used. -.IP "\fB\s-1OSSL_HPKE_MODE_PSK\s0\fR, 0x01" 4 -.IX Item "OSSL_HPKE_MODE_PSK, 0x01" -Authenticates possession of a pre-shared key (\s-1PSK\s0). -.IP "\fB\s-1OSSL_HPKE_MODE_AUTH\s0\fR, 0x02" 4 -.IX Item "OSSL_HPKE_MODE_AUTH, 0x02" -Authenticates possession of a KEM-based sender private key. -.IP "\fB\s-1OSSL_HPKE_MODE_PSKAUTH\s0\fR, 0x03" 4 -.IX Item "OSSL_HPKE_MODE_PSKAUTH, 0x03" -A combination of \fB\s-1OSSL_HPKE_MODE_PSK\s0\fR and \fB\s-1OSSL_HPKE_MODE_AUTH\s0\fR. -Both the \s-1PSK\s0 and the senders authentication public/private must be -supplied before the encapsulation/decapsulation operation will work. -.PP -For further information related to authentication see \*(L"Pre-Shared Key \s-1HPKE\s0 -modes\*(R" and \*(L"Sender-authenticated \s-1HPKE\s0 Modes\*(R". -.SS "\s-1HPKE\s0 Roles" -.IX Subsection "HPKE Roles" -\&\s-1HPKE\s0 contexts have a role \- either sender or receiver. This is used -to control which functions can be called and so that senders do not -reuse a key and nonce with different plaintexts. -.PP -\&\fBOSSL_HPKE_CTX_free()\fR, \fBOSSL_HPKE_export()\fR, \fBOSSL_HPKE_CTX_set1_psk()\fR, -and \fBOSSL_HPKE_CTX_get_seq()\fR can be called regardless of role. -.IP "\fB\s-1OSSL_HPKE_ROLE_SENDER\s0\fR, 0" 4 -.IX Item "OSSL_HPKE_ROLE_SENDER, 0" -An \fI\s-1OSSL_HPKE_CTX\s0\fR with this role can be used with -\&\fBOSSL_HPKE_encap()\fR, \fBOSSL_HPKE_seal()\fR, \fBOSSL_HPKE_CTX_set1_ikme()\fR and -\&\fBOSSL_HPKE_CTX_set1_authpriv()\fR. -.IP "\fB\s-1OSSL_HPKE_ROLE_RECEIVER\s0\fR, 1" 4 -.IX Item "OSSL_HPKE_ROLE_RECEIVER, 1" -An \fI\s-1OSSL_HPKE_CTX\s0\fR with this role can be used with \fBOSSL_HPKE_decap()\fR, -\&\fBOSSL_HPKE_open()\fR, \fBOSSL_HPKE_CTX_set1_authpub()\fR and \fBOSSL_HPKE_CTX_set_seq()\fR. -.PP -Calling a function with an incorrect role set on \fI\s-1OSSL_HPKE_CTX\s0\fR will result -in an error. -.SS "Parameter Size Limits" -.IX Subsection "Parameter Size Limits" -In order to improve interoperability, \s-1RFC9180,\s0 section 7.2.1 suggests a -\&\s-1RECOMMENDED\s0 maximum size of 64 octets for various input parameters. In this -implementation we apply a limit of 66 octets for the \fIikmlen\fR, \fIpsklen\fR, and -\&\fIlabellen\fR parameters, and for the length of the string \fIpskid\fR for \s-1HPKE\s0 -functions below. The constant \fI\s-1OSSL_HPKE_MAX_PARMLEN\s0\fR is defined as the limit -of this value. (We chose 66 octets so that we can validate all the test -vectors present in \s-1RFC9180,\s0 Appendix A.) -.PP -In accordance with \s-1RFC9180,\s0 section 9.5, we define a constant -\&\fI\s-1OSSL_HPKE_MIN_PSKLEN\s0\fR with a value of 32 for the minimum length of a -pre-shared key, passed in \fIpsklen\fR. -.PP -While \s-1RFC9180\s0 also \s-1RECOMMENDS\s0 a 64 octet limit for the \fIinfolen\fR parameter, -that is not sufficient for \s-1TLS\s0 Encrypted ClientHello (\s-1ECH\s0) processing, so we -enforce a limit of \fI\s-1OSSL_HPKE_MAX_INFOLEN\s0\fR with a value of 1024 as the limit -for the \fIinfolen\fR parameter. -.SS "Context Construct/Free" -.IX Subsection "Context Construct/Free" -\&\fBOSSL_HPKE_CTX_new()\fR creates a \fB\s-1OSSL_HPKE_CTX\s0\fR context object used for -subsequent \s-1HPKE\s0 operations, given a \fImode\fR (See \*(L"\s-1HPKE\s0 Modes\*(R"), \fIsuite\fR (see -\&\*(L"\s-1OSSL_HPKE_SUITE\s0 Identifiers\*(R") and a \fIrole\fR (see \*(L"\s-1HPKE\s0 Roles\*(R"). The -\&\fIlibctx\fR and \fIpropq\fR are used when fetching algorithms from providers and may -be set to \s-1NULL.\s0 -.PP -\&\fBOSSL_HPKE_CTX_free()\fR frees the \fIctx\fR \fB\s-1OSSL_HPKE_CTX\s0\fR that was created -previously by a call to \fBOSSL_HPKE_CTX_new()\fR. If the argument to -\&\fBOSSL_HPKE_CTX_free()\fR is \s-1NULL,\s0 nothing is done. -.SS "Sender APIs" -.IX Subsection "Sender APIs" -A sender's goal is to use \s-1HPKE\s0 to encrypt using a public key, via use of a -\&\s-1KEM,\s0 then a \s-1KDF\s0 and finally an \s-1AEAD.\s0 The first step is to encapsulate (using -\&\fBOSSL_HPKE_encap()\fR) the sender's public value using the recipient's public key, -(\fIpub\fR) and to internally derive secrets. This produces the encapsulated public value -(\fIenc\fR) to be sent to the recipient in whatever protocol is using \s-1HPKE.\s0 Having done the -encapsulation step, the sender can then make one or more calls to -\&\fBOSSL_HPKE_seal()\fR to encrypt plaintexts using the secret stored within \fIctx\fR. -.PP -\&\fBOSSL_HPKE_encap()\fR uses the \s-1HPKE\s0 context \fIctx\fR, the recipient public value -\&\fIpub\fR of size \fIpublen\fR, and an optional \fIinfo\fR parameter of size \fIinfolen\fR, -to produce the encapsulated public value \fIenc\fR. -On input \fIenclen\fR should contain the maximum size of the \fIenc\fR buffer, and returns -the output size. An error will occur if the input \fIenclen\fR is -smaller than the value returned from \fBOSSL_HPKE_get_public_encap_size()\fR. -\&\fIinfo\fR may be used to bind other protocol or application artefacts such as identifiers. -Generally, the encapsulated public value \fIenc\fR corresponds to a -single-use ephemeral private value created as part of the encapsulation -process. Only a single call to \fBOSSL_HPKE_encap()\fR is allowed for a given -\&\fB\s-1OSSL_HPKE_CTX\s0\fR. -.PP -\&\fBOSSL_HPKE_seal()\fR takes the \fB\s-1OSSL_HPKE_CTX\s0\fR context \fIctx\fR, the plaintext -buffer \fIpt\fR of size \fIptlen\fR and optional additional authenticated data buffer -\&\fIaad\fR of size \fIaadlen\fR, and returns the ciphertext \fIct\fR of size \fIctlen\fR. -On input \fIctlen\fR should contain the maximum size of the \fIct\fR buffer, and returns -the output size. An error will occur if the input \fIctlen\fR is -smaller than the value returned from \fBOSSL_HPKE_get_public_encap_size()\fR. -.PP -\&\fBOSSL_HPKE_encap()\fR must be called before the \fBOSSL_HPKE_seal()\fR. \fBOSSL_HPKE_seal()\fR -may be called multiple times, with an internal \*(L"nonce\*(R" being incremented by one -after each call. -.SS "Recipient APIs" -.IX Subsection "Recipient APIs" -Recipients using \s-1HPKE\s0 require a typically less ephemeral private value so that -the public value can be distributed to potential senders via whatever protocol -is using \s-1HPKE.\s0 For this reason, recipients will generally first generate a key -pair and will need to manage their private key value using standard mechanisms -outside the scope of this \s-1API.\s0 Private keys use normal \s-1\fBEVP_PKEY\s0\fR\|(3) pointers -so normal private key management mechanisms can be used for the relevant -values. -.PP -In order to enable encapsulation, the recipient needs to make it's public value -available to the sender. There is no generic \s-1HPKE\s0 format defined for that \- the -relevant formatting is intended to be defined by the application/protocols that -makes use of \s-1HPKE. ECH\s0 for example defines an ECHConfig data structure that -combines the public value with other \s-1ECH\s0 data items. Normal library functions -must therefore be used to extract the public value in the required format based -on the \s-1\fBEVP_PKEY\s0\fR\|(3) for the private value. -.PP -\&\fBOSSL_HPKE_keygen()\fR provides a way for recipients to generate a key pair based -on the \s-1HPKE\s0 \fIsuite\fR to be used. It returns a \s-1\fBEVP_PKEY\s0\fR\|(3) pointer -for the private value \fIpriv\fR and a encoded public key \fIpub\fR of size \fIpublen\fR. -On input \fIpublen\fR should contain the maximum size of the \fIpub\fR buffer, and -returns the output size. An error will occur if the input \fIpublen\fR is too small. -The \fIlibctx\fR and \fIpropq\fR are used when fetching algorithms from providers -and may be set to \s-1NULL.\s0 -The \s-1HPKE\s0 specification also defines a deterministic key generation scheme where -the private value is derived from initial keying material (\s-1IKM\s0), so -\&\fBOSSL_HPKE_keygen()\fR also has an option to use that scheme, using the \fIikm\fR -parameter of size \fIikmlen\fR. If either \fIikm\fR is \s-1NULL\s0 or \fIikmlen\fR is zero, -then a randomly generated key for the relevant \fIsuite\fR will be produced. -If required \fIikmlen\fR should be greater than or equal to -\&\fBOSSL_HPKE_get_recommended_ikmelen()\fR. -.PP -\&\fBOSSL_HPKE_decap()\fR takes as input the sender's encapsulated public value -produced by \fBOSSL_HPKE_encap()\fR (\fIenc\fR) and the recipient's \s-1\fBEVP_PKEY\s0\fR\|(3) -pointer (\fIprov\fR), and then re-generates the internal secret derived by the -sender. As before, an optional \fIinfo\fR parameter allows binding that derived -secret to other application/protocol artefacts. Only a single call to -\&\fBOSSL_HPKE_decap()\fR is allowed for a given \fB\s-1OSSL_HPKE_CTX\s0\fR. -.PP -\&\fBOSSL_HPKE_open()\fR is used by the recipient to decrypt the ciphertext \fIct\fR of -size \fIctlen\fR using the \fIctx\fR and additional authenticated data \fIaad\fR of -size \fIaadlen\fR, to produce the plaintext \fIpt\fR of size \fIptlen\fR. -On input \fIptlen\fR should contain the maximum size of the \fIpt\fR buffer, and -returns the output size. A \fIpt\fR buffer that is the same size as the -\&\fIct\fR buffer will suffice \- generally the plaintext output will be -a little smaller than the ciphertext input. -An error will occur if the input \fIptlen\fR is too small. -\&\fBOSSL_HPKE_open()\fR may be called multiple times, but as with \fBOSSL_HPKE_seal()\fR -there is an internally incrementing nonce value so ciphertexts need to be -presented in the same order as used by the \fBOSSL_HPKE_seal()\fR. -See \*(L"Re-sequencing\*(R" if you need to process multiple ciphertexts in a -different order. -.SS "Exporting Secrets" -.IX Subsection "Exporting Secrets" -\&\s-1HPKE\s0 defines a way to produce exported secrets for use by the -application. -.PP -\&\fBOSSL_HPKE_export()\fR takes as input the \fB\s-1OSSL_HPKE_CTX\s0\fR, and an application -supplied label \fIlabel\fR of size \fIlabellen\fR, to produce a secret \fIsecret\fR -of size \fIsecretlen\fR. The sender must first call \fBOSSL_HPKE_encap()\fR, and the -receiver must call \fBOSSL_HPKE_decap()\fR in order to derive the same shared secret. -.PP -Multiple calls to \fBOSSL_HPKE_export()\fR with the same inputs will produce the -same secret. -\&\fI\s-1OSSL_HPKE_AEAD_ID_EXPORTONLY\s0\fR may be used as the \fB\s-1OSSL_HPKE_SUITE\s0\fR \fIaead_id\fR -that is passed to \fBOSSL_HPKE_CTX_new()\fR if the user needs to produce a shared -secret, but does not wish to perform \s-1HPKE\s0 encryption. -.SS "Sender-authenticated \s-1HPKE\s0 Modes" -.IX Subsection "Sender-authenticated HPKE Modes" -\&\s-1HPKE\s0 defines modes that support KEM-based sender-authentication -\&\fB\s-1OSSL_HPKE_MODE_AUTH\s0\fR and \fB\s-1OSSL_HPKE_MODE_PSKAUTH\s0\fR. This works by binding -the sender's authentication private/public values into the encapsulation and -decapsulation operations. The key used for such modes must also use the same -\&\s-1KEM\s0 as used for the overall exchange. \fBOSSL_HPKE_keygen()\fR can be used to -generate the private value required. -.PP -\&\fBOSSL_HPKE_CTX_set1_authpriv()\fR can be used by the sender to set the senders -private \fIpriv\fR \fB\s-1EVP_PKEY\s0\fR key into the \fB\s-1OSSL_HPKE_CTX\s0\fR \fIctx\fR before calling -\&\fBOSSL_HPKE_encap()\fR. -.PP -\&\fBOSSL_HPKE_CTX_set1_authpub()\fR can be used by the receiver to set the senders -encoded pub key \fIpub\fR of size \fIpublen\fR into the \fB\s-1OSSL_HPKE_CTX\s0\fR \fIctx\fR before -calling \fBOSSL_HPKE_decap()\fR. -.SS "Pre-Shared Key \s-1HPKE\s0 modes" -.IX Subsection "Pre-Shared Key HPKE modes" -\&\s-1HPKE\s0 also defines a symmetric equivalent to the authentication described above -using a pre-shared key (\s-1PSK\s0) and a \s-1PSK\s0 identifier. PSKs can be used with the -\&\fB\s-1OSSL_HPKE_MODE_PSK\s0\fR and \fB\s-1OSSL_HPKE_MODE_PSKAUTH\s0\fR modes. -.PP -\&\fBOSSL_HPKE_CTX_set1_psk()\fR sets the \s-1PSK\s0 identifier \fIpskid\fR string, and \s-1PSK\s0 buffer -\&\fIpsk\fR of size \fIpsklen\fR into the \fIctx\fR. If required this must be called -before \fBOSSL_HPKE_encap()\fR or \fBOSSL_HPKE_decap()\fR. -As per \s-1RFC9180,\s0 if required, both \fIpsk\fR and \fIpskid\fR must be set to non-NULL values. -As PSKs are symmetric the same calls must happen on both sender and receiver -sides. -.SS "Deterministic key generation for senders" -.IX Subsection "Deterministic key generation for senders" -Normally the senders ephemeral private key is generated randomly inside -\&\fBOSSL_HPKE_encap()\fR and remains secret. -\&\fBOSSL_HPKE_CTX_set1_ikme()\fR allows the user to override this behaviour by -setting a deterministic input key material \fIikm\fR of size \fIikmlen\fR into -the \fB\s-1OSSL_HPKE_CTX\s0\fR \fIctx\fR. -If required \fBOSSL_HPKE_CTX_set1_ikme()\fR can optionally be called before -\&\fBOSSL_HPKE_encap()\fR. -\&\fIikmlen\fR should be greater than or equal to \fBOSSL_HPKE_get_recommended_ikmelen()\fR. -.PP -It is generally undesirable to use \fBOSSL_HPKE_CTX_set1_ikme()\fR, since it -exposes the relevant secret to the application rather then preserving it -within the library, and is more likely to result in use of predictable values -or values that leak. -.SS "Re-sequencing" -.IX Subsection "Re-sequencing" -Some protocols may have to deal with packet loss while still being able to -decrypt arriving packets later. We provide a way to set the increment used for -the nonce to the next subsequent call to \fBOSSL_HPKE_open()\fR (but not to -\&\fBOSSL_HPKE_seal()\fR as explained below). The \fBOSSL_HPKE_CTX_set_seq()\fR \s-1API\s0 can be -used for such purposes with the \fIseq\fR parameter value resetting the internal -nonce increment to be used for the next call. -.PP -A baseline nonce value is established based on the encapsulation or -decapsulation operation and is then incremented by 1 for each call to seal or -open. (In other words, the first \fIseq\fR increment defaults to zero.) -.PP -If a caller needs to determine how many calls to seal or open have been made -the \fBOSSL_HPKE_CTX_get_seq()\fR \s-1API\s0 can be used to retrieve the increment (in the -\&\fIseq\fR output) that will be used in the next call to seal or open. That would -return 0 before the first call a sender made to \fBOSSL_HPKE_seal()\fR and 1 after -that first call. -.PP -Note that reuse of the same nonce and key with different plaintexts would -be very dangerous and could lead to loss of confidentiality and integrity. -We therefore only support application control over \fIseq\fR for decryption -(i.e. \fBOSSL_HPKE_open()\fR) operations. -.PP -For compatibility with other implementations these \fIseq\fR increments are -represented as \fIuint64_t\fR. -.SS "Protocol Convenience Functions" -.IX Subsection "Protocol Convenience Functions" -Additional convenience APIs allow the caller to access internal details of -local \s-1HPKE\s0 support and/or algorithms, such as parameter lengths. -.PP -\&\fBOSSL_HPKE_suite_check()\fR checks if a specific \fB\s-1OSSL_HPKE_SUITE\s0\fR \fIsuite\fR -is supported locally. -.PP -To assist with memory allocation, \fBOSSL_HPKE_get_ciphertext_size()\fR provides a -way for the caller to know by how much ciphertext will be longer than a -plaintext of length \fIclearlen\fR. (\s-1AEAD\s0 algorithms add a data integrity tag, -so there is a small amount of ciphertext expansion.) -.PP -\&\fBOSSL_HPKE_get_public_encap_size()\fR provides a way for senders to know how big -the encapsulated public value will be for a given \s-1HPKE\s0 \fIsuite\fR. -.PP -\&\fBOSSL_HPKE_get_recommended_ikmelen()\fR returns the recommended Input Key Material -size (in bytes) for a given \fIsuite\fR. This is needed in cases where the same -public value needs to be regenerated by a sender before calling \fBOSSL_HPKE_seal()\fR. -\&\fIikmlen\fR should be at least this size. -.PP -\&\fBOSSL_HPKE_get_grease_value()\fR produces values of the appropriate length for a -given \fIsuite_in\fR value (or a random value if \fIsuite_in\fR is \s-1NULL\s0) so that a -protocol using \s-1HPKE\s0 can send so-called \s-1GREASE\s0 (see \s-1RFC8701\s0) values that are -harder to distinguish from a real use of \s-1HPKE.\s0 The buffer sizes should -be supplied on input. The output \fIenc\fR value will have an appropriate -length for \fIsuite_out\fR and a random value, and the \fIct\fR output will be -a random value. The relevant sizes for buffers can be found using -\&\fBOSSL_HPKE_get_ciphertext_size()\fR and \fBOSSL_HPKE_get_public_encap_size()\fR. -.PP -\&\fBOSSL_HPKE_str2suite()\fR maps input \fIstr\fR strings to an \fB\s-1OSSL_HPKE_SUITE\s0\fR object. -The input \fIstr\fR should be a comma-separated string with a \s-1KEM, -KDF\s0 and \s-1AEAD\s0 name in that order, for example \*(L"x25519,hkdf\-sha256,aes128gcm\*(R". -This can be used by command line tools that accept string form names for \s-1HPKE\s0 -codepoints. Valid (case-insensitive) names are: -\&\*(L"p\-256\*(R", \*(L"p\-384\*(R", \*(L"p\-521\*(R", \*(L"x25519\*(R" and \*(L"x448\*(R" for \s-1KEM,\s0 -\&\*(L"hkdf\-sha256\*(R", \*(L"hkdf\-sha384\*(R" and \*(L"hkdf\-sha512\*(R" for \s-1KDF,\s0 and -\&\*(L"aes\-gcm\-128\*(R", \*(L"aes\-gcm\-256\*(R", \*(L"chacha20\-poly1305\*(R" and \*(L"exporter\*(R" for \s-1AEAD.\s0 -String variants of the numbers listed in \*(L"\s-1OSSL_HPKE_SUITE\s0 Identifiers\*(R" -can also be used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_HPKE_CTX_new()\fR returns an \s-1OSSL_HPKE_CTX\s0 pointer or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_HPKE_get_ciphertext_size()\fR, \fBOSSL_HPKE_get_public_encap_size()\fR, -\&\fBOSSL_HPKE_get_recommended_ikmelen()\fR all return a size_t with the -relevant value or zero on error. -.PP -All other functions return 1 for success or zero for error. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example demonstrates a minimal round-trip using \s-1HPKE.\s0 -.PP -.Vb 4 -\& #include -\& #include -\& #include -\& #include -\& -\& /* -\& * this is big enough for this example, real code would need different -\& * handling -\& */ -\& #define LBUFSIZE 48 -\& -\& /* Do a round\-trip, generating a key, encrypting and decrypting */ -\& int main(int argc, char **argv) -\& { -\& int ok = 0; -\& int hpke_mode = OSSL_HPKE_MODE_BASE; -\& OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; -\& OSSL_HPKE_CTX *sctx = NULL, *rctx = NULL; -\& EVP_PKEY *priv = NULL; -\& unsigned char pub[LBUFSIZE]; -\& size_t publen = sizeof(pub); -\& unsigned char enc[LBUFSIZE]; -\& size_t enclen = sizeof(enc); -\& unsigned char ct[LBUFSIZE]; -\& size_t ctlen = sizeof(ct); -\& unsigned char clear[LBUFSIZE]; -\& size_t clearlen = sizeof(clear); -\& const unsigned char *pt = "a message not in a bottle"; -\& size_t ptlen = strlen((char *)pt); -\& const unsigned char *info = "Some info"; -\& size_t infolen = strlen((char *)info); -\& unsigned char aad[] = { 1, 2, 3, 4, 5, 6, 7, 8 }; -\& size_t aadlen = sizeof(aad); -\& -\& /* -\& * Generate receiver\*(Aqs key pair. -\& * The receiver gives this public key to the sender. -\& */ -\& if (OSSL_HPKE_keygen(hpke_suite, pub, &publen, &priv, -\& NULL, 0, NULL, NULL) != 1) -\& goto err; -\& -\& /* sender\*(Aqs actions \- encrypt data using the receivers public key */ -\& if ((sctx = OSSL_HPKE_CTX_new(hpke_mode, hpke_suite, -\& OSSL_HPKE_ROLE_SENDER, -\& NULL, NULL)) == NULL) -\& goto err; -\& if (OSSL_HPKE_encap(sctx, enc, &enclen, pub, publen, info, infolen) != 1) -\& goto err; -\& if (OSSL_HPKE_seal(sctx, ct, &ctlen, aad, aadlen, pt, ptlen) != 1) -\& goto err; -\& -\& /* receiver\*(Aqs actions \- decrypt data using the receivers private key */ -\& if ((rctx = OSSL_HPKE_CTX_new(hpke_mode, hpke_suite, -\& OSSL_HPKE_ROLE_RECEIVER, -\& NULL, NULL)) == NULL) -\& goto err; -\& if (OSSL_HPKE_decap(rctx, enc, enclen, priv, info, infolen) != 1) -\& goto err; -\& if (OSSL_HPKE_open(rctx, clear, &clearlen, aad, aadlen, ct, ctlen) != 1) -\& goto err; -\& ok = 1; -\& err: -\& /* clean up */ -\& printf(ok ? "All Good!\en" : "Error!\en"); -\& OSSL_HPKE_CTX_free(rctx); -\& OSSL_HPKE_CTX_free(sctx); -\& EVP_PKEY_free(priv); -\& return 0; -\& } -.Ve -.SH "WARNINGS" -.IX Header "WARNINGS" -Note that the \fBOSSL_HPKE_CTX_set_seq()\fR \s-1API\s0 could be dangerous \- if used with \s-1GCM\s0 -that could lead to nonce-reuse, which is a known danger. So avoid that -entirely, or be very very careful when using that \s-1API.\s0 -.PP -Use of an \s-1IKM\s0 value for deterministic key generation (via -\&\fBOSSL_HPKE_CTX_set1_ikme()\fR or \fBOSSL_HPKE_keygen()\fR) creates the potential for -leaking keys (or \s-1IKM\s0 values). Only use that if really needed and if you -understand how keys or \s-1IKM\s0 values could be abused. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -The \s-1RFC9180\s0 specification: https://datatracker.ietf.org/doc/rfc9180/ -.SH "HISTORY" -.IX Header "HISTORY" -This functionality described here was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpriv.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpriv.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpriv.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpub.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpub.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_authpub.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_ikme.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_ikme.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_ikme.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_psk.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_psk.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set1_psk.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set_seq.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_CTX_set_seq.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_CTX_set_seq.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_decap.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_decap.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_decap.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_encap.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_encap.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_encap.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_export.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_export.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_export.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_get_ciphertext_size.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_get_ciphertext_size.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_get_ciphertext_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_get_grease_value.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_get_grease_value.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_get_grease_value.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_get_public_encap_size.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_get_public_encap_size.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_get_public_encap_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_get_recommended_ikmelen.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_get_recommended_ikmelen.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_get_recommended_ikmelen.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_keygen.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_keygen.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_open.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_open.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_open.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_seal.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_seal.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_seal.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_str2suite.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_str2suite.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_str2suite.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HPKE_suite_check.3ossl b/openssl-install/share/man/man3/OSSL_HPKE_suite_check.3ossl deleted file mode 120000 index da5de7d3..00000000 --- a/openssl-install/share/man/man3/OSSL_HPKE_suite_check.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HPKE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX.3ossl deleted file mode 100644 index f0d8c6f4..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX.3ossl +++ /dev/null @@ -1,418 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_HTTP_REQ_CTX 3ossl" -.TH OSSL_HTTP_REQ_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_HTTP_REQ_CTX, -OSSL_HTTP_REQ_CTX_new, -OSSL_HTTP_REQ_CTX_free, -OSSL_HTTP_REQ_CTX_set_request_line, -OSSL_HTTP_REQ_CTX_add1_header, -OSSL_HTTP_REQ_CTX_set_expected, -OSSL_HTTP_REQ_CTX_set1_req, -OSSL_HTTP_REQ_CTX_nbio, -OSSL_HTTP_REQ_CTX_nbio_d2i, -OSSL_HTTP_REQ_CTX_exchange, -OSSL_HTTP_REQ_CTX_get0_mem_bio, -OSSL_HTTP_REQ_CTX_get_resp_len, -OSSL_HTTP_REQ_CTX_set_max_response_length, -OSSL_HTTP_is_alive, -OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines -\&\- HTTP client low\-level functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_http_req_ctx_st OSSL_HTTP_REQ_CTX; -\& -\& OSSL_HTTP_REQ_CTX *OSSL_HTTP_REQ_CTX_new(BIO *wbio, BIO *rbio, int buf_size); -\& void OSSL_HTTP_REQ_CTX_free(OSSL_HTTP_REQ_CTX *rctx); -\& -\& int OSSL_HTTP_REQ_CTX_set_request_line(OSSL_HTTP_REQ_CTX *rctx, int method_POST, -\& const char *server, const char *port, -\& const char *path); -\& int OSSL_HTTP_REQ_CTX_add1_header(OSSL_HTTP_REQ_CTX *rctx, -\& const char *name, const char *value); -\& -\& int OSSL_HTTP_REQ_CTX_set_expected(OSSL_HTTP_REQ_CTX *rctx, -\& const char *content_type, int asn1, -\& int timeout, int keep_alive); -\& int OSSL_HTTP_REQ_CTX_set1_req(OSSL_HTTP_REQ_CTX *rctx, const char *content_type, -\& const ASN1_ITEM *it, const ASN1_VALUE *req); -\& int OSSL_HTTP_REQ_CTX_nbio(OSSL_HTTP_REQ_CTX *rctx); -\& int OSSL_HTTP_REQ_CTX_nbio_d2i(OSSL_HTTP_REQ_CTX *rctx, -\& ASN1_VALUE **pval, const ASN1_ITEM *it); -\& BIO *OSSL_HTTP_REQ_CTX_exchange(OSSL_HTTP_REQ_CTX *rctx); -\& -\& BIO *OSSL_HTTP_REQ_CTX_get0_mem_bio(const OSSL_HTTP_REQ_CTX *rctx); -\& size_t OSSL_HTTP_REQ_CTX_get_resp_len(const OSSL_HTTP_REQ_CTX *rctx); -\& void OSSL_HTTP_REQ_CTX_set_max_response_length(OSSL_HTTP_REQ_CTX *rctx, -\& unsigned long len); -\& -\& int OSSL_HTTP_is_alive(const OSSL_HTTP_REQ_CTX *rctx); -\& -\& void OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines(OSSL_HTTP_REQ_CTX *rctx, -\& size_t count); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_HTTP_REQ_CTX\s0\fR is a context structure for an \s-1HTTP\s0 request and response, -used to collect all the necessary data to perform that request. -.PP -This file documents low-level \s-1HTTP\s0 functions rarely used directly. High-level -\&\s-1HTTP\s0 client functions like \fBOSSL_HTTP_get\fR\|(3) and \fBOSSL_HTTP_transfer\fR\|(3) -should be preferred. -.PP -\&\fBOSSL_HTTP_REQ_CTX_new()\fR allocates a new \s-1HTTP\s0 request context structure, -which gets populated with the \fB\s-1BIO\s0\fR to write/send the request to (\fIwbio\fR), -the \fB\s-1BIO\s0\fR to read/receive the response from (\fIrbio\fR, which may be equal to -\&\fIwbio\fR), and the maximum expected response header line length \fIbuf_size\fR. -A value <= 0 indicates that -the \fB\s-1OSSL_HTTP_DEFAULT_MAX_LINE_LEN\s0\fR of 4KiB should be used. -\&\fIbuf_size\fR is also used as the number of content bytes that are read at a time. -The allocated context structure includes an internal memory \fB\s-1BIO\s0\fR, -which collects the \s-1HTTP\s0 request header lines. -.PP -\&\fBOSSL_HTTP_REQ_CTX_free()\fR frees up the \s-1HTTP\s0 request context \fIrctx\fR. -The \fIrbio\fR is not free'd, \fIwbio\fR will be free'd if \fIfree_wbio\fR is set. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_HTTP_REQ_CTX_set_request_line()\fR adds the 1st \s-1HTTP\s0 request line to \fIrctx\fR. -The \s-1HTTP\s0 method is determined by \fImethod_POST\fR, -which should be 1 to indicate \f(CW\*(C`POST\*(C'\fR or 0 to indicate \f(CW\*(C`GET\*(C'\fR. -\&\fIserver\fR and \fIport\fR may be set to give the server and the optional port that -an \s-1HTTP\s0 proxy shall forward the request to, otherwise they must be left \s-1NULL.\s0 -\&\fIpath\fR provides the \s-1HTTP\s0 request path; if left \s-1NULL,\s0 \f(CW\*(C`/\*(C'\fR is used. -For backward compatibility, \fIpath\fR may begin with \f(CW\*(C`http://\*(C'\fR and thus convey -an absoluteURI. In this case it indicates \s-1HTTP\s0 proxy use and provides also the -server (and optionally the port) that the proxy shall forward the request to. -In this case the \fIserver\fR and \fIport\fR arguments must be \s-1NULL.\s0 -.PP -\&\fBOSSL_HTTP_REQ_CTX_add1_header()\fR adds header \fIname\fR with value \fIvalue\fR to the -context \fIrctx\fR. It can be called more than once to add multiple header lines. -For example, to add a \f(CW\*(C`Host\*(C'\fR header for \f(CW\*(C`example.com\*(C'\fR you would call: -.PP -.Vb 1 -\& OSSL_HTTP_REQ_CTX_add1_header(ctx, "Host", "example.com"); -.Ve -.PP -\&\fBOSSL_HTTP_REQ_CTX_set_expected()\fR optionally sets in \fIrctx\fR some expectations -of the \s-1HTTP\s0 client on the response. -Due to the structure of an \s-1HTTP\s0 request, if the \fIkeep_alive\fR argument is -nonzero the function must be used before calling \fBOSSL_HTTP_REQ_CTX_set1_req()\fR. -.PP -If the \fIcontent_type\fR argument is not \s-1NULL,\s0 -the client will check that the specified content-type string -is included in the \s-1HTTP\s0 header of the response and return an error if not. -In the content-type header line the specified string should be present either -as a whole, or in case the specified string does not include a \f(CW\*(C`;\*(C'\fR character, -it is sufficient that the specified string appears as a prefix -in the header line, followed by a \f(CW\*(C`;\*(C'\fR character and any further text. -For instance, if the \fIcontent_type\fR argument specifies \f(CW\*(C`text/html\*(C'\fR, -this is matched by \f(CW\*(C`text/html\*(C'\fR, \f(CW\*(C`text/html; charset=UTF\-8\*(C'\fR, etc. -.PP -If the \fIasn1\fR parameter is nonzero a structure in \s-1ASN.1\s0 encoding will be -expected as the response content and input streaming is disabled. This means -that an \s-1ASN.1\s0 sequence header is required, its length field is checked, and -\&\fBOSSL_HTTP_REQ_CTX_get0_mem_bio()\fR should be used to get the buffered response. -Otherwise (by default) any input format is allowed without length checks. -In this case the \s-1BIO\s0 given as \fIrbio\fR argument to \fBOSSL_HTTP_REQ_CTX_new()\fR should -be used directly to read the response contents, which may support streaming. -If the \fItimeout\fR parameter is > 0 this indicates the maximum number of seconds -the subsequent \s-1HTTP\s0 transfer (sending the request and receiving a response) -is allowed to take. -\&\fItimeout\fR == 0 enables waiting indefinitely, i.e., no timeout can occur. -This is the default. -\&\fItimeout\fR < 0 takes over any value set via the \fIoverall_timeout\fR argument of -\&\fBOSSL_HTTP_open\fR\|(3) with the default being 0, which means no timeout. -If the \fIkeep_alive\fR parameter is 0, which is the default, the connection is not -kept open after receiving a response. This is the default behavior for \s-1HTTP 1.0.\s0 -If the value is 1 or 2 then a persistent connection is requested. -If the value is 2 then a persistent connection is required, -i.e., an error occurs in case the server does not grant it. -.PP -\&\fBOSSL_HTTP_REQ_CTX_set1_req()\fR finalizes the \s-1HTTP\s0 request context. -It is needed if the \fImethod_POST\fR parameter in the -\&\fBOSSL_HTTP_REQ_CTX_set_request_line()\fR call was 1 -and an \s-1ASN\s0.1\-encoded request should be sent. -It must also be used when requesting \*(L"keep-alive\*(R", -even if a \s-1GET\s0 request is going to be sent, in which case \fIreq\fR must be \s-1NULL.\s0 -Unless \fIreq\fR is \s-1NULL,\s0 the function adds the \s-1DER\s0 encoding of \fIreq\fR using -the \s-1ASN.1\s0 template \fIit\fR to do the encoding (which does not support streaming). -The \s-1HTTP\s0 header \f(CW\*(C`Content\-Length\*(C'\fR is filled out with the length of the request. -\&\fIcontent_type\fR must be \s-1NULL\s0 if \fIreq\fR is \s-1NULL.\s0 -If \fIcontent_type\fR isn't \s-1NULL,\s0 -the \s-1HTTP\s0 header \f(CW\*(C`Content\-Type\*(C'\fR is also added with the given string value. -The header lines are added to the internal memory \fB\s-1BIO\s0\fR for the request header. -.PP -\&\fBOSSL_HTTP_REQ_CTX_nbio()\fR attempts to send the request prepared in \fIrctx\fR -and to gather the response via \s-1HTTP,\s0 using the \fIwbio\fR and \fIrbio\fR -that were given when calling \fBOSSL_HTTP_REQ_CTX_new()\fR. -The function may need to be called again if its result is \-1, which indicates -\&\fBBIO_should_retry\fR\|(3). In such a case it is advisable to sleep a little in -between, using \fBBIO_wait\fR\|(3) on the read \s-1BIO\s0 to prevent a busy loop. -.PP -\&\fBOSSL_HTTP_REQ_CTX_nbio_d2i()\fR is like \fBOSSL_HTTP_REQ_CTX_nbio()\fR but on success -in addition parses the response, which must be a DER-encoded \s-1ASN.1\s0 structure, -using the \s-1ASN.1\s0 template \fIit\fR and places the result in \fI*pval\fR. -.PP -\&\fBOSSL_HTTP_REQ_CTX_exchange()\fR calls \fBOSSL_HTTP_REQ_CTX_nbio()\fR as often as needed -in order to exchange a request and response or until a timeout is reached. -On success it returns a pointer to the \s-1BIO\s0 that can be used to read the result. -If an \s-1ASN\s0.1\-encoded response was expected, this is the \s-1BIO\s0 -returned by \fBOSSL_HTTP_REQ_CTX_get0_mem_bio()\fR when called after the exchange. -This memory \s-1BIO\s0 does not support streaming. -Otherwise the returned \s-1BIO\s0 is the \fIrbio\fR given to \fBOSSL_HTTP_REQ_CTX_new()\fR, -which may support streaming. -When this \s-1BIO\s0 is returned, it has been read past the end of the response header, -such that the actual response body can be read from it. -The returned \s-1BIO\s0 pointer \s-1MUST NOT\s0 be freed by the caller. -.PP -\&\fBOSSL_HTTP_REQ_CTX_get0_mem_bio()\fR returns the internal memory \fB\s-1BIO\s0\fR. -Before the \s-1HTTP\s0 request is sent, this could be used to adapt its header lines. -\&\fIUse with caution!\fR -After receiving a response via \s-1HTTP,\s0 the \s-1BIO\s0 represents the current state of -reading the response header. If the response was expected to be \s-1ASN.1\s0 encoded, -its contents can be read via this \s-1BIO,\s0 which does not support streaming. -The returned \s-1BIO\s0 pointer must not be freed by the caller. -.PP -\&\fBOSSL_HTTP_REQ_CTX_get_resp_len()\fR returns the size of the response contents -in \fIrctx\fR if provided by the server as header field, else 0. -.PP -\&\fBOSSL_HTTP_REQ_CTX_set_max_response_length()\fR sets the maximum allowed -response content length for \fIrctx\fR to \fIlen\fR. If not set or \fIlen\fR is 0 -then the \fB\s-1OSSL_HTTP_DEFAULT_MAX_RESP_LEN\s0\fR is used, which currently is 100 KiB. -If the \f(CW\*(C`Content\-Length\*(C'\fR header is present and exceeds this value or -the content is an \s-1ASN.1\s0 encoded structure with a length exceeding this value -or both length indications are present but disagree then an error occurs. -.PP -\&\fBOSSL_HTTP_is_alive()\fR can be used to query if the \s-1HTTP\s0 connection -given by \fIrctx\fR is still alive, i.e., has not been closed. -It returns 0 if \fIrctx\fR is \s-1NULL.\s0 -.PP -If the client application requested or required a persistent connection -and this was granted by the server, it can keep \fIrctx\fR as long as it wants -to send further requests and \fBOSSL_HTTP_is_alive()\fR returns nonzero, -else it should call \fIOSSL_HTTP_REQ_CTX_free(rctx)\fR or \fBOSSL_HTTP_close\fR\|(3). -In case the client application keeps \fIrctx\fR but the connection then dies -for any reason at the server side, it will notice this obtaining an -I/O error when trying to send the next request via \fIrctx\fR. -.PP -The \fBOSSL_HTTP_REQ_CTX_set_max_response_hdr_lines()\fR function changes the limit -for the number of \s-1HTTP\s0 headers which can be received in a response. The default -value is 256. If the number of \s-1HTTP\s0 headers in a response exceeds the limit, -then the \s-1HTTP_R_RESPONSE_TOO_MANY_HDRLINES\s0 error is indicated. Setting the -limit to 0 disables the check. -.SH "WARNINGS" -.IX Header "WARNINGS" -The server's response may be unexpected if the hostname that was used to -create the \fIwbio\fR, any \f(CW\*(C`Host\*(C'\fR header, and the host specified in the -request \s-1URL\s0 do not match. -.PP -Many of these functions must be called in a certain order. -.PP -First, the \s-1HTTP\s0 request context must be allocated: -\&\fBOSSL_HTTP_REQ_CTX_new()\fR. -.PP -Then, the \s-1HTTP\s0 request must be prepared with request data: -.IP "1." 4 -Calling \fBOSSL_HTTP_REQ_CTX_set_request_line()\fR. -.IP "2." 4 -Adding extra header lines with \fBOSSL_HTTP_REQ_CTX_add1_header()\fR. -This is optional and may be done multiple times with different names. -.IP "3." 4 -Finalize the request using \fBOSSL_HTTP_REQ_CTX_set1_req()\fR. -This may be omitted if the \s-1GET\s0 method is used and \*(L"keep-alive\*(R" is not requested. -.PP -When the request context is fully prepared, the \s-1HTTP\s0 exchange may be performed -with \fBOSSL_HTTP_REQ_CTX_nbio()\fR or \fBOSSL_HTTP_REQ_CTX_exchange()\fR. -.SH "NOTES" -.IX Header "NOTES" -When built with tracing enabled, \fBOSSL_HTTP_REQ_CTX_nbio()\fR and all functions -using it, such as \fBOSSL_HTTP_REQ_CTX_exchange()\fR and \fBOSSL_HTTP_transfer\fR\|(3), -may be traced using \fB\s-1OSSL_TRACE_CATEGORY_HTTP\s0\fR. -See also \fBOSSL_trace_enabled\fR\|(3) and \fBopenssl\-env\fR\|(7). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_HTTP_REQ_CTX_new()\fR returns a pointer to a \fB\s-1OSSL_HTTP_REQ_CTX\s0\fR, or \s-1NULL\s0 -on error. -.PP -\&\fBOSSL_HTTP_REQ_CTX_free()\fR and \fBOSSL_HTTP_REQ_CTX_set_max_response_length()\fR -do not return values. -.PP -\&\fBOSSL_HTTP_REQ_CTX_set_request_line()\fR, \fBOSSL_HTTP_REQ_CTX_add1_header()\fR, -\&\fBOSSL_HTTP_REQ_CTX_set1_req()\fR, and \fBOSSL_HTTP_REQ_CTX_set_expected()\fR -return 1 for success and 0 for failure. -.PP -\&\fBOSSL_HTTP_REQ_CTX_nbio()\fR and \fBOSSL_HTTP_REQ_CTX_nbio_d2i()\fR -return 1 for success, 0 on error or redirection, \-1 if retry is needed. -.PP -\&\fBOSSL_HTTP_REQ_CTX_exchange()\fR and \fBOSSL_HTTP_REQ_CTX_get0_mem_bio()\fR -return a pointer to a \fB\s-1BIO\s0\fR on success as described above or \s-1NULL\s0 on failure. -The returned \s-1BIO\s0 must not be freed by the caller. -.PP -\&\fBOSSL_HTTP_REQ_CTX_get_resp_len()\fR returns the size of the response contents -or 0 if not available or an error occurred. -.PP -\&\fBOSSL_HTTP_is_alive()\fR returns 1 if its argument is non-NULL -and the client requested a persistent connection -and the server did not disagree on keeping the connection open, else 0. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_should_retry\fR\|(3), -\&\fBBIO_wait\fR\|(3), -\&\fBASN1_item_d2i_bio\fR\|(3), -\&\fBASN1_item_i2d_mem_bio\fR\|(3), -\&\fBOSSL_HTTP_open\fR\|(3), -\&\fBOSSL_HTTP_get\fR\|(3), -\&\fBOSSL_HTTP_transfer\fR\|(3), -\&\fBOSSL_HTTP_close\fR\|(3), -\&\fBOSSL_trace_enabled\fR\|(3), and \fBopenssl\-env\fR\|(7). -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_add1_header.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_add1_header.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_add1_header.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_exchange.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_exchange.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_exchange.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_free.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_free.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get0_mem_bio.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get0_mem_bio.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get0_mem_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get_resp_len.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get_resp_len.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_get_resp_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio_d2i.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio_d2i.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_nbio_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_new.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_new.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set1_req.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set1_req.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set1_req.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_expected.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_expected.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_expected.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_length.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_length.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_max_response_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_request_line.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_request_line.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_REQ_CTX_set_request_line.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_adapt_proxy.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_adapt_proxy.3ossl deleted file mode 120000 index 0a203382..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_adapt_proxy.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_parse_url.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_bio_cb_t.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_bio_cb_t.3ossl deleted file mode 120000 index c2f0e130..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_bio_cb_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_transfer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_close.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_close.3ossl deleted file mode 120000 index c2f0e130..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_close.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_transfer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_exchange.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_exchange.3ossl deleted file mode 120000 index c2f0e130..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_exchange.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_transfer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_get.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_get.3ossl deleted file mode 120000 index c2f0e130..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_transfer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_is_alive.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_is_alive.3ossl deleted file mode 120000 index 71d875ab..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_is_alive.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_REQ_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_open.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_open.3ossl deleted file mode 120000 index c2f0e130..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_open.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_transfer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_parse_url.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_parse_url.3ossl deleted file mode 100644 index 31b2efa1..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_parse_url.3ossl +++ /dev/null @@ -1,245 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_HTTP_PARSE_URL 3ossl" -.TH OSSL_HTTP_PARSE_URL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_HTTP_adapt_proxy, -OSSL_parse_url, -OSSL_HTTP_parse_url, -OCSP_parse_url -\&\- http utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *OSSL_HTTP_adapt_proxy(const char *proxy, const char *no_proxy, -\& const char *server, int use_ssl); -\& -\& int OSSL_parse_url(const char *url, char **pscheme, char **puser, char **phost, -\& char **pport, int *pport_num, -\& char **ppath, char **pquery, char **pfrag); -\& int OSSL_HTTP_parse_url(const char *url, -\& int *pssl, char **puser, char **phost, -\& char **pport, int *pport_num, -\& char **ppath, char **pquery, char **pfrag); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int OCSP_parse_url(const char *url, char **phost, char **pport, char **ppath, -\& int *pssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_HTTP_adapt_proxy()\fR takes an optional proxy hostname \fIproxy\fR -and returns it transformed according to the optional \fIno_proxy\fR parameter, -\&\fIserver\fR, \fIuse_ssl\fR, and the applicable environment variable, as follows. -If \fIproxy\fR is \s-1NULL,\s0 take any default value from the \f(CW\*(C`http_proxy\*(C'\fR -environment variable, or from \f(CW\*(C`https_proxy\*(C'\fR if \fIuse_ssl\fR is nonzero. -If this still does not yield a proxy hostname, -take any further default value from the \f(CW\*(C`HTTP_PROXY\*(C'\fR -environment variable, or from \f(CW\*(C`HTTPS_PROXY\*(C'\fR if \fIuse_ssl\fR is nonzero. -If \fIno_proxy\fR is \s-1NULL,\s0 take any default exclusion value from the \f(CW\*(C`no_proxy\*(C'\fR -environment variable, or else from \f(CW\*(C`NO_PROXY\*(C'\fR. -Return the determined proxy host unless the exclusion value, -which is a list of proxy hosts separated by \f(CW\*(C`,\*(C'\fR and/or whitespace, -contains \fIserver\fR. -Otherwise return \s-1NULL.\s0 -When \fIserver\fR is a string delimited by \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR, which are used for IPv6 -addresses, the enclosing \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR are stripped prior to comparison. -.PP -\&\fBOSSL_parse_url()\fR parses its input string \fIurl\fR as a \s-1URL\s0 of the form -\&\f(CW\*(C`[scheme://][userinfo@]host[:port][/path][?query][#fragment]\*(C'\fR and splits it up -into scheme, userinfo, host, port, path, query, and fragment components. -The host (or server) component may be a \s-1DNS\s0 name or an \s-1IP\s0 address -where IPv6 addresses must be enclosed in square brackets \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -The port component is optional and defaults to \f(CW0\fR. -If given, it must be in decimal form. If the \fIpport_num\fR argument is not \s-1NULL\s0 -the integer value of the port number is assigned to \fI*pport_num\fR on success. -The path component is also optional and defaults to \f(CW\*(C`/\*(C'\fR. -Each non-NULL result pointer argument \fIpscheme\fR, \fIpuser\fR, \fIphost\fR, \fIpport\fR, -\&\fIppath\fR, \fIpquery\fR, and \fIpfrag\fR, is assigned the respective url component. -Any IPv6 address in \fI*phost\fR is enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -On success, they are guaranteed to contain non-NULL string pointers, else \s-1NULL.\s0 -It is the responsibility of the caller to free them using \fBOPENSSL_free\fR\|(3). -If \fIpquery\fR is \s-1NULL,\s0 any given query component is handled as part of the path. -A string returned via \fI*ppath\fR is guaranteed to begin with a \f(CW\*(C`/\*(C'\fR character. -For absent scheme, userinfo, port, query, and fragment components -an empty string is provided. -.PP -\&\fBOSSL_HTTP_parse_url()\fR is a special form of \fBOSSL_parse_url()\fR -where the scheme, if given, must be \f(CW\*(C`http\*(C'\fR or \f(CW\*(C`https\*(C'\fR. -If \fIpssl\fR is not \s-1NULL,\s0 \fI*pssl\fR is assigned 1 in case parsing was successful -and the scheme is \f(CW\*(C`https\*(C'\fR, else 0. -The port component is optional and defaults to \f(CW443\fR if the scheme is \f(CW\*(C`https\*(C'\fR, -else \f(CW80\fR. -Note that relative paths must be given with a leading \f(CW\*(C`/\*(C'\fR, -otherwise the first path element is interpreted as the host. -.PP -Calling the deprecated function OCSP_parse_url(url, host, port, path, ssl) -is equivalent to -OSSL_HTTP_parse_url(url, ssl, \s-1NULL,\s0 host, port, \s-1NULL,\s0 path, \s-1NULL, NULL\s0). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_HTTP_adapt_proxy()\fR returns \s-1NULL\s0 if no proxy is to be used, -otherwise a constant proxy hostname string, -which is either the proxy name handed in or an environment variable value. -.PP -\&\fBOSSL_parse_url()\fR, \fBOSSL_HTTP_parse_url()\fR, and \fBOCSP_parse_url()\fR -return 1 on success, 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_HTTP_transfer\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_HTTP_adapt_proxy()\fR, -\&\fBOSSL_parse_url()\fR and \fBOSSL_HTTP_parse_url()\fR were added in OpenSSL 3.0. -\&\fBOCSP_parse_url()\fR was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_HTTP_proxy_connect.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_proxy_connect.3ossl deleted file mode 120000 index c2f0e130..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_proxy_connect.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_transfer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_set1_request.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_set1_request.3ossl deleted file mode 120000 index c2f0e130..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_set1_request.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_transfer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_HTTP_transfer.3ossl b/openssl-install/share/man/man3/OSSL_HTTP_transfer.3ossl deleted file mode 100644 index 46ea131e..00000000 --- a/openssl-install/share/man/man3/OSSL_HTTP_transfer.3ossl +++ /dev/null @@ -1,440 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_HTTP_TRANSFER 3ossl" -.TH OSSL_HTTP_TRANSFER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_HTTP_open, -OSSL_HTTP_bio_cb_t, -OSSL_HTTP_proxy_connect, -OSSL_HTTP_set1_request, -OSSL_HTTP_exchange, -OSSL_HTTP_get, -OSSL_HTTP_transfer, -OSSL_HTTP_close -\&\- HTTP client high\-level functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef BIO *(*OSSL_HTTP_bio_cb_t)(BIO *bio, void *arg, -\& int connect, int detail); -\& OSSL_HTTP_REQ_CTX *OSSL_HTTP_open(const char *server, const char *port, -\& const char *proxy, const char *no_proxy, -\& int use_ssl, BIO *bio, BIO *rbio, -\& OSSL_HTTP_bio_cb_t bio_update_fn, void *arg, -\& int buf_size, int overall_timeout); -\& int OSSL_HTTP_proxy_connect(BIO *bio, const char *server, const char *port, -\& const char *proxyuser, const char *proxypass, -\& int timeout, BIO *bio_err, const char *prog); -\& int OSSL_HTTP_set1_request(OSSL_HTTP_REQ_CTX *rctx, const char *path, -\& const STACK_OF(CONF_VALUE) *headers, -\& const char *content_type, BIO *req, -\& const char *expected_content_type, int expect_asn1, -\& size_t max_resp_len, int timeout, int keep_alive); -\& BIO *OSSL_HTTP_exchange(OSSL_HTTP_REQ_CTX *rctx, char **redirection_url); -\& BIO *OSSL_HTTP_get(const char *url, const char *proxy, const char *no_proxy, -\& BIO *bio, BIO *rbio, -\& OSSL_HTTP_bio_cb_t bio_update_fn, void *arg, -\& int buf_size, const STACK_OF(CONF_VALUE) *headers, -\& const char *expected_content_type, int expect_asn1, -\& size_t max_resp_len, int timeout); -\& BIO *OSSL_HTTP_transfer(OSSL_HTTP_REQ_CTX **prctx, -\& const char *server, const char *port, -\& const char *path, int use_ssl, -\& const char *proxy, const char *no_proxy, -\& BIO *bio, BIO *rbio, -\& OSSL_HTTP_bio_cb_t bio_update_fn, void *arg, -\& int buf_size, const STACK_OF(CONF_VALUE) *headers, -\& const char *content_type, BIO *req, -\& const char *expected_content_type, int expect_asn1, -\& size_t max_resp_len, int timeout, int keep_alive); -\& int OSSL_HTTP_close(OSSL_HTTP_REQ_CTX *rctx, int ok); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_HTTP_open()\fR initiates an \s-1HTTP\s0 session using the \fIbio\fR argument if not -\&\s-1NULL,\s0 else by connecting to a given \fIserver\fR optionally via a \fIproxy\fR. -.PP -Typically the OpenSSL build supports sockets and the \fIbio\fR parameter is \s-1NULL.\s0 -In this case \fIrbio\fR must be \s-1NULL\s0 as well and the \fIserver\fR must be non-NULL. -The function creates a network \s-1BIO\s0 internally using \fBBIO_new_connect\fR\|(3) -for connecting to the given server and the optionally given \fIport\fR, -defaulting to 80 for \s-1HTTP\s0 or 443 for \s-1HTTPS.\s0 -Then this internal \s-1BIO\s0 is used for setting up a connection -and for exchanging one or more request and response. -.PP -If \fIbio\fR is given and \fIrbio\fR is \s-1NULL\s0 then this \fIbio\fR is used instead. -If both \fIbio\fR and \fIrbio\fR are given (which may be memory BIOs for instance) -then no explicit connection is set up, but -\&\fIbio\fR is used for writing requests and \fIrbio\fR for reading responses. -As soon as the client has flushed \fIbio\fR the server must be ready to provide -a response or indicate a waiting condition via \fIrbio\fR. -.PP -If \fIbio\fR is given, -it is an error to provide non-NULL \fIproxy\fR or \fIno_proxy\fR arguments, -while \fIserver\fR and \fIport\fR arguments may be given to support diagnostic output. -If \fIbio\fR is \s-1NULL\s0 the optional \fIproxy\fR parameter can be used to set an -\&\s-1HTTP\s0(S) proxy to use (unless overridden by \*(L"no_proxy\*(R" settings). -If \s-1TLS\s0 is not used this defaults to the environment variable \f(CW\*(C`http_proxy\*(C'\fR -if set, else \f(CW\*(C`HTTP_PROXY\*(C'\fR. -If \fIuse_ssl\fR != 0 it defaults to \f(CW\*(C`https_proxy\*(C'\fR if set, else \f(CW\*(C`HTTPS_PROXY\*(C'\fR. -An empty proxy string \f(CW""\fR forbids using a proxy. -Otherwise, the format is -\&\f(CW\*(C`[http[s]://][userinfo@]host[:port][/path][?query][#fragment]\*(C'\fR, -where any userinfo, path, query, and fragment given is ignored. -If the host string is an IPv6 address, it must be enclosed in \f(CW\*(C`[\*(C'\fR and \f(CW\*(C`]\*(C'\fR. -The default proxy port number is 80, or 443 in case \*(L"https:\*(R" is given. -The \s-1HTTP\s0 client functions connect via the given proxy unless the \fIserver\fR -is found in the optional list \fIno_proxy\fR of proxy hostnames or \s-1IP\s0 addresses -separated by \f(CW\*(C`,\*(C'\fR and/or whitespace (if not \s-1NULL\s0; -default is the environment variable \f(CW\*(C`no_proxy\*(C'\fR if set, else \f(CW\*(C`NO_PROXY\*(C'\fR). -Proxying plain \s-1HTTP\s0 is supported directly, -while using a proxy for \s-1HTTPS\s0 connections requires a suitable callback function -such as \fBOSSL_HTTP_proxy_connect()\fR, described below. -.PP -If \fIuse_ssl\fR is nonzero a \s-1TLS\s0 connection is requested -and the \fIbio_update_fn\fR parameter must be provided. -.PP -The parameter \fIbio_update_fn\fR, which is optional if \fIuse_ssl\fR is 0, -may be used to modify the connection \s-1BIO\s0 used by the \s-1HTTP\s0 client, -but cannot be used when both \fIbio\fR and \fIrbio\fR are given. -\&\fIbio_update_fn\fR is a \s-1BIO\s0 connect/disconnect callback function with prototype -.PP -.Vb 1 -\& BIO *(*OSSL_HTTP_bio_cb_t)(BIO *bio, void *arg, int connect, int detail) -.Ve -.PP -The callback function may modify the \s-1BIO\s0 provided in the \fIbio\fR argument, -whereby it may use an optional custom defined argument \fIarg\fR, -which can for instance point to an \fB\s-1SSL_CTX\s0\fR structure. -During connection establishment, just after calling \fBBIO_do_connect_retry()\fR, the -callback function is invoked with the \fIconnect\fR argument being 1 and -\&\fIdetail\fR being 1 if \fIuse_ssl\fR is nonzero (i.e., \s-1HTTPS\s0 is requested), else 0. -On disconnect \fIconnect\fR is 0 and \fIdetail\fR is 1 if no error occurred, else 0. -For instance, on connect the callback may push an \s-1SSL BIO\s0 to implement \s-1HTTPS\s0; -after disconnect it may do some diagnostic output and pop and free the \s-1SSL BIO.\s0 -.PP -The callback function must return either the potentially modified \s-1BIO\s0 \fIbio\fR -or \s-1NULL\s0 to indicate failure, in which case it should not modify the \s-1BIO.\s0 -.PP -Here is a simple example that supports \s-1TLS\s0 connections (but not via a proxy): -.PP -.Vb 5 -\& BIO *http_tls_cb(BIO *bio, void *arg, int connect, int detail) -\& { -\& if (connect && detail) { /* connecting with TLS */ -\& SSL_CTX *ctx = (SSL_CTX *)arg; -\& BIO *sbio = BIO_new_ssl(ctx, 1); -\& -\& bio = sbio != NULL ? BIO_push(sbio, bio) : NULL; -\& } else if (!connect) { /* disconnecting */ -\& BIO *hbio; -\& -\& if (!detail) { /* an error has occurred */ -\& /* optionally add diagnostics here */ -\& } -\& BIO_ssl_shutdown(bio); -\& hbio = BIO_pop(bio); -\& BIO_free(bio); /* SSL BIO */ -\& bio = hbio; -\& } -\& return bio; -\& } -.Ve -.PP -After disconnect the modified \s-1BIO\s0 will be deallocated using \fBBIO_free_all()\fR. -The optional callback function argument \fIarg\fR is not consumed, -so must be freed by the caller when not needed any more. -.PP -The \fIbuf_size\fR parameter specifies the response header maximum line length. -A value <= 0 means that the \fB\s-1OSSL_HTTP_DEFAULT_MAX_LINE_LEN\s0\fR (4KiB) is used. -\&\fIbuf_size\fR is also used as the number of content bytes that are read at a time. -.PP -If the \fIoverall_timeout\fR parameter is > 0 this indicates the maximum number of -seconds the overall \s-1HTTP\s0 transfer (i.e., connection setup if needed, -sending requests, and receiving responses) is allowed to take until completion. -A value <= 0 enables waiting indefinitely, i.e., no timeout. -.PP -\&\fBOSSL_HTTP_proxy_connect()\fR may be used by an above \s-1BIO\s0 connect callback function -to set up an \s-1SSL/TLS\s0 connection via an \s-1HTTPS\s0 proxy. -It promotes the given \s-1BIO\s0 \fIbio\fR representing a connection -pre-established with a \s-1TLS\s0 proxy using the \s-1HTTP CONNECT\s0 method, -optionally using proxy client credentials \fIproxyuser\fR and \fIproxypass\fR, -to connect with \s-1TLS\s0 protection ultimately to \fIserver\fR and \fIport\fR. -If the \fIport\fR argument is \s-1NULL\s0 or the empty string it defaults to \*(L"443\*(R". -If the \fItimeout\fR parameter is > 0 this indicates the maximum number of -seconds the connection setup is allowed to take. -A value <= 0 enables waiting indefinitely, i.e., no timeout. -Since this function is typically called by applications such as -\&\fBopenssl\-s_client\fR\|(1) it uses the \fIbio_err\fR and \fIprog\fR parameters (unless -\&\s-1NULL\s0) to print additional diagnostic information in a user-oriented way. -.PP -\&\fBOSSL_HTTP_set1_request()\fR sets up in \fIrctx\fR the request header and content data -and expectations on the response using the following parameters. -If indicates using a proxy for \s-1HTTP\s0 (but not \s-1HTTPS\s0), the server host -(and optionally port) needs to be placed in the header; thus it must be present -in \fIrctx\fR. -For backward compatibility, the server (and optional port) may also be given in -the \fIpath\fR argument beginning with \f(CW\*(C`http://\*(C'\fR (thus giving an absoluteURI). -If \fIpath\fR is \s-1NULL\s0 it defaults to \*(L"/\*(R". -If \fIreq\fR is \s-1NULL\s0 the \s-1HTTP GET\s0 method will be used to send the request -else \s-1HTTP POST\s0 with the contents of \fIreq\fR and optional \fIcontent_type\fR, where -the length of the data in \fIreq\fR does not need to be determined in advance: the -\&\s-1BIO\s0 will be read on-the-fly while sending the request, which supports streaming. -The optional list \fIheaders\fR may contain additional custom \s-1HTTP\s0 header lines. -.PP -If the \fIexpected_content_type\fR argument is not \s-1NULL,\s0 -the client will check that the specified content-type string -is included in the \s-1HTTP\s0 header of the response and return an error if not. -In the content-type header line the specified string should be present either -as a whole, or in case the specified string does not include a \f(CW\*(C`;\*(C'\fR character, -it is sufficient that the specified string appears as a prefix -in the header line, followed by a \f(CW\*(C`;\*(C'\fR character and any further text. -For instance, if \fIexpected_content_type\fR specifies \f(CW\*(C`text/html\*(C'\fR, -this is matched by \f(CW\*(C`text/html\*(C'\fR, \f(CW\*(C`text/html; charset=UTF\-8\*(C'\fR, etc. -.PP -If the \fIexpect_asn1\fR parameter is nonzero, -a structure in \s-1ASN.1\s0 encoding will be expected as response content. -The \fImax_resp_len\fR parameter specifies the maximum allowed -response content length, where the value 0 indicates no limit. -If the \fItimeout\fR parameter is > 0 this indicates the maximum number of seconds -the subsequent \s-1HTTP\s0 transfer (sending the request and receiving a response) -is allowed to take. -A value of 0 enables waiting indefinitely, i.e., no timeout. -A value < 0 indicates that the \fIoverall_timeout\fR parameter value given -when opening the \s-1HTTP\s0 transfer will be used instead. -If \fIkeep_alive\fR is 0 the connection is not kept open -after receiving a response, which is the default behavior for \s-1HTTP 1.0.\s0 -If the value is 1 or 2 then a persistent connection is requested. -If the value is 2 then a persistent connection is required, -i.e., an error occurs in case the server does not grant it. -.PP -\&\fBOSSL_HTTP_exchange()\fR exchanges any form of \s-1HTTP\s0 request and response -as specified by \fIrctx\fR, which must include both connection and request data, -typically set up using \fBOSSL_HTTP_open()\fR and \fBOSSL_HTTP_set1_request()\fR. -It implements the core of the functions described below. -If the \s-1HTTP\s0 method is \s-1GET\s0 and \fIredirection_url\fR -is not \s-1NULL\s0 the latter pointer is used to provide any new location that -the server may return with \s-1HTTP\s0 code 301 (\s-1MOVED_PERMANENTLY\s0) or 302 (\s-1FOUND\s0). -In this case the function returns \s-1NULL\s0 and the caller is -responsible for deallocating the \s-1URL\s0 with \fBOPENSSL_free\fR\|(3). -If the response header contains one or more \*(L"Content-Length\*(R" header lines and/or -an \s-1ASN\s0.1\-encoded response is expected, which should include a total length, -the length indications received are checked for consistency -and for not exceeding any given maximum response length. -If an \s-1ASN\s0.1\-encoded response is expected, the function returns on success -the contents buffered in a memory \s-1BIO,\s0 which does not support streaming. -Otherwise it returns directly the read \s-1BIO\s0 that holds the response contents, -which allows a response of indefinite length and may support streaming. -The caller is responsible for freeing the \s-1BIO\s0 pointer obtained. -.PP -\&\fBOSSL_HTTP_get()\fR uses \s-1HTTP GET\s0 to obtain data from \fIbio\fR if non-NULL, -else from the server contained in the \fIurl\fR, and returns it as a \s-1BIO.\s0 -It supports redirection via \s-1HTTP\s0 status code 301 or 302. It is meant for -transfers with a single round trip, so does not support persistent connections. -If \fIbio\fR is non-NULL, any host and port components in the \fIurl\fR are not used -for connecting but the hostname is used, as usual, for the \f(CW\*(C`Host\*(C'\fR header. -Any userinfo and fragment components in the \fIurl\fR are ignored. -Any query component is handled as part of the path component. -If the scheme component of the \fIurl\fR is \f(CW\*(C`https\*(C'\fR a \s-1TLS\s0 connection is requested -and the \fIbio_update_fn\fR, as described for \fBOSSL_HTTP_open()\fR, must be provided. -Also the remaining parameters are interpreted as described for \fBOSSL_HTTP_open()\fR -and \fBOSSL_HTTP_set1_request()\fR, respectively. -The caller is responsible for freeing the \s-1BIO\s0 pointer obtained. -.PP -\&\fBOSSL_HTTP_transfer()\fR exchanges an \s-1HTTP\s0 request and response -over a connection managed via \fIprctx\fR without supporting redirection. -It combines \fBOSSL_HTTP_open()\fR, \fBOSSL_HTTP_set1_request()\fR, \fBOSSL_HTTP_exchange()\fR, -and \fBOSSL_HTTP_close()\fR. -If \fIprctx\fR is not \s-1NULL\s0 it reuses any open connection represented by a non-NULL -\&\fI*prctx\fR. It keeps the connection open if a persistent connection is requested -or required and this was granted by the server, else it closes the connection -and assigns \s-1NULL\s0 to \fI*prctx\fR. -The remaining parameters are interpreted as described for \fBOSSL_HTTP_open()\fR -and \fBOSSL_HTTP_set1_request()\fR, respectively. -The caller is responsible for freeing the \s-1BIO\s0 pointer obtained. -.PP -\&\fBOSSL_HTTP_close()\fR closes the connection and releases \fIrctx\fR. -The \fIok\fR parameter is passed to any \s-1BIO\s0 update function -given during setup as described above for \fBOSSL_HTTP_open()\fR. -It must be 1 if no error occurred during the \s-1HTTP\s0 transfer and 0 otherwise. -.SH "NOTES" -.IX Header "NOTES" -The names of the environment variables used by this implementation: -\&\f(CW\*(C`http_proxy\*(C'\fR, \f(CW\*(C`HTTP_PROXY\*(C'\fR, \f(CW\*(C`https_proxy\*(C'\fR, \f(CW\*(C`HTTPS_PROXY\*(C'\fR, \f(CW\*(C`no_proxy\*(C'\fR, and -\&\f(CW\*(C`NO_PROXY\*(C'\fR, have been chosen for maximal compatibility with -other \s-1HTTP\s0 client implementations such as wget, curl, and git. -.PP -When built with tracing enabled, \fBOSSL_HTTP_transfer()\fR and all functions using it -may be traced using \fB\s-1OSSL_TRACE_CATEGORY_HTTP\s0\fR. -See also \fBOSSL_trace_enabled\fR\|(3) and \fBopenssl\-env\fR\|(7). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_HTTP_open()\fR returns on success a \fB\s-1OSSL_HTTP_REQ_CTX\s0\fR, else \s-1NULL.\s0 -.PP -\&\fBOSSL_HTTP_proxy_connect()\fR and \fBOSSL_HTTP_set1_request()\fR -return 1 on success, 0 on error. -.PP -On success, \fBOSSL_HTTP_exchange()\fR, \fBOSSL_HTTP_get()\fR, and \fBOSSL_HTTP_transfer()\fR -return a memory \s-1BIO\s0 that buffers all the data received if an \s-1ASN\s0.1\-encoded -response is expected, otherwise a \s-1BIO\s0 that may support streaming. -The \s-1BIO\s0 must be freed by the caller. -On failure, they return \s-1NULL.\s0 -Failure conditions include connection/transfer timeout, parse errors, etc. -The caller is responsible for freeing the \s-1BIO\s0 pointer obtained. -.PP -\&\fBOSSL_HTTP_close()\fR returns 0 if anything went wrong while disconnecting, else 1. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_HTTP_parse_url\fR\|(3), \fBBIO_new_connect\fR\|(3), -\&\fBASN1_item_i2d_mem_bio\fR\|(3), \fBASN1_item_d2i_bio\fR\|(3), -\&\fBOSSL_HTTP_is_alive\fR\|(3), -\&\fBOSSL_trace_enabled\fR\|(3), and \fBopenssl\-env\fR\|(7). -.SH "HISTORY" -.IX Header "HISTORY" -All the functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX.3ossl deleted file mode 100644 index 2ed2de74..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX.3ossl +++ /dev/null @@ -1,222 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_IETF_ATTR_SYNTAX 3ossl" -.TH OSSL_IETF_ATTR_SYNTAX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_IETF_ATTR_SYNTAX, -OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority, -OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority, -OSSL_IETF_ATTR_SYNTAX_get_value_num, -OSSL_IETF_ATTR_SYNTAX_get0_value, -OSSL_IETF_ATTR_SYNTAX_add1_value -\&\- Accessors and setters for OSSL_IETF_ATTR_SYNTAX -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct OSSL_IETF_ATTR_SYNTAX_st OSSL_IETF_ATTR_SYNTAX; -\& -\& const GENERAL_NAMES * -\& OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority(const OSSL_IETF_ATTR_SYNTAX *a); -\& void OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority(OSSL_IETF_ATTR_SYNTAX *a, -\& GENERAL_NAMES *names); -\& -\& int OSSL_IETF_ATTR_SYNTAX_get_value_num(const OSSL_IETF_ATTR_SYNTAX *a); -\& void *OSSL_IETF_ATTR_SYNTAX_get0_value(const OSSL_IETF_ATTR_SYNTAX *a, -\& int ind, int *type); -\& int OSSL_IETF_ATTR_SYNTAX_add1_value(OSSL_IETF_ATTR_SYNTAX *a, int type, -\& void *data); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_IETF_ATTR_SYNTAX\s0\fR is an opaque structure that represents the -IetfAttrSyntax type defined in \s-1RFC 5755\s0 (Section 4.4) for use -as an AttributeValue. -.PP -\&\fBOSSL_IETF_ATTR_SYNTAX_get0_policyAuthority()\fR and \fBOSSL_IETF_ATTR_SYNTAX_set0_policyAuthority()\fR -get and set the policyAuthority field of the structure. Both routines act on -internal pointers of the structure and must not be freed by the application. -.PP -An \fB\s-1OSSL_IETF_ATTR_SYNTAX\s0\fR object also holds a sequence of values. -\&\fBOSSL_IETF_ATTR_SYNTAX_get_value_num()\fR returns the number of values in the -sequence. \fBOSSL_IETF_ATTR_SYNTAX_add1_value()\fR, adds a copy of \fIdata\fR of a specified -\&\fItype\fR to the sequence. The caller should free the \fIdata\fR after use. -.PP -\&\fBOSSL_IETF_ATTR_SYNTAX_get0_value()\fR will return the value and a specific index \fIind\fR -in the sequence or \s-1NULL\s0 on error. If \fItype\fR is not \s-1NULL,\s0 the type of the -value will be written to this location. -.PP -The \fItype\fR of the values stored in the \fB\s-1OSSL_IETF_ATTR_SYNTAX\s0\fR value sequence is -one of the following: -.IP "\s-1OSSL_IETFAS_OCTETS\s0" 4 -.IX Item "OSSL_IETFAS_OCTETS" -A pointer to an \s-1ASN1_OCTET_STRING\s0 -.IP "\s-1OSSL_IETFAS_OID\s0" 4 -.IX Item "OSSL_IETFAS_OID" -A pointer to an \s-1ASN1_OBJECT\s0 -.IP "\s-1OSSL_IETFAS_STRING\s0" 4 -.IX Item "OSSL_IETFAS_STRING" -A pointer to an \s-1ASN1_UTF8STRING\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_IETF_ATTR_SYNTAX_get0_policyAuthority()\fR returns an pointer to a -\&\fB\s-1GENERAL_NAMES\s0\fR structure or \fB\s-1NULL\s0\fR if the policy authority has not been -set. -.PP -\&\fBOSSL_IETF_ATTR_SYNTAX_get_value_num()\fR returns the number of entries in the value -sequence or \-1 on error. -.PP -\&\fBOSSL_IETF_ATTR_SYNTAX_get0_value()\fR returns a pointer to the value at the given index -or \s-1NULL\s0 if the index is out of range. -.PP -\&\fBOSSL_IETF_ATTR_SYNTAX_add1_value()\fR returns 1 on success and 0 on failure. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_IETF_ATTR_SYNTAX_get0_policyAuthority()\fR, \fBOSSL_IETF_ATTR_SYNTAX_set0_policyAuthority()\fR, -\&\fBOSSL_IETF_ATTR_SYNTAX_get_value_num()\fR, \fBOSSL_IETF_ATTR_SYNTAX_get0_value()\fR, and -\&\fBOSSL_IETF_ATTR_SYNTAX_add1_value()\fR were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_free.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_it.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_new.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_VALUE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_add1_value.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_add1_value.3ossl deleted file mode 120000 index e46df32b..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_add1_value.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_IETF_ATTR_SYNTAX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_free.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority.3ossl deleted file mode 120000 index e46df32b..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_IETF_ATTR_SYNTAX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_value.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_value.3ossl deleted file mode 120000 index e46df32b..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get0_value.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_IETF_ATTR_SYNTAX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get_value_num.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get_value_num.3ossl deleted file mode 120000 index e46df32b..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_get_value_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_IETF_ATTR_SYNTAX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_it.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_new.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_print.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_print.3ossl deleted file mode 100644 index c309bc38..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_print.3ossl +++ /dev/null @@ -1,172 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_IETF_ATTR_SYNTAX_PRINT 3ossl" -.TH OSSL_IETF_ATTR_SYNTAX_PRINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_IETF_ATTR_SYNTAX_print \- OSSL_IETF_ATTR_SYNTAX printing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_IETF_ATTR_SYNTAX_print(BIO *bp, OSSL_IETF_ATTR_SYNTAX *a, -\& int indent); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_IETF_ATTR_SYNTAX_print()\fR prints a human readable version of \fIa\fR to -\&\s-1BIO\s0 \fIbp\fR. -Each line of the output is indented by \fIindent\fR spaces. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_IETF_ATTR_SYNTAX_print()\fR return 1 on success or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBASN1_STRING_print_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_IETF_ATTR_SYNTAX_print()\fR was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority.3ossl b/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority.3ossl deleted file mode 120000 index e46df32b..00000000 --- a/openssl-install/share/man/man3/OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_IETF_ATTR_SYNTAX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_INDICATOR_get_callback.3ossl b/openssl-install/share/man/man3/OSSL_INDICATOR_get_callback.3ossl deleted file mode 120000 index a0a4123d..00000000 --- a/openssl-install/share/man/man3/OSSL_INDICATOR_get_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_INDICATOR_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_INDICATOR_set_callback.3ossl b/openssl-install/share/man/man3/OSSL_INDICATOR_set_callback.3ossl deleted file mode 100644 index a9616bd1..00000000 --- a/openssl-install/share/man/man3/OSSL_INDICATOR_set_callback.3ossl +++ /dev/null @@ -1,214 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_INDICATOR_SET_CALLBACK 3ossl" -.TH OSSL_INDICATOR_SET_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_INDICATOR_set_callback, -OSSL_INDICATOR_get_callback \- specify a callback for FIPS indicators -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -typedef int (\s-1OSSL_INDICATOR_CALLBACK\s0)(const char *type, const char *desc, - const \s-1OSSL_PARAM\s0 params[]); -.PP -.Vb 4 -\& void OSSL_INDICATOR_set_callback(OSSL_LIB_CTX *libctx, -\& OSSL_INDICATOR_CALLBACK *cb); -\& void OSSL_INDICATOR_get_callback(OSSL_LIB_CTX *libctx, -\& OSSL_INDICATOR_CALLBACK **cb); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_INDICATOR_set_callback()\fR sets a user callback \fIcb\fR associated with a -\&\fIlibctx\fR that will be called when a non approved \s-1FIPS\s0 operation is detected. -.PP -The user's callback may be triggered multiple times during an algorithm operation -to indicate different approved mode checks have failed. -.PP -Non approved operations may only occur if the user has deliberately chosen to do -so (either by setting a global \s-1FIPS\s0 configuration option or via an option in an -algorithm's operation context). -.PP -The user's callback \fB\s-1OSSL_INDICATOR_CALLBACK\s0\fR \fItype\fR and \fIdesc\fR -contain the algorithm type and operation that is not approved. -\&\fIparams\fR is not currently used. -.PP -If the user callback returns 0, an error will occur in the caller. This can be -used for testing purposes. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_INDICATOR_get_callback()\fR returns the callback that has been set via -\&\fBOSSL_INDICATOR_set_callback()\fR for the given library context \fIlibctx\fR, or \s-1NULL\s0 -if no callback is currently set. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -A simple indicator callback to log non approved \s-1FIPS\s0 operations -.PP -.Vb 9 -\& static int indicator_cb(const char *type, const char *desc, -\& const OSSL_PARAM params[]) -\& { -\& if (type != NULL && desc != NULL) -\& fprintf(stdout, "%s %s is not approved\en", type, desc); -\&end: -\& /* For Testing purposes you could return 0 here to cause an error */ -\& return 1; -\& } -\& -\& OSSL_INDICATOR_set_callback(libctx, indicator_cb); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core.h\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_free.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuer.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuer.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuerUID.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuerUID.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_issuerUID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_serial.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_serial.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_get0_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_new.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuer.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuer.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuerUID.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuerUID.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_issuerUID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_serial.3ossl b/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_serial.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_ISSUER_SERIAL_set1_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_ITEM.3ossl b/openssl-install/share/man/man3/OSSL_ITEM.3ossl deleted file mode 100644 index 1f404a64..00000000 --- a/openssl-install/share/man/man3/OSSL_ITEM.3ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_ITEM 3ossl" -.TH OSSL_ITEM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_ITEM \- OpenSSL Core type for generic itemized data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_item_st OSSL_ITEM; -\& struct ossl_item_st { -\& unsigned int id; -\& void *ptr; -\& }; -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This type is a tuple of integer and pointer. -It's a generic type used as a generic descriptor, its exact meaning -being defined by how it's used. -Arrays of this type are passed between the OpenSSL libraries and the -providers, and must be terminated with a tuple where the integer is -zero and the pointer \s-1NULL.\s0 -.PP -This is currently mainly used for the return value of the provider's error -reason strings array, see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), \fBprovider\-base\fR\|(7), \fBopenssl\-core.h\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fB\s-1OSSL_ITEM\s0\fR was added in OpenSSL 3.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX.3ossl deleted file mode 100644 index 4b56076f..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX.3ossl +++ /dev/null @@ -1,284 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_LIB_CTX 3ossl" -.TH OSSL_LIB_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_LIB_CTX, OSSL_LIB_CTX_get_data, OSSL_LIB_CTX_new, -OSSL_LIB_CTX_new_from_dispatch, OSSL_LIB_CTX_new_child, -OSSL_LIB_CTX_free, OSSL_LIB_CTX_load_config, -OSSL_LIB_CTX_get0_global_default, OSSL_LIB_CTX_set0_default -\&\- OpenSSL library context -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_lib_ctx_st OSSL_LIB_CTX; -\& -\& OSSL_LIB_CTX *OSSL_LIB_CTX_new(void); -\& OSSL_LIB_CTX *OSSL_LIB_CTX_new_from_dispatch(const OSSL_CORE_HANDLE *handle, -\& const OSSL_DISPATCH *in); -\& OSSL_LIB_CTX *OSSL_LIB_CTX_new_child(const OSSL_CORE_HANDLE *handle, -\& const OSSL_DISPATCH *in); -\& int OSSL_LIB_CTX_load_config(OSSL_LIB_CTX *ctx, const char *config_file); -\& void OSSL_LIB_CTX_free(OSSL_LIB_CTX *ctx); -\& OSSL_LIB_CTX *OSSL_LIB_CTX_get0_global_default(void); -\& OSSL_LIB_CTX *OSSL_LIB_CTX_set0_default(OSSL_LIB_CTX *ctx); -\& void *OSSL_LIB_CTX_get_data(OSSL_LIB_CTX *ctx, int index); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_LIB_CTX\s0\fR is an internal OpenSSL library context type. -Applications may allocate their own, but may also use \s-1NULL\s0 to use -a default context with functions that take an \fB\s-1OSSL_LIB_CTX\s0\fR -argument. -.PP -When a non default library context is in use care should be taken with -multi-threaded applications to properly clean up thread local resources before -the \s-1OSSL_LIB_CTX\s0 is freed. -See \fBOPENSSL_thread_stop_ex\fR\|(3) for more information. -.PP -\&\fBOSSL_LIB_CTX_new()\fR creates a new OpenSSL library context. -.PP -\&\fBOSSL_LIB_CTX_new_from_dispatch()\fR creates a new OpenSSL library context -initialised to use callbacks from the \s-1OSSL_DISPATCH\s0 structure. This is primarily -useful for provider authors. The \fIhandle\fR and dispatch structure arguments -passed should be the same ones as passed to a provider's -OSSL_provider_init function. Some OpenSSL functions, such as -\&\fBBIO_new_from_core_bio\fR\|(3), require the library context to be created in this -way in order to work. -.PP -\&\fBOSSL_LIB_CTX_new_child()\fR is only useful to provider authors and does the same -thing as \fBOSSL_LIB_CTX_new_from_dispatch()\fR except that it additionally links the -new library context to the application library context. The new library context -is a full library context in its own right, but will have all the same providers -available to it that are available in the application library context (without -having to reload them). If the application loads or unloads providers from the -application library context then this will be automatically mirrored in the -child library context. -.PP -In addition providers that are not loaded in the parent library context can be -explicitly loaded into the child library context independently from the parent -library context. Providers loaded independently in this way will not be mirrored -in the parent library context and will not be affected if the parent library -context subsequently loads the same provider. -.PP -A provider may call the function \fBOSSL_PROVIDER_load\fR\|(3) with the child library -context as required. If the provider already exists due to it being mirrored -from the parent library context then it will remain available and its reference -count will be increased. If \fBOSSL_PROVIDER_load\fR\|(3) is called in this way then -\&\fBOSSL_PROVIDER_unload\fR\|(3) should be subsequently called to decrement the -reference count. \fBOSSL_PROVIDER_unload\fR\|(3) must not be called for a provider in -the child library context that did not have an earlier \fBOSSL_PROVIDER_load\fR\|(3) -call for that provider in that child library context. -.PP -In addition to providers, a child library context will also mirror the default -properties (set via \fBEVP_set_default_properties\fR\|(3)) from the parent library -context. If \fBEVP_set_default_properties\fR\|(3) is called directly on a child -library context then the new properties will override anything from the parent -library context and mirroring of the properties will stop. -.PP -When \fBOSSL_LIB_CTX_new_child()\fR is called from within the scope of a provider's -\&\fBOSSL_provider_init\fR function the currently initialising provider is not yet -available in the application's library context and therefore will similarly not -yet be available in the newly constructed child library context. As soon as the -\&\fBOSSL_provider_init\fR function returns then the new provider is available in the -application's library context and will be similarly mirrored in the child -library context. -.PP -\&\fBOSSL_LIB_CTX_load_config()\fR loads a configuration file using the given \fIctx\fR. -This can be used to associate a library context with providers that are loaded -from a configuration. This function must not be called concurrently from -multiple threads on a single \fIctx\fR. -.PP -\&\fBOSSL_LIB_CTX_free()\fR frees the given \fIctx\fR, unless it happens to be the -default OpenSSL library context. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_LIB_CTX_get0_global_default()\fR returns a concrete (non \s-1NULL\s0) reference to -the global default library context. -.PP -\&\fBOSSL_LIB_CTX_set0_default()\fR sets the default OpenSSL library context to be -\&\fIctx\fR in the current thread. The previous default library context is -returned. Care should be taken by the caller to restore the previous -default library context with a subsequent call of this function. If \fIctx\fR is -\&\s-1NULL\s0 then no change is made to the default library context, but a pointer to -the current library context is still returned. On a successful call of this -function the returned value will always be a concrete (non \s-1NULL\s0) library -context. -.PP -Care should be taken when changing the default library context and starting -async jobs (see \fBASYNC_start_job\fR\|(3)), as the default library context when -the job is started will be used throughout the lifetime of an async job, no -matter how the calling thread makes further default library context changes -in the mean time. This means that the calling thread must not free the -library context that was the default at the start of the async job before -that job has finished. -.PP -\&\fBOSSL_LIB_CTX_get_data()\fR returns a memory address whose interpretation depends -on the index. The index argument refers to a context member which is -to be retrieved. The values for index are all private to OpenSSL currently -and so applications should not typically call this function. -If ctx is \s-1NULL\s0 then the function operates on the default library context. -\&\fBOSSL_LIB_CTX_get_data()\fR returns a memory address whose interpretation -depends on the index. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_LIB_CTX_new()\fR, \fBOSSL_LIB_CTX_get0_global_default()\fR and -\&\fBOSSL_LIB_CTX_set0_default()\fR return a library context pointer on success, or \s-1NULL\s0 -on error. -.PP -\&\fBOSSL_LIB_CTX_free()\fR doesn't return any value. -.PP -\&\fBOSSL_LIB_CTX_load_config()\fR returns 1 on success, 0 on error. -.PP -\&\fBOSSL_LIB_CTX_get_data()\fR returns a memory address whose interpretation -depends on the index. -.SH "HISTORY" -.IX Header "HISTORY" -All of the functions described on this page were added in OpenSSL 3.0. -.PP -\&\fBOSSL_LIB_CTX_get_data()\fR was introduced in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_free.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_free.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_get0_global_default.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_get0_global_default.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_get0_global_default.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_get_conf_diagnostics.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_get_conf_diagnostics.3ossl deleted file mode 120000 index 2983788c..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_get_conf_diagnostics.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX_set_conf_diagnostics.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_get_data.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_get_data.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_get_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_load_config.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_load_config.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_load_config.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_new.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_new.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_new_child.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_new_child.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_new_child.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_new_from_dispatch.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_new_from_dispatch.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_new_from_dispatch.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_set0_default.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_set0_default.3ossl deleted file mode 120000 index 6c9e6346..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_set0_default.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_LIB_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_LIB_CTX_set_conf_diagnostics.3ossl b/openssl-install/share/man/man3/OSSL_LIB_CTX_set_conf_diagnostics.3ossl deleted file mode 100644 index 25a2f0ae..00000000 --- a/openssl-install/share/man/man3/OSSL_LIB_CTX_set_conf_diagnostics.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_LIB_CTX_SET_CONF_DIAGNOSTICS 3ossl" -.TH OSSL_LIB_CTX_SET_CONF_DIAGNOSTICS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_LIB_CTX_set_conf_diagnostics, OSSL_LIB_CTX_get_conf_diagnostics -\&\- Set and get configuration diagnostics -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void OSSL_LIB_CTX_set_conf_diagnostics(OSSL_LIB_CTX *ctx, int value); -\& int OSSL_LIB_CTX_get_conf_diagnostics(OSSL_LIB_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_LIB_CTX_set_conf_diagnostics()\fR sets the value of the configuration -diagnostics flag. If \fIvalue\fR is nonzero subsequent parsing and application -of configuration data can report errors that would otherwise be ignored. In -particular any errors in the ssl configuration module will cause a failure -of \fBSSL_CTX_new\fR\|(3) and \fBSSL_CTX_new_ex\fR\|(3) calls. The configuration -diagnostics flag can be also set when a configuration file is being loaded -into \fB\s-1OSSL_LIB_CTX\s0\fR with \fBOSSL_LIB_CTX_load_config\fR\|(3). If the configuration -sets a \fBconfig_diagnostics\fR value as described in \fBconfig\fR\|(5), it will -override the value set by \fBOSSL_LIB_CTX_set_conf_diagnostics()\fR before -loading the configuration file. -.PP -\&\fBOSSL_LIB_CTX_get_conf_diagnostics()\fR returns the current value of the -configuration diagnostics flag. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_LIB_CTX_get_conf_diagnostics()\fR returns 0 if the configuration diagnostics -should not be performed, nonzero otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_new\fR\|(3), \fBOSSL_LIB_CTX_load_config\fR\|(3), \fBconfig\fR\|(5) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described on this page were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_free.3ossl b/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_get0_digest.3ossl b/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_get0_digest.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_get0_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_new.3ossl b/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_set1_digest.3ossl b/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_set1_digest.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/OSSL_OBJECT_DIGEST_INFO_set1_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM.3ossl b/openssl-install/share/man/man3/OSSL_PARAM.3ossl deleted file mode 100644 index 440ddd3f..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM.3ossl +++ /dev/null @@ -1,466 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PARAM 3ossl" -.TH OSSL_PARAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PARAM \- a structure to pass or request object parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_param_st OSSL_PARAM; -\& struct ossl_param_st { -\& const char *key; /* the name of the parameter */ -\& unsigned int data_type; /* declare what kind of content is in data */ -\& void *data; /* value being passed in or out */ -\& size_t data_size; /* data size */ -\& size_t return_size; /* returned size */ -\& }; -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_PARAM\s0\fR is a type that allows passing arbitrary data for some -object between two parties that have no or very little shared -knowledge about their respective internal structures for that object. -.PP -A typical usage example could be an application that wants to set some -parameters for an object, or wants to find out some parameters of an -object. -.PP -Arrays of this type can be used for the following purposes: -.IP "\(bu" 4 -Setting parameters for some object -.Sp -The caller sets up the \fB\s-1OSSL_PARAM\s0\fR array and calls some function -(the \fIsetter\fR) that has intimate knowledge about the object that can -take the data from the \fB\s-1OSSL_PARAM\s0\fR array and assign them in a -suitable form for the internal structure of the object. -.IP "\(bu" 4 -Request parameters of some object -.Sp -The caller (the \fIrequester\fR) sets up the \fB\s-1OSSL_PARAM\s0\fR array and -calls some function (the \fIresponder\fR) that has intimate knowledge -about the object, which can take the internal data of the object and -copy (possibly convert) that to the memory prepared by the -\&\fIrequester\fR and pointed at with the \fB\s-1OSSL_PARAM\s0\fR \fIdata\fR. -.IP "\(bu" 4 -Request parameter descriptors -.Sp -The caller gets an array of constant \fB\s-1OSSL_PARAM\s0\fR, which describe -available parameters and some of their properties; name, data type and -expected data size. -For a detailed description of each field for this use, see the field -descriptions below. -.Sp -The caller may then use the information from this descriptor array to -build up its own \fB\s-1OSSL_PARAM\s0\fR array to pass down to a \fIsetter\fR or -\&\fIresponder\fR. -.PP -Normally, the order of the an \fB\s-1OSSL_PARAM\s0\fR array is not relevant. -However, if the \fIresponder\fR can handle multiple elements with the -same key, those elements must be handled in the order they are in. -.PP -An \fB\s-1OSSL_PARAM\s0\fR array must have a terminating element, where \fIkey\fR -is \s-1NULL.\s0 The usual full terminating template is: -.PP -.Vb 1 -\& { NULL, 0, NULL, 0, 0 } -.Ve -.PP -This can also be specified using \s-1\fBOSSL_PARAM_END\s0\fR\|(3). -.SS "Functional support" -.IX Subsection "Functional support" -Libcrypto offers a limited set of helper functions to handle -\&\fB\s-1OSSL_PARAM\s0\fR items and arrays, please see \fBOSSL_PARAM_get_int\fR\|(3). -Developers are free to extend or replace those as they see fit. -.SS "\fB\s-1OSSL_PARAM\s0\fP fields" -.IX Subsection "OSSL_PARAM fields" -.IP "\fIkey\fR" 4 -.IX Item "key" -The identity of the parameter in the form of a string. -.Sp -In an \fB\s-1OSSL_PARAM\s0\fR array, an item with this field set to \s-1NULL\s0 is -considered a terminating item. -.IP "\fIdata_type\fR" 4 -.IX Item "data_type" -The \fIdata_type\fR is a value that describes the type and organization of -the data. -See \*(L"Supported types\*(R" below for a description of the types. -.IP "\fIdata\fR" 4 -.IX Item "data" -.PD 0 -.IP "\fIdata_size\fR" 4 -.IX Item "data_size" -.PD -\&\fIdata\fR is a pointer to the memory where the parameter data is (when -setting parameters) or shall (when requesting parameters) be stored, -and \fIdata_size\fR is its size in bytes. -The organization of the data depends on the parameter type and flag. -.Sp -The \fIdata_size\fR needs special attention with the parameter type -\&\fB\s-1OSSL_PARAM_UTF8_STRING\s0\fR in relation to C strings. When setting -parameters, the size should be set to the length of the string, not -counting the terminating \s-1NUL\s0 byte. When requesting parameters, the -size should be set to the size of the buffer to be populated, which -should accommodate enough space for a terminating \s-1NUL\s0 byte. -.Sp -When \fIrequesting parameters\fR, it's acceptable for \fIdata\fR to be \s-1NULL.\s0 -This can be used by the \fIrequester\fR to figure out dynamically exactly -how much buffer space is needed to store the parameter data. -In this case, \fIdata_size\fR is ignored. -.Sp -When the \fB\s-1OSSL_PARAM\s0\fR is used as a parameter descriptor, \fIdata\fR -should be ignored. -If \fIdata_size\fR is zero, it means that an arbitrary data size is -accepted, otherwise it specifies the maximum size allowed. -.IP "\fIreturn_size\fR" 4 -.IX Item "return_size" -When an array of \fB\s-1OSSL_PARAM\s0\fR is used to request data, the -\&\fIresponder\fR must set this field to indicate size of the parameter -data, including padding as the case may be. -In case the \fIdata_size\fR is an unsuitable size for the data, the -\&\fIresponder\fR must still set this field to indicate the minimum data -size required. -(further notes on this in \*(L"\s-1NOTES\*(R"\s0 below). -.Sp -When the \fB\s-1OSSL_PARAM\s0\fR is used as a parameter descriptor, -\&\fIreturn_size\fR should be ignored. -.PP -\&\fB\s-1NOTE:\s0\fR -.PP -The key names and associated types are defined by the entity that -offers these parameters, i.e. names for parameters provided by the -OpenSSL libraries are defined by the libraries, and names for -parameters provided by providers are defined by those providers, -except for the pointer form of strings (see data type descriptions -below). -Entities that want to set or request parameters need to know what -those keys are and of what type, any functionality between those two -entities should remain oblivious and just pass the \fB\s-1OSSL_PARAM\s0\fR array -along. -.SS "Supported types" -.IX Subsection "Supported types" -The \fIdata_type\fR field can be one of the following types: -.IP "\fB\s-1OSSL_PARAM_INTEGER\s0\fR" 4 -.IX Item "OSSL_PARAM_INTEGER" -.PD 0 -.IP "\fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR" 4 -.IX Item "OSSL_PARAM_UNSIGNED_INTEGER" -.PD -The parameter data is an integer (signed or unsigned) of arbitrary -length, organized in native form, i.e. most significant byte first on -Big-Endian systems, and least significant byte first on Little-Endian -systems. -.IP "\fB\s-1OSSL_PARAM_REAL\s0\fR" 4 -.IX Item "OSSL_PARAM_REAL" -The parameter data is a floating point value in native form. -.IP "\fB\s-1OSSL_PARAM_UTF8_STRING\s0\fR" 4 -.IX Item "OSSL_PARAM_UTF8_STRING" -The parameter data is a printable string. -.IP "\fB\s-1OSSL_PARAM_OCTET_STRING\s0\fR" 4 -.IX Item "OSSL_PARAM_OCTET_STRING" -The parameter data is an arbitrary string of bytes. -.IP "\fB\s-1OSSL_PARAM_UTF8_PTR\s0\fR" 4 -.IX Item "OSSL_PARAM_UTF8_PTR" -The parameter data is a pointer to a printable string. -.Sp -The difference between this and \fB\s-1OSSL_PARAM_UTF8_STRING\s0\fR is that \fIdata\fR -doesn't point directly at the data, but to a pointer that points to the data. -.Sp -If there is any uncertainty about which to use, \fB\s-1OSSL_PARAM_UTF8_STRING\s0\fR is -almost certainly the correct choice. -.Sp -This is used to indicate that constant data is or will be passed, -and there is therefore no need to copy the data that is passed, just -the pointer to it. -.Sp -\&\fIdata_size\fR must be set to the size of the data, not the size of the -pointer to the data. -If this is used in a parameter request, -\&\fIdata_size\fR is not relevant. However, the \fIresponder\fR will set -\&\fIreturn_size\fR to the size of the data. -.Sp -Note that the use of this type is \fBfragile\fR and can only be safely -used for data that remains constant and in a constant location for a -long enough duration (such as the life-time of the entity that -offers these parameters). -.IP "\fB\s-1OSSL_PARAM_OCTET_PTR\s0\fR" 4 -.IX Item "OSSL_PARAM_OCTET_PTR" -The parameter data is a pointer to an arbitrary string of bytes. -.Sp -The difference between this and \fB\s-1OSSL_PARAM_OCTET_STRING\s0\fR is that -\&\fIdata\fR doesn't point directly at the data, but to a pointer that -points to the data. -.Sp -If there is any uncertainty about which to use, \fB\s-1OSSL_PARAM_OCTET_STRING\s0\fR is -almost certainly the correct choice. -.Sp -This is used to indicate that constant data is or will be passed, and -there is therefore no need to copy the data that is passed, just the -pointer to it. -.Sp -\&\fIdata_size\fR must be set to the size of the data, not the size of the -pointer to the data. -If this is used in a parameter request, -\&\fIdata_size\fR is not relevant. However, the \fIresponder\fR will set -\&\fIreturn_size\fR to the size of the data. -.Sp -Note that the use of this type is \fBfragile\fR and can only be safely -used for data that remains constant and in a constant location for a -long enough duration (such as the life-time of the entity that -offers these parameters). -.SH "NOTES" -.IX Header "NOTES" -Both when setting and requesting parameters, the functions that are -called will have to decide what is and what is not an error. -The recommended behaviour is: -.IP "\(bu" 4 -Keys that a \fIsetter\fR or \fIresponder\fR doesn't recognise should simply -be ignored. -That in itself isn't an error. -.IP "\(bu" 4 -If the keys that a called \fIsetter\fR recognises form a consistent -enough set of data, that call should succeed. -.IP "\(bu" 4 -Apart from the \fIreturn_size\fR, a \fIresponder\fR must never change the fields -of an \fB\s-1OSSL_PARAM\s0\fR. -To return a value, it should change the contents of the memory that -\&\fIdata\fR points at. -.IP "\(bu" 4 -If the data type for a key that it's associated with is incorrect, -the called function may return an error. -.Sp -The called function may also try to convert the data to a suitable -form (for example, it's plausible to pass a large number as an octet -string, so even though a given key is defined as an -\&\fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR, is plausible to pass the value as an -\&\fB\s-1OSSL_PARAM_OCTET_STRING\s0\fR), but this is in no way mandatory. -.IP "\(bu" 4 -If \fIdata\fR for a \fB\s-1OSSL_PARAM_OCTET_STRING\s0\fR or a -\&\fB\s-1OSSL_PARAM_UTF8_STRING\s0\fR is \s-1NULL,\s0 the \fIresponder\fR should -set \fIreturn_size\fR to the size of the item to be returned -and return success. Later the responder will be called again -with \fIdata\fR pointing at the place for the value to be put. -.IP "\(bu" 4 -If a \fIresponder\fR finds that some data sizes are too small for the -requested data, it must set \fIreturn_size\fR for each such -\&\fB\s-1OSSL_PARAM\s0\fR item to the minimum required size, and eventually return -an error. -.IP "\(bu" 4 -For the integer type parameters (\fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR and -\&\fB\s-1OSSL_PARAM_INTEGER\s0\fR), a \fIresponder\fR may choose to return an error -if the \fIdata_size\fR isn't a suitable size (even if \fIdata_size\fR is -bigger than needed). If the \fIresponder\fR finds the size suitable, it -must fill all \fIdata_size\fR bytes and ensure correct padding for the -native endianness, and set \fIreturn_size\fR to the same value as -\&\fIdata_size\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -A couple of examples to just show how \fB\s-1OSSL_PARAM\s0\fR arrays could be -set up. -.PP -\fIExample 1\fR -.IX Subsection "Example 1" -.PP -This example is for setting parameters on some object: -.PP -.Vb 1 -\& #include -\& -\& const char *foo = "some string"; -\& size_t foo_l = strlen(foo); -\& const char bar[] = "some other string"; -\& OSSL_PARAM set[] = { -\& { "foo", OSSL_PARAM_UTF8_PTR, &foo, foo_l, 0 }, -\& { "bar", OSSL_PARAM_UTF8_STRING, (void *)&bar, sizeof(bar) \- 1, 0 }, -\& { NULL, 0, NULL, 0, 0 } -\& }; -.Ve -.PP -\fIExample 2\fR -.IX Subsection "Example 2" -.PP -This example is for requesting parameters on some object: -.PP -.Vb 9 -\& const char *foo = NULL; -\& size_t foo_l; -\& char bar[1024]; -\& size_t bar_l; -\& OSSL_PARAM request[] = { -\& { "foo", OSSL_PARAM_UTF8_PTR, &foo, 0 /*irrelevant*/, 0 }, -\& { "bar", OSSL_PARAM_UTF8_STRING, &bar, sizeof(bar), 0 }, -\& { NULL, 0, NULL, 0, 0 } -\& }; -.Ve -.PP -A \fIresponder\fR that receives this array (as \fIparams\fR in this example) -could fill in the parameters like this: -.PP -.Vb 1 -\& /* OSSL_PARAM *params */ -\& -\& int i; -\& -\& for (i = 0; params[i].key != NULL; i++) { -\& if (strcmp(params[i].key, "foo") == 0) { -\& *(char **)params[i].data = "foo value"; -\& params[i].return_size = 9; /* length of "foo value" string */ -\& } else if (strcmp(params[i].key, "bar") == 0) { -\& memcpy(params[i].data, "bar value", 10); -\& params[i].return_size = 9; /* length of "bar value" string */ -\& } -\& /* Ignore stuff we don\*(Aqt know */ -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core.h\fR\|(7), \fBOSSL_PARAM_get_int\fR\|(3), \fBOSSL_PARAM_dup\fR\|(3), \fBOSSL_PARAM_construct_utf8_string\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fB\s-1OSSL_PARAM\s0\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD.3ossl deleted file mode 100644 index c15b4dc5..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD.3ossl +++ /dev/null @@ -1,339 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PARAM_BLD 3ossl" -.TH OSSL_PARAM_BLD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PARAM_BLD, OSSL_PARAM_BLD_new, OSSL_PARAM_BLD_to_param, -OSSL_PARAM_BLD_free, OSSL_PARAM_BLD_push_int, -OSSL_PARAM_BLD_push_uint, OSSL_PARAM_BLD_push_long, -OSSL_PARAM_BLD_push_ulong, OSSL_PARAM_BLD_push_int32, -OSSL_PARAM_BLD_push_uint32, OSSL_PARAM_BLD_push_int64, -OSSL_PARAM_BLD_push_uint64, OSSL_PARAM_BLD_push_size_t, -OSSL_PARAM_BLD_push_time_t, OSSL_PARAM_BLD_push_double, -OSSL_PARAM_BLD_push_BN, OSSL_PARAM_BLD_push_BN_pad, -OSSL_PARAM_BLD_push_utf8_string, OSSL_PARAM_BLD_push_utf8_ptr, -OSSL_PARAM_BLD_push_octet_string, OSSL_PARAM_BLD_push_octet_ptr -\&\- functions to assist in the creation of OSSL_PARAM arrays -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct OSSL_PARAM_BLD; -\& -\& OSSL_PARAM_BLD *OSSL_PARAM_BLD_new(void); -\& OSSL_PARAM *OSSL_PARAM_BLD_to_param(OSSL_PARAM_BLD *bld); -\& void OSSL_PARAM_BLD_free(OSSL_PARAM_BLD *bld); -\& -\& int OSSL_PARAM_BLD_push_TYPE(OSSL_PARAM_BLD *bld, const char *key, TYPE val); -\& -\& int OSSL_PARAM_BLD_push_BN(OSSL_PARAM_BLD *bld, const char *key, -\& const BIGNUM *bn); -\& int OSSL_PARAM_BLD_push_BN_pad(OSSL_PARAM_BLD *bld, const char *key, -\& const BIGNUM *bn, size_t sz); -\& -\& int OSSL_PARAM_BLD_push_utf8_string(OSSL_PARAM_BLD *bld, const char *key, -\& const char *buf, size_t bsize); -\& int OSSL_PARAM_BLD_push_utf8_ptr(OSSL_PARAM_BLD *bld, const char *key, -\& char *buf, size_t bsize); -\& int OSSL_PARAM_BLD_push_octet_string(OSSL_PARAM_BLD *bld, const char *key, -\& const void *buf, size_t bsize); -\& int OSSL_PARAM_BLD_push_octet_ptr(OSSL_PARAM_BLD *bld, const char *key, -\& void *buf, size_t bsize); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A collection of utility functions that simplify the creation of \s-1OSSL_PARAM\s0 -arrays. The \fB\f(BI\s-1TYPE\s0\fB\fR names are as per \fBOSSL_PARAM_int\fR\|(3). -.PP -\&\fBOSSL_PARAM_BLD_new()\fR allocates and initialises a new \s-1OSSL_PARAM_BLD\s0 structure -so that values can be added. -Any existing values are cleared. -.PP -\&\fBOSSL_PARAM_BLD_free()\fR deallocates the memory allocates by \fBOSSL_PARAM_BLD_new()\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_PARAM_BLD_to_param()\fR converts a built up \s-1OSSL_PARAM_BLD\s0 structure -\&\fIbld\fR into an allocated \s-1OSSL_PARAM\s0 array. -The \s-1OSSL_PARAM\s0 array and all associated storage must be freed by calling -\&\fBOSSL_PARAM_free()\fR with the functions return value. -\&\fBOSSL_PARAM_BLD_free()\fR can safely be called any time after this function is. -.PP -\&\fBOSSL_PARAM_BLD_push_\f(BI\s-1TYPE\s0\fB\fR() are a series of functions which will create -\&\s-1OSSL_PARAM\s0 objects of the specified size and correct type for the \fIval\fR -argument. -\&\fIval\fR is stored by value and an expression or auto variable can be used. -.PP -When \fB\f(BI\s-1TYPE\s0\fB\fR denotes an integer type, signed integer types will normally -get the \s-1OSSL_PARAM\s0 type \fB\s-1OSSL_PARAM_INTEGER\s0\fR params. -When \fB\f(BI\s-1TYPE\s0\fB\fR denotes an unsigned integer type will get the \s-1OSSL_PARAM\s0 type -\&\fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR. -.PP -\&\fBOSSL_PARAM_BLD_push_BN()\fR is a function that will create an \s-1OSSL_PARAM\s0 object -that holds the specified \s-1BIGNUM\s0 \fIbn\fR. -When the \fIbn\fR is zero or positive, its \s-1OSSL_PARAM\s0 type becomes -\&\fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR. -When the \fIbn\fR is negative, its \s-1OSSL_PARAM\s0 type becomes \fB\s-1OSSL_PARAM_INTEGER\s0\fR. -If \fIbn\fR is marked as being securely allocated, its \s-1OSSL_PARAM\s0 representation -will also be securely allocated. -The \fIbn\fR argument is stored by reference and the underlying \s-1BIGNUM\s0 object -must exist until after \fBOSSL_PARAM_BLD_to_param()\fR has been called. -.PP -\&\fBOSSL_PARAM_BLD_push_BN_pad()\fR is a function that will create an \s-1OSSL_PARAM\s0 object -that holds the specified \s-1BIGNUM\s0 \fIbn\fR. -The object will be padded to occupy exactly \fIsz\fR bytes, if insufficient space -is specified an error results. -When the \fIbn\fR is zero or positive, its \s-1OSSL_PARAM\s0 type becomes -\&\fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR. -When the \fIbn\fR is negative, its \s-1OSSL_PARAM\s0 type becomes \fB\s-1OSSL_PARAM_INTEGER\s0\fR. -If \fIbn\fR is marked as being securely allocated, its \s-1OSSL_PARAM\s0 representation -will also be securely allocated. -The \fIbn\fR argument is stored by reference and the underlying \s-1BIGNUM\s0 object -must exist until after \fBOSSL_PARAM_BLD_to_param()\fR has been called. -.PP -\&\fBOSSL_PARAM_BLD_push_utf8_string()\fR is a function that will create an \s-1OSSL_PARAM\s0 -object that references the \s-1UTF8\s0 string specified by \fIbuf\fR. -The length of the string \fIbsize\fR should not include the terminating \s-1NUL\s0 byte. -If it is zero then it will be calculated. -The string that \fIbuf\fR points to is stored by reference and must remain in -scope until after \fBOSSL_PARAM_BLD_to_param()\fR has been called. -.PP -\&\fBOSSL_PARAM_BLD_push_octet_string()\fR is a function that will create an \s-1OSSL_PARAM\s0 -object that references the octet string specified by \fIbuf\fR and . -The memory that \fIbuf\fR points to is stored by reference and must remain in -scope until after \fBOSSL_PARAM_BLD_to_param()\fR has been called. -.PP -\&\fBOSSL_PARAM_BLD_push_utf8_ptr()\fR is a function that will create an \s-1OSSL_PARAM\s0 -object that references the \s-1UTF8\s0 string specified by \fIbuf\fR. -The length of the string \fIbsize\fR should not include the terminating \s-1NUL\s0 byte. -If it is zero then it will be calculated. -The string \fIbuf\fR points to is stored by reference and must remain in -scope until the \s-1OSSL_PARAM\s0 array is freed. -.PP -\&\fBOSSL_PARAM_BLD_push_octet_ptr()\fR is a function that will create an \s-1OSSL_PARAM\s0 -object that references the octet string specified by \fIbuf\fR. -The memory \fIbuf\fR points to is stored by reference and must remain in -scope until the \s-1OSSL_PARAM\s0 array is freed. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_PARAM_BLD_new()\fR returns the allocated \s-1OSSL_PARAM_BLD\s0 structure, or \s-1NULL\s0 -on error. -.PP -\&\fBOSSL_PARAM_BLD_to_param()\fR returns the allocated \s-1OSSL_PARAM\s0 array, or \s-1NULL\s0 -on error. -.PP -All of the OSSL_PARAM_BLD_push_TYPE functions return 1 on success and 0 -on error. -.SH "NOTES" -.IX Header "NOTES" -\&\fBOSSL_PARAM_BLD_push_BN()\fR and \fBOSSL_PARAM_BLD_push_BN_pad()\fR only -support nonnegative \fB\s-1BIGNUM\s0\fRs. They return an error on negative -\&\fB\s-1BIGNUM\s0\fRs. -To pass signed \fB\s-1BIGNUM\s0\fRs, use \fBOSSL_PARAM_BLD_push_signed_BN()\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Both examples creating an \s-1OSSL_PARAM\s0 array that contains an \s-1RSA\s0 key. -For both, the predefined key variables are: -.PP -.Vb 6 -\& BIGNUM *n; /* modulus */ -\& unsigned int e; /* public exponent */ -\& BIGNUM *d; /* private exponent */ -\& BIGNUM *p, *q; /* first two prime factors */ -\& BIGNUM *dmp1, *dmq1; /* first two CRT exponents */ -\& BIGNUM *iqmp; /* first CRT coefficient */ -.Ve -.SS "Example 1" -.IX Subsection "Example 1" -This example shows how to create an \s-1OSSL_PARAM\s0 array that contains an \s-1RSA\s0 -private key. -.PP -.Vb 2 -\& OSSL_PARAM_BLD *bld = OSSL_PARAM_BLD_new(); -\& OSSL_PARAM *params = NULL; -\& -\& if (bld == NULL -\& || !OSSL_PARAM_BLD_push_BN(bld, "n", n) -\& || !OSSL_PARAM_BLD_push_uint(bld, "e", e) -\& || !OSSL_PARAM_BLD_push_BN(bld, "d", d) -\& || !OSSL_PARAM_BLD_push_BN(bld, "rsa\-factor1", p) -\& || !OSSL_PARAM_BLD_push_BN(bld, "rsa\-factor2", q) -\& || !OSSL_PARAM_BLD_push_BN(bld, "rsa\-exponent1", dmp1) -\& || !OSSL_PARAM_BLD_push_BN(bld, "rsa\-exponent2", dmq1) -\& || !OSSL_PARAM_BLD_push_BN(bld, "rsa\-coefficient1", iqmp) -\& || (params = OSSL_PARAM_BLD_to_param(bld)) == NULL) -\& goto err; -\& OSSL_PARAM_BLD_free(bld); -\& /* Use params */ -\& ... -\& OSSL_PARAM_free(params); -.Ve -.SS "Example 2" -.IX Subsection "Example 2" -This example shows how to create an \s-1OSSL_PARAM\s0 array that contains an \s-1RSA\s0 -public key. -.PP -.Vb 2 -\& OSSL_PARAM_BLD *bld = OSSL_PARAM_BLD_new(); -\& OSSL_PARAM *params = NULL; -\& -\& if (nld == NULL -\& || !OSSL_PARAM_BLD_push_BN(bld, "n", n) -\& || !OSSL_PARAM_BLD_push_uint(bld, "e", e) -\& || (params = OSSL_PARAM_BLD_to_param(bld)) == NULL) -\& goto err; -\& OSSL_PARAM_BLD_free(bld); -\& /* Use params */ -\& ... -\& OSSL_PARAM_free(params); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_PARAM_int\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3), \fBOSSL_PARAM_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were all added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_free.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_free.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_new.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_new.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN_pad.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN_pad.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_BN_pad.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_double.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_double.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_double.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int32.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int64.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_long.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_long.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_ptr.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_string.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_octet_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_size_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_size_t.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_size_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_time_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_time_t.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_time_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint32.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint64.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_ulong.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_ulong.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_ulong.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_ptr.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_string.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_push_utf8_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BLD_to_param.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BLD_to_param.3ossl deleted file mode 120000 index 69d2da6e..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BLD_to_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_BLD.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_BN.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_BN.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_DEFN.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_DEFN.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_DEFN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_END.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_END.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_END.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_UNMODIFIED.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_UNMODIFIED.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_UNMODIFIED.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_allocate_from_text.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_allocate_from_text.3ossl deleted file mode 100644 index b2730e33..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_allocate_from_text.3ossl +++ /dev/null @@ -1,330 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PARAM_ALLOCATE_FROM_TEXT 3ossl" -.TH OSSL_PARAM_ALLOCATE_FROM_TEXT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PARAM_allocate_from_text -\&\- OSSL_PARAM construction utilities -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_PARAM_allocate_from_text(OSSL_PARAM *to, -\& const OSSL_PARAM *paramdefs, -\& const char *key, const char *value, -\& size_t value_n, -\& int *found); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -With OpenSSL before version 3.0, parameters were passed down to or -retrieved from algorithm implementations via control functions. -Some of these control functions existed in variants that took string -parameters, for example \fBEVP_PKEY_CTX_ctrl_str\fR\|(3). -.PP -OpenSSL 3.0 introduces a new mechanism to do the same thing with an -array of parameters that contain name, value, value type and value -size (see \s-1\fBOSSL_PARAM\s0\fR\|(3) for more information). -.PP -\&\fBOSSL_PARAM_allocate_from_text()\fR uses \fIkey\fR to look up an item in -\&\fIparamdefs\fR. If an item was found, it converts \fIvalue\fR to something -suitable for that item's \fIdata_type\fR, and stores the result in -\&\fIto\->data\fR as well as its size in \fIto\->data_size\fR. -\&\fIto\->key\fR and \fIto\->data_type\fR are assigned the corresponding -values from the item that was found, and \fIto\->return_size\fR is set -to zero. -.PP -\&\fIto\->data\fR is always allocated using \fBOPENSSL_zalloc\fR\|(3) and -needs to be freed by the caller when it's not useful any more, using -\&\fBOPENSSL_free\fR\|(3). -.PP -If \fIfound\fR is not \s-1NULL,\s0 \fI*found\fR is set to 1 if \fIkey\fR could be -located in \fIparamdefs\fR, and to 0 otherwise. -.SS "The use of \fIkey\fP and \fIvalue\fP in detail" -.IX Subsection "The use of key and value in detail" -\&\fBOSSL_PARAM_allocate_from_text()\fR takes note if \fIkey\fR starts with -\&\*(L"hex\*(R", and will only use the rest of \fIkey\fR to look up an item in -\&\fIparamdefs\fR in that case. As an example, if \fIkey\fR is \*(L"hexid\*(R", \*(L"id\*(R" -will be looked up in \fIparamdefs\fR. -.PP -When an item in \fIparamdefs\fR has been found, \fIvalue\fR is converted -depending on that item's \fIdata_type\fR, as follows: -.IP "\fB\s-1OSSL_PARAM_INTEGER\s0\fR and \fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR" 4 -.IX Item "OSSL_PARAM_INTEGER and OSSL_PARAM_UNSIGNED_INTEGER" -If \fIkey\fR didn't start with \*(L"hex\*(R", \fIvalue\fR is assumed to contain -\&\fIvalue_n\fR decimal characters, which are decoded, and the resulting -bytes become the number stored in the \fIto\->data\fR storage. -.Sp -If \fIvalue\fR starts with \*(L"0x\*(R", it is assumed to contain \fIvalue_n\fR -hexadecimal characters. -.Sp -If \fIkey\fR started with \*(L"hex\*(R", \fIvalue\fR is assumed to contain -\&\fIvalue_n\fR hexadecimal characters without the \*(L"0x\*(R" prefix. -.Sp -If \fIvalue\fR contains characters that couldn't be decoded as -hexadecimal or decimal characters, \fBOSSL_PARAM_allocate_from_text()\fR -considers that an error. -.IP "\fB\s-1OSSL_PARAM_UTF8_STRING\s0\fR" 4 -.IX Item "OSSL_PARAM_UTF8_STRING" -If \fIkey\fR started with \*(L"hex\*(R", \fBOSSL_PARAM_allocate_from_text()\fR -considers that an error. -.Sp -Otherwise, \fIvalue\fR is considered a C string and is copied to the -\&\fIto\->data\fR storage. -On systems where the native character encoding is \s-1EBCDIC,\s0 the bytes in -\&\fIto\->data\fR are converted to \s-1ASCII.\s0 -.IP "\fB\s-1OSSL_PARAM_OCTET_STRING\s0\fR" 4 -.IX Item "OSSL_PARAM_OCTET_STRING" -If \fIkey\fR started with \*(L"hex\*(R", \fIvalue\fR is assumed to contain -\&\fIvalue_n\fR hexadecimal characters, which are decoded, and the -resulting bytes are stored in the \fIto\->data\fR storage. -If \fIvalue\fR contains characters that couldn't be decoded as -hexadecimal or decimal characters, \fBOSSL_PARAM_allocate_from_text()\fR -considers that an error. -.Sp -If \fIkey\fR didn't start with \*(L"hex\*(R", \fIvalue_n\fR bytes from \fIvalue\fR are -copied to the \fIto\->data\fR storage. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_PARAM_allocate_from_text()\fR returns 1 if \fIkey\fR was found in -\&\fIparamdefs\fR and there was no other failure, otherwise 0. -.SH "NOTES" -.IX Header "NOTES" -The parameter descriptor array comes from functions dedicated to -return them. -The following \s-1\fBOSSL_PARAM\s0\fR\|(3) attributes are used: -.IP "\fIkey\fR" 4 -.IX Item "key" -.PD 0 -.IP "\fIdata_type\fR" 4 -.IX Item "data_type" -.IP "\fIdata_size\fR" 4 -.IX Item "data_size" -.PD -.PP -All other attributes are ignored. -.PP -The \fIdata_size\fR attribute can be zero, meaning that the parameter it -describes expects arbitrary length data. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Code that looked like this: -.PP -.Vb 4 -\& int mac_ctrl_string(EVP_PKEY_CTX *ctx, const char *value) -\& { -\& int rv; -\& char *stmp, *vtmp = NULL; -\& -\& stmp = OPENSSL_strdup(value); -\& if (stmp == NULL) -\& return \-1; -\& vtmp = strchr(stmp, \*(Aq:\*(Aq); -\& if (vtmp != NULL) -\& *vtmp++ = \*(Aq\e0\*(Aq; -\& rv = EVP_MAC_ctrl_str(ctx, stmp, vtmp); -\& OPENSSL_free(stmp); -\& return rv; -\& } -\& -\& ... -\& -\& -\& for (i = 0; i < sk_OPENSSL_STRING_num(macopts); i++) { -\& char *macopt = sk_OPENSSL_STRING_value(macopts, i); -\& -\& if (pkey_ctrl_string(mac_ctx, macopt) <= 0) { -\& BIO_printf(bio_err, -\& "MAC parameter error \e"%s\e"\en", macopt); -\& ERR_print_errors(bio_err); -\& goto mac_end; -\& } -\& } -.Ve -.PP -Can be written like this instead: -.PP -.Vb 6 -\& OSSL_PARAM *params = -\& OPENSSL_zalloc(sizeof(*params) -\& * (sk_OPENSSL_STRING_num(opts) + 1)); -\& const OSSL_PARAM *paramdefs = EVP_MAC_settable_ctx_params(mac); -\& size_t params_n; -\& char *opt = ""; -\& -\& for (params_n = 0; params_n < (size_t)sk_OPENSSL_STRING_num(opts); -\& params_n++) { -\& char *stmp, *vtmp = NULL; -\& -\& opt = sk_OPENSSL_STRING_value(opts, (int)params_n); -\& if ((stmp = OPENSSL_strdup(opt)) == NULL -\& || (vtmp = strchr(stmp, \*(Aq:\*(Aq)) == NULL) -\& goto err; -\& -\& *vtmp++ = \*(Aq\e0\*(Aq; -\& if (!OSSL_PARAM_allocate_from_text(¶ms[params_n], -\& paramdefs, stmp, -\& vtmp, strlen(vtmp), NULL)) -\& goto err; -\& } -\& params[params_n] = OSSL_PARAM_construct_end(); -\& if (!EVP_MAC_CTX_set_params(ctx, params)) -\& goto err; -\& while (params_n\-\- > 0) -\& OPENSSL_free(params[params_n].data); -\& OPENSSL_free(params); -\& /* ... */ -\& return; -\& -\& err: -\& BIO_printf(bio_err, "MAC parameter error \*(Aq%s\*(Aq\en", opt); -\& ERR_print_errors(bio_err); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), \fBOSSL_PARAM_int\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_BN.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_BN.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_double.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_double.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_double.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_end.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_end.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_end.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_int.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_int.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_int.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_int32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_int32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_int32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_int64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_int64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_long.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_long.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_octet_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_octet_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_octet_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_octet_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_octet_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_octet_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_size_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_size_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_size_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_time_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_time_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_time_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_uint.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_uint.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_uint32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_uint32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_uint32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_uint64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_uint64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_ulong.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_ulong.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_ulong.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_construct_utf8_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_double.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_double.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_double.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_dup.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_dup.3ossl deleted file mode 100644 index 24e557a0..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_dup.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PARAM_DUP 3ossl" -.TH OSSL_PARAM_DUP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PARAM_dup, OSSL_PARAM_merge, OSSL_PARAM_free -\&\- OSSL_PARAM array copy functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_PARAM *OSSL_PARAM_dup(const OSSL_PARAM *params); -\& OSSL_PARAM *OSSL_PARAM_merge(const OSSL_PARAM *params, const OSSL_PARAM *params1); -\& void OSSL_PARAM_free(OSSL_PARAM *params); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Algorithm parameters can be exported/imported from/to providers using arrays of -\&\s-1\fBOSSL_PARAM\s0\fR\|(3). The following utility functions allow the parameters to be -duplicated and merged with other \s-1\fBOSSL_PARAM\s0\fR\|(3) to assist in this process. -.PP -\&\fBOSSL_PARAM_dup()\fR duplicates the parameter array \fIparams\fR. This function does a -deep copy of the data. -.PP -\&\fBOSSL_PARAM_merge()\fR merges the parameter arrays \fIparams\fR and \fIparams1\fR into a -new parameter array. If \fIparams\fR and \fIparams1\fR contain values with the same -\&'key' then the value from \fIparams1\fR will replace the \fIparam\fR value. This -function does a shallow copy of the parameters. Either \fIparams\fR or \fIparams1\fR -may be \s-1NULL.\s0 The behaviour of the merge is unpredictable if \fIparams\fR and -\&\fIparams1\fR contain the same key, and there are multiple entries within either -array that have the same key. -.PP -\&\fBOSSL_PARAM_free()\fR frees the parameter array \fIparams\fR that was created using -\&\fBOSSL_PARAM_dup()\fR, \fBOSSL_PARAM_merge()\fR or \fBOSSL_PARAM_BLD_to_param()\fR. -If the argument to \fBOSSL_PARAM_free()\fR is \s-1NULL,\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions \fBOSSL_PARAM_dup()\fR and \fBOSSL_PARAM_merge()\fR return a newly allocated -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) array, or \s-1NULL\s0 if there was an error. If both parameters are \s-1NULL\s0 - then \s-1NULL\s0 is returned. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), \s-1\fBOSSL_PARAM_BLD\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_PARAM_free.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_free.3ossl deleted file mode 120000 index f89285ed..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_BN.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_BN.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_double.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_double.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_double.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_int.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_int.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_int.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_int32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_int32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_int32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_int64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_int64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_long.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_long.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_octet_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_octet_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_octet_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_octet_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_octet_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_octet_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_octet_string_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_octet_string_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_octet_string_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_size_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_size_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_size_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_time_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_time_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_time_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_uint.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_uint.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_uint32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_uint32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_uint32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_uint64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_uint64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_ulong.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_ulong.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_ulong.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_get_utf8_string_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_int.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_int.3ossl deleted file mode 100644 index 0cba1adb..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_int.3ossl +++ /dev/null @@ -1,543 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PARAM_INT 3ossl" -.TH OSSL_PARAM_INT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PARAM_double, OSSL_PARAM_int, OSSL_PARAM_int32, OSSL_PARAM_int64, -OSSL_PARAM_long, OSSL_PARAM_size_t, OSSL_PARAM_time_t, OSSL_PARAM_uint, -OSSL_PARAM_uint32, OSSL_PARAM_uint64, OSSL_PARAM_ulong, OSSL_PARAM_BN, -OSSL_PARAM_utf8_string, OSSL_PARAM_octet_string, OSSL_PARAM_utf8_ptr, -OSSL_PARAM_octet_ptr, -OSSL_PARAM_END, OSSL_PARAM_DEFN, -OSSL_PARAM_construct_double, OSSL_PARAM_construct_int, -OSSL_PARAM_construct_int32, OSSL_PARAM_construct_int64, -OSSL_PARAM_construct_long, OSSL_PARAM_construct_size_t, -OSSL_PARAM_construct_time_t, OSSL_PARAM_construct_uint, -OSSL_PARAM_construct_uint32, OSSL_PARAM_construct_uint64, -OSSL_PARAM_construct_ulong, OSSL_PARAM_construct_BN, -OSSL_PARAM_construct_utf8_string, OSSL_PARAM_construct_utf8_ptr, -OSSL_PARAM_construct_octet_string, OSSL_PARAM_construct_octet_ptr, -OSSL_PARAM_construct_end, -OSSL_PARAM_locate, OSSL_PARAM_locate_const, -OSSL_PARAM_get_double, OSSL_PARAM_get_int, OSSL_PARAM_get_int32, -OSSL_PARAM_get_int64, OSSL_PARAM_get_long, OSSL_PARAM_get_size_t, -OSSL_PARAM_get_time_t, OSSL_PARAM_get_uint, OSSL_PARAM_get_uint32, -OSSL_PARAM_get_uint64, OSSL_PARAM_get_ulong, OSSL_PARAM_get_BN, -OSSL_PARAM_get_utf8_string, OSSL_PARAM_get_octet_string, -OSSL_PARAM_get_utf8_ptr, OSSL_PARAM_get_octet_ptr, -OSSL_PARAM_get_utf8_string_ptr, OSSL_PARAM_get_octet_string_ptr, -OSSL_PARAM_set_double, OSSL_PARAM_set_int, OSSL_PARAM_set_int32, -OSSL_PARAM_set_int64, OSSL_PARAM_set_long, OSSL_PARAM_set_size_t, -OSSL_PARAM_set_time_t, OSSL_PARAM_set_uint, OSSL_PARAM_set_uint32, -OSSL_PARAM_set_uint64, OSSL_PARAM_set_ulong, OSSL_PARAM_set_BN, -OSSL_PARAM_set_utf8_string, OSSL_PARAM_set_octet_string, -OSSL_PARAM_set_utf8_ptr, OSSL_PARAM_set_octet_ptr, -OSSL_PARAM_UNMODIFIED, OSSL_PARAM_modified, OSSL_PARAM_set_all_unmodified -\&\- OSSL_PARAM helpers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& /* -\& * TYPE in function names is one of: -\& * double, int, int32, int64, long, size_t, time_t, uint, uint32, uint64, ulong -\& * Corresponding TYPE in function arguments is one of: -\& * double, int, int32_t, int64_t, long, size_t, time_t, unsigned int, uint32_t, -\& * uint64_t, unsigned long -\& */ -\& -\& #define OSSL_PARAM_TYPE(key, address) -\& #define OSSL_PARAM_BN(key, address, size) -\& #define OSSL_PARAM_utf8_string(key, address, size) -\& #define OSSL_PARAM_octet_string(key, address, size) -\& #define OSSL_PARAM_utf8_ptr(key, address, size) -\& #define OSSL_PARAM_octet_ptr(key, address, size) -\& #define OSSL_PARAM_END -\& -\& #define OSSL_PARAM_UNMODIFIED -\& -\& #define OSSL_PARAM_DEFN(key, type, addr, sz) \e -\& { (key), (type), (addr), (sz), OSSL_PARAM_UNMODIFIED } -\& -\& OSSL_PARAM OSSL_PARAM_construct_TYPE(const char *key, TYPE *buf); -\& OSSL_PARAM OSSL_PARAM_construct_BN(const char *key, unsigned char *buf, -\& size_t bsize); -\& OSSL_PARAM OSSL_PARAM_construct_utf8_string(const char *key, char *buf, -\& size_t bsize); -\& OSSL_PARAM OSSL_PARAM_construct_octet_string(const char *key, void *buf, -\& size_t bsize); -\& OSSL_PARAM OSSL_PARAM_construct_utf8_ptr(const char *key, char **buf, -\& size_t bsize); -\& OSSL_PARAM OSSL_PARAM_construct_octet_ptr(const char *key, void **buf, -\& size_t bsize); -\& OSSL_PARAM OSSL_PARAM_construct_end(void); -\& -\& OSSL_PARAM *OSSL_PARAM_locate(OSSL_PARAM *array, const char *key); -\& const OSSL_PARAM *OSSL_PARAM_locate_const(const OSSL_PARAM *array, -\& const char *key); -\& -\& int OSSL_PARAM_get_TYPE(const OSSL_PARAM *p, TYPE *val); -\& int OSSL_PARAM_set_TYPE(OSSL_PARAM *p, TYPE val); -\& -\& int OSSL_PARAM_get_BN(const OSSL_PARAM *p, BIGNUM **val); -\& int OSSL_PARAM_set_BN(OSSL_PARAM *p, const BIGNUM *val); -\& -\& int OSSL_PARAM_get_utf8_string(const OSSL_PARAM *p, char **val, -\& size_t max_len); -\& int OSSL_PARAM_set_utf8_string(OSSL_PARAM *p, const char *val); -\& -\& int OSSL_PARAM_get_octet_string(const OSSL_PARAM *p, void **val, -\& size_t max_len, size_t *used_len); -\& int OSSL_PARAM_set_octet_string(OSSL_PARAM *p, const void *val, size_t len); -\& -\& int OSSL_PARAM_get_utf8_ptr(const OSSL_PARAM *p, const char **val); -\& int OSSL_PARAM_set_utf8_ptr(OSSL_PARAM *p, const char *val); -\& -\& int OSSL_PARAM_get_octet_ptr(const OSSL_PARAM *p, const void **val, -\& size_t *used_len); -\& int OSSL_PARAM_set_octet_ptr(OSSL_PARAM *p, const void *val, -\& size_t used_len); -\& -\& int OSSL_PARAM_get_utf8_string_ptr(const OSSL_PARAM *p, const char **val); -\& int OSSL_PARAM_get_octet_string_ptr(const OSSL_PARAM *p, const void **val, -\& size_t *used_len); -\& -\& int OSSL_PARAM_modified(const OSSL_PARAM *param); -\& void OSSL_PARAM_set_all_unmodified(OSSL_PARAM *params); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A collection of utility functions that simplify and add type safety to the -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) arrays. The following \fB\f(BI\s-1TYPE\s0\fB\fR names are supported: -.IP "\(bu" 2 -double -.IP "\(bu" 2 -int -.IP "\(bu" 2 -int32 (int32_t) -.IP "\(bu" 2 -int64 (int64_t) -.IP "\(bu" 2 -long int (long) -.IP "\(bu" 2 -time_t -.IP "\(bu" 2 -size_t -.IP "\(bu" 2 -uint32 (uint32_t) -.IP "\(bu" 2 -uint64 (uint64_t) -.IP "\(bu" 2 -unsigned int (uint) -.IP "\(bu" 2 -unsigned long int (ulong) -.PP -\&\s-1\fBOSSL_PARAM_TYPE\s0()\fR are a series of macros designed to assist initialising an -array of \s-1\fBOSSL_PARAM\s0\fR\|(3) structures. -Each of these macros defines a parameter of the specified \fB\f(BI\s-1TYPE\s0\fB\fR with the -provided \fIkey\fR and parameter variable \fIaddress\fR. -.PP -\&\fBOSSL_PARAM_utf8_string()\fR, \fBOSSL_PARAM_octet_string()\fR, \fBOSSL_PARAM_utf8_ptr()\fR, -\&\fBOSSL_PARAM_octet_ptr()\fR, \s-1\fBOSSL_PARAM_BN\s0()\fR are macros that provide support -for defining \s-1UTF8\s0 strings, \s-1OCTET\s0 strings and big numbers. -A parameter with name \fIkey\fR is defined. -The storage for this parameter is at \fIaddress\fR and is of \fIsize\fR bytes. -.PP -\&\s-1OSSL_PARAM_END\s0 provides an end of parameter list marker. -This should terminate all \s-1\fBOSSL_PARAM\s0\fR\|(3) arrays. -.PP -The \s-1\fBOSSL_PARAM_DEFN\s0()\fR macro provides the ability to construct a single -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) (typically used in the construction of \fB\s-1OSSL_PARAM\s0\fR arrays). The -\&\fIkey\fR, \fItype\fR, \fIaddr\fR and \fIsz\fR arguments correspond to the \fIkey\fR, -\&\fIdata_type\fR, \fIdata\fR and \fIdata_size\fR fields of the \s-1\fBOSSL_PARAM\s0\fR\|(3) structure as -described on the \s-1\fBOSSL_PARAM\s0\fR\|(3) page. -.PP -\&\fBOSSL_PARAM_construct_TYPE()\fR are a series of functions that create \s-1\fBOSSL_PARAM\s0\fR\|(3) -records dynamically. -A parameter with name \fIkey\fR is created. -The parameter will use storage pointed to by \fIbuf\fR and return size of \fIret\fR. -.PP -\&\fBOSSL_PARAM_construct_BN()\fR is a function that constructs a large integer -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) structure. -A parameter with name \fIkey\fR, storage \fIbuf\fR, size \fIbsize\fR and return -size \fIrsize\fR is created. -.PP -\&\fBOSSL_PARAM_construct_utf8_string()\fR is a function that constructs a \s-1UTF8\s0 -string \s-1\fBOSSL_PARAM\s0\fR\|(3) structure. -A parameter with name \fIkey\fR, storage \fIbuf\fR and size \fIbsize\fR is created. -If \fIbsize\fR is zero, the string length is determined using \fBstrlen\fR\|(3). -Generally pass zero for \fIbsize\fR instead of calling \fBstrlen\fR\|(3) yourself. -.PP -\&\fBOSSL_PARAM_construct_octet_string()\fR is a function that constructs an \s-1OCTET\s0 -string \s-1\fBOSSL_PARAM\s0\fR\|(3) structure. -A parameter with name \fIkey\fR, storage \fIbuf\fR and size \fIbsize\fR is created. -.PP -\&\fBOSSL_PARAM_construct_utf8_ptr()\fR is a function that constructs a \s-1UTF8\s0 string -pointer \s-1\fBOSSL_PARAM\s0\fR\|(3) structure. -A parameter with name \fIkey\fR, storage pointer \fI*buf\fR and size \fIbsize\fR -is created. -.PP -\&\fBOSSL_PARAM_construct_octet_ptr()\fR is a function that constructs an \s-1OCTET\s0 string -pointer \s-1\fBOSSL_PARAM\s0\fR\|(3) structure. -A parameter with name \fIkey\fR, storage pointer \fI*buf\fR and size \fIbsize\fR -is created. -.PP -\&\fBOSSL_PARAM_construct_end()\fR is a function that constructs the terminating -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) structure. -.PP -\&\fBOSSL_PARAM_locate()\fR is a function that searches an \fIarray\fR of parameters for -the one matching the \fIkey\fR name. -.PP -\&\fBOSSL_PARAM_locate_const()\fR behaves exactly like \fBOSSL_PARAM_locate()\fR except for -the presence of \fIconst\fR for the \fIarray\fR argument and its return value. -.PP -\&\fBOSSL_PARAM_get_TYPE()\fR retrieves a value of type \fB\f(BI\s-1TYPE\s0\fB\fR from the parameter -\&\fIp\fR. -The value is copied to the address \fIval\fR. -Type coercion takes place as discussed in the \s-1NOTES\s0 section. -.PP -\&\fBOSSL_PARAM_set_TYPE()\fR stores a value \fIval\fR of type \fB\f(BI\s-1TYPE\s0\fB\fR into the -parameter \fIp\fR. -If the parameter's \fIdata\fR field is \s-1NULL,\s0 then only its \fIreturn_size\fR field -will be assigned the size the parameter's \fIdata\fR buffer should have. -Type coercion takes place as discussed in the \s-1NOTES\s0 section. -.PP -\&\fBOSSL_PARAM_get_BN()\fR retrieves a \s-1BIGNUM\s0 from the parameter pointed to by \fIp\fR. -The \s-1BIGNUM\s0 referenced by \fIval\fR is updated and is allocated if \fI*val\fR is -\&\s-1NULL.\s0 -.PP -\&\fBOSSL_PARAM_set_BN()\fR stores the \s-1BIGNUM\s0 \fIval\fR into the parameter \fIp\fR. -If the parameter's \fIdata\fR field is \s-1NULL,\s0 then only its \fIreturn_size\fR field -will be assigned the size the parameter's \fIdata\fR buffer should have. -.PP -\&\fBOSSL_PARAM_get_utf8_string()\fR retrieves a \s-1UTF8\s0 string from the parameter -pointed to by \fIp\fR. -The string is stored into \fI*val\fR with a size limit of \fImax_len\fR, -which must be large enough to accommodate a terminating \s-1NUL\s0 byte, -otherwise this function will fail. -If \fI*val\fR is \s-1NULL,\s0 memory is allocated for the string (including the -terminating \s-1NUL\s0 byte) and \fImax_len\fR is ignored. -If memory is allocated by this function, it must be freed by the caller. -.PP -\&\fBOSSL_PARAM_set_utf8_string()\fR sets a \s-1UTF8\s0 string from the parameter pointed to -by \fIp\fR to the value referenced by \fIval\fR. -If the parameter's \fIdata\fR field isn't \s-1NULL,\s0 its \fIdata_size\fR must indicate -that the buffer is large enough to accommodate the string that \fIval\fR points at, -not including the terminating \s-1NUL\s0 byte, or this function will fail. -A terminating \s-1NUL\s0 byte is added only if the parameter's \fIdata_size\fR indicates -the buffer is longer than the string length, otherwise the string will not be -\&\s-1NUL\s0 terminated. -If the parameter's \fIdata\fR field is \s-1NULL,\s0 then only its \fIreturn_size\fR field -will be assigned the minimum size the parameter's \fIdata\fR buffer should have -to accommodate the string, not including a terminating \s-1NUL\s0 byte. -.PP -\&\fBOSSL_PARAM_get_octet_string()\fR retrieves an \s-1OCTET\s0 string from the parameter -pointed to by \fIp\fR. -The OCTETs are either stored into \fI*val\fR with a length limit of \fImax_len\fR or, -in the case when \fI*val\fR is \s-1NULL,\s0 memory is allocated and -\&\fImax_len\fR is ignored. \fI*used_len\fR is populated with the number of OCTETs -stored. If \fIval\fR is \s-1NULL\s0 then the \s-1OCTETS\s0 are not stored, but \fI*used_len\fR is -still populated. -If memory is allocated by this function, it must be freed by the caller. -.PP -\&\fBOSSL_PARAM_set_octet_string()\fR sets an \s-1OCTET\s0 string from the parameter -pointed to by \fIp\fR to the value referenced by \fIval\fR. -If the parameter's \fIdata\fR field is \s-1NULL,\s0 then only its \fIreturn_size\fR field -will be assigned the size the parameter's \fIdata\fR buffer should have. -.PP -\&\fBOSSL_PARAM_get_utf8_ptr()\fR retrieves the \s-1UTF8\s0 string pointer from the parameter -referenced by \fIp\fR and stores it in \fI*val\fR. -.PP -\&\fBOSSL_PARAM_set_utf8_ptr()\fR sets the \s-1UTF8\s0 string pointer in the parameter -referenced by \fIp\fR to the values \fIval\fR. -.PP -\&\fBOSSL_PARAM_get_octet_ptr()\fR retrieves the \s-1OCTET\s0 string pointer from the parameter -referenced by \fIp\fR and stores it in \fI*val\fR. -The length of the \s-1OCTET\s0 string is stored in \fI*used_len\fR. -.PP -\&\fBOSSL_PARAM_set_octet_ptr()\fR sets the \s-1OCTET\s0 string pointer in the parameter -referenced by \fIp\fR to the values \fIval\fR. -The length of the \s-1OCTET\s0 string is provided by \fIused_len\fR. -.PP -\&\fBOSSL_PARAM_get_utf8_string_ptr()\fR retrieves the pointer to a \s-1UTF8\s0 string from -the parameter pointed to by \fIp\fR, and stores that pointer in \fI*val\fR. -This is different from \fBOSSL_PARAM_get_utf8_string()\fR, which copies the -string. -.PP -\&\fBOSSL_PARAM_get_octet_string_ptr()\fR retrieves the pointer to a octet string -from the parameter pointed to by \fIp\fR, and stores that pointer in \fI*val\fR, -along with the string's length in \fI*used_len\fR. -This is different from \fBOSSL_PARAM_get_octet_string()\fR, which copies the -string. -.PP -The \s-1OSSL_PARAM_UNMODIFIED\s0 macro is used to detect if a parameter was set. On -creation, via either the macros or construct calls, the \fIreturn_size\fR field -is set to this. If the parameter is set using the calls defined herein, the -\&\fIreturn_size\fR field is changed. -.PP -\&\fBOSSL_PARAM_modified()\fR queries if the parameter \fIparam\fR has been set or not -using the calls defined herein. -.PP -\&\fBOSSL_PARAM_set_all_unmodified()\fR resets the unused indicator for all parameters -in the array \fIparams\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_PARAM_construct_TYPE()\fR, \fBOSSL_PARAM_construct_BN()\fR, -\&\fBOSSL_PARAM_construct_utf8_string()\fR, \fBOSSL_PARAM_construct_octet_string()\fR, -\&\fBOSSL_PARAM_construct_utf8_ptr()\fR and \fBOSSL_PARAM_construct_octet_ptr()\fR -return a populated \s-1\fBOSSL_PARAM\s0\fR\|(3) structure. -.PP -\&\fBOSSL_PARAM_locate()\fR and \fBOSSL_PARAM_locate_const()\fR return a pointer to -the matching \s-1\fBOSSL_PARAM\s0\fR\|(3) object. They return \s-1NULL\s0 on error or when -no object matching \fIkey\fR exists in the \fIarray\fR. -.PP -\&\fBOSSL_PARAM_modified()\fR returns 1 if the parameter was set and 0 otherwise. -.PP -All other functions return 1 on success and 0 on failure. -.SH "NOTES" -.IX Header "NOTES" -Native types will be converted as required only if the value is exactly -representable by the target type or parameter. -Apart from that, the functions must be used appropriately for the -expected type of the parameter. -.PP -\&\fBOSSL_PARAM_get_BN()\fR and \fBOSSL_PARAM_set_BN()\fR only support nonnegative -\&\fB\s-1BIGNUM\s0\fRs when the desired data type is \fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR. -\&\fBOSSL_PARAM_construct_BN()\fR currently constructs an \s-1\fBOSSL_PARAM\s0\fR\|(3) structure -with the data type \fB\s-1OSSL_PARAM_UNSIGNED_INTEGER\s0\fR. -.PP -For \fBOSSL_PARAM_construct_utf8_ptr()\fR and \fBOSSL_PARAM_consstruct_octet_ptr()\fR, -\&\fIbsize\fR is not relevant if the purpose is to send the \s-1\fBOSSL_PARAM\s0\fR\|(3) array -to a \fIresponder\fR, i.e. to get parameter data back. -In that case, \fIbsize\fR can safely be given zero. -See \*(L"\s-1DESCRIPTION\*(R"\s0 in \s-1\fBOSSL_PARAM\s0\fR\|(3) for further information on the -possible purposes. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Reusing the examples from \s-1\fBOSSL_PARAM\s0\fR\|(3) to just show how -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) arrays can be handled using the macros and functions -defined herein. -.SS "Example 1" -.IX Subsection "Example 1" -This example is for setting parameters on some object: -.PP -.Vb 1 -\& #include -\& -\& const char *foo = "some string"; -\& size_t foo_l = strlen(foo); -\& const char bar[] = "some other string"; -\& const OSSL_PARAM set[] = { -\& OSSL_PARAM_utf8_ptr("foo", &foo, foo_l), -\& OSSL_PARAM_utf8_string("bar", bar, sizeof(bar) \- 1), -\& OSSL_PARAM_END -\& }; -.Ve -.SS "Example 2" -.IX Subsection "Example 2" -This example is for requesting parameters on some object, and also -demonstrates that the requester isn't obligated to request all -available parameters: -.PP -.Vb 7 -\& const char *foo = NULL; -\& char bar[1024]; -\& OSSL_PARAM request[] = { -\& OSSL_PARAM_utf8_ptr("foo", &foo, 0), -\& OSSL_PARAM_utf8_string("bar", bar, sizeof(bar)), -\& OSSL_PARAM_END -\& }; -.Ve -.PP -A \fIresponder\fR that receives this array (as \f(CW\*(C`params\*(C'\fR in this example) -could fill in the parameters like this: -.PP -.Vb 1 -\& /* OSSL_PARAM *params */ -\& -\& OSSL_PARAM *p; -\& -\& if ((p = OSSL_PARAM_locate(params, "foo")) != NULL) -\& OSSL_PARAM_set_utf8_ptr(p, "foo value"); -\& if ((p = OSSL_PARAM_locate(params, "bar")) != NULL) -\& OSSL_PARAM_set_utf8_string(p, "bar value"); -\& if ((p = OSSL_PARAM_locate(params, "cookie")) != NULL) -\& OSSL_PARAM_set_utf8_ptr(p, "cookie value"); -.Ve -.SS "Example 3" -.IX Subsection "Example 3" -This example shows a special case where -\&\fI\-Wincompatible\-pointer\-types\-discards\-qualifiers\fR may be set during -compilation. The value for \fIbuf\fR cannot be a \fIconst char *\fR type string. An -alternative in this case would be to use \fB\s-1OSSL_PARAM\s0\fR macro abbreviated calls -rather than the specific callers which allows you to define the sha1 argument -as a standard character array (\fIchar[]\fR). -.PP -For example, this code: -.PP -.Vb 3 -\& OSSL_PARAM params[2]; -\& params[0] = OSSL_PARAM_construct_utf8_string("digest", "SHA1", 0); -\& params[1] = OSSL_PARAM_construct_end(); -.Ve -.PP -Can be made compatible with the following version: -.PP -.Vb 2 -\& char sha1[] = "SHA1"; /* sha1 is defined as char[] in this case */ -\& OSSL_PARAM params[2]; -\& -\& params[0] = OSSL_PARAM_construct_utf8_string("digest", sha1, 0); -\& params[1] = OSSL_PARAM_construct_end(); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core.h\fR\|(7), \s-1\fBOSSL_PARAM\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These APIs were introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_PARAM_int32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_int32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_int32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_int64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_int64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_locate.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_locate.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_locate.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_locate_const.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_locate_const.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_locate_const.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_long.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_long.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_merge.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_merge.3ossl deleted file mode 120000 index f89285ed..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_merge.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_modified.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_modified.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_modified.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_octet_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_octet_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_octet_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_octet_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_octet_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_octet_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_BN.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_BN.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_all_unmodified.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_all_unmodified.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_all_unmodified.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_double.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_double.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_double.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_int.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_int.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_int.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_int32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_int32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_int32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_int64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_int64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_int64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_long.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_long.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_octet_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_octet_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_octet_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_octet_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_octet_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_octet_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_size_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_size_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_size_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_time_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_time_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_time_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_uint.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_uint.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_uint32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_uint32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_uint32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_uint64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_uint64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_ulong.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_ulong.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_ulong.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_utf8_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_utf8_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_utf8_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_set_utf8_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_set_utf8_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_set_utf8_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_size_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_size_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_size_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_time_t.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_time_t.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_time_t.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_uint.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_uint.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_uint32.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_uint32.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_uint32.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_uint64.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_uint64.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_uint64.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_ulong.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_ulong.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_ulong.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_utf8_ptr.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_utf8_ptr.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_utf8_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PARAM_utf8_string.3ossl b/openssl-install/share/man/man3/OSSL_PARAM_utf8_string.3ossl deleted file mode 120000 index 94177bf6..00000000 --- a/openssl-install/share/man/man3/OSSL_PARAM_utf8_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PARAM_int.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PASSPHRASE_CALLBACK.3ossl b/openssl-install/share/man/man3/OSSL_PASSPHRASE_CALLBACK.3ossl deleted file mode 120000 index cdc757bd..00000000 --- a/openssl-install/share/man/man3/OSSL_PASSPHRASE_CALLBACK.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CALLBACK.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER.3ossl deleted file mode 100644 index 3518f0f5..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER.3ossl +++ /dev/null @@ -1,380 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PROVIDER 3ossl" -.TH OSSL_PROVIDER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PROVIDER_set_default_search_path, -OSSL_PROVIDER_get0_default_search_path, -OSSL_PROVIDER, OSSL_PROVIDER_load, OSSL_PROVIDER_try_load, OSSL_PROVIDER_unload, -OSSL_PROVIDER_load_ex, OSSL_PROVIDER_try_load_ex, -OSSL_PROVIDER_available, OSSL_PROVIDER_do_all, -OSSL_PROVIDER_gettable_params, OSSL_PROVIDER_get_params, -OSSL_PROVIDER_query_operation, OSSL_PROVIDER_unquery_operation, -OSSL_PROVIDER_get0_provider_ctx, OSSL_PROVIDER_get0_dispatch, -OSSL_PROVIDER_add_builtin, OSSL_PROVIDER_get0_name, OSSL_PROVIDER_get_capabilities, -OSSL_PROVIDER_self_test -\&\- provider routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_provider_st OSSL_PROVIDER; -\& -\& int OSSL_PROVIDER_set_default_search_path(OSSL_LIB_CTX *libctx, -\& const char *path); -\& const char *OSSL_PROVIDER_get0_default_search_path(OSSL_LIB_CTX *libctx); -\& -\& OSSL_PROVIDER *OSSL_PROVIDER_load(OSSL_LIB_CTX *libctx, const char *name); -\& OSSL_PROVIDER *OSSL_PROVIDER_load_ex(OSSL_LIB_CTX *, const char *name, -\& OSSL_PARAM *params); -\& OSSL_PROVIDER *OSSL_PROVIDER_try_load(OSSL_LIB_CTX *libctx, const char *name, -\& int retain_fallbacks); -\& OSSL_PROVIDER *OSSL_PROVIDER_try_load_ex(OSSL_LIB_CTX *, const char *name, -\& OSSL_PARAM *params, -\& int retain_fallbacks); -\& int OSSL_PROVIDER_unload(OSSL_PROVIDER *prov); -\& int OSSL_PROVIDER_available(OSSL_LIB_CTX *libctx, const char *name); -\& int OSSL_PROVIDER_do_all(OSSL_LIB_CTX *ctx, -\& int (*cb)(OSSL_PROVIDER *provider, void *cbdata), -\& void *cbdata); -\& -\& const OSSL_PARAM *OSSL_PROVIDER_gettable_params(OSSL_PROVIDER *prov); -\& int OSSL_PROVIDER_get_params(OSSL_PROVIDER *prov, OSSL_PARAM params[]); -\& -\& const OSSL_ALGORITHM *OSSL_PROVIDER_query_operation(const OSSL_PROVIDER *prov, -\& int operation_id, -\& int *no_cache); -\& void OSSL_PROVIDER_unquery_operation(const OSSL_PROVIDER *prov, -\& int operation_id, -\& const OSSL_ALGORITHM *algs); -\& void *OSSL_PROVIDER_get0_provider_ctx(const OSSL_PROVIDER *prov); -\& const OSSL_DISPATCH *OSSL_PROVIDER_get0_dispatch(const OSSL_PROVIDER *prov); -\& -\& int OSSL_PROVIDER_add_builtin(OSSL_LIB_CTX *libctx, const char *name, -\& ossl_provider_init_fn *init_fn); -\& -\& const char *OSSL_PROVIDER_get0_name(const OSSL_PROVIDER *prov); -\& -\& int OSSL_PROVIDER_get_capabilities(const OSSL_PROVIDER *prov, -\& const char *capability, -\& OSSL_CALLBACK *cb, -\& void *arg); -\& int OSSL_PROVIDER_self_test(const OSSL_PROVIDER *prov); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_PROVIDER\s0\fR is a type that holds internal information about -implementation providers (see \fBprovider\fR\|(7) for information on what a -provider is). -A provider can be built in to the application or the OpenSSL -libraries, or can be a loadable module. -The functions described here handle both forms. -.PP -Some of these functions operate within a library context, please see -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3) for further details. -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_PROVIDER_set_default_search_path()\fR specifies the default search \fIpath\fR -that is to be used for looking for providers in the specified \fIlibctx\fR. -If left unspecified, an environment variable and a fall back default value will -be used instead. -.PP -\&\fBOSSL_PROVIDER_get0_default_search_path()\fR retrieves the default search \fIpath\fR -that is to be used for looking for providers in the specified \fIlibctx\fR. -If successful returns the path or empty string; the path is valid until the -context is released or \fBOSSL_PROVIDER_set_default_search_path()\fR is called. -.PP -\&\fBOSSL_PROVIDER_add_builtin()\fR is used to add a built in provider to -\&\fB\s-1OSSL_PROVIDER\s0\fR store in the given library context, by associating a -provider name with a provider initialization function. -This name can then be used with \fBOSSL_PROVIDER_load()\fR. -.PP -\&\fBOSSL_PROVIDER_load()\fR loads and initializes a provider. -This may simply initialize a provider that was previously added with -\&\fBOSSL_PROVIDER_add_builtin()\fR and run its given initialization function, -or load a provider module with the given name and run its provider -entry point, \f(CW\*(C`OSSL_provider_init\*(C'\fR. The \fIname\fR can be a path -to a provider module, in that case the provider name as returned -by \fBOSSL_PROVIDER_get0_name()\fR will be the path. Interpretation -of relative paths is platform dependent and they are relative -to the configured \*(L"\s-1MODULESDIR\*(R"\s0 directory or the path set in -the environment variable \s-1OPENSSL_MODULES\s0 if set. -.PP -\&\fBOSSL_PROVIDER_try_load()\fR functions like \fBOSSL_PROVIDER_load()\fR, except that -it does not disable the fallback providers if the provider cannot be -loaded and initialized or if \fIretain_fallbacks\fR is nonzero. -If the provider loads successfully and \fIretain_fallbacks\fR is zero, the -fallback providers are disabled. -.PP -\&\fBOSSL_PROVIDER_load_ex()\fR and \fBOSSL_PROVIDER_try_load_ex()\fR are the variants -of the previous functions accepting an \f(CW\*(C`OSSL_PARAM\*(C'\fR array of the parameters -that are passed as the configuration of the loaded provider. The parameters -of any type but \f(CW\*(C`OSSL_PARAM_UTF8_STRING\*(C'\fR are silently ignored. If the -parameters are provided, they replace \fBall\fR the ones specified in the -configuration file. -.PP -\&\fBOSSL_PROVIDER_unload()\fR unloads the given provider. -For a provider added with \fBOSSL_PROVIDER_add_builtin()\fR, this simply -runs its teardown function. -.PP -\&\fBOSSL_PROVIDER_available()\fR checks if a named provider is available -for use. -.PP -\&\fBOSSL_PROVIDER_do_all()\fR iterates over all loaded providers, calling -\&\fIcb\fR for each one, with the current provider in \fIprovider\fR and the -\&\fIcbdata\fR that comes from the caller. If no other provider has been loaded -before calling this function, the default provider is still available as -fallback. -See \fBOSSL_PROVIDER\-default\fR\|(7) for more information on this fallback -behaviour. -.PP -\&\fBOSSL_PROVIDER_gettable_params()\fR is used to get a provider parameter -descriptor set as a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array. -.PP -\&\fBOSSL_PROVIDER_get_params()\fR is used to get provider parameter values. -The caller must prepare the \s-1\fBOSSL_PARAM\s0\fR\|(3) array before calling this -function, and the variables acting as buffers for this parameter array -should be filled with data when it returns successfully. -.PP -\&\fBOSSL_PROVIDER_self_test()\fR is used to run a provider's self tests on demand. -If the self tests fail then the provider will fail to provide any further -services and algorithms. \fBOSSL_SELF_TEST_set_callback\fR\|(3) may be called -beforehand in order to display diagnostics for the running self tests. -.PP -\&\fBOSSL_PROVIDER_query_operation()\fR calls the provider's \fIquery_operation\fR -function (see \fBprovider\fR\|(7)), if the provider has one. It returns an -array of \fI\s-1OSSL_ALGORITHM\s0\fR for the given \fIoperation_id\fR terminated by an all -\&\s-1NULL OSSL_ALGORITHM\s0 entry. This is considered a low-level function that most -applications should not need to call. -.PP -\&\fBOSSL_PROVIDER_unquery_operation()\fR calls the provider's \fIunquery_operation\fR -function (see \fBprovider\fR\|(7)), if the provider has one. This is considered a -low-level function that most applications should not need to call. -.PP -\&\fBOSSL_PROVIDER_get0_provider_ctx()\fR returns the provider context for the given -provider. The provider context is an opaque handle set by the provider itself -and is passed back to the provider by libcrypto in various function calls. -.PP -\&\fBOSSL_PROVIDER_get0_dispatch()\fR returns the provider's dispatch table as it was -returned in the \fIout\fR parameter from the provider's init function. See -\&\fBprovider\-base\fR\|(7). -.PP -If it is permissible to cache references to this array then \fI*no_store\fR is set -to 0 or 1 otherwise. If the array is not cacheable then it is assumed to -have a short lifetime. -.PP -\&\fBOSSL_PROVIDER_get0_name()\fR returns the name of the given provider. -.PP -\&\fBOSSL_PROVIDER_get_capabilities()\fR provides information about the capabilities -supported by the provider specified in \fIprov\fR with the capability name -\&\fIcapability\fR. For each capability of that name supported by the provider it -will call the callback \fIcb\fR and supply a set of \s-1\fBOSSL_PARAM\s0\fR\|(3)s describing the -capability. It will also pass back the argument \fIarg\fR. For more details about -capabilities and what they can be used for please see -\&\*(L"\s-1CAPABILTIIES\*(R"\s0 in \fBprovider\-base\fR\|(7). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_PROVIDER_set_default_search_path()\fR, \fBOSSL_PROVIDER_add()\fR, -\&\fBOSSL_PROVIDER_unload()\fR, \fBOSSL_PROVIDER_get_params()\fR and -\&\fBOSSL_PROVIDER_get_capabilities()\fR return 1 on success, or 0 on error. -.PP -\&\fBOSSL_PROVIDER_get0_default_search_path()\fR returns a pointer to a path on success, -or \s-1NULL\s0 on error or if the path has not previously been set. -.PP -\&\fBOSSL_PROVIDER_load()\fR and \fBOSSL_PROVIDER_try_load()\fR return a pointer to a -provider object on success, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_PROVIDER_do_all()\fR returns 1 if the callback \fIcb\fR returns 1 for every -provider it is called with, or 0 if any provider callback invocation returns 0; -callback processing stops at the first callback invocation on a provider -that returns 0. -.PP -\&\fBOSSL_PROVIDER_available()\fR returns 1 if the named provider is available, -otherwise 0. -.PP -\&\fBOSSL_PROVIDER_gettable_params()\fR returns a pointer to an array -of constant \s-1\fBOSSL_PARAM\s0\fR\|(3), or \s-1NULL\s0 if none is provided. -.PP -\&\fBOSSL_PROVIDER_get_params()\fR and returns 1 on success, or 0 on error. -.PP -\&\fBOSSL_PROVIDER_query_operation()\fR returns an array of \s-1OSSL_ALGORITHM\s0 or \s-1NULL\s0 on -error. -.PP -\&\fBOSSL_PROVIDER_self_test()\fR returns 1 if the self tests pass, or 0 on error. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This demonstrates how to load the provider module \*(L"foo\*(R" and ask for -its build information. -.PP -.Vb 3 -\& #include -\& #include -\& #include -\& -\& OSSL_PROVIDER *prov = NULL; -\& const char *build = NULL; -\& OSSL_PARAM request[] = { -\& { "buildinfo", OSSL_PARAM_UTF8_PTR, &build, 0, 0 }, -\& { NULL, 0, NULL, 0, 0 } -\& }; -\& -\& if ((prov = OSSL_PROVIDER_load(NULL, "foo")) != NULL -\& && OSSL_PROVIDER_get_params(prov, request)) -\& printf("Provider \*(Aqfoo\*(Aq buildinfo: %s\en", build); -\& else -\& ERR_print_errors_fp(stderr); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core.h\fR\|(7), \s-1\fBOSSL_LIB_CTX\s0\fR\|(3), \fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The type and functions described here were added in OpenSSL 3.0. -.PP -The \fIOSSL_PROVIDER_load_ex\fR and \fIOSSL_PROVIDER_try_load_ex\fR functions were -added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_add_builtin.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_add_builtin.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_add_builtin.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_available.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_available.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_available.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_do_all.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_do_all.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_default_search_path.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_get0_default_search_path.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_default_search_path.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_dispatch.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_get0_dispatch.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_dispatch.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_name.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_get0_name.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_provider_ctx.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_get0_provider_ctx.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_get0_provider_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_get_capabilities.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_get_capabilities.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_get_capabilities.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_get_params.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_get_params.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_get_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_gettable_params.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_gettable_params.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_gettable_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_load.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_load.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_load_ex.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_load_ex.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_load_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_query_operation.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_query_operation.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_query_operation.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_self_test.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_self_test.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_self_test.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_set_default_search_path.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_set_default_search_path.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_set_default_search_path.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_try_load.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_try_load.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_try_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_try_load_ex.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_try_load_ex.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_try_load_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_unload.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_unload.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_unload.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_PROVIDER_unquery_operation.3ossl b/openssl-install/share/man/man3/OSSL_PROVIDER_unquery_operation.3ossl deleted file mode 120000 index 02699843..00000000 --- a/openssl-install/share/man/man3/OSSL_PROVIDER_unquery_operation.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_PROVIDER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_AEAD_LIMIT_REACHED.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_AEAD_LIMIT_REACHED.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_AEAD_LIMIT_REACHED.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_APPLICATION_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_APPLICATION_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_APPLICATION_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_REFUSED.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_REFUSED.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CONNECTION_REFUSED.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_END.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_END.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_CRYPTO_ERR_END.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_FINAL_SIZE_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_FINAL_SIZE_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_FINAL_SIZE_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_FLOW_CONTROL_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_FLOW_CONTROL_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_FLOW_CONTROL_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_FRAME_ENCODING_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_FRAME_ENCODING_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_FRAME_ENCODING_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_INTERNAL_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_INTERNAL_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_INTERNAL_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_INVALID_TOKEN.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_INVALID_TOKEN.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_INVALID_TOKEN.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_KEY_UPDATE_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_KEY_UPDATE_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_KEY_UPDATE_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_VIABLE_PATH.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_VIABLE_PATH.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_NO_VIABLE_PATH.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_PROTOCOL_VIOLATION.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_PROTOCOL_VIOLATION.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_PROTOCOL_VIOLATION.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_LIMIT_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_LIMIT_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_LIMIT_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_STATE_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_STATE_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_STREAM_STATE_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_QUIC_client_method.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_client_method.3ossl deleted file mode 100644 index d56e80f5..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_client_method.3ossl +++ /dev/null @@ -1,181 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_QUIC_CLIENT_METHOD 3ossl" -.TH OSSL_QUIC_CLIENT_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_QUIC_client_method, OSSL_QUIC_client_thread_method -\&\- Provide SSL_METHOD objects for QUIC enabled functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const SSL_METHOD *OSSL_QUIC_client_method(void); -\& const SSL_METHOD *OSSL_QUIC_client_thread_method(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBOSSL_QUIC_client_method()\fR, \fBOSSL_QUIC_client_thread_method()\fR, and -\&\fBOSSL_QUIC_server_method()\fR functions provide methods for the -\&\fBSSL_CTX_new_ex\fR\|(3) function to provide \s-1QUIC\s0 protocol support. -.PP -The \fBOSSL_QUIC_client_thread_method()\fR uses threads to allow for a blocking -mode of operation and avoid the need to return control to the -OpenSSL library for processing time based events. -The \fBOSSL_QUIC_client_method()\fR does not use threads and depends on -nonblocking mode of operation and the application periodically calling \s-1SSL\s0 -functions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return pointers to the constant method objects. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_new_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_QUIC_client_method()\fR and \fBOSSL_QUIC_client_thread_method()\fR were added in -OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_QUIC_client_thread_method.3ossl b/openssl-install/share/man/man3/OSSL_QUIC_client_thread_method.3ossl deleted file mode 120000 index f156d86a..00000000 --- a/openssl-install/share/man/man3/OSSL_QUIC_client_thread_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_QUIC_client_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_SELF_TEST_free.3ossl b/openssl-install/share/man/man3/OSSL_SELF_TEST_free.3ossl deleted file mode 120000 index 95ba1ec9..00000000 --- a/openssl-install/share/man/man3/OSSL_SELF_TEST_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_SELF_TEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_SELF_TEST_get_callback.3ossl b/openssl-install/share/man/man3/OSSL_SELF_TEST_get_callback.3ossl deleted file mode 120000 index 3a14476d..00000000 --- a/openssl-install/share/man/man3/OSSL_SELF_TEST_get_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_SELF_TEST_set_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_SELF_TEST_new.3ossl b/openssl-install/share/man/man3/OSSL_SELF_TEST_new.3ossl deleted file mode 100644 index 32d506f8..00000000 --- a/openssl-install/share/man/man3/OSSL_SELF_TEST_new.3ossl +++ /dev/null @@ -1,292 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_SELF_TEST_NEW 3ossl" -.TH OSSL_SELF_TEST_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_SELF_TEST_new, -OSSL_SELF_TEST_free, -OSSL_SELF_TEST_onbegin, -OSSL_SELF_TEST_oncorrupt_byte, -OSSL_SELF_TEST_onend \- functionality to trigger a callback during a self test -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_SELF_TEST *OSSL_SELF_TEST_new(OSSL_CALLBACK *cb, void *cbarg); -\& void OSSL_SELF_TEST_free(OSSL_SELF_TEST *st); -\& -\& void OSSL_SELF_TEST_onbegin(OSSL_SELF_TEST *st, const char *type, -\& const char *desc); -\& int OSSL_SELF_TEST_oncorrupt_byte(OSSL_SELF_TEST *st, unsigned char *bytes); -\& void OSSL_SELF_TEST_onend(OSSL_SELF_TEST *st, int ret); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These methods are intended for use by provider implementers, to display -diagnostic information during self testing. -.PP -\&\fBOSSL_SELF_TEST_new()\fR allocates an opaque \fB\s-1OSSL_SELF_TEST\s0\fR object that has a -callback and callback argument associated with it. -.PP -The callback \fIcb\fR may be triggered multiple times by a self test to indicate -different phases. -.PP -\&\fBOSSL_SELF_TEST_free()\fR frees the space allocated by \fBOSSL_SELF_TEST_new()\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_SELF_TEST_onbegin()\fR may be inserted at the start of a block of self test -code. It can be used for diagnostic purposes. -If this method is called the callback \fIcb\fR will receive the following -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) object. -.ie n .IP """st-phase"" (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_PHASE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``st-phase'' (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_PHASE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "st-phase (OSSL_PROV_PARAM_SELF_TEST_PHASE) " -The value is the string \*(L"Start\*(R" -.PP -\&\fBOSSL_SELF_TEST_oncorrupt_byte()\fR may be inserted just after the known answer is -calculated, but before the self test compares the result. The first byte in the -passed in array of \fIbytes\fR will be corrupted if the callback returns 0, -otherwise it leaves the array unaltered. It can be used for failure testing. -The \fItype\fR and \fIdesc\fR can be used to identify an individual self test to -target for failure testing. -If this method is called the callback \fIcb\fR will receive the following -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) object. -.ie n .IP """st-phase"" (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_PHASE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``st-phase'' (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_PHASE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "st-phase (OSSL_PROV_PARAM_SELF_TEST_PHASE) " -The value is the string \*(L"Corrupt\*(R" -.PP -\&\fBOSSL_SELF_TEST_onend()\fR may be inserted at the end of a block of self test code -just before cleanup to indicate if the test passed or failed. It can be used for -diagnostic purposes. -If this method is called the callback \fIcb\fR will receive the following -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) object. -.ie n .IP """st-phase"" (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_PHASE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``st-phase'' (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_PHASE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "st-phase (OSSL_PROV_PARAM_SELF_TEST_PHASE) " -The value of the string is \*(L"Pass\*(R" if \fIret\fR is non zero, otherwise it has the -value \*(L"Fail\*(R". -.PP -After the callback \fIcb\fR has been called the values that were set by -\&\fBOSSL_SELF_TEST_onbegin()\fR for \fItype\fR and \fIdesc\fR are set to the value \*(L"None\*(R". -.PP -If \fBOSSL_SELF_TEST_onbegin()\fR, \fBOSSL_SELF_TEST_oncorrupt_byte()\fR or -\&\fBOSSL_SELF_TEST_onend()\fR is called the following additional \s-1\fBOSSL_PARAM\s0\fR\|(3) are -passed to the callback. -.ie n .IP """st-type"" (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``st-type'' (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "st-type (OSSL_PROV_PARAM_SELF_TEST_TYPE) " -The value is setup by the \fItype\fR passed to \fBOSSL_SELF_TEST_onbegin()\fR. -This allows the callback to identify the type of test being run. -.ie n .IP """st-desc"" (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_DESC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``st-desc'' (\fB\s-1OSSL_PROV_PARAM_SELF_TEST_DESC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "st-desc (OSSL_PROV_PARAM_SELF_TEST_DESC) " -The value is setup by the \fItype\fR passed to \fBOSSL_SELF_TEST_onbegin()\fR. -This allows the callback to identify the sub category of the test being run. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_SELF_TEST_new()\fR returns the allocated \fB\s-1OSSL_SELF_TEST\s0\fR object, or \s-1NULL\s0 if -it fails. -.PP -\&\fBOSSL_SELF_TEST_oncorrupt_byte()\fR returns 1 if corruption occurs, otherwise it -returns 0. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -A single self test could be set up in the following way: -.PP -.Vb 8 -\& OSSL_SELF_TEST *st = NULL; -\& OSSL_CALLBACK *cb; -\& void *cbarg; -\& int ok = 0; -\& unsigned char out[EVP_MAX_MD_SIZE]; -\& unsigned int out_len = 0; -\& EVP_MD_CTX *ctx = EVP_MD_CTX_new(); -\& EVP_MD *md = EVP_MD_fetch(libctx, t\->algorithm, NULL); -\& -\& /* -\& * Retrieve the callback \- will be NULL if not set by the application via -\& * OSSL_SELF_TEST_set_callback(). -\& */ -\& OSSL_SELF_TEST_get_callback(libctx, &cb, &cbarg); -\& -\& st = OSSL_SELF_TEST_new(cb, cb_arg); -\& -\& /* Trigger the optional callback */ -\& OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_DIGEST, -\& OSSL_SELF_TEST_DESC_MD_SHA2); -\& -\& if (!EVP_DigestInit_ex(ctx, md, NULL) -\& || !EVP_DigestUpdate(ctx, pt, pt_len) -\& || !EVP_DigestFinal(ctx, out, &out_len)) -\& goto err; -\& -\& /* Optional corruption \- If the application callback returns 0 */ -\& OSSL_SELF_TEST_oncorrupt_byte(st, out); -\& -\& if (out_len != t\->expected_len -\& || memcmp(out, t\->expected, out_len) != 0) -\& goto err; -\& ok = 1; -\& err: -\& OSSL_SELF_TEST_onend(st, ok); -\& EVP_MD_free(md); -\& EVP_MD_CTX_free(ctx); -.Ve -.PP -Multiple self test's can be set up in a similar way by repeating the pattern of -\&\fBOSSL_SELF_TEST_onbegin()\fR, \fBOSSL_SELF_TEST_oncorrupt_byte()\fR, \fBOSSL_SELF_TEST_onend()\fR -for each test. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_SELF_TEST_set_callback\fR\|(3), -\&\fBopenssl\-core.h\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_SELF_TEST_onbegin.3ossl b/openssl-install/share/man/man3/OSSL_SELF_TEST_onbegin.3ossl deleted file mode 120000 index 95ba1ec9..00000000 --- a/openssl-install/share/man/man3/OSSL_SELF_TEST_onbegin.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_SELF_TEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_SELF_TEST_oncorrupt_byte.3ossl b/openssl-install/share/man/man3/OSSL_SELF_TEST_oncorrupt_byte.3ossl deleted file mode 120000 index 95ba1ec9..00000000 --- a/openssl-install/share/man/man3/OSSL_SELF_TEST_oncorrupt_byte.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_SELF_TEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_SELF_TEST_onend.3ossl b/openssl-install/share/man/man3/OSSL_SELF_TEST_onend.3ossl deleted file mode 120000 index 95ba1ec9..00000000 --- a/openssl-install/share/man/man3/OSSL_SELF_TEST_onend.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_SELF_TEST_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_SELF_TEST_set_callback.3ossl b/openssl-install/share/man/man3/OSSL_SELF_TEST_set_callback.3ossl deleted file mode 100644 index fe577a94..00000000 --- a/openssl-install/share/man/man3/OSSL_SELF_TEST_set_callback.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_SELF_TEST_SET_CALLBACK 3ossl" -.TH OSSL_SELF_TEST_SET_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_SELF_TEST_set_callback, -OSSL_SELF_TEST_get_callback \- specify a callback for processing self tests -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void OSSL_SELF_TEST_set_callback(OSSL_LIB_CTX *ctx, OSSL_CALLBACK *cb, void *cbarg); -\& void OSSL_SELF_TEST_get_callback(OSSL_LIB_CTX *ctx, OSSL_CALLBACK **cb, void **cbarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Set or gets the optional application callback (and the callback argument) that -is called during self testing. -The application callback \s-1\fBOSSL_CALLBACK\s0\fR\|(3) is associated with a \fB\s-1OSSL_LIB_CTX\s0\fR. -The application callback function receives information about a running self test, -and may return a result to the calling self test. -See \fBopenssl\-core.h\fR\|(7) for further information on the callback. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_SELF_TEST_get_callback()\fR returns the callback and callback argument that -has been set via \fBOSSL_SELF_TEST_set_callback()\fR for the given library context -\&\fIctx\fR. -These returned parameters will be \s-1NULL\s0 if \fBOSSL_SELF_TEST_set_callback()\fR has -not been called. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core.h\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -\&\fBOSSL_SELF_TEST_new\fR\|(3) -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_STACK_OF_X509_free.3ossl b/openssl-install/share/man/man3/OSSL_STACK_OF_X509_free.3ossl deleted file mode 120000 index 43cc5a14..00000000 --- a/openssl-install/share/man/man3/OSSL_STACK_OF_X509_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_CTX.3ossl b/openssl-install/share/man/man3/OSSL_STORE_CTX.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_CTX.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO.3ossl deleted file mode 100644 index 37858d7d..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO.3ossl +++ /dev/null @@ -1,350 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE_INFO 3ossl" -.TH OSSL_STORE_INFO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_STORE_INFO, OSSL_STORE_INFO_get_type, OSSL_STORE_INFO_get0_NAME, -OSSL_STORE_INFO_get0_NAME_description, -OSSL_STORE_INFO_get0_PARAMS, OSSL_STORE_INFO_get0_PUBKEY, -OSSL_STORE_INFO_get0_PKEY, OSSL_STORE_INFO_get0_CERT, OSSL_STORE_INFO_get0_CRL, -OSSL_STORE_INFO_get1_NAME, OSSL_STORE_INFO_get1_NAME_description, -OSSL_STORE_INFO_get1_PARAMS, OSSL_STORE_INFO_get1_PUBKEY, -OSSL_STORE_INFO_get1_PKEY, OSSL_STORE_INFO_get1_CERT, OSSL_STORE_INFO_get1_CRL, -OSSL_STORE_INFO_type_string, OSSL_STORE_INFO_free, -OSSL_STORE_INFO_new_NAME, OSSL_STORE_INFO_set0_NAME_description, -OSSL_STORE_INFO_new_PARAMS, OSSL_STORE_INFO_new_PUBKEY, -OSSL_STORE_INFO_new_PKEY, OSSL_STORE_INFO_new_CERT, OSSL_STORE_INFO_new_CRL, -OSSL_STORE_INFO_new, OSSL_STORE_INFO_get0_data -\&\- Functions to manipulate OSSL_STORE_INFO objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_store_info_st OSSL_STORE_INFO; -\& -\& int OSSL_STORE_INFO_get_type(const OSSL_STORE_INFO *store_info); -\& const char *OSSL_STORE_INFO_get0_NAME(const OSSL_STORE_INFO *store_info); -\& char *OSSL_STORE_INFO_get1_NAME(const OSSL_STORE_INFO *store_info); -\& const char *OSSL_STORE_INFO_get0_NAME_description(const OSSL_STORE_INFO -\& *store_info); -\& char *OSSL_STORE_INFO_get1_NAME_description(const OSSL_STORE_INFO *store_info); -\& EVP_PKEY *OSSL_STORE_INFO_get0_PARAMS(const OSSL_STORE_INFO *store_info); -\& EVP_PKEY *OSSL_STORE_INFO_get1_PARAMS(const OSSL_STORE_INFO *store_info); -\& EVP_PKEY *OSSL_STORE_INFO_get0_PUBKEY(const OSSL_STORE_INFO *info); -\& EVP_PKEY *OSSL_STORE_INFO_get1_PUBKEY(const OSSL_STORE_INFO *info); -\& EVP_PKEY *OSSL_STORE_INFO_get0_PKEY(const OSSL_STORE_INFO *store_info); -\& EVP_PKEY *OSSL_STORE_INFO_get1_PKEY(const OSSL_STORE_INFO *store_info); -\& X509 *OSSL_STORE_INFO_get0_CERT(const OSSL_STORE_INFO *store_info); -\& X509 *OSSL_STORE_INFO_get1_CERT(const OSSL_STORE_INFO *store_info); -\& X509_CRL *OSSL_STORE_INFO_get0_CRL(const OSSL_STORE_INFO *store_info); -\& X509_CRL *OSSL_STORE_INFO_get1_CRL(const OSSL_STORE_INFO *store_info); -\& -\& const char *OSSL_STORE_INFO_type_string(int type); -\& -\& void OSSL_STORE_INFO_free(OSSL_STORE_INFO *store_info); -\& -\& OSSL_STORE_INFO *OSSL_STORE_INFO_new_NAME(char *name); -\& int OSSL_STORE_INFO_set0_NAME_description(OSSL_STORE_INFO *info, char *desc); -\& OSSL_STORE_INFO *OSSL_STORE_INFO_new_PARAMS(DSA *dsa_params); -\& OSSL_STORE_INFO *OSSL_STORE_INFO_new_PUBKEY(EVP_PKEY *pubkey); -\& OSSL_STORE_INFO *OSSL_STORE_INFO_new_PKEY(EVP_PKEY *pkey); -\& OSSL_STORE_INFO *OSSL_STORE_INFO_new_CERT(X509 *x509); -\& OSSL_STORE_INFO *OSSL_STORE_INFO_new_CRL(X509_CRL *crl); -\& -\& OSSL_STORE_INFO *OSSL_STORE_INFO_new(int type, void *data); -\& void *OSSL_STORE_INFO_get0_data(int type, const OSSL_STORE_INFO *info); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are primarily useful for applications to retrieve -supported objects from \fB\s-1OSSL_STORE_INFO\s0\fR objects and for scheme specific -loaders to create \fB\s-1OSSL_STORE_INFO\s0\fR holders. -.SS "Types" -.IX Subsection "Types" -\&\fB\s-1OSSL_STORE_INFO\s0\fR is an opaque type that's just an intermediary holder for -the objects that have been retrieved by \fBOSSL_STORE_load()\fR and similar functions. -Supported OpenSSL type object can be extracted using one of -STORE_INFO_get0_<\s-1TYPE\s0>() where <\s-1TYPE\s0> can be \s-1NAME, PARAMS, PKEY, CERT,\s0 or \s-1CRL.\s0 -The life time of this extracted object is as long as the life time of -the \fB\s-1OSSL_STORE_INFO\s0\fR it was extracted from, so care should be taken not -to free the latter too early. -As an alternative, STORE_INFO_get1_<\s-1TYPE\s0>() extracts a duplicate (or the -same object with its reference count increased), which can be used -after the containing \fB\s-1OSSL_STORE_INFO\s0\fR has been freed. -The object returned by STORE_INFO_get1_<\s-1TYPE\s0>() must be freed separately -by the caller. -See \*(L"\s-1SUPPORTED OBJECTS\*(R"\s0 for more information on the types that are supported. -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_STORE_INFO_get_type()\fR takes a \fB\s-1OSSL_STORE_INFO\s0\fR and returns the \s-1STORE\s0 -type number for the object inside. -.PP -\&\fBSTORE_INFO_get_type_string()\fR takes a \s-1STORE\s0 type number and returns a -short string describing it. -.PP -\&\fBOSSL_STORE_INFO_get0_NAME()\fR, \fBOSSL_STORE_INFO_get0_NAME_description()\fR, -\&\fBOSSL_STORE_INFO_get0_PARAMS()\fR, \fBOSSL_STORE_INFO_get0_PUBKEY()\fR, -\&\fBOSSL_STORE_INFO_get0_PKEY()\fR, \fBOSSL_STORE_INFO_get0_CERT()\fR, -\&\fBOSSL_STORE_INFO_get0_CRL()\fR -all take a \fB\s-1OSSL_STORE_INFO\s0\fR and return the object it holds if the -\&\fB\s-1OSSL_STORE_INFO\s0\fR type (as returned by \fBOSSL_STORE_INFO_get_type()\fR) -matches the function, otherwise \s-1NULL.\s0 -.PP -\&\fBOSSL_STORE_INFO_get1_NAME()\fR, \fBOSSL_STORE_INFO_get1_NAME_description()\fR, -\&\fBOSSL_STORE_INFO_get1_PARAMS()\fR, \fBOSSL_STORE_INFO_get1_PUBKEY()\fR, -\&\fBOSSL_STORE_INFO_get1_PKEY()\fR, \fBOSSL_STORE_INFO_get1_CERT()\fR and -\&\fBOSSL_STORE_INFO_get1_CRL()\fR -all take a \fB\s-1OSSL_STORE_INFO\s0\fR and return a duplicate the object it -holds if the \fB\s-1OSSL_STORE_INFO\s0\fR type (as returned by -\&\fBOSSL_STORE_INFO_get_type()\fR) matches the function, otherwise \s-1NULL.\s0 -.PP -\&\fBOSSL_STORE_INFO_free()\fR frees a \fB\s-1OSSL_STORE_INFO\s0\fR and its contained type. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_STORE_INFO_new_NAME()\fR , \fBOSSL_STORE_INFO_new_PARAMS()\fR, -, \fBOSSL_STORE_INFO_new_PUBKEY()\fR, \fBOSSL_STORE_INFO_new_PKEY()\fR, -\&\fBOSSL_STORE_INFO_new_CERT()\fR and \fBOSSL_STORE_INFO_new_CRL()\fR -create a \fB\s-1OSSL_STORE_INFO\s0\fR object to hold the given input object. -On success the input object is consumed. -.PP -Additionally, for \fB\s-1OSSL_STORE_INFO_NAME\s0\fR objects, -\&\fBOSSL_STORE_INFO_set0_NAME_description()\fR can be used to add an extra -description. -This description is meant to be human readable and should be used for -information printout. -.PP -\&\fBOSSL_STORE_INFO_new()\fR creates a \fB\s-1OSSL_STORE_INFO\s0\fR with an arbitrary \fItype\fR -number and \fIdata\fR structure. It's the responsibility of the caller to -define type numbers other than the ones defined by \fI\fR, -and to handle freeing the associated data structure on their own. -\&\fIUsing type numbers that are defined by \fI\fI may cause -undefined behaviours, including crashes\fR. -.PP -\&\fBOSSL_STORE_INFO_get0_data()\fR returns the data pointer that was passed to -\&\fBOSSL_STORE_INFO_new()\fR if \fItype\fR matches the type number in \fIinfo\fR. -.PP -\&\fBOSSL_STORE_INFO_new()\fR and \fBOSSL_STORE_INFO_get0_data()\fR may be useful for -applications that define their own \s-1STORE\s0 data, but must be used with care. -.SH "SUPPORTED OBJECTS" -.IX Header "SUPPORTED OBJECTS" -Currently supported object types are: -.IP "\s-1OSSL_STORE_INFO_NAME\s0" 4 -.IX Item "OSSL_STORE_INFO_NAME" -A name is exactly that, a name. -It's like a name in a directory, but formatted as a complete \s-1URI.\s0 -For example, the path in \s-1URI\s0 \f(CW\*(C`file:/foo/bar/\*(C'\fR could include a file -named \f(CW\*(C`cookie.pem\*(C'\fR, and in that case, the returned \fB\s-1OSSL_STORE_INFO_NAME\s0\fR -object would have the \s-1URI\s0 \f(CW\*(C`file:/foo/bar/cookie.pem\*(C'\fR, which can be -used by the application to get the objects in that file. -This can be applied to all schemes that can somehow support a listing -of object URIs. -.Sp -For \f(CW\*(C`file:\*(C'\fR URIs that are used without the explicit scheme, the -returned name will be the path of each object, so if \f(CW\*(C`/foo/bar\*(C'\fR was -given and that path has the file \f(CW\*(C`cookie.pem\*(C'\fR, the name -\&\f(CW\*(C`/foo/bar/cookie.pem\*(C'\fR will be returned. -.Sp -The returned \s-1URI\s0 is considered canonical and must be unique and permanent -for the storage where the object (or collection of objects) resides. -Each loader is responsible for ensuring that it only returns canonical -URIs. -However, it's possible that certain schemes allow an object (or collection -thereof) to be reached with alternative URIs; just because one \s-1URI\s0 is -canonical doesn't mean that other variants can't be used. -.Sp -At the discretion of the loader that was used to get these names, an -extra description may be attached as well. -.IP "\s-1OSSL_STORE_INFO_PARAMS\s0" 4 -.IX Item "OSSL_STORE_INFO_PARAMS" -Key parameters. -.IP "\s-1OSSL_STORE_INFO_PKEY\s0" 4 -.IX Item "OSSL_STORE_INFO_PKEY" -A keypair or just a private key (possibly with key parameters). -.IP "\s-1OSSL_STORE_INFO_PUBKEY\s0" 4 -.IX Item "OSSL_STORE_INFO_PUBKEY" -A public key (possibly with key parameters). -.IP "\s-1OSSL_STORE_INFO_CERT\s0" 4 -.IX Item "OSSL_STORE_INFO_CERT" -An X.509 certificate. -.IP "\s-1OSSL_STORE_INFO_CRL\s0" 4 -.IX Item "OSSL_STORE_INFO_CRL" -A X.509 certificate revocation list. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_STORE_INFO_get_type()\fR returns the \s-1STORE\s0 type number of the given -\&\fB\s-1OSSL_STORE_INFO\s0\fR. -There is no error value. -.PP -\&\fBOSSL_STORE_INFO_get0_NAME()\fR, \fBOSSL_STORE_INFO_get0_NAME_description()\fR, -\&\fBOSSL_STORE_INFO_get0_PARAMS()\fR, \fBOSSL_STORE_INFO_get0_PKEY()\fR, -\&\fBOSSL_STORE_INFO_get0_CERT()\fR and \fBOSSL_STORE_INFO_get0_CRL()\fR all return -a pointer to the OpenSSL object on success, \s-1NULL\s0 otherwise. -.PP -\&\fBOSSL_STORE_INFO_get1_NAME()\fR, \fBOSSL_STORE_INFO_get1_NAME_description()\fR, -\&\fBOSSL_STORE_INFO_get1_PARAMS()\fR, \fBOSSL_STORE_INFO_get1_PKEY()\fR, -\&\fBOSSL_STORE_INFO_get1_CERT()\fR and \fBOSSL_STORE_INFO_get1_CRL()\fR all return -a pointer to a duplicate of the OpenSSL object on success, \s-1NULL\s0 otherwise. -.PP -\&\fBOSSL_STORE_INFO_type_string()\fR returns a string on success, or \s-1NULL\s0 on -failure. -.PP -\&\fBOSSL_STORE_INFO_new_NAME()\fR, \fBOSSL_STORE_INFO_new_PARAMS()\fR, -\&\fBOSSL_STORE_INFO_new_PKEY()\fR, \fBOSSL_STORE_INFO_new_CERT()\fR and -\&\fBOSSL_STORE_INFO_new_CRL()\fR return a \fB\s-1OSSL_STORE_INFO\s0\fR -pointer on success, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_STORE_INFO_set0_NAME_description()\fR returns 1 on success, or 0 on -failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \fBOSSL_STORE_open\fR\|(3), \fBOSSL_STORE_register_loader\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1OSSL_STORE API\s0 was added in OpenSSL 1.1.1. -.PP -The \s-1OSSL_STORE_INFO_PUBKEY\s0 object type was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_free.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_free.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CERT.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CERT.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CRL.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CRL.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME_description.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME_description.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_NAME_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PARAMS.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PARAMS.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PKEY.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PKEY.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PUBKEY.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PUBKEY.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_data.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_data.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get0_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CERT.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CERT.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CRL.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CRL.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME_description.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME_description.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_NAME_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PARAMS.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PARAMS.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PKEY.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PKEY.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PUBKEY.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PUBKEY.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get1_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_get_type.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_get_type.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_new.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_new.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_CERT.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_new_CERT.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_CERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_CRL.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_new_CRL.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_NAME.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_new_NAME.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PARAMS.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PARAMS.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PKEY.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PKEY.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PUBKEY.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PUBKEY.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_new_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_set0_NAME_description.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_set0_NAME_description.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_set0_NAME_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_INFO_type_string.3ossl b/openssl-install/share/man/man3/OSSL_STORE_INFO_type_string.3ossl deleted file mode 120000 index a4dd7efd..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_INFO_type_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_INFO.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER.3ossl deleted file mode 100644 index 97e02176..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER.3ossl +++ /dev/null @@ -1,507 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE_LOADER 3ossl" -.TH OSSL_STORE_LOADER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_STORE_LOADER, -OSSL_STORE_LOADER_fetch, -OSSL_STORE_LOADER_up_ref, -OSSL_STORE_LOADER_free, -OSSL_STORE_LOADER_get0_provider, -OSSL_STORE_LOADER_get0_properties, -OSSL_STORE_LOADER_is_a, -OSSL_STORE_LOADER_get0_description, -OSSL_STORE_LOADER_do_all_provided, -OSSL_STORE_LOADER_names_do_all, -OSSL_STORE_LOADER_CTX, OSSL_STORE_LOADER_new, -OSSL_STORE_LOADER_get0_engine, OSSL_STORE_LOADER_get0_scheme, -OSSL_STORE_LOADER_set_open, OSSL_STORE_LOADER_set_open_ex, -OSSL_STORE_LOADER_set_attach, OSSL_STORE_LOADER_set_ctrl, -OSSL_STORE_LOADER_set_expect, OSSL_STORE_LOADER_set_find, -OSSL_STORE_LOADER_set_load, OSSL_STORE_LOADER_set_eof, -OSSL_STORE_LOADER_set_error, OSSL_STORE_LOADER_set_close, -OSSL_STORE_register_loader, OSSL_STORE_unregister_loader, -OSSL_STORE_open_fn, OSSL_STORE_open_ex_fn, -OSSL_STORE_attach_fn, OSSL_STORE_ctrl_fn, -OSSL_STORE_expect_fn, OSSL_STORE_find_fn, -OSSL_STORE_load_fn, OSSL_STORE_eof_fn, OSSL_STORE_error_fn, -OSSL_STORE_close_fn \- Types and functions to manipulate, register and -unregister STORE loaders for different URI schemes -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_store_loader_st OSSL_STORE_LOADER; -\& -\& OSSL_STORE_LOADER *OSSL_STORE_LOADER_fetch(OSSL_LIB_CTX *libctx, -\& const char *scheme, -\& const char *properties); -\& int OSSL_STORE_LOADER_up_ref(OSSL_STORE_LOADER *loader); -\& void OSSL_STORE_LOADER_free(OSSL_STORE_LOADER *loader); -\& const OSSL_PROVIDER *OSSL_STORE_LOADER_get0_provider(const OSSL_STORE_LOADER * -\& loader); -\& const char *OSSL_STORE_LOADER_get0_properties(const OSSL_STORE_LOADER *loader); -\& const char *OSSL_STORE_LOADER_get0_description(const OSSL_STORE_LOADER *loader); -\& int OSSL_STORE_LOADER_is_a(const OSSL_STORE_LOADER *loader, -\& const char *scheme); -\& void OSSL_STORE_LOADER_do_all_provided(OSSL_LIB_CTX *libctx, -\& void (*user_fn)(OSSL_STORE_LOADER *loader, -\& void *arg), -\& void *user_arg); -\& int OSSL_STORE_LOADER_names_do_all(const OSSL_STORE_LOADER *loader, -\& void (*fn)(const char *name, void *data), -\& void *data); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 5 -\& OSSL_STORE_LOADER *OSSL_STORE_LOADER_new(ENGINE *e, const char *scheme); -\& const ENGINE *OSSL_STORE_LOADER_get0_engine(const OSSL_STORE_LOADER -\& *store_loader); -\& const char *OSSL_STORE_LOADER_get0_scheme(const OSSL_STORE_LOADER -\& *store_loader); -\& -\& /* struct ossl_store_loader_ctx_st is defined differently by each loader */ -\& typedef struct ossl_store_loader_ctx_st OSSL_STORE_LOADER_CTX; -\& -\& typedef OSSL_STORE_LOADER_CTX *(*OSSL_STORE_open_fn)( -\& const char *uri, const UI_METHOD *ui_method, void *ui_data); -\& int OSSL_STORE_LOADER_set_open(OSSL_STORE_LOADER *store_loader, -\& OSSL_STORE_open_fn store_open_function); -\& typedef OSSL_STORE_LOADER_CTX *(*OSSL_STORE_open_ex_fn)( -\& const char *uri, const UI_METHOD *ui_method, void *ui_data); -\& int OSSL_STORE_LOADER_set_open_ex -\& (OSSL_STORE_LOADER *store_loader, -\& OSSL_STORE_open_ex_fn store_open_ex_function); -\& typedef OSSL_STORE_LOADER_CTX *(*OSSL_STORE_attach_fn) -\& (const OSSL_STORE_LOADER *loader, BIO *bio, -\& OSSL_LIB_CTX *libctx, const char *propq, -\& const UI_METHOD *ui_method, void *ui_data); -\& int OSSL_STORE_LOADER_set_attach(OSSL_STORE_LOADER *loader, -\& OSSL_STORE_attach_fn attach_function); -\& typedef int (*OSSL_STORE_ctrl_fn)(OSSL_STORE_LOADER_CTX *ctx, int cmd, -\& va_list args); -\& int OSSL_STORE_LOADER_set_ctrl(OSSL_STORE_LOADER *store_loader, -\& OSSL_STORE_ctrl_fn store_ctrl_function); -\& typedef int (*OSSL_STORE_expect_fn)(OSSL_STORE_LOADER_CTX *ctx, int expected); -\& int OSSL_STORE_LOADER_set_expect(OSSL_STORE_LOADER *loader, -\& OSSL_STORE_expect_fn expect_function); -\& typedef int (*OSSL_STORE_find_fn)(OSSL_STORE_LOADER_CTX *ctx, -\& OSSL_STORE_SEARCH *criteria); -\& int OSSL_STORE_LOADER_set_find(OSSL_STORE_LOADER *loader, -\& OSSL_STORE_find_fn find_function); -\& typedef OSSL_STORE_INFO *(*OSSL_STORE_load_fn)(OSSL_STORE_LOADER_CTX *ctx, -\& UI_METHOD *ui_method, -\& void *ui_data); -\& int OSSL_STORE_LOADER_set_load(OSSL_STORE_LOADER *store_loader, -\& OSSL_STORE_load_fn store_load_function); -\& typedef int (*OSSL_STORE_eof_fn)(OSSL_STORE_LOADER_CTX *ctx); -\& int OSSL_STORE_LOADER_set_eof(OSSL_STORE_LOADER *store_loader, -\& OSSL_STORE_eof_fn store_eof_function); -\& typedef int (*OSSL_STORE_error_fn)(OSSL_STORE_LOADER_CTX *ctx); -\& int OSSL_STORE_LOADER_set_error(OSSL_STORE_LOADER *store_loader, -\& OSSL_STORE_error_fn store_error_function); -\& typedef int (*OSSL_STORE_close_fn)(OSSL_STORE_LOADER_CTX *ctx); -\& int OSSL_STORE_LOADER_set_close(OSSL_STORE_LOADER *store_loader, -\& OSSL_STORE_close_fn store_close_function); -\& -\& int OSSL_STORE_register_loader(OSSL_STORE_LOADER *loader); -\& OSSL_STORE_LOADER *OSSL_STORE_unregister_loader(const char *scheme); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fB\s-1OSSL_STORE_LOADER\s0\fR is a method for \s-1OSSL_STORE\s0 loaders, which implement -\&\fBOSSL_STORE_open()\fR, \fBOSSL_STORE_open_ex()\fR, \fBOSSL_STORE_load()\fR, -\&\fBOSSL_STORE_eof()\fR, \fBOSSL_STORE_error()\fR and \fBOSSL_STORE_close()\fR for specific -storage schemes. -.PP -\&\fBOSSL_STORE_LOADER_fetch()\fR looks for an implementation for a storage -\&\fIscheme\fR within the providers that has been loaded into the \fB\s-1OSSL_LIB_CTX\s0\fR -given by \fIlibctx\fR, and with the properties given by \fIproperties\fR. -.PP -\&\fBOSSL_STORE_LOADER_up_ref()\fR increments the reference count for the given -\&\fIloader\fR. -.PP -\&\fBOSSL_STORE_LOADER_free()\fR decrements the reference count for the given -\&\fIloader\fR, and when the count reaches zero, frees it. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_STORE_LOADER_get0_provider()\fR returns the provider of the given -\&\fIloader\fR. -.PP -\&\fBOSSL_STORE_LOADER_get0_properties()\fR returns the property definition associated -with the given \fIloader\fR. -.PP -\&\fBOSSL_STORE_LOADER_is_a()\fR checks if \fIloader\fR is an implementation -of an algorithm that's identifiable with \fIscheme\fR. -.PP -\&\fBOSSL_STORE_LOADER_get0_description()\fR returns a description of the \fIloader\fR, meant -for display and human consumption. The description is at the discretion of the -\&\fIloader\fR implementation. -.PP -\&\fBOSSL_STORE_LOADER_do_all_provided()\fR traverses all store implementations -by all activated providers in the library context \fIlibctx\fR, and for each -of the implementations, calls \fIuser_fn\fR with the implementation method and -\&\fIuser_arg\fR as arguments. -.PP -\&\fBOSSL_STORE_LOADER_names_do_all()\fR traverses all names for the given -\&\fIloader\fR, and calls \fIfn\fR with each name and \fIdata\fR. -.SS "Legacy Types and Functions (deprecated)" -.IX Subsection "Legacy Types and Functions (deprecated)" -These functions help applications and engines to create loaders for -schemes they support. These are all deprecated and discouraged in favour of -provider implementations, see \fBprovider\-storemgmt\fR\|(7). -.PP -\&\fB\s-1OSSL_STORE_LOADER_CTX\s0\fR is a type template, to be defined by each loader -using \f(CW\*(C`struct ossl_store_loader_ctx_st { ... }\*(C'\fR. -.PP -\&\fBOSSL_STORE_open_fn\fR, \fBOSSL_STORE_open_ex_fn\fR, -\&\fBOSSL_STORE_ctrl_fn\fR, \fBOSSL_STORE_expect_fn\fR, \fBOSSL_STORE_find_fn\fR, -\&\fBOSSL_STORE_load_fn\fR, \fBOSSL_STORE_eof_fn\fR, and \fBOSSL_STORE_close_fn\fR -are the function pointer types used within a \s-1STORE\s0 loader. -The functions pointed at define the functionality of the given loader. -.IP "\fBOSSL_STORE_open_fn\fR and \fBOSSL_STORE_open_ex_fn\fR" 4 -.IX Item "OSSL_STORE_open_fn and OSSL_STORE_open_ex_fn" -\&\fBOSSL_STORE_open_ex_fn\fR takes a \s-1URI\s0 and is expected to -interpret it in the best manner possible according to the scheme the -loader implements. It also takes a \fB\s-1UI_METHOD\s0\fR and associated data, -to be used any time something needs to be prompted for, as well as a -library context \fIlibctx\fR with an associated property query \fIpropq\fR, -to be used when fetching necessary algorithms to perform the loads. -Furthermore, this function is expected to initialize what needs to be -initialized, to create a private data store (\fB\s-1OSSL_STORE_LOADER_CTX\s0\fR, -see above), and to return it. -If something goes wrong, this function is expected to return \s-1NULL.\s0 -.Sp -\&\fBOSSL_STORE_open_fn\fR does the same thing as -\&\fBOSSL_STORE_open_ex_fn\fR but uses \s-1NULL\s0 for the library -context \fIlibctx\fR and property query \fIpropq\fR. -.IP "\fBOSSL_STORE_attach_fn\fR" 4 -.IX Item "OSSL_STORE_attach_fn" -This function takes a \fB\s-1BIO\s0\fR, otherwise works like -\&\fBOSSL_STORE_open_ex_fn\fR. -.IP "\fBOSSL_STORE_ctrl_fn\fR" 4 -.IX Item "OSSL_STORE_ctrl_fn" -This function takes a \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer, a command number -\&\fIcmd\fR and a \fBva_list\fR \fIargs\fR and is used to manipulate loader -specific parameters. -.Sp -Loader specific command numbers must begin at \fB\s-1OSSL_STORE_C_CUSTOM_START\s0\fR. -Any number below that is reserved for future globally known command -numbers. -.Sp -This function is expected to return 1 on success, 0 on error. -.IP "\fBOSSL_STORE_expect_fn\fR" 4 -.IX Item "OSSL_STORE_expect_fn" -This function takes a \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer and a \fB\s-1OSSL_STORE_INFO\s0\fR -identity \fIexpected\fR, and is used to tell the loader what object type is -expected. -\&\fIexpected\fR may be zero to signify that no specific object type is expected. -.Sp -This function is expected to return 1 on success, 0 on error. -.IP "\fBOSSL_STORE_find_fn\fR" 4 -.IX Item "OSSL_STORE_find_fn" -This function takes a \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer and a -\&\fB\s-1OSSL_STORE_SEARCH\s0\fR search criterion, and is used to tell the loader what -to search for. -.Sp -When called with the loader context being \s-1NULL,\s0 this function is expected -to return 1 if the loader supports the criterion, otherwise 0. -.Sp -When called with the loader context being something other than \s-1NULL,\s0 this -function is expected to return 1 on success, 0 on error. -.IP "\fBOSSL_STORE_load_fn\fR" 4 -.IX Item "OSSL_STORE_load_fn" -This function takes a \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer and a \fB\s-1UI_METHOD\s0\fR -with associated data. -It's expected to load the next available data, mold it into a data -structure that can be wrapped in a \fB\s-1OSSL_STORE_INFO\s0\fR using one of the -\&\s-1\fBOSSL_STORE_INFO\s0\fR\|(3) functions. -If no more data is available or an error occurs, this function is -expected to return \s-1NULL.\s0 -The \fBOSSL_STORE_eof_fn\fR and \fBOSSL_STORE_error_fn\fR functions must indicate if -it was in fact the end of data or if an error occurred. -.Sp -Note that this function retrieves \fIone\fR data item only. -.IP "\fBOSSL_STORE_eof_fn\fR" 4 -.IX Item "OSSL_STORE_eof_fn" -This function takes a \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer and is expected to -return 1 to indicate that the end of available data has been reached. -It is otherwise expected to return 0. -.IP "\fBOSSL_STORE_error_fn\fR" 4 -.IX Item "OSSL_STORE_error_fn" -This function takes a \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer and is expected to -return 1 to indicate that an error occurred in a previous call to the -\&\fBOSSL_STORE_load_fn\fR function. -It is otherwise expected to return 0. -.IP "\fBOSSL_STORE_close_fn\fR" 4 -.IX Item "OSSL_STORE_close_fn" -This function takes a \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer and is expected to -close or shut down what needs to be closed, and finally free the -contents of the \fB\s-1OSSL_STORE_LOADER_CTX\s0\fR pointer. -It returns 1 on success and 0 on error. -.PP -\&\fBOSSL_STORE_LOADER_new()\fR creates a new \fB\s-1OSSL_STORE_LOADER\s0\fR. -It takes an \fB\s-1ENGINE\s0\fR \fIe\fR and a string \fIscheme\fR. -\&\fIscheme\fR must \fIalways\fR be set. -Both \fIe\fR and \fIscheme\fR are used as is and must therefore be alive as -long as the created loader is. -.PP -\&\fBOSSL_STORE_LOADER_get0_engine()\fR returns the engine of the \fIstore_loader\fR. -\&\fBOSSL_STORE_LOADER_get0_scheme()\fR returns the scheme of the \fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_open()\fR sets the opener function for the -\&\fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_open_ex()\fR sets the opener with library context -function for the \fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_attach()\fR sets the attacher function for the -\&\fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_ctrl()\fR sets the control function for the -\&\fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_expect()\fR sets the expect function for the -\&\fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_load()\fR sets the loader function for the -\&\fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_eof()\fR sets the end of file checker function for the -\&\fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_set_close()\fR sets the closing function for the -\&\fIstore_loader\fR. -.PP -\&\fBOSSL_STORE_LOADER_free()\fR frees the given \fIstore_loader\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBOSSL_STORE_register_loader()\fR register the given \fIstore_loader\fR and -thereby makes it available for use with \fBOSSL_STORE_open()\fR, -\&\fBOSSL_STORE_open_ex()\fR, \fBOSSL_STORE_load()\fR, \fBOSSL_STORE_eof()\fR -and \fBOSSL_STORE_close()\fR. -.PP -\&\fBOSSL_STORE_unregister_loader()\fR unregister the store loader for the given -\&\fIscheme\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_STORE_LOADER_fetch()\fR returns a pointer to an \s-1OSSL_STORE_LOADER\s0 object, -or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_STORE_LOADER_up_ref()\fR returns 1 on success, or 0 on error. -.PP -\&\fBOSSL_STORE_LOADER_names_do_all()\fR returns 1 if the callback was called for all -names. A return value of 0 means that the callback was not called for any names. -.PP -\&\fBOSSL_STORE_LOADER_free()\fR doesn't return any value. -.PP -\&\fBOSSL_STORE_LOADER_get0_provider()\fR returns a pointer to a provider object, or -\&\s-1NULL\s0 on error. -.PP -\&\fBOSSL_STORE_LOADER_get0_properties()\fR returns a pointer to a property -definition string, or \s-1NULL\s0 on error. -.PP -\&\fBOSSL_STORE_LOADER_is_a()\fR returns 1 if \fIloader\fR was identifiable, -otherwise 0. -.PP -\&\fBOSSL_STORE_LOADER_get0_description()\fR returns a pointer to a description, or \s-1NULL\s0 if -there isn't one. -.PP -The functions with the types \fBOSSL_STORE_open_fn\fR, -\&\fBOSSL_STORE_open_ex_fn\fR, \fBOSSL_STORE_ctrl_fn\fR, -\&\fBOSSL_STORE_expect_fn\fR, \fBOSSL_STORE_load_fn\fR, \fBOSSL_STORE_eof_fn\fR -and \fBOSSL_STORE_close_fn\fR have the same return values as \fBOSSL_STORE_open()\fR, -\&\fBOSSL_STORE_open_ex()\fR, \fBOSSL_STORE_ctrl()\fR, \fBOSSL_STORE_expect()\fR, -\&\fBOSSL_STORE_load()\fR, \fBOSSL_STORE_eof()\fR and \fBOSSL_STORE_close()\fR, respectively. -.PP -\&\fBOSSL_STORE_LOADER_new()\fR returns a pointer to a \fB\s-1OSSL_STORE_LOADER\s0\fR on success, -or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_STORE_LOADER_set_open()\fR, \fBOSSL_STORE_LOADER_set_open_ex()\fR, -\&\fBOSSL_STORE_LOADER_set_ctrl()\fR, \fBOSSL_STORE_LOADER_set_load()\fR, -\&\fBOSSL_STORE_LOADER_set_eof()\fR and \fBOSSL_STORE_LOADER_set_close()\fR return 1 -on success, or 0 on failure. -.PP -\&\fBOSSL_STORE_register_loader()\fR returns 1 on success, or 0 on failure. -.PP -\&\fBOSSL_STORE_unregister_loader()\fR returns the unregistered loader on success, -or \s-1NULL\s0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \fBOSSL_STORE_open\fR\|(3), \s-1\fBOSSL_LIB_CTX\s0\fR\|(3), -\&\fBprovider\-storemgmt\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_STORE_LOADER_fetch()\fR, \fBOSSL_STORE_LOADER_up_ref()\fR, -\&\fBOSSL_STORE_LOADER_get0_provider()\fR, \fBOSSL_STORE_LOADER_get0_properties()\fR, -\&\fBOSSL_STORE_LOADER_get0_description()\fR, \fBOSSL_STORE_LOADER_is_a()\fR, -\&\fBOSSL_STORE_LOADER_do_all_provided()\fR and \fBOSSL_STORE_LOADER_names_do_all()\fR -were added in OpenSSL 3.0. -.PP -\&\fB\s-1OSSL_STORE_LOADER\s0\fR and \fBOSSL_STORE_LOADER_free()\fR were added in OpenSSL -1.1.1. -.PP -\&\fBOSSL_STORE_LOADER_set_open_ex()\fR and \fBOSSL_STORE_open_ex_fn()\fR were added in -OpenSSL 3.0, and are deprecated. -.PP -\&\fB\s-1OSSL_STORE_LOADER_CTX\s0\fR, \fBOSSL_STORE_LOADER_new()\fR, -\&\fBOSSL_STORE_LOADER_set0_scheme()\fR, \fBOSSL_STORE_LOADER_get0_scheme()\fR, -\&\fBOSSL_STORE_LOADER_get0_engine()\fR, \fBOSSL_STORE_LOADER_set_expect()\fR, -\&\fBOSSL_STORE_LOADER_set_find()\fR, \fBOSSL_STORE_LOADER_set_attach()\fR, -\&\fBOSSL_STORE_LOADER_set_open_ex()\fR, \fBOSSL_STORE_LOADER_set_open()\fR, -\&\fBOSSL_STORE_LOADER_set_ctrl()\fR, -\&\fBOSSL_STORE_LOADER_set_load()\fR, \fBOSSL_STORE_LOADER_set_eof()\fR, -\&\fBOSSL_STORE_LOADER_set_close()\fR, -\&\fBOSSL_STORE_register_loader()\fR, \fBOSSL_STORE_LOADER_set_error()\fR, -\&\fBOSSL_STORE_unregister_loader()\fR, \fBOSSL_STORE_open_fn()\fR, \fBOSSL_STORE_ctrl_fn()\fR, -\&\fBOSSL_STORE_load_fn()\fR, \fBOSSL_STORE_eof_fn()\fR and \fBOSSL_STORE_close_fn()\fR -were added in OpenSSL 1.1.1, and became deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_CTX.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_CTX.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_CTX.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_do_all_provided.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_do_all_provided.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_do_all_provided.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_fetch.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_fetch.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_fetch.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_free.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_free.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_description.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_description.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_engine.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_engine.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_properties.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_properties.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_properties.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_provider.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_provider.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_provider.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_scheme.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_scheme.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_get0_scheme.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_is_a.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_is_a.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_is_a.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_names_do_all.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_names_do_all.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_names_do_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_new.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_new.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_attach.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_attach.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_attach.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_close.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_close.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_close.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_ctrl.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_ctrl.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_eof.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_eof.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_eof.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_error.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_error.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_expect.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_expect.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_expect.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_find.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_find.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_load.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_load.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open_ex.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open_ex.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_set_open_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_LOADER_up_ref.3ossl b/openssl-install/share/man/man3/OSSL_STORE_LOADER_up_ref.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_LOADER_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH.3ossl deleted file mode 100644 index 6cb75e8c..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH.3ossl +++ /dev/null @@ -1,313 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE_SEARCH 3ossl" -.TH OSSL_STORE_SEARCH 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_STORE_SEARCH, -OSSL_STORE_SEARCH_by_name, -OSSL_STORE_SEARCH_by_issuer_serial, -OSSL_STORE_SEARCH_by_key_fingerprint, -OSSL_STORE_SEARCH_by_alias, -OSSL_STORE_SEARCH_free, -OSSL_STORE_SEARCH_get_type, -OSSL_STORE_SEARCH_get0_name, -OSSL_STORE_SEARCH_get0_serial, -OSSL_STORE_SEARCH_get0_bytes, -OSSL_STORE_SEARCH_get0_string, -OSSL_STORE_SEARCH_get0_digest -\&\- Type and functions to create OSSL_STORE search criteria -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_store_search_st OSSL_STORE_SEARCH; -\& -\& OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(X509_NAME *name); -\& OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(X509_NAME *name, -\& const ASN1_INTEGER -\& *serial); -\& OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_key_fingerprint(const EVP_MD *digest, -\& const unsigned char -\& *bytes, int len); -\& OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_alias(const char *alias); -\& -\& void OSSL_STORE_SEARCH_free(OSSL_STORE_SEARCH *search); -\& -\& int OSSL_STORE_SEARCH_get_type(const OSSL_STORE_SEARCH *criterion); -\& X509_NAME *OSSL_STORE_SEARCH_get0_name(OSSL_STORE_SEARCH *criterion); -\& const ASN1_INTEGER *OSSL_STORE_SEARCH_get0_serial(const OSSL_STORE_SEARCH -\& *criterion); -\& const unsigned char *OSSL_STORE_SEARCH_get0_bytes(const OSSL_STORE_SEARCH -\& *criterion, size_t *length); -\& const char *OSSL_STORE_SEARCH_get0_string(const OSSL_STORE_SEARCH *criterion); -\& const EVP_MD *OSSL_STORE_SEARCH_get0_digest(const OSSL_STORE_SEARCH -\& *criterion); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are used to specify search criteria to help search for specific -objects through other names than just the \s-1URI\s0 that's given to \fBOSSL_STORE_open()\fR. -For example, this can be useful for an application that has received a \s-1URI\s0 -and then wants to add on search criteria in a uniform and supported manner. -.SS "Types" -.IX Subsection "Types" -\&\fB\s-1OSSL_STORE_SEARCH\s0\fR is an opaque type that holds the constructed search -criterion, and that can be given to an \s-1OSSL_STORE\s0 context with -\&\fBOSSL_STORE_find()\fR. -.PP -The calling application owns the allocation of an \fB\s-1OSSL_STORE_SEARCH\s0\fR at all -times, and should therefore be careful not to deallocate it before -\&\fBOSSL_STORE_close()\fR has been called for the \s-1OSSL_STORE\s0 context it was given -to. -.SS "Application Functions" -.IX Subsection "Application Functions" -\&\fBOSSL_STORE_SEARCH_by_name()\fR, -\&\fBOSSL_STORE_SEARCH_by_issuer_serial()\fR, -\&\fBOSSL_STORE_SEARCH_by_key_fingerprint()\fR, -and \fBOSSL_STORE_SEARCH_by_alias()\fR -are used to create an \fB\s-1OSSL_STORE_SEARCH\s0\fR from a subject name, an issuer name -and serial number pair, a key fingerprint, and an alias (for example a friendly -name). -The parameters that are provided are not copied, only referred to in a -criterion, so they must have at least the same life time as the created -\&\fB\s-1OSSL_STORE_SEARCH\s0\fR. -.PP -\&\fBOSSL_STORE_SEARCH_free()\fR is used to free the \fB\s-1OSSL_STORE_SEARCH\s0\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.SS "Loader Functions" -.IX Subsection "Loader Functions" -\&\fBOSSL_STORE_SEARCH_get_type()\fR returns the criterion type for the given -\&\fB\s-1OSSL_STORE_SEARCH\s0\fR. -.PP -\&\fBOSSL_STORE_SEARCH_get0_name()\fR, \fBOSSL_STORE_SEARCH_get0_serial()\fR, -\&\fBOSSL_STORE_SEARCH_get0_bytes()\fR, \fBOSSL_STORE_SEARCH_get0_string()\fR, -and \fBOSSL_STORE_SEARCH_get0_digest()\fR -are used to retrieve different data from a \fB\s-1OSSL_STORE_SEARCH\s0\fR, as -available for each type. -For more information, see \*(L"\s-1SUPPORTED CRITERION TYPES\*(R"\s0 below. -.SH "SUPPORTED CRITERION TYPES" -.IX Header "SUPPORTED CRITERION TYPES" -Currently supported criterion types are: -.IP "\s-1OSSL_STORE_SEARCH_BY_NAME\s0" 4 -.IX Item "OSSL_STORE_SEARCH_BY_NAME" -This criterion supports a search by exact match of subject name. -The subject name itself is a \fBX509_NAME\fR pointer. -A criterion of this type is created with \fBOSSL_STORE_SEARCH_by_name()\fR, -and the actual subject name is retrieved with \fBOSSL_STORE_SEARCH_get0_name()\fR. -.IP "\s-1OSSL_STORE_SEARCH_BY_ISSUER_SERIAL\s0" 4 -.IX Item "OSSL_STORE_SEARCH_BY_ISSUER_SERIAL" -This criterion supports a search by exact match of both issuer name and serial -number. -The issuer name itself is a \fBX509_NAME\fR pointer, and the serial number is -a \fB\s-1ASN1_INTEGER\s0\fR pointer. -A criterion of this type is created with \fBOSSL_STORE_SEARCH_by_issuer_serial()\fR -and the actual issuer name and serial number are retrieved with -\&\fBOSSL_STORE_SEARCH_get0_name()\fR and \fBOSSL_STORE_SEARCH_get0_serial()\fR. -.IP "\s-1OSSL_STORE_SEARCH_BY_KEY_FINGERPRINT\s0" 4 -.IX Item "OSSL_STORE_SEARCH_BY_KEY_FINGERPRINT" -This criterion supports a search by exact match of key fingerprint. -The key fingerprint in itself is a string of bytes and its length, as -well as the algorithm that was used to compute the fingerprint. -The digest may be left unspecified (\s-1NULL\s0), and in that case, the -loader has to decide on a default digest and compare fingerprints -accordingly. -A criterion of this type is created with \fBOSSL_STORE_SEARCH_by_key_fingerprint()\fR -and the actual fingerprint and its length can be retrieved with -\&\fBOSSL_STORE_SEARCH_get0_bytes()\fR. -The digest can be retrieved with \fBOSSL_STORE_SEARCH_get0_digest()\fR. -.IP "\s-1OSSL_STORE_SEARCH_BY_ALIAS\s0" 4 -.IX Item "OSSL_STORE_SEARCH_BY_ALIAS" -This criterion supports a search by match of an alias of some kind. -The alias in itself is a simple C string. -A criterion of this type is created with \fBOSSL_STORE_SEARCH_by_alias()\fR -and the actual alias is retrieved with \fBOSSL_STORE_SEARCH_get0_string()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_STORE_SEARCH_by_name()\fR, -\&\fBOSSL_STORE_SEARCH_by_issuer_serial()\fR, -\&\fBOSSL_STORE_SEARCH_by_key_fingerprint()\fR, -and \fBOSSL_STORE_SEARCH_by_alias()\fR -return a \fB\s-1OSSL_STORE_SEARCH\s0\fR pointer on success, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_STORE_SEARCH_get_type()\fR returns the criterion type of the given -\&\fB\s-1OSSL_STORE_SEARCH\s0\fR. -There is no error value. -.PP -\&\fBOSSL_STORE_SEARCH_get0_name()\fR returns a \fBX509_NAME\fR pointer on success, -or \s-1NULL\s0 when the given \fB\s-1OSSL_STORE_SEARCH\s0\fR was of a different type. -.PP -\&\fBOSSL_STORE_SEARCH_get0_serial()\fR returns a \fB\s-1ASN1_INTEGER\s0\fR pointer on success, -or \s-1NULL\s0 when the given \fB\s-1OSSL_STORE_SEARCH\s0\fR was of a different type. -.PP -\&\fBOSSL_STORE_SEARCH_get0_bytes()\fR returns a \fBconst unsigned char\fR pointer and -sets \fI*length\fR to the strings length on success, or \s-1NULL\s0 when the given -\&\fB\s-1OSSL_STORE_SEARCH\s0\fR was of a different type. -.PP -\&\fBOSSL_STORE_SEARCH_get0_string()\fR returns a \fBconst char\fR pointer on success, -or \s-1NULL\s0 when the given \fB\s-1OSSL_STORE_SEARCH\s0\fR was of a different type. -.PP -\&\fBOSSL_STORE_SEARCH_get0_digest()\fR returns a \fBconst \s-1EVP_MD\s0\fR pointer. -\&\s-1NULL\s0 is a valid value and means that the store loader default will -be used when applicable. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \fBOSSL_STORE_supports_search\fR\|(3), \fBOSSL_STORE_find\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fB\s-1OSSL_STORE_SEARCH\s0\fR, -\&\fBOSSL_STORE_SEARCH_by_name()\fR, -\&\fBOSSL_STORE_SEARCH_by_issuer_serial()\fR, -\&\fBOSSL_STORE_SEARCH_by_key_fingerprint()\fR, -\&\fBOSSL_STORE_SEARCH_by_alias()\fR, -\&\fBOSSL_STORE_SEARCH_free()\fR, -\&\fBOSSL_STORE_SEARCH_get_type()\fR, -\&\fBOSSL_STORE_SEARCH_get0_name()\fR, -\&\fBOSSL_STORE_SEARCH_get0_serial()\fR, -\&\fBOSSL_STORE_SEARCH_get0_bytes()\fR, -and \fBOSSL_STORE_SEARCH_get0_string()\fR -were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_alias.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_alias.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_alias.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_issuer_serial.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_issuer_serial.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_issuer_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_key_fingerprint.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_key_fingerprint.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_key_fingerprint.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_name.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_name.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_by_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_free.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_free.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_bytes.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_bytes.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_bytes.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_digest.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_digest.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_name.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_name.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_serial.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_serial.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_string.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_string.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get0_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get_type.3ossl b/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get_type.3ossl deleted file mode 120000 index 866688bc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_SEARCH_get_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_SEARCH.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_attach.3ossl b/openssl-install/share/man/man3/OSSL_STORE_attach.3ossl deleted file mode 100644 index 8e159bef..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_attach.3ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE_ATTACH 3ossl" -.TH OSSL_STORE_ATTACH 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_STORE_attach \- Functions to read objects from a BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& OSSL_STORE_CTX *OSSL_STORE_attach(BIO *bio, const char *scheme, -\& OSSL_LIB_CTX *libctx, const char *propq, -\& const UI_METHOD *ui_method, void *ui_data, -\& const OSSL_PARAM params[], -\& OSSL_STORE_post_process_info_fn post_process, -\& void *post_process_data); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_STORE_attach()\fR works like \fBOSSL_STORE_open\fR\|(3), except it takes a \fB\s-1BIO\s0\fR -\&\fIbio\fR instead of a \fIuri\fR, along with a \fIscheme\fR to determine what loader -should be used to process the data. The reference count of the \fB\s-1BIO\s0\fR object -is increased by 1 if the call is successful. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_STORE_attach()\fR returns a pointer to a \fB\s-1OSSL_STORE_CTX\s0\fR on success, or -\&\s-1NULL\s0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \fBOSSL_STORE_open\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_STORE_attach()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_STORE_attach_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_attach_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_attach_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_close.3ossl b/openssl-install/share/man/man3/OSSL_STORE_close.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_close.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_close_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_close_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_close_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_ctrl.3ossl b/openssl-install/share/man/man3/OSSL_STORE_ctrl.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_ctrl_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_ctrl_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_ctrl_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_delete.3ossl b/openssl-install/share/man/man3/OSSL_STORE_delete.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_delete.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_eof.3ossl b/openssl-install/share/man/man3/OSSL_STORE_eof.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_eof.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_eof_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_eof_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_eof_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_error.3ossl b/openssl-install/share/man/man3/OSSL_STORE_error.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_error_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_error_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_error_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_expect.3ossl b/openssl-install/share/man/man3/OSSL_STORE_expect.3ossl deleted file mode 100644 index cb982a60..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_expect.3ossl +++ /dev/null @@ -1,211 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE_EXPECT 3ossl" -.TH OSSL_STORE_EXPECT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_STORE_expect, -OSSL_STORE_supports_search, -OSSL_STORE_find -\&\- Specify what object type is expected -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_STORE_expect(OSSL_STORE_CTX *ctx, int expected_type); -\& -\& int OSSL_STORE_supports_search(OSSL_STORE_CTX *ctx, int criterion_type); -\& -\& int OSSL_STORE_find(OSSL_STORE_CTX *ctx, OSSL_STORE_SEARCH *search); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_STORE_expect()\fR helps applications filter what \fBOSSL_STORE_load()\fR returns -by specifying a \fB\s-1OSSL_STORE_INFO\s0\fR type. -By default, no expectations on the types of objects to be loaded are made. -\&\fIexpected_type\fR may be 0 to indicate explicitly that no expectation is made, -or it may be any of the known object types (see -\&\*(L"\s-1SUPPORTED OBJECTS\*(R"\s0 in \s-1\fBOSSL_STORE_INFO\s0\fR\|(3)) except for \fB\s-1OSSL_STORE_INFO_NAME\s0\fR. -For example, if \f(CW\*(C`file:/foo/bar/store.pem\*(C'\fR contains several objects of different -type and only certificates are interesting, the application can simply say -that it expects the type \fB\s-1OSSL_STORE_INFO_CERT\s0\fR. -.PP -\&\fBOSSL_STORE_find()\fR helps applications specify a criterion for a more fine -grained search of objects. -.PP -\&\fBOSSL_STORE_supports_search()\fR checks if the loader of the given \s-1OSSL_STORE\s0 -context supports the given search type. -See \*(L"\s-1SUPPORTED CRITERION TYPES\*(R"\s0 in \s-1\fBOSSL_STORE_SEARCH\s0\fR\|(3) for information on the -supported search criterion types. -.PP -\&\fBOSSL_STORE_expect()\fR and OSSL_STORE_find \fImust\fR be called before the first -\&\fBOSSL_STORE_load()\fR of a given session, or they will fail. -.SH "NOTES" -.IX Header "NOTES" -If a more elaborate filter is required by the application, a better choice -would be to use a post-processing function. -See \fBOSSL_STORE_open\fR\|(3) for more information. -.PP -However, some loaders may take advantage of the knowledge of an expected type -to make object retrieval more efficient, so if a single type is expected, this -method is usually preferable. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_STORE_expect()\fR returns 1 on success, or 0 on failure. -.PP -\&\fBOSSL_STORE_supports_search()\fR returns 1 if the criterion is supported, or 0 -otherwise. -.PP -\&\fBOSSL_STORE_find()\fR returns 1 on success, or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \s-1\fBOSSL_STORE_INFO\s0\fR\|(3), \s-1\fBOSSL_STORE_SEARCH\s0\fR\|(3), -\&\fBOSSL_STORE_load\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_STORE_expect()\fR, \fBOSSL_STORE_supports_search()\fR and \fBOSSL_STORE_find()\fR -were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_STORE_expect_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_expect_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_expect_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_find.3ossl b/openssl-install/share/man/man3/OSSL_STORE_find.3ossl deleted file mode 120000 index bc24efbc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_expect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_find_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_find_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_find_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_load.3ossl b/openssl-install/share/man/man3/OSSL_STORE_load.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_load_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_load_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_load_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_open.3ossl b/openssl-install/share/man/man3/OSSL_STORE_open.3ossl deleted file mode 100644 index c50d67af..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_open.3ossl +++ /dev/null @@ -1,317 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE_OPEN 3ossl" -.TH OSSL_STORE_OPEN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_STORE_CTX, OSSL_STORE_post_process_info_fn, -OSSL_STORE_open, OSSL_STORE_open_ex, -OSSL_STORE_ctrl, OSSL_STORE_load, OSSL_STORE_eof, OSSL_STORE_delete, -OSSL_STORE_error, OSSL_STORE_close -\&\- Types and functions to read objects from a URI -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ossl_store_ctx_st OSSL_STORE_CTX; -\& -\& typedef OSSL_STORE_INFO *(*OSSL_STORE_post_process_info_fn)(OSSL_STORE_INFO *, -\& void *); -\& -\& OSSL_STORE_CTX *OSSL_STORE_open(const char *uri, const UI_METHOD *ui_method, -\& void *ui_data, -\& OSSL_STORE_post_process_info_fn post_process, -\& void *post_process_data); -\& OSSL_STORE_CTX * -\& OSSL_STORE_open_ex(const char *uri, OSSL_LIB_CTX *libctx, const char *propq, -\& const UI_METHOD *ui_method, void *ui_data, -\& const OSSL_PARAM params[], -\& OSSL_STORE_post_process_info_fn post_process, -\& void *post_process_data); -\& -\& OSSL_STORE_INFO *OSSL_STORE_load(OSSL_STORE_CTX *ctx); -\& int OSSL_STORE_eof(OSSL_STORE_CTX *ctx); -\& int OSSL_STORE_delete(const char *uri, OSSL_LIB_CTX *libctx, const char *propq, -\& const UI_METHOD *ui_method, void *ui_data, -\& const OSSL_PARAM params[]); -\& int OSSL_STORE_error(OSSL_STORE_CTX *ctx); -\& int OSSL_STORE_close(OSSL_STORE_CTX *ctx); -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int OSSL_STORE_ctrl(OSSL_STORE_CTX *ctx, int cmd, ... /* args */); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions help the application to fetch supported objects (see -\&\*(L"\s-1SUPPORTED OBJECTS\*(R"\s0 in \s-1\fBOSSL_STORE_INFO\s0\fR\|(3) for information on which those are) -from a given \s-1URI.\s0 -The general method to do so is to \*(L"open\*(R" the \s-1URI\s0 using \fBOSSL_STORE_open()\fR, -read each available and supported object using \fBOSSL_STORE_load()\fR as long as -\&\fBOSSL_STORE_eof()\fR hasn't been reached, and finish it off with \fBOSSL_STORE_close()\fR. -.PP -The retrieved information is stored in a \fB\s-1OSSL_STORE_INFO\s0\fR, which is further -described in \s-1\fBOSSL_STORE_INFO\s0\fR\|(3). -.SS "Types" -.IX Subsection "Types" -\&\fB\s-1OSSL_STORE_CTX\s0\fR is a context variable that holds all the internal -information for \fBOSSL_STORE_open()\fR, \fBOSSL_STORE_open_ex()\fR, -\&\fBOSSL_STORE_load()\fR, \fBOSSL_STORE_eof()\fR and \fBOSSL_STORE_close()\fR to work -together. -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_STORE_open_ex()\fR takes a uri or path \fIuri\fR, password \s-1UI\s0 method -\&\fIui_method\fR with associated data \fIui_data\fR, and post processing -callback \fIpost_process\fR with associated data \fIpost_process_data\fR, -a library context \fIlibctx\fR with an associated property query \fIpropq\fR, -and opens a channel to the data located at the \s-1URI\s0 and returns a -\&\fB\s-1OSSL_STORE_CTX\s0\fR with all necessary internal information. -The given \fIui_method\fR and \fIui_data\fR will be reused by all -functions that use \fB\s-1OSSL_STORE_CTX\s0\fR when interaction is needed, -for instance to provide a password. -The auxiliary \s-1\fBOSSL_PARAM\s0\fR\|(3) parameters in \fIparams\fR can be set to further -modify the store operation. -The given \fIpost_process\fR and \fIpost_process_data\fR will be reused by -\&\fBOSSL_STORE_load()\fR to manipulate or drop the value to be returned. -The \fIpost_process\fR function drops values by returning \s-1NULL,\s0 which -will cause \fBOSSL_STORE_load()\fR to start its process over with loading -the next object, until \fIpost_process\fR returns something other than -\&\s-1NULL,\s0 or the end of data is reached as indicated by \fBOSSL_STORE_eof()\fR. -.PP -\&\fBOSSL_STORE_open()\fR is similar to \fBOSSL_STORE_open_ex()\fR but uses \s-1NULL\s0 for -the \fIparams\fR, the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBOSSL_STORE_ctrl()\fR takes a \fB\s-1OSSL_STORE_CTX\s0\fR, and command number \fIcmd\fR and -more arguments not specified here. -The available loader specific command numbers and arguments they each -take depends on the loader that's used and is documented together with -that loader. -.PP -There are also global controls available: -.IP "\fB\s-1OSSL_STORE_C_USE_SECMEM\s0\fR" 4 -.IX Item "OSSL_STORE_C_USE_SECMEM" -Controls if the loader should attempt to use secure memory for any -allocated \fB\s-1OSSL_STORE_INFO\s0\fR and its contents. -This control expects one argument, a pointer to an \fIint\fR that is expected to -have the value 1 (yes) or 0 (no). -Any other value is an error. -.PP -\&\fBOSSL_STORE_load()\fR takes a \fB\s-1OSSL_STORE_CTX\s0\fR and tries to load the next -available object and return it wrapped with \fB\s-1OSSL_STORE_INFO\s0\fR. -.PP -\&\fBOSSL_STORE_delete()\fR deletes the object identified by \fIuri\fR. -.PP -\&\fBOSSL_STORE_eof()\fR takes a \fB\s-1OSSL_STORE_CTX\s0\fR and checks if we've reached the end -of data. -.PP -\&\fBOSSL_STORE_error()\fR takes a \fB\s-1OSSL_STORE_CTX\s0\fR and checks if an error occurred in -the last \fBOSSL_STORE_load()\fR call. -Note that it may still be meaningful to try and load more objects, unless -\&\fBOSSL_STORE_eof()\fR shows that the end of data has been reached. -.PP -\&\fBOSSL_STORE_close()\fR takes a \fB\s-1OSSL_STORE_CTX\s0\fR, closes the channel that was opened -by \fBOSSL_STORE_open()\fR and frees all other information that was stored in the -\&\fB\s-1OSSL_STORE_CTX\s0\fR, as well as the \fB\s-1OSSL_STORE_CTX\s0\fR itself. -If \fIctx\fR is \s-1NULL\s0 it does nothing. -.SH "NOTES" -.IX Header "NOTES" -A string without a scheme prefix (that is, a non-URI string) is -implicitly interpreted as using the \fIfile:\fR scheme. -.PP -There are some tools that can be used together with -\&\fBOSSL_STORE_open()\fR to determine if any failure is caused by an unparsable -\&\s-1URI,\s0 or if it's a different error (such as memory allocation -failures); if the \s-1URI\s0 was parsable but the scheme unregistered, the -top error will have the reason \f(CW\*(C`OSSL_STORE_R_UNREGISTERED_SCHEME\*(C'\fR. -.PP -These functions make no direct assumption regarding the pass phrase received -from the password callback. -The loaders may make assumptions, however. -For example, the \fBfile:\fR scheme loader inherits the assumptions made by -OpenSSL functionality that handles the different file types; this is mostly -relevant for PKCS#12 objects. -See \fBpassphrase\-encoding\fR\|(7) for further information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_STORE_open()\fR returns a pointer to a \fB\s-1OSSL_STORE_CTX\s0\fR on success, or -\&\s-1NULL\s0 on failure. -.PP -\&\fBOSSL_STORE_load()\fR returns a pointer to a \fB\s-1OSSL_STORE_INFO\s0\fR on success, or \s-1NULL\s0 -on error or when end of data is reached. -Use \fBOSSL_STORE_error()\fR and \fBOSSL_STORE_eof()\fR to determine the meaning of a -returned \s-1NULL.\s0 -.PP -\&\fBOSSL_STORE_eof()\fR returns 1 if the end of data has been reached -or an error occurred, 0 otherwise. -.PP -\&\fBOSSL_STORE_error()\fR returns 1 if an error occurred in an \fBOSSL_STORE_load()\fR call, -otherwise 0. -.PP -\&\fBOSSL_STORE_delete()\fR, \fBOSSL_STORE_ctrl()\fR and \fBOSSL_STORE_close()\fR return 1 on -success, or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \s-1\fBOSSL_STORE_INFO\s0\fR\|(3), \fBOSSL_STORE_register_loader\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_STORE_delete()\fR was added in OpenSSL 3.2. -.PP -\&\fBOSSL_STORE_open_ex()\fR was added in OpenSSL 3.0. -.PP -\&\fB\s-1OSSL_STORE_CTX\s0\fR, \fBOSSL_STORE_post_process_info_fn()\fR, \fBOSSL_STORE_open()\fR, -\&\fBOSSL_STORE_ctrl()\fR, \fBOSSL_STORE_load()\fR, \fBOSSL_STORE_eof()\fR and \fBOSSL_STORE_close()\fR -were added in OpenSSL 1.1.1. -.PP -Handling of \s-1NULL\s0 \fIctx\fR argument for \fBOSSL_STORE_close()\fR -was introduced in OpenSSL 1.1.1h. -.PP -\&\fBOSSL_STORE_ctrl()\fR and \fBOSSL_STORE_vctrl()\fR were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_STORE_open_ex.3ossl b/openssl-install/share/man/man3/OSSL_STORE_open_ex.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_open_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_open_ex_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_open_ex_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_open_ex_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_open_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_open_fn.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_open_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_post_process_info_fn.3ossl b/openssl-install/share/man/man3/OSSL_STORE_post_process_info_fn.3ossl deleted file mode 120000 index beca2c23..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_post_process_info_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_open.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_register_loader.3ossl b/openssl-install/share/man/man3/OSSL_STORE_register_loader.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_register_loader.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_supports_search.3ossl b/openssl-install/share/man/man3/OSSL_STORE_supports_search.3ossl deleted file mode 120000 index bc24efbc..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_supports_search.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_expect.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_STORE_unregister_loader.3ossl b/openssl-install/share/man/man3/OSSL_STORE_unregister_loader.3ossl deleted file mode 120000 index 1d2fc8e3..00000000 --- a/openssl-install/share/man/man3/OSSL_STORE_unregister_loader.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_STORE_LOADER.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_free.3ossl b/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_it.3ossl b/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_new.3ossl b/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGETING_INFORMATION_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGETS_free.3ossl b/openssl-install/share/man/man3/OSSL_TARGETS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGETS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGETS_it.3ossl b/openssl-install/share/man/man3/OSSL_TARGETS_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGETS_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGETS_new.3ossl b/openssl-install/share/man/man3/OSSL_TARGETS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGETS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGET_CERT_free.3ossl b/openssl-install/share/man/man3/OSSL_TARGET_CERT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGET_CERT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGET_CERT_it.3ossl b/openssl-install/share/man/man3/OSSL_TARGET_CERT_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGET_CERT_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGET_CERT_new.3ossl b/openssl-install/share/man/man3/OSSL_TARGET_CERT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGET_CERT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGET_free.3ossl b/openssl-install/share/man/man3/OSSL_TARGET_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGET_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGET_it.3ossl b/openssl-install/share/man/man3/OSSL_TARGET_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGET_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TARGET_new.3ossl b/openssl-install/share/man/man3/OSSL_TARGET_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_TARGET_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN.3ossl b/openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL.3ossl b/openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE.3ossl b/openssl-install/share/man/man3/OSSL_TRACE.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE1.3ossl b/openssl-install/share/man/man3/OSSL_TRACE1.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE1.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE2.3ossl b/openssl-install/share/man/man3/OSSL_TRACE2.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE2.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE3.3ossl b/openssl-install/share/man/man3/OSSL_TRACE3.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE3.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE4.3ossl b/openssl-install/share/man/man3/OSSL_TRACE4.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE4.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE5.3ossl b/openssl-install/share/man/man3/OSSL_TRACE5.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE5.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE6.3ossl b/openssl-install/share/man/man3/OSSL_TRACE6.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE6.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE7.3ossl b/openssl-install/share/man/man3/OSSL_TRACE7.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE7.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE8.3ossl b/openssl-install/share/man/man3/OSSL_TRACE8.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE8.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE9.3ossl b/openssl-install/share/man/man3/OSSL_TRACE9.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE9.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACEV.3ossl b/openssl-install/share/man/man3/OSSL_TRACEV.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACEV.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE_BEGIN.3ossl b/openssl-install/share/man/man3/OSSL_TRACE_BEGIN.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE_BEGIN.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE_CANCEL.3ossl b/openssl-install/share/man/man3/OSSL_TRACE_CANCEL.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE_CANCEL.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE_ENABLED.3ossl b/openssl-install/share/man/man3/OSSL_TRACE_ENABLED.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE_ENABLED.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE_END.3ossl b/openssl-install/share/man/man3/OSSL_TRACE_END.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE_END.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE_STRING.3ossl b/openssl-install/share/man/man3/OSSL_TRACE_STRING.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_TRACE_STRING_MAX.3ossl b/openssl-install/share/man/man3/OSSL_TRACE_STRING_MAX.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_TRACE_STRING_MAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_free.3ossl b/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_it.3ossl b/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_new.3ossl b/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OSSL_USER_NOTICE_SYNTAX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_default_cipher_list.3ossl b/openssl-install/share/man/man3/OSSL_default_cipher_list.3ossl deleted file mode 120000 index e8b09412..00000000 --- a/openssl-install/share/man/man3/OSSL_default_cipher_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cipher_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_default_ciphersuites.3ossl b/openssl-install/share/man/man3/OSSL_default_ciphersuites.3ossl deleted file mode 120000 index e8b09412..00000000 --- a/openssl-install/share/man/man3/OSSL_default_ciphersuites.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cipher_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_get_max_threads.3ossl b/openssl-install/share/man/man3/OSSL_get_max_threads.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/OSSL_get_max_threads.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_get_thread_support_flags.3ossl b/openssl-install/share/man/man3/OSSL_get_thread_support_flags.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/OSSL_get_thread_support_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_parse_url.3ossl b/openssl-install/share/man/man3/OSSL_parse_url.3ossl deleted file mode 120000 index 0a203382..00000000 --- a/openssl-install/share/man/man3/OSSL_parse_url.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_HTTP_parse_url.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_set_max_threads.3ossl b/openssl-install/share/man/man3/OSSL_set_max_threads.3ossl deleted file mode 120000 index 2c76e1d9..00000000 --- a/openssl-install/share/man/man3/OSSL_set_max_threads.3ossl +++ /dev/null @@ -1 +0,0 @@ -CRYPTO_THREAD_run_once.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_sleep.3ossl b/openssl-install/share/man/man3/OSSL_sleep.3ossl deleted file mode 100644 index caa37c73..00000000 --- a/openssl-install/share/man/man3/OSSL_sleep.3ossl +++ /dev/null @@ -1,174 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_SLEEP 3ossl" -.TH OSSL_SLEEP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_sleep \- delay execution for a specified number of milliseconds -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void OSSL_sleep(uint64_t millis); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_sleep()\fR is a convenience function to delay execution of the calling -thread for (at least) \fImillis\fR milliseconds. The delay is not guaranteed; -it may be affected by system activity, by the time spent processing the call, -limitation on the underlying system call parameter size or by system timer -granularity. -.PP -In particular on Windows the maximum amount of time it will sleep is -49 days and on systems where the regular \fBsleep\fR\|(3) is used as the underlying -system call the maximum sleep time is about 136 years. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_sleep()\fR does not return any value. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_sleep()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_trace_begin.3ossl b/openssl-install/share/man/man3/OSSL_trace_begin.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_begin.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_trace_cb.3ossl b/openssl-install/share/man/man3/OSSL_trace_cb.3ossl deleted file mode 120000 index 03c51957..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_set_channel.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_trace_enabled.3ossl b/openssl-install/share/man/man3/OSSL_trace_enabled.3ossl deleted file mode 100644 index d9c5ffba..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_enabled.3ossl +++ /dev/null @@ -1,466 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_TRACE_ENABLED 3ossl" -.TH OSSL_TRACE_ENABLED 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_trace_enabled, OSSL_trace_begin, OSSL_trace_end, -OSSL_TRACE_BEGIN, OSSL_TRACE_END, OSSL_TRACE_CANCEL, -OSSL_TRACE, OSSL_TRACE1, OSSL_TRACE2, OSSL_TRACE3, OSSL_TRACE4, -OSSL_TRACE5, OSSL_TRACE6, OSSL_TRACE7, OSSL_TRACE8, OSSL_TRACE9, -OSSL_TRACEV, -OSSL_TRACE_STRING, OSSL_TRACE_STRING_MAX, OSSL_trace_string, -OSSL_TRACE_ENABLED -\&\- OpenSSL Tracing API -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_trace_enabled(int category); -\& -\& BIO *OSSL_trace_begin(int category); -\& void OSSL_trace_end(int category, BIO *channel); -\& -\& /* trace group macros */ -\& OSSL_TRACE_BEGIN(category) { -\& ... -\& if (some_error) { -\& /* Leave trace group prematurely in case of an error */ -\& OSSL_TRACE_CANCEL(category); -\& goto err; -\& } -\& ... -\& } OSSL_TRACE_END(category); -\& -\& /* one\-shot trace macros */ -\& OSSL_TRACE(category, text) -\& OSSL_TRACE1(category, format, arg1) -\& OSSL_TRACE2(category, format, arg1, arg2) -\& ... -\& OSSL_TRACE9(category, format, arg1, ..., arg9) -\& OSSL_TRACE_STRING(category, text, full, data, len) -\& -\& #define OSSL_TRACE_STRING_MAX 80 -\& int OSSL_trace_string(BIO *out, int text, int full, -\& const unsigned char *data, size_t size); -\& -\& /* check whether a trace category is enabled */ -\& if (OSSL_TRACE_ENABLED(category)) { -\& ... -\& } -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions described here are mainly interesting for those who provide -OpenSSL functionality, either in OpenSSL itself or in engine modules -or similar. -.PP -If the tracing facility is enabled (see \*(L"Configure Tracing\*(R" below), -these functions are used to generate free text tracing output. -.PP -The tracing output is divided into types which are enabled -individually by the application. -The tracing types are described in detail in -\&\*(L"Trace types\*(R" in \fBOSSL_trace_set_callback\fR\|(3). -The fallback type \fB\s-1OSSL_TRACE_CATEGORY_ALL\s0\fR should \fInot\fR be used -with the functions described here. -.PP -Tracing for a specific category is enabled at run-time if a so-called -\&\fItrace channel\fR is attached to it. A trace channel is simply a -\&\s-1BIO\s0 object to which the application can write its trace output. -.PP -The application has two different ways of registering a trace channel, -either by directly providing a \s-1BIO\s0 object using \fBOSSL_trace_set_channel\fR\|(3), -or by providing a callback routine using \fBOSSL_trace_set_callback\fR\|(3). -The latter is wrapped internally by a dedicated \s-1BIO\s0 object, so for the -tracing code both channel types are effectively indistinguishable. -We call them a \fIsimple trace channel\fR and a \fIcallback trace channel\fR, -respectively. -.PP -To produce trace output, it is necessary to obtain a pointer to the -trace channel (i.e., the \s-1BIO\s0 object) using \fBOSSL_trace_begin()\fR, write -to it using arbitrary \s-1BIO\s0 output routines, and finally releases the -channel using \fBOSSL_trace_end()\fR. The \fBOSSL_trace_begin()\fR/\fBOSSL_trace_end()\fR -calls surrounding the trace output create a group, which acts as a -critical section (guarded by a mutex) to ensure that the trace output -of different threads does not get mixed up. -.PP -The tracing code normally does not call OSSL_trace_{begin,end}() directly, -but rather uses a set of convenience macros, see the \*(L"Macros\*(R" section below. -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_trace_enabled()\fR can be used to check if tracing for the given -\&\fIcategory\fR is enabled, i.e., if the tracing facility has been statically -enabled (see \*(L"Configure Tracing\*(R" below) and a trace channel has been -registered using \fBOSSL_trace_set_channel\fR\|(3) or \fBOSSL_trace_set_callback\fR\|(3). -.PP -\&\fBOSSL_trace_begin()\fR is used to start a tracing section, -and get the channel for the given \fIcategory\fR in form of a \s-1BIO.\s0 -This \s-1BIO\s0 can only be used for output. -The pointer returned is \s-1NULL\s0 if the category is invalid or not enabled. -.PP -\&\fBOSSL_trace_end()\fR is used to end a tracing section. -.PP -Using \fBOSSL_trace_begin()\fR and \fBOSSL_trace_end()\fR to wrap tracing sections -is \fImandatory\fR. -The result of trying to produce tracing output outside of such -sections is undefined. -.PP -\&\fBOSSL_trace_string()\fR outputs \fIdata\fR of length \fIsize\fR as a string on \s-1BIO\s0 \fIout\fR. -If \fItext\fR is 0, the function masks any included control characters apart from -newlines and makes sure for nonempty input that the output ends with a newline. -Unless \fIfull\fR is nonzero, the length is limited (with a suitable warning) -to \fB\s-1OSSL_TRACE_STRING_MAX\s0\fR characters, which currently is 80. -.SS "Macros" -.IX Subsection "Macros" -There are a number of convenience macros defined, to make tracing -easy and consistent. -.PP -\&\s-1\fBOSSL_TRACE_BEGIN\s0()\fR and \s-1\fBOSSL_TRACE_END\s0()\fR reserve the \fB\s-1BIO\s0\fR \f(CW\*(C`trc_out\*(C'\fR and are -used as follows to wrap a trace section: -.PP -.Vb 1 -\& OSSL_TRACE_BEGIN(TLS) { -\& -\& BIO_printf(trc_out, ... ); -\& -\& } OSSL_TRACE_END(TLS); -.Ve -.PP -This will normally expand to: -.PP -.Vb 8 -\& do { -\& BIO *trc_out = OSSL_trace_begin(OSSL_TRACE_CATEGORY_TLS); -\& if (trc_out != NULL) { -\& ... -\& BIO_printf(trc_out, ...); -\& } -\& OSSL_trace_end(OSSL_TRACE_CATEGORY_TLS, trc_out); -\& } while (0); -.Ve -.PP -\&\s-1\fBOSSL_TRACE_CANCEL\s0()\fR must be used before returning from or jumping out of a -trace section: -.PP -.Vb 1 -\& OSSL_TRACE_BEGIN(TLS) { -\& -\& if (some_error) { -\& OSSL_TRACE_CANCEL(TLS); -\& goto err; -\& } -\& BIO_printf(trc_out, ... ); -\& -\& } OSSL_TRACE_END(TLS); -.Ve -.PP -This will normally expand to: -.PP -.Vb 11 -\& do { -\& BIO *trc_out = OSSL_trace_begin(OSSL_TRACE_CATEGORY_TLS); -\& if (trc_out != NULL) { -\& if (some_error) { -\& OSSL_trace_end(OSSL_TRACE_CATEGORY_TLS, trc_out); -\& goto err; -\& } -\& BIO_printf(trc_out, ... ); -\& } -\& OSSL_trace_end(OSSL_TRACE_CATEGORY_TLS, trc_out); -\& } while (0); -.Ve -.PP -\&\s-1\fBOSSL_TRACE\s0()\fR and \s-1\fBOSSL_TRACE1\s0()\fR, \s-1\fBOSSL_TRACE2\s0()\fR, ... \s-1\fBOSSL_TRACE9\s0()\fR are -so-called one-shot macros: -.PP -The macro call \f(CW\*(C`OSSL_TRACE(category, text)\*(C'\fR, produces literal text trace output. -.PP -The macro call \f(CW\*(C`OSSL_TRACEn(category, format, arg1, ..., argn)\*(C'\fR produces -printf-style trace output with n format field arguments (n=1,...,9). -It expands to: -.PP -.Vb 3 -\& OSSL_TRACE_BEGIN(category) { -\& BIO_printf(trc_out, format, arg1, ..., argN); -\& } OSSL_TRACE_END(category) -.Ve -.PP -Internally, all one-shot macros are implemented using a generic \s-1\fBOSSL_TRACEV\s0()\fR -macro, since C90 does not support variadic macros. This helper macro has a rather -weird synopsis and should not be used directly. -.PP -The macro call \f(CW\*(C`OSSL_TRACE_STRING(category, text, full, data, len)\*(C'\fR -outputs \fIdata\fR of length \fIsize\fR as a string -if tracing for the given \fIcategory\fR is enabled. -It expands to: -.PP -.Vb 3 -\& OSSL_TRACE_BEGIN(category) { -\& OSSL_trace_string(trc_out, text, full, data, len); -\& } OSSL_TRACE_END(category) -.Ve -.PP -The \s-1\fBOSSL_TRACE_ENABLED\s0()\fR macro can be used to conditionally execute some code -only if a specific trace category is enabled. -In some situations this is simpler than entering a trace section using -\&\s-1\fBOSSL_TRACE_BEGIN\s0()\fR and \s-1\fBOSSL_TRACE_END\s0()\fR. -For example, the code -.PP -.Vb 3 -\& if (OSSL_TRACE_ENABLED(TLS)) { -\& ... -\& } -.Ve -.PP -expands to -.PP -.Vb 3 -\& if (OSSL_trace_enabled(OSSL_TRACE_CATEGORY_TLS) { -\& ... -\& } -.Ve -.SH "NOTES" -.IX Header "NOTES" -It is not needed to guard trace output function calls like -\&\fI\s-1OSSL_TRACE\s0(category, ...)\fR by \fI\s-1OSSL_TRACE_ENABLED\s0(category)\fR. -.PP -If producing the trace output requires carrying out auxiliary calculations, -this auxiliary code should be placed inside a conditional block which is -executed only if the trace category is enabled. -.PP -The most natural way to do this is to place the code inside the trace section -itself because it already introduces such a conditional block. -.PP -.Vb 2 -\& OSSL_TRACE_BEGIN(TLS) { -\& int var = do_some_auxiliary_calculation(); -\& -\& BIO_printf(trc_out, "var = %d\en", var); -\& -\& } OSSL_TRACE_END(TLS); -.Ve -.PP -In some cases it is more advantageous to use a simple conditional group instead -of a trace section. This is the case if calculations and tracing happen in -different locations of the code, or if the calculations are so time consuming -that placing them inside a (critical) trace section would create too much -contention. -.PP -.Vb 2 -\& if (OSSL_TRACE_ENABLED(TLS)) { -\& int var = do_some_auxiliary_calculation(); -\& -\& OSSL_TRACE1("var = %d\en", var); -\& } -.Ve -.PP -Note however that premature optimization of tracing code is in general futile -and it's better to keep the tracing code as simple as possible. -Because most often the limiting factor for the application's speed is the time -it takes to print the trace output, not to calculate it. -.SS "Configure Tracing" -.IX Subsection "Configure Tracing" -By default, the OpenSSL library is built with tracing disabled. To -use the tracing functionality documented here, it is therefore -necessary to configure and build OpenSSL with the 'enable\-trace' option. -.PP -When the library is built with tracing disabled: -.IP "\(bu" 4 -The macro \fB\s-1OPENSSL_NO_TRACE\s0\fR is defined in \fI\fR. -.IP "\(bu" 4 -all functions are still present, but \fBOSSL_trace_enabled()\fR will always -report the categories as disabled, and all other functions will do -nothing. -.IP "\(bu" 4 -the convenience macros are defined to produce dead code. -For example, take this example from \*(L"Macros\*(R" section above: -.Sp -.Vb 1 -\& OSSL_TRACE_BEGIN(TLS) { -\& -\& if (condition) { -\& OSSL_TRACE_CANCEL(TLS); -\& goto err; -\& } -\& BIO_printf(trc_out, ... ); -\& -\& } OSSL_TRACE_END(TLS); -.Ve -.Sp -When the tracing \s-1API\s0 isn't operational, that will expand to: -.Sp -.Vb 10 -\& do { -\& BIO *trc_out = NULL; -\& if (0) { -\& if (condition) { -\& ((void)0); -\& goto err; -\& } -\& BIO_printf(trc_out, ... ); -\& } -\& } while (0); -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_trace_enabled()\fR returns 1 if tracing for the given \fItype\fR is -operational and enabled, otherwise 0. -.PP -\&\fBOSSL_trace_begin()\fR returns a \fB\s-1BIO\s0\fR pointer if the given \fItype\fR is enabled, -otherwise \s-1NULL.\s0 -.PP -\&\fBOSSL_trace_string()\fR returns the number of characters emitted, or \-1 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_trace_set_channel\fR\|(3), \fBOSSL_trace_set_callback\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL Tracing \s-1API\s0 was added in OpenSSL 3.0. -.PP -\&\s-1\fBOSSL_TRACE_STRING\s0()\fR, \s-1OSSL_TRACE_STRING_MAX,\s0 and OSSL_trace_string -were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_trace_end.3ossl b/openssl-install/share/man/man3/OSSL_trace_end.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_end.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_trace_get_category_name.3ossl b/openssl-install/share/man/man3/OSSL_trace_get_category_name.3ossl deleted file mode 120000 index 1d029b40..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_get_category_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_get_category_num.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_trace_get_category_num.3ossl b/openssl-install/share/man/man3/OSSL_trace_get_category_num.3ossl deleted file mode 100644 index 2844b72f..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_get_category_num.3ossl +++ /dev/null @@ -1,176 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_TRACE_GET_CATEGORY_NUM 3ossl" -.TH OSSL_TRACE_GET_CATEGORY_NUM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_trace_get_category_num, OSSL_trace_get_category_name -\&\- OpenSSL tracing information functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int OSSL_trace_get_category_num(const char *name); -\& const char *OSSL_trace_get_category_name(int num); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBOSSL_trace_get_category_num()\fR gives the category number corresponding -to the given \f(CW\*(C`name\*(C'\fR. -.PP -\&\fBOSSL_trace_get_category_name()\fR gives the category name corresponding -to the given \f(CW\*(C`num\*(C'\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_trace_get_category_num()\fR returns the category number if the given -\&\f(CW\*(C`name\*(C'\fR is a recognised category name, otherwise \-1. -.PP -\&\fBOSSL_trace_get_category_name()\fR returns the category name if the given -\&\f(CW\*(C`num\*(C'\fR is a recognised category number, otherwise \s-1NULL.\s0 -.SH "HISTORY" -.IX Header "HISTORY" -The OpenSSL Tracing \s-1API\s0 was added ino OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_trace_set_callback.3ossl b/openssl-install/share/man/man3/OSSL_trace_set_callback.3ossl deleted file mode 120000 index 03c51957..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_set_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_set_channel.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_trace_set_channel.3ossl b/openssl-install/share/man/man3/OSSL_trace_set_channel.3ossl deleted file mode 100644 index 191c82c0..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_set_channel.3ossl +++ /dev/null @@ -1,449 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_TRACE_SET_CHANNEL 3ossl" -.TH OSSL_TRACE_SET_CHANNEL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_trace_set_channel, OSSL_trace_set_prefix, OSSL_trace_set_suffix, -OSSL_trace_set_callback, OSSL_trace_cb \- Enabling trace output -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef size_t (*OSSL_trace_cb)(const char *buf, size_t cnt, -\& int category, int cmd, void *data); -\& -\& void OSSL_trace_set_channel(int category, BIO *bio); -\& void OSSL_trace_set_prefix(int category, const char *prefix); -\& void OSSL_trace_set_suffix(int category, const char *suffix); -\& void OSSL_trace_set_callback(int category, OSSL_trace_cb cb, void *data); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -If available (see \*(L"Configure Tracing\*(R" below), the application can request -internal trace output. -This output comes in form of free text for humans to read. -.PP -The trace output is divided into categories which can be -enabled individually. -Every category can be enabled individually by attaching a so-called -\&\fItrace channel\fR to it, which in the simplest case is just a \s-1BIO\s0 object -to which the application can write the tracing output for this category. -Alternatively, the application can provide a tracer callback in order to -get more finegrained trace information. This callback will be wrapped -internally by a dedicated \s-1BIO\s0 object. -.PP -For the tracing code, both trace channel types are indistinguishable. -These are called a \fIsimple trace channel\fR and a \fIcallback trace channel\fR, -respectively. -.PP -\&\s-1\fBOSSL_TRACE_ENABLED\s0\fR\|(3) can be used to check whether tracing is currently -enabled for the given category. -Functions like \s-1\fBOSSL_TRACE1\s0\fR\|(3) and macros like \s-1\fBOSSL_TRACE_BEGIN\s0\fR\|(3) -can be used for producing free-text trace output. -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_trace_set_channel()\fR is used to enable the given trace \f(CW\*(C`category\*(C'\fR -by attaching the \fB\s-1BIO\s0\fR \fIbio\fR object as (simple) trace channel. -On success the ownership of the \s-1BIO\s0 is transferred to the channel, -so the caller must not free it directly. -.PP -\&\fBOSSL_trace_set_prefix()\fR and \fBOSSL_trace_set_suffix()\fR can be used to add -an extra line for each channel, to be output before and after group of -tracing output. -What constitutes an output group is decided by the code that produces -the output. -The lines given here are considered immutable; for more dynamic -tracing prefixes, consider setting a callback with -\&\fBOSSL_trace_set_callback()\fR instead. -.PP -\&\fBOSSL_trace_set_callback()\fR is used to enable the given trace -\&\fIcategory\fR by giving it the tracer callback \fIcb\fR with the associated -data \fIdata\fR, which will simply be passed through to \fIcb\fR whenever -it's called. The callback function is internally wrapped by a -dedicated \s-1BIO\s0 object, the so-called \fIcallback trace channel\fR. -This should be used when it's desirable to do form the trace output to -something suitable for application needs where a prefix and suffix -line aren't enough. -.PP -\&\fBOSSL_trace_set_channel()\fR and \fBOSSL_trace_set_callback()\fR are mutually -exclusive, calling one of them will clear whatever was set by the -previous call. -.PP -Calling \fBOSSL_trace_set_channel()\fR with \s-1NULL\s0 for \fIchannel\fR or -\&\fBOSSL_trace_set_callback()\fR with \s-1NULL\s0 for \fIcb\fR disables tracing for -the given \fIcategory\fR. -.SS "Trace callback" -.IX Subsection "Trace callback" -The tracer callback must return a \fBsize_t\fR, which must be zero on -error and otherwise return the number of bytes that were output. -It receives a text buffer \fIbuf\fR with \fIcnt\fR bytes of text, as well as -the \fIcategory\fR, a control number \fIcmd\fR, and the \fIdata\fR that was -passed to \fBOSSL_trace_set_callback()\fR. -.PP -The possible control numbers are: -.IP "\fB\s-1OSSL_TRACE_CTRL_BEGIN\s0\fR" 4 -.IX Item "OSSL_TRACE_CTRL_BEGIN" -The callback is called from \fBOSSL_trace_begin()\fR, which gives the -callback the possibility to output a dynamic starting line, or set a -prefix that should be output at the beginning of each line, or -something other. -.IP "\fB\s-1OSSL_TRACE_CTRL_WRITE\s0\fR" 4 -.IX Item "OSSL_TRACE_CTRL_WRITE" -This callback is called whenever data is written to the \s-1BIO\s0 by some -regular \s-1BIO\s0 output routine. -An arbitrary number of \fB\s-1OSSL_TRACE_CTRL_WRITE\s0\fR callbacks can occur -inside a group marked by a pair of \fB\s-1OSSL_TRACE_CTRL_BEGIN\s0\fR and -\&\fB\s-1OSSL_TRACE_CTRL_END\s0\fR calls, but never outside such a group. -.IP "\fB\s-1OSSL_TRACE_CTRL_END\s0\fR" 4 -.IX Item "OSSL_TRACE_CTRL_END" -The callback is called from \fBOSSL_trace_end()\fR, which gives the callback -the possibility to output a dynamic ending line, or reset the line -prefix that was set with \fB\s-1OSSL_TRACE_CTRL_BEGIN\s0\fR, or something other. -.SS "Trace categories" -.IX Subsection "Trace categories" -The trace categories are simple numbers available through macros. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_TRACE\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_TRACE" -Traces the OpenSSL trace \s-1API\s0 itself. -.Sp -More precisely, this will generate trace output any time a new -trace hook is set. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_INIT\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_INIT" -Traces OpenSSL library initialization and cleanup. -.Sp -This needs special care, as OpenSSL will do automatic cleanup after -exit from \f(CW\*(C`main()\*(C'\fR, and any tracing output done during this cleanup -will be lost if the tracing channel or callback were cleaned away -prematurely. -A suggestion is to make such cleanup part of a function that's -registered very early with \fBatexit\fR\|(3). -.IP "\fB\s-1OSSL_TRACE_CATEGORY_TLS\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_TLS" -Traces the \s-1TLS/SSL\s0 protocol. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_TLS_CIPHER\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_TLS_CIPHER" -Traces the ciphers used by the \s-1TLS/SSL\s0 protocol. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_CONF\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_CONF" -Traces details about the provider and engine configuration. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_ENGINE_TABLE\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_ENGINE_TABLE" -Traces the \s-1ENGINE\s0 algorithm table selection. -.Sp -More precisely, functions like \fBENGINE_get_pkey_asn1_meth_engine()\fR, -\&\fBENGINE_get_pkey_meth_engine()\fR, \fBENGINE_get_cipher_engine()\fR, -\&\fBENGINE_get_digest_engine()\fR, will generate trace summaries of the -handling of internal tables. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_ENGINE_REF_COUNT\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_ENGINE_REF_COUNT" -Traces the \s-1ENGINE\s0 reference counting. -.Sp -More precisely, both reference counts in the \s-1ENGINE\s0 structure will be -monitored with a line of trace output generated for each change. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_PKCS5V2\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_PKCS5V2" -Traces PKCS#5 v2 key generation. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_PKCS12_KEYGEN\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_PKCS12_KEYGEN" -Traces PKCS#12 key generation. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_PKCS12_DECRYPT\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_PKCS12_DECRYPT" -Traces PKCS#12 decryption. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_X509V3_POLICY\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_X509V3_POLICY" -Traces X509v3 policy processing. -.Sp -More precisely, this generates the complete policy tree at various -point during evaluation. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_BN_CTX\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_BN_CTX" -Traces \s-1BIGNUM\s0 context operations. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_CMP\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_CMP" -Traces \s-1CMP\s0 client and server activity. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_STORE\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_STORE" -Traces \s-1STORE\s0 operations. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_DECODER\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_DECODER" -Traces decoder operations. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_ENCODER\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_ENCODER" -Traces encoder operations. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_REF_COUNT\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_REF_COUNT" -Traces decrementing certain \s-1ASN.1\s0 structure references. -.IP "\fB\s-1OSSL_TRACE_CATEGORY_HTTP\s0\fR" 4 -.IX Item "OSSL_TRACE_CATEGORY_HTTP" -Traces the \s-1HTTP\s0 client, such as message headers being sent and received. -.PP -There is also \fB\s-1OSSL_TRACE_CATEGORY_ALL\s0\fR, which works as a fallback -and can be used to get \fIall\fR trace output. -.PP -Note, however, that in this case all trace output will effectively be -associated with the '\s-1ALL\s0' category, which is undesirable if the -application intends to include the category name in the trace output. -In this case it is better to register separate channels for each -trace category instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_trace_set_channel()\fR, \fBOSSL_trace_set_prefix()\fR, -\&\fBOSSL_trace_set_suffix()\fR, and \fBOSSL_trace_set_callback()\fR return 1 on -success, or 0 on failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -In all examples below, the trace producing code is assumed to be -the following: -.PP -.Vb 3 -\& int foo = 42; -\& const char bar[] = { 0, 1, 2, 3, 4, 5, 6, 7, -\& 8, 9, 10, 11, 12, 13, 14, 15 }; -\& -\& OSSL_TRACE_BEGIN(TLS) { -\& BIO_puts(trc_out, "foo: "); -\& BIO_printf(trc_out, "%d\en", foo); -\& BIO_dump(trc_out, bar, sizeof(bar)); -\& } OSSL_TRACE_END(TLS); -.Ve -.SS "Simple example" -.IX Subsection "Simple example" -An example with just a channel and constant prefix / suffix. -.PP -.Vb 6 -\& int main(int argc, char *argv[]) -\& { -\& BIO *err = BIO_new_fp(stderr, BIO_NOCLOSE | BIO_FP_TEXT); -\& OSSL_trace_set_channel(OSSL_TRACE_CATEGORY_SSL, err); -\& OSSL_trace_set_prefix(OSSL_TRACE_CATEGORY_SSL, "BEGIN TRACE[TLS]"); -\& OSSL_trace_set_suffix(OSSL_TRACE_CATEGORY_SSL, "END TRACE[TLS]"); -\& -\& /* ... work ... */ -\& } -.Ve -.PP -When the trace producing code above is performed, this will be output -on standard error: -.PP -.Vb 4 -\& BEGIN TRACE[TLS] -\& foo: 42 -\& 0000 \- 00 01 02 03 04 05 06 07\-08 09 0a 0b 0c 0d 0e 0f ................ -\& END TRACE[TLS] -.Ve -.SS "Advanced example" -.IX Subsection "Advanced example" -This example uses the callback, and depends on pthreads functionality. -.PP -.Vb 5 -\& static size_t cb(const char *buf, size_t cnt, -\& int category, int cmd, void *vdata) -\& { -\& BIO *bio = vdata; -\& const char *label = NULL; -\& -\& switch (cmd) { -\& case OSSL_TRACE_CTRL_BEGIN: -\& label = "BEGIN"; -\& break; -\& case OSSL_TRACE_CTRL_END: -\& label = "END"; -\& break; -\& } -\& -\& if (label != NULL) { -\& union { -\& pthread_t tid; -\& unsigned long ltid; -\& } tid; -\& -\& tid.tid = pthread_self(); -\& BIO_printf(bio, "%s TRACE[%s]:%lx\en", -\& label, OSSL_trace_get_category_name(category), tid.ltid); -\& } -\& return (size_t)BIO_puts(bio, buf); -\& } -\& -\& int main(int argc, char *argv[]) -\& { -\& BIO *err = BIO_new_fp(stderr, BIO_NOCLOSE | BIO_FP_TEXT); -\& OSSL_trace_set_callback(OSSL_TRACE_CATEGORY_SSL, cb, err); -\& -\& /* ... work ... */ -\& } -.Ve -.PP -The output is almost the same as for the simple example above. -.PP -.Vb 4 -\& BEGIN TRACE[TLS]:7f9eb0193b80 -\& foo: 42 -\& 0000 \- 00 01 02 03 04 05 06 07\-08 09 0a 0b 0c 0d 0e 0f ................ -\& END TRACE[TLS]:7f9eb0193b80 -.Ve -.SH "NOTES" -.IX Header "NOTES" -.SS "Configure Tracing" -.IX Subsection "Configure Tracing" -By default, the OpenSSL library is built with tracing disabled. To -use the tracing functionality documented here, it is therefore -necessary to configure and build OpenSSL with the 'enable\-trace' option. -.PP -When the library is built with tracing disabled, the macro -\&\fB\s-1OPENSSL_NO_TRACE\s0\fR is defined in \fI\fR and all -functions described here are inoperational, i.e. will do nothing. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_TRACE_ENABLED\s0\fR\|(3), \s-1\fBOSSL_TRACE_BEGIN\s0\fR\|(3), \s-1\fBOSSL_TRACE1\s0\fR\|(3), -\&\fBatexit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_trace_set_channel()\fR, \fBOSSL_trace_set_prefix()\fR, -\&\fBOSSL_trace_set_suffix()\fR, and \fBOSSL_trace_set_callback()\fR were all added -in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OSSL_trace_set_prefix.3ossl b/openssl-install/share/man/man3/OSSL_trace_set_prefix.3ossl deleted file mode 120000 index 03c51957..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_set_prefix.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_set_channel.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_trace_set_suffix.3ossl b/openssl-install/share/man/man3/OSSL_trace_set_suffix.3ossl deleted file mode 120000 index 03c51957..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_set_suffix.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_set_channel.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OSSL_trace_string.3ossl b/openssl-install/share/man/man3/OSSL_trace_string.3ossl deleted file mode 120000 index 90548a66..00000000 --- a/openssl-install/share/man/man3/OSSL_trace_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_trace_enabled.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OTHERNAME_free.3ossl b/openssl-install/share/man/man3/OTHERNAME_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OTHERNAME_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OTHERNAME_new.3ossl b/openssl-install/share/man/man3/OTHERNAME_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/OTHERNAME_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OpenSSL_add_all_algorithms.3ossl b/openssl-install/share/man/man3/OpenSSL_add_all_algorithms.3ossl deleted file mode 100644 index fd527bc9..00000000 --- a/openssl-install/share/man/man3/OpenSSL_add_all_algorithms.3ossl +++ /dev/null @@ -1,196 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_ADD_ALL_ALGORITHMS 3ossl" -.TH OPENSSL_ADD_ALL_ALGORITHMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OpenSSL_add_all_algorithms, OpenSSL_add_all_ciphers, OpenSSL_add_all_digests, EVP_cleanup \- -add algorithms to internal table -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& void OpenSSL_add_all_algorithms(void); -\& void OpenSSL_add_all_ciphers(void); -\& void OpenSSL_add_all_digests(void); -\& -\& void EVP_cleanup(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL keeps an internal table of digest algorithms and ciphers. It uses -this table to lookup ciphers via functions such as \fBEVP_get_cipher_byname()\fR. -.PP -\&\fBOpenSSL_add_all_digests()\fR adds all digest algorithms to the table. -.PP -\&\fBOpenSSL_add_all_algorithms()\fR adds all algorithms to the table (digests and -ciphers). -.PP -\&\fBOpenSSL_add_all_ciphers()\fR adds all encryption algorithms to the table including -password based encryption algorithms. -.PP -In versions prior to 1.1.0 \fBEVP_cleanup()\fR removed all ciphers and digests from -the table. It no longer has any effect in OpenSSL 1.1.0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -None of the functions return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), \fBEVP_DigestInit\fR\|(3), -\&\fBEVP_EncryptInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBOpenSSL_add_all_algorithms()\fR, \fBOpenSSL_add_all_ciphers()\fR, -\&\fBOpenSSL_add_all_digests()\fR, and \fBEVP_cleanup()\fR, functions -were deprecated in OpenSSL 1.1.0 by \fBOPENSSL_init_crypto()\fR and should -not be used. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OpenSSL_add_all_ciphers.3ossl b/openssl-install/share/man/man3/OpenSSL_add_all_ciphers.3ossl deleted file mode 120000 index 741d473b..00000000 --- a/openssl-install/share/man/man3/OpenSSL_add_all_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_add_all_algorithms.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OpenSSL_add_all_digests.3ossl b/openssl-install/share/man/man3/OpenSSL_add_all_digests.3ossl deleted file mode 120000 index 741d473b..00000000 --- a/openssl-install/share/man/man3/OpenSSL_add_all_digests.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_add_all_algorithms.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OpenSSL_add_ssl_algorithms.3ossl b/openssl-install/share/man/man3/OpenSSL_add_ssl_algorithms.3ossl deleted file mode 120000 index 2cecdc9b..00000000 --- a/openssl-install/share/man/man3/OpenSSL_add_ssl_algorithms.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_library_init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/OpenSSL_version.3ossl b/openssl-install/share/man/man3/OpenSSL_version.3ossl deleted file mode 100644 index 7bb1d949..00000000 --- a/openssl-install/share/man/man3/OpenSSL_version.3ossl +++ /dev/null @@ -1,364 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_VERSION 3ossl" -.TH OPENSSL_VERSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OPENSSL_VERSION_MAJOR, OPENSSL_VERSION_MINOR, OPENSSL_VERSION_PATCH, -OPENSSL_VERSION_PRE_RELEASE, OPENSSL_VERSION_BUILD_METADATA, -OPENSSL_VERSION_TEXT, OPENSSL_VERSION_PREREQ, OPENSSL_version_major, -OPENSSL_version_minor, OPENSSL_version_patch, OPENSSL_version_pre_release, -OPENSSL_version_build_metadata, OpenSSL_version, OPENSSL_VERSION_NUMBER, -OpenSSL_version_num, OPENSSL_info -\&\- get OpenSSL version number and other information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define OPENSSL_VERSION_MAJOR x -\& #define OPENSSL_VERSION_MINOR y -\& #define OPENSSL_VERSION_PATCH z -\& -\& /* The definitions here are typical release values */ -\& #define OPENSSL_VERSION_PRE_RELEASE "" -\& #define OPENSSL_VERSION_BUILD_METADATA "" -\& -\& #define OPENSSL_VERSION_TEXT "OpenSSL x.y.z xx XXX xxxx" -\& -\& #define OPENSSL_VERSION_PREREQ(maj,min) -\& -\& #include -\& -\& unsigned int OPENSSL_version_major(void); -\& unsigned int OPENSSL_version_minor(void); -\& unsigned int OPENSSL_version_patch(void); -\& const char *OPENSSL_version_pre_release(void); -\& const char *OPENSSL_version_build_metadata(void); -\& -\& const char *OpenSSL_version(int t); -\& -\& const char *OPENSSL_info(int t); -\& -\& /* from openssl/opensslv.h */ -\& #define OPENSSL_VERSION_NUMBER 0xnnnnnnnnL -\& -\& /* from openssl/crypto.h */ -\& unsigned long OpenSSL_version_num(); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -.SS "Macros" -.IX Subsection "Macros" -The three macros \fB\s-1OPENSSL_VERSION_MAJOR\s0\fR, \fB\s-1OPENSSL_VERSION_MINOR\s0\fR and -\&\fB\s-1OPENSSL_VERSION_PATCH\s0\fR represent the three parts of a version -identifier, \fB\f(BI\s-1MAJOR\s0\fB.\f(BI\s-1MINOR\s0\fB.\f(BI\s-1PATCH\s0\fB\fR. -.PP -The macro \fB\s-1OPENSSL_VERSION_PRE_RELEASE\s0\fR is an added bit of text that -indicates that this is a pre-release version, such as \f(CW"\-dev"\fR for an -ongoing development snapshot or \f(CW"\-alpha3"\fR for an alpha release. -The value must be a string. -.PP -The macro \fB\s-1OPENSSL_VERSION_BUILD_METADATA\s0\fR is extra information, reserved -for other parties, such as \f(CW"+fips"\fR, or \f(CW"+vendor.1"\fR). -The OpenSSL project will not touch this macro (will leave it an empty string). -The value must be a string. -.PP -\&\fB\s-1OPENSSL_VERSION_STR\s0\fR is a convenience macro to get the short version -identifier string, \f(CW"\f(CIMAJOR\f(CW.\f(CIMINOR\f(CW.\f(CIPATCH\f(CW"\fR. -.PP -\&\fB\s-1OPENSSL_FULL_VERSION_STR\s0\fR is a convenience macro to get the longer -version identifier string, which combines \fB\s-1OPENSSL_VERSION_STR\s0\fR, -\&\fB\s-1OPENSSL_VERSION_PRE_RELEASE\s0\fR and \fB\s-1OPENSSL_VERSION_BUILD_METADATA\s0\fR. -.PP -\&\fB\s-1OPENSSL_VERSION_TEXT\s0\fR is a convenience macro to get a full descriptive -version text, which includes \fB\s-1OPENSSL_FULL_VERSION_STR\s0\fR and the release -date. -.PP -\&\fB\s-1OPENSSL_VERSION_PREREQ\s0\fR is a useful macro for checking whether the OpenSSL -version for the headers in use is at least at the given pre-requisite major -(\fBmaj\fR) and minor (\fBmin\fR) number or not. It will evaluate to true if the -header version number (\fB\s-1OPENSSL_VERSION_MAJOR\s0\fR.\fB\s-1OPENSSL_VERSION_MINOR\s0\fR) is -greater than or equal to \fBmaj\fR.\fBmin\fR. -.PP -\&\fB\s-1OPENSSL_VERSION_NUMBER\s0\fR is a combination of the major, minor and -patch version into a single integer 0xMNN00PP0L, where: -.IP "M" 4 -.IX Item "M" -is the number from \fB\s-1OPENSSL_VERSION_MAJOR\s0\fR, in hexadecimal notation -.IP "\s-1NN\s0" 4 -.IX Item "NN" -is the number from \fB\s-1OPENSSL_VERSION_MINOR\s0\fR, in hexadecimal notation -.IP "\s-1PP\s0" 4 -.IX Item "PP" -is the number from \fB\s-1OPENSSL_VERSION_PATCH\s0\fR, in hexadecimal notation -.SS "Functions" -.IX Subsection "Functions" -\&\fBOPENSSL_version_major()\fR, \fBOPENSSL_version_minor()\fR, \fBOPENSSL_version_patch()\fR, -\&\fBOPENSSL_version_pre_release()\fR, and \fBOPENSSL_version_build_metadata()\fR return -the values of the macros above for the build of the library, respectively. -.PP -\&\fBOpenSSL_version()\fR returns different strings depending on \fIt\fR: -.IP "\s-1OPENSSL_VERSION\s0" 4 -.IX Item "OPENSSL_VERSION" -The value of \fB\s-1OPENSSL_VERSION_TEXT\s0\fR -.IP "\s-1OPENSSL_VERSION_STRING\s0" 4 -.IX Item "OPENSSL_VERSION_STRING" -The value of \fB\s-1OPENSSL_VERSION_STR\s0\fR -.IP "\s-1OPENSSL_FULL_VERSION_STRING\s0" 4 -.IX Item "OPENSSL_FULL_VERSION_STRING" -The value of \fB\s-1OPENSSL_FULL_VERSION_STR\s0\fR -.IP "\s-1OPENSSL_CFLAGS\s0" 4 -.IX Item "OPENSSL_CFLAGS" -The compiler flags set for the compilation process in the form -\&\f(CW\*(C`compiler: ...\*(C'\fR if available, or \f(CW\*(C`compiler: information not available\*(C'\fR -otherwise. -.IP "\s-1OPENSSL_BUILT_ON\s0" 4 -.IX Item "OPENSSL_BUILT_ON" -The date of the build process in the form \f(CW\*(C`built on: ...\*(C'\fR if available -or \f(CW\*(C`built on: date not available\*(C'\fR otherwise. -The date would not be available in a reproducible build, for example. -.IP "\s-1OPENSSL_PLATFORM\s0" 4 -.IX Item "OPENSSL_PLATFORM" -The \*(L"Configure\*(R" target of the library build in the form \f(CW\*(C`platform: ...\*(C'\fR -if available, or \f(CW\*(C`platform: information not available\*(C'\fR otherwise. -.IP "\s-1OPENSSL_DIR\s0" 4 -.IX Item "OPENSSL_DIR" -The \fB\s-1OPENSSLDIR\s0\fR setting of the library build in the form \f(CW\*(C`OPENSSLDIR: "..."\*(C'\fR -if available, or \f(CW\*(C`OPENSSLDIR: N/A\*(C'\fR otherwise. -.IP "\s-1OPENSSL_ENGINES_DIR\s0" 4 -.IX Item "OPENSSL_ENGINES_DIR" -The \fB\s-1ENGINESDIR\s0\fR setting of the library build in the form \f(CW\*(C`ENGINESDIR: "..."\*(C'\fR -if available, or \f(CW\*(C`ENGINESDIR: N/A\*(C'\fR otherwise. This option is deprecated in -OpenSSL 3.0. -.IP "\s-1OPENSSL_MODULES_DIR\s0" 4 -.IX Item "OPENSSL_MODULES_DIR" -The \fB\s-1MODULESDIR\s0\fR setting of the library build in the form \f(CW\*(C`MODULESDIR: "..."\*(C'\fR -if available, or \f(CW\*(C`MODULESDIR: N/A\*(C'\fR otherwise. -.IP "\s-1OPENSSL_CPU_INFO\s0" 4 -.IX Item "OPENSSL_CPU_INFO" -The current OpenSSL cpu settings. -This is the current setting of the cpu capability flags. It is usually -automatically configured but may be set via an environment variable. -The value has the same syntax as the environment variable. -For x86 the string looks like \f(CW\*(C`CPUINFO: OPENSSL_ia32cap=0x123:0x456\*(C'\fR -or \f(CW\*(C`CPUINFO: N/A\*(C'\fR if not available. -.IP "\s-1OPENSSL_WINCTX\s0" 4 -.IX Item "OPENSSL_WINCTX" -The Windows install context. -The Windows install context is used to compute the OpenSSL registry key name -on Windows. The full registry key is -\&\f(CW\*(C`SOFTWARE\eWOW6432Node\eOpenSSL\-{major}.{minor}\-{context}\*(C'\fR, where \f(CW\*(C`{major}\*(C'\fR, -\&\f(CW\*(C`{minor}\*(C'\fR and \f(CW\*(C`{context}\*(C'\fR are OpenSSL's major version number, minor version -number and the Windows install context, respectively. -.PP -For an unknown \fIt\fR, the text \f(CW\*(C`not available\*(C'\fR is returned. -.PP -\&\fBOPENSSL_info()\fR also returns different strings depending on \fIt\fR: -.IP "\s-1OPENSSL_INFO_CONFIG_DIR\s0" 4 -.IX Item "OPENSSL_INFO_CONFIG_DIR" -The configured \f(CW\*(C`OPENSSLDIR\*(C'\fR, which is the default location for -OpenSSL configuration files. -.IP "\s-1OPENSSL_INFO_ENGINES_DIR\s0" 4 -.IX Item "OPENSSL_INFO_ENGINES_DIR" -The configured \f(CW\*(C`ENGINESDIR\*(C'\fR, which is the default location for -OpenSSL engines. -.IP "\s-1OPENSSL_INFO_MODULES_DIR\s0" 4 -.IX Item "OPENSSL_INFO_MODULES_DIR" -The configured \f(CW\*(C`MODULESDIR\*(C'\fR, which is the default location for -dynamically loadable OpenSSL modules other than engines. -.IP "\s-1OPENSSL_INFO_DSO_EXTENSION\s0" 4 -.IX Item "OPENSSL_INFO_DSO_EXTENSION" -The configured dynamically loadable module extension. -.IP "\s-1OPENSSL_INFO_DIR_FILENAME_SEPARATOR\s0" 4 -.IX Item "OPENSSL_INFO_DIR_FILENAME_SEPARATOR" -The separator between a directory specification and a filename. -Note that on some operating systems, this is not the same as the -separator between directory elements. -.IP "\s-1OPENSSL_INFO_LIST_SEPARATOR\s0" 4 -.IX Item "OPENSSL_INFO_LIST_SEPARATOR" -The OpenSSL list separator. -This is typically used in strings that are lists of items, such as the -value of the environment variable \f(CW$PATH\fR on Unix (where the -separator is \f(CW\*(C`:\*(C'\fR) or \f(CW\*(C`%PATH%\*(C'\fR on Windows (where the separator is -\&\f(CW\*(C`;\*(C'\fR). -.IP "\s-1OPENSSL_INFO_CPU_SETTINGS\s0" 4 -.IX Item "OPENSSL_INFO_CPU_SETTINGS" -The current OpenSSL cpu settings. -This is the current setting of the cpu capability flags. It is usually -automatically configured but may be set via an environment variable. -The value has the same syntax as the environment variable. -For x86 the string looks like \f(CW\*(C`OPENSSL_ia32cap=0x123:0x456\*(C'\fR. -.IP "\s-1OPENSSL_INFO_WINDOWS_CONTEXT\s0" 4 -.IX Item "OPENSSL_INFO_WINDOWS_CONTEXT" -The Windows install context. -The Windows install context is used to compute the OpenSSL registry key name -on Windows. The full registry key is -\&\f(CW\*(C`SOFTWARE\eWOW6432Node\eOpenSSL\-{major}.{minor}\-{context}\*(C'\fR, where \f(CW\*(C`{major}\*(C'\fR, -\&\f(CW\*(C`{minor}\*(C'\fR and \f(CW\*(C`{context}\*(C'\fR are OpenSSL's major version number, minor version -number and the Windows install context, respectively. -.PP -For an unknown \fIt\fR, \s-1NULL\s0 is returned. -.PP -\&\fBOpenSSL_version_num()\fR returns the value of \fB\s-1OPENSSL_VERSION_NUMBER\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOPENSSL_version_major()\fR, \fBOPENSSL_version_minor()\fR and \fBOPENSSL_version_patch()\fR -return the version number parts as integers. -.PP -\&\fBOPENSSL_version_pre_release()\fR and \fBOPENSSL_version_build_metadata()\fR return -the values of \fB\s-1OPENSSL_VERSION_PRE_RELEASE\s0\fR and -\&\fB\s-1OPENSSL_VERSION_BUILD_METADATA\s0\fR respectively as constant strings. -For any of them that is undefined, the empty string is returned. -.PP -\&\fBOpenSSL_version()\fR returns constant strings. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The macros and functions described here were added in OpenSSL 3.0, -except for \s-1OPENSSL_VERSION_NUMBER\s0 and \fBOpenSSL_version_num()\fR. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/OpenSSL_version_num.3ossl b/openssl-install/share/man/man3/OpenSSL_version_num.3ossl deleted file mode 120000 index 8d69450d..00000000 --- a/openssl-install/share/man/man3/OpenSSL_version_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -OpenSSL_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBE2PARAM_free.3ossl b/openssl-install/share/man/man3/PBE2PARAM_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBE2PARAM_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBE2PARAM_new.3ossl b/openssl-install/share/man/man3/PBE2PARAM_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBE2PARAM_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBEPARAM_free.3ossl b/openssl-install/share/man/man3/PBEPARAM_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBEPARAM_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBEPARAM_new.3ossl b/openssl-install/share/man/man3/PBEPARAM_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBEPARAM_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBKDF2PARAM_free.3ossl b/openssl-install/share/man/man3/PBKDF2PARAM_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBKDF2PARAM_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBKDF2PARAM_new.3ossl b/openssl-install/share/man/man3/PBKDF2PARAM_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBKDF2PARAM_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBMAC1PARAM_free.3ossl b/openssl-install/share/man/man3/PBMAC1PARAM_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBMAC1PARAM_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBMAC1PARAM_it.3ossl b/openssl-install/share/man/man3/PBMAC1PARAM_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBMAC1PARAM_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBMAC1PARAM_new.3ossl b/openssl-install/share/man/man3/PBMAC1PARAM_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PBMAC1PARAM_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PBMAC1_get1_pbkdf2_param.3ossl b/openssl-install/share/man/man3/PBMAC1_get1_pbkdf2_param.3ossl deleted file mode 100644 index 04aa2d9a..00000000 --- a/openssl-install/share/man/man3/PBMAC1_get1_pbkdf2_param.3ossl +++ /dev/null @@ -1,176 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PBMAC1_GET1_PBKDF2_PARAM 3ossl" -.TH PBMAC1_GET1_PBKDF2_PARAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PBMAC1_get1_pbkdf2_param \- Function to manipulate a PBMAC1 -MAC structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PBKDF2PARAM *PBMAC1_get1_pbkdf2_param(const X509_ALGOR *macalg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPBMAC1_get1_pbkdf2_param()\fR retrieves a \fB\s-1PBKDF2PARAM\s0\fR structure from an -\&\fIX509_ALGOR\fR structure. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPBMAC1_get1_pbkdf2_param()\fR returns \s-1NULL\s0 in case when \s-1PBMAC1\s0 uses an algorithm -apart from \fB\s-1PBKDF2\s0\fR or when passed incorrect parameters and a pointer to -\&\fB\s-1PBKDF2PARAM\s0\fR structure otherwise. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 9579\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-pkcs12\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fIPBMAC1_get1_pbkdf2_param\fR function was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_FLAG_EAY_COMPATIBLE.3ossl b/openssl-install/share/man/man3/PEM_FLAG_EAY_COMPATIBLE.3ossl deleted file mode 120000 index a17e737d..00000000 --- a/openssl-install/share/man/man3/PEM_FLAG_EAY_COMPATIBLE.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_FLAG_ONLY_B64.3ossl b/openssl-install/share/man/man3/PEM_FLAG_ONLY_B64.3ossl deleted file mode 120000 index a17e737d..00000000 --- a/openssl-install/share/man/man3/PEM_FLAG_ONLY_B64.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_FLAG_SECURE.3ossl b/openssl-install/share/man/man3/PEM_FLAG_SECURE.3ossl deleted file mode 120000 index a17e737d..00000000 --- a/openssl-install/share/man/man3/PEM_FLAG_SECURE.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_X509_INFO_read.3ossl b/openssl-install/share/man/man3/PEM_X509_INFO_read.3ossl deleted file mode 120000 index ae685634..00000000 --- a/openssl-install/share/man/man3/PEM_X509_INFO_read.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_X509_INFO_read_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_X509_INFO_read_bio.3ossl b/openssl-install/share/man/man3/PEM_X509_INFO_read_bio.3ossl deleted file mode 120000 index ae685634..00000000 --- a/openssl-install/share/man/man3/PEM_X509_INFO_read_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_X509_INFO_read_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_X509_INFO_read_bio_ex.3ossl b/openssl-install/share/man/man3/PEM_X509_INFO_read_bio_ex.3ossl deleted file mode 100644 index 63485ed3..00000000 --- a/openssl-install/share/man/man3/PEM_X509_INFO_read_bio_ex.3ossl +++ /dev/null @@ -1,214 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_X509_INFO_READ_BIO_EX 3ossl" -.TH PEM_X509_INFO_READ_BIO_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PEM_X509_INFO_read_ex, PEM_X509_INFO_read, PEM_X509_INFO_read_bio_ex, PEM_X509_INFO_read_bio -\&\- read PEM\-encoded data structures into one or more X509_INFO objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(X509_INFO) *PEM_X509_INFO_read_ex(FILE *fp, STACK_OF(X509_INFO) *sk, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, -\& const char *propq); -\& STACK_OF(X509_INFO) *PEM_X509_INFO_read(FILE *fp, STACK_OF(X509_INFO) *sk, -\& pem_password_cb *cb, void *u); -\& STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bio, -\& STACK_OF(X509_INFO) *sk, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, -\& const char *propq); -\& STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio(BIO *bp, STACK_OF(X509_INFO) *sk, -\& pem_password_cb *cb, void *u); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPEM_X509_INFO_read_ex()\fR loads the \fBX509_INFO\fR objects from a file \fIfp\fR. -.PP -\&\fBPEM_X509_INFO_read()\fR is similar to \fBPEM_X509_INFO_read_ex()\fR -but uses the default (\s-1NULL\s0) library context \fIlibctx\fR -and empty property query \fIpropq\fR. -.PP -\&\fBPEM_X509_INFO_read_bio_ex()\fR loads the \fBX509_INFO\fR objects using a bio \fIbp\fR. -.PP -\&\fBPEM_X509_INFO_read_bio()\fR is similar to \fBPEM_X509_INFO_read_bio_ex()\fR -but uses the default (\s-1NULL\s0) library context \fIlibctx\fR -and empty property query \fIpropq\fR. -.PP -Each of the loaded \fBX509_INFO\fR objects can contain a \s-1CRL,\s0 a certificate, -and/or a private key. -The elements are read sequentially, and as far as they are of different type than -the elements read before, they are combined into the same \fBX509_INFO\fR object. -The idea behind this is that if, for instance, a certificate is followed by -a private key, the private key is supposed to correspond to the certificate. -.PP -If the input stack \fIsk\fR is \s-1NULL\s0 a new stack is allocated, -else the given stack is extended. -.PP -The optional \fIcb\fR and \fIu\fR parameters can be used for providing a pass phrase -needed for decrypting encrypted \s-1PEM\s0 structures (normally only private keys). -See \fBPEM_read_bio_PrivateKey\fR\|(3) and \fBpassphrase\-encoding\fR\|(7) for details. -.PP -The library context \fIlibctx\fR and property query \fIpropq\fR are used for fetching -algorithms from providers. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPEM_X509_INFO_read_ex()\fR, \fBPEM_X509_INFO_read()\fR, -\&\fBPEM_X509_INFO_read_bio_ex()\fR and \fBPEM_X509_INFO_read_bio()\fR return -a stack of \fBX509_INFO\fR objects or \s-1NULL\s0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPEM_read_bio_ex\fR\|(3), -\&\fBPEM_read_bio_PrivateKey\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBPEM_X509_INFO_read_ex()\fR and -\&\fBPEM_X509_INFO_read_bio_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_X509_INFO_read_ex.3ossl b/openssl-install/share/man/man3/PEM_X509_INFO_read_ex.3ossl deleted file mode 120000 index ae685634..00000000 --- a/openssl-install/share/man/man3/PEM_X509_INFO_read_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_X509_INFO_read_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_bytes_read_bio.3ossl b/openssl-install/share/man/man3/PEM_bytes_read_bio.3ossl deleted file mode 100644 index 7e5d43a4..00000000 --- a/openssl-install/share/man/man3/PEM_bytes_read_bio.3ossl +++ /dev/null @@ -1,216 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_BYTES_READ_BIO 3ossl" -.TH PEM_BYTES_READ_BIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PEM_bytes_read_bio, PEM_bytes_read_bio_secmem \- read a PEM\-encoded data structure from a BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PEM_bytes_read_bio(unsigned char **pdata, long *plen, char **pnm, -\& const char *name, BIO *bp, pem_password_cb *cb, -\& void *u); -\& int PEM_bytes_read_bio_secmem(unsigned char **pdata, long *plen, char **pnm, -\& const char *name, BIO *bp, pem_password_cb *cb, -\& void *u); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPEM_bytes_read_bio()\fR reads PEM-formatted (\s-1IETF RFC 1421\s0 and \s-1IETF RFC 7468\s0) -data from the \s-1BIO\s0 -\&\fIbp\fR for the data type given in \fIname\fR (\s-1RSA PRIVATE KEY, CERTIFICATE,\s0 -etc.). If multiple PEM-encoded data structures are present in the same -stream, \fBPEM_bytes_read_bio()\fR will skip non-matching data types and -continue reading. Non-PEM data present in the stream may cause an -error. -.PP -The \s-1PEM\s0 header may indicate that the following data is encrypted; if so, -the data will be decrypted, waiting on user input to supply a passphrase -if needed. The password callback \fIcb\fR and rock \fIu\fR are used to obtain -the decryption passphrase, if applicable. -.PP -Some data types have compatibility aliases, such as a file containing -X509 \s-1CERTIFICATE\s0 matching a request for the deprecated type \s-1CERTIFICATE.\s0 -The actual type indicated by the file is returned in \fI*pnm\fR if \fIpnm\fR is -non-NULL. The caller must free the storage pointed to by \fI*pnm\fR. -.PP -The returned data is the DER-encoded form of the requested type, in -\&\fI*pdata\fR with length \fI*plen\fR. The caller must free the storage pointed -to by \fI*pdata\fR. -.PP -\&\fBPEM_bytes_read_bio_secmem()\fR is similar to \fBPEM_bytes_read_bio()\fR, but uses -memory from the secure heap for its temporary buffers and the storage -returned in \fI*pdata\fR and \fI*pnm\fR. Accordingly, the caller must use -\&\fBOPENSSL_secure_free()\fR to free that storage. -.SH "NOTES" -.IX Header "NOTES" -\&\fBPEM_bytes_read_bio_secmem()\fR only enforces that the secure heap is used for -storage allocated within the \s-1PEM\s0 processing stack. The \s-1BIO\s0 stack from -which input is read may also use temporary buffers, which are not necessarily -allocated from the secure heap. In cases where it is desirable to ensure -that the contents of the \s-1PEM\s0 file only appears in memory from the secure heap, -care is needed in generating the \s-1BIO\s0 passed as \fIbp\fR. In particular, the -use of \fBBIO_s_file()\fR indicates the use of the operating system stdio -functionality, which includes buffering as a feature; \fBBIO_s_fd()\fR is likely -to be more appropriate in such cases. -.PP -These functions make no assumption regarding the pass phrase received from the -password callback. -It will simply be treated as a byte sequence. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPEM_bytes_read_bio()\fR and \fBPEM_bytes_read_bio_secmem()\fR return 1 for success or -0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPEM_read_bio_ex\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPEM_bytes_read_bio_secmem()\fR was introduced in OpenSSL 1.1.1 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_bytes_read_bio_secmem.3ossl b/openssl-install/share/man/man3/PEM_bytes_read_bio_secmem.3ossl deleted file mode 120000 index eb78ff87..00000000 --- a/openssl-install/share/man/man3/PEM_bytes_read_bio_secmem.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_bytes_read_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_do_header.3ossl b/openssl-install/share/man/man3/PEM_do_header.3ossl deleted file mode 120000 index 3953a8a7..00000000 --- a/openssl-install/share/man/man3/PEM_do_header.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_get_EVP_CIPHER_INFO.3ossl b/openssl-install/share/man/man3/PEM_get_EVP_CIPHER_INFO.3ossl deleted file mode 120000 index 3953a8a7..00000000 --- a/openssl-install/share/man/man3/PEM_get_EVP_CIPHER_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read.3ossl b/openssl-install/share/man/man3/PEM_read.3ossl deleted file mode 100644 index 43690533..00000000 --- a/openssl-install/share/man/man3/PEM_read.3ossl +++ /dev/null @@ -1,265 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_READ 3ossl" -.TH PEM_READ 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PEM_write, PEM_write_bio, -PEM_read, PEM_read_bio, PEM_do_header, PEM_get_EVP_CIPHER_INFO -\&\- PEM encoding routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PEM_write(FILE *fp, const char *name, const char *header, -\& const unsigned char *data, long len); -\& int PEM_write_bio(BIO *bp, const char *name, const char *header, -\& const unsigned char *data, long len); -\& -\& int PEM_read(FILE *fp, char **name, char **header, -\& unsigned char **data, long *len); -\& int PEM_read_bio(BIO *bp, char **name, char **header, -\& unsigned char **data, long *len); -\& -\& int PEM_get_EVP_CIPHER_INFO(char *header, EVP_CIPHER_INFO *cinfo); -\& int PEM_do_header(EVP_CIPHER_INFO *cinfo, unsigned char *data, long *len, -\& pem_password_cb *cb, void *u); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions read and write PEM-encoded objects, using the \s-1PEM\s0 -type \fBname\fR, any additional \fBheader\fR information, and the raw -\&\fBdata\fR of length \fBlen\fR. -.PP -\&\s-1PEM\s0 is the term used for binary content encoding first defined in \s-1IETF -RFC 1421.\s0 The content is a series of base64\-encoded lines, surrounded -by begin/end markers each on their own line. For example: -.PP -.Vb 4 -\& \-\-\-\-\-BEGIN PRIVATE KEY\-\-\-\-\- -\& MIICdg.... -\& ... bhTQ== -\& \-\-\-\-\-END PRIVATE KEY\-\-\-\-\- -.Ve -.PP -Optional header line(s) may appear after the begin line, and their -existence depends on the type of object being written or read. -.PP -\&\fBPEM_write()\fR writes to the file \fBfp\fR, while \fBPEM_write_bio()\fR writes to -the \s-1BIO\s0 \fBbp\fR. The \fBname\fR is the name to use in the marker, the -\&\fBheader\fR is the header value or \s-1NULL,\s0 and \fBdata\fR and \fBlen\fR specify -the data and its length. -.PP -The final \fBdata\fR buffer is typically an \s-1ASN.1\s0 object which can be decoded with -the \fBd2i\fR function appropriate to the type \fBname\fR; see \fBd2i_X509\fR\|(3) -for examples. -.PP -\&\fBPEM_read()\fR reads from the file \fBfp\fR, while \fBPEM_read_bio()\fR reads -from the \s-1BIO\s0 \fBbp\fR. -Both skip any non-PEM data that precedes the start of the next \s-1PEM\s0 object. -When an object is successfully retrieved, the type name from the \*(L"\-\-\-\-BEGIN -\-\-\-\-\-\*(R" is returned via the \fBname\fR argument, any encapsulation headers -are returned in \fBheader\fR and the base64\-decoded content and its length are -returned via \fBdata\fR and \fBlen\fR respectively. -The \fBname\fR, \fBheader\fR and \fBdata\fR pointers are allocated via \fBOPENSSL_malloc()\fR -and should be freed by the caller via \fBOPENSSL_free()\fR when no longer needed. -.PP -\&\fBPEM_get_EVP_CIPHER_INFO()\fR can be used to determine the \fBdata\fR returned by -\&\fBPEM_read()\fR or \fBPEM_read_bio()\fR is encrypted and to retrieve the associated cipher -and \s-1IV.\s0 -The caller passes a pointer to structure of type \fB\s-1EVP_CIPHER_INFO\s0\fR via the -\&\fBcinfo\fR argument and the \fBheader\fR returned via \fBPEM_read()\fR or \fBPEM_read_bio()\fR. -If the call is successful 1 is returned and the cipher and \s-1IV\s0 are stored at the -address pointed to by \fBcinfo\fR. -When the header is malformed, or not supported or when the cipher is unknown -or some internal error happens 0 is returned. -This function is deprecated, see \fB\s-1NOTES\s0\fR below. -.PP -\&\fBPEM_do_header()\fR can then be used to decrypt the data if the header -indicates encryption. -The \fBcinfo\fR argument is a pointer to the structure initialized by the previous -call to \fBPEM_get_EVP_CIPHER_INFO()\fR. -The \fBdata\fR and \fBlen\fR arguments are those returned by the previous call to -\&\fBPEM_read()\fR or \fBPEM_read_bio()\fR. -The \fBcb\fR and \fBu\fR arguments make it possible to override the default password -prompt function as described in \fBPEM_read_PrivateKey\fR\|(3). -On successful completion the \fBdata\fR is decrypted in place, and \fBlen\fR is -updated to indicate the plaintext length. -This function is deprecated, see \fB\s-1NOTES\s0\fR below. -.PP -If the data is a priori known to not be encrypted, then neither \fBPEM_do_header()\fR -nor \fBPEM_get_EVP_CIPHER_INFO()\fR need be called. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPEM_read()\fR and \fBPEM_read_bio()\fR return 1 on success and 0 on failure, the latter -includes the case when no more \s-1PEM\s0 objects remain in the input file. -To distinguish end of file from more serious errors the caller must peek at the -error stack and check for \fB\s-1PEM_R_NO_START_LINE\s0\fR, which indicates that no more -\&\s-1PEM\s0 objects were found. See \fBERR_peek_last_error\fR\|(3), \s-1\fBERR_GET_REASON\s0\fR\|(3). -.PP -\&\fBPEM_get_EVP_CIPHER_INFO()\fR and \fBPEM_do_header()\fR return 1 on success, and 0 on -failure. -The \fBdata\fR is likely meaningless if these functions fail. -.SH "NOTES" -.IX Header "NOTES" -The \fBPEM_get_EVP_CIPHER_INFO()\fR and \fBPEM_do_header()\fR functions are deprecated. -This is because the underlying \s-1PEM\s0 encryption format is obsolete, and should -be avoided. -It uses an encryption format with an OpenSSL-specific key-derivation function, -which employs \s-1MD5\s0 with an iteration count of 1! -Instead, private keys should be stored in PKCS#8 form, with a strong PKCS#5 -v2.0 \s-1PBE.\s0 -See \fBPEM_write_PrivateKey\fR\|(3) and \fBd2i_PKCS8PrivateKey_bio\fR\|(3). -.PP -\&\fBPEM_do_header()\fR makes no assumption regarding the pass phrase received from the -password callback. -It will simply be treated as a byte sequence. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_peek_last_error\fR\|(3), \s-1\fBERR_GET_LIB\s0\fR\|(3), -\&\fBd2i_PKCS8PrivateKey_bio\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 1998\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_read_CMS.3ossl b/openssl-install/share/man/man3/PEM_read_CMS.3ossl deleted file mode 100644 index a28a7714..00000000 --- a/openssl-install/share/man/man3/PEM_read_CMS.3ossl +++ /dev/null @@ -1,282 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_READ_CMS 3ossl" -.TH PEM_READ_CMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DECLARE_PEM_rw, -PEM_read_CMS, -PEM_read_bio_CMS, -PEM_write_CMS, -PEM_write_bio_CMS, -PEM_write_DHxparams, -PEM_write_bio_DHxparams, -PEM_read_ECPKParameters, -PEM_read_bio_ECPKParameters, -PEM_write_ECPKParameters, -PEM_write_bio_ECPKParameters, -PEM_read_ECPrivateKey, -PEM_write_ECPrivateKey, -PEM_write_bio_ECPrivateKey, -PEM_read_EC_PUBKEY, -PEM_read_bio_EC_PUBKEY, -PEM_write_EC_PUBKEY, -PEM_write_bio_EC_PUBKEY, -PEM_read_NETSCAPE_CERT_SEQUENCE, -PEM_read_bio_NETSCAPE_CERT_SEQUENCE, -PEM_write_NETSCAPE_CERT_SEQUENCE, -PEM_write_bio_NETSCAPE_CERT_SEQUENCE, -PEM_read_PKCS8, -PEM_read_bio_PKCS8, -PEM_write_PKCS8, -PEM_write_bio_PKCS8, -PEM_write_PKCS8_PRIV_KEY_INFO, -PEM_read_bio_PKCS8_PRIV_KEY_INFO, -PEM_read_PKCS8_PRIV_KEY_INFO, -PEM_write_bio_PKCS8_PRIV_KEY_INFO, -PEM_read_SSL_SESSION, -PEM_read_bio_SSL_SESSION, -PEM_write_SSL_SESSION, -PEM_write_bio_SSL_SESSION, -PEM_read_X509_PUBKEY, -PEM_read_bio_X509_PUBKEY, -PEM_write_X509_PUBKEY, -PEM_write_bio_X509_PUBKEY -\&\- PEM object encoding routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& DECLARE_PEM_rw(name, TYPE) -\& -\& TYPE *PEM_read_TYPE(FILE *fp, TYPE **a, pem_password_cb *cb, void *u); -\& TYPE *PEM_read_bio_TYPE(BIO *bp, TYPE **a, pem_password_cb *cb, void *u); -\& int PEM_write_TYPE(FILE *fp, const TYPE *a); -\& int PEM_write_bio_TYPE(BIO *bp, const TYPE *a); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #include -\& -\& int PEM_write_DHxparams(FILE *out, const DH *dh); -\& int PEM_write_bio_DHxparams(BIO *out, const DH *dh); -\& EC_GROUP *PEM_read_ECPKParameters(FILE *fp, EC_GROUP **x, pem_password_cb *cb, void *u); -\& EC_GROUP *PEM_read_bio_ECPKParameters(BIO *bp, EC_GROUP **x, pem_password_cb *cb, void *u); -\& int PEM_write_ECPKParameters(FILE *out, const EC_GROUP *x); -\& int PEM_write_bio_ECPKParameters(BIO *out, const EC_GROUP *x), -\& -\& EC_KEY *PEM_read_EC_PUBKEY(FILE *fp, EC_KEY **x, pem_password_cb *cb, void *u); -\& EC_KEY *PEM_read_bio_EC_PUBKEY(BIO *bp, EC_KEY **x, pem_password_cb *cb, void *u); -\& int PEM_write_EC_PUBKEY(FILE *out, const EC_KEY *x); -\& int PEM_write_bio_EC_PUBKEY(BIO *out, const EC_KEY *x); -\& -\& EC_KEY *PEM_read_ECPrivateKey(FILE *out, EC_KEY **x, pem_password_cb *cb, void *u); -\& EC_KEY *PEM_read_bio_ECPrivateKey(BIO *out, EC_KEY **x, pem_password_cb *cb, void *u); -\& int PEM_write_ECPrivateKey(FILE *out, const EC_KEY *x, const EVP_CIPHER *enc, -\& const unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_ECPrivateKey(BIO *out, const EC_KEY *x, const EVP_CIPHER *enc, -\& const unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should use \fBOSSL_ENCODER_to_bio()\fR and \fBOSSL_DECODER_from_bio()\fR -instead. -.PP -In the description below, \fB\f(BI\s-1TYPE\s0\fB\fR is used -as a placeholder for any of the OpenSSL datatypes, such as \fBX509\fR. -The macro \fBDECLARE_PEM_rw\fR expands to the set of declarations shown in -the next four lines of the synopsis. -.PP -These routines convert between local instances of \s-1ASN1\s0 datatypes and -the \s-1PEM\s0 encoding. For more information on the templates, see -\&\s-1\fBASN1_ITEM\s0\fR\|(3). For more information on the lower-level routines used -by the functions here, see \fBPEM_read\fR\|(3). -.PP -\&\fBPEM_read_\f(BI\s-1TYPE\s0\fB\fR() reads a PEM-encoded object of \fB\f(BI\s-1TYPE\s0\fB\fR from the file -\&\fIfp\fR and returns it. The \fIcb\fR and \fIu\fR parameters are as described in -\&\fBpem_password_cb\fR\|(3). -.PP -\&\fBPEM_read_bio_\f(BI\s-1TYPE\s0\fB\fR() is similar to \fBPEM_read_\f(BI\s-1TYPE\s0\fB\fR() but reads from -the \s-1BIO\s0 \fIbp\fR. -.PP -\&\fBPEM_write_\f(BI\s-1TYPE\s0\fB\fR() writes the \s-1PEM\s0 encoding of the object \fIa\fR to the file -\&\fIfp\fR. -.PP -\&\fBPEM_write_bio_\f(BI\s-1TYPE\s0\fB\fR() similarly writes to the \s-1BIO\s0 \fIbp\fR. -.SH "NOTES" -.IX Header "NOTES" -These functions make no assumption regarding the pass phrase received from the -password callback. -It will simply be treated as a byte sequence. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPEM_read_\f(BI\s-1TYPE\s0\fB\fR() and \fBPEM_read_bio_\f(BI\s-1TYPE\s0\fB\fR() return a pointer to an -allocated object, which should be released by calling \fB\f(BI\s-1TYPE\s0\fB_free\fR(), or -\&\s-1NULL\s0 on error. -.PP -\&\fBPEM_write_\f(BI\s-1TYPE\s0\fB\fR() and \fBPEM_write_bio_\f(BI\s-1TYPE\s0\fB\fR() return 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPEM_read\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBPEM_write_DHxparams()\fR, \fBPEM_write_bio_DHxparams()\fR, -\&\fBPEM_read_ECPKParameters()\fR, \fBPEM_read_bio_ECPKParameters()\fR, -\&\fBPEM_write_ECPKParameters()\fR, \fBPEM_write_bio_ECPKParameters()\fR, -\&\fBPEM_read_EC_PUBKEY()\fR, \fBPEM_read_bio_EC_PUBKEY()\fR, -\&\fBPEM_write_EC_PUBKEY()\fR, \fBPEM_write_bio_EC_PUBKEY()\fR, -\&\fBPEM_read_ECPrivateKey()\fR, \fBPEM_read_bio_ECPrivateKey()\fR, -\&\fBPEM_write_ECPrivateKey()\fR and \fBPEM_write_bio_ECPrivateKey()\fR -were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 1998\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_read_DHparams.3ossl b/openssl-install/share/man/man3/PEM_read_DHparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_DHparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_DSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_read_DSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_DSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_DSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_DSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_DSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_DSAparams.3ossl b/openssl-install/share/man/man3/PEM_read_DSAparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_DSAparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_ECPKParameters.3ossl b/openssl-install/share/man/man3/PEM_read_ECPKParameters.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_ECPKParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_ECPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_read_ECPrivateKey.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_ECPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_EC_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_EC_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_EC_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_NETSCAPE_CERT_SEQUENCE.3ossl b/openssl-install/share/man/man3/PEM_read_NETSCAPE_CERT_SEQUENCE.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_NETSCAPE_CERT_SEQUENCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_PKCS7.3ossl b/openssl-install/share/man/man3/PEM_read_PKCS7.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_PKCS7.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_PKCS8.3ossl b/openssl-install/share/man/man3/PEM_read_PKCS8.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_PKCS8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_PKCS8_PRIV_KEY_INFO.3ossl b/openssl-install/share/man/man3/PEM_read_PKCS8_PRIV_KEY_INFO.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_PKCS8_PRIV_KEY_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_PUBKEY_ex.3ossl b/openssl-install/share/man/man3/PEM_read_PUBKEY_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_PUBKEY_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_PrivateKey.3ossl b/openssl-install/share/man/man3/PEM_read_PrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_PrivateKey_ex.3ossl b/openssl-install/share/man/man3/PEM_read_PrivateKey_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_PrivateKey_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_read_RSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_RSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_RSAPublicKey.3ossl b/openssl-install/share/man/man3/PEM_read_RSAPublicKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_RSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_RSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_RSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_RSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_SSL_SESSION.3ossl b/openssl-install/share/man/man3/PEM_read_SSL_SESSION.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_SSL_SESSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_X509.3ossl b/openssl-install/share/man/man3/PEM_read_X509.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_X509.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_X509_ACERT.3ossl b/openssl-install/share/man/man3/PEM_read_X509_ACERT.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_X509_ACERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_X509_AUX.3ossl b/openssl-install/share/man/man3/PEM_read_X509_AUX.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_X509_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_X509_CRL.3ossl b/openssl-install/share/man/man3/PEM_read_X509_CRL.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_X509_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_X509_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_X509_REQ.3ossl b/openssl-install/share/man/man3/PEM_read_X509_REQ.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_X509_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio.3ossl b/openssl-install/share/man/man3/PEM_read_bio.3ossl deleted file mode 120000 index 3953a8a7..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_CMS.3ossl b/openssl-install/share/man/man3/PEM_read_bio_CMS.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_CMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_DHparams.3ossl b/openssl-install/share/man/man3/PEM_read_bio_DHparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_DHparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_DSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_read_bio_DSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_DSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_DSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_bio_DSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_DSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_DSAparams.3ossl b/openssl-install/share/man/man3/PEM_read_bio_DSAparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_DSAparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_ECPKParameters.3ossl b/openssl-install/share/man/man3/PEM_read_bio_ECPKParameters.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_ECPKParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_EC_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_bio_EC_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_EC_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_NETSCAPE_CERT_SEQUENCE.3ossl b/openssl-install/share/man/man3/PEM_read_bio_NETSCAPE_CERT_SEQUENCE.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_NETSCAPE_CERT_SEQUENCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_PKCS7.3ossl b/openssl-install/share/man/man3/PEM_read_bio_PKCS7.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_PKCS7.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_PKCS8.3ossl b/openssl-install/share/man/man3/PEM_read_bio_PKCS8.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_PKCS8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_PKCS8_PRIV_KEY_INFO.3ossl b/openssl-install/share/man/man3/PEM_read_bio_PKCS8_PRIV_KEY_INFO.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_PKCS8_PRIV_KEY_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_bio_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_PUBKEY_ex.3ossl b/openssl-install/share/man/man3/PEM_read_bio_PUBKEY_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_PUBKEY_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_Parameters.3ossl b/openssl-install/share/man/man3/PEM_read_bio_Parameters.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_Parameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_Parameters_ex.3ossl b/openssl-install/share/man/man3/PEM_read_bio_Parameters_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_Parameters_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_PrivateKey.3ossl b/openssl-install/share/man/man3/PEM_read_bio_PrivateKey.3ossl deleted file mode 100644 index 44730fb3..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_PrivateKey.3ossl +++ /dev/null @@ -1,753 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_READ_BIO_PRIVATEKEY 3ossl" -.TH PEM_READ_BIO_PRIVATEKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -pem_password_cb, -PEM_read_bio_PrivateKey_ex, PEM_read_bio_PrivateKey, -PEM_read_PrivateKey_ex, PEM_read_PrivateKey, -PEM_write_bio_PrivateKey_ex, PEM_write_bio_PrivateKey, -PEM_write_bio_PrivateKey_traditional, -PEM_write_PrivateKey_ex, PEM_write_PrivateKey, -PEM_write_bio_PKCS8PrivateKey, PEM_write_PKCS8PrivateKey, -PEM_write_bio_PKCS8PrivateKey_nid, PEM_write_PKCS8PrivateKey_nid, -PEM_read_bio_PUBKEY_ex, PEM_read_bio_PUBKEY, -PEM_read_PUBKEY_ex, PEM_read_PUBKEY, -PEM_write_bio_PUBKEY_ex, PEM_write_bio_PUBKEY, -PEM_write_PUBKEY_ex, PEM_write_PUBKEY, -PEM_read_bio_RSAPrivateKey, PEM_read_RSAPrivateKey, -PEM_write_bio_RSAPrivateKey, PEM_write_RSAPrivateKey, -PEM_read_bio_RSAPublicKey, PEM_read_RSAPublicKey, PEM_write_bio_RSAPublicKey, -PEM_write_RSAPublicKey, PEM_read_bio_RSA_PUBKEY, PEM_read_RSA_PUBKEY, -PEM_write_bio_RSA_PUBKEY, PEM_write_RSA_PUBKEY, PEM_read_bio_DSAPrivateKey, -PEM_read_DSAPrivateKey, PEM_write_bio_DSAPrivateKey, PEM_write_DSAPrivateKey, -PEM_read_bio_DSA_PUBKEY, PEM_read_DSA_PUBKEY, PEM_write_bio_DSA_PUBKEY, -PEM_write_DSA_PUBKEY, PEM_read_bio_Parameters_ex, PEM_read_bio_Parameters, -PEM_write_bio_Parameters, PEM_read_bio_DSAparams, PEM_read_DSAparams, -PEM_write_bio_DSAparams, PEM_write_DSAparams, PEM_read_bio_DHparams, -PEM_read_DHparams, PEM_write_bio_DHparams, PEM_write_DHparams, -PEM_read_bio_X509, PEM_read_X509, PEM_write_bio_X509, PEM_write_X509, -PEM_read_bio_X509_ACERT, PEM_read_X509_ACERT, -PEM_write_bio_X509_ACERT, PEM_write_X509_ACERT, -PEM_read_bio_X509_AUX, PEM_read_X509_AUX, PEM_write_bio_X509_AUX, -PEM_write_X509_AUX, PEM_read_bio_X509_REQ, PEM_read_X509_REQ, -PEM_write_bio_X509_REQ, PEM_write_X509_REQ, PEM_write_bio_X509_REQ_NEW, -PEM_write_X509_REQ_NEW, PEM_read_bio_X509_CRL, PEM_read_X509_CRL, -PEM_write_bio_X509_CRL, PEM_write_X509_CRL, PEM_read_bio_PKCS7, PEM_read_PKCS7, -PEM_write_bio_PKCS7, PEM_write_PKCS7 \- PEM routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int pem_password_cb(char *buf, int size, int rwflag, void *u); -\& -\& EVP_PKEY *PEM_read_bio_PrivateKey_ex(BIO *bp, EVP_PKEY **x, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& EVP_PKEY *PEM_read_bio_PrivateKey(BIO *bp, EVP_PKEY **x, -\& pem_password_cb *cb, void *u); -\& EVP_PKEY *PEM_read_PrivateKey_ex(FILE *fp, EVP_PKEY **x, pem_password_cb *cb, -\& void *u, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& EVP_PKEY *PEM_read_PrivateKey(FILE *fp, EVP_PKEY **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_PrivateKey_ex(BIO *bp, const EVP_PKEY *x, -\& const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int PEM_write_bio_PrivateKey(BIO *bp, const EVP_PKEY *x, const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_PrivateKey_traditional(BIO *bp, EVP_PKEY *x, -\& const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_PrivateKey_ex(FILE *fp, EVP_PKEY *x, const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int PEM_write_PrivateKey(FILE *fp, EVP_PKEY *x, const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_PKCS8PrivateKey(BIO *bp, EVP_PKEY *x, const EVP_CIPHER *enc, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_PKCS8PrivateKey(FILE *fp, EVP_PKEY *x, const EVP_CIPHER *enc, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_PKCS8PrivateKey_nid(BIO *bp, const EVP_PKEY *x, int nid, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_PKCS8PrivateKey_nid(FILE *fp, const EVP_PKEY *x, int nid, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& -\& EVP_PKEY *PEM_read_bio_PUBKEY_ex(BIO *bp, EVP_PKEY **x, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& EVP_PKEY *PEM_read_bio_PUBKEY(BIO *bp, EVP_PKEY **x, -\& pem_password_cb *cb, void *u); -\& EVP_PKEY *PEM_read_PUBKEY_ex(FILE *fp, EVP_PKEY **x, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& EVP_PKEY *PEM_read_PUBKEY(FILE *fp, EVP_PKEY **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_PUBKEY_ex(BIO *bp, EVP_PKEY *x, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int PEM_write_bio_PUBKEY(BIO *bp, EVP_PKEY *x); -\& int PEM_write_PUBKEY_ex(FILE *fp, EVP_PKEY *x, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int PEM_write_PUBKEY(FILE *fp, EVP_PKEY *x); -\& -\& EVP_PKEY *PEM_read_bio_Parameters_ex(BIO *bp, EVP_PKEY **x, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& EVP_PKEY *PEM_read_bio_Parameters(BIO *bp, EVP_PKEY **x); -\& int PEM_write_bio_Parameters(BIO *bp, const EVP_PKEY *x); -\& -\& X509 *PEM_read_bio_X509(BIO *bp, X509 **x, pem_password_cb *cb, void *u); -\& X509 *PEM_read_X509(FILE *fp, X509 **x, pem_password_cb *cb, void *u); -\& int PEM_write_bio_X509(BIO *bp, X509 *x); -\& int PEM_write_X509(FILE *fp, X509 *x); -\& -\& X509_ACERT *PEM_read_bio_X509_ACERT(BIO *bp, X509_ACERT **x, -\& pem_password_cb *cb, void *u); -\& X509_ACERT *PEM_read_X509_ACERT(FILE *fp, X509_ACERT **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_X509_ACERT(BIO *bp, X509_ACERT *x); -\& int PEM_write_X509_ACERT(FILE *fp, X509_ACERT *x); -\& -\& X509 *PEM_read_bio_X509_AUX(BIO *bp, X509 **x, pem_password_cb *cb, void *u); -\& X509 *PEM_read_X509_AUX(FILE *fp, X509 **x, pem_password_cb *cb, void *u); -\& int PEM_write_bio_X509_AUX(BIO *bp, X509 *x); -\& int PEM_write_X509_AUX(FILE *fp, X509 *x); -\& -\& X509_REQ *PEM_read_bio_X509_REQ(BIO *bp, X509_REQ **x, -\& pem_password_cb *cb, void *u); -\& X509_REQ *PEM_read_X509_REQ(FILE *fp, X509_REQ **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_X509_REQ(BIO *bp, X509_REQ *x); -\& int PEM_write_X509_REQ(FILE *fp, X509_REQ *x); -\& int PEM_write_bio_X509_REQ_NEW(BIO *bp, X509_REQ *x); -\& int PEM_write_X509_REQ_NEW(FILE *fp, X509_REQ *x); -\& -\& X509_CRL *PEM_read_bio_X509_CRL(BIO *bp, X509_CRL **x, -\& pem_password_cb *cb, void *u); -\& X509_CRL *PEM_read_X509_CRL(FILE *fp, X509_CRL **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_X509_CRL(BIO *bp, X509_CRL *x); -\& int PEM_write_X509_CRL(FILE *fp, X509_CRL *x); -\& -\& PKCS7 *PEM_read_bio_PKCS7(BIO *bp, PKCS7 **x, pem_password_cb *cb, void *u); -\& PKCS7 *PEM_read_PKCS7(FILE *fp, PKCS7 **x, pem_password_cb *cb, void *u); -\& int PEM_write_bio_PKCS7(BIO *bp, PKCS7 *x); -\& int PEM_write_PKCS7(FILE *fp, PKCS7 *x); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& RSA *PEM_read_bio_RSAPrivateKey(BIO *bp, RSA **x, -\& pem_password_cb *cb, void *u); -\& RSA *PEM_read_RSAPrivateKey(FILE *fp, RSA **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_RSAPrivateKey(BIO *bp, RSA *x, const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_RSAPrivateKey(FILE *fp, RSA *x, const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& -\& RSA *PEM_read_bio_RSAPublicKey(BIO *bp, RSA **x, -\& pem_password_cb *cb, void *u); -\& RSA *PEM_read_RSAPublicKey(FILE *fp, RSA **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_RSAPublicKey(BIO *bp, RSA *x); -\& int PEM_write_RSAPublicKey(FILE *fp, RSA *x); -\& -\& RSA *PEM_read_bio_RSA_PUBKEY(BIO *bp, RSA **x, -\& pem_password_cb *cb, void *u); -\& RSA *PEM_read_RSA_PUBKEY(FILE *fp, RSA **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_RSA_PUBKEY(BIO *bp, RSA *x); -\& int PEM_write_RSA_PUBKEY(FILE *fp, RSA *x); -\& -\& DSA *PEM_read_bio_DSAPrivateKey(BIO *bp, DSA **x, -\& pem_password_cb *cb, void *u); -\& DSA *PEM_read_DSAPrivateKey(FILE *fp, DSA **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_DSAPrivateKey(BIO *bp, DSA *x, const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& int PEM_write_DSAPrivateKey(FILE *fp, DSA *x, const EVP_CIPHER *enc, -\& unsigned char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& -\& DSA *PEM_read_bio_DSA_PUBKEY(BIO *bp, DSA **x, -\& pem_password_cb *cb, void *u); -\& DSA *PEM_read_DSA_PUBKEY(FILE *fp, DSA **x, -\& pem_password_cb *cb, void *u); -\& int PEM_write_bio_DSA_PUBKEY(BIO *bp, DSA *x); -\& int PEM_write_DSA_PUBKEY(FILE *fp, DSA *x); -\& DSA *PEM_read_bio_DSAparams(BIO *bp, DSA **x, pem_password_cb *cb, void *u); -\& DSA *PEM_read_DSAparams(FILE *fp, DSA **x, pem_password_cb *cb, void *u); -\& int PEM_write_bio_DSAparams(BIO *bp, DSA *x); -\& int PEM_write_DSAparams(FILE *fp, DSA *x); -\& -\& DH *PEM_read_bio_DHparams(BIO *bp, DH **x, pem_password_cb *cb, void *u); -\& DH *PEM_read_DHparams(FILE *fp, DH **x, pem_password_cb *cb, void *u); -\& int PEM_write_bio_DHparams(BIO *bp, DH *x); -\& int PEM_write_DHparams(FILE *fp, DH *x); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page that have a \fI\s-1TYPE\s0\fR of \fB\s-1DH\s0\fR, \fB\s-1DSA\s0\fR -and \fB\s-1RSA\s0\fR are deprecated. Applications should use \fBOSSL_ENCODER_to_bio\fR\|(3) and -\&\fBOSSL_DECODER_from_bio\fR\|(3) instead. -.PP -The \s-1PEM\s0 functions read or write structures in \s-1PEM\s0 format. In -this sense \s-1PEM\s0 format is simply base64 encoded data surrounded -by header lines. -.PP -For more details about the meaning of arguments see the -\&\fB\s-1PEM FUNCTION ARGUMENTS\s0\fR section. -.PP -Each operation has four functions associated with it. For -brevity the term "\fB\f(BI\s-1TYPE\s0\fB\fR functions" will be used below to collectively -refer to the \fBPEM_read_bio_\f(BI\s-1TYPE\s0\fB\fR(), \fBPEM_read_\f(BI\s-1TYPE\s0\fB\fR(), -\&\fBPEM_write_bio_\f(BI\s-1TYPE\s0\fB\fR(), and \fBPEM_write_\f(BI\s-1TYPE\s0\fB\fR() functions. -.PP -Some operations have additional variants that take a library context \fIlibctx\fR -and a property query string \fIpropq\fR. The \fBX509\fR, \fBX509_REQ\fR and \fBX509_CRL\fR -objects may have an associated library context or property query string but -there are no variants of these functions that take a library context or property -query string parameter. In this case it is possible to set the appropriate -library context or property query string by creating an empty \fBX509\fR, -\&\fBX509_REQ\fR or \fBX509_CRL\fR object using \fBX509_new_ex\fR\|(3), \fBX509_REQ_new_ex\fR\|(3) -or \fBX509_CRL_new_ex\fR\|(3) respectively. Then pass the empty object as a parameter -to the relevant \s-1PEM\s0 function. See the \*(L"\s-1EXAMPLES\*(R"\s0 section below. -.PP -The \fBPrivateKey\fR functions read or write a private key in \s-1PEM\s0 format using -an \s-1EVP_PKEY\s0 structure. The write routines use PKCS#8 private key format and are -equivalent to \fBPEM_write_bio_PKCS8PrivateKey()\fR. The read functions transparently -handle traditional and PKCS#8 format encrypted and unencrypted keys. -.PP -\&\fBPEM_write_bio_PrivateKey_traditional()\fR writes out a private key in the -\&\*(L"traditional\*(R" format with a simple private key marker and should only -be used for compatibility with legacy programs. -.PP -\&\fBPEM_write_bio_PKCS8PrivateKey()\fR and \fBPEM_write_PKCS8PrivateKey()\fR write a private -key in an \s-1EVP_PKEY\s0 structure in PKCS#8 EncryptedPrivateKeyInfo format using -PKCS#5 v2.0 password based encryption algorithms. The \fIcipher\fR argument -specifies the encryption algorithm to use: unlike some other \s-1PEM\s0 routines the -encryption is applied at the PKCS#8 level and not in the \s-1PEM\s0 headers. If -\&\fIcipher\fR is \s-1NULL\s0 then no encryption is used and a PKCS#8 PrivateKeyInfo -structure is used instead. -.PP -\&\fBPEM_write_bio_PKCS8PrivateKey_nid()\fR and \fBPEM_write_PKCS8PrivateKey_nid()\fR -also write out a private key as a PKCS#8 EncryptedPrivateKeyInfo however -it uses PKCS#5 v1.5 or PKCS#12 encryption algorithms instead. The algorithm -to use is specified in the \fInid\fR parameter and should be the \s-1NID\s0 of the -corresponding \s-1OBJECT IDENTIFIER\s0 (see \s-1NOTES\s0 section). -.PP -The \fB\s-1PUBKEY\s0\fR functions process a public key using an \s-1EVP_PKEY\s0 -structure. The public key is encoded as a SubjectPublicKeyInfo -structure. -.PP -The \fBRSAPrivateKey\fR functions process an \s-1RSA\s0 private key using an -\&\s-1RSA\s0 structure. The write routines uses traditional format. The read -routines handles the same formats as the \fBPrivateKey\fR -functions but an error occurs if the private key is not \s-1RSA.\s0 -.PP -The \fBRSAPublicKey\fR functions process an \s-1RSA\s0 public key using an -\&\s-1RSA\s0 structure. The public key is encoded using a PKCS#1 RSAPublicKey -structure. -.PP -The \fB\s-1RSA_PUBKEY\s0\fR functions also process an \s-1RSA\s0 public key using -an \s-1RSA\s0 structure. However, the public key is encoded using a -SubjectPublicKeyInfo structure and an error occurs if the public -key is not \s-1RSA.\s0 -.PP -The \fBDSAPrivateKey\fR functions process a \s-1DSA\s0 private key using a -\&\s-1DSA\s0 structure. The write routines uses traditional format. The read -routines handles the same formats as the \fBPrivateKey\fR -functions but an error occurs if the private key is not \s-1DSA.\s0 -.PP -The \fB\s-1DSA_PUBKEY\s0\fR functions process a \s-1DSA\s0 public key using -a \s-1DSA\s0 structure. The public key is encoded using a -SubjectPublicKeyInfo structure and an error occurs if the public -key is not \s-1DSA.\s0 -.PP -The \fBParameters\fR functions read or write key parameters in \s-1PEM\s0 format using -an \s-1EVP_PKEY\s0 structure. The encoding depends on the type of key; for \s-1DSA\s0 key -parameters, it will be a Dss-Parms structure as defined in \s-1RFC2459,\s0 and for \s-1DH\s0 -key parameters, it will be a PKCS#3 DHparameter structure. \fIThese functions -only exist for the \f(BI\s-1BIO\s0\fI type\fR. -.PP -The \fBDSAparams\fR functions process \s-1DSA\s0 parameters using a \s-1DSA\s0 -structure. The parameters are encoded using a Dss-Parms structure -as defined in \s-1RFC2459.\s0 -.PP -The \fBDHparams\fR functions process \s-1DH\s0 parameters using a \s-1DH\s0 -structure. The parameters are encoded using a PKCS#3 DHparameter -structure. -.PP -The \fBX509\fR functions process an X509 certificate using an X509 -structure. They will also process a trusted X509 certificate but -any trust settings are discarded. -.PP -The \fBX509_ACERT\fR functions process an X509 attribute certificate using -an X509_ACERT structure. -.PP -The \fBX509_AUX\fR functions process a trusted X509 certificate using -an X509 structure. -.PP -The \fBX509_REQ\fR and \fBX509_REQ_NEW\fR functions process a PKCS#10 -certificate request using an X509_REQ structure. The \fBX509_REQ\fR -write functions use \fB\s-1CERTIFICATE REQUEST\s0\fR in the header whereas -the \fBX509_REQ_NEW\fR functions use \fB\s-1NEW CERTIFICATE REQUEST\s0\fR -(as required by some CAs). The \fBX509_REQ\fR read functions will -handle either form so there are no \fBX509_REQ_NEW\fR read functions. -.PP -The \fBX509_CRL\fR functions process an X509 \s-1CRL\s0 using an X509_CRL -structure. -.PP -The \fB\s-1PKCS7\s0\fR functions process a PKCS#7 ContentInfo using a \s-1PKCS7\s0 -structure. -.SH "PEM FUNCTION ARGUMENTS" -.IX Header "PEM FUNCTION ARGUMENTS" -The \s-1PEM\s0 functions have many common arguments. -.PP -The \fIbp\fR \s-1BIO\s0 parameter (if present) specifies the \s-1BIO\s0 to read from -or write to. -.PP -The \fIfp\fR \s-1FILE\s0 parameter (if present) specifies the \s-1FILE\s0 pointer to -read from or write to. -.PP -The \s-1PEM\s0 read functions all take an argument \fI\f(BI\s-1TYPE\s0\fI **x\fR and return -a \fI\f(BI\s-1TYPE\s0\fI *\fR pointer. Where \fI\f(BI\s-1TYPE\s0\fI\fR is whatever structure the function -uses. If \fIx\fR is \s-1NULL\s0 then the parameter is ignored. If \fIx\fR is not -\&\s-1NULL\s0 but \fI*x\fR is \s-1NULL\s0 then the structure returned will be written -to \fI*x\fR. If neither \fIx\fR nor \fI*x\fR is \s-1NULL\s0 then an attempt is made -to reuse the structure at \fI*x\fR (but see \s-1BUGS\s0 and \s-1EXAMPLES\s0 sections). -Irrespective of the value of \fIx\fR a pointer to the structure is always -returned (or \s-1NULL\s0 if an error occurred). The caller retains ownership of the -returned object and needs to free it when it is no longer needed, e.g. -using \fBX509_free()\fR for X509 objects or \fBEVP_PKEY_free()\fR for \s-1EVP_PKEY\s0 objects. -.PP -The \s-1PEM\s0 functions which write private keys take an \fIenc\fR parameter -which specifies the encryption algorithm to use, encryption is done -at the \s-1PEM\s0 level. If this parameter is set to \s-1NULL\s0 then the private -key is written in unencrypted form. -.PP -The \fIcb\fR argument is the callback to use when querying for the pass -phrase used for encrypted \s-1PEM\s0 structures (normally only private keys). -.PP -For the \s-1PEM\s0 write routines if the \fIkstr\fR parameter is not \s-1NULL\s0 then -\&\fIklen\fR bytes at \fIkstr\fR are used as the passphrase and \fIcb\fR is -ignored. -.PP -If the \fIcb\fR parameters is set to \s-1NULL\s0 and the \fIu\fR parameter is not -\&\s-1NULL\s0 then the \fIu\fR parameter is interpreted as a \s-1NUL\s0 terminated string -to use as the passphrase. If both \fIcb\fR and \fIu\fR are \s-1NULL\s0 then the -default callback routine is used which will typically prompt for the -passphrase on the current terminal with echoing turned off. -.PP -The default passphrase callback is sometimes inappropriate (for example -in a \s-1GUI\s0 application) so an alternative can be supplied. The callback -routine has the following form: -.PP -.Vb 1 -\& int cb(char *buf, int size, int rwflag, void *u); -.Ve -.PP -\&\fIbuf\fR is the buffer to write the passphrase to. \fIsize\fR is the maximum -length of the passphrase (i.e. the size of buf). \fIrwflag\fR is a flag -which is set to 0 when reading and 1 when writing. A typical routine -will ask the user to verify the passphrase (for example by prompting -for it twice) if \fIrwflag\fR is 1. The \fIu\fR parameter has the same -value as the \fIu\fR parameter passed to the \s-1PEM\s0 routine. It allows -arbitrary data to be passed to the callback by the application -(for example a window handle in a \s-1GUI\s0 application). The callback -\&\fImust\fR return the number of characters in the passphrase or \-1 if -an error occurred. The passphrase can be arbitrary data; in the case where it -is a string, it is not \s-1NUL\s0 terminated. See the \*(L"\s-1EXAMPLES\*(R"\s0 section below. -.PP -Some implementations may need to use cryptographic algorithms during their -operation. If this is the case and \fIlibctx\fR and \fIpropq\fR parameters have been -passed then any algorithm fetches will use that library context and property -query string. Otherwise the default library context and property query string -will be used. -.SH "NOTES" -.IX Header "NOTES" -The \s-1PEM\s0 reading functions will skip any extraneous content or \s-1PEM\s0 data of -a different type than they expect. This allows for example having a certificate -(or multiple certificates) and a key in the \s-1PEM\s0 format in a single file. -.PP -The old \fBPrivateKey\fR write routines are retained for compatibility. -New applications should write private keys using the -\&\fBPEM_write_bio_PKCS8PrivateKey()\fR or \fBPEM_write_PKCS8PrivateKey()\fR routines -because they are more secure (they use an iteration count of 2048 whereas -the traditional routines use a count of 1) unless compatibility with older -versions of OpenSSL is important. -.PP -The \fBPrivateKey\fR read routines can be used in all applications because -they handle all formats transparently. -.PP -A frequent cause of problems is attempting to use the \s-1PEM\s0 routines like -this: -.PP -.Vb 1 -\& X509 *x; -\& -\& PEM_read_bio_X509(bp, &x, 0, NULL); -.Ve -.PP -this is a bug because an attempt will be made to reuse the data at \fIx\fR -which is an uninitialised pointer. -.PP -These functions make no assumption regarding the pass phrase received from the -password callback. -It will simply be treated as a byte sequence. -.SH "PEM ENCRYPTION FORMAT" -.IX Header "PEM ENCRYPTION FORMAT" -These old \fBPrivateKey\fR routines use a non standard technique for encryption. -.PP -The private key (or other data) takes the following form: -.PP -.Vb 3 -\& \-\-\-\-\-BEGIN RSA PRIVATE KEY\-\-\-\-\- -\& Proc\-Type: 4,ENCRYPTED -\& DEK\-Info: DES\-EDE3\-CBC,3F17F5316E2BAC89 -\& -\& ...base64 encoded data... -\& \-\-\-\-\-END RSA PRIVATE KEY\-\-\-\-\- -.Ve -.PP -The line beginning with \fIProc-Type\fR contains the version and the -protection on the encapsulated data. The line beginning \fIDEK-Info\fR -contains two comma separated values: the encryption algorithm name as -used by \fBEVP_get_cipherbyname()\fR and an initialization vector used by the -cipher encoded as a set of hexadecimal digits. After those two lines is -the base64\-encoded encrypted data. -.PP -The encryption key is derived using \fBEVP_BytesToKey()\fR. The cipher's -initialization vector is passed to \fBEVP_BytesToKey()\fR as the \fIsalt\fR -parameter. Internally, \fB\s-1PKCS5_SALT_LEN\s0\fR bytes of the salt are used -(regardless of the size of the initialization vector). The user's -password is passed to \fBEVP_BytesToKey()\fR using the \fIdata\fR and \fIdatal\fR -parameters. Finally, the library uses an iteration count of 1 for -\&\fBEVP_BytesToKey()\fR. -.PP -The \fIkey\fR derived by \fBEVP_BytesToKey()\fR along with the original initialization -vector is then used to decrypt the encrypted data. The \fIiv\fR produced by -\&\fBEVP_BytesToKey()\fR is not utilized or needed, and \s-1NULL\s0 should be passed to -the function. -.PP -The pseudo code to derive the key would look similar to: -.PP -.Vb 2 -\& EVP_CIPHER* cipher = EVP_des_ede3_cbc(); -\& EVP_MD* md = EVP_md5(); -\& -\& unsigned int nkey = EVP_CIPHER_get_key_length(cipher); -\& unsigned int niv = EVP_CIPHER_get_iv_length(cipher); -\& unsigned char key[nkey]; -\& unsigned char iv[niv]; -\& -\& memcpy(iv, HexToBin("3F17F5316E2BAC89"), niv); -\& rc = EVP_BytesToKey(cipher, md, iv /*salt*/, pword, plen, 1, key, NULL /*iv*/); -\& if (rc != nkey) -\& /* Error */ -\& -\& /* On success, use key and iv to initialize the cipher */ -.Ve -.SH "BUGS" -.IX Header "BUGS" -The \s-1PEM\s0 read routines in some versions of OpenSSL will not correctly reuse -an existing structure. Therefore, the following: -.PP -.Vb 1 -\& PEM_read_bio_X509(bp, &x, 0, NULL); -.Ve -.PP -where \fIx\fR already contains a valid certificate, may not work, whereas: -.PP -.Vb 2 -\& X509_free(x); -\& x = PEM_read_bio_X509(bp, NULL, 0, NULL); -.Ve -.PP -is guaranteed to work. It is always acceptable for \fIx\fR to contain a newly -allocated, empty \fBX509\fR object (for example allocated via \fBX509_new_ex\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The read routines return either a pointer to the structure read or \s-1NULL\s0 -if an error occurred. -.PP -The write routines return 1 for success or 0 for failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Although the \s-1PEM\s0 routines take several arguments in almost all applications -most of them are set to 0 or \s-1NULL.\s0 -.PP -To read a certificate with a library context in \s-1PEM\s0 format from a \s-1BIO:\s0 -.PP -.Vb 1 -\& X509 *x = X509_new_ex(libctx, NULL); -\& -\& if (x == NULL) -\& /* Error */ -\& -\& if (PEM_read_bio_X509(bp, &x, 0, NULL) == NULL) -\& /* Error */ -.Ve -.PP -Read a certificate in \s-1PEM\s0 format from a \s-1BIO:\s0 -.PP -.Vb 1 -\& X509 *x; -\& -\& x = PEM_read_bio_X509(bp, NULL, 0, NULL); -\& if (x == NULL) -\& /* Error */ -.Ve -.PP -Alternative method: -.PP -.Vb 1 -\& X509 *x = NULL; -\& -\& if (!PEM_read_bio_X509(bp, &x, 0, NULL)) -\& /* Error */ -.Ve -.PP -Write a certificate to a \s-1BIO:\s0 -.PP -.Vb 2 -\& if (!PEM_write_bio_X509(bp, x)) -\& /* Error */ -.Ve -.PP -Write a private key (using traditional format) to a \s-1BIO\s0 using -triple \s-1DES\s0 encryption, the pass phrase is prompted for: -.PP -.Vb 2 -\& if (!PEM_write_bio_PrivateKey(bp, key, EVP_des_ede3_cbc(), NULL, 0, 0, NULL)) -\& /* Error */ -.Ve -.PP -Write a private key (using PKCS#8 format) to a \s-1BIO\s0 using triple -\&\s-1DES\s0 encryption, using the pass phrase \*(L"hello\*(R": -.PP -.Vb 3 -\& if (!PEM_write_bio_PKCS8PrivateKey(bp, key, EVP_des_ede3_cbc(), -\& NULL, 0, 0, "hello")) -\& /* Error */ -.Ve -.PP -Read a private key from a \s-1BIO\s0 using a pass phrase callback: -.PP -.Vb 3 -\& key = PEM_read_bio_PrivateKey(bp, NULL, pass_cb, "My Private Key"); -\& if (key == NULL) -\& /* Error */ -.Ve -.PP -Skeleton pass phrase callback: -.PP -.Vb 2 -\& int pass_cb(char *buf, int size, int rwflag, void *u) -\& { -\& -\& /* We\*(Aqd probably do something else if \*(Aqrwflag\*(Aq is 1 */ -\& printf("Enter pass phrase for \e"%s\e"\en", (char *)u); -\& -\& /* get pass phrase, length \*(Aqlen\*(Aq into \*(Aqtmp\*(Aq */ -\& char *tmp = "hello"; -\& if (tmp == NULL) /* An error occurred */ -\& return \-1; -\& -\& size_t len = strlen(tmp); -\& -\& if (len > size) -\& len = size; -\& memcpy(buf, tmp, len); -\& return len; -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_EncryptInit\fR\|(3), \fBEVP_BytesToKey\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The old Netscape certificate sequences were no longer documented -in OpenSSL 1.1.0; applications should use the \s-1PKCS7\s0 standard instead -as they will be formally deprecated in a future releases. -.PP -\&\fBPEM_read_bio_PrivateKey_ex()\fR, \fBPEM_read_PrivateKey_ex()\fR, -\&\fBPEM_read_bio_PUBKEY_ex()\fR, \fBPEM_read_PUBKEY_ex()\fR and -\&\fBPEM_read_bio_Parameters_ex()\fR were introduced in OpenSSL 3.0. -.PP -The functions \fBPEM_read_bio_RSAPrivateKey()\fR, \fBPEM_read_RSAPrivateKey()\fR, -\&\fBPEM_write_bio_RSAPrivateKey()\fR, \fBPEM_write_RSAPrivateKey()\fR, -\&\fBPEM_read_bio_RSAPublicKey()\fR, \fBPEM_read_RSAPublicKey()\fR, -\&\fBPEM_write_bio_RSAPublicKey()\fR, \fBPEM_write_RSAPublicKey()\fR, -\&\fBPEM_read_bio_RSA_PUBKEY()\fR, \fBPEM_read_RSA_PUBKEY()\fR, -\&\fBPEM_write_bio_RSA_PUBKEY()\fR, \fBPEM_write_RSA_PUBKEY()\fR, -\&\fBPEM_read_bio_DSAPrivateKey()\fR, \fBPEM_read_DSAPrivateKey()\fR, -\&\fBPEM_write_bio_DSAPrivateKey()\fR, \fBPEM_write_DSAPrivateKey()\fR, -\&\fBPEM_read_bio_DSA_PUBKEY()\fR, \fBPEM_read_DSA_PUBKEY()\fR, -\&\fBPEM_write_bio_DSA_PUBKEY()\fR, \fBPEM_write_DSA_PUBKEY()\fR; -\&\fBPEM_read_bio_DSAparams()\fR, \fBPEM_read_DSAparams()\fR, -\&\fBPEM_write_bio_DSAparams()\fR, \fBPEM_write_DSAparams()\fR, -\&\fBPEM_read_bio_DHparams()\fR, \fBPEM_read_DHparams()\fR, -\&\fBPEM_write_bio_DHparams()\fR and \fBPEM_write_DHparams()\fR were deprecated in 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_read_bio_PrivateKey_ex.3ossl b/openssl-install/share/man/man3/PEM_read_bio_PrivateKey_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_PrivateKey_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_read_bio_RSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_RSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_RSAPublicKey.3ossl b/openssl-install/share/man/man3/PEM_read_bio_RSAPublicKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_RSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_RSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_bio_RSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_RSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_SSL_SESSION.3ossl b/openssl-install/share/man/man3/PEM_read_bio_SSL_SESSION.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_SSL_SESSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_X509.3ossl b/openssl-install/share/man/man3/PEM_read_bio_X509.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_X509.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_X509_ACERT.3ossl b/openssl-install/share/man/man3/PEM_read_bio_X509_ACERT.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_X509_ACERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_X509_AUX.3ossl b/openssl-install/share/man/man3/PEM_read_bio_X509_AUX.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_X509_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_X509_CRL.3ossl b/openssl-install/share/man/man3/PEM_read_bio_X509_CRL.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_X509_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_read_bio_X509_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_X509_REQ.3ossl b/openssl-install/share/man/man3/PEM_read_bio_X509_REQ.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_X509_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_read_bio_ex.3ossl b/openssl-install/share/man/man3/PEM_read_bio_ex.3ossl deleted file mode 100644 index 103eb4a3..00000000 --- a/openssl-install/share/man/man3/PEM_read_bio_ex.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_READ_BIO_EX 3ossl" -.TH PEM_READ_BIO_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PEM_read_bio_ex, PEM_FLAG_SECURE, PEM_FLAG_EAY_COMPATIBLE, -PEM_FLAG_ONLY_B64 \- read PEM format files with custom processing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define PEM_FLAG_SECURE 0x1 -\& #define PEM_FLAG_EAY_COMPATIBLE 0x2 -\& #define PEM_FLAG_ONLY_B64 0x4 -\& int PEM_read_bio_ex(BIO *in, char **name, char **header, -\& unsigned char **data, long *len, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPEM_read_bio_ex()\fR reads in \s-1PEM\s0 formatted data from an input \s-1BIO,\s0 outputting -the name of the type of contained data, the header information regarding -the possibly encrypted data, and the binary data payload (after base64 decoding). -It should generally only be used to implement PEM_read_bio_\-family functions -for specific data types or other usage, but is exposed to allow greater flexibility -over how processing is performed, if needed. -.PP -If \s-1PEM_FLAG_SECURE\s0 is set, the intermediate buffers used to read in lines of -input are allocated from the secure heap. -.PP -If \s-1PEM_FLAG_EAY_COMPATIBLE\s0 is set, a simple algorithm is used to remove whitespace -and control characters from the end of each line, so as to be compatible with -the historical behavior of \fBPEM_read_bio()\fR. -.PP -If \s-1PEM_FLAG_ONLY_B64\s0 is set, all characters are required to be valid base64 -characters (or newlines); non\-base64 characters are treated as end of input. -.PP -If neither \s-1PEM_FLAG_EAY_COMPATIBLE\s0 or \s-1PEM_FLAG_ONLY_B64\s0 is set, control characters -are ignored. -.PP -If both \s-1PEM_FLAG_EAY_COMPATIBLE\s0 and \s-1PEM_FLAG_ONLY_B64\s0 are set, an error is returned; -these options are not compatible with each other. -.SH "NOTES" -.IX Header "NOTES" -The caller must release the storage allocated for *name, *header, and *data. -If \s-1PEM_FLAG_SECURE\s0 was set, use \fBOPENSSL_secure_free()\fR; otherwise, -\&\fBOPENSSL_free()\fR is used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPEM_read_bio_ex()\fR returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPEM_bytes_read_bio\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBPEM_read_bio_ex()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_write.3ossl b/openssl-install/share/man/man3/PEM_write.3ossl deleted file mode 120000 index 3953a8a7..00000000 --- a/openssl-install/share/man/man3/PEM_write.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_CMS.3ossl b/openssl-install/share/man/man3/PEM_write_CMS.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_CMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_DHparams.3ossl b/openssl-install/share/man/man3/PEM_write_DHparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_DHparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_DHxparams.3ossl b/openssl-install/share/man/man3/PEM_write_DHxparams.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_DHxparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_DSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_DSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_DSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_DSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_DSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_DSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_DSAparams.3ossl b/openssl-install/share/man/man3/PEM_write_DSAparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_DSAparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_ECPKParameters.3ossl b/openssl-install/share/man/man3/PEM_write_ECPKParameters.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_ECPKParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_ECPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_ECPrivateKey.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_ECPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_EC_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_EC_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_EC_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_NETSCAPE_CERT_SEQUENCE.3ossl b/openssl-install/share/man/man3/PEM_write_NETSCAPE_CERT_SEQUENCE.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_NETSCAPE_CERT_SEQUENCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PKCS7.3ossl b/openssl-install/share/man/man3/PEM_write_PKCS7.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_PKCS7.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PKCS8.3ossl b/openssl-install/share/man/man3/PEM_write_PKCS8.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_PKCS8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey_nid.3ossl b/openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey_nid.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_PKCS8PrivateKey_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PKCS8_PRIV_KEY_INFO.3ossl b/openssl-install/share/man/man3/PEM_write_PKCS8_PRIV_KEY_INFO.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_PKCS8_PRIV_KEY_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PUBKEY_ex.3ossl b/openssl-install/share/man/man3/PEM_write_PUBKEY_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_PUBKEY_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_PrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_PrivateKey_ex.3ossl b/openssl-install/share/man/man3/PEM_write_PrivateKey_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_PrivateKey_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_RSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_RSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_RSAPublicKey.3ossl b/openssl-install/share/man/man3/PEM_write_RSAPublicKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_RSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_RSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_RSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_RSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_SSL_SESSION.3ossl b/openssl-install/share/man/man3/PEM_write_SSL_SESSION.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_SSL_SESSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_X509.3ossl b/openssl-install/share/man/man3/PEM_write_X509.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_X509.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_X509_ACERT.3ossl b/openssl-install/share/man/man3/PEM_write_X509_ACERT.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_X509_ACERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_X509_AUX.3ossl b/openssl-install/share/man/man3/PEM_write_X509_AUX.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_X509_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_X509_CRL.3ossl b/openssl-install/share/man/man3/PEM_write_X509_CRL.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_X509_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_X509_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_X509_REQ.3ossl b/openssl-install/share/man/man3/PEM_write_X509_REQ.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_X509_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_X509_REQ_NEW.3ossl b/openssl-install/share/man/man3/PEM_write_X509_REQ_NEW.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_X509_REQ_NEW.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio.3ossl b/openssl-install/share/man/man3/PEM_write_bio.3ossl deleted file mode 120000 index 3953a8a7..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_CMS.3ossl b/openssl-install/share/man/man3/PEM_write_bio_CMS.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_CMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_CMS_stream.3ossl b/openssl-install/share/man/man3/PEM_write_bio_CMS_stream.3ossl deleted file mode 100644 index 76008ac2..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_CMS_stream.3ossl +++ /dev/null @@ -1,180 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_WRITE_BIO_CMS_STREAM 3ossl" -.TH PEM_WRITE_BIO_CMS_STREAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PEM_write_bio_CMS_stream \- output CMS_ContentInfo structure in PEM format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PEM_write_bio_CMS_stream(BIO *out, CMS_ContentInfo *cms, BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPEM_write_bio_CMS_stream()\fR outputs a CMS_ContentInfo structure in \s-1PEM\s0 format. -.PP -It is otherwise identical to the function \fBSMIME_write_CMS()\fR. -.SH "NOTES" -.IX Header "NOTES" -This function is effectively a version of the \fBPEM_write_bio_CMS()\fR supporting -streaming. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPEM_write_bio_CMS_stream()\fR returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3), -\&\fBCMS_verify\fR\|(3), \fBCMS_encrypt\fR\|(3) -\&\fBCMS_decrypt\fR\|(3), -\&\fBPEM_write\fR\|(3), -\&\fBSMIME_write_CMS\fR\|(3), -\&\fBi2d_CMS_bio_stream\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBPEM_write_bio_CMS_stream()\fR function was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_write_bio_DHparams.3ossl b/openssl-install/share/man/man3/PEM_write_bio_DHparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_DHparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_DHxparams.3ossl b/openssl-install/share/man/man3/PEM_write_bio_DHxparams.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_DHxparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_DSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_bio_DSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_DSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_DSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_bio_DSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_DSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_DSAparams.3ossl b/openssl-install/share/man/man3/PEM_write_bio_DSAparams.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_DSAparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_ECPKParameters.3ossl b/openssl-install/share/man/man3/PEM_write_bio_ECPKParameters.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_ECPKParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_ECPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_bio_ECPrivateKey.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_ECPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_EC_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_bio_EC_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_EC_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_NETSCAPE_CERT_SEQUENCE.3ossl b/openssl-install/share/man/man3/PEM_write_bio_NETSCAPE_CERT_SEQUENCE.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_NETSCAPE_CERT_SEQUENCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PKCS7.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PKCS7.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PKCS7.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PKCS7_stream.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PKCS7_stream.3ossl deleted file mode 100644 index ce539a77..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PKCS7_stream.3ossl +++ /dev/null @@ -1,179 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PEM_WRITE_BIO_PKCS7_STREAM 3ossl" -.TH PEM_WRITE_BIO_PKCS7_STREAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PEM_write_bio_PKCS7_stream \- output PKCS7 structure in PEM format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PEM_write_bio_PKCS7_stream(BIO *out, PKCS7 *p7, BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPEM_write_bio_PKCS7_stream()\fR outputs a \s-1PKCS7\s0 structure in \s-1PEM\s0 format. -.PP -It is otherwise identical to the function \fBSMIME_write_PKCS7()\fR. -.SH "NOTES" -.IX Header "NOTES" -This function is effectively a version of the \fBPEM_write_bio_PKCS7()\fR supporting -streaming. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPEM_write_bio_PKCS7_stream()\fR returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBPKCS7_sign\fR\|(3), -\&\fBPKCS7_verify\fR\|(3), \fBPKCS7_encrypt\fR\|(3) -\&\fBPKCS7_decrypt\fR\|(3), -\&\fBSMIME_write_PKCS7\fR\|(3), -\&\fBi2d_PKCS7_bio_stream\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBPEM_write_bio_PKCS7_stream()\fR function was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PEM_write_bio_PKCS8.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PKCS8.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PKCS8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey_nid.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey_nid.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PKCS8PrivateKey_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PKCS8_PRIV_KEY_INFO.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PKCS8_PRIV_KEY_INFO.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PKCS8_PRIV_KEY_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PUBKEY_ex.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PUBKEY_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PUBKEY_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_Parameters.3ossl b/openssl-install/share/man/man3/PEM_write_bio_Parameters.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_Parameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PrivateKey_ex.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PrivateKey_ex.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PrivateKey_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_PrivateKey_traditional.3ossl b/openssl-install/share/man/man3/PEM_write_bio_PrivateKey_traditional.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_PrivateKey_traditional.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/PEM_write_bio_RSAPrivateKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_RSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_RSAPublicKey.3ossl b/openssl-install/share/man/man3/PEM_write_bio_RSAPublicKey.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_RSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_RSA_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_bio_RSA_PUBKEY.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_RSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_SSL_SESSION.3ossl b/openssl-install/share/man/man3/PEM_write_bio_SSL_SESSION.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_SSL_SESSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_X509.3ossl b/openssl-install/share/man/man3/PEM_write_bio_X509.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_X509.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_X509_ACERT.3ossl b/openssl-install/share/man/man3/PEM_write_bio_X509_ACERT.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_X509_ACERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_X509_AUX.3ossl b/openssl-install/share/man/man3/PEM_write_bio_X509_AUX.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_X509_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_X509_CRL.3ossl b/openssl-install/share/man/man3/PEM_write_bio_X509_CRL.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_X509_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/PEM_write_bio_X509_PUBKEY.3ossl deleted file mode 120000 index 8e0bdd03..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_X509_REQ.3ossl b/openssl-install/share/man/man3/PEM_write_bio_X509_REQ.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_X509_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PEM_write_bio_X509_REQ_NEW.3ossl b/openssl-install/share/man/man3/PEM_write_bio_X509_REQ_NEW.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/PEM_write_bio_X509_REQ_NEW.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_BAGS_free.3ossl b/openssl-install/share/man/man3/PKCS12_BAGS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_BAGS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_BAGS_new.3ossl b/openssl-install/share/man/man3/PKCS12_BAGS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_BAGS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_MAC_DATA_free.3ossl b/openssl-install/share/man/man3/PKCS12_MAC_DATA_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_MAC_DATA_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_MAC_DATA_new.3ossl b/openssl-install/share/man/man3/PKCS12_MAC_DATA_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_MAC_DATA_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_PBE_keyivgen.3ossl b/openssl-install/share/man/man3/PKCS12_PBE_keyivgen.3ossl deleted file mode 100644 index 2475a653..00000000 --- a/openssl-install/share/man/man3/PKCS12_PBE_keyivgen.3ossl +++ /dev/null @@ -1,237 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_PBE_KEYIVGEN 3ossl" -.TH PKCS12_PBE_KEYIVGEN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_PBE_keyivgen, PKCS12_PBE_keyivgen_ex, -PKCS12_pbe_crypt, PKCS12_pbe_crypt_ex \- PKCS#12 Password based encryption -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_PBE_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass, int passlen, -\& ASN1_TYPE *param, const EVP_CIPHER *cipher, -\& const EVP_MD *md_type, int en_de); -\& int PKCS12_PBE_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, int passlen, -\& ASN1_TYPE *param, const EVP_CIPHER *cipher, -\& const EVP_MD *md_type, int en_de, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& unsigned char *PKCS12_pbe_crypt(const X509_ALGOR *algor, -\& const char *pass, int passlen, -\& const unsigned char *in, int inlen, -\& unsigned char **data, int *datalen, -\& int en_de); -\& unsigned char *PKCS12_pbe_crypt_ex(const X509_ALGOR *algor, -\& const char *pass, int passlen, -\& const unsigned char *in, int inlen, -\& unsigned char **data, int *datalen, -\& int en_de, OSSL_LIB_CTX *libctx, -\& const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_PBE_keyivgen()\fR and \fBPKCS12_PBE_keyivgen_ex()\fR take a password \fIpass\fR of -length \fIpasslen\fR, parameters \fIparam\fR and a message digest function \fImd_type\fR -and perform a key derivation according to PKCS#12. The resulting key is -then used to initialise the cipher context \fIctx\fR with a cipher \fIcipher\fR for -encryption (\fIen_de\fR=1) or decryption (\fIen_de\fR=0). -.PP -\&\fBPKCS12_PBE_keyivgen_ex()\fR also allows the application to specify a library context -\&\fIlibctx\fR and property query \fIpropq\fR to select appropriate algorithm -implementations. -.PP -\&\fBPKCS12_pbe_crypt()\fR and \fBPKCS12_pbe_crypt_ex()\fR will encrypt or decrypt a buffer -based on the algorithm in \fIalgor\fR and password \fIpass\fR of length \fIpasslen\fR. -The input is from \fIin\fR of length \fIinlen\fR and output is into a malloc'd buffer -returned in \fI*data\fR of length \fIdatalen\fR. The operation is determined by \fIen_de\fR, -encryption (\fIen_de\fR=1) or decryption (\fIen_de\fR=0). -.PP -\&\fBPKCS12_pbe_crypt_ex()\fR allows the application to specify a library context -\&\fIlibctx\fR and property query \fIpropq\fR to select appropriate algorithm -implementations. -.PP -\&\fIpass\fR is the password used in the derivation of length \fIpasslen\fR. \fIpass\fR -is an optional parameter and can be \s-1NULL.\s0 If \fIpasslen\fR is \-1, then the -function will calculate the length of \fIpass\fR using \fBstrlen()\fR. -.PP -\&\fIsalt\fR is the salt used in the derivation of length \fIsaltlen\fR. If the -\&\fIsalt\fR is \s-1NULL,\s0 then \fIsaltlen\fR must be 0. The function will not -attempt to calculate the length of the \fIsalt\fR because it is not assumed to -be \s-1NULL\s0 terminated. -.PP -\&\fIiter\fR is the iteration count and its value should be greater than or -equal to 1. \s-1RFC 2898\s0 suggests an iteration count of at least 1000. Any -\&\fIiter\fR less than 1 is treated as a single iteration. -.PP -\&\fIdigest\fR is the message digest function used in the derivation. -.PP -Functions ending in \fB_ex()\fR take optional parameters \fIlibctx\fR and \fIpropq\fR which -are used to select appropriate algorithm implementations. -.SH "NOTES" -.IX Header "NOTES" -The functions are typically used in PKCS#12 to encrypt objects. -.PP -These functions make no assumption regarding the given password. -It will simply be treated as a byte sequence. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_PBE_keyivgen()\fR, \fBPKCS12_PBE_keyivgen_ex()\fR return 1 on success or 0 on error. -.PP -\&\fBPKCS12_pbe_crypt()\fR and \fBPKCS12_pbe_crypt_ex()\fR return a buffer containing the -output or \s-1NULL\s0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PBE_CipherInit_ex\fR\|(3), -\&\fBPKCS8_encrypt_ex\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_PBE_keyivgen_ex()\fR and \fBPKCS12_pbe_crypt_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2014\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_PBE_keyivgen_ex.3ossl b/openssl-install/share/man/man3/PKCS12_PBE_keyivgen_ex.3ossl deleted file mode 120000 index f7edd552..00000000 --- a/openssl-install/share/man/man3/PKCS12_PBE_keyivgen_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_p8inf.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_p8inf.3ossl deleted file mode 120000 index a1c0011f..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_p8inf.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_create_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_pkcs8.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_pkcs8.3ossl deleted file mode 120000 index a1c0011f..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create0_pkcs8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_create_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_cert.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_cert.3ossl deleted file mode 100644 index 64d2f873..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_cert.3ossl +++ /dev/null @@ -1,229 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_SAFEBAG_CREATE_CERT 3ossl" -.TH PKCS12_SAFEBAG_CREATE_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_SAFEBAG_create_cert, PKCS12_SAFEBAG_create_crl, -PKCS12_SAFEBAG_create_secret, PKCS12_SAFEBAG_create0_p8inf, -PKCS12_SAFEBAG_create0_pkcs8, PKCS12_SAFEBAG_create_pkcs8_encrypt, -PKCS12_SAFEBAG_create_pkcs8_encrypt_ex \- Create PKCS#12 safeBag objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_cert(X509 *x509); -\& PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_crl(X509_CRL *crl); -\& PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_secret(int type, int vtype, -\& const unsigned char* value, -\& int len); -\& PKCS12_SAFEBAG *PKCS12_SAFEBAG_create0_p8inf(PKCS8_PRIV_KEY_INFO *p8); -\& PKCS12_SAFEBAG *PKCS12_SAFEBAG_create0_pkcs8(X509_SIG *p8); -\& PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_pkcs8_encrypt(int pbe_nid, -\& const char *pass, -\& int passlen, -\& unsigned char *salt, -\& int saltlen, int iter, -\& PKCS8_PRIV_KEY_INFO *p8inf); -\& PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_pkcs8_encrypt_ex(int pbe_nid, -\& const char *pass, -\& int passlen, -\& unsigned char *salt, -\& int saltlen, int iter, -\& PKCS8_PRIV_KEY_INFO *p8inf, -\& OSSL_LIB_CTX *ctx, -\& const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_SAFEBAG_create_cert()\fR creates a new \fB\s-1PKCS12_SAFEBAG\s0\fR of type \fBNID_certBag\fR -containing the supplied certificate. -.PP -\&\fBPKCS12_SAFEBAG_create_crl()\fR creates a new \fB\s-1PKCS12_SAFEBAG\s0\fR of type \fBNID_crlBag\fR -containing the supplied crl. -.PP -\&\fBPKCS12_SAFEBAG_create_secret()\fR creates a new \fB\s-1PKCS12_SAFEBAG\s0\fR of type -corresponding to a PKCS#12 \fBsecretBag\fR. The \fBsecretBag\fR contents are tagged as -\&\fItype\fR with an \s-1ASN1\s0 value of type \fIvtype\fR constructed using the bytes in -\&\fIvalue\fR of length \fIlen\fR. -.PP -\&\fBPKCS12_SAFEBAG_create0_p8inf()\fR creates a new \fB\s-1PKCS12_SAFEBAG\s0\fR of type \fBNID_keyBag\fR -containing the supplied \s-1PKCS8\s0 structure. -.PP -\&\fBPKCS12_SAFEBAG_create0_pkcs8()\fR creates a new \fB\s-1PKCS12_SAFEBAG\s0\fR of type -\&\fBNID_pkcs8ShroudedKeyBag\fR containing the supplied \s-1PKCS8\s0 structure. -.PP -\&\fBPKCS12_SAFEBAG_create_pkcs8_encrypt()\fR creates a new \fB\s-1PKCS12_SAFEBAG\s0\fR of type -\&\fBNID_pkcs8ShroudedKeyBag\fR by encrypting the supplied \s-1PKCS8\s0 \fIp8inf\fR. -If \fIpbe_nid\fR is 0, a default encryption algorithm is used. \fIpass\fR is the -passphrase and \fIiter\fR is the iteration count. If \fIiter\fR is zero then a default -value of 2048 is used. If \fIsalt\fR is \s-1NULL\s0 then a salt is generated randomly. -.PP -\&\fBPKCS12_SAFEBAG_create_pkcs8_encrypt_ex()\fR is identical to \fBPKCS12_SAFEBAG_create_pkcs8_encrypt()\fR -but allows for a library context \fIctx\fR and property query \fIpropq\fR to be used to select -algorithm implementations. -.SH "NOTES" -.IX Header "NOTES" -\&\fBPKCS12_SAFEBAG_create_pkcs8_encrypt()\fR makes assumptions regarding the encoding of the given pass -phrase. -See \fBpassphrase\-encoding\fR\|(7) for more information. -.PP -\&\fBPKCS12_SAFEBAG_create_secret()\fR was added in OpenSSL 3.0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All of these functions return a valid \fB\s-1PKCS12_SAFEBAG\s0\fR structure or \s-1NULL\s0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_create\fR\|(3), -\&\fBPKCS12_add_safe\fR\|(3), -\&\fBPKCS12_add_safes\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_SAFEBAG_create_pkcs8_encrypt_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_crl.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_crl.3ossl deleted file mode 120000 index a1c0011f..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_create_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt.3ossl deleted file mode 120000 index a1c0011f..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_create_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt_ex.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt_ex.3ossl deleted file mode 120000 index a1c0011f..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_pkcs8_encrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_create_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_secret.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_secret.3ossl deleted file mode 120000 index a1c0011f..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_create_secret.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_create_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_free.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attr.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attr.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attrs.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attrs.3ossl deleted file mode 100644 index deb7291e..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_attrs.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_SAFEBAG_GET0_ATTRS 3ossl" -.TH PKCS12_SAFEBAG_GET0_ATTRS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_SAFEBAG_get0_attrs, PKCS12_get_attr_gen -\&\- Retrieve attributes from a PKCS#12 safeBag -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const STACK_OF(X509_ATTRIBUTE) *PKCS12_SAFEBAG_get0_attrs(const PKCS12_SAFEBAG *bag); -\& -\& ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs, -\& int attr_nid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_SAFEBAG_get0_attrs()\fR retrieves the stack of \fBX509_ATTRIBUTE\fRs from a -PKCS#12 safeBag. \fIbag\fR is the \fB\s-1PKCS12_SAFEBAG\s0\fR to retrieve the attributes from. -.PP -\&\fBPKCS12_get_attr_gen()\fR retrieves an attribute by \s-1NID\s0 from a stack of -\&\fBX509_ATTRIBUTE\fRs. \fIattr_nid\fR is the \s-1NID\s0 of the attribute to retrieve. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_SAFEBAG_get0_attrs()\fR returns the stack of \fBX509_ATTRIBUTE\fRs from a -PKCS#12 safeBag, which could be empty. -.PP -\&\fBPKCS12_get_attr_gen()\fR returns an \fB\s-1ASN1_TYPE\s0\fR object containing the attribute, -or \s-1NULL\s0 if the attribute was either not present or an error occurred. -.PP -\&\fBPKCS12_get_attr_gen()\fR does not allocate a new attribute. The returned attribute -is still owned by the \fB\s-1PKCS12_SAFEBAG\s0\fR in which it resides. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_get_friendlyname\fR\|(3), -\&\fBPKCS12_add_friendlyname_asc\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_obj.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_obj.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_obj.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_type.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_type.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_bag_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_p8inf.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_p8inf.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_p8inf.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_pkcs8.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_pkcs8.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_pkcs8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_safes.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_safes.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_safes.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_type.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_type.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get0_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert.3ossl deleted file mode 100644 index 4349b576..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_SAFEBAG_GET1_CERT 3ossl" -.TH PKCS12_SAFEBAG_GET1_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_SAFEBAG_get0_attr, PKCS12_SAFEBAG_get0_type, -PKCS12_SAFEBAG_get_nid, PKCS12_SAFEBAG_get_bag_nid, -PKCS12_SAFEBAG_get0_bag_obj, PKCS12_SAFEBAG_get0_bag_type, -PKCS12_SAFEBAG_get1_cert_ex, PKCS12_SAFEBAG_get1_cert, -PKCS12_SAFEBAG_get1_crl_ex, PKCS12_SAFEBAG_get1_crl, -PKCS12_SAFEBAG_get0_safes, PKCS12_SAFEBAG_get0_p8inf, -PKCS12_SAFEBAG_get0_pkcs8 \- Get objects from a PKCS#12 safeBag -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const ASN1_TYPE *PKCS12_SAFEBAG_get0_attr(const PKCS12_SAFEBAG *bag, -\& int attr_nid); -\& const ASN1_OBJECT *PKCS12_SAFEBAG_get0_type(const PKCS12_SAFEBAG *bag); -\& int PKCS12_SAFEBAG_get_nid(const PKCS12_SAFEBAG *bag); -\& int PKCS12_SAFEBAG_get_bag_nid(const PKCS12_SAFEBAG *bag); -\& const ASN1_TYPE *PKCS12_SAFEBAG_get0_bag_obj(const PKCS12_SAFEBAG *bag); -\& const ASN1_OBJECT *PKCS12_SAFEBAG_get0_bag_type(const PKCS12_SAFEBAG *bag); -\& X509_CRL *PKCS12_SAFEBAG_get1_cert_ex(const PKCS12_SAFEBAG *bag, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& X509 *PKCS12_SAFEBAG_get1_cert(const PKCS12_SAFEBAG *bag); -\& X509_CRL *PKCS12_SAFEBAG_get1_crl_ex(const PKCS12_SAFEBAG *bag, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& X509_CRL *PKCS12_SAFEBAG_get1_crl(const PKCS12_SAFEBAG *bag); -\& const STACK_OF(PKCS12_SAFEBAG) *PKCS12_SAFEBAG_get0_safes(const PKCS12_SAFEBAG *bag); -\& const PKCS8_PRIV_KEY_INFO *PKCS12_SAFEBAG_get0_p8inf(const PKCS12_SAFEBAG *bag); -\& const X509_SIG *PKCS12_SAFEBAG_get0_pkcs8(const PKCS12_SAFEBAG *bag); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_SAFEBAG_get0_attr()\fR gets the attribute value corresponding to the \fBattr_nid\fR. -.PP -\&\fBPKCS12_SAFEBAG_get0_type()\fR gets the \fBsafeBag\fR type as an \s-1OID,\s0 whereas -\&\fBPKCS12_SAFEBAG_get_nid()\fR gets the \fBsafeBag\fR type as an \s-1NID,\s0 which could be -\&\fBNID_certBag\fR, \fBNID_crlBag\fR, \fBNID_keyBag\fR, \fBNID_secretBag\fR, \fBNID_safeContentsBag\fR -or \fBNID_pkcs8ShroudedKeyBag\fR. -.PP -\&\fBPKCS12_SAFEBAG_get_bag_nid()\fR gets the type of the object contained within the -\&\fB\s-1PKCS12_SAFEBAG\s0\fR. This corresponds to the bag type for most bags, but can be -arbitrary for \fBsecretBag\fRs. \fBPKCS12_SAFEBAG_get0_bag_type()\fR gets this type as an \s-1OID.\s0 -.PP -\&\fBPKCS12_SAFEBAG_get0_bag_obj()\fR retrieves the object contained within the safeBag. -.PP -\&\fBPKCS12_SAFEBAG_get1_cert_ex()\fR and \fBPKCS12_SAFEBAG_get1_crl_ex()\fR return new \fBX509\fR or -\&\fBX509_CRL\fR objects from the item in the safeBag. \fIlibctx\fR and \fIpropq\fR are used when -fetching algorithms, and may optionally be set to \s-1NULL.\s0 -.PP -\&\fBPKCS12_SAFEBAG_get1_cert()\fR and \fBPKCS12_SAFEBAG_get1_crl()\fR are the same as -\&\fBPKCS12_SAFEBAG_get1_cert_ex()\fR and \fBPKCS12_SAFEBAG_get1_crl_ex()\fR and set the \fIlibctx\fR and -\&\fIprop\fR to \s-1NULL.\s0 This will use the default library context. -.PP -\&\fBPKCS12_SAFEBAG_get0_p8inf()\fR and \fBPKCS12_SAFEBAG_get0_pkcs8()\fR return the \s-1PKCS8\s0 object -from a PKCS8shroudedKeyBag or a keyBag. -.PP -\&\fBPKCS12_SAFEBAG_get0_safes()\fR retrieves the set of \fBsafeBags\fR contained within a -safeContentsBag. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_SAFEBAG_get_nid()\fR and \fBPKCS12_SAFEBAG_get_bag_nid()\fR return the \s-1NID\s0 of the safeBag -or bag object, or \-1 if there is no corresponding \s-1NID.\s0 -Other functions return a valid object of the specified type or \s-1NULL\s0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_create\fR\|(3), -\&\fBPKCS12_add_safe\fR\|(3), -\&\fBPKCS12_add_safes\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBPKCS12_SAFEBAG_get1_cert_ex()\fR and \fBPKCS12_SAFEBAG_get1_crl_ex()\fR were -added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert_ex.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert_ex.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_cert_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl_ex.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl_ex.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get1_crl_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get_bag_nid.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get_bag_nid.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get_bag_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get_nid.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_get_nid.3ossl deleted file mode 120000 index 9ec3c432..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_get_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get1_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_new.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_SAFEBAG_set0_attrs.3ossl b/openssl-install/share/man/man3/PKCS12_SAFEBAG_set0_attrs.3ossl deleted file mode 100644 index 7b820b15..00000000 --- a/openssl-install/share/man/man3/PKCS12_SAFEBAG_set0_attrs.3ossl +++ /dev/null @@ -1,165 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_SAFEBAG_SET0_ATTRS 3ossl" -.TH PKCS12_SAFEBAG_SET0_ATTRS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_SAFEBAG_set0_attrs -\&\- Set attributes for a PKCS#12 safeBag -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void PKCS12_SAFEBAG_set0_attrs(PKCS12_SAFEBAG *bag, STACK_OF(X509_ATTRIBUTE) *attrs); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_SAFEBAG_set0_attrs()\fR assigns the stack of \fBX509_ATTRIBUTE\fRs to a -PKCS#12 safeBag. \fIbag\fR is the \fB\s-1PKCS12_SAFEBAG\s0\fR to assign the attributes to. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_SAFEBAG_set0_attrs()\fR does not return a value. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/PKCS12_add1_attr_by_NID.3ossl deleted file mode 100644 index eeeb4afa..00000000 --- a/openssl-install/share/man/man3/PKCS12_add1_attr_by_NID.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_ADD1_ATTR_BY_NID 3ossl" -.TH PKCS12_ADD1_ATTR_BY_NID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_add1_attr_by_NID, PKCS12_add1_attr_by_txt \- Add an attribute to a PKCS#12 -safeBag structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_add1_attr_by_NID(PKCS12_SAFEBAG *bag, int nid, int type, -\& const unsigned char *bytes, int len); -\& int PKCS12_add1_attr_by_txt(PKCS12_SAFEBAG *bag, const char *attrname, int type, -\& const unsigned char *bytes, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions add a PKCS#12 Attribute to the Attribute Set of the \fBbag\fR. -.PP -\&\fBPKCS12_add1_attr_by_NID()\fR adds an attribute of type \fBnid\fR with a value of \s-1ASN1\s0 -type \fBtype\fR constructed using \fBlen\fR bytes from \fBbytes\fR. -.PP -\&\fBPKCS12_add1_attr_by_txt()\fR adds an attribute of type \fBattrname\fR with a value of -\&\s-1ASN1\s0 type \fBtype\fR constructed using \fBlen\fR bytes from \fBbytes\fR. -.SH "NOTES" -.IX Header "NOTES" -These functions do not check whether an existing attribute of the same type is -present. There can be multiple attributes with the same type assigned to a -safeBag. -.PP -Both functions were added in OpenSSL 3.0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -A return value of 1 indicates success, 0 indicates failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_create\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_add1_attr_by_txt.3ossl b/openssl-install/share/man/man3/PKCS12_add1_attr_by_txt.3ossl deleted file mode 120000 index 7eebdf24..00000000 --- a/openssl-install/share/man/man3/PKCS12_add1_attr_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add1_attr_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_CSPName_asc.3ossl b/openssl-install/share/man/man3/PKCS12_add_CSPName_asc.3ossl deleted file mode 100644 index 03c8a503..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_CSPName_asc.3ossl +++ /dev/null @@ -1,168 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_ADD_CSPNAME_ASC 3ossl" -.TH PKCS12_ADD_CSPNAME_ASC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_add_CSPName_asc \- Add a Microsoft CSP Name attribute to a PKCS#12 safeBag -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_add_CSPName_asc(PKCS12_SAFEBAG *bag, const char *name, int namelen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_add_CSPName_asc()\fR adds an \s-1ASCII\s0 string representation of the Microsoft \s-1CSP\s0 Name attribute to a PKCS#12 safeBag. -.PP -\&\fIbag\fR is the \fB\s-1PKCS12_SAFEBAG\s0\fR to add the attribute to. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_add_friendlyname_asc\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_add_cert.3ossl b/openssl-install/share/man/man3/PKCS12_add_cert.3ossl deleted file mode 100644 index a619757a..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_cert.3ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_ADD_CERT 3ossl" -.TH PKCS12_ADD_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_add_cert, PKCS12_add_key, PKCS12_add_key_ex, -PKCS12_add_secret \- Add an object to a set of PKCS#12 safeBags -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS12_SAFEBAG *PKCS12_add_cert(STACK_OF(PKCS12_SAFEBAG) **pbags, X509 *cert); -\& PKCS12_SAFEBAG *PKCS12_add_key(STACK_OF(PKCS12_SAFEBAG) **pbags, -\& EVP_PKEY *key, int key_usage, int iter, -\& int key_nid, const char *pass); -\& PKCS12_SAFEBAG *PKCS12_add_key_ex(STACK_OF(PKCS12_SAFEBAG) **pbags, -\& EVP_PKEY *key, int key_usage, int iter, -\& int key_nid, const char *pass, -\& OSSL_LIB_CTX *ctx, const char *propq); -\& -\& PKCS12_SAFEBAG *PKCS12_add_secret(STACK_OF(PKCS12_SAFEBAG) **pbags, -\& int nid_type, const unsigned char *value, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions create a new \fB\s-1PKCS12_SAFEBAG\s0\fR and add it to the set of safeBags -in \fIpbags\fR. -.PP -\&\fBPKCS12_add_cert()\fR creates a PKCS#12 certBag containing the supplied -certificate and adds this to the set of PKCS#12 safeBags. -.PP -\&\fBPKCS12_add_key()\fR creates a PKCS#12 keyBag (unencrypted) or a pkcs8shroudedKeyBag -(encrypted) containing the supplied \fB\s-1EVP_PKEY\s0\fR and adds this to the set of PKCS#12 -safeBags. If \fIkey_nid\fR is not \-1 then the key is encrypted with the supplied -algorithm, using \fIpass\fR as the passphrase and \fIiter\fR as the iteration count. If -\&\fIiter\fR is zero then a default value for iteration count of 2048 is used. -.PP -\&\fBPKCS12_add_key_ex()\fR is identical to \fBPKCS12_add_key()\fR but allows for a library -context \fIctx\fR and property query \fIpropq\fR to be used to select algorithm -implementations. -.PP -\&\fBPKCS12_add_secret()\fR creates a PKCS#12 secretBag with an \s-1OID\s0 corresponding to -the supplied \fInid_type\fR containing the supplied value as an \s-1ASN1\s0 octet string. -This is then added to the set of PKCS#12 safeBags. -.SH "NOTES" -.IX Header "NOTES" -If a certificate contains an \fIalias\fR or a \fIkeyid\fR then this will be -used for the corresponding \fBfriendlyName\fR or \fBlocalKeyID\fR in the -\&\s-1PKCS12\s0 structure. -.PP -\&\fBPKCS12_add_key()\fR makes assumptions regarding the encoding of the given pass -phrase. -See \fBpassphrase\-encoding\fR\|(7) for more information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -A valid \fB\s-1PKCS12_SAFEBAG\s0\fR structure or \s-1NULL\s0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_create\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_add_secret()\fR and \fBPKCS12_add_key_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_add_friendlyname_asc.3ossl b/openssl-install/share/man/man3/PKCS12_add_friendlyname_asc.3ossl deleted file mode 100644 index 3fc174da..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_friendlyname_asc.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_ADD_FRIENDLYNAME_ASC 3ossl" -.TH PKCS12_ADD_FRIENDLYNAME_ASC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_add_friendlyname_asc, PKCS12_add_friendlyname_utf8, -PKCS12_add_friendlyname_uni \- Functions to add the friendlyname attribute to a -PKCS#12 safeBag -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_add_friendlyname_asc(PKCS12_SAFEBAG *bag, const char *name, -\& int namelen); -\& -\& int PKCS12_add_friendlyname_utf8(PKCS12_SAFEBAG *bag, const char *name, -\& int namelen); -\& -\& int PKCS12_add_friendlyname_uni(PKCS12_SAFEBAG *bag, -\& const unsigned char *name, int namelen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_add_friendlyname_asc()\fR adds an \s-1ASCII\s0 string representation of the PKCS#9 -friendlyName attribute to a PKCS#12 safeBag. -.PP -\&\fBPKCS12_add_friendlyname_utf8()\fR adds a \s-1UTF\-8\s0 string representation of the PKCS#9 -friendlyName attribute to a PKCS#12 safeBag. -.PP -\&\fBPKCS12_add_friendlyname_uni()\fR adds a Unicode string representation of the PKCS#9 -friendlyName attribute to a PKCS#12 safeBag. -.PP -\&\fIbag\fR is the \fB\s-1PKCS12_SAFEBAG\s0\fR to add the attribute to. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_get_friendlyname\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_add_friendlyname_uni.3ossl b/openssl-install/share/man/man3/PKCS12_add_friendlyname_uni.3ossl deleted file mode 120000 index 4f226787..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_friendlyname_uni.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_friendlyname_asc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_friendlyname_utf8.3ossl b/openssl-install/share/man/man3/PKCS12_add_friendlyname_utf8.3ossl deleted file mode 120000 index 4f226787..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_friendlyname_utf8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_friendlyname_asc.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_key.3ossl b/openssl-install/share/man/man3/PKCS12_add_key.3ossl deleted file mode 120000 index 6738fa68..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_key_ex.3ossl b/openssl-install/share/man/man3/PKCS12_add_key_ex.3ossl deleted file mode 120000 index 6738fa68..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_localkeyid.3ossl b/openssl-install/share/man/man3/PKCS12_add_localkeyid.3ossl deleted file mode 100644 index 26344557..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_localkeyid.3ossl +++ /dev/null @@ -1,170 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_ADD_LOCALKEYID 3ossl" -.TH PKCS12_ADD_LOCALKEYID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_add_localkeyid \- Add the localKeyId attribute to a PKCS#12 safeBag -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, const char *name, -\& int namelen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_add_localkeyid()\fR adds an octet string representation of the PKCS#9 -localKeyId attribute to a PKCS#12 safeBag. -.PP -\&\fIbag\fR is the \fB\s-1PKCS12_SAFEBAG\s0\fR to add the attribute to. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_add_friendlyname_asc\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_add_safe.3ossl b/openssl-install/share/man/man3/PKCS12_add_safe.3ossl deleted file mode 100644 index d9d3a25d..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_safe.3ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_ADD_SAFE 3ossl" -.TH PKCS12_ADD_SAFE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_add_safe, PKCS12_add_safe_ex, -PKCS12_add_safes, PKCS12_add_safes_ex \- Create and add objects to a PKCS#12 structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_add_safe(STACK_OF(PKCS7) **psafes, STACK_OF(PKCS12_SAFEBAG) *bags, -\& int safe_nid, int iter, const char *pass); -\& int PKCS12_add_safe_ex(STACK_OF(PKCS7) **psafes, STACK_OF(PKCS12_SAFEBAG) *bags, -\& int safe_nid, int iter, const char *pass, -\& OSSL_LIB_CTX *ctx, const char *propq); -\& -\& PKCS12 *PKCS12_add_safes(STACK_OF(PKCS7) *safes, int p7_nid); -\& PKCS12 *PKCS12_add_safes_ex(STACK_OF(PKCS7) *safes, int p7_nid, -\& OSSL_LIB_CTX *ctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_add_safe()\fR creates a new \s-1PKCS7\s0 contentInfo containing the supplied -\&\fB\s-1PKCS12_SAFEBAG\s0\fRs and adds this to a set of \s-1PKCS7\s0 contentInfos. Its type -depends on the value of \fBsafe_nid\fR: -.IP "\(bu" 4 -If \fIsafe_nid\fR is \-1, a plain \s-1PKCS7\s0 \fIdata\fR contentInfo is created. -.IP "\(bu" 4 -If \fIsafe_nid\fR is a valid \s-1PBE\s0 algorithm \s-1NID,\s0 a \s-1PKCS7\s0 \fBencryptedData\fR -contentInfo is created. The algorithm uses \fIpass\fR as the passphrase and \fIiter\fR -as the iteration count. If \fIiter\fR is zero then a default value for iteration -count of 2048 is used. -.IP "\(bu" 4 -If \fIsafe_nid\fR is 0, a \s-1PKCS7\s0 \fBencryptedData\fR contentInfo is created using -a default encryption algorithm, currently \fBNID_pbe_WithSHA1And3_Key_TripleDES_CBC\fR. -.PP -\&\fBPKCS12_add_safe_ex()\fR is identical to \fBPKCS12_add_safe()\fR but allows for a library -context \fIctx\fR and property query \fIpropq\fR to be used to select algorithm -implementations. -.PP -\&\fBPKCS12_add_safes()\fR creates a \fB\s-1PKCS12\s0\fR structure containing the supplied set of -\&\s-1PKCS7\s0 contentInfos. The \fIsafes\fR are enclosed first within a \s-1PKCS7\s0 contentInfo -of type \fIp7_nid\fR. Currently the only supported type is \fBNID_pkcs7_data\fR. -.PP -\&\fBPKCS12_add_safes_ex()\fR is identical to \fBPKCS12_add_safes()\fR but allows for a -library context \fIctx\fR and property query \fIpropq\fR to be used to select -algorithm implementations. -.SH "NOTES" -.IX Header "NOTES" -\&\fBPKCS12_add_safe()\fR makes assumptions regarding the encoding of the given pass -phrase. -See \fBpassphrase\-encoding\fR\|(7) for more information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_add_safe()\fR returns a value of 1 indicating success or 0 for failure. -.PP -\&\fBPKCS12_add_safes()\fR returns a valid \fB\s-1PKCS12\s0\fR structure or \s-1NULL\s0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_create\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_add_safe_ex()\fR and \fBPKCS12_add_safes_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_add_safe_ex.3ossl b/openssl-install/share/man/man3/PKCS12_add_safe_ex.3ossl deleted file mode 120000 index f44f9c22..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_safe_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_safe.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_safes.3ossl b/openssl-install/share/man/man3/PKCS12_add_safes.3ossl deleted file mode 120000 index f44f9c22..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_safes.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_safe.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_safes_ex.3ossl b/openssl-install/share/man/man3/PKCS12_add_safes_ex.3ossl deleted file mode 120000 index f44f9c22..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_safes_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_safe.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_add_secret.3ossl b/openssl-install/share/man/man3/PKCS12_add_secret.3ossl deleted file mode 120000 index 6738fa68..00000000 --- a/openssl-install/share/man/man3/PKCS12_add_secret.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_create.3ossl b/openssl-install/share/man/man3/PKCS12_create.3ossl deleted file mode 100644 index c551b576..00000000 --- a/openssl-install/share/man/man3/PKCS12_create.3ossl +++ /dev/null @@ -1,266 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_CREATE 3ossl" -.TH PKCS12_CREATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_create, PKCS12_create_ex, PKCS12_create_cb, PKCS12_create_ex2 \- create a PKCS#12 structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS12 *PKCS12_create(const char *pass, const char *name, EVP_PKEY *pkey, -\& X509 *cert, STACK_OF(X509) *ca, -\& int nid_key, int nid_cert, int iter, int mac_iter, int keytype); -\& PKCS12 *PKCS12_create_ex(const char *pass, const char *name, EVP_PKEY *pkey, -\& X509 *cert, STACK_OF(X509) *ca, int nid_key, int nid_cert, -\& int iter, int mac_iter, int keytype, -\& OSSL_LIB_CTX *ctx, const char *propq); -\& -\& typedef int PKCS12_create_cb(PKCS12_SAFEBAG *bag, void *cbarg); -\& -\& PKCS12 *PKCS12_create_ex2(const char *pass, const char *name, EVP_PKEY *pkey, -\& X509 *cert, STACK_OF(X509) *ca, int nid_key, int nid_cert, -\& int iter, int mac_iter, int keytype, -\& OSSL_LIB_CTX *ctx, const char *propq, -\& PKCS12_create_cb *cb, void *cbarg); -\&=head1 DESCRIPTION -.Ve -.PP -\&\fBPKCS12_create()\fR creates a PKCS#12 structure. -.PP -\&\fIpass\fR is the passphrase to use. \fIname\fR is the \fBfriendlyName\fR to use for -the supplied certificate and key. \fIpkey\fR is the private key to include in -the structure and \fIcert\fR its corresponding certificates. \fIca\fR, if not \fB\s-1NULL\s0\fR -is an optional set of certificates to also include in the structure. -.PP -\&\fInid_key\fR and \fInid_cert\fR are the encryption algorithms that should be used -for the key and certificate respectively. The modes -\&\s-1GCM, CCM, XTS,\s0 and \s-1OCB\s0 are unsupported. \fIiter\fR is the encryption algorithm -iteration count to use and \fImac_iter\fR is the \s-1MAC\s0 iteration count to use. -\&\fIkeytype\fR is the type of key. -.PP -\&\fBPKCS12_create_ex()\fR is identical to \fBPKCS12_create()\fR but allows for a library context -\&\fIctx\fR and property query \fIpropq\fR to be used to select algorithm implementations. -.PP -\&\fBPKCS12_create_ex2()\fR is identical to \fBPKCS12_create_ex()\fR but allows for a user defined -callback \fIcb\fR of type \fBPKCS12_create_cb\fR to be specified and also allows for an -optional argument \fIcbarg\fR to be passed back to the callback. -.PP -The \fIcb\fR if specified will be called for every safebag added to the -\&\s-1PKCS12\s0 structure and allows for optional application processing on the associated -safebag. For example one such use could be to add attributes to the safebag. -.SH "NOTES" -.IX Header "NOTES" -The parameters \fInid_key\fR, \fInid_cert\fR, \fIiter\fR, \fImac_iter\fR and \fIkeytype\fR -can all be set to zero and sensible defaults will be used. -.PP -These defaults are: \s-1AES\s0 password based encryption (\s-1PBES2\s0 with \s-1PBKDF2\s0 and -\&\s-1AES\-256\-CBC\s0) for private keys and certificates, the \s-1PBKDF2\s0 and \s-1MAC\s0 key -derivation iteration count of \fB\s-1PKCS12_DEFAULT_ITER\s0\fR (currently 2048), and -\&\s-1MAC\s0 algorithm \s-1HMAC\s0 with \s-1SHA2\-256.\s0 The \s-1MAC\s0 key derivation algorithm used -for the outer PKCS#12 structure is \s-1PKCS12KDF.\s0 -.PP -The default \s-1MAC\s0 iteration count is 1 in order to retain compatibility with -old software which did not interpret \s-1MAC\s0 iteration counts. If such compatibility -is not required then \fImac_iter\fR should be set to \s-1PKCS12_DEFAULT_ITER.\s0 -.PP -\&\fIkeytype\fR adds a flag to the store private key. This is a non standard extension -that is only currently interpreted by \s-1MSIE.\s0 If set to zero the flag is omitted, -if set to \fB\s-1KEY_SIG\s0\fR the key can be used for signing only, if set to \fB\s-1KEY_EX\s0\fR -it can be used for signing and encryption. This option was useful for old -export grade software which could use signing only keys of arbitrary size but -had restrictions on the permissible sizes of keys which could be used for -encryption. -.PP -If \fIname\fR is \fB\s-1NULL\s0\fR and \fIcert\fR contains an \fIalias\fR then this will be -used for the corresponding \fBfriendlyName\fR in the \s-1PKCS12\s0 structure instead. -Similarly, if \fIpkey\fR is \s-1NULL\s0 and \fIcert\fR contains a \fIkeyid\fR then this will be -used for the corresponding \fBlocalKeyID\fR in the \s-1PKCS12\s0 structure instead of the -id calculated from the \fIpkey\fR. -.PP -For all certificates in \fIca\fR then if a certificate contains an \fIalias\fR or -\&\fIkeyid\fR then this will be used for the corresponding \fBfriendlyName\fR or -\&\fBlocalKeyID\fR in the \s-1PKCS12\s0 structure. -.PP -Either \fIpkey\fR, \fIcert\fR or both can be \fB\s-1NULL\s0\fR to indicate that no key or -certificate is required. In previous versions both had to be present or -a fatal error is returned. -.PP -\&\fInid_key\fR or \fInid_cert\fR can be set to \-1 indicating that no encryption -should be used. -.PP -\&\fImac_iter\fR can be set to \-1 and the \s-1MAC\s0 will then be omitted entirely. -This can be useful when running with the \s-1FIPS\s0 provider as the \s-1PKCS12KDF\s0 -is not a \s-1FIPS\s0 approvable algorithm. -.PP -\&\fBPKCS12_create()\fR makes assumptions regarding the encoding of the given pass -phrase. -See \fBpassphrase\-encoding\fR\|(7) for more information. -.PP -If \fIcb\fR is specified, then it should return 1 for success and \-1 for a fatal error. -A return of 0 is intended to mean to not add the bag after all. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_create()\fR returns a valid \fB\s-1PKCS12\s0\fR structure or \s-1NULL\s0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\-PKCS12KDF\s0\fR\|(7), -\&\fBd2i_PKCS12\fR\|(3), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_create_ex()\fR was added in OpenSSL 3.0. -\&\fBPKCS12_create_ex2()\fR was added in OpenSSL 3.2. -.PP -The defaults for encryption algorithms, \s-1MAC\s0 algorithm, and the \s-1MAC\s0 key -derivation iteration count were changed in OpenSSL 3.0 to more modern -standards. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_create_cb.3ossl b/openssl-install/share/man/man3/PKCS12_create_cb.3ossl deleted file mode 120000 index 69f5bfc8..00000000 --- a/openssl-install/share/man/man3/PKCS12_create_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_create_ex.3ossl b/openssl-install/share/man/man3/PKCS12_create_ex.3ossl deleted file mode 120000 index 69f5bfc8..00000000 --- a/openssl-install/share/man/man3/PKCS12_create_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_create_ex2.3ossl b/openssl-install/share/man/man3/PKCS12_create_ex2.3ossl deleted file mode 120000 index 69f5bfc8..00000000 --- a/openssl-install/share/man/man3/PKCS12_create_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_create.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_decrypt_skey.3ossl b/openssl-install/share/man/man3/PKCS12_decrypt_skey.3ossl deleted file mode 100644 index 7974169e..00000000 --- a/openssl-install/share/man/man3/PKCS12_decrypt_skey.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_DECRYPT_SKEY 3ossl" -.TH PKCS12_DECRYPT_SKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_decrypt_skey, PKCS12_decrypt_skey_ex \- PKCS12 shrouded keyBag -decrypt functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS8_PRIV_KEY_INFO *PKCS12_decrypt_skey(const PKCS12_SAFEBAG *bag, -\& const char *pass, int passlen); -\& PKCS8_PRIV_KEY_INFO *PKCS12_decrypt_skey_ex(const PKCS12_SAFEBAG *bag, -\& const char *pass, int passlen, -\& OSSL_LIB_CTX *ctx, -\& const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_decrypt_skey()\fR Decrypt the PKCS#8 shrouded keybag contained within \fIbag\fR -using the supplied password \fIpass\fR of length \fIpasslen\fR. -.PP -\&\fBPKCS12_decrypt_skey_ex()\fR is similar to the above but allows for a library context -\&\fIctx\fR and property query \fIpropq\fR to be used to select algorithm implementations. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Both functions will return the decrypted key or \s-1NULL\s0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS8_decrypt_ex\fR\|(3), -\&\fBPKCS8_encrypt_ex\fR\|(3), -\&\fBPKCS12_add_key_ex\fR\|(3), -\&\fBPKCS12_SAFEBAG_create_pkcs8_encrypt_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_decrypt_skey_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_decrypt_skey_ex.3ossl b/openssl-install/share/man/man3/PKCS12_decrypt_skey_ex.3ossl deleted file mode 120000 index 1e1b4d88..00000000 --- a/openssl-install/share/man/man3/PKCS12_decrypt_skey_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_decrypt_skey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_free.3ossl b/openssl-install/share/man/man3/PKCS12_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_gen_mac.3ossl b/openssl-install/share/man/man3/PKCS12_gen_mac.3ossl deleted file mode 100644 index 70fb6948..00000000 --- a/openssl-install/share/man/man3/PKCS12_gen_mac.3ossl +++ /dev/null @@ -1,224 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_GEN_MAC 3ossl" -.TH PKCS12_GEN_MAC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_gen_mac, PKCS12_setup_mac, PKCS12_set_mac, -PKCS12_set_pbmac1_pbkdf2, PKCS12_verify_mac, PKCS12_get0_mac \- -Functions to create and manipulate a PKCS#12 MAC structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_gen_mac(PKCS12 *p12, const char *pass, int passlen, -\& unsigned char *mac, unsigned int *maclen); -\& int PKCS12_verify_mac(PKCS12 *p12, const char *pass, int passlen); -\& int PKCS12_set_mac(PKCS12 *p12, const char *pass, int passlen, -\& unsigned char *salt, int saltlen, int iter, -\& const EVP_MD *md_type); -\& int PKCS12_set_pbmac1_pbkdf2(PKCS12 *p12, const char *pass, int passlen, -\& unsigned char *salt, int saltlen, int iter, -\& const EVP_MD *md_type, -\& const char *prf_md_name); -\& int PKCS12_setup_mac(PKCS12 *p12, int iter, unsigned char *salt, -\& int saltlen, const EVP_MD *md_type); -\& -\& void PKCS12_get0_mac(const ASN1_OCTET_STRING **pmac, -\& const X509_ALGOR **pmacalg, -\& const ASN1_OCTET_STRING **psalt, -\& const ASN1_INTEGER **piter, -\& const PKCS12 *p12); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_gen_mac()\fR generates an \s-1HMAC\s0 over the entire PKCS#12 object using the -supplied password along with a set of already configured parameters. -The default key generation mechanism used is \s-1PKCS12KDF.\s0 -.PP -\&\fBPKCS12_verify_mac()\fR verifies the PKCS#12 object's \s-1HMAC\s0 using the supplied -password. -.PP -\&\fBPKCS12_setup_mac()\fR sets the \s-1MAC\s0 part of the PKCS#12 structure with the supplied -parameters. -.PP -\&\fBPKCS12_set_mac()\fR sets the \s-1MAC\s0 and \s-1MAC\s0 parameters into the PKCS#12 object. -\&\fBPKCS12_set_pbmac1_pbkdf2()\fR sets the \s-1MAC\s0 and \s-1MAC\s0 parameters into the PKCS#12 -object when \fB\s-1PBMAC1\s0\fR with \s-1PBKDF2\s0 is used for protection of the PKCS#12 object. -.PP -\&\fIpass\fR is the passphrase to use in the \s-1HMAC.\s0 \fIsalt\fR is the salt value to use, -\&\fIiter\fR is the iteration count and \fImd_type\fR is the message digest function to -use. \fIprf_md_name\fR specifies the digest used for the \s-1PBKDF2\s0 in \s-1PBMAC1 KDF.\s0 -.PP -\&\fBPKCS12_get0_mac()\fR retrieves any included \s-1MAC\s0 value, \fBX509_ALGOR\fR object, -\&\fIsalt\fR, and \fIiter\fR count from the \s-1PKCS12\s0 object. -.SH "NOTES" -.IX Header "NOTES" -If \fIsalt\fR is \s-1NULL\s0 then a suitable salt will be generated and used. -.PP -If \fIiter\fR is 1 then an iteration count will be omitted from the PKCS#12 -structure. -.PP -\&\fBPKCS12_gen_mac()\fR, \fBPKCS12_verify_mac()\fR, \fBPKCS12_set_mac()\fR and -\&\fBPKCS12_set_pbmac1_pbkdf2()\fR make assumptions regarding the encoding of the -given passphrase. See \fBpassphrase\-encoding\fR\|(7) for more information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions returning an integer return 1 on success and 0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -\&\s-1IETF RFC 9579\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_PKCS12\fR\|(3), -\&\s-1\fBEVP_KDF\-PKCS12KDF\s0\fR\|(7), -\&\fBPKCS12_create\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fIPKCS12_set_pbmac1_pbkdf2\fR function was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_get0_mac.3ossl b/openssl-install/share/man/man3/PKCS12_get0_mac.3ossl deleted file mode 120000 index b8177497..00000000 --- a/openssl-install/share/man/man3/PKCS12_get0_mac.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_gen_mac.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_get_attr_gen.3ossl b/openssl-install/share/man/man3/PKCS12_get_attr_gen.3ossl deleted file mode 120000 index f959c998..00000000 --- a/openssl-install/share/man/man3/PKCS12_get_attr_gen.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_SAFEBAG_get0_attrs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_get_friendlyname.3ossl b/openssl-install/share/man/man3/PKCS12_get_friendlyname.3ossl deleted file mode 100644 index ba81c1f9..00000000 --- a/openssl-install/share/man/man3/PKCS12_get_friendlyname.3ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_GET_FRIENDLYNAME 3ossl" -.TH PKCS12_GET_FRIENDLYNAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_get_friendlyname \- Retrieve the friendlyname attribute from a PKCS#12 safeBag -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& char *PKCS12_get_friendlyname(PKCS12_SAFEBAG *bag); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_get_friendlyname()\fR retrieves a \s-1UTF\-8\s0 string representation of the PKCS#9 -friendlyName attribute for a PKCS#12 safeBag item. -.PP -\&\fIbag\fR is the \fB\s-1PKCS12_SAFEBAG\s0\fR to retrieve the attribute from. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -A \s-1UTF\-8\s0 string, or \s-1NULL\s0 if the attribute was either not present or an error occurred. -.PP -The returned string is allocated by OpenSSL and should be freed by the user. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_add_friendlyname_asc\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_init.3ossl b/openssl-install/share/man/man3/PKCS12_init.3ossl deleted file mode 100644 index 4a787e8e..00000000 --- a/openssl-install/share/man/man3/PKCS12_init.3ossl +++ /dev/null @@ -1,179 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_INIT 3ossl" -.TH PKCS12_INIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_init, PKCS12_init_ex \- Create a new empty PKCS#12 structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS12 *PKCS12_init(int mode); -\& PKCS12 *PKCS12_init_ex(int mode, OSSL_LIB_CTX *ctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_init()\fR creates an empty PKCS#12 structure. Any PKCS#7 authSafes added -to this structure are enclosed first within a single PKCS#7 contentInfo -of type \fImode\fR. Currently the only supported type is \fBNID_pkcs7_data\fR. -.PP -\&\fBPKCS12_init_ex()\fR creates an empty PKCS#12 structure and assigns the supplied -\&\fIctx\fR and \fIpropq\fR to be used to select algorithm implementations for -operations performed on the \fB\s-1PKCS12\s0\fR object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_init()\fR and \fBPKCS12_init_ex()\fR return a valid \fB\s-1PKCS12\s0\fR structure or \s-1NULL\s0 -if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_PKCS12\fR\|(3), -\&\fBPKCS12_create\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_init_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_init_ex.3ossl b/openssl-install/share/man/man3/PKCS12_init_ex.3ossl deleted file mode 120000 index 2592ccf3..00000000 --- a/openssl-install/share/man/man3/PKCS12_init_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_item_decrypt_d2i.3ossl b/openssl-install/share/man/man3/PKCS12_item_decrypt_d2i.3ossl deleted file mode 100644 index 78964637..00000000 --- a/openssl-install/share/man/man3/PKCS12_item_decrypt_d2i.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_ITEM_DECRYPT_D2I 3ossl" -.TH PKCS12_ITEM_DECRYPT_D2I 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_item_decrypt_d2i, PKCS12_item_decrypt_d2i_ex, -PKCS12_item_i2d_encrypt, PKCS12_item_i2d_encrypt_ex \- PKCS12 item -encrypt/decrypt functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void *PKCS12_item_decrypt_d2i(const X509_ALGOR *algor, const ASN1_ITEM *it, -\& const char *pass, int passlen, -\& const ASN1_OCTET_STRING *oct, int zbuf); -\& void *PKCS12_item_decrypt_d2i_ex(const X509_ALGOR *algor, const ASN1_ITEM *it, -\& const char *pass, int passlen, -\& const ASN1_OCTET_STRING *oct, int zbuf, -\& OSSL_LIB_CTX *libctx, -\& const char *propq); -\& ASN1_OCTET_STRING *PKCS12_item_i2d_encrypt(X509_ALGOR *algor, -\& const ASN1_ITEM *it, -\& const char *pass, int passlen, -\& void *obj, int zbuf); -\& ASN1_OCTET_STRING *PKCS12_item_i2d_encrypt_ex(X509_ALGOR *algor, -\& const ASN1_ITEM *it, -\& const char *pass, int passlen, -\& void *obj, int zbuf, -\& OSSL_LIB_CTX *ctx, -\& const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_item_decrypt_d2i()\fR and \fBPKCS12_item_decrypt_d2i_ex()\fR decrypt an octet -string containing an \s-1ASN.1\s0 encoded object using the algorithm \fIalgor\fR and -password \fIpass\fR of length \fIpasslen\fR. If \fIzbuf\fR is nonzero then the output -buffer will zeroed after the decrypt. -.PP -\&\fBPKCS12_item_i2d_encrypt()\fR and \fBPKCS12_item_i2d_encrypt_ex()\fR encrypt an \s-1ASN.1\s0 -object \fIit\fR using the algorithm \fIalgor\fR and password \fIpass\fR of length -\&\fIpasslen\fR, returning an encoded object in \fIobj\fR. If \fIzbuf\fR is nonzero then -the buffer containing the input encoding will be zeroed after the encrypt. -.PP -Functions ending in \fB_ex()\fR allow for a library context \fIctx\fR and property query -\&\fIpropq\fR to be used to select algorithm implementations. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_item_decrypt_d2i()\fR and \fBPKCS12_item_decrypt_d2i_ex()\fR return the decrypted -object or \s-1NULL\s0 if an error occurred. -.PP -\&\fBPKCS12_item_i2d_encrypt()\fR and \fBPKCS12_item_i2d_encrypt_ex()\fR return the encrypted -data as an \s-1ASN.1\s0 Octet String or \s-1NULL\s0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_pbe_crypt_ex\fR\|(3), -\&\fBPKCS8_encrypt_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_item_decrypt_d2i_ex()\fR and \fBPKCS12_item_i2d_encrypt_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_item_decrypt_d2i_ex.3ossl b/openssl-install/share/man/man3/PKCS12_item_decrypt_d2i_ex.3ossl deleted file mode 120000 index 35f5ccfc..00000000 --- a/openssl-install/share/man/man3/PKCS12_item_decrypt_d2i_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_item_decrypt_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_item_i2d_encrypt.3ossl b/openssl-install/share/man/man3/PKCS12_item_i2d_encrypt.3ossl deleted file mode 120000 index 35f5ccfc..00000000 --- a/openssl-install/share/man/man3/PKCS12_item_i2d_encrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_item_decrypt_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_item_i2d_encrypt_ex.3ossl b/openssl-install/share/man/man3/PKCS12_item_i2d_encrypt_ex.3ossl deleted file mode 120000 index 35f5ccfc..00000000 --- a/openssl-install/share/man/man3/PKCS12_item_i2d_encrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_item_decrypt_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_key_gen_asc.3ossl b/openssl-install/share/man/man3/PKCS12_key_gen_asc.3ossl deleted file mode 120000 index 1e332ea4..00000000 --- a/openssl-install/share/man/man3/PKCS12_key_gen_asc.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_key_gen_utf8_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_key_gen_asc_ex.3ossl b/openssl-install/share/man/man3/PKCS12_key_gen_asc_ex.3ossl deleted file mode 120000 index 1e332ea4..00000000 --- a/openssl-install/share/man/man3/PKCS12_key_gen_asc_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_key_gen_utf8_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_key_gen_uni.3ossl b/openssl-install/share/man/man3/PKCS12_key_gen_uni.3ossl deleted file mode 120000 index 1e332ea4..00000000 --- a/openssl-install/share/man/man3/PKCS12_key_gen_uni.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_key_gen_utf8_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_key_gen_uni_ex.3ossl b/openssl-install/share/man/man3/PKCS12_key_gen_uni_ex.3ossl deleted file mode 120000 index 1e332ea4..00000000 --- a/openssl-install/share/man/man3/PKCS12_key_gen_uni_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_key_gen_utf8_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_key_gen_utf8.3ossl b/openssl-install/share/man/man3/PKCS12_key_gen_utf8.3ossl deleted file mode 120000 index 1e332ea4..00000000 --- a/openssl-install/share/man/man3/PKCS12_key_gen_utf8.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_key_gen_utf8_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_key_gen_utf8_ex.3ossl b/openssl-install/share/man/man3/PKCS12_key_gen_utf8_ex.3ossl deleted file mode 100644 index c7d59f28..00000000 --- a/openssl-install/share/man/man3/PKCS12_key_gen_utf8_ex.3ossl +++ /dev/null @@ -1,247 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_KEY_GEN_UTF8_EX 3ossl" -.TH PKCS12_KEY_GEN_UTF8_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_key_gen_asc, PKCS12_key_gen_asc_ex, -PKCS12_key_gen_uni, PKCS12_key_gen_uni_ex, -PKCS12_key_gen_utf8, PKCS12_key_gen_utf8_ex \- PKCS#12 Password based key derivation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_key_gen_asc(const char *pass, int passlen, unsigned char *salt, -\& int saltlen, int id, int iter, int n, -\& unsigned char *out, const EVP_MD *md_type); -\& int PKCS12_key_gen_asc_ex(const char *pass, int passlen, unsigned char *salt, -\& int saltlen, int id, int iter, int n, -\& unsigned char *out, const EVP_MD *md_type, -\& OSSL_LIB_CTX *ctx, const char *propq); -\& int PKCS12_key_gen_uni(unsigned char *pass, int passlen, unsigned char *salt, -\& int saltlen, int id, int iter, int n, -\& unsigned char *out, const EVP_MD *md_type); -\& int PKCS12_key_gen_uni_ex(unsigned char *pass, int passlen, unsigned char *salt, -\& int saltlen, int id, int iter, int n, -\& unsigned char *out, const EVP_MD *md_type, -\& OSSL_LIB_CTX *ctx, const char *propq); -\& int PKCS12_key_gen_utf8(const char *pass, int passlen, unsigned char *salt, -\& int saltlen, int id, int iter, int n, -\& unsigned char *out, const EVP_MD *md_type); -\& int PKCS12_key_gen_utf8_ex(const char *pass, int passlen, unsigned char *salt, -\& int saltlen, int id, int iter, int n, -\& unsigned char *out, const EVP_MD *md_type, -\& OSSL_LIB_CTX *ctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These methods perform a key derivation according to PKCS#12 (\s-1RFC7292\s0) -with an input password \fIpass\fR of length \fIpasslen\fR, a salt \fIsalt\fR of length -\&\fIsaltlen\fR, an iteration count \fIiter\fR and a digest algorithm \fImd_type\fR. -The \s-1ID\s0 byte \fIid\fR determines how the resulting key is intended to be used: -.IP "\(bu" 4 -If ID=1, then the pseudorandom bits being produced are to be used -as key material for performing encryption or decryption. -.IP "\(bu" 4 -If ID=2, then the pseudorandom bits being produced are to be used -as an \s-1IV\s0 (Initial Value) for encryption or decryption. -.IP "\(bu" 4 -If ID=3, then the pseudorandom bits being produced are to be used -as an integrity key for MACing. -.PP -The intended format of the supplied password is determined by the method chosen: -.IP "\(bu" 4 -\&\fBPKCS12_key_gen_asc()\fR and \fBPKCS12_key_gen_asc_ex()\fR expect an ASCII-formatted password. -.IP "\(bu" 4 -\&\fBPKCS12_key_gen_uni()\fR and \fBPKCS12_key_gen_uni_ex()\fR expect a Unicode-formatted password. -.IP "\(bu" 4 -\&\fBPKCS12_key_gen_utf8()\fR and \fBPKCS12_key_gen_utf8_ex()\fR expect a \s-1UTF\-8\s0 encoded password. -.PP -\&\fIpass\fR is the password used in the derivation of length \fIpasslen\fR. \fIpass\fR -is an optional parameter and can be \s-1NULL.\s0 If \fIpasslen\fR is \-1, then the -function will calculate the length of \fIpass\fR using \fBstrlen()\fR. -.PP -\&\fIsalt\fR is the salt used in the derivation of length \fIsaltlen\fR. If the -\&\fIsalt\fR is \s-1NULL,\s0 then \fIsaltlen\fR must be 0. The function will not -attempt to calculate the length of the \fIsalt\fR because it is not assumed to -be \s-1NULL\s0 terminated. -.PP -\&\fIiter\fR is the iteration count and its value should be greater than or -equal to 1. \s-1RFC 2898\s0 suggests an iteration count of at least 1000. Any -\&\fIiter\fR less than 1 is treated as a single iteration. -.PP -\&\fIdigest\fR is the message digest function used in the derivation. -.PP -The derived key will be written to \fIout\fR. The size of the \fIout\fR buffer -is specified via \fIn\fR. -.PP -Functions ending in \fB_ex()\fR allow for a library context \fIctx\fR and property query -\&\fIpropq\fR to be used to select algorithm implementations. -.SH "NOTES" -.IX Header "NOTES" -A typical application of this function is to derive keying material for an -encryption algorithm from a password in the \fIpass\fR, a salt in \fIsalt\fR, -and an iteration count. -.PP -Increasing the \fIiter\fR parameter slows down the algorithm which makes it -harder for an attacker to perform a brute force attack using a large number -of candidate passwords. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success or 0 on error. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_create_ex\fR\|(3), -\&\fBPKCS12_pbe_crypt_ex\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_key_gen_asc_ex()\fR, \fBPKCS12_key_gen_uni_ex()\fR and \fBPKCS12_key_gen_utf8_ex()\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_new.3ossl b/openssl-install/share/man/man3/PKCS12_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS12_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_newpass.3ossl b/openssl-install/share/man/man3/PKCS12_newpass.3ossl deleted file mode 100644 index 1b9c845c..00000000 --- a/openssl-install/share/man/man3/PKCS12_newpass.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_NEWPASS 3ossl" -.TH PKCS12_NEWPASS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_newpass \- change the password of a PKCS12 structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_newpass(PKCS12 *p12, const char *oldpass, const char *newpass); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_newpass()\fR changes the password of a \s-1PKCS12\s0 structure. -.PP -\&\fBp12\fR is a pointer to a \s-1PKCS12\s0 structure. \fBoldpass\fR is the existing password -and \fBnewpass\fR is the new password. -.PP -Each of \fBoldpass\fR and \fBnewpass\fR is independently interpreted as a string in -the \s-1UTF\-8\s0 encoding. If it is not valid \s-1UTF\-8,\s0 it is assumed to be \s-1ISO8859\-1\s0 -instead. -.PP -In particular, this means that passwords in the locale character set -(or code page on Windows) must potentially be converted to \s-1UTF\-8\s0 before -use. This may include passwords from local text files, or input from -the terminal or command line. Refer to the documentation of -\&\fBUI_OpenSSL\fR\|(3), for example. -.PP -If the PKCS#12 structure does not have a password, then you must use the empty -string "" for \fBoldpass\fR. Using \s-1NULL\s0 for \fBoldpass\fR will result in a -\&\fBPKCS12_newpass()\fR failure. -.PP -If the wrong password is used for \fBoldpass\fR then the function will fail, -with a \s-1MAC\s0 verification error. In rare cases the \s-1PKCS12\s0 structure does not -contain a \s-1MAC:\s0 in this case it will usually fail with a decryption padding -error. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_newpass()\fR returns 1 on success or 0 on failure. Applications can -retrieve the most recent error from \fBPKCS12_newpass()\fR with \fBERR_get_error()\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example loads a PKCS#12 file, changes its password and writes out -the result to a new file. -.PP -.Vb 5 -\& #include -\& #include -\& #include -\& #include -\& #include -\& -\& int main(int argc, char **argv) -\& { -\& FILE *fp; -\& PKCS12 *p12; -\& -\& if (argc != 5) { -\& fprintf(stderr, "Usage: pkread p12file password newpass opfile\en"); -\& return 1; -\& } -\& if ((fp = fopen(argv[1], "rb")) == NULL) { -\& fprintf(stderr, "Error opening file %s\en", argv[1]); -\& return 1; -\& } -\& p12 = d2i_PKCS12_fp(fp, NULL); -\& fclose(fp); -\& if (p12 == NULL) { -\& fprintf(stderr, "Error reading PKCS#12 file\en"); -\& ERR_print_errors_fp(stderr); -\& return 1; -\& } -\& if (PKCS12_newpass(p12, argv[2], argv[3]) == 0) { -\& fprintf(stderr, "Error changing password\en"); -\& ERR_print_errors_fp(stderr); -\& PKCS12_free(p12); -\& return 1; -\& } -\& if ((fp = fopen(argv[4], "wb")) == NULL) { -\& fprintf(stderr, "Error opening file %s\en", argv[4]); -\& PKCS12_free(p12); -\& return 1; -\& } -\& i2d_PKCS12_fp(fp, p12); -\& PKCS12_free(p12); -\& fclose(fp); -\& return 0; -\& } -.Ve -.SH "BUGS" -.IX Header "BUGS" -The password format is a \s-1NULL\s0 terminated \s-1ASCII\s0 string which is converted to -Unicode form internally. As a result some passwords cannot be supplied to -this function. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_create\fR\|(3), \fBERR_get_error\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_pack_p7encdata.3ossl b/openssl-install/share/man/man3/PKCS12_pack_p7encdata.3ossl deleted file mode 100644 index 2ff21782..00000000 --- a/openssl-install/share/man/man3/PKCS12_pack_p7encdata.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_PACK_P7ENCDATA 3ossl" -.TH PKCS12_PACK_P7ENCDATA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_pack_p7encdata, PKCS12_pack_p7encdata_ex \- Pack a set of PKCS#12 safeBags -into a PKCS#7 encrypted data object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS7 *PKCS12_pack_p7encdata(int pbe_nid, const char *pass, int passlen, -\& unsigned char *salt, int saltlen, int iter, -\& STACK_OF(PKCS12_SAFEBAG) *bags); -\& PKCS7 *PKCS12_pack_p7encdata_ex(int pbe_nid, const char *pass, int passlen, -\& unsigned char *salt, int saltlen, int iter, -\& STACK_OF(PKCS12_SAFEBAG) *bags, -\& OSSL_LIB_CTX *ctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_pack_p7encdata()\fR generates a PKCS#7 ContentInfo object of encrypted-data -type from the set of safeBags \fIbags\fR. The algorithm \s-1ID\s0 in \fIpbe_nid\fR can be -a PKCS#12 or PKCS#5 password based encryption algorithm, or a cipher algorithm. -If a cipher algorithm is passed, the PKCS#5 \s-1PBES2\s0 algorithm will be used with -this cipher as a parameter. -The password \fIpass\fR of length \fIpasslen\fR, salt \fIsalt\fR of length \fIsaltlen\fR -and iteration count \fIiter\fR are inputs into the encryption operation. -.PP -\&\fBPKCS12_pack_p7encdata_ex()\fR operates similar to the above but allows for a -library context \fIctx\fR and property query \fIpropq\fR to be used to select the -algorithm implementation. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -A \fB\s-1PKCS7\s0\fR object if successful, or \s-1NULL\s0 if an error occurred. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 2315\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS12_pbe_crypt_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS12_pack_p7encdata_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_pack_p7encdata_ex.3ossl b/openssl-install/share/man/man3/PKCS12_pack_p7encdata_ex.3ossl deleted file mode 120000 index 24c6dde5..00000000 --- a/openssl-install/share/man/man3/PKCS12_pack_p7encdata_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_pack_p7encdata.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_parse.3ossl b/openssl-install/share/man/man3/PKCS12_parse.3ossl deleted file mode 100644 index 1020878e..00000000 --- a/openssl-install/share/man/man3/PKCS12_parse.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS12_PARSE 3ossl" -.TH PKCS12_PARSE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS12_parse \- parse a PKCS#12 structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS12_parse(PKCS12 *p12, const char *pass, EVP_PKEY **pkey, X509 **cert, -\& STACK_OF(X509) **ca); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS12_parse()\fR parses a \s-1PKCS12\s0 structure. -.PP -\&\fBp12\fR is the \fB\s-1PKCS12\s0\fR structure to parse. \fBpass\fR is the passphrase to use. -If successful the private key will be written to \fB*pkey\fR, the corresponding -certificate to \fB*cert\fR and any additional certificates to \fB*ca\fR. -.SH "NOTES" -.IX Header "NOTES" -Each of the parameters \fBpkey\fR, \fBcert\fR, and \fBca\fR can be \s-1NULL\s0 in which case -the private key, the corresponding certificate, or the additional certificates, -respectively, will be discarded. -If any of \fBpkey\fR and \fBcert\fR is non-NULL the variable it points to is -initialized. -If \fBca\fR is non-NULL and \fB*ca\fR is \s-1NULL\s0 a new \s-1STACK\s0 will be allocated. -If \fBca\fR is non-NULL and \fB*ca\fR is a valid \s-1STACK\s0 -then additional certificates are appended in the given order to \fB*ca\fR. -.PP -The \fBfriendlyName\fR and \fBlocalKeyID\fR attributes (if present) on each -certificate will be stored in the \fBalias\fR and \fBkeyid\fR attributes of the -\&\fBX509\fR structure. -.PP -The parameter \fBpass\fR is interpreted as a string in the \s-1UTF\-8\s0 encoding. If it -is not valid \s-1UTF\-8,\s0 then it is assumed to be \s-1ISO8859\-1\s0 instead. -.PP -In particular, this means that passwords in the locale character set -(or code page on Windows) must potentially be converted to \s-1UTF\-8\s0 before -use. This may include passwords from local text files, or input from -the terminal or command line. Refer to the documentation of -\&\fBUI_OpenSSL\fR\|(3), for example. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS12_parse()\fR returns 1 for success and zero if an error occurred. -.PP -The error can be obtained from \fBERR_get_error\fR\|(3) -.SH "BUGS" -.IX Header "BUGS" -Only a single private key and corresponding certificate is returned by this -function. More complex PKCS#12 files with multiple private keys will only -return the first match. -.PP -Only \fBfriendlyName\fR and \fBlocalKeyID\fR attributes are currently stored in -certificates. Other attributes are discarded. -.PP -Attributes currently cannot be stored in the private key \fB\s-1EVP_PKEY\s0\fR structure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_PKCS12\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS12_pbe_crypt.3ossl b/openssl-install/share/man/man3/PKCS12_pbe_crypt.3ossl deleted file mode 120000 index f7edd552..00000000 --- a/openssl-install/share/man/man3/PKCS12_pbe_crypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_pbe_crypt_ex.3ossl b/openssl-install/share/man/man3/PKCS12_pbe_crypt_ex.3ossl deleted file mode 120000 index f7edd552..00000000 --- a/openssl-install/share/man/man3/PKCS12_pbe_crypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_set_mac.3ossl b/openssl-install/share/man/man3/PKCS12_set_mac.3ossl deleted file mode 120000 index b8177497..00000000 --- a/openssl-install/share/man/man3/PKCS12_set_mac.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_gen_mac.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_set_pbmac1_pbkdf2.3ossl b/openssl-install/share/man/man3/PKCS12_set_pbmac1_pbkdf2.3ossl deleted file mode 120000 index b8177497..00000000 --- a/openssl-install/share/man/man3/PKCS12_set_pbmac1_pbkdf2.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_gen_mac.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_setup_mac.3ossl b/openssl-install/share/man/man3/PKCS12_setup_mac.3ossl deleted file mode 120000 index b8177497..00000000 --- a/openssl-install/share/man/man3/PKCS12_setup_mac.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_gen_mac.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS12_verify_mac.3ossl b/openssl-install/share/man/man3/PKCS12_verify_mac.3ossl deleted file mode 120000 index b8177497..00000000 --- a/openssl-install/share/man/man3/PKCS12_verify_mac.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS12_gen_mac.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_PBE_keyivgen.3ossl b/openssl-install/share/man/man3/PKCS5_PBE_keyivgen.3ossl deleted file mode 100644 index ff89291d..00000000 --- a/openssl-install/share/man/man3/PKCS5_PBE_keyivgen.3ossl +++ /dev/null @@ -1,315 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS5_PBE_KEYIVGEN 3ossl" -.TH PKCS5_PBE_KEYIVGEN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS5_PBE_keyivgen, PKCS5_PBE_keyivgen_ex, PKCS5_pbe2_set, PKCS5_pbe2_set_iv, -PKCS5_pbe2_set_iv_ex, PKCS5_pbe_set, PKCS5_pbe_set_ex, PKCS5_pbe2_set_scrypt, -PKCS5_pbe_set0_algor, PKCS5_pbe_set0_algor_ex, -PKCS5_v2_PBE_keyivgen, PKCS5_v2_PBE_keyivgen_ex, -PKCS5_v2_scrypt_keyivgen, PKCS5_v2_scrypt_keyivgen_ex, -PKCS5_pbkdf2_set, PKCS5_pbkdf2_set_ex, EVP_PBE_scrypt, EVP_PBE_scrypt_ex -\&\- PKCS#5 Password based encryption routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS5_PBE_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass, int passlen, -\& ASN1_TYPE *param, const EVP_CIPHER *cipher, -\& const EVP_MD *md, int en_de); -\& int PKCS5_PBE_keyivgen_ex(EVP_CIPHER_CTX *cctx, const char *pass, int passlen, -\& ASN1_TYPE *param, const EVP_CIPHER *cipher, -\& const EVP_MD *md, int en_de, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int PKCS5_v2_PBE_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass, int passlen, -\& ASN1_TYPE *param, const EVP_CIPHER *cipher, -\& const EVP_MD *md, int en_de); -\& int PKCS5_v2_PBE_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, int passlen, -\& ASN1_TYPE *param, const EVP_CIPHER *cipher, -\& const EVP_MD *md, int en_de, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int EVP_PBE_scrypt(const char *pass, size_t passlen, -\& const unsigned char *salt, size_t saltlen, -\& uint64_t N, uint64_t r, uint64_t p, uint64_t maxmem, -\& unsigned char *key, size_t keylen); -\& int EVP_PBE_scrypt_ex(const char *pass, size_t passlen, -\& const unsigned char *salt, size_t saltlen, -\& uint64_t N, uint64_t r, uint64_t p, uint64_t maxmem, -\& unsigned char *key, size_t keylen, -\& OSSL_LIB_CTX *ctx, const char *propq); -\& int PKCS5_v2_scrypt_keyivgen(EVP_CIPHER_CTX *ctx, const char *pass, -\& int passlen, ASN1_TYPE *param, -\& const EVP_CIPHER *c, const EVP_MD *md, int en_de); -\& int PKCS5_v2_scrypt_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, -\& int passlen, ASN1_TYPE *param, -\& const EVP_CIPHER *c, const EVP_MD *md, int en_de, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& -\& #include -\& -\& int PKCS5_pbe_set0_algor(X509_ALGOR *algor, int alg, int iter, -\& const unsigned char *salt, int saltlen); -\& int PKCS5_pbe_set0_algor_ex(X509_ALGOR *algor, int alg, int iter, -\& const unsigned char *salt, int saltlen, -\& OSSL_LIB_CTX *libctx); -\& -\& X509_ALGOR *PKCS5_pbe_set(int alg, int iter, -\& const unsigned char *salt, int saltlen); -\& X509_ALGOR *PKCS5_pbe_set_ex(int alg, int iter, -\& const unsigned char *salt, int saltlen, -\& OSSL_LIB_CTX *libctx); -\& -\& X509_ALGOR *PKCS5_pbe2_set(const EVP_CIPHER *cipher, int iter, -\& unsigned char *salt, int saltlen); -\& X509_ALGOR *PKCS5_pbe2_set_iv(const EVP_CIPHER *cipher, int iter, -\& unsigned char *salt, int saltlen, -\& unsigned char *aiv, int prf_nid); -\& X509_ALGOR *PKCS5_pbe2_set_iv_ex(const EVP_CIPHER *cipher, int iter, -\& unsigned char *salt, int saltlen, -\& unsigned char *aiv, int prf_nid, -\& OSSL_LIB_CTX *libctx); -\& X509_ALGOR *PKCS5_pbe2_set_scrypt(const EVP_CIPHER *cipher, -\& const unsigned char *salt, int saltlen, -\& unsigned char *aiv, uint64_t N, uint64_t r, -\& uint64_t p); -\& -\& X509_ALGOR *PKCS5_pbkdf2_set(int iter, unsigned char *salt, int saltlen, -\& int prf_nid, int keylen); -\& X509_ALGOR *PKCS5_pbkdf2_set_ex(int iter, unsigned char *salt, int saltlen, -\& int prf_nid, int keylen, -\& OSSL_LIB_CTX *libctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -.SS "Key Derivation" -.IX Subsection "Key Derivation" -\&\fBPKCS5_PBE_keyivgen()\fR and \fBPKCS5_PBE_keyivgen_ex()\fR take a password \fIpass\fR of -length \fIpasslen\fR, parameters \fIparam\fR and a message digest function \fImd_type\fR -and performs a key derivation according to PKCS#5 \s-1PBES1.\s0 The resulting key is -then used to initialise the cipher context \fIctx\fR with a cipher \fIcipher\fR for -encryption (\fIen_de\fR=1) or decryption (\fIen_de\fR=0). -.PP -\&\fIpass\fR is an optional parameter and can be \s-1NULL.\s0 If \fIpasslen\fR is \-1, then the -function will calculate the length of \fIpass\fR using \fBstrlen()\fR. -.PP -\&\fBPKCS5_v2_PBE_keyivgen()\fR and \fBPKCS5_v2_PBE_keyivgen_ex()\fR are similar to the above -but instead use PKCS#5 \s-1PBES2\s0 as the encryption algorithm using the supplied -parameters. -.PP -\&\fBPKCS5_v2_scrypt_keyivgen()\fR and \fBPKCS5_v2_scrypt_keyivgen_ex()\fR use \s-1SCRYPT\s0 as the -key derivation part of the encryption algorithm. -.PP -\&\fIsalt\fR is the salt used in the derivation of length \fIsaltlen\fR. If the -\&\fIsalt\fR is \s-1NULL,\s0 then \fIsaltlen\fR must be 0. The function will not -attempt to calculate the length of the \fIsalt\fR because it is not assumed to -be \s-1NULL\s0 terminated. -.PP -\&\fIiter\fR is the iteration count and its value should be greater than or -equal to 1. \s-1RFC 2898\s0 suggests an iteration count of at least 1000. Any -\&\fIiter\fR less than 1 is treated as a single iteration. -.PP -\&\fIdigest\fR is the message digest function used in the derivation. -.PP -Functions ending in \fB_ex()\fR take optional parameters \fIlibctx\fR and \fIpropq\fR which -are used to select appropriate algorithm implementations. -.SS "Algorithm Identifier Creation" -.IX Subsection "Algorithm Identifier Creation" -\&\fBPKCS5_pbe_set()\fR, \fBPKCS5_pbe_set_ex()\fR, \fBPKCS5_pbe2_set()\fR, \fBPKCS5_pbe2_set_iv()\fR, -\&\fBPKCS5_pbe2_set_iv_ex()\fR and \fBPKCS5_pbe2_set_scrypt()\fR generate an \fBX509_ALGOR\fR -object which represents an AlgorithmIdentifier containing the algorithm \s-1OID\s0 and -associated parameters for the \s-1PBE\s0 algorithm. -.PP -\&\fBPKCS5_pbkdf2_set()\fR and \fBPKCS5_pbkdf2_set_ex()\fR generate an \fBX509_ALGOR\fR -object which represents an AlgorithmIdentifier containing the algorithm \s-1OID\s0 and -associated parameters for the \s-1PBKDF2\s0 algorithm. -.PP -\&\fBPKCS5_pbe_set0_algor()\fR and \fBPKCS5_pbe_set0_algor_ex()\fR set the \s-1PBE\s0 algorithm \s-1OID\s0 and -parameters into the supplied \fBX509_ALGOR\fR. -.PP -If \fIsalt\fR is \s-1NULL,\s0 then \fIsaltlen\fR specifies the size in bytes of the random salt to -generate. If \fIsaltlen\fR is 0 then a default size is used. -For \s-1PBE\s0 related functions such as \fBPKCS5_pbe_set_ex()\fR the default salt length is 8 bytes. -For \s-1PBE2\s0 related functions that use \s-1PBKDF2\s0 such as \fBPKCS5_pbkdf2_set()\fR, -\&\fBPKCS5_pbe2_set_scrypt()\fR and \fBPKCS5_pbe2_set()\fR the default salt length is 16 bytes. -.SH "NOTES" -.IX Header "NOTES" -The *\fB_keyivgen()\fR functions are typically used in PKCS#12 to encrypt objects. -.PP -These functions make no assumption regarding the given password. -It will simply be treated as a byte sequence. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS5_PBE_keyivgen()\fR, \fBPKCS5_v2_PBE_keyivgen()\fR, -\&\fBPKCS5_v2_PBE_keyivgen_ex()\fR, \fBPKCS5_v2_scrypt_keyivgen()\fR, -\&\fBPKCS5_v2_scrypt_keyivgen_ex()\fR, \fBPKCS5_pbe_set0_algor()\fR and -\&\fBPKCS5_pbe_set0_algor_ex()\fR return 1 for success and 0 if an error occurs. -.PP -\&\fBPKCS5_pbe_set()\fR, \fBPKCS5_pbe_set_ex()\fR, \fBPKCS5_pbe2_set()\fR, \fBPKCS5_pbe2_set_iv()\fR, -\&\fBPKCS5_pbe2_set_iv_ex()\fR, \fBPKCS5_pbe2_set_scrypt()\fR, -\&\fBPKCS5_pbkdf2_set()\fR and \fBPKCS5_pbkdf2_set_ex()\fR return an \fBX509_ALGOR\fR object or -\&\s-1NULL\s0 if an error occurs. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 8018\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PBE_CipherInit_ex\fR\|(3), -\&\fBPKCS12_pbe_crypt_ex\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS5_v2_PBE_keyivgen_ex()\fR, \fBEVP_PBE_scrypt_ex()\fR, \fBPKCS5_v2_scrypt_keyivgen_ex()\fR, -\&\fBPKCS5_pbe_set0_algor_ex()\fR, \fBPKCS5_pbe_set_ex()\fR, \fBPKCS5_pbe2_set_iv_ex()\fR and -\&\fBPKCS5_pbkdf2_set_ex()\fR were added in OpenSSL 3.0. -.PP -From OpenSSL 3.0 the \s-1PBKDF1\s0 algorithm used in \fBPKCS5_PBE_keyivgen()\fR and -\&\fBPKCS5_PBE_keyivgen_ex()\fR has been moved to the legacy provider as an \s-1EVP_KDF.\s0 -.PP -In OpenSSL 3.2 the default salt length changed from 8 bytes to 16 bytes for \s-1PBE2\s0 -related functions such as \fBPKCS5_pbe2_set()\fR. -This is required for \s-1PBKDF2 FIPS\s0 compliance. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS5_PBE_keyivgen_ex.3ossl b/openssl-install/share/man/man3/PKCS5_PBE_keyivgen_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_PBE_keyivgen_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC.3ossl b/openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC.3ossl deleted file mode 100644 index d62b280a..00000000 --- a/openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC.3ossl +++ /dev/null @@ -1,208 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS5_PBKDF2_HMAC 3ossl" -.TH PKCS5_PBKDF2_HMAC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS5_PBKDF2_HMAC, PKCS5_PBKDF2_HMAC_SHA1 \- password based derivation routines with salt and iteration count -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS5_PBKDF2_HMAC(const char *pass, int passlen, -\& const unsigned char *salt, int saltlen, int iter, -\& const EVP_MD *digest, -\& int keylen, unsigned char *out); -\& -\& int PKCS5_PBKDF2_HMAC_SHA1(const char *pass, int passlen, -\& const unsigned char *salt, int saltlen, int iter, -\& int keylen, unsigned char *out); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1\fBPKCS5_PBKDF2_HMAC\s0()\fR derives a key from a password using a salt and iteration count -as specified in \s-1RFC 2898.\s0 -.PP -\&\fBpass\fR is the password used in the derivation of length \fBpasslen\fR. \fBpass\fR -is an optional parameter and can be \s-1NULL.\s0 If \fBpasslen\fR is \-1, then the -function will calculate the length of \fBpass\fR using \fBstrlen()\fR. -.PP -\&\fBsalt\fR is the salt used in the derivation of length \fBsaltlen\fR. If the -\&\fBsalt\fR is \s-1NULL,\s0 then \fBsaltlen\fR must be 0. The function will not -attempt to calculate the length of the \fBsalt\fR because it is not assumed to -be \s-1NULL\s0 terminated. -.PP -\&\fBiter\fR is the iteration count and its value should be greater than or -equal to 1. \s-1RFC 2898\s0 suggests an iteration count of at least 1000. Any -\&\fBiter\fR value less than 1 is invalid; such values will result in failure -and raise the \s-1PROV_R_INVALID_ITERATION_COUNT\s0 error. -.PP -\&\fBdigest\fR is the message digest function used in the derivation. -\&\s-1\fBPKCS5_PBKDF2_HMAC_SHA1\s0()\fR calls \s-1\fBPKCS5_PBKDF2_HMAC\s0()\fR with \fBEVP_sha1()\fR. -.PP -The derived key will be written to \fBout\fR. The size of the \fBout\fR buffer -is specified via \fBkeylen\fR. -.SH "NOTES" -.IX Header "NOTES" -A typical application of this function is to derive keying material for an -encryption algorithm from a password in the \fBpass\fR, a salt in \fBsalt\fR, -and an iteration count. -.PP -Increasing the \fBiter\fR parameter slows down the algorithm which makes it -harder for an attacker to perform a brute force attack using a large number -of candidate passwords. -.PP -These functions make no assumption regarding the given password. -It will simply be treated as a byte sequence. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1\fBPKCS5_PBKDF2_HMAC\s0()\fR and \s-1\fBPBKCS5_PBKDF2_HMAC_SHA1\s0()\fR return 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), \fBRAND_bytes\fR\|(3), -\&\fBEVP_BytesToKey\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2014\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC_SHA1.3ossl b/openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC_SHA1.3ossl deleted file mode 120000 index 84281cb6..00000000 --- a/openssl-install/share/man/man3/PKCS5_PBKDF2_HMAC_SHA1.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBKDF2_HMAC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe2_set.3ossl b/openssl-install/share/man/man3/PKCS5_pbe2_set.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe2_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe2_set_iv.3ossl b/openssl-install/share/man/man3/PKCS5_pbe2_set_iv.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe2_set_iv.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe2_set_iv_ex.3ossl b/openssl-install/share/man/man3/PKCS5_pbe2_set_iv_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe2_set_iv_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe2_set_scrypt.3ossl b/openssl-install/share/man/man3/PKCS5_pbe2_set_scrypt.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe2_set_scrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe_set.3ossl b/openssl-install/share/man/man3/PKCS5_pbe_set.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe_set0_algor.3ossl b/openssl-install/share/man/man3/PKCS5_pbe_set0_algor.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe_set0_algor.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe_set0_algor_ex.3ossl b/openssl-install/share/man/man3/PKCS5_pbe_set0_algor_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe_set0_algor_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbe_set_ex.3ossl b/openssl-install/share/man/man3/PKCS5_pbe_set_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbe_set_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbkdf2_set.3ossl b/openssl-install/share/man/man3/PKCS5_pbkdf2_set.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbkdf2_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_pbkdf2_set_ex.3ossl b/openssl-install/share/man/man3/PKCS5_pbkdf2_set_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_pbkdf2_set_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen.3ossl b/openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen_ex.3ossl b/openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_v2_PBE_keyivgen_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen.3ossl b/openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen_ex.3ossl b/openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen_ex.3ossl deleted file mode 120000 index 6b22d886..00000000 --- a/openssl-install/share/man/man3/PKCS5_v2_scrypt_keyivgen_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS5_PBE_keyivgen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_DIGEST_free.3ossl b/openssl-install/share/man/man3/PKCS7_DIGEST_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_DIGEST_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_DIGEST_new.3ossl b/openssl-install/share/man/man3/PKCS7_DIGEST_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_DIGEST_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ENCRYPT_free.3ossl b/openssl-install/share/man/man3/PKCS7_ENCRYPT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ENCRYPT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ENCRYPT_new.3ossl b/openssl-install/share/man/man3/PKCS7_ENCRYPT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ENCRYPT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ENC_CONTENT_free.3ossl b/openssl-install/share/man/man3/PKCS7_ENC_CONTENT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ENC_CONTENT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ENC_CONTENT_new.3ossl b/openssl-install/share/man/man3/PKCS7_ENC_CONTENT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ENC_CONTENT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ENVELOPE_free.3ossl b/openssl-install/share/man/man3/PKCS7_ENVELOPE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ENVELOPE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ENVELOPE_new.3ossl b/openssl-install/share/man/man3/PKCS7_ENVELOPE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ENVELOPE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_digest.3ossl b/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_digest.3ossl deleted file mode 120000 index c2b39912..00000000 --- a/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_digest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_free.3ossl b/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_new.3ossl b/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_ISSUER_AND_SERIAL_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_RECIP_INFO_free.3ossl b/openssl-install/share/man/man3/PKCS7_RECIP_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_RECIP_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_RECIP_INFO_new.3ossl b/openssl-install/share/man/man3/PKCS7_RECIP_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_RECIP_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_SIGNED_free.3ossl b/openssl-install/share/man/man3/PKCS7_SIGNED_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_SIGNED_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_SIGNED_new.3ossl b/openssl-install/share/man/man3/PKCS7_SIGNED_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_SIGNED_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_SIGNER_INFO_free.3ossl b/openssl-install/share/man/man3/PKCS7_SIGNER_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_SIGNER_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_SIGNER_INFO_new.3ossl b/openssl-install/share/man/man3/PKCS7_SIGNER_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_SIGNER_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_free.3ossl b/openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_new.3ossl b/openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_SIGN_ENVELOPE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_add_certificate.3ossl b/openssl-install/share/man/man3/PKCS7_add_certificate.3ossl deleted file mode 120000 index 849ded70..00000000 --- a/openssl-install/share/man/man3/PKCS7_add_certificate.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS7_sign_add_signer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_add_crl.3ossl b/openssl-install/share/man/man3/PKCS7_add_crl.3ossl deleted file mode 120000 index 849ded70..00000000 --- a/openssl-install/share/man/man3/PKCS7_add_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS7_sign_add_signer.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_decrypt.3ossl b/openssl-install/share/man/man3/PKCS7_decrypt.3ossl deleted file mode 100644 index 0d42ed3f..00000000 --- a/openssl-install/share/man/man3/PKCS7_decrypt.3ossl +++ /dev/null @@ -1,187 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS7_DECRYPT 3ossl" -.TH PKCS7_DECRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS7_decrypt \- decrypt content from a PKCS#7 envelopedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS7_decrypt(PKCS7 *p7, EVP_PKEY *pkey, X509 *cert, BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS7_decrypt()\fR extracts and decrypts the content from a PKCS#7 envelopedData -structure. \fBpkey\fR is the private key of the recipient, \fBcert\fR is the -recipients certificate, \fBdata\fR is a \s-1BIO\s0 to write the content to and -\&\fBflags\fR is an optional set of flags. -.SH "NOTES" -.IX Header "NOTES" -Although the recipients certificate is not needed to decrypt the data it is needed -to locate the appropriate (of possible several) recipients in the PKCS#7 structure. -.PP -The following flags can be passed in the \fBflags\fR parameter. -.PP -If the \fB\s-1PKCS7_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are deleted -from the content. If the content is not of type \fBtext/plain\fR then an error is -returned. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS7_decrypt()\fR returns either 1 for success or 0 for failure. -The error can be obtained from \fBERR_get_error\fR\|(3) -.SH "BUGS" -.IX Header "BUGS" -\&\fBPKCS7_decrypt()\fR must be passed the correct recipient key and certificate. It would -be better if it could look up the correct key and certificate from a database. -.PP -The lack of single pass processing and need to hold all data in memory as -mentioned in \fBPKCS7_sign()\fR also applies to \fBPKCS7_verify()\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBPKCS7_encrypt\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS7_dup.3ossl b/openssl-install/share/man/man3/PKCS7_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_encrypt.3ossl b/openssl-install/share/man/man3/PKCS7_encrypt.3ossl deleted file mode 100644 index 4938784f..00000000 --- a/openssl-install/share/man/man3/PKCS7_encrypt.3ossl +++ /dev/null @@ -1,227 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS7_ENCRYPT 3ossl" -.TH PKCS7_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS7_encrypt_ex, PKCS7_encrypt -\&\- create a PKCS#7 envelopedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS7 *PKCS7_encrypt_ex(STACK_OF(X509) *certs, BIO *in, -\& const EVP_CIPHER *cipher, int flags, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& PKCS7 *PKCS7_encrypt(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, -\& int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS7_encrypt_ex()\fR creates and returns a PKCS#7 envelopedData structure. -\&\fIcerts\fR is a list of recipient certificates. \fIin\fR is the content to be -encrypted. \fIcipher\fR is the symmetric cipher to use. \fIflags\fR is an optional set -of flags. The library context \fIlibctx\fR and the property query \fIpropq\fR are used -when retrieving algorithms from providers. -.PP -Only \s-1RSA\s0 keys are supported in PKCS#7 and envelopedData so the recipient -certificates supplied to this function must all contain \s-1RSA\s0 public keys, though -they do not have to be signed using the \s-1RSA\s0 algorithm. -.PP -\&\fBEVP_des_ede3_cbc()\fR (triple \s-1DES\s0) is the algorithm of choice for S/MIME use -because most clients will support it. -.PP -Some old \*(L"export grade\*(R" clients may only support weak encryption using 40 or 64 -bit \s-1RC2.\s0 These can be used by passing \fBEVP_rc2_40_cbc()\fR and \fBEVP_rc2_64_cbc()\fR -respectively. -.PP -The algorithm passed in the \fBcipher\fR parameter must support \s-1ASN1\s0 encoding of -its parameters. -.PP -Many browsers implement a \*(L"sign and encrypt\*(R" option which is simply an S/MIME -envelopedData containing an S/MIME signed message. This can be readily produced -by storing the S/MIME signed message in a memory \s-1BIO\s0 and passing it to -\&\fBPKCS7_encrypt()\fR. -.PP -The following flags can be passed in the \fBflags\fR parameter. -.PP -If the \fB\s-1PKCS7_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are -prepended to the data. -.PP -Normally the supplied content is translated into \s-1MIME\s0 canonical format (as -required by the S/MIME specifications) if \fB\s-1PKCS7_BINARY\s0\fR is set no translation -occurs. This option should be used if the supplied data is in binary format -otherwise the translation will corrupt it. If \fB\s-1PKCS7_BINARY\s0\fR is set then -\&\fB\s-1PKCS7_TEXT\s0\fR is ignored. -.PP -If the \fB\s-1PKCS7_STREAM\s0\fR flag is set a partial \fB\s-1PKCS7\s0\fR structure is output -suitable for streaming I/O: no data is read from the \s-1BIO\s0 \fBin\fR. -.PP -If the flag \fB\s-1PKCS7_STREAM\s0\fR is set the returned \fB\s-1PKCS7\s0\fR structure is \fBnot\fR -complete and outputting its contents via a function that does not -properly finalize the \fB\s-1PKCS7\s0\fR structure will give unpredictable -results. -.PP -Several functions including \fBSMIME_write_PKCS7()\fR, \fBi2d_PKCS7_bio_stream()\fR, -\&\fBPEM_write_bio_PKCS7_stream()\fR finalize the structure. Alternatively finalization -can be performed by obtaining the streaming \s-1ASN1\s0 \fB\s-1BIO\s0\fR directly using -\&\fBBIO_new_PKCS7()\fR. -.PP -\&\fBPKCS7_encrypt()\fR is similar to \fBPKCS7_encrypt_ex()\fR but uses default -values of \s-1NULL\s0 for the library context \fIlibctx\fR and the property query \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS7_encrypt_ex()\fR and \fBPKCS7_encrypt()\fR return either a \s-1PKCS7\s0 structure -or \s-1NULL\s0 if an error occurred. The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBPKCS7_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBPKCS7_encrypt_ex()\fR was added in OpenSSL 3.0. -.PP -The \fB\s-1PKCS7_STREAM\s0\fR flag was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS7_encrypt_ex.3ossl b/openssl-install/share/man/man3/PKCS7_encrypt_ex.3ossl deleted file mode 120000 index d72dd4ea..00000000 --- a/openssl-install/share/man/man3/PKCS7_encrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS7_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_free.3ossl b/openssl-install/share/man/man3/PKCS7_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_get0_signers.3ossl b/openssl-install/share/man/man3/PKCS7_get0_signers.3ossl deleted file mode 120000 index b8301e79..00000000 --- a/openssl-install/share/man/man3/PKCS7_get0_signers.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS7_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_get_octet_string.3ossl b/openssl-install/share/man/man3/PKCS7_get_octet_string.3ossl deleted file mode 100644 index c0969944..00000000 --- a/openssl-install/share/man/man3/PKCS7_get_octet_string.3ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS7_GET_OCTET_STRING 3ossl" -.TH PKCS7_GET_OCTET_STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS7_get_octet_string \- return octet string from a PKCS#7 envelopedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_OCTET_STRING *PKCS7_get_octet_string(PKCS7 *p7); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS7_get_octet_string()\fR returns a pointer to an \s-1ASN1\s0 octet string from a -PKCS#7 envelopedData structure or \fB\s-1NULL\s0\fR if the structure cannot be parsed. -.SH "NOTES" -.IX Header "NOTES" -As the \fB0\fR implies, \fBPKCS7_get_octet_string()\fR returns internal pointers which -should not be freed by the caller. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS7_get_octet_string()\fR returns an \s-1ASN1_OCTET_STRING\s0 pointer. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS7_type_is_data\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS7_new.3ossl b/openssl-install/share/man/man3/PKCS7_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_new_ex.3ossl b/openssl-install/share/man/man3/PKCS7_new_ex.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_print_ctx.3ossl b/openssl-install/share/man/man3/PKCS7_print_ctx.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS7_print_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_sign.3ossl b/openssl-install/share/man/man3/PKCS7_sign.3ossl deleted file mode 100644 index bc5e7877..00000000 --- a/openssl-install/share/man/man3/PKCS7_sign.3ossl +++ /dev/null @@ -1,262 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS7_SIGN 3ossl" -.TH PKCS7_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS7_sign_ex, PKCS7_sign -\&\- create a PKCS#7 signedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, -\& BIO *data, int flags, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, -\& BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS7_sign_ex()\fR creates and returns a PKCS#7 signedData structure. -\&\fIsigncert\fR is the certificate to sign with, \fIpkey\fR is the corresponding -private key. \fIcerts\fR is an optional set of extra certificates to include -in the PKCS#7 structure (for example any intermediate CAs in the chain). -The library context \fIlibctx\fR and property query \fIpropq\fR are used when -retrieving algorithms from providers. -.PP -The data to be signed is read from \s-1BIO\s0 \fIdata\fR. -.PP -\&\fIflags\fR is an optional set of flags. -.PP -Any of the following flags (ored together) can be passed in the \fIflags\fR -parameter. -.PP -Many S/MIME clients expect the signed content to include valid \s-1MIME\s0 headers. If -the \fB\s-1PKCS7_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \f(CW\*(C`text/plain\*(C'\fR are prepended -to the data. -.PP -If \fB\s-1PKCS7_NOCERTS\s0\fR is set the signer's certificate and the extra \fIcerts\fR -will not be included in the \s-1PKCS7\s0 structure. -The signer's certificate must still be supplied in the \fIsigncert\fR parameter -though. This can reduce the size of the signatures if the signer's certificates -can be obtained by other means: for example a previously signed message. -.PP -The data being signed is included in the \s-1PKCS7\s0 structure, unless -\&\fB\s-1PKCS7_DETACHED\s0\fR is set in which case it is omitted. This is used for \s-1PKCS7\s0 -detached signatures which are used in S/MIME plaintext signed messages for -example. -.PP -Normally the supplied content is translated into \s-1MIME\s0 canonical format (as -required by the S/MIME specifications) if \fB\s-1PKCS7_BINARY\s0\fR is set no translation -occurs. This option should be used if the supplied data is in binary format -otherwise the translation will corrupt it. -.PP -The signedData structure includes several PKCS#7 authenticatedAttributes -including the signing time, the PKCS#7 content type and the supported list of -ciphers in an SMIMECapabilities attribute. If \fB\s-1PKCS7_NOATTR\s0\fR is set then no -authenticatedAttributes will be used. If \fB\s-1PKCS7_NOSMIMECAP\s0\fR is set then just -the SMIMECapabilities are omitted. -.PP -If present the SMIMECapabilities attribute indicates support for the following -algorithms: triple \s-1DES, 128\s0 bit \s-1RC2, 64\s0 bit \s-1RC2, DES\s0 and 40 bit \s-1RC2.\s0 If any of -these algorithms is disabled then it will not be included. -.PP -If the flags \fB\s-1PKCS7_STREAM\s0\fR is set then the returned \fB\s-1PKCS7\s0\fR structure is -just initialized ready to perform the signing operation. The signing is however -\&\fBnot\fR performed and the data to be signed is not read from the \fIdata\fR -parameter. Signing is deferred until after the data has been written. In this -way data can be signed in a single pass. -.PP -If the \fB\s-1PKCS7_PARTIAL\s0\fR flag is set a partial \fB\s-1PKCS7\s0\fR structure is output to -which additional signers and capabilities can be added before finalization. -.PP -If the flag \fB\s-1PKCS7_STREAM\s0\fR is set the returned \fB\s-1PKCS7\s0\fR structure is \fBnot\fR -complete and outputting its contents via a function that does not properly -finalize the \fB\s-1PKCS7\s0\fR structure will give unpredictable results. -.PP -Several functions including \fBSMIME_write_PKCS7()\fR, \fBi2d_PKCS7_bio_stream()\fR, -\&\fBPEM_write_bio_PKCS7_stream()\fR finalize the structure. Alternatively finalization -can be performed by obtaining the streaming \s-1ASN1\s0 \fB\s-1BIO\s0\fR directly using -\&\fBBIO_new_PKCS7()\fR. -.PP -If a signer is specified it will use the default digest for the signing -algorithm. This is \fB\s-1SHA256\s0\fR for both \s-1RSA\s0 and \s-1DSA\s0 keys. -.PP -The \fIcerts\fR, \fIsigncert\fR and \fIpkey\fR parameters can all be -\&\s-1NULL\s0 if the \fB\s-1PKCS7_PARTIAL\s0\fR flag is set. One or more signers can be added -using the function \fBPKCS7_sign_add_signer()\fR. \fBPKCS7_final()\fR must also be -called to finalize the structure if streaming is not enabled. Alternative -signing digests can also be specified using this method. -.PP -If \fIsigncert\fR and \fIpkey\fR are \s-1NULL\s0 then a certificates only -PKCS#7 structure is output. -.PP -In versions of OpenSSL before 1.0.0 the \fIsigncert\fR and \fIpkey\fR parameters must -not be \s-1NULL.\s0 -.PP -\&\fBPKCS7_sign()\fR is like \fBPKCS7_sign_ex()\fR except that it uses default values of -\&\s-1NULL\s0 for the library context \fIlibctx\fR and the property query \fIpropq\fR. -This is retained for \s-1API\s0 backward compatibility. -.SH "BUGS" -.IX Header "BUGS" -Some advanced attributes such as counter signatures are not supported. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS7_sign_ex()\fR and \fBPKCS7_sign()\fR return either a valid \s-1PKCS7\s0 structure -or \s-1NULL\s0 if an error occurred. The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBPKCS7_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBPKCS7_sign_ex()\fR was added in OpenSSL 3.0. -.PP -The \fB\s-1PKCS7_PARTIAL\s0\fR flag, and the ability for \fIcerts\fR, \fIsigncert\fR, -and \fIpkey\fR parameters to be \s-1NULL\s0 were added in OpenSSL 1.0.0. -.PP -The \fB\s-1PKCS7_STREAM\s0\fR flag was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS7_sign_add_signer.3ossl b/openssl-install/share/man/man3/PKCS7_sign_add_signer.3ossl deleted file mode 100644 index ff47a910..00000000 --- a/openssl-install/share/man/man3/PKCS7_sign_add_signer.3ossl +++ /dev/null @@ -1,239 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS7_SIGN_ADD_SIGNER 3ossl" -.TH PKCS7_SIGN_ADD_SIGNER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS7_sign_add_signer, -PKCS7_add_certificate, PKCS7_add_crl \- add information to PKCS7 structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS7_SIGNER_INFO *PKCS7_sign_add_signer(PKCS7 *p7, X509 *signcert, -\& EVP_PKEY *pkey, const EVP_MD *md, int flags); -\& int PKCS7_add_certificate(PKCS7 *p7, X509 *cert); -\& int PKCS7_add_crl(PKCS7 *p7, X509_CRL *crl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS7_sign_add_signer()\fR adds a signer with certificate \fIsigncert\fR and private -key \fIpkey\fR using message digest \fImd\fR to a \s-1PKCS7\s0 signed data structure \fIp7\fR. -.PP -The \fB\s-1PKCS7\s0\fR structure should be obtained from an initial call to \fBPKCS7_sign()\fR -with the flag \fB\s-1PKCS7_PARTIAL\s0\fR set or in the case or re-signing a valid PKCS#7 -signed data structure. -.PP -If the \fImd\fR parameter is \s-1NULL\s0 then the default digest for the public -key algorithm will be used. -.PP -Unless the \fB\s-1PKCS7_REUSE_DIGEST\s0\fR flag is set the returned \fB\s-1PKCS7\s0\fR structure -is not complete and must be finalized either by streaming (if applicable) or -a call to \fBPKCS7_final()\fR. -.SH "NOTES" -.IX Header "NOTES" -The main purpose of this function is to provide finer control over a PKCS#7 -signed data structure where the simpler \fBPKCS7_sign()\fR function defaults are -not appropriate. For example if multiple signers or non default digest -algorithms are needed. -.PP -Any of the following flags (ored together) can be passed in the \fIflags\fR -parameter. -.PP -If \fB\s-1PKCS7_REUSE_DIGEST\s0\fR is set then an attempt is made to copy the content -digest value from the \fB\s-1PKCS7\s0\fR structure: to add a signer to an existing structure. -An error occurs if a matching digest value cannot be found to copy. The -returned \fB\s-1PKCS7\s0\fR structure will be valid and finalized when this flag is set. -.PP -If \fB\s-1PKCS7_PARTIAL\s0\fR is set in addition to \fB\s-1PKCS7_REUSE_DIGEST\s0\fR then the -\&\fB\s-1PKCS7_SIGNER_INO\s0\fR structure will not be finalized so additional attributes -can be added. In this case an explicit call to \fBPKCS7_SIGNER_INFO_sign()\fR is -needed to finalize it. -.PP -If \fB\s-1PKCS7_NOCERTS\s0\fR is set the signer's certificate will not be included in the -\&\fB\s-1PKCS7\s0\fR structure, the signer's certificate must still be supplied in the -\&\fIsigncert\fR parameter though. This can reduce the size of the signature if the -signers certificate can be obtained by other means: for example a previously -signed message. -.PP -The signedData structure includes several PKCS#7 authenticatedAttributes -including the signing time, the PKCS#7 content type and the supported list of -ciphers in an SMIMECapabilities attribute. If \fB\s-1PKCS7_NOATTR\s0\fR is set then no -authenticatedAttributes will be used. If \fB\s-1PKCS7_NOSMIMECAP\s0\fR is set then just -the SMIMECapabilities are omitted. -.PP -If present the SMIMECapabilities attribute indicates support for the following -algorithms: triple \s-1DES, 128\s0 bit \s-1RC2, 64\s0 bit \s-1RC2, DES\s0 and 40 bit \s-1RC2.\s0 If any of -these algorithms is disabled then it will not be included. -.PP -\&\fBPKCS7_sign_add_signers()\fR returns an internal pointer to the \fB\s-1PKCS7_SIGNER_INFO\s0\fR -structure just added, which can be used to set additional attributes -before it is finalized. -.PP -\&\fBPKCS7_add_certificate()\fR adds to the \fB\s-1PKCS7\s0\fR structure \fIp7\fR the certificate -\&\fIcert\fR, which may be an end-entity (signer) certificate -or a \s-1CA\s0 certificate useful for chain building. -This is done internally by \fBPKCS7_sign_ex\fR\|(3) and similar signing functions. -It may have to be used before calling \fBPKCS7_verify\fR\|(3) -in order to provide any missing certificate(s) needed for verification. -.PP -\&\fBPKCS7_add_crl()\fR adds the \s-1CRL\s0 \fIcrl\fR to the \fB\s-1PKCS7\s0\fR structure \fIp7\fR. -This may be called to provide certificate status information -to be included when signing or to use when verifying the \fB\s-1PKCS7\s0\fR structure. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS7_sign_add_signers()\fR returns an internal pointer to the \fB\s-1PKCS7_SIGNER_INFO\s0\fR -structure just added or \s-1NULL\s0 if an error occurs. -.PP -\&\fBPKCS7_add_certificate()\fR and \fBPKCS7_add_crl()\fR return 1 on success, 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBPKCS7_sign_ex\fR\|(3), -\&\fBPKCS7_final\fR\|(3), \fBPKCS7_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBPPKCS7_sign_add_signer()\fR function was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2007\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS7_sign_ex.3ossl b/openssl-install/share/man/man3/PKCS7_sign_ex.3ossl deleted file mode 120000 index 0dded3c1..00000000 --- a/openssl-install/share/man/man3/PKCS7_sign_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS7_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS7_type_is_other.3ossl b/openssl-install/share/man/man3/PKCS7_type_is_other.3ossl deleted file mode 100644 index 58ba5509..00000000 --- a/openssl-install/share/man/man3/PKCS7_type_is_other.3ossl +++ /dev/null @@ -1,174 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS7_TYPE_IS_OTHER 3ossl" -.TH PKCS7_TYPE_IS_OTHER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS7_type_is_other \- determine content type of PKCS#7 envelopedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS7_type_is_other(PKCS7 *p7); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS7_type_is_other()\fR returns the whether the content type of a PKCS#7 envelopedData -structure is one of the following content types: -.PP -NID_pkcs7_data -NID_pkcs7_signed -NID_pkcs7_enveloped -NID_pkcs7_signedAndEnveloped -NID_pkcs7_digest -NID_pkcs7_encrypted -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS7_type_is_other()\fR returns either 0 if the content type is matched or 1 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPKCS7_type_is_data\fR\|(3), \fBPKCS7_get_octet_string\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS7_verify.3ossl b/openssl-install/share/man/man3/PKCS7_verify.3ossl deleted file mode 100644 index a43b3dcd..00000000 --- a/openssl-install/share/man/man3/PKCS7_verify.3ossl +++ /dev/null @@ -1,272 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS7_VERIFY 3ossl" -.TH PKCS7_VERIFY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS7_verify, PKCS7_get0_signers \- verify a PKCS#7 signedData structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int PKCS7_verify(PKCS7 *p7, STACK_OF(X509) *certs, X509_STORE *store, -\& BIO *indata, BIO *out, int flags); -\& -\& STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, STACK_OF(X509) *certs, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS7_verify()\fR is very similar to \fBCMS_verify\fR\|(3). -It verifies a PKCS#7 signedData structure given in \fIp7\fR. -The optional \fIcerts\fR parameter refers to a set of certificates -in which to search for signer's certificates. -It is also used -as a source of untrusted intermediate \s-1CA\s0 certificates for chain building. -\&\fIp7\fR may contain extra untrusted \s-1CA\s0 certificates that may be used for -chain building as well as CRLs that may be used for certificate validation. -\&\fIstore\fR may be \s-1NULL\s0 or point to -the trusted certificate store to use for chain verification. -\&\fIindata\fR refers to the signed data if the content is detached from \fIp7\fR. -Otherwise \fIindata\fR should be \s-1NULL,\s0 and then the signed data must be in \fIp7\fR. -The content is written to the \s-1BIO\s0 \fIout\fR unless it is \s-1NULL.\s0 -\&\fIflags\fR is an optional set of flags, which can be used to modify the operation. -.PP -\&\fBPKCS7_get0_signers()\fR retrieves the signer's certificates from \fIp7\fR, it does -\&\fBnot\fR check their validity or whether any signatures are valid. The \fIcerts\fR -and \fIflags\fR parameters have the same meanings as in \fBPKCS7_verify()\fR. -.SH "VERIFY PROCESS" -.IX Header "VERIFY PROCESS" -Normally the verify process proceeds as follows. -.PP -Initially some sanity checks are performed on \fIp7\fR. The type of \fIp7\fR must -be SignedData. There must be at least one signature on the data and if -the content is detached \fIindata\fR cannot be \s-1NULL.\s0 If the content is -not detached and \fIindata\fR is not \s-1NULL\s0 then the structure has both -embedded and external content. To treat this as an error, use the flag -\&\fB\s-1PKCS7_NO_DUAL_CONTENT\s0\fR. -The default behavior allows this, for compatibility with older -versions of OpenSSL. -.PP -An attempt is made to locate all the signer's certificates, first looking in -the \fIcerts\fR parameter (if it is not \s-1NULL\s0). Then they are looked up in any -certificates contained in the \fIp7\fR structure unless \fB\s-1PKCS7_NOINTERN\s0\fR is set. -If any signer's certificates cannot be located the operation fails. -.PP -Each signer's certificate is chain verified using the \fBsmimesign\fR purpose and -using the trusted certificate store \fIstore\fR if supplied. -Any internal certificates in the message, which may have been added using -\&\fBPKCS7_add_certificate\fR\|(3), are used as untrusted CAs unless \fB\s-1PKCS7_NOCHAIN\s0\fR -is set. -If \s-1CRL\s0 checking is enabled in \fIstore\fR and \fB\s-1PKCS7_NOCRL\s0\fR is not set, -any internal CRLs, which may have been added using \fBPKCS7_add_crl\fR\|(3), -are used in addition to attempting to look them up in \fIstore\fR. -If \fIstore\fR is not \s-1NULL\s0 and any chain verify fails an error code is returned. -.PP -Finally the signed content is read (and written to \fIout\fR unless it is \s-1NULL\s0) -and the signature is checked. -.PP -If all signatures verify correctly then the function is successful. -.PP -Any of the following flags (ored together) can be passed in the \fIflags\fR -parameter to change the default verify behaviour. -Only the flag \fB\s-1PKCS7_NOINTERN\s0\fR is meaningful to \fBPKCS7_get0_signers()\fR. -.PP -If \fB\s-1PKCS7_NOINTERN\s0\fR is set the certificates in the message itself are not -searched when locating the signer's certificates. -This means that all the signer's certificates must be in the \fIcerts\fR parameter. -.PP -If \fB\s-1PKCS7_NOCRL\s0\fR is set and \s-1CRL\s0 checking is enabled in \fIstore\fR then any -CRLs in the message itself are ignored. -.PP -If the \fB\s-1PKCS7_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \f(CW\*(C`text/plain\*(C'\fR are deleted -from the content. If the content is not of type \f(CW\*(C`text/plain\*(C'\fR then an error is -returned. -.PP -If \fB\s-1PKCS7_NOVERIFY\s0\fR is set the signer's certificates are not chain verified. -.PP -If \fB\s-1PKCS7_NOCHAIN\s0\fR is set then the certificates contained in the message are -not used as untrusted CAs. This means that the whole verify chain (apart from -the signer's certificates) must be contained in the trusted store. -.PP -If \fB\s-1PKCS7_NOSIGS\s0\fR is set then the signatures on the data are not checked. -.SH "NOTES" -.IX Header "NOTES" -One application of \fB\s-1PKCS7_NOINTERN\s0\fR is to only accept messages signed by -a small number of certificates. The acceptable certificates would be passed -in the \fIcerts\fR parameter. In this case if the signer's certificate is not one -of the certificates supplied in \fIcerts\fR then the verify will fail because the -signer cannot be found. -.PP -Care should be taken when modifying the default verify behaviour, for example -setting \f(CW\*(C`PKCS7_NOVERIFY|PKCS7_NOSIGS\*(C'\fR will totally disable all verification -and any signed message will be considered valid. This combination is however -useful if one merely wishes to write the content to \fIout\fR and its validity -is not considered important. -.PP -Chain verification should arguably be performed using the signing time rather -than the current time. However, since the signing time is supplied by the -signer it cannot be trusted without additional evidence (such as a trusted -timestamp). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS7_verify()\fR returns 1 for a successful verification and 0 if an error occurs. -.PP -\&\fBPKCS7_get0_signers()\fR returns all signers or \s-1NULL\s0 if an error occurred. -.PP -The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "BUGS" -.IX Header "BUGS" -The trusted certificate store is not searched for the signer's certificates. -This is primarily due to the inadequacies of the current \fBX509_STORE\fR -functionality. -.PP -The lack of single pass processing means that the signed content must all -be held in memory if it is not detached. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBCMS_verify\fR\|(3), \fBPKCS7_add_certificate\fR\|(3), \fBPKCS7_add_crl\fR\|(3), -\&\fBERR_get_error\fR\|(3), \fBPKCS7_sign\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_free.3ossl b/openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_new.3ossl b/openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKCS8_PRIV_KEY_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_decrypt.3ossl b/openssl-install/share/man/man3/PKCS8_decrypt.3ossl deleted file mode 120000 index 015f46b4..00000000 --- a/openssl-install/share/man/man3/PKCS8_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_decrypt_ex.3ossl b/openssl-install/share/man/man3/PKCS8_decrypt_ex.3ossl deleted file mode 120000 index 015f46b4..00000000 --- a/openssl-install/share/man/man3/PKCS8_decrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_encrypt.3ossl b/openssl-install/share/man/man3/PKCS8_encrypt.3ossl deleted file mode 100644 index ff19731b..00000000 --- a/openssl-install/share/man/man3/PKCS8_encrypt.3ossl +++ /dev/null @@ -1,208 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS8_ENCRYPT 3ossl" -.TH PKCS8_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS8_decrypt, PKCS8_decrypt_ex, PKCS8_encrypt, PKCS8_encrypt_ex, -PKCS8_set0_pbe, PKCS8_set0_pbe_ex \- PKCS8 encrypt/decrypt functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS8_PRIV_KEY_INFO *PKCS8_decrypt(const X509_SIG *p8, const char *pass, -\& int passlen); -\& PKCS8_PRIV_KEY_INFO *PKCS8_decrypt_ex(const X509_SIG *p8, const char *pass, -\& int passlen, OSSL_LIB_CTX *ctx, -\& const char *propq); -\& X509_SIG *PKCS8_encrypt(int pbe_nid, const EVP_CIPHER *cipher, -\& const char *pass, int passlen, unsigned char *salt, -\& int saltlen, int iter, PKCS8_PRIV_KEY_INFO *p8); -\& X509_SIG *PKCS8_encrypt_ex(int pbe_nid, const EVP_CIPHER *cipher, -\& const char *pass, int passlen, unsigned char *salt, -\& int saltlen, int iter, PKCS8_PRIV_KEY_INFO *p8, -\& OSSL_LIB_CTX *ctx, const char *propq); -\& X509_SIG *PKCS8_set0_pbe(const char *pass, int passlen, -\& PKCS8_PRIV_KEY_INFO *p8inf, X509_ALGOR *pbe); -\& X509_SIG *PKCS8_set0_pbe_ex(const char *pass, int passlen, -\& PKCS8_PRIV_KEY_INFO *p8inf, X509_ALGOR *pbe, -\& OSSL_LIB_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS8_encrypt()\fR and \fBPKCS8_encrypt_ex()\fR perform encryption of an object \fIp8\fR using -the password \fIpass\fR of length \fIpasslen\fR, salt \fIsalt\fR of length \fIsaltlen\fR -and iteration count \fIiter\fR. -The resulting \fBX509_SIG\fR contains the encoded algorithm parameters and encrypted -key. -.PP -\&\fBPKCS8_decrypt()\fR and \fBPKCS8_decrypt_ex()\fR perform decryption of an \fBX509_SIG\fR in -\&\fIp8\fR using the password \fIpass\fR of length \fIpasslen\fR along with algorithm -parameters obtained from the \fIp8\fR. -.PP -\&\fBPKCS8_set0_pbe()\fR and \fBPKCS8_set0_pbe_ex()\fR perform encryption of the \fIp8inf\fR -using the password \fIpass\fR of length \fIpasslen\fR and parameters \fIpbe\fR. -.PP -Functions ending in \fB_ex()\fR allow for a library context \fIctx\fR and property query -\&\fIpropq\fR to be used to select algorithm implementations. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS8_encrypt()\fR, \fBPKCS8_encrypt_ex()\fR, \fBPKCS8_set0_pbe()\fR and \fBPKCS8_set0_pbe_ex()\fR -return an encrypted key in a \fBX509_SIG\fR structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBPKCS8_decrypt()\fR and \fBPKCS8_decrypt_ex()\fR return a \fB\s-1PKCS8_PRIV_KEY_INFO\s0\fR or \s-1NULL\s0 -if an error occurs. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1IETF RFC 7292\s0 () -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBPKCS8_decrypt_ex()\fR, \fBPKCS8_encrypt_ex()\fR and \fBPKCS8_set0_pbe_ex()\fR were added in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS8_encrypt_ex.3ossl b/openssl-install/share/man/man3/PKCS8_encrypt_ex.3ossl deleted file mode 120000 index 015f46b4..00000000 --- a/openssl-install/share/man/man3/PKCS8_encrypt_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_pkey_add1_attr.3ossl b/openssl-install/share/man/man3/PKCS8_pkey_add1_attr.3ossl deleted file mode 100644 index 1411a761..00000000 --- a/openssl-install/share/man/man3/PKCS8_pkey_add1_attr.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PKCS8_PKEY_ADD1_ATTR 3ossl" -.TH PKCS8_PKEY_ADD1_ATTR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -PKCS8_pkey_get0_attrs, PKCS8_pkey_add1_attr, PKCS8_pkey_add1_attr_by_NID, PKCS8_pkey_add1_attr_by_OBJ \- PKCS8 attribute functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const STACK_OF(X509_ATTRIBUTE) * -\& PKCS8_pkey_get0_attrs(const PKCS8_PRIV_KEY_INFO *p8); -\& int PKCS8_pkey_add1_attr(PKCS8_PRIV_KEY_INFO *p8, X509_ATTRIBUTE *attr); -\& int PKCS8_pkey_add1_attr_by_NID(PKCS8_PRIV_KEY_INFO *p8, int nid, int type, -\& const unsigned char *bytes, int len); -\& int PKCS8_pkey_add1_attr_by_OBJ(PKCS8_PRIV_KEY_INFO *p8, const ASN1_OBJECT *obj, -\& int type, const unsigned char *bytes, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBPKCS8_pkey_get0_attrs()\fR returns a const \s-1STACK\s0 of X509_ATTRIBUTE present in -the passed const \s-1PKCS8_PRIV_KEY_INFO\s0 structure \fBp8\fR. -.PP -\&\fBPKCS8_pkey_add1_attr()\fR adds a constructed X509_ATTRIBUTE \fBattr\fR to the -existing \s-1PKCS8_PRIV_KEY_INFO\s0 structure \fBp8\fR. -.PP -\&\fBPKCS8_pkey_add1_attr_by_NID()\fR and \fBPKCS8_pkey_add1_attr_by_OBJ()\fR construct a new -X509_ATTRIBUTE from the passed arguments and add it to the existing -\&\s-1PKCS8_PRIV_KEY_INFO\s0 structure \fBp8\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBPKCS8_pkey_add1_attr()\fR, \fBPKCS8_pkey_add1_attr_by_NID()\fR, and -\&\fBPKCS8_pkey_add1_attr_by_OBJ()\fR return 1 for success and 0 for failure. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1STACK\s0 of X509_ATTRIBUTE is present in many X509\-related structures and some of -them have the corresponding set of similar functions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_NID.3ossl deleted file mode 120000 index b6ba4dac..00000000 --- a/openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_pkey_add1_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_OBJ.3ossl deleted file mode 120000 index b6ba4dac..00000000 --- a/openssl-install/share/man/man3/PKCS8_pkey_add1_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_pkey_add1_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_pkey_get0_attrs.3ossl b/openssl-install/share/man/man3/PKCS8_pkey_get0_attrs.3ossl deleted file mode 120000 index b6ba4dac..00000000 --- a/openssl-install/share/man/man3/PKCS8_pkey_get0_attrs.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_pkey_add1_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_set0_pbe.3ossl b/openssl-install/share/man/man3/PKCS8_set0_pbe.3ossl deleted file mode 120000 index 015f46b4..00000000 --- a/openssl-install/share/man/man3/PKCS8_set0_pbe.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKCS8_set0_pbe_ex.3ossl b/openssl-install/share/man/man3/PKCS8_set0_pbe_ex.3ossl deleted file mode 120000 index 015f46b4..00000000 --- a/openssl-install/share/man/man3/PKCS8_set0_pbe_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -PKCS8_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKEY_USAGE_PERIOD_free.3ossl b/openssl-install/share/man/man3/PKEY_USAGE_PERIOD_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKEY_USAGE_PERIOD_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PKEY_USAGE_PERIOD_new.3ossl b/openssl-install/share/man/man3/PKEY_USAGE_PERIOD_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PKEY_USAGE_PERIOD_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICYINFO_free.3ossl b/openssl-install/share/man/man3/POLICYINFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICYINFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICYINFO_new.3ossl b/openssl-install/share/man/man3/POLICYINFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICYINFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICYQUALINFO_free.3ossl b/openssl-install/share/man/man3/POLICYQUALINFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICYQUALINFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICYQUALINFO_new.3ossl b/openssl-install/share/man/man3/POLICYQUALINFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICYQUALINFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICY_CONSTRAINTS_free.3ossl b/openssl-install/share/man/man3/POLICY_CONSTRAINTS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICY_CONSTRAINTS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICY_CONSTRAINTS_new.3ossl b/openssl-install/share/man/man3/POLICY_CONSTRAINTS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICY_CONSTRAINTS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICY_MAPPING_free.3ossl b/openssl-install/share/man/man3/POLICY_MAPPING_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICY_MAPPING_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/POLICY_MAPPING_new.3ossl b/openssl-install/share/man/man3/POLICY_MAPPING_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/POLICY_MAPPING_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFOS.3ossl b/openssl-install/share/man/man3/PROFESSION_INFOS.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFOS.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFOS_free.3ossl b/openssl-install/share/man/man3/PROFESSION_INFOS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFOS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFOS_new.3ossl b/openssl-install/share/man/man3/PROFESSION_INFOS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFOS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_free.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_get0_addProfessionInfo.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_get0_addProfessionInfo.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_get0_addProfessionInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_get0_namingAuthority.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_get0_namingAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_get0_namingAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_get0_professionItems.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_get0_professionItems.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_get0_professionItems.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_get0_professionOIDs.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_get0_professionOIDs.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_get0_professionOIDs.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_get0_registrationNumber.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_get0_registrationNumber.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_get0_registrationNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_new.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_set0_addProfessionInfo.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_set0_addProfessionInfo.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_set0_addProfessionInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_set0_namingAuthority.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_set0_namingAuthority.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_set0_namingAuthority.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_set0_professionItems.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_set0_professionItems.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_set0_professionItems.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_set0_professionOIDs.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_set0_professionOIDs.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_set0_professionOIDs.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROFESSION_INFO_set0_registrationNumber.3ossl b/openssl-install/share/man/man3/PROFESSION_INFO_set0_registrationNumber.3ossl deleted file mode 120000 index d03e14cb..00000000 --- a/openssl-install/share/man/man3/PROFESSION_INFO_set0_registrationNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -ADMISSIONS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_free.3ossl b/openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_new.3ossl b/openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROXY_CERT_INFO_EXTENSION_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROXY_POLICY_free.3ossl b/openssl-install/share/man/man3/PROXY_POLICY_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROXY_POLICY_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/PROXY_POLICY_new.3ossl b/openssl-install/share/man/man3/PROXY_POLICY_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/PROXY_POLICY_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_OpenSSL.3ossl b/openssl-install/share/man/man3/RAND_OpenSSL.3ossl deleted file mode 120000 index 8efdc379..00000000 --- a/openssl-install/share/man/man3/RAND_OpenSSL.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_set_rand_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_add.3ossl b/openssl-install/share/man/man3/RAND_add.3ossl deleted file mode 100644 index 5d02ebbf..00000000 --- a/openssl-install/share/man/man3/RAND_add.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_ADD 3ossl" -.TH RAND_ADD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_add, RAND_poll, RAND_seed, RAND_status, RAND_event, RAND_screen, -RAND_keep_random_devices_open -\&\- add randomness to the PRNG or get its status -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int RAND_status(void); -\& int RAND_poll(); -\& -\& void RAND_add(const void *buf, int num, double randomness); -\& void RAND_seed(const void *buf, int num); -\& -\& void RAND_keep_random_devices_open(int keep); -.Ve -.PP -The following functions have been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int RAND_event(UINT iMsg, WPARAM wParam, LPARAM lParam); -\& void RAND_screen(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions can be used to seed the random generator and to check its -seeded state. -In general, manual (re\-)seeding of the default OpenSSL random generator -(\fBRAND_OpenSSL\fR\|(3)) is not necessary (but allowed), since it does (re\-)seed -itself automatically using trusted system entropy sources. -This holds unless the default \s-1RAND_METHOD\s0 has been replaced or OpenSSL was -built with automatic reseeding disabled, see \s-1\fBRAND\s0\fR\|(7) for more details. -.PP -\&\fBRAND_status()\fR indicates whether or not the random generator has been sufficiently -seeded. If not, functions such as \fBRAND_bytes\fR\|(3) will fail. -.PP -\&\fBRAND_poll()\fR uses the system's capabilities to seed the random generator using -random input obtained from polling various trusted entropy sources. -The default choice of the entropy source can be modified at build time, -see \s-1\fBRAND\s0\fR\|(7) for more details. -.PP -\&\fBRAND_add()\fR mixes the \fBnum\fR bytes at \fBbuf\fR into the internal state -of the random generator. -This function will not normally be needed, as mentioned above. -The \fBrandomness\fR argument is an estimate of how much randomness is -contained in -\&\fBbuf\fR, in bytes, and should be a number between zero and \fBnum\fR. -Details about sources of randomness and how to estimate their randomness -can be found in the literature; for example [\s-1NIST SP 800\-90B\s0]. -The content of \fBbuf\fR cannot be recovered from subsequent random generator output. -Applications that intend to save and restore random state in an external file -should consider using \fBRAND_load_file\fR\|(3) instead. -.PP -\&\s-1NOTE:\s0 In \s-1FIPS\s0 mode, random data provided by the application is not considered to -be a trusted entropy source. It is mixed into the internal state of the \s-1RNG\s0 as -additional data only and this does not count as a full reseed. -For more details, see \s-1\fBEVP_RAND\s0\fR\|(7). -.PP -\&\fBRAND_seed()\fR is equivalent to \fBRAND_add()\fR with \fBrandomness\fR set to \fBnum\fR. -.PP -\&\fBRAND_keep_random_devices_open()\fR is used to control file descriptor -usage by the random seed sources. Some seed sources maintain open file -descriptors by default, which allows such sources to operate in a -\&\fBchroot\fR\|(2) jail without the associated device nodes being available. When -the \fBkeep\fR argument is zero, this call disables the retention of file -descriptors. Conversely, a nonzero argument enables the retention of -file descriptors. This function is usually called during initialization -and it takes effect immediately. This capability only applies to the default -provider. -.PP -\&\fBRAND_event()\fR and \fBRAND_screen()\fR are equivalent to \fBRAND_poll()\fR and exist -for compatibility reasons only. See \s-1HISTORY\s0 section below. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRAND_status()\fR returns 1 if the random generator has been seeded -with enough data, 0 otherwise. -.PP -\&\fBRAND_poll()\fR returns 1 if it generated seed data, 0 otherwise. -.PP -\&\fBRAND_event()\fR returns \fBRAND_status()\fR. -.PP -The other functions do not return values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRAND_bytes\fR\|(3), -\&\fBRAND_egd\fR\|(3), -\&\fBRAND_load_file\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -\&\s-1\fBEVP_RAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBRAND_event()\fR and \fBRAND_screen()\fR were deprecated in OpenSSL 1.1.0 and should -not be used. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_bytes.3ossl b/openssl-install/share/man/man3/RAND_bytes.3ossl deleted file mode 100644 index f19b0be0..00000000 --- a/openssl-install/share/man/man3/RAND_bytes.3ossl +++ /dev/null @@ -1,234 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_BYTES 3ossl" -.TH RAND_BYTES 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_bytes, RAND_priv_bytes, RAND_bytes_ex, RAND_priv_bytes_ex, -RAND_pseudo_bytes \- generate random data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int RAND_bytes(unsigned char *buf, int num); -\& int RAND_priv_bytes(unsigned char *buf, int num); -\& -\& int RAND_bytes_ex(OSSL_LIB_CTX *ctx, unsigned char *buf, size_t num, -\& unsigned int strength); -\& int RAND_priv_bytes_ex(OSSL_LIB_CTX *ctx, unsigned char *buf, size_t num, -\& unsigned int strength); -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int RAND_pseudo_bytes(unsigned char *buf, int num); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBRAND_bytes()\fR generates \fBnum\fR random bytes using a cryptographically -secure pseudo random generator (\s-1CSPRNG\s0) and stores them in \fBbuf\fR. -.PP -\&\fBRAND_priv_bytes()\fR has the same semantics as \fBRAND_bytes()\fR. It is intended to -be used for generating values that should remain private. If using the -default \s-1RAND_METHOD,\s0 this function uses a separate \*(L"private\*(R" \s-1PRNG\s0 -instance so that a compromise of the \*(L"public\*(R" \s-1PRNG\s0 instance will not -affect the secrecy of these private values, as described in \s-1\fBRAND\s0\fR\|(7) -and \s-1\fBEVP_RAND\s0\fR\|(7). -.PP -\&\fBRAND_bytes_ex()\fR and \fBRAND_priv_bytes_ex()\fR are the same as \fBRAND_bytes()\fR and -\&\fBRAND_priv_bytes()\fR except that they both take additional \fIstrength\fR and -\&\fIctx\fR parameters. The bytes generated will have a security strength of at -least \fIstrength\fR bits. -The \s-1DRBG\s0 used for the operation is the public or private \s-1DRBG\s0 associated with -the specified \fIctx\fR. The parameter can be \s-1NULL,\s0 in which case -the default library context is used (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3). -If the default \s-1RAND_METHOD\s0 has been changed then for compatibility reasons the -\&\s-1RAND_METHOD\s0 will be used in preference and the \s-1DRBG\s0 of the library context -ignored. -.SH "NOTES" -.IX Header "NOTES" -By default, the OpenSSL \s-1CSPRNG\s0 supports a security level of 256 bits, provided it -was able to seed itself from a trusted entropy source. -On all major platforms supported by OpenSSL (including the Unix-like platforms -and Windows), OpenSSL is configured to automatically seed the \s-1CSPRNG\s0 on first use -using the operating systems's random generator. -.PP -If the entropy source fails or is not available, the \s-1CSPRNG\s0 will enter an -error state and refuse to generate random bytes. For that reason, it is important -to always check the error return value of \fBRAND_bytes()\fR and \fBRAND_priv_bytes()\fR and -not take randomness for granted. -.PP -On other platforms, there might not be a trusted entropy source available -or OpenSSL might have been explicitly configured to use different entropy sources. -If you are in doubt about the quality of the entropy source, don't hesitate to ask -your operating system vendor or post a question on GitHub or the openssl-users -mailing list. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRAND_bytes()\fR and \fBRAND_priv_bytes()\fR -return 1 on success, \-1 if not supported by the current -\&\s-1RAND\s0 method, or 0 on other failure. The error code can be -obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRAND_add\fR\|(3), -\&\fBRAND_bytes\fR\|(3), -\&\fBRAND_priv_bytes\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7), -\&\s-1\fBEVP_RAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -.IP "\(bu" 2 -\&\fBRAND_pseudo_bytes()\fR was deprecated in OpenSSL 1.1.0; use \fBRAND_bytes()\fR instead. -.IP "\(bu" 2 -The \fBRAND_priv_bytes()\fR function was added in OpenSSL 1.1.1. -.IP "\(bu" 2 -The \fBRAND_bytes_ex()\fR and \fBRAND_priv_bytes_ex()\fR functions were added in OpenSSL 3.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_bytes_ex.3ossl b/openssl-install/share/man/man3/RAND_bytes_ex.3ossl deleted file mode 120000 index 7a179b48..00000000 --- a/openssl-install/share/man/man3/RAND_bytes_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_bytes.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_cleanup.3ossl b/openssl-install/share/man/man3/RAND_cleanup.3ossl deleted file mode 100644 index ab6d34e9..00000000 --- a/openssl-install/share/man/man3/RAND_cleanup.3ossl +++ /dev/null @@ -1,179 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_CLEANUP 3ossl" -.TH RAND_CLEANUP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_cleanup \- erase the PRNG state -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void RAND_cleanup(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Prior to OpenSSL 1.1.0, \fBRAND_cleanup()\fR released all resources used by -the \s-1PRNG.\s0 As of version 1.1.0, it does nothing and should not be called, -since no explicit initialisation or de-initialisation is necessary. See -\&\fBOPENSSL_init_crypto\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRAND_cleanup()\fR returns no value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBRAND_cleanup()\fR was deprecated in OpenSSL 1.1.0; do not use it. -See \fBOPENSSL_init_crypto\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_egd.3ossl b/openssl-install/share/man/man3/RAND_egd.3ossl deleted file mode 100644 index af3e014b..00000000 --- a/openssl-install/share/man/man3/RAND_egd.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_EGD 3ossl" -.TH RAND_EGD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_egd, RAND_egd_bytes, RAND_query_egd_bytes \- query entropy gathering daemon -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int RAND_egd_bytes(const char *path, int num); -\& int RAND_egd(const char *path); -\& -\& int RAND_query_egd_bytes(const char *path, unsigned char *buf, int num); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -On older platforms without a good source of randomness such as \f(CW\*(C`/dev/urandom\*(C'\fR, -it is possible to query an Entropy Gathering Daemon (\s-1EGD\s0) over a local -socket to obtain randomness and seed the OpenSSL \s-1RNG.\s0 -The protocol used is defined by the EGDs available at - or . -.PP -\&\fBRAND_egd_bytes()\fR requests \fBnum\fR bytes of randomness from an \s-1EGD\s0 at the -specified socket \fBpath\fR, and passes the data it receives into \fBRAND_add()\fR. -\&\fBRAND_egd()\fR is equivalent to \fBRAND_egd_bytes()\fR with \fBnum\fR set to 255. -.PP -\&\fBRAND_query_egd_bytes()\fR requests \fBnum\fR bytes of randomness from an \s-1EGD\s0 at -the specified socket \fBpath\fR, where \fBnum\fR must be less than 256. -If \fBbuf\fR is \fB\s-1NULL\s0\fR, it is equivalent to \fBRAND_egd_bytes()\fR. -If \fBbuf\fR is not \fB\s-1NULL\s0\fR, then the data is copied to the buffer and -\&\fBRAND_add()\fR is not called. -.PP -OpenSSL can be configured at build time to try to use the \s-1EGD\s0 for seeding -automatically. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRAND_egd()\fR and \fBRAND_egd_bytes()\fR return the number of bytes read from the -daemon on success, or \-1 if the connection failed or the daemon did not -return enough data to fully seed the \s-1PRNG.\s0 -.PP -\&\fBRAND_query_egd_bytes()\fR returns the number of bytes read from the daemon on -success, or \-1 if the connection failed. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRAND_add\fR\|(3), -\&\fBRAND_bytes\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_egd_bytes.3ossl b/openssl-install/share/man/man3/RAND_egd_bytes.3ossl deleted file mode 120000 index be3656b0..00000000 --- a/openssl-install/share/man/man3/RAND_egd_bytes.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_egd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_event.3ossl b/openssl-install/share/man/man3/RAND_event.3ossl deleted file mode 120000 index ba600c0b..00000000 --- a/openssl-install/share/man/man3/RAND_event.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_file_name.3ossl b/openssl-install/share/man/man3/RAND_file_name.3ossl deleted file mode 120000 index 3d870a35..00000000 --- a/openssl-install/share/man/man3/RAND_file_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_load_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_get0_primary.3ossl b/openssl-install/share/man/man3/RAND_get0_primary.3ossl deleted file mode 100644 index 028c1088..00000000 --- a/openssl-install/share/man/man3/RAND_get0_primary.3ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_GET0_PRIMARY 3ossl" -.TH RAND_GET0_PRIMARY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_get0_primary, -RAND_get0_public, -RAND_get0_private, -RAND_set0_public, -RAND_set0_private -\&\- get access to the global EVP_RAND_CTX instances -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_RAND_CTX *RAND_get0_primary(OSSL_LIB_CTX *ctx); -\& EVP_RAND_CTX *RAND_get0_public(OSSL_LIB_CTX *ctx); -\& EVP_RAND_CTX *RAND_get0_private(OSSL_LIB_CTX *ctx); -\& int RAND_set0_public(OSSL_LIB_CTX *ctx, EVP_RAND_CTX *rand); -\& int RAND_set0_private(OSSL_LIB_CTX *ctx, EVP_RAND_CTX *rand); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The default \s-1RAND API\s0 implementation (\fBRAND_OpenSSL()\fR) utilizes three -shared \s-1DRBG\s0 instances which are accessed via the \s-1RAND API:\s0 -.PP -The \fIpublic\fR and \fIprivate\fR \s-1DRBG\s0 are thread-local instances, which are used -by \fBRAND_bytes()\fR and \fBRAND_priv_bytes()\fR, respectively. -The \fIprimary\fR \s-1DRBG\s0 is a global instance, which is not intended to be used -directly, but is used internally to reseed the other two instances. -.PP -The three get functions provide access to the shared \s-1DRBG\s0 instances. -.PP -The two set functions allow the public and private \s-1DRBG\s0 instances to be -replaced by another random number generator. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRAND_get0_primary()\fR returns a pointer to the \fIprimary\fR \s-1DRBG\s0 instance -for the given \s-1OSSL_LIB_CTX\s0 \fBctx\fR. -.PP -\&\fBRAND_get0_public()\fR returns a pointer to the \fIpublic\fR \s-1DRBG\s0 instance -for the given \s-1OSSL_LIB_CTX\s0 \fBctx\fR. -.PP -\&\fBRAND_get0_private()\fR returns a pointer to the \fIprivate\fR \s-1DRBG\s0 instance -for the given \s-1OSSL_LIB_CTX\s0 \fBctx\fR. -.PP -\&\fBRAND_set0_public()\fR and \fBRAND_set0_private()\fR return 1 on success and 0 -on error. -.SH "NOTES" -.IX Header "NOTES" -It is not thread-safe to access the \fIprimary\fR \s-1DRBG\s0 instance. -The \fIpublic\fR and \fIprivate\fR \s-1DRBG\s0 instance can be accessed safely, because -they are thread-local. Note however, that changes to these two instances -apply only to the current thread. -.PP -For that reason it is recommended not to change the settings of these -three instances directly. -Instead, an application should change the default settings for new \s-1DRBG\s0 instances -at initialization time, before creating additional threads. -.PP -During initialization, it is possible to change the reseed interval -and reseed time interval. -It is also possible to exchange the reseeding callbacks entirely. -.PP -To set the type of \s-1DRBG\s0 that will be instantiated, use the -\&\fBRAND_set_DRBG_type\fR\|(3) call before accessing the random number generation -infrastructure. -.PP -The two set functions, operate on the current thread. If you want to -use the same random number generator across all threads, each thread -must individually call the set functions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\fBRAND_set_DRBG_type\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBRAND_set0_public()\fR and \fBRAND_set0_private()\fR were added in OpenSSL 3.1. -.PP -The remaining functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_get0_private.3ossl b/openssl-install/share/man/man3/RAND_get0_private.3ossl deleted file mode 120000 index 43e9590e..00000000 --- a/openssl-install/share/man/man3/RAND_get0_private.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_get0_primary.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_get0_public.3ossl b/openssl-install/share/man/man3/RAND_get0_public.3ossl deleted file mode 120000 index 43e9590e..00000000 --- a/openssl-install/share/man/man3/RAND_get0_public.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_get0_primary.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_get_rand_method.3ossl b/openssl-install/share/man/man3/RAND_get_rand_method.3ossl deleted file mode 120000 index 8efdc379..00000000 --- a/openssl-install/share/man/man3/RAND_get_rand_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_set_rand_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_keep_random_devices_open.3ossl b/openssl-install/share/man/man3/RAND_keep_random_devices_open.3ossl deleted file mode 120000 index ba600c0b..00000000 --- a/openssl-install/share/man/man3/RAND_keep_random_devices_open.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_load_file.3ossl b/openssl-install/share/man/man3/RAND_load_file.3ossl deleted file mode 100644 index 3f693268..00000000 --- a/openssl-install/share/man/man3/RAND_load_file.3ossl +++ /dev/null @@ -1,218 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_LOAD_FILE 3ossl" -.TH RAND_LOAD_FILE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_load_file, RAND_write_file, RAND_file_name \- PRNG seed file -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int RAND_load_file(const char *filename, long max_bytes); -\& -\& int RAND_write_file(const char *filename); -\& -\& const char *RAND_file_name(char *buf, size_t num); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBRAND_load_file()\fR reads a number of bytes from file \fBfilename\fR and -adds them to the \s-1PRNG.\s0 If \fBmax_bytes\fR is nonnegative, -up to \fBmax_bytes\fR are read; -if \fBmax_bytes\fR is \-1, the complete file is read. -Do not load the same file multiple times unless its contents have -been updated by \fBRAND_write_file()\fR between reads. -Also, note that \fBfilename\fR should be adequately protected so that an -attacker cannot replace or examine the contents. -If \fBfilename\fR is not a regular file, then user is considered to be -responsible for any side effects, e.g. non-anticipated blocking or -capture of controlling terminal. -.PP -\&\fBRAND_write_file()\fR writes a number of random bytes (currently 128) to -file \fBfilename\fR which can be used to initialize the \s-1PRNG\s0 by calling -\&\fBRAND_load_file()\fR in a later session. -.PP -\&\fBRAND_file_name()\fR generates a default path for the random seed -file. \fBbuf\fR points to a buffer of size \fBnum\fR in which to store the -filename. -.PP -On all systems, if the environment variable \fB\s-1RANDFILE\s0\fR is set, its -value will be used as the seed filename. -Otherwise, the file is called \f(CW\*(C`.rnd\*(C'\fR, found in platform dependent locations: -.IP "On Windows (in order of preference)" 4 -.IX Item "On Windows (in order of preference)" -.Vb 1 -\& %HOME%, %USERPROFILE%, %SYSTEMROOT%, C:\e -.Ve -.IP "On \s-1VMS\s0" 4 -.IX Item "On VMS" -.Vb 1 -\& SYS$LOGIN: -.Ve -.IP "On all other systems" 4 -.IX Item "On all other systems" -.Vb 1 -\& $HOME -.Ve -.PP -If \f(CW$HOME\fR (on non-Windows and non-VMS system) is not set either, or -\&\fBnum\fR is too small for the pathname, an error occurs. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRAND_load_file()\fR returns the number of bytes read or \-1 on error. -.PP -\&\fBRAND_write_file()\fR returns the number of bytes written, or \-1 if the -bytes written were generated without appropriate seeding. -.PP -\&\fBRAND_file_name()\fR returns a pointer to \fBbuf\fR on success, and \s-1NULL\s0 on -error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRAND_add\fR\|(3), -\&\fBRAND_bytes\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_poll.3ossl b/openssl-install/share/man/man3/RAND_poll.3ossl deleted file mode 120000 index ba600c0b..00000000 --- a/openssl-install/share/man/man3/RAND_poll.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_priv_bytes.3ossl b/openssl-install/share/man/man3/RAND_priv_bytes.3ossl deleted file mode 120000 index 7a179b48..00000000 --- a/openssl-install/share/man/man3/RAND_priv_bytes.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_bytes.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_priv_bytes_ex.3ossl b/openssl-install/share/man/man3/RAND_priv_bytes_ex.3ossl deleted file mode 120000 index 7a179b48..00000000 --- a/openssl-install/share/man/man3/RAND_priv_bytes_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_bytes.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_pseudo_bytes.3ossl b/openssl-install/share/man/man3/RAND_pseudo_bytes.3ossl deleted file mode 120000 index 7a179b48..00000000 --- a/openssl-install/share/man/man3/RAND_pseudo_bytes.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_bytes.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_query_egd_bytes.3ossl b/openssl-install/share/man/man3/RAND_query_egd_bytes.3ossl deleted file mode 120000 index be3656b0..00000000 --- a/openssl-install/share/man/man3/RAND_query_egd_bytes.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_egd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_screen.3ossl b/openssl-install/share/man/man3/RAND_screen.3ossl deleted file mode 120000 index ba600c0b..00000000 --- a/openssl-install/share/man/man3/RAND_screen.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_seed.3ossl b/openssl-install/share/man/man3/RAND_seed.3ossl deleted file mode 120000 index ba600c0b..00000000 --- a/openssl-install/share/man/man3/RAND_seed.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_set0_private.3ossl b/openssl-install/share/man/man3/RAND_set0_private.3ossl deleted file mode 120000 index 43e9590e..00000000 --- a/openssl-install/share/man/man3/RAND_set0_private.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_get0_primary.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_set0_public.3ossl b/openssl-install/share/man/man3/RAND_set0_public.3ossl deleted file mode 120000 index 43e9590e..00000000 --- a/openssl-install/share/man/man3/RAND_set0_public.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_get0_primary.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_set_DRBG_type.3ossl b/openssl-install/share/man/man3/RAND_set_DRBG_type.3ossl deleted file mode 100644 index cb89138d..00000000 --- a/openssl-install/share/man/man3/RAND_set_DRBG_type.3ossl +++ /dev/null @@ -1,203 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_SET_DRBG_TYPE 3ossl" -.TH RAND_SET_DRBG_TYPE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_set_DRBG_type, -RAND_set_seed_source_type -\&\- specify the global random number generator types -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int RAND_set_DRBG_type(OSSL_LIB_CTX *ctx, const char *drbg, const char *propq, -\& const char *cipher, const char *digest); -\& int RAND_set_seed_source_type(OSSL_LIB_CTX *ctx, const char *seed, -\& const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBRAND_set_DRBG_type()\fR specifies the random bit generator that will be -used within the library context \fIctx\fR. A generator of name \fIdrbg\fR -with properties \fIpropq\fR will be fetched. It will be instantiated with -either \fIcipher\fR or \fIdigest\fR as its underlying cryptographic algorithm. -This specifies the type that will be used for the primary, public and -private random instances. -.PP -\&\fBRAND_set_seed_source_type()\fR specifies the seed source that will be used -within the library context \fIctx\fR. The seed source of name \fIseed\fR -with properties \fIpropq\fR will be fetched and used to seed the primary -random bit generator. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These function return 1 on success and 0 on failure. -.SH "NOTES" -.IX Header "NOTES" -These functions must be called before the random bit generators are first -created in the library context. They will return an error if the call -is made too late. -.PP -The default \s-1DRBG\s0 is \*(L"CTR-DRBG\*(R" using the \*(L"\s-1AES\-256\-CTR\*(R"\s0 cipher. -.PP -The default seed source can be configured when OpenSSL is compiled by -setting \fB\-DOPENSSL_DEFAULT_SEED_SRC=SEED\-SRC\fR. If not set then -\&\*(L"SEED-SRC\*(R" is used. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 3 -\& unsigned char bytes[100]; -\& RAND_set_seed_source_type(NULL, "JITTER", NULL); -\& RAND_bytes(bytes, 100); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\fBRAND_get0_primary\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_set_rand_method.3ossl b/openssl-install/share/man/man3/RAND_set_rand_method.3ossl deleted file mode 100644 index bb456670..00000000 --- a/openssl-install/share/man/man3/RAND_set_rand_method.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND_SET_RAND_METHOD 3ossl" -.TH RAND_SET_RAND_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND_set_rand_method, RAND_get_rand_method, RAND_OpenSSL \- select RAND method -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& RAND_METHOD *RAND_OpenSSL(void); -\& -\& int RAND_set_rand_method(const RAND_METHOD *meth); -\& -\& const RAND_METHOD *RAND_get_rand_method(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBRAND_set_DRBG_type\fR\|(3), -\&\s-1\fBEVP_RAND\s0\fR\|(3) and \s-1\fBEVP_RAND\s0\fR\|(7). -.PP -A \fB\s-1RAND_METHOD\s0\fR specifies the functions that OpenSSL uses for random number -generation. -.PP -\&\fBRAND_OpenSSL()\fR returns the default \fB\s-1RAND_METHOD\s0\fR implementation by OpenSSL. -This implementation ensures that the \s-1PRNG\s0 state is unique for each thread. -.PP -If an \fB\s-1ENGINE\s0\fR is loaded that provides the \s-1RAND API,\s0 however, it will -be used instead of the method returned by \fBRAND_OpenSSL()\fR. This is deprecated -in OpenSSL 3.0. -.PP -\&\fBRAND_set_rand_method()\fR makes \fBmeth\fR the method for \s-1PRNG\s0 use. If an -\&\s-1ENGINE\s0 was providing the method, it will be released first. -.PP -\&\fBRAND_get_rand_method()\fR returns a pointer to the current \fB\s-1RAND_METHOD\s0\fR. -.SH "THE RAND_METHOD STRUCTURE" -.IX Header "THE RAND_METHOD STRUCTURE" -.Vb 8 -\& typedef struct rand_meth_st { -\& int (*seed)(const void *buf, int num); -\& int (*bytes)(unsigned char *buf, int num); -\& void (*cleanup)(void); -\& int (*add)(const void *buf, int num, double entropy); -\& int (*pseudorand)(unsigned char *buf, int num); -\& int (*status)(void); -\& } RAND_METHOD; -.Ve -.PP -The fields point to functions that are used by, in order, -\&\fBRAND_seed()\fR, \fBRAND_bytes()\fR, internal \s-1RAND\s0 cleanup, \fBRAND_add()\fR, \fBRAND_pseudo_rand()\fR -and \fBRAND_status()\fR. -Each pointer may be \s-1NULL\s0 if the function is not implemented. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRAND_set_rand_method()\fR returns 1 on success and 0 on failure. -\&\fBRAND_get_rand_method()\fR and \fBRAND_OpenSSL()\fR return pointers to the respective -methods. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\fBRAND_set_DRBG_type\fR\|(3), -\&\fBRAND_bytes\fR\|(3), -\&\fBENGINE_by_id\fR\|(3), -\&\s-1\fBEVP_RAND\s0\fR\|(7), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RAND_set_seed_source_type.3ossl b/openssl-install/share/man/man3/RAND_set_seed_source_type.3ossl deleted file mode 120000 index 91a6b488..00000000 --- a/openssl-install/share/man/man3/RAND_set_seed_source_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_set_DRBG_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_status.3ossl b/openssl-install/share/man/man3/RAND_status.3ossl deleted file mode 120000 index ba600c0b..00000000 --- a/openssl-install/share/man/man3/RAND_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_add.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RAND_write_file.3ossl b/openssl-install/share/man/man3/RAND_write_file.3ossl deleted file mode 120000 index 3d870a35..00000000 --- a/openssl-install/share/man/man3/RAND_write_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -RAND_load_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RC4.3ossl b/openssl-install/share/man/man3/RC4.3ossl deleted file mode 120000 index d4b490f5..00000000 --- a/openssl-install/share/man/man3/RC4.3ossl +++ /dev/null @@ -1 +0,0 @@ -RC4_set_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RC4_set_key.3ossl b/openssl-install/share/man/man3/RC4_set_key.3ossl deleted file mode 100644 index 71ac001d..00000000 --- a/openssl-install/share/man/man3/RC4_set_key.3ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RC4_SET_KEY 3ossl" -.TH RC4_SET_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RC4_set_key, RC4 \- RC4 encryption -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void RC4_set_key(RC4_KEY *key, int len, const unsigned char *data); -\& -\& void RC4(RC4_KEY *key, unsigned long len, const unsigned char *indata, -\& unsigned char *outdata); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. Applications should -instead use \fBEVP_EncryptInit_ex\fR\|(3), \fBEVP_EncryptUpdate\fR\|(3) and -\&\fBEVP_EncryptFinal_ex\fR\|(3) or the equivalently named decrypt functions. -.PP -This library implements the Alleged \s-1RC4\s0 cipher, which is described for -example in \fIApplied Cryptography\fR. It is believed to be compatible -with RC4[\s-1TM\s0], a proprietary cipher of \s-1RSA\s0 Security Inc. -.PP -\&\s-1RC4\s0 is a stream cipher with variable key length. Typically, 128 bit -(16 byte) keys are used for strong encryption, but shorter insecure -key sizes have been widely used due to export restrictions. -.PP -\&\s-1RC4\s0 consists of a key setup phase and the actual encryption or -decryption phase. -.PP -\&\fBRC4_set_key()\fR sets up the \fB\s-1RC4_KEY\s0\fR \fBkey\fR using the \fBlen\fR bytes long -key at \fBdata\fR. -.PP -\&\s-1\fBRC4\s0()\fR encrypts or decrypts the \fBlen\fR bytes of data at \fBindata\fR using -\&\fBkey\fR and places the result at \fBoutdata\fR. Repeated \s-1\fBRC4\s0()\fR calls with -the same \fBkey\fR yield a continuous key stream. -.PP -Since \s-1RC4\s0 is a stream cipher (the input is XORed with a pseudo-random -key stream to produce the output), decryption uses the same function -calls as encryption. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRC4_set_key()\fR and \s-1\fBRC4\s0()\fR do not return values. -.SH "NOTE" -.IX Header "NOTE" -Applications should use the higher level functions -\&\fBEVP_EncryptInit\fR\|(3) etc. instead of calling these -functions directly. -.PP -It is difficult to securely use stream ciphers. For example, do not perform -multiple encryptions using the same key stream. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_EncryptInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RIPEMD160.3ossl b/openssl-install/share/man/man3/RIPEMD160.3ossl deleted file mode 120000 index d53183b2..00000000 --- a/openssl-install/share/man/man3/RIPEMD160.3ossl +++ /dev/null @@ -1 +0,0 @@ -RIPEMD160_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RIPEMD160_Final.3ossl b/openssl-install/share/man/man3/RIPEMD160_Final.3ossl deleted file mode 120000 index d53183b2..00000000 --- a/openssl-install/share/man/man3/RIPEMD160_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -RIPEMD160_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RIPEMD160_Init.3ossl b/openssl-install/share/man/man3/RIPEMD160_Init.3ossl deleted file mode 100644 index eb2ecb32..00000000 --- a/openssl-install/share/man/man3/RIPEMD160_Init.3ossl +++ /dev/null @@ -1,214 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RIPEMD160_INIT 3ossl" -.TH RIPEMD160_INIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RIPEMD160, RIPEMD160_Init, RIPEMD160_Update, RIPEMD160_Final \- -RIPEMD\-160 hash function -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& unsigned char *RIPEMD160(const unsigned char *d, unsigned long n, -\& unsigned char *md); -\& -\& int RIPEMD160_Init(RIPEMD160_CTX *c); -\& int RIPEMD160_Update(RIPEMD160_CTX *c, const void *data, unsigned long len); -\& int RIPEMD160_Final(unsigned char *md, RIPEMD160_CTX *c); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_DigestInit_ex\fR\|(3), \fBEVP_DigestUpdate\fR\|(3) -and \fBEVP_DigestFinal_ex\fR\|(3). -.PP -\&\s-1RIPEMD\-160\s0 is a cryptographic hash function with a -160 bit output. -.PP -\&\s-1\fBRIPEMD160\s0()\fR computes the \s-1RIPEMD\-160\s0 message digest of the \fBn\fR -bytes at \fBd\fR and places it in \fBmd\fR (which must have space for -\&\s-1RIPEMD160_DIGEST_LENGTH\s0 == 20 bytes of output). If \fBmd\fR is \s-1NULL,\s0 the digest -is placed in a static array. -.PP -The following functions may be used if the message is not completely -stored in memory: -.PP -\&\fBRIPEMD160_Init()\fR initializes a \fB\s-1RIPEMD160_CTX\s0\fR structure. -.PP -\&\fBRIPEMD160_Update()\fR can be called repeatedly with chunks of the message to -be hashed (\fBlen\fR bytes at \fBdata\fR). -.PP -\&\fBRIPEMD160_Final()\fR places the message digest in \fBmd\fR, which must have -space for \s-1RIPEMD160_DIGEST_LENGTH\s0 == 20 bytes of output, and erases -the \fB\s-1RIPEMD160_CTX\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1\fBRIPEMD160\s0()\fR returns a pointer to the hash value. -.PP -\&\fBRIPEMD160_Init()\fR, \fBRIPEMD160_Update()\fR and \fBRIPEMD160_Final()\fR return 1 for -success, 0 otherwise. -.SH "NOTE" -.IX Header "NOTE" -Applications should use the higher level functions -\&\fBEVP_DigestInit\fR\|(3) etc. instead of calling these -functions directly. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ISO/IEC 10118\-3:2016\s0 Dedicated Hash-Function 1 (\s-1RIPEMD\-160\s0). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RIPEMD160_Update.3ossl b/openssl-install/share/man/man3/RIPEMD160_Update.3ossl deleted file mode 120000 index d53183b2..00000000 --- a/openssl-install/share/man/man3/RIPEMD160_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -RIPEMD160_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSAPrivateKey_dup.3ossl b/openssl-install/share/man/man3/RSAPrivateKey_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/RSAPrivateKey_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSAPublicKey_dup.3ossl b/openssl-install/share/man/man3/RSAPublicKey_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/RSAPublicKey_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_OAEP_PARAMS_free.3ossl b/openssl-install/share/man/man3/RSA_OAEP_PARAMS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/RSA_OAEP_PARAMS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_OAEP_PARAMS_new.3ossl b/openssl-install/share/man/man3/RSA_OAEP_PARAMS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/RSA_OAEP_PARAMS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_PKCS1_OpenSSL.3ossl b/openssl-install/share/man/man3/RSA_PKCS1_OpenSSL.3ossl deleted file mode 120000 index ed5907f5..00000000 --- a/openssl-install/share/man/man3/RSA_PKCS1_OpenSSL.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_PSS_PARAMS_dup.3ossl b/openssl-install/share/man/man3/RSA_PSS_PARAMS_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/RSA_PSS_PARAMS_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_PSS_PARAMS_free.3ossl b/openssl-install/share/man/man3/RSA_PSS_PARAMS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/RSA_PSS_PARAMS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_PSS_PARAMS_new.3ossl b/openssl-install/share/man/man3/RSA_PSS_PARAMS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/RSA_PSS_PARAMS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_bits.3ossl b/openssl-install/share/man/man3/RSA_bits.3ossl deleted file mode 120000 index 4d3a22c6..00000000 --- a/openssl-install/share/man/man3/RSA_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_blinding_off.3ossl b/openssl-install/share/man/man3/RSA_blinding_off.3ossl deleted file mode 120000 index 51ae84e2..00000000 --- a/openssl-install/share/man/man3/RSA_blinding_off.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_blinding_on.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_blinding_on.3ossl b/openssl-install/share/man/man3/RSA_blinding_on.3ossl deleted file mode 100644 index 7f3ccf2d..00000000 --- a/openssl-install/share/man/man3/RSA_blinding_on.3ossl +++ /dev/null @@ -1,187 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_BLINDING_ON 3ossl" -.TH RSA_BLINDING_ON 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_blinding_on, RSA_blinding_off \- protect the RSA operation from timing attacks -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int RSA_blinding_on(RSA *rsa, BN_CTX *ctx); -\& -\& void RSA_blinding_off(RSA *rsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -.PP -\&\s-1RSA\s0 is vulnerable to timing attacks. In a setup where attackers can -measure the time of \s-1RSA\s0 decryption or signature operations, blinding -must be used to protect the \s-1RSA\s0 operation from that attack. -.PP -\&\fBRSA_blinding_on()\fR turns blinding on for key \fBrsa\fR and generates a -random blinding factor. \fBctx\fR is \fB\s-1NULL\s0\fR or a preallocated and -initialized \fB\s-1BN_CTX\s0\fR. -.PP -\&\fBRSA_blinding_off()\fR turns blinding off and frees the memory used for -the blinding factor. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_blinding_on()\fR returns 1 on success, and 0 if an error occurred. -.PP -\&\fBRSA_blinding_off()\fR returns no value. -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_check_key.3ossl b/openssl-install/share/man/man3/RSA_check_key.3ossl deleted file mode 100644 index 6f427962..00000000 --- a/openssl-install/share/man/man3/RSA_check_key.3ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_CHECK_KEY 3ossl" -.TH RSA_CHECK_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_check_key_ex, RSA_check_key \- validate private RSA keys -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int RSA_check_key_ex(const RSA *rsa, BN_GENCB *cb); -\& -\& int RSA_check_key(const RSA *rsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Both of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_public_check\fR\|(3), -\&\fBEVP_PKEY_private_check\fR\|(3) and \fBEVP_PKEY_pairwise_check\fR\|(3). -.PP -\&\fBRSA_check_key_ex()\fR function validates \s-1RSA\s0 keys. -It checks that \fBp\fR and \fBq\fR are -in fact prime, and that \fBn = p*q\fR. -.PP -It does not work on \s-1RSA\s0 public keys that have only the modulus -and public exponent elements populated. -It also checks that \fBd*e = 1 mod (p\-1*q\-1)\fR, -and that \fBdmp1\fR, \fBdmq1\fR and \fBiqmp\fR are set correctly or are \fB\s-1NULL\s0\fR. -It performs integrity checks on all -the \s-1RSA\s0 key material, so the \s-1RSA\s0 key structure must contain all the private -key data too. -Therefore, it cannot be used with any arbitrary \s-1RSA\s0 key object, -even if it is otherwise fit for regular \s-1RSA\s0 operation. -.PP -The \fBcb\fR parameter is a callback that will be invoked in the same -manner as \fBBN_is_prime_ex\fR\|(3). -.PP -\&\fBRSA_check_key()\fR is equivalent to \fBRSA_check_key_ex()\fR with a \s-1NULL\s0 \fBcb\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_check_key_ex()\fR and \fBRSA_check_key()\fR -return 1 if \fBrsa\fR is a valid \s-1RSA\s0 key, and 0 otherwise. -They return \-1 if an error occurs while checking the key. -.PP -If the key is invalid or an error occurred, the reason code can be -obtained using \fBERR_get_error\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -Unlike most other \s-1RSA\s0 functions, this function does \fBnot\fR work -transparently with any underlying \s-1ENGINE\s0 implementation because it uses the -key data in the \s-1RSA\s0 structure directly. An \s-1ENGINE\s0 implementation can -override the way key data is stored and handled, and can even provide -support for \s-1HSM\s0 keys \- in which case the \s-1RSA\s0 structure may contain \fBno\fR -key data at all! If the \s-1ENGINE\s0 in question is only being used for -acceleration or analysis purposes, then in all likelihood the \s-1RSA\s0 key data -is complete and untouched, but this can't be assumed in the general case. -.SH "BUGS" -.IX Header "BUGS" -A method of verifying the \s-1RSA\s0 key using opaque \s-1RSA API\s0 functions might need -to be considered. Right now \fBRSA_check_key()\fR simply uses the \s-1RSA\s0 structure -elements directly, bypassing the \s-1RSA_METHOD\s0 table altogether (and -completely violating encapsulation and object-orientation in the process). -The best fix will probably be to introduce a \*(L"\fBcheck_key()\fR\*(R" handler to the -\&\s-1RSA_METHOD\s0 function table so that alternative implementations can also -provide their own verifiers. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBN_is_prime_ex\fR\|(3), -\&\fBERR_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -\&\fBRSA_check_key_ex()\fR appeared after OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_check_key_ex.3ossl b/openssl-install/share/man/man3/RSA_check_key_ex.3ossl deleted file mode 120000 index 8148a87e..00000000 --- a/openssl-install/share/man/man3/RSA_check_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_check_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_clear_flags.3ossl b/openssl-install/share/man/man3/RSA_clear_flags.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_flags.3ossl b/openssl-install/share/man/man3/RSA_flags.3ossl deleted file mode 120000 index ed5907f5..00000000 --- a/openssl-install/share/man/man3/RSA_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_free.3ossl b/openssl-install/share/man/man3/RSA_free.3ossl deleted file mode 120000 index 996b2c1b..00000000 --- a/openssl-install/share/man/man3/RSA_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_generate_key.3ossl b/openssl-install/share/man/man3/RSA_generate_key.3ossl deleted file mode 100644 index 0f05fbf7..00000000 --- a/openssl-install/share/man/man3/RSA_generate_key.3ossl +++ /dev/null @@ -1,251 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_GENERATE_KEY 3ossl" -.TH RSA_GENERATE_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RSA_gen, -RSA_generate_key_ex, RSA_generate_key, -RSA_generate_multi_prime_key \- generate RSA key pair -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *EVP_RSA_gen(unsigned int bits); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int RSA_generate_key_ex(RSA *rsa, int bits, BIGNUM *e, BN_GENCB *cb); -\& int RSA_generate_multi_prime_key(RSA *rsa, int bits, int primes, BIGNUM *e, BN_GENCB *cb); -.Ve -.PP -The following function has been deprecated since OpenSSL 0.9.8, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& RSA *RSA_generate_key(int bits, unsigned long e, -\& void (*callback)(int, int, void *), void *cb_arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBEVP_RSA_gen()\fR generates a new \s-1RSA\s0 key pair with modulus size \fIbits\fR. -.PP -All of the functions described below are deprecated. -Applications should instead use \fBEVP_RSA_gen()\fR, \fBEVP_PKEY_Q_keygen\fR\|(3), or -\&\fBEVP_PKEY_keygen_init\fR\|(3) and \fBEVP_PKEY_keygen\fR\|(3). -.PP -\&\fBRSA_generate_key_ex()\fR generates a 2\-prime \s-1RSA\s0 key pair and stores it in the -\&\fB\s-1RSA\s0\fR structure provided in \fIrsa\fR. -.PP -\&\fBRSA_generate_multi_prime_key()\fR generates a multi-prime \s-1RSA\s0 key pair and stores -it in the \fB\s-1RSA\s0\fR structure provided in \fIrsa\fR. The number of primes is given by -the \fIprimes\fR parameter. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.PP -The modulus size will be of length \fIbits\fR, the number of primes to form the -modulus will be \fIprimes\fR, and the public exponent will be \fIe\fR. Key sizes -with \fInum\fR < 1024 should be considered insecure. The exponent is an odd -number, typically 3, 17 or 65537. -.PP -In order to maintain adequate security level, the maximum number of permitted -\&\fIprimes\fR depends on modulus bit length: -.PP -.Vb 3 -\& <1024 | >=1024 | >=4096 | >=8192 -\& \-\-\-\-\-\-+\-\-\-\-\-\-\-\-+\-\-\-\-\-\-\-\-+\-\-\-\-\-\-\- -\& 2 | 3 | 4 | 5 -.Ve -.PP -A callback function may be used to provide feedback about the -progress of the key generation. If \fIcb\fR is not \s-1NULL,\s0 it -will be called as follows using the \fBBN_GENCB_call()\fR function -described on the \fBBN_generate_prime\fR\|(3) page. -.PP -\&\fBRSA_generate_key()\fR is similar to \fBRSA_generate_key_ex()\fR but -expects an old-style callback function; see -\&\fBBN_generate_prime\fR\|(3) for information on the old-style callback. -.IP "\(bu" 2 -While a random prime number is generated, it is called as -described in \fBBN_generate_prime\fR\|(3). -.IP "\(bu" 2 -When the n\-th randomly generated prime is rejected as not -suitable for the key, \fIBN_GENCB_call(cb, 2, n)\fR is called. -.IP "\(bu" 2 -When a random p has been found with p\-1 relatively prime to \fIe\fR, -it is called as \fIBN_GENCB_call(cb, 3, 0)\fR. -.PP -The process is then repeated for prime q and other primes (if any) -with \fIBN_GENCB_call(cb, 3, i)\fR where \fIi\fR indicates the i\-th prime. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBEVP_RSA_gen()\fR returns an \fI\s-1EVP_PKEY\s0\fR or \s-1NULL\s0 on failure. -.PP -\&\fBRSA_generate_multi_prime_key()\fR returns 1 on success or 0 on error. -\&\fBRSA_generate_key_ex()\fR returns 1 on success or 0 on error. -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.PP -\&\fBRSA_generate_key()\fR returns a pointer to the \s-1RSA\s0 structure or -\&\s-1NULL\s0 if the key generation fails. -.SH "BUGS" -.IX Header "BUGS" -\&\fIBN_GENCB_call(cb, 2, x)\fR is used with two different meanings. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_Q_keygen\fR\|(3) -\&\fBBN_generate_prime\fR\|(3), \fBERR_get_error\fR\|(3), -\&\fBRAND_bytes\fR\|(3), \s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBEVP_RSA_gen()\fR was added in OpenSSL 3.0. -All other functions described here were deprecated in OpenSSL 3.0. -For replacement see \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_generate_key_ex.3ossl b/openssl-install/share/man/man3/RSA_generate_key_ex.3ossl deleted file mode 120000 index 5316c699..00000000 --- a/openssl-install/share/man/man3/RSA_generate_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_generate_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_generate_multi_prime_key.3ossl b/openssl-install/share/man/man3/RSA_generate_multi_prime_key.3ossl deleted file mode 120000 index 5316c699..00000000 --- a/openssl-install/share/man/man3/RSA_generate_multi_prime_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_generate_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_crt_params.3ossl b/openssl-install/share/man/man3/RSA_get0_crt_params.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_crt_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_d.3ossl b/openssl-install/share/man/man3/RSA_get0_d.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_d.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_dmp1.3ossl b/openssl-install/share/man/man3/RSA_get0_dmp1.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_dmp1.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_dmq1.3ossl b/openssl-install/share/man/man3/RSA_get0_dmq1.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_dmq1.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_e.3ossl b/openssl-install/share/man/man3/RSA_get0_e.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_e.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_engine.3ossl b/openssl-install/share/man/man3/RSA_get0_engine.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_engine.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_factors.3ossl b/openssl-install/share/man/man3/RSA_get0_factors.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_factors.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_iqmp.3ossl b/openssl-install/share/man/man3/RSA_get0_iqmp.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_iqmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_key.3ossl b/openssl-install/share/man/man3/RSA_get0_key.3ossl deleted file mode 100644 index f6ee98c4..00000000 --- a/openssl-install/share/man/man3/RSA_get0_key.3ossl +++ /dev/null @@ -1,326 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_GET0_KEY 3ossl" -.TH RSA_GET0_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_set0_key, RSA_set0_factors, RSA_set0_crt_params, RSA_get0_key, -RSA_get0_factors, RSA_get0_crt_params, -RSA_get0_n, RSA_get0_e, RSA_get0_d, RSA_get0_p, RSA_get0_q, -RSA_get0_dmp1, RSA_get0_dmq1, RSA_get0_iqmp, RSA_get0_pss_params, -RSA_clear_flags, -RSA_test_flags, RSA_set_flags, RSA_get0_engine, RSA_get_multi_prime_extra_count, -RSA_get0_multi_prime_factors, RSA_get0_multi_prime_crt_params, -RSA_set0_multi_prime_params, RSA_get_version -\&\- Routines for getting and setting data in an RSA object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& int RSA_set0_key(RSA *r, BIGNUM *n, BIGNUM *e, BIGNUM *d); -\& int RSA_set0_factors(RSA *r, BIGNUM *p, BIGNUM *q); -\& int RSA_set0_crt_params(RSA *r, BIGNUM *dmp1, BIGNUM *dmq1, BIGNUM *iqmp); -\& void RSA_get0_key(const RSA *r, -\& const BIGNUM **n, const BIGNUM **e, const BIGNUM **d); -\& void RSA_get0_factors(const RSA *r, const BIGNUM **p, const BIGNUM **q); -\& void RSA_get0_crt_params(const RSA *r, -\& const BIGNUM **dmp1, const BIGNUM **dmq1, -\& const BIGNUM **iqmp); -\& const BIGNUM *RSA_get0_n(const RSA *d); -\& const BIGNUM *RSA_get0_e(const RSA *d); -\& const BIGNUM *RSA_get0_d(const RSA *d); -\& const BIGNUM *RSA_get0_p(const RSA *d); -\& const BIGNUM *RSA_get0_q(const RSA *d); -\& const BIGNUM *RSA_get0_dmp1(const RSA *r); -\& const BIGNUM *RSA_get0_dmq1(const RSA *r); -\& const BIGNUM *RSA_get0_iqmp(const RSA *r); -\& const RSA_PSS_PARAMS *RSA_get0_pss_params(const RSA *r); -\& void RSA_clear_flags(RSA *r, int flags); -\& int RSA_test_flags(const RSA *r, int flags); -\& void RSA_set_flags(RSA *r, int flags); -\& ENGINE *RSA_get0_engine(RSA *r); -\& int RSA_get_multi_prime_extra_count(const RSA *r); -\& int RSA_get0_multi_prime_factors(const RSA *r, const BIGNUM *primes[]); -\& int RSA_get0_multi_prime_crt_params(const RSA *r, const BIGNUM *exps[], -\& const BIGNUM *coeffs[]); -\& int RSA_set0_multi_prime_params(RSA *r, BIGNUM *primes[], BIGNUM *exps[], -\& BIGNUM *coeffs[], int pnum); -\& int RSA_get_version(RSA *r); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_get_bn_param\fR\|(3) for any methods that -return a \fB\s-1BIGNUM\s0\fR. Refer to \s-1\fBEVP_PKEY\-DH\s0\fR\|(7) for more information. -.PP -An \s-1RSA\s0 object contains the components for the public and private key, -\&\fBn\fR, \fBe\fR, \fBd\fR, \fBp\fR, \fBq\fR, \fBdmp1\fR, \fBdmq1\fR and \fBiqmp\fR. \fBn\fR is -the modulus common to both public and private key, \fBe\fR is the public -exponent and \fBd\fR is the private exponent. \fBp\fR, \fBq\fR, \fBdmp1\fR, -\&\fBdmq1\fR and \fBiqmp\fR are the factors for the second representation of a -private key (see PKCS#1 section 3 Key Types), where \fBp\fR and \fBq\fR are -the first and second factor of \fBn\fR and \fBdmp1\fR, \fBdmq1\fR and \fBiqmp\fR -are the exponents and coefficient for \s-1CRT\s0 calculations. -.PP -For multi-prime \s-1RSA\s0 (defined in \s-1RFC 8017\s0), there are also one or more -\&'triplet' in an \s-1RSA\s0 object. A triplet contains three members, \fBr\fR, \fBd\fR -and \fBt\fR. \fBr\fR is the additional prime besides \fBp\fR and \fBq\fR. \fBd\fR and -\&\fBt\fR are the exponent and coefficient for \s-1CRT\s0 calculations. -.PP -The \fBn\fR, \fBe\fR and \fBd\fR parameters can be obtained by calling -\&\fBRSA_get0_key()\fR. If they have not been set yet, then \fB*n\fR, \fB*e\fR and -\&\fB*d\fR will be set to \s-1NULL.\s0 Otherwise, they are set to pointers to -their respective values. These point directly to the internal -representations of the values and therefore should not be freed -by the caller. -.PP -The \fBn\fR, \fBe\fR and \fBd\fR parameter values can be set by calling -\&\fBRSA_set0_key()\fR and passing the new values for \fBn\fR, \fBe\fR and \fBd\fR as -parameters to the function. The values \fBn\fR and \fBe\fR must be non-NULL -the first time this function is called on a given \s-1RSA\s0 object. The -value \fBd\fR may be \s-1NULL.\s0 On subsequent calls any of these values may be -\&\s-1NULL\s0 which means the corresponding \s-1RSA\s0 field is left untouched. -Calling this function transfers the memory management of the values to -the \s-1RSA\s0 object, and therefore the values that have been passed in -should not be freed by the caller after this function has been called. -.PP -In a similar fashion, the \fBp\fR and \fBq\fR parameters can be obtained and -set with \fBRSA_get0_factors()\fR and \fBRSA_set0_factors()\fR, and the \fBdmp1\fR, -\&\fBdmq1\fR and \fBiqmp\fR parameters can be obtained and set with -\&\fBRSA_get0_crt_params()\fR and \fBRSA_set0_crt_params()\fR. -.PP -For \fBRSA_get0_key()\fR, \fBRSA_get0_factors()\fR, and \fBRSA_get0_crt_params()\fR, -\&\s-1NULL\s0 value \s-1BIGNUM\s0 ** output parameters are permitted. The functions -ignore \s-1NULL\s0 parameters but return values for other, non-NULL, parameters. -.PP -For multi-prime \s-1RSA,\s0 \fBRSA_get0_multi_prime_factors()\fR and \fBRSA_get0_multi_prime_params()\fR -can be used to obtain other primes and related \s-1CRT\s0 parameters. The -return values are stored in an array of \fB\s-1BIGNUM\s0 *\fR. \fBRSA_set0_multi_prime_params()\fR -sets a collect of multi-prime 'triplet' members (prime, exponent and coefficient) -into an \s-1RSA\s0 object. -.PP -Any of the values \fBn\fR, \fBe\fR, \fBd\fR, \fBp\fR, \fBq\fR, \fBdmp1\fR, \fBdmq1\fR, and \fBiqmp\fR can also be -retrieved separately by the corresponding function -\&\fBRSA_get0_n()\fR, \fBRSA_get0_e()\fR, \fBRSA_get0_d()\fR, \fBRSA_get0_p()\fR, \fBRSA_get0_q()\fR, -\&\fBRSA_get0_dmp1()\fR, \fBRSA_get0_dmq1()\fR, and \fBRSA_get0_iqmp()\fR, respectively. -.PP -\&\fBRSA_get0_pss_params()\fR is used to retrieve the RSA-PSS parameters. -.PP -\&\fBRSA_set_flags()\fR sets the flags in the \fBflags\fR parameter on the \s-1RSA\s0 -object. Multiple flags can be passed in one go (bitwise ORed together). -Any flags that are already set are left set. \fBRSA_test_flags()\fR tests to -see whether the flags passed in the \fBflags\fR parameter are currently -set in the \s-1RSA\s0 object. Multiple flags can be tested in one go. All -flags that are currently set are returned, or zero if none of the -flags are set. \fBRSA_clear_flags()\fR clears the specified flags within the -\&\s-1RSA\s0 object. -.PP -\&\fBRSA_get0_engine()\fR returns a handle to the \s-1ENGINE\s0 that has been set for -this \s-1RSA\s0 object, or \s-1NULL\s0 if no such \s-1ENGINE\s0 has been set. -.PP -\&\fBRSA_get_version()\fR returns the version of an \s-1RSA\s0 object \fBr\fR. -.SH "NOTES" -.IX Header "NOTES" -Values retrieved with \fBRSA_get0_key()\fR are owned by the \s-1RSA\s0 object used -in the call and may therefore \fInot\fR be passed to \fBRSA_set0_key()\fR. If -needed, duplicate the received value using \fBBN_dup()\fR and pass the -duplicate. The same applies to \fBRSA_get0_factors()\fR and \fBRSA_set0_factors()\fR -as well as \fBRSA_get0_crt_params()\fR and \fBRSA_set0_crt_params()\fR. -.PP -The caller should obtain the size by calling \fBRSA_get_multi_prime_extra_count()\fR -in advance and allocate sufficient buffer to store the return values before -calling \fBRSA_get0_multi_prime_factors()\fR and \fBRSA_get0_multi_prime_params()\fR. -.PP -\&\fBRSA_set0_multi_prime_params()\fR always clears the original multi-prime -triplets in \s-1RSA\s0 object \fBr\fR and assign the new set of triplets into it. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_set0_key()\fR, \fBRSA_set0_factors()\fR, \fBRSA_set0_crt_params()\fR and -\&\fBRSA_set0_multi_prime_params()\fR return 1 on success or 0 on failure. -.PP -\&\fBRSA_get0_n()\fR, \fBRSA_get0_e()\fR, \fBRSA_get0_d()\fR, \fBRSA_get0_p()\fR, \fBRSA_get0_q()\fR, -\&\fBRSA_get0_dmp1()\fR, \fBRSA_get0_dmq1()\fR, and \fBRSA_get0_iqmp()\fR -return the respective value. -.PP -\&\fBRSA_get0_pss_params()\fR returns a \fB\s-1RSA_PSS_PARAMS\s0\fR pointer, or \s-1NULL\s0 if -there is none. -.PP -\&\fBRSA_get0_multi_prime_factors()\fR and \fBRSA_get0_multi_prime_crt_params()\fR return -1 on success or 0 on failure. -.PP -\&\fBRSA_get_multi_prime_extra_count()\fR returns two less than the number of primes -in use, which is 0 for traditional \s-1RSA\s0 and the number of extra primes for -multi-prime \s-1RSA.\s0 -.PP -\&\fBRSA_get_version()\fR returns \fB\s-1RSA_ASN1_VERSION_MULTI\s0\fR for multi-prime \s-1RSA\s0 and -\&\fB\s-1RSA_ASN1_VERSION_DEFAULT\s0\fR for normal two-prime \s-1RSA,\s0 as defined in \s-1RFC 8017.\s0 -.PP -\&\fBRSA_test_flags()\fR returns the current state of the flags in the \s-1RSA\s0 object. -.PP -\&\fBRSA_get0_engine()\fR returns the \s-1ENGINE\s0 set for the \s-1RSA\s0 object or \s-1NULL\s0 if no -\&\s-1ENGINE\s0 has been set. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRSA_new\fR\|(3), \fBRSA_size\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBRSA_get0_pss_params()\fR function was added in OpenSSL 1.1.1e. -.PP -The -\&\fBRSA_get_multi_prime_extra_count()\fR, \fBRSA_get0_multi_prime_factors()\fR, -\&\fBRSA_get0_multi_prime_crt_params()\fR, \fBRSA_set0_multi_prime_params()\fR, -and \fBRSA_get_version()\fR functions were added in OpenSSL 1.1.1. -.PP -Other functions described here were added in OpenSSL 1.1.0. -.PP -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_get0_multi_prime_crt_params.3ossl b/openssl-install/share/man/man3/RSA_get0_multi_prime_crt_params.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_multi_prime_crt_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_multi_prime_factors.3ossl b/openssl-install/share/man/man3/RSA_get0_multi_prime_factors.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_multi_prime_factors.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_n.3ossl b/openssl-install/share/man/man3/RSA_get0_n.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_n.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_p.3ossl b/openssl-install/share/man/man3/RSA_get0_p.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_p.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_pss_params.3ossl b/openssl-install/share/man/man3/RSA_get0_pss_params.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_pss_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get0_q.3ossl b/openssl-install/share/man/man3/RSA_get0_q.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get0_q.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get_app_data.3ossl b/openssl-install/share/man/man3/RSA_get_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/RSA_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get_default_method.3ossl b/openssl-install/share/man/man3/RSA_get_default_method.3ossl deleted file mode 120000 index ed5907f5..00000000 --- a/openssl-install/share/man/man3/RSA_get_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get_ex_data.3ossl b/openssl-install/share/man/man3/RSA_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/RSA_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get_ex_new_index.3ossl b/openssl-install/share/man/man3/RSA_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/RSA_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get_method.3ossl b/openssl-install/share/man/man3/RSA_get_method.3ossl deleted file mode 120000 index ed5907f5..00000000 --- a/openssl-install/share/man/man3/RSA_get_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get_multi_prime_extra_count.3ossl b/openssl-install/share/man/man3/RSA_get_multi_prime_extra_count.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get_multi_prime_extra_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_get_version.3ossl b/openssl-install/share/man/man3/RSA_get_version.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_get_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_dup.3ossl b/openssl-install/share/man/man3/RSA_meth_dup.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_free.3ossl b/openssl-install/share/man/man3/RSA_meth_free.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get0_app_data.3ossl b/openssl-install/share/man/man3/RSA_meth_get0_app_data.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get0_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get0_name.3ossl b/openssl-install/share/man/man3/RSA_meth_get0_name.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_bn_mod_exp.3ossl b/openssl-install/share/man/man3/RSA_meth_get_bn_mod_exp.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_bn_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_finish.3ossl b/openssl-install/share/man/man3/RSA_meth_get_finish.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_flags.3ossl b/openssl-install/share/man/man3/RSA_meth_get_flags.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_init.3ossl b/openssl-install/share/man/man3/RSA_meth_get_init.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_keygen.3ossl b/openssl-install/share/man/man3/RSA_meth_get_keygen.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_mod_exp.3ossl b/openssl-install/share/man/man3/RSA_meth_get_mod_exp.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_multi_prime_keygen.3ossl b/openssl-install/share/man/man3/RSA_meth_get_multi_prime_keygen.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_multi_prime_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_priv_dec.3ossl b/openssl-install/share/man/man3/RSA_meth_get_priv_dec.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_priv_dec.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_priv_enc.3ossl b/openssl-install/share/man/man3/RSA_meth_get_priv_enc.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_priv_enc.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_pub_dec.3ossl b/openssl-install/share/man/man3/RSA_meth_get_pub_dec.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_pub_dec.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_pub_enc.3ossl b/openssl-install/share/man/man3/RSA_meth_get_pub_enc.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_pub_enc.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_sign.3ossl b/openssl-install/share/man/man3/RSA_meth_get_sign.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_get_verify.3ossl b/openssl-install/share/man/man3/RSA_meth_get_verify.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_get_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_new.3ossl b/openssl-install/share/man/man3/RSA_meth_new.3ossl deleted file mode 100644 index 4d31cede..00000000 --- a/openssl-install/share/man/man3/RSA_meth_new.3ossl +++ /dev/null @@ -1,404 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_METH_NEW 3ossl" -.TH RSA_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_meth_get0_app_data, RSA_meth_set0_app_data, -RSA_meth_new, RSA_meth_free, RSA_meth_dup, RSA_meth_get0_name, -RSA_meth_set1_name, RSA_meth_get_flags, RSA_meth_set_flags, -RSA_meth_get_pub_enc, -RSA_meth_set_pub_enc, RSA_meth_get_pub_dec, RSA_meth_set_pub_dec, -RSA_meth_get_priv_enc, RSA_meth_set_priv_enc, RSA_meth_get_priv_dec, -RSA_meth_set_priv_dec, RSA_meth_get_mod_exp, RSA_meth_set_mod_exp, -RSA_meth_get_bn_mod_exp, RSA_meth_set_bn_mod_exp, RSA_meth_get_init, -RSA_meth_set_init, RSA_meth_get_finish, RSA_meth_set_finish, -RSA_meth_get_sign, RSA_meth_set_sign, RSA_meth_get_verify, -RSA_meth_set_verify, RSA_meth_get_keygen, RSA_meth_set_keygen, -RSA_meth_get_multi_prime_keygen, RSA_meth_set_multi_prime_keygen -\&\- Routines to build up RSA methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& RSA_METHOD *RSA_meth_new(const char *name, int flags); -\& void RSA_meth_free(RSA_METHOD *meth); -\& -\& RSA_METHOD *RSA_meth_dup(const RSA_METHOD *meth); -\& -\& const char *RSA_meth_get0_name(const RSA_METHOD *meth); -\& int RSA_meth_set1_name(RSA_METHOD *meth, const char *name); -\& -\& int RSA_meth_get_flags(const RSA_METHOD *meth); -\& int RSA_meth_set_flags(RSA_METHOD *meth, int flags); -\& -\& void *RSA_meth_get0_app_data(const RSA_METHOD *meth); -\& int RSA_meth_set0_app_data(RSA_METHOD *meth, void *app_data); -\& -\& int (*RSA_meth_get_pub_enc(const RSA_METHOD *meth))(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& int RSA_meth_set_pub_enc(RSA_METHOD *rsa, -\& int (*pub_enc)(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, -\& int padding)); -\& -\& int (*RSA_meth_get_pub_dec(const RSA_METHOD *meth)) -\& (int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& int RSA_meth_set_pub_dec(RSA_METHOD *rsa, -\& int (*pub_dec)(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, -\& int padding)); -\& -\& int (*RSA_meth_get_priv_enc(const RSA_METHOD *meth))(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, -\& int padding); -\& int RSA_meth_set_priv_enc(RSA_METHOD *rsa, -\& int (*priv_enc)(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding)); -\& -\& int (*RSA_meth_get_priv_dec(const RSA_METHOD *meth))(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, -\& int padding); -\& int RSA_meth_set_priv_dec(RSA_METHOD *rsa, -\& int (*priv_dec)(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding)); -\& -\& /* Can be null */ -\& int (*RSA_meth_get_mod_exp(const RSA_METHOD *meth))(BIGNUM *r0, const BIGNUM *i, -\& RSA *rsa, BN_CTX *ctx); -\& int RSA_meth_set_mod_exp(RSA_METHOD *rsa, -\& int (*mod_exp)(BIGNUM *r0, const BIGNUM *i, RSA *rsa, -\& BN_CTX *ctx)); -\& -\& /* Can be null */ -\& int (*RSA_meth_get_bn_mod_exp(const RSA_METHOD *meth))(BIGNUM *r, const BIGNUM *a, -\& const BIGNUM *p, const BIGNUM *m, -\& BN_CTX *ctx, BN_MONT_CTX *m_ctx); -\& int RSA_meth_set_bn_mod_exp(RSA_METHOD *rsa, -\& int (*bn_mod_exp)(BIGNUM *r, const BIGNUM *a, -\& const BIGNUM *p, const BIGNUM *m, -\& BN_CTX *ctx, BN_MONT_CTX *m_ctx)); -\& -\& /* called at new */ -\& int (*RSA_meth_get_init(const RSA_METHOD *meth) (RSA *rsa); -\& int RSA_meth_set_init(RSA_METHOD *rsa, int (*init (RSA *rsa)); -\& -\& /* called at free */ -\& int (*RSA_meth_get_finish(const RSA_METHOD *meth))(RSA *rsa); -\& int RSA_meth_set_finish(RSA_METHOD *rsa, int (*finish)(RSA *rsa)); -\& -\& int (*RSA_meth_get_sign(const RSA_METHOD *meth))(int type, const unsigned char *m, -\& unsigned int m_length, -\& unsigned char *sigret, -\& unsigned int *siglen, const RSA *rsa); -\& int RSA_meth_set_sign(RSA_METHOD *rsa, -\& int (*sign)(int type, const unsigned char *m, -\& unsigned int m_length, unsigned char *sigret, -\& unsigned int *siglen, const RSA *rsa)); -\& -\& int (*RSA_meth_get_verify(const RSA_METHOD *meth))(int dtype, const unsigned char *m, -\& unsigned int m_length, -\& const unsigned char *sigbuf, -\& unsigned int siglen, const RSA *rsa); -\& int RSA_meth_set_verify(RSA_METHOD *rsa, -\& int (*verify)(int dtype, const unsigned char *m, -\& unsigned int m_length, -\& const unsigned char *sigbuf, -\& unsigned int siglen, const RSA *rsa)); -\& -\& int (*RSA_meth_get_keygen(const RSA_METHOD *meth))(RSA *rsa, int bits, BIGNUM *e, -\& BN_GENCB *cb); -\& int RSA_meth_set_keygen(RSA_METHOD *rsa, -\& int (*keygen)(RSA *rsa, int bits, BIGNUM *e, -\& BN_GENCB *cb)); -\& -\& int (*RSA_meth_get_multi_prime_keygen(const RSA_METHOD *meth))(RSA *rsa, int bits, -\& int primes, BIGNUM *e, -\& BN_GENCB *cb); -\& -\& int RSA_meth_set_multi_prime_keygen(RSA_METHOD *meth, -\& int (*keygen) (RSA *rsa, int bits, -\& int primes, BIGNUM *e, -\& BN_GENCB *cb)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the \s-1OSSL_PROVIDER\s0 APIs. -.PP -The \fB\s-1RSA_METHOD\s0\fR type is a structure used for the provision of custom -\&\s-1RSA\s0 implementations. It provides a set of functions used by OpenSSL -for the implementation of the various \s-1RSA\s0 capabilities. -.PP -\&\fBRSA_meth_new()\fR creates a new \fB\s-1RSA_METHOD\s0\fR structure. It should be -given a unique \fBname\fR and a set of \fBflags\fR. The \fBname\fR should be a -\&\s-1NULL\s0 terminated string, which will be duplicated and stored in the -\&\fB\s-1RSA_METHOD\s0\fR object. It is the callers responsibility to free the -original string. The flags will be used during the construction of a -new \fB\s-1RSA\s0\fR object based on this \fB\s-1RSA_METHOD\s0\fR. Any new \fB\s-1RSA\s0\fR object -will have those flags set by default. -.PP -\&\fBRSA_meth_dup()\fR creates a duplicate copy of the \fB\s-1RSA_METHOD\s0\fR object -passed as a parameter. This might be useful for creating a new -\&\fB\s-1RSA_METHOD\s0\fR based on an existing one, but with some differences. -.PP -\&\fBRSA_meth_free()\fR destroys an \fB\s-1RSA_METHOD\s0\fR structure and frees up any -memory associated with it. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBRSA_meth_get0_name()\fR will return a pointer to the name of this -\&\s-1RSA_METHOD.\s0 This is a pointer to the internal name string and so -should not be freed by the caller. \fBRSA_meth_set1_name()\fR sets the name -of the \s-1RSA_METHOD\s0 to \fBname\fR. The string is duplicated and the copy is -stored in the \s-1RSA_METHOD\s0 structure, so the caller remains responsible -for freeing the memory associated with the name. -.PP -\&\fBRSA_meth_get_flags()\fR returns the current value of the flags associated -with this \s-1RSA_METHOD.\s0 \fBRSA_meth_set_flags()\fR provides the ability to set -these flags. -.PP -The functions \fBRSA_meth_get0_app_data()\fR and \fBRSA_meth_set0_app_data()\fR -provide the ability to associate implementation specific data with the -\&\s-1RSA_METHOD.\s0 It is the application's responsibility to free this data -before the \s-1RSA_METHOD\s0 is freed via a call to \fBRSA_meth_free()\fR. -.PP -\&\fBRSA_meth_get_sign()\fR and \fBRSA_meth_set_sign()\fR get and set the function -used for creating an \s-1RSA\s0 signature respectively. This function will be -called in response to the application calling \fBRSA_sign()\fR. The -parameters for the function have the same meaning as for \fBRSA_sign()\fR. -.PP -\&\fBRSA_meth_get_verify()\fR and \fBRSA_meth_set_verify()\fR get and set the -function used for verifying an \s-1RSA\s0 signature respectively. This -function will be called in response to the application calling -\&\fBRSA_verify()\fR. The parameters for the function have the same meaning as -for \fBRSA_verify()\fR. -.PP -\&\fBRSA_meth_get_mod_exp()\fR and \fBRSA_meth_set_mod_exp()\fR get and set the -function used for \s-1CRT\s0 computations. -.PP -\&\fBRSA_meth_get_bn_mod_exp()\fR and \fBRSA_meth_set_bn_mod_exp()\fR get and set -the function used for \s-1CRT\s0 computations, specifically the following -value: -.PP -.Vb 1 -\& r = a ^ p mod m -.Ve -.PP -Both the \fBmod_exp()\fR and \fBbn_mod_exp()\fR functions are called by the -default OpenSSL method during encryption, decryption, signing and -verification. -.PP -\&\fBRSA_meth_get_init()\fR and \fBRSA_meth_set_init()\fR get and set the function -used for creating a new \s-1RSA\s0 instance respectively. This function will -be called in response to the application calling \fBRSA_new()\fR (if the -current default \s-1RSA_METHOD\s0 is this one) or \fBRSA_new_method()\fR. The -\&\fBRSA_new()\fR and \fBRSA_new_method()\fR functions will allocate the memory for -the new \s-1RSA\s0 object, and a pointer to this newly allocated structure -will be passed as a parameter to the function. This function may be -\&\s-1NULL.\s0 -.PP -\&\fBRSA_meth_get_finish()\fR and \fBRSA_meth_set_finish()\fR get and set the -function used for destroying an instance of an \s-1RSA\s0 object respectively. -This function will be called in response to the application calling -\&\fBRSA_free()\fR. A pointer to the \s-1RSA\s0 to be destroyed is passed as a -parameter. The destroy function should be used for \s-1RSA\s0 implementation -specific clean up. The memory for the \s-1RSA\s0 itself should not be freed -by this function. This function may be \s-1NULL.\s0 -.PP -\&\fBRSA_meth_get_keygen()\fR and \fBRSA_meth_set_keygen()\fR get and set the -function used for generating a new \s-1RSA\s0 key pair respectively. This -function will be called in response to the application calling -\&\fBRSA_generate_key_ex()\fR. The parameter for the function has the same -meaning as for \fBRSA_generate_key_ex()\fR. -.PP -\&\fBRSA_meth_get_multi_prime_keygen()\fR and \fBRSA_meth_set_multi_prime_keygen()\fR get -and set the function used for generating a new multi-prime \s-1RSA\s0 key pair -respectively. This function will be called in response to the application calling -\&\fBRSA_generate_multi_prime_key()\fR. The parameter for the function has the same -meaning as for \fBRSA_generate_multi_prime_key()\fR. -.PP -\&\fBRSA_meth_get_pub_enc()\fR, \fBRSA_meth_set_pub_enc()\fR, -\&\fBRSA_meth_get_pub_dec()\fR, \fBRSA_meth_set_pub_dec()\fR, -\&\fBRSA_meth_get_priv_enc()\fR, \fBRSA_meth_set_priv_enc()\fR, -\&\fBRSA_meth_get_priv_dec()\fR, \fBRSA_meth_set_priv_dec()\fR get and set the -functions used for public and private key encryption and decryption. -These functions will be called in response to the application calling -\&\fBRSA_public_encrypt()\fR, \fBRSA_private_decrypt()\fR, \fBRSA_private_encrypt()\fR and -\&\fBRSA_public_decrypt()\fR and take the same parameters as those. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_meth_new()\fR and \fBRSA_meth_dup()\fR return the newly allocated -\&\s-1RSA_METHOD\s0 object or \s-1NULL\s0 on failure. -.PP -\&\fBRSA_meth_get0_name()\fR and \fBRSA_meth_get_flags()\fR return the name and -flags associated with the \s-1RSA_METHOD\s0 respectively. -.PP -All other RSA_meth_get_*() functions return the appropriate function -pointer that has been set in the \s-1RSA_METHOD,\s0 or \s-1NULL\s0 if no such -pointer has yet been set. -.PP -RSA_meth_set1_name and all RSA_meth_set_*() functions return 1 on -success or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRSA_new\fR\|(3), \fBRSA_generate_key_ex\fR\|(3), \fBRSA_sign\fR\|(3), -\&\fBRSA_set_method\fR\|(3), \fBRSA_size\fR\|(3), \fBRSA_get0_key\fR\|(3), -\&\fBRSA_generate_multi_prime_key\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -\&\fBRSA_meth_get_multi_prime_keygen()\fR and \fBRSA_meth_set_multi_prime_keygen()\fR were -added in OpenSSL 1.1.1. -.PP -Other functions described here were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_meth_set0_app_data.3ossl b/openssl-install/share/man/man3/RSA_meth_set0_app_data.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set0_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set1_name.3ossl b/openssl-install/share/man/man3/RSA_meth_set1_name.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set1_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_bn_mod_exp.3ossl b/openssl-install/share/man/man3/RSA_meth_set_bn_mod_exp.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_bn_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_finish.3ossl b/openssl-install/share/man/man3/RSA_meth_set_finish.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_flags.3ossl b/openssl-install/share/man/man3/RSA_meth_set_flags.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_init.3ossl b/openssl-install/share/man/man3/RSA_meth_set_init.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_keygen.3ossl b/openssl-install/share/man/man3/RSA_meth_set_keygen.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_mod_exp.3ossl b/openssl-install/share/man/man3/RSA_meth_set_mod_exp.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_mod_exp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_multi_prime_keygen.3ossl b/openssl-install/share/man/man3/RSA_meth_set_multi_prime_keygen.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_multi_prime_keygen.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_priv_dec.3ossl b/openssl-install/share/man/man3/RSA_meth_set_priv_dec.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_priv_dec.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_priv_enc.3ossl b/openssl-install/share/man/man3/RSA_meth_set_priv_enc.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_priv_enc.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_pub_dec.3ossl b/openssl-install/share/man/man3/RSA_meth_set_pub_dec.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_pub_dec.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_pub_enc.3ossl b/openssl-install/share/man/man3/RSA_meth_set_pub_enc.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_pub_enc.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_sign.3ossl b/openssl-install/share/man/man3/RSA_meth_set_sign.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_meth_set_verify.3ossl b/openssl-install/share/man/man3/RSA_meth_set_verify.3ossl deleted file mode 120000 index a5f9fe55..00000000 --- a/openssl-install/share/man/man3/RSA_meth_set_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_new.3ossl b/openssl-install/share/man/man3/RSA_new.3ossl deleted file mode 100644 index f1057df1..00000000 --- a/openssl-install/share/man/man3/RSA_new.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_NEW 3ossl" -.TH RSA_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_new, RSA_free \- allocate and free RSA objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& RSA *RSA_new(void); -\& -\& void RSA_free(RSA *rsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBRSA_new()\fR allocates and initializes an \fB\s-1RSA\s0\fR structure. It is equivalent to -calling RSA_new_method(\s-1NULL\s0). -.PP -\&\fBRSA_free()\fR frees the \fB\s-1RSA\s0\fR structure and its components. The key is -erased before the memory is returned to the system. -If \fBrsa\fR is \s-1NULL\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBRSA_new()\fR returns \fB\s-1NULL\s0\fR and sets an error -code that can be obtained by \fBERR_get_error\fR\|(3). Otherwise it returns -a pointer to the newly allocated structure. -.PP -\&\fBRSA_free()\fR returns no value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBRSA_generate_key\fR\|(3), -\&\fBRSA_new_method\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All functions described here were deprecated in OpenSSL 3.0. -For replacement see \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_new_method.3ossl b/openssl-install/share/man/man3/RSA_new_method.3ossl deleted file mode 120000 index ed5907f5..00000000 --- a/openssl-install/share/man/man3/RSA_new_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP.3ossl b/openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP_mgf1.3ossl b/openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP_mgf1.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_OAEP_mgf1.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_1.3ossl b/openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_1.3ossl deleted file mode 100644 index 58ca4d1d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_1.3ossl +++ /dev/null @@ -1,287 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_PADDING_ADD_PKCS1_TYPE_1 3ossl" -.TH RSA_PADDING_ADD_PKCS1_TYPE_1 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_padding_add_PKCS1_type_1, RSA_padding_check_PKCS1_type_1, -RSA_padding_add_PKCS1_type_2, RSA_padding_check_PKCS1_type_2, -RSA_padding_add_PKCS1_OAEP, RSA_padding_check_PKCS1_OAEP, -RSA_padding_add_PKCS1_OAEP_mgf1, RSA_padding_check_PKCS1_OAEP_mgf1, -RSA_padding_add_none, RSA_padding_check_none \- asymmetric encryption -padding -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int RSA_padding_add_PKCS1_type_1(unsigned char *to, int tlen, -\& const unsigned char *f, int fl); -\& -\& int RSA_padding_check_PKCS1_type_1(unsigned char *to, int tlen, -\& const unsigned char *f, int fl, int rsa_len); -\& -\& int RSA_padding_add_PKCS1_type_2(unsigned char *to, int tlen, -\& const unsigned char *f, int fl); -\& -\& int RSA_padding_check_PKCS1_type_2(unsigned char *to, int tlen, -\& const unsigned char *f, int fl, int rsa_len); -\& -\& int RSA_padding_add_PKCS1_OAEP(unsigned char *to, int tlen, -\& const unsigned char *f, int fl, -\& const unsigned char *p, int pl); -\& -\& int RSA_padding_check_PKCS1_OAEP(unsigned char *to, int tlen, -\& const unsigned char *f, int fl, int rsa_len, -\& const unsigned char *p, int pl); -\& -\& int RSA_padding_add_PKCS1_OAEP_mgf1(unsigned char *to, int tlen, -\& const unsigned char *f, int fl, -\& const unsigned char *p, int pl, -\& const EVP_MD *md, const EVP_MD *mgf1md); -\& -\& int RSA_padding_check_PKCS1_OAEP_mgf1(unsigned char *to, int tlen, -\& const unsigned char *f, int fl, int rsa_len, -\& const unsigned char *p, int pl, -\& const EVP_MD *md, const EVP_MD *mgf1md); -\& -\& int RSA_padding_add_none(unsigned char *to, int tlen, -\& const unsigned char *f, int fl); -\& -\& int RSA_padding_check_none(unsigned char *to, int tlen, -\& const unsigned char *f, int fl, int rsa_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the \s-1EVP PKEY\s0 APIs. -.PP -The \fBRSA_padding_xxx_xxx()\fR functions are called from the \s-1RSA\s0 encrypt, -decrypt, sign and verify functions. Normally they should not be called -from application programs. -.PP -However, they can also be called directly to implement padding for other -asymmetric ciphers. \fBRSA_padding_add_PKCS1_OAEP()\fR and -\&\fBRSA_padding_check_PKCS1_OAEP()\fR may be used in an application combined -with \fB\s-1RSA_NO_PADDING\s0\fR in order to implement \s-1OAEP\s0 with an encoding -parameter. -.PP -\&\fBRSA_padding_add_xxx()\fR encodes \fBfl\fR bytes from \fBf\fR so as to fit into -\&\fBtlen\fR bytes and stores the result at \fBto\fR. An error occurs if \fBfl\fR -does not meet the size requirements of the encoding method. -.PP -The following encoding methods are implemented: -.IP "PKCS1_type_1" 4 -.IX Item "PKCS1_type_1" -\&\s-1PKCS\s0 #1 v2.0 EMSA\-PKCS1\-v1_5 (\s-1PKCS\s0 #1 v1.5 block type 1); used for signatures -.IP "PKCS1_type_2" 4 -.IX Item "PKCS1_type_2" -\&\s-1PKCS\s0 #1 v2.0 EME\-PKCS1\-v1_5 (\s-1PKCS\s0 #1 v1.5 block type 2) -.IP "\s-1PKCS1_OAEP\s0" 4 -.IX Item "PKCS1_OAEP" -\&\s-1PKCS\s0 #1 v2.0 EME-OAEP -.IP "none" 4 -.IX Item "none" -simply copy the data -.PP -The random number generator must be seeded prior to calling -\&\fBRSA_padding_add_xxx()\fR. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.PP -\&\fBRSA_padding_check_xxx()\fR verifies that the \fBfl\fR bytes at \fBf\fR contain -a valid encoding for a \fBrsa_len\fR byte \s-1RSA\s0 key in the respective -encoding method and stores the recovered data of at most \fBtlen\fR bytes -(for \fB\s-1RSA_NO_PADDING\s0\fR: of size \fBtlen\fR) -at \fBto\fR. -.PP -For \fBRSA_padding_xxx_OAEP()\fR, \fBp\fR points to the encoding parameter -of length \fBpl\fR. \fBp\fR may be \fB\s-1NULL\s0\fR if \fBpl\fR is 0. -.PP -For \fBRSA_padding_xxx_OAEP_mgf1()\fR, \fBmd\fR points to the md hash, -if \fBmd\fR is \fB\s-1NULL\s0\fR that means md=sha1, and \fBmgf1md\fR points to -the mgf1 hash, if \fBmgf1md\fR is \fB\s-1NULL\s0\fR that means mgf1md=md. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBRSA_padding_add_xxx()\fR functions return 1 on success, 0 on error. -The \fBRSA_padding_check_xxx()\fR functions return the length of the -recovered data, \-1 on error. Error codes can be obtained by calling -\&\fBERR_get_error\fR\|(3). -.SH "WARNINGS" -.IX Header "WARNINGS" -The result of \fBRSA_padding_check_PKCS1_type_2()\fR is exactly the -information which is used to mount a classical Bleichenbacher -padding oracle attack. This is an inherent weakness in the \s-1PKCS\s0 #1 -v1.5 padding design. Prefer \s-1PKCS1_OAEP\s0 padding. If that is not -possible, the result of \fBRSA_padding_check_PKCS1_type_2()\fR should be -checked in constant time if it matches the expected length of the -plaintext and additionally some application specific consistency -checks on the plaintext need to be performed in constant time. -If the plaintext is rejected it must be kept secret which of the -checks caused the application to reject the message. -Do not remove the zero-padding from the decrypted raw \s-1RSA\s0 data -which was computed by \fBRSA_private_decrypt()\fR with \fB\s-1RSA_NO_PADDING\s0\fR, -as this would create a small timing side channel which could be -used to mount a Bleichenbacher attack against any padding mode -including \s-1PKCS1_OAEP.\s0 -.PP -You should prefer the use of \s-1EVP PKEY\s0 APIs for PKCS#1 v1.5 decryption -as they implement the necessary workarounds internally. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRSA_public_encrypt\fR\|(3), -\&\fBRSA_private_decrypt\fR\|(3), -\&\fBRSA_sign\fR\|(3), \fBRSA_verify\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_2.3ossl b/openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_2.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_add_PKCS1_type_2.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_add_none.3ossl b/openssl-install/share/man/man3/RSA_padding_add_none.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_add_none.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP.3ossl b/openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP_mgf1.3ossl b/openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP_mgf1.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_OAEP_mgf1.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_1.3ossl b/openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_1.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_1.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_2.3ossl b/openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_2.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_check_PKCS1_type_2.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_padding_check_none.3ossl b/openssl-install/share/man/man3/RSA_padding_check_none.3ossl deleted file mode 120000 index 880f645d..00000000 --- a/openssl-install/share/man/man3/RSA_padding_check_none.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_padding_add_PKCS1_type_1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_print.3ossl b/openssl-install/share/man/man3/RSA_print.3ossl deleted file mode 100644 index 87c95822..00000000 --- a/openssl-install/share/man/man3/RSA_print.3ossl +++ /dev/null @@ -1,216 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_PRINT 3ossl" -.TH RSA_PRINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_print, RSA_print_fp, -DSAparams_print, DSAparams_print_fp, DSA_print, DSA_print_fp, -DHparams_print, DHparams_print_fp \- print cryptographic parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int RSA_print(BIO *bp, const RSA *x, int offset); -\& int RSA_print_fp(FILE *fp, const RSA *x, int offset); -\& -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& int DSAparams_print(BIO *bp, const DSA *x); -\& int DSAparams_print_fp(FILE *fp, const DSA *x); -\& int DSA_print(BIO *bp, const DSA *x, int offset); -\& int DSA_print_fp(FILE *fp, const DSA *x, int offset); -\& -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int DHparams_print(BIO *bp, DH *x); -\& int DHparams_print_fp(FILE *fp, const DH *x); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_print_params\fR\|(3) and -\&\fBEVP_PKEY_print_private\fR\|(3). -.PP -A human-readable hexadecimal output of the components of the \s-1RSA\s0 -key, \s-1DSA\s0 parameters or key or \s-1DH\s0 parameters is printed to \fBbp\fR or \fBfp\fR. -.PP -The output lines are indented by \fBoffset\fR spaces. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBDSAparams_print()\fR, \fBDSAparams_print_fp()\fR, \fBDSA_print()\fR, and \fBDSA_print_fp()\fR -return 1 for success and 0 or a negative value for failure. -.PP -\&\fBDHparams_print()\fR and \fBDHparams_print_fp()\fR return 1 on success, 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -.Vb 3 -\& L, -\& L, -\& L -.Ve -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_print_fp.3ossl b/openssl-install/share/man/man3/RSA_print_fp.3ossl deleted file mode 120000 index f53ff3b2..00000000 --- a/openssl-install/share/man/man3/RSA_print_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_private_decrypt.3ossl b/openssl-install/share/man/man3/RSA_private_decrypt.3ossl deleted file mode 120000 index 57b4db95..00000000 --- a/openssl-install/share/man/man3/RSA_private_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_public_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_private_encrypt.3ossl b/openssl-install/share/man/man3/RSA_private_encrypt.3ossl deleted file mode 100644 index 49b1f5fa..00000000 --- a/openssl-install/share/man/man3/RSA_private_encrypt.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_PRIVATE_ENCRYPT 3ossl" -.TH RSA_PRIVATE_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_private_encrypt, RSA_public_decrypt \- low\-level signature operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int RSA_private_encrypt(int flen, unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& -\& int RSA_public_decrypt(int flen, unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Both of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_sign_init_ex\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), \fBEVP_PKEY_verify_recover_init\fR\|(3), and -\&\fBEVP_PKEY_verify_recover\fR\|(3). -.PP -These functions handle \s-1RSA\s0 signatures at a low-level. -.PP -\&\fBRSA_private_encrypt()\fR signs the \fBflen\fR bytes at \fBfrom\fR (usually a -message digest with an algorithm identifier) using the private key -\&\fBrsa\fR and stores the signature in \fBto\fR. \fBto\fR must point to -\&\fBRSA_size(rsa)\fR bytes of memory. -.PP -\&\fBpadding\fR denotes one of the following modes: -.IP "\s-1RSA_PKCS1_PADDING\s0" 4 -.IX Item "RSA_PKCS1_PADDING" -\&\s-1PKCS\s0 #1 v1.5 padding. This function does not handle the -\&\fBalgorithmIdentifier\fR specified in \s-1PKCS\s0 #1. When generating or -verifying \s-1PKCS\s0 #1 signatures, \fBRSA_sign\fR\|(3) and \fBRSA_verify\fR\|(3) should be -used. -.IP "\s-1RSA_NO_PADDING\s0" 4 -.IX Item "RSA_NO_PADDING" -Raw \s-1RSA\s0 signature. This mode should \fIonly\fR be used to implement -cryptographically sound padding modes in the application code. -Signing user data directly with \s-1RSA\s0 is insecure. -.PP -\&\fBRSA_public_decrypt()\fR recovers the message digest from the \fBflen\fR -bytes long signature at \fBfrom\fR using the signer's public key -\&\fBrsa\fR. \fBto\fR must point to a memory section large enough to hold the -message digest (which is smaller than \fBRSA_size(rsa) \- -11\fR). \fBpadding\fR is the padding mode that was used to sign the data. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_private_encrypt()\fR returns the size of the signature (i.e., -RSA_size(rsa)). \fBRSA_public_decrypt()\fR returns the size of the -recovered message digest. -.PP -On error, \-1 is returned; the error codes can be -obtained by \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBRSA_sign\fR\|(3), \fBRSA_verify\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), \fBEVP_PKEY_verify_recover\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -Both of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_public_decrypt.3ossl b/openssl-install/share/man/man3/RSA_public_decrypt.3ossl deleted file mode 120000 index ecc12e1e..00000000 --- a/openssl-install/share/man/man3/RSA_public_decrypt.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_private_encrypt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_public_encrypt.3ossl b/openssl-install/share/man/man3/RSA_public_encrypt.3ossl deleted file mode 100644 index dd415048..00000000 --- a/openssl-install/share/man/man3/RSA_public_encrypt.3ossl +++ /dev/null @@ -1,255 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_PUBLIC_ENCRYPT 3ossl" -.TH RSA_PUBLIC_ENCRYPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_public_encrypt, RSA_private_decrypt \- RSA public key cryptography -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int RSA_public_encrypt(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& -\& int RSA_private_decrypt(int flen, const unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Both of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_encrypt_init_ex\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), \fBEVP_PKEY_decrypt_init_ex\fR\|(3) and -\&\fBEVP_PKEY_decrypt\fR\|(3). -.PP -\&\fBRSA_public_encrypt()\fR encrypts the \fBflen\fR bytes at \fBfrom\fR (usually a -session key) using the public key \fBrsa\fR and stores the ciphertext in -\&\fBto\fR. \fBto\fR must point to RSA_size(\fBrsa\fR) bytes of memory. -.PP -\&\fBpadding\fR denotes one of the following modes: -.IP "\s-1RSA_PKCS1_PADDING\s0" 4 -.IX Item "RSA_PKCS1_PADDING" -\&\s-1PKCS\s0 #1 v1.5 padding. This currently is the most widely used mode. -However, it is highly recommended to use \s-1RSA_PKCS1_OAEP_PADDING\s0 in -new applications. \s-1SEE WARNING BELOW.\s0 -.IP "\s-1RSA_PKCS1_OAEP_PADDING\s0" 4 -.IX Item "RSA_PKCS1_OAEP_PADDING" -EME-OAEP as defined in \s-1PKCS\s0 #1 v2.0 with \s-1SHA\-1, MGF1\s0 and an empty -encoding parameter. This mode is recommended for all new applications. -.IP "\s-1RSA_NO_PADDING\s0" 4 -.IX Item "RSA_NO_PADDING" -Raw \s-1RSA\s0 encryption. This mode should \fIonly\fR be used to implement -cryptographically sound padding modes in the application code. -Encrypting user data directly with \s-1RSA\s0 is insecure. -.PP -When encrypting \fBflen\fR must not be more than RSA_size(\fBrsa\fR) \- 11 for the -\&\s-1PKCS\s0 #1 v1.5 based padding modes, not more than RSA_size(\fBrsa\fR) \- 42 for -\&\s-1RSA_PKCS1_OAEP_PADDING\s0 and exactly RSA_size(\fBrsa\fR) for \s-1RSA_NO_PADDING.\s0 -When a padding mode other than \s-1RSA_NO_PADDING\s0 is in use, then -\&\fBRSA_public_encrypt()\fR will include some random bytes into the ciphertext -and therefore the ciphertext will be different each time, even if the -plaintext and the public key are exactly identical. -The returned ciphertext in \fBto\fR will always be zero padded to exactly -RSA_size(\fBrsa\fR) bytes. -\&\fBto\fR and \fBfrom\fR may overlap. -.PP -\&\fBRSA_private_decrypt()\fR decrypts the \fBflen\fR bytes at \fBfrom\fR using the -private key \fBrsa\fR and stores the plaintext in \fBto\fR. \fBflen\fR should -be equal to RSA_size(\fBrsa\fR) but may be smaller, when leading zero -bytes are in the ciphertext. Those are not important and may be removed, -but \fBRSA_public_encrypt()\fR does not do that. \fBto\fR must point -to a memory section large enough to hold the maximal possible decrypted -data (which is equal to RSA_size(\fBrsa\fR) for \s-1RSA_NO_PADDING,\s0 -RSA_size(\fBrsa\fR) \- 11 for the \s-1PKCS\s0 #1 v1.5 based padding modes and -RSA_size(\fBrsa\fR) \- 42 for \s-1RSA_PKCS1_OAEP_PADDING\s0). -\&\fBpadding\fR is the padding mode that was used to encrypt the data. -\&\fBto\fR and \fBfrom\fR may overlap. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_public_encrypt()\fR returns the size of the encrypted data (i.e., -RSA_size(\fBrsa\fR)). \fBRSA_private_decrypt()\fR returns the size of the -recovered plaintext. A return value of 0 is not an error and -means only that the plaintext was empty. -.PP -On error, \-1 is returned; the error codes can be -obtained by \fBERR_get_error\fR\|(3). -.SH "WARNINGS" -.IX Header "WARNINGS" -Decryption failures in the \s-1RSA_PKCS1_PADDING\s0 mode leak information -which can potentially be used to mount a Bleichenbacher padding oracle -attack. This is an inherent weakness in the \s-1PKCS\s0 #1 v1.5 padding -design. Prefer \s-1RSA_PKCS1_OAEP_PADDING.\s0 -.PP -In OpenSSL before version 3.2.0, both the return value and the length of -returned value could be used to mount the Bleichenbacher attack. -Since version 3.2.0, the default provider in OpenSSL does not return an -error when padding checks fail. Instead it generates a random -message based on used private -key and provided ciphertext so that application code doesn't have to implement -a side-channel secure error handling. -Applications that want to be secure against side-channel attacks with -providers that don't implement implicit rejection, still need to -handle the returned values using side-channel free code. -Side-channel free handling of the error stack can be performed using -either a pair of unconditional \fBERR_set_mark\fR\|(3) and \fBERR_pop_to_mark\fR\|(3) -calls or by using the \fBERR_clear_error\fR\|(3) call. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1SSL, PKCS\s0 #1 v2.0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBRAND_bytes\fR\|(3), -\&\fBRSA_size\fR\|(3), \fBEVP_PKEY_decrypt\fR\|(3), \fBEVP_PKEY_encrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -Both of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_security_bits.3ossl b/openssl-install/share/man/man3/RSA_security_bits.3ossl deleted file mode 120000 index 4d3a22c6..00000000 --- a/openssl-install/share/man/man3/RSA_security_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set0_crt_params.3ossl b/openssl-install/share/man/man3/RSA_set0_crt_params.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_set0_crt_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set0_factors.3ossl b/openssl-install/share/man/man3/RSA_set0_factors.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_set0_factors.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set0_key.3ossl b/openssl-install/share/man/man3/RSA_set0_key.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_set0_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set0_multi_prime_params.3ossl b/openssl-install/share/man/man3/RSA_set0_multi_prime_params.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_set0_multi_prime_params.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set_app_data.3ossl b/openssl-install/share/man/man3/RSA_set_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/RSA_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set_default_method.3ossl b/openssl-install/share/man/man3/RSA_set_default_method.3ossl deleted file mode 120000 index ed5907f5..00000000 --- a/openssl-install/share/man/man3/RSA_set_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_set_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set_ex_data.3ossl b/openssl-install/share/man/man3/RSA_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/RSA_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set_flags.3ossl b/openssl-install/share/man/man3/RSA_set_flags.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_set_method.3ossl b/openssl-install/share/man/man3/RSA_set_method.3ossl deleted file mode 100644 index 5413bc9e..00000000 --- a/openssl-install/share/man/man3/RSA_set_method.3ossl +++ /dev/null @@ -1,328 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_SET_METHOD 3ossl" -.TH RSA_SET_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_set_default_method, RSA_get_default_method, RSA_set_method, -RSA_get_method, RSA_PKCS1_OpenSSL, RSA_flags, -RSA_new_method \- select RSA method -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void RSA_set_default_method(const RSA_METHOD *meth); -\& -\& const RSA_METHOD *RSA_get_default_method(void); -\& -\& int RSA_set_method(RSA *rsa, const RSA_METHOD *meth); -\& -\& const RSA_METHOD *RSA_get_method(const RSA *rsa); -\& -\& const RSA_METHOD *RSA_PKCS1_OpenSSL(void); -\& -\& int RSA_flags(const RSA *rsa); -\& -\& RSA *RSA_new_method(ENGINE *engine); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use the \s-1OSSL_PROVIDER\s0 APIs. -.PP -An \fB\s-1RSA_METHOD\s0\fR specifies the functions that OpenSSL uses for \s-1RSA\s0 -operations. By modifying the method, alternative implementations such as -hardware accelerators may be used. \s-1IMPORTANT:\s0 See the \s-1NOTES\s0 section for -important information about how these \s-1RSA API\s0 functions are affected by the -use of \fB\s-1ENGINE\s0\fR \s-1API\s0 calls. -.PP -Initially, the default \s-1RSA_METHOD\s0 is the OpenSSL internal implementation, -as returned by \fBRSA_PKCS1_OpenSSL()\fR. -.PP -\&\fBRSA_set_default_method()\fR makes \fBmeth\fR the default method for all \s-1RSA\s0 -structures created later. -\&\fB\s-1NB\s0\fR: This is true only whilst no \s-1ENGINE\s0 has -been set as a default for \s-1RSA,\s0 so this function is no longer recommended. -This function is not thread-safe and should not be called at the same time -as other OpenSSL functions. -.PP -\&\fBRSA_get_default_method()\fR returns a pointer to the current default -\&\s-1RSA_METHOD.\s0 However, the meaningfulness of this result is dependent on -whether the \s-1ENGINE API\s0 is being used, so this function is no longer -recommended. -.PP -\&\fBRSA_set_method()\fR selects \fBmeth\fR to perform all operations using the key -\&\fBrsa\fR. This will replace the \s-1RSA_METHOD\s0 used by the \s-1RSA\s0 key and if the -previous method was supplied by an \s-1ENGINE,\s0 the handle to that \s-1ENGINE\s0 will -be released during the change. It is possible to have \s-1RSA\s0 keys that only -work with certain \s-1RSA_METHOD\s0 implementations (e.g. from an \s-1ENGINE\s0 module -that supports embedded hardware-protected keys), and in such cases -attempting to change the \s-1RSA_METHOD\s0 for the key can have unexpected -results. -.PP -\&\fBRSA_get_method()\fR returns a pointer to the \s-1RSA_METHOD\s0 being used by \fBrsa\fR. -This method may or may not be supplied by an \s-1ENGINE\s0 implementation, but if -it is, the return value can only be guaranteed to be valid as long as the -\&\s-1RSA\s0 key itself is valid and does not have its implementation changed by -\&\fBRSA_set_method()\fR. -.PP -\&\fBRSA_flags()\fR returns the \fBflags\fR that are set for \fBrsa\fR's current -\&\s-1RSA_METHOD.\s0 See the \s-1BUGS\s0 section. -.PP -\&\fBRSA_new_method()\fR allocates and initializes an \s-1RSA\s0 structure so that -\&\fBengine\fR will be used for the \s-1RSA\s0 operations. If \fBengine\fR is \s-1NULL,\s0 the -default \s-1ENGINE\s0 for \s-1RSA\s0 operations is used, and if no default \s-1ENGINE\s0 is set, -the \s-1RSA_METHOD\s0 controlled by \fBRSA_set_default_method()\fR is used. -.PP -\&\fBRSA_flags()\fR returns the \fBflags\fR that are set for \fBrsa\fR's current method. -.PP -\&\fBRSA_new_method()\fR allocates and initializes an \fB\s-1RSA\s0\fR structure so that -\&\fBmethod\fR will be used for the \s-1RSA\s0 operations. If \fBmethod\fR is \fB\s-1NULL\s0\fR, -the default method is used. -.SH "THE RSA_METHOD STRUCTURE" -.IX Header "THE RSA_METHOD STRUCTURE" -.Vb 4 -\& typedef struct rsa_meth_st -\& { -\& /* name of the implementation */ -\& const char *name; -\& -\& /* encrypt */ -\& int (*rsa_pub_enc)(int flen, unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& -\& /* verify arbitrary data */ -\& int (*rsa_pub_dec)(int flen, unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& -\& /* sign arbitrary data */ -\& int (*rsa_priv_enc)(int flen, unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& -\& /* decrypt */ -\& int (*rsa_priv_dec)(int flen, unsigned char *from, -\& unsigned char *to, RSA *rsa, int padding); -\& -\& /* compute r0 = r0 ^ I mod rsa\->n (May be NULL for some implementations) */ -\& int (*rsa_mod_exp)(BIGNUM *r0, BIGNUM *I, RSA *rsa); -\& -\& /* compute r = a ^ p mod m (May be NULL for some implementations) */ -\& int (*bn_mod_exp)(BIGNUM *r, BIGNUM *a, const BIGNUM *p, -\& const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *m_ctx); -\& -\& /* called at RSA_new */ -\& int (*init)(RSA *rsa); -\& -\& /* called at RSA_free */ -\& int (*finish)(RSA *rsa); -\& -\& /* -\& * RSA_FLAG_EXT_PKEY \- rsa_mod_exp is called for private key -\& * operations, even if p,q,dmp1,dmq1,iqmp -\& * are NULL -\& * RSA_METHOD_FLAG_NO_CHECK \- don\*(Aqt check pub/private match -\& */ -\& int flags; -\& -\& char *app_data; /* ?? */ -\& -\& int (*rsa_sign)(int type, -\& const unsigned char *m, unsigned int m_length, -\& unsigned char *sigret, unsigned int *siglen, const RSA *rsa); -\& int (*rsa_verify)(int dtype, -\& const unsigned char *m, unsigned int m_length, -\& const unsigned char *sigbuf, unsigned int siglen, -\& const RSA *rsa); -\& /* keygen. If NULL built\-in RSA key generation will be used */ -\& int (*rsa_keygen)(RSA *rsa, int bits, BIGNUM *e, BN_GENCB *cb); -\& -\& } RSA_METHOD; -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_PKCS1_OpenSSL()\fR, \fBRSA_PKCS1_null_method()\fR, \fBRSA_get_default_method()\fR -and \fBRSA_get_method()\fR return pointers to the respective RSA_METHODs. -.PP -\&\fBRSA_set_default_method()\fR returns no value. -.PP -\&\fBRSA_set_method()\fR returns a pointer to the old \s-1RSA_METHOD\s0 implementation -that was replaced. However, this return value should probably be ignored -because if it was supplied by an \s-1ENGINE,\s0 the pointer could be invalidated -at any time if the \s-1ENGINE\s0 is unloaded (in fact it could be unloaded as a -result of the \fBRSA_set_method()\fR function releasing its handle to the -\&\s-1ENGINE\s0). For this reason, the return type may be replaced with a \fBvoid\fR -declaration in a future release. -.PP -\&\fBRSA_new_method()\fR returns \s-1NULL\s0 and sets an error code that can be obtained -by \fBERR_get_error\fR\|(3) if the allocation fails. Otherwise -it returns a pointer to the newly allocated structure. -.SH "BUGS" -.IX Header "BUGS" -The behaviour of \fBRSA_flags()\fR is a mis-feature that is left as-is for now -to avoid creating compatibility problems. \s-1RSA\s0 functionality, such as the -encryption functions, are controlled by the \fBflags\fR value in the \s-1RSA\s0 key -itself, not by the \fBflags\fR value in the \s-1RSA_METHOD\s0 attached to the \s-1RSA\s0 key -(which is what this function returns). If the flags element of an \s-1RSA\s0 key -is changed, the changes will be honoured by \s-1RSA\s0 functionality but will not -be reflected in the return value of the \fBRSA_flags()\fR function \- in effect -\&\fBRSA_flags()\fR behaves more like an \fBRSA_default_flags()\fR function (which does -not currently exist). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRSA_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.PP -The \fBRSA_null_method()\fR, which was a partial attempt to avoid patent issues, -was replaced to always return \s-1NULL\s0 in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_sign.3ossl b/openssl-install/share/man/man3/RSA_sign.3ossl deleted file mode 100644 index 7cc41f8e..00000000 --- a/openssl-install/share/man/man3/RSA_sign.3ossl +++ /dev/null @@ -1,209 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_SIGN 3ossl" -.TH RSA_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_sign, RSA_verify \- RSA signatures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& int RSA_sign(int type, const unsigned char *m, unsigned int m_len, -\& unsigned char *sigret, unsigned int *siglen, RSA *rsa); -\& -\& int RSA_verify(int type, const unsigned char *m, unsigned int m_len, -\& unsigned char *sigbuf, unsigned int siglen, RSA *rsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_sign_init\fR\|(3), \fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify_init\fR\|(3) and \fBEVP_PKEY_verify\fR\|(3). -.PP -\&\fBRSA_sign()\fR signs the message digest \fBm\fR of size \fBm_len\fR using the -private key \fBrsa\fR using RSASSA\-PKCS1\-v1_5 as specified in \s-1RFC 3447.\s0 It -stores the signature in \fBsigret\fR and the signature size in \fBsiglen\fR. -\&\fBsigret\fR must point to RSA_size(\fBrsa\fR) bytes of memory. -Note that \s-1PKCS\s0 #1 adds meta-data, placing limits on the size of the -key that can be used. -See \fBRSA_private_encrypt\fR\|(3) for lower-level -operations. -.PP -\&\fBtype\fR denotes the message digest algorithm that was used to generate -\&\fBm\fR. -If \fBtype\fR is \fBNID_md5_sha1\fR, -an \s-1SSL\s0 signature (\s-1MD5\s0 and \s-1SHA1\s0 message digests with \s-1PKCS\s0 #1 padding -and no algorithm identifier) is created. -.PP -\&\fBRSA_verify()\fR verifies that the signature \fBsigbuf\fR of size \fBsiglen\fR -matches a given message digest \fBm\fR of size \fBm_len\fR. \fBtype\fR denotes -the message digest algorithm that was used to generate the signature. -\&\fBrsa\fR is the signer's public key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_sign()\fR returns 1 on success and 0 for failure. -\&\fBRSA_verify()\fR returns 1 on successful verification and 0 for failure. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1SSL, PKCS\s0 #1 v2.0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBRSA_private_encrypt\fR\|(3), -\&\fBRSA_public_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_sign_ASN1_OCTET_STRING.3ossl b/openssl-install/share/man/man3/RSA_sign_ASN1_OCTET_STRING.3ossl deleted file mode 100644 index db950536..00000000 --- a/openssl-install/share/man/man3/RSA_sign_ASN1_OCTET_STRING.3ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_SIGN_ASN1_OCTET_STRING 3ossl" -.TH RSA_SIGN_ASN1_OCTET_STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_sign_ASN1_OCTET_STRING, RSA_verify_ASN1_OCTET_STRING \- RSA signatures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& int RSA_sign_ASN1_OCTET_STRING(int dummy, unsigned char *m, -\& unsigned int m_len, unsigned char *sigret, -\& unsigned int *siglen, RSA *rsa); -\& -\& int RSA_verify_ASN1_OCTET_STRING(int dummy, unsigned char *m, -\& unsigned int m_len, unsigned char *sigbuf, -\& unsigned int siglen, RSA *rsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. -Applications should instead use \s-1EVP PKEY\s0 APIs. -.PP -\&\fBRSA_sign_ASN1_OCTET_STRING()\fR signs the octet string \fBm\fR of size -\&\fBm_len\fR using the private key \fBrsa\fR represented in \s-1DER\s0 using \s-1PKCS\s0 #1 -padding. It stores the signature in \fBsigret\fR and the signature size -in \fBsiglen\fR. \fBsigret\fR must point to \fBRSA_size(rsa)\fR bytes of -memory. -.PP -\&\fBdummy\fR is ignored. -.PP -The random number generator must be seeded when calling -\&\fBRSA_sign_ASN1_OCTET_STRING()\fR. -If the automatic seeding or reseeding of the OpenSSL \s-1CSPRNG\s0 fails due to -external circumstances (see \s-1\fBRAND\s0\fR\|(7)), the operation will fail. -.PP -\&\fBRSA_verify_ASN1_OCTET_STRING()\fR verifies that the signature \fBsigbuf\fR -of size \fBsiglen\fR is the \s-1DER\s0 representation of a given octet string -\&\fBm\fR of size \fBm_len\fR. \fBdummy\fR is ignored. \fBrsa\fR is the signer's -public key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_sign_ASN1_OCTET_STRING()\fR returns 1 on success, 0 otherwise. -\&\fBRSA_verify_ASN1_OCTET_STRING()\fR returns 1 on successful verification, 0 -otherwise. -.PP -The error codes can be obtained by \fBERR_get_error\fR\|(3). -.SH "BUGS" -.IX Header "BUGS" -These functions serve no recognizable purpose. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBRAND_bytes\fR\|(3), \fBRSA_sign\fR\|(3), -\&\fBRSA_verify\fR\|(3), -\&\s-1\fBRAND\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_size.3ossl b/openssl-install/share/man/man3/RSA_size.3ossl deleted file mode 100644 index 5548d51e..00000000 --- a/openssl-install/share/man/man3/RSA_size.3ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA_SIZE 3ossl" -.TH RSA_SIZE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA_size, RSA_bits, RSA_security_bits \- get RSA modulus size or security bits -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int RSA_bits(const RSA *rsa); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& int RSA_size(const RSA *rsa); -\& -\& int RSA_security_bits(const RSA *rsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBRSA_bits()\fR returns the number of significant bits. -.PP -\&\fBrsa\fR and \fBrsa\->n\fR must not be \fB\s-1NULL\s0\fR. -.PP -The remaining functions described on this page are deprecated. -Applications should instead use \fBEVP_PKEY_get_size\fR\|(3), \fBEVP_PKEY_get_bits\fR\|(3) -and \fBEVP_PKEY_get_security_bits\fR\|(3). -.PP -\&\fBRSA_size()\fR returns the \s-1RSA\s0 modulus size in bytes. It can be used to -determine how much memory must be allocated for an \s-1RSA\s0 encrypted -value. -.PP -\&\fBRSA_security_bits()\fR returns the number of security bits of the given \fBrsa\fR -key. See \fBBN_security_bits\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBRSA_bits()\fR returns the number of bits in the key. -.PP -\&\fBRSA_size()\fR returns the size of modulus in bytes. -.PP -\&\fBRSA_security_bits()\fR returns the number of security bits. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBN_num_bits\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBRSA_size()\fR and \fBRSA_security_bits()\fR functions were deprecated in OpenSSL 3.0. -.PP -The \fBRSA_bits()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/RSA_test_flags.3ossl b/openssl-install/share/man/man3/RSA_test_flags.3ossl deleted file mode 120000 index ad681808..00000000 --- a/openssl-install/share/man/man3/RSA_test_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_get0_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_verify.3ossl b/openssl-install/share/man/man3/RSA_verify.3ossl deleted file mode 120000 index 6273192f..00000000 --- a/openssl-install/share/man/man3/RSA_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/RSA_verify_ASN1_OCTET_STRING.3ossl b/openssl-install/share/man/man3/RSA_verify_ASN1_OCTET_STRING.3ossl deleted file mode 120000 index 44876a3c..00000000 --- a/openssl-install/share/man/man3/RSA_verify_ASN1_OCTET_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -RSA_sign_ASN1_OCTET_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCRYPT_PARAMS_free.3ossl b/openssl-install/share/man/man3/SCRYPT_PARAMS_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/SCRYPT_PARAMS_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCRYPT_PARAMS_new.3ossl b/openssl-install/share/man/man3/SCRYPT_PARAMS_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/SCRYPT_PARAMS_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_LIST_free.3ossl b/openssl-install/share/man/man3/SCT_LIST_free.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_LIST_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_LIST_print.3ossl b/openssl-install/share/man/man3/SCT_LIST_print.3ossl deleted file mode 120000 index f866db60..00000000 --- a/openssl-install/share/man/man3/SCT_LIST_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_LIST_validate.3ossl b/openssl-install/share/man/man3/SCT_LIST_validate.3ossl deleted file mode 120000 index 153079c5..00000000 --- a/openssl-install/share/man/man3/SCT_LIST_validate.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_validate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_free.3ossl b/openssl-install/share/man/man3/SCT_free.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get0_extensions.3ossl b/openssl-install/share/man/man3/SCT_get0_extensions.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get0_log_id.3ossl b/openssl-install/share/man/man3/SCT_get0_log_id.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get0_log_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get0_signature.3ossl b/openssl-install/share/man/man3/SCT_get0_signature.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get_log_entry_type.3ossl b/openssl-install/share/man/man3/SCT_get_log_entry_type.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get_log_entry_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get_signature_nid.3ossl b/openssl-install/share/man/man3/SCT_get_signature_nid.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get_signature_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get_source.3ossl b/openssl-install/share/man/man3/SCT_get_source.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get_source.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get_timestamp.3ossl b/openssl-install/share/man/man3/SCT_get_timestamp.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get_timestamp.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get_validation_status.3ossl b/openssl-install/share/man/man3/SCT_get_validation_status.3ossl deleted file mode 120000 index 153079c5..00000000 --- a/openssl-install/share/man/man3/SCT_get_validation_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_validate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_get_version.3ossl b/openssl-install/share/man/man3/SCT_get_version.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_get_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_new.3ossl b/openssl-install/share/man/man3/SCT_new.3ossl deleted file mode 100644 index 12aca577..00000000 --- a/openssl-install/share/man/man3/SCT_new.3ossl +++ /dev/null @@ -1,322 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SCT_NEW 3ossl" -.TH SCT_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SCT_new, SCT_new_from_base64, SCT_free, SCT_LIST_free, -SCT_get_version, SCT_set_version, -SCT_get_log_entry_type, SCT_set_log_entry_type, -SCT_get0_log_id, SCT_set0_log_id, SCT_set1_log_id, -SCT_get_timestamp, SCT_set_timestamp, -SCT_get_signature_nid, SCT_set_signature_nid, -SCT_get0_signature, SCT_set0_signature, SCT_set1_signature, -SCT_get0_extensions, SCT_set0_extensions, SCT_set1_extensions, -SCT_get_source, SCT_set_source -\&\- A Certificate Transparency Signed Certificate Timestamp -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef enum { -\& CT_LOG_ENTRY_TYPE_NOT_SET = \-1, -\& CT_LOG_ENTRY_TYPE_X509 = 0, -\& CT_LOG_ENTRY_TYPE_PRECERT = 1 -\& } ct_log_entry_type_t; -\& -\& typedef enum { -\& SCT_VERSION_NOT_SET = \-1, -\& SCT_VERSION_V1 = 0 -\& } sct_version_t; -\& -\& typedef enum { -\& SCT_SOURCE_UNKNOWN, -\& SCT_SOURCE_TLS_EXTENSION, -\& SCT_SOURCE_X509V3_EXTENSION, -\& SCT_SOURCE_OCSP_STAPLED_RESPONSE -\& } sct_source_t; -\& -\& SCT *SCT_new(void); -\& SCT *SCT_new_from_base64(unsigned char version, -\& const char *logid_base64, -\& ct_log_entry_type_t entry_type, -\& uint64_t timestamp, -\& const char *extensions_base64, -\& const char *signature_base64); -\& -\& void SCT_free(SCT *sct); -\& void SCT_LIST_free(STACK_OF(SCT) *a); -\& -\& sct_version_t SCT_get_version(const SCT *sct); -\& int SCT_set_version(SCT *sct, sct_version_t version); -\& -\& ct_log_entry_type_t SCT_get_log_entry_type(const SCT *sct); -\& int SCT_set_log_entry_type(SCT *sct, ct_log_entry_type_t entry_type); -\& -\& size_t SCT_get0_log_id(const SCT *sct, unsigned char **log_id); -\& int SCT_set0_log_id(SCT *sct, unsigned char *log_id, size_t log_id_len); -\& int SCT_set1_log_id(SCT *sct, const unsigned char *log_id, size_t log_id_len); -\& -\& uint64_t SCT_get_timestamp(const SCT *sct); -\& void SCT_set_timestamp(SCT *sct, uint64_t timestamp); -\& -\& int SCT_get_signature_nid(const SCT *sct); -\& int SCT_set_signature_nid(SCT *sct, int nid); -\& -\& size_t SCT_get0_signature(const SCT *sct, unsigned char **sig); -\& void SCT_set0_signature(SCT *sct, unsigned char *sig, size_t sig_len); -\& int SCT_set1_signature(SCT *sct, const unsigned char *sig, size_t sig_len); -\& -\& size_t SCT_get0_extensions(const SCT *sct, unsigned char **ext); -\& void SCT_set0_extensions(SCT *sct, unsigned char *ext, size_t ext_len); -\& int SCT_set1_extensions(SCT *sct, const unsigned char *ext, size_t ext_len); -\& -\& sct_source_t SCT_get_source(const SCT *sct); -\& int SCT_set_source(SCT *sct, sct_source_t source); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Signed Certificate Timestamps (SCTs) are defined by \s-1RFC 6962,\s0 Section 3.2. -They constitute a promise by a Certificate Transparency (\s-1CT\s0) log to publicly -record a certificate. By cryptographically verifying that a log did indeed issue -an \s-1SCT,\s0 some confidence can be gained that the certificate is publicly known. -.PP -An internal representation of an \s-1SCT\s0 can be created in one of two ways. -The first option is to create a blank \s-1SCT,\s0 using \fBSCT_new()\fR, and then populate -it using: -.IP "\(bu" 2 -\&\fBSCT_set_version()\fR to set the \s-1SCT\s0 version. -.Sp -Only \s-1SCT_VERSION_V1\s0 is currently supported. -.IP "\(bu" 2 -\&\fBSCT_set_log_entry_type()\fR to set the type of certificate the \s-1SCT\s0 was issued for: -.Sp -\&\fB\s-1CT_LOG_ENTRY_TYPE_X509\s0\fR for a normal certificate. -\&\fB\s-1CT_LOG_ENTRY_TYPE_PRECERT\s0\fR for a pre-certificate. -.IP "\(bu" 2 -\&\fBSCT_set0_log_id()\fR or \fBSCT_set1_log_id()\fR to set the LogID of the \s-1CT\s0 log that the \s-1SCT\s0 came from. -.Sp -The former takes ownership, whereas the latter makes a copy. -See \s-1RFC 6962,\s0 Section 3.2 for the definition of LogID. -.IP "\(bu" 2 -\&\fBSCT_set_timestamp()\fR to set the time the \s-1SCT\s0 was issued (time in milliseconds -since the Unix Epoch). -.IP "\(bu" 2 -\&\fBSCT_set_signature_nid()\fR to set the \s-1NID\s0 of the signature. -.IP "\(bu" 2 -\&\fBSCT_set0_signature()\fR or \fBSCT_set1_signature()\fR to set the raw signature value. -.Sp -The former takes ownership, whereas the latter makes a copy. -.IP "\(bu" 2 -\&\fBSCT_set0_extensions()\fR or \fBSCT_set1_extensions\fR to provide \s-1SCT\s0 extensions. -.Sp -The former takes ownership, whereas the latter makes a copy. -.PP -Alternatively, the \s-1SCT\s0 can be pre-populated from the following data using -\&\fBSCT_new_from_base64()\fR: -.IP "\(bu" 2 -The \s-1SCT\s0 version (only \s-1SCT_VERSION_V1\s0 is currently supported). -.IP "\(bu" 2 -The LogID (see \s-1RFC 6962,\s0 Section 3.2), base64 encoded. -.IP "\(bu" 2 -The type of certificate the \s-1SCT\s0 was issued for: -\&\fB\s-1CT_LOG_ENTRY_TYPE_X509\s0\fR for a normal certificate. -\&\fB\s-1CT_LOG_ENTRY_TYPE_PRECERT\s0\fR for a pre-certificate. -.IP "\(bu" 2 -The time that the \s-1SCT\s0 was issued (time in milliseconds since the Unix Epoch). -.IP "\(bu" 2 -The \s-1SCT\s0 extensions, base64 encoded. -.IP "\(bu" 2 -The \s-1SCT\s0 signature, base64 encoded. -.PP -\&\fBSCT_set_source()\fR can be used to record where the \s-1SCT\s0 was found -(\s-1TLS\s0 extension, X.509 certificate extension or \s-1OCSP\s0 response). This is not -required for verifying the \s-1SCT.\s0 -.PP -\&\fBSCT_free()\fR frees the specified \s-1SCT.\s0 -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBSCT_LIST_free()\fR frees the specified stack of SCTs. -If the argument is \s-1NULL,\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -Some of the setters return int, instead of void. These will all return 1 on -success, 0 on failure. They will not make changes on failure. -.PP -All of the setters will reset the validation status of the \s-1SCT\s0 to -\&\s-1SCT_VALIDATION_STATUS_NOT_SET\s0 (see \fBSCT_validate\fR\|(3)). -.PP -\&\fBSCT_set_source()\fR will call \fBSCT_set_log_entry_type()\fR if the type of -certificate the \s-1SCT\s0 was issued for can be inferred from where the \s-1SCT\s0 was found. -For example, an \s-1SCT\s0 found in an X.509 extension must have been issued for a pre\- -certificate. -.PP -\&\fBSCT_set_source()\fR will not refuse unknown values. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSCT_set_version()\fR returns 1 if the specified version is supported, 0 otherwise. -.PP -\&\fBSCT_set_log_entry_type()\fR returns 1 if the specified log entry type is supported, 0 otherwise. -.PP -\&\fBSCT_set0_log_id()\fR and \fBSCT_set1_log_id\fR return 1 if the specified LogID is a -valid \s-1SHA\-256\s0 hash, 0 otherwise. Additionally, \fBSCT_set1_log_id\fR returns 0 if -malloc fails. -.PP -\&\fBSCT_set_signature_nid\fR returns 1 if the specified \s-1NID\s0 is supported, 0 otherwise. -.PP -\&\fBSCT_set1_extensions\fR and \fBSCT_set1_signature\fR return 1 if the supplied buffer -is copied successfully, 0 otherwise (i.e. if malloc fails). -.PP -\&\fBSCT_set_source\fR returns 1 on success, 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7), -\&\fBSCT_validate\fR\|(3), -\&\fBOBJ_nid2obj\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SCT_new_from_base64.3ossl b/openssl-install/share/man/man3/SCT_new_from_base64.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_new_from_base64.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_print.3ossl b/openssl-install/share/man/man3/SCT_print.3ossl deleted file mode 100644 index 4df9bd32..00000000 --- a/openssl-install/share/man/man3/SCT_print.3ossl +++ /dev/null @@ -1,188 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SCT_PRINT 3ossl" -.TH SCT_PRINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SCT_print, SCT_LIST_print, SCT_validation_status_string \- -Prints Signed Certificate Timestamps in a human\-readable way -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SCT_print(const SCT *sct, BIO *out, int indent, const CTLOG_STORE *logs); -\& void SCT_LIST_print(const STACK_OF(SCT) *sct_list, BIO *out, int indent, -\& const char *separator, const CTLOG_STORE *logs); -\& const char *SCT_validation_status_string(const SCT *sct); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSCT_print()\fR prints a single Signed Certificate Timestamp (\s-1SCT\s0) to a \fB\s-1BIO\s0\fR in -a human-readable format. \fBSCT_LIST_print()\fR prints an entire list of SCTs in a -similar way. A separator can be specified to delimit each \s-1SCT\s0 in the output. -.PP -The output can be indented by a specified number of spaces. If a \fB\s-1CTLOG_STORE\s0\fR -is provided, it will be used to print the description of the \s-1CT\s0 log that issued -each \s-1SCT\s0 (if that log is in the \s-1CTLOG_STORE\s0). Alternatively, \s-1NULL\s0 can be passed -as the \s-1CTLOG_STORE\s0 parameter to disable this feature. -.PP -\&\fBSCT_validation_status_string()\fR will return the validation status of an \s-1SCT\s0 as -a human-readable string. Call \fBSCT_validate()\fR or \fBSCT_LIST_validate()\fR -beforehand in order to set the validation status of an \s-1SCT\s0 first. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSCT_validation_status_string()\fR returns a NUL-terminated string representing -the validation status of an \fB\s-1SCT\s0\fR object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7), -\&\fBbio\fR\|(7), -\&\fBCTLOG_STORE_new\fR\|(3), -\&\fBSCT_validate\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SCT_set0_extensions.3ossl b/openssl-install/share/man/man3/SCT_set0_extensions.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set0_log_id.3ossl b/openssl-install/share/man/man3/SCT_set0_log_id.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set0_log_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set0_signature.3ossl b/openssl-install/share/man/man3/SCT_set0_signature.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set1_extensions.3ossl b/openssl-install/share/man/man3/SCT_set1_extensions.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set1_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set1_log_id.3ossl b/openssl-install/share/man/man3/SCT_set1_log_id.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set1_log_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set1_signature.3ossl b/openssl-install/share/man/man3/SCT_set1_signature.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set1_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set_log_entry_type.3ossl b/openssl-install/share/man/man3/SCT_set_log_entry_type.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set_log_entry_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set_signature_nid.3ossl b/openssl-install/share/man/man3/SCT_set_signature_nid.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set_signature_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set_source.3ossl b/openssl-install/share/man/man3/SCT_set_source.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set_source.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set_timestamp.3ossl b/openssl-install/share/man/man3/SCT_set_timestamp.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set_timestamp.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_set_version.3ossl b/openssl-install/share/man/man3/SCT_set_version.3ossl deleted file mode 120000 index d7e6f2c2..00000000 --- a/openssl-install/share/man/man3/SCT_set_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SCT_validate.3ossl b/openssl-install/share/man/man3/SCT_validate.3ossl deleted file mode 100644 index ea319298..00000000 --- a/openssl-install/share/man/man3/SCT_validate.3ossl +++ /dev/null @@ -1,224 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SCT_VALIDATE 3ossl" -.TH SCT_VALIDATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SCT_validate, SCT_LIST_validate, SCT_get_validation_status \- -checks Signed Certificate Timestamps (SCTs) are valid -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef enum { -\& SCT_VALIDATION_STATUS_NOT_SET, -\& SCT_VALIDATION_STATUS_UNKNOWN_LOG, -\& SCT_VALIDATION_STATUS_VALID, -\& SCT_VALIDATION_STATUS_INVALID, -\& SCT_VALIDATION_STATUS_UNVERIFIED, -\& SCT_VALIDATION_STATUS_UNKNOWN_VERSION -\& } sct_validation_status_t; -\& -\& int SCT_validate(SCT *sct, const CT_POLICY_EVAL_CTX *ctx); -\& int SCT_LIST_validate(const STACK_OF(SCT) *scts, CT_POLICY_EVAL_CTX *ctx); -\& sct_validation_status_t SCT_get_validation_status(const SCT *sct); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSCT_validate()\fR will check that an \s-1SCT\s0 is valid and verify its signature. -\&\fBSCT_LIST_validate()\fR performs the same checks on an entire stack of SCTs. -The result of the validation checks can be obtained by passing the \s-1SCT\s0 to -\&\fBSCT_get_validation_status()\fR. -.PP -A \s-1CT_POLICY_EVAL_CTX\s0 must be provided that specifies: -.IP "\(bu" 2 -The certificate the \s-1SCT\s0 was issued for. -.Sp -Failure to provide the certificate will result in the validation status being -\&\s-1SCT_VALIDATION_STATUS_UNVERIFIED.\s0 -.IP "\(bu" 2 -The issuer of that certificate. -.Sp -This is only required if the \s-1SCT\s0 was issued for a pre-certificate -(see \s-1RFC 6962\s0). If it is required but not provided, the validation status will -be \s-1SCT_VALIDATION_STATUS_UNVERIFIED.\s0 -.IP "\(bu" 2 -A \s-1CTLOG_STORE\s0 that contains the \s-1CT\s0 log that issued this \s-1SCT.\s0 -.Sp -If the \s-1SCT\s0 was issued by a log that is not in this \s-1CTLOG_STORE,\s0 the validation -status will be \s-1SCT_VALIDATION_STATUS_UNKNOWN_LOG.\s0 -.PP -If the \s-1SCT\s0 is of an unsupported version (only v1 is currently supported), the -validation status will be \s-1SCT_VALIDATION_STATUS_UNKNOWN_VERSION.\s0 -.PP -If the \s-1SCT\s0's signature is incorrect, its timestamp is in the future (relative to -the time in \s-1CT_POLICY_EVAL_CTX\s0), or if it is otherwise invalid, the validation -status will be \s-1SCT_VALIDATION_STATUS_INVALID.\s0 -.PP -If all checks pass, the validation status will be \s-1SCT_VALIDATION_STATUS_VALID.\s0 -.SH "NOTES" -.IX Header "NOTES" -A return value of 0 from \fBSCT_LIST_validate()\fR should not be interpreted as a -failure. At a minimum, only one valid \s-1SCT\s0 may provide sufficient confidence -that a certificate has been publicly logged. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSCT_validate()\fR returns a negative integer if an internal error occurs, 0 if the -\&\s-1SCT\s0 fails validation, or 1 if the \s-1SCT\s0 passes validation. -.PP -\&\fBSCT_LIST_validate()\fR returns a negative integer if an internal error occurs, 0 -if any of SCTs fails validation, or 1 if they all pass validation. -.PP -\&\fBSCT_get_validation_status()\fR returns the validation status of the \s-1SCT.\s0 -If \fBSCT_validate()\fR or \fBSCT_LIST_validate()\fR have not been passed that \s-1SCT,\s0 the -returned value will be \s-1SCT_VALIDATION_STATUS_NOT_SET.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SCT_validation_status_string.3ossl b/openssl-install/share/man/man3/SCT_validation_status_string.3ossl deleted file mode 120000 index f866db60..00000000 --- a/openssl-install/share/man/man3/SCT_validation_status_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -SCT_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA1.3ossl b/openssl-install/share/man/man3/SHA1.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA1.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA1_Final.3ossl b/openssl-install/share/man/man3/SHA1_Final.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA1_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA1_Init.3ossl b/openssl-install/share/man/man3/SHA1_Init.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA1_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA1_Update.3ossl b/openssl-install/share/man/man3/SHA1_Update.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA1_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA224.3ossl b/openssl-install/share/man/man3/SHA224.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA224.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA224_Final.3ossl b/openssl-install/share/man/man3/SHA224_Final.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA224_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA224_Init.3ossl b/openssl-install/share/man/man3/SHA224_Init.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA224_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA224_Update.3ossl b/openssl-install/share/man/man3/SHA224_Update.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA224_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA256.3ossl b/openssl-install/share/man/man3/SHA256.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA256.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA256_Final.3ossl b/openssl-install/share/man/man3/SHA256_Final.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA256_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA256_Init.3ossl b/openssl-install/share/man/man3/SHA256_Init.3ossl deleted file mode 100644 index e7674342..00000000 --- a/openssl-install/share/man/man3/SHA256_Init.3ossl +++ /dev/null @@ -1,249 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SHA256_INIT 3ossl" -.TH SHA256_INIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SHA1, SHA1_Init, SHA1_Update, SHA1_Final, SHA224, SHA224_Init, SHA224_Update, -SHA224_Final, SHA256, SHA256_Init, SHA256_Update, SHA256_Final, SHA384, -SHA384_Init, SHA384_Update, SHA384_Final, SHA512, SHA512_Init, SHA512_Update, -SHA512_Final \- Secure Hash Algorithm -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned char *SHA1(const unsigned char *data, size_t count, unsigned char *md_buf); -\& unsigned char *SHA224(const unsigned char *data, size_t count, unsigned char *md_buf); -\& unsigned char *SHA256(const unsigned char *data, size_t count, unsigned char *md_buf); -\& unsigned char *SHA384(const unsigned char *data, size_t count, unsigned char *md_buf); -\& unsigned char *SHA512(const unsigned char *data, size_t count, unsigned char *md_buf); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& int SHA1_Init(SHA_CTX *c); -\& int SHA1_Update(SHA_CTX *c, const void *data, size_t len); -\& int SHA1_Final(unsigned char *md, SHA_CTX *c); -\& -\& int SHA224_Init(SHA256_CTX *c); -\& int SHA224_Update(SHA256_CTX *c, const void *data, size_t len); -\& int SHA224_Final(unsigned char *md, SHA256_CTX *c); -\& -\& int SHA256_Init(SHA256_CTX *c); -\& int SHA256_Update(SHA256_CTX *c, const void *data, size_t len); -\& int SHA256_Final(unsigned char *md, SHA256_CTX *c); -\& -\& int SHA384_Init(SHA512_CTX *c); -\& int SHA384_Update(SHA512_CTX *c, const void *data, size_t len); -\& int SHA384_Final(unsigned char *md, SHA512_CTX *c); -\& -\& int SHA512_Init(SHA512_CTX *c); -\& int SHA512_Update(SHA512_CTX *c, const void *data, size_t len); -\& int SHA512_Final(unsigned char *md, SHA512_CTX *c); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page -except for \s-1\fBSHA1\s0()\fR, \s-1\fBSHA224\s0()\fR, \s-1\fBSHA256\s0()\fR, \s-1\fBSHA384\s0()\fR and \s-1\fBSHA512\s0()\fR are deprecated. -Applications should instead use \fBEVP_DigestInit_ex\fR\|(3), \fBEVP_DigestUpdate\fR\|(3) -and \fBEVP_DigestFinal_ex\fR\|(3), or the quick one-shot function \fBEVP_Q_digest\fR\|(3). -\&\s-1\fBSHA1\s0()\fR, \s-1\fBSHA224\s0()\fR, \s-1\fBSHA256\s0()\fR, \s-1\fBSHA384\s0()\fR, and \s-1\fBSHA256\s0()\fR -can continue to be used. They can also be replaced by, e.g., -.PP -.Vb 1 -\& (EVP_Q_digest(d, n, md, NULL, NULL, "SHA256", NULL) ? md : NULL) -.Ve -.PP -\&\s-1SHA\-1\s0 (Secure Hash Algorithm) is a cryptographic hash function with a -160 bit output. -.PP -\&\s-1\fBSHA1\s0()\fR computes the \s-1SHA\-1\s0 message digest of the \fBn\fR -bytes at \fBd\fR and places it in \fBmd\fR (which must have space for -\&\s-1SHA_DIGEST_LENGTH\s0 == 20 bytes of output). If \fBmd\fR is \s-1NULL,\s0 the digest -is placed in a static array. Note: setting \fBmd\fR to \s-1NULL\s0 is \fBnot thread safe\fR. -.PP -The following functions may be used if the message is not completely -stored in memory: -.PP -\&\fBSHA1_Init()\fR initializes a \fB\s-1SHA_CTX\s0\fR structure. -.PP -\&\fBSHA1_Update()\fR can be called repeatedly with chunks of the message to -be hashed (\fBlen\fR bytes at \fBdata\fR). -.PP -\&\fBSHA1_Final()\fR places the message digest in \fBmd\fR, which must have space -for \s-1SHA_DIGEST_LENGTH\s0 == 20 bytes of output, and erases the \fB\s-1SHA_CTX\s0\fR. -.PP -The \s-1SHA224, SHA256, SHA384\s0 and \s-1SHA512\s0 families of functions operate in the -same way as for the \s-1SHA1\s0 functions. Note that \s-1SHA224\s0 and \s-1SHA256\s0 use a -\&\fB\s-1SHA256_CTX\s0\fR object instead of \fB\s-1SHA_CTX\s0\fR. \s-1SHA384\s0 and \s-1SHA512\s0 use \fB\s-1SHA512_CTX\s0\fR. -The buffer \fBmd\fR must have space for the output from the \s-1SHA\s0 variant being used -(defined by \s-1SHA224_DIGEST_LENGTH, SHA256_DIGEST_LENGTH, SHA384_DIGEST_LENGTH\s0 and -\&\s-1SHA512_DIGEST_LENGTH\s0). Also note that, as for the \s-1\fBSHA1\s0()\fR function above, the -\&\s-1\fBSHA224\s0()\fR, \s-1\fBSHA256\s0()\fR, \s-1\fBSHA384\s0()\fR and \s-1\fBSHA512\s0()\fR functions are not thread safe if -\&\fBmd\fR is \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1\fBSHA1\s0()\fR, \s-1\fBSHA224\s0()\fR, \s-1\fBSHA256\s0()\fR, \s-1\fBSHA384\s0()\fR and \s-1\fBSHA512\s0()\fR return a pointer to the hash -value. -.PP -\&\fBSHA1_Init()\fR, \fBSHA1_Update()\fR and \fBSHA1_Final()\fR and equivalent \s-1SHA224, SHA256, -SHA384\s0 and \s-1SHA512\s0 functions return 1 for success, 0 otherwise. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1US\s0 Federal Information Processing Standard \s-1FIPS PUB 180\-4\s0 (Secure Hash -Standard), -\&\s-1ANSI X9.30\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_Q_digest\fR\|(3), -\&\fBEVP_DigestInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -All of these functions except SHA*() were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SHA256_Update.3ossl b/openssl-install/share/man/man3/SHA256_Update.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA256_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA384.3ossl b/openssl-install/share/man/man3/SHA384.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA384.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA384_Final.3ossl b/openssl-install/share/man/man3/SHA384_Final.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA384_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA384_Init.3ossl b/openssl-install/share/man/man3/SHA384_Init.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA384_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA384_Update.3ossl b/openssl-install/share/man/man3/SHA384_Update.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA384_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA512.3ossl b/openssl-install/share/man/man3/SHA512.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA512.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA512_Final.3ossl b/openssl-install/share/man/man3/SHA512_Final.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA512_Final.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA512_Init.3ossl b/openssl-install/share/man/man3/SHA512_Init.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA512_Init.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SHA512_Update.3ossl b/openssl-install/share/man/man3/SHA512_Update.3ossl deleted file mode 120000 index 0efba531..00000000 --- a/openssl-install/share/man/man3/SHA512_Update.3ossl +++ /dev/null @@ -1 +0,0 @@ -SHA256_Init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SMIME_read_ASN1.3ossl b/openssl-install/share/man/man3/SMIME_read_ASN1.3ossl deleted file mode 100644 index 07bb3db6..00000000 --- a/openssl-install/share/man/man3/SMIME_read_ASN1.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SMIME_READ_ASN1 3ossl" -.TH SMIME_READ_ASN1 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SMIME_read_ASN1_ex, SMIME_read_ASN1 -\&\- parse S/MIME message -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_VALUE *SMIME_read_ASN1_ex(BIO *in, int flags, BIO **bcont, -\& const ASN1_ITEM *it, ASN1_VALUE **x, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& ASN1_VALUE *SMIME_read_ASN1(BIO *in, BIO **bcont, const ASN1_ITEM *it); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSMIME_read_ASN1_ex()\fR parses a message in S/MIME format. -.PP -\&\fIin\fR is a \s-1BIO\s0 to read the message from. -If the \fIflags\fR argument contains \fB\s-1CMS_BINARY\s0\fR then the input is assumed to be -in binary format and is not translated to canonical form. -If in addition \fB\s-1SMIME_ASCIICRLF\s0\fR is set then the binary input is assumed -to be followed by \fB\s-1CR\s0\fR and \fB\s-1LF\s0\fR characters, else only by an \fB\s-1LF\s0\fR character. -\&\fIx\fR can be used to optionally supply -a previously created \fIit\fR \s-1ASN1_VALUE\s0 object (such as CMS_ContentInfo or \s-1PKCS7\s0), -it can be set to \s-1NULL.\s0 Valid values that can be used by \s-1ASN.1\s0 structure \fIit\fR -are ASN1_ITEM_rptr(\s-1PKCS7\s0) or ASN1_ITEM_rptr(CMS_ContentInfo). Any algorithm -fetches that occur during the operation will use the \fB\s-1OSSL_LIB_CTX\s0\fR supplied in -the \fIlibctx\fR parameter, and use the property query string \fIpropq\fR See -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for further details about algorithm fetching. -.PP -If cleartext signing is used then the content is saved in a memory bio which is -written to \fI*bcont\fR, otherwise \fI*bcont\fR is set to \s-1NULL.\s0 -.PP -The parsed \s-1ASN1_VALUE\s0 structure is returned or \s-1NULL\s0 if an error occurred. -.PP -\&\fBSMIME_read_ASN1()\fR is similar to \fBSMIME_read_ASN1_ex()\fR but sets the value of \fIx\fR -to \s-1NULL\s0 and the value of \fIflags\fR to 0. -.SH "NOTES" -.IX Header "NOTES" -The higher level functions \fBSMIME_read_CMS_ex\fR\|(3) and -\&\fBSMIME_read_PKCS7_ex\fR\|(3) should be used instead of \fBSMIME_read_ASN1_ex()\fR. -.PP -To support future functionality if \fIbcont\fR is not \s-1NULL\s0 \fI*bcont\fR should be -initialized to \s-1NULL.\s0 -.SH "BUGS" -.IX Header "BUGS" -The \s-1MIME\s0 parser used by \fBSMIME_read_ASN1_ex()\fR is somewhat primitive. While it will -handle most S/MIME messages more complex compound formats may not work. -.PP -The use of a memory \s-1BIO\s0 to hold the signed content limits the size of message -which can be processed due to memory restraints: a streaming single pass option -should be available. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSMIME_read_ASN1_ex()\fR and \fBSMIME_read_ASN1()\fR return a valid \fB\s-1ASN1_VALUE\s0\fR -structure or \fB\s-1NULL\s0\fR if an error occurred. The error can be obtained from -\&\fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBSMIME_read_CMS_ex\fR\|(3), -\&\fBSMIME_read_PKCS7_ex\fR\|(3), -\&\fBSMIME_write_ASN1\fR\|(3), -\&\fBSMIME_write_ASN1_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBSMIME_read_ASN1_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SMIME_read_ASN1_ex.3ossl b/openssl-install/share/man/man3/SMIME_read_ASN1_ex.3ossl deleted file mode 120000 index ba27d7fb..00000000 --- a/openssl-install/share/man/man3/SMIME_read_ASN1_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SMIME_read_ASN1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SMIME_read_CMS.3ossl b/openssl-install/share/man/man3/SMIME_read_CMS.3ossl deleted file mode 100644 index 377bebde..00000000 --- a/openssl-install/share/man/man3/SMIME_read_CMS.3ossl +++ /dev/null @@ -1,223 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SMIME_READ_CMS 3ossl" -.TH SMIME_READ_CMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SMIME_read_CMS_ex, SMIME_read_CMS \- parse S/MIME message -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& CMS_ContentInfo *SMIME_read_CMS_ex(BIO *bio, int flags, BIO **bcont, -\& CMS_ContentInfo **cms); -\& CMS_ContentInfo *SMIME_read_CMS(BIO *in, BIO **bcont); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSMIME_read_CMS()\fR parses a message in S/MIME format. -.PP -\&\fBin\fR is a \s-1BIO\s0 to read the message from. -.PP -If cleartext signing is used then the content is saved in a memory bio which is -written to \fB*bcont\fR, otherwise \fB*bcont\fR is set to \s-1NULL.\s0 -.PP -The parsed CMS_ContentInfo structure is returned or \s-1NULL\s0 if an -error occurred. -.PP -\&\fBSMIME_read_CMS_ex()\fR is similar to \fBSMIME_read_CMS()\fR but optionally a previously -created \fIcms\fR CMS_ContentInfo object can be supplied as well as some \fIflags\fR. -To create a \fIcms\fR object use \fBCMS_ContentInfo_new_ex\fR\|(3). -If the \fIflags\fR argument contains \fB\s-1CMS_BINARY\s0\fR then the input is assumed to be -in binary format and is not translated to canonical form. -If in addition \fB\s-1SMIME_ASCIICRLF\s0\fR is set then the binary input is assumed -to be followed by \fB\s-1CR\s0\fR and \fB\s-1LF\s0\fR characters, else only by an \fB\s-1LF\s0\fR character. -If \fIflags\fR is 0 and \fIcms\fR is \s-1NULL\s0 then it is identical to \fBSMIME_read_CMS()\fR. -.SH "NOTES" -.IX Header "NOTES" -If \fB*bcont\fR is not \s-1NULL\s0 then the message is clear text signed. \fB*bcont\fR can -then be passed to \fBCMS_verify()\fR with the \fB\s-1CMS_DETACHED\s0\fR flag set. -.PP -Otherwise the type of the returned structure can be determined -using \fBCMS_get0_type()\fR. -.PP -To support future functionality if \fBbcont\fR is not \s-1NULL\s0 \fB*bcont\fR should be -initialized to \s-1NULL.\s0 For example: -.PP -.Vb 2 -\& BIO *cont = NULL; -\& CMS_ContentInfo *cms; -\& -\& cms = SMIME_read_CMS(in, &cont); -.Ve -.SH "BUGS" -.IX Header "BUGS" -The \s-1MIME\s0 parser used by \fBSMIME_read_CMS()\fR is somewhat primitive. While it will -handle most S/MIME messages more complex compound formats may not work. -.PP -The parser assumes that the CMS_ContentInfo structure is always base64 encoded -and will not handle the case where it is in binary format or uses quoted -printable format. -.PP -The use of a memory \s-1BIO\s0 to hold the signed content limits the size of message -which can be processed due to memory restraints: a streaming single pass option -should be available. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSMIME_read_CMS_ex()\fR and \fBSMIME_read_CMS()\fR return a valid \fBCMS_ContentInfo\fR -structure or \fB\s-1NULL\s0\fR if an error occurred. The error can be obtained from -\&\fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBCMS_sign\fR\|(3), -\&\fBCMS_verify\fR\|(3), -\&\fBCMS_encrypt\fR\|(3), -\&\fBCMS_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBSMIME_read_CMS_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SMIME_read_CMS_ex.3ossl b/openssl-install/share/man/man3/SMIME_read_CMS_ex.3ossl deleted file mode 120000 index cb4b7297..00000000 --- a/openssl-install/share/man/man3/SMIME_read_CMS_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SMIME_read_CMS.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SMIME_read_PKCS7.3ossl b/openssl-install/share/man/man3/SMIME_read_PKCS7.3ossl deleted file mode 100644 index 1fca7cf8..00000000 --- a/openssl-install/share/man/man3/SMIME_read_PKCS7.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SMIME_READ_PKCS7 3ossl" -.TH SMIME_READ_PKCS7 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SMIME_read_PKCS7_ex, SMIME_read_PKCS7 \- parse S/MIME message -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& PKCS7 *SMIME_read_PKCS7_ex(BIO *bio, BIO **bcont, PKCS7 **p7); -\& PKCS7 *SMIME_read_PKCS7(BIO *in, BIO **bcont); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSMIME_read_PKCS7()\fR parses a message in S/MIME format. -.PP -\&\fBin\fR is a \s-1BIO\s0 to read the message from. -.PP -If cleartext signing is used then the content is saved in -a memory bio which is written to \fB*bcont\fR, otherwise -\&\fB*bcont\fR is set to \fB\s-1NULL\s0\fR. -.PP -The parsed PKCS#7 structure is returned or \fB\s-1NULL\s0\fR if an -error occurred. -.PP -\&\fBSMIME_read_PKCS7_ex()\fR is similar to \fBSMIME_read_PKCS7()\fR but can optionally supply -a previously created \fIp7\fR PKCS#7 object. If \fIp7\fR is \s-1NULL\s0 then it is identical -to \fBSMIME_read_PKCS7()\fR. -To create a \fIp7\fR object use \fBPKCS7_new_ex\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -If \fB*bcont\fR is not \fB\s-1NULL\s0\fR then the message is clear text -signed. \fB*bcont\fR can then be passed to \fBPKCS7_verify()\fR with -the \fB\s-1PKCS7_DETACHED\s0\fR flag set. -.PP -Otherwise the type of the returned structure can be determined -using \fBPKCS7_type_is_enveloped()\fR, etc. -.PP -To support future functionality if \fBbcont\fR is not \fB\s-1NULL\s0\fR -\&\fB*bcont\fR should be initialized to \fB\s-1NULL\s0\fR. For example: -.PP -.Vb 2 -\& BIO *cont = NULL; -\& PKCS7 *p7; -\& -\& p7 = SMIME_read_PKCS7(in, &cont); -.Ve -.SH "BUGS" -.IX Header "BUGS" -The \s-1MIME\s0 parser used by \fBSMIME_read_PKCS7()\fR is somewhat primitive. -While it will handle most S/MIME messages more complex compound -formats may not work. -.PP -The parser assumes that the \s-1PKCS7\s0 structure is always base64 -encoded and will not handle the case where it is in binary format -or uses quoted printable format. -.PP -The use of a memory \s-1BIO\s0 to hold the signed content limits the size -of message which can be processed due to memory restraints: a -streaming single pass option should be available. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSMIME_read_PKCS7_ex()\fR and \fBSMIME_read_PKCS7()\fR return a valid \fB\s-1PKCS7\s0\fR structure -or \fB\s-1NULL\s0\fR if an error occurred. The error can be obtained from \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBSMIME_read_PKCS7\fR\|(3), \fBPKCS7_sign\fR\|(3), -\&\fBPKCS7_verify\fR\|(3), \fBPKCS7_encrypt\fR\|(3) -\&\fBPKCS7_decrypt\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBSMIME_read_PKCS7_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SMIME_read_PKCS7_ex.3ossl b/openssl-install/share/man/man3/SMIME_read_PKCS7_ex.3ossl deleted file mode 120000 index 66627db8..00000000 --- a/openssl-install/share/man/man3/SMIME_read_PKCS7_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SMIME_read_PKCS7.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SMIME_write_ASN1.3ossl b/openssl-install/share/man/man3/SMIME_write_ASN1.3ossl deleted file mode 100644 index 8618be14..00000000 --- a/openssl-install/share/man/man3/SMIME_write_ASN1.3ossl +++ /dev/null @@ -1,213 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SMIME_WRITE_ASN1 3ossl" -.TH SMIME_WRITE_ASN1 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SMIME_write_ASN1_ex, SMIME_write_ASN1 -\&\- convert structure to S/MIME format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SMIME_write_ASN1_ex(BIO *out, ASN1_VALUE *val, BIO *data, int flags, -\& int ctype_nid, int econt_nid, -\& STACK_OF(X509_ALGOR) *mdalgs, const ASN1_ITEM *it, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& -\& int SMIME_write_ASN1(BIO *out, -\& ASN1_VALUE *val, BIO *data, int flags, int ctype_nid, int econt_nid, -\& STACK_OF(X509_ALGOR) *mdalgs, const ASN1_ITEM *it); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSMIME_write_ASN1_ex()\fR adds the appropriate \s-1MIME\s0 headers to an object -structure to produce an S/MIME message. -.PP -\&\fIout\fR is the \s-1BIO\s0 to write the data to. \fIvalue\fR is the appropriate \s-1ASN1_VALUE\s0 -structure (either CMS_ContentInfo or \s-1PKCS7\s0). If streaming is enabled then the -content must be supplied via \fIdata\fR. -\&\fIflags\fR is an optional set of flags. \fIctype_nid\fR is the \s-1NID\s0 of the content -type, \fIecont_nid\fR is the \s-1NID\s0 of the embedded content type and \fImdalgs\fR is a -list of signed data digestAlgorithms. Valid values that can be used by the -\&\s-1ASN.1\s0 structure \fIit\fR are ASN1_ITEM_rptr(\s-1PKCS7\s0) or ASN1_ITEM_rptr(CMS_ContentInfo). -The library context \fIlibctx\fR and the property query \fIpropq\fR are used when -retrieving algorithms from providers. -.SH "NOTES" -.IX Header "NOTES" -The higher level functions \fBSMIME_write_CMS\fR\|(3) and -\&\fBSMIME_write_PKCS7\fR\|(3) should be used instead of \fBSMIME_write_ASN1()\fR. -.PP -The following flags can be passed in the \fBflags\fR parameter. -.PP -If \fB\s-1CMS_DETACHED\s0\fR is set then cleartext signing will be used, this option only -makes sense for SignedData where \fB\s-1CMS_DETACHED\s0\fR is also set when the \fBsign()\fR -method is called. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are added to -the content, this only makes sense if \fB\s-1CMS_DETACHED\s0\fR is also set. -.PP -If the \fB\s-1CMS_STREAM\s0\fR flag is set streaming is performed. This flag should only -be set if \fB\s-1CMS_STREAM\s0\fR was also set in the previous call to a CMS_ContentInfo -or \s-1PKCS7\s0 creation function. -.PP -If cleartext signing is being used and \fB\s-1CMS_STREAM\s0\fR not set then the data must -be read twice: once to compute the signature in sign method and once to output -the S/MIME message. -.PP -If streaming is performed the content is output in \s-1BER\s0 format using indefinite -length constructed encoding except in the case of signed data with detached -content where the content is absent and \s-1DER\s0 format is used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSMIME_write_ASN1_ex()\fR and \fBSMIME_write_ASN1()\fR return 1 for success or -0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBSMIME_write_CMS\fR\|(3), -\&\fBSMIME_write_PKCS7\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SMIME_write_ASN1_ex.3ossl b/openssl-install/share/man/man3/SMIME_write_ASN1_ex.3ossl deleted file mode 120000 index 5bb91d66..00000000 --- a/openssl-install/share/man/man3/SMIME_write_ASN1_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SMIME_write_ASN1.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SMIME_write_CMS.3ossl b/openssl-install/share/man/man3/SMIME_write_CMS.3ossl deleted file mode 100644 index b5d8aaac..00000000 --- a/openssl-install/share/man/man3/SMIME_write_CMS.3ossl +++ /dev/null @@ -1,199 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SMIME_WRITE_CMS 3ossl" -.TH SMIME_WRITE_CMS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SMIME_write_CMS \- convert CMS structure to S/MIME format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SMIME_write_CMS(BIO *out, CMS_ContentInfo *cms, BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSMIME_write_CMS()\fR adds the appropriate \s-1MIME\s0 headers to a \s-1CMS\s0 -structure to produce an S/MIME message. -.PP -\&\fBout\fR is the \s-1BIO\s0 to write the data to. \fBcms\fR is the appropriate -\&\fBCMS_ContentInfo\fR structure. If streaming is enabled then the content must be -supplied in the \fBdata\fR argument. \fBflags\fR is an optional set of flags. -.SH "NOTES" -.IX Header "NOTES" -The following flags can be passed in the \fBflags\fR parameter. -.PP -If \fB\s-1CMS_DETACHED\s0\fR is set then cleartext signing will be used, this option only -makes sense for SignedData where \fB\s-1CMS_DETACHED\s0\fR is also set when \fBCMS_sign()\fR is -called. -.PP -If the \fB\s-1CMS_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR are added to -the content, this only makes sense if \fB\s-1CMS_DETACHED\s0\fR is also set. -.PP -If the \fB\s-1CMS_STREAM\s0\fR flag is set streaming is performed. This flag should only -be set if \fB\s-1CMS_STREAM\s0\fR was also set in the previous call to a CMS_ContentInfo -creation function. -.PP -If cleartext signing is being used and \fB\s-1CMS_STREAM\s0\fR not set then the data must -be read twice: once to compute the signature in \fBCMS_sign()\fR and once to output -the S/MIME message. -.PP -If streaming is performed the content is output in \s-1BER\s0 format using indefinite -length constructed encoding except in the case of signed data with detached -content where the content is absent and \s-1DER\s0 format is used. -.SH "BUGS" -.IX Header "BUGS" -\&\fBSMIME_write_CMS()\fR always base64 encodes \s-1CMS\s0 structures, there should be an -option to disable this. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSMIME_write_CMS()\fR returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3), -\&\fBCMS_verify\fR\|(3), \fBCMS_encrypt\fR\|(3) -\&\fBCMS_decrypt\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SMIME_write_PKCS7.3ossl b/openssl-install/share/man/man3/SMIME_write_PKCS7.3ossl deleted file mode 100644 index 62bfe819..00000000 --- a/openssl-install/share/man/man3/SMIME_write_PKCS7.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SMIME_WRITE_PKCS7 3ossl" -.TH SMIME_WRITE_PKCS7 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SMIME_write_PKCS7 \- convert PKCS#7 structure to S/MIME format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SMIME_write_PKCS7(BIO *out, PKCS7 *p7, BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSMIME_write_PKCS7()\fR adds the appropriate \s-1MIME\s0 headers to a PKCS#7 -structure to produce an S/MIME message. -.PP -\&\fBout\fR is the \s-1BIO\s0 to write the data to. \fBp7\fR is the appropriate \fB\s-1PKCS7\s0\fR -structure. If streaming is enabled then the content must be supplied in the -\&\fBdata\fR argument. \fBflags\fR is an optional set of flags. -.SH "NOTES" -.IX Header "NOTES" -The following flags can be passed in the \fBflags\fR parameter. -.PP -If \fB\s-1PKCS7_DETACHED\s0\fR is set then cleartext signing will be used, -this option only makes sense for signedData where \fB\s-1PKCS7_DETACHED\s0\fR -is also set when \fBPKCS7_sign()\fR is also called. -.PP -If the \fB\s-1PKCS7_TEXT\s0\fR flag is set \s-1MIME\s0 headers for type \fBtext/plain\fR -are added to the content, this only makes sense if \fB\s-1PKCS7_DETACHED\s0\fR -is also set. -.PP -If the \fB\s-1PKCS7_STREAM\s0\fR flag is set streaming is performed. This flag should -only be set if \fB\s-1PKCS7_STREAM\s0\fR was also set in the previous call to -\&\fBPKCS7_sign()\fR or \fBPKCS7_encrypt()\fR. -.PP -If cleartext signing is being used and \fB\s-1PKCS7_STREAM\s0\fR not set then -the data must be read twice: once to compute the signature in \fBPKCS7_sign()\fR -and once to output the S/MIME message. -.PP -If streaming is performed the content is output in \s-1BER\s0 format using indefinite -length constructed encoding except in the case of signed data with detached -content where the content is absent and \s-1DER\s0 format is used. -.SH "BUGS" -.IX Header "BUGS" -\&\fBSMIME_write_PKCS7()\fR always base64 encodes PKCS#7 structures, there -should be an option to disable this. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSMIME_write_PKCS7()\fR returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBPKCS7_sign\fR\|(3), -\&\fBPKCS7_verify\fR\|(3), \fBPKCS7_encrypt\fR\|(3) -\&\fBPKCS7_decrypt\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SRP_Calc_A.3ossl b/openssl-install/share/man/man3/SRP_Calc_A.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_A.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_B.3ossl b/openssl-install/share/man/man3/SRP_Calc_B.3ossl deleted file mode 100644 index 60147b7b..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_B.3ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SRP_CALC_B 3ossl" -.TH SRP_CALC_B 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SRP_Calc_server_key, -SRP_Calc_A, -SRP_Calc_B_ex, -SRP_Calc_B, -SRP_Calc_u_ex, -SRP_Calc_u, -SRP_Calc_x_ex, -SRP_Calc_x, -SRP_Calc_client_key_ex, -SRP_Calc_client_key -\&\- SRP authentication primitives -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 7 -\& /* server side .... */ -\& BIGNUM *SRP_Calc_server_key(const BIGNUM *A, const BIGNUM *v, const BIGNUM *u, -\& const BIGNUM *b, const BIGNUM *N); -\& BIGNUM *SRP_Calc_B_ex(const BIGNUM *b, const BIGNUM *N, const BIGNUM *g, -\& const BIGNUM *v, OSSL_LIB_CTX *libctx, const char *propq); -\& BIGNUM *SRP_Calc_B(const BIGNUM *b, const BIGNUM *N, const BIGNUM *g, -\& const BIGNUM *v); -\& -\& BIGNUM *SRP_Calc_u_ex(const BIGNUM *A, const BIGNUM *B, const BIGNUM *N, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& BIGNUM *SRP_Calc_u(const BIGNUM *A, const BIGNUM *B, const BIGNUM *N); -\& -\& /* client side .... */ -\& BIGNUM *SRP_Calc_client_key_ex(const BIGNUM *N, const BIGNUM *B, const BIGNUM *g, -\& const BIGNUM *x, const BIGNUM *a, const BIGNUM *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& BIGNUM *SRP_Calc_client_key(const BIGNUM *N, const BIGNUM *B, const BIGNUM *g, -\& const BIGNUM *x, const BIGNUM *a, const BIGNUM *u); -\& BIGNUM *SRP_Calc_x_ex(const BIGNUM *s, const char *user, const char *pass, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& BIGNUM *SRP_Calc_x(const BIGNUM *s, const char *user, const char *pass); -\& BIGNUM *SRP_Calc_A(const BIGNUM *a, const BIGNUM *N, const BIGNUM *g); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. There are no -available replacement functions at this time. -.PP -The \s-1SRP\s0 functions described on this page are used to calculate various -parameters and keys used by \s-1SRP\s0 as defined in \s-1RFC2945.\s0 The server key and \fIB\fR -and \fIu\fR parameters are used on the server side and are calculated via -\&\fBSRP_Calc_server_key()\fR, \fBSRP_Calc_B_ex()\fR, \fBSRP_Calc_B()\fR, \fBSRP_Calc_u_ex()\fR and -\&\fBSRP_Calc_u()\fR. The client key and \fBx\fR and \fBA\fR parameters are used on the -client side and are calculated via the functions \fBSRP_Calc_client_key_ex()\fR, -\&\fBSRP_Calc_client_key()\fR, \fBSRP_Calc_x_ex()\fR, \fBSRP_Calc_x()\fR and \fBSRP_Calc_A()\fR. See -\&\s-1RFC2945\s0 for a detailed description of their usage and the meaning of the various -\&\s-1BIGNUM\s0 parameters to these functions. -.PP -Most of these functions come in two forms. Those that take a \fIlibctx\fR and -\&\fIpropq\fR parameter, and those that don't. Any cryptogrpahic functions that -are fetched and used during the calculation use the provided \fIlibctx\fR and -\&\fIpropq\fR. See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for more details. The variants -that do not take a \fIlibctx\fR and \fIpropq\fR parameter use the default library -context and property query string. The \fBSRP_Calc_server_key()\fR and \fBSRP_Calc_A()\fR -functions do not have a form that takes \fIlibctx\fR or \fIpropq\fR parameters because -they do not need to fetch any cryptographic algorithms. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return the calculated key or parameter, or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-srp\fR\|(1), -\&\fBSRP_VBASE_new\fR\|(3), -\&\fBSRP_user_pwd_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -SRP_Calc_B_ex, SRP_Calc_u_ex, SRP_Calc_client_key_ex and SRP_Calc_x_ex were -introduced in OpenSSL 3.0. -.PP -All of the other functions were added in OpenSSL 1.0.1. -.PP -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SRP_Calc_B_ex.3ossl b/openssl-install/share/man/man3/SRP_Calc_B_ex.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_B_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_client_key.3ossl b/openssl-install/share/man/man3/SRP_Calc_client_key.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_client_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_client_key_ex.3ossl b/openssl-install/share/man/man3/SRP_Calc_client_key_ex.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_client_key_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_server_key.3ossl b/openssl-install/share/man/man3/SRP_Calc_server_key.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_server_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_u.3ossl b/openssl-install/share/man/man3/SRP_Calc_u.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_u.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_u_ex.3ossl b/openssl-install/share/man/man3/SRP_Calc_u_ex.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_u_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_x.3ossl b/openssl-install/share/man/man3/SRP_Calc_x.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_x.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_Calc_x_ex.3ossl b/openssl-install/share/man/man3/SRP_Calc_x_ex.3ossl deleted file mode 120000 index e92a9ed6..00000000 --- a/openssl-install/share/man/man3/SRP_Calc_x_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_Calc_B.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_VBASE_add0_user.3ossl b/openssl-install/share/man/man3/SRP_VBASE_add0_user.3ossl deleted file mode 120000 index e7fa7c6f..00000000 --- a/openssl-install/share/man/man3/SRP_VBASE_add0_user.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_VBASE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_VBASE_free.3ossl b/openssl-install/share/man/man3/SRP_VBASE_free.3ossl deleted file mode 120000 index e7fa7c6f..00000000 --- a/openssl-install/share/man/man3/SRP_VBASE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_VBASE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_VBASE_get1_by_user.3ossl b/openssl-install/share/man/man3/SRP_VBASE_get1_by_user.3ossl deleted file mode 120000 index e7fa7c6f..00000000 --- a/openssl-install/share/man/man3/SRP_VBASE_get1_by_user.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_VBASE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_VBASE_get_by_user.3ossl b/openssl-install/share/man/man3/SRP_VBASE_get_by_user.3ossl deleted file mode 120000 index e7fa7c6f..00000000 --- a/openssl-install/share/man/man3/SRP_VBASE_get_by_user.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_VBASE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_VBASE_init.3ossl b/openssl-install/share/man/man3/SRP_VBASE_init.3ossl deleted file mode 120000 index e7fa7c6f..00000000 --- a/openssl-install/share/man/man3/SRP_VBASE_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_VBASE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_VBASE_new.3ossl b/openssl-install/share/man/man3/SRP_VBASE_new.3ossl deleted file mode 100644 index 882c9291..00000000 --- a/openssl-install/share/man/man3/SRP_VBASE_new.3ossl +++ /dev/null @@ -1,241 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SRP_VBASE_NEW 3ossl" -.TH SRP_VBASE_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SRP_VBASE_new, -SRP_VBASE_free, -SRP_VBASE_init, -SRP_VBASE_add0_user, -SRP_VBASE_get1_by_user, -SRP_VBASE_get_by_user -\&\- Functions to create and manage a stack of SRP user verifier information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& SRP_VBASE *SRP_VBASE_new(char *seed_key); -\& void SRP_VBASE_free(SRP_VBASE *vb); -\& -\& int SRP_VBASE_init(SRP_VBASE *vb, char *verifier_file); -\& -\& int SRP_VBASE_add0_user(SRP_VBASE *vb, SRP_user_pwd *user_pwd); -\& SRP_user_pwd *SRP_VBASE_get1_by_user(SRP_VBASE *vb, char *username); -\& SRP_user_pwd *SRP_VBASE_get_by_user(SRP_VBASE *vb, char *username); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. There are no -available replacement functions at this time. -.PP -The \fBSRP_VBASE_new()\fR function allocates a structure to store server side \s-1SRP\s0 -verifier information. -If \fBseed_key\fR is not \s-1NULL\s0 a copy is stored and used to generate dummy parameters -for users that are not found by \fBSRP_VBASE_get1_by_user()\fR. This allows the server -to hide the fact that it doesn't have a verifier for a particular username, -as described in section 2.5.1.3 'Unknown \s-1SRP\s0' of \s-1RFC 5054.\s0 -The seed string should contain random \s-1NUL\s0 terminated binary data (therefore -the random data should not contain \s-1NUL\s0 bytes!). -.PP -The \fBSRP_VBASE_free()\fR function frees up the \fBvb\fR structure. -If \fBvb\fR is \s-1NULL,\s0 nothing is done. -.PP -The \fBSRP_VBASE_init()\fR function parses the information in a verifier file and -populates the \fBvb\fR structure. -The verifier file is a text file containing multiple entries, whose format is: -flag base64(verifier) base64(salt) username gNid userinfo(optional) -where the flag can be 'V' (valid) or 'R' (revoked). -Note that the base64 encoding used here is non-standard so it is recommended -to use \fBopenssl\-srp\fR\|(1) to generate this file. -.PP -The \fBSRP_VBASE_add0_user()\fR function adds the \fBuser_pwd\fR verifier information -to the \fBvb\fR structure. See \fBSRP_user_pwd_new\fR\|(3) to create and populate this -record. -The library takes ownership of \fBuser_pwd\fR, it should not be freed by the caller. -.PP -The \fBSRP_VBASE_get1_by_user()\fR function returns the password info for the user -whose username matches \fBusername\fR. It replaces the deprecated -\&\fBSRP_VBASE_get_by_user()\fR. -If no matching user is found but a seed_key and default gN parameters have been -set, dummy authentication information is generated from the seed_key, allowing -the server to hide the fact that it doesn't have a verifier for a particular -username. When using \s-1SRP\s0 as a \s-1TLS\s0 authentication mechanism, this will cause -the handshake to proceed normally but the first client will be rejected with -a \*(L"bad_record_mac\*(R" alert, as if the password was incorrect. -If no matching user is found and the seed_key is not set, \s-1NULL\s0 is returned. -Ownership of the returned pointer is released to the caller, it must be freed -with \fBSRP_user_pwd_free()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSRP_VBASE_init()\fR returns \fB\s-1SRP_NO_ERROR\s0\fR (0) on success and a positive value -on failure. -The error codes are \fB\s-1SRP_ERR_OPEN_FILE\s0\fR if the file could not be opened, -\&\fB\s-1SRP_ERR_VBASE_INCOMPLETE_FILE\s0\fR if the file could not be parsed, -\&\fB\s-1SRP_ERR_MEMORY\s0\fR on memory allocation failure and \fB\s-1SRP_ERR_VBASE_BN_LIB\s0\fR -for invalid decoded parameter values. -.PP -\&\fBSRP_VBASE_add0_user()\fR returns 1 on success and 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-srp\fR\|(1), -\&\fBSRP_create_verifier\fR\|(3), -\&\fBSRP_user_pwd_new\fR\|(3), -\&\fBSSL_CTX_set_srp_password\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSRP_VBASE_add0_user()\fR function was added in OpenSSL 3.0. -.PP -All other functions were added in OpenSSL 1.0.1. -.PP -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SRP_check_known_gN_param.3ossl b/openssl-install/share/man/man3/SRP_check_known_gN_param.3ossl deleted file mode 120000 index 146d8b64..00000000 --- a/openssl-install/share/man/man3/SRP_check_known_gN_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_create_verifier.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_create_verifier.3ossl b/openssl-install/share/man/man3/SRP_create_verifier.3ossl deleted file mode 100644 index 15ebec12..00000000 --- a/openssl-install/share/man/man3/SRP_create_verifier.3ossl +++ /dev/null @@ -1,273 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SRP_CREATE_VERIFIER 3ossl" -.TH SRP_CREATE_VERIFIER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SRP_create_verifier_ex, -SRP_create_verifier, -SRP_create_verifier_BN_ex, -SRP_create_verifier_BN, -SRP_check_known_gN_param, -SRP_get_default_gN -\&\- SRP authentication primitives -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 11 -\& int SRP_create_verifier_BN_ex(const char *user, const char *pass, BIGNUM **salt, -\& BIGNUM **verifier, const BIGNUM *N, -\& const BIGNUM *g, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& char *SRP_create_verifier_BN(const char *user, const char *pass, BIGNUM **salt, -\& BIGNUM **verifier, const BIGNUM *N, const BIGNUM *g); -\& char *SRP_create_verifier_ex(const char *user, const char *pass, char **salt, -\& char **verifier, const char *N, const char *g, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& char *SRP_create_verifier(const char *user, const char *pass, char **salt, -\& char **verifier, const char *N, const char *g); -\& -\& char *SRP_check_known_gN_param(const BIGNUM *g, const BIGNUM *N); -\& SRP_gN *SRP_get_default_gN(const char *id); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. There are no -available replacement functions at this time. -.PP -The \fBSRP_create_verifier_BN_ex()\fR function creates an \s-1SRP\s0 password verifier from -the supplied parameters as defined in section 2.4 of \s-1RFC 5054\s0 using the library -context \fIlibctx\fR and property query string \fIpropq\fR. Any cryptographic -algorithms that need to be fetched will use the \fIlibctx\fR and \fIpropq\fR. See -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7). -.PP -\&\fBSRP_create_verifier_BN()\fR is the same as \fBSRP_create_verifier_BN_ex()\fR except the -default library context and property query string is used. -.PP -On successful exit \fI*verifier\fR will point to a newly allocated \s-1BIGNUM\s0 containing -the verifier and (if a salt was not provided) \fI*salt\fR will be populated with a -newly allocated \s-1BIGNUM\s0 containing a random salt. If \fI*salt\fR is not \s-1NULL\s0 then -the provided salt is used instead. -The caller is responsible for freeing the allocated \fI*salt\fR and \fI*verifier\fR -\&\s-1BIGNUMS\s0 (use \fBBN_free\fR\|(3)). -.PP -The \fBSRP_create_verifier()\fR function is similar to \fBSRP_create_verifier_BN()\fR but -all numeric parameters are in a non-standard base64 encoding originally designed -for compatibility with libsrp. This is mainly present for historical compatibility -and its use is discouraged. -It is possible to pass \s-1NULL\s0 as \fIN\fR and an \s-1SRP\s0 group id as \fIg\fR instead to -load the appropriate gN values (see \fBSRP_get_default_gN()\fR). -If both \fIN\fR and \fIg\fR are \s-1NULL\s0 the 8192\-bit \s-1SRP\s0 group parameters are used. -The caller is responsible for freeing the allocated \fI*salt\fR and \fI*verifier\fR -(use \fBOPENSSL_free\fR\|(3)). -.PP -The \fBSRP_check_known_gN_param()\fR function checks that \fIg\fR and \fIN\fR are valid -\&\s-1SRP\s0 group parameters from \s-1RFC 5054\s0 appendix A. -.PP -The \fBSRP_get_default_gN()\fR function returns the gN parameters for the \s-1RFC 5054\s0 \fIid\fR -\&\s-1SRP\s0 group size. -The known ids are \*(L"1024\*(R", \*(L"1536\*(R", \*(L"2048\*(R", \*(L"3072\*(R", \*(L"4096\*(R", \*(L"6144\*(R" and \*(L"8192\*(R". -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSRP_create_verifier_BN_ex()\fR and \fBSRP_create_verifier_BN()\fR return 1 on success and -0 on failure. -.PP -\&\fBSRP_create_verifier_ex()\fR and \fBSRP_create_verifier()\fR return \s-1NULL\s0 on failure and a -non-NULL value on success: -\&\*(L"*\*(R" if \fIN\fR is not \s-1NULL,\s0 the selected group id otherwise. This value should -not be freed. -.PP -\&\fBSRP_check_known_gN_param()\fR returns the text representation of the group id -(i.e. the prime bit size) or \s-1NULL\s0 if the arguments are not valid \s-1SRP\s0 group parameters. -This value should not be freed. -.PP -\&\fBSRP_get_default_gN()\fR returns \s-1NULL\s0 if \fIid\fR is not a valid group size, -or the 8192\-bit group parameters if \fIid\fR is \s-1NULL.\s0 -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Generate and store a 8192 bit password verifier (error handling -omitted for clarity): -.PP -.Vb 2 -\& #include -\& #include -\& -\& const char *username = "username"; -\& const char *password = "password"; -\& -\& SRP_VBASE *srpData = SRP_VBASE_new(NULL); -\& -\& SRP_gN *gN = SRP_get_default_gN("8192"); -\& -\& BIGNUM *salt = NULL, *verifier = NULL; -\& SRP_create_verifier_BN_ex(username, password, &salt, &verifier, gN\->N, gN\->g, -\& NULL, NULL); -\& -\& SRP_user_pwd *pwd = SRP_user_pwd_new(); -\& SRP_user_pwd_set1_ids(pwd, username, NULL); -\& SRP_user_pwd_set0_sv(pwd, salt, verifier); -\& SRP_user_pwd_set_gN(pwd, gN\->g, gN\->N); -\& -\& SRP_VBASE_add0_user(srpData, pwd); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-srp\fR\|(1), -\&\fBSRP_VBASE_new\fR\|(3), -\&\fBSRP_user_pwd_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSRP_create_verifier_BN_ex()\fR and \fBSRP_create_verifier_ex()\fR were introduced in -OpenSSL 3.0. All other functions were added in OpenSSL 1.0.1. -.PP -All of these functions were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SRP_create_verifier_BN.3ossl b/openssl-install/share/man/man3/SRP_create_verifier_BN.3ossl deleted file mode 120000 index 146d8b64..00000000 --- a/openssl-install/share/man/man3/SRP_create_verifier_BN.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_create_verifier.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_create_verifier_BN_ex.3ossl b/openssl-install/share/man/man3/SRP_create_verifier_BN_ex.3ossl deleted file mode 120000 index 146d8b64..00000000 --- a/openssl-install/share/man/man3/SRP_create_verifier_BN_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_create_verifier.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_create_verifier_ex.3ossl b/openssl-install/share/man/man3/SRP_create_verifier_ex.3ossl deleted file mode 120000 index 146d8b64..00000000 --- a/openssl-install/share/man/man3/SRP_create_verifier_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_create_verifier.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_get_default_gN.3ossl b/openssl-install/share/man/man3/SRP_get_default_gN.3ossl deleted file mode 120000 index 146d8b64..00000000 --- a/openssl-install/share/man/man3/SRP_get_default_gN.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_create_verifier.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_user_pwd_free.3ossl b/openssl-install/share/man/man3/SRP_user_pwd_free.3ossl deleted file mode 120000 index 95d4373f..00000000 --- a/openssl-install/share/man/man3/SRP_user_pwd_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_user_pwd_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_user_pwd_new.3ossl b/openssl-install/share/man/man3/SRP_user_pwd_new.3ossl deleted file mode 100644 index b3742e83..00000000 --- a/openssl-install/share/man/man3/SRP_user_pwd_new.3ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SRP_USER_PWD_NEW 3ossl" -.TH SRP_USER_PWD_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SRP_user_pwd_new, -SRP_user_pwd_free, -SRP_user_pwd_set1_ids, -SRP_user_pwd_set_gN, -SRP_user_pwd_set0_sv -\&\- Functions to create a record of SRP user verifier information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& SRP_user_pwd *SRP_user_pwd_new(void); -\& void SRP_user_pwd_free(SRP_user_pwd *user_pwd); -\& -\& int SRP_user_pwd_set1_ids(SRP_user_pwd *user_pwd, const char *id, const char *info); -\& void SRP_user_pwd_set_gN(SRP_user_pwd *user_pwd, const BIGNUM *g, const BIGNUM *N); -\& int SRP_user_pwd_set0_sv(SRP_user_pwd *user_pwd, BIGNUM *s, BIGNUM *v); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. There are no -available replacement functions at this time. -.PP -The \fBSRP_user_pwd_new()\fR function allocates a structure to store a user verifier -record. -.PP -The \fBSRP_user_pwd_free()\fR function frees up the \fBuser_pwd\fR structure. -If \fBuser_pwd\fR is \s-1NULL,\s0 nothing is done. -.PP -The \fBSRP_user_pwd_set1_ids()\fR function sets the username to \fBid\fR and the optional -user info to \fBinfo\fR for \fBuser_pwd\fR. -The library allocates new copies of \fBid\fR and \fBinfo\fR, the caller still -owns the original memory. -.PP -The \fBSRP_user_pwd_set0_sv()\fR function sets the user salt to \fBs\fR and the verifier -to \fBv\fR for \fBuser_pwd\fR. -The library takes ownership of the values, they should not be freed by the caller. -.PP -The \fBSRP_user_pwd_set_gN()\fR function sets the \s-1SRP\s0 group parameters for \fBuser_pwd\fR. -The memory is not freed by \fBSRP_user_pwd_free()\fR, the caller must make sure it is -freed once it is no longer used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSRP_user_pwd_set1_ids()\fR returns 1 on success and 0 on failure or if \fBid\fR was \s-1NULL.\s0 -.PP -\&\fBSRP_user_pwd_set0_sv()\fR returns 1 if both \fBs\fR and \fBv\fR are not \s-1NULL, 0\s0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-srp\fR\|(1), -\&\fBSRP_create_verifier\fR\|(3), -\&\fBSRP_VBASE_new\fR\|(3), -\&\fBSSL_CTX_set_srp_password\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were made public in OpenSSL 3.0 and are deprecated. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SRP_user_pwd_set0_sv.3ossl b/openssl-install/share/man/man3/SRP_user_pwd_set0_sv.3ossl deleted file mode 120000 index 95d4373f..00000000 --- a/openssl-install/share/man/man3/SRP_user_pwd_set0_sv.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_user_pwd_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_user_pwd_set1_ids.3ossl b/openssl-install/share/man/man3/SRP_user_pwd_set1_ids.3ossl deleted file mode 120000 index 95d4373f..00000000 --- a/openssl-install/share/man/man3/SRP_user_pwd_set1_ids.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_user_pwd_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SRP_user_pwd_set_gN.3ossl b/openssl-install/share/man/man3/SRP_user_pwd_set_gN.3ossl deleted file mode 120000 index 95d4373f..00000000 --- a/openssl-install/share/man/man3/SRP_user_pwd_set_gN.3ossl +++ /dev/null @@ -1 +0,0 @@ -SRP_user_pwd_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_ACCEPT_STREAM_NO_BLOCK.3ossl b/openssl-install/share/man/man3/SSL_ACCEPT_STREAM_NO_BLOCK.3ossl deleted file mode 120000 index f030cc7e..00000000 --- a/openssl-install/share/man/man3/SSL_ACCEPT_STREAM_NO_BLOCK.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_accept_stream.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_description.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_description.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_description.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_find.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_find.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_auth_nid.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_auth_nid.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_auth_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_bits.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_bits.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_cipher_nid.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_cipher_nid.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_cipher_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_digest_nid.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_digest_nid.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_digest_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_handshake_digest.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_handshake_digest.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_handshake_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_id.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_id.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_kx_nid.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_kx_nid.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_kx_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_name.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_name.3ossl deleted file mode 100644 index 2bc1dd6c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_name.3ossl +++ /dev/null @@ -1,340 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CIPHER_GET_NAME 3ossl" -.TH SSL_CIPHER_GET_NAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CIPHER_get_name, -SSL_CIPHER_standard_name, -OPENSSL_cipher_name, -SSL_CIPHER_get_bits, -SSL_CIPHER_get_version, -SSL_CIPHER_description, -SSL_CIPHER_get_cipher_nid, -SSL_CIPHER_get_digest_nid, -SSL_CIPHER_get_handshake_digest, -SSL_CIPHER_get_kx_nid, -SSL_CIPHER_get_auth_nid, -SSL_CIPHER_is_aead, -SSL_CIPHER_find, -SSL_CIPHER_get_id, -SSL_CIPHER_get_protocol_id -\&\- get SSL_CIPHER properties -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_CIPHER_get_name(const SSL_CIPHER *cipher); -\& const char *SSL_CIPHER_standard_name(const SSL_CIPHER *cipher); -\& const char *OPENSSL_cipher_name(const char *stdname); -\& int SSL_CIPHER_get_bits(const SSL_CIPHER *cipher, int *alg_bits); -\& const char *SSL_CIPHER_get_version(const SSL_CIPHER *cipher); -\& char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int size); -\& int SSL_CIPHER_get_cipher_nid(const SSL_CIPHER *c); -\& int SSL_CIPHER_get_digest_nid(const SSL_CIPHER *c); -\& const EVP_MD *SSL_CIPHER_get_handshake_digest(const SSL_CIPHER *c); -\& int SSL_CIPHER_get_kx_nid(const SSL_CIPHER *c); -\& int SSL_CIPHER_get_auth_nid(const SSL_CIPHER *c); -\& int SSL_CIPHER_is_aead(const SSL_CIPHER *c); -\& const SSL_CIPHER *SSL_CIPHER_find(SSL *ssl, const unsigned char *ptr); -\& uint32_t SSL_CIPHER_get_id(const SSL_CIPHER *c); -\& uint32_t SSL_CIPHER_get_protocol_id(const SSL_CIPHER *c); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CIPHER_get_name()\fR returns a pointer to the name of \fBcipher\fR. If the -\&\fBcipher\fR is \s-1NULL,\s0 it returns \*(L"(\s-1NONE\s0)\*(R". -.PP -\&\fBSSL_CIPHER_standard_name()\fR returns a pointer to the standard \s-1RFC\s0 name of -\&\fBcipher\fR. If the \fBcipher\fR is \s-1NULL,\s0 it returns \*(L"(\s-1NONE\s0)\*(R". If the \fBcipher\fR -has no standard name, it returns \fB\s-1NULL\s0\fR. If \fBcipher\fR was defined in both -SSLv3 and \s-1TLS,\s0 it returns the \s-1TLS\s0 name. -.PP -\&\fBOPENSSL_cipher_name()\fR returns a pointer to the OpenSSL name of \fBstdname\fR. -If the \fBstdname\fR is \s-1NULL,\s0 or \fBstdname\fR has no corresponding OpenSSL name, -it returns \*(L"(\s-1NONE\s0)\*(R". Where both exist, \fBstdname\fR should be the \s-1TLS\s0 name rather -than the SSLv3 name. -.PP -\&\fBSSL_CIPHER_get_bits()\fR returns the number of secret bits used for \fBcipher\fR. -If \fBcipher\fR is \s-1NULL, 0\s0 is returned. -.PP -\&\fBSSL_CIPHER_get_version()\fR returns string which indicates the \s-1SSL/TLS\s0 protocol -version that first defined the cipher. It returns \*(L"(\s-1NONE\s0)\*(R" if \fBcipher\fR is \s-1NULL.\s0 -.PP -\&\fBSSL_CIPHER_get_cipher_nid()\fR returns the cipher \s-1NID\s0 corresponding to \fBc\fR. -If there is no cipher (e.g. for cipher suites with no encryption) then -\&\fBNID_undef\fR is returned. -.PP -\&\fBSSL_CIPHER_get_digest_nid()\fR returns the digest \s-1NID\s0 corresponding to the \s-1MAC\s0 -used by \fBc\fR during record encryption/decryption. If there is no digest (e.g. -for \s-1AEAD\s0 cipher suites) then \fBNID_undef\fR is returned. -.PP -\&\fBSSL_CIPHER_get_handshake_digest()\fR returns an \s-1EVP_MD\s0 for the digest used during -the \s-1SSL/TLS\s0 handshake when using the \s-1SSL_CIPHER\s0 \fBc\fR. Note that this may be -different to the digest used to calculate the \s-1MAC\s0 for encrypted records. -.PP -\&\fBSSL_CIPHER_get_kx_nid()\fR returns the key exchange \s-1NID\s0 corresponding to the method -used by \fBc\fR. If there is no key exchange, then \fBNID_undef\fR is returned. -If any appropriate key exchange algorithm can be used (as in the case of \s-1TLS 1.3\s0 -cipher suites) \fBNID_kx_any\fR is returned. Examples (not comprehensive): -.PP -.Vb 4 -\& NID_kx_rsa -\& NID_kx_ecdhe -\& NID_kx_dhe -\& NID_kx_psk -.Ve -.PP -\&\fBSSL_CIPHER_get_auth_nid()\fR returns the authentication \s-1NID\s0 corresponding to the method -used by \fBc\fR. If there is no authentication, then \fBNID_undef\fR is returned. -If any appropriate authentication algorithm can be used (as in the case of -\&\s-1TLS 1.3\s0 cipher suites) \fBNID_auth_any\fR is returned. Examples (not comprehensive): -.PP -.Vb 3 -\& NID_auth_rsa -\& NID_auth_ecdsa -\& NID_auth_psk -.Ve -.PP -\&\fBSSL_CIPHER_is_aead()\fR returns 1 if the cipher \fBc\fR is \s-1AEAD\s0 (e.g. \s-1GCM\s0 or -ChaCha20/Poly1305), and 0 if it is not \s-1AEAD.\s0 -.PP -\&\fBSSL_CIPHER_find()\fR returns a \fB\s-1SSL_CIPHER\s0\fR structure which has the cipher \s-1ID\s0 stored -in \fBptr\fR. The \fBptr\fR parameter is a two element array of \fBchar\fR, which stores the -two-byte \s-1TLS\s0 cipher \s-1ID\s0 (as allocated by \s-1IANA\s0) in network byte order. This parameter -is usually retrieved from a \s-1TLS\s0 packet by using functions like -\&\fBSSL_client_hello_get0_ciphers\fR\|(3). \fBSSL_CIPHER_find()\fR returns \s-1NULL\s0 if an -error occurs or the indicated cipher is not found. -.PP -\&\fBSSL_CIPHER_get_id()\fR returns the OpenSSL-specific \s-1ID\s0 of the given cipher \fBc\fR. That \s-1ID\s0 is -not the same as the IANA-specific \s-1ID.\s0 -.PP -\&\fBSSL_CIPHER_get_protocol_id()\fR returns the two-byte \s-1ID\s0 used in the \s-1TLS\s0 protocol of the given -cipher \fBc\fR. -.PP -\&\fBSSL_CIPHER_description()\fR returns a textual description of the cipher used -into the buffer \fBbuf\fR of length \fBlen\fR provided. If \fBbuf\fR is provided, it -must be at least 128 bytes. If \fBbuf\fR is \s-1NULL\s0 it will be allocated using -\&\fBOPENSSL_malloc()\fR. If the provided buffer is too small, or the allocation fails, -\&\fB\s-1NULL\s0\fR is returned. -.PP -The string returned by \fBSSL_CIPHER_description()\fR consists of several fields -separated by whitespace: -.IP "" 4 -.IX Item "" -Textual representation of the cipher name. -.IP "" 4 -.IX Item "" -The minimum protocol version that the ciphersuite supports, such as \fBTLSv1.2\fR. -Note that this is not always the same as the protocol version in which the -ciphersuite was first defined because some ciphersuites are backwards compatible -with earlier protocol versions. -.IP "Kx=" 4 -.IX Item "Kx=" -Key exchange method such as \fB\s-1RSA\s0\fR, \fB\s-1ECDHE\s0\fR, etc. -.IP "Au=" 4 -.IX Item "Au=" -Authentication method such as \fB\s-1RSA\s0\fR, \fBNone\fR, etc.. None is the -representation of anonymous ciphers. -.IP "Enc=" 4 -.IX Item "Enc=" -Encryption method, with number of secret bits, such as \fB\s-1AESGCM\s0(128)\fR. -.IP "Mac=" 4 -.IX Item "Mac=" -Message digest, such as \fB\s-1SHA256\s0\fR. -.PP -Some examples for the output of \fBSSL_CIPHER_description()\fR: -.PP -.Vb 2 -\& ECDHE\-RSA\-AES256\-GCM\-SHA256 TLSv1.2 Kx=ECDH Au=RSA Enc=AESGCM(256) Mac=AEAD -\& RSA\-PSK\-AES256\-CBC\-SHA384 TLSv1.0 Kx=RSAPSK Au=RSA Enc=AES(256) Mac=SHA384 -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CIPHER_get_name()\fR, \fBSSL_CIPHER_standard_name()\fR, \fBOPENSSL_cipher_name()\fR, -\&\fBSSL_CIPHER_get_version()\fR and \fBSSL_CIPHER_description()\fR return the corresponding -value in a NUL-terminated string for a specific cipher or \*(L"(\s-1NONE\s0)\*(R" -if the cipher is not found. -.PP -\&\fBSSL_CIPHER_get_bits()\fR returns a positive integer representing the number of -secret bits or 0 if an error occurred. -.PP -\&\fBSSL_CIPHER_get_cipher_nid()\fR, \fBSSL_CIPHER_get_digest_nid()\fR, -\&\fBSSL_CIPHER_get_kx_nid()\fR and \fBSSL_CIPHER_get_auth_nid()\fR return the \s-1NID\s0 value or -\&\fBNID_undef\fR if an error occurred. -.PP -\&\fBSSL_CIPHER_get_handshake_digest()\fR returns a valid \fB\s-1EVP_MD\s0\fR structure or \s-1NULL\s0 -if an error occurred. -.PP -\&\fBSSL_CIPHER_is_aead()\fR returns 1 if the cipher is \s-1AEAD\s0 or 0 otherwise. -.PP -\&\fBSSL_CIPHER_find()\fR returns a valid \fB\s-1SSL_CIPHER\s0\fR structure or \s-1NULL\s0 if an error -occurred. -.PP -\&\fBSSL_CIPHER_get_id()\fR returns a 4\-byte integer representing the OpenSSL-specific \s-1ID.\s0 -.PP -\&\fBSSL_CIPHER_get_protocol_id()\fR returns a 2\-byte integer representing the \s-1TLS\s0 -protocol-specific \s-1ID.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_current_cipher\fR\|(3), -\&\fBSSL_get_ciphers\fR\|(3), \fBopenssl\-ciphers\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_CIPHER_get_version()\fR function was updated to always return the -correct protocol string in OpenSSL 1.1.0. -.PP -The \fBSSL_CIPHER_description()\fR function was changed to return \fB\s-1NULL\s0\fR on error, -rather than a fixed string, in OpenSSL 1.1.0. -.PP -The \fBSSL_CIPHER_get_handshake_digest()\fR function was added in OpenSSL 1.1.1. -.PP -The \fBSSL_CIPHER_standard_name()\fR function was globally available in OpenSSL 1.1.1. - Before OpenSSL 1.1.1, tracing (\fBenable-ssl-trace\fR argument to Configure) was -required to enable this function. -.PP -The \fBOPENSSL_cipher_name()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_protocol_id.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_protocol_id.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_protocol_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_get_version.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_get_version.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_get_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_is_aead.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_is_aead.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_is_aead.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CIPHER_standard_name.3ossl b/openssl-install/share/man/man3/SSL_CIPHER_standard_name.3ossl deleted file mode 120000 index 0c6c563c..00000000 --- a/openssl-install/share/man/man3/SSL_CIPHER_standard_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CIPHER_get_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_COMP_add_compression_method.3ossl b/openssl-install/share/man/man3/SSL_COMP_add_compression_method.3ossl deleted file mode 100644 index 46beb844..00000000 --- a/openssl-install/share/man/man3/SSL_COMP_add_compression_method.3ossl +++ /dev/null @@ -1,243 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_COMP_ADD_COMPRESSION_METHOD 3ossl" -.TH SSL_COMP_ADD_COMPRESSION_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_COMP_add_compression_method, SSL_COMP_get_compression_methods, -SSL_COMP_get0_name, SSL_COMP_get_id, SSL_COMP_free_compression_methods -\&\- handle SSL/TLS integrated compression methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_COMP_add_compression_method(int id, COMP_METHOD *cm); -\& STACK_OF(SSL_COMP) *SSL_COMP_get_compression_methods(void); -\& const char *SSL_COMP_get0_name(const SSL_COMP *comp); -\& int SSL_COMP_get_id(const SSL_COMP *comp); -.Ve -.PP -The following function has been deprecated since OpenSSL 1.1.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void SSL_COMP_free_compression_methods(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_COMP_add_compression_method()\fR adds the compression method \fBcm\fR with -the identifier \fBid\fR to the list of available compression methods. This -list is globally maintained for all \s-1SSL\s0 operations within this application. -It cannot be set for specific \s-1SSL_CTX\s0 or \s-1SSL\s0 objects. -.PP -\&\fBSSL_COMP_get_compression_methods()\fR returns a stack of all of the available -compression methods or \s-1NULL\s0 on error. -.PP -\&\fBSSL_COMP_get0_name()\fR returns the name of the compression method \fBcomp\fR. -.PP -\&\fBSSL_COMP_get_id()\fR returns the id of the compression method \fBcomp\fR. -.PP -\&\fBSSL_COMP_free_compression_methods()\fR releases any resources acquired to -maintain the internal table of compression methods. -.SH "NOTES" -.IX Header "NOTES" -The \s-1TLS\s0 standard (or SSLv3) allows the integration of compression methods -into the communication. The \s-1TLS RFC\s0 does however not specify compression -methods or their corresponding identifiers, so there is currently no compatible -way to integrate compression with unknown peers. It is therefore currently not -recommended to integrate compression into applications. Applications for -non-public use may agree on certain compression methods. Using different -compression methods with the same identifier will lead to connection failure. -.PP -An OpenSSL client speaking a protocol that allows compression (SSLv3, TLSv1) -will unconditionally send the list of all compression methods enabled with -\&\fBSSL_COMP_add_compression_method()\fR to the server during the handshake. -Unlike the mechanisms to set a cipher list, there is no method available to -restrict the list of compression method on a per connection basis. -.PP -An OpenSSL server will match the identifiers listed by a client against -its own compression methods and will unconditionally activate compression -when a matching identifier is found. There is no way to restrict the list -of compression methods supported on a per connection basis. -.PP -If enabled during compilation, the OpenSSL library will have the -following compression methods available: -.IP "\fBCOMP_zlib()\fR" 4 -.IX Item "COMP_zlib()" -.PD 0 -.IP "\fBCOMP_brotli()\fR" 4 -.IX Item "COMP_brotli()" -.IP "\fBCOMP_brotli_oneshot()\fR" 4 -.IX Item "COMP_brotli_oneshot()" -.IP "\fBCOMP_zstd()\fR" 4 -.IX Item "COMP_zstd()" -.IP "\fBCOMP_zstd_oneshot()\fR" 4 -.IX Item "COMP_zstd_oneshot()" -.PD -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_COMP_add_compression_method()\fR may return the following values: -.IP "0" 4 -The operation succeeded. -.IP "1" 4 -.IX Item "1" -The operation failed. Check the error queue to find out the reason. -.PP -\&\fBSSL_COMP_get_compression_methods()\fR returns the stack of compressions methods or -\&\s-1NULL\s0 on error. -.PP -\&\fBSSL_COMP_get0_name()\fR returns the name of the compression method or \s-1NULL\s0 on error. -.PP -\&\fBSSL_COMP_get_id()\fR returns the name of the compression method or \-1 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_COMP_free_compression_methods()\fR function was deprecated in OpenSSL 1.1.0. -The \fBSSL_COMP_get0_name()\fR and \fBSSL_comp_get_id()\fR functions were added in OpenSSL 1.1.0d. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_COMP_free_compression_methods.3ossl b/openssl-install/share/man/man3/SSL_COMP_free_compression_methods.3ossl deleted file mode 120000 index 80510e31..00000000 --- a/openssl-install/share/man/man3/SSL_COMP_free_compression_methods.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_COMP_add_compression_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_COMP_get0_name.3ossl b/openssl-install/share/man/man3/SSL_COMP_get0_name.3ossl deleted file mode 120000 index 80510e31..00000000 --- a/openssl-install/share/man/man3/SSL_COMP_get0_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_COMP_add_compression_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_COMP_get_compression_methods.3ossl b/openssl-install/share/man/man3/SSL_COMP_get_compression_methods.3ossl deleted file mode 120000 index 80510e31..00000000 --- a/openssl-install/share/man/man3/SSL_COMP_get_compression_methods.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_COMP_add_compression_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_COMP_get_id.3ossl b/openssl-install/share/man/man3/SSL_COMP_get_id.3ossl deleted file mode 120000 index 80510e31..00000000 --- a/openssl-install/share/man/man3/SSL_COMP_get_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_COMP_add_compression_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_clear_flags.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_clear_flags.3ossl deleted file mode 120000 index 9592b147..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CONF_CTX_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_finish.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_finish.3ossl deleted file mode 120000 index 459afcaa..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_finish.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CONF_CTX_set_ssl_ctx.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_free.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_free.3ossl deleted file mode 120000 index d69ad5f1..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CONF_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_new.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_new.3ossl deleted file mode 100644 index 2c8d4fe6..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_new.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CONF_CTX_NEW 3ossl" -.TH SSL_CONF_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CONF_CTX_new, SSL_CONF_CTX_free \- SSL configuration allocation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL_CONF_CTX *SSL_CONF_CTX_new(void); -\& void SSL_CONF_CTX_free(SSL_CONF_CTX *cctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBSSL_CONF_CTX_new()\fR allocates and initialises an \fB\s-1SSL_CONF_CTX\s0\fR -structure for use with the \s-1SSL_CONF\s0 functions. -.PP -The function \fBSSL_CONF_CTX_free()\fR frees up the context \fBcctx\fR. -If \fBcctx\fR is \s-1NULL\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CONF_CTX_new()\fR returns either the newly allocated \fB\s-1SSL_CONF_CTX\s0\fR structure -or \fB\s-1NULL\s0\fR if an error occurs. -.PP -\&\fBSSL_CONF_CTX_free()\fR does not return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CONF_CTX_set_flags\fR\|(3), -\&\fBSSL_CONF_CTX_set_ssl_ctx\fR\|(3), -\&\fBSSL_CONF_CTX_set1_prefix\fR\|(3), -\&\fBSSL_CONF_cmd\fR\|(3), -\&\fBSSL_CONF_cmd_argv\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2012\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_set1_prefix.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_set1_prefix.3ossl deleted file mode 100644 index 1de409e8..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_set1_prefix.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CONF_CTX_SET1_PREFIX 3ossl" -.TH SSL_CONF_CTX_SET1_PREFIX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CONF_CTX_set1_prefix \- Set configuration context command prefix -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned int SSL_CONF_CTX_set1_prefix(SSL_CONF_CTX *cctx, const char *prefix); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBSSL_CONF_CTX_set1_prefix()\fR sets the command prefix of \fBcctx\fR -to \fBprefix\fR. If \fBprefix\fR is \fB\s-1NULL\s0\fR it is restored to the default value. -.SH "NOTES" -.IX Header "NOTES" -Command prefixes alter the commands recognised by subsequent \fBSSL_CONF_cmd()\fR -calls. For example for files, if the prefix \*(L"\s-1SSL\*(R"\s0 is set then command names -such as \*(L"SSLProtocol\*(R", \*(L"SSLOptions\*(R" etc. are recognised instead of \*(L"Protocol\*(R" -and \*(L"Options\*(R". Similarly for command lines if the prefix is \*(L"\-\-ssl\-\*(R" then -\&\*(L"\-\-ssl\-no_tls1_2\*(R" is recognised instead of \*(L"\-no_tls1_2\*(R". -.PP -If the \fB\s-1SSL_CONF_FLAG_CMDLINE\s0\fR flag is set then prefix checks are case -sensitive and \*(L"\-\*(R" is the default. In the unlikely even an application -explicitly wants to set no prefix it must be explicitly set to "". -.PP -If the \fB\s-1SSL_CONF_FLAG_FILE\s0\fR flag is set then prefix checks are case -insensitive and no prefix is the default. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CONF_CTX_set1_prefix()\fR returns 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CONF_CTX_new\fR\|(3), -\&\fBSSL_CONF_CTX_set_flags\fR\|(3), -\&\fBSSL_CONF_CTX_set_ssl_ctx\fR\|(3), -\&\fBSSL_CONF_cmd\fR\|(3), -\&\fBSSL_CONF_cmd_argv\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2012\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_set_flags.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_set_flags.3ossl deleted file mode 100644 index 28c85e4b..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_set_flags.3ossl +++ /dev/null @@ -1,206 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CONF_CTX_SET_FLAGS 3ossl" -.TH SSL_CONF_CTX_SET_FLAGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CONF_CTX_set_flags, SSL_CONF_CTX_clear_flags \- Set or clear SSL configuration context flags -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned int SSL_CONF_CTX_set_flags(SSL_CONF_CTX *cctx, unsigned int flags); -\& unsigned int SSL_CONF_CTX_clear_flags(SSL_CONF_CTX *cctx, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBSSL_CONF_CTX_set_flags()\fR sets \fBflags\fR in the context \fBcctx\fR. -.PP -The function \fBSSL_CONF_CTX_clear_flags()\fR clears \fBflags\fR in the context \fBcctx\fR. -.SH "NOTES" -.IX Header "NOTES" -The flags set affect how subsequent calls to \fBSSL_CONF_cmd()\fR or -\&\fBSSL_CONF_argv()\fR behave. -.PP -Currently the following \fBflags\fR values are recognised: -.IP "\s-1SSL_CONF_FLAG_CMDLINE, SSL_CONF_FLAG_FILE\s0" 4 -.IX Item "SSL_CONF_FLAG_CMDLINE, SSL_CONF_FLAG_FILE" -recognise options intended for command line or configuration file use. At -least one of these flags must be set. -.IP "\s-1SSL_CONF_FLAG_CLIENT, SSL_CONF_FLAG_SERVER\s0" 4 -.IX Item "SSL_CONF_FLAG_CLIENT, SSL_CONF_FLAG_SERVER" -recognise options intended for use in \s-1SSL/TLS\s0 clients or servers. One or -both of these flags must be set. -.IP "\s-1SSL_CONF_FLAG_CERTIFICATE\s0" 4 -.IX Item "SSL_CONF_FLAG_CERTIFICATE" -recognise certificate and private key options. -.IP "\s-1SSL_CONF_FLAG_REQUIRE_PRIVATE\s0" 4 -.IX Item "SSL_CONF_FLAG_REQUIRE_PRIVATE" -If this option is set then if a private key is not specified for a certificate -it will attempt to load a private key from the certificate file when -\&\fBSSL_CONF_CTX_finish()\fR is called. If a key cannot be loaded from the certificate -file an error occurs. -.IP "\s-1SSL_CONF_FLAG_SHOW_ERRORS\s0" 4 -.IX Item "SSL_CONF_FLAG_SHOW_ERRORS" -indicate errors relating to unrecognised options or missing arguments in -the error queue. If this option isn't set such errors are only reflected -in the return values of \fBSSL_CONF_set_cmd()\fR or \fBSSL_CONF_set_argv()\fR -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CONF_CTX_set_flags()\fR and \fBSSL_CONF_CTX_clear_flags()\fR returns the new flags -value after setting or clearing flags. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CONF_CTX_new\fR\|(3), -\&\fBSSL_CONF_CTX_set_ssl_ctx\fR\|(3), -\&\fBSSL_CONF_CTX_set1_prefix\fR\|(3), -\&\fBSSL_CONF_cmd\fR\|(3), -\&\fBSSL_CONF_cmd_argv\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2012\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl.3ossl deleted file mode 120000 index 459afcaa..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CONF_CTX_set_ssl_ctx.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl_ctx.3ossl b/openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl_ctx.3ossl deleted file mode 100644 index 78d3488f..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_CTX_set_ssl_ctx.3ossl +++ /dev/null @@ -1,195 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CONF_CTX_SET_SSL_CTX 3ossl" -.TH SSL_CONF_CTX_SET_SSL_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CONF_CTX_finish, -SSL_CONF_CTX_set_ssl_ctx, SSL_CONF_CTX_set_ssl \- set context to configure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CONF_CTX_set_ssl_ctx(SSL_CONF_CTX *cctx, SSL_CTX *ctx); -\& void SSL_CONF_CTX_set_ssl(SSL_CONF_CTX *cctx, SSL *ssl); -\& int SSL_CONF_CTX_finish(SSL_CONF_CTX *cctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CONF_CTX_set_ssl_ctx()\fR sets the context associated with \fBcctx\fR to the -\&\fB\s-1SSL_CTX\s0\fR structure \fBctx\fR. Any previous \fB\s-1SSL\s0\fR or \fB\s-1SSL_CTX\s0\fR associated with -\&\fBcctx\fR is cleared. Subsequent calls to \fBSSL_CONF_cmd()\fR will be sent to -\&\fBctx\fR. -.PP -\&\fBSSL_CONF_CTX_set_ssl()\fR sets the context associated with \fBcctx\fR to the -\&\fB\s-1SSL\s0\fR structure \fBssl\fR. Any previous \fB\s-1SSL\s0\fR or \fB\s-1SSL_CTX\s0\fR associated with -\&\fBcctx\fR is cleared. Subsequent calls to \fBSSL_CONF_cmd()\fR will be sent to -\&\fBssl\fR. -.PP -The function \fBSSL_CONF_CTX_finish()\fR must be called after all configuration -operations have been completed. It is used to finalise any operations -or to process defaults. -.SH "NOTES" -.IX Header "NOTES" -The context need not be set or it can be set to \fB\s-1NULL\s0\fR in which case only -syntax checking of commands is performed, where possible. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CONF_CTX_set_ssl_ctx()\fR and \fBSSL_CTX_set_ssl()\fR do not return a value. -.PP -\&\fBSSL_CONF_CTX_finish()\fR returns 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CONF_CTX_new\fR\|(3), -\&\fBSSL_CONF_CTX_set_flags\fR\|(3), -\&\fBSSL_CONF_CTX_set1_prefix\fR\|(3), -\&\fBSSL_CONF_cmd\fR\|(3), -\&\fBSSL_CONF_cmd_argv\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2012\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CONF_cmd.3ossl b/openssl-install/share/man/man3/SSL_CONF_cmd.3ossl deleted file mode 100644 index 97309bdc..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_cmd.3ossl +++ /dev/null @@ -1,896 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CONF_CMD 3ossl" -.TH SSL_CONF_CMD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CONF_cmd_value_type, -SSL_CONF_cmd \- send configuration command -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CONF_cmd(SSL_CONF_CTX *ctx, const char *option, const char *value); -\& int SSL_CONF_cmd_value_type(SSL_CONF_CTX *ctx, const char *option); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBSSL_CONF_cmd()\fR performs configuration operation \fBoption\fR with -optional parameter \fBvalue\fR on \fBctx\fR. Its purpose is to simplify application -configuration of \fB\s-1SSL_CTX\s0\fR or \fB\s-1SSL\s0\fR structures by providing a common -framework for command line options or configuration files. -.PP -\&\fBSSL_CONF_cmd_value_type()\fR returns the type of value that \fBoption\fR refers to. -.SH "SUPPORTED COMMAND LINE COMMANDS" -.IX Header "SUPPORTED COMMAND LINE COMMANDS" -Currently supported \fBoption\fR names for command lines (i.e. when the -flag \fB\s-1SSL_CONF_FLAG_CMDLINE\s0\fR is set) are listed below. Note: all \fBoption\fR -names are case sensitive. Unless otherwise stated commands can be used by -both clients and servers and the \fBvalue\fR parameter is not used. The default -prefix for command line commands is \fB\-\fR and that is reflected below. -.IP "\fB\-bugs\fR" 4 -.IX Item "-bugs" -Various bug workarounds are set, same as setting \fB\s-1SSL_OP_ALL\s0\fR. -.IP "\fB\-no_comp\fR" 4 -.IX Item "-no_comp" -Disables support for \s-1SSL/TLS\s0 compression, same as setting -\&\fB\s-1SSL_OP_NO_COMPRESSION\s0\fR. -As of OpenSSL 1.1.0, compression is off by default. -.IP "\fB\-comp\fR" 4 -.IX Item "-comp" -Enables support for \s-1SSL/TLS\s0 compression, same as clearing -\&\fB\s-1SSL_OP_NO_COMPRESSION\s0\fR. -This command was introduced in OpenSSL 1.1.0. -As of OpenSSL 1.1.0, compression is off by default. \s-1TLS\s0 compression can only be -used in security level 1 or lower. From OpenSSL 3.2.0 and above the default -security level is 2, so this option will have no effect without also changing -the security level. See \fBSSL_CTX_set_security_level\fR\|(3). -.IP "\fB\-no_ticket\fR" 4 -.IX Item "-no_ticket" -Disables support for session tickets, same as setting \fB\s-1SSL_OP_NO_TICKET\s0\fR. -.IP "\fB\-serverpref\fR" 4 -.IX Item "-serverpref" -Use server and not client preference order when determining which cipher suite, -signature algorithm or elliptic curve to use for an incoming connection. -Equivalent to \fB\s-1SSL_OP_CIPHER_SERVER_PREFERENCE\s0\fR. Only used by servers. -.IP "\fB\-client_renegotiation\fR" 4 -.IX Item "-client_renegotiation" -Allows servers to accept client-initiated renegotiation. Equivalent to -setting \fB\s-1SSL_OP_ALLOW_CLIENT_RENEGOTIATION\s0\fR. -Only used by servers. -.IP "\fB\-legacy_renegotiation\fR" 4 -.IX Item "-legacy_renegotiation" -Permits the use of unsafe legacy renegotiation. Equivalent to setting -\&\fB\s-1SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION\s0\fR. -.IP "\fB\-no_renegotiation\fR" 4 -.IX Item "-no_renegotiation" -Disables all attempts at renegotiation in (D)TLSv1.2 and earlier, same as setting -\&\fB\s-1SSL_OP_NO_RENEGOTIATION\s0\fR. -.IP "\fB\-no_resumption_on_reneg\fR" 4 -.IX Item "-no_resumption_on_reneg" -Sets \fB\s-1SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION\s0\fR. Only used by servers. -.IP "\fB\-legacy_server_connect\fR, \fB\-no_legacy_server_connect\fR" 4 -.IX Item "-legacy_server_connect, -no_legacy_server_connect" -Permits or prohibits the use of unsafe legacy renegotiation for OpenSSL -clients only. Equivalent to setting or clearing \fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR. -.IP "\fB\-prioritize_chacha\fR" 4 -.IX Item "-prioritize_chacha" -Prioritize ChaCha ciphers when the client has a ChaCha20 cipher at the top of -its preference list. This usually indicates a client without \s-1AES\s0 hardware -acceleration (e.g. mobile) is in use. Equivalent to \fB\s-1SSL_OP_PRIORITIZE_CHACHA\s0\fR. -Only used by servers. Requires \fB\-serverpref\fR. -.IP "\fB\-allow_no_dhe_kex\fR" 4 -.IX Item "-allow_no_dhe_kex" -In TLSv1.3 allow a non\-(ec)dhe based key exchange mode on resumption. This means -that there will be no forward secrecy for the resumed session. -.IP "\fB\-prefer_no_dhe_kex\fR" 4 -.IX Item "-prefer_no_dhe_kex" -In TLSv1.3, on resumption let the server prefer a non\-(ec)dhe based key -exchange mode over an (ec)dhe based one. Requires \fB\-allow_no_dhe_kex\fR. -Equivalent to \fB\s-1SSL_OP_PREFER_NO_DHE_KEX\s0\fR. Only used by servers. -.IP "\fB\-strict\fR" 4 -.IX Item "-strict" -Enables strict mode protocol handling. Equivalent to setting -\&\fB\s-1SSL_CERT_FLAG_TLS_STRICT\s0\fR. -.IP "\fB\-sigalgs\fR \fIalgs\fR" 4 -.IX Item "-sigalgs algs" -This sets the supported signature algorithms for TLSv1.2 and TLSv1.3. -For clients this value is used directly for the supported signature -algorithms extension. For servers it is used to determine which signature -algorithms to support. -.Sp -The \fBalgs\fR argument should be a colon separated list of signature -algorithms in order of decreasing preference of the form \fBalgorithm+hash\fR -or \fBsignature_scheme\fR. For the default providers shipped with OpenSSL, -\&\fBalgorithm\fR is one of \fB\s-1RSA\s0\fR, \fB\s-1DSA\s0\fR or \fB\s-1ECDSA\s0\fR and -\&\fBhash\fR is a supported algorithm \s-1OID\s0 short name such as \fB\s-1SHA1\s0\fR, \fB\s-1SHA224\s0\fR, -\&\fB\s-1SHA256\s0\fR, \fB\s-1SHA384\s0\fR or \fB\s-1SHA512\s0\fR. Note: algorithm and hash names are case -sensitive. \fBsignature_scheme\fR is one of the signature schemes defined in -TLSv1.3, specified using the \s-1IETF\s0 name, e.g., \fBecdsa_secp256r1_sha256\fR, -\&\fBed25519\fR, or \fBrsa_pss_pss_sha256\fR. Additional providers may make available -further algorithms via the \s-1TLS_SIGALG\s0 capability. -See \*(L"\s-1CAPABILITIES\*(R"\s0 in \fBprovider\-base\fR\|(7). -.Sp -If this option is not set then all signature algorithms supported by all -activated providers are permissible. -.Sp -Note: algorithms which specify a PKCS#1 v1.5 signature scheme (either by -using \fB\s-1RSA\s0\fR as the \fBalgorithm\fR or by using one of the \fBrsa_pkcs1_*\fR -identifiers) are ignored in TLSv1.3 and will not be negotiated. -.IP "\fB\-client_sigalgs\fR \fIalgs\fR" 4 -.IX Item "-client_sigalgs algs" -This sets the supported signature algorithms associated with client -authentication for TLSv1.2 and TLSv1.3. For servers the \fBalgs\fR is used -in the \fBsignature_algorithms\fR field of a \fBCertificateRequest\fR message. -For clients it is used to determine which signature algorithm to use with -the client certificate. If a server does not request a certificate this -option has no effect. -.Sp -The syntax of \fBalgs\fR is identical to \fB\-sigalgs\fR. If not set, then the -value set for \fB\-sigalgs\fR will be used instead. -.IP "\fB\-groups\fR \fIgroups\fR" 4 -.IX Item "-groups groups" -This sets the supported groups. For clients, the groups are sent using -the supported groups extension. For servers, it is used to determine which -group to use. This setting affects groups used for signatures (in TLSv1.2 -and earlier) and key exchange. The first group listed will also be used -for the \fBkey_share\fR sent by a client in a TLSv1.3 \fBClientHello\fR. -.Sp -The \fBgroups\fR argument is a colon separated list of groups. The group can -be either the \fB\s-1NIST\s0\fR name (e.g. \fBP\-256\fR), some other commonly used name -where applicable (e.g. \fBX25519\fR, \fBffdhe2048\fR) or an OpenSSL \s-1OID\s0 name -(e.g. \fBprime256v1\fR). Group names are case sensitive. The list should be -in order of preference with the most preferred group first. -.Sp -Currently supported groups for \fBTLSv1.3\fR are \fBP\-256\fR, \fBP\-384\fR, \fBP\-521\fR, -\&\fBX25519\fR, \fBX448\fR, \fBffdhe2048\fR, \fBffdhe3072\fR, \fBffdhe4096\fR, \fBffdhe6144\fR, -\&\fBffdhe8192\fR. -.IP "\fB\-curves\fR \fIgroups\fR" 4 -.IX Item "-curves groups" -This is a synonym for the \fB\-groups\fR command. -.IP "\fB\-named_curve\fR \fIcurve\fR" 4 -.IX Item "-named_curve curve" -This sets the temporary curve used for ephemeral \s-1ECDH\s0 modes. Only used -by servers. -.IP "\fB\-tx_cert_comp\fR" 4 -.IX Item "-tx_cert_comp" -Enables support for sending TLSv1.3 compressed certificates. -.IP "\fB\-no_tx_cert_comp\fR" 4 -.IX Item "-no_tx_cert_comp" -Disables support for sending TLSv1.3 compressed certificates. -.IP "\fB\-rx_cert_comp\fR" 4 -.IX Item "-rx_cert_comp" -Enables support for receiving TLSv1.3 compressed certificates. -.IP "\fB\-no_rx_cert_comp\fR" 4 -.IX Item "-no_rx_cert_comp" -Disables support for receiving TLSv1.3 compressed certificates. -.IP "\fB\-comp\fR" 4 -.IX Item "-comp" -The \fBgroups\fR argument is a curve name or the special value \fBauto\fR which -picks an appropriate curve based on client and server preferences. The -curve can be either the \fB\s-1NIST\s0\fR name (e.g. \fBP\-256\fR) or an OpenSSL \s-1OID\s0 name -(e.g. \fBprime256v1\fR). Curve names are case sensitive. -.IP "\fB\-cipher\fR \fIciphers\fR" 4 -.IX Item "-cipher ciphers" -Sets the TLSv1.2 and below ciphersuite list to \fBciphers\fR. This list will be -combined with any configured TLSv1.3 ciphersuites. Note: syntax checking -of \fBciphers\fR is currently not performed unless a \fB\s-1SSL\s0\fR or \fB\s-1SSL_CTX\s0\fR -structure is associated with \fBctx\fR. -.IP "\fB\-ciphersuites\fR \fI1.3ciphers\fR" 4 -.IX Item "-ciphersuites 1.3ciphers" -Sets the available ciphersuites for TLSv1.3 to value. This is a -colon-separated list of TLSv1.3 ciphersuite names in order of preference. This -list will be combined any configured TLSv1.2 and below ciphersuites. -See \fBopenssl\-ciphers\fR\|(1) for more information. -.IP "\fB\-min_protocol\fR \fIminprot\fR, \fB\-max_protocol\fR \fImaxprot\fR" 4 -.IX Item "-min_protocol minprot, -max_protocol maxprot" -Sets the minimum and maximum supported protocol. -Currently supported protocol values are \fBSSLv3\fR, \fBTLSv1\fR, \fBTLSv1.1\fR, -\&\fBTLSv1.2\fR, \fBTLSv1.3\fR for \s-1TLS\s0; \fBDTLSv1\fR, \fBDTLSv1.2\fR for \s-1DTLS,\s0 and \fBNone\fR -for no limit. -If either the lower or upper bound is not specified then only the other bound -applies, if specified. -If your application supports both \s-1TLS\s0 and \s-1DTLS\s0 you can specify any of these -options twice, once with a bound for \s-1TLS\s0 and again with an appropriate bound -for \s-1DTLS.\s0 -To restrict the supported protocol versions use these commands rather than the -deprecated alternative commands below. -.IP "\fB\-record_padding\fR \fIpadding\fR" 4 -.IX Item "-record_padding padding" -Controls use of TLSv1.3 record layer padding. \fBpadding\fR is a string of the -form \*(L"number[,number]\*(R" where the (required) first number is the padding block -size (in octets) for application data, and the optional second number is the -padding block size for handshake and alert messages. If the optional second -number is omitted, the same padding will be applied to all messages. -.Sp -Padding attempts to pad TLSv1.3 records so that they are a multiple of the set -length on send. A value of 0 or 1 turns off padding as relevant. Otherwise, the -values must be >1 or <=16384. -.IP "\fB\-debug_broken_protocol\fR" 4 -.IX Item "-debug_broken_protocol" -Ignored. -.IP "\fB\-no_middlebox\fR" 4 -.IX Item "-no_middlebox" -Turn off \*(L"middlebox compatibility\*(R", as described below. -.SS "Additional Options" -.IX Subsection "Additional Options" -The following options are accepted by \fBSSL_CONF_cmd()\fR, but are not -processed by the OpenSSL commands. -.IP "\fB\-cert\fR \fIfile\fR" 4 -.IX Item "-cert file" -Attempts to use \fBfile\fR as the certificate for the appropriate context. It -currently uses \fBSSL_CTX_use_certificate_chain_file()\fR if an \fB\s-1SSL_CTX\s0\fR -structure is set or \fBSSL_use_certificate_file()\fR with filetype \s-1PEM\s0 if an -\&\fB\s-1SSL\s0\fR structure is set. This option is only supported if certificate -operations are permitted. -.IP "\fB\-key\fR \fIfile\fR" 4 -.IX Item "-key file" -Attempts to use \fBfile\fR as the private key for the appropriate context. This -option is only supported if certificate operations are permitted. Note: -if no \fB\-key\fR option is set then a private key is not loaded unless the -flag \fB\s-1SSL_CONF_FLAG_REQUIRE_PRIVATE\s0\fR is set. -.IP "\fB\-dhparam\fR \fIfile\fR" 4 -.IX Item "-dhparam file" -Attempts to use \fBfile\fR as the set of temporary \s-1DH\s0 parameters for -the appropriate context. This option is only supported if certificate -operations are permitted. -.IP "\fB\-no_ssl3\fR, \fB\-no_tls1\fR, \fB\-no_tls1_1\fR, \fB\-no_tls1_2\fR, \fB\-no_tls1_3\fR" 4 -.IX Item "-no_ssl3, -no_tls1, -no_tls1_1, -no_tls1_2, -no_tls1_3" -Disables protocol support for SSLv3, TLSv1.0, TLSv1.1, TLSv1.2 or TLSv1.3 by -setting the corresponding options \fBSSL_OP_NO_SSLv3\fR, \fBSSL_OP_NO_TLSv1\fR, -\&\fBSSL_OP_NO_TLSv1_1\fR, \fBSSL_OP_NO_TLSv1_2\fR and \fBSSL_OP_NO_TLSv1_3\fR -respectively. These options are deprecated, use \fB\-min_protocol\fR and -\&\fB\-max_protocol\fR instead. -.IP "\fB\-anti_replay\fR, \fB\-no_anti_replay\fR" 4 -.IX Item "-anti_replay, -no_anti_replay" -Switches replay protection, on or off respectively. With replay protection on, -OpenSSL will automatically detect if a session ticket has been used more than -once, TLSv1.3 has been negotiated, and early data is enabled on the server. A -full handshake is forced if a session ticket is used a second or subsequent -time. Anti-Replay is on by default unless overridden by a configuration file and -is only used by servers. Anti-replay measures are required for compliance with -the TLSv1.3 specification. Some applications may be able to mitigate the replay -risks in other ways and in such cases the built-in OpenSSL functionality is not -required. Switching off anti-replay is equivalent to \fB\s-1SSL_OP_NO_ANTI_REPLAY\s0\fR. -.SH "SUPPORTED CONFIGURATION FILE COMMANDS" -.IX Header "SUPPORTED CONFIGURATION FILE COMMANDS" -Currently supported \fBoption\fR names for configuration files (i.e., when the -flag \fB\s-1SSL_CONF_FLAG_FILE\s0\fR is set) are listed below. All configuration file -\&\fBoption\fR names are case insensitive so \fBsignaturealgorithms\fR is recognised -as well as \fBSignatureAlgorithms\fR. Unless otherwise stated the \fBvalue\fR names -are also case insensitive. -.PP -Note: the command prefix (if set) alters the recognised \fBoption\fR values. -.IP "\fBCipherString\fR" 4 -.IX Item "CipherString" -Sets the ciphersuite list for TLSv1.2 and below to \fBvalue\fR. This list will be -combined with any configured TLSv1.3 ciphersuites. Note: syntax -checking of \fBvalue\fR is currently not performed unless an \fB\s-1SSL\s0\fR or \fB\s-1SSL_CTX\s0\fR -structure is associated with \fBctx\fR. -.IP "\fBCiphersuites\fR" 4 -.IX Item "Ciphersuites" -Sets the available ciphersuites for TLSv1.3 to \fBvalue\fR. This is a -colon-separated list of TLSv1.3 ciphersuite names in order of preference. This -list will be combined any configured TLSv1.2 and below ciphersuites. -See \fBopenssl\-ciphers\fR\|(1) for more information. -.IP "\fBCertificate\fR" 4 -.IX Item "Certificate" -Attempts to use the file \fBvalue\fR as the certificate for the appropriate -context. It currently uses \fBSSL_CTX_use_certificate_chain_file()\fR if an \fB\s-1SSL_CTX\s0\fR -structure is set or \fBSSL_use_certificate_file()\fR with filetype \s-1PEM\s0 if an \fB\s-1SSL\s0\fR -structure is set. This option is only supported if certificate operations -are permitted. -.IP "\fBPrivateKey\fR" 4 -.IX Item "PrivateKey" -Attempts to use the file \fBvalue\fR as the private key for the appropriate -context. This option is only supported if certificate operations -are permitted. Note: if no \fBPrivateKey\fR option is set then a private key is -not loaded unless the \fB\s-1SSL_CONF_FLAG_REQUIRE_PRIVATE\s0\fR is set. -.IP "\fBChainCAFile\fR, \fBChainCAPath\fR, \fBVerifyCAFile\fR, \fBVerifyCAPath\fR" 4 -.IX Item "ChainCAFile, ChainCAPath, VerifyCAFile, VerifyCAPath" -These options indicate a file or directory used for building certificate -chains or verifying certificate chains. These options are only supported -if certificate operations are permitted. -.IP "\fBRequestCAFile\fR" 4 -.IX Item "RequestCAFile" -This option indicates a file containing a set of certificates in \s-1PEM\s0 form. -The subject names of the certificates are sent to the peer in the -\&\fBcertificate_authorities\fR extension for \s-1TLS 1.3\s0 (in ClientHello or -CertificateRequest) or in a certificate request for previous versions or -\&\s-1TLS.\s0 -.IP "\fBServerInfoFile\fR" 4 -.IX Item "ServerInfoFile" -Attempts to use the file \fBvalue\fR in the \*(L"serverinfo\*(R" extension using the -function SSL_CTX_use_serverinfo_file. -.IP "\fBDHParameters\fR" 4 -.IX Item "DHParameters" -Attempts to use the file \fBvalue\fR as the set of temporary \s-1DH\s0 parameters for -the appropriate context. This option is only supported if certificate -operations are permitted. -.IP "\fBRecordPadding\fR" 4 -.IX Item "RecordPadding" -Controls use of TLSv1.3 record layer padding. \fBvalue\fR is a string of the form -\&\*(L"number[,number]\*(R" where the (required) first number is the padding block size -(in octets) for application data, and the optional second number is the padding -block size for handshake and alert messages. If the optional second number is -omitted, the same padding will be applied to all messages. -.Sp -Padding attempts to pad TLSv1.3 records so that they are a multiple of the set -length on send. A value of 0 or 1 turns off padding as relevant. Otherwise, the -values must be >1 or <=16384. -.IP "\fBSignatureAlgorithms\fR" 4 -.IX Item "SignatureAlgorithms" -This sets the supported signature algorithms for TLSv1.2 and TLSv1.3. -For clients this -value is used directly for the supported signature algorithms extension. For -servers it is used to determine which signature algorithms to support. -.Sp -The \fBvalue\fR argument should be a colon separated list of signature algorithms -in order of decreasing preference of the form \fBalgorithm+hash\fR or -\&\fBsignature_scheme\fR. For the default providers shipped with OpenSSL, -\&\fBalgorithm\fR is one of \fB\s-1RSA\s0\fR, \fB\s-1DSA\s0\fR or \fB\s-1ECDSA\s0\fR and \fBhash\fR is a supported -algorithm \s-1OID\s0 short name such as \fB\s-1SHA1\s0\fR, \fB\s-1SHA224\s0\fR, \fB\s-1SHA256\s0\fR, \fB\s-1SHA384\s0\fR -or \fB\s-1SHA512\s0\fR. -Note: algorithm and hash names are case sensitive. -\&\fBsignature_scheme\fR is one of the signature schemes defined in TLSv1.3, -specified using the \s-1IETF\s0 name, e.g., \fBecdsa_secp256r1_sha256\fR, \fBed25519\fR, -or \fBrsa_pss_pss_sha256\fR. -Additional providers may make available further algorithms via the \s-1TLS_SIGALG\s0 -capability. See \*(L"\s-1CAPABILITIES\*(R"\s0 in \fBprovider\-base\fR\|(7). -.Sp -If this option is not set then all signature algorithms supported by all -activated providers are permissible. -.Sp -Note: algorithms which specify a PKCS#1 v1.5 signature scheme (either by -using \fB\s-1RSA\s0\fR as the \fBalgorithm\fR or by using one of the \fBrsa_pkcs1_*\fR -identifiers) are ignored in TLSv1.3 and will not be negotiated. -.IP "\fBClientSignatureAlgorithms\fR" 4 -.IX Item "ClientSignatureAlgorithms" -This sets the supported signature algorithms associated with client -authentication for TLSv1.2 and TLSv1.3. -For servers the value is used in the -\&\fBsignature_algorithms\fR field of a \fBCertificateRequest\fR message. -For clients it is -used to determine which signature algorithm to use with the client certificate. -If a server does not request a certificate this option has no effect. -.Sp -The syntax of \fBvalue\fR is identical to \fBSignatureAlgorithms\fR. If not set then -the value set for \fBSignatureAlgorithms\fR will be used instead. -.IP "\fBGroups\fR" 4 -.IX Item "Groups" -This sets the supported groups. For clients, the groups are -sent using the supported groups extension. For servers, it is used -to determine which group to use. This setting affects groups used for -signatures (in TLSv1.2 and earlier) and key exchange. The first group listed -will also be used for the \fBkey_share\fR sent by a client in a TLSv1.3 -\&\fBClientHello\fR. -.Sp -The \fBvalue\fR argument is a colon separated list of groups. The group can be -either the \fB\s-1NIST\s0\fR name (e.g. \fBP\-256\fR), some other commonly used name where -applicable (e.g. \fBX25519\fR, \fBffdhe2048\fR) or an OpenSSL \s-1OID\s0 name -(e.g. \fBprime256v1\fR). Group names are case sensitive. The list should be in -order of preference with the most preferred group first. -.Sp -Currently supported groups for \fBTLSv1.3\fR are \fBP\-256\fR, \fBP\-384\fR, \fBP\-521\fR, -\&\fBX25519\fR, \fBX448\fR, \fBffdhe2048\fR, \fBffdhe3072\fR, \fBffdhe4096\fR, \fBffdhe6144\fR, -\&\fBffdhe8192\fR. -.IP "\fBCurves\fR" 4 -.IX Item "Curves" -This is a synonym for the \*(L"Groups\*(R" command. -.IP "\fBMinProtocol\fR" 4 -.IX Item "MinProtocol" -This sets the minimum supported \s-1SSL, TLS\s0 or \s-1DTLS\s0 version. -.Sp -Currently supported protocol values are \fBSSLv3\fR, \fBTLSv1\fR, \fBTLSv1.1\fR, -\&\fBTLSv1.2\fR, \fBTLSv1.3\fR, \fBDTLSv1\fR and \fBDTLSv1.2\fR. -The \s-1SSL\s0 and \s-1TLS\s0 bounds apply only to TLS-based contexts, while the \s-1DTLS\s0 bounds -apply only to DTLS-based contexts. -The command can be repeated with one instance setting a \s-1TLS\s0 bound, and the -other setting a \s-1DTLS\s0 bound. -The value \fBNone\fR applies to both types of contexts and disables the limits. -.IP "\fBMaxProtocol\fR" 4 -.IX Item "MaxProtocol" -This sets the maximum supported \s-1SSL, TLS\s0 or \s-1DTLS\s0 version. -.Sp -Currently supported protocol values are \fBSSLv3\fR, \fBTLSv1\fR, \fBTLSv1.1\fR, -\&\fBTLSv1.2\fR, \fBTLSv1.3\fR, \fBDTLSv1\fR and \fBDTLSv1.2\fR. -The \s-1SSL\s0 and \s-1TLS\s0 bounds apply only to TLS-based contexts, while the \s-1DTLS\s0 bounds -apply only to DTLS-based contexts. -The command can be repeated with one instance setting a \s-1TLS\s0 bound, and the -other setting a \s-1DTLS\s0 bound. -The value \fBNone\fR applies to both types of contexts and disables the limits. -.IP "\fBProtocol\fR" 4 -.IX Item "Protocol" -This can be used to enable or disable certain versions of the \s-1SSL, -TLS\s0 or \s-1DTLS\s0 protocol. -.Sp -The \fBvalue\fR argument is a comma separated list of supported protocols -to enable or disable. -If a protocol is preceded by \fB\-\fR that version is disabled. -.Sp -All protocol versions are enabled by default. -You need to disable at least one protocol version for this setting have any -effect. -Only enabling some protocol versions does not disable the other protocol -versions. -.Sp -Currently supported protocol values are \fBSSLv3\fR, \fBTLSv1\fR, \fBTLSv1.1\fR, -\&\fBTLSv1.2\fR, \fBTLSv1.3\fR, \fBDTLSv1\fR and \fBDTLSv1.2\fR. -The special value \fB\s-1ALL\s0\fR refers to all supported versions. -.Sp -This can't enable protocols that are disabled using \fBMinProtocol\fR -or \fBMaxProtocol\fR, but can disable protocols that are still allowed -by them. -.Sp -The \fBProtocol\fR command is fragile and deprecated; do not use it. -Use \fBMinProtocol\fR and \fBMaxProtocol\fR instead. -If you do use \fBProtocol\fR, make sure that the resulting range of enabled -protocols has no \*(L"holes\*(R", e.g. if \s-1TLS 1.0\s0 and \s-1TLS 1.2\s0 are both enabled, make -sure to also leave \s-1TLS 1.1\s0 enabled. -.IP "\fBOptions\fR" 4 -.IX Item "Options" -The \fBvalue\fR argument is a comma separated list of various flags to set. -If a flag string is preceded \fB\-\fR it is disabled. -See the \fBSSL_CTX_set_options\fR\|(3) function for more details of -individual options. -.Sp -Each option is listed below. Where an operation is enabled by default -the \fB\-flag\fR syntax is needed to disable it. -.Sp -\&\fBSessionTicket\fR: session ticket support, enabled by default. Inverse of -\&\fB\s-1SSL_OP_NO_TICKET\s0\fR: that is \fB\-SessionTicket\fR is the same as setting -\&\fB\s-1SSL_OP_NO_TICKET\s0\fR. -.Sp -\&\fBCompression\fR: \s-1SSL/TLS\s0 compression support, disabled by default. Inverse -of \fB\s-1SSL_OP_NO_COMPRESSION\s0\fR. -.Sp -\&\fBEmptyFragments\fR: use empty fragments as a countermeasure against a -\&\s-1SSL 3.0/TLS 1.0\s0 protocol vulnerability affecting \s-1CBC\s0 ciphers. It -is set by default. Inverse of \fB\s-1SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS\s0\fR. -.Sp -\&\fBBugs\fR: enable various bug workarounds. Same as \fB\s-1SSL_OP_ALL\s0\fR. -.Sp -\&\fBDHSingle\fR: enable single use \s-1DH\s0 keys, set by default. Inverse of -\&\fB\s-1SSL_OP_DH_SINGLE\s0\fR. Only used by servers. -.Sp -\&\fBECDHSingle\fR: enable single use \s-1ECDH\s0 keys, set by default. Inverse of -\&\fB\s-1SSL_OP_ECDH_SINGLE\s0\fR. Only used by servers. -.Sp -\&\fBServerPreference\fR: use server and not client preference order when -determining which cipher suite, signature algorithm or elliptic curve -to use for an incoming connection. Equivalent to -\&\fB\s-1SSL_OP_CIPHER_SERVER_PREFERENCE\s0\fR. Only used by servers. -.Sp -\&\fBPrioritizeChaCha\fR: prioritizes ChaCha ciphers when the client has a -ChaCha20 cipher at the top of its preference list. This usually indicates -a mobile client is in use. Equivalent to \fB\s-1SSL_OP_PRIORITIZE_CHACHA\s0\fR. -Only used by servers. -.Sp -\&\fBNoResumptionOnRenegotiation\fR: set -\&\fB\s-1SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION\s0\fR flag. Only used by servers. -.Sp -\&\fBNoRenegotiation\fR: disables all attempts at renegotiation in TLSv1.2 and -earlier, same as setting \fB\s-1SSL_OP_NO_RENEGOTIATION\s0\fR. -.Sp -\&\fBUnsafeLegacyRenegotiation\fR: permits the use of unsafe legacy renegotiation. -Equivalent to \fB\s-1SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION\s0\fR. -.Sp -\&\fBUnsafeLegacyServerConnect\fR: permits the use of unsafe legacy renegotiation -for OpenSSL clients only. Equivalent to \fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR. -.Sp -\&\fBEncryptThenMac\fR: use encrypt-then-mac extension, enabled by -default. Inverse of \fB\s-1SSL_OP_NO_ENCRYPT_THEN_MAC\s0\fR: that is, -\&\fB\-EncryptThenMac\fR is the same as setting \fB\s-1SSL_OP_NO_ENCRYPT_THEN_MAC\s0\fR. -.Sp -\&\fBAllowNoDHEKEX\fR: In TLSv1.3 allow a non\-(ec)dhe based key exchange mode on -resumption. This means that there will be no forward secrecy for the resumed -session. Equivalent to \fB\s-1SSL_OP_ALLOW_NO_DHE_KEX\s0\fR. -.Sp -\&\fBPreferNoDHEKEX\fR: In TLSv1.3, on resumption let the server prefer a -non\-(ec)dhe based key exchange mode over an (ec)dhe based one. Requires -\&\fBAllowNoDHEKEX\fR. Equivalent to \fB\s-1SSL_OP_PREFER_NO_DHE_KEX\s0\fR. Only used by -servers. -.Sp -\&\fBMiddleboxCompat\fR: If set then dummy Change Cipher Spec (\s-1CCS\s0) messages are sent -in TLSv1.3. This has the effect of making TLSv1.3 look more like TLSv1.2 so that -middleboxes that do not understand TLSv1.3 will not drop the connection. This -option is set by default. A future version of OpenSSL may not set this by -default. Equivalent to \fB\s-1SSL_OP_ENABLE_MIDDLEBOX_COMPAT\s0\fR. -.Sp -\&\fBAntiReplay\fR: If set then OpenSSL will automatically detect if a session ticket -has been used more than once, TLSv1.3 has been negotiated, and early data is -enabled on the server. A full handshake is forced if a session ticket is used a -second or subsequent time. This option is set by default and is only used by -servers. Anti-replay measures are required to comply with the TLSv1.3 -specification. Some applications may be able to mitigate the replay risks in -other ways and in such cases the built-in OpenSSL functionality is not required. -Disabling anti-replay is equivalent to setting \fB\s-1SSL_OP_NO_ANTI_REPLAY\s0\fR. -.Sp -\&\fBExtendedMasterSecret\fR: use extended master secret extension, enabled by -default. Inverse of \fB\s-1SSL_OP_NO_EXTENDED_MASTER_SECRET\s0\fR: that is, -\&\fB\-ExtendedMasterSecret\fR is the same as setting \fB\s-1SSL_OP_NO_EXTENDED_MASTER_SECRET\s0\fR. -.Sp -\&\fBCANames\fR: use \s-1CA\s0 names extension, enabled by -default. Inverse of \fB\s-1SSL_OP_DISABLE_TLSEXT_CA_NAMES\s0\fR: that is, -\&\fB\-CANames\fR is the same as setting \fB\s-1SSL_OP_DISABLE_TLSEXT_CA_NAMES\s0\fR. -.Sp -\&\fB\s-1KTLS\s0\fR: Enables kernel \s-1TLS\s0 if support has been compiled in, and it is supported -by the negotiated ciphersuites and extensions. Equivalent to -\&\fB\s-1SSL_OP_ENABLE_KTLS\s0\fR. -.Sp -\&\fBStrictCertCheck\fR: Enable strict certificate checking. Equivalent to -setting \fB\s-1SSL_CERT_FLAG_TLS_STRICT\s0\fR with \fBSSL_CTX_set_cert_flags()\fR. -.Sp -\&\fBTxCertificateCompression\fR: support sending compressed certificates, enabled by -default. Inverse of \fB\s-1SSL_OP_NO_TX_CERTIFICATE_COMPRESSION\s0\fR: that is, -\&\fB\-TxCertificateCompression\fR is the same as setting \fB\s-1SSL_OP_NO_TX_CERTIFICATE_COMPRESSION\s0\fR. -.Sp -\&\fBRxCertificateCompression\fR: support receiving compressed certificates, enabled by -default. Inverse of \fB\s-1SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\s0\fR: that is, -\&\fB\-RxCertificateCompression\fR is the same as setting \fB\s-1SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\s0\fR. -.Sp -\&\fBKTLSTxZerocopySendfile\fR: use the zerocopy \s-1TX\s0 mode of \fBsendfile()\fR, which gives -a performance boost when used with \s-1KTLS\s0 hardware offload. Note that invalid \s-1TLS\s0 -records might be transmitted if the file is changed while being sent. This -option has no effect if \fB\s-1KTLS\s0\fR is not enabled. Equivalent to -\&\fB\s-1SSL_OP_ENABLE_KTLS_TX_ZEROCOPY_SENDFILE\s0\fR. This option only applies to Linux. -\&\s-1KTLS\s0 sendfile on FreeBSD doesn't offer an option to disable zerocopy and -always runs in this mode. -.Sp -\&\fBIgnoreUnexpectedEOF\fR: Equivalent to \fB\s-1SSL_OP_IGNORE_UNEXPECTED_EOF\s0\fR. -You should only enable this option if the protocol running over \s-1TLS\s0 can detect -a truncation attack itself, and that the application is checking for that -truncation attack. -.IP "\fBVerifyMode\fR" 4 -.IX Item "VerifyMode" -The \fBvalue\fR argument is a comma separated list of flags to set. -.Sp -\&\fBPeer\fR enables peer verification: for clients only. -.Sp -\&\fBRequest\fR requests but does not require a certificate from the client. -Servers only. -.Sp -\&\fBRequire\fR requests and requires a certificate from the client: an error -occurs if the client does not present a certificate. Servers only. -.Sp -\&\fBOnce\fR requests a certificate from a client only on the initial connection: -not when renegotiating. Servers only. -.Sp -\&\fBRequestPostHandshake\fR configures the connection to support requests but does -not require a certificate from the client post-handshake. A certificate will -not be requested during the initial handshake. The server application must -provide a mechanism to request a certificate post-handshake. Servers only. -TLSv1.3 only. -.Sp -\&\fBRequiresPostHandshake\fR configures the connection to support requests and -requires a certificate from the client post-handshake: an error occurs if the -client does not present a certificate. A certificate will not be requested -during the initial handshake. The server application must provide a mechanism -to request a certificate post-handshake. Servers only. TLSv1.3 only. -.IP "\fBClientCAFile\fR, \fBClientCAPath\fR" 4 -.IX Item "ClientCAFile, ClientCAPath" -A file or directory of certificates in \s-1PEM\s0 format whose names are used as the -set of acceptable names for client CAs. Servers only. This option is only -supported if certificate operations are permitted. -.SH "SUPPORTED COMMAND TYPES" -.IX Header "SUPPORTED COMMAND TYPES" -The function \fBSSL_CONF_cmd_value_type()\fR currently returns one of the following -types: -.IP "\fB\s-1SSL_CONF_TYPE_UNKNOWN\s0\fR" 4 -.IX Item "SSL_CONF_TYPE_UNKNOWN" -The \fBoption\fR string is unrecognised, this return value can be use to flag -syntax errors. -.IP "\fB\s-1SSL_CONF_TYPE_STRING\s0\fR" 4 -.IX Item "SSL_CONF_TYPE_STRING" -The value is a string without any specific structure. -.IP "\fB\s-1SSL_CONF_TYPE_FILE\s0\fR" 4 -.IX Item "SSL_CONF_TYPE_FILE" -The value is a filename. -.IP "\fB\s-1SSL_CONF_TYPE_DIR\s0\fR" 4 -.IX Item "SSL_CONF_TYPE_DIR" -The value is a directory name. -.IP "\fB\s-1SSL_CONF_TYPE_NONE\s0\fR" 4 -.IX Item "SSL_CONF_TYPE_NONE" -The value string is not used e.g. a command line option which doesn't take an -argument. -.SH "NOTES" -.IX Header "NOTES" -The order of operations is significant. This can be used to set either defaults -or values which cannot be overridden. For example if an application calls: -.PP -.Vb 2 -\& SSL_CONF_cmd(ctx, "Protocol", "\-SSLv3"); -\& SSL_CONF_cmd(ctx, userparam, uservalue); -.Ve -.PP -it will disable SSLv3 support by default but the user can override it. If -however the call sequence is: -.PP -.Vb 2 -\& SSL_CONF_cmd(ctx, userparam, uservalue); -\& SSL_CONF_cmd(ctx, "Protocol", "\-SSLv3"); -.Ve -.PP -SSLv3 is \fBalways\fR disabled and attempt to override this by the user are -ignored. -.PP -By checking the return code of \fBSSL_CONF_cmd()\fR it is possible to query if a -given \fBoption\fR is recognised, this is useful if \fBSSL_CONF_cmd()\fR values are -mixed with additional application specific operations. -.PP -For example an application might call \fBSSL_CONF_cmd()\fR and if it returns -\&\-2 (unrecognised command) continue with processing of application specific -commands. -.PP -Applications can also use \fBSSL_CONF_cmd()\fR to process command lines though the -utility function \fBSSL_CONF_cmd_argv()\fR is normally used instead. One way -to do this is to set the prefix to an appropriate value using -\&\fBSSL_CONF_CTX_set1_prefix()\fR, pass the current argument to \fBoption\fR and the -following argument to \fBvalue\fR (which may be \s-1NULL\s0). -.PP -In this case if the return value is positive then it is used to skip that -number of arguments as they have been processed by \fBSSL_CONF_cmd()\fR. If \-2 is -returned then \fBoption\fR is not recognised and application specific arguments -can be checked instead. If \-3 is returned a required argument is missing -and an error is indicated. If 0 is returned some other error occurred and -this can be reported back to the user. -.PP -The function \fBSSL_CONF_cmd_value_type()\fR can be used by applications to -check for the existence of a command or to perform additional syntax -checking or translation of the command value. For example if the return -value is \fB\s-1SSL_CONF_TYPE_FILE\s0\fR an application could translate a relative -pathname to an absolute pathname. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CONF_cmd()\fR returns 1 if the value of \fBoption\fR is recognised and \fBvalue\fR is -\&\fB\s-1NOT\s0\fR used and 2 if both \fBoption\fR and \fBvalue\fR are used. In other words it -returns the number of arguments processed. This is useful when processing -command lines. -.PP -A return value of \-2 means \fBoption\fR is not recognised. -.PP -A return value of \-3 means \fBoption\fR is recognised and the command requires a -value but \fBvalue\fR is \s-1NULL.\s0 -.PP -A return code of 0 indicates that both \fBoption\fR and \fBvalue\fR are valid but an -error occurred attempting to perform the operation: for example due to an -error in the syntax of \fBvalue\fR in this case the error queue may provide -additional information. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Set supported signature algorithms: -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "SignatureAlgorithms", "ECDSA+SHA256:RSA+SHA256:DSA+SHA256"); -.Ve -.PP -There are various ways to select the supported protocols. -.PP -This set the minimum protocol version to TLSv1, and so disables SSLv3. -This is the recommended way to disable protocols. -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "MinProtocol", "TLSv1"); -.Ve -.PP -The following also disables SSLv3: -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "Protocol", "\-SSLv3"); -.Ve -.PP -The following will first enable all protocols, and then disable -SSLv3. -If no protocol versions were disabled before this has the same effect as -\&\*(L"\-SSLv3\*(R", but if some versions were disables this will re-enable them before -disabling SSLv3. -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "Protocol", "ALL,\-SSLv3"); -.Ve -.PP -Only enable TLSv1.2: -.PP -.Vb 2 -\& SSL_CONF_cmd(ctx, "MinProtocol", "TLSv1.2"); -\& SSL_CONF_cmd(ctx, "MaxProtocol", "TLSv1.2"); -.Ve -.PP -This also only enables TLSv1.2: -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "Protocol", "\-ALL,TLSv1.2"); -.Ve -.PP -Disable \s-1TLS\s0 session tickets: -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "Options", "\-SessionTicket"); -.Ve -.PP -Enable compression: -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "Options", "Compression"); -.Ve -.PP -Set supported curves to P\-256, P\-384: -.PP -.Vb 1 -\& SSL_CONF_cmd(ctx, "Curves", "P\-256:P\-384"); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CONF_CTX_new\fR\|(3), -\&\fBSSL_CONF_CTX_set_flags\fR\|(3), -\&\fBSSL_CONF_CTX_set1_prefix\fR\|(3), -\&\fBSSL_CONF_CTX_set_ssl_ctx\fR\|(3), -\&\fBSSL_CONF_cmd_argv\fR\|(3), -\&\fBSSL_CTX_set_options\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_CONF_cmd()\fR function was added in OpenSSL 1.0.2. -.PP -The \fB\s-1SSL_OP_NO_SSL2\s0\fR option doesn't have effect since 1.1.0, but the macro -is retained for backwards compatibility. -.PP -The \fB\s-1SSL_CONF_TYPE_NONE\s0\fR was added in OpenSSL 1.1.0. In earlier versions of -OpenSSL passing a command which didn't take an argument would return -\&\fB\s-1SSL_CONF_TYPE_UNKNOWN\s0\fR. -.PP -\&\fBMinProtocol\fR and \fBMaxProtocol\fR where added in OpenSSL 1.1.0. -.PP -\&\fBAllowNoDHEKEX\fR and \fBPrioritizeChaCha\fR were added in OpenSSL 1.1.1. -.PP -The \fBUnsafeLegacyServerConnect\fR option is no longer set by default from -OpenSSL 3.0. -.PP -The \fBTxCertificateCompression\fR and \fBRxCertificateCompression\fR options were -added in OpenSSL 3.2. -.PP -\&\fBPreferNoDHEKEX\fR was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2012\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CONF_cmd_argv.3ossl b/openssl-install/share/man/man3/SSL_CONF_cmd_argv.3ossl deleted file mode 100644 index a6fe2db4..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_cmd_argv.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CONF_CMD_ARGV 3ossl" -.TH SSL_CONF_CMD_ARGV 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CONF_cmd_argv \- SSL configuration command line processing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CONF_cmd_argv(SSL_CONF_CTX *cctx, int *pargc, char ***pargv); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBSSL_CONF_cmd_argv()\fR processes at most two command line -arguments from \fBpargv\fR and \fBpargc\fR. The values of \fBpargv\fR and \fBpargc\fR -are updated to reflect the number of command options processed. The \fBpargc\fR -argument can be set to \fB\s-1NULL\s0\fR if it is not used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CONF_cmd_argv()\fR returns the number of command arguments processed: 0, 1, 2 -or a negative error code. -.PP -If \-2 is returned then an argument for a command is missing. -.PP -If \-1 is returned the command is recognised but couldn't be processed due -to an error: for example a syntax error in the argument. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CONF_CTX_new\fR\|(3), -\&\fBSSL_CONF_CTX_set_flags\fR\|(3), -\&\fBSSL_CONF_CTX_set1_prefix\fR\|(3), -\&\fBSSL_CONF_CTX_set_ssl_ctx\fR\|(3), -\&\fBSSL_CONF_cmd\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2012\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CONF_cmd_value_type.3ossl b/openssl-install/share/man/man3/SSL_CONF_cmd_value_type.3ossl deleted file mode 120000 index 6766219b..00000000 --- a/openssl-install/share/man/man3/SSL_CONF_cmd_value_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CONF_cmd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_LOCAL.3ossl b/openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_LOCAL.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_LOCAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_TRANSPORT.3ossl b/openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_TRANSPORT.3ossl deleted file mode 120000 index 896018f5..00000000 --- a/openssl-install/share/man/man3/SSL_CONN_CLOSE_FLAG_TRANSPORT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_conn_close_info.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_add0_chain_cert.3ossl b/openssl-install/share/man/man3/SSL_CTX_add0_chain_cert.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add0_chain_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_add1_chain_cert.3ossl b/openssl-install/share/man/man3/SSL_CTX_add1_chain_cert.3ossl deleted file mode 100644 index 2623b5e9..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add1_chain_cert.3ossl +++ /dev/null @@ -1,292 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_ADD1_CHAIN_CERT 3ossl" -.TH SSL_CTX_ADD1_CHAIN_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set0_chain, SSL_CTX_set1_chain, SSL_CTX_add0_chain_cert, -SSL_CTX_add1_chain_cert, SSL_CTX_get0_chain_certs, SSL_CTX_clear_chain_certs, -SSL_set0_chain, SSL_set1_chain, SSL_add0_chain_cert, SSL_add1_chain_cert, -SSL_get0_chain_certs, SSL_clear_chain_certs, SSL_CTX_build_cert_chain, -SSL_build_cert_chain, SSL_CTX_select_current_cert, -SSL_select_current_cert, SSL_CTX_set_current_cert, SSL_set_current_cert \- extra -chain certificate processing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set0_chain(SSL_CTX *ctx, STACK_OF(X509) *sk); -\& int SSL_CTX_set1_chain(SSL_CTX *ctx, STACK_OF(X509) *sk); -\& int SSL_CTX_add0_chain_cert(SSL_CTX *ctx, X509 *x509); -\& int SSL_CTX_add1_chain_cert(SSL_CTX *ctx, X509 *x509); -\& int SSL_CTX_get0_chain_certs(SSL_CTX *ctx, STACK_OF(X509) **sk); -\& int SSL_CTX_clear_chain_certs(SSL_CTX *ctx); -\& -\& int SSL_set0_chain(SSL *ssl, STACK_OF(X509) *sk); -\& int SSL_set1_chain(SSL *ssl, STACK_OF(X509) *sk); -\& int SSL_add0_chain_cert(SSL *ssl, X509 *x509); -\& int SSL_add1_chain_cert(SSL *ssl, X509 *x509); -\& int SSL_get0_chain_certs(SSL *ssl, STACK_OF(X509) **sk); -\& int SSL_clear_chain_certs(SSL *ssl); -\& -\& int SSL_CTX_build_cert_chain(SSL_CTX *ctx, flags); -\& int SSL_build_cert_chain(SSL *ssl, flags); -\& -\& int SSL_CTX_select_current_cert(SSL_CTX *ctx, X509 *x509); -\& int SSL_select_current_cert(SSL *ssl, X509 *x509); -\& int SSL_CTX_set_current_cert(SSL_CTX *ctx, long op); -\& int SSL_set_current_cert(SSL *ssl, long op); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set0_chain()\fR and \fBSSL_CTX_set1_chain()\fR set the certificate chain -associated with the current certificate of \fBctx\fR to \fBsk\fR. -.PP -\&\fBSSL_CTX_add0_chain_cert()\fR and \fBSSL_CTX_add1_chain_cert()\fR append the single -certificate \fBx509\fR to the chain associated with the current certificate of -\&\fBctx\fR. -.PP -\&\fBSSL_CTX_get0_chain_certs()\fR retrieves the chain associated with the current -certificate of \fBctx\fR. -.PP -\&\fBSSL_CTX_clear_chain_certs()\fR clears any existing chain associated with the -current certificate of \fBctx\fR. (This is implemented by calling -\&\fBSSL_CTX_set0_chain()\fR with \fBsk\fR set to \fB\s-1NULL\s0\fR). -.PP -\&\fBSSL_CTX_build_cert_chain()\fR builds the certificate chain for \fBctx\fR. -Normally this uses the chain store -or the verify store if the chain store is not set. -If the function is successful the built chain will replace any existing chain. -The \fBflags\fR parameter can be set to \fB\s-1SSL_BUILD_CHAIN_FLAG_UNTRUSTED\s0\fR to use -existing chain certificates as untrusted CAs, \fB\s-1SSL_BUILD_CHAIN_FLAG_NO_ROOT\s0\fR -to omit the root \s-1CA\s0 from the built chain, \fB\s-1SSL_BUILD_CHAIN_FLAG_CHECK\s0\fR to -use all existing chain certificates only to build the chain (effectively -sanity checking and rearranging them if necessary), the flag -\&\fB\s-1SSL_BUILD_CHAIN_FLAG_IGNORE_ERROR\s0\fR ignores any errors during verification: -if flag \fB\s-1SSL_BUILD_CHAIN_FLAG_CLEAR_ERROR\s0\fR is also set verification errors -are cleared from the error queue. -Details of the chain building process are described in -\&\*(L"Certification Path Building\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.PP -Each of these functions operates on the \fIcurrent\fR end entity -(i.e. server or client) certificate. This is the last certificate loaded or -selected on the corresponding \fBctx\fR structure. -.PP -\&\fBSSL_CTX_select_current_cert()\fR selects \fBx509\fR as the current end entity -certificate, but only if \fBx509\fR has already been loaded into \fBctx\fR using a -function such as \fBSSL_CTX_use_certificate()\fR. -.PP -\&\fBSSL_set0_chain()\fR, \fBSSL_set1_chain()\fR, \fBSSL_add0_chain_cert()\fR, -\&\fBSSL_add1_chain_cert()\fR, \fBSSL_get0_chain_certs()\fR, \fBSSL_clear_chain_certs()\fR, -\&\fBSSL_build_cert_chain()\fR, \fBSSL_select_current_cert()\fR and \fBSSL_set_current_cert()\fR -are similar except they apply to \s-1SSL\s0 structure \fBssl\fR. -.PP -\&\fBSSL_CTX_set_current_cert()\fR changes the current certificate to a value based -on the \fBop\fR argument. Currently \fBop\fR can be \fB\s-1SSL_CERT_SET_FIRST\s0\fR to use -the first valid certificate or \fB\s-1SSL_CERT_SET_NEXT\s0\fR to set the next valid -certificate after the current certificate. These two operations can be -used to iterate over all certificates in an \fB\s-1SSL_CTX\s0\fR structure. -.PP -\&\fBSSL_set_current_cert()\fR also supports the option \fB\s-1SSL_CERT_SET_SERVER\s0\fR. -If \fBssl\fR is a server and has sent a certificate to a connected client -this option sets that certificate to the current certificate and returns 1. -If the negotiated cipher suite is anonymous (and thus no certificate will -be sent) 2 is returned and the current certificate is unchanged. If \fBssl\fR -is not a server or a certificate has not been sent 0 is returned and -the current certificate is unchanged. -.PP -All these functions are implemented as macros. Those containing a \fB1\fR -increment the reference count of the supplied certificate or chain so it must -be freed at some point after the operation. Those containing a \fB0\fR do -not increment reference counts and the supplied certificate or chain -\&\fB\s-1MUST NOT\s0\fR be freed after the operation. -.SH "NOTES" -.IX Header "NOTES" -The chains associate with an \s-1SSL_CTX\s0 structure are copied to any \s-1SSL\s0 -structures when \fBSSL_new()\fR is called. \s-1SSL\s0 structures will not be affected -by any chains subsequently changed in the parent \s-1SSL_CTX.\s0 -.PP -One chain can be set for each key type supported by a server. So, for example, -an \s-1RSA\s0 and a \s-1DSA\s0 certificate can (and often will) have different chains. -.PP -The functions \fBSSL_CTX_build_cert_chain()\fR and \fBSSL_build_cert_chain()\fR can -be used to check application configuration and to ensure any necessary -subordinate CAs are sent in the correct order. Misconfigured applications -sending incorrect certificate chains often cause problems with peers. -.PP -For example an application can add any set of certificates using -\&\fBSSL_CTX_use_certificate_chain_file()\fR then call \fBSSL_CTX_build_cert_chain()\fR -with the option \fB\s-1SSL_BUILD_CHAIN_FLAG_CHECK\s0\fR to check and reorder them. -.PP -Applications can issue non fatal warnings when checking chains by setting -the flag \fB\s-1SSL_BUILD_CHAIN_FLAG_IGNORE_ERRORS\s0\fR and checking the return -value. -.PP -Calling \fBSSL_CTX_build_cert_chain()\fR or \fBSSL_build_cert_chain()\fR is more -efficient than the automatic chain building as it is only performed once. -Automatic chain building is performed on each new session. -.PP -If any certificates are added using these functions no certificates added -using \fBSSL_CTX_add_extra_chain_cert()\fR will be used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_current_cert()\fR with \fB\s-1SSL_CERT_SET_SERVER\s0\fR return 1 for success, 2 if -no server certificate is used because the cipher suites is anonymous and 0 -for failure. -.PP -\&\fBSSL_CTX_build_cert_chain()\fR and \fBSSL_build_cert_chain()\fR return 1 for success -and 0 for failure. If the flag \fB\s-1SSL_BUILD_CHAIN_FLAG_IGNORE_ERROR\s0\fR and -a verification error occurs then 2 is returned. -.PP -All other functions return 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_add1_to_CA_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_add1_to_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add1_to_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_add_client_CA.3ossl b/openssl-install/share/man/man3/SSL_CTX_add_client_CA.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add_client_CA.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_add_client_custom_ext.3ossl b/openssl-install/share/man/man3/SSL_CTX_add_client_custom_ext.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add_client_custom_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_add_custom_ext.3ossl b/openssl-install/share/man/man3/SSL_CTX_add_custom_ext.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add_custom_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_add_extra_chain_cert.3ossl b/openssl-install/share/man/man3/SSL_CTX_add_extra_chain_cert.3ossl deleted file mode 100644 index 3ef7a6a4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add_extra_chain_cert.3ossl +++ /dev/null @@ -1,224 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_ADD_EXTRA_CHAIN_CERT 3ossl" -.TH SSL_CTX_ADD_EXTRA_CHAIN_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_add_extra_chain_cert, -SSL_CTX_get_extra_chain_certs, -SSL_CTX_get_extra_chain_certs_only, -SSL_CTX_clear_extra_chain_certs -\&\- add, get or clear extra chain certificates -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_add_extra_chain_cert(SSL_CTX *ctx, X509 *x509); -\& long SSL_CTX_get_extra_chain_certs(SSL_CTX *ctx, STACK_OF(X509) **sk); -\& long SSL_CTX_get_extra_chain_certs_only(SSL_CTX *ctx, STACK_OF(X509) **sk); -\& long SSL_CTX_clear_extra_chain_certs(SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_add_extra_chain_cert()\fR adds the certificate \fBx509\fR to the extra chain -certificates associated with \fBctx\fR. Several certificates can be added one -after another. -.PP -\&\fBSSL_CTX_get_extra_chain_certs()\fR retrieves the extra chain certificates -associated with \fBctx\fR, or the chain associated with the current certificate -of \fBctx\fR if the extra chain is empty. -The returned stack should not be freed by the caller. -.PP -\&\fBSSL_CTX_get_extra_chain_certs_only()\fR retrieves the extra chain certificates -associated with \fBctx\fR. -The returned stack should not be freed by the caller. -.PP -\&\fBSSL_CTX_clear_extra_chain_certs()\fR clears all extra chain certificates -associated with \fBctx\fR. -.PP -These functions are implemented as macros. -.SH "NOTES" -.IX Header "NOTES" -When sending a certificate chain, extra chain certificates are sent in order -following the end entity certificate. -.PP -If no chain is specified, the library will try to complete the chain from the -available \s-1CA\s0 certificates in the trusted \s-1CA\s0 storage, see -\&\fBSSL_CTX_load_verify_locations\fR\|(3). -.PP -The \fBx509\fR certificate provided to \fBSSL_CTX_add_extra_chain_cert()\fR will be -freed by the library when the \fB\s-1SSL_CTX\s0\fR is destroyed. An application -\&\fBshould not\fR free the \fBx509\fR object. -.SH "RESTRICTIONS" -.IX Header "RESTRICTIONS" -Only one set of extra chain certificates can be specified per \s-1SSL_CTX\s0 -structure. Different chains for different certificates (for example if both -\&\s-1RSA\s0 and \s-1DSA\s0 certificates are specified by the same server) or different \s-1SSL\s0 -structures with the same parent \s-1SSL_CTX\s0 cannot be specified using this -function. For more flexibility functions such as \fBSSL_add1_chain_cert()\fR should -be used instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_add_extra_chain_cert()\fR and \fBSSL_CTX_clear_extra_chain_certs()\fR return -1 on success and 0 for failure. Check out the error stack to find out the -reason for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_use_certificate\fR\|(3), -\&\fBSSL_CTX_set_client_cert_cb\fR\|(3), -\&\fBSSL_CTX_load_verify_locations\fR\|(3) -\&\fBSSL_CTX_set0_chain\fR\|(3) -\&\fBSSL_CTX_set1_chain\fR\|(3) -\&\fBSSL_CTX_add0_chain_cert\fR\|(3) -\&\fBSSL_CTX_add1_chain_cert\fR\|(3) -\&\fBSSL_set0_chain\fR\|(3) -\&\fBSSL_set1_chain\fR\|(3) -\&\fBSSL_add0_chain_cert\fR\|(3) -\&\fBSSL_add1_chain_cert\fR\|(3) -\&\fBSSL_CTX_build_cert_chain\fR\|(3) -\&\fBSSL_build_cert_chain\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_add_server_custom_ext.3ossl b/openssl-install/share/man/man3/SSL_CTX_add_server_custom_ext.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add_server_custom_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_add_session.3ossl b/openssl-install/share/man/man3/SSL_CTX_add_session.3ossl deleted file mode 100644 index 5ccfdf62..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_add_session.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_ADD_SESSION 3ossl" -.TH SSL_CTX_ADD_SESSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_add_session, SSL_CTX_remove_session \- manipulate session cache -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_add_session(SSL_CTX *ctx, SSL_SESSION *c); -\& -\& int SSL_CTX_remove_session(SSL_CTX *ctx, SSL_SESSION *c); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_add_session()\fR adds the session \fBc\fR to the context \fBctx\fR. The -reference count for session \fBc\fR is incremented by 1. If a session with -the same session id already exists, the old session is removed by calling -\&\fBSSL_SESSION_free\fR\|(3). -.PP -\&\fBSSL_CTX_remove_session()\fR removes the session \fBc\fR from the context \fBctx\fR and -marks it as non-resumable. \fBSSL_SESSION_free\fR\|(3) is called once for \fBc\fR. -.SH "NOTES" -.IX Header "NOTES" -When adding a new session to the internal session cache, it is examined -whether a session with the same session id already exists. In this case -it is assumed that both sessions are identical. If the same session is -stored in a different \s-1SSL_SESSION\s0 object, The old session is -removed and replaced by the new session. If the session is actually -identical (the \s-1SSL_SESSION\s0 object is identical), \fBSSL_CTX_add_session()\fR -is a no-op, and the return value is 0. -.PP -If a server \s-1SSL_CTX\s0 is configured with the \s-1SSL_SESS_CACHE_NO_INTERNAL_STORE\s0 -flag then the internal cache will not be populated automatically by new -sessions negotiated by the \s-1SSL/TLS\s0 implementation, even though the internal -cache will be searched automatically for session-resume requests (the -latter can be suppressed by \s-1SSL_SESS_CACHE_NO_INTERNAL_LOOKUP\s0). So the -application can use \fBSSL_CTX_add_session()\fR directly to have full control -over the sessions that can be resumed if desired. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following values are returned by all functions: -.IP "0" 4 -The operation failed. In case of the add operation, it was tried to add -the same (identical) session twice. In case of the remove operation, the -session was not found in the cache. -.IP "1" 4 -.IX Item "1" -The operation succeeded. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -\&\fBSSL_SESSION_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_build_cert_chain.3ossl b/openssl-install/share/man/man3/SSL_CTX_build_cert_chain.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_build_cert_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_callback_ctrl.3ossl b/openssl-install/share/man/man3/SSL_CTX_callback_ctrl.3ossl deleted file mode 120000 index 0dbfa7e7..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_callback_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_check_private_key.3ossl b/openssl-install/share/man/man3/SSL_CTX_check_private_key.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_check_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_clear_chain_certs.3ossl b/openssl-install/share/man/man3/SSL_CTX_clear_chain_certs.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_clear_chain_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_clear_extra_chain_certs.3ossl b/openssl-install/share/man/man3/SSL_CTX_clear_extra_chain_certs.3ossl deleted file mode 120000 index 0b6a1e06..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_clear_extra_chain_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add_extra_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_clear_mode.3ossl b/openssl-install/share/man/man3/SSL_CTX_clear_mode.3ossl deleted file mode 120000 index ea309712..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_clear_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_clear_options.3ossl b/openssl-install/share/man/man3/SSL_CTX_clear_options.3ossl deleted file mode 120000 index 742650be..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_clear_options.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_options.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_compress_certs.3ossl b/openssl-install/share/man/man3/SSL_CTX_compress_certs.3ossl deleted file mode 120000 index 7aaf058c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_compress_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_cert_comp_preference.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_config.3ossl b/openssl-install/share/man/man3/SSL_CTX_config.3ossl deleted file mode 100644 index 7ccf8463..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_config.3ossl +++ /dev/null @@ -1,224 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_CONFIG 3ossl" -.TH SSL_CTX_CONFIG 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_config, SSL_config \- configure SSL_CTX or SSL structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_config(SSL_CTX *ctx, const char *name); -\& int SSL_config(SSL *s, const char *name); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions \fBSSL_CTX_config()\fR and \fBSSL_config()\fR configure an \fB\s-1SSL_CTX\s0\fR or -\&\fB\s-1SSL\s0\fR structure using the configuration \fBname\fR. -.PP -By calling \fBSSL_CTX_config()\fR or \fBSSL_config()\fR an application can perform many -complex tasks based on the contents of the configuration file: greatly -simplifying application configuration code. A degree of future proofing -can also be achieved: an application can support configuration features -in newer versions of OpenSSL automatically. -.PP -A configuration file must have been previously loaded, for example using -\&\fBCONF_modules_load_file()\fR. See \fBconfig\fR\|(5) for details of the configuration -file syntax. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_config()\fR and \fBSSL_config()\fR return 1 for success or 0 if an error -occurred. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -If the file \*(L"config.cnf\*(R" contains the following: -.PP -.Vb 1 -\& testapp = test_sect -\& -\& [test_sect] -\& # list of configuration modules -\& -\& ssl_conf = ssl_sect -\& -\& [ssl_sect] -\& server = server_section -\& -\& [server_section] -\& RSA.Certificate = server\-rsa.pem -\& ECDSA.Certificate = server\-ecdsa.pem -\& Ciphers = ALL:!RC4 -.Ve -.PP -An application could call: -.PP -.Vb 4 -\& if (CONF_modules_load_file("config.cnf", "testapp", 0) <= 0) { -\& fprintf(stderr, "Error processing config file\en"); -\& goto err; -\& } -\& -\& ctx = SSL_CTX_new(TLS_server_method()); -\& -\& if (SSL_CTX_config(ctx, "server") == 0) { -\& fprintf(stderr, "Error configuring server.\en"); -\& goto err; -\& } -.Ve -.PP -In this example two certificates and the cipher list are configured without -the need for any additional application code. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBconfig\fR\|(5), -\&\fBSSL_CONF_cmd\fR\|(3), -\&\fBCONF_modules_load_file\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_CTX_config()\fR and \fBSSL_config()\fR functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_ct_is_enabled.3ossl b/openssl-install/share/man/man3/SSL_CTX_ct_is_enabled.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_ct_is_enabled.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_ctrl.3ossl b/openssl-install/share/man/man3/SSL_CTX_ctrl.3ossl deleted file mode 100644 index a5b7c550..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_ctrl.3ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_CTRL 3ossl" -.TH SSL_CTX_CTRL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_ctrl, SSL_CTX_callback_ctrl, SSL_ctrl, SSL_callback_ctrl \- internal handling functions for SSL_CTX and SSL objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_ctrl(SSL_CTX *ctx, int cmd, long larg, void *parg); -\& long SSL_CTX_callback_ctrl(SSL_CTX *, int cmd, void (*fp)()); -\& -\& long SSL_ctrl(SSL *ssl, int cmd, long larg, void *parg); -\& long SSL_callback_ctrl(SSL *, int cmd, void (*fp)()); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The SSL_*\fB_ctrl()\fR family of functions is used to manipulate settings of -the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects. Depending on the command \fBcmd\fR the arguments -\&\fBlarg\fR, \fBparg\fR, or \fBfp\fR are evaluated. These functions should never -be called directly. All functionalities needed are made available via -other functions or macros. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The return values of the SSL*\fB_ctrl()\fR functions depend on the command -supplied via the \fBcmd\fR parameter. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_dane_clear_flags.3ossl b/openssl-install/share/man/man3/SSL_CTX_dane_clear_flags.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_dane_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_dane_enable.3ossl b/openssl-install/share/man/man3/SSL_CTX_dane_enable.3ossl deleted file mode 100644 index 773adb8e..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_dane_enable.3ossl +++ /dev/null @@ -1,517 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_DANE_ENABLE 3ossl" -.TH SSL_CTX_DANE_ENABLE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_dane_enable, SSL_CTX_dane_mtype_set, SSL_dane_enable, -SSL_dane_tlsa_add, SSL_get0_dane_authority, SSL_get0_dane_tlsa, -SSL_CTX_dane_set_flags, SSL_CTX_dane_clear_flags, -SSL_dane_set_flags, SSL_dane_clear_flags -\&\- enable DANE TLS authentication of the remote TLS server in the local -TLS client -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_dane_enable(SSL_CTX *ctx); -\& int SSL_CTX_dane_mtype_set(SSL_CTX *ctx, const EVP_MD *md, -\& uint8_t mtype, uint8_t ord); -\& int SSL_dane_enable(SSL *s, const char *basedomain); -\& int SSL_dane_tlsa_add(SSL *s, uint8_t usage, uint8_t selector, -\& uint8_t mtype, const unsigned char *data, size_t dlen); -\& int SSL_get0_dane_authority(SSL *s, X509 **mcert, EVP_PKEY **mspki); -\& int SSL_get0_dane_tlsa(SSL *s, uint8_t *usage, uint8_t *selector, -\& uint8_t *mtype, const unsigned char **data, -\& size_t *dlen); -\& unsigned long SSL_CTX_dane_set_flags(SSL_CTX *ctx, unsigned long flags); -\& unsigned long SSL_CTX_dane_clear_flags(SSL_CTX *ctx, unsigned long flags); -\& unsigned long SSL_dane_set_flags(SSL *ssl, unsigned long flags); -\& unsigned long SSL_dane_clear_flags(SSL *ssl, unsigned long flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions implement support for \s-1DANE TLSA\s0 (\s-1RFC6698\s0 and \s-1RFC7671\s0) -peer authentication. -.PP -\&\fBSSL_CTX_dane_enable()\fR must be called first to initialize the shared state -required for \s-1DANE\s0 support. -Individual connections associated with the context can then enable -per-connection \s-1DANE\s0 support as appropriate. -\&\s-1DANE\s0 authentication is implemented in the \fBX509_verify_cert\fR\|(3) function, and -applications that override \fBX509_verify_cert\fR\|(3) via -\&\fBSSL_CTX_set_cert_verify_callback\fR\|(3) are responsible to authenticate the peer -chain in whatever manner they see fit. -.PP -\&\fBSSL_CTX_dane_mtype_set()\fR may then be called zero or more times to adjust the -supported digest algorithms. -This must be done before any \s-1SSL\s0 handles are created for the context. -.PP -The \fBmtype\fR argument specifies a \s-1DANE TLSA\s0 matching type and the \fBmd\fR -argument specifies the associated digest algorithm handle. -The \fBord\fR argument specifies a strength ordinal. -Algorithms with a larger strength ordinal are considered more secure. -Strength ordinals are used to implement \s-1RFC7671\s0 digest algorithm agility. -Specifying a \fB\s-1NULL\s0\fR digest algorithm for a matching type disables -support for that matching type. -Matching type \fBFull\fR\|(0) cannot be modified or disabled. -.PP -By default, matching type \f(CW\*(C`SHA2\-256(1)\*(C'\fR (see \s-1RFC7218\s0 for definitions -of the \s-1DANE TLSA\s0 parameter acronyms) is mapped to \f(CW\*(C`EVP_sha256()\*(C'\fR -with a strength ordinal of \f(CW1\fR and matching type \f(CW\*(C`SHA2\-512(2)\*(C'\fR -is mapped to \f(CW\*(C`EVP_sha512()\*(C'\fR with a strength ordinal of \f(CW2\fR. -.PP -\&\fBSSL_dane_enable()\fR must be called before the \s-1SSL\s0 handshake is initiated with -\&\fBSSL_connect\fR\|(3) if (and only if) you want to enable \s-1DANE\s0 for that connection. -(The connection must be associated with a DANE-enabled \s-1SSL\s0 context). -The \fBbasedomain\fR argument specifies the \s-1RFC7671 TLSA\s0 base domain, -which will be the primary peer reference identifier for certificate -name checks. -Additional server names can be specified via \fBSSL_add1_host\fR\|(3). -The \fBbasedomain\fR is used as the default \s-1SNI\s0 hint if none has yet been -specified via \fBSSL_set_tlsext_host_name\fR\|(3). -.PP -\&\fBSSL_dane_tlsa_add()\fR may then be called one or more times, to load each of the -\&\s-1TLSA\s0 records that apply to the remote \s-1TLS\s0 peer. -(This too must be done prior to the beginning of the \s-1SSL\s0 handshake). -The arguments specify the fields of the \s-1TLSA\s0 record. -The \fBdata\fR field is provided in binary (wire \s-1RDATA\s0) form, not the hexadecimal -\&\s-1ASCII\s0 presentation form, with an explicit length passed via \fBdlen\fR. -The library takes a copy of the \fBdata\fR buffer contents and the caller may -free the original \fBdata\fR buffer when convenient. -A return value of 0 indicates that \*(L"unusable\*(R" \s-1TLSA\s0 records (with invalid or -unsupported parameters) were provided. -A negative return value indicates an internal error in processing the record. -.PP -The caller is expected to check the return value of each \fBSSL_dane_tlsa_add()\fR -call and take appropriate action if none are usable or an internal error -is encountered in processing some records. -.PP -If no \s-1TLSA\s0 records are added successfully, \s-1DANE\s0 authentication is not enabled, -and authentication will be based on any configured traditional trust-anchors; -authentication success in this case does not mean that the peer was -DANE-authenticated. -.PP -\&\fBSSL_get0_dane_authority()\fR can be used to get more detailed information about -the matched \s-1DANE\s0 trust-anchor after successful connection completion. -The return value is negative if \s-1DANE\s0 verification failed (or was not enabled), -0 if an \s-1EE TLSA\s0 record directly matched the leaf certificate, or a positive -number indicating the depth at which a \s-1TA\s0 record matched an issuer certificate. -The complete verified chain can be retrieved via \fBSSL_get0_verified_chain\fR\|(3). -The return value is an index into this verified chain, rather than the list of -certificates sent by the peer as returned by \fBSSL_get_peer_cert_chain\fR\|(3). -.PP -If the \fBmcert\fR argument is not \fB\s-1NULL\s0\fR and a \s-1TLSA\s0 record matched a chain -certificate, a pointer to the matching certificate is returned via \fBmcert\fR. -The returned address is a short-term internal reference to the certificate and -must not be freed by the application. -Applications that want to retain access to the certificate can call -\&\fBX509_up_ref\fR\|(3) to obtain a long-term reference which must then be freed via -\&\fBX509_free\fR\|(3) once no longer needed. -.PP -If no \s-1TLSA\s0 records directly matched any elements of the certificate chain, but -a \s-1\fBDANE\-TA\s0\fR\|(2) \s-1\fBSPKI\s0\fR\|(1) \fBFull\fR\|(0) record provided the public key that signed an -element of the chain, then that key is returned via \fBmspki\fR argument (if not -\&\s-1NULL\s0). -In this case the return value is the depth of the top-most element of the -validated certificate chain. -As with \fBmcert\fR this is a short-term internal reference, and -\&\fBEVP_PKEY_up_ref\fR\|(3) and \fBEVP_PKEY_free\fR\|(3) can be used to acquire and -release long-term references respectively. -.PP -\&\fBSSL_get0_dane_tlsa()\fR can be used to retrieve the fields of the \s-1TLSA\s0 record that -matched the peer certificate chain. -The return value indicates the match depth or failure to match just as with -\&\fBSSL_get0_dane_authority()\fR. -When the return value is nonnegative, the storage pointed to by the \fBusage\fR, -\&\fBselector\fR, \fBmtype\fR and \fBdata\fR parameters is updated to the corresponding -\&\s-1TLSA\s0 record fields. -The \fBdata\fR field is in binary wire form, and is therefore not NUL-terminated, -its length is returned via the \fBdlen\fR parameter. -If any of these parameters is \s-1NULL,\s0 the corresponding field is not returned. -The \fBdata\fR parameter is set to a short-term internal-copy of the associated -data field and must not be freed by the application. -Applications that need long-term access to this field need to copy the content. -.PP -\&\fBSSL_CTX_dane_set_flags()\fR and \fBSSL_dane_set_flags()\fR can be used to enable -optional \s-1DANE\s0 verification features. -\&\fBSSL_CTX_dane_clear_flags()\fR and \fBSSL_dane_clear_flags()\fR can be used to disable -the same features. -The \fBflags\fR argument is a bit-mask of the features to enable or disable. -The \fBflags\fR set for an \fB\s-1SSL_CTX\s0\fR context are copied to each \fB\s-1SSL\s0\fR handle -associated with that context at the time the handle is created. -Subsequent changes in the context's \fBflags\fR have no effect on the \fBflags\fR set -for the handle. -.PP -At present, the only available option is \fB\s-1DANE_FLAG_NO_DANE_EE_NAMECHECKS\s0\fR -which can be used to disable server name checks when authenticating via -\&\s-1\fBDANE\-EE\s0\fR\|(3) \s-1TLSA\s0 records. -For some applications, primarily web browsers, it is not safe to disable name -checks due to \*(L"unknown key share\*(R" attacks, in which a malicious server can -convince a client that a connection to a victim server is instead a secure -connection to the malicious server. -The malicious server may then be able to violate cross-origin scripting -restrictions. -Thus, despite the text of \s-1RFC7671,\s0 name checks are by default enabled for -\&\s-1\fBDANE\-EE\s0\fR\|(3) \s-1TLSA\s0 records, and can be disabled in applications where it is safe -to do so. -In particular, \s-1SMTP\s0 and \s-1XMPP\s0 clients should set this option as \s-1SRV\s0 and \s-1MX\s0 -records already make it possible for a remote domain to redirect client -connections to any server of its choice, and in any case \s-1SMTP\s0 and \s-1XMPP\s0 clients -do not execute scripts downloaded from remote servers. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions \fBSSL_CTX_dane_enable()\fR, \fBSSL_CTX_dane_mtype_set()\fR, -\&\fBSSL_dane_enable()\fR and \fBSSL_dane_tlsa_add()\fR return a positive value on success. -Negative return values indicate resource problems (out of memory, etc.) in the -\&\s-1SSL\s0 library, while a return value of \fB0\fR indicates incorrect usage or invalid -input, such as an unsupported \s-1TLSA\s0 record certificate usage, selector or -matching type. -Invalid input also includes malformed data, either a digest length that does -not match the digest algorithm, or a \f(CWFull(0)\fR (binary \s-1ASN.1 DER\s0 form) -certificate or a public key that fails to parse. -.PP -The functions \fBSSL_get0_dane_authority()\fR and \fBSSL_get0_dane_tlsa()\fR return a -negative value when \s-1DANE\s0 authentication failed or was not enabled, a -nonnegative value indicates the chain depth at which the \s-1TLSA\s0 record matched a -chain certificate, or the depth of the top-most certificate, when the \s-1TLSA\s0 -record is a full public key that is its signer. -.PP -The functions \fBSSL_CTX_dane_set_flags()\fR, \fBSSL_CTX_dane_clear_flags()\fR, -\&\fBSSL_dane_set_flags()\fR and \fBSSL_dane_clear_flags()\fR return the \fBflags\fR in effect -before they were called. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Suppose \*(L"smtp.example.com\*(R" is the \s-1MX\s0 host of the domain \*(L"example.com\*(R", and has -DNSSEC-validated \s-1TLSA\s0 records. -The calls below will perform \s-1DANE\s0 authentication and arrange to match either -the \s-1MX\s0 hostname or the destination domain name in the \s-1SMTP\s0 server certificate. -Wildcards are supported, but must match the entire label. -The actual name matched in the certificate (which might be a wildcard) is -retrieved, and must be copied by the application if it is to be retained beyond -the lifetime of the \s-1SSL\s0 connection. -.PP -.Vb 7 -\& SSL_CTX *ctx; -\& SSL *ssl; -\& int (*verify_cb)(int ok, X509_STORE_CTX *sctx) = NULL; -\& int num_usable = 0; -\& const char *nexthop_domain = "example.com"; -\& const char *dane_tlsa_domain = "smtp.example.com"; -\& uint8_t usage, selector, mtype; -\& -\& if ((ctx = SSL_CTX_new(TLS_client_method())) == NULL) -\& /* error */ -\& if (SSL_CTX_dane_enable(ctx) <= 0) -\& /* error */ -\& if ((ssl = SSL_new(ctx)) == NULL) -\& /* error */ -\& if (SSL_dane_enable(ssl, dane_tlsa_domain) <= 0) -\& /* error */ -\& -\& /* -\& * For many applications it is safe to skip DANE\-EE(3) namechecks. Do not -\& * disable the checks unless "unknown key share" attacks pose no risk for -\& * your application. -\& */ -\& SSL_dane_set_flags(ssl, DANE_FLAG_NO_DANE_EE_NAMECHECKS); -\& -\& if (!SSL_add1_host(ssl, nexthop_domain)) -\& /* error */ -\& SSL_set_hostflags(ssl, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS); -\& -\& for (... each TLSA record ...) { -\& unsigned char *data; -\& size_t len; -\& int ret; -\& -\& /* set usage, selector, mtype, data, len */ -\& -\& /* -\& * Opportunistic DANE TLS clients support only DANE\-TA(2) or DANE\-EE(3). -\& * They treat all other certificate usages, and in particular PKIX\-TA(0) -\& * and PKIX\-EE(1), as unusable. -\& */ -\& switch (usage) { -\& default: -\& case 0: /* PKIX\-TA(0) */ -\& case 1: /* PKIX\-EE(1) */ -\& continue; -\& case 2: /* DANE\-TA(2) */ -\& case 3: /* DANE\-EE(3) */ -\& break; -\& } -\& -\& ret = SSL_dane_tlsa_add(ssl, usage, selector, mtype, data, len); -\& /* free data as appropriate */ -\& -\& if (ret < 0) -\& /* handle SSL library internal error */ -\& else if (ret == 0) -\& /* handle unusable TLSA record */ -\& else -\& ++num_usable; -\& } -\& -\& /* -\& * At this point, the verification mode is still the default SSL_VERIFY_NONE. -\& * Opportunistic DANE clients use unauthenticated TLS when all TLSA records -\& * are unusable, so continue the handshake even if authentication fails. -\& */ -\& if (num_usable == 0) { -\& /* Log all records unusable? */ -\& -\& /* Optionally set verify_cb to a suitable non\-NULL callback. */ -\& SSL_set_verify(ssl, SSL_VERIFY_NONE, verify_cb); -\& } else { -\& /* At least one usable record. We expect to verify the peer */ -\& -\& /* Optionally set verify_cb to a suitable non\-NULL callback. */ -\& -\& /* -\& * Below we elect to fail the handshake when peer verification fails. -\& * Alternatively, use the permissive SSL_VERIFY_NONE verification mode, -\& * complete the handshake, check the verification status, and if not -\& * verified disconnect gracefully at the application layer, especially if -\& * application protocol supports informing the server that authentication -\& * failed. -\& */ -\& SSL_set_verify(ssl, SSL_VERIFY_PEER, verify_cb); -\& } -\& -\& /* -\& * Load any saved session for resumption, making sure that the previous -\& * session applied the same security and authentication requirements that -\& * would be expected of a fresh connection. -\& */ -\& -\& /* Perform SSL_connect() handshake and handle errors here */ -\& -\& if (SSL_session_reused(ssl)) { -\& if (SSL_get_verify_result(ssl) == X509_V_OK) { -\& /* -\& * Resumed session was originally verified, this connection is -\& * authenticated. -\& */ -\& } else { -\& /* -\& * Resumed session was not originally verified, this connection is not -\& * authenticated. -\& */ -\& } -\& } else if (SSL_get_verify_result(ssl) == X509_V_OK) { -\& const char *peername = SSL_get0_peername(ssl); -\& EVP_PKEY *mspki = NULL; -\& -\& int depth = SSL_get0_dane_authority(ssl, NULL, &mspki); -\& if (depth >= 0) { -\& (void) SSL_get0_dane_tlsa(ssl, &usage, &selector, &mtype, NULL, NULL); -\& printf("DANE TLSA %d %d %d ", usage, selector, mtype); -\& if (SSL_get0_peer_rpk(ssl) == NULL) -\& printf("%s certificate at depth %d\en", -\& (mspki != NULL) ? "signed the peer" : -\& mdpth ? "matched the TA" : "matched the EE", mdpth); -\& else -\& printf(bio, "matched the peer raw public key\en"); -\& } -\& if (peername != NULL) { -\& /* Name checks were in scope and matched the peername */ -\& printf("Verified peername: %s\en", peername); -\& } -\& } else { -\& /* -\& * Not authenticated, presumably all TLSA rrs unusable, but possibly a -\& * callback suppressed connection termination despite the presence of -\& * usable TLSA RRs none of which matched. Do whatever is appropriate for -\& * fresh unauthenticated connections. -\& */ -\& } -.Ve -.SH "NOTES" -.IX Header "NOTES" -It is expected that the majority of clients employing \s-1DANE TLS\s0 will be doing -\&\*(L"opportunistic \s-1DANE TLS\*(R"\s0 in the sense of \s-1RFC7672\s0 and \s-1RFC7435.\s0 -That is, they will use \s-1DANE\s0 authentication when DNSSEC-validated \s-1TLSA\s0 records -are published for a given peer, and otherwise will use unauthenticated \s-1TLS\s0 or -even cleartext. -.PP -Such applications should generally treat any \s-1TLSA\s0 records published by the peer -with usages \s-1\fBPKIX\-TA\s0\fR\|(0) and \s-1\fBPKIX\-EE\s0\fR\|(1) as \*(L"unusable\*(R", and should not include -them among the \s-1TLSA\s0 records used to authenticate peer connections. -In addition, some \s-1TLSA\s0 records with supported usages may be \*(L"unusable\*(R" as a -result of invalid or unsupported parameters. -.PP -When a peer has \s-1TLSA\s0 records, but none are \*(L"usable\*(R", an opportunistic -application must avoid cleartext, but cannot authenticate the peer, -and so should generally proceed with an unauthenticated connection. -Opportunistic applications need to note the return value of each -call to \fBSSL_dane_tlsa_add()\fR, and if all return 0 (due to invalid -or unsupported parameters) disable peer authentication by calling -\&\fBSSL_set_verify\fR\|(3) with \fBmode\fR equal to \fB\s-1SSL_VERIFY_NONE\s0\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_new\fR\|(3), -\&\fBSSL_add1_host\fR\|(3), -\&\fBSSL_set_hostflags\fR\|(3), -\&\fBSSL_set_tlsext_host_name\fR\|(3), -\&\fBSSL_set_verify\fR\|(3), -\&\fBSSL_CTX_set_cert_verify_callback\fR\|(3), -\&\fBSSL_get0_verified_chain\fR\|(3), -\&\fBSSL_get_peer_cert_chain\fR\|(3), -\&\fBSSL_get_verify_result\fR\|(3), -\&\fBSSL_connect\fR\|(3), -\&\fBSSL_get0_peername\fR\|(3), -\&\fBX509_verify_cert\fR\|(3), -\&\fBX509_up_ref\fR\|(3), -\&\fBX509_free\fR\|(3), -\&\fBEVP_get_digestbyname\fR\|(3), -\&\fBEVP_PKEY_up_ref\fR\|(3), -\&\fBEVP_PKEY_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_dane_mtype_set.3ossl b/openssl-install/share/man/man3/SSL_CTX_dane_mtype_set.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_dane_mtype_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_dane_set_flags.3ossl b/openssl-install/share/man/man3/SSL_CTX_dane_set_flags.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_dane_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_decrypt_session_ticket_fn.3ossl b/openssl-install/share/man/man3/SSL_CTX_decrypt_session_ticket_fn.3ossl deleted file mode 120000 index 4051be05..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_decrypt_session_ticket_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_session_ticket_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_disable_ct.3ossl b/openssl-install/share/man/man3/SSL_CTX_disable_ct.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_disable_ct.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_enable_ct.3ossl b/openssl-install/share/man/man3/SSL_CTX_enable_ct.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_enable_ct.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_flush_sessions.3ossl b/openssl-install/share/man/man3/SSL_CTX_flush_sessions.3ossl deleted file mode 100644 index f35c4d3a..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_flush_sessions.3ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_FLUSH_SESSIONS 3ossl" -.TH SSL_CTX_FLUSH_SESSIONS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_flush_sessions_ex, SSL_CTX_flush_sessions \- remove expired sessions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_flush_sessions_ex(SSL_CTX *ctx, time_t tm); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.4, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& void SSL_CTX_flush_sessions(SSL_CTX *ctx, long tm); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_flush_sessions_ex()\fR causes a run through the session cache of -\&\fBctx\fR to remove sessions expired at time \fBtm\fR. -.PP -\&\fBSSL_CTX_flush_sessions()\fR is an older variant of the function that is not -Y2038 safe due to usage of long datatype instead of time_t. -.SH "NOTES" -.IX Header "NOTES" -If enabled, the internal session cache will collect all sessions established -up to the specified maximum number (see \fBSSL_CTX_sess_set_cache_size()\fR). -As sessions will not be reused ones they are expired, they should be -removed from the cache to save resources. This can either be done -automatically whenever 255 new sessions were established (see -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3)) -or manually by calling \fBSSL_CTX_flush_sessions_ex()\fR. -.PP -The parameter \fBtm\fR specifies the time which should be used for the -expiration test, in most cases the actual time given by \fBtime\fR\|(0) -will be used. -.PP -\&\fBSSL_CTX_flush_sessions_ex()\fR will only check sessions stored in the internal -cache. When a session is found and removed, the remove_session_cb is however -called to synchronize with the external cache (see -\&\fBSSL_CTX_sess_set_get_cb\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_flush_sessions_ex()\fR does not return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -\&\fBSSL_CTX_set_timeout\fR\|(3), -\&\fBSSL_CTX_sess_set_get_cb\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_CTX_flush_sessions_ex()\fR was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_flush_sessions_ex.3ossl b/openssl-install/share/man/man3/SSL_CTX_flush_sessions_ex.3ossl deleted file mode 120000 index c2162045..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_flush_sessions_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_flush_sessions.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_free.3ossl b/openssl-install/share/man/man3/SSL_CTX_free.3ossl deleted file mode 100644 index f1143b42..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_free.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_FREE 3ossl" -.TH SSL_CTX_FREE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_free \- free an allocated SSL_CTX object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_free(SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_free()\fR decrements the reference count of \fBctx\fR, and removes the -\&\s-1SSL_CTX\s0 object pointed to by \fBctx\fR and frees up the allocated memory if the reference count has reached 0. -.PP -It also calls the \fBfree()\fRing procedures for indirectly affected items, if -applicable: the session cache, the list of ciphers, the list of Client CAs, -the certificates and keys. -.PP -If \fBctx\fR is \s-1NULL\s0 nothing is done. -.SH "WARNINGS" -.IX Header "WARNINGS" -If a session-remove callback is set (\fBSSL_CTX_sess_set_remove_cb()\fR), this -callback will be called for each session being freed from \fBctx\fR's -session cache. This implies, that all corresponding sessions from an -external session cache are removed as well. If this is not desired, the user -should explicitly unset the callback by calling -SSL_CTX_sess_set_remove_cb(\fBctx\fR, \s-1NULL\s0) prior to calling \fBSSL_CTX_free()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_free()\fR does not provide diagnostic information. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_new\fR\|(3), \fBssl\fR\|(7), -\&\fBSSL_CTX_sess_set_get_cb\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_generate_session_ticket_fn.3ossl b/openssl-install/share/man/man3/SSL_CTX_generate_session_ticket_fn.3ossl deleted file mode 120000 index 4051be05..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_generate_session_ticket_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_session_ticket_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_CA_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_chain_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_chain_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_chain_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_chain_certs.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_chain_certs.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_chain_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_client_cert_type.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_client_cert_type.3ossl deleted file mode 120000 index 44c96a96..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_client_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_server_cert_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_param.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_param.3ossl deleted file mode 100644 index 04219f30..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_param.3ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_GET0_PARAM 3ossl" -.TH SSL_CTX_GET0_PARAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_get0_param, SSL_get0_param, SSL_CTX_set1_param, SSL_set1_param, -SSL_CTX_set_purpose, SSL_CTX_set_trust, SSL_set_purpose, SSL_set_trust \- -get and set verification parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_VERIFY_PARAM *SSL_CTX_get0_param(SSL_CTX *ctx); -\& X509_VERIFY_PARAM *SSL_get0_param(SSL *ssl); -\& int SSL_CTX_set1_param(SSL_CTX *ctx, X509_VERIFY_PARAM *vpm); -\& int SSL_set1_param(SSL *ssl, X509_VERIFY_PARAM *vpm); -\& -\& int SSL_CTX_set_purpose(SSL_CTX *ctx, int purpose); -\& int SSL_set_purpose(SSL *ssl, int purpose); -\& -\& int SSL_CTX_set_trust(SSL_CTX *ctx, int trust); -\& int SSL_set_trust(SSL *ssl, int trust); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_get0_param()\fR and \fBSSL_get0_param()\fR retrieve an internal pointer to -the verification parameters for \fBctx\fR or \fBssl\fR respectively. The returned -pointer must not be freed by the calling application. -.PP -\&\fBSSL_CTX_set1_param()\fR and \fBSSL_set1_param()\fR set the verification parameters -to \fBvpm\fR for \fBctx\fR or \fBssl\fR. -.PP -The functions \fBSSL_CTX_set_purpose()\fR and \fBSSL_set_purpose()\fR are shorthands which -set the purpose parameter on the verification parameters object. These functions -are equivalent to calling \fBX509_VERIFY_PARAM_set_purpose()\fR directly. -.PP -The functions \fBSSL_CTX_set_trust()\fR and \fBSSL_set_trust()\fR are similarly shorthands -which set the trust parameter on the verification parameters object. These -functions are equivalent to calling \fBX509_VERIFY_PARAM_set_trust()\fR directly. -.SH "NOTES" -.IX Header "NOTES" -Typically parameters are retrieved from an \fB\s-1SSL_CTX\s0\fR or \fB\s-1SSL\s0\fR structure -using \fBSSL_CTX_get0_param()\fR or \fBSSL_get0_param()\fR and an application modifies -them to suit its needs: for example to add a hostname check. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_get0_param()\fR and \fBSSL_get0_param()\fR return a pointer to an -\&\fBX509_VERIFY_PARAM\fR structure. -.PP -\&\fBSSL_CTX_set1_param()\fR, \fBSSL_set1_param()\fR, \fBSSL_CTX_set_purpose()\fR, -\&\fBSSL_set_purpose()\fR, \fBSSL_CTX_set_trust()\fR and \fBSSL_set_trust()\fR return 1 for success -and 0 for failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Check hostname matches \*(L"www.foo.com\*(R" in peer certificate: -.PP -.Vb 2 -\& X509_VERIFY_PARAM *vpm = SSL_get0_param(ssl); -\& X509_VERIFY_PARAM_set1_host(vpm, "www.foo.com", 0); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBX509_VERIFY_PARAM_set_flags\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_security_ex_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_security_ex_data.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_security_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_server_cert_type.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_server_cert_type.3ossl deleted file mode 120000 index 44c96a96..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_server_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_server_cert_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get0_verify_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_get0_verify_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get0_verify_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get1_compressed_cert.3ossl b/openssl-install/share/man/man3/SSL_CTX_get1_compressed_cert.3ossl deleted file mode 120000 index 7aaf058c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get1_compressed_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_cert_comp_preference.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_app_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_cert_store.3ossl deleted file mode 120000 index 4d089987..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_ciphers.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_ciphers.3ossl deleted file mode 120000 index 5ab60591..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_ciphers.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_client_CA_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_client_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_client_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_client_cert_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_client_cert_cb.3ossl deleted file mode 120000 index 4bb1a9b5..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_client_cert_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_cert_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb.3ossl deleted file mode 120000 index 5e9f9bdf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_default_passwd_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb_userdata.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb_userdata.3ossl deleted file mode 120000 index 5e9f9bdf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_default_passwd_cb_userdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_default_passwd_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_default_read_ahead.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_default_read_ahead.3ossl deleted file mode 120000 index 095d1f88..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_default_read_ahead.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_read_ahead.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_ex_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_ex_new_index.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs.3ossl deleted file mode 120000 index 0b6a1e06..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add_extra_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs_only.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs_only.3ossl deleted file mode 120000 index 0b6a1e06..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_extra_chain_certs_only.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add_extra_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_info_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_info_callback.3ossl deleted file mode 120000 index f805afdc..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_info_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_info_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_keylog_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_keylog_callback.3ossl deleted file mode 120000 index b37cf65b..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_keylog_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_keylog_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_max_cert_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_max_cert_list.3ossl deleted file mode 120000 index 4861aab5..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_max_cert_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_max_cert_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_max_proto_version.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_max_proto_version.3ossl deleted file mode 120000 index 60193888..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_max_proto_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_min_proto_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_min_proto_version.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_min_proto_version.3ossl deleted file mode 120000 index 60193888..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_min_proto_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_min_proto_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_mode.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_mode.3ossl deleted file mode 120000 index ea309712..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_num_tickets.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_num_tickets.3ossl deleted file mode 120000 index 619b5ce0..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_num_tickets.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_num_tickets.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_options.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_options.3ossl deleted file mode 120000 index 742650be..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_options.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_options.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_quiet_shutdown.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_quiet_shutdown.3ossl deleted file mode 120000 index 1bef418d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_quiet_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_quiet_shutdown.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_read_ahead.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_read_ahead.3ossl deleted file mode 120000 index 095d1f88..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_read_ahead.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_read_ahead.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_record_padding_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_record_padding_callback_arg.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_record_padding_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_recv_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_recv_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_recv_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_security_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_security_callback.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_security_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_security_level.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_security_level.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_security_level.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_session_cache_mode.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_session_cache_mode.3ossl deleted file mode 120000 index 1f08be24..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_session_cache_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_session_cache_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_ssl_method.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_ssl_method.3ossl deleted file mode 120000 index 05c88c50..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_ssl_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ssl_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_timeout.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_timeout.3ossl deleted file mode 120000 index ffa6098f..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_timeout.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_timeout.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_arg.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_cb.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_type.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_type.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_tlsext_status_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_verify_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_verify_callback.3ossl deleted file mode 120000 index c88643e6..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_verify_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get_verify_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_verify_depth.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_verify_depth.3ossl deleted file mode 120000 index c88643e6..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_verify_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get_verify_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_get_verify_mode.3ossl b/openssl-install/share/man/man3/SSL_CTX_get_verify_mode.3ossl deleted file mode 100644 index b8e8cdba..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_get_verify_mode.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_GET_VERIFY_MODE 3ossl" -.TH SSL_CTX_GET_VERIFY_MODE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_get_verify_mode, SSL_get_verify_mode, SSL_CTX_get_verify_depth, SSL_get_verify_depth, SSL_get_verify_callback, SSL_CTX_get_verify_callback \- get currently set verification parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_get_verify_mode(const SSL_CTX *ctx); -\& int SSL_get_verify_mode(const SSL *ssl); -\& int SSL_CTX_get_verify_depth(const SSL_CTX *ctx); -\& int SSL_get_verify_depth(const SSL *ssl); -\& int (*SSL_CTX_get_verify_callback(const SSL_CTX *ctx))(int, X509_STORE_CTX *); -\& int (*SSL_get_verify_callback(const SSL *ssl))(int, X509_STORE_CTX *); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_get_verify_mode()\fR returns the verification mode currently set in -\&\fBctx\fR. -.PP -\&\fBSSL_get_verify_mode()\fR returns the verification mode currently set in -\&\fBssl\fR. -.PP -\&\fBSSL_CTX_get_verify_depth()\fR returns the verification depth limit currently set -in \fBctx\fR. If no limit has been explicitly set, \-1 is returned and the -default value will be used. -.PP -\&\fBSSL_get_verify_depth()\fR returns the verification depth limit currently set -in \fBssl\fR. If no limit has been explicitly set, \-1 is returned and the -default value will be used. -.PP -\&\fBSSL_CTX_get_verify_callback()\fR returns a function pointer to the verification -callback currently set in \fBctx\fR. If no callback was explicitly set, the -\&\s-1NULL\s0 pointer is returned and the default callback will be used. -.PP -\&\fBSSL_get_verify_callback()\fR returns a function pointer to the verification -callback currently set in \fBssl\fR. If no callback was explicitly set, the -\&\s-1NULL\s0 pointer is returned and the default callback will be used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -See \s-1DESCRIPTION\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_verify\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_has_client_custom_ext.3ossl b/openssl-install/share/man/man3/SSL_CTX_has_client_custom_ext.3ossl deleted file mode 100644 index 8b12f88b..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_has_client_custom_ext.3ossl +++ /dev/null @@ -1,169 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_HAS_CLIENT_CUSTOM_EXT 3ossl" -.TH SSL_CTX_HAS_CLIENT_CUSTOM_EXT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_has_client_custom_ext \- check whether a handler exists for a particular -client extension type -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_has_client_custom_ext(const SSL_CTX *ctx, unsigned int ext_type); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_has_client_custom_ext()\fR checks whether a handler has been set for a -client extension of type \fBext_type\fR using \fBSSL_CTX_add_client_custom_ext()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 if a handler has been set, 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_add_client_custom_ext\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_keylog_cb_func.3ossl b/openssl-install/share/man/man3/SSL_CTX_keylog_cb_func.3ossl deleted file mode 120000 index b37cf65b..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_keylog_cb_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_keylog_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_load_verify_dir.3ossl b/openssl-install/share/man/man3/SSL_CTX_load_verify_dir.3ossl deleted file mode 120000 index 443728eb..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_load_verify_dir.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_load_verify_locations.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_load_verify_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_load_verify_file.3ossl deleted file mode 120000 index 443728eb..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_load_verify_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_load_verify_locations.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_load_verify_locations.3ossl b/openssl-install/share/man/man3/SSL_CTX_load_verify_locations.3ossl deleted file mode 100644 index f564358b..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_load_verify_locations.3ossl +++ /dev/null @@ -1,309 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_LOAD_VERIFY_LOCATIONS 3ossl" -.TH SSL_CTX_LOAD_VERIFY_LOCATIONS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_load_verify_dir, SSL_CTX_load_verify_file, -SSL_CTX_load_verify_store, SSL_CTX_set_default_verify_paths, -SSL_CTX_set_default_verify_dir, SSL_CTX_set_default_verify_file, -SSL_CTX_set_default_verify_store, SSL_CTX_load_verify_locations -\&\- set default locations for trusted CA certificates -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_load_verify_dir(SSL_CTX *ctx, const char *CApath); -\& int SSL_CTX_load_verify_file(SSL_CTX *ctx, const char *CAfile); -\& int SSL_CTX_load_verify_store(SSL_CTX *ctx, const char *CAstore); -\& -\& int SSL_CTX_set_default_verify_paths(SSL_CTX *ctx); -\& -\& int SSL_CTX_set_default_verify_dir(SSL_CTX *ctx); -\& int SSL_CTX_set_default_verify_file(SSL_CTX *ctx); -\& int SSL_CTX_set_default_verify_store(SSL_CTX *ctx); -\& -\& int SSL_CTX_load_verify_locations(SSL_CTX *ctx, const char *CAfile, -\& const char *CApath); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_load_verify_locations()\fR, \fBSSL_CTX_load_verify_dir()\fR, -\&\fBSSL_CTX_load_verify_file()\fR, \fBSSL_CTX_load_verify_store()\fR specifies the -locations for \fBctx\fR, at which \s-1CA\s0 certificates for verification purposes -are located. The certificates available via \fBCAfile\fR, \fBCApath\fR and -\&\fBCAstore\fR are trusted. -.PP -Details of the certificate verification and chain checking process are -described in \*(L"Certification Path Validation\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.PP -\&\fBSSL_CTX_set_default_verify_paths()\fR specifies that the default locations from -which \s-1CA\s0 certificates are loaded should be used. There is one default directory, -one default file and one default store. -The default \s-1CA\s0 certificates directory is called \fIcerts\fR in the default OpenSSL -directory, and this is also the default store. -Alternatively the \fB\s-1SSL_CERT_DIR\s0\fR environment variable can be defined to -override this location. -The default \s-1CA\s0 certificates file is called \fIcert.pem\fR in the default -OpenSSL directory. -Alternatively the \fB\s-1SSL_CERT_FILE\s0\fR environment variable can be defined to -override this location. -.PP -\&\fBSSL_CTX_set_default_verify_dir()\fR is similar to -\&\fBSSL_CTX_set_default_verify_paths()\fR except that just the default directory is -used. -.PP -\&\fBSSL_CTX_set_default_verify_file()\fR is similar to -\&\fBSSL_CTX_set_default_verify_paths()\fR except that just the default file is -used. -.PP -\&\fBSSL_CTX_set_default_verify_store()\fR is similar to -\&\fBSSL_CTX_set_default_verify_paths()\fR except that just the default store is -used. -.SH "NOTES" -.IX Header "NOTES" -If \fBCAfile\fR is not \s-1NULL,\s0 it points to a file of \s-1CA\s0 certificates in \s-1PEM\s0 -format. The file can contain several \s-1CA\s0 certificates identified by -.PP -.Vb 3 -\& \-\-\-\-\-BEGIN CERTIFICATE\-\-\-\-\- -\& ... (CA certificate in base64 encoding) ... -\& \-\-\-\-\-END CERTIFICATE\-\-\-\-\- -.Ve -.PP -sequences. Before, between, and after the certificates text is allowed -which can be used e.g. for descriptions of the certificates. -.PP -The \fBCAfile\fR is processed on execution of the \fBSSL_CTX_load_verify_locations()\fR -function. -.PP -If \fBCApath\fR is not \s-1NULL,\s0 it points to a directory containing \s-1CA\s0 certificates -in \s-1PEM\s0 format. The files each contain one \s-1CA\s0 certificate. The files are -looked up by the \s-1CA\s0 subject name hash value, which must hence be available. -If more than one \s-1CA\s0 certificate with the same name hash value exist, the -extension must be different (e.g. 9d66eef0.0, 9d66eef0.1 etc). The search -is performed in the ordering of the extension number, regardless of other -properties of the certificates. -Use the \fBc_rehash\fR utility to create the necessary links. -.PP -The certificates in \fBCApath\fR are only looked up when required, e.g. when -building the certificate chain or when actually performing the verification -of a peer certificate. -.PP -When looking up \s-1CA\s0 certificates for chain building, the OpenSSL library -will search for suitable certificates first in \fBCAfile\fR, then in \fBCApath\fR. -Details of the chain building process are described in -\&\*(L"Certification Path Building\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.PP -If \fBCAstore\fR is not \s-1NULL,\s0 it's a \s-1URI\s0 for to a store, which may -represent a single container or a whole catalogue of containers. -Apart from the \fBCAstore\fR not necessarily being a local file or -directory, it's generally treated the same way as a \fBCApath\fR. -.PP -In server mode, when requesting a client certificate, the server must send -the list of CAs of which it will accept client certificates. This list -is not influenced by the contents of \fBCAfile\fR or \fBCApath\fR and must -explicitly be set using the -\&\fBSSL_CTX_set_client_CA_list\fR\|(3) -family of functions. -.PP -When building its own certificate chain, an OpenSSL client/server will -try to fill in missing certificates from \fBCAfile\fR/\fBCApath\fR, if the -certificate chain was not explicitly specified (see -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3), -\&\fBSSL_CTX_use_certificate\fR\|(3). -.SH "WARNINGS" -.IX Header "WARNINGS" -If several \s-1CA\s0 certificates matching the name, key identifier, and serial -number condition are available, only the first one will be examined. This -may lead to unexpected results if the same \s-1CA\s0 certificate is available -with different expiration dates. If a \*(L"certificate expired\*(R" verification -error occurs, no other certificate will be searched. Make sure to not -have expired certificates mixed with valid ones. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -For SSL_CTX_load_verify_locations the following return values can occur: -.IP "0" 4 -The operation failed because \fBCAfile\fR and \fBCApath\fR are \s-1NULL\s0 or the -processing at one of the locations specified failed. Check the error -stack to find out the reason. -.IP "1" 4 -.IX Item "1" -The operation succeeded. -.PP -\&\fBSSL_CTX_set_default_verify_paths()\fR, \fBSSL_CTX_set_default_verify_dir()\fR and -\&\fBSSL_CTX_set_default_verify_file()\fR all return 1 on success or 0 on failure. A -missing default location is still treated as a success. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Generate a \s-1CA\s0 certificate file with descriptive text from the \s-1CA\s0 certificates -ca1.pem ca2.pem ca3.pem: -.PP -.Vb 5 -\& #!/bin/sh -\& rm CAfile.pem -\& for i in ca1.pem ca2.pem ca3.pem ; do -\& openssl x509 \-in $i \-text >> CAfile.pem -\& done -.Ve -.PP -Prepare the directory /some/where/certs containing several \s-1CA\s0 certificates -for use as \fBCApath\fR: -.PP -.Vb 2 -\& cd /some/where/certs -\& c_rehash . -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_client_CA_list\fR\|(3), -\&\fBSSL_get_client_CA_list\fR\|(3), -\&\fBSSL_CTX_use_certificate\fR\|(3), -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3), -\&\fBSSL_CTX_set_cert_store\fR\|(3), -\&\fBSSL_CTX_set_client_CA_list\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_load_verify_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_load_verify_store.3ossl deleted file mode 120000 index 443728eb..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_load_verify_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_load_verify_locations.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_new.3ossl b/openssl-install/share/man/man3/SSL_CTX_new.3ossl deleted file mode 100644 index 7e422921..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_new.3ossl +++ /dev/null @@ -1,372 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_NEW 3ossl" -.TH SSL_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -TLSv1_2_method, TLSv1_2_server_method, TLSv1_2_client_method, -SSL_CTX_new, SSL_CTX_new_ex, SSL_CTX_up_ref, SSLv3_method, -SSLv3_server_method, SSLv3_client_method, TLSv1_method, TLSv1_server_method, -TLSv1_client_method, TLSv1_1_method, TLSv1_1_server_method, -TLSv1_1_client_method, TLS_method, TLS_server_method, TLS_client_method, -SSLv23_method, SSLv23_server_method, SSLv23_client_method, DTLS_method, -DTLS_server_method, DTLS_client_method, DTLSv1_method, DTLSv1_server_method, -DTLSv1_client_method, DTLSv1_2_method, DTLSv1_2_server_method, -DTLSv1_2_client_method -\&\- create a new SSL_CTX object as framework for TLS/SSL or DTLS enabled -functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL_CTX *SSL_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq, -\& const SSL_METHOD *method); -\& SSL_CTX *SSL_CTX_new(const SSL_METHOD *method); -\& int SSL_CTX_up_ref(SSL_CTX *ctx); -\& -\& const SSL_METHOD *TLS_method(void); -\& const SSL_METHOD *TLS_server_method(void); -\& const SSL_METHOD *TLS_client_method(void); -\& -\& const SSL_METHOD *SSLv23_method(void); -\& const SSL_METHOD *SSLv23_server_method(void); -\& const SSL_METHOD *SSLv23_client_method(void); -\& -\& #ifndef OPENSSL_NO_SSL3_METHOD -\& const SSL_METHOD *SSLv3_method(void); -\& const SSL_METHOD *SSLv3_server_method(void); -\& const SSL_METHOD *SSLv3_client_method(void); -\& #endif -\& -\& #ifndef OPENSSL_NO_TLS1_METHOD -\& const SSL_METHOD *TLSv1_method(void); -\& const SSL_METHOD *TLSv1_server_method(void); -\& const SSL_METHOD *TLSv1_client_method(void); -\& #endif -\& -\& #ifndef OPENSSL_NO_TLS1_1_METHOD -\& const SSL_METHOD *TLSv1_1_method(void); -\& const SSL_METHOD *TLSv1_1_server_method(void); -\& const SSL_METHOD *TLSv1_1_client_method(void); -\& #endif -\& -\& #ifndef OPENSSL_NO_TLS1_2_METHOD -\& const SSL_METHOD *TLSv1_2_method(void); -\& const SSL_METHOD *TLSv1_2_server_method(void); -\& const SSL_METHOD *TLSv1_2_client_method(void); -\& #endif -\& -\& const SSL_METHOD *DTLS_method(void); -\& const SSL_METHOD *DTLS_server_method(void); -\& const SSL_METHOD *DTLS_client_method(void); -\& -\& #ifndef OPENSSL_NO_DTLS1_METHOD -\& const SSL_METHOD *DTLSv1_method(void); -\& const SSL_METHOD *DTLSv1_server_method(void); -\& const SSL_METHOD *DTLSv1_client_method(void); -\& #endif -\& -\& #ifndef OPENSSL_NO_DTLS1_2_METHOD -\& const SSL_METHOD *DTLSv1_2_method(void); -\& const SSL_METHOD *DTLSv1_2_server_method(void); -\& const SSL_METHOD *DTLSv1_2_client_method(void); -\& #endif -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_new_ex()\fR creates a new \fB\s-1SSL_CTX\s0\fR object, which holds various -configuration and data relevant to \s-1SSL/TLS\s0 or \s-1DTLS\s0 session establishment. -These are later inherited by the \fB\s-1SSL\s0\fR object representing an active session. -The \fImethod\fR parameter specifies whether the context will be used for the -client or server side or both \- for details see the \*(L"\s-1NOTES\*(R"\s0 below. -The library context \fIlibctx\fR (see \s-1\fBOSSL_LIB_CTX\s0\fR\|(3)) is used to provide the -cryptographic algorithms needed for the session. Any cryptographic algorithms -that are used by any \fB\s-1SSL\s0\fR objects created from this \fB\s-1SSL_CTX\s0\fR will be fetched -from the \fIlibctx\fR using the property query string \fIpropq\fR (see -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7). Either or both the \fIlibctx\fR or \fIpropq\fR -parameters may be \s-1NULL.\s0 -.PP -\&\fBSSL_CTX_new()\fR does the same as \fBSSL_CTX_new_ex()\fR except that the default -library context is used and no property query string is specified. -.PP -An \fB\s-1SSL_CTX\s0\fR object is reference counted. Creating an \fB\s-1SSL_CTX\s0\fR object for the -first time increments the reference count. Freeing the \fB\s-1SSL_CTX\s0\fR (using -SSL_CTX_free) decrements it. When the reference count drops to zero, any memory -or resources allocated to the \fB\s-1SSL_CTX\s0\fR object are freed. \fBSSL_CTX_up_ref()\fR -increments the reference count for an existing \fB\s-1SSL_CTX\s0\fR structure. -.PP -An \fB\s-1SSL_CTX\s0\fR object should not be changed after it is used to create any \fB\s-1SSL\s0\fR -objects or from multiple threads concurrently, since the implementation does not -provide serialization of access for these cases. -.SH "NOTES" -.IX Header "NOTES" -On session establishment, by default, no peer credentials verification is done. -This must be explicitly requested, typically using \fBSSL_CTX_set_verify\fR\|(3). -For verifying peer certificates many options can be set using various functions -such as \fBSSL_CTX_load_verify_locations\fR\|(3) and \fBSSL_CTX_set1_param\fR\|(3). -.PP -The \s-1SSL/\s0(D)TLS implementation uses the \fBX509_STORE_CTX_set_default\fR\|(3) -function to prepare checks for \fBX509_PURPOSE_SSL_SERVER\fR on the client side -and \fBX509_PURPOSE_SSL_CLIENT\fR on the server side. -The \fBX509_VERIFY_PARAM_set_purpose\fR\|(3) function can be used, also in conjunction -with \fBSSL_CTX_get0_param\fR\|(3), to override the default purpose of the session. -.PP -The \s-1SSL_CTX\s0 object uses \fImethod\fR as the connection method. -Three method variants are available: a generic method (for either client or -server use), a server-only method, and a client-only method. -.PP -The \fImethod\fR parameter of \fBSSL_CTX_new_ex()\fR and \fBSSL_CTX_new()\fR -can be one of the following: -.IP "\fBTLS_method()\fR, \fBTLS_server_method()\fR, \fBTLS_client_method()\fR" 4 -.IX Item "TLS_method(), TLS_server_method(), TLS_client_method()" -These are the general-purpose \fIversion-flexible\fR \s-1SSL/TLS\s0 methods. -The actual protocol version used will be negotiated to the highest version -mutually supported by the client and the server. -The supported protocols are SSLv3, TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3. -Applications should use these methods, and avoid the version-specific -methods described below, which are deprecated. -.IP "\fBSSLv23_method()\fR, \fBSSLv23_server_method()\fR, \fBSSLv23_client_method()\fR" 4 -.IX Item "SSLv23_method(), SSLv23_server_method(), SSLv23_client_method()" -These functions do not exist anymore, they have been renamed to -\&\fBTLS_method()\fR, \fBTLS_server_method()\fR and \fBTLS_client_method()\fR respectively. -Currently, the old function calls are renamed to the corresponding new -ones by preprocessor macros, to ensure that existing code which uses the -old function names still compiles. However, using the old function names -is deprecated and new code should call the new functions instead. -.IP "\fBTLSv1_2_method()\fR, \fBTLSv1_2_server_method()\fR, \fBTLSv1_2_client_method()\fR" 4 -.IX Item "TLSv1_2_method(), TLSv1_2_server_method(), TLSv1_2_client_method()" -A \s-1TLS/SSL\s0 connection established with these methods will only understand the -TLSv1.2 protocol. These methods are deprecated. -.IP "\fBTLSv1_1_method()\fR, \fBTLSv1_1_server_method()\fR, \fBTLSv1_1_client_method()\fR" 4 -.IX Item "TLSv1_1_method(), TLSv1_1_server_method(), TLSv1_1_client_method()" -A \s-1TLS/SSL\s0 connection established with these methods will only understand the -TLSv1.1 protocol. These methods are deprecated. -.IP "\fBTLSv1_method()\fR, \fBTLSv1_server_method()\fR, \fBTLSv1_client_method()\fR" 4 -.IX Item "TLSv1_method(), TLSv1_server_method(), TLSv1_client_method()" -A \s-1TLS/SSL\s0 connection established with these methods will only understand the -TLSv1 protocol. These methods are deprecated. -.IP "\fBSSLv3_method()\fR, \fBSSLv3_server_method()\fR, \fBSSLv3_client_method()\fR" 4 -.IX Item "SSLv3_method(), SSLv3_server_method(), SSLv3_client_method()" -A \s-1TLS/SSL\s0 connection established with these methods will only understand the -SSLv3 protocol. -The SSLv3 protocol is deprecated and should not be used. -.IP "\fBDTLS_method()\fR, \fBDTLS_server_method()\fR, \fBDTLS_client_method()\fR" 4 -.IX Item "DTLS_method(), DTLS_server_method(), DTLS_client_method()" -These are the version-flexible \s-1DTLS\s0 methods. -Currently supported protocols are \s-1DTLS 1.0\s0 and \s-1DTLS 1.2.\s0 -.IP "\fBDTLSv1_2_method()\fR, \fBDTLSv1_2_server_method()\fR, \fBDTLSv1_2_client_method()\fR" 4 -.IX Item "DTLSv1_2_method(), DTLSv1_2_server_method(), DTLSv1_2_client_method()" -These are the version-specific methods for DTLSv1.2. -These methods are deprecated. -.IP "\fBDTLSv1_method()\fR, \fBDTLSv1_server_method()\fR, \fBDTLSv1_client_method()\fR" 4 -.IX Item "DTLSv1_method(), DTLSv1_server_method(), DTLSv1_client_method()" -These are the version-specific methods for DTLSv1. -These methods are deprecated. -.PP -\&\fBSSL_CTX_new()\fR initializes the list of ciphers, the session cache setting, the -callbacks, the keys and certificates and the options to their default values. -.PP -\&\fBTLS_method()\fR, \fBTLS_server_method()\fR, \fBTLS_client_method()\fR, \fBDTLS_method()\fR, -\&\fBDTLS_server_method()\fR and \fBDTLS_client_method()\fR are the \fIversion-flexible\fR -methods. -All other methods only support one specific protocol version. -Use the \fIversion-flexible\fR methods instead of the version specific methods. -.PP -If you want to limit the supported protocols for the version flexible -methods you can use \fBSSL_CTX_set_min_proto_version\fR\|(3), -\&\fBSSL_set_min_proto_version\fR\|(3), \fBSSL_CTX_set_max_proto_version\fR\|(3) and -\&\fBSSL_set_max_proto_version\fR\|(3) functions. -Using these functions it is possible to choose e.g. \fBTLS_server_method()\fR -and be able to negotiate with all possible clients, but to only -allow newer protocols like \s-1TLS 1.0, TLS 1.1, TLS 1.2\s0 or \s-1TLS 1.3.\s0 -.PP -The list of protocols available can also be limited using the -\&\fBSSL_OP_NO_SSLv3\fR, \fBSSL_OP_NO_TLSv1\fR, \fBSSL_OP_NO_TLSv1_1\fR, -\&\fBSSL_OP_NO_TLSv1_3\fR, \fBSSL_OP_NO_TLSv1_2\fR and \fBSSL_OP_NO_TLSv1_3\fR -options of the -\&\fBSSL_CTX_set_options\fR\|(3) or \fBSSL_set_options\fR\|(3) functions, but this approach -is not recommended. Clients should avoid creating \*(L"holes\*(R" in the set of -protocols they support. When disabling a protocol, make sure that you also -disable either all previous or all subsequent protocol versions. -In clients, when a protocol version is disabled without disabling \fIall\fR -previous protocol versions, the effect is to also disable all subsequent -protocol versions. -.PP -The SSLv3 protocol is deprecated and should generally not be used. -Applications should typically use \fBSSL_CTX_set_min_proto_version\fR\|(3) to set -the minimum protocol to at least \fB\s-1TLS1_VERSION\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "\s-1NULL\s0" 4 -.IX Item "NULL" -The creation of a new \s-1SSL_CTX\s0 object failed. Check the error stack to find out -the reason. -.IP "Pointer to an \s-1SSL_CTX\s0 object" 4 -.IX Item "Pointer to an SSL_CTX object" -The return value points to an allocated \s-1SSL_CTX\s0 object. -.Sp -\&\fBSSL_CTX_up_ref()\fR returns 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_set_options\fR\|(3), \fBSSL_CTX_free\fR\|(3), \fBX509_STORE_CTX_set_default\fR\|(3), -\&\fBSSL_CTX_set_verify\fR\|(3), \fBSSL_CTX_set1_param\fR\|(3), \fBSSL_CTX_get0_param\fR\|(3), -\&\fBSSL_connect\fR\|(3), \fBSSL_accept\fR\|(3), -\&\fBSSL_CTX_set_min_proto_version\fR\|(3), \fBssl\fR\|(7), \fBSSL_set_connect_state\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -Support for SSLv2 and the corresponding \fBSSLv2_method()\fR, -\&\fBSSLv2_server_method()\fR and \fBSSLv2_client_method()\fR functions where -removed in OpenSSL 1.1.0. -.PP -\&\fBSSLv23_method()\fR, \fBSSLv23_server_method()\fR and \fBSSLv23_client_method()\fR -were deprecated and the preferred \fBTLS_method()\fR, \fBTLS_server_method()\fR -and \fBTLS_client_method()\fR functions were added in OpenSSL 1.1.0. -.PP -All version-specific methods were deprecated in OpenSSL 1.1.0. -.PP -\&\fBSSL_CTX_new_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_new_ex.3ossl b/openssl-install/share/man/man3/SSL_CTX_new_ex.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_remove_session.3ossl b/openssl-install/share/man/man3/SSL_CTX_remove_session.3ossl deleted file mode 120000 index 07bdbfca..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_remove_session.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add_session.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_select_current_cert.3ossl b/openssl-install/share/man/man3/SSL_CTX_select_current_cert.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_select_current_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_accept.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_accept.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_accept.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_accept_good.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_accept_good.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_accept_good.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_accept_renegotiate.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_accept_renegotiate.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_accept_renegotiate.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_cache_full.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_cache_full.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_cache_full.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_cb_hits.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_cb_hits.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_cb_hits.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_connect.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_connect.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_connect.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_connect_good.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_connect_good.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_connect_good.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_connect_renegotiate.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_connect_renegotiate.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_connect_renegotiate.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_get_cache_size.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_get_cache_size.3ossl deleted file mode 120000 index 801aa1e9..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_get_cache_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_set_cache_size.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_get_get_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_get_get_cb.3ossl deleted file mode 120000 index 171e3a57..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_get_get_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_set_get_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_get_new_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_get_new_cb.3ossl deleted file mode 120000 index 171e3a57..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_get_new_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_set_get_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_get_remove_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_get_remove_cb.3ossl deleted file mode 120000 index 171e3a57..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_get_remove_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_set_get_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_hits.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_hits.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_hits.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_misses.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_misses.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_misses.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_number.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_number.3ossl deleted file mode 100644 index 34d41075..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_number.3ossl +++ /dev/null @@ -1,217 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SESS_NUMBER 3ossl" -.TH SSL_CTX_SESS_NUMBER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_sess_number, SSL_CTX_sess_connect, SSL_CTX_sess_connect_good, SSL_CTX_sess_connect_renegotiate, SSL_CTX_sess_accept, SSL_CTX_sess_accept_good, SSL_CTX_sess_accept_renegotiate, SSL_CTX_sess_hits, SSL_CTX_sess_cb_hits, SSL_CTX_sess_misses, SSL_CTX_sess_timeouts, SSL_CTX_sess_cache_full \- obtain session cache statistics -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_sess_number(SSL_CTX *ctx); -\& long SSL_CTX_sess_connect(SSL_CTX *ctx); -\& long SSL_CTX_sess_connect_good(SSL_CTX *ctx); -\& long SSL_CTX_sess_connect_renegotiate(SSL_CTX *ctx); -\& long SSL_CTX_sess_accept(SSL_CTX *ctx); -\& long SSL_CTX_sess_accept_good(SSL_CTX *ctx); -\& long SSL_CTX_sess_accept_renegotiate(SSL_CTX *ctx); -\& long SSL_CTX_sess_hits(SSL_CTX *ctx); -\& long SSL_CTX_sess_cb_hits(SSL_CTX *ctx); -\& long SSL_CTX_sess_misses(SSL_CTX *ctx); -\& long SSL_CTX_sess_timeouts(SSL_CTX *ctx); -\& long SSL_CTX_sess_cache_full(SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_sess_number()\fR returns the current number of sessions in the internal -session cache. -.PP -\&\fBSSL_CTX_sess_connect()\fR returns the number of started \s-1SSL/TLS\s0 handshakes in -client mode. -.PP -\&\fBSSL_CTX_sess_connect_good()\fR returns the number of successfully established -\&\s-1SSL/TLS\s0 sessions in client mode. -.PP -\&\fBSSL_CTX_sess_connect_renegotiate()\fR returns the number of started renegotiations -in client mode. -.PP -\&\fBSSL_CTX_sess_accept()\fR returns the number of started \s-1SSL/TLS\s0 handshakes in -server mode. -.PP -\&\fBSSL_CTX_sess_accept_good()\fR returns the number of successfully established -\&\s-1SSL/TLS\s0 sessions in server mode. -.PP -\&\fBSSL_CTX_sess_accept_renegotiate()\fR returns the number of started renegotiations -in server mode. -.PP -\&\fBSSL_CTX_sess_hits()\fR returns the number of successfully reused sessions. -In client mode a session set with \fBSSL_set_session\fR\|(3) -successfully reused is counted as a hit. In server mode a session successfully -retrieved from internal or external cache is counted as a hit. -.PP -\&\fBSSL_CTX_sess_cb_hits()\fR returns the number of successfully retrieved sessions -from the external session cache in server mode. -.PP -\&\fBSSL_CTX_sess_misses()\fR returns the number of sessions proposed by clients -that were not found in the internal session cache in server mode. -.PP -\&\fBSSL_CTX_sess_timeouts()\fR returns the number of sessions proposed by clients -and either found in the internal or external session cache in server mode, - but that were invalid due to timeout. These sessions are not included in -the \fBSSL_CTX_sess_hits()\fR count. -.PP -\&\fBSSL_CTX_sess_cache_full()\fR returns the number of sessions that were removed -because the maximum session cache size was exceeded. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions return the values indicated in the \s-1DESCRIPTION\s0 section. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_set_session\fR\|(3), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3) -\&\fBSSL_CTX_sess_set_cache_size\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_set_cache_size.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_set_cache_size.3ossl deleted file mode 100644 index 74af7af3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_set_cache_size.3ossl +++ /dev/null @@ -1,193 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SESS_SET_CACHE_SIZE 3ossl" -.TH SSL_CTX_SESS_SET_CACHE_SIZE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_sess_set_cache_size, SSL_CTX_sess_get_cache_size \- manipulate session cache size -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_sess_set_cache_size(SSL_CTX *ctx, long t); -\& long SSL_CTX_sess_get_cache_size(SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_sess_set_cache_size()\fR sets the size of the internal session cache -of context \fBctx\fR to \fBt\fR. -This value is a hint and not an absolute; see the notes below. -.PP -\&\fBSSL_CTX_sess_get_cache_size()\fR returns the currently valid session cache size. -.SH "NOTES" -.IX Header "NOTES" -The internal session cache size is \s-1SSL_SESSION_CACHE_MAX_SIZE_DEFAULT,\s0 -currently 1024*20, so that up to 20000 sessions can be held. This size -can be modified using the \fBSSL_CTX_sess_set_cache_size()\fR call. A special -case is the size 0, which is used for unlimited size. -.PP -If adding the session makes the cache exceed its size, then unused -sessions are dropped from the end of the cache. -Cache space may also be reclaimed by calling -\&\fBSSL_CTX_flush_sessions\fR\|(3) to remove -expired sessions. -.PP -If the size of the session cache is reduced and more sessions are already -in the session cache, old session will be removed at the next time a -session shall be added. This removal is not synchronized with the -expiration of sessions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_sess_set_cache_size()\fR returns the previously valid size. -.PP -\&\fBSSL_CTX_sess_get_cache_size()\fR returns the currently valid size. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -\&\fBSSL_CTX_sess_number\fR\|(3), -\&\fBSSL_CTX_flush_sessions\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_set_get_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_set_get_cb.3ossl deleted file mode 100644 index 376fb3c9..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_set_get_cb.3ossl +++ /dev/null @@ -1,254 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SESS_SET_GET_CB 3ossl" -.TH SSL_CTX_SESS_SET_GET_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_sess_set_new_cb, SSL_CTX_sess_set_remove_cb, SSL_CTX_sess_set_get_cb, SSL_CTX_sess_get_new_cb, SSL_CTX_sess_get_remove_cb, SSL_CTX_sess_get_get_cb \- provide callback functions for server side external session caching -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_sess_set_new_cb(SSL_CTX *ctx, -\& int (*new_session_cb)(SSL *, SSL_SESSION *)); -\& void SSL_CTX_sess_set_remove_cb(SSL_CTX *ctx, -\& void (*remove_session_cb)(SSL_CTX *ctx, -\& SSL_SESSION *)); -\& void SSL_CTX_sess_set_get_cb(SSL_CTX *ctx, -\& SSL_SESSION (*get_session_cb)(SSL *, -\& const unsigned char *, -\& int, int *)); -\& -\& int (*SSL_CTX_sess_get_new_cb(SSL_CTX *ctx))(struct ssl_st *ssl, -\& SSL_SESSION *sess); -\& void (*SSL_CTX_sess_get_remove_cb(SSL_CTX *ctx))(struct ssl_ctx_st *ctx, -\& SSL_SESSION *sess); -\& SSL_SESSION *(*SSL_CTX_sess_get_get_cb(SSL_CTX *ctx))(struct ssl_st *ssl, -\& const unsigned char *data, -\& int len, int *copy); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_sess_set_new_cb()\fR sets the callback function that is -called whenever a new session was negotiated. -.PP -\&\fBSSL_CTX_sess_set_remove_cb()\fR sets the callback function that is -called whenever a session is removed by the \s-1SSL\s0 engine. For example, -this can occur because a session is considered faulty or has become obsolete -because of exceeding the timeout value. -.PP -\&\fBSSL_CTX_sess_set_get_cb()\fR sets the callback function that is called -whenever a \s-1TLS\s0 client proposed to resume a session but the session -could not be found in the internal session cache (see -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3)). -(\s-1TLS\s0 server only.) -.PP -\&\fBSSL_CTX_sess_get_new_cb()\fR, \fBSSL_CTX_sess_get_remove_cb()\fR, and -\&\fBSSL_CTX_sess_get_get_cb()\fR retrieve the function pointers set by the -corresponding set callback functions. If a callback function has not been -set, the \s-1NULL\s0 pointer is returned. -.SH "NOTES" -.IX Header "NOTES" -In order to allow external session caching, synchronization with the internal -session cache is realized via callback functions. Inside these callback -functions, session can be saved to disk or put into a database using the -\&\fBd2i_SSL_SESSION\fR\|(3) interface. -.PP -The \fBnew_session_cb()\fR is called whenever a new session has been negotiated and -session caching is enabled (see \fBSSL_CTX_set_session_cache_mode\fR\|(3)). The -\&\fBnew_session_cb()\fR is passed the \fBssl\fR connection and the nascent -ssl session \fBsess\fR. -Since sessions are reference-counted objects, the reference count on the -session is incremented before the callback, on behalf of the application. If -the callback returns \fB0\fR, the session will be immediately removed from the -internal cache and the reference count released. If the callback returns \fB1\fR, -the application retains the reference (for an entry in the -application-maintained \*(L"external session cache\*(R"), and is responsible for -calling \fBSSL_SESSION_free()\fR when the session reference is no longer in use. -.PP -Note that in TLSv1.3, sessions are established after the main -handshake has completed. The server decides when to send the client the session -information and this may occur some time after the end of the handshake (or not -at all). This means that applications should expect the \fBnew_session_cb()\fR -function to be invoked during the handshake (for <= TLSv1.2) or after the -handshake (for TLSv1.3). It is also possible in TLSv1.3 for multiple sessions to -be established with a single connection. In these case the \fBnew_session_cb()\fR -function will be invoked multiple times. -.PP -In TLSv1.3 it is recommended that each \s-1SSL_SESSION\s0 object is only used for -resumption once. One way of enforcing that is for applications to call -\&\fBSSL_CTX_remove_session\fR\|(3) after a session has been used. -.PP -The \fBremove_session_cb()\fR is called whenever the \s-1SSL\s0 engine removes a session -from the internal cache. This can happen when the session is removed because -it is expired or when a connection was not shutdown cleanly. It also happens -for all sessions in the internal session cache when -\&\fBSSL_CTX_free\fR\|(3) is called. The \fBremove_session_cb()\fR is passed -the \fBctx\fR and the ssl session \fBsess\fR. It does not provide any feedback. -.PP -The \fBget_session_cb()\fR is only called on \s-1SSL/TLS\s0 servers, and is given -the session id -proposed by the client. The \fBget_session_cb()\fR is always called, even when -session caching was disabled. The \fBget_session_cb()\fR is passed the -\&\fBssl\fR connection and the session id of length \fBlength\fR at the memory location -\&\fBdata\fR. By setting the parameter \fBcopy\fR to \fB1\fR, the callback can require the -\&\s-1SSL\s0 engine to increment the reference count of the \s-1SSL_SESSION\s0 object; -setting \fBcopy\fR to \fB0\fR causes the reference count to remain unchanged. -If the \fBget_session_cb()\fR does not write to \fBcopy\fR, the reference count -is incremented and the session must be explicitly freed with -\&\fBSSL_SESSION_free\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_sess_get_new_cb()\fR, \fBSSL_CTX_sess_get_remove_cb()\fR and \fBSSL_CTX_sess_get_get_cb()\fR -return different callback function pointers respectively. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBd2i_SSL_SESSION\fR\|(3), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -\&\fBSSL_CTX_flush_sessions\fR\|(3), -\&\fBSSL_SESSION_free\fR\|(3), -\&\fBSSL_CTX_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_set_new_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_set_new_cb.3ossl deleted file mode 120000 index 171e3a57..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_set_new_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_set_get_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_set_remove_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_set_remove_cb.3ossl deleted file mode 120000 index 171e3a57..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_set_remove_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_set_get_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sess_timeouts.3ossl b/openssl-install/share/man/man3/SSL_CTX_sess_timeouts.3ossl deleted file mode 120000 index b664109c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sess_timeouts.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_sess_number.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_sessions.3ossl b/openssl-install/share/man/man3/SSL_CTX_sessions.3ossl deleted file mode 100644 index 612a350d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_sessions.3ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SESSIONS 3ossl" -.TH SSL_CTX_SESSIONS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_sessions \- access internal session cache -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& LHASH_OF(SSL_SESSION) *SSL_CTX_sessions(SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_sessions()\fR returns a pointer to the lhash databases containing the -internal session cache for \fBctx\fR. -.SH "NOTES" -.IX Header "NOTES" -The sessions in the internal session cache are kept in an -\&\s-1\fBLHASH\s0\fR\|(3) type database. It is possible to directly -access this database e.g. for searching. In parallel, the sessions -form a linked list which is maintained separately from the -\&\s-1\fBLHASH\s0\fR\|(3) operations, so that the database must not be -modified directly but by using the -\&\fBSSL_CTX_add_session\fR\|(3) family of functions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_sessions()\fR returns a pointer to the lhash of \fB\s-1SSL_SESSION\s0\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \s-1\fBLHASH\s0\fR\|(3), -\&\fBSSL_CTX_add_session\fR\|(3), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set0_CA_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set0_CA_list.3ossl deleted file mode 100644 index 7e2cffb4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set0_CA_list.3ossl +++ /dev/null @@ -1,320 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET0_CA_LIST 3ossl" -.TH SSL_CTX_SET0_CA_LIST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_client_CA_list, -SSL_set_client_CA_list, -SSL_get_client_CA_list, -SSL_CTX_get_client_CA_list, -SSL_CTX_add_client_CA, -SSL_add_client_CA, -SSL_set0_CA_list, -SSL_CTX_set0_CA_list, -SSL_get0_CA_list, -SSL_CTX_get0_CA_list, -SSL_add1_to_CA_list, -SSL_CTX_add1_to_CA_list, -SSL_get0_peer_CA_list -\&\- get or set CA list -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_client_CA_list(SSL_CTX *ctx, STACK_OF(X509_NAME) *list); -\& void SSL_set_client_CA_list(SSL *s, STACK_OF(X509_NAME) *list); -\& STACK_OF(X509_NAME) *SSL_get_client_CA_list(const SSL *s); -\& STACK_OF(X509_NAME) *SSL_CTX_get_client_CA_list(const SSL_CTX *ctx); -\& int SSL_CTX_add_client_CA(SSL_CTX *ctx, X509 *cacert); -\& int SSL_add_client_CA(SSL *ssl, X509 *cacert); -\& -\& void SSL_CTX_set0_CA_list(SSL_CTX *ctx, STACK_OF(X509_NAME) *name_list); -\& void SSL_set0_CA_list(SSL *s, STACK_OF(X509_NAME) *name_list); -\& const STACK_OF(X509_NAME) *SSL_CTX_get0_CA_list(const SSL_CTX *ctx); -\& const STACK_OF(X509_NAME) *SSL_get0_CA_list(const SSL *s); -\& int SSL_CTX_add1_to_CA_list(SSL_CTX *ctx, const X509 *x); -\& int SSL_add1_to_CA_list(SSL *ssl, const X509 *x); -\& -\& const STACK_OF(X509_NAME) *SSL_get0_peer_CA_list(const SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions described here set and manage the list of \s-1CA\s0 names that are sent -between two communicating peers. -.PP -For \s-1TLS\s0 versions 1.2 and earlier the list of \s-1CA\s0 names is only sent from the -server to the client when requesting a client certificate. So any list of \s-1CA\s0 -names set is never sent from client to server and the list of \s-1CA\s0 names retrieved -by \fBSSL_get0_peer_CA_list()\fR is always \fB\s-1NULL\s0\fR. -.PP -For \s-1TLS 1.3\s0 the list of \s-1CA\s0 names is sent using the \fBcertificate_authorities\fR -extension and may be sent by a client (in the ClientHello message) or by -a server (when requesting a certificate). -.PP -In most cases it is not necessary to set \s-1CA\s0 names on the client side. The list -of \s-1CA\s0 names that are acceptable to the client will be sent in plaintext to the -server. This has privacy implications and may also have performance implications -if the list is large. This optional capability was introduced as part of TLSv1.3 -and therefore setting \s-1CA\s0 names on the client side will have no impact if that -protocol version has been disabled. Most servers do not need this and so this -should be avoided unless required. -.PP -The \*(L"client \s-1CA\s0 list\*(R" functions below only have an effect when called on the -server side. -.PP -\&\fBSSL_CTX_set_client_CA_list()\fR sets the \fBlist\fR of CAs sent to the client when -requesting a client certificate for \fBctx\fR. Ownership of \fBlist\fR is transferred -to \fBctx\fR and it should not be freed by the caller. -.PP -\&\fBSSL_set_client_CA_list()\fR sets the \fBlist\fR of CAs sent to the client when -requesting a client certificate for the chosen \fBssl\fR, overriding the -setting valid for \fBssl\fR's \s-1SSL_CTX\s0 object. Ownership of \fBlist\fR is transferred -to \fBs\fR and it should not be freed by the caller. -.PP -\&\fBSSL_CTX_get_client_CA_list()\fR returns the list of client CAs explicitly set for -\&\fBctx\fR using \fBSSL_CTX_set_client_CA_list()\fR. The returned list should not be freed -by the caller. -.PP -\&\fBSSL_get_client_CA_list()\fR returns the list of client CAs explicitly -set for \fBssl\fR using \fBSSL_set_client_CA_list()\fR or \fBssl\fR's \s-1SSL_CTX\s0 object with -\&\fBSSL_CTX_set_client_CA_list()\fR, when in server mode. In client mode, -SSL_get_client_CA_list returns the list of client CAs sent from the server, if -any. The returned list should not be freed by the caller. -.PP -\&\fBSSL_CTX_add_client_CA()\fR adds the \s-1CA\s0 name extracted from \fBcacert\fR to the -list of CAs sent to the client when requesting a client certificate for -\&\fBctx\fR. -.PP -\&\fBSSL_add_client_CA()\fR adds the \s-1CA\s0 name extracted from \fBcacert\fR to the -list of CAs sent to the client when requesting a client certificate for -the chosen \fBssl\fR, overriding the setting valid for \fBssl\fR's \s-1SSL_CTX\s0 object. -.PP -\&\fBSSL_get0_peer_CA_list()\fR retrieves the list of \s-1CA\s0 names (if any) the peer -has sent. This can be called on either the server or the client side. The -returned list should not be freed by the caller. -.PP -The \*(L"generic \s-1CA\s0 list\*(R" functions below are very similar to the \*(L"client \s-1CA\s0 -list\*(R" functions except that they have an effect on both the server and client -sides. The lists of \s-1CA\s0 names managed are separate \- so you cannot (for example) -set \s-1CA\s0 names using the \*(L"client \s-1CA\s0 list\*(R" functions and then get them using the -\&\*(L"generic \s-1CA\s0 list\*(R" functions. Where a mix of the two types of functions has been -used on the server side then the \*(L"client \s-1CA\s0 list\*(R" functions take precedence. -Typically, on the server side, the \*(L"client \s-1CA\s0 list \*(R" functions should be used in -preference. As noted above in most cases it is not necessary to set \s-1CA\s0 names on -the client side. -.PP -\&\fBSSL_CTX_set0_CA_list()\fR sets the list of CAs to be sent to the peer to -\&\fBname_list\fR. Ownership of \fBname_list\fR is transferred to \fBctx\fR and -it should not be freed by the caller. -.PP -\&\fBSSL_set0_CA_list()\fR sets the list of CAs to be sent to the peer to \fBname_list\fR -overriding any list set in the parent \fB\s-1SSL_CTX\s0\fR of \fBs\fR. Ownership of -\&\fBname_list\fR is transferred to \fBs\fR and it should not be freed by the caller. -.PP -\&\fBSSL_CTX_get0_CA_list()\fR retrieves any previously set list of CAs set for -\&\fBctx\fR. The returned list should not be freed by the caller. -.PP -\&\fBSSL_get0_CA_list()\fR retrieves any previously set list of CAs set for -\&\fBs\fR or if none are set the list from the parent \fB\s-1SSL_CTX\s0\fR is retrieved. The -returned list should not be freed by the caller. -.PP -\&\fBSSL_CTX_add1_to_CA_list()\fR appends the \s-1CA\s0 subject name extracted from \fBx\fR to the -list of CAs sent to peer for \fBctx\fR. -.PP -\&\fBSSL_add1_to_CA_list()\fR appends the \s-1CA\s0 subject name extracted from \fBx\fR to the -list of CAs sent to the peer for \fBs\fR, overriding the setting in the parent -\&\fB\s-1SSL_CTX\s0\fR. -.SH "NOTES" -.IX Header "NOTES" -When a \s-1TLS/SSL\s0 server requests a client certificate (see -\&\fB\fBSSL_CTX_set_verify\fB\|(3)\fR), it sends a list of CAs, for which it will accept -certificates, to the client. -.PP -This list must explicitly be set using \fBSSL_CTX_set_client_CA_list()\fR or -\&\fBSSL_CTX_set0_CA_list()\fR for \fBctx\fR and \fBSSL_set_client_CA_list()\fR or -\&\fBSSL_set0_CA_list()\fR for the specific \fBssl\fR. The list specified -overrides the previous setting. The CAs listed do not become trusted (\fBlist\fR -only contains the names, not the complete certificates); use -\&\fBSSL_CTX_load_verify_locations\fR\|(3) to additionally load them for verification. -.PP -If the list of acceptable CAs is compiled in a file, the -\&\fBSSL_load_client_CA_file\fR\|(3) function can be used to help to import the -necessary data. -.PP -\&\fBSSL_CTX_add_client_CA()\fR, \fBSSL_CTX_add1_to_CA_list()\fR, \fBSSL_add_client_CA()\fR and -\&\fBSSL_add1_to_CA_list()\fR can be used to add additional items the list of CAs. If no -list was specified before using \fBSSL_CTX_set_client_CA_list()\fR, -\&\fBSSL_CTX_set0_CA_list()\fR, \fBSSL_set_client_CA_list()\fR or \fBSSL_set0_CA_list()\fR, a -new \s-1CA\s0 list for \fBctx\fR or \fBssl\fR (as appropriate) is opened. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_client_CA_list()\fR, \fBSSL_set_client_CA_list()\fR, -\&\fBSSL_CTX_set_client_CA_list()\fR, \fBSSL_set_client_CA_list()\fR, \fBSSL_CTX_set0_CA_list()\fR -and \fBSSL_set0_CA_list()\fR do not return a value. -.PP -\&\fBSSL_CTX_get_client_CA_list()\fR, \fBSSL_get_client_CA_list()\fR, \fBSSL_CTX_get0_CA_list()\fR -and \fBSSL_get0_CA_list()\fR return a stack of \s-1CA\s0 names or \fB\s-1NULL\s0\fR is no \s-1CA\s0 names are -set. -.PP -\&\fBSSL_CTX_add_client_CA()\fR,\fBSSL_add_client_CA()\fR, \fBSSL_CTX_add1_to_CA_list()\fR and -\&\fBSSL_add1_to_CA_list()\fR return 1 for success and 0 for failure. -.PP -\&\fBSSL_get0_peer_CA_list()\fR returns a stack of \s-1CA\s0 names sent by the peer or -\&\fB\s-1NULL\s0\fR or an empty stack if no list was sent. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Scan all certificates in \fBCAfile\fR and list them as acceptable CAs: -.PP -.Vb 1 -\& SSL_CTX_set_client_CA_list(ctx, SSL_load_client_CA_file(CAfile)); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_load_client_CA_file\fR\|(3), -\&\fBSSL_CTX_load_verify_locations\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set0_chain.3ossl b/openssl-install/share/man/man3/SSL_CTX_set0_chain.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set0_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set0_chain_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_set0_chain_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set0_chain_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set0_security_ex_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_set0_security_ex_data.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set0_security_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set0_tmp_dh_pkey.3ossl b/openssl-install/share/man/man3/SSL_CTX_set0_tmp_dh_pkey.3ossl deleted file mode 120000 index 838d6609..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set0_tmp_dh_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_dh_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set0_verify_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_set0_verify_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set0_verify_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_cert_comp_preference.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_cert_comp_preference.3ossl deleted file mode 100644 index 2a6f4bcf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_cert_comp_preference.3ossl +++ /dev/null @@ -1,281 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET1_CERT_COMP_PREFERENCE 3ossl" -.TH SSL_CTX_SET1_CERT_COMP_PREFERENCE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set1_cert_comp_preference, -SSL_set1_cert_comp_preference, -SSL_CTX_compress_certs, -SSL_compress_certs, -SSL_CTX_get1_compressed_cert, -SSL_get1_compressed_cert, -SSL_CTX_set1_compressed_cert, -SSL_set1_compressed_cert \- Certificate compression functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set1_cert_comp_preference(SSL_CTX *ctx, int *algs, size_t len); -\& int SSL_set1_cert_comp_preference(SSL *ssl, int *algs, size_t len); -\& -\& int SSL_CTX_compress_certs(SSL_CTX *ctx, int alg); -\& int SSL_compress_certs(SSL *ssl, int alg); -\& -\& size_t SSL_CTX_get1_compressed_cert(SSL_CTX *ctx, int alg, unsigned char **data, -\& size_t *orig_len); -\& size_t SSL_get1_compressed_cert(SSL *ssl, int alg, unsigned char **data, -\& size_t *orig_len); -\& -\& int SSL_CTX_set1_compressed_cert(SSL_CTX *ctx, int alg, -\& unsigned char *comp_data, -\& size_t comp_length, size_t orig_length); -\& int SSL_set1_compressed_cert(SSL *ssl, int alg, unsigned char *comp_data, -\& size_t comp_length, size_t orig_length); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions control the certificate compression feature. Certificate -compression is only available for TLSv1.3 as defined in \s-1RFC8879.\s0 -.PP -\&\fBSSL_CTX_set1_cert_comp_preference()\fR and \fBSSL_set1_cert_comp_preference()\fR are used -to specify the preferred compression algorithms. The \fBalgs\fR argument is an array -of algorithms, and \fBlength\fR is number of elements in the \fBalgs\fR array. Only -those algorithms enabled in the library will be accepted in \fBalgs\fR, unknown -algorithms in \fBalgs\fR are ignored. On an error, the preference order is left -unmodified. -.PP -The following compression algorithms (\fBalg\fR arguments) may be used: -.IP "\(bu" 4 -TLSEXT_comp_cert_brotli -.IP "\(bu" 4 -TLSEXT_comp_cert_zlib -.IP "\(bu" 4 -TLSEXT_comp_cert_zstd -.PP -The above is also the default preference order. If a preference order is not -specified, then the default preference order is sent to the peer and the -received peer's preference order will be used when compressing a certificate. -Otherwise, the configured preference order is sent to the peer and is used -to filter the peer's preference order. -.PP -\&\fBSSL_CTX_compress_certs()\fR and \fBSSL_compress_certs()\fR are used to pre-compress all -the configured certificates on an \s-1SSL_CTX/SSL\s0 object with algorithm \fBalg\fR. If -\&\fBalg\fR is 0, then the certificates are compressed with the algorithms specified -in the preference list. Calling these functions on a client \s-1SSL_CTX/SSL\s0 object -will result in an error, as only server certificates may be pre-compressed. -.PP -\&\fBSSL_CTX_get1_compressed_cert()\fR and \fBSSL_get1_compressed_cert()\fR are used to get -the pre-compressed certificate most recently set that may be stored for later -use. Calling these functions on a client \s-1SSL_CTX/SSL\s0 object will result in an -error, as only server certificates may be pre-compressed. The \fBdata\fR and -\&\fBorig_len\fR arguments are required. -.PP -The compressed certificate data may be passed to \fBSSL_CTX_set1_compressed_cert()\fR -or \fBSSL_set1_compressed_cert()\fR to provide a pre-compressed version of the -most recently set certificate. This pre-compressed certificate can only be used -by a server. -.SH "NOTES" -.IX Header "NOTES" -Each side of the connection sends their compression algorithm preference list -to their peer indicating compressed certificate support. The received preference -list is filtered by the configured preference list (i.e. the intersection is -saved). As the default list includes all the enabled algorithms, not specifying -a preference will allow any enabled algorithm by the peer. The filtered peer's -preference order is used to determine what algorithm to use when sending a -compressed certificate. -.PP -Only server certificates may be pre-compressed. Calling any of these functions -(except \fBSSL_CTX_set1_cert_comp_preference()\fR/\fBSSL_set1_cert_comp_preference()\fR) -on a client \s-1SSL_CTX/SSL\s0 object will return an error. Client certificates are -compressed on-demand as unique context data from the server is compressed along -with the certificate. -.PP -For \fBSSL_CTX_set1_cert_comp_preference()\fR and \fBSSL_set1_cert_comp_preference()\fR -the \fBlen\fR argument is the size of the \fBalgs\fR argument in bytes. -.PP -The compressed certificate returned by \fBSSL_CTX_get1_compressed_cert()\fR and -\&\fBSSL_get1_compressed_cert()\fR is the last certificate set on the \s-1SSL_CTX/SSL\s0 object. -The certificate is copied by the function and the caller must free \fB*data\fR via -\&\fBOPENSSL_free()\fR. -.PP -The compressed certificate data set by \fBSSL_CTX_set1_compressed_cert()\fR and -\&\fBSSL_set1_compressed_cert()\fR is copied into the \s-1SSL_CTX/SSL\s0 object. -.PP -\&\fBSSL_CTX_compress_certs()\fR and \fBSSL_compress_certs()\fR return an error under the -following conditions: -.IP "\(bu" 4 -If no certificates have been configured. -.IP "\(bu" 4 -If the specified algorithm \fBalg\fR is not enabled. -.IP "\(bu" 4 -If \fBalg\fR is 0 and no compression algorithms are enabled. -.PP -Sending compressed certificates may be disabled on a connection via the -\&\s-1SSL_OP_NO_TX_CERTIFICATE_COMPRESSION\s0 option. Receiving compressed certificates -may be disabled on a connection via the \s-1SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\s0 -option. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set1_cert_comp_preference()\fR, -\&\fBSSL_set1_cert_comp_preference()\fR, -\&\fBSSL_CTX_compress_certs()\fR, -\&\fBSSL_compress_certs()\fR, -\&\fBSSL_CTX_set1_compressed_cert()\fR, and -\&\fBSSL_set1_compressed_cert()\fR -return 1 for success and 0 on error. -.PP -\&\fBSSL_CTX_get1_compressed_cert()\fR and -\&\fBSSL_get1_compressed_cert()\fR -return the length of the allocated memory on success and 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_set_options\fR\|(3), -\&\fBSSL_CTX_use_certificate\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_cert_store.3ossl deleted file mode 120000 index 4d089987..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_chain.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_chain.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_chain_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_chain_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_chain_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_client_cert_type.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_client_cert_type.3ossl deleted file mode 120000 index 44c96a96..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_client_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_server_cert_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs.3ossl deleted file mode 120000 index f594d7af..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs_list.3ossl deleted file mode 120000 index f594d7af..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_client_sigalgs_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_compressed_cert.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_compressed_cert.3ossl deleted file mode 120000 index 7aaf058c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_compressed_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_cert_comp_preference.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_curves.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_curves.3ossl deleted file mode 100644 index d3b16661..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_curves.3ossl +++ /dev/null @@ -1,304 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET1_CURVES 3ossl" -.TH SSL_CTX_SET1_CURVES 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set1_groups, SSL_CTX_set1_groups_list, SSL_set1_groups, -SSL_set1_groups_list, SSL_get1_groups, SSL_get0_iana_groups, -SSL_get_shared_group, SSL_get_negotiated_group, SSL_CTX_set1_curves, -SSL_CTX_set1_curves_list, SSL_set1_curves, SSL_set1_curves_list, -SSL_get1_curves, SSL_get_shared_curve -\&\- EC supported curve functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set1_groups(SSL_CTX *ctx, int *glist, int glistlen); -\& int SSL_CTX_set1_groups_list(SSL_CTX *ctx, char *list); -\& -\& int SSL_set1_groups(SSL *ssl, int *glist, int glistlen); -\& int SSL_set1_groups_list(SSL *ssl, char *list); -\& -\& int SSL_get1_groups(SSL *ssl, int *groups); -\& int SSL_get0_iana_groups(SSL *ssl, uint16_t **out); -\& int SSL_get_shared_group(SSL *s, int n); -\& int SSL_get_negotiated_group(SSL *s); -\& -\& int SSL_CTX_set1_curves(SSL_CTX *ctx, int *clist, int clistlen); -\& int SSL_CTX_set1_curves_list(SSL_CTX *ctx, char *list); -\& -\& int SSL_set1_curves(SSL *ssl, int *clist, int clistlen); -\& int SSL_set1_curves_list(SSL *ssl, char *list); -\& -\& int SSL_get1_curves(SSL *ssl, int *curves); -\& int SSL_get_shared_curve(SSL *s, int n); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -For all of the functions below that set the supported groups there must be at -least one group in the list. A number of these functions identify groups via a -unique integer \s-1NID\s0 value. However, support for some groups may be added by -external providers. In this case there will be no \s-1NID\s0 assigned for the group. -When setting such groups applications should use the \*(L"list\*(R" form of these -functions (i.e. \fBSSL_CTX_set1_groups_list()\fR and SSL_set1_groups_list). -.PP -\&\fBSSL_CTX_set1_groups()\fR sets the supported groups for \fBctx\fR to \fBglistlen\fR -groups in the array \fBglist\fR. The array consist of all NIDs of supported groups. -Currently supported groups for \fBTLSv1.3\fR are \fBNID_X9_62_prime256v1\fR, -\&\fBNID_secp384r1\fR, \fBNID_secp521r1\fR, \fB\s-1NID_X25519\s0\fR, \fB\s-1NID_X448\s0\fR, -\&\fBNID_brainpoolP256r1tls13\fR, \fBNID_brainpoolP384r1tls13\fR, -\&\fBNID_brainpoolP512r1tls13\fR, \fBNID_ffdhe2048\fR, \fBNID_ffdhe3072\fR, -\&\fBNID_ffdhe4096\fR, \fBNID_ffdhe6144\fR and \fBNID_ffdhe8192\fR. -OpenSSL will use this array in different ways depending on \s-1TLS\s0 role and version: -.IP "For a \s-1TLS\s0 client, the groups are used directly in the supported groups extension. The extension's preference order, to be evaluated by the server, is determined by the order of the elements in the array." 4 -.IX Item "For a TLS client, the groups are used directly in the supported groups extension. The extension's preference order, to be evaluated by the server, is determined by the order of the elements in the array." -.PD 0 -.IP "For a \s-1TLS 1.2\s0 server, the groups determine the selected group. If \fB\s-1SSL_OP_CIPHER_SERVER_PREFERENCE\s0\fR is set, the order of the elements in the array determines the selected group. Otherwise, the order is ignored and the client's order determines the selection." 4 -.IX Item "For a TLS 1.2 server, the groups determine the selected group. If SSL_OP_CIPHER_SERVER_PREFERENCE is set, the order of the elements in the array determines the selected group. Otherwise, the order is ignored and the client's order determines the selection." -.IP "For a \s-1TLS 1.3\s0 server, the groups determine the selected group, but selection is more complex. A \s-1TLS 1.3\s0 client sends both a group list as well as a predicted subset of groups. Choosing a group outside the predicted subset incurs an extra roundtrip. However, in some situations, the most preferred group may not be predicted. OpenSSL considers all supported groups to be comparable in security and prioritizes avoiding roundtrips above either client or server preference order. If an application uses an external provider to extend OpenSSL with, e.g., a post-quantum algorithm, this behavior may allow a network attacker to downgrade connections to a weaker algorithm." 4 -.IX Item "For a TLS 1.3 server, the groups determine the selected group, but selection is more complex. A TLS 1.3 client sends both a group list as well as a predicted subset of groups. Choosing a group outside the predicted subset incurs an extra roundtrip. However, in some situations, the most preferred group may not be predicted. OpenSSL considers all supported groups to be comparable in security and prioritizes avoiding roundtrips above either client or server preference order. If an application uses an external provider to extend OpenSSL with, e.g., a post-quantum algorithm, this behavior may allow a network attacker to downgrade connections to a weaker algorithm." -.PD -.PP -\&\fBSSL_CTX_set1_groups_list()\fR sets the supported groups for \fBctx\fR to -string \fBlist\fR. The string is a colon separated list of group names, for example -\&\*(L"P\-521:P\-384:P\-256:X25519:ffdhe2048\*(R". The groups are used as in -\&\fBSSL_CTX_set1_groups()\fR, described above. Currently supported groups for -\&\fBTLSv1.3\fR are \fBP\-256\fR, \fBP\-384\fR, \fBP\-521\fR, \fBX25519\fR, \fBX448\fR, -\&\fBbrainpoolP256r1tls13\fR, \fBbrainpoolP384r1tls13\fR, \fBbrainpoolP512r1tls13\fR, -\&\fBffdhe2048\fR, \fBffdhe3072\fR, \fBffdhe4096\fR, \fBffdhe6144\fR and \fBffdhe8192\fR. Support -for other groups may be added by external providers, however note the discussion -on \s-1TLS 1.3\s0 selection criteria above. If a group name is preceded with the \f(CW\*(C`?\*(C'\fR -character, it will be ignored if an implementation is missing. -.PP -\&\fBSSL_set1_groups()\fR and \fBSSL_set1_groups_list()\fR are similar except they set -supported groups for the \s-1SSL\s0 structure \fBssl\fR. -.PP -\&\fBSSL_get1_groups()\fR returns the set of supported groups sent by a client -in the supported groups extension. It returns the total number of -supported groups. The \fBgroups\fR parameter can be \fB\s-1NULL\s0\fR to simply -return the number of groups for memory allocation purposes. The -\&\fBgroups\fR array is in the form of a set of group NIDs in preference -order. It can return zero if the client did not send a supported groups -extension. If a supported group \s-1NID\s0 is unknown then the value is set to the -bitwise \s-1OR\s0 of TLSEXT_nid_unknown (0x1000000) and the id of the group. -.PP -\&\fBSSL_get0_iana_groups()\fR retrieves the list of groups sent by the -client in the supported_groups extension. The \fB*out\fR array of bytes -is populated with the host-byte-order representation of the uint16_t group -identifiers, as assigned by \s-1IANA.\s0 The group list is returned in the same order -that was received in the ClientHello. The return value is the number of groups, -not the number of bytes written. -.PP -\&\fBSSL_get_shared_group()\fR returns the \s-1NID\s0 of the shared group \fBn\fR for a -server-side \s-1SSL\s0 \fBssl\fR. If \fBn\fR is \-1 then the total number of shared groups is -returned, which may be zero. Other than for diagnostic purposes, -most applications will only be interested in the first shared group -so \fBn\fR is normally set to zero. If the value \fBn\fR is out of range, -NID_undef is returned. If the \s-1NID\s0 for the shared group is unknown then the value -is set to the bitwise \s-1OR\s0 of TLSEXT_nid_unknown (0x1000000) and the id of the -group. -.PP -\&\fBSSL_get_negotiated_group()\fR returns the \s-1NID\s0 of the negotiated group used for -the handshake key exchange process. For TLSv1.3 connections this typically -reflects the state of the current connection, though in the case of PSK-only -resumption, the returned value will be from a previous connection. For earlier -\&\s-1TLS\s0 versions, when a session has been resumed, it always reflects the group -used for key exchange during the initial handshake (otherwise it is from the -current, non-resumption, connection). This can be called by either client or -server. If the \s-1NID\s0 for the shared group is unknown then the value is set to the -bitwise \s-1OR\s0 of TLSEXT_nid_unknown (0x1000000) and the id of the group. See also -\&\fBSSL_get0_group_name\fR\|(3) which returns the name of the negotiated group -directly and is generally preferred over \fBSSL_get_negotiated_group()\fR. -.PP -All these functions are implemented as macros. -.PP -The curve functions are synonyms for the equivalently named group functions and -are identical in every respect. They exist because, prior to \s-1TLS1.3,\s0 there was -only the concept of supported curves. In \s-1TLS1.3\s0 this was renamed to supported -groups, and extended to include Diffie Hellman groups. The group functions -should be used in preference. -.SH "NOTES" -.IX Header "NOTES" -If an application wishes to make use of several of these functions for -configuration purposes either on a command line or in a file it should -consider using the \s-1SSL_CONF\s0 interface instead of manually parsing options. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set1_groups()\fR, \fBSSL_CTX_set1_groups_list()\fR, \fBSSL_set1_groups()\fR and -\&\fBSSL_set1_groups_list()\fR, return 1 for success and 0 for failure. -.PP -\&\fBSSL_get1_groups()\fR returns the number of groups, which may be zero. -.PP -\&\fBSSL_get0_iana_groups()\fR returns the number of (uint16_t) groups, which may be zero. -.PP -\&\fBSSL_get_shared_group()\fR returns the \s-1NID\s0 of shared group \fBn\fR or NID_undef if there -is no shared group \fBn\fR; or the total number of shared groups if \fBn\fR -is \-1. -.PP -When called on a client \fBssl\fR, \fBSSL_get_shared_group()\fR has no meaning and -returns \-1. -.PP -\&\fBSSL_get_negotiated_group()\fR returns the \s-1NID\s0 of the negotiated group used for -key exchange, or NID_undef if there was no negotiated group. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3), -\&\fBSSL_get0_group_name\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The curve functions were added in OpenSSL 1.0.2. The equivalent group -functions were added in OpenSSL 1.1.1. The \fBSSL_get_negotiated_group()\fR function -was added in OpenSSL 3.0.0. -.PP -Support for ignoring unknown groups in \fBSSL_CTX_set1_groups_list()\fR and -\&\fBSSL_set1_groups_list()\fR was added in OpenSSL 3.3. -.PP -Earlier versions of this document described the list as a preference order. -However, OpenSSL's behavior as a \s-1TLS 1.3\s0 server is to consider \fIall\fR -supported groups as comparable in security. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_curves_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_curves_list.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_curves_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_groups.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_groups.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_groups.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_groups_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_groups_list.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_groups_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_param.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_param.3ossl deleted file mode 120000 index fd781e23..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_server_cert_type.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_server_cert_type.3ossl deleted file mode 120000 index 44c96a96..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_server_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_server_cert_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_sigalgs.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_sigalgs.3ossl deleted file mode 100644 index 0f79c2cc..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_sigalgs.3ossl +++ /dev/null @@ -1,259 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET1_SIGALGS 3ossl" -.TH SSL_CTX_SET1_SIGALGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set1_sigalgs, SSL_set1_sigalgs, SSL_CTX_set1_sigalgs_list, -SSL_set1_sigalgs_list, SSL_CTX_set1_client_sigalgs, -SSL_set1_client_sigalgs, SSL_CTX_set1_client_sigalgs_list, -SSL_set1_client_sigalgs_list \- set supported signature algorithms -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set1_sigalgs(SSL_CTX *ctx, const int *slist, long slistlen); -\& long SSL_set1_sigalgs(SSL *ssl, const int *slist, long slistlen); -\& long SSL_CTX_set1_sigalgs_list(SSL_CTX *ctx, const char *str); -\& long SSL_set1_sigalgs_list(SSL *ssl, const char *str); -\& -\& long SSL_CTX_set1_client_sigalgs(SSL_CTX *ctx, const int *slist, long slistlen); -\& long SSL_set1_client_sigalgs(SSL *ssl, const int *slist, long slistlen); -\& long SSL_CTX_set1_client_sigalgs_list(SSL_CTX *ctx, const char *str); -\& long SSL_set1_client_sigalgs_list(SSL *ssl, const char *str); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set1_sigalgs()\fR and \fBSSL_set1_sigalgs()\fR set the supported signature -algorithms for \fBctx\fR or \fBssl\fR. The array \fBslist\fR of length \fBslistlen\fR -must consist of pairs of NIDs corresponding to digest and public key -algorithms. -.PP -\&\fBSSL_CTX_set1_sigalgs_list()\fR and \fBSSL_set1_sigalgs_list()\fR set the supported -signature algorithms for \fBctx\fR or \fBssl\fR. The \fBstr\fR parameter -must be a null terminated string consisting of a colon separated list of -elements, where each element is either a combination of a public key -algorithm and a digest separated by \fB+\fR, or a \s-1TLS 1\s0.3\-style named -SignatureScheme such as rsa_pss_pss_sha256. If a list entry is preceded -with the \f(CW\*(C`?\*(C'\fR character, it will be ignored if an implementation is missing. -.PP -\&\fBSSL_CTX_set1_client_sigalgs()\fR, \fBSSL_set1_client_sigalgs()\fR, -\&\fBSSL_CTX_set1_client_sigalgs_list()\fR and \fBSSL_set1_client_sigalgs_list()\fR set -signature algorithms related to client authentication, otherwise they are -identical to \fBSSL_CTX_set1_sigalgs()\fR, \fBSSL_set1_sigalgs()\fR, -\&\fBSSL_CTX_set1_sigalgs_list()\fR and \fBSSL_set1_sigalgs_list()\fR. -.PP -All these functions are implemented as macros. The signature algorithm -parameter (integer array or string) is not freed: the application should -free it, if necessary. -.SH "NOTES" -.IX Header "NOTES" -If an application wishes to allow the setting of signature algorithms -as one of many user configurable options it should consider using the more -flexible \s-1SSL_CONF API\s0 instead. -.PP -The signature algorithms set by a client are used directly in the supported -signature algorithm in the client hello message. -.PP -The supported signature algorithms set by a server are not sent to the -client but are used to determine the set of shared signature algorithms -and (if server preferences are set with \s-1SSL_OP_CIPHER_SERVER_PREFERENCE\s0) -their order. -.PP -The client authentication signature algorithms set by a server are sent -in a certificate request message if client authentication is enabled, -otherwise they are unused. -.PP -Similarly client authentication signature algorithms set by a client are -used to determined the set of client authentication shared signature -algorithms. -.PP -Signature algorithms will neither be advertised nor used if the security level -prohibits them (for example \s-1SHA1\s0 if the security level is 4 or more). -.PP -Currently the NID_md5, NID_sha1, NID_sha224, NID_sha256, NID_sha384 and -NID_sha512 digest NIDs are supported and the public key algorithm NIDs -\&\s-1EVP_PKEY_RSA, EVP_PKEY_RSA_PSS, EVP_PKEY_DSA\s0 and \s-1EVP_PKEY_EC.\s0 -.PP -The short or long name values for digests can be used in a string (for -example \*(L"\s-1MD5\*(R", \*(L"SHA1\*(R", \*(L"SHA224\*(R", \*(L"SHA256\*(R", \*(L"SHA384\*(R", \*(L"SHA512\*(R"\s0) and -the public key algorithm strings \*(L"\s-1RSA\*(R",\s0 \*(L"RSA-PSS\*(R", \*(L"\s-1DSA\*(R"\s0 or \*(L"\s-1ECDSA\*(R".\s0 -.PP -The \s-1TLS 1.3\s0 signature scheme names (such as \*(L"rsa_pss_pss_sha256\*(R") can also -be used with the \fB_list\fR forms of the \s-1API.\s0 -.PP -The use of \s-1MD5\s0 as a digest is strongly discouraged due to security weaknesses. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 for success and 0 for failure. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Set supported signature algorithms to \s-1SHA256\s0 with \s-1ECDSA\s0 and \s-1SHA256\s0 with \s-1RSA\s0 -using an array: -.PP -.Vb 1 -\& const int slist[] = {NID_sha256, EVP_PKEY_EC, NID_sha256, EVP_PKEY_RSA}; -\& -\& SSL_CTX_set1_sigalgs(ctx, slist, 4); -.Ve -.PP -Set supported signature algorithms to \s-1SHA256\s0 with \s-1ECDSA\s0 and \s-1SHA256\s0 with \s-1RSA\s0 -using a string: -.PP -.Vb 1 -\& SSL_CTX_set1_sigalgs_list(ctx, "ECDSA+SHA256:RSA+SHA256"); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_shared_sigalgs\fR\|(3), -\&\fBSSL_CONF_CTX_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -Support for ignoring unknown signature algorithms in -\&\fBSSL_CTX_set1_sigalgs_list()\fR, \fBSSL_set1_sigalgs_list()\fR, -\&\fBSSL_CTX_set1_client_sigalgs_list()\fR and \fBSSL_set1_client_sigalgs_list()\fR -was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_sigalgs_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_sigalgs_list.3ossl deleted file mode 120000 index f594d7af..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_sigalgs_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set1_verify_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_set1_verify_cert_store.3ossl deleted file mode 100644 index 6a7b5876..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set1_verify_cert_store.3ossl +++ /dev/null @@ -1,245 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET1_VERIFY_CERT_STORE 3ossl" -.TH SSL_CTX_SET1_VERIFY_CERT_STORE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set0_verify_cert_store, SSL_CTX_set1_verify_cert_store, -SSL_CTX_set0_chain_cert_store, SSL_CTX_set1_chain_cert_store, -SSL_set0_verify_cert_store, SSL_set1_verify_cert_store, -SSL_set0_chain_cert_store, SSL_set1_chain_cert_store, -SSL_CTX_get0_verify_cert_store, SSL_CTX_get0_chain_cert_store, -SSL_get0_verify_cert_store, SSL_get0_chain_cert_store \- set certificate -verification or chain store -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set0_verify_cert_store(SSL_CTX *ctx, X509_STORE *st); -\& int SSL_CTX_set1_verify_cert_store(SSL_CTX *ctx, X509_STORE *st); -\& int SSL_CTX_set0_chain_cert_store(SSL_CTX *ctx, X509_STORE *st); -\& int SSL_CTX_set1_chain_cert_store(SSL_CTX *ctx, X509_STORE *st); -\& int SSL_CTX_get0_verify_cert_store(SSL_CTX *ctx, X509_STORE **st); -\& int SSL_CTX_get0_chain_cert_store(SSL_CTX *ctx, X509_STORE **st); -\& -\& int SSL_set0_verify_cert_store(SSL *ctx, X509_STORE *st); -\& int SSL_set1_verify_cert_store(SSL *ctx, X509_STORE *st); -\& int SSL_set0_chain_cert_store(SSL *ctx, X509_STORE *st); -\& int SSL_set1_chain_cert_store(SSL *ctx, X509_STORE *st); -\& int SSL_get0_verify_cert_store(SSL *ctx, X509_STORE **st); -\& int SSL_get0_chain_cert_store(SSL *ctx, X509_STORE **st); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set0_verify_cert_store()\fR and \fBSSL_CTX_set1_verify_cert_store()\fR -set the certificate store used for certificate verification to \fBst\fR. -.PP -\&\fBSSL_CTX_set0_chain_cert_store()\fR and \fBSSL_CTX_set1_chain_cert_store()\fR -set the certificate store used for certificate chain building to \fBst\fR. -.PP -\&\fBSSL_set0_verify_cert_store()\fR, \fBSSL_set1_verify_cert_store()\fR, -\&\fBSSL_set0_chain_cert_store()\fR and \fBSSL_set1_chain_cert_store()\fR are similar -except they apply to \s-1SSL\s0 structure \fBssl\fR. -.PP -\&\fBSSL_CTX_get0_verify_chain_store()\fR, \fBSSL_get0_verify_chain_store()\fR, -\&\fBSSL_CTX_get0_chain_cert_store()\fR and \fBSSL_get0_chain_cert_store()\fR retrieve the -objects previously set via the above calls. A pointer to the object (or \s-1NULL\s0 if -no such object has been set) is written to \fB*st\fR. -.PP -All these functions are implemented as macros. Those containing a \fB1\fR -increment the reference count of the supplied store so it must -be freed at some point after the operation. Those containing a \fB0\fR do -not increment reference counts and the supplied store \fB\s-1MUST NOT\s0\fR be freed -after the operation. -.SH "NOTES" -.IX Header "NOTES" -The stores pointers associated with an \s-1SSL_CTX\s0 structure are copied to any \s-1SSL\s0 -structures when \fBSSL_new()\fR is called. As a result \s-1SSL\s0 structures will not be -affected if the parent \s-1SSL_CTX\s0 store pointer is set to a new value. -.PP -The verification store is used to verify the certificate chain sent by the -peer: that is an \s-1SSL/TLS\s0 client will use the verification store to verify -the server's certificate chain and a \s-1SSL/TLS\s0 server will use it to verify -any client certificate chain. -.PP -The chain store is used to build the certificate chain. -Details of the chain building and checking process are described in -\&\*(L"Certification Path Building\*(R" in \fBopenssl\-verification\-options\fR\|(1) and -\&\*(L"Certification Path Validation\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.PP -If the mode \fB\s-1SSL_MODE_NO_AUTO_CHAIN\s0\fR is set or a certificate chain is -configured already (for example using the functions such as -\&\fBSSL_CTX_add1_chain_cert\fR\|(3) or -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3)) then -automatic chain building is disabled. -.PP -If the mode \fB\s-1SSL_MODE_NO_AUTO_CHAIN\s0\fR is set then automatic chain building -is disabled. -.PP -If the chain or the verification store is not set then the store associated -with the parent \s-1SSL_CTX\s0 is used instead to retain compatibility with previous -versions of OpenSSL. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3) -\&\fBSSL_CTX_set0_chain\fR\|(3) -\&\fBSSL_CTX_set1_chain\fR\|(3) -\&\fBSSL_CTX_add0_chain_cert\fR\|(3) -\&\fBSSL_CTX_add1_chain_cert\fR\|(3) -\&\fBSSL_set0_chain\fR\|(3) -\&\fBSSL_set1_chain\fR\|(3) -\&\fBSSL_add0_chain_cert\fR\|(3) -\&\fBSSL_add1_chain_cert\fR\|(3) -\&\fBSSL_CTX_build_cert_chain\fR\|(3) -\&\fBSSL_build_cert_chain\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_allow_early_data_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_allow_early_data_cb.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_allow_early_data_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_alpn_protos.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_alpn_protos.3ossl deleted file mode 120000 index fa1385af..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_alpn_protos.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_alpn_select_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_alpn_select_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_alpn_select_cb.3ossl deleted file mode 100644 index bbe1931a..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_alpn_select_cb.3ossl +++ /dev/null @@ -1,332 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_ALPN_SELECT_CB 3ossl" -.TH SSL_CTX_SET_ALPN_SELECT_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_alpn_protos, SSL_set_alpn_protos, SSL_CTX_set_alpn_select_cb, -SSL_CTX_set_next_proto_select_cb, SSL_CTX_set_next_protos_advertised_cb, -SSL_select_next_proto, SSL_get0_alpn_selected, SSL_get0_next_proto_negotiated -\&\- handle application layer protocol negotiation (ALPN) -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_alpn_protos(SSL_CTX *ctx, const unsigned char *protos, -\& unsigned int protos_len); -\& int SSL_set_alpn_protos(SSL *ssl, const unsigned char *protos, -\& unsigned int protos_len); -\& void SSL_CTX_set_alpn_select_cb(SSL_CTX *ctx, -\& int (*cb) (SSL *ssl, -\& const unsigned char **out, -\& unsigned char *outlen, -\& const unsigned char *in, -\& unsigned int inlen, -\& void *arg), void *arg); -\& void SSL_get0_alpn_selected(const SSL *ssl, const unsigned char **data, -\& unsigned int *len); -\& -\& void SSL_CTX_set_next_protos_advertised_cb(SSL_CTX *ctx, -\& int (*cb)(SSL *ssl, -\& const unsigned char **out, -\& unsigned int *outlen, -\& void *arg), -\& void *arg); -\& void SSL_CTX_set_next_proto_select_cb(SSL_CTX *ctx, -\& int (*cb)(SSL *s, -\& unsigned char **out, -\& unsigned char *outlen, -\& const unsigned char *in, -\& unsigned int inlen, -\& void *arg), -\& void *arg); -\& int SSL_select_next_proto(unsigned char **out, unsigned char *outlen, -\& const unsigned char *server, -\& unsigned int server_len, -\& const unsigned char *client, -\& unsigned int client_len); -\& void SSL_get0_next_proto_negotiated(const SSL *s, const unsigned char **data, -\& unsigned *len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_alpn_protos()\fR and \fBSSL_set_alpn_protos()\fR are used by the client to -set the list of protocols available to be negotiated. The \fBprotos\fR must be in -protocol-list format, described below. The length of \fBprotos\fR is specified in -\&\fBprotos_len\fR. Setting \fBprotos_len\fR to 0 clears any existing list of \s-1ALPN\s0 -protocols and no \s-1ALPN\s0 extension will be sent to the server. -.PP -\&\fBSSL_CTX_set_alpn_select_cb()\fR sets the application callback \fBcb\fR used by a -server to select which protocol to use for the incoming connection. When \fBcb\fR -is \s-1NULL, ALPN\s0 is not used. The \fBarg\fR value is a pointer which is passed to -the application callback. -.PP -\&\fBcb\fR is the application defined callback. The \fBin\fR, \fBinlen\fR parameters are a -vector in protocol-list format. The value of the \fBout\fR, \fBoutlen\fR vector -should be set to the value of a single protocol selected from the \fBin\fR, -\&\fBinlen\fR vector. The \fBout\fR buffer may point directly into \fBin\fR, or to a -buffer that outlives the handshake. The \fBarg\fR parameter is the pointer set via -\&\fBSSL_CTX_set_alpn_select_cb()\fR. -.PP -\&\fBSSL_select_next_proto()\fR is a helper function used to select protocols. It -implements the standard protocol selection. It is expected that this function -is called from the application callback \fBcb\fR. The protocol data in \fBserver\fR, -\&\fBserver_len\fR and \fBclient\fR, \fBclient_len\fR must be in the protocol-list format -described below. The first item in the \fBserver\fR, \fBserver_len\fR list that -matches an item in the \fBclient\fR, \fBclient_len\fR list is selected, and returned -in \fBout\fR, \fBoutlen\fR. The \fBout\fR value will point into either \fBserver\fR or -\&\fBclient\fR, so it should be copied immediately. The client list must include at -least one valid (nonempty) protocol entry in the list. -.PP -The \fBSSL_select_next_proto()\fR helper function can be useful from either the \s-1ALPN\s0 -callback or the \s-1NPN\s0 callback (described below). If no match is found, the first -item in \fBclient\fR, \fBclient_len\fR is returned in \fBout\fR, \fBoutlen\fR and -\&\fB\s-1OPENSSL_NPN_NO_OVERLAP\s0\fR is returned. This can be useful when implementing -the \s-1NPN\s0 callback. In the \s-1ALPN\s0 case, the value returned in \fBout\fR and \fBoutlen\fR -must be ignored if \fB\s-1OPENSSL_NPN_NO_OVERLAP\s0\fR has been returned from -\&\fBSSL_select_next_proto()\fR. -.PP -\&\fBSSL_CTX_set_next_proto_select_cb()\fR sets a callback \fBcb\fR that is called when a -client needs to select a protocol from the server's provided list, and a -user-defined pointer argument \fBarg\fR which will be passed to this callback. -For the callback itself, \fBout\fR -must be set to point to the selected protocol (which may be within \fBin\fR). -The length of the protocol name must be written into \fBoutlen\fR. The -server's advertised protocols are provided in \fBin\fR and \fBinlen\fR. The -callback can assume that \fBin\fR is syntactically valid. The client must -select a protocol (although it may be an empty, zero length protocol). It is -fatal to the connection if this callback returns a value other than -\&\fB\s-1SSL_TLSEXT_ERR_OK\s0\fR or if the zero length protocol is selected. The \fBarg\fR -parameter is the pointer set via \fBSSL_CTX_set_next_proto_select_cb()\fR. -.PP -\&\fBSSL_CTX_set_next_protos_advertised_cb()\fR sets a callback \fBcb\fR that is called -when a \s-1TLS\s0 server needs a list of supported protocols for Next Protocol -Negotiation. The returned list must be in protocol-list format, described -below. The list is -returned by setting \fBout\fR to point to it and \fBoutlen\fR to its length. This -memory will not be modified, but the \fB\s-1SSL\s0\fR does keep a -reference to it. The callback should return \fB\s-1SSL_TLSEXT_ERR_OK\s0\fR if it -wishes to advertise. Otherwise, no such extension will be included in the -ServerHello. -.PP -\&\fBSSL_get0_alpn_selected()\fR returns a pointer to the selected protocol in \fBdata\fR -with length \fBlen\fR. It is not NUL-terminated. \fBdata\fR is set to \s-1NULL\s0 and \fBlen\fR -is set to 0 if no protocol has been selected. \fBdata\fR must not be freed. -.PP -\&\fBSSL_get0_next_proto_negotiated()\fR sets \fBdata\fR and \fBlen\fR to point to the -client's requested protocol for this connection. If the client did not -request any protocol or \s-1NPN\s0 is not enabled, then \fBdata\fR is set to \s-1NULL\s0 and -\&\fBlen\fR to 0. Note that -the client can request any protocol it chooses. The value returned from -this function need not be a member of the list of supported protocols -provided by the callback. -.PP -\&\s-1NPN\s0 functionality cannot be used with \s-1QUIC SSL\s0 objects. Use of \s-1ALPN\s0 is mandatory -when using \s-1QUIC SSL\s0 objects. \fBSSL_CTX_set_next_protos_advertised_cb()\fR and -\&\fBSSL_CTX_set_next_proto_select_cb()\fR have no effect if called on a \s-1QUIC SSL\s0 -context. -.SH "NOTES" -.IX Header "NOTES" -The protocol-lists must be in wire-format, which is defined as a vector of -nonempty, 8\-bit length-prefixed, byte strings. The length-prefix byte is not -included in the length. Each string is limited to 255 bytes. A byte-string -length of 0 is invalid. A truncated byte-string is invalid. The length of the -vector is not in the vector itself, but in a separate variable. -.PP -Example: -.PP -.Vb 5 -\& unsigned char vector[] = { -\& 6, \*(Aqs\*(Aq, \*(Aqp\*(Aq, \*(Aqd\*(Aq, \*(Aqy\*(Aq, \*(Aq/\*(Aq, \*(Aq1\*(Aq, -\& 8, \*(Aqh\*(Aq, \*(Aqt\*(Aq, \*(Aqt\*(Aq, \*(Aqp\*(Aq, \*(Aq/\*(Aq, \*(Aq1\*(Aq, \*(Aq.\*(Aq, \*(Aq1\*(Aq -\& }; -\& unsigned int length = sizeof(vector); -.Ve -.PP -The \s-1ALPN\s0 callback is executed after the servername callback; as that servername -callback may update the \s-1SSL_CTX,\s0 and subsequently, the \s-1ALPN\s0 callback. -.PP -If there is no \s-1ALPN\s0 proposed in the ClientHello, the \s-1ALPN\s0 callback is not -invoked. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_alpn_protos()\fR and \fBSSL_set_alpn_protos()\fR return 0 on success, and -non\-0 on failure. \s-1WARNING:\s0 these functions reverse the return value convention. -.PP -\&\fBSSL_select_next_proto()\fR returns one of the following: -.IP "\s-1OPENSSL_NPN_NEGOTIATED\s0" 4 -.IX Item "OPENSSL_NPN_NEGOTIATED" -A match was found and is returned in \fBout\fR, \fBoutlen\fR. -.IP "\s-1OPENSSL_NPN_NO_OVERLAP\s0" 4 -.IX Item "OPENSSL_NPN_NO_OVERLAP" -No match was found. The first item in \fBclient\fR, \fBclient_len\fR is returned in -\&\fBout\fR, \fBoutlen\fR (or \fB\s-1NULL\s0\fR and 0 in the case where the first entry in -\&\fBclient\fR is invalid). -.PP -The \s-1ALPN\s0 select callback \fBcb\fR, must return one of the following: -.IP "\s-1SSL_TLSEXT_ERR_OK\s0" 4 -.IX Item "SSL_TLSEXT_ERR_OK" -\&\s-1ALPN\s0 protocol selected. -.IP "\s-1SSL_TLSEXT_ERR_ALERT_FATAL\s0" 4 -.IX Item "SSL_TLSEXT_ERR_ALERT_FATAL" -There was no overlap between the client's supplied list and the server -configuration. -.IP "\s-1SSL_TLSEXT_ERR_NOACK\s0" 4 -.IX Item "SSL_TLSEXT_ERR_NOACK" -\&\s-1ALPN\s0 protocol not selected, e.g., because no \s-1ALPN\s0 protocols are configured for -this connection. -.PP -The callback set using \fBSSL_CTX_set_next_proto_select_cb()\fR should return -\&\fB\s-1SSL_TLSEXT_ERR_OK\s0\fR if successful. Any other value is fatal to the connection. -.PP -The callback set using \fBSSL_CTX_set_next_protos_advertised_cb()\fR should return -\&\fB\s-1SSL_TLSEXT_ERR_OK\s0\fR if it wishes to advertise. Otherwise, no such extension -will be included in the ServerHello. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_tlsext_servername_callback\fR\|(3), -\&\fBSSL_CTX_set_tlsext_servername_arg\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_app_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_async_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_async_callback.3ossl deleted file mode 120000 index ea95f1d7..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_async_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_async_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_async_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_async_callback_arg.3ossl deleted file mode 120000 index ea95f1d7..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_async_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_async_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_block_padding.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_block_padding.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_block_padding.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_block_padding_ex.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_block_padding_ex.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_block_padding_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_cert_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_cert_cb.3ossl deleted file mode 100644 index 3ab3e090..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_cert_cb.3ossl +++ /dev/null @@ -1,211 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CERT_CB 3ossl" -.TH SSL_CTX_SET_CERT_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_cert_cb, SSL_set_cert_cb \- handle certificate callback function -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_cert_cb(SSL_CTX *c, int (*cert_cb)(SSL *ssl, void *arg), -\& void *arg); -\& void SSL_set_cert_cb(SSL *s, int (*cert_cb)(SSL *ssl, void *arg), void *arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_cert_cb()\fR and \fBSSL_set_cert_cb()\fR sets the \fIcert_cb\fR callback, -\&\fIarg\fR value is pointer which is passed to the application callback. -.PP -When \fIcert_cb\fR is \s-1NULL,\s0 no callback function is used. -.PP -\&\fIcert_cb\fR is the application defined callback. It is called before a -certificate will be used by a client or server. The callback can then inspect -the passed \fIssl\fR structure and set or clear any appropriate certificates. If -the callback is successful it \fB\s-1MUST\s0\fR return 1 even if no certificates have -been set. A zero is returned on error which will abort the handshake with a -fatal internal error alert. A negative return value will suspend the handshake -and the handshake function will return immediately. -\&\fBSSL_get_error\fR\|(3) will return \s-1SSL_ERROR_WANT_X509_LOOKUP\s0 to -indicate, that the handshake was suspended. The next call to the handshake -function will again lead to the call of \fIcert_cb\fR. It is the job of the -\&\fIcert_cb\fR to store information about the state of the last call, -if required to continue. -.SH "NOTES" -.IX Header "NOTES" -An application will typically call \fBSSL_use_certificate()\fR and -\&\fBSSL_use_PrivateKey()\fR to set the end entity certificate and private key. -It can add intermediate and optionally the root \s-1CA\s0 certificates using -\&\fBSSL_add1_chain_cert()\fR. -.PP -It might also call \fBSSL_certs_clear()\fR to delete any certificates associated -with the \fB\s-1SSL\s0\fR object. -.PP -The certificate callback functionality supersedes the (largely broken) -functionality provided by the old client certificate callback interface. -It is \fBalways\fR called even is a certificate is already set so the callback -can modify or delete the existing certificate. -.PP -A more advanced callback might examine the handshake parameters and set -whatever chain is appropriate. For example a legacy client supporting only -TLSv1.0 might receive a certificate chain signed using \s-1SHA1\s0 whereas a -TLSv1.2 or later client which advertises support for \s-1SHA256\s0 could receive a -chain using \s-1SHA256.\s0 -.PP -Normal server sanity checks are performed on any certificates set -by the callback. So if an \s-1EC\s0 chain is set for a curve the client does not -support it will \fBnot\fR be used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_cert_cb()\fR and \fBSSL_set_cert_cb()\fR do not return values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_use_certificate\fR\|(3), -\&\fBSSL_add1_chain_cert\fR\|(3), -\&\fBSSL_get_client_CA_list\fR\|(3), -\&\fBSSL_clear\fR\|(3), \fBSSL_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2014\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_cert_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_cert_store.3ossl deleted file mode 100644 index ef7d942b..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_cert_store.3ossl +++ /dev/null @@ -1,221 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CERT_STORE 3ossl" -.TH SSL_CTX_SET_CERT_STORE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_cert_store, SSL_CTX_set1_cert_store, SSL_CTX_get_cert_store \- manipulate X509 certificate verification storage -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_cert_store(SSL_CTX *ctx, X509_STORE *store); -\& void SSL_CTX_set1_cert_store(SSL_CTX *ctx, X509_STORE *store); -\& X509_STORE *SSL_CTX_get_cert_store(const SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_cert_store()\fR sets/replaces the certificate verification storage -of \fBctx\fR to/with \fBstore\fR. If another X509_STORE object is currently -set in \fBctx\fR, it will be \fBX509_STORE_free()\fRed. \fBSSL_CTX_set_cert_store()\fR will -take ownership of the \fBstore\fR, i.e., the call \f(CW\*(C`X509_STORE_free(store)\*(C'\fR is no -longer needed. -.PP -\&\fBSSL_CTX_set1_cert_store()\fR sets/replaces the certificate verification storage -of \fBctx\fR to/with \fBstore\fR. The \fBstore\fR's reference count is incremented. -If another X509_STORE object is currently set in \fBctx\fR, it will be \fBX509_STORE_free()\fRed. -.PP -\&\fBSSL_CTX_get_cert_store()\fR returns a pointer to the current certificate -verification storage. -.SH "NOTES" -.IX Header "NOTES" -In order to verify the certificates presented by the peer, trusted \s-1CA\s0 -certificates must be accessed. These \s-1CA\s0 certificates are made available -via lookup methods, handled inside the X509_STORE. From the X509_STORE -the X509_STORE_CTX used when verifying certificates is created. -.PP -Typically the trusted certificate store is handled indirectly via using -\&\fBSSL_CTX_load_verify_locations\fR\|(3). -Using the \fBSSL_CTX_set_cert_store()\fR and \fBSSL_CTX_get_cert_store()\fR functions -it is possible to manipulate the X509_STORE object beyond the -\&\fBSSL_CTX_load_verify_locations\fR\|(3) -call. -.PP -Currently no detailed documentation on how to use the X509_STORE -object is available. Not all members of the X509_STORE are used when -the verification takes place. So will e.g. the \fBverify_callback()\fR be -overridden with the \fBverify_callback()\fR set via the -\&\fBSSL_CTX_set_verify\fR\|(3) family of functions. -This document must therefore be updated when documentation about the -X509_STORE object and its handling becomes available. -.PP -\&\fBSSL_CTX_set_cert_store()\fR does not increment the \fBstore\fR's reference -count, so it should not be used to assign an X509_STORE that is owned -by another \s-1SSL_CTX.\s0 -.PP -To share X509_STOREs between two SSL_CTXs, use \fBSSL_CTX_get_cert_store()\fR -to get the X509_STORE from the first \s-1SSL_CTX,\s0 and then use -\&\fBSSL_CTX_set1_cert_store()\fR to assign to the second \s-1SSL_CTX\s0 and -increment the reference count of the X509_STORE. -.SH "RESTRICTIONS" -.IX Header "RESTRICTIONS" -The X509_STORE structure used by an \s-1SSL_CTX\s0 is used for verifying peer -certificates and building certificate chains, it is also shared by -every child \s-1SSL\s0 structure. Applications wanting finer control can use -functions such as \fBSSL_CTX_set1_verify_cert_store()\fR instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_cert_store()\fR does not return diagnostic output. -.PP -\&\fBSSL_CTX_set1_cert_store()\fR does not return diagnostic output. -.PP -\&\fBSSL_CTX_get_cert_store()\fR returns the current setting. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_load_verify_locations\fR\|(3), -\&\fBSSL_CTX_set_verify\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_cert_verify_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_cert_verify_callback.3ossl deleted file mode 100644 index a3e1a714..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_cert_verify_callback.3ossl +++ /dev/null @@ -1,235 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CERT_VERIFY_CALLBACK 3ossl" -.TH SSL_CTX_SET_CERT_VERIFY_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_cert_verify_callback \- set peer certificate verification procedure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_cert_verify_callback(SSL_CTX *ctx, -\& int (*callback)(X509_STORE_CTX *, void *), -\& void *arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_cert_verify_callback()\fR sets the verification callback function for -\&\fIctx\fR. \s-1SSL\s0 objects that are created from \fIctx\fR inherit the setting valid at -the time when \fBSSL_new\fR\|(3) is called. -.SH "NOTES" -.IX Header "NOTES" -When a peer certificate has been received during a \s-1SSL/TLS\s0 handshake, -a verification function is called regardless of the verification mode. -If the application does not explicitly specify a verification callback function, -the built-in verification function is used. -If a verification callback \fIcallback\fR is specified via -\&\fBSSL_CTX_set_cert_verify_callback()\fR, the supplied callback function is called -instead with the arguments callback(X509_STORE_CTX *x509_store_ctx, void *arg). -The argument \fIarg\fR is specified by the application when setting \fIcallback\fR. -By setting \fIcallback\fR to \s-1NULL,\s0 the default behaviour is restored. -.PP -\&\fIcallback\fR should return 1 to indicate verification success -and 0 to indicate verification failure. -In server mode, a return value of 0 leads to handshake failure. -In client mode, the behaviour is as follows. -All values, including 0, are ignored -if the verification mode is \fB\s-1SSL_VERIFY_NONE\s0\fR. -Otherwise, when the return value is less than or equal to 0, the handshake will -fail. -.PP -In client mode \fIcallback\fR may also call the \fBSSL_set_retry_verify\fR\|(3) -function on the \fB\s-1SSL\s0\fR object set in the \fIx509_store_ctx\fR ex data (see -\&\fBSSL_get_ex_data_X509_STORE_CTX_idx\fR\|(3)) and return 1. This would be -typically done in case the certificate verification was not yet able -to succeed. This makes the handshake suspend and return control to the -calling application with \fB\s-1SSL_ERROR_WANT_RETRY_VERIFY\s0\fR. The app can for -instance fetch further certificates or cert status information needed for -the verification. Calling \fBSSL_connect\fR\|(3) again resumes the connection -attempt by retrying the server certificate verification step. -This process may even be repeated if need be. -.PP -In any case a viable verification result value must be reflected -in the \fBerror\fR member of \fIx509_store_ctx\fR, -which can be done using \fBX509_STORE_CTX_set_error\fR\|(3). -This is particularly important in case -the \fIcallback\fR allows the connection to continue (by returning 1). -Note that the verification status in the store context is a possibly durable -indication of the chain's validity! -This gets recorded in the \s-1SSL\s0 session (and thus also in session tickets) -and the validity of the originally presented chain is then visible -on resumption, even though no chain is presented int that case. -Moreover, the calling application will be informed about the detailed result of -the verification procedure and may elect to base further decisions on it. -.PP -Within \fIx509_store_ctx\fR, \fIcallback\fR has access to the \fIverify_callback\fR -function set using \fBSSL_CTX_set_verify\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_cert_verify_callback()\fR does not return a value. -.SH "WARNINGS" -.IX Header "WARNINGS" -Do not mix the verification callback described in this function with the -\&\fBverify_callback\fR function called during the verification process. The -latter is set using the \fBSSL_CTX_set_verify\fR\|(3) -family of functions. -.PP -Providing a complete verification procedure including certificate purpose -settings etc is a complex task. The built-in procedure is quite powerful -and in most cases it should be sufficient to modify its behaviour using -the \fBverify_callback\fR function. -.SH "BUGS" -.IX Header "BUGS" -\&\fBSSL_CTX_set_cert_verify_callback()\fR does not provide diagnostic information. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_verify\fR\|(3), -\&\fBX509_STORE_CTX_set_error\fR\|(3), -\&\fBSSL_get_verify_result\fR\|(3), -\&\fBSSL_set_retry_verify\fR\|(3), -\&\fBSSL_CTX_load_verify_locations\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_cipher_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_cipher_list.3ossl deleted file mode 100644 index 1a3f0706..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_cipher_list.3ossl +++ /dev/null @@ -1,261 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CIPHER_LIST 3ossl" -.TH SSL_CTX_SET_CIPHER_LIST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_cipher_list, -SSL_set_cipher_list, -SSL_CTX_set_ciphersuites, -SSL_set_ciphersuites, -OSSL_default_cipher_list, -OSSL_default_ciphersuites -\&\- choose list of available SSL_CIPHERs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_cipher_list(SSL_CTX *ctx, const char *str); -\& int SSL_set_cipher_list(SSL *ssl, const char *str); -\& -\& int SSL_CTX_set_ciphersuites(SSL_CTX *ctx, const char *str); -\& int SSL_set_ciphersuites(SSL *s, const char *str); -\& -\& const char *OSSL_default_cipher_list(void); -\& const char *OSSL_default_ciphersuites(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_cipher_list()\fR sets the list of available ciphers (TLSv1.2 and below) -for \fBctx\fR using the control string \fBstr\fR. The format of the string is described -in \fBopenssl\-ciphers\fR\|(1). The list of ciphers is inherited by all -\&\fBssl\fR objects created from \fBctx\fR. This function does not impact TLSv1.3 -ciphersuites. Use \fBSSL_CTX_set_ciphersuites()\fR to configure those. -.PP -\&\fBSSL_set_cipher_list()\fR sets the list of ciphers (TLSv1.2 and below) only for -\&\fBssl\fR. -.PP -\&\fBSSL_CTX_set_ciphersuites()\fR is used to configure the available TLSv1.3 -ciphersuites for \fBctx\fR. This is a simple colon (\*(L":\*(R") separated list of TLSv1.3 -ciphersuite names in order of preference. Valid TLSv1.3 ciphersuite names are: -.IP "\s-1TLS_AES_128_GCM_SHA256\s0" 4 -.IX Item "TLS_AES_128_GCM_SHA256" -.PD 0 -.IP "\s-1TLS_AES_256_GCM_SHA384\s0" 4 -.IX Item "TLS_AES_256_GCM_SHA384" -.IP "\s-1TLS_CHACHA20_POLY1305_SHA256\s0" 4 -.IX Item "TLS_CHACHA20_POLY1305_SHA256" -.IP "\s-1TLS_AES_128_CCM_SHA256\s0" 4 -.IX Item "TLS_AES_128_CCM_SHA256" -.IP "\s-1TLS_AES_128_CCM_8_SHA256\s0" 4 -.IX Item "TLS_AES_128_CCM_8_SHA256" -.IP "\s-1TLS_SHA384_SHA384\s0 \- integrity-only" 4 -.IX Item "TLS_SHA384_SHA384 - integrity-only" -.IP "\s-1TLS_SHA256_SHA256\s0 \- integrity-only" 4 -.IX Item "TLS_SHA256_SHA256 - integrity-only" -.PD -.PP -An empty list is permissible. The default value for this setting is: -.PP -\&\*(L"\s-1TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:TLS_AES_128_GCM_SHA256\*(R"\s0 -.PP -\&\fBSSL_set_ciphersuites()\fR is the same as \fBSSL_CTX_set_ciphersuites()\fR except it -configures the ciphersuites for \fBssl\fR. -.PP -\&\fBOSSL_default_cipher_list()\fR returns the default cipher string for TLSv1.2 -(and earlier) ciphers. \fBOSSL_default_ciphersuites()\fR returns the default -cipher string for TLSv1.3 ciphersuites. -.SH "NOTES" -.IX Header "NOTES" -The control string \fBstr\fR for \fBSSL_CTX_set_cipher_list()\fR, \fBSSL_set_cipher_list()\fR, -\&\fBSSL_CTX_set_ciphersuites()\fR and \fBSSL_set_ciphersuites()\fR should be universally -usable and not depend on details of the library configuration (ciphers compiled -in). Thus no syntax checking takes place. Items that are not recognized, because -the corresponding ciphers are not compiled in or because they are mistyped, -are simply ignored. Failure is only flagged if no ciphers could be collected -at all. -.PP -It should be noted, that inclusion of a cipher to be used into the list is -a necessary condition. On the client side, the inclusion into the list is -also sufficient unless the security level excludes it. On the server side, -additional restrictions apply. All ciphers have additional requirements. -\&\s-1ADH\s0 ciphers don't need a certificate, but DH-parameters must have been set. -All other ciphers need a corresponding certificate and key. -.PP -An \s-1RSA\s0 cipher can only be chosen, when an \s-1RSA\s0 certificate is available. -\&\s-1RSA\s0 ciphers using \s-1DHE\s0 need a certificate and key and additional DH-parameters -(see \fBSSL_CTX_set_tmp_dh_callback\fR\|(3)). -.PP -A \s-1DSA\s0 cipher can only be chosen, when a \s-1DSA\s0 certificate is available. -\&\s-1DSA\s0 ciphers always use \s-1DH\s0 key exchange and therefore need DH-parameters -(see \fBSSL_CTX_set_tmp_dh_callback\fR\|(3)). -.PP -When these conditions are not met for any cipher in the list (e.g. a -client only supports export \s-1RSA\s0 ciphers with an asymmetric key length -of 512 bits and the server is not configured to use temporary \s-1RSA\s0 -keys), the \*(L"no shared cipher\*(R" (\s-1SSL_R_NO_SHARED_CIPHER\s0) error is generated -and the handshake will fail. -.PP -\&\fBOSSL_default_cipher_list()\fR and \fBOSSL_default_ciphersuites()\fR replace -\&\s-1SSL_DEFAULT_CIPHER_LIST\s0 and \s-1TLS_DEFAULT_CIPHERSUITES,\s0 respectively. The -cipher list defines are deprecated as of 3.0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_cipher_list()\fR and \fBSSL_set_cipher_list()\fR return 1 if any cipher -could be selected and 0 on complete failure. -.PP -\&\fBSSL_CTX_set_ciphersuites()\fR and \fBSSL_set_ciphersuites()\fR return 1 if the requested -ciphersuite list was configured, and 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_ciphers\fR\|(3), -\&\fBSSL_CTX_use_certificate\fR\|(3), -\&\fBSSL_CTX_set_tmp_dh_callback\fR\|(3), -\&\fBopenssl\-ciphers\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBOSSL_default_cipher_list()\fR and \fBOSSL_default_ciphersites()\fR are new in 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_ciphersuites.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_ciphersuites.3ossl deleted file mode 120000 index e8b09412..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_ciphersuites.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cipher_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_client_CA_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_client_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_client_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_client_cert_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_client_cert_cb.3ossl deleted file mode 100644 index 416d7472..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_client_cert_cb.3ossl +++ /dev/null @@ -1,240 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CLIENT_CERT_CB 3ossl" -.TH SSL_CTX_SET_CLIENT_CERT_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_client_cert_cb, SSL_CTX_get_client_cert_cb \- handle client certificate callback function -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_client_cert_cb(SSL_CTX *ctx, -\& int (*client_cert_cb)(SSL *ssl, X509 **x509, -\& EVP_PKEY **pkey)); -\& int (*SSL_CTX_get_client_cert_cb(SSL_CTX *ctx))(SSL *ssl, X509 **x509, -\& EVP_PKEY **pkey); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_client_cert_cb()\fR sets the \fIclient_cert_cb\fR callback, that is -called when a client certificate is requested by a server and no certificate -was yet set for the \s-1SSL\s0 object. -.PP -When \fIclient_cert_cb\fR is \s-1NULL,\s0 no callback function is used. -.PP -\&\fBSSL_CTX_get_client_cert_cb()\fR returns a pointer to the currently set callback -function. -.PP -\&\fIclient_cert_cb\fR is the application defined callback. If it wants to -set a certificate, a certificate/private key combination must be set -using the \fIx509\fR and \fIpkey\fR arguments and \*(L"1\*(R" must be returned. The -certificate will be installed into \fIssl\fR, see the \s-1NOTES\s0 and \s-1BUGS\s0 sections. -If no certificate should be set, \*(L"0\*(R" has to be returned and no certificate -will be sent. A negative return value will suspend the handshake and the -handshake function will return immediately. \fBSSL_get_error\fR\|(3) -will return \s-1SSL_ERROR_WANT_X509_LOOKUP\s0 to indicate, that the handshake was -suspended. The next call to the handshake function will again lead to the call -of \fIclient_cert_cb\fR. It is the job of the \fIclient_cert_cb\fR to store information -about the state of the last call, if required to continue. -.SH "NOTES" -.IX Header "NOTES" -During a handshake (or renegotiation) a server may request a certificate -from the client. A client certificate must only be sent, when the server -did send the request. -.PP -When a certificate was set using the -\&\fBSSL_CTX_use_certificate\fR\|(3) family of functions, -it will be sent to the server. The \s-1TLS\s0 standard requires that only a -certificate is sent, if it matches the list of acceptable CAs sent by the -server. This constraint is violated by the default behavior of the OpenSSL -library. Using the callback function it is possible to implement a proper -selection routine or to allow a user interaction to choose the certificate to -be sent. -.PP -If a callback function is defined and no certificate was yet defined for the -\&\s-1SSL\s0 object, the callback function will be called. -If the callback function returns a certificate, the OpenSSL library -will try to load the private key and certificate data into the \s-1SSL\s0 -object using the \fBSSL_use_certificate()\fR and \fBSSL_use_private_key()\fR functions. -Thus it will permanently install the certificate and key for this \s-1SSL\s0 -object. It will not be reset by calling \fBSSL_clear\fR\|(3). -If the callback returns no certificate, the OpenSSL library will not send -a certificate. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_get_client_cert_cb()\fR returns function pointer of \fIclient_cert_cb\fR or -\&\s-1NULL\s0 if the callback is not set. -.SH "BUGS" -.IX Header "BUGS" -The \fIclient_cert_cb\fR cannot return a complete certificate chain, it can -only return one client certificate. If the chain only has a length of 2, -the root \s-1CA\s0 certificate may be omitted according to the \s-1TLS\s0 standard and -thus a standard conforming answer can be sent to the server. For a -longer chain, the client must send the complete chain (with the option -to leave out the root \s-1CA\s0 certificate). This can only be accomplished by -either adding the intermediate \s-1CA\s0 certificates into the trusted -certificate store for the \s-1SSL_CTX\s0 object (resulting in having to add -\&\s-1CA\s0 certificates that otherwise maybe would not be trusted), or by adding -the chain certificates using the -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3) -function, which is only available for the \s-1SSL_CTX\s0 object as a whole and that -therefore probably can only apply for one client certificate, making -the concept of the callback function (to allow the choice from several -certificates) questionable. -.PP -Once the \s-1SSL\s0 object has been used in conjunction with the callback function, -the certificate will be set for the \s-1SSL\s0 object and will not be cleared -even when \fBSSL_clear\fR\|(3) is being called. It is therefore -mandatory to destroy the \s-1SSL\s0 object using \fBSSL_free\fR\|(3) -and create a new one to return to the previous state. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_use_certificate\fR\|(3), -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3), -\&\fBSSL_get_client_CA_list\fR\|(3), -\&\fBSSL_clear\fR\|(3), \fBSSL_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_client_hello_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_client_hello_cb.3ossl deleted file mode 100644 index c159d798..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_client_hello_cb.3ossl +++ /dev/null @@ -1,281 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CLIENT_HELLO_CB 3ossl" -.TH SSL_CTX_SET_CLIENT_HELLO_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_client_hello_cb, SSL_client_hello_cb_fn, SSL_client_hello_isv2, SSL_client_hello_get0_legacy_version, SSL_client_hello_get0_random, SSL_client_hello_get0_session_id, SSL_client_hello_get0_ciphers, SSL_client_hello_get0_compression_methods, SSL_client_hello_get1_extensions_present, SSL_client_hello_get_extension_order, SSL_client_hello_get0_ext \- callback functions for early server\-side ClientHello processing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 10 -\& typedef int (*SSL_client_hello_cb_fn)(SSL *s, int *al, void *arg); -\& void SSL_CTX_set_client_hello_cb(SSL_CTX *c, SSL_client_hello_cb_fn *f, -\& void *arg); -\& int SSL_client_hello_isv2(SSL *s); -\& unsigned int SSL_client_hello_get0_legacy_version(SSL *s); -\& size_t SSL_client_hello_get0_random(SSL *s, const unsigned char **out); -\& size_t SSL_client_hello_get0_session_id(SSL *s, const unsigned char **out); -\& size_t SSL_client_hello_get0_ciphers(SSL *s, const unsigned char **out); -\& size_t SSL_client_hello_get0_compression_methods(SSL *s, -\& const unsigned char **out); -\& int SSL_client_hello_get1_extensions_present(SSL *s, int **out, -\& size_t *outlen); -\& int SSL_client_hello_get_extension_order(SSL *s, uint16_t *exts, -\& size_t *num_exts); -\& int SSL_client_hello_get0_ext(SSL *s, unsigned int type, const unsigned char **out, -\& size_t *outlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_client_hello_cb()\fR sets the callback function, which is automatically -called during the early stages of ClientHello processing on the server. -The argument supplied when setting the callback is passed back to the -callback at run time. A callback that returns failure (0) will cause the -connection to terminate, and callbacks returning failure should indicate -what alert value is to be sent in the \fBal\fR parameter. A callback may -also return a negative value to suspend the handshake, and the handshake -function will return immediately. \fBSSL_get_error\fR\|(3) will return -\&\s-1SSL_ERROR_WANT_CLIENT_HELLO_CB\s0 to indicate that the handshake was suspended. -It is the job of the ClientHello callback to store information about the state -of the last call if needed to continue. On the next call into the handshake -function, the ClientHello callback will be called again, and, if it returns -success, normal handshake processing will continue from that point. -.PP -\&\fBSSL_client_hello_isv2()\fR indicates whether the ClientHello was carried in a -SSLv2 record and is in the SSLv2 format. The SSLv2 format has substantial -differences from the normal SSLv3 format, including using three bytes per -cipher suite, and not allowing extensions. Additionally, the SSLv2 format -\&'challenge' field is exposed via \fBSSL_client_hello_get0_random()\fR, padded to -\&\s-1SSL3_RANDOM_SIZE\s0 bytes with zeros if needed. For SSLv2 format ClientHellos, -\&\fBSSL_client_hello_get0_compression_methods()\fR returns a dummy list that only includes -the null compression method, since the SSLv2 format does not include a -mechanism by which to negotiate compression. -.PP -\&\fBSSL_client_hello_get0_random()\fR, \fBSSL_client_hello_get0_session_id()\fR, -\&\fBSSL_client_hello_get0_ciphers()\fR, and -\&\fBSSL_client_hello_get0_compression_methods()\fR provide access to the corresponding -ClientHello fields, returning the field length and optionally setting an out -pointer to the octets of that field. -.PP -Similarly, \fBSSL_client_hello_get0_ext()\fR provides access to individual extensions -from the ClientHello on a per-extension basis. For the provided wire -protocol extension type value, the extension value and length are returned -in the output parameters (if present). -.PP -\&\fBSSL_client_hello_get1_extensions_present()\fR can be used prior to -\&\fBSSL_client_hello_get0_ext()\fR, to determine which extensions are present in the -ClientHello before querying for them. The \fBout\fR and \fBoutlen\fR parameters are -both required, and on success the caller must release the storage allocated for -\&\fB*out\fR using \fBOPENSSL_free()\fR. The contents of \fB*out\fR is an array of integers -holding the numerical value of the \s-1TLS\s0 extension types in the order they appear -in the ClientHello. \fB*outlen\fR contains the number of elements in the array. -In situations when the ClientHello has no extensions, the function will return -success with \fB*out\fR set to \s-1NULL\s0 and \fB*outlen\fR set to 0. -.PP -\&\fBSSL_client_hello_get_extension_order()\fR is similar to -\&\fBSSL_client_hello_get1_extensions_present()\fR, without internal memory allocation. -When called with \fBexts\fR set to \s-1NULL,\s0 returns the number of extensions -(e.g., to allocate storage for a subsequent call). Otherwise, \fB*exts\fR is populated -with the ExtensionType values in the order that the corresponding extensions -appeared in the ClientHello. \fB*num_exts\fR is an input/output parameter, used -as input to supply the size of storage allocated by the caller, and as output to -indicate how many ExtensionType values were written. If the input \fB*num_exts\fR -is smaller then the number of extensions in question, that is treated as an error. -A subsequent call with \fBexts\fR set to \s-1NULL\s0 can retrieve the size of storage needed. -A ClientHello that contained no extensions is treated as success, with \fB*num_exts\fR -set to 0. -.SH "NOTES" -.IX Header "NOTES" -The ClientHello callback provides a vast window of possibilities for application -code to affect the \s-1TLS\s0 handshake. A primary use of the callback is to -allow the server to examine the server name indication extension provided -by the client in order to select an appropriate certificate to present, -and make other configuration adjustments relevant to that server name -and its configuration. Such configuration changes can include swapping out -the associated \s-1SSL_CTX\s0 pointer, modifying the server's list of permitted \s-1TLS\s0 -versions, changing the server's cipher list in response to the client's -cipher list, etc. -.PP -It is also recommended that applications utilize a ClientHello callback and -not use a servername callback, in order to avoid unexpected behavior that -occurs due to the relative order of processing between things like session -resumption and the historical servername callback. -.PP -The SSL_client_hello_* family of functions may only be called from code executing -within a ClientHello callback. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The application's supplied ClientHello callback returns -\&\s-1SSL_CLIENT_HELLO_SUCCESS\s0 on success, \s-1SSL_CLIENT_HELLO_ERROR\s0 on failure, and -\&\s-1SSL_CLIENT_HELLO_RETRY\s0 to suspend processing. -.PP -\&\fBSSL_client_hello_isv2()\fR returns 1 for SSLv2\-format ClientHellos and 0 otherwise. -.PP -\&\fBSSL_client_hello_get0_random()\fR, \fBSSL_client_hello_get0_session_id()\fR, -\&\fBSSL_client_hello_get0_ciphers()\fR, and -\&\fBSSL_client_hello_get0_compression_methods()\fR return the length of the -corresponding ClientHello fields. If zero is returned, the output pointer -should not be assumed to be valid. -.PP -\&\fBSSL_client_hello_get0_ext()\fR returns 1 if the extension of type 'type' is present, and -0 otherwise. -.PP -\&\fBSSL_client_hello_get1_extensions_present()\fR returns 1 on success and 0 on failure. -.PP -\&\fBSSL_client_hello_get_extension_order()\fR returns 1 on success and 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_tlsext_servername_callback\fR\|(3), -\&\fBSSL_bytes_to_cipher_list\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1SSL\s0 ClientHello callback, \fBSSL_client_hello_isv2()\fR, -\&\fBSSL_client_hello_get0_random()\fR, \fBSSL_client_hello_get0_session_id()\fR, -\&\fBSSL_client_hello_get0_ciphers()\fR, \fBSSL_client_hello_get0_compression_methods()\fR, -\&\fBSSL_client_hello_get0_ext()\fR, and \fBSSL_client_hello_get1_extensions_present()\fR -were added in OpenSSL 1.1.1. -\&\fBSSL_client_hello_get_extension_order()\fR -was added in OpenSSL 3.2.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_cookie_generate_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_cookie_generate_cb.3ossl deleted file mode 120000 index e3679a79..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_cookie_generate_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_stateless_cookie_generate_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_cookie_verify_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_cookie_verify_cb.3ossl deleted file mode 120000 index e3679a79..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_cookie_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_stateless_cookie_generate_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_ct_validation_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_ct_validation_callback.3ossl deleted file mode 100644 index 3f90cd67..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_ct_validation_callback.3ossl +++ /dev/null @@ -1,275 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CT_VALIDATION_CALLBACK 3ossl" -.TH SSL_CTX_SET_CT_VALIDATION_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ssl_ct_validation_cb, -SSL_enable_ct, SSL_CTX_enable_ct, SSL_disable_ct, SSL_CTX_disable_ct, -SSL_set_ct_validation_callback, SSL_CTX_set_ct_validation_callback, -SSL_ct_is_enabled, SSL_CTX_ct_is_enabled \- -control Certificate Transparency policy -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*ssl_ct_validation_cb)(const CT_POLICY_EVAL_CTX *ctx, -\& const STACK_OF(SCT) *scts, void *arg); -\& -\& int SSL_enable_ct(SSL *s, int validation_mode); -\& int SSL_CTX_enable_ct(SSL_CTX *ctx, int validation_mode); -\& int SSL_set_ct_validation_callback(SSL *s, ssl_ct_validation_cb callback, -\& void *arg); -\& int SSL_CTX_set_ct_validation_callback(SSL_CTX *ctx, -\& ssl_ct_validation_cb callback, -\& void *arg); -\& void SSL_disable_ct(SSL *s); -\& void SSL_CTX_disable_ct(SSL_CTX *ctx); -\& int SSL_ct_is_enabled(const SSL *s); -\& int SSL_CTX_ct_is_enabled(const SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_enable_ct()\fR and \fBSSL_CTX_enable_ct()\fR enable the processing of signed -certificate timestamps (SCTs) either for a given \s-1SSL\s0 connection or for all -connections that share the given \s-1SSL\s0 context, respectively. -This is accomplished by setting a built-in \s-1CT\s0 validation callback. -The behaviour of the callback is determined by the \fBvalidation_mode\fR argument, -which can be either of \fB\s-1SSL_CT_VALIDATION_PERMISSIVE\s0\fR or -\&\fB\s-1SSL_CT_VALIDATION_STRICT\s0\fR as described below. -.PP -If \fBvalidation_mode\fR is equal to \fB\s-1SSL_CT_VALIDATION_STRICT\s0\fR, then in a full -\&\s-1TLS\s0 handshake with the verification mode set to \fB\s-1SSL_VERIFY_PEER\s0\fR, if the peer -presents no valid SCTs the handshake will be aborted. -If the verification mode is \fB\s-1SSL_VERIFY_NONE\s0\fR, the handshake will continue -despite lack of valid SCTs. -However, in that case if the verification status before the built-in callback -was \fBX509_V_OK\fR it will be set to \fBX509_V_ERR_NO_VALID_SCTS\fR after the -callback. -Applications can call \fBSSL_get_verify_result\fR\|(3) to check the status at -handshake completion, even after session resumption since the verification -status is part of the saved session state. -See \fBSSL_set_verify\fR\|(3), <\fBSSL_get_verify_result\fR\|(3)>, \fBSSL_session_reused\fR\|(3). -.PP -If \fBvalidation_mode\fR is equal to \fB\s-1SSL_CT_VALIDATION_PERMISSIVE\s0\fR, then the -handshake continues, and the verification status is not modified, regardless of -the validation status of any SCTs. -The application can still inspect the validation status of the SCTs at -handshake completion. -Note that with session resumption there will not be any SCTs presented during -the handshake. -Therefore, in applications that delay \s-1SCT\s0 policy enforcement until after -handshake completion, such delayed \s-1SCT\s0 checks should only be performed when the -session is not resumed. -.PP -\&\fBSSL_set_ct_validation_callback()\fR and \fBSSL_CTX_set_ct_validation_callback()\fR -register a custom callback that may implement a different policy than either of -the above. -This callback can examine the peer's SCTs and determine whether they are -sufficient to allow the connection to continue. -The \s-1TLS\s0 handshake is aborted if the verification mode is not \fB\s-1SSL_VERIFY_NONE\s0\fR -and the callback returns a non-positive result. -.PP -An arbitrary callback data argument, \fBarg\fR, can be passed in when setting -the callback. -This will be passed to the callback whenever it is invoked. -Ownership of this context remains with the caller. -.PP -If no callback is set, SCTs will not be requested and Certificate Transparency -validation will not occur. -.PP -No callback will be invoked when the peer presents no certificate, e.g. by -employing an anonymous (aNULL) cipher suite. -In that case the handshake continues as it would had no callback been -requested. -Callbacks are also not invoked when the peer certificate chain is invalid or -validated via \s-1\fBDANE\-TA\s0\fR\|(2) or \s-1\fBDANE\-EE\s0\fR\|(3) \s-1TLSA\s0 records which use a private X.509 -\&\s-1PKI,\s0 or no X.509 \s-1PKI\s0 at all, respectively. -Clients that require SCTs are expected to not have enabled any aNULL ciphers -nor to have specified server verification via \s-1\fBDANE\-TA\s0\fR\|(2) or \s-1\fBDANE\-EE\s0\fR\|(3) \s-1TLSA\s0 -records. -.PP -\&\fBSSL_disable_ct()\fR and \fBSSL_CTX_disable_ct()\fR turn off \s-1CT\s0 processing, whether -enabled via the built-in or the custom callbacks, by setting a \s-1NULL\s0 callback. -These may be implemented as macros. -.PP -\&\fBSSL_ct_is_enabled()\fR and \fBSSL_CTX_ct_is_enabled()\fR return 1 if \s-1CT\s0 processing is -enabled via either \fBSSL_enable_ct()\fR or a non-null custom callback, and 0 -otherwise. -.SH "NOTES" -.IX Header "NOTES" -When \s-1SCT\s0 processing is enabled, \s-1OCSP\s0 stapling will be enabled. This is because -one possible source of SCTs is the \s-1OCSP\s0 response from a server. -.PP -The time returned by \fBSSL_SESSION_get_time_ex()\fR will be used to evaluate whether any -presented SCTs have timestamps that are in the future (and therefore invalid). -.SH "RESTRICTIONS" -.IX Header "RESTRICTIONS" -Certificate Transparency validation cannot be enabled and so a callback cannot -be set if a custom client extension handler has been registered to handle \s-1SCT\s0 -extensions (\fBTLSEXT_TYPE_signed_certificate_timestamp\fR). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_enable_ct()\fR, \fBSSL_CTX_enable_ct()\fR, \fBSSL_CTX_set_ct_validation_callback()\fR and -\&\fBSSL_set_ct_validation_callback()\fR return 1 if the \fBcallback\fR is successfully -set. -They return 0 if an error occurs, e.g. a custom client extension handler has -been setup to handle SCTs. -.PP -\&\fBSSL_disable_ct()\fR and \fBSSL_CTX_disable_ct()\fR do not return a result. -.PP -\&\fBSSL_CTX_ct_is_enabled()\fR and \fBSSL_ct_is_enabled()\fR return a 1 if a non-null \s-1CT\s0 -validation callback is set, or 0 if no callback (or equivalently a \s-1NULL\s0 -callback) is set. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -<\fBSSL_get_verify_result\fR\|(3)>, -\&\fBSSL_session_reused\fR\|(3), -\&\fBSSL_set_verify\fR\|(3), -\&\fBSSL_CTX_set_verify\fR\|(3), -\&\fBSSL_SESSION_get_time\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_ctlog_list_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_ctlog_list_file.3ossl deleted file mode 100644 index fe415a0d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_ctlog_list_file.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_CTLOG_LIST_FILE 3ossl" -.TH SSL_CTX_SET_CTLOG_LIST_FILE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_default_ctlog_list_file, SSL_CTX_set_ctlog_list_file \- -load a Certificate Transparency log list from a file -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_default_ctlog_list_file(SSL_CTX *ctx); -\& int SSL_CTX_set_ctlog_list_file(SSL_CTX *ctx, const char *path); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_default_ctlog_list_file()\fR loads a list of Certificate Transparency -(\s-1CT\s0) logs from the default file location, \*(L"ct_log_list.cnf\*(R", found in the -directory where OpenSSL is installed. -.PP -\&\fBSSL_CTX_set_ctlog_list_file()\fR loads a list of \s-1CT\s0 logs from a specific path. -See \fBCTLOG_STORE_new\fR\|(3) for the file format. -.SH "NOTES" -.IX Header "NOTES" -These functions will not clear the existing \s-1CT\s0 log list \- it will be appended -to. To replace the existing list, use \fBSSL_CTX_set0_ctlog_store\fR\|(3) first. -.PP -If an error occurs whilst parsing a particular log entry in the file, that log -entry will be skipped. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_default_ctlog_list_file()\fR and \fBSSL_CTX_set_ctlog_list_file()\fR -return 1 if the log list is successfully loaded, and 0 if an error occurs. In -the case of an error, the log list may have been partially loaded. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_ct_validation_callback\fR\|(3), -\&\fBCTLOG_STORE_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_current_cert.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_current_cert.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_current_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_ctlog_list_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_ctlog_list_file.3ossl deleted file mode 120000 index a2b44ee4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_ctlog_list_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ctlog_list_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb.3ossl deleted file mode 100644 index f2a4e53f..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb.3ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_DEFAULT_PASSWD_CB 3ossl" -.TH SSL_CTX_SET_DEFAULT_PASSWD_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_default_passwd_cb, SSL_CTX_set_default_passwd_cb_userdata, -SSL_CTX_get_default_passwd_cb, SSL_CTX_get_default_passwd_cb_userdata, -SSL_set_default_passwd_cb, SSL_set_default_passwd_cb_userdata, -SSL_get_default_passwd_cb, SSL_get_default_passwd_cb_userdata \- set or -get passwd callback for encrypted PEM file handling -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_default_passwd_cb(SSL_CTX *ctx, pem_password_cb *cb); -\& void SSL_CTX_set_default_passwd_cb_userdata(SSL_CTX *ctx, void *u); -\& pem_password_cb *SSL_CTX_get_default_passwd_cb(SSL_CTX *ctx); -\& void *SSL_CTX_get_default_passwd_cb_userdata(SSL_CTX *ctx); -\& -\& void SSL_set_default_passwd_cb(SSL *s, pem_password_cb *cb); -\& void SSL_set_default_passwd_cb_userdata(SSL *s, void *u); -\& pem_password_cb *SSL_get_default_passwd_cb(SSL *s); -\& void *SSL_get_default_passwd_cb_userdata(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_default_passwd_cb()\fR sets the default password callback called -when loading/storing a \s-1PEM\s0 certificate with encryption. -.PP -\&\fBSSL_CTX_set_default_passwd_cb_userdata()\fR sets a pointer to userdata, \fBu\fR, -which will be provided to the password callback on invocation. -.PP -\&\fBSSL_CTX_get_default_passwd_cb()\fR returns a function pointer to the password -callback currently set in \fBctx\fR. If no callback was explicitly set, the -\&\s-1NULL\s0 pointer is returned. -.PP -\&\fBSSL_CTX_get_default_passwd_cb_userdata()\fR returns a pointer to the userdata -currently set in \fBctx\fR. If no userdata was explicitly set, the \s-1NULL\s0 pointer -is returned. -.PP -\&\fBSSL_set_default_passwd_cb()\fR, \fBSSL_set_default_passwd_cb_userdata()\fR, -\&\fBSSL_get_default_passwd_cb()\fR and \fBSSL_get_default_passwd_cb_userdata()\fR perform -the same function as their \s-1SSL_CTX\s0 counterparts, but using an \s-1SSL\s0 object. -.PP -The password callback, which must be provided by the application, hands back the -password to be used during decryption. -On invocation a pointer to userdata -is provided. The function must store the password into the provided buffer -\&\fBbuf\fR which is of size \fBsize\fR. The actual length of the password must -be returned to the calling function. \fBrwflag\fR indicates whether the -callback is used for reading/decryption (rwflag=0) or writing/encryption -(rwflag=1). -For more details, see \fBpem_password_cb\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -When loading or storing private keys, a password might be supplied to -protect the private key. The way this password can be supplied may depend -on the application. If only one private key is handled, it can be practical -to have the callback handle the password dialog interactively. If several -keys have to be handled, it can be practical to ask for the password once, -then keep it in memory and use it several times. In the last case, the -password could be stored into the userdata storage and the -callback only returns the password already stored. -.PP -When asking for the password interactively, the callback can use -\&\fBrwflag\fR to check, whether an item shall be encrypted (rwflag=1). -In this case the password dialog may ask for the same password twice -for comparison in order to catch typos, that would make decryption -impossible. -.PP -Other items in \s-1PEM\s0 formatting (certificates) can also be encrypted, it is -however not usual, as certificate information is considered public. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions do not provide diagnostic information. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following example returns the password provided as userdata to the -calling function. The password is considered to be a '\e0' terminated -string. If the password does not fit into the buffer, the password is -truncated. -.PP -.Vb 6 -\& int my_cb(char *buf, int size, int rwflag, void *u) -\& { -\& strncpy(buf, (char *)u, size); -\& buf[size \- 1] = \*(Aq\e0\*(Aq; -\& return strlen(buf); -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_use_certificate\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_CTX_get_default_passwd_cb()\fR, \fBSSL_CTX_get_default_passwd_cb_userdata()\fR, -\&\fBSSL_set_default_passwd_cb()\fR and \fBSSL_set_default_passwd_cb_userdata()\fR were -added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2019 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb_userdata.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb_userdata.3ossl deleted file mode 120000 index 5e9f9bdf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_passwd_cb_userdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_default_passwd_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_read_buffer_len.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_read_buffer_len.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_read_buffer_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_dir.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_verify_dir.3ossl deleted file mode 120000 index 443728eb..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_dir.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_load_verify_locations.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_verify_file.3ossl deleted file mode 120000 index 443728eb..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_load_verify_locations.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_paths.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_verify_paths.3ossl deleted file mode 120000 index 443728eb..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_paths.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_load_verify_locations.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_store.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_default_verify_store.3ossl deleted file mode 120000 index 443728eb..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_default_verify_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_load_verify_locations.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_dh_auto.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_dh_auto.3ossl deleted file mode 120000 index 838d6609..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_dh_auto.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_dh_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_ecdh_auto.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_ecdh_auto.3ossl deleted file mode 120000 index 3b8a967a..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_ecdh_auto.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_ecdh.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_ex_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_generate_session_id.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_generate_session_id.3ossl deleted file mode 100644 index 436a4658..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_generate_session_id.3ossl +++ /dev/null @@ -1,269 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_GENERATE_SESSION_ID 3ossl" -.TH SSL_CTX_SET_GENERATE_SESSION_ID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_generate_session_id, SSL_set_generate_session_id, -SSL_has_matching_session_id, GEN_SESSION_CB -\&\- manipulate generation of SSL session IDs (server only) -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*GEN_SESSION_CB)(SSL *ssl, unsigned char *id, -\& unsigned int *id_len); -\& -\& int SSL_CTX_set_generate_session_id(SSL_CTX *ctx, GEN_SESSION_CB cb); -\& int SSL_set_generate_session_id(SSL *ssl, GEN_SESSION_CB, cb); -\& int SSL_has_matching_session_id(const SSL *ssl, const unsigned char *id, -\& unsigned int id_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_generate_session_id()\fR sets the callback function for generating -new session ids for \s-1SSL/TLS\s0 sessions for \fBctx\fR to be \fBcb\fR. -.PP -\&\fBSSL_set_generate_session_id()\fR sets the callback function for generating -new session ids for \s-1SSL/TLS\s0 sessions for \fBssl\fR to be \fBcb\fR. -.PP -\&\fBSSL_has_matching_session_id()\fR checks, whether a session with id \fBid\fR -(of length \fBid_len\fR) is already contained in the internal session cache -of the parent context of \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -When a new session is established between client and server, the server -generates a session id. The session id is an arbitrary sequence of bytes. -The length of the session id is between 1 and 32 bytes. The session id is not -security critical but must be unique for the server. Additionally, the session id is -transmitted in the clear when reusing the session so it must not contain -sensitive information. -.PP -Without a callback being set, an OpenSSL server will generate a unique -session id from pseudo random numbers of the maximum possible length. -Using the callback function, the session id can be changed to contain -additional information like e.g. a host id in order to improve load balancing -or external caching techniques. -.PP -The callback function receives a pointer to the memory location to put -\&\fBid\fR into and a pointer to the maximum allowed length \fBid_len\fR. The -buffer at location \fBid\fR is only guaranteed to have the size \fBid_len\fR. -The callback is only allowed to generate a shorter id and reduce \fBid_len\fR; -the callback \fBmust never\fR increase \fBid_len\fR or write to the location -\&\fBid\fR exceeding the given limit. -.PP -The location \fBid\fR is filled with 0x00 before the callback is called, so the -callback may only fill part of the possible length and leave \fBid_len\fR -untouched while maintaining reproducibility. -.PP -Since the sessions must be distinguished, session ids must be unique. -Without the callback a random number is used, so that the probability -of generating the same session id is extremely small (2^256 for SSLv3/TLSv1). -In order to assure the uniqueness of the generated session id, the callback must call -\&\fBSSL_has_matching_session_id()\fR and generate another id if a conflict occurs. -If an id conflict is not resolved, the handshake will fail. -If the application codes e.g. a unique host id, a unique process number, and -a unique sequence number into the session id, uniqueness could easily be -achieved without randomness added (it should however be taken care that -no confidential information is leaked this way). If the application can not -guarantee uniqueness, it is recommended to use the maximum \fBid_len\fR and -fill in the bytes not used to code special information with random data -to avoid collisions. -.PP -\&\fBSSL_has_matching_session_id()\fR will only query the internal session cache, -not the external one. Since the session id is generated before the -handshake is completed, it is not immediately added to the cache. If -another thread is using the same internal session cache, a race condition -can occur in that another thread generates the same session id. -Collisions can also occur when using an external session cache, since -the external cache is not tested with \fBSSL_has_matching_session_id()\fR -and the same race condition applies. -.PP -The callback must return 0 if it cannot generate a session id for whatever -reason and return 1 on success. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_generate_session_id()\fR and \fBSSL_set_generate_session_id()\fR -return 1 on success and 0 for failure. -.PP -\&\fBSSL_has_matching_session_id()\fR returns 1 if another session with the -same id is already in the cache, or 0 otherwise. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The callback function listed will generate a session id with the -server id given, and will fill the rest with pseudo random bytes: -.PP -.Vb 1 -\& const char session_id_prefix = "www\-18"; -\& -\& #define MAX_SESSION_ID_ATTEMPTS 10 -\& static int generate_session_id(SSL *ssl, unsigned char *id, -\& unsigned int *id_len) -\& { -\& unsigned int count = 0; -\& -\& do { -\& RAND_pseudo_bytes(id, *id_len); -\& /* -\& * Prefix the session_id with the required prefix. NB: If our -\& * prefix is too long, clip it \- but there will be worse effects -\& * anyway, e.g. the server could only possibly create 1 session -\& * ID (i.e. the prefix!) so all future session negotiations will -\& * fail due to conflicts. -\& */ -\& memcpy(id, session_id_prefix, strlen(session_id_prefix) < *id_len ? -\& strlen(session_id_prefix) : *id_len); -\& } while (SSL_has_matching_session_id(ssl, id, *id_len) -\& && ++count < MAX_SESSION_ID_ATTEMPTS); -\& if (count >= MAX_SESSION_ID_ATTEMPTS) -\& return 0; -\& return 1; -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_version\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_info_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_info_callback.3ossl deleted file mode 100644 index ae0a0ac1..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_info_callback.3ossl +++ /dev/null @@ -1,293 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_INFO_CALLBACK 3ossl" -.TH SSL_CTX_SET_INFO_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_info_callback, -SSL_CTX_get_info_callback, -SSL_set_info_callback, -SSL_get_info_callback -\&\- handle information callback for SSL connections -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_info_callback(SSL_CTX *ctx, -\& void (*callback) (const SSL *ssl, int type, int val)); -\& -\& void (*SSL_CTX_get_info_callback(SSL_CTX *ctx)) (const SSL *ssl, int type, int val); -\& -\& void SSL_set_info_callback(SSL *ssl, -\& void (*callback) (const SSL *ssl, int type, int val)); -\& -\& void (*SSL_get_info_callback(const SSL *ssl)) (const SSL *ssl, int type, int val); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_info_callback()\fR sets the \fBcallback\fR function, that can be used to -obtain state information for \s-1SSL\s0 objects created from \fBctx\fR during connection -setup and use. The setting for \fBctx\fR is overridden from the setting for -a specific \s-1SSL\s0 object, if specified. -When \fBcallback\fR is \s-1NULL,\s0 no callback function is used. -.PP -\&\fBSSL_set_info_callback()\fR sets the \fBcallback\fR function, that can be used to -obtain state information for \fBssl\fR during connection setup and use. -When \fBcallback\fR is \s-1NULL,\s0 the callback setting currently valid for -\&\fBctx\fR is used. -.PP -\&\fBSSL_CTX_get_info_callback()\fR returns a pointer to the currently set information -callback function for \fBctx\fR. -.PP -\&\fBSSL_get_info_callback()\fR returns a pointer to the currently set information -callback function for \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -When setting up a connection and during use, it is possible to obtain state -information from the \s-1SSL/TLS\s0 engine. When set, an information callback function -is called whenever a significant event occurs such as: the state changes, -an alert appears, or an error occurs. -.PP -The callback function is called as \fBcallback(\s-1SSL\s0 *ssl, int where, int ret)\fR. -The \fBwhere\fR argument specifies information about where (in which context) -the callback function was called. If \fBret\fR is 0, an error condition occurred. -If an alert is handled, \s-1SSL_CB_ALERT\s0 is set and \fBret\fR specifies the alert -information. -.PP -\&\fBwhere\fR is a bit-mask made up of the following bits: -.IP "\s-1SSL_CB_LOOP\s0" 4 -.IX Item "SSL_CB_LOOP" -Callback has been called to indicate state change or some other significant -state machine event. This may mean that the callback gets invoked more than once -per state in some situations. -.IP "\s-1SSL_CB_EXIT\s0" 4 -.IX Item "SSL_CB_EXIT" -Callback has been called to indicate exit of a handshake function. This will -happen after the end of a handshake, but may happen at other times too such as -on error or when \s-1IO\s0 might otherwise block and nonblocking is being used. -.IP "\s-1SSL_CB_READ\s0" 4 -.IX Item "SSL_CB_READ" -Callback has been called during read operation. -.IP "\s-1SSL_CB_WRITE\s0" 4 -.IX Item "SSL_CB_WRITE" -Callback has been called during write operation. -.IP "\s-1SSL_CB_ALERT\s0" 4 -.IX Item "SSL_CB_ALERT" -Callback has been called due to an alert being sent or received. -.IP "\s-1SSL_CB_READ_ALERT\s0 (SSL_CB_ALERT|SSL_CB_READ)" 4 -.IX Item "SSL_CB_READ_ALERT (SSL_CB_ALERT|SSL_CB_READ)" -.PD 0 -.IP "\s-1SSL_CB_WRITE_ALERT\s0 (SSL_CB_ALERT|SSL_CB_WRITE)" 4 -.IX Item "SSL_CB_WRITE_ALERT (SSL_CB_ALERT|SSL_CB_WRITE)" -.IP "\s-1SSL_CB_ACCEPT_LOOP\s0 (SSL_ST_ACCEPT|SSL_CB_LOOP)" 4 -.IX Item "SSL_CB_ACCEPT_LOOP (SSL_ST_ACCEPT|SSL_CB_LOOP)" -.IP "\s-1SSL_CB_ACCEPT_EXIT\s0 (SSL_ST_ACCEPT|SSL_CB_EXIT)" 4 -.IX Item "SSL_CB_ACCEPT_EXIT (SSL_ST_ACCEPT|SSL_CB_EXIT)" -.IP "\s-1SSL_CB_CONNECT_LOOP\s0 (SSL_ST_CONNECT|SSL_CB_LOOP)" 4 -.IX Item "SSL_CB_CONNECT_LOOP (SSL_ST_CONNECT|SSL_CB_LOOP)" -.IP "\s-1SSL_CB_CONNECT_EXIT\s0 (SSL_ST_CONNECT|SSL_CB_EXIT)" 4 -.IX Item "SSL_CB_CONNECT_EXIT (SSL_ST_CONNECT|SSL_CB_EXIT)" -.IP "\s-1SSL_CB_HANDSHAKE_START\s0" 4 -.IX Item "SSL_CB_HANDSHAKE_START" -.PD -Callback has been called because a new handshake is started. It also occurs when -resuming a handshake following a pause to handle early data. -.IP "\s-1SSL_CB_HANDSHAKE_DONE\s0" 4 -.IX Item "SSL_CB_HANDSHAKE_DONE" -Callback has been called because a handshake is finished. It also occurs if the -handshake is paused to allow the exchange of early data. -.PP -The current state information can be obtained using the -\&\fBSSL_state_string\fR\|(3) family of functions. -.PP -The \fBret\fR information can be evaluated using the -\&\fBSSL_alert_type_string\fR\|(3) family of functions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_info_callback()\fR does not provide diagnostic information. -.PP -\&\fBSSL_get_info_callback()\fR returns the current setting. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following example callback function prints state strings, information -about alerts being handled and error messages to the \fBbio_err\fR \s-1BIO.\s0 -.PP -.Vb 4 -\& void apps_ssl_info_callback(const SSL *s, int where, int ret) -\& { -\& const char *str; -\& int w = where & ~SSL_ST_MASK; -\& -\& if (w & SSL_ST_CONNECT) -\& str = "SSL_connect"; -\& else if (w & SSL_ST_ACCEPT) -\& str = "SSL_accept"; -\& else -\& str = "undefined"; -\& -\& if (where & SSL_CB_LOOP) { -\& BIO_printf(bio_err, "%s:%s\en", str, SSL_state_string_long(s)); -\& } else if (where & SSL_CB_ALERT) { -\& str = (where & SSL_CB_READ) ? "read" : "write"; -\& BIO_printf(bio_err, "SSL3 alert %s:%s:%s\en", str, -\& SSL_alert_type_string_long(ret), -\& SSL_alert_desc_string_long(ret)); -\& } else if (where & SSL_CB_EXIT) { -\& if (ret == 0) { -\& BIO_printf(bio_err, "%s:failed in %s\en", -\& str, SSL_state_string_long(s)); -\& } else if (ret < 0) { -\& BIO_printf(bio_err, "%s:error in %s\en", -\& str, SSL_state_string_long(s)); -\& } -\& } -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_state_string\fR\|(3), -\&\fBSSL_alert_type_string\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_keylog_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_keylog_callback.3ossl deleted file mode 100644 index 737e5431..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_keylog_callback.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_KEYLOG_CALLBACK 3ossl" -.TH SSL_CTX_SET_KEYLOG_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_keylog_callback, SSL_CTX_get_keylog_callback, -SSL_CTX_keylog_cb_func \- logging TLS key material -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef void (*SSL_CTX_keylog_cb_func)(const SSL *ssl, const char *line); -\& -\& void SSL_CTX_set_keylog_callback(SSL_CTX *ctx, SSL_CTX_keylog_cb_func cb); -\& SSL_CTX_keylog_cb_func SSL_CTX_get_keylog_callback(const SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_keylog_callback()\fR sets the \s-1TLS\s0 key logging callback. This callback -is called whenever \s-1TLS\s0 key material is generated or received, in order to allow -applications to store this keying material for debugging purposes. -.PP -\&\fBSSL_CTX_get_keylog_callback()\fR retrieves the previously set \s-1TLS\s0 key logging -callback. If no callback has been set, this will return \s-1NULL.\s0 When there is no -key logging callback, or if SSL_CTX_set_keylog_callback is called with \s-1NULL\s0 as -the value of cb, no logging of key material will be done. -.PP -The key logging callback is called with two items: the \fBssl\fR object associated -with the connection, and \fBline\fR, a string containing the key material in the -format used by \s-1NSS\s0 for its \fB\s-1SSLKEYLOGFILE\s0\fR debugging output. To recreate that -file, the key logging callback should log \fBline\fR, followed by a newline. -\&\fBline\fR will always be a NUL-terminated string. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_get_keylog_callback()\fR returns a pointer to \fBSSL_CTX_keylog_cb_func\fR or -\&\s-1NULL\s0 if the callback is not set. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_max_cert_list.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_max_cert_list.3ossl deleted file mode 100644 index a872baa8..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_max_cert_list.3ossl +++ /dev/null @@ -1,213 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_MAX_CERT_LIST 3ossl" -.TH SSL_CTX_SET_MAX_CERT_LIST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_max_cert_list, SSL_CTX_get_max_cert_list, SSL_set_max_cert_list, SSL_get_max_cert_list \- manipulate allowed size for the peer's certificate chain -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_max_cert_list(SSL_CTX *ctx, long size); -\& long SSL_CTX_get_max_cert_list(SSL_CTX *ctx); -\& -\& long SSL_set_max_cert_list(SSL *ssl, long size); -\& long SSL_get_max_cert_list(SSL *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_max_cert_list()\fR sets the maximum size allowed for the peer's -certificate chain for all \s-1SSL\s0 objects created from \fBctx\fR to be bytes. -The \s-1SSL\s0 objects inherit the setting valid for \fBctx\fR at the time -\&\fBSSL_new\fR\|(3) is being called. -.PP -\&\fBSSL_CTX_get_max_cert_list()\fR returns the currently set maximum size for \fBctx\fR. -.PP -\&\fBSSL_set_max_cert_list()\fR sets the maximum size allowed for the peer's -certificate chain for \fBssl\fR to be bytes. This setting stays valid -until a new value is set. -.PP -\&\fBSSL_get_max_cert_list()\fR returns the currently set maximum size for \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -During the handshake process, the peer may send a certificate chain. -The \s-1TLS/SSL\s0 standard does not give any maximum size of the certificate chain. -The OpenSSL library handles incoming data by a dynamically allocated buffer. -In order to prevent this buffer from growing without bounds due to data -received from a faulty or malicious peer, a maximum size for the certificate -chain is set. -.PP -The default value for the maximum certificate chain size is 100kB (30kB -on the 16\-bit \s-1DOS\s0 platform). This should be sufficient for usual certificate -chains (OpenSSL's default maximum chain length is 10, see -\&\fBSSL_CTX_set_verify\fR\|(3), and certificates -without special extensions have a typical size of 1\-2kB). -.PP -For special applications it can be necessary to extend the maximum certificate -chain size allowed to be sent by the peer, see e.g. the work on -\&\*(L"Internet X.509 Public Key Infrastructure Proxy Certificate Profile\*(R" -and \*(L"\s-1TLS\s0 Delegation Protocol\*(R" at http://www.ietf.org/ and -http://www.globus.org/ . -.PP -Under normal conditions it should never be necessary to set a value smaller -than the default, as the buffer is handled dynamically and only uses the -memory actually required by the data sent by the peer. -.PP -If the maximum certificate chain size allowed is exceeded, the handshake will -fail with a \s-1SSL_R_EXCESSIVE_MESSAGE_SIZE\s0 error. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_max_cert_list()\fR and \fBSSL_set_max_cert_list()\fR return the previously -set value. -.PP -\&\fBSSL_CTX_get_max_cert_list()\fR and \fBSSL_get_max_cert_list()\fR return the currently -set value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3), -\&\fBSSL_CTX_set_verify\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_max_pipelines.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_max_pipelines.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_max_pipelines.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_max_proto_version.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_max_proto_version.3ossl deleted file mode 120000 index 60193888..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_max_proto_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_min_proto_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_max_send_fragment.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_max_send_fragment.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_max_send_fragment.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_min_proto_version.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_min_proto_version.3ossl deleted file mode 100644 index 7388898a..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_min_proto_version.3ossl +++ /dev/null @@ -1,208 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_MIN_PROTO_VERSION 3ossl" -.TH SSL_CTX_SET_MIN_PROTO_VERSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_min_proto_version, SSL_CTX_set_max_proto_version, -SSL_CTX_get_min_proto_version, SSL_CTX_get_max_proto_version, -SSL_set_min_proto_version, SSL_set_max_proto_version, -SSL_get_min_proto_version, SSL_get_max_proto_version \- Get and set minimum -and maximum supported protocol version -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_min_proto_version(SSL_CTX *ctx, int version); -\& int SSL_CTX_set_max_proto_version(SSL_CTX *ctx, int version); -\& int SSL_CTX_get_min_proto_version(SSL_CTX *ctx); -\& int SSL_CTX_get_max_proto_version(SSL_CTX *ctx); -\& -\& int SSL_set_min_proto_version(SSL *ssl, int version); -\& int SSL_set_max_proto_version(SSL *ssl, int version); -\& int SSL_get_min_proto_version(SSL *ssl); -\& int SSL_get_max_proto_version(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions get or set the minimum and maximum supported protocol versions -for the \fBctx\fR or \fBssl\fR. -This works in combination with the options set via -\&\fBSSL_CTX_set_options\fR\|(3) that also make it possible to disable -specific protocol versions. -Use these functions instead of disabling specific protocol versions. -.PP -Setting the minimum or maximum version to 0 (default), will enable protocol -versions down to the lowest version, or up to the highest version -supported by the library, respectively. The supported versions might be -controlled by system configuration. -.PP -Getters return 0 in case \fBctx\fR or \fBssl\fR have been configured to -automatically use the lowest or highest version supported by the library. -.PP -Currently supported versions are \fB\s-1SSL3_VERSION\s0\fR, \fB\s-1TLS1_VERSION\s0\fR, -\&\fB\s-1TLS1_1_VERSION\s0\fR, \fB\s-1TLS1_2_VERSION\s0\fR, \fB\s-1TLS1_3_VERSION\s0\fR for \s-1TLS\s0 and -\&\fB\s-1DTLS1_VERSION\s0\fR, \fB\s-1DTLS1_2_VERSION\s0\fR for \s-1DTLS.\s0 -.PP -In the current version of OpenSSL only QUICv1 is supported in conjunction with -TLSv1.3. Calling these functions on a \s-1QUIC\s0 object has no effect. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These setter functions return 1 on success and 0 on failure. The getter -functions return the configured version or 0 for auto-configuration of -lowest or highest protocol, respectively. -.SH "NOTES" -.IX Header "NOTES" -All these functions are implemented using macros. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_options\fR\|(3), \fBSSL_CONF_cmd\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The setter functions were added in OpenSSL 1.1.0. The getter functions -were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_mode.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_mode.3ossl deleted file mode 100644 index 6c5b34a7..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_mode.3ossl +++ /dev/null @@ -1,269 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_MODE 3ossl" -.TH SSL_CTX_SET_MODE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_mode, SSL_CTX_clear_mode, SSL_set_mode, SSL_clear_mode, SSL_CTX_get_mode, SSL_get_mode \- manipulate SSL engine mode -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_mode(SSL_CTX *ctx, long mode); -\& long SSL_CTX_clear_mode(SSL_CTX *ctx, long mode); -\& long SSL_set_mode(SSL *ssl, long mode); -\& long SSL_clear_mode(SSL *ssl, long mode); -\& -\& long SSL_CTX_get_mode(SSL_CTX *ctx); -\& long SSL_get_mode(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_mode()\fR adds the mode set via bit-mask in \fBmode\fR to \fBctx\fR. -Options already set before are not cleared. -\&\fBSSL_CTX_clear_mode()\fR removes the mode set via bit-mask in \fBmode\fR from \fBctx\fR. -.PP -\&\fBSSL_set_mode()\fR adds the mode set via bit-mask in \fBmode\fR to \fBssl\fR. -Options already set before are not cleared. -\&\fBSSL_clear_mode()\fR removes the mode set via bit-mask in \fBmode\fR from \fBssl\fR. -.PP -\&\fBSSL_CTX_get_mode()\fR returns the mode set for \fBctx\fR. -.PP -\&\fBSSL_get_mode()\fR returns the mode set for \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -The following mode changes are available: -.IP "\s-1SSL_MODE_ENABLE_PARTIAL_WRITE\s0" 4 -.IX Item "SSL_MODE_ENABLE_PARTIAL_WRITE" -Allow SSL_write_ex(..., n, &r) to return with 0 < r < n (i.e. report success -when just a single record has been written). This works in a similar way for -\&\fBSSL_write()\fR. When not set (the default), \fBSSL_write_ex()\fR or \fBSSL_write()\fR will only -report success once the complete chunk was written. Once \fBSSL_write_ex()\fR or -\&\fBSSL_write()\fR returns successful, \fBr\fR bytes have been written and the next call -to \fBSSL_write_ex()\fR or \fBSSL_write()\fR must only send the n\-r bytes left, imitating -the behaviour of \fBwrite()\fR. -.Sp -This mode cannot be enabled while in the middle of an incomplete write -operation. -.IP "\s-1SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER\s0" 4 -.IX Item "SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER" -Make it possible to retry \fBSSL_write_ex()\fR or \fBSSL_write()\fR with changed buffer -location (the buffer contents must stay the same). This is not the default to -avoid the misconception that nonblocking \fBSSL_write()\fR behaves like -nonblocking \fBwrite()\fR. -.IP "\s-1SSL_MODE_AUTO_RETRY\s0" 4 -.IX Item "SSL_MODE_AUTO_RETRY" -During normal operations, non-application data records might need to be sent or -received that the application is not aware of. -If a non-application data record was processed, -\&\fBSSL_read_ex\fR\|(3) and \fBSSL_read\fR\|(3) can return with a failure and indicate the -need to retry with \fB\s-1SSL_ERROR_WANT_READ\s0\fR. -If such a non-application data record was processed, the flag -\&\fB\s-1SSL_MODE_AUTO_RETRY\s0\fR causes it to try to process the next record instead of -returning. -.Sp -In a nonblocking environment applications must be prepared to handle -incomplete read/write operations. -Setting \fB\s-1SSL_MODE_AUTO_RETRY\s0\fR for a nonblocking \fB\s-1BIO\s0\fR will process -non-application data records until either no more data is available or -an application data record has been processed. -.Sp -In a blocking environment, applications are not always prepared to -deal with the functions returning intermediate reports such as retry -requests, and setting the \fB\s-1SSL_MODE_AUTO_RETRY\s0\fR flag will cause the functions -to only return after successfully processing an application data record or a -failure. -.Sp -Turning off \fB\s-1SSL_MODE_AUTO_RETRY\s0\fR can be useful with blocking \fB\s-1BIO\s0\fRs in case -they are used in combination with something like \fBselect()\fR or \fBpoll()\fR. -Otherwise the call to \fBSSL_read()\fR or \fBSSL_read_ex()\fR might hang when a -non-application record was sent and no application data was sent. -.IP "\s-1SSL_MODE_RELEASE_BUFFERS\s0" 4 -.IX Item "SSL_MODE_RELEASE_BUFFERS" -When we no longer need a read buffer or a write buffer for a given \s-1SSL,\s0 -then release the memory we were using to hold it. -Using this flag can -save around 34k per idle \s-1SSL\s0 connection. -This flag has no effect on \s-1SSL\s0 v2 connections, or on \s-1DTLS\s0 connections. -.IP "\s-1SSL_MODE_SEND_FALLBACK_SCSV\s0" 4 -.IX Item "SSL_MODE_SEND_FALLBACK_SCSV" -Send \s-1TLS_FALLBACK_SCSV\s0 in the ClientHello. -To be set only by applications that reconnect with a downgraded protocol -version; see draft\-ietf\-tls\-downgrade\-scsv\-00 for details. -.Sp -\&\s-1DO NOT ENABLE THIS\s0 if your application attempts a normal handshake. -Only use this in explicit fallback retries, following the guidance -in draft\-ietf\-tls\-downgrade\-scsv\-00. -.IP "\s-1SSL_MODE_ASYNC\s0" 4 -.IX Item "SSL_MODE_ASYNC" -Enable asynchronous processing. \s-1TLS I/O\s0 operations may indicate a retry with -\&\s-1SSL_ERROR_WANT_ASYNC\s0 with this mode set if an asynchronous capable engine is -used to perform cryptographic operations. See \fBSSL_get_error\fR\|(3). -.IP "\s-1SSL_MODE_DTLS_SCTP_LABEL_LENGTH_BUG\s0" 4 -.IX Item "SSL_MODE_DTLS_SCTP_LABEL_LENGTH_BUG" -Older versions of OpenSSL had a bug in the computation of the label length -used for computing the endpoint-pair shared secret. The bug was that the -terminating zero was included in the length of the label. Setting this option -enables this behaviour to allow interoperability with such broken -implementations. Please note that setting this option breaks interoperability -with correct implementations. This option only applies to \s-1DTLS\s0 over \s-1SCTP.\s0 -.PP -All modes are off by default except for \s-1SSL_MODE_AUTO_RETRY\s0 which is on by -default since 1.1.1. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_mode()\fR and \fBSSL_set_mode()\fR return the new mode bit-mask -after adding \fBmode\fR. -.PP -\&\fBSSL_CTX_get_mode()\fR and \fBSSL_get_mode()\fR return the current bit-mask. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_read_ex\fR\|(3), \fBSSL_read\fR\|(3), \fBSSL_write_ex\fR\|(3) or -\&\fBSSL_write\fR\|(3), \fBSSL_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\s-1SSL_MODE_ASYNC\s0 was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_msg_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_msg_callback.3ossl deleted file mode 100644 index 687f3a35..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_msg_callback.3ossl +++ /dev/null @@ -1,300 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_MSG_CALLBACK 3ossl" -.TH SSL_CTX_SET_MSG_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_msg_callback, -SSL_CTX_set_msg_callback_arg, -SSL_set_msg_callback, -SSL_set_msg_callback_arg, -SSL_trace -\&\- install callback for observing protocol messages -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_msg_callback(SSL_CTX *ctx, -\& void (*cb)(int write_p, int version, -\& int content_type, const void *buf, -\& size_t len, SSL *ssl, void *arg)); -\& void SSL_CTX_set_msg_callback_arg(SSL_CTX *ctx, void *arg); -\& -\& void SSL_set_msg_callback(SSL *ssl, -\& void (*cb)(int write_p, int version, -\& int content_type, const void *buf, -\& size_t len, SSL *ssl, void *arg)); -\& void SSL_set_msg_callback_arg(SSL *ssl, void *arg); -\& -\& void SSL_trace(int write_p, int version, int content_type, -\& const void *buf, size_t len, SSL *ssl, void *arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_msg_callback()\fR or \fBSSL_set_msg_callback()\fR can be used to -define a message callback function \fIcb\fR for observing all \s-1SSL/TLS/QUIC\s0 -protocol messages (such as handshake messages) that are received or -sent, as well as other events that occur during processing. -\&\fBSSL_CTX_set_msg_callback_arg()\fR and \fBSSL_set_msg_callback_arg()\fR -can be used to set argument \fIarg\fR to the callback function, which is -available for arbitrary application use. -.PP -\&\fBSSL_CTX_set_msg_callback()\fR and \fBSSL_CTX_set_msg_callback_arg()\fR specify -default settings that will be copied to new \fB\s-1SSL\s0\fR objects by -\&\fBSSL_new\fR\|(3). \fBSSL_set_msg_callback()\fR and -\&\fBSSL_set_msg_callback_arg()\fR modify the actual settings of an \fB\s-1SSL\s0\fR -object. Using a \fB\s-1NULL\s0\fR pointer for \fIcb\fR disables the message callback. -.PP -When \fIcb\fR is called by the \s-1SSL/TLS/QUIC\s0 library the function arguments have the -following meaning: -.IP "\fIwrite_p\fR" 4 -.IX Item "write_p" -This flag is \fB0\fR when a protocol message has been received and \fB1\fR -when a protocol message has been sent. -.IP "\fIversion\fR" 4 -.IX Item "version" -The protocol version according to which the protocol message is -interpreted by the library such as \fB\s-1TLS1_3_VERSION\s0\fR, \fB\s-1TLS1_2_VERSION\s0\fR, -\&\fB\s-1OSSL_QUIC1_VERSION\s0\fR etc. For the \s-1SSL3_RT_HEADER\s0 pseudo -content type (see \s-1NOTES\s0 below) this value will be the decoded -version/legacy_version field of the record header. -.IP "\fIcontent_type\fR" 4 -.IX Item "content_type" -This is one of the content type values defined in the protocol specification -(\fB\s-1SSL3_RT_CHANGE_CIPHER_SPEC\s0\fR, \fB\s-1SSL3_RT_ALERT\s0\fR, \fB\s-1SSL3_RT_HANDSHAKE\s0\fR; but never -\&\fB\s-1SSL3_RT_APPLICATION_DATA\s0\fR because the callback will only be called for protocol -messages). Alternatively it may be a \*(L"pseudo\*(R" content type. These pseudo -content types are used to signal some other event in the processing of data (see -\&\s-1NOTES\s0 below). -.IP "\fIbuf\fR, \fIlen\fR" 4 -.IX Item "buf, len" -\&\fIbuf\fR points to a buffer containing the protocol message or other data (in the -case of pseudo content types), which consists of \fIlen\fR bytes. The buffer is no -longer valid after the callback function has returned. -.IP "\fIssl\fR" 4 -.IX Item "ssl" -The \fB\s-1SSL\s0\fR object that received or sent the message. -.IP "\fIarg\fR" 4 -.IX Item "arg" -The user-defined argument optionally defined by -\&\fBSSL_CTX_set_msg_callback_arg()\fR or \fBSSL_set_msg_callback_arg()\fR. -.PP -The \fBSSL_trace()\fR function can be used as a pre-written callback in a call to -\&\fBSSL_CTX_set_msg_callback()\fR or \fBSSL_set_msg_callback()\fR. It requires a \s-1BIO\s0 to be -set as the callback argument via \fBSSL_CTX_set_msg_callback_arg()\fR or -\&\fBSSL_set_msg_callback_arg()\fR. Setting this callback will cause human readable -diagostic tracing information about an \s-1SSL/TLS/QUIC\s0 connection to be written to -the \s-1BIO.\s0 -.SH "NOTES" -.IX Header "NOTES" -Protocol messages are passed to the callback function after decryption -and fragment collection where applicable. (Thus record boundaries are -not visible.) -.PP -If processing a received protocol message results in an error, -the callback function may not be called. For example, the callback -function will never see messages that are considered too large to be -processed. -.PP -Due to automatic protocol version negotiation, \fIversion\fR is not -necessarily the protocol version used by the sender of the message: If -a \s-1TLS 1.0\s0 ClientHello message is received by an \s-1SSL 3\s0.0\-only server, -\&\fIversion\fR will be \fB\s-1SSL3_VERSION\s0\fR. -.PP -Pseudo content type values may be sent at various points during the processing -of data. The following pseudo content types are currently defined: -.IP "\fB\s-1SSL3_RT_HEADER\s0\fR" 4 -.IX Item "SSL3_RT_HEADER" -Used when a \s-1TLS\s0 record is sent or received. The \fBbuf\fR contains the record header -bytes only. -.IP "\fB\s-1SSL3_RT_INNER_CONTENT_TYPE\s0\fR" 4 -.IX Item "SSL3_RT_INNER_CONTENT_TYPE" -Used when an encrypted TLSv1.3 record is sent or received. In encrypted TLSv1.3 -records the content type in the record header is always -\&\s-1SSL3_RT_APPLICATION_DATA.\s0 The real content type for the record is contained in -an \*(L"inner\*(R" content type. \fBbuf\fR contains the encoded \*(L"inner\*(R" content type byte. -.IP "\fB\s-1SSL3_RT_QUIC_DATAGRAM\s0\fR" 4 -.IX Item "SSL3_RT_QUIC_DATAGRAM" -Used when a \s-1QUIC\s0 datagram is sent or received. -.IP "\fB\s-1SSL3_RT_QUIC_PACKET\s0\fR" 4 -.IX Item "SSL3_RT_QUIC_PACKET" -Used when a \s-1QUIC\s0 packet is sent or received. -.IP "\fB\s-1SSL3_RT_QUIC_FRAME_FULL\s0\fR" 4 -.IX Item "SSL3_RT_QUIC_FRAME_FULL" -Used when a \s-1QUIC\s0 frame is sent or received. This is only used for non-crypto -and stream data related frames. The full \s-1QUIC\s0 frame data is supplied. -.IP "\fB\s-1SSL3_RT_QUIC_FRAME_HEADER\s0\fR" 4 -.IX Item "SSL3_RT_QUIC_FRAME_HEADER" -Used when a \s-1QUIC\s0 stream data or crypto frame is sent or received. Only the \s-1QUIC\s0 -frame header data is supplied. -.IP "\fB\s-1SSL3_RT_QUIC_FRAME_PADDING\s0\fR" 4 -.IX Item "SSL3_RT_QUIC_FRAME_PADDING" -Used when a sequence of one or more \s-1QUIC\s0 padding frames is sent or received. -A padding frame consists of a single byte and it is common to have multiple -such frames in a sequence. Rather than supplying each frame individually the -callback will supply all the padding frames in one go via this pseudo content -type. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_msg_callback()\fR, \fBSSL_CTX_set_msg_callback_arg()\fR, \fBSSL_set_msg_callback()\fR -and \fBSSL_set_msg_callback_arg()\fR do not return values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The pseudo content type \fB\s-1SSL3_RT_INNER_CONTENT_TYPE\s0\fR was added in OpenSSL 1.1.1. -.PP -The pseudo content types \fB\s-1SSL3_RT_QUIC_DATAGRAM\s0\fR, \fB\s-1SSL3_RT_QUIC_PACKET\s0\fR, -\&\fB\s-1SSL3_RT_QUIC_FRAME_FULL\s0\fR, \fB\s-1SSL3_RT_QUIC_FRAME_HEADER\s0\fR and -\&\fB\s-1SSL3_RT_QUIC_FRAME_PADDING\s0\fR were added in OpenSSL 3.2. -.PP -In versions previous to OpenSSL 3.0 \fIcb\fR was called with 0 as \fIversion\fR for -the pseudo content type \fB\s-1SSL3_RT_HEADER\s0\fR for \s-1TLS\s0 records. -.PP -In versions previous to OpenSSL 3.2 \fIcb\fR was called with 0 as \fIversion\fR for -the pseudo content type \fB\s-1SSL3_RT_HEADER\s0\fR for \s-1DTLS\s0 records. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_msg_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_msg_callback_arg.3ossl deleted file mode 120000 index dff83f3f..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_msg_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_msg_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_next_proto_select_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_next_proto_select_cb.3ossl deleted file mode 120000 index fa1385af..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_next_proto_select_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_alpn_select_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_next_protos_advertised_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_next_protos_advertised_cb.3ossl deleted file mode 120000 index fa1385af..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_next_protos_advertised_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_alpn_select_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_num_tickets.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_num_tickets.3ossl deleted file mode 100644 index 5ca42222..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_num_tickets.3ossl +++ /dev/null @@ -1,227 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_NUM_TICKETS 3ossl" -.TH SSL_CTX_SET_NUM_TICKETS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_num_tickets, -SSL_get_num_tickets, -SSL_CTX_set_num_tickets, -SSL_CTX_get_num_tickets, -SSL_new_session_ticket -\&\- control the number of TLSv1.3 session tickets that are issued -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set_num_tickets(SSL *s, size_t num_tickets); -\& size_t SSL_get_num_tickets(const SSL *s); -\& int SSL_CTX_set_num_tickets(SSL_CTX *ctx, size_t num_tickets); -\& size_t SSL_CTX_get_num_tickets(const SSL_CTX *ctx); -\& int SSL_new_session_ticket(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_num_tickets()\fR and \fBSSL_set_num_tickets()\fR can be called for a server -application and set the number of TLSv1.3 session tickets that will be sent to -the client after a full handshake. Set the desired value (which could be 0) in -the \fBnum_tickets\fR argument. Typically these functions should be called before -the start of the handshake. -.PP -The default number of tickets is 2. Following a resumption the number of tickets -issued will never be more than 1 regardless of the value set via -\&\fBSSL_set_num_tickets()\fR or \fBSSL_CTX_set_num_tickets()\fR. If \fBnum_tickets\fR is set to -0 then no tickets will be issued for either a normal connection or a resumption. -.PP -Tickets are also issued on receipt of a post-handshake certificate from the -client following a request by the server using -\&\fBSSL_verify_client_post_handshake\fR\|(3). These new tickets will be associated -with the updated client identity (i.e. including their certificate and -verification status). The number of tickets issued will normally be the same as -was used for the initial handshake. If the initial handshake was a full -handshake then \fBSSL_set_num_tickets()\fR can be called again prior to calling -\&\fBSSL_verify_client_post_handshake()\fR to update the number of tickets that will be -sent. -.PP -To issue tickets after other events (such as application-layer changes), -\&\fBSSL_new_session_ticket()\fR is used by a server application to request that a new -ticket be sent when it is safe to do so. New tickets are only allowed to be -sent in this manner after the initial handshake has completed, and only for -\&\s-1TLS 1.3\s0 connections. By default, the ticket generation and transmission are -delayed until the server is starting a new write operation, so that it is -bundled with other application data being written and properly aligned to a -record boundary. If the connection was at a record boundary when -\&\fBSSL_new_session_ticket()\fR was called, the ticket can be sent immediately -(without waiting for the next application write) by calling -\&\fBSSL_do_handshake()\fR. \fBSSL_new_session_ticket()\fR can be called more than once to -request additional tickets be sent; all such requests are queued and written -together when it is safe to do so and triggered by \fBSSL_write()\fR or -\&\fBSSL_do_handshake()\fR. Note that a successful return from -\&\fBSSL_new_session_ticket()\fR indicates only that the request to send a ticket was -processed, not that the ticket itself was sent. To be notified when the -ticket itself is sent, a new-session callback can be registered with -\&\fBSSL_CTX_sess_set_new_cb\fR\|(3) that will be invoked as the ticket or tickets -are generated. -.PP -\&\fBSSL_CTX_get_num_tickets()\fR and \fBSSL_get_num_tickets()\fR return the number of -tickets set by a previous call to \fBSSL_CTX_set_num_tickets()\fR or -\&\fBSSL_set_num_tickets()\fR, or 2 if no such call has been made. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_num_tickets()\fR, \fBSSL_set_num_tickets()\fR, and -\&\fBSSL_new_session_ticket()\fR return 1 on success or 0 on failure. -.PP -\&\fBSSL_CTX_get_num_tickets()\fR and \fBSSL_get_num_tickets()\fR return the number of tickets -that have been previously set. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_new_session_ticket()\fR was added in OpenSSL 3.0.0. -\&\fBSSL_set_num_tickets()\fR, \fBSSL_get_num_tickets()\fR, \fBSSL_CTX_set_num_tickets()\fR, and -\&\fBSSL_CTX_get_num_tickets()\fR were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_options.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_options.3ossl deleted file mode 100644 index a544303e..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_options.3ossl +++ /dev/null @@ -1,627 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_OPTIONS 3ossl" -.TH SSL_CTX_SET_OPTIONS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_options, SSL_set_options, SSL_CTX_clear_options, -SSL_clear_options, SSL_CTX_get_options, SSL_get_options, -SSL_get_secure_renegotiation_support \- manipulate SSL options -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& uint64_t SSL_CTX_set_options(SSL_CTX *ctx, uint64_t options); -\& uint64_t SSL_set_options(SSL *ssl, uint64_t options); -\& -\& uint64_t SSL_CTX_clear_options(SSL_CTX *ctx, uint64_t options); -\& uint64_t SSL_clear_options(SSL *ssl, uint64_t options); -\& -\& uint64_t SSL_CTX_get_options(const SSL_CTX *ctx); -\& uint64_t SSL_get_options(const SSL *ssl); -\& -\& long SSL_get_secure_renegotiation_support(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_options()\fR adds the options set via bit-mask in \fBoptions\fR to \fBctx\fR. -Options already set before are not cleared! -.PP -\&\fBSSL_set_options()\fR adds the options set via bit-mask in \fBoptions\fR to \fBssl\fR. -Options already set before are not cleared! -.PP -\&\fBSSL_CTX_clear_options()\fR clears the options set via bit-mask in \fBoptions\fR -to \fBctx\fR. -.PP -\&\fBSSL_clear_options()\fR clears the options set via bit-mask in \fBoptions\fR to \fBssl\fR. -.PP -\&\fBSSL_CTX_get_options()\fR returns the options set for \fBctx\fR. -.PP -\&\fBSSL_get_options()\fR returns the options set for \fBssl\fR. -.PP -\&\fBSSL_get_secure_renegotiation_support()\fR indicates whether the peer supports -secure renegotiation. -Note, this is implemented via a macro. -.SH "NOTES" -.IX Header "NOTES" -The behaviour of the \s-1SSL\s0 library can be changed by setting several options. -The options are coded as bit-masks and can be combined by a bitwise \fBor\fR -operation (|). -.PP -\&\fBSSL_CTX_set_options()\fR and \fBSSL_set_options()\fR affect the (external) -protocol behaviour of the \s-1SSL\s0 library. The (internal) behaviour of -the \s-1API\s0 can be changed by using the similar -\&\fBSSL_CTX_set_mode\fR\|(3) and \fBSSL_set_mode()\fR functions. -.PP -During a handshake, the option settings of the \s-1SSL\s0 object are used. When -a new \s-1SSL\s0 object is created from a context using \fBSSL_new()\fR, the current -option setting is copied. Changes to \fBctx\fR do not affect already created -\&\s-1SSL\s0 objects. \fBSSL_clear()\fR does not affect the settings. -.PP -The following \fBbug workaround\fR options are available: -.IP "\s-1SSL_OP_CRYPTOPRO_TLSEXT_BUG\s0" 4 -.IX Item "SSL_OP_CRYPTOPRO_TLSEXT_BUG" -Add server-hello extension from the early version of cryptopro draft -when \s-1GOST\s0 ciphersuite is negotiated. Required for interoperability with CryptoPro -\&\s-1CSP 3\s0.x. -.IP "\s-1SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS\s0" 4 -.IX Item "SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS" -Disables a countermeasure against a \s-1SSL 3.0/TLS 1.0\s0 protocol -vulnerability affecting \s-1CBC\s0 ciphers, which cannot be handled by some -broken \s-1SSL\s0 implementations. This option has no effect for connections -using other ciphers. -.IP "\s-1SSL_OP_SAFARI_ECDHE_ECDSA_BUG\s0" 4 -.IX Item "SSL_OP_SAFARI_ECDHE_ECDSA_BUG" -Don't prefer ECDHE-ECDSA ciphers when the client appears to be Safari on \s-1OS X. -OS X 10.8..10.8.3\s0 has broken support for ECDHE-ECDSA ciphers. -.IP "\s-1SSL_OP_TLSEXT_PADDING\s0" 4 -.IX Item "SSL_OP_TLSEXT_PADDING" -Adds a padding extension to ensure the ClientHello size is never between -256 and 511 bytes in length. This is needed as a workaround for some -implementations. -.IP "\s-1SSL_OP_ALL\s0" 4 -.IX Item "SSL_OP_ALL" -All of the above bug workarounds. -.PP -It is usually safe to use \fB\s-1SSL_OP_ALL\s0\fR to enable the bug workaround -options if compatibility with somewhat broken implementations is -desired. -.PP -The following \fBmodifying\fR options are available: -.IP "\s-1SSL_OP_ALLOW_CLIENT_RENEGOTIATION\s0" 4 -.IX Item "SSL_OP_ALLOW_CLIENT_RENEGOTIATION" -Client-initiated renegotiation is disabled by default. Use -this option to enable it. -.IP "\s-1SSL_OP_ALLOW_NO_DHE_KEX\s0" 4 -.IX Item "SSL_OP_ALLOW_NO_DHE_KEX" -In TLSv1.3 allow a non\-(ec)dhe based key exchange mode on resumption. This means -that there will be no forward secrecy for the resumed session. -.IP "\s-1SSL_OP_PREFER_NO_DHE_KEX\s0" 4 -.IX Item "SSL_OP_PREFER_NO_DHE_KEX" -In TLSv1.3, on resumption let the server prefer a non\-(ec)dhe based key -exchange mode over an (ec)dhe based one. Ignored without \fB\s-1SSL_OP_ALLOW_NO_DHE_KEX\s0\fR -being set as well. Always ignored on the client. -.IP "\s-1SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION\s0" 4 -.IX Item "SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION" -Allow legacy insecure renegotiation between OpenSSL and unpatched clients or -servers. See the \fB\s-1SECURE RENEGOTIATION\s0\fR section for more details. -.IP "\s-1SSL_OP_CIPHER_SERVER_PREFERENCE\s0" 4 -.IX Item "SSL_OP_CIPHER_SERVER_PREFERENCE" -When choosing a cipher, use the server's preferences instead of the client -preferences. When not set, the \s-1SSL\s0 server will always follow the clients -preferences. When set, the \s-1SSL/TLS\s0 server will choose following its -own preferences. -.IP "\s-1SSL_OP_CISCO_ANYCONNECT\s0" 4 -.IX Item "SSL_OP_CISCO_ANYCONNECT" -Use Cisco's version identifier of \s-1DTLS_BAD_VER\s0 when establishing a DTLSv1 -connection. Only available when using the deprecated \fBDTLSv1_client_method()\fR \s-1API.\s0 -.IP "\s-1SSL_OP_CLEANSE_PLAINTEXT\s0" 4 -.IX Item "SSL_OP_CLEANSE_PLAINTEXT" -By default \s-1TLS\s0 and \s-1QUIC SSL\s0 objects keep a copy of received plaintext -application data in a static buffer until it is overwritten by the -next portion of data. When enabling \s-1SSL_OP_CLEANSE_PLAINTEXT\s0 -deciphered application data is cleansed by calling \fBOPENSSL_cleanse\fR\|(3) -after passing data to the application. Data is also cleansed when -releasing the connection (e.g. \fBSSL_free\fR\|(3)). -.Sp -Since OpenSSL only cleanses internal buffers, the application is still -responsible for cleansing all other buffers. Most notably, this -applies to buffers passed to functions like \fBSSL_read\fR\|(3), -\&\fBSSL_peek\fR\|(3) but also like \fBSSL_write\fR\|(3). -.Sp -\&\s-1TLS\s0 connections do not buffer data to be sent in plaintext. \s-1QUIC\s0 stream -objects do buffer plaintext data to be sent and this option will also cause -that data to be cleansed when it is discarded. -.Sp -This option can be set differently on individual \s-1QUIC\s0 stream objects and -has no effect on \s-1QUIC\s0 connection objects (except where a default stream is -being used). -.IP "\s-1SSL_OP_COOKIE_EXCHANGE\s0" 4 -.IX Item "SSL_OP_COOKIE_EXCHANGE" -Turn on Cookie Exchange as described in \s-1RFC4347\s0 Section 4.2.1. Only affects -\&\s-1DTLS\s0 connections. -.IP "\s-1SSL_OP_DISABLE_TLSEXT_CA_NAMES\s0" 4 -.IX Item "SSL_OP_DISABLE_TLSEXT_CA_NAMES" -Disable \s-1TLS\s0 Extension \s-1CA\s0 Names. You may want to disable it for security reasons -or for compatibility with some Windows \s-1TLS\s0 implementations crashing when this -extension is larger than 1024 bytes. -.IP "\s-1SSL_OP_ENABLE_KTLS\s0" 4 -.IX Item "SSL_OP_ENABLE_KTLS" -Enable the use of kernel \s-1TLS.\s0 In order to benefit from kernel \s-1TLS\s0 OpenSSL must -have been compiled with support for it, and it must be supported by the -negotiated ciphersuites and extensions. The specific ciphersuites and extensions -that are supported may vary by platform and kernel version. -.Sp -The kernel \s-1TLS\s0 data-path implements the record layer, and the encryption -algorithm. The kernel will utilize the best hardware -available for encryption. Using the kernel data-path should reduce the memory -footprint of OpenSSL because no buffering is required. Also, the throughput -should improve because data copy is avoided when user data is encrypted into -kernel memory instead of the usual encrypt then copy to kernel. -.Sp -Kernel \s-1TLS\s0 might not support all the features of OpenSSL. For instance, -renegotiation, and setting the maximum fragment size is not possible as of -Linux 4.20. -.Sp -Note that with kernel \s-1TLS\s0 enabled some cryptographic operations are performed -by the kernel directly and not via any available OpenSSL Providers. This might -be undesirable if, for example, the application requires all cryptographic -operations to be performed by the \s-1FIPS\s0 provider. -.IP "\s-1SSL_OP_ENABLE_KTLS_TX_ZEROCOPY_SENDFILE\s0" 4 -.IX Item "SSL_OP_ENABLE_KTLS_TX_ZEROCOPY_SENDFILE" -With this option, \fBsendfile()\fR will use the zerocopy mode, which gives a -performance boost when used with \s-1KTLS\s0 hardware offload. Note that invalid \s-1TLS\s0 -records might be transmitted if the file is changed while being sent. This -option has no effect if \fB\s-1SSL_OP_ENABLE_KTLS\s0\fR is not enabled. -.Sp -This option only applies to Linux. \s-1KTLS\s0 sendfile on FreeBSD doesn't offer an -option to disable zerocopy and always runs in this mode. -.IP "\s-1SSL_OP_ENABLE_MIDDLEBOX_COMPAT\s0" 4 -.IX Item "SSL_OP_ENABLE_MIDDLEBOX_COMPAT" -If set then dummy Change Cipher Spec (\s-1CCS\s0) messages are sent in TLSv1.3. This -has the effect of making TLSv1.3 look more like TLSv1.2 so that middleboxes that -do not understand TLSv1.3 will not drop the connection. Regardless of whether -this option is set or not \s-1CCS\s0 messages received from the peer will always be -ignored in TLSv1.3. This option is set by default. To switch it off use -\&\fBSSL_clear_options()\fR. A future version of OpenSSL may not set this by default. -.IP "\s-1SSL_OP_IGNORE_UNEXPECTED_EOF\s0" 4 -.IX Item "SSL_OP_IGNORE_UNEXPECTED_EOF" -Some \s-1TLS\s0 implementations do not send the mandatory close_notify alert on -shutdown. If the application tries to wait for the close_notify alert but the -peer closes the connection without sending it, an error is generated. When this -option is enabled the peer does not need to send the close_notify alert and a -closed connection will be treated as if the close_notify alert was received. -.Sp -You should only enable this option if the protocol running over \s-1TLS\s0 -can detect a truncation attack itself, and that the application is checking for -that truncation attack. -.Sp -For more information on shutting down a connection, see \fBSSL_shutdown\fR\|(3). -.IP "\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0" 4 -.IX Item "SSL_OP_LEGACY_SERVER_CONNECT" -Allow legacy insecure renegotiation between OpenSSL and unpatched servers -\&\fBonly\fR. See the \fB\s-1SECURE RENEGOTIATION\s0\fR section for more details. -.IP "\s-1SSL_OP_NO_ANTI_REPLAY\s0" 4 -.IX Item "SSL_OP_NO_ANTI_REPLAY" -By default, when a server is configured for early data (i.e., max_early_data > 0), -OpenSSL will switch on replay protection. See \fBSSL_read_early_data\fR\|(3) for a -description of the replay protection feature. Anti-replay measures are required -to comply with the TLSv1.3 specification. Some applications may be able to -mitigate the replay risks in other ways and in such cases the built in OpenSSL -functionality is not required. Those applications can turn this feature off by -setting this option. This is a server-side option only. It is ignored by -clients. -.IP "\s-1SSL_OP_NO_TX_CERTIFICATE_COMPRESSION\s0" 4 -.IX Item "SSL_OP_NO_TX_CERTIFICATE_COMPRESSION" -Normally clients and servers will transparently attempt to negotiate the -\&\s-1RFC8879\s0 certificate compression option on TLSv1.3 connections. -.Sp -If this option is set, the certificate compression extension is ignored -upon receipt and compressed certificates will not be sent to the peer. -.IP "\s-1SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\s0" 4 -.IX Item "SSL_OP_NO_RX_CERTIFICATE_COMPRESSION" -Normally clients and servers will transparently attempt to negotiate the -\&\s-1RFC8879\s0 certificate compression option on TLSv1.3 connections. -.Sp -If this option is set, the certificate compression extension will not be sent -and compressed certificates will not be accepted from the peer. -.IP "\s-1SSL_OP_NO_COMPRESSION\s0" 4 -.IX Item "SSL_OP_NO_COMPRESSION" -Do not use \s-1TLS\s0 record compression even if it is supported. This option is set by -default. To switch it off use \fBSSL_clear_options()\fR. Note that \s-1TLS\s0 record -compression is not recommended and is not available at security level 2 or -above. From OpenSSL 3.2 the default security level is 2, so clearing this option -will have no effect without also changing the default security level. See -\&\fBSSL_CTX_set_security_level\fR\|(3). -.IP "\s-1SSL_OP_NO_ENCRYPT_THEN_MAC\s0" 4 -.IX Item "SSL_OP_NO_ENCRYPT_THEN_MAC" -Normally clients and servers will transparently attempt to negotiate the -\&\s-1RFC7366\s0 Encrypt-then-MAC option on \s-1TLS\s0 and \s-1DTLS\s0 connection. -.Sp -If this option is set, Encrypt-then-MAC is disabled. Clients will not -propose, and servers will not accept the extension. -.IP "\s-1SSL_OP_NO_EXTENDED_MASTER_SECRET\s0" 4 -.IX Item "SSL_OP_NO_EXTENDED_MASTER_SECRET" -Normally clients and servers will transparently attempt to negotiate the -\&\s-1RFC7627\s0 Extended Master Secret option on \s-1TLS\s0 and \s-1DTLS\s0 connection. -.Sp -If this option is set, Extended Master Secret is disabled. Clients will -not propose, and servers will not accept the extension. -.IP "\s-1SSL_OP_NO_QUERY_MTU\s0" 4 -.IX Item "SSL_OP_NO_QUERY_MTU" -Do not query the \s-1MTU.\s0 Only affects \s-1DTLS\s0 connections. -.IP "\s-1SSL_OP_NO_RENEGOTIATION\s0" 4 -.IX Item "SSL_OP_NO_RENEGOTIATION" -Disable all renegotiation in (D)TLSv1.2 and earlier. Do not send HelloRequest -messages, and ignore renegotiation requests via ClientHello. -.IP "\s-1SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION\s0" 4 -.IX Item "SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION" -When performing renegotiation as a server, always start a new session -(i.e., session resumption requests are only accepted in the initial -handshake). This option is not needed for clients. -.IP "SSL_OP_NO_SSLv3, SSL_OP_NO_TLSv1, SSL_OP_NO_TLSv1_1, SSL_OP_NO_TLSv1_2, SSL_OP_NO_TLSv1_3, SSL_OP_NO_DTLSv1, SSL_OP_NO_DTLSv1_2" 4 -.IX Item "SSL_OP_NO_SSLv3, SSL_OP_NO_TLSv1, SSL_OP_NO_TLSv1_1, SSL_OP_NO_TLSv1_2, SSL_OP_NO_TLSv1_3, SSL_OP_NO_DTLSv1, SSL_OP_NO_DTLSv1_2" -These options turn off the SSLv3, TLSv1, TLSv1.1, TLSv1.2 or TLSv1.3 protocol -versions with \s-1TLS\s0 or the DTLSv1, DTLSv1.2 versions with \s-1DTLS,\s0 -respectively. -As of OpenSSL 1.1.0, these options are deprecated, use -\&\fBSSL_CTX_set_min_proto_version\fR\|(3) and -\&\fBSSL_CTX_set_max_proto_version\fR\|(3) instead. -.IP "\s-1SSL_OP_NO_TICKET\s0" 4 -.IX Item "SSL_OP_NO_TICKET" -\&\s-1SSL/TLS\s0 supports two mechanisms for resuming sessions: session ids and stateless -session tickets. -.Sp -When using session ids a copy of the session information is -cached on the server and a unique id is sent to the client. When the client -wishes to resume it provides the unique id so that the server can retrieve the -session information from its cache. -.Sp -When using stateless session tickets the server uses a session ticket encryption -key to encrypt the session information. This encrypted data is sent to the -client as a \*(L"ticket\*(R". When the client wishes to resume it sends the encrypted -data back to the server. The server uses its key to decrypt the data and resume -the session. In this way the server can operate statelessly \- no session -information needs to be cached locally. -.Sp -The TLSv1.3 protocol only supports tickets and does not directly support session -ids. However, OpenSSL allows two modes of ticket operation in TLSv1.3: stateful -and stateless. Stateless tickets work the same way as in TLSv1.2 and below. -Stateful tickets mimic the session id behaviour available in TLSv1.2 and below. -The session information is cached on the server and the session id is wrapped up -in a ticket and sent back to the client. When the client wishes to resume, it -presents a ticket in the same way as for stateless tickets. The server can then -extract the session id from the ticket and retrieve the session information from -its cache. -.Sp -By default OpenSSL will use stateless tickets. The \s-1SSL_OP_NO_TICKET\s0 option will -cause stateless tickets to not be issued. In TLSv1.2 and below this means no -ticket gets sent to the client at all. In TLSv1.3 a stateful ticket will be -sent. This is a server-side option only. -.Sp -In TLSv1.3 it is possible to suppress all tickets (stateful and stateless) from -being sent by calling \fBSSL_CTX_set_num_tickets\fR\|(3) or -\&\fBSSL_set_num_tickets\fR\|(3). -.IP "\s-1SSL_OP_PRIORITIZE_CHACHA\s0" 4 -.IX Item "SSL_OP_PRIORITIZE_CHACHA" -When \s-1SSL_OP_CIPHER_SERVER_PREFERENCE\s0 is set, temporarily reprioritize -ChaCha20\-Poly1305 ciphers to the top of the server cipher list if a -ChaCha20\-Poly1305 cipher is at the top of the client cipher list. This helps -those clients (e.g. mobile) use ChaCha20\-Poly1305 if that cipher is anywhere -in the server cipher list; but still allows other clients to use \s-1AES\s0 and other -ciphers. Requires \fB\s-1SSL_OP_CIPHER_SERVER_PREFERENCE\s0\fR. -.IP "\s-1SSL_OP_TLS_ROLLBACK_BUG\s0" 4 -.IX Item "SSL_OP_TLS_ROLLBACK_BUG" -Disable version rollback attack detection. -.Sp -During the client key exchange, the client must send the same information -about acceptable \s-1SSL/TLS\s0 protocol levels as during the first hello. Some -clients violate this rule by adapting to the server's answer. (Example: -the client sends a SSLv2 hello and accepts up to SSLv3.1=TLSv1, the server -only understands up to SSLv3. In this case the client must still use the -same SSLv3.1=TLSv1 announcement. Some clients step down to SSLv3 with respect -to the server's answer and violate the version rollback protection.) -.PP -The following options no longer have any effect but their identifiers are -retained for compatibility purposes: -.IP "\s-1SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG\s0" 4 -.IX Item "SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG" -.PD 0 -.IP "\s-1SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER\s0" 4 -.IX Item "SSL_OP_MICROSOFT_BIG_SSLV3_BUFFER" -.IP "\s-1SSL_OP_SSLEAY_080_CLIENT_DH_BUG\s0" 4 -.IX Item "SSL_OP_SSLEAY_080_CLIENT_DH_BUG" -.IP "\s-1SSL_OP_TLS_D5_BUG\s0" 4 -.IX Item "SSL_OP_TLS_D5_BUG" -.IP "\s-1SSL_OP_TLS_BLOCK_PADDING_BUG\s0" 4 -.IX Item "SSL_OP_TLS_BLOCK_PADDING_BUG" -.IP "\s-1SSL_OP_MSIE_SSLV2_RSA_PADDING\s0" 4 -.IX Item "SSL_OP_MSIE_SSLV2_RSA_PADDING" -.IP "\s-1SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG\s0" 4 -.IX Item "SSL_OP_SSLREF2_REUSE_CERT_TYPE_BUG" -.IP "\s-1SSL_OP_MICROSOFT_SESS_ID_BUG\s0" 4 -.IX Item "SSL_OP_MICROSOFT_SESS_ID_BUG" -.IP "\s-1SSL_OP_NETSCAPE_CHALLENGE_BUG\s0" 4 -.IX Item "SSL_OP_NETSCAPE_CHALLENGE_BUG" -.IP "\s-1SSL_OP_PKCS1_CHECK_1\s0" 4 -.IX Item "SSL_OP_PKCS1_CHECK_1" -.IP "\s-1SSL_OP_PKCS1_CHECK_2\s0" 4 -.IX Item "SSL_OP_PKCS1_CHECK_2" -.IP "\s-1SSL_OP_SINGLE_DH_USE\s0" 4 -.IX Item "SSL_OP_SINGLE_DH_USE" -.IP "\s-1SSL_OP_SINGLE_ECDH_USE\s0" 4 -.IX Item "SSL_OP_SINGLE_ECDH_USE" -.IP "\s-1SSL_OP_EPHEMERAL_RSA\s0" 4 -.IX Item "SSL_OP_EPHEMERAL_RSA" -.IP "\s-1SSL_OP_NETSCAPE_CA_DN_BUG\s0" 4 -.IX Item "SSL_OP_NETSCAPE_CA_DN_BUG" -.IP "\s-1SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG\s0" 4 -.IX Item "SSL_OP_NETSCAPE_DEMO_CIPHER_CHANGE_BUG" -.PD -.SH "SECURE RENEGOTIATION" -.IX Header "SECURE RENEGOTIATION" -OpenSSL always attempts to use secure renegotiation as -described in \s-1RFC5746.\s0 This counters the prefix attack described in -\&\s-1CVE\-2009\-3555\s0 and elsewhere. -.PP -This attack has far reaching consequences which application writers should be -aware of. In the description below an implementation supporting secure -renegotiation is referred to as \fIpatched\fR. A server not supporting secure -renegotiation is referred to as \fIunpatched\fR. -.PP -The following sections describe the operations permitted by OpenSSL's secure -renegotiation implementation. -.SS "Patched client and server" -.IX Subsection "Patched client and server" -Connections and renegotiation are always permitted by OpenSSL implementations. -.SS "Unpatched client and patched OpenSSL server" -.IX Subsection "Unpatched client and patched OpenSSL server" -The initial connection succeeds but client renegotiation is denied by the -server with a \fBno_renegotiation\fR warning alert if \s-1TLS\s0 v1.0 is used or a fatal -\&\fBhandshake_failure\fR alert in \s-1SSL\s0 v3.0. -.PP -If the patched OpenSSL server attempts to renegotiate a fatal -\&\fBhandshake_failure\fR alert is sent. This is because the server code may be -unaware of the unpatched nature of the client. -.PP -If the option \fB\s-1SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION\s0\fR is set then -renegotiation \fBalways\fR succeeds. -.SS "Patched OpenSSL client and unpatched server" -.IX Subsection "Patched OpenSSL client and unpatched server" -If the option \fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR or -\&\fB\s-1SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION\s0\fR is set then initial connections -and renegotiation between patched OpenSSL clients and unpatched servers -succeeds. If neither option is set then initial connections to unpatched -servers will fail. -.PP -Setting the option \fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR has security implications; -clients that are willing to connect to servers that do not implement -\&\s-1RFC 5746\s0 secure renegotiation are subject to attacks such as -\&\s-1CVE\-2009\-3555.\s0 -.PP -OpenSSL client applications wishing to ensure they can connect to unpatched -servers should always \fBset\fR \fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR -.PP -OpenSSL client applications that want to ensure they can \fBnot\fR connect to -unpatched servers (and thus avoid any security issues) should always \fBclear\fR -\&\fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR using \fBSSL_CTX_clear_options()\fR or -\&\fBSSL_clear_options()\fR. -.PP -The difference between the \fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR and -\&\fB\s-1SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION\s0\fR options is that -\&\fB\s-1SSL_OP_LEGACY_SERVER_CONNECT\s0\fR enables initial connections and secure -renegotiation between OpenSSL clients and unpatched servers \fBonly\fR, while -\&\fB\s-1SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION\s0\fR allows initial connections -and renegotiation between OpenSSL and unpatched clients or servers. -.SS "Applicability of options to \s-1QUIC\s0 connections and streams" -.IX Subsection "Applicability of options to QUIC connections and streams" -These options apply to \s-1SSL\s0 objects referencing a \s-1QUIC\s0 connection: -.IP "\s-1SSL_OP_ALLOW_NO_DHE_KEX\s0" 4 -.IX Item "SSL_OP_ALLOW_NO_DHE_KEX" -.PD 0 -.IP "\s-1SSL_OP_NO_TX_CERTIFICATE_COMPRESSION\s0" 4 -.IX Item "SSL_OP_NO_TX_CERTIFICATE_COMPRESSION" -.IP "\s-1SSL_OP_NO_RX_CERTIFICATE_COMPRESSION\s0" 4 -.IX Item "SSL_OP_NO_RX_CERTIFICATE_COMPRESSION" -.IP "\s-1SSL_OP_NO_TICKET\s0" 4 -.IX Item "SSL_OP_NO_TICKET" -.IP "\s-1SSL_OP_PRIORITIZE_CHACHA\s0" 4 -.IX Item "SSL_OP_PRIORITIZE_CHACHA" -.PD -.PP -These options apply to \s-1SSL\s0 objects referencing a \s-1QUIC\s0 stream: -.IP "\s-1SSL_OP_CLEANSE_PLAINTEXT\s0" 4 -.IX Item "SSL_OP_CLEANSE_PLAINTEXT" -.PP -Options on \s-1QUIC\s0 connections are initialized from the options set on \s-1SSL_CTX\s0 -before a \s-1QUIC\s0 connection \s-1SSL\s0 object is created. Options on \s-1QUIC\s0 streams are -initialised from the options configured on the \s-1QUIC\s0 connection \s-1SSL\s0 object -they are created from. -.PP -Setting options which relate to \s-1QUIC\s0 streams on a \s-1QUIC\s0 connection \s-1SSL\s0 object has -no direct effect on the \s-1QUIC\s0 connection \s-1SSL\s0 object itself, but will change the -options set on the default stream (if there is one) and will also determine the -default options set on any future streams which are created. -.PP -Other options not mentioned above do not have an effect and will be ignored. -.PP -Options which relate to \s-1QUIC\s0 streams may also be set directly on \s-1QUIC\s0 stream \s-1SSL\s0 -objects. Setting connection-related options on such an object has no effect. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_options()\fR and \fBSSL_set_options()\fR return the new options bit-mask -after adding \fBoptions\fR. -.PP -\&\fBSSL_CTX_clear_options()\fR and \fBSSL_clear_options()\fR return the new options bit-mask -after clearing \fBoptions\fR. -.PP -\&\fBSSL_CTX_get_options()\fR and \fBSSL_get_options()\fR return the current bit-mask. -.PP -\&\fBSSL_get_secure_renegotiation_support()\fR returns 1 is the peer supports -secure renegotiation and 0 if it does not. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3), \fBSSL_clear\fR\|(3), \fBSSL_shutdown\fR\|(3) -\&\fBSSL_CTX_set_tmp_dh_callback\fR\|(3), -\&\fBSSL_CTX_set_min_proto_version\fR\|(3), -\&\fBopenssl\-dhparam\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The attempt to always try to use secure renegotiation was added in -OpenSSL 0.9.8m. -.PP -The \fB\s-1SSL_OP_PRIORITIZE_CHACHA\s0\fR and \fB\s-1SSL_OP_NO_RENEGOTIATION\s0\fR options -were added in OpenSSL 1.1.1. -.PP -The \fB\s-1SSL_OP_NO_EXTENDED_MASTER_SECRET\s0\fR and \fB\s-1SSL_OP_IGNORE_UNEXPECTED_EOF\s0\fR -options were added in OpenSSL 3.0. -.PP -The \fB\s-1SSL_OP_\s0\fR constants and the corresponding parameter and return values -of the affected functions were changed to \f(CW\*(C`uint64_t\*(C'\fR type in OpenSSL 3.0. -For that reason it is no longer possible use the \fB\s-1SSL_OP_\s0\fR macro values -in preprocessor \f(CW\*(C`#if\*(C'\fR conditions. However it is still possible to test -whether these macros are defined or not. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_post_handshake_auth.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_post_handshake_auth.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_post_handshake_auth.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_psk_client_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_psk_client_callback.3ossl deleted file mode 100644 index cf739fcc..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_psk_client_callback.3ossl +++ /dev/null @@ -1,301 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_PSK_CLIENT_CALLBACK 3ossl" -.TH SSL_CTX_SET_PSK_CLIENT_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_psk_client_cb_func, -SSL_psk_use_session_cb_func, -SSL_CTX_set_psk_client_callback, -SSL_set_psk_client_callback, -SSL_CTX_set_psk_use_session_callback, -SSL_set_psk_use_session_callback -\&\- set PSK client callback -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*SSL_psk_use_session_cb_func)(SSL *ssl, const EVP_MD *md, -\& const unsigned char **id, -\& size_t *idlen, -\& SSL_SESSION **sess); -\& -\& -\& void SSL_CTX_set_psk_use_session_callback(SSL_CTX *ctx, -\& SSL_psk_use_session_cb_func cb); -\& void SSL_set_psk_use_session_callback(SSL *s, SSL_psk_use_session_cb_func cb); -\& -\& -\& typedef unsigned int (*SSL_psk_client_cb_func)(SSL *ssl, -\& const char *hint, -\& char *identity, -\& unsigned int max_identity_len, -\& unsigned char *psk, -\& unsigned int max_psk_len); -\& -\& void SSL_CTX_set_psk_client_callback(SSL_CTX *ctx, SSL_psk_client_cb_func cb); -\& void SSL_set_psk_client_callback(SSL *ssl, SSL_psk_client_cb_func cb); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A client application wishing to use TLSv1.3 PSKs should use either -\&\fBSSL_CTX_set_psk_use_session_callback()\fR or \fBSSL_set_psk_use_session_callback()\fR as -appropriate. These functions cannot be used for TLSv1.2 and below PSKs. -.PP -The callback function is given a pointer to the \s-1SSL\s0 connection in \fBssl\fR. -.PP -The first time the callback is called for a connection the \fBmd\fR parameter is -\&\s-1NULL.\s0 In some circumstances the callback will be called a second time. In that -case the server will have specified a ciphersuite to use already and the \s-1PSK\s0 -must be compatible with the digest for that ciphersuite. The digest will be -given in \fBmd\fR. The \s-1PSK\s0 returned by the callback is allowed to be different -between the first and second time it is called. -.PP -On successful completion the callback must store a pointer to an identifier for -the \s-1PSK\s0 in \fB*id\fR. The identifier length in bytes should be stored in \fB*idlen\fR. -The memory pointed to by \fB*id\fR remains owned by the application and should -be freed by it as required at any point after the handshake is complete. -.PP -Additionally the callback should store a pointer to an \s-1SSL_SESSION\s0 object in -\&\fB*sess\fR. This is used as the basis for the \s-1PSK,\s0 and should, at a minimum, have -the following fields set: -.IP "The master key" 4 -.IX Item "The master key" -This can be set via a call to \fBSSL_SESSION_set1_master_key\fR\|(3). -.IP "A ciphersuite" 4 -.IX Item "A ciphersuite" -Only the handshake digest associated with the ciphersuite is relevant for the -\&\s-1PSK\s0 (the server may go on to negotiate any ciphersuite which is compatible with -the digest). The application can use any TLSv1.3 ciphersuite. If \fBmd\fR is -not \s-1NULL\s0 the handshake digest for the ciphersuite should be the same. -The ciphersuite can be set via a call to <\fBSSL_SESSION_set_cipher\fR\|(3)>. The -handshake digest of an \s-1SSL_CIPHER\s0 object can be checked using -<\fBSSL_CIPHER_get_handshake_digest\fR\|(3)>. -.IP "The protocol version" 4 -.IX Item "The protocol version" -This can be set via a call to \fBSSL_SESSION_set_protocol_version\fR\|(3) and should -be \s-1TLS1_3_VERSION.\s0 -.PP -Additionally the maximum early data value should be set via a call to -\&\fBSSL_SESSION_set_max_early_data\fR\|(3) if the \s-1PSK\s0 will be used for sending early -data. -.PP -Alternatively an \s-1SSL_SESSION\s0 created from a previous non-PSK handshake may also -be used as the basis for a \s-1PSK.\s0 -.PP -Ownership of the \s-1SSL_SESSION\s0 object is passed to the OpenSSL library and so it -should not be freed by the application. -.PP -It is also possible for the callback to succeed but not supply a \s-1PSK.\s0 In this -case no \s-1PSK\s0 will be sent to the server but the handshake will continue. To do -this the callback should return successfully and ensure that \fB*sess\fR is -\&\s-1NULL.\s0 The contents of \fB*id\fR and \fB*idlen\fR will be ignored. -.PP -A client application wishing to use \s-1PSK\s0 ciphersuites for TLSv1.2 and below must -provide a different callback function. This function will be called when the -client is sending the ClientKeyExchange message to the server. -.PP -The purpose of the callback function is to select the \s-1PSK\s0 identity and -the pre-shared key to use during the connection setup phase. -.PP -The callback is set using functions \fBSSL_CTX_set_psk_client_callback()\fR -or \fBSSL_set_psk_client_callback()\fR. The callback function is given the -connection in parameter \fBssl\fR, a \fB\s-1NUL\s0\fR\-terminated \s-1PSK\s0 identity hint -sent by the server in parameter \fBhint\fR, a buffer \fBidentity\fR of -length \fBmax_identity_len\fR bytes (including the \fB\s-1NUL\s0\fR\-terminator) where the -resulting \fB\s-1NUL\s0\fR\-terminated identity is to be stored, and a buffer \fBpsk\fR -of length \fBmax_psk_len\fR bytes where the resulting pre-shared key is to -be stored. -.PP -The callback for use in TLSv1.2 will also work in TLSv1.3 although it is -recommended to use \fBSSL_CTX_set_psk_use_session_callback()\fR -or \fBSSL_set_psk_use_session_callback()\fR for this purpose instead. If TLSv1.3 has -been negotiated then OpenSSL will first check to see if a callback has been set -via \fBSSL_CTX_set_psk_use_session_callback()\fR or \fBSSL_set_psk_use_session_callback()\fR -and it will use that in preference. If no such callback is present then it will -check to see if a callback has been set via \fBSSL_CTX_set_psk_client_callback()\fR or -\&\fBSSL_set_psk_client_callback()\fR and use that. In this case the \fBhint\fR value will -always be \s-1NULL\s0 and the handshake digest will default to \s-1SHA\-256\s0 for any returned -\&\s-1PSK.\s0 TLSv1.3 early data exchanges are possible in \s-1PSK\s0 connections only with the -\&\fBSSL_psk_use_session_cb_func\fR callback, and are not possible with the -\&\fBSSL_psk_client_cb_func\fR callback. -.SH "NOTES" -.IX Header "NOTES" -Note that parameter \fBhint\fR given to the callback may be \fB\s-1NULL\s0\fR. -.PP -A connection established via a TLSv1.3 \s-1PSK\s0 will appear as if session resumption -has occurred so that \fBSSL_session_reused\fR\|(3) will return true. -.PP -There are no known security issues with sharing the same \s-1PSK\s0 between TLSv1.2 (or -below) and TLSv1.3. However, the \s-1RFC\s0 has this note of caution: -.PP -\&\*(L"While there is no known way in which the same \s-1PSK\s0 might produce related output -in both versions, only limited analysis has been done. Implementations can -ensure safety from cross-protocol related output by not reusing PSKs between -\&\s-1TLS 1.3\s0 and \s-1TLS 1.2.\*(R"\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Return values from the \fBSSL_psk_client_cb_func\fR callback are interpreted as -follows: -.PP -On success (callback found a \s-1PSK\s0 identity and a pre-shared key to use) -the length (> 0) of \fBpsk\fR in bytes is returned. -.PP -Otherwise or on errors the callback should return 0. In this case -the connection setup fails. -.PP -The SSL_psk_use_session_cb_func callback should return 1 on success or 0 on -failure. In the event of failure the connection setup fails. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_psk_find_session_callback\fR\|(3), -\&\fBSSL_set_psk_find_session_callback\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_CTX_set_psk_use_session_callback()\fR and \fBSSL_set_psk_use_session_callback()\fR -were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_psk_find_session_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_psk_find_session_callback.3ossl deleted file mode 120000 index 205e7e3e..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_psk_find_session_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_psk_identity_hint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_psk_server_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_psk_server_callback.3ossl deleted file mode 120000 index 205e7e3e..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_psk_server_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_psk_identity_hint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_psk_use_session_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_psk_use_session_callback.3ossl deleted file mode 120000 index da6a3a7b..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_psk_use_session_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_psk_client_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_purpose.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_purpose.3ossl deleted file mode 120000 index fd781e23..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_purpose.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_quiet_shutdown.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_quiet_shutdown.3ossl deleted file mode 100644 index 5e80bac5..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_quiet_shutdown.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_QUIET_SHUTDOWN 3ossl" -.TH SSL_CTX_SET_QUIET_SHUTDOWN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_quiet_shutdown, SSL_CTX_get_quiet_shutdown, SSL_set_quiet_shutdown, -SSL_get_quiet_shutdown \- manipulate shutdown behaviour -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_quiet_shutdown(SSL_CTX *ctx, int mode); -\& int SSL_CTX_get_quiet_shutdown(const SSL_CTX *ctx); -\& -\& void SSL_set_quiet_shutdown(SSL *ssl, int mode); -\& int SSL_get_quiet_shutdown(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_quiet_shutdown()\fR sets the \*(L"quiet shutdown\*(R" flag for \fBctx\fR to be -\&\fBmode\fR. \s-1SSL\s0 objects created from \fBctx\fR inherit the \fBmode\fR valid at the time -\&\fBSSL_new\fR\|(3) is called. \fBmode\fR may be 0 or 1. -.PP -\&\fBSSL_CTX_get_quiet_shutdown()\fR returns the \*(L"quiet shutdown\*(R" setting of \fBctx\fR. -.PP -\&\fBSSL_set_quiet_shutdown()\fR sets the \*(L"quiet shutdown\*(R" flag for \fBssl\fR to be -\&\fBmode\fR. The setting stays valid until \fBssl\fR is removed with -\&\fBSSL_free\fR\|(3) or \fBSSL_set_quiet_shutdown()\fR is called again. -It is not changed when \fBSSL_clear\fR\|(3) is called. -\&\fBmode\fR may be 0 or 1. -.PP -\&\fBSSL_get_quiet_shutdown()\fR returns the \*(L"quiet shutdown\*(R" setting of \fBssl\fR. -.PP -These functions are not supported for \s-1QUIC SSL\s0 objects. \fBSSL_set_quiet_shutdown()\fR -has no effect if called on a \s-1QUIC SSL\s0 object. -.SH "NOTES" -.IX Header "NOTES" -Normally when a \s-1SSL\s0 connection is finished, the parties must send out -close_notify alert messages using \fBSSL_shutdown\fR\|(3) -for a clean shutdown. -.PP -When setting the \*(L"quiet shutdown\*(R" flag to 1, \fBSSL_shutdown\fR\|(3) -will set the internal flags to SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN. -(\fBSSL_shutdown\fR\|(3) then behaves like -\&\fBSSL_set_shutdown\fR\|(3) called with -SSL_SENT_SHUTDOWN|SSL_RECEIVED_SHUTDOWN.) -The session is thus considered to be shutdown, but no close_notify alert -is sent to the peer. This behaviour violates the \s-1TLS\s0 standard. -.PP -The default is normal shutdown behaviour as described by the \s-1TLS\s0 standard. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_quiet_shutdown()\fR and \fBSSL_set_quiet_shutdown()\fR do not return -diagnostic information. -.PP -\&\fBSSL_CTX_get_quiet_shutdown()\fR and \fBSSL_get_quiet_shutdown()\fR return the current -setting. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_shutdown\fR\|(3), -\&\fBSSL_set_shutdown\fR\|(3), \fBSSL_new\fR\|(3), -\&\fBSSL_clear\fR\|(3), \fBSSL_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_read_ahead.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_read_ahead.3ossl deleted file mode 100644 index b8e550b6..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_read_ahead.3ossl +++ /dev/null @@ -1,208 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_READ_AHEAD 3ossl" -.TH SSL_CTX_SET_READ_AHEAD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_read_ahead, SSL_CTX_get_read_ahead, -SSL_set_read_ahead, SSL_get_read_ahead, -SSL_CTX_get_default_read_ahead -\&\- manage whether to read as many input bytes as possible -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_set_read_ahead(SSL *s, int yes); -\& int SSL_get_read_ahead(const SSL *s); -\& -\& SSL_CTX_set_read_ahead(SSL_CTX *ctx, int yes); -\& long SSL_CTX_get_read_ahead(SSL_CTX *ctx); -\& long SSL_CTX_get_default_read_ahead(SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_read_ahead()\fR and \fBSSL_set_read_ahead()\fR set whether we should read as -many input bytes as possible (for nonblocking reads) or not. For example if -\&\fBx\fR bytes are currently required by OpenSSL, but \fBy\fR bytes are available from -the underlying \s-1BIO\s0 (where \fBy\fR > \fBx\fR), then OpenSSL will read all \fBy\fR bytes -into its buffer (providing that the buffer is large enough) if reading ahead is -on, or \fBx\fR bytes otherwise. -Setting the parameter \fByes\fR to 0 turns reading ahead is off, other values turn -it on. -\&\fBSSL_CTX_set_default_read_ahead()\fR is identical to \fBSSL_CTX_set_read_ahead()\fR. -.PP -\&\fBSSL_CTX_get_read_ahead()\fR and \fBSSL_get_read_ahead()\fR indicate whether reading -ahead has been set or not. -\&\fBSSL_CTX_get_default_read_ahead()\fR is identical to \fBSSL_CTX_get_read_ahead()\fR. -.PP -These functions cannot be used with \s-1QUIC SSL\s0 objects. \fBSSL_set_read_ahead()\fR -has no effect if called on a \s-1QUIC SSL\s0 object. -.SH "NOTES" -.IX Header "NOTES" -These functions have no impact when used with \s-1DTLS.\s0 The return values for -\&\fBSSL_CTX_get_read_head()\fR and \fBSSL_get_read_ahead()\fR are undefined for \s-1DTLS.\s0 Setting -\&\fBread_ahead\fR can impact the behaviour of the \fBSSL_pending()\fR function -(see \fBSSL_pending\fR\|(3)). -.PP -Since \fBSSL_read()\fR can return \fB\s-1SSL_ERROR_WANT_READ\s0\fR for non-application data -records, and \fBSSL_has_pending()\fR can't tell the difference between processed and -unprocessed data, it's recommended that if read ahead is turned on that -\&\fB\s-1SSL_MODE_AUTO_RETRY\s0\fR is not turned off using \fBSSL_CTX_clear_mode()\fR. -That will prevent getting \fB\s-1SSL_ERROR_WANT_READ\s0\fR when there is still a complete -record available that hasn't been processed. -.PP -If the application wants to continue to use the underlying transport (e.g. \s-1TCP\s0 -connection) after the \s-1SSL\s0 connection is finished using \fBSSL_shutdown()\fR reading -ahead should be turned off. -Otherwise the \s-1SSL\s0 structure might read data that it shouldn't. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_read_ahead()\fR and \fBSSL_CTX_get_read_ahead()\fR return 0 if reading ahead is off, -and non zero otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_pending\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback.3ossl deleted file mode 100644 index 245bc635..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback.3ossl +++ /dev/null @@ -1,249 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_RECORD_PADDING_CALLBACK 3ossl" -.TH SSL_CTX_SET_RECORD_PADDING_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_record_padding_callback, -SSL_set_record_padding_callback, -SSL_CTX_set_record_padding_callback_arg, -SSL_set_record_padding_callback_arg, -SSL_CTX_get_record_padding_callback_arg, -SSL_get_record_padding_callback_arg, -SSL_CTX_set_block_padding, -SSL_CTX_set_block_padding_ex, -SSL_set_block_padding, -SSL_set_block_padding_ex \- install callback to specify TLS 1.3 record padding -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_record_padding_callback(SSL_CTX *ctx, size_t (*cb)(SSL *s, int type, size_t len, void *arg)); -\& int SSL_set_record_padding_callback(SSL *ssl, size_t (*cb)(SSL *s, int type, size_t len, void *arg)); -\& -\& void SSL_CTX_set_record_padding_callback_arg(SSL_CTX *ctx, void *arg); -\& void *SSL_CTX_get_record_padding_callback_arg(const SSL_CTX *ctx); -\& -\& void SSL_set_record_padding_callback_arg(SSL *ssl, void *arg); -\& void *SSL_get_record_padding_callback_arg(const SSL *ssl); -\& -\& int SSL_CTX_set_block_padding(SSL_CTX *ctx, size_t block_size); -\& int SSL_set_block_padding(SSL *ssl, size_t block_size); -\& int SSL_CTX_set_block_padding_ex(SSL_CTX *ctx, size_t app_block_size, size_t hs_block_size); -\& int SSL_set_block_padding_ex(SSL *ssl, size_t app_block_size, size_t hs_block_size); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_record_padding_callback()\fR or \fBSSL_set_record_padding_callback()\fR -can be used to assign a callback function \fIcb\fR to specify the padding -for \s-1TLS 1.3\s0 records. The value set in \fBctx\fR is copied to a new \s-1SSL\s0 by \fBSSL_new()\fR. -Kernel \s-1TLS\s0 is not possible if the record padding callback is set, and the callback -function cannot be set if Kernel \s-1TLS\s0 is already configured for the current \s-1SSL\s0 object. -.PP -\&\fBSSL_CTX_set_record_padding_callback_arg()\fR and \fBSSL_set_record_padding_callback_arg()\fR -assign a value \fBarg\fR that is passed to the callback when it is invoked. The value -set in \fBctx\fR is copied to a new \s-1SSL\s0 by \fBSSL_new()\fR. -.PP -\&\fBSSL_CTX_get_record_padding_callback_arg()\fR and \fBSSL_get_record_padding_callback_arg()\fR -retrieve the \fBarg\fR value that is passed to the callback. -.PP -\&\fBSSL_CTX_set_block_padding()\fR and \fBSSL_set_block_padding()\fR pads the record to a multiple -of the \fBblock_size\fR. A \fBblock_size\fR of 0 or 1 disables block padding. The limit of -\&\fBblock_size\fR is \s-1SSL3_RT_MAX_PLAIN_LENGTH.\s0 -.PP -\&\fBSSL_CTX_set_block_padding_ex()\fR and \fBSSL_set_block_padding_ex()\fR do similarly but -allow the caller to separately specify the padding block size to be applied to -handshake and application data messages. -.PP -The callback is invoked for every record before encryption. -The \fBtype\fR parameter is the \s-1TLS\s0 record type that is being processed; may be -one of \s-1SSL3_RT_APPLICATION_DATA, SSL3_RT_HANDSHAKE,\s0 or \s-1SSL3_RT_ALERT.\s0 -The \fBlen\fR parameter is the current plaintext length of the record before encryption. -The \fBarg\fR parameter is the value set via \fBSSL_CTX_set_record_padding_callback_arg()\fR -or \fBSSL_set_record_padding_callback_arg()\fR. -.PP -These functions cannot be used with \s-1QUIC SSL\s0 objects. -\&\fBSSL_set_record_padding_callback()\fR and \fBSSL_set_block_padding()\fR fail if called on -a \s-1QUIC SSL\s0 object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBSSL_CTX_get_record_padding_callback_arg()\fR and \fBSSL_get_record_padding_callback_arg()\fR -functions return the \fBarg\fR value assigned in the corresponding set functions. -.PP -The \fBSSL_CTX_set_block_padding()\fR and \fBSSL_set_block_padding()\fR functions return 1 on success -or 0 if \fBblock_size\fR is too large. -.PP -The \fBcb\fR returns the number of padding bytes to add to the record. A return of 0 -indicates no padding will be added. A return value that causes the record to -exceed the maximum record size (\s-1SSL3_RT_MAX_PLAIN_LENGTH\s0) will pad out to the -maximum record size. -.PP -The \fBSSL_CTX_get_record_padding_callback_arg()\fR function returns 1 on success or 0 if -the callback function is not set because Kernel \s-1TLS\s0 is configured for the \s-1SSL\s0 object. -.SH "NOTES" -.IX Header "NOTES" -The default behavior is to add no padding to the record. -.PP -A user-supplied padding callback function will override the behavior set by -\&\fBSSL_set_block_padding()\fR or \fBSSL_CTX_set_block_padding()\fR. Setting the user-supplied -callback to \s-1NULL\s0 will restore the configured block padding behavior. -.PP -These functions only apply to \s-1TLS 1.3\s0 records being written. -.PP -Padding bytes are not added in constant-time. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The record padding \s-1API\s0 was added for \s-1TLS 1.3\s0 support in OpenSSL 1.1.1. -.PP -The return type of \fBSSL_CTX_set_record_padding_callback()\fR function was -changed to int in OpenSSL 3.0. -.PP -The functions \fBSSL_set_block_padding_ex()\fR and \fBSSL_CTX_set_block_padding_ex()\fR -were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback_arg.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_record_padding_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_recv_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_recv_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_recv_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_security_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_security_callback.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_security_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_security_level.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_security_level.3ossl deleted file mode 100644 index cf1cb914..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_security_level.3ossl +++ /dev/null @@ -1,307 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_SECURITY_LEVEL 3ossl" -.TH SSL_CTX_SET_SECURITY_LEVEL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_security_level, SSL_set_security_level, SSL_CTX_get_security_level, SSL_get_security_level, SSL_CTX_set_security_callback, SSL_set_security_callback, SSL_CTX_get_security_callback, SSL_get_security_callback, SSL_CTX_set0_security_ex_data, SSL_set0_security_ex_data, SSL_CTX_get0_security_ex_data, SSL_get0_security_ex_data \- SSL/TLS security framework -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_security_level(SSL_CTX *ctx, int level); -\& void SSL_set_security_level(SSL *s, int level); -\& -\& int SSL_CTX_get_security_level(const SSL_CTX *ctx); -\& int SSL_get_security_level(const SSL *s); -\& -\& void SSL_CTX_set_security_callback(SSL_CTX *ctx, -\& int (*cb)(SSL *s, SSL_CTX *ctx, int op, -\& int bits, int nid, -\& void *other, void *ex)); -\& -\& void SSL_set_security_callback(SSL *s, int (*cb)(SSL *s, SSL_CTX *ctx, int op, -\& int bits, int nid, -\& void *other, void *ex)); -\& -\& int (*SSL_CTX_get_security_callback(const SSL_CTX *ctx))(SSL *s, SSL_CTX *ctx, int op, -\& int bits, int nid, void *other, -\& void *ex); -\& int (*SSL_get_security_callback(const SSL *s))(SSL *s, SSL_CTX *ctx, int op, -\& int bits, int nid, void *other, -\& void *ex); -\& -\& void SSL_CTX_set0_security_ex_data(SSL_CTX *ctx, void *ex); -\& void SSL_set0_security_ex_data(SSL *s, void *ex); -\& -\& void *SSL_CTX_get0_security_ex_data(const SSL_CTX *ctx); -\& void *SSL_get0_security_ex_data(const SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions \fBSSL_CTX_set_security_level()\fR and \fBSSL_set_security_level()\fR set -the security level to \fBlevel\fR. If not set the library default security level -is used. -.PP -The functions \fBSSL_CTX_get_security_level()\fR and \fBSSL_get_security_level()\fR -retrieve the current security level. -.PP -\&\fBSSL_CTX_set_security_callback()\fR, \fBSSL_set_security_callback()\fR, -\&\fBSSL_CTX_get_security_callback()\fR and \fBSSL_get_security_callback()\fR get or set -the security callback associated with \fBctx\fR or \fBs\fR. If not set a default -security callback is used. The meaning of the parameters and the behaviour -of the default callbacks is described below. -.PP -\&\fBSSL_CTX_set0_security_ex_data()\fR, \fBSSL_set0_security_ex_data()\fR, -\&\fBSSL_CTX_get0_security_ex_data()\fR and \fBSSL_get0_security_ex_data()\fR set the -extra data pointer passed to the \fBex\fR parameter of the callback. This -value is passed to the callback verbatim and can be set to any convenient -application specific value. -.SH "DEFAULT CALLBACK BEHAVIOUR" -.IX Header "DEFAULT CALLBACK BEHAVIOUR" -If an application doesn't set its own security callback the default -callback is used. It is intended to provide sane defaults. The meaning -of each level is described below. -.IP "\fBLevel 0\fR" 4 -.IX Item "Level 0" -Everything is permitted. This retains compatibility with previous versions of -OpenSSL. -.IP "\fBLevel 1\fR" 4 -.IX Item "Level 1" -The security level corresponds to a minimum of 80 bits of security. Any -parameters offering below 80 bits of security are excluded. As a result \s-1RSA, -DSA\s0 and \s-1DH\s0 keys shorter than 1024 bits and \s-1ECC\s0 keys shorter than 160 bits -are prohibited. Any cipher suite using \s-1MD5\s0 for the \s-1MAC\s0 is also prohibited. Any -cipher suites using \s-1CCM\s0 with a 64 bit authentication tag are prohibited. Note -that signatures using \s-1SHA1\s0 and \s-1MD5\s0 are also forbidden at this level as they -have less than 80 security bits. Additionally, SSLv3, \s-1TLS 1.0, TLS 1.1\s0 and -\&\s-1DTLS 1.0\s0 are all disabled at this level. -.IP "\fBLevel 2\fR" 4 -.IX Item "Level 2" -Security level set to 112 bits of security. As a result \s-1RSA, DSA\s0 and \s-1DH\s0 keys -shorter than 2048 bits and \s-1ECC\s0 keys shorter than 224 bits are prohibited. -In addition to the level 1 exclusions any cipher suite using \s-1RC4\s0 is also -prohibited. Compression is disabled. -.IP "\fBLevel 3\fR" 4 -.IX Item "Level 3" -Security level set to 128 bits of security. As a result \s-1RSA, DSA\s0 and \s-1DH\s0 keys -shorter than 3072 bits and \s-1ECC\s0 keys shorter than 256 bits are prohibited. -In addition to the level 2 exclusions cipher suites not offering forward -secrecy are prohibited. Session tickets are disabled. -.IP "\fBLevel 4\fR" 4 -.IX Item "Level 4" -Security level set to 192 bits of security. As a result \s-1RSA, DSA\s0 and -\&\s-1DH\s0 keys shorter than 7680 bits and \s-1ECC\s0 keys shorter than 384 bits are -prohibited. Cipher suites using \s-1SHA1\s0 for the \s-1MAC\s0 are prohibited. -.IP "\fBLevel 5\fR" 4 -.IX Item "Level 5" -Security level set to 256 bits of security. As a result \s-1RSA, DSA\s0 and \s-1DH\s0 keys -shorter than 15360 bits and \s-1ECC\s0 keys shorter than 512 bits are prohibited. -.SH "APPLICATION DEFINED SECURITY CALLBACKS" -.IX Header "APPLICATION DEFINED SECURITY CALLBACKS" -\&\fIDocumentation to be provided.\fR -.SH "NOTES" -.IX Header "NOTES" -The default security level can be configured when OpenSSL is compiled by -setting \fB\-DOPENSSL_TLS_SECURITY_LEVEL=level\fR. If not set then 2 is used. -.PP -The security framework disables or reject parameters inconsistent with the -set security level. In the past this was difficult as applications had to set -a number of distinct parameters (supported ciphers, supported curves supported -signature algorithms) to achieve this end and some cases (\s-1DH\s0 parameter size -for example) could not be checked at all. -.PP -By setting an appropriate security level much of this complexity can be -avoided. -.PP -The bits of security limits affect all relevant parameters including -cipher suite encryption algorithms, supported \s-1ECC\s0 curves, supported -signature algorithms, \s-1DH\s0 parameter sizes, certificate key sizes and -signature algorithms. This limit applies no matter what other custom -settings an application has set: so if the cipher suite is set to \fB\s-1ALL\s0\fR -then only cipher suites consistent with the security level are permissible. -.PP -See \s-1SP800\-57\s0 for how the security limits are related to individual -algorithms. -.PP -Some security levels require large key sizes for non-ECC public key -algorithms which can severely degrade performance. For example 256 bits -of security requires the use of \s-1RSA\s0 keys of at least 15360 bits in size. -.PP -Some restrictions can be gracefully handled: for example cipher suites -offering insufficient security are not sent by the client and will not -be selected by the server. Other restrictions such as the peer certificate -key size or the \s-1DH\s0 parameter size will abort the handshake with a fatal -alert. -.PP -Attempts to set certificates or parameters with insufficient security are -also blocked. For example trying to set a certificate using a 512 bit \s-1RSA\s0 key -or a certificate with a signature with \s-1SHA1\s0 digest at level 1 using -\&\fBSSL_CTX_use_certificate()\fR. Applications which do not check the return values -for errors will misbehave: for example it might appear that a certificate is -not set at all because it had been rejected. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_security_level()\fR and \fBSSL_set_security_level()\fR do not return values. -.PP -\&\fBSSL_CTX_get_security_level()\fR and \fBSSL_get_security_level()\fR return a integer that -represents the security level with \fB\s-1SSL_CTX\s0\fR or \fB\s-1SSL\s0\fR, respectively. -.PP -\&\fBSSL_CTX_set_security_callback()\fR and \fBSSL_set_security_callback()\fR do not return -values. -.PP -\&\fBSSL_CTX_get_security_callback()\fR and \fBSSL_get_security_callback()\fR return the pointer -to the security callback or \s-1NULL\s0 if the callback is not set. -.PP -\&\fBSSL_CTX_get0_security_ex_data()\fR and \fBSSL_get0_security_ex_data()\fR return the extra -data pointer or \s-1NULL\s0 if the ex data is not set. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2014\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_session_cache_mode.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_session_cache_mode.3ossl deleted file mode 100644 index c93d1c48..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_session_cache_mode.3ossl +++ /dev/null @@ -1,263 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_SESSION_CACHE_MODE 3ossl" -.TH SSL_CTX_SET_SESSION_CACHE_MODE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_session_cache_mode, SSL_CTX_get_session_cache_mode \- enable/disable session caching -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_session_cache_mode(SSL_CTX ctx, long mode); -\& long SSL_CTX_get_session_cache_mode(SSL_CTX ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_session_cache_mode()\fR enables/disables session caching -by setting the operational mode for \fBctx\fR to . -.PP -\&\fBSSL_CTX_get_session_cache_mode()\fR returns the currently used cache mode. -.SH "NOTES" -.IX Header "NOTES" -The OpenSSL library can store/retrieve \s-1SSL/TLS\s0 sessions for later reuse. -The sessions can be held in memory for each \fBctx\fR, if more than one -\&\s-1SSL_CTX\s0 object is being maintained, the sessions are unique for each \s-1SSL_CTX\s0 -object. -.PP -In order to reuse a session, a client must send the session's id to the -server. It can only send exactly one id. The server then either -agrees to reuse the session or it starts a full handshake (to create a new -session). -.PP -A server will look up the session in its internal session storage. If the -session is not found in internal storage or lookups for the internal storage -have been deactivated (\s-1SSL_SESS_CACHE_NO_INTERNAL_LOOKUP\s0), the server will try -the external storage if available. -.PP -Since a client may try to reuse a session intended for use in a different -context, the session id context must be set by the server (see -\&\fBSSL_CTX_set_session_id_context\fR\|(3)). -.PP -The following session cache modes and modifiers are available: -.IP "\s-1SSL_SESS_CACHE_OFF\s0" 4 -.IX Item "SSL_SESS_CACHE_OFF" -No session caching for client or server takes place. -.IP "\s-1SSL_SESS_CACHE_CLIENT\s0" 4 -.IX Item "SSL_SESS_CACHE_CLIENT" -Client sessions are added to the session cache. As there is no reliable way -for the OpenSSL library to know whether a session should be reused or which -session to choose (due to the abstract \s-1BIO\s0 layer the \s-1SSL\s0 engine does not -have details about the connection), the application must select the session -to be reused by using the \fBSSL_set_session\fR\|(3) -function. This option is not activated by default. -.IP "\s-1SSL_SESS_CACHE_SERVER\s0" 4 -.IX Item "SSL_SESS_CACHE_SERVER" -Server sessions are added to the session cache. When a client proposes a -session to be reused, the server looks for the corresponding session in (first) -the internal session cache (unless \s-1SSL_SESS_CACHE_NO_INTERNAL_LOOKUP\s0 is set), -then (second) in the external cache if available. If the session is found, the -server will try to reuse the session. This is the default. -.IP "\s-1SSL_SESS_CACHE_BOTH\s0" 4 -.IX Item "SSL_SESS_CACHE_BOTH" -Enable both \s-1SSL_SESS_CACHE_CLIENT\s0 and \s-1SSL_SESS_CACHE_SERVER\s0 at the same time. -.IP "\s-1SSL_SESS_CACHE_NO_AUTO_CLEAR\s0" 4 -.IX Item "SSL_SESS_CACHE_NO_AUTO_CLEAR" -Normally the session cache is checked for expired sessions every -255 connections using the -\&\fBSSL_CTX_flush_sessions\fR\|(3) function. Since -this may lead to a delay which cannot be controlled, the automatic -flushing may be disabled and -\&\fBSSL_CTX_flush_sessions\fR\|(3) can be called -explicitly by the application. -.IP "\s-1SSL_SESS_CACHE_NO_INTERNAL_LOOKUP\s0" 4 -.IX Item "SSL_SESS_CACHE_NO_INTERNAL_LOOKUP" -By setting this flag, session-resume operations in an \s-1SSL/TLS\s0 server will not -automatically look up sessions in the internal cache, even if sessions are -automatically stored there. If external session caching callbacks are in use, -this flag guarantees that all lookups are directed to the external cache. -As automatic lookup only applies for \s-1SSL/TLS\s0 servers, the flag has no effect on -clients. -.IP "\s-1SSL_SESS_CACHE_NO_INTERNAL_STORE\s0" 4 -.IX Item "SSL_SESS_CACHE_NO_INTERNAL_STORE" -Depending on the presence of \s-1SSL_SESS_CACHE_CLIENT\s0 and/or \s-1SSL_SESS_CACHE_SERVER,\s0 -sessions negotiated in an \s-1SSL/TLS\s0 handshake may be cached for possible reuse. -Normally a new session is added to the internal cache as well as any external -session caching (callback) that is configured for the \s-1SSL_CTX.\s0 This flag will -prevent sessions being stored in the internal cache (though the application can -add them manually using \fBSSL_CTX_add_session\fR\|(3)). Note: -in any \s-1SSL/TLS\s0 servers where external caching is configured, any successful -session lookups in the external cache (i.e. for session-resume requests) would -normally be copied into the local cache before processing continues \- this flag -prevents these additions to the internal cache as well. -.IP "\s-1SSL_SESS_CACHE_NO_INTERNAL\s0" 4 -.IX Item "SSL_SESS_CACHE_NO_INTERNAL" -Enable both \s-1SSL_SESS_CACHE_NO_INTERNAL_LOOKUP\s0 and -\&\s-1SSL_SESS_CACHE_NO_INTERNAL_STORE\s0 at the same time. -.IP "\s-1SSL_SESS_CACHE_UPDATE_TIME\s0" 4 -.IX Item "SSL_SESS_CACHE_UPDATE_TIME" -Updates the timestamp of the session when it is used, increasing the lifespan -of the session. The session timeout applies to last use, rather then creation -time. -.PP -The default mode is \s-1SSL_SESS_CACHE_SERVER.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_session_cache_mode()\fR returns the previously set cache mode. -.PP -\&\fBSSL_CTX_get_session_cache_mode()\fR returns the currently set cache mode. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_set_session\fR\|(3), -\&\fBSSL_session_reused\fR\|(3), -\&\fBSSL_CTX_add_session\fR\|(3), -\&\fBSSL_CTX_sess_number\fR\|(3), -\&\fBSSL_CTX_sess_set_cache_size\fR\|(3), -\&\fBSSL_CTX_sess_set_get_cb\fR\|(3), -\&\fBSSL_CTX_set_session_id_context\fR\|(3), -\&\fBSSL_CTX_set_timeout\fR\|(3), -\&\fBSSL_CTX_flush_sessions\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_session_id_context.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_session_id_context.3ossl deleted file mode 100644 index 5fcfa163..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_session_id_context.3ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_SESSION_ID_CONTEXT 3ossl" -.TH SSL_CTX_SET_SESSION_ID_CONTEXT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_session_id_context, SSL_set_session_id_context \- set context within which session can be reused (server side only) -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_session_id_context(SSL_CTX *ctx, const unsigned char *sid_ctx, -\& unsigned int sid_ctx_len); -\& int SSL_set_session_id_context(SSL *ssl, const unsigned char *sid_ctx, -\& unsigned int sid_ctx_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_session_id_context()\fR sets the context \fBsid_ctx\fR of length -\&\fBsid_ctx_len\fR within which a session can be reused for the \fBctx\fR object. -.PP -\&\fBSSL_set_session_id_context()\fR sets the context \fBsid_ctx\fR of length -\&\fBsid_ctx_len\fR within which a session can be reused for the \fBssl\fR object. -.SH "NOTES" -.IX Header "NOTES" -Sessions are generated within a certain context. When exporting/importing -sessions with \fBi2d_SSL_SESSION\fR/\fBd2i_SSL_SESSION\fR it would be possible, -to re-import a session generated from another context (e.g. another -application), which might lead to malfunctions. Therefore, each application -must set its own session id context \fBsid_ctx\fR which is used to distinguish -the contexts and is stored in exported sessions. The \fBsid_ctx\fR can be -any kind of binary data with a given length, it is therefore possible -to use e.g. the name of the application and/or the hostname and/or service -name ... -.PP -The session id context becomes part of the session. The session id context -is set by the \s-1SSL/TLS\s0 server. The \fBSSL_CTX_set_session_id_context()\fR and -\&\fBSSL_set_session_id_context()\fR functions are therefore only useful on the -server side. -.PP -OpenSSL clients will check the session id context returned by the server -when reusing a session. -.PP -The maximum length of the \fBsid_ctx\fR is limited to -\&\fB\s-1SSL_MAX_SID_CTX_LENGTH\s0\fR. -.SH "WARNINGS" -.IX Header "WARNINGS" -If the session id context is not set on an \s-1SSL/TLS\s0 server and client -certificates are used, stored sessions -will not be reused but a fatal error will be flagged and the handshake -will fail. -.PP -If a server returns a different session id context to an OpenSSL client -when reusing a session, an error will be flagged and the handshake will -fail. OpenSSL servers will always return the correct session id context, -as an OpenSSL server checks the session id context itself before reusing -a session as described above. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_session_id_context()\fR and \fBSSL_set_session_id_context()\fR -return the following values: -.IP "0" 4 -The length \fBsid_ctx_len\fR of the session id context \fBsid_ctx\fR exceeded -the maximum allowed length of \fB\s-1SSL_MAX_SID_CTX_LENGTH\s0\fR. The error -is logged to the error stack. -.IP "1" 4 -.IX Item "1" -The operation succeeded. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_session_ticket_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_session_ticket_cb.3ossl deleted file mode 100644 index 8c922308..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_session_ticket_cb.3ossl +++ /dev/null @@ -1,305 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_SESSION_TICKET_CB 3ossl" -.TH SSL_CTX_SET_SESSION_TICKET_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_session_ticket_cb, -SSL_SESSION_get0_ticket_appdata, -SSL_SESSION_set1_ticket_appdata, -SSL_CTX_generate_session_ticket_fn, -SSL_CTX_decrypt_session_ticket_fn \- manage session ticket application data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*SSL_CTX_generate_session_ticket_fn)(SSL *s, void *arg); -\& typedef SSL_TICKET_RETURN (*SSL_CTX_decrypt_session_ticket_fn)(SSL *s, SSL_SESSION *ss, -\& const unsigned char *keyname, -\& size_t keyname_len, -\& SSL_TICKET_STATUS status, -\& void *arg); -\& int SSL_CTX_set_session_ticket_cb(SSL_CTX *ctx, -\& SSL_CTX_generate_session_ticket_fn gen_cb, -\& SSL_CTX_decrypt_session_ticket_fn dec_cb, -\& void *arg); -\& int SSL_SESSION_set1_ticket_appdata(SSL_SESSION *ss, const void *data, size_t len); -\& int SSL_SESSION_get0_ticket_appdata(SSL_SESSION *ss, void **data, size_t *len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_set_session_ticket_cb()\fR sets the application callbacks \fBgen_cb\fR -and \fBdec_cb\fR that are used by a server to set and get application data stored -with a session, and placed into a session ticket. Either callback function may -be set to \s-1NULL.\s0 The value of \fBarg\fR is passed to the callbacks. -.PP -\&\fBgen_cb\fR is the application defined callback invoked when a session ticket is -about to be created. The application can call \fBSSL_SESSION_set1_ticket_appdata()\fR -at this time to add application data to the session ticket. The value of \fBarg\fR -is the same as that given to \fBSSL_CTX_set_session_ticket_cb()\fR. The \fBgen_cb\fR -callback is defined as type \fBSSL_CTX_generate_session_ticket_fn\fR. -.PP -\&\fBdec_cb\fR is the application defined callback invoked after session ticket -decryption has been attempted and any session ticket application data is -available. If ticket decryption was successful then the \fBss\fR argument contains -the session data. The \fBkeyname\fR and \fBkeyname_len\fR arguments identify the key -used to decrypt the session ticket. The \fBstatus\fR argument is the result of the -ticket decryption. See the \*(L"\s-1NOTES\*(R"\s0 section below for further details. The value -of \fBarg\fR is the same as that given to \fBSSL_CTX_set_session_ticket_cb()\fR. The -\&\fBdec_cb\fR callback is defined as type \fBSSL_CTX_decrypt_session_ticket_fn\fR. -.PP -\&\fBSSL_SESSION_set1_ticket_appdata()\fR sets the application data specified by -\&\fBdata\fR and \fBlen\fR into \fBss\fR which is then placed into any generated session -tickets. It can be called at any time before a session ticket is created to -update the data placed into the session ticket. However, given that sessions -and tickets are created by the handshake, the \fBgen_cb\fR is provided to notify -the application that a session ticket is about to be generated. -.PP -\&\fBSSL_SESSION_get0_ticket_appdata()\fR assigns \fBdata\fR to the session ticket -application data and assigns \fBlen\fR to the length of the session ticket -application data from \fBss\fR. The application data can be set via -\&\fBSSL_SESSION_set1_ticket_appdata()\fR or by a session ticket. \s-1NULL\s0 will be assigned -to \fBdata\fR and 0 will be assigned to \fBlen\fR if there is no session ticket -application data. \fBSSL_SESSION_get0_ticket_appdata()\fR can be called any time -after a session has been created. The \fBdec_cb\fR is provided to notify the -application that a session ticket has just been decrypted. -.SH "NOTES" -.IX Header "NOTES" -When the \fBdec_cb\fR callback is invoked, the \s-1SSL_SESSION\s0 \fBss\fR has not yet been -assigned to the \s-1SSL\s0 \fBs\fR. The \fBstatus\fR indicates the result of the ticket -decryption. The callback must check the \fBstatus\fR value before performing any -action, as it is called even if ticket decryption fails. -.PP -The \fBkeyname\fR and \fBkeyname_len\fR arguments to \fBdec_cb\fR may be used to identify -the key that was used to encrypt the session ticket. -.PP -The \fBstatus\fR argument can be any of these values: -.IP "\s-1SSL_TICKET_EMPTY\s0" 4 -.IX Item "SSL_TICKET_EMPTY" -Empty ticket present. No ticket data will be used and a new ticket should be -sent to the client. This only occurs in TLSv1.2 or below. In TLSv1.3 it is not -valid for a client to send an empty ticket. -.IP "\s-1SSL_TICKET_NO_DECRYPT\s0" 4 -.IX Item "SSL_TICKET_NO_DECRYPT" -The ticket couldn't be decrypted. No ticket data will be used and a new ticket -should be sent to the client. -.IP "\s-1SSL_TICKET_SUCCESS\s0" 4 -.IX Item "SSL_TICKET_SUCCESS" -A ticket was successfully decrypted, any session ticket application data should -be available. A new ticket should not be sent to the client. -.IP "\s-1SSL_TICKET_SUCCESS_RENEW\s0" 4 -.IX Item "SSL_TICKET_SUCCESS_RENEW" -Same as \fB\s-1SSL_TICKET_SUCCESS\s0\fR, but a new ticket should be sent to the client. -.PP -The return value can be any of these values: -.IP "\s-1SSL_TICKET_RETURN_ABORT\s0" 4 -.IX Item "SSL_TICKET_RETURN_ABORT" -The handshake should be aborted, either because of an error or because of some -policy. Note that in TLSv1.3 a client may send more than one ticket in a single -handshake. Therefore, just because one ticket is unacceptable it does not mean -that all of them are. For this reason this option should be used with caution. -.IP "\s-1SSL_TICKET_RETURN_IGNORE\s0" 4 -.IX Item "SSL_TICKET_RETURN_IGNORE" -Do not use a ticket (if one was available). Do not send a renewed ticket to the -client. -.IP "\s-1SSL_TICKET_RETURN_IGNORE_RENEW\s0" 4 -.IX Item "SSL_TICKET_RETURN_IGNORE_RENEW" -Do not use a ticket (if one was available). Send a renewed ticket to the client. -.Sp -If the callback does not wish to change the default ticket behaviour then it -should return this value if \fBstatus\fR is \fB\s-1SSL_TICKET_EMPTY\s0\fR or -\&\fB\s-1SSL_TICKET_NO_DECRYPT\s0\fR. -.IP "\s-1SSL_TICKET_RETURN_USE\s0" 4 -.IX Item "SSL_TICKET_RETURN_USE" -Use the ticket. Do not send a renewed ticket to the client. It is an error for -the callback to return this value if \fBstatus\fR has a value other than -\&\fB\s-1SSL_TICKET_SUCCESS\s0\fR or \fB\s-1SSL_TICKET_SUCCESS_RENEW\s0\fR. -.Sp -If the callback does not wish to change the default ticket behaviour then it -should return this value if \fBstatus\fR is \fB\s-1SSL_TICKET_SUCCESS\s0\fR. -.IP "\s-1SSL_TICKET_RETURN_USE_RENEW\s0" 4 -.IX Item "SSL_TICKET_RETURN_USE_RENEW" -Use the ticket. Send a renewed ticket to the client. It is an error for the -callback to return this value if \fBstatus\fR has a value other than -\&\fB\s-1SSL_TICKET_SUCCESS\s0\fR or \fB\s-1SSL_TICKET_SUCCESS_RENEW\s0\fR. -.Sp -If the callback does not wish to change the default ticket behaviour then it -should return this value if \fBstatus\fR is \fB\s-1SSL_TICKET_SUCCESS_RENEW\s0\fR. -.PP -If \fBstatus\fR has the value \fB\s-1SSL_TICKET_EMPTY\s0\fR or \fB\s-1SSL_TICKET_NO_DECRYPT\s0\fR then -no session data will be available and the callback must not use the \fBss\fR -argument. If \fBstatus\fR has the value \fB\s-1SSL_TICKET_SUCCESS\s0\fR or -\&\fB\s-1SSL_TICKET_SUCCESS_RENEW\s0\fR then the application can call -\&\fBSSL_SESSION_get0_ticket_appdata()\fR using the session provided in the \fBss\fR -argument to retrieve the application data. -.PP -When the \fBgen_cb\fR callback is invoked, the \fBSSL_get_session()\fR function can be -used to retrieve the \s-1SSL_SESSION\s0 for \fBSSL_SESSION_set1_ticket_appdata()\fR. -.PP -By default, in TLSv1.2 and below, a new session ticket is not issued on a -successful resumption and therefore \fBgen_cb\fR will not be called. In TLSv1.3 the -default behaviour is to always issue a new ticket on resumption. In both cases -this behaviour can be changed if a ticket key callback is in use (see -\&\fBSSL_CTX_set_tlsext_ticket_key_cb\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBSSL_CTX_set_session_ticket_cb()\fR, \fBSSL_SESSION_set1_ticket_appdata()\fR and -\&\fBSSL_SESSION_get0_ticket_appdata()\fR functions return 1 on success and 0 on -failure. -.PP -The \fBgen_cb\fR callback must return 1 to continue the connection. A return of 0 -will terminate the connection with an \s-1INTERNAL_ERROR\s0 alert. -.PP -The \fBdec_cb\fR callback must return a value as described in \*(L"\s-1NOTES\*(R"\s0 above. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_get_session\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_CTX_set_session_ticket_cb()\fR, \fBSSL_SESSION_set1_ticket_appdata()\fR -and \fBSSL_SESSION_get_ticket_appdata()\fR functions were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_split_send_fragment.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_split_send_fragment.3ossl deleted file mode 100644 index f5facc31..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_split_send_fragment.3ossl +++ /dev/null @@ -1,318 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_SPLIT_SEND_FRAGMENT 3ossl" -.TH SSL_CTX_SET_SPLIT_SEND_FRAGMENT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_max_send_fragment, SSL_set_max_send_fragment, -SSL_CTX_set_split_send_fragment, SSL_set_split_send_fragment, -SSL_CTX_set_max_pipelines, SSL_set_max_pipelines, -SSL_CTX_set_default_read_buffer_len, SSL_set_default_read_buffer_len, -SSL_CTX_set_tlsext_max_fragment_length, -SSL_set_tlsext_max_fragment_length, -SSL_SESSION_get_max_fragment_length \- Control fragment size settings and pipelining operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_max_send_fragment(SSL_CTX *ctx, long); -\& long SSL_set_max_send_fragment(SSL *ssl, long m); -\& -\& long SSL_CTX_set_max_pipelines(SSL_CTX *ctx, long m); -\& long SSL_set_max_pipelines(SSL_CTX *ssl, long m); -\& -\& long SSL_CTX_set_split_send_fragment(SSL_CTX *ctx, long m); -\& long SSL_set_split_send_fragment(SSL *ssl, long m); -\& -\& void SSL_CTX_set_default_read_buffer_len(SSL_CTX *ctx, size_t len); -\& void SSL_set_default_read_buffer_len(SSL *s, size_t len); -\& -\& int SSL_CTX_set_tlsext_max_fragment_length(SSL_CTX *ctx, uint8_t mode); -\& int SSL_set_tlsext_max_fragment_length(SSL *ssl, uint8_t mode); -\& uint8_t SSL_SESSION_get_max_fragment_length(const SSL_SESSION *session); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Some engines are able to process multiple simultaneous crypto operations. This -capability could be utilised to parallelise the processing of a single -connection. For example a single write can be split into multiple records and -each one encrypted independently and in parallel. Note: this will only work in -\&\s-1TLS1.1+.\s0 There is no support in SSLv3, TLSv1.0 or \s-1DTLS\s0 (any version). This -capability is known as \*(L"pipelining\*(R" within OpenSSL. -.PP -In order to benefit from the pipelining capability. You need to have an engine -that provides ciphers that support this. The OpenSSL \*(L"dasync\*(R" engine provides -\&\s-1AES128\-SHA\s0 based ciphers that have this capability. However, these are for -development and test purposes only. -.PP -\&\fBSSL_CTX_set_max_send_fragment()\fR and \fBSSL_set_max_send_fragment()\fR set the -\&\fBmax_send_fragment\fR parameter for \s-1SSL_CTX\s0 and \s-1SSL\s0 objects respectively. This -value restricts the amount of plaintext bytes that will be sent in any one -\&\s-1SSL/TLS\s0 record. By default its value is \s-1SSL3_RT_MAX_PLAIN_LENGTH\s0 (16384). These -functions will only accept a value in the range 512 \- \s-1SSL3_RT_MAX_PLAIN_LENGTH.\s0 -.PP -\&\fBSSL_CTX_set_max_pipelines()\fR and \fBSSL_set_max_pipelines()\fR set the maximum number -of pipelines that will be used at any one time. This value applies to both -\&\*(L"read\*(R" pipelining and \*(L"write\*(R" pipelining. By default only one pipeline will be -used (i.e. normal non-parallel operation). The number of pipelines set must be -in the range 1 \- \s-1SSL_MAX_PIPELINES\s0 (32). Setting this to a value > 1 will also -automatically turn on \*(L"read_ahead\*(R" (see \fBSSL_CTX_set_read_ahead\fR\|(3)). This is -explained further below. OpenSSL will only ever use more than one pipeline if -a cipher suite is negotiated that uses a pipeline capable cipher provided by an -engine. -.PP -Pipelining operates slightly differently for reading encrypted data compared to -writing encrypted data. \fBSSL_CTX_set_split_send_fragment()\fR and -\&\fBSSL_set_split_send_fragment()\fR define how data is split up into pipelines when -writing encrypted data. The number of pipelines used will be determined by the -amount of data provided to the \fBSSL_write_ex()\fR or \fBSSL_write()\fR call divided by -\&\fBsplit_send_fragment\fR. -.PP -For example if \fBsplit_send_fragment\fR is set to 2000 and \fBmax_pipelines\fR is 4 -then: -.PP -SSL_write/SSL_write_ex called with 0\-2000 bytes == 1 pipeline used -.PP -SSL_write/SSL_write_ex called with 2001\-4000 bytes == 2 pipelines used -.PP -SSL_write/SSL_write_ex called with 4001\-6000 bytes == 3 pipelines used -.PP -SSL_write/SSL_write_ex called with 6001+ bytes == 4 pipelines used -.PP -\&\fBsplit_send_fragment\fR must always be less than or equal to -\&\fBmax_send_fragment\fR. By default it is set to be equal to \fBmax_send_fragment\fR. -This will mean that the same number of records will always be created as would -have been created in the non-parallel case, although the data will be -apportioned differently. In the parallel case data will be spread equally -between the pipelines. -.PP -Read pipelining is controlled in a slightly different way than with write -pipelining. While reading we are constrained by the number of records that the -peer (and the network) can provide to us in one go. The more records we can get -in one go the more opportunity we have to parallelise the processing. As noted -above when setting \fBmax_pipelines\fR to a value greater than one, \fBread_ahead\fR -is automatically set. The \fBread_ahead\fR parameter causes OpenSSL to attempt to -read as much data into the read buffer as the network can provide and will fit -into the buffer. Without this set data is read into the read buffer one record -at a time. The more data that can be read, the more opportunity there is for -parallelising the processing at the cost of increased memory overhead per -connection. Setting \fBread_ahead\fR can impact the behaviour of the \fBSSL_pending()\fR -function (see \fBSSL_pending\fR\|(3)). In addition the default size of the internal -read buffer is multiplied by the number of pipelines available to ensure that we -can read multiple records in one go. This can therefore have a significant -impact on memory usage. -.PP -The \fBSSL_CTX_set_default_read_buffer_len()\fR and \fBSSL_set_default_read_buffer_len()\fR -functions control the size of the read buffer that will be used. The \fBlen\fR -parameter sets the size of the buffer. The value will only be used if it is -greater than the default that would have been used anyway. The normal default -value depends on a number of factors but it will be at least -\&\s-1SSL3_RT_MAX_PLAIN_LENGTH + SSL3_RT_MAX_ENCRYPTED_OVERHEAD\s0 (16704) bytes. -.PP -\&\fBSSL_CTX_set_tlsext_max_fragment_length()\fR sets the default maximum fragment -length negotiation mode via value \fBmode\fR to \fBctx\fR. -This setting affects only \s-1SSL\s0 instances created after this function is called. -It affects the client-side as only its side may initiate this extension use. -.PP -\&\fBSSL_set_tlsext_max_fragment_length()\fR sets the maximum fragment length -negotiation mode via value \fBmode\fR to \fBssl\fR. -This setting will be used during a handshake when extensions are exchanged -between client and server. -So it only affects \s-1SSL\s0 sessions created after this function is called. -It affects the client-side as only its side may initiate this extension use. -.PP -\&\fBSSL_SESSION_get_max_fragment_length()\fR gets the maximum fragment length -negotiated in \fBsession\fR. -.PP -These functions cannot be used with \s-1QUIC SSL\s0 objects. -\&\fBSSL_set_max_send_fragment()\fR, \fBSSL_set_max_pipelines()\fR, -\&\fBSSL_set_split_send_fragment()\fR, \fBSSL_set_default_read_buffer_len()\fR and -\&\fBSSL_set_tlsext_max_fragment_length()\fR fail if called on a \s-1QUIC SSL\s0 object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All non-void functions return 1 on success and 0 on failure. -.SH "NOTES" -.IX Header "NOTES" -The Maximum Fragment Length extension support is optional on the server side. -If the server does not support this extension then -\&\fBSSL_SESSION_get_max_fragment_length()\fR will return: -TLSEXT_max_fragment_length_DISABLED. -.PP -The following modes are available: -.IP "TLSEXT_max_fragment_length_DISABLED" 4 -.IX Item "TLSEXT_max_fragment_length_DISABLED" -Disables Maximum Fragment Length Negotiation (default). -.IP "TLSEXT_max_fragment_length_512" 4 -.IX Item "TLSEXT_max_fragment_length_512" -Sets Maximum Fragment Length to 512 bytes. -.IP "TLSEXT_max_fragment_length_1024" 4 -.IX Item "TLSEXT_max_fragment_length_1024" -Sets Maximum Fragment Length to 1024. -.IP "TLSEXT_max_fragment_length_2048" 4 -.IX Item "TLSEXT_max_fragment_length_2048" -Sets Maximum Fragment Length to 2048. -.IP "TLSEXT_max_fragment_length_4096" 4 -.IX Item "TLSEXT_max_fragment_length_4096" -Sets Maximum Fragment Length to 4096. -.PP -With the exception of \fBSSL_CTX_set_default_read_buffer_len()\fR -\&\fBSSL_set_default_read_buffer_len()\fR, \fBSSL_CTX_set_tlsext_max_fragment_length()\fR, -\&\fBSSL_set_tlsext_max_fragment_length()\fR and \fBSSL_SESSION_get_max_fragment_length()\fR -all these functions are implemented using macros. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_read_ahead\fR\|(3), \fBSSL_pending\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_CTX_set_max_pipelines()\fR, \fBSSL_set_max_pipelines()\fR, -\&\fBSSL_CTX_set_split_send_fragment()\fR, \fBSSL_set_split_send_fragment()\fR, -\&\fBSSL_CTX_set_default_read_buffer_len()\fR and \fBSSL_set_default_read_buffer_len()\fR -functions were added in OpenSSL 1.1.0. -.PP -The \fBSSL_CTX_set_tlsext_max_fragment_length()\fR, \fBSSL_set_tlsext_max_fragment_length()\fR -and \fBSSL_SESSION_get_max_fragment_length()\fR functions were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_srp_cb_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_srp_cb_arg.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_srp_cb_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_srp_client_pwd_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_srp_client_pwd_callback.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_srp_client_pwd_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_srp_password.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_srp_password.3ossl deleted file mode 100644 index 85e94f09..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_srp_password.3ossl +++ /dev/null @@ -1,360 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_SRP_PASSWORD 3ossl" -.TH SSL_CTX_SET_SRP_PASSWORD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_srp_username, -SSL_CTX_set_srp_password, -SSL_CTX_set_srp_strength, -SSL_CTX_set_srp_cb_arg, -SSL_CTX_set_srp_username_callback, -SSL_CTX_set_srp_client_pwd_callback, -SSL_CTX_set_srp_verify_param_callback, -SSL_set_srp_server_param, -SSL_set_srp_server_param_pw, -SSL_get_srp_g, -SSL_get_srp_N, -SSL_get_srp_username, -SSL_get_srp_userinfo -\&\- SRP control operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 10 -\& int SSL_CTX_set_srp_username(SSL_CTX *ctx, char *name); -\& int SSL_CTX_set_srp_password(SSL_CTX *ctx, char *password); -\& int SSL_CTX_set_srp_strength(SSL_CTX *ctx, int strength); -\& int SSL_CTX_set_srp_cb_arg(SSL_CTX *ctx, void *arg); -\& int SSL_CTX_set_srp_username_callback(SSL_CTX *ctx, -\& int (*cb) (SSL *s, int *ad, void *arg)); -\& int SSL_CTX_set_srp_client_pwd_callback(SSL_CTX *ctx, -\& char *(*cb) (SSL *s, void *arg)); -\& int SSL_CTX_set_srp_verify_param_callback(SSL_CTX *ctx, -\& int (*cb) (SSL *s, void *arg)); -\& -\& int SSL_set_srp_server_param(SSL *s, const BIGNUM *N, const BIGNUM *g, -\& BIGNUM *sa, BIGNUM *v, char *info); -\& int SSL_set_srp_server_param_pw(SSL *s, const char *user, const char *pass, -\& const char *grp); -\& -\& BIGNUM *SSL_get_srp_g(SSL *s); -\& BIGNUM *SSL_get_srp_N(SSL *s); -\& -\& char *SSL_get_srp_username(SSL *s); -\& char *SSL_get_srp_userinfo(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All of the functions described on this page are deprecated. There are no -available replacement functions at this time. -.PP -These functions provide access to \s-1SRP\s0 (Secure Remote Password) parameters, -an alternate authentication mechanism for \s-1TLS. SRP\s0 allows the use of usernames -and passwords over unencrypted channels without revealing the password to an -eavesdropper. \s-1SRP\s0 also supplies a shared secret at the end of the authentication -sequence that can be used to generate encryption keys. -.PP -The \s-1SRP\s0 protocol, version 3 is specified in \s-1RFC 2945. SRP\s0 version 6 is described -in \s-1RFC 5054\s0 with applications to \s-1TLS\s0 authentication. -.PP -The \fBSSL_CTX_set_srp_username()\fR function sets the \s-1SRP\s0 username for \fBctx\fR. This -should be called on the client prior to creating a connection to the server. -The length of \fBname\fR must be shorter or equal to 255 characters. -.PP -The \fBSSL_CTX_set_srp_password()\fR function sets the \s-1SRP\s0 password for \fBctx\fR. This -may be called on the client prior to creating a connection to the server. -This overrides the effect of \fBSSL_CTX_set_srp_client_pwd_callback()\fR. -.PP -The \fBSSL_CTX_set_srp_strength()\fR function sets the \s-1SRP\s0 strength for \fBctx\fR. This -is the minimal length of the \s-1SRP\s0 prime in bits. If not specified 1024 is used. -If not satisfied by the server key exchange the connection will be rejected. -.PP -The \fBSSL_CTX_set_srp_cb_arg()\fR function sets an extra parameter that will -be passed to all following callbacks as \fBarg\fR. -.PP -The \fBSSL_CTX_set_srp_username_callback()\fR function sets the server side callback -that is invoked when an \s-1SRP\s0 username is found in a ClientHello. -The callback parameters are the \s-1SSL\s0 connection \fBs\fR, a writable error flag \fBad\fR -and the extra argument \fBarg\fR set by \fBSSL_CTX_set_srp_cb_arg()\fR. -This callback should setup the server for the key exchange by calling -\&\fBSSL_set_srp_server_param()\fR with the appropriate parameters for the received -username. The username can be obtained by calling \fBSSL_get_srp_username()\fR. -See \fBSRP_VBASE_init\fR\|(3) to parse the verifier file created by \fBopenssl\-srp\fR\|(1) or -\&\fBSRP_create_verifier\fR\|(3) to generate it. -The callback should return \fB\s-1SSL_ERROR_NONE\s0\fR to proceed with the server key exchange, -\&\fB\s-1SSL3_AL_FATAL\s0\fR for a fatal error or any value < 0 for a retryable error. -In the event of a \fB\s-1SSL3_AL_FATAL\s0\fR the alert flag given by \fB*al\fR will be sent -back. By default this will be \fB\s-1SSL_AD_UNKNOWN_PSK_IDENTITY\s0\fR. -.PP -The \fBSSL_CTX_set_srp_client_pwd_callback()\fR function sets the client password -callback on the client. -The callback parameters are the \s-1SSL\s0 connection \fBs\fR and the extra argument \fBarg\fR -set by \fBSSL_CTX_set_srp_cb_arg()\fR. -The callback will be called as part of the generation of the client secrets. -It should return the client password in text form or \s-1NULL\s0 to abort the connection. -The resulting memory will be freed by the library as part of the callback resolution. -This overrides the effect of \fBSSL_CTX_set_srp_password()\fR. -.PP -The \fBSSL_CTX_set_srp_verify_param_callback()\fR sets the \s-1SRP\s0 gN parameter verification -callback on the client. This allows the client to perform custom verification when -receiving the server \s-1SRP\s0 proposed parameters. -The callback parameters are the \s-1SSL\s0 connection \fBs\fR and the extra argument \fBarg\fR -set by \fBSSL_CTX_set_srp_cb_arg()\fR. -The callback should return a positive value to accept the server parameters. -Returning 0 or a negative value will abort the connection. The server parameters -can be obtained by calling \fBSSL_get_srp_N()\fR and \fBSSL_get_srp_g()\fR. -Sanity checks are already performed by the library after the handshake -(B % N non zero, check against the strength parameter) and are not necessary. -If no callback is set the g and N parameters will be checked against -known \s-1RFC 5054\s0 values. -.PP -The \fBSSL_set_srp_server_param()\fR function sets all \s-1SRP\s0 parameters for -the connection \fBs\fR. \fBN\fR and \fBg\fR are the \s-1SRP\s0 group parameters, \fBsa\fR is the -user salt, \fBv\fR the password verifier and \fBinfo\fR is the optional user info. -.PP -The \fBSSL_set_srp_server_param_pw()\fR function sets all \s-1SRP\s0 parameters for the -connection \fBs\fR by generating a random salt and a password verifier. -\&\fBuser\fR is the username, \fBpass\fR the password and \fBgrp\fR the \s-1SRP\s0 group parameters -identifier for \fBSRP_get_default_gN\fR\|(3). -.PP -The \fBSSL_get_srp_g()\fR function returns the \s-1SRP\s0 group generator for \fBs\fR, or from -the underlying \s-1SSL_CTX\s0 if it is \s-1NULL.\s0 -.PP -The \fBSSL_get_srp_N()\fR function returns the \s-1SRP\s0 prime for \fBs\fR, or from -the underlying \s-1SSL_CTX\s0 if it is \s-1NULL.\s0 -.PP -The \fBSSL_get_srp_username()\fR function returns the \s-1SRP\s0 username for \fBs\fR, or from -the underlying \s-1SSL_CTX\s0 if it is \s-1NULL.\s0 -.PP -The \fBSSL_get_srp_userinfo()\fR function returns the \s-1SRP\s0 user info for \fBs\fR, or from -the underlying \s-1SSL_CTX\s0 if it is \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All SSL_CTX_set_* functions return 1 on success and 0 on failure. -.PP -\&\fBSSL_set_srp_server_param()\fR returns 1 on success and \-1 on failure. -.PP -The SSL_get_SRP_* functions return a pointer to the requested data, the memory -is owned by the library and should not be freed by the caller. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Setup \s-1SRP\s0 parameters on the client: -.PP -.Vb 1 -\& #include -\& -\& const char *username = "username"; -\& const char *password = "password"; -\& -\& SSL_CTX *ctx = SSL_CTX_new(TLS_client_method()); -\& if (!ctx) -\& /* Error */ -\& if (!SSL_CTX_set_srp_username(ctx, username)) -\& /* Error */ -\& if (!SSL_CTX_set_srp_password(ctx, password)) -\& /* Error */ -.Ve -.PP -Setup \s-1SRP\s0 server with verifier file: -.PP -.Vb 2 -\& #include -\& #include -\& -\& const char *srpvfile = "password.srpv"; -\& -\& int srpServerCallback(SSL *s, int *ad, void *arg) -\& { -\& SRP_VBASE *srpData = (SRP_VBASE*) arg; -\& char *username = SSL_get_srp_username(s); -\& -\& SRP_user_pwd *user_pwd = SRP_VBASE_get1_by_user(srpData, username); -\& if (!user_pwd) -\& /* Error */ -\& return SSL3_AL_FATAL; -\& -\& if (SSL_set_srp_server_param(s, user_pwd\->N, user_pwd\->g, -\& user_pwd\->s, user_pwd\->v, user_pwd\->info) < 0) -\& /* Error */ -\& -\& SRP_user_pwd_free(user_pwd); -\& return SSL_ERROR_NONE; -\& } -\& -\& SSL_CTX *ctx = SSL_CTX_new(TLS_server_method()); -\& if (!ctx) -\& /* Error */ -\& -\& /* -\& * seedKey should contain a NUL terminated sequence -\& * of random non NUL bytes -\& */ -\& const char *seedKey; -\& -\& SRP_VBASE *srpData = SRP_VBASE_new(seedKey); -\& if (SRP_VBASE_init(srpData, (char*) srpvfile) != SRP_NO_ERROR) -\& /* Error */ -\& -\& SSL_CTX_set_srp_cb_arg(ctx, srpData); -\& SSL_CTX_set_srp_username_callback(ctx, srpServerCallback); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBopenssl\-srp\fR\|(1), -\&\fBSRP_VBASE_new\fR\|(3), -\&\fBSRP_create_verifier\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.1 and deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_srp_strength.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_srp_strength.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_srp_strength.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_srp_username.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_srp_username.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_srp_username.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_srp_username_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_srp_username_callback.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_srp_username_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_srp_verify_param_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_srp_verify_param_callback.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_srp_verify_param_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_ssl_version.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_ssl_version.3ossl deleted file mode 100644 index 55915f84..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_ssl_version.3ossl +++ /dev/null @@ -1,216 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_SSL_VERSION 3ossl" -.TH SSL_CTX_SET_SSL_VERSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_ssl_version, SSL_CTX_get_ssl_method, SSL_set_ssl_method, SSL_get_ssl_method -\&\- choose a new TLS/SSL method -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_ssl_version(SSL_CTX *ctx, const SSL_METHOD *method); -\& const SSL_METHOD *SSL_CTX_get_ssl_method(const SSL_CTX *ctx); -\& -\& int SSL_set_ssl_method(SSL *s, const SSL_METHOD *method); -\& const SSL_METHOD *SSL_get_ssl_method(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_ssl_version()\fR sets a new default \s-1TLS/SSL\s0 \fBmethod\fR for \s-1SSL\s0 objects -newly created from this \fBctx\fR. Most of the configuration attached to the -\&\s-1SSL_CTX\s0 object is retained, with the exception of the configured \s-1TLS\s0 ciphers, -which are reset to the default values. \s-1SSL\s0 objects already created from this -\&\s-1SSL_CTX\s0 with \fBSSL_new\fR\|(3) are not affected, except when \fBSSL_clear\fR\|(3) is -being called, as described below. -.PP -\&\fBSSL_CTX_get_ssl_method()\fR returns the \s-1SSL_METHOD\s0 which was used to construct the -\&\s-1SSL_CTX.\s0 -.PP -\&\fBSSL_set_ssl_method()\fR sets a new \s-1TLS/SSL\s0 \fBmethod\fR for a particular \fBssl\fR -object. It may be reset, when \fBSSL_clear()\fR is called. -.PP -\&\fBSSL_get_ssl_method()\fR returns a pointer to the \s-1TLS/SSL\s0 method -set in \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -The available \fBmethod\fR choices are described in -\&\fBSSL_CTX_new\fR\|(3). -.PP -When \fBSSL_clear\fR\|(3) is called and no session is connected to -an \s-1SSL\s0 object, the method of the \s-1SSL\s0 object is reset to the method currently -set in the corresponding \s-1SSL_CTX\s0 object. -.PP -\&\fBSSL_CTX_set_version()\fR has unusual semantics and no clear use case; -it would usually be preferable to create a new \s-1SSL_CTX\s0 object than to -try to reuse an existing one in this fashion. Its usage is considered -deprecated. -.PP -\&\fBSSL_set_ssl_method()\fR cannot be used to change a non-QUIC \s-1SSL\s0 object to a \s-1QUIC -SSL\s0 object or vice versa, or change a \s-1QUIC SSL\s0 object from one \s-1QUIC\s0 method to -another. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur for \fBSSL_CTX_set_ssl_version()\fR -and \fBSSL_set_ssl_method()\fR: -.IP "0" 4 -The new choice failed, check the error stack to find out the reason. -.IP "1" 4 -.IX Item "1" -The operation succeeded. -.PP -\&\fBSSL_CTX_get_ssl_method()\fR and \fBSSL_get_ssl_method()\fR always return non-NULL -pointers. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_new\fR\|(3), \fBSSL_new\fR\|(3), -\&\fBSSL_clear\fR\|(3), \fBssl\fR\|(7), -\&\fBSSL_set_connect_state\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_CTX_set_ssl_version()\fR was deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_generate_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_generate_cb.3ossl deleted file mode 100644 index 6e54248c..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_generate_cb.3ossl +++ /dev/null @@ -1,227 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_STATELESS_COOKIE_GENERATE_CB 3ossl" -.TH SSL_CTX_SET_STATELESS_COOKIE_GENERATE_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_stateless_cookie_generate_cb, -SSL_CTX_set_stateless_cookie_verify_cb, -SSL_CTX_set_cookie_generate_cb, -SSL_CTX_set_cookie_verify_cb -\&\- Callback functions for stateless TLS1.3 cookies -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_CTX_set_stateless_cookie_generate_cb( -\& SSL_CTX *ctx, -\& int (*gen_stateless_cookie_cb) (SSL *ssl, -\& unsigned char *cookie, -\& size_t *cookie_len)); -\& void SSL_CTX_set_stateless_cookie_verify_cb( -\& SSL_CTX *ctx, -\& int (*verify_stateless_cookie_cb) (SSL *ssl, -\& const unsigned char *cookie, -\& size_t cookie_len)); -\& -\& void SSL_CTX_set_cookie_generate_cb(SSL_CTX *ctx, -\& int (*app_gen_cookie_cb) (SSL *ssl, -\& unsigned char -\& *cookie, -\& unsigned int -\& *cookie_len)); -\& void SSL_CTX_set_cookie_verify_cb(SSL_CTX *ctx, -\& int (*app_verify_cookie_cb) (SSL *ssl, -\& const unsigned -\& char *cookie, -\& unsigned int -\& cookie_len)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_stateless_cookie_generate_cb()\fR sets the callback used by -\&\fBSSL_stateless\fR\|(3) to generate the application-controlled portion of the cookie -provided to clients in the HelloRetryRequest transmitted as a response to a -ClientHello with a missing or invalid cookie. \fBgen_stateless_cookie_cb()\fR must -write at most \s-1SSL_COOKIE_LENGTH\s0 bytes into \fBcookie\fR, and must write the number -of bytes written to \fBcookie_len\fR. If a cookie cannot be generated, a zero -return value can be used to abort the handshake. -.PP -\&\fBSSL_CTX_set_stateless_cookie_verify_cb()\fR sets the callback used by -\&\fBSSL_stateless\fR\|(3) to determine whether the application-controlled portion of a -ClientHello cookie is valid. The cookie data is pointed to by \fBcookie\fR and is of -length \fBcookie_len\fR. A nonzero return value from \fBverify_stateless_cookie_cb()\fR -communicates that the cookie is valid. The integrity of the entire cookie, -including the application-controlled portion, is automatically verified by \s-1HMAC\s0 -before \fBverify_stateless_cookie_cb()\fR is called. -.PP -\&\fBSSL_CTX_set_cookie_generate_cb()\fR sets the callback used by \fBDTLSv1_listen\fR\|(3) -to generate the cookie provided to clients in the HelloVerifyRequest transmitted -as a response to a ClientHello with a missing or invalid cookie. -\&\fBapp_gen_cookie_cb()\fR must write at most \s-1DTLS1_COOKIE_LENGTH\s0 bytes into -\&\fBcookie\fR, and must write the number of bytes written to \fBcookie_len\fR. If a -cookie cannot be generated, a zero return value can be used to abort the -handshake. -.PP -\&\fBSSL_CTX_set_cookie_verify_cb()\fR sets the callback used by \fBDTLSv1_listen\fR\|(3) to -determine whether the cookie in a ClientHello is valid. The cookie data is -pointed to by \fBcookie\fR and is of length \fBcookie_len\fR. A nonzero return value -from \fBapp_verify_cookie_cb()\fR communicates that the cookie is valid. The -integrity of the cookie is not verified by OpenSSL. This is an application -responsibility. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Neither function returns a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_stateless\fR\|(3), -\&\fBDTLSv1_listen\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_CTX_set_stateless_cookie_generate_cb()\fR and -\&\fBSSL_CTX_set_stateless_cookie_verify_cb()\fR were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_verify_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_verify_cb.3ossl deleted file mode 120000 index e3679a79..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_stateless_cookie_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_stateless_cookie_generate_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_timeout.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_timeout.3ossl deleted file mode 100644 index c98f3c39..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_timeout.3ossl +++ /dev/null @@ -1,209 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_TIMEOUT 3ossl" -.TH SSL_CTX_SET_TIMEOUT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_timeout, SSL_CTX_get_timeout \- manipulate timeout values for session caching -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_timeout(SSL_CTX *ctx, long t); -\& long SSL_CTX_get_timeout(SSL_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_timeout()\fR sets the timeout for newly created sessions for -\&\fBctx\fR to \fBt\fR. The timeout value \fBt\fR must be given in seconds. -.PP -\&\fBSSL_CTX_get_timeout()\fR returns the currently set timeout value for \fBctx\fR. -.SH "NOTES" -.IX Header "NOTES" -Whenever a new session is created, it is assigned a maximum lifetime. This -lifetime is specified by storing the creation time of the session and the -timeout value valid at this time. If the actual time is later than creation -time plus timeout, the session is not reused. -.PP -Due to this realization, all sessions behave according to the timeout value -valid at the time of the session negotiation. Changes of the timeout value -do not affect already established sessions. -.PP -The expiration time of a single session can be modified using the -\&\fBSSL_SESSION_get_time\fR\|(3) family of functions. -.PP -Expired sessions are removed from the internal session cache, whenever -\&\fBSSL_CTX_flush_sessions\fR\|(3) is called, either -directly by the application or automatically (see -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3)) -.PP -The default value for session timeout is decided on a per protocol -basis, see \fBSSL_get_default_timeout\fR\|(3). -All currently supported protocols have the same default timeout value -of 300 seconds. -.PP -This timeout value is used as the ticket lifetime hint for stateless session -tickets. It is also used as the timeout value within the ticket itself. -.PP -For TLSv1.3, \s-1RFC8446\s0 limits transmission of this value to 1 week (604800 -seconds). -.PP -For TLSv1.2, tickets generated during an initial handshake use the value -as specified. Tickets generated during a resumed handshake have a value -of 0 for the ticket lifetime hint. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_timeout()\fR returns the previously set timeout value. -.PP -\&\fBSSL_CTX_get_timeout()\fR returns the currently set timeout value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -\&\fBSSL_SESSION_get_time\fR\|(3), -\&\fBSSL_CTX_flush_sessions\fR\|(3), -\&\fBSSL_get_default_timeout\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_max_fragment_length.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_max_fragment_length.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_max_fragment_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_arg.3ossl deleted file mode 120000 index f62c51f3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_servername_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_callback.3ossl deleted file mode 100644 index ae2dbfb0..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_servername_callback.3ossl +++ /dev/null @@ -1,287 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_TLSEXT_SERVERNAME_CALLBACK 3ossl" -.TH SSL_CTX_SET_TLSEXT_SERVERNAME_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_tlsext_servername_callback, SSL_CTX_set_tlsext_servername_arg, -SSL_get_servername_type, SSL_get_servername, -SSL_set_tlsext_host_name \- handle server name indication (SNI) -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_tlsext_servername_callback(SSL_CTX *ctx, -\& int (*cb)(SSL *s, int *al, void *arg)); -\& long SSL_CTX_set_tlsext_servername_arg(SSL_CTX *ctx, void *arg); -\& -\& const char *SSL_get_servername(const SSL *s, const int type); -\& int SSL_get_servername_type(const SSL *s); -\& -\& int SSL_set_tlsext_host_name(const SSL *s, const char *name); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functionality provided by the servername callback is mostly superseded by -the ClientHello callback, which can be set using \fBSSL_CTX_set_client_hello_cb()\fR. -However, even where the ClientHello callback is used, the servername callback is -still necessary in order to acknowledge the servername requested by the client. -.PP -\&\fBSSL_CTX_set_tlsext_servername_callback()\fR sets the application callback \fBcb\fR -used by a server to perform any actions or configuration required based on -the servername extension received in the incoming connection. When \fBcb\fR -is \s-1NULL, SNI\s0 is not used. -.PP -The servername callback should return one of the following values: -.IP "\s-1SSL_TLSEXT_ERR_OK\s0" 4 -.IX Item "SSL_TLSEXT_ERR_OK" -This is used to indicate that the servername requested by the client has been -accepted. Typically a server will call \fBSSL_set_SSL_CTX()\fR in the callback to set -up a different configuration for the selected servername in this case. -.IP "\s-1SSL_TLSEXT_ERR_ALERT_FATAL\s0" 4 -.IX Item "SSL_TLSEXT_ERR_ALERT_FATAL" -In this case the servername requested by the client is not accepted and the -handshake will be aborted. The value of the alert to be used should be stored in -the location pointed to by the \fBal\fR parameter to the callback. By default this -value is initialised to \s-1SSL_AD_UNRECOGNIZED_NAME.\s0 -.IP "\s-1SSL_TLSEXT_ERR_ALERT_WARNING\s0" 4 -.IX Item "SSL_TLSEXT_ERR_ALERT_WARNING" -If this value is returned then the servername is not accepted by the server. -However, the handshake will continue and send a warning alert instead. The value -of the alert should be stored in the location pointed to by the \fBal\fR parameter -as for \s-1SSL_TLSEXT_ERR_ALERT_FATAL\s0 above. Note that TLSv1.3 does not support -warning alerts, so if TLSv1.3 has been negotiated then this return value is -treated the same way as \s-1SSL_TLSEXT_ERR_NOACK.\s0 -.IP "\s-1SSL_TLSEXT_ERR_NOACK\s0" 4 -.IX Item "SSL_TLSEXT_ERR_NOACK" -This return value indicates that the servername is not accepted by the server. -No alerts are sent and the server will not acknowledge the requested servername. -.PP -\&\fBSSL_CTX_set_tlsext_servername_arg()\fR sets a context-specific argument to be -passed into the callback (via the \fBarg\fR parameter) for this \fB\s-1SSL_CTX\s0\fR. -.PP -The behaviour of \fBSSL_get_servername()\fR depends on a number of different factors. -In particular note that in TLSv1.3 the servername is negotiated in every -handshake. In TLSv1.2 the servername is only negotiated on initial handshakes -and not on resumption handshakes. -.IP "On the client, before the handshake" 4 -.IX Item "On the client, before the handshake" -If a servername has been set via a call to \fBSSL_set_tlsext_host_name()\fR then it -will return that servername. -.Sp -If one has not been set, but a TLSv1.2 resumption is being attempted and the -session from the original handshake had a servername accepted by the server then -it will return that servername. -.Sp -Otherwise it returns \s-1NULL.\s0 -.IP "On the client, during or after the handshake and a TLSv1.2 (or below) resumption occurred" 4 -.IX Item "On the client, during or after the handshake and a TLSv1.2 (or below) resumption occurred" -If the session from the original handshake had a servername accepted by the -server then it will return that servername. -.Sp -Otherwise it returns the servername set via \fBSSL_set_tlsext_host_name()\fR or \s-1NULL\s0 -if it was not called. -.IP "On the client, during or after the handshake and a TLSv1.2 (or below) resumption did not occur" 4 -.IX Item "On the client, during or after the handshake and a TLSv1.2 (or below) resumption did not occur" -It will return the servername set via \fBSSL_set_tlsext_host_name()\fR or \s-1NULL\s0 if it -was not called. -.IP "On the server, before the handshake" 4 -.IX Item "On the server, before the handshake" -The function will always return \s-1NULL\s0 before the handshake -.IP "On the server, after the servername extension has been processed and a TLSv1.2 (or below) resumption occurred" 4 -.IX Item "On the server, after the servername extension has been processed and a TLSv1.2 (or below) resumption occurred" -If a servername was accepted by the server in the original handshake then it -will return that servername, or \s-1NULL\s0 otherwise. -.IP "On the server, after the servername extension has been processed and a TLSv1.2 (or below) resumption did not occur" 4 -.IX Item "On the server, after the servername extension has been processed and a TLSv1.2 (or below) resumption did not occur" -The function will return the servername requested by the client in this -handshake or \s-1NULL\s0 if none was requested. -.PP -Note that the ClientHello callback occurs before a servername extension from the -client is processed. The servername, certificate and \s-1ALPN\s0 callbacks occur after -a servername extension from the client is processed. -.PP -\&\fBSSL_get_servername_type()\fR returns the servername type or \-1 if no servername -is present. Currently the only supported type (defined in \s-1RFC3546\s0) is -\&\fBTLSEXT_NAMETYPE_host_name\fR. -.PP -\&\fBSSL_set_tlsext_host_name()\fR sets the server name indication ClientHello extension -to contain the value \fBname\fR. The type of server name indication extension is set -to \fBTLSEXT_NAMETYPE_host_name\fR (defined in \s-1RFC3546\s0). -.SH "NOTES" -.IX Header "NOTES" -Several callbacks are executed during ClientHello processing, including -the ClientHello, \s-1ALPN,\s0 and servername callbacks. The ClientHello callback is -executed first, then the servername callback, followed by the \s-1ALPN\s0 callback. -.PP -The \fBSSL_set_tlsext_host_name()\fR function should only be called on \s-1SSL\s0 objects -that will act as clients; otherwise the configured \fBname\fR will be ignored. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_tlsext_servername_callback()\fR and -\&\fBSSL_CTX_set_tlsext_servername_arg()\fR both always return 1 indicating success. -\&\fBSSL_set_tlsext_host_name()\fR returns 1 on success, 0 in case of error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_alpn_select_cb\fR\|(3), -\&\fBSSL_get0_alpn_selected\fR\|(3), \fBSSL_CTX_set_client_hello_cb\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_get_servername()\fR historically provided some unexpected results in certain -corner cases. This has been fixed from OpenSSL 1.1.1e. -.PP -Prior to 1.1.1e, when the client requested a servername in an initial TLSv1.2 -handshake, the server accepted it, and then the client successfully resumed but -set a different explicit servername in the second handshake then when called by -the client it returned the servername from the second handshake. This has now -been changed to return the servername requested in the original handshake. -.PP -Also prior to 1.1.1e, if the client sent a servername in the first handshake but -the server did not accept it, and then a second handshake occurred where TLSv1.2 -resumption was successful then when called by the server it returned the -servername requested in the original handshake. This has now been changed to -\&\s-1NULL.\s0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_arg.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_arg.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_cb.3ossl deleted file mode 100644 index 0dbfd5ee..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_cb.3ossl +++ /dev/null @@ -1,258 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_TLSEXT_STATUS_CB 3ossl" -.TH SSL_CTX_SET_TLSEXT_STATUS_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_tlsext_status_cb, -SSL_CTX_get_tlsext_status_cb, -SSL_CTX_set_tlsext_status_arg, -SSL_CTX_get_tlsext_status_arg, -SSL_CTX_set_tlsext_status_type, -SSL_CTX_get_tlsext_status_type, -SSL_set_tlsext_status_type, -SSL_get_tlsext_status_type, -SSL_get_tlsext_status_ocsp_resp, -SSL_set_tlsext_status_ocsp_resp -\&\- OCSP Certificate Status Request functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_tlsext_status_cb(SSL_CTX *ctx, int (*callback)(SSL *, void *)); -\& long SSL_CTX_get_tlsext_status_cb(SSL_CTX *ctx, int (**callback)(SSL *, void *)); -\& -\& long SSL_CTX_set_tlsext_status_arg(SSL_CTX *ctx, void *arg); -\& long SSL_CTX_get_tlsext_status_arg(SSL_CTX *ctx, void **arg); -\& -\& long SSL_CTX_set_tlsext_status_type(SSL_CTX *ctx, int type); -\& long SSL_CTX_get_tlsext_status_type(SSL_CTX *ctx); -\& -\& long SSL_set_tlsext_status_type(SSL *s, int type); -\& long SSL_get_tlsext_status_type(SSL *s); -\& -\& long SSL_get_tlsext_status_ocsp_resp(ssl, unsigned char **resp); -\& long SSL_set_tlsext_status_ocsp_resp(ssl, unsigned char *resp, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A client application may request that a server send back an \s-1OCSP\s0 status response -(also known as \s-1OCSP\s0 stapling). To do so the client should call the -\&\fBSSL_CTX_set_tlsext_status_type()\fR function prior to the creation of any \s-1SSL\s0 -objects. Alternatively an application can call the \fBSSL_set_tlsext_status_type()\fR -function on an individual \s-1SSL\s0 object prior to the start of the handshake. -Currently the only supported type is \fBTLSEXT_STATUSTYPE_ocsp\fR. This value -should be passed in the \fBtype\fR argument. Calling -\&\fBSSL_CTX_get_tlsext_status_type()\fR will return the type \fBTLSEXT_STATUSTYPE_ocsp\fR -previously set via \fBSSL_CTX_set_tlsext_status_type()\fR or \-1 if not set. -.PP -The client should additionally provide a callback function to decide what to do -with the returned \s-1OCSP\s0 response by calling \fBSSL_CTX_set_tlsext_status_cb()\fR. The -callback function should determine whether the returned \s-1OCSP\s0 response is -acceptable or not. The callback will be passed as an argument the value -previously set via a call to \fBSSL_CTX_set_tlsext_status_arg()\fR. Note that the -callback will not be called in the event of a handshake where session resumption -occurs (because there are no Certificates exchanged in such a handshake). -The callback previously set via \fBSSL_CTX_set_tlsext_status_cb()\fR can be retrieved -by calling \fBSSL_CTX_get_tlsext_status_cb()\fR, and the argument by calling -\&\fBSSL_CTX_get_tlsext_status_arg()\fR. -.PP -On the client side \fBSSL_get_tlsext_status_type()\fR can be used to determine whether -the client has previously called \fBSSL_set_tlsext_status_type()\fR. It will return -\&\fBTLSEXT_STATUSTYPE_ocsp\fR if it has been called or \-1 otherwise. On the server -side \fBSSL_get_tlsext_status_type()\fR can be used to determine whether the client -requested \s-1OCSP\s0 stapling. If the client requested it then this function will -return \fBTLSEXT_STATUSTYPE_ocsp\fR, or \-1 otherwise. -.PP -The response returned by the server can be obtained via a call to -\&\fBSSL_get_tlsext_status_ocsp_resp()\fR. The value \fB*resp\fR will be updated to point -to the \s-1OCSP\s0 response data and the return value will be the length of that data. -Typically a callback would obtain an \s-1OCSP_RESPONSE\s0 object from this data via a -call to the \fBd2i_OCSP_RESPONSE()\fR function. If the server has not provided any -response data then \fB*resp\fR will be \s-1NULL\s0 and the return value from -\&\fBSSL_get_tlsext_status_ocsp_resp()\fR will be \-1. -.PP -A server application must also call the \fBSSL_CTX_set_tlsext_status_cb()\fR function -if it wants to be able to provide clients with \s-1OCSP\s0 Certificate Status -responses. Typically the server callback would obtain the server certificate -that is being sent back to the client via a call to \fBSSL_get_certificate()\fR; -obtain the \s-1OCSP\s0 response to be sent back; and then set that response data by -calling \fBSSL_set_tlsext_status_ocsp_resp()\fR. A pointer to the response data should -be provided in the \fBresp\fR argument, and the length of that data should be in -the \fBlen\fR argument. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The callback when used on the client side should return a negative value on -error; 0 if the response is not acceptable (in which case the handshake will -fail) or a positive value if it is acceptable. -.PP -The callback when used on the server side should return with either -\&\s-1SSL_TLSEXT_ERR_OK\s0 (meaning that the \s-1OCSP\s0 response that has been set should be -returned), \s-1SSL_TLSEXT_ERR_NOACK\s0 (meaning that an \s-1OCSP\s0 response should not be -returned) or \s-1SSL_TLSEXT_ERR_ALERT_FATAL\s0 (meaning that a fatal error has -occurred). -.PP -\&\fBSSL_CTX_set_tlsext_status_cb()\fR, \fBSSL_CTX_set_tlsext_status_arg()\fR, -\&\fBSSL_CTX_set_tlsext_status_type()\fR, \fBSSL_set_tlsext_status_type()\fR and -\&\fBSSL_set_tlsext_status_ocsp_resp()\fR return 0 on error or 1 on success. -.PP -\&\fBSSL_CTX_get_tlsext_status_type()\fR returns the value previously set by -\&\fBSSL_CTX_set_tlsext_status_type()\fR, or \-1 if not set. -.PP -\&\fBSSL_get_tlsext_status_ocsp_resp()\fR returns the length of the \s-1OCSP\s0 response data -or \-1 if there is no \s-1OCSP\s0 response data. -.PP -\&\fBSSL_get_tlsext_status_type()\fR returns \fBTLSEXT_STATUSTYPE_ocsp\fR on the client -side if \fBSSL_set_tlsext_status_type()\fR was previously called, or on the server -side if the client requested \s-1OCSP\s0 stapling. Otherwise \-1 is returned. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_get_tlsext_status_type()\fR, \fBSSL_CTX_get_tlsext_status_type()\fR -and \fBSSL_CTX_set_tlsext_status_type()\fR functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_type.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_type.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_status_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_cb.3ossl deleted file mode 100644 index 85c93d62..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_cb.3ossl +++ /dev/null @@ -1,375 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_TLSEXT_TICKET_KEY_CB 3ossl" -.TH SSL_CTX_SET_TLSEXT_TICKET_KEY_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_tlsext_ticket_key_evp_cb, -SSL_CTX_set_tlsext_ticket_key_cb -\&\- set a callback for session ticket processing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL_CTX sslctx, -\& int (*cb)(SSL *s, unsigned char key_name[16], -\& unsigned char iv[EVP_MAX_IV_LENGTH], -\& EVP_CIPHER_CTX *ctx, EVP_MAC_CTX *hctx, int enc)); -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& int SSL_CTX_set_tlsext_ticket_key_cb(SSL_CTX sslctx, -\& int (*cb)(SSL *s, unsigned char key_name[16], -\& unsigned char iv[EVP_MAX_IV_LENGTH], -\& EVP_CIPHER_CTX *ctx, HMAC_CTX *hctx, int enc)); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_tlsext_ticket_key_evp_cb()\fR sets a callback function \fIcb\fR for handling -session tickets for the ssl context \fIsslctx\fR. Session tickets, defined in -\&\s-1RFC5077\s0 provide an enhanced session resumption capability where the server -implementation is not required to maintain per session state. It only applies -to \s-1TLS\s0 and there is no SSLv3 implementation. -.PP -The callback function \fIcb\fR will be called for every client instigated \s-1TLS\s0 -session when session ticket extension is presented in the \s-1TLS\s0 hello -message. It is the responsibility of this function to create or retrieve the -cryptographic parameters and to maintain their state. -.PP -The OpenSSL library uses your callback function to help implement a common \s-1TLS\s0 -ticket construction state according to \s-1RFC5077\s0 Section 4 such that per session -state is unnecessary and a small set of cryptographic variables needs to be -maintained by the callback function implementation. -.PP -In order to reuse a session, a \s-1TLS\s0 client must send the session ticket -extension to the server. The client must send exactly one session ticket. -The server, through the callback function, either agrees to reuse the session -ticket information or it starts a full \s-1TLS\s0 handshake to create a new session -ticket. -.PP -Before the callback function is started \fIctx\fR and \fIhctx\fR have been -initialised with \fBEVP_CIPHER_CTX_reset\fR\|(3) and \fBEVP_MAC_CTX_new\fR\|(3) -respectively. -.PP -For new sessions tickets, when the client doesn't present a session ticket, or -an attempted retrieval of the ticket failed, or a renew option was indicated, -the callback function will be called with \fIenc\fR equal to 1. The OpenSSL -library expects that the function will set an arbitrary \fIname\fR, initialize -\&\fIiv\fR, and set the cipher context \fIctx\fR and the hash context \fIhctx\fR. -.PP -The \fIname\fR is 16 characters long and is used as a key identifier. -.PP -The \fIiv\fR length is the length of the \s-1IV\s0 of the corresponding cipher. The -maximum \s-1IV\s0 length is \fB\s-1EVP_MAX_IV_LENGTH\s0\fR bytes defined in \fI\fR. -.PP -The initialization vector \fIiv\fR should be a random value. The cipher context -\&\fIctx\fR should use the initialisation vector \fIiv\fR. The cipher context can be -set using \fBEVP_EncryptInit_ex\fR\|(3). The hmac context and digest can be set using -\&\fBEVP_MAC_CTX_set_params\fR\|(3) with the \fB\s-1OSSL_MAC_PARAM_KEY\s0\fR and -\&\fB\s-1OSSL_MAC_PARAM_DIGEST\s0\fR parameters respectively. -.PP -When the client presents a session ticket, the callback function with be called -with \fIenc\fR set to 0 indicating that the \fIcb\fR function should retrieve a set -of parameters. In this case \fIname\fR and \fIiv\fR have already been parsed out of -the session ticket. The OpenSSL library expects that the \fIname\fR will be used -to retrieve a cryptographic parameters and that the cryptographic context -\&\fIctx\fR will be set with the retrieved parameters and the initialization vector -\&\fIiv\fR. using a function like \fBEVP_DecryptInit_ex\fR\|(3). The key material and -digest for \fIhctx\fR need to be set using \fBEVP_MAC_CTX_set_params\fR\|(3) with the -\&\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR and \fB\s-1OSSL_MAC_PARAM_DIGEST\s0\fR parameters respectively. -.PP -If the \fIname\fR is still valid but a renewal of the ticket is required the -callback function should return 2. The library will call the callback again -with an argument of enc equal to 1 to set the new ticket. -.PP -The return value of the \fIcb\fR function is used by OpenSSL to determine what -further processing will occur. The following return values have meaning: -.IP "2" 4 -.IX Item "2" -This indicates that the \fIctx\fR and \fIhctx\fR have been set and the session can -continue on those parameters. Additionally it indicates that the session -ticket is in a renewal period and should be replaced. The OpenSSL library will -call \fIcb\fR again with an enc argument of 1 to set the new ticket (see \s-1RFC5077 -3.3\s0 paragraph 2). -.IP "1" 4 -.IX Item "1" -This indicates that the \fIctx\fR and \fIhctx\fR have been set and the session can -continue on those parameters. -.IP "0" 4 -This indicates that it was not possible to set/retrieve a session ticket and -the \s-1SSL/TLS\s0 session will continue by negotiating a set of cryptographic -parameters or using the alternate \s-1SSL/TLS\s0 resumption mechanism, session ids. -.Sp -If called with enc equal to 0 the library will call the \fIcb\fR again to get -a new set of parameters. -.IP "less than 0" 4 -.IX Item "less than 0" -This indicates an error. -.PP -The \fBSSL_CTX_set_tlsext_ticket_key_cb()\fR function is identical to -\&\fBSSL_CTX_set_tlsext_ticket_key_evp_cb()\fR except that it takes a deprecated -\&\s-1HMAC_CTX\s0 pointer instead of an \s-1EVP_MAC_CTX\s0 one. -Before this callback function is started \fIhctx\fR will have been -initialised with \fBEVP_MAC_CTX_new\fR\|(3) and the digest set with -\&\fBEVP_MAC_CTX_set_params\fR\|(3). -The \fIhctx\fR key material can be set using \fBHMAC_Init_ex\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -Session resumption shortcuts the \s-1TLS\s0 handshake so that the client certificate -negotiation doesn't occur. It makes up for this by storing the client certificate -and all other negotiated state information encrypted within the ticket. In a -resumed session the applications will have all this state information available -exactly as if a full negotiation had occurred. -.PP -If an attacker can obtain the key used to encrypt a session ticket, they can -obtain the master secret for any ticket using that key and decrypt any traffic -using that session: even if the cipher suite supports forward secrecy. As -a result applications may wish to use multiple keys and avoid using long term -keys stored in files. -.PP -Applications can use longer keys to maintain a consistent level of security. -For example if a cipher suite uses 256 bit ciphers but only a 128 bit ticket key -the overall security is only 128 bits because breaking the ticket key will -enable an attacker to obtain the session keys. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 to indicate the callback function was set and 0 otherwise. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Reference Implementation: -.PP -.Vb 2 -\& SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL, ssl_tlsext_ticket_key_cb); -\& ... -\& -\& static int ssl_tlsext_ticket_key_cb(SSL *s, unsigned char key_name[16], -\& unsigned char *iv, EVP_CIPHER_CTX *ctx, -\& EVP_MAC_CTX *hctx, int enc) -\& { -\& OSSL_PARAM params[3]; -\& your_type_t *key; /* something that you need to implement */ -\& -\& if (enc) { /* create new session */ -\& if (RAND_bytes(iv, EVP_MAX_IV_LENGTH) <= 0) -\& return \-1; /* insufficient random */ -\& -\& key = currentkey(); /* something that you need to implement */ -\& if (key == NULL) { -\& /* current key doesn\*(Aqt exist or isn\*(Aqt valid */ -\& key = createkey(); /* -\& * Something that you need to implement. -\& * createkey needs to initialise a name, -\& * an aes_key, a hmac_key and optionally -\& * an expire time. -\& */ -\& if (key == NULL) /* key couldn\*(Aqt be created */ -\& return 0; -\& } -\& memcpy(key_name, key\->name, 16); -\& -\& if (EVP_EncryptInit_ex(&ctx, EVP_aes_256_cbc(), NULL, key\->aes_key, -\& iv) == 0) -\& return \-1; /* error in cipher initialisation */ -\& -\& params[0] = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY, -\& key\->hmac_key, 32); -\& params[1] = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST, -\& "sha256", 0); -\& params[2] = OSSL_PARAM_construct_end(); -\& if (EVP_MAC_CTX_set_params(hctx, params) == 0) -\& return \-1; /* error in mac initialisation */ -\& -\& return 1; -\& -\& } else { /* retrieve session */ -\& time_t t = time(NULL); -\& key = findkey(key_name); /* something that you need to implement */ -\& -\& if (key == NULL || key\->expire < t) -\& return 0; -\& -\& params[0] = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -\& key\->hmac_key, 32); -\& params[1] = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST, -\& "sha256", 0); -\& params[2] = OSSL_PARAM_construct_end(); -\& if (EVP_MAC_CTX_set_params(hctx, params) == 0) -\& return \-1; /* error in mac initialisation */ -\& -\& if (EVP_DecryptInit_ex(&ctx, EVP_aes_256_cbc(), NULL, key\->aes_key, -\& iv) == 0) -\& return \-1; /* error in cipher initialisation */ -\& -\& if (key\->expire < t \- RENEW_TIME) { /* RENEW_TIME: implement */ -\& /* -\& * return 2 \- This session will get a new ticket even though the -\& * current one is still valid. -\& */ -\& return 2; -\& } -\& return 1; -\& } -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_set_session\fR\|(3), -\&\fBSSL_session_reused\fR\|(3), -\&\fBSSL_CTX_add_session\fR\|(3), -\&\fBSSL_CTX_sess_number\fR\|(3), -\&\fBSSL_CTX_sess_set_get_cb\fR\|(3), -\&\fBSSL_CTX_set_session_id_context\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_CTX_set_tlsext_ticket_key_cb()\fR function was deprecated in OpenSSL 3.0. -.PP -The \fBSSL_CTX_set_tlsext_ticket_key_evp_cb()\fR function was introduced in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2014\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_evp_cb.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_evp_cb.3ossl deleted file mode 120000 index 012c67c3..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_ticket_key_evp_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_ticket_key_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_use_srtp.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tlsext_use_srtp.3ossl deleted file mode 100644 index 2d0b563e..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tlsext_use_srtp.3ossl +++ /dev/null @@ -1,264 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_TLSEXT_USE_SRTP 3ossl" -.TH SSL_CTX_SET_TLSEXT_USE_SRTP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_tlsext_use_srtp, -SSL_set_tlsext_use_srtp, -SSL_get_srtp_profiles, -SSL_get_selected_srtp_profile -\&\- Configure and query SRTP support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_tlsext_use_srtp(SSL_CTX *ctx, const char *profiles); -\& int SSL_set_tlsext_use_srtp(SSL *ssl, const char *profiles); -\& -\& STACK_OF(SRTP_PROTECTION_PROFILE) *SSL_get_srtp_profiles(SSL *ssl); -\& SRTP_PROTECTION_PROFILE *SSL_get_selected_srtp_profile(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1SRTP\s0 is the Secure Real-Time Transport Protocol. OpenSSL implements support for -the \*(L"use_srtp\*(R" \s-1DTLS\s0 extension defined in \s-1RFC5764.\s0 This provides a mechanism for -establishing \s-1SRTP\s0 keying material, algorithms and parameters using \s-1DTLS.\s0 This -capability may be used as part of an implementation that conforms to \s-1RFC5763.\s0 -OpenSSL does not implement \s-1SRTP\s0 itself or \s-1RFC5763.\s0 Note that OpenSSL does not -support the use of \s-1SRTP\s0 Master Key Identifiers (MKIs). Also note that this -extension is only supported in \s-1DTLS.\s0 Any \s-1SRTP\s0 configuration will be ignored if a -\&\s-1TLS\s0 connection is attempted. -.PP -An OpenSSL client wishing to send the \*(L"use_srtp\*(R" extension should call -\&\fBSSL_CTX_set_tlsext_use_srtp()\fR to set its use for all \s-1SSL\s0 objects subsequently -created from an \s-1SSL_CTX.\s0 Alternatively a client may call -\&\fBSSL_set_tlsext_use_srtp()\fR to set its use for an individual \s-1SSL\s0 object. The -\&\fBprofiles\fR parameters should point to a NUL-terminated, colon delimited list of -\&\s-1SRTP\s0 protection profile names. -.PP -The currently supported protection profile names are: -.IP "\s-1SRTP_AES128_CM_SHA1_80\s0" 4 -.IX Item "SRTP_AES128_CM_SHA1_80" -This corresponds to \s-1SRTP_AES128_CM_HMAC_SHA1_80\s0 defined in \s-1RFC5764.\s0 -.IP "\s-1SRTP_AES128_CM_SHA1_32\s0" 4 -.IX Item "SRTP_AES128_CM_SHA1_32" -This corresponds to \s-1SRTP_AES128_CM_HMAC_SHA1_32\s0 defined in \s-1RFC5764.\s0 -.IP "\s-1SRTP_AEAD_AES_128_GCM\s0" 4 -.IX Item "SRTP_AEAD_AES_128_GCM" -This corresponds to the profile of the same name defined in \s-1RFC7714.\s0 -.IP "\s-1SRTP_AEAD_AES_256_GCM\s0" 4 -.IX Item "SRTP_AEAD_AES_256_GCM" -This corresponds to the profile of the same name defined in \s-1RFC7714.\s0 -.IP "\s-1SRTP_DOUBLE_AEAD_AES_128_GCM_AEAD_AES_128_GCM\s0" 4 -.IX Item "SRTP_DOUBLE_AEAD_AES_128_GCM_AEAD_AES_128_GCM" -This corresponds to the profile of the same name defined in \s-1RFC8723.\s0 -.IP "\s-1SRTP_DOUBLE_AEAD_AES_256_GCM_AEAD_AES_256_GCM\s0" 4 -.IX Item "SRTP_DOUBLE_AEAD_AES_256_GCM_AEAD_AES_256_GCM" -This corresponds to the profile of the same name defined in \s-1RFC8723.\s0 -.IP "\s-1SRTP_ARIA_128_CTR_HMAC_SHA1_80\s0" 4 -.IX Item "SRTP_ARIA_128_CTR_HMAC_SHA1_80" -This corresponds to the profile of the same name defined in \s-1RFC8269.\s0 -.IP "\s-1SRTP_ARIA_128_CTR_HMAC_SHA1_32\s0" 4 -.IX Item "SRTP_ARIA_128_CTR_HMAC_SHA1_32" -This corresponds to the profile of the same name defined in \s-1RFC8269.\s0 -.IP "\s-1SRTP_ARIA_256_CTR_HMAC_SHA1_80\s0" 4 -.IX Item "SRTP_ARIA_256_CTR_HMAC_SHA1_80" -This corresponds to the profile of the same name defined in \s-1RFC8269.\s0 -.IP "\s-1SRTP_ARIA_256_CTR_HMAC_SHA1_32\s0" 4 -.IX Item "SRTP_ARIA_256_CTR_HMAC_SHA1_32" -This corresponds to the profile of the same name defined in \s-1RFC8269.\s0 -.IP "\s-1SRTP_AEAD_ARIA_128_GCM\s0" 4 -.IX Item "SRTP_AEAD_ARIA_128_GCM" -This corresponds to the profile of the same name defined in \s-1RFC8269.\s0 -.IP "\s-1SRTP_AEAD_ARIA_256_GCM\s0" 4 -.IX Item "SRTP_AEAD_ARIA_256_GCM" -This corresponds to the profile of the same name defined in \s-1RFC8269.\s0 -.PP -Supplying an unrecognised protection profile name will result in an error. -.PP -An OpenSSL server wishing to support the \*(L"use_srtp\*(R" extension should also call -\&\fBSSL_CTX_set_tlsext_use_srtp()\fR or \fBSSL_set_tlsext_use_srtp()\fR to indicate the -protection profiles that it is willing to negotiate. -.PP -The currently configured list of protection profiles for either a client or a -server can be obtained by calling \fBSSL_get_srtp_profiles()\fR. This returns a stack -of \s-1SRTP_PROTECTION_PROFILE\s0 objects. The memory pointed to in the return value of -this function should not be freed by the caller. -.PP -After a handshake has been completed the negotiated \s-1SRTP\s0 protection profile (if -any) can be obtained (on the client or the server) by calling -\&\fBSSL_get_selected_srtp_profile()\fR. This function will return \s-1NULL\s0 if no \s-1SRTP\s0 -protection profile was negotiated. The memory returned from this function should -not be freed by the caller. -.PP -If an \s-1SRTP\s0 protection profile has been successfully negotiated then the \s-1SRTP\s0 -keying material (on both the client and server) should be obtained via a call to -\&\fBSSL_export_keying_material\fR\|(3). This call should provide a label value of -\&\*(L"EXTRACTOR\-dtls_srtp\*(R" and a \s-1NULL\s0 context value (use_context is 0). The total -length of keying material obtained should be equal to two times the sum of the -master key length and the salt length as defined for the protection profile in -use. This provides the client write master key, the server write master key, the -client write master salt and the server write master salt in that order. -.PP -These functions cannot be used with \s-1QUIC SSL\s0 objects. -\&\fBSSL_CTX_set_tlsext_use_srtp()\fR fails if called on a \s-1QUIC SSL\s0 context. -\&\fBSSL_set_tlsext_use_srtp()\fR fails if called on a \s-1QUIC SSL\s0 object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_tlsext_use_srtp()\fR and \fBSSL_set_tlsext_use_srtp()\fR return 0 on success -or 1 on error. -.PP -\&\fBSSL_get_srtp_profiles()\fR returns a stack of \s-1SRTP_PROTECTION_PROFILE\s0 objects on -success or \s-1NULL\s0 on error or if no protection profiles have been configured. -.PP -\&\fBSSL_get_selected_srtp_profile()\fR returns a pointer to an \s-1SRTP_PROTECTION_PROFILE\s0 -object if one has been negotiated or \s-1NULL\s0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_export_keying_material\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tmp_dh.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tmp_dh.3ossl deleted file mode 120000 index 838d6609..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tmp_dh.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_dh_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tmp_dh_callback.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tmp_dh_callback.3ossl deleted file mode 100644 index ee6438b9..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tmp_dh_callback.3ossl +++ /dev/null @@ -1,256 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_TMP_DH_CALLBACK 3ossl" -.TH SSL_CTX_SET_TMP_DH_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_dh_auto, SSL_set_dh_auto, SSL_CTX_set0_tmp_dh_pkey, -SSL_set0_tmp_dh_pkey, SSL_CTX_set_tmp_dh_callback, SSL_CTX_set_tmp_dh, -SSL_set_tmp_dh_callback, SSL_set_tmp_dh -\&\- handle DH keys for ephemeral key exchange -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_dh_auto(SSL_CTX *ctx, int onoff); -\& long SSL_set_dh_auto(SSL *s, int onoff); -\& int SSL_CTX_set0_tmp_dh_pkey(SSL_CTX *ctx, EVP_PKEY *dhpkey); -\& int SSL_set0_tmp_dh_pkey(SSL *s, EVP_PKEY *dhpkey); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& void SSL_CTX_set_tmp_dh_callback(SSL_CTX *ctx, -\& DH *(*tmp_dh_callback)(SSL *ssl, int is_export, -\& int keylength)); -\& long SSL_CTX_set_tmp_dh(SSL_CTX *ctx, DH *dh); -\& -\& void SSL_set_tmp_dh_callback(SSL *ctx, -\& DH *(*tmp_dh_callback)(SSL *ssl, int is_export, -\& int keylength)); -\& long SSL_set_tmp_dh(SSL *ssl, DH *dh); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions described on this page are relevant for servers only. -.PP -Some ciphersuites may use ephemeral Diffie-Hellman (\s-1DH\s0) key exchange. In these -cases, the session data is negotiated using the ephemeral/temporary \s-1DH\s0 key and -the key supplied and certified by the certificate chain is only used for -signing. Anonymous ciphers (without a permanent server key) also use ephemeral -\&\s-1DH\s0 keys. -.PP -Using ephemeral \s-1DH\s0 key exchange yields forward secrecy as the connection -can only be decrypted when the \s-1DH\s0 key is known. By generating a temporary -\&\s-1DH\s0 key inside the server application that is lost when the application -is left, it becomes impossible for an attacker to decrypt past sessions, -even if they get hold of the normal (certified) key, as this key was -only used for signing. -.PP -In order to perform a \s-1DH\s0 key exchange the server must use a \s-1DH\s0 group -(\s-1DH\s0 parameters) and generate a \s-1DH\s0 key. The server will always generate -a new \s-1DH\s0 key during the negotiation. -.PP -As generating \s-1DH\s0 parameters is extremely time consuming, an application -should not generate the parameters on the fly. \s-1DH\s0 parameters can be reused, as -the actual key is newly generated during the negotiation. -.PP -Typically applications should use well known \s-1DH\s0 parameters that have built-in -support in OpenSSL. The macros \fBSSL_CTX_set_dh_auto()\fR and \fBSSL_set_dh_auto()\fR -configure OpenSSL to use the default built-in \s-1DH\s0 parameters for the \fB\s-1SSL_CTX\s0\fR -and \fB\s-1SSL\s0\fR objects respectively. Passing a value of 1 in the \fIonoff\fR parameter -switches the feature on, and passing a value of 0 switches it off. The default -setting is off. -.PP -If \*(L"auto\*(R" \s-1DH\s0 parameters are switched on then the parameters will be selected to -be consistent with the size of the key associated with the server's certificate. -If there is no certificate (e.g. for \s-1PSK\s0 ciphersuites), then it it will be -consistent with the size of the negotiated symmetric cipher key. -.PP -Applications may supply their own \s-1DH\s0 parameters instead of using the built-in -values. This approach is discouraged and applications should in preference use -the built-in parameter support described above. Applications wishing to supply -their own \s-1DH\s0 parameters should call \fBSSL_CTX_set0_tmp_dh_pkey()\fR or -\&\fBSSL_set0_tmp_dh_pkey()\fR to supply the parameters for the \fB\s-1SSL_CTX\s0\fR or \fB\s-1SSL\s0\fR -respectively. The parameters should be supplied in the \fIdhpkey\fR argument as -an \fB\s-1EVP_PKEY\s0\fR containing \s-1DH\s0 parameters. Ownership of the \fIdhpkey\fR value is -passed to the \fB\s-1SSL_CTX\s0\fR or \fB\s-1SSL\s0\fR object as a result of this call, and so the -caller should not free it if the function call is successful. -.PP -The deprecated macros \fBSSL_CTX_set_tmp_dh()\fR and \fBSSL_set_tmp_dh()\fR do the same -thing as \fBSSL_CTX_set0_tmp_dh_pkey()\fR and \fBSSL_set0_tmp_dh_pkey()\fR except that the -\&\s-1DH\s0 parameters are supplied in a \fB\s-1DH\s0\fR object instead in the \fIdh\fR argument, and -ownership of the \fB\s-1DH\s0\fR object is retained by the application. Applications -should use \*(L"auto\*(R" parameters instead, or call \fBSSL_CTX_set0_tmp_dh_pkey()\fR or -\&\fBSSL_set0_tmp_dh_pkey()\fR as appropriate. -.PP -An application may instead specify the \s-1DH\s0 parameters via a callback function -using the functions \fBSSL_CTX_set_tmp_dh_callback()\fR or \fBSSL_set_tmp_dh_callback()\fR -to set the callback for the \fB\s-1SSL_CTX\s0\fR or \fB\s-1SSL\s0\fR object respectively. These -functions are deprecated. Applications should instead use \*(L"auto\*(R" parameters, or -specify the parameters via \fBSSL_CTX_set0_tmp_dh_pkey()\fR or \fBSSL_set0_tmp_dh_pkey()\fR -as appropriate. -.PP -The callback will be invoked during a connection when \s-1DH\s0 parameters are -required. The \fB\s-1SSL\s0\fR object for the current connection is supplied as an -argument. Previous versions of OpenSSL used the \fBis_export\fR and \fBkeylength\fR -arguments to control parameter generation for export and non-export -cipher suites. Modern OpenSSL does not support export ciphersuites and so these -arguments are unused and can be ignored by the callback. The callback should -return the parameters to be used in a \s-1DH\s0 object. Ownership of the \s-1DH\s0 object is -retained by the application and should later be freed. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All of these functions/macros return 1 for success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_cipher_list\fR\|(3), -\&\fBSSL_CTX_set_options\fR\|(3), -\&\fBopenssl\-ciphers\fR\|(1), \fBopenssl\-dhparam\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_tmp_ecdh.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_tmp_ecdh.3ossl deleted file mode 100644 index fd476258..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_tmp_ecdh.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_TMP_ECDH 3ossl" -.TH SSL_CTX_SET_TMP_ECDH 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_tmp_ecdh, SSL_set_tmp_ecdh, SSL_CTX_set_ecdh_auto, SSL_set_ecdh_auto -\&\- handle ECDH keys for ephemeral key exchange -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_CTX_set_tmp_ecdh(SSL_CTX *ctx, const EC_KEY *ecdh); -\& long SSL_set_tmp_ecdh(SSL *ssl, const EC_KEY *ecdh); -\& -\& long SSL_CTX_set_ecdh_auto(SSL_CTX *ctx, int state); -\& long SSL_set_ecdh_auto(SSL *ssl, int state); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_tmp_ecdh()\fR sets \s-1ECDH\s0 parameters to be used to be \fBecdh\fR. -The key is inherited by all \fBssl\fR objects created from \fBctx\fR. -This macro is deprecated in favor of \fBSSL_CTX_set1_groups\fR\|(3). -.PP -\&\fBSSL_set_tmp_ecdh()\fR sets the parameters only for \fBssl\fR. -This macro is deprecated in favor of \fBSSL_set1_groups\fR\|(3). -.PP -\&\fBSSL_CTX_set_ecdh_auto()\fR and \fBSSL_set_ecdh_auto()\fR are deprecated and -have no effect. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_tmp_ecdh()\fR and \fBSSL_set_tmp_ecdh()\fR return 1 on success and 0 -on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set1_curves\fR\|(3), \fBSSL_CTX_set_cipher_list\fR\|(3), -\&\fBSSL_CTX_set_options\fR\|(3), \fBSSL_CTX_set_tmp_dh_callback\fR\|(3), -\&\fBopenssl\-ciphers\fR\|(1), \fBopenssl\-ecparam\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_trust.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_trust.3ossl deleted file mode 120000 index fd781e23..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_trust.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_set_verify.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_verify.3ossl deleted file mode 100644 index 1eaa56e9..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_verify.3ossl +++ /dev/null @@ -1,500 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_SET_VERIFY 3ossl" -.TH SSL_CTX_SET_VERIFY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_ex_data_X509_STORE_CTX_idx, -SSL_CTX_set_verify, SSL_set_verify, -SSL_CTX_set_verify_depth, SSL_set_verify_depth, -SSL_verify_cb, -SSL_verify_client_post_handshake, -SSL_set_post_handshake_auth, -SSL_CTX_set_post_handshake_auth -\&\- set various SSL/TLS parameters for peer certificate verification -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*SSL_verify_cb)(int preverify_ok, X509_STORE_CTX *x509_ctx); -\& -\& void SSL_CTX_set_verify(SSL_CTX *ctx, int mode, SSL_verify_cb verify_callback); -\& void SSL_set_verify(SSL *ssl, int mode, SSL_verify_cb verify_callback); -\& SSL_get_ex_data_X509_STORE_CTX_idx(void); -\& -\& void SSL_CTX_set_verify_depth(SSL_CTX *ctx, int depth); -\& void SSL_set_verify_depth(SSL *ssl, int depth); -\& -\& int SSL_verify_client_post_handshake(SSL *ssl); -\& void SSL_CTX_set_post_handshake_auth(SSL_CTX *ctx, int val); -\& void SSL_set_post_handshake_auth(SSL *ssl, int val); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_verify()\fR sets the verification flags for \fBctx\fR to be \fBmode\fR and -specifies the \fBverify_callback\fR function to be used. If no callback function -shall be specified, the \s-1NULL\s0 pointer can be used for \fBverify_callback\fR. -.PP -\&\fBSSL_set_verify()\fR sets the verification flags for \fBssl\fR to be \fBmode\fR and -specifies the \fBverify_callback\fR function to be used. If no callback function -shall be specified, the \s-1NULL\s0 pointer can be used for \fBverify_callback\fR. In -this case last \fBverify_callback\fR set specifically for this \fBssl\fR remains. If -no special \fBcallback\fR was set before, the default callback for the underlying -\&\fBctx\fR is used, that was valid at the time \fBssl\fR was created with -\&\fBSSL_new\fR\|(3). Within the callback function, -\&\fBSSL_get_ex_data_X509_STORE_CTX_idx\fR can be called to get the data index -of the current \s-1SSL\s0 object that is doing the verification. -.PP -In client mode \fBverify_callback\fR may also call the \fBSSL_set_retry_verify\fR\|(3) -function on the \fB\s-1SSL\s0\fR object set in the \fIx509_store_ctx\fR ex data (see -\&\fBSSL_get_ex_data_X509_STORE_CTX_idx\fR\|(3)) and return 1. -This would be typically done in case the certificate verification was not yet -able to succeed. -This makes the handshake suspend and return control to the calling application -with \fB\s-1SSL_ERROR_WANT_RETRY_VERIFY\s0\fR. -The application can for instance fetch further certificates or cert status -information needed for the verification. -Calling \fBSSL_connect\fR\|(3) again resumes the connection attempt by retrying the -server certificate verification step. -This process may even be repeated if need be. -Note that the handshake may still be aborted if a subsequent invocation of the -callback (e.g., at a lower depth, or for a separate error condition) returns 0. -.PP -\&\fBSSL_CTX_set_verify_depth()\fR sets the maximum \fBdepth\fR for the certificate chain -verification that shall be allowed for \fBctx\fR. -.PP -\&\fBSSL_set_verify_depth()\fR sets the maximum \fBdepth\fR for the certificate chain -verification that shall be allowed for \fBssl\fR. -.PP -\&\fBSSL_CTX_set_post_handshake_auth()\fR and \fBSSL_set_post_handshake_auth()\fR enable the -Post-Handshake Authentication extension to be added to the ClientHello such that -post-handshake authentication can be requested by the server. If \fBval\fR is 0 -then the extension is not sent, otherwise it is. By default the extension is not -sent. A certificate callback will need to be set via -\&\fBSSL_CTX_set_client_cert_cb()\fR if no certificate is provided at initialization. -.PP -\&\fBSSL_verify_client_post_handshake()\fR causes a CertificateRequest message to be -sent by a server on the given \fBssl\fR connection. The \s-1SSL_VERIFY_PEER\s0 flag must -be set; the \s-1SSL_VERIFY_POST_HANDSHAKE\s0 flag is optional. -.SH "NOTES" -.IX Header "NOTES" -The verification of certificates can be controlled by a set of logically -or'ed \fBmode\fR flags: -.IP "\s-1SSL_VERIFY_NONE\s0" 4 -.IX Item "SSL_VERIFY_NONE" -\&\fBServer mode:\fR the server will not send a client certificate request to the -client, so the client will not send a certificate. -.Sp -\&\fBClient mode:\fR if not using an anonymous cipher (by default disabled), the -server will send a certificate which will be checked. The result of the -certificate verification process can be checked after the \s-1TLS/SSL\s0 handshake -using the \fBSSL_get_verify_result\fR\|(3) function. -The handshake will be continued regardless of the verification result. -.IP "\s-1SSL_VERIFY_PEER\s0" 4 -.IX Item "SSL_VERIFY_PEER" -\&\fBServer mode:\fR the server sends a client certificate request to the client. -The certificate returned (if any) is checked. If the verification process -fails, the \s-1TLS/SSL\s0 handshake is -immediately terminated with an alert message containing the reason for -the verification failure. -The behaviour can be controlled by the additional -\&\s-1SSL_VERIFY_FAIL_IF_NO_PEER_CERT, SSL_VERIFY_CLIENT_ONCE\s0 and -\&\s-1SSL_VERIFY_POST_HANDSHAKE\s0 flags. -.Sp -\&\fBClient mode:\fR the server certificate is verified. If the verification process -fails, the \s-1TLS/SSL\s0 handshake is -immediately terminated with an alert message containing the reason for -the verification failure. If no server certificate is sent, because an -anonymous cipher is used, \s-1SSL_VERIFY_PEER\s0 is ignored. -.IP "\s-1SSL_VERIFY_FAIL_IF_NO_PEER_CERT\s0" 4 -.IX Item "SSL_VERIFY_FAIL_IF_NO_PEER_CERT" -\&\fBServer mode:\fR if the client did not return a certificate, the \s-1TLS/SSL\s0 -handshake is immediately terminated with a \*(L"handshake failure\*(R" alert. -This flag must be used together with \s-1SSL_VERIFY_PEER.\s0 -.Sp -\&\fBClient mode:\fR ignored (see \s-1BUGS\s0) -.IP "\s-1SSL_VERIFY_CLIENT_ONCE\s0" 4 -.IX Item "SSL_VERIFY_CLIENT_ONCE" -\&\fBServer mode:\fR only request a client certificate once during the -connection. Do not ask for a client certificate again during -renegotiation or post-authentication if a certificate was requested -during the initial handshake. This flag must be used together with -\&\s-1SSL_VERIFY_PEER.\s0 -.Sp -\&\fBClient mode:\fR ignored (see \s-1BUGS\s0) -.IP "\s-1SSL_VERIFY_POST_HANDSHAKE\s0" 4 -.IX Item "SSL_VERIFY_POST_HANDSHAKE" -\&\fBServer mode:\fR the server will not send a client certificate request -during the initial handshake, but will send the request via -\&\fBSSL_verify_client_post_handshake()\fR. This allows the \s-1SSL_CTX\s0 or \s-1SSL\s0 -to be configured for post-handshake peer verification before the -handshake occurs. This flag must be used together with -\&\s-1SSL_VERIFY_PEER.\s0 TLSv1.3 only; no effect on pre\-TLSv1.3 connections. -.Sp -\&\fBClient mode:\fR ignored (see \s-1BUGS\s0) -.PP -If the \fBmode\fR is \s-1SSL_VERIFY_NONE\s0 none of the other flags may be set. -.PP -If verification flags are not modified explicitly by \f(CW\*(C`SSL_CTX_set_verify()\*(C'\fR -or \f(CW\*(C`SSL_set_verify()\*(C'\fR, the default value will be \s-1SSL_VERIFY_NONE.\s0 -.PP -The actual verification procedure is performed either using the built-in -verification procedure or using another application provided verification -function set with -\&\fBSSL_CTX_set_cert_verify_callback\fR\|(3). -The following descriptions apply in the case of the built-in procedure. An -application provided procedure also has access to the verify depth information -and the \fBverify_callback()\fR function, but the way this information is used -may be different. -.PP -\&\fBSSL_CTX_set_verify_depth()\fR and \fBSSL_set_verify_depth()\fR set a limit on the -number of certificates between the end-entity and trust-anchor certificates. -Neither the -end-entity nor the trust-anchor certificates count against \fBdepth\fR. If the -certificate chain needed to reach a trusted issuer is longer than \fBdepth+2\fR, -X509_V_ERR_CERT_CHAIN_TOO_LONG will be issued. -The depth count is \*(L"level 0:peer certificate\*(R", \*(L"level 1: \s-1CA\s0 certificate\*(R", -\&\*(L"level 2: higher level \s-1CA\s0 certificate\*(R", and so on. Setting the maximum -depth to 2 allows the levels 0, 1, 2 and 3 (0 being the end-entity and 3 the -trust-anchor). -The default depth limit is 100, -allowing for the peer certificate, at most 100 intermediate \s-1CA\s0 certificates and -a final trust anchor certificate. -.PP -The \fBverify_callback\fR function is used to control the behaviour when the -\&\s-1SSL_VERIFY_PEER\s0 flag is set. It must be supplied by the application and -receives two arguments: \fBpreverify_ok\fR indicates, whether the verification of -the certificate in question was passed (preverify_ok=1) or not -(preverify_ok=0). \fBx509_ctx\fR is a pointer to the complete context used -for the certificate chain verification. -.PP -The certificate chain is checked starting with the deepest nesting level -(the root \s-1CA\s0 certificate) and worked upward to the peer's certificate. -At each level signatures and issuer attributes are checked. Whenever -a verification error is found, the error number is stored in \fBx509_ctx\fR -and \fBverify_callback\fR is called with \fBpreverify_ok\fR=0. By applying -X509_CTX_store_* functions \fBverify_callback\fR can locate the certificate -in question and perform additional steps (see \s-1EXAMPLES\s0). If no error is -found for a certificate, \fBverify_callback\fR is called with \fBpreverify_ok\fR=1 -before advancing to the next level. -.PP -The return value of \fBverify_callback\fR controls the strategy of the further -verification process. If \fBverify_callback\fR returns 0, the verification -process is immediately stopped with \*(L"verification failed\*(R" state. If -\&\s-1SSL_VERIFY_PEER\s0 is set, a verification failure alert is sent to the peer and -the \s-1TLS/SSL\s0 handshake is terminated. If \fBverify_callback\fR returns 1, -the verification process is continued. If \fBverify_callback\fR always returns -1, the \s-1TLS/SSL\s0 handshake will not be terminated with respect to verification -failures and the connection will be established. The calling process can -however retrieve the error code of the last verification error using -\&\fBSSL_get_verify_result\fR\|(3) or by maintaining its -own error storage managed by \fBverify_callback\fR. -.PP -If no \fBverify_callback\fR is specified, the default callback will be used. -Its return value is identical to \fBpreverify_ok\fR, so that any verification -failure will lead to a termination of the \s-1TLS/SSL\s0 handshake with an -alert message, if \s-1SSL_VERIFY_PEER\s0 is set. -.PP -After calling \fBSSL_set_post_handshake_auth()\fR, the client will need to add a -certificate or certificate callback to its configuration before it can -successfully authenticate. This must be called before \fBSSL_connect()\fR. -.PP -\&\fBSSL_verify_client_post_handshake()\fR requires that verify flags have been -previously set, and that a client sent the post-handshake authentication -extension. When the client returns a certificate the verify callback will be -invoked. A write operation must take place for the Certificate Request to be -sent to the client, this can be done with \fBSSL_do_handshake()\fR or \fBSSL_write_ex()\fR. -Only one certificate request may be outstanding at any time. -.PP -When post-handshake authentication occurs, a refreshed NewSessionTicket -message is sent to the client. -.PP -Post-handshake authentication cannot be used with \s-1QUIC.\s0 -\&\fBSSL_set_post_handshake_auth()\fR has no effect if called on a \s-1QUIC SSL\s0 object. -.SH "BUGS" -.IX Header "BUGS" -In client mode, it is not checked whether the \s-1SSL_VERIFY_PEER\s0 flag -is set, but whether any flags other than \s-1SSL_VERIFY_NONE\s0 are set. This can -lead to unexpected behaviour if \s-1SSL_VERIFY_PEER\s0 and other flags are not used as -required. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The SSL*_set_verify*() functions do not provide diagnostic information. -.PP -The \fBSSL_verify_client_post_handshake()\fR function returns 1 if the request -succeeded, and 0 if the request failed. The error stack can be examined -to determine the failure reason. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following code sequence realizes an example \fBverify_callback\fR function -that will always continue the \s-1TLS/SSL\s0 handshake regardless of verification -failure, if wished. The callback realizes a verification depth limit with -more informational output. -.PP -All verification errors are printed; information about the certificate chain -is printed on request. -The example is realized for a server that does allow but not require client -certificates. -.PP -The example makes use of the ex_data technique to store application data -into/retrieve application data from the \s-1SSL\s0 structure -(see \fBCRYPTO_get_ex_new_index\fR\|(3), -\&\fBSSL_get_ex_data_X509_STORE_CTX_idx\fR\|(3)). -.PP -.Vb 7 -\& ... -\& typedef struct { -\& int verbose_mode; -\& int verify_depth; -\& int always_continue; -\& } mydata_t; -\& int mydata_index; -\& -\& ... -\& static int verify_callback(int preverify_ok, X509_STORE_CTX *ctx) -\& { -\& char buf[256]; -\& X509 *err_cert; -\& int err, depth; -\& SSL *ssl; -\& mydata_t *mydata; -\& -\& err_cert = X509_STORE_CTX_get_current_cert(ctx); -\& err = X509_STORE_CTX_get_error(ctx); -\& depth = X509_STORE_CTX_get_error_depth(ctx); -\& -\& /* -\& * Retrieve the pointer to the SSL of the connection currently treated -\& * and the application specific data stored into the SSL object. -\& */ -\& ssl = X509_STORE_CTX_get_ex_data(ctx, SSL_get_ex_data_X509_STORE_CTX_idx()); -\& mydata = SSL_get_ex_data(ssl, mydata_index); -\& -\& X509_NAME_oneline(X509_get_subject_name(err_cert), buf, 256); -\& -\& /* -\& * Catch a too long certificate chain. The depth limit set using -\& * SSL_CTX_set_verify_depth() is by purpose set to "limit+1" so -\& * that whenever the "depth>verify_depth" condition is met, we -\& * have violated the limit and want to log this error condition. -\& * We must do it here, because the CHAIN_TOO_LONG error would not -\& * be found explicitly; only errors introduced by cutting off the -\& * additional certificates would be logged. -\& */ -\& if (depth > mydata\->verify_depth) { -\& preverify_ok = 0; -\& err = X509_V_ERR_CERT_CHAIN_TOO_LONG; -\& X509_STORE_CTX_set_error(ctx, err); -\& } -\& if (!preverify_ok) { -\& printf("verify error:num=%d:%s:depth=%d:%s\en", err, -\& X509_verify_cert_error_string(err), depth, buf); -\& } else if (mydata\->verbose_mode) { -\& printf("depth=%d:%s\en", depth, buf); -\& } -\& -\& /* -\& * At this point, err contains the last verification error. We can use -\& * it for something special -\& */ -\& if (!preverify_ok && (err == X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT)) { -\& X509_NAME_oneline(X509_get_issuer_name(err_cert), buf, 256); -\& printf("issuer= %s\en", buf); -\& } -\& -\& if (mydata\->always_continue) -\& return 1; -\& else -\& return preverify_ok; -\& } -\& ... -\& -\& mydata_t mydata; -\& -\& ... -\& mydata_index = SSL_get_ex_new_index(0, "mydata index", NULL, NULL, NULL); -\& -\& ... -\& SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE, -\& verify_callback); -\& -\& /* -\& * Let the verify_callback catch the verify_depth error so that we get -\& * an appropriate error in the logfile. -\& */ -\& SSL_CTX_set_verify_depth(verify_depth + 1); -\& -\& /* -\& * Set up the SSL specific data into "mydata" and store it into th SSL -\& * structure. -\& */ -\& mydata.verify_depth = verify_depth; ... -\& SSL_set_ex_data(ssl, mydata_index, &mydata); -\& -\& ... -\& SSL_accept(ssl); /* check of success left out for clarity */ -\& if (peer = SSL_get_peer_certificate(ssl)) { -\& if (SSL_get_verify_result(ssl) == X509_V_OK) { -\& /* The client sent a certificate which verified OK */ -\& } -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3), -\&\fBSSL_CTX_get_verify_mode\fR\|(3), -\&\fBSSL_get_verify_result\fR\|(3), -\&\fBSSL_CTX_load_verify_locations\fR\|(3), -\&\fBSSL_get_peer_certificate\fR\|(3), -\&\fBSSL_CTX_set_cert_verify_callback\fR\|(3), -\&\fBSSL_get_ex_data_X509_STORE_CTX_idx\fR\|(3), -\&\fBSSL_CTX_set_client_cert_cb\fR\|(3), -\&\fBCRYPTO_get_ex_new_index\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1SSL_VERIFY_POST_HANDSHAKE\s0 option, and the \fBSSL_verify_client_post_handshake()\fR -and \fBSSL_set_post_handshake_auth()\fR functions were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_set_verify_depth.3ossl b/openssl-install/share/man/man3/SSL_CTX_set_verify_depth.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_set_verify_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_up_ref.3ossl b/openssl-install/share/man/man3/SSL_CTX_up_ref.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_ASN1.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_ASN1.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_ASN1.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_PrivateKey_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_ASN1.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_ASN1.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_ASN1.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_RSAPrivateKey_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_cert_and_key.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_cert_and_key.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_cert_and_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_certificate.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_certificate.3ossl deleted file mode 100644 index c87e6e06..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_certificate.3ossl +++ /dev/null @@ -1,337 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_USE_CERTIFICATE 3ossl" -.TH SSL_CTX_USE_CERTIFICATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_use_certificate, SSL_CTX_use_certificate_ASN1, -SSL_CTX_use_certificate_file, SSL_use_certificate, SSL_use_certificate_ASN1, -SSL_use_certificate_file, SSL_CTX_use_certificate_chain_file, -SSL_use_certificate_chain_file, -SSL_CTX_use_PrivateKey, SSL_CTX_use_PrivateKey_ASN1, -SSL_CTX_use_PrivateKey_file, SSL_CTX_use_RSAPrivateKey, -SSL_CTX_use_RSAPrivateKey_ASN1, SSL_CTX_use_RSAPrivateKey_file, -SSL_use_PrivateKey_file, SSL_use_PrivateKey_ASN1, SSL_use_PrivateKey, -SSL_use_RSAPrivateKey, SSL_use_RSAPrivateKey_ASN1, -SSL_use_RSAPrivateKey_file, SSL_CTX_check_private_key, SSL_check_private_key, -SSL_CTX_use_cert_and_key, SSL_use_cert_and_key -\&\- load certificate and key data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_use_certificate(SSL_CTX *ctx, X509 *x); -\& int SSL_CTX_use_certificate_ASN1(SSL_CTX *ctx, int len, const unsigned char *d); -\& int SSL_CTX_use_certificate_file(SSL_CTX *ctx, const char *file, int type); -\& int SSL_use_certificate(SSL *ssl, X509 *x); -\& int SSL_use_certificate_ASN1(SSL *ssl, const unsigned char *d, int len); -\& int SSL_use_certificate_file(SSL *ssl, const char *file, int type); -\& -\& int SSL_CTX_use_certificate_chain_file(SSL_CTX *ctx, const char *file); -\& int SSL_use_certificate_chain_file(SSL *ssl, const char *file); -\& -\& int SSL_CTX_use_PrivateKey(SSL_CTX *ctx, EVP_PKEY *pkey); -\& int SSL_CTX_use_PrivateKey_ASN1(int pk, SSL_CTX *ctx, const unsigned char *d, -\& long len); -\& int SSL_CTX_use_PrivateKey_file(SSL_CTX *ctx, const char *file, int type); -\& int SSL_CTX_use_RSAPrivateKey(SSL_CTX *ctx, RSA *rsa); -\& int SSL_CTX_use_RSAPrivateKey_ASN1(SSL_CTX *ctx, const unsigned char *d, long len); -\& int SSL_CTX_use_RSAPrivateKey_file(SSL_CTX *ctx, const char *file, int type); -\& int SSL_use_PrivateKey(SSL *ssl, EVP_PKEY *pkey); -\& int SSL_use_PrivateKey_ASN1(int pk, SSL *ssl, const unsigned char *d, long len); -\& int SSL_use_PrivateKey_file(SSL *ssl, const char *file, int type); -\& int SSL_use_RSAPrivateKey(SSL *ssl, RSA *rsa); -\& int SSL_use_RSAPrivateKey_ASN1(SSL *ssl, const unsigned char *d, long len); -\& int SSL_use_RSAPrivateKey_file(SSL *ssl, const char *file, int type); -\& -\& int SSL_CTX_check_private_key(const SSL_CTX *ctx); -\& int SSL_check_private_key(const SSL *ssl); -\& -\& int SSL_CTX_use_cert_and_key(SSL_CTX *ctx, X509 *x, EVP_PKEY *pkey, STACK_OF(X509) *chain, int override); -\& int SSL_use_cert_and_key(SSL *ssl, X509 *x, EVP_PKEY *pkey, STACK_OF(X509) *chain, int override); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions load the certificates and private keys into the \s-1SSL_CTX\s0 -or \s-1SSL\s0 object, respectively. -.PP -The SSL_CTX_* class of functions loads the certificates and keys into the -\&\s-1SSL_CTX\s0 object \fBctx\fR. The information is passed to \s-1SSL\s0 objects \fBssl\fR -created from \fBctx\fR with \fBSSL_new\fR\|(3) by copying, so that -changes applied to \fBctx\fR do not propagate to already existing \s-1SSL\s0 objects. -.PP -The SSL_* class of functions only loads certificates and keys into a -specific \s-1SSL\s0 object. The specific information is kept, when -\&\fBSSL_clear\fR\|(3) is called for this \s-1SSL\s0 object. -.PP -\&\fBSSL_CTX_use_certificate()\fR loads the certificate \fBx\fR into \fBctx\fR, -\&\fBSSL_use_certificate()\fR loads \fBx\fR into \fBssl\fR. The rest of the -certificates needed to form the complete certificate chain can be -specified using the -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3) -function. On success the reference counter of the \fBx\fR is incremented. -.PP -\&\fBSSL_CTX_use_certificate_ASN1()\fR loads the \s-1ASN1\s0 encoded certificate from -the memory location \fBd\fR (with length \fBlen\fR) into \fBctx\fR, -\&\fBSSL_use_certificate_ASN1()\fR loads the \s-1ASN1\s0 encoded certificate into \fBssl\fR. -.PP -\&\fBSSL_CTX_use_certificate_file()\fR loads the first certificate stored in \fBfile\fR -into \fBctx\fR. The formatting \fBtype\fR of the certificate must be specified -from the known types \s-1SSL_FILETYPE_PEM, SSL_FILETYPE_ASN1.\s0 -\&\fBSSL_use_certificate_file()\fR loads the certificate from \fBfile\fR into \fBssl\fR. -See the \s-1NOTES\s0 section on why \fBSSL_CTX_use_certificate_chain_file()\fR -should be preferred. -.PP -\&\fBSSL_CTX_use_certificate_chain_file()\fR loads a certificate chain from -\&\fBfile\fR into \fBctx\fR. The certificates must be in \s-1PEM\s0 format and must -be sorted starting with the subject's certificate (actual client or server -certificate), followed by intermediate \s-1CA\s0 certificates if applicable, and -ending at the highest level (root) \s-1CA.\s0 \fBSSL_use_certificate_chain_file()\fR is -similar except it loads the certificate chain into \fBssl\fR. -.PP -\&\fBSSL_CTX_use_PrivateKey()\fR adds \fBpkey\fR as private key to \fBctx\fR. -\&\fBSSL_CTX_use_RSAPrivateKey()\fR adds the private key \fBrsa\fR of type \s-1RSA\s0 -to \fBctx\fR. \fBSSL_use_PrivateKey()\fR adds \fBpkey\fR as private key to \fBssl\fR; -\&\fBSSL_use_RSAPrivateKey()\fR adds \fBrsa\fR as private key of type \s-1RSA\s0 to \fBssl\fR. -If a certificate has already been set and the private key does not belong -to the certificate an error is returned. To change a [certificate/private\-key] -pair, the new certificate needs to be set first with \fBSSL_use_certificate()\fR or -\&\fBSSL_CTX_use_certificate()\fR before setting the private key with -\&\fBSSL_CTX_use_PrivateKey()\fR or \fBSSL_use_PrivateKey()\fR. -On success the reference counter of the \fBpkey\fR/\fBrsa\fR is incremented. -.PP -\&\fBSSL_CTX_use_cert_and_key()\fR and \fBSSL_use_cert_and_key()\fR assign the X.509 -certificate \fBx\fR, private key \fBkey\fR, and certificate \fBchain\fR onto the -corresponding \fBssl\fR or \fBctx\fR. The \fBpkey\fR argument must be the private -key of the X.509 certificate \fBx\fR. If the \fBoverride\fR argument is 0, then -\&\fBx\fR, \fBpkey\fR and \fBchain\fR are set only if all were not previously set. -If \fBoverride\fR is non\-0, then the certificate, private key and chain certs -are always set. If \fBpkey\fR is \s-1NULL,\s0 then the public key of \fBx\fR is used as -the private key. This is intended to be used with hardware (via the \s-1ENGINE\s0 -interface) that stores the private key securely, such that it cannot be -accessed by OpenSSL. The reference count of the public key is incremented -(twice if there is no private key); it is not copied nor duplicated. This -allows all private key validations checks to succeed without an actual -private key being assigned via \fBSSL_CTX_use_PrivateKey()\fR, etc. -.PP -\&\fBSSL_CTX_use_PrivateKey_ASN1()\fR adds the private key of type \fBpk\fR -stored at memory location \fBd\fR (length \fBlen\fR) to \fBctx\fR. -\&\fBSSL_CTX_use_RSAPrivateKey_ASN1()\fR adds the private key of type \s-1RSA\s0 -stored at memory location \fBd\fR (length \fBlen\fR) to \fBctx\fR. -\&\fBSSL_use_PrivateKey_ASN1()\fR and \fBSSL_use_RSAPrivateKey_ASN1()\fR add the private -key to \fBssl\fR. -.PP -\&\fBSSL_CTX_use_PrivateKey_file()\fR adds the first private key found in -\&\fBfile\fR to \fBctx\fR. The formatting \fBtype\fR of the private key must be specified -from the known types \s-1SSL_FILETYPE_PEM, SSL_FILETYPE_ASN1.\s0 -\&\fBSSL_CTX_use_RSAPrivateKey_file()\fR adds the first private \s-1RSA\s0 key found in -\&\fBfile\fR to \fBctx\fR. \fBSSL_use_PrivateKey_file()\fR adds the first private key found -in \fBfile\fR to \fBssl\fR; \fBSSL_use_RSAPrivateKey_file()\fR adds the first private -\&\s-1RSA\s0 key found to \fBssl\fR. -.PP -\&\fBSSL_CTX_check_private_key()\fR checks the consistency of a private key with -the corresponding certificate loaded into \fBctx\fR. If more than one -key/certificate pair (\s-1RSA/DSA\s0) is installed, the last item installed will -be checked. If e.g. the last item was an \s-1RSA\s0 certificate or key, the \s-1RSA\s0 -key/certificate pair will be checked. \fBSSL_check_private_key()\fR performs -the same check for \fBssl\fR. If no key/certificate was explicitly added for -this \fBssl\fR, the last item added into \fBctx\fR will be checked. -.SH "NOTES" -.IX Header "NOTES" -The internal certificate store of OpenSSL can hold several private -key/certificate pairs at a time. The certificate used depends on the -cipher selected, see also \fBSSL_CTX_set_cipher_list\fR\|(3). -.PP -When reading certificates and private keys from file, files of type -\&\s-1SSL_FILETYPE_ASN1\s0 (also known as \fB\s-1DER\s0\fR, binary encoding) can only contain -one certificate or private key, consequently -\&\fBSSL_CTX_use_certificate_chain_file()\fR is only applicable to \s-1PEM\s0 formatting. -Files of type \s-1SSL_FILETYPE_PEM\s0 can contain more than one item. -.PP -\&\fBSSL_CTX_use_certificate_chain_file()\fR adds the first certificate found -in the file to the certificate store. The other certificates are added -to the store of chain certificates using \fBSSL_CTX_add1_chain_cert\fR\|(3). -Note: versions of OpenSSL before 1.0.2 only had a single -certificate chain store for all certificate types, OpenSSL 1.0.2 and later -have a separate chain store for each type. \fBSSL_CTX_use_certificate_chain_file()\fR -should be used instead of the \fBSSL_CTX_use_certificate_file()\fR function in order -to allow the use of complete certificate chains even when no trusted \s-1CA\s0 -storage is used or when the \s-1CA\s0 issuing the certificate shall not be added to -the trusted \s-1CA\s0 storage. -.PP -If additional certificates are needed to complete the chain during the -\&\s-1TLS\s0 negotiation, \s-1CA\s0 certificates are additionally looked up in the -locations of trusted \s-1CA\s0 certificates, see -\&\fBSSL_CTX_load_verify_locations\fR\|(3). -.PP -The private keys loaded from file can be encrypted. In order to successfully -load encrypted keys, a function returning the passphrase must have been -supplied, see -\&\fBSSL_CTX_set_default_passwd_cb\fR\|(3). -(Certificate files might be encrypted as well from the technical point -of view, it however does not make sense as the data in the certificate -is considered public anyway.) -.PP -All of the functions to set a new certificate will replace any existing -certificate of the same type that has already been set. Similarly all of the -functions to set a new private key will replace any private key that has already -been set. Applications should call \fBSSL_CTX_check_private_key\fR\|(3) or -\&\fBSSL_check_private_key\fR\|(3) as appropriate after loading a new certificate and -private key to confirm that the certificate and key match. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -On success, the functions return 1. -Otherwise check out the error stack to find out the reason. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3), \fBSSL_clear\fR\|(3), -\&\fBSSL_CTX_load_verify_locations\fR\|(3), -\&\fBSSL_CTX_set_default_passwd_cb\fR\|(3), -\&\fBSSL_CTX_set_cipher_list\fR\|(3), -\&\fBSSL_CTX_set_client_CA_list\fR\|(3), -\&\fBSSL_CTX_set_client_cert_cb\fR\|(3), -\&\fBSSL_CTX_add_extra_chain_cert\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_use_certificate_ASN1.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_certificate_ASN1.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_certificate_ASN1.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_certificate_chain_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_certificate_chain_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_certificate_chain_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_certificate_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_certificate_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_certificate_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_psk_identity_hint.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_psk_identity_hint.3ossl deleted file mode 100644 index 948f27aa..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_psk_identity_hint.3ossl +++ /dev/null @@ -1,279 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_USE_PSK_IDENTITY_HINT 3ossl" -.TH SSL_CTX_USE_PSK_IDENTITY_HINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_psk_server_cb_func, -SSL_psk_find_session_cb_func, -SSL_CTX_use_psk_identity_hint, -SSL_use_psk_identity_hint, -SSL_CTX_set_psk_server_callback, -SSL_set_psk_server_callback, -SSL_CTX_set_psk_find_session_callback, -SSL_set_psk_find_session_callback -\&\- set PSK identity hint to use -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*SSL_psk_find_session_cb_func)(SSL *ssl, -\& const unsigned char *identity, -\& size_t identity_len, -\& SSL_SESSION **sess); -\& -\& -\& void SSL_CTX_set_psk_find_session_callback(SSL_CTX *ctx, -\& SSL_psk_find_session_cb_func cb); -\& void SSL_set_psk_find_session_callback(SSL *s, SSL_psk_find_session_cb_func cb); -\& -\& typedef unsigned int (*SSL_psk_server_cb_func)(SSL *ssl, -\& const char *identity, -\& unsigned char *psk, -\& unsigned int max_psk_len); -\& -\& int SSL_CTX_use_psk_identity_hint(SSL_CTX *ctx, const char *hint); -\& int SSL_use_psk_identity_hint(SSL *ssl, const char *hint); -\& -\& void SSL_CTX_set_psk_server_callback(SSL_CTX *ctx, SSL_psk_server_cb_func cb); -\& void SSL_set_psk_server_callback(SSL *ssl, SSL_psk_server_cb_func cb); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A server application wishing to use TLSv1.3 PSKs should set a callback -using either \fBSSL_CTX_set_psk_find_session_callback()\fR or -\&\fBSSL_set_psk_find_session_callback()\fR as appropriate. -.PP -The callback function is given a pointer to the \s-1SSL\s0 connection in \fBssl\fR and -an identity in \fBidentity\fR of length \fBidentity_len\fR. The callback function -should identify an \s-1SSL_SESSION\s0 object that provides the \s-1PSK\s0 details and store it -in \fB*sess\fR. The \s-1SSL_SESSION\s0 object should, as a minimum, set the master key, -the ciphersuite and the protocol version. See -\&\fBSSL_CTX_set_psk_use_session_callback\fR\|(3) for details. -.PP -It is also possible for the callback to succeed but not supply a \s-1PSK.\s0 In this -case no \s-1PSK\s0 will be used but the handshake will continue. To do this the -callback should return successfully and ensure that \fB*sess\fR is -\&\s-1NULL.\s0 -.PP -Identity hints are not relevant for TLSv1.3. A server application wishing to use -\&\s-1PSK\s0 ciphersuites for TLSv1.2 and below may call \fBSSL_CTX_use_psk_identity_hint()\fR -to set the given \fB\s-1NUL\s0\fR\-terminated \s-1PSK\s0 identity hint \fBhint\fR for \s-1SSL\s0 context -object \fBctx\fR. \fBSSL_use_psk_identity_hint()\fR sets the given \fB\s-1NUL\s0\fR\-terminated \s-1PSK\s0 -identity hint \fBhint\fR for the \s-1SSL\s0 connection object \fBssl\fR. If \fBhint\fR is -\&\fB\s-1NULL\s0\fR the current hint from \fBctx\fR or \fBssl\fR is deleted. -.PP -In the case where \s-1PSK\s0 identity hint is \fB\s-1NULL\s0\fR, the server does not send the -ServerKeyExchange message to the client. -.PP -A server application wishing to use PSKs for TLSv1.2 and below must provide a -callback function which is called when the server receives the -ClientKeyExchange message from the client. The purpose of the callback function -is to validate the received \s-1PSK\s0 identity and to fetch the pre-shared key used -during the connection setup phase. The callback is set using the functions -\&\fBSSL_CTX_set_psk_server_callback()\fR or \fBSSL_set_psk_server_callback()\fR. The callback -function is given the connection in parameter \fBssl\fR, \fB\s-1NUL\s0\fR\-terminated \s-1PSK\s0 -identity sent by the client in parameter \fBidentity\fR, and a buffer \fBpsk\fR of -length \fBmax_psk_len\fR bytes where the pre-shared key is to be stored. -.PP -The callback for use in TLSv1.2 will also work in TLSv1.3 although it is -recommended to use \fBSSL_CTX_set_psk_find_session_callback()\fR -or \fBSSL_set_psk_find_session_callback()\fR for this purpose instead. If TLSv1.3 has -been negotiated then OpenSSL will first check to see if a callback has been set -via \fBSSL_CTX_set_psk_find_session_callback()\fR or \fBSSL_set_psk_find_session_callback()\fR -and it will use that in preference. If no such callback is present then it will -check to see if a callback has been set via \fBSSL_CTX_set_psk_server_callback()\fR or -\&\fBSSL_set_psk_server_callback()\fR and use that. In this case the handshake digest -will default to \s-1SHA\-256\s0 for any returned \s-1PSK.\s0 TLSv1.3 early data exchanges are -possible in \s-1PSK\s0 connections only with the \fBSSL_psk_find_session_cb_func\fR -callback, and are not possible with the \fBSSL_psk_server_cb_func\fR callback. -.PP -A connection established via a TLSv1.3 \s-1PSK\s0 will appear as if session resumption -has occurred so that \fBSSL_session_reused\fR\|(3) will return true. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fB\fBSSL_CTX_use_psk_identity_hint()\fB\fR and \fB\fBSSL_use_psk_identity_hint()\fB\fR return -1 on success, 0 otherwise. -.PP -Return values from the TLSv1.2 and below server callback are interpreted as -follows: -.IP "0" 4 -\&\s-1PSK\s0 identity was not found. An \*(L"unknown_psk_identity\*(R" alert message -will be sent and the connection setup fails. -.IP ">0" 4 -.IX Item ">0" -\&\s-1PSK\s0 identity was found and the server callback has provided the \s-1PSK\s0 -successfully in parameter \fBpsk\fR. Return value is the length of -\&\fBpsk\fR in bytes. It is an error to return a value greater than -\&\fBmax_psk_len\fR. -.Sp -If the \s-1PSK\s0 identity was not found but the callback instructs the -protocol to continue anyway, the callback must provide some random -data to \fBpsk\fR and return the length of the random data, so the -connection will fail with decryption_error before it will be finished -completely. -.PP -The \fBSSL_psk_find_session_cb_func\fR callback should return 1 on success or 0 on -failure. In the event of failure the connection setup fails. -.SH "NOTES" -.IX Header "NOTES" -There are no known security issues with sharing the same \s-1PSK\s0 between TLSv1.2 (or -below) and TLSv1.3. However, the \s-1RFC\s0 has this note of caution: -.PP -\&\*(L"While there is no known way in which the same \s-1PSK\s0 might produce related output -in both versions, only limited analysis has been done. Implementations can -ensure safety from cross-protocol related output by not reusing PSKs between -\&\s-1TLS 1.3\s0 and \s-1TLS 1.2.\*(R"\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_psk_use_session_callback\fR\|(3), -\&\fBSSL_set_psk_use_session_callback\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_CTX_set_psk_find_session_callback()\fR and \fBSSL_set_psk_find_session_callback()\fR -were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_use_serverinfo.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_serverinfo.3ossl deleted file mode 100644 index 140fb512..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_serverinfo.3ossl +++ /dev/null @@ -1,221 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CTX_USE_SERVERINFO 3ossl" -.TH SSL_CTX_USE_SERVERINFO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_use_serverinfo_ex, -SSL_CTX_use_serverinfo, -SSL_CTX_use_serverinfo_file -\&\- use serverinfo extension -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_use_serverinfo_ex(SSL_CTX *ctx, unsigned int version, -\& const unsigned char *serverinfo, -\& size_t serverinfo_length); -\& -\& int SSL_CTX_use_serverinfo(SSL_CTX *ctx, const unsigned char *serverinfo, -\& size_t serverinfo_length); -\& -\& int SSL_CTX_use_serverinfo_file(SSL_CTX *ctx, const char *file); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions load \*(L"serverinfo\*(R" \s-1TLS\s0 extensions into the \s-1SSL_CTX. A\s0 -\&\*(L"serverinfo\*(R" extension is returned in response to an empty ClientHello -Extension. -.PP -\&\fBSSL_CTX_use_serverinfo_ex()\fR loads one or more serverinfo extensions from -a byte array into \fBctx\fR. The \fBversion\fR parameter specifies the format of the -byte array provided in \fB*serverinfo\fR which is of length \fBserverinfo_length\fR. -.PP -If \fBversion\fR is \fB\s-1SSL_SERVERINFOV2\s0\fR then the extensions in the array must -consist of a 4\-byte context, a 2\-byte Extension Type, a 2\-byte length, and then -length bytes of extension_data. The context and type values have the same -meaning as for \fBSSL_CTX_add_custom_ext\fR\|(3). If serverinfo is being loaded for -extensions to be added to a Certificate message, then the extension will only -be added for the first certificate in the message (which is always the -end-entity certificate). -.PP -If \fBversion\fR is \fB\s-1SSL_SERVERINFOV1\s0\fR then the extensions in the array must -consist of a 2\-byte Extension Type, a 2\-byte length, and then length bytes of -extension_data. The type value has the same meaning as for -\&\fBSSL_CTX_add_custom_ext\fR\|(3). The following default context value will be used -in this case: -.PP -.Vb 2 -\& SSL_EXT_TLS1_2_AND_BELOW_ONLY | SSL_EXT_CLIENT_HELLO -\& | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_IGNORE_ON_RESUMPTION -.Ve -.PP -\&\fBSSL_CTX_use_serverinfo()\fR does the same thing as \fBSSL_CTX_use_serverinfo_ex()\fR -except that there is no \fBversion\fR parameter so a default version of -\&\s-1SSL_SERVERINFOV1\s0 is used instead. -.PP -\&\fBSSL_CTX_use_serverinfo_file()\fR loads one or more serverinfo extensions from -\&\fBfile\fR into \fBctx\fR. The extensions must be in \s-1PEM\s0 format. Each extension -must be in a format as described above for \fBSSL_CTX_use_serverinfo_ex()\fR. Each -\&\s-1PEM\s0 extension name must begin with the phrase \*(L"\s-1BEGIN SERVERINFOV2 FOR \*(R"\s0 for -\&\s-1SSL_SERVERINFOV2\s0 data or \*(L"\s-1BEGIN SERVERINFO FOR \*(R"\s0 for \s-1SSL_SERVERINFOV1\s0 data. -.PP -If more than one certificate (\s-1RSA/DSA\s0) is installed using -\&\fBSSL_CTX_use_certificate()\fR, the serverinfo extension will be loaded into the -last certificate installed. If e.g. the last item was an \s-1RSA\s0 certificate, the -loaded serverinfo extension data will be loaded for that certificate. To -use the serverinfo extension for multiple certificates, -\&\fBSSL_CTX_use_serverinfo()\fR needs to be called multiple times, once \fBafter\fR -each time a certificate is loaded via a call to \fBSSL_CTX_use_certificate()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -On success, the functions return 1. -On failure, the functions return 0. Check out the error stack to find out -the reason. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2013\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_CTX_use_serverinfo_ex.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_serverinfo_ex.3ossl deleted file mode 120000 index 54fa08a7..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_serverinfo_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_serverinfo.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_CTX_use_serverinfo_file.3ossl b/openssl-install/share/man/man3/SSL_CTX_use_serverinfo_file.3ossl deleted file mode 120000 index 54fa08a7..00000000 --- a/openssl-install/share/man/man3/SSL_CTX_use_serverinfo_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_serverinfo.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_BIDI.3ossl b/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_BIDI.3ossl deleted file mode 120000 index 36008190..00000000 --- a/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_BIDI.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_default_stream_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_UNI.3ossl b/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_UNI.3ossl deleted file mode 120000 index 36008190..00000000 --- a/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_AUTO_UNI.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_default_stream_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_NONE.3ossl b/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_NONE.3ossl deleted file mode 120000 index 36008190..00000000 --- a/openssl-install/share/man/man3/SSL_DEFAULT_STREAM_MODE_NONE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_default_stream_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_ACCEPT.3ossl b/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_ACCEPT.3ossl deleted file mode 120000 index dedd760d..00000000 --- a/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_ACCEPT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_incoming_stream_policy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_AUTO.3ossl b/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_AUTO.3ossl deleted file mode 120000 index dedd760d..00000000 --- a/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_AUTO.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_incoming_stream_policy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_REJECT.3ossl b/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_REJECT.3ossl deleted file mode 120000 index dedd760d..00000000 --- a/openssl-install/share/man/man3/SSL_INCOMING_STREAM_POLICY_REJECT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_incoming_stream_policy.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_OP_BIT.3ossl b/openssl-install/share/man/man3/SSL_OP_BIT.3ossl deleted file mode 120000 index 57a93e37..00000000 --- a/openssl-install/share/man/man3/SSL_OP_BIT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CORE_MAKE_FUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_E.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_E.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_E.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_EC.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_EC.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_EC.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_ECD.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_ECD.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_ECD.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_ER.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_ER.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_ER.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_EW.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_EW.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_EW.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_F.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_F.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_F.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_I.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_I.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_I.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_IS.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_IS.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_IS.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_ISB.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_ISB.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_ISB.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_ISE.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_ISE.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_ISE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_ISU.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_ISU.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_ISU.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_NONE.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_NONE.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_NONE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_OS.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_OS.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_OS.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_OSB.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_OSB.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_OSB.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_OSE.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_OSE.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_OSE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_OSU.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_OSU.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_OSU.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_R.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_R.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_R.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_RE.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_RE.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_RE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_RW.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_RW.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_RW.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_RWE.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_RWE.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_RWE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_W.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_W.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_W.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_EVENT_WE.3ossl b/openssl-install/share/man/man3/SSL_POLL_EVENT_WE.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_EVENT_WE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_POLL_FLAG_NO_HANDLE_EVENTS.3ossl b/openssl-install/share/man/man3/SSL_POLL_FLAG_NO_HANDLE_EVENTS.3ossl deleted file mode 120000 index 5c29a1d8..00000000 --- a/openssl-install/share/man/man3/SSL_POLL_FLAG_NO_HANDLE_EVENTS.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_poll.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_dup.3ossl b/openssl-install/share/man/man3/SSL_SESSION_dup.3ossl deleted file mode 120000 index d9535c42..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_free.3ossl b/openssl-install/share/man/man3/SSL_SESSION_free.3ossl deleted file mode 100644 index f16573b7..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_free.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_FREE 3ossl" -.TH SSL_SESSION_FREE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_new, -SSL_SESSION_dup, -SSL_SESSION_up_ref, -SSL_SESSION_free \- create, free and manage SSL_SESSION structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL_SESSION *SSL_SESSION_new(void); -\& SSL_SESSION *SSL_SESSION_dup(const SSL_SESSION *src); -\& int SSL_SESSION_up_ref(SSL_SESSION *ses); -\& void SSL_SESSION_free(SSL_SESSION *session); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_new()\fR creates a new \s-1SSL_SESSION\s0 structure and returns a pointer to -it. -.PP -\&\fBSSL_SESSION_dup()\fR creates a new \s-1SSL_SESSION\s0 structure that is a copy of \fBsrc\fR. -The copy is not owned by any cache that \fBsrc\fR may have been in. -.PP -\&\fBSSL_SESSION_up_ref()\fR increments the reference count on the given \s-1SSL_SESSION\s0 -structure. -.PP -\&\fBSSL_SESSION_free()\fR decrements the reference count of \fBsession\fR and removes -the \fB\s-1SSL_SESSION\s0\fR structure pointed to by \fBsession\fR and frees up the allocated -memory, if the reference count has reached 0. -If \fBsession\fR is \s-1NULL\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -\&\s-1SSL_SESSION\s0 objects are allocated, when a \s-1TLS/SSL\s0 handshake operation -is successfully completed. Depending on the settings, see -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -the \s-1SSL_SESSION\s0 objects are internally referenced by the \s-1SSL_CTX\s0 and -linked into its session cache. \s-1SSL\s0 objects may be using the \s-1SSL_SESSION\s0 object; -as a session may be reused, several \s-1SSL\s0 objects may be using one \s-1SSL_SESSION\s0 -object at the same time. It is therefore crucial to keep the reference -count (usage information) correct and not delete a \s-1SSL_SESSION\s0 object -that is still used, as this may lead to program failures due to -dangling pointers. These failures may also appear delayed, e.g. -when an \s-1SSL_SESSION\s0 object was completely freed as the reference count -incorrectly became 0, but it is still referenced in the internal -session cache and the cache list is processed during a -\&\fBSSL_CTX_flush_sessions\fR\|(3) operation. -.PP -\&\fBSSL_SESSION_free()\fR must only be called for \s-1SSL_SESSION\s0 objects, for -which the reference count was explicitly incremented (e.g. -by calling \fBSSL_get1_session()\fR, see \fBSSL_get_session\fR\|(3)) -or when the \s-1SSL_SESSION\s0 object was generated outside a \s-1TLS\s0 handshake -operation, e.g. by using \fBd2i_SSL_SESSION\fR\|(3). -It must not be called on other \s-1SSL_SESSION\s0 objects, as this would cause -incorrect reference counts and therefore program failures. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -SSL_SESSION_new returns a pointer to the newly allocated \s-1SSL_SESSION\s0 structure -or \s-1NULL\s0 on error. -.PP -SSL_SESSION_dup returns a pointer to the new copy or \s-1NULL\s0 on error. -.PP -SSL_SESSION_up_ref returns 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_session\fR\|(3), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -\&\fBSSL_CTX_flush_sessions\fR\|(3), -\&\fBd2i_SSL_SESSION\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_dup()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_alpn_selected.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_alpn_selected.3ossl deleted file mode 120000 index 45673ade..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_alpn_selected.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get0_hostname.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_cipher.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_cipher.3ossl deleted file mode 100644 index 0c43df14..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_cipher.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_GET0_CIPHER 3ossl" -.TH SSL_SESSION_GET0_CIPHER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get0_cipher, -SSL_SESSION_set_cipher -\&\- set and retrieve the SSL cipher associated with a session -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const SSL_CIPHER *SSL_SESSION_get0_cipher(const SSL_SESSION *s); -\& int SSL_SESSION_set_cipher(SSL_SESSION *s, const SSL_CIPHER *cipher); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_get0_cipher()\fR retrieves the cipher that was used by the -connection when the session was created, or \s-1NULL\s0 if it cannot be determined. -.PP -The value returned is a pointer to an object maintained within \fBs\fR and -should not be released. -.PP -\&\fBSSL_SESSION_set_cipher()\fR can be used to set the ciphersuite associated with the -\&\s-1SSL_SESSION\s0 \fBs\fR to \fBcipher\fR. For example, this could be used to set up a -session based \s-1PSK\s0 (see \fBSSL_CTX_set_psk_use_session_callback\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_get0_cipher()\fR returns the \s-1SSL_CIPHER\s0 associated with the \s-1SSL_SESSION\s0 -or \s-1NULL\s0 if it cannot be determined. -.PP -\&\fBSSL_SESSION_set_cipher()\fR returns 1 on success or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBd2i_SSL_SESSION\fR\|(3), -\&\fBSSL_SESSION_get_time\fR\|(3), -\&\fBSSL_SESSION_get0_hostname\fR\|(3), -\&\fBSSL_SESSION_free\fR\|(3), -\&\fBSSL_CTX_set_psk_use_session_callback\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_get0_cipher()\fR function was added in OpenSSL 1.1.0. -The \fBSSL_SESSION_set_cipher()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_hostname.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_hostname.3ossl deleted file mode 100644 index e0437deb..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_hostname.3ossl +++ /dev/null @@ -1,206 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_GET0_HOSTNAME 3ossl" -.TH SSL_SESSION_GET0_HOSTNAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get0_hostname, -SSL_SESSION_set1_hostname, -SSL_SESSION_get0_alpn_selected, -SSL_SESSION_set1_alpn_selected -\&\- get and set SNI and ALPN data associated with a session -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_SESSION_get0_hostname(const SSL_SESSION *s); -\& int SSL_SESSION_set1_hostname(SSL_SESSION *s, const char *hostname); -\& -\& void SSL_SESSION_get0_alpn_selected(const SSL_SESSION *s, -\& const unsigned char **alpn, -\& size_t *len); -\& int SSL_SESSION_set1_alpn_selected(SSL_SESSION *s, const unsigned char *alpn, -\& size_t len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_get0_hostname()\fR retrieves the \s-1SNI\s0 value that was sent by the -client when the session was created if it was accepted by the server. Otherwise -\&\s-1NULL\s0 is returned. -.PP -The value returned is a pointer to memory maintained within \fBs\fR and -should not be free'd. -.PP -\&\fBSSL_SESSION_set1_hostname()\fR sets the \s-1SNI\s0 value for the hostname to a copy of -the string provided in hostname. -.PP -\&\fBSSL_SESSION_get0_alpn_selected()\fR retrieves the selected \s-1ALPN\s0 protocol for this -session and its associated length in bytes. The returned value of \fB*alpn\fR is a -pointer to memory maintained within \fBs\fR and should not be free'd. -.PP -\&\fBSSL_SESSION_set1_alpn_selected()\fR sets the \s-1ALPN\s0 protocol for this session to the -value in \fBalpn\fR which should be of length \fBlen\fR bytes. A copy of the input -value is made, and the caller retains ownership of the memory pointed to by -\&\fBalpn\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_get0_hostname()\fR returns either a string or \s-1NULL\s0 based on if there -is the \s-1SNI\s0 value sent by client. -.PP -\&\fBSSL_SESSION_set1_hostname()\fR returns 1 on success or 0 on error. -.PP -\&\fBSSL_SESSION_set1_alpn_selected()\fR returns 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBd2i_SSL_SESSION\fR\|(3), -\&\fBSSL_SESSION_get_time\fR\|(3), -\&\fBSSL_SESSION_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_set1_hostname()\fR, \fBSSL_SESSION_get0_alpn_selected()\fR and -\&\fBSSL_SESSION_set1_alpn_selected()\fR functions were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_id_context.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_id_context.3ossl deleted file mode 100644 index e6a1c071..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_id_context.3ossl +++ /dev/null @@ -1,187 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_GET0_ID_CONTEXT 3ossl" -.TH SSL_SESSION_GET0_ID_CONTEXT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get0_id_context, -SSL_SESSION_set1_id_context -\&\- get and set the SSL ID context associated with a session -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const unsigned char *SSL_SESSION_get0_id_context(const SSL_SESSION *s, -\& unsigned int *len); -\& int SSL_SESSION_set1_id_context(SSL_SESSION *s, const unsigned char *sid_ctx, -\& unsigned int sid_ctx_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -See \fBSSL_CTX_set_session_id_context\fR\|(3) for further details on session \s-1ID\s0 -contexts. -.PP -\&\fBSSL_SESSION_get0_id_context()\fR returns the \s-1ID\s0 context associated with -the \s-1SSL/TLS\s0 session \fBs\fR. The length of the \s-1ID\s0 context is written to -\&\fB*len\fR if \fBlen\fR is not \s-1NULL.\s0 -.PP -The value returned is a pointer to an object maintained within \fBs\fR and -should not be released. -.PP -\&\fBSSL_SESSION_set1_id_context()\fR takes a copy of the provided \s-1ID\s0 context given in -\&\fBsid_ctx\fR and associates it with the session \fBs\fR. The length of the \s-1ID\s0 context -is given by \fBsid_ctx_len\fR which must not exceed \s-1SSL_MAX_SID_CTX_LENGTH\s0 bytes. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_set1_id_context()\fR returns 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_set_session_id_context\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_get0_id_context()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_peer.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_peer.3ossl deleted file mode 100644 index ea295338..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_peer.3ossl +++ /dev/null @@ -1,170 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_GET0_PEER 3ossl" -.TH SSL_SESSION_GET0_PEER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get0_peer -\&\- get details about peer's certificate for a session -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509 *SSL_SESSION_get0_peer(SSL_SESSION *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_get0_peer()\fR returns the peer certificate associated with the session -\&\fBs\fR or \s-1NULL\s0 if no peer certificate is available. The caller should not free the -returned value (unless \fBX509_up_ref\fR\|(3) has also been called). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_get0_peer()\fR returns a pointer to the peer certificate or \s-1NULL\s0 if -no peer certificate is available. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_peer_rpk.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_peer_rpk.3ossl deleted file mode 120000 index 320912ea..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_peer_rpk.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get0_peer_rpk.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_ticket.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_ticket.3ossl deleted file mode 120000 index e109c634..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_ticket.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_has_ticket.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get0_ticket_appdata.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get0_ticket_appdata.3ossl deleted file mode 120000 index 4051be05..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get0_ticket_appdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_session_ticket_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_app_data.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_compress_id.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_compress_id.3ossl deleted file mode 100644 index 346c49bc..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_compress_id.3ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_GET_COMPRESS_ID 3ossl" -.TH SSL_SESSION_GET_COMPRESS_ID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get_compress_id -\&\- get details about the compression associated with a session -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned int SSL_SESSION_get_compress_id(const SSL_SESSION *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -If compression has been negotiated for an ssl session then -\&\fBSSL_SESSION_get_compress_id()\fR will return the id for the compression method or -0 otherwise. The only built-in supported compression method is zlib which has an -id of 1. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_get_compress_id()\fR returns the id of the compression method or 0 if -none. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_ex_data.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_ex_new_index.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_id.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_id.3ossl deleted file mode 120000 index c0fc6fa8..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_set1_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_master_key.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_master_key.3ossl deleted file mode 120000 index d0f74356..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_master_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_client_random.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_max_fragment_length.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_max_fragment_length.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_max_fragment_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_protocol_version.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_protocol_version.3ossl deleted file mode 100644 index 3d5d9bdb..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_protocol_version.3ossl +++ /dev/null @@ -1,187 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_GET_PROTOCOL_VERSION 3ossl" -.TH SSL_SESSION_GET_PROTOCOL_VERSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get_protocol_version, -SSL_SESSION_set_protocol_version -\&\- get and set the session protocol version -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_SESSION_get_protocol_version(const SSL_SESSION *s); -\& int SSL_SESSION_set_protocol_version(SSL_SESSION *s, int version); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_get_protocol_version()\fR returns the protocol version number used -by session \fBs\fR. -.PP -\&\fBSSL_SESSION_set_protocol_version()\fR sets the protocol version associated with the -\&\s-1SSL_SESSION\s0 object \fBs\fR to the value \fBversion\fR. This value should be a version -constant such as \fB\s-1TLS1_3_VERSION\s0\fR etc. For example, this could be used to set -up a session based \s-1PSK\s0 (see \fBSSL_CTX_set_psk_use_session_callback\fR\|(3)). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_get_protocol_version()\fR returns a number indicating the protocol -version used for the session; this number matches the constants \fIe.g.\fR -\&\fB\s-1TLS1_VERSION\s0\fR, \fB\s-1TLS1_2_VERSION\s0\fR or \fB\s-1TLS1_3_VERSION\s0\fR. -.PP -Note that the \fBSSL_SESSION_get_protocol_version()\fR function -does \fBnot\fR perform a null check on the provided session \fBs\fR pointer. -.PP -\&\fBSSL_SESSION_set_protocol_version()\fR returns 1 on success or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_psk_use_session_callback\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_get_protocol_version()\fR function was added in OpenSSL 1.1.0. -The \fBSSL_SESSION_set_protocol_version()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_ticket_lifetime_hint.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_ticket_lifetime_hint.3ossl deleted file mode 120000 index e109c634..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_ticket_lifetime_hint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_has_ticket.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_time.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_time.3ossl deleted file mode 100644 index 7b50a7fc..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_time.3ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_GET_TIME 3ossl" -.TH SSL_SESSION_GET_TIME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get_time, SSL_SESSION_set_time, SSL_SESSION_get_timeout, -SSL_SESSION_set_timeout, SSL_SESSION_get_time_ex, SSL_SESSION_set_time_ex, -SSL_get_time, SSL_set_time, SSL_get_timeout, SSL_set_timeout -\&\- retrieve and manipulate session time and timeout settings -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_SESSION_get_timeout(const SSL_SESSION *s); -\& long SSL_SESSION_set_timeout(SSL_SESSION *s, long tm); -\& -\& long SSL_get_timeout(const SSL_SESSION *s); -\& long SSL_set_timeout(SSL_SESSION *s, long tm); -\& -\& time_t SSL_SESSION_get_time_ex(const SSL_SESSION *s); -\& time_t SSL_SESSION_set_time_ex(SSL_SESSION *s, time_t tm); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.4, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 4 -\& long SSL_SESSION_get_time(const SSL_SESSION *s); -\& long SSL_SESSION_set_time(SSL_SESSION *s, long tm); -\& long SSL_get_time(const SSL_SESSION *s); -\& long SSL_set_time(SSL_SESSION *s, long tm); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_get_time_ex()\fR returns the time at which the session \fBs\fR was -established. The time is given in seconds since the Epoch and therefore -compatible to the time delivered by the \fBtime()\fR call. -.PP -\&\fBSSL_SESSION_set_time_ex()\fR replaces the creation time of the session \fBs\fR with -the chosen value \fBtm\fR. -.PP -\&\fBSSL_SESSION_get_timeout()\fR returns the timeout value set for session \fBs\fR -in seconds. -.PP -\&\fBSSL_SESSION_set_timeout()\fR sets the timeout value for session \fBs\fR in seconds -to \fBtm\fR. -.PP -\&\fBSSL_SESSION_get_time()\fR and \fBSSL_SESSION_set_time()\fR functions use -the long datatype instead of time_t and are therefore deprecated due to not -being Y2038\-safe on 32 bit systems. Note that such systems still need -to be configured to use 64 bit time_t to be able to avoid overflow in system time. -.PP -The \fBSSL_get_time()\fR, \fBSSL_set_time()\fR, \fBSSL_get_timeout()\fR, and \fBSSL_set_timeout()\fR -functions are synonyms for the SSL_SESSION_*() counterparts. -.SH "NOTES" -.IX Header "NOTES" -Sessions are expired by examining the creation time and the timeout value. -Both are set at creation time of the session to the actual time and the -default timeout value at creation, respectively, as set by -\&\fBSSL_CTX_set_timeout\fR\|(3). -Using these functions it is possible to extend or shorten the lifetime -of the session. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_get_time_ex()\fR and \fBSSL_SESSION_get_timeout()\fR return the currently -valid values. -.PP -\&\fBSSL_SESSION_set_time_ex()\fR returns time on success. -.PP -\&\fBSSL_SESSION_set_timeout()\fR returns 1 on success. -.PP -If any of the function is passed the \s-1NULL\s0 pointer for the session \fBs\fR, -0 is returned. -.SH "BUGS" -.IX Header "BUGS" -The data type long is typically 32 bits on many systems, hence the old -functions \fBSSL_SESSION_get_time()\fR and \fBSSL_SESSION_set_time()\fR are not always -Y2038 safe. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_timeout\fR\|(3), -\&\fBSSL_get_default_timeout\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBSSL_SESSION_get_time_ex()\fR and \fBSSL_SESSION_set_time_ex()\fR were -added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_time_ex.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_time_ex.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_time_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_get_timeout.3ossl b/openssl-install/share/man/man3/SSL_SESSION_get_timeout.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_get_timeout.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_has_ticket.3ossl b/openssl-install/share/man/man3/SSL_SESSION_has_ticket.3ossl deleted file mode 100644 index 644d668a..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_has_ticket.3ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_HAS_TICKET 3ossl" -.TH SSL_SESSION_HAS_TICKET 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get0_ticket, -SSL_SESSION_has_ticket, SSL_SESSION_get_ticket_lifetime_hint -\&\- get details about the ticket associated with a session -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_SESSION_has_ticket(const SSL_SESSION *s); -\& unsigned long SSL_SESSION_get_ticket_lifetime_hint(const SSL_SESSION *s); -\& void SSL_SESSION_get0_ticket(const SSL_SESSION *s, const unsigned char **tick, -\& size_t *len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_has_ticket()\fR returns 1 if there is a Session Ticket associated with -this session, and 0 otherwise. -.PP -SSL_SESSION_get_ticket_lifetime_hint returns the lifetime hint in seconds -associated with the session ticket. -.PP -SSL_SESSION_get0_ticket obtains a pointer to the ticket associated with a -session. The length of the ticket is written to \fB*len\fR. If \fBtick\fR is non -\&\s-1NULL\s0 then a pointer to the ticket is written to \fB*tick\fR. The pointer is only -valid while the connection is in use. The session (and hence the ticket pointer) -may also become invalid as a result of a call to \fBSSL_CTX_flush_sessions()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_has_ticket()\fR returns 1 if session ticket exists or 0 otherwise. -.PP -\&\fBSSL_SESSION_get_ticket_lifetime_hint()\fR returns the number of seconds. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBd2i_SSL_SESSION\fR\|(3), -\&\fBSSL_SESSION_get_time\fR\|(3), -\&\fBSSL_SESSION_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_has_ticket()\fR, \fBSSL_SESSION_get_ticket_lifetime_hint()\fR -and \fBSSL_SESSION_get0_ticket()\fR functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_is_resumable.3ossl b/openssl-install/share/man/man3/SSL_SESSION_is_resumable.3ossl deleted file mode 100644 index e4a07a84..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_is_resumable.3ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_IS_RESUMABLE 3ossl" -.TH SSL_SESSION_IS_RESUMABLE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_is_resumable -\&\- determine whether an SSL_SESSION object can be used for resumption -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_SESSION_is_resumable(const SSL_SESSION *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_is_resumable()\fR determines whether an \s-1SSL_SESSION\s0 object can be used -to resume a session or not. Returns 1 if it can or 0 if not. Note that -attempting to resume with a non-resumable session will result in a full -handshake. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_is_resumable()\fR returns 1 if the session is resumable or 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_get_session\fR\|(3), -\&\fBSSL_CTX_sess_set_new_cb\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_is_resumable()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_new.3ossl b/openssl-install/share/man/man3/SSL_SESSION_new.3ossl deleted file mode 120000 index d9535c42..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_print.3ossl b/openssl-install/share/man/man3/SSL_SESSION_print.3ossl deleted file mode 100644 index 252998f8..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_print.3ossl +++ /dev/null @@ -1,179 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_PRINT 3ossl" -.TH SSL_SESSION_PRINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_print, -SSL_SESSION_print_fp, -SSL_SESSION_print_keylog -\&\- printf information about a session -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_SESSION_print(BIO *fp, const SSL_SESSION *ses); -\& int SSL_SESSION_print_fp(FILE *fp, const SSL_SESSION *ses); -\& int SSL_SESSION_print_keylog(BIO *bp, const SSL_SESSION *x); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_print()\fR prints summary information about the session provided in -\&\fBses\fR to the \s-1BIO\s0 \fBfp\fR. -.PP -\&\fBSSL_SESSION_print_fp()\fR does the same as \fBSSL_SESSION_print()\fR except it prints it -to the \s-1FILE\s0 \fBfp\fR. -.PP -\&\fBSSL_SESSION_print_keylog()\fR prints session information to the provided \s-1BIO\s0 -in \s-1NSS\s0 keylog format. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_print()\fR, \fBSSL_SESSION_print_fp()\fR and SSL_SESSION_print_keylog return -1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_print_fp.3ossl b/openssl-install/share/man/man3/SSL_SESSION_print_fp.3ossl deleted file mode 120000 index a54ea177..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_print_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_print_keylog.3ossl b/openssl-install/share/man/man3/SSL_SESSION_print_keylog.3ossl deleted file mode 120000 index a54ea177..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_print_keylog.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_print.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set1_alpn_selected.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set1_alpn_selected.3ossl deleted file mode 120000 index 45673ade..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set1_alpn_selected.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get0_hostname.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set1_hostname.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set1_hostname.3ossl deleted file mode 120000 index 45673ade..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set1_hostname.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get0_hostname.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set1_id.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set1_id.3ossl deleted file mode 100644 index 5c7c6ec0..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set1_id.3ossl +++ /dev/null @@ -1,181 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_SET1_ID 3ossl" -.TH SSL_SESSION_SET1_ID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_SESSION_get_id, -SSL_SESSION_set1_id -\&\- get and set the SSL session ID -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const unsigned char *SSL_SESSION_get_id(const SSL_SESSION *s, -\& unsigned int *len); -\& int SSL_SESSION_set1_id(SSL_SESSION *s, const unsigned char *sid, -\& unsigned int sid_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_SESSION_get_id()\fR returns a pointer to the internal session id value for the -session \fBs\fR. The length of the id in bytes is stored in \fB*len\fR. The length may -be 0. The caller should not free the returned pointer directly. -.PP -\&\fBSSL_SESSION_set1_id()\fR sets the session \s-1ID\s0 for the \fBssl\fR \s-1SSL/TLS\s0 session -to \fBsid\fR of length \fBsid_len\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_get_id()\fR returns a pointer to the session id value. -\&\fBSSL_SESSION_set1_id()\fR returns 1 for success and 0 for failure, for example -if the supplied session \s-1ID\s0 length exceeds \fB\s-1SSL_MAX_SSL_SESSION_ID_LENGTH\s0\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_SESSION_set1_id()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_SESSION_set1_id_context.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set1_id_context.3ossl deleted file mode 120000 index 4d710c91..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set1_id_context.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get0_id_context.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set1_master_key.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set1_master_key.3ossl deleted file mode 120000 index d0f74356..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set1_master_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_client_random.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set1_ticket_appdata.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set1_ticket_appdata.3ossl deleted file mode 120000 index 4051be05..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set1_ticket_appdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_session_ticket_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_app_data.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_cipher.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_cipher.3ossl deleted file mode 120000 index f0243c2a..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get0_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_ex_data.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_protocol_version.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_protocol_version.3ossl deleted file mode 120000 index 07ba2235..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_protocol_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_protocol_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_time.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_time.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_time_ex.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_time_ex.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_time_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_set_timeout.3ossl b/openssl-install/share/man/man3/SSL_SESSION_set_timeout.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_set_timeout.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_SESSION_up_ref.3ossl b/openssl-install/share/man/man3/SSL_SESSION_up_ref.3ossl deleted file mode 120000 index d9535c42..00000000 --- a/openssl-install/share/man/man3/SSL_SESSION_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_free.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_FLAG_ADVANCE.3ossl b/openssl-install/share/man/man3/SSL_STREAM_FLAG_ADVANCE.3ossl deleted file mode 120000 index 6fbfb2de..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_FLAG_ADVANCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_new_stream.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_FLAG_NO_BLOCK.3ossl b/openssl-install/share/man/man3/SSL_STREAM_FLAG_NO_BLOCK.3ossl deleted file mode 120000 index 6fbfb2de..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_FLAG_NO_BLOCK.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_new_stream.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_FLAG_UNI.3ossl b/openssl-install/share/man/man3/SSL_STREAM_FLAG_UNI.3ossl deleted file mode 120000 index 6fbfb2de..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_FLAG_UNI.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_new_stream.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_STATE_CONN_CLOSED.3ossl b/openssl-install/share/man/man3/SSL_STREAM_STATE_CONN_CLOSED.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_STATE_CONN_CLOSED.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_STATE_FINISHED.3ossl b/openssl-install/share/man/man3/SSL_STREAM_STATE_FINISHED.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_STATE_FINISHED.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_STATE_NONE.3ossl b/openssl-install/share/man/man3/SSL_STREAM_STATE_NONE.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_STATE_NONE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_STATE_OK.3ossl b/openssl-install/share/man/man3/SSL_STREAM_STATE_OK.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_STATE_OK.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_LOCAL.3ossl b/openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_LOCAL.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_LOCAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_REMOTE.3ossl b/openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_REMOTE.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_STATE_RESET_REMOTE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_STATE_WRONG_DIR.3ossl b/openssl-install/share/man/man3/SSL_STREAM_STATE_WRONG_DIR.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_STATE_WRONG_DIR.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_TYPE_BIDI.3ossl b/openssl-install/share/man/man3/SSL_STREAM_TYPE_BIDI.3ossl deleted file mode 120000 index bdbd18f4..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_TYPE_BIDI.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_TYPE_NONE.3ossl b/openssl-install/share/man/man3/SSL_STREAM_TYPE_NONE.3ossl deleted file mode 120000 index bdbd18f4..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_TYPE_NONE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_TYPE_READ.3ossl b/openssl-install/share/man/man3/SSL_STREAM_TYPE_READ.3ossl deleted file mode 120000 index bdbd18f4..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_TYPE_READ.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_STREAM_TYPE_WRITE.3ossl b/openssl-install/share/man/man3/SSL_STREAM_TYPE_WRITE.3ossl deleted file mode 120000 index bdbd18f4..00000000 --- a/openssl-install/share/man/man3/SSL_STREAM_TYPE_WRITE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_NEGOTIATED.3ossl b/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_NEGOTIATED.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_NEGOTIATED.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_PEER_REQUEST.3ossl b/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_PEER_REQUEST.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_PEER_REQUEST.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_REQUEST.3ossl b/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_REQUEST.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_CLASS_FEATURE_REQUEST.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_CLASS_GENERIC.3ossl b/openssl-install/share/man/man3/SSL_VALUE_CLASS_GENERIC.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_CLASS_GENERIC.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE.3ossl b/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT.3ossl b/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT.3ossl b/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_INHERIT.3ossl b/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_INHERIT.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_EVENT_HANDLING_MODE_INHERIT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_QUIC_IDLE_TIMEOUT.3ossl b/openssl-install/share/man/man3/SSL_VALUE_QUIC_IDLE_TIMEOUT.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_QUIC_IDLE_TIMEOUT.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL.3ossl b/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL.3ossl b/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL.3ossl b/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL.3ossl b/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_AVAIL.3ossl b/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_AVAIL.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_AVAIL.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_SIZE.3ossl b/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_SIZE.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_SIZE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_USED.3ossl b/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_USED.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_VALUE_STREAM_WRITE_BUF_USED.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_WRITE_FLAG_CONCLUDE.3ossl b/openssl-install/share/man/man3/SSL_WRITE_FLAG_CONCLUDE.3ossl deleted file mode 120000 index c5148886..00000000 --- a/openssl-install/share/man/man3/SSL_WRITE_FLAG_CONCLUDE.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_write.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_accept.3ossl b/openssl-install/share/man/man3/SSL_accept.3ossl deleted file mode 100644 index 2d62e8f3..00000000 --- a/openssl-install/share/man/man3/SSL_accept.3ossl +++ /dev/null @@ -1,205 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_ACCEPT 3ossl" -.TH SSL_ACCEPT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_accept \- wait for a TLS/SSL client to initiate a TLS/SSL handshake -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_accept(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_accept()\fR waits for a \s-1TLS/SSL\s0 client to initiate the \s-1TLS/SSL\s0 handshake. -The communication channel must already have been set and assigned to the -\&\fBssl\fR by setting an underlying \fB\s-1BIO\s0\fR. -.SH "NOTES" -.IX Header "NOTES" -The behaviour of \fBSSL_accept()\fR depends on the underlying \s-1BIO.\s0 -.PP -If the underlying \s-1BIO\s0 is \fBblocking\fR, \fBSSL_accept()\fR will only return once the -handshake has been finished or an error occurred. -.PP -If the underlying \s-1BIO\s0 is \fBnonblocking\fR, \fBSSL_accept()\fR will also return -when the underlying \s-1BIO\s0 could not satisfy the needs of \fBSSL_accept()\fR -to continue the handshake, indicating the problem by the return value \-1. -In this case a call to \fBSSL_get_error()\fR with the -return value of \fBSSL_accept()\fR will yield \fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. The calling process then must repeat the call after -taking appropriate action to satisfy the needs of \fBSSL_accept()\fR. -The action depends on the underlying \s-1BIO.\s0 When using a nonblocking socket, -nothing is to be done, but \fBselect()\fR can be used to check for the required -condition. When using a buffering \s-1BIO,\s0 like a \s-1BIO\s0 pair, data must be written -into or retrieved out of the \s-1BIO\s0 before being able to continue. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0" 4 -The \s-1TLS/SSL\s0 handshake was not successful but was shut down controlled and -by the specifications of the \s-1TLS/SSL\s0 protocol. Call \fBSSL_get_error()\fR with the -return value \fBret\fR to find out the reason. -.IP "1" 4 -.IX Item "1" -The \s-1TLS/SSL\s0 handshake was successfully completed, a \s-1TLS/SSL\s0 connection has been -established. -.IP "<0" 4 -.IX Item "<0" -The \s-1TLS/SSL\s0 handshake was not successful because a fatal error occurred either -at the protocol level or a connection failure occurred. The shutdown was -not clean. It can also occur if action is needed to continue the operation -for nonblocking BIOs. Call \fBSSL_get_error()\fR with the return value \fBret\fR -to find out the reason. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_error\fR\|(3), \fBSSL_connect\fR\|(3), -\&\fBSSL_shutdown\fR\|(3), \fBssl\fR\|(7), \fBbio\fR\|(7), -\&\fBSSL_set_connect_state\fR\|(3), -\&\fBSSL_do_handshake\fR\|(3), -\&\fBSSL_CTX_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_accept_stream.3ossl b/openssl-install/share/man/man3/SSL_accept_stream.3ossl deleted file mode 100644 index f31cb7f0..00000000 --- a/openssl-install/share/man/man3/SSL_accept_stream.3ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_ACCEPT_STREAM 3ossl" -.TH SSL_ACCEPT_STREAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_accept_stream, SSL_get_accept_stream_queue_len, SSL_ACCEPT_STREAM_NO_BLOCK \- -accept an incoming QUIC stream from a QUIC peer -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_ACCEPT_STREAM_NO_BLOCK -\& -\& SSL *SSL_accept_stream(SSL *ssl, uint64_t flags); -\& -\& size_t SSL_get_accept_stream_queue_len(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBSSL_accept_stream()\fR function attempts to dequeue an incoming stream from the -given \s-1QUIC\s0 connection \s-1SSL\s0 object and returns the newly allocated \s-1QUIC\s0 stream \s-1SSL\s0 -object. -.PP -If the queue of incoming streams is empty, this function returns \s-1NULL\s0 (in -nonblocking mode) or waits for an incoming stream (in blocking mode). This -function may still return \s-1NULL\s0 in blocking mode, for example if the underlying -connection is terminated. -.PP -The caller is responsible for managing the lifetime of the returned \s-1QUIC\s0 stream -\&\s-1SSL\s0 object; for more information, see \fBSSL_free\fR\|(3). -.PP -This function will block if the \s-1QUIC\s0 connection \s-1SSL\s0 object is configured in -blocking mode (see \fBSSL_set_blocking_mode\fR\|(3)), but this may be bypassed by -passing the flag \fB\s-1SSL_ACCEPT_STREAM_NO_BLOCK\s0\fR in \fIflags\fR. If this flag is set, -this function never blocks. -.PP -Calling \fBSSL_accept_stream()\fR if there is no default stream already present -inhibits the future creation of a default stream. See \fBopenssl\-quic\fR\|(7). -.PP -\&\fBSSL_get_accept_stream_queue_len()\fR returns the number of incoming streams -currently waiting in the accept queue. -.PP -These functions can be used from multiple threads for the same \s-1QUIC\s0 connection. -.PP -Depending on whether default stream functionality is being used, it may be -necessary to explicitly configure the incoming stream policy before streams can -be accepted; see \fBSSL_set_incoming_stream_policy\fR\|(3). See also -\&\*(L"\s-1MODES OF OPERATION\*(R"\s0 in \fBopenssl\-quic\fR\|(7) for more information on default stream -functionality. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_accept_stream()\fR returns a newly allocated \s-1QUIC\s0 stream \s-1SSL\s0 object, or \s-1NULL\s0 if -no new incoming streams are available, or if the connection has been terminated, -or if called on a \s-1SSL\s0 object other than a \s-1QUIC\s0 connection \s-1SSL\s0 object. -\&\fBSSL_get_error\fR\|(3) can be used to obtain further information in this case. -.PP -\&\fBSSL_get_accept_stream_queue_len()\fR returns the number of incoming streams -currently waiting in the accept queue, or 0 if called on a \s-1SSL\s0 object other than -a \s-1QUIC\s0 connection \s-1SSL\s0 object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\*(L"\s-1MODES OF OPERATION\*(R"\s0 in \fBopenssl\-quic\fR\|(7), \fBSSL_new_stream\fR\|(3), -\&\fBSSL_set_blocking_mode\fR\|(3), \fBSSL_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_accept_stream()\fR and \fBSSL_get_accept_stream_queue_len()\fR were added in OpenSSL -3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_add0_chain_cert.3ossl b/openssl-install/share/man/man3/SSL_add0_chain_cert.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_add0_chain_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add1_chain_cert.3ossl b/openssl-install/share/man/man3/SSL_add1_chain_cert.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_add1_chain_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add1_host.3ossl b/openssl-install/share/man/man3/SSL_add1_host.3ossl deleted file mode 120000 index b101e006..00000000 --- a/openssl-install/share/man/man3/SSL_add1_host.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_host.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add1_to_CA_list.3ossl b/openssl-install/share/man/man3/SSL_add1_to_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_add1_to_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add_client_CA.3ossl b/openssl-install/share/man/man3/SSL_add_client_CA.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_add_client_CA.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add_dir_cert_subjects_to_stack.3ossl b/openssl-install/share/man/man3/SSL_add_dir_cert_subjects_to_stack.3ossl deleted file mode 120000 index 24445e17..00000000 --- a/openssl-install/share/man/man3/SSL_add_dir_cert_subjects_to_stack.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_load_client_CA_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add_expected_rpk.3ossl b/openssl-install/share/man/man3/SSL_add_expected_rpk.3ossl deleted file mode 120000 index 320912ea..00000000 --- a/openssl-install/share/man/man3/SSL_add_expected_rpk.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get0_peer_rpk.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add_file_cert_subjects_to_stack.3ossl b/openssl-install/share/man/man3/SSL_add_file_cert_subjects_to_stack.3ossl deleted file mode 120000 index 24445e17..00000000 --- a/openssl-install/share/man/man3/SSL_add_file_cert_subjects_to_stack.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_load_client_CA_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_add_store_cert_subjects_to_stack.3ossl b/openssl-install/share/man/man3/SSL_add_store_cert_subjects_to_stack.3ossl deleted file mode 120000 index 24445e17..00000000 --- a/openssl-install/share/man/man3/SSL_add_store_cert_subjects_to_stack.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_load_client_CA_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_alert_desc_string.3ossl b/openssl-install/share/man/man3/SSL_alert_desc_string.3ossl deleted file mode 120000 index aa50e1b2..00000000 --- a/openssl-install/share/man/man3/SSL_alert_desc_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_alert_type_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_alert_desc_string_long.3ossl b/openssl-install/share/man/man3/SSL_alert_desc_string_long.3ossl deleted file mode 120000 index aa50e1b2..00000000 --- a/openssl-install/share/man/man3/SSL_alert_desc_string_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_alert_type_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_alert_type_string.3ossl b/openssl-install/share/man/man3/SSL_alert_type_string.3ossl deleted file mode 100644 index 8615a380..00000000 --- a/openssl-install/share/man/man3/SSL_alert_type_string.3ossl +++ /dev/null @@ -1,369 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_ALERT_TYPE_STRING 3ossl" -.TH SSL_ALERT_TYPE_STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_alert_type_string, SSL_alert_type_string_long, SSL_alert_desc_string, SSL_alert_desc_string_long \- get textual description of alert information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_alert_type_string(int value); -\& const char *SSL_alert_type_string_long(int value); -\& -\& const char *SSL_alert_desc_string(int value); -\& const char *SSL_alert_desc_string_long(int value); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_alert_type_string()\fR returns a one letter string indicating the -type of the alert specified by \fBvalue\fR. -.PP -\&\fBSSL_alert_type_string_long()\fR returns a string indicating the type of the alert -specified by \fBvalue\fR. -.PP -\&\fBSSL_alert_desc_string()\fR returns a two letter string as a short form -describing the reason of the alert specified by \fBvalue\fR. -.PP -\&\fBSSL_alert_desc_string_long()\fR returns a string describing the reason -of the alert specified by \fBvalue\fR. -.SH "NOTES" -.IX Header "NOTES" -When one side of an \s-1SSL/TLS\s0 communication wants to inform the peer about -a special situation, it sends an alert. The alert is sent as a special message -and does not influence the normal data stream (unless its contents results -in the communication being canceled). -.PP -A warning alert is sent, when a non-fatal error condition occurs. The -\&\*(L"close notify\*(R" alert is sent as a warning alert. Other examples for -non-fatal errors are certificate errors (\*(L"certificate expired\*(R", -\&\*(L"unsupported certificate\*(R"), for which a warning alert may be sent. -(The sending party may however decide to send a fatal error.) The -receiving side may cancel the connection on reception of a warning -alert on it discretion. -.PP -Several alert messages must be sent as fatal alert messages as specified -by the \s-1TLS RFC. A\s0 fatal alert always leads to a connection abort. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following strings can occur for \fBSSL_alert_type_string()\fR or -\&\fBSSL_alert_type_string_long()\fR: -.ie n .IP """W""/""warning""" 4 -.el .IP "``W''/``warning''" 4 -.IX Item "W/warning" -.PD 0 -.ie n .IP """F""/""fatal""" 4 -.el .IP "``F''/``fatal''" 4 -.IX Item "F/fatal" -.ie n .IP """U""/""unknown""" 4 -.el .IP "``U''/``unknown''" 4 -.IX Item "U/unknown" -.PD -This indicates that no support is available for this alert type. -Probably \fBvalue\fR does not contain a correct alert message. -.PP -The following strings can occur for \fBSSL_alert_desc_string()\fR or -\&\fBSSL_alert_desc_string_long()\fR: -.ie n .IP """\s-1CN""/\s0""close notify""" 4 -.el .IP "``\s-1CN''/\s0``close notify''" 4 -.IX Item "CN/close notify" -The connection shall be closed. This is a warning alert. -.ie n .IP """\s-1UM""/\s0""unexpected message""" 4 -.el .IP "``\s-1UM''/\s0``unexpected message''" 4 -.IX Item "UM/unexpected message" -An inappropriate message was received. This alert is always fatal -and should never be observed in communication between proper -implementations. -.ie n .IP """\s-1BM""/\s0""bad record mac""" 4 -.el .IP "``\s-1BM''/\s0``bad record mac''" 4 -.IX Item "BM/bad record mac" -This alert is returned if a record is received with an incorrect -\&\s-1MAC.\s0 This message is always fatal. -.ie n .IP """\s-1DF""/\s0""decompression failure""" 4 -.el .IP "``\s-1DF''/\s0``decompression failure''" 4 -.IX Item "DF/decompression failure" -The decompression function received improper input (e.g. data -that would expand to excessive length). This message is always -fatal. -.ie n .IP """\s-1HF""/\s0""handshake failure""" 4 -.el .IP "``\s-1HF''/\s0``handshake failure''" 4 -.IX Item "HF/handshake failure" -Reception of a handshake_failure alert message indicates that the -sender was unable to negotiate an acceptable set of security -parameters given the options available. This is a fatal error. -.ie n .IP """\s-1NC""/\s0""no certificate""" 4 -.el .IP "``\s-1NC''/\s0``no certificate''" 4 -.IX Item "NC/no certificate" -A client, that was asked to send a certificate, does not send a certificate -(SSLv3 only). -.ie n .IP """\s-1BC""/\s0""bad certificate""" 4 -.el .IP "``\s-1BC''/\s0``bad certificate''" 4 -.IX Item "BC/bad certificate" -A certificate was corrupt, contained signatures that did not -verify correctly, etc -.ie n .IP """\s-1UC""/\s0""unsupported certificate""" 4 -.el .IP "``\s-1UC''/\s0``unsupported certificate''" 4 -.IX Item "UC/unsupported certificate" -A certificate was of an unsupported type. -.ie n .IP """\s-1CR""/\s0""certificate revoked""" 4 -.el .IP "``\s-1CR''/\s0``certificate revoked''" 4 -.IX Item "CR/certificate revoked" -A certificate was revoked by its signer. -.ie n .IP """\s-1CE""/\s0""certificate expired""" 4 -.el .IP "``\s-1CE''/\s0``certificate expired''" 4 -.IX Item "CE/certificate expired" -A certificate has expired or is not currently valid. -.ie n .IP """\s-1CU""/\s0""certificate unknown""" 4 -.el .IP "``\s-1CU''/\s0``certificate unknown''" 4 -.IX Item "CU/certificate unknown" -Some other (unspecified) issue arose in processing the -certificate, rendering it unacceptable. -.ie n .IP """\s-1IP""/\s0""illegal parameter""" 4 -.el .IP "``\s-1IP''/\s0``illegal parameter''" 4 -.IX Item "IP/illegal parameter" -A field in the handshake was out of range or inconsistent with -other fields. This is always fatal. -.ie n .IP """\s-1DC""/\s0""decryption failed""" 4 -.el .IP "``\s-1DC''/\s0``decryption failed''" 4 -.IX Item "DC/decryption failed" -A TLSCiphertext decrypted in an invalid way: either it wasn't an -even multiple of the block length or its padding values, when -checked, weren't correct. This message is always fatal. -.ie n .IP """\s-1RO""/\s0""record overflow""" 4 -.el .IP "``\s-1RO''/\s0``record overflow''" 4 -.IX Item "RO/record overflow" -A TLSCiphertext record was received which had a length more than -2^14+2048 bytes, or a record decrypted to a TLSCompressed record -with more than 2^14+1024 bytes. This message is always fatal. -.ie n .IP """\s-1CA""/\s0""unknown \s-1CA""\s0" 4 -.el .IP "``\s-1CA''/\s0``unknown \s-1CA''\s0" 4 -.IX Item "CA/unknown CA" -A valid certificate chain or partial chain was received, but the -certificate was not accepted because the \s-1CA\s0 certificate could not -be located or couldn't be matched with a known, trusted \s-1CA.\s0 This -message is always fatal. -.ie n .IP """\s-1AD""/\s0""access denied""" 4 -.el .IP "``\s-1AD''/\s0``access denied''" 4 -.IX Item "AD/access denied" -A valid certificate was received, but when access control was -applied, the sender decided not to proceed with negotiation. -This message is always fatal. -.ie n .IP """\s-1DE""/\s0""decode error""" 4 -.el .IP "``\s-1DE''/\s0``decode error''" 4 -.IX Item "DE/decode error" -A message could not be decoded because some field was out of the -specified range or the length of the message was incorrect. This -message is always fatal. -.ie n .IP """\s-1CY""/\s0""decrypt error""" 4 -.el .IP "``\s-1CY''/\s0``decrypt error''" 4 -.IX Item "CY/decrypt error" -A handshake cryptographic operation failed, including being -unable to correctly verify a signature, decrypt a key exchange, -or validate a finished message. -.ie n .IP """\s-1ER""/\s0""export restriction""" 4 -.el .IP "``\s-1ER''/\s0``export restriction''" 4 -.IX Item "ER/export restriction" -A negotiation not in compliance with export restrictions was -detected; for example, attempting to transfer a 1024 bit -ephemeral \s-1RSA\s0 key for the \s-1RSA_EXPORT\s0 handshake method. This -message is always fatal. -.ie n .IP """\s-1PV""/\s0""protocol version""" 4 -.el .IP "``\s-1PV''/\s0``protocol version''" 4 -.IX Item "PV/protocol version" -The protocol version the client has attempted to negotiate is -recognized, but not supported. (For example, old protocol -versions might be avoided for security reasons). This message is -always fatal. -.ie n .IP """\s-1IS""/\s0""insufficient security""" 4 -.el .IP "``\s-1IS''/\s0``insufficient security''" 4 -.IX Item "IS/insufficient security" -Returned instead of handshake_failure when a negotiation has -failed specifically because the server requires ciphers more -secure than those supported by the client. This message is always -fatal. -.ie n .IP """\s-1IE""/\s0""internal error""" 4 -.el .IP "``\s-1IE''/\s0``internal error''" 4 -.IX Item "IE/internal error" -An internal error unrelated to the peer or the correctness of the -protocol makes it impossible to continue (such as a memory -allocation failure). This message is always fatal. -.ie n .IP """\s-1US""/\s0""user canceled""" 4 -.el .IP "``\s-1US''/\s0``user canceled''" 4 -.IX Item "US/user canceled" -This handshake is being canceled for some reason unrelated to a -protocol failure. If the user cancels an operation after the -handshake is complete, just closing the connection by sending a -close_notify is more appropriate. This alert should be followed -by a close_notify. This message is generally a warning. -.ie n .IP """\s-1NR""/\s0""no renegotiation""" 4 -.el .IP "``\s-1NR''/\s0``no renegotiation''" 4 -.IX Item "NR/no renegotiation" -Sent by the client in response to a hello request or by the -server in response to a client hello after initial handshaking. -Either of these would normally lead to renegotiation; when that -is not appropriate, the recipient should respond with this alert; -at that point, the original requester can decide whether to -proceed with the connection. One case where this would be -appropriate would be where a server has spawned a process to -satisfy a request; the process might receive security parameters -(key length, authentication, etc.) at startup and it might be -difficult to communicate changes to these parameters after that -point. This message is always a warning. -.ie n .IP """\s-1UP""/\s0""unknown \s-1PSK\s0 identity""" 4 -.el .IP "``\s-1UP''/\s0``unknown \s-1PSK\s0 identity''" 4 -.IX Item "UP/unknown PSK identity" -Sent by the server to indicate that it does not recognize a \s-1PSK\s0 -identity or an \s-1SRP\s0 identity. -.ie n .IP """\s-1UK""/\s0""unknown""" 4 -.el .IP "``\s-1UK''/\s0``unknown''" 4 -.IX Item "UK/unknown" -This indicates that no description is available for this alert type. -Probably \fBvalue\fR does not contain a correct alert message. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_info_callback\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_alert_type_string_long.3ossl b/openssl-install/share/man/man3/SSL_alert_type_string_long.3ossl deleted file mode 120000 index aa50e1b2..00000000 --- a/openssl-install/share/man/man3/SSL_alert_type_string_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_alert_type_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_alloc_buffers.3ossl b/openssl-install/share/man/man3/SSL_alloc_buffers.3ossl deleted file mode 100644 index 915c3c59..00000000 --- a/openssl-install/share/man/man3/SSL_alloc_buffers.3ossl +++ /dev/null @@ -1,197 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_ALLOC_BUFFERS 3ossl" -.TH SSL_ALLOC_BUFFERS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_free_buffers, SSL_alloc_buffers \- manage SSL structure buffers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_free_buffers(SSL *ssl); -\& int SSL_alloc_buffers(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_free_buffers()\fR frees the read and write buffers of the given \fBssl\fR. -\&\fBSSL_alloc_buffers()\fR allocates the read and write buffers of the given \fBssl\fR. -.PP -The \fB\s-1SSL_MODE_RELEASE_BUFFERS\s0\fR mode releases read or write buffers whenever -the buffers have been drained. These functions allow applications to manually -control when buffers are freed and allocated. -.PP -After freeing the buffers, the buffers are automatically reallocated upon a -new read or write. The \fBSSL_alloc_buffers()\fR does not need to be called, but -can be used to make sure the buffers are preallocated. This can be used to -avoid allocation during data processing or with \fBCRYPTO_set_mem_functions()\fR -to control where and how buffers are allocated. -.PP -These functions are no-ops when used with \s-1QUIC SSL\s0 objects. For \s-1QUIC,\s0 -\&\fBSSL_free_buffers()\fR always fails, and \fBSSL_alloc_buffers()\fR always succeeds. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0 (Failure)" 4 -.IX Item "0 (Failure)" -The \fBSSL_free_buffers()\fR function returns 0 when there is pending data to be -read or written. The \fBSSL_alloc_buffers()\fR function returns 0 when there is -an allocation failure. -.IP "1 (Success)" 4 -.IX Item "1 (Success)" -The \fBSSL_free_buffers()\fR function returns 1 if the buffers have been freed. This -value is also returned if the buffers had been freed before calling -\&\fBSSL_free_buffers()\fR. -The \fBSSL_alloc_buffers()\fR function returns 1 if the buffers have been allocated. -This value is also returned if the buffers had been allocated before calling -\&\fBSSL_alloc_buffers()\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_free\fR\|(3), \fBSSL_clear\fR\|(3), -\&\fBSSL_new\fR\|(3), \fBSSL_CTX_set_mode\fR\|(3), -\&\fBCRYPTO_set_mem_functions\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_allow_early_data_cb_fn.3ossl b/openssl-install/share/man/man3/SSL_allow_early_data_cb_fn.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_allow_early_data_cb_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_async_callback_fn.3ossl b/openssl-install/share/man/man3/SSL_async_callback_fn.3ossl deleted file mode 120000 index ea95f1d7..00000000 --- a/openssl-install/share/man/man3/SSL_async_callback_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_async_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_build_cert_chain.3ossl b/openssl-install/share/man/man3/SSL_build_cert_chain.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_build_cert_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_bytes_to_cipher_list.3ossl b/openssl-install/share/man/man3/SSL_bytes_to_cipher_list.3ossl deleted file mode 120000 index 5ab60591..00000000 --- a/openssl-install/share/man/man3/SSL_bytes_to_cipher_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_ciphers.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_callback_ctrl.3ossl b/openssl-install/share/man/man3/SSL_callback_ctrl.3ossl deleted file mode 120000 index 0dbfa7e7..00000000 --- a/openssl-install/share/man/man3/SSL_callback_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_check_chain.3ossl b/openssl-install/share/man/man3/SSL_check_chain.3ossl deleted file mode 100644 index b42d0369..00000000 --- a/openssl-install/share/man/man3/SSL_check_chain.3ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CHECK_CHAIN 3ossl" -.TH SSL_CHECK_CHAIN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_check_chain \- check certificate chain suitability -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_check_chain(SSL *s, X509 *x, EVP_PKEY *pk, STACK_OF(X509) *chain); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_check_chain()\fR checks whether certificate \fBx\fR, private key \fBpk\fR and -certificate chain \fBchain\fR is suitable for use with the current session -\&\fBs\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_check_chain()\fR returns a bitmap of flags indicating the validity of the -chain. -.PP -\&\fB\s-1CERT_PKEY_VALID\s0\fR: the chain can be used with the current session. -If this flag is \fBnot\fR set then the certificate will never be used even -if the application tries to set it because it is inconsistent with the -peer preferences. -.PP -\&\fB\s-1CERT_PKEY_SIGN\s0\fR: the \s-1EE\s0 key can be used for signing. -.PP -\&\fB\s-1CERT_PKEY_EE_SIGNATURE\s0\fR: the signature algorithm of the \s-1EE\s0 certificate is -acceptable. -.PP -\&\fB\s-1CERT_PKEY_CA_SIGNATURE\s0\fR: the signature algorithms of all \s-1CA\s0 certificates -are acceptable. -.PP -\&\fB\s-1CERT_PKEY_EE_PARAM\s0\fR: the parameters of the end entity certificate are -acceptable (e.g. it is a supported curve). -.PP -\&\fB\s-1CERT_PKEY_CA_PARAM\s0\fR: the parameters of all \s-1CA\s0 certificates are acceptable. -.PP -\&\fB\s-1CERT_PKEY_EXPLICIT_SIGN\s0\fR: the end entity certificate algorithm -can be used explicitly for signing (i.e. it is mentioned in the signature -algorithms extension). -.PP -\&\fB\s-1CERT_PKEY_ISSUER_NAME\s0\fR: the issuer name is acceptable. This is only -meaningful for client authentication. -.PP -\&\fB\s-1CERT_PKEY_CERT_TYPE\s0\fR: the certificate type is acceptable. Only meaningful -for client authentication. -.PP -\&\fB\s-1CERT_PKEY_SUITEB\s0\fR: chain is suitable for Suite B use. -.SH "NOTES" -.IX Header "NOTES" -\&\fBSSL_check_chain()\fR must be called in servers after a client hello message or in -clients after a certificate request message. It will typically be called -in the certificate callback. -.PP -An application wishing to support multiple certificate chains may call this -function on each chain in turn: starting with the one it considers the -most secure. It could then use the chain of the first set which returns -suitable flags. -.PP -As a minimum the flag \fB\s-1CERT_PKEY_VALID\s0\fR must be set for a chain to be -usable. An application supporting multiple chains with different \s-1CA\s0 signature -algorithms may also wish to check \fB\s-1CERT_PKEY_CA_SIGNATURE\s0\fR too. If no -chain is suitable a server should fall back to the most secure chain which -sets \fB\s-1CERT_PKEY_VALID\s0\fR. -.PP -The validity of a chain is determined by checking if it matches a supported -signature algorithm, supported curves and in the case of client authentication -certificate types and issuer names. -.PP -Since the supported signature algorithms extension is only used in \s-1TLS 1.2, -TLS 1.3\s0 and \s-1DTLS 1.2\s0 the results for earlier versions of \s-1TLS\s0 and \s-1DTLS\s0 may not -be very useful. Applications may wish to specify a different \*(L"legacy\*(R" chain -for earlier versions of \s-1TLS\s0 or \s-1DTLS.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_set_cert_cb\fR\|(3), -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_check_private_key.3ossl b/openssl-install/share/man/man3/SSL_check_private_key.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_check_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_clear.3ossl b/openssl-install/share/man/man3/SSL_clear.3ossl deleted file mode 100644 index bfc408e8..00000000 --- a/openssl-install/share/man/man3/SSL_clear.3ossl +++ /dev/null @@ -1,211 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CLEAR 3ossl" -.TH SSL_CLEAR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_clear \- reset SSL object to allow another connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_clear(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Reset \fBssl\fR to allow another connection. All settings (method, ciphers, -BIOs) are kept. -.SH "NOTES" -.IX Header "NOTES" -SSL_clear is used to prepare an \s-1SSL\s0 object for a new connection. While all -settings are kept, a side effect is the handling of the current \s-1SSL\s0 session. -If a session is still \fBopen\fR, it is considered bad and will be removed -from the session cache, as required by \s-1RFC2246. A\s0 session is considered open, -if \fBSSL_shutdown\fR\|(3) was not called for the connection -or at least \fBSSL_set_shutdown\fR\|(3) was used to -set the \s-1SSL_SENT_SHUTDOWN\s0 state. -.PP -If a session was closed cleanly, the session object will be kept and all -settings corresponding. This explicitly means, that e.g. the special method -used during the session will be kept for the next handshake. So if the -session was a TLSv1 session, a \s-1SSL\s0 client object will use a TLSv1 client -method for the next handshake and a \s-1SSL\s0 server object will use a TLSv1 -server method, even if TLS_*_methods were chosen on startup. This -will might lead to connection failures (see \fBSSL_new\fR\|(3)) -for a description of the method's properties. -.PP -This function is not supported on \s-1QUIC SSL\s0 objects and returns failure if called -on such an object. -.SH "WARNINGS" -.IX Header "WARNINGS" -\&\fBSSL_clear()\fR resets the \s-1SSL\s0 object to allow for another connection. The -reset operation however keeps several settings of the last sessions -(some of these settings were made automatically during the last -handshake). It only makes sense for a new connection with the exact -same peer that shares these settings, and may fail if that peer -changes its settings between connections. Use the sequence -\&\fBSSL_get_session\fR\|(3); -\&\fBSSL_new\fR\|(3); -\&\fBSSL_set_session\fR\|(3); -\&\fBSSL_free\fR\|(3) -instead to avoid such failures -(or simply \fBSSL_free\fR\|(3); \fBSSL_new\fR\|(3) -if session reuse is not desired). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0" 4 -The \fBSSL_clear()\fR operation could not be performed. Check the error stack to -find out the reason. -.IP "1" 4 -.IX Item "1" -The \fBSSL_clear()\fR operation was successful. -.PP -\&\fBSSL_new\fR\|(3), \fBSSL_free\fR\|(3), -\&\fBSSL_shutdown\fR\|(3), \fBSSL_set_shutdown\fR\|(3), -\&\fBSSL_CTX_set_options\fR\|(3), \fBssl\fR\|(7), -\&\fBSSL_CTX_set_client_cert_cb\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_clear_chain_certs.3ossl b/openssl-install/share/man/man3/SSL_clear_chain_certs.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_clear_chain_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_clear_mode.3ossl b/openssl-install/share/man/man3/SSL_clear_mode.3ossl deleted file mode 120000 index ea309712..00000000 --- a/openssl-install/share/man/man3/SSL_clear_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_clear_options.3ossl b/openssl-install/share/man/man3/SSL_clear_options.3ossl deleted file mode 120000 index 742650be..00000000 --- a/openssl-install/share/man/man3/SSL_clear_options.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_options.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_cb_fn.3ossl b/openssl-install/share/man/man3/SSL_client_hello_cb_fn.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_cb_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get0_ciphers.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get0_ciphers.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get0_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get0_compression_methods.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get0_compression_methods.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get0_compression_methods.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get0_ext.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get0_ext.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get0_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get0_legacy_version.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get0_legacy_version.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get0_legacy_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get0_random.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get0_random.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get0_random.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get0_session_id.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get0_session_id.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get0_session_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get1_extensions_present.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get1_extensions_present.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get1_extensions_present.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_get_extension_order.3ossl b/openssl-install/share/man/man3/SSL_client_hello_get_extension_order.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_get_extension_order.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_hello_isv2.3ossl b/openssl-install/share/man/man3/SSL_client_hello_isv2.3ossl deleted file mode 120000 index 43730f70..00000000 --- a/openssl-install/share/man/man3/SSL_client_hello_isv2.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_client_hello_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_client_version.3ossl b/openssl-install/share/man/man3/SSL_client_version.3ossl deleted file mode 120000 index 5d8aa60f..00000000 --- a/openssl-install/share/man/man3/SSL_client_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_compress_certs.3ossl b/openssl-install/share/man/man3/SSL_compress_certs.3ossl deleted file mode 120000 index 7aaf058c..00000000 --- a/openssl-install/share/man/man3/SSL_compress_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_cert_comp_preference.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_config.3ossl b/openssl-install/share/man/man3/SSL_config.3ossl deleted file mode 120000 index 3bce9845..00000000 --- a/openssl-install/share/man/man3/SSL_config.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_config.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_connect.3ossl b/openssl-install/share/man/man3/SSL_connect.3ossl deleted file mode 100644 index ed673468..00000000 --- a/openssl-install/share/man/man3/SSL_connect.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_CONNECT 3ossl" -.TH SSL_CONNECT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_connect \- initiate the TLS/SSL handshake with an TLS/SSL server -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_connect(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_connect()\fR initiates the \s-1TLS/SSL\s0 handshake with a server. The communication -channel must already have been set and assigned to the \fBssl\fR by setting an -underlying \fB\s-1BIO\s0\fR. -.SH "NOTES" -.IX Header "NOTES" -The behaviour of \fBSSL_connect()\fR depends on the underlying \s-1BIO.\s0 -.PP -If the underlying \s-1BIO\s0 is \fBblocking\fR, \fBSSL_connect()\fR will only return once the -handshake has been finished or an error occurred. -.PP -If the underlying \s-1BIO\s0 is \fBnonblocking\fR, \fBSSL_connect()\fR will also return -when the underlying \s-1BIO\s0 could not satisfy the needs of \fBSSL_connect()\fR -to continue the handshake, indicating the problem by the return value \-1. -In this case a call to \fBSSL_get_error()\fR with the -return value of \fBSSL_connect()\fR will yield \fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. The calling process then must repeat the call after -taking appropriate action to satisfy the needs of \fBSSL_connect()\fR. -The action depends on the underlying \s-1BIO.\s0 When using a nonblocking socket, -nothing is to be done, but \fBselect()\fR can be used to check for the required -condition. When using a buffering \s-1BIO,\s0 like a \s-1BIO\s0 pair, data must be written -into or retrieved out of the \s-1BIO\s0 before being able to continue. -.PP -Many systems implement Nagle's algorithm by default which means that it will -buffer outgoing \s-1TCP\s0 data if a \s-1TCP\s0 packet has already been sent for which no -corresponding \s-1ACK\s0 has been received yet from the peer. This can have performance -impacts after a successful TLSv1.3 handshake or a successful TLSv1.2 (or below) -resumption handshake, because the last peer to communicate in the handshake is -the client. If the client is also the first to send application data (as is -typical for many protocols) then this data could be buffered until an \s-1ACK\s0 has -been received for the final handshake message. -.PP -The \fB\s-1TCP_NODELAY\s0\fR socket option is often available to disable Nagle's -algorithm. If an application opts to disable Nagle's algorithm consideration -should be given to turning it back on again later if appropriate. The helper -function \fBBIO_set_tcp_ndelay()\fR can be used to turn on or off the \fB\s-1TCP_NODELAY\s0\fR -option. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0" 4 -The \s-1TLS/SSL\s0 handshake was not successful but was shut down controlled and -by the specifications of the \s-1TLS/SSL\s0 protocol. Call \fBSSL_get_error()\fR with the -return value \fBret\fR to find out the reason. -.IP "1" 4 -.IX Item "1" -The \s-1TLS/SSL\s0 handshake was successfully completed, a \s-1TLS/SSL\s0 connection has been -established. -.IP "<0" 4 -.IX Item "<0" -The \s-1TLS/SSL\s0 handshake was not successful, because a fatal error occurred either -at the protocol level or a connection failure occurred. The shutdown was -not clean. It can also occur if action is needed to continue the operation -for nonblocking BIOs. Call \fBSSL_get_error()\fR with the return value \fBret\fR -to find out the reason. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_error\fR\|(3), \fBSSL_accept\fR\|(3), -\&\fBSSL_shutdown\fR\|(3), \fBssl\fR\|(7), \fBbio\fR\|(7), -\&\fBSSL_set_connect_state\fR\|(3), -\&\fBSSL_do_handshake\fR\|(3), -\&\fBSSL_CTX_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_ct_is_enabled.3ossl b/openssl-install/share/man/man3/SSL_ct_is_enabled.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/SSL_ct_is_enabled.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_ctrl.3ossl b/openssl-install/share/man/man3/SSL_ctrl.3ossl deleted file mode 120000 index 0dbfa7e7..00000000 --- a/openssl-install/share/man/man3/SSL_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_ctrl.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_custom_ext_add_cb_ex.3ossl b/openssl-install/share/man/man3/SSL_custom_ext_add_cb_ex.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/SSL_custom_ext_add_cb_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_custom_ext_free_cb_ex.3ossl b/openssl-install/share/man/man3/SSL_custom_ext_free_cb_ex.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/SSL_custom_ext_free_cb_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_custom_ext_parse_cb_ex.3ossl b/openssl-install/share/man/man3/SSL_custom_ext_parse_cb_ex.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/SSL_custom_ext_parse_cb_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_dane_clear_flags.3ossl b/openssl-install/share/man/man3/SSL_dane_clear_flags.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_dane_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_dane_enable.3ossl b/openssl-install/share/man/man3/SSL_dane_enable.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_dane_enable.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_dane_set_flags.3ossl b/openssl-install/share/man/man3/SSL_dane_set_flags.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_dane_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_dane_tlsa_add.3ossl b/openssl-install/share/man/man3/SSL_dane_tlsa_add.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_dane_tlsa_add.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_disable_ct.3ossl b/openssl-install/share/man/man3/SSL_disable_ct.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/SSL_disable_ct.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_do_handshake.3ossl b/openssl-install/share/man/man3/SSL_do_handshake.3ossl deleted file mode 100644 index 6cd95c9a..00000000 --- a/openssl-install/share/man/man3/SSL_do_handshake.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_DO_HANDSHAKE 3ossl" -.TH SSL_DO_HANDSHAKE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_do_handshake \- perform a TLS/SSL handshake -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_do_handshake(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_do_handshake()\fR will wait for a \s-1SSL/TLS\s0 handshake to take place. If the -connection is in client mode, the handshake will be started. The handshake -routines may have to be explicitly set in advance using either -\&\fBSSL_set_connect_state\fR\|(3) or -\&\fBSSL_set_accept_state\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The behaviour of \fBSSL_do_handshake()\fR depends on the underlying \s-1BIO.\s0 -.PP -If the underlying \s-1BIO\s0 is \fBblocking\fR, \fBSSL_do_handshake()\fR will only return -once the handshake has been finished or an error occurred. -.PP -If the underlying \s-1BIO\s0 is \fBnonblocking\fR, \fBSSL_do_handshake()\fR will also return -when the underlying \s-1BIO\s0 could not satisfy the needs of \fBSSL_do_handshake()\fR -to continue the handshake. In this case a call to \fBSSL_get_error()\fR with the -return value of \fBSSL_do_handshake()\fR will yield \fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. The calling process then must repeat the call after -taking appropriate action to satisfy the needs of \fBSSL_do_handshake()\fR. -The action depends on the underlying \s-1BIO.\s0 When using a nonblocking socket, -nothing is to be done, but \fBselect()\fR can be used to check for the required -condition. When using a buffering \s-1BIO,\s0 like a \s-1BIO\s0 pair, data must be written -into or retrieved out of the \s-1BIO\s0 before being able to continue. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0" 4 -The \s-1TLS/SSL\s0 handshake was not successful but was shut down controlled and -by the specifications of the \s-1TLS/SSL\s0 protocol. Call \fBSSL_get_error()\fR with the -return value \fBret\fR to find out the reason. -.IP "1" 4 -.IX Item "1" -The \s-1TLS/SSL\s0 handshake was successfully completed, a \s-1TLS/SSL\s0 connection has been -established. -.IP "<0" 4 -.IX Item "<0" -The \s-1TLS/SSL\s0 handshake was not successful because a fatal error occurred either -at the protocol level or a connection failure occurred. The shutdown was -not clean. It can also occur if action is needed to continue the operation -for nonblocking BIOs. Call \fBSSL_get_error()\fR with the return value \fBret\fR -to find out the reason. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_error\fR\|(3), \fBSSL_connect\fR\|(3), -\&\fBSSL_accept\fR\|(3), \fBssl\fR\|(7), \fBbio\fR\|(7), -\&\fBSSL_set_connect_state\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_dup.3ossl b/openssl-install/share/man/man3/SSL_dup.3ossl deleted file mode 120000 index 2a935814..00000000 --- a/openssl-install/share/man/man3/SSL_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_enable_ct.3ossl b/openssl-install/share/man/man3/SSL_enable_ct.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/SSL_enable_ct.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_export_keying_material.3ossl b/openssl-install/share/man/man3/SSL_export_keying_material.3ossl deleted file mode 100644 index 9e736cf4..00000000 --- a/openssl-install/share/man/man3/SSL_export_keying_material.3ossl +++ /dev/null @@ -1,222 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_EXPORT_KEYING_MATERIAL 3ossl" -.TH SSL_EXPORT_KEYING_MATERIAL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_export_keying_material, -SSL_export_keying_material_early -\&\- obtain keying material for application use -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_export_keying_material(SSL *s, unsigned char *out, size_t olen, -\& const char *label, size_t llen, -\& const unsigned char *context, -\& size_t contextlen, int use_context); -\& -\& int SSL_export_keying_material_early(SSL *s, unsigned char *out, size_t olen, -\& const char *label, size_t llen, -\& const unsigned char *context, -\& size_t contextlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -During the creation of a \s-1TLS\s0 or \s-1DTLS\s0 connection shared keying material is -established between the two endpoints. The functions -\&\fBSSL_export_keying_material()\fR and \fBSSL_export_keying_material_early()\fR enable an -application to use some of this keying material for its own purposes in -accordance with \s-1RFC5705\s0 (for TLSv1.2 and below) or \s-1RFC8446\s0 (for TLSv1.3). -.PP -\&\fBSSL_export_keying_material()\fR derives keying material using -the \fIexporter_master_secret\fR established in the handshake. -.PP -\&\fBSSL_export_keying_material_early()\fR is only usable with TLSv1.3, and derives -keying material using the \fIearly_exporter_master_secret\fR (as defined in the -\&\s-1TLS 1.3 RFC\s0). For the client, the \fIearly_exporter_master_secret\fR is only -available when the client attempts to send 0\-RTT data. For the server, it is -only available when the server accepts 0\-RTT data. -.PP -An application may need to securely establish the context within which this -keying material will be used. For example this may include identifiers for the -application session, application algorithms or parameters, or the lifetime of -the context. The context value is left to the application but must be the same -on both sides of the communication. -.PP -For a given \s-1SSL\s0 connection \fBs\fR, \fBolen\fR bytes of data will be written to -\&\fBout\fR. The application specific context should be supplied in the location -pointed to by \fBcontext\fR and should be \fBcontextlen\fR bytes long. Provision of -a context is optional. If the context should be omitted entirely then -\&\fBuse_context\fR should be set to 0. Otherwise it should be any other value. If -\&\fBuse_context\fR is 0 then the values of \fBcontext\fR and \fBcontextlen\fR are ignored. -Note that in TLSv1.2 and below a zero length context is treated differently from -no context at all, and will result in different keying material being returned. -In TLSv1.3 a zero length context is that same as no context at all and will -result in the same keying material being returned. -.PP -An application specific label should be provided in the location pointed to by -\&\fBlabel\fR and should be \fBllen\fR bytes long. Typically this will be a value from -the \s-1IANA\s0 Exporter Label Registry -(). -Alternatively labels beginning with \*(L"\s-1EXPERIMENTAL\*(R"\s0 are permitted by the standard -to be used without registration. TLSv1.3 imposes a maximum label length of -249 bytes. -.PP -Note that this function is only defined for TLSv1.0 and above, and DTLSv1.0 and -above. Attempting to use it in SSLv3 will result in an error. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_export_keying_material()\fR returns 0 or \-1 on failure or 1 on success. -.PP -\&\fBSSL_export_keying_material_early()\fR returns 0 on failure or 1 on success. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_export_keying_material_early()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_export_keying_material_early.3ossl b/openssl-install/share/man/man3/SSL_export_keying_material_early.3ossl deleted file mode 120000 index 02aba987..00000000 --- a/openssl-install/share/man/man3/SSL_export_keying_material_early.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_export_keying_material.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_extension_supported.3ossl b/openssl-install/share/man/man3/SSL_extension_supported.3ossl deleted file mode 100644 index 97d26b12..00000000 --- a/openssl-install/share/man/man3/SSL_extension_supported.3ossl +++ /dev/null @@ -1,409 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_EXTENSION_SUPPORTED 3ossl" -.TH SSL_EXTENSION_SUPPORTED 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_extension_supported, -SSL_custom_ext_add_cb_ex, -SSL_custom_ext_free_cb_ex, -SSL_custom_ext_parse_cb_ex, -SSL_CTX_add_custom_ext, -SSL_CTX_add_client_custom_ext, SSL_CTX_add_server_custom_ext, -custom_ext_add_cb, custom_ext_free_cb, custom_ext_parse_cb -\&\- custom TLS extension handling -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*SSL_custom_ext_add_cb_ex)(SSL *s, unsigned int ext_type, -\& unsigned int context, -\& const unsigned char **out, -\& size_t *outlen, X509 *x, -\& size_t chainidx, int *al, -\& void *add_arg); -\& -\& typedef void (*SSL_custom_ext_free_cb_ex)(SSL *s, unsigned int ext_type, -\& unsigned int context, -\& const unsigned char *out, -\& void *add_arg); -\& -\& typedef int (*SSL_custom_ext_parse_cb_ex)(SSL *s, unsigned int ext_type, -\& unsigned int context, -\& const unsigned char *in, -\& size_t inlen, X509 *x, -\& size_t chainidx, int *al, -\& void *parse_arg); -\& -\& int SSL_CTX_add_custom_ext(SSL_CTX *ctx, unsigned int ext_type, -\& unsigned int context, -\& SSL_custom_ext_add_cb_ex add_cb, -\& SSL_custom_ext_free_cb_ex free_cb, -\& void *add_arg, -\& SSL_custom_ext_parse_cb_ex parse_cb, -\& void *parse_arg); -\& -\& typedef int (*custom_ext_add_cb)(SSL *s, unsigned int ext_type, -\& const unsigned char **out, -\& size_t *outlen, int *al, -\& void *add_arg); -\& -\& typedef void (*custom_ext_free_cb)(SSL *s, unsigned int ext_type, -\& const unsigned char *out, -\& void *add_arg); -\& -\& typedef int (*custom_ext_parse_cb)(SSL *s, unsigned int ext_type, -\& const unsigned char *in, -\& size_t inlen, int *al, -\& void *parse_arg); -\& -\& int SSL_CTX_add_client_custom_ext(SSL_CTX *ctx, unsigned int ext_type, -\& custom_ext_add_cb add_cb, -\& custom_ext_free_cb free_cb, void *add_arg, -\& custom_ext_parse_cb parse_cb, -\& void *parse_arg); -\& -\& int SSL_CTX_add_server_custom_ext(SSL_CTX *ctx, unsigned int ext_type, -\& custom_ext_add_cb add_cb, -\& custom_ext_free_cb free_cb, void *add_arg, -\& custom_ext_parse_cb parse_cb, -\& void *parse_arg); -\& -\& int SSL_extension_supported(unsigned int ext_type); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_add_custom_ext()\fR adds a custom extension for a \s-1TLS/DTLS\s0 client or server -for all supported protocol versions with extension type \fBext_type\fR and -callbacks \fBadd_cb\fR, \fBfree_cb\fR and \fBparse_cb\fR (see the -\&\*(L"\s-1EXTENSION CALLBACKS\*(R"\s0 section below). The \fBcontext\fR value determines -which messages and under what conditions the extension will be added/parsed (see -the \*(L"\s-1EXTENSION CONTEXTS\*(R"\s0 section below). -.PP -\&\fBSSL_CTX_add_client_custom_ext()\fR adds a custom extension for a \s-1TLS/DTLS\s0 client -with extension type \fBext_type\fR and callbacks \fBadd_cb\fR, \fBfree_cb\fR and -\&\fBparse_cb\fR. This function is similar to \fBSSL_CTX_add_custom_ext()\fR except it only -applies to clients, uses the older style of callbacks, and implicitly sets the -\&\fBcontext\fR value to: -.PP -.Vb 2 -\& SSL_EXT_TLS1_2_AND_BELOW_ONLY | SSL_EXT_CLIENT_HELLO -\& | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_IGNORE_ON_RESUMPTION -.Ve -.PP -\&\fBSSL_CTX_add_server_custom_ext()\fR adds a custom extension for a \s-1TLS/DTLS\s0 server -with extension type \fBext_type\fR and callbacks \fBadd_cb\fR, \fBfree_cb\fR and -\&\fBparse_cb\fR. This function is similar to \fBSSL_CTX_add_custom_ext()\fR except it -only applies to servers, uses the older style of callbacks, and implicitly sets -the \fBcontext\fR value to the same as for \fBSSL_CTX_add_client_custom_ext()\fR above. -.PP -The \fBext_type\fR parameter corresponds to the \fBextension_type\fR field of -\&\s-1RFC5246\s0 et al. It is \fBnot\fR a \s-1NID.\s0 In all cases the extension type must not be -handled by OpenSSL internally or an error occurs. -.PP -\&\fBSSL_extension_supported()\fR returns 1 if the extension \fBext_type\fR is handled -internally by OpenSSL and 0 otherwise. -.SH "EXTENSION CALLBACKS" -.IX Header "EXTENSION CALLBACKS" -The callback \fBadd_cb\fR is called to send custom extension data to be -included in various \s-1TLS\s0 messages. The \fBext_type\fR parameter is set to the -extension type which will be added and \fBadd_arg\fR to the value set when the -extension handler was added. When using the new style callbacks the \fBcontext\fR -parameter will indicate which message is currently being constructed e.g. for -the ClientHello it will be set to \fB\s-1SSL_EXT_CLIENT_HELLO\s0\fR. -.PP -If the application wishes to include the extension \fBext_type\fR it should -set \fB*out\fR to the extension data, set \fB*outlen\fR to the length of the -extension data and return 1. -.PP -If the \fBadd_cb\fR does not wish to include the extension it must return 0. -.PP -If \fBadd_cb\fR returns \-1 a fatal handshake error occurs using the \s-1TLS\s0 -alert value specified in \fB*al\fR. -.PP -When constructing the ClientHello, if \fBadd_cb\fR is set to \s-1NULL\s0 a zero length -extension is added for \fBext_type\fR. For all other messages if \fBadd_cb\fR is set -to \s-1NULL\s0 then no extension is added. -.PP -When constructing a Certificate message the callback will be called for each -certificate in the message. The \fBx\fR parameter will indicate the -current certificate and the \fBchainidx\fR parameter will indicate the position -of the certificate in the message. The first certificate is always the end -entity certificate and has a \fBchainidx\fR value of 0. The certificates are in the -order that they were received in the Certificate message. -.PP -For all messages except the ServerHello and EncryptedExtensions every -registered \fBadd_cb\fR is always called to see if the application wishes to add an -extension (as long as all requirements of the specified \fBcontext\fR are met). -.PP -For the ServerHello and EncryptedExtension messages every registered \fBadd_cb\fR -is called once if and only if the requirements of the specified \fBcontext\fR are -met and the corresponding extension was received in the ClientHello. That is, if -no corresponding extension was received in the ClientHello then \fBadd_cb\fR will -not be called. -.PP -If an extension is added (that is \fBadd_cb\fR returns 1) \fBfree_cb\fR is called -(if it is set) with the value of \fBout\fR set by the add callback. It can be -used to free up any dynamic extension data set by \fBadd_cb\fR. Since \fBout\fR is -constant (to permit use of constant data in \fBadd_cb\fR) applications may need to -cast away const to free the data. -.PP -The callback \fBparse_cb\fR receives data for \s-1TLS\s0 extensions. The callback is only -called if the extension is present and relevant for the context (see -\&\*(L"\s-1EXTENSION CONTEXTS\*(R"\s0 below). -.PP -The extension data consists of \fBinlen\fR bytes in the buffer \fBin\fR for the -extension \fBext_type\fR. -.PP -If the message being parsed is a TLSv1.3 compatible Certificate message then -\&\fBparse_cb\fR will be called for each certificate contained within the message. -The \fBx\fR parameter will indicate the current certificate and the \fBchainidx\fR -parameter will indicate the position of the certificate in the message. The -first certificate is always the end entity certificate and has a \fBchainidx\fR -value of 0. -.PP -If the \fBparse_cb\fR considers the extension data acceptable it must return -1. If it returns 0 or a negative value a fatal handshake error occurs -using the \s-1TLS\s0 alert value specified in \fB*al\fR. -.PP -The buffer \fBin\fR is a temporary internal buffer which will not be valid after -the callback returns. -.SH "EXTENSION CONTEXTS" -.IX Header "EXTENSION CONTEXTS" -An extension context defines which messages and under which conditions an -extension should be added or expected. The context is built up by performing -a bitwise \s-1OR\s0 of multiple pre-defined values together. The valid context values -are: -.IP "\s-1SSL_EXT_TLS_ONLY\s0" 4 -.IX Item "SSL_EXT_TLS_ONLY" -The extension is only allowed in \s-1TLS\s0 -.IP "\s-1SSL_EXT_DTLS_ONLY\s0" 4 -.IX Item "SSL_EXT_DTLS_ONLY" -The extension is only allowed in \s-1DTLS\s0 -.IP "\s-1SSL_EXT_TLS_IMPLEMENTATION_ONLY\s0" 4 -.IX Item "SSL_EXT_TLS_IMPLEMENTATION_ONLY" -The extension is allowed in \s-1DTLS,\s0 but there is only a \s-1TLS\s0 implementation -available (so it is ignored in \s-1DTLS\s0). -.IP "\s-1SSL_EXT_SSL3_ALLOWED\s0" 4 -.IX Item "SSL_EXT_SSL3_ALLOWED" -Extensions are not typically defined for SSLv3. Setting this value will allow -the extension in SSLv3. Applications will not typically need to use this. -.IP "\s-1SSL_EXT_TLS1_2_AND_BELOW_ONLY\s0" 4 -.IX Item "SSL_EXT_TLS1_2_AND_BELOW_ONLY" -The extension is only defined for TLSv1.2/DTLSv1.2 and below. Servers will -ignore this extension if it is present in the ClientHello and TLSv1.3 is -negotiated. -.IP "\s-1SSL_EXT_TLS1_3_ONLY\s0" 4 -.IX Item "SSL_EXT_TLS1_3_ONLY" -The extension is only defined for \s-1TLS1.3\s0 and above. Servers will ignore this -extension if it is present in the ClientHello and TLSv1.2 or below is -negotiated. -.IP "\s-1SSL_EXT_IGNORE_ON_RESUMPTION\s0" 4 -.IX Item "SSL_EXT_IGNORE_ON_RESUMPTION" -The extension will be ignored during parsing if a previous session is being -successfully resumed. -.IP "\s-1SSL_EXT_CLIENT_HELLO\s0" 4 -.IX Item "SSL_EXT_CLIENT_HELLO" -The extension may be present in the ClientHello message. -.IP "\s-1SSL_EXT_TLS1_2_SERVER_HELLO\s0" 4 -.IX Item "SSL_EXT_TLS1_2_SERVER_HELLO" -The extension may be present in a TLSv1.2 or below compatible ServerHello -message. -.IP "\s-1SSL_EXT_TLS1_3_SERVER_HELLO\s0" 4 -.IX Item "SSL_EXT_TLS1_3_SERVER_HELLO" -The extension may be present in a TLSv1.3 compatible ServerHello message. -.IP "\s-1SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS\s0" 4 -.IX Item "SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS" -The extension may be present in an EncryptedExtensions message. -.IP "\s-1SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST\s0" 4 -.IX Item "SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST" -The extension may be present in a HelloRetryRequest message. -.IP "\s-1SSL_EXT_TLS1_3_CERTIFICATE\s0" 4 -.IX Item "SSL_EXT_TLS1_3_CERTIFICATE" -The extension may be present in a TLSv1.3 compatible Certificate message. -.IP "\s-1SSL_EXT_TLS1_3_NEW_SESSION_TICKET\s0" 4 -.IX Item "SSL_EXT_TLS1_3_NEW_SESSION_TICKET" -The extension may be present in a TLSv1.3 compatible NewSessionTicket message. -.IP "\s-1SSL_EXT_TLS1_3_CERTIFICATE_REQUEST\s0" 4 -.IX Item "SSL_EXT_TLS1_3_CERTIFICATE_REQUEST" -The extension may be present in a TLSv1.3 compatible CertificateRequest message. -.PP -The context must include at least one message value (otherwise the extension -will never be used). -.SH "NOTES" -.IX Header "NOTES" -The \fBadd_arg\fR and \fBparse_arg\fR parameters can be set to arbitrary values -which will be passed to the corresponding callbacks. They can, for example, -be used to store the extension data received in a convenient structure or -pass the extension data to be added or freed when adding extensions. -.PP -If the same custom extension type is received multiple times a fatal -\&\fBdecode_error\fR alert is sent and the handshake aborts. If a custom extension -is received in a ServerHello/EncryptedExtensions message which was not sent in -the ClientHello a fatal \fBunsupported_extension\fR alert is sent and the -handshake is aborted. The ServerHello/EncryptedExtensions \fBadd_cb\fR callback is -only called if the corresponding extension was received in the ClientHello. This -is compliant with the \s-1TLS\s0 specifications. This behaviour ensures that each -callback is called at most once and that an application can never send -unsolicited extensions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_add_custom_ext()\fR, \fBSSL_CTX_add_client_custom_ext()\fR and -\&\fBSSL_CTX_add_server_custom_ext()\fR return 1 for success and 0 for failure. A -failure can occur if an attempt is made to add the same \fBext_type\fR more than -once, if an attempt is made to use an extension type handled internally by -OpenSSL or if an internal error occurs (for example a memory allocation -failure). -.PP -\&\fBSSL_extension_supported()\fR returns 1 if the extension \fBext_type\fR is handled -internally by OpenSSL and 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_CTX_add_custom_ext()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2014\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_free.3ossl b/openssl-install/share/man/man3/SSL_free.3ossl deleted file mode 100644 index f4c4d8bd..00000000 --- a/openssl-install/share/man/man3/SSL_free.3ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_FREE 3ossl" -.TH SSL_FREE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_free \- free an allocated SSL structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_free(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_free()\fR decrements the reference count of \fBssl\fR, and removes the \s-1SSL\s0 -structure pointed to by \fBssl\fR and frees up the allocated memory if the -reference count has reached 0. -If \fBssl\fR is \s-1NULL\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -\&\fBSSL_free()\fR also calls the \fBfree()\fRing procedures for indirectly affected items, if -applicable: the buffering \s-1BIO,\s0 the read and write BIOs, -cipher lists specially created for this \fBssl\fR, the \fB\s-1SSL_SESSION\s0\fR. -Do not explicitly free these indirectly freed up items before or after -calling \fBSSL_free()\fR, as trying to free things twice may lead to program -failure. -.PP -The ssl session has reference counts from two users: the \s-1SSL\s0 object, for -which the reference count is removed by \fBSSL_free()\fR and the internal -session cache. If the session is considered bad, because -\&\fBSSL_shutdown\fR\|(3) was not called for the connection -and \fBSSL_set_shutdown\fR\|(3) was not used to set the -\&\s-1SSL_SENT_SHUTDOWN\s0 state, the session will also be removed -from the session cache as required by \s-1RFC2246.\s0 -.PP -When used to free a \s-1QUIC\s0 stream \s-1SSL\s0 object, the respective sending and receiving -parts of the stream are reset unless those parts have already been concluded -normally: -.IP "\(bu" 4 -If the stream has a sending part (in other words, if it is bidirectional or a -locally-initiated unidirectional stream) and that part has not been concluded -via a call to \fBSSL_stream_conclude\fR\|(3) or \fBSSL_stream_reset\fR\|(3) on the \s-1QUIC\s0 -stream \s-1SSL\s0 object, a call to \fBSSL_free()\fR automatically resets the sending part of -the stream as though \fBSSL_stream_reset\fR\|(3) were called with a \s-1QUIC\s0 application -error code of 0. -.IP "\(bu" 4 -If the stream has a receiving part (in other words, if it is bidirectional or a -remotely-initiated unidirectional stream), and the peer has not yet concluded -that part of the stream normally (such as via a call to -\&\fBSSL_stream_conclude\fR\|(3) on its own end), a call to \fBSSL_free()\fR automatically -requests the reset of the receiving part of the stream using a \s-1QUIC STOP_SENDING\s0 -frame with a \s-1QUIC\s0 application error code of 0. Note that as per the \s-1QUIC\s0 -protocol, this will automatically cause the peer to reset that part of the -stream in turn (which is its sending part). -.PP -A \s-1QUIC\s0 stream \s-1SSL\s0 object maintains a reference to a \s-1QUIC\s0 connection \s-1SSL\s0 object -internally, therefore a \s-1QUIC\s0 stream \s-1SSL\s0 object and its parent \s-1QUIC\s0 connection -\&\s-1SSL\s0 object can be freed in either order. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_free()\fR does not provide diagnostic information. -.PP -\&\fBSSL_new\fR\|(3), \fBSSL_clear\fR\|(3), -\&\fBSSL_shutdown\fR\|(3), \fBSSL_set_shutdown\fR\|(3), -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_free_buffers.3ossl b/openssl-install/share/man/man3/SSL_free_buffers.3ossl deleted file mode 120000 index bfda3238..00000000 --- a/openssl-install/share/man/man3/SSL_free_buffers.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_alloc_buffers.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_CA_list.3ossl b/openssl-install/share/man/man3/SSL_get0_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_get0_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_alpn_selected.3ossl b/openssl-install/share/man/man3/SSL_get0_alpn_selected.3ossl deleted file mode 120000 index fa1385af..00000000 --- a/openssl-install/share/man/man3/SSL_get0_alpn_selected.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_alpn_select_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_chain_cert_store.3ossl b/openssl-install/share/man/man3/SSL_get0_chain_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_get0_chain_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_chain_certs.3ossl b/openssl-install/share/man/man3/SSL_get0_chain_certs.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_get0_chain_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_client_cert_type.3ossl b/openssl-install/share/man/man3/SSL_get0_client_cert_type.3ossl deleted file mode 120000 index 44c96a96..00000000 --- a/openssl-install/share/man/man3/SSL_get0_client_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_server_cert_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_connection.3ossl b/openssl-install/share/man/man3/SSL_get0_connection.3ossl deleted file mode 100644 index 3d39399b..00000000 --- a/openssl-install/share/man/man3/SSL_get0_connection.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET0_CONNECTION 3ossl" -.TH SSL_GET0_CONNECTION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get0_connection, SSL_is_connection \- get a QUIC connection SSL object from a -QUIC stream SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL *SSL_get0_connection(SSL *ssl); -\& int SSL_is_connection(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBSSL_get0_connection()\fR function, when called on a \s-1QUIC\s0 stream \s-1SSL\s0 object, -returns the \s-1QUIC\s0 connection \s-1SSL\s0 object which the \s-1QUIC\s0 stream \s-1SSL\s0 object belongs -to. -.PP -When called on a \s-1QUIC\s0 connection \s-1SSL\s0 object, it returns the same object. -.PP -When called on a non-QUIC object, it returns the same object it was passed. -.PP -\&\fBSSL_is_connection()\fR returns 1 for \s-1QUIC\s0 connection \s-1SSL\s0 objects and for non-QUIC -\&\s-1SSL\s0 objects, but returns 0 for \s-1QUIC\s0 stream \s-1SSL\s0 objects. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get0_connection()\fR returns the \s-1QUIC\s0 connection \s-1SSL\s0 object (for a \s-1QUIC\s0 stream -\&\s-1SSL\s0 object) and otherwise returns the same \s-1SSL\s0 object passed. It always returns -non-NULL. -.PP -\&\fBSSL_is_connection()\fR returns 1 if the \s-1SSL\s0 object is not a \s-1QUIC\s0 stream \s-1SSL\s0 object -and 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_new\fR\|(3), \fBSSL_new_stream\fR\|(3), \fBSSL_accept_stream\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get0_dane_authority.3ossl b/openssl-install/share/man/man3/SSL_get0_dane_authority.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_get0_dane_authority.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_dane_tlsa.3ossl b/openssl-install/share/man/man3/SSL_get0_dane_tlsa.3ossl deleted file mode 120000 index 0e4ce18c..00000000 --- a/openssl-install/share/man/man3/SSL_get0_dane_tlsa.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_dane_enable.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_group_name.3ossl b/openssl-install/share/man/man3/SSL_get0_group_name.3ossl deleted file mode 100644 index 2e196bc3..00000000 --- a/openssl-install/share/man/man3/SSL_get0_group_name.3ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET0_GROUP_NAME 3ossl" -.TH SSL_GET0_GROUP_NAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get0_group_name \- get name of the group that was used for the key -agreement of the current TLS session establishment -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_get0_group_name(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get0_group_name()\fR returns the name of the group that was used for -the key agreement of the current \s-1TLS\s0 session establishment. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If non-NULL, \fBSSL_get0_group_name()\fR returns the name of the group that was used for -the key agreement of the current \s-1TLS\s0 session establishment. -If \fBSSL_get0_group_name()\fR returns \s-1NULL,\s0 an error occurred; possibly no \s-1TLS\s0 session -has been established. See also \fBSSL_get_negotiated_group\fR\|(3). -.PP -Note that the return value is valid only during the lifetime of the -\&\s-1SSL\s0 object \fIssl\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_get_negotiated_group\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get0_iana_groups.3ossl b/openssl-install/share/man/man3/SSL_get0_iana_groups.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_get0_iana_groups.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_next_proto_negotiated.3ossl b/openssl-install/share/man/man3/SSL_get0_next_proto_negotiated.3ossl deleted file mode 120000 index fa1385af..00000000 --- a/openssl-install/share/man/man3/SSL_get0_next_proto_negotiated.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_alpn_select_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_param.3ossl b/openssl-install/share/man/man3/SSL_get0_param.3ossl deleted file mode 120000 index fd781e23..00000000 --- a/openssl-install/share/man/man3/SSL_get0_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_peer_CA_list.3ossl b/openssl-install/share/man/man3/SSL_get0_peer_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_get0_peer_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_peer_certificate.3ossl b/openssl-install/share/man/man3/SSL_get0_peer_certificate.3ossl deleted file mode 120000 index 1c33b486..00000000 --- a/openssl-install/share/man/man3/SSL_get0_peer_certificate.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_peer_rpk.3ossl b/openssl-install/share/man/man3/SSL_get0_peer_rpk.3ossl deleted file mode 100644 index 12bf5027..00000000 --- a/openssl-install/share/man/man3/SSL_get0_peer_rpk.3ossl +++ /dev/null @@ -1,227 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET0_PEER_RPK 3ossl" -.TH SSL_GET0_PEER_RPK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_add_expected_rpk, -SSL_get_negotiated_client_cert_type, -SSL_get_negotiated_server_cert_type, -SSL_get0_peer_rpk, -SSL_SESSION_get0_peer_rpk \- raw public key (RFC7250) support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_add_expected_rpk(SSL *s, EVP_PKEY *rpk); -\& int SSL_get_negotiated_client_cert_type(const SSL *s); -\& int SSL_get_negotiated_server_cert_type(const SSL *s); -\& EVP_PKEY *SSL_get0_peer_rpk(const SSL *s); -\& EVP_PKEY *SSL_SESSION_get0_peer_rpk(const SSL_SESSION *ss); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_add_expected_rpk()\fR adds a \s-1DANE TLSA\s0 record matching public key \fBrpk\fR -to \s-1SSL\s0 \fBs\fR's \s-1DANE\s0 validation policy. -.PP -\&\fBSSL_get_negotiated_client_cert_type()\fR returns the connection's negotiated -client certificate type. -.PP -\&\fBSSL_get_negotiated_server_cert_type()\fR returns the connection's negotiated -server certificate type. -.PP -\&\fBSSL_get0_peer_rpk()\fR returns the peer's raw public key from \s-1SSL\s0 \fBs\fR. -.PP -\&\fBSSL_SESSION_get0_peer_rpk()\fR returns the peer's raw public key from -\&\s-1SSL_SESSION\s0 \fBss\fR. -.SH "NOTES" -.IX Header "NOTES" -Raw public keys are used in place of certificates when the option is -negotiated. -\&\fB\fBSSL_add_expected_rpk()\fB\fR may be called multiple times to configure -multiple trusted keys, this makes it possible to allow for key rotation, -where a peer might be expected to offer an \*(L"old\*(R" or \*(L"new\*(R" key and the -endpoint must be able to accept either one. -.PP -When raw public keys are used, the certificate verify callback is called, and -may be used to inspect the public key via \fBX509_STORE_CTX_get0_rpk\fR\|(3). -Raw public keys have no subject, issuer, validity dates nor digital signature -to verify. They can, however, be matched verbatim or by their digest value, this -is done by specifying one or more \s-1TLSA\s0 records, see \fBSSL_CTX_dane_enable\fR\|(3). -.PP -The raw public key is typically taken from the certificate assigned to the -connection (e.g. via \fBSSL_use_certificate\fR\|(3)), but if a certificate is not -configured, then the public key will be extracted from the assigned -private key. -.PP -The \fBSSL_add_expected_rpk()\fR function is a wrapper around -\&\fBSSL_dane_tlsa_add\fR\|(3). -When \s-1DANE\s0 is enabled via \fBSSL_dane_enable\fR\|(3), the configured \s-1TLSA\s0 records -will be used to validate the peer's public key or certificate. -If \s-1DANE\s0 is not enabled, then no validation will occur. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_add_expected_rpk()\fR returns 1 on success and 0 on failure. -.PP -\&\fBSSL_get0_peer_rpk()\fR and \fBSSL_SESSION_get0_peer_rpk()\fR return the peer's raw -public key as an \s-1EVP_PKEY\s0 or \s-1NULL\s0 when the raw public key is not available. -.PP -\&\fBSSL_get_negotiated_client_cert_type()\fR and \fBSSL_get_negotiated_server_cert_type()\fR -return one of the following values: -.IP "TLSEXT_cert_type_x509" 4 -.IX Item "TLSEXT_cert_type_x509" -.PD 0 -.IP "TLSEXT_cert_type_rpk" 4 -.IX Item "TLSEXT_cert_type_rpk" -.PD -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_dane_enable\fR\|(3), -\&\fBSSL_CTX_set_options\fR\|(3), -\&\fBSSL_dane_enable\fR\|(3), -\&\fBSSL_get_verify_result\fR\|(3), -\&\fBSSL_set_verify\fR\|(3), -\&\fBSSL_use_certificate\fR\|(3), -\&\fBX509_STORE_CTX_get0_rpk\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. diff --git a/openssl-install/share/man/man3/SSL_get0_peer_scts.3ossl b/openssl-install/share/man/man3/SSL_get0_peer_scts.3ossl deleted file mode 100644 index d8f7af32..00000000 --- a/openssl-install/share/man/man3/SSL_get0_peer_scts.3ossl +++ /dev/null @@ -1,176 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET0_PEER_SCTS 3ossl" -.TH SSL_GET0_PEER_SCTS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get0_peer_scts \- get SCTs received -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const STACK_OF(SCT) *SSL_get0_peer_scts(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get0_peer_scts()\fR returns the signed certificate timestamps (SCTs) that have -been received. If this is the first time that this function has been called for -a given \fB\s-1SSL\s0\fR instance, it will examine the \s-1TLS\s0 extensions, \s-1OCSP\s0 response and -the peer's certificate for SCTs. Future calls will return the same SCTs. -.SH "RESTRICTIONS" -.IX Header "RESTRICTIONS" -If no Certificate Transparency validation callback has been set (using -\&\fBSSL_CTX_set_ct_validation_callback\fR or \fBSSL_set_ct_validation_callback\fR), -this function is not guaranteed to return all of the SCTs that the peer is -capable of sending. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get0_peer_scts()\fR returns a list of SCTs found, or \s-1NULL\s0 if an error occurs. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_ct_validation_callback\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get0_peername.3ossl b/openssl-install/share/man/man3/SSL_get0_peername.3ossl deleted file mode 120000 index b101e006..00000000 --- a/openssl-install/share/man/man3/SSL_get0_peername.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_host.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_security_ex_data.3ossl b/openssl-install/share/man/man3/SSL_get0_security_ex_data.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_get0_security_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_server_cert_type.3ossl b/openssl-install/share/man/man3/SSL_get0_server_cert_type.3ossl deleted file mode 120000 index 44c96a96..00000000 --- a/openssl-install/share/man/man3/SSL_get0_server_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_server_cert_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_session.3ossl b/openssl-install/share/man/man3/SSL_get0_session.3ossl deleted file mode 120000 index f7697d29..00000000 --- a/openssl-install/share/man/man3/SSL_get0_session.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_session.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_verified_chain.3ossl b/openssl-install/share/man/man3/SSL_get0_verified_chain.3ossl deleted file mode 120000 index c69a2bea..00000000 --- a/openssl-install/share/man/man3/SSL_get0_verified_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_cert_chain.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get0_verify_cert_store.3ossl b/openssl-install/share/man/man3/SSL_get0_verify_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_get0_verify_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get1_builtin_sigalgs.3ossl b/openssl-install/share/man/man3/SSL_get1_builtin_sigalgs.3ossl deleted file mode 100644 index 6ad19a0d..00000000 --- a/openssl-install/share/man/man3/SSL_get1_builtin_sigalgs.3ossl +++ /dev/null @@ -1,173 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET1_BUILTIN_SIGALGS 3ossl" -.TH SSL_GET1_BUILTIN_SIGALGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get1_builtin_sigalgs \- get list of built\-in signature algorithms -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& char *SSL_get1_builtin_sigalgs(OSSL_LIB_CTX *libctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Return the colon-separated list of built-in and available \s-1TLS\s0 signature -algorithms. -The string returned must be freed by the user using \fBOPENSSL_free\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The string may be empty (strlen==0) if none of the built-in \s-1TLS\s0 signature -algorithms can be activated, e.g., if suitable providers are missing. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\s-1NULL\s0 may be returned if no memory could be allocated. Otherwise, a -newly allocated string is always returned but it may have strlen == 0. -.SH "HISTORY" -.IX Header "HISTORY" -This call was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get1_compressed_cert.3ossl b/openssl-install/share/man/man3/SSL_get1_compressed_cert.3ossl deleted file mode 120000 index 7aaf058c..00000000 --- a/openssl-install/share/man/man3/SSL_get1_compressed_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_cert_comp_preference.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get1_curves.3ossl b/openssl-install/share/man/man3/SSL_get1_curves.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_get1_curves.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get1_groups.3ossl b/openssl-install/share/man/man3/SSL_get1_groups.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_get1_groups.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get1_peer_certificate.3ossl b/openssl-install/share/man/man3/SSL_get1_peer_certificate.3ossl deleted file mode 120000 index 1c33b486..00000000 --- a/openssl-install/share/man/man3/SSL_get1_peer_certificate.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get1_session.3ossl b/openssl-install/share/man/man3/SSL_get1_session.3ossl deleted file mode 120000 index f7697d29..00000000 --- a/openssl-install/share/man/man3/SSL_get1_session.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_session.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get1_supported_ciphers.3ossl b/openssl-install/share/man/man3/SSL_get1_supported_ciphers.3ossl deleted file mode 120000 index 5ab60591..00000000 --- a/openssl-install/share/man/man3/SSL_get1_supported_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_ciphers.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_SSL_CTX.3ossl b/openssl-install/share/man/man3/SSL_get_SSL_CTX.3ossl deleted file mode 100644 index 45ac3379..00000000 --- a/openssl-install/share/man/man3/SSL_get_SSL_CTX.3ossl +++ /dev/null @@ -1,167 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_SSL_CTX 3ossl" -.TH SSL_GET_SSL_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_SSL_CTX \- get the SSL_CTX from which an SSL is created -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL_CTX *SSL_get_SSL_CTX(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_SSL_CTX()\fR returns a pointer to the \s-1SSL_CTX\s0 object, from which -\&\fBssl\fR was created with \fBSSL_new\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The pointer to the \s-1SSL_CTX\s0 object is returned. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_accept_stream_queue_len.3ossl b/openssl-install/share/man/man3/SSL_get_accept_stream_queue_len.3ossl deleted file mode 120000 index f030cc7e..00000000 --- a/openssl-install/share/man/man3/SSL_get_accept_stream_queue_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_accept_stream.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_all_async_fds.3ossl b/openssl-install/share/man/man3/SSL_get_all_async_fds.3ossl deleted file mode 100644 index 61bc7312..00000000 --- a/openssl-install/share/man/man3/SSL_get_all_async_fds.3ossl +++ /dev/null @@ -1,217 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_ALL_ASYNC_FDS 3ossl" -.TH SSL_GET_ALL_ASYNC_FDS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_waiting_for_async, -SSL_get_all_async_fds, -SSL_get_changed_async_fds -\&\- manage asynchronous operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& int SSL_waiting_for_async(SSL *s); -\& int SSL_get_all_async_fds(SSL *s, OSSL_ASYNC_FD *fd, size_t *numfds); -\& int SSL_get_changed_async_fds(SSL *s, OSSL_ASYNC_FD *addfd, size_t *numaddfds, -\& OSSL_ASYNC_FD *delfd, size_t *numdelfds); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_waiting_for_async()\fR determines whether an \s-1SSL\s0 connection is currently -waiting for asynchronous operations to complete (see the \fB\s-1SSL_MODE_ASYNC\s0\fR mode -in \fBSSL_CTX_set_mode\fR\|(3)). -.PP -\&\fBSSL_get_all_async_fds()\fR returns a list of file descriptor which can be used in a -call to \fBselect()\fR or \fBpoll()\fR to determine whether the current asynchronous -operation has completed or not. A completed operation will result in data -appearing as \*(L"read ready\*(R" on the file descriptor (no actual data should be read -from the file descriptor). This function should only be called if the \fB\s-1SSL\s0\fR -object is currently waiting for asynchronous work to complete (i.e. -\&\fB\s-1SSL_ERROR_WANT_ASYNC\s0\fR has been received \- see \fBSSL_get_error\fR\|(3)). Typically -the list will only contain one file descriptor. However, if multiple asynchronous -capable engines are in use then more than one is possible. The number of file -descriptors returned is stored in \fI*numfds\fR and the file descriptors themselves -are in \fI*fds\fR. The \fIfds\fR parameter may be \s-1NULL\s0 in which case no file -descriptors are returned but \fI*numfds\fR is still populated. It is the callers -responsibility to ensure sufficient memory is allocated at \fI*fds\fR so typically -this function is called twice (once with a \s-1NULL\s0 \fIfds\fR parameter and once -without). -.PP -\&\fBSSL_get_changed_async_fds()\fR returns a list of the asynchronous file descriptors -that have been added and a list that have been deleted since the last -\&\fB\s-1SSL_ERROR_WANT_ASYNC\s0\fR was received (or since the \fB\s-1SSL\s0\fR object was created if -no \fB\s-1SSL_ERROR_WANT_ASYNC\s0\fR has been received). Similar to \fBSSL_get_all_async_fds()\fR -it is the callers responsibility to ensure that \fI*addfd\fR and \fI*delfd\fR have -sufficient memory allocated, although they may be \s-1NULL.\s0 The number of added fds -and the number of deleted fds are stored in \fI*numaddfds\fR and \fI*numdelfds\fR -respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_waiting_for_async()\fR will return 1 if the current \s-1SSL\s0 operation is waiting -for an async operation to complete and 0 otherwise. -.PP -\&\fBSSL_get_all_async_fds()\fR and \fBSSL_get_changed_async_fds()\fR return 1 on success or -0 on error. -.SH "NOTES" -.IX Header "NOTES" -On Windows platforms the \fI\fR header is dependent on some -of the types customarily made available by including \fI\fR. The -application developer is likely to require control over when the latter -is included, commonly as one of the first included headers. Therefore, -it is defined as an application developer's responsibility to include -\&\fI\fR prior to \fI\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_get_error\fR\|(3), \fBSSL_CTX_set_mode\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_waiting_for_async()\fR, \fBSSL_get_all_async_fds()\fR -and \fBSSL_get_changed_async_fds()\fR functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_app_data.3ossl b/openssl-install/share/man/man3/SSL_get_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_async_status.3ossl b/openssl-install/share/man/man3/SSL_get_async_status.3ossl deleted file mode 120000 index ea95f1d7..00000000 --- a/openssl-install/share/man/man3/SSL_get_async_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_async_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_blocking_mode.3ossl b/openssl-install/share/man/man3/SSL_get_blocking_mode.3ossl deleted file mode 120000 index 0b721da8..00000000 --- a/openssl-install/share/man/man3/SSL_get_blocking_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_blocking_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_certificate.3ossl b/openssl-install/share/man/man3/SSL_get_certificate.3ossl deleted file mode 100644 index e2d652b3..00000000 --- a/openssl-install/share/man/man3/SSL_get_certificate.3ossl +++ /dev/null @@ -1,196 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_CERTIFICATE 3ossl" -.TH SSL_GET_CERTIFICATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_certificate, SSL_get_privatekey \- retrieve TLS/SSL certificate and -private key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509 *SSL_get_certificate(const SSL *s); -\& EVP_PKEY *SSL_get_privatekey(const SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_certificate()\fR returns a pointer to an \fBX509\fR object representing a -certificate used as the local peer's identity. -.PP -Multiple certificates can be configured; for example, a server might have both -\&\s-1RSA\s0 and \s-1ECDSA\s0 certificates. The certificate which is returned by -\&\fBSSL_get_certificate()\fR is determined as follows: -.IP "\(bu" 4 -If it is called before certificate selection has occurred, it returns the most -recently added certificate, or \s-1NULL\s0 if no certificate has been added. -.IP "\(bu" 4 -After certificate selection has occurred, it returns the certificate which was -selected during the handshake, or \s-1NULL\s0 if no certificate was selected (for -example, on a client where no client certificate is in use). -.PP -Certificate selection occurs during the handshake; therefore, the value returned -by \fBSSL_get_certificate()\fR during any callback made during the handshake process -will depend on whether that callback is made before or after certificate -selection occurs. -.PP -A specific use for \fBSSL_get_certificate()\fR is inside a callback set via a call to -\&\fBSSL_CTX_set_tlsext_status_cb\fR\|(3). This callback occurs after certificate -selection, where it can be used to examine a server's chosen certificate, for -example for the purpose of identifying a certificate's \s-1OCSP\s0 responder \s-1URL\s0 so -that an \s-1OCSP\s0 response can be obtained. -.PP -\&\fBSSL_get_privatekey()\fR returns a pointer to the \fB\s-1EVP_PKEY\s0\fR object corresponding -to the certificate returned by \fBSSL_get_certificate()\fR, if any. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return pointers to their respective objects, or \s-1NULL\s0 if no such -object is available. Returned objects are owned by the \s-1SSL\s0 object and should not -be freed by users of these functions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_tlsext_status_cb\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_changed_async_fds.3ossl b/openssl-install/share/man/man3/SSL_get_changed_async_fds.3ossl deleted file mode 120000 index 18b3c38c..00000000 --- a/openssl-install/share/man/man3/SSL_get_changed_async_fds.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_all_async_fds.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_cipher.3ossl b/openssl-install/share/man/man3/SSL_get_cipher.3ossl deleted file mode 120000 index 68e038bc..00000000 --- a/openssl-install/share/man/man3/SSL_get_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_current_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_cipher_bits.3ossl b/openssl-install/share/man/man3/SSL_get_cipher_bits.3ossl deleted file mode 120000 index 68e038bc..00000000 --- a/openssl-install/share/man/man3/SSL_get_cipher_bits.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_current_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_cipher_list.3ossl b/openssl-install/share/man/man3/SSL_get_cipher_list.3ossl deleted file mode 120000 index 5ab60591..00000000 --- a/openssl-install/share/man/man3/SSL_get_cipher_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_ciphers.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_cipher_name.3ossl b/openssl-install/share/man/man3/SSL_get_cipher_name.3ossl deleted file mode 120000 index 68e038bc..00000000 --- a/openssl-install/share/man/man3/SSL_get_cipher_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_current_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_cipher_version.3ossl b/openssl-install/share/man/man3/SSL_get_cipher_version.3ossl deleted file mode 120000 index 68e038bc..00000000 --- a/openssl-install/share/man/man3/SSL_get_cipher_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_current_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_ciphers.3ossl b/openssl-install/share/man/man3/SSL_get_ciphers.3ossl deleted file mode 100644 index cda7c948..00000000 --- a/openssl-install/share/man/man3/SSL_get_ciphers.3ossl +++ /dev/null @@ -1,248 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_CIPHERS 3ossl" -.TH SSL_GET_CIPHERS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get1_supported_ciphers, -SSL_get_client_ciphers, -SSL_get_ciphers, -SSL_CTX_get_ciphers, -SSL_bytes_to_cipher_list, -SSL_get_cipher_list, -SSL_get_shared_ciphers -\&\- get list of available SSL_CIPHERs -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *ssl); -\& STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx); -\& STACK_OF(SSL_CIPHER) *SSL_get1_supported_ciphers(SSL *s); -\& STACK_OF(SSL_CIPHER) *SSL_get_client_ciphers(const SSL *ssl); -\& int SSL_bytes_to_cipher_list(SSL *s, const unsigned char *bytes, size_t len, -\& int isv2format, STACK_OF(SSL_CIPHER) **sk, -\& STACK_OF(SSL_CIPHER) **scsvs); -\& const char *SSL_get_cipher_list(const SSL *ssl, int priority); -\& char *SSL_get_shared_ciphers(const SSL *s, char *buf, int size); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_ciphers()\fR returns the stack of available SSL_CIPHERs for \fBssl\fR, -sorted by preference. If \fBssl\fR is \s-1NULL\s0 or no ciphers are available, \s-1NULL\s0 -is returned. -.PP -\&\fBSSL_CTX_get_ciphers()\fR returns the stack of available SSL_CIPHERs for \fBctx\fR. -.PP -\&\fBSSL_get1_supported_ciphers()\fR returns the stack of enabled SSL_CIPHERs for -\&\fBssl\fR as would be sent in a ClientHello (that is, sorted by preference). -The list depends on settings like the cipher list, the supported protocol -versions, the security level, and the enabled signature algorithms. -\&\s-1SRP\s0 and \s-1PSK\s0 ciphers are only enabled if the appropriate callbacks or settings -have been applied. -The list of ciphers that would be sent in a ClientHello can differ from -the list of ciphers that would be acceptable when acting as a server. -For example, additional ciphers may be usable by a server if there is -a gap in the list of supported protocols, and some ciphers may not be -usable by a server if there is not a suitable certificate configured. -If \fBssl\fR is \s-1NULL\s0 or no ciphers are available, \s-1NULL\s0 is returned. -.PP -\&\fBSSL_get_client_ciphers()\fR returns the stack of available SSL_CIPHERs matching the -list received from the client on \fBssl\fR. If \fBssl\fR is \s-1NULL,\s0 no ciphers are -available, or \fBssl\fR is not operating in server mode, \s-1NULL\s0 is returned. -.PP -\&\fBSSL_bytes_to_cipher_list()\fR treats the supplied \fBlen\fR octets in \fBbytes\fR -as a wire-protocol cipher suite specification (in the three-octet-per-cipher -SSLv2 wire format if \fBisv2format\fR is nonzero; otherwise the two-octet -SSLv3/TLS wire format), and parses the cipher suites supported by the library -into the returned stacks of \s-1SSL_CIPHER\s0 objects sk and Signalling Cipher-Suite -Values scsvs. Unsupported cipher suites are ignored. Returns 1 on success -and 0 on failure. -.PP -\&\fBSSL_get_cipher_list()\fR returns a pointer to the name of the \s-1SSL_CIPHER\s0 -listed for \fBssl\fR with \fBpriority\fR. If \fBssl\fR is \s-1NULL,\s0 no ciphers are -available, or there are less ciphers than \fBpriority\fR available, \s-1NULL\s0 -is returned. -.PP -\&\fBSSL_get_shared_ciphers()\fR creates a colon separated and \s-1NUL\s0 terminated list of -\&\s-1SSL_CIPHER\s0 names that are available in both the client and the server. \fBbuf\fR is -the buffer that should be populated with the list of names and \fBsize\fR is the -size of that buffer. A pointer to \fBbuf\fR is returned on success or \s-1NULL\s0 on -error. If the supplied buffer is not large enough to contain the complete list -of names then a truncated list of names will be returned. Note that just because -a ciphersuite is available (i.e. it is configured in the cipher list) and shared -by both the client and the server it does not mean that it is enabled (see the -description of \fBSSL_get1_supported_ciphers()\fR above). This function will return -available shared ciphersuites whether or not they are enabled. This is a server -side function only and must only be called after the completion of the initial -handshake. -.SH "NOTES" -.IX Header "NOTES" -The details of the ciphers obtained by \fBSSL_get_ciphers()\fR, \fBSSL_CTX_get_ciphers()\fR -\&\fBSSL_get1_supported_ciphers()\fR and \fBSSL_get_client_ciphers()\fR can be obtained using -the \fBSSL_CIPHER_get_name\fR\|(3) family of functions. -.PP -Call \fBSSL_get_cipher_list()\fR with \fBpriority\fR starting from 0 to obtain the -sorted list of available ciphers, until \s-1NULL\s0 is returned. -.PP -Note: \fBSSL_get_ciphers()\fR, \fBSSL_CTX_get_ciphers()\fR and \fBSSL_get_client_ciphers()\fR -return a pointer to an internal cipher stack, which will be freed later on when -the \s-1SSL\s0 or \s-1SSL_SESSION\s0 object is freed. Therefore, the calling code \fB\s-1MUST NOT\s0\fR -free the return value itself. -.PP -The stack returned by \fBSSL_get1_supported_ciphers()\fR should be freed using -\&\fBsk_SSL_CIPHER_free()\fR. -.PP -The stacks returned by \fBSSL_bytes_to_cipher_list()\fR should be freed using -\&\fBsk_SSL_CIPHER_free()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -See \s-1DESCRIPTION\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_cipher_list\fR\|(3), -\&\fBSSL_CIPHER_get_name\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_client_CA_list.3ossl b/openssl-install/share/man/man3/SSL_get_client_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_get_client_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_client_ciphers.3ossl b/openssl-install/share/man/man3/SSL_get_client_ciphers.3ossl deleted file mode 120000 index 5ab60591..00000000 --- a/openssl-install/share/man/man3/SSL_get_client_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_ciphers.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_client_random.3ossl b/openssl-install/share/man/man3/SSL_get_client_random.3ossl deleted file mode 100644 index d0020784..00000000 --- a/openssl-install/share/man/man3/SSL_get_client_random.3ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_CLIENT_RANDOM 3ossl" -.TH SSL_GET_CLIENT_RANDOM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_client_random, -SSL_get_server_random, -SSL_SESSION_get_master_key, -SSL_SESSION_set1_master_key -\&\- get internal TLS/SSL random values and get/set master key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& size_t SSL_get_client_random(const SSL *ssl, unsigned char *out, size_t outlen); -\& size_t SSL_get_server_random(const SSL *ssl, unsigned char *out, size_t outlen); -\& size_t SSL_SESSION_get_master_key(const SSL_SESSION *session, -\& unsigned char *out, size_t outlen); -\& int SSL_SESSION_set1_master_key(SSL_SESSION *sess, const unsigned char *in, -\& size_t len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_client_random()\fR extracts the random value sent from the client -to the server during the initial \s-1SSL/TLS\s0 handshake. It copies as many -bytes as it can of this value into the buffer provided in \fBout\fR, -which must have at least \fBoutlen\fR bytes available. It returns the -total number of bytes that were actually copied. If \fBoutlen\fR is -zero, \fBSSL_get_client_random()\fR copies nothing, and returns the -total size of the client_random value. -.PP -\&\fBSSL_get_server_random()\fR behaves the same, but extracts the random value -sent from the server to the client during the initial \s-1SSL/TLS\s0 handshake. -.PP -\&\fBSSL_SESSION_get_master_key()\fR behaves the same, but extracts the master -secret used to guarantee the security of the \s-1SSL/TLS\s0 session. This one -can be dangerous if misused; see \s-1NOTES\s0 below. -.PP -\&\fBSSL_SESSION_set1_master_key()\fR sets the master key value associated with the -\&\s-1SSL_SESSION\s0 \fBsess\fR. For example, this could be used to set up a session based -\&\s-1PSK\s0 (see \fBSSL_CTX_set_psk_use_session_callback\fR\|(3)). The master key of length -\&\fBlen\fR should be provided at \fBin\fR. The supplied master key is copied by the -function, so the caller is responsible for freeing and cleaning any memory -associated with \fBin\fR. The caller must ensure that the length of the key is -suitable for the ciphersuite associated with the \s-1SSL_SESSION.\s0 -.SH "NOTES" -.IX Header "NOTES" -You probably shouldn't use these functions. -.PP -These functions expose internal values from the \s-1TLS\s0 handshake, for -use in low-level protocols. You probably should not use them, unless -you are implementing something that needs access to the internal protocol -details. -.PP -Despite the names of \fBSSL_get_client_random()\fR and \fBSSL_get_server_random()\fR, they -\&\s-1ARE NOT\s0 random number generators. Instead, they return the mostly-random values that -were already generated and used in the \s-1TLS\s0 protocol. Using them -in place of \fBRAND_bytes()\fR would be grossly foolish. -.PP -The security of your \s-1TLS\s0 session depends on keeping the master key secret: -do not expose it, or any information about it, to anybody. -If you need to calculate another secret value that depends on the master -secret, you should probably use \fBSSL_export_keying_material()\fR instead, and -forget that you ever saw these functions. -.PP -In current versions of the \s-1TLS\s0 protocols, the length of client_random -(and also server_random) is always \s-1SSL3_RANDOM_SIZE\s0 bytes. Support for -other outlen arguments to the SSL_get_*\fB_random()\fR functions is provided -in case of the unlikely event that a future version or variant of \s-1TLS\s0 -uses some other length there. -.PP -Finally, though the \*(L"client_random\*(R" and \*(L"server_random\*(R" values are called -\&\*(L"random\*(R", many \s-1TLS\s0 implementations will generate four bytes of those -values based on their view of the current time. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_SESSION_set1_master_key()\fR returns 1 on success or 0 on failure. -.PP -For the other functions, if \fBoutlen\fR is greater than 0 then these functions -return the number of bytes actually copied, which will be less than or equal to -\&\fBoutlen\fR. If \fBoutlen\fR is 0 then these functions return the maximum number -of bytes they would copy \*(-- that is, the length of the underlying field. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBRAND_bytes\fR\|(3), -\&\fBSSL_export_keying_material\fR\|(3), -\&\fBSSL_CTX_set_psk_use_session_callback\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_conn_close_info.3ossl b/openssl-install/share/man/man3/SSL_get_conn_close_info.3ossl deleted file mode 100644 index af502539..00000000 --- a/openssl-install/share/man/man3/SSL_get_conn_close_info.3ossl +++ /dev/null @@ -1,293 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_CONN_CLOSE_INFO 3ossl" -.TH SSL_GET_CONN_CLOSE_INFO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_conn_close_info, SSL_CONN_CLOSE_FLAG_LOCAL, -SSL_CONN_CLOSE_FLAG_TRANSPORT, -OSSL_QUIC_ERR_NO_ERROR, -OSSL_QUIC_ERR_INTERNAL_ERROR, -OSSL_QUIC_ERR_CONNECTION_REFUSED, -OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, -OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, -OSSL_QUIC_ERR_STREAM_STATE_ERROR, -OSSL_QUIC_ERR_FINAL_SIZE_ERROR, -OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, -OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR, -OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR, -OSSL_QUIC_ERR_PROTOCOL_VIOLATION, -OSSL_QUIC_ERR_INVALID_TOKEN, -OSSL_QUIC_ERR_APPLICATION_ERROR, -OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED, -OSSL_QUIC_ERR_KEY_UPDATE_ERROR, -OSSL_QUIC_ERR_AEAD_LIMIT_REACHED, -OSSL_QUIC_ERR_NO_VIABLE_PATH, -OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN, -OSSL_QUIC_ERR_CRYPTO_ERR_END, -OSSL_QUIC_ERR_CRYPTO_ERR, -OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT -\&\- get information about why a QUIC connection was closed -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_CONN_CLOSE_FLAG_LOCAL -\& #define SSL_CONN_CLOSE_FLAG_TRANSPORT -\& -\& typedef struct ssl_conn_close_info_st { -\& uint64_t error_code, frame_type; -\& char *reason; -\& size_t reason_len; -\& uint32_t flags; -\& } SSL_CONN_CLOSE_INFO; -\& -\& int SSL_get_conn_close_info(SSL *ssl, SSL_CONN_CLOSE_INFO *info, -\& size_t info_len); -\& -\& #define OSSL_QUIC_ERR_NO_ERROR 0x00 -\& #define OSSL_QUIC_ERR_INTERNAL_ERROR 0x01 -\& #define OSSL_QUIC_ERR_CONNECTION_REFUSED 0x02 -\& #define OSSL_QUIC_ERR_FLOW_CONTROL_ERROR 0x03 -\& #define OSSL_QUIC_ERR_STREAM_LIMIT_ERROR 0x04 -\& #define OSSL_QUIC_ERR_STREAM_STATE_ERROR 0x05 -\& #define OSSL_QUIC_ERR_FINAL_SIZE_ERROR 0x06 -\& #define OSSL_QUIC_ERR_FRAME_ENCODING_ERROR 0x07 -\& #define OSSL_QUIC_ERR_TRANSPORT_PARAMETER_ERROR 0x08 -\& #define OSSL_QUIC_ERR_CONNECTION_ID_LIMIT_ERROR 0x09 -\& #define OSSL_QUIC_ERR_PROTOCOL_VIOLATION 0x0A -\& #define OSSL_QUIC_ERR_INVALID_TOKEN 0x0B -\& #define OSSL_QUIC_ERR_APPLICATION_ERROR 0x0C -\& #define OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED 0x0D -\& #define OSSL_QUIC_ERR_KEY_UPDATE_ERROR 0x0E -\& #define OSSL_QUIC_ERR_AEAD_LIMIT_REACHED 0x0F -\& #define OSSL_QUIC_ERR_NO_VIABLE_PATH 0x10 -\& -\& /* Inclusive range for handshake\-specific errors. */ -\& #define OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN 0x0100 -\& #define OSSL_QUIC_ERR_CRYPTO_ERR_END 0x01FF -\& -\& #define OSSL_QUIC_ERR_CRYPTO_ERR(X) -\& -\& #define OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBSSL_get_conn_close_info()\fR function provides information about why and how a -\&\s-1QUIC\s0 connection was closed. -.PP -Connection closure information is written to \fI*info\fR, which must be non-NULL. -\&\fIinfo_len\fR must be set to \f(CW\*(C`sizeof(*info)\*(C'\fR. -.PP -The following fields are set: -.IP "\fIerror_code\fR" 4 -.IX Item "error_code" -This is a 62\-bit \s-1QUIC\s0 error code. It is either a 62\-bit application error code -(if \fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR not set in \fIflags\fR) or a 62\-bit standard -\&\s-1QUIC\s0 transport error code (if \fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR is set in -\&\fIflags\fR). -.IP "\fIframe_type\fR" 4 -.IX Item "frame_type" -If \fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR is set, this may be set to a \s-1QUIC\s0 frame type -number which caused the connection to be closed. It may also be set to 0 if no -frame type was specified as causing the connection to be closed. If -\&\fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR is not set, this is set to 0. -.IP "\fIreason\fR" 4 -.IX Item "reason" -If non-NULL, this is intended to be a \s-1UTF\-8\s0 textual string briefly describing -the reason for connection closure. The length of the reason string in bytes is -given in \fIreason_len\fR. While, if non-NULL, OpenSSL guarantees that this string -will be zero terminated, consider that this buffer may originate from the -(untrusted) peer and thus may also contain zero bytes elsewhere. Therefore, use -of \fIreason_len\fR is recommended. -.Sp -While it is intended as per the \s-1QUIC\s0 protocol that this be a \s-1UTF\-8\s0 string, there -is no guarantee that this is the case for strings received from the peer. -.IP "\fB\s-1SSL_CONN_CLOSE_FLAG_LOCAL\s0\fR" 4 -.IX Item "SSL_CONN_CLOSE_FLAG_LOCAL" -If \fIflags\fR has \fB\s-1SSL_CONN_CLOSE_FLAG_LOCAL\s0\fR set, connection closure was locally -triggered. This could be due to an application request (e.g. if -\&\fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR is unset), or (if -\&\fI\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR is set) due to logic internal to the \s-1QUIC\s0 -implementation (for example, if the peer engages in a protocol violation, or an -idle timeout occurs). -.Sp -If unset, connection closure was remotely triggered. -.IP "\fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR" 4 -.IX Item "SSL_CONN_CLOSE_FLAG_TRANSPORT" -If \fIflags\fR has \fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR set, connection closure was -triggered for \s-1QUIC\s0 protocol reasons. Otherwise, connection closure was triggered -by the local or remote application. -.PP -The \fB\s-1OSSL_QUIC_ERR\s0\fR macro definitions provide the \s-1QUIC\s0 transport error codes as -defined by \s-1RFC 9000.\s0 The \s-1\fBOSSL_QUIC_ERR_CRYPTO_ERR\s0()\fR macro can be used to convert -a \s-1TLS\s0 alert code into a \s-1QUIC\s0 transport error code by mapping it into the range -reserved for such codes by \s-1RFC 9000.\s0 This range begins at -\&\fB\s-1OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN\s0\fR and ends at \fB\s-1OSSL_QUIC_ERR_CRYPTO_ERR_END\s0\fR -inclusive. -.SH "NON-STANDARD TRANSPORT ERROR CODES" -.IX Header "NON-STANDARD TRANSPORT ERROR CODES" -Some conditions which can cause \s-1QUIC\s0 connection termination are not signalled on -the wire and therefore do not have standard error codes. OpenSSL indicates these -errors via \fBSSL_get_conn_close_info()\fR by setting \fB\s-1SSL_CONN_CLOSE_FLAG_TRANSPORT\s0\fR -and using one of the following error values. These codes are specific to -OpenSSL, and cannot be sent over the wire, as they are above 2**62. -.IP "\fB\s-1OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT\s0\fR" 4 -.IX Item "OSSL_QUIC_LOCAL_ERR_IDLE_TIMEOUT" -The connection was terminated immediately due to the idle timeout expiring. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_conn_close_info()\fR returns 1 on success and 0 on failure. This function -fails if called on a \s-1QUIC\s0 connection \s-1SSL\s0 object which has not yet been -terminated. It also fails if called on a \s-1QUIC\s0 stream \s-1SSL\s0 object or a non-QUIC -\&\s-1SSL\s0 object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_shutdown_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_current_cipher.3ossl b/openssl-install/share/man/man3/SSL_get_current_cipher.3ossl deleted file mode 100644 index acf79ce3..00000000 --- a/openssl-install/share/man/man3/SSL_get_current_cipher.3ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_CURRENT_CIPHER 3ossl" -.TH SSL_GET_CURRENT_CIPHER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_current_cipher, SSL_get_cipher_name, SSL_get_cipher, -SSL_get_cipher_bits, SSL_get_cipher_version, -SSL_get_pending_cipher \- get SSL_CIPHER of a connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const SSL_CIPHER *SSL_get_current_cipher(const SSL *ssl); -\& const SSL_CIPHER *SSL_get_pending_cipher(const SSL *ssl); -\& -\& const char *SSL_get_cipher_name(const SSL *s); -\& const char *SSL_get_cipher(const SSL *s); -\& int SSL_get_cipher_bits(const SSL *s, int *np); -\& const char *SSL_get_cipher_version(const SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_current_cipher()\fR returns a pointer to an \s-1SSL_CIPHER\s0 object containing -the description of the actually used cipher of a connection established with -the \fBssl\fR object. -See \fBSSL_CIPHER_get_name\fR\|(3) for more details. -.PP -\&\fBSSL_get_cipher_name()\fR obtains the -name of the currently used cipher. -\&\fBSSL_get_cipher()\fR is identical to \fBSSL_get_cipher_name()\fR. -\&\fBSSL_get_cipher_bits()\fR is a -macro to obtain the number of secret/algorithm bits used and -\&\fBSSL_get_cipher_version()\fR returns the protocol name. -.PP -\&\fBSSL_get_pending_cipher()\fR returns a pointer to an \s-1SSL_CIPHER\s0 object containing -the description of the cipher (if any) that has been negotiated for future use -on the connection established with the \fBssl\fR object, but is not yet in use. -This may be the case during handshake processing, when control flow can be -returned to the application via any of several callback methods. The internal -sequencing of handshake processing and callback invocation is not guaranteed -to be stable from release to release, and at present only the callback set -by \fBSSL_CTX_set_alpn_select_cb()\fR is guaranteed to have a non-NULL return value. -Other callbacks may be added to this list over time. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_current_cipher()\fR returns the cipher actually used, or \s-1NULL\s0 if -no session has been established. -.PP -\&\fBSSL_get_pending_cipher()\fR returns the cipher to be used at the next change -of cipher suite, or \s-1NULL\s0 if no such cipher is known. -.SH "NOTES" -.IX Header "NOTES" -SSL_get_cipher, SSL_get_cipher_bits, SSL_get_cipher_version, and -SSL_get_cipher_name are implemented as macros. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CIPHER_get_name\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_default_passwd_cb.3ossl b/openssl-install/share/man/man3/SSL_get_default_passwd_cb.3ossl deleted file mode 120000 index 5e9f9bdf..00000000 --- a/openssl-install/share/man/man3/SSL_get_default_passwd_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_default_passwd_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_default_passwd_cb_userdata.3ossl b/openssl-install/share/man/man3/SSL_get_default_passwd_cb_userdata.3ossl deleted file mode 120000 index 5e9f9bdf..00000000 --- a/openssl-install/share/man/man3/SSL_get_default_passwd_cb_userdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_default_passwd_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_default_timeout.3ossl b/openssl-install/share/man/man3/SSL_get_default_timeout.3ossl deleted file mode 100644 index c828705d..00000000 --- a/openssl-install/share/man/man3/SSL_get_default_timeout.3ossl +++ /dev/null @@ -1,181 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_DEFAULT_TIMEOUT 3ossl" -.TH SSL_GET_DEFAULT_TIMEOUT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_default_timeout \- get default session timeout value -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_get_default_timeout(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_default_timeout()\fR returns the default timeout value assigned to -\&\s-1SSL_SESSION\s0 objects negotiated for the protocol valid for \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -Whenever a new session is negotiated, it is assigned a timeout value, -after which it will not be accepted for session reuse. If the timeout -value was not explicitly set using -\&\fBSSL_CTX_set_timeout\fR\|(3), the hardcoded default -timeout for the protocol will be used. -.PP -\&\fBSSL_get_default_timeout()\fR return this hardcoded value, which is 300 seconds -for all currently supported protocols. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -See description. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3), -\&\fBSSL_SESSION_get_time\fR\|(3), -\&\fBSSL_CTX_flush_sessions\fR\|(3), -\&\fBSSL_get_default_timeout\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_early_data_status.3ossl b/openssl-install/share/man/man3/SSL_get_early_data_status.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_get_early_data_status.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_error.3ossl b/openssl-install/share/man/man3/SSL_get_error.3ossl deleted file mode 100644 index d98881c4..00000000 --- a/openssl-install/share/man/man3/SSL_get_error.3ossl +++ /dev/null @@ -1,318 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_ERROR 3ossl" -.TH SSL_GET_ERROR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_error \- obtain result code for TLS/SSL I/O operation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_error(const SSL *ssl, int ret); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_error()\fR returns a result code (suitable for the C \*(L"switch\*(R" -statement) for a preceding call to \fBSSL_connect()\fR, \fBSSL_accept()\fR, \fBSSL_do_handshake()\fR, -\&\fBSSL_read_ex()\fR, \fBSSL_read()\fR, \fBSSL_peek_ex()\fR, \fBSSL_peek()\fR, \fBSSL_shutdown()\fR, -\&\fBSSL_write_ex()\fR or \fBSSL_write()\fR on \fBssl\fR. The value returned by that \s-1TLS/SSL I/O\s0 -function must be passed to \fBSSL_get_error()\fR in parameter \fBret\fR. -.PP -In addition to \fBssl\fR and \fBret\fR, \fBSSL_get_error()\fR inspects the -current thread's OpenSSL error queue. Thus, \fBSSL_get_error()\fR must be -used in the same thread that performed the \s-1TLS/SSL I/O\s0 operation, and no -other OpenSSL function calls should appear in between. The current -thread's error queue must be empty before the \s-1TLS/SSL I/O\s0 operation is -attempted, or \fBSSL_get_error()\fR will not work reliably. -.SH "NOTES" -.IX Header "NOTES" -Some \s-1TLS\s0 implementations do not send a close_notify alert on shutdown. -.PP -On an unexpected \s-1EOF,\s0 versions before OpenSSL 3.0 returned -\&\fB\s-1SSL_ERROR_SYSCALL\s0\fR, nothing was added to the error stack, and errno was 0. -Since OpenSSL 3.0 the returned error is \fB\s-1SSL_ERROR_SSL\s0\fR with a meaningful -error on the error stack (\s-1SSL_R_UNEXPECTED_EOF_WHILE_READING\s0). This error reason -code may be used for control flow decisions (see the man page for -\&\s-1\fBERR_GET_REASON\s0\fR\|(3) for further details on this). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can currently occur: -.IP "\s-1SSL_ERROR_NONE\s0" 4 -.IX Item "SSL_ERROR_NONE" -The \s-1TLS/SSL I/O\s0 operation completed. This result code is returned -if and only if \fBret > 0\fR. -.IP "\s-1SSL_ERROR_ZERO_RETURN\s0" 4 -.IX Item "SSL_ERROR_ZERO_RETURN" -The \s-1TLS/SSL\s0 peer has closed the connection for writing by sending the -close_notify alert. -No more data can be read. -Note that \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR does not necessarily -indicate that the underlying transport has been closed. -.Sp -This error can also appear when the option \fB\s-1SSL_OP_IGNORE_UNEXPECTED_EOF\s0\fR -is set. See \fBSSL_CTX_set_options\fR\|(3) for more details. -.IP "\s-1SSL_ERROR_WANT_READ, SSL_ERROR_WANT_WRITE\s0" 4 -.IX Item "SSL_ERROR_WANT_READ, SSL_ERROR_WANT_WRITE" -The operation did not complete and can be retried later. -.Sp -For non-QUIC \s-1SSL\s0 objects, \fB\s-1SSL_ERROR_WANT_READ\s0\fR is returned when the last -operation was a read operation from a nonblocking \fB\s-1BIO\s0\fR. -It means that not enough data was available at this time to complete the -operation. -If at a later time the underlying \fB\s-1BIO\s0\fR has data available for reading the same -function can be called again. -.Sp -\&\fBSSL_read()\fR and \fBSSL_read_ex()\fR can also set \fB\s-1SSL_ERROR_WANT_READ\s0\fR when there is -still unprocessed data available at either the \fB\s-1SSL\s0\fR or the \fB\s-1BIO\s0\fR layer, even -for a blocking \fB\s-1BIO\s0\fR. -See \fBSSL_read\fR\|(3) for more information. -.Sp -For non-QUIC \s-1SSL\s0 objects, \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR is returned when the last -operation was a write to a nonblocking \fB\s-1BIO\s0\fR and it was unable to send all data -to the \fB\s-1BIO\s0\fR. When the \fB\s-1BIO\s0\fR is writable again, the same function can be -called again. -.Sp -Note that the retry may again lead to an \fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR condition. -There is no fixed upper limit for the number of iterations that -may be necessary until progress becomes visible at application -protocol level. -.Sp -For \s-1QUIC SSL\s0 objects, the meaning of \fB\s-1SSL_ERROR_WANT_READ\s0\fR and -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR have different but largely compatible semantics. Since -\&\s-1QUIC\s0 implements its own flow control and uses \s-1UDP\s0 datagrams, backpressure -conditions in terms of the underlying \s-1BIO\s0 providing network I/O are not directly -relevant to the circumstances in which these errors are produced. In particular, -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR indicates that the OpenSSL internal send buffer for a -given \s-1QUIC\s0 stream has been filled. Likewise, \fB\s-1SSL_ERROR_WANT_READ\s0\fR indicates -that the OpenSSL internal receive buffer for a given \s-1QUIC\s0 stream is empty. -.Sp -It is safe to call \fBSSL_read()\fR or \fBSSL_read_ex()\fR when more data is available -even when the call that set this error was an \fBSSL_write()\fR or \fBSSL_write_ex()\fR. -However, if the call was an \fBSSL_write()\fR or \fBSSL_write_ex()\fR, it should be called -again to continue sending the application data. If you get \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR -from \fBSSL_write()\fR or \fBSSL_write_ex()\fR then you should not do any other operation -that could trigger \fB\s-1IO\s0\fR other than to repeat the previous \fBSSL_write()\fR call. -.Sp -For socket \fB\s-1BIO\s0\fRs (e.g. when \fBSSL_set_fd()\fR was used), \fBselect()\fR or -\&\fBpoll()\fR on the underlying socket can be used to find out when the -\&\s-1TLS/SSL I/O\s0 function should be retried. -.Sp -Caveat: Any \s-1TLS/SSL I/O\s0 function can lead to either of -\&\fB\s-1SSL_ERROR_WANT_READ\s0\fR and \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. -In particular, -\&\fBSSL_read_ex()\fR, \fBSSL_read()\fR, \fBSSL_peek_ex()\fR, or \fBSSL_peek()\fR may want to write data -and \fBSSL_write()\fR or \fBSSL_write_ex()\fR may want to read data. -This is mainly because -\&\s-1TLS/SSL\s0 handshakes may occur at any time during the protocol (initiated by -either the client or the server); \fBSSL_read_ex()\fR, \fBSSL_read()\fR, \fBSSL_peek_ex()\fR, -\&\fBSSL_peek()\fR, \fBSSL_write_ex()\fR, and \fBSSL_write()\fR will handle any pending handshakes. -.IP "\s-1SSL_ERROR_WANT_CONNECT, SSL_ERROR_WANT_ACCEPT\s0" 4 -.IX Item "SSL_ERROR_WANT_CONNECT, SSL_ERROR_WANT_ACCEPT" -The operation did not complete; the same \s-1TLS/SSL I/O\s0 function should be -called again later. The underlying \s-1BIO\s0 was not connected yet to the peer -and the call would block in \fBconnect()\fR/\fBaccept()\fR. The \s-1SSL\s0 function should be -called again when the connection is established. These messages can only -appear with a \fBBIO_s_connect()\fR or \fBBIO_s_accept()\fR \s-1BIO,\s0 respectively. -In order to find out, when the connection has been successfully established, -on many platforms \fBselect()\fR or \fBpoll()\fR for writing on the socket file descriptor -can be used. -.IP "\s-1SSL_ERROR_WANT_X509_LOOKUP\s0" 4 -.IX Item "SSL_ERROR_WANT_X509_LOOKUP" -The operation did not complete because an application callback set by -\&\fBSSL_CTX_set_client_cert_cb()\fR has asked to be called again. -The \s-1TLS/SSL I/O\s0 function should be called again later. -Details depend on the application. -.IP "\s-1SSL_ERROR_WANT_ASYNC\s0" 4 -.IX Item "SSL_ERROR_WANT_ASYNC" -The operation did not complete because an asynchronous engine is still -processing data. This will only occur if the mode has been set to \s-1SSL_MODE_ASYNC\s0 -using \fBSSL_CTX_set_mode\fR\|(3) or \fBSSL_set_mode\fR\|(3) and an asynchronous capable -engine is being used. An application can determine whether the engine has -completed its processing using \fBselect()\fR or \fBpoll()\fR on the asynchronous wait file -descriptor. This file descriptor is available by calling -\&\fBSSL_get_all_async_fds\fR\|(3) or \fBSSL_get_changed_async_fds\fR\|(3). The \s-1TLS/SSL I/O\s0 -function should be called again later. The function \fBmust\fR be called from the -same thread that the original call was made from. -.IP "\s-1SSL_ERROR_WANT_ASYNC_JOB\s0" 4 -.IX Item "SSL_ERROR_WANT_ASYNC_JOB" -The asynchronous job could not be started because there were no async jobs -available in the pool (see \fBASYNC_init_thread\fR\|(3)). This will only occur if the -mode has been set to \s-1SSL_MODE_ASYNC\s0 using \fBSSL_CTX_set_mode\fR\|(3) or -\&\fBSSL_set_mode\fR\|(3) and a maximum limit has been set on the async job pool -through a call to \fBASYNC_init_thread\fR\|(3). The application should retry the -operation after a currently executing asynchronous operation for the current -thread has completed. -.IP "\s-1SSL_ERROR_WANT_CLIENT_HELLO_CB\s0" 4 -.IX Item "SSL_ERROR_WANT_CLIENT_HELLO_CB" -The operation did not complete because an application callback set by -\&\fBSSL_CTX_set_client_hello_cb()\fR has asked to be called again. -The \s-1TLS/SSL I/O\s0 function should be called again later. -Details depend on the application. -.IP "\s-1SSL_ERROR_SYSCALL\s0" 4 -.IX Item "SSL_ERROR_SYSCALL" -Some non-recoverable, fatal I/O error occurred. The OpenSSL error queue may -contain more information on the error. For socket I/O on Unix systems, consult -\&\fBerrno\fR for details. If this error occurs then no further I/O operations should -be performed on the connection and \fBSSL_shutdown()\fR must not be called. -.Sp -This value can also be returned for other errors, check the error queue for -details. -.IP "\s-1SSL_ERROR_SSL\s0" 4 -.IX Item "SSL_ERROR_SSL" -A non-recoverable, fatal error in the \s-1SSL\s0 library occurred, usually a protocol -error. The OpenSSL error queue contains more information on the error. If this -error occurs then no further I/O operations should be performed on the -connection and \fBSSL_shutdown()\fR must not be called. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1SSL_ERROR_WANT_ASYNC\s0 error code was added in OpenSSL 1.1.0. -The \s-1SSL_ERROR_WANT_CLIENT_HELLO_CB\s0 error code was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_event_handling_mode.3ossl b/openssl-install/share/man/man3/SSL_get_event_handling_mode.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_event_handling_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_event_timeout.3ossl b/openssl-install/share/man/man3/SSL_get_event_timeout.3ossl deleted file mode 100644 index ba7eb82b..00000000 --- a/openssl-install/share/man/man3/SSL_get_event_timeout.3ossl +++ /dev/null @@ -1,209 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_EVENT_TIMEOUT 3ossl" -.TH SSL_GET_EVENT_TIMEOUT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_event_timeout \- determine when an SSL object next needs to have events -handled -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_event_timeout(SSL *s, struct timeval *tv, int *is_infinite); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_event_timeout()\fR determines when the \s-1SSL\s0 object next needs to perform -internal processing due to the passage of time. -.PP -All arguments are required; \fItv\fR and \fIis_infinite\fR must be non-NULL. -.PP -Upon the successful return of \fBSSL_get_event_timeout()\fR, one of the following -cases applies: -.IP "\(bu" 4 -The \s-1SSL\s0 object has events which need to be handled immediately; The fields of -\&\fI*tv\fR are set to 0 and \fI*is_infinite\fR is set to 0. -.IP "\(bu" 4 -The \s-1SSL\s0 object has events which need to be handled after some amount of time -(relative to the time at which \fBSSL_get_event_timeout()\fR was called). \fI*tv\fR is -set to the amount of time after which \fBSSL_handle_events\fR\|(3) should be called -and \fI*is_infinite\fR is set to 0. -.IP "\(bu" 4 -There are currently no timer events which require handling in the future. The -value of \fI*tv\fR is unspecified and \fI*is_infinite\fR is set to 1. -.PP -This function is currently applicable only to \s-1DTLS\s0 and \s-1QUIC\s0 connection \s-1SSL\s0 -objects. If it is called on any other kind of \s-1SSL\s0 object, it always outputs -infinity. This is considered a success condition. -.PP -For \s-1DTLS,\s0 this function can be used instead of the older -\&\fBDTLSv1_get_timeout\fR\|(3) function. Note that this function differs from -\&\fBDTLSv1_get_timeout\fR\|(3) in that the case where no timeout is active is -considered a success condition. -.PP -Note that the value output by a call to \fBSSL_get_event_timeout()\fR may change as a -result of other calls to the \s-1SSL\s0 object. -.PP -Once the timeout expires, \fBSSL_handle_events\fR\|(3) should be called to handle any -internal processing which is due; for more information, see -\&\fBSSL_handle_events\fR\|(3). -.PP -Note that \fBSSL_get_event_timeout()\fR supersedes the older \fBDTLSv1_get_timeout\fR\|(3) -function for all use cases. -.PP -If the call to \fBSSL_get_event_timeout()\fR fails, the values of \fI*tv\fR and -\&\fI*is_infinite\fR may still be changed and their values become unspecified. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success and 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_handle_events\fR\|(3), \fBDTLSv1_get_timeout\fR\|(3), \fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_get_event_timeout()\fR function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_ex_data.3ossl b/openssl-install/share/man/man3/SSL_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_ex_data_X509_STORE_CTX_idx.3ossl b/openssl-install/share/man/man3/SSL_get_ex_data_X509_STORE_CTX_idx.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_get_ex_data_X509_STORE_CTX_idx.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_ex_new_index.3ossl b/openssl-install/share/man/man3/SSL_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_extms_support.3ossl b/openssl-install/share/man/man3/SSL_get_extms_support.3ossl deleted file mode 100644 index ba01162a..00000000 --- a/openssl-install/share/man/man3/SSL_get_extms_support.3ossl +++ /dev/null @@ -1,172 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_EXTMS_SUPPORT 3ossl" -.TH SSL_GET_EXTMS_SUPPORT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_extms_support \- extended master secret support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_extms_support(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_extms_support()\fR indicates whether the current session used extended -master secret. -.PP -This function is implemented as a macro. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_extms_support()\fR returns 1 if the current session used extended -master secret, 0 if it did not and \-1 if a handshake is currently in -progress i.e. it is not possible to determine if extended master secret -was used. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_fd.3ossl b/openssl-install/share/man/man3/SSL_get_fd.3ossl deleted file mode 100644 index 5dd3528f..00000000 --- a/openssl-install/share/man/man3/SSL_get_fd.3ossl +++ /dev/null @@ -1,179 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_FD 3ossl" -.TH SSL_GET_FD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_fd, SSL_get_rfd, SSL_get_wfd \- get file descriptor linked to an SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_fd(const SSL *ssl); -\& int SSL_get_rfd(const SSL *ssl); -\& int SSL_get_wfd(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_fd()\fR returns the file descriptor which is linked to \fBssl\fR. -\&\fBSSL_get_rfd()\fR and \fBSSL_get_wfd()\fR return the file descriptors for the -read or the write channel, which can be different. If the read and the -write channel are different, \fBSSL_get_fd()\fR will return the file descriptor -of the read channel. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "\-1" 4 -.IX Item "-1" -The operation failed, because the underlying \s-1BIO\s0 is not of the correct type -(suitable for file descriptors). -.IP ">=0" 4 -.IX Item ">=0" -The file descriptor linked to \fBssl\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_set_fd\fR\|(3), \fBssl\fR\|(7) , \fBbio\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_feature_negotiated_uint.3ossl b/openssl-install/share/man/man3/SSL_get_feature_negotiated_uint.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_feature_negotiated_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_feature_peer_request_uint.3ossl b/openssl-install/share/man/man3/SSL_get_feature_peer_request_uint.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_feature_peer_request_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_feature_request_uint.3ossl b/openssl-install/share/man/man3/SSL_get_feature_request_uint.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_feature_request_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_generic_value_uint.3ossl b/openssl-install/share/man/man3/SSL_get_generic_value_uint.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_generic_value_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_handshake_rtt.3ossl b/openssl-install/share/man/man3/SSL_get_handshake_rtt.3ossl deleted file mode 100644 index 986b75c5..00000000 --- a/openssl-install/share/man/man3/SSL_get_handshake_rtt.3ossl +++ /dev/null @@ -1,192 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_HANDSHAKE_RTT 3ossl" -.TH SSL_GET_HANDSHAKE_RTT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_handshake_rtt -\&\- get round trip time for SSL Handshake -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_handshake_rtt(const SSL *s, uint64_t *rtt); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_handshake_rtt()\fR retrieves the round-trip time (\s-1RTT\s0) for \fIssl\fR. -.PP -This metric is represented in microseconds (us) as a uint64_t data type. -.SH "NOTES" -.IX Header "NOTES" -This metric is created by taking two timestamps during the handshake and -providing the difference between these two times. -.PP -When acting as the server, one timestamp is taken when the server is finished -writing to the client. This is during the ServerFinished in \s-1TLS 1.3\s0 and -ServerHelloDone in \s-1TLS 1.2.\s0 The other timestamp is taken when the server is -done reading the client's response. This is after the client has responded -with ClientFinished. -.PP -When acting as the client, one timestamp is taken when the client is finished -writing the ClientHello and early data (if any). The other is taken when -client is done reading the server's response. This is after ServerFinished in -\&\s-1TLS 1.3\s0 and after ServerHelloDone in \s-1TLS 1.2.\s0 -.PP -In addition to network propagation delay and network stack overhead, this -metric includes processing time on both endpoints, as this is based on \s-1TLS\s0 -protocol-level messages and the \s-1TLS\s0 protocol is not designed to measure -network timings. In some cases the processing time can be significant, -especially when the processing includes asymmetric cryptographic operations. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 if the \s-1TLS\s0 handshake \s-1RTT\s0 is successfully retrieved. -Returns 0 if the \s-1TLS\s0 handshake \s-1RTT\s0 cannot be determined yet. -Returns \-1 if, while retrieving the \s-1TLS\s0 handshake \s-1RTT,\s0 an error occurs. -.SH "HISTORY" -.IX Header "HISTORY" -This function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_info_callback.3ossl b/openssl-install/share/man/man3/SSL_get_info_callback.3ossl deleted file mode 120000 index f805afdc..00000000 --- a/openssl-install/share/man/man3/SSL_get_info_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_info_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_key_update_type.3ossl b/openssl-install/share/man/man3/SSL_get_key_update_type.3ossl deleted file mode 120000 index af21c78b..00000000 --- a/openssl-install/share/man/man3/SSL_get_key_update_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_key_update.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_max_cert_list.3ossl b/openssl-install/share/man/man3/SSL_get_max_cert_list.3ossl deleted file mode 120000 index 4861aab5..00000000 --- a/openssl-install/share/man/man3/SSL_get_max_cert_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_max_cert_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_get_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_get_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_max_proto_version.3ossl b/openssl-install/share/man/man3/SSL_get_max_proto_version.3ossl deleted file mode 120000 index 60193888..00000000 --- a/openssl-install/share/man/man3/SSL_get_max_proto_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_min_proto_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_min_proto_version.3ossl b/openssl-install/share/man/man3/SSL_get_min_proto_version.3ossl deleted file mode 120000 index 60193888..00000000 --- a/openssl-install/share/man/man3/SSL_get_min_proto_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_min_proto_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_mode.3ossl b/openssl-install/share/man/man3/SSL_get_mode.3ossl deleted file mode 120000 index ea309712..00000000 --- a/openssl-install/share/man/man3/SSL_get_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_negotiated_client_cert_type.3ossl b/openssl-install/share/man/man3/SSL_get_negotiated_client_cert_type.3ossl deleted file mode 120000 index 320912ea..00000000 --- a/openssl-install/share/man/man3/SSL_get_negotiated_client_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get0_peer_rpk.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_negotiated_group.3ossl b/openssl-install/share/man/man3/SSL_get_negotiated_group.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_get_negotiated_group.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_negotiated_server_cert_type.3ossl b/openssl-install/share/man/man3/SSL_get_negotiated_server_cert_type.3ossl deleted file mode 120000 index 320912ea..00000000 --- a/openssl-install/share/man/man3/SSL_get_negotiated_server_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get0_peer_rpk.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_num_tickets.3ossl b/openssl-install/share/man/man3/SSL_get_num_tickets.3ossl deleted file mode 120000 index 619b5ce0..00000000 --- a/openssl-install/share/man/man3/SSL_get_num_tickets.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_num_tickets.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_options.3ossl b/openssl-install/share/man/man3/SSL_get_options.3ossl deleted file mode 120000 index 742650be..00000000 --- a/openssl-install/share/man/man3/SSL_get_options.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_options.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_peer_cert_chain.3ossl b/openssl-install/share/man/man3/SSL_get_peer_cert_chain.3ossl deleted file mode 100644 index c1411638..00000000 --- a/openssl-install/share/man/man3/SSL_get_peer_cert_chain.3ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_PEER_CERT_CHAIN 3ossl" -.TH SSL_GET_PEER_CERT_CHAIN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_peer_cert_chain, SSL_get0_verified_chain \- get the X509 certificate -chain of the peer -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(X509) *SSL_get_peer_cert_chain(const SSL *ssl); -\& STACK_OF(X509) *SSL_get0_verified_chain(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_peer_cert_chain()\fR returns a pointer to \s-1STACK_OF\s0(X509) certificates -forming the certificate chain sent by the peer. If called on the client side, -the stack also contains the peer's certificate; if called on the server -side, the peer's certificate must be obtained separately using -\&\fBSSL_get_peer_certificate\fR\|(3). -If the peer did not present a certificate, \s-1NULL\s0 is returned. -.PP -\&\s-1NB:\s0 \fBSSL_get_peer_cert_chain()\fR returns the peer chain as sent by the peer: it -only consists of certificates the peer has sent (in the order the peer -has sent them) it is \fBnot\fR a verified chain. -.PP -\&\fBSSL_get0_verified_chain()\fR returns the \fBverified\fR certificate chain -of the peer including the peer's end entity certificate. It must be called -after a session has been successfully established. If peer verification was -not successful (as indicated by \fBSSL_get_verify_result()\fR not returning -X509_V_OK) the chain may be incomplete or invalid. -.SH "NOTES" -.IX Header "NOTES" -If the session is resumed peers do not send certificates so a \s-1NULL\s0 pointer -is returned by these functions. Applications can call \fBSSL_session_reused()\fR -to determine whether a session is resumed. -.PP -The reference count of each certificate in the returned \s-1STACK_OF\s0(X509) object -is not incremented and the returned stack may be invalidated by renegotiation. -If applications wish to use any certificates in the returned chain -indefinitely they must increase the reference counts using \fBX509_up_ref()\fR or -obtain a copy of the whole chain with \fBX509_chain_up_ref()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "\s-1NULL\s0" 4 -.IX Item "NULL" -No certificate was presented by the peer or no connection was established -or the certificate chain is no longer available when a session is reused. -.IP "Pointer to a \s-1STACK_OF\s0(X509)" 4 -.IX Item "Pointer to a STACK_OF(X509)" -The return value points to the certificate chain presented by the peer. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_peer_certificate\fR\|(3), \fBX509_up_ref\fR\|(3), -\&\fBX509_chain_up_ref\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_peer_certificate.3ossl b/openssl-install/share/man/man3/SSL_get_peer_certificate.3ossl deleted file mode 100644 index 2598f18b..00000000 --- a/openssl-install/share/man/man3/SSL_get_peer_certificate.3ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_PEER_CERTIFICATE 3ossl" -.TH SSL_GET_PEER_CERTIFICATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_peer_certificate, -SSL_get0_peer_certificate, -SSL_get1_peer_certificate \- get the X509 certificate of the peer -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509 *SSL_get0_peer_certificate(const SSL *ssl); -\& X509 *SSL_get1_peer_certificate(const SSL *ssl); -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0, -and can be hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable -version value, see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& X509 *SSL_get_peer_certificate(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions return a pointer to the X509 certificate the -peer presented. If the peer did not present a certificate, \s-1NULL\s0 is returned. -.SH "NOTES" -.IX Header "NOTES" -Due to the protocol definition, a \s-1TLS/SSL\s0 server will always send a -certificate, if present. A client will only send a certificate when -explicitly requested to do so by the server (see -\&\fBSSL_CTX_set_verify\fR\|(3)). If an anonymous cipher -is used, no certificates are sent. -.PP -That a certificate is returned does not indicate information about the -verification state, use \fBSSL_get_verify_result\fR\|(3) -to check the verification state. -.PP -The reference count of the X509 object returned by \fBSSL_get1_peer_certificate()\fR -is incremented by one, so that it will not be destroyed when the session -containing the peer certificate is freed. The X509 object must be explicitly -freed using \fBX509_free()\fR. -.PP -The reference count of the X509 object returned by \fBSSL_get0_peer_certificate()\fR -is not incremented, and must not be freed. -.PP -\&\fBSSL_get_peer_certificate()\fR is an alias of \fBSSL_get1_peer_certificate()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "\s-1NULL\s0" 4 -.IX Item "NULL" -No certificate was presented by the peer or no connection was established. -.IP "Pointer to an X509 certificate" 4 -.IX Item "Pointer to an X509 certificate" -The return value points to the certificate presented by the peer. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_verify_result\fR\|(3), -\&\fBSSL_CTX_set_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_get0_peer_certificate()\fR and \fBSSL_get1_peer_certificate()\fR were added in 3.0.0. -\&\fBSSL_get_peer_certificate()\fR was deprecated in 3.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_peer_signature_nid.3ossl b/openssl-install/share/man/man3/SSL_get_peer_signature_nid.3ossl deleted file mode 100644 index bc9a80ea..00000000 --- a/openssl-install/share/man/man3/SSL_get_peer_signature_nid.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_PEER_SIGNATURE_NID 3ossl" -.TH SSL_GET_PEER_SIGNATURE_NID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_peer_signature_nid, SSL_get_peer_signature_type_nid, -SSL_get_signature_nid, SSL_get_signature_type_nid \- get TLS message signing -types -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_peer_signature_nid(SSL *ssl, int *psig_nid); -\& int SSL_get_peer_signature_type_nid(const SSL *ssl, int *psigtype_nid); -\& int SSL_get_signature_nid(SSL *ssl, int *psig_nid); -\& int SSL_get_signature_type_nid(const SSL *ssl, int *psigtype_nid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_peer_signature_nid()\fR sets \fB*psig_nid\fR to the \s-1NID\s0 of the digest used -by the peer to sign \s-1TLS\s0 messages. It is implemented as a macro. -.PP -\&\fBSSL_get_peer_signature_type_nid()\fR sets \fB*psigtype_nid\fR to the signature -type used by the peer to sign \s-1TLS\s0 messages. Currently the signature type -is the \s-1NID\s0 of the public key type used for signing except for \s-1PSS\s0 signing -where it is \fB\s-1EVP_PKEY_RSA_PSS\s0\fR. To differentiate between -\&\fBrsa_pss_rsae_*\fR and \fBrsa_pss_pss_*\fR signatures, it's necessary to check -the type of public key in the peer's certificate. -.PP -\&\fBSSL_get_signature_nid()\fR and \fBSSL_get_signature_type_nid()\fR return the equivalent -information for the local end of the connection. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return 1 for success and 0 for failure. There are several -possible reasons for failure: the cipher suite has no signature (e.g. it -uses \s-1RSA\s0 key exchange or is anonymous), the \s-1TLS\s0 version is below 1.2 or -the functions were called too early, e.g. before the peer signed a message. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_peer_certificate\fR\|(3), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_peer_signature_type_nid.3ossl b/openssl-install/share/man/man3/SSL_get_peer_signature_type_nid.3ossl deleted file mode 120000 index 2ce2c761..00000000 --- a/openssl-install/share/man/man3/SSL_get_peer_signature_type_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_signature_nid.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_peer_tmp_key.3ossl b/openssl-install/share/man/man3/SSL_get_peer_tmp_key.3ossl deleted file mode 100644 index c26486e2..00000000 --- a/openssl-install/share/man/man3/SSL_get_peer_tmp_key.3ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_PEER_TMP_KEY 3ossl" -.TH SSL_GET_PEER_TMP_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_peer_tmp_key, SSL_get_server_tmp_key, SSL_get_tmp_key \- get information -about temporary keys used during a handshake -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_get_peer_tmp_key(SSL *ssl, EVP_PKEY **key); -\& long SSL_get_server_tmp_key(SSL *ssl, EVP_PKEY **key); -\& long SSL_get_tmp_key(SSL *ssl, EVP_PKEY **key); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_peer_tmp_key()\fR returns the temporary key provided by the peer and -used during key exchange. For example, if \s-1ECDHE\s0 is in use, then this represents -the peer's public \s-1ECDHE\s0 key. On success a pointer to the key is stored in -\&\fB*key\fR. It is the caller's responsibility to free this key after use using -\&\fBEVP_PKEY_free\fR\|(3). -.PP -\&\fBSSL_get_server_tmp_key()\fR is a backwards compatibility alias for -\&\fBSSL_get_peer_tmp_key()\fR. -Under that name it worked just on the client side of the connection, its -behaviour on the server end is release-dependent. -.PP -\&\fBSSL_get_tmp_key()\fR returns the equivalent information for the local -end of the connection. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All these functions return 1 on success and 0 otherwise. -.SH "NOTES" -.IX Header "NOTES" -This function is implemented as a macro. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBEVP_PKEY_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_pending_cipher.3ossl b/openssl-install/share/man/man3/SSL_get_pending_cipher.3ossl deleted file mode 120000 index 68e038bc..00000000 --- a/openssl-install/share/man/man3/SSL_get_pending_cipher.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_current_cipher.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_privatekey.3ossl b/openssl-install/share/man/man3/SSL_get_privatekey.3ossl deleted file mode 120000 index 74b09da9..00000000 --- a/openssl-install/share/man/man3/SSL_get_privatekey.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_psk_identity.3ossl b/openssl-install/share/man/man3/SSL_get_psk_identity.3ossl deleted file mode 100644 index 63720d00..00000000 --- a/openssl-install/share/man/man3/SSL_get_psk_identity.3ossl +++ /dev/null @@ -1,176 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_PSK_IDENTITY 3ossl" -.TH SSL_GET_PSK_IDENTITY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_psk_identity, SSL_get_psk_identity_hint \- get PSK client identity and hint -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_get_psk_identity_hint(const SSL *ssl); -\& const char *SSL_get_psk_identity(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_psk_identity_hint()\fR is used to retrieve the \s-1PSK\s0 identity hint -used during the connection setup related to \s-1SSL\s0 object -\&\fBssl\fR. Similarly, \fBSSL_get_psk_identity()\fR is used to retrieve the \s-1PSK\s0 -identity used during the connection setup. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If non\-\fB\s-1NULL\s0\fR, \fBSSL_get_psk_identity_hint()\fR returns the \s-1PSK\s0 identity -hint and \fBSSL_get_psk_identity()\fR returns the \s-1PSK\s0 identity. Both are -\&\fB\s-1NULL\s0\fR\-terminated. \fBSSL_get_psk_identity_hint()\fR may return \fB\s-1NULL\s0\fR if -no \s-1PSK\s0 identity hint was used during the connection setup. -.PP -Note that the return value is valid only during the lifetime of the -\&\s-1SSL\s0 object \fBssl\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2006\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_psk_identity_hint.3ossl b/openssl-install/share/man/man3/SSL_get_psk_identity_hint.3ossl deleted file mode 120000 index 4d277d8d..00000000 --- a/openssl-install/share/man/man3/SSL_get_psk_identity_hint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_psk_identity.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_quic_stream_bidi_local_avail.3ossl b/openssl-install/share/man/man3/SSL_get_quic_stream_bidi_local_avail.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_quic_stream_bidi_local_avail.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_quic_stream_bidi_remote_avail.3ossl b/openssl-install/share/man/man3/SSL_get_quic_stream_bidi_remote_avail.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_quic_stream_bidi_remote_avail.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_quic_stream_uni_local_avail.3ossl b/openssl-install/share/man/man3/SSL_get_quic_stream_uni_local_avail.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_quic_stream_uni_local_avail.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_quic_stream_uni_remote_avail.3ossl b/openssl-install/share/man/man3/SSL_get_quic_stream_uni_remote_avail.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_quic_stream_uni_remote_avail.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_quiet_shutdown.3ossl b/openssl-install/share/man/man3/SSL_get_quiet_shutdown.3ossl deleted file mode 120000 index 1bef418d..00000000 --- a/openssl-install/share/man/man3/SSL_get_quiet_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_quiet_shutdown.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_rbio.3ossl b/openssl-install/share/man/man3/SSL_get_rbio.3ossl deleted file mode 100644 index 0bfcb761..00000000 --- a/openssl-install/share/man/man3/SSL_get_rbio.3ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_RBIO 3ossl" -.TH SSL_GET_RBIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_rbio, SSL_get_wbio \- get BIO linked to an SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& BIO *SSL_get_rbio(SSL *ssl); -\& BIO *SSL_get_wbio(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_rbio()\fR and \fBSSL_get_wbio()\fR return pointers to the BIOs for the -read or the write channel, which can be different. The reference count -of the \s-1BIO\s0 is not incremented. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "\s-1NULL\s0" 4 -.IX Item "NULL" -No \s-1BIO\s0 was connected to the \s-1SSL\s0 object -.IP "Any other pointer" 4 -.IX Item "Any other pointer" -The \s-1BIO\s0 linked to \fBssl\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_set_bio\fR\|(3), \fBssl\fR\|(7) , \fBbio\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_read_ahead.3ossl b/openssl-install/share/man/man3/SSL_get_read_ahead.3ossl deleted file mode 120000 index 095d1f88..00000000 --- a/openssl-install/share/man/man3/SSL_get_read_ahead.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_read_ahead.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_record_padding_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_get_record_padding_callback_arg.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_get_record_padding_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_recv_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_get_recv_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_get_recv_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_rfd.3ossl b/openssl-install/share/man/man3/SSL_get_rfd.3ossl deleted file mode 120000 index cc6f89a3..00000000 --- a/openssl-install/share/man/man3/SSL_get_rfd.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_fd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_rpoll_descriptor.3ossl b/openssl-install/share/man/man3/SSL_get_rpoll_descriptor.3ossl deleted file mode 100644 index 63b2785e..00000000 --- a/openssl-install/share/man/man3/SSL_get_rpoll_descriptor.3ossl +++ /dev/null @@ -1,221 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_RPOLL_DESCRIPTOR 3ossl" -.TH SSL_GET_RPOLL_DESCRIPTOR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_rpoll_descriptor, SSL_get_wpoll_descriptor, SSL_net_read_desired, -SSL_net_write_desired \- obtain information which can be used to determine when -network I/O can be performed -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_rpoll_descriptor(SSL *s, BIO_POLL_DESCRIPTOR *desc); -\& int SSL_get_wpoll_descriptor(SSL *s, BIO_POLL_DESCRIPTOR *desc); -\& int SSL_net_read_desired(SSL *s); -\& int SSL_net_write_desired(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The functions \fBSSL_get_rpoll_descriptor()\fR and \fBSSL_get_wpoll_descriptor()\fR can be -used to determine when an \s-1SSL\s0 object which represents a \s-1QUIC\s0 connection can -perform useful network I/O, so that an application using a \s-1QUIC\s0 connection \s-1SSL\s0 -object in nonblocking mode can determine when it should call \fBSSL_handle_events()\fR. -.PP -On success, these functions output poll descriptors. For more information on -poll descriptors, see \fBBIO_get_rpoll_descriptor\fR\|(3). -.PP -The functions \fBSSL_net_read_desired()\fR and \fBSSL_net_write_desired()\fR return 1 or 0 -depending on whether the \s-1SSL\s0 object is currently interested in receiving data -from the network and/or writing data to the network respectively. -If an \s-1SSL\s0 object is not interested in reading data from the network at the -current time, \fBSSL_net_read_desired()\fR will return 0; likewise, if an \s-1SSL\s0 object is -not interested in writing data to the network at the current time, -\&\fBSSL_net_write_desired()\fR will return 0. -.PP -The intention is that an application using \s-1QUIC\s0 in nonblocking mode can use -these calls, in conjunction with \fBSSL_get_event_timeout\fR\|(3) to wait for network -I/O conditions which allow the \s-1SSL\s0 object to perform useful work. When such a -condition arises, \fBSSL_handle_events\fR\|(3) should be called. -.PP -In particular, the expected usage is as follows: -.IP "\(bu" 4 -\&\fBSSL_handle_events()\fR should be called whenever the timeout returned by -\&\fBSSL_get_event_timeout\fR\|(3) (if any) expires -.IP "\(bu" 4 -If the last call to \fBSSL_net_read_desired()\fR returned 1, \fBSSL_handle_events()\fR should be called -whenever the poll descriptor output by \fBSSL_get_rpoll_descriptor()\fR becomes -readable. -.IP "\(bu" 4 -If the last call to \fBSSL_net_write_desired()\fR returned 1, \fBSSL_handle_events()\fR should be called -whenever the poll descriptor output by \fBSSL_get_wpoll_descriptor()\fR becomes -writable. -.PP -The return values of the \fBSSL_net_read_desired()\fR and \fBSSL_net_write_desired()\fR functions -may change in response to any call to the \s-1SSL\s0 object other than -\&\fBSSL_net_read_desired()\fR, \fBSSL_net_write_desired()\fR, \fBSSL_get_rpoll_descriptor()\fR, -\&\fBSSL_get_wpoll_descriptor()\fR and \fBSSL_get_event_timeout()\fR. -.PP -On non-QUIC \s-1SSL\s0 objects, calls to \fBSSL_get_rpoll_descriptor()\fR and -\&\fBSSL_get_wpoll_descriptor()\fR function the same as calls to -\&\fBBIO_get_rpoll_descriptor()\fR and \fBBIO_get_wpoll_descriptor()\fR on the respective read -and write BIOs configured on the \s-1SSL\s0 object. -.PP -On non-QUIC \s-1SSL\s0 objects, calls to \fBSSL_net_read_desired()\fR and -\&\fBSSL_net_write_desired()\fR function identically to calls to \fBSSL_want_read()\fR and -\&\fBSSL_want_write()\fR respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return 1 on success and 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_handle_events\fR\|(3), \fBSSL_get_event_timeout\fR\|(3), \fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_get_rpoll_descriptor()\fR, \fBSSL_get_wpoll_descriptor()\fR, \fBSSL_net_read_desired()\fR -and \fBSSL_net_write_desired()\fR functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_secure_renegotiation_support.3ossl b/openssl-install/share/man/man3/SSL_get_secure_renegotiation_support.3ossl deleted file mode 120000 index 742650be..00000000 --- a/openssl-install/share/man/man3/SSL_get_secure_renegotiation_support.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_options.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_security_callback.3ossl b/openssl-install/share/man/man3/SSL_get_security_callback.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_get_security_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_security_level.3ossl b/openssl-install/share/man/man3/SSL_get_security_level.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_get_security_level.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_selected_srtp_profile.3ossl b/openssl-install/share/man/man3/SSL_get_selected_srtp_profile.3ossl deleted file mode 120000 index ab61a632..00000000 --- a/openssl-install/share/man/man3/SSL_get_selected_srtp_profile.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_use_srtp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_server_random.3ossl b/openssl-install/share/man/man3/SSL_get_server_random.3ossl deleted file mode 120000 index d0f74356..00000000 --- a/openssl-install/share/man/man3/SSL_get_server_random.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_client_random.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_server_tmp_key.3ossl b/openssl-install/share/man/man3/SSL_get_server_tmp_key.3ossl deleted file mode 120000 index 821f2f77..00000000 --- a/openssl-install/share/man/man3/SSL_get_server_tmp_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_tmp_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_servername.3ossl b/openssl-install/share/man/man3/SSL_get_servername.3ossl deleted file mode 120000 index f62c51f3..00000000 --- a/openssl-install/share/man/man3/SSL_get_servername.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_servername_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_servername_type.3ossl b/openssl-install/share/man/man3/SSL_get_servername_type.3ossl deleted file mode 120000 index f62c51f3..00000000 --- a/openssl-install/share/man/man3/SSL_get_servername_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_servername_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_session.3ossl b/openssl-install/share/man/man3/SSL_get_session.3ossl deleted file mode 100644 index be28a91c..00000000 --- a/openssl-install/share/man/man3/SSL_get_session.3ossl +++ /dev/null @@ -1,238 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_SESSION 3ossl" -.TH SSL_GET_SESSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_session, SSL_get0_session, SSL_get1_session \- retrieve TLS/SSL session data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL_SESSION *SSL_get_session(const SSL *ssl); -\& SSL_SESSION *SSL_get0_session(const SSL *ssl); -\& SSL_SESSION *SSL_get1_session(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_session()\fR returns a pointer to the \fB\s-1SSL_SESSION\s0\fR actually used in -\&\fBssl\fR. The reference count of the \fB\s-1SSL_SESSION\s0\fR is not incremented, so -that the pointer can become invalid by other operations. -.PP -\&\fBSSL_get0_session()\fR is the same as \fBSSL_get_session()\fR. -.PP -\&\fBSSL_get1_session()\fR is the same as \fBSSL_get_session()\fR, but the reference -count of the \fB\s-1SSL_SESSION\s0\fR is incremented by one. -.SH "NOTES" -.IX Header "NOTES" -The ssl session contains all information required to re-establish the -connection without a full handshake for \s-1SSL\s0 versions up to and including -TLSv1.2. In TLSv1.3 the same is true, but sessions are established after the -main handshake has occurred. The server will send the session information to the -client at a time of its choosing, which may be some while after the initial -connection is established (or never). Calling these functions on the client side -in TLSv1.3 before the session has been established will still return an -\&\s-1SSL_SESSION\s0 object but that object cannot be used for resuming the session. See -\&\fBSSL_SESSION_is_resumable\fR\|(3) for information on how to determine whether an -\&\s-1SSL_SESSION\s0 object can be used for resumption or not. -.PP -Additionally, in TLSv1.3, a server can send multiple messages that establish a -session for a single connection. In that case, on the client side, the above -functions will only return information on the last session that was received. On -the server side they will only return information on the last session that was -sent, or if no session tickets were sent then the session for the current -connection. -.PP -The preferred way for applications to obtain a resumable \s-1SSL_SESSION\s0 object is -to use a new session callback as described in \fBSSL_CTX_sess_set_new_cb\fR\|(3). -The new session callback is only invoked when a session is actually established, -so this avoids the problem described above where an application obtains an -\&\s-1SSL_SESSION\s0 object that cannot be used for resumption in TLSv1.3. It also -enables applications to obtain information about all sessions sent by the -server. -.PP -A session will be automatically removed from the session cache and marked as -non-resumable if the connection is not closed down cleanly, e.g. if a fatal -error occurs on the connection or \fBSSL_shutdown\fR\|(3) is not called prior to -\&\fBSSL_free\fR\|(3). -.PP -In TLSv1.3 it is recommended that each \s-1SSL_SESSION\s0 object is only used for -resumption once. -.PP -\&\fBSSL_get0_session()\fR returns a pointer to the actual session. As the -reference counter is not incremented, the pointer is only valid while -the connection is in use. If \fBSSL_clear\fR\|(3) or -\&\fBSSL_free\fR\|(3) is called, the session may be removed completely -(if considered bad), and the pointer obtained will become invalid. Even -if the session is valid, it can be removed at any time due to timeout -during \fBSSL_CTX_flush_sessions\fR\|(3). -.PP -If the data is to be kept, \fBSSL_get1_session()\fR will increment the reference -count, so that the session will not be implicitly removed by other operations -but stays in memory. In order to remove the session -\&\fBSSL_SESSION_free\fR\|(3) must be explicitly called once -to decrement the reference count again. -.PP -\&\s-1SSL_SESSION\s0 objects keep internal link information about the session cache -list, when being inserted into one \s-1SSL_CTX\s0 object's session cache. -One \s-1SSL_SESSION\s0 object, regardless of its reference count, must therefore -only be used with one \s-1SSL_CTX\s0 object (and the \s-1SSL\s0 objects created -from this \s-1SSL_CTX\s0 object). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "\s-1NULL\s0" 4 -.IX Item "NULL" -There is no session available in \fBssl\fR. -.IP "Pointer to an \s-1SSL_SESSION\s0" 4 -.IX Item "Pointer to an SSL_SESSION" -The return value points to the data of an \s-1SSL\s0 session. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_free\fR\|(3), -\&\fBSSL_clear\fR\|(3), -\&\fBSSL_SESSION_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_shared_ciphers.3ossl b/openssl-install/share/man/man3/SSL_get_shared_ciphers.3ossl deleted file mode 120000 index 5ab60591..00000000 --- a/openssl-install/share/man/man3/SSL_get_shared_ciphers.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_ciphers.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_shared_curve.3ossl b/openssl-install/share/man/man3/SSL_get_shared_curve.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_get_shared_curve.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_shared_group.3ossl b/openssl-install/share/man/man3/SSL_get_shared_group.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_get_shared_group.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_shared_sigalgs.3ossl b/openssl-install/share/man/man3/SSL_get_shared_sigalgs.3ossl deleted file mode 100644 index e555f11f..00000000 --- a/openssl-install/share/man/man3/SSL_get_shared_sigalgs.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_SHARED_SIGALGS 3ossl" -.TH SSL_GET_SHARED_SIGALGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_shared_sigalgs, SSL_get_sigalgs \- get supported signature algorithms -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_shared_sigalgs(SSL *s, int idx, -\& int *psign, int *phash, int *psignhash, -\& unsigned char *rsig, unsigned char *rhash); -\& -\& int SSL_get_sigalgs(SSL *s, int idx, -\& int *psign, int *phash, int *psignhash, -\& unsigned char *rsig, unsigned char *rhash); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_shared_sigalgs()\fR returns information about the shared signature -algorithms supported by peer \fBs\fR. The parameter \fBidx\fR indicates the index -of the shared signature algorithm to return starting from zero. The signature -algorithm \s-1NID\s0 is written to \fB*psign\fR, the hash \s-1NID\s0 to \fB*phash\fR and the -sign and hash \s-1NID\s0 to \fB*psignhash\fR. The raw signature and hash values -are written to \fB*rsig\fR and \fB*rhash\fR. -.PP -\&\fBSSL_get_sigalgs()\fR is similar to \fBSSL_get_shared_sigalgs()\fR except it returns -information about all signature algorithms supported by \fBs\fR in the order -they were sent by the peer. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_shared_sigalgs()\fR and \fBSSL_get_sigalgs()\fR return the number of -signature algorithms or \fB0\fR if the \fBidx\fR parameter is out of range. -.SH "NOTES" -.IX Header "NOTES" -These functions are typically called for debugging purposes (to report -the peer's preferences) or where an application wants finer control over -certificate selection. Most applications will rely on internal handling -and will not need to call them. -.PP -If an application is only interested in the highest preference shared -signature algorithm it can just set \fBidx\fR to zero. -.PP -Any or all of the parameters \fBpsign\fR, \fBphash\fR, \fBpsignhash\fR, \fBrsig\fR or -\&\fBrhash\fR can be set to \fB\s-1NULL\s0\fR if the value is not required. By setting -them all to \fB\s-1NULL\s0\fR and setting \fBidx\fR to zero the total number of -signature algorithms can be determined: which can be zero. -.PP -These functions must be called after the peer has sent a list of supported -signature algorithms: after a client hello (for servers) or a certificate -request (for clients). They can (for example) be called in the certificate -callback. -.PP -Only \s-1TLS 1.2, TLS 1.3\s0 and \s-1DTLS 1.2\s0 currently support signature algorithms. -If these -functions are called on an earlier version of \s-1TLS\s0 or \s-1DTLS\s0 zero is returned. -.PP -The shared signature algorithms returned by \fBSSL_get_shared_sigalgs()\fR are -ordered according to configuration and peer preferences. -.PP -The raw values correspond to the on the wire form as defined by \s-1RFC5246\s0 et al. -The NIDs are OpenSSL equivalents. For example if the peer sent \fBsha256\fR\|(4) and -\&\fBrsa\fR\|(1) then \fB*rhash\fR would be 4, \fB*rsign\fR 1, \fB*phash\fR NID_sha256, \fB*psig\fR -NID_rsaEncryption and \fB*psignhash\fR NID_sha256WithRSAEncryption. -.PP -If a signature algorithm is not recognised the corresponding NIDs -will be set to \fBNID_undef\fR. This may be because the value is not supported, -is not an appropriate combination (for example \s-1MD5\s0 and \s-1DSA\s0) or the -signature algorithm does not use a hash (for example Ed25519). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_CTX_set_cert_cb\fR\|(3), -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_shutdown.3ossl b/openssl-install/share/man/man3/SSL_get_shutdown.3ossl deleted file mode 120000 index 5b96bd6d..00000000 --- a/openssl-install/share/man/man3/SSL_get_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_shutdown.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_sigalgs.3ossl b/openssl-install/share/man/man3/SSL_get_sigalgs.3ossl deleted file mode 120000 index ef88f25e..00000000 --- a/openssl-install/share/man/man3/SSL_get_sigalgs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_shared_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_signature_nid.3ossl b/openssl-install/share/man/man3/SSL_get_signature_nid.3ossl deleted file mode 120000 index 2ce2c761..00000000 --- a/openssl-install/share/man/man3/SSL_get_signature_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_signature_nid.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_signature_type_nid.3ossl b/openssl-install/share/man/man3/SSL_get_signature_type_nid.3ossl deleted file mode 120000 index 2ce2c761..00000000 --- a/openssl-install/share/man/man3/SSL_get_signature_type_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_signature_nid.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_srp_N.3ossl b/openssl-install/share/man/man3/SSL_get_srp_N.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_get_srp_N.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_srp_g.3ossl b/openssl-install/share/man/man3/SSL_get_srp_g.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_get_srp_g.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_srp_userinfo.3ossl b/openssl-install/share/man/man3/SSL_get_srp_userinfo.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_get_srp_userinfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_srp_username.3ossl b/openssl-install/share/man/man3/SSL_get_srp_username.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_get_srp_username.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_srtp_profiles.3ossl b/openssl-install/share/man/man3/SSL_get_srtp_profiles.3ossl deleted file mode 120000 index ab61a632..00000000 --- a/openssl-install/share/man/man3/SSL_get_srtp_profiles.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_use_srtp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_ssl_method.3ossl b/openssl-install/share/man/man3/SSL_get_ssl_method.3ossl deleted file mode 120000 index 05c88c50..00000000 --- a/openssl-install/share/man/man3/SSL_get_ssl_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ssl_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_state.3ossl b/openssl-install/share/man/man3/SSL_get_state.3ossl deleted file mode 120000 index b7a9c523..00000000 --- a/openssl-install/share/man/man3/SSL_get_state.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_in_init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_stream_id.3ossl b/openssl-install/share/man/man3/SSL_get_stream_id.3ossl deleted file mode 100644 index e7b1ee70..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_id.3ossl +++ /dev/null @@ -1,232 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_STREAM_ID 3ossl" -.TH SSL_GET_STREAM_ID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_stream_id, SSL_get_stream_type, SSL_STREAM_TYPE_NONE, -SSL_STREAM_TYPE_READ, SSL_STREAM_TYPE_WRITE, SSL_STREAM_TYPE_BIDI, -SSL_is_stream_local \- get QUIC stream ID and stream type information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& uint64_t SSL_get_stream_id(SSL *ssl); -\& -\& #define SSL_STREAM_TYPE_NONE -\& #define SSL_STREAM_TYPE_BIDI -\& #define SSL_STREAM_TYPE_READ -\& #define SSL_STREAM_TYPE_WRITE -\& int SSL_get_stream_type(SSL *ssl); -\& -\& int SSL_is_stream_local(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBSSL_get_stream_id()\fR function returns the \s-1QUIC\s0 stream \s-1ID\s0 for a \s-1QUIC\s0 stream -\&\s-1SSL\s0 object, or for a \s-1QUIC\s0 connection \s-1SSL\s0 object which has a default stream -attached. -.PP -The \fBSSL_get_stream_type()\fR function identifies what operations can be performed -on the stream, and returns one of the following values: -.IP "\fB\s-1SSL_STREAM_TYPE_NONE\s0\fR" 4 -.IX Item "SSL_STREAM_TYPE_NONE" -The \s-1SSL\s0 object is a \s-1QUIC\s0 connection \s-1SSL\s0 object without a default stream -attached. -.IP "\fB\s-1SSL_STREAM_TYPE_BIDI\s0\fR" 4 -.IX Item "SSL_STREAM_TYPE_BIDI" -The \s-1SSL\s0 object is a non-QUIC \s-1SSL\s0 object, or is a \s-1QUIC\s0 stream object (or \s-1QUIC\s0 -connection \s-1SSL\s0 object with a default stream attached), and that stream is a -bidirectional \s-1QUIC\s0 stream. -.IP "\fB\s-1SSL_STREAM_TYPE_READ\s0\fR" 4 -.IX Item "SSL_STREAM_TYPE_READ" -The \s-1SSL\s0 object is a \s-1QUIC\s0 stream object (or \s-1QUIC\s0 connection \s-1SSL\s0 object with a -default stream attached), and that stream is a unidirectional \s-1QUIC\s0 stream which -was initiated by the remote peer; thus, it can be read from, but not written to. -.IP "\fB\s-1SSL_STREAM_TYPE_WRITE\s0\fR" 4 -.IX Item "SSL_STREAM_TYPE_WRITE" -The \s-1SSL\s0 object is a \s-1QUIC\s0 stream object (or \s-1QUIC\s0 connection \s-1SSL\s0 object with a -default stream attached), and that stream is a unidirectional \s-1QUIC\s0 stream which -was initiated by the local application; thus, it can be written to, but not read -from. -.PP -The \fBSSL_is_stream_local()\fR function determines whether a stream was locally -created. -.SH "NOTES" -.IX Header "NOTES" -While QUICv1 assigns specific meaning to the low two bits of a \s-1QUIC\s0 stream \s-1ID, -QUIC\s0 stream IDs in future versions of \s-1QUIC\s0 are not required to have the same -semantics. Do not determine stream properties using these bits. Instead, use -\&\fBSSL_get_stream_type()\fR to determine the stream type and \fBSSL_get_stream_is_local()\fR -to determine the stream initiator. -.PP -The \fBSSL_get_stream_type()\fR identifies the type of a \s-1QUIC\s0 stream based on its -identity, and does not indicate whether an operation can currently be -successfully performed on a stream. For example, you might locally initiate a -unidirectional stream, write to it, and then conclude the stream using -\&\fBSSL_stream_conclude\fR\|(3), meaning that it can no longer be written to, but -\&\fBSSL_get_stream_type()\fR would still return \fB\s-1SSL_STREAM_TYPE_WRITE\s0\fR. The value -returned by \fBSSL_get_stream_type()\fR does not vary over the lifespan of a stream. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_stream_id()\fR returns a \s-1QUIC\s0 stream \s-1ID,\s0 or \fB\s-1UINT64_MAX\s0\fR if called on an -\&\s-1SSL\s0 object which is not a \s-1QUIC SSL\s0 object, or if called on a \s-1QUIC\s0 connection \s-1SSL\s0 -object without a default stream attached. Note that valid \s-1QUIC\s0 stream IDs are -always below 2**62. -.PP -\&\fBSSL_get_stream_type()\fR returns one of the \fB\s-1SSL_STREAM_TYPE\s0\fR values. -.PP -\&\fBSSL_is_stream_local()\fR returns 1 if called on a \s-1QUIC\s0 stream \s-1SSL\s0 object which -represents a stream which was locally initiated. It returns 0 if called on a -\&\s-1QUIC\s0 stream \s-1SSL\s0 object which represents a stream which was remotely initiated by -a peer, and \-1 if called on any other kind of \s-1SSL\s0 object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_new_stream\fR\|(3), \fBSSL_accept_stream\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_stream_read_error_code.3ossl b/openssl-install/share/man/man3/SSL_get_stream_read_error_code.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_read_error_code.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_stream_read_state.3ossl b/openssl-install/share/man/man3/SSL_get_stream_read_state.3ossl deleted file mode 100644 index 1caf42e2..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_read_state.3ossl +++ /dev/null @@ -1,281 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_STREAM_READ_STATE 3ossl" -.TH SSL_GET_STREAM_READ_STATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_stream_read_state, SSL_get_stream_write_state, -SSL_get_stream_read_error_code, SSL_get_stream_write_error_code, -SSL_STREAM_STATE_NONE, SSL_STREAM_STATE_OK, SSL_STREAM_STATE_WRONG_DIR, -SSL_STREAM_STATE_FINISHED, SSL_STREAM_STATE_RESET_LOCAL, -SSL_STREAM_STATE_RESET_REMOTE, SSL_STREAM_STATE_CONN_CLOSED \- get QUIC stream -state -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_STREAM_STATE_NONE -\& #define SSL_STREAM_STATE_OK -\& #define SSL_STREAM_STATE_WRONG_DIR -\& #define SSL_STREAM_STATE_FINISHED -\& #define SSL_STREAM_STATE_RESET_LOCAL -\& #define SSL_STREAM_STATE_RESET_REMOTE -\& #define SSL_STREAM_STATE_CONN_CLOSED -\& -\& int SSL_get_stream_read_state(SSL *ssl); -\& int SSL_get_stream_write_state(SSL *ssl); -\& -\& int SSL_get_stream_read_error_code(SSL *ssl, uint64_t *app_error_code); -\& int SSL_get_stream_write_error_code(SSL *ssl, uint64_t *app_error_code); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_stream_read_state()\fR and \fBSSL_get_stream_write_state()\fR retrieve the -overall state of the receiving and sending parts of a \s-1QUIC\s0 stream, respectively. -.PP -They both return one of the following values: -.IP "\fB\s-1SSL_STREAM_STATE_NONE\s0\fR" 4 -.IX Item "SSL_STREAM_STATE_NONE" -This value is returned if called on a non-QUIC \s-1SSL\s0 object, or on a \s-1QUIC\s0 -connection \s-1SSL\s0 object without a default stream attached. -.IP "\fB\s-1SSL_STREAM_STATE_OK\s0\fR" 4 -.IX Item "SSL_STREAM_STATE_OK" -This value is returned on a stream which has not been concluded and remains -healthy. -.IP "\fB\s-1SSL_STREAM_STATE_WRONG_DIR\s0\fR" 4 -.IX Item "SSL_STREAM_STATE_WRONG_DIR" -This value is returned if \fBSSL_get_stream_read_state()\fR is called on a -locally-initiated (and thus send-only) unidirectional stream, or, conversely, if -\&\fBSSL_get_stream_write_state()\fR is called on a remotely-initiated (and thus -receive-only) unidirectional stream. -.IP "\fB\s-1SSL_STREAM_STATE_FINISHED\s0\fR" 4 -.IX Item "SSL_STREAM_STATE_FINISHED" -For \fBSSL_get_stream_read_state()\fR, this value is returned when the remote peer has -signalled the end of the receiving part of the stream. Note that there may still -be residual data available to read via \fBSSL_read\fR\|(3) when this state is -returned. -.Sp -For \fBSSL_get_stream_write_state()\fR, this value is returned when the local -application has concluded the stream using \fBSSL_stream_conclude\fR\|(3). Future -\&\fBSSL_write\fR\|(3) calls will not succeed. -.IP "\fB\s-1SSL_STREAM_STATE_RESET_LOCAL\s0\fR" 4 -.IX Item "SSL_STREAM_STATE_RESET_LOCAL" -This value is returned when the applicable stream part was reset by the local -application. -.Sp -For \fBSSL_get_stream_read_state()\fR, this means that the receiving part of the -stream was aborted using a locally transmitted \s-1QUIC\s0 \fB\s-1STOP_SENDING\s0\fR frame. It -may or may not still be possible to obtain any residual data which remains to be -read by calling \fBSSL_read\fR\|(3). -.Sp -For \fBSSL_get_stream_write_state()\fR, this means that the sending part of the stream -was aborted, for example because the application called \fBSSL_stream_reset\fR\|(3), -or because a \s-1QUIC\s0 stream \s-1SSL\s0 object with an un-concluded sending part was freed -using \fBSSL_free\fR\|(3). Calls to \fBSSL_write\fR\|(3) will fail. -.Sp -When this value is returned, the application error code which was signalled can -be obtained by calling \fBSSL_get_stream_read_error_code()\fR or -\&\fBSSL_get_stream_write_error_code()\fR as appropriate. -.IP "\fB\s-1SSL_STREAM_STATE_RESET_REMOTE\s0\fR" 4 -.IX Item "SSL_STREAM_STATE_RESET_REMOTE" -This value is returned when the applicable stream part was reset by the remote -peer. -.Sp -For \fBSSL_get_stream_read_state()\fR, this means that the peer sent a \s-1QUIC\s0 -\&\fB\s-1RESET_STREAM\s0\fR frame for the receiving part of the stream; the receiving part -of the stream was logically aborted by the peer. -.Sp -For \fBSSL_get_stream_write_state()\fR, this means that the peer sent a \s-1QUIC\s0 -\&\fB\s-1STOP_SENDING\s0\fR frame for the sending part of the stream; the peer has indicated -that it does not wish to receive further data on the sending part of the stream. -Calls to \fBSSL_write\fR\|(3) will fail. -.Sp -When this value is returned, the application error code which was signalled can -be obtained by calling \fBSSL_get_stream_read_error_code()\fR or -\&\fBSSL_get_stream_write_error_code()\fR as appropriate. -.IP "\fB\s-1SSL_STREAM_STATE_CONN_CLOSED\s0\fR" 4 -.IX Item "SSL_STREAM_STATE_CONN_CLOSED" -The \s-1QUIC\s0 connection to which the stream belongs was closed. You can obtain -information about the circumstances of this closure using -\&\fBSSL_get_conn_close_info\fR\|(3). There may still be residual data available to -read via \fBSSL_read\fR\|(3) when this state is returned. Calls to \fBSSL_write\fR\|(3) -will fail. \fBSSL_get_stream_read_state()\fR will return this state if and only if -\&\fBSSL_get_stream_write_state()\fR will also return this state. -.PP -\&\fBSSL_get_stream_read_error_code()\fR and \fBSSL_get_stream_write_error_code()\fR provide -the application error code which was signalled during non-normal termination of -the receiving or sending parts of a stream, respectively. On success, the -application error code is written to \fI*app_error_code\fR. -.SH "NOTES" -.IX Header "NOTES" -If a \s-1QUIC\s0 connection is closed, the stream state for all streams transitions to -\&\fB\s-1SSL_STREAM_STATE_CONN_CLOSED\s0\fR, but no application error code can be retrieved -using \fBSSL_get_stream_read_error_code()\fR or \fBSSL_get_stream_write_error_code()\fR, as -the \s-1QUIC\s0 connection closure process does not cause an application error code to -be associated with each individual stream still existing at the time of -connection closure. However, you can obtain the overall error code associated -with the connection closure using \fBSSL_get_conn_close_info\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_stream_read_state()\fR and \fBSSL_get_stream_write_state()\fR return one of the -\&\fB\s-1SSL_STREAM_STATE\s0\fR values. If called on a non-QUIC \s-1SSL\s0 object, or a \s-1QUIC\s0 -connection \s-1SSL\s0 object without a default stream, \fB\s-1SSL_STREAM_STATE_NONE\s0\fR is -returned. -.PP -\&\fBSSL_get_stream_read_error_code()\fR and \fBSSL_get_stream_write_error_code()\fR return 1 -on success and 0 if the stream was terminated normally. They return \-1 on error, -for example if the stream is still healthy, was still healthy at the time of -connection closure, if called on a stream for which the respective stream part -does not exist (e.g. on a unidirectional stream), or if called on a non-QUIC -object or a \s-1QUIC\s0 connection \s-1SSL\s0 object without a default stream attached. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_stream_conclude\fR\|(3), \fBSSL_stream_reset\fR\|(3), \fBSSL_new_stream\fR\|(3), -\&\fBSSL_accept_stream\fR\|(3), \fBSSL_get_conn_close_info\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_stream_type.3ossl b/openssl-install/share/man/man3/SSL_get_stream_type.3ossl deleted file mode 120000 index bdbd18f4..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_stream_write_buf_avail.3ossl b/openssl-install/share/man/man3/SSL_get_stream_write_buf_avail.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_write_buf_avail.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_stream_write_buf_size.3ossl b/openssl-install/share/man/man3/SSL_get_stream_write_buf_size.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_write_buf_size.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_stream_write_buf_used.3ossl b/openssl-install/share/man/man3/SSL_get_stream_write_buf_used.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_write_buf_used.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_stream_write_error_code.3ossl b/openssl-install/share/man/man3/SSL_get_stream_write_error_code.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_write_error_code.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_stream_write_state.3ossl b/openssl-install/share/man/man3/SSL_get_stream_write_state.3ossl deleted file mode 120000 index 26906ad6..00000000 --- a/openssl-install/share/man/man3/SSL_get_stream_write_state.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_read_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_time.3ossl b/openssl-install/share/man/man3/SSL_get_time.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_get_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_timeout.3ossl b/openssl-install/share/man/man3/SSL_get_timeout.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_get_timeout.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_tlsext_status_ocsp_resp.3ossl b/openssl-install/share/man/man3/SSL_get_tlsext_status_ocsp_resp.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_get_tlsext_status_ocsp_resp.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_tlsext_status_type.3ossl b/openssl-install/share/man/man3/SSL_get_tlsext_status_type.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_get_tlsext_status_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_tmp_key.3ossl b/openssl-install/share/man/man3/SSL_get_tmp_key.3ossl deleted file mode 120000 index 821f2f77..00000000 --- a/openssl-install/share/man/man3/SSL_get_tmp_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_peer_tmp_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_value_uint.3ossl b/openssl-install/share/man/man3/SSL_get_value_uint.3ossl deleted file mode 100644 index 1bd63708..00000000 --- a/openssl-install/share/man/man3/SSL_get_value_uint.3ossl +++ /dev/null @@ -1,449 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_VALUE_UINT 3ossl" -.TH SSL_GET_VALUE_UINT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_value_uint, SSL_set_value_uint, SSL_get_generic_value_uint, -SSL_set_generic_value_uint, SSL_get_feature_request_uint, -SSL_set_feature_request_uint, SSL_get_feature_peer_request_uint, -SSL_get_feature_negotiated_uint, SSL_get_quic_stream_bidi_local_avail, -SSL_get_quic_stream_bidi_remote_avail, SSL_get_quic_stream_uni_local_avail, -SSL_get_quic_stream_uni_remote_avail, SSL_VALUE_CLASS_GENERIC, -SSL_VALUE_CLASS_FEATURE_REQUEST, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, -SSL_VALUE_CLASS_FEATURE_NEGOTIATED, SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL, -SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL, SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL, -SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL, SSL_VALUE_QUIC_IDLE_TIMEOUT, -SSL_VALUE_EVENT_HANDLING_MODE, -SSL_VALUE_EVENT_HANDLING_MODE_INHERIT, -SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT, -SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT, -SSL_get_event_handling_mode, -SSL_set_event_handling_mode, -SSL_VALUE_STREAM_WRITE_BUF_SIZE, -SSL_get_stream_write_buf_size, -SSL_VALUE_STREAM_WRITE_BUF_USED, -SSL_get_stream_write_buf_used, -SSL_VALUE_STREAM_WRITE_BUF_AVAIL, -SSL_get_stream_write_buf_avail \- -manage negotiable features and configuration values for a SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_get_value_uint(SSL *ssl, uint32_t class_, uint32_t id, -\& uint64_t *value); -\& int SSL_set_value_uint(SSL *ssl, uint32_t class_, uint32_t id, -\& uint64_t value); -\& -\& #define SSL_VALUE_CLASS_GENERIC -\& #define SSL_VALUE_CLASS_FEATURE_REQUEST -\& #define SSL_VALUE_CLASS_FEATURE_PEER_REQUEST -\& #define SSL_VALUE_CLASS_FEATURE_NEGOTIATED -\& -\& #define SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL -\& #define SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL -\& #define SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL -\& #define SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL -\& #define SSL_VALUE_QUIC_IDLE_TIMEOUT -\& -\& #define SSL_VALUE_EVENT_HANDLING_MODE -\& #define SSL_VALUE_EVENT_HANDLING_MODE_INHERIT -\& #define SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT -\& #define SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT -\& -\& #define SSL_VALUE_STREAM_WRITE_BUF_SIZE -\& #define SSL_VALUE_STREAM_WRITE_BUF_USED -\& #define SSL_VALUE_STREAM_WRITE_BUF_AVAIL -.Ve -.PP -The following convenience macros can also be used: -.PP -.Vb 2 -\& int SSL_get_generic_value_uint(SSL *ssl, uint32_t id, uint64_t *value); -\& int SSL_set_generic_value_uint(SSL *ssl, uint32_t id, uint64_t value); -\& -\& int SSL_get_feature_request_uint(SSL *ssl, uint32_t id, uint64_t *value); -\& int SSL_set_feature_request_uint(SSL *ssl, uint32_t id, uint64_t value); -\& -\& int SSL_get_feature_peer_request_uint(SSL *ssl, uint32_t id, uint64_t *value); -\& int SSL_get_feature_negotiated_uint(SSL *ssl, uint32_t id, uint64_t *value); -\& -\& int SSL_get_quic_stream_bidi_local_avail(SSL *ssl, uint64_t *value); -\& int SSL_get_quic_stream_bidi_remote_avail(SSL *ssl, uint64_t *value); -\& int SSL_get_quic_stream_uni_local_avail(SSL *ssl, uint64_t *value); -\& int SSL_get_quic_stream_uni_remote_avail(SSL *ssl, uint64_t *value); -\& -\& int SSL_get_event_handling_mode(SSL *ssl, uint64_t *value); -\& int SSL_set_event_handling_mode(SSL *ssl, uint64_t value); -\& -\& int SSL_get_stream_write_buf_size(SSL *ssl, uint64_t *value); -\& int SSL_get_stream_write_buf_avail(SSL *ssl, uint64_t *value); -\& int SSL_get_stream_write_buf_used(SSL *ssl, uint64_t *value); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_value_uint()\fR and \fBSSL_set_value_uint()\fR provide access to configurable -parameters for a given \s-1SSL\s0 object. Amongst other things, they are used to -provide control over the feature negotiation process during establishment of a -connection, and access to statistics about that connection. -.PP -\&\fBSSL_get_value_uint()\fR and \fBSSL_set_value_uint()\fR get and set configurable values -within a given value class. The value classes are enumerated by -\&\fB\s-1SSL_VALUE_CLASS\s0\fR and are as follows: -.IP "\fB\s-1SSL_VALUE_CLASS_GENERIC\s0\fR" 4 -.IX Item "SSL_VALUE_CLASS_GENERIC" -Values in this class do not participate in the feature negotiation process. They -may represent connection parameters which do not participate in explicit -negotiation or provide connection statistics. Values in this class might be -read-write or read-only. -.Sp -You can access values in this class using the convenience macros -\&\fBSSL_get_generic_value_uint()\fR and \fBSSL_set_generic_value_uint()\fR for brevity. -.IP "\fB\s-1SSL_VALUE_CLASS_FEATURE_REQUEST\s0\fR" 4 -.IX Item "SSL_VALUE_CLASS_FEATURE_REQUEST" -Values in this class are read-write, and represent what the local party is -requesting during feature negotiation. Such a request will not necessarily be -honoured; see \fB\s-1SSL_VALUE_CLASS_FEATURE_NEGOTIATED\s0\fR. -.Sp -A value in this class may become read-only in certain circumstances; for -example, after a connection has been established, for a value which cannot be -renegotiated after connection establishment. Setting a value in this class after -connection establishment represents a request for online renegotiation of the -specified feature. -.Sp -You can access values in this class using the convenience macros -\&\fBSSL_get_feature_request_uint()\fR and \fBSSL_set_feature_request_uint()\fR for brevity. -.IP "\fB\s-1SSL_VALUE_CLASS_FEATURE_PEER_REQUEST\s0\fR" 4 -.IX Item "SSL_VALUE_CLASS_FEATURE_PEER_REQUEST" -Values in this value class are read-only, and represent what was requested by a -peer during feature negotiation. Such a request has not necessarily been -honoured; see \fB\s-1SSL_VALUE_CLASS_FEATURE_NEGOTIATED\s0\fR. -.Sp -You can access values in this class using the convenience macro -\&\fBSSL_get_feature_peer_request_uint()\fR for brevity. -.IP "\fB\s-1SSL_VALUE_CLASS_FEATURE_NEGOTIATED\s0\fR" 4 -.IX Item "SSL_VALUE_CLASS_FEATURE_NEGOTIATED" -Values in this value class are read-only, and represent the value which was -actually negotiated based on both local and peer input during feature -negotiation. This is the effective value in actual use. -.Sp -Attempting to read a value in this class will generally fail if the feature -negotiation process has not yet completed and the value is therefore currently -unknown, unless the nature of the feature in question causes a provisional value -to be used prior to completion of feature negotiation, in which case that value -may be returned. If an online (post-handshake) renegotiation of a feature is -in progress, retrieving the negotiated value will continue to retrieve the -previous negotiated value until that process is completed. See the documentation -of specific values for full details of its behaviour. -.Sp -You can access values in this class using the convenience macro -\&\fBSSL_get_feature_negotiated_uint()\fR for brevity. -.SH "CONFIGURABLE VALUES FOR QUIC OBJECTS" -.IX Header "CONFIGURABLE VALUES FOR QUIC OBJECTS" -The following configurable values are supported for \s-1QUIC SSL\s0 objects. Whether a -value is supported for a \s-1QUIC\s0 connection \s-1SSL\s0 object or a \s-1QUIC\s0 stream \s-1SSL\s0 object -is indicated in the heading for each value. Values supported for \s-1QUIC\s0 stream \s-1SSL\s0 -objects are also supported on \s-1QUIC\s0 connection \s-1SSL\s0 objects if they have a default -stream attached. -.PP -\&\fBSSL_get_value()\fR does not cause internal event processing to occur unless the -documentation for a specific value specifies otherwise. -.IP "\fB\s-1SSL_VALUE_QUIC_IDLE_TIMEOUT\s0\fR (connection object)" 4 -.IX Item "SSL_VALUE_QUIC_IDLE_TIMEOUT (connection object)" -Negotiated feature value. This configures the desired \s-1QUIC\s0 idle timeout in -milliseconds, where 0 represents a lack of an idle timeout. This feature can -only be configured prior to connection establishment and cannot be subsequently -changed. -.Sp -This release of OpenSSL uses a default value of 30 seconds. This default value -may change between releases of OpenSSL. -.IP "\fB\s-1SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL\s0\fR (connection object)" 4 -.IX Item "SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL (connection object)" -Generic read-only statistical value. The number of bidirectional, -locally-initiated streams available to be created (but not yet created). For -example, a value of 100 would mean that \fBSSL_new_stream\fR\|(3) could be called 100 -times to create 100 bidirectional streams before \fBSSL_new_stream\fR\|(3) would -block or fail due to backpressure. -.Sp -Can be queried using the convenience macro -\&\fBSSL_get_quic_stream_bidi_local_avail()\fR. -.IP "\fB\s-1SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL\s0\fR (connection object)" 4 -.IX Item "SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL (connection object)" -As above, but provides the number of unidirectional, locally-initiated streams -available to be created (but not yet created). -.Sp -Can be queried using the convenience macro -\&\fBSSL_get_quic_stream_uni_local_avail()\fR. -.IP "\fB\s-1SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL\s0\fR (connection object)" 4 -.IX Item "SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL (connection object)" -As above, but provides the number of bidirectional, remotely-initiated streams -available to be created (but not yet created) by the peer. This represents the -number of streams the local endpoint has authorised the peer to create in terms -of \s-1QUIC\s0 stream creation flow control. -.Sp -Can be queried using the convenience macro -\&\fBSSL_get_quic_stream_bidi_remote_avail()\fR. -.IP "\fB\s-1SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL\s0\fR (connection object)" 4 -.IX Item "SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL (connection object)" -As above, but provides the number of unidirectional, remotely-initiated streams -available to be created (but not yet created). -.Sp -Can be queried using the convenience macro -\&\fBSSL_get_quic_stream_uni_remote_avail()\fR. -.IP "\fB\s-1SSL_VALUE_EVENT_HANDLING_MODE\s0\fR (connection or stream object)" 4 -.IX Item "SSL_VALUE_EVENT_HANDLING_MODE (connection or stream object)" -Generic value. This is an integer value which takes one of the following values, -and determines the event handling mode in use: -.RS 4 -.IP "\fB\s-1SSL_VALUE_EVENT_HANDLING_MODE_INHERIT\s0\fR" 4 -.IX Item "SSL_VALUE_EVENT_HANDLING_MODE_INHERIT" -When set, the event handling mode used is inherited from the value set on the -parent connection (for a stream), or, for a connection, defaults to the implicit -event handling model. -.Sp -When a new connection is created, or a new stream is created or accepted, it -defaults to this setting. -.IP "\fB\s-1SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT\s0\fR (Implicit event handling)" 4 -.IX Item "SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT (Implicit event handling)" -If set to this value, the implicit event handling model is used. Under this -model, \s-1QUIC\s0 objects will automatically perform background event processing -(equivalent to a call to \fBSSL_handle_events\fR\|(3)) when calls to I/O functions -such as \fBSSL_read_ex\fR\|(3) or \fBSSL_write_ex\fR\|(3) are made on a \s-1QUIC SSL\s0 object. -This helps to maintain the health of the \s-1QUIC\s0 connection and ensures that -incoming datagrams and timeout events are processed. -.IP "\fB\s-1SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT\s0\fR (Explicit event handling)" 4 -.IX Item "SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT (Explicit event handling)" -If set to this value, the explicit event handling model is used. Under this -model, \fBnonblocking\fR calls to I/O functions such as \fBSSL_read_ex\fR\|(3) or -\&\fBSSL_write_ex\fR\|(3) do not result in the automatic processing of \s-1QUIC\s0 events. Any -new incoming network traffic is not handled; no new outgoing network traffic is -generated, and pending timeout events are not processed. This allows an -application to obtain greater control over the circumstances in which \s-1QUIC\s0 event -processing occurs. If this event handling model is used, it is the application's -responsibility to call \fBSSL_handle_events\fR\|(3) as and when called for by the -\&\s-1QUIC\s0 implementation; see the \fBSSL_get_rpoll_descriptor\fR\|(3) man page for more -information. -.Sp -Selecting this model does not affect the operation of blocking I/O calls, which -will continue to use the implicit event handling model. Therefore, applications -using this model will generally want to disable blocking operation using -\&\fBSSL_set_blocking_mode\fR\|(3). -.RE -.RS 4 -.Sp -Can be configured using the convenience macros \fBSSL_get_event_handling_mode()\fR and -\&\fBSSL_set_event_handling_mode()\fR. -.Sp -A call to \fBSSL_set_value_uint()\fR which causes this value to switch back to the -implicit event handling model does not in itself cause implicit event handling -to occur; such handling will occur on the next I/O \s-1API\s0 call. Equally, a call to -\&\fBSSL_set_value_uint()\fR which causes this value to switch to the explicit event -handling model will not cause event handling to occur before making that -transition. -.Sp -This value controls whether implicit event handling occurs when making an I/O -\&\s-1API\s0 call on the \s-1SSL\s0 object it is set on. However, event processing is not -confined to state which relates to only that object. For example, if you -configure explicit event handling on \s-1QUIC\s0 stream \s-1SSL\s0 object \*(L"A\*(R" and configure -implicit event handling on \s-1QUIC\s0 stream \s-1SSL\s0 object \*(L"B\*(R", a call to an I/O function -on \*(L"B\*(R" may result in state changes to \*(L"A\*(R". In other words, if event handling -does happen as a result of an \s-1API\s0 call to an object related to a connection, -processing of background events (for example, received \s-1QUIC\s0 network traffic) may -also affect the state of any other object related to a connection. -.RE -.IP "\fB\s-1SSL_VALUE_STREAM_WRITE_BUF_SIZE\s0\fR (stream object)" 4 -.IX Item "SSL_VALUE_STREAM_WRITE_BUF_SIZE (stream object)" -Generic read-only statistical value. The size of the write buffer allocated to -hold data written to a stream with \fBSSL_write_ex\fR\|(3) until it is transmitted -and subsequently acknowledged by the peer. This value may change at any time, as -buffer sizes are optimised in response to network conditions to optimise -throughput. -.Sp -Can be queried using the convenience macro \fBSSL_get_stream_write_buf_size()\fR. -.IP "\fB\s-1SSL_VALUE_STREAM_WRITE_BUF_USED\s0\fR (stream object)" 4 -.IX Item "SSL_VALUE_STREAM_WRITE_BUF_USED (stream object)" -Generic read-only statistical value. The number of bytes currently consumed -in the write buffer which have yet to be acknowledged by the peer. Successful -calls to \fBSSL_write_ex\fR\|(3) which accept data cause this number to increase. -This number will then decrease as data is acknowledged by the peer. -.Sp -Can be queried using the convenience macro \fBSSL_get_stream_write_buf_used()\fR. -.IP "\fB\s-1SSL_VALUE_STREAM_WRITE_BUF_AVAIL\s0\fR (stream object)" 4 -.IX Item "SSL_VALUE_STREAM_WRITE_BUF_AVAIL (stream object)" -Generic read-only statistical value. The number of bytes available in the write -buffer which have yet to be consumed by calls to \fBSSL_write_ex\fR\|(3). Successful -calls to \fBSSL_write_ex\fR\|(3) which accept data cause this number to decrease. -This number will increase as data is acknowledged by the peer. It may also -change if the buffer is resized automatically to optimise throughput. -.Sp -Can be queried using the convenience macro \fBSSL_get_stream_write_buf_avail()\fR. -.PP -No configurable values are currently defined for non-QUIC \s-1SSL\s0 objects. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success or 0 on failure. This function can fail for a number of -reasons: -.IP "\(bu" 4 -An argument is invalid (e.g. \s-1NULL\s0 pointer or invalid class). -.IP "\(bu" 4 -The given value is not supported by the \s-1SSL\s0 object on which it was called. -.IP "\(bu" 4 -The given operation (get or set) is not supported by the specified -configurable value. -.IP "\(bu" 4 -You are trying to modify the given value and the value is not modifiable at this -time. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_ctrl\fR\|(3), \fBSSL_get_accept_stream_queue_len\fR\|(3), -\&\fBSSL_get_stream_read_state\fR\|(3), \fBSSL_get_stream_write_state\fR\|(3), -\&\fBSSL_get_stream_read_error_code\fR\|(3), \fBSSL_get_stream_write_error_code\fR\|(3), -\&\fBSSL_set_default_stream_mode\fR\|(3), \fBSSL_set_incoming_stream_policy\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_verify_callback.3ossl b/openssl-install/share/man/man3/SSL_get_verify_callback.3ossl deleted file mode 120000 index c88643e6..00000000 --- a/openssl-install/share/man/man3/SSL_get_verify_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get_verify_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_verify_depth.3ossl b/openssl-install/share/man/man3/SSL_get_verify_depth.3ossl deleted file mode 120000 index c88643e6..00000000 --- a/openssl-install/share/man/man3/SSL_get_verify_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get_verify_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_verify_mode.3ossl b/openssl-install/share/man/man3/SSL_get_verify_mode.3ossl deleted file mode 120000 index c88643e6..00000000 --- a/openssl-install/share/man/man3/SSL_get_verify_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get_verify_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_verify_result.3ossl b/openssl-install/share/man/man3/SSL_get_verify_result.3ossl deleted file mode 100644 index 12964dc0..00000000 --- a/openssl-install/share/man/man3/SSL_get_verify_result.3ossl +++ /dev/null @@ -1,197 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_VERIFY_RESULT 3ossl" -.TH SSL_GET_VERIFY_RESULT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_get_verify_result \- get result of peer certificate verification -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long SSL_get_verify_result(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_get_verify_result()\fR returns the result of the verification of the -X509 certificate presented by the peer, if any. -.SH "NOTES" -.IX Header "NOTES" -\&\fBSSL_get_verify_result()\fR can only return one error code while the verification -of a certificate can fail because of many reasons at the same time. Only -the last verification error that occurred during the processing is available -from \fBSSL_get_verify_result()\fR. -.PP -Sometimes there can be a sequence of errors leading to the verification -failure as reported by \fBSSL_get_verify_result()\fR. -To get the errors, it is necessary to setup a verify callback via -\&\fBSSL_CTX_set_verify\fR\|(3) or \fBSSL_set_verify\fR\|(3) and retrieve the errors -from the error stack there, because once \fBSSL_connect\fR\|(3) returns, -these errors may no longer be available. -.PP -The verification result is part of the established session and is restored -when a session is reused. -.SH "BUGS" -.IX Header "BUGS" -If no peer certificate was presented, the returned result code is -X509_V_OK. This is because no verification error occurred, it does however -not indicate success. \fBSSL_get_verify_result()\fR is only useful in connection -with \fBSSL_get_peer_certificate\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can currently occur: -.IP "X509_V_OK" 4 -.IX Item "X509_V_OK" -The verification succeeded or no peer certificate was presented. -.IP "Any other value" 4 -.IX Item "Any other value" -Documented in \fBopenssl\-verify\fR\|(1). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_set_verify_result\fR\|(3), -\&\fBSSL_get_peer_certificate\fR\|(3), -\&\fBopenssl\-verify\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_version.3ossl b/openssl-install/share/man/man3/SSL_get_version.3ossl deleted file mode 100644 index 73b4b57a..00000000 --- a/openssl-install/share/man/man3/SSL_get_version.3ossl +++ /dev/null @@ -1,255 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GET_VERSION 3ossl" -.TH SSL_GET_VERSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_client_version, SSL_get_version, SSL_is_dtls, SSL_is_tls, SSL_is_quic, -SSL_version \- get the protocol information of a connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_client_version(const SSL *s); -\& -\& const char *SSL_get_version(const SSL *ssl); -\& -\& int SSL_is_dtls(const SSL *ssl); -\& int SSL_is_tls(const SSL *ssl); -\& int SSL_is_quic(const SSL *ssl); -\& -\& int SSL_version(const SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -For \s-1SSL, TLS\s0 and \s-1DTLS\s0 protocols \fBSSL_client_version()\fR returns the numeric -protocol version advertised by the client in the legacy_version field of the -ClientHello when initiating the connection. Note that, for \s-1TLS,\s0 this value -will never indicate a version greater than TLSv1.2 even if TLSv1.3 is -subsequently negotiated. For \s-1QUIC\s0 connections it returns \s-1OSSL_QUIC1_VERSION.\s0 -.PP -\&\fBSSL_get_version()\fR returns the name of the protocol used for the connection. -\&\fBSSL_version()\fR returns the numeric protocol version used for the connection. -They should only be called after the initial handshake has been completed. -Prior to that the results returned from these functions may be unreliable. -.PP -\&\fBSSL_is_dtls()\fR returns 1 if the connection is using \s-1DTLS\s0 or 0 if not. -.PP -\&\fBSSL_is_tls()\fR returns 1 if the connection is using \s-1SSL/TLS\s0 or 0 if not. -.PP -\&\fBSSL_is_quic()\fR returns 1 if the connection is using \s-1QUIC\s0 or 0 if not. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_get_version()\fR returns one of the following strings: -.IP "SSLv3" 4 -.IX Item "SSLv3" -The connection uses the SSLv3 protocol. -.IP "TLSv1" 4 -.IX Item "TLSv1" -The connection uses the TLSv1.0 protocol. -.IP "TLSv1.1" 4 -.IX Item "TLSv1.1" -The connection uses the TLSv1.1 protocol. -.IP "TLSv1.2" 4 -.IX Item "TLSv1.2" -The connection uses the TLSv1.2 protocol. -.IP "TLSv1.3" 4 -.IX Item "TLSv1.3" -The connection uses the TLSv1.3 protocol. -.IP "DTLSv0.9" 4 -.IX Item "DTLSv0.9" -The connection uses an obsolete pre-standardisation \s-1DTLS\s0 protocol -.IP "DTLSv1" 4 -.IX Item "DTLSv1" -The connection uses the DTLSv1 protocol -.IP "DTLSv1.2" 4 -.IX Item "DTLSv1.2" -The connection uses the DTLSv1.2 protocol -.IP "QUICv1" 4 -.IX Item "QUICv1" -The connection uses the QUICv1 protocol. -.IP "unknown" 4 -.IX Item "unknown" -This indicates an unknown protocol version. -.PP -\&\fBSSL_version()\fR and \fBSSL_client_version()\fR return an integer which could include any -of the following: -.IP "\s-1SSL3_VERSION\s0" 4 -.IX Item "SSL3_VERSION" -The connection uses the SSLv3 protocol. -.IP "\s-1TLS1_VERSION\s0" 4 -.IX Item "TLS1_VERSION" -The connection uses the TLSv1.0 protocol. -.IP "\s-1TLS1_1_VERSION\s0" 4 -.IX Item "TLS1_1_VERSION" -The connection uses the TLSv1.1 protocol. -.IP "\s-1TLS1_2_VERSION\s0" 4 -.IX Item "TLS1_2_VERSION" -The connection uses the TLSv1.2 protocol. -.IP "\s-1TLS1_3_VERSION\s0" 4 -.IX Item "TLS1_3_VERSION" -The connection uses the TLSv1.3 protocol (never returned for -\&\fBSSL_client_version()\fR). -.IP "\s-1DTLS1_BAD_VER\s0" 4 -.IX Item "DTLS1_BAD_VER" -The connection uses an obsolete pre-standardisation \s-1DTLS\s0 protocol -.IP "\s-1DTLS1_VERSION\s0" 4 -.IX Item "DTLS1_VERSION" -The connection uses the DTLSv1 protocol -.IP "\s-1DTLS1_2_VERSION\s0" 4 -.IX Item "DTLS1_2_VERSION" -The connection uses the DTLSv1.2 protocol -.IP "\s-1OSSL_QUIC1_VERSION\s0" 4 -.IX Item "OSSL_QUIC1_VERSION" -The connection uses the QUICv1 protocol. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_is_dtls()\fR function was added in OpenSSL 1.1.0. The \fBSSL_is_tls()\fR and -\&\fBSSL_is_quic()\fR functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_get_wbio.3ossl b/openssl-install/share/man/man3/SSL_get_wbio.3ossl deleted file mode 120000 index 08b6922a..00000000 --- a/openssl-install/share/man/man3/SSL_get_wbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_rbio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_wfd.3ossl b/openssl-install/share/man/man3/SSL_get_wfd.3ossl deleted file mode 120000 index cc6f89a3..00000000 --- a/openssl-install/share/man/man3/SSL_get_wfd.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_fd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_get_wpoll_descriptor.3ossl b/openssl-install/share/man/man3/SSL_get_wpoll_descriptor.3ossl deleted file mode 120000 index 3e5cf526..00000000 --- a/openssl-install/share/man/man3/SSL_get_wpoll_descriptor.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_rpoll_descriptor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_group_to_name.3ossl b/openssl-install/share/man/man3/SSL_group_to_name.3ossl deleted file mode 100644 index a134e04e..00000000 --- a/openssl-install/share/man/man3/SSL_group_to_name.3ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_GROUP_TO_NAME 3ossl" -.TH SSL_GROUP_TO_NAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_group_to_name \- get name of group -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_group_to_name(SSL *ssl, int id); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_group_to_name()\fR is used to retrieve the \s-1TLS\s0 group name -associated with a given \s-1TLS\s0 group \s-1ID,\s0 as registered via built-in -or external providers and as returned by a call to \fBSSL_get1_groups()\fR -or \fBSSL_get_shared_group()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If non-NULL, \fBSSL_group_to_name()\fR returns the \s-1TLS\s0 group name -corresponding to the given \fIid\fR as a NUL-terminated string. -If \fBSSL_group_to_name()\fR returns \s-1NULL,\s0 an error occurred; possibly no -corresponding tlsname was registered during provider initialisation. -.PP -Note that the return value is valid only during the lifetime of the -\&\s-1SSL\s0 object \fIssl\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_handle_events.3ossl b/openssl-install/share/man/man3/SSL_handle_events.3ossl deleted file mode 100644 index 9d23f6ee..00000000 --- a/openssl-install/share/man/man3/SSL_handle_events.3ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_HANDLE_EVENTS 3ossl" -.TH SSL_HANDLE_EVENTS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_handle_events \- advance asynchronous state machine and perform network I/O -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_handle_events(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_handle_events()\fR performs any internal processing which is due on a \s-1SSL\s0 object. The -exact operations performed by \fBSSL_handle_events()\fR vary depending on what kind of protocol -is being used with the given \s-1SSL\s0 object. For example, \fBSSL_handle_events()\fR may handle -timeout events which have become due, or may attempt, to the extent currently -possible, to perform network I/O operations on one of the BIOs underlying the -\&\s-1SSL\s0 object. -.PP -The primary use case for \fBSSL_handle_events()\fR is to allow an application which uses -OpenSSL in nonblocking mode to give OpenSSL an opportunity to handle timer -events, or to respond to the availability of new data to be read from an -underlying \s-1BIO,\s0 or to respond to the opportunity to write pending data to an -underlying \s-1BIO.\s0 -.PP -\&\fBSSL_handle_events()\fR can be used only with the following types of \s-1SSL\s0 object: -.IP "\s-1DTLS SSL\s0 objects" 4 -.IX Item "DTLS SSL objects" -Using \fBSSL_handle_events()\fR on an \s-1SSL\s0 object being used with a \s-1DTLS\s0 method allows timeout -events to be handled properly. This is equivalent to a call to -\&\fBDTLSv1_handle_timeout\fR\|(3). Since \fBSSL_handle_events()\fR handles a superset of the use -cases of \fBDTLSv1_handle_timeout\fR\|(3), it should be preferred for new -applications which do not require support for OpenSSL 3.1 or older. -.Sp -When using \s-1DTLS,\s0 an application must call \fBSSL_handle_events()\fR as indicated by -calls to \fBSSL_get_event_timeout\fR\|(3); event handling is not performed -automatically by calls to other \s-1SSL\s0 functions such as \fBSSL_read\fR\|(3) or -\&\fBSSL_write\fR\|(3). Note that this is different to \s-1QUIC\s0 which also performs event -handling implicitly; see below. -.IP "\s-1QUIC\s0 connection \s-1SSL\s0 objects" 4 -.IX Item "QUIC connection SSL objects" -Using \fBSSL_handle_events()\fR on an \s-1SSL\s0 object which represents a \s-1QUIC\s0 connection allows -timeout events to be handled properly, as well as incoming network data to be -processed, and queued outgoing network data to be written, if the underlying \s-1BIO\s0 -has the capacity to accept it. -.Sp -Ordinarily, when an application uses an \s-1SSL\s0 object in blocking mode, it does not -need to call \fBSSL_handle_events()\fR because OpenSSL performs ticking internally on an -automatic basis. However, if an application uses a \s-1QUIC\s0 connection in -nonblocking mode, it must at a minimum ensure that \fBSSL_handle_events()\fR is called -periodically to allow timeout events to be handled. An application can find out -when it next needs to call \fBSSL_handle_events()\fR for this purpose (if at all) by calling -\&\fBSSL_get_event_timeout\fR\|(3). -.Sp -Calling \fBSSL_handle_events()\fR on a \s-1QUIC\s0 connection \s-1SSL\s0 object being used in blocking mode -is not necessary unless no I/O calls (such as \fBSSL_read\fR\|(3) or \fBSSL_write\fR\|(3)) -will be made to the object for a substantial period of time. So long as at least -one call to the \s-1SSL\s0 object is blocking, no such call is needed. However, -\&\fBSSL_handle_events()\fR may optionally be used on a \s-1QUIC\s0 connection object if desired. -.Sp -With the thread-assisted mode of operation \fBOSSL_QUIC_client_thread_method\fR\|(3) -it is unnecessary to call \fBSSL_handle_events()\fR as the assist thread handles the \s-1QUIC\s0 -connection events. -.PP -Calling \fBSSL_handle_events()\fR on any other kind of \s-1SSL\s0 object is a no-op. This is -considered a success case. -.PP -Note that \fBSSL_handle_events()\fR supersedes the older \fBDTLSv1_handle_timeout\fR\|(3) function -for all use cases. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success and 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_event_timeout\fR\|(3), \fBDTLSv1_handle_timeout\fR\|(3), \fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_handle_events()\fR function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_has_matching_session_id.3ossl b/openssl-install/share/man/man3/SSL_has_matching_session_id.3ossl deleted file mode 120000 index 625534b5..00000000 --- a/openssl-install/share/man/man3/SSL_has_matching_session_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_generate_session_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_has_pending.3ossl b/openssl-install/share/man/man3/SSL_has_pending.3ossl deleted file mode 120000 index c99c6325..00000000 --- a/openssl-install/share/man/man3/SSL_has_pending.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_pending.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_in_accept_init.3ossl b/openssl-install/share/man/man3/SSL_in_accept_init.3ossl deleted file mode 120000 index b7a9c523..00000000 --- a/openssl-install/share/man/man3/SSL_in_accept_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_in_init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_in_before.3ossl b/openssl-install/share/man/man3/SSL_in_before.3ossl deleted file mode 120000 index b7a9c523..00000000 --- a/openssl-install/share/man/man3/SSL_in_before.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_in_init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_in_connect_init.3ossl b/openssl-install/share/man/man3/SSL_in_connect_init.3ossl deleted file mode 120000 index b7a9c523..00000000 --- a/openssl-install/share/man/man3/SSL_in_connect_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_in_init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_in_init.3ossl b/openssl-install/share/man/man3/SSL_in_init.3ossl deleted file mode 100644 index 66ea06ee..00000000 --- a/openssl-install/share/man/man3/SSL_in_init.3ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_IN_INIT 3ossl" -.TH SSL_IN_INIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_in_before, -SSL_in_init, -SSL_is_init_finished, -SSL_in_connect_init, -SSL_in_accept_init, -SSL_get_state -\&\- retrieve information about the handshake state machine -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_in_init(const SSL *s); -\& int SSL_in_before(const SSL *s); -\& int SSL_is_init_finished(const SSL *s); -\& -\& int SSL_in_connect_init(SSL *s); -\& int SSL_in_accept_init(SSL *s); -\& -\& OSSL_HANDSHAKE_STATE SSL_get_state(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_in_init()\fR returns 1 if the \s-1SSL/TLS\s0 state machine is currently processing or -awaiting handshake messages, or 0 otherwise. -.PP -\&\fBSSL_in_before()\fR returns 1 if no \s-1SSL/TLS\s0 handshake has yet been initiated, or 0 -otherwise. -.PP -\&\fBSSL_is_init_finished()\fR returns 1 if the \s-1SSL/TLS\s0 connection is in a state where -fully protected application data can be transferred or 0 otherwise. -.PP -Note that in some circumstances (such as when early data is being transferred) -\&\fBSSL_in_init()\fR, \fBSSL_in_before()\fR and \fBSSL_is_init_finished()\fR can all return 0. -.PP -\&\fBSSL_in_connect_init()\fR returns 1 if \fBs\fR is acting as a client and \fBSSL_in_init()\fR -would return 1, or 0 otherwise. -.PP -\&\fBSSL_in_accept_init()\fR returns 1 if \fBs\fR is acting as a server and \fBSSL_in_init()\fR -would return 1, or 0 otherwise. -.PP -\&\fBSSL_in_connect_init()\fR and \fBSSL_in_accept_init()\fR are implemented as macros. -.PP -\&\fBSSL_get_state()\fR returns a value indicating the current state of the handshake -state machine. \s-1OSSL_HANDSHAKE_STATE\s0 is an enumerated type where each value -indicates a discrete state machine state. Note that future versions of OpenSSL -may define more states so applications should expect to receive unrecognised -state values. The naming format is made up of a number of elements as follows: -.PP -\&\fBprotocol\fR_ST_\fBrole\fR_\fBmessage\fR -.PP -\&\fBprotocol\fR is one of \s-1TLS\s0 or \s-1DTLS. DTLS\s0 is used where a state is specific to the -\&\s-1DTLS\s0 protocol. Otherwise \s-1TLS\s0 is used. -.PP -\&\fBrole\fR is one of \s-1CR, CW, SR\s0 or \s-1SW\s0 to indicate \*(L"client reading\*(R", -\&\*(L"client writing\*(R", \*(L"server reading\*(R" or \*(L"server writing\*(R" respectively. -.PP -\&\fBmessage\fR is the name of a handshake message that is being or has been sent, or -is being or has been processed. -.PP -Additionally there are some special states that do not conform to the above -format. These are: -.IP "\s-1TLS_ST_BEFORE\s0" 4 -.IX Item "TLS_ST_BEFORE" -No handshake messages have yet been been sent or received. -.IP "\s-1TLS_ST_OK\s0" 4 -.IX Item "TLS_ST_OK" -Handshake message sending/processing has completed. -.IP "\s-1TLS_ST_EARLY_DATA\s0" 4 -.IX Item "TLS_ST_EARLY_DATA" -Early data is being processed -.IP "\s-1TLS_ST_PENDING_EARLY_DATA_END\s0" 4 -.IX Item "TLS_ST_PENDING_EARLY_DATA_END" -Awaiting the end of early data processing -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_in_init()\fR, \fBSSL_in_before()\fR, \fBSSL_is_init_finished()\fR, \fBSSL_in_connect_init()\fR -and \fBSSL_in_accept_init()\fR return values as indicated above. -.PP -\&\fBSSL_get_state()\fR returns the current handshake state. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_read_early_data\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_inject_net_dgram.3ossl b/openssl-install/share/man/man3/SSL_inject_net_dgram.3ossl deleted file mode 100644 index da06e4ae..00000000 --- a/openssl-install/share/man/man3/SSL_inject_net_dgram.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_INJECT_NET_DGRAM 3ossl" -.TH SSL_INJECT_NET_DGRAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_inject_net_dgram \- inject a datagram as though received from the network -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_inject_net_dgram(SSL *s, const unsigned char *buf, -\& size_t buf_len, -\& const BIO_ADDR *peer, -\& const BIO_ADDR *local); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This function can be used to inject a datagram payload to a \s-1QUIC\s0 connection \s-1SSL\s0 -object. The payload is processed as though it was received from the network. -This function can be used for debugging purposes or to allow datagrams to be fed -to \s-1QUIC\s0 from alternative sources. -.PP -\&\fIbuf\fR is required and must point to a datagram payload to inject. \fIbuf_len\fR is -the length of the buffer in bytes. The buffer is copied and need not remain -valid after this function returns. -.PP -\&\fIpeer\fR and \fIlocal\fR are optional values pointing to \fB\s-1BIO_ADDR\s0\fR structures -describing the remote and local \s-1UDP\s0 endpoint addresses for the packet. Though -the injected packet was not actually received from the network directly by -OpenSSL, the packet will be processed as though the received datagram had the -given addresses. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success or 0 on failure. This function always fails if called -on a \s-1SSL\s0 object which is not a \s-1QUIC\s0 connection \s-1SSL\s0 object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_QUIC_client_method\fR\|(3), \fBSSL_handle_events\fR\|(3), \fBSSL_set_blocking_mode\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBSSL_inject_net_dgram()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_is_connection.3ossl b/openssl-install/share/man/man3/SSL_is_connection.3ossl deleted file mode 120000 index ade55d7b..00000000 --- a/openssl-install/share/man/man3/SSL_is_connection.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get0_connection.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_is_dtls.3ossl b/openssl-install/share/man/man3/SSL_is_dtls.3ossl deleted file mode 120000 index 5d8aa60f..00000000 --- a/openssl-install/share/man/man3/SSL_is_dtls.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_is_init_finished.3ossl b/openssl-install/share/man/man3/SSL_is_init_finished.3ossl deleted file mode 120000 index b7a9c523..00000000 --- a/openssl-install/share/man/man3/SSL_is_init_finished.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_in_init.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_is_quic.3ossl b/openssl-install/share/man/man3/SSL_is_quic.3ossl deleted file mode 120000 index 5d8aa60f..00000000 --- a/openssl-install/share/man/man3/SSL_is_quic.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_is_server.3ossl b/openssl-install/share/man/man3/SSL_is_server.3ossl deleted file mode 120000 index 5b8be4e3..00000000 --- a/openssl-install/share/man/man3/SSL_is_server.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_connect_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_is_stream_local.3ossl b/openssl-install/share/man/man3/SSL_is_stream_local.3ossl deleted file mode 120000 index bdbd18f4..00000000 --- a/openssl-install/share/man/man3/SSL_is_stream_local.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_stream_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_is_tls.3ossl b/openssl-install/share/man/man3/SSL_is_tls.3ossl deleted file mode 120000 index 5d8aa60f..00000000 --- a/openssl-install/share/man/man3/SSL_is_tls.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_key_update.3ossl b/openssl-install/share/man/man3/SSL_key_update.3ossl deleted file mode 100644 index c8e2d846..00000000 --- a/openssl-install/share/man/man3/SSL_key_update.3ossl +++ /dev/null @@ -1,260 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_KEY_UPDATE 3ossl" -.TH SSL_KEY_UPDATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_key_update, -SSL_get_key_update_type, -SSL_renegotiate, -SSL_renegotiate_abbreviated, -SSL_renegotiate_pending -\&\- initiate and obtain information about updating connection keys -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_key_update(SSL *s, int updatetype); -\& int SSL_get_key_update_type(const SSL *s); -\& -\& int SSL_renegotiate(SSL *s); -\& int SSL_renegotiate_abbreviated(SSL *s); -\& int SSL_renegotiate_pending(const SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_key_update()\fR schedules an update of the keys for the current \s-1TLS\s0 connection. -If the \fBupdatetype\fR parameter is set to \fB\s-1SSL_KEY_UPDATE_NOT_REQUESTED\s0\fR then -the sending keys for this connection will be updated and the peer will be -informed of the change. If the \fBupdatetype\fR parameter is set to -\&\fB\s-1SSL_KEY_UPDATE_REQUESTED\s0\fR then the sending keys for this connection will be -updated and the peer will be informed of the change along with a request for the -peer to additionally update its sending keys. It is an error if \fBupdatetype\fR is -set to \fB\s-1SSL_KEY_UPDATE_NONE\s0\fR. -.PP -\&\fBSSL_key_update()\fR must only be called after the initial handshake has been -completed and TLSv1.3 or \s-1QUIC\s0 has been negotiated, at the same time, the -application needs to ensure that the writing of data has been completed. The key -update will not take place until the next time an \s-1IO\s0 operation such as -\&\fBSSL_read_ex()\fR or \fBSSL_write_ex()\fR takes place on the connection. Alternatively -\&\fBSSL_do_handshake()\fR can be called to force the update to take place immediately. -.PP -\&\fBSSL_get_key_update_type()\fR can be used to determine whether a key update -operation has been scheduled but not yet performed. The type of the pending key -update operation will be returned if there is one, or \s-1SSL_KEY_UPDATE_NONE\s0 -otherwise. -.PP -\&\fBSSL_renegotiate()\fR and \fBSSL_renegotiate_abbreviated()\fR should only be called for -connections that have negotiated TLSv1.2 or less. Calling them on any other -connection will result in an error. -.PP -When called from the client side, \fBSSL_renegotiate()\fR schedules a completely new -handshake over an existing \s-1SSL/TLS\s0 connection. The next time an \s-1IO\s0 operation -such as \fBSSL_read_ex()\fR or \fBSSL_write_ex()\fR takes place on the connection a check -will be performed to confirm that it is a suitable time to start a -renegotiation. If so, then it will be initiated immediately. OpenSSL will not -attempt to resume any session associated with the connection in the new -handshake. Note that some servers will respond to reneogitation attempts with -a \*(L"no_renegotiation\*(R" alert. An OpenSSL will immediately fail the connection in -this case. -.PP -When called from the client side, \fBSSL_renegotiate_abbreviated()\fR works in the -same was as \fBSSL_renegotiate()\fR except that OpenSSL will attempt to resume the -session associated with the current connection in the new handshake. -.PP -When called from the server side, \fBSSL_renegotiate()\fR and -\&\fBSSL_renegotiate_abbreviated()\fR behave identically. They both schedule a request -for a new handshake to be sent to the client. The next time an \s-1IO\s0 operation is -performed then the same checks as on the client side are performed and then, if -appropriate, the request is sent. The client may or may not respond with a new -handshake and it may or may not attempt to resume an existing session. If -a new handshake is started then this will be handled transparently by calling -any OpenSSL \s-1IO\s0 function. -.PP -If an OpenSSL client receives a renegotiation request from a server then again -this will be handled transparently through calling any OpenSSL \s-1IO\s0 function. For -a \s-1TLS\s0 connection the client will attempt to resume the current session in the -new handshake. For historical reasons, \s-1DTLS\s0 clients will not attempt to resume -the session in the new handshake. -.PP -The \fBSSL_renegotiate_pending()\fR function returns 1 if a renegotiation or -renegotiation request has been scheduled but not yet acted on, or 0 otherwise. -.SH "USAGE WITH QUIC" -.IX Header "USAGE WITH QUIC" -\&\fBSSL_key_update()\fR can also be used to perform a key update when using \s-1QUIC.\s0 The -function must be called on a \s-1QUIC\s0 connection \s-1SSL\s0 object. This is normally done -automatically when needed. Since a locally initiated \s-1QUIC\s0 key update always -causes a peer to also trigger a key update, passing -\&\fB\s-1SSL_KEY_UPDATE_NOT_REQUESTED\s0\fR as \fBupdatetype\fR has the same effect as passing -\&\fB\s-1SSL_KEY_UPDATE_REQUESTED\s0\fR. -.PP -The \s-1QUIC\s0 connection must have been fully established before a key update can be -performed, and other \s-1QUIC\s0 protocol rules govern how frequently \s-1QUIC\s0 key update -can be performed. \fBSSL_key_update()\fR will fail if these requirements are not met. -.PP -Because \s-1QUIC\s0 key updates are always handled immediately, -\&\fBSSL_get_key_update_type()\fR always returns \s-1SSL_KEY_UPDATE_NONE\s0 when called on a -\&\s-1QUIC\s0 connection \s-1SSL\s0 object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_key_update()\fR, \fBSSL_renegotiate()\fR and \fBSSL_renegotiate_abbreviated()\fR return 1 -on success or 0 on error. -.PP -\&\fBSSL_get_key_update_type()\fR returns the update type of the pending key update -operation or \s-1SSL_KEY_UPDATE_NONE\s0 if there is none. -.PP -\&\fBSSL_renegotiate_pending()\fR returns 1 if a renegotiation or renegotiation request -has been scheduled but not yet acted on, or 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_read_ex\fR\|(3), -\&\fBSSL_write_ex\fR\|(3), -\&\fBSSL_do_handshake\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_key_update()\fR and \fBSSL_get_key_update_type()\fR functions were added in -OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_library_init.3ossl b/openssl-install/share/man/man3/SSL_library_init.3ossl deleted file mode 100644 index 5ca5fe6c..00000000 --- a/openssl-install/share/man/man3/SSL_library_init.3ossl +++ /dev/null @@ -1,186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_LIBRARY_INIT 3ossl" -.TH SSL_LIBRARY_INIT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_library_init, OpenSSL_add_ssl_algorithms -\&\- initialize SSL library by registering algorithms -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_library_init(void); -\& -\& int OpenSSL_add_ssl_algorithms(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_library_init()\fR registers the available \s-1SSL/TLS\s0 ciphers and digests. -.PP -\&\fBOpenSSL_add_ssl_algorithms()\fR is a synonym for \fBSSL_library_init()\fR and is -implemented as a macro. -.SH "NOTES" -.IX Header "NOTES" -\&\fBSSL_library_init()\fR must be called before any other action takes place. -\&\fBSSL_library_init()\fR is not reentrant. -.SH "WARNINGS" -.IX Header "WARNINGS" -\&\fBSSL_library_init()\fR adds ciphers and digests used directly and indirectly by -\&\s-1SSL/TLS.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_library_init()\fR always returns \*(L"1\*(R", so it is safe to discard the return -value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBRAND_add\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_library_init()\fR and \fBOpenSSL_add_ssl_algorithms()\fR functions were -deprecated in OpenSSL 1.1.0 by \fBOPENSSL_init_ssl()\fR. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_load_client_CA_file.3ossl b/openssl-install/share/man/man3/SSL_load_client_CA_file.3ossl deleted file mode 100644 index 83312140..00000000 --- a/openssl-install/share/man/man3/SSL_load_client_CA_file.3ossl +++ /dev/null @@ -1,241 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_LOAD_CLIENT_CA_FILE 3ossl" -.TH SSL_LOAD_CLIENT_CA_FILE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_load_client_CA_file_ex, SSL_load_client_CA_file, -SSL_add_file_cert_subjects_to_stack, -SSL_add_dir_cert_subjects_to_stack, -SSL_add_store_cert_subjects_to_stack -\&\- load certificate names -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(X509_NAME) *SSL_load_client_CA_file_ex(const char *file, -\& OSSL_LIB_CTX *libctx, -\& const char *propq); -\& STACK_OF(X509_NAME) *SSL_load_client_CA_file(const char *file); -\& -\& int SSL_add_file_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack, -\& const char *file); -\& int SSL_add_dir_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack, -\& const char *dir); -\& int SSL_add_store_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack, -\& const char *store); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_load_client_CA_file_ex()\fR reads certificates from \fIfile\fR and returns -a \s-1STACK_OF\s0(X509_NAME) with the subject names found. The library context \fIlibctx\fR -and property query \fIpropq\fR are used when fetching algorithms from providers. -.PP -\&\fBSSL_load_client_CA_file()\fR is similar to \fBSSL_load_client_CA_file_ex()\fR -but uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBSSL_add_file_cert_subjects_to_stack()\fR reads certificates from \fIfile\fR, -and adds their subject name to the already existing \fIstack\fR. -.PP -\&\fBSSL_add_dir_cert_subjects_to_stack()\fR reads certificates from every -file in the directory \fIdir\fR, and adds their subject name to the -already existing \fIstack\fR. -.PP -\&\fBSSL_add_store_cert_subjects_to_stack()\fR loads certificates from the -\&\fIstore\fR \s-1URI,\s0 and adds their subject name to the already existing -\&\fIstack\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\fBSSL_load_client_CA_file()\fR reads a file of \s-1PEM\s0 formatted certificates and -extracts the X509_NAMES of the certificates found. While the name suggests -the specific usage as support function for -\&\fBSSL_CTX_set_client_CA_list\fR\|(3), -it is not limited to \s-1CA\s0 certificates. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur for \fBSSL_load_client_CA_file_ex()\fR, and -\&\fBSSL_load_client_CA_file()\fR: -.IP "\s-1NULL\s0" 4 -.IX Item "NULL" -The operation failed, check out the error stack for the reason. -.IP "Pointer to \s-1STACK_OF\s0(X509_NAME)" 4 -.IX Item "Pointer to STACK_OF(X509_NAME)" -Pointer to the subject names of the successfully read certificates. -.PP -The following return values can occur for \fBSSL_add_file_cert_subjects_to_stack()\fR, -\&\fBSSL_add_dir_cert_subjects_to_stack()\fR, and \fBSSL_add_store_cert_subjects_to_stack()\fR: -.IP "0 (Failure)" 4 -.IX Item "0 (Failure)" -The operation failed. -.IP "1 (Success)" 4 -.IX Item "1 (Success)" -The operation succeeded. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Load names of CAs from file and use it as a client \s-1CA\s0 list: -.PP -.Vb 2 -\& SSL_CTX *ctx; -\& STACK_OF(X509_NAME) *cert_names; -\& -\& ... -\& cert_names = SSL_load_client_CA_file("/path/to/CAfile.pem"); -\& if (cert_names != NULL) -\& SSL_CTX_set_client_CA_list(ctx, cert_names); -\& else -\& /* error */ -\& ... -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBossl_store\fR\|(7), -\&\fBSSL_CTX_set_client_CA_list\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_load_client_CA_file_ex()\fR and \fBSSL_add_store_cert_subjects_to_stack()\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_load_client_CA_file_ex.3ossl b/openssl-install/share/man/man3/SSL_load_client_CA_file_ex.3ossl deleted file mode 120000 index 24445e17..00000000 --- a/openssl-install/share/man/man3/SSL_load_client_CA_file_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_load_client_CA_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_load_error_strings.3ossl b/openssl-install/share/man/man3/SSL_load_error_strings.3ossl deleted file mode 120000 index 04b9ca0f..00000000 --- a/openssl-install/share/man/man3/SSL_load_error_strings.3ossl +++ /dev/null @@ -1 +0,0 @@ -ERR_load_crypto_strings.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_net_read_desired.3ossl b/openssl-install/share/man/man3/SSL_net_read_desired.3ossl deleted file mode 120000 index 3e5cf526..00000000 --- a/openssl-install/share/man/man3/SSL_net_read_desired.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_rpoll_descriptor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_net_write_desired.3ossl b/openssl-install/share/man/man3/SSL_net_write_desired.3ossl deleted file mode 120000 index 3e5cf526..00000000 --- a/openssl-install/share/man/man3/SSL_net_write_desired.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_rpoll_descriptor.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_new.3ossl b/openssl-install/share/man/man3/SSL_new.3ossl deleted file mode 100644 index 9aa32609..00000000 --- a/openssl-install/share/man/man3/SSL_new.3ossl +++ /dev/null @@ -1,255 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_NEW 3ossl" -.TH SSL_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_dup, SSL_new, SSL_up_ref \- create an SSL structure for a connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL *SSL_dup(SSL *s); -\& SSL *SSL_new(SSL_CTX *ctx); -\& int SSL_up_ref(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_new()\fR creates a new \fB\s-1SSL\s0\fR structure which is needed to hold the -data for a \s-1TLS/SSL\s0 connection. The new structure inherits the settings -of the underlying context \fBctx\fR: connection method, -options, verification settings, timeout settings. An \fB\s-1SSL\s0\fR structure is -reference counted. Creating an \fB\s-1SSL\s0\fR structure for the first time increments -the reference count. Freeing it (using SSL_free) decrements it. When the -reference count drops to zero, any memory or resources allocated to the \fB\s-1SSL\s0\fR -structure are freed. -.PP -\&\fBSSL_up_ref()\fR increments the reference count for an -existing \fB\s-1SSL\s0\fR structure. -.PP -The function \fBSSL_dup()\fR creates and returns a new \fB\s-1SSL\s0\fR structure from the same -\&\fB\s-1SSL_CTX\s0\fR that was used to create \fIs\fR. It additionally duplicates a subset of -the settings in \fIs\fR into the new \fB\s-1SSL\s0\fR object. -.PP -For \fBSSL_dup()\fR to work, the connection \s-1MUST\s0 be in its initial state and -\&\s-1MUST NOT\s0 have yet started the \s-1SSL\s0 handshake. For connections that are not in -their initial state \fBSSL_dup()\fR just increments an internal -reference count and returns the \fIsame\fR handle. It may be possible to -use \fBSSL_clear\fR\|(3) to recycle an \s-1SSL\s0 handle that is not in its initial -state for reuse, but this is best avoided. Instead, save and restore -the session, if desired, and construct a fresh handle for each connection. -.PP -The subset of settings in \fIs\fR that are duplicated are: -.IP "any session data if configured (including the session_id_context)" 4 -.IX Item "any session data if configured (including the session_id_context)" -.PD 0 -.IP "any tmp_dh settings set via \fBSSL_set_tmp_dh\fR\|(3), \fBSSL_set_tmp_dh_callback\fR\|(3), or \fBSSL_set_dh_auto\fR\|(3)" 4 -.IX Item "any tmp_dh settings set via SSL_set_tmp_dh, SSL_set_tmp_dh_callback, or SSL_set_dh_auto" -.IP "any configured certificates, private keys or certificate chains" 4 -.IX Item "any configured certificates, private keys or certificate chains" -.IP "any configured signature algorithms, or client signature algorithms" 4 -.IX Item "any configured signature algorithms, or client signature algorithms" -.IP "any \s-1DANE\s0 settings" 4 -.IX Item "any DANE settings" -.IP "any Options set via \fBSSL_set_options\fR\|(3)" 4 -.IX Item "any Options set via SSL_set_options" -.IP "any Mode set via \fBSSL_set_mode\fR\|(3)" 4 -.IX Item "any Mode set via SSL_set_mode" -.IP "any minimum or maximum protocol settings set via \fBSSL_set_min_proto_version\fR\|(3) or \fBSSL_set_max_proto_version\fR\|(3) (Note: Only from OpenSSL 1.1.1h and above)" 4 -.IX Item "any minimum or maximum protocol settings set via SSL_set_min_proto_version or SSL_set_max_proto_version (Note: Only from OpenSSL 1.1.1h and above)" -.IP "any verify mode, callback or depth set via \fBSSL_set_verify\fR\|(3) or \fBSSL_set_verify_depth\fR\|(3) or any configured X509 verification parameters" 4 -.IX Item "any verify mode, callback or depth set via SSL_set_verify or SSL_set_verify_depth or any configured X509 verification parameters" -.IP "any msg callback or info callback set via \fBSSL_set_msg_callback\fR\|(3) or \fBSSL_set_info_callback\fR\|(3)" 4 -.IX Item "any msg callback or info callback set via SSL_set_msg_callback or SSL_set_info_callback" -.IP "any default password callback set via \fBSSL_set_default_passwd_cb\fR\|(3)" 4 -.IX Item "any default password callback set via SSL_set_default_passwd_cb" -.IP "any session id generation callback set via \fBSSL_set_generate_session_id\fR\|(3)" 4 -.IX Item "any session id generation callback set via SSL_set_generate_session_id" -.IP "any configured Cipher List" 4 -.IX Item "any configured Cipher List" -.IP "initial accept (server) or connect (client) state" 4 -.IX Item "initial accept (server) or connect (client) state" -.IP "the max cert list value set via \fBSSL_set_max_cert_list\fR\|(3)" 4 -.IX Item "the max cert list value set via SSL_set_max_cert_list" -.IP "the read_ahead value set via \fBSSL_set_read_ahead\fR\|(3)" 4 -.IX Item "the read_ahead value set via SSL_set_read_ahead" -.IP "application specific data set via \fBSSL_set_ex_data\fR\|(3)" 4 -.IX Item "application specific data set via SSL_set_ex_data" -.IP "any \s-1CA\s0 list or client \s-1CA\s0 list set via \fBSSL_set0_CA_list\fR\|(3), \fBSSL_set0_client_CA_list()\fR or similar functions" 4 -.IX Item "any CA list or client CA list set via SSL_set0_CA_list, SSL_set0_client_CA_list() or similar functions" -.IP "any security level settings or callbacks" 4 -.IX Item "any security level settings or callbacks" -.IP "any configured serverinfo data" 4 -.IX Item "any configured serverinfo data" -.IP "any configured \s-1PSK\s0 identity hint" 4 -.IX Item "any configured PSK identity hint" -.IP "any configured custom extensions" 4 -.IX Item "any configured custom extensions" -.IP "any client certificate types configured via SSL_set1_client_certificate_types" 4 -.IX Item "any client certificate types configured via SSL_set1_client_certificate_types" -.PD -.PP -\&\fBSSL_dup()\fR is not supported on \s-1QUIC SSL\s0 objects and returns \s-1NULL\s0 if called on -such an object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "\s-1NULL\s0" 4 -.IX Item "NULL" -The creation of a new \s-1SSL\s0 structure failed. Check the error stack to -find out the reason. -.IP "Pointer to an \s-1SSL\s0 structure" 4 -.IX Item "Pointer to an SSL structure" -The return value points to an allocated \s-1SSL\s0 structure. -.Sp -\&\fBSSL_up_ref()\fR returns 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_free\fR\|(3), \fBSSL_clear\fR\|(3), -\&\fBSSL_CTX_set_options\fR\|(3), -\&\fBSSL_get_SSL_CTX\fR\|(3), -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_new_session_ticket.3ossl b/openssl-install/share/man/man3/SSL_new_session_ticket.3ossl deleted file mode 120000 index 619b5ce0..00000000 --- a/openssl-install/share/man/man3/SSL_new_session_ticket.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_num_tickets.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_new_stream.3ossl b/openssl-install/share/man/man3/SSL_new_stream.3ossl deleted file mode 100644 index 74c47e5b..00000000 --- a/openssl-install/share/man/man3/SSL_new_stream.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_NEW_STREAM 3ossl" -.TH SSL_NEW_STREAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_new_stream, SSL_STREAM_FLAG_UNI, SSL_STREAM_FLAG_NO_BLOCK, -SSL_STREAM_FLAG_ADVANCE \- create a new locally\-initiated QUIC stream -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_STREAM_FLAG_UNI (1U << 0) -\& #define SSL_STREAM_FLAG_NO_BLOCK (1U << 1) -\& #define SSL_STREAM_FLAG_ADVANCE (1U << 2) -\& SSL *SSL_new_stream(SSL *ssl, uint64_t flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBSSL_new_stream()\fR function, when passed a \s-1QUIC\s0 connection \s-1SSL\s0 object, creates -a new locally-initiated bidirectional or unidirectional \s-1QUIC\s0 stream and returns -the newly created \s-1QUIC\s0 stream \s-1SSL\s0 object. -.PP -If the \fB\s-1SSL_STREAM_FLAG_UNI\s0\fR flag is passed, a unidirectional stream is -created; else a bidirectional stream is created. -.PP -To retrieve the stream \s-1ID\s0 of the newly created stream, use -\&\fBSSL_get_stream_id\fR\|(3). -.PP -It is the caller's responsibility to free the \s-1QUIC\s0 stream \s-1SSL\s0 object using -\&\fBSSL_free\fR\|(3). The lifetime of the \s-1QUIC\s0 connection \s-1SSL\s0 object must exceed that -of the \s-1QUIC\s0 stream \s-1SSL\s0 object; in other words, the \s-1QUIC\s0 stream \s-1SSL\s0 object must -be freed first. -.PP -Once a stream has been created using \fBSSL_new_stream()\fR, it may be used in the -normal way using \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3). -.PP -This function can only be used to create stream objects for locally-initiated -streams. To accept incoming streams initiated by a peer, use -\&\fBSSL_accept_stream\fR\|(3). -.PP -Calling \fBSSL_new_stream()\fR if there is no default stream already present -inhibits the future creation of a default stream. See \fBopenssl\-quic\fR\|(7). -.PP -The creation of new streams is subject to flow control by the \s-1QUIC\s0 protocol. If -it is currently not possible to create a new locally initiated stream of the -specified type, a call to \fBSSL_new_stream()\fR will either block (if the connection -is configured in blocking mode) until a new stream can be created, or otherwise -return \s-1NULL.\s0 -.PP -This function operates in blocking mode if the \s-1QUIC\s0 connection \s-1SSL\s0 object is -configured in blocking mode (see \fBSSL_set_blocking_mode\fR\|(3)). It may also be -used in nonblocking mode on a connection configured in blocking mode by passing -the flag \fB\s-1SSL_STREAM_FLAG_NO_BLOCK\s0\fR. -.PP -The flag \fB\s-1SSL_STREAM_FLAG_ADVANCE\s0\fR may be used to create a \s-1QUIC\s0 stream \s-1SSL\s0 -object even if a new \s-1QUIC\s0 stream cannot yet be opened due to flow control. The -caller may begin to use the new stream and fill the write buffer of the stream -by calling \fBSSL_write\fR\|(3). However, no actual stream data (or \s-1QUIC\s0 frames -regarding the stream) will be sent until \s-1QUIC\s0 flow control allows it. Any queued -data will be sent as soon as a peer permits it. There is no guarantee the stream -will be eventually created; for example, the connection could fail, or a peer -might simply decide never to increase the number of allowed streams for the -remainder of the connection lifetime. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_new_stream()\fR returns a new stream object, or \s-1NULL\s0 on error. -.PP -This function fails if called on a \s-1QUIC\s0 stream \s-1SSL\s0 object or on a non-QUIC \s-1SSL\s0 -object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_accept_stream\fR\|(3), \fBSSL_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_new_stream()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_peek.3ossl b/openssl-install/share/man/man3/SSL_peek.3ossl deleted file mode 120000 index 9dc5a909..00000000 --- a/openssl-install/share/man/man3/SSL_peek.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_peek_ex.3ossl b/openssl-install/share/man/man3/SSL_peek_ex.3ossl deleted file mode 120000 index 9dc5a909..00000000 --- a/openssl-install/share/man/man3/SSL_peek_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_pending.3ossl b/openssl-install/share/man/man3/SSL_pending.3ossl deleted file mode 100644 index 19e6d31e..00000000 --- a/openssl-install/share/man/man3/SSL_pending.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_PENDING 3ossl" -.TH SSL_PENDING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_pending, SSL_has_pending \- check for readable bytes buffered in an -SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_pending(const SSL *ssl); -\& int SSL_has_pending(const SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Data is received in whole blocks known as records from the peer. A whole record -is processed (e.g. decrypted) in one go and is buffered by OpenSSL until it is -read by the application via a call to \fBSSL_read_ex\fR\|(3) or \fBSSL_read\fR\|(3). -.PP -\&\fBSSL_pending()\fR returns the number of bytes which have been processed, buffered -and are available inside \fBssl\fR for immediate read. -.PP -If the \fB\s-1SSL\s0\fR object's \fIread_ahead\fR flag is set (see -\&\fBSSL_CTX_set_read_ahead\fR\|(3)), additional protocol bytes (beyond the current -record) may have been read containing more \s-1TLS/SSL\s0 records. This also applies to -\&\s-1DTLS\s0 and pipelining (see \fBSSL_CTX_set_split_send_fragment\fR\|(3)). These -additional bytes will be buffered by OpenSSL but will remain unprocessed until -they are needed. As these bytes are still in an unprocessed state \fBSSL_pending()\fR -will ignore them. Therefore, it is possible for no more bytes to be readable from -the underlying \s-1BIO\s0 (because OpenSSL has already read them) and for \fBSSL_pending()\fR -to return 0, even though readable application data bytes are available (because -the data is in unprocessed buffered records). -.PP -\&\fBSSL_has_pending()\fR returns 1 if \fBs\fR has buffered data (whether processed or -unprocessed) and 0 otherwise. Note that it is possible for \fBSSL_has_pending()\fR to -return 1, and then a subsequent call to \fBSSL_read_ex()\fR or \fBSSL_read()\fR to return no -data because the unprocessed buffered data when processed yielded no application -data (for example this can happen during renegotiation). It is also possible in -this scenario for \fBSSL_has_pending()\fR to continue to return 1 even after an -\&\fBSSL_read_ex()\fR or \fBSSL_read()\fR call because the buffered and unprocessed data is -not yet processable (e.g. because OpenSSL has only received a partial record so -far). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_pending()\fR returns the number of buffered and processed application data -bytes that are pending and are available for immediate read. \fBSSL_has_pending()\fR -returns 1 if there is buffered record data in the \s-1SSL\s0 object and 0 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_read_ex\fR\|(3), \fBSSL_read\fR\|(3), \fBSSL_CTX_set_read_ahead\fR\|(3), -\&\fBSSL_CTX_set_split_send_fragment\fR\|(3), \fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_has_pending()\fR function was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_poll.3ossl b/openssl-install/share/man/man3/SSL_poll.3ossl deleted file mode 100644 index 8f6339f5..00000000 --- a/openssl-install/share/man/man3/SSL_poll.3ossl +++ /dev/null @@ -1,471 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_POLL 3ossl" -.TH SSL_POLL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_poll, -SSL_POLL_EVENT_NONE, -SSL_POLL_EVENT_F, -SSL_POLL_EVENT_EC, -SSL_POLL_EVENT_ECD, -SSL_POLL_EVENT_ER, -SSL_POLL_EVENT_EW, -SSL_POLL_EVENT_R, -SSL_POLL_EVENT_W, -SSL_POLL_EVENT_ISB, -SSL_POLL_EVENT_ISU, -SSL_POLL_EVENT_OSB, -SSL_POLL_EVENT_OSU, -SSL_POLL_EVENT_RW, -SSL_POLL_EVENT_RE, -SSL_POLL_EVENT_WE, -SSL_POLL_EVENT_RWE, -SSL_POLL_EVENT_E, -SSL_POLL_EVENT_IS, -SSL_POLL_EVENT_ISE, -SSL_POLL_EVENT_I, -SSL_POLL_EVENT_OS, -SSL_POLL_EVENT_OSE, -SSL_POLL_FLAG_NO_HANDLE_EVENTS -\&\- determine or await readiness conditions for one or more pollable objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_POLL_EVENT_NONE 0 -\& -\& #define SSL_POLL_EVENT_F /* F (Failure) */ -\& #define SSL_POLL_EVENT_EC /* EC (Exception on Conn) */ -\& #define SSL_POLL_EVENT_ECD /* ECD (Exception on Conn Drained) */ -\& #define SSL_POLL_EVENT_ER /* ER (Exception on Read) */ -\& #define SSL_POLL_EVENT_EW /* EW (Exception on Write) */ -\& #define SSL_POLL_EVENT_R /* R (Readable) */ -\& #define SSL_POLL_EVENT_W /* W (Writable) */ -\& #define SSL_POLL_EVENT_ISB /* ISB (Incoming Stream: Bidi) */ -\& #define SSL_POLL_EVENT_ISU /* ISU (Incoming Stream: Uni) */ -\& #define SSL_POLL_EVENT_OSB /* OSB (Outgoing Stream: Bidi) */ -\& #define SSL_POLL_EVENT_OSU /* OSU (Outgoing Stream: Uni) */ -\& -\& #define SSL_POLL_EVENT_RW /* R | W */ -\& #define SSL_POLL_EVENT_RE /* R | ER */ -\& #define SSL_POLL_EVENT_WE /* W | EW */ -\& #define SSL_POLL_EVENT_RWE /* RE | WE */ -\& #define SSL_POLL_EVENT_E /* EC | ER | EW */ -\& #define SSL_POLL_EVENT_IS /* ISB | ISU */ -\& #define SSL_POLL_EVENT_ISE /* IS | EC */ -\& #define SSL_POLL_EVENT_I /* IS */ -\& #define SSL_POLL_EVENT_OS /* OSB | OSU */ -\& #define SSL_POLL_EVENT_OSE /* OS | EC */ -\& -\& typedef struct ssl_poll_item_st { -\& BIO_POLL_DESCRIPTOR desc; -\& uint64_t events, revents; -\& } SSL_POLL_ITEM; -\& -\& #define SSL_POLL_FLAG_NO_HANDLE_EVENTS -\& -\& int SSL_poll(SSL_POLL_ITEM *items, -\& size_t num_items, -\& size_t stride, -\& const struct timeval *timeout, -\& uint64_t flags, -\& size_t *result_count); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_poll()\fR allows the readiness conditions of the resources represented by one -or more \s-1BIO_POLL_DESCRIPTOR\s0 structures to be determined. In particular, it can -be used to query for readiness conditions on \s-1QUIC\s0 connection \s-1SSL\s0 objects and -\&\s-1QUIC\s0 stream \s-1SSL\s0 objects in a single call. -.PP -A call to \fBSSL_poll()\fR specifies an array of \fB\s-1SSL_POLL_ITEM\s0\fR structures, each of -which designates a resource which is being polled for readiness, and a set of -event flags which indicate the specific readiness events which the caller is -interested in in relation to the specified resource. -.PP -The fields of \fB\s-1SSL_POLL_ITEM\s0\fR are as follows: -.IP "\fIdesc\fR" 4 -.IX Item "desc" -The resource being polled for readiness, as represented by a -\&\fB\s-1BIO_POLL_DESCRIPTOR\s0\fR. Currently, this must be a poll descriptor of type -\&\fB\s-1BIO_POLL_DESCRIPTOR_TYPE_SSL\s0\fR, representing a \s-1SSL\s0 object pointer, and the \s-1SSL\s0 -object must be a \s-1QUIC\s0 connection \s-1SSL\s0 object or \s-1QUIC\s0 stream \s-1SSL\s0 object. -.Sp -If a \fB\s-1SSL_POLL_ITEM\s0\fR has a poll descriptor type of -\&\fB\s-1BIO_POLL_DESCRIPTOR_TYPE_NONE\s0\fR, or the \s-1SSL\s0 object pointer is \s-1NULL,\s0 the -\&\fB\s-1SSL_POLL_ITEM\s0\fR array entry is ignored and \fIrevents\fR will be set to 0 on -return. -.IP "\fIevents\fR" 4 -.IX Item "events" -This is the set of zero or more events which the caller is interested in -learning about in relation to the resource described by \fIdesc\fR. It is a -collection of zero or more \fB\s-1SSL_POLL_EVENT\s0\fR flags. See \*(L"\s-1EVENT TYPES\*(R"\s0 for a -description of each of the event types. -.IP "\fIrevents\fR" 4 -.IX Item "revents" -After \fBSSL_poll()\fR returns, this is the set of zero or more events which are -actually applicable to the resource described by \fIdesc\fR. As for \fIevents\fR, -it is a collection of zero or more \fB\s-1SSL_POLL_EVENT\s0\fR flags. -.Sp -\&\fIrevents\fR need not be a subset of the events specified in \fIevents\fR, as some -event types are defined as always being enabled (non-maskable). See \*(L"\s-1EVENT -TYPES\*(R"\s0 for more information. -.PP -To use \fBSSL_poll()\fR, call it with an array of \fB\s-1SSL_POLL_ITEM\s0\fR structures. The -array need remain allocated only for the duration of the call. \fInum_items\fR must -be set to the number of entries in the array, and \fIstride\fR must be set to -\&\f(CW\*(C`sizeof(SSL_POLL_ITEM)\*(C'\fR. -.PP -The present implementation of \fBSSL_poll()\fR is a subset of the functionality which -will eventually be available. Only a nonblocking mode of operation is available -at this time, where \fBSSL_poll()\fR always returns immediately. As such, \fItimeout\fR -must point to a valid \fBstruct timeval\fR and that structure must be set to zero. -In future, other inputs to the \fItimeout\fR argument will result in a blocking -mode of operation, which is not currently supported. For more information, see -\&\*(L"\s-1LIMITATIONS\*(R"\s0. -.PP -The following flags are currently defined for the \fIflags\fR argument: -.IP "\fB\s-1SSL_POLL_FLAG_NO_HANDLE_EVENTS\s0\fR" 4 -.IX Item "SSL_POLL_FLAG_NO_HANDLE_EVENTS" -This flag indicates that internal state machine processing should not be -performed in an attempt to generate new readiness events. Only existing -readiness events will be reported. -.PP -The \fIresult_count\fR argument is optional. If it is non-NULL, it is used to -output the number of entries in the array which have nonzero \fIrevents\fR fields -when the call to \fBSSL_poll()\fR returns; see \*(L"\s-1RETURN VALUES\*(R"\s0 for details. -.SH "EVENT TYPES" -.IX Header "EVENT TYPES" -The \fBSSL_poll()\fR interface reports zero or more event types on a given resource, -represented by a bit mask. -.PP -All of the event types are level triggered and represent a readiness or -permanent exception condition; as such, after an event has been reported by -\&\fBSSL_poll()\fR for a resource, it will continue to be reported in future \fBSSL_poll()\fR -calls until the condition ceases to be in effect. A caller must mask the given -event type bit in future \fBSSL_poll()\fR calls if it does not wish to receive -repeated notifications and has not caused the underlying readiness condition -(for example, consuming all available data using \fBSSL_read_ex\fR\|(3) after -\&\fB\s-1SSL_POLL_EVENT_R\s0\fR is reported) to be deasserted. -.PP -Some event types do not make sense on a given kind of resource. In this case, -specifying that event type in \fIevents\fR is a no-op and will be ignored, and the -given event will never be reported in \fIrevents\fR. -.PP -Failure of the polling mechanism itself is considered distinct from an exception -condition on a resource which was successfully polled. See \fB\s-1SSL_POLL_EVENT_F\s0\fR -and \*(L"\s-1RETURN VALUES\*(R"\s0 for details. -.PP -In general, an application should always listen for the event types -corresponding to exception conditions if it is listening to the corresponding -non-exception event types (e.g. \fB\s-1SSL_POLL_EVENT_EC\s0\fR and \fB\s-1SSL_POLL_EVENT_ER\s0\fR -for \fB\s-1SSL_POLL_EVENT_R\s0\fR), as not doing so is unlikely to be a sound design. -.PP -Some event types are non-maskable and may be reported in \fIrevents\fR regardless -of whether they were requested in \fIevents\fR. -.PP -The following event types are supported: -.IP "\fB\s-1SSL_POLL_EVENT_F\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_F" -Polling failure. This event is raised when a resource could not be polled. It is -distinct from an exception condition reported on a resource which was -successfully polled and represents a failure of the polling process itself in -relation to a resource. This may mean that \fBSSL_poll()\fR does not support the kind -of resource specified. -.Sp -Where this event is raised on at least one item in \fIitems\fR, \fBSSL_poll()\fR will -return 0 and the \s-1ERR\s0 stack will contain information pertaining to the first item -in \fIitems\fR with \fB\s-1SSL_POLL_EVENT_F\s0\fR set. See \*(L"\s-1RETURN VALUES\*(R"\s0 for more -information. -.Sp -This event type may be raised even if it was not requested in \fIevents\fR; -specifying this event type in \fIevents\fR does nothing. -.IP "\fB\s-1SSL_POLL_EVENT_EC\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_EC" -Error at connection level. This event is raised when a connection has failed. -In particular, it is raised when a connection begins terminating. -.Sp -This event is never raised on objects which are not connections. -.IP "\fB\s-1SSL_POLL_EVENT_DCD\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_DCD" -Error at connection level (drained). This event is raised when a connection has -finished terminating, and has reached the terminated state. This event will -generally occur after an interval of time passes after the \fB\s-1SSL_POLL_EVENT_EC\s0\fR -event is raised on a connection. -.Sp -This event is never raised on objects which are not connections. -.IP "\fB\s-1SSL_POLL_EVENT_ER\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_ER" -Error in read direction. For \s-1QUIC,\s0 this is raised only in the event that a -stream has a read part and that read part has been reset by the peer (for -example, using a \fB\s-1RESET_STREAM\s0\fR frame). -.IP "\fB\s-1SSL_POLL_EVENT_EW\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_EW" -Error in write direction. For \s-1QUIC,\s0 this is raised only in the event that a -stream has a write part and that write part has been reset by the peer using a -\&\fB\s-1STOP_SENDING\s0\fR frame. -.IP "\fB\s-1SSL_POLL_EVENT_R\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_R" -Readable. This event is raised when a \s-1QUIC\s0 stream \s-1SSL\s0 object (or a \s-1QUIC\s0 -connection \s-1SSL\s0 object with a default stream attached) has application data -waiting to be read using \fBSSL_read_ex\fR\|(3), or a \s-1FIN\s0 event as represented by -\&\fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR waiting to be read. -.Sp -It is not raised in the event of the receiving part of the \s-1QUIC\s0 stream being -reset by the peer; see \fB\s-1SSL_POLL_EVENT_ER\s0\fR. -.IP "\fB\s-1SSL_POLL_EVENT_W\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_W" -Writable. This event is raised when a \s-1QUIC\s0 stream \s-1SSL\s0 object (or a \s-1QUIC\s0 -connection \s-1SSL\s0 object with a default stream attached) could accept more -application data using \fBSSL_write_ex\fR\|(3). -.Sp -This event is never raised by a receive-only stream. -.Sp -This event is never raised by a stream which has had its send part concluded -normally (as with \fBSSL_stream_conclude\fR\|(3)) or locally reset (as with -\&\fBSSL_stream_reset\fR\|(3)). -.Sp -This event does not guarantee that a subsequent call to \fBSSL_write_ex\fR\|(3) will -succeed. -.IP "\fB\s-1SSL_POLL_EVENT_ISB\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_ISB" -This event, which is only raised by a \s-1QUIC\s0 connection \s-1SSL\s0 object, is raised when -one or more incoming bidirectional streams are available to be accepted using -\&\fBSSL_accept_stream\fR\|(3). -.IP "\fB\s-1SSL_POLL_EVENT_ISU\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_ISU" -This event, which is only raised by a \s-1QUIC\s0 connection \s-1SSL\s0 object, is raised when -one or more incoming unidirectional streams are available to be accepted using -\&\fBSSL_accept_stream\fR\|(3). -.IP "\fB\s-1SSL_POLL_EVENT_OSB\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_OSB" -This event, which is only raised by a \s-1QUIC\s0 connection \s-1SSL\s0 object, is raised when -\&\s-1QUIC\s0 stream creation flow control currently permits at least one additional -bidirectional stream to be locally created. -.IP "\fB\s-1SSL_POLL_EVENT_OSU\s0\fR" 4 -.IX Item "SSL_POLL_EVENT_OSU" -This event, which is only raised by a \s-1QUIC\s0 connection \s-1SSL\s0 object, is raised when -\&\s-1QUIC\s0 stream creation flow control currently permits at least one additional -unidirectional stream to be locally created. -.SH "LIMITATIONS" -.IX Header "LIMITATIONS" -\&\fBSSL_poll()\fR as presently implemented has the following limitations: -.IP "\(bu" 4 -The implementation of \fBSSL_poll()\fR only supports nonblocking operation and -therefore requires the \fItimeout\fR argument be used to specify a zero timeout. -Calls to \fBSSL_poll()\fR which specify another value, or which pass \fItimeout\fR as -\&\s-1NULL,\s0 will fail. This does not allow waiting, but does allow multiple \s-1QUIC SSL\s0 -objects to be queried for their readiness state in a single call. -.Sp -Future releases will remove this limitation and support blocking \fBSSL_poll()\fR. -.IP "\(bu" 4 -Only \fB\s-1BIO_POLL_DESCRIPTOR\s0\fR structures with type -\&\fB\s-1BIO_POLL_DESCRIPTOR_TYPE_SSL\s0\fR, referencing \s-1QUIC\s0 connection \s-1SSL\s0 objects or \s-1QUIC\s0 -stream \s-1SSL\s0 objects, are supported. -.PP -These limitations will be revised in a future release of OpenSSL. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_poll()\fR returns 1 on success and 0 on failure. -.PP -Unless the \fIitems\fR pointer itself is invalid, \fBSSL_poll()\fR will always initialise -the \fIrevents\fR fields of all items in the input array upon returning, even if it -returns failure. -.PP -If \fIresult_count\fR is non-NULL, it is always written with the number of items in -the array with nonzero \fIrevents\fR fields, even if the \fBSSL_poll()\fR call returns -failure. -.PP -It is possible for \fIresult_count\fR to be written as 0 even if the \fBSSL_poll()\fR -call returns success, namely if no events were output but the polling process -was successful (e.g. in nonblocking usage) or timed out. -.PP -It is possible for \fIresult_count\fR to be written as a nonzero value if the -\&\fBSSL_poll()\fR call returns failure, for example due to \fB\s-1SSL_POLL_EVENT_F\s0\fR events, -or because some events were detected and output before encountering a failure -condition while processing a subsequent entry in the \fIitems\fR array. -.PP -If at least one \fB\s-1SSL_POLL_EVENT_F\s0\fR event is output, \fBSSL_poll()\fR is guaranteed -to return 0 and guaranteed to place at least one \s-1ERR\s0 on the error stack -describing the first \fB\s-1SSL_POLL_EVENT_F\s0\fR output. Detailed information on any -additional \fB\s-1SSL_POLL_EVENT_F\s0\fR events is not available. \fBSSL_poll()\fR may or may -not return more than one \fB\s-1SSL_POLL_EVENT_F\s0\fR event at once. -.PP -\&\*(L"Normal\*(R" events representing exceptional I/O conditions which do not -constitute a failure of the \fBSSL_poll()\fR mechanism itself are not considered -errors by \fBSSL_poll()\fR and are instead represented using their own event type; see -\&\*(L"\s-1EVENT TYPES\*(R"\s0 for details. -.PP -The caller can establish the meaning of the \fBSSL_poll()\fR return and output values -as follows: -.IP "\(bu" 4 -If \fBSSL_poll()\fR returns 1 and \fIresult_count\fR is zero, the operation timed out -before any resource was ready. -.IP "\(bu" 4 -If \fBSSL_poll()\fR returns 1 and \fIresult_count\fR is nonzero, that many events were -output. -.IP "\(bu" 4 -If \fBSSL_poll()\fR returns 0 and \fIresult_count\fR is zero, the caller has made a basic -usage error; check the \s-1ERR\s0 stack for details. -.IP "\(bu" 4 -If \fBSSL_poll()\fR returns 0 and \fIresult_count\fR is nonzero, inspect the \fIitems\fR -array for \fB\s-1SSL_POLL_ITEM\s0\fR structures with the \fB\s-1SSL_POLL_EVENT_F\s0\fR event type -raised in \fIrevents\fR. The entries added to the \s-1ERR\s0 stack (of which there is -guaranteed to be at least one) reflect the cause of the failure of the first -item in \fIitems\fR with \fB\s-1SSL_POLL_EVENT_F\s0\fR raised. Note that there may be events -other than \fI\s-1SSL_POLL_EVENT_F\s0\fR output for items which come before the first -item with \fB\s-1SSL_POLL_EVENT_F\s0\fR raised, and additional \fB\s-1SSL_POLL_EVENT_F\s0\fR -events may or may not have been output, both of which which will be reflected in -\&\fIresult_count\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_get_rpoll_descriptor\fR\|(3), \fBBIO_get_wpoll_descriptor\fR\|(3), -\&\fBSSL_get_rpoll_descriptor\fR\|(3), \fBSSL_get_wpoll_descriptor\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_poll()\fR was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_psk_client_cb_func.3ossl b/openssl-install/share/man/man3/SSL_psk_client_cb_func.3ossl deleted file mode 120000 index da6a3a7b..00000000 --- a/openssl-install/share/man/man3/SSL_psk_client_cb_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_psk_client_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_psk_find_session_cb_func.3ossl b/openssl-install/share/man/man3/SSL_psk_find_session_cb_func.3ossl deleted file mode 120000 index 205e7e3e..00000000 --- a/openssl-install/share/man/man3/SSL_psk_find_session_cb_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_psk_identity_hint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_psk_server_cb_func.3ossl b/openssl-install/share/man/man3/SSL_psk_server_cb_func.3ossl deleted file mode 120000 index 205e7e3e..00000000 --- a/openssl-install/share/man/man3/SSL_psk_server_cb_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_psk_identity_hint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_psk_use_session_cb_func.3ossl b/openssl-install/share/man/man3/SSL_psk_use_session_cb_func.3ossl deleted file mode 120000 index da6a3a7b..00000000 --- a/openssl-install/share/man/man3/SSL_psk_use_session_cb_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_psk_client_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_read.3ossl b/openssl-install/share/man/man3/SSL_read.3ossl deleted file mode 100644 index 703985fd..00000000 --- a/openssl-install/share/man/man3/SSL_read.3ossl +++ /dev/null @@ -1,284 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_READ 3ossl" -.TH SSL_READ 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_read_ex, SSL_read, SSL_peek_ex, SSL_peek -\&\- read bytes from a TLS/SSL connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_read_ex(SSL *ssl, void *buf, size_t num, size_t *readbytes); -\& int SSL_read(SSL *ssl, void *buf, int num); -\& -\& int SSL_peek_ex(SSL *ssl, void *buf, size_t num, size_t *readbytes); -\& int SSL_peek(SSL *ssl, void *buf, int num); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_read_ex()\fR and \fBSSL_read()\fR try to read \fBnum\fR bytes from the specified \fBssl\fR -into the buffer \fBbuf\fR. On success \fBSSL_read_ex()\fR will store the number of bytes -actually read in \fB*readbytes\fR. -.PP -\&\fBSSL_peek_ex()\fR and \fBSSL_peek()\fR are identical to \fBSSL_read_ex()\fR and \fBSSL_read()\fR -respectively except no bytes are actually removed from the underlying \s-1BIO\s0 during -the read, so that a subsequent call to \fBSSL_read_ex()\fR or \fBSSL_read()\fR will yield -at least the same bytes. -.SH "NOTES" -.IX Header "NOTES" -In the paragraphs below a \*(L"read function\*(R" is defined as one of \fBSSL_read_ex()\fR, -\&\fBSSL_read()\fR, \fBSSL_peek_ex()\fR or \fBSSL_peek()\fR. -.PP -If necessary, a read function will negotiate a \s-1TLS/SSL\s0 session, if not already -explicitly performed by \fBSSL_connect\fR\|(3) or \fBSSL_accept\fR\|(3). If the -peer requests a re-negotiation, it will be performed transparently during -the read function operation. The behaviour of the read functions depends on the -underlying \s-1BIO.\s0 -.PP -For the transparent negotiation to succeed, the \fBssl\fR must have been -initialized to client or server mode. This is being done by calling -\&\fBSSL_set_connect_state\fR\|(3) or \fBSSL_set_accept_state()\fR before the first -invocation of a read function. -.PP -The read functions work based on the \s-1SSL/TLS\s0 records. The data are received in -records (with a maximum record size of 16kB). Only when a record has been -completely received, can it be processed (decryption and check of integrity). -Therefore, data that was not retrieved at the last read call can still be -buffered inside the \s-1SSL\s0 layer and will be retrieved on the next read -call. If \fBnum\fR is higher than the number of bytes buffered then the read -functions will return with the bytes buffered. If no more bytes are in the -buffer, the read functions will trigger the processing of the next record. -Only when the record has been received and processed completely will the read -functions return reporting success. At most the contents of one record will -be returned. As the size of an \s-1SSL/TLS\s0 record may exceed the maximum packet size -of the underlying transport (e.g. \s-1TCP\s0), it may be necessary to read several -packets from the transport layer before the record is complete and the read call -can succeed. -.PP -If \fB\s-1SSL_MODE_AUTO_RETRY\s0\fR has been switched off and a non-application data -record has been processed, the read function can return and set the error to -\&\fB\s-1SSL_ERROR_WANT_READ\s0\fR. -In this case there might still be unprocessed data available in the \fB\s-1BIO\s0\fR. -If read ahead was set using \fBSSL_CTX_set_read_ahead\fR\|(3), there might also still -be unprocessed data available in the \fB\s-1SSL\s0\fR. -This behaviour can be controlled using the \fBSSL_CTX_set_mode\fR\|(3) call. -.PP -If the underlying \s-1BIO\s0 is \fBblocking\fR, a read function will only return once the -read operation has been finished or an error occurred, except when a -non-application data record has been processed and \fB\s-1SSL_MODE_AUTO_RETRY\s0\fR is -not set. -Note that if \fB\s-1SSL_MODE_AUTO_RETRY\s0\fR is set and only non-application data is -available the call will hang. -.PP -If the underlying \s-1BIO\s0 is \fBnonblocking\fR, a read function will also return when -the underlying \s-1BIO\s0 could not satisfy the needs of the function to continue the -operation. -In this case a call to \fBSSL_get_error\fR\|(3) with the -return value of the read function will yield \fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. -As at any time it's possible that non-application data needs to be sent, -a read function can also cause write operations. -The calling process then must repeat the call after taking appropriate action -to satisfy the needs of the read function. -The action depends on the underlying \s-1BIO.\s0 -When using a nonblocking socket, nothing is to be done, but \fBselect()\fR can be -used to check for the required condition. -When using a buffering \s-1BIO,\s0 like a \s-1BIO\s0 pair, data must be written into or -retrieved out of the \s-1BIO\s0 before being able to continue. -.PP -\&\fBSSL_pending\fR\|(3) can be used to find out whether there -are buffered bytes available for immediate retrieval. -In this case the read function can be called without blocking or actually -receiving new data from the underlying socket. -.PP -When used with a \s-1QUIC SSL\s0 object, calling an I/O function such as \fBSSL_read()\fR -allows internal network event processing to be performed. It is important that -this processing is performed regularly. If an application is not using thread -assisted mode, an application should ensure that an I/O function such as -\&\fBSSL_read()\fR is called regularly, or alternatively ensure that \fBSSL_handle_events()\fR -is called regularly. See \fBopenssl\-quic\fR\|(7) and \fBSSL_handle_events\fR\|(3) for more -information. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_read_ex()\fR and \fBSSL_peek_ex()\fR will return 1 for success or 0 for failure. -Success means that 1 or more application data bytes have been read from the \s-1SSL\s0 -connection. -Failure means that no bytes could be read from the \s-1SSL\s0 connection. -Failures can be retryable (e.g. we are waiting for more bytes to -be delivered by the network) or non-retryable (e.g. a fatal network error). -In the event of a failure call \fBSSL_get_error\fR\|(3) to find out the reason which -indicates whether the call is retryable or not. -.PP -For \fBSSL_read()\fR and \fBSSL_peek()\fR the following return values can occur: -.IP "> 0" 4 -.IX Item "> 0" -The read operation was successful. -The return value is the number of bytes actually read from the \s-1TLS/SSL\s0 -connection. -.IP "<= 0" 4 -.IX Item "<= 0" -The read operation was not successful, because either the connection was closed, -an error occurred or action must be taken by the calling process. -Call \fBSSL_get_error\fR\|(3) with the return value \fBret\fR to find out the reason. -.Sp -Old documentation indicated a difference between 0 and \-1, and that \-1 was -retryable. -You should instead call \fBSSL_get_error()\fR to find out if it's retryable. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_error\fR\|(3), \fBSSL_write_ex\fR\|(3), -\&\fBSSL_CTX_set_mode\fR\|(3), \fBSSL_CTX_new\fR\|(3), -\&\fBSSL_connect\fR\|(3), \fBSSL_accept\fR\|(3) -\&\fBSSL_set_connect_state\fR\|(3), -\&\fBSSL_pending\fR\|(3), -\&\fBSSL_shutdown\fR\|(3), \fBSSL_set_shutdown\fR\|(3), -\&\fBssl\fR\|(7), \fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_read_ex()\fR and \fBSSL_peek_ex()\fR functions were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_read_early_data.3ossl b/openssl-install/share/man/man3/SSL_read_early_data.3ossl deleted file mode 100644 index ceaf5193..00000000 --- a/openssl-install/share/man/man3/SSL_read_early_data.3ossl +++ /dev/null @@ -1,502 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_READ_EARLY_DATA 3ossl" -.TH SSL_READ_EARLY_DATA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_max_early_data, -SSL_CTX_set_max_early_data, -SSL_get_max_early_data, -SSL_CTX_get_max_early_data, -SSL_set_recv_max_early_data, -SSL_CTX_set_recv_max_early_data, -SSL_get_recv_max_early_data, -SSL_CTX_get_recv_max_early_data, -SSL_SESSION_get_max_early_data, -SSL_SESSION_set_max_early_data, -SSL_write_early_data, -SSL_read_early_data, -SSL_get_early_data_status, -SSL_allow_early_data_cb_fn, -SSL_CTX_set_allow_early_data_cb, -SSL_set_allow_early_data_cb -\&\- functions for sending and receiving early data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_CTX_set_max_early_data(SSL_CTX *ctx, uint32_t max_early_data); -\& uint32_t SSL_CTX_get_max_early_data(const SSL_CTX *ctx); -\& int SSL_set_max_early_data(SSL *s, uint32_t max_early_data); -\& uint32_t SSL_get_max_early_data(const SSL *s); -\& -\& int SSL_CTX_set_recv_max_early_data(SSL_CTX *ctx, uint32_t recv_max_early_data); -\& uint32_t SSL_CTX_get_recv_max_early_data(const SSL_CTX *ctx); -\& int SSL_set_recv_max_early_data(SSL *s, uint32_t recv_max_early_data); -\& uint32_t SSL_get_recv_max_early_data(const SSL *s); -\& -\& uint32_t SSL_SESSION_get_max_early_data(const SSL_SESSION *s); -\& int SSL_SESSION_set_max_early_data(SSL_SESSION *s, uint32_t max_early_data); -\& -\& int SSL_write_early_data(SSL *s, const void *buf, size_t num, size_t *written); -\& -\& int SSL_read_early_data(SSL *s, void *buf, size_t num, size_t *readbytes); -\& -\& int SSL_get_early_data_status(const SSL *s); -\& -\& -\& typedef int (*SSL_allow_early_data_cb_fn)(SSL *s, void *arg); -\& -\& void SSL_CTX_set_allow_early_data_cb(SSL_CTX *ctx, -\& SSL_allow_early_data_cb_fn cb, -\& void *arg); -\& void SSL_set_allow_early_data_cb(SSL *s, -\& SSL_allow_early_data_cb_fn cb, -\& void *arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are used to send and receive early data where TLSv1.3 has been -negotiated. Early data can be sent by the client immediately after its initial -ClientHello without having to wait for the server to complete the handshake. -Early data can be sent if a session has previously been established with the -server or when establishing a new session using an out-of-band \s-1PSK,\s0 and only -when the server is known to support it. Additionally these functions can be used -to send data from the server to the client when the client has not yet completed -the authentication stage of the handshake. -.PP -Early data has weaker security properties than other data sent over an \s-1SSL/TLS\s0 -connection. In particular the data does not have forward secrecy. There are also -additional considerations around replay attacks (see \*(L"\s-1REPLAY PROTECTION\*(R"\s0 -below). For these reasons extreme care should be exercised when using early -data. For specific details, consult the \s-1TLS 1.3\s0 specification. -.PP -When a server receives early data it may opt to immediately respond by sending -application data back to the client. Data sent by the server at this stage is -done before the full handshake has been completed. Specifically the client's -authentication messages have not yet been received, i.e. the client is -unauthenticated at this point and care should be taken when using this -capability. -.PP -A server or client can determine whether the full handshake has been completed -or not by calling \fBSSL_is_init_finished\fR\|(3). -.PP -On the client side, the function \fBSSL_SESSION_get_max_early_data()\fR can be used to -determine if a session established with a server can be used to send early data. -If the session cannot be used then this function will return 0. Otherwise it -will return the maximum number of early data bytes that can be sent. -.PP -The function \fBSSL_SESSION_set_max_early_data()\fR sets the maximum number of early -data bytes that can be sent for a session. This would typically be used when -creating a \s-1PSK\s0 session file (see \fBSSL_CTX_set_psk_use_session_callback\fR\|(3)). If -using a ticket based \s-1PSK\s0 then this is set automatically to the value provided by -the server. -.PP -A client uses the function \fBSSL_write_early_data()\fR to send early data. This -function is similar to the \fBSSL_write_ex\fR\|(3) function, but with the following -differences. See \fBSSL_write_ex\fR\|(3) for information on how to write bytes to -the underlying connection, and how to handle any errors that may arise. This -page describes the differences between \fBSSL_write_early_data()\fR and -\&\fBSSL_write_ex\fR\|(3). -.PP -When called by a client, \fBSSL_write_early_data()\fR must be the first \s-1IO\s0 function -called on a new connection, i.e. it must occur before any calls to -\&\fBSSL_write_ex\fR\|(3), \fBSSL_read_ex\fR\|(3), \fBSSL_connect\fR\|(3), \fBSSL_do_handshake\fR\|(3) -or other similar functions. It may be called multiple times to stream data to -the server, but the total number of bytes written must not exceed the value -returned from \fBSSL_SESSION_get_max_early_data()\fR. Once the initial -\&\fBSSL_write_early_data()\fR call has completed successfully the client may interleave -calls to \fBSSL_read_ex\fR\|(3) and \fBSSL_read\fR\|(3) with calls to -\&\fBSSL_write_early_data()\fR as required. -.PP -If \fBSSL_write_early_data()\fR fails you should call \fBSSL_get_error\fR\|(3) to determine -the correct course of action, as for \fBSSL_write_ex\fR\|(3). -.PP -When the client no longer wishes to send any more early data then it should -complete the handshake by calling a function such as \fBSSL_connect\fR\|(3) or -\&\fBSSL_do_handshake\fR\|(3). Alternatively you can call a standard write function -such as \fBSSL_write_ex\fR\|(3), which will transparently complete the connection and -write the requested data. -.PP -A server may choose to ignore early data that has been sent to it. Once the -connection has been completed you can determine whether the server accepted or -rejected the early data by calling \fBSSL_get_early_data_status()\fR. This will return -\&\s-1SSL_EARLY_DATA_ACCEPTED\s0 if the data was accepted, \s-1SSL_EARLY_DATA_REJECTED\s0 if it -was rejected or \s-1SSL_EARLY_DATA_NOT_SENT\s0 if no early data was sent. This function -may be called by either the client or the server. -.PP -A server uses the \fBSSL_read_early_data()\fR function to receive early data on a -connection for which early data has been enabled using -\&\fBSSL_CTX_set_max_early_data()\fR or \fBSSL_set_max_early_data()\fR. As for -\&\fBSSL_write_early_data()\fR, this must be the first \s-1IO\s0 function -called on a connection, i.e. it must occur before any calls to -\&\fBSSL_write_ex\fR\|(3), \fBSSL_read_ex\fR\|(3), \fBSSL_accept\fR\|(3), \fBSSL_do_handshake\fR\|(3), -or other similar functions. -.PP -\&\fBSSL_read_early_data()\fR is similar to \fBSSL_read_ex\fR\|(3) with the following -differences. Refer to \fBSSL_read_ex\fR\|(3) for full details. -.PP -\&\fBSSL_read_early_data()\fR may return 3 possible values: -.IP "\s-1SSL_READ_EARLY_DATA_ERROR\s0" 4 -.IX Item "SSL_READ_EARLY_DATA_ERROR" -This indicates an \s-1IO\s0 or some other error occurred. This should be treated in the -same way as a 0 return value from \fBSSL_read_ex\fR\|(3). -.IP "\s-1SSL_READ_EARLY_DATA_SUCCESS\s0" 4 -.IX Item "SSL_READ_EARLY_DATA_SUCCESS" -This indicates that early data was successfully read. This should be treated in -the same way as a 1 return value from \fBSSL_read_ex\fR\|(3). You should continue to -call \fBSSL_read_early_data()\fR to read more data. -.IP "\s-1SSL_READ_EARLY_DATA_FINISH\s0" 4 -.IX Item "SSL_READ_EARLY_DATA_FINISH" -This indicates that no more early data can be read. It may be returned on the -first call to \fBSSL_read_early_data()\fR if the client has not sent any early data, -or if the early data was rejected. -.PP -Once the initial \fBSSL_read_early_data()\fR call has completed successfully (i.e. it -has returned \s-1SSL_READ_EARLY_DATA_SUCCESS\s0 or \s-1SSL_READ_EARLY_DATA_FINISH\s0) then the -server may choose to write data immediately to the unauthenticated client using -\&\fBSSL_write_early_data()\fR. If \fBSSL_read_early_data()\fR returned -\&\s-1SSL_READ_EARLY_DATA_FINISH\s0 then in some situations (e.g. if the client only -supports TLSv1.2) the handshake may have already been completed and calls -to \fBSSL_write_early_data()\fR are not allowed. Call \fBSSL_is_init_finished\fR\|(3) to -determine whether the handshake has completed or not. If the handshake is still -in progress then the server may interleave calls to \fBSSL_write_early_data()\fR with -calls to \fBSSL_read_early_data()\fR as required. -.PP -Servers must not call \fBSSL_read_ex\fR\|(3), \fBSSL_read\fR\|(3), \fBSSL_write_ex\fR\|(3) or -\&\fBSSL_write\fR\|(3) until \fBSSL_read_early_data()\fR has returned with -\&\s-1SSL_READ_EARLY_DATA_FINISH.\s0 Once it has done so the connection to the client -still needs to be completed. Complete the connection by calling a function such -as \fBSSL_accept\fR\|(3) or \fBSSL_do_handshake\fR\|(3). Alternatively you can call a -standard read function such as \fBSSL_read_ex\fR\|(3), which will transparently -complete the connection and read the requested data. Note that it is an error to -attempt to complete the connection before \fBSSL_read_early_data()\fR has returned -\&\s-1SSL_READ_EARLY_DATA_FINISH.\s0 -.PP -Only servers may call \fBSSL_read_early_data()\fR. -.PP -Calls to \fBSSL_read_early_data()\fR may, in certain circumstances, complete the -connection immediately without further need to call a function such as -\&\fBSSL_accept\fR\|(3). This can happen if the client is using a protocol version less -than TLSv1.3. Applications can test for this by calling -\&\fBSSL_is_init_finished\fR\|(3). Alternatively, applications may choose to call -\&\fBSSL_accept\fR\|(3) anyway. Such a call will successfully return immediately with no -further action taken. -.PP -When a session is created between a server and a client the server will specify -the maximum amount of any early data that it will accept on any future -connection attempt. By default the server does not accept early data; a -server may indicate support for early data by calling -\&\fBSSL_CTX_set_max_early_data()\fR or -\&\fBSSL_set_max_early_data()\fR to set it for the whole \s-1SSL_CTX\s0 or an individual \s-1SSL\s0 -object respectively. The \fBmax_early_data\fR parameter specifies the maximum -amount of early data in bytes that is permitted to be sent on a single -connection. Similarly the \fBSSL_CTX_get_max_early_data()\fR and -\&\fBSSL_get_max_early_data()\fR functions can be used to obtain the current maximum -early data settings for the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects respectively. Generally a -server application will either use both of \fBSSL_read_early_data()\fR and -\&\fBSSL_CTX_set_max_early_data()\fR (or \fBSSL_set_max_early_data()\fR), or neither of them, -since there is no practical benefit from using only one of them. If the maximum -early data setting for a server is nonzero then replay protection is -automatically enabled (see \*(L"\s-1REPLAY PROTECTION\*(R"\s0 below). -.PP -If the server rejects the early data sent by a client then it will skip over -the data that is sent. The maximum amount of received early data that is skipped -is controlled by the recv_max_early_data setting. If a client sends more than -this then the connection will abort. This value can be set by calling -\&\fBSSL_CTX_set_recv_max_early_data()\fR or \fBSSL_set_recv_max_early_data()\fR. The current -value for this setting can be obtained by calling -\&\fBSSL_CTX_get_recv_max_early_data()\fR or \fBSSL_get_recv_max_early_data()\fR. The default -value for this setting is 16,384 bytes. -.PP -The recv_max_early_data value also has an impact on early data that is accepted. -The amount of data that is accepted will always be the lower of the -max_early_data for the session and the recv_max_early_data setting for the -server. If a client sends more data than this then the connection will abort. -.PP -The configured value for max_early_data on a server may change over time as -required. However, clients may have tickets containing the previously configured -max_early_data value. The recv_max_early_data should always be equal to or -higher than any recently configured max_early_data value in order to avoid -aborted connections. The recv_max_early_data should never be set to less than -the current configured max_early_data value. -.PP -Some server applications may wish to have more control over whether early data -is accepted or not, for example to mitigate replay risks (see \*(L"\s-1REPLAY PROTECTION\*(R"\s0 -below) or to decline early_data when the server is heavily loaded. The functions -\&\fBSSL_CTX_set_allow_early_data_cb()\fR and \fBSSL_set_allow_early_data_cb()\fR set a -callback which is called at a point in the handshake immediately before a -decision is made to accept or reject early data. The callback is provided with a -pointer to the user data argument that was provided when the callback was first -set. Returning 1 from the callback will allow early data and returning 0 will -reject it. Note that the OpenSSL library may reject early data for other reasons -in which case this callback will not get called. Notably, the built-in replay -protection feature will still be used even if a callback is present unless it -has been explicitly disabled using the \s-1SSL_OP_NO_ANTI_REPLAY\s0 option. See -\&\*(L"\s-1REPLAY PROTECTION\*(R"\s0 below. -.PP -These functions cannot currently be used with \s-1QUIC SSL\s0 objects. -\&\fBSSL_set_max_early_data()\fR, \fBSSL_set_recv_max_early_data()\fR, \fBSSL_write_early_data()\fR, -\&\fBSSL_read_early_data()\fR, \fBSSL_get_early_data_status()\fR and -\&\fBSSL_set_allow_early_data_cb()\fR fail if called on a \s-1QUIC SSL\s0 object. -.SH "NOTES" -.IX Header "NOTES" -The whole purpose of early data is to enable a client to start sending data to -the server before a full round trip of network traffic has occurred. Application -developers should ensure they consider optimisation of the underlying \s-1TCP\s0 socket -to obtain a performant solution. For example Nagle's algorithm is commonly used -by operating systems in an attempt to avoid lots of small \s-1TCP\s0 packets. In many -scenarios this is beneficial for performance, but it does not work well with the -early data solution as implemented in OpenSSL. In Nagle's algorithm the \s-1OS\s0 will -buffer outgoing \s-1TCP\s0 data if a \s-1TCP\s0 packet has already been sent which we have not -yet received an \s-1ACK\s0 for from the peer. The buffered data will only be -transmitted if enough data to fill an entire \s-1TCP\s0 packet is accumulated, or if -the \s-1ACK\s0 is received from the peer. The initial ClientHello will be sent in the -first \s-1TCP\s0 packet along with any data from the first call to -\&\fBSSL_write_early_data()\fR. If the amount of data written will exceed the size of a -single \s-1TCP\s0 packet, or if there are more calls to \fBSSL_write_early_data()\fR then -that additional data will be sent in subsequent \s-1TCP\s0 packets which will be -buffered by the \s-1OS\s0 and not sent until an \s-1ACK\s0 is received for the first packet -containing the ClientHello. This means the early data is not actually -sent until a complete round trip with the server has occurred which defeats the -objective of early data. -.PP -In many operating systems the \s-1TCP_NODELAY\s0 socket option is available to disable -Nagle's algorithm. If an application opts to disable Nagle's algorithm -consideration should be given to turning it back on again after the handshake is -complete if appropriate. -.PP -In rare circumstances, it may be possible for a client to have a session that -reports a max early data value greater than 0, but where the server does not -support this. For example, this can occur if a server has had its configuration -changed to accept a lower max early data value such as by calling -\&\fBSSL_CTX_set_recv_max_early_data()\fR. Another example is if a server used to -support TLSv1.3 but was later downgraded to TLSv1.2. Sending early data to such -a server will cause the connection to abort. Clients that encounter an aborted -connection while sending early data may want to retry the connection without -sending early data as this does not happen automatically. A client will have to -establish a new transport layer connection to the server and attempt the \s-1SSL/TLS\s0 -connection again but without sending early data. Note that it is inadvisable to -retry with a lower maximum protocol version. -.SH "REPLAY PROTECTION" -.IX Header "REPLAY PROTECTION" -When early data is in use the \s-1TLS\s0 protocol provides no security guarantees that -the same early data was not replayed across multiple connections. As a -mitigation for this issue OpenSSL automatically enables replay protection if the -server is configured with a nonzero max early data value. With replay -protection enabled sessions are forced to be single use only. If a client -attempts to reuse a session ticket more than once, then the second and -subsequent attempts will fall back to a full handshake (and any early data that -was submitted will be ignored). Note that single use tickets are enforced even -if a client does not send any early data. -.PP -The replay protection mechanism relies on the internal OpenSSL server session -cache (see \fBSSL_CTX_set_session_cache_mode\fR\|(3)). When replay protection is -being used the server will operate as if the \s-1SSL_OP_NO_TICKET\s0 option had been -selected (see \fBSSL_CTX_set_options\fR\|(3)). Sessions will be added to the cache -whenever a session ticket is issued. When a client attempts to resume the -session, OpenSSL will check for its presence in the internal cache. If it exists -then the resumption is allowed and the session is removed from the cache. If it -does not exist then the resumption is not allowed and a full handshake will -occur. -.PP -Note that some applications may maintain an external cache of sessions (see -\&\fBSSL_CTX_sess_set_new_cb\fR\|(3) and similar functions). It is the application's -responsibility to ensure that any sessions in the external cache are also -populated in the internal cache and that once removed from the internal cache -they are similarly removed from the external cache. Failing to do this could -result in an application becoming vulnerable to replay attacks. Note that -OpenSSL will lock the internal cache while a session is removed but that lock is -not held when the remove session callback (see \fBSSL_CTX_sess_set_remove_cb\fR\|(3)) -is called. This could result in a small amount of time where the session has -been removed from the internal cache but is still available in the external -cache. Applications should be designed with this in mind in order to minimise -the possibility of replay attacks. -.PP -The OpenSSL replay protection does not apply to external Pre Shared Keys (PSKs) -(e.g. see \fBSSL_CTX_set_psk_find_session_callback\fR\|(3)). Therefore, extreme caution -should be applied when combining external PSKs with early data. -.PP -Some applications may mitigate the replay risks in other ways. For those -applications it is possible to turn off the built-in replay protection feature -using the \fB\s-1SSL_OP_NO_ANTI_REPLAY\s0\fR option. See \fBSSL_CTX_set_options\fR\|(3) for -details. Applications can also set a callback to make decisions about accepting -early data or not. See \fBSSL_CTX_set_allow_early_data_cb()\fR above for details. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_write_early_data()\fR returns 1 for success or 0 for failure. In the event of a -failure call \fBSSL_get_error\fR\|(3) to determine the correct course of action. -.PP -\&\fBSSL_read_early_data()\fR returns \s-1SSL_READ_EARLY_DATA_ERROR\s0 for failure, -\&\s-1SSL_READ_EARLY_DATA_SUCCESS\s0 for success with more data to read and -\&\s-1SSL_READ_EARLY_DATA_FINISH\s0 for success with no more to data be read. In the -event of a failure call \fBSSL_get_error\fR\|(3) to determine the correct course of -action. -.PP -\&\fBSSL_get_max_early_data()\fR, \fBSSL_CTX_get_max_early_data()\fR and -\&\fBSSL_SESSION_get_max_early_data()\fR return the maximum number of early data bytes -that may be sent. -.PP -\&\fBSSL_set_max_early_data()\fR, \fBSSL_CTX_set_max_early_data()\fR and -\&\fBSSL_SESSION_set_max_early_data()\fR return 1 for success or 0 for failure. -.PP -\&\fBSSL_get_early_data_status()\fR returns \s-1SSL_EARLY_DATA_ACCEPTED\s0 if early data was -accepted by the server, \s-1SSL_EARLY_DATA_REJECTED\s0 if early data was rejected by -the server, or \s-1SSL_EARLY_DATA_NOT_SENT\s0 if no early data was sent. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_error\fR\|(3), -\&\fBSSL_write_ex\fR\|(3), -\&\fBSSL_read_ex\fR\|(3), -\&\fBSSL_connect\fR\|(3), -\&\fBSSL_accept\fR\|(3), -\&\fBSSL_do_handshake\fR\|(3), -\&\fBSSL_CTX_set_psk_use_session_callback\fR\|(3), -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -All of the functions described above were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_read_ex.3ossl b/openssl-install/share/man/man3/SSL_read_ex.3ossl deleted file mode 120000 index 9dc5a909..00000000 --- a/openssl-install/share/man/man3/SSL_read_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_renegotiate.3ossl b/openssl-install/share/man/man3/SSL_renegotiate.3ossl deleted file mode 120000 index af21c78b..00000000 --- a/openssl-install/share/man/man3/SSL_renegotiate.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_key_update.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_renegotiate_abbreviated.3ossl b/openssl-install/share/man/man3/SSL_renegotiate_abbreviated.3ossl deleted file mode 120000 index af21c78b..00000000 --- a/openssl-install/share/man/man3/SSL_renegotiate_abbreviated.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_key_update.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_renegotiate_pending.3ossl b/openssl-install/share/man/man3/SSL_renegotiate_pending.3ossl deleted file mode 120000 index af21c78b..00000000 --- a/openssl-install/share/man/man3/SSL_renegotiate_pending.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_key_update.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_rstate_string.3ossl b/openssl-install/share/man/man3/SSL_rstate_string.3ossl deleted file mode 100644 index 9e140f3e..00000000 --- a/openssl-install/share/man/man3/SSL_rstate_string.3ossl +++ /dev/null @@ -1,194 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_RSTATE_STRING 3ossl" -.TH SSL_RSTATE_STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_rstate_string, SSL_rstate_string_long \- get textual description of state of an SSL object during read operation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_rstate_string(SSL *ssl); -\& const char *SSL_rstate_string_long(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_rstate_string()\fR returns a 2 letter string indicating the current read state -of the \s-1SSL\s0 object \fBssl\fR. -.PP -\&\fBSSL_rstate_string_long()\fR returns a string indicating the current read state of -the \s-1SSL\s0 object \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -When performing a read operation, the \s-1SSL/TLS\s0 engine must parse the record, -consisting of header and body. When working in a blocking environment, -SSL_rstate_string[_long]() should always return \*(L"\s-1RD\*(R"/\s0\*(L"read done\*(R". -.PP -This function should only seldom be needed in applications. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_rstate_string()\fR and \fBSSL_rstate_string_long()\fR can return the following -values: -.ie n .IP """\s-1RH""/\s0""read header""" 4 -.el .IP "``\s-1RH''/\s0``read header''" 4 -.IX Item "RH/read header" -The header of the record is being evaluated. -.ie n .IP """\s-1RB""/\s0""read body""" 4 -.el .IP "``\s-1RB''/\s0``read body''" 4 -.IX Item "RB/read body" -The body of the record is being evaluated. -.ie n .IP """unknown""/""unknown""" 4 -.el .IP "``unknown''/``unknown''" 4 -.IX Item "unknown/unknown" -The read state is unknown. This should never happen. -.PP -When used with \s-1QUIC SSL\s0 objects, these functions always return \*(L"\s-1RH\*(R"/\s0\*(L"read -header\*(R" in normal conditions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_rstate_string_long.3ossl b/openssl-install/share/man/man3/SSL_rstate_string_long.3ossl deleted file mode 120000 index 831aafbe..00000000 --- a/openssl-install/share/man/man3/SSL_rstate_string_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_rstate_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_select_current_cert.3ossl b/openssl-install/share/man/man3/SSL_select_current_cert.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_select_current_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_select_next_proto.3ossl b/openssl-install/share/man/man3/SSL_select_next_proto.3ossl deleted file mode 120000 index fa1385af..00000000 --- a/openssl-install/share/man/man3/SSL_select_next_proto.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_alpn_select_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_sendfile.3ossl b/openssl-install/share/man/man3/SSL_sendfile.3ossl deleted file mode 120000 index c5148886..00000000 --- a/openssl-install/share/man/man3/SSL_sendfile.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_write.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_session_reused.3ossl b/openssl-install/share/man/man3/SSL_session_reused.3ossl deleted file mode 100644 index f0cf40e0..00000000 --- a/openssl-install/share/man/man3/SSL_session_reused.3ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SESSION_REUSED 3ossl" -.TH SSL_SESSION_REUSED 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_session_reused \- query whether a reused session was negotiated during handshake -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_session_reused(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Query, whether a reused session was negotiated during the handshake. -.SH "NOTES" -.IX Header "NOTES" -During the negotiation, a client can propose to reuse a session. The server -then looks up the session in its cache. If both client and server agree -on the session, it will be reused and a flag is being set that can be -queried by the application. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0" 4 -A new session was negotiated. -.IP "1" 4 -.IX Item "1" -A session was reused. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_set_session\fR\|(3), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set0_CA_list.3ossl b/openssl-install/share/man/man3/SSL_set0_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_set0_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set0_chain.3ossl b/openssl-install/share/man/man3/SSL_set0_chain.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_set0_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set0_chain_cert_store.3ossl b/openssl-install/share/man/man3/SSL_set0_chain_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_set0_chain_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set0_rbio.3ossl b/openssl-install/share/man/man3/SSL_set0_rbio.3ossl deleted file mode 120000 index 6628dde0..00000000 --- a/openssl-install/share/man/man3/SSL_set0_rbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set0_security_ex_data.3ossl b/openssl-install/share/man/man3/SSL_set0_security_ex_data.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_set0_security_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set0_tmp_dh_pkey.3ossl b/openssl-install/share/man/man3/SSL_set0_tmp_dh_pkey.3ossl deleted file mode 120000 index 838d6609..00000000 --- a/openssl-install/share/man/man3/SSL_set0_tmp_dh_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_dh_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set0_verify_cert_store.3ossl b/openssl-install/share/man/man3/SSL_set0_verify_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_set0_verify_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set0_wbio.3ossl b/openssl-install/share/man/man3/SSL_set0_wbio.3ossl deleted file mode 120000 index 6628dde0..00000000 --- a/openssl-install/share/man/man3/SSL_set0_wbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_cert_comp_preference.3ossl b/openssl-install/share/man/man3/SSL_set1_cert_comp_preference.3ossl deleted file mode 120000 index 7aaf058c..00000000 --- a/openssl-install/share/man/man3/SSL_set1_cert_comp_preference.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_cert_comp_preference.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_chain.3ossl b/openssl-install/share/man/man3/SSL_set1_chain.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_set1_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_chain_cert_store.3ossl b/openssl-install/share/man/man3/SSL_set1_chain_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_set1_chain_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_client_cert_type.3ossl b/openssl-install/share/man/man3/SSL_set1_client_cert_type.3ossl deleted file mode 120000 index 44c96a96..00000000 --- a/openssl-install/share/man/man3/SSL_set1_client_cert_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_server_cert_type.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_client_sigalgs.3ossl b/openssl-install/share/man/man3/SSL_set1_client_sigalgs.3ossl deleted file mode 120000 index f594d7af..00000000 --- a/openssl-install/share/man/man3/SSL_set1_client_sigalgs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_client_sigalgs_list.3ossl b/openssl-install/share/man/man3/SSL_set1_client_sigalgs_list.3ossl deleted file mode 120000 index f594d7af..00000000 --- a/openssl-install/share/man/man3/SSL_set1_client_sigalgs_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_compressed_cert.3ossl b/openssl-install/share/man/man3/SSL_set1_compressed_cert.3ossl deleted file mode 120000 index 7aaf058c..00000000 --- a/openssl-install/share/man/man3/SSL_set1_compressed_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_cert_comp_preference.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_curves.3ossl b/openssl-install/share/man/man3/SSL_set1_curves.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_set1_curves.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_curves_list.3ossl b/openssl-install/share/man/man3/SSL_set1_curves_list.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_set1_curves_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_groups.3ossl b/openssl-install/share/man/man3/SSL_set1_groups.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_set1_groups.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_groups_list.3ossl b/openssl-install/share/man/man3/SSL_set1_groups_list.3ossl deleted file mode 120000 index 399ce906..00000000 --- a/openssl-install/share/man/man3/SSL_set1_groups_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_curves.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_host.3ossl b/openssl-install/share/man/man3/SSL_set1_host.3ossl deleted file mode 100644 index d253521c..00000000 --- a/openssl-install/share/man/man3/SSL_set1_host.3ossl +++ /dev/null @@ -1,259 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET1_HOST 3ossl" -.TH SSL_SET1_HOST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set1_host, SSL_add1_host, SSL_set_hostflags, SSL_get0_peername \- -SSL server verification parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set1_host(SSL *s, const char *host); -\& int SSL_add1_host(SSL *s, const char *host); -\& void SSL_set_hostflags(SSL *s, unsigned int flags); -\& const char *SSL_get0_peername(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions configure server hostname checks in the \s-1SSL\s0 client. -.PP -\&\fBSSL_set1_host()\fR sets in the verification parameters of \fIs\fR -the expected \s-1DNS\s0 hostname or \s-1IP\s0 address to \fIhost\fR, -clearing any previously specified \s-1IP\s0 address and hostnames. -If \fIhost\fR is \s-1NULL\s0 or the empty string, \s-1IP\s0 address -and hostname checks are not performed on the peer certificate. -When a nonempty \fIhost\fR is specified, certificate verification automatically -checks the peer hostname via \fBX509_check_host\fR\|(3) with \fIflags\fR as specified -via \fBSSL_set_hostflags()\fR. Clients that enable \s-1DANE TLSA\s0 authentication -via \fBSSL_dane_enable\fR\|(3) should leave it to that function to set -the primary reference identifier of the peer, and should not call -\&\fBSSL_set1_host()\fR. -.PP -\&\fBSSL_add1_host()\fR adds \fIhost\fR as an additional reference identifier -that can match the peer's certificate. Any previous hostnames -set via \fBSSL_set1_host()\fR or \fBSSL_add1_host()\fR are retained. -Adding an \s-1IP\s0 address is allowed only if no \s-1IP\s0 address has been set before. -No change is made if \fIhost\fR is \s-1NULL\s0 or empty. -When an \s-1IP\s0 address and/or multiple hostnames are configured, -the peer is considered verified when any of these matches. -This function is required for \s-1DANE TLSA\s0 in the presence of service name indirection -via \s-1CNAME, MX\s0 or \s-1SRV\s0 records as specified in RFCs 7671, 7672, and 7673. -.PP -\&\s-1TLS\s0 clients are recommended to use \fBSSL_set1_host()\fR or \fBSSL_add1_host()\fR -for server hostname or \s-1IP\s0 address validation, -as well as \fBSSL_set_tlsext_host_name\fR\|(3) for Server Name Indication (\s-1SNI\s0), -which may be crucial also for correct routing of the connection request. -.PP -\&\fBSSL_set_hostflags()\fR sets the \fIflags\fR that will be passed to -\&\fBX509_check_host\fR\|(3) when name checks are applicable, by default -the \fIflags\fR value is 0. See \fBX509_check_host\fR\|(3) for the list -of available flags and their meaning. -.PP -\&\fBSSL_get0_peername()\fR returns the \s-1DNS\s0 hostname or subject CommonName -from the peer certificate that matched one of the reference -identifiers. When wildcard matching is not disabled, the name -matched in the peer certificate may be a wildcard name. When one -of the reference identifiers configured via \fBSSL_set1_host()\fR or -\&\fBSSL_add1_host()\fR starts with \*(L".\*(R", which indicates a parent domain prefix -rather than a fixed name, the matched peer name may be a sub-domain -of the reference identifier. The returned string is allocated by -the library and is no longer valid once the associated \fIssl\fR handle -is cleared or freed, or a renegotiation takes place. Applications -must not free the return value. -.PP -\&\s-1SSL\s0 clients are advised to use these functions in preference to -explicitly calling \fBX509_check_host\fR\|(3). Hostname checks may be out -of scope with the \s-1RFC 7671 \fBDANE\-EE\s0\fR\|(3) certificate usage, and the -internal check will be suppressed as appropriate when \s-1DANE\s0 is -enabled. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set1_host()\fR and \fBSSL_add1_host()\fR return 1 for success and 0 for -failure. -.PP -\&\fBSSL_set_hostflags()\fR returns nothing at all. -.PP -\&\fBSSL_get0_peername()\fR returns \s-1NULL\s0 if peername verification is not -applicable (as with \s-1RFC 7671 \fBDANE\-EE\s0\fR\|(3)), or no trusted peername was -matched. Otherwise, it returns the matched peername. To determine -whether verification succeeded call \fBSSL_get_verify_result\fR\|(3). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Suppose \*(L"smtp.example.com\*(R" is the \s-1MX\s0 host of the domain \*(L"example.com\*(R". -The calls below will arrange to match either the \s-1MX\s0 hostname or the -destination domain name in the \s-1SMTP\s0 server certificate. Wildcards -are supported, but must match the entire label. The actual name -matched in the certificate (which might be a wildcard) is retrieved, -and must be copied by the application if it is to be retained beyond -the lifetime of the \s-1SSL\s0 connection. -.PP -.Vb 5 -\& SSL_set_hostflags(ssl, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS); -\& if (!SSL_set1_host(ssl, "smtp.example.com")) -\& /* error */ -\& if (!SSL_add1_host(ssl, "example.com")) -\& /* error */ -\& -\& /* XXX: Perform SSL_connect() handshake and handle errors here */ -\& -\& if (SSL_get_verify_result(ssl) == X509_V_OK) { -\& const char *peername = SSL_get0_peername(ssl); -\& -\& if (peername != NULL) -\& /* Name checks were in scope and matched the peername */ -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBX509_check_host\fR\|(3), \fBSSL_set_tlsext_host_name\fR\|(3), -\&\fBSSL_get_verify_result\fR\|(3), \fBSSL_dane_enable\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set1_initial_peer_addr.3ossl b/openssl-install/share/man/man3/SSL_set1_initial_peer_addr.3ossl deleted file mode 100644 index 3efaccb9..00000000 --- a/openssl-install/share/man/man3/SSL_set1_initial_peer_addr.3ossl +++ /dev/null @@ -1,192 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET1_INITIAL_PEER_ADDR 3ossl" -.TH SSL_SET1_INITIAL_PEER_ADDR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set1_initial_peer_addr \- set the initial peer address for a QUIC connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set1_initial_peer_addr(SSL *s, const BIO_ADDR *addr); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set1_initial_peer_addr()\fR sets the initial destination peer address to be used -for the purposes of establishing a \s-1QUIC\s0 connection in client mode. This function -can be used only on a \s-1QUIC\s0 connection \s-1SSL\s0 object, and can be used only before a -connection attempt is first made. \fIaddr\fR must point to a \fB\s-1BIO_ADDR\s0\fR -representing a \s-1UDP\s0 destination address of the server to connect to. -.PP -Where a \s-1QUIC\s0 connection object is provided with a write \s-1BIO\s0 which supports the -\&\fB\s-1BIO_CTRL_DGRAM_GET_PEER\s0\fR control (for example, \fBBIO_s_dgram\fR), the initial -destination peer address can be detected automatically; if -\&\fB\s-1BIO_CTRL_DGRAM_GET_PEER\s0\fR returns a valid (non\-\fB\s-1AF_UNSPEC\s0\fR) peer address and -no valid peer address has yet been set, this will be set automatically as the -initial peer address. This behaviour can be overridden by calling -\&\fBSSL_set1_initial_peer_addr()\fR with a valid peer address explicitly. -.PP -The destination address used by \s-1QUIC\s0 may change over time in response to -connection events, such as connection migration (where supported). -\&\fBSSL_set1_initial_peer_addr()\fR configures the destination address used for initial -connection establishment, and does not confer any guarantee about the -destination address being used for communication at any later time in the -connection lifecycle. -.PP -This function makes a copy of the address passed by the caller; the \fB\s-1BIO_ADDR\s0\fR -structure pointed to by \fIaddr\fR may be freed by the caller after this function -returns. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success and 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBBIO_ADDR\s0\fR\|(3), \fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_set1_initial_peer_addr()\fR function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set1_param.3ossl b/openssl-install/share/man/man3/SSL_set1_param.3ossl deleted file mode 120000 index fd781e23..00000000 --- a/openssl-install/share/man/man3/SSL_set1_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_server_cert_type.3ossl b/openssl-install/share/man/man3/SSL_set1_server_cert_type.3ossl deleted file mode 100644 index 4c599da0..00000000 --- a/openssl-install/share/man/man3/SSL_set1_server_cert_type.3ossl +++ /dev/null @@ -1,323 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET1_SERVER_CERT_TYPE 3ossl" -.TH SSL_SET1_SERVER_CERT_TYPE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set1_client_cert_type, -SSL_set1_server_cert_type, -SSL_CTX_set1_client_cert_type, -SSL_CTX_set1_server_cert_type, -SSL_get0_client_cert_type, -SSL_get0_server_cert_type, -SSL_CTX_get0_client_cert_type, -SSL_CTX_get0_server_cert_type \- certificate type (RFC7250) support -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set1_client_cert_type(SSL *s, const unsigned char *val, size_t len); -\& int SSL_set1_server_cert_type(SSL *s, const unsigned char *val, size_t len); -\& int SSL_CTX_set1_client_cert_type(SSL_CTX *ctx, const unsigned char *val, size_t len); -\& int SSL_CTX_set1_server_cert_type(SSL_CTX *ctx, const unsigned char *val, size_t len); -\& int SSL_get0_client_cert_type(const SSL *s, unsigned char **val, size_t *len); -\& int SSL_get0_server_cert_type(const SSL *s, unsigned char **val, size_t *len); -\& int SSL_CTX_get0_client_cert_type(const SSL_CTX *ctx, unsigned char **val, size_t *len); -\& int SSL_CTX_get0_server_cert_type(const SSL_CTX *s, unsigned char **val, size_t *len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBSSL_set1_client_cert_type()\fR and \fBSSL_CTX_set1_client_cert_type()\fR functions -set the values for the client certificate type extension. -The \fBSSL_get0_client_cert_type()\fR and \fBSSL_CTX_get0_client_cert_type()\fR functions -retrieve the local values to be used in the client certificate type extension. -.PP -The \fBSSL_set1_server_cert_type()\fR and \fBSSL_CTX_set1_server_cert_type()\fR functions -set the values for the server certificate type extension. -The \fBSSL_get0_server_cert_type()\fR and \fBSSL_CTX_get0_server_cert_type()\fR functions -retrieve the local values to be used in the server certificate type extension. -.SH "NOTES" -.IX Header "NOTES" -The certificate type extensions are used to negotiate the certificate type to -be used in the handshake. -These extensions let each side know what its peer is able to accept. -.PP -The client certificate type is sent from the client to the server to indicate -what certificate types the client is able to present. -Values are configured in preference order. -On the server, this setting determines which certificate types the server is -willing to accept. -The server ultimately chooses what type to request (if any) from the values -that are mutually supported. -By default (if no explicit settings are specified), only X.509 certificates -are supported. -.PP -The server certificate type is sent from the client to the server to indicate -what certificate types the client accepts. -Values are configured in preference order. -On the server, this setting determines which certificate types the server is -willing to present. -The server ultimately chooses what type to use from the values that are -mutually supported. -By default (if no explicit settings are specified), only X.509 certificates -are supported. -.PP -Having \s-1RPK\s0 specified first means that side will attempt to send (or request) -RPKs if its peer also supports RPKs, otherwise X.509 certificate will be used -if both have specified that (or have not configured these options). -.PP -The two supported values in the \fBval\fR array are: -.IP "TLSEXT_cert_type_x509" 4 -.IX Item "TLSEXT_cert_type_x509" -Which corresponds to an X.509 certificate normally used in \s-1TLS.\s0 -.IP "TLSEXT_cert_type_rpk" 4 -.IX Item "TLSEXT_cert_type_rpk" -Which corresponds to a raw public key. -.PP -If \fBval\fR is set to a non-NULL value, then the extension is sent in the handshake. -If b is set to a \s-1NULL\s0 value (and \fBlen\fR is 0), then the extension is -disabled. The default value is \s-1NULL,\s0 meaning the extension is not sent, and -X.509 certificates are used in the handshake. -.PP -Raw public keys may be used in place of certificates when specified in the -certificate type and negotiated. -Raw public keys have no subject, issuer, validity dates or digital signature. -.PP -Use the \fBSSL_get_negotiated_client_cert_type\fR\|(3) and -\&\fBSSL_get_negotiated_server_cert_type\fR\|(3) functions to get the negotiated cert -type values (at the conclusion of the handshake, or in callbacks that happen -after the \s-1TLS\s0 ServerHello has been processed). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return 1 on success and 0 on failure. -.PP -The memory returned from the get0 functions must not be freed. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To use raw public keys on the server, set up the \s-1SSL_CTX\s0 and \s-1SSL\s0 as follows: -.PP -.Vb 4 -\& SSL_CTX *ctx; -\& SSL *ssl; -\& unsigned char cert_type[] = { TLSEXT_cert_type_rpk, TLSEXT_cert_type_x509 }; -\& EVP_PKEY *rpk; -\& -\& /* Assign rpk to an EVP_PKEY from a file or other means */ -\& -\& if ((ctx = SSL_CTX_new(TLS_server_method())) == NULL) -\& /* error */ -\& if ((ssl = SSL_new(ctx)) == NULL) -\& /* error */ -\& if (!SSL_set1_server_cert_type(ssl, cert_type, sizeof(cert_type))) -\& /* error */ -\& -\& /* A certificate does not need to be specified when using raw public keys */ -\& if (!SSL_use_PrivateKey(ssl, rpk)) -\& /* error */ -\& -\& /* Perform SSL_accept() operations */ -.Ve -.PP -To connect to this server, set the client \s-1SSL_CTX\s0 and \s-1SSL\s0 as follows: -.PP -.Vb 1 -\& /* Connect function */ -\& -\& SSL_CTX *ctx; -\& SSL *ssl; -\& const char *dane_tlsa_domain = "smtp.example.com"; -\& unsigned char cert_type[] = { TLSEXT_cert_type_rpk, TLSEXT_cert_type_x509 }; -\& EVP_PKEY *rpk; -\& int verify_result; -\& -\& /* Assign rpk to an EVP_PKEY from a file or other means */ -\& -\& if ((ctx = SSL_CTX_new(TLS_client_method())) == NULL) -\& /* error */ -\& if (SSL_CTX_dane_enable(ctx) <= 0) -\& /* error */ -\& if ((ssl = SSL_new(ctx)) == NULL) -\& /* error */ -\& /* -\& * The \`dane_tlsa_domain\` arguments sets the default SNI hostname. -\& * It may be set to NULL when enabling DANE on the server side. -\& */ -\& if (SSL_dane_enable(ssl, dane_tlsa_domain) <= 0) -\& /* error */ -\& if (!SSL_set1_server_cert_type(ssl, cert_type, sizeof(cert_type))) -\& /* error */ -\& if (!SSL_add_expected_rpk(ssl, rpk)) -\& /* error */ -\& -\& /* Do SSL_connect() handshake and handle errors here */ -\& -\& /* Optional: verify the peer RPK */ -\& verify_result = SSL_get_verify_result(ssl); -\& if (verify_result == X509_V_OK) { -\& /* The server\*(Aqs raw public key matched the TLSA record */ -\& } else if (verify_result == X509_V_ERR_DANE_NO_MATCH) { -\& /* -\& * The server\*(Aqs raw public key, or public key in certificate, did not -\& * match the TLSA record -\& */ -\& } else if (verify_result == X509_V_ERR_RPK_UNTRUSTED) { -\& /* -\& * No TLSA records of the correct type are available to verify the -\& * server\*(Aqs raw public key. This would not happen in this example, -\& * as a TLSA record is configured. -\& */ -\& } else { -\& /* Some other verify error */ -\& } -.Ve -.PP -To validate client raw public keys, code from the client example may need to be -incorporated into the server side. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get0_peer_rpk\fR\|(3), -\&\fBSSL_get_negotiated_client_cert_type\fR\|(3), -\&\fBSSL_get_negotiated_server_cert_type\fR\|(3), -\&\fBSSL_use_certificate\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. diff --git a/openssl-install/share/man/man3/SSL_set1_sigalgs.3ossl b/openssl-install/share/man/man3/SSL_set1_sigalgs.3ossl deleted file mode 120000 index f594d7af..00000000 --- a/openssl-install/share/man/man3/SSL_set1_sigalgs.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_sigalgs_list.3ossl b/openssl-install/share/man/man3/SSL_set1_sigalgs_list.3ossl deleted file mode 120000 index f594d7af..00000000 --- a/openssl-install/share/man/man3/SSL_set1_sigalgs_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_sigalgs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set1_verify_cert_store.3ossl b/openssl-install/share/man/man3/SSL_set1_verify_cert_store.3ossl deleted file mode 120000 index aeaa33f1..00000000 --- a/openssl-install/share/man/man3/SSL_set1_verify_cert_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set1_verify_cert_store.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_accept_state.3ossl b/openssl-install/share/man/man3/SSL_set_accept_state.3ossl deleted file mode 120000 index 5b8be4e3..00000000 --- a/openssl-install/share/man/man3/SSL_set_accept_state.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_connect_state.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_allow_early_data_cb.3ossl b/openssl-install/share/man/man3/SSL_set_allow_early_data_cb.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_set_allow_early_data_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_alpn_protos.3ossl b/openssl-install/share/man/man3/SSL_set_alpn_protos.3ossl deleted file mode 120000 index fa1385af..00000000 --- a/openssl-install/share/man/man3/SSL_set_alpn_protos.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_alpn_select_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_app_data.3ossl b/openssl-install/share/man/man3/SSL_set_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_async_callback.3ossl b/openssl-install/share/man/man3/SSL_set_async_callback.3ossl deleted file mode 100644 index 1a126e70..00000000 --- a/openssl-install/share/man/man3/SSL_set_async_callback.3ossl +++ /dev/null @@ -1,238 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_ASYNC_CALLBACK 3ossl" -.TH SSL_SET_ASYNC_CALLBACK 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_CTX_set_async_callback, -SSL_CTX_set_async_callback_arg, -SSL_set_async_callback, -SSL_set_async_callback_arg, -SSL_get_async_status, -SSL_async_callback_fn -\&\- manage asynchronous operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*SSL_async_callback_fn)(SSL *s, void *arg); -\& int SSL_CTX_set_async_callback(SSL_CTX *ctx, SSL_async_callback_fn callback); -\& int SSL_CTX_set_async_callback_arg(SSL_CTX *ctx, void *arg); -\& int SSL_set_async_callback(SSL *s, SSL_async_callback_fn callback); -\& int SSL_set_async_callback_arg(SSL *s, void *arg); -\& int SSL_get_async_status(SSL *s, int *status); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_CTX_set_async_callback()\fR sets an asynchronous callback function. All \fB\s-1SSL\s0\fR -objects generated based on this \fB\s-1SSL_CTX\s0\fR will get this callback. If an engine -supports the callback mechanism, it will be automatically called if -\&\fB\s-1SSL_MODE_ASYNC\s0\fR has been set and an asynchronous capable engine completes a -cryptography operation to notify the application to resume the paused work flow. -.PP -\&\fBSSL_CTX_set_async_callback_arg()\fR sets the callback argument. -.PP -\&\fBSSL_set_async_callback()\fR allows an application to set a callback in an -asynchronous \fB\s-1SSL\s0\fR object, so that when an engine completes a cryptography -operation, the callback will be called to notify the application to resume the -paused work flow. -.PP -\&\fBSSL_set_async_callback_arg()\fR sets an argument for the \fB\s-1SSL\s0\fR object when the -above callback is called. -.PP -\&\fBSSL_get_async_status()\fR returns the engine status. This function facilitates the -communication from the engine to the application. During an \s-1SSL\s0 session, -cryptographic operations are dispatched to an engine. The engine status is very -useful for an application to know if the operation has been successfully -dispatched. If the engine does not support this additional callback method, -\&\fB\s-1ASYNC_STATUS_UNSUPPORTED\s0\fR will be returned. See \fBASYNC_WAIT_CTX_set_status()\fR -for a description of all of the status values. -.PP -An example of the above functions would be the following: -.IP "1." 4 -Application sets the async callback and callback data on an \s-1SSL\s0 connection -by calling \fBSSL_set_async_callback()\fR. -.IP "2." 4 -Application sets \fB\s-1SSL_MODE_ASYNC\s0\fR and makes an asynchronous \s-1SSL\s0 call -.IP "3." 4 -OpenSSL submits the asynchronous request to the engine. If a retry occurs at -this point then the status within the \fB\s-1ASYNC_WAIT_CTX\s0\fR would be set and the -async callback function would be called (goto Step 7). -.IP "4." 4 -The OpenSSL engine pauses the current job and returns, so that the -application can continue processing other connections. -.IP "5." 4 -At a future point in time (probably via a polling mechanism or via an -interrupt) the engine will become aware that the asynchronous request has -finished processing. -.IP "6." 4 -The engine will call the application's callback passing the callback data as -a parameter. -.IP "7." 4 -The callback function should then run. Note: it is a requirement that the -callback function is small and nonblocking as it will be run in the context of -a polling mechanism or an interrupt. -.IP "8." 4 -It is the application's responsibility via the callback function to schedule -recalling the OpenSSL asynchronous function and to continue processing. -.IP "9." 4 -The callback function has the option to check the status returned via -\&\fBSSL_get_async_status()\fR to determine whether a retry happened instead of the -request being submitted, allowing different processing if required. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_CTX_set_async_callback()\fR, \fBSSL_set_async_callback()\fR, -\&\fBSSL_CTX_set_async_callback_arg()\fR, \fBSSL_CTX_set_async_callback_arg()\fR and -\&\fBSSL_get_async_status()\fR return 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_CTX_set_async_callback()\fR, \fBSSL_CTX_set_async_callback_arg()\fR, -\&\fBSSL_set_async_callback()\fR, \fBSSL_set_async_callback_arg()\fR and -\&\fBSSL_get_async_status()\fR were first added to OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_async_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_set_async_callback_arg.3ossl deleted file mode 120000 index ea95f1d7..00000000 --- a/openssl-install/share/man/man3/SSL_set_async_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_async_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_bio.3ossl b/openssl-install/share/man/man3/SSL_set_bio.3ossl deleted file mode 100644 index 41fae900..00000000 --- a/openssl-install/share/man/man3/SSL_set_bio.3ossl +++ /dev/null @@ -1,240 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_BIO 3ossl" -.TH SSL_SET_BIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_bio, SSL_set0_rbio, SSL_set0_wbio \- connect the SSL object with a BIO -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_set_bio(SSL *ssl, BIO *rbio, BIO *wbio); -\& void SSL_set0_rbio(SSL *s, BIO *rbio); -\& void SSL_set0_wbio(SSL *s, BIO *wbio); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set0_rbio()\fR connects the \s-1BIO\s0 \fBrbio\fR for the read operations of the \fBssl\fR -object. The \s-1SSL\s0 engine inherits the behaviour of \fBrbio\fR. If the \s-1BIO\s0 is -nonblocking then the \fBssl\fR object will also have nonblocking behaviour. This -function transfers ownership of \fBrbio\fR to \fBssl\fR. It will be automatically -freed using \fBBIO_free_all\fR\|(3) when the \fBssl\fR is freed. On calling this -function, any existing \fBrbio\fR that was previously set will also be freed via a -call to \fBBIO_free_all\fR\|(3) (this includes the case where the \fBrbio\fR is set to -the same value as previously). -.PP -If using a custom \s-1BIO,\s0 \fBrbio\fR must implement either -\&\fBBIO_meth_set_read_ex\fR\|(3) or \fBBIO_meth_set_read\fR\|(3). -.PP -\&\fBSSL_set0_wbio()\fR works in the same as \fBSSL_set0_rbio()\fR except that it connects -the \s-1BIO\s0 \fBwbio\fR for the write operations of the \fBssl\fR object. Note that if the -rbio and wbio are the same then \fBSSL_set0_rbio()\fR and \fBSSL_set0_wbio()\fR each take -ownership of one reference. Therefore, it may be necessary to increment the -number of references available using \fBBIO_up_ref\fR\|(3) before calling the set0 -functions. -.PP -If using a custom \s-1BIO,\s0 \fBwbio\fR must implement -\&\fBBIO_meth_set_write_ex\fR\|(3) or \fBBIO_meth_set_write\fR\|(3). It additionally must -implement \fBBIO_flush\fR\|(3) using \fB\s-1BIO_CTRL_FLUSH\s0\fR and \fBBIO_meth_set_ctrl\fR\|(3). -If flushing is unnecessary with \fBwbio\fR, \fBBIO_flush\fR\|(3) should return one and -do nothing. -.PP -\&\fBSSL_set_bio()\fR is similar to \fBSSL_set0_rbio()\fR and \fBSSL_set0_wbio()\fR except -that it connects both the \fBrbio\fR and the \fBwbio\fR at the same time, and -transfers the ownership of \fBrbio\fR and \fBwbio\fR to \fBssl\fR according to -the following set of rules: -.IP "\(bu" 2 -If neither the \fBrbio\fR or \fBwbio\fR have changed from their previous values -then nothing is done. -.IP "\(bu" 2 -If the \fBrbio\fR and \fBwbio\fR parameters are different and both are different -to their -previously set values then one reference is consumed for the rbio and one -reference is consumed for the wbio. -.IP "\(bu" 2 -If the \fBrbio\fR and \fBwbio\fR parameters are the same and the \fBrbio\fR is not -the same as the previously set value then one reference is consumed. -.IP "\(bu" 2 -If the \fBrbio\fR and \fBwbio\fR parameters are the same and the \fBrbio\fR is the -same as the previously set value, then no additional references are consumed. -.IP "\(bu" 2 -If the \fBrbio\fR and \fBwbio\fR parameters are different and the \fBrbio\fR is the -same as the -previously set value then one reference is consumed for the \fBwbio\fR and no -references are consumed for the \fBrbio\fR. -.IP "\(bu" 2 -If the \fBrbio\fR and \fBwbio\fR parameters are different and the \fBwbio\fR is the -same as the previously set value and the old \fBrbio\fR and \fBwbio\fR values -were the same as each other then one reference is consumed for the \fBrbio\fR -and no references are consumed for the \fBwbio\fR. -.IP "\(bu" 2 -If the \fBrbio\fR and \fBwbio\fR parameters are different and the \fBwbio\fR -is the same as the -previously set value and the old \fBrbio\fR and \fBwbio\fR values were different -to each other, then one reference is consumed for the \fBrbio\fR and one -reference is consumed for the \fBwbio\fR. -.PP -Because of this complexity, this function should be avoided; -use \fBSSL_set0_rbio()\fR and \fBSSL_set0_wbio()\fR instead. -.PP -Where a new \s-1BIO\s0 is set on a \s-1QUIC\s0 connection \s-1SSL\s0 object, blocking mode will be -disabled on that \s-1SSL\s0 object if the \s-1BIO\s0 cannot support blocking mode. If another -\&\s-1BIO\s0 is subsequently set on the \s-1SSL\s0 object which can support blocking mode, -blocking mode will not be automatically re-enabled. For more information, see -\&\fBSSL_set_blocking_mode\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_bio()\fR, \fBSSL_set0_rbio()\fR and \fBSSL_set0_wbio()\fR cannot fail. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_rbio\fR\|(3), -\&\fBSSL_connect\fR\|(3), \fBSSL_accept\fR\|(3), -\&\fBSSL_shutdown\fR\|(3), \fBssl\fR\|(7), \fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_set0_rbio()\fR and \fBSSL_set0_wbio()\fR were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_block_padding.3ossl b/openssl-install/share/man/man3/SSL_set_block_padding.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_set_block_padding.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_block_padding_ex.3ossl b/openssl-install/share/man/man3/SSL_set_block_padding_ex.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_set_block_padding_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_blocking_mode.3ossl b/openssl-install/share/man/man3/SSL_set_blocking_mode.3ossl deleted file mode 100644 index ac6263d5..00000000 --- a/openssl-install/share/man/man3/SSL_set_blocking_mode.3ossl +++ /dev/null @@ -1,205 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_BLOCKING_MODE 3ossl" -.TH SSL_SET_BLOCKING_MODE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_blocking_mode, SSL_get_blocking_mode \- configure blocking mode for a -QUIC SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set_blocking_mode(SSL *s, int blocking); -\& int SSL_get_blocking_mode(SSL *s); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_blocking_mode()\fR can be used to enable or disable blocking mode on a \s-1QUIC\s0 -connection \s-1SSL\s0 object. By default, blocking is enabled, unless the \s-1SSL\s0 object is -configured to use an underlying read or write \s-1BIO\s0 which cannot provide a poll -descriptor (see \fBBIO_get_rpoll_descriptor\fR\|(3)), as blocking mode cannot be -supported in this case. -.PP -To enable blocking mode, call \fBSSL_set_blocking_mode()\fR with \fIblocking\fR set to 1; -to disable it, call \fBSSL_set_blocking_mode()\fR with \fIblocking\fR set to 0. -.PP -To retrieve the current blocking mode, call \fBSSL_get_blocking_mode()\fR. -.PP -Blocking mode means that calls such as \fBSSL_read()\fR and \fBSSL_write()\fR will block -until the requested operation can be performed. In nonblocking mode, these -calls will fail if the requested operation cannot be performed immediately; see -\&\fBSSL_get_error\fR\|(3). -.PP -These functions are only applicable to \s-1QUIC\s0 connection \s-1SSL\s0 objects. Other kinds -of \s-1SSL\s0 object, such as those for \s-1TLS,\s0 automatically function in blocking or -nonblocking mode based on whether the underlying network read and write BIOs -provided to the \s-1SSL\s0 object are themselves configured in nonblocking mode. -.PP -Where a \s-1QUIC\s0 connection \s-1SSL\s0 object is used in nonblocking mode, an application -is responsible for ensuring that the \s-1SSL\s0 object is ticked regularly; see -\&\fBSSL_handle_events\fR\|(3). -.PP -Blocking mode is disabled automatically if the application provides a \s-1QUIC\s0 -connection \s-1SSL\s0 object with a network \s-1BIO\s0 which cannot support blocking mode. To -re-enable blocking mode in this case, an application must set a network \s-1BIO\s0 -which can support blocking mode and explicitly call \fBSSL_set_blocking_mode()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_blocking_mode()\fR returns 1 on success and 0 on failure. The function -fails if called on a \s-1SSL\s0 object which does not represent a \s-1QUIC\s0 connection, -or if blocking mode cannot be used for the given connection. -.PP -\&\fBSSL_get_blocking_mode()\fR returns 1 if blocking is currently enabled. It returns -\&\-1 if called on an unsupported \s-1SSL\s0 object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_handle_events\fR\|(3), \fBssl\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_set_blocking_mode()\fR and \fBSSL_get_blocking_mode()\fR functions were added in -OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_cert_cb.3ossl b/openssl-install/share/man/man3/SSL_set_cert_cb.3ossl deleted file mode 120000 index 5458b7a2..00000000 --- a/openssl-install/share/man/man3/SSL_set_cert_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cert_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_cipher_list.3ossl b/openssl-install/share/man/man3/SSL_set_cipher_list.3ossl deleted file mode 120000 index e8b09412..00000000 --- a/openssl-install/share/man/man3/SSL_set_cipher_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cipher_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_ciphersuites.3ossl b/openssl-install/share/man/man3/SSL_set_ciphersuites.3ossl deleted file mode 120000 index e8b09412..00000000 --- a/openssl-install/share/man/man3/SSL_set_ciphersuites.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_cipher_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_client_CA_list.3ossl b/openssl-install/share/man/man3/SSL_set_client_CA_list.3ossl deleted file mode 120000 index 5c96c008..00000000 --- a/openssl-install/share/man/man3/SSL_set_client_CA_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set0_CA_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_connect_state.3ossl b/openssl-install/share/man/man3/SSL_set_connect_state.3ossl deleted file mode 100644 index 2cd3a96f..00000000 --- a/openssl-install/share/man/man3/SSL_set_connect_state.3ossl +++ /dev/null @@ -1,208 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_CONNECT_STATE 3ossl" -.TH SSL_SET_CONNECT_STATE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_connect_state, SSL_set_accept_state, SSL_is_server -\&\- functions for manipulating and examining the client or server mode of an SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_set_connect_state(SSL *ssl); -\& -\& void SSL_set_accept_state(SSL *ssl); -\& -\& int SSL_is_server(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_connect_state()\fR sets \fBssl\fR to work in client mode. -.PP -\&\fBSSL_set_accept_state()\fR sets \fBssl\fR to work in server mode. -.PP -\&\fBSSL_is_server()\fR checks if \fBssl\fR is working in server mode. -.SH "NOTES" -.IX Header "NOTES" -When the \s-1SSL_CTX\s0 object was created with \fBSSL_CTX_new\fR\|(3), -it was either assigned a dedicated client method, a dedicated server -method, or a generic method, that can be used for both client and -server connections. (The method might have been changed with -\&\fBSSL_CTX_set_ssl_version\fR\|(3) or -\&\fBSSL_set_ssl_method\fR\|(3).) -.PP -When beginning a new handshake, the \s-1SSL\s0 engine must know whether it must -call the connect (client) or accept (server) routines. Even though it may -be clear from the method chosen, whether client or server mode was -requested, the handshake routines must be explicitly set. -.PP -When using the \fBSSL_connect\fR\|(3) or -\&\fBSSL_accept\fR\|(3) routines, the correct handshake -routines are automatically set. When performing a transparent negotiation -using \fBSSL_write_ex\fR\|(3), \fBSSL_write\fR\|(3), \fBSSL_read_ex\fR\|(3), or \fBSSL_read\fR\|(3), -the handshake routines must be explicitly set in advance using either -\&\fBSSL_set_connect_state()\fR or \fBSSL_set_accept_state()\fR. -.PP -If \fBSSL_is_server()\fR is called before \fBSSL_set_connect_state()\fR or -\&\fBSSL_set_accept_state()\fR is called (either automatically or explicitly), -the result depends on what method was used when \s-1SSL_CTX\s0 was created with -\&\fBSSL_CTX_new\fR\|(3). If a generic method or a dedicated server method was -passed to \fBSSL_CTX_new\fR\|(3), \fBSSL_is_server()\fR returns 1; otherwise, it returns 0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_connect_state()\fR and \fBSSL_set_accept_state()\fR do not return diagnostic -information. -.PP -\&\fBSSL_is_server()\fR returns 1 if \fBssl\fR is working in server mode or 0 for client mode. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_new\fR\|(3), \fBSSL_CTX_new\fR\|(3), -\&\fBSSL_connect\fR\|(3), \fBSSL_accept\fR\|(3), -\&\fBSSL_write_ex\fR\|(3), \fBSSL_write\fR\|(3), \fBSSL_read_ex\fR\|(3), \fBSSL_read\fR\|(3), -\&\fBSSL_do_handshake\fR\|(3), -\&\fBSSL_CTX_set_ssl_version\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_ct_validation_callback.3ossl b/openssl-install/share/man/man3/SSL_set_ct_validation_callback.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/SSL_set_ct_validation_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_current_cert.3ossl b/openssl-install/share/man/man3/SSL_set_current_cert.3ossl deleted file mode 120000 index e159229d..00000000 --- a/openssl-install/share/man/man3/SSL_set_current_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_add1_chain_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_default_passwd_cb.3ossl b/openssl-install/share/man/man3/SSL_set_default_passwd_cb.3ossl deleted file mode 120000 index 5e9f9bdf..00000000 --- a/openssl-install/share/man/man3/SSL_set_default_passwd_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_default_passwd_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_default_passwd_cb_userdata.3ossl b/openssl-install/share/man/man3/SSL_set_default_passwd_cb_userdata.3ossl deleted file mode 120000 index 5e9f9bdf..00000000 --- a/openssl-install/share/man/man3/SSL_set_default_passwd_cb_userdata.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_default_passwd_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_default_read_buffer_len.3ossl b/openssl-install/share/man/man3/SSL_set_default_read_buffer_len.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_set_default_read_buffer_len.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_default_stream_mode.3ossl b/openssl-install/share/man/man3/SSL_set_default_stream_mode.3ossl deleted file mode 100644 index 3dfccb37..00000000 --- a/openssl-install/share/man/man3/SSL_set_default_stream_mode.3ossl +++ /dev/null @@ -1,251 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_DEFAULT_STREAM_MODE 3ossl" -.TH SSL_SET_DEFAULT_STREAM_MODE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_default_stream_mode, -SSL_DEFAULT_STREAM_MODE_NONE, SSL_DEFAULT_STREAM_MODE_AUTO_BIDI, -SSL_DEFAULT_STREAM_MODE_AUTO_UNI \- manage the default stream for a QUIC -connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_DEFAULT_STREAM_MODE_NONE -\& #define SSL_DEFAULT_STREAM_MODE_AUTO_BIDI -\& #define SSL_DEFAULT_STREAM_MODE_AUTO_UNI -\& -\& int SSL_set_default_stream_mode(SSL *conn, uint32_t mode); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A \s-1QUIC\s0 connection \s-1SSL\s0 object may have a default stream attached to it. A default -stream is a \s-1QUIC\s0 stream to which calls to \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) -made on a \s-1QUIC\s0 connection \s-1SSL\s0 object are redirected. Default stream handling -allows legacy applications to use \s-1QUIC\s0 similarly to a traditional \s-1TLS\s0 -connection. -.PP -When not disabled, a default stream is automatically created on an outgoing -connection once \fBSSL_read\fR\|(3) or \fBSSL_write\fR\|(3) is called. -.PP -A \s-1QUIC\s0 stream must be explicitly designated as client-initiated or -server-initiated up front. This broadly corresponds to whether an application -protocol involves the client transmitting first, or the server transmitting -first. As such, if \fBSSL_read\fR\|(3) is called first (before any call to -\&\fBSSL_write\fR\|(3)) after establishing a connection, OpenSSL will wait for the -server to open the first server-initiated stream, and then bind this as the -default stream. Conversely, if \fBSSL_write\fR\|(3) is called before any call to -\&\fBSSL_read\fR\|(3), OpenSSL assumes the client wishes to transmit first, creates a -client-initiated stream, and binds this as the default stream. -.PP -By default, the default stream created is bidirectional. If a unidirectional -stream is desired, or if the application wishes to disable default stream -functionality, \fBSSL_set_default_stream_mode()\fR (discussed below) can be used to -accomplish this. -.PP -When a \s-1QUIC\s0 connection \s-1SSL\s0 object has no default stream currently associated -with it, for example because default stream functionality was disabled, calls to -functions which require a stream on the \s-1QUIC\s0 connection \s-1SSL\s0 object (for example, -\&\fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3)) will fail. -.PP -It is recommended that new applications and applications which rely on multiple -streams forego use of the default stream functionality, which is intended for -legacy applications. -.PP -\&\fBSSL_set_default_stream_mode()\fR can be used to configure or disable default stream -handling. It can only be called on a \s-1QUIC\s0 connection \s-1SSL\s0 object prior to any -default stream being created. If used, it is recommended to call it immediately -after calling \fBSSL_new\fR\|(3), prior to initiating a connection. The argument -\&\fImode\fR may be one of the following options: -.IP "\s-1SSL_DEFAULT_STREAM_MODE_AUTO_BIDI\s0" 4 -.IX Item "SSL_DEFAULT_STREAM_MODE_AUTO_BIDI" -This is the default setting. If \fBSSL_write\fR\|(3) is called prior to any call to -\&\fBSSL_read\fR\|(3), a bidirectional client-initiated stream is created and bound as -the default stream. If \fBSSL_read\fR\|(3) is called prior to any call to -\&\fBSSL_write\fR\|(3), OpenSSL waits for an incoming stream from the peer (causing -\&\fBSSL_read\fR\|(3) to block if the connection is in blocking mode), and then binds -that stream as the default stream. Note that this incoming stream may be either -bidirectional or unidirectional; thus, this setting does not guarantee the -presence of a bidirectional stream when \fBSSL_read\fR\|(3) is called first. To -determine the type of a stream after a call to \fBSSL_read\fR\|(3), use -\&\fBSSL_get_stream_type\fR\|(3). -.IP "\s-1SSL_DEFAULT_STREAM_MODE_AUTO_UNI\s0" 4 -.IX Item "SSL_DEFAULT_STREAM_MODE_AUTO_UNI" -In this mode, if \fBSSL_write\fR\|(3) is called prior to any call to \fBSSL_read\fR\|(3), -a unidirectional client-initiated stream is created and bound as the default -stream. The behaviour is otherwise identical to that of -\&\fB\s-1SSL_DEFAULT_STREAM_MODE_AUTO_BIDI\s0\fR. The behaviour when \fBSSL_read\fR\|(3) is -called prior to any call to \fBSSL_write\fR\|(3) is unchanged. -.IP "\s-1SSL_DEFAULT_STREAM_MODE_NONE\s0" 4 -.IX Item "SSL_DEFAULT_STREAM_MODE_NONE" -Default stream creation is inhibited. This is the recommended mode of operation. -\&\fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) calls cannot be made on the \s-1QUIC\s0 connection -\&\s-1SSL\s0 object directly. You must obtain streams using \fBSSL_new_stream\fR\|(3) or -\&\fBSSL_accept_stream\fR\|(3) in order to communicate with the peer. -.PP -A default stream will not be automatically created on a \s-1QUIC\s0 connection \s-1SSL\s0 -object if the default stream mode is set to \fB\s-1SSL_DEFAULT_STREAM_MODE_NONE\s0\fR. -.PP -\&\fBSSL_set_incoming_stream_policy\fR\|(3) interacts significantly with the default -stream functionality. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_default_stream_mode()\fR returns 1 on success and 0 on failure. -.PP -\&\fBSSL_set_default_stream_mode()\fR fails if it is called after a default stream has -already been established. -.PP -These functions fail if called on a \s-1QUIC\s0 stream \s-1SSL\s0 object or on a non-QUIC \s-1SSL\s0 -object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_new_stream\fR\|(3), \fBSSL_accept_stream\fR\|(3), \fBSSL_free\fR\|(3), -\&\fBSSL_set_incoming_stream_policy\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_dh_auto.3ossl b/openssl-install/share/man/man3/SSL_set_dh_auto.3ossl deleted file mode 120000 index 838d6609..00000000 --- a/openssl-install/share/man/man3/SSL_set_dh_auto.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_dh_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_ecdh_auto.3ossl b/openssl-install/share/man/man3/SSL_set_ecdh_auto.3ossl deleted file mode 120000 index 3b8a967a..00000000 --- a/openssl-install/share/man/man3/SSL_set_ecdh_auto.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_ecdh.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_event_handling_mode.3ossl b/openssl-install/share/man/man3/SSL_set_event_handling_mode.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_set_event_handling_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_ex_data.3ossl b/openssl-install/share/man/man3/SSL_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/SSL_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_fd.3ossl b/openssl-install/share/man/man3/SSL_set_fd.3ossl deleted file mode 100644 index c02f9537..00000000 --- a/openssl-install/share/man/man3/SSL_set_fd.3ossl +++ /dev/null @@ -1,201 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_FD 3ossl" -.TH SSL_SET_FD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_fd, SSL_set_rfd, SSL_set_wfd \- connect the SSL object with a file descriptor -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set_fd(SSL *ssl, int fd); -\& int SSL_set_rfd(SSL *ssl, int fd); -\& int SSL_set_wfd(SSL *ssl, int fd); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_fd()\fR sets the file descriptor \fBfd\fR as the input/output facility -for the \s-1TLS/SSL\s0 (encrypted) side of \fBssl\fR. \fBfd\fR will typically be the -socket file descriptor of a network connection. -.PP -When performing the operation, a \fBsocket \s-1BIO\s0\fR is automatically created to -interface between the \fBssl\fR and \fBfd\fR. The \s-1BIO\s0 and hence the \s-1SSL\s0 engine -inherit the behaviour of \fBfd\fR. If \fBfd\fR is nonblocking, the \fBssl\fR will -also have nonblocking behaviour. -.PP -When used on a \s-1QUIC\s0 connection \s-1SSL\s0 object, a \fBdatagram \s-1BIO\s0\fR is automatically -created instead of a \fBsocket \s-1BIO\s0\fR. These functions fail if called -on a \s-1QUIC\s0 stream \s-1SSL\s0 object. -.PP -If there was already a \s-1BIO\s0 connected to \fBssl\fR, \fBBIO_free()\fR will be called -(for both the reading and writing side, if different). -.PP -\&\fBSSL_set_rfd()\fR and \fBSSL_set_wfd()\fR perform the respective action, but only -for the read channel or the write channel, which can be set independently. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0" 4 -The operation failed. Check the error stack to find out why. -.IP "1" 4 -.IX Item "1" -The operation succeeded. -.SH "NOTES" -.IX Header "NOTES" -On Windows, a socket handle is a 64\-bit data type (\s-1UINT_PTR\s0), which leads to a -compiler warning (conversion from '\s-1SOCKET\s0' to 'int', possible loss of data) when -passing the socket handle to SSL_set_*\fBfd()\fR. For the time being, this warning can -safely be ignored, because although the Microsoft documentation claims that the -upper limit is \s-1INVALID_SOCKET\-1\s0 (2^64 \- 2), in practice the current \fBsocket()\fR -implementation returns an index into the kernel handle table, the size of which -is limited to 2^24. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_fd\fR\|(3), \fBSSL_set_bio\fR\|(3), -\&\fBSSL_connect\fR\|(3), \fBSSL_accept\fR\|(3), -\&\fBSSL_shutdown\fR\|(3), \fBssl\fR\|(7) , \fBbio\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_feature_request_uint.3ossl b/openssl-install/share/man/man3/SSL_set_feature_request_uint.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_set_feature_request_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_generate_session_id.3ossl b/openssl-install/share/man/man3/SSL_set_generate_session_id.3ossl deleted file mode 120000 index 625534b5..00000000 --- a/openssl-install/share/man/man3/SSL_set_generate_session_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_generate_session_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_generic_value_uint.3ossl b/openssl-install/share/man/man3/SSL_set_generic_value_uint.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_set_generic_value_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_hostflags.3ossl b/openssl-install/share/man/man3/SSL_set_hostflags.3ossl deleted file mode 120000 index b101e006..00000000 --- a/openssl-install/share/man/man3/SSL_set_hostflags.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set1_host.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_incoming_stream_policy.3ossl b/openssl-install/share/man/man3/SSL_set_incoming_stream_policy.3ossl deleted file mode 100644 index fe5431fd..00000000 --- a/openssl-install/share/man/man3/SSL_set_incoming_stream_policy.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_INCOMING_STREAM_POLICY 3ossl" -.TH SSL_SET_INCOMING_STREAM_POLICY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_incoming_stream_policy, SSL_INCOMING_STREAM_POLICY_AUTO, -SSL_INCOMING_STREAM_POLICY_ACCEPT, -SSL_INCOMING_STREAM_POLICY_REJECT \- manage the QUIC incoming stream -policy -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_INCOMING_STREAM_POLICY_AUTO -\& #define SSL_INCOMING_STREAM_POLICY_ACCEPT -\& #define SSL_INCOMING_STREAM_POLICY_REJECT -\& -\& int SSL_set_incoming_stream_policy(SSL *conn, int policy, -\& uint64_t app_error_code); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_incoming_stream_policy()\fR policy changes the incoming stream policy for a -\&\s-1QUIC\s0 connection. Depending on the policy configured, OpenSSL \s-1QUIC\s0 may -automatically reject incoming streams initiated by the peer. This is intended to -ensure that legacy applications using single-stream operation with a default -stream on a \s-1QUIC\s0 connection \s-1SSL\s0 object are not passed remotely-initiated streams -by a peer which those applications are not prepared to handle. -.PP -\&\fIapp_error_code\fR is an application error code which will be used in any \s-1QUIC\s0 -\&\fB\s-1STOP_SENDING\s0\fR or \fB\s-1RESET_STREAM\s0\fR frames generated to implement the policy. The -default application error code is 0. -.PP -The valid values for \fIpolicy\fR are: -.IP "\s-1SSL_INCOMING_STREAM_POLICY_AUTO\s0" 4 -.IX Item "SSL_INCOMING_STREAM_POLICY_AUTO" -This is the default setting. Incoming streams are accepted according to the -following rules: -.RS 4 -.IP "\(bu" 4 -If the default stream mode (configured using \fBSSL_set_default_stream_mode\fR\|(3)) -is set to \fB\s-1SSL_DEFAULT_STREAM_MODE_AUTO_BIDI\s0\fR (the default) or -\&\fB\s-1SSL_DEFAULT_STREAM_MODE_AUTO_UNI\s0\fR, the incoming stream is rejected. -.IP "\(bu" 4 -Otherwise (where the default stream mode is \fB\s-1SSL_DEFAULT_STREAM_MODE_NONE\s0\fR), -the application is assumed to be stream aware, and the incoming stream is -accepted. -.RE -.RS 4 -.RE -.IP "\s-1SSL_INCOMING_STREAM_POLICY_ACCEPT\s0" 4 -.IX Item "SSL_INCOMING_STREAM_POLICY_ACCEPT" -Always accept incoming streams, allowing them to be dequeued using -\&\fBSSL_accept_stream\fR\|(3). -.IP "\s-1SSL_INCOMING_STREAM_POLICY_REJECT\s0" 4 -.IX Item "SSL_INCOMING_STREAM_POLICY_REJECT" -Always reject incoming streams. -.PP -Where an incoming stream is rejected, it is rejected immediately and it is not -possible to gain access to the stream using \fBSSL_accept_stream\fR\|(3). The stream -is rejected using \s-1QUIC\s0 \fB\s-1STOP_SENDING\s0\fR and \fB\s-1RESET_STREAM\s0\fR frames as -appropriate. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success and 0 on failure. -.PP -This function fails if called on a \s-1QUIC\s0 stream \s-1SSL\s0 object, or on a non-QUIC \s-1SSL\s0 -object. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_set_default_stream_mode\fR\|(3), \fBSSL_accept_stream\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_set_incoming_stream_policy()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_info_callback.3ossl b/openssl-install/share/man/man3/SSL_set_info_callback.3ossl deleted file mode 120000 index f805afdc..00000000 --- a/openssl-install/share/man/man3/SSL_set_info_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_info_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_max_cert_list.3ossl b/openssl-install/share/man/man3/SSL_set_max_cert_list.3ossl deleted file mode 120000 index 4861aab5..00000000 --- a/openssl-install/share/man/man3/SSL_set_max_cert_list.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_max_cert_list.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_set_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_set_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_max_pipelines.3ossl b/openssl-install/share/man/man3/SSL_set_max_pipelines.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_set_max_pipelines.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_max_proto_version.3ossl b/openssl-install/share/man/man3/SSL_set_max_proto_version.3ossl deleted file mode 120000 index 60193888..00000000 --- a/openssl-install/share/man/man3/SSL_set_max_proto_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_min_proto_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_max_send_fragment.3ossl b/openssl-install/share/man/man3/SSL_set_max_send_fragment.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_set_max_send_fragment.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_min_proto_version.3ossl b/openssl-install/share/man/man3/SSL_set_min_proto_version.3ossl deleted file mode 120000 index 60193888..00000000 --- a/openssl-install/share/man/man3/SSL_set_min_proto_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_min_proto_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_mode.3ossl b/openssl-install/share/man/man3/SSL_set_mode.3ossl deleted file mode 120000 index ea309712..00000000 --- a/openssl-install/share/man/man3/SSL_set_mode.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_mode.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_msg_callback.3ossl b/openssl-install/share/man/man3/SSL_set_msg_callback.3ossl deleted file mode 120000 index dff83f3f..00000000 --- a/openssl-install/share/man/man3/SSL_set_msg_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_msg_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_msg_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_set_msg_callback_arg.3ossl deleted file mode 120000 index dff83f3f..00000000 --- a/openssl-install/share/man/man3/SSL_set_msg_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_msg_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_num_tickets.3ossl b/openssl-install/share/man/man3/SSL_set_num_tickets.3ossl deleted file mode 120000 index 619b5ce0..00000000 --- a/openssl-install/share/man/man3/SSL_set_num_tickets.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_num_tickets.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_options.3ossl b/openssl-install/share/man/man3/SSL_set_options.3ossl deleted file mode 120000 index 742650be..00000000 --- a/openssl-install/share/man/man3/SSL_set_options.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_options.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_post_handshake_auth.3ossl b/openssl-install/share/man/man3/SSL_set_post_handshake_auth.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_set_post_handshake_auth.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_psk_client_callback.3ossl b/openssl-install/share/man/man3/SSL_set_psk_client_callback.3ossl deleted file mode 120000 index da6a3a7b..00000000 --- a/openssl-install/share/man/man3/SSL_set_psk_client_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_psk_client_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_psk_find_session_callback.3ossl b/openssl-install/share/man/man3/SSL_set_psk_find_session_callback.3ossl deleted file mode 120000 index 205e7e3e..00000000 --- a/openssl-install/share/man/man3/SSL_set_psk_find_session_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_psk_identity_hint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_psk_server_callback.3ossl b/openssl-install/share/man/man3/SSL_set_psk_server_callback.3ossl deleted file mode 120000 index 205e7e3e..00000000 --- a/openssl-install/share/man/man3/SSL_set_psk_server_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_psk_identity_hint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_psk_use_session_callback.3ossl b/openssl-install/share/man/man3/SSL_set_psk_use_session_callback.3ossl deleted file mode 120000 index da6a3a7b..00000000 --- a/openssl-install/share/man/man3/SSL_set_psk_use_session_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_psk_client_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_purpose.3ossl b/openssl-install/share/man/man3/SSL_set_purpose.3ossl deleted file mode 120000 index fd781e23..00000000 --- a/openssl-install/share/man/man3/SSL_set_purpose.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_quiet_shutdown.3ossl b/openssl-install/share/man/man3/SSL_set_quiet_shutdown.3ossl deleted file mode 120000 index 1bef418d..00000000 --- a/openssl-install/share/man/man3/SSL_set_quiet_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_quiet_shutdown.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_read_ahead.3ossl b/openssl-install/share/man/man3/SSL_set_read_ahead.3ossl deleted file mode 120000 index 095d1f88..00000000 --- a/openssl-install/share/man/man3/SSL_set_read_ahead.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_read_ahead.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_record_padding_callback.3ossl b/openssl-install/share/man/man3/SSL_set_record_padding_callback.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_set_record_padding_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_record_padding_callback_arg.3ossl b/openssl-install/share/man/man3/SSL_set_record_padding_callback_arg.3ossl deleted file mode 120000 index e72e4a8d..00000000 --- a/openssl-install/share/man/man3/SSL_set_record_padding_callback_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_record_padding_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_recv_max_early_data.3ossl b/openssl-install/share/man/man3/SSL_set_recv_max_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_set_recv_max_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_retry_verify.3ossl b/openssl-install/share/man/man3/SSL_set_retry_verify.3ossl deleted file mode 100644 index c5f9c9e1..00000000 --- a/openssl-install/share/man/man3/SSL_set_retry_verify.3ossl +++ /dev/null @@ -1,201 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_RETRY_VERIFY 3ossl" -.TH SSL_SET_RETRY_VERIFY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_retry_verify \- indicate that certificate verification should be retried -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set_retry_verify(SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_retry_verify()\fR should be called from the certificate verification -callback on a client when the application wants to indicate that the handshake -should be suspended and the control should be returned to the application. -\&\fBSSL_want_retry_verify\fR\|(3) will return 1 as a consequence until the handshake -is resumed again by the application, retrying the verification step. -.PP -Please refer to \fBSSL_CTX_set_cert_verify_callback\fR\|(3) for further details. -.SH "NOTES" -.IX Header "NOTES" -The effect of calling \fBSSL_set_retry_verify()\fR outside of the certificate -verification callback on the client side is undefined. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -SSL_set_retry \fBverify()\fR returns 1 on success, 0 otherwise. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The following code snippet shows how to obtain the \fB\s-1SSL\s0\fR object associated -with the \fBX509_STORE_CTX\fR to call the \fBSSL_set_retry_verify()\fR function: -.PP -.Vb 2 -\& int idx = SSL_get_ex_data_X509_STORE_CTX_idx(); -\& SSL *ssl; -\& -\& /* this should not happen but check anyway */ -\& if (idx < 0 -\& || (ssl = X509_STORE_CTX_get_ex_data(ctx, idx)) == NULL) -\& return 0; -\& -\& if (/* we need to retry verification callback */) -\& return SSL_set_retry_verify(ssl); -\& -\& /* do normal processing of the verification callback */ -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_connect\fR\|(3), \fBSSL_CTX_set_cert_verify_callback\fR\|(3), -\&\fBSSL_want_retry_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_set_retry_verify()\fR was added in OpenSSL 3.0.2 to replace backwards -incompatible handling of a negative return value from the verification -callback. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_rfd.3ossl b/openssl-install/share/man/man3/SSL_set_rfd.3ossl deleted file mode 120000 index ee4ad367..00000000 --- a/openssl-install/share/man/man3/SSL_set_rfd.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_fd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_security_callback.3ossl b/openssl-install/share/man/man3/SSL_set_security_callback.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_set_security_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_security_level.3ossl b/openssl-install/share/man/man3/SSL_set_security_level.3ossl deleted file mode 120000 index 34ae20ff..00000000 --- a/openssl-install/share/man/man3/SSL_set_security_level.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_security_level.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_session.3ossl b/openssl-install/share/man/man3/SSL_set_session.3ossl deleted file mode 100644 index 2dfe4130..00000000 --- a/openssl-install/share/man/man3/SSL_set_session.3ossl +++ /dev/null @@ -1,195 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_SESSION 3ossl" -.TH SSL_SET_SESSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_session \- set a TLS/SSL session to be used during TLS/SSL connect -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_set_session(SSL *ssl, SSL_SESSION *session); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_session()\fR sets \fBsession\fR to be used when the \s-1TLS/SSL\s0 connection -is to be established. \fBSSL_set_session()\fR is only useful for \s-1TLS/SSL\s0 clients. -When the session is set, the reference count of \fBsession\fR is incremented -by 1. If the session is not reused, the reference count is decremented -again during \fBSSL_connect()\fR. Whether the session was reused can be queried -with the \fBSSL_session_reused\fR\|(3) call. -.PP -If there is already a session set inside \fBssl\fR (because it was set with -\&\fBSSL_set_session()\fR before or because the same \fBssl\fR was already used for -a connection), \fBSSL_SESSION_free()\fR will be called for that session. -This is also the case when \fBsession\fR is a \s-1NULL\s0 pointer. If that old -session is still \fBopen\fR, it is considered bad and will be removed from the -session cache (if used). A session is considered open, if \fBSSL_shutdown\fR\|(3) was -not called for the connection (or at least \fBSSL_set_shutdown\fR\|(3) was used to -set the \s-1SSL_SENT_SHUTDOWN\s0 state). -.SH "NOTES" -.IX Header "NOTES" -\&\s-1SSL_SESSION\s0 objects keep internal link information about the session cache -list, when being inserted into one \s-1SSL_CTX\s0 object's session cache. -One \s-1SSL_SESSION\s0 object, regardless of its reference count, must therefore -only be used with one \s-1SSL_CTX\s0 object (and the \s-1SSL\s0 objects created -from this \s-1SSL_CTX\s0 object). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can occur: -.IP "0" 4 -The operation failed; check the error stack to find out the reason. -.IP "1" 4 -.IX Item "1" -The operation succeeded. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_SESSION_free\fR\|(3), -\&\fBSSL_get_session\fR\|(3), -\&\fBSSL_session_reused\fR\|(3), -\&\fBSSL_CTX_set_session_cache_mode\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_session_id_context.3ossl b/openssl-install/share/man/man3/SSL_set_session_id_context.3ossl deleted file mode 120000 index 0f3fd73a..00000000 --- a/openssl-install/share/man/man3/SSL_set_session_id_context.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_session_id_context.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_session_secret_cb.3ossl b/openssl-install/share/man/man3/SSL_set_session_secret_cb.3ossl deleted file mode 100644 index 3b382f7f..00000000 --- a/openssl-install/share/man/man3/SSL_set_session_secret_cb.3ossl +++ /dev/null @@ -1,201 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_SESSION_SECRET_CB 3ossl" -.TH SSL_SET_SESSION_SECRET_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_session_secret_cb, tls_session_secret_cb_fn -\&\- set the session secret callback -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*tls_session_secret_cb_fn)(SSL *s, void *secret, int *secret_len, -\& STACK_OF(SSL_CIPHER) *peer_ciphers, -\& const SSL_CIPHER **cipher, void *arg); -\& -\& int SSL_set_session_secret_cb(SSL *s, -\& tls_session_secret_cb_fn session_secret_cb, -\& void *arg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_session_secret_cb()\fR sets the session secret callback to be used -(\fIsession_secret_cb\fR), and an optional argument (\fIarg\fR) to be passed to that -callback when it is called. This is only useful for an implementation of -EAP-FAST (\s-1RFC4851\s0). The presence of the callback also modifies the internal -OpenSSL \s-1TLS\s0 state machine to match the modified \s-1TLS\s0 behaviour as described in -\&\s-1RFC4851.\s0 Therefore this callback should not be used except when implementing -EAP-FAST. -.PP -The callback is expected to set the master secret to be used by filling in the -data pointed to by \fI*secret\fR. The size of the secret buffer is initially -available in \fI*secret_len\fR and may be updated by the callback (but must not be -larger than the initial value). -.PP -On the server side the set of ciphersuites offered by the peer is provided in -the \fIpeer_ciphers\fR stack. Optionally the callback may select the preferred -ciphersuite by setting it in \fI*cipher\fR. -.PP -On the client side the \fIpeer_ciphers\fR stack will always be \s-1NULL.\s0 The callback -may specify the preferred cipher in \fI*cipher\fR and this will be associated with -the \fB\s-1SSL_SESSION\s0\fR \- but it does not affect the ciphersuite selected by the -server. -.PP -The callback is also supplied with an additional argument in \fIarg\fR which is the -argument that was provided to the original \fBSSL_set_session_secret_cb()\fR call. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_session_secret_cb()\fR returns 1 on success and 0 on failure. -.PP -If the callback returns 1 then this indicates it has successfully set the -secret. A return value of 0 indicates that the secret has not been set. On the -client this will cause an immediate abort of the handshake. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), -\&\fBSSL_get_session\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_shutdown.3ossl b/openssl-install/share/man/man3/SSL_set_shutdown.3ossl deleted file mode 100644 index 6c7e3347..00000000 --- a/openssl-install/share/man/man3/SSL_set_shutdown.3ossl +++ /dev/null @@ -1,214 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_SHUTDOWN 3ossl" -.TH SSL_SET_SHUTDOWN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_shutdown, SSL_get_shutdown \- manipulate shutdown state of an SSL connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_set_shutdown(SSL *ssl, int mode); -\& -\& int SSL_get_shutdown(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_shutdown()\fR sets the shutdown state of \fBssl\fR to \fBmode\fR. -.PP -\&\fBSSL_get_shutdown()\fR returns the shutdown mode of \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -The shutdown state of an ssl connection is a bit-mask of: -.IP "0" 4 -No shutdown setting, yet. -.IP "\s-1SSL_SENT_SHUTDOWN\s0" 4 -.IX Item "SSL_SENT_SHUTDOWN" -A close_notify shutdown alert was sent to the peer, the connection is being -considered closed and the session is closed and correct. -.IP "\s-1SSL_RECEIVED_SHUTDOWN\s0" 4 -.IX Item "SSL_RECEIVED_SHUTDOWN" -A shutdown alert was received form the peer, either a normal close_notify -or a fatal error. -.PP -\&\s-1SSL_SENT_SHUTDOWN\s0 and \s-1SSL_RECEIVED_SHUTDOWN\s0 can be set at the same time. -.PP -The shutdown state of the connection is used to determine the state of -the ssl session. If the session is still open, when -\&\fBSSL_clear\fR\|(3) or \fBSSL_free\fR\|(3) is called, -it is considered bad and removed according to \s-1RFC2246.\s0 -The actual condition for a correctly closed session is \s-1SSL_SENT_SHUTDOWN\s0 -(according to the \s-1TLS RFC,\s0 it is acceptable to only send the close_notify -alert but to not wait for the peer's answer, when the underlying connection -is closed). -\&\fBSSL_set_shutdown()\fR can be used to set this state without sending a -close alert to the peer (see \fBSSL_shutdown\fR\|(3)). -.PP -If a close_notify was received, \s-1SSL_RECEIVED_SHUTDOWN\s0 will be set, -for setting \s-1SSL_SENT_SHUTDOWN\s0 the application must however still call -\&\fBSSL_shutdown\fR\|(3) or \fBSSL_set_shutdown()\fR itself. -.PP -\&\fBSSL_set_shutdown()\fR is not supported for \s-1QUIC SSL\s0 objects. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_shutdown()\fR does not return diagnostic information. -.PP -\&\fBSSL_get_shutdown()\fR returns the current shutdown state as set or based -on the actual connection state. -.PP -\&\fBSSL_get_shutdown()\fR returns 0 if called on a \s-1QUIC\s0 stream \s-1SSL\s0 object. If it -is called on a \s-1QUIC\s0 connection \s-1SSL\s0 object, it returns a value with -\&\s-1SSL_SENT_SHUTDOWN\s0 set if \s-1CONNECTION_CLOSE\s0 has been sent to the peer and -it returns a value with \s-1SSL_RECEIVED_SHUTDOWN\s0 set if \s-1CONNECTION_CLOSE\s0 -has been received from the peer or the \s-1QUIC\s0 connection is fully terminated -for other reasons. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_shutdown\fR\|(3), -\&\fBSSL_CTX_set_quiet_shutdown\fR\|(3), -\&\fBSSL_clear\fR\|(3), \fBSSL_free\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_split_send_fragment.3ossl b/openssl-install/share/man/man3/SSL_set_split_send_fragment.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_set_split_send_fragment.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_srp_server_param.3ossl b/openssl-install/share/man/man3/SSL_set_srp_server_param.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_set_srp_server_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_srp_server_param_pw.3ossl b/openssl-install/share/man/man3/SSL_set_srp_server_param_pw.3ossl deleted file mode 120000 index f1f8afaf..00000000 --- a/openssl-install/share/man/man3/SSL_set_srp_server_param_pw.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_srp_password.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_ssl_method.3ossl b/openssl-install/share/man/man3/SSL_set_ssl_method.3ossl deleted file mode 120000 index 05c88c50..00000000 --- a/openssl-install/share/man/man3/SSL_set_ssl_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ssl_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_time.3ossl b/openssl-install/share/man/man3/SSL_set_time.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_set_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_timeout.3ossl b/openssl-install/share/man/man3/SSL_set_timeout.3ossl deleted file mode 120000 index 6d5ef06f..00000000 --- a/openssl-install/share/man/man3/SSL_set_timeout.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_SESSION_get_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tlsext_host_name.3ossl b/openssl-install/share/man/man3/SSL_set_tlsext_host_name.3ossl deleted file mode 120000 index f62c51f3..00000000 --- a/openssl-install/share/man/man3/SSL_set_tlsext_host_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_servername_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tlsext_max_fragment_length.3ossl b/openssl-install/share/man/man3/SSL_set_tlsext_max_fragment_length.3ossl deleted file mode 120000 index 0a2484a3..00000000 --- a/openssl-install/share/man/man3/SSL_set_tlsext_max_fragment_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_split_send_fragment.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tlsext_status_ocsp_resp.3ossl b/openssl-install/share/man/man3/SSL_set_tlsext_status_ocsp_resp.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_set_tlsext_status_ocsp_resp.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tlsext_status_type.3ossl b/openssl-install/share/man/man3/SSL_set_tlsext_status_type.3ossl deleted file mode 120000 index 89a272ec..00000000 --- a/openssl-install/share/man/man3/SSL_set_tlsext_status_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_status_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tlsext_use_srtp.3ossl b/openssl-install/share/man/man3/SSL_set_tlsext_use_srtp.3ossl deleted file mode 120000 index ab61a632..00000000 --- a/openssl-install/share/man/man3/SSL_set_tlsext_use_srtp.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tlsext_use_srtp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tmp_dh.3ossl b/openssl-install/share/man/man3/SSL_set_tmp_dh.3ossl deleted file mode 120000 index 838d6609..00000000 --- a/openssl-install/share/man/man3/SSL_set_tmp_dh.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_dh_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tmp_dh_callback.3ossl b/openssl-install/share/man/man3/SSL_set_tmp_dh_callback.3ossl deleted file mode 120000 index 838d6609..00000000 --- a/openssl-install/share/man/man3/SSL_set_tmp_dh_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_dh_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_tmp_ecdh.3ossl b/openssl-install/share/man/man3/SSL_set_tmp_ecdh.3ossl deleted file mode 120000 index 3b8a967a..00000000 --- a/openssl-install/share/man/man3/SSL_set_tmp_ecdh.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_tmp_ecdh.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_trust.3ossl b/openssl-install/share/man/man3/SSL_set_trust.3ossl deleted file mode 120000 index fd781e23..00000000 --- a/openssl-install/share/man/man3/SSL_set_trust.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_value_uint.3ossl b/openssl-install/share/man/man3/SSL_set_value_uint.3ossl deleted file mode 120000 index 56146889..00000000 --- a/openssl-install/share/man/man3/SSL_set_value_uint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_value_uint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_verify.3ossl b/openssl-install/share/man/man3/SSL_set_verify.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_set_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_verify_depth.3ossl b/openssl-install/share/man/man3/SSL_set_verify_depth.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_set_verify_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_set_verify_result.3ossl b/openssl-install/share/man/man3/SSL_set_verify_result.3ossl deleted file mode 100644 index eced36ca..00000000 --- a/openssl-install/share/man/man3/SSL_set_verify_result.3ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SET_VERIFY_RESULT 3ossl" -.TH SSL_SET_VERIFY_RESULT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_set_verify_result \- override result of peer certificate verification -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void SSL_set_verify_result(SSL *ssl, long verify_result); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_set_verify_result()\fR sets \fBverify_result\fR of the object \fBssl\fR to be the -result of the verification of the X509 certificate presented by the peer, -if any. -.SH "NOTES" -.IX Header "NOTES" -\&\fBSSL_set_verify_result()\fR overrides the verification result. It only changes -the verification result of the \fBssl\fR object. It does not become part of the -established session, so if the session is to be reused later, the original -value will reappear. -.PP -The valid codes for \fBverify_result\fR are documented in \fBopenssl\-verify\fR\|(1). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_set_verify_result()\fR does not provide a return value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_verify_result\fR\|(3), -\&\fBSSL_get_peer_certificate\fR\|(3), -\&\fBopenssl\-verify\fR\|(1) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_set_wfd.3ossl b/openssl-install/share/man/man3/SSL_set_wfd.3ossl deleted file mode 120000 index ee4ad367..00000000 --- a/openssl-install/share/man/man3/SSL_set_wfd.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_fd.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_shutdown.3ossl b/openssl-install/share/man/man3/SSL_shutdown.3ossl deleted file mode 100644 index 8be0fb9f..00000000 --- a/openssl-install/share/man/man3/SSL_shutdown.3ossl +++ /dev/null @@ -1,528 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_SHUTDOWN 3ossl" -.TH SSL_SHUTDOWN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_shutdown, SSL_shutdown_ex \- shut down a TLS/SSL or QUIC connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_shutdown(SSL *ssl); -\& -\& typedef struct ssl_shutdown_ex_args_st { -\& uint64_t quic_error_code; -\& const char *quic_reason; -\& } SSL_SHUTDOWN_EX_ARGS; -\& -\& _\|_owur int SSL_shutdown_ex(SSL *ssl, uint64_t flags, -\& const SSL_SHUTDOWN_EX_ARGS *args, -\& size_t args_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_shutdown()\fR shuts down an active connection represented by an \s-1SSL\s0 object. -.PP -\&\fBSSL_shutdown_ex()\fR is an extended version of \fBSSL_shutdown()\fR. If non-NULL, \fIargs\fR -must point to a \fB\s-1SSL_SHUTDOWN_EX_ARGS\s0\fR structure and \fIargs_len\fR must be set to -\&\f(CW\*(C`sizeof(SSL_SHUTDOWN_EX_ARGS)\*(C'\fR. The \fB\s-1SSL_SHUTDOWN_EX_ARGS\s0\fR structure must be -zero-initialized. If \fIargs\fR is \s-1NULL,\s0 the behaviour is the same as passing a -zero-initialised \fB\s-1SSL_SHUTDOWN_EX_ARGS\s0\fR structure. Currently, all extended -arguments relate to usage with \s-1QUIC,\s0 therefore this call functions identically -to \fBSSL_shutdown()\fR when not being used with \s-1QUIC.\s0 -.PP -While the general operation of \fBSSL_shutdown()\fR is common between protocols, the -exact nature of how a shutdown is performed depends on the underlying protocol -being used. See the section below pertaining to each protocol for more -information. -.PP -In general, calling \fBSSL_shutdown()\fR in nonblocking mode will initiate the -shutdown process and return 0 to indicate that the shutdown process has not yet -completed. Once the shutdown process has completed, subsequent calls to -\&\fBSSL_shutdown()\fR will return 1. See the \s-1RETURN VALUES\s0 section for more -information. -.PP -\&\fBSSL_shutdown()\fR should not be called if a previous fatal error has occurred on a -connection; i.e., if \fBSSL_get_error\fR\|(3) has returned \fB\s-1SSL_ERROR_SYSCALL\s0\fR or -\&\fB\s-1SSL_ERROR_SSL\s0\fR. -.SH "TLS AND DTLS-SPECIFIC CONSIDERATIONS" -.IX Header "TLS AND DTLS-SPECIFIC CONSIDERATIONS" -Shutdown for \s-1SSL/TLS\s0 and \s-1DTLS\s0 is implemented in terms of the \s-1SSL/TLS/DTLS\s0 -close_notify alert message. The shutdown process for \s-1SSL/TLS\s0 and \s-1DTLS\s0 -consists of two steps: -.IP "\(bu" 4 -A close_notify shutdown alert message is sent to the peer. -.IP "\(bu" 4 -A close_notify shutdown alert message is received from the peer. -.PP -These steps can occur in either order depending on whether the connection -shutdown process was first initiated by the local application or by the peer. -.SS "Locally-Initiated Shutdown" -.IX Subsection "Locally-Initiated Shutdown" -Calling \fBSSL_shutdown()\fR on a \s-1SSL/TLS\s0 or \s-1DTLS SSL\s0 object initiates the shutdown -process and causes OpenSSL to try to send a close_notify shutdown alert to the -peer. The shutdown process will then be considered completed once the peer -responds in turn with a close_notify shutdown alert message. -.PP -Calling \fBSSL_shutdown()\fR only closes the write direction of the connection; the -read direction is closed by the peer. Once \fBSSL_shutdown()\fR is called, -\&\fBSSL_write\fR\|(3) can no longer be used, but \fBSSL_read\fR\|(3) may still be used -until the peer decides to close the connection in turn. The peer might -continue sending data for some period of time before handling the local -application's shutdown indication. -.PP -\&\fBSSL_shutdown()\fR does not affect an underlying network connection such as a \s-1TCP\s0 -connection, which remains open. -.SS "Remotely-Initiated Shutdown" -.IX Subsection "Remotely-Initiated Shutdown" -If the peer was the first to initiate the shutdown process by sending a -close_notify alert message, an application will be notified of this as an \s-1EOF\s0 -condition when calling -\&\fBSSL_read\fR\|(3) (i.e., \fBSSL_read\fR\|(3) will fail and \fBSSL_get_error\fR\|(3) will -return \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR), after all application data sent by the peer -prior to initiating the shutdown has been read. An application should handle -this condition by calling \fBSSL_shutdown()\fR to respond with a close_notify alert in -turn, completing the shutdown process, though it may choose to write additional -application data using \fBSSL_write\fR\|(3) before doing so. If an application does -not call \fBSSL_shutdown()\fR in this case, a close_notify alert will not be sent and -the behaviour will not be fully standards compliant. -.SS "Shutdown Lifecycle" -.IX Subsection "Shutdown Lifecycle" -Regardless of whether a shutdown was initiated locally or by the peer, if the -underlying \s-1BIO\s0 is blocking, a call to \fBSSL_shutdown()\fR will return firstly once a -close_notify alert message is written to the peer (returning 0), and upon a -second and subsequent call, once a corresponding message is received from the -peer (returning 1 and completing the shutdown process). Calls to \fBSSL_shutdown()\fR -with a blocking underlying \s-1BIO\s0 will also return if an error occurs. -.PP -If the underlying \s-1BIO\s0 is nonblocking and the shutdown process is not yet -complete (for example, because a close_notify alert message has not yet been -received from the peer, or because a close_notify alert message needs to be sent -but would currently block), \fBSSL_shutdown()\fR returns 0 to indicate that the -shutdown process is still ongoing; in this case, a call to \fBSSL_get_error\fR\|(3) -will yield \fB\s-1SSL_ERROR_WANT_READ\s0\fR or \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. -.PP -An application can then detect completion of the shutdown process by calling -\&\fBSSL_shutdown()\fR again repeatedly until it returns 1, indicating that the shutdown -process is complete (with a close_notify alert having both been sent and -received). -.PP -However, the preferred method of waiting for the shutdown to complete is to use -\&\fBSSL_read\fR\|(3) until \fBSSL_get_error\fR\|(3) indicates \s-1EOF\s0 by returning -\&\fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR. This ensures any data received immediately before the -peer's close_notify alert is still provided to the application. It also ensures -any final handshake-layer messages received are processed (for example, messages -issuing new session tickets). -.PP -If this approach is not used, the second call to \fBSSL_shutdown()\fR (to complete the -shutdown by confirming receipt of the peer's close_notify message) will fail if -it is called when the application has not read all pending application data -sent by the peer using \fBSSL_read\fR\|(3). -.PP -When calling \fBSSL_shutdown()\fR, the \fB\s-1SSL_SENT_SHUTDOWN\s0\fR flag is set once an -attempt is made to send a close_notify alert, regardless of whether the attempt -was successful. The \fB\s-1SSL_RECEIVED_SHUTDOWN\s0\fR flag is set once a close_notify -alert is received, which may occur during any call which processes incoming data -from the network, such as \fBSSL_read\fR\|(3) or \fBSSL_shutdown()\fR. These flags -may be checked using \fBSSL_get_shutdown\fR\|(3). -.SS "Fast Shutdown" -.IX Subsection "Fast Shutdown" -Alternatively, it is acceptable for an application to call \fBSSL_shutdown()\fR once -(such that it returns 0) and then close the underlying connection without -waiting for the peer's response. This allows for a more rapid shutdown process -if the application does not wish to wait for the peer. -.PP -This alternative \*(L"fast shutdown\*(R" approach should only be done if it is known -that the peer will not send more data, otherwise there is a risk of an -application exposing itself to a truncation attack. The full \fBSSL_shutdown()\fR -process, in which both parties send close_notify alerts and \fBSSL_shutdown()\fR -returns 1, provides a cryptographically authenticated indication of the end of a -connection. -.PP -This approach of a single \fBSSL_shutdown()\fR call without waiting is preferable to -simply calling \fBSSL_free\fR\|(3) or \fBSSL_clear\fR\|(3) as calling \fBSSL_shutdown()\fR -beforehand makes an \s-1SSL\s0 session eligible for subsequent reuse and notifies the -peer of connection shutdown. -.PP -The fast shutdown approach can only be used if there is no intention to reuse -the underlying connection (e.g. a \s-1TCP\s0 connection) for further communication; in -this case, the full shutdown process must be performed to ensure -synchronisation. -.SS "Effects on Session Reuse" -.IX Subsection "Effects on Session Reuse" -Calling \fBSSL_shutdown()\fR sets the \s-1SSL_SENT_SHUTDOWN\s0 flag (see -\&\fBSSL_set_shutdown\fR\|(3)), regardless of whether the transmission of the -close_notify alert was successful or not. This makes the \s-1SSL\s0 session eligible -for reuse; the \s-1SSL\s0 session is considered properly closed and can be reused for -future connections. -.SS "Quiet Shutdown" -.IX Subsection "Quiet Shutdown" -\&\fBSSL_shutdown()\fR can be modified to set the connection to the \*(L"shutdown\*(R" -state without actually sending a close_notify alert message; see -\&\fBSSL_CTX_set_quiet_shutdown\fR\|(3). When \*(L"quiet shutdown\*(R" is enabled, -\&\fBSSL_shutdown()\fR will always succeed and return 1 immediately. -.PP -This is not standards-compliant behaviour. It should only be done when the -application protocol in use enables the peer to ensure that all data has been -received, such that it doesn't need to wait for a close_notify alert, otherwise -application data may be truncated unexpectedly. -.SS "Non-Compliant Peers" -.IX Subsection "Non-Compliant Peers" -There are \s-1SSL/TLS\s0 implementations that never send the required close_notify -alert message but simply close the underlying transport (e.g. a \s-1TCP\s0 connection) -instead. This will ordinarily result in an error being generated. -.PP -If compatibility with such peers is desired, the option -\&\fB\s-1SSL_OP_IGNORE_UNEXPECTED_EOF\s0\fR can be set. For more information, see -\&\fBSSL_CTX_set_options\fR\|(3). -.PP -Note that use of this option means that the \s-1EOF\s0 condition for application data -does not receive cryptographic protection, and therefore renders an application -potentially vulnerable to truncation attacks. Thus, this option must only be -used in conjunction with an application protocol which indicates unambiguously -when all data has been received. -.PP -An alternative approach is to simply avoid calling \fBSSL_read\fR\|(3) if it is known -that no more data is going to be sent. This requires an application protocol -which indicates unambiguously when all data has been sent. -.SS "Session Ticket Handling" -.IX Subsection "Session Ticket Handling" -If a client application only writes to a \s-1SSL/TLS\s0 or \s-1DTLS\s0 connection and never -reads, OpenSSL may never process new \s-1SSL/TLS\s0 session tickets sent by the server. -This is because OpenSSL ordinarily processes handshake messages received from a -peer during calls to \fBSSL_read\fR\|(3) by the application. -.PP -Therefore, client applications which only write and do not read but which wish -to benefit from session resumption are advised to perform a complete shutdown -procedure by calling \fBSSL_shutdown()\fR until it returns 1, as described above. This -will ensure there is an opportunity for \s-1SSL/TLS\s0 session ticket messages to be -received and processed by OpenSSL. -.SH "QUIC-SPECIFIC SHUTDOWN CONSIDERATIONS" -.IX Header "QUIC-SPECIFIC SHUTDOWN CONSIDERATIONS" -When used with a \s-1QUIC\s0 connection \s-1SSL\s0 object, \fBSSL_shutdown()\fR initiates a \s-1QUIC\s0 -immediate close using \s-1QUIC\s0 \fB\s-1CONNECTION_CLOSE\s0\fR frames. -.PP -\&\fBSSL_shutdown()\fR cannot be used on \s-1QUIC\s0 stream \s-1SSL\s0 objects. To conclude a stream -normally, see \fBSSL_stream_conclude\fR\|(3); to perform a non-normal stream -termination, see \fBSSL_stream_reset\fR\|(3). -.PP -\&\fBSSL_shutdown_ex()\fR may be used instead of \fBSSL_shutdown()\fR by an application to -provide additional information to the peer on the reason why a connection is -being shut down. The information which can be provided is as follows: -.IP "\fIquic_error_code\fR" 4 -.IX Item "quic_error_code" -An optional 62\-bit application error code to be signalled to the peer. The value -must be in the range [0, 2**62\-1], else the call to \fBSSL_shutdown_ex()\fR fails. If -not provided, an error code of 0 is used by default. -.IP "\fIquic_reason\fR" 4 -.IX Item "quic_reason" -An optional zero-terminated (\s-1UTF\-8\s0) reason string to be signalled to the peer. -The application is responsible for providing a valid \s-1UTF\-8\s0 string and OpenSSL -will not validate the string. If a reason is not provided, or \fBSSL_shutdown()\fR is -used, a zero-length string is used as the reason. If provided, the reason string -is copied and stored inside the \s-1QUIC\s0 connection \s-1SSL\s0 object and need not remain -allocated after the call to \fBSSL_shutdown_ex()\fR returns. Reason strings are -bounded by the path \s-1MTU\s0 and may be silently truncated if they are too long to -fit in a \s-1QUIC\s0 packet. -.Sp -Reason strings are intended for human diagnostic purposes only, and should not -be used for application signalling. -.PP -The arguments to \fBSSL_shutdown_ex()\fR are used only on the first call to -\&\fBSSL_shutdown_ex()\fR (or \fBSSL_shutdown()\fR) for a given \s-1QUIC\s0 connection \s-1SSL\s0 object. -These arguments are ignored on subsequent calls. -.PP -These functions do not affect an underlying network \s-1BIO\s0 or the resource it -represents; for example, a \s-1UDP\s0 datagram provided to a \s-1QUIC\s0 connection as the -network \s-1BIO\s0 will remain open. -.PP -Note that when using \s-1QUIC,\s0 an application must call \fBSSL_shutdown()\fR if it wants -to ensure that all transmitted data was received by the peer. This is unlike a -\&\s-1TLS/TCP\s0 connection, where reliable transmission of buffered data is the -responsibility of the operating system. If an application calls \fBSSL_free()\fR on a -\&\s-1QUIC\s0 connection \s-1SSL\s0 object or exits before completing the shutdown process using -\&\fBSSL_shutdown()\fR, data which was written by the application using \fBSSL_write()\fR, but -could not yet be transmitted, or which was sent but lost in the network, may not -be received by the peer. -.PP -When using \s-1QUIC,\s0 calling \fBSSL_shutdown()\fR allows internal network event processing -to be performed. It is important that this processing is performed regularly, -whether during connection usage or during shutdown. If an application is not -using thread assisted mode, an application conducting shutdown should either -ensure that \fBSSL_shutdown()\fR is called regularly, or alternatively ensure that -\&\fBSSL_handle_events()\fR is called regularly. See \fBopenssl\-quic\fR\|(7) and -\&\fBSSL_handle_events\fR\|(3) for more information. -.SS "Application Data Drainage Behaviour" -.IX Subsection "Application Data Drainage Behaviour" -When using \s-1QUIC,\s0 \fBSSL_shutdown()\fR or \fBSSL_shutdown_ex()\fR ordinarily waits until all -data written to a stream by an application has been acknowledged by the peer. In -other words, the shutdown process waits until all data written by the -application has been sent to the peer, and until the receipt of all such data is -acknowledged by the peer. Only once this process is completed is the shutdown -considered complete. -.PP -An exception to this is streams which terminated in a non-normal fashion, for -example due to a stream reset; only streams which are non-terminated at the time -\&\fBSSL_shutdown()\fR is called, or which terminated in a normal fashion, have their -pending send buffers flushed in this manner. -.PP -This behaviour of flushing streams during the shutdown process can be skipped by -setting the \fB\s-1SSL_SHUTDOWN_FLAG_NO_STREAM_FLUSH\s0\fR flag in a call to -\&\fBSSL_shutdown_ex()\fR; in this case, data remaining in stream send buffers may not -be transmitted to the peer. This flag may be used when a non-normal application -condition has occurred and the delivery of data written to streams via -\&\fBSSL_write\fR\|(3) is no longer relevant. -.SS "Shutdown Mode" -.IX Subsection "Shutdown Mode" -Aspects of how \s-1QUIC\s0 handles connection closure must be taken into account by -applications. Ordinarily, \s-1QUIC\s0 expects a connection to continue to be serviced -for a substantial period of time after it is nominally closed. This is necessary -to ensure that any connection closure notification sent to the peer was -successfully received. However, a consequence of this is that a fully -RFC-compliant \s-1QUIC\s0 connection closure process could take of the order of -seconds. This may be unsuitable for some applications, such as short-lived -processes which need to exit immediately after completing an application-layer -transaction. -.PP -As such, there are two shutdown modes available to users of \s-1QUIC\s0 connection \s-1SSL\s0 -objects: -.IP "\s-1RFC\s0 compliant shutdown mode" 4 -.IX Item "RFC compliant shutdown mode" -This is the default behaviour. The shutdown process may take a period of time up -to three times the current estimated \s-1RTT\s0 to the peer. It is possible for the -closure process to complete much faster in some circumstances but this cannot be -relied upon. -.Sp -In blocking mode, the function will return once the closure process is complete. -In nonblocking mode, \fBSSL_shutdown_ex()\fR should be called until it returns 1, -indicating the closure process is complete and the connection is now fully shut -down. -.IP "Rapid shutdown mode" 4 -.IX Item "Rapid shutdown mode" -In this mode, the peer is notified of connection closure on a best effort basis -by sending a single \s-1QUIC\s0 packet. If that \s-1QUIC\s0 packet is lost, the peer will not -know that the connection has terminated until the negotiated idle timeout (if -any) expires. -.Sp -This will generally return 0 on success, indicating that the connection has not -yet been fully shut down (unless it has already done so, in which case it will -return 1). -.PP -If \fB\s-1SSL_SHUTDOWN_FLAG_RAPID\s0\fR is specified in \fIflags\fR, a rapid shutdown is -performed, otherwise an RFC-compliant shutdown is performed. -.PP -If an application calls \fBSSL_shutdown_ex()\fR with \fB\s-1SSL_SHUTDOWN_FLAG_RAPID\s0\fR, an -application can subsequently change its mind about performing a rapid shutdown -by making a subsequent call to \fBSSL_shutdown_ex()\fR without the flag set. -.SS "Peer-Initiated Shutdown" -.IX Subsection "Peer-Initiated Shutdown" -In some cases, an application may wish to wait for a shutdown initiated by the -peer rather than triggered locally. To do this, call \fBSSL_shutdown_ex()\fR with -\&\fI\s-1SSL_SHUTDOWN_FLAG_WAIT_PEER\s0\fR specified in \fIflags\fR. In blocking mode, this -waits until the peer initiates a shutdown or the connection otherwise becomes -terminated for another reason. In nonblocking mode it exits immediately with -either success or failure depending on whether a shutdown has occurred. -.PP -If a locally initiated shutdown has already been triggered or the connection has -started terminating for another reason, this flag has no effect. -.PP -\&\fB\s-1SSL_SHUTDOWN_FLAG_WAIT_PEER\s0\fR implies \fB\s-1SSL_SHUTDOWN_FLAG_NO_STREAM_FLUSH\s0\fR, as -stream data cannot be flushed after a peer closes the connection. Stream data -may still be sent to the peer in any time spent waiting before the peer closes -the connection, though there is no guarantee of this. -.SS "Nonblocking Mode" -.IX Subsection "Nonblocking Mode" -\&\fBSSL_shutdown()\fR and \fBSSL_shutdown_ex()\fR block if the connection is configured in -blocking mode. This may be overridden by specifying -\&\fB\s-1SSL_SHUTDOWN_FLAG_NO_BLOCK\s0\fR in \fIflags\fR when calling \fBSSL_shutdown_ex()\fR, which -causes the call to operate as though in nonblocking mode. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -For both \fBSSL_shutdown()\fR and \fBSSL_shutdown_ex()\fR the following return values can occur: -.IP "0" 4 -The shutdown process is ongoing and has not yet completed. -.Sp -For \s-1TLS\s0 and \s-1DTLS,\s0 this means that a close_notify alert has been sent but the -peer has not yet replied in turn with its own close_notify. -.Sp -For \s-1QUIC\s0 connection \s-1SSL\s0 objects, a \s-1CONNECTION_CLOSE\s0 frame may have been -sent but the connection closure process has not yet completed. -.Sp -Unlike most other functions, returning 0 does not indicate an error. -\&\fBSSL_get_error\fR\|(3) should not be called; it may misleadingly indicate an error -even though no error occurred. -.IP "1" 4 -.IX Item "1" -The shutdown was successfully completed. -.Sp -For \s-1TLS\s0 and \s-1DTLS,\s0 this means that a close_notify alert was sent and the peer's -close_notify alert was received. -.Sp -For \s-1QUIC\s0 connection \s-1SSL\s0 objects, this means that the connection closure process -has completed. -.IP "<0" 4 -.IX Item "<0" -The shutdown was not successful. -Call \fBSSL_get_error\fR\|(3) with the return value \fBret\fR to find out the reason. -It can occur if an action is needed to continue the operation for nonblocking -BIOs. -.Sp -It can also occur when not all data was read using \fBSSL_read()\fR, or if called -on a \s-1QUIC\s0 stream \s-1SSL\s0 object. -.Sp -This value is also returned when called on \s-1QUIC\s0 stream \s-1SSL\s0 objects. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_error\fR\|(3), \fBSSL_connect\fR\|(3), -\&\fBSSL_accept\fR\|(3), \fBSSL_set_shutdown\fR\|(3), -\&\fBSSL_CTX_set_quiet_shutdown\fR\|(3), \fBSSL_CTX_set_options\fR\|(3) -\&\fBSSL_clear\fR\|(3), \fBSSL_free\fR\|(3), -\&\fBssl\fR\|(7), \fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_shutdown_ex()\fR function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_shutdown_ex.3ossl b/openssl-install/share/man/man3/SSL_shutdown_ex.3ossl deleted file mode 120000 index 035fd025..00000000 --- a/openssl-install/share/man/man3/SSL_shutdown_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_shutdown.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_state_string.3ossl b/openssl-install/share/man/man3/SSL_state_string.3ossl deleted file mode 100644 index 322255d3..00000000 --- a/openssl-install/share/man/man3/SSL_state_string.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_STATE_STRING 3ossl" -.TH SSL_STATE_STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_state_string, SSL_state_string_long \- get textual description of state of an SSL object -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *SSL_state_string(const SSL *ssl); -\& const char *SSL_state_string_long(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_state_string()\fR returns an abbreviated string indicating the current state -of the \s-1SSL\s0 object \fBssl\fR. The returned NUL-terminated string contains 6 or fewer characters. -.PP -\&\fBSSL_state_string_long()\fR returns a descriptive string indicating the current state of -the \s-1SSL\s0 object \fBssl\fR. -.SH "NOTES" -.IX Header "NOTES" -During its use, an \s-1SSL\s0 objects passes several states. The state is internally -maintained. Querying the state information is not very informative before -or when a connection has been established. It however can be of significant -interest during the handshake. -.PP -When using nonblocking sockets, the function call performing the handshake -may return with \s-1SSL_ERROR_WANT_READ\s0 or \s-1SSL_ERROR_WANT_WRITE\s0 condition, -so that SSL_state_string[_long]() may be called. -.PP -For both blocking or nonblocking sockets, the details state information -can be used within the info_callback function set with the -\&\fBSSL_set_info_callback()\fR call. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Detailed description of possible states to be included later. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_CTX_set_info_callback\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_state_string_long.3ossl b/openssl-install/share/man/man3/SSL_state_string_long.3ossl deleted file mode 120000 index 398cb4fa..00000000 --- a/openssl-install/share/man/man3/SSL_state_string_long.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_state_string.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_stateless.3ossl b/openssl-install/share/man/man3/SSL_stateless.3ossl deleted file mode 120000 index b976758b..00000000 --- a/openssl-install/share/man/man3/SSL_stateless.3ossl +++ /dev/null @@ -1 +0,0 @@ -DTLSv1_listen.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_stream_conclude.3ossl b/openssl-install/share/man/man3/SSL_stream_conclude.3ossl deleted file mode 100644 index be2c147d..00000000 --- a/openssl-install/share/man/man3/SSL_stream_conclude.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_STREAM_CONCLUDE 3ossl" -.TH SSL_STREAM_CONCLUDE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_stream_conclude \- conclude the sending part of a QUIC stream -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& _\|_owur int SSL_stream_conclude(SSL *s, uint64_t flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_stream_conclude()\fR signals the normal end-of-stream condition for the send -part of a \s-1QUIC\s0 stream. If called on a \s-1QUIC\s0 connection \s-1SSL\s0 object with an -associated default stream, it signals the end of the single stream to the peer. -.PP -Any data already queued for transmission via a call to \fBSSL_write()\fR will still be -written in a reliable manner before the end-of-stream is signalled, assuming the -connection remains healthy. This function can be thought of as appending a -logical end-of-stream marker after any data which has previously been written to -the stream via calls to \fBSSL_write()\fR. Further attempts to call \fBSSL_write()\fR after -calling this function will fail. -.PP -When calling this on a stream, the receive part of the stream remains -unaffected, and the peer may continue to send data until it also signals the end -of the stream. Thus, \fBSSL_read()\fR can still be used. -.PP -\&\fIflags\fR is reserved and should be set to 0. -.PP -Only the first call to this function has any effect for a given stream; -subsequent calls are no-ops. This is considered a success case. -.PP -This function is not supported on an object other than a \s-1QUIC\s0 stream \s-1SSL\s0 object. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success and 0 on failure. -.PP -Returns 0 if called on an \s-1SSL\s0 object not representing a \s-1QUIC\s0 stream. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-quic\fR\|(7), \fBssl\fR\|(7), \fBSSL_shutdown_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_stream_conclude()\fR function was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_stream_reset.3ossl b/openssl-install/share/man/man3/SSL_stream_reset.3ossl deleted file mode 100644 index 54f5c796..00000000 --- a/openssl-install/share/man/man3/SSL_stream_reset.3ossl +++ /dev/null @@ -1,209 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_STREAM_RESET 3ossl" -.TH SSL_STREAM_RESET 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_stream_reset \- reset a QUIC stream -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ssl_stream_reset_args_st { -\& uint64_t quic_error_code; -\& } SSL_STREAM_RESET_ARGS; -\& -\& int SSL_stream_reset(SSL *ssl, -\& const SSL_STREAM_RESET_ARGS *args, -\& size_t args_len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBSSL_stream_reset()\fR function resets the send part of a \s-1QUIC\s0 stream when -called on a \s-1QUIC\s0 stream \s-1SSL\s0 object, or on a \s-1QUIC\s0 connection \s-1SSL\s0 object with a -default stream attached. -.PP -If \fIargs\fR is non-NULL, \fIargs_len\fR must be set to \f(CW\*(C`sizeof(*args)\*(C'\fR. -.PP -\&\fIquic_error_code\fR is an application-specified error code, which must be in the -range [0, 2**62\-1]. If \fIargs\fR is \s-1NULL,\s0 a value of 0 is used. -.PP -Resetting a stream indicates to an application that the sending part of the -stream is terminating abnormally. When a stream is reset, the implementation -does not guarantee that any data already passed to \fBSSL_write\fR\|(3) will be -received by the peer, and data already passed to \fBSSL_write\fR\|(3) but not yet -transmitted may or may not be discarded. As such, you should only reset -a stream when the information transmitted on the stream no longer matters, for -example due to an error condition. -.PP -This function cannot be called on a unidirectional stream initiated by the peer, -as only the sending side of a stream can initiate a stream reset. -.PP -It is also possible to trigger a stream reset by calling \fBSSL_free\fR\|(3); see the -documentation for \fBSSL_free\fR\|(3) for details. -.PP -The receiving part of the stream (for bidirectional streams) continues to -function normally. -.SH "NOTES" -.IX Header "NOTES" -This function corresponds to the \s-1QUIC\s0 \fB\s-1RESET_STREAM\s0\fR frame. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Returns 1 on success and 0 on failure. -.PP -This function fails if called on a \s-1QUIC\s0 connection \s-1SSL\s0 object without a default -stream attached, or on a non-QUIC \s-1SSL\s0 object. -.PP -After the first call to this function succeeds for a given stream, -subsequent calls succeed but are ignored. The application error code -used is that passed to the first successful call to this function. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_free\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBSSL_stream_reset()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_trace.3ossl b/openssl-install/share/man/man3/SSL_trace.3ossl deleted file mode 120000 index dff83f3f..00000000 --- a/openssl-install/share/man/man3/SSL_trace.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_msg_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_up_ref.3ossl b/openssl-install/share/man/man3/SSL_up_ref.3ossl deleted file mode 120000 index 2a935814..00000000 --- a/openssl-install/share/man/man3/SSL_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_PrivateKey.3ossl b/openssl-install/share/man/man3/SSL_use_PrivateKey.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_PrivateKey_ASN1.3ossl b/openssl-install/share/man/man3/SSL_use_PrivateKey_ASN1.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_PrivateKey_ASN1.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_PrivateKey_file.3ossl b/openssl-install/share/man/man3/SSL_use_PrivateKey_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_PrivateKey_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/SSL_use_RSAPrivateKey.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_RSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_RSAPrivateKey_ASN1.3ossl b/openssl-install/share/man/man3/SSL_use_RSAPrivateKey_ASN1.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_RSAPrivateKey_ASN1.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_RSAPrivateKey_file.3ossl b/openssl-install/share/man/man3/SSL_use_RSAPrivateKey_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_RSAPrivateKey_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_cert_and_key.3ossl b/openssl-install/share/man/man3/SSL_use_cert_and_key.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_cert_and_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_certificate.3ossl b/openssl-install/share/man/man3/SSL_use_certificate.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_certificate.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_certificate_ASN1.3ossl b/openssl-install/share/man/man3/SSL_use_certificate_ASN1.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_certificate_ASN1.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_certificate_chain_file.3ossl b/openssl-install/share/man/man3/SSL_use_certificate_chain_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_certificate_chain_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_certificate_file.3ossl b/openssl-install/share/man/man3/SSL_use_certificate_file.3ossl deleted file mode 120000 index a80cf94d..00000000 --- a/openssl-install/share/man/man3/SSL_use_certificate_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_certificate.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_use_psk_identity_hint.3ossl b/openssl-install/share/man/man3/SSL_use_psk_identity_hint.3ossl deleted file mode 120000 index 205e7e3e..00000000 --- a/openssl-install/share/man/man3/SSL_use_psk_identity_hint.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_use_psk_identity_hint.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_verify_cb.3ossl b/openssl-install/share/man/man3/SSL_verify_cb.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_verify_client_post_handshake.3ossl b/openssl-install/share/man/man3/SSL_verify_client_post_handshake.3ossl deleted file mode 120000 index dd971f76..00000000 --- a/openssl-install/share/man/man3/SSL_verify_client_post_handshake.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_version.3ossl b/openssl-install/share/man/man3/SSL_version.3ossl deleted file mode 120000 index 5d8aa60f..00000000 --- a/openssl-install/share/man/man3/SSL_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_waiting_for_async.3ossl b/openssl-install/share/man/man3/SSL_waiting_for_async.3ossl deleted file mode 120000 index 18b3c38c..00000000 --- a/openssl-install/share/man/man3/SSL_waiting_for_async.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_get_all_async_fds.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want.3ossl b/openssl-install/share/man/man3/SSL_want.3ossl deleted file mode 100644 index a3fef288..00000000 --- a/openssl-install/share/man/man3/SSL_want.3ossl +++ /dev/null @@ -1,241 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_WANT 3ossl" -.TH SSL_WANT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_want, SSL_want_nothing, SSL_want_read, SSL_want_write, -SSL_want_x509_lookup, SSL_want_retry_verify, SSL_want_async, SSL_want_async_job, -SSL_want_client_hello_cb \- obtain state information TLS/SSL I/O operation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int SSL_want(const SSL *ssl); -\& int SSL_want_nothing(const SSL *ssl); -\& int SSL_want_read(const SSL *ssl); -\& int SSL_want_write(const SSL *ssl); -\& int SSL_want_x509_lookup(const SSL *ssl); -\& int SSL_want_retry_verify(const SSL *ssl); -\& int SSL_want_async(const SSL *ssl); -\& int SSL_want_async_job(const SSL *ssl); -\& int SSL_want_client_hello_cb(const SSL *ssl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_want()\fR returns state information for the \s-1SSL\s0 object \fBssl\fR. -.PP -The other SSL_want_*() calls are shortcuts for the possible states returned -by \fBSSL_want()\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\fBSSL_want()\fR examines the internal state information of the \s-1SSL\s0 object. Its -return values are similar to that of \fBSSL_get_error\fR\|(3). -Unlike \fBSSL_get_error\fR\|(3), which also evaluates the -error queue, the results are obtained by examining an internal state flag -only. The information must therefore only be used for normal operation under -nonblocking I/O. Error conditions are not handled and must be treated -using \fBSSL_get_error\fR\|(3). -.PP -The result returned by \fBSSL_want()\fR should always be consistent with -the result of \fBSSL_get_error\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The following return values can currently occur for \fBSSL_want()\fR: -.IP "\s-1SSL_NOTHING\s0" 4 -.IX Item "SSL_NOTHING" -There is no data to be written or to be read. -.IP "\s-1SSL_WRITING\s0" 4 -.IX Item "SSL_WRITING" -There are data in the \s-1SSL\s0 buffer that must be written to the underlying -\&\fB\s-1BIO\s0\fR layer in order to complete the actual SSL_*() operation. -A call to \fBSSL_get_error\fR\|(3) should return \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. -.IP "\s-1SSL_READING\s0" 4 -.IX Item "SSL_READING" -More data must be read from the underlying \fB\s-1BIO\s0\fR layer in order to -complete the actual SSL_*() operation. -A call to \fBSSL_get_error\fR\|(3) should return \fB\s-1SSL_ERROR_WANT_READ\s0\fR. -.IP "\s-1SSL_X509_LOOKUP\s0" 4 -.IX Item "SSL_X509_LOOKUP" -The operation did not complete because an application callback set by -\&\fBSSL_CTX_set_client_cert_cb()\fR has asked to be called again. -A call to \fBSSL_get_error\fR\|(3) should return \fB\s-1SSL_ERROR_WANT_X509_LOOKUP\s0\fR. -.IP "\s-1SSL_RETRY_VERIFY\s0" 4 -.IX Item "SSL_RETRY_VERIFY" -The operation did not complete because a certificate verification callback -has asked to be called again via \fBSSL_set_retry_verify\fR\|(3). -A call to \fBSSL_get_error\fR\|(3) should return \fB\s-1SSL_ERROR_WANT_RETRY_VERIFY\s0\fR. -.IP "\s-1SSL_ASYNC_PAUSED\s0" 4 -.IX Item "SSL_ASYNC_PAUSED" -An asynchronous operation partially completed and was then paused. See -\&\fBSSL_get_all_async_fds\fR\|(3). A call to \fBSSL_get_error\fR\|(3) should return -\&\fB\s-1SSL_ERROR_WANT_ASYNC\s0\fR. -.IP "\s-1SSL_ASYNC_NO_JOBS\s0" 4 -.IX Item "SSL_ASYNC_NO_JOBS" -The asynchronous job could not be started because there were no async jobs -available in the pool (see \fBASYNC_init_thread\fR\|(3)). A call to \fBSSL_get_error\fR\|(3) -should return \fB\s-1SSL_ERROR_WANT_ASYNC_JOB\s0\fR. -.IP "\s-1SSL_CLIENT_HELLO_CB\s0" 4 -.IX Item "SSL_CLIENT_HELLO_CB" -The operation did not complete because an application callback set by -\&\fBSSL_CTX_set_client_hello_cb()\fR has asked to be called again. -A call to \fBSSL_get_error\fR\|(3) should return \fB\s-1SSL_ERROR_WANT_CLIENT_HELLO_CB\s0\fR. -.PP -\&\fBSSL_want_nothing()\fR, \fBSSL_want_read()\fR, \fBSSL_want_write()\fR, -\&\fBSSL_want_x509_lookup()\fR, \fBSSL_want_retry_verify()\fR, -\&\fBSSL_want_async()\fR, \fBSSL_want_async_job()\fR, and \fBSSL_want_client_hello_cb()\fR -return 1 when the corresponding condition is true or 0 otherwise. -.SH "QUIC-SPECIFIC CONSIDERATIONS" -.IX Header "QUIC-SPECIFIC CONSIDERATIONS" -For \s-1QUIC,\s0 these functions relate only to the \s-1TLS\s0 handshake layer. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_want_client_hello_cb()\fR function and the \s-1SSL_CLIENT_HELLO_CB\s0 return value -were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_want_async.3ossl b/openssl-install/share/man/man3/SSL_want_async.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_async.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want_async_job.3ossl b/openssl-install/share/man/man3/SSL_want_async_job.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_async_job.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want_client_hello_cb.3ossl b/openssl-install/share/man/man3/SSL_want_client_hello_cb.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_client_hello_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want_nothing.3ossl b/openssl-install/share/man/man3/SSL_want_nothing.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_nothing.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want_read.3ossl b/openssl-install/share/man/man3/SSL_want_read.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_read.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want_retry_verify.3ossl b/openssl-install/share/man/man3/SSL_want_retry_verify.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_retry_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want_write.3ossl b/openssl-install/share/man/man3/SSL_want_write.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_write.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_want_x509_lookup.3ossl b/openssl-install/share/man/man3/SSL_want_x509_lookup.3ossl deleted file mode 120000 index 2ea53bbb..00000000 --- a/openssl-install/share/man/man3/SSL_want_x509_lookup.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_want.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_write.3ossl b/openssl-install/share/man/man3/SSL_write.3ossl deleted file mode 100644 index d2b0a814..00000000 --- a/openssl-install/share/man/man3/SSL_write.3ossl +++ /dev/null @@ -1,321 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "SSL_WRITE 3ossl" -.TH SSL_WRITE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -SSL_write_ex2, SSL_write_ex, SSL_write, SSL_sendfile, SSL_WRITE_FLAG_CONCLUDE \- -write bytes to a TLS/SSL connection -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& #define SSL_WRITE_FLAG_CONCLUDE -\& -\& ossl_ssize_t SSL_sendfile(SSL *s, int fd, off_t offset, size_t size, int flags); -\& int SSL_write_ex2(SSL *s, const void *buf, size_t num, -\& uint64_t flags, -\& size_t *written); -\& int SSL_write_ex(SSL *s, const void *buf, size_t num, size_t *written); -\& int SSL_write(SSL *ssl, const void *buf, int num); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBSSL_write_ex()\fR and \fBSSL_write()\fR write \fBnum\fR bytes from the buffer \fBbuf\fR into -the specified \fBssl\fR connection. On success \fBSSL_write_ex()\fR will store the number -of bytes written in \fB*written\fR. -.PP -\&\fBSSL_write_ex2()\fR functions similarly to \fBSSL_write_ex()\fR but can also accept -optional flags which modify its behaviour. Calling \fBSSL_write_ex2()\fR with a -\&\fIflags\fR argument of 0 is exactly equivalent to calling \fBSSL_write_ex()\fR. -.PP -\&\fBSSL_sendfile()\fR writes \fBsize\fR bytes from offset \fBoffset\fR in the file -descriptor \fBfd\fR to the specified \s-1SSL\s0 connection \fBs\fR. This function provides -efficient zero-copy semantics. \fBSSL_sendfile()\fR is available only when -Kernel \s-1TLS\s0 is enabled, which can be checked by calling \fBBIO_get_ktls_send()\fR. -It is provided here to allow users to maintain the same interface. -The meaning of \fBflags\fR is platform dependent. -Currently, under Linux it is ignored. -.PP -The \fIflags\fR argument to \fBSSL_write_ex2()\fR can accept zero or more of the -following flags. Note that which flags are supported will depend on the kind of -\&\s-1SSL\s0 object and underlying protocol being used: -.IP "\fB\s-1SSL_WRITE_FLAG_CONCLUDE\s0\fR" 4 -.IX Item "SSL_WRITE_FLAG_CONCLUDE" -This flag is only supported on \s-1QUIC\s0 stream \s-1SSL\s0 objects (or \s-1QUIC\s0 connection \s-1SSL\s0 -objects with a default stream attached). -.Sp -If this flag is set, and the call to \fBSSL_write_ex2()\fR succeeds, and all of the -data passed to the call is written (meaning that \f(CW\*(C`*written == num\*(C'\fR), the -relevant \s-1QUIC\s0 stream's send part is concluded automatically as though -\&\fBSSL_stream_conclude\fR\|(3) was called (causing transmission of a \s-1FIN\s0 for the -stream). -.Sp -While using this flag is semantically equivalent to calling -\&\fBSSL_stream_conclude\fR\|(3) after a successful call to this function, using this -flag enables greater efficiency than making these two \s-1API\s0 calls separately, as -it enables the written stream data and the \s-1FIN\s0 flag indicating the end of the -stream to be scheduled as part of the same \s-1QUIC STREAM\s0 frame and \s-1QUIC\s0 packet. -.Sp -Setting this flag does not cause a stream's send part to be concluded if not all -of the data passed to the call was consumed. -.PP -A call to \fBSSL_write_ex2()\fR fails if a flag is passed which is not supported or -understood by the given \s-1SSL\s0 object. An application should determine if a flag is -supported (for example, for \fB\s-1SSL_WRITE_FLAG_CONCLUDE\s0\fR, that a \s-1QUIC\s0 stream \s-1SSL\s0 -object is being used) before attempting to use it. -.SH "NOTES" -.IX Header "NOTES" -In the paragraphs below a \*(L"write function\*(R" is defined as one of either -\&\fBSSL_write_ex()\fR, or \fBSSL_write()\fR. -.PP -If necessary, a write function will negotiate a \s-1TLS/SSL\s0 session, if not already -explicitly performed by \fBSSL_connect\fR\|(3) or \fBSSL_accept\fR\|(3). If the peer -requests a re-negotiation, it will be performed transparently during -the write function operation. The behaviour of the write functions depends on the -underlying \s-1BIO.\s0 -.PP -For the transparent negotiation to succeed, the \fBssl\fR must have been -initialized to client or server mode. This is being done by calling -\&\fBSSL_set_connect_state\fR\|(3) or \fBSSL_set_accept_state()\fR -before the first call to a write function. -.PP -If the underlying \s-1BIO\s0 is \fBblocking\fR, the write functions will only return, once -the write operation has been finished or an error occurred. -.PP -If the underlying \s-1BIO\s0 is \fBnonblocking\fR the write functions will also return -when the underlying \s-1BIO\s0 could not satisfy the needs of the function to continue -the operation. In this case a call to \fBSSL_get_error\fR\|(3) with the -return value of the write function will yield \fB\s-1SSL_ERROR_WANT_READ\s0\fR -or \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. As at any time a re-negotiation is possible, a -call to a write function can also cause read operations! The calling process -then must repeat the call after taking appropriate action to satisfy the needs -of the write function. The action depends on the underlying \s-1BIO.\s0 When using a -nonblocking socket, nothing is to be done, but \fBselect()\fR can be used to check -for the required condition. When using a buffering \s-1BIO,\s0 like a \s-1BIO\s0 pair, data -must be written into or retrieved out of the \s-1BIO\s0 before being able to continue. -.PP -The write functions will only return with success when the complete contents of -\&\fBbuf\fR of length \fBnum\fR has been written. This default behaviour can be changed -with the \s-1SSL_MODE_ENABLE_PARTIAL_WRITE\s0 option of \fBSSL_CTX_set_mode\fR\|(3). When -this flag is set the write functions will also return with success when a -partial write has been successfully completed. In this case the write function -operation is considered completed. The bytes are sent and a new write call with -a new buffer (with the already sent bytes removed) must be started. A partial -write is performed with the size of a message block, which is 16kB. -.PP -When used with a \s-1QUIC SSL\s0 object, calling an I/O function such as \fBSSL_write()\fR -allows internal network event processing to be performed. It is important that -this processing is performed regularly. If an application is not using thread -assisted mode, an application should ensure that an I/O function such as -\&\fBSSL_write()\fR is called regularly, or alternatively ensure that \fBSSL_handle_events()\fR -is called regularly. See \fBopenssl\-quic\fR\|(7) and \fBSSL_handle_events\fR\|(3) for more -information. -.SH "WARNINGS" -.IX Header "WARNINGS" -When a write function call has to be repeated because \fBSSL_get_error\fR\|(3) -returned \fB\s-1SSL_ERROR_WANT_READ\s0\fR or \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR, it must be repeated -with the same arguments. -The data that was passed might have been partially processed. -When \fB\s-1SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER\s0\fR was set using \fBSSL_CTX_set_mode\fR\|(3) -the pointer can be different, but the data and length should still be the same. -.PP -You should not call \fBSSL_write()\fR with num=0, it will return an error. -\&\fBSSL_write_ex()\fR can be called with num=0, but will not send application data to -the peer. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBSSL_write_ex()\fR and \fBSSL_write_ex2()\fR return 1 for success or 0 for failure. -Success means that all requested application data bytes have been written to the -\&\s-1SSL\s0 connection or, if \s-1SSL_MODE_ENABLE_PARTIAL_WRITE\s0 is in use, at least 1 -application data byte has been written to the \s-1SSL\s0 connection. Failure means that -not all the requested bytes have been written yet (if -\&\s-1SSL_MODE_ENABLE_PARTIAL_WRITE\s0 is not in use) or no bytes could be written to the -\&\s-1SSL\s0 connection (if \s-1SSL_MODE_ENABLE_PARTIAL_WRITE\s0 is in use). Failures can be -retryable (e.g. the network write buffer has temporarily filled up) or -non-retryable (e.g. a fatal network error). In the event of a failure call -\&\fBSSL_get_error\fR\|(3) to find out the reason which indicates whether the call is -retryable or not. -.PP -For \fBSSL_write()\fR the following return values can occur: -.IP "> 0" 4 -.IX Item "> 0" -The write operation was successful, the return value is the number of -bytes actually written to the \s-1TLS/SSL\s0 connection. -.IP "<= 0" 4 -.IX Item "<= 0" -The write operation was not successful, because either the connection was -closed, an error occurred or action must be taken by the calling process. -Call \fBSSL_get_error()\fR with the return value \fBret\fR to find out the reason. -.Sp -Old documentation indicated a difference between 0 and \-1, and that \-1 was -retryable. -You should instead call \fBSSL_get_error()\fR to find out if it's retryable. -.PP -For \fBSSL_sendfile()\fR, the following return values can occur: -.IP ">= 0" 4 -.IX Item ">= 0" -The write operation was successful, the return value is the number -of bytes of the file written to the \s-1TLS/SSL\s0 connection. The return -value can be less than \fBsize\fR for a partial write. -.IP "< 0" 4 -.IX Item "< 0" -The write operation was not successful, because either the connection was -closed, an error occurred or action must be taken by the calling process. -Call \fBSSL_get_error()\fR with the return value to find out the reason. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_error\fR\|(3), \fBSSL_read_ex\fR\|(3), \fBSSL_read\fR\|(3) -\&\fBSSL_CTX_set_mode\fR\|(3), \fBSSL_CTX_new\fR\|(3), -\&\fBSSL_connect\fR\|(3), \fBSSL_accept\fR\|(3) -\&\fBSSL_set_connect_state\fR\|(3), \fBBIO_ctrl\fR\|(3), -\&\fBssl\fR\|(7), \fBbio\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBSSL_write_ex()\fR function was added in OpenSSL 1.1.1. -The \fBSSL_sendfile()\fR function was added in OpenSSL 3.0. -The \fBSSL_write_ex2()\fR function was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/SSL_write_early_data.3ossl b/openssl-install/share/man/man3/SSL_write_early_data.3ossl deleted file mode 120000 index 40c86bf4..00000000 --- a/openssl-install/share/man/man3/SSL_write_early_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_read_early_data.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_write_ex.3ossl b/openssl-install/share/man/man3/SSL_write_ex.3ossl deleted file mode 120000 index c5148886..00000000 --- a/openssl-install/share/man/man3/SSL_write_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_write.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSL_write_ex2.3ossl b/openssl-install/share/man/man3/SSL_write_ex2.3ossl deleted file mode 120000 index c5148886..00000000 --- a/openssl-install/share/man/man3/SSL_write_ex2.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_write.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSLv23_client_method.3ossl b/openssl-install/share/man/man3/SSLv23_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSLv23_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSLv23_method.3ossl b/openssl-install/share/man/man3/SSLv23_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSLv23_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSLv23_server_method.3ossl b/openssl-install/share/man/man3/SSLv23_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSLv23_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSLv3_client_method.3ossl b/openssl-install/share/man/man3/SSLv3_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSLv3_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSLv3_method.3ossl b/openssl-install/share/man/man3/SSLv3_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSLv3_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SSLv3_server_method.3ossl b/openssl-install/share/man/man3/SSLv3_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/SSLv3_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SXNETID_free.3ossl b/openssl-install/share/man/man3/SXNETID_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/SXNETID_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SXNETID_new.3ossl b/openssl-install/share/man/man3/SXNETID_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/SXNETID_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SXNET_free.3ossl b/openssl-install/share/man/man3/SXNET_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/SXNET_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/SXNET_new.3ossl b/openssl-install/share/man/man3/SXNET_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/SXNET_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLS_FEATURE_free.3ossl b/openssl-install/share/man/man3/TLS_FEATURE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TLS_FEATURE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLS_FEATURE_new.3ossl b/openssl-install/share/man/man3/TLS_FEATURE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TLS_FEATURE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLS_client_method.3ossl b/openssl-install/share/man/man3/TLS_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLS_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLS_method.3ossl b/openssl-install/share/man/man3/TLS_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLS_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLS_server_method.3ossl b/openssl-install/share/man/man3/TLS_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLS_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_1_client_method.3ossl b/openssl-install/share/man/man3/TLSv1_1_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_1_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_1_method.3ossl b/openssl-install/share/man/man3/TLSv1_1_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_1_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_1_server_method.3ossl b/openssl-install/share/man/man3/TLSv1_1_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_1_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_2_client_method.3ossl b/openssl-install/share/man/man3/TLSv1_2_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_2_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_2_method.3ossl b/openssl-install/share/man/man3/TLSv1_2_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_2_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_2_server_method.3ossl b/openssl-install/share/man/man3/TLSv1_2_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_2_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_client_method.3ossl b/openssl-install/share/man/man3/TLSv1_client_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_client_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_method.3ossl b/openssl-install/share/man/man3/TLSv1_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TLSv1_server_method.3ossl b/openssl-install/share/man/man3/TLSv1_server_method.3ossl deleted file mode 120000 index 3e757bee..00000000 --- a/openssl-install/share/man/man3/TLSv1_server_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_ACCURACY_dup.3ossl b/openssl-install/share/man/man3/TS_ACCURACY_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_ACCURACY_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_ACCURACY_free.3ossl b/openssl-install/share/man/man3/TS_ACCURACY_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_ACCURACY_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_ACCURACY_new.3ossl b/openssl-install/share/man/man3/TS_ACCURACY_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_ACCURACY_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_MSG_IMPRINT_dup.3ossl b/openssl-install/share/man/man3/TS_MSG_IMPRINT_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_MSG_IMPRINT_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_MSG_IMPRINT_free.3ossl b/openssl-install/share/man/man3/TS_MSG_IMPRINT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_MSG_IMPRINT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_MSG_IMPRINT_new.3ossl b/openssl-install/share/man/man3/TS_MSG_IMPRINT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_MSG_IMPRINT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_REQ_dup.3ossl b/openssl-install/share/man/man3/TS_REQ_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_REQ_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_REQ_free.3ossl b/openssl-install/share/man/man3/TS_REQ_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_REQ_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_REQ_new.3ossl b/openssl-install/share/man/man3/TS_REQ_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_REQ_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_RESP_CTX_free.3ossl b/openssl-install/share/man/man3/TS_RESP_CTX_free.3ossl deleted file mode 120000 index 5bcd2be9..00000000 --- a/openssl-install/share/man/man3/TS_RESP_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_RESP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_RESP_CTX_new.3ossl b/openssl-install/share/man/man3/TS_RESP_CTX_new.3ossl deleted file mode 100644 index 17bdae7c..00000000 --- a/openssl-install/share/man/man3/TS_RESP_CTX_new.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "TS_RESP_CTX_NEW 3ossl" -.TH TS_RESP_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -TS_RESP_CTX_new_ex, TS_RESP_CTX_new, -TS_RESP_CTX_free \- Timestamp response context object creation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& TS_RESP_CTX *TS_RESP_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq); -\& TS_RESP_CTX *TS_RESP_CTX_new(void); -\& void TS_RESP_CTX_free(TS_RESP_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Creates a response context that can be used for generating responses. -.PP -\&\fBTS_RESP_CTX_new_ex()\fR allocates and initializes a \s-1TS_RESP_CTX\s0 structure with a -library context of \fIlibctx\fR and a property query of \fIpropq\fR. -The library context and property query can be used to select which providers -supply the fetched algorithms. -.PP -\&\fBTS_RESP_CTX_new()\fR is similar to \fBTS_RESP_CTX_new_ex()\fR but sets the library context -and property query to \s-1NULL.\s0 This results in the default (\s-1NULL\s0) library context -being used for any operations requiring algorithm fetches. -.PP -\&\fBTS_RESP_CTX_free()\fR frees the \fB\s-1TS_RESP_CTX\s0\fR object \fIctx\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBTS_RESP_CTX_new_ex()\fR and \fBTS_RESP_CTX_new()\fR return \s-1NULL,\s0 -otherwise it returns a pointer to the newly allocated structure. -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBTS_RESP_CTX_new_ex()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/TS_RESP_CTX_new_ex.3ossl b/openssl-install/share/man/man3/TS_RESP_CTX_new_ex.3ossl deleted file mode 120000 index 5bcd2be9..00000000 --- a/openssl-install/share/man/man3/TS_RESP_CTX_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_RESP_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_RESP_dup.3ossl b/openssl-install/share/man/man3/TS_RESP_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_RESP_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_RESP_free.3ossl b/openssl-install/share/man/man3/TS_RESP_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_RESP_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_RESP_new.3ossl b/openssl-install/share/man/man3/TS_RESP_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_RESP_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_STATUS_INFO_dup.3ossl b/openssl-install/share/man/man3/TS_STATUS_INFO_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_STATUS_INFO_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_STATUS_INFO_free.3ossl b/openssl-install/share/man/man3/TS_STATUS_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_STATUS_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_STATUS_INFO_new.3ossl b/openssl-install/share/man/man3/TS_STATUS_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_STATUS_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_TST_INFO_dup.3ossl b/openssl-install/share/man/man3/TS_TST_INFO_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_TST_INFO_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_TST_INFO_free.3ossl b/openssl-install/share/man/man3/TS_TST_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_TST_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_TST_INFO_new.3ossl b/openssl-install/share/man/man3/TS_TST_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/TS_TST_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTS_set_certs.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTS_set_certs.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTS_set_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX.3ossl deleted file mode 100644 index 606a68d4..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX.3ossl +++ /dev/null @@ -1,289 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "TS_VERIFY_CTX 3ossl" -.TH TS_VERIFY_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -TS_VERIFY_CTX, TS_VERIFY_CTX_new, TS_VERIFY_CTX_init, TS_VERIFY_CTX_free, -TS_VERIFY_CTX_cleanup, TS_VERIFY_CTX_set_flags, TS_VERIFY_CTX_add_flags, -TS_VERIFY_CTX_set0_data, TS_VERIFY_CTX_set0_imprint, TS_VERIFY_CTX_set0_store, -TS_VERIFY_CTX_set0_certs, TS_VERIFY_CTX_set_certs, TS_VERIFY_CTS_set_certs, -TS_VERIFY_CTX_set_data, TS_VERIFY_CTX_set_imprint, TS_VERIFY_CTX_set_store -\&\- manage the TS response verification context -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct TS_verify_ctx TS_VERIFY_CTX; -\& -\& TS_VERIFY_CTX *TS_VERIFY_CTX_new(void); -\& void TS_VERIFY_CTX_init(TS_VERIFY_CTX *ctx); -\& void TS_VERIFY_CTX_free(TS_VERIFY_CTX *ctx); -\& void TS_VERIFY_CTX_cleanup(TS_VERIFY_CTX *ctx); -\& int TS_VERIFY_CTX_set_flags(TS_VERIFY_CTX *ctx, int f); -\& int TS_VERIFY_CTX_add_flags(TS_VERIFY_CTX *ctx, int f); -\& int TS_VERIFY_CTX_set0_data(TS_VERIFY_CTX *ctx, BIO *b); -\& int TS_VERIFY_CTX_set0_imprint(TS_VERIFY_CTX *ctx, -\& unsigned char *hexstr, long len); -\& int TS_VERIFY_CTX_set0_store(TS_VERIFY_CTX *ctx, X509_STORE *s); -\& int TS_VERIFY_CTX_set0_certs(TS_VERIFY_CTX *ctx, STACK_OF(X509) *certs); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.4: -.PP -.Vb 6 -\& BIO *TS_VERIFY_CTX_set_data(TS_VERIFY_CTX *ctx, BIO *b); -\& unsigned char *TS_VERIFY_CTX_set_imprint(TS_VERIFY_CTX *ctx, -\& unsigned char *hexstr, long len); -\& X509_STORE *TS_VERIFY_CTX_set_store(TS_VERIFY_CTX *ctx, X509_STORE *s); -\& STACK_OF(X509) *TS_VERIFY_CTX_set_certs(TS_VERIFY_CTX *ctx, -\& STACK_OF(X509) *certs); -.Ve -.PP -The following function has been deprecated since OpenSSL 3.0: -.PP -.Vb 2 -\& STACK_OF(X509) *TS_VERIFY_CTS_set_certs(TS_VERIFY_CTX *ctx, -\& STACK_OF(X509) *certs); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The Time-Stamp Protocol (\s-1TSP\s0) is defined by \s-1RFC 3161. TSP\s0 is a protocol used to -provide long-term proof of the existence of certain data before a particular -time. \s-1TSP\s0 defines a Time Stamping Authority (\s-1TSA\s0) and an entity that makes -requests to the \s-1TSA.\s0 Usually, the \s-1TSA\s0 is referred to as the server side, and the -requesting entity is referred to as the client. -.PP -In \s-1TSP,\s0 when a server sends a response to a client, the server normally -needs to sign the response data \- the TimeStampToken (\s-1TST\s0) \- with its private -key. Then the client verifies the received \s-1TST\s0 using the server's certificate -chain. -.PP -For all the following methods, unless noted otherwise, \fIctx\fR is the -verification context created in advance. -.PP -\&\fBTS_VERIFY_CTX_new()\fR returns an allocated \fB\s-1TS_VERIFY_CTX\s0\fR structure. -.PP -\&\fBTS_VERIFY_CTX_init()\fR initializes a verification context. -.PP -\&\fBTS_VERIFY_CTX_free()\fR frees up a \fB\s-1TS_VERIFY_CTX\s0\fR object. \fIctx\fR is the -verification context to be freed. If \fIctx\fR is \s-1NULL,\s0 the call is ignored. -.PP -\&\fBTS_VERIFY_CTX_set_flags()\fR sets the flags in the verification context. \fIf\fR are -the flags to be set. -.PP -\&\fBTS_VERIFY_CTX_add_flags()\fR adds flags to the verification context. \fIf\fR are the -flags to be added (\s-1OR\s0'd). -.PP -\&\fBTS_VERIFY_CTX_set0_data()\fR sets the data to be verified. \fIb\fR is the \fB\s-1BIO\s0\fR with -the data. A previously assigned \fB\s-1BIO\s0\fR is freed. -.PP -\&\fBTS_VERIFY_CTX_set0_imprint()\fR sets the message imprint. \fIhexstr\fR is the -message imprint to be assigned. A previously assigned imprint is freed. -.PP -\&\fBTS_VERIFY_CTX_set0_store()\fR sets the store for the verification context. \fIs\fR is -the store to be assigned. A previously assigned store is freed. -.PP -\&\fBTS_VERIFY_CTX_set0_certs()\fR is used to set the server's certificate chain when -verifying a \s-1TST.\s0 \fIcerts\fR is a stack of \fBX509\fR certificates. -.PP -\&\fBTS_VERIFY_CTX_cleanup()\fR frees all data associated with the given -\&\fB\s-1TS_VERIFY_CTX\s0\fR object and initializes it. \fIctx\fR is the verification context -created in advance. If \fIctx\fR is \s-1NULL,\s0 the call is ignored. -.PP -All of the following functions described are deprecated. Applications should -instead use the functions \fBTS_VERIFY_CTX_set0_data\fR\|(3), -\&\fBTS_VERIFY_CTX_set0_imprint\fR\|(3), \fBTS_VERIFY_CTX_set0_store\fR\|(3), -\&\fBTS_VERIFY_CTX_set0_certs\fR\|(3). -.PP -\&\fBTS_VERIFY_CTX_set_data()\fR is used to set the \s-1BIO\s0 with the data to be verified. -A previously assigned \s-1BIO\s0 is \fBnot freed\fR by this call. \fIb\fR is the \fB\s-1BIO\s0\fR -with the data to assign. -.PP -\&\fBTS_VERIFY_CTX_set_imprint()\fR is used to set the message imprint. A previously -assigned imprint \fBis freed\fR by this call. \fIhexstr\fR is the string with the -message imprint to assign. -.PP -\&\fBTS_VERIFY_CTX_set_store()\fR is used to set the certificate store. A previously -assigned store is \fBnot freed\fR by this call. \fIs\fR is the store to assign. -.PP -\&\fBTS_VERIFY_CTX_set_certs()\fR is used to set the server's certificate chain. -A previously assigned stack is \fBnot freed\fR by this call. \fIcerts\fR is a stack -of \fBX509\fR certificates. -.PP -\&\fBTS_VERIFY_CTS_set_certs()\fR is a misspelled version of \fBTS_VERIFY_CTX_set_certs()\fR -which takes the same parameters and returns the same result. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBTS_VERIFY_CTX_new()\fR returns an allocated \fB\s-1TS_VERIFY_CTX\s0\fR structure. -.PP -\&\fBTS_VERIFY_CTX_set_flags()\fR returns the flags passed via parameter \fIf\fR. -.PP -\&\fBTS_VERIFY_CTX_add_flags()\fR returns the flags of the context after the ones -passed via parameter \fIf\fR are added to it. -.PP -\&\fBTS_VERIFY_CTX_set0_data()\fR, \fBTS_VERIFY_CTX_set0_imprint()\fR, -\&\fBTS_VERIFY_CTX_set0_store()\fR, and \fBTS_VERIFY_CTX_set0_certs()\fR return 1 if the -value could be successfully set and 0 in case of any error. -.PP -The deprecated functions \fBTS_VERIFY_CTX_set_data()\fR, \fBTS_VERIFY_CTX_set_imprint()\fR, -\&\fBTS_VERIFY_CTX_set_store()\fR, \fBTS_VERIFY_CTX_set_certs()\fR return the parameter -the user passes via parameter \fIbio\fR, \fIhexstr\fR, \fIs\fR or \fIcerts\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_ESS_check_signing_certs\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBTS_VERIFY_CTX_set0_data()\fR, \fBTS_VERIFY_CTX_set0_imprint()\fR, -\&\fBTS_VERIFY_CTX_set0_store()\fR, \fBTS_VERIFY_CTX_set0_certs()\fR replace the functions -\&\fBTS_VERIFY_CTX_set_data()\fR, \fBTS_VERIFY_CTX_set_imprint()\fR, -\&\fBTS_VERIFY_CTX_set_store()\fR, \fBTS_VERIFY_CTX_set_certs()\fR that were deprecated -in OpenSSL 3.4.0. -.PP -The spelling of \fBTS_VERIFY_CTX_set_certs()\fR was corrected in OpenSSL 3.0.0. -The misspelled version \fBTS_VERIFY_CTS_set_certs()\fR has been retained for -compatibility reasons, but it is deprecated in OpenSSL 3.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_add_flags.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_add_flags.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_add_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_cleanup.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_cleanup.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_free.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_free.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_init.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_init.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_new.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_new.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_certs.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_certs.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_data.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_data.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_imprint.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_imprint.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_imprint.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_store.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_store.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set0_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_certs.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set_certs.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_data.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set_data.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_flags.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set_flags.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_imprint.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set_imprint.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_imprint.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_store.3ossl b/openssl-install/share/man/man3/TS_VERIFY_CTX_set_store.3ossl deleted file mode 120000 index b6621645..00000000 --- a/openssl-install/share/man/man3/TS_VERIFY_CTX_set_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -TS_VERIFY_CTX.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI.3ossl b/openssl-install/share/man/man3/UI.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_METHOD.3ossl b/openssl-install/share/man/man3/UI_METHOD.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_METHOD.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_OpenSSL.3ossl b/openssl-install/share/man/man3/UI_OpenSSL.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_OpenSSL.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_STRING.3ossl b/openssl-install/share/man/man3/UI_STRING.3ossl deleted file mode 100644 index 06670935..00000000 --- a/openssl-install/share/man/man3/UI_STRING.3ossl +++ /dev/null @@ -1,279 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "UI_STRING 3ossl" -.TH UI_STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -UI_STRING, UI_string_types, UI_get_string_type, -UI_get_input_flags, UI_get0_output_string, -UI_get0_action_string, UI_get0_result_string, UI_get_result_string_length, -UI_get0_test_string, UI_get_result_minsize, -UI_get_result_maxsize, UI_set_result, UI_set_result_ex -\&\- User interface string parsing -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ui_string_st UI_STRING; -\& -\& enum UI_string_types { -\& UIT_NONE = 0, -\& UIT_PROMPT, /* Prompt for a string */ -\& UIT_VERIFY, /* Prompt for a string and verify */ -\& UIT_BOOLEAN, /* Prompt for a yes/no response */ -\& UIT_INFO, /* Send info to the user */ -\& UIT_ERROR /* Send an error message to the user */ -\& }; -\& -\& enum UI_string_types UI_get_string_type(UI_STRING *uis); -\& int UI_get_input_flags(UI_STRING *uis); -\& const char *UI_get0_output_string(UI_STRING *uis); -\& const char *UI_get0_action_string(UI_STRING *uis); -\& const char *UI_get0_result_string(UI_STRING *uis); -\& int UI_get_result_string_length(UI_STRING *uis); -\& const char *UI_get0_test_string(UI_STRING *uis); -\& int UI_get_result_minsize(UI_STRING *uis); -\& int UI_get_result_maxsize(UI_STRING *uis); -\& int UI_set_result(UI *ui, UI_STRING *uis, const char *result); -\& int UI_set_result_ex(UI *ui, UI_STRING *uis, const char *result, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1UI_STRING\s0\fR gets created internally and added to a \fB\s-1UI\s0\fR whenever -one of the functions \fBUI_add_input_string()\fR, \fBUI_dup_input_string()\fR, -\&\fBUI_add_verify_string()\fR, \fBUI_dup_verify_string()\fR, -\&\fBUI_add_input_boolean()\fR, \fBUI_dup_input_boolean()\fR, \fBUI_add_info_string()\fR, -\&\fBUI_dup_info_string()\fR, \fBUI_add_error_string()\fR or \fBUI_dup_error_string()\fR -is called. -For a \fB\s-1UI_METHOD\s0\fR user, there's no need to know more. -For a \fB\s-1UI_METHOD\s0\fR creator, it is of interest to fetch text from these -\&\fB\s-1UI_STRING\s0\fR objects as well as adding results to some of them. -.PP -\&\fBUI_get_string_type()\fR is used to retrieve the type of the given -\&\fB\s-1UI_STRING\s0\fR. -.PP -\&\fBUI_get_input_flags()\fR is used to retrieve the flags associated with the -given \fB\s-1UI_STRING\s0\fR. -.PP -\&\fBUI_get0_output_string()\fR is used to retrieve the actual string to -output (prompt, info, error, ...). -.PP -\&\fBUI_get0_action_string()\fR is used to retrieve the action description -associated with a \fB\s-1UIT_BOOLEAN\s0\fR type \fB\s-1UI_STRING\s0\fR. -For all other \fB\s-1UI_STRING\s0\fR types, \s-1NULL\s0 is returned. -See \fBUI_add_input_boolean\fR\|(3). -.PP -\&\fBUI_get0_result_string()\fR and \fBUI_get_result_string_length()\fR are used to -retrieve the result of a prompt and its length. -This is only useful for \fB\s-1UIT_PROMPT\s0\fR and \fB\s-1UIT_VERIFY\s0\fR type strings. -For all other \fB\s-1UI_STRING\s0\fR types, \fBUI_get0_result_string()\fR returns \s-1NULL\s0 -and \fBUI_get_result_string_length()\fR returns \-1. -.PP -\&\fBUI_get0_test_string()\fR is used to retrieve the string to compare the -prompt result with. -This is only useful for \fB\s-1UIT_VERIFY\s0\fR type strings. -For all other \fB\s-1UI_STRING\s0\fR types, \s-1NULL\s0 is returned. -.PP -\&\fBUI_get_result_minsize()\fR and \fBUI_get_result_maxsize()\fR are used to -retrieve the minimum and maximum required size of the result. -This is only useful for \fB\s-1UIT_PROMPT\s0\fR and \fB\s-1UIT_VERIFY\s0\fR type strings. -For all other \fB\s-1UI_STRING\s0\fR types, \-1 is returned. -.PP -\&\fBUI_set_result_ex()\fR is used to set the result value of a prompt and its length. -For \fB\s-1UIT_PROMPT\s0\fR and \fB\s-1UIT_VERIFY\s0\fR type \s-1UI\s0 strings, this sets the -result retrievable with \fBUI_get0_result_string()\fR by copying the -contents of \fBresult\fR if its length fits the minimum and maximum size -requirements. -For \fB\s-1UIT_BOOLEAN\s0\fR type \s-1UI\s0 strings, this sets the first character of -the result retrievable with \fBUI_get0_result_string()\fR to the first -\&\fBok_char\fR given with \fBUI_add_input_boolean()\fR or \fBUI_dup_input_boolean()\fR -if the \fBresult\fR matched any of them, or the first of the -\&\fBcancel_chars\fR if the \fBresult\fR matched any of them, otherwise it's -set to the \s-1NUL\s0 char \f(CW\*(C`\e0\*(C'\fR. -See \fBUI_add_input_boolean\fR\|(3) for more information on \fBok_chars\fR and -\&\fBcancel_chars\fR. -.PP -\&\fBUI_set_result()\fR does the same thing as \fBUI_set_result_ex()\fR, but calculates -its length internally. -It expects the string to be terminated with a \s-1NUL\s0 byte, and is therefore -only useful with normal C strings. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBUI_get_string_type()\fR returns the \s-1UI\s0 string type. -.PP -\&\fBUI_get_input_flags()\fR returns the \s-1UI\s0 string flags. -.PP -\&\fBUI_get0_output_string()\fR returns the \s-1UI\s0 string output string. -.PP -\&\fBUI_get0_action_string()\fR returns the \s-1UI\s0 string action description -string for \fB\s-1UIT_BOOLEAN\s0\fR type \s-1UI\s0 strings, \s-1NULL\s0 for any other type. -.PP -\&\fBUI_get0_result_string()\fR returns the \s-1UI\s0 string result buffer for -\&\fB\s-1UIT_PROMPT\s0\fR and \fB\s-1UIT_VERIFY\s0\fR type \s-1UI\s0 strings, \s-1NULL\s0 for any other -type. -.PP -\&\fBUI_get_result_string_length()\fR returns the \s-1UI\s0 string result buffer's -content length for \fB\s-1UIT_PROMPT\s0\fR and \fB\s-1UIT_VERIFY\s0\fR type \s-1UI\s0 strings, -\&\-1 for any other type. -.PP -\&\fBUI_get0_test_string()\fR returns the \s-1UI\s0 string action description -string for \fB\s-1UIT_VERIFY\s0\fR type \s-1UI\s0 strings, \s-1NULL\s0 for any other type. -.PP -\&\fBUI_get_result_minsize()\fR returns the minimum allowed result size for -the \s-1UI\s0 string for \fB\s-1UIT_PROMPT\s0\fR and \fB\s-1UIT_VERIFY\s0\fR type strings, -\&\-1 for any other type. -.PP -\&\fBUI_get_result_maxsize()\fR returns the minimum allowed result size for -the \s-1UI\s0 string for \fB\s-1UIT_PROMPT\s0\fR and \fB\s-1UIT_VERIFY\s0\fR type strings, -\&\-1 for any other type. -.PP -\&\fBUI_set_result()\fR returns 0 on success or when the \s-1UI\s0 string is of any -type other than \fB\s-1UIT_PROMPT\s0\fR, \fB\s-1UIT_VERIFY\s0\fR or \fB\s-1UIT_BOOLEAN\s0\fR, \-1 on -error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBUI\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/UI_UTIL_read_pw.3ossl b/openssl-install/share/man/man3/UI_UTIL_read_pw.3ossl deleted file mode 100644 index a8a2cec8..00000000 --- a/openssl-install/share/man/man3/UI_UTIL_read_pw.3ossl +++ /dev/null @@ -1,203 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "UI_UTIL_READ_PW 3ossl" -.TH UI_UTIL_READ_PW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -UI_UTIL_read_pw_string, UI_UTIL_read_pw, -UI_UTIL_wrap_read_pem_callback \- user interface utilities -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int UI_UTIL_read_pw_string(char *buf, int length, const char *prompt, -\& int verify); -\& int UI_UTIL_read_pw(char *buf, char *buff, int size, const char *prompt, -\& int verify); -\& UI_METHOD *UI_UTIL_wrap_read_pem_callback(pem_password_cb *cb, int rwflag); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBUI_UTIL_read_pw_string()\fR asks for a passphrase, using \fBprompt\fR as a -prompt, and stores it in \fBbuf\fR. -The maximum allowed size is given with \fBlength\fR, including the -terminating \s-1NUL\s0 byte. -If \fBverify\fR is nonzero, the password will be verified as well. -.PP -\&\fBUI_UTIL_read_pw()\fR does the same as \fBUI_UTIL_read_pw_string()\fR, the -difference is that you can give it an external buffer \fBbuff\fR for the -verification passphrase. -.PP -\&\fBUI_UTIL_wrap_read_pem_callback()\fR can be used to create a temporary -\&\fB\s-1UI_METHOD\s0\fR that wraps a given \s-1PEM\s0 password callback \fBcb\fR. -\&\fBrwflag\fR is used to specify if this method will be used for -passphrase entry without (0) or with (1) verification. -When not used any more, the returned method should be freed with -\&\fBUI_destroy_method()\fR. -.SH "NOTES" -.IX Header "NOTES" -\&\fBUI_UTIL_read_pw_string()\fR and \fBUI_UTIL_read_pw()\fR use default -\&\fB\s-1UI_METHOD\s0\fR. -See \fBUI_get_default_method\fR\|(3) and friends for more information. -.PP -The result from the \fB\s-1UI_METHOD\s0\fR created by -\&\fBUI_UTIL_wrap_read_pem_callback()\fR will generate password strings in the -encoding that the given password callback generates. -The default password prompting functions (apart from -\&\fBUI_UTIL_read_pw_string()\fR and \fBUI_UTIL_read_pw()\fR, there is -\&\fBPEM_def_callback()\fR, \fBEVP_read_pw_string()\fR and \fBEVP_read_pw_string_min()\fR) -all use the default \fB\s-1UI_METHOD\s0\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBUI_UTIL_read_pw_string()\fR and \fBUI_UTIL_read_pw()\fR return 0 on success or a negative -value on error. -.PP -\&\fBUI_UTIL_wrap_read_pem_callback()\fR returns a valid \fB\s-1UI_METHOD\s0\fR structure or \s-1NULL\s0 -if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBUI_get_default_method\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/UI_UTIL_read_pw_string.3ossl b/openssl-install/share/man/man3/UI_UTIL_read_pw_string.3ossl deleted file mode 120000 index 19065bf0..00000000 --- a/openssl-install/share/man/man3/UI_UTIL_read_pw_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_UTIL_read_pw.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_UTIL_wrap_read_pem_callback.3ossl b/openssl-install/share/man/man3/UI_UTIL_wrap_read_pem_callback.3ossl deleted file mode 120000 index 19065bf0..00000000 --- a/openssl-install/share/man/man3/UI_UTIL_wrap_read_pem_callback.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_UTIL_read_pw.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_add_error_string.3ossl b/openssl-install/share/man/man3/UI_add_error_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_add_error_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_add_info_string.3ossl b/openssl-install/share/man/man3/UI_add_info_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_add_info_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_add_input_boolean.3ossl b/openssl-install/share/man/man3/UI_add_input_boolean.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_add_input_boolean.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_add_input_string.3ossl b/openssl-install/share/man/man3/UI_add_input_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_add_input_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_add_user_data.3ossl b/openssl-install/share/man/man3/UI_add_user_data.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_add_user_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_add_verify_string.3ossl b/openssl-install/share/man/man3/UI_add_verify_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_add_verify_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_construct_prompt.3ossl b/openssl-install/share/man/man3/UI_construct_prompt.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_construct_prompt.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_create_method.3ossl b/openssl-install/share/man/man3/UI_create_method.3ossl deleted file mode 100644 index 1fa1f341..00000000 --- a/openssl-install/share/man/man3/UI_create_method.3ossl +++ /dev/null @@ -1,328 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "UI_CREATE_METHOD 3ossl" -.TH UI_CREATE_METHOD 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -UI_METHOD, -UI_create_method, UI_destroy_method, UI_method_set_opener, -UI_method_set_writer, UI_method_set_flusher, UI_method_set_reader, -UI_method_set_closer, UI_method_set_data_duplicator, -UI_method_set_prompt_constructor, UI_method_set_ex_data, -UI_method_get_opener, UI_method_get_writer, UI_method_get_flusher, -UI_method_get_reader, UI_method_get_closer, -UI_method_get_data_duplicator, UI_method_get_data_destructor, -UI_method_get_prompt_constructor, UI_method_get_ex_data \- user -interface method creation and destruction -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ui_method_st UI_METHOD; -\& -\& UI_METHOD *UI_create_method(const char *name); -\& void UI_destroy_method(UI_METHOD *ui_method); -\& int UI_method_set_opener(UI_METHOD *method, int (*opener) (UI *ui)); -\& int UI_method_set_writer(UI_METHOD *method, -\& int (*writer) (UI *ui, UI_STRING *uis)); -\& int UI_method_set_flusher(UI_METHOD *method, int (*flusher) (UI *ui)); -\& int UI_method_set_reader(UI_METHOD *method, -\& int (*reader) (UI *ui, UI_STRING *uis)); -\& int UI_method_set_closer(UI_METHOD *method, int (*closer) (UI *ui)); -\& int UI_method_set_data_duplicator(UI_METHOD *method, -\& void *(*duplicator) (UI *ui, void *ui_data), -\& void (*destructor)(UI *ui, void *ui_data)); -\& int UI_method_set_prompt_constructor(UI_METHOD *method, -\& char *(*prompt_constructor) (UI *ui, -\& const char -\& *object_desc, -\& const char -\& *object_name)); -\& int UI_method_set_ex_data(UI_METHOD *method, int idx, void *data); -\& int (*UI_method_get_opener(const UI_METHOD *method)) (UI *); -\& int (*UI_method_get_writer(const UI_METHOD *method)) (UI *, UI_STRING *); -\& int (*UI_method_get_flusher(const UI_METHOD *method)) (UI *); -\& int (*UI_method_get_reader(const UI_METHOD *method)) (UI *, UI_STRING *); -\& int (*UI_method_get_closer(const UI_METHOD *method)) (UI *); -\& char *(*UI_method_get_prompt_constructor(const UI_METHOD *method)) -\& (UI *, const char *, const char *); -\& void *(*UI_method_get_data_duplicator(const UI_METHOD *method)) (UI *, void *); -\& void (*UI_method_get_data_destructor(const UI_METHOD *method)) (UI *, void *); -\& const void *UI_method_get_ex_data(const UI_METHOD *method, int idx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A method contains a few functions that implement the low-level of the -User Interface. -These functions are: -.IP "an opener" 4 -.IX Item "an opener" -This function takes a reference to a \s-1UI\s0 and starts a session, for -example by opening a channel to a tty, or by creating a dialog box. -.IP "a writer" 4 -.IX Item "a writer" -This function takes a reference to a \s-1UI\s0 and a \s-1UI\s0 String, and writes -the string where appropriate, maybe to the tty, maybe added as a field -label in a dialog box. -Note that this gets fed all strings associated with a \s-1UI,\s0 one after -the other, so care must be taken which ones it actually uses. -.IP "a flusher" 4 -.IX Item "a flusher" -This function takes a reference to a \s-1UI,\s0 and flushes everything that -has been output so far. -For example, if the method builds up a dialog box, this can be used to -actually display it and accepting input ended with a pressed button. -.IP "a reader" 4 -.IX Item "a reader" -This function takes a reference to a \s-1UI\s0 and a \s-1UI\s0 string and reads off -the given prompt, maybe from the tty, maybe from a field in a dialog -box. -Note that this gets fed all strings associated with a \s-1UI,\s0 one after -the other, so care must be taken which ones it actually uses. -.IP "a closer" 4 -.IX Item "a closer" -This function takes a reference to a \s-1UI,\s0 and closes the session, maybe -by closing the channel to the tty, maybe by destroying a dialog box. -.PP -All of these functions are expected to return 0 on error, 1 on -success, or \-1 on out-off-band events, for example if some prompting -has been cancelled (by pressing Ctrl-C, for example). -Only the flusher or the reader are expected to return \-1. -If returned by another of the functions, it's treated as if 0 was -returned. -.PP -Regarding the writer and the reader, don't assume the former should -only write and don't assume the latter should only read. -This depends on the needs of the method. -.PP -For example, a typical tty reader wouldn't write the prompts in the -write, but would rather do so in the reader, because of the sequential -nature of prompting on a tty. -This is how the \fBUI_OpenSSL()\fR method does it. -.PP -In contrast, a method that builds up a dialog box would add all prompt -text in the writer, have all input read in the flusher and store the -results in some temporary buffer, and finally have the reader just -fetch those results. -.PP -The central function that uses these method functions is \fBUI_process()\fR, -and it does it in five steps: -.IP "1." 4 -Open the session using the opener function if that one's defined. -If an error occurs, jump to 5. -.IP "2." 4 -For every \s-1UI\s0 String associated with the \s-1UI,\s0 call the writer function -if that one's defined. -If an error occurs, jump to 5. -.IP "3." 4 -Flush everything using the flusher function if that one's defined. -If an error occurs, jump to 5. -.IP "4." 4 -For every \s-1UI\s0 String associated with the \s-1UI,\s0 call the reader function -if that one's defined. -If an error occurs, jump to 5. -.IP "5." 4 -Close the session using the closer function if that one's defined. -.PP -\&\fBUI_create_method()\fR creates a new \s-1UI\s0 method with a given \fBname\fR. -.PP -\&\fBUI_destroy_method()\fR destroys the given \s-1UI\s0 method \fBui_method\fR. -.PP -\&\fBUI_method_set_opener()\fR, \fBUI_method_set_writer()\fR, -\&\fBUI_method_set_flusher()\fR, \fBUI_method_set_reader()\fR and -\&\fBUI_method_set_closer()\fR set the five main method function to the given -function pointer. -.PP -\&\fBUI_method_set_data_duplicator()\fR sets the user data duplicator and destructor. -See \fBUI_dup_user_data\fR\|(3). -.PP -\&\fBUI_method_set_prompt_constructor()\fR sets the prompt constructor. -See \fBUI_construct_prompt\fR\|(3). -.PP -\&\fBUI_method_set_ex_data()\fR sets application specific data with a given -\&\s-1EX_DATA\s0 index. -See \fBCRYPTO_get_ex_new_index\fR\|(3) for general information on how to -get that index. -.PP -\&\fBUI_method_get_opener()\fR, \fBUI_method_get_writer()\fR, -\&\fBUI_method_get_flusher()\fR, \fBUI_method_get_reader()\fR, -\&\fBUI_method_get_closer()\fR, \fBUI_method_get_data_duplicator()\fR, -\&\fBUI_method_get_data_destructor()\fR and \fBUI_method_get_prompt_constructor()\fR -return the different method functions. -.PP -\&\fBUI_method_get_ex_data()\fR returns the application data previously stored -with \fBUI_method_set_ex_data()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBUI_create_method()\fR returns a \s-1UI_METHOD\s0 pointer on success, \s-1NULL\s0 on -error. -.PP -\&\fBUI_method_set_opener()\fR, \fBUI_method_set_writer()\fR, -\&\fBUI_method_set_flusher()\fR, \fBUI_method_set_reader()\fR, -\&\fBUI_method_set_closer()\fR, \fBUI_method_set_data_duplicator()\fR and -\&\fBUI_method_set_prompt_constructor()\fR -return 0 on success, \-1 if the given \fBmethod\fR is \s-1NULL.\s0 -.PP -\&\fBUI_method_set_ex_data()\fR returns 1 on success and 0 on error (because -\&\fBCRYPTO_set_ex_data()\fR does so). -.PP -\&\fBUI_method_get_opener()\fR, \fBUI_method_get_writer()\fR, -\&\fBUI_method_get_flusher()\fR, \fBUI_method_get_reader()\fR, -\&\fBUI_method_get_closer()\fR, \fBUI_method_get_data_duplicator()\fR, -\&\fBUI_method_get_data_destructor()\fR and \fBUI_method_get_prompt_constructor()\fR -return the requested function pointer if it's set in the method, -otherwise \s-1NULL.\s0 -.PP -\&\fBUI_method_get_ex_data()\fR returns a pointer to the application specific -data associated with the method. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBUI\s0\fR\|(3), \fBCRYPTO_get_ex_data\fR\|(3), \s-1\fBUI_STRING\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBUI_method_set_data_duplicator()\fR, \fBUI_method_get_data_duplicator()\fR -and \fBUI_method_get_data_destructor()\fR functions were added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/UI_ctrl.3ossl b/openssl-install/share/man/man3/UI_ctrl.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_destroy_method.3ossl b/openssl-install/share/man/man3/UI_destroy_method.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_destroy_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_dup_error_string.3ossl b/openssl-install/share/man/man3/UI_dup_error_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_dup_error_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_dup_info_string.3ossl b/openssl-install/share/man/man3/UI_dup_info_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_dup_info_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_dup_input_boolean.3ossl b/openssl-install/share/man/man3/UI_dup_input_boolean.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_dup_input_boolean.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_dup_input_string.3ossl b/openssl-install/share/man/man3/UI_dup_input_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_dup_input_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_dup_user_data.3ossl b/openssl-install/share/man/man3/UI_dup_user_data.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_dup_user_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_dup_verify_string.3ossl b/openssl-install/share/man/man3/UI_dup_verify_string.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_dup_verify_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_free.3ossl b/openssl-install/share/man/man3/UI_free.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get0_action_string.3ossl b/openssl-install/share/man/man3/UI_get0_action_string.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get0_action_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get0_output_string.3ossl b/openssl-install/share/man/man3/UI_get0_output_string.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get0_output_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get0_result.3ossl b/openssl-install/share/man/man3/UI_get0_result.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_get0_result.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get0_result_string.3ossl b/openssl-install/share/man/man3/UI_get0_result_string.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get0_result_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get0_test_string.3ossl b/openssl-install/share/man/man3/UI_get0_test_string.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get0_test_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get0_user_data.3ossl b/openssl-install/share/man/man3/UI_get0_user_data.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_get0_user_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_app_data.3ossl b/openssl-install/share/man/man3/UI_get_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/UI_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_default_method.3ossl b/openssl-install/share/man/man3/UI_get_default_method.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_get_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_ex_data.3ossl b/openssl-install/share/man/man3/UI_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/UI_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_ex_new_index.3ossl b/openssl-install/share/man/man3/UI_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/UI_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_input_flags.3ossl b/openssl-install/share/man/man3/UI_get_input_flags.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get_input_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_method.3ossl b/openssl-install/share/man/man3/UI_get_method.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_get_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_result_length.3ossl b/openssl-install/share/man/man3/UI_get_result_length.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_get_result_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_result_maxsize.3ossl b/openssl-install/share/man/man3/UI_get_result_maxsize.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get_result_maxsize.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_result_minsize.3ossl b/openssl-install/share/man/man3/UI_get_result_minsize.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get_result_minsize.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_result_string_length.3ossl b/openssl-install/share/man/man3/UI_get_result_string_length.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get_result_string_length.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_get_string_type.3ossl b/openssl-install/share/man/man3/UI_get_string_type.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_get_string_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_closer.3ossl b/openssl-install/share/man/man3/UI_method_get_closer.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_closer.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_data_destructor.3ossl b/openssl-install/share/man/man3/UI_method_get_data_destructor.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_data_destructor.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_data_duplicator.3ossl b/openssl-install/share/man/man3/UI_method_get_data_duplicator.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_data_duplicator.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_ex_data.3ossl b/openssl-install/share/man/man3/UI_method_get_ex_data.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_flusher.3ossl b/openssl-install/share/man/man3/UI_method_get_flusher.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_flusher.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_opener.3ossl b/openssl-install/share/man/man3/UI_method_get_opener.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_opener.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_prompt_constructor.3ossl b/openssl-install/share/man/man3/UI_method_get_prompt_constructor.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_prompt_constructor.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_reader.3ossl b/openssl-install/share/man/man3/UI_method_get_reader.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_reader.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_get_writer.3ossl b/openssl-install/share/man/man3/UI_method_get_writer.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_get_writer.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_closer.3ossl b/openssl-install/share/man/man3/UI_method_set_closer.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_closer.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_data_duplicator.3ossl b/openssl-install/share/man/man3/UI_method_set_data_duplicator.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_data_duplicator.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_ex_data.3ossl b/openssl-install/share/man/man3/UI_method_set_ex_data.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_flusher.3ossl b/openssl-install/share/man/man3/UI_method_set_flusher.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_flusher.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_opener.3ossl b/openssl-install/share/man/man3/UI_method_set_opener.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_opener.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_prompt_constructor.3ossl b/openssl-install/share/man/man3/UI_method_set_prompt_constructor.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_prompt_constructor.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_reader.3ossl b/openssl-install/share/man/man3/UI_method_set_reader.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_reader.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_method_set_writer.3ossl b/openssl-install/share/man/man3/UI_method_set_writer.3ossl deleted file mode 120000 index b20ebea9..00000000 --- a/openssl-install/share/man/man3/UI_method_set_writer.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_create_method.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_new.3ossl b/openssl-install/share/man/man3/UI_new.3ossl deleted file mode 100644 index dc05314b..00000000 --- a/openssl-install/share/man/man3/UI_new.3ossl +++ /dev/null @@ -1,386 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "UI_NEW 3ossl" -.TH UI_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -UI, -UI_new, UI_new_method, UI_free, UI_add_input_string, UI_dup_input_string, -UI_add_verify_string, UI_dup_verify_string, UI_add_input_boolean, -UI_dup_input_boolean, UI_add_info_string, UI_dup_info_string, -UI_add_error_string, UI_dup_error_string, UI_construct_prompt, -UI_add_user_data, UI_dup_user_data, UI_get0_user_data, UI_get0_result, -UI_get_result_length, -UI_process, UI_ctrl, UI_set_default_method, UI_get_default_method, -UI_get_method, UI_set_method, UI_OpenSSL, UI_null \- user interface -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct ui_st UI; -\& -\& UI *UI_new(void); -\& UI *UI_new_method(const UI_METHOD *method); -\& void UI_free(UI *ui); -\& -\& int UI_add_input_string(UI *ui, const char *prompt, int flags, -\& char *result_buf, int minsize, int maxsize); -\& int UI_dup_input_string(UI *ui, const char *prompt, int flags, -\& char *result_buf, int minsize, int maxsize); -\& int UI_add_verify_string(UI *ui, const char *prompt, int flags, -\& char *result_buf, int minsize, int maxsize, -\& const char *test_buf); -\& int UI_dup_verify_string(UI *ui, const char *prompt, int flags, -\& char *result_buf, int minsize, int maxsize, -\& const char *test_buf); -\& int UI_add_input_boolean(UI *ui, const char *prompt, const char *action_desc, -\& const char *ok_chars, const char *cancel_chars, -\& int flags, char *result_buf); -\& int UI_dup_input_boolean(UI *ui, const char *prompt, const char *action_desc, -\& const char *ok_chars, const char *cancel_chars, -\& int flags, char *result_buf); -\& int UI_add_info_string(UI *ui, const char *text); -\& int UI_dup_info_string(UI *ui, const char *text); -\& int UI_add_error_string(UI *ui, const char *text); -\& int UI_dup_error_string(UI *ui, const char *text); -\& -\& char *UI_construct_prompt(UI *ui_method, -\& const char *phrase_desc, const char *object_name); -\& -\& void *UI_add_user_data(UI *ui, void *user_data); -\& int UI_dup_user_data(UI *ui, void *user_data); -\& void *UI_get0_user_data(UI *ui); -\& -\& const char *UI_get0_result(UI *ui, int i); -\& int UI_get_result_length(UI *ui, int i); -\& -\& int UI_process(UI *ui); -\& -\& int UI_ctrl(UI *ui, int cmd, long i, void *p, void (*f)()); -\& -\& void UI_set_default_method(const UI_METHOD *meth); -\& const UI_METHOD *UI_get_default_method(void); -\& const UI_METHOD *UI_get_method(UI *ui); -\& const UI_METHOD *UI_set_method(UI *ui, const UI_METHOD *meth); -\& -\& UI_METHOD *UI_OpenSSL(void); -\& const UI_METHOD *UI_null(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\s-1UI\s0 stands for User Interface, and is general purpose set of routines to -prompt the user for text-based information. Through user-written methods -(see \fBUI_create_method\fR\|(3)), prompting can be done in any way -imaginable, be it plain text prompting, through dialog boxes or from a -cell phone. -.PP -All the functions work through a context of the type \s-1UI.\s0 This context -contains all the information needed to prompt correctly as well as a -reference to a \s-1UI_METHOD,\s0 which is an ordered vector of functions that -carry out the actual prompting. -.PP -The first thing to do is to create a \s-1UI\s0 with \fBUI_new()\fR or \fBUI_new_method()\fR, -then add information to it with the UI_add or UI_dup functions. Also, -user-defined random data can be passed down to the underlying method -through calls to \fBUI_add_user_data()\fR or \fBUI_dup_user_data()\fR. The default -\&\s-1UI\s0 method doesn't care about these data, but other methods might. Finally, -use \fBUI_process()\fR to actually perform the prompting and \fBUI_get0_result()\fR -and \fBUI_get_result_length()\fR to find the result to the prompt and its length. -.PP -A \s-1UI\s0 can contain more than one prompt, which are performed in the given -sequence. Each prompt gets an index number which is returned by the -UI_add and UI_dup functions, and has to be used to get the corresponding -result with \fBUI_get0_result()\fR and \fBUI_get_result_length()\fR. -.PP -\&\fBUI_process()\fR can be called more than once on the same \s-1UI,\s0 thereby allowing -a \s-1UI\s0 to have a long lifetime, but can just as well have a short lifetime. -.PP -The functions are as follows: -.PP -\&\fBUI_new()\fR creates a new \s-1UI\s0 using the default \s-1UI\s0 method. When done with -this \s-1UI,\s0 it should be freed using \fBUI_free()\fR. -.PP -\&\fBUI_new_method()\fR creates a new \s-1UI\s0 using the given \s-1UI\s0 method. When done with -this \s-1UI,\s0 it should be freed using \fBUI_free()\fR. -.PP -\&\fBUI_OpenSSL()\fR returns the built-in \s-1UI\s0 method (note: not necessarily the -default one, since the default can be changed. See further on). This -method is the most machine/OS dependent part of OpenSSL and normally -generates the most problems when porting. -.PP -\&\fBUI_null()\fR returns a \s-1UI\s0 method that does nothing. Its use is to avoid -getting internal defaults for passed \s-1UI_METHOD\s0 pointers. -.PP -\&\fBUI_free()\fR removes a \s-1UI\s0 from memory, along with all other pieces of memory -that's connected to it, like duplicated input strings, results and others. -If \fBui\fR is \s-1NULL\s0 nothing is done. -.PP -\&\fBUI_add_input_string()\fR and \fBUI_add_verify_string()\fR add a prompt to the \s-1UI,\s0 -as well as flags and a result buffer and the desired minimum and maximum -sizes of the result, not counting the final \s-1NUL\s0 character. The given -information is used to prompt for information, for example a password, -and to verify a password (i.e. having the user enter it twice and check -that the same string was entered twice). \fBUI_add_verify_string()\fR takes -and extra argument that should be a pointer to the result buffer of the -input string that it's supposed to verify, or verification will fail. -.PP -\&\fBUI_add_input_boolean()\fR adds a prompt to the \s-1UI\s0 that's supposed to be answered -in a boolean way, with a single character for yes and a different character -for no. A set of characters that can be used to cancel the prompt is given -as well. The prompt itself is divided in two, one part being the -descriptive text (given through the \fIprompt\fR argument) and one describing -the possible answers (given through the \fIaction_desc\fR argument). -.PP -\&\fBUI_add_info_string()\fR and \fBUI_add_error_string()\fR add strings that are shown at -the same time as the prompt for extra information or to show an error string. -The difference between the two is only conceptual. With the built-in method, -there's no technical difference between them. Other methods may make a -difference between them, however. -.PP -The flags currently supported are \fB\s-1UI_INPUT_FLAG_ECHO\s0\fR, which is relevant for -\&\fBUI_add_input_string()\fR and will have the users response be echoed (when -prompting for a password, this flag should obviously not be used, and -\&\fB\s-1UI_INPUT_FLAG_DEFAULT_PWD\s0\fR, which means that a default password of some -sort will be used (completely depending on the application and the \s-1UI\s0 -method). -.PP -\&\fBUI_dup_input_string()\fR, \fBUI_dup_verify_string()\fR, \fBUI_dup_input_boolean()\fR, -\&\fBUI_dup_info_string()\fR and \fBUI_dup_error_string()\fR are basically the same -as their UI_add counterparts, except that they make their own copies -of all strings. -.PP -\&\fBUI_construct_prompt()\fR is a helper function that can be used to create -a prompt from two pieces of information: a phrase description \fIphrase_desc\fR -and an object name \fIobject_name\fR, where the latter may be \s-1NULL.\s0 -The default constructor (if there is none provided by the method used) -creates a string "Enter \fIphrase_desc\fR for \fIobject_name\fR:\*(L" -where the \*(R" for \fIobject_name\fR" part is left out if \fIobject_name\fR is \s-1NULL.\s0 -With the description \*(L"pass phrase\*(R" and the filename \*(L"foo.key\*(R", that becomes -\&\*(L"Enter pass phrase for foo.key:\*(R". Other methods may create whatever -string and may include encodings that will be processed by the other -method functions. -.PP -\&\fBUI_add_user_data()\fR adds a user data pointer for the method to use at any -time. The built-in \s-1UI\s0 method doesn't care about this info. Note that several -calls to this function doesn't add data, it replaces the previous blob -with the one given as argument. -.PP -\&\fBUI_dup_user_data()\fR duplicates the user data and works as an alternative -to \fBUI_add_user_data()\fR when the user data needs to be preserved for a longer -duration, perhaps even the lifetime of the application. The \s-1UI\s0 object takes -ownership of this duplicate and will free it whenever it gets replaced or -the \s-1UI\s0 is destroyed. \fBUI_dup_user_data()\fR returns 0 on success, or \-1 on memory -allocation failure or if the method doesn't have a duplicator function. -.PP -\&\fBUI_get0_user_data()\fR retrieves the data that has last been given to the -\&\s-1UI\s0 with \fBUI_add_user_data()\fR or UI_dup_user_data. -.PP -\&\fBUI_get0_result()\fR returns a pointer to the result buffer associated with -the information indexed by \fIi\fR. -.PP -\&\fBUI_get_result_length()\fR returns the length of the result buffer associated with -the information indexed by \fIi\fR. -.PP -\&\fBUI_process()\fR goes through the information given so far, does all the printing -and prompting and returns the final status, which is \-2 on out-of-band events -(Interrupt, Cancel, ...), \-1 on error and 0 on success. -.PP -\&\fBUI_ctrl()\fR adds extra control for the application author. For now, it -understands two commands: \fB\s-1UI_CTRL_PRINT_ERRORS\s0\fR, which makes \fBUI_process()\fR -print the OpenSSL error stack as part of processing the \s-1UI,\s0 and -\&\fB\s-1UI_CTRL_IS_REDOABLE\s0\fR, which returns a flag saying if the used \s-1UI\s0 can -be used again or not. -.PP -\&\fBUI_set_default_method()\fR changes the default \s-1UI\s0 method to the one given. -This function is not thread-safe and should not be called at the same time -as other OpenSSL functions. -.PP -\&\fBUI_get_default_method()\fR returns a pointer to the current default \s-1UI\s0 method. -.PP -\&\fBUI_get_method()\fR returns the \s-1UI\s0 method associated with a given \s-1UI.\s0 -.PP -\&\fBUI_set_method()\fR changes the \s-1UI\s0 method associated with a given \s-1UI.\s0 -.SH "NOTES" -.IX Header "NOTES" -The resulting strings that the built in method \fBUI_OpenSSL()\fR generate -are assumed to be encoded according to the current locale or (for -Windows) code page. -For applications having different demands, these strings need to be -converted appropriately by the caller. -For Windows, if the \fB\s-1OPENSSL_WIN32_UTF8\s0\fR environment variable is set, -the built-in method \fBUI_OpenSSL()\fR will produce \s-1UTF\-8\s0 encoded strings -instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBUI_new()\fR and \fBUI_new_method()\fR return a valid \fB\s-1UI\s0\fR structure or \s-1NULL\s0 if an error -occurred. -.PP -\&\fBUI_add_input_string()\fR, \fBUI_dup_input_string()\fR, \fBUI_add_verify_string()\fR, -\&\fBUI_dup_verify_string()\fR, \fBUI_add_input_boolean()\fR, \fBUI_dup_input_boolean()\fR, -\&\fBUI_add_info_string()\fR, \fBUI_dup_info_string()\fR, \fBUI_add_error_string()\fR -and \fBUI_dup_error_string()\fR return a positive number on success or a value which -is less than or equal to 0 otherwise. -.PP -\&\fBUI_construct_prompt()\fR returns a string or \s-1NULL\s0 if an error occurred. -.PP -\&\fBUI_dup_user_data()\fR returns 0 on success or \-1 on error. -.PP -\&\fBUI_get0_result()\fR returns a string or \s-1NULL\s0 on error. -.PP -\&\fBUI_get_result_length()\fR returns a positive integer or 0 on success; otherwise it -returns \-1 on error. -.PP -\&\fBUI_process()\fR returns 0 on success or a negative value on error. -.PP -\&\fBUI_ctrl()\fR returns a mask on success or \-1 on error. -.PP -\&\fBUI_get_default_method()\fR, \fBUI_get_method()\fR, \fBUI_OpenSSL()\fR, \fBUI_null()\fR and -\&\fBUI_set_method()\fR return either a valid \fB\s-1UI_METHOD\s0\fR structure or \s-1NULL\s0 -respectively. -.SH "HISTORY" -.IX Header "HISTORY" -The \fBUI_dup_user_data()\fR function was added in OpenSSL 1.1.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/UI_new_method.3ossl b/openssl-install/share/man/man3/UI_new_method.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_new_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_null.3ossl b/openssl-install/share/man/man3/UI_null.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_null.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_process.3ossl b/openssl-install/share/man/man3/UI_process.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_process.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_set_app_data.3ossl b/openssl-install/share/man/man3/UI_set_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/UI_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_set_default_method.3ossl b/openssl-install/share/man/man3/UI_set_default_method.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_set_default_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_set_ex_data.3ossl b/openssl-install/share/man/man3/UI_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/UI_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_set_method.3ossl b/openssl-install/share/man/man3/UI_set_method.3ossl deleted file mode 120000 index a7ac9ff5..00000000 --- a/openssl-install/share/man/man3/UI_set_method.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_set_result.3ossl b/openssl-install/share/man/man3/UI_set_result.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_set_result.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_set_result_ex.3ossl b/openssl-install/share/man/man3/UI_set_result_ex.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_set_result_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/UI_string_types.3ossl b/openssl-install/share/man/man3/UI_string_types.3ossl deleted file mode 120000 index f658dc09..00000000 --- a/openssl-install/share/man/man3/UI_string_types.3ossl +++ /dev/null @@ -1 +0,0 @@ -UI_STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/USERNOTICE_free.3ossl b/openssl-install/share/man/man3/USERNOTICE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/USERNOTICE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/USERNOTICE_new.3ossl b/openssl-install/share/man/man3/USERNOTICE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/USERNOTICE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509V3_EXT_d2i.3ossl b/openssl-install/share/man/man3/X509V3_EXT_d2i.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509V3_EXT_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509V3_EXT_i2d.3ossl b/openssl-install/share/man/man3/X509V3_EXT_i2d.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509V3_EXT_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509V3_add1_i2d.3ossl b/openssl-install/share/man/man3/X509V3_add1_i2d.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509V3_add1_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509V3_get_d2i.3ossl b/openssl-install/share/man/man3/X509V3_get_d2i.3ossl deleted file mode 100644 index dedc72d5..00000000 --- a/openssl-install/share/man/man3/X509V3_get_d2i.3ossl +++ /dev/null @@ -1,396 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509V3_GET_D2I 3ossl" -.TH X509V3_GET_D2I 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509V3_get_d2i, X509V3_add1_i2d, X509V3_EXT_d2i, X509V3_EXT_i2d, -X509_get_ext_d2i, X509_add1_ext_i2d, -X509_ACERT_get_ext_d2i, X509_ACERT_add1_ext_i2d, -X509_CRL_get_ext_d2i, X509_CRL_add1_ext_i2d, -X509_REVOKED_get_ext_d2i, X509_REVOKED_add1_ext_i2d, -X509_get0_extensions, X509_ACERT_get0_extensions, X509_CRL_get0_extensions, -X509_REVOKED_get0_extensions \- X509 extension decode and encode functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void *X509V3_get_d2i(const STACK_OF(X509_EXTENSION) *x, int nid, int *crit, -\& int *idx); -\& int X509V3_add1_i2d(STACK_OF(X509_EXTENSION) **x, int nid, void *value, -\& int crit, unsigned long flags); -\& -\& void *X509V3_EXT_d2i(X509_EXTENSION *ext); -\& X509_EXTENSION *X509V3_EXT_i2d(int ext_nid, int crit, void *ext_struc); -\& -\& void *X509_get_ext_d2i(const X509 *x, int nid, int *crit, int *idx); -\& int X509_add1_ext_i2d(X509 *x, int nid, void *value, int crit, -\& unsigned long flags); -\& -\& void *X509_ACERT_get_ext_d2i(const X509_ACERT *x, int nid, int *crit, int *idx); -\& int X509_ACERT_add1_ext_i2d(X509_ACERT *x, int nid, void *value, int crit, -\& unsigned long flags); -\& -\& void *X509_CRL_get_ext_d2i(const X509_CRL *crl, int nid, int *crit, int *idx); -\& int X509_CRL_add1_ext_i2d(X509_CRL *crl, int nid, void *value, int crit, -\& unsigned long flags); -\& -\& void *X509_REVOKED_get_ext_d2i(const X509_REVOKED *r, int nid, int *crit, int *idx); -\& int X509_REVOKED_add1_ext_i2d(X509_REVOKED *r, int nid, void *value, int crit, -\& unsigned long flags); -\& -\& const STACK_OF(X509_EXTENSION) *X509_get0_extensions(const X509 *x); -\& const STACK_OF(X509_EXTENSION) *X509_ACERT_get0_extensions(const X509 *x); -\& const STACK_OF(X509_EXTENSION) *X509_CRL_get0_extensions(const X509_CRL *crl); -\& const STACK_OF(X509_EXTENSION) *X509_REVOKED_get0_extensions(const X509_REVOKED *r); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509V3_get_d2i()\fR looks for an extension with \s-1OID\s0 \fInid\fR in the extensions -\&\fIx\fR and, if found, decodes it. If \fIidx\fR is \s-1NULL\s0 then only one -occurrence of an extension is permissible, otherwise the first extension after -index \fI*idx\fR is returned and \fI*idx\fR updated to the location of the extension. -If \fIcrit\fR is not \s-1NULL\s0 then \fI*crit\fR is set to a status value: \-2 if the -extension occurs multiple times (this is only returned if \fIidx\fR is \s-1NULL\s0), -\&\-1 if the extension could not be found, 0 if the extension is found and is -not critical and 1 if critical. A pointer to an extension specific structure -or \s-1NULL\s0 is returned. -.PP -\&\fBX509V3_add1_i2d()\fR adds extension \fIvalue\fR to \s-1STACK\s0 \fI*x\fR (allocating a new -\&\s-1STACK\s0 if necessary) using \s-1OID\s0 \fInid\fR and criticality \fIcrit\fR according -to \fIflags\fR. -.PP -\&\fBX509V3_EXT_d2i()\fR attempts to decode the \s-1ASN.1\s0 data contained in extension -\&\fIext\fR and returns a pointer to an extension specific structure or \s-1NULL\s0 -if the extension could not be decoded (invalid syntax or not supported). -.PP -\&\fBX509V3_EXT_i2d()\fR encodes the extension specific structure \fIext_struc\fR -with \s-1OID\s0 \fIext_nid\fR and criticality \fIcrit\fR. -.PP -\&\fBX509_get_ext_d2i()\fR and \fBX509_add1_ext_i2d()\fR operate on the extensions of -certificate \fIx\fR. They are otherwise identical to \fBX509V3_get_d2i()\fR and -\&\fBX509V3_add1_i2d()\fR. -.PP -\&\fBX509_ACERT_get_ext_d2i()\fR and \fBX509_ACERT_add1_ext_i2d()\fR operate on the extensions -of \fBX509_ACERT\fR structure \fIx\fR. They are otherwise identical to \fBX509V3_get_d2i()\fR -and \fBX509V3_add1_i2d()\fR. -.PP -\&\fBX509_CRL_get_ext_d2i()\fR and \fBX509_CRL_add1_ext_i2d()\fR operate on the extensions -of \s-1CRL\s0 \fIcrl\fR. They are otherwise identical to \fBX509V3_get_d2i()\fR and -\&\fBX509V3_add1_i2d()\fR. -.PP -\&\fBX509_REVOKED_get_ext_d2i()\fR and \fBX509_REVOKED_add1_ext_i2d()\fR operate on the -extensions of \fBX509_REVOKED\fR structure \fIr\fR (i.e for \s-1CRL\s0 entry extensions). -They are otherwise identical to \fBX509V3_get_d2i()\fR and \fBX509V3_add1_i2d()\fR. -.PP -\&\fBX509_get0_extensions()\fR, \fBX509_ACERT_get0_extensions()\fR, -\&\fBX509_CRL_get0_extensions()\fR and \fBX509_REVOKED_get0_extensions()\fR return a -\&\s-1STACK\s0 of all the extensions of a certificate, an attribute certificate, -a \s-1CRL\s0 or a \s-1CRL\s0 entry respectively. -.SH "NOTES" -.IX Header "NOTES" -In almost all cases an extension can occur at most once and multiple -occurrences is an error. Therefore, the \fIidx\fR parameter is usually \s-1NULL.\s0 -.PP -The \fIflags\fR parameter may be one of the following values. -.PP -\&\fBX509V3_ADD_DEFAULT\fR appends a new extension only if the extension does -not exist. An error is returned if the extension exists. -.PP -\&\fBX509V3_ADD_APPEND\fR appends a new extension, ignoring whether the extension -exists. -.PP -\&\fBX509V3_ADD_REPLACE\fR replaces an existing extension. If the extension does -not exist, appends a new extension. -.PP -\&\fBX509V3_ADD_REPLACE_EXISTING\fR replaces an existing extension. If the -extension does not exist, returns an error. -.PP -\&\fBX509V3_ADD_KEEP_EXISTING\fR appends a new extension only if the extension does -not exist. An error is \fBnot\fR returned if the extension exists. -.PP -\&\fBX509V3_ADD_DELETE\fR deletes and frees an existing extension. If the extension -does not exist, returns an error. No new extension is added. -.PP -If \fBX509V3_ADD_SILENT\fR is bitwise ORed with \fIflags\fR: any error returned -will not be added to the error queue. -.PP -The function \fBX509V3_get_d2i()\fR and its variants -will return \s-1NULL\s0 if the extension is not -found, occurs multiple times or cannot be decoded. It is possible to -determine the precise reason by checking the value of \fI*crit\fR. -The returned pointer must be explicitly freed. -.PP -The function \fBX509V3_add1_i2d()\fR and its variants allocate \fBX509_EXTENSION\fR -objects on \s-1STACK\s0 \fI*x\fR depending on \fIflags\fR. The \fBX509_EXTENSION\fR objects -must be explicitly freed using \fBX509_EXTENSION_free()\fR. -.SH "SUPPORTED EXTENSIONS" -.IX Header "SUPPORTED EXTENSIONS" -The following sections contain a list of all supported extensions -including their name and \s-1NID.\s0 -.SS "\s-1PKIX\s0 Certificate Extensions" -.IX Subsection "PKIX Certificate Extensions" -The following certificate extensions are defined in \s-1PKIX\s0 standards such as -\&\s-1RFC5280.\s0 -.PP -.Vb 3 -\& Basic Constraints NID_basic_constraints -\& Key Usage NID_key_usage -\& Extended Key Usage NID_ext_key_usage -\& -\& Subject Key Identifier NID_subject_key_identifier -\& Authority Key Identifier NID_authority_key_identifier -\& -\& Private Key Usage Period NID_private_key_usage_period -\& -\& Subject Alternative Name NID_subject_alt_name -\& Issuer Alternative Name NID_issuer_alt_name -\& -\& Authority Information Access NID_info_access -\& Subject Information Access NID_sinfo_access -\& -\& Name Constraints NID_name_constraints -\& -\& Certificate Policies NID_certificate_policies -\& Policy Mappings NID_policy_mappings -\& Policy Constraints NID_policy_constraints -\& Inhibit Any Policy NID_inhibit_any_policy -\& -\& TLS Feature NID_tlsfeature -.Ve -.SS "Netscape Certificate Extensions" -.IX Subsection "Netscape Certificate Extensions" -The following are (largely obsolete) Netscape certificate extensions. -.PP -.Vb 8 -\& Netscape Cert Type NID_netscape_cert_type -\& Netscape Base Url NID_netscape_base_url -\& Netscape Revocation Url NID_netscape_revocation_url -\& Netscape CA Revocation Url NID_netscape_ca_revocation_url -\& Netscape Renewal Url NID_netscape_renewal_url -\& Netscape CA Policy Url NID_netscape_ca_policy_url -\& Netscape SSL Server Name NID_netscape_ssl_server_name -\& Netscape Comment NID_netscape_comment -.Ve -.SS "Miscellaneous Certificate Extensions" -.IX Subsection "Miscellaneous Certificate Extensions" -.Vb 2 -\& Strong Extranet ID NID_sxnet -\& Proxy Certificate Information NID_proxyCertInfo -.Ve -.SS "\s-1PKIX CRL\s0 Extensions" -.IX Subsection "PKIX CRL Extensions" -The following are \s-1CRL\s0 extensions from \s-1PKIX\s0 standards such as \s-1RFC5280.\s0 -.PP -.Vb 6 -\& CRL Number NID_crl_number -\& CRL Distribution Points NID_crl_distribution_points -\& Delta CRL Indicator NID_delta_crl -\& Freshest CRL NID_freshest_crl -\& Invalidity Date NID_invalidity_date -\& Issuing Distribution Point NID_issuing_distribution_point -.Ve -.PP -The following are \s-1CRL\s0 entry extensions from \s-1PKIX\s0 standards such as \s-1RFC5280.\s0 -.PP -.Vb 2 -\& CRL Reason Code NID_crl_reason -\& Certificate Issuer NID_certificate_issuer -.Ve -.SS "\s-1OCSP\s0 Extensions" -.IX Subsection "OCSP Extensions" -.Vb 7 -\& OCSP Nonce NID_id_pkix_OCSP_Nonce -\& OCSP CRL ID NID_id_pkix_OCSP_CrlID -\& Acceptable OCSP Responses NID_id_pkix_OCSP_acceptableResponses -\& OCSP No Check NID_id_pkix_OCSP_noCheck -\& OCSP Archive Cutoff NID_id_pkix_OCSP_archiveCutoff -\& OCSP Service Locator NID_id_pkix_OCSP_serviceLocator -\& Hold Instruction Code NID_hold_instruction_code -.Ve -.SS "Certificate Transparency Extensions" -.IX Subsection "Certificate Transparency Extensions" -The following extensions are used by certificate transparency, \s-1RFC6962\s0 -.PP -.Vb 2 -\& CT Precertificate SCTs NID_ct_precert_scts -\& CT Certificate SCTs NID_ct_cert_scts -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509V3_get_d2i()\fR, its variants, and \fBX509V3_EXT_d2i()\fR return -a pointer to an extension specific structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBX509V3_add1_i2d()\fR and its variants return 1 if the operation is successful -and 0 if it fails due to a non-fatal error (extension not found, already exists, -cannot be encoded) or \-1 due to a fatal error such as a memory allocation -failure. -.PP -\&\fBX509V3_EXT_i2d()\fR returns a pointer to an \fBX509_EXTENSION\fR structure -or \s-1NULL\s0 if an error occurs. -.PP -\&\fBX509_get0_extensions()\fR, \fBX509_CRL_get0_extensions()\fR and -\&\fBX509_REVOKED_get0_extensions()\fR return a stack of extensions. They return -\&\s-1NULL\s0 if no extensions are present. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509V3_set_ctx.3ossl b/openssl-install/share/man/man3/X509V3_set_ctx.3ossl deleted file mode 100644 index f4b2e01f..00000000 --- a/openssl-install/share/man/man3/X509V3_set_ctx.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509V3_SET_CTX 3ossl" -.TH X509V3_SET_CTX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509V3_set_ctx, -X509V3_set_issuer_pkey \- X.509 v3 extension generation utilities -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void X509V3_set_ctx(X509V3_CTX *ctx, X509 *issuer, X509 *subject, -\& X509_REQ *req, X509_CRL *crl, int flags); -\& int X509V3_set_issuer_pkey(X509V3_CTX *ctx, EVP_PKEY *pkey); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509V3_set_ctx()\fR fills in the basic fields of \fIctx\fR of type \fBX509V3_CTX\fR, -providing details potentially needed by functions producing X509 v3 extensions. -These may make use of fields of the certificate \fIsubject\fR, the certification -request \fIreq\fR, or the certificate revocation list \fIcrl\fR. -At most one of these three parameters can be non-NULL. -When constructing the subject key identifier of a certificate by computing a -hash value of its public key, the public key is taken from \fIsubject\fR or \fIreq\fR. -Similarly, when constructing subject alternative names from any email addresses -contained in a subject \s-1DN,\s0 the subject \s-1DN\s0 is taken from \fIsubject\fR or \fIreq\fR. -If \fIsubject\fR or \fIcrl\fR is provided, \fIissuer\fR should point to its issuer, for -instance as a reference for generating the authority key identifier extension. -\&\fIissuer\fR may be the same pointer value as \fIsubject\fR (which usually is an -indication that the \fIsubject\fR certificate is self-issued or even self-signed). -In this case the fallback source for generating the authority key identifier -extension will be taken from any value provided using \fBX509V3_set_issuer_pkey()\fR. -\&\fIflags\fR may be 0 -or contain \fBX509V3_CTX_TEST\fR, which means that just the syntax of -extension definitions is to be checked without actually producing any extension, -or \fBX509V3_CTX_REPLACE\fR, which means that each X.509v3 extension added as -defined in some configuration section shall replace any already existing -extension with the same \s-1OID.\s0 -.PP -\&\fBX509V3_set_issuer_pkey()\fR explicitly sets the issuer private key of -the subject certificate that has been provided in \fIctx\fR. -This should be done in case the \fIissuer\fR and \fIsubject\fR arguments to -\&\fBX509V3_set_ctx()\fR have the same pointer value -to provide fallback data for the authority key identifier extension. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509V3_set_issuer_pkey()\fR returns 1 on success and 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_add_ext\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509V3_set_issuer_pkey()\fR was added in OpenSSL 3.0. -.PP -\&\s-1CTX_TEST\s0 was deprecated in OpenSSL 3.0; use X509V3_CTX_TEST instead. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509V3_set_issuer_pkey.3ossl b/openssl-install/share/man/man3/X509V3_set_issuer_pkey.3ossl deleted file mode 120000 index 5fef4434..00000000 --- a/openssl-install/share/man/man3/X509V3_set_issuer_pkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_set_ctx.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_INFO_free.3ossl b/openssl-install/share/man/man3/X509_ACERT_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_INFO_it.3ossl b/openssl-install/share/man/man3/X509_ACERT_INFO_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_INFO_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_INFO_new.3ossl b/openssl-install/share/man/man3/X509_ACERT_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_free.3ossl b/openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_new.3ossl b/openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_ISSUER_V2FORM_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_add1_attr.3ossl b/openssl-install/share/man/man3/X509_ACERT_add1_attr.3ossl deleted file mode 100644 index ca842048..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_add1_attr.3ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ACERT_ADD1_ATTR 3ossl" -.TH X509_ACERT_ADD1_ATTR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_ACERT_add1_attr, -X509_ACERT_add1_attr_by_NID, -X509_ACERT_add1_attr_by_OBJ, -X509_ACERT_add1_attr_by_txt, -X509_ACERT_delete_attr -\&\- X509_ACERT attribute functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_ACERT_add1_attr(X509_ACERT *x, X509_ATTRIBUTE *attr); -\& int X509_ACERT_add1_attr_by_NID(X509_ACERT *x, int nid, int type, -\& const void *bytes, int len); -\& int X509_ACERT_add1_attr_by_OBJ(X509_ACERT *x, const ASN1_OBJECT *obj, -\& int type, const void *bytes, int len); -\& int X509_ACERT_add1_attr_by_txt(X509_ACERT *x, const char *attrname, int type, -\& const unsigned char *bytes, int len); -\& X509_ATTRIBUTE *X509_ACERT_delete_attr(X509_ACERT *x, int loc); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_ACERT_add1_attr()\fR adds a constructed X509_ATTRIBUTE \fBattr\fR to the -existing X509_ACERT structure \fBx\fR. -.PP -\&\fBX509_ACERT_add1_attr_by_NID()\fR and \fBX509_ACERT_add1_attr_by_OBJ()\fR -add an attribute of type \fInid\fR or \fIobj\fR with a value of \s-1ASN1\s0 -type \fItype\fR constructed using \fIlen\fR bytes from \fIbytes\fR. -.PP -\&\fBX509_ACERT_add1_attr_by_txt()\fR adds an attribute of type \fIattrname\fR with a value of -\&\s-1ASN1\s0 type \fItype\fR constructed using \fIlen\fR bytes from \fIbytes\fR. -.PP -\&\fBX509_ACERT_delete_attr()\fR will delete the \fIloc\fRth attribute from \fIx\fR and -return a pointer to it or \s-1NULL\s0 if there are fewer than \fIloc\fR attributes -contained in \fIx\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_ACERT_add1_attr()\fR, \fBX509_ACERT_add1_attr_by_NID()\fR, and -\&\fBX509_ACERT_add1_attr_by_OBJ()\fR return 1 for success and 0 for failure. -.PP -\&\fBX509_ACERT_delete_attr()\fR returns a \fBX509_ATTRIBUTE\fR pointer on -success or \s-1NULL\s0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_ACERT_get_attr_count\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_ACERT_add1_attr()\fR, \fBX509_ACERT_add1_attr_by_NID()\fR, \fBX509_ACERT_add1_attr_by_OBJ()\fR, -\&\fBX509_ACERT_add1_attr_by_txt()\fR and \fBX509_ACERT_delete_attr()\fR were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_NID.3ossl deleted file mode 120000 index 978d51ff..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_add1_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_OBJ.3ossl deleted file mode 120000 index 978d51ff..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_add1_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_txt.3ossl b/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_txt.3ossl deleted file mode 120000 index 978d51ff..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_add1_attr_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_add1_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_add1_ext_i2d.3ossl b/openssl-install/share/man/man3/X509_ACERT_add1_ext_i2d.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_add1_ext_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_add_attr_nconf.3ossl b/openssl-install/share/man/man3/X509_ACERT_add_attr_nconf.3ossl deleted file mode 100644 index bb486f57..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_add_attr_nconf.3ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ACERT_ADD_ATTR_NCONF 3ossl" -.TH X509_ACERT_ADD_ATTR_NCONF 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_ACERT_add_attr_nconf -\&\- Add attributes to X509_ACERT from configuration section -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_ACERT_add_attr_nconf(CONF *conf, const char *section, -\& X509_ACERT *acert); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_ACERT_add_attr_nconf()\fR adds one or more \fBX509_ATTRIBUTE\fRs to the -existing \fBX509_ACERT\fR structure \fIacert\fR. The attributes are read -from a \fIsection\fR of the \fIconf\fR object. -.PP -The give \fIsection\fR of the configuration should contain attribute -descriptions of the form: -.PP -.Vb 1 -\& attribute_name = value -.Ve -.PP -The format of \fBvalue\fR will vary depending on the \fBattribute_name\fR. -\&\fBvalue\fR can either be a string value or an \fB\s-1ASN1_TYPE\s0\fR -object. -.PP -To encode an \fB\s-1ASN1_TYPE\s0\fR object, use the prefix \*(L"\s-1ASN1:\*(R"\s0 followed by -the object description that uses the same syntax as \fBASN1_generate_nconf\fR\|(3). -For example: -.PP -.Vb 1 -\& id\-aca\-group = ASN1:SEQUENCE:ietfattr -\& -\& [ietfattr] -\& values = SEQUENCE:groups -\& -\& [groups] -\& 1.string = UTF8:mygroup1 -.Ve -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_ACERT_add_attr_nconf()\fR returns 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBASN1_generate_nconf\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBX509_ACERT_add_attr_nconf()\fR was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_ACERT_delete_attr.3ossl b/openssl-install/share/man/man3/X509_ACERT_delete_attr.3ossl deleted file mode 120000 index 978d51ff..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_delete_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_add1_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_dup.3ossl b/openssl-install/share/man/man3/X509_ACERT_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_free.3ossl b/openssl-install/share/man/man3/X509_ACERT_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_extensions.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_extensions.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_holder_baseCertId.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_holder_baseCertId.3ossl deleted file mode 100644 index 4a9151c4..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_holder_baseCertId.3ossl +++ /dev/null @@ -1,246 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ACERT_GET0_HOLDER_BASECERTID 3ossl" -.TH X509_ACERT_GET0_HOLDER_BASECERTID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_ACERT_get0_holder_baseCertId, -X509_ACERT_get0_holder_digest, -X509_ACERT_get0_holder_entityName, -X509_ACERT_set0_holder_baseCertId, -X509_ACERT_set0_holder_digest, -X509_ACERT_set0_holder_entityName, -OSSL_ISSUER_SERIAL_get0_issuer, -OSSL_ISSUER_SERIAL_get0_issuerUID, -OSSL_ISSUER_SERIAL_get0_serial, -OSSL_ISSUER_SERIAL_set1_issuer, -OSSL_ISSUER_SERIAL_set1_issuerUID, -OSSL_ISSUER_SERIAL_set1_serial, -OSSL_OBJECT_DIGEST_INFO_get0_digest, -OSSL_OBJECT_DIGEST_INFO_set1_digest \- get and set Attribute Certificate holder fields -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const GENERAL_NAMES *X509_ACERT_get0_holder_entityName(const X509_ACERT *x); -\& OSSL_ISSUER_SERIAL *X509_ACERT_get0_holder_baseCertId(const X509_ACERT *x); -\& OSSL_OBJECT_DIGEST_INFO * X509_ACERT_get0_holder_digest(const X509_ACERT *x); -\& void X509_ACERT_set0_holder_entityName(X509_ACERT *x, GENERAL_NAMES *name); -\& void X509_ACERT_set0_holder_baseCertId(X509_ACERT *x, OSSL_ISSUER_SERIAL *isss); -\& void X509_ACERT_set0_holder_digest(X509_ACERT *x, -\& OSSL_OBJECT_DIGEST_INFO *dinfo); -\& -\& X509_NAME *OSSL_ISSUER_SERIAL_get0_issuer(OSSL_ISSUER_SERIAL *isss); -\& ASN1_INTEGER *OSSL_ISSUER_SERIAL_get0_serial(OSSL_ISSUER_SERIAL *isss); -\& ASN1_BIT_STRING *OSSL_ISSUER_SERIAL_get0_issuerUID(OSSL_ISSUER_SERIAL *isss); -\& int OSSL_ISSUER_SERIAL_set1_issuer(OSSL_ISSUER_SERIAL *isss, X509_NAME *issuer); -\& int OSSL_ISSUER_SERIAL_set1_serial(OSSL_ISSUER_SERIAL *isss, ASN1_INTEGER *serial); -\& int OSSL_ISSUER_SERIAL_set1_issuerUID(OSSL_ISSUER_SERIAL *isss, ASN1_BIT_STRING *uid); -\& -\& void OSSL_OBJECT_DIGEST_INFO_get0_digest(OSSL_OBJECT_DIGEST_INFO *o, -\& ASN1_ENUMERATED **digestedObjectType, -\& X509_ALGOR **digestAlgorithm, -\& ASN1_BIT_STRING **digest); -\& void OSSL_OBJECT_DIGEST_INFO_set1_digest(OSSL_OBJECT_DIGEST_INFO *o, -\& ASN1_ENUMERATED *digestedObjectType, -\& X509_ALGOR *digestAlgorithm, -\& ASN1_BIT_STRING *digest); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These routines set and get the holder identity of an X509 attribute certificate. -.PP -\&\fBX509_ACERT_set0_holder_entityName()\fR sets the identity as a \fB\s-1GENERAL_NAME\s0\fR -\&\fIname\fR, \fBX509_ACERT_set0_holder_baseCertId()\fR sets the identity based on the -issuer and serial number of a certificate detailed in \fIisss\fR and -\&\fBX509_ACERT_set0_holder_digest()\fR sets the holder entity based on digest -information \fIdinfo\fR. Although \s-1RFC 5755\s0 section 4.2.2 recommends that only -one of the above methods be used to set the holder identity for a given -attribute certificate \fIx\fR, setting multiple methods at the same time is -possible. It is up to the application to handle cases when conflicting -identity information is specified using different methods. -.PP -Pointers to the internal structures describing the holder identity of -attribute certificate \fIx\fR can be retrieved with -\&\fBX509_ACERT_get0_holder_entityName()\fR, \fBX509_ACERT_get0_holder_baseCertId()\fR, and -\&\fBX509_ACERT_get0_holder_digest()\fR. -.PP -A \fB\s-1OSSL_ISSUER_SERIAL\s0\fR object holds the subject name and \s-1UID\s0 of a certificate -issuer and a certificate's serial number. \fBOSSL_ISSUER_SERIAL_set1_issuer()\fR, -\&\fBOSSL_ISSUER_SERIAL_set1_issuerUID()\fR, and \fBOSSL_ISSUER_SERIAL_set1_serial()\fR -respectively copy these values into the \fB\s-1OSSL_ISSUER_SERIAL\s0\fR structure. -The application is responsible for freeing its own copy of these values after -use. \fBOSSL_ISSUER_SERIAL_get0_issuer()\fR, \fBOSSL_ISSUER_SERIAL_get0_issuerUID()\fR, -and \fBOSSL_ISSUER_SERIAL_get0_serial()\fR return pointers to these values in the object. -.PP -An \fB\s-1OSSL_OBJECT_DIGEST_INFO\s0\fR object holds a digest of data to identify the -attribute certificate holder. \fBOSSL_OBJECT_DIGEST_INFO_set1_digest()\fR sets the -digest information of the object. The type of \fIdigest\fR information is given -by \fIdigestedObjectType\fR and can be one of: -.IP "\s-1OSSL_OBJECT_DIGEST_INFO_PUBLIC_KEY\s0" 4 -.IX Item "OSSL_OBJECT_DIGEST_INFO_PUBLIC_KEY" -Hash of a public key -.IP "\s-1OSSL_OBJECT_DIGEST_INFO_PUBLIC_KEY_CERT\s0" 4 -.IX Item "OSSL_OBJECT_DIGEST_INFO_PUBLIC_KEY_CERT" -Hash of a public key certificate -.IP "\s-1OSSL_OBJECT_DIGEST_INFO_OTHER\s0" 4 -.IX Item "OSSL_OBJECT_DIGEST_INFO_OTHER" -Hash of another object. See \s-1NOTES\s0 below. -.PP -\&\fIdigestAlgorithm\fR indicates the algorithm used to compute \fIdigest\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All \fIset0\fR/\fIset1\fR routines return 1 for success and 0 for failure. -All \fIget0\fR functions return a pointer to the object's inner structure. These -pointers must not be freed after use. -.SH "NOTES" -.IX Header "NOTES" -Although the value of \fB\s-1OSSL_OBJECT_DIGEST_INFO_OTHER\s0\fR is defined in \s-1RFC 5755,\s0 -its use is prohibited for conformant attribute certificates. -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_holder_digest.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_holder_digest.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_holder_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_holder_entityName.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_holder_entityName.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_holder_entityName.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_info_sigalg.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_info_sigalg.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_info_sigalg.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_issuerName.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_issuerName.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_issuerName.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_issuerUID.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_issuerUID.3ossl deleted file mode 120000 index 1ea789ac..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_issuerUID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_uids.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_notAfter.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_notAfter.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_notAfter.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_notBefore.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_notBefore.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_notBefore.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_serialNumber.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_serialNumber.3ossl deleted file mode 120000 index b95323a0..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_serialNumber.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get0_signature.3ossl b/openssl-install/share/man/man3/X509_ACERT_get0_signature.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get_attr.3ossl b/openssl-install/share/man/man3/X509_ACERT_get_attr.3ossl deleted file mode 100644 index 6d6a53ad..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get_attr.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ACERT_GET_ATTR 3ossl" -.TH X509_ACERT_GET_ATTR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_ACERT_get_attr, -X509_ACERT_get_attr_by_NID, -X509_ACERT_get_attr_by_OBJ, -X509_ACERT_get_attr_count -\&\- Retrieve attributes from an X509_ACERT structure -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_ATTRIBUTE *X509_ACERT_get_attr(const X509_ACERT *x, int loc); -\& int X509_ACERT_get_attr_by_NID(const X509_ACERT *x, int nid, int lastpos); -\& int X509_ACERT_get_attr_by_OBJ(const X509_ACERT *x, const ASN1_OBJECT *obj, -\& int lastpos); -\& int X509_ACERT_get_attr_count(const X509_ACERT *x); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_ACERT_get0_attr()\fR retrieves the \fIloc\fRth \fBX509_ATTRIBUTE\fR from an -\&\fBX509_ACERT\fR \fIx\fR. \fBX509_ACERT_get_attr_count()\fR returns the total number -of attributes in the \fBX509_ACERT\fR. -.PP -\&\fBX509_ACERT_get_attr_by_NID()\fR and \fBX509_ACERT_get_attr_by_OBJ()\fR retrieve the next -attribute location matching \fInid\fR or \fIobj\fR after \fIlastpos\fR. \fIlastpos\fR -should initially be set to \-1. -If there are no more entries \-1 is returned. If \fInid\fR is invalid -(doesn't correspond to a valid \s-1OID\s0) then \-2 is returned. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_ACERT_get0_attr()\fR return a \fBX509_ATTRIBUTE\fR from an attribute -certificate, or \s-1NULL\s0 if the specified attribute is not found. -.PP -\&\fBX509_ACERT_get_attr_by_NID()\fR and \fBX509_ACERT_get_attr_by_OBJ()\fR return -the location of the next attribute requested or \-1 if not found. -\&\fBX509_ACERT_get_attr_by_NID()\fR can also return \-2 if the supplied \s-1NID\s0 is invalid. -.PP -\&\fBX509_ACERT_get_attr_count()\fR returns the number of attributes in the given -attribute certificate. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_ACERT_get0_attr()\fR, \fBX509_ACERT_get_attr_by_NID()\fR, \fBX509_ACERT_get_attr_by_OBJ()\fR and -\&\fBX509_ACERT_get_attr_count()\fR were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_ACERT_get_attr_by_NID.3ossl b/openssl-install/share/man/man3/X509_ACERT_get_attr_by_NID.3ossl deleted file mode 120000 index 6919fb63..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_ACERT_get_attr_by_OBJ.3ossl deleted file mode 120000 index 6919fb63..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get_attr_count.3ossl b/openssl-install/share/man/man3/X509_ACERT_get_attr_count.3ossl deleted file mode 120000 index 6919fb63..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get_attr_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get_ext_d2i.3ossl b/openssl-install/share/man/man3/X509_ACERT_get_ext_d2i.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get_ext_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get_signature_nid.3ossl b/openssl-install/share/man/man3/X509_ACERT_get_signature_nid.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get_signature_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_get_version.3ossl b/openssl-install/share/man/man3/X509_ACERT_get_version.3ossl deleted file mode 120000 index 6a7e2ebc..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_get_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_it.3ossl b/openssl-install/share/man/man3/X509_ACERT_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_new.3ossl b/openssl-install/share/man/man3/X509_ACERT_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_print.3ossl b/openssl-install/share/man/man3/X509_ACERT_print.3ossl deleted file mode 120000 index a78ffac7..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_print_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_print_ex.3ossl b/openssl-install/share/man/man3/X509_ACERT_print_ex.3ossl deleted file mode 100644 index 42afe0cc..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_print_ex.3ossl +++ /dev/null @@ -1,237 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ACERT_PRINT_EX 3ossl" -.TH X509_ACERT_PRINT_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_ACERT_print_ex, X509_ACERT_print -\&\- X509_ACERT printing routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_ACERT_print(BIO *bp, X509_ACERT *acert); -\& int X509_ACERT_print_ex(BIO *bp, X509_ACERT *acert, unsigned long nmflags, -\& unsigned long cflag); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_ACERT_print_ex()\fR prints a human readable version of the attribute -certificate \fIacert\fR to \s-1BIO\s0 \fIbp\fR. -.PP -The following data contained in the attribute certificate is printed -in order: -.IP "\(bu" 4 -The header text \*(L"Attribute certificate:\*(R" and \*(L"Data:\*(R" (X509_FLAG_NO_HEADER) -.Sp -= item * -.Sp -The attribute certificate version number as defined by the standard, -followed in parentheses by the value contained in the version field in -hexadecimal notation. If the version number is not a valid value according -to the specification, only the raw value is printed. -See \fBX509_ACERT_get_version\fR\|(3) for details. (X509_FLAG_NO_VERSION) -.Sp -= item * -.Sp -The serial number of the attribute certificate (X509_FLAG_NO_SERIAL) -.Sp -= item * -.Sp -The identity of the holder of the attribute certificate. If the -holder issuer name is present, the first \s-1GENERAL_NAME\s0 -returned by \fBX509_ACERT_get0_holder_entityName()\fR is printed. -If the holder baseCertificateId is present, the issuer name -(printed with X509_NAME_print_ex) and serial number of the -holder's certificate are displayed. (X509_FLAG_NO_SUBJECT) -.Sp -= item * -.Sp -The name of the attribute certificate issuer as returned from -\&\fBX509_ACERT_get0_issuerName()\fR and printed using \fBX509_NAME_print_ex()\fR. -(X509_FLAG_NO_ISSUER) -.Sp -= item * -.Sp -The period of validity between the times returned from \fBX509_ACERT_get0_notBefore()\fR -and \fBX509_ACERT_get0_notAfter()\fR. The values are printed as a generalized times -using \fBASN1_GENERALIZEDTIME_print()\fR. (X509_FLAG_NO_VALIDITY) -.Sp -= item * -.Sp -The list of attributes contained in the attribute certificate. -The attribute type is printed with \fBi2a_ASN1_OBJECT()\fR. String valued -attributes are printed as raw string data. \s-1ASN1\s0 encoded values are -printed with \fBASN1_parse_dump()\fR. (X509_FLAG_NO_ATTRIBUTES) -.Sp -= item * -.Sp -All X.509 extensions contained in the attribute certificate. (X509_FLAG_NO_EXTENSIONS) -.Sp -= item * -.Sp -The signature is printed with \fBX509_signature_print()\fR. (X509_FLAG_NO_SIGDUMP) -.Sp -If \fIcflag\fR is specifies as X509_FLAG_COMPAT, all of the above data in the -attribute certificate will be printed. -.Sp -The \fInmflags\fR flag determines the format used to output all fields printed using -\&\fBX509_NAME_print_ex()\fR. See \fBX509_NAME_print_ex\fR\|(3) for details. -.Sp -\&\fBX509_ACERT_print()\fR is equivalent to calling \fBX509_ACERT_print_ex()\fR with the -\&\fInmflags\fR and \fIcflags\fR set to \s-1XN_FLAG_COMPAT\s0 and X509_FLAG_COMPAT -respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_ACERT_print_ex()\fR \fBX509_ACERT_print()\fR return 1 for -success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_NAME_print_ex\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_ACERT_print()\fR and \fBX509_ACERT_print_ex()\fR were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_ACERT_set0_holder_baseCertId.3ossl b/openssl-install/share/man/man3/X509_ACERT_set0_holder_baseCertId.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set0_holder_baseCertId.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_set0_holder_digest.3ossl b/openssl-install/share/man/man3/X509_ACERT_set0_holder_digest.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set0_holder_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_set0_holder_entityName.3ossl b/openssl-install/share/man/man3/X509_ACERT_set0_holder_entityName.3ossl deleted file mode 120000 index 63b759d0..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set0_holder_entityName.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ACERT_get0_holder_baseCertId.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_set1_issuerName.3ossl b/openssl-install/share/man/man3/X509_ACERT_set1_issuerName.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set1_issuerName.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_set1_notAfter.3ossl b/openssl-install/share/man/man3/X509_ACERT_set1_notAfter.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set1_notAfter.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_set1_notBefore.3ossl b/openssl-install/share/man/man3/X509_ACERT_set1_notBefore.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set1_notBefore.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_set1_serialNumber.3ossl b/openssl-install/share/man/man3/X509_ACERT_set1_serialNumber.3ossl deleted file mode 120000 index b95323a0..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set1_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_serialNumber.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_set_version.3ossl b/openssl-install/share/man/man3/X509_ACERT_set_version.3ossl deleted file mode 120000 index 6a7e2ebc..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_set_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_sign.3ossl b/openssl-install/share/man/man3/X509_ACERT_sign.3ossl deleted file mode 120000 index 9080e9e2..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_sign_ctx.3ossl b/openssl-install/share/man/man3/X509_ACERT_sign_ctx.3ossl deleted file mode 120000 index 9080e9e2..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_sign_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ACERT_verify.3ossl b/openssl-install/share/man/man3/X509_ACERT_verify.3ossl deleted file mode 120000 index 81904cb5..00000000 --- a/openssl-install/share/man/man3/X509_ACERT_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_cmp.3ossl b/openssl-install/share/man/man3/X509_ALGOR_cmp.3ossl deleted file mode 120000 index 289ee33e..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ALGOR_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_copy.3ossl b/openssl-install/share/man/man3/X509_ALGOR_copy.3ossl deleted file mode 120000 index 289ee33e..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ALGOR_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_dup.3ossl b/openssl-install/share/man/man3/X509_ALGOR_dup.3ossl deleted file mode 100644 index 30be4aa7..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_dup.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ALGOR_DUP 3ossl" -.TH X509_ALGOR_DUP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_ALGOR_dup, -X509_ALGOR_set0, X509_ALGOR_get0, -X509_ALGOR_set_md, X509_ALGOR_cmp, -X509_ALGOR_copy \- AlgorithmIdentifier functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_ALGOR *X509_ALGOR_dup(X509_ALGOR *alg); -\& int X509_ALGOR_set0(X509_ALGOR *alg, ASN1_OBJECT *aobj, int ptype, void *pval); -\& void X509_ALGOR_get0(const ASN1_OBJECT **paobj, int *pptype, -\& const void **ppval, const X509_ALGOR *alg); -\& void X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md); -\& int X509_ALGOR_cmp(const X509_ALGOR *a, const X509_ALGOR *b); -\& int X509_ALGOR_copy(X509_ALGOR *dest, const X509_ALGOR *src); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_ALGOR_dup()\fR returns a copy of \fIalg\fR. -.PP -\&\fBX509_ALGOR_set0()\fR sets the algorithm \s-1OID\s0 of \fIalg\fR to \fIaobj\fR and the -associated parameter type to \fIptype\fR with value \fIpval\fR. If \fIptype\fR is -\&\fBV_ASN1_UNDEF\fR the parameter is omitted, otherwise \fIptype\fR and \fIpval\fR have -the same meaning as the \fItype\fR and \fIvalue\fR parameters to \fBASN1_TYPE_set()\fR. -All the supplied parameters are used internally so must \fB\s-1NOT\s0\fR be freed after -this call succeeded; -otherwise ownership remains with the caller and \fIalg\fR remains untouched. -.PP -\&\fBX509_ALGOR_get0()\fR is the inverse of \fBX509_ALGOR_set0()\fR: it returns the -algorithm \s-1OID\s0 in \fI*paobj\fR and the associated parameter in \fI*pptype\fR -and \fI*ppval\fR from the \fBAlgorithmIdentifier\fR \fIalg\fR. -.PP -\&\fBX509_ALGOR_set_md()\fR sets the \fBAlgorithmIdentifier\fR \fIalg\fR to appropriate -values for the message digest \fImd\fR. -.PP -\&\fBX509_ALGOR_cmp()\fR compares \fIa\fR and \fIb\fR and returns 0 if they have identical -encodings and nonzero otherwise. -.PP -\&\fBX509_ALGOR_copy()\fR copies the source values into the dest structs; making -a duplicate of each (and free any thing pointed to from within *dest). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_ALGOR_dup()\fR returns a valid \fBX509_ALGOR\fR structure or \s-1NULL\s0 if an error -occurred. -.PP -\&\fBX509_ALGOR_set0()\fR and \fBX509_ALGOR_copy()\fR return 1 on success or 0 on error. -.PP -\&\fBX509_ALGOR_get0()\fR and \fBX509_ALGOR_set_md()\fR return no values. -.PP -\&\fBX509_ALGOR_cmp()\fR returns 0 if the two parameters have identical encodings and -nonzero otherwise. -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_ALGOR_copy()\fR was added in 1.1.1e. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_ALGOR_free.3ossl b/openssl-install/share/man/man3/X509_ALGOR_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_get0.3ossl b/openssl-install/share/man/man3/X509_ALGOR_get0.3ossl deleted file mode 120000 index 289ee33e..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ALGOR_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_it.3ossl b/openssl-install/share/man/man3/X509_ALGOR_it.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_it.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_new.3ossl b/openssl-install/share/man/man3/X509_ALGOR_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_set0.3ossl b/openssl-install/share/man/man3/X509_ALGOR_set0.3ossl deleted file mode 120000 index 289ee33e..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_set0.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ALGOR_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ALGOR_set_md.3ossl b/openssl-install/share/man/man3/X509_ALGOR_set_md.3ossl deleted file mode 120000 index 289ee33e..00000000 --- a/openssl-install/share/man/man3/X509_ALGOR_set_md.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ALGOR_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE.3ossl deleted file mode 100644 index d35d703b..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE.3ossl +++ /dev/null @@ -1,399 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ATTRIBUTE 3ossl" -.TH X509_ATTRIBUTE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_ATTRIBUTE, X509at_get_attr, -X509at_get_attr_count, X509at_get_attr_by_NID, X509at_get_attr_by_OBJ, -X509at_delete_attr, -X509at_add1_attr, -X509at_add1_attr_by_OBJ, X509at_add1_attr_by_NID, X509at_add1_attr_by_txt, -X509at_get0_data_by_OBJ, -X509_ATTRIBUTE_create, X509_ATTRIBUTE_create_by_NID, -X509_ATTRIBUTE_create_by_OBJ, X509_ATTRIBUTE_create_by_txt, -X509_ATTRIBUTE_set1_object, X509_ATTRIBUTE_set1_data, -X509_ATTRIBUTE_count, -X509_ATTRIBUTE_get0_data, X509_ATTRIBUTE_get0_object, X509_ATTRIBUTE_get0_type -\&\- X509 attribute functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef struct x509_attributes_st X509_ATTRIBUTE; -\& -\& int X509at_get_attr_count(const STACK_OF(X509_ATTRIBUTE) *x); -\& int X509at_get_attr_by_NID(const STACK_OF(X509_ATTRIBUTE) *x, int nid, -\& int lastpos); -\& int X509at_get_attr_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *sk, -\& const ASN1_OBJECT *obj, int lastpos); -\& X509_ATTRIBUTE *X509at_get_attr(const STACK_OF(X509_ATTRIBUTE) *x, int loc); -\& X509_ATTRIBUTE *X509at_delete_attr(STACK_OF(X509_ATTRIBUTE) *x, int loc); -\& STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr(STACK_OF(X509_ATTRIBUTE) **x, -\& X509_ATTRIBUTE *attr); -\& STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_OBJ(STACK_OF(X509_ATTRIBUTE) -\& **x, const ASN1_OBJECT *obj, -\& int type, -\& const unsigned char *bytes, -\& int len); -\& STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_NID(STACK_OF(X509_ATTRIBUTE) -\& **x, int nid, int type, -\& const unsigned char *bytes, -\& int len); -\& STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_txt(STACK_OF(X509_ATTRIBUTE) -\& **x, const char *attrname, -\& int type, -\& const unsigned char *bytes, -\& int len); -\& void *X509at_get0_data_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *x, -\& const ASN1_OBJECT *obj, int lastpos, int type); -\& X509_ATTRIBUTE *X509_ATTRIBUTE_create(int nid, int atrtype, void *value); -\& X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_NID(X509_ATTRIBUTE **attr, int nid, -\& int atrtype, const void *data, -\& int len); -\& X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_OBJ(X509_ATTRIBUTE **attr, -\& const ASN1_OBJECT *obj, -\& int atrtype, const void *data, -\& int len); -\& X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_txt(X509_ATTRIBUTE **attr, -\& const char *atrname, int type, -\& const unsigned char *bytes, -\& int len); -\& int X509_ATTRIBUTE_set1_object(X509_ATTRIBUTE *attr, const ASN1_OBJECT *obj); -\& int X509_ATTRIBUTE_set1_data(X509_ATTRIBUTE *attr, int attrtype, -\& const void *data, int len); -\& void *X509_ATTRIBUTE_get0_data(X509_ATTRIBUTE *attr, int idx, int atrtype, -\& void *data); -\& int X509_ATTRIBUTE_count(const X509_ATTRIBUTE *attr); -\& ASN1_OBJECT *X509_ATTRIBUTE_get0_object(X509_ATTRIBUTE *attr); -\& ASN1_TYPE *X509_ATTRIBUTE_get0_type(X509_ATTRIBUTE *attr, int idx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_ATTRIBUTE\fR objects are used by many standards including X509, X509_REQ, -\&\s-1PKCS12, PKCS8, PKCS7\s0 and \s-1CMS.\s0 -.PP -The \fBX509_ATTRIBUTE\fR object is used to represent the \s-1ASN.1\s0 Attribute as defined -in \s-1RFC 5280,\s0 i.e. -.PP -.Vb 3 -\& Attribute ::= SEQUENCE { -\& type AttributeType, -\& values SET OF AttributeValue } -\& -\& AttributeType ::= OBJECT IDENTIFIER -\& AttributeValue ::= ANY \-\- DEFINED BY AttributeType -.Ve -.PP -For example \s-1CMS\s0 defines the signing-time attribute as: -.PP -.Vb 2 -\& id\-signingTime OBJECT IDENTIFIER ::= { iso(1) member\-body(2) -\& us(840) rsadsi(113549) pkcs(1) pkcs9(9) 5 } -\& -\& SigningTime ::= Time -\& -\& Time ::= CHOICE { -\& utcTime UTCTime, -\& generalizedTime GeneralizedTime } -.Ve -.PP -In OpenSSL \fBAttributeType\fR maps to an \fB\s-1ASN1_OBJECT\s0\fR object -and \fBAttributeValue\fR maps to a list of \fB\s-1ASN1_TYPE\s0\fR objects. -.PP -The following functions are used for \fBX509_ATTRIBUTE\fR objects. -.PP -\&\fBX509at_get_attr_by_OBJ()\fR finds the location of the first matching object \fIobj\fR -in a list of attributes \fIsk\fR. The search starts at the position after \fIlastpos\fR. -If the returned value is positive then it can be used on the next call to -\&\fBX509at_get_attr_by_OBJ()\fR as the value of \fIlastpos\fR in order to iterate through -the remaining attributes. \fIlastpos\fR can be set to any negative value on the -first call, in order to start searching from the start of the list. -.PP -\&\fBX509at_get_attr_by_NID()\fR is similar to \fBX509at_get_attr_by_OBJ()\fR except that it -passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBX509at_get_attr()\fR returns the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in the -list of attributes \fIx\fR. \fIloc\fR should be in the range from 0 to -\&\fBX509at_get_attr_count()\fR \- 1. -.PP -\&\fBX509at_delete_attr()\fR removes the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in -the list of attributes \fIx\fR. -.PP -\&\fBX509at_add1_attr()\fR pushes a copy of the passed in \fBX509_ATTRIBUTE\fR object -to the list \fIx\fR. -Both \fIx\fR and \fIattr\fR must be non \s-1NULL\s0 or an error will occur. -If \fI*x\fR is \s-1NULL\s0 then a new list is created, otherwise it uses the -passed in list. An error will occur if an existing attribute (with the same -attribute type) already exists in the attribute list. -.PP -\&\fBX509at_add1_attr_by_OBJ()\fR creates a new \fBX509_ATTRIBUTE\fR using -\&\fBX509_ATTRIBUTE_set1_object()\fR and \fBX509_ATTRIBUTE_set1_data()\fR to assign a new -\&\fIobj\fR with type \fItype\fR and data \fIbytes\fR of length \fIlen\fR and then pushes it -to the attribute list \fIx\fR. Both \fIx\fR and \fIattr\fR must be non \s-1NULL\s0 or an error -will occur. If \fI*x\fR is \s-1NULL\s0 then a new attribute list is created. If \fIobj\fR -already exists in the attribute list then an error occurs. -.PP -\&\fBX509at_add1_attr_by_NID()\fR is similar to \fBX509at_add1_attr_by_OBJ()\fR except that it -passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBX509at_add1_attr_by_txt()\fR is similar to \fBX509at_add1_attr_by_OBJ()\fR except that it -passes a name \fIattrname\fR associated with the object. -See for a list of SN_* names. -.PP -\&\fBX509_ATTRIBUTE_set1_object()\fR assigns a \fB\s-1ASN1_OBJECT\s0\fR \fIobj\fR -to the attribute \fIattr\fR. If \fIattr\fR contained an existing \fB\s-1ASN1_OBJECT\s0\fR then -it is freed. An error occurs if either \fIattr\fR or \fIobj\fR are \s-1NULL,\s0 or if -the passed in \fIobj\fR cannot be duplicated. -.PP -\&\fBX509_ATTRIBUTE_set1_data()\fR pushes a new \fB\s-1ASN1_TYPE\s0\fR object onto the \fIattr\fR -attributes list. The new object is assigned a copy of the data in \fIdata\fR of -size \fIlen\fR. -If \fIattrtype\fR has flag \fI\s-1MBSTRING_FLAG\s0\fR set then a table lookup using the -\&\fIattr\fR attributes \s-1NID\s0 is used to set an \fB\s-1ASN1_STRING\s0\fR using -\&\fBASN1_STRING_set_by_NID()\fR, and the passed in \fIdata\fR must be in the format -required for that object type or an error will occur. -If \fIlen\fR is not \-1 then internally \fBASN1_STRING_type_new()\fR is -used with the passed in \fIattrtype\fR. -If \fIattrtype\fR is 0 the call does nothing except return 1. -.PP -\&\fBX509_ATTRIBUTE_create()\fR creates a new \fBX509_ATTRIBUTE\fR using the \fInid\fR -to set the \fB\s-1ASN1_OBJECT\s0\fR \s-1OID\s0 and the \fIatrtype\fR and \fIvalue\fR to set the -\&\fB\s-1ASN1_TYPE\s0\fR. -.PP -\&\fBX509_ATTRIBUTE_create_by_OBJ()\fR uses \fBX509_ATTRIBUTE_set1_object()\fR and -\&\fBX509_ATTRIBUTE_set1_data()\fR to assign a new \fIobj\fR with type \fIatrtype\fR and -data \fIdata\fR of length \fIlen\fR. If the passed in attribute \fIattr\fR \s-1OR\s0 \fI*attr\fR is -\&\s-1NULL\s0 then a new \fBX509_ATTRIBUTE\fR will be returned, otherwise the passed in -\&\fBX509_ATTRIBUTE\fR is used. Note that the \s-1ASN1_OBJECT\s0 \fIobj\fR is pushed onto the -attributes existing list of objects, which could be an issue if the attributes -<\s-1ASN1_OBJECT\s0> was different. -.PP -\&\fBX509_ATTRIBUTE_create_by_NID()\fR is similar to \fBX509_ATTRIBUTE_create_by_OBJ()\fR -except that it passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the -object. See for a list of NID_*. -.PP -\&\fBX509_ATTRIBUTE_create_by_txt()\fR is similar to \fBX509_ATTRIBUTE_create_by_OBJ()\fR -except that it passes a name \fIatrname\fR associated with the -object. See for a list of SN_* names. -.PP -\&\fBX509_ATTRIBUTE_count()\fR returns the number of \fB\s-1ASN1_TYPE\s0\fR objects in an -attribute \fIattr\fR. -.PP -\&\fBX509_ATTRIBUTE_get0_type()\fR returns the \fB\s-1ASN1_TYPE\s0\fR object at index \fIidx\fR in -the attribute list \fIattr\fR. \fIidx\fR should be in the -range of 0 to \fBX509_ATTRIBUTE_count()\fR \- 1 or an error will occur. -.PP -\&\fBX509_ATTRIBUTE_get0_data()\fR returns the data of an \fB\s-1ASN1_TYPE\s0\fR object at -index \fIidx\fR in the attribute \fIattr\fR. \fIdata\fR is unused and can be set to \s-1NULL.\s0 -An error will occur if the attribute type \fIatrtype\fR does not match the type of -the \fB\s-1ASN1_TYPE\s0\fR object at index \fIidx\fR \s-1OR\s0 if \fIatrtype\fR is either -\&\fBV_ASN1_BOOLEAN\fR or \fBV_ASN1_NULL\fR \s-1OR\s0 if the \fIidx\fR is not in the -range 0 to \fBX509_ATTRIBUTE_count()\fR \- 1. -.PP -\&\fBX509at_get0_data_by_OBJ()\fR finds the first attribute in an attribute list \fIx\fR -that matches the \fIobj\fR starting at index \fIlastpos\fR and returns the data -retrieved from the found attributes first \fB\s-1ASN1_TYPE\s0\fR object. An error will -occur if the attribute type \fItype\fR does not match the type of the \fB\s-1ASN1_TYPE\s0\fR -object \s-1OR\s0 if \fItype\fR is either \fBV_ASN1_BOOLEAN\fR or \fBV_ASN1_NULL\fR \s-1OR\s0 the -attribute is not found. -If \fIlastpos\fR is less than \-1 then an error will occur if there are multiple -objects in the list \fIx\fR that match \fIobj\fR. -If \fIlastpos\fR is less than \-2 then an error will occur if there is more than -one \fB\s-1ASN1_TYPE\s0\fR object in the found attribute. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509at_get_attr_count()\fR returns the number of attributes in the list \fIx\fR or \-1 -if \fIx\fR is \s-1NULL.\s0 -.PP -\&\fBX509at_get_attr_by_OBJ()\fR returns \-1 if either the list is empty \s-1OR\s0 the object -is not found, otherwise it returns the location of the object in the list. -.PP -\&\fBX509at_get_attr_by_NID()\fR is similar to \fBX509at_get_attr_by_OBJ()\fR, except that -it returns \-2 if the \fInid\fR is not known by OpenSSL. -.PP -\&\fBX509at_get_attr()\fR returns either an \fBX509_ATTRIBUTE\fR or \s-1NULL\s0 if there is a error. -.PP -\&\fBX509at_delete_attr()\fR returns either the removed \fBX509_ATTRIBUTE\fR or \s-1NULL\s0 if -there is a error. -.PP -\&\fBX509_ATTRIBUTE_count()\fR returns \-1 on error, otherwise it returns the number -of \fB\s-1ASN1_TYPE\s0\fR elements. -.PP -\&\fBX509_ATTRIBUTE_get0_type()\fR returns \s-1NULL\s0 on error, otherwise it returns a -\&\fB\s-1ASN1_TYPE\s0\fR object. -.PP -\&\fBX509_ATTRIBUTE_get0_data()\fR returns \s-1NULL\s0 if an error occurs, -otherwise it returns the data associated with an \fB\s-1ASN1_TYPE\s0\fR object. -.PP -\&\fBX509_ATTRIBUTE_set1_object()\fR and \fBX509_ATTRIBUTE_set1_data()\fR returns 1 on -success, or 0 otherwise. -.PP -\&\fBX509_ATTRIBUTE_create()\fR, \fBX509_ATTRIBUTE_create_by_OBJ()\fR, -\&\fBX509_ATTRIBUTE_create_by_NID()\fR and \fBX509_ATTRIBUTE_create_by_txt()\fR return either -a \fBX509_ATTRIBUTE\fR on success, or \s-1NULL\s0 if there is a error. -.PP -\&\fBX509at_add1_attr()\fR, \fBX509at_add1_attr_by_OBJ()\fR, \fBX509at_add1_attr_by_NID()\fR and -\&\fBX509at_add1_attr_by_txt()\fR return \s-1NULL\s0 on error, otherwise they return a list -of \fBX509_ATTRIBUTE\fR. -.PP -\&\fBX509at_get0_data_by_OBJ()\fR returns the data retrieved from the found attributes -first \fB\s-1ASN1_TYPE\s0\fR object, or \s-1NULL\s0 if an error occurs. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBASN1_TYPE_get\fR\|(3), -\&\fBASN1_INTEGER_get\fR\|(3), -\&\fBASN1_ENUMERATED_get\fR\|(3), -\&\fBASN1_STRING_get0_data\fR\|(3), -\&\fBASN1_STRING_length\fR\|(3), -\&\fBASN1_STRING_type\fR\|(3), -\&\fBX509_REQ_get_attr\fR\|(3), -\&\fBEVP_PKEY_get_attr\fR\|(3), -\&\fBCMS_signed_get_attr\fR\|(3), -\&\fBPKCS8_pkey_get0_attrs\fR\|(3), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_count.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_count.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_create.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_create.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_create.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_NID.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_NID.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_OBJ.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_txt.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_txt.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_create_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_dup.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_free.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_data.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_data.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_object.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_object.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_object.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_type.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_type.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_get0_type.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_new.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_set1_data.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_set1_data.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_set1_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_ATTRIBUTE_set1_object.3ossl b/openssl-install/share/man/man3/X509_ATTRIBUTE_set1_object.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509_ATTRIBUTE_set1_object.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CERT_AUX_free.3ossl b/openssl-install/share/man/man3/X509_CERT_AUX_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CERT_AUX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CERT_AUX_new.3ossl b/openssl-install/share/man/man3/X509_CERT_AUX_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CERT_AUX_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CINF_free.3ossl b/openssl-install/share/man/man3/X509_CINF_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CINF_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CINF_new.3ossl b/openssl-install/share/man/man3/X509_CINF_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CINF_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_INFO_free.3ossl b/openssl-install/share/man/man3/X509_CRL_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CRL_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_INFO_new.3ossl b/openssl-install/share/man/man3/X509_CRL_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CRL_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_add0_revoked.3ossl b/openssl-install/share/man/man3/X509_CRL_add0_revoked.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_CRL_add0_revoked.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_add1_ext_i2d.3ossl b/openssl-install/share/man/man3/X509_CRL_add1_ext_i2d.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_CRL_add1_ext_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_add_ext.3ossl b/openssl-install/share/man/man3/X509_CRL_add_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_add_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_cmp.3ossl b/openssl-install/share/man/man3/X509_CRL_cmp.3ossl deleted file mode 120000 index e12f4f89..00000000 --- a/openssl-install/share/man/man3/X509_CRL_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_delete_ext.3ossl b/openssl-install/share/man/man3/X509_CRL_delete_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_delete_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_digest.3ossl b/openssl-install/share/man/man3/X509_CRL_digest.3ossl deleted file mode 120000 index c2b39912..00000000 --- a/openssl-install/share/man/man3/X509_CRL_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_digest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_dup.3ossl b/openssl-install/share/man/man3/X509_CRL_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CRL_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_free.3ossl b/openssl-install/share/man/man3/X509_CRL_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CRL_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get0_by_cert.3ossl b/openssl-install/share/man/man3/X509_CRL_get0_by_cert.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get0_by_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get0_by_serial.3ossl b/openssl-install/share/man/man3/X509_CRL_get0_by_serial.3ossl deleted file mode 100644 index d03ebdab..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get0_by_serial.3ossl +++ /dev/null @@ -1,246 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CRL_GET0_BY_SERIAL 3ossl" -.TH X509_CRL_GET0_BY_SERIAL 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_CRL_get0_by_serial, X509_CRL_get0_by_cert, X509_CRL_get_REVOKED, -X509_REVOKED_get0_serialNumber, X509_REVOKED_get0_revocationDate, -X509_REVOKED_set_serialNumber, X509_REVOKED_set_revocationDate, -X509_CRL_add0_revoked, X509_CRL_sort \- CRL revoked entry utility -functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_CRL_get0_by_serial(X509_CRL *crl, -\& X509_REVOKED **ret, const ASN1_INTEGER *serial); -\& int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, X509 *x); -\& -\& STACK_OF(X509_REVOKED) *X509_CRL_get_REVOKED(X509_CRL *crl); -\& -\& const ASN1_INTEGER *X509_REVOKED_get0_serialNumber(const X509_REVOKED *r); -\& const ASN1_TIME *X509_REVOKED_get0_revocationDate(const X509_REVOKED *r); -\& -\& int X509_REVOKED_set_serialNumber(X509_REVOKED *r, ASN1_INTEGER *serial); -\& int X509_REVOKED_set_revocationDate(X509_REVOKED *r, ASN1_TIME *tm); -\& -\& int X509_CRL_add0_revoked(X509_CRL *crl, X509_REVOKED *rev); -\& -\& int X509_CRL_sort(X509_CRL *crl); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_CRL_get0_by_serial()\fR attempts to find a revoked entry in \fIcrl\fR for -serial number \fIserial\fR. If it is successful, it sets \fI*ret\fR to the internal -pointer of the matching entry. As a result, \fI*ret\fR \fB\s-1MUST NOT\s0\fR be freed -after the call. -.PP -\&\fBX509_CRL_get0_by_cert()\fR is similar to \fBX509_get0_by_serial()\fR except it -looks for a revoked entry using the serial number of certificate \fIx\fR. -.PP -\&\fBX509_CRL_get_REVOKED()\fR returns an internal pointer to a \s-1STACK\s0 of all -revoked entries for \fIcrl\fR. -.PP -\&\fBX509_REVOKED_get0_serialNumber()\fR returns an internal pointer to the -serial number of \fIr\fR. -.PP -\&\fBX509_REVOKED_get0_revocationDate()\fR returns an internal pointer to the -revocation date of \fIr\fR. -.PP -\&\fBX509_REVOKED_set_serialNumber()\fR sets the serial number of \fIr\fR to \fIserial\fR. -The supplied \fIserial\fR pointer is not used internally so it should be -freed after use. -.PP -\&\fBX509_REVOKED_set_revocationDate()\fR sets the revocation date of \fIr\fR to -\&\fItm\fR. The supplied \fItm\fR pointer is not used internally so it should be -freed after use. -.PP -\&\fBX509_CRL_add0_revoked()\fR appends revoked entry \fIrev\fR to \s-1CRL\s0 \fIcrl\fR. The -pointer \fIrev\fR is used internally so it \fB\s-1MUST NOT\s0\fR be freed after the call: -it is freed when the parent \s-1CRL\s0 is freed. -.PP -\&\fBX509_CRL_sort()\fR sorts the revoked entries of \fIcrl\fR into ascending serial -number order. -.SH "NOTES" -.IX Header "NOTES" -Applications can determine the number of revoked entries returned by -\&\fBX509_CRL_get_REVOKED()\fR using \fBsk_X509_REVOKED_num()\fR and examine each one -in turn using \fBsk_X509_REVOKED_value()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_CRL_get0_by_serial()\fR and \fBX509_CRL_get0_by_cert()\fR return 0 for failure, -1 on success except if the revoked entry has the reason \f(CW\*(C`removeFromCRL\*(C'\fR (8), -in which case 2 is returned. -.PP -\&\fBX509_CRL_get_REVOKED()\fR returns a \s-1STACK\s0 of revoked entries. -.PP -\&\fBX509_REVOKED_get0_serialNumber()\fR returns an \fB\s-1ASN1_INTEGER\s0\fR structure. -.PP -\&\fBX509_REVOKED_get0_revocationDate()\fR returns an \fB\s-1ASN1_TIME\s0\fR structure. -.PP -\&\fBX509_REVOKED_set_serialNumber()\fR, \fBX509_REVOKED_set_revocationDate()\fR, -\&\fBX509_CRL_add0_revoked()\fR and \fBX509_CRL_sort()\fR return 1 for success and 0 for -failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_CRL_get0_extensions.3ossl b/openssl-install/share/man/man3/X509_CRL_get0_extensions.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get0_lastUpdate.3ossl b/openssl-install/share/man/man3/X509_CRL_get0_lastUpdate.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get0_lastUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get0_nextUpdate.3ossl b/openssl-install/share/man/man3/X509_CRL_get0_nextUpdate.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get0_nextUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get0_signature.3ossl b/openssl-install/share/man/man3/X509_CRL_get0_signature.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_REVOKED.3ossl b/openssl-install/share/man/man3/X509_CRL_get_REVOKED.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_REVOKED.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_ext.3ossl b/openssl-install/share/man/man3/X509_CRL_get_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_ext_by_NID.3ossl b/openssl-install/share/man/man3/X509_CRL_get_ext_by_NID.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_ext_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_ext_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_CRL_get_ext_by_OBJ.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_ext_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_ext_by_critical.3ossl b/openssl-install/share/man/man3/X509_CRL_get_ext_by_critical.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_ext_by_critical.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_ext_count.3ossl b/openssl-install/share/man/man3/X509_CRL_get_ext_count.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_ext_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_ext_d2i.3ossl b/openssl-install/share/man/man3/X509_CRL_get_ext_d2i.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_ext_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_issuer.3ossl b/openssl-install/share/man/man3/X509_CRL_get_issuer.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_signature_nid.3ossl b/openssl-install/share/man/man3/X509_CRL_get_signature_nid.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_signature_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_get_version.3ossl b/openssl-install/share/man/man3/X509_CRL_get_version.3ossl deleted file mode 120000 index 6a7e2ebc..00000000 --- a/openssl-install/share/man/man3/X509_CRL_get_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_http_nbio.3ossl b/openssl-install/share/man/man3/X509_CRL_http_nbio.3ossl deleted file mode 120000 index f41a0530..00000000 --- a/openssl-install/share/man/man3/X509_CRL_http_nbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_load_http.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_load_http.3ossl b/openssl-install/share/man/man3/X509_CRL_load_http.3ossl deleted file mode 120000 index f41a0530..00000000 --- a/openssl-install/share/man/man3/X509_CRL_load_http.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_load_http.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_match.3ossl b/openssl-install/share/man/man3/X509_CRL_match.3ossl deleted file mode 120000 index e12f4f89..00000000 --- a/openssl-install/share/man/man3/X509_CRL_match.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_new.3ossl b/openssl-install/share/man/man3/X509_CRL_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CRL_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_new_ex.3ossl b/openssl-install/share/man/man3/X509_CRL_new_ex.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_CRL_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_set1_lastUpdate.3ossl b/openssl-install/share/man/man3/X509_CRL_set1_lastUpdate.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_CRL_set1_lastUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_set1_nextUpdate.3ossl b/openssl-install/share/man/man3/X509_CRL_set1_nextUpdate.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_CRL_set1_nextUpdate.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_set_issuer_name.3ossl b/openssl-install/share/man/man3/X509_CRL_set_issuer_name.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_CRL_set_issuer_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_set_version.3ossl b/openssl-install/share/man/man3/X509_CRL_set_version.3ossl deleted file mode 120000 index 6a7e2ebc..00000000 --- a/openssl-install/share/man/man3/X509_CRL_set_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_sign.3ossl b/openssl-install/share/man/man3/X509_CRL_sign.3ossl deleted file mode 120000 index 9080e9e2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_sign_ctx.3ossl b/openssl-install/share/man/man3/X509_CRL_sign_ctx.3ossl deleted file mode 120000 index 9080e9e2..00000000 --- a/openssl-install/share/man/man3/X509_CRL_sign_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_sort.3ossl b/openssl-install/share/man/man3/X509_CRL_sort.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_CRL_sort.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_CRL_verify.3ossl b/openssl-install/share/man/man3/X509_CRL_verify.3ossl deleted file mode 120000 index 81904cb5..00000000 --- a/openssl-install/share/man/man3/X509_CRL_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_create_by_NID.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_create_by_NID.3ossl deleted file mode 120000 index 5d26d062..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_create_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_EXTENSION_set_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_create_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_create_by_OBJ.3ossl deleted file mode 120000 index 5d26d062..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_create_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_EXTENSION_set_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_dup.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_free.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_get_critical.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_get_critical.3ossl deleted file mode 120000 index 5d26d062..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_get_critical.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_EXTENSION_set_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_get_data.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_get_data.3ossl deleted file mode 120000 index 5d26d062..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_get_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_EXTENSION_set_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_get_object.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_get_object.3ossl deleted file mode 120000 index 5d26d062..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_get_object.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_EXTENSION_set_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_new.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_set_critical.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_set_critical.3ossl deleted file mode 120000 index 5d26d062..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_set_critical.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_EXTENSION_set_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_set_data.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_set_data.3ossl deleted file mode 120000 index 5d26d062..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_set_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_EXTENSION_set_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_EXTENSION_set_object.3ossl b/openssl-install/share/man/man3/X509_EXTENSION_set_object.3ossl deleted file mode 100644 index 346a8bf2..00000000 --- a/openssl-install/share/man/man3/X509_EXTENSION_set_object.3ossl +++ /dev/null @@ -1,227 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_EXTENSION_SET_OBJECT 3ossl" -.TH X509_EXTENSION_SET_OBJECT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_EXTENSION_set_object, X509_EXTENSION_set_critical, -X509_EXTENSION_set_data, X509_EXTENSION_create_by_NID, -X509_EXTENSION_create_by_OBJ, X509_EXTENSION_get_object, -X509_EXTENSION_get_critical, X509_EXTENSION_get_data \- extension utility -functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 3 -\& int X509_EXTENSION_set_object(X509_EXTENSION *ex, const ASN1_OBJECT *obj); -\& int X509_EXTENSION_set_critical(X509_EXTENSION *ex, int crit); -\& int X509_EXTENSION_set_data(X509_EXTENSION *ex, ASN1_OCTET_STRING *data); -\& -\& X509_EXTENSION *X509_EXTENSION_create_by_NID(X509_EXTENSION **ex, -\& int nid, int crit, -\& ASN1_OCTET_STRING *data); -\& X509_EXTENSION *X509_EXTENSION_create_by_OBJ(X509_EXTENSION **ex, -\& const ASN1_OBJECT *obj, int crit, -\& ASN1_OCTET_STRING *data); -\& -\& ASN1_OBJECT *X509_EXTENSION_get_object(X509_EXTENSION *ex); -\& int X509_EXTENSION_get_critical(const X509_EXTENSION *ex); -\& ASN1_OCTET_STRING *X509_EXTENSION_get_data(X509_EXTENSION *ne); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_EXTENSION_set_object()\fR sets the extension type of \fBex\fR to \fBobj\fR. The -\&\fBobj\fR pointer is duplicated internally so \fBobj\fR should be freed up after use. -.PP -\&\fBX509_EXTENSION_set_critical()\fR sets the criticality of \fBex\fR to \fBcrit\fR. If -\&\fBcrit\fR is zero the extension in non-critical otherwise it is critical. -.PP -\&\fBX509_EXTENSION_set_data()\fR sets the data in extension \fBex\fR to \fBdata\fR. The -\&\fBdata\fR pointer is duplicated internally. -.PP -\&\fBX509_EXTENSION_create_by_NID()\fR creates an extension of type \fBnid\fR, -criticality \fBcrit\fR using data \fBdata\fR. The created extension is returned and -written to \fB*ex\fR reusing or allocating a new extension if necessary so \fB*ex\fR -should either be \fB\s-1NULL\s0\fR or a valid \fBX509_EXTENSION\fR structure it must -\&\fBnot\fR be an uninitialised pointer. -.PP -\&\fBX509_EXTENSION_create_by_OBJ()\fR is identical to \fBX509_EXTENSION_create_by_NID()\fR -except it creates and extension using \fBobj\fR instead of a \s-1NID.\s0 -.PP -\&\fBX509_EXTENSION_get_object()\fR returns the extension type of \fBex\fR as an -\&\fB\s-1ASN1_OBJECT\s0\fR pointer. The returned pointer is an internal value which must -not be freed up. -.PP -\&\fBX509_EXTENSION_get_critical()\fR returns the criticality of extension \fBex\fR it -returns \fB1\fR for critical and \fB0\fR for non-critical. -.PP -\&\fBX509_EXTENSION_get_data()\fR returns the data of extension \fBex\fR. The returned -pointer is an internal value which must not be freed up. -.SH "NOTES" -.IX Header "NOTES" -These functions manipulate the contents of an extension directly. Most -applications will want to parse or encode and add an extension: they should -use the extension encode and decode functions instead such as -\&\fBX509_add1_ext_i2d()\fR and \fBX509_get_ext_d2i()\fR. -.PP -The \fBdata\fR associated with an extension is the extension encoding in an -\&\fB\s-1ASN1_OCTET_STRING\s0\fR structure. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_EXTENSION_set_object()\fR \fBX509_EXTENSION_set_critical()\fR and -\&\fBX509_EXTENSION_set_data()\fR return \fB1\fR for success and \fB0\fR for failure. -.PP -\&\fBX509_EXTENSION_create_by_NID()\fR and \fBX509_EXTENSION_create_by_OBJ()\fR return -an \fBX509_EXTENSION\fR pointer or \fB\s-1NULL\s0\fR if an error occurs. -.PP -\&\fBX509_EXTENSION_get_object()\fR returns an \fB\s-1ASN1_OBJECT\s0\fR pointer. -.PP -\&\fBX509_EXTENSION_get_critical()\fR returns \fB0\fR for non-critical and \fB1\fR for -critical. -.PP -\&\fBX509_EXTENSION_get_data()\fR returns an \fB\s-1ASN1_OCTET_STRING\s0\fR pointer. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509V3_get_d2i\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_LOOKUP.3ossl b/openssl-install/share/man/man3/X509_LOOKUP.3ossl deleted file mode 100644 index 35c5ca64..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP.3ossl +++ /dev/null @@ -1,371 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_LOOKUP 3ossl" -.TH X509_LOOKUP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_LOOKUP, X509_LOOKUP_TYPE, -X509_LOOKUP_new, X509_LOOKUP_free, X509_LOOKUP_init, -X509_LOOKUP_shutdown, -X509_LOOKUP_set_method_data, X509_LOOKUP_get_method_data, -X509_LOOKUP_ctrl_ex, X509_LOOKUP_ctrl, -X509_LOOKUP_load_file_ex, X509_LOOKUP_load_file, -X509_LOOKUP_add_dir, -X509_LOOKUP_add_store_ex, X509_LOOKUP_add_store, -X509_LOOKUP_load_store_ex, X509_LOOKUP_load_store, -X509_LOOKUP_get_store, -X509_LOOKUP_by_subject_ex, X509_LOOKUP_by_subject, -X509_LOOKUP_by_issuer_serial, X509_LOOKUP_by_fingerprint, -X509_LOOKUP_by_alias -\&\- OpenSSL certificate lookup mechanisms -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef x509_lookup_st X509_LOOKUP; -\& -\& typedef enum X509_LOOKUP_TYPE; -\& -\& X509_LOOKUP *X509_LOOKUP_new(X509_LOOKUP_METHOD *method); -\& int X509_LOOKUP_init(X509_LOOKUP *ctx); -\& int X509_LOOKUP_shutdown(X509_LOOKUP *ctx); -\& void X509_LOOKUP_free(X509_LOOKUP *ctx); -\& -\& int X509_LOOKUP_set_method_data(X509_LOOKUP *ctx, void *data); -\& void *X509_LOOKUP_get_method_data(const X509_LOOKUP *ctx); -\& -\& int X509_LOOKUP_ctrl_ex(X509_LOOKUP *ctx, int cmd, const char *argc, long argl, -\& char **ret, OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_LOOKUP_ctrl(X509_LOOKUP *ctx, int cmd, const char *argc, -\& long argl, char **ret); -\& int X509_LOOKUP_load_file_ex(X509_LOOKUP *ctx, char *name, long type, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_LOOKUP_load_file(X509_LOOKUP *ctx, char *name, long type); -\& int X509_LOOKUP_load_file_ex(X509_LOOKUP *ctx, char *name, long type, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_LOOKUP_add_dir(X509_LOOKUP *ctx, char *name, long type); -\& int X509_LOOKUP_add_store_ex(X509_LOOKUP *ctx, char *uri, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int X509_LOOKUP_add_store(X509_LOOKUP *ctx, char *uri); -\& int X509_LOOKUP_load_store_ex(X509_LOOKUP *ctx, char *uri, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int X509_LOOKUP_load_store(X509_LOOKUP *ctx, char *uri); -\& -\& X509_STORE *X509_LOOKUP_get_store(const X509_LOOKUP *ctx); -\& -\& int X509_LOOKUP_by_subject_ex(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type, -\& const X509_NAME *name, X509_OBJECT *ret, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_LOOKUP_by_subject(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type, -\& const X509_NAME *name, X509_OBJECT *ret); -\& int X509_LOOKUP_by_issuer_serial(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type, -\& const X509_NAME *name, -\& const ASN1_INTEGER *serial, X509_OBJECT *ret); -\& int X509_LOOKUP_by_fingerprint(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type, -\& const unsigned char *bytes, int len, -\& X509_OBJECT *ret); -\& int X509_LOOKUP_by_alias(X509_LOOKUP *ctx, X509_LOOKUP_TYPE type, -\& const char *str, int len, X509_OBJECT *ret); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX509_LOOKUP\fR structure holds the information needed to look up -certificates and CRLs according to an associated \fBX509_LOOKUP_METHOD\fR\|(3). -Multiple \fBX509_LOOKUP\fR instances can be added to an \fBX509_STORE\fR\|(3) -to enable lookup in that store. -.PP -\&\fBX509_LOOKUP_new()\fR creates a new \fBX509_LOOKUP\fR using the given lookup -\&\fImethod\fR. -It can also be created by calling \fBX509_STORE_add_lookup\fR\|(3), which -will associate a \fBX509_STORE\fR with the lookup mechanism. -.PP -\&\fBX509_LOOKUP_init()\fR initializes the internal state and resources as -needed by the given \fBX509_LOOKUP\fR to do its work. -.PP -\&\fBX509_LOOKUP_shutdown()\fR tears down the internal state and resources of -the given \fBX509_LOOKUP\fR. -.PP -\&\fBX509_LOOKUP_free()\fR destructs the given \fBX509_LOOKUP\fR. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBX509_LOOKUP_set_method_data()\fR and \fBX509_LOOKUP_get_method_data()\fR -associates and retrieves a pointer to application data to and from the -given \fBX509_LOOKUP\fR, respectively. -.PP -\&\fBX509_LOOKUP_ctrl_ex()\fR is used to set or get additional data to or from -a \fBX509_LOOKUP\fR structure using any control function in the -associated \fBX509_LOOKUP_METHOD\fR\|(3). -The arguments of the control command are passed via \fIargc\fR and \fIargl\fR, -its return value via \fI*ret\fR. The library context \fIlibctx\fR and property -query \fIpropq\fR are used when fetching algorithms from providers. -The meaning of the arguments depends on the \fIcmd\fR number of the -control command. In general, this function is not called directly, but -wrapped by a macro call, see below. -The control \fIcmd\fRs known to OpenSSL are discussed in more depth -in \*(L"Control Commands\*(R". -.PP -\&\fBX509_LOOKUP_ctrl()\fR is similar to \fBX509_LOOKUP_ctrl_ex()\fR but -uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBX509_LOOKUP_load_file_ex()\fR passes a filename to be loaded immediately -into the associated \fBX509_STORE\fR. The library context \fIlibctx\fR and property -query \fIpropq\fR are used when fetching algorithms from providers. -\&\fItype\fR indicates what type of object is expected. -This can only be used with a lookup using the implementation -\&\fBX509_LOOKUP_file\fR\|(3). -.PP -\&\fBX509_LOOKUP_load_file()\fR is similar to \fBX509_LOOKUP_load_file_ex()\fR but -uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBX509_LOOKUP_add_dir()\fR passes a directory specification from which -certificates and CRLs are loaded on demand into the associated -\&\fBX509_STORE\fR. -\&\fItype\fR indicates what type of object is expected. -This can only be used with a lookup using the implementation -\&\fBX509_LOOKUP_hash_dir\fR\|(3). -.PP -\&\fBX509_LOOKUP_add_store_ex()\fR passes a \s-1URI\s0 for a directory-like structure -from which containers with certificates and CRLs are loaded on demand -into the associated \fBX509_STORE\fR. The library context \fIlibctx\fR and property -query \fIpropq\fR are used when fetching algorithms from providers. -.PP -\&\fBX509_LOOKUP_add_store()\fR is similar to \fBX509_LOOKUP_add_store_ex()\fR but -uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBX509_LOOKUP_load_store_ex()\fR passes a \s-1URI\s0 for a single container from -which certificates and CRLs are immediately loaded into the associated -\&\fBX509_STORE\fR. The library context \fIlibctx\fR and property query \fIpropq\fR are used -when fetching algorithms from providers. -These functions can only be used with a lookup using the -implementation \fBX509_LOOKUP_store\fR\|(3). -.PP -\&\fBX509_LOOKUP_load_store()\fR is similar to \fBX509_LOOKUP_load_store_ex()\fR but -uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBX509_LOOKUP_load_file_ex()\fR, \fBX509_LOOKUP_load_file()\fR, -\&\fBX509_LOOKUP_add_dir()\fR, -\&\fBX509_LOOKUP_add_store_ex()\fR \fBX509_LOOKUP_add_store()\fR, -\&\fBX509_LOOKUP_load_store_ex()\fR and \fBX509_LOOKUP_load_store()\fR are -implemented as macros that use \fBX509_LOOKUP_ctrl()\fR. -.PP -\&\fBX509_LOOKUP_by_subject_ex()\fR, \fBX509_LOOKUP_by_subject()\fR, -\&\fBX509_LOOKUP_by_issuer_serial()\fR, \fBX509_LOOKUP_by_fingerprint()\fR, and -\&\fBX509_LOOKUP_by_alias()\fR look up certificates and CRLs in the \fBX509_STORE\fR\|(3) -associated with the \fBX509_LOOKUP\fR using different criteria, where the looked up -object is stored in \fIret\fR. -Some of the underlying \fBX509_LOOKUP_METHOD\fRs will also cache objects -matching the criteria in the associated \fBX509_STORE\fR, which makes it -possible to handle cases where the criteria have more than one hit. -.SS "Control Commands" -.IX Subsection "Control Commands" -The \fBX509_LOOKUP_METHOD\fRs built into OpenSSL recognize the following -\&\fBX509_LOOKUP_ctrl()\fR \fIcmd\fRs: -.IP "\fBX509_L_FILE_LOAD\fR" 4 -.IX Item "X509_L_FILE_LOAD" -This is the command that \fBX509_LOOKUP_load_file_ex()\fR and -\&\fBX509_LOOKUP_load_file()\fR use. -The filename is passed in \fIargc\fR, and the type in \fIargl\fR. -.IP "\fBX509_L_ADD_DIR\fR" 4 -.IX Item "X509_L_ADD_DIR" -This is the command that \fBX509_LOOKUP_add_dir()\fR uses. -The directory specification is passed in \fIargc\fR, and the type in -\&\fIargl\fR. -.IP "\fBX509_L_ADD_STORE\fR" 4 -.IX Item "X509_L_ADD_STORE" -This is the command that \fBX509_LOOKUP_add_store_ex()\fR and -\&\fBX509_LOOKUP_add_store()\fR use. -The \s-1URI\s0 is passed in \fIargc\fR. -.IP "\fBX509_L_LOAD_STORE\fR" 4 -.IX Item "X509_L_LOAD_STORE" -This is the command that \fBX509_LOOKUP_load_store_ex()\fR and -\&\fBX509_LOOKUP_load_store()\fR use. -The \s-1URI\s0 is passed in \fIargc\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_LOOKUP_new()\fR returns a \fBX509_LOOKUP\fR pointer when successful, -or \s-1NULL\s0 on error. -.PP -\&\fBX509_LOOKUP_init()\fR and \fBX509_LOOKUP_shutdown()\fR return 1 on success, or -0 on error. -.PP -\&\fBX509_LOOKUP_ctrl_ex()\fR and \fBX509_LOOKUP_ctrl()\fR -return \-1 if the \fBX509_LOOKUP\fR doesn't have an -associated \fBX509_LOOKUP_METHOD\fR, or 1 if the -doesn't have a control function. -Otherwise, it returns what the control function in the -\&\fBX509_LOOKUP_METHOD\fR returns, which is usually 1 on success and 0 on error -but could also be \-1 on failure. -.IX Xref "509_LOOKUP_METHOD" -.PP -\&\fBX509_LOOKUP_get_store()\fR returns a \fBX509_STORE\fR pointer if there is -one, otherwise \s-1NULL.\s0 -.PP -\&\fBX509_LOOKUP_by_subject_ex()\fR returns 0 if there is no \fBX509_LOOKUP_METHOD\fR -that implements any of the \fBget_by_subject_ex()\fR or \fBget_by_subject()\fR functions. -It calls \fBget_by_subject_ex()\fR if present, otherwise \fBget_by_subject()\fR, and returns -the result of the function, which is usually 1 on success and 0 on error. -.PP -\&\fBX509_LOOKUP_by_subject()\fR is similar to \fBX509_LOOKUP_by_subject_ex()\fR -but passes \s-1NULL\s0 for both the libctx and propq. -.PP -\&\fBX509_LOOKUP_by_issuer_serial()\fR, \fBX509_LOOKUP_by_fingerprint()\fR, and -\&\fBX509_LOOKUP_by_alias()\fR all return 0 if there is no \fBX509_LOOKUP_METHOD\fR or that -method doesn't implement the corresponding function. -Otherwise, they return what the corresponding function in the -\&\fBX509_LOOKUP_METHOD\fR returns, which is usually 1 on success and 0 in -error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_LOOKUP_METHOD\fR\|(3), \fBX509_STORE\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBX509_LOOKUP_by_subject_ex()\fR and -\&\fBX509_LOOKUP_ctrl_ex()\fR were added in OpenSSL 3.0. -.PP -The macros \fBX509_LOOKUP_load_file_ex()\fR, -\&\fBX509_LOOKUP_load_store_ex()\fR and 509_LOOKUP_add_store_ex() were -added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_LOOKUP_METHOD.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_METHOD.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_METHOD.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_TYPE.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_TYPE.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_TYPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_add_dir.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_add_dir.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_add_dir.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_add_store.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_add_store.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_add_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_add_store_ex.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_add_store_ex.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_add_store_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_by_alias.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_by_alias.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_by_alias.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_by_fingerprint.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_by_fingerprint.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_by_fingerprint.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_by_issuer_serial.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_by_issuer_serial.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_by_issuer_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_by_subject.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_by_subject.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_by_subject.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_by_subject_ex.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_by_subject_ex.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_by_subject_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_ctrl.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_ctrl.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_ctrl_ex.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_ctrl_ex.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_ctrl_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_ctrl_fn.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_ctrl_fn.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_ctrl_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_file.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_file.3ossl deleted file mode 120000 index c5406670..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_hash_dir.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_free.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_free.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_get_by_alias_fn.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_get_by_alias_fn.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_get_by_alias_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_get_by_fingerprint_fn.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_get_by_fingerprint_fn.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_get_by_fingerprint_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_get_by_issuer_serial_fn.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_get_by_issuer_serial_fn.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_get_by_issuer_serial_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_get_by_subject_fn.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_get_by_subject_fn.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_get_by_subject_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_get_method_data.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_get_method_data.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_get_method_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_get_store.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_get_store.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_get_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_hash_dir.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_hash_dir.3ossl deleted file mode 100644 index ce3a7d5a..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_hash_dir.3ossl +++ /dev/null @@ -1,291 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_LOOKUP_HASH_DIR 3ossl" -.TH X509_LOOKUP_HASH_DIR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_LOOKUP_hash_dir, X509_LOOKUP_file, X509_LOOKUP_store, -X509_load_cert_file_ex, X509_load_cert_file, -X509_load_crl_file, -X509_load_cert_crl_file_ex, X509_load_cert_crl_file -\&\- Default OpenSSL certificate lookup methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_LOOKUP_METHOD *X509_LOOKUP_hash_dir(void); -\& X509_LOOKUP_METHOD *X509_LOOKUP_file(void); -\& X509_LOOKUP_METHOD *X509_LOOKUP_store(void); -\& -\& int X509_load_cert_file_ex(X509_LOOKUP *ctx, const char *file, int type, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_load_cert_file(X509_LOOKUP *ctx, const char *file, int type); -\& int X509_load_crl_file(X509_LOOKUP *ctx, const char *file, int type); -\& int X509_load_cert_crl_file_ex(X509_LOOKUP *ctx, const char *file, int type, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_load_cert_crl_file(X509_LOOKUP *ctx, const char *file, int type); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_LOOKUP_hash_dir\fR and \fBX509_LOOKUP_file\fR are two certificate -lookup methods to use with \fBX509_STORE\fR, provided by OpenSSL library. -.PP -Users of the library typically do not need to create instances of these -methods manually, they would be created automatically by -\&\fBX509_STORE_load_locations\fR\|(3) or -\&\fBSSL_CTX_load_verify_locations\fR\|(3) -functions. -.PP -Internally loading of certificates and CRLs is implemented via functions -\&\fBX509_load_cert_crl_file\fR, \fBX509_load_cert_file\fR and -\&\fBX509_load_crl_file\fR. These functions support parameter \fItype\fR, which -can be one of constants \fB\s-1FILETYPE_PEM\s0\fR, \fB\s-1FILETYPE_ASN1\s0\fR and -\&\fB\s-1FILETYPE_DEFAULT\s0\fR. They load certificates and/or CRLs from specified -file into memory cache of \fBX509_STORE\fR objects which given \fBctx\fR -parameter is associated with. -.PP -Functions \fBX509_load_cert_file\fR and -\&\fBX509_load_crl_file\fR can load both \s-1PEM\s0 and \s-1DER\s0 formats depending of -type value. Because \s-1DER\s0 format cannot contain more than one certificate -or \s-1CRL\s0 object (while \s-1PEM\s0 can contain several concatenated \s-1PEM\s0 objects) -\&\fBX509_load_cert_crl_file\fR with \fB\s-1FILETYPE_ASN1\s0\fR is equivalent to -\&\fBX509_load_cert_file\fR. -.PP -Constant \fB\s-1FILETYPE_DEFAULT\s0\fR with \s-1NULL\s0 filename causes these functions -to load default certificate store file (see -\&\fBX509_STORE_set_default_paths\fR\|(3). -.PP -Functions return number of objects loaded from file or 0 in case of -error. -.PP -Both methods support adding several certificate locations into one -\&\fBX509_STORE\fR. -.PP -This page documents certificate store formats used by these methods and -caching policy. -.SS "File Method" -.IX Subsection "File Method" -The \fBX509_LOOKUP_file\fR method loads all the certificates or CRLs -present in a file into memory at the time the file is added as a -lookup source. -.PP -File format is \s-1ASCII\s0 text which contains concatenated \s-1PEM\s0 certificates -and CRLs. -.PP -This method should be used by applications which work with a small -set of CAs. -.SS "Hashed Directory Method" -.IX Subsection "Hashed Directory Method" -\&\fBX509_LOOKUP_hash_dir\fR is a more advanced method, which loads -certificates and CRLs on demand, and caches them in memory once -they are loaded. As of OpenSSL 1.0.0, it also checks for newer CRLs -upon each lookup, so that newer CRLs are as soon as they appear in -the directory. -.PP -The directory should contain one certificate or \s-1CRL\s0 per file in \s-1PEM\s0 format, -with a filename of the form \fIhash\fR.\fIN\fR for a certificate, or -\&\fIhash\fR.\fBr\fR\fIN\fR for a \s-1CRL.\s0 -The \fIhash\fR is the value returned by the \fBX509_NAME_hash_ex\fR\|(3) function -applied to the subject name for certificates or issuer name for CRLs. -The hash can also be obtained via the \fB\-hash\fR option of the -\&\fBopenssl\-x509\fR\|(1) or \fBopenssl\-crl\fR\|(1) commands. -.PP -The .\fIN\fR or .\fBr\fR\fIN\fR suffix is a sequence number that starts at zero, and is -incremented consecutively for each certificate or \s-1CRL\s0 with the same \fIhash\fR -value. -Gaps in the sequence numbers are not supported, it is assumed that there are no -more objects with the same hash beyond the first missing number in the -sequence. -.PP -Sequence numbers make it possible for the directory to contain multiple -certificates with same subject name hash value. -For example, it is possible to have in the store several certificates with same -subject or several CRLs with same issuer (and, for example, different validity -period). -.PP -When checking for new CRLs once one \s-1CRL\s0 for given hash value is -loaded, hash_dir lookup method checks only for certificates with -sequence number greater than that of the already cached \s-1CRL.\s0 -.PP -Note that the hash algorithm used for subject name hashing changed in OpenSSL -1.0.0, and all certificate stores have to be rehashed when moving from OpenSSL -0.9.8 to 1.0.0. -.PP -OpenSSL includes a \fBopenssl\-rehash\fR\|(1) utility which creates symlinks with -hashed names for all files with \fI.pem\fR suffix in a given directory. -.SS "\s-1OSSL_STORE\s0 Method" -.IX Subsection "OSSL_STORE Method" -\&\fBX509_LOOKUP_store\fR is a method that allows access to any store of -certificates and CRLs through any loader supported by -\&\fBossl_store\fR\|(7). -It works with the help of URIs, which can be direct references to -certificates or CRLs, but can also be references to catalogues of such -objects (that behave like directories). -.PP -This method overlaps the \*(L"File Method\*(R" and \*(L"Hashed Directory Method\*(R" -because of the 'file:' scheme loader. -It does no caching of its own, but can use a caching \fBossl_store\fR\|(7) -loader, and therefore depends on the loader's capability. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_LOOKUP_hash_dir()\fR, \fBX509_LOOKUP_file()\fR and \fBX509_LOOKUP_store()\fR -always return a valid \fBX509_LOOKUP_METHOD\fR structure. -.PP -\&\fBX509_load_cert_file()\fR, \fBX509_load_crl_file()\fR and \fBX509_load_cert_crl_file()\fR return -the number of loaded objects or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPEM_read_PrivateKey\fR\|(3), -\&\fBX509_STORE_load_locations\fR\|(3), -\&\fBSSL_CTX_load_verify_locations\fR\|(3), -\&\fBX509_LOOKUP_meth_new\fR\|(3), -\&\fBossl_store\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBX509_load_cert_file_ex()\fR, -\&\fBX509_load_cert_crl_file_ex()\fR and \fBX509_LOOKUP_store()\fR were added in -OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_LOOKUP_init.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_init.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_load_file.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_load_file.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_load_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_load_file_ex.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_load_file_ex.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_load_file_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_load_store.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_load_store.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_load_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_load_store_ex.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_load_store_ex.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_load_store_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_free.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_free.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_ctrl.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_ctrl.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_free.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_free.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_alias.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_alias.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_alias.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_fingerprint.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_fingerprint.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_fingerprint.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_issuer_serial.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_issuer_serial.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_issuer_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_subject.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_subject.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_get_by_subject.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_init.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_init.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_new_item.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_new_item.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_new_item.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_shutdown.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_get_shutdown.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_get_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_new.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_new.3ossl deleted file mode 100644 index 05b5c091..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_new.3ossl +++ /dev/null @@ -1,328 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_LOOKUP_METH_NEW 3ossl" -.TH X509_LOOKUP_METH_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_LOOKUP_METHOD, -X509_LOOKUP_meth_new, X509_LOOKUP_meth_free, X509_LOOKUP_meth_set_new_item, -X509_LOOKUP_meth_get_new_item, X509_LOOKUP_meth_set_free, -X509_LOOKUP_meth_get_free, X509_LOOKUP_meth_set_init, -X509_LOOKUP_meth_get_init, X509_LOOKUP_meth_set_shutdown, -X509_LOOKUP_meth_get_shutdown, -X509_LOOKUP_ctrl_fn, X509_LOOKUP_meth_set_ctrl, X509_LOOKUP_meth_get_ctrl, -X509_LOOKUP_get_by_subject_fn, X509_LOOKUP_meth_set_get_by_subject, -X509_LOOKUP_meth_get_get_by_subject, -X509_LOOKUP_get_by_issuer_serial_fn, X509_LOOKUP_meth_set_get_by_issuer_serial, -X509_LOOKUP_meth_get_get_by_issuer_serial, -X509_LOOKUP_get_by_fingerprint_fn, X509_LOOKUP_meth_set_get_by_fingerprint, -X509_LOOKUP_meth_get_get_by_fingerprint, -X509_LOOKUP_get_by_alias_fn, X509_LOOKUP_meth_set_get_by_alias, -X509_LOOKUP_meth_get_get_by_alias, -X509_OBJECT_set1_X509, X509_OBJECT_set1_X509_CRL -\&\- Routines to build up X509_LOOKUP methods -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef x509_lookup_method_st X509_LOOKUP_METHOD; -\& -\& X509_LOOKUP_METHOD *X509_LOOKUP_meth_new(const char *name); -\& void X509_LOOKUP_meth_free(X509_LOOKUP_METHOD *method); -\& -\& int X509_LOOKUP_meth_set_new_item(X509_LOOKUP_METHOD *method, -\& int (*new_item) (X509_LOOKUP *ctx)); -\& int (*X509_LOOKUP_meth_get_new_item(const X509_LOOKUP_METHOD* method)) -\& (X509_LOOKUP *ctx); -\& -\& int X509_LOOKUP_meth_set_free(X509_LOOKUP_METHOD *method, -\& void (*free) (X509_LOOKUP *ctx)); -\& void (*X509_LOOKUP_meth_get_free(const X509_LOOKUP_METHOD* method)) -\& (X509_LOOKUP *ctx); -\& -\& int X509_LOOKUP_meth_set_init(X509_LOOKUP_METHOD *method, -\& int (*init) (X509_LOOKUP *ctx)); -\& int (*X509_LOOKUP_meth_get_init(const X509_LOOKUP_METHOD* method)) -\& (X509_LOOKUP *ctx); -\& -\& int X509_LOOKUP_meth_set_shutdown(X509_LOOKUP_METHOD *method, -\& int (*shutdown) (X509_LOOKUP *ctx)); -\& int (*X509_LOOKUP_meth_get_shutdown(const X509_LOOKUP_METHOD* method)) -\& (X509_LOOKUP *ctx); -\& -\& typedef int (*X509_LOOKUP_ctrl_fn)(X509_LOOKUP *ctx, int cmd, const char *argc, -\& long argl, char **ret); -\& int X509_LOOKUP_meth_set_ctrl(X509_LOOKUP_METHOD *method, -\& X509_LOOKUP_ctrl_fn ctrl_fn); -\& X509_LOOKUP_ctrl_fn X509_LOOKUP_meth_get_ctrl(const X509_LOOKUP_METHOD *method); -\& -\& typedef int (*X509_LOOKUP_get_by_subject_fn)(X509_LOOKUP *ctx, -\& X509_LOOKUP_TYPE type, -\& const X509_NAME *name, -\& X509_OBJECT *ret); -\& int X509_LOOKUP_meth_set_get_by_subject(X509_LOOKUP_METHOD *method, -\& X509_LOOKUP_get_by_subject_fn fn); -\& X509_LOOKUP_get_by_subject_fn X509_LOOKUP_meth_get_get_by_subject( -\& const X509_LOOKUP_METHOD *method); -\& -\& typedef int (*X509_LOOKUP_get_by_issuer_serial_fn)(X509_LOOKUP *ctx, -\& X509_LOOKUP_TYPE type, -\& const X509_NAME *name, -\& const ASN1_INTEGER *serial, -\& X509_OBJECT *ret); -\& int X509_LOOKUP_meth_set_get_by_issuer_serial( -\& X509_LOOKUP_METHOD *method, X509_LOOKUP_get_by_issuer_serial_fn fn); -\& X509_LOOKUP_get_by_issuer_serial_fn X509_LOOKUP_meth_get_get_by_issuer_serial( -\& const X509_LOOKUP_METHOD *method); -\& -\& typedef int (*X509_LOOKUP_get_by_fingerprint_fn)(X509_LOOKUP *ctx, -\& X509_LOOKUP_TYPE type, -\& const unsigned char* bytes, -\& int len, -\& X509_OBJECT *ret); -\& int X509_LOOKUP_meth_set_get_by_fingerprint(X509_LOOKUP_METHOD *method, -\& X509_LOOKUP_get_by_fingerprint_fn fn); -\& X509_LOOKUP_get_by_fingerprint_fn X509_LOOKUP_meth_get_get_by_fingerprint( -\& const X509_LOOKUP_METHOD *method); -\& -\& typedef int (*X509_LOOKUP_get_by_alias_fn)(X509_LOOKUP *ctx, -\& X509_LOOKUP_TYPE type, -\& const char *str, -\& int len, -\& X509_OBJECT *ret); -\& int X509_LOOKUP_meth_set_get_by_alias(X509_LOOKUP_METHOD *method, -\& X509_LOOKUP_get_by_alias_fn fn); -\& X509_LOOKUP_get_by_alias_fn X509_LOOKUP_meth_get_get_by_alias( -\& const X509_LOOKUP_METHOD *method); -\& -\& int X509_OBJECT_set1_X509(X509_OBJECT *a, X509 *obj); -\& int X509_OBJECT_set1_X509_CRL(X509_OBJECT *a, X509_CRL *obj); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX509_LOOKUP_METHOD\fR type is a structure used for the implementation of new -X509_LOOKUP types. It provides a set of functions used by OpenSSL for the -implementation of various X509 and X509_CRL lookup capabilities. One instance -of an X509_LOOKUP_METHOD can be associated to many instantiations of an -\&\fBX509_LOOKUP\fR structure. -.PP -\&\fBX509_LOOKUP_meth_new()\fR creates a new \fBX509_LOOKUP_METHOD\fR structure. It should -be given a human-readable string containing a brief description of the lookup -method. -.PP -\&\fBX509_LOOKUP_meth_free()\fR destroys a \fBX509_LOOKUP_METHOD\fR structure. -If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fBX509_LOOKUP_get_new_item()\fR and \fBX509_LOOKUP_set_new_item()\fR get and set the -function that is called when an \fBX509_LOOKUP\fR object is created with -\&\fBX509_LOOKUP_new()\fR. If an X509_LOOKUP_METHOD requires any per\-X509_LOOKUP -specific data, the supplied new_item function should allocate this data and -invoke \fBX509_LOOKUP_set_method_data\fR\|(3). -.PP -\&\fBX509_LOOKUP_get_free()\fR and \fBX509_LOOKUP_set_free()\fR get and set the function -that is used to free any method data that was allocated and set from within -new_item function. -.PP -\&\fBX509_LOOKUP_meth_get_init()\fR and \fBX509_LOOKUP_meth_set_init()\fR get and set the -function that is used to initialize the method data that was set with -\&\fBX509_LOOKUP_set_method_data\fR\|(3) as part of the new_item routine. -.PP -\&\fBX509_LOOKUP_meth_get_shutdown()\fR and \fBX509_LOOKUP_meth_set_shutdown()\fR get and set -the function that is used to shut down the method data whose state was -previously initialized in the init function. -.PP -\&\fBX509_LOOKUP_meth_get_ctrl()\fR and \fBX509_LOOKUP_meth_set_ctrl()\fR get and set a -function to be used to handle arbitrary control commands issued by -\&\fBX509_LOOKUP_ctrl()\fR. The control function is given the X509_LOOKUP -\&\fBctx\fR, along with the arguments passed by X509_LOOKUP_ctrl. \fBcmd\fR is -an arbitrary integer that defines some operation. \fBargc\fR is a pointer -to an array of characters. \fBargl\fR is an integer. \fBret\fR, if set, -points to a location where any return data should be written to. How -\&\fBargc\fR and \fBargl\fR are used depends entirely on the control function. -.PP -\&\fBX509_LOOKUP_set_get_by_subject()\fR, \fBX509_LOOKUP_set_get_by_issuer_serial()\fR, -\&\fBX509_LOOKUP_set_get_by_fingerprint()\fR, \fBX509_LOOKUP_set_get_by_alias()\fR set -the functions used to retrieve an X509 or X509_CRL object by the object's -subject, issuer, fingerprint, and alias respectively. These functions are given -the X509_LOOKUP context, the type of the X509_OBJECT being requested, parameters -related to the lookup, and an X509_OBJECT that will receive the requested -object. -.PP -Implementations must add objects they find to the \fBX509_STORE\fR object -using \fBX509_STORE_add_cert()\fR or \fBX509_STORE_add_crl()\fR. This increments -its reference count. However, the \fBX509_STORE_CTX_get_by_subject\fR\|(3) -function also increases the reference count which leads to one too -many references being held. Therefore, applications should -additionally call \fBX509_free()\fR or \fBX509_CRL_free()\fR to decrement the -reference count again. -.PP -Implementations should also use either \fBX509_OBJECT_set1_X509()\fR or -\&\fBX509_OBJECT_set1_X509_CRL()\fR to set the result. Note that this also -increments the result's reference count. -.PP -Any method data that was created as a result of the new_item function -set by \fBX509_LOOKUP_meth_set_new_item()\fR can be accessed with -\&\fBX509_LOOKUP_get_method_data\fR\|(3). The \fBX509_STORE\fR object that owns the -X509_LOOKUP may be accessed with \fBX509_LOOKUP_get_store\fR\|(3). Successful -lookups should return 1, and unsuccessful lookups should return 0. -.PP -\&\fBX509_LOOKUP_get_get_by_subject()\fR, \fBX509_LOOKUP_get_get_by_issuer_serial()\fR, -\&\fBX509_LOOKUP_get_get_by_fingerprint()\fR, \fBX509_LOOKUP_get_get_by_alias()\fR retrieve -the function set by the corresponding setter. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBX509_LOOKUP_meth_set\fR functions return 1 on success or 0 on error. -.PP -The \fBX509_LOOKUP_meth_get\fR functions return the corresponding function -pointers. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_STORE_CTX_get_by_subject\fR\|(3), -\&\fBX509_STORE_new\fR\|(3), \fBSSL_CTX_set_cert_store\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions described here were added in OpenSSL 1.1.0i. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_ctrl.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_ctrl.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_ctrl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_free.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_free.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_alias.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_alias.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_alias.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_fingerprint.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_fingerprint.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_fingerprint.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_issuer_serial.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_issuer_serial.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_issuer_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_subject.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_subject.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_get_by_subject.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_init.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_init.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_new_item.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_new_item.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_new_item.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_shutdown.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_meth_set_shutdown.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_meth_set_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_new.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_new.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_set_method_data.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_set_method_data.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_set_method_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_shutdown.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_shutdown.3ossl deleted file mode 120000 index d0dcce04..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_shutdown.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_LOOKUP_store.3ossl b/openssl-install/share/man/man3/X509_LOOKUP_store.3ossl deleted file mode 120000 index c5406670..00000000 --- a/openssl-install/share/man/man3/X509_LOOKUP_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_hash_dir.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_NID.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_NID.3ossl deleted file mode 120000 index 9ebc6080..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_ENTRY_get_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_OBJ.3ossl deleted file mode 120000 index 9ebc6080..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_ENTRY_get_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_txt.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_txt.3ossl deleted file mode 120000 index 9ebc6080..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_create_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_ENTRY_get_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_dup.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_free.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_get_data.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_get_data.3ossl deleted file mode 120000 index 9ebc6080..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_get_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_ENTRY_get_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_get_object.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_get_object.3ossl deleted file mode 100644 index 00898fda..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_get_object.3ossl +++ /dev/null @@ -1,227 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_NAME_ENTRY_GET_OBJECT 3ossl" -.TH X509_NAME_ENTRY_GET_OBJECT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_NAME_ENTRY_get_object, X509_NAME_ENTRY_get_data, -X509_NAME_ENTRY_set_object, X509_NAME_ENTRY_set_data, -X509_NAME_ENTRY_create_by_txt, X509_NAME_ENTRY_create_by_NID, -X509_NAME_ENTRY_create_by_OBJ \- X509_NAME_ENTRY utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne); -\& ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne); -\& -\& int X509_NAME_ENTRY_set_object(X509_NAME_ENTRY *ne, const ASN1_OBJECT *obj); -\& int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type, -\& const unsigned char *bytes, int len); -\& -\& X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_txt(X509_NAME_ENTRY **ne, const char *field, -\& int type, const unsigned char *bytes, -\& int len); -\& X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_NID(X509_NAME_ENTRY **ne, int nid, -\& int type, const unsigned char *bytes, -\& int len); -\& X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_OBJ(X509_NAME_ENTRY **ne, -\& const ASN1_OBJECT *obj, int type, -\& const unsigned char *bytes, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_NAME_ENTRY_get_object()\fR retrieves the field name of \fBne\fR in -and \fB\s-1ASN1_OBJECT\s0\fR structure. -.PP -\&\fBX509_NAME_ENTRY_get_data()\fR retrieves the field value of \fBne\fR in -and \fB\s-1ASN1_STRING\s0\fR structure. -.PP -\&\fBX509_NAME_ENTRY_set_object()\fR sets the field name of \fBne\fR to \fBobj\fR. -.PP -\&\fBX509_NAME_ENTRY_set_data()\fR sets the field value of \fBne\fR to string type -\&\fBtype\fR and value determined by \fBbytes\fR and \fBlen\fR. -.PP -\&\fBX509_NAME_ENTRY_create_by_txt()\fR, \fBX509_NAME_ENTRY_create_by_NID()\fR -and \fBX509_NAME_ENTRY_create_by_OBJ()\fR create and return an -\&\fBX509_NAME_ENTRY\fR structure. -.SH "NOTES" -.IX Header "NOTES" -\&\fBX509_NAME_ENTRY_get_object()\fR and \fBX509_NAME_ENTRY_get_data()\fR can be -used to examine an \fBX509_NAME_ENTRY\fR function as returned by -\&\fBX509_NAME_get_entry()\fR for example. -.PP -\&\fBX509_NAME_ENTRY_create_by_txt()\fR, \fBX509_NAME_ENTRY_create_by_OBJ()\fR, -\&\fBX509_NAME_ENTRY_create_by_NID()\fR and \fBX509_NAME_ENTRY_set_data()\fR -are seldom used in practice because \fBX509_NAME_ENTRY\fR structures -are almost always part of \fBX509_NAME\fR structures and the -corresponding \fBX509_NAME\fR functions are typically used to -create and add new entries in a single operation. -.PP -The arguments of these functions support similar options to the similarly -named ones of the corresponding \fBX509_NAME\fR functions such as -\&\fBX509_NAME_add_entry_by_txt()\fR. So for example \fBtype\fR can be set to -\&\fB\s-1MBSTRING_ASC\s0\fR but in the case of \fBX509_set_data()\fR the field name must be -set first so the relevant field information can be looked up internally. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_NAME_ENTRY_get_object()\fR returns a valid \fB\s-1ASN1_OBJECT\s0\fR structure if it is -set or \s-1NULL\s0 if an error occurred. -.PP -\&\fBX509_NAME_ENTRY_get_data()\fR returns a valid \fB\s-1ASN1_STRING\s0\fR structure if it is set -or \s-1NULL\s0 if an error occurred. -.PP -\&\fBX509_NAME_ENTRY_set_object()\fR and \fBX509_NAME_ENTRY_set_data()\fR return 1 on success -or 0 on error. -.PP -\&\fBX509_NAME_ENTRY_create_by_txt()\fR, \fBX509_NAME_ENTRY_create_by_NID()\fR and -\&\fBX509_NAME_ENTRY_create_by_OBJ()\fR return a valid \fBX509_NAME_ENTRY\fR on success or -\&\s-1NULL\s0 if an error occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBd2i_X509_NAME\fR\|(3), -\&\fBOBJ_nid2obj\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_new.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_set_data.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_set_data.3ossl deleted file mode 120000 index 9ebc6080..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_set_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_ENTRY_get_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_ENTRY_set_object.3ossl b/openssl-install/share/man/man3/X509_NAME_ENTRY_set_object.3ossl deleted file mode 120000 index 9ebc6080..00000000 --- a/openssl-install/share/man/man3/X509_NAME_ENTRY_set_object.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_ENTRY_get_object.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_add_entry.3ossl b/openssl-install/share/man/man3/X509_NAME_add_entry.3ossl deleted file mode 120000 index b819127e..00000000 --- a/openssl-install/share/man/man3/X509_NAME_add_entry.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_add_entry_by_txt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_add_entry_by_NID.3ossl b/openssl-install/share/man/man3/X509_NAME_add_entry_by_NID.3ossl deleted file mode 120000 index b819127e..00000000 --- a/openssl-install/share/man/man3/X509_NAME_add_entry_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_add_entry_by_txt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_add_entry_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_NAME_add_entry_by_OBJ.3ossl deleted file mode 120000 index b819127e..00000000 --- a/openssl-install/share/man/man3/X509_NAME_add_entry_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_add_entry_by_txt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_add_entry_by_txt.3ossl b/openssl-install/share/man/man3/X509_NAME_add_entry_by_txt.3ossl deleted file mode 100644 index 329976de..00000000 --- a/openssl-install/share/man/man3/X509_NAME_add_entry_by_txt.3ossl +++ /dev/null @@ -1,258 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_NAME_ADD_ENTRY_BY_TXT 3ossl" -.TH X509_NAME_ADD_ENTRY_BY_TXT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_NAME_add_entry_by_txt, X509_NAME_add_entry_by_OBJ, X509_NAME_add_entry_by_NID, -X509_NAME_add_entry, X509_NAME_delete_entry \- X509_NAME modification functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_NAME_add_entry_by_txt(X509_NAME *name, const char *field, int type, -\& const unsigned char *bytes, int len, int loc, int set); -\& -\& int X509_NAME_add_entry_by_OBJ(X509_NAME *name, const ASN1_OBJECT *obj, int type, -\& const unsigned char *bytes, int len, int loc, int set); -\& -\& int X509_NAME_add_entry_by_NID(X509_NAME *name, int nid, int type, -\& const unsigned char *bytes, int len, int loc, int set); -\& -\& int X509_NAME_add_entry(X509_NAME *name, const X509_NAME_ENTRY *ne, int loc, int set); -\& -\& X509_NAME_ENTRY *X509_NAME_delete_entry(X509_NAME *name, int loc); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_NAME_add_entry_by_txt()\fR, \fBX509_NAME_add_entry_by_OBJ()\fR and -\&\fBX509_NAME_add_entry_by_NID()\fR add a field whose name is defined -by a string \fBfield\fR, an object \fBobj\fR or a \s-1NID\s0 \fBnid\fR respectively. -The field value to be added is in \fBbytes\fR of length \fBlen\fR. If -\&\fBlen\fR is \-1 then the field length is calculated internally using -strlen(bytes). -.PP -The type of field is determined by \fBtype\fR which can either be a -definition of the type of \fBbytes\fR (such as \fB\s-1MBSTRING_ASC\s0\fR) or a -standard \s-1ASN1\s0 type (such as \fBV_ASN1_IA5STRING\fR). The new entry is -added to a position determined by \fBloc\fR and \fBset\fR. -.PP -\&\fBX509_NAME_add_entry()\fR adds a copy of \fBX509_NAME_ENTRY\fR structure \fBne\fR -to \fBname\fR. The new entry is added to a position determined by \fBloc\fR -and \fBset\fR. Since a copy of \fBne\fR is added \fBne\fR must be freed up after -the call. -.PP -\&\fBX509_NAME_delete_entry()\fR deletes an entry from \fBname\fR at position -\&\fBloc\fR. The deleted entry is returned and must be freed up. -.SH "NOTES" -.IX Header "NOTES" -The use of string types such as \fB\s-1MBSTRING_ASC\s0\fR or \fB\s-1MBSTRING_UTF8\s0\fR -is strongly recommended for the \fBtype\fR parameter. This allows the -internal code to correctly determine the type of the field and to -apply length checks according to the relevant standards. This is -done using \fBASN1_STRING_set_by_NID()\fR. -.PP -If instead an \s-1ASN1\s0 type is used no checks are performed and the -supplied data in \fBbytes\fR is used directly. -.PP -In \fBX509_NAME_add_entry_by_txt()\fR the \fBfield\fR string represents -the field name using OBJ_txt2obj(field, 0). -.PP -The \fBloc\fR and \fBset\fR parameters determine where a new entry should -be added. For almost all applications \fBloc\fR can be set to \-1 and \fBset\fR -to 0. This adds a new entry to the end of \fBname\fR as a single valued -RelativeDistinguishedName (\s-1RDN\s0). -.PP -\&\fBloc\fR actually determines the index where the new entry is inserted: -if it is \-1 it is appended. -.PP -\&\fBset\fR determines how the new type is added. -If it is zero a new \s-1RDN\s0 is created. -.PP -If \fBset\fR is \-1 or 1 it is added as a new set member -to the previous or next \s-1RDN\s0 structure, respectively. -This will then become part of a multi-valued \s-1RDN\s0 (containing a set of AVAs). -Since multi-valued RDNs are very rarely used \fBset\fR typically will be zero. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_NAME_add_entry_by_txt()\fR, \fBX509_NAME_add_entry_by_OBJ()\fR, -\&\fBX509_NAME_add_entry_by_NID()\fR and \fBX509_NAME_add_entry()\fR return 1 for -success of 0 if an error occurred. -.PP -\&\fBX509_NAME_delete_entry()\fR returns either the deleted \fBX509_NAME_ENTRY\fR -structure or \fB\s-1NULL\s0\fR if an error occurred. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create an \fBX509_NAME\fR structure: -.PP -\&\*(L"C=UK, O=Disorganized Organization, CN=Joe Bloggs\*(R" -.PP -.Vb 1 -\& X509_NAME *nm; -\& -\& nm = X509_NAME_new(); -\& if (nm == NULL) -\& /* Some error */ -\& if (!X509_NAME_add_entry_by_txt(nm, "C", MBSTRING_ASC, -\& "UK", \-1, \-1, 0)) -\& /* Error */ -\& if (!X509_NAME_add_entry_by_txt(nm, "O", MBSTRING_ASC, -\& "Disorganized Organization", \-1, \-1, 0)) -\& /* Error */ -\& if (!X509_NAME_add_entry_by_txt(nm, "CN", MBSTRING_ASC, -\& "Joe Bloggs", \-1, \-1, 0)) -\& /* Error */ -.Ve -.SH "BUGS" -.IX Header "BUGS" -\&\fBtype\fR can still be set to \fBV_ASN1_APP_CHOOSE\fR to use a -different algorithm to determine field types. Since this form does -not understand multicharacter types, performs no length checks and -can result in invalid field types its use is strongly discouraged. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBd2i_X509_NAME\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_NAME_cmp.3ossl b/openssl-install/share/man/man3/X509_NAME_cmp.3ossl deleted file mode 120000 index e12f4f89..00000000 --- a/openssl-install/share/man/man3/X509_NAME_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_delete_entry.3ossl b/openssl-install/share/man/man3/X509_NAME_delete_entry.3ossl deleted file mode 120000 index b819127e..00000000 --- a/openssl-install/share/man/man3/X509_NAME_delete_entry.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_add_entry_by_txt.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_digest.3ossl b/openssl-install/share/man/man3/X509_NAME_digest.3ossl deleted file mode 120000 index c2b39912..00000000 --- a/openssl-install/share/man/man3/X509_NAME_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_digest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_dup.3ossl b/openssl-install/share/man/man3/X509_NAME_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_NAME_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_entry_count.3ossl b/openssl-install/share/man/man3/X509_NAME_entry_count.3ossl deleted file mode 120000 index 65acb784..00000000 --- a/openssl-install/share/man/man3/X509_NAME_entry_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_get_index_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_free.3ossl b/openssl-install/share/man/man3/X509_NAME_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_NAME_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_get0_der.3ossl b/openssl-install/share/man/man3/X509_NAME_get0_der.3ossl deleted file mode 100644 index 48146c41..00000000 --- a/openssl-install/share/man/man3/X509_NAME_get0_der.3ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_NAME_GET0_DER 3ossl" -.TH X509_NAME_GET0_DER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_NAME_get0_der \- get X509_NAME DER encoding -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_NAME_get0_der(const X509_NAME *nm, const unsigned char **pder, -\& size_t *pderlen); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The function \fBX509_NAME_get0_der()\fR returns an internal pointer to the -encoding of an \fBX509_NAME\fR structure in \fB*pder\fR and consisting of -\&\fB*pderlen\fR bytes. It is useful for applications that wish to examine -the encoding of an \fBX509_NAME\fR structure without copying it. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The function \fBX509_NAME_get0_der()\fR returns 1 for success and 0 if an error -occurred. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_NAME_get_entry.3ossl b/openssl-install/share/man/man3/X509_NAME_get_entry.3ossl deleted file mode 120000 index 65acb784..00000000 --- a/openssl-install/share/man/man3/X509_NAME_get_entry.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_get_index_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_get_index_by_NID.3ossl b/openssl-install/share/man/man3/X509_NAME_get_index_by_NID.3ossl deleted file mode 100644 index 671b7415..00000000 --- a/openssl-install/share/man/man3/X509_NAME_get_index_by_NID.3ossl +++ /dev/null @@ -1,260 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_NAME_GET_INDEX_BY_NID 3ossl" -.TH X509_NAME_GET_INDEX_BY_NID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_NAME_get_index_by_NID, X509_NAME_get_index_by_OBJ, X509_NAME_get_entry, -X509_NAME_entry_count, X509_NAME_get_text_by_NID, X509_NAME_get_text_by_OBJ \- -X509_NAME lookup and enumeration functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_NAME_get_index_by_NID(const X509_NAME *name, int nid, int lastpos); -\& int X509_NAME_get_index_by_OBJ(const X509_NAME *name, -\& const ASN1_OBJECT *obj, int lastpos); -\& -\& int X509_NAME_entry_count(const X509_NAME *name); -\& X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc); -\& -\& int X509_NAME_get_text_by_NID(const X509_NAME *name, int nid, -\& char *buf, int len); -\& int X509_NAME_get_text_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj, -\& char *buf, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions allow an \fBX509_NAME\fR structure to be examined. The -\&\fBX509_NAME\fR structure is the same as the \fBName\fR type defined in -\&\s-1RFC2459\s0 (and elsewhere) and used for example in certificate subject -and issuer names. -.PP -\&\fBX509_NAME_get_index_by_NID()\fR and \fBX509_NAME_get_index_by_OBJ()\fR retrieve -the next index matching \fBnid\fR or \fBobj\fR after \fBlastpos\fR. \fBlastpos\fR -should initially be set to \-1. If there are no more entries \-1 is returned. -If \fBnid\fR is invalid (doesn't correspond to a valid \s-1OID\s0) then \-2 is returned. -.PP -\&\fBX509_NAME_entry_count()\fR returns the total number of entries in \fBname\fR. -.PP -\&\fBX509_NAME_get_entry()\fR retrieves the \fBX509_NAME_ENTRY\fR from \fBname\fR -corresponding to index \fBloc\fR. Acceptable values for \fBloc\fR run from -0 to (X509_NAME_entry_count(name) \- 1). The value returned is an -internal pointer which must not be freed. -.PP -\&\fBX509_NAME_get_text_by_NID()\fR, \fBX509_NAME_get_text_by_OBJ()\fR retrieve -the \*(L"text\*(R" from the first entry in \fBname\fR which matches \fBnid\fR or -\&\fBobj\fR, if no such entry exists \-1 is returned. At most \fBlen\fR bytes -will be written and the text written to \fBbuf\fR will be null -terminated. The length of the output string written is returned -excluding the terminating null. If \fBbuf\fR is <\s-1NULL\s0> then the amount -of space needed in \fBbuf\fR (excluding the final null) is returned. -.SH "NOTES" -.IX Header "NOTES" -\&\fBX509_NAME_get_text_by_NID()\fR and \fBX509_NAME_get_text_by_OBJ()\fR should be -considered deprecated because they -have various limitations which make them -of minimal use in practice. They can only find the first matching -entry and will copy the contents of the field verbatim: this can -be highly confusing if the target is a multicharacter string type -like a BMPString or a UTF8String. -.PP -For a more general solution \fBX509_NAME_get_index_by_NID()\fR or -\&\fBX509_NAME_get_index_by_OBJ()\fR should be used followed by -\&\fBX509_NAME_get_entry()\fR on any matching indices and then the -various \fBX509_NAME_ENTRY\fR utility functions on the result. -.PP -The list of all relevant \fBNID_*\fR and \fBOBJ_* codes\fR can be found in -the source code header files \fI\fR and/or -\&\fI\fR. -.PP -Applications which could pass invalid NIDs to \fBX509_NAME_get_index_by_NID()\fR -should check for the return value of \-2. Alternatively the \s-1NID\s0 validity -can be determined first by checking OBJ_nid2obj(nid) is not \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_NAME_get_index_by_NID()\fR and \fBX509_NAME_get_index_by_OBJ()\fR -return the index of the next matching entry or \-1 if not found. -\&\fBX509_NAME_get_index_by_NID()\fR can also return \-2 if the supplied -\&\s-1NID\s0 is invalid. -.PP -\&\fBX509_NAME_entry_count()\fR returns the total number of entries, and 0 -for failure. -.PP -\&\fBX509_NAME_get_entry()\fR returns an \fBX509_NAME\fR pointer to the -requested entry or \fB\s-1NULL\s0\fR if the index is invalid. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Process all entries: -.PP -.Vb 2 -\& int i; -\& X509_NAME_ENTRY *e; -\& -\& for (i = 0; i < X509_NAME_entry_count(nm); i++) { -\& e = X509_NAME_get_entry(nm, i); -\& /* Do something with e */ -\& } -.Ve -.PP -Process all commonName entries: -.PP -.Vb 2 -\& int lastpos = \-1; -\& X509_NAME_ENTRY *e; -\& -\& for (;;) { -\& lastpos = X509_NAME_get_index_by_NID(nm, NID_commonName, lastpos); -\& if (lastpos == \-1) -\& break; -\& e = X509_NAME_get_entry(nm, lastpos); -\& /* Do something with e */ -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBd2i_X509_NAME\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_NAME_get_index_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_NAME_get_index_by_OBJ.3ossl deleted file mode 120000 index 65acb784..00000000 --- a/openssl-install/share/man/man3/X509_NAME_get_index_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_get_index_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_get_text_by_NID.3ossl b/openssl-install/share/man/man3/X509_NAME_get_text_by_NID.3ossl deleted file mode 120000 index 65acb784..00000000 --- a/openssl-install/share/man/man3/X509_NAME_get_text_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_get_index_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_get_text_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_NAME_get_text_by_OBJ.3ossl deleted file mode 120000 index 65acb784..00000000 --- a/openssl-install/share/man/man3/X509_NAME_get_text_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_get_index_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_hash.3ossl b/openssl-install/share/man/man3/X509_NAME_hash.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_NAME_hash.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_hash_ex.3ossl b/openssl-install/share/man/man3/X509_NAME_hash_ex.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_NAME_hash_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_new.3ossl b/openssl-install/share/man/man3/X509_NAME_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_NAME_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_oneline.3ossl b/openssl-install/share/man/man3/X509_NAME_oneline.3ossl deleted file mode 120000 index 6bd86cbf..00000000 --- a/openssl-install/share/man/man3/X509_NAME_oneline.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_print_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_print.3ossl b/openssl-install/share/man/man3/X509_NAME_print.3ossl deleted file mode 120000 index 6bd86cbf..00000000 --- a/openssl-install/share/man/man3/X509_NAME_print.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_print_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_NAME_print_ex.3ossl b/openssl-install/share/man/man3/X509_NAME_print_ex.3ossl deleted file mode 100644 index 237c9bf9..00000000 --- a/openssl-install/share/man/man3/X509_NAME_print_ex.3ossl +++ /dev/null @@ -1,263 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_NAME_PRINT_EX 3ossl" -.TH X509_NAME_PRINT_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_NAME_print_ex, X509_NAME_print_ex_fp, X509_NAME_print, -X509_NAME_oneline \- X509_NAME printing routines -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_NAME_print_ex(BIO *out, const X509_NAME *nm, -\& int indent, unsigned long flags); -\& int X509_NAME_print_ex_fp(FILE *fp, const X509_NAME *nm, -\& int indent, unsigned long flags); -\& char *X509_NAME_oneline(const X509_NAME *a, char *buf, int size); -\& int X509_NAME_print(BIO *bp, const X509_NAME *name, int obase); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_NAME_print_ex()\fR prints a human readable version of \fInm\fR to \s-1BIO\s0 \fIout\fR. -Each line (for multiline formats) is indented by \fIindent\fR spaces. The -output format can be extensively customised by use of the \fIflags\fR parameter. -.PP -\&\fBX509_NAME_print_ex_fp()\fR is identical to \fBX509_NAME_print_ex()\fR -except the output is written to \s-1FILE\s0 pointer \fIfp\fR. -.PP -\&\fBX509_NAME_oneline()\fR prints an \s-1ASCII\s0 version of \fIa\fR to \fIbuf\fR. -This supports multi-valued RDNs and escapes \fB/\fR and \fB+\fR characters in values. -If \fIbuf\fR is \fB\s-1NULL\s0\fR then a buffer is dynamically allocated and returned, and -\&\fIsize\fR is ignored. -Otherwise, at most \fIsize\fR bytes will be written, including the ending '\e0', -and \fIbuf\fR is returned. -.PP -\&\fBX509_NAME_print()\fR prints out \fIname\fR to \fIbp\fR indenting each line by \fIobase\fR -characters. Multiple lines are used if the output (including indent) exceeds -80 characters. -.SH "NOTES" -.IX Header "NOTES" -The functions \fBX509_NAME_oneline()\fR and \fBX509_NAME_print()\fR -produce a non standard output form, they don't handle multi-character fields and -have various quirks and inconsistencies. -Their use is strongly discouraged in new applications and they could -be deprecated in a future release. -.PP -Although there are a large number of possible flags for most purposes -\&\fB\s-1XN_FLAG_ONELINE\s0\fR, \fB\s-1XN_FLAG_MULTILINE\s0\fR or \fB\s-1XN_FLAG_RFC2253\s0\fR will suffice. -As noted on the \fBASN1_STRING_print_ex\fR\|(3) manual page -for \s-1UTF8\s0 terminals the \fB\s-1ASN1_STRFLGS_ESC_MSB\s0\fR should be unset: so for example -\&\fB\s-1XN_FLAG_ONELINE &\s0 ~ASN1_STRFLGS_ESC_MSB\fR would be used. -.PP -The complete set of the flags supported by \fBX509_NAME_print_ex()\fR is listed below. -.PP -Several options can be ored together. -.PP -The options \fB\s-1XN_FLAG_SEP_COMMA_PLUS\s0\fR, \fB\s-1XN_FLAG_SEP_CPLUS_SPC\s0\fR, -\&\fB\s-1XN_FLAG_SEP_SPLUS_SPC\s0\fR and \fB\s-1XN_FLAG_SEP_MULTILINE\s0\fR -determine the field separators to use. -Two distinct separators are used between distinct RelativeDistinguishedName -components and separate values in the same \s-1RDN\s0 for a multi-valued \s-1RDN.\s0 -Multi-valued RDNs are currently very rare -so the second separator will hardly ever be used. -.PP -\&\fB\s-1XN_FLAG_SEP_COMMA_PLUS\s0\fR uses comma and plus as separators. -\&\fB\s-1XN_FLAG_SEP_CPLUS_SPC\s0\fR uses comma and plus with spaces: -this is more readable that plain comma and plus. -\&\fB\s-1XN_FLAG_SEP_SPLUS_SPC\s0\fR uses spaced semicolon and plus. -\&\fB\s-1XN_FLAG_SEP_MULTILINE\s0\fR uses spaced newline and plus respectively. -.PP -If \fB\s-1XN_FLAG_DN_REV\s0\fR is set the whole \s-1DN\s0 is printed in reversed order. -.PP -The fields \fB\s-1XN_FLAG_FN_SN\s0\fR, \fB\s-1XN_FLAG_FN_LN\s0\fR, \fB\s-1XN_FLAG_FN_OID\s0\fR, -\&\fB\s-1XN_FLAG_FN_NONE\s0\fR determine how a field name is displayed. It will -use the short name (e.g. \s-1CN\s0) the long name (e.g. commonName) always -use \s-1OID\s0 numerical form (normally OIDs are only used if the field name is not -recognised) and no field name respectively. -.PP -If \fB\s-1XN_FLAG_SPC_EQ\s0\fR is set then spaces will be placed around the '=' character -separating field names and values. -.PP -If \fB\s-1XN_FLAG_DUMP_UNKNOWN_FIELDS\s0\fR is set then the encoding of unknown fields is -printed instead of the values. -.PP -If \fB\s-1XN_FLAG_FN_ALIGN\s0\fR is set then field names are padded to 20 characters: this -is only of use for multiline format. -.PP -Additionally all the options supported by \fBASN1_STRING_print_ex()\fR can be used to -control how each field value is displayed. -.PP -In addition a number options can be set for commonly used formats. -.PP -\&\fB\s-1XN_FLAG_RFC2253\s0\fR sets options which produce an output compatible with \s-1RFC2253.\s0 -It is equivalent to: - \f(CW\*(C`ASN1_STRFLGS_RFC2253 | XN_FLAG_SEP_COMMA_PLUS | XN_FLAG_DN_REV - | XN_FLAG_FN_SN | XN_FLAG_DUMP_UNKNOWN_FIELDS\*(C'\fR -.PP -\&\fB\s-1XN_FLAG_ONELINE\s0\fR is a more readable one line format which is the same as: - \f(CW\*(C`ASN1_STRFLGS_RFC2253 | ASN1_STRFLGS_ESC_QUOTE | XN_FLAG_SEP_CPLUS_SPC - | XN_FLAG_SPC_EQ | XN_FLAG_FN_SN\*(C'\fR -.PP -\&\fB\s-1XN_FLAG_MULTILINE\s0\fR is a multiline format which is the same as: - \f(CW\*(C`ASN1_STRFLGS_ESC_CTRL | ASN1_STRFLGS_ESC_MSB | XN_FLAG_SEP_MULTILINE - | XN_FLAG_SPC_EQ | XN_FLAG_FN_LN | XN_FLAG_FN_ALIGN\*(C'\fR -.PP -\&\fB\s-1XN_FLAG_COMPAT\s0\fR uses a format identical to \fBX509_NAME_print()\fR: -in fact it calls \fBX509_NAME_print()\fR internally. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_NAME_oneline()\fR returns a valid string on success or \s-1NULL\s0 on error. -.PP -\&\fBX509_NAME_print()\fR returns 1 on success or 0 on error. -.PP -\&\fBX509_NAME_print_ex()\fR and \fBX509_NAME_print_ex_fp()\fR return 1 on success or 0 on -error if the \fB\s-1XN_FLAG_COMPAT\s0\fR is set, which is the same as \fBX509_NAME_print()\fR. -Otherwise, it returns \-1 on error or other values on success. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBASN1_STRING_print_ex\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_NAME_print_ex_fp.3ossl b/openssl-install/share/man/man3/X509_NAME_print_ex_fp.3ossl deleted file mode 120000 index 6bd86cbf..00000000 --- a/openssl-install/share/man/man3/X509_NAME_print_ex_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_NAME_print_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_OBJECT_set1_X509.3ossl b/openssl-install/share/man/man3/X509_OBJECT_set1_X509.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_OBJECT_set1_X509.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_OBJECT_set1_X509_CRL.3ossl b/openssl-install/share/man/man3/X509_OBJECT_set1_X509_CRL.3ossl deleted file mode 120000 index 0612def5..00000000 --- a/openssl-install/share/man/man3/X509_OBJECT_set1_X509_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_meth_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_dup.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_dup.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_eq.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_eq.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_eq.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_free.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_free.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_get.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_get.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_get0.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_get0.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_get0.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_get0_param.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_get0_param.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_get0_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_new.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_new.3ossl deleted file mode 100644 index 8b279a84..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_new.3ossl +++ /dev/null @@ -1,310 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_PUBKEY_NEW 3ossl" -.TH X509_PUBKEY_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_PUBKEY_new_ex, X509_PUBKEY_new, X509_PUBKEY_free, X509_PUBKEY_dup, -X509_PUBKEY_set, X509_PUBKEY_get0, X509_PUBKEY_get, -d2i_PUBKEY_ex, d2i_PUBKEY, i2d_PUBKEY, d2i_PUBKEY_ex_bio, d2i_PUBKEY_bio, -d2i_PUBKEY_ex_fp, d2i_PUBKEY_fp, i2d_PUBKEY_fp, i2d_PUBKEY_bio, -X509_PUBKEY_set0_public_key, X509_PUBKEY_set0_param, X509_PUBKEY_get0_param, -X509_PUBKEY_eq \- SubjectPublicKeyInfo public key functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_PUBKEY *X509_PUBKEY_new_ex(OSSL_LIB_CTX *libctx, const char *propq); -\& X509_PUBKEY *X509_PUBKEY_new(void); -\& void X509_PUBKEY_free(X509_PUBKEY *a); -\& X509_PUBKEY *X509_PUBKEY_dup(const X509_PUBKEY *a); -\& -\& int X509_PUBKEY_set(X509_PUBKEY **x, EVP_PKEY *pkey); -\& EVP_PKEY *X509_PUBKEY_get0(const X509_PUBKEY *key); -\& EVP_PKEY *X509_PUBKEY_get(const X509_PUBKEY *key); -\& -\& EVP_PKEY *d2i_PUBKEY_ex(EVP_PKEY **a, const unsigned char **pp, long length, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& EVP_PKEY *d2i_PUBKEY(EVP_PKEY **a, const unsigned char **pp, long length); -\& int i2d_PUBKEY(const EVP_PKEY *a, unsigned char **pp); -\& -\& EVP_PKEY *d2i_PUBKEY_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& EVP_PKEY *d2i_PUBKEY_bio(BIO *bp, EVP_PKEY **a); -\& -\& EVP_PKEY *d2i_PUBKEY_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& EVP_PKEY *d2i_PUBKEY_fp(FILE *fp, EVP_PKEY **a); -\& -\& int i2d_PUBKEY_fp(const FILE *fp, EVP_PKEY *pkey); -\& int i2d_PUBKEY_bio(BIO *bp, const EVP_PKEY *pkey); -\& -\& void X509_PUBKEY_set0_public_key(X509_PUBKEY *pub, -\& unsigned char *penc, int penclen); -\& int X509_PUBKEY_set0_param(X509_PUBKEY *pub, ASN1_OBJECT *aobj, -\& int ptype, void *pval, -\& unsigned char *penc, int penclen); -\& int X509_PUBKEY_get0_param(ASN1_OBJECT **ppkalg, -\& const unsigned char **pk, int *ppklen, -\& X509_ALGOR **pa, const X509_PUBKEY *pub); -\& int X509_PUBKEY_eq(X509_PUBKEY *a, X509_PUBKEY *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX509_PUBKEY\fR structure represents the \s-1ASN.1\s0 \fBSubjectPublicKeyInfo\fR -structure defined in \s-1RFC5280\s0 and used in certificates and certificate requests. -.PP -\&\fBX509_PUBKEY_new_ex()\fR allocates and initializes an \fBX509_PUBKEY\fR structure -associated with the given \fB\s-1OSSL_LIB_CTX\s0\fR in the \fIlibctx\fR parameter. Any -algorithm fetches associated with using the \fBX509_PUBKEY\fR object will use -the property query string \fIpropq\fR. See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7) for -further information about algorithm fetching. -.PP -\&\fBX509_PUBKEY_new()\fR is the same as \fBX509_PUBKEY_new_ex()\fR except that the default -(\s-1NULL\s0) \fB\s-1OSSL_LIB_CTX\s0\fR and a \s-1NULL\s0 property query string are used. -.PP -\&\fBX509_PUBKEY_dup()\fR creates a duplicate copy of the \fBX509_PUBKEY\fR object -specified by \fIa\fR. -.PP -\&\fBX509_PUBKEY_free()\fR frees up \fBX509_PUBKEY\fR structure \fIa\fR. If \fIa\fR is \s-1NULL\s0 -nothing is done. -.PP -\&\fBX509_PUBKEY_set()\fR sets the public key in \fI*x\fR to the public key contained -in the \fB\s-1EVP_PKEY\s0\fR structure \fIpkey\fR. If \fI*x\fR is not \s-1NULL\s0 any existing -public key structure will be freed. -.PP -\&\fBX509_PUBKEY_get0()\fR returns the public key contained in \fIkey\fR. The returned -value is an internal pointer which \fB\s-1MUST NOT\s0\fR be freed after use. -.PP -\&\fBX509_PUBKEY_get()\fR is similar to \fBX509_PUBKEY_get0()\fR except the reference -count on the returned key is incremented so it \fB\s-1MUST\s0\fR be freed using -\&\fBEVP_PKEY_free()\fR after use. -.PP -\&\fBd2i_PUBKEY_ex()\fR decodes an \fB\s-1EVP_PKEY\s0\fR structure using \fBSubjectPublicKeyInfo\fR -format. Some public key decoding implementations may use cryptographic -algorithms. In this case the supplied library context \fIlibctx\fR and property -query string \fIpropq\fR are used. -\&\fBd2i_PUBKEY()\fR does the same as \fBd2i_PUBKEY_ex()\fR except that the default -library context and property query string are used. -.PP -\&\fBi2d_PUBKEY()\fR encodes an \fB\s-1EVP_PKEY\s0\fR structure using \fBSubjectPublicKeyInfo\fR -format. -.PP -\&\fBd2i_PUBKEY_bio()\fR, \fBd2i_PUBKEY_fp()\fR, \fBi2d_PUBKEY_bio()\fR and \fBi2d_PUBKEY_fp()\fR are -similar to \fBd2i_PUBKEY()\fR and \fBi2d_PUBKEY()\fR except they decode or encode using a -\&\fB\s-1BIO\s0\fR or \fB\s-1FILE\s0\fR pointer. -.PP -\&\fBd2i_PUBKEY_ex_bio()\fR and \fBd2i_PUBKEY_ex_fp()\fR are similar to \fBd2i_PUBKEY_ex()\fR except -they decode using a \fB\s-1BIO\s0\fR or \fB\s-1FILE\s0\fR pointer. -.PP -\&\fBX509_PUBKEY_set0_public_key()\fR sets the public-key encoding of \fIpub\fR -to the \fIpenclen\fR bytes contained in buffer \fIpenc\fR. -Any earlier public-key encoding in \fIpub\fR is freed. -\&\fIpenc\fR may be \s-1NULL\s0 to indicate that there is no actual public key data. -Ownership of the \fIpenc\fR argument is passed to \fIpub\fR. -.PP -\&\fBX509_PUBKEY_set0_param()\fR sets the public-key parameters of \fIpub\fR. -The \s-1OID\s0 associated with the algorithm is set to \fIaobj\fR. The type of the -algorithm parameters is set to \fItype\fR using the structure \fIpval\fR. -If \fIpenc\fR is not \s-1NULL\s0 the encoding of the public key itself is set -to the \fIpenclen\fR bytes contained in buffer \fIpenc\fR and -any earlier public-key encoding in \fIpub\fR is freed. -On success ownership of all the supplied arguments is passed to \fIpub\fR -so they must not be freed after the call. -.PP -\&\fBX509_PUBKEY_get0_param()\fR retrieves the public key parameters from \fIpub\fR, -\&\fI*ppkalg\fR is set to the associated \s-1OID\s0 and the encoding consists of -\&\fI*ppklen\fR bytes at \fI*pk\fR, \fI*pa\fR is set to the associated -AlgorithmIdentifier for the public key. If the value of any of these -parameters is not required it can be set to \s-1NULL.\s0 All of the -retrieved pointers are internal and must not be freed after the -call. -.PP -\&\fBX509_PUBKEY_eq()\fR compares two \fBX509_PUBKEY\fR values. -.SH "NOTES" -.IX Header "NOTES" -The \fBX509_PUBKEY\fR functions can be used to encode and decode public keys -in a standard format. -.PP -In many cases applications will not call the \fBX509_PUBKEY\fR functions -directly: they will instead call wrapper functions such as \fBX509_get0_pubkey()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBX509_PUBKEY_new()\fR and \fBX509_PUBKEY_dup()\fR return -\&\s-1NULL\s0 and set an error code that can be obtained by \fBERR_get_error\fR\|(3). -Otherwise they return a pointer to the newly allocated structure. -.PP -\&\fBX509_PUBKEY_free()\fR does not return a value. -.PP -\&\fBX509_PUBKEY_get0()\fR, \fBX509_PUBKEY_get()\fR, \fBd2i_PUBKEY_ex()\fR, \fBd2i_PUBKEY()\fR, -\&\fBd2i_PUBKEY_ex_bio()\fR, \fBd2i_PUBKEY_bio()\fR, \fBd2i_PUBKEY_ex_fp()\fR and \fBd2i_PUBKEY_fp()\fR -return a pointer to an \fB\s-1EVP_PKEY\s0\fR structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBi2d_PUBKEY()\fR returns the number of bytes successfully encoded or a -negative value if an error occurs. -.PP -\&\fBi2d_PUBKEY_fp()\fR and \fBi2d_PUBKEY_bio()\fR return 1 if successfully -encoded or 0 if an error occurs. -.PP -\&\fBX509_PUBKEY_set0_public_key()\fR does not return a value. -.PP -\&\fBX509_PUBKEY_set()\fR, \fBX509_PUBKEY_set0_param()\fR and \fBX509_PUBKEY_get0_param()\fR -return 1 for success and 0 if an error occurred. -.PP -\&\fBX509_PUBKEY_eq()\fR returns 1 for equal, 0 for different, and < 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_PUBKEY_new_ex()\fR and \fBX509_PUBKEY_eq()\fR functions were added in OpenSSL -3.0. -.PP -The \fBX509_PUBKEY_set0_public_key()\fR, \fBd2i_PUBKEY_ex_bio()\fR and \fBd2i_PUBKEY_ex_fp()\fR -functions were added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_PUBKEY_new_ex.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_new_ex.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_set.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_set.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_set0_param.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_set0_param.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_set0_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_PUBKEY_set0_public_key.3ossl b/openssl-install/share/man/man3/X509_PUBKEY_set0_public_key.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/X509_PUBKEY_set0_public_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_INFO_free.3ossl b/openssl-install/share/man/man3/X509_REQ_INFO_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_INFO_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_INFO_new.3ossl b/openssl-install/share/man/man3/X509_REQ_INFO_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_INFO_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_add1_attr.3ossl b/openssl-install/share/man/man3/X509_REQ_add1_attr.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_add1_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/X509_REQ_add1_attr_by_NID.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_add1_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_add1_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_REQ_add1_attr_by_OBJ.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_add1_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_add1_attr_by_txt.3ossl b/openssl-install/share/man/man3/X509_REQ_add1_attr_by_txt.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_add1_attr_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_add_extensions.3ossl b/openssl-install/share/man/man3/X509_REQ_add_extensions.3ossl deleted file mode 120000 index 9650ffdc..00000000 --- a/openssl-install/share/man/man3/X509_REQ_add_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_extensions.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_add_extensions_nid.3ossl b/openssl-install/share/man/man3/X509_REQ_add_extensions_nid.3ossl deleted file mode 120000 index 9650ffdc..00000000 --- a/openssl-install/share/man/man3/X509_REQ_add_extensions_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_extensions.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_check_private_key.3ossl b/openssl-install/share/man/man3/X509_REQ_check_private_key.3ossl deleted file mode 120000 index 44f5d1c0..00000000 --- a/openssl-install/share/man/man3/X509_REQ_check_private_key.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_check_private_key.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_delete_attr.3ossl b/openssl-install/share/man/man3/X509_REQ_delete_attr.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_delete_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_digest.3ossl b/openssl-install/share/man/man3/X509_REQ_digest.3ossl deleted file mode 120000 index c2b39912..00000000 --- a/openssl-install/share/man/man3/X509_REQ_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_digest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_dup.3ossl b/openssl-install/share/man/man3/X509_REQ_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_free.3ossl b/openssl-install/share/man/man3/X509_REQ_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get0_distinguishing_id.3ossl b/openssl-install/share/man/man3/X509_REQ_get0_distinguishing_id.3ossl deleted file mode 120000 index 8e2f6903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get0_distinguishing_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_distinguishing_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get0_pubkey.3ossl b/openssl-install/share/man/man3/X509_REQ_get0_pubkey.3ossl deleted file mode 120000 index b4c8dd7c..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get0_pubkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_pubkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get0_signature.3ossl b/openssl-install/share/man/man3/X509_REQ_get0_signature.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/X509_REQ_get_X509_PUBKEY.3ossl deleted file mode 120000 index b4c8dd7c..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_pubkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_attr.3ossl b/openssl-install/share/man/man3/X509_REQ_get_attr.3ossl deleted file mode 100644 index 372632cf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_attr.3ossl +++ /dev/null @@ -1,242 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_REQ_GET_ATTR 3ossl" -.TH X509_REQ_GET_ATTR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_REQ_get_attr_count, -X509_REQ_get_attr_by_NID, X509_REQ_get_attr_by_OBJ, X509_REQ_get_attr, -X509_REQ_delete_attr, -X509_REQ_add1_attr, X509_REQ_add1_attr_by_OBJ, X509_REQ_add1_attr_by_NID, -X509_REQ_add1_attr_by_txt -\&\- X509_ATTRIBUTE support for signed certificate requests -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_REQ_get_attr_count(const X509_REQ *req); -\& int X509_REQ_get_attr_by_NID(const X509_REQ *req, int nid, int lastpos); -\& int X509_REQ_get_attr_by_OBJ(const X509_REQ *req, const ASN1_OBJECT *obj, -\& int lastpos); -\& X509_ATTRIBUTE *X509_REQ_get_attr(const X509_REQ *req, int loc); -\& X509_ATTRIBUTE *X509_REQ_delete_attr(X509_REQ *req, int loc); -\& int X509_REQ_add1_attr(X509_REQ *req, X509_ATTRIBUTE *attr); -\& int X509_REQ_add1_attr_by_OBJ(X509_REQ *req, -\& const ASN1_OBJECT *obj, int type, -\& const unsigned char *bytes, int len); -\& int X509_REQ_add1_attr_by_NID(X509_REQ *req, -\& int nid, int type, -\& const unsigned char *bytes, int len); -\& int X509_REQ_add1_attr_by_txt(X509_REQ *req, -\& const char *attrname, int type, -\& const unsigned char *bytes, int len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_REQ_get_attr_by_OBJ()\fR finds the location of the first matching object \fIobj\fR -in the \fIreq\fR attribute list. The search starts at the position after \fIlastpos\fR. -If the returned value is positive then it can be used on the next call to -\&\fBX509_REQ_get_attr_by_OBJ()\fR as the value of \fIlastpos\fR in order to iterate through -the remaining attributes. \fIlastpos\fR can be set to any negative value on the -first call, in order to start searching from the start of the attribute list. -.PP -\&\fBX509_REQ_get_attr_by_NID()\fR is similar to \fBX509_REQ_get_attr_by_OBJ()\fR except that -it passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBX509_REQ_get_attr()\fR returns the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in the -\&\fIreq\fR attribute list. \fIloc\fR should be in the range from 0 to -\&\fBX509_REQ_get_attr_count()\fR \- 1. -.PP -\&\fBX509_REQ_delete_attr()\fR removes the \fBX509_ATTRIBUTE\fR object at index \fIloc\fR in -the \fIreq\fR objects list of attributes. An error occurs if \fIreq\fR is \s-1NULL.\s0 -.PP -\&\fBX509_REQ_add1_attr()\fR pushes a copy of the passed in \fBX509_ATTRIBUTE\fR \fI\fRattr> -to the \fIreq\fR object's attribute list. An error will occur if either the -attribute list is \s-1NULL\s0 or the attribute already exists. -.PP -\&\fBX509_REQ_add1_attr_by_OBJ()\fR creates a new \fBX509_ATTRIBUTE\fR using -\&\fBX509_ATTRIBUTE_set1_object()\fR and \fBX509_ATTRIBUTE_set1_data()\fR to assign a new -\&\fIobj\fR with type \fItype\fR and data \fIbytes\fR of length \fIlen\fR and then pushes it -to the \fIreq\fR object's attribute list. \fIreq\fR must be non \s-1NULL\s0 or an error -will occur. If \fIobj\fR already exists in the attribute list then an error occurs. -.PP -\&\fBX509_REQ_add1_attr_by_NID()\fR is similar to \fBX509_REQ_add1_attr_by_OBJ()\fR except -that it passes the numerical identifier (\s-1NID\s0) \fInid\fR associated with the object. -See for a list of NID_*. -.PP -\&\fBX509_REQ_add1_attr_by_txt()\fR is similar to \fBX509_REQ_add1_attr_by_OBJ()\fR except -that it passes a name \fIattrname\fR associated with the object. -See for a list of SN_* names. -.PP -Refer to \fBX509_ATTRIBUTE\fR\|(3) for information related to attributes. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_REQ_get_attr_count()\fR returns the number of attributes in the \fIreq\fR object -attribute list or \-1 if the attribute list is \s-1NULL.\s0 -.PP -\&\fBX509_REQ_get_attr_by_OBJ()\fR returns \-1 if either the \fIreq\fR object's attribute -list is empty \s-1OR\s0 \fIobj\fR is not found, otherwise it returns the location of the -\&\fIobj\fR in the attribute list. -.PP -\&\fBX509_REQ_get_attr_by_NID()\fR is similar to \fBX509_REQ_get_attr_by_OBJ()\fR, except that -it returns \-2 if the \fInid\fR is not known by OpenSSL. -.PP -\&\fBX509_REQ_get_attr()\fR returns either an \fBX509_ATTRIBUTE\fR or \s-1NULL\s0 on error. -.PP -\&\fBX509_REQ_delete_attr()\fR returns either the removed \fBX509_ATTRIBUTE\fR or \s-1NULL\s0 if -there is a error. -.PP -\&\fBX509_REQ_add1_attr()\fR, \fBX509_REQ_add1_attr_by_OBJ()\fR, \fBX509_REQ_add1_attr_by_NID()\fR -and \fBX509_REQ_add1_attr_by_txt()\fR return 1 on success or 0 on error. -.SH "NOTES" -.IX Header "NOTES" -Any functions that modify the attributes (add or delete) internally set a flag -to indicate the \s-1ASN.1\s0 encoding has been modified. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_ATTRIBUTE\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_REQ_get_attr_by_NID.3ossl b/openssl-install/share/man/man3/X509_REQ_get_attr_by_NID.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_REQ_get_attr_by_OBJ.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_attr_count.3ossl b/openssl-install/share/man/man3/X509_REQ_get_attr_count.3ossl deleted file mode 120000 index c633adcf..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_attr_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_REQ_get_attr.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_extensions.3ossl b/openssl-install/share/man/man3/X509_REQ_get_extensions.3ossl deleted file mode 100644 index 6ab09643..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_extensions.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_REQ_GET_EXTENSIONS 3ossl" -.TH X509_REQ_GET_EXTENSIONS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_REQ_get_extensions, -X509_REQ_add_extensions, X509_REQ_add_extensions_nid -\&\- handle X.509 extension attributes of a CSR -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(X509_EXTENSION) *X509_REQ_get_extensions(const X509_REQ *req); -\& int X509_REQ_add_extensions(X509_REQ *req, const STACK_OF(X509_EXTENSION) *exts); -\& int X509_REQ_add_extensions_nid(X509_REQ *req, -\& const STACK_OF(X509_EXTENSION) *exts, int nid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_REQ_get_extensions()\fR returns the first list of X.509 extensions -found in the attributes of \fIreq\fR. -The returned list is empty if there are no such extensions in \fIreq\fR. -The caller is responsible for freeing the list obtained. -.PP -\&\fBX509_REQ_add_extensions_nid()\fR adds to \fIreq\fR a list of X.509 extensions \fIexts\fR, -using \fInid\fR to identify the extensions attribute. -\&\fIreq\fR is unchanged if \fIexts\fR is \s-1NULL\s0 or an empty list. -This function may be called more than once on the same \fIreq\fR and \fInid\fR. -In such case any previous extensions are augmented, where an extension to be -added that has the same \s-1OID\s0 as a pre-existing one replaces this earlier one. -.PP -\&\fBX509_REQ_add_extensions()\fR is like \fBX509_REQ_add_extensions_nid()\fR -except that the default \fBNID_ext_req\fR is used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_REQ_get_extensions()\fR returns a pointer to \fB\s-1STACK_OF\s0(X509_EXTENSION)\fR -or \s-1NULL\s0 on error. -.PP -\&\fBX509_REQ_add_extensions()\fR and \fBX509_REQ_add_extensions_nid()\fR -return 1 on success, 0 on error. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_REQ_get_pubkey.3ossl b/openssl-install/share/man/man3/X509_REQ_get_pubkey.3ossl deleted file mode 120000 index b4c8dd7c..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_pubkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_pubkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_signature_nid.3ossl b/openssl-install/share/man/man3/X509_REQ_get_signature_nid.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_signature_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_subject_name.3ossl b/openssl-install/share/man/man3/X509_REQ_get_subject_name.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_subject_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_get_version.3ossl b/openssl-install/share/man/man3/X509_REQ_get_version.3ossl deleted file mode 120000 index 6a7e2ebc..00000000 --- a/openssl-install/share/man/man3/X509_REQ_get_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_new.3ossl b/openssl-install/share/man/man3/X509_REQ_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_new_ex.3ossl b/openssl-install/share/man/man3/X509_REQ_new_ex.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_set0_distinguishing_id.3ossl b/openssl-install/share/man/man3/X509_REQ_set0_distinguishing_id.3ossl deleted file mode 120000 index 8e2f6903..00000000 --- a/openssl-install/share/man/man3/X509_REQ_set0_distinguishing_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_distinguishing_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_set0_signature.3ossl b/openssl-install/share/man/man3/X509_REQ_set0_signature.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_REQ_set0_signature.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_set1_signature_algo.3ossl b/openssl-install/share/man/man3/X509_REQ_set1_signature_algo.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_REQ_set1_signature_algo.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_set_pubkey.3ossl b/openssl-install/share/man/man3/X509_REQ_set_pubkey.3ossl deleted file mode 120000 index b4c8dd7c..00000000 --- a/openssl-install/share/man/man3/X509_REQ_set_pubkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_pubkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_set_subject_name.3ossl b/openssl-install/share/man/man3/X509_REQ_set_subject_name.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_REQ_set_subject_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_set_version.3ossl b/openssl-install/share/man/man3/X509_REQ_set_version.3ossl deleted file mode 120000 index 6a7e2ebc..00000000 --- a/openssl-install/share/man/man3/X509_REQ_set_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_sign.3ossl b/openssl-install/share/man/man3/X509_REQ_sign.3ossl deleted file mode 120000 index 9080e9e2..00000000 --- a/openssl-install/share/man/man3/X509_REQ_sign.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_sign_ctx.3ossl b/openssl-install/share/man/man3/X509_REQ_sign_ctx.3ossl deleted file mode 120000 index 9080e9e2..00000000 --- a/openssl-install/share/man/man3/X509_REQ_sign_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_verify.3ossl b/openssl-install/share/man/man3/X509_REQ_verify.3ossl deleted file mode 120000 index 81904cb5..00000000 --- a/openssl-install/share/man/man3/X509_REQ_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REQ_verify_ex.3ossl b/openssl-install/share/man/man3/X509_REQ_verify_ex.3ossl deleted file mode 120000 index 81904cb5..00000000 --- a/openssl-install/share/man/man3/X509_REQ_verify_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_add1_ext_i2d.3ossl b/openssl-install/share/man/man3/X509_REVOKED_add1_ext_i2d.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_add1_ext_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_add_ext.3ossl b/openssl-install/share/man/man3/X509_REVOKED_add_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_add_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_delete_ext.3ossl b/openssl-install/share/man/man3/X509_REVOKED_delete_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_delete_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_dup.3ossl b/openssl-install/share/man/man3/X509_REVOKED_dup.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_free.3ossl b/openssl-install/share/man/man3/X509_REVOKED_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get0_extensions.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get0_extensions.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get0_revocationDate.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get0_revocationDate.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get0_revocationDate.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get0_serialNumber.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get0_serialNumber.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get0_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get_ext.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_NID.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_NID.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_OBJ.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_critical.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_critical.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get_ext_by_critical.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get_ext_count.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get_ext_count.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get_ext_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_get_ext_d2i.3ossl b/openssl-install/share/man/man3/X509_REVOKED_get_ext_d2i.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_get_ext_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_new.3ossl b/openssl-install/share/man/man3/X509_REVOKED_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_set_revocationDate.3ossl b/openssl-install/share/man/man3/X509_REVOKED_set_revocationDate.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_set_revocationDate.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_REVOKED_set_serialNumber.3ossl b/openssl-install/share/man/man3/X509_REVOKED_set_serialNumber.3ossl deleted file mode 120000 index 3df24d63..00000000 --- a/openssl-install/share/man/man3/X509_REVOKED_set_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_CRL_get0_by_serial.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_SIG_INFO_get.3ossl b/openssl-install/share/man/man3/X509_SIG_INFO_get.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_SIG_INFO_get.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_SIG_INFO_set.3ossl b/openssl-install/share/man/man3/X509_SIG_INFO_set.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_SIG_INFO_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_SIG_free.3ossl b/openssl-install/share/man/man3/X509_SIG_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_SIG_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_SIG_get0.3ossl b/openssl-install/share/man/man3/X509_SIG_get0.3ossl deleted file mode 100644 index 26570bb1..00000000 --- a/openssl-install/share/man/man3/X509_SIG_get0.3ossl +++ /dev/null @@ -1,172 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_SIG_GET0 3ossl" -.TH X509_SIG_GET0 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_SIG_get0, X509_SIG_getm \- DigestInfo functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void X509_SIG_get0(const X509_SIG *sig, const X509_ALGOR **palg, -\& const ASN1_OCTET_STRING **pdigest); -\& void X509_SIG_getm(X509_SIG *sig, X509_ALGOR **palg, -\& ASN1_OCTET_STRING **pdigest); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_SIG_get0()\fR returns pointers to the algorithm identifier and digest -value in \fBsig\fR. \fBX509_SIG_getm()\fR is identical to \fBX509_SIG_get0()\fR -except the pointers returned are not constant and can be modified: -for example to initialise them. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_SIG_get0()\fR and \fBX509_SIG_getm()\fR return no values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_SIG_getm.3ossl b/openssl-install/share/man/man3/X509_SIG_getm.3ossl deleted file mode 120000 index 806bbf67..00000000 --- a/openssl-install/share/man/man3/X509_SIG_getm.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_SIG_get0.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_SIG_new.3ossl b/openssl-install/share/man/man3/X509_SIG_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_SIG_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE.3ossl b/openssl-install/share/man/man3/X509_STORE.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_cert_crl_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_cert_crl_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_cert_crl_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_check_crl_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_check_crl_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_check_crl_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_check_issued_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_check_issued_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_check_issued_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_check_policy_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_check_policy_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_check_policy_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_check_revocation_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_check_revocation_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_check_revocation_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_cleanup.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_cleanup.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_cleanup_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_cleanup_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_cleanup_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_free.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_free.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get0_cert.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get0_cert.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get0_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get0_chain.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get0_chain.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get0_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get0_param.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get0_param.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get0_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get0_rpk.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get0_rpk.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get0_rpk.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get0_untrusted.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get0_untrusted.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get0_untrusted.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get1_chain.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get1_chain.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get1_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get1_issuer.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get1_issuer.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get1_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_app_data.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_by_subject.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_by_subject.3ossl deleted file mode 100644 index 3a5bc9b7..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_by_subject.3ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_CTX_GET_BY_SUBJECT 3ossl" -.TH X509_STORE_CTX_GET_BY_SUBJECT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE_CTX_get_by_subject, -X509_STORE_CTX_get_obj_by_subject -\&\- X509 and X509_CRL lookup functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_STORE_CTX_get_by_subject(const X509_STORE_CTX *vs, -\& X509_LOOKUP_TYPE type, -\& const X509_NAME *name, X509_OBJECT *ret); -\& X509_OBJECT *X509_STORE_CTX_get_obj_by_subject(X509_STORE_CTX *vs, -\& X509_LOOKUP_TYPE type, -\& const X509_NAME *name); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_STORE_CTX_get_by_subject()\fR tries to find an object -of given \fItype\fR, which may be \fBX509_LU_X509\fR or \fBX509_LU_CRL\fR, -and subject \fIname\fR from the store in the provided store context \fIvs\fR. -If found and \fIret\fR is not \s-1NULL,\s0 it increments the reference count and -stores the looked up object in \fIret\fR. -.PP -\&\fBX509_STORE_CTX_get_obj_by_subject()\fR is like \fBX509_STORE_CTX_get_by_subject()\fR -but returns the found object on success, else \s-1NULL.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_STORE_CTX_get_by_subject()\fR returns 1 if the lookup was successful, else 0. -.PP -\&\fBX509_STORE_CTX_get_obj_by_subject()\fR returns an object on success, else \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_LOOKUP_meth_set_get_by_subject\fR\|(3), -\&\fBX509_LOOKUP_by_subject\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_cert_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_cert_crl.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_cert_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_check_crl.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_issued.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_check_issued.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_issued.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_policy.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_check_policy.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_policy.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_revocation.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_check_revocation.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_check_revocation.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_cleanup.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_cleanup.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_crl_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_crl_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_crl_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_current_cert.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_current_cert.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_current_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_error.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_error.3ossl deleted file mode 100644 index 8cd25919..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_error.3ossl +++ /dev/null @@ -1,532 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_CTX_GET_ERROR 3ossl" -.TH X509_STORE_CTX_GET_ERROR 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE_CTX_get_error, X509_STORE_CTX_set_error, -X509_STORE_CTX_get_error_depth, X509_STORE_CTX_set_error_depth, -X509_STORE_CTX_get_current_cert, X509_STORE_CTX_set_current_cert, -X509_STORE_CTX_get0_cert, X509_STORE_CTX_get1_chain, -X509_verify_cert_error_string \- get or set certificate verification status -information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_STORE_CTX_get_error(const X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_set_error(X509_STORE_CTX *ctx, int s); -\& int X509_STORE_CTX_get_error_depth(const X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_set_error_depth(X509_STORE_CTX *ctx, int depth); -\& X509 *X509_STORE_CTX_get_current_cert(const X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_set_current_cert(X509_STORE_CTX *ctx, X509 *x); -\& X509 *X509_STORE_CTX_get0_cert(const X509_STORE_CTX *ctx); -\& -\& STACK_OF(X509) *X509_STORE_CTX_get1_chain(const X509_STORE_CTX *ctx); -\& -\& const char *X509_verify_cert_error_string(long n); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions are typically called after certificate or chain verification -using \fBX509_verify_cert\fR\|(3) or \fBX509_STORE_CTX_verify\fR\|(3) has indicated -an error or in a verification callback to determine the nature of an error. -.PP -\&\fBX509_STORE_CTX_get_error()\fR returns the error code of \fIctx\fR. -See the \*(L"\s-1ERROR CODES\*(R"\s0 section for a full description of all error codes. -It may return a code != X509_V_OK even if \fBX509_verify_cert()\fR did not indicate -an error, likely because a verification callback function has waived the error. -.PP -\&\fBX509_STORE_CTX_set_error()\fR sets the error code of \fIctx\fR to \fIs\fR. For example -it might be used in a verification callback to set an error based on additional -checks. -.PP -\&\fBX509_STORE_CTX_get_error_depth()\fR returns the \fIdepth\fR of the error. This is a -nonnegative integer representing where in the certificate chain the error -occurred. If it is zero it occurred in the end entity certificate, one if -it is the certificate which signed the end entity certificate and so on. -.PP -\&\fBX509_STORE_CTX_set_error_depth()\fR sets the error \fIdepth\fR. -This can be used in combination with \fBX509_STORE_CTX_set_error()\fR to set the -depth at which an error condition was detected. -.PP -\&\fBX509_STORE_CTX_get_current_cert()\fR returns the current certificate in -\&\fIctx\fR. If an error occurred, the current certificate will be the one -that is most closely related to the error, or possibly \s-1NULL\s0 if no such -certificate is relevant. -.PP -\&\fBX509_STORE_CTX_set_current_cert()\fR sets the certificate \fIx\fR in \fIctx\fR which -caused the error. -This value is not intended to remain valid for very long, and remains owned by -the caller. -It may be examined by a verification callback invoked to handle each error -encountered during chain verification and is no longer required after such a -callback. -If a callback wishes the save the certificate for use after it returns, it -needs to increment its reference count via \fBX509_up_ref\fR\|(3). -Once such a \fIsaved\fR certificate is no longer needed it can be freed with -\&\fBX509_free\fR\|(3). -.PP -\&\fBX509_STORE_CTX_get0_cert()\fR retrieves an internal pointer to the -certificate being verified by the \fIctx\fR. It may be \s-1NULL\s0 if a raw public -key is being verified. -.PP -\&\fBX509_STORE_CTX_get1_chain()\fR returns a complete validate chain if a previous -verification is successful. Otherwise the returned chain may be incomplete or -invalid. The returned chain persists after the \fIctx\fR structure is freed. -When it is no longer needed it should be free up using: -.PP -.Vb 1 -\& OSSL_STACK_OF_X509_free(chain); -.Ve -.PP -\&\fBX509_verify_cert_error_string()\fR returns a human readable error string for -verification error \fIn\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_STORE_CTX_get_error()\fR returns \fBX509_V_OK\fR or an error code. -.PP -\&\fBX509_STORE_CTX_get_error_depth()\fR returns a nonnegative error depth. -.PP -\&\fBX509_STORE_CTX_get_current_cert()\fR returns the certificate which caused the -error or \s-1NULL\s0 if no certificate is relevant to the error. -.PP -\&\fBX509_verify_cert_error_string()\fR returns a human readable error string for -verification error \fIn\fR. -.SH "ERROR CODES" -.IX Header "ERROR CODES" -A list of error codes and messages is shown below. Some of the -error codes are defined but currently never returned: these are described as -\&\*(L"unused\*(R". -.IP "\fBX509_V_OK: ok\fR" 4 -.IX Item "X509_V_OK: ok" -The operation was successful. -.IP "\fBX509_V_ERR_UNSPECIFIED: unspecified certificate verification error\fR" 4 -.IX Item "X509_V_ERR_UNSPECIFIED: unspecified certificate verification error" -Unspecified error; should not happen. -.IP "\fBX509_V_ERR_UNABLE_TO_GET_ISSUER_CERT: unable to get issuer certificate\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT: unable to get issuer certificate" -The issuer certificate of a locally looked up certificate could not be found. -This normally means the list of trusted certificates is not complete. -To allow any certificate (not only a self-signed one) in the trust store -to terminate the chain the \fBX509_V_FLAG_PARTIAL_CHAIN\fR flag may be set. -.IP "\fBX509_V_ERR_UNABLE_TO_GET_CRL: unable to get certificate \s-1CRL\s0\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_GET_CRL: unable to get certificate CRL" -The \s-1CRL\s0 of a certificate could not be found. -.IP "\fBX509_V_ERR_UNABLE_TO_DECRYPT_CERT_SIGNATURE: unable to decrypt certificate's signature\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_DECRYPT_CERT_SIGNATURE: unable to decrypt certificate's signature" -The certificate signature could not be decrypted. This means that the actual -signature value could not be determined rather than it not matching the -expected value, this is only meaningful for \s-1RSA\s0 keys. -.IP "\fBX509_V_ERR_UNABLE_TO_DECRYPT_CRL_SIGNATURE: unable to decrypt \s-1CRL\s0's signature\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_DECRYPT_CRL_SIGNATURE: unable to decrypt CRL's signature" -The \s-1CRL\s0 signature could not be decrypted: this means that the actual signature -value could not be determined rather than it not matching the expected value. -Unused. -.IP "\fBX509_V_ERR_UNABLE_TO_DECODE_ISSUER_PUBLIC_KEY: unable to decode issuer public key\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_DECODE_ISSUER_PUBLIC_KEY: unable to decode issuer public key" -The public key in the certificate \f(CW\*(C`SubjectPublicKeyInfo\*(C'\fR field could -not be read. -.IP "\fBX509_V_ERR_CERT_SIGNATURE_FAILURE: certificate signature failure\fR" 4 -.IX Item "X509_V_ERR_CERT_SIGNATURE_FAILURE: certificate signature failure" -The signature of the certificate is invalid. -.IP "\fBX509_V_ERR_CRL_SIGNATURE_FAILURE: \s-1CRL\s0 signature failure\fR" 4 -.IX Item "X509_V_ERR_CRL_SIGNATURE_FAILURE: CRL signature failure" -The signature of the \s-1CRL\s0 is invalid. -.IP "\fBX509_V_ERR_CERT_NOT_YET_VALID: certificate is not yet valid\fR" 4 -.IX Item "X509_V_ERR_CERT_NOT_YET_VALID: certificate is not yet valid" -The certificate is not yet valid: the \f(CW\*(C`notBefore\*(C'\fR date is after the -current time. -.IP "\fBX509_V_ERR_CERT_HAS_EXPIRED: certificate has expired\fR" 4 -.IX Item "X509_V_ERR_CERT_HAS_EXPIRED: certificate has expired" -The certificate has expired: that is the \f(CW\*(C`notAfter\*(C'\fR date is before the -current time. -.IP "\fBX509_V_ERR_CRL_NOT_YET_VALID: \s-1CRL\s0 is not yet valid\fR" 4 -.IX Item "X509_V_ERR_CRL_NOT_YET_VALID: CRL is not yet valid" -The \s-1CRL\s0 is not yet valid. -.IP "\fBX509_V_ERR_CRL_HAS_EXPIRED: \s-1CRL\s0 has expired\fR" 4 -.IX Item "X509_V_ERR_CRL_HAS_EXPIRED: CRL has expired" -The \s-1CRL\s0 has expired. -.IP "\fBX509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD: format error in certificate's notBefore field\fR" 4 -.IX Item "X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD: format error in certificate's notBefore field" -The certificate \f(CW\*(C`notBefore\*(C'\fR field contains an invalid time. -.IP "\fBX509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD: format error in certificate's notAfter field\fR" 4 -.IX Item "X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD: format error in certificate's notAfter field" -The certificate \f(CW\*(C`notAfter\*(C'\fR field contains an invalid time. -.IP "\fBX509_V_ERR_ERROR_IN_CRL_LAST_UPDATE_FIELD: format error in \s-1CRL\s0's lastUpdate field\fR" 4 -.IX Item "X509_V_ERR_ERROR_IN_CRL_LAST_UPDATE_FIELD: format error in CRL's lastUpdate field" -The \s-1CRL\s0 \fBlastUpdate\fR field contains an invalid time. -.IP "\fBX509_V_ERR_ERROR_IN_CRL_NEXT_UPDATE_FIELD: format error in \s-1CRL\s0's nextUpdate field\fR" 4 -.IX Item "X509_V_ERR_ERROR_IN_CRL_NEXT_UPDATE_FIELD: format error in CRL's nextUpdate field" -The \s-1CRL\s0 \f(CW\*(C`nextUpdate\*(C'\fR field contains an invalid time. -.IP "\fBX509_V_ERR_OUT_OF_MEM: out of memory\fR" 4 -.IX Item "X509_V_ERR_OUT_OF_MEM: out of memory" -An error occurred trying to allocate memory. -.IP "\fBX509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT: self-signed certificate\fR" 4 -.IX Item "X509_V_ERR_DEPTH_ZERO_SELF_SIGNED_CERT: self-signed certificate" -The passed certificate is self-signed and the same certificate cannot be found -in the list of trusted certificates. -.IP "\fBX509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN: self-signed certificate in certificate chain\fR" 4 -.IX Item "X509_V_ERR_SELF_SIGNED_CERT_IN_CHAIN: self-signed certificate in certificate chain" -The certificate chain could be built up using the untrusted certificates -but no suitable trust anchor (which typically is a self-signed root certificate) -could be found in the trust store. -.IP "\fBX509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY: unable to get local issuer certificate\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY: unable to get local issuer certificate" -The issuer certificate could not be found: this occurs if the issuer certificate -of an untrusted certificate cannot be found. -.IP "\fBX509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE: unable to verify the first certificate\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_VERIFY_LEAF_SIGNATURE: unable to verify the first certificate" -No signatures could be verified because the chain contains only one certificate -and it is not self-signed and the \fBX509_V_FLAG_PARTIAL_CHAIN\fR flag is not set. -.IP "\fBX509_V_ERR_CERT_CHAIN_TOO_LONG: certificate chain too long\fR" 4 -.IX Item "X509_V_ERR_CERT_CHAIN_TOO_LONG: certificate chain too long" -The certificate chain length is greater than the supplied maximum depth. -.IP "\fBX509_V_ERR_CERT_REVOKED: certificate revoked\fR" 4 -.IX Item "X509_V_ERR_CERT_REVOKED: certificate revoked" -The certificate has been revoked. -.IP "\fBX509_V_ERR_NO_ISSUER_PUBLIC_KEY: issuer certificate doesn't have a public key\fR" 4 -.IX Item "X509_V_ERR_NO_ISSUER_PUBLIC_KEY: issuer certificate doesn't have a public key" -The issuer certificate does not have a public key. -.IP "\fBX509_V_ERR_PATH_LENGTH_EXCEEDED: path length constraint exceeded\fR" 4 -.IX Item "X509_V_ERR_PATH_LENGTH_EXCEEDED: path length constraint exceeded" -The basicConstraints path-length parameter has been exceeded. -.IP "\fBX509_V_ERR_INVALID_PURPOSE: unsuitable certificate purpose\fR" 4 -.IX Item "X509_V_ERR_INVALID_PURPOSE: unsuitable certificate purpose" -The target certificate cannot be used for the specified purpose. -.IP "\fBX509_V_ERR_CERT_UNTRUSTED: certificate not trusted\fR" 4 -.IX Item "X509_V_ERR_CERT_UNTRUSTED: certificate not trusted" -The root \s-1CA\s0 is not marked as trusted for the specified purpose. -.IP "\fBX509_V_ERR_CERT_REJECTED: certificate rejected\fR" 4 -.IX Item "X509_V_ERR_CERT_REJECTED: certificate rejected" -The root \s-1CA\s0 is marked to reject the specified purpose. -.IP "\fBX509_V_ERR_SUBJECT_ISSUER_MISMATCH: subject issuer mismatch\fR" 4 -.IX Item "X509_V_ERR_SUBJECT_ISSUER_MISMATCH: subject issuer mismatch" -The current candidate issuer certificate was rejected because its subject name -did not match the issuer name of the current certificate. -.IP "\fBX509_V_ERR_AKID_SKID_MISMATCH: authority and subject key identifier mismatch\fR" 4 -.IX Item "X509_V_ERR_AKID_SKID_MISMATCH: authority and subject key identifier mismatch" -The current candidate issuer certificate was rejected because its subject key -identifier was present and did not match the authority key identifier current -certificate. -.IP "\fBX509_V_ERR_AKID_ISSUER_SERIAL_MISMATCH: authority and issuer serial number mismatch\fR" 4 -.IX Item "X509_V_ERR_AKID_ISSUER_SERIAL_MISMATCH: authority and issuer serial number mismatch" -The current candidate issuer certificate was rejected because its issuer name -and serial number was present and did not match the authority key identifier of -the current certificate. -.IP "\fBX509_V_ERR_KEYUSAGE_NO_CERTSIGN: key usage does not include certificate signing\fR" 4 -.IX Item "X509_V_ERR_KEYUSAGE_NO_CERTSIGN: key usage does not include certificate signing" -The current candidate issuer certificate was rejected because its \f(CW\*(C`keyUsage\*(C'\fR -extension does not permit certificate signing. -.IP "\fBX509_V_ERR_UNABLE_TO_GET_CRL_ISSUER: unable to get \s-1CRL\s0 issuer certificate\fR" 4 -.IX Item "X509_V_ERR_UNABLE_TO_GET_CRL_ISSUER: unable to get CRL issuer certificate" -Unable to get \s-1CRL\s0 issuer certificate. -.IP "\fBX509_V_ERR_UNHANDLED_CRITICAL_EXTENSION: unhandled critical extension\fR" 4 -.IX Item "X509_V_ERR_UNHANDLED_CRITICAL_EXTENSION: unhandled critical extension" -Unhandled critical extension. -.IP "\fBX509_V_ERR_KEYUSAGE_NO_CRL_SIGN: key usage does not include \s-1CRL\s0 signing\fR" 4 -.IX Item "X509_V_ERR_KEYUSAGE_NO_CRL_SIGN: key usage does not include CRL signing" -Key usage does not include \s-1CRL\s0 signing. -.IP "\fBX509_V_ERR_UNHANDLED_CRITICAL_CRL_EXTENSION: unhandled critical \s-1CRL\s0 extension\fR" 4 -.IX Item "X509_V_ERR_UNHANDLED_CRITICAL_CRL_EXTENSION: unhandled critical CRL extension" -Unhandled critical \s-1CRL\s0 extension. -.IP "\fBX509_V_ERR_INVALID_NON_CA: invalid non-CA certificate (has \s-1CA\s0 markings)\fR" 4 -.IX Item "X509_V_ERR_INVALID_NON_CA: invalid non-CA certificate (has CA markings)" -Invalid non-CA certificate has \s-1CA\s0 markings. -.IP "\fBX509_V_ERR_PROXY_PATH_LENGTH_EXCEEDED: proxy path length constraint exceeded\fR" 4 -.IX Item "X509_V_ERR_PROXY_PATH_LENGTH_EXCEEDED: proxy path length constraint exceeded" -Proxy path length constraint exceeded. -.IP "\fBX509_V_ERR_KEYUSAGE_NO_DIGITAL_SIGNATURE: key usage does not include digital signature\fR" 4 -.IX Item "X509_V_ERR_KEYUSAGE_NO_DIGITAL_SIGNATURE: key usage does not include digital signature" -Key usage does not include digital signature, and therefore cannot sign -certificates. -.IP "\fBX509_V_ERR_PROXY_CERTIFICATES_NOT_ALLOWED: proxy certificates not allowed, please set the appropriate flag\fR" 4 -.IX Item "X509_V_ERR_PROXY_CERTIFICATES_NOT_ALLOWED: proxy certificates not allowed, please set the appropriate flag" -Proxy certificates not allowed unless the \fBX509_V_FLAG_ALLOW_PROXY_CERTS\fR flag -is set. -.IP "\fBX509_V_ERR_INVALID_EXTENSION: invalid or inconsistent certificate extension\fR" 4 -.IX Item "X509_V_ERR_INVALID_EXTENSION: invalid or inconsistent certificate extension" -A certificate extension had an invalid value (for example an incorrect -encoding) or some value inconsistent with other extensions. -.IP "\fBX509_V_ERR_INVALID_POLICY_EXTENSION: invalid or inconsistent certificate policy extension\fR" 4 -.IX Item "X509_V_ERR_INVALID_POLICY_EXTENSION: invalid or inconsistent certificate policy extension" -A certificate policies extension had an invalid value (for example an incorrect -encoding) or some value inconsistent with other extensions. This error only -occurs if policy processing is enabled. -.IP "\fBX509_V_ERR_NO_EXPLICIT_POLICY: no explicit policy\fR" 4 -.IX Item "X509_V_ERR_NO_EXPLICIT_POLICY: no explicit policy" -The verification flags were set to require and explicit policy but none was -present. -.IP "\fBX509_V_ERR_DIFFERENT_CRL_SCOPE: different \s-1CRL\s0 scope\fR" 4 -.IX Item "X509_V_ERR_DIFFERENT_CRL_SCOPE: different CRL scope" -The only CRLs that could be found did not match the scope of the certificate. -.IP "\fBX509_V_ERR_UNSUPPORTED_EXTENSION_FEATURE: unsupported extension feature\fR" 4 -.IX Item "X509_V_ERR_UNSUPPORTED_EXTENSION_FEATURE: unsupported extension feature" -Some feature of a certificate extension is not supported. Unused. -.IP "\fBX509_V_ERR_UNNESTED_RESOURCE: \s-1RFC 3779\s0 resource not subset of parent's resources\fR" 4 -.IX Item "X509_V_ERR_UNNESTED_RESOURCE: RFC 3779 resource not subset of parent's resources" -See \s-1RFC 3779\s0 for details. -.IP "\fBX509_V_ERR_PERMITTED_VIOLATION: permitted subtree violation\fR" 4 -.IX Item "X509_V_ERR_PERMITTED_VIOLATION: permitted subtree violation" -A name constraint violation occurred in the permitted subtrees. -.IP "\fBX509_V_ERR_EXCLUDED_VIOLATION: excluded subtree violation\fR" 4 -.IX Item "X509_V_ERR_EXCLUDED_VIOLATION: excluded subtree violation" -A name constraint violation occurred in the excluded subtrees. -.IP "\fBX509_V_ERR_SUBTREE_MINMAX: name constraints minimum and maximum not supported\fR" 4 -.IX Item "X509_V_ERR_SUBTREE_MINMAX: name constraints minimum and maximum not supported" -A certificate name constraints extension included a minimum or maximum field: -this is not supported. -.IP "\fBX509_V_ERR_APPLICATION_VERIFICATION: application verification failure\fR" 4 -.IX Item "X509_V_ERR_APPLICATION_VERIFICATION: application verification failure" -An application specific error. This will never be returned unless explicitly -set by an application callback. -.IP "\fBX509_V_ERR_UNSUPPORTED_CONSTRAINT_TYPE: unsupported name constraint type\fR" 4 -.IX Item "X509_V_ERR_UNSUPPORTED_CONSTRAINT_TYPE: unsupported name constraint type" -An unsupported name constraint type was encountered. OpenSSL currently only -supports directory name, \s-1DNS\s0 name, email and \s-1URI\s0 types. -.IP "\fBX509_V_ERR_UNSUPPORTED_CONSTRAINT_SYNTAX: unsupported or invalid name constraint syntax\fR" 4 -.IX Item "X509_V_ERR_UNSUPPORTED_CONSTRAINT_SYNTAX: unsupported or invalid name constraint syntax" -The format of the name constraint is not recognised: for example an email -address format of a form not mentioned in \s-1RFC3280.\s0 This could be caused by -a garbage extension or some new feature not currently supported. -.IP "\fBX509_V_ERR_UNSUPPORTED_NAME_SYNTAX: unsupported or invalid name syntax\fR" 4 -.IX Item "X509_V_ERR_UNSUPPORTED_NAME_SYNTAX: unsupported or invalid name syntax" -Unsupported or invalid name syntax. -.IP "\fBX509_V_ERR_CRL_PATH_VALIDATION_ERROR: \s-1CRL\s0 path validation error\fR" 4 -.IX Item "X509_V_ERR_CRL_PATH_VALIDATION_ERROR: CRL path validation error" -An error occurred when attempting to verify the \s-1CRL\s0 path. This error can only -happen if extended \s-1CRL\s0 checking is enabled. -.IP "\fBX509_V_ERR_PATH_LOOP: path loop\fR" 4 -.IX Item "X509_V_ERR_PATH_LOOP: path loop" -Path loop. -.IP "\fBX509_V_ERR_HOSTNAME_MISMATCH: hostname mismatch\fR" 4 -.IX Item "X509_V_ERR_HOSTNAME_MISMATCH: hostname mismatch" -Hostname mismatch. -.IP "\fBX509_V_ERR_EMAIL_MISMATCH: email address mismatch\fR" 4 -.IX Item "X509_V_ERR_EMAIL_MISMATCH: email address mismatch" -Email address mismatch. -.IP "\fBX509_V_ERR_IP_ADDRESS_MISMATCH: \s-1IP\s0 address mismatch\fR" 4 -.IX Item "X509_V_ERR_IP_ADDRESS_MISMATCH: IP address mismatch" -\&\s-1IP\s0 address mismatch. -.IP "\fBX509_V_ERR_DANE_NO_MATCH: no matching \s-1DANE TLSA\s0 records\fR" 4 -.IX Item "X509_V_ERR_DANE_NO_MATCH: no matching DANE TLSA records" -\&\s-1DANE TLSA\s0 authentication is enabled, but no \s-1TLSA\s0 records matched the -certificate chain. -This error is only possible in \fBopenssl\-s_client\fR\|(1). -.IP "\fBX509_V_ERR_EE_KEY_TOO_SMALL: \s-1EE\s0 certificate key too weak\fR" 4 -.IX Item "X509_V_ERR_EE_KEY_TOO_SMALL: EE certificate key too weak" -\&\s-1EE\s0 certificate key too weak. -.IP "\fBX509_V_ERR_CA_KEY_TOO_SMALL: \s-1CA\s0 certificate key too weak\fR" 4 -.IX Item "X509_V_ERR_CA_KEY_TOO_SMALL: CA certificate key too weak" -\&\s-1CA\s0 certificate key too weak. -.IP "\fBX509_V_ERR_CA_MD_TOO_WEAK: \s-1CA\s0 signature digest algorithm too weak\fR" 4 -.IX Item "X509_V_ERR_CA_MD_TOO_WEAK: CA signature digest algorithm too weak" -\&\s-1CA\s0 signature digest algorithm too weak. -.IP "\fBX509_V_ERR_INVALID_CALL: invalid certificate verification context\fR" 4 -.IX Item "X509_V_ERR_INVALID_CALL: invalid certificate verification context" -Invalid certificate verification context. -.IP "\fBX509_V_ERR_STORE_LOOKUP: issuer certificate lookup error\fR" 4 -.IX Item "X509_V_ERR_STORE_LOOKUP: issuer certificate lookup error" -Issuer certificate lookup error. -.IP "\fBX509_V_ERR_NO_VALID_SCTS: certificate transparency required, but no valid SCTs found\fR" 4 -.IX Item "X509_V_ERR_NO_VALID_SCTS: certificate transparency required, but no valid SCTs found" -Certificate Transparency required, but no valid SCTs found. -.IP "\fBX509_V_ERR_PROXY_SUBJECT_NAME_VIOLATION: proxy subject name violation\fR" 4 -.IX Item "X509_V_ERR_PROXY_SUBJECT_NAME_VIOLATION: proxy subject name violation" -Proxy subject name violation. -.IP "\fBX509_V_ERR_OCSP_VERIFY_NEEDED: \s-1OCSP\s0 verification needed\fR" 4 -.IX Item "X509_V_ERR_OCSP_VERIFY_NEEDED: OCSP verification needed" -Returned by the verify callback to indicate an \s-1OCSP\s0 verification is needed. -.IP "\fBX509_V_ERR_OCSP_VERIFY_FAILED: \s-1OCSP\s0 verification failed\fR" 4 -.IX Item "X509_V_ERR_OCSP_VERIFY_FAILED: OCSP verification failed" -Returned by the verify callback to indicate \s-1OCSP\s0 verification failed. -.IP "\fBX509_V_ERR_OCSP_CERT_UNKNOWN: \s-1OCSP\s0 unknown cert\fR" 4 -.IX Item "X509_V_ERR_OCSP_CERT_UNKNOWN: OCSP unknown cert" -Returned by the verify callback to indicate that the certificate is not -recognized by the \s-1OCSP\s0 responder. -.IP "\fBX509_V_ERR_UNSUPPORTED_SIGNATURE_ALGORITHM: unsupported signature algorithm\fR" 4 -.IX Item "X509_V_ERR_UNSUPPORTED_SIGNATURE_ALGORITHM: unsupported signature algorithm" -Cannot find certificate signature algorithm. -.IP "\fBX509_V_ERR_SIGNATURE_ALGORITHM_MISMATCH: subject signature algorithm and issuer public key algorithm mismatch\fR" 4 -.IX Item "X509_V_ERR_SIGNATURE_ALGORITHM_MISMATCH: subject signature algorithm and issuer public key algorithm mismatch" -The issuer's public key is not of the type required by the signature in -the subject's certificate. -.IP "\fBX509_V_ERR_SIGNATURE_ALGORITHM_INCONSISTENCY: cert info signature and signature algorithm mismatch\fR" 4 -.IX Item "X509_V_ERR_SIGNATURE_ALGORITHM_INCONSISTENCY: cert info signature and signature algorithm mismatch" -The algorithm given in the certificate info is inconsistent - with the one used for the certificate signature. -.IP "\fBX509_V_ERR_INVALID_CA: invalid \s-1CA\s0 certificate\fR" 4 -.IX Item "X509_V_ERR_INVALID_CA: invalid CA certificate" -A \s-1CA\s0 certificate is invalid. Either it is not a \s-1CA\s0 or its extensions are not -consistent with the supplied purpose. -.IP "\fBX509_V_ERR_RPK_UNTRUSTED: raw public key untrusted, no trusted keys configured\fR" 4 -.IX Item "X509_V_ERR_RPK_UNTRUSTED: raw public key untrusted, no trusted keys configured" -No \s-1TLS\s0 records were configured to validate the raw public key, or \s-1DANE\s0 was not -enabled on the connection. -.SH "NOTES" -.IX Header "NOTES" -The above functions should be used instead of directly referencing the fields -in the \fBX509_VERIFY_CTX\fR structure. -.PP -In versions of OpenSSL before 1.0 the current certificate returned by -\&\fBX509_STORE_CTX_get_current_cert()\fR was never \s-1NULL.\s0 Applications should -check the return value before printing out any debugging information relating -to the current certificate. -.PP -If an unrecognised error code is passed to \fBX509_verify_cert_error_string()\fR the -numerical value of the unknown code is returned in a static buffer. This is not -thread safe but will never happen unless an invalid code is passed. -.SH "BUGS" -.IX Header "BUGS" -Previous versions of this documentation swapped the meaning of the -\&\fBX509_V_ERR_UNABLE_TO_GET_ISSUER_CERT\fR and -\&\fBX509_V_ERR_UNABLE_TO_GET_ISSUER_CERT_LOCALLY\fR error codes. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_verify_cert\fR\|(3), \fBX509_STORE_CTX_verify\fR\|(3), -\&\fBX509_up_ref\fR\|(3), -\&\fBX509_free\fR\|(3). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2009\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_error_depth.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_error_depth.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_error_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_ex_data.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_ex_new_index.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_get_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_get_crl.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_get_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_get_issuer.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_get_issuer.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_get_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_issuer_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_issuer_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_issuer_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_certs.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_certs.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_crls.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_crls.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_lookup_crls.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_num_untrusted.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_num_untrusted.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_num_untrusted.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_obj_by_subject.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_obj_by_subject.3ossl deleted file mode 120000 index 4b769ce2..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_obj_by_subject.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_by_subject.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_verify.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_verify.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_get_verify_cb.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_get_verify_cb.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_get_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_init.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_init.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_init.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_init_rpk.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_init_rpk.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_init_rpk.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_lookup_certs_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_lookup_certs_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_lookup_certs_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_lookup_crls_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_lookup_crls_fn.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_lookup_crls_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_new.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_new.3ossl deleted file mode 100644 index 13d98493..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_new.3ossl +++ /dev/null @@ -1,460 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_CTX_NEW 3ossl" -.TH X509_STORE_CTX_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE_CTX_new_ex, X509_STORE_CTX_new, X509_STORE_CTX_cleanup, -X509_STORE_CTX_free, X509_STORE_CTX_init, -X509_STORE_CTX_init_rpk, -X509_STORE_CTX_set0_trusted_stack, -X509_STORE_CTX_set_cert, X509_STORE_CTX_set0_crls, -X509_STORE_CTX_set0_rpk, -X509_STORE_CTX_get0_param, X509_STORE_CTX_set0_param, -X509_STORE_CTX_get0_untrusted, X509_STORE_CTX_set0_untrusted, -X509_STORE_CTX_get_num_untrusted, -X509_STORE_CTX_get0_chain, X509_STORE_CTX_set0_verified_chain, -X509_STORE_CTX_get0_rpk, -X509_STORE_CTX_set_default, -X509_STORE_CTX_set_verify, -X509_STORE_CTX_verify_fn, -X509_STORE_CTX_set_purpose, -X509_STORE_CTX_set_trust, -X509_STORE_CTX_purpose_inherit -\&\- X509_STORE_CTX initialisation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_STORE_CTX *X509_STORE_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq); -\& X509_STORE_CTX *X509_STORE_CTX_new(void); -\& void X509_STORE_CTX_cleanup(X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_free(X509_STORE_CTX *ctx); -\& -\& int X509_STORE_CTX_init(X509_STORE_CTX *ctx, X509_STORE *trust_store, -\& X509 *target, STACK_OF(X509) *untrusted); -\& int X509_STORE_CTX_init_rpk(X509_STORE_CTX *ctx, X509_STORE *trust_store, -\& EVP_PKEY *rpk); -\& -\& void X509_STORE_CTX_set0_trusted_stack(X509_STORE_CTX *ctx, STACK_OF(X509) *sk); -\& -\& void X509_STORE_CTX_set_cert(X509_STORE_CTX *ctx, X509 *target); -\& void X509_STORE_CTX_set0_crls(X509_STORE_CTX *ctx, STACK_OF(X509_CRL) *sk); -\& void X509_STORE_CTX_set0_rpk(X509_STORE_CTX *ctx, EVP_PKEY *target); -\& -\& X509_VERIFY_PARAM *X509_STORE_CTX_get0_param(const X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_set0_param(X509_STORE_CTX *ctx, X509_VERIFY_PARAM *param); -\& -\& STACK_OF(X509)* X509_STORE_CTX_get0_untrusted(const X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_set0_untrusted(X509_STORE_CTX *ctx, STACK_OF(X509) *sk); -\& -\& int X509_STORE_CTX_get_num_untrusted(const X509_STORE_CTX *ctx); -\& STACK_OF(X509) *X509_STORE_CTX_get0_chain(const X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_set0_verified_chain(X509_STORE_CTX *ctx, STACK_OF(X509) *chain); -\& EVP_PKEY *X509_STORE_CTX_get0_rpk(const X509_STORE_CTX *ctx); -\& -\& int X509_STORE_CTX_set_default(X509_STORE_CTX *ctx, const char *name); -\& typedef int (*X509_STORE_CTX_verify_fn)(X509_STORE_CTX *); -\& void X509_STORE_CTX_set_verify(X509_STORE_CTX *ctx, X509_STORE_CTX_verify_fn verify); -\& -\& int X509_STORE_CTX_set_purpose(X509_STORE_CTX *ctx, int purpose); -\& int X509_STORE_CTX_set_trust(X509_STORE_CTX *ctx, int trust); -\& int X509_STORE_CTX_purpose_inherit(X509_STORE_CTX *ctx, int def_purpose, -\& int purpose, int trust); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions initialise an \fBX509_STORE_CTX\fR structure for subsequent use -by \fBX509_verify_cert\fR\|(3) or \fBX509_STORE_CTX_verify\fR\|(3). -.PP -\&\fBX509_STORE_CTX_new_ex()\fR returns a newly initialised \fBX509_STORE_CTX\fR -structure associated with the specified library context \fIlibctx\fR and property -query string \fIpropq\fR. Any cryptographic algorithms fetched while performing -processing with the X509_STORE_CTX will use that library context and property -query string. -.PP -\&\fBX509_STORE_CTX_new()\fR is the same as \fBX509_STORE_CTX_new_ex()\fR except that -the default library context and a \s-1NULL\s0 property query string are used. -.PP -\&\fBX509_STORE_CTX_cleanup()\fR internally cleans up an \fBX509_STORE_CTX\fR structure. -It is used by \fBX509_STORE_CTX_init()\fR and \fBX509_STORE_CTX_free()\fR. -.PP -\&\fBX509_STORE_CTX_free()\fR completely frees up \fIctx\fR. After this call \fIctx\fR -is no longer valid. -If \fIctx\fR is \s-1NULL\s0 nothing is done. -.PP -\&\fBX509_STORE_CTX_init()\fR sets up \fIctx\fR for a subsequent verification operation. -.PP -\&\fBX509_STORE_CTX_init()\fR initializes the internal state and resources of the -given \fIctx\fR. Among others, it sets the verification parameters associcated -with the method name \f(CW\*(C`default\*(C'\fR, which includes the \f(CW\*(C`any\*(C'\fR purpose, -and takes over callback function pointers from \fItrust_store\fR (unless \s-1NULL\s0). -It must be called before each call to \fBX509_verify_cert\fR\|(3) or -\&\fBX509_STORE_CTX_verify\fR\|(3), i.e., a context is only good for one verification. -If you want to verify a further certificate or chain with the same \fIctx\fR -then you must call \fBX509_STORE_CTX_init()\fR again. -The trusted certificate store is set to \fItrust_store\fR of type \fBX509_STORE\fR. -This may be \s-1NULL\s0 because there are no trusted certificates or because -they are provided simply as a list using \fBX509_STORE_CTX_set0_trusted_stack()\fR. -The certificate to be verified is set to \fItarget\fR, -and a list of additional certificates may be provided in \fIuntrusted\fR, -which will be untrusted but may be used to build the chain. -The \fItarget\fR certificate is not copied (its reference count is not updated), -and the caller must not free it before verification is complete. -Each of the \fItrust_store\fR, \fItarget\fR and \fIuntrusted\fR parameters can be \s-1NULL.\s0 -Yet note that \fBX509_verify_cert\fR\|(3) and \fBX509_STORE_CTX_verify\fR\|(3) -will need a verification target. -This can also be set using \fBX509_STORE_CTX_set_cert()\fR. -For \fBX509_STORE_CTX_verify\fR\|(3), which takes by default the first element of the -list of untrusted certificates as its verification target, -this can be also set indirectly using \fBX509_STORE_CTX_set0_untrusted()\fR. -.PP -\&\fBX509_STORE_CTX_init_rpk()\fR sets up \fIctx\fR for a subsequent verification -operation for the \fItarget\fR raw public key. -It behaves similarly to \fBX509_STORE_CTX_init()\fR. -The \fItarget\fR raw public key can also be supplied separately, via -\&\fBX509_STORE_CTX_set0_rpk()\fR. -The \fItarget\fR public key is not copied (its reference count is not updated), -and the caller must not free it before verification is complete. -.PP -\&\fBX509_STORE_CTX_set0_trusted_stack()\fR sets the set of trusted certificates of -\&\fIctx\fR to \fIsk\fR. This is an alternative way of specifying trusted certificates -instead of using an \fBX509_STORE\fR where its complexity is not needed -or to make sure that only the given set \fIsk\fR of certificates are trusted. -.PP -\&\fBX509_STORE_CTX_set_cert()\fR sets the target certificate to be verified in \fIctx\fR -to \fItarget\fR. -The target certificate is not copied (its reference count is not updated), -and the caller must not free it before verification is complete. -.PP -\&\fBX509_STORE_CTX_set0_rpk()\fR sets the target raw public key to be verified in \fIctx\fR -to \fItarget\fR, a non-NULL raw public key preempts any target certificate, which -is then ignored. -The \fItarget\fR public key is not copied (its reference count is not updated), -and the caller must not free it before verification is complete. -.PP -\&\fBX509_STORE_CTX_set0_verified_chain()\fR sets the validated chain to \fIchain\fR. -Ownership of the chain is transferred to \fIctx\fR, -and so it should not be free'd by the caller. -.PP -\&\fBX509_STORE_CTX_get0_chain()\fR returns the internal pointer used by the -\&\fIctx\fR that contains the constructed (output) chain. -.PP -\&\fBX509_STORE_CTX_get0_rpk()\fR returns the internal pointer used by the -\&\fIctx\fR that contains the raw public key. -.PP -\&\fBX509_STORE_CTX_set0_crls()\fR sets a set of CRLs to use to aid certificate -verification to \fIsk\fR. These CRLs will only be used if \s-1CRL\s0 verification is -enabled in the associated \fBX509_VERIFY_PARAM\fR structure. This might be -used where additional \*(L"useful\*(R" CRLs are supplied as part of a protocol, -for example in a PKCS#7 structure. -.PP -\&\fBX509_STORE_CTX_get0_param()\fR retrieves an internal pointer -to the verification parameters associated with \fIctx\fR. -.PP -\&\fBX509_STORE_CTX_set0_param()\fR sets the internal verification parameter pointer -to \fIparam\fR. After this call \fBparam\fR should not be used. -.PP -\&\fBX509_STORE_CTX_get0_untrusted()\fR retrieves an internal pointer to the -stack of untrusted certificates associated with \fIctx\fR. -.PP -\&\fBX509_STORE_CTX_set0_untrusted()\fR sets the internal pointer to the stack -of untrusted certificates associated with \fIctx\fR to \fIsk\fR. -\&\fBX509_STORE_CTX_verify()\fR will take the first element, if any, -as its default target if the target certificate is not set explicitly. -.PP -\&\fBX509_STORE_CTX_get_num_untrusted()\fR returns the number of untrusted certificates -that were used in building the chain. -This is can be used after calling \fBX509_verify_cert\fR\|(3) and similar functions. -With \fBX509_STORE_CTX_verify\fR\|(3), this does not count the first chain element. -.PP -\&\fBX509_STORE_CTX_get0_chain()\fR returns the internal pointer used by the -\&\fIctx\fR that contains the validated chain. -.PP -Details of the chain building and checking process are described in -\&\*(L"Certification Path Building\*(R" in \fBopenssl\-verification\-options\fR\|(1) and -\&\*(L"Certification Path Validation\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.PP -\&\fBX509_STORE_CTX_set0_verified_chain()\fR sets the validated chain used -by \fIctx\fR to be \fIchain\fR. -Ownership of the chain is transferred to \fIctx\fR, -and so it should not be free'd by the caller. -.PP -\&\fBX509_STORE_CTX_set_default()\fR looks up and sets the default verification method. -This uses the function \fBX509_VERIFY_PARAM_lookup()\fR to find -the set of parameters associated with the given verification method \fIname\fR. -Among others, the parameters determine the trust model and verification purpose. -More detail, including the list of currently predefined methods, -is described for the \fB\-verify_name\fR command-line option -in \*(L"Verification Options\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.PP -\&\fBX509_STORE_CTX_set_verify()\fR provides the capability for overriding the default -verify function. This function is responsible for verifying chain signatures and -expiration times. -.PP -A verify function is defined as an X509_STORE_CTX_verify type which has the -following signature: -.PP -.Vb 1 -\& int (*verify)(X509_STORE_CTX *); -.Ve -.PP -This function should receive the current X509_STORE_CTX as a parameter and -return 1 on success or 0 on failure. -.PP -X509 certificates may contain information about what purposes keys contained -within them can be used for. For example \*(L"\s-1TLS WWW\s0 Server Authentication\*(R" or -\&\*(L"Email Protection\*(R". This \*(L"key usage\*(R" information is held internally to the -certificate itself. In addition the trust store containing trusted certificates -can declare what purposes we trust different certificates for. This \*(L"trust\*(R" -information is not held within the certificate itself but is \*(L"meta\*(R" information -held alongside it. This \*(L"meta\*(R" information is associated with the certificate -after it is issued and could be determined by a system administrator. For -example a certificate might declare that it is suitable for use for both -\&\*(L"\s-1TLS WWW\s0 Server Authentication\*(R" and \*(L"\s-1TLS\s0 Client Authentication\*(R", but a system -administrator might only trust it for the former. An X.509 certificate extension -exists that can record extended key usage information to supplement the purpose -information described above. This extended mechanism is arbitrarily extensible -and not well suited for a generic library \s-1API\s0; applications that need to -validate extended key usage information in certificates will need to define a -custom \*(L"purpose\*(R" (see below) or supply a nondefault verification callback -(\fBX509_STORE_set_verify_cb_func\fR\|(3)). -.PP -\&\fBX509_STORE_CTX_set_purpose()\fR sets the purpose for the target certificate being -verified in the \fIctx\fR. Built-in available values for the \fIpurpose\fR argument -are \fBX509_PURPOSE_SSL_CLIENT\fR, \fBX509_PURPOSE_SSL_SERVER\fR, -\&\fBX509_PURPOSE_NS_SSL_SERVER\fR, \fBX509_PURPOSE_SMIME_SIGN\fR, -\&\fBX509_PURPOSE_SMIME_ENCRYPT\fR, \fBX509_PURPOSE_CRL_SIGN\fR, \fBX509_PURPOSE_ANY\fR, -\&\fBX509_PURPOSE_OCSP_HELPER\fR, \fBX509_PURPOSE_TIMESTAMP_SIGN\fR and -\&\fBX509_PURPOSE_CODE_SIGN\fR. It is also -possible to create a custom purpose value. Setting a purpose requests that -the key usage and extended key usage (\s-1EKU\s0) extensions optionally declared within -the certificate and its chain are verified to be consistent with that purpose. -For \s-1SSL\s0 client, \s-1SSL\s0 server, and S/MIME purposes, the \s-1EKU\s0 is checked also for the -\&\s-1CA\s0 certificates along the chain, including any given trust anchor certificate. -Potentially also further checks are done (depending on the purpose given). -Every purpose also has an associated default trust value, which will also be set -at the same time. During verification, this trust setting will be verified -to check whether it is consistent with the trust set by the system administrator -for certificates in the chain. -.PP -\&\fBX509_STORE_CTX_set_trust()\fR sets the trust value for the target certificate -being verified in the \fIctx\fR. Built-in available values for the \fItrust\fR -argument are \fBX509_TRUST_COMPAT\fR, \fBX509_TRUST_SSL_CLIENT\fR, -\&\fBX509_TRUST_SSL_SERVER\fR, \fBX509_TRUST_EMAIL\fR, \fBX509_TRUST_OBJECT_SIGN\fR, -\&\fBX509_TRUST_OCSP_SIGN\fR, \fBX509_TRUST_OCSP_REQUEST\fR and \fBX509_TRUST_TSA\fR. It is -also possible to create a custom trust value. Since \fBX509_STORE_CTX_set_purpose()\fR -also sets the trust value it is normally sufficient to only call that function. -If both are called then \fBX509_STORE_CTX_set_trust()\fR should be called after -\&\fBX509_STORE_CTX_set_purpose()\fR since the trust setting of the last call will be -used. -.PP -It should not normally be necessary for end user applications to call -\&\fBX509_STORE_CTX_purpose_inherit()\fR directly. Typically applications should call -\&\fBX509_STORE_CTX_set_purpose()\fR or \fBX509_STORE_CTX_set_trust()\fR instead. Using this -function it is possible to set the purpose and trust values for the \fIctx\fR at -the same time. -Both \fIctx\fR and its internal verification parameter pointer must not be \s-1NULL.\s0 -The \fIdef_purpose\fR and \fIpurpose\fR arguments can have the same -purpose values as described for \fBX509_STORE_CTX_set_purpose()\fR above. The \fItrust\fR -argument can have the same trust values as described in -\&\fBX509_STORE_CTX_set_trust()\fR above. Any of the \fIdef_purpose\fR, \fIpurpose\fR or -\&\fItrust\fR values may also have the value 0 to indicate that the supplied -parameter should be ignored. After calling this function the purpose to be used -for verification is set from the \fIpurpose\fR argument unless the purpose was -already set in \fIctx\fR before, and the trust is set from the \fItrust\fR argument -unless the trust was already set in \fIctx\fR before. -If \fItrust\fR is 0 then the trust value will be set from -the default trust value for \fIpurpose\fR. If the default trust value for the -purpose is \fIX509_TRUST_DEFAULT\fR and \fItrust\fR is 0 then the default trust value -associated with the \fIdef_purpose\fR value is used for the trust setting instead. -.SH "NOTES" -.IX Header "NOTES" -The certificates and CRLs in a store are used internally and should \fBnot\fR -be freed up until after the associated \fBX509_STORE_CTX\fR is freed. -.SH "BUGS" -.IX Header "BUGS" -The certificates and CRLs in a context are used internally and should \fBnot\fR -be freed up until after the associated \fBX509_STORE_CTX\fR is freed. Copies -should be made or reference counts increased instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_STORE_CTX_new()\fR returns a newly allocated context or \s-1NULL\s0 if an -error occurred. -.PP -\&\fBX509_STORE_CTX_init()\fR and \fBX509_STORE_CTX_init_rpk()\fR return 1 for success -or 0 if an error occurred. -.PP -\&\fBX509_STORE_CTX_get0_param()\fR returns a pointer to an \fBX509_VERIFY_PARAM\fR -structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBX509_STORE_CTX_get0_rpk()\fR returns a pointer to an \fB\s-1EVP_PKEY\s0\fR structure if -present, or \s-1NULL\s0 if absent. -.PP -\&\fBX509_STORE_CTX_cleanup()\fR, \fBX509_STORE_CTX_free()\fR, -\&\fBX509_STORE_CTX_set0_trusted_stack()\fR, -\&\fBX509_STORE_CTX_set_cert()\fR, -\&\fBX509_STORE_CTX_set0_crls()\fR and \fBX509_STORE_CTX_set0_param()\fR do not return -values. -.PP -\&\fBX509_STORE_CTX_set_default()\fR returns 1 for success or 0 if an error occurred. -.PP -\&\fBX509_STORE_CTX_get_num_untrusted()\fR returns the number of untrusted certificates -used. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_verify_cert\fR\|(3), \fBX509_STORE_CTX_verify\fR\|(3), -\&\fBX509_VERIFY_PARAM_set_flags\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_STORE_CTX_set0_crls()\fR function was added in OpenSSL 1.0.0. -The \fBX509_STORE_CTX_get_num_untrusted()\fR function was added in OpenSSL 1.1.0. -The \fBX509_STORE_CTX_new_ex()\fR function was added in OpenSSL 3.0. -The \fBX509_STORE_CTX_init_rpk()\fR, \fBX509_STORE_CTX_get0_rpk()\fR, and -\&\fBX509_STORE_CTX_set0_rpk()\fR functions were added in OpenSSL 3.2. -.PP -There is no need to call \fBX509_STORE_CTX_cleanup()\fR explicitly since OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2009\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_new_ex.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_new_ex.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_print_verify_cb.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_print_verify_cb.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_print_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_purpose_inherit.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_purpose_inherit.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_purpose_inherit.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set0_crls.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set0_crls.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set0_crls.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set0_param.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set0_param.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set0_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set0_rpk.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set0_rpk.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set0_rpk.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set0_trusted_stack.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set0_trusted_stack.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set0_trusted_stack.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set0_untrusted.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set0_untrusted.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set0_untrusted.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set0_verified_chain.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set0_verified_chain.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set0_verified_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_app_data.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_app_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_app_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_cert.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_cert.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_current_cert.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_current_cert.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_current_cert.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_current_reasons.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_current_reasons.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_current_reasons.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_default.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_default.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_default.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_error.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_error.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_error_depth.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_error_depth.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_error_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_ex_data.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_get_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_get_crl.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_get_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_purpose.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_purpose.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_purpose.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_trust.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_trust.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_trust.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_verify.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_verify.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_set_verify_cb.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_set_verify_cb.3ossl deleted file mode 100644 index fcd1898b..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_set_verify_cb.3ossl +++ /dev/null @@ -1,377 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_CTX_SET_VERIFY_CB 3ossl" -.TH X509_STORE_CTX_SET_VERIFY_CB 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE_CTX_get_cleanup, -X509_STORE_CTX_get_lookup_crls, -X509_STORE_CTX_get_lookup_certs, -X509_STORE_CTX_get_check_policy, -X509_STORE_CTX_get_cert_crl, -X509_STORE_CTX_get_check_crl, -X509_STORE_CTX_get_get_crl, -X509_STORE_CTX_set_get_crl, -X509_STORE_CTX_get_check_revocation, -X509_STORE_CTX_get_check_issued, -X509_STORE_CTX_get_get_issuer, -X509_STORE_CTX_get_verify_cb, -X509_STORE_CTX_set_verify_cb, -X509_STORE_CTX_verify_cb, -X509_STORE_CTX_print_verify_cb, -X509_STORE_CTX_set_current_reasons -\&\- get and set X509_STORE_CTX components such as verification callback -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*X509_STORE_CTX_verify_cb)(int, X509_STORE_CTX *); -\& int X509_STORE_CTX_print_verify_cb(int ok, X509_STORE_CTX *ctx); -\& -\& X509_STORE_CTX_verify_cb X509_STORE_CTX_get_verify_cb(X509_STORE_CTX *ctx); -\& -\& void X509_STORE_CTX_set_verify_cb(X509_STORE_CTX *ctx, -\& X509_STORE_CTX_verify_cb verify_cb); -\& -\& X509_STORE_CTX_get_issuer_fn X509_STORE_CTX_get_get_issuer(X509_STORE_CTX *ctx); -\& X509_STORE_CTX_check_issued_fn X509_STORE_CTX_get_check_issued(X509_STORE_CTX *ctx); -\& X509_STORE_CTX_check_revocation_fn X509_STORE_CTX_get_check_revocation(X509_STORE_CTX *ctx); -\& -\& X509_STORE_CTX_get_crl_fn X509_STORE_CTX_get_get_crl(X509_STORE_CTX *ctx); -\& -\& void X509_STORE_CTX_set_get_crl(X509_STORE_CTX *ctx, -\& X509_STORE_CTX_get_crl_fn get_crl); -\& -\& X509_STORE_CTX_check_crl_fn X509_STORE_CTX_get_check_crl(X509_STORE_CTX *ctx); -\& X509_STORE_CTX_cert_crl_fn X509_STORE_CTX_get_cert_crl(X509_STORE_CTX *ctx); -\& X509_STORE_CTX_check_policy_fn X509_STORE_CTX_get_check_policy(X509_STORE_CTX *ctx); -\& X509_STORE_CTX_lookup_certs_fn X509_STORE_CTX_get_lookup_certs(X509_STORE_CTX *ctx); -\& X509_STORE_CTX_lookup_crls_fn X509_STORE_CTX_get_lookup_crls(X509_STORE_CTX *ctx); -\& X509_STORE_CTX_cleanup_fn X509_STORE_CTX_get_cleanup(X509_STORE_CTX *ctx); -\& void X509_STORE_CTX_set_current_reasons(X509_STORE_CTX *ctx, -\& unsigned int current_reasons); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_STORE_CTX_set_verify_cb()\fR sets the verification callback of \fBctx\fR to -\&\fBverify_cb\fR overwriting any existing callback. -.PP -The verification callback can be used to customise the operation of certificate -verification, for instance by overriding error conditions or logging errors for -debugging purposes. -.PP -However, a verification callback is \fBnot\fR essential and the default operation -is often sufficient. -.PP -The \fBok\fR parameter to the callback indicates the value the callback should -return to retain the default behaviour. If it is zero then an error condition -is indicated. If it is 1 then no error occurred. If the flag -\&\fBX509_V_FLAG_NOTIFY_POLICY\fR is set then \fBok\fR is set to 2 to indicate the -policy checking is complete. -.PP -The \fBctx\fR parameter to the callback is the \fBX509_STORE_CTX\fR structure that -is performing the verification operation. A callback can examine this -structure and receive additional information about the error, for example -by calling \fBX509_STORE_CTX_get_current_cert()\fR. Additional application data can -be passed to the callback via the \fBex_data\fR mechanism. -.PP -\&\fBX509_STORE_CTX_print_verify_cb()\fR is a verification callback function that, -when a certificate verification has failed, adds an entry to the error queue -with code \fBX509_R_CERTIFICATE_VERIFICATION_FAILED\fR and with diagnostic details, -including the most relevant fields of the target certificate that failed to -verify and, if appropriate, of the available untrusted and trusted certificates. -.PP -\&\fBX509_STORE_CTX_get_verify_cb()\fR returns the value of the current callback -for the specific \fBctx\fR. -.PP -\&\fBX509_STORE_CTX_get_get_issuer()\fR, -\&\fBX509_STORE_CTX_get_check_issued()\fR, \fBX509_STORE_CTX_get_check_revocation()\fR, -\&\fBX509_STORE_CTX_get_get_crl()\fR, \fBX509_STORE_CTX_get_check_crl()\fR, -\&\fBX509_STORE_CTX_get_cert_crl()\fR, \fBX509_STORE_CTX_get_check_policy()\fR, -\&\fBX509_STORE_CTX_get_lookup_certs()\fR, \fBX509_STORE_CTX_get_lookup_crls()\fR -and \fBX509_STORE_CTX_get_cleanup()\fR return the function pointers cached -from the corresponding \fBX509_STORE\fR, please see -\&\fBX509_STORE_set_verify\fR\|(3) for more information. -.PP -\&\fBX509_STORE_CTX_set_get_crl()\fR sets the function to get the crl for a given -certificate \fIx\fR. -When found, the crl must be assigned to \fI*crl\fR. -This function must return 0 on failure and 1 on success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_CTX_set_current_reasons()\fR is used in conjunction with -X509_STORE_CTX_get_crl_fn. The X509_STORE_CTX_get_crl_fn callback must -use this method to set the reason why the certificate is invalid. -.SH "WARNINGS" -.IX Header "WARNINGS" -In general a verification callback should \fB\s-1NOT\s0\fR unconditionally return 1 in -all circumstances because this will allow verification to succeed no matter -what the error. This effectively removes all security from the application -because \fBany\fR certificate (including untrusted generated ones) will be -accepted. -.SH "NOTES" -.IX Header "NOTES" -The verification callback can be set and inherited from the parent structure -performing the operation. In some cases (such as S/MIME verification) the -\&\fBX509_STORE_CTX\fR structure is created and destroyed internally and the -only way to set a custom verification callback is by inheriting it from the -associated \fBX509_STORE\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_STORE_CTX_set_verify_cb()\fR does not return a value. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Default callback operation: -.PP -.Vb 3 -\& int verify_callback(int ok, X509_STORE_CTX *ctx) { -\& return ok; -\& } -.Ve -.PP -Simple example, suppose a certificate in the chain is expired and we wish -to continue after this error: -.PP -.Vb 7 -\& int verify_callback(int ok, X509_STORE_CTX *ctx) { -\& /* Tolerate certificate expiration */ -\& if (X509_STORE_CTX_get_error(ctx) == X509_V_ERR_CERT_HAS_EXPIRED) -\& return 1; -\& /* Otherwise don\*(Aqt override */ -\& return ok; -\& } -.Ve -.PP -More complex example, we don't wish to continue after \fBany\fR certificate has -expired just one specific case: -.PP -.Vb 4 -\& int verify_callback(int ok, X509_STORE_CTX *ctx) -\& { -\& int err = X509_STORE_CTX_get_error(ctx); -\& X509 *err_cert = X509_STORE_CTX_get_current_cert(ctx); -\& -\& if (err == X509_V_ERR_CERT_HAS_EXPIRED) { -\& if (check_is_acceptable_expired_cert(err_cert) -\& return 1; -\& } -\& return ok; -\& } -.Ve -.PP -Full featured logging callback. In this case the \fBbio_err\fR is assumed to be -a global logging \fB\s-1BIO\s0\fR, an alternative would to store a \s-1BIO\s0 in \fBctx\fR using -\&\fBex_data\fR. -.PP -.Vb 4 -\& int verify_callback(int ok, X509_STORE_CTX *ctx) -\& { -\& X509 *err_cert; -\& int err, depth; -\& -\& err_cert = X509_STORE_CTX_get_current_cert(ctx); -\& err = X509_STORE_CTX_get_error(ctx); -\& depth = X509_STORE_CTX_get_error_depth(ctx); -\& -\& BIO_printf(bio_err, "depth=%d ", depth); -\& if (err_cert) { -\& X509_NAME_print_ex(bio_err, X509_get_subject_name(err_cert), -\& 0, XN_FLAG_ONELINE); -\& BIO_puts(bio_err, "\en"); -\& } -\& else -\& BIO_puts(bio_err, "\en"); -\& if (!ok) -\& BIO_printf(bio_err, "verify error:num=%d:%s\en", err, -\& X509_verify_cert_error_string(err)); -\& switch (err) { -\& case X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT: -\& BIO_puts(bio_err, "issuer= "); -\& X509_NAME_print_ex(bio_err, X509_get_issuer_name(err_cert), -\& 0, XN_FLAG_ONELINE); -\& BIO_puts(bio_err, "\en"); -\& break; -\& case X509_V_ERR_CERT_NOT_YET_VALID: -\& case X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD: -\& BIO_printf(bio_err, "notBefore="); -\& ASN1_TIME_print(bio_err, X509_get_notBefore(err_cert)); -\& BIO_printf(bio_err, "\en"); -\& break; -\& case X509_V_ERR_CERT_HAS_EXPIRED: -\& case X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD: -\& BIO_printf(bio_err, "notAfter="); -\& ASN1_TIME_print(bio_err, X509_get_notAfter(err_cert)); -\& BIO_printf(bio_err, "\en"); -\& break; -\& case X509_V_ERR_NO_EXPLICIT_POLICY: -\& policies_print(bio_err, ctx); -\& break; -\& } -\& if (err == X509_V_OK && ok == 2) -\& /* print out policies */ -\& -\& BIO_printf(bio_err, "verify return:%d\en", ok); -\& return(ok); -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_STORE_CTX_get_error\fR\|(3) -\&\fBX509_STORE_set_verify_cb_func\fR\|(3) -\&\fBX509_STORE_CTX_get_ex_new_index\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The -\&\fBX509_STORE_CTX_get_get_issuer()\fR, -\&\fBX509_STORE_CTX_get_check_issued()\fR, \fBX509_STORE_CTX_get_check_revocation()\fR, -\&\fBX509_STORE_CTX_get_get_crl()\fR, \fBX509_STORE_CTX_get_check_crl()\fR, -\&\fBX509_STORE_CTX_get_cert_crl()\fR, \fBX509_STORE_CTX_get_check_policy()\fR, -\&\fBX509_STORE_CTX_get_lookup_certs()\fR, \fBX509_STORE_CTX_get_lookup_crls()\fR -and \fBX509_STORE_CTX_get_cleanup()\fR functions were added in OpenSSL 1.1.0. -.PP -\&\fBX509_STORE_CTX_print_verify_cb()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2009\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_verify.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_verify.3ossl deleted file mode 120000 index 997cc079..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_verify_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_verify_cb.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_verify_cb.3ossl deleted file mode 120000 index 73531225..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_set_verify_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_CTX_verify_fn.3ossl b/openssl-install/share/man/man3/X509_STORE_CTX_verify_fn.3ossl deleted file mode 120000 index 51362b4c..00000000 --- a/openssl-install/share/man/man3/X509_STORE_CTX_verify_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_add_cert.3ossl b/openssl-install/share/man/man3/X509_STORE_add_cert.3ossl deleted file mode 100644 index d900054f..00000000 --- a/openssl-install/share/man/man3/X509_STORE_add_cert.3ossl +++ /dev/null @@ -1,303 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_ADD_CERT 3ossl" -.TH X509_STORE_ADD_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE, -X509_STORE_add_cert, X509_STORE_add_crl, X509_STORE_set_depth, -X509_STORE_set_flags, X509_STORE_set_purpose, X509_STORE_set_trust, -X509_STORE_add_lookup, -X509_STORE_load_file_ex, X509_STORE_load_file, X509_STORE_load_path, -X509_STORE_load_store_ex, X509_STORE_load_store, -X509_STORE_set_default_paths_ex, X509_STORE_set_default_paths, -X509_STORE_load_locations_ex, X509_STORE_load_locations -\&\- X509_STORE manipulation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef x509_store_st X509_STORE; -\& -\& int X509_STORE_add_cert(X509_STORE *xs, X509 *x); -\& int X509_STORE_add_crl(X509_STORE *xs, X509_CRL *x); -\& int X509_STORE_set_depth(X509_STORE *store, int depth); -\& int X509_STORE_set_flags(X509_STORE *xs, unsigned long flags); -\& int X509_STORE_set_purpose(X509_STORE *xs, int purpose); -\& int X509_STORE_set_trust(X509_STORE *xs, int trust); -\& -\& X509_LOOKUP *X509_STORE_add_lookup(X509_STORE *store, -\& X509_LOOKUP_METHOD *meth); -\& -\& int X509_STORE_set_default_paths_ex(X509_STORE *xs, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int X509_STORE_set_default_paths(X509_STORE *xs); -\& int X509_STORE_load_file_ex(X509_STORE *xs, const char *file, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_STORE_load_file(X509_STORE *xs, const char *file); -\& int X509_STORE_load_path(X509_STORE *xs, const char *dir); -\& int X509_STORE_load_store_ex(X509_STORE *xs, const char *uri, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_STORE_load_store(X509_STORE *xs, const char *uri); -\& int X509_STORE_load_locations_ex(X509_STORE *xs, const char *file, -\& const char *dir, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int X509_STORE_load_locations(X509_STORE *xs, -\& const char *file, const char *dir); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX509_STORE\fR structure is intended to be a consolidated mechanism for -holding information about X.509 certificates and CRLs, and constructing -and validating chains of certificates terminating in trusted roots. -It admits multiple lookup mechanisms and efficient scaling performance -with large numbers of certificates, and a great deal of flexibility in -how validation and policy checks are performed. -.PP -Details of the chain building and checking process are described in -\&\*(L"Certification Path Building\*(R" in \fBopenssl\-verification\-options\fR\|(1) and -\&\*(L"Certification Path Validation\*(R" in \fBopenssl\-verification\-options\fR\|(1). -.PP -\&\fBX509_STORE_new\fR\|(3) creates an empty \fBX509_STORE\fR structure, which contains -no information about trusted certificates or where such certificates -are located on disk, and is generally not usable. Normally, trusted -certificates will be added to the \fBX509_STORE\fR to prepare it for use, -via mechanisms such as \fBX509_STORE_add_lookup()\fR and \fBX509_LOOKUP_file()\fR, or -\&\fBPEM_read_bio_X509_AUX()\fR and \fBX509_STORE_add_cert()\fR. CRLs can also be added, -and many behaviors configured as desired. -.PP -Once the \fBX509_STORE\fR is suitably configured, \fBX509_STORE_CTX_new()\fR is -used to instantiate a single-use \fBX509_STORE_CTX\fR for each chain-building -and verification operation. That process includes providing the end-entity -certificate to be verified and an additional set of untrusted certificates -that may be used in chain-building. As such, it is expected that the -certificates included in the \fBX509_STORE\fR are certificates that represent -trusted entities such as root certificate authorities (CAs). -OpenSSL represents these trusted certificates internally as \fBX509\fR objects -with an associated \fBX509_CERT_AUX\fR, as are produced by -\&\fBPEM_read_bio_X509_AUX()\fR and similar routines that refer to X509_AUX. -The public interfaces that operate on such trusted certificates still -operate on pointers to \fBX509\fR objects, though. -.PP -\&\fBX509_STORE_add_cert()\fR and \fBX509_STORE_add_crl()\fR add the respective object -to the \fBX509_STORE\fR's local storage. Untrusted objects should not be -added in this way. The added object's reference count is incremented by one, -hence the caller retains ownership of the object and needs to free it when it -is no longer needed. -.PP -\&\fBX509_STORE_set_depth()\fR, \fBX509_STORE_set_flags()\fR, \fBX509_STORE_set_purpose()\fR, -\&\fBX509_STORE_set_trust()\fR, and \fBX509_STORE_set1_param()\fR set the default values -for the corresponding values used in certificate chain validation. Their -behavior is documented in the corresponding \fBX509_VERIFY_PARAM\fR manual -pages, e.g., \fBX509_VERIFY_PARAM_set_depth\fR\|(3). -.PP -\&\fBX509_STORE_add_lookup()\fR finds or creates a \fBX509_LOOKUP\fR\|(3) with the -\&\fBX509_LOOKUP_METHOD\fR\|(3) \fImeth\fR and adds it to the \fBX509_STORE\fR -\&\fIstore\fR. This also associates the \fBX509_STORE\fR with the lookup, so -\&\fBX509_LOOKUP\fR functions can look up objects in that store. -.PP -\&\fBX509_STORE_load_file_ex()\fR loads trusted certificate(s) into an -\&\fBX509_STORE\fR from a given file. The library context \fIlibctx\fR and property -query \fIpropq\fR are used when fetching algorithms from providers. -.PP -\&\fBX509_STORE_load_file()\fR is similar to \fBX509_STORE_load_file_ex()\fR but -uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBX509_STORE_load_path()\fR loads trusted certificate(s) into an -\&\fBX509_STORE\fR from a given directory path. -The certificates in the directory must be in hashed form, as -documented in \fBX509_LOOKUP_hash_dir\fR\|(3). -.PP -\&\fBX509_STORE_load_store_ex()\fR loads trusted certificate(s) into an -\&\fBX509_STORE\fR from a store at a given \s-1URI.\s0 The library context \fIlibctx\fR and -property query \fIpropq\fR are used when fetching algorithms from providers. -.PP -\&\fBX509_STORE_load_store()\fR is similar to \fBX509_STORE_load_store_ex()\fR but -uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBX509_STORE_load_locations_ex()\fR combines -\&\fBX509_STORE_load_file_ex()\fR and \fBX509_STORE_load_path()\fR for a given file -and/or directory path. -It is permitted to specify just a file, just a directory, or both -paths. -.PP -\&\fBX509_STORE_load_locations()\fR is similar to \fBX509_STORE_load_locations_ex()\fR -but uses \s-1NULL\s0 for the library context \fIlibctx\fR and property query \fIpropq\fR. -.PP -\&\fBX509_STORE_set_default_paths_ex()\fR is somewhat misnamed, in that it does -not set what default paths should be used for loading certificates. Instead, -it loads certificates into the \fBX509_STORE\fR from the hardcoded default -paths. The library context \fIlibctx\fR and property query \fIpropq\fR are used when -fetching algorithms from providers. -.PP -\&\fBX509_STORE_set_default_paths()\fR is similar to -\&\fBX509_STORE_set_default_paths_ex()\fR but uses \s-1NULL\s0 for the library -context \fIlibctx\fR and property query \fIpropq\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_STORE_add_cert()\fR, \fBX509_STORE_add_crl()\fR, \fBX509_STORE_set_depth()\fR, -\&\fBX509_STORE_set_flags()\fR, \fBX509_STORE_set_purpose()\fR, \fBX509_STORE_set_trust()\fR, -\&\fBX509_STORE_load_file_ex()\fR, \fBX509_STORE_load_file()\fR, -\&\fBX509_STORE_load_path()\fR, -\&\fBX509_STORE_load_store_ex()\fR, \fBX509_STORE_load_store()\fR, -\&\fBX509_STORE_load_locations_ex()\fR, \fBX509_STORE_load_locations()\fR, -\&\fBX509_STORE_set_default_paths_ex()\fR and \fBX509_STORE_set_default_paths()\fR -return 1 on success or 0 on failure. -.PP -\&\fBX509_STORE_add_lookup()\fR returns the found or created -\&\fBX509_LOOKUP\fR\|(3), or \s-1NULL\s0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_LOOKUP_hash_dir\fR\|(3). -\&\fBX509_VERIFY_PARAM_set_depth\fR\|(3). -\&\fBX509_STORE_new\fR\|(3), -\&\fBX509_STORE_get0_param\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBX509_STORE_set_default_paths_ex()\fR, -\&\fBX509_STORE_load_file_ex()\fR, \fBX509_STORE_load_store_ex()\fR and -\&\fBX509_STORE_load_locations_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_add_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_add_crl.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_add_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_add_lookup.3ossl b/openssl-install/share/man/man3/X509_STORE_add_lookup.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_add_lookup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_free.3ossl b/openssl-install/share/man/man3/X509_STORE_free.3ossl deleted file mode 120000 index 5cb1635d..00000000 --- a/openssl-install/share/man/man3/X509_STORE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get0_objects.3ossl b/openssl-install/share/man/man3/X509_STORE_get0_objects.3ossl deleted file mode 120000 index 46ac73fb..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get0_objects.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get0_param.3ossl b/openssl-install/share/man/man3/X509_STORE_get0_param.3ossl deleted file mode 100644 index f1268d73..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get0_param.3ossl +++ /dev/null @@ -1,206 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_GET0_PARAM 3ossl" -.TH X509_STORE_GET0_PARAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE_get0_param, X509_STORE_set1_param, -X509_STORE_get1_objects, X509_STORE_get0_objects, X509_STORE_get1_all_certs -\&\- X509_STORE setter and getter functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_VERIFY_PARAM *X509_STORE_get0_param(const X509_STORE *xs); -\& int X509_STORE_set1_param(X509_STORE *xs, const X509_VERIFY_PARAM *pm); -\& STACK_OF(X509_OBJECT) *X509_STORE_get1_objects(X509_STORE *xs); -\& STACK_OF(X509_OBJECT) *X509_STORE_get0_objects(const X509_STORE *xs); -\& STACK_OF(X509) *X509_STORE_get1_all_certs(X509_STORE *xs); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_STORE_set1_param()\fR sets the verification parameters to \fIpm\fR for \fIxs\fR. -.PP -\&\fBX509_STORE_get0_param()\fR retrieves an internal pointer to the verification -parameters for \fIxs\fR. The returned pointer must not be freed by the -calling application -.PP -\&\fBX509_STORE_get1_objects()\fR returns a snapshot of all objects in the store's X509 -cache. The cache contains \fBX509\fR and \fBX509_CRL\fR objects. The caller is -responsible for freeing the returned list. -.PP -\&\fBX509_STORE_get0_objects()\fR retrieves an internal pointer to the store's -X509 object cache. The cache contains \fBX509\fR and \fBX509_CRL\fR objects. The -returned pointer must not be freed by the calling application. If the store is -shared across multiple threads, it is not safe to use the result of this -function. Use \fBX509_STORE_get1_objects()\fR instead, which avoids this problem. -.PP -\&\fBX509_STORE_get1_all_certs()\fR returns a list of all certificates in the store. -The caller is responsible for freeing the returned list. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_STORE_get0_param()\fR returns a pointer to an -\&\fBX509_VERIFY_PARAM\fR structure. -.PP -\&\fBX509_STORE_set1_param()\fR returns 1 for success and 0 for failure. -.PP -\&\fBX509_STORE_get1_objects()\fR returns a pointer to a stack of the retrieved -objects on success, else \s-1NULL.\s0 -.PP -\&\fBX509_STORE_get0_objects()\fR returns a pointer to a stack of \fBX509_OBJECT\fR. -.PP -\&\fBX509_STORE_get1_all_certs()\fR returns a pointer to a stack of the retrieved -certificates on success, else \s-1NULL.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_STORE_new\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_STORE_get0_param\fR and \fBX509_STORE_get0_objects\fR were added in -OpenSSL 1.1.0. -\&\fBX509_STORE_get1_certs\fR was added in OpenSSL 3.0. -\&\fBX509_STORE_get1_objects\fR was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_get1_all_certs.3ossl b/openssl-install/share/man/man3/X509_STORE_get1_all_certs.3ossl deleted file mode 120000 index 46ac73fb..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get1_all_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get1_objects.3ossl b/openssl-install/share/man/man3/X509_STORE_get1_objects.3ossl deleted file mode 120000 index 46ac73fb..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get1_objects.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_cert_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_get_cert_crl.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_cert_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_check_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_get_check_crl.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_check_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_check_issued.3ossl b/openssl-install/share/man/man3/X509_STORE_get_check_issued.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_check_issued.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_check_policy.3ossl b/openssl-install/share/man/man3/X509_STORE_get_check_policy.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_check_policy.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_check_revocation.3ossl b/openssl-install/share/man/man3/X509_STORE_get_check_revocation.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_check_revocation.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_cleanup.3ossl b/openssl-install/share/man/man3/X509_STORE_get_cleanup.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_ex_data.3ossl b/openssl-install/share/man/man3/X509_STORE_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_ex_new_index.3ossl b/openssl-install/share/man/man3/X509_STORE_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_get_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_get_get_crl.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_get_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_get_issuer.3ossl b/openssl-install/share/man/man3/X509_STORE_get_get_issuer.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_get_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_lookup_certs.3ossl b/openssl-install/share/man/man3/X509_STORE_get_lookup_certs.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_lookup_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_lookup_crls.3ossl b/openssl-install/share/man/man3/X509_STORE_get_lookup_crls.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_lookup_crls.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_get_verify_cb.3ossl b/openssl-install/share/man/man3/X509_STORE_get_verify_cb.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_get_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_load_file.3ossl b/openssl-install/share/man/man3/X509_STORE_load_file.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_load_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_load_file_ex.3ossl b/openssl-install/share/man/man3/X509_STORE_load_file_ex.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_load_file_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_load_locations.3ossl b/openssl-install/share/man/man3/X509_STORE_load_locations.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_load_locations.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_load_locations_ex.3ossl b/openssl-install/share/man/man3/X509_STORE_load_locations_ex.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_load_locations_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_load_path.3ossl b/openssl-install/share/man/man3/X509_STORE_load_path.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_load_path.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_load_store.3ossl b/openssl-install/share/man/man3/X509_STORE_load_store.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_load_store.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_load_store_ex.3ossl b/openssl-install/share/man/man3/X509_STORE_load_store_ex.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_load_store_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_lock.3ossl b/openssl-install/share/man/man3/X509_STORE_lock.3ossl deleted file mode 120000 index 5cb1635d..00000000 --- a/openssl-install/share/man/man3/X509_STORE_lock.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_new.3ossl b/openssl-install/share/man/man3/X509_STORE_new.3ossl deleted file mode 100644 index 5176c4cc..00000000 --- a/openssl-install/share/man/man3/X509_STORE_new.3ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_NEW 3ossl" -.TH X509_STORE_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE_new, X509_STORE_up_ref, X509_STORE_free, -X509_STORE_lock,X509_STORE_unlock -\&\- X509_STORE allocation, freeing and locking functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509_STORE *X509_STORE_new(void); -\& void X509_STORE_free(X509_STORE *xs); -\& int X509_STORE_lock(X509_STORE *xs); -\& int X509_STORE_unlock(X509_STORE *xs); -\& int X509_STORE_up_ref(X509_STORE *xs); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX509_STORE_new()\fR function returns a new X509_STORE. -.PP -\&\fBX509_STORE_up_ref()\fR increments the reference count associated with the -X509_STORE object. -.PP -\&\fBX509_STORE_lock()\fR locks the store from modification by other threads, -\&\fBX509_STORE_unlock()\fR unlocks it. -.PP -\&\fBX509_STORE_free()\fR frees up a single X509_STORE object. -If the argument is \s-1NULL,\s0 nothing is done. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_STORE_new()\fR returns a newly created X509_STORE or \s-1NULL\s0 if the call fails. -.PP -\&\fBX509_STORE_up_ref()\fR, \fBX509_STORE_lock()\fR and \fBX509_STORE_unlock()\fR return -1 for success and 0 for failure. -.PP -\&\fBX509_STORE_free()\fR does not return values. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_STORE_set_verify_cb_func\fR\|(3) -\&\fBX509_STORE_get0_param\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_STORE_up_ref()\fR, \fBX509_STORE_lock()\fR and \fBX509_STORE_unlock()\fR -functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_set1_param.3ossl b/openssl-install/share/man/man3/X509_STORE_set1_param.3ossl deleted file mode 120000 index 46ac73fb..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set1_param.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_get0_param.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_cert_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_set_cert_crl.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_cert_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_check_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_set_check_crl.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_check_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_check_issued.3ossl b/openssl-install/share/man/man3/X509_STORE_set_check_issued.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_check_issued.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_check_policy.3ossl b/openssl-install/share/man/man3/X509_STORE_set_check_policy.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_check_policy.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_check_revocation.3ossl b/openssl-install/share/man/man3/X509_STORE_set_check_revocation.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_check_revocation.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_cleanup.3ossl b/openssl-install/share/man/man3/X509_STORE_set_cleanup.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_cleanup.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_default_paths.3ossl b/openssl-install/share/man/man3/X509_STORE_set_default_paths.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_default_paths.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_default_paths_ex.3ossl b/openssl-install/share/man/man3/X509_STORE_set_default_paths_ex.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_default_paths_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_depth.3ossl b/openssl-install/share/man/man3/X509_STORE_set_depth.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_ex_data.3ossl b/openssl-install/share/man/man3/X509_STORE_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_flags.3ossl b/openssl-install/share/man/man3/X509_STORE_set_flags.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_get_crl.3ossl b/openssl-install/share/man/man3/X509_STORE_set_get_crl.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_get_crl.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_get_issuer.3ossl b/openssl-install/share/man/man3/X509_STORE_set_get_issuer.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_get_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_lookup_certs.3ossl b/openssl-install/share/man/man3/X509_STORE_set_lookup_certs.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_lookup_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_lookup_crls.3ossl b/openssl-install/share/man/man3/X509_STORE_set_lookup_crls.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_lookup_crls.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_lookup_crls_cb.3ossl b/openssl-install/share/man/man3/X509_STORE_set_lookup_crls_cb.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_lookup_crls_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_purpose.3ossl b/openssl-install/share/man/man3/X509_STORE_set_purpose.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_purpose.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_trust.3ossl b/openssl-install/share/man/man3/X509_STORE_set_trust.3ossl deleted file mode 120000 index 217c5c63..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_trust.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_verify.3ossl b/openssl-install/share/man/man3/X509_STORE_set_verify.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_verify.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_verify_cb.3ossl b/openssl-install/share/man/man3/X509_STORE_set_verify_cb.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_verify_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_set_verify_cb_func.3ossl b/openssl-install/share/man/man3/X509_STORE_set_verify_cb_func.3ossl deleted file mode 100644 index d7f5eadb..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_verify_cb_func.3ossl +++ /dev/null @@ -1,416 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_STORE_SET_VERIFY_CB_FUNC 3ossl" -.TH X509_STORE_SET_VERIFY_CB_FUNC 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_STORE_set_lookup_crls_cb, -X509_STORE_set_verify_func, -X509_STORE_get_cleanup, -X509_STORE_set_cleanup, -X509_STORE_get_lookup_crls, -X509_STORE_set_lookup_crls, -X509_STORE_get_lookup_certs, -X509_STORE_set_lookup_certs, -X509_STORE_get_check_policy, -X509_STORE_set_check_policy, -X509_STORE_get_cert_crl, -X509_STORE_set_cert_crl, -X509_STORE_get_check_crl, -X509_STORE_set_check_crl, -X509_STORE_get_get_crl, -X509_STORE_set_get_crl, -X509_STORE_get_check_revocation, -X509_STORE_set_check_revocation, -X509_STORE_get_check_issued, -X509_STORE_set_check_issued, -X509_STORE_CTX_get1_issuer, -X509_STORE_get_get_issuer, -X509_STORE_set_get_issuer, -X509_STORE_CTX_get_verify, -X509_STORE_set_verify, -X509_STORE_get_verify_cb, -X509_STORE_set_verify_cb_func, X509_STORE_set_verify_cb, -X509_STORE_CTX_cert_crl_fn, X509_STORE_CTX_check_crl_fn, -X509_STORE_CTX_check_issued_fn, X509_STORE_CTX_check_policy_fn, -X509_STORE_CTX_check_revocation_fn, X509_STORE_CTX_cleanup_fn, -X509_STORE_CTX_get_crl_fn, X509_STORE_CTX_get_issuer_fn, -X509_STORE_CTX_lookup_certs_fn, X509_STORE_CTX_lookup_crls_fn -\&\- set verification callback -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& typedef int (*X509_STORE_CTX_get_issuer_fn)(X509 **issuer, -\& X509_STORE_CTX *ctx, X509 *x); -\& typedef int (*X509_STORE_CTX_check_issued_fn)(X509_STORE_CTX *ctx, -\& X509 *x, X509 *issuer); -\& typedef int (*X509_STORE_CTX_check_revocation_fn)(X509_STORE_CTX *ctx); -\& typedef int (*X509_STORE_CTX_get_crl_fn)(X509_STORE_CTX *ctx, -\& X509_CRL **crl, X509 *x); -\& typedef int (*X509_STORE_CTX_check_crl_fn)(X509_STORE_CTX *ctx, X509_CRL *crl); -\& typedef int (*X509_STORE_CTX_cert_crl_fn)(X509_STORE_CTX *ctx, -\& X509_CRL *crl, X509 *x); -\& typedef int (*X509_STORE_CTX_check_policy_fn)(X509_STORE_CTX *ctx); -\& typedef STACK_OF(X509) *(*X509_STORE_CTX_lookup_certs_fn)(X509_STORE_CTX *ctx, -\& const X509_NAME *nm); -\& typedef STACK_OF(X509_CRL) *(*X509_STORE_CTX_lookup_crls_fn)(const -\& X509_STORE_CTX *ctx, -\& const X509_NAME *nm); -\& typedef int (*X509_STORE_CTX_cleanup_fn)(X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_verify_cb(X509_STORE *xs, -\& X509_STORE_CTX_verify_cb verify_cb); -\& X509_STORE_CTX_verify_cb X509_STORE_get_verify_cb(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_verify(X509_STORE *xs, X509_STORE_CTX_verify_fn verify); -\& X509_STORE_CTX_verify_fn X509_STORE_CTX_get_verify(const X509_STORE_CTX *ctx); -\& -\& int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, X509 *x); -\& X509_STORE_CTX_get_issuer_fn X509_STORE_get_get_issuer(const X509_STORE_CTX *ctx); -\& void X509_STORE_set_get_issuer(X509_STORE *xs, -\& X509_STORE_CTX_get_issuer_fn get_issuer); -\& -\& void X509_STORE_set_check_issued(X509_STORE *xs, -\& X509_STORE_CTX_check_issued_fn check_issued); -\& X509_STORE_CTX_check_issued_fn -\& X509_STORE_get_check_issued(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_check_revocation(X509_STORE *xs, -\& X509_STORE_CTX_check_revocation_fn check_revocation); -\& X509_STORE_CTX_check_revocation_fn -\& X509_STORE_get_check_revocation(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_get_crl(X509_STORE *xs, -\& X509_STORE_CTX_get_crl_fn get_crl); -\& X509_STORE_CTX_get_crl_fn X509_STORE_get_get_crl(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_check_crl(X509_STORE *xs, -\& X509_STORE_CTX_check_crl_fn check_crl); -\& X509_STORE_CTX_check_crl_fn -\& X509_STORE_get_check_crl(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_cert_crl(X509_STORE *xs, -\& X509_STORE_CTX_cert_crl_fn cert_crl); -\& X509_STORE_CTX_cert_crl_fn X509_STORE_get_cert_crl(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_check_policy(X509_STORE *xs, -\& X509_STORE_CTX_check_policy_fn check_policy); -\& X509_STORE_CTX_check_policy_fn -\& X509_STORE_get_check_policy(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_lookup_certs(X509_STORE *xs, -\& X509_STORE_CTX_lookup_certs_fn lookup_certs); -\& X509_STORE_CTX_lookup_certs_fn -\& X509_STORE_get_lookup_certs(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_lookup_crls(X509_STORE *xs, -\& X509_STORE_CTX_lookup_crls_fn lookup_crls); -\& X509_STORE_CTX_lookup_crls_fn -\& X509_STORE_get_lookup_crls(const X509_STORE_CTX *ctx); -\& -\& void X509_STORE_set_cleanup(X509_STORE *xs, -\& X509_STORE_CTX_cleanup_fn cleanup); -\& X509_STORE_CTX_cleanup_fn X509_STORE_get_cleanup(const X509_STORE_CTX *ctx); -\& -\& /* Aliases */ -\& void X509_STORE_set_verify_cb_func(X509_STORE *st, -\& X509_STORE_CTX_verify_cb verify_cb); -\& void X509_STORE_set_verify_func(X509_STORE *xs, -\& X509_STORE_CTX_verify_fn verify); -\& void X509_STORE_set_lookup_crls_cb(X509_STORE *xs, -\& X509_STORE_CTX_lookup_crls_fn lookup_crls); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_STORE_set_verify_cb()\fR sets the verification callback of \fIxs\fR to -\&\fIverify_cb\fR overwriting the previous callback. -The callback assigned with this function becomes a default for the one -that can be assigned directly to the corresponding \fBX509_STORE_CTX\fR, -please see \fBX509_STORE_CTX_set_verify_cb\fR\|(3) for further information. -.PP -\&\fBX509_STORE_set_verify()\fR sets the final chain verification function for -\&\fIxs\fR to \fIverify\fR. -Its purpose is to go through the chain of certificates and check that -all signatures are valid and that the current time is within the -limits of each certificate's first and last validity time. -The final chain verification functions must return 0 on failure and 1 -on success. -\&\fIIf no chain verification function is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_CTX_get1_issuer()\fR tries to find a certificate from the \fIstore\fR -component of \fIctx\fR that has a subject name matching the issuer name of \fIx\fR -and is accepted by the \fIcheck_issued\fR function in \fIctx\fR. -On success it assigns to \fI*issuer\fR the first match that has a suitable validity -period or otherwise has the latest expiration date of all matching certificates. -If the function returns 1 the caller is responsible for freeing \fI*issuer\fR. -Note that this search does not support backtracking. -.PP -\&\fBX509_STORE_set_get_issuer()\fR sets the function \fIget_issuer\fR that is used -to get the \*(L"best\*(R" candidate issuer certificate of the given certificate \fIx\fR. -When such a certificate is found, \fIget_issuer\fR must up-ref and assign it -to \fI*issuer\fR and then return 1. -Otherwise \fIget_issuer\fR must return 0 if not found and \-1 (or 0) on failure. -If \fBX509_STORE_set_get_issuer()\fR is not used or \fIget_issuer\fR is \s-1NULL\s0 -then \fBX509_STORE_CTX_get1_issuer()\fR is used as the default implementation. -.PP -\&\fBX509_STORE_set_check_issued()\fR sets the function to check that a given -certificate \fIx\fR is issued by the issuer certificate \fIissuer\fR. -This function must return 0 on failure (among others if \fIx\fR hasn't -been issued with \fIissuer\fR) and 1 on success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_set_check_revocation()\fR sets the revocation checking -function. -Its purpose is to look through the final chain and check the -revocation status for each certificate. -It must return 0 on failure and 1 on success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_set_get_crl()\fR sets the function to get the crl for a given -certificate \fIx\fR. -When found, the crl must be assigned to \fI*crl\fR. -This function must return 0 on failure and 1 on success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_set_check_crl()\fR sets the function to check the validity of -the given \fIcrl\fR. -This function must return 0 on failure and 1 on success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_set_cert_crl()\fR sets the function to check the revocation -status of the given certificate \fIx\fR against the given \fIcrl\fR. -This function must return 0 on failure and 1 on success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_set_check_policy()\fR sets the function to check the policies -of all the certificates in the final chain.. -This function must return 0 on failure and 1 on success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_set_lookup_certs()\fR and \fBX509_STORE_set_lookup_crls()\fR set the -functions to look up all the certs or all the CRLs that match the -given name \fInm\fR. -These functions return \s-1NULL\s0 on failure and a pointer to a stack of -certificates (\fBX509\fR) or to a stack of CRLs (\fBX509_CRL\fR) on -success. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_set_cleanup()\fR sets the final cleanup function, which is -called when the context (\fBX509_STORE_CTX\fR) is being torn down. -This function doesn't return any value. -\&\fIIf no function to get the issuer is provided, the internal default -function will be used instead.\fR -.PP -\&\fBX509_STORE_get_verify_cb()\fR, \fBX509_STORE_CTX_get_verify()\fR, -\&\fBX509_STORE_get_get_issuer()\fR, \fBX509_STORE_get_check_issued()\fR, -\&\fBX509_STORE_get_check_revocation()\fR, \fBX509_STORE_get_get_crl()\fR, -\&\fBX509_STORE_get_check_crl()\fR, \fBX509_STORE_set_verify()\fR, -\&\fBX509_STORE_set_get_issuer()\fR, \fBX509_STORE_get_cert_crl()\fR, -\&\fBX509_STORE_get_check_policy()\fR, \fBX509_STORE_get_lookup_certs()\fR, -\&\fBX509_STORE_get_lookup_crls()\fR and \fBX509_STORE_get_cleanup()\fR all return -the function pointer assigned with \fBX509_STORE_set_check_issued()\fR, -\&\fBX509_STORE_set_check_revocation()\fR, \fBX509_STORE_set_get_crl()\fR, -\&\fBX509_STORE_set_check_crl()\fR, \fBX509_STORE_set_cert_crl()\fR, -\&\fBX509_STORE_set_check_policy()\fR, \fBX509_STORE_set_lookup_certs()\fR, -\&\fBX509_STORE_set_lookup_crls()\fR and \fBX509_STORE_set_cleanup()\fR, or \s-1NULL\s0 if -no assignment has been made. -.PP -\&\fBX509_STORE_set_verify_cb_func()\fR, \fBX509_STORE_set_verify_func()\fR and -\&\fBX509_STORE_set_lookup_crls_cb()\fR are aliases for -\&\fBX509_STORE_set_verify_cb()\fR, \fBX509_STORE_set_verify()\fR and -X509_STORE_set_lookup_crls, available as macros for backward -compatibility. -.SH "NOTES" -.IX Header "NOTES" -All the callbacks from a \fBX509_STORE\fR are inherited by the -corresponding \fBX509_STORE_CTX\fR structure when it is initialized. -See \fBX509_STORE_CTX_set_verify_cb\fR\|(3) for further details. -.SH "BUGS" -.IX Header "BUGS" -The macro version of this function was the only one available before -OpenSSL 1.0.0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The X509_STORE_set_*() functions do not return a value. -.PP -The X509_STORE_get_*() functions return a pointer of the appropriate -function type. -.PP -\&\fBX509_STORE_CTX_get1_issuer()\fR returns -1 if a suitable certificate is found, 0 if not found, \-1 on other error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_STORE_CTX_set_verify_cb\fR\|(3), \fBX509_STORE_CTX_get0_chain\fR\|(3), -\&\fBX509_STORE_CTX_verify_cb\fR\|(3), \fBX509_STORE_CTX_verify_fn\fR\|(3), -\&\fBCMS_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_STORE_set_verify_cb()\fR function was added in OpenSSL 1.0.0. -.PP -The functions -\&\fBX509_STORE_set_verify_cb()\fR, \fBX509_STORE_get_verify_cb()\fR, -\&\fBX509_STORE_set_verify()\fR, \fBX509_STORE_CTX_get_verify()\fR, -\&\fBX509_STORE_set_get_issuer()\fR, \fBX509_STORE_get_get_issuer()\fR, -\&\fBX509_STORE_set_check_issued()\fR, \fBX509_STORE_get_check_issued()\fR, -\&\fBX509_STORE_set_check_revocation()\fR, \fBX509_STORE_get_check_revocation()\fR, -\&\fBX509_STORE_set_get_crl()\fR, \fBX509_STORE_get_get_crl()\fR, -\&\fBX509_STORE_set_check_crl()\fR, \fBX509_STORE_get_check_crl()\fR, -\&\fBX509_STORE_set_cert_crl()\fR, \fBX509_STORE_get_cert_crl()\fR, -\&\fBX509_STORE_set_check_policy()\fR, \fBX509_STORE_get_check_policy()\fR, -\&\fBX509_STORE_set_lookup_certs()\fR, \fBX509_STORE_get_lookup_certs()\fR, -\&\fBX509_STORE_set_lookup_crls()\fR, \fBX509_STORE_get_lookup_crls()\fR, -\&\fBX509_STORE_set_cleanup()\fR and \fBX509_STORE_get_cleanup()\fR -were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2009\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_STORE_set_verify_func.3ossl b/openssl-install/share/man/man3/X509_STORE_set_verify_func.3ossl deleted file mode 120000 index 51c79cbf..00000000 --- a/openssl-install/share/man/man3/X509_STORE_set_verify_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_set_verify_cb_func.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_unlock.3ossl b/openssl-install/share/man/man3/X509_STORE_unlock.3ossl deleted file mode 120000 index 5cb1635d..00000000 --- a/openssl-install/share/man/man3/X509_STORE_unlock.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_STORE_up_ref.3ossl b/openssl-install/share/man/man3/X509_STORE_up_ref.3ossl deleted file mode 120000 index 5cb1635d..00000000 --- a/openssl-install/share/man/man3/X509_STORE_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VAL_free.3ossl b/openssl-install/share/man/man3/X509_VAL_free.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_VAL_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VAL_new.3ossl b/openssl-install/share/man/man3/X509_VAL_new.3ossl deleted file mode 120000 index 7f7bd903..00000000 --- a/openssl-install/share/man/man3/X509_VAL_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_dup.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_add0_policy.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_add0_policy.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_add0_policy.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_add1_host.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_add1_host.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_add1_host.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_clear_flags.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_clear_flags.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_clear_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_email.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_email.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_email.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_host.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_host.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_host.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_peername.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_peername.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get0_peername.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get1_ip_asc.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get1_ip_asc.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get1_ip_asc.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_auth_level.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_auth_level.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_auth_level.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_depth.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_depth.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_flags.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_flags.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_hostflags.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_hostflags.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_hostflags.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_inh_flags.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_inh_flags.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_inh_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_time.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_time.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_get_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_email.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_email.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_email.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_host.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_host.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_host.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip_asc.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip_asc.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_ip_asc.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_policies.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_policies.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set1_policies.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_auth_level.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_auth_level.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_auth_level.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_depth.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_depth.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_depth.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_flags.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_flags.3ossl deleted file mode 100644 index a1847886..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_flags.3ossl +++ /dev/null @@ -1,545 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_VERIFY_PARAM_SET_FLAGS 3ossl" -.TH X509_VERIFY_PARAM_SET_FLAGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_VERIFY_PARAM_set_flags, X509_VERIFY_PARAM_clear_flags, -X509_VERIFY_PARAM_get_flags, X509_VERIFY_PARAM_set_purpose, -X509_VERIFY_PARAM_get_inh_flags, X509_VERIFY_PARAM_set_inh_flags, -X509_VERIFY_PARAM_set_trust, X509_VERIFY_PARAM_set_depth, -X509_VERIFY_PARAM_get_depth, X509_VERIFY_PARAM_set_auth_level, -X509_VERIFY_PARAM_get_auth_level, X509_VERIFY_PARAM_set_time, -X509_VERIFY_PARAM_get_time, -X509_VERIFY_PARAM_add0_policy, X509_VERIFY_PARAM_set1_policies, -X509_VERIFY_PARAM_get0_host, -X509_VERIFY_PARAM_set1_host, X509_VERIFY_PARAM_add1_host, -X509_VERIFY_PARAM_set_hostflags, -X509_VERIFY_PARAM_get_hostflags, -X509_VERIFY_PARAM_get0_peername, -X509_VERIFY_PARAM_get0_email, X509_VERIFY_PARAM_set1_email, -X509_VERIFY_PARAM_set1_ip, X509_VERIFY_PARAM_get1_ip_asc, -X509_VERIFY_PARAM_set1_ip_asc -\&\- X509 verification parameters -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_VERIFY_PARAM_set_flags(X509_VERIFY_PARAM *param, -\& unsigned long flags); -\& int X509_VERIFY_PARAM_clear_flags(X509_VERIFY_PARAM *param, -\& unsigned long flags); -\& unsigned long X509_VERIFY_PARAM_get_flags(const X509_VERIFY_PARAM *param); -\& -\& int X509_VERIFY_PARAM_set_inh_flags(X509_VERIFY_PARAM *param, -\& uint32_t flags); -\& uint32_t X509_VERIFY_PARAM_get_inh_flags(const X509_VERIFY_PARAM *param); -\& -\& int X509_VERIFY_PARAM_set_purpose(X509_VERIFY_PARAM *param, int purpose); -\& int X509_VERIFY_PARAM_set_trust(X509_VERIFY_PARAM *param, int trust); -\& -\& void X509_VERIFY_PARAM_set_time(X509_VERIFY_PARAM *param, time_t t); -\& time_t X509_VERIFY_PARAM_get_time(const X509_VERIFY_PARAM *param); -\& -\& int X509_VERIFY_PARAM_add0_policy(X509_VERIFY_PARAM *param, -\& ASN1_OBJECT *policy); -\& int X509_VERIFY_PARAM_set1_policies(X509_VERIFY_PARAM *param, -\& STACK_OF(ASN1_OBJECT) *policies); -\& -\& void X509_VERIFY_PARAM_set_depth(X509_VERIFY_PARAM *param, int depth); -\& int X509_VERIFY_PARAM_get_depth(const X509_VERIFY_PARAM *param); -\& -\& void X509_VERIFY_PARAM_set_auth_level(X509_VERIFY_PARAM *param, -\& int auth_level); -\& int X509_VERIFY_PARAM_get_auth_level(const X509_VERIFY_PARAM *param); -\& -\& char *X509_VERIFY_PARAM_get0_host(X509_VERIFY_PARAM *param, int n); -\& int X509_VERIFY_PARAM_set1_host(X509_VERIFY_PARAM *param, -\& const char *name, size_t namelen); -\& int X509_VERIFY_PARAM_add1_host(X509_VERIFY_PARAM *param, -\& const char *name, size_t namelen); -\& void X509_VERIFY_PARAM_set_hostflags(X509_VERIFY_PARAM *param, -\& unsigned int flags); -\& unsigned int X509_VERIFY_PARAM_get_hostflags(const X509_VERIFY_PARAM *param); -\& char *X509_VERIFY_PARAM_get0_peername(const X509_VERIFY_PARAM *param); -\& char *X509_VERIFY_PARAM_get0_email(X509_VERIFY_PARAM *param); -\& int X509_VERIFY_PARAM_set1_email(X509_VERIFY_PARAM *param, -\& const char *email, size_t emaillen); -\& char *X509_VERIFY_PARAM_get1_ip_asc(X509_VERIFY_PARAM *param); -\& int X509_VERIFY_PARAM_set1_ip(X509_VERIFY_PARAM *param, -\& const unsigned char *ip, size_t iplen); -\& int X509_VERIFY_PARAM_set1_ip_asc(X509_VERIFY_PARAM *param, const char *ipasc); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions manipulate the \fBX509_VERIFY_PARAM\fR structure associated with -a certificate verification operation. -.PP -The \fBX509_VERIFY_PARAM_set_flags()\fR function sets the flags in \fBparam\fR by oring -it with \fBflags\fR. See \*(L"\s-1VERIFICATION FLAGS\*(R"\s0 for a complete -description of values the \fBflags\fR parameter can take. -.PP -\&\fBX509_VERIFY_PARAM_get_flags()\fR returns the flags in \fBparam\fR. -.PP -\&\fBX509_VERIFY_PARAM_get_inh_flags()\fR returns the inheritance flags in \fBparam\fR -which specifies how verification flags are copied from one structure to -another. \fBX509_VERIFY_PARAM_set_inh_flags()\fR sets the inheritance flags. -See the \fB\s-1INHERITANCE FLAGS\s0\fR section for a description of these bits. -.PP -\&\fBX509_VERIFY_PARAM_clear_flags()\fR clears the flags \fBflags\fR in \fBparam\fR. -.PP -\&\fBX509_VERIFY_PARAM_set_purpose()\fR sets the verification purpose in \fBparam\fR -to \fBpurpose\fR. This determines the acceptable purpose of the certificate -chain, for example \fBX509_PURPOSE_SSL_CLIENT\fR. -The purpose requirement is cleared if \fBpurpose\fR is 0. -.PP -\&\fBX509_VERIFY_PARAM_set_trust()\fR sets the trust setting in \fBparam\fR to -\&\fBtrust\fR. -.PP -\&\fBX509_VERIFY_PARAM_set_time()\fR sets the verification time in \fBparam\fR to -\&\fBt\fR. Normally the current time is used. -.PP -\&\fBX509_VERIFY_PARAM_add0_policy()\fR adds \fBpolicy\fR to the acceptable policy set. -Contrary to preexisting documentation of this function it does not enable -policy checking. -.PP -\&\fBX509_VERIFY_PARAM_set1_policies()\fR enables policy checking (it is disabled -by default) and sets the acceptable policy set to \fBpolicies\fR. Any existing -policy set is cleared. The \fBpolicies\fR parameter can be \fB\s-1NULL\s0\fR to clear -an existing policy set. -.PP -\&\fBX509_VERIFY_PARAM_set_depth()\fR sets the maximum verification depth to \fBdepth\fR. -That is the maximum number of intermediate \s-1CA\s0 certificates that can appear in a -chain. -A maximal depth chain contains 2 more certificates than the limit, since -neither the end-entity certificate nor the trust-anchor count against this -limit. -Thus a \fBdepth\fR limit of 0 only allows the end-entity certificate to be signed -directly by the trust anchor, while with a \fBdepth\fR limit of 1 there can be one -intermediate \s-1CA\s0 certificate between the trust anchor and the end-entity -certificate. -.PP -\&\fBX509_VERIFY_PARAM_set_auth_level()\fR sets the authentication security level to -\&\fBauth_level\fR. -The authentication security level determines the acceptable signature and public -key strength when verifying certificate chains. -For a certificate chain to validate, the public keys of all the certificates -must meet the specified security level. -The signature algorithm security level is not enforced for the chain's \fItrust -anchor\fR certificate, which is either directly trusted or validated by means other -than its signature. -See \fBSSL_CTX_set_security_level\fR\|(3) for the definitions of the available -levels. -The default security level is \-1, or \*(L"not set\*(R". -At security level 0 or lower all algorithms are acceptable. -Security level 1 requires at least 80\-bit\-equivalent security and is broadly -interoperable, though it will, for example, reject \s-1MD5\s0 signatures or \s-1RSA\s0 keys -shorter than 1024 bits. -.PP -\&\fBX509_VERIFY_PARAM_get0_host()\fR returns the \fBn\fRth expected \s-1DNS\s0 hostname that has -been set using \fBX509_VERIFY_PARAM_set1_host()\fR or \fBX509_VERIFY_PARAM_add1_host()\fR. -To obtain all names start with \fBn\fR = 0 and increment \fBn\fR as long as no \s-1NULL\s0 -pointer is returned. -.PP -\&\fBX509_VERIFY_PARAM_set1_host()\fR sets the expected \s-1DNS\s0 hostname to -\&\fBname\fR clearing any previously specified hostname. If -\&\fBname\fR is \s-1NULL,\s0 or empty the list of hostnames is cleared, and -name checks are not performed on the peer certificate. If \fBname\fR -is NUL-terminated, \fBnamelen\fR may be zero, otherwise \fBnamelen\fR -must be set to the length of \fBname\fR. -.PP -When a hostname is specified, -certificate verification automatically invokes \fBX509_check_host\fR\|(3) -with flags equal to the \fBflags\fR argument given to -\&\fBX509_VERIFY_PARAM_set_hostflags()\fR (default zero). Applications -are strongly advised to use this interface in preference to explicitly -calling \fBX509_check_host\fR\|(3), hostname checks may be out of scope -with the \s-1\fBDANE\-EE\s0\fR\|(3) certificate usage, and the internal check will -be suppressed as appropriate when \s-1DANE\s0 verification is enabled. -.PP -When the subject CommonName will not be ignored, whether as a result of the -\&\fBX509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT\fR host flag, or because no \s-1DNS\s0 subject -alternative names are present in the certificate, any \s-1DNS\s0 name constraints in -issuer certificates apply to the subject CommonName as well as the subject -alternative name extension. -.PP -When the subject CommonName will be ignored, whether as a result of the -\&\fBX509_CHECK_FLAG_NEVER_CHECK_SUBJECT\fR host flag, or because some \s-1DNS\s0 subject -alternative names are present in the certificate, \s-1DNS\s0 name constraints in -issuer certificates will not be applied to the subject \s-1DN.\s0 -As described in \fBX509_check_host\fR\|(3) the \fBX509_CHECK_FLAG_NEVER_CHECK_SUBJECT\fR -flag takes precedence over the \fBX509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT\fR flag. -.PP -\&\fBX509_VERIFY_PARAM_get_hostflags()\fR returns any host flags previously set via a -call to \fBX509_VERIFY_PARAM_set_hostflags()\fR. -.PP -\&\fBX509_VERIFY_PARAM_add1_host()\fR adds \fBname\fR as an additional reference -identifier that can match the peer's certificate. Any previous names -set via \fBX509_VERIFY_PARAM_set1_host()\fR or \fBX509_VERIFY_PARAM_add1_host()\fR -are retained, no change is made if \fBname\fR is \s-1NULL\s0 or empty. When -multiple names are configured, the peer is considered verified when -any name matches. -.PP -\&\fBX509_VERIFY_PARAM_get0_peername()\fR returns the \s-1DNS\s0 hostname or subject -CommonName from the peer certificate that matched one of the reference -identifiers. When wildcard matching is not disabled, or when a -reference identifier specifies a parent domain (starts with \*(L".\*(R") -rather than a hostname, the peer name may be a wildcard name or a -sub-domain of the reference identifier respectively. The return -string is allocated by the library and is no longer valid once the -associated \fBparam\fR argument is freed. Applications must not free -the return value. -.PP -\&\fBX509_VERIFY_PARAM_get0_email()\fR returns the expected \s-1RFC822\s0 email address. -.PP -\&\fBX509_VERIFY_PARAM_set1_email()\fR sets the expected \s-1RFC822\s0 email address to -\&\fBemail\fR. If \fBemail\fR is NUL-terminated, \fBemaillen\fR may be zero, otherwise -\&\fBemaillen\fR must be set to the length of \fBemail\fR. When an email address -is specified, certificate verification automatically invokes -\&\fBX509_check_email\fR\|(3). -.PP -\&\fBX509_VERIFY_PARAM_get1_ip_asc()\fR returns the expected \s-1IP\s0 address as a string. -The caller is responsible for freeing it. -.PP -\&\fBX509_VERIFY_PARAM_set1_ip()\fR sets the expected \s-1IP\s0 address to \fBip\fR. -The \fBip\fR argument is in binary format, in network byte-order and -\&\fBiplen\fR must be set to 4 for IPv4 and 16 for IPv6. When an \s-1IP\s0 -address is specified, certificate verification automatically invokes -\&\fBX509_check_ip\fR\|(3). -.PP -\&\fBX509_VERIFY_PARAM_set1_ip_asc()\fR sets the expected \s-1IP\s0 address to -\&\fBipasc\fR. The \fBipasc\fR argument is a NUL-terminal \s-1ASCII\s0 string: -dotted decimal quad for IPv4 and colon-separated hexadecimal for -IPv6. The condensed \*(L"::\*(R" notation is supported for IPv6 addresses. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_VERIFY_PARAM_set_flags()\fR, \fBX509_VERIFY_PARAM_clear_flags()\fR, -\&\fBX509_VERIFY_PARAM_set_inh_flags()\fR, -\&\fBX509_VERIFY_PARAM_set_purpose()\fR, \fBX509_VERIFY_PARAM_set_trust()\fR, -\&\fBX509_VERIFY_PARAM_add0_policy()\fR \fBX509_VERIFY_PARAM_set1_policies()\fR, -\&\fBX509_VERIFY_PARAM_set1_host()\fR, \fBX509_VERIFY_PARAM_add1_host()\fR, -\&\fBX509_VERIFY_PARAM_set1_email()\fR, \fBX509_VERIFY_PARAM_set1_ip()\fR and -\&\fBX509_VERIFY_PARAM_set1_ip_asc()\fR return 1 for success and 0 for -failure. -.PP -\&\fBX509_VERIFY_PARAM_get0_host()\fR, \fBX509_VERIFY_PARAM_get0_email()\fR, and -\&\fBX509_VERIFY_PARAM_get1_ip_asc()\fR, return the string pointers specified above -or \s-1NULL\s0 if the respective value has not been set or on error. -.PP -\&\fBX509_VERIFY_PARAM_get_flags()\fR returns the current verification flags. -.PP -\&\fBX509_VERIFY_PARAM_get_hostflags()\fR returns any current host flags. -.PP -\&\fBX509_VERIFY_PARAM_get_inh_flags()\fR returns the current inheritance flags. -.PP -\&\fBX509_VERIFY_PARAM_set_time()\fR and \fBX509_VERIFY_PARAM_set_depth()\fR do not return -values. -.PP -\&\fBX509_VERIFY_PARAM_get_depth()\fR returns the current verification depth. -.PP -\&\fBX509_VERIFY_PARAM_get_auth_level()\fR returns the current authentication security -level. -.SH "VERIFICATION FLAGS" -.IX Header "VERIFICATION FLAGS" -The verification flags consists of zero or more of the following flags -ored together. -.PP -\&\fBX509_V_FLAG_CRL_CHECK\fR enables \s-1CRL\s0 checking for the certificate chain leaf -certificate. An error occurs if a suitable \s-1CRL\s0 cannot be found. -.PP -\&\fBX509_V_FLAG_CRL_CHECK_ALL\fR expands \s-1CRL\s0 checking to the entire certificate -chain if \fBX509_V_FLAG_CRL_CHECK\fR has also been enabled, and is otherwise ignored. -.PP -\&\fBX509_V_FLAG_IGNORE_CRITICAL\fR disables critical extension checking. By default -any unhandled critical extensions in certificates or (if checked) CRLs result -in a fatal error. If this flag is set unhandled critical extensions are -ignored. \fB\s-1WARNING\s0\fR setting this option for anything other than debugging -purposes can be a security risk. Finer control over which extensions are -supported can be performed in the verification callback. -.PP -The \fBX509_V_FLAG_X509_STRICT\fR flag disables workarounds for some broken -certificates and makes the verification strictly apply \fBX509\fR rules. -.PP -\&\fBX509_V_FLAG_ALLOW_PROXY_CERTS\fR enables proxy certificate verification. -.PP -\&\fBX509_V_FLAG_POLICY_CHECK\fR enables certificate policy checking, by default -no policy checking is performed. Additional information is sent to the -verification callback relating to policy checking. -.PP -\&\fBX509_V_FLAG_EXPLICIT_POLICY\fR, \fBX509_V_FLAG_INHIBIT_ANY\fR and -\&\fBX509_V_FLAG_INHIBIT_MAP\fR set the \fBrequire explicit policy\fR, \fBinhibit any -policy\fR and \fBinhibit policy mapping\fR flags respectively as defined in -\&\fB\s-1RFC3280\s0\fR. Policy checking is automatically enabled if any of these flags -are set. -.PP -If \fBX509_V_FLAG_NOTIFY_POLICY\fR is set and the policy checking is successful -a special status code is set to the verification callback. This permits it -to examine the valid policy tree and perform additional checks or simply -log it for debugging purposes. -.PP -By default some additional features such as indirect CRLs and CRLs signed by -different keys are disabled. If \fBX509_V_FLAG_EXTENDED_CRL_SUPPORT\fR is set -they are enabled. -.PP -If \fBX509_V_FLAG_USE_DELTAS\fR is set delta CRLs (if present) are used to -determine certificate status. If not set deltas are ignored. -.PP -\&\fBX509_V_FLAG_CHECK_SS_SIGNATURE\fR requests checking the signature of -the last certificate in a chain if the certificate is supposedly self-signed. -This is prohibited and will result in an error if it is a non-conforming \s-1CA\s0 -certificate with key usage restrictions not including the \fIkeyCertSign\fR bit. -By default this check is disabled because it doesn't -add any additional security but in some cases applications might want to -check the signature anyway. A side effect of not checking the self-signature -of such a certificate is that disabled or unsupported message digests used for -the signature are not treated as fatal errors. -.PP -When \fBX509_V_FLAG_TRUSTED_FIRST\fR is set, which is always the case since -OpenSSL 1.1.0, construction of the certificate chain -in \fBX509_verify_cert\fR\|(3) searches the trust store for issuer certificates -before searching the provided untrusted certificates. -Local issuer certificates are often more likely to satisfy local security -requirements and lead to a locally trusted root. -This is especially important when some certificates in the trust store have -explicit trust settings (see \*(L"\s-1TRUST SETTINGS\*(R"\s0 in \fBopenssl\-x509\fR\|(1)). -.PP -The \fBX509_V_FLAG_NO_ALT_CHAINS\fR flag could have been used before OpenSSL 1.1.0 -to suppress checking for alternative chains. -By default, unless \fBX509_V_FLAG_TRUSTED_FIRST\fR is set, when building a -certificate chain, if the first certificate chain found is not trusted, then -OpenSSL will attempt to replace untrusted certificates supplied by the peer -with certificates from the trust store to see if an alternative chain can be -found that is trusted. -As of OpenSSL 1.1.0, with \fBX509_V_FLAG_TRUSTED_FIRST\fR always set, this option -has no effect. -.PP -The \fBX509_V_FLAG_PARTIAL_CHAIN\fR flag causes non-self-signed certificates in the -trust store to be treated as trust anchors, in the same way as self-signed -root \s-1CA\s0 certificates. -This makes it possible to trust self-issued certificates as well as certificates -issued by an intermediate \s-1CA\s0 without having to trust their ancestor root \s-1CA.\s0 -With OpenSSL 1.1.0 and later and \fBX509_V_FLAG_PARTIAL_CHAIN\fR set, chain -construction stops as soon as the first certificate contained in the trust store -is added to the chain, whether that certificate is a self-signed \*(L"root\*(R" -certificate or a not self-signed \*(L"intermediate\*(R" or self-issued certificate. -Thus, when an intermediate certificate is found in the trust store, the -verified chain passed to callbacks may be shorter than it otherwise would -be without the \fBX509_V_FLAG_PARTIAL_CHAIN\fR flag. -.PP -The \fBX509_V_FLAG_NO_CHECK_TIME\fR flag suppresses checking the validity period -of certificates and CRLs against the current time. If \fBX509_VERIFY_PARAM_set_time()\fR -is used to specify a verification time, the check is not suppressed. -.SH "INHERITANCE FLAGS" -.IX Header "INHERITANCE FLAGS" -These flags specify how parameters are \*(L"inherited\*(R" from one structure to -another. -.PP -If \fBX509_VP_FLAG_ONCE\fR is set then the current setting is zeroed -after the next call. -.PP -If \fBX509_VP_FLAG_LOCKED\fR is set then no values are copied. This overrides -all of the following flags. -.PP -If \fBX509_VP_FLAG_DEFAULT\fR is set then anything set in the source is copied -to the destination. Effectively the values in \*(L"to\*(R" become default values -which will be used only if nothing new is set in \*(L"from\*(R". This is the -default. -.PP -If \fBX509_VP_FLAG_OVERWRITE\fR is set then all value are copied across whether -they are set or not. Flags is still Ored though. -.PP -If \fBX509_VP_FLAG_RESET_FLAGS\fR is set then the flags value is copied instead -of ORed. -.SH "NOTES" -.IX Header "NOTES" -The above functions should be used to manipulate verification parameters -instead of functions which work in specific structures such as -\&\fBX509_STORE_CTX_set_flags()\fR which are likely to be deprecated in a future -release. -.SH "BUGS" -.IX Header "BUGS" -Delta \s-1CRL\s0 checking is currently primitive. Only a single delta can be used and -(partly due to limitations of \fBX509_STORE\fR) constructed CRLs are not -maintained. -.PP -If CRLs checking is enable CRLs are expected to be available in the -corresponding \fBX509_STORE\fR structure. No attempt is made to download -CRLs from the \s-1CRL\s0 distribution points extension. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Enable \s-1CRL\s0 checking when performing certificate verification during \s-1SSL\s0 -connections associated with an \fB\s-1SSL_CTX\s0\fR structure \fBctx\fR: -.PP -.Vb 1 -\& X509_VERIFY_PARAM *param; -\& -\& param = X509_VERIFY_PARAM_new(); -\& X509_VERIFY_PARAM_set_flags(param, X509_V_FLAG_CRL_CHECK); -\& SSL_CTX_set1_param(ctx, param); -\& X509_VERIFY_PARAM_free(param); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_verify_cert\fR\|(3), -\&\fBX509_check_host\fR\|(3), -\&\fBX509_check_email\fR\|(3), -\&\fBX509_check_ip\fR\|(3), -\&\fBopenssl\-x509\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_V_FLAG_NO_ALT_CHAINS\fR flag was added in OpenSSL 1.1.0. -The flag \fBX509_V_FLAG_CB_ISSUER_CHECK\fR was deprecated in OpenSSL 1.1.0 -and has no effect. -.PP -The \fBX509_VERIFY_PARAM_get_hostflags()\fR function was added in OpenSSL 1.1.0i. -.PP -The \fBX509_VERIFY_PARAM_get0_host()\fR, \fBX509_VERIFY_PARAM_get0_email()\fR, -and \fBX509_VERIFY_PARAM_get1_ip_asc()\fR functions were added in OpenSSL 3.0. -.PP -The function \fBX509_VERIFY_PARAM_add0_policy()\fR was historically documented as -enabling policy checking however the implementation has never done this. -The documentation was changed to align with the implementation. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2009\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_hostflags.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_hostflags.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_hostflags.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_inh_flags.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_inh_flags.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_inh_flags.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_purpose.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_purpose.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_purpose.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_time.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_time.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_trust.3ossl b/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_trust.3ossl deleted file mode 120000 index a34fc5a9..00000000 --- a/openssl-install/share/man/man3/X509_VERIFY_PARAM_set_trust.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_VERIFY_PARAM_set_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_add1_ext_i2d.3ossl b/openssl-install/share/man/man3/X509_add1_ext_i2d.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_add1_ext_i2d.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_add_cert.3ossl b/openssl-install/share/man/man3/X509_add_cert.3ossl deleted file mode 100644 index 3cb1a146..00000000 --- a/openssl-install/share/man/man3/X509_add_cert.3ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_ADD_CERT 3ossl" -.TH X509_ADD_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_add_cert, -X509_add_certs \- -X509 certificate list addition functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_add_cert(STACK_OF(X509) *sk, X509 *cert, int flags); -\& int X509_add_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_add_cert()\fR adds a certificate \fIcert\fR to the given list \fIsk\fR. -It is an error for the \fIcert\fR argument to be \s-1NULL.\s0 -.PP -\&\fBX509_add_certs()\fR adds a list of certificate \fIcerts\fR to the given list \fIsk\fR. -The \fIcerts\fR argument may be \s-1NULL,\s0 which implies no effect. -It does not modify the list \fIcerts\fR but -in case the \fBX509_ADD_FLAG_UP_REF\fR flag (described below) is set -the reference counters of those of its members added to \fIsk\fR are increased. -.PP -Both these functions have a \fIflags\fR parameter, -which is used to control details of the operation. -.PP -The value \fBX509_ADD_FLAG_DEFAULT\fR, which equals 0, means no special semantics. -.PP -If \fBX509_ADD_FLAG_UP_REF\fR is set then -the reference counts of those certificates added successfully are increased. -.PP -If \fBX509_ADD_FLAG_PREPEND\fR is set then the certificates are prepended to \fIsk\fR. -By default they are appended to \fIsk\fR. -In both cases the original order of the added certificates is preserved. -.PP -If \fBX509_ADD_FLAG_NO_DUP\fR is set then certificates already contained in \fIsk\fR, -which is determined using \fBX509_cmp\fR\|(3), are ignored. -.PP -If \fBX509_ADD_FLAG_NO_SS\fR is set then certificates that are marked self-signed, -which is determined using \fBX509_self_signed\fR\|(3), are ignored. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Both functions return 1 for success and 0 for failure. -.SH "NOTES" -.IX Header "NOTES" -If \fBX509_add_certs()\fR is used with the flags \fBX509_ADD_FLAG_NO_DUP\fR or -\&\fBX509_ADD_FLAG_NO_SS\fR it is advisable to use also \fBX509_ADD_FLAG_UP_REF\fR -because otherwise likely not for all members of the \fIcerts\fR list -the ownership is transferred to the list of certificates \fIsk\fR. -.PP -Care should also be taken in case the \fIcerts\fR argument equals \fIsk\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_cmp\fR\|(3) -\&\fBX509_self_signed\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBX509_add_cert()\fR and \fBX509_add_certs()\fR -were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_add_certs.3ossl b/openssl-install/share/man/man3/X509_add_certs.3ossl deleted file mode 120000 index fc7c359a..00000000 --- a/openssl-install/share/man/man3/X509_add_certs.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_add_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_add_ext.3ossl b/openssl-install/share/man/man3/X509_add_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_add_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_build_chain.3ossl b/openssl-install/share/man/man3/X509_build_chain.3ossl deleted file mode 120000 index 997cc079..00000000 --- a/openssl-install/share/man/man3/X509_build_chain.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_verify_cert.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_chain_up_ref.3ossl b/openssl-install/share/man/man3/X509_chain_up_ref.3ossl deleted file mode 120000 index 43cc5a14..00000000 --- a/openssl-install/share/man/man3/X509_chain_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_check_ca.3ossl b/openssl-install/share/man/man3/X509_check_ca.3ossl deleted file mode 100644 index fc284348..00000000 --- a/openssl-install/share/man/man3/X509_check_ca.3ossl +++ /dev/null @@ -1,180 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CHECK_CA 3ossl" -.TH X509_CHECK_CA 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_check_ca \- check if given certificate is CA certificate -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_check_ca(X509 *cert); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This function checks if given certificate is \s-1CA\s0 certificate (can be used -to sign other certificates). The certificate must be a complete certificate -otherwise an error is returned. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -Function return 0, if it is not \s-1CA\s0 certificate, 1 if it is proper X509v3 -\&\s-1CA\s0 certificate with \fBbasicConstraints\fR extension \s-1CA:TRUE, -3,\s0 if it is self-signed X509 v1 certificate, 4, if it is certificate with -\&\fBkeyUsage\fR extension with bit \fBkeyCertSign\fR set, but without -\&\fBbasicConstraints\fR, and 5 if it has outdated Netscape Certificate Type -extension telling that it is \s-1CA\s0 certificate. -.PP -This function will also return 0 on error. -.PP -Actually, any nonzero value means that this certificate could have been -used to sign other certificates. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_verify_cert\fR\|(3), -\&\fBX509_check_issued\fR\|(3), -\&\fBX509_check_purpose\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_check_email.3ossl b/openssl-install/share/man/man3/X509_check_email.3ossl deleted file mode 120000 index 50bacf32..00000000 --- a/openssl-install/share/man/man3/X509_check_email.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_check_host.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_check_host.3ossl b/openssl-install/share/man/man3/X509_check_host.3ossl deleted file mode 100644 index 115d18c9..00000000 --- a/openssl-install/share/man/man3/X509_check_host.3ossl +++ /dev/null @@ -1,292 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CHECK_HOST 3ossl" -.TH X509_CHECK_HOST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_check_host, X509_check_email, X509_check_ip, X509_check_ip_asc \- X.509 certificate matching -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_check_host(X509 *, const char *name, size_t namelen, -\& unsigned int flags, char **peername); -\& int X509_check_email(X509 *, const char *address, size_t addresslen, -\& unsigned int flags); -\& int X509_check_ip(X509 *, const unsigned char *address, size_t addresslen, -\& unsigned int flags); -\& int X509_check_ip_asc(X509 *, const char *address, unsigned int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The certificate matching functions are used to check whether a -certificate matches a given hostname, email address, or \s-1IP\s0 address. -The validity of the certificate and its trust level has to be checked by -other means. -.PP -\&\fBX509_check_host()\fR checks if the certificate Subject Alternative -Name (\s-1SAN\s0) or Subject CommonName (\s-1CN\s0) matches the specified hostname, -which must be encoded in the preferred name syntax described -in section 3.5 of \s-1RFC 1034.\s0 By default, wildcards are supported -and they match only in the left-most label; but they may match -part of that label with an explicit prefix or suffix. For example, -by default, the host \fBname\fR \*(L"www.example.com\*(R" would match a -certificate with a \s-1SAN\s0 or \s-1CN\s0 value of \*(L"*.example.com\*(R", \*(L"w*.example.com\*(R" -or \*(L"*w.example.com\*(R". -.PP -Per section 6.4.2 of \s-1RFC 6125,\s0 \fBname\fR values representing international -domain names must be given in A\-label form. The \fBnamelen\fR argument -must be the number of characters in the name string or zero in which -case the length is calculated with strlen(\fBname\fR). When \fBname\fR starts -with a dot (e.g. \*(L".example.com\*(R"), it will be matched by a certificate -valid for any sub-domain of \fBname\fR, (see also -\&\fBX509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS\fR below). -.PP -When the certificate is matched, and \fBpeername\fR is not \s-1NULL,\s0 a -pointer to a copy of the matching \s-1SAN\s0 or \s-1CN\s0 from the peer certificate -is stored at the address passed in \fBpeername\fR. The application -is responsible for freeing the peername via \fBOPENSSL_free()\fR when it -is no longer needed. -.PP -\&\fBX509_check_email()\fR checks if the certificate matches the specified -email \fBaddress\fR. The mailbox syntax of \s-1RFC 822\s0 is supported, -comments are not allowed, and no attempt is made to normalize quoted -characters. The mailbox syntax of \s-1RFC 6531\s0 is supported for -SmtpUTF8Mailbox address in subjectAltName according to \s-1RFC 8398,\s0 -with similar limitations as for \s-1RFC 822\s0 syntax, and no attempt -is made to convert from A\-label to U\-label before comparison. -The \fBaddresslen\fR argument must be the number of -characters in the address string or zero in which case the length -is calculated with strlen(\fBaddress\fR). -.PP -\&\fBX509_check_ip()\fR checks if the certificate matches a specified IPv4 or -IPv6 address. The \fBaddress\fR array is in binary format, in network -byte order. The length is either 4 (IPv4) or 16 (IPv6). Only -explicitly marked addresses in the certificates are considered; \s-1IP\s0 -addresses stored in \s-1DNS\s0 names and Common Names are ignored. There are -currently no \fBflags\fR that would affect the behavior of this call. -.PP -\&\fBX509_check_ip_asc()\fR is similar, except that the NUL-terminated -string \fBaddress\fR is first converted to the internal representation. -.PP -The \fBflags\fR argument is usually 0. It can be the bitwise \s-1OR\s0 of the -flags: -.IP "\fBX509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT\fR," 4 -.IX Item "X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT," -.PD 0 -.IP "\fBX509_CHECK_FLAG_NEVER_CHECK_SUBJECT\fR," 4 -.IX Item "X509_CHECK_FLAG_NEVER_CHECK_SUBJECT," -.IP "\fBX509_CHECK_FLAG_NO_WILDCARDS\fR," 4 -.IX Item "X509_CHECK_FLAG_NO_WILDCARDS," -.IP "\fBX509_CHECK_FLAG_NO_PARTIAL_WILDCARDS\fR," 4 -.IX Item "X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS," -.IP "\fBX509_CHECK_FLAG_MULTI_LABEL_WILDCARDS\fR." 4 -.IX Item "X509_CHECK_FLAG_MULTI_LABEL_WILDCARDS." -.IP "\fBX509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS\fR." 4 -.IX Item "X509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS." -.PD -.PP -The \fBX509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT\fR flag causes the function -to consider the subject \s-1DN\s0 even if the certificate contains at least -one subject alternative name of the right type (\s-1DNS\s0 name or email -address as appropriate); the default is to ignore the subject \s-1DN\s0 -when at least one corresponding subject alternative names is present. -.PP -The \fBX509_CHECK_FLAG_NEVER_CHECK_SUBJECT\fR flag causes the function to never -consider the subject \s-1DN\s0 even if the certificate contains no subject alternative -names of the right type (\s-1DNS\s0 name or email address as appropriate); the default -is to use the subject \s-1DN\s0 when no corresponding subject alternative names are -present. -If both \fBX509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT\fR and -\&\fBX509_CHECK_FLAG_NEVER_CHECK_SUBJECT\fR are specified, the latter takes -precedence and the subject \s-1DN\s0 is not checked for matching names. -.PP -If set, \fBX509_CHECK_FLAG_NO_WILDCARDS\fR disables wildcard -expansion; this only applies to \fBX509_check_host\fR. -.PP -If set, \fBX509_CHECK_FLAG_NO_PARTIAL_WILDCARDS\fR suppresses support -for \*(L"*\*(R" as wildcard pattern in labels that have a prefix or suffix, -such as: \*(L"www*\*(R" or \*(L"*www\*(R"; this only applies to \fBX509_check_host\fR. -.PP -If set, \fBX509_CHECK_FLAG_MULTI_LABEL_WILDCARDS\fR allows a \*(L"*\*(R" that -constitutes the complete label of a \s-1DNS\s0 name (e.g. \*(L"*.example.com\*(R") -to match more than one label in \fBname\fR; this flag only applies -to \fBX509_check_host\fR. -.PP -If set, \fBX509_CHECK_FLAG_SINGLE_LABEL_SUBDOMAINS\fR restricts \fBname\fR -values which start with \*(L".\*(R", that would otherwise match any sub-domain -in the peer certificate, to only match direct child sub-domains. -Thus, for instance, with this flag set a \fBname\fR of \*(L".example.com\*(R" -would match a peer certificate with a \s-1DNS\s0 name of \*(L"www.example.com\*(R", -but would not match a peer certificate with a \s-1DNS\s0 name of -\&\*(L"www.sub.example.com\*(R"; this flag only applies to \fBX509_check_host\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The functions return 1 for a successful match, 0 for a failed match -and \-1 for an internal error: typically a memory allocation failure -or an \s-1ASN.1\s0 decoding error. -.PP -All functions can also return \-2 if the input is malformed. For example, -\&\fBX509_check_host()\fR returns \-2 if the provided \fBname\fR contains embedded -NULs. -.SH "NOTES" -.IX Header "NOTES" -Applications are encouraged to use \fBX509_VERIFY_PARAM_set1_host()\fR -rather than explicitly calling \fBX509_check_host\fR\|(3). Hostname -checks may be out of scope with the \s-1\fBDANE\-EE\s0\fR\|(3) certificate usage, -and the internal checks will be suppressed as appropriate when -\&\s-1DANE\s0 support is enabled. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_get_verify_result\fR\|(3), -\&\fBX509_VERIFY_PARAM_set1_host\fR\|(3), -\&\fBX509_VERIFY_PARAM_add1_host\fR\|(3), -\&\fBX509_VERIFY_PARAM_set1_email\fR\|(3), -\&\fBX509_VERIFY_PARAM_set1_ip\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.0.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2012\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_check_ip.3ossl b/openssl-install/share/man/man3/X509_check_ip.3ossl deleted file mode 120000 index 50bacf32..00000000 --- a/openssl-install/share/man/man3/X509_check_ip.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_check_host.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_check_ip_asc.3ossl b/openssl-install/share/man/man3/X509_check_ip_asc.3ossl deleted file mode 120000 index 50bacf32..00000000 --- a/openssl-install/share/man/man3/X509_check_ip_asc.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_check_host.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_check_issued.3ossl b/openssl-install/share/man/man3/X509_check_issued.3ossl deleted file mode 100644 index a63d4cb6..00000000 --- a/openssl-install/share/man/man3/X509_check_issued.3ossl +++ /dev/null @@ -1,177 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CHECK_ISSUED 3ossl" -.TH X509_CHECK_ISSUED 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_check_issued \- checks if certificate is apparently issued by another -certificate -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_check_issued(X509 *issuer, X509 *subject); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_check_issued()\fR checks if certificate \fIsubject\fR was apparently issued -using (\s-1CA\s0) certificate \fIissuer\fR. This function takes into account not only -matching of the issuer field of \fIsubject\fR with the subject field of \fIissuer\fR, -but also compares all sub-fields of the \fBauthorityKeyIdentifier\fR extension of -\&\fIsubject\fR, as far as present, with the respective \fBsubjectKeyIdentifier\fR, -serial number, and issuer fields of \fIissuer\fR, as far as present. It also checks -if the \fBkeyUsage\fR field (if present) of \fIissuer\fR allows certificate signing. -It does not actually check the certificate signature. An error is returned -if the \fIissuer\fR or the \fIsubject\fR are incomplete certificates. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_check_issued()\fR returns \fBX509_V_OK\fR if all checks are successful -or some \fBX509_V_ERR*\fR constant to indicate an error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_verify_cert\fR\|(3), \fBX509_verify\fR\|(3), \fBX509_check_ca\fR\|(3), -\&\fBopenssl\-verify\fR\|(1), \fBX509_self_signed\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_check_private_key.3ossl b/openssl-install/share/man/man3/X509_check_private_key.3ossl deleted file mode 100644 index cb97aa4f..00000000 --- a/openssl-install/share/man/man3/X509_check_private_key.3ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CHECK_PRIVATE_KEY 3ossl" -.TH X509_CHECK_PRIVATE_KEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_check_private_key, X509_REQ_check_private_key \- check the consistency -of a private key with the public key in an X509 certificate or certificate -request -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_check_private_key(const X509 *cert, EVP_PKEY *pkey); -\& -\& int X509_REQ_check_private_key(X509_REQ *req, EVP_PKEY *pkey); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_check_private_key()\fR function checks the consistency of private -key \fIpkey\fR with the public key in \fIcert\fR. -.PP -\&\fBX509_REQ_check_private_key()\fR is equivalent to \fBX509_check_private_key()\fR -except that \fIreq\fR represents a certificate request of structure \fBX509_REQ\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_check_private_key()\fR and \fBX509_REQ_check_private_key()\fR return 1 if -the keys match each other, and 0 if not. -.PP -If the key is invalid or an error occurred, the reason code can be -obtained using \fBERR_get_error\fR\|(3). -.SH "BUGS" -.IX Header "BUGS" -The \fBX509_check_private_key()\fR and \fBX509_REQ_check_private_key()\fR functions -do not check if \fIpkey\fR itself is indeed a private key or not. -They merely compare the public materials (e.g., exponent and modulus of an \s-1RSA\s0 -key) and/or key parameters (e.g. \s-1EC\s0 params of an \s-1EC\s0 key) of a key pair. -So they also return success if \fIpkey\fR is a matching public key. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_check_purpose.3ossl b/openssl-install/share/man/man3/X509_check_purpose.3ossl deleted file mode 100644 index 22575839..00000000 --- a/openssl-install/share/man/man3/X509_check_purpose.3ossl +++ /dev/null @@ -1,209 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CHECK_PURPOSE 3ossl" -.TH X509_CHECK_PURPOSE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_check_purpose \- Check the purpose of a certificate -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_check_purpose(X509 *x, int id, int ca); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This function checks if certificate \fIx\fR was created with the purpose -represented by \fIid\fR. If \fIca\fR is nonzero, then certificate \fIx\fR is -checked to determine if it's a possible \s-1CA\s0 with various levels of certainty -possibly returned. The certificate \fIx\fR must be a complete certificate -otherwise the function returns an error. -.PP -Below are the potential \s-1ID\s0's that can be checked: -.PP -.Vb 10 -\& # define X509_PURPOSE_SSL_CLIENT 1 -\& # define X509_PURPOSE_SSL_SERVER 2 -\& # define X509_PURPOSE_NS_SSL_SERVER 3 -\& # define X509_PURPOSE_SMIME_SIGN 4 -\& # define X509_PURPOSE_SMIME_ENCRYPT 5 -\& # define X509_PURPOSE_CRL_SIGN 6 -\& # define X509_PURPOSE_ANY 7 -\& # define X509_PURPOSE_OCSP_HELPER 8 -\& # define X509_PURPOSE_TIMESTAMP_SIGN 9 -\& # define X509_PURPOSE_CODE_SIGN 10 -.Ve -.PP -The checks performed take into account the X.509 extensions -keyUsage, extendedKeyUsage, and basicConstraints. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -For non-CA checks -.IP "\-1 an error condition has occurred" 4 -.IX Item "-1 an error condition has occurred" -.PD 0 -.IP " 1 if the certificate was created to perform the purpose represented by \fIid\fR" 4 -.IX Item " 1 if the certificate was created to perform the purpose represented by id" -.IP " 0 if the certificate was not created to perform the purpose represented by \fIid\fR" 4 -.IX Item " 0 if the certificate was not created to perform the purpose represented by id" -.PD -.PP -For \s-1CA\s0 checks the below integers could be returned with the following meanings: -.IP "\-1 an error condition has occurred" 4 -.IX Item "-1 an error condition has occurred" -.PD 0 -.IP " 0 not a \s-1CA\s0 or does not have the purpose represented by \fIid\fR" 4 -.IX Item " 0 not a CA or does not have the purpose represented by id" -.IP " 1 is a \s-1CA.\s0" 4 -.IX Item " 1 is a CA." -.IP " 2 Only possible in old versions of openSSL when basicConstraints are absent. New versions will not return this value. May be a \s-1CA\s0" 4 -.IX Item " 2 Only possible in old versions of openSSL when basicConstraints are absent. New versions will not return this value. May be a CA" -.IP " 3 basicConstraints absent but self signed V1." 4 -.IX Item " 3 basicConstraints absent but self signed V1." -.IP " 4 basicConstraints absent but keyUsage present and keyCertSign asserted." 4 -.IX Item " 4 basicConstraints absent but keyUsage present and keyCertSign asserted." -.IP " 5 legacy Netscape specific \s-1CA\s0 Flags present" 4 -.IX Item " 5 legacy Netscape specific CA Flags present" -.PD -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use this -file except in compliance with the License. You can obtain a copy in the file -\&\s-1LICENSE\s0 in the source distribution or at . diff --git a/openssl-install/share/man/man3/X509_cmp.3ossl b/openssl-install/share/man/man3/X509_cmp.3ossl deleted file mode 100644 index 2cf34094..00000000 --- a/openssl-install/share/man/man3/X509_cmp.3ossl +++ /dev/null @@ -1,217 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CMP 3ossl" -.TH X509_CMP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_cmp, X509_NAME_cmp, -X509_issuer_and_serial_cmp, X509_issuer_name_cmp, X509_subject_name_cmp, -X509_CRL_cmp, X509_CRL_match -\&\- compare X509 certificates and related values -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_cmp(const X509 *a, const X509 *b); -\& int X509_NAME_cmp(const X509_NAME *a, const X509_NAME *b); -\& int X509_issuer_and_serial_cmp(const X509 *a, const X509 *b); -\& int X509_issuer_name_cmp(const X509 *a, const X509 *b); -\& int X509_subject_name_cmp(const X509 *a, const X509 *b); -\& int X509_CRL_cmp(const X509_CRL *a, const X509_CRL *b); -\& int X509_CRL_match(const X509_CRL *a, const X509_CRL *b); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This set of functions are used to compare X509 objects, including X509 -certificates, X509 \s-1CRL\s0 objects and various values in an X509 certificate. -.PP -The \fBX509_cmp()\fR function compares two \fBX509\fR objects indicated by parameters -\&\fIa\fR and \fIb\fR. The comparison is based on the \fBmemcmp\fR result of the hash -values of two \fBX509\fR objects and the canonical (\s-1DER\s0) encoding values. -.PP -The \fBX509_NAME_cmp()\fR function compares two \fBX509_NAME\fR objects indicated by -parameters \fIa\fR and \fIb\fR, any of which may be \s-1NULL.\s0 -The comparison is based on the \fBmemcmp\fR result of the -canonical (\s-1DER\s0) encoding values of the two objects using \fBi2d_X509_NAME\fR\|(3). -This procedure adheres to the matching rules for Distinguished Names (\s-1DN\s0) -given in \s-1RFC 4517\s0 section 4.2.15 and \s-1RFC 5280\s0 section 7.1. -In particular, the order of Relative Distinguished Names (RDNs) is relevant. -On the other hand, if an \s-1RDN\s0 is multi-valued, i.e., it contains a set of -AttributeValueAssertions (AVAs), its members are effectively not ordered. -.PP -The \fBX509_issuer_and_serial_cmp()\fR function compares the serial number and issuer -values in the given \fBX509\fR objects \fIa\fR and \fIb\fR. -.PP -The \fBX509_issuer_name_cmp()\fR, \fBX509_subject_name_cmp()\fR and \fBX509_CRL_cmp()\fR functions -are effectively wrappers of the \fBX509_NAME_cmp()\fR function. These functions compare -issuer names and subject names of the objects, or issuers of \fBX509_CRL\fR -objects, respectively. -.IX Xref "509" -.PP -The \fBX509_CRL_match()\fR function compares two \fBX509_CRL\fR objects. Unlike the -\&\fBX509_CRL_cmp()\fR function, this function compares the whole \s-1CRL\s0 content instead -of just the issuer name. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBX509\fR comparison functions return \fB\-1\fR, \fB0\fR, or \fB1\fR if object \fIa\fR is -found to be less than, to match, or be greater than object \fIb\fR, respectively. -.PP -\&\fBX509_NAME_cmp()\fR, \fBX509_issuer_and_serial_cmp()\fR, \fBX509_issuer_name_cmp()\fR, -\&\fBX509_subject_name_cmp()\fR, \fBX509_CRL_cmp()\fR, and \fBX509_CRL_match()\fR -may return \fB\-2\fR to indicate an error. -.SH "NOTES" -.IX Header "NOTES" -These functions in fact utilize the underlying \fBmemcmp\fR of the C library to do -the comparison job. Data to be compared varies from \s-1DER\s0 encoding data, hash -value or \fB\s-1ASN1_STRING\s0\fR. The sign of the comparison can be used to order the -objects but it does not have a special meaning in some cases. -.PP -\&\fBX509_NAME_cmp()\fR and wrappers utilize the value \fB\-2\fR to indicate errors in some -circumstances, which could cause confusion for the applications. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBi2d_X509_NAME\fR\|(3), \fBi2d_X509\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_cmp_current_time.3ossl b/openssl-install/share/man/man3/X509_cmp_current_time.3ossl deleted file mode 120000 index cdeff4ec..00000000 --- a/openssl-install/share/man/man3/X509_cmp_current_time.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_cmp_time.3ossl b/openssl-install/share/man/man3/X509_cmp_time.3ossl deleted file mode 100644 index 74a9f44c..00000000 --- a/openssl-install/share/man/man3/X509_cmp_time.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_CMP_TIME 3ossl" -.TH X509_CMP_TIME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_cmp_time, X509_cmp_current_time, X509_cmp_timeframe, -X509_time_adj, X509_time_adj_ex, X509_gmtime_adj -\&\- X509 time functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 8 -\& int X509_cmp_time(const ASN1_TIME *asn1_time, time_t *in_tm); -\& int X509_cmp_current_time(const ASN1_TIME *asn1_time); -\& int X509_cmp_timeframe(const X509_VERIFY_PARAM *vpm, -\& const ASN1_TIME *start, const ASN1_TIME *end); -\& ASN1_TIME *X509_time_adj(ASN1_TIME *asn1_time, long offset_sec, time_t *in_tm); -\& ASN1_TIME *X509_time_adj_ex(ASN1_TIME *asn1_time, int offset_day, long -\& offset_sec, time_t *in_tm); -\& ASN1_TIME *X509_gmtime_adj(ASN1_TIME *asn1_time, long offset_sec); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_cmp_time()\fR compares the \s-1ASN1_TIME\s0 in \fIasn1_time\fR with the time -in . -.PP -\&\fBX509_cmp_current_time()\fR compares the \s-1ASN1_TIME\s0 in -\&\fIasn1_time\fR with the current time, expressed as time_t. -.PP -\&\fBX509_cmp_timeframe()\fR compares the given time period with the reference time -included in the verification parameters \fIvpm\fR if they are not \s-1NULL\s0 and contain -\&\fBX509_V_FLAG_USE_CHECK_TIME\fR; else the current time is used as reference time. -.PP -\&\fBX509_time_adj_ex()\fR sets the \s-1ASN1_TIME\s0 structure \fIasn1_time\fR to the time -\&\fIoffset_day\fR and \fIoffset_sec\fR after \fIin_tm\fR. -.PP -\&\fBX509_time_adj()\fR sets the \s-1ASN1_TIME\s0 structure \fIasn1_time\fR to the time -\&\fIoffset_sec\fR after \fIin_tm\fR. This method can only handle second -offsets up to the capacity of long, so the newer \fBX509_time_adj_ex()\fR -\&\s-1API\s0 should be preferred. -.PP -In both methods, if \fIasn1_time\fR is \s-1NULL,\s0 a new \s-1ASN1_TIME\s0 structure -is allocated and returned. -.PP -In all methods, if \fIin_tm\fR is \s-1NULL,\s0 the current time, expressed as -time_t, is used. -.PP -\&\fIasn1_time\fR must satisfy the \s-1ASN1_TIME\s0 format mandated by \s-1RFC 5280,\s0 -i.e., its format must be either \s-1YYMMDDHHMMSSZ\s0 or \s-1YYYYMMDDHHMMSSZ.\s0 -.PP -\&\fBX509_gmtime_adj()\fR sets the \s-1ASN1_TIME\s0 structure \fIasn1_time\fR to the time -\&\fIoffset_sec\fR after the current time. It is equivalent to calling -\&\fBX509_time_adj()\fR with the last parameter as \s-1NULL.\s0 -.SH "BUGS" -.IX Header "BUGS" -Unlike many standard comparison functions, \fBX509_cmp_time()\fR and -\&\fBX509_cmp_current_time()\fR return 0 on error. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_cmp_time()\fR and \fBX509_cmp_current_time()\fR return \-1 if \fIasn1_time\fR -is earlier than, or equal to, \fIin_tm\fR (resp. current time), and 1 -otherwise. These methods return 0 on error. -.PP -\&\fBX509_cmp_timeframe()\fR returns 0 if \fIvpm\fR is not \s-1NULL\s0 and the verification -parameters do not contain \fBX509_V_FLAG_USE_CHECK_TIME\fR -but do contain \fBX509_V_FLAG_NO_CHECK_TIME\fR. Otherwise it returns -1 if the end time is not \s-1NULL\s0 and the reference time (which has determined as -stated above) is past the end time, \-1 if the start time is not \s-1NULL\s0 and the -reference time is before, else 0 to indicate that the reference time is in range -(implying that the end time is not before the start time if both are present). -.PP -\&\fBX509_time_adj()\fR, \fBX509_time_adj_ex()\fR and \fBX509_gmtime_adj()\fR return a pointer to -the updated \s-1ASN1_TIME\s0 structure, and \s-1NULL\s0 on error. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_cmp_timeframe()\fR was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_cmp_timeframe.3ossl b/openssl-install/share/man/man3/X509_cmp_timeframe.3ossl deleted file mode 120000 index cdeff4ec..00000000 --- a/openssl-install/share/man/man3/X509_cmp_timeframe.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_delete_ext.3ossl b/openssl-install/share/man/man3/X509_delete_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_delete_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_digest.3ossl b/openssl-install/share/man/man3/X509_digest.3ossl deleted file mode 100644 index 8ef23d41..00000000 --- a/openssl-install/share/man/man3/X509_digest.3ossl +++ /dev/null @@ -1,222 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_DIGEST 3ossl" -.TH X509_DIGEST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_digest, -X509_digest_sig, -X509_CRL_digest, -X509_pubkey_digest, -X509_NAME_digest, -X509_REQ_digest, -PKCS7_ISSUER_AND_SERIAL_digest -\&\- get digest of various objects -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_digest(const X509 *data, const EVP_MD *type, unsigned char *md, -\& unsigned int *len); -\& ASN1_OCTET_STRING *X509_digest_sig(const X509 *cert, -\& EVP_MD **md_used, int *md_is_fallback); -\& -\& int X509_CRL_digest(const X509_CRL *data, const EVP_MD *type, unsigned char *md, -\& unsigned int *len); -\& -\& int X509_pubkey_digest(const X509 *data, const EVP_MD *type, -\& unsigned char *md, unsigned int *len); -\& -\& int X509_REQ_digest(const X509_REQ *data, const EVP_MD *type, -\& unsigned char *md, unsigned int *len); -\& -\& int X509_NAME_digest(const X509_NAME *data, const EVP_MD *type, -\& unsigned char *md, unsigned int *len); -\& -\& #include -\& -\& int PKCS7_ISSUER_AND_SERIAL_digest(PKCS7_ISSUER_AND_SERIAL *data, -\& const EVP_MD *type, unsigned char *md, -\& unsigned int *len); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_digest_sig()\fR calculates a digest of the given certificate \fIcert\fR -using the same hash algorithm as in its signature, if the digest -is an integral part of the certificate signature algorithm identifier. -Otherwise, a fallback hash algorithm is determined as follows: -\&\s-1SHA512\s0 if the signature algorithm is \s-1ED25519, -SHAKE256\s0 if it is \s-1ED448,\s0 otherwise \s-1SHA256.\s0 -The output parameters are assigned as follows. -Unless \fImd_used\fR is \s-1NULL,\s0 the hash algorithm used is provided -in \fI*md_used\fR and must be freed by the caller (if it is not \s-1NULL\s0). -Unless \fImd_is_fallback\fR is \s-1NULL,\s0 -the \fI*md_is_fallback\fR is set to 1 if the hash algorithm used is a fallback, -otherwise to 0. -.PP -\&\fBX509_pubkey_digest()\fR returns a digest of the \s-1DER\s0 representation of the public -key in the specified X509 \fIdata\fR object. -.PP -All other functions described here return a digest of the \s-1DER\s0 representation -of their entire \fIdata\fR objects. -.PP -The \fItype\fR parameter specifies the digest to -be used, such as \fBEVP_sha1()\fR. The \fImd\fR is a pointer to the buffer where the -digest will be copied and is assumed to be large enough; the constant -\&\fB\s-1EVP_MAX_MD_SIZE\s0\fR is suggested. The \fIlen\fR parameter, if not \s-1NULL,\s0 points -to a place where the digest size will be stored. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_digest_sig()\fR returns an \s-1ASN1_OCTET_STRING\s0 pointer on success, else \s-1NULL.\s0 -.PP -All other functions described here return 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_sha1\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_digest_sig()\fR function was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_digest_sig.3ossl b/openssl-install/share/man/man3/X509_digest_sig.3ossl deleted file mode 120000 index c2b39912..00000000 --- a/openssl-install/share/man/man3/X509_digest_sig.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_digest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_dup.3ossl b/openssl-install/share/man/man3/X509_dup.3ossl deleted file mode 100644 index e7b34d64..00000000 --- a/openssl-install/share/man/man3/X509_dup.3ossl +++ /dev/null @@ -1,590 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_DUP 3ossl" -.TH X509_DUP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -DECLARE_ASN1_FUNCTIONS, -IMPLEMENT_ASN1_FUNCTIONS, -ASN1_ITEM, -ACCESS_DESCRIPTION_free, -ACCESS_DESCRIPTION_new, -ADMISSIONS_free, -ADMISSIONS_new, -ADMISSION_SYNTAX_free, -ADMISSION_SYNTAX_new, -ASIdOrRange_free, -ASIdOrRange_new, -ASIdentifierChoice_free, -ASIdentifierChoice_new, -ASIdentifiers_free, -ASIdentifiers_new, -ASRange_free, -ASRange_new, -AUTHORITY_INFO_ACCESS_free, -AUTHORITY_INFO_ACCESS_new, -AUTHORITY_KEYID_free, -AUTHORITY_KEYID_new, -BASIC_CONSTRAINTS_free, -BASIC_CONSTRAINTS_new, -CERTIFICATEPOLICIES_free, -CERTIFICATEPOLICIES_new, -CMS_ContentInfo_free, -CMS_ContentInfo_new, -CMS_ContentInfo_new_ex, -CMS_ContentInfo_print_ctx, -CMS_EnvelopedData_it, -CMS_ReceiptRequest_free, -CMS_ReceiptRequest_new, -CMS_SignedData_free, -CMS_SignedData_new, -CRL_DIST_POINTS_free, -CRL_DIST_POINTS_new, -DIRECTORYSTRING_free, -DIRECTORYSTRING_new, -DISPLAYTEXT_free, -DISPLAYTEXT_new, -DIST_POINT_NAME_free, -DIST_POINT_NAME_new, -DIST_POINT_NAME_dup, -DIST_POINT_free, -DIST_POINT_new, -DSAparams_dup, -ECPARAMETERS_free, -ECPARAMETERS_new, -ECPKPARAMETERS_free, -ECPKPARAMETERS_new, -EDIPARTYNAME_free, -EDIPARTYNAME_new, -ESS_CERT_ID_dup, -ESS_CERT_ID_free, -ESS_CERT_ID_new, -ESS_CERT_ID_V2_dup, -ESS_CERT_ID_V2_free, -ESS_CERT_ID_V2_new, -ESS_ISSUER_SERIAL_dup, -ESS_ISSUER_SERIAL_free, -ESS_ISSUER_SERIAL_new, -ESS_SIGNING_CERT_dup, -ESS_SIGNING_CERT_free, -ESS_SIGNING_CERT_it, -ESS_SIGNING_CERT_new, -ESS_SIGNING_CERT_V2_dup, -ESS_SIGNING_CERT_V2_free, -ESS_SIGNING_CERT_V2_it, -ESS_SIGNING_CERT_V2_new, -EXTENDED_KEY_USAGE_free, -EXTENDED_KEY_USAGE_new, -GENERAL_NAMES_free, -GENERAL_NAMES_new, -GENERAL_NAME_dup, -GENERAL_NAME_free, -GENERAL_NAME_new, -GENERAL_SUBTREE_free, -GENERAL_SUBTREE_new, -OSSL_IETF_ATTR_SYNTAX_free, -OSSL_IETF_ATTR_SYNTAX_it, -OSSL_IETF_ATTR_SYNTAX_new, -IPAddressChoice_free, -IPAddressChoice_new, -IPAddressFamily_free, -IPAddressFamily_new, -IPAddressOrRange_free, -IPAddressOrRange_new, -IPAddressRange_free, -IPAddressRange_new, -ISSUER_SIGN_TOOL_free, -ISSUER_SIGN_TOOL_it, -ISSUER_SIGN_TOOL_new, -ISSUING_DIST_POINT_free, -ISSUING_DIST_POINT_it, -ISSUING_DIST_POINT_new, -NAME_CONSTRAINTS_free, -NAME_CONSTRAINTS_new, -NAMING_AUTHORITY_free, -NAMING_AUTHORITY_new, -NETSCAPE_CERT_SEQUENCE_free, -NETSCAPE_CERT_SEQUENCE_new, -NETSCAPE_SPKAC_free, -NETSCAPE_SPKAC_new, -NETSCAPE_SPKI_free, -NETSCAPE_SPKI_new, -NOTICEREF_free, -NOTICEREF_new, -OCSP_BASICRESP_free, -OCSP_BASICRESP_new, -OCSP_CERTID_dup, -OCSP_CERTID_new, -OCSP_CERTSTATUS_free, -OCSP_CERTSTATUS_new, -OCSP_CRLID_free, -OCSP_CRLID_new, -OCSP_ONEREQ_free, -OCSP_ONEREQ_new, -OCSP_REQINFO_free, -OCSP_REQINFO_new, -OCSP_RESPBYTES_free, -OCSP_RESPBYTES_new, -OCSP_RESPDATA_free, -OCSP_RESPDATA_new, -OCSP_RESPID_free, -OCSP_RESPID_new, -OCSP_RESPONSE_new, -OCSP_REVOKEDINFO_free, -OCSP_REVOKEDINFO_new, -OCSP_SERVICELOC_free, -OCSP_SERVICELOC_new, -OCSP_SIGNATURE_free, -OCSP_SIGNATURE_new, -OCSP_SINGLERESP_free, -OCSP_SINGLERESP_new, -OSSL_ATTRIBUTES_SYNTAX_free, -OSSL_ATTRIBUTES_SYNTAX_it, -OSSL_ATTRIBUTES_SYNTAX_new, -OSSL_BASIC_ATTR_CONSTRAINTS_free, -OSSL_BASIC_ATTR_CONSTRAINTS_it, -OSSL_BASIC_ATTR_CONSTRAINTS_new, -OSSL_CMP_ATAVS_new, -OSSL_CMP_ATAVS_free, -OSSL_CMP_ATAVS_it, -OSSL_CMP_CRLSTATUS_free, -OSSL_CMP_ITAV_dup, -OSSL_CMP_ITAV_free, -OSSL_CMP_MSG_dup, -OSSL_CMP_MSG_it, -OSSL_CMP_MSG_free, -OSSL_CMP_PKIHEADER_free, -OSSL_CMP_PKIHEADER_it, -OSSL_CMP_PKIHEADER_new, -OSSL_CMP_PKISI_dup, -OSSL_CMP_PKISI_free, -OSSL_CMP_PKISI_it, -OSSL_CMP_PKISI_new, -OSSL_CMP_PKISTATUS_it, -OSSL_CRMF_CERTID_dup, -OSSL_CRMF_CERTID_free, -OSSL_CRMF_CERTID_it, -OSSL_CRMF_CERTID_new, -OSSL_CRMF_CERTTEMPLATE_free, -OSSL_CRMF_CERTTEMPLATE_it, -OSSL_CRMF_CERTTEMPLATE_new, -OSSL_CRMF_CERTTEMPLATE_dup, -OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup, -OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free, -OSSL_CRMF_ENCRYPTEDVALUE_free, -OSSL_CRMF_ENCRYPTEDVALUE_it, -OSSL_CRMF_ENCRYPTEDVALUE_new, -OSSL_CRMF_MSGS_free, -OSSL_CRMF_MSGS_it, -OSSL_CRMF_MSGS_new, -OSSL_CRMF_MSG_dup, -OSSL_CRMF_MSG_free, -OSSL_CRMF_MSG_it, -OSSL_CRMF_MSG_new, -OSSL_CRMF_PBMPARAMETER_free, -OSSL_CRMF_PBMPARAMETER_it, -OSSL_CRMF_PBMPARAMETER_new, -OSSL_CRMF_PKIPUBLICATIONINFO_free, -OSSL_CRMF_PKIPUBLICATIONINFO_it, -OSSL_CRMF_PKIPUBLICATIONINFO_new, -OSSL_CRMF_SINGLEPUBINFO_free, -OSSL_CRMF_SINGLEPUBINFO_it, -OSSL_CRMF_SINGLEPUBINFO_new, -OSSL_TARGET_CERT_free, -OSSL_TARGET_CERT_it, -OSSL_TARGET_CERT_new, -OSSL_TARGET_free, -OSSL_TARGET_it, -OSSL_TARGET_new, -OSSL_TARGETING_INFORMATION_free, -OSSL_TARGETING_INFORMATION_it, -OSSL_TARGETING_INFORMATION_new, -OSSL_TARGETS_free, -OSSL_TARGETS_it, -OSSL_TARGETS_new, -OSSL_IETF_ATTR_SYNTAX_VALUE_free, -OSSL_IETF_ATTR_SYNTAX_VALUE_it, -OSSL_IETF_ATTR_SYNTAX_VALUE_new, -OSSL_ISSUER_SERIAL_free, -OSSL_ISSUER_SERIAL_new, -OSSL_OBJECT_DIGEST_INFO_free, -OSSL_OBJECT_DIGEST_INFO_new, -OSSL_USER_NOTICE_SYNTAX_free, -OSSL_USER_NOTICE_SYNTAX_new, -OSSL_USER_NOTICE_SYNTAX_it, -OTHERNAME_free, -OTHERNAME_new, -PBE2PARAM_free, -PBE2PARAM_new, -PBEPARAM_free, -PBEPARAM_new, -PBKDF2PARAM_free, -PBKDF2PARAM_new, -PBMAC1PARAM_free, -PBMAC1PARAM_it, -PBMAC1PARAM_new, -PKCS12_BAGS_free, -PKCS12_BAGS_new, -PKCS12_MAC_DATA_free, -PKCS12_MAC_DATA_new, -PKCS12_SAFEBAG_free, -PKCS12_SAFEBAG_new, -PKCS12_free, -PKCS12_new, -PKCS7_DIGEST_free, -PKCS7_DIGEST_new, -PKCS7_ENCRYPT_free, -PKCS7_ENCRYPT_new, -PKCS7_ENC_CONTENT_free, -PKCS7_ENC_CONTENT_new, -PKCS7_ENVELOPE_free, -PKCS7_ENVELOPE_new, -PKCS7_ISSUER_AND_SERIAL_free, -PKCS7_ISSUER_AND_SERIAL_new, -PKCS7_RECIP_INFO_free, -PKCS7_RECIP_INFO_new, -PKCS7_SIGNED_free, -PKCS7_SIGNED_new, -PKCS7_SIGNER_INFO_free, -PKCS7_SIGNER_INFO_new, -PKCS7_SIGN_ENVELOPE_free, -PKCS7_SIGN_ENVELOPE_new, -PKCS7_dup, -PKCS7_free, -PKCS7_new_ex, -PKCS7_new, -PKCS7_print_ctx, -PKCS8_PRIV_KEY_INFO_free, -PKCS8_PRIV_KEY_INFO_new, -PKEY_USAGE_PERIOD_free, -PKEY_USAGE_PERIOD_new, -POLICYINFO_free, -POLICYINFO_new, -POLICYQUALINFO_free, -POLICYQUALINFO_new, -POLICY_CONSTRAINTS_free, -POLICY_CONSTRAINTS_new, -POLICY_MAPPING_free, -POLICY_MAPPING_new, -PROFESSION_INFOS_free, -PROFESSION_INFOS_new, -PROFESSION_INFO_free, -PROFESSION_INFO_new, -PROXY_CERT_INFO_EXTENSION_free, -PROXY_CERT_INFO_EXTENSION_new, -PROXY_POLICY_free, -PROXY_POLICY_new, -RSAPrivateKey_dup, -RSAPublicKey_dup, -RSA_OAEP_PARAMS_free, -RSA_OAEP_PARAMS_new, -RSA_PSS_PARAMS_free, -RSA_PSS_PARAMS_new, -RSA_PSS_PARAMS_dup, -SCRYPT_PARAMS_free, -SCRYPT_PARAMS_new, -SXNETID_free, -SXNETID_new, -SXNET_free, -SXNET_new, -TLS_FEATURE_free, -TLS_FEATURE_new, -TS_ACCURACY_dup, -TS_ACCURACY_free, -TS_ACCURACY_new, -TS_MSG_IMPRINT_dup, -TS_MSG_IMPRINT_free, -TS_MSG_IMPRINT_new, -TS_REQ_dup, -TS_REQ_free, -TS_REQ_new, -TS_RESP_dup, -TS_RESP_free, -TS_RESP_new, -TS_STATUS_INFO_dup, -TS_STATUS_INFO_free, -TS_STATUS_INFO_new, -TS_TST_INFO_dup, -TS_TST_INFO_free, -TS_TST_INFO_new, -USERNOTICE_free, -USERNOTICE_new, -X509_ACERT_dup, -X509_ACERT_free, -X509_ACERT_it, -X509_ACERT_new, -X509_ACERT_INFO_free, -X509_ACERT_INFO_it, -X509_ACERT_INFO_new, -X509_ACERT_ISSUER_V2FORM_free, -X509_ACERT_ISSUER_V2FORM_new, -X509_ALGOR_free, -X509_ALGOR_it, -X509_ALGOR_new, -X509_ATTRIBUTE_dup, -X509_ATTRIBUTE_free, -X509_ATTRIBUTE_new, -X509_CERT_AUX_free, -X509_CERT_AUX_new, -X509_CINF_free, -X509_CINF_new, -X509_CRL_INFO_free, -X509_CRL_INFO_new, -X509_CRL_dup, -X509_CRL_free, -X509_CRL_new_ex, -X509_CRL_new, -X509_EXTENSION_dup, -X509_EXTENSION_free, -X509_EXTENSION_new, -X509_NAME_ENTRY_dup, -X509_NAME_ENTRY_free, -X509_NAME_ENTRY_new, -X509_NAME_dup, -X509_NAME_free, -X509_NAME_new, -X509_REQ_INFO_free, -X509_REQ_INFO_new, -X509_REQ_dup, -X509_REQ_free, -X509_REQ_new, -X509_REQ_new_ex, -X509_REVOKED_dup, -X509_REVOKED_free, -X509_REVOKED_new, -X509_SIG_free, -X509_SIG_new, -X509_VAL_free, -X509_VAL_new, -X509_dup, -\&\- ASN1 object utilities -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& DECLARE_ASN1_FUNCTIONS(type) -\& IMPLEMENT_ASN1_FUNCTIONS(stname) -\& -\& typedef struct ASN1_ITEM_st ASN1_ITEM; -\& -\& extern const ASN1_ITEM TYPE_it; -\& TYPE *TYPE_new(void); -\& TYPE *TYPE_dup(const TYPE *a); -\& void TYPE_free(TYPE *a); -\& int TYPE_print_ctx(BIO *out, TYPE *a, int indent, const ASN1_PCTX *pctx); -.Ve -.PP -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 3 -\& DSA *DSAparams_dup(const DSA *dsa); -\& RSA *RSAPrivateKey_dup(const RSA *rsa); -\& RSA *RSAPublicKey_dup(const RSA *rsa); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -In the description below, \fB\f(BI\s-1TYPE\s0\fB\fR is used -as a placeholder for any of the OpenSSL datatypes, such as \fBX509\fR. -.PP -The OpenSSL \s-1ASN1\s0 parsing library templates are like a data-driven bytecode -interpreter. -Every \s-1ASN1\s0 object as a global variable, TYPE_it, that describes the item -such as its fields. (On systems which cannot export variables from shared -libraries, the global is instead a function which returns a pointer to a -static variable. -.PP -The macro \s-1\fBDECLARE_ASN1_FUNCTIONS\s0()\fR is typically used in header files -to generate the function declarations. -.PP -The macro \s-1\fBIMPLEMENT_ASN1_FUNCTIONS\s0()\fR is used once in a source file -to generate the function bodies. -.PP -\&\fB\f(BI\s-1TYPE\s0\fB_new\fR() allocates an empty object of the indicated type. -The object returned must be released by calling \fB\f(BI\s-1TYPE\s0\fB_free\fR(). -.PP -\&\fB\f(BI\s-1TYPE\s0\fB_new_ex\fR() is similar to \fB\f(BI\s-1TYPE\s0\fB_new\fR() but also passes the -library context \fIlibctx\fR and the property query \fIpropq\fR to use when retrieving -algorithms from providers. This created object can then be used when loading -binary data using \fBd2i_\f(BI\s-1TYPE\s0\fB\fR(). -.PP -\&\fB\f(BI\s-1TYPE\s0\fB_dup\fR() copies an existing object, leaving it untouched. -Note, however, that the internal representation of the object -may contain (besides the \s-1ASN.1\s0 structure) further data, which is not copied. -For instance, an \fBX509\fR object usually is augmented by cached information -on X.509v3 extensions, etc., and losing it can lead to wrong validation results. -To avoid such situations, better use \fB\f(BI\s-1TYPE\s0\fB_up_ref\fR() if available. -For the case of \fBX509\fR objects, an alternative to using \fBX509_up_ref\fR\|(3) -may be to still call \fB\f(BI\s-1TYPE\s0\fB_dup\fR(), e.g., \fIcopied_cert = X509_dup(cert)\fR, -followed by \fIX509_check_purpose(copied_cert, \-1, 0)\fR, -which re-builds the cached data. -.PP -\&\fB\f(BI\s-1TYPE\s0\fB_free\fR() releases the object and all pointers and sub-objects -within it. If the argument is \s-1NULL,\s0 nothing is done. -.PP -\&\fB\f(BI\s-1TYPE\s0\fB_print_ctx\fR() prints the object \fIa\fR on the specified \s-1BIO\s0 \fIout\fR. -Each line will be prefixed with \fIindent\fR spaces. -The \fIpctx\fR specifies the printing context and is for internal -use; use \s-1NULL\s0 to get the default behavior. If a print function is -user-defined, then pass in any \fIpctx\fR down to any nested calls. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fB\f(BI\s-1TYPE\s0\fB_new\fR(), \fB\f(BI\s-1TYPE\s0\fB_new_ex\fR() and \fB\f(BI\s-1TYPE\s0\fB_dup\fR() return a pointer to -the object or \s-1NULL\s0 on failure. -.PP -\&\fB\f(BI\s-1TYPE\s0\fB_print_ctx\fR() returns 1 on success or zero on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_up_ref\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The functions \fBX509_REQ_new_ex()\fR, \fBX509_CRL_new_ex()\fR, \fBPKCS7_new_ex()\fR and -\&\fBCMS_ContentInfo_new_ex()\fR were added in OpenSSL 3.0. -.PP -The functions \fBDSAparams_dup()\fR, \fBRSAPrivateKey_dup()\fR and \fBRSAPublicKey_dup()\fR were -deprecated in 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_free.3ossl b/openssl-install/share/man/man3/X509_free.3ossl deleted file mode 120000 index 43cc5a14..00000000 --- a/openssl-install/share/man/man3/X509_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_authority_issuer.3ossl b/openssl-install/share/man/man3/X509_get0_authority_issuer.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get0_authority_issuer.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_authority_key_id.3ossl b/openssl-install/share/man/man3/X509_get0_authority_key_id.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get0_authority_key_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_authority_serial.3ossl b/openssl-install/share/man/man3/X509_get0_authority_serial.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get0_authority_serial.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_distinguishing_id.3ossl b/openssl-install/share/man/man3/X509_get0_distinguishing_id.3ossl deleted file mode 100644 index 3c5ae5c6..00000000 --- a/openssl-install/share/man/man3/X509_get0_distinguishing_id.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET0_DISTINGUISHING_ID 3ossl" -.TH X509_GET0_DISTINGUISHING_ID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get0_distinguishing_id, X509_set0_distinguishing_id, -X509_REQ_get0_distinguishing_id, X509_REQ_set0_distinguishing_id -\&\- get or set the Distinguishing ID for certificate operations -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_OCTET_STRING *X509_get0_distinguishing_id(X509 *x); -\& void X509_set0_distinguishing_id(X509 *x, ASN1_OCTET_STRING *distid); -\& ASN1_OCTET_STRING *X509_REQ_get0_distinguishing_id(X509_REQ *x); -\& void X509_REQ_set0_distinguishing_id(X509_REQ *x, ASN1_OCTET_STRING *distid); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The Distinguishing \s-1ID\s0 is defined in \s-1FIPS 196\s0 as follows: -.IP "\fIDistinguishing identifier\fR" 4 -.IX Item "Distinguishing identifier" -Information which unambiguously distinguishes -an entity in the authentication process. -.PP -The \s-1SM2\s0 signature algorithm requires a Distinguishing \s-1ID\s0 value when generating -and verifying a signature, but the Ddistinguishing \s-1ID\s0 may also find other uses. -In the context of \s-1SM2,\s0 the Distinguishing \s-1ID\s0 is often referred to as the \*(L"\s-1SM2 -ID\*(R".\s0 -.PP -For the purpose off verifying a certificate or a certification request, a -Distinguishing \s-1ID\s0 may be attached to it, so functions like \fBX509_verify\fR\|(3) -or \fBX509_REQ_verify\fR\|(3) have easy access to that identity for signature -verification. -.PP -\&\fBX509_get0_distinguishing_id()\fR gets the Distinguishing \s-1ID\s0 value of a certificate -\&\fBx\fR by returning an \fB\s-1ASN1_OCTET_STRING\s0\fR object which should not be freed by -the caller. -.PP -\&\fBX509_set0_distinguishing_id()\fR assigns \fBdistid\fR to the certificate \fBx\fR. -Calling this function transfers the memory management of the value to the X509 -object, and therefore the value that has been passed in should not be freed by -the caller after this function has been called. -.PP -\&\fBX509_REQ_get0_distinguishing_id()\fR and \fBX509_REQ_set0_distinguishing_id()\fR -have the same functionality as \fBX509_get0_distinguishing_id()\fR and -\&\fBX509_set0_distinguishing_id()\fR except that they deal with \fBX509_REQ\fR -objects instead of \fBX509\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_set0_distinguishing_id()\fR and \fBX509_REQ_set0_distinguishing_id()\fR do not -return a value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_verify\fR\|(3), \s-1\fBSM2\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get0_extensions.3ossl b/openssl-install/share/man/man3/X509_get0_extensions.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_get0_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_notAfter.3ossl b/openssl-install/share/man/man3/X509_get0_notAfter.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_get0_notAfter.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_notBefore.3ossl b/openssl-install/share/man/man3/X509_get0_notBefore.3ossl deleted file mode 100644 index 0a99f66c..00000000 --- a/openssl-install/share/man/man3/X509_get0_notBefore.3ossl +++ /dev/null @@ -1,260 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET0_NOTBEFORE 3ossl" -.TH X509_GET0_NOTBEFORE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get0_notBefore, X509_getm_notBefore, X509_get0_notAfter, -X509_getm_notAfter, X509_set1_notBefore, X509_set1_notAfter, -X509_ACERT_get0_notBefore, X509_ACERT_get0_notAfter, -X509_ACERT_set1_notBefore, X509_ACERT_set1_notAfter, -X509_CRL_get0_lastUpdate, X509_CRL_get0_nextUpdate, X509_CRL_set1_lastUpdate, -X509_CRL_set1_nextUpdate \- get or set certificate or CRL dates -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const ASN1_TIME *X509_get0_notBefore(const X509 *x); -\& const ASN1_TIME *X509_get0_notAfter(const X509 *x); -\& -\& ASN1_TIME *X509_getm_notBefore(const X509 *x); -\& ASN1_TIME *X509_getm_notAfter(const X509 *x); -\& -\& int X509_set1_notBefore(X509 *x, const ASN1_TIME *tm); -\& int X509_set1_notAfter(X509 *x, const ASN1_TIME *tm); -\& -\& const ASN1_GENERALIZEDTIME *X509_ACERT_get0_notBefore(const X509 *x); -\& const ASN1_GENERALIZEDTIME *X509_ACERT_get0_notAfter(const X509 *x); -\& -\& int X509_ACERT_set1_notBefore(X509_ACERT *x, const ASN1_GENERALIZEDTIME *tm); -\& int X509_ACERT_set1_notAfter(X509_ACERT *x, const ASN1_GENERALIZEDTIME *tm); -\& -\& const ASN1_TIME *X509_CRL_get0_lastUpdate(const X509_CRL *crl); -\& const ASN1_TIME *X509_CRL_get0_nextUpdate(const X509_CRL *crl); -\& -\& int X509_CRL_set1_lastUpdate(X509_CRL *x, const ASN1_TIME *tm); -\& int X509_CRL_set1_nextUpdate(X509_CRL *x, const ASN1_TIME *tm); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_get0_notBefore()\fR and \fBX509_get0_notAfter()\fR return the \fBnotBefore\fR -and \fBnotAfter\fR fields of certificate \fIx\fR respectively. The value -returned is an internal pointer which must not be freed up after -the call. -.PP -\&\fBX509_getm_notBefore()\fR and \fBX509_getm_notAfter()\fR are similar to -\&\fBX509_get0_notBefore()\fR and \fBX509_get0_notAfter()\fR except they return -non-constant mutable references to the associated date field of -the certificate. -.PP -\&\fBX509_set1_notBefore()\fR and \fBX509_set1_notAfter()\fR set the \fBnotBefore\fR -and \fBnotAfter\fR fields of \fIx\fR to \fItm\fR. Ownership of the passed -parameter \fItm\fR is not transferred by these functions so it must -be freed up after the call. -.PP -\&\fBX509_ACERT_get0_notBefore()\fR and \fBX509_ACERT_get0_notAfter()\fR return -the \fBnotBefore\fR and \fBnotAfter\fR fields of certificate \fBx\fR respectively. -returned is an internal pointer which must not be freed up after -the call. -.PP -\&\fBX509_ACERT_set1_notBefore()\fR and \fBX509_ACERT_set1_notAfter()\fR set the \fBnotBefore\fR -and \fBnotAfter\fR fields of \fBx\fR to \fBtm\fR. Ownership of the passed -parameter \fBtm\fR is not transferred by these functions so it must -be freed up after the call. -.PP -\&\fBX509_CRL_get0_lastUpdate()\fR and \fBX509_CRL_get0_nextUpdate()\fR return the -\&\fBlastUpdate\fR and \fBnextUpdate\fR fields of \fIcrl\fR. The value -returned is an internal pointer which must not be freed up after -the call. If the \fBnextUpdate\fR field is absent from \fIcrl\fR then -\&\s-1NULL\s0 is returned. -.PP -\&\fBX509_CRL_set1_lastUpdate()\fR and \fBX509_CRL_set1_nextUpdate()\fR set the \fBlastUpdate\fR -and \fBnextUpdate\fR fields of \fIcrl\fR to \fItm\fR. Ownership of the passed parameter -\&\fItm\fR is not transferred by these functions so it must be freed up after the -call. -For \fBX509_CRL_set1_nextUpdate()\fR the \fItm\fR argument may be \s-1NULL,\s0 -which implies removal of the optional \fBnextUpdate\fR field. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get0_notBefore()\fR, \fBX509_get0_notAfter()\fR and \fBX509_CRL_get0_lastUpdate()\fR -return a pointer to an \fB\s-1ASN1_TIME\s0\fR structure. -.PP -\&\fBX509_CRL_get0_lastUpdate()\fR return a pointer to an \fB\s-1ASN1_TIME\s0\fR structure -or \s-1NULL\s0 if the \fBlastUpdate\fR field is absent. -.PP -\&\fBX509_set1_notBefore()\fR, \fBX509_set1_notAfter()\fR, \fBX509_CRL_set1_lastUpdate()\fR and -\&\fBX509_CRL_set1_nextUpdate()\fR return 1 for success or 0 for failure. -.SH "NOTES" -.IX Header "NOTES" -Unlike the \fBX509\fR and \fBX509_CRL\fR routines, the \fBX509_ACERT\fR routines -use the \s-1ASN1_GENERALIZEDTIME\s0 format instead of \s-1ASN1_TIME\s0 for holding time -data. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBASN1_GENERALIZEDTIME_check\fR\|(3) -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions are available in all versions of OpenSSL. -.PP -\&\fBX509_get_notBefore()\fR and \fBX509_get_notAfter()\fR were deprecated in OpenSSL -1.1.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get0_pubkey.3ossl b/openssl-install/share/man/man3/X509_get0_pubkey.3ossl deleted file mode 120000 index b4c8dd7c..00000000 --- a/openssl-install/share/man/man3/X509_get0_pubkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_pubkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_serialNumber.3ossl b/openssl-install/share/man/man3/X509_get0_serialNumber.3ossl deleted file mode 120000 index b95323a0..00000000 --- a/openssl-install/share/man/man3/X509_get0_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_serialNumber.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_signature.3ossl b/openssl-install/share/man/man3/X509_get0_signature.3ossl deleted file mode 100644 index 16141869..00000000 --- a/openssl-install/share/man/man3/X509_get0_signature.3ossl +++ /dev/null @@ -1,290 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET0_SIGNATURE 3ossl" -.TH X509_GET0_SIGNATURE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get0_signature, X509_REQ_set0_signature, X509_REQ_set1_signature_algo, -X509_get_signature_nid, X509_get0_tbs_sigalg, X509_REQ_get0_signature, -X509_REQ_get_signature_nid, X509_CRL_get0_signature, X509_CRL_get_signature_nid, -X509_ACERT_get0_signature, X509_ACERT_get0_info_sigalg, -X509_ACERT_get_signature_nid, X509_get_signature_info, -X509_SIG_INFO_get, X509_SIG_INFO_set \- signature information -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void X509_get0_signature(const ASN1_BIT_STRING **psig, -\& const X509_ALGOR **palg, -\& const X509 *x); -\& void X509_REQ_set0_signature(X509_REQ *req, ASN1_BIT_STRING *psig); -\& int X509_REQ_set1_signature_algo(X509_REQ *req, X509_ALGOR *palg); -\& int X509_get_signature_nid(const X509 *x); -\& const X509_ALGOR *X509_get0_tbs_sigalg(const X509 *x); -\& -\& void X509_REQ_get0_signature(const X509_REQ *crl, -\& const ASN1_BIT_STRING **psig, -\& const X509_ALGOR **palg); -\& int X509_REQ_get_signature_nid(const X509_REQ *crl); -\& -\& const X509_ALGOR *X509_ACERT_get0_info_sigalg(const X509_ACERT *x); -\& -\& void X509_CRL_get0_signature(const X509_CRL *crl, -\& const ASN1_BIT_STRING **psig, -\& const X509_ALGOR **palg); -\& int X509_CRL_get_signature_nid(const X509_CRL *crl); -\& -\& int X509_get_signature_info(X509 *x, int *mdnid, int *pknid, int *secbits, -\& uint32_t *flags); -\& -\& int X509_SIG_INFO_get(const X509_SIG_INFO *siginf, int *mdnid, int *pknid, -\& int *secbits, uint32_t *flags); -\& void X509_SIG_INFO_set(X509_SIG_INFO *siginf, int mdnid, int pknid, -\& int secbits, uint32_t flags); -\& -\& #include -\& -\& void X509_ACERT_get0_signature(const X509_ACERT *x, -\& const ASN1_BIT_STRING **psig, -\& const X509_ALGOR **palg); -\& int X509_ACERT_get_signature_nid(const X509_ACERT *x); -\&=head1 DESCRIPTION -.Ve -.PP -\&\fBX509_get0_signature()\fR sets \fB*psig\fR to the signature of \fBx\fR and \fB*palg\fR -to the signature algorithm of \fBx\fR. The values returned are internal -pointers which \fB\s-1MUST NOT\s0\fR be freed up after the call. -.PP -\&\fBX509_set0_signature()\fR and \fBX509_REQ_set1_signature_algo()\fR are the -equivalent setters for the two values of \fBX509_get0_signature()\fR. -.PP -\&\fBX509_get0_tbs_sigalg()\fR returns the signature algorithm in the signed -portion of \fBx\fR. -.PP -\&\fBX509_get_signature_nid()\fR returns the \s-1NID\s0 corresponding to the signature -algorithm of \fBx\fR. -.PP -\&\fBX509_REQ_get0_signature()\fR, \fBX509_REQ_get_signature_nid()\fR -\&\fBX509_CRL_get0_signature()\fR and \fBX509_CRL_get_signature_nid()\fR perform the -same function for certificate requests and CRLs. -.PP -\&\fBX509_ACERT_get0_signature()\fR, \fBX509_ACERT_get_signature_nid()\fR and -\&\fBX509_ACERT_get0_info_sigalg()\fR perform the same function for attribute -certificates. -.PP -\&\fBX509_get_signature_info()\fR retrieves information about the signature of -certificate \fBx\fR. The \s-1NID\s0 of the signing digest is written to \fB*mdnid\fR, -the public key algorithm to \fB*pknid\fR, the effective security bits to -\&\fB*secbits\fR and flag details to \fB*flags\fR. Any of the parameters can -be set to \fB\s-1NULL\s0\fR if the information is not required. -.PP -\&\fBX509_SIG_INFO_get()\fR and \fBX509_SIG_INFO_set()\fR get and set information -about a signature in an \fBX509_SIG_INFO\fR structure. They are only -used by implementations of algorithms which need to set custom -signature information: most applications will never need to call -them. -.SH "NOTES" -.IX Header "NOTES" -These functions provide lower level access to signatures in certificates -where an application wishes to analyse or generate a signature in a form -where \fBX509_sign()\fR et al is not appropriate (for example a non standard -or unsupported format). -.PP -The security bits returned by \fBX509_get_signature_info()\fR refers to information -available from the certificate signature (such as the signing digest). In some -cases the actual security of the signature is less because the signing -key is less secure: for example a certificate signed using \s-1SHA\-512\s0 and a -1024 bit \s-1RSA\s0 key. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get_signature_nid()\fR, \fBX509_REQ_get_signature_nid()\fR and -\&\fBX509_CRL_get_signature_nid()\fR return a \s-1NID.\s0 -.PP -\&\fBX509_get0_signature()\fR, \fBX509_REQ_get0_signature()\fR and -\&\fBX509_CRL_get0_signature()\fR do not return values. -.PP -\&\fBX509_get_signature_info()\fR returns 1 if the signature information -returned is valid or 0 if the information is not available (e.g. -unknown algorithms or malformed parameters). -.PP -\&\fBX509_REQ_set1_signature_algo()\fR returns 0 on success; or 1 on an -error (e.g. null \s-1ALGO\s0 pointer). X509_REQ_set0_signature does -not return an error value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The -\&\fBX509_get0_signature()\fR and \fBX509_get_signature_nid()\fR functions were -added in OpenSSL 1.0.2. -.PP -The -\&\fBX509_REQ_get0_signature()\fR, \fBX509_REQ_get_signature_nid()\fR, -\&\fBX509_CRL_get0_signature()\fR and \fBX509_CRL_get_signature_nid()\fR were -added in OpenSSL 1.1.0. -.PP -The \fBX509_REQ_set0_signature()\fR and \fBX509_REQ_set1_signature_algo()\fR -were added in OpenSSL 1.1.1e. -.PP -The \fBX509_ACERT_get0_signature()\fR, \fBX509_ACERT_get0_info_sigalg()\fR and -\&\fBX509_ACERT_get_signature_nid()\fR functions were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get0_subject_key_id.3ossl b/openssl-install/share/man/man3/X509_get0_subject_key_id.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get0_subject_key_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_tbs_sigalg.3ossl b/openssl-install/share/man/man3/X509_get0_tbs_sigalg.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_get0_tbs_sigalg.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get0_uids.3ossl b/openssl-install/share/man/man3/X509_get0_uids.3ossl deleted file mode 100644 index ea4793d5..00000000 --- a/openssl-install/share/man/man3/X509_get0_uids.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET0_UIDS 3ossl" -.TH X509_GET0_UIDS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get0_uids, X509_ACERT_get0_issuerUID -\&\- get certificate and attribute certificate unique identifiers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& void X509_get0_uids(const X509 *x, const ASN1_BIT_STRING **piuid, -\& const ASN1_BIT_STRING **psuid); -\& -\& #include -\& -\& ASN1_BIT_STRING *X509_ACERT_get0_issuerUID(X509_ACERT *x); -\&=head1 DESCRIPTION -.Ve -.PP -\&\fBX509_get0_uids()\fR sets \fB*piuid\fR and \fB*psuid\fR to the issuer and subject unique -identifiers of certificate \fBx\fR or \s-1NULL\s0 if the fields are not present. -.PP -\&\fBX509_ACERT_get0_issuerUID()\fR returns the issuer unique identifier of the -attribute certificate \fBx\fR or \s-1NULL\s0 if the field is not present. -.SH "NOTES" -.IX Header "NOTES" -The issuer and subject unique identifier fields are very rarely encountered in -practice outside test cases. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get0_uids()\fR does not return a value. -.PP -\&\fBX509_ACERT_get0_issuerUID()\fR returns a unique identifier on success or \s-1NULL\s0 -on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_get0_uids()\fR was added in OpenSSL 1.1.0. -.PP -\&\fBX509_ACERT_get0_issuerUID()\fR was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/X509_get_X509_PUBKEY.3ossl deleted file mode 120000 index b4c8dd7c..00000000 --- a/openssl-install/share/man/man3/X509_get_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_pubkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_default_cert_dir.3ossl b/openssl-install/share/man/man3/X509_get_default_cert_dir.3ossl deleted file mode 120000 index b7b9bca9..00000000 --- a/openssl-install/share/man/man3/X509_get_default_cert_dir.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_default_cert_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_default_cert_dir_env.3ossl b/openssl-install/share/man/man3/X509_get_default_cert_dir_env.3ossl deleted file mode 120000 index b7b9bca9..00000000 --- a/openssl-install/share/man/man3/X509_get_default_cert_dir_env.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_default_cert_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_default_cert_file.3ossl b/openssl-install/share/man/man3/X509_get_default_cert_file.3ossl deleted file mode 100644 index fe99f30f..00000000 --- a/openssl-install/share/man/man3/X509_get_default_cert_file.3ossl +++ /dev/null @@ -1,217 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET_DEFAULT_CERT_FILE 3ossl" -.TH X509_GET_DEFAULT_CERT_FILE 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get_default_cert_file, X509_get_default_cert_file_env, -X509_get_default_cert_dir, X509_get_default_cert_dir_env \- -retrieve default locations for trusted CA certificates -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& const char *X509_get_default_cert_file(void); -\& const char *X509_get_default_cert_dir(void); -\& -\& const char *X509_get_default_cert_file_env(void); -\& const char *X509_get_default_cert_dir_env(void); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX509_get_default_cert_file()\fR function returns the default path -to a file containing trusted \s-1CA\s0 certificates. OpenSSL will use this as -the default path when it is asked to load trusted \s-1CA\s0 certificates -from a file and no other path is specified. If the file exists, \s-1CA\s0 certificates -are loaded from the file. -.PP -The \fBX509_get_default_cert_dir()\fR function returns a default delimeter-separated -list of paths to a directories containing trusted \s-1CA\s0 certificates named in the -hashed format. OpenSSL will use this as the default list of paths when it is -asked to load trusted \s-1CA\s0 certificates from a directory and no other path is -specified. If a given directory in the list exists, OpenSSL attempts to lookup -\&\s-1CA\s0 certificates in this directory by calculating a filename based on a hash of -the certificate's subject name. -.PP -\&\fBX509_get_default_cert_file_env()\fR returns an environment variable name which is -recommended to specify a nondefault value to be used instead of the value -returned by \fBX509_get_default_cert_file()\fR. The value returned by the latter -function is not affected by these environment variables; you must check for this -environment variable yourself, using this function to retrieve the correct -environment variable name. If an environment variable is not set, the value -returned by the \fBX509_get_default_cert_file()\fR should be used. -.PP -\&\fBX509_get_default_cert_dir_env()\fR returns the environment variable name which is -recommended to specify a nondefault value to be used instead of the value -returned by \fBX509_get_default_cert_dir()\fR. The value specified by this environment -variable can also be a store \s-1URI\s0 (but see \s-1BUGS\s0 below). -.SH "BUGS" -.IX Header "BUGS" -By default (for example, when \fBX509_STORE_set_default_paths\fR\|(3) is used), the -environment variable name returned by \fBX509_get_default_cert_dir_env()\fR is -interpreted both as a delimiter-separated list of paths, and as a store \s-1URI.\s0 -This is ambiguous. For example, specifying a value of \fB\*(L"file:///etc/certs\*(R"\fR -would cause instantiation of the \*(L"file\*(R" store provided as part of the default -provider, but would also cause an \fBX509_LOOKUP_hash_dir\fR\|(3) instance to look -for certificates in the directory \fB\*(L"file\*(R"\fR (relative to the current working -directory) and the directory \fB\*(L"///etc/certs\*(R"\fR. This can be avoided by avoiding -use of the environment variable mechanism and using other methods to construct -X509_LOOKUP instances. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -These functions return pointers to constant strings with static storage -duration. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_LOOKUP\fR\|(3), -\&\fBSSL_CTX_set_default_verify_file\fR\|(3), -\&\fBSSL_CTX_set_default_verify_dir\fR\|(3), -\&\fBSSL_CTX_set_default_verify_store\fR\|(3), -\&\fBSSL_CTX_load_verify_file\fR\|(3), -\&\fBSSL_CTX_load_verify_dir\fR\|(3), -\&\fBSSL_CTX_load_verify_store\fR\|(3), -\&\fBSSL_CTX_load_verify_locations\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get_default_cert_file_env.3ossl b/openssl-install/share/man/man3/X509_get_default_cert_file_env.3ossl deleted file mode 120000 index b7b9bca9..00000000 --- a/openssl-install/share/man/man3/X509_get_default_cert_file_env.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_default_cert_file.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ex_data.3ossl b/openssl-install/share/man/man3/X509_get_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_get_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ex_new_index.3ossl b/openssl-install/share/man/man3/X509_get_ex_new_index.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_get_ex_new_index.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ext.3ossl b/openssl-install/share/man/man3/X509_get_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_get_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ext_by_NID.3ossl b/openssl-install/share/man/man3/X509_get_ext_by_NID.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_get_ext_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ext_by_OBJ.3ossl b/openssl-install/share/man/man3/X509_get_ext_by_OBJ.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_get_ext_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ext_by_critical.3ossl b/openssl-install/share/man/man3/X509_get_ext_by_critical.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_get_ext_by_critical.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ext_count.3ossl b/openssl-install/share/man/man3/X509_get_ext_count.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509_get_ext_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_ext_d2i.3ossl b/openssl-install/share/man/man3/X509_get_ext_d2i.3ossl deleted file mode 120000 index 250de180..00000000 --- a/openssl-install/share/man/man3/X509_get_ext_d2i.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509V3_get_d2i.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_extended_key_usage.3ossl b/openssl-install/share/man/man3/X509_get_extended_key_usage.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get_extended_key_usage.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_extension_flags.3ossl b/openssl-install/share/man/man3/X509_get_extension_flags.3ossl deleted file mode 100644 index e69cc79e..00000000 --- a/openssl-install/share/man/man3/X509_get_extension_flags.3ossl +++ /dev/null @@ -1,322 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET_EXTENSION_FLAGS 3ossl" -.TH X509_GET_EXTENSION_FLAGS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get0_subject_key_id, -X509_get0_authority_key_id, -X509_get0_authority_issuer, -X509_get0_authority_serial, -X509_get_pathlen, -X509_get_extension_flags, -X509_get_key_usage, -X509_get_extended_key_usage, -X509_set_proxy_flag, -X509_set_proxy_pathlen, -X509_get_proxy_pathlen \- retrieve certificate extension data -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long X509_get_pathlen(X509 *x); -\& uint32_t X509_get_extension_flags(X509 *x); -\& uint32_t X509_get_key_usage(X509 *x); -\& uint32_t X509_get_extended_key_usage(X509 *x); -\& const ASN1_OCTET_STRING *X509_get0_subject_key_id(X509 *x); -\& const ASN1_OCTET_STRING *X509_get0_authority_key_id(X509 *x); -\& const GENERAL_NAMES *X509_get0_authority_issuer(X509 *x); -\& const ASN1_INTEGER *X509_get0_authority_serial(X509 *x); -\& void X509_set_proxy_flag(X509 *x); -\& void X509_set_proxy_pathlen(int l); -\& long X509_get_proxy_pathlen(X509 *x); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions retrieve information related to commonly used certificate extensions. -.PP -\&\fBX509_get_pathlen()\fR retrieves the path length extension from a certificate. -This extension is used to limit the length of a cert chain that may be -issued from that \s-1CA.\s0 -.PP -\&\fBX509_get_extension_flags()\fR retrieves general information about a certificate, -it will return one or more of the following flags ored together. -.IP "\fB\s-1EXFLAG_V1\s0\fR" 4 -.IX Item "EXFLAG_V1" -The certificate is an obsolete version 1 certificate. -.IP "\fB\s-1EXFLAG_BCONS\s0\fR" 4 -.IX Item "EXFLAG_BCONS" -The certificate contains a basic constraints extension. -.IP "\fB\s-1EXFLAG_CA\s0\fR" 4 -.IX Item "EXFLAG_CA" -The certificate contains basic constraints and asserts the \s-1CA\s0 flag. -.IP "\fB\s-1EXFLAG_PROXY\s0\fR" 4 -.IX Item "EXFLAG_PROXY" -The certificate is a valid proxy certificate. -.IP "\fB\s-1EXFLAG_SI\s0\fR" 4 -.IX Item "EXFLAG_SI" -The certificate is self issued (that is subject and issuer names match). -.IP "\fB\s-1EXFLAG_SS\s0\fR" 4 -.IX Item "EXFLAG_SS" -The subject and issuer names match and extension values imply it is self -signed. -.IP "\fB\s-1EXFLAG_FRESHEST\s0\fR" 4 -.IX Item "EXFLAG_FRESHEST" -The freshest \s-1CRL\s0 extension is present in the certificate. -.IP "\fB\s-1EXFLAG_CRITICAL\s0\fR" 4 -.IX Item "EXFLAG_CRITICAL" -The certificate contains an unhandled critical extension. -.IP "\fB\s-1EXFLAG_INVALID\s0\fR" 4 -.IX Item "EXFLAG_INVALID" -Some certificate extension values are invalid or inconsistent. -The certificate should be rejected. -This bit may also be raised after an out-of-memory error while -processing the X509 object, so it may not be related to the processed -\&\s-1ASN1\s0 object itself. -.IP "\fB\s-1EXFLAG_NO_FINGERPRINT\s0\fR" 4 -.IX Item "EXFLAG_NO_FINGERPRINT" -Failed to compute the internal \s-1SHA1\s0 hash value of the certificate or \s-1CRL.\s0 -This may be due to malloc failure or because no \s-1SHA1\s0 implementation was found. -.IP "\fB\s-1EXFLAG_INVALID_POLICY\s0\fR" 4 -.IX Item "EXFLAG_INVALID_POLICY" -The NID_certificate_policies certificate extension is invalid or -inconsistent. The certificate should be rejected. -This bit may also be raised after an out-of-memory error while -processing the X509 object, so it may not be related to the processed -\&\s-1ASN1\s0 object itself. -.IP "\fB\s-1EXFLAG_KUSAGE\s0\fR" 4 -.IX Item "EXFLAG_KUSAGE" -The certificate contains a key usage extension. The value can be retrieved -using \fBX509_get_key_usage()\fR. -.IP "\fB\s-1EXFLAG_XKUSAGE\s0\fR" 4 -.IX Item "EXFLAG_XKUSAGE" -The certificate contains an extended key usage extension. The value can be -retrieved using \fBX509_get_extended_key_usage()\fR. -.PP -\&\fBX509_get_key_usage()\fR returns the value of the key usage extension. If key -usage is present will return zero or more of the flags: -\&\fB\s-1KU_DIGITAL_SIGNATURE\s0\fR, \fB\s-1KU_NON_REPUDIATION\s0\fR, \fB\s-1KU_KEY_ENCIPHERMENT\s0\fR, -\&\fB\s-1KU_DATA_ENCIPHERMENT\s0\fR, \fB\s-1KU_KEY_AGREEMENT\s0\fR, \fB\s-1KU_KEY_CERT_SIGN\s0\fR, -\&\fB\s-1KU_CRL_SIGN\s0\fR, \fB\s-1KU_ENCIPHER_ONLY\s0\fR or \fB\s-1KU_DECIPHER_ONLY\s0\fR corresponding to -individual key usage bits. If key usage is absent then \fB\s-1UINT32_MAX\s0\fR is -returned. -.PP -\&\fBX509_get_extended_key_usage()\fR returns the value of the extended key usage -extension. If extended key usage is present it will return zero or more of the -flags: \fB\s-1XKU_SSL_SERVER\s0\fR, \fB\s-1XKU_SSL_CLIENT\s0\fR, \fB\s-1XKU_SMIME\s0\fR, \fB\s-1XKU_CODE_SIGN\s0\fR -\&\fB\s-1XKU_OCSP_SIGN\s0\fR, \fB\s-1XKU_TIMESTAMP\s0\fR, \fB\s-1XKU_DVCS\s0\fR or \fB\s-1XKU_ANYEKU\s0\fR. These -correspond to the OIDs \fBid-kp-serverAuth\fR, \fBid-kp-clientAuth\fR, -\&\fBid-kp-emailProtection\fR, \fBid-kp-codeSigning\fR, \fBid-kp-OCSPSigning\fR, -\&\fBid-kp-timeStamping\fR, \fBid-kp-dvcs\fR and \fBanyExtendedKeyUsage\fR respectively. -Additionally \fB\s-1XKU_SGC\s0\fR is set if either Netscape or Microsoft \s-1SGC\s0 OIDs are -present. -.PP -\&\fBX509_get0_subject_key_id()\fR returns an internal pointer to the subject key -identifier of \fBx\fR as an \fB\s-1ASN1_OCTET_STRING\s0\fR or \fB\s-1NULL\s0\fR if the extension -is not present or cannot be parsed. -.PP -\&\fBX509_get0_authority_key_id()\fR returns an internal pointer to the authority key -identifier of \fBx\fR as an \fB\s-1ASN1_OCTET_STRING\s0\fR or \fB\s-1NULL\s0\fR if the extension -is not present or cannot be parsed. -.PP -\&\fBX509_get0_authority_issuer()\fR returns an internal pointer to the authority -certificate issuer of \fBx\fR as a stack of \fB\s-1GENERAL_NAME\s0\fR structures or -\&\fB\s-1NULL\s0\fR if the extension is not present or cannot be parsed. -.PP -\&\fBX509_get0_authority_serial()\fR returns an internal pointer to the authority -certificate serial number of \fBx\fR as an \fB\s-1ASN1_INTEGER\s0\fR or \fB\s-1NULL\s0\fR if the -extension is not present or cannot be parsed. -.PP -\&\fBX509_set_proxy_flag()\fR marks the certificate with the \fB\s-1EXFLAG_PROXY\s0\fR flag. -This is for the users who need to mark non\-RFC3820 proxy certificates as -such, as OpenSSL only detects \s-1RFC3820\s0 compliant ones. -.PP -\&\fBX509_set_proxy_pathlen()\fR sets the proxy certificate path length for the given -certificate \fBx\fR. This is for the users who need to mark non\-RFC3820 proxy -certificates as such, as OpenSSL only detects \s-1RFC3820\s0 compliant ones. -.PP -\&\fBX509_get_proxy_pathlen()\fR returns the proxy certificate path length for the -given certificate \fBx\fR if it is a proxy certificate. -.SH "NOTES" -.IX Header "NOTES" -The value of the flags correspond to extension values which are cached -in the \fBX509\fR structure. If the flags returned do not provide sufficient -information an application should examine extension values directly -for example using \fBX509_get_ext_d2i()\fR. -.PP -If the key usage or extended key usage extension is absent then typically usage -is unrestricted. For this reason \fBX509_get_key_usage()\fR and -\&\fBX509_get_extended_key_usage()\fR return \fB\s-1UINT32_MAX\s0\fR when the corresponding -extension is absent. Applications can additionally check the return value of -\&\fBX509_get_extension_flags()\fR and take appropriate action is an extension is -absent. -.PP -If \fBX509_get0_subject_key_id()\fR returns \fB\s-1NULL\s0\fR then the extension may be -absent or malformed. Applications can determine the precise reason using -\&\fBX509_get_ext_d2i()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get_pathlen()\fR returns the path length value, or \-1 if the extension -is not present. -.PP -\&\fBX509_get_extension_flags()\fR, \fBX509_get_key_usage()\fR and -\&\fBX509_get_extended_key_usage()\fR return sets of flags corresponding to the -certificate extension values. -.PP -\&\fBX509_get0_subject_key_id()\fR returns the subject key identifier as a -pointer to an \fB\s-1ASN1_OCTET_STRING\s0\fR structure or \fB\s-1NULL\s0\fR if the extension -is absent or an error occurred during parsing. -.PP -\&\fBX509_get_proxy_pathlen()\fR returns the path length value if the given -certificate is a proxy one and has a path length set, and \-1 otherwise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_check_purpose\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_get_pathlen()\fR, \fBX509_set_proxy_flag()\fR, \fBX509_set_proxy_pathlen()\fR and -\&\fBX509_get_proxy_pathlen()\fR were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get_issuer_name.3ossl b/openssl-install/share/man/man3/X509_get_issuer_name.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_get_issuer_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_key_usage.3ossl b/openssl-install/share/man/man3/X509_get_key_usage.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get_key_usage.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_pathlen.3ossl b/openssl-install/share/man/man3/X509_get_pathlen.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get_pathlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_proxy_pathlen.3ossl b/openssl-install/share/man/man3/X509_get_proxy_pathlen.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_get_proxy_pathlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_pubkey.3ossl b/openssl-install/share/man/man3/X509_get_pubkey.3ossl deleted file mode 100644 index 4de3059e..00000000 --- a/openssl-install/share/man/man3/X509_get_pubkey.3ossl +++ /dev/null @@ -1,218 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET_PUBKEY 3ossl" -.TH X509_GET_PUBKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get_pubkey, X509_get0_pubkey, X509_set_pubkey, X509_get_X509_PUBKEY, -X509_REQ_get_pubkey, X509_REQ_get0_pubkey, X509_REQ_set_pubkey, -X509_REQ_get_X509_PUBKEY \- get or set certificate or certificate request -public key -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *X509_get_pubkey(X509 *x); -\& EVP_PKEY *X509_get0_pubkey(const X509 *x); -\& int X509_set_pubkey(X509 *x, EVP_PKEY *pkey); -\& X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x); -\& -\& EVP_PKEY *X509_REQ_get_pubkey(X509_REQ *req); -\& EVP_PKEY *X509_REQ_get0_pubkey(X509_REQ *req); -\& int X509_REQ_set_pubkey(X509_REQ *x, EVP_PKEY *pkey); -\& X509_PUBKEY *X509_REQ_get_X509_PUBKEY(X509_REQ *x); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_get_pubkey()\fR attempts to decode the public key for certificate \fBx\fR. If -successful it returns the public key as an \fB\s-1EVP_PKEY\s0\fR pointer with its -reference count incremented: this means the returned key must be freed up -after use. \fBX509_get0_pubkey()\fR is similar except it does \fBnot\fR increment -the reference count of the returned \fB\s-1EVP_PKEY\s0\fR so it must not be freed up -after use. -.PP -\&\fBX509_get_X509_PUBKEY()\fR returns an internal pointer to the \fBX509_PUBKEY\fR -structure which encodes the certificate of \fBx\fR. The returned value -must not be freed up after use. -.PP -\&\fBX509_set_pubkey()\fR attempts to set the public key for certificate \fBx\fR to -\&\fBpkey\fR. The key \fBpkey\fR should be freed up after use. -.PP -\&\fBX509_REQ_get_pubkey()\fR, \fBX509_REQ_get0_pubkey()\fR, \fBX509_REQ_set_pubkey()\fR and -\&\fBX509_REQ_get_X509_PUBKEY()\fR are similar but operate on certificate request \fBreq\fR. -.SH "NOTES" -.IX Header "NOTES" -The first time a public key is decoded the \fB\s-1EVP_PKEY\s0\fR structure is -cached in the certificate or certificate request itself. Subsequent calls -return the cached structure with its reference count incremented to -improve performance. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get_pubkey()\fR, \fBX509_get0_pubkey()\fR, \fBX509_get_X509_PUBKEY()\fR, -\&\fBX509_REQ_get_pubkey()\fR and \fBX509_REQ_get_X509_PUBKEY()\fR return a public key or -\&\fB\s-1NULL\s0\fR if an error occurred. -.PP -\&\fBX509_set_pubkey()\fR and \fBX509_REQ_set_pubkey()\fR return 1 for success and 0 -for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get_serialNumber.3ossl b/openssl-install/share/man/man3/X509_get_serialNumber.3ossl deleted file mode 100644 index dd93f31f..00000000 --- a/openssl-install/share/man/man3/X509_get_serialNumber.3ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET_SERIALNUMBER 3ossl" -.TH X509_GET_SERIALNUMBER 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get_serialNumber, -X509_get0_serialNumber, -X509_set_serialNumber, -X509_ACERT_get0_serialNumber, -X509_ACERT_set1_serialNumber -\&\- get or set certificate serial number -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& ASN1_INTEGER *X509_get_serialNumber(X509 *x); -\& const ASN1_INTEGER *X509_get0_serialNumber(const X509 *x); -\& int X509_set_serialNumber(X509 *x, ASN1_INTEGER *serial); -\& -\& #include -\& -\& ASN1_INTEGER *X509_ACERT_get0_serialNumber(X509_ACERT *x); -\& int X509_ACERT_set1_serialNumber(X509_ACERT *x, ASN1_INTEGER *serial); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_get_serialNumber()\fR returns the serial number of certificate \fBx\fR as an -\&\fB\s-1ASN1_INTEGER\s0\fR structure which can be examined or initialised. The value -returned is an internal pointer which \fB\s-1MUST NOT\s0\fR be freed up after the call. -.PP -\&\fBX509_get0_serialNumber()\fR is the same as \fBX509_get_serialNumber()\fR except it -accepts a const parameter and returns a const result. -.PP -\&\fBX509_set_serialNumber()\fR sets the serial number of certificate \fBx\fR to -\&\fBserial\fR. A copy of the serial number is used internally so \fBserial\fR should -be freed up after use. -.PP -\&\fBX509_ACERT_get0_serialNumber()\fR performs the same operation as -\&\fBX509_get_serialNumber()\fR for attribute certificates. -.PP -\&\fBX509_ACERT_set1_serialNumber()\fR performs the same operation as -\&\fBX509_set_serialNumber()\fR for attribute certificates. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get_serialNumber()\fR, \fBX509_get0_serialNumber()\fR and -\&\fBX509_ACERT_get0_serialNumber()\fR return a pointer to an \fB\s-1ASN1_INTEGER\s0\fR structure. -.PP -\&\fBX509_set_serialNumber()\fR and \fBX509_ACERT_set1_serialNumber()\fR return 1 for success -and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_get_serialNumber()\fR and \fBX509_set_serialNumber()\fR functions are -available in all versions of OpenSSL. -The \fBX509_get0_serialNumber()\fR function was added in OpenSSL 1.1.0. -The \fBX509_ACERT_get0_serialNumber()\fR and \fBX509_ACERT_set1_serialNumber()\fR -functions were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get_signature_info.3ossl b/openssl-install/share/man/man3/X509_get_signature_info.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_get_signature_info.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_signature_nid.3ossl b/openssl-install/share/man/man3/X509_get_signature_nid.3ossl deleted file mode 120000 index 9982ca27..00000000 --- a/openssl-install/share/man/man3/X509_get_signature_nid.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_signature.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_get_subject_name.3ossl b/openssl-install/share/man/man3/X509_get_subject_name.3ossl deleted file mode 100644 index 2b14ef4a..00000000 --- a/openssl-install/share/man/man3/X509_get_subject_name.3ossl +++ /dev/null @@ -1,271 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET_SUBJECT_NAME 3ossl" -.TH X509_GET_SUBJECT_NAME 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_NAME_hash_ex, X509_NAME_hash, -X509_get_subject_name, X509_set_subject_name, X509_subject_name_hash, -X509_get_issuer_name, X509_set_issuer_name, X509_issuer_name_hash, -X509_REQ_get_subject_name, X509_REQ_set_subject_name, -X509_ACERT_get0_issuerName, X509_ACERT_set1_issuerName, -X509_CRL_get_issuer, X509_CRL_set_issuer_name \- -get X509_NAME hashes or get and set issuer or subject names -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& unsigned long X509_NAME_hash_ex(const X509_NAME *x, OSSL_LIB_CTX *libctx, -\& const char *propq, int *ok); -\& -\& X509_NAME *X509_get_subject_name(const X509 *x); -\& int X509_set_subject_name(X509 *x, const X509_NAME *name); -\& unsigned long X509_subject_name_hash(X509 *x); -\& -\& X509_NAME *X509_get_issuer_name(const X509 *x); -\& int X509_set_issuer_name(X509 *x, const X509_NAME *name); -\& unsigned long X509_issuer_name_hash(X509 *x); -\& -\& X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req); -\& int X509_REQ_set_subject_name(X509_REQ *req, const X509_NAME *name); -\& -\& X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl); -\& int X509_CRL_set_issuer_name(X509_CRL *x, const X509_NAME *name); -\& -\& #include -\& -\& X509_NAME *X509_ACERT_get0_issuerName(const X509_ACERT *x); -\& int X509_ACERT_set1_issuerName(X509_ACERT *x, const X509_NAME *name); -.Ve -.PP -The following macro has been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 1 -\& #define X509_NAME_hash(x) X509_NAME_hash_ex(x, NULL, NULL, NULL) -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_NAME_hash_ex()\fR returns a hash value of name \fIx\fR or 0 on failure, -using any given library context \fIlibctx\fR and property query \fIpropq\fR. -The \fIok\fR result argument may be \s-1NULL\s0 -or else is used to return 1 for success and 0 for failure. -Failure may happen on malloc error or if no \s-1SHA1\s0 implementation is available. -.PP -\&\fBX509_NAME_hash()\fR returns a hash value of name \fIx\fR or 0 on failure, -using the default library context and default property query. -.PP -\&\fBX509_get_subject_name()\fR returns the subject name of certificate \fIx\fR. The -returned value is an internal pointer which \fB\s-1MUST NOT\s0\fR be freed. -.PP -\&\fBX509_set_subject_name()\fR sets the issuer name of certificate \fIx\fR to -\&\fIname\fR. The \fIname\fR parameter is copied internally and should be freed -up when it is no longer needed. -.PP -\&\fBX509_subject_name_hash()\fR returns a hash value of the subject name of -certificate \fIx\fR. -.PP -\&\fBX509_get_issuer_name()\fR, \fBX509_set_issuer_name()\fR, and \fBX509_issuer_name_hash()\fR -are identical to -\&\fBX509_get_subject_name()\fR, \fBX509_set_subject_name()\fR, and \fBX509_subject_name_hash()\fR -except they relate to the issuer name of \fIx\fR. -.PP -Similarly \fBX509_REQ_get_subject_name()\fR, \fBX509_REQ_set_subject_name()\fR, -\&\fBX509_ACERT_get0_issuerName()\fR, \fBX509_ACERT_set1_issuerName()\fR, -\&\fBX509_CRL_get_issuer()\fR and \fBX509_CRL_set_issuer_name()\fR get or set the subject -or issuer names of certificate requests of CRLs respectively. -.PP -Since attribute certificates do not have a subject name, only the issuer name -can be set. For details on setting X509_ACERT holder identities, see -\&\fBX509_ACERT_set0_holder_entityName\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get_subject_name()\fR, \fBX509_get_issuer_name()\fR, \fBX509_REQ_get_subject_name()\fR -\&\fBX509_ACERT_get0_issuerName()\fR and \fBX509_CRL_get_issuer()\fR return -an \fBX509_NAME\fR pointer. -.PP -\&\fBX509_NAME_hash_ex()\fR, \fBX509_NAME_hash()\fR, -\&\fBX509_subject_name_hash()\fR and \fBX509_issuer_name_hash()\fR -return the first four bytes of the \s-1SHA1\s0 hash value, -converted to \fBunsigned long\fR in little endian order, -or 0 on failure. -.PP -\&\fBX509_set_subject_name()\fR, \fBX509_set_issuer_name()\fR, \fBX509_REQ_set_subject_name()\fR, -\&\fBX509_ACERT_get0_issuerName()\fR and \fBX509_CRL_set_issuer_name()\fR return 1 for -success and 0 for failure. -.SH "BUGS" -.IX Header "BUGS" -In case \fBX509_NAME_hash()\fR, \fBX509_subject_name_hash()\fR, or \fBX509_issuer_name_hash()\fR -returns 0 it remains unclear if this is the real hash value or due to failure. -Better use \fBX509_NAME_hash_ex()\fR instead. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), \fBd2i_X509\fR\|(3) -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_REQ_get_subject_name()\fR is a function in OpenSSL 1.1.0 and a macro in -earlier versions. -.PP -\&\fBX509_CRL_get_issuer()\fR is a function in OpenSSL 1.1.0. It was previously -added in OpenSSL 1.0.0 as a macro. -.PP -\&\fBX509_NAME_hash()\fR was turned into a macro and deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_get_version.3ossl b/openssl-install/share/man/man3/X509_get_version.3ossl deleted file mode 100644 index 85283b90..00000000 --- a/openssl-install/share/man/man3/X509_get_version.3ossl +++ /dev/null @@ -1,223 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_GET_VERSION 3ossl" -.TH X509_GET_VERSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_get_version, X509_set_version, X509_REQ_get_version, X509_REQ_set_version, -X509_ACERT_get_version, X509_ACERT_set_version, X509_CRL_get_version, -X509_CRL_set_version \- get or set certificate, -certificate request or CRL version -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& long X509_get_version(const X509 *x); -\& int X509_set_version(X509 *x, long version); -\& -\& long X509_REQ_get_version(const X509_REQ *req); -\& int X509_REQ_set_version(X509_REQ *x, long version); -\& -\& long X509_CRL_get_version(const X509_CRL *crl); -\& int X509_CRL_set_version(X509_CRL *x, long version); -\& -\& #include -\& -\& int X509_ACERT_set_version(X509_ACERT *x, long version); -\& long X509_ACERT_get_version(const X509_ACERT *x); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_get_version()\fR returns the numerical value of the version field of -certificate \fIx\fR. These correspond to the constants \fBX509_VERSION_1\fR, -\&\fBX509_VERSION_2\fR, and \fBX509_VERSION_3\fR. Note: the values of these constants -are defined by standards (X.509 et al) to be one less than the certificate -version. So \fBX509_VERSION_3\fR has value 2 and \fBX509_VERSION_1\fR has value 0. -.PP -\&\fBX509_set_version()\fR sets the numerical value of the version field of certificate -\&\fIx\fR to \fIversion\fR. -.PP -Similarly \fBX509_REQ_get_version()\fR, \fBX509_REQ_set_version()\fR, -\&\fBX509_ACERT_get_version()\fR, \fBX509_ACERT_set_version()\fR, -\&\fBX509_CRL_get_version()\fR and \fBX509_CRL_set_version()\fR get and set the version -number of certificate requests and CRLs. They use constants -\&\fBX509_REQ_VERSION_1\fR, \fBX509_ACERT_VERSION_2\fR, \fBX509_CRL_VERSION_1\fR, -and \fBX509_CRL_VERSION_2\fR. -.SH "NOTES" -.IX Header "NOTES" -The version field of certificates, certificate requests and CRLs has a -\&\s-1DEFAULT\s0 value of \fB\fBv1\fB\|(0)\fR meaning the field should be omitted for version -1. This is handled transparently by these functions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_get_version()\fR, \fBX509_REQ_get_version()\fR and \fBX509_CRL_get_version()\fR -return the numerical value of the version field. -.PP -\&\fBX509_set_version()\fR, \fBX509_REQ_set_version()\fR and \fBX509_CRL_set_version()\fR -return 1 for success and 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_get_version()\fR, \fBX509_REQ_get_version()\fR and \fBX509_CRL_get_version()\fR are -functions in OpenSSL 1.1.0, in previous versions they were macros. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_getm_notAfter.3ossl b/openssl-install/share/man/man3/X509_getm_notAfter.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_getm_notAfter.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_getm_notBefore.3ossl b/openssl-install/share/man/man3/X509_getm_notBefore.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_getm_notBefore.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_gmtime_adj.3ossl b/openssl-install/share/man/man3/X509_gmtime_adj.3ossl deleted file mode 120000 index cdeff4ec..00000000 --- a/openssl-install/share/man/man3/X509_gmtime_adj.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_http_nbio.3ossl b/openssl-install/share/man/man3/X509_http_nbio.3ossl deleted file mode 120000 index f41a0530..00000000 --- a/openssl-install/share/man/man3/X509_http_nbio.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_load_http.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_issuer_and_serial_cmp.3ossl b/openssl-install/share/man/man3/X509_issuer_and_serial_cmp.3ossl deleted file mode 120000 index e12f4f89..00000000 --- a/openssl-install/share/man/man3/X509_issuer_and_serial_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_issuer_name_cmp.3ossl b/openssl-install/share/man/man3/X509_issuer_name_cmp.3ossl deleted file mode 120000 index e12f4f89..00000000 --- a/openssl-install/share/man/man3/X509_issuer_name_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_issuer_name_hash.3ossl b/openssl-install/share/man/man3/X509_issuer_name_hash.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_issuer_name_hash.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_load_cert_crl_file.3ossl b/openssl-install/share/man/man3/X509_load_cert_crl_file.3ossl deleted file mode 120000 index c5406670..00000000 --- a/openssl-install/share/man/man3/X509_load_cert_crl_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_hash_dir.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_load_cert_crl_file_ex.3ossl b/openssl-install/share/man/man3/X509_load_cert_crl_file_ex.3ossl deleted file mode 120000 index c5406670..00000000 --- a/openssl-install/share/man/man3/X509_load_cert_crl_file_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_hash_dir.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_load_cert_file.3ossl b/openssl-install/share/man/man3/X509_load_cert_file.3ossl deleted file mode 120000 index c5406670..00000000 --- a/openssl-install/share/man/man3/X509_load_cert_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_hash_dir.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_load_cert_file_ex.3ossl b/openssl-install/share/man/man3/X509_load_cert_file_ex.3ossl deleted file mode 120000 index c5406670..00000000 --- a/openssl-install/share/man/man3/X509_load_cert_file_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_hash_dir.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_load_crl_file.3ossl b/openssl-install/share/man/man3/X509_load_crl_file.3ossl deleted file mode 120000 index c5406670..00000000 --- a/openssl-install/share/man/man3/X509_load_crl_file.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_LOOKUP_hash_dir.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_load_http.3ossl b/openssl-install/share/man/man3/X509_load_http.3ossl deleted file mode 100644 index 3a15c593..00000000 --- a/openssl-install/share/man/man3/X509_load_http.3ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_LOAD_HTTP 3ossl" -.TH X509_LOAD_HTTP 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_load_http, -X509_http_nbio, -X509_CRL_load_http, -X509_CRL_http_nbio -\&\- certificate and CRL loading functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509 *X509_load_http(const char *url, BIO *bio, BIO *rbio, int timeout); -\& X509_CRL *X509_CRL_load_http(const char *url, BIO *bio, BIO *rbio, int timeout); -.Ve -.PP -The following macros have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 2 -\& #define X509_http_nbio(rctx, pcert) -\& #define X509_CRL_http_nbio(rctx, pcrl) -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_load_http()\fR and \fBX509_CRL_load_http()\fR loads a certificate or a \s-1CRL,\s0 -respectively, in \s-1ASN.1\s0 format using \s-1HTTP\s0 from the given \fBurl\fR. -.PP -Maximum size of the \s-1HTTP\s0 response is 100 kB for certificates and 32 \s-1MB\s0 for CRLs -and hard coded in the functions. -.PP -If \fBbio\fR is given and \fBrbio\fR is \s-1NULL\s0 then this \s-1BIO\s0 is used instead of an -internal one for connecting, writing the request, and reading the response. -If both \fBbio\fR and \fBrbio\fR are given (which may be memory BIOs, for instance) -then no explicit connection is attempted, -\&\fBbio\fR is used for writing the request, and \fBrbio\fR for reading the response. -.PP -If the \fBtimeout\fR parameter is > 0 this indicates the maximum number of seconds -to wait until the transfer is complete. -A value of 0 enables waiting indefinitely, -while a value < 0 immediately leads to a timeout condition. -.PP -\&\fBX509_http_nbio()\fR and \fBX509_CRL_http_nbio()\fR are macros for backward compatibility -that have the same effect as the functions above but with infinite timeout -and without the possibility to specify custom BIOs. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -On success the function yield the loaded value, else \s-1NULL.\s0 -Error conditions include connection/transfer timeout, parse errors, etc. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_HTTP_get\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_load_http()\fR and \fBX509_CRL_load_http()\fR were added in OpenSSL 3.0. -\&\fBX509_http_nbio()\fR and \fBX509_CRL_http_nbio()\fR were deprecated in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_new.3ossl b/openssl-install/share/man/man3/X509_new.3ossl deleted file mode 100644 index 49a84f3f..00000000 --- a/openssl-install/share/man/man3/X509_new.3ossl +++ /dev/null @@ -1,238 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_NEW 3ossl" -.TH X509_NEW 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_new, X509_new_ex, -X509_free, X509_up_ref, -X509_chain_up_ref, -OSSL_STACK_OF_X509_free -\&\- X509 certificate ASN1 allocation and deallocation functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509 *X509_new(void); -\& X509 *X509_new_ex(OSSL_LIB_CTX *libctx, const char *propq); -\& void X509_free(X509 *a); -\& int X509_up_ref(X509 *a); -\& STACK_OF(X509) *X509_chain_up_ref(STACK_OF(X509) *x); -\& void OSSL_STACK_OF_X509_free(STACK_OF(X509) *certs); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The X509 \s-1ASN1\s0 allocation routines allocate and free an -X509 structure, which represents an X509 certificate. -.PP -\&\fBX509_new_ex()\fR allocates and initializes a X509 structure with a -library context of \fIlibctx\fR, property query of \fIpropq\fR and a reference -count of \fB1\fR. Many X509 functions such as \fBX509_check_purpose()\fR, and -\&\fBX509_verify()\fR use this library context to select which providers supply the -fetched algorithms (\s-1SHA1\s0 is used internally). This created X509 object can then -be used when loading binary data using \fBd2i_X509()\fR. -.PP -\&\fBX509_new()\fR is similar to \fBX509_new_ex()\fR but sets the library context -and property query to \s-1NULL.\s0 This results in the default (\s-1NULL\s0) library context -being used for any X509 operations requiring algorithm fetches. -.PP -\&\fBX509_free()\fR decrements the reference count of \fBX509\fR structure \fBa\fR and -frees it up if the reference count is zero. If the argument is \s-1NULL,\s0 -nothing is done. -.PP -\&\fBX509_up_ref()\fR increments the reference count of \fBa\fR. -.PP -\&\fBX509_chain_up_ref()\fR increases the reference count of all certificates in -chain \fBx\fR and returns a copy of the stack, or an empty stack if \fBa\fR is \s-1NULL.\s0 -.PP -\&\fBOSSL_STACK_OF_X509_free()\fR deallocates the given list of pointers to -certificates after calling \fBX509_free()\fR on all its elements. -If the argument is \s-1NULL,\s0 nothing is done. -.SH "NOTES" -.IX Header "NOTES" -The function \fBX509_up_ref()\fR if useful if a certificate structure is being -used by several different operations each of which will free it up after -use: this avoids the need to duplicate the entire certificate structure. -.PP -The function \fBX509_chain_up_ref()\fR doesn't just up the reference count of -each certificate. It also returns a copy of the stack, using \fBsk_X509_dup()\fR, -but it serves a similar purpose: the returned chain persists after the -original has been freed. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -If the allocation fails, \fBX509_new()\fR returns \s-1NULL\s0 and sets an error -code that can be obtained by \fBERR_get_error\fR\|(3). -Otherwise it returns a pointer to the newly allocated structure. -.PP -\&\fBX509_up_ref()\fR returns 1 for success and 0 for failure. -.PP -\&\fBX509_chain_up_ref()\fR returns a copy of the stack or \s-1NULL\s0 if an error occurred. -.PP -\&\fBOSSL_STACK_OF_X509_free()\fR has no return value. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_new_ex()\fR was added in OpenSSL 3.0. -.PP -\&\fBOSSL_STACK_OF_X509_free()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_new_ex.3ossl b/openssl-install/share/man/man3/X509_new_ex.3ossl deleted file mode 120000 index 43cc5a14..00000000 --- a/openssl-install/share/man/man3/X509_new_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_pubkey_digest.3ossl b/openssl-install/share/man/man3/X509_pubkey_digest.3ossl deleted file mode 120000 index c2b39912..00000000 --- a/openssl-install/share/man/man3/X509_pubkey_digest.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_digest.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_self_signed.3ossl b/openssl-install/share/man/man3/X509_self_signed.3ossl deleted file mode 120000 index 81904cb5..00000000 --- a/openssl-install/share/man/man3/X509_self_signed.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_verify.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set0_distinguishing_id.3ossl b/openssl-install/share/man/man3/X509_set0_distinguishing_id.3ossl deleted file mode 120000 index 8e2f6903..00000000 --- a/openssl-install/share/man/man3/X509_set0_distinguishing_id.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_distinguishing_id.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set1_notAfter.3ossl b/openssl-install/share/man/man3/X509_set1_notAfter.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_set1_notAfter.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set1_notBefore.3ossl b/openssl-install/share/man/man3/X509_set1_notBefore.3ossl deleted file mode 120000 index 08b7f45d..00000000 --- a/openssl-install/share/man/man3/X509_set1_notBefore.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get0_notBefore.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_ex_data.3ossl b/openssl-install/share/man/man3/X509_set_ex_data.3ossl deleted file mode 120000 index 9b1e8cf3..00000000 --- a/openssl-install/share/man/man3/X509_set_ex_data.3ossl +++ /dev/null @@ -1 +0,0 @@ -BIO_get_ex_new_index.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_issuer_name.3ossl b/openssl-install/share/man/man3/X509_set_issuer_name.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_set_issuer_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_proxy_flag.3ossl b/openssl-install/share/man/man3/X509_set_proxy_flag.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_set_proxy_flag.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_proxy_pathlen.3ossl b/openssl-install/share/man/man3/X509_set_proxy_pathlen.3ossl deleted file mode 120000 index 207ee79d..00000000 --- a/openssl-install/share/man/man3/X509_set_proxy_pathlen.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_extension_flags.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_pubkey.3ossl b/openssl-install/share/man/man3/X509_set_pubkey.3ossl deleted file mode 120000 index b4c8dd7c..00000000 --- a/openssl-install/share/man/man3/X509_set_pubkey.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_pubkey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_serialNumber.3ossl b/openssl-install/share/man/man3/X509_set_serialNumber.3ossl deleted file mode 120000 index b95323a0..00000000 --- a/openssl-install/share/man/man3/X509_set_serialNumber.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_serialNumber.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_subject_name.3ossl b/openssl-install/share/man/man3/X509_set_subject_name.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_set_subject_name.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_set_version.3ossl b/openssl-install/share/man/man3/X509_set_version.3ossl deleted file mode 120000 index 6a7e2ebc..00000000 --- a/openssl-install/share/man/man3/X509_set_version.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_version.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_sign.3ossl b/openssl-install/share/man/man3/X509_sign.3ossl deleted file mode 100644 index e86c1093..00000000 --- a/openssl-install/share/man/man3/X509_sign.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_SIGN 3ossl" -.TH X509_SIGN 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_sign, X509_sign_ctx, -X509_REQ_sign, X509_REQ_sign_ctx, -X509_ACERT_sign, X509_ACERT_sign_ctx, -X509_CRL_sign, X509_CRL_sign_ctx \- -sign certificate, certificate request, or CRL signature -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_sign(X509 *x, EVP_PKEY *pkey, const EVP_MD *md); -\& int X509_sign_ctx(X509 *x, EVP_MD_CTX *ctx); -\& -\& int X509_REQ_sign(X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md); -\& int X509_REQ_sign_ctx(X509_REQ *x, EVP_MD_CTX *ctx); -\& -\& int X509_CRL_sign(X509_CRL *x, EVP_PKEY *pkey, const EVP_MD *md); -\& int X509_CRL_sign_ctx(X509_CRL *x, EVP_MD_CTX *ctx); -\& -\& #include -\& -\& int X509_ACERT_sign(X509_ACERT *x, EVP_PKEY *pkey, const EVP_MD *md); -\& int X509_ACERT_sign_ctx(X509_ACERT *x, EVP_MD_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_sign()\fR signs certificate \fIx\fR using private key \fIpkey\fR and message -digest \fImd\fR and sets the signature in \fIx\fR. \fBX509_sign_ctx()\fR also signs -certificate \fIx\fR but uses the parameters contained in digest context \fIctx\fR. -If the certificate information includes X.509 extensions, -these two functions make sure that the certificate bears X.509 version 3. -.PP -\&\fBX509_REQ_sign()\fR, \fBX509_REQ_sign_ctx()\fR, -\&\fBX509_ACERT_sign()\fR, \fBX509_ACERT_sign_ctx()\fR, -\&\fBX509_CRL_sign()\fR, and \fBX509_CRL_sign_ctx()\fR -sign certificate requests and CRLs, respectively. -.SH "NOTES" -.IX Header "NOTES" -\&\fBX509_sign_ctx()\fR is used where the default parameters for the corresponding -public key and digest are not suitable. It can be used to sign keys using -RSA-PSS for example. -.PP -For efficiency reasons and to work around \s-1ASN.1\s0 encoding issues the encoding -of the signed portion of a certificate, certificate request and \s-1CRL\s0 is cached -internally. If the signed portion of the structure is modified the encoding -is not always updated meaning a stale version is sometimes used. This is not -normally a problem because modifying the signed portion will invalidate the -signature and signing will always update the encoding. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All functions return the size of the signature -in bytes for success and zero for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_verify_cert\fR\|(3), -\&\fBX509_verify\fR\|(3), -\&\fBX509_REQ_verify_ex\fR\|(3), \fBX509_REQ_verify\fR\|(3), -\&\fBX509_CRL_verify\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_sign()\fR, \fBX509_REQ_sign()\fR and \fBX509_CRL_sign()\fR functions are -available in all versions of OpenSSL. -.PP -The \fBX509_sign_ctx()\fR, \fBX509_REQ_sign_ctx()\fR -and \fBX509_CRL_sign_ctx()\fR functions were added in OpenSSL 1.0.1. -.PP -The \fBX509_ACERT_sign()\fR and \fBX509_ACERT_sign_ctx()\fR functions were added -in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_sign_ctx.3ossl b/openssl-install/share/man/man3/X509_sign_ctx.3ossl deleted file mode 120000 index 9080e9e2..00000000 --- a/openssl-install/share/man/man3/X509_sign_ctx.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_sign.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_subject_name_cmp.3ossl b/openssl-install/share/man/man3/X509_subject_name_cmp.3ossl deleted file mode 120000 index e12f4f89..00000000 --- a/openssl-install/share/man/man3/X509_subject_name_cmp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_subject_name_hash.3ossl b/openssl-install/share/man/man3/X509_subject_name_hash.3ossl deleted file mode 120000 index b1215d35..00000000 --- a/openssl-install/share/man/man3/X509_subject_name_hash.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_get_subject_name.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_time_adj.3ossl b/openssl-install/share/man/man3/X509_time_adj.3ossl deleted file mode 120000 index cdeff4ec..00000000 --- a/openssl-install/share/man/man3/X509_time_adj.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_time_adj_ex.3ossl b/openssl-install/share/man/man3/X509_time_adj_ex.3ossl deleted file mode 120000 index cdeff4ec..00000000 --- a/openssl-install/share/man/man3/X509_time_adj_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_cmp_time.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_up_ref.3ossl b/openssl-install/share/man/man3/X509_up_ref.3ossl deleted file mode 120000 index 43cc5a14..00000000 --- a/openssl-install/share/man/man3/X509_up_ref.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509_verify.3ossl b/openssl-install/share/man/man3/X509_verify.3ossl deleted file mode 100644 index 3c1429ef..00000000 --- a/openssl-install/share/man/man3/X509_verify.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_VERIFY 3ossl" -.TH X509_VERIFY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_verify, X509_self_signed, -X509_REQ_verify_ex, X509_REQ_verify, -X509_CRL_verify, X509_ACERT_verify \- -verify certificate, certificate request, or CRL signature -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509_verify(X509 *x, EVP_PKEY *pkey); -\& int X509_self_signed(X509 *cert, int verify_signature); -\& -\& int X509_REQ_verify_ex(X509_REQ *a, EVP_PKEY *pkey, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int X509_REQ_verify(X509_REQ *a, EVP_PKEY *r); -\& int X509_CRL_verify(X509_CRL *a, EVP_PKEY *r); -\& -\& #include -\& int X509_ACERT_verify(X509_CRL *a, EVP_PKEY *r); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_verify()\fR verifies the signature of certificate \fIx\fR using public key -\&\fIpkey\fR. Only the signature is checked: no other checks (such as certificate -chain validity) are performed. -.PP -\&\fBX509_self_signed()\fR checks whether certificate \fIcert\fR is self-signed. -For success the issuer and subject names must match, the components of the -authority key identifier (if present) must match the subject key identifier etc. -The signature itself is actually verified only if \fBverify_signature\fR is 1, as -for explicitly trusted certificates this verification is not worth the effort. -.PP -\&\fBX509_REQ_verify_ex()\fR, \fBX509_REQ_verify()\fR, \fBX509_CRL_verify()\fR and \fBX509_ACERT_verify()\fR -verify the signatures of certificate requests, CRLs and attribute certificates -respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_verify()\fR, -\&\fBX509_REQ_verify_ex()\fR, \fBX509_REQ_verify()\fR and \fBX509_CRL_verify()\fR -return 1 if the signature is valid and 0 if the signature check fails. -If the signature could not be checked at all because it was ill-formed, -the certificate or the request was not complete or some other error occurred -then \-1 is returned. -.PP -\&\fBX509_self_signed()\fR returns the same values but also returns 1 -if all respective fields match and \fBverify_signature\fR is 0. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_X509\fR\|(3), -\&\fBERR_get_error\fR\|(3), -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3), -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBX509_verify()\fR, \fBX509_REQ_verify()\fR, and \fBX509_CRL_verify()\fR -functions are available in all versions of OpenSSL. -.PP -\&\fBX509_REQ_verify_ex()\fR, and \fBX509_self_signed()\fR were added in OpenSSL 3.0. -.PP -\&\fBX509_ACERT_verify()\fR was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_verify_cert.3ossl b/openssl-install/share/man/man3/X509_verify_cert.3ossl deleted file mode 100644 index 2bd1b929..00000000 --- a/openssl-install/share/man/man3/X509_verify_cert.3ossl +++ /dev/null @@ -1,243 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509_VERIFY_CERT 3ossl" -.TH X509_VERIFY_CERT 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509_build_chain, -X509_verify_cert, -X509_STORE_CTX_verify \- build and verify X509 certificate chain -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(X509) *X509_build_chain(X509 *target, STACK_OF(X509) *certs, -\& X509_STORE *store, int with_self_signed, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int X509_verify_cert(X509_STORE_CTX *ctx); -\& int X509_STORE_CTX_verify(X509_STORE_CTX *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509_build_chain()\fR builds a certificate chain starting from \fItarget\fR -using the optional list of intermediate \s-1CA\s0 certificates \fIcerts\fR. -If \fIstore\fR is \s-1NULL\s0 it builds the chain as far down as possible, ignoring errors. -Else the chain must reach a trust anchor contained in \fIstore\fR. -It internally uses a \fBX509_STORE_CTX\fR structure associated with the library -context \fIlibctx\fR and property query string \fIpropq\fR, both of which may be \s-1NULL.\s0 -In case there is more than one possibility for the chain, only one is taken. -.PP -On success it returns a pointer to a new stack of (up_ref'ed) certificates -starting with \fItarget\fR and followed by all available intermediate certificates. -A self-signed trust anchor is included only if \fItarget\fR is the trust anchor -of \fIwith_self_signed\fR is 1. -If a non-NULL stack is returned the caller is responsible for freeing it. -.PP -The \fBX509_verify_cert()\fR function attempts to discover and validate a -certificate chain based on parameters in \fIctx\fR. -The verification context, of type \fBX509_STORE_CTX\fR, can be constructed -using \fBX509_STORE_CTX_new\fR\|(3) and \fBX509_STORE_CTX_init\fR\|(3). -It usually includes a target certificate to be verified, -a set of certificates serving as trust anchors, -a list of non-trusted certificates that may be helpful for chain construction, -flags such as X509_V_FLAG_X509_STRICT, and various other optional components -such as a callback function that allows customizing the verification outcome. -A complete description of the certificate verification process is contained in -the \fBopenssl\-verification\-options\fR\|(1) manual page. -.PP -Applications rarely call this function directly but it is used by -OpenSSL internally for certificate validation, in both the S/MIME and -\&\s-1SSL/TLS\s0 code. -.PP -A negative return value from \fBX509_verify_cert()\fR can occur if it is invoked -incorrectly, such as with no certificate set in \fIctx\fR, or when it is called -twice in succession without reinitialising \fIctx\fR for the second call. -A negative return value can also happen due to internal resource problems -or because an internal inconsistency has been detected. -Applications must interpret any return value <= 0 as an error. -.PP -The \fBX509_STORE_CTX_verify()\fR behaves like \fBX509_verify_cert()\fR except that its -target certificate is the first element of the list of untrusted certificates -in \fIctx\fR unless a target certificate is set explicitly. -.PP -When the verification target is a raw public key, rather than a certificate, -both functions validate the target raw public key. -In that case the number of possible checks is significantly reduced. -The raw public key can be authenticated only via \s-1DANE TLSA\s0 records, either -locally synthesised or obtained by the application from \s-1DNS.\s0 -Raw public key \s-1DANE TLSA\s0 records may be added via \fBSSL_add_expected_rpk\fR\|(3) or -\&\fBSSL_dane_tlsa_add\fR\|(3). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509_build_chain()\fR returns \s-1NULL\s0 on error, else a stack of certificates. -.PP -Both \fBX509_verify_cert()\fR and \fBX509_STORE_CTX_verify()\fR -return 1 if a complete chain can be built and validated, -otherwise they return 0, and in exceptional circumstances (such as malloc -failure and internal errors) they can also return a negative code. -.PP -If a complete chain can be built and validated both functions return 1. -If the certificate must be rejected on the basis of the data available -or any required certificate status data is not available they return 0. -If no definite answer possible they usually return a negative code. -.PP -On error or failure additional error information can be obtained by -examining \fIctx\fR using, for example, \fBX509_STORE_CTX_get_error\fR\|(3). Even if -verification indicated success, the stored error code may be different from -X509_V_OK, likely because a verification callback function has waived the error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_add_expected_rpk\fR\|(3), -\&\fBSSL_CTX_dane_enable\fR\|(3), -\&\fBSSL_dane_tlsa_add\fR\|(3), -\&\fBX509_STORE_CTX_new\fR\|(3), -\&\fBX509_STORE_CTX_init\fR\|(3), -\&\fBX509_STORE_CTX_init_rpk\fR\|(3), -\&\fBX509_STORE_CTX_get_error\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509_build_chain()\fR and \fBX509_STORE_CTX_verify()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2009\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509_verify_cert_error_string.3ossl b/openssl-install/share/man/man3/X509_verify_cert_error_string.3ossl deleted file mode 120000 index d322bb86..00000000 --- a/openssl-install/share/man/man3/X509_verify_cert_error_string.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_STORE_CTX_get_error.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_add1_attr.3ossl b/openssl-install/share/man/man3/X509at_add1_attr.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_add1_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_add1_attr_by_NID.3ossl b/openssl-install/share/man/man3/X509at_add1_attr_by_NID.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_add1_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_add1_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/X509at_add1_attr_by_OBJ.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_add1_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_add1_attr_by_txt.3ossl b/openssl-install/share/man/man3/X509at_add1_attr_by_txt.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_add1_attr_by_txt.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_delete_attr.3ossl b/openssl-install/share/man/man3/X509at_delete_attr.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_delete_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_get0_data_by_OBJ.3ossl b/openssl-install/share/man/man3/X509at_get0_data_by_OBJ.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_get0_data_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_get_attr.3ossl b/openssl-install/share/man/man3/X509at_get_attr.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_get_attr.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_get_attr_by_NID.3ossl b/openssl-install/share/man/man3/X509at_get_attr_by_NID.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_get_attr_by_NID.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_get_attr_by_OBJ.3ossl b/openssl-install/share/man/man3/X509at_get_attr_by_OBJ.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_get_attr_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509at_get_attr_count.3ossl b/openssl-install/share/man/man3/X509at_get_attr_count.3ossl deleted file mode 120000 index 86647cfa..00000000 --- a/openssl-install/share/man/man3/X509at_get_attr_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_ATTRIBUTE.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509v3_add_ext.3ossl b/openssl-install/share/man/man3/X509v3_add_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509v3_add_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509v3_add_extensions.3ossl b/openssl-install/share/man/man3/X509v3_add_extensions.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509v3_add_extensions.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509v3_delete_ext.3ossl b/openssl-install/share/man/man3/X509v3_delete_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509v3_delete_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509v3_get_ext.3ossl b/openssl-install/share/man/man3/X509v3_get_ext.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509v3_get_ext.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509v3_get_ext_by_NID.3ossl b/openssl-install/share/man/man3/X509v3_get_ext_by_NID.3ossl deleted file mode 100644 index 63cf6132..00000000 --- a/openssl-install/share/man/man3/X509v3_get_ext_by_NID.3ossl +++ /dev/null @@ -1,298 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509V3_GET_EXT_BY_NID 3ossl" -.TH X509V3_GET_EXT_BY_NID 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X509v3_get_ext_count, X509v3_get_ext, X509v3_get_ext_by_NID, -X509v3_get_ext_by_OBJ, X509v3_get_ext_by_critical, X509v3_delete_ext, -X509v3_add_ext, X509v3_add_extensions, X509_get_ext_count, X509_get_ext, -X509_get_ext_by_NID, X509_get_ext_by_OBJ, X509_get_ext_by_critical, -X509_delete_ext, X509_add_ext, X509_CRL_get_ext_count, X509_CRL_get_ext, -X509_CRL_get_ext_by_NID, X509_CRL_get_ext_by_OBJ, X509_CRL_get_ext_by_critical, -X509_CRL_delete_ext, X509_CRL_add_ext, X509_REVOKED_get_ext_count, -X509_REVOKED_get_ext, X509_REVOKED_get_ext_by_NID, X509_REVOKED_get_ext_by_OBJ, -X509_REVOKED_get_ext_by_critical, X509_REVOKED_delete_ext, -X509_REVOKED_add_ext \- extension stack utility functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION) *x); -\& X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc); -\& -\& int X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION) *x, -\& int nid, int lastpos); -\& int X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION) *x, -\& const ASN1_OBJECT *obj, int lastpos); -\& int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION) *x, -\& int crit, int lastpos); -\& X509_EXTENSION *X509v3_delete_ext(STACK_OF(X509_EXTENSION) *x, int loc); -\& STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x, -\& X509_EXTENSION *ex, int loc); -\& STACK_OF(X509_EXTENSION) -\& *X509v3_add_extensions(STACK_OF(X509_EXTENSION) **target, -\& const STACK_OF(X509_EXTENSION) *exts); -\& -\& int X509_get_ext_count(const X509 *x); -\& X509_EXTENSION *X509_get_ext(const X509 *x, int loc); -\& int X509_get_ext_by_NID(const X509 *x, int nid, int lastpos); -\& int X509_get_ext_by_OBJ(const X509 *x, const ASN1_OBJECT *obj, int lastpos); -\& int X509_get_ext_by_critical(const X509 *x, int crit, int lastpos); -\& X509_EXTENSION *X509_delete_ext(X509 *x, int loc); -\& int X509_add_ext(X509 *x, X509_EXTENSION *ex, int loc); -\& -\& int X509_CRL_get_ext_count(const X509_CRL *x); -\& X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc); -\& int X509_CRL_get_ext_by_NID(const X509_CRL *x, int nid, int lastpos); -\& int X509_CRL_get_ext_by_OBJ(const X509_CRL *x, const ASN1_OBJECT *obj, -\& int lastpos); -\& int X509_CRL_get_ext_by_critical(const X509_CRL *x, int crit, int lastpos); -\& X509_EXTENSION *X509_CRL_delete_ext(X509_CRL *x, int loc); -\& int X509_CRL_add_ext(X509_CRL *x, X509_EXTENSION *ex, int loc); -\& -\& int X509_REVOKED_get_ext_count(const X509_REVOKED *x); -\& X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc); -\& int X509_REVOKED_get_ext_by_NID(const X509_REVOKED *x, int nid, int lastpos); -\& int X509_REVOKED_get_ext_by_OBJ(const X509_REVOKED *x, const ASN1_OBJECT *obj, -\& int lastpos); -\& int X509_REVOKED_get_ext_by_critical(const X509_REVOKED *x, int crit, int lastpos); -\& X509_EXTENSION *X509_REVOKED_delete_ext(X509_REVOKED *x, int loc); -\& int X509_REVOKED_add_ext(X509_REVOKED *x, X509_EXTENSION *ex, int loc); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBX509v3_get_ext_count()\fR retrieves the number of extensions in \fIx\fR. -.PP -\&\fBX509v3_get_ext()\fR retrieves extension \fIloc\fR from \fIx\fR. The index \fIloc\fR -can take any value from 0 to X509_get_ext_count(\fIx\fR) \- 1. The returned -extension is an internal pointer which \fB\s-1MUST NOT\s0\fR be freed by the -application. -.PP -\&\fBX509v3_get_ext_by_NID()\fR and \fBX509v3_get_ext_by_OBJ()\fR look for an extension -with \fInid\fR or \fIobj\fR from extension \s-1STACK\s0 \fIx\fR. The search starts from the -extension after \fIlastpos\fR or from the beginning if \fIlastpos\fR is \-1. If -the extension is found, its index is returned, otherwise \-1 is returned. -.PP -\&\fBX509v3_get_ext_by_critical()\fR is similar to \fBX509v3_get_ext_by_NID()\fR except it -looks for an extension of criticality \fIcrit\fR. A zero value for \fIcrit\fR -looks for a non-critical extension. A nonzero value looks for a critical -extension. -.PP -\&\fBX509v3_delete_ext()\fR deletes the extension with index \fIloc\fR from \fIx\fR. -The deleted extension is returned and must be freed by the caller. -If \fIloc\fR is an invalid index value, \s-1NULL\s0 is returned. -.PP -\&\fBX509v3_add_ext()\fR inserts extension \fIex\fR to \s-1STACK\s0 \fI*x\fR at position \fIloc\fR. -If \fIloc\fR is \-1, the new extension is added to the end. -A new \s-1STACK\s0 is allocated if \fI*x\fR is \s-1NULL.\s0 -The passed extension \fIex\fR is duplicated so it must be freed after use. -.PP -\&\fBX509v3_add_extensions()\fR adds the list of extensions \fIexts\fR to \s-1STACK\s0 \fI*target\fR. -The \s-1STACK\s0 \fI*target\fR is returned unchanged if \fIexts\fR is \s-1NULL\s0 or an empty list. -Otherwise a new stack is allocated if \fI*target\fR is \s-1NULL.\s0 -An extension to be added -that has the same \s-1OID\s0 as a pre-existing one replaces this earlier one. -.PP -\&\fBX509_get_ext_count()\fR, \fBX509_get_ext()\fR, \fBX509_get_ext_by_NID()\fR, -\&\fBX509_get_ext_by_OBJ()\fR, \fBX509_get_ext_by_critical()\fR, \fBX509_delete_ext()\fR -and \fBX509_add_ext()\fR operate on the extensions of certificate \fIx\fR. They are -otherwise identical to the X509v3 functions. -.PP -\&\fBX509_CRL_get_ext_count()\fR, \fBX509_CRL_get_ext()\fR, \fBX509_CRL_get_ext_by_NID()\fR, -\&\fBX509_CRL_get_ext_by_OBJ()\fR, \fBX509_CRL_get_ext_by_critical()\fR, -\&\fBX509_CRL_delete_ext()\fR and \fBX509_CRL_add_ext()\fR operate on the extensions of -\&\s-1CRL\s0 \fIx\fR. They are otherwise identical to the X509v3 functions. -.PP -\&\fBX509_REVOKED_get_ext_count()\fR, \fBX509_REVOKED_get_ext()\fR, -\&\fBX509_REVOKED_get_ext_by_NID()\fR, \fBX509_REVOKED_get_ext_by_OBJ()\fR, -\&\fBX509_REVOKED_get_ext_by_critical()\fR, \fBX509_REVOKED_delete_ext()\fR and -\&\fBX509_REVOKED_add_ext()\fR operate on the extensions of \s-1CRL\s0 entry \fIx\fR. -They are otherwise identical to the X509v3 functions. -.SH "NOTES" -.IX Header "NOTES" -These functions are used to examine stacks of extensions directly. -Applications that want to parse or encode and add an extension should -use the extension encode and decode functions instead, such as -\&\fBX509_add1_ext_i2d()\fR and \fBX509_get_ext_d2i()\fR. -.PP -For \fBX509v3_get_ext_by_NID()\fR, \fBX509v3_get_ext_by_OBJ()\fR, -\&\fBX509v3_get_ext_by_critical()\fR and its variants, a zero index return value -is not an error since extension \s-1STACK\s0 \fIx\fR indices start from zero. -These search functions start from the extension \fBafter\fR the \fIlastpos\fR parameter -so it should initially be set to \-1. If it is set to zero, the initial extension -will not be checked. -.PP -\&\fBX509v3_delete_ext()\fR and its variants are a bit counter-intuitive -because these functions do not free the extension they delete. -They return an \fBX509_EXTENSION\fR object which must be explicitly freed -using \fBX509_EXTENSION_free()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBX509v3_get_ext_count()\fR returns the extension count or 0 for failure. -.PP -\&\fBX509v3_get_ext()\fR, \fBX509v3_delete_ext()\fR and \fBX509_delete_ext()\fR return an -\&\fBX509_EXTENSION\fR structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBX509v3_get_ext_by_OBJ()\fR and \fBX509v3_get_ext_by_critical()\fR return -the extension index or \-1 if an error occurs. -.PP -\&\fBX509v3_get_ext_by_NID()\fR returns the extension index or negative values if an -error occurs. -.PP -\&\fBX509v3_add_ext()\fR returns a \s-1STACK\s0 of extensions or \s-1NULL\s0 on error. -.PP -\&\fBX509v3_add_extensions()\fR returns a \s-1STACK\s0 of extensions -or \s-1NULL\s0 on error or if \fI*target\fR is \s-1NULL\s0 and \fIexts\fR is \s-1NULL\s0 or an empty list. -.PP -\&\fBX509_add_ext()\fR returns 1 on success and 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509V3_get_d2i\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBX509v3_add_extensions()\fR was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2015\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/X509v3_get_ext_by_OBJ.3ossl b/openssl-install/share/man/man3/X509v3_get_ext_by_OBJ.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509v3_get_ext_by_OBJ.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509v3_get_ext_by_critical.3ossl b/openssl-install/share/man/man3/X509v3_get_ext_by_critical.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509v3_get_ext_by_critical.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/X509v3_get_ext_count.3ossl b/openssl-install/share/man/man3/X509v3_get_ext_count.3ossl deleted file mode 120000 index c197bab2..00000000 --- a/openssl-install/share/man/man3/X509v3_get_ext_count.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509v3_get_ext_by_NID.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/b2i_PVK_bio.3ossl b/openssl-install/share/man/man3/b2i_PVK_bio.3ossl deleted file mode 120000 index 77ba71b4..00000000 --- a/openssl-install/share/man/man3/b2i_PVK_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -b2i_PVK_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/b2i_PVK_bio_ex.3ossl b/openssl-install/share/man/man3/b2i_PVK_bio_ex.3ossl deleted file mode 100644 index 832a2166..00000000 --- a/openssl-install/share/man/man3/b2i_PVK_bio_ex.3ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "B2I_PVK_BIO_EX 3ossl" -.TH B2I_PVK_BIO_EX 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -b2i_PVK_bio, b2i_PVK_bio_ex, i2b_PVK_bio, i2b_PVK_bio_ex \- Decode and encode -functions for reading and writing MSBLOB format private keys -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *b2i_PVK_bio(BIO *in, pem_password_cb *cb, void *u); -\& EVP_PKEY *b2i_PVK_bio_ex(BIO *in, pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -\& int i2b_PVK_bio(BIO *out, const EVP_PKEY *pk, int enclevel, -\& pem_password_cb *cb, void *u); -\& int i2b_PVK_bio_ex(BIO *out, const EVP_PKEY *pk, int enclevel, -\& pem_password_cb *cb, void *u, -\& OSSL_LIB_CTX *libctx, const char *propq); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBb2i_PVK_bio_ex()\fR decodes a private key of \s-1MSBLOB\s0 format read from a \fB\s-1BIO\s0\fR. It -attempts to automatically determine the key type. If the key is encrypted then -\&\fIcb\fR is called with the user data \fIu\fR in order to obtain a password to decrypt -the key. The supplied library context \fIlibctx\fR and property query -string \fIpropq\fR are used in any decrypt operation. -.PP -\&\fBb2i_PVK_bio()\fR does the same as \fBb2i_PVK_bio_ex()\fR except that the default -library context and property query string are used. -.PP -\&\fBi2b_PVK_bio_ex()\fR encodes \fIpk\fR using \s-1MSBLOB\s0 format. If \fIenclevel\fR is 1 then -a password obtained via \fIpem_password_cb\fR is used to encrypt the private key. -If \fIenclevel\fR is 0 then no encryption is applied. The user data in \fIu\fR is -passed to the password callback. The supplied library context \fIlibctx\fR and -property query string \fIpropq\fR are used in any decrypt operation. -.PP -\&\fBi2b_PVK_bio()\fR does the same as \fBi2b_PVK_bio_ex()\fR except that the default -library context and property query string are used. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBb2i_PVK_bio()\fR and \fBb2i_PVK_bio_ex()\fR functions return a valid \fB\s-1EVP_KEY\s0\fR -structure or \fB\s-1NULL\s0\fR if an error occurs. The error code can be obtained by calling -\&\fBERR_get_error\fR\|(3). -.PP -\&\fBi2b_PVK_bio()\fR and \fBi2b_PVK_bio_ex()\fR return the number of bytes successfully -encoded or a negative value if an error occurs. The error code can be obtained -by calling \fBERR_get_error\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), -\&\fBd2i_PKCS8PrivateKey_bio\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBb2i_PVK_bio_ex()\fR and \fBi2b_PVK_bio_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/custom_ext_add_cb.3ossl b/openssl-install/share/man/man3/custom_ext_add_cb.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/custom_ext_add_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/custom_ext_free_cb.3ossl b/openssl-install/share/man/man3/custom_ext_free_cb.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/custom_ext_free_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/custom_ext_parse_cb.3ossl b/openssl-install/share/man/man3/custom_ext_parse_cb.3ossl deleted file mode 120000 index 35804750..00000000 --- a/openssl-install/share/man/man3/custom_ext_parse_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_extension_supported.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ACCESS_DESCRIPTION.3ossl b/openssl-install/share/man/man3/d2i_ACCESS_DESCRIPTION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ACCESS_DESCRIPTION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ADMISSIONS.3ossl b/openssl-install/share/man/man3/d2i_ADMISSIONS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ADMISSIONS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ADMISSION_SYNTAX.3ossl b/openssl-install/share/man/man3/d2i_ADMISSION_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ADMISSION_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASIdOrRange.3ossl b/openssl-install/share/man/man3/d2i_ASIdOrRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASIdOrRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASIdentifierChoice.3ossl b/openssl-install/share/man/man3/d2i_ASIdentifierChoice.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASIdentifierChoice.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASIdentifiers.3ossl b/openssl-install/share/man/man3/d2i_ASIdentifiers.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASIdentifiers.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_BIT_STRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_BIT_STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_BIT_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_BMPSTRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_BMPSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_BMPSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_ENUMERATED.3ossl b/openssl-install/share/man/man3/d2i_ASN1_ENUMERATED.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_ENUMERATED.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_GENERALIZEDTIME.3ossl b/openssl-install/share/man/man3/d2i_ASN1_GENERALIZEDTIME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_GENERALIZEDTIME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_GENERALSTRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_GENERALSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_GENERALSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_IA5STRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_IA5STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_IA5STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_INTEGER.3ossl b/openssl-install/share/man/man3/d2i_ASN1_INTEGER.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_INTEGER.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_NULL.3ossl b/openssl-install/share/man/man3/d2i_ASN1_NULL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_NULL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_OBJECT.3ossl b/openssl-install/share/man/man3/d2i_ASN1_OBJECT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_OBJECT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_OCTET_STRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_OCTET_STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_OCTET_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_PRINTABLE.3ossl b/openssl-install/share/man/man3/d2i_ASN1_PRINTABLE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_PRINTABLE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_PRINTABLESTRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_PRINTABLESTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_PRINTABLESTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_SEQUENCE_ANY.3ossl b/openssl-install/share/man/man3/d2i_ASN1_SEQUENCE_ANY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_SEQUENCE_ANY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_SET_ANY.3ossl b/openssl-install/share/man/man3/d2i_ASN1_SET_ANY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_SET_ANY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_T61STRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_T61STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_T61STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_TIME.3ossl b/openssl-install/share/man/man3/d2i_ASN1_TIME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_TIME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_TYPE.3ossl b/openssl-install/share/man/man3/d2i_ASN1_TYPE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_TYPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_UINTEGER.3ossl b/openssl-install/share/man/man3/d2i_ASN1_UINTEGER.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_UINTEGER.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_UNIVERSALSTRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_UNIVERSALSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_UNIVERSALSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_UTCTIME.3ossl b/openssl-install/share/man/man3/d2i_ASN1_UTCTIME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_UTCTIME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_UTF8STRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_UTF8STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_UTF8STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASN1_VISIBLESTRING.3ossl b/openssl-install/share/man/man3/d2i_ASN1_VISIBLESTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASN1_VISIBLESTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ASRange.3ossl b/openssl-install/share/man/man3/d2i_ASRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ASRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_AUTHORITY_INFO_ACCESS.3ossl b/openssl-install/share/man/man3/d2i_AUTHORITY_INFO_ACCESS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_AUTHORITY_INFO_ACCESS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_AUTHORITY_KEYID.3ossl b/openssl-install/share/man/man3/d2i_AUTHORITY_KEYID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_AUTHORITY_KEYID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_AutoPrivateKey.3ossl b/openssl-install/share/man/man3/d2i_AutoPrivateKey.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_AutoPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_AutoPrivateKey_ex.3ossl b/openssl-install/share/man/man3/d2i_AutoPrivateKey_ex.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_AutoPrivateKey_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_BASIC_CONSTRAINTS.3ossl b/openssl-install/share/man/man3/d2i_BASIC_CONSTRAINTS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_BASIC_CONSTRAINTS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_CERTIFICATEPOLICIES.3ossl b/openssl-install/share/man/man3/d2i_CERTIFICATEPOLICIES.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_CERTIFICATEPOLICIES.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_CMS_ContentInfo.3ossl b/openssl-install/share/man/man3/d2i_CMS_ContentInfo.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_CMS_ContentInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_CMS_ReceiptRequest.3ossl b/openssl-install/share/man/man3/d2i_CMS_ReceiptRequest.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_CMS_ReceiptRequest.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_CMS_bio.3ossl b/openssl-install/share/man/man3/d2i_CMS_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_CMS_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_CRL_DIST_POINTS.3ossl b/openssl-install/share/man/man3/d2i_CRL_DIST_POINTS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_CRL_DIST_POINTS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DHparams.3ossl b/openssl-install/share/man/man3/d2i_DHparams.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DHparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DHparams_bio.3ossl b/openssl-install/share/man/man3/d2i_DHparams_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DHparams_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DHparams_fp.3ossl b/openssl-install/share/man/man3/d2i_DHparams_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DHparams_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DHxparams.3ossl b/openssl-install/share/man/man3/d2i_DHxparams.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_DHxparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DIRECTORYSTRING.3ossl b/openssl-install/share/man/man3/d2i_DIRECTORYSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_DIRECTORYSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DISPLAYTEXT.3ossl b/openssl-install/share/man/man3/d2i_DISPLAYTEXT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_DISPLAYTEXT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DIST_POINT.3ossl b/openssl-install/share/man/man3/d2i_DIST_POINT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_DIST_POINT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DIST_POINT_NAME.3ossl b/openssl-install/share/man/man3/d2i_DIST_POINT_NAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_DIST_POINT_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSAPrivateKey.3ossl b/openssl-install/share/man/man3/d2i_DSAPrivateKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSAPrivateKey_bio.3ossl b/openssl-install/share/man/man3/d2i_DSAPrivateKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSAPrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSAPrivateKey_fp.3ossl b/openssl-install/share/man/man3/d2i_DSAPrivateKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSAPrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSAPublicKey.3ossl b/openssl-install/share/man/man3/d2i_DSAPublicKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSA_PUBKEY.3ossl b/openssl-install/share/man/man3/d2i_DSA_PUBKEY.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSA_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/d2i_DSA_PUBKEY_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSA_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSA_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/d2i_DSA_PUBKEY_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSA_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSA_SIG.3ossl b/openssl-install/share/man/man3/d2i_DSA_SIG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_DSA_SIG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_DSAparams.3ossl b/openssl-install/share/man/man3/d2i_DSAparams.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_DSAparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ECDSA_SIG.3ossl b/openssl-install/share/man/man3/d2i_ECDSA_SIG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ECDSA_SIG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ECPKParameters.3ossl b/openssl-install/share/man/man3/d2i_ECPKParameters.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ECPKParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ECParameters.3ossl b/openssl-install/share/man/man3/d2i_ECParameters.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_ECParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ECPrivateKey.3ossl b/openssl-install/share/man/man3/d2i_ECPrivateKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_ECPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ECPrivateKey_bio.3ossl b/openssl-install/share/man/man3/d2i_ECPrivateKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_ECPrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ECPrivateKey_fp.3ossl b/openssl-install/share/man/man3/d2i_ECPrivateKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_ECPrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_EC_PUBKEY.3ossl b/openssl-install/share/man/man3/d2i_EC_PUBKEY.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_EC_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_EC_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/d2i_EC_PUBKEY_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_EC_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_EC_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/d2i_EC_PUBKEY_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_EC_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_EDIPARTYNAME.3ossl b/openssl-install/share/man/man3/d2i_EDIPARTYNAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_EDIPARTYNAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ESS_CERT_ID.3ossl b/openssl-install/share/man/man3/d2i_ESS_CERT_ID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ESS_CERT_ID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ESS_CERT_ID_V2.3ossl b/openssl-install/share/man/man3/d2i_ESS_CERT_ID_V2.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ESS_CERT_ID_V2.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ESS_ISSUER_SERIAL.3ossl b/openssl-install/share/man/man3/d2i_ESS_ISSUER_SERIAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ESS_ISSUER_SERIAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT.3ossl b/openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT_V2.3ossl b/openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT_V2.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ESS_SIGNING_CERT_V2.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_EXTENDED_KEY_USAGE.3ossl b/openssl-install/share/man/man3/d2i_EXTENDED_KEY_USAGE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_EXTENDED_KEY_USAGE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_GENERAL_NAME.3ossl b/openssl-install/share/man/man3/d2i_GENERAL_NAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_GENERAL_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_GENERAL_NAMES.3ossl b/openssl-install/share/man/man3/d2i_GENERAL_NAMES.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_GENERAL_NAMES.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_IPAddressChoice.3ossl b/openssl-install/share/man/man3/d2i_IPAddressChoice.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_IPAddressChoice.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_IPAddressFamily.3ossl b/openssl-install/share/man/man3/d2i_IPAddressFamily.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_IPAddressFamily.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_IPAddressOrRange.3ossl b/openssl-install/share/man/man3/d2i_IPAddressOrRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_IPAddressOrRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_IPAddressRange.3ossl b/openssl-install/share/man/man3/d2i_IPAddressRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_IPAddressRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ISSUER_SIGN_TOOL.3ossl b/openssl-install/share/man/man3/d2i_ISSUER_SIGN_TOOL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ISSUER_SIGN_TOOL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_ISSUING_DIST_POINT.3ossl b/openssl-install/share/man/man3/d2i_ISSUING_DIST_POINT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_ISSUING_DIST_POINT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_KeyParams.3ossl b/openssl-install/share/man/man3/d2i_KeyParams.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_KeyParams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_KeyParams_bio.3ossl b/openssl-install/share/man/man3/d2i_KeyParams_bio.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_KeyParams_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_NAMING_AUTHORITY.3ossl b/openssl-install/share/man/man3/d2i_NAMING_AUTHORITY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_NAMING_AUTHORITY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_NETSCAPE_CERT_SEQUENCE.3ossl b/openssl-install/share/man/man3/d2i_NETSCAPE_CERT_SEQUENCE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_NETSCAPE_CERT_SEQUENCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_NETSCAPE_SPKAC.3ossl b/openssl-install/share/man/man3/d2i_NETSCAPE_SPKAC.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_NETSCAPE_SPKAC.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_NETSCAPE_SPKI.3ossl b/openssl-install/share/man/man3/d2i_NETSCAPE_SPKI.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_NETSCAPE_SPKI.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_NOTICEREF.3ossl b/openssl-install/share/man/man3/d2i_NOTICEREF.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_NOTICEREF.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_BASICRESP.3ossl b/openssl-install/share/man/man3/d2i_OCSP_BASICRESP.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_BASICRESP.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_CERTID.3ossl b/openssl-install/share/man/man3/d2i_OCSP_CERTID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_CERTID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_CERTSTATUS.3ossl b/openssl-install/share/man/man3/d2i_OCSP_CERTSTATUS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_CERTSTATUS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_CRLID.3ossl b/openssl-install/share/man/man3/d2i_OCSP_CRLID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_CRLID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_ONEREQ.3ossl b/openssl-install/share/man/man3/d2i_OCSP_ONEREQ.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_ONEREQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_REQINFO.3ossl b/openssl-install/share/man/man3/d2i_OCSP_REQINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_REQINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_REQUEST.3ossl b/openssl-install/share/man/man3/d2i_OCSP_REQUEST.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_REQUEST.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_RESPBYTES.3ossl b/openssl-install/share/man/man3/d2i_OCSP_RESPBYTES.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_RESPBYTES.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_RESPDATA.3ossl b/openssl-install/share/man/man3/d2i_OCSP_RESPDATA.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_RESPDATA.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_RESPID.3ossl b/openssl-install/share/man/man3/d2i_OCSP_RESPID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_RESPID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_RESPONSE.3ossl b/openssl-install/share/man/man3/d2i_OCSP_RESPONSE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_RESPONSE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_REVOKEDINFO.3ossl b/openssl-install/share/man/man3/d2i_OCSP_REVOKEDINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_REVOKEDINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_SERVICELOC.3ossl b/openssl-install/share/man/man3/d2i_OCSP_SERVICELOC.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_SERVICELOC.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_SIGNATURE.3ossl b/openssl-install/share/man/man3/d2i_OCSP_SIGNATURE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_SIGNATURE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OCSP_SINGLERESP.3ossl b/openssl-install/share/man/man3/d2i_OCSP_SINGLERESP.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OCSP_SINGLERESP.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_ATTRIBUTES_SYNTAX.3ossl b/openssl-install/share/man/man3/d2i_OSSL_ATTRIBUTES_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_ATTRIBUTES_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl b/openssl-install/share/man/man3/d2i_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CMP_ATAVS.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CMP_ATAVS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CMP_ATAVS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CMP_MSG.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CMP_MSG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CMP_MSG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CMP_MSG_bio.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CMP_MSG_bio.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CMP_MSG_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CMP_PKIHEADER.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CMP_PKIHEADER.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CMP_PKIHEADER.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CMP_PKISI.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CMP_PKISI.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CMP_PKISI.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTID.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTTEMPLATE.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTTEMPLATE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_CERTTEMPLATE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_ENCRYPTEDVALUE.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_ENCRYPTEDVALUE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_ENCRYPTEDVALUE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_MSG.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_MSG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_MSG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_MSGS.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_MSGS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_MSGS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_PBMPARAMETER.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_PBMPARAMETER.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_PBMPARAMETER.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_CRMF_SINGLEPUBINFO.3ossl b/openssl-install/share/man/man3/d2i_OSSL_CRMF_SINGLEPUBINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_CRMF_SINGLEPUBINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_IETF_ATTR_SYNTAX.3ossl b/openssl-install/share/man/man3/d2i_OSSL_IETF_ATTR_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_IETF_ATTR_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_ISSUER_SERIAL.3ossl b/openssl-install/share/man/man3/d2i_OSSL_ISSUER_SERIAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_ISSUER_SERIAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_OBJECT_DIGEST_INFO.3ossl b/openssl-install/share/man/man3/d2i_OSSL_OBJECT_DIGEST_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_OBJECT_DIGEST_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_TARGET.3ossl b/openssl-install/share/man/man3/d2i_OSSL_TARGET.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_TARGET.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_TARGETING_INFORMATION.3ossl b/openssl-install/share/man/man3/d2i_OSSL_TARGETING_INFORMATION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_TARGETING_INFORMATION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_TARGETS.3ossl b/openssl-install/share/man/man3/d2i_OSSL_TARGETS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_TARGETS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_TARGET_CERT.3ossl b/openssl-install/share/man/man3/d2i_OSSL_TARGET_CERT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_TARGET_CERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OSSL_USER_NOTICE_SYNTAX.3ossl b/openssl-install/share/man/man3/d2i_OSSL_USER_NOTICE_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OSSL_USER_NOTICE_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_OTHERNAME.3ossl b/openssl-install/share/man/man3/d2i_OTHERNAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_OTHERNAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PBE2PARAM.3ossl b/openssl-install/share/man/man3/d2i_PBE2PARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PBE2PARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PBEPARAM.3ossl b/openssl-install/share/man/man3/d2i_PBEPARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PBEPARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PBKDF2PARAM.3ossl b/openssl-install/share/man/man3/d2i_PBKDF2PARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PBKDF2PARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PBMAC1PARAM.3ossl b/openssl-install/share/man/man3/d2i_PBMAC1PARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PBMAC1PARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS12.3ossl b/openssl-install/share/man/man3/d2i_PKCS12.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS12.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS12_BAGS.3ossl b/openssl-install/share/man/man3/d2i_PKCS12_BAGS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS12_BAGS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS12_MAC_DATA.3ossl b/openssl-install/share/man/man3/d2i_PKCS12_MAC_DATA.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS12_MAC_DATA.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS12_SAFEBAG.3ossl b/openssl-install/share/man/man3/d2i_PKCS12_SAFEBAG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS12_SAFEBAG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS12_bio.3ossl b/openssl-install/share/man/man3/d2i_PKCS12_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS12_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS12_fp.3ossl b/openssl-install/share/man/man3/d2i_PKCS12_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS12_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7.3ossl b/openssl-install/share/man/man3/d2i_PKCS7.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_DIGEST.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_DIGEST.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_DIGEST.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_ENCRYPT.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_ENCRYPT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_ENCRYPT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_ENC_CONTENT.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_ENC_CONTENT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_ENC_CONTENT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_ENVELOPE.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_ENVELOPE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_ENVELOPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_ISSUER_AND_SERIAL.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_ISSUER_AND_SERIAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_ISSUER_AND_SERIAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_RECIP_INFO.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_RECIP_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_RECIP_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_SIGNED.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_SIGNED.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_SIGNED.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_SIGNER_INFO.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_SIGNER_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_SIGNER_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_SIGN_ENVELOPE.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_SIGN_ENVELOPE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_SIGN_ENVELOPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_bio.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS7_fp.3ossl b/openssl-install/share/man/man3/d2i_PKCS7_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS7_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS8PrivateKey_bio.3ossl b/openssl-install/share/man/man3/d2i_PKCS8PrivateKey_bio.3ossl deleted file mode 100644 index dba5dd7e..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS8PrivateKey_bio.3ossl +++ /dev/null @@ -1,205 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "D2I_PKCS8PRIVATEKEY_BIO 3ossl" -.TH D2I_PKCS8PRIVATEKEY_BIO 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -d2i_PKCS8PrivateKey_bio, d2i_PKCS8PrivateKey_fp, -i2d_PKCS8PrivateKey_bio, i2d_PKCS8PrivateKey_fp, -i2d_PKCS8PrivateKey_nid_bio, i2d_PKCS8PrivateKey_nid_fp \- PKCS#8 format private key functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *d2i_PKCS8PrivateKey_bio(BIO *bp, EVP_PKEY **x, pem_password_cb *cb, void *u); -\& EVP_PKEY *d2i_PKCS8PrivateKey_fp(FILE *fp, EVP_PKEY **x, pem_password_cb *cb, void *u); -\& -\& int i2d_PKCS8PrivateKey_bio(BIO *bp, const EVP_PKEY *x, const EVP_CIPHER *enc, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& -\& int i2d_PKCS8PrivateKey_fp(FILE *fp, const EVP_PKEY *x, const EVP_CIPHER *enc, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& -\& int i2d_PKCS8PrivateKey_nid_bio(BIO *bp, const EVP_PKEY *x, int nid, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -\& -\& int i2d_PKCS8PrivateKey_nid_fp(FILE *fp, const EVP_PKEY *x, int nid, -\& char *kstr, int klen, -\& pem_password_cb *cb, void *u); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The PKCS#8 functions encode and decode private keys in PKCS#8 format using both -PKCS#5 v1.5 and PKCS#5 v2.0 password based encryption algorithms. -.PP -Other than the use of \s-1DER\s0 as opposed to \s-1PEM\s0 these functions are identical to the -corresponding \fB\s-1PEM\s0\fR function as described in \fBPEM_read_PrivateKey\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -These functions are currently the only way to store encrypted private keys using \s-1DER\s0 format. -.PP -Currently all the functions use BIOs or \s-1FILE\s0 pointers, there are no functions which -work directly on memory: this can be readily worked around by converting the buffers -to memory BIOs, see \fBBIO_s_mem\fR\|(3) for details. -.PP -These functions make no assumption regarding the pass phrase received from the -password callback. -It will simply be treated as a byte sequence. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBd2i_PKCS8PrivateKey_bio()\fR and \fBd2i_PKCS8PrivateKey_fp()\fR return a valid \fB\s-1EVP_PKEY\s0\fR -structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBi2d_PKCS8PrivateKey_bio()\fR, \fBi2d_PKCS8PrivateKey_fp()\fR, \fBi2d_PKCS8PrivateKey_nid_bio()\fR -and \fBi2d_PKCS8PrivateKey_nid_fp()\fR return 1 on success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBPEM_read_PrivateKey\fR\|(3), -\&\fBpassphrase\-encoding\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/d2i_PKCS8PrivateKey_fp.3ossl b/openssl-install/share/man/man3/d2i_PKCS8PrivateKey_fp.3ossl deleted file mode 120000 index 082536d2..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS8PrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PKCS8PrivateKey_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO.3ossl b/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_bio.3ossl b/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_fp.3ossl b/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS8_PRIV_KEY_INFO_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS8_bio.3ossl b/openssl-install/share/man/man3/d2i_PKCS8_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS8_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKCS8_fp.3ossl b/openssl-install/share/man/man3/d2i_PKCS8_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKCS8_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PKEY_USAGE_PERIOD.3ossl b/openssl-install/share/man/man3/d2i_PKEY_USAGE_PERIOD.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PKEY_USAGE_PERIOD.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_POLICYINFO.3ossl b/openssl-install/share/man/man3/d2i_POLICYINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_POLICYINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_POLICYQUALINFO.3ossl b/openssl-install/share/man/man3/d2i_POLICYQUALINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_POLICYQUALINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PROFESSION_INFO.3ossl b/openssl-install/share/man/man3/d2i_PROFESSION_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PROFESSION_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PROXY_CERT_INFO_EXTENSION.3ossl b/openssl-install/share/man/man3/d2i_PROXY_CERT_INFO_EXTENSION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PROXY_CERT_INFO_EXTENSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PROXY_POLICY.3ossl b/openssl-install/share/man/man3/d2i_PROXY_POLICY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_PROXY_POLICY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PUBKEY.3ossl b/openssl-install/share/man/man3/d2i_PUBKEY.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/d2i_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/d2i_PUBKEY_bio.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/d2i_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PUBKEY_ex.3ossl b/openssl-install/share/man/man3/d2i_PUBKEY_ex.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/d2i_PUBKEY_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PUBKEY_ex_bio.3ossl b/openssl-install/share/man/man3/d2i_PUBKEY_ex_bio.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/d2i_PUBKEY_ex_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PUBKEY_ex_fp.3ossl b/openssl-install/share/man/man3/d2i_PUBKEY_ex_fp.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/d2i_PUBKEY_ex_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/d2i_PUBKEY_fp.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/d2i_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PrivateKey.3ossl b/openssl-install/share/man/man3/d2i_PrivateKey.3ossl deleted file mode 100644 index 30fe1a4c..00000000 --- a/openssl-install/share/man/man3/d2i_PrivateKey.3ossl +++ /dev/null @@ -1,265 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "D2I_PRIVATEKEY 3ossl" -.TH D2I_PRIVATEKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -d2i_PrivateKey_ex, d2i_PrivateKey, d2i_PublicKey, d2i_KeyParams, -d2i_AutoPrivateKey_ex, d2i_AutoPrivateKey, i2d_PrivateKey, i2d_PublicKey, -i2d_KeyParams, i2d_KeyParams_bio, d2i_PrivateKey_ex_bio, d2i_PrivateKey_bio, -d2i_PrivateKey_ex_fp, d2i_PrivateKey_fp, d2i_KeyParams_bio, i2d_PrivateKey_bio, -i2d_PrivateKey_fp -\&\- decode and encode functions for reading and saving EVP_PKEY structures -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& EVP_PKEY *d2i_PrivateKey_ex(int type, EVP_PKEY **a, const unsigned char **pp, -\& long length, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& EVP_PKEY *d2i_PrivateKey(int type, EVP_PKEY **a, const unsigned char **pp, -\& long length); -\& EVP_PKEY *d2i_PublicKey(int type, EVP_PKEY **a, const unsigned char **pp, -\& long length); -\& EVP_PKEY *d2i_KeyParams(int type, EVP_PKEY **a, const unsigned char **pp, -\& long length); -\& EVP_PKEY *d2i_AutoPrivateKey_ex(EVP_PKEY **a, const unsigned char **pp, -\& long length, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& EVP_PKEY *d2i_AutoPrivateKey(EVP_PKEY **a, const unsigned char **pp, -\& long length); -\& -\& int i2d_PrivateKey(const EVP_PKEY *a, unsigned char **pp); -\& int i2d_PublicKey(const EVP_PKEY *a, unsigned char **pp); -\& int i2d_KeyParams(const EVP_PKEY *a, unsigned char **pp); -\& int i2d_KeyParams_bio(BIO *bp, const EVP_PKEY *pkey); -\& EVP_PKEY *d2i_KeyParams_bio(int type, EVP_PKEY **a, BIO *in); -\& -\& -\& #include -\& -\& EVP_PKEY *d2i_PrivateKey_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& EVP_PKEY *d2i_PrivateKey_bio(BIO *bp, EVP_PKEY **a); -\& EVP_PKEY *d2i_PrivateKey_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& EVP_PKEY *d2i_PrivateKey_fp(FILE *fp, EVP_PKEY **a); -\& -\& int i2d_PrivateKey_bio(BIO *bp, const EVP_PKEY *pkey); -\& int i2d_PrivateKey_fp(FILE *fp, const EVP_PKEY *pkey); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBd2i_PrivateKey_ex()\fR decodes a private key using algorithm \fItype\fR. It attempts -to use any key-specific format or PKCS#8 unencrypted PrivateKeyInfo format. -The \fItype\fR parameter should be a public key algorithm constant such as -\&\fB\s-1EVP_PKEY_RSA\s0\fR. An error occurs if the decoded key does not match \fItype\fR. Some -private key decoding implementations may use cryptographic algorithms (for -example to automatically derive the public key if it is not explicitly -included in the encoding). In this case the supplied library context \fIlibctx\fR -and property query string \fIpropq\fR are used. -If successful and the \fIa\fR parameter is not \s-1NULL\s0 the function assigns the -returned \fB\s-1EVP_PKEY\s0\fR structure pointer to \fI*a\fR, overwriting any previous value. -.PP -\&\fBd2i_PrivateKey()\fR does the same as \fBd2i_PrivateKey_ex()\fR except that the default -library context and property query string are used. -\&\fBd2i_PublicKey()\fR does the same for public keys. -\&\fBd2i_KeyParams()\fR does the same for key parameters. -.PP -The \fBd2i_PrivateKey_ex_bio()\fR and \fBd2i_PrivateKey_bio()\fR functions are similar to -\&\fBd2i_PrivateKey_ex()\fR and \fBd2i_PrivateKey()\fR respectively except that they decode -the data read from the given \s-1BIO.\s0 The \fBd2i_PrivateKey_ex_fp()\fR and -\&\fBd2i_PrivateKey_fp()\fR functions are the same except that they read the data from -the given \s-1FILE.\s0 -.PP -\&\fBd2i_AutoPrivateKey_ex()\fR and \fBd2i_AutoPrivateKey()\fR are similar to -\&\fBd2i_PrivateKey_ex()\fR and \fBd2i_PrivateKey()\fR respectively except that they attempt -to automatically detect the private key format. -.PP -\&\fBi2d_PrivateKey()\fR encodes \fIa\fR. It uses a key specific format or, if none is -defined for that key type, PKCS#8 unencrypted PrivateKeyInfo format. -\&\fBi2d_PublicKey()\fR does the same for public keys. -\&\fBi2d_KeyParams()\fR does the same for key parameters. -These functions are similar to the \fBd2i_X509()\fR functions; see \fBd2i_X509\fR\|(3). -\&\fBi2d_PrivateKey_bio()\fR and \fBi2d_PrivateKey_fp()\fR do the same thing except that they -encode to a \fB\s-1BIO\s0\fR or \fB\s-1FILE\s0\fR respectively. Again, these work similarly to the -functions described in \fBd2i_X509\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -All the functions that operate on data in memory update the data pointer \fI*pp\fR -after a successful operation, just like the other d2i and i2d functions; -see \fBd2i_X509\fR\|(3). -.PP -All these functions use \s-1DER\s0 format and unencrypted keys. Applications wishing -to encrypt or decrypt private keys should use other functions such as -\&\fBd2i_PKCS8PrivateKey()\fR instead. -.PP -To decode a key with type \fB\s-1EVP_PKEY_EC\s0\fR, \fBd2i_PublicKey()\fR requires \fI*a\fR to be -a non-NULL \s-1EVP_PKEY\s0 structure assigned an \s-1EC_KEY\s0 structure referencing the proper -\&\s-1EC_GROUP.\s0 -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -The \fBd2i_PrivateKey_ex()\fR, \fBd2i_PrivateKey()\fR, \fBd2i_AutoPrivateKey_ex()\fR, -\&\fBd2i_AutoPrivateKey()\fR, \fBd2i_PrivateKey_ex_bio()\fR, \fBd2i_PrivateKey_bio()\fR, -\&\fBd2i_PrivateKey_ex_fp()\fR, \fBd2i_PrivateKey_fp()\fR, \fBd2i_PublicKey()\fR, \fBd2i_KeyParams()\fR -and \fBd2i_KeyParams_bio()\fR functions return a valid \fB\s-1EVP_PKEY\s0\fR structure or \s-1NULL\s0 if -an error occurs. The error code can be obtained by calling \fBERR_get_error\fR\|(3). -.PP -\&\fBi2d_PrivateKey()\fR, \fBi2d_PublicKey()\fR and \fBi2d_KeyParams()\fR return the number of -bytes successfully encoded or a negative value if an error occurs. The error -code can be obtained by calling \fBERR_get_error\fR\|(3). -.PP -\&\fBi2d_PrivateKey_bio()\fR, \fBi2d_PrivateKey_fp()\fR and \fBi2d_KeyParams_bio()\fR return 1 if -successfully encoded or zero if an error occurs. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBcrypto\fR\|(7), -\&\fBd2i_PKCS8PrivateKey_bio\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBd2i_PrivateKey_ex()\fR, \fBd2i_PrivateKey_ex_bio()\fR, \fBd2i_PrivateKey_ex_fp()\fR, and -\&\fBd2i_AutoPrivateKey_ex()\fR were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/d2i_PrivateKey_bio.3ossl b/openssl-install/share/man/man3/d2i_PrivateKey_bio.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_PrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PrivateKey_ex.3ossl b/openssl-install/share/man/man3/d2i_PrivateKey_ex.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_PrivateKey_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PrivateKey_ex_bio.3ossl b/openssl-install/share/man/man3/d2i_PrivateKey_ex_bio.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_PrivateKey_ex_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PrivateKey_ex_fp.3ossl b/openssl-install/share/man/man3/d2i_PrivateKey_ex_fp.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_PrivateKey_ex_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PrivateKey_fp.3ossl b/openssl-install/share/man/man3/d2i_PrivateKey_fp.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_PrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_PublicKey.3ossl b/openssl-install/share/man/man3/d2i_PublicKey.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/d2i_PublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/d2i_RSAPrivateKey.3ossl deleted file mode 100644 index 89619395..00000000 --- a/openssl-install/share/man/man3/d2i_RSAPrivateKey.3ossl +++ /dev/null @@ -1,426 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "D2I_RSAPRIVATEKEY 3ossl" -.TH D2I_RSAPRIVATEKEY 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -d2i_DSAPrivateKey, -d2i_DSAPrivateKey_bio, -d2i_DSAPrivateKey_fp, -d2i_DSAPublicKey, -d2i_DSA_PUBKEY, -d2i_DSA_PUBKEY_bio, -d2i_DSA_PUBKEY_fp, -d2i_DSAparams, -d2i_RSAPrivateKey, -d2i_RSAPrivateKey_bio, -d2i_RSAPrivateKey_fp, -d2i_RSAPublicKey, -d2i_RSAPublicKey_bio, -d2i_RSAPublicKey_fp, -d2i_RSA_PUBKEY, -d2i_RSA_PUBKEY_bio, -d2i_RSA_PUBKEY_fp, -d2i_DHparams, -d2i_DHparams_bio, -d2i_DHparams_fp, -d2i_ECParameters, -d2i_ECPrivateKey, -d2i_ECPrivateKey_bio, -d2i_ECPrivateKey_fp, -d2i_EC_PUBKEY, -d2i_EC_PUBKEY_bio, -d2i_EC_PUBKEY_fp, -i2d_RSAPrivateKey, -i2d_RSAPrivateKey_bio, -i2d_RSAPrivateKey_fp, -i2d_RSAPublicKey, -i2d_RSAPublicKey_bio, -i2d_RSAPublicKey_fp, -i2d_RSA_PUBKEY, -i2d_RSA_PUBKEY_bio, -i2d_RSA_PUBKEY_fp, -i2d_DHparams, -i2d_DHparams_bio, -i2d_DHparams_fp, -i2d_DSAPrivateKey, -i2d_DSAPrivateKey_bio, -i2d_DSAPrivateKey_fp, -i2d_DSAPublicKey, -i2d_DSA_PUBKEY, -i2d_DSA_PUBKEY_bio, -i2d_DSA_PUBKEY_fp, -i2d_DSAparams, -i2d_ECParameters, -i2d_ECPrivateKey, -i2d_ECPrivateKey_bio, -i2d_ECPrivateKey_fp, -i2d_EC_PUBKEY, -i2d_EC_PUBKEY_bio, -i2d_EC_PUBKEY_fp -\&\- DEPRECATED -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -The following functions have been deprecated since OpenSSL 3.0, and can be -hidden entirely by defining \fB\s-1OPENSSL_API_COMPAT\s0\fR with a suitable version value, -see \fBopenssl_user_macros\fR\|(7): -.PP -.Vb 12 -\& TYPE *d2i_TYPEPrivateKey(TYPE **a, const unsigned char **ppin, long length); -\& TYPE *d2i_TYPEPrivateKey_bio(BIO *bp, TYPE **a); -\& TYPE *d2i_TYPEPrivateKey_fp(FILE *fp, TYPE **a); -\& TYPE *d2i_TYPEPublicKey(TYPE **a, const unsigned char **ppin, long length); -\& TYPE *d2i_TYPEPublicKey_bio(BIO *bp, TYPE **a); -\& TYPE *d2i_TYPEPublicKey_fp(FILE *fp, TYPE **a); -\& TYPE *d2i_TYPEparams(TYPE **a, const unsigned char **ppin, long length); -\& TYPE *d2i_TYPEparams_bio(BIO *bp, TYPE **a); -\& TYPE *d2i_TYPEparams_fp(FILE *fp, TYPE **a); -\& TYPE *d2i_TYPE_PUBKEY(TYPE **a, const unsigned char **ppin, long length); -\& TYPE *d2i_TYPE_PUBKEY_bio(BIO *bp, TYPE **a); -\& TYPE *d2i_TYPE_PUBKEY_fp(FILE *fp, TYPE **a); -\& -\& int i2d_TYPEPrivateKey(const TYPE *a, unsigned char **ppout); -\& int i2d_TYPEPrivateKey(TYPE *a, unsigned char **ppout); -\& int i2d_TYPEPrivateKey_fp(FILE *fp, const TYPE *a); -\& int i2d_TYPEPrivateKey_fp(FILE *fp, TYPE *a); -\& int i2d_TYPEPrivateKey_bio(BIO *bp, const TYPE *a); -\& int i2d_TYPEPrivateKey_bio(BIO *bp, TYPE *a); -\& int i2d_TYPEPublicKey(const TYPE *a, unsigned char **ppout); -\& int i2d_TYPEPublicKey(TYPE *a, unsigned char **ppout); -\& int i2d_TYPEPublicKey_fp(FILE *fp, const TYPE *a); -\& int i2d_TYPEPublicKey_fp(FILE *fp, TYPE *a); -\& int i2d_TYPEPublicKey_bio(BIO *bp, const TYPE *a); -\& int i2d_TYPEPublicKey_bio(BIO *bp, TYPE *a); -\& int i2d_TYPEparams(const TYPE *a, unsigned char **ppout); -\& int i2d_TYPEparams(TYPE *a, unsigned char **ppout); -\& int i2d_TYPEparams_fp(FILE *fp, const TYPE *a); -\& int i2d_TYPEparams_fp(FILE *fp, TYPE *a); -\& int i2d_TYPEparams_bio(BIO *bp, const TYPE *a); -\& int i2d_TYPEparams_bio(BIO *bp, TYPE *a); -\& int i2d_TYPE_PUBKEY(const TYPE *a, unsigned char **ppout); -\& int i2d_TYPE_PUBKEY(TYPE *a, unsigned char **ppout); -\& int i2d_TYPE_PUBKEY_fp(FILE *fp, const TYPE *a); -\& int i2d_TYPE_PUBKEY_fp(FILE *fp, TYPE *a); -\& int i2d_TYPE_PUBKEY_bio(BIO *bp, const TYPE *a); -\& int i2d_TYPE_PUBKEY_bio(BIO *bp, TYPE *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All functions described here are deprecated. Please use \s-1\fBOSSL_DECODER\s0\fR\|(3) -instead of the \fBd2i\fR functions and \s-1\fBOSSL_ENCODER\s0\fR\|(3) instead of the \fBi2d\fR -functions. See \*(L"Migration\*(R" below. -.PP -In the description here, \fB\f(BI\s-1TYPE\s0\fB\fR is used a placeholder for any of the -OpenSSL datatypes, such as \fB\s-1RSA\s0\fR. -The function parameters \fIppin\fR and \fIppout\fR are generally either both named -\&\fIpp\fR in the headers, or \fIin\fR and \fIout\fR. -.PP -All the functions here behave the way that's described in \fBd2i_X509\fR\|(3). -.PP -Please note that not all functions in the synopsis are available for all key -types. For example, there are no \fBd2i_RSAparams()\fR or \fBi2d_RSAparams()\fR, -because the PKCS#1 \fB\s-1RSA\s0\fR structure doesn't include any key parameters. -.PP -\&\fBd2i_\f(BI\s-1TYPE\s0\fBPrivateKey\fR() and derivates thereof decode \s-1DER\s0 encoded -\&\fB\f(BI\s-1TYPE\s0\fB\fR private key data organized in a type specific structure. -.PP -\&\fBd2i_\f(BI\s-1TYPE\s0\fBPublicKey\fR() and derivates thereof decode \s-1DER\s0 encoded -\&\fB\f(BI\s-1TYPE\s0\fB\fR public key data organized in a type specific structure. -.PP -\&\fBd2i_\f(BI\s-1TYPE\s0\fBparams\fR() and derivates thereof decode \s-1DER\s0 encoded \fB\f(BI\s-1TYPE\s0\fB\fR -key parameters organized in a type specific structure. -.PP -\&\fBd2i_\f(BI\s-1TYPE\s0\fB_PUBKEY\fR() and derivates thereof decode \s-1DER\s0 encoded \fB\f(BI\s-1TYPE\s0\fB\fR -public key data organized in a \fBSubjectPublicKeyInfo\fR structure. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fBPrivateKey\fR() and derivates thereof encode the private key -\&\fB\f(BI\s-1TYPE\s0\fB\fR data into a type specific \s-1DER\s0 encoded structure. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fBPublicKey\fR() and derivates thereof encode the public key -\&\fB\f(BI\s-1TYPE\s0\fB\fR data into a type specific \s-1DER\s0 encoded structure. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fBparams\fR() and derivates thereof encode the \fB\f(BI\s-1TYPE\s0\fB\fR key -parameters data into a type specific \s-1DER\s0 encoded structure. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB_PUBKEY\fR() and derivates thereof encode the public key -\&\fB\f(BI\s-1TYPE\s0\fB\fR data into a \s-1DER\s0 encoded \fBSubjectPublicKeyInfo\fR structure. -.PP -For example, \fBd2i_RSAPrivateKey()\fR and \fBd2i_RSAPublicKey()\fR expects the -structure defined by PKCS#1. -Similarly, \fBi2d_RSAPrivateKey()\fR and \fBi2d_RSAPublicKey()\fR produce \s-1DER\s0 encoded -string organized according to PKCS#1. -.SS "Migration" -.IX Subsection "Migration" -Migration from the diverse \fB\f(BI\s-1TYPE\s0\fB\fRs requires using corresponding new -OpenSSL types. For all \fB\f(BI\s-1TYPE\s0\fB\fRs described here, the corresponding new -type is \fB\s-1EVP_PKEY\s0\fR. The rest of this section assumes that this has been -done, exactly how to do that is described elsewhere. -.PP -There are two migration paths: -.IP "\(bu" 4 -Replace -b with \fBd2i_PrivateKey\fR\|(3), -b with \fBd2i_PublicKey\fR\|(3), -b with \fBd2i_KeyParams\fR\|(3), -b with \fBd2i_PUBKEY\fR\|(3), -b with \fBi2d_PrivateKey\fR\|(3), -b with \fBi2d_PublicKey\fR\|(3), -b with \fBi2d_KeyParams\fR\|(3), -b with \fBi2d_PUBKEY\fR\|(3). -A caveat is that \fBi2d_PrivateKey\fR\|(3) may output a \s-1DER\s0 encoded PKCS#8 -outermost structure instead of the type specific structure, and that -\&\fBd2i_PrivateKey\fR\|(3) recognises and unpacks a PKCS#8 structures. -.IP "\(bu" 4 -Use \s-1\fBOSSL_DECODER\s0\fR\|(3) and \s-1\fBOSSL_ENCODER\s0\fR\|(3). How to migrate is described -below. All those descriptions assume that the key to be encoded is in the -variable \fIpkey\fR. -.PP -\fIMigrating \f(BIi2d\fI functions to \f(BI\s-1OSSL_ENCODER\s0\fI\fR -.IX Subsection "Migrating i2d functions to OSSL_ENCODER" -.PP -The exact \s-1\fBOSSL_ENCODER\s0\fR\|(3) output is driven by arguments rather than by -function names. The sample code to get \s-1DER\s0 encoded output in a type -specific structure is uniform, the only things that vary are the selection -of what part of the \fB\s-1EVP_PKEY\s0\fR should be output, and the structure. The -\&\fBi2d\fR functions names can therefore be translated into two variables, -\&\fIselection\fR and \fIstructure\fR as follows: -.IP "\fBi2d_\f(BI\s-1TYPE\s0\fBPrivateKey\fR() translates into:" 4 -.IX Item "i2d_TYPEPrivateKey() translates into:" -.Vb 2 -\& int selection = EVP_PKEY_KEYPAIR; -\& const char *structure = "type\-specific"; -.Ve -.IP "\fBi2d_\f(BI\s-1TYPE\s0\fBPublicKey\fR() translates into:" 4 -.IX Item "i2d_TYPEPublicKey() translates into:" -.Vb 2 -\& int selection = EVP_PKEY_PUBLIC_KEY; -\& const char *structure = "type\-specific"; -.Ve -.IP "\fBi2d_\f(BI\s-1TYPE\s0\fBparams\fR() translates into:" 4 -.IX Item "i2d_TYPEparams() translates into:" -.Vb 2 -\& int selection = EVP_PKEY_PARAMETERS; -\& const char *structure = "type\-specific"; -.Ve -.IP "\fBi2d_\f(BI\s-1TYPE\s0\fB_PUBKEY\fR() translates into:" 4 -.IX Item "i2d_TYPE_PUBKEY() translates into:" -.Vb 2 -\& int selection = EVP_PKEY_PUBLIC_KEY; -\& const char *structure = "SubjectPublicKeyInfo"; -.Ve -.PP -The following sample code does the rest of the work: -.PP -.Vb 10 -\& unsigned char *p = buffer; /* |buffer| is supplied by the caller */ -\& size_t len = buffer_size; /* assumed be the size of |buffer| */ -\& OSSL_ENCODER_CTX *ctx = -\& OSSL_ENCODER_CTX_new_for_pkey(pkey, selection, "DER", structure, -\& NULL, NULL); -\& if (ctx == NULL) { -\& /* fatal error handling */ -\& } -\& if (OSSL_ENCODER_CTX_get_num_encoders(ctx) == 0) { -\& OSSL_ENCODER_CTX_free(ctx); -\& /* non\-fatal error handling */ -\& } -\& if (!OSSL_ENCODER_to_data(ctx, &p, &len)) { -\& OSSL_ENCODER_CTX_free(ctx); -\& /* error handling */ -\& } -\& OSSL_ENCODER_CTX_free(ctx); -.Ve -.SH "NOTES" -.IX Header "NOTES" -The letters \fBi\fR and \fBd\fR in \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() stand for -\&\*(L"internal\*(R" (that is, an internal C structure) and \*(L"\s-1DER\*(R"\s0 respectively. -So \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() converts from internal to \s-1DER.\s0 -.PP -The functions can also understand \fB\s-1BER\s0\fR forms. -.PP -The actual \s-1TYPE\s0 structure passed to \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() must be a valid -populated \fB\f(BI\s-1TYPE\s0\fB\fR structure \*(-- it \fBcannot\fR simply be fed with an -empty structure such as that returned by \fBTYPE_new()\fR. -.PP -The encoded data is in binary form and may contain embedded zeros. -Therefore, any \s-1FILE\s0 pointers or BIOs should be opened in binary mode. -Functions such as \fBstrlen()\fR will \fBnot\fR return the correct length -of the encoded structure. -.PP -The ways that \fI*ppin\fR and \fI*ppout\fR are incremented after the operation -can trap the unwary. See the \fB\s-1WARNINGS\s0\fR section in \fBd2i_X509\fR\|(3) for some -common errors. -The reason for this-auto increment behaviour is to reflect a typical -usage of \s-1ASN1\s0 functions: after one structure is encoded or decoded -another will be processed after it. -.PP -The following points about the data types might be useful: -.IP "\fB\s-1DSA_PUBKEY\s0\fR" 4 -.IX Item "DSA_PUBKEY" -Represents a \s-1DSA\s0 public key using a \fBSubjectPublicKeyInfo\fR structure. -.IP "\fBDSAPublicKey\fR, \fBDSAPrivateKey\fR" 4 -.IX Item "DSAPublicKey, DSAPrivateKey" -Use a non-standard OpenSSL format and should be avoided; use \fB\s-1DSA_PUBKEY\s0\fR, -\&\fBPEM_write_PrivateKey\fR\|(3), or similar instead. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBd2i_\f(BI\s-1TYPE\s0\fB\fR(), \fBd2i_\f(BI\s-1TYPE\s0\fB_bio\fR() and \fBd2i_\f(BI\s-1TYPE\s0\fB_fp\fR() return a valid -\&\fB\f(BI\s-1TYPE\s0\fB\fR structure or \s-1NULL\s0 if an error occurs. If the \*(L"reuse\*(R" capability has -been used with a valid structure being passed in via \fIa\fR, then the object is -freed in the event of error and \fI*a\fR is set to \s-1NULL.\s0 -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB\fR() returns the number of bytes successfully encoded or a negative -value if an error occurs. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB_bio\fR() and \fBi2d_\f(BI\s-1TYPE\s0\fB_fp\fR() return 1 for success and 0 if an -error occurs. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_ENCODER\s0\fR\|(3), \s-1\fBOSSL_DECODER\s0\fR\|(3), -\&\fBd2i_PrivateKey\fR\|(3), \fBd2i_PublicKey\fR\|(3), \fBd2i_KeyParams\fR\|(3), -\&\fBd2i_PUBKEY\fR\|(3), -\&\fBi2d_PrivateKey\fR\|(3), \fBi2d_PublicKey\fR\|(3), \fBi2d_KeyParams\fR\|(3), -\&\fBi2d_PUBKEY\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/d2i_RSAPrivateKey_bio.3ossl b/openssl-install/share/man/man3/d2i_RSAPrivateKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSAPrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSAPrivateKey_fp.3ossl b/openssl-install/share/man/man3/d2i_RSAPrivateKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSAPrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSAPublicKey.3ossl b/openssl-install/share/man/man3/d2i_RSAPublicKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSAPublicKey_bio.3ossl b/openssl-install/share/man/man3/d2i_RSAPublicKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSAPublicKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSAPublicKey_fp.3ossl b/openssl-install/share/man/man3/d2i_RSAPublicKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSAPublicKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSA_OAEP_PARAMS.3ossl b/openssl-install/share/man/man3/d2i_RSA_OAEP_PARAMS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_RSA_OAEP_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSA_PSS_PARAMS.3ossl b/openssl-install/share/man/man3/d2i_RSA_PSS_PARAMS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_RSA_PSS_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSA_PUBKEY.3ossl b/openssl-install/share/man/man3/d2i_RSA_PUBKEY.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSA_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/d2i_RSA_PUBKEY_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSA_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_RSA_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/d2i_RSA_PUBKEY_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/d2i_RSA_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_SCRYPT_PARAMS.3ossl b/openssl-install/share/man/man3/d2i_SCRYPT_PARAMS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_SCRYPT_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_SCT_LIST.3ossl b/openssl-install/share/man/man3/d2i_SCT_LIST.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_SCT_LIST.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_SSL_SESSION.3ossl b/openssl-install/share/man/man3/d2i_SSL_SESSION.3ossl deleted file mode 100644 index ee60e384..00000000 --- a/openssl-install/share/man/man3/d2i_SSL_SESSION.3ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "D2I_SSL_SESSION 3ossl" -.TH D2I_SSL_SESSION 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -d2i_SSL_SESSION, d2i_SSL_SESSION_ex, i2d_SSL_SESSION \- convert SSL_SESSION object from/to ASN1 representation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& SSL_SESSION *d2i_SSL_SESSION(SSL_SESSION **a, const unsigned char **pp, -\& long length); -\& SSL_SESSION *d2i_SSL_SESSION_ex(SSL_SESSION **a, const unsigned char **pp, -\& long length, OSSL_LIB_CTX *libctx, -\& const char *propq); -\& int i2d_SSL_SESSION(SSL_SESSION *in, unsigned char **pp); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions decode and encode an \s-1SSL_SESSION\s0 object. -For encoding details see \fBd2i_X509\fR\|(3). -.PP -\&\s-1SSL_SESSION\s0 objects keep internal link information about the session cache -list, when being inserted into one \s-1SSL_CTX\s0 object's session cache. -One \s-1SSL_SESSION\s0 object, regardless of its reference count, must therefore -only be used with one \s-1SSL_CTX\s0 object (and the \s-1SSL\s0 objects created -from this \s-1SSL_CTX\s0 object). -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBd2i_SSL_SESSION()\fR and \fBd2i_SSL_SESSION_ex()\fR return a pointer to the newly -allocated \s-1SSL_SESSION\s0 object. -In case of failure the NULL-pointer is returned and the error message -can be retrieved from the error stack. -.PP -\&\fBi2d_SSL_SESSION()\fR returns the size of the \s-1ASN1\s0 representation in bytes. -When the session is not valid, \fB0\fR is returned and no operation is performed. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBssl\fR\|(7), \fBSSL_SESSION_free\fR\|(3), -\&\fBSSL_CTX_sess_set_get_cb\fR\|(3), -\&\fBd2i_X509\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The function \fBd2i_SSL_SESSION_ex()\fR was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2001\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/d2i_SSL_SESSION_ex.3ossl b/openssl-install/share/man/man3/d2i_SSL_SESSION_ex.3ossl deleted file mode 120000 index 05f96010..00000000 --- a/openssl-install/share/man/man3/d2i_SSL_SESSION_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_SSL_SESSION.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_SXNET.3ossl b/openssl-install/share/man/man3/d2i_SXNET.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_SXNET.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_SXNETID.3ossl b/openssl-install/share/man/man3/d2i_SXNETID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_SXNETID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_ACCURACY.3ossl b/openssl-install/share/man/man3/d2i_TS_ACCURACY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_ACCURACY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT.3ossl b/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_bio.3ossl b/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_fp.3ossl b/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_MSG_IMPRINT_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_REQ.3ossl b/openssl-install/share/man/man3/d2i_TS_REQ.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_REQ_bio.3ossl b/openssl-install/share/man/man3/d2i_TS_REQ_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_REQ_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_REQ_fp.3ossl b/openssl-install/share/man/man3/d2i_TS_REQ_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_REQ_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_RESP.3ossl b/openssl-install/share/man/man3/d2i_TS_RESP.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_RESP.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_RESP_bio.3ossl b/openssl-install/share/man/man3/d2i_TS_RESP_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_RESP_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_RESP_fp.3ossl b/openssl-install/share/man/man3/d2i_TS_RESP_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_RESP_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_STATUS_INFO.3ossl b/openssl-install/share/man/man3/d2i_TS_STATUS_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_STATUS_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_TST_INFO.3ossl b/openssl-install/share/man/man3/d2i_TS_TST_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_TST_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_TST_INFO_bio.3ossl b/openssl-install/share/man/man3/d2i_TS_TST_INFO_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_TST_INFO_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_TS_TST_INFO_fp.3ossl b/openssl-install/share/man/man3/d2i_TS_TST_INFO_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_TS_TST_INFO_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_USERNOTICE.3ossl b/openssl-install/share/man/man3/d2i_USERNOTICE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_USERNOTICE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509.3ossl b/openssl-install/share/man/man3/d2i_X509.3ossl deleted file mode 100644 index 20e673a4..00000000 --- a/openssl-install/share/man/man3/d2i_X509.3ossl +++ /dev/null @@ -1,777 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "D2I_X509 3ossl" -.TH D2I_X509 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -d2i_ACCESS_DESCRIPTION, -d2i_ADMISSIONS, -d2i_ADMISSION_SYNTAX, -d2i_ASIdOrRange, -d2i_ASIdentifierChoice, -d2i_ASIdentifiers, -d2i_ASN1_BIT_STRING, -d2i_ASN1_BMPSTRING, -d2i_ASN1_ENUMERATED, -d2i_ASN1_GENERALIZEDTIME, -d2i_ASN1_GENERALSTRING, -d2i_ASN1_IA5STRING, -d2i_ASN1_INTEGER, -d2i_ASN1_NULL, -d2i_ASN1_OBJECT, -d2i_ASN1_OCTET_STRING, -d2i_ASN1_PRINTABLE, -d2i_ASN1_PRINTABLESTRING, -d2i_ASN1_SEQUENCE_ANY, -d2i_ASN1_SET_ANY, -d2i_ASN1_T61STRING, -d2i_ASN1_TIME, -d2i_ASN1_TYPE, -d2i_ASN1_UINTEGER, -d2i_ASN1_UNIVERSALSTRING, -d2i_ASN1_UTCTIME, -d2i_ASN1_UTF8STRING, -d2i_ASN1_VISIBLESTRING, -d2i_ASRange, -d2i_AUTHORITY_INFO_ACCESS, -d2i_AUTHORITY_KEYID, -d2i_BASIC_CONSTRAINTS, -d2i_CERTIFICATEPOLICIES, -d2i_CMS_ContentInfo, -d2i_CMS_ReceiptRequest, -d2i_CMS_bio, -d2i_CRL_DIST_POINTS, -d2i_DHxparams, -d2i_DIRECTORYSTRING, -d2i_DISPLAYTEXT, -d2i_DIST_POINT, -d2i_DIST_POINT_NAME, -d2i_DSA_SIG, -d2i_ECDSA_SIG, -d2i_ECPKParameters, -d2i_EDIPARTYNAME, -d2i_ESS_CERT_ID, -d2i_ESS_CERT_ID_V2, -d2i_ESS_ISSUER_SERIAL, -d2i_ESS_SIGNING_CERT, -d2i_ESS_SIGNING_CERT_V2, -d2i_EXTENDED_KEY_USAGE, -d2i_GENERAL_NAME, -d2i_GENERAL_NAMES, -d2i_IPAddressChoice, -d2i_IPAddressFamily, -d2i_IPAddressOrRange, -d2i_IPAddressRange, -d2i_ISSUER_SIGN_TOOL, -d2i_ISSUING_DIST_POINT, -d2i_NAMING_AUTHORITY, -d2i_NETSCAPE_CERT_SEQUENCE, -d2i_NETSCAPE_SPKAC, -d2i_NETSCAPE_SPKI, -d2i_NOTICEREF, -d2i_OCSP_BASICRESP, -d2i_OCSP_CERTID, -d2i_OCSP_CERTSTATUS, -d2i_OCSP_CRLID, -d2i_OCSP_ONEREQ, -d2i_OCSP_REQINFO, -d2i_OCSP_REQUEST, -d2i_OCSP_RESPBYTES, -d2i_OCSP_RESPDATA, -d2i_OCSP_RESPID, -d2i_OCSP_RESPONSE, -d2i_OCSP_REVOKEDINFO, -d2i_OCSP_SERVICELOC, -d2i_OCSP_SIGNATURE, -d2i_OCSP_SINGLERESP, -d2i_OSSL_ATTRIBUTES_SYNTAX, -d2i_OSSL_BASIC_ATTR_CONSTRAINTS, -d2i_OSSL_CMP_ATAVS, -d2i_OSSL_CMP_MSG, -d2i_OSSL_CMP_PKIHEADER, -d2i_OSSL_CMP_PKISI, -d2i_OSSL_CRMF_CERTID, -d2i_OSSL_CRMF_CERTTEMPLATE, -d2i_OSSL_CRMF_ENCRYPTEDVALUE, -d2i_OSSL_CRMF_MSG, -d2i_OSSL_CRMF_MSGS, -d2i_OSSL_CRMF_PBMPARAMETER, -d2i_OSSL_CRMF_PKIPUBLICATIONINFO, -d2i_OSSL_CRMF_SINGLEPUBINFO, -d2i_OSSL_IETF_ATTR_SYNTAX, -d2i_OSSL_ISSUER_SERIAL, -d2i_OSSL_OBJECT_DIGEST_INFO, -d2i_OSSL_TARGET_CERT, -d2i_OSSL_TARGET, -d2i_OSSL_TARGETING_INFORMATION, -d2i_OSSL_TARGETS, -d2i_OSSL_USER_NOTICE_SYNTAX, -d2i_OTHERNAME, -d2i_PBE2PARAM, -d2i_PBEPARAM, -d2i_PBKDF2PARAM, -d2i_PBMAC1PARAM, -d2i_PKCS12, -d2i_PKCS12_BAGS, -d2i_PKCS12_MAC_DATA, -d2i_PKCS12_SAFEBAG, -d2i_PKCS12_bio, -d2i_PKCS12_fp, -d2i_PKCS7, -d2i_PKCS7_DIGEST, -d2i_PKCS7_ENCRYPT, -d2i_PKCS7_ENC_CONTENT, -d2i_PKCS7_ENVELOPE, -d2i_PKCS7_ISSUER_AND_SERIAL, -d2i_PKCS7_RECIP_INFO, -d2i_PKCS7_SIGNED, -d2i_PKCS7_SIGNER_INFO, -d2i_PKCS7_SIGN_ENVELOPE, -d2i_PKCS7_bio, -d2i_PKCS7_fp, -d2i_PKCS8_PRIV_KEY_INFO, -d2i_PKCS8_PRIV_KEY_INFO_bio, -d2i_PKCS8_PRIV_KEY_INFO_fp, -d2i_PKCS8_bio, -d2i_PKCS8_fp, -d2i_PKEY_USAGE_PERIOD, -d2i_POLICYINFO, -d2i_POLICYQUALINFO, -d2i_PROFESSION_INFO, -d2i_PROXY_CERT_INFO_EXTENSION, -d2i_PROXY_POLICY, -d2i_RSA_OAEP_PARAMS, -d2i_RSA_PSS_PARAMS, -d2i_SCRYPT_PARAMS, -d2i_SCT_LIST, -d2i_SXNET, -d2i_SXNETID, -d2i_TS_ACCURACY, -d2i_TS_MSG_IMPRINT, -d2i_TS_MSG_IMPRINT_bio, -d2i_TS_MSG_IMPRINT_fp, -d2i_TS_REQ, -d2i_TS_REQ_bio, -d2i_TS_REQ_fp, -d2i_TS_RESP, -d2i_TS_RESP_bio, -d2i_TS_RESP_fp, -d2i_TS_STATUS_INFO, -d2i_TS_TST_INFO, -d2i_TS_TST_INFO_bio, -d2i_TS_TST_INFO_fp, -d2i_USERNOTICE, -d2i_X509, -d2i_X509_bio, -d2i_X509_fp, -d2i_X509_ACERT, -d2i_X509_ACERT_bio, -d2i_X509_ACERT_fp, -d2i_X509_ALGOR, -d2i_X509_ALGORS, -d2i_X509_ATTRIBUTE, -d2i_X509_CERT_AUX, -d2i_X509_CINF, -d2i_X509_CRL, -d2i_X509_CRL_INFO, -d2i_X509_CRL_bio, -d2i_X509_CRL_fp, -d2i_X509_EXTENSION, -d2i_X509_EXTENSIONS, -d2i_X509_NAME, -d2i_X509_NAME_ENTRY, -d2i_X509_PUBKEY, -d2i_X509_PUBKEY_bio, -d2i_X509_PUBKEY_fp, -d2i_X509_REQ, -d2i_X509_REQ_INFO, -d2i_X509_REQ_bio, -d2i_X509_REQ_fp, -d2i_X509_REVOKED, -d2i_X509_SIG, -d2i_X509_VAL, -i2d_ACCESS_DESCRIPTION, -i2d_ADMISSIONS, -i2d_ADMISSION_SYNTAX, -i2d_ASIdOrRange, -i2d_ASIdentifierChoice, -i2d_ASIdentifiers, -i2d_ASN1_BIT_STRING, -i2d_ASN1_BMPSTRING, -i2d_ASN1_ENUMERATED, -i2d_ASN1_GENERALIZEDTIME, -i2d_ASN1_GENERALSTRING, -i2d_ASN1_IA5STRING, -i2d_ASN1_INTEGER, -i2d_ASN1_NULL, -i2d_ASN1_OBJECT, -i2d_ASN1_OCTET_STRING, -i2d_ASN1_PRINTABLE, -i2d_ASN1_PRINTABLESTRING, -i2d_ASN1_SEQUENCE_ANY, -i2d_ASN1_SET_ANY, -i2d_ASN1_T61STRING, -i2d_ASN1_TIME, -i2d_ASN1_TYPE, -i2d_ASN1_UNIVERSALSTRING, -i2d_ASN1_UTCTIME, -i2d_ASN1_UTF8STRING, -i2d_ASN1_VISIBLESTRING, -i2d_ASN1_bio_stream, -i2d_ASRange, -i2d_AUTHORITY_INFO_ACCESS, -i2d_AUTHORITY_KEYID, -i2d_BASIC_CONSTRAINTS, -i2d_CERTIFICATEPOLICIES, -i2d_CMS_ContentInfo, -i2d_CMS_ReceiptRequest, -i2d_CMS_bio, -i2d_CRL_DIST_POINTS, -i2d_DHxparams, -i2d_DIRECTORYSTRING, -i2d_DISPLAYTEXT, -i2d_DIST_POINT, -i2d_DIST_POINT_NAME, -i2d_DSA_SIG, -i2d_ECDSA_SIG, -i2d_ECPKParameters, -i2d_EDIPARTYNAME, -i2d_ESS_CERT_ID, -i2d_ESS_CERT_ID_V2, -i2d_ESS_ISSUER_SERIAL, -i2d_ESS_SIGNING_CERT, -i2d_ESS_SIGNING_CERT_V2, -i2d_EXTENDED_KEY_USAGE, -i2d_GENERAL_NAME, -i2d_GENERAL_NAMES, -i2d_IPAddressChoice, -i2d_IPAddressFamily, -i2d_IPAddressOrRange, -i2d_IPAddressRange, -i2d_ISSUER_SIGN_TOOL, -i2d_ISSUING_DIST_POINT, -i2d_NAMING_AUTHORITY, -i2d_NETSCAPE_CERT_SEQUENCE, -i2d_NETSCAPE_SPKAC, -i2d_NETSCAPE_SPKI, -i2d_NOTICEREF, -i2d_OCSP_BASICRESP, -i2d_OCSP_CERTID, -i2d_OCSP_CERTSTATUS, -i2d_OCSP_CRLID, -i2d_OCSP_ONEREQ, -i2d_OCSP_REQINFO, -i2d_OCSP_REQUEST, -i2d_OCSP_RESPBYTES, -i2d_OCSP_RESPDATA, -i2d_OCSP_RESPID, -i2d_OCSP_RESPONSE, -i2d_OCSP_REVOKEDINFO, -i2d_OCSP_SERVICELOC, -i2d_OCSP_SIGNATURE, -i2d_OCSP_SINGLERESP, -i2d_OSSL_ATTRIBUTES_SYNTAX, -i2d_OSSL_BASIC_ATTR_CONSTRAINTS, -i2d_OSSL_CMP_ATAVS, -i2d_OSSL_CMP_MSG, -i2d_OSSL_CMP_PKIHEADER, -i2d_OSSL_CMP_PKISI, -i2d_OSSL_CRMF_CERTID, -i2d_OSSL_CRMF_CERTTEMPLATE, -i2d_OSSL_CRMF_ENCRYPTEDVALUE, -i2d_OSSL_CRMF_MSG, -i2d_OSSL_CRMF_MSGS, -i2d_OSSL_CRMF_PBMPARAMETER, -i2d_OSSL_CRMF_PKIPUBLICATIONINFO, -i2d_OSSL_CRMF_SINGLEPUBINFO, -i2d_OSSL_IETF_ATTR_SYNTAX, -i2d_OSSL_ISSUER_SERIAL, -i2d_OSSL_OBJECT_DIGEST_INFO, -i2d_OSSL_TARGET_CERT, -i2d_OSSL_TARGET, -i2d_OSSL_TARGETING_INFORMATION, -i2d_OSSL_TARGETS, -i2d_OSSL_USER_NOTICE_SYNTAX, -i2d_OTHERNAME, -i2d_PBE2PARAM, -i2d_PBEPARAM, -i2d_PBKDF2PARAM, -i2d_PBMAC1PARAM, -i2d_PKCS12, -i2d_PKCS12_BAGS, -i2d_PKCS12_MAC_DATA, -i2d_PKCS12_SAFEBAG, -i2d_PKCS12_bio, -i2d_PKCS12_fp, -i2d_PKCS7, -i2d_PKCS7_DIGEST, -i2d_PKCS7_ENCRYPT, -i2d_PKCS7_ENC_CONTENT, -i2d_PKCS7_ENVELOPE, -i2d_PKCS7_ISSUER_AND_SERIAL, -i2d_PKCS7_NDEF, -i2d_PKCS7_RECIP_INFO, -i2d_PKCS7_SIGNED, -i2d_PKCS7_SIGNER_INFO, -i2d_PKCS7_SIGN_ENVELOPE, -i2d_PKCS7_bio, -i2d_PKCS7_fp, -i2d_PKCS8PrivateKeyInfo_bio, -i2d_PKCS8PrivateKeyInfo_fp, -i2d_PKCS8_PRIV_KEY_INFO, -i2d_PKCS8_PRIV_KEY_INFO_bio, -i2d_PKCS8_PRIV_KEY_INFO_fp, -i2d_PKCS8_bio, -i2d_PKCS8_fp, -i2d_PKEY_USAGE_PERIOD, -i2d_POLICYINFO, -i2d_POLICYQUALINFO, -i2d_PROFESSION_INFO, -i2d_PROXY_CERT_INFO_EXTENSION, -i2d_PROXY_POLICY, -i2d_RSA_OAEP_PARAMS, -i2d_RSA_PSS_PARAMS, -i2d_SCRYPT_PARAMS, -i2d_SCT_LIST, -i2d_SXNET, -i2d_SXNETID, -i2d_TS_ACCURACY, -i2d_TS_MSG_IMPRINT, -i2d_TS_MSG_IMPRINT_bio, -i2d_TS_MSG_IMPRINT_fp, -i2d_TS_REQ, -i2d_TS_REQ_bio, -i2d_TS_REQ_fp, -i2d_TS_RESP, -i2d_TS_RESP_bio, -i2d_TS_RESP_fp, -i2d_TS_STATUS_INFO, -i2d_TS_TST_INFO, -i2d_TS_TST_INFO_bio, -i2d_TS_TST_INFO_fp, -i2d_USERNOTICE, -i2d_X509, -i2d_X509_bio, -i2d_X509_fp, -i2d_X509_ACERT, -i2d_X509_ACERT_bio, -i2d_X509_ACERT_fp, -i2d_X509_ALGOR, -i2d_X509_ALGORS, -i2d_X509_ATTRIBUTE, -i2d_X509_CERT_AUX, -i2d_X509_CINF, -i2d_X509_CRL, -i2d_X509_CRL_INFO, -i2d_X509_CRL_bio, -i2d_X509_CRL_fp, -i2d_X509_EXTENSION, -i2d_X509_EXTENSIONS, -i2d_X509_NAME, -i2d_X509_NAME_ENTRY, -i2d_X509_PUBKEY, -i2d_X509_PUBKEY_bio, -i2d_X509_PUBKEY_fp, -i2d_X509_REQ, -i2d_X509_REQ_INFO, -i2d_X509_REQ_bio, -i2d_X509_REQ_fp, -i2d_X509_REVOKED, -i2d_X509_SIG, -i2d_X509_VAL, -\&\- convert objects from/to ASN.1/DER representation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 3 -\& TYPE *d2i_TYPE(TYPE **a, const unsigned char **ppin, long length); -\& TYPE *d2i_TYPE_bio(BIO *bp, TYPE **a); -\& TYPE *d2i_TYPE_fp(FILE *fp, TYPE **a); -\& -\& int i2d_TYPE(const TYPE *a, unsigned char **ppout); -\& int i2d_TYPE(TYPE *a, unsigned char **ppout); -\& int i2d_TYPE_fp(FILE *fp, const TYPE *a); -\& int i2d_TYPE_fp(FILE *fp, TYPE *a); -\& int i2d_TYPE_bio(BIO *bp, const TYPE *a); -\& int i2d_TYPE_bio(BIO *bp, TYPE *a); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -In the description here, \fB\f(BI\s-1TYPE\s0\fB\fR is used a placeholder -for any of the OpenSSL datatypes, such as \fBX509_CRL\fR. -The function parameters \fIppin\fR and \fIppout\fR are generally -either both named \fIpp\fR in the headers, or \fIin\fR and \fIout\fR. -.PP -These functions convert OpenSSL objects to and from their \s-1ASN.1/DER\s0 -encoding. Unlike the C structures which can have pointers to sub-objects -within, the \s-1DER\s0 is a serialized encoding, suitable for sending over the -network, writing to a file, and so on. -.PP -\&\fBd2i_\f(BI\s-1TYPE\s0\fB\fR() attempts to decode \fIlen\fR bytes at \fI*ppin\fR. If successful a -pointer to the \fB\f(BI\s-1TYPE\s0\fB\fR structure is returned and \fI*ppin\fR is incremented to -the byte following the parsed data. If \fIa\fR is not \s-1NULL\s0 then a pointer -to the returned structure is also written to \fI*a\fR. If an error occurred -then \s-1NULL\s0 is returned. The caller retains ownership of the -returned object and needs to free it when it is no longer needed, e.g. -using \fBX509_free()\fR for X509 objects or \fBDSA_SIG_free()\fR for \s-1DSA_SIG\s0 objects. -.PP -On a successful return, if \fI*a\fR is not \s-1NULL\s0 then it is assumed that \fI*a\fR -contains a valid \fB\f(BI\s-1TYPE\s0\fB\fR structure and an attempt is made to reuse it. -For \fB\f(BI\s-1TYPE\s0\fB\fR structures where it matters it is possible to set up a library -context on the decoded structure this way (see the \fB\s-1EXAMPLES\s0\fR section). -However using the \*(L"reuse\*(R" capability for other purposes is \fBstrongly -discouraged\fR (see \fB\s-1BUGS\s0\fR below, and the discussion in the \fB\s-1RETURN VALUES\s0\fR -section). -.PP -\&\fBd2i_\f(BI\s-1TYPE\s0\fB_bio\fR() is similar to \fBd2i_\f(BI\s-1TYPE\s0\fB\fR() except it attempts -to parse data from \s-1BIO\s0 \fIbp\fR. -.PP -\&\fBd2i_\f(BI\s-1TYPE\s0\fB_fp\fR() is similar to \fBd2i_\f(BI\s-1TYPE\s0\fB\fR() except it attempts -to parse data from \s-1FILE\s0 pointer \fIfp\fR. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB\fR() encodes the structure pointed to by \fIa\fR into \s-1DER\s0 format. -If \fIppout\fR is not \s-1NULL,\s0 it writes the \s-1DER\s0 encoded data to the buffer -at \fI*ppout\fR, and increments it to point after the data just written. -If the return value is negative an error occurred, otherwise it -returns the length of the encoded data. -.PP -If \fI*ppout\fR is \s-1NULL\s0 memory will be allocated for a buffer and the encoded -data written to it. In this case \fI*ppout\fR is not incremented and it points -to the start of the data just written. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB_bio\fR() is similar to \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() except it writes -the encoding of the structure \fIa\fR to \s-1BIO\s0 \fIbp\fR and it -returns 1 for success and 0 for failure. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB_fp\fR() is similar to \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() except it writes -the encoding of the structure \fIa\fR to \s-1FILE\s0 pointer \fIfp\fR and it -returns 1 for success and 0 for failure. -.PP -These routines do not encrypt private keys and therefore offer no -security; use \fBPEM_write_PrivateKey\fR\|(3) or similar for writing to files. -.SH "NOTES" -.IX Header "NOTES" -The letters \fBi\fR and \fBd\fR in \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() stand for -\&\*(L"internal\*(R" (that is, an internal C structure) and \*(L"\s-1DER\*(R"\s0 respectively. -So \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() converts from internal to \s-1DER.\s0 -.PP -The functions can also understand \fB\s-1BER\s0\fR forms. -.PP -The actual \s-1TYPE\s0 structure passed to \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() must be a valid -populated \fB\f(BI\s-1TYPE\s0\fB\fR structure \*(-- it \fBcannot\fR simply be fed with an -empty structure such as that returned by \fBTYPE_new()\fR. -.PP -The encoded data is in binary form and may contain embedded zeros. -Therefore, any \s-1FILE\s0 pointers or BIOs should be opened in binary mode. -Functions such as \fBstrlen()\fR will \fBnot\fR return the correct length -of the encoded structure. -.PP -The ways that \fI*ppin\fR and \fI*ppout\fR are incremented after the operation -can trap the unwary. See the \fB\s-1WARNINGS\s0\fR section for some common -errors. -The reason for this-auto increment behaviour is to reflect a typical -usage of \s-1ASN1\s0 functions: after one structure is encoded or decoded -another will be processed after it. -.PP -The following points about the data types might be useful: -.IP "\fB\s-1ASN1_OBJECT\s0\fR" 4 -.IX Item "ASN1_OBJECT" -Represents an \s-1ASN1 OBJECT IDENTIFIER.\s0 -.IP "\fBDHparams\fR" 4 -.IX Item "DHparams" -Represents a PKCS#3 \s-1DH\s0 parameters structure. -.IP "\fBDHxparams\fR" 4 -.IX Item "DHxparams" -Represents an \s-1ANSI X9.42 DH\s0 parameters structure. -.IP "\fB\s-1ECDSA_SIG\s0\fR" 4 -.IX Item "ECDSA_SIG" -Represents an \s-1ECDSA\s0 signature. -.IP "\fBX509_ALGOR\fR" 4 -.IX Item "X509_ALGOR" -Represents an \fBAlgorithmIdentifier\fR structure as used in \s-1IETF RFC 6960\s0 and -elsewhere. -.IP "\fBX509_NAME\fR" 4 -.IX Item "X509_NAME" -Represents a \fBName\fR type as used for subject and issuer names in -\&\s-1IETF RFC 6960\s0 and elsewhere. -.IP "\fBX509_REQ\fR" 4 -.IX Item "X509_REQ" -Represents a PKCS#10 certificate request. -.IP "\fBX509_SIG\fR" 4 -.IX Item "X509_SIG" -Represents the \fBDigestInfo\fR structure defined in PKCS#1 and PKCS#7. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBd2i_\f(BI\s-1TYPE\s0\fB\fR(), \fBd2i_\f(BI\s-1TYPE\s0\fB_bio\fR() and \fBd2i_\f(BI\s-1TYPE\s0\fB_fp\fR() return a valid -\&\fB\f(BI\s-1TYPE\s0\fB\fR structure or \s-1NULL\s0 if an error occurs. If the \*(L"reuse\*(R" capability has -been used with a valid structure being passed in via \fIa\fR, then the object is -freed in the event of error and \fI*a\fR is set to \s-1NULL.\s0 -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB\fR() returns the number of bytes successfully encoded or a negative -value if an error occurs. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB_bio\fR() and \fBi2d_\f(BI\s-1TYPE\s0\fB_fp\fR() return 1 for success and 0 if an -error occurs. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Allocate and encode the \s-1DER\s0 encoding of an X509 structure: -.PP -.Vb 2 -\& int len; -\& unsigned char *buf; -\& -\& buf = NULL; -\& len = i2d_X509(x, &buf); -\& if (len < 0) -\& /* error */ -.Ve -.PP -Attempt to decode a buffer: -.PP -.Vb 4 -\& X509 *x; -\& unsigned char *buf; -\& const unsigned char *p; -\& int len; -\& -\& /* Set up buf and len to point to the input buffer. */ -\& p = buf; -\& x = d2i_X509(NULL, &p, len); -\& if (x == NULL) -\& /* error */ -.Ve -.PP -Alternative technique: -.PP -.Vb 4 -\& X509 *x; -\& unsigned char *buf; -\& const unsigned char *p; -\& int len; -\& -\& /* Set up buf and len to point to the input buffer. */ -\& p = buf; -\& x = NULL; -\& -\& if (d2i_X509(&x, &p, len) == NULL) -\& /* error */ -.Ve -.PP -Setting up a library context and property query: -.PP -.Vb 6 -\& X509 *x; -\& unsigned char *buf; -\& const unsigned char *p; -\& int len; -\& OSSL_LIB_CTX *libctx = ....; -\& const char *propq = ....; -\& -\& /* Set up buf and len to point to the input buffer. */ -\& p = buf; -\& x = X509_new_ex(libctx, propq); -\& -\& if (d2i_X509(&x, &p, len) == NULL) -\& /* error, x was freed and NULL assigned to it (see RETURN VALUES) */ -.Ve -.SH "WARNINGS" -.IX Header "WARNINGS" -Using a temporary variable is mandatory. A common -mistake is to attempt to use a buffer directly as follows: -.PP -.Vb 2 -\& int len; -\& unsigned char *buf; -\& -\& len = i2d_X509(x, NULL); -\& buf = OPENSSL_malloc(len); -\& ... -\& i2d_X509(x, &buf); -\& ... -\& OPENSSL_free(buf); -.Ve -.PP -This code will result in \fIbuf\fR apparently containing garbage because -it was incremented after the call to point after the data just written. -Also \fIbuf\fR will no longer contain the pointer allocated by \fBOPENSSL_malloc()\fR -and the subsequent call to \fBOPENSSL_free()\fR is likely to crash. -.PP -Another trap to avoid is misuse of the \fIa\fR argument to \fBd2i_\f(BI\s-1TYPE\s0\fB\fR(): -.PP -.Vb 1 -\& X509 *x; -\& -\& if (d2i_X509(&x, &p, len) == NULL) -\& /* error */ -.Ve -.PP -This will probably crash somewhere in \fBd2i_X509()\fR. The reason for this -is that the variable \fIx\fR is uninitialized and an attempt will be made to -interpret its (invalid) value as an \fBX509\fR structure, typically causing -a segmentation violation. If \fIx\fR is set to \s-1NULL\s0 first then this will not -happen. -.SH "BUGS" -.IX Header "BUGS" -In some versions of OpenSSL the \*(L"reuse\*(R" behaviour of \fBd2i_\f(BI\s-1TYPE\s0\fB\fR() when -\&\fI*a\fR is valid is broken and some parts of the reused structure may -persist if they are not present in the new one. Additionally, in versions of -OpenSSL prior to 1.1.0, when the \*(L"reuse\*(R" behaviour is used and an error occurs -the behaviour is inconsistent. Some functions behaved as described here, while -some did not free \fI*a\fR on error and did not set \fI*a\fR to \s-1NULL.\s0 -.PP -As a result of the above issues the \*(L"reuse\*(R" behaviour is strongly discouraged. -.PP -\&\fBi2d_\f(BI\s-1TYPE\s0\fB\fR() will not return an error in many versions of OpenSSL, -if mandatory fields are not initialized due to a programming error -then the encoded structure may contain invalid data or omit the -fields entirely and will not be parsed by \fBd2i_\f(BI\s-1TYPE\s0\fB\fR(). This may be -fixed in future so code should not assume that \fBi2d_\f(BI\s-1TYPE\s0\fB\fR() will -always succeed. -.PP -Any function which encodes a structure (\fBi2d_\f(BI\s-1TYPE\s0\fB\fR(), -\&\fBi2d_\f(BI\s-1TYPE\s0\fB_bio\fR() or \fBi2d_\f(BI\s-1TYPE\s0\fB_fp\fR()) may return a stale encoding if the -structure has been modified after deserialization or previous -serialization. This is because some objects cache the encoding for -efficiency reasons. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 1998\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/d2i_X509_ACERT.3ossl b/openssl-install/share/man/man3/d2i_X509_ACERT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_ACERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_ACERT_bio.3ossl b/openssl-install/share/man/man3/d2i_X509_ACERT_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_ACERT_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_ACERT_fp.3ossl b/openssl-install/share/man/man3/d2i_X509_ACERT_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_ACERT_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_ALGOR.3ossl b/openssl-install/share/man/man3/d2i_X509_ALGOR.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_ALGOR.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_ALGORS.3ossl b/openssl-install/share/man/man3/d2i_X509_ALGORS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_ALGORS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_ATTRIBUTE.3ossl b/openssl-install/share/man/man3/d2i_X509_ATTRIBUTE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_ATTRIBUTE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_AUX.3ossl b/openssl-install/share/man/man3/d2i_X509_AUX.3ossl deleted file mode 120000 index 91b802a5..00000000 --- a/openssl-install/share/man/man3/d2i_X509_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -i2d_re_X509_tbs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_CERT_AUX.3ossl b/openssl-install/share/man/man3/d2i_X509_CERT_AUX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_CERT_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_CINF.3ossl b/openssl-install/share/man/man3/d2i_X509_CINF.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_CINF.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_CRL.3ossl b/openssl-install/share/man/man3/d2i_X509_CRL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_CRL_INFO.3ossl b/openssl-install/share/man/man3/d2i_X509_CRL_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_CRL_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_CRL_bio.3ossl b/openssl-install/share/man/man3/d2i_X509_CRL_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_CRL_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_CRL_fp.3ossl b/openssl-install/share/man/man3/d2i_X509_CRL_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_CRL_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_EXTENSION.3ossl b/openssl-install/share/man/man3/d2i_X509_EXTENSION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_EXTENSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_EXTENSIONS.3ossl b/openssl-install/share/man/man3/d2i_X509_EXTENSIONS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_EXTENSIONS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_NAME.3ossl b/openssl-install/share/man/man3/d2i_X509_NAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_NAME_ENTRY.3ossl b/openssl-install/share/man/man3/d2i_X509_NAME_ENTRY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_NAME_ENTRY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/d2i_X509_PUBKEY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/d2i_X509_PUBKEY_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/d2i_X509_PUBKEY_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_REQ.3ossl b/openssl-install/share/man/man3/d2i_X509_REQ.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_REQ_INFO.3ossl b/openssl-install/share/man/man3/d2i_X509_REQ_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_REQ_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_REQ_bio.3ossl b/openssl-install/share/man/man3/d2i_X509_REQ_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_REQ_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_REQ_fp.3ossl b/openssl-install/share/man/man3/d2i_X509_REQ_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_REQ_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_REVOKED.3ossl b/openssl-install/share/man/man3/d2i_X509_REVOKED.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_REVOKED.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_SIG.3ossl b/openssl-install/share/man/man3/d2i_X509_SIG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_SIG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_VAL.3ossl b/openssl-install/share/man/man3/d2i_X509_VAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_VAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_bio.3ossl b/openssl-install/share/man/man3/d2i_X509_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/d2i_X509_fp.3ossl b/openssl-install/share/man/man3/d2i_X509_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/d2i_X509_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2b_PVK_bio.3ossl b/openssl-install/share/man/man3/i2b_PVK_bio.3ossl deleted file mode 120000 index 77ba71b4..00000000 --- a/openssl-install/share/man/man3/i2b_PVK_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -b2i_PVK_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2b_PVK_bio_ex.3ossl b/openssl-install/share/man/man3/i2b_PVK_bio_ex.3ossl deleted file mode 120000 index 77ba71b4..00000000 --- a/openssl-install/share/man/man3/i2b_PVK_bio_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -b2i_PVK_bio_ex.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ACCESS_DESCRIPTION.3ossl b/openssl-install/share/man/man3/i2d_ACCESS_DESCRIPTION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ACCESS_DESCRIPTION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ADMISSIONS.3ossl b/openssl-install/share/man/man3/i2d_ADMISSIONS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ADMISSIONS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ADMISSION_SYNTAX.3ossl b/openssl-install/share/man/man3/i2d_ADMISSION_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ADMISSION_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASIdOrRange.3ossl b/openssl-install/share/man/man3/i2d_ASIdOrRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASIdOrRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASIdentifierChoice.3ossl b/openssl-install/share/man/man3/i2d_ASIdentifierChoice.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASIdentifierChoice.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASIdentifiers.3ossl b/openssl-install/share/man/man3/i2d_ASIdentifiers.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASIdentifiers.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_BIT_STRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_BIT_STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_BIT_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_BMPSTRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_BMPSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_BMPSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_ENUMERATED.3ossl b/openssl-install/share/man/man3/i2d_ASN1_ENUMERATED.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_ENUMERATED.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_GENERALIZEDTIME.3ossl b/openssl-install/share/man/man3/i2d_ASN1_GENERALIZEDTIME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_GENERALIZEDTIME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_GENERALSTRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_GENERALSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_GENERALSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_IA5STRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_IA5STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_IA5STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_INTEGER.3ossl b/openssl-install/share/man/man3/i2d_ASN1_INTEGER.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_INTEGER.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_NULL.3ossl b/openssl-install/share/man/man3/i2d_ASN1_NULL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_NULL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_OBJECT.3ossl b/openssl-install/share/man/man3/i2d_ASN1_OBJECT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_OBJECT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_OCTET_STRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_OCTET_STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_OCTET_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_PRINTABLE.3ossl b/openssl-install/share/man/man3/i2d_ASN1_PRINTABLE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_PRINTABLE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_PRINTABLESTRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_PRINTABLESTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_PRINTABLESTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_SEQUENCE_ANY.3ossl b/openssl-install/share/man/man3/i2d_ASN1_SEQUENCE_ANY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_SEQUENCE_ANY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_SET_ANY.3ossl b/openssl-install/share/man/man3/i2d_ASN1_SET_ANY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_SET_ANY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_T61STRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_T61STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_T61STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_TIME.3ossl b/openssl-install/share/man/man3/i2d_ASN1_TIME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_TIME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_TYPE.3ossl b/openssl-install/share/man/man3/i2d_ASN1_TYPE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_TYPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_UNIVERSALSTRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_UNIVERSALSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_UNIVERSALSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_UTCTIME.3ossl b/openssl-install/share/man/man3/i2d_ASN1_UTCTIME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_UTCTIME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_UTF8STRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_UTF8STRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_UTF8STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_VISIBLESTRING.3ossl b/openssl-install/share/man/man3/i2d_ASN1_VISIBLESTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_VISIBLESTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASN1_bio_stream.3ossl b/openssl-install/share/man/man3/i2d_ASN1_bio_stream.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASN1_bio_stream.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ASRange.3ossl b/openssl-install/share/man/man3/i2d_ASRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ASRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_AUTHORITY_INFO_ACCESS.3ossl b/openssl-install/share/man/man3/i2d_AUTHORITY_INFO_ACCESS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_AUTHORITY_INFO_ACCESS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_AUTHORITY_KEYID.3ossl b/openssl-install/share/man/man3/i2d_AUTHORITY_KEYID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_AUTHORITY_KEYID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_BASIC_CONSTRAINTS.3ossl b/openssl-install/share/man/man3/i2d_BASIC_CONSTRAINTS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_BASIC_CONSTRAINTS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_CERTIFICATEPOLICIES.3ossl b/openssl-install/share/man/man3/i2d_CERTIFICATEPOLICIES.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_CERTIFICATEPOLICIES.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_CMS_ContentInfo.3ossl b/openssl-install/share/man/man3/i2d_CMS_ContentInfo.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_CMS_ContentInfo.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_CMS_ReceiptRequest.3ossl b/openssl-install/share/man/man3/i2d_CMS_ReceiptRequest.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_CMS_ReceiptRequest.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_CMS_bio.3ossl b/openssl-install/share/man/man3/i2d_CMS_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_CMS_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_CMS_bio_stream.3ossl b/openssl-install/share/man/man3/i2d_CMS_bio_stream.3ossl deleted file mode 100644 index b740445f..00000000 --- a/openssl-install/share/man/man3/i2d_CMS_bio_stream.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "I2D_CMS_BIO_STREAM 3ossl" -.TH I2D_CMS_BIO_STREAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -i2d_CMS_bio_stream \- output CMS_ContentInfo structure in BER format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int i2d_CMS_bio_stream(BIO *out, CMS_ContentInfo *cms, BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBi2d_CMS_bio_stream()\fR outputs a CMS_ContentInfo structure in \s-1BER\s0 format. -.PP -It is otherwise identical to the function \fBSMIME_write_CMS()\fR. -.SH "NOTES" -.IX Header "NOTES" -This function is effectively a version of the \fBi2d_CMS_bio()\fR supporting -streaming. -.SH "BUGS" -.IX Header "BUGS" -The prefix \*(L"i2d\*(R" is arguably wrong because the function outputs \s-1BER\s0 format. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBi2d_CMS_bio_stream()\fR returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBCMS_sign\fR\|(3), -\&\fBCMS_verify\fR\|(3), \fBCMS_encrypt\fR\|(3) -\&\fBCMS_decrypt\fR\|(3), -\&\fBSMIME_write_CMS\fR\|(3), -\&\fBPEM_write_bio_CMS_stream\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBi2d_CMS_bio_stream()\fR function was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/i2d_CRL_DIST_POINTS.3ossl b/openssl-install/share/man/man3/i2d_CRL_DIST_POINTS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_CRL_DIST_POINTS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DHparams.3ossl b/openssl-install/share/man/man3/i2d_DHparams.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DHparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DHparams_bio.3ossl b/openssl-install/share/man/man3/i2d_DHparams_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DHparams_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DHparams_fp.3ossl b/openssl-install/share/man/man3/i2d_DHparams_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DHparams_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DHxparams.3ossl b/openssl-install/share/man/man3/i2d_DHxparams.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_DHxparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DIRECTORYSTRING.3ossl b/openssl-install/share/man/man3/i2d_DIRECTORYSTRING.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_DIRECTORYSTRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DISPLAYTEXT.3ossl b/openssl-install/share/man/man3/i2d_DISPLAYTEXT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_DISPLAYTEXT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DIST_POINT.3ossl b/openssl-install/share/man/man3/i2d_DIST_POINT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_DIST_POINT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DIST_POINT_NAME.3ossl b/openssl-install/share/man/man3/i2d_DIST_POINT_NAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_DIST_POINT_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSAPrivateKey.3ossl b/openssl-install/share/man/man3/i2d_DSAPrivateKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSAPrivateKey_bio.3ossl b/openssl-install/share/man/man3/i2d_DSAPrivateKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSAPrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSAPrivateKey_fp.3ossl b/openssl-install/share/man/man3/i2d_DSAPrivateKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSAPrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSAPublicKey.3ossl b/openssl-install/share/man/man3/i2d_DSAPublicKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSA_PUBKEY.3ossl b/openssl-install/share/man/man3/i2d_DSA_PUBKEY.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSA_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/i2d_DSA_PUBKEY_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSA_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSA_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/i2d_DSA_PUBKEY_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSA_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSA_SIG.3ossl b/openssl-install/share/man/man3/i2d_DSA_SIG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_DSA_SIG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_DSAparams.3ossl b/openssl-install/share/man/man3/i2d_DSAparams.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_DSAparams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ECDSA_SIG.3ossl b/openssl-install/share/man/man3/i2d_ECDSA_SIG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ECDSA_SIG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ECPKParameters.3ossl b/openssl-install/share/man/man3/i2d_ECPKParameters.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ECPKParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ECParameters.3ossl b/openssl-install/share/man/man3/i2d_ECParameters.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_ECParameters.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ECPrivateKey.3ossl b/openssl-install/share/man/man3/i2d_ECPrivateKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_ECPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ECPrivateKey_bio.3ossl b/openssl-install/share/man/man3/i2d_ECPrivateKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_ECPrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ECPrivateKey_fp.3ossl b/openssl-install/share/man/man3/i2d_ECPrivateKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_ECPrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_EC_PUBKEY.3ossl b/openssl-install/share/man/man3/i2d_EC_PUBKEY.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_EC_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_EC_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/i2d_EC_PUBKEY_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_EC_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_EC_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/i2d_EC_PUBKEY_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_EC_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_EDIPARTYNAME.3ossl b/openssl-install/share/man/man3/i2d_EDIPARTYNAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_EDIPARTYNAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ESS_CERT_ID.3ossl b/openssl-install/share/man/man3/i2d_ESS_CERT_ID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ESS_CERT_ID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ESS_CERT_ID_V2.3ossl b/openssl-install/share/man/man3/i2d_ESS_CERT_ID_V2.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ESS_CERT_ID_V2.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ESS_ISSUER_SERIAL.3ossl b/openssl-install/share/man/man3/i2d_ESS_ISSUER_SERIAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ESS_ISSUER_SERIAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT.3ossl b/openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT_V2.3ossl b/openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT_V2.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ESS_SIGNING_CERT_V2.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_EXTENDED_KEY_USAGE.3ossl b/openssl-install/share/man/man3/i2d_EXTENDED_KEY_USAGE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_EXTENDED_KEY_USAGE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_GENERAL_NAME.3ossl b/openssl-install/share/man/man3/i2d_GENERAL_NAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_GENERAL_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_GENERAL_NAMES.3ossl b/openssl-install/share/man/man3/i2d_GENERAL_NAMES.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_GENERAL_NAMES.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_IPAddressChoice.3ossl b/openssl-install/share/man/man3/i2d_IPAddressChoice.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_IPAddressChoice.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_IPAddressFamily.3ossl b/openssl-install/share/man/man3/i2d_IPAddressFamily.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_IPAddressFamily.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_IPAddressOrRange.3ossl b/openssl-install/share/man/man3/i2d_IPAddressOrRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_IPAddressOrRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_IPAddressRange.3ossl b/openssl-install/share/man/man3/i2d_IPAddressRange.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_IPAddressRange.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ISSUER_SIGN_TOOL.3ossl b/openssl-install/share/man/man3/i2d_ISSUER_SIGN_TOOL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ISSUER_SIGN_TOOL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_ISSUING_DIST_POINT.3ossl b/openssl-install/share/man/man3/i2d_ISSUING_DIST_POINT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_ISSUING_DIST_POINT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_KeyParams.3ossl b/openssl-install/share/man/man3/i2d_KeyParams.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/i2d_KeyParams.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_KeyParams_bio.3ossl b/openssl-install/share/man/man3/i2d_KeyParams_bio.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/i2d_KeyParams_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_NAMING_AUTHORITY.3ossl b/openssl-install/share/man/man3/i2d_NAMING_AUTHORITY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_NAMING_AUTHORITY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_NETSCAPE_CERT_SEQUENCE.3ossl b/openssl-install/share/man/man3/i2d_NETSCAPE_CERT_SEQUENCE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_NETSCAPE_CERT_SEQUENCE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_NETSCAPE_SPKAC.3ossl b/openssl-install/share/man/man3/i2d_NETSCAPE_SPKAC.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_NETSCAPE_SPKAC.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_NETSCAPE_SPKI.3ossl b/openssl-install/share/man/man3/i2d_NETSCAPE_SPKI.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_NETSCAPE_SPKI.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_NOTICEREF.3ossl b/openssl-install/share/man/man3/i2d_NOTICEREF.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_NOTICEREF.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_BASICRESP.3ossl b/openssl-install/share/man/man3/i2d_OCSP_BASICRESP.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_BASICRESP.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_CERTID.3ossl b/openssl-install/share/man/man3/i2d_OCSP_CERTID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_CERTID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_CERTSTATUS.3ossl b/openssl-install/share/man/man3/i2d_OCSP_CERTSTATUS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_CERTSTATUS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_CRLID.3ossl b/openssl-install/share/man/man3/i2d_OCSP_CRLID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_CRLID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_ONEREQ.3ossl b/openssl-install/share/man/man3/i2d_OCSP_ONEREQ.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_ONEREQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_REQINFO.3ossl b/openssl-install/share/man/man3/i2d_OCSP_REQINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_REQINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_REQUEST.3ossl b/openssl-install/share/man/man3/i2d_OCSP_REQUEST.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_REQUEST.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_RESPBYTES.3ossl b/openssl-install/share/man/man3/i2d_OCSP_RESPBYTES.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_RESPBYTES.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_RESPDATA.3ossl b/openssl-install/share/man/man3/i2d_OCSP_RESPDATA.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_RESPDATA.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_RESPID.3ossl b/openssl-install/share/man/man3/i2d_OCSP_RESPID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_RESPID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_RESPONSE.3ossl b/openssl-install/share/man/man3/i2d_OCSP_RESPONSE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_RESPONSE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_REVOKEDINFO.3ossl b/openssl-install/share/man/man3/i2d_OCSP_REVOKEDINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_REVOKEDINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_SERVICELOC.3ossl b/openssl-install/share/man/man3/i2d_OCSP_SERVICELOC.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_SERVICELOC.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_SIGNATURE.3ossl b/openssl-install/share/man/man3/i2d_OCSP_SIGNATURE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_SIGNATURE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OCSP_SINGLERESP.3ossl b/openssl-install/share/man/man3/i2d_OCSP_SINGLERESP.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OCSP_SINGLERESP.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_ATTRIBUTES_SYNTAX.3ossl b/openssl-install/share/man/man3/i2d_OSSL_ATTRIBUTES_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_ATTRIBUTES_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl b/openssl-install/share/man/man3/i2d_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_BASIC_ATTR_CONSTRAINTS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CMP_ATAVS.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CMP_ATAVS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CMP_ATAVS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CMP_MSG.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CMP_MSG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CMP_MSG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CMP_MSG_bio.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CMP_MSG_bio.3ossl deleted file mode 120000 index e2f83fa8..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CMP_MSG_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -OSSL_CMP_MSG_get0_header.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CMP_PKIHEADER.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CMP_PKIHEADER.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CMP_PKIHEADER.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CMP_PKISI.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CMP_PKISI.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CMP_PKISI.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTID.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTTEMPLATE.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTTEMPLATE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_CERTTEMPLATE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_ENCRYPTEDVALUE.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_ENCRYPTEDVALUE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_ENCRYPTEDVALUE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_MSG.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_MSG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_MSG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_MSGS.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_MSGS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_MSGS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_PBMPARAMETER.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_PBMPARAMETER.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_PBMPARAMETER.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_PKIPUBLICATIONINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_CRMF_SINGLEPUBINFO.3ossl b/openssl-install/share/man/man3/i2d_OSSL_CRMF_SINGLEPUBINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_CRMF_SINGLEPUBINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_IETF_ATTR_SYNTAX.3ossl b/openssl-install/share/man/man3/i2d_OSSL_IETF_ATTR_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_IETF_ATTR_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_ISSUER_SERIAL.3ossl b/openssl-install/share/man/man3/i2d_OSSL_ISSUER_SERIAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_ISSUER_SERIAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_OBJECT_DIGEST_INFO.3ossl b/openssl-install/share/man/man3/i2d_OSSL_OBJECT_DIGEST_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_OBJECT_DIGEST_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_TARGET.3ossl b/openssl-install/share/man/man3/i2d_OSSL_TARGET.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_TARGET.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_TARGETING_INFORMATION.3ossl b/openssl-install/share/man/man3/i2d_OSSL_TARGETING_INFORMATION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_TARGETING_INFORMATION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_TARGETS.3ossl b/openssl-install/share/man/man3/i2d_OSSL_TARGETS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_TARGETS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_TARGET_CERT.3ossl b/openssl-install/share/man/man3/i2d_OSSL_TARGET_CERT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_TARGET_CERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OSSL_USER_NOTICE_SYNTAX.3ossl b/openssl-install/share/man/man3/i2d_OSSL_USER_NOTICE_SYNTAX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OSSL_USER_NOTICE_SYNTAX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_OTHERNAME.3ossl b/openssl-install/share/man/man3/i2d_OTHERNAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_OTHERNAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PBE2PARAM.3ossl b/openssl-install/share/man/man3/i2d_PBE2PARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PBE2PARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PBEPARAM.3ossl b/openssl-install/share/man/man3/i2d_PBEPARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PBEPARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PBKDF2PARAM.3ossl b/openssl-install/share/man/man3/i2d_PBKDF2PARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PBKDF2PARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PBMAC1PARAM.3ossl b/openssl-install/share/man/man3/i2d_PBMAC1PARAM.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PBMAC1PARAM.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS12.3ossl b/openssl-install/share/man/man3/i2d_PKCS12.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS12.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS12_BAGS.3ossl b/openssl-install/share/man/man3/i2d_PKCS12_BAGS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS12_BAGS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS12_MAC_DATA.3ossl b/openssl-install/share/man/man3/i2d_PKCS12_MAC_DATA.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS12_MAC_DATA.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS12_SAFEBAG.3ossl b/openssl-install/share/man/man3/i2d_PKCS12_SAFEBAG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS12_SAFEBAG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS12_bio.3ossl b/openssl-install/share/man/man3/i2d_PKCS12_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS12_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS12_fp.3ossl b/openssl-install/share/man/man3/i2d_PKCS12_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS12_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7.3ossl b/openssl-install/share/man/man3/i2d_PKCS7.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_DIGEST.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_DIGEST.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_DIGEST.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_ENCRYPT.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_ENCRYPT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_ENCRYPT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_ENC_CONTENT.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_ENC_CONTENT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_ENC_CONTENT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_ENVELOPE.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_ENVELOPE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_ENVELOPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_ISSUER_AND_SERIAL.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_ISSUER_AND_SERIAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_ISSUER_AND_SERIAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_NDEF.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_NDEF.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_NDEF.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_RECIP_INFO.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_RECIP_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_RECIP_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_SIGNED.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_SIGNED.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_SIGNED.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_SIGNER_INFO.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_SIGNER_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_SIGNER_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_SIGN_ENVELOPE.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_SIGN_ENVELOPE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_SIGN_ENVELOPE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_bio.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS7_bio_stream.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_bio_stream.3ossl deleted file mode 100644 index 5d1c3d4e..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_bio_stream.3ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "I2D_PKCS7_BIO_STREAM 3ossl" -.TH I2D_PKCS7_BIO_STREAM 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -i2d_PKCS7_bio_stream \- output PKCS7 structure in BER format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& int i2d_PKCS7_bio_stream(BIO *out, PKCS7 *p7, BIO *data, int flags); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fBi2d_PKCS7_bio_stream()\fR outputs a \s-1PKCS7\s0 structure in \s-1BER\s0 format. -.PP -It is otherwise identical to the function \fBSMIME_write_PKCS7()\fR. -.SH "NOTES" -.IX Header "NOTES" -This function is effectively a version of the \fBd2i_PKCS7_bio()\fR supporting -streaming. -.SH "BUGS" -.IX Header "BUGS" -The prefix \*(L"i2d\*(R" is arguably wrong because the function outputs \s-1BER\s0 format. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBi2d_PKCS7_bio_stream()\fR returns 1 for success or 0 for failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3), \fBPKCS7_sign\fR\|(3), -\&\fBPKCS7_verify\fR\|(3), \fBPKCS7_encrypt\fR\|(3) -\&\fBPKCS7_decrypt\fR\|(3), -\&\fBSMIME_write_PKCS7\fR\|(3), -\&\fBPEM_write_bio_PKCS7_stream\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \fBi2d_PKCS7_bio_stream()\fR function was added in OpenSSL 1.0.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2008\-2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/i2d_PKCS7_fp.3ossl b/openssl-install/share/man/man3/i2d_PKCS7_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS7_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_bio.3ossl b/openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_fp.3ossl b/openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8PrivateKeyInfo_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_bio.3ossl b/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_bio.3ossl deleted file mode 120000 index 082536d2..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PKCS8PrivateKey_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_fp.3ossl b/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_fp.3ossl deleted file mode 120000 index 082536d2..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PKCS8PrivateKey_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_bio.3ossl b/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_bio.3ossl deleted file mode 120000 index 082536d2..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PKCS8PrivateKey_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_fp.3ossl b/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_fp.3ossl deleted file mode 120000 index 082536d2..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8PrivateKey_nid_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PKCS8PrivateKey_bio.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO.3ossl b/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_bio.3ossl b/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_fp.3ossl b/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8_PRIV_KEY_INFO_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8_bio.3ossl b/openssl-install/share/man/man3/i2d_PKCS8_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKCS8_fp.3ossl b/openssl-install/share/man/man3/i2d_PKCS8_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKCS8_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PKEY_USAGE_PERIOD.3ossl b/openssl-install/share/man/man3/i2d_PKEY_USAGE_PERIOD.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PKEY_USAGE_PERIOD.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_POLICYINFO.3ossl b/openssl-install/share/man/man3/i2d_POLICYINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_POLICYINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_POLICYQUALINFO.3ossl b/openssl-install/share/man/man3/i2d_POLICYQUALINFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_POLICYQUALINFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PROFESSION_INFO.3ossl b/openssl-install/share/man/man3/i2d_PROFESSION_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PROFESSION_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PROXY_CERT_INFO_EXTENSION.3ossl b/openssl-install/share/man/man3/i2d_PROXY_CERT_INFO_EXTENSION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PROXY_CERT_INFO_EXTENSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PROXY_POLICY.3ossl b/openssl-install/share/man/man3/i2d_PROXY_POLICY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_PROXY_POLICY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PUBKEY.3ossl b/openssl-install/share/man/man3/i2d_PUBKEY.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/i2d_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/i2d_PUBKEY_bio.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/i2d_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/i2d_PUBKEY_fp.3ossl deleted file mode 120000 index 4bf063ff..00000000 --- a/openssl-install/share/man/man3/i2d_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -X509_PUBKEY_new.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PrivateKey.3ossl b/openssl-install/share/man/man3/i2d_PrivateKey.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/i2d_PrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PrivateKey_bio.3ossl b/openssl-install/share/man/man3/i2d_PrivateKey_bio.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/i2d_PrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PrivateKey_fp.3ossl b/openssl-install/share/man/man3/i2d_PrivateKey_fp.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/i2d_PrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_PublicKey.3ossl b/openssl-install/share/man/man3/i2d_PublicKey.3ossl deleted file mode 120000 index 77c86e78..00000000 --- a/openssl-install/share/man/man3/i2d_PublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSAPrivateKey.3ossl b/openssl-install/share/man/man3/i2d_RSAPrivateKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSAPrivateKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSAPrivateKey_bio.3ossl b/openssl-install/share/man/man3/i2d_RSAPrivateKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSAPrivateKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSAPrivateKey_fp.3ossl b/openssl-install/share/man/man3/i2d_RSAPrivateKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSAPrivateKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSAPublicKey.3ossl b/openssl-install/share/man/man3/i2d_RSAPublicKey.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSAPublicKey.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSAPublicKey_bio.3ossl b/openssl-install/share/man/man3/i2d_RSAPublicKey_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSAPublicKey_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSAPublicKey_fp.3ossl b/openssl-install/share/man/man3/i2d_RSAPublicKey_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSAPublicKey_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSA_OAEP_PARAMS.3ossl b/openssl-install/share/man/man3/i2d_RSA_OAEP_PARAMS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_RSA_OAEP_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSA_PSS_PARAMS.3ossl b/openssl-install/share/man/man3/i2d_RSA_PSS_PARAMS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_RSA_PSS_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSA_PUBKEY.3ossl b/openssl-install/share/man/man3/i2d_RSA_PUBKEY.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSA_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSA_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/i2d_RSA_PUBKEY_bio.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSA_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_RSA_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/i2d_RSA_PUBKEY_fp.3ossl deleted file mode 120000 index bef83ee9..00000000 --- a/openssl-install/share/man/man3/i2d_RSA_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_RSAPrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_SCRYPT_PARAMS.3ossl b/openssl-install/share/man/man3/i2d_SCRYPT_PARAMS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_SCRYPT_PARAMS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_SCT_LIST.3ossl b/openssl-install/share/man/man3/i2d_SCT_LIST.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_SCT_LIST.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_SSL_SESSION.3ossl b/openssl-install/share/man/man3/i2d_SSL_SESSION.3ossl deleted file mode 120000 index 05f96010..00000000 --- a/openssl-install/share/man/man3/i2d_SSL_SESSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_SSL_SESSION.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_SXNET.3ossl b/openssl-install/share/man/man3/i2d_SXNET.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_SXNET.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_SXNETID.3ossl b/openssl-install/share/man/man3/i2d_SXNETID.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_SXNETID.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_ACCURACY.3ossl b/openssl-install/share/man/man3/i2d_TS_ACCURACY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_ACCURACY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT.3ossl b/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_bio.3ossl b/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_fp.3ossl b/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_MSG_IMPRINT_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_REQ.3ossl b/openssl-install/share/man/man3/i2d_TS_REQ.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_REQ_bio.3ossl b/openssl-install/share/man/man3/i2d_TS_REQ_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_REQ_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_REQ_fp.3ossl b/openssl-install/share/man/man3/i2d_TS_REQ_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_REQ_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_RESP.3ossl b/openssl-install/share/man/man3/i2d_TS_RESP.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_RESP.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_RESP_bio.3ossl b/openssl-install/share/man/man3/i2d_TS_RESP_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_RESP_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_RESP_fp.3ossl b/openssl-install/share/man/man3/i2d_TS_RESP_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_RESP_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_STATUS_INFO.3ossl b/openssl-install/share/man/man3/i2d_TS_STATUS_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_STATUS_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_TST_INFO.3ossl b/openssl-install/share/man/man3/i2d_TS_TST_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_TST_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_TST_INFO_bio.3ossl b/openssl-install/share/man/man3/i2d_TS_TST_INFO_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_TST_INFO_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_TS_TST_INFO_fp.3ossl b/openssl-install/share/man/man3/i2d_TS_TST_INFO_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_TS_TST_INFO_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_USERNOTICE.3ossl b/openssl-install/share/man/man3/i2d_USERNOTICE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_USERNOTICE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509.3ossl b/openssl-install/share/man/man3/i2d_X509.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_ACERT.3ossl b/openssl-install/share/man/man3/i2d_X509_ACERT.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_ACERT.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_ACERT_bio.3ossl b/openssl-install/share/man/man3/i2d_X509_ACERT_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_ACERT_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_ACERT_fp.3ossl b/openssl-install/share/man/man3/i2d_X509_ACERT_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_ACERT_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_ALGOR.3ossl b/openssl-install/share/man/man3/i2d_X509_ALGOR.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_ALGOR.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_ALGORS.3ossl b/openssl-install/share/man/man3/i2d_X509_ALGORS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_ALGORS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_ATTRIBUTE.3ossl b/openssl-install/share/man/man3/i2d_X509_ATTRIBUTE.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_ATTRIBUTE.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_AUX.3ossl b/openssl-install/share/man/man3/i2d_X509_AUX.3ossl deleted file mode 120000 index 91b802a5..00000000 --- a/openssl-install/share/man/man3/i2d_X509_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -i2d_re_X509_tbs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_CERT_AUX.3ossl b/openssl-install/share/man/man3/i2d_X509_CERT_AUX.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_CERT_AUX.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_CINF.3ossl b/openssl-install/share/man/man3/i2d_X509_CINF.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_CINF.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_CRL.3ossl b/openssl-install/share/man/man3/i2d_X509_CRL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_CRL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_CRL_INFO.3ossl b/openssl-install/share/man/man3/i2d_X509_CRL_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_CRL_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_CRL_bio.3ossl b/openssl-install/share/man/man3/i2d_X509_CRL_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_CRL_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_CRL_fp.3ossl b/openssl-install/share/man/man3/i2d_X509_CRL_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_CRL_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_EXTENSION.3ossl b/openssl-install/share/man/man3/i2d_X509_EXTENSION.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_EXTENSION.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_EXTENSIONS.3ossl b/openssl-install/share/man/man3/i2d_X509_EXTENSIONS.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_EXTENSIONS.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_NAME.3ossl b/openssl-install/share/man/man3/i2d_X509_NAME.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_NAME.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_NAME_ENTRY.3ossl b/openssl-install/share/man/man3/i2d_X509_NAME_ENTRY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_NAME_ENTRY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_PUBKEY.3ossl b/openssl-install/share/man/man3/i2d_X509_PUBKEY.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_PUBKEY.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_PUBKEY_bio.3ossl b/openssl-install/share/man/man3/i2d_X509_PUBKEY_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_PUBKEY_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_PUBKEY_fp.3ossl b/openssl-install/share/man/man3/i2d_X509_PUBKEY_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_PUBKEY_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_REQ.3ossl b/openssl-install/share/man/man3/i2d_X509_REQ.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_REQ.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_REQ_INFO.3ossl b/openssl-install/share/man/man3/i2d_X509_REQ_INFO.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_REQ_INFO.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_REQ_bio.3ossl b/openssl-install/share/man/man3/i2d_X509_REQ_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_REQ_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_REQ_fp.3ossl b/openssl-install/share/man/man3/i2d_X509_REQ_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_REQ_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_REVOKED.3ossl b/openssl-install/share/man/man3/i2d_X509_REVOKED.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_REVOKED.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_SIG.3ossl b/openssl-install/share/man/man3/i2d_X509_SIG.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_SIG.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_VAL.3ossl b/openssl-install/share/man/man3/i2d_X509_VAL.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_VAL.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_bio.3ossl b/openssl-install/share/man/man3/i2d_X509_bio.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_bio.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_X509_fp.3ossl b/openssl-install/share/man/man3/i2d_X509_fp.3ossl deleted file mode 120000 index 53f0e953..00000000 --- a/openssl-install/share/man/man3/i2d_X509_fp.3ossl +++ /dev/null @@ -1 +0,0 @@ -d2i_X509.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_re_X509_CRL_tbs.3ossl b/openssl-install/share/man/man3/i2d_re_X509_CRL_tbs.3ossl deleted file mode 120000 index 91b802a5..00000000 --- a/openssl-install/share/man/man3/i2d_re_X509_CRL_tbs.3ossl +++ /dev/null @@ -1 +0,0 @@ -i2d_re_X509_tbs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_re_X509_REQ_tbs.3ossl b/openssl-install/share/man/man3/i2d_re_X509_REQ_tbs.3ossl deleted file mode 120000 index 91b802a5..00000000 --- a/openssl-install/share/man/man3/i2d_re_X509_REQ_tbs.3ossl +++ /dev/null @@ -1 +0,0 @@ -i2d_re_X509_tbs.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2d_re_X509_tbs.3ossl b/openssl-install/share/man/man3/i2d_re_X509_tbs.3ossl deleted file mode 100644 index 17d24a0f..00000000 --- a/openssl-install/share/man/man3/i2d_re_X509_tbs.3ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "I2D_RE_X509_TBS 3ossl" -.TH I2D_RE_X509_TBS 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -d2i_X509_AUX, i2d_X509_AUX, -i2d_re_X509_tbs, i2d_re_X509_CRL_tbs, i2d_re_X509_REQ_tbs -\&\- X509 encode and decode functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& X509 *d2i_X509_AUX(X509 **px, const unsigned char **in, long len); -\& int i2d_X509_AUX(const X509 *x, unsigned char **out); -\& int i2d_re_X509_tbs(X509 *x, unsigned char **out); -\& int i2d_re_X509_CRL_tbs(X509_CRL *crl, unsigned char **pp); -\& int i2d_re_X509_REQ_tbs(X509_REQ *req, unsigned char **pp); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The X509 encode and decode routines encode and parse an -\&\fBX509\fR structure, which represents an X509 certificate. -.PP -\&\fBd2i_X509_AUX()\fR is similar to \fBd2i_X509\fR\|(3) but the input is expected to -consist of an X509 certificate followed by auxiliary trust information. -This is used by the \s-1PEM\s0 routines to read \*(L"\s-1TRUSTED CERTIFICATE\*(R"\s0 objects. -This function should not be called on untrusted input. -.PP -\&\fBi2d_X509_AUX()\fR is similar to \fBi2d_X509\fR\|(3), but the encoded output -contains both the certificate and any auxiliary trust information. -This is used by the \s-1PEM\s0 routines to write \*(L"\s-1TRUSTED CERTIFICATE\*(R"\s0 objects. -Note that this is a non-standard OpenSSL-specific data format. -.PP -\&\fBi2d_re_X509_tbs()\fR is similar to \fBi2d_X509\fR\|(3) except it encodes only -the TBSCertificate portion of the certificate. \fBi2d_re_X509_CRL_tbs()\fR -and \fBi2d_re_X509_REQ_tbs()\fR are analogous for \s-1CRL\s0 and certificate request, -respectively. The \*(L"re\*(R" in \fBi2d_re_X509_tbs\fR stands for \*(L"re-encode\*(R", -and ensures that a fresh encoding is generated in case the object has been -modified after creation (see the \s-1BUGS\s0 section). -.PP -The encoding of the TBSCertificate portion of a certificate is cached -in the \fBX509\fR structure internally to improve encoding performance -and to ensure certificate signatures are verified correctly in some -certificates with broken (non-DER) encodings. -.PP -If, after modification, the \fBX509\fR object is re-signed with \fBX509_sign()\fR, -the encoding is automatically renewed. Otherwise, the encoding of the -TBSCertificate portion of the \fBX509\fR can be manually renewed by calling -\&\fBi2d_re_X509_tbs()\fR. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBd2i_X509_AUX()\fR returns a valid \fBX509\fR structure or \s-1NULL\s0 if an error occurred. -.PP -\&\fBi2d_X509_AUX()\fR returns the length of encoded data or \-1 on error. -.PP -\&\fBi2d_re_X509_tbs()\fR, \fBi2d_re_X509_CRL_tbs()\fR and \fBi2d_re_X509_REQ_tbs()\fR return the -length of encoded data or <=0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBERR_get_error\fR\|(3) -\&\fBX509_CRL_get0_by_serial\fR\|(3), -\&\fBX509_get0_signature\fR\|(3), -\&\fBX509_get_ext_d2i\fR\|(3), -\&\fBX509_get_extension_flags\fR\|(3), -\&\fBX509_get_pubkey\fR\|(3), -\&\fBX509_get_subject_name\fR\|(3), -\&\fBX509_get_version\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_get_index_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_new\fR\|(3), -\&\fBX509_sign\fR\|(3), -\&\fBX509V3_get_d2i\fR\|(3), -\&\fBX509_verify_cert\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2002\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/i2o_SCT.3ossl b/openssl-install/share/man/man3/i2o_SCT.3ossl deleted file mode 120000 index 9a0d7aab..00000000 --- a/openssl-install/share/man/man3/i2o_SCT.3ossl +++ /dev/null @@ -1 +0,0 @@ -o2i_SCT_LIST.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2o_SCT_LIST.3ossl b/openssl-install/share/man/man3/i2o_SCT_LIST.3ossl deleted file mode 120000 index 9a0d7aab..00000000 --- a/openssl-install/share/man/man3/i2o_SCT_LIST.3ossl +++ /dev/null @@ -1 +0,0 @@ -o2i_SCT_LIST.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2s_ASN1_ENUMERATED.3ossl b/openssl-install/share/man/man3/i2s_ASN1_ENUMERATED.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/i2s_ASN1_ENUMERATED.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2s_ASN1_ENUMERATED_TABLE.3ossl b/openssl-install/share/man/man3/i2s_ASN1_ENUMERATED_TABLE.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/i2s_ASN1_ENUMERATED_TABLE.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2s_ASN1_IA5STRING.3ossl b/openssl-install/share/man/man3/i2s_ASN1_IA5STRING.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/i2s_ASN1_IA5STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2s_ASN1_INTEGER.3ossl b/openssl-install/share/man/man3/i2s_ASN1_INTEGER.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/i2s_ASN1_INTEGER.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2s_ASN1_OCTET_STRING.3ossl b/openssl-install/share/man/man3/i2s_ASN1_OCTET_STRING.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/i2s_ASN1_OCTET_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2s_ASN1_UTF8STRING.3ossl b/openssl-install/share/man/man3/i2s_ASN1_UTF8STRING.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/i2s_ASN1_UTF8STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/i2t_ASN1_OBJECT.3ossl b/openssl-install/share/man/man3/i2t_ASN1_OBJECT.3ossl deleted file mode 120000 index deea29f6..00000000 --- a/openssl-install/share/man/man3/i2t_ASN1_OBJECT.3ossl +++ /dev/null @@ -1 +0,0 @@ -OBJ_nid2obj.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_delete.3ossl b/openssl-install/share/man/man3/lh_TYPE_delete.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_delete.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_doall.3ossl b/openssl-install/share/man/man3/lh_TYPE_doall.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_doall.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_doall_arg.3ossl b/openssl-install/share/man/man3/lh_TYPE_doall_arg.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_doall_arg.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_error.3ossl b/openssl-install/share/man/man3/lh_TYPE_error.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_error.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_flush.3ossl b/openssl-install/share/man/man3/lh_TYPE_flush.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_flush.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_free.3ossl b/openssl-install/share/man/man3/lh_TYPE_free.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_get_down_load.3ossl b/openssl-install/share/man/man3/lh_TYPE_get_down_load.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_get_down_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_insert.3ossl b/openssl-install/share/man/man3/lh_TYPE_insert.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_insert.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_new.3ossl b/openssl-install/share/man/man3/lh_TYPE_new.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_num_items.3ossl b/openssl-install/share/man/man3/lh_TYPE_num_items.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_num_items.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_retrieve.3ossl b/openssl-install/share/man/man3/lh_TYPE_retrieve.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_retrieve.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/lh_TYPE_set_down_load.3ossl b/openssl-install/share/man/man3/lh_TYPE_set_down_load.3ossl deleted file mode 120000 index de274842..00000000 --- a/openssl-install/share/man/man3/lh_TYPE_set_down_load.3ossl +++ /dev/null @@ -1 +0,0 @@ -OPENSSL_LH_COMPFUNC.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/o2i_SCT.3ossl b/openssl-install/share/man/man3/o2i_SCT.3ossl deleted file mode 120000 index 9a0d7aab..00000000 --- a/openssl-install/share/man/man3/o2i_SCT.3ossl +++ /dev/null @@ -1 +0,0 @@ -o2i_SCT_LIST.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/o2i_SCT_LIST.3ossl b/openssl-install/share/man/man3/o2i_SCT_LIST.3ossl deleted file mode 100644 index 45c53894..00000000 --- a/openssl-install/share/man/man3/o2i_SCT_LIST.3ossl +++ /dev/null @@ -1,180 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "O2I_SCT_LIST 3ossl" -.TH O2I_SCT_LIST 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -o2i_SCT_LIST, i2o_SCT_LIST, o2i_SCT, i2o_SCT \- -decode and encode Signed Certificate Timestamp lists in TLS wire format -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& STACK_OF(SCT) *o2i_SCT_LIST(STACK_OF(SCT) **a, const unsigned char **pp, -\& size_t len); -\& int i2o_SCT_LIST(const STACK_OF(SCT) *a, unsigned char **pp); -\& SCT *o2i_SCT(SCT **psct, const unsigned char **in, size_t len); -\& int i2o_SCT(const SCT *sct, unsigned char **out); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1SCT_LIST\s0 and \s-1SCT\s0 functions are very similar to the i2d and d2i family of -functions, except that they convert to and from \s-1TLS\s0 wire format, as described in -\&\s-1RFC 6962.\s0 See \fBd2i_SCT_LIST\fR\|(3) for more information about how the parameters are -treated and the return values. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -All of the functions have return values consistent with those stated for -\&\fBd2i_SCT_LIST\fR\|(3) and \fBi2d_SCT_LIST\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBct\fR\|(7), -\&\fBd2i_SCT_LIST\fR\|(3), -\&\fBi2d_SCT_LIST\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -These functions were added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/pem_password_cb.3ossl b/openssl-install/share/man/man3/pem_password_cb.3ossl deleted file mode 120000 index e13d21fb..00000000 --- a/openssl-install/share/man/man3/pem_password_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -PEM_read_bio_PrivateKey.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/s2i_ASN1_IA5STRING.3ossl b/openssl-install/share/man/man3/s2i_ASN1_IA5STRING.3ossl deleted file mode 100644 index 7f4969cc..00000000 --- a/openssl-install/share/man/man3/s2i_ASN1_IA5STRING.3ossl +++ /dev/null @@ -1,230 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "S2I_ASN1_IA5STRING 3ossl" -.TH S2I_ASN1_IA5STRING 3ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -i2s_ASN1_IA5STRING, -s2i_ASN1_IA5STRING, -i2s_ASN1_INTEGER, -s2i_ASN1_INTEGER, -i2s_ASN1_OCTET_STRING, -s2i_ASN1_OCTET_STRING, -i2s_ASN1_ENUMERATED, -i2s_ASN1_ENUMERATED_TABLE, -i2s_ASN1_UTF8STRING, -s2i_ASN1_UTF8STRING -\&\- convert objects from/to ASN.1/string representation -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& char *i2s_ASN1_IA5STRING(X509V3_EXT_METHOD *method, ASN1_IA5STRING *ia5); -\& ASN1_IA5STRING *s2i_ASN1_IA5STRING(X509V3_EXT_METHOD *method, -\& X509V3_CTX *ctx, const char *str); -\& char *i2s_ASN1_INTEGER(X509V3_EXT_METHOD *method, const ASN1_INTEGER *a); -\& ASN1_INTEGER *s2i_ASN1_INTEGER(X509V3_EXT_METHOD *method, const char *value); -\& char *i2s_ASN1_OCTET_STRING(X509V3_EXT_METHOD *method, -\& const ASN1_OCTET_STRING *oct); -\& ASN1_OCTET_STRING *s2i_ASN1_OCTET_STRING(X509V3_EXT_METHOD *method, -\& X509V3_CTX *ctx, const char *str); -\& char *i2s_ASN1_ENUMERATED(X509V3_EXT_METHOD *method, const ASN1_ENUMERATED *a); -\& char *i2s_ASN1_ENUMERATED_TABLE(X509V3_EXT_METHOD *method, -\& const ASN1_ENUMERATED *e); -\& -\& char *i2s_ASN1_UTF8STRING(X509V3_EXT_METHOD *method, -\& ASN1_UTF8STRING *utf8); -\& ASN1_UTF8STRING *s2i_ASN1_UTF8STRING(X509V3_EXT_METHOD *method, -\& X509V3_CTX *ctx, const char *str); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -These functions convert OpenSSL objects to and from their \s-1ASN\s0.1/string -representation. This function is used for \fBX509v3\fR extensions. -.SH "NOTES" -.IX Header "NOTES" -The letters \fBi\fR and \fBs\fR in \fBi2s\fR and \fBs2i\fR stand for -\&\*(L"internal\*(R" (that is, an internal C structure) and string respectively. -So \fBi2s_ASN1_IA5STRING\fR() converts from internal to string. -.PP -It is the caller's responsibility to free the returned string. -In the \fBi2s_ASN1_IA5STRING\fR() function the string is copied and -the ownership of the original string remains with the caller. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBi2s_ASN1_IA5STRING\fR() returns the pointer to a \s-1IA5\s0 string -or \s-1NULL\s0 if an error occurs. -.PP -\&\fBs2i_ASN1_IA5STRING\fR() return a valid -\&\fB\s-1ASN1_IA5STRING\s0\fR structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBi2s_ASN1_INTEGER\fR() return a valid -string or \s-1NULL\s0 if an error occurs. -.PP -\&\fBs2i_ASN1_INTEGER\fR() returns the pointer to a \fB\s-1ASN1_INTEGER\s0\fR -structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBi2s_ASN1_OCTET_STRING\fR() returns the pointer to a \s-1OCTET_STRING\s0 string -or \s-1NULL\s0 if an error occurs. -.PP -\&\fBs2i_ASN1_OCTET_STRING\fR() return a valid -\&\fB\s-1ASN1_OCTET_STRING\s0\fR structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBi2s_ASN1_ENUMERATED\fR() return a valid -string or \s-1NULL\s0 if an error occurs. -.PP -\&\fBs2i_ASN1_ENUMERATED\fR() returns the pointer to a \fB\s-1ASN1_ENUMERATED\s0\fR -structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBs2i_ASN1_UTF8STRING\fR() return a valid -\&\fB\s-1ASN1_UTF8STRING\s0\fR structure or \s-1NULL\s0 if an error occurs. -.PP -\&\fBi2s_ASN1_UTF8STRING\fR() returns the pointer to a \s-1UTF\-8\s0 string -or \s-1NULL\s0 if an error occurs. -.SH "HISTORY" -.IX Header "HISTORY" -\&\fBi2s_ASN1_UTF8STRING()\fR and \fBs2i_ASN1_UTF8STRING()\fR were made public in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man3/s2i_ASN1_INTEGER.3ossl b/openssl-install/share/man/man3/s2i_ASN1_INTEGER.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/s2i_ASN1_INTEGER.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/s2i_ASN1_OCTET_STRING.3ossl b/openssl-install/share/man/man3/s2i_ASN1_OCTET_STRING.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/s2i_ASN1_OCTET_STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/s2i_ASN1_UTF8STRING.3ossl b/openssl-install/share/man/man3/s2i_ASN1_UTF8STRING.3ossl deleted file mode 120000 index 0c78be46..00000000 --- a/openssl-install/share/man/man3/s2i_ASN1_UTF8STRING.3ossl +++ /dev/null @@ -1 +0,0 @@ -s2i_ASN1_IA5STRING.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_deep_copy.3ossl b/openssl-install/share/man/man3/sk_TYPE_deep_copy.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_deep_copy.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_delete.3ossl b/openssl-install/share/man/man3/sk_TYPE_delete.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_delete.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_delete_ptr.3ossl b/openssl-install/share/man/man3/sk_TYPE_delete_ptr.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_delete_ptr.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_dup.3ossl b/openssl-install/share/man/man3/sk_TYPE_dup.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_dup.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_find.3ossl b/openssl-install/share/man/man3/sk_TYPE_find.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_find.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_find_all.3ossl b/openssl-install/share/man/man3/sk_TYPE_find_all.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_find_all.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_find_ex.3ossl b/openssl-install/share/man/man3/sk_TYPE_find_ex.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_find_ex.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_free.3ossl b/openssl-install/share/man/man3/sk_TYPE_free.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_insert.3ossl b/openssl-install/share/man/man3/sk_TYPE_insert.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_insert.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_is_sorted.3ossl b/openssl-install/share/man/man3/sk_TYPE_is_sorted.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_is_sorted.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_new.3ossl b/openssl-install/share/man/man3/sk_TYPE_new.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_new.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_new_null.3ossl b/openssl-install/share/man/man3/sk_TYPE_new_null.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_new_null.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_new_reserve.3ossl b/openssl-install/share/man/man3/sk_TYPE_new_reserve.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_new_reserve.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_num.3ossl b/openssl-install/share/man/man3/sk_TYPE_num.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_num.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_pop.3ossl b/openssl-install/share/man/man3/sk_TYPE_pop.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_pop.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_pop_free.3ossl b/openssl-install/share/man/man3/sk_TYPE_pop_free.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_pop_free.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_push.3ossl b/openssl-install/share/man/man3/sk_TYPE_push.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_push.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_reserve.3ossl b/openssl-install/share/man/man3/sk_TYPE_reserve.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_reserve.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_set.3ossl b/openssl-install/share/man/man3/sk_TYPE_set.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_set.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_set_cmp_func.3ossl b/openssl-install/share/man/man3/sk_TYPE_set_cmp_func.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_set_cmp_func.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_shift.3ossl b/openssl-install/share/man/man3/sk_TYPE_shift.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_shift.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_sort.3ossl b/openssl-install/share/man/man3/sk_TYPE_sort.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_sort.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_unshift.3ossl b/openssl-install/share/man/man3/sk_TYPE_unshift.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_unshift.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_value.3ossl b/openssl-install/share/man/man3/sk_TYPE_value.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_value.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/sk_TYPE_zero.3ossl b/openssl-install/share/man/man3/sk_TYPE_zero.3ossl deleted file mode 120000 index eb0827ae..00000000 --- a/openssl-install/share/man/man3/sk_TYPE_zero.3ossl +++ /dev/null @@ -1 +0,0 @@ -DEFINE_STACK_OF.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/ssl_ct_validation_cb.3ossl b/openssl-install/share/man/man3/ssl_ct_validation_cb.3ossl deleted file mode 120000 index 08be3b02..00000000 --- a/openssl-install/share/man/man3/ssl_ct_validation_cb.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_CTX_set_ct_validation_callback.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man3/tls_session_secret_cb_fn.3ossl b/openssl-install/share/man/man3/tls_session_secret_cb_fn.3ossl deleted file mode 120000 index bb67a334..00000000 --- a/openssl-install/share/man/man3/tls_session_secret_cb_fn.3ossl +++ /dev/null @@ -1 +0,0 @@ -SSL_set_session_secret_cb.3ossl \ No newline at end of file diff --git a/openssl-install/share/man/man5/config.5ossl b/openssl-install/share/man/man5/config.5ossl deleted file mode 100644 index c5406411..00000000 --- a/openssl-install/share/man/man5/config.5ossl +++ /dev/null @@ -1,721 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CONFIG 5ossl" -.TH CONFIG 5ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -config \- OpenSSL CONF library configuration files -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This page documents the syntax of OpenSSL configuration files, -as parsed by \fBNCONF_load\fR\|(3) and related functions. -This format is used by many of the OpenSSL commands, and to -initialize the libraries when used by any application. -.PP -The first part describes the general syntax of the configuration -files, and subsequent sections describe the semantics of individual -modules. Other modules are described in \fBfips_config\fR\|(5) and -\&\fBx509v3_config\fR\|(5). -The syntax for defining \s-1ASN.1\s0 values is described in -\&\fBASN1_generate_nconf\fR\|(3). -.SH "SYNTAX" -.IX Header "SYNTAX" -A configuration file is a series of lines. Blank lines, and whitespace -between the elements of a line, have no significance. A comment starts -with a \fB#\fR character; the rest of the line is ignored. If the \fB#\fR -is the first non-space character in a line, the entire line is ignored. -.SS "Directives" -.IX Subsection "Directives" -Two directives can be used to control the parsing of configuration files: -\&\fB.include\fR and \fB.pragma\fR. -.PP -For compatibility with older versions of OpenSSL, an equal sign after the -directive will be ignored. Older versions will treat it as an assignment, -so care should be taken if the difference in semantics is important. -.PP -A file can include other files using the include syntax: -.PP -.Vb 1 -\& .include [=] pathname -.Ve -.PP -If \fBpathname\fR is a simple filename, that file is included directly at -that point. Included files can have \fB.include\fR statements that specify -other files. If \fBpathname\fR is a directory, all files within that directory -that have a \f(CW\*(C`.cnf\*(C'\fR or \f(CW\*(C`.conf\*(C'\fR extension will be included. (This is only -available on systems with \s-1POSIX IO\s0 support.) Any sub-directories found -inside the \fBpathname\fR are \fBignored\fR. Similarly, if a file is opened -while scanning a directory, and that file has an \fB.include\fR directive -that specifies a directory, that is also ignored. -.PP -As a general rule, the \fBpathname\fR should be an absolute path; this can -be enforced with the \fBabspath\fR and \fBincludedir\fR pragmas, described below. -The environment variable \fB\s-1OPENSSL_CONF_INCLUDE\s0\fR, if it exists, -is prepended to all relative pathnames. -If the pathname is still relative, it is interpreted based on the -current working directory. -.PP -To require all file inclusions to name absolute paths, use the following -directive: -.PP -.Vb 1 -\& .pragma [=] abspath:value -.Ve -.PP -The default behavior, where the \fBvalue\fR is \fBfalse\fR or \fBoff\fR, is to allow -relative paths. To require all \fB.include\fR pathnames to be absolute paths, -use a \fBvalue\fR of \fBtrue\fR or \fBon\fR. -.PP -In these files, the dollar sign, \fB$\fR, is used to reference a variable, as -described below. On some platforms, however, it is common to treat \fB$\fR -as a regular character in symbol names. Supporting this behavior can be -done with the following directive: -.PP -.Vb 1 -\& .pragma [=] dollarid:value -.Ve -.PP -The default behavior, where the \fBvalue\fR is \fBfalse\fR or \fBoff\fR, is to treat -the dollarsign as indicating a variable name; \f(CW\*(C`foo$bar\*(C'\fR is interpreted as -\&\f(CW\*(C`foo\*(C'\fR followed by the expansion of the variable \f(CW\*(C`bar\*(C'\fR. If \fBvalue\fR is -\&\fBtrue\fR or \fBon\fR, then \f(CW\*(C`foo$bar\*(C'\fR is a single seven-character name and -variable expansions must be specified using braces or parentheses. -.PP -.Vb 1 -\& .pragma [=] includedir:value -.Ve -.PP -If a relative pathname is specified in the \fB.include\fR directive, and -the \fB\s-1OPENSSL_CONF_INCLUDE\s0\fR environment variable doesn't exist, then -the value of the \fBincludedir\fR pragma, if it exists, is prepended to the -pathname. -.SS "Settings" -.IX Subsection "Settings" -A configuration file is divided into a number of \fIsections\fR. A section -begins with the section name in square brackets, and ends when a new -section starts, or at the end of the file. The section name can consist -of alphanumeric characters and underscores. -Whitespace between the name and the brackets is removed. -.PP -The first section of a configuration file is special and is referred to -as the \fBdefault\fR section. This section is usually unnamed and spans from -the start of file until the first named section. When a name is being -looked up, it is first looked up in the current or named section, -and then the default section if necessary. -.PP -The environment is mapped onto a section called \fB\s-1ENV\s0\fR. -.PP -Within a section are a series of name/value assignments, described in more -detail below. As a reminder, the square brackets shown in this example -are required, not optional: -.PP -.Vb 7 -\& [ section ] -\& name1 = This is value1 -\& name2 = Another value -\& ... -\& [ newsection ] -\& name1 = New value1 -\& name3 = Value 3 -.Ve -.PP -The \fBname\fR can contain any alphanumeric characters as well as a few -punctuation symbols such as \fB.\fR \fB,\fR \fB;\fR and \fB_\fR. -Whitespace after the name and before the equal sign is ignored. -.PP -If a name is repeated in the same section, then all but the last -value are ignored. In certain circumstances, such as with -Certificate DNs, the same field may occur multiple times. -In order to support this, commands like \fBopenssl\-req\fR\|(1) ignore any -leading text that is preceded with a period. For example: -.PP -.Vb 2 -\& 1.OU = First OU -\& 2.OU = Second OU -.Ve -.PP -The \fBvalue\fR consists of the string following the \fB=\fR character until end -of line with any leading and trailing whitespace removed. -.PP -The value string undergoes variable expansion. The text \f(CW$var\fR or \f(CW\*(C`${var}\*(C'\fR -inserts the value of the named variable from the current section. -To use a value from another section use \f(CW$section::name\fR -or \f(CW\*(C`${section::name}\*(C'\fR. -By using \f(CW$ENV::name\fR, the value of the specified environment -variable will be substituted. -.PP -Variables must be defined before their value is referenced, otherwise -an error is flagged and the file will not load. -This can be worked around by specifying a default value in the \fBdefault\fR -section before the variable is used. -.PP -Any name/value settings in an \fB\s-1ENV\s0\fR section are available -to the configuration file, but are not propagated to the environment. -.PP -It is an error if the value ends up longer than 64k. -.PP -It is possible to escape certain characters by using a single \fB'\fR or -double \fB"\fR quote around the value, or using a backslash \fB\e\fR before the -character, -By making the last character of a line a \fB\e\fR -a \fBvalue\fR string can be spread across multiple lines. In addition -the sequences \fB\en\fR, \fB\er\fR, \fB\eb\fR and \fB\et\fR are recognized. -.PP -The expansion and escape rules as described above that apply to \fBvalue\fR -also apply to the pathname of the \fB.include\fR directive. -.SH "OPENSSL LIBRARY CONFIGURATION" -.IX Header "OPENSSL LIBRARY CONFIGURATION" -The sections below use the informal term \fImodule\fR to refer to a part -of the OpenSSL functionality. This is not the same as the formal term -\&\fI\s-1FIPS\s0 module\fR, for example. -.PP -The OpenSSL configuration looks up the value of \fBopenssl_conf\fR -in the default section and takes that as the name of a section that specifies -how to configure any modules in the library. It is not an error to leave -any module in its default configuration. An application can specify a -different name by calling \fBCONF_modules_load_file()\fR, for example, directly. -.PP -OpenSSL also looks up the value of \fBconfig_diagnostics\fR. -If this exists and has a nonzero numeric value, any error suppressing flags -passed to \fBCONF_modules_load()\fR will be ignored. -This is useful for diagnosing misconfigurations but its use in -production requires additional consideration. With this option enabled, -a configuration error will completely prevent access to a service. -Without this option and in the presence of a configuration error, access -will be allowed but the desired configuration will \fBnot\fR be used. -.PP -.Vb 3 -\& # These must be in the default section -\& config_diagnostics = 1 -\& openssl_conf = openssl_init -\& -\& [openssl_init] -\& oid_section = oids -\& providers = providers -\& alg_section = evp_properties -\& ssl_conf = ssl_configuration -\& engines = engines -\& random = random -\& -\& [oids] -\& ... new oids here ... -\& -\& [providers] -\& ... provider stuff here ... -\& -\& [evp_properties] -\& ... EVP properties here ... -\& -\& [ssl_configuration] -\& ... SSL/TLS configuration properties here ... -\& -\& [engines] -\& ... engine properties here ... -\& -\& [random] -\& ... random properties here ... -.Ve -.PP -The semantics of each module are described below. The phrase \*(L"in the -initialization section\*(R" refers to the section identified by the -\&\fBopenssl_conf\fR or other name (given as \fBopenssl_init\fR in the -example above). The examples below assume the configuration above -is used to specify the individual sections. -.SS "\s-1ASN.1\s0 Object Identifier Configuration" -.IX Subsection "ASN.1 Object Identifier Configuration" -The name \fBoid_section\fR in the initialization section names the section -containing name/value pairs of \s-1OID\s0's. -The name is the short name; the value is an optional long name followed -by a comma, and the numeric value. -While some OpenSSL commands have their own section for specifying \s-1OID\s0's, -this section makes them available to all commands and applications. -.PP -.Vb 4 -\& [oids] -\& shortName = a very long OID name, 1.2.3.4 -\& newoid1 = 1.2.3.4.1 -\& some_other_oid = 1.2.3.5 -.Ve -.PP -If a full configuration with the above fragment is in the file -\&\fIexample.cnf\fR, then the following command line: -.PP -.Vb 1 -\& OPENSSL_CONF=example.cnf openssl asn1parse \-genstr OID:1.2.3.4.1 -.Ve -.PP -will output: -.PP -.Vb 1 -\& 0:d=0 hl=2 l= 4 prim: OBJECT :newoid1 -.Ve -.PP -showing that the \s-1OID\s0 \*(L"newoid1\*(R" has been added as \*(L"1.2.3.4.1\*(R". -.SS "Provider Configuration" -.IX Subsection "Provider Configuration" -The name \fBproviders\fR in the initialization section names the section -containing cryptographic provider configuration. The name/value assignments -in this section each name a provider, and point to the configuration section -for that provider. The provider-specific section is used to specify how -to load the module, activate it, and set other parameters. -.PP -Within a provider section, the following names have meaning: -.IP "\fBidentity\fR" 4 -.IX Item "identity" -This is used to specify an alternate name, overriding the default name -specified in the list of providers. For example: -.Sp -.Vb 2 -\& [providers] -\& foo = foo_provider -\& -\& [foo_provider] -\& identity = my_fips_module -.Ve -.IP "\fBmodule\fR" 4 -.IX Item "module" -Specifies the pathname of the module (typically a shared library) to load. -.IP "\fBactivate\fR" 4 -.IX Item "activate" -If present and set to one of the values yes, on, true or 1, then the associated -provider will be activated. Conversely, setting this value to no, off, false, or -0 will prevent the provider from being activated. Settings can be given in lower -or uppercase. Setting activate to any other setting, or omitting a setting -value will result in an error. -.Sp -= item \fBsoft_load\fR -.Sp -If enabled, informs the library to clear the error stack on failure to activate -requested provider. A value of 1, yes, true or on (in lower or uppercase) will -activate this setting, while a value of 0, no, false, or off (again in lower or -uppercase) will disable this setting. Any other value will produce an error. -Note this setting defaults to off if not provided -.PP -All parameters in the section as well as sub-sections are made -available to the provider. -.PP -\fIDefault provider and its activation\fR -.IX Subsection "Default provider and its activation" -.PP -If no providers are activated explicitly, the default one is activated implicitly. -See \fBOSSL_PROVIDER\-default\fR\|(7) for more details. -.PP -If you add a section explicitly activating any other provider(s), -you most probably need to explicitly activate the default provider, -otherwise it becomes unavailable in openssl. It may make the system remotely unavailable. -.SS "\s-1EVP\s0 Configuration" -.IX Subsection "EVP Configuration" -The name \fBalg_section\fR in the initialization section names the section -containing algorithmic properties when using the \fB\s-1EVP\s0\fR \s-1API.\s0 -.PP -Within the algorithm properties section, the following names have meaning: -.IP "\fBdefault_properties\fR" 4 -.IX Item "default_properties" -The value may be anything that is acceptable as a property query -string for \fBEVP_set_default_properties()\fR. -.IP "\fBfips_mode\fR (deprecated)" 4 -.IX Item "fips_mode (deprecated)" -The value is a boolean that can be \fByes\fR or \fBno\fR. If the value is -\&\fByes\fR, this is exactly equivalent to: -.Sp -.Vb 1 -\& default_properties = fips=yes -.Ve -.Sp -If the value is \fBno\fR, nothing happens. Using this name is deprecated, and -if used, it must be the only name in the section. -.SS "\s-1SSL\s0 Configuration" -.IX Subsection "SSL Configuration" -The name \fBssl_conf\fR in the initialization section names the section -containing the list of \s-1SSL/TLS\s0 configurations. -As with the providers, each name in this section identifies a -section with the configuration for that name. For example: -.PP -.Vb 4 -\& [ssl_configuration] -\& server = server_tls_config -\& client = client_tls_config -\& system_default = tls_system_default -\& -\& [server_tls_config] -\& ... configuration for SSL/TLS servers ... -\& -\& [client_tls_config] -\& ... configuration for SSL/TLS clients ... -.Ve -.PP -The configuration name \fBsystem_default\fR has a special meaning. If it -exists, it is applied whenever an \fB\s-1SSL_CTX\s0\fR object is created. For example, -to impose system-wide minimum \s-1TLS\s0 and \s-1DTLS\s0 protocol versions: -.PP -.Vb 3 -\& [tls_system_default] -\& MinProtocol = TLSv1.2 -\& MinProtocol = DTLSv1.2 -.Ve -.PP -The minimum \s-1TLS\s0 protocol is applied to \fB\s-1SSL_CTX\s0\fR objects that are TLS-based, -and the minimum \s-1DTLS\s0 protocol to those are DTLS-based. -The same applies also to maximum versions set with \fBMaxProtocol\fR. -.PP -Each configuration section consists of name/value pairs that are parsed -by \fB\fBSSL_CONF_cmd\fB\|(3)\fR, which will be called by \fBSSL_CTX_config()\fR or -\&\fBSSL_config()\fR, appropriately. Note that any characters before an initial -dot in the configuration section are ignored, so that the same command can -be used multiple times. This probably is most useful for loading different -key types, as shown here: -.PP -.Vb 3 -\& [server_tls_config] -\& RSA.Certificate = server\-rsa.pem -\& ECDSA.Certificate = server\-ecdsa.pem -.Ve -.SS "Engine Configuration" -.IX Subsection "Engine Configuration" -The name \fBengines\fR in the initialization section names the section -containing the list of \s-1ENGINE\s0 configurations. -As with the providers, each name in this section identifies an engine -with the configuration for that engine. -The engine-specific section is used to specify how to load the engine, -activate it, and set other parameters. -.PP -Within an engine section, the following names have meaning: -.IP "\fBengine_id\fR" 4 -.IX Item "engine_id" -This is used to specify an alternate name, overriding the default name -specified in the list of engines. If present, it must be first. -For example: -.Sp -.Vb 2 -\& [engines] -\& foo = foo_engine -\& -\& [foo_engine] -\& engine_id = myfoo -.Ve -.IP "\fBdynamic_path\fR" 4 -.IX Item "dynamic_path" -This loads and adds an \s-1ENGINE\s0 from the given path. It is equivalent to -sending the ctrls \fB\s-1SO_PATH\s0\fR with the path argument followed by \fB\s-1LIST_ADD\s0\fR -with value \fB2\fR and \fB\s-1LOAD\s0\fR to the dynamic \s-1ENGINE.\s0 If this is not the -required behaviour then alternative ctrls can be sent directly to the -dynamic \s-1ENGINE\s0 using ctrl commands. -.IP "\fBinit\fR" 4 -.IX Item "init" -This specifies whether to initialize the \s-1ENGINE.\s0 If the value is \fB0\fR the -\&\s-1ENGINE\s0 will not be initialized, if the value is \fB1\fR an attempt is made -to initialize -the \s-1ENGINE\s0 immediately. If the \fBinit\fR command is not present then an -attempt will be made to initialize the \s-1ENGINE\s0 after all commands in its -section have been processed. -.IP "\fBdefault_algorithms\fR" 4 -.IX Item "default_algorithms" -This sets the default algorithms an \s-1ENGINE\s0 will supply using the function -\&\fBENGINE_set_default_string()\fR. -.PP -All other names are taken to be the name of a ctrl command that is -sent to the \s-1ENGINE,\s0 and the value is the argument passed with the command. -The special value \fB\s-1EMPTY\s0\fR means no value is sent with the command. -For example: -.PP -.Vb 2 -\& [engines] -\& foo = foo_engine -\& -\& [foo_engine] -\& dynamic_path = /some/path/fooengine.so -\& some_ctrl = some_value -\& default_algorithms = ALL -\& other_ctrl = EMPTY -.Ve -.SS "Random Configuration" -.IX Subsection "Random Configuration" -The name \fBrandom\fR in the initialization section names the section -containing the random number generator settings. -.PP -Within the random section, the following names have meaning: -.IP "\fBrandom\fR" 4 -.IX Item "random" -This is used to specify the random bit generator. -For example: -.Sp -.Vb 2 -\& [random] -\& random = CTR\-DRBG -.Ve -.Sp -The available random bit generators are: -.RS 4 -.IP "\fBCTR-DRBG\fR" 4 -.IX Item "CTR-DRBG" -.PD 0 -.IP "\fBHASH-DRBG\fR" 4 -.IX Item "HASH-DRBG" -.IP "\fBHMAC-DRBG\fR" 4 -.IX Item "HMAC-DRBG" -.RE -.RS 4 -.RE -.IP "\fBcipher\fR" 4 -.IX Item "cipher" -.PD -This specifies what cipher a \fBCTR-DRBG\fR random bit generator will use. -Other random bit generators ignore this name. -The default value is \fB\s-1AES\-256\-CTR\s0\fR. -.IP "\fBdigest\fR" 4 -.IX Item "digest" -This specifies what digest the \fBHASH-DRBG\fR or \fBHMAC-DRBG\fR random bit -generators will use. Other random bit generators ignore this name. -.IP "\fBproperties\fR" 4 -.IX Item "properties" -This sets the property query used when fetching the random bit generator and -any underlying algorithms. -.IP "\fBseed\fR" 4 -.IX Item "seed" -This sets the randomness source that should be used. By default \fBSEED-SRC\fR -will be used outside of the \s-1FIPS\s0 provider. The \s-1FIPS\s0 provider uses call backs -to access the same randomness sources from outside the validated boundary. -.IP "\fBseed_properties\fR" 4 -.IX Item "seed_properties" -This sets the property query used when fetching the randomness source. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example shows how to use quoting and escaping. -.PP -.Vb 3 -\& # This is the default section. -\& HOME = /temp -\& configdir = $ENV::HOME/config -\& -\& [ section_one ] -\& # Quotes permit leading and trailing whitespace -\& any = " any variable name " -\& other = A string that can \e -\& cover several lines \e -\& by including \e\e characters -\& message = Hello World\en -\& -\& [ section_two ] -\& greeting = $section_one::message -.Ve -.PP -This example shows how to expand environment variables safely. -In this example, the variable \fBtempfile\fR is intended to refer -to a temporary file, and the environment variable \fB\s-1TEMP\s0\fR or -\&\fB\s-1TMP\s0\fR, if present, specify the directory where the file -should be put. -Since the default section is checked if a variable does not -exist, it is possible to set \fB\s-1TMP\s0\fR to default to \fI/tmp\fR, and -\&\fB\s-1TEMP\s0\fR to default to \fB\s-1TMP\s0\fR. -.PP -.Vb 3 -\& # These two lines must be in the default section. -\& TMP = /tmp -\& TEMP = $ENV::TMP -\& -\& # This can be used anywhere -\& tmpfile = ${ENV::TEMP}/tmp.filename -.Ve -.PP -This example shows how to enforce \s-1FIPS\s0 mode for the application -\&\fIsample\fR. -.PP -.Vb 1 -\& sample = fips_config -\& -\& [fips_config] -\& alg_section = evp_properties -\& -\& [evp_properties] -\& default_properties = "fips=yes" -.Ve -.SH "ENVIRONMENT" -.IX Header "ENVIRONMENT" -.IP "\fB\s-1OPENSSL_CONF\s0\fR" 4 -.IX Item "OPENSSL_CONF" -The path to the config file, or the empty string for none. -Ignored in set-user-ID and set-group-ID programs. -.IP "\fB\s-1OPENSSL_ENGINES\s0\fR" 4 -.IX Item "OPENSSL_ENGINES" -The path to the engines directory. -Ignored in set-user-ID and set-group-ID programs. -.IP "\fB\s-1OPENSSL_MODULES\s0\fR" 4 -.IX Item "OPENSSL_MODULES" -The path to the directory with OpenSSL modules, such as providers. -Ignored in set-user-ID and set-group-ID programs. -.IP "\fB\s-1OPENSSL_CONF_INCLUDE\s0\fR" 4 -.IX Item "OPENSSL_CONF_INCLUDE" -The optional path to prepend to all \fB.include\fR paths. -.SH "BUGS" -.IX Header "BUGS" -There is no way to include characters using the octal \fB\ennn\fR form. Strings -are all null terminated so nulls cannot form part of the value. -.PP -The escaping isn't quite right: if you want to use sequences like \fB\en\fR -you can't use any quote escaping on the same line. -.PP -The limit that only one directory can be opened and read at a time -can be considered a bug and should be fixed. -.SH "HISTORY" -.IX Header "HISTORY" -An undocumented \s-1API, \fBNCONF_WIN32\s0()\fR, used a slightly different set -of parsing rules there were intended to be tailored to -the Microsoft Windows platform. -Specifically, the backslash character was not an escape character and -could be used in pathnames, only the double-quote character was recognized, -and comments began with a semi-colon. -This function was deprecated in OpenSSL 3.0; applications with -configuration files using that syntax will have to be modified. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-x509\fR\|(1), \fBopenssl\-req\fR\|(1), \fBopenssl\-ca\fR\|(1), -\&\fBopenssl\-fipsinstall\fR\|(1), -\&\fBASN1_generate_nconf\fR\|(3), -\&\fBEVP_set_default_properties\fR\|(3), -\&\fBCONF_modules_load\fR\|(3), -\&\fBCONF_modules_load_file\fR\|(3), -\&\fBfips_config\fR\|(5), and -\&\fBx509v3_config\fR\|(5). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man5/fips_config.5ossl b/openssl-install/share/man/man5/fips_config.5ossl deleted file mode 100644 index 34fab889..00000000 --- a/openssl-install/share/man/man5/fips_config.5ossl +++ /dev/null @@ -1,326 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "FIPS_CONFIG 5ossl" -.TH FIPS_CONFIG 5ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -fips_config \- OpenSSL FIPS configuration -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A separate configuration file, using the OpenSSL \fBconfig\fR\|(5) syntax, -is used to hold information about the \s-1FIPS\s0 module. This includes a digest -of the shared library file, and status about the self-testing. -This data is used automatically by the module itself for two -purposes: -.IP "\- Run the startup \s-1FIPS\s0 self-test known answer tests (\s-1KATS\s0)." 4 -.IX Item "- Run the startup FIPS self-test known answer tests (KATS)." -This is normally done once, at installation time, but may also be set up to -run each time the module is used. -.IP "\- Verify the module's checksum." 4 -.IX Item "- Verify the module's checksum." -This is done each time the module is used. -.PP -This file is generated by the \fBopenssl\-fipsinstall\fR\|(1) program, and -used internally by the \s-1FIPS\s0 module during its initialization. -.PP -The following options are supported. They should all appear in a section -whose name is identified by the \fBfips\fR option in the \fBproviders\fR -section, as described in \*(L"Provider Configuration Module\*(R" in \fBconfig\fR\|(5). -.IP "\fBactivate\fR" 4 -.IX Item "activate" -If present, the module is activated. The value assigned to this name is not -significant. -.IP "\fBconditional-errors\fR" 4 -.IX Item "conditional-errors" -The \s-1FIPS\s0 module normally enters an internal error mode if any self test fails. -Once this error mode is active, no services or cryptographic algorithms are -accessible from this point on. -Continuous tests are a subset of the self tests (e.g., a key pair test during key -generation, or the \s-1CRNG\s0 output test). -Setting this value to \f(CW0\fR allows the error mode to not be triggered if any -continuous test fails. The default value of \f(CW1\fR will trigger the error mode. -Regardless of the value, the operation (e.g., key generation) that called the -continuous test will return an error code if its continuous test fails. The -operation may then be retried if the error mode has not been triggered. -.IP "\fBmodule-mac\fR" 4 -.IX Item "module-mac" -The calculated \s-1MAC\s0 of the \s-1FIPS\s0 provider file. -.IP "\fBinstall-version\fR" 4 -.IX Item "install-version" -A version number for the fips install process. Should be 1. -.IP "\fBinstall-status\fR" 4 -.IX Item "install-status" -An indicator that the self-tests were successfully run. -This should only be written after the module has -successfully passed its self tests during installation. -If this field is not present, then the self tests will run when the module -loads. -.IP "\fBinstall-mac\fR" 4 -.IX Item "install-mac" -A \s-1MAC\s0 of the value of the \fBinstall-status\fR option, to prevent accidental -changes to that value. -It is written-to at the same time as \fBinstall-status\fR is updated. -.SS "\s-1FIPS\s0 indicator options" -.IX Subsection "FIPS indicator options" -The following \s-1FIPS\s0 configuration options indicate if run-time checks related to -enforcement of \s-1FIPS\s0 security parameters such as minimum security strength of -keys and approved curve names are used. -A value of '1' will perform the checks, otherwise if the value is '0' the checks -are not performed and \s-1FIPS\s0 compliance must be done by procedures documented in -the relevant Security Policy. -.PP -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) for further information related to these -options. -.IP "\fBsecurity-checks\fR" 4 -.IX Item "security-checks" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-no_security_checks\fR -.IP "\fBtls1\-prf\-ems\-check\fR" 4 -.IX Item "tls1-prf-ems-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-ems_check\fR -.IP "\fBno-short-mac\fR" 4 -.IX Item "no-short-mac" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-no_short_mac\fR -.IP "\fBdrbg-no-trunc-md\fR" 4 -.IX Item "drbg-no-trunc-md" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-no_drbg_truncated_digests\fR -.IP "\fBsignature-digest-check\fR" 4 -.IX Item "signature-digest-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-signature_digest_check\fR -.IP "\fBhkdf-digest-check\fR" 4 -.IX Item "hkdf-digest-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-hkdf_digest_check\fR -.IP "\fBtls13\-kdf\-digest\-check\fR" 4 -.IX Item "tls13-kdf-digest-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-tls13_kdf_digest_check\fR -.IP "\fBtls1\-prf\-digest\-check\fR" 4 -.IX Item "tls1-prf-digest-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-tls1_prf_digest_check\fR -.IP "\fBsshkdf-digest-check\fR" 4 -.IX Item "sshkdf-digest-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-sshkdf_digest_check\fR -.IP "\fBsskdf-digest-check\fR" 4 -.IX Item "sskdf-digest-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-sskdf_digest_check\fR -.IP "\fBx963kdf\-digest\-check\fR" 4 -.IX Item "x963kdf-digest-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-x963kdf_digest_check\fR -.IP "\fBdsa-sign-disabled\fR" 4 -.IX Item "dsa-sign-disabled" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-dsa_sign_disabled\fR -.IP "\fBtdes-encrypt-disabled\fR" 4 -.IX Item "tdes-encrypt-disabled" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-tdes_encrypt_disabled\fR -.IP "\fBrsa\-pkcs15\-pad\-disabled\fR" 4 -.IX Item "rsa-pkcs15-pad-disabled" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-rsa_pkcs15_pad_disabled\fR -.IP "\fBrsa-pss-saltlen-check\fR" 4 -.IX Item "rsa-pss-saltlen-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-rsa_pss_saltlen_check\fR -.IP "\fBrsa\-sign\-x931\-pad\-disabled\fR" 4 -.IX Item "rsa-sign-x931-pad-disabled" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-rsa_sign_x931_disabled\fR -.IP "\fBhkdf-key-check\fR" 4 -.IX Item "hkdf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-hkdf_key_check\fR -.IP "\fBkbkdf-key-check\fR" 4 -.IX Item "kbkdf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-kbkdf_key_check\fR -.IP "\fBtls13\-kdf\-key\-check\fR" 4 -.IX Item "tls13-kdf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-tls13_kdf_key_check\fR -.IP "\fBtls1\-prf\-key\-check\fR" 4 -.IX Item "tls1-prf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-tls1_prf_key_check\fR -.IP "\fBsshkdf-key-check\fR" 4 -.IX Item "sshkdf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-sshkdf_key_check\fR -.IP "\fBsskdf-key-check\fR" 4 -.IX Item "sskdf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-sskdf_key_check\fR -.IP "\fBx963kdf\-key\-check\fR" 4 -.IX Item "x963kdf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-x963kdf_key_check\fR -.IP "\fBx942kdf\-key\-check\fR" 4 -.IX Item "x942kdf-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-x942kdf_key_check\fR -.IP "\fBpbkdf2\-lower\-bound\-check\fR" 4 -.IX Item "pbkdf2-lower-bound-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-no_pbkdf2_lower_bound_check\fR -.IP "\fBecdh-cofactor-check\fR" 4 -.IX Item "ecdh-cofactor-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-ecdh_cofactor_check\fR -.IP "\fBhmac-key-check\fR" 4 -.IX Item "hmac-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-hmac_key_check\fR -.IP "\fBkmac-key-check\fR" 4 -.IX Item "kmac-key-check" -See \*(L"\s-1OPTIONS\*(R"\s0 in \fBopenssl\-fipsinstall\fR\|(1) \fB\-kmac_key_check\fR -.PP -For example: -.PP -.Vb 8 -\& [fips_sect] -\& activate = 1 -\& install\-version = 1 -\& conditional\-errors = 1 -\& security\-checks = 1 -\& module\-mac = 41:D0:FA:C2:5D:41:75:CD:7D:C3:90:55:6F:A4:DC -\& install\-mac = FE:10:13:5A:D3:B4:C7:82:1B:1E:17:4C:AC:84:0C -\& install\-status = INSTALL_SELF_TEST_KATS_RUN -.Ve -.SH "NOTES" -.IX Header "NOTES" -When using the \s-1FIPS\s0 provider, it is recommended that the -\&\fBconfig_diagnostics\fR option is enabled to prevent accidental use of -non-FIPS validated algorithms via broken or mistaken configuration. -See \fBconfig\fR\|(5). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBconfig\fR\|(5) -\&\fBopenssl\-fipsinstall\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man5/x509v3_config.5ossl b/openssl-install/share/man/man5/x509v3_config.5ossl deleted file mode 100644 index 527f7b78..00000000 --- a/openssl-install/share/man/man5/x509v3_config.5ossl +++ /dev/null @@ -1,771 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509V3_CONFIG 5ossl" -.TH X509V3_CONFIG 5ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -x509v3_config \- X509 V3 certificate extension configuration format -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Several OpenSSL commands can add extensions to a certificate or -certificate request based on the contents of a configuration file -and \s-1CLI\s0 options such as \fB\-addext\fR. -The syntax of configuration files is described in \fBconfig\fR\|(5). -The commands typically have an option to specify the name of the configuration -file, and a section within that file; see the documentation of the -individual command for details. -.PP -This page uses \fBextensions\fR as the name of the section, when needed -in examples. -.PP -Each entry in the extension section takes the form: -.PP -.Vb 1 -\& name = [critical, ]value(s) -.Ve -.PP -If \fBcritical\fR is present then the extension will be marked as critical. -.PP -If multiple entries are processed for the same extension name, -later entries override earlier ones with the same name. -.PP -The format of \fBvalues\fR depends on the value of \fBname\fR, many have a -type-value pairing where the type and value are separated by a colon. -There are four main types of extension: -.PP -.Vb 4 -\& string -\& multi\-valued -\& raw -\& arbitrary -.Ve -.PP -Each is described in the following paragraphs. -.PP -String extensions simply have a string which contains either the value itself -or how it is obtained. -.PP -Multi-valued extensions have a short form and a long form. The short form -is a comma-separated list of names and values: -.PP -.Vb 1 -\& basicConstraints = critical, CA:true, pathlen:1 -.Ve -.PP -The long form allows the values to be placed in a separate section: -.PP -.Vb 2 -\& [extensions] -\& basicConstraints = critical, @basic_constraints -\& -\& [basic_constraints] -\& CA = true -\& pathlen = 1 -.Ve -.PP -Both forms are equivalent. -.PP -If an extension is multi-value and a field value must contain a comma the long -form must be used otherwise the comma would be misinterpreted as a field -separator. For example: -.PP -.Vb 1 -\& subjectAltName = URI:ldap://somehost.com/CN=foo,OU=bar -.Ve -.PP -will produce an error but the equivalent form: -.PP -.Vb 2 -\& [extensions] -\& subjectAltName = @subject_alt_section -\& -\& [subject_alt_section] -\& subjectAltName = URI:ldap://somehost.com/CN=foo,OU=bar -.Ve -.PP -is valid. -.PP -OpenSSL does not support multiple occurrences of the same field within a -section. In this example: -.PP -.Vb 2 -\& [extensions] -\& subjectAltName = @alt_section -\& -\& [alt_section] -\& email = steve@example.com -\& email = steve@example.org -.Ve -.PP -will only recognize the last value. To specify multiple values append a -numeric identifier, as shown here: -.PP -.Vb 2 -\& [extensions] -\& subjectAltName = @alt_section -\& -\& [alt_section] -\& email.1 = steve@example.com -\& email.2 = steve@example.org -.Ve -.PP -The syntax of raw extensions is defined by the source code that parses -the extension but should be documented. -See \*(L"Certificate Policies\*(R" for an example of a raw extension. -.PP -If an extension type is unsupported, then the \fIarbitrary\fR extension syntax -must be used, see the \*(L"\s-1ARBITRARY EXTENSIONS\*(R"\s0 section for more details. -.SH "STANDARD EXTENSIONS" -.IX Header "STANDARD EXTENSIONS" -The following sections describe the syntax of each supported extension. -They do not define the semantics of the extension. -.SS "Basic Constraints" -.IX Subsection "Basic Constraints" -This is a multi-valued extension which indicates whether a certificate is -a \s-1CA\s0 certificate. The first value is \fB\s-1CA\s0\fR followed by \fB\s-1TRUE\s0\fR or -\&\fB\s-1FALSE\s0\fR. If \fB\s-1CA\s0\fR is \fB\s-1TRUE\s0\fR then an optional \fBpathlen\fR name followed by a -nonnegative value can be included. -.PP -For example: -.PP -.Vb 1 -\& basicConstraints = CA:TRUE -\& -\& basicConstraints = CA:FALSE -\& -\& basicConstraints = critical, CA:TRUE, pathlen:1 -.Ve -.PP -A \s-1CA\s0 certificate \fImust\fR include the \fBbasicConstraints\fR name with the \fB\s-1CA\s0\fR -parameter set to \fB\s-1TRUE\s0\fR. An end-user certificate must either have \fB\s-1CA:FALSE\s0\fR -or omit the extension entirely. -The \fBpathlen\fR parameter specifies the maximum number of CAs that can appear -below this one in a chain. A \fBpathlen\fR of zero means the \s-1CA\s0 cannot sign -any sub-CA's, and can only sign end-entity certificates. -.SS "Key Usage" -.IX Subsection "Key Usage" -Key usage is a multi-valued extension consisting of a list of names of -the permitted key usages. The defined values are: \f(CW\*(C`digitalSignature\*(C'\fR, -\&\f(CW\*(C`nonRepudiation\*(C'\fR, \f(CW\*(C`keyEncipherment\*(C'\fR, \f(CW\*(C`dataEncipherment\*(C'\fR, \f(CW\*(C`keyAgreement\*(C'\fR, -\&\f(CW\*(C`keyCertSign\*(C'\fR, \f(CW\*(C`cRLSign\*(C'\fR, \f(CW\*(C`encipherOnly\*(C'\fR, and \f(CW\*(C`decipherOnly\*(C'\fR. -.PP -Examples: -.PP -.Vb 1 -\& keyUsage = digitalSignature, nonRepudiation -\& -\& keyUsage = critical, keyCertSign -.Ve -.SS "Extended Key Usage" -.IX Subsection "Extended Key Usage" -This extension consists of a list of values indicating purposes for which -the certificate public key can be used. -Each value can be either a short text name or an \s-1OID.\s0 -The following text names, and their intended meaning, are known: -.PP -.Vb 10 -\& Value Meaning according to RFC 5280 etc. -\& \-\-\-\-\- \-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\- -\& serverAuth SSL/TLS WWW Server Authentication -\& clientAuth SSL/TLS WWW Client Authentication -\& codeSigning Code Signing -\& emailProtection E\-mail Protection (S/MIME) -\& timeStamping Trusted Timestamping -\& OCSPSigning OCSP Signing -\& ipsecIKE ipsec Internet Key Exchange -\& msCodeInd Microsoft Individual Code Signing (authenticode) -\& msCodeCom Microsoft Commercial Code Signing (authenticode) -\& msCTLSign Microsoft Trust List Signing -\& msEFS Microsoft Encrypted File System -.Ve -.PP -While \s-1IETF RFC 5280\s0 says that \fBid-kp-serverAuth\fR and \fBid-kp-clientAuth\fR -are only for \s-1WWW\s0 use, in practice they are used for all kinds of \s-1TLS\s0 clients -and servers, and this is what OpenSSL assumes as well. -.PP -Examples: -.PP -.Vb 1 -\& extendedKeyUsage = critical, codeSigning, 1.2.3.4 -\& -\& extendedKeyUsage = serverAuth, clientAuth -.Ve -.SS "Subject Key Identifier" -.IX Subsection "Subject Key Identifier" -The \s-1SKID\s0 extension specification has a value with three choices. -.IP "\fBnone\fR" 4 -.IX Item "none" -No \s-1SKID\s0 extension will be included. -.IP "\fBhash\fR" 4 -.IX Item "hash" -The process specified in \s-1RFC 5280\s0 section 4.2.1.2. (1) is followed: -The keyIdentifier is composed of the 160\-bit \s-1SHA\-1\s0 hash of the value of the \s-1BIT -STRING\s0 subjectPublicKey (excluding the tag, length, and number of unused bits). -.ie n .IP "A hex string (possibly with "":"" separating bytes)" 4 -.el .IP "A hex string (possibly with \f(CW:\fR separating bytes)" 4 -.IX Item "A hex string (possibly with : separating bytes)" -The provided value is output directly. -This choice is strongly discouraged. -.PP -By default the \fBx509\fR, \fBreq\fR, and \fBca\fR apps behave as if \fBhash\fR was given. -.PP -Example: -.PP -.Vb 1 -\& subjectKeyIdentifier = hash -.Ve -.SS "Authority Key Identifier" -.IX Subsection "Authority Key Identifier" -The \s-1AKID\s0 extension specification may have the value \fBnone\fR -indicating that no \s-1AKID\s0 shall be included. -Otherwise it may have the value \fBkeyid\fR or \fBissuer\fR -or both of them, separated by \f(CW\*(C`,\*(C'\fR. -Either or both can have the option \fBalways\fR, -indicated by putting a colon \f(CW\*(C`:\*(C'\fR between the value and this option. -For self-signed certificates the \s-1AKID\s0 is suppressed unless \fBalways\fR is present. -.PP -By default the \fBx509\fR, \fBreq\fR, and \fBca\fR apps behave as if \fBnone\fR was given -for self-signed certificates and \fBkeyid\fR\f(CW\*(C`,\*(C'\fR \fBissuer\fR otherwise. -.PP -If \fBkeyid\fR is present, an attempt is made to -copy the subject key identifier (\s-1SKID\s0) from the issuer certificate except if -the issuer certificate is the same as the current one and it is not self-signed. -The hash of the public key related to the signing key is taken as fallback -if the issuer certificate is the same as the current certificate. -If \fBalways\fR is present but no value can be obtained, an error is returned. -.PP -If \fBissuer\fR is present, and in addition it has the option \fBalways\fR specified -or \fBkeyid\fR is not present, -then the issuer \s-1DN\s0 and serial number are copied from the issuer certificate. -If this fails, an error is returned. -.PP -Examples: -.PP -.Vb 1 -\& authorityKeyIdentifier = keyid, issuer -\& -\& authorityKeyIdentifier = keyid, issuer:always -.Ve -.SS "Subject Alternative Name" -.IX Subsection "Subject Alternative Name" -This is a multi-valued extension that supports several types of name -identifier, including -\&\fBemail\fR (an email address), -\&\fB\s-1URI\s0\fR (a uniform resource indicator), -\&\fB\s-1DNS\s0\fR (a \s-1DNS\s0 domain name), -\&\fB\s-1RID\s0\fR (a registered \s-1ID: OBJECT IDENTIFIER\s0), -\&\fB\s-1IP\s0\fR (an \s-1IP\s0 address), -\&\fBdirName\fR (a distinguished name), -and \fBotherName\fR. -The syntax of each is described in the following paragraphs. -.PP -The \fBemail\fR option has two special values. -\&\f(CW\*(C`copy\*(C'\fR will automatically include any email addresses -contained in the certificate subject name in the extension. -\&\f(CW\*(C`move\*(C'\fR will automatically move any email addresses -from the certificate subject name to the extension. -.PP -The \s-1IP\s0 address used in the \fB\s-1IP\s0\fR option can be in either IPv4 or IPv6 format. -.PP -The value of \fBdirName\fR is specifies the configuration section containing -the distinguished name to use, as a set of name-value pairs. -Multi-valued AVAs can be formed by prefacing the name with a \fB+\fR character. -.PP -The value of \fBotherName\fR can include arbitrary data associated with an \s-1OID\s0; -the value should be the \s-1OID\s0 followed by a semicolon and the content in specified -using the syntax in \fBASN1_generate_nconf\fR\|(3). -.PP -Examples: -.PP -.Vb 1 -\& subjectAltName = email:copy, email:my@example.com, URI:http://my.example.com/ -\& -\& subjectAltName = IP:192.168.7.1 -\& -\& subjectAltName = IP:13::17 -\& -\& subjectAltName = email:my@example.com, RID:1.2.3.4 -\& -\& subjectAltName = otherName:1.2.3.4;UTF8:some other identifier -\& -\& [extensions] -\& subjectAltName = dirName:dir_sect -\& -\& [dir_sect] -\& C = UK -\& O = My Organization -\& OU = My Unit -\& CN = My Name -.Ve -.PP -Non-ASCII Email Address conforming the syntax defined in Section 3.3 of \s-1RFC 6531\s0 -are provided as otherName.SmtpUTF8Mailbox. According to \s-1RFC 8398,\s0 the email -address should be provided as UTF8String. To enforce the valid representation in -the certificate, the SmtpUTF8Mailbox should be provided as follows -.PP -.Vb 3 -\& subjectAltName=@alts -\& [alts] -\& otherName = 1.3.6.1.5.5.7.8.9;FORMAT:UTF8,UTF8String:nonasciiname.example.com -.Ve -.SS "Issuer Alternative Name" -.IX Subsection "Issuer Alternative Name" -This extension supports most of the options of subject alternative name; -it does not support \fBemail:copy\fR. -It also adds \fBissuer:copy\fR as an allowed value, which copies any subject -alternative names from the issuer certificate, if possible. -.PP -Example: -.PP -.Vb 1 -\& issuerAltName = issuer:copy -.Ve -.SS "Authority Info Access" -.IX Subsection "Authority Info Access" -This extension gives details about how to retrieve information that -related to the certificate that the \s-1CA\s0 makes available. The syntax is -\&\fBaccess_id;location\fR, where \fBaccess_id\fR is an object identifier -(although only a few values are well-known) and \fBlocation\fR has the same -syntax as subject alternative name (except that \fBemail:copy\fR is not supported). -.PP -Possible values for access_id include \fB\s-1OCSP\s0\fR (\s-1OCSP\s0 responder), -\&\fBcaIssuers\fR (\s-1CA\s0 Issuers), -\&\fBad_timestamping\fR (\s-1AD\s0 Time Stamping), -\&\fB\s-1AD_DVCS\s0\fR (ad dvcs), -\&\fBcaRepository\fR (\s-1CA\s0 Repository). -.PP -Examples: -.PP -.Vb 1 -\& authorityInfoAccess = OCSP;URI:http://ocsp.example.com/,caIssuers;URI:http://myca.example.com/ca.cer -\& -\& authorityInfoAccess = OCSP;URI:http://ocsp.example.com/ -.Ve -.SS "\s-1CRL\s0 distribution points" -.IX Subsection "CRL distribution points" -This is a multi-valued extension whose values can be either a name-value -pair using the same form as subject alternative name or a single value -specifying the section name containing all the distribution point values. -.PP -When a name-value pair is used, a DistributionPoint extension will -be set with the given value as the fullName field as the distributionPoint -value, and the reasons and cRLIssuer fields will be omitted. -.PP -When a single option is used, the value specifies the section, and that -section can have the following items: -.IP "fullname" 4 -.IX Item "fullname" -The full name of the distribution point, in the same format as the subject -alternative name. -.IP "relativename" 4 -.IX Item "relativename" -The value is taken as a distinguished name fragment that is set as the -value of the nameRelativeToCRLIssuer field. -.IP "CRLIssuer" 4 -.IX Item "CRLIssuer" -The value must in the same format as the subject alternative name. -.IP "reasons" 4 -.IX Item "reasons" -A multi-value field that contains the reasons for revocation. The recognized -values are: \f(CW\*(C`keyCompromise\*(C'\fR, \f(CW\*(C`CACompromise\*(C'\fR, \f(CW\*(C`affiliationChanged\*(C'\fR, -\&\f(CW\*(C`superseded\*(C'\fR, \f(CW\*(C`cessationOfOperation\*(C'\fR, \f(CW\*(C`certificateHold\*(C'\fR, -\&\f(CW\*(C`privilegeWithdrawn\*(C'\fR, and \f(CW\*(C`AACompromise\*(C'\fR. -.PP -Only one of \fBfullname\fR or \fBrelativename\fR should be specified. -.PP -Simple examples: -.PP -.Vb 1 -\& crlDistributionPoints = URI:http://example.com/myca.crl -\& -\& crlDistributionPoints = URI:http://example.com/myca.crl, URI:http://example.org/my.crl -.Ve -.PP -Full distribution point example: -.PP -.Vb 2 -\& [extensions] -\& crlDistributionPoints = crldp1_section -\& -\& [crldp1_section] -\& fullname = URI:http://example.com/myca.crl -\& CRLissuer = dirName:issuer_sect -\& reasons = keyCompromise, CACompromise -\& -\& [issuer_sect] -\& C = UK -\& O = Organisation -\& CN = Some Name -.Ve -.SS "Issuing Distribution Point" -.IX Subsection "Issuing Distribution Point" -This extension should only appear in CRLs. It is a multi-valued extension -whose syntax is similar to the \*(L"section\*(R" pointed to by the \s-1CRL\s0 distribution -points extension. The following names have meaning: -.IP "fullname" 4 -.IX Item "fullname" -The full name of the distribution point, in the same format as the subject -alternative name. -.IP "relativename" 4 -.IX Item "relativename" -The value is taken as a distinguished name fragment that is set as the -value of the nameRelativeToCRLIssuer field. -.IP "onlysomereasons" 4 -.IX Item "onlysomereasons" -A multi-value field that contains the reasons for revocation. The recognized -values are: \f(CW\*(C`keyCompromise\*(C'\fR, \f(CW\*(C`CACompromise\*(C'\fR, \f(CW\*(C`affiliationChanged\*(C'\fR, -\&\f(CW\*(C`superseded\*(C'\fR, \f(CW\*(C`cessationOfOperation\*(C'\fR, \f(CW\*(C`certificateHold\*(C'\fR, -\&\f(CW\*(C`privilegeWithdrawn\*(C'\fR, and \f(CW\*(C`AACompromise\*(C'\fR. -.IP "onlyuser, onlyCA, onlyAA, indirectCRL" 4 -.IX Item "onlyuser, onlyCA, onlyAA, indirectCRL" -The value for each of these names is a boolean. -.PP -Example: -.PP -.Vb 2 -\& [extensions] -\& issuingDistributionPoint = critical, @idp_section -\& -\& [idp_section] -\& fullname = URI:http://example.com/myca.crl -\& indirectCRL = TRUE -\& onlysomereasons = keyCompromise, CACompromise -.Ve -.SS "Certificate Policies" -.IX Subsection "Certificate Policies" -This is a \fIraw\fR extension that supports all of the defined fields of the -certificate extension. -.PP -Policies without qualifiers are specified by giving the \s-1OID.\s0 -Multiple policies are comma-separated. For example: -.PP -.Vb 1 -\& certificatePolicies = 1.2.4.5, 1.1.3.4 -.Ve -.PP -To include policy qualifiers, use the \*(L"@section\*(R" syntax to point to a -section that specifies all the information. -.PP -The section referred to must include the policy \s-1OID\s0 using the name -\&\fBpolicyIdentifier\fR. cPSuri qualifiers can be included using the syntax: -.PP -.Vb 1 -\& CPS.nnn = value -.Ve -.PP -where \f(CW\*(C`nnn\*(C'\fR is a number. -.PP -userNotice qualifiers can be set using the syntax: -.PP -.Vb 1 -\& userNotice.nnn = @notice -.Ve -.PP -The value of the userNotice qualifier is specified in the relevant section. -This section can include \fBexplicitText\fR, \fBorganization\fR, and \fBnoticeNumbers\fR -options. explicitText and organization are text strings, noticeNumbers is a -comma separated list of numbers. The organization and noticeNumbers options -(if included) must \s-1BOTH\s0 be present. Some software might require -the \fBia5org\fR option at the top level; this changes the encoding from -Displaytext to IA5String. -.PP -Example: -.PP -.Vb 2 -\& [extensions] -\& certificatePolicies = ia5org, 1.2.3.4, 1.5.6.7.8, @polsect -\& -\& [polsect] -\& policyIdentifier = 1.3.5.8 -\& CPS.1 = "http://my.host.example.com/" -\& CPS.2 = "http://my.your.example.com/" -\& userNotice.1 = @notice -\& -\& [notice] -\& explicitText = "Explicit Text Here" -\& organization = "Organisation Name" -\& noticeNumbers = 1, 2, 3, 4 -.Ve -.PP -The character encoding of explicitText can be specified by prefixing the -value with \fB\s-1UTF8\s0\fR, \fB\s-1BMP\s0\fR, or \fB\s-1VISIBLE\s0\fR followed by colon. For example: -.PP -.Vb 2 -\& [notice] -\& explicitText = "UTF8:Explicit Text Here" -.Ve -.SS "Policy Constraints" -.IX Subsection "Policy Constraints" -This is a multi-valued extension which consisting of the names -\&\fBrequireExplicitPolicy\fR or \fBinhibitPolicyMapping\fR and a non negative integer -value. At least one component must be present. -.PP -Example: -.PP -.Vb 1 -\& policyConstraints = requireExplicitPolicy:3 -.Ve -.SS "Inhibit Any Policy" -.IX Subsection "Inhibit Any Policy" -This is a string extension whose value must be a non negative integer. -.PP -Example: -.PP -.Vb 1 -\& inhibitAnyPolicy = 2 -.Ve -.SS "Name Constraints" -.IX Subsection "Name Constraints" -This is a multi-valued extension. The name should -begin with the word \fBpermitted\fR or \fBexcluded\fR followed by a \fB;\fR. The rest of -the name and the value follows the syntax of subjectAltName except -\&\fBemail:copy\fR -is not supported and the \fB\s-1IP\s0\fR form should consist of an \s-1IP\s0 addresses and -subnet mask separated by a \fB/\fR. -.PP -Examples: -.PP -.Vb 1 -\& nameConstraints = permitted;IP:192.168.0.0/255.255.0.0 -\& -\& nameConstraints = permitted;email:.example.com -\& -\& nameConstraints = excluded;email:.com -.Ve -.SS "\s-1OCSP\s0 No Check" -.IX Subsection "OCSP No Check" -This is a string extension. It is parsed, but ignored. -.PP -Example: -.PP -.Vb 1 -\& noCheck = ignored -.Ve -.SS "\s-1TLS\s0 Feature (aka Must Staple)" -.IX Subsection "TLS Feature (aka Must Staple)" -This is a multi-valued extension consisting of a list of \s-1TLS\s0 extension -identifiers. Each identifier may be a number (0..65535) or a supported name. -When a \s-1TLS\s0 client sends a listed extension, the \s-1TLS\s0 server is expected to -include that extension in its reply. -.PP -The supported names are: \fBstatus_request\fR and \fBstatus_request_v2\fR. -.PP -Example: -.PP -.Vb 1 -\& tlsfeature = status_request -.Ve -.SH "DEPRECATED EXTENSIONS" -.IX Header "DEPRECATED EXTENSIONS" -The following extensions are non standard, Netscape specific and largely -obsolete. Their use in new applications is discouraged. -.SS "Netscape String extensions" -.IX Subsection "Netscape String extensions" -Netscape Comment (\fBnsComment\fR) is a string extension containing a comment -which will be displayed when the certificate is viewed in some browsers. -Other extensions of this type are: \fBnsBaseUrl\fR, -\&\fBnsRevocationUrl\fR, \fBnsCaRevocationUrl\fR, \fBnsRenewalUrl\fR, \fBnsCaPolicyUrl\fR -and \fBnsSslServerName\fR. -.SS "Netscape Certificate Type" -.IX Subsection "Netscape Certificate Type" -This is a multi-valued extensions which consists of a list of flags to be -included. It was used to indicate the purposes for which a certificate could -be used. The basicConstraints, keyUsage and extended key usage extensions are -now used instead. -.PP -Acceptable values for nsCertType are: \fBclient\fR, \fBserver\fR, \fBemail\fR, -\&\fBobjsign\fR, \fBreserved\fR, \fBsslCA\fR, \fBemailCA\fR, \fBobjCA\fR. -.SH "ARBITRARY EXTENSIONS" -.IX Header "ARBITRARY EXTENSIONS" -If an extension is not supported by the OpenSSL code then it must be encoded -using the arbitrary extension format. It is also possible to use the arbitrary -format for supported extensions. Extreme care should be taken to ensure that -the data is formatted correctly for the given extension type. -.PP -There are two ways to encode arbitrary extensions. -.PP -The first way is to use the word \s-1ASN1\s0 followed by the extension content -using the same syntax as \fBASN1_generate_nconf\fR\|(3). -For example: -.PP -.Vb 3 -\& [extensions] -\& 1.2.3.4 = critical, ASN1:UTF8String:Some random data -\& 1.2.3.4.1 = ASN1:SEQUENCE:seq_sect -\& -\& [seq_sect] -\& field1 = UTF8:field1 -\& field2 = UTF8:field2 -.Ve -.PP -It is also possible to use the word \s-1DER\s0 to include the raw encoded data in any -extension. -.PP -.Vb 2 -\& 1.2.3.4 = critical, DER:01:02:03:04 -\& 1.2.3.4.1 = DER:01020304 -.Ve -.PP -The value following \s-1DER\s0 is a hex dump of the \s-1DER\s0 encoding of the extension -Any extension can be placed in this form to override the default behaviour. -For example: -.PP -.Vb 1 -\& basicConstraints = critical, DER:00:01:02:03 -.Ve -.SH "WARNINGS" -.IX Header "WARNINGS" -There is no guarantee that a specific implementation will process a given -extension. It may therefore be sometimes possible to use certificates for -purposes prohibited by their extensions because a specific application does -not recognize or honour the values of the relevant extensions. -.PP -The \s-1DER\s0 and \s-1ASN1\s0 options should be used with caution. It is possible to create -invalid extensions if they are not used carefully. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-req\fR\|(1), \fBopenssl\-ca\fR\|(1), \fBopenssl\-x509\fR\|(1), -\&\fBASN1_generate_nconf\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2004\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_ASYM_CIPHER-RSA.7ossl b/openssl-install/share/man/man7/EVP_ASYM_CIPHER-RSA.7ossl deleted file mode 100644 index d11f85d3..00000000 --- a/openssl-install/share/man/man7/EVP_ASYM_CIPHER-RSA.7ossl +++ /dev/null @@ -1,261 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_ASYM_CIPHER-RSA 7ossl" -.TH EVP_ASYM_CIPHER-RSA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_ASYM_CIPHER\-RSA -\&\- RSA Asymmetric Cipher algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Asymmetric Cipher support for the \fB\s-1RSA\s0\fR key type. -.SS "\s-1RSA\s0 Asymmetric Cipher parameters" -.IX Subsection "RSA Asymmetric Cipher parameters" -.ie n .IP """pad-mode"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``pad-mode'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "pad-mode (OSSL_ASYM_CIPHER_PARAM_PAD_MODE) " -The default provider understands these \s-1RSA\s0 padding modes in string form: -.RS 4 -.ie n .IP """none"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_NONE\s0\fR)" 4 -.el .IP "``none'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_NONE\s0\fR)" 4 -.IX Item "none (OSSL_PKEY_RSA_PAD_MODE_NONE)" -.PD 0 -.ie n .IP """oaep"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_OAEP\s0\fR)" 4 -.el .IP "``oaep'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_OAEP\s0\fR)" 4 -.IX Item "oaep (OSSL_PKEY_RSA_PAD_MODE_OAEP)" -.ie n .IP """pkcs1"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_PKCSV15\s0\fR)" 4 -.el .IP "``pkcs1'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_PKCSV15\s0\fR)" 4 -.IX Item "pkcs1 (OSSL_PKEY_RSA_PAD_MODE_PKCSV15)" -.PD -This padding mode is no longer supported by the \s-1FIPS\s0 provider for key -agreement and key transport. -(This is a \s-1FIPS 140\-3\s0 requirement) -.ie n .IP """x931"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_X931\s0\fR)" 4 -.el .IP "``x931'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_X931\s0\fR)" 4 -.IX Item "x931 (OSSL_PKEY_RSA_PAD_MODE_X931)" -.RE -.RS 4 -.RE -.PD 0 -.ie n .IP """pad-mode"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_PAD_MODE\s0\fR) " 4 -.el .IP "``pad-mode'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_PAD_MODE\s0\fR) " 4 -.IX Item "pad-mode (OSSL_ASYM_CIPHER_PARAM_PAD_MODE) " -.PD -The default provider understands these \s-1RSA\s0 padding modes in integer form: -.RS 4 -.IP "1 (\fB\s-1RSA_PKCS1_PADDING\s0\fR)" 4 -.IX Item "1 (RSA_PKCS1_PADDING)" -This padding mode is no longer supported by the \s-1FIPS\s0 provider for key -agreement and key transport. -(This is a \s-1FIPS 140\-3\s0 requirement) -.IP "3 (\fB\s-1RSA_NO_PADDING\s0\fR)" 4 -.IX Item "3 (RSA_NO_PADDING)" -.PD 0 -.IP "4 (\fB\s-1RSA_PKCS1_OAEP_PADDING\s0\fR)" 4 -.IX Item "4 (RSA_PKCS1_OAEP_PADDING)" -.IP "5 (\fB\s-1RSA_X931_PADDING\s0\fR)" 4 -.IX Item "5 (RSA_X931_PADDING)" -.RE -.RS 4 -.PD -.Sp -See \fBEVP_PKEY_CTX_set_rsa_padding\fR\|(3) for further details. -.RE -.ie n .IP """digest"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST) " -.PD 0 -.ie n .IP """digest-props"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest-props'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest-props (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS) " -.ie n .IP """mgf1\-digest"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mgf1\-digest'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mgf1-digest (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST) " -.ie n .IP """mgf1\-digest\-props"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mgf1\-digest\-props'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mgf1-digest-props (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS) " -.ie n .IP """oaep-label"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL\s0\fR) " 4 -.el .IP "``oaep-label'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL\s0\fR) " 4 -.IX Item "oaep-label (OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL) " -.ie n .IP """tls-client-version"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.el .IP "``tls-client-version'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.IX Item "tls-client-version (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) " -.PD -See \fB\s-1RSA_PKCS1_WITH_TLS_PADDING\s0\fR on the page \fBEVP_PKEY_CTX_set_rsa_padding\fR\|(3). -.ie n .IP """tls-negotiated-version"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.el .IP "``tls-negotiated-version'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.IX Item "tls-negotiated-version (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) " -See \fB\s-1RSA_PKCS1_WITH_TLS_PADDING\s0\fR on the page \fBEVP_PKEY_CTX_set_rsa_padding\fR\|(3). -.Sp -See \*(L"Asymmetric Cipher Parameters\*(R" in \fBprovider\-asym_cipher\fR\|(7) for more information. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) " -.PD 0 -.ie n .IP """key-check"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK) " -.PD -See \*(L"Asymmetric Cipher Parameters\*(R" in \fBprovider\-asym_cipher\fR\|(7) for more information. -.ie n .IP """pkcs15\-pad\-disabled"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_RSA_PKCS15_PAD_DISABLED\s0\fR) " 4 -.el .IP "``pkcs15\-pad\-disabled'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_RSA_PKCS15_PAD_DISABLED\s0\fR) " 4 -.IX Item "pkcs15-pad-disabled (OSSL_ASYM_CIPHER_PARAM_FIPS_RSA_PKCS15_PAD_DISABLED) " -The default value of 1 causes an error during encryption if the \s-1RSA\s0 padding -mode is set to \*(L"pkcs1\*(R". -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-RSA\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-asym_cipher\fR\|(7), -\&\fBprovider\-keymgmt\fR\|(7), -\&\fBOSSL_PROVIDER\-default\fR\|(7) -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_ASYM_CIPHER-SM2.7ossl b/openssl-install/share/man/man7/EVP_ASYM_CIPHER-SM2.7ossl deleted file mode 100644 index 13f6255d..00000000 --- a/openssl-install/share/man/man7/EVP_ASYM_CIPHER-SM2.7ossl +++ /dev/null @@ -1,172 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_ASYM_CIPHER-SM2 7ossl" -.TH EVP_ASYM_CIPHER-SM2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_ASYM_CIPHER\-SM2 -\&\- SM2 Asymmetric Cipher algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Asymmetric Cipher support for the \fB\s-1SM2\s0\fR key type. -.SS "\s-1SM2\s0 Asymmetric Cipher parameters" -.IX Subsection "SM2 Asymmetric Cipher parameters" -.ie n .IP """digest"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_ASYM_CIPHER_PARAM_DIGEST) " -.PD 0 -.ie n .IP """digest-props"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest-props'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest-props (OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS) " -.PD -See \*(L"Asymmetric Cipher Parameters\*(R" in \fBprovider\-asym_cipher\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-SM2\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-asym_cipher\fR\|(7), -\&\fBprovider\-keymgmt\fR\|(7), -\&\fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-AES.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-AES.7ossl deleted file mode 100644 index 64e55bdc..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-AES.7ossl +++ /dev/null @@ -1,228 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-AES 7ossl" -.TH EVP_CIPHER-AES 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-AES \- The AES EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1AES\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the \s-1FIPS\s0 provider as well as the -default provider: -.ie n .IP """\s-1AES\-128\-CBC"", ""AES\-192\-CBC""\s0 and ""\s-1AES\-256\-CBC""\s0" 4 -.el .IP "``\s-1AES\-128\-CBC'', ``AES\-192\-CBC''\s0 and ``\s-1AES\-256\-CBC''\s0" 4 -.IX Item "AES-128-CBC, AES-192-CBC and AES-256-CBC" -.PD 0 -.ie n .IP """\s-1AES\-128\-CBC\-CTS"", ""AES\-192\-CBC\-CTS""\s0 and ""\s-1AES\-256\-CBC\-CTS""\s0" 4 -.el .IP "``\s-1AES\-128\-CBC\-CTS'', ``AES\-192\-CBC\-CTS''\s0 and ``\s-1AES\-256\-CBC\-CTS''\s0" 4 -.IX Item "AES-128-CBC-CTS, AES-192-CBC-CTS and AES-256-CBC-CTS" -.ie n .IP """\s-1AES\-128\-CFB"", ""AES\-192\-CFB"", ""AES\-256\-CFB"", ""AES\-128\-CFB1"", ""AES\-192\-CFB1"", ""AES\-256\-CFB1"", ""AES\-128\-CFB8"", ""AES\-192\-CFB8""\s0 and ""\s-1AES\-256\-CFB8""\s0" 4 -.el .IP "``\s-1AES\-128\-CFB'', ``AES\-192\-CFB'', ``AES\-256\-CFB'', ``AES\-128\-CFB1'', ``AES\-192\-CFB1'', ``AES\-256\-CFB1'', ``AES\-128\-CFB8'', ``AES\-192\-CFB8''\s0 and ``\s-1AES\-256\-CFB8''\s0" 4 -.IX Item "AES-128-CFB, AES-192-CFB, AES-256-CFB, AES-128-CFB1, AES-192-CFB1, AES-256-CFB1, AES-128-CFB8, AES-192-CFB8 and AES-256-CFB8" -.ie n .IP """\s-1AES\-128\-CTR"", ""AES\-192\-CTR""\s0 and ""\s-1AES\-256\-CTR""\s0" 4 -.el .IP "``\s-1AES\-128\-CTR'', ``AES\-192\-CTR''\s0 and ``\s-1AES\-256\-CTR''\s0" 4 -.IX Item "AES-128-CTR, AES-192-CTR and AES-256-CTR" -.ie n .IP """\s-1AES\-128\-ECB"", ""AES\-192\-ECB""\s0 and ""\s-1AES\-256\-ECB""\s0" 4 -.el .IP "``\s-1AES\-128\-ECB'', ``AES\-192\-ECB''\s0 and ``\s-1AES\-256\-ECB''\s0" 4 -.IX Item "AES-128-ECB, AES-192-ECB and AES-256-ECB" -.ie n .IP """\s-1AES\-192\-OFB"", ""AES\-128\-OFB""\s0 and ""\s-1AES\-256\-OFB""\s0" 4 -.el .IP "``\s-1AES\-192\-OFB'', ``AES\-128\-OFB''\s0 and ``\s-1AES\-256\-OFB''\s0" 4 -.IX Item "AES-192-OFB, AES-128-OFB and AES-256-OFB" -.ie n .IP """\s-1AES\-128\-XTS""\s0 and ""\s-1AES\-256\-XTS""\s0" 4 -.el .IP "``\s-1AES\-128\-XTS''\s0 and ``\s-1AES\-256\-XTS''\s0" 4 -.IX Item "AES-128-XTS and AES-256-XTS" -.ie n .IP """\s-1AES\-128\-CCM"", ""AES\-192\-CCM""\s0 and ""\s-1AES\-256\-CCM""\s0" 4 -.el .IP "``\s-1AES\-128\-CCM'', ``AES\-192\-CCM''\s0 and ``\s-1AES\-256\-CCM''\s0" 4 -.IX Item "AES-128-CCM, AES-192-CCM and AES-256-CCM" -.ie n .IP """\s-1AES\-128\-GCM"", ""AES\-192\-GCM""\s0 and ""\s-1AES\-256\-GCM""\s0" 4 -.el .IP "``\s-1AES\-128\-GCM'', ``AES\-192\-GCM''\s0 and ``\s-1AES\-256\-GCM''\s0" 4 -.IX Item "AES-128-GCM, AES-192-GCM and AES-256-GCM" -.ie n .IP """\s-1AES\-128\-WRAP"", ""AES\-192\-WRAP"", ""AES\-256\-WRAP"", ""AES\-128\-WRAP\-PAD"", ""AES\-192\-WRAP\-PAD"", ""AES\-256\-WRAP\-PAD"", ""AES\-128\-WRAP\-INV"", ""AES\-192\-WRAP\-INV"", ""AES\-256\-WRAP\-INV"", ""AES\-128\-WRAP\-PAD\-INV"", ""AES\-192\-WRAP\-PAD\-INV""\s0 and ""\s-1AES\-256\-WRAP\-PAD\-INV""\s0" 4 -.el .IP "``\s-1AES\-128\-WRAP'', ``AES\-192\-WRAP'', ``AES\-256\-WRAP'', ``AES\-128\-WRAP\-PAD'', ``AES\-192\-WRAP\-PAD'', ``AES\-256\-WRAP\-PAD'', ``AES\-128\-WRAP\-INV'', ``AES\-192\-WRAP\-INV'', ``AES\-256\-WRAP\-INV'', ``AES\-128\-WRAP\-PAD\-INV'', ``AES\-192\-WRAP\-PAD\-INV''\s0 and ``\s-1AES\-256\-WRAP\-PAD\-INV''\s0" 4 -.IX Item "AES-128-WRAP, AES-192-WRAP, AES-256-WRAP, AES-128-WRAP-PAD, AES-192-WRAP-PAD, AES-256-WRAP-PAD, AES-128-WRAP-INV, AES-192-WRAP-INV, AES-256-WRAP-INV, AES-128-WRAP-PAD-INV, AES-192-WRAP-PAD-INV and AES-256-WRAP-PAD-INV" -.ie n .IP """\s-1AES\-128\-CBC\-HMAC\-SHA1"", ""AES\-256\-CBC\-HMAC\-SHA1"", ""AES\-128\-CBC\-HMAC\-SHA256""\s0 and ""\s-1AES\-256\-CBC\-HMAC\-SHA256""\s0" 4 -.el .IP "``\s-1AES\-128\-CBC\-HMAC\-SHA1'', ``AES\-256\-CBC\-HMAC\-SHA1'', ``AES\-128\-CBC\-HMAC\-SHA256''\s0 and ``\s-1AES\-256\-CBC\-HMAC\-SHA256''\s0" 4 -.IX Item "AES-128-CBC-HMAC-SHA1, AES-256-CBC-HMAC-SHA1, AES-128-CBC-HMAC-SHA256 and AES-256-CBC-HMAC-SHA256" -.PD -.PP -The following algorithms are available in the default provider, but not the -\&\s-1FIPS\s0 provider: -.ie n .IP """\s-1AES\-128\-OCB"", ""AES\-192\-OCB""\s0 and ""\s-1AES\-256\-OCB""\s0" 4 -.el .IP "``\s-1AES\-128\-OCB'', ``AES\-192\-OCB''\s0 and ``\s-1AES\-256\-OCB''\s0" 4 -.IX Item "AES-128-OCB, AES-192-OCB and AES-256-OCB" -.PD 0 -.ie n .IP """\s-1AES\-128\-SIV"", ""AES\-192\-SIV""\s0 and ""\s-1AES\-256\-SIV""\s0" 4 -.el .IP "``\s-1AES\-128\-SIV'', ``AES\-192\-SIV''\s0 and ``\s-1AES\-256\-SIV''\s0" 4 -.IX Item "AES-128-SIV, AES-192-SIV and AES-256-SIV" -.ie n .IP """\s-1AES\-128\-GCM\-SIV"", ""AES\-192\-GCM\-SIV""\s0 and ""\s-1AES\-256\-GCM\-SIV""\s0" 4 -.el .IP "``\s-1AES\-128\-GCM\-SIV'', ``AES\-192\-GCM\-SIV''\s0 and ``\s-1AES\-256\-GCM\-SIV''\s0" 4 -.IX Item "AES-128-GCM-SIV, AES-192-GCM-SIV and AES-256-GCM-SIV" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The AES-SIV and AES-WRAP mode implementations do not support streaming. That -means to obtain correct results there can be only one \fBEVP_EncryptUpdate\fR\|(3) -or \fBEVP_DecryptUpdate\fR\|(3) call after the initialization of the context. -.PP -The AES-XTS implementations allow streaming to be performed, but each -\&\fBEVP_EncryptUpdate\fR\|(3) or \fBEVP_DecryptUpdate\fR\|(3) call requires each input -to be a multiple of the blocksize. Only the final \fBEVP_EncryptUpdate()\fR or -\&\fBEVP_DecryptUpdate()\fR call can optionally have an input that is not a multiple -of the blocksize but is larger than one block. In that case ciphertext -stealing (\s-1CTS\s0) is used to fill the block. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The GCM-SIV mode ciphers were added in OpenSSL version 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-ARIA.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-ARIA.7ossl deleted file mode 100644 index c95a738d..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-ARIA.7ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-ARIA 7ossl" -.TH EVP_CIPHER-ARIA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-ARIA \- The ARIA EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1ARIA\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the default provider: -.ie n .IP """\s-1ARIA\-128\-CBC"", ""ARIA\-192\-CBC""\s0 and ""\s-1ARIA\-256\-CBC""\s0" 4 -.el .IP "``\s-1ARIA\-128\-CBC'', ``ARIA\-192\-CBC''\s0 and ``\s-1ARIA\-256\-CBC''\s0" 4 -.IX Item "ARIA-128-CBC, ARIA-192-CBC and ARIA-256-CBC" -.PD 0 -.ie n .IP """\s-1ARIA\-128\-CFB"", ""ARIA\-192\-CFB"", ""ARIA\-256\-CFB"", ""ARIA\-128\-CFB1"", ""ARIA\-192\-CFB1"", ""ARIA\-256\-CFB1"", ""ARIA\-128\-CFB8"", ""ARIA\-192\-CFB8""\s0 and ""\s-1ARIA\-256\-CFB8""\s0" 4 -.el .IP "``\s-1ARIA\-128\-CFB'', ``ARIA\-192\-CFB'', ``ARIA\-256\-CFB'', ``ARIA\-128\-CFB1'', ``ARIA\-192\-CFB1'', ``ARIA\-256\-CFB1'', ``ARIA\-128\-CFB8'', ``ARIA\-192\-CFB8''\s0 and ``\s-1ARIA\-256\-CFB8''\s0" 4 -.IX Item "ARIA-128-CFB, ARIA-192-CFB, ARIA-256-CFB, ARIA-128-CFB1, ARIA-192-CFB1, ARIA-256-CFB1, ARIA-128-CFB8, ARIA-192-CFB8 and ARIA-256-CFB8" -.ie n .IP """\s-1ARIA\-128\-CTR"", ""ARIA\-192\-CTR""\s0 and ""\s-1ARIA\-256\-CTR""\s0" 4 -.el .IP "``\s-1ARIA\-128\-CTR'', ``ARIA\-192\-CTR''\s0 and ``\s-1ARIA\-256\-CTR''\s0" 4 -.IX Item "ARIA-128-CTR, ARIA-192-CTR and ARIA-256-CTR" -.ie n .IP """\s-1ARIA\-128\-ECB"", ""ARIA\-192\-ECB""\s0 and ""\s-1ARIA\-256\-ECB""\s0" 4 -.el .IP "``\s-1ARIA\-128\-ECB'', ``ARIA\-192\-ECB''\s0 and ``\s-1ARIA\-256\-ECB''\s0" 4 -.IX Item "ARIA-128-ECB, ARIA-192-ECB and ARIA-256-ECB" -.ie n .IP """\s-1AES\-192\-OCB"", ""AES\-128\-OCB""\s0 and ""\s-1AES\-256\-OCB""\s0" 4 -.el .IP "``\s-1AES\-192\-OCB'', ``AES\-128\-OCB''\s0 and ``\s-1AES\-256\-OCB''\s0" 4 -.IX Item "AES-192-OCB, AES-128-OCB and AES-256-OCB" -.ie n .IP """\s-1ARIA\-128\-OFB"", ""ARIA\-192\-OFB""\s0 and ""\s-1ARIA\-256\-OFB""\s0" 4 -.el .IP "``\s-1ARIA\-128\-OFB'', ``ARIA\-192\-OFB''\s0 and ``\s-1ARIA\-256\-OFB''\s0" 4 -.IX Item "ARIA-128-OFB, ARIA-192-OFB and ARIA-256-OFB" -.ie n .IP """\s-1ARIA\-128\-CCM"", ""ARIA\-192\-CCM""\s0 and ""\s-1ARIA\-256\-CCM""\s0" 4 -.el .IP "``\s-1ARIA\-128\-CCM'', ``ARIA\-192\-CCM''\s0 and ``\s-1ARIA\-256\-CCM''\s0" 4 -.IX Item "ARIA-128-CCM, ARIA-192-CCM and ARIA-256-CCM" -.ie n .IP """\s-1ARIA\-128\-GCM"", ""ARIA\-192\-GCM""\s0 and ""\s-1ARIA\-256\-GCM""\s0" 4 -.el .IP "``\s-1ARIA\-128\-GCM'', ``ARIA\-192\-GCM''\s0 and ``\s-1ARIA\-256\-GCM''\s0" 4 -.IX Item "ARIA-128-GCM, ARIA-192-GCM and ARIA-256-GCM" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-BLOWFISH.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-BLOWFISH.7ossl deleted file mode 100644 index 47eca097..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-BLOWFISH.7ossl +++ /dev/null @@ -1,177 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-BLOWFISH 7ossl" -.TH EVP_CIPHER-BLOWFISH 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-BLOWFISH \- The BLOBFISH EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1BLOWFISH\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the legacy provider: -.ie n .IP """BF-ECB""" 4 -.el .IP "``BF-ECB''" 4 -.IX Item "BF-ECB" -.PD 0 -.ie n .IP """BF-CBC""" 4 -.el .IP "``BF-CBC''" 4 -.IX Item "BF-CBC" -.ie n .IP """BF-OFB""" 4 -.el .IP "``BF-OFB''" 4 -.IX Item "BF-OFB" -.ie n .IP """BF-CFB""" 4 -.el .IP "``BF-CFB''" 4 -.IX Item "BF-CFB" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-CAMELLIA.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-CAMELLIA.7ossl deleted file mode 100644 index ed912e22..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-CAMELLIA.7ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-CAMELLIA 7ossl" -.TH EVP_CIPHER-CAMELLIA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-CAMELLIA \- The CAMELLIA EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1CAMELLIA\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the default provider: -.ie n .IP """\s-1CAMELLIA\-128\-CBC"", ""CAMELLIA\-192\-CBC""\s0 and ""\s-1CAMELLIA\-256\-CBC""\s0" 4 -.el .IP "``\s-1CAMELLIA\-128\-CBC'', ``CAMELLIA\-192\-CBC''\s0 and ``\s-1CAMELLIA\-256\-CBC''\s0" 4 -.IX Item "CAMELLIA-128-CBC, CAMELLIA-192-CBC and CAMELLIA-256-CBC" -.PD 0 -.ie n .IP """\s-1CAMELLIA\-128\-CBC\-CTS"", ""CAMELLIA\-192\-CBC\-CTS""\s0 and ""\s-1CAMELLIA\-256\-CBC\-CTS""\s0" 4 -.el .IP "``\s-1CAMELLIA\-128\-CBC\-CTS'', ``CAMELLIA\-192\-CBC\-CTS''\s0 and ``\s-1CAMELLIA\-256\-CBC\-CTS''\s0" 4 -.IX Item "CAMELLIA-128-CBC-CTS, CAMELLIA-192-CBC-CTS and CAMELLIA-256-CBC-CTS" -.ie n .IP """\s-1CAMELLIA\-128\-CFB"", ""CAMELLIA\-192\-CFB"", ""CAMELLIA\-256\-CFB"", ""CAMELLIA\-128\-CFB1"", ""CAMELLIA\-192\-CFB1"", ""CAMELLIA\-256\-CFB1"", ""CAMELLIA\-128\-CFB8"", ""CAMELLIA\-192\-CFB8""\s0 and ""\s-1CAMELLIA\-256\-CFB8""\s0" 4 -.el .IP "``\s-1CAMELLIA\-128\-CFB'', ``CAMELLIA\-192\-CFB'', ``CAMELLIA\-256\-CFB'', ``CAMELLIA\-128\-CFB1'', ``CAMELLIA\-192\-CFB1'', ``CAMELLIA\-256\-CFB1'', ``CAMELLIA\-128\-CFB8'', ``CAMELLIA\-192\-CFB8''\s0 and ``\s-1CAMELLIA\-256\-CFB8''\s0" 4 -.IX Item "CAMELLIA-128-CFB, CAMELLIA-192-CFB, CAMELLIA-256-CFB, CAMELLIA-128-CFB1, CAMELLIA-192-CFB1, CAMELLIA-256-CFB1, CAMELLIA-128-CFB8, CAMELLIA-192-CFB8 and CAMELLIA-256-CFB8" -.ie n .IP """\s-1CAMELLIA\-128\-CTR"", ""CAMELLIA\-192\-CTR""\s0 and ""\s-1CAMELLIA\-256\-CTR""\s0" 4 -.el .IP "``\s-1CAMELLIA\-128\-CTR'', ``CAMELLIA\-192\-CTR''\s0 and ``\s-1CAMELLIA\-256\-CTR''\s0" 4 -.IX Item "CAMELLIA-128-CTR, CAMELLIA-192-CTR and CAMELLIA-256-CTR" -.ie n .IP """\s-1CAMELLIA\-128\-ECB"", ""CAMELLIA\-192\-ECB""\s0 and ""\s-1CAMELLIA\-256\-ECB""\s0" 4 -.el .IP "``\s-1CAMELLIA\-128\-ECB'', ``CAMELLIA\-192\-ECB''\s0 and ``\s-1CAMELLIA\-256\-ECB''\s0" 4 -.IX Item "CAMELLIA-128-ECB, CAMELLIA-192-ECB and CAMELLIA-256-ECB" -.ie n .IP """\s-1CAMELLIA\-192\-OFB"", ""CAMELLIA\-128\-OFB""\s0 and ""\s-1CAMELLIA\-256\-OFB""\s0" 4 -.el .IP "``\s-1CAMELLIA\-192\-OFB'', ``CAMELLIA\-128\-OFB''\s0 and ``\s-1CAMELLIA\-256\-OFB''\s0" 4 -.IX Item "CAMELLIA-192-OFB, CAMELLIA-128-OFB and CAMELLIA-256-OFB" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-CAST.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-CAST.7ossl deleted file mode 100644 index 9c16d9b6..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-CAST.7ossl +++ /dev/null @@ -1,177 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-CAST 7ossl" -.TH EVP_CIPHER-CAST 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-CAST \- The CAST EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1CAST\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the legacy provider: -.ie n .IP """\s-1CAST\-128\-CBC"", ""CAST\-192\-CBC""\s0 and ""\s-1CAST\-256\-CBC""\s0" 4 -.el .IP "``\s-1CAST\-128\-CBC'', ``CAST\-192\-CBC''\s0 and ``\s-1CAST\-256\-CBC''\s0" 4 -.IX Item "CAST-128-CBC, CAST-192-CBC and CAST-256-CBC" -.PD 0 -.ie n .IP """\s-1CAST\-128\-CFB"", ""CAST\-192\-CFB"", ""CAST\-256\-CFB""\s0" 4 -.el .IP "``\s-1CAST\-128\-CFB'', ``CAST\-192\-CFB'', ``CAST\-256\-CFB''\s0" 4 -.IX Item "CAST-128-CFB, CAST-192-CFB, CAST-256-CFB" -.ie n .IP """\s-1CAST\-128\-ECB"", ""CAST\-192\-ECB""\s0 and ""\s-1CAST\-256\-ECB""\s0" 4 -.el .IP "``\s-1CAST\-128\-ECB'', ``CAST\-192\-ECB''\s0 and ``\s-1CAST\-256\-ECB''\s0" 4 -.IX Item "CAST-128-ECB, CAST-192-ECB and CAST-256-ECB" -.ie n .IP """\s-1CAST\-192\-OFB"", ""CAST\-128\-OFB""\s0 and ""\s-1CAST\-256\-OFB""\s0" 4 -.el .IP "``\s-1CAST\-192\-OFB'', ``CAST\-128\-OFB''\s0 and ``\s-1CAST\-256\-OFB''\s0" 4 -.IX Item "CAST-192-OFB, CAST-128-OFB and CAST-256-OFB" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-CHACHA.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-CHACHA.7ossl deleted file mode 100644 index 146b2283..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-CHACHA.7ossl +++ /dev/null @@ -1,171 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-CHACHA 7ossl" -.TH EVP_CIPHER-CHACHA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-CHACHA \- The CHACHA EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1CHACHA\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the default provider: -.ie n .IP """ChaCha20""" 4 -.el .IP "``ChaCha20''" 4 -.IX Item "ChaCha20" -.PD 0 -.ie n .IP """ChaCha20\-Poly1305""" 4 -.el .IP "``ChaCha20\-Poly1305''" 4 -.IX Item "ChaCha20-Poly1305" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-DES.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-DES.7ossl deleted file mode 100644 index e54f369a..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-DES.7ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-DES 7ossl" -.TH EVP_CIPHER-DES 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-DES \- The DES EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1DES\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the \s-1FIPS\s0 provider as well as the -default provider: -.ie n .IP """\s-1DES\-EDE3\-ECB""\s0 or ""\s-1DES\-EDE3""\s0" 4 -.el .IP "``\s-1DES\-EDE3\-ECB''\s0 or ``\s-1DES\-EDE3''\s0" 4 -.IX Item "DES-EDE3-ECB or DES-EDE3" -.PD 0 -.ie n .IP """\s-1DES\-EDE3\-CBC""\s0 or ""\s-1DES3""\s0" 4 -.el .IP "``\s-1DES\-EDE3\-CBC''\s0 or ``\s-1DES3''\s0" 4 -.IX Item "DES-EDE3-CBC or DES3" -.PD -.PP -The following algorithms are available in the default provider, but not the -\&\s-1FIPS\s0 provider: -.ie n .IP """\s-1DES\-EDE3\-CFB8""\s0 and ""\s-1DES\-EDE3\-CFB1""\s0" 4 -.el .IP "``\s-1DES\-EDE3\-CFB8''\s0 and ``\s-1DES\-EDE3\-CFB1''\s0" 4 -.IX Item "DES-EDE3-CFB8 and DES-EDE3-CFB1" -.PD 0 -.ie n .IP """DES-EDE-ECB"" or ""DES-EDE""" 4 -.el .IP "``DES-EDE-ECB'' or ``DES-EDE''" 4 -.IX Item "DES-EDE-ECB or DES-EDE" -.ie n .IP """DES-EDE-CBC""" 4 -.el .IP "``DES-EDE-CBC''" 4 -.IX Item "DES-EDE-CBC" -.ie n .IP """DES-EDE-OFB""" 4 -.el .IP "``DES-EDE-OFB''" 4 -.IX Item "DES-EDE-OFB" -.ie n .IP """DES-EDE-CFB""" 4 -.el .IP "``DES-EDE-CFB''" 4 -.IX Item "DES-EDE-CFB" -.ie n .IP """\s-1DES3\-WRAP""\s0" 4 -.el .IP "``\s-1DES3\-WRAP''\s0" 4 -.IX Item "DES3-WRAP" -.PD -.PP -The following algorithms are available in the legacy provider: -.ie n .IP """DES-ECB""" 4 -.el .IP "``DES-ECB''" 4 -.IX Item "DES-ECB" -.PD 0 -.ie n .IP """DES-CBC""" 4 -.el .IP "``DES-CBC''" 4 -.IX Item "DES-CBC" -.ie n .IP """DES-OFB""" 4 -.el .IP "``DES-OFB''" 4 -.IX Item "DES-OFB" -.ie n .IP """DES-CFB"", ""\s-1DES\-CFB1""\s0 and ""\s-1DES\-CFB8""\s0" 4 -.el .IP "``DES-CFB'', ``\s-1DES\-CFB1''\s0 and ``\s-1DES\-CFB8''\s0" 4 -.IX Item "DES-CFB, DES-CFB1 and DES-CFB8" -.ie n .IP """DESX-CBC""" 4 -.el .IP "``DESX-CBC''" 4 -.IX Item "DESX-CBC" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3) including \*(L"encrypt-check\*(R" and \*(L"fips-indicator\*(R". -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7), -\&\fBOSSL_PROVIDER\-legacy\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-IDEA.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-IDEA.7ossl deleted file mode 100644 index 89c59d1c..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-IDEA.7ossl +++ /dev/null @@ -1,177 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-IDEA 7ossl" -.TH EVP_CIPHER-IDEA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-IDEA \- The IDEA EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1IDEA\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the legacy provider: -.ie n .IP """IDEA-ECB""" 4 -.el .IP "``IDEA-ECB''" 4 -.IX Item "IDEA-ECB" -.PD 0 -.ie n .IP """IDEA-CBC""" 4 -.el .IP "``IDEA-CBC''" 4 -.IX Item "IDEA-CBC" -.ie n .IP """IDEA-OFB"" or ""\s-1IDEA\-OFB64""\s0" 4 -.el .IP "``IDEA-OFB'' or ``\s-1IDEA\-OFB64''\s0" 4 -.IX Item "IDEA-OFB or IDEA-OFB64" -.ie n .IP """IDEA-CFB"" or ""\s-1IDEA\-CFB64""\s0" 4 -.el .IP "``IDEA-CFB'' or ``\s-1IDEA\-CFB64''\s0" 4 -.IX Item "IDEA-CFB or IDEA-CFB64" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-NULL.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-NULL.7ossl deleted file mode 100644 index 597ef8bb..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-NULL.7ossl +++ /dev/null @@ -1,199 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-NULL 7ossl" -.TH EVP_CIPHER-NULL 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-NULL \- The NULL EVP_CIPHER implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for a \s-1NULL\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -This is used when the \s-1TLS\s0 cipher suite is \s-1TLS_NULL_WITH_NULL_NULL.\s0 -This does no encryption (just copies the data) and has a mac size of zero. -.SS "Algorithm Name" -.IX Subsection "Algorithm Name" -The following algorithm is available in the default provider: -.ie n .IP """\s-1NULL""\s0" 4 -.el .IP "``\s-1NULL''\s0" 4 -.IX Item "NULL" -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the following parameters: -.PP -\fIGettable \s-1EVP_CIPHER\s0 parameters\fR -.IX Subsection "Gettable EVP_CIPHER parameters" -.PP -See \*(L"Gettable \s-1EVP_CIPHER\s0 parameters\*(R" in \fBEVP_EncryptInit\fR\|(3) -.PP -\fIGettable \s-1EVP_CIPHER_CTX\s0 parameters\fR -.IX Subsection "Gettable EVP_CIPHER_CTX parameters" -.ie n .IP """keylen"" (\fB\s-1OSSL_CIPHER_PARAM_KEYLEN\s0\fR) " 4 -.el .IP "``keylen'' (\fB\s-1OSSL_CIPHER_PARAM_KEYLEN\s0\fR) " 4 -.IX Item "keylen (OSSL_CIPHER_PARAM_KEYLEN) " -.PD 0 -.ie n .IP """ivlen"" (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR and <\fB\s-1OSSL_CIPHER_PARAM_AEAD_IVLEN\s0\fR) " 4 -.el .IP "``ivlen'' (\fB\s-1OSSL_CIPHER_PARAM_IVLEN\s0\fR and <\fB\s-1OSSL_CIPHER_PARAM_AEAD_IVLEN\s0\fR) " 4 -.IX Item "ivlen (OSSL_CIPHER_PARAM_IVLEN and " -.ie n .IP """tls-mac"" (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC\s0\fR) " 4 -.el .IP "``tls-mac'' (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC\s0\fR) " 4 -.IX Item "tls-mac (OSSL_CIPHER_PARAM_TLS_MAC) " -.PD -.PP -See \*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3) for further information. -.PP -\fISettable \s-1EVP_CIPHER_CTX\s0 parameters\fR -.IX Subsection "Settable EVP_CIPHER_CTX parameters" -.ie n .IP """tls-mac-size"" (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC_SIZE\s0\fR) " 4 -.el .IP "``tls-mac-size'' (\fB\s-1OSSL_CIPHER_PARAM_TLS_MAC_SIZE\s0\fR) " 4 -.IX Item "tls-mac-size (OSSL_CIPHER_PARAM_TLS_MAC_SIZE) " -.PP -See \*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3) for further information. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 5246\s0 section\-6.2.3.1 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-RC2.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-RC2.7ossl deleted file mode 100644 index c2e34b3c..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-RC2.7ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-RC2 7ossl" -.TH EVP_CIPHER-RC2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-RC2 \- The RC2 EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1RC2\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the legacy provider: -.ie n .IP """\s-1RC2\-CBC"", ""RC2""\s0 or ""\s-1RC2\-128""\s0" 4 -.el .IP "``\s-1RC2\-CBC'', ``RC2''\s0 or ``\s-1RC2\-128''\s0" 4 -.IX Item "RC2-CBC, RC2 or RC2-128" -.PD 0 -.ie n .IP """\s-1RC2\-40\-CBC""\s0 or ""\s-1RC2\-40""\s0" 4 -.el .IP "``\s-1RC2\-40\-CBC''\s0 or ``\s-1RC2\-40''\s0" 4 -.IX Item "RC2-40-CBC or RC2-40" -.ie n .IP """\s-1RC2\-64\-CBC""\s0 or ""\s-1RC2\-64""\s0" 4 -.el .IP "``\s-1RC2\-64\-CBC''\s0 or ``\s-1RC2\-64''\s0" 4 -.IX Item "RC2-64-CBC or RC2-64" -.ie n .IP """\s-1RC2\-ECB""\s0" 4 -.el .IP "``\s-1RC2\-ECB''\s0" 4 -.IX Item "RC2-ECB" -.ie n .IP """\s-1RC2\-CFB""\s0" 4 -.el .IP "``\s-1RC2\-CFB''\s0" 4 -.IX Item "RC2-CFB" -.ie n .IP """\s-1RC2\-OFB""\s0" 4 -.el .IP "``\s-1RC2\-OFB''\s0" 4 -.IX Item "RC2-OFB" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-RC4.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-RC4.7ossl deleted file mode 100644 index 13113d7a..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-RC4.7ossl +++ /dev/null @@ -1,174 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-RC4 7ossl" -.TH EVP_CIPHER-RC4 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-RC4 \- The RC4 EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1RC4\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the legacy provider: -.ie n .IP """\s-1RC4""\s0" 4 -.el .IP "``\s-1RC4''\s0" 4 -.IX Item "RC4" -.PD 0 -.ie n .IP """\s-1RC4\-40""\s0" 4 -.el .IP "``\s-1RC4\-40''\s0" 4 -.IX Item "RC4-40" -.ie n .IP """\s-1RC4\-HMAC\-MD5""\s0" 4 -.el .IP "``\s-1RC4\-HMAC\-MD5''\s0" 4 -.IX Item "RC4-HMAC-MD5" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-RC5.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-RC5.7ossl deleted file mode 100644 index 3b72202e..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-RC5.7ossl +++ /dev/null @@ -1,179 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-RC5 7ossl" -.TH EVP_CIPHER-RC5 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-RC5 \- The RC5 EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1RC5\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.PP -Disabled by default. Use the \fIenable\-rc5\fR configuration option to enable. -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the legacy provider: -.ie n .IP """\s-1RC5\-CBC""\s0 or ""\s-1RC5""\s0" 4 -.el .IP "``\s-1RC5\-CBC''\s0 or ``\s-1RC5''\s0" 4 -.IX Item "RC5-CBC or RC5" -.PD 0 -.ie n .IP """\s-1RC5\-ECB""\s0" 4 -.el .IP "``\s-1RC5\-ECB''\s0" 4 -.IX Item "RC5-ECB" -.ie n .IP """\s-1RC5\-OFB""\s0" 4 -.el .IP "``\s-1RC5\-OFB''\s0" 4 -.IX Item "RC5-OFB" -.ie n .IP """\s-1RC5\-CFB""\s0" 4 -.el .IP "``\s-1RC5\-CFB''\s0" 4 -.IX Item "RC5-CFB" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-SEED.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-SEED.7ossl deleted file mode 100644 index e25c2669..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-SEED.7ossl +++ /dev/null @@ -1,177 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-SEED 7ossl" -.TH EVP_CIPHER-SEED 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-SEED \- The SEED EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1SEED\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the legacy provider: -.ie n .IP """SEED-CBC"" or ""\s-1SEED""\s0" 4 -.el .IP "``SEED-CBC'' or ``\s-1SEED''\s0" 4 -.IX Item "SEED-CBC or SEED" -.PD 0 -.ie n .IP """SEED-ECB""" 4 -.el .IP "``SEED-ECB''" 4 -.IX Item "SEED-ECB" -.ie n .IP """SEED-OFB"" or ""\s-1SEED\-OFB128""\s0" 4 -.el .IP "``SEED-OFB'' or ``\s-1SEED\-OFB128''\s0" 4 -.IX Item "SEED-OFB or SEED-OFB128" -.ie n .IP """SEED-CFB"" or ""\s-1SEED\-CFB128""\s0" 4 -.el .IP "``SEED-CFB'' or ``\s-1SEED\-CFB128''\s0" 4 -.IX Item "SEED-CFB or SEED-CFB128" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_CIPHER-SM4.7ossl b/openssl-install/share/man/man7/EVP_CIPHER-SM4.7ossl deleted file mode 100644 index 3e88471d..00000000 --- a/openssl-install/share/man/man7/EVP_CIPHER-SM4.7ossl +++ /dev/null @@ -1,197 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_CIPHER-SM4 7ossl" -.TH EVP_CIPHER-SM4 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_CIPHER\-SM4 \- The SM4 EVP_CIPHER implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for \s-1SM4\s0 symmetric encryption using the \fB\s-1EVP_CIPHER\s0\fR \s-1API.\s0 -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -The following algorithms are available in the default provider: -.ie n .IP """\s-1SM4\-CBC:SM4""\s0" 4 -.el .IP "``\s-1SM4\-CBC:SM4''\s0" 4 -.IX Item "SM4-CBC:SM4" -.PD 0 -.ie n .IP """\s-1SM4\-ECB""\s0" 4 -.el .IP "``\s-1SM4\-ECB''\s0" 4 -.IX Item "SM4-ECB" -.ie n .IP """\s-1SM4\-CTR""\s0" 4 -.el .IP "``\s-1SM4\-CTR''\s0" 4 -.IX Item "SM4-CTR" -.ie n .IP """\s-1SM4\-OFB""\s0 or ""\s-1SM4\-OFB128""\s0" 4 -.el .IP "``\s-1SM4\-OFB''\s0 or ``\s-1SM4\-OFB128''\s0" 4 -.IX Item "SM4-OFB or SM4-OFB128" -.ie n .IP """\s-1SM4\-CFB""\s0 or ""\s-1SM4\-CFB128""\s0" 4 -.el .IP "``\s-1SM4\-CFB''\s0 or ``\s-1SM4\-CFB128''\s0" 4 -.IX Item "SM4-CFB or SM4-CFB128" -.ie n .IP """\s-1SM4\-GCM""\s0" 4 -.el .IP "``\s-1SM4\-GCM''\s0" 4 -.IX Item "SM4-GCM" -.ie n .IP """\s-1SM4\-CCM""\s0" 4 -.el .IP "``\s-1SM4\-CCM''\s0" 4 -.IX Item "SM4-CCM" -.ie n .IP """\s-1SM4\-XTS""\s0" 4 -.el .IP "``\s-1SM4\-XTS''\s0" 4 -.IX Item "SM4-XTS" -.PD -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the parameters described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -The \s-1SM4\-XTS\s0 implementation allows streaming to be performed, but each -\&\fBEVP_EncryptUpdate\fR\|(3) or \fBEVP_DecryptUpdate\fR\|(3) call requires each input -to be a multiple of the blocksize. Only the final \fBEVP_EncryptUpdate()\fR or -\&\fBEVP_DecryptUpdate()\fR call can optionally have an input that is not a multiple -of the blocksize but is larger than one block. In that case ciphertext -stealing (\s-1CTS\s0) is used to fill the block. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-ARGON2.7ossl b/openssl-install/share/man/man7/EVP_KDF-ARGON2.7ossl deleted file mode 100644 index 67f817ff..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-ARGON2.7ossl +++ /dev/null @@ -1,326 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-ARGON2 7ossl" -.TH EVP_KDF-ARGON2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-ARGON2 \- The Argon2 EVP KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fBargon2\fR password-based \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR -\&\s-1API.\s0 -.PP -The \s-1EVP_KDF\-ARGON2\s0 algorithm implements the Argon2 password-based key -derivation function, as described in \s-1IETF RFC 9106.\s0 It is memory-hard in -the sense that it deliberately requires a significant amount of \s-1RAM\s0 for efficient -computation. The intention of this is to render brute forcing of passwords on -systems that lack large amounts of main memory (such as GPUs or ASICs) -computationally infeasible. -.PP -Argon2d (Argon2i) uses data-dependent (data-independent) memory access and -primary seek to address trade-off (side-channel) attacks. -.PP -Argon2id is a hybrid construction which, in the first two slices of the first -pass, generates reference addresses data-independently as in Argon2i, whereas -in later slices and next passes it generates them data-dependently as in -Argon2d. -.PP -Sbox-hardened version Argon2ds is not supported. -.PP -For more information, please refer to \s-1RFC 9106.\s0 -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -.PD 0 -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.ie n .IP """secret"" (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.el .IP "``secret'' (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.IX Item "secret (OSSL_KDF_PARAM_SECRET) " -.ie n .IP """iter"" (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.el .IP "``iter'' (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.IX Item "iter (OSSL_KDF_PARAM_ITER) " -.ie n .IP """size"" (\fB\s-1OSSL_KDF_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_KDF_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_KDF_PARAM_SIZE) " -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.Sp -Note that \s-1RFC 9106\s0 recommends 128 bits salt for most applications, or 64 bits -salt in the case of space constraints. At least 128 bits output length is -recommended. -.Sp -Note that secret (or pepper) is an optional secret data used along the -password. -.ie n .IP """threads"" (\fB\s-1OSSL_KDF_PARAM_THREADS\s0\fR) " 4 -.el .IP "``threads'' (\fB\s-1OSSL_KDF_PARAM_THREADS\s0\fR) " 4 -.IX Item "threads (OSSL_KDF_PARAM_THREADS) " -The number of threads, bounded above by the number of lanes. -.Sp -This can only be used with built-in thread support. Threading must be -explicitly enabled. See \s-1EXAMPLES\s0 section for more information. -.ie n .IP """ad"" (\fB\s-1OSSL_KDF_PARAM_ARGON2_AD\s0\fR) " 4 -.el .IP "``ad'' (\fB\s-1OSSL_KDF_PARAM_ARGON2_AD\s0\fR) " 4 -.IX Item "ad (OSSL_KDF_PARAM_ARGON2_AD) " -Optional associated data, may be used to \*(L"tag\*(R" a group of keys, or tie them -to a particular public key, without having to modify salt. -.ie n .IP """lanes"" (\fB\s-1OSSL_KDF_PARAM_ARGON2_LANES\s0\fR) " 4 -.el .IP "``lanes'' (\fB\s-1OSSL_KDF_PARAM_ARGON2_LANES\s0\fR) " 4 -.IX Item "lanes (OSSL_KDF_PARAM_ARGON2_LANES) " -Argon2 splits the requested memory size into lanes, each of which is designed -to be processed in parallel. For example, on a system with p cores, it's -recommended to use p lanes. -.Sp -The number of lanes is used to derive the key. It is possible to specify -more lanes than the number of available computational threads. This is -especially encouraged if multi-threading is disabled. -.ie n .IP """memcost"" (\fB\s-1OSSL_KDF_PARAM_ARGON2_MEMCOST\s0\fR) " 4 -.el .IP "``memcost'' (\fB\s-1OSSL_KDF_PARAM_ARGON2_MEMCOST\s0\fR) " 4 -.IX Item "memcost (OSSL_KDF_PARAM_ARGON2_MEMCOST) " -Memory cost parameter (the number of 1k memory blocks used). -.ie n .IP """version"" (\fB\s-1OSSL_KDF_PARAM_ARGON2_VERSION\s0\fR) " 4 -.el .IP "``version'' (\fB\s-1OSSL_KDF_PARAM_ARGON2_VERSION\s0\fR) " 4 -.IX Item "version (OSSL_KDF_PARAM_ARGON2_VERSION) " -Argon2 version. Supported values: 0x10, 0x13 (default). -.ie n .IP """early_clean"" (\fB\s-1OSSL_KDF_PARAM_EARLY_CLEAN\s0\fR) " 4 -.el .IP "``early_clean'' (\fB\s-1OSSL_KDF_PARAM_EARLY_CLEAN\s0\fR) " 4 -.IX Item "early_clean (OSSL_KDF_PARAM_EARLY_CLEAN) " -If set (nonzero), password and secret stored in Argon2 context are zeroed -early during initial hash computation, as soon as they are not needed. -Otherwise, they are zeroed along the rest of Argon2 context data on clear, -free, reset. -.Sp -This can be useful if, for example, multiple keys with different ad value -are to be generated from a single password and secret. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example uses Argon2d with password \*(L"1234567890\*(R", salt \*(L"saltsalt\*(R", -using 2 lanes, 2 threads, and memory cost of 65536: -.PP -.Vb 5 -\& #include /* strlen */ -\& #include /* OSSL_KDF_* */ -\& #include /* OSSL_PARAM_* */ -\& #include /* OSSL_set_max_threads */ -\& #include /* EVP_KDF_* */ -\& -\& int main(void) -\& { -\& int retval = 1; -\& -\& EVP_KDF *kdf = NULL; -\& EVP_KDF_CTX *kctx = NULL; -\& OSSL_PARAM params[6], *p = params; -\& -\& /* argon2 params, please refer to RFC9106 for recommended defaults */ -\& uint32_t lanes = 2, threads = 2, memcost = 65536; -\& char pwd[] = "1234567890", salt[] = "saltsalt"; -\& -\& /* derive result */ -\& size_t outlen = 128; -\& unsigned char result[outlen]; -\& -\& /* required if threads > 1 */ -\& if (OSSL_set_max_threads(NULL, threads) != 1) -\& goto fail; -\& -\& p = params; -\& *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_THREADS, &threads); -\& *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_ARGON2_LANES, -\& &lanes); -\& *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_ARGON2_MEMCOST, -\& &memcost); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -\& salt, -\& strlen((const char *)salt)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASSWORD, -\& pwd, -\& strlen((const char *)pwd)); -\& *p++ = OSSL_PARAM_construct_end(); -\& -\& if ((kdf = EVP_KDF_fetch(NULL, "ARGON2D", NULL)) == NULL) -\& goto fail; -\& if ((kctx = EVP_KDF_CTX_new(kdf)) == NULL) -\& goto fail; -\& if (EVP_KDF_derive(kctx, &result[0], outlen, params) != 1) -\& goto fail; -\& -\& printf("Output = %s\en", OPENSSL_buf2hexstr(result, outlen)); -\& retval = 0; -\& -\& fail: -\& EVP_KDF_free(kdf); -\& EVP_KDF_CTX_free(kctx); -\& OSSL_set_max_threads(NULL, 0); -\& -\& return retval; -\& } -.Ve -.SH "NOTES" -.IX Header "NOTES" -\&\*(L"\s-1ARGON2I\*(R", \*(L"ARGON2D\*(R",\s0 and \*(L"\s-1ARGON2ID\*(R"\s0 are the names for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 9106\s0 Argon2, see . -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added to OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-HKDF.7ossl b/openssl-install/share/man/man7/EVP_KDF-HKDF.7ossl deleted file mode 100644 index 46f4d564..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-HKDF.7ossl +++ /dev/null @@ -1,307 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-HKDF 7ossl" -.TH EVP_KDF-HKDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-HKDF \- The HKDF EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fB\s-1HKDF\s0\fR \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR \s-1API.\s0 -.PP -The \s-1EVP_KDF\-HKDF\s0 algorithm implements the \s-1HKDF\s0 key derivation function. -\&\s-1HKDF\s0 follows the \*(L"extract-then-expand\*(R" paradigm, where the \s-1KDF\s0 logically -consists of two modules. The first stage takes the input keying material -and \*(L"extracts\*(R" from it a fixed-length pseudorandom key K. The second stage -\&\*(L"expands\*(R" the key K into several additional pseudorandom keys (the output -of the \s-1KDF\s0). -.PP -The output is considered to be keying material. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1HKDF\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """info"" (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.el .IP "``info'' (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.IX Item "info (OSSL_KDF_PARAM_INFO) " -This parameter sets the info value. -The length of the context info buffer cannot exceed 1024 bytes; -this should be more than enough for any normal use of \s-1HKDF.\s0 -.ie n .IP """mode"" (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string> or " 4 -.el .IP "``mode'' (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string> or " 4 -.IX Item "mode (OSSL_KDF_PARAM_MODE) or " -This parameter sets the mode for the \s-1HKDF\s0 operation. -There are three modes that are currently defined: -.RS 4 -.ie n .IP """\s-1EXTRACT_AND_EXPAND""\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXTRACT_AND_EXPAND\s0\fR" 4 -.el .IP "``\s-1EXTRACT_AND_EXPAND''\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXTRACT_AND_EXPAND\s0\fR" 4 -.IX Item "EXTRACT_AND_EXPAND or EVP_KDF_HKDF_MODE_EXTRACT_AND_EXPAND" -This is the default mode. Calling \fBEVP_KDF_derive\fR\|(3) on an \s-1EVP_KDF_CTX\s0 set -up for \s-1HKDF\s0 will perform an extract followed by an expand operation in one go. -The derived key returned will be the result after the expand operation. The -intermediate fixed-length pseudorandom key K is not returned. -.Sp -In this mode the digest, key, salt and info values must be set before a key is -derived otherwise an error will occur. -.ie n .IP """\s-1EXTRACT_ONLY""\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXTRACT_ONLY\s0\fR" 4 -.el .IP "``\s-1EXTRACT_ONLY''\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXTRACT_ONLY\s0\fR" 4 -.IX Item "EXTRACT_ONLY or EVP_KDF_HKDF_MODE_EXTRACT_ONLY" -In this mode calling \fBEVP_KDF_derive\fR\|(3) will just perform the extract -operation. The value returned will be the intermediate fixed-length pseudorandom -key K. The \fIkeylen\fR parameter must match the size of K, which can be looked -up by calling \fBEVP_KDF_CTX_get_kdf_size()\fR after setting the mode and digest. -.Sp -The digest, key and salt values must be set before a key is derived otherwise -an error will occur. -.ie n .IP """\s-1EXPAND_ONLY""\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXPAND_ONLY\s0\fR" 4 -.el .IP "``\s-1EXPAND_ONLY''\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXPAND_ONLY\s0\fR" 4 -.IX Item "EXPAND_ONLY or EVP_KDF_HKDF_MODE_EXPAND_ONLY" -In this mode calling \fBEVP_KDF_derive\fR\|(3) will just perform the expand -operation. The input key should be set to the intermediate fixed-length -pseudorandom key K returned from a previous extract operation. -.Sp -The digest, key and info values must be set before a key is derived otherwise -an error will occur. -.RE -.RS 4 -.RE -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if \*(L"key-check\*(R" -is set to 0 and the check fails. -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1HKDF\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "HKDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of an \s-1HKDF\s0 expand operation is specified via the \fIkeylen\fR -parameter to the \fBEVP_KDF_derive\fR\|(3) function. When using -\&\s-1EVP_KDF_HKDF_MODE_EXTRACT_ONLY\s0 the \fIkeylen\fR parameter must equal the size of -the intermediate fixed-length pseudorandom key otherwise an error will occur. -For that mode, the fixed output size can be looked up by calling \fBEVP_KDF_CTX_get_kdf_size()\fR -after setting the mode and digest on the \fB\s-1EVP_KDF_CTX\s0\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 10 bytes using \s-1SHA\-256\s0 with the secret key \*(L"secret\*(R", -salt value \*(L"salt\*(R" and info value \*(L"label\*(R": -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[5], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "HKDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -\& SN_sha256, strlen(SN_sha256)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -\& "secret", (size_t)6); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -\& "label", (size_t)5); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -\& "salt", (size_t)4); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { -\& error("EVP_KDF_derive"); -\& } -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 5869\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3), -\&\s-1\fBEVP_KDF\-TLS13_KDF\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-HMAC-DRBG.7ossl b/openssl-install/share/man/man7/EVP_KDF-HMAC-DRBG.7ossl deleted file mode 100644 index 3f01aede..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-HMAC-DRBG.7ossl +++ /dev/null @@ -1,199 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-HMAC-DRBG 7ossl" -.TH EVP_KDF-HMAC-DRBG 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-HMAC\-DRBG -\&\- The HMAC DRBG DETERMINISTIC EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for a deterministic \s-1HMAC DRBG\s0 using the \fB\s-1EVP_KDF\s0\fR \s-1API.\s0 This is similar -to \s-1\fBEVP_RAND\-HMAC\-DRBG\s0\fR\|(7), but uses fixed values for its entropy and nonce -values. This is used to generate deterministic nonce value required by \s-1ECDSA\s0 -and \s-1DSA\s0 (as defined in \s-1RFC 6979\s0). -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"HMAC-DRBG-KDF\*(R" is the name for this implementation; it can be used -with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """digest"" (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_DRBG_PARAM_DIGEST) " -.PD 0 -.ie n .IP """properties"" (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_DRBG_PARAM_PROPERTIES) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """entropy"" (\fB\s-1OSSL_KDF_PARAM_HMACDRBG_ENTROPY\s0\fR) " 4 -.el .IP "``entropy'' (\fB\s-1OSSL_KDF_PARAM_HMACDRBG_ENTROPY\s0\fR) " 4 -.IX Item "entropy (OSSL_KDF_PARAM_HMACDRBG_ENTROPY) " -Sets the entropy bytes supplied to the HMAC-DRBG. -.ie n .IP """nonce"" (\fB\s-1OSSL_KDF_PARAM_HMACDRBG_NONCE\s0\fR) " 4 -.el .IP "``nonce'' (\fB\s-1OSSL_KDF_PARAM_HMACDRBG_NONCE\s0\fR) " 4 -.IX Item "nonce (OSSL_KDF_PARAM_HMACDRBG_NONCE) " -Sets the nonce bytes supplied to the HMAC-DRBG. -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1KDF HMAC DRBG\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "HMAC\-DRBG\-KDF", NULL); -\& EVP_KDF_CTX *kdf_ctx = EVP_KDF_CTX_new(kdf, NULL); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 6979\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1EVP_KDF\-HMAC\-DRBG\s0 functionality was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-KB.7ossl b/openssl-install/share/man/man7/EVP_KDF-KB.7ossl deleted file mode 100644 index 8d3a272e..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-KB.7ossl +++ /dev/null @@ -1,336 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-KB 7ossl" -.TH EVP_KDF-KB 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-KB \- The Key\-Based EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP_KDF\-KB\s0 algorithm implements the Key-Based key derivation function -(\s-1KBKDF\s0). \s-1KBKDF\s0 derives a key from repeated application of a keyed \s-1MAC\s0 to an -input secret (and other optional values). -.PP -The output is considered to be keying material. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1KBKDF\*(R"\s0 is the name for this implementation; it can be used with the -\&\fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """mode"" (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mode'' (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mode (OSSL_KDF_PARAM_MODE) " -The mode parameter determines which flavor of \s-1KBKDF\s0 to use \- currently the -choices are \*(L"counter\*(R" and \*(L"feedback\*(R". \*(L"counter\*(R" is the default, and will be -used if unspecified. -.ie n .IP """mac"" (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mac'' (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mac (OSSL_KDF_PARAM_MAC) " -The value is either \s-1CMAC, HMAC, KMAC128\s0 or \s-1KMAC256.\s0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD 0 -.ie n .IP """cipher"" (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_KDF_PARAM_CIPHER) " -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.IP """info (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.IX Item """info (OSSL_KDF_PARAM_INFO) " -.ie n .IP """seed"" (\fB\s-1OSSL_KDF_PARAM_SEED\s0\fR) " 4 -.el .IP "``seed'' (\fB\s-1OSSL_KDF_PARAM_SEED\s0\fR) " 4 -.IX Item "seed (OSSL_KDF_PARAM_SEED) " -.PD -The seed parameter is unused in counter mode. -.ie n .IP """use-l"" (\fB\s-1OSSL_KDF_PARAM_KBKDF_USE_L\s0\fR) " 4 -.el .IP "``use-l'' (\fB\s-1OSSL_KDF_PARAM_KBKDF_USE_L\s0\fR) " 4 -.IX Item "use-l (OSSL_KDF_PARAM_KBKDF_USE_L) " -Set to \fB0\fR to disable use of the optional Fixed Input data 'L' (see \s-1SP800\-108\s0). -The default value of \fB1\fR will be used if unspecified. -.ie n .IP """use-separator"" (\fB\s-1OSSL_KDF_PARAM_KBKDF_USE_SEPARATOR\s0\fR) " 4 -.el .IP "``use-separator'' (\fB\s-1OSSL_KDF_PARAM_KBKDF_USE_SEPARATOR\s0\fR) " 4 -.IX Item "use-separator (OSSL_KDF_PARAM_KBKDF_USE_SEPARATOR) " -Set to \fB0\fR to disable use of the optional Fixed Input data 'zero separator' -(see \s-1SP800\-108\s0) that is placed between the Label and Context. -The default value of \fB1\fR will be used if unspecified. -.ie n .IP """r"" (\fB\s-1OSSL_KDF_PARAM_KBKDF_R\s0\fR) " 4 -.el .IP "``r'' (\fB\s-1OSSL_KDF_PARAM_KBKDF_R\s0\fR) " 4 -.IX Item "r (OSSL_KDF_PARAM_KBKDF_R) " -Set the fixed value 'r', indicating the length of the counter in bits. -.Sp -Supported values are \fB8\fR, \fB16\fR, \fB24\fR, and \fB32\fR. -The default value of \fB32\fR will be used if unspecified. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if \*(L"key-check\*(R" -is set to 0 and the check fails. -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.PP -Depending on whether mac is \s-1CMAC\s0 or \s-1HMAC,\s0 either digest or cipher is required -(respectively) and the other is unused. They are unused for \s-1KMAC128\s0 and \s-1KMAC256.\s0 -.PP -The parameters key, salt, info, and seed correspond to \s-1KI,\s0 Label, Context, and -\&\s-1IV\s0 (respectively) in \s-1SP800\-108.\s0 As in that document, salt, info, and seed are -optional and may be omitted. -.PP -\&\*(L"mac\*(R", \*(L"digest\*(R", cipher\*(L" and \*(R"properties" are described in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1KBKDF\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of an \s-1KBKDF\s0 is specified via the \f(CW\*(C`keylen\*(C'\fR -parameter to the \fBEVP_KDF_derive\fR\|(3) function. -.PP -Note that currently OpenSSL only implements counter and feedback modes. Other -variants may be supported in the future. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 10 bytes using \s-1COUNTER\-HMAC\-SHA256,\s0 with \s-1KI\s0 \*(L"secret\*(R", -Label \*(L"label\*(R", and Context \*(L"context\*(R". -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[6], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -\& "SHA2\-256", 0); -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, -\& "HMAC", 0); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -\& "secret", strlen("secret")); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -\& "label", strlen("label")); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -\& "context", strlen("context")); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) -\& error("EVP_KDF_derive"); -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.PP -This example derives 10 bytes using \s-1FEEDBACK\-CMAC\-AES256,\s0 with \s-1KI\s0 \*(L"secret\*(R", -Label \*(L"label\*(R", and \s-1IV\s0 \*(L"sixteen bytes iv\*(R". -.PP -.Vb 5 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[8], *p = params; -\& unsigned char *iv = "sixteen bytes iv"; -\& -\& kdf = EVP_KDF_fetch(NULL, "KBKDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, "AES256", 0); -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, "CMAC", 0); -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MODE, "FEEDBACK", 0); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -\& "secret", strlen("secret")); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -\& "label", strlen("label")); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -\& "context", strlen("context")); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SEED, -\& iv, strlen(iv)); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) -\& error("EVP_KDF_derive"); -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST SP800\-108, IETF RFC 6803, IETF RFC 8009.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.PP -Support for \s-1KMAC\s0 was added in OpenSSL 3.1. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -Copyright 2019 Red Hat, Inc. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-KRB5KDF.7ossl b/openssl-install/share/man/man7/EVP_KDF-KRB5KDF.7ossl deleted file mode 100644 index 75797024..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-KRB5KDF.7ossl +++ /dev/null @@ -1,244 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-KRB5KDF 7ossl" -.TH EVP_KDF-KRB5KDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-KRB5KDF \- The RFC3961 Krb5 KDF EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fB\s-1KRB5KDF\s0\fR \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR \s-1API.\s0 -.PP -The \s-1EVP_KDF\-KRB5KDF\s0 algorithm implements the key derivation function defined -in \s-1RFC 3961,\s0 section 5.1 and is used by Krb5 to derive session keys. -Three inputs are required to perform key derivation: a cipher, (for example -\&\s-1AES\-128\-CBC\s0), the initial key, and a constant. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1KRB5KDF\*(R"\s0 is the name for this implementation; -it can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """cipher"" (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_KDF_PARAM_CIPHER) " -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """constant"" (\fB\s-1OSSL_KDF_PARAM_CONSTANT\s0\fR) " 4 -.el .IP "``constant'' (\fB\s-1OSSL_KDF_PARAM_CONSTANT\s0\fR) " 4 -.IX Item "constant (OSSL_KDF_PARAM_CONSTANT) " -This parameter sets the constant value for the \s-1KDF.\s0 -If a value is already set, the contents are replaced. -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1KRB5KDF\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of the \s-1KRB5KDF\s0 derivation is specified via the \fIkeylen\fR -parameter to the \fBEVP_KDF_derive\fR\|(3) function, and \s-1MUST\s0 match the key -length for the chosen cipher or an error is returned. Moreover, the -constant's length must not exceed the block size of the cipher. -Since the \s-1KRB5KDF\s0 output length depends on the chosen cipher, calling -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3) to obtain the requisite length returns the correct length -only after the cipher is set. Prior to that \fB\s-1EVP_MAX_KEY_LENGTH\s0\fR is returned. -The caller must allocate a buffer of the correct length for the chosen -cipher, and pass that buffer to the \fBEVP_KDF_derive\fR\|(3) function along -with that length. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives a key using the \s-1AES\-128\-CBC\s0 cipher: -.PP -.Vb 7 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char key[16] = "01234..."; -\& unsigned char constant[] = "I\*(Aqm a constant"; -\& unsigned char out[16]; -\& size_t outlen = sizeof(out); -\& OSSL_PARAM params[4], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "KRB5KDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, -\& SN_aes_128_cbc, -\& strlen(SN_aes_128_cbc)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -\& key, (size_t)16); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_CONSTANT, -\& constant, strlen(constant)); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, outlen, params) <= 0) -\& /* Error */ -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 3961\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-PBKDF1.7ossl b/openssl-install/share/man/man7/EVP_KDF-PBKDF1.7ossl deleted file mode 100644 index bbd26f6c..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-PBKDF1.7ossl +++ /dev/null @@ -1,215 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-PBKDF1 7ossl" -.TH EVP_KDF-PBKDF1 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-PBKDF1 \- The PBKDF1 EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fB\s-1PBKDF1\s0\fR password-based \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR -\&\s-1API.\s0 -.PP -The \s-1EVP_KDF\-PBKDF1\s0 algorithm implements the \s-1PBKDF1\s0 password-based key -derivation function, as described in \s-1RFC 8018\s0; it derives a key from a password -using a salt and iteration count. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1PBKDF1\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -.PD 0 -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.ie n .IP """iter"" (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.el .IP "``iter'' (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.IX Item "iter (OSSL_KDF_PARAM_ITER) " -.PD -This parameter has a default value of 0 and should be set. -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -A typical application of this algorithm is to derive keying material for an -encryption algorithm from a password in the \*(L"pass\*(R", a salt in \*(L"salt\*(R", -and an iteration count. -.PP -Increasing the \*(L"iter\*(R" parameter slows down the algorithm which makes it -harder for an attacker to perform a brute force attack using a large number -of candidate passwords. -.PP -No assumption is made regarding the given password; it is simply treated as a -byte sequence. -.PP -The legacy provider needs to be available in order to access this algorithm. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 8018\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-PBKDF2.7ossl b/openssl-install/share/man/man7/EVP_KDF-PBKDF2.7ossl deleted file mode 100644 index c24edb75..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-PBKDF2.7ossl +++ /dev/null @@ -1,247 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-PBKDF2 7ossl" -.TH EVP_KDF-PBKDF2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-PBKDF2 \- The PBKDF2 EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fB\s-1PBKDF2\s0\fR password-based \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR -\&\s-1API.\s0 -.PP -The \s-1EVP_KDF\-PBKDF2\s0 algorithm implements the \s-1PBKDF2\s0 password-based key -derivation function, as described in \s-1SP800\-132\s0; it derives a key from a password -using a salt and iteration count. -.PP -The output is considered to be a cryptographic key. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1PBKDF2\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -.PD 0 -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.ie n .IP """iter"" (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.el .IP "``iter'' (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.IX Item "iter (OSSL_KDF_PARAM_ITER) " -.PD -This parameter has a default value of 2048. -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """pkcs5"" (\fB\s-1OSSL_KDF_PARAM_PKCS5\s0\fR) " 4 -.el .IP "``pkcs5'' (\fB\s-1OSSL_KDF_PARAM_PKCS5\s0\fR) " 4 -.IX Item "pkcs5 (OSSL_KDF_PARAM_PKCS5) " -This parameter can be used to enable or disable \s-1SP800\-132\s0 compliance checks. -Setting the mode to 0 enables the compliance checks. -.Sp -The checks performed are: -.RS 4 -.IP "\- the iteration count is at least 1000." 4 -.IX Item "- the iteration count is at least 1000." -.PD 0 -.IP "\- the salt length is at least 128 bits." 4 -.IX Item "- the salt length is at least 128 bits." -.IP "\- the derived key length is at least 112 bits." 4 -.IX Item "- the derived key length is at least 112 bits." -.RE -.RS 4 -.PD -.Sp -The default provider uses a default mode of 1 for backwards compatibility, -and the \s-1FIPS\s0 provider uses a default mode of 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.RE -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -This option is used by the OpenSSL \s-1FIPS\s0 provider. -.Sp -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if \*(L"pkcs5\*(R" -is set to 1 and the derived key length, salt length or iteration count test -fails. -.SH "NOTES" -.IX Header "NOTES" -A typical application of this algorithm is to derive keying material for an -encryption algorithm from a password in the \*(L"pass\*(R", a salt in \*(L"salt\*(R", -and an iteration count. -.PP -Increasing the \*(L"iter\*(R" parameter slows down the algorithm which makes it -harder for an attacker to perform a brute force attack using a large number -of candidate passwords. -.PP -No assumption is made regarding the given password; it is simply treated as a -byte sequence. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1SP800\-132\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-PKCS12KDF.7ossl b/openssl-install/share/man/man7/EVP_KDF-PKCS12KDF.7ossl deleted file mode 100644 index bd8f09cd..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-PKCS12KDF.7ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-PKCS12KDF 7ossl" -.TH EVP_KDF-PKCS12KDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-PKCS12KDF \- The PKCS#12 EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fBPKCS#12\fR password-based \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR -\&\s-1API.\s0 -.PP -The \s-1EVP_KDF\-PKCS12KDF\s0 algorithm implements the PKCS#12 password-based key -derivation function, as described in appendix B of \s-1RFC 7292\s0 (\s-1PKCS\s0 #12: -Personal Information Exchange Syntax); it derives a key from a password -using a salt, iteration count and the intended usage. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1PKCS12KDF\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -.PD 0 -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.ie n .IP """iter"" (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.el .IP "``iter'' (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.IX Item "iter (OSSL_KDF_PARAM_ITER) " -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """id"" (\fB\s-1OSSL_KDF_PARAM_PKCS12_ID\s0\fR) " 4 -.el .IP "``id'' (\fB\s-1OSSL_KDF_PARAM_PKCS12_ID\s0\fR) " 4 -.IX Item "id (OSSL_KDF_PARAM_PKCS12_ID) " -This parameter is used to specify the intended usage of the output bits, as per -\&\s-1RFC 7292\s0 section B.3. -.SH "NOTES" -.IX Header "NOTES" -This algorithm is not available in the \s-1FIPS\s0 provider as it is not \s-1FIPS\s0 -approvable. -.PP -A typical application of this algorithm is to derive keying material for an -encryption algorithm from a password in the \*(L"pass\*(R", a salt in \*(L"salt\*(R", -and an iteration count. -.PP -Increasing the \*(L"iter\*(R" parameter slows down the algorithm which makes it -harder for an attacker to perform a brute force attack using a large number -of candidate passwords. -.PP -No assumption is made regarding the given password; it is simply treated as a -byte sequence. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC7292\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-PVKKDF.7ossl b/openssl-install/share/man/man7/EVP_KDF-PVKKDF.7ossl deleted file mode 100644 index 62261cd0..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-PVKKDF.7ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-PVKKDF 7ossl" -.TH EVP_KDF-PVKKDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-PVKKDF \- The PVK EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fB\s-1PVK KDF\s0\fR PIN-based \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR -\&\s-1API.\s0 -.PP -The \s-1EVP_KDF\-PVKKDF\s0 algorithm implements a \s-1PVK\s0 PIN-based key -derivation function; it derives a key from a password using a salt. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1PVKKDF\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -.PD 0 -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -A typical application of this algorithm is to derive keying material for an -encryption algorithm from a password in the \*(L"pass\*(R" and a salt in \*(L"salt\*(R". -.PP -No assumption is made regarding the given password; it is simply treated as a -byte sequence. -.PP -The legacy provider needs to be available in order to access this algorithm. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-SCRYPT.7ossl b/openssl-install/share/man/man7/EVP_KDF-SCRYPT.7ossl deleted file mode 100644 index 897b14e3..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-SCRYPT.7ossl +++ /dev/null @@ -1,284 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-SCRYPT 7ossl" -.TH EVP_KDF-SCRYPT 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-SCRYPT \- The scrypt EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fBscrypt\fR password-based \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR -\&\s-1API.\s0 -.PP -The \s-1EVP_KDF\-SCRYPT\s0 algorithm implements the scrypt password-based key -derivation function, as described in \s-1RFC 7914.\s0 It is memory-hard in the sense -that it deliberately requires a significant amount of \s-1RAM\s0 for efficient -computation. The intention of this is to render brute forcing of passwords on -systems that lack large amounts of main memory (such as GPUs or ASICs) -computationally infeasible. -.PP -scrypt provides three work factors that can be customized: N, r and p. N, which -has to be a positive power of two, is the general work factor and scales \s-1CPU\s0 -time in an approximately linear fashion. r is the block size of the internally -used hash function and p is the parallelization factor. Both r and p need to be -greater than zero. The amount of \s-1RAM\s0 that scrypt requires for its computation -is roughly (128 * N * r * p) bytes. -.PP -In the original paper of Colin Percival (\*(L"Stronger Key Derivation via -Sequential Memory-Hard Functions\*(R", 2009), the suggested values that give a -computation time of less than 5 seconds on a 2.5 GHz Intel Core 2 Duo are N = -2^20 = 1048576, r = 8, p = 1. Consequently, the required amount of memory for -this computation is roughly 1 GiB. On a more recent \s-1CPU\s0 (Intel i7\-5930K at 3.5 -GHz), this computation takes about 3 seconds. When N, r or p are not specified, -they default to 1048576, 8, and 1, respectively. The maximum amount of \s-1RAM\s0 that -may be used by scrypt defaults to 1025 MiB. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1SCRYPT\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -.PD 0 -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """n"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_N\s0\fR) " 4 -.el .IP "``n'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_N\s0\fR) " 4 -.IX Item "n (OSSL_KDF_PARAM_SCRYPT_N) " -.PD 0 -.ie n .IP """r"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_R\s0\fR) " 4 -.el .IP "``r'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_R\s0\fR) " 4 -.IX Item "r (OSSL_KDF_PARAM_SCRYPT_R) " -.ie n .IP """p"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_P\s0\fR) " 4 -.el .IP "``p'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_P\s0\fR) " 4 -.IX Item "p (OSSL_KDF_PARAM_SCRYPT_P) " -.ie n .IP """maxmem_bytes"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_MAXMEM\s0\fR) " 4 -.el .IP "``maxmem_bytes'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_MAXMEM\s0\fR) " 4 -.IX Item "maxmem_bytes (OSSL_KDF_PARAM_SCRYPT_MAXMEM) " -.PD -These parameters configure the scrypt work factors N, r, maxmem and p. -Both N and maxmem_bytes are parameters of type \fBuint64_t\fR. -Both r and p are parameters of type \fBuint32_t\fR. -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -This can be used to set the property query string when fetching the -fixed digest internally. \s-1NULL\s0 is used if this value is not set. -.SH "NOTES" -.IX Header "NOTES" -A context for scrypt can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "SCRYPT", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of an scrypt key derivation is specified via the -\&\*(L"keylen\*(R" parameter to the \fBEVP_KDF_derive\fR\|(3) function. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives a 64\-byte long test vector using scrypt with the password -\&\*(L"password\*(R", salt \*(L"NaCl\*(R" and N = 1024, r = 8, p = 16. -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[64]; -\& OSSL_PARAM params[6], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "SCRYPT", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASSWORD, -\& "password", (size_t)8); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -\& "NaCl", (size_t)4); -\& *p++ = OSSL_PARAM_construct_uint64(OSSL_KDF_PARAM_SCRYPT_N, (uint64_t)1024); -\& *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_SCRYPT_R, (uint32_t)8); -\& *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_SCRYPT_P, (uint32_t)16); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { -\& error("EVP_KDF_derive"); -\& } -\& -\& { -\& const unsigned char expected[sizeof(out)] = { -\& 0xfd, 0xba, 0xbe, 0x1c, 0x9d, 0x34, 0x72, 0x00, -\& 0x78, 0x56, 0xe7, 0x19, 0x0d, 0x01, 0xe9, 0xfe, -\& 0x7c, 0x6a, 0xd7, 0xcb, 0xc8, 0x23, 0x78, 0x30, -\& 0xe7, 0x73, 0x76, 0x63, 0x4b, 0x37, 0x31, 0x62, -\& 0x2e, 0xaf, 0x30, 0xd9, 0x2e, 0x22, 0xa3, 0x88, -\& 0x6f, 0xf1, 0x09, 0x27, 0x9d, 0x98, 0x30, 0xda, -\& 0xc7, 0x27, 0xaf, 0xb9, 0x4a, 0x83, 0xee, 0x6d, -\& 0x83, 0x60, 0xcb, 0xdf, 0xa2, 0xcc, 0x06, 0x40 -\& }; -\& -\& assert(!memcmp(out, expected, sizeof(out))); -\& } -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 7914\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-SS.7ossl b/openssl-install/share/man/man7/EVP_KDF-SS.7ossl deleted file mode 100644 index bd501608..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-SS.7ossl +++ /dev/null @@ -1,343 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-SS 7ossl" -.TH EVP_KDF-SS 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-SS \- The Single Step / One Step EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP_KDF\-SS\s0 algorithm implements the Single Step key derivation function (\s-1SSKDF\s0). -\&\s-1SSKDF\s0 derives a key using input such as a shared secret key (that was generated -during the execution of a key establishment scheme) and fixedinfo. -\&\s-1SSKDF\s0 is also informally referred to as 'Concat \s-1KDF\s0'. -.PP -The output is considered to be keying material. -.SS "Auxiliary function" -.IX Subsection "Auxiliary function" -The implementation uses a selectable auxiliary function H, which can be one of: -.IP "\fBH(x) = hash(x, digest=md)\fR" 4 -.IX Item "H(x) = hash(x, digest=md)" -.PD 0 -.IP "\fBH(x) = HMAC_hash(x, key=salt, digest=md)\fR" 4 -.IX Item "H(x) = HMAC_hash(x, key=salt, digest=md)" -.ie n .IP "\fBH(x) = KMACxxx(x, key=salt, custom=""\s-1KDF"",\s0 outlen=mac_size)\fR" 4 -.el .IP "\fBH(x) = KMACxxx(x, key=salt, custom=``\s-1KDF'',\s0 outlen=mac_size)\fR" 4 -.IX Item "H(x) = KMACxxx(x, key=salt, custom=KDF, outlen=mac_size)" -.PD -.PP -Both the \s-1HMAC\s0 and \s-1KMAC\s0 implementations set the key using the 'salt' value. -The hash and \s-1HMAC\s0 also require the digest to be set. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1SSKDF\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -This parameter is ignored for \s-1KMAC.\s0 -.ie n .IP """mac"" (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mac'' (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mac (OSSL_KDF_PARAM_MAC) " -.PD 0 -.ie n .IP """maclen"" (\fB\s-1OSSL_KDF_PARAM_MAC_SIZE\s0\fR) " 4 -.el .IP "``maclen'' (\fB\s-1OSSL_KDF_PARAM_MAC_SIZE\s0\fR) " 4 -.IX Item "maclen (OSSL_KDF_PARAM_MAC_SIZE) " -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_SECRET) " -This parameter set the shared secret that is used for key derivation. -.ie n .IP """info"" (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.el .IP "``info'' (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.IX Item "info (OSSL_KDF_PARAM_INFO) " -This parameter sets an optional value for fixedinfo, also known as otherinfo. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if \*(L"key-check\*(R" -is set to 0 and the check fails. -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1SSKDF\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of an \s-1SSKDF\s0 is specified via the \fIkeylen\fR -parameter to the \fBEVP_KDF_derive\fR\|(3) function. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 10 bytes using H(x) = \s-1SHA\-256,\s0 with the secret key \*(L"secret\*(R" -and fixedinfo value \*(L"label\*(R": -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[4], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -\& SN_sha256, strlen(SN_sha256)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -\& "secret", (size_t)6); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -\& "label", (size_t)5); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { -\& error("EVP_KDF_derive"); -\& } -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.PP -This example derives 10 bytes using H(x) = \s-1HMAC\s0(\s-1SHA\-256\s0), with the secret key \*(L"secret\*(R", -fixedinfo value \*(L"label\*(R" and salt \*(L"salt\*(R": -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[6], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, -\& SN_hmac, strlen(SN_hmac)); -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -\& SN_sha256, strlen(SN_sha256)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, -\& "secret", (size_t)6); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -\& "label", (size_t)5); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -\& "salt", (size_t)4); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { -\& error("EVP_KDF_derive"); -\& } -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.PP -This example derives 10 bytes using H(x) = \s-1KMAC128\s0(x,salt,outlen), with the secret key \*(L"secret\*(R" -fixedinfo value \*(L"label\*(R", salt of \*(L"salt\*(R" and \s-1KMAC\s0 outlen of 20: -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[6], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "SSKDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_MAC, -\& SN_kmac128, strlen(SN_kmac128)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, -\& "secret", (size_t)6); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -\& "label", (size_t)5); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, -\& "salt", (size_t)4); -\& *p++ = OSSL_PARAM_construct_size_t(OSSL_KDF_PARAM_MAC_SIZE, (size_t)20); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { -\& error("EVP_KDF_derive"); -\& } -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST\s0 SP800\-56Cr1. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. Copyright -(c) 2019, Oracle and/or its affiliates. All rights reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-SSHKDF.7ossl b/openssl-install/share/man/man7/EVP_KDF-SSHKDF.7ossl deleted file mode 100644 index 43a409e3..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-SSHKDF.7ossl +++ /dev/null @@ -1,318 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-SSHKDF 7ossl" -.TH EVP_KDF-SSHKDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-SSHKDF \- The SSHKDF EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fB\s-1SSHKDF\s0\fR \s-1KDF\s0 through the \fB\s-1EVP_KDF\s0\fR \s-1API.\s0 -.PP -The \s-1EVP_KDF\-SSHKDF\s0 algorithm implements the \s-1SSHKDF\s0 key derivation function. -It is defined in \s-1RFC 4253,\s0 section 7.2 and is used by \s-1SSH\s0 to derive IVs, -encryption keys and integrity keys. -Five inputs are required to perform key derivation: The hashing function -(for example \s-1SHA256\s0), the Initial Key, the Exchange Hash, the Session \s-1ID,\s0 -and the derivation key type. -.PP -The output is considered to be keying material. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1SSHKDF\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """xcghash"" (\fB\s-1OSSL_KDF_PARAM_SSHKDF_XCGHASH\s0\fR) " 4 -.el .IP "``xcghash'' (\fB\s-1OSSL_KDF_PARAM_SSHKDF_XCGHASH\s0\fR) " 4 -.IX Item "xcghash (OSSL_KDF_PARAM_SSHKDF_XCGHASH) " -.PD 0 -.ie n .IP """session_id"" (\fB\s-1OSSL_KDF_PARAM_SSHKDF_SESSION_ID\s0\fR) " 4 -.el .IP "``session_id'' (\fB\s-1OSSL_KDF_PARAM_SSHKDF_SESSION_ID\s0\fR) " 4 -.IX Item "session_id (OSSL_KDF_PARAM_SSHKDF_SESSION_ID) " -.PD -These parameters set the respective values for the \s-1KDF.\s0 -If a value is already set, the contents are replaced. -.ie n .IP """type"" (\fB\s-1OSSL_KDF_PARAM_SSHKDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``type'' (\fB\s-1OSSL_KDF_PARAM_SSHKDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "type (OSSL_KDF_PARAM_SSHKDF_TYPE) " -This parameter sets the type for the \s-1SSHKDF\s0 operation. -There are six supported types: -.RS 4 -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV" -The Initial \s-1IV\s0 from client to server. -A single char of value 65 (\s-1ASCII\s0 char 'A'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INITIAL_IV_SRV_TO_CLI\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INITIAL_IV_SRV_TO_CLI" -The Initial \s-1IV\s0 from server to client -A single char of value 66 (\s-1ASCII\s0 char 'B'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_CLI_TO_SRV\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_CLI_TO_SRV" -The Encryption Key from client to server -A single char of value 67 (\s-1ASCII\s0 char 'C'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_SRV_TO_CLI\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_SRV_TO_CLI" -The Encryption Key from server to client -A single char of value 68 (\s-1ASCII\s0 char 'D'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_CLI_TO_SRV\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_CLI_TO_SRV" -The Integrity Key from client to server -A single char of value 69 (\s-1ASCII\s0 char 'E'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_SRV_TO_CLI\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_SRV_TO_CLI" -The Integrity Key from client to server -A single char of value 70 (\s-1ASCII\s0 char 'F'). -.RE -.RS 4 -.RE -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if any \*(L"***\-check\*(R" -related parameter is set to 0 and the check fails. -.ie n .IP """digest-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if -used digest is not approved. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.Sp -According to \s-1SP\s0 800\-135r1, the following are approved digest algorithms: \s-1SHA\-1, -SHA2\-224, SHA2\-256, SHA2\-384, SHA2\-512.\s0 -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1SSHKDF\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "SSHKDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of the \s-1SSHKDF\s0 derivation is specified via the \fIkeylen\fR -parameter to the \fBEVP_KDF_derive\fR\|(3) function. -Since the \s-1SSHKDF\s0 output length is variable, calling \fBEVP_KDF_CTX_get_kdf_size\fR\|(3) -to obtain the requisite length is not meaningful. The caller must -allocate a buffer of the desired length, and pass that buffer to the -\&\fBEVP_KDF_derive\fR\|(3) function along with the desired length. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives an 8 byte \s-1IV\s0 using \s-1SHA\-256\s0 with a 1K \*(L"key\*(R" and appropriate -\&\*(L"xcghash\*(R" and \*(L"session_id\*(R" values: -.PP -.Vb 9 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& char type = EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV; -\& unsigned char key[1024] = "01234..."; -\& unsigned char xcghash[32] = "012345..."; -\& unsigned char session_id[32] = "012345..."; -\& unsigned char out[8]; -\& size_t outlen = sizeof(out); -\& OSSL_PARAM params[6], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "SSHKDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -\& SN_sha256, strlen(SN_sha256)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, -\& key, (size_t)1024); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SSHKDF_XCGHASH, -\& xcghash, (size_t)32); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SSHKDF_SESSION_ID, -\& session_id, (size_t)32); -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_SSHKDF_TYPE, -\& &type, sizeof(type)); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, outlen, params) <= 0) -\& /* Error */ -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 4253\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-TLS13_KDF.7ossl b/openssl-install/share/man/man7/EVP_KDF-TLS13_KDF.7ossl deleted file mode 100644 index 8cc954be..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-TLS13_KDF.7ossl +++ /dev/null @@ -1,294 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-TLS13_KDF 7ossl" -.TH EVP_KDF-TLS13_KDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-TLS13_KDF \- The TLS 1.3 EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \s-1TLS 1.3\s0 version of the \fB\s-1HKDF\s0\fR \s-1KDF\s0 through -the \fB\s-1EVP_KDF\s0\fR \s-1API.\s0 -.PP -The \s-1EVP_KDF\-TLS13_KDF\s0 algorithm implements the \s-1HKDF\s0 key derivation function -as used by \s-1TLS 1.3.\s0 -.PP -The output is considered to be keying material. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1TLS13\-KDF\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -.ie n .IP """salt"" (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_KDF_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_KDF_PARAM_SALT) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """prefix"" (\fB\s-1OSSL_KDF_PARAM_PREFIX\s0\fR) " 4 -.el .IP "``prefix'' (\fB\s-1OSSL_KDF_PARAM_PREFIX\s0\fR) " 4 -.IX Item "prefix (OSSL_KDF_PARAM_PREFIX) " -This parameter sets the label prefix on the specified \s-1TLS 1.3 KDF\s0 context. -For \s-1TLS 1.3\s0 this should be set to the \s-1ASCII\s0 string \*(L"tls13 \*(R" without a -trailing zero byte. Refer to \s-1RFC 8446\s0 section 7.1 \*(L"Key Schedule\*(R" for details. -.ie n .IP """label"" (\fB\s-1OSSL_KDF_PARAM_LABEL\s0\fR) " 4 -.el .IP "``label'' (\fB\s-1OSSL_KDF_PARAM_LABEL\s0\fR) " 4 -.IX Item "label (OSSL_KDF_PARAM_LABEL) " -This parameter sets the label on the specified \s-1TLS 1.3 KDF\s0 context. -Refer to \s-1RFC 8446\s0 section 7.1 \*(L"Key Schedule\*(R" for details. -.ie n .IP """data"" (\fB\s-1OSSL_KDF_PARAM_DATA\s0\fR) " 4 -.el .IP "``data'' (\fB\s-1OSSL_KDF_PARAM_DATA\s0\fR) " 4 -.IX Item "data (OSSL_KDF_PARAM_DATA) " -This parameter sets the context data on the specified \s-1TLS 1.3 KDF\s0 context. -Refer to \s-1RFC 8446\s0 section 7.1 \*(L"Key Schedule\*(R" for details. -.ie n .IP """mode"" (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string> or " 4 -.el .IP "``mode'' (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string> or " 4 -.IX Item "mode (OSSL_KDF_PARAM_MODE) or " -This parameter sets the mode for the \s-1TLS 1.3 KDF\s0 operation. -There are two modes that are currently defined: -.RS 4 -.ie n .IP """\s-1EXTRACT_ONLY""\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXTRACT_ONLY\s0\fR" 4 -.el .IP "``\s-1EXTRACT_ONLY''\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXTRACT_ONLY\s0\fR" 4 -.IX Item "EXTRACT_ONLY or EVP_KDF_HKDF_MODE_EXTRACT_ONLY" -In this mode calling \fBEVP_KDF_derive\fR\|(3) will just perform the extract -operation. The value returned will be the intermediate fixed-length pseudorandom -key K. The \fIkeylen\fR parameter must match the size of K, which can be looked -up by calling \fBEVP_KDF_CTX_get_kdf_size()\fR after setting the mode and digest. -.Sp -The digest, key and salt values must be set before a key is derived otherwise -an error will occur. -.ie n .IP """\s-1EXPAND_ONLY""\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXPAND_ONLY\s0\fR" 4 -.el .IP "``\s-1EXPAND_ONLY''\s0 or \fB\s-1EVP_KDF_HKDF_MODE_EXPAND_ONLY\s0\fR" 4 -.IX Item "EXPAND_ONLY or EVP_KDF_HKDF_MODE_EXPAND_ONLY" -In this mode calling \fBEVP_KDF_derive\fR\|(3) will just perform the expand -operation. The input key should be set to the intermediate fixed-length -pseudorandom key K returned from a previous extract operation. -.Sp -The digest, key and info values must be set before a key is derived otherwise -an error will occur. -.RE -.RS 4 -.RE -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if any \*(L"***\-check\*(R" -related parameter is set to 0 and the check fails. -.ie n .IP """digest-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if -used digest is not approved. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.Sp -According to \s-1RFC 8446,\s0 the following are approved digest algorithms: \s-1SHA2\-256, -SHA2\-384.\s0 -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -This \s-1KDF\s0 is intended for use by the \s-1TLS 1.3\s0 implementation in libssl. -It does not support all the options and capabilities that \s-1HKDF\s0 does. -.PP -The \fI\s-1OSSL_PARAM\s0\fR array passed to \fBEVP_KDF_derive\fR\|(3) or -\&\fBEVP_KDF_CTX_set_params\fR\|(3) must specify all of the parameters required. -This \s-1KDF\s0 does not support a piecemeal approach to providing these. -.PP -A context for a \s-1TLS 1.3 KDF\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "TLS13\-KDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of a \s-1TLS 1.3 KDF\s0 expand operation is specified via the -\&\fIkeylen\fR parameter to the \fBEVP_KDF_derive\fR\|(3) function. When using -\&\s-1EVP_KDF_HKDF_MODE_EXTRACT_ONLY\s0 the \fIkeylen\fR parameter must equal the size of -the intermediate fixed-length pseudorandom key otherwise an error will occur. -For that mode, the fixed output size can be looked up by calling -\&\fBEVP_KDF_CTX_get_kdf_size()\fR after setting the mode and digest on the -\&\fB\s-1EVP_KDF_CTX\s0\fR. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 8446\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3), -\&\s-1\fBEVP_KDF\-HKDF\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-TLS1_PRF.7ossl b/openssl-install/share/man/man7/EVP_KDF-TLS1_PRF.7ossl deleted file mode 100644 index 209a41e5..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-TLS1_PRF.7ossl +++ /dev/null @@ -1,283 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-TLS1_PRF 7ossl" -.TH EVP_KDF-TLS1_PRF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-TLS1_PRF \- The TLS1 PRF EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing the \fB\s-1TLS1\s0\fR \s-1PRF\s0 through the \fB\s-1EVP_KDF\s0\fR \s-1API.\s0 -.PP -The \s-1EVP_KDF\-TLS1_PRF\s0 algorithm implements the \s-1PRF\s0 used by \s-1TLS\s0 versions up to -and including \s-1TLS 1.2.\s0 -.PP -The output is considered to be keying material. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1TLS1\-PRF\*(R"\s0 is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.Sp -The \fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR parameter is used to set the message digest -associated with the \s-1TLS PRF.\s0 -\&\fBEVP_md5_sha1()\fR is treated as a special case which uses the -\&\s-1PRF\s0 algorithm using both \fB\s-1MD5\s0\fR and \fB\s-1SHA1\s0\fR as used in \s-1TLS 1.0\s0 and 1.1. -.ie n .IP """secret"" (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.el .IP "``secret'' (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.IX Item "secret (OSSL_KDF_PARAM_SECRET) " -This parameter sets the secret value of the \s-1TLS PRF.\s0 -Any existing secret value is replaced. -.ie n .IP """seed"" (\fB\s-1OSSL_KDF_PARAM_SEED\s0\fR) " 4 -.el .IP "``seed'' (\fB\s-1OSSL_KDF_PARAM_SEED\s0\fR) " 4 -.IX Item "seed (OSSL_KDF_PARAM_SEED) " -This parameter sets the context seed. -The length of the context seed cannot exceed 1024 bytes; -this should be more than enough for any normal use of the \s-1TLS PRF.\s0 -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if any \*(L"***\-check\*(R" -related parameter is set to 0 and the check fails. -.ie n .IP """ems_check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_EMS_CHECK\s0\fR) " 4 -.el .IP "``ems_check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_EMS_CHECK\s0\fR) " 4 -.IX Item "ems_check (OSSL_KDF_PARAM_FIPS_EMS_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_derive()\fR if -\&\*(L"master secret\*(R" is used instead of \*(L"extended master secret\*(R" Setting this to zero -will ignore the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.ie n .IP """digest-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if -used digest is not approved. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.Sp -According to \s-1SP\s0 800\-135r1, the following are approved digest algorithms: -\&\s-1SHA2\-256, SHA2\-384, SHA2\-512.\s0 -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -A context for the \s-1TLS PRF\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "TLS1\-PRF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The digest, secret value and seed must be set before a key is derived otherwise -an error will occur. -.PP -The output length of the \s-1PRF\s0 is specified by the \fIkeylen\fR parameter to the -\&\fBEVP_KDF_derive()\fR function. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 10 bytes using \s-1SHA\-256\s0 with the secret key \*(L"secret\*(R" -and seed value \*(L"seed\*(R": -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[4], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "TLS1\-PRF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -\& SN_sha256, strlen(SN_sha256)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, -\& "secret", (size_t)6); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SEED, -\& "seed", (size_t)4); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { -\& error("EVP_KDF_derive"); -\& } -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 2246, RFC 5246\s0 and \s-1NIST SP 800\-135\s0 r1 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-X942-ASN1.7ossl b/openssl-install/share/man/man7/EVP_KDF-X942-ASN1.7ossl deleted file mode 100644 index 877187c2..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-X942-ASN1.7ossl +++ /dev/null @@ -1,300 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-X942-ASN1 7ossl" -.TH EVP_KDF-X942-ASN1 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-X942\-ASN1 \- The X9.42\-2003 asn1 EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP_KDF\-X942\-ASN1\s0 algorithm implements the key derivation function -X942KDF\-ASN1. It is used by \s-1DH\s0 KeyAgreement, to derive a key using input such as -a shared secret key and other info. The other info is \s-1DER\s0 encoded data that -contains a 32 bit counter as well as optional fields for \*(L"partyu-info\*(R", -\&\*(L"partyv-info\*(R", \*(L"supp-pubinfo\*(R" and \*(L"supp-privinfo\*(R". -This kdf is used by Cryptographic Message Syntax (\s-1CMS\s0). -.PP -The output is considered to be keying material. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"X942KDF\-ASN1\*(R" or \*(L"X942KDF\*(R" is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """secret"" (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.el .IP "``secret'' (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.IX Item "secret (OSSL_KDF_PARAM_SECRET) " -The shared secret used for key derivation. This parameter sets the secret. -.ie n .IP """acvp-info"" (\fB\s-1OSSL_KDF_PARAM_X942_ACVPINFO\s0\fR) " 4 -.el .IP "``acvp-info'' (\fB\s-1OSSL_KDF_PARAM_X942_ACVPINFO\s0\fR) " 4 -.IX Item "acvp-info (OSSL_KDF_PARAM_X942_ACVPINFO) " -This value should not be used in production and should only be used for \s-1ACVP\s0 -testing. It is an optional octet string containing a combined \s-1DER\s0 encoded blob -of any of the optional fields related to \*(L"partyu-info\*(R", \*(L"partyv-info\*(R", -\&\*(L"supp-pubinfo\*(R" and \*(L"supp-privinfo\*(R". If it is specified then none of these other -fields should be used. -.ie n .IP """partyu-info"" (\fB\s-1OSSL_KDF_PARAM_X942_PARTYUINFO\s0\fR) " 4 -.el .IP "``partyu-info'' (\fB\s-1OSSL_KDF_PARAM_X942_PARTYUINFO\s0\fR) " 4 -.IX Item "partyu-info (OSSL_KDF_PARAM_X942_PARTYUINFO) " -An optional octet string containing public info contributed by the initiator. -.ie n .IP """ukm"" (\fB\s-1OSSL_KDF_PARAM_UKM\s0\fR) " 4 -.el .IP "``ukm'' (\fB\s-1OSSL_KDF_PARAM_UKM\s0\fR) " 4 -.IX Item "ukm (OSSL_KDF_PARAM_UKM) " -An alias for \*(L"partyu-info\*(R". -In \s-1CMS\s0 this is the user keying material. -.ie n .IP """partyv-info"" (\fB\s-1OSSL_KDF_PARAM_X942_PARTYVINFO\s0\fR) " 4 -.el .IP "``partyv-info'' (\fB\s-1OSSL_KDF_PARAM_X942_PARTYVINFO\s0\fR) " 4 -.IX Item "partyv-info (OSSL_KDF_PARAM_X942_PARTYVINFO) " -An optional octet string containing public info contributed by the responder. -.ie n .IP """supp-pubinfo"" (\fB\s-1OSSL_KDF_PARAM_X942_SUPP_PUBINFO\s0\fR) " 4 -.el .IP "``supp-pubinfo'' (\fB\s-1OSSL_KDF_PARAM_X942_SUPP_PUBINFO\s0\fR) " 4 -.IX Item "supp-pubinfo (OSSL_KDF_PARAM_X942_SUPP_PUBINFO) " -An optional octet string containing some additional, mutually-known public -information. Setting this value also sets \*(L"use-keybits\*(R" to 0. -.ie n .IP """use-keybits"" (\fB\s-1OSSL_KDF_PARAM_X942_USE_KEYBITS\s0\fR) " 4 -.el .IP "``use-keybits'' (\fB\s-1OSSL_KDF_PARAM_X942_USE_KEYBITS\s0\fR) " 4 -.IX Item "use-keybits (OSSL_KDF_PARAM_X942_USE_KEYBITS) " -The default value of 1 will use the \s-1KEK\s0 key length (in bits) as the -\&\*(L"supp-pubinfo\*(R". A value of 0 disables setting the \*(L"supp-pubinfo\*(R". -.ie n .IP """supp-privinfo"" (\fB\s-1OSSL_KDF_PARAM_X942_SUPP_PRIVINFO\s0\fR) " 4 -.el .IP "``supp-privinfo'' (\fB\s-1OSSL_KDF_PARAM_X942_SUPP_PRIVINFO\s0\fR) " 4 -.IX Item "supp-privinfo (OSSL_KDF_PARAM_X942_SUPP_PRIVINFO) " -An optional octet string containing some additional, mutually-known private -information. -.ie n .IP """cekalg"" (\fB\s-1OSSL_KDF_PARAM_CEK_ALG\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cekalg'' (\fB\s-1OSSL_KDF_PARAM_CEK_ALG\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cekalg (OSSL_KDF_PARAM_CEK_ALG) " -This parameter sets the \s-1CEK\s0 wrapping algorithm name. -Valid values are \*(L"\s-1AES\-128\-WRAP\*(R", \*(L"AES\-192\-WRAP\*(R", \*(L"AES\-256\-WRAP\*(R"\s0 and \*(L"\s-1DES3\-WRAP\*(R".\s0 -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if \*(L"key-check\*(R" -parameter is set to 0 and the check fails. -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -A context for X942KDF can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "X942KDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of an X942KDF is specified via the \fIkeylen\fR -parameter to the \fBEVP_KDF_derive\fR\|(3) function. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 24 bytes, with the secret key \*(L"secret\*(R" and random user -keying material: -.PP -.Vb 5 -\& EVP_KDF_CTX *kctx; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[192/8]; -\& unsignred char ukm[64]; -\& OSSL_PARAM params[5], *p = params; -\& -\& if (RAND_bytes(ukm, sizeof(ukm)) <= 0) -\& error("RAND_bytes"); -\& -\& kdf = EVP_KDF_fetch(NULL, "X942KDF", NULL); -\& if (kctx == NULL) -\& error("EVP_KDF_fetch"); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& if (kctx == NULL) -\& error("EVP_KDF_CTX_new"); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, "SHA256", 0); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, -\& "secret", (size_t)6); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_UKM, ukm, sizeof(ukm)); -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CEK_ALG, "AES\-256\-WRAP, 0); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) -\& error("EVP_KDF_derive"); -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1ANS1 X9.42\-2003 -RFC 2631\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-X942-CONCAT.7ossl b/openssl-install/share/man/man7/EVP_KDF-X942-CONCAT.7ossl deleted file mode 100644 index a337d3b5..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-X942-CONCAT.7ossl +++ /dev/null @@ -1,166 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-X942-CONCAT 7ossl" -.TH EVP_KDF-X942-CONCAT 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-X942\-CONCAT \- The X942 Concat EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP_KDF\-X942\-CONCAT\s0 algorithm is identical to \s-1EVP_KDF\-X963.\s0 It is -used for key agreement to derive a key using input such as a shared secret key -and shared info. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"X942KDF_CONCAT\*(R" is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.PP -This is an alias for \*(L"X963KDF\*(R". -.PP -See \s-1\fBEVP_KDF\-X963\s0\fR\|(7) for a list of supported parameters and examples. -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KDF-X963.7ossl b/openssl-install/share/man/man7/EVP_KDF-X963.7ossl deleted file mode 100644 index c1709e1d..00000000 --- a/openssl-install/share/man/man7/EVP_KDF-X963.7ossl +++ /dev/null @@ -1,270 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KDF-X963 7ossl" -.TH EVP_KDF-X963 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KDF\-X963 \- The X9.63\-2001 EVP_KDF implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP_KDF\-X963\s0 algorithm implements the key derivation function (X963KDF). -X963KDF is used by Cryptographic Message Syntax (\s-1CMS\s0) for \s-1EC\s0 KeyAgreement, to -derive a key using input such as a shared secret key and shared info. -.PP -The output is considered to be keying material. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"X963KDF\*(R" is the name for this implementation; it -can be used with the \fBEVP_KDF_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3). -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -The shared secret used for key derivation. -This parameter sets the secret. -.ie n .IP """info"" (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.el .IP "``info'' (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.IX Item "info (OSSL_KDF_PARAM_INFO) " -This parameter specifies an optional value for shared info. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling EVP_KDF_derive. It returns 0 if any \*(L"***\-check\*(R" -related parameter is set to 0 and the check fails. -.ie n .IP """digest-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_KDF_PARAM_FIPS_DIGEST_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if -used digest is not approved. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.Sp -According to \s-1ANSI X9.63\-2001,\s0 the following are approved digest algorithms: -\&\s-1SHA2\-224, SHA2\-256, SHA2\-384, SHA2\-512, SHA2\-512/224, SHA2\-512/256, SHA3\-224, -SHA3\-256, SHA3\-384, SHA3\-512.\s0 -.ie n .IP """key-check"" (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KDF_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KDF_PARAM_FIPS_KEY_CHECK) " -The default value of 1 causes an error during \fBEVP_KDF_CTX_set_params()\fR if the -length of used key-derivation key (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) is shorter than 112 -bits. -Setting this to zero will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -X963KDF is very similar to the \s-1SSKDF\s0 that uses a digest as the auxiliary function, -X963KDF appends the counter to the secret, whereas \s-1SSKDF\s0 prepends the counter. -.PP -A context for X963KDF can be obtained by calling: -.PP -.Vb 2 -\& EVP_KDF *kdf = EVP_KDF_fetch(NULL, "X963KDF", NULL); -\& EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); -.Ve -.PP -The output length of an X963KDF is specified via the \fIkeylen\fR -parameter to the \fBEVP_KDF_derive\fR\|(3) function. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example derives 10 bytes, with the secret key \*(L"secret\*(R" and sharedinfo -value \*(L"label\*(R": -.PP -.Vb 4 -\& EVP_KDF *kdf; -\& EVP_KDF_CTX *kctx; -\& unsigned char out[10]; -\& OSSL_PARAM params[4], *p = params; -\& -\& kdf = EVP_KDF_fetch(NULL, "X963KDF", NULL); -\& kctx = EVP_KDF_CTX_new(kdf); -\& EVP_KDF_free(kdf); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, -\& SN_sha256, strlen(SN_sha256)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, -\& "secret", (size_t)6); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_INFO, -\& "label", (size_t)5); -\& *p = OSSL_PARAM_construct_end(); -\& if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { -\& error("EVP_KDF_derive"); -\& } -\& -\& EVP_KDF_CTX_free(kctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\*(L"\s-1SEC 1:\s0 Elliptic Curve Cryptography\*(R" -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KDF\s0\fR\|(3), -\&\fBEVP_KDF_CTX_new\fR\|(3), -\&\fBEVP_KDF_CTX_free\fR\|(3), -\&\fBEVP_KDF_CTX_set_params\fR\|(3), -\&\fBEVP_KDF_CTX_get_kdf_size\fR\|(3), -\&\fBEVP_KDF_derive\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_KDF\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KEM-EC.7ossl b/openssl-install/share/man/man7/EVP_KEM-EC.7ossl deleted file mode 100644 index 60d17665..00000000 --- a/openssl-install/share/man/man7/EVP_KEM-EC.7ossl +++ /dev/null @@ -1,205 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEM-EC 7ossl" -.TH EVP_KEM-EC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEM\-EC -\&\- EVP_KEM EC keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1EC\s0\fR keytype and its parameters are described in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7). -See \fBEVP_PKEY_encapsulate\fR\|(3) and \fBEVP_PKEY_decapsulate\fR\|(3) for more info. -.SS "\s-1EC KEM\s0 parameters" -.IX Subsection "EC KEM parameters" -.ie n .IP """operation"" (\fB\s-1OSSL_KEM_PARAM_OPERATION\s0\fR)<\s-1UTF8\s0 string>" 4 -.el .IP "``operation'' (\fB\s-1OSSL_KEM_PARAM_OPERATION\s0\fR)<\s-1UTF8\s0 string>" 4 -.IX Item "operation (OSSL_KEM_PARAM_OPERATION)" -The OpenSSL \s-1EC\s0 Key Encapsulation Mechanisms only supports the -following operation: -.RS 4 -.ie n .IP """\s-1DHKEM""\s0 (\fB\s-1OSSL_KEM_PARAM_OPERATION_DHKEM\s0\fR)" 4 -.el .IP "``\s-1DHKEM''\s0 (\fB\s-1OSSL_KEM_PARAM_OPERATION_DHKEM\s0\fR)" 4 -.IX Item "DHKEM (OSSL_KEM_PARAM_OPERATION_DHKEM)" -The encapsulate function generates an ephemeral keypair. It produces keymaterial -by doing an \s-1ECDH\s0 key exchange using the ephemeral private key and a supplied -recipient public key. A \s-1HKDF\s0 operation using the keymaterial and a kem context -then produces a shared secret. The shared secret and the ephemeral public key -are returned. -The decapsulate function uses the recipient private key and the -ephemeral public key to produce the same keymaterial, which can then be used to -produce the same shared secret. -See -.RE -.RS 4 -.Sp -This can be set using either \fBEVP_PKEY_CTX_set_kem_op()\fR or -\&\fBEVP_PKEY_CTX_set_params()\fR. -.RE -.ie n .IP """ikme"" (\fB\s-1OSSL_KEM_PARAM_IKME\s0\fR) " 4 -.el .IP "``ikme'' (\fB\s-1OSSL_KEM_PARAM_IKME\s0\fR) " 4 -.IX Item "ikme (OSSL_KEM_PARAM_IKME) " -Used to specify the key material used for generation of the ephemeral key. -This value should not be reused for other purposes. -It can only be used for the curves \*(L"P\-256\*(R", \*(L"P\-384\*(R" and \*(L"P\-521\*(R" and should -have a length of at least the size of the encoded private key -(i.e. 32, 48 and 66 for the listed curves). -If this value is not set, then a random ikm is used. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -.IP "\s-1RFC9180\s0" 4 -.IX Item "RFC9180" -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_kem_op\fR\|(3), -\&\fBEVP_PKEY_encapsulate\fR\|(3), -\&\fBEVP_PKEY_decapsulate\fR\|(3) -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keymgmt\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KEM-RSA.7ossl b/openssl-install/share/man/man7/EVP_KEM-RSA.7ossl deleted file mode 100644 index 80a94281..00000000 --- a/openssl-install/share/man/man7/EVP_KEM-RSA.7ossl +++ /dev/null @@ -1,200 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEM-RSA 7ossl" -.TH EVP_KEM-RSA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEM\-RSA -\&\- EVP_KEM RSA keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1RSA\s0\fR keytype and its parameters are described in \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7). -See \fBEVP_PKEY_encapsulate\fR\|(3) and \fBEVP_PKEY_decapsulate\fR\|(3) for more info. -.SS "\s-1RSA KEM\s0 parameters" -.IX Subsection "RSA KEM parameters" -.ie n .IP """operation"" (\fB\s-1OSSL_KEM_PARAM_OPERATION\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``operation'' (\fB\s-1OSSL_KEM_PARAM_OPERATION\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "operation (OSSL_KEM_PARAM_OPERATION) " -The OpenSSL \s-1RSA\s0 Key Encapsulation Mechanism only currently supports the -following operation -.RS 4 -.ie n .IP """\s-1RSASVE""\s0" 4 -.el .IP "``\s-1RSASVE''\s0" 4 -.IX Item "RSASVE" -The encapsulate function simply generates a secret using random bytes and then -encrypts the secret using the \s-1RSA\s0 public key (with no padding). -The decapsulate function recovers the secret using the \s-1RSA\s0 private key. -.RE -.RS 4 -.Sp -This can be set using \fBEVP_PKEY_CTX_set_kem_op()\fR. -.RE -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR) " -.PD 0 -.ie n .IP """key-check"" (\fB\s-1OSSL_KEM_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KEM_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KEM_PARAM_FIPS_KEY_CHECK) " -.PD -These parameters are described in \fBprovider\-kem\fR\|(7). -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -.IP "SP800\-56Br2" 4 -.IX Item "SP800-56Br2" -Section 7.2.1.2 \s-1RSASVE\s0 Generate Operation (\s-1RSASVE.GENERATE\s0). -Section 7.2.1.3 \s-1RSASVE\s0 Recovery Operation (\s-1RSASVE.RECOVER\s0). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_kem_op\fR\|(3), -\&\fBEVP_PKEY_encapsulate\fR\|(3), -\&\fBEVP_PKEY_decapsulate\fR\|(3) -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keymgmt\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KEM-X25519.7ossl b/openssl-install/share/man/man7/EVP_KEM-X25519.7ossl deleted file mode 100644 index 622daead..00000000 --- a/openssl-install/share/man/man7/EVP_KEM-X25519.7ossl +++ /dev/null @@ -1,204 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEM-X25519 7ossl" -.TH EVP_KEM-X25519 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEM\-X25519, EVP_KEM\-X448 -\&\- EVP_KEM X25519 and EVP_KEM X448 keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX25519\fR and keytype and its parameters are described in -\&\s-1\fBEVP_PKEY\-X25519\s0\fR\|(7). -See \fBEVP_PKEY_encapsulate\fR\|(3) and \fBEVP_PKEY_decapsulate\fR\|(3) for more info. -.SS "X25519 and X448 \s-1KEM\s0 parameters" -.IX Subsection "X25519 and X448 KEM parameters" -.ie n .IP """operation"" (\fB\s-1OSSL_KEM_PARAM_OPERATION\s0\fR)<\s-1UTF8\s0 string>" 4 -.el .IP "``operation'' (\fB\s-1OSSL_KEM_PARAM_OPERATION\s0\fR)<\s-1UTF8\s0 string>" 4 -.IX Item "operation (OSSL_KEM_PARAM_OPERATION)" -The OpenSSL X25519 and X448 Key Encapsulation Mechanisms only support the -following operation: -.RS 4 -.ie n .IP """\s-1DHKEM""\s0 (\fB\s-1OSSL_KEM_PARAM_OPERATION_DHKEM\s0\fR)" 4 -.el .IP "``\s-1DHKEM''\s0 (\fB\s-1OSSL_KEM_PARAM_OPERATION_DHKEM\s0\fR)" 4 -.IX Item "DHKEM (OSSL_KEM_PARAM_OPERATION_DHKEM)" -The encapsulate function generates an ephemeral keypair. It produces keymaterial -by doing an X25519 or X448 key exchange using the ephemeral private key and a -supplied recipient public key. A \s-1HKDF\s0 operation using the keymaterial and a kem -context then produces a shared secret. The shared secret and the ephemeral -public key are returned. -The decapsulate function uses the recipient private key and the -ephemeral public key to produce the same keymaterial, which can then be used to -produce the same shared secret. -See -.RE -.RS 4 -.Sp -This can be set using either \fBEVP_PKEY_CTX_set_kem_op()\fR or -\&\fBEVP_PKEY_CTX_set_params()\fR. -.RE -.ie n .IP """ikme"" (\fB\s-1OSSL_KEM_PARAM_IKME\s0\fR) " 4 -.el .IP "``ikme'' (\fB\s-1OSSL_KEM_PARAM_IKME\s0\fR) " 4 -.IX Item "ikme (OSSL_KEM_PARAM_IKME) " -Used to specify the key material used for generation of the ephemeral key. -This value should not be reused for other purposes. -It should have a length of at least 32 for X25519, and 56 for X448. -If this value is not set, then a random ikm is used. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -.IP "\s-1RFC9180\s0" 4 -.IX Item "RFC9180" -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_kem_op\fR\|(3), -\&\fBEVP_PKEY_encapsulate\fR\|(3), -\&\fBEVP_PKEY_decapsulate\fR\|(3) -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keymgmt\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.2. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KEM-X448.7ossl b/openssl-install/share/man/man7/EVP_KEM-X448.7ossl deleted file mode 120000 index f95a7dce..00000000 --- a/openssl-install/share/man/man7/EVP_KEM-X448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEM-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYEXCH-DH.7ossl b/openssl-install/share/man/man7/EVP_KEYEXCH-DH.7ossl deleted file mode 100644 index 5195dc0d..00000000 --- a/openssl-install/share/man/man7/EVP_KEYEXCH-DH.7ossl +++ /dev/null @@ -1,277 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEYEXCH-DH 7ossl" -.TH EVP_KEYEXCH-DH 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEYEXCH\-DH -\&\- DH Key Exchange algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Key exchange support for the \fB\s-1DH\s0\fR and \fB\s-1DHX\s0\fR key types. -.PP -Please note that although both key types support the same key exchange -operations, they cannot be used together in a single key exchange. It -is not possible to use a private key of the \fB\s-1DH\s0\fR type in key exchange -with the public key of \fB\s-1DHX\s0\fR type and vice versa. -.SS "\s-1DH\s0 and \s-1DHX\s0 key exchange parameters" -.IX Subsection "DH and DHX key exchange parameters" -.ie n .IP """pad"" (\fB\s-1OSSL_EXCHANGE_PARAM_PAD\s0\fR) " 4 -.el .IP "``pad'' (\fB\s-1OSSL_EXCHANGE_PARAM_PAD\s0\fR) " 4 -.IX Item "pad (OSSL_EXCHANGE_PARAM_PAD) " -Sets the padding mode for the associated key exchange ctx. -Setting a value of 1 will turn padding on. -Setting a value of 0 will turn padding off. -If padding is off then the derived shared secret may be smaller than the -largest possible secret size. -If padding is on then the derived shared secret will have its first bytes -filled with zeros where necessary to make the shared secret the same size as -the largest possible secret size. -The padding mode parameter is ignored (and padding implicitly enabled) when -the \s-1KDF\s0 type is set to \*(L"X942KDF\-ASN1\*(R" (\fB\s-1OSSL_KDF_NAME_X942KDF_ASN1\s0\fR). -.ie n .IP """kdf-type"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-type'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-type (OSSL_EXCHANGE_PARAM_KDF_TYPE) " -.PD 0 -.ie n .IP """kdf-digest"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-digest'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-digest (OSSL_EXCHANGE_PARAM_KDF_DIGEST) " -.ie n .IP """kdf-digest-props"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-digest-props'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-digest-props (OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS) " -.ie n .IP """kdf-outlen"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_OUTLEN\s0\fR) " 4 -.el .IP "``kdf-outlen'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_OUTLEN\s0\fR) " 4 -.IX Item "kdf-outlen (OSSL_EXCHANGE_PARAM_KDF_OUTLEN) " -.ie n .IP """kdf-ukm"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.el .IP "``kdf-ukm'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.IX Item "kdf-ukm (OSSL_EXCHANGE_PARAM_KDF_UKM) " -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) " -.ie n .IP """key-check"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK) " -.ie n .IP """digest-check"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK) " -.PD -See \*(L"Common Key Exchange parameters\*(R" in \fBprovider\-keyexch\fR\|(7). -.ie n .IP """cekalg"" (\fB\s-1OSSL_KDF_PARAM_CEK_ALG\s0\fR) " 4 -.el .IP "``cekalg'' (\fB\s-1OSSL_KDF_PARAM_CEK_ALG\s0\fR) " 4 -.IX Item "cekalg (OSSL_KDF_PARAM_CEK_ALG) " -See \*(L"\s-1KDF\s0 Parameters\*(R" in \fBprovider\-kdf\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -The examples assume a host and peer both generate keys using the same -named group (or domain parameters). See \*(L"Examples\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7). -Both the host and peer transfer their public key to each other. -.PP -To convert the peer's generated key pair to a public key in \s-1DER\s0 format in order -to transfer to the host: -.PP -.Vb 3 -\& EVP_PKEY *peer_key; /* It is assumed this contains the peers generated key */ -\& unsigned char *peer_pub_der = NULL; -\& int peer_pub_der_len; -\& -\& peer_pub_der_len = i2d_PUBKEY(peer_key, &peer_pub_der); -\& ... -\& OPENSSL_free(peer_pub_der); -.Ve -.PP -To convert the received peer's public key from \s-1DER\s0 format on the host: -.PP -.Vb 4 -\& const unsigned char *pd = peer_pub_der; -\& EVP_PKEY *peer_pub_key = d2i_PUBKEY(NULL, &pd, peer_pub_der_len); -\& ... -\& EVP_PKEY_free(peer_pub_key); -.Ve -.PP -To derive a shared secret on the host using the host's key and the peer's public -key: -.PP -.Vb 8 -\& /* It is assumed that the host_key and peer_pub_key are set up */ -\& void derive_secret(EVP_KEY *host_key, EVP_PKEY *peer_pub_key) -\& { -\& unsigned int pad = 1; -\& OSSL_PARAM params[2]; -\& unsigned char *secret = NULL; -\& size_t secret_len = 0; -\& EVP_PKEY_CTX *dctx = EVP_PKEY_CTX_new_from_pkey(NULL, host_key, NULL); -\& -\& EVP_PKEY_derive_init(dctx); -\& -\& /* Optionally set the padding */ -\& params[0] = OSSL_PARAM_construct_uint(OSSL_EXCHANGE_PARAM_PAD, &pad); -\& params[1] = OSSL_PARAM_construct_end(); -\& EVP_PKEY_CTX_set_params(dctx, params); -\& -\& EVP_PKEY_derive_set_peer(dctx, peer_pub_key); -\& -\& /* Get the size by passing NULL as the buffer */ -\& EVP_PKEY_derive(dctx, NULL, &secret_len); -\& secret = OPENSSL_zalloc(secret_len); -\& -\& EVP_PKEY_derive(dctx, secret, &secret_len); -\& ... -\& OPENSSL_clear_free(secret, secret_len); -\& EVP_PKEY_CTX_free(dctx); -\& } -.Ve -.PP -Very similar code can be used by the peer to derive the same shared secret -using the host's public key and the peer's generated key pair. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-DH\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-FFC\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keyexch\fR\|(7), -\&\fBprovider\-keymgmt\fR\|(7), -\&\fBOSSL_PROVIDER\-default\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KEYEXCH-ECDH.7ossl b/openssl-install/share/man/man7/EVP_KEYEXCH-ECDH.7ossl deleted file mode 100644 index 9de9ebba..00000000 --- a/openssl-install/share/man/man7/EVP_KEYEXCH-ECDH.7ossl +++ /dev/null @@ -1,269 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEYEXCH-ECDH 7ossl" -.TH EVP_KEYEXCH-ECDH 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEYEXCH\-ECDH \- ECDH Key Exchange algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Key exchange support for the \fB\s-1ECDH\s0\fR key type. -.SS "\s-1ECDH\s0 Key Exchange parameters" -.IX Subsection "ECDH Key Exchange parameters" -.ie n .IP """ecdh-cofactor-mode"" (\fB\s-1OSSL_EXCHANGE_PARAM_EC_ECDH_COFACTOR_MODE\s0\fR) " 4 -.el .IP "``ecdh-cofactor-mode'' (\fB\s-1OSSL_EXCHANGE_PARAM_EC_ECDH_COFACTOR_MODE\s0\fR) " 4 -.IX Item "ecdh-cofactor-mode (OSSL_EXCHANGE_PARAM_EC_ECDH_COFACTOR_MODE) " -Sets or gets the \s-1ECDH\s0 mode of operation for the associated key exchange ctx. -.Sp -In the context of an Elliptic Curve Diffie-Hellman key exchange, this parameter -can be used to select between the plain Diffie-Hellman (\s-1DH\s0) or Cofactor -Diffie-Hellman (\s-1CDH\s0) variants of the key exchange algorithm. -.Sp -When setting, the value should be 1, 0 or \-1, respectively forcing cofactor mode -on, off, or resetting it to the default for the private key associated with the -given key exchange ctx. -.Sp -When getting, the value should be either 1 or 0, respectively signaling if the -cofactor mode is on or off. -.Sp -See also \fBprovider\-keymgmt\fR\|(7) for the related -\&\fB\s-1OSSL_PKEY_PARAM_USE_COFACTOR_ECDH\s0\fR parameter that can be set on a -per-key basis. -.ie n .IP """kdf-type"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-type'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-type (OSSL_EXCHANGE_PARAM_KDF_TYPE) " -.PD 0 -.ie n .IP """kdf-digest"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-digest'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-digest (OSSL_EXCHANGE_PARAM_KDF_DIGEST) " -.ie n .IP """kdf-digest-props"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-digest-props'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-digest-props (OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS) " -.ie n .IP """kdf-outlen"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_OUTLEN\s0\fR) " 4 -.el .IP "``kdf-outlen'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_OUTLEN\s0\fR) " 4 -.IX Item "kdf-outlen (OSSL_EXCHANGE_PARAM_KDF_OUTLEN) " -.ie n .IP """kdf-ukm"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.el .IP "``kdf-ukm'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.IX Item "kdf-ukm (OSSL_EXCHANGE_PARAM_KDF_UKM) " -.PD -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) " -.PD 0 -.ie n .IP """key-check"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK) " -.ie n .IP """digest-check"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK) " -.PD -See \*(L"Common Key Exchange parameters\*(R" in \fBprovider\-keyexch\fR\|(7). -.ie n .IP """ecdh-cofactor-check"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_ECDH_COFACTOR_CHECK\s0\fR) " 4 -.el .IP "``ecdh-cofactor-check'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_ECDH_COFACTOR_CHECK\s0\fR) " 4 -.IX Item "ecdh-cofactor-check (OSSL_EXCHANGE_PARAM_FIPS_ECDH_COFACTOR_CHECK) " -If required this parameter should before \fBOSSL_FUNC_keyexch_derive()\fR. -The default value of 1 causes an error during the OSSL_FUNC_keyexch_derive if -the \s-1EC\s0 curve has a cofactor that is not 1, and the cofactor is not used. -Setting this to 0 will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Examples of key agreement can be found in demos/keyexch. -.PP -Keys for the host and peer must be generated as shown in -\&\*(L"Examples\*(R" in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) using the same curve name. -.PP -The code to generate a shared secret for the normal case is identical to -\&\*(L"Examples\*(R" in \s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7). -.PP -To derive a shared secret on the host using the host's key and the peer's public -key but also using X963KDF with a user key material: -.PP -.Vb 10 -\& /* It is assumed that the host_key, peer_pub_key and ukm are set up */ -\& void derive_secret(EVP_PKEY *host_key, EVP_PKEY *peer_key, -\& unsigned char *ukm, size_t ukm_len) -\& { -\& unsigned char secret[64]; -\& size_t out_len = sizeof(secret); -\& size_t secret_len = out_len; -\& unsigned int pad = 1; -\& OSSL_PARAM params[6]; -\& EVP_PKEY_CTX *dctx = EVP_PKEY_CTX_new_from_pkey(NULL, host_key, NULL); -\& -\& EVP_PKEY_derive_init(dctx); -\& -\& params[0] = OSSL_PARAM_construct_uint(OSSL_EXCHANGE_PARAM_PAD, &pad); -\& params[1] = OSSL_PARAM_construct_utf8_string(OSSL_EXCHANGE_PARAM_KDF_TYPE, -\& "X963KDF", 0); -\& params[2] = OSSL_PARAM_construct_utf8_string(OSSL_EXCHANGE_PARAM_KDF_DIGEST, -\& "SHA1", 0); -\& params[3] = OSSL_PARAM_construct_size_t(OSSL_EXCHANGE_PARAM_KDF_OUTLEN, -\& &out_len); -\& params[4] = OSSL_PARAM_construct_octet_string(OSSL_EXCHANGE_PARAM_KDF_UKM, -\& ukm, ukm_len); -\& params[5] = OSSL_PARAM_construct_end(); -\& EVP_PKEY_CTX_set_params(dctx, params); -\& -\& EVP_PKEY_derive_set_peer(dctx, peer_pub_key); -\& EVP_PKEY_derive(dctx, secret, &secret_len); -\& ... -\& OPENSSL_clear_free(secret, secret_len); -\& EVP_PKEY_CTX_free(dctx); -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-EC\s0\fR\|(7) -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keyexch\fR\|(7), -\&\fBprovider\-keymgmt\fR\|(7), -\&\fBOSSL_PROVIDER\-default\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KEYEXCH-X25519.7ossl b/openssl-install/share/man/man7/EVP_KEYEXCH-X25519.7ossl deleted file mode 100644 index c7f52f52..00000000 --- a/openssl-install/share/man/man7/EVP_KEYEXCH-X25519.7ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_KEYEXCH-X25519 7ossl" -.TH EVP_KEYEXCH-X25519 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_KEYEXCH\-X25519, -EVP_KEYEXCH\-X448 -\&\- X25519 and X448 Key Exchange algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Key exchange support for the \fBX25519\fR and \fBX448\fR key types. -.SS "Key exchange parameters" -.IX Subsection "Key exchange parameters" -.ie n .IP """pad"" (\fB\s-1OSSL_EXCHANGE_PARAM_PAD\s0\fR) " 4 -.el .IP "``pad'' (\fB\s-1OSSL_EXCHANGE_PARAM_PAD\s0\fR) " 4 -.IX Item "pad (OSSL_EXCHANGE_PARAM_PAD) " -.PD 0 -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) " -.PD -\&\fBX25519\fR and \fBX448\fR are not \s-1FIPS\s0 approved in \s-1FIPS 140\-3.\s0 -So this getter will return 0. -.Sp -See \*(L"Common Key Exchange parameters\*(R" in \fBprovider\-keyexch\fR\|(7). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Keys for the host and peer can be generated as shown in -\&\*(L"Examples\*(R" in \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7). -.PP -The code to generate a shared secret is identical to -\&\*(L"Examples\*(R" in \s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-FFC\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-DH\s0\fR\|(7) -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keyexch\fR\|(7), -\&\fBprovider\-keymgmt\fR\|(7), -\&\fBOSSL_PROVIDER\-default\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_KEYEXCH-X448.7ossl b/openssl-install/share/man/man7/EVP_KEYEXCH-X448.7ossl deleted file mode 120000 index 1278a3f8..00000000 --- a/openssl-install/share/man/man7/EVP_KEYEXCH-X448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_KEYEXCH-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-CMAC.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-CMAC.7ossl deleted file mode 120000 index e258700c..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-CMAC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-DH.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-DH.7ossl deleted file mode 120000 index cdb249c3..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-DH.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-DH.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-DHX.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-DHX.7ossl deleted file mode 120000 index cdb249c3..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-DHX.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-DH.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-DSA.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-DSA.7ossl deleted file mode 120000 index bbec8646..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-DSA.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-DSA.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-EC.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-EC.7ossl deleted file mode 120000 index 4ab03e18..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-EC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-EC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-ED25519.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-ED25519.7ossl deleted file mode 120000 index 564c378e..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-ED25519.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-ED448.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-ED448.7ossl deleted file mode 120000 index 564c378e..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-ED448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-HMAC.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-HMAC.7ossl deleted file mode 120000 index e258700c..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-HMAC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-Poly1305.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-Poly1305.7ossl deleted file mode 120000 index e258700c..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-Poly1305.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-RSA.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-RSA.7ossl deleted file mode 120000 index 95ecf373..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-RSA.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-RSA.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-SM2.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-SM2.7ossl deleted file mode 120000 index a439e053..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-SM2.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-SM2.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-Siphash.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-Siphash.7ossl deleted file mode 120000 index e258700c..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-Siphash.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-X25519.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-X25519.7ossl deleted file mode 120000 index 564c378e..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-X25519.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_KEYMGMT-X448.7ossl b/openssl-install/share/man/man7/EVP_KEYMGMT-X448.7ossl deleted file mode 120000 index 564c378e..00000000 --- a/openssl-install/share/man/man7/EVP_KEYMGMT-X448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_MAC-BLAKE2.7ossl b/openssl-install/share/man/man7/EVP_MAC-BLAKE2.7ossl deleted file mode 100644 index fa7d5a07..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-BLAKE2.7ossl +++ /dev/null @@ -1,216 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC-BLAKE2 7ossl" -.TH EVP_MAC-BLAKE2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC\-BLAKE2, EVP_MAC\-BLAKE2BMAC, EVP_MAC\-BLAKE2SMAC -\&\- The BLAKE2 EVP_MAC implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1BLAKE2\s0 MACs through the \fB\s-1EVP_MAC\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -These implementations are identified with one of these names and -properties, to be used with \fBEVP_MAC_fetch()\fR: -.ie n .IP """\s-1BLAKE2BMAC"",\s0 ""provider=default""" 4 -.el .IP "``\s-1BLAKE2BMAC'',\s0 ``provider=default''" 4 -.IX Item "BLAKE2BMAC, provider=default" -.PD 0 -.ie n .IP """\s-1BLAKE2SMAC"",\s0 ""provider=default""" 4 -.el .IP "``\s-1BLAKE2SMAC'',\s0 ``provider=default''" 4 -.IX Item "BLAKE2SMAC, provider=default" -.PD -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The general description of these parameters can be found in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3). -.PP -All these parameters (except for \*(L"block-size\*(R") can be set with -\&\fBEVP_MAC_CTX_set_params()\fR. -Furthermore, the \*(L"size\*(R" parameter can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR, or with \fBEVP_MAC_CTX_get_mac_size()\fR. -The length of the \*(L"size\*(R" parameter should not exceed that of a \fBsize_t\fR. -Likewise, the \*(L"block-size\*(R" parameter can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR, or with \fBEVP_MAC_CTX_get_block_size()\fR. -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Sets the \s-1MAC\s0 key. -It may be at most 64 bytes for \s-1BLAKE2BMAC\s0 or 32 for \s-1BLAKE2SMAC\s0 and at -least 1 byte in both cases. -Setting this parameter is identical to passing a \fIkey\fR to \fBEVP_MAC_init\fR\|(3). -.ie n .IP """custom"" (\fB\s-1OSSL_MAC_PARAM_CUSTOM\s0\fR) " 4 -.el .IP "``custom'' (\fB\s-1OSSL_MAC_PARAM_CUSTOM\s0\fR) " 4 -.IX Item "custom (OSSL_MAC_PARAM_CUSTOM) " -Sets the customization/personalization string. -It is an optional value of at most 16 bytes for \s-1BLAKE2BMAC\s0 or 8 for -\&\s-1BLAKE2SMAC,\s0 and is empty by default. -.ie n .IP """salt"" (\fB\s-1OSSL_MAC_PARAM_SALT\s0\fR) " 4 -.el .IP "``salt'' (\fB\s-1OSSL_MAC_PARAM_SALT\s0\fR) " 4 -.IX Item "salt (OSSL_MAC_PARAM_SALT) " -Sets the salt. -It is an optional value of at most 16 bytes for \s-1BLAKE2BMAC\s0 or 8 for -\&\s-1BLAKE2SMAC,\s0 and is empty by default. -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -Sets the \s-1MAC\s0 size. -It can be any number between 1 and 32 for \s-1EVP_MAC_BLAKE2S\s0 or between 1 -and 64 for \s-1EVP_MAC_BLAKE2B.\s0 -It is 32 and 64 respectively by default. -.ie n .IP """block-size"" (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``block-size'' (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "block-size (OSSL_MAC_PARAM_BLOCK_SIZE) " -Gets the \s-1MAC\s0 block size. -It is 64 for \s-1EVP_MAC_BLAKE2S\s0 and 128 for \s-1EVP_MAC_BLAKE2B.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_CTX_get_params\fR\|(3), \fBEVP_MAC_CTX_set_params\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The macros and functions described here were added to OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MAC-BLAKE2BMAC.7ossl b/openssl-install/share/man/man7/EVP_MAC-BLAKE2BMAC.7ossl deleted file mode 120000 index 30823522..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-BLAKE2BMAC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC-BLAKE2.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_MAC-BLAKE2SMAC.7ossl b/openssl-install/share/man/man7/EVP_MAC-BLAKE2SMAC.7ossl deleted file mode 120000 index 30823522..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-BLAKE2SMAC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC-BLAKE2.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_MAC-CMAC.7ossl b/openssl-install/share/man/man7/EVP_MAC-CMAC.7ossl deleted file mode 100644 index 8ba83a12..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-CMAC.7ossl +++ /dev/null @@ -1,222 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC-CMAC 7ossl" -.TH EVP_MAC-CMAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC\-CMAC \- The CMAC EVP_MAC implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1CMAC\s0 MACs through the \fB\s-1EVP_MAC\s0\fR \s-1API.\s0 -.PP -This implementation uses \s-1EVP_CIPHER\s0 functions to get access to the underlying -cipher. -.SS "Identity" -.IX Subsection "Identity" -This implementation is identified with this name and properties, to be -used with \fBEVP_MAC_fetch()\fR: -.ie n .IP """\s-1CMAC"",\s0 ""provider=default"" or ""provider=fips""" 4 -.el .IP "``\s-1CMAC'',\s0 ``provider=default'' or ``provider=fips''" 4 -.IX Item "CMAC, provider=default or provider=fips" -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The general description of these parameters can be found in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3). -.PP -The following parameter can be set with \fBEVP_MAC_CTX_set_params()\fR: -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Sets the \s-1MAC\s0 key. -Setting this parameter is identical to passing a \fIkey\fR to \fBEVP_MAC_init\fR\|(3). -.ie n .IP """cipher"" (\fB\s-1OSSL_MAC_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_MAC_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_MAC_PARAM_CIPHER) " -Sets the name of the underlying cipher to be used. The mode of the cipher -must be \s-1CBC.\s0 -.ie n .IP """properties"" (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_MAC_PARAM_PROPERTIES) " -Sets the properties to be queried when trying to fetch the underlying cipher. -This must be given together with the cipher naming parameter to be considered -valid. -.ie n .IP """encrypt-check"" (\fB\s-1OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK\s0\fR) " 4 -.el .IP "``encrypt-check'' (\fB\s-1OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK\s0\fR) " 4 -.IX Item "encrypt-check (OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK) " -This option is used by the OpenSSL \s-1FIPS\s0 provider. -If required this parameter should be set before \fBEVP_MAC_init()\fR -.Sp -The default value of 1 causes an error when a unapproved Triple-DES encryption -operation is triggered. -Setting this to 0 will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.PP -The following parameters can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR: -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -The \*(L"size\*(R" parameter can also be retrieved with with \fBEVP_MAC_CTX_get_mac_size()\fR. -The length of the \*(L"size\*(R" parameter is equal to that of an \fBunsigned int\fR. -.ie n .IP """block-size"" (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``block-size'' (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "block-size (OSSL_MAC_PARAM_BLOCK_SIZE) " -Gets the \s-1MAC\s0 block size. The \*(L"block-size\*(R" parameter can also be retrieved with -\&\fBEVP_MAC_CTX_get_block_size()\fR. -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) " -This option is used by the OpenSSL \s-1FIPS\s0 provider. -.Sp -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling \fBEVP_MAC_final()\fR. -It may return 0 if the \*(L"encrypt-check\*(R" option is set to 0. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_CTX_get_params\fR\|(3), \fBEVP_MAC_CTX_set_params\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MAC-GMAC.7ossl b/openssl-install/share/man/man7/EVP_MAC-GMAC.7ossl deleted file mode 100644 index 1aefe112..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-GMAC.7ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC-GMAC 7ossl" -.TH EVP_MAC-GMAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC\-GMAC \- The GMAC EVP_MAC implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1GMAC\s0 MACs through the \fB\s-1EVP_MAC\s0\fR \s-1API.\s0 -.PP -This implementation uses \s-1EVP_CIPHER\s0 functions to get access to the underlying -cipher. -.SS "Identity" -.IX Subsection "Identity" -This implementation is identified with this name and properties, to be -used with \fBEVP_MAC_fetch()\fR: -.ie n .IP """\s-1GMAC"",\s0 ""provider=default"" or ""provider=fips""" 4 -.el .IP "``\s-1GMAC'',\s0 ``provider=default'' or ``provider=fips''" 4 -.IX Item "GMAC, provider=default or provider=fips" -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The general description of these parameters can be found in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3). -.PP -The following parameter can be set with \fBEVP_MAC_CTX_set_params()\fR: -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Sets the \s-1MAC\s0 key. -Setting this parameter is identical to passing a \fIkey\fR to \fBEVP_MAC_init\fR\|(3). -.ie n .IP """iv"" (\fB\s-1OSSL_MAC_PARAM_IV\s0\fR) " 4 -.el .IP "``iv'' (\fB\s-1OSSL_MAC_PARAM_IV\s0\fR) " 4 -.IX Item "iv (OSSL_MAC_PARAM_IV) " -Sets the \s-1IV\s0 of the underlying cipher, when applicable. -.ie n .IP """cipher"" (\fB\s-1OSSL_MAC_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_MAC_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_MAC_PARAM_CIPHER) " -Sets the name of the underlying cipher to be used. -.ie n .IP """properties"" (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_MAC_PARAM_PROPERTIES) " -Sets the properties to be queried when trying to fetch the underlying cipher. -This must be given together with the cipher naming parameter to be considered -valid. -.PP -The following parameters can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR: -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -Gets the \s-1MAC\s0 size. -.PP -The \*(L"size\*(R" parameter can also be retrieved with \fBEVP_MAC_CTX_get_mac_size()\fR. -The length of the \*(L"size\*(R" parameter is equal to that of an \fBunsigned int\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_CTX_get_params\fR\|(3), \fBEVP_MAC_CTX_set_params\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MAC-HMAC.7ossl b/openssl-install/share/man/man7/EVP_MAC-HMAC.7ossl deleted file mode 100644 index e4e31cce..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-HMAC.7ossl +++ /dev/null @@ -1,228 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC-HMAC 7ossl" -.TH EVP_MAC-HMAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC\-HMAC \- The HMAC EVP_MAC implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1HMAC\s0 MACs through the \fB\s-1EVP_MAC\s0\fR \s-1API.\s0 -.PP -This implementation uses \s-1EVP_MD\s0 functions to get access to the underlying -digest. -.SS "Identity" -.IX Subsection "Identity" -This implementation is identified with this name and properties, to be -used with \fBEVP_MAC_fetch()\fR: -.ie n .IP """\s-1HMAC"",\s0 ""provider=default"" or ""provider=fips""" 4 -.el .IP "``\s-1HMAC'',\s0 ``provider=default'' or ``provider=fips''" 4 -.IX Item "HMAC, provider=default or provider=fips" -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The general description of these parameters can be found in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3). -.PP -The following parameters can be set with \fBEVP_MAC_CTX_set_params()\fR: -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Sets the \s-1MAC\s0 key. -Setting this parameter is identical to passing a \fIkey\fR to \fBEVP_MAC_init\fR\|(3). -.ie n .IP """digest"" (\fB\s-1OSSL_MAC_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_MAC_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_MAC_PARAM_DIGEST) " -Sets the name of the underlying digest to be used. -.ie n .IP """properties"" (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_MAC_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_MAC_PARAM_PROPERTIES) " -Sets the properties to be queried when trying to fetch the underlying digest. -This must be given together with the digest naming parameter (\*(L"digest\*(R", or -\&\fB\s-1OSSL_MAC_PARAM_DIGEST\s0\fR) to be considered valid. -.ie n .IP """digest-noinit"" (\fB\s-1OSSL_MAC_PARAM_DIGEST_NOINIT\s0\fR) " 4 -.el .IP "``digest-noinit'' (\fB\s-1OSSL_MAC_PARAM_DIGEST_NOINIT\s0\fR) " 4 -.IX Item "digest-noinit (OSSL_MAC_PARAM_DIGEST_NOINIT) " -A flag to set the \s-1MAC\s0 digest to not initialise the implementation -specific data. -The value 0 or 1 is expected. -This option is deprecated and will be removed in a future release. -It may be set but is currently ignored -.ie n .IP """digest-oneshot"" (\fB\s-1OSSL_MAC_PARAM_DIGEST_ONESHOT\s0\fR) " 4 -.el .IP "``digest-oneshot'' (\fB\s-1OSSL_MAC_PARAM_DIGEST_ONESHOT\s0\fR) " 4 -.IX Item "digest-oneshot (OSSL_MAC_PARAM_DIGEST_ONESHOT) " -A flag to set the \s-1MAC\s0 digest to be a one-shot operation. -The value 0 or 1 is expected. -This option is deprecated and will be removed in a future release. -It may be set but is currently ignored. -.ie n .IP """tls-data-size"" (\fB\s-1OSSL_MAC_PARAM_TLS_DATA_SIZE\s0\fR) " 4 -.el .IP "``tls-data-size'' (\fB\s-1OSSL_MAC_PARAM_TLS_DATA_SIZE\s0\fR) " 4 -.IX Item "tls-data-size (OSSL_MAC_PARAM_TLS_DATA_SIZE) " -.PD 0 -.ie n .IP """key-check"" (\fB\s-1OSSL_MAC_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_MAC_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_MAC_PARAM_FIPS_KEY_CHECK) " -.PD -See \*(L"Mac Parameters\*(R" in \fBprovider\-mac\fR\|(7). -.PP -The following parameters can be retrieved with \fBEVP_MAC_CTX_get_params()\fR: -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -The \*(L"size\*(R" parameter can also be retrieved with \fBEVP_MAC_CTX_get_mac_size()\fR. -The length of the \*(L"size\*(R" parameter is equal to that of an \fBunsigned int\fR. -.ie n .IP """block-size"" (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``block-size'' (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "block-size (OSSL_MAC_PARAM_BLOCK_SIZE) " -Gets the \s-1MAC\s0 block size. The \*(L"block-size\*(R" parameter can also be retrieved with -\&\fBEVP_MAC_CTX_get_block_size()\fR. -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR) " -See \*(L"Mac Parameters\*(R" in \fBprovider\-mac\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_CTX_get_params\fR\|(3), \fBEVP_MAC_CTX_set_params\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3), \s-1\fBHMAC\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MAC-KMAC.7ossl b/openssl-install/share/man/man7/EVP_MAC-KMAC.7ossl deleted file mode 100644 index 053ae093..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-KMAC.7ossl +++ /dev/null @@ -1,296 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC-KMAC 7ossl" -.TH EVP_MAC-KMAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC\-KMAC, EVP_MAC\-KMAC128, EVP_MAC\-KMAC256 -\&\- The KMAC EVP_MAC implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1KMAC\s0 MACs through the \fB\s-1EVP_MAC\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -These implementations are identified with one of these names and -properties, to be used with \fBEVP_MAC_fetch()\fR: -.ie n .IP """\s-1KMAC\-128"",\s0 ""provider=default"" or ""provider=fips""" 4 -.el .IP "``\s-1KMAC\-128'',\s0 ``provider=default'' or ``provider=fips''" 4 -.IX Item "KMAC-128, provider=default or provider=fips" -.PD 0 -.ie n .IP """\s-1KMAC\-256"",\s0 ""provider=default"" or ""provider=fips""" 4 -.el .IP "``\s-1KMAC\-256'',\s0 ``provider=default'' or ``provider=fips''" 4 -.IX Item "KMAC-256, provider=default or provider=fips" -.PD -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The general description of these parameters can be found in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3). -.PP -All these parameters (except for \*(L"block-size\*(R") can be set with -\&\fBEVP_MAC_CTX_set_params()\fR. -Furthermore, the \*(L"size\*(R" parameter can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR, or with \fBEVP_MAC_CTX_get_mac_size()\fR. -The length of the \*(L"size\*(R" parameter should not exceed that of a \fBsize_t\fR. -Likewise, the \*(L"block-size\*(R" parameter can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR, or with \fBEVP_MAC_CTX_get_block_size()\fR. -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Sets the \s-1MAC\s0 key. -Setting this parameter is identical to passing a \fIkey\fR to \fBEVP_MAC_init\fR\|(3). -The length of the key (in bytes) must be in the range 4...512. -.ie n .IP """custom"" (\fB\s-1OSSL_MAC_PARAM_CUSTOM\s0\fR) " 4 -.el .IP "``custom'' (\fB\s-1OSSL_MAC_PARAM_CUSTOM\s0\fR) " 4 -.IX Item "custom (OSSL_MAC_PARAM_CUSTOM) " -Sets the customization string. -It is an optional value with a length of at most 512 bytes, and is -empty by default. -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -Sets the \s-1MAC\s0 size. -By default, it is 32 for \f(CW\*(C`KMAC\-128\*(C'\fR and 64 for \f(CW\*(C`KMAC\-256\*(C'\fR. -.ie n .IP """block-size"" (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``block-size'' (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "block-size (OSSL_MAC_PARAM_BLOCK_SIZE) " -Gets the \s-1MAC\s0 block size. -It is 168 for \f(CW\*(C`KMAC\-128\*(C'\fR and 136 for \f(CW\*(C`KMAC\-256\*(C'\fR. -.ie n .IP """xof"" (\fB\s-1OSSL_MAC_PARAM_XOF\s0\fR) " 4 -.el .IP "``xof'' (\fB\s-1OSSL_MAC_PARAM_XOF\s0\fR) " 4 -.IX Item "xof (OSSL_MAC_PARAM_XOF) " -The \*(L"xof\*(R" parameter value is expected to be 1 or 0. Use 1 to enable \s-1XOF\s0 mode. -The default value is 0. -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR) " -This settable parameter is described in \fBprovider\-mac\fR\|(7). -.ie n .IP """no-short-mac"" (\fB\s-1OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC\s0\fR) " 4 -.el .IP "``no-short-mac'' (\fB\s-1OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC\s0\fR) " 4 -.IX Item "no-short-mac (OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC) " -This settable parameter is described in \fBprovider\-mac\fR\|(7). It is used by -the OpenSSL \s-1FIPS\s0 provider and the minimum length output for \s-1KMAC\s0 -is defined by \s-1NIST\s0's \s-1SP 800\-185 8.4.2.\s0 -.ie n .IP """key-check"" (\fB\s-1OSSL_MAC_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_MAC_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_MAC_PARAM_FIPS_KEY_CHECK) " -This settable parameter is described in \fBprovider\-mac\fR\|(7). -.PP -The \*(L"custom\*(R" and \*(L"no-short-mac\*(R" parameters must be set as part of or before -the \fBEVP_MAC_init()\fR call. -The \*(L"xof\*(R" and \*(L"size\*(R" parameters can be set at any time before \fBEVP_MAC_final()\fR. -The \*(L"key\*(R" parameter is set as part of the \fBEVP_MAC_init()\fR call, but can be -set before it instead. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 2 -\& #include -\& #include -\& -\& static int do_kmac(const unsigned char *in, size_t in_len, -\& const unsigned char *key, size_t key_len, -\& const unsigned char *custom, size_t custom_len, -\& int xof_enabled, unsigned char *out, int out_len) -\& { -\& EVP_MAC_CTX *ctx = NULL; -\& EVP_MAC *mac = NULL; -\& OSSL_PARAM params[4], *p; -\& int ret = 0; -\& size_t l = 0; -\& -\& mac = EVP_MAC_fetch(NULL, "KMAC\-128", NULL); -\& if (mac == NULL) -\& goto err; -\& ctx = EVP_MAC_CTX_new(mac); -\& /* The mac can be freed after it is used by EVP_MAC_CTX_new */ -\& EVP_MAC_free(mac); -\& if (ctx == NULL) -\& goto err; -\& -\& /* -\& * Setup parameters required before calling EVP_MAC_init() -\& * The parameters OSSL_MAC_PARAM_XOF and OSSL_MAC_PARAM_SIZE may also be -\& * used at this point. -\& */ -\& p = params; -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY, -\& (void *)key, key_len); -\& if (custom != NULL && custom_len != 0) -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_CUSTOM, -\& (void *)custom, custom_len); -\& *p = OSSL_PARAM_construct_end(); -\& if (!EVP_MAC_CTX_set_params(ctx, params)) -\& goto err; -\& -\& if (!EVP_MAC_init(ctx)) -\& goto err; -\& -\& /* -\& * Note: the following optional parameters can be set any time -\& * before EVP_MAC_final(). -\& */ -\& p = params; -\& *p++ = OSSL_PARAM_construct_int(OSSL_MAC_PARAM_XOF, &xof_enabled); -\& *p++ = OSSL_PARAM_construct_int(OSSL_MAC_PARAM_SIZE, &out_len); -\& *p = OSSL_PARAM_construct_end(); -\& if (!EVP_MAC_CTX_set_params(ctx, params)) -\& goto err; -\& -\& /* The update may be called multiple times here for streamed input */ -\& if (!EVP_MAC_update(ctx, in, in_len)) -\& goto err; -\& if (!EVP_MAC_final(ctx, out, &l, out_len)) -\& goto err; -\& ret = 1; -\& err: -\& EVP_MAC_CTX_free(ctx); -\& return ret; -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_CTX_get_params\fR\|(3), \fBEVP_MAC_CTX_set_params\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3), -\&\s-1SP 800\-185 8.4.2\s0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MAC-KMAC128.7ossl b/openssl-install/share/man/man7/EVP_MAC-KMAC128.7ossl deleted file mode 120000 index 74190af6..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-KMAC128.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC-KMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_MAC-KMAC256.7ossl b/openssl-install/share/man/man7/EVP_MAC-KMAC256.7ossl deleted file mode 120000 index 74190af6..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-KMAC256.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MAC-KMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_MAC-Poly1305.7ossl b/openssl-install/share/man/man7/EVP_MAC-Poly1305.7ossl deleted file mode 100644 index a3f21636..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-Poly1305.7ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC-POLY1305 7ossl" -.TH EVP_MAC-POLY1305 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC\-Poly1305 \- The Poly1305 EVP_MAC implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing Poly1305 MACs through the \fB\s-1EVP_MAC\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is identified with this name and properties, to be -used with \fBEVP_MAC_fetch()\fR: -.ie n .IP """\s-1POLY1305"",\s0 ""provider=default""" 4 -.el .IP "``\s-1POLY1305'',\s0 ``provider=default''" 4 -.IX Item "POLY1305, provider=default" -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The general description of these parameters can be found in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3). -.PP -The following parameter can be set with \fBEVP_MAC_CTX_set_params()\fR: -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Sets the \s-1MAC\s0 key. -Setting this parameter is identical to passing a \fIkey\fR to \fBEVP_MAC_init\fR\|(3). -.PP -The following parameters can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR: -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -Gets the \s-1MAC\s0 size. -.PP -The \*(L"size\*(R" parameter can also be retrieved with with \fBEVP_MAC_CTX_get_mac_size()\fR. -The length of the \*(L"size\*(R" parameter should not exceed that of an \fBunsigned int\fR. -.SH "NOTES" -.IX Header "NOTES" -The OpenSSL implementation of the Poly 1305 \s-1MAC\s0 corresponds to \s-1RFC 7539.\s0 -.PP -It is critical to never reuse the key. The security implication noted in -\&\s-1RFC 8439\s0 applies equally to the OpenSSL implementation. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_CTX_get_params\fR\|(3), \fBEVP_MAC_CTX_set_params\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MAC-Siphash.7ossl b/openssl-install/share/man/man7/EVP_MAC-Siphash.7ossl deleted file mode 100644 index 3066cf84..00000000 --- a/openssl-install/share/man/man7/EVP_MAC-Siphash.7ossl +++ /dev/null @@ -1,190 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MAC-SIPHASH 7ossl" -.TH EVP_MAC-SIPHASH 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MAC\-Siphash \- The Siphash EVP_MAC implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing Siphash MACs through the \fB\s-1EVP_MAC\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is identified with this name and properties, to be -used with \fBEVP_MAC_fetch()\fR: -.ie n .IP """\s-1SIPHASH"",\s0 ""provider=default""" 4 -.el .IP "``\s-1SIPHASH'',\s0 ``provider=default''" 4 -.IX Item "SIPHASH, provider=default" -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The general description of these parameters can be found in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3). -.PP -All these parameters can be set with \fBEVP_MAC_CTX_set_params()\fR. -Furthermore, the \*(L"size\*(R" parameter can be retrieved with -\&\fBEVP_MAC_CTX_get_params()\fR, or with \fBEVP_MAC_CTX_get_mac_size()\fR. -The length of the \*(L"size\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -Sets the \s-1MAC\s0 key. -Setting this parameter is identical to passing a \fIkey\fR to \fBEVP_MAC_init\fR\|(3). -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -Sets the \s-1MAC\s0 size. -.ie n .IP """c\-rounds"" (\fB\s-1OSSL_MAC_PARAM_C_ROUNDS\s0\fR) " 4 -.el .IP "``c\-rounds'' (\fB\s-1OSSL_MAC_PARAM_C_ROUNDS\s0\fR) " 4 -.IX Item "c-rounds (OSSL_MAC_PARAM_C_ROUNDS) " -Specifies the number of rounds per message block. By default this is \fI2\fR. -.ie n .IP """d\-rounds"" (\fB\s-1OSSL_MAC_PARAM_D_ROUNDS\s0\fR) " 4 -.el .IP "``d\-rounds'' (\fB\s-1OSSL_MAC_PARAM_D_ROUNDS\s0\fR) " 4 -.IX Item "d-rounds (OSSL_MAC_PARAM_D_ROUNDS) " -Specifies the number of finalisation rounds. By default this is \fI4\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_CTX_get_params\fR\|(3), \fBEVP_MAC_CTX_set_params\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBOSSL_PARAM\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-BLAKE2.7ossl b/openssl-install/share/man/man7/EVP_MD-BLAKE2.7ossl deleted file mode 100644 index 99e2cb1b..00000000 --- a/openssl-install/share/man/man7/EVP_MD-BLAKE2.7ossl +++ /dev/null @@ -1,198 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-BLAKE2 7ossl" -.TH EVP_MD-BLAKE2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-BLAKE2 \- The BLAKE2 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1BLAKE2\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identities" -.IX Subsection "Identities" -This implementation is only available with the default provider, and -includes the following varieties: -.IP "\s-1BLAKE2S\-256\s0" 4 -.IX Item "BLAKE2S-256" -Known names are \*(L"\s-1BLAKE2S\-256\*(R"\s0 and \*(L"BLAKE2s256\*(R". -.IP "\s-1BLAKE2B\-512\s0" 4 -.IX Item "BLAKE2B-512" -Known names are \*(L"\s-1BLAKE2B\-512\*(R"\s0 and \*(L"BLAKE2b512\*(R". -.SS "Settable Parameters" -.IX Subsection "Settable Parameters" -\&\*(L"\s-1BLAKE2B\-512\*(R"\s0 supports the following \fBEVP_MD_CTX_set_params()\fR key -described in \*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_DigestInit\fR\|(3). -.ie n .IP """size"" (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_DIGEST_PARAM_SIZE) " -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SS "Settable Context Parameters" -.IX Subsection "Settable Context Parameters" -The implementation supports the following \s-1\fBOSSL_PARAM\s0\fR\|(3) entries which -are settable for an \fB\s-1EVP_MD_CTX\s0\fR with \fBEVP_DigestInit_ex2\fR\|(3) or -\&\fBEVP_MD_CTX_set_params\fR\|(3): -.ie n .IP """size"" (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_DIGEST_PARAM_SIZE) " -Sets a different digest length for the \fBEVP_DigestFinal\fR\|(3) output. -The value of the \*(L"size\*(R" parameter must not exceed the default digest length -of the respective \s-1BLAKE2\s0 algorithm variants, 64 for \s-1BLAKE2B\-512\s0 and -32 for \s-1BLAKE2S\-256.\s0 The parameter must be set with the -\&\fBEVP_DigestInit_ex2\fR\|(3) call to have an immediate effect. When set with -\&\fBEVP_MD_CTX_set_params\fR\|(3) it will have an effect only if the \fB\s-1EVP_MD_CTX\s0\fR -context is reinitialized. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.PP -The variable size support was added in OpenSSL 3.2 for \s-1BLAKE2B\-512\s0 and -in OpenSSL 3.3 for \s-1BLAKE2S\-256.\s0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-KECCAK-KMAC.7ossl b/openssl-install/share/man/man7/EVP_MD-KECCAK-KMAC.7ossl deleted file mode 120000 index 4ef4821a..00000000 --- a/openssl-install/share/man/man7/EVP_MD-KECCAK-KMAC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_MD-SHAKE.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_MD-KECCAK.7ossl b/openssl-install/share/man/man7/EVP_MD-KECCAK.7ossl deleted file mode 100644 index 4fb7dd3c..00000000 --- a/openssl-install/share/man/man7/EVP_MD-KECCAK.7ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-KECCAK 7ossl" -.TH EVP_MD-KECCAK 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-KECCAK \- The KECCAK EVP_MD implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1KECCAK\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identities" -.IX Subsection "Identities" -This implementation is available in the default provider and -includes the following varieties: -.ie n .IP """\s-1KECCAK\-224""\s0" 4 -.el .IP "``\s-1KECCAK\-224''\s0" 4 -.IX Item "KECCAK-224" -.PD 0 -.ie n .IP """\s-1KECCAK\-256""\s0" 4 -.el .IP "``\s-1KECCAK\-256''\s0" 4 -.IX Item "KECCAK-256" -.ie n .IP """\s-1KECCAK\-384""\s0" 4 -.el .IP "``\s-1KECCAK\-384''\s0" 4 -.IX Item "KECCAK-384" -.ie n .IP """\s-1KECCAK\-512""\s0" 4 -.el .IP "``\s-1KECCAK\-512''\s0" 4 -.IX Item "KECCAK-512" -.PD -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-MD2.7ossl b/openssl-install/share/man/man7/EVP_MD-MD2.7ossl deleted file mode 100644 index dd26cdb1..00000000 --- a/openssl-install/share/man/man7/EVP_MD-MD2.7ossl +++ /dev/null @@ -1,164 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-MD2 7ossl" -.TH EVP_MD-MD2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-MD2 \- The MD2 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1MD2\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is only available with the legacy provider, and is -identified with the name \*(L"\s-1MD2\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-MD4.7ossl b/openssl-install/share/man/man7/EVP_MD-MD4.7ossl deleted file mode 100644 index fad5989a..00000000 --- a/openssl-install/share/man/man7/EVP_MD-MD4.7ossl +++ /dev/null @@ -1,164 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-MD4 7ossl" -.TH EVP_MD-MD4 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-MD4 \- The MD4 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1MD4\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is only available with the legacy provider, and is -identified with the name \*(L"\s-1MD4\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-MD5-SHA1.7ossl b/openssl-install/share/man/man7/EVP_MD-MD5-SHA1.7ossl deleted file mode 100644 index e891e7ab..00000000 --- a/openssl-install/share/man/man7/EVP_MD-MD5-SHA1.7ossl +++ /dev/null @@ -1,181 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-MD5-SHA1 7ossl" -.TH EVP_MD-MD5-SHA1 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-MD5\-SHA1 \- The MD5\-SHA1 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1MD5\-SHA1\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.PP -\&\s-1MD5\-SHA1\s0 is a rather special digest that's used with SSLv3. -.SS "Identity" -.IX Subsection "Identity" -This implementation is only available with the default provider, and is -identified with the name \*(L"\s-1MD5\-SHA1\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SS "Settable Context Parameters" -.IX Subsection "Settable Context Parameters" -This implementation supports the following \s-1\fBOSSL_PARAM\s0\fR\|(3) entries, -settable for an \fB\s-1EVP_MD_CTX\s0\fR with \fBEVP_MD_CTX_set_params\fR\|(3): -.ie n .IP """ssl3\-ms"" (\fB\s-1OSSL_DIGEST_PARAM_SSL3_MS\s0\fR) " 4 -.el .IP "``ssl3\-ms'' (\fB\s-1OSSL_DIGEST_PARAM_SSL3_MS\s0\fR) " 4 -.IX Item "ssl3-ms (OSSL_DIGEST_PARAM_SSL3_MS) " -This parameter is set by libssl in order to calculate a signature hash for an -SSLv3 CertificateVerify message as per \s-1RFC6101.\s0 -It is only set after all handshake messages have already been digested via -\&\fBOP_digest_update()\fR calls. -The parameter provides the master secret value to be added to the digest. -The digest implementation should calculate the complete digest as per \s-1RFC6101\s0 -section 5.6.8. -The next call after setting this parameter should be \fBOP_digest_final()\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_CTX_set_params\fR\|(3), \fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-MD5.7ossl b/openssl-install/share/man/man7/EVP_MD-MD5.7ossl deleted file mode 100644 index 3785c113..00000000 --- a/openssl-install/share/man/man7/EVP_MD-MD5.7ossl +++ /dev/null @@ -1,164 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-MD5 7ossl" -.TH EVP_MD-MD5 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-MD5 \- The MD5 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1MD5\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is only available with the default provider, and is -identified with the name \*(L"\s-1MD5\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-MDC2.7ossl b/openssl-install/share/man/man7/EVP_MD-MDC2.7ossl deleted file mode 100644 index 05482a4f..00000000 --- a/openssl-install/share/man/man7/EVP_MD-MDC2.7ossl +++ /dev/null @@ -1,175 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-MDC2 7ossl" -.TH EVP_MD-MDC2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-MDC2 \- The MDC2 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1MDC2\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is only available with the legacy provider, and is -identified with the name \*(L"\s-1MDC2\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SS "Settable Context Parameters" -.IX Subsection "Settable Context Parameters" -This implementation supports the following \s-1\fBOSSL_PARAM\s0\fR\|(3) entries, -settable for an \fB\s-1EVP_MD_CTX\s0\fR with \fBEVP_MD_CTX_set_params\fR\|(3): -.ie n .IP """pad-type"" (\fB\s-1OSSL_DIGEST_PARAM_PAD_TYPE\s0\fR) " 4 -.el .IP "``pad-type'' (\fB\s-1OSSL_DIGEST_PARAM_PAD_TYPE\s0\fR) " 4 -.IX Item "pad-type (OSSL_DIGEST_PARAM_PAD_TYPE) " -Sets the padding type to be used. -Normally the final \s-1MDC2\s0 block is padded with zeros. -If the pad type is set to 2 then the final block is padded with 0x80 followed by -zeros. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_CTX_set_params\fR\|(3), \fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-NULL.7ossl b/openssl-install/share/man/man7/EVP_MD-NULL.7ossl deleted file mode 100644 index 0dd79d43..00000000 --- a/openssl-install/share/man/man7/EVP_MD-NULL.7ossl +++ /dev/null @@ -1,169 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-NULL 7ossl" -.TH EVP_MD-NULL 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-NULL \- The NULL EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for a \s-1NULL\s0 digest through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -This algorithm does nothing and returns 1 for its init, -update and final methods. -.SS "Algorithm Name" -.IX Subsection "Algorithm Name" -The following algorithm is available in the default provider: -.ie n .IP """\s-1NULL""\s0" 4 -.el .IP "``\s-1NULL''\s0" 4 -.IX Item "NULL" -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_CTX_set_params\fR\|(3), \fBprovider\-digest\fR\|(7), -\&\fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-RIPEMD160.7ossl b/openssl-install/share/man/man7/EVP_MD-RIPEMD160.7ossl deleted file mode 100644 index 8a3d4349..00000000 --- a/openssl-install/share/man/man7/EVP_MD-RIPEMD160.7ossl +++ /dev/null @@ -1,168 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-RIPEMD160 7ossl" -.TH EVP_MD-RIPEMD160 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-RIPEMD160 \- The RIPEMD160 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1RIPEMD160\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identities" -.IX Subsection "Identities" -This implementation is available in both the default and legacy providers, and is -identified with any of the names \*(L"\s-1RIPEMD\-160\*(R", \*(L"RIPEMD160\*(R", \*(L"RIPEMD\*(R"\s0 and -\&\*(L"\s-1RMD160\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This digest was added to the default provider in OpenSSL 3.0.7. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-SHA1.7ossl b/openssl-install/share/man/man7/EVP_MD-SHA1.7ossl deleted file mode 100644 index 90d0cee2..00000000 --- a/openssl-install/share/man/man7/EVP_MD-SHA1.7ossl +++ /dev/null @@ -1,180 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-SHA1 7ossl" -.TH EVP_MD-SHA1 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-SHA1 \- The SHA1 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1SHA1\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identities" -.IX Subsection "Identities" -This implementation is available with the \s-1FIPS\s0 provider as well as the -default provider, and is identified with the names \*(L"\s-1SHA1\*(R"\s0 and \*(L"\s-1SHA\-1\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SS "Settable Context Parameters" -.IX Subsection "Settable Context Parameters" -This implementation supports the following \s-1\fBOSSL_PARAM\s0\fR\|(3) entries, -settable for an \fB\s-1EVP_MD_CTX\s0\fR with \fBEVP_MD_CTX_set_params\fR\|(3): -.ie n .IP """ssl3\-ms"" (\fB\s-1OSSL_DIGEST_PARAM_SSL3_MS\s0\fR) " 4 -.el .IP "``ssl3\-ms'' (\fB\s-1OSSL_DIGEST_PARAM_SSL3_MS\s0\fR) " 4 -.IX Item "ssl3-ms (OSSL_DIGEST_PARAM_SSL3_MS) " -This parameter is set by libssl in order to calculate a signature hash for an -SSLv3 CertificateVerify message as per \s-1RFC6101.\s0 -It is only set after all handshake messages have already been digested via -\&\fBOP_digest_update()\fR calls. -The parameter provides the master secret value to be added to the digest. -The digest implementation should calculate the complete digest as per \s-1RFC6101\s0 -section 5.6.8. -The next call after setting this parameter should be \fBOP_digest_final()\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_CTX_set_params\fR\|(3), \fBprovider\-digest\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-SHA2.7ossl b/openssl-install/share/man/man7/EVP_MD-SHA2.7ossl deleted file mode 100644 index c9897acf..00000000 --- a/openssl-install/share/man/man7/EVP_MD-SHA2.7ossl +++ /dev/null @@ -1,196 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-SHA2 7ossl" -.TH EVP_MD-SHA2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-SHA2 \- The SHA2 EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1SHA2\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identities" -.IX Subsection "Identities" -This implementation includes the following varieties: -.IP "\(bu" 4 -Available with the \s-1FIPS\s0 provider as well as the default provider: -.RS 4 -.IP "\s-1SHA2\-224\s0" 4 -.IX Item "SHA2-224" -Known names are \*(L"\s-1SHA2\-224\*(R", \*(L"SHA\-224\*(R"\s0 and \*(L"\s-1SHA224\*(R".\s0 -.IP "\s-1SHA2\-256\s0" 4 -.IX Item "SHA2-256" -Known names are \*(L"\s-1SHA2\-256\*(R", \*(L"SHA\-256\*(R"\s0 and \*(L"\s-1SHA256\*(R".\s0 -.IP "\s-1SHA2\-384\s0" 4 -.IX Item "SHA2-384" -Known names are \*(L"\s-1SHA2\-384\*(R", \*(L"SHA\-384\*(R"\s0 and \*(L"\s-1SHA384\*(R".\s0 -.IP "\s-1SHA2\-512\s0" 4 -.IX Item "SHA2-512" -Known names are \*(L"\s-1SHA2\-512\*(R", \*(L"SHA\-512\*(R"\s0 and \*(L"\s-1SHA512\*(R".\s0 -.RE -.RS 4 -.RE -.IP "\(bu" 4 -Available with the default provider: -.RS 4 -.IP "\s-1SHA2\-256/192\s0" 4 -.IX Item "SHA2-256/192" -Known names are \*(L"\s-1SHA2\-256/192\*(R", \*(L"SHA\-256/192\*(R"\s0 and \*(L"\s-1SHA256\-192\*(R".\s0 -.IP "\s-1SHA2\-512/224\s0" 4 -.IX Item "SHA2-512/224" -Known names are \*(L"\s-1SHA2\-512/224\*(R", \*(L"SHA\-512/224\*(R"\s0 and \*(L"\s-1SHA512\-224\*(R".\s0 -.IP "\s-1SHA2\-512/256\s0" 4 -.IX Item "SHA2-512/256" -Known names are \*(L"\s-1SHA2\-512/256\*(R", \*(L"SHA\-512/256\*(R"\s0 and \*(L"\s-1SHA512\-256\*(R".\s0 -.RE -.RS 4 -.RE -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-SHA3.7ossl b/openssl-install/share/man/man7/EVP_MD-SHA3.7ossl deleted file mode 100644 index 83b62850..00000000 --- a/openssl-install/share/man/man7/EVP_MD-SHA3.7ossl +++ /dev/null @@ -1,178 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-SHA3 7ossl" -.TH EVP_MD-SHA3 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-SHA3 \- The SHA3 EVP_MD implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1SHA3\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identities" -.IX Subsection "Identities" -This implementation is available with the \s-1FIPS\s0 provider as well as the -default provider, and includes the following varieties: -.ie n .IP """\s-1SHA3\-224""\s0" 4 -.el .IP "``\s-1SHA3\-224''\s0" 4 -.IX Item "SHA3-224" -.PD 0 -.ie n .IP """\s-1SHA3\-256""\s0" 4 -.el .IP "``\s-1SHA3\-256''\s0" 4 -.IX Item "SHA3-256" -.ie n .IP """\s-1SHA3\-384""\s0" 4 -.el .IP "``\s-1SHA3\-384''\s0" 4 -.IX Item "SHA3-384" -.ie n .IP """\s-1SHA3\-512""\s0" 4 -.el .IP "``\s-1SHA3\-512''\s0" 4 -.IX Item "SHA3-512" -.PD -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-SHAKE.7ossl b/openssl-install/share/man/man7/EVP_MD-SHAKE.7ossl deleted file mode 100644 index 7f39e7a6..00000000 --- a/openssl-install/share/man/man7/EVP_MD-SHAKE.7ossl +++ /dev/null @@ -1,217 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-SHAKE 7ossl" -.TH EVP_MD-SHAKE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-SHAKE, EVP_MD\-KECCAK\-KMAC -\&\- The SHAKE / KECCAK family EVP_MD implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1SHAKE\s0 or KECCAK-KMAC digests through the -\&\fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.PP -KECCAK-KMAC is an Extendable Output Function (\s-1XOF\s0), with a definition -similar to \s-1SHAKE,\s0 used by the \s-1KMAC EVP_MAC\s0 implementation (see -\&\s-1\fBEVP_MAC\-KMAC\s0\fR\|(7)). -.SS "Identities" -.IX Subsection "Identities" -This implementation is available in the \s-1FIPS\s0 provider as well as the default -provider, and includes the following varieties: -.IP "\s-1KECCAK\-KMAC\-128\s0" 4 -.IX Item "KECCAK-KMAC-128" -Known names are \*(L"\s-1KECCAK\-KMAC\-128\*(R"\s0 and \*(L"\s-1KECCAK\-KMAC128\*(R".\s0 This is used -by \s-1\fBEVP_MAC\-KMAC128\s0\fR\|(7). Using the notation from \s-1NIST FIPS 202\s0 -(Section 6.2), we have \s-1KECCAK\-KMAC\-128\s0(M,\ d) = KECCAK[256](M\ ||\ 00,\ d) -(see the description of \s-1KMAC128\s0 in Appendix A of \s-1NIST SP 800\-185\s0). -.IP "\s-1KECCAK\-KMAC\-256\s0" 4 -.IX Item "KECCAK-KMAC-256" -Known names are \*(L"\s-1KECCAK\-KMAC\-256\*(R"\s0 and \*(L"\s-1KECCAK\-KMAC256\*(R".\s0 This is used -by \s-1\fBEVP_MAC\-KMAC256\s0\fR\|(7). Using the notation from \s-1NIST FIPS 202\s0 -(Section 6.2), we have \s-1KECCAK\-KMAC\-256\s0(M,\ d) = KECCAK[512](M\ ||\ 00,\ d) -(see the description of \s-1KMAC256\s0 in Appendix A of \s-1NIST SP 800\-185\s0). -.IP "\s-1SHAKE\-128\s0" 4 -.IX Item "SHAKE-128" -Known names are \*(L"\s-1SHAKE\-128\*(R"\s0 and \*(L"\s-1SHAKE128\*(R".\s0 -.IP "\s-1SHAKE\-256\s0" 4 -.IX Item "SHAKE-256" -Known names are \*(L"\s-1SHAKE\-256\*(R"\s0 and \*(L"\s-1SHAKE256\*(R".\s0 -.SS "Parameters" -.IX Subsection "Parameters" -This implementation supports the following \s-1\fBOSSL_PARAM\s0\fR\|(3) entries: -.ie n .IP """xoflen"" (\fB\s-1OSSL_DIGEST_PARAM_XOFLEN\s0\fR) " 4 -.el .IP "``xoflen'' (\fB\s-1OSSL_DIGEST_PARAM_XOFLEN\s0\fR) " 4 -.IX Item "xoflen (OSSL_DIGEST_PARAM_XOFLEN) " -Sets or Gets the digest length for extendable output functions. -The length of the \*(L"xoflen\*(R" parameter should not exceed that of a \fBsize_t\fR. -.Sp -The \s-1SHAKE\-128\s0 and \s-1SHAKE\-256\s0 implementations do not have any default digest -length. -.Sp -This parameter must be set before calling either \fBEVP_DigestFinal_ex()\fR or -\&\fBEVP_DigestFinal()\fR, since these functions were not designed to handle variable -length output. It is recommended to either use \fBEVP_DigestSqueeze()\fR or -\&\fBEVP_DigestFinalXOF()\fR instead. -.ie n .IP """size"" (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_DIGEST_PARAM_SIZE) " -An alias of \*(L"xoflen\*(R". -.PP -See \*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_DigestInit\fR\|(3) for further information related to parameters -.SH "NOTES" -.IX Header "NOTES" -For \s-1SHAKE\-128,\s0 to ensure the maximum security strength of 128 bits, the output -length passed to \fBEVP_DigestFinalXOF()\fR should be at least 32. -.PP -For \s-1SHAKE\-256,\s0 to ensure the maximum security strength of 256 bits, the output -length passed to \fBEVP_DigestFinalXOF()\fR should be at least 64. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MD_CTX_set_params\fR\|(3), \fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -Since OpenSSL 3.4 the \s-1SHAKE\-128\s0 and \s-1SHAKE\-256\s0 implementations have no default -digest length. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-SM3.7ossl b/openssl-install/share/man/man7/EVP_MD-SM3.7ossl deleted file mode 100644 index 016ff616..00000000 --- a/openssl-install/share/man/man7/EVP_MD-SM3.7ossl +++ /dev/null @@ -1,164 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-SM3 7ossl" -.TH EVP_MD-SM3 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-SM3 \- The SM3 EVP_MD implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1SM3\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is only available with the default provider, and is -identified with the name \*(L"\s-1SM3\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-WHIRLPOOL.7ossl b/openssl-install/share/man/man7/EVP_MD-WHIRLPOOL.7ossl deleted file mode 100644 index f04ac697..00000000 --- a/openssl-install/share/man/man7/EVP_MD-WHIRLPOOL.7ossl +++ /dev/null @@ -1,164 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-WHIRLPOOL 7ossl" -.TH EVP_MD-WHIRLPOOL 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-WHIRLPOOL \- The WHIRLPOOL EVP_MD implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1WHIRLPOOL\s0 digests through the \fB\s-1EVP_MD\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -This implementation is only available with the legacy provider, and is -identified with the name \*(L"\s-1WHIRLPOOL\*(R".\s0 -.SS "Gettable Parameters" -.IX Subsection "Gettable Parameters" -This implementation supports the common gettable parameters described -in \fBEVP_MD\-common\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_MD-common.7ossl b/openssl-install/share/man/man7/EVP_MD-common.7ossl deleted file mode 100644 index 609b83dd..00000000 --- a/openssl-install/share/man/man7/EVP_MD-common.7ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_MD-COMMON 7ossl" -.TH EVP_MD-COMMON 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_MD\-common \- The OpenSSL EVP_MD implementations, common things -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All the OpenSSL \s-1EVP_MD\s0 implementations understand the following -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) entries that are -gettable with \fBEVP_MD_get_params\fR\|(3), as well as these: -.ie n .IP """blocksize"" (\fB\s-1OSSL_DIGEST_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``blocksize'' (\fB\s-1OSSL_DIGEST_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "blocksize (OSSL_DIGEST_PARAM_BLOCK_SIZE) " -The digest block size. -The length of the \*(L"blocksize\*(R" parameter should not exceed that of a -\&\fBsize_t\fR. -.Sp -This value can also be retrieved with \fBEVP_MD_get_block_size\fR\|(3). -.ie n .IP """size"" (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_DIGEST_PARAM_SIZE) " -The digest output size. -The length of the \*(L"size\*(R" parameter should not exceed that of a \fBsize_t\fR. -.Sp -This value can also be retrieved with \fBEVP_MD_get_size\fR\|(3). -.ie n .IP """flags"" (\fB\s-1OSSL_DIGEST_PARAM_FLAGS\s0\fR) " 4 -.el .IP "``flags'' (\fB\s-1OSSL_DIGEST_PARAM_FLAGS\s0\fR) " 4 -.IX Item "flags (OSSL_DIGEST_PARAM_FLAGS) " -Diverse flags that describe exceptional behaviour for the digest. -These flags are described in \*(L"\s-1DESCRIPTION\*(R"\s0 in \fBEVP_MD_meth_set_flags\fR\|(3). -.Sp -The length of the \*(L"flags\*(R" parameter should equal that of an -\&\fBunsigned long int\fR. -.Sp -This value can also be retrieved with \fBEVP_MD_get_flags\fR\|(3). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_DigestInit\fR\|(3), \fBEVP_MD_get_params\fR\|(3), \fBprovider\-digest\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-CMAC.7ossl b/openssl-install/share/man/man7/EVP_PKEY-CMAC.7ossl deleted file mode 120000 index e258700c..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-CMAC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_PKEY-DH.7ossl b/openssl-install/share/man/man7/EVP_PKEY-DH.7ossl deleted file mode 100644 index 6353501d..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-DH.7ossl +++ /dev/null @@ -1,459 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-DH 7ossl" -.TH EVP_PKEY-DH 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-DH, EVP_PKEY\-DHX, EVP_KEYMGMT\-DH, EVP_KEYMGMT\-DHX -\&\- EVP_PKEY DH and DHX keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -For finite field Diffie-Hellman key agreement, two classes of domain -parameters can be used: \*(L"safe\*(R" domain parameters that are associated with -approved named safe-prime groups, and a class of \*(L"FIPS186\-type\*(R" domain -parameters. FIPS186\-type domain parameters should only be used for backward -compatibility with existing applications that cannot be upgraded to use the -approved safe-prime groups. -.PP -See \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7) for more information about \s-1FFC\s0 keys. -.PP -The \fB\s-1DH\s0\fR key type uses PKCS#3 format which saves \fIp\fR and \fIg\fR, but not the -\&\fIq\fR value. -The \fB\s-1DHX\s0\fR key type uses X9.42 format which saves the value of \fIq\fR and this -must be used for \s-1FIPS186\-4.\s0 If key validation is required, users should be aware -of the nuances associated with \s-1FIPS186\-4\s0 style parameters as discussed in -\&\*(L"\s-1DH\s0 and \s-1DHX\s0 key validation\*(R". -.SS "\s-1DH\s0 and \s-1DHX\s0 domain parameters" -.IX Subsection "DH and DHX domain parameters" -In addition to the common \s-1FFC\s0 parameters that all \s-1FFC\s0 keytypes should support -(see \*(L"\s-1FFC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7)) the \fB\s-1DHX\s0\fR and \fB\s-1DH\s0\fR keytype -implementations support the following: -.ie n .IP """group"" (\fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``group'' (\fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "group (OSSL_PKEY_PARAM_GROUP_NAME) " -Sets or gets a string that associates a \fB\s-1DH\s0\fR or \fB\s-1DHX\s0\fR named safe prime group -with known values for \fIp\fR, \fIq\fR and \fIg\fR. -.Sp -The following values can be used by the OpenSSL's default and \s-1FIPS\s0 providers: -\&\*(L"ffdhe2048\*(R", \*(L"ffdhe3072\*(R", \*(L"ffdhe4096\*(R", \*(L"ffdhe6144\*(R", \*(L"ffdhe8192\*(R", -\&\*(L"modp_2048\*(R", \*(L"modp_3072\*(R", \*(L"modp_4096\*(R", \*(L"modp_6144\*(R", \*(L"modp_8192\*(R". -.Sp -The following additional values can also be used by OpenSSL's default provider: -\&\*(L"modp_1536\*(R", \*(L"dh_1024_160\*(R", \*(L"dh_2048_224\*(R", \*(L"dh_2048_256\*(R". -.Sp -\&\s-1DH/DHX\s0 named groups can be easily validated since the parameters are well known. -For protocols that only transfer \fIp\fR and \fIg\fR the value of \fIq\fR can also be -retrieved. -.SS "\s-1DH\s0 and \s-1DHX\s0 additional parameters" -.IX Subsection "DH and DHX additional parameters" -.ie n .IP """encoded-pub-key"" (\fB\s-1OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY\s0\fR) " 4 -.el .IP "``encoded-pub-key'' (\fB\s-1OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY\s0\fR) " 4 -.IX Item "encoded-pub-key (OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY) " -Used for getting and setting the encoding of the \s-1DH\s0 public key used in a key -exchange message for the \s-1TLS\s0 protocol. -See \fBEVP_PKEY_set1_encoded_public_key()\fR and \fBEVP_PKEY_get1_encoded_public_key()\fR. -.SS "\s-1DH\s0 additional domain parameters" -.IX Subsection "DH additional domain parameters" -.ie n .IP """safeprime-generator"" (\fB\s-1OSSL_PKEY_PARAM_DH_GENERATOR\s0\fR) " 4 -.el .IP "``safeprime-generator'' (\fB\s-1OSSL_PKEY_PARAM_DH_GENERATOR\s0\fR) " 4 -.IX Item "safeprime-generator (OSSL_PKEY_PARAM_DH_GENERATOR) " -Used for \s-1DH\s0 generation of safe primes using the old safe prime generator code. -The default value is 2. -It is recommended to use a named safe prime group instead, if domain parameter -validation is required. -.Sp -Randomly generated safe primes are not allowed by \s-1FIPS,\s0 so setting this value -for the OpenSSL \s-1FIPS\s0 provider will instead choose a named safe prime group -based on the size of \fIp\fR. -.SS "\s-1DH\s0 and \s-1DHX\s0 domain parameter / key generation parameters" -.IX Subsection "DH and DHX domain parameter / key generation parameters" -In addition to the common \s-1FFC\s0 key generation parameters that all \s-1FFC\s0 key types -should support (see \*(L"\s-1FFC\s0 key generation parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7)) the -\&\fB\s-1DH\s0\fR and \fB\s-1DHX\s0\fR keytype implementation supports the following: -.ie n .IP """type"" (\fB\s-1OSSL_PKEY_PARAM_FFC_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``type'' (\fB\s-1OSSL_PKEY_PARAM_FFC_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "type (OSSL_PKEY_PARAM_FFC_TYPE) " -Sets the type of parameter generation. For \fB\s-1DH\s0\fR valid values are: -.RS 4 -.ie n .IP """fips186_4""" 4 -.el .IP "``fips186_4''" 4 -.IX Item "fips186_4" -.PD 0 -.ie n .IP """default""" 4 -.el .IP "``default''" 4 -.IX Item "default" -.ie n .IP """fips186_2""" 4 -.el .IP "``fips186_2''" 4 -.IX Item "fips186_2" -.PD -These are described in \*(L"\s-1FFC\s0 key generation parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7) -.ie n .IP """group""" 4 -.el .IP "``group''" 4 -.IX Item "group" -This specifies that a named safe prime name will be chosen using the \*(L"pbits\*(R" -type. -.ie n .IP """generator""" 4 -.el .IP "``generator''" 4 -.IX Item "generator" -A safe prime generator. See the \*(L"safeprime-generator\*(R" type above. -This is only valid for \fB\s-1DH\s0\fR keys. -.RE -.RS 4 -.RE -.ie n .IP """pbits"" (\fB\s-1OSSL_PKEY_PARAM_FFC_PBITS\s0\fR) " 4 -.el .IP "``pbits'' (\fB\s-1OSSL_PKEY_PARAM_FFC_PBITS\s0\fR) " 4 -.IX Item "pbits (OSSL_PKEY_PARAM_FFC_PBITS) " -Sets the size (in bits) of the prime 'p'. -.Sp -For \*(L"fips186_4\*(R" this must be 2048. -For \*(L"fips186_2\*(R" this must be 1024. -For \*(L"group\*(R" this can be any one of 2048, 3072, 4096, 6144 or 8192. -.ie n .IP """priv_len"" (\fB\s-1OSSL_PKEY_PARAM_DH_PRIV_LEN\s0\fR) " 4 -.el .IP "``priv_len'' (\fB\s-1OSSL_PKEY_PARAM_DH_PRIV_LEN\s0\fR) " 4 -.IX Item "priv_len (OSSL_PKEY_PARAM_DH_PRIV_LEN) " -An optional value to set the maximum length of the generated private key. -The default value used if this is not set is the maximum value of -BN_num_bits(\fIq\fR)). The minimum value that this can be set to is 2 * s. -Where s is the security strength of the key which has values of -112, 128, 152, 176 and 200 for key sizes of 2048, 3072, 4096, 6144 and 8192. -.SS "\s-1DH\s0 and \s-1DHX\s0 key validation" -.IX Subsection "DH and DHX key validation" -For keys that are not a named group the \s-1FIPS186\-4\s0 standard specifies that the -values used for \s-1FFC\s0 parameter generation are also required for parameter -validation. This means that optional \s-1FFC\s0 domain parameter values for -\&\fIseed\fR, \fIpcounter\fR and \fIgindex\fR or \fIhindex\fR may need to be stored for -validation purposes. -For \fB\s-1DHX\s0\fR the \fIseed\fR and \fIpcounter\fR can be stored in \s-1ASN1\s0 data -(but the \fIgindex\fR or \fIhindex\fR cannot be stored). It is recommended to use a -\&\fB\s-1DH\s0\fR parameters with named safe prime group instead. -.PP -With the OpenSSL \s-1FIPS\s0 provider, \fBEVP_PKEY_param_check\fR\|(3) and -\&\fBEVP_PKEY_param_check_quick\fR\|(3) behave in the following way: the parameters -are tested if they are either an approved safe prime group \s-1OR\s0 that the \s-1FFC\s0 -parameters conform to \s-1FIPS186\-4\s0 as defined in SP800\-56Ar3 \fIAssurances of -Domain-Parameter Validity\fR. -.PP -The OpenSSL default provider uses simpler checks that allows there to be no \fIq\fR -value for backwards compatibility, however the \fBEVP_PKEY_param_check\fR\|(3) will -test the \fIp\fR value for being a prime (and a safe prime if \fIq\fR is missing) -which can take significant time. The \fBEVP_PKEY_param_check_quick\fR\|(3) avoids -the prime tests. -.PP -\&\fBEVP_PKEY_public_check\fR\|(3) conforms to SP800\-56Ar3 -\&\fI\s-1FFC\s0 Full Public-Key Validation\fR. -.PP -\&\fBEVP_PKEY_public_check_quick\fR\|(3) conforms to SP800\-56Ar3 -\&\fI\s-1FFC\s0 Partial Public-Key Validation\fR when the key is an approved named safe -prime group, otherwise it is the same as \fBEVP_PKEY_public_check\fR\|(3). -.PP -\&\fBEVP_PKEY_private_check\fR\|(3) tests that the private key is in the correct range -according to SP800\-56Ar3. The OpenSSL \s-1FIPS\s0 provider requires the value of \fIq\fR -to be set (note that this is implicitly set for named safe prime groups). -For backwards compatibility the OpenSSL default provider only requires \fIp\fR to -be set. -.PP -\&\fBEVP_PKEY_pairwise_check\fR\|(3) conforms to SP800\-56Ar3 -\&\fIOwner Assurance of Pair-wise Consistency\fR. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -An \fB\s-1EVP_PKEY\s0\fR context can be obtained by calling: -.PP -.Vb 1 -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "DH", NULL); -.Ve -.PP -A \fB\s-1DH\s0\fR key can be generated with a named safe prime group by calling: -.PP -.Vb 4 -\& int priv_len = 2 * 112; -\& OSSL_PARAM params[3]; -\& EVP_PKEY *pkey = NULL; -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "DH", NULL); -\& -\& params[0] = OSSL_PARAM_construct_utf8_string("group", "ffdhe2048", 0); -\& /* "priv_len" is optional */ -\& params[1] = OSSL_PARAM_construct_int("priv_len", &priv_len); -\& params[2] = OSSL_PARAM_construct_end(); -\& -\& EVP_PKEY_keygen_init(pctx); -\& EVP_PKEY_CTX_set_params(pctx, params); -\& EVP_PKEY_generate(pctx, &pkey); -\& ... -\& EVP_PKEY_free(pkey); -\& EVP_PKEY_CTX_free(pctx); -.Ve -.PP -\&\fB\s-1DHX\s0\fR domain parameters can be generated according to \fB\s-1FIPS186\-4\s0\fR by calling: -.PP -.Vb 6 -\& int gindex = 2; -\& unsigned int pbits = 2048; -\& unsigned int qbits = 256; -\& OSSL_PARAM params[6]; -\& EVP_PKEY *param_key = NULL; -\& EVP_PKEY_CTX *pctx = NULL; -\& -\& pctx = EVP_PKEY_CTX_new_from_name(NULL, "DHX", NULL); -\& EVP_PKEY_paramgen_init(pctx); -\& -\& params[0] = OSSL_PARAM_construct_uint("pbits", &pbits); -\& params[1] = OSSL_PARAM_construct_uint("qbits", &qbits); -\& params[2] = OSSL_PARAM_construct_int("gindex", &gindex); -\& params[3] = OSSL_PARAM_construct_utf8_string("type", "fips186_4", 0); -\& params[4] = OSSL_PARAM_construct_utf8_string("digest", "SHA256", 0); -\& params[5] = OSSL_PARAM_construct_end(); -\& EVP_PKEY_CTX_set_params(pctx, params); -\& -\& EVP_PKEY_generate(pctx, ¶m_key); -\& -\& EVP_PKEY_print_params(bio_out, param_key, 0, NULL); -\& ... -\& EVP_PKEY_free(param_key); -\& EVP_PKEY_CTX_free(pctx); -.Ve -.PP -A \fB\s-1DH\s0\fR key can be generated using domain parameters by calling: -.PP -.Vb 2 -\& EVP_PKEY *key = NULL; -\& EVP_PKEY_CTX *gctx = EVP_PKEY_CTX_new_from_pkey(NULL, param_key, NULL); -\& -\& EVP_PKEY_keygen_init(gctx); -\& EVP_PKEY_generate(gctx, &key); -\& EVP_PKEY_print_private(bio_out, key, 0, NULL); -\& ... -\& EVP_PKEY_free(key); -\& EVP_PKEY_CTX_free(gctx); -.Ve -.PP -To validate \fB\s-1FIPS186\-4\s0\fR \fB\s-1DHX\s0\fR domain parameters decoded from \fB\s-1PEM\s0\fR or -\&\fB\s-1DER\s0\fR data, additional values used during generation may be required to -be set into the key. -.PP -\&\fBEVP_PKEY_todata()\fR, \fBOSSL_PARAM_merge()\fR, and \fBEVP_PKEY_fromdata()\fR are useful -to add these parameters to the original key or domain parameters before -the actual validation. In production code the return values should be checked. -.PP -.Vb 11 -\& EVP_PKEY *received_domp = ...; /* parameters received and decoded */ -\& unsigned char *seed = ...; /* and additional parameters received */ -\& size_t seedlen = ...; /* by other means, required */ -\& int gindex = ...; /* for the validation */ -\& int pcounter = ...; -\& int hindex = ...; -\& OSSL_PARAM extra_params[4]; -\& OSSL_PARAM *domain_params = NULL; -\& OSSL_PARAM *merged_params = NULL; -\& EVP_PKEY_CTX *ctx = NULL, *validate_ctx = NULL; -\& EVP_PKEY *complete_domp = NULL; -\& -\& EVP_PKEY_todata(received_domp, OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS, -\& &domain_params); -\& extra_params[0] = OSSL_PARAM_construct_octet_string("seed", seed, seedlen); -\& /* -\& * NOTE: For unverifiable g use "hindex" instead of "gindex" -\& * extra_params[1] = OSSL_PARAM_construct_int("hindex", &hindex); -\& */ -\& extra_params[1] = OSSL_PARAM_construct_int("gindex", &gindex); -\& extra_params[2] = OSSL_PARAM_construct_int("pcounter", &pcounter); -\& extra_params[3] = OSSL_PARAM_construct_end(); -\& merged_params = OSSL_PARAM_merge(domain_params, extra_params); -\& -\& ctx = EVP_PKEY_CTX_new_from_name(NULL, "DHX", NULL); -\& EVP_PKEY_fromdata_init(ctx); -\& EVP_PKEY_fromdata(ctx, &complete_domp, OSSL_KEYMGMT_SELECT_ALL, -\& merged_params); -\& -\& validate_ctx = EVP_PKEY_CTX_new_from_pkey(NULL, complete_domp, NULL); -\& if (EVP_PKEY_param_check(validate_ctx) > 0) -\& /* validation_passed(); */ -\& else -\& /* validation_failed(); */ -\& -\& OSSL_PARAM_free(domain_params); -\& OSSL_PARAM_free(merged_params); -\& EVP_PKEY_CTX_free(ctx); -\& EVP_PKEY_CTX_free(validate_ctx); -\& EVP_PKEY_free(complete_domp); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -.IP "\s-1RFC 7919\s0 (\s-1TLS\s0 ffdhe named safe prime groups)" 4 -.IX Item "RFC 7919 (TLS ffdhe named safe prime groups)" -.PD 0 -.IP "\s-1RFC 3526\s0 (\s-1IKE\s0 modp named safe prime groups)" 4 -.IX Item "RFC 3526 (IKE modp named safe prime groups)" -.ie n .IP "\s-1RFC 5114\s0 (Additional \s-1DH\s0 named groups for dh_1024_160"", ""dh_2048_224"" and ""dh_2048_256"")." 4 -.el .IP "\s-1RFC 5114\s0 (Additional \s-1DH\s0 named groups for dh_1024_160``, ''dh_2048_224`` and ''dh_2048_256"")." 4 -.IX Item "RFC 5114 (Additional DH named groups for dh_1024_160, dh_2048_224 and dh_2048_256"")." -.PD -.PP -The following sections of SP800\-56Ar3: -.IP "5.5.1.1 \s-1FFC\s0 Domain Parameter Selection/Generation" 4 -.IX Item "5.5.1.1 FFC Domain Parameter Selection/Generation" -.PD 0 -.IP "Appendix D: \s-1FFC\s0 Safe-prime Groups" 4 -.IX Item "Appendix D: FFC Safe-prime Groups" -.PD -.PP -The following sections of \s-1FIPS186\-4:\s0 -.IP "A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function." 4 -.IX Item "A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function." -.PD 0 -.IP "A.2.3 Generation of canonical generator g." 4 -.IX Item "A.2.3 Generation of canonical generator g." -.IP "A.2.1 Unverifiable Generation of the Generator g." 4 -.IX Item "A.2.1 Unverifiable Generation of the Generator g." -.PD -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-FFC\s0\fR\|(7), -\&\s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7) -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keymgmt\fR\|(7), -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), -\&\fBOSSL_PROVIDER\-default\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-DHX.7ossl b/openssl-install/share/man/man7/EVP_PKEY-DHX.7ossl deleted file mode 120000 index cdb249c3..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-DHX.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-DH.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_PKEY-DSA.7ossl b/openssl-install/share/man/man7/EVP_PKEY-DSA.7ossl deleted file mode 100644 index 805f8984..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-DSA.7ossl +++ /dev/null @@ -1,271 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-DSA 7ossl" -.TH EVP_PKEY-DSA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-DSA, EVP_KEYMGMT\-DSA \- EVP_PKEY DSA keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -For \fB\s-1DSA\s0\fR the \s-1FIPS 186\-4\s0 standard specifies that the values used for \s-1FFC\s0 -parameter generation are also required for parameter validation. -This means that optional \s-1FFC\s0 domain parameter values for \fIseed\fR, \fIpcounter\fR -and \fIgindex\fR may need to be stored for validation purposes. For \fB\s-1DSA\s0\fR these -fields are not stored in the \s-1ASN1\s0 data so they need to be stored externally if -validation is required. -.PP -As part of \s-1FIPS 140\-3 DSA\s0 is not longer \s-1FIPS\s0 approved for key generation and -signature validation, but is still allowed for signature verification. -.SS "\s-1DSA\s0 parameters" -.IX Subsection "DSA parameters" -The \fB\s-1DSA\s0\fR key type supports the \s-1FFC\s0 parameters (see -\&\*(L"\s-1FFC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7)). -.PP -It also supports the following parameters: -.ie n .IP """sign-check"" (\fB\s-1OSSL_PKEY_PARAM_FIPS_SIGN_CHECK\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) " -.PD -See \*(L"Common Information Parameters\*(R" in \fBprovider\-keymgmt\fR\|(7) for more information. -.SS "\s-1DSA\s0 key generation parameters" -.IX Subsection "DSA key generation parameters" -The \fB\s-1DSA\s0\fR key type supports the \s-1FFC\s0 key generation parameters (see -\&\*(L"\s-1FFC\s0 key generation parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7) -.PP -The following restrictions apply to the \*(L"pbits\*(R" field: -.PP -For \*(L"fips186_4\*(R" this must be either 2048 or 3072. -For \*(L"fips186_2\*(R" this must be 1024. -For \*(L"group\*(R" this can be any one of 2048, 3072, 4096, 6144 or 8192. -.SS "\s-1DSA\s0 key validation" -.IX Subsection "DSA key validation" -For \s-1DSA\s0 keys, \fBEVP_PKEY_param_check\fR\|(3) behaves in the following way: -The OpenSSL \s-1FIPS\s0 provider conforms to the rules within the \s-1FIPS186\-4\s0 -standard for \s-1FFC\s0 parameter validation. For backwards compatibility the OpenSSL -default provider uses a much simpler check (see below) for parameter validation, -unless the seed parameter is set. -.PP -For \s-1DSA\s0 keys, \fBEVP_PKEY_param_check_quick\fR\|(3) behaves in the following way: -A simple check of L and N and partial g is performed. The default provider -also supports validation of legacy \*(L"fips186_2\*(R" keys. -.PP -For \s-1DSA\s0 keys, \fBEVP_PKEY_public_check\fR\|(3), \fBEVP_PKEY_private_check\fR\|(3) and -\&\fBEVP_PKEY_pairwise_check\fR\|(3) the OpenSSL default and \s-1FIPS\s0 providers conform to -the rules within SP800\-56Ar3 for public, private and pairwise tests respectively. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -An \fB\s-1EVP_PKEY\s0\fR context can be obtained by calling: -.PP -.Vb 1 -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "DSA", NULL); -.Ve -.PP -The \fB\s-1DSA\s0\fR domain parameters can be generated by calling: -.PP -.Vb 6 -\& unsigned int pbits = 2048; -\& unsigned int qbits = 256; -\& int gindex = 1; -\& OSSL_PARAM params[5]; -\& EVP_PKEY *param_key = NULL; -\& EVP_PKEY_CTX *pctx = NULL; -\& -\& pctx = EVP_PKEY_CTX_new_from_name(NULL, "DSA", NULL); -\& EVP_PKEY_paramgen_init(pctx); -\& -\& params[0] = OSSL_PARAM_construct_uint("pbits", &pbits); -\& params[1] = OSSL_PARAM_construct_uint("qbits", &qbits); -\& params[2] = OSSL_PARAM_construct_int("gindex", &gindex); -\& params[3] = OSSL_PARAM_construct_utf8_string("digest", "SHA384", 0); -\& params[4] = OSSL_PARAM_construct_end(); -\& EVP_PKEY_CTX_set_params(pctx, params); -\& -\& EVP_PKEY_generate(pctx, ¶m_key); -\& EVP_PKEY_CTX_free(pctx); -\& -\& EVP_PKEY_print_params(bio_out, param_key, 0, NULL); -.Ve -.PP -A \fB\s-1DSA\s0\fR key can be generated using domain parameters by calling: -.PP -.Vb 2 -\& EVP_PKEY *key = NULL; -\& EVP_PKEY_CTX *gctx = NULL; -\& -\& gctx = EVP_PKEY_CTX_new_from_pkey(NULL, param_key, NULL); -\& EVP_PKEY_keygen_init(gctx); -\& EVP_PKEY_generate(gctx, &key); -\& EVP_PKEY_CTX_free(gctx); -\& EVP_PKEY_print_private(bio_out, key, 0, NULL); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -The following sections of \s-1FIPS186\-4:\s0 -.IP "A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function." 4 -.IX Item "A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function." -.PD 0 -.IP "A.2.3 Generation of canonical generator g." 4 -.IX Item "A.2.3 Generation of canonical generator g." -.IP "A.2.1 Unverifiable Generation of the Generator g." 4 -.IX Item "A.2.1 Unverifiable Generation of the Generator g." -.PD -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-FFC\s0\fR\|(7), -\&\s-1\fBEVP_SIGNATURE\-DSA\s0\fR\|(7) -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keymgmt\fR\|(7), -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), -\&\fBOSSL_PROVIDER\-default\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -\&\s-1DSA\s0 Key generation and signature generation are no longer \s-1FIPS\s0 approved in -OpenSSL 3.4. See \*(L"\s-1FIPS\s0 indicators\*(R" in \fBfips_module\fR\|(7) for more information. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-EC.7ossl b/openssl-install/share/man/man7/EVP_PKEY-EC.7ossl deleted file mode 100644 index 9979aa03..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-EC.7ossl +++ /dev/null @@ -1,447 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-EC 7ossl" -.TH EVP_PKEY-EC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-EC, -EVP_KEYMGMT\-EC -\&\- EVP_PKEY EC keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1EC\s0\fR keytype is implemented in OpenSSL's default provider. -.SS "Common \s-1EC\s0 parameters" -.IX Subsection "Common EC parameters" -The normal way of specifying domain parameters for an \s-1EC\s0 curve is via the -curve name \*(L"group\*(R". For curves with no curve name, explicit parameters can be -used that specify \*(L"field-type\*(R", \*(L"p\*(R", \*(L"a\*(R", \*(L"b\*(R", \*(L"generator\*(R" and \*(L"order\*(R". -Explicit parameters are supported for backwards compatibility reasons, but they -are not compliant with multiple standards (including \s-1RFC5915\s0) which only allow -named curves. -.PP -The following Key generation/Gettable/Import/Export types are available for the -built-in \s-1EC\s0 algorithm: -.ie n .IP """group"" (\fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``group'' (\fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "group (OSSL_PKEY_PARAM_GROUP_NAME) " -The curve name. -.ie n .IP """field-type"" (\fB\s-1OSSL_PKEY_PARAM_EC_FIELD_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``field-type'' (\fB\s-1OSSL_PKEY_PARAM_EC_FIELD_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "field-type (OSSL_PKEY_PARAM_EC_FIELD_TYPE) " -The value should be either \*(L"prime-field\*(R" or \*(L"characteristic-two-field\*(R", -which correspond to prime field Fp and binary field F2^m. -.ie n .IP """p"" (\fB\s-1OSSL_PKEY_PARAM_EC_P\s0\fR) " 4 -.el .IP "``p'' (\fB\s-1OSSL_PKEY_PARAM_EC_P\s0\fR) " 4 -.IX Item "p (OSSL_PKEY_PARAM_EC_P) " -For a curve over Fp \fIp\fR is the prime for the field. For a curve over F2^m \fIp\fR -represents the irreducible polynomial \- each bit represents a term in the -polynomial. Therefore, there will either be three or five bits set dependent on -whether the polynomial is a trinomial or a pentanomial. -.ie n .IP """a"" (\fB\s-1OSSL_PKEY_PARAM_EC_A\s0\fR) " 4 -.el .IP "``a'' (\fB\s-1OSSL_PKEY_PARAM_EC_A\s0\fR) " 4 -.IX Item "a (OSSL_PKEY_PARAM_EC_A) " -.PD 0 -.ie n .IP """b"" (\fB\s-1OSSL_PKEY_PARAM_EC_B\s0\fR) " 4 -.el .IP "``b'' (\fB\s-1OSSL_PKEY_PARAM_EC_B\s0\fR) " 4 -.IX Item "b (OSSL_PKEY_PARAM_EC_B) " -.ie n .IP """seed"" (\fB\s-1OSSL_PKEY_PARAM_EC_SEED\s0\fR) " 4 -.el .IP "``seed'' (\fB\s-1OSSL_PKEY_PARAM_EC_SEED\s0\fR) " 4 -.IX Item "seed (OSSL_PKEY_PARAM_EC_SEED) " -.PD -\&\fIa\fR and \fIb\fR represents the coefficients of the curve -For Fp: y^2 mod p = x^3 +ax + b mod p \s-1OR\s0 -For F2^m: y^2 + xy = x^3 + ax^2 + b -.Sp -\&\fIseed\fR is an optional value that is for information purposes only. -It represents the random number seed used to generate the coefficient \fIb\fR from a -random number. -.ie n .IP """generator"" (\fB\s-1OSSL_PKEY_PARAM_EC_GENERATOR\s0\fR) " 4 -.el .IP "``generator'' (\fB\s-1OSSL_PKEY_PARAM_EC_GENERATOR\s0\fR) " 4 -.IX Item "generator (OSSL_PKEY_PARAM_EC_GENERATOR) " -.PD 0 -.ie n .IP """order"" (\fB\s-1OSSL_PKEY_PARAM_EC_ORDER\s0\fR) " 4 -.el .IP "``order'' (\fB\s-1OSSL_PKEY_PARAM_EC_ORDER\s0\fR) " 4 -.IX Item "order (OSSL_PKEY_PARAM_EC_ORDER) " -.ie n .IP """cofactor"" (\fB\s-1OSSL_PKEY_PARAM_EC_COFACTOR\s0\fR) " 4 -.el .IP "``cofactor'' (\fB\s-1OSSL_PKEY_PARAM_EC_COFACTOR\s0\fR) " 4 -.IX Item "cofactor (OSSL_PKEY_PARAM_EC_COFACTOR) " -.PD -The \fIgenerator\fR is a well defined point on the curve chosen for cryptographic -operations. The encoding conforms with Sec. 2.3.3 of the \s-1SECG SEC 1\s0 (\*(L"Elliptic Curve -Cryptography\*(R") standard. See \fBEC_POINT_oct2point()\fR. -Integers used for point multiplications will be between 0 and -\&\fIorder\fR \- 1. -\&\fIcofactor\fR is an optional value. -\&\fIorder\fR multiplied by the \fIcofactor\fR gives the number of points on the curve. -.ie n .IP """decoded-from-explicit"" (\fB\s-1OSSL_PKEY_PARAM_EC_DECODED_FROM_EXPLICIT_PARAMS\s0\fR) " 4 -.el .IP "``decoded-from-explicit'' (\fB\s-1OSSL_PKEY_PARAM_EC_DECODED_FROM_EXPLICIT_PARAMS\s0\fR) " 4 -.IX Item "decoded-from-explicit (OSSL_PKEY_PARAM_EC_DECODED_FROM_EXPLICIT_PARAMS) " -Gets a flag indicating whether the key or parameters were decoded from explicit -curve parameters. Set to 1 if so or 0 if a named curve was used. -.ie n .IP """use-cofactor-flag"" (\fB\s-1OSSL_PKEY_PARAM_USE_COFACTOR_ECDH\s0\fR) " 4 -.el .IP "``use-cofactor-flag'' (\fB\s-1OSSL_PKEY_PARAM_USE_COFACTOR_ECDH\s0\fR) " 4 -.IX Item "use-cofactor-flag (OSSL_PKEY_PARAM_USE_COFACTOR_ECDH) " -Enable Cofactor \s-1DH\s0 (\s-1ECC CDH\s0) if this value is 1, otherwise it uses normal \s-1EC DH\s0 -if the value is zero. The cofactor variant multiplies the shared secret by the -\&\s-1EC\s0 curve's cofactor (note for some curves the cofactor is 1). -.Sp -See also \s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7) for the related -\&\fB\s-1OSSL_EXCHANGE_PARAM_EC_ECDH_COFACTOR_MODE\s0\fR parameter that can be set on a -per-operation basis. -.ie n .IP """encoding"" (\fB\s-1OSSL_PKEY_PARAM_EC_ENCODING\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``encoding'' (\fB\s-1OSSL_PKEY_PARAM_EC_ENCODING\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "encoding (OSSL_PKEY_PARAM_EC_ENCODING) " -Set the format used for serializing the \s-1EC\s0 group parameters. -Valid values are \*(L"explicit\*(R" or \*(L"named_curve\*(R". The default value is \*(L"named_curve\*(R". -.ie n .IP """point-format"" (\fB\s-1OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``point-format'' (\fB\s-1OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "point-format (OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT) " -Sets or gets the point_conversion_form for the \fIkey\fR. For a description of -point_conversion_forms please see \fBEC_POINT_new\fR\|(3). Valid values are -\&\*(L"uncompressed\*(R" or \*(L"compressed\*(R". The default value is \*(L"uncompressed\*(R". -.ie n .IP """group-check"" (\fB\s-1OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``group-check'' (\fB\s-1OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "group-check (OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE) " -Sets or Gets the type of group check done when \fBEVP_PKEY_param_check()\fR is called. -Valid values are \*(L"default\*(R", \*(L"named\*(R" and \*(L"named-nist\*(R". -The \*(L"named\*(R" type checks that the domain parameters match the inbuilt curve parameters, -\&\*(L"named-nist\*(R" is similar but also checks that the named curve is a nist curve. -The \*(L"default\*(R" type does domain parameter validation for the OpenSSL default provider, -but is equivalent to \*(L"named-nist\*(R" for the OpenSSL \s-1FIPS\s0 provider. -.ie n .IP """include-public"" (\fB\s-1OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC\s0\fR) " 4 -.el .IP "``include-public'' (\fB\s-1OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC\s0\fR) " 4 -.IX Item "include-public (OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC) " -Setting this value to 0 indicates that the public key should not be included when -encoding the private key. The default value of 1 will include the public key. -.ie n .IP """pub"" (\fB\s-1OSSL_PKEY_PARAM_PUB_KEY\s0\fR) " 4 -.el .IP "``pub'' (\fB\s-1OSSL_PKEY_PARAM_PUB_KEY\s0\fR) " 4 -.IX Item "pub (OSSL_PKEY_PARAM_PUB_KEY) " -The public key value in encoded \s-1EC\s0 point format conforming to Sec. 2.3.3 and -2.3.4 of the \s-1SECG SEC 1\s0 (\*(L"Elliptic Curve Cryptography\*(R") standard. -This parameter is used when importing or exporting the public key value with the -\&\fBEVP_PKEY_fromdata()\fR and \fBEVP_PKEY_todata()\fR functions. -.Sp -Note, in particular, that the choice of point compression format used for -encoding the exported value via \fBEVP_PKEY_todata()\fR depends on the underlying -provider implementation. -Before OpenSSL 3.0.8, the implementation of providers included with OpenSSL always -opted for an encoding in compressed format, unconditionally. -Since OpenSSL 3.0.8, the implementation has been changed to honor the -\&\fB\s-1OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT\s0\fR parameter, if set, or to default -to uncompressed format. -.ie n .IP """priv"" (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.el .IP "``priv'' (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.IX Item "priv (OSSL_PKEY_PARAM_PRIV_KEY) " -The private key value. -.ie n .IP """encoded-pub-key"" (\fB\s-1OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY\s0\fR) " 4 -.el .IP "``encoded-pub-key'' (\fB\s-1OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY\s0\fR) " 4 -.IX Item "encoded-pub-key (OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY) " -Used for getting and setting the encoding of an \s-1EC\s0 public key. The public key -is expected to be a point conforming to Sec. 2.3.4 of the \s-1SECG SEC 1\s0 (\*(L"Elliptic -Curve Cryptography\*(R") standard. -.ie n .IP """qx"" (\fB\s-1OSSL_PKEY_PARAM_EC_PUB_X\s0\fR) " 4 -.el .IP "``qx'' (\fB\s-1OSSL_PKEY_PARAM_EC_PUB_X\s0\fR) " 4 -.IX Item "qx (OSSL_PKEY_PARAM_EC_PUB_X) " -Used for getting the \s-1EC\s0 public key X component. -.ie n .IP """qy"" (\fB\s-1OSSL_PKEY_PARAM_EC_PUB_Y\s0\fR) " 4 -.el .IP "``qy'' (\fB\s-1OSSL_PKEY_PARAM_EC_PUB_Y\s0\fR) " 4 -.IX Item "qy (OSSL_PKEY_PARAM_EC_PUB_Y) " -Used for getting the \s-1EC\s0 public key Y component. -.ie n .IP """default-digest"" (\fB\s-1OSSL_PKEY_PARAM_DEFAULT_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``default-digest'' (\fB\s-1OSSL_PKEY_PARAM_DEFAULT_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "default-digest (OSSL_PKEY_PARAM_DEFAULT_DIGEST) " -Getter that returns the default digest name. -(Currently returns \*(L"\s-1SHA256\*(R"\s0 as of OpenSSL 3.0). -.ie n .IP """dhkem-ikm"" (\fB\s-1OSSL_PKEY_PARAM_DHKEM_IKM\s0\fR) " 4 -.el .IP "``dhkem-ikm'' (\fB\s-1OSSL_PKEY_PARAM_DHKEM_IKM\s0\fR) " 4 -.IX Item "dhkem-ikm (OSSL_PKEY_PARAM_DHKEM_IKM) " -\&\s-1DHKEM\s0 requires the generation of a keypair using an input key material (seed). -Use this to specify the key material used for generation of the private key. -This value should not be reused for other purposes. It can only be used -for the curves \*(L"P\-256\*(R", \*(L"P\-384\*(R" and \*(L"P\-521\*(R" and should have a length of at least -the size of the encoded private key (i.e. 32, 48 and 66 for the listed curves). -.PP -The following Gettable types are also available for the built-in \s-1EC\s0 algorithm: -.ie n .IP """basis-type"" (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``basis-type'' (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "basis-type (OSSL_PKEY_PARAM_EC_CHAR2_TYPE) " -Supports the values \*(L"tpBasis\*(R" for a trinomial or \*(L"ppBasis\*(R" for a pentanomial. -This field is only used for a binary field F2^m. -.ie n .IP """m"" (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_M\s0\fR) " 4 -.el .IP "``m'' (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_M\s0\fR) " 4 -.IX Item "m (OSSL_PKEY_PARAM_EC_CHAR2_M) " -.PD 0 -.ie n .IP """tp"" (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_TP_BASIS\s0\fR) " 4 -.el .IP "``tp'' (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_TP_BASIS\s0\fR) " 4 -.IX Item "tp (OSSL_PKEY_PARAM_EC_CHAR2_TP_BASIS) " -.ie n .IP """k1"" (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_PP_K1\s0\fR) " 4 -.el .IP "``k1'' (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_PP_K1\s0\fR) " 4 -.IX Item "k1 (OSSL_PKEY_PARAM_EC_CHAR2_PP_K1) " -.ie n .IP """k2"" (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_PP_K2\s0\fR) " 4 -.el .IP "``k2'' (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_PP_K2\s0\fR) " 4 -.IX Item "k2 (OSSL_PKEY_PARAM_EC_CHAR2_PP_K2) " -.ie n .IP """k3"" (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_PP_K3\s0\fR) " 4 -.el .IP "``k3'' (\fB\s-1OSSL_PKEY_PARAM_EC_CHAR2_PP_K3\s0\fR) " 4 -.IX Item "k3 (OSSL_PKEY_PARAM_EC_CHAR2_PP_K3) " -.PD -These fields are only used for a binary field F2^m. -\&\fIm\fR is the degree of the binary field. -.Sp -\&\fItp\fR is the middle bit of a trinomial so its value must be in the -range m > tp > 0. -.Sp -\&\fIk1\fR, \fIk2\fR and \fIk3\fR are used to get the middle bits of a pentanomial such -that m > k3 > k2 > k1 > 0 -.PP -The following key generation settable parameter is also available for the -OpenSSL \s-1FIPS\s0 provider's \s-1EC\s0 algorithm: -.ie n .IP """key-check"" (\fB\s-1OSSL_PKEY_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_PKEY_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_PKEY_PARAM_FIPS_KEY_CHECK) " -See \*(L"Common Information Parameters\*(R" in \fBprovider\-keymgmt\fR\|(7) for further information. -.PP -The following key generation Gettable parameter is available for the OpenSSL -\&\s-1FIPS\s0 provider's \s-1EC\s0 algorithm: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) " -See \*(L"Common Information Parameters\*(R" in \fBprovider\-keymgmt\fR\|(7) for further information. -.SS "\s-1EC\s0 key validation" -.IX Subsection "EC key validation" -For \s-1EC\s0 keys, \fBEVP_PKEY_param_check\fR\|(3) behaves in the following way: -For the OpenSSL default provider it uses either -\&\fBEC_GROUP_check\fR\|(3) or \fBEC_GROUP_check_named_curve\fR\|(3) depending on the flag -\&\s-1EC_FLAG_CHECK_NAMED_GROUP.\s0 -The OpenSSL \s-1FIPS\s0 provider uses \fBEC_GROUP_check_named_curve\fR\|(3) in order to -conform to SP800\-56Ar3 \fIAssurances of Domain-Parameter Validity\fR. -.PP -For \s-1EC\s0 keys, \fBEVP_PKEY_param_check_quick\fR\|(3) is equivalent to -\&\fBEVP_PKEY_param_check\fR\|(3). -.PP -For \s-1EC\s0 keys, \fBEVP_PKEY_public_check\fR\|(3) and \fBEVP_PKEY_public_check_quick\fR\|(3) -conform to SP800\-56Ar3 \fI\s-1ECC\s0 Full Public-Key Validation\fR and -\&\fI\s-1ECC\s0 Partial Public-Key Validation\fR respectively. -.PP -For \s-1EC\s0 Keys, \fBEVP_PKEY_private_check\fR\|(3) and \fBEVP_PKEY_pairwise_check\fR\|(3) -conform to SP800\-56Ar3 \fIPrivate key validity\fR and -\&\fIOwner Assurance of Pair-wise Consistency\fR respectively. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -An \fB\s-1EVP_PKEY\s0\fR context can be obtained by calling: -.PP -.Vb 2 -\& EVP_PKEY_CTX *pctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL); -.Ve -.PP -An \fB\s-1EVP_PKEY\s0\fR \s-1ECDSA\s0 or \s-1ECDH\s0 key can be generated with a \*(L"P\-256\*(R" named group by -calling: -.PP -.Vb 1 -\& pkey = EVP_EC_gen("P\-256"); -.Ve -.PP -or like this: -.PP -.Vb 4 -\& EVP_PKEY *key = NULL; -\& OSSL_PARAM params[2]; -\& EVP_PKEY_CTX *gctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL); -\& -\& EVP_PKEY_keygen_init(gctx); -\& -\& params[0] = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME, -\& "P\-256", 0); -\& params[1] = OSSL_PARAM_construct_end(); -\& EVP_PKEY_CTX_set_params(gctx, params); -\& -\& EVP_PKEY_generate(gctx, &key); -\& -\& EVP_PKEY_print_private(bio_out, key, 0, NULL); -\& ... -\& EVP_PKEY_free(key); -\& EVP_PKEY_CTX_free(gctx); -.Ve -.PP -An \fB\s-1EVP_PKEY\s0\fR \s-1EC CDH\s0 (Cofactor Diffie-Hellman) key can be generated with a -\&\*(L"K\-571\*(R" named group by calling: -.PP -.Vb 5 -\& int use_cdh = 1; -\& EVP_PKEY *key = NULL; -\& OSSL_PARAM params[3]; -\& EVP_PKEY_CTX *gctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL); -\& -\& EVP_PKEY_keygen_init(gctx); -\& -\& params[0] = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME, -\& "K\-571", 0); -\& /* -\& * This curve has a cofactor that is not 1 \- so setting CDH mode changes -\& * the behaviour. For many curves the cofactor is 1 \- so setting this has -\& * no effect. -\& */ -\& params[1] = OSSL_PARAM_construct_int(OSSL_PKEY_PARAM_USE_COFACTOR_ECDH, -\& &use_cdh); -\& params[2] = OSSL_PARAM_construct_end(); -\& EVP_PKEY_CTX_set_params(gctx, params); -\& -\& EVP_PKEY_generate(gctx, &key); -\& EVP_PKEY_print_private(bio_out, key, 0, NULL); -\& ... -\& EVP_PKEY_free(key); -\& EVP_PKEY_CTX_free(gctx); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_EC_gen\fR\|(3), -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keymgmt\fR\|(7), -\&\s-1\fBEVP_SIGNATURE\-ECDSA\s0\fR\|(7), -\&\s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-ED25519.7ossl b/openssl-install/share/man/man7/EVP_PKEY-ED25519.7ossl deleted file mode 120000 index 564c378e..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-ED25519.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_PKEY-ED448.7ossl b/openssl-install/share/man/man7/EVP_PKEY-ED448.7ossl deleted file mode 120000 index 564c378e..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-ED448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_PKEY-FFC.7ossl b/openssl-install/share/man/man7/EVP_PKEY-FFC.7ossl deleted file mode 100644 index 972eae38..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-FFC.7ossl +++ /dev/null @@ -1,346 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-FFC 7ossl" -.TH EVP_PKEY-FFC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-FFC \- EVP_PKEY DSA and DH/DHX shared FFC parameters. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Finite field cryptography (\s-1FFC\s0) is a method of implementing discrete logarithm -cryptography using finite field mathematics. \s-1DSA\s0 is an example of \s-1FFC\s0 and -Diffie-Hellman key establishment algorithms specified in \s-1SP800\-56A\s0 can also be -implemented as \s-1FFC.\s0 -.PP -The \fB\s-1DSA\s0\fR, \fB\s-1DH\s0\fR and \fB\s-1DHX\s0\fR keytypes are implemented in OpenSSL's default and -\&\s-1FIPS\s0 providers. -The implementations support the basic \s-1DSA, DH\s0 and \s-1DHX\s0 keys, containing the public -and private keys \fIpub\fR and \fIpriv\fR as well as the three main domain parameters -\&\fIp\fR, \fIq\fR and \fIg\fR. -.PP -For \fB\s-1DSA\s0\fR (and \fB\s-1DH\s0\fR that is not a named group) the \s-1FIPS186\-4\s0 standard -specifies that the values used for \s-1FFC\s0 parameter generation are also required -for parameter validation. -This means that optional \s-1FFC\s0 domain parameter values for \fIseed\fR, \fIpcounter\fR -and \fIgindex\fR may need to be stored for validation purposes. -For \fB\s-1DH\s0\fR the \fIseed\fR and \fIpcounter\fR can be stored in \s-1ASN1\s0 data -(but the \fIgindex\fR is not). For \fB\s-1DSA\s0\fR however, these fields are not stored in -the \s-1ASN1\s0 data so they need to be stored externally if validation is required. -.PP -The \fB\s-1DH\s0\fR key type uses PKCS#3 format which saves p and g, but not the 'q' value. -The \fB\s-1DHX\s0\fR key type uses X9.42 format which saves the value of 'q' and this -must be used for \s-1FIPS186\-4.\s0 -.SS "\s-1FFC\s0 parameters" -.IX Subsection "FFC parameters" -In addition to the common parameters that all keytypes should support (see -\&\*(L"Common parameters\*(R" in \fBprovider\-keymgmt\fR\|(7)), the \fB\s-1DSA\s0\fR, \fB\s-1DH\s0\fR and \fB\s-1DHX\s0\fR keytype -implementations support the following. -.ie n .IP """pub"" (\fB\s-1OSSL_PKEY_PARAM_PUB_KEY\s0\fR) " 4 -.el .IP "``pub'' (\fB\s-1OSSL_PKEY_PARAM_PUB_KEY\s0\fR) " 4 -.IX Item "pub (OSSL_PKEY_PARAM_PUB_KEY) " -The public key value. -.ie n .IP """priv"" (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.el .IP "``priv'' (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.IX Item "priv (OSSL_PKEY_PARAM_PRIV_KEY) " -The private key value. -.SS "\s-1FFC DSA, DH\s0 and \s-1DHX\s0 domain parameters" -.IX Subsection "FFC DSA, DH and DHX domain parameters" -.ie n .IP """p"" (\fB\s-1OSSL_PKEY_PARAM_FFC_P\s0\fR) " 4 -.el .IP "``p'' (\fB\s-1OSSL_PKEY_PARAM_FFC_P\s0\fR) " 4 -.IX Item "p (OSSL_PKEY_PARAM_FFC_P) " -A \s-1DSA\s0 or Diffie-Hellman prime \*(L"p\*(R" value. -.ie n .IP """g"" (\fB\s-1OSSL_PKEY_PARAM_FFC_G\s0\fR) " 4 -.el .IP "``g'' (\fB\s-1OSSL_PKEY_PARAM_FFC_G\s0\fR) " 4 -.IX Item "g (OSSL_PKEY_PARAM_FFC_G) " -A \s-1DSA\s0 or Diffie-Hellman generator \*(L"g\*(R" value. -.SS "\s-1FFC DSA\s0 and \s-1DHX\s0 domain parameters" -.IX Subsection "FFC DSA and DHX domain parameters" -.ie n .IP """q"" (\fB\s-1OSSL_PKEY_PARAM_FFC_Q\s0\fR) " 4 -.el .IP "``q'' (\fB\s-1OSSL_PKEY_PARAM_FFC_Q\s0\fR) " 4 -.IX Item "q (OSSL_PKEY_PARAM_FFC_Q) " -A \s-1DSA\s0 or Diffie-Hellman prime \*(L"q\*(R" value. -.ie n .IP """seed"" (\fB\s-1OSSL_PKEY_PARAM_FFC_SEED\s0\fR) " 4 -.el .IP "``seed'' (\fB\s-1OSSL_PKEY_PARAM_FFC_SEED\s0\fR) " 4 -.IX Item "seed (OSSL_PKEY_PARAM_FFC_SEED) " -An optional domain parameter \fIseed\fR value used during generation and validation -of \fIp\fR, \fIq\fR and canonical \fIg\fR. -For validation this needs to set the \fIseed\fR that was produced during generation. -.ie n .IP """gindex"" (\fB\s-1OSSL_PKEY_PARAM_FFC_GINDEX\s0\fR) " 4 -.el .IP "``gindex'' (\fB\s-1OSSL_PKEY_PARAM_FFC_GINDEX\s0\fR) " 4 -.IX Item "gindex (OSSL_PKEY_PARAM_FFC_GINDEX) " -Sets the index to use for canonical generation and verification of the generator -\&\fIg\fR. -Set this to a positive value from 0..FF to use this mode. This \fIgindex\fR can -then be reused during key validation to verify the value of \fIg\fR. If this value -is not set or is \-1 then unverifiable generation of the generator \fIg\fR will be -used. -.ie n .IP """pcounter"" (\fB\s-1OSSL_PKEY_PARAM_FFC_PCOUNTER\s0\fR) " 4 -.el .IP "``pcounter'' (\fB\s-1OSSL_PKEY_PARAM_FFC_PCOUNTER\s0\fR) " 4 -.IX Item "pcounter (OSSL_PKEY_PARAM_FFC_PCOUNTER) " -An optional domain parameter \fIcounter\fR value that is output during generation -of \fIp\fR. This value must be saved if domain parameter validation is required. -.ie n .IP """hindex"" (\fB\s-1OSSL_PKEY_PARAM_FFC_H\s0\fR) " 4 -.el .IP "``hindex'' (\fB\s-1OSSL_PKEY_PARAM_FFC_H\s0\fR) " 4 -.IX Item "hindex (OSSL_PKEY_PARAM_FFC_H) " -For unverifiable generation of the generator \fIg\fR this value is output during -generation of \fIg\fR. Its value is the first integer larger than one that -satisfies g = h^j mod p (where g != 1 and \*(L"j\*(R" is the cofactor). -.ie n .IP """j"" (\fB\s-1OSSL_PKEY_PARAM_FFC_COFACTOR\s0\fR) " 4 -.el .IP "``j'' (\fB\s-1OSSL_PKEY_PARAM_FFC_COFACTOR\s0\fR) " 4 -.IX Item "j (OSSL_PKEY_PARAM_FFC_COFACTOR) " -An optional informational cofactor parameter that should equal to (p \- 1) / q. -.ie n .IP """validate-pq"" (\fB\s-1OSSL_PKEY_PARAM_FFC_VALIDATE_PQ\s0\fR) " 4 -.el .IP "``validate-pq'' (\fB\s-1OSSL_PKEY_PARAM_FFC_VALIDATE_PQ\s0\fR) " 4 -.IX Item "validate-pq (OSSL_PKEY_PARAM_FFC_VALIDATE_PQ) " -.PD 0 -.ie n .IP """validate-g"" (\fB\s-1OSSL_PKEY_PARAM_FFC_VALIDATE_G\s0\fR) " 4 -.el .IP "``validate-g'' (\fB\s-1OSSL_PKEY_PARAM_FFC_VALIDATE_G\s0\fR) " 4 -.IX Item "validate-g (OSSL_PKEY_PARAM_FFC_VALIDATE_G) " -.PD -These boolean values are used during \s-1FIPS186\-4\s0 or \s-1FIPS186\-2\s0 key validation checks -(See \fBEVP_PKEY_param_check\fR\|(3)) to select validation options. By default -\&\fIvalidate-pq\fR and \fIvalidate-g\fR are both set to 1 to check that p,q and g are -valid. Either of these may be set to 0 to skip a test, which is mainly useful -for testing purposes. -.ie n .IP """validate-legacy"" (\fB\s-1OSSL_PKEY_PARAM_FFC_VALIDATE_LEGACY\s0\fR) " 4 -.el .IP "``validate-legacy'' (\fB\s-1OSSL_PKEY_PARAM_FFC_VALIDATE_LEGACY\s0\fR) " 4 -.IX Item "validate-legacy (OSSL_PKEY_PARAM_FFC_VALIDATE_LEGACY) " -This boolean value is used during key validation checks -(See \fBEVP_PKEY_param_check\fR\|(3)) to select the validation type. The default -value of 0 selects \s-1FIPS186\-4\s0 validation. Setting this value to 1 selects -\&\s-1FIPS186\-2\s0 validation. -.SS "\s-1FFC\s0 key generation parameters" -.IX Subsection "FFC key generation parameters" -The following key generation types are available for \s-1DSA\s0 and \s-1DHX\s0 algorithms: -.ie n .IP """type"" (\fB\s-1OSSL_PKEY_PARAM_FFC_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``type'' (\fB\s-1OSSL_PKEY_PARAM_FFC_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "type (OSSL_PKEY_PARAM_FFC_TYPE) " -Sets the type of parameter generation. The shared valid values are: -.RS 4 -.ie n .IP """fips186_4""" 4 -.el .IP "``fips186_4''" 4 -.IX Item "fips186_4" -The current standard. -.ie n .IP """fips186_2""" 4 -.el .IP "``fips186_2''" 4 -.IX Item "fips186_2" -The old standard that should only be used for legacy purposes. -.ie n .IP """default""" 4 -.el .IP "``default''" 4 -.IX Item "default" -This can choose one of \*(L"fips186_4\*(R" or \*(L"fips186_2\*(R" depending on other -parameters set for parameter generation. -.RE -.RS 4 -.RE -.ie n .IP """pbits"" (\fB\s-1OSSL_PKEY_PARAM_FFC_PBITS\s0\fR) " 4 -.el .IP "``pbits'' (\fB\s-1OSSL_PKEY_PARAM_FFC_PBITS\s0\fR) " 4 -.IX Item "pbits (OSSL_PKEY_PARAM_FFC_PBITS) " -Sets the size (in bits) of the prime 'p'. -.ie n .IP """qbits"" (\fB\s-1OSSL_PKEY_PARAM_FFC_QBITS\s0\fR) " 4 -.el .IP "``qbits'' (\fB\s-1OSSL_PKEY_PARAM_FFC_QBITS\s0\fR) " 4 -.IX Item "qbits (OSSL_PKEY_PARAM_FFC_QBITS) " -Sets the size (in bits) of the prime 'q'. -.Sp -For \*(L"fips186_4\*(R" this can be either 224 or 256. -For \*(L"fips186_2\*(R" this has a size of 160. -.ie n .IP """digest"" (\fB\s-1OSSL_PKEY_PARAM_FFC_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_PKEY_PARAM_FFC_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_PKEY_PARAM_FFC_DIGEST) " -Sets the Digest algorithm to be used as part of the Key Generation Function -associated with the given Key Generation \fIctx\fR. -This must also be set for key validation. -.ie n .IP """properties"" (\fB\s-1OSSL_PKEY_PARAM_FFC_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_PKEY_PARAM_FFC_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_PKEY_PARAM_FFC_DIGEST_PROPS) " -Sets properties to be used upon look up of the implementation for the selected -Digest algorithm for the Key Generation Function associated with the given key -generation \fIctx\fR. This may also be set for key validation. -.ie n .IP """seed"" (\fB\s-1OSSL_PKEY_PARAM_FFC_SEED\s0\fR) " 4 -.el .IP "``seed'' (\fB\s-1OSSL_PKEY_PARAM_FFC_SEED\s0\fR) " 4 -.IX Item "seed (OSSL_PKEY_PARAM_FFC_SEED) " -For \*(L"fips186_4\*(R" or \*(L"fips186_2\*(R" generation this sets the \fIseed\fR data to use -instead of generating a random seed internally. This should be used for -testing purposes only. This will either produce fixed values for the generated -parameters \s-1OR\s0 it will fail if the seed did not generate valid primes. -.ie n .IP """gindex"" (\fB\s-1OSSL_PKEY_PARAM_FFC_GINDEX\s0\fR) " 4 -.el .IP "``gindex'' (\fB\s-1OSSL_PKEY_PARAM_FFC_GINDEX\s0\fR) " 4 -.IX Item "gindex (OSSL_PKEY_PARAM_FFC_GINDEX) " -.PD 0 -.ie n .IP """pcounter"" (\fB\s-1OSSL_PKEY_PARAM_FFC_PCOUNTER\s0\fR) " 4 -.el .IP "``pcounter'' (\fB\s-1OSSL_PKEY_PARAM_FFC_PCOUNTER\s0\fR) " 4 -.IX Item "pcounter (OSSL_PKEY_PARAM_FFC_PCOUNTER) " -.ie n .IP """hindex"" (\fB\s-1OSSL_PKEY_PARAM_FFC_H\s0\fR) " 4 -.el .IP "``hindex'' (\fB\s-1OSSL_PKEY_PARAM_FFC_H\s0\fR) " 4 -.IX Item "hindex (OSSL_PKEY_PARAM_FFC_H) " -.PD -These types are described above. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -The following sections of SP800\-56Ar3: -.IP "5.5.1.1 \s-1FFC\s0 Domain Parameter Selection/Generation" 4 -.IX Item "5.5.1.1 FFC Domain Parameter Selection/Generation" -.PP -The following sections of \s-1FIPS186\-4:\s0 -.IP "A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function." 4 -.IX Item "A.1.1.2 Generation of Probable Primes p and q Using an Approved Hash Function." -.PD 0 -.IP "A.2.3 Generation of canonical generator g." 4 -.IX Item "A.2.3 Generation of canonical generator g." -.IP "A.2.1 Unverifiable Generation of the Generator g." 4 -.IX Item "A.2.1 Unverifiable Generation of the Generator g." -.PD -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-DH\s0\fR\|(7), -\&\s-1\fBEVP_SIGNATURE\-DSA\s0\fR\|(7), -\&\s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7) -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), -\&\s-1\fBEVP_PKEY\s0\fR\|(3), -\&\fBprovider\-keymgmt\fR\|(7), -\&\fBOSSL_PROVIDER\-default\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-HMAC.7ossl b/openssl-install/share/man/man7/EVP_PKEY-HMAC.7ossl deleted file mode 100644 index 77835aa6..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-HMAC.7ossl +++ /dev/null @@ -1,207 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-HMAC 7ossl" -.TH EVP_PKEY-HMAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-HMAC, EVP_KEYMGMT\-HMAC, EVP_PKEY\-Siphash, EVP_KEYMGMT\-Siphash, -EVP_PKEY\-Poly1305, EVP_KEYMGMT\-Poly1305, EVP_PKEY\-CMAC, EVP_KEYMGMT\-CMAC -\&\- EVP_PKEY legacy MAC keytypes and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1HMAC\s0\fR and \fB\s-1CMAC\s0\fR key types are implemented in OpenSSL's default and \s-1FIPS\s0 -providers. Additionally the \fBSiphash\fR and \fBPoly1305\fR key types are implemented -in the default provider. Performing \s-1MAC\s0 operations via an \s-1EVP_PKEY\s0 -is considered legacy and are only available for backwards compatibility purposes -and for a restricted set of algorithms. The preferred way of performing \s-1MAC\s0 -operations is via the \s-1EVP_MAC\s0 APIs. See \fBEVP_MAC_init\fR\|(3). -.PP -For further details on using \s-1EVP_PKEY\s0 based \s-1MAC\s0 keys see -\&\s-1\fBEVP_SIGNATURE\-HMAC\s0\fR\|(7), \fBEVP_SIGNATURE\-Siphash\fR\|(7), -\&\fBEVP_SIGNATURE\-Poly1305\fR\|(7) or \s-1\fBEVP_SIGNATURE\-CMAC\s0\fR\|(7). -.SS "Common \s-1MAC\s0 parameters" -.IX Subsection "Common MAC parameters" -All the \fB\s-1MAC\s0\fR keytypes support the following parameters. -.ie n .IP """priv"" (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.el .IP "``priv'' (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.IX Item "priv (OSSL_PKEY_PARAM_PRIV_KEY) " -The \s-1MAC\s0 key value. -.ie n .IP """properties"" (\fB\s-1OSSL_PKEY_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_PKEY_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_PKEY_PARAM_PROPERTIES) " -A property query string to be used when any algorithms are fetched. -.SS "\s-1CMAC\s0 parameters" -.IX Subsection "CMAC parameters" -As well as the parameters described above, the \fB\s-1CMAC\s0\fR keytype additionally -supports the following parameters. -.ie n .IP """cipher"" (\fB\s-1OSSL_PKEY_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_PKEY_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_PKEY_PARAM_CIPHER) " -The name of a cipher to be used when generating the \s-1MAC.\s0 -.ie n .IP """engine"" (\fB\s-1OSSL_PKEY_PARAM_ENGINE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``engine'' (\fB\s-1OSSL_PKEY_PARAM_ENGINE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "engine (OSSL_PKEY_PARAM_ENGINE) " -The name of an engine to be used for the specified cipher (if any). -.SS "Common \s-1MAC\s0 key generation parameters" -.IX Subsection "Common MAC key generation parameters" -\&\s-1MAC\s0 key generation is unusual in that no new key is actually generated. Instead -a new provider side key object is created with the supplied raw key value. This -is done for backwards compatibility with previous versions of OpenSSL. -.ie n .IP """priv"" (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.el .IP "``priv'' (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.IX Item "priv (OSSL_PKEY_PARAM_PRIV_KEY) " -The \s-1MAC\s0 key value. -.SS "\s-1CMAC\s0 key generation parameters" -.IX Subsection "CMAC key generation parameters" -In addition to the common \s-1MAC\s0 key generation parameters, the \s-1CMAC\s0 key generation -additionally recognises the following. -.ie n .IP """cipher"" (\fB\s-1OSSL_PKEY_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_PKEY_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_PKEY_PARAM_CIPHER) " -The name of a cipher to be used when generating the \s-1MAC.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), \s-1\fBEVP_PKEY\s0\fR\|(3), \fBprovider\-keymgmt\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-Poly1305.7ossl b/openssl-install/share/man/man7/EVP_PKEY-Poly1305.7ossl deleted file mode 120000 index e258700c..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-Poly1305.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_PKEY-RSA.7ossl b/openssl-install/share/man/man7/EVP_PKEY-RSA.7ossl deleted file mode 100644 index a417940c..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-RSA.7ossl +++ /dev/null @@ -1,438 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-RSA 7ossl" -.TH EVP_PKEY-RSA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-RSA, EVP_KEYMGMT\-RSA, RSA -\&\- EVP_PKEY RSA keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1RSA\s0\fR keytype is implemented in OpenSSL's default and \s-1FIPS\s0 providers. -That implementation supports the basic \s-1RSA\s0 keys, containing the modulus \fIn\fR, -the public exponent \fIe\fR, the private exponent \fId\fR, and a collection of prime -factors, exponents and coefficient for \s-1CRT\s0 calculations, of which the first -few are known as \fIp\fR and \fIq\fR, \fIdP\fR and \fIdQ\fR, and \fIqInv\fR. -.SS "Common \s-1RSA\s0 parameters" -.IX Subsection "Common RSA parameters" -In addition to the common parameters that all keytypes should support (see -\&\*(L"Common parameters\*(R" in \fBprovider\-keymgmt\fR\|(7)), the \fB\s-1RSA\s0\fR keytype implementation -supports the following. -.ie n .IP """n"" (\fB\s-1OSSL_PKEY_PARAM_RSA_N\s0\fR) " 4 -.el .IP "``n'' (\fB\s-1OSSL_PKEY_PARAM_RSA_N\s0\fR) " 4 -.IX Item "n (OSSL_PKEY_PARAM_RSA_N) " -The \s-1RSA\s0 modulus \*(L"n\*(R" value. -.ie n .IP """e"" (\fB\s-1OSSL_PKEY_PARAM_RSA_E\s0\fR) " 4 -.el .IP "``e'' (\fB\s-1OSSL_PKEY_PARAM_RSA_E\s0\fR) " 4 -.IX Item "e (OSSL_PKEY_PARAM_RSA_E) " -The \s-1RSA\s0 public exponent \*(L"e\*(R" value. -This value must always be set when creating a raw key using \fBEVP_PKEY_fromdata\fR\|(3). -Note that when a decryption operation is performed, that this value is used for -blinding purposes to prevent timing attacks. -.ie n .IP """d"" (\fB\s-1OSSL_PKEY_PARAM_RSA_D\s0\fR) " 4 -.el .IP "``d'' (\fB\s-1OSSL_PKEY_PARAM_RSA_D\s0\fR) " 4 -.IX Item "d (OSSL_PKEY_PARAM_RSA_D) " -The \s-1RSA\s0 private exponent \*(L"d\*(R" value. -.ie n .IP """rsa\-factor1"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR1\s0\fR) " 4 -.el .IP "``rsa\-factor1'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR1\s0\fR) " 4 -.IX Item "rsa-factor1 (OSSL_PKEY_PARAM_RSA_FACTOR1) " -.PD 0 -.ie n .IP """rsa\-factor2"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR2\s0\fR) " 4 -.el .IP "``rsa\-factor2'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR2\s0\fR) " 4 -.IX Item "rsa-factor2 (OSSL_PKEY_PARAM_RSA_FACTOR2) " -.ie n .IP """rsa\-factor3"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR3\s0\fR) " 4 -.el .IP "``rsa\-factor3'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR3\s0\fR) " 4 -.IX Item "rsa-factor3 (OSSL_PKEY_PARAM_RSA_FACTOR3) " -.ie n .IP """rsa\-factor4"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR4\s0\fR) " 4 -.el .IP "``rsa\-factor4'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR4\s0\fR) " 4 -.IX Item "rsa-factor4 (OSSL_PKEY_PARAM_RSA_FACTOR4) " -.ie n .IP """rsa\-factor5"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR5\s0\fR) " 4 -.el .IP "``rsa\-factor5'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR5\s0\fR) " 4 -.IX Item "rsa-factor5 (OSSL_PKEY_PARAM_RSA_FACTOR5) " -.ie n .IP """rsa\-factor6"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR6\s0\fR) " 4 -.el .IP "``rsa\-factor6'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR6\s0\fR) " 4 -.IX Item "rsa-factor6 (OSSL_PKEY_PARAM_RSA_FACTOR6) " -.ie n .IP """rsa\-factor7"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR7\s0\fR) " 4 -.el .IP "``rsa\-factor7'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR7\s0\fR) " 4 -.IX Item "rsa-factor7 (OSSL_PKEY_PARAM_RSA_FACTOR7) " -.ie n .IP """rsa\-factor8"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR8\s0\fR) " 4 -.el .IP "``rsa\-factor8'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR8\s0\fR) " 4 -.IX Item "rsa-factor8 (OSSL_PKEY_PARAM_RSA_FACTOR8) " -.ie n .IP """rsa\-factor9"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR9\s0\fR) " 4 -.el .IP "``rsa\-factor9'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR9\s0\fR) " 4 -.IX Item "rsa-factor9 (OSSL_PKEY_PARAM_RSA_FACTOR9) " -.ie n .IP """rsa\-factor10"" (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR10\s0\fR) " 4 -.el .IP "``rsa\-factor10'' (\fB\s-1OSSL_PKEY_PARAM_RSA_FACTOR10\s0\fR) " 4 -.IX Item "rsa-factor10 (OSSL_PKEY_PARAM_RSA_FACTOR10) " -.PD -\&\s-1RSA\s0 prime factors. The factors are known as \*(L"p\*(R", \*(L"q\*(R" and \*(L"r_i\*(R" in \s-1RFC8017.\s0 -Up to eight additional \*(L"r_i\*(R" prime factors are supported. -.ie n .IP """rsa\-exponent1"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT1\s0\fR) " 4 -.el .IP "``rsa\-exponent1'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT1\s0\fR) " 4 -.IX Item "rsa-exponent1 (OSSL_PKEY_PARAM_RSA_EXPONENT1) " -.PD 0 -.ie n .IP """rsa\-exponent2"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT2\s0\fR) " 4 -.el .IP "``rsa\-exponent2'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT2\s0\fR) " 4 -.IX Item "rsa-exponent2 (OSSL_PKEY_PARAM_RSA_EXPONENT2) " -.ie n .IP """rsa\-exponent3"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT3\s0\fR) " 4 -.el .IP "``rsa\-exponent3'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT3\s0\fR) " 4 -.IX Item "rsa-exponent3 (OSSL_PKEY_PARAM_RSA_EXPONENT3) " -.ie n .IP """rsa\-exponent4"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT4\s0\fR) " 4 -.el .IP "``rsa\-exponent4'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT4\s0\fR) " 4 -.IX Item "rsa-exponent4 (OSSL_PKEY_PARAM_RSA_EXPONENT4) " -.ie n .IP """rsa\-exponent5"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT5\s0\fR) " 4 -.el .IP "``rsa\-exponent5'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT5\s0\fR) " 4 -.IX Item "rsa-exponent5 (OSSL_PKEY_PARAM_RSA_EXPONENT5) " -.ie n .IP """rsa\-exponent6"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT6\s0\fR) " 4 -.el .IP "``rsa\-exponent6'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT6\s0\fR) " 4 -.IX Item "rsa-exponent6 (OSSL_PKEY_PARAM_RSA_EXPONENT6) " -.ie n .IP """rsa\-exponent7"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT7\s0\fR) " 4 -.el .IP "``rsa\-exponent7'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT7\s0\fR) " 4 -.IX Item "rsa-exponent7 (OSSL_PKEY_PARAM_RSA_EXPONENT7) " -.ie n .IP """rsa\-exponent8"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT8\s0\fR) " 4 -.el .IP "``rsa\-exponent8'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT8\s0\fR) " 4 -.IX Item "rsa-exponent8 (OSSL_PKEY_PARAM_RSA_EXPONENT8) " -.ie n .IP """rsa\-exponent9"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT9\s0\fR) " 4 -.el .IP "``rsa\-exponent9'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT9\s0\fR) " 4 -.IX Item "rsa-exponent9 (OSSL_PKEY_PARAM_RSA_EXPONENT9) " -.ie n .IP """rsa\-exponent10"" (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT10\s0\fR) " 4 -.el .IP "``rsa\-exponent10'' (\fB\s-1OSSL_PKEY_PARAM_RSA_EXPONENT10\s0\fR) " 4 -.IX Item "rsa-exponent10 (OSSL_PKEY_PARAM_RSA_EXPONENT10) " -.PD -\&\s-1RSA CRT\s0 (Chinese Remainder Theorem) exponents. The exponents are known -as \*(L"dP\*(R", \*(L"dQ\*(R" and \*(L"d_i\*(R" in \s-1RFC8017.\s0 -Up to eight additional \*(L"d_i\*(R" exponents are supported. -.ie n .IP """rsa\-coefficient1"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT1\s0\fR) " 4 -.el .IP "``rsa\-coefficient1'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT1\s0\fR) " 4 -.IX Item "rsa-coefficient1 (OSSL_PKEY_PARAM_RSA_COEFFICIENT1) " -.PD 0 -.ie n .IP """rsa\-coefficient2"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT2\s0\fR) " 4 -.el .IP "``rsa\-coefficient2'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT2\s0\fR) " 4 -.IX Item "rsa-coefficient2 (OSSL_PKEY_PARAM_RSA_COEFFICIENT2) " -.ie n .IP """rsa\-coefficient3"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT3\s0\fR) " 4 -.el .IP "``rsa\-coefficient3'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT3\s0\fR) " 4 -.IX Item "rsa-coefficient3 (OSSL_PKEY_PARAM_RSA_COEFFICIENT3) " -.ie n .IP """rsa\-coefficient4"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT4\s0\fR) " 4 -.el .IP "``rsa\-coefficient4'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT4\s0\fR) " 4 -.IX Item "rsa-coefficient4 (OSSL_PKEY_PARAM_RSA_COEFFICIENT4) " -.ie n .IP """rsa\-coefficient5"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT5\s0\fR) " 4 -.el .IP "``rsa\-coefficient5'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT5\s0\fR) " 4 -.IX Item "rsa-coefficient5 (OSSL_PKEY_PARAM_RSA_COEFFICIENT5) " -.ie n .IP """rsa\-coefficient6"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT6\s0\fR) " 4 -.el .IP "``rsa\-coefficient6'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT6\s0\fR) " 4 -.IX Item "rsa-coefficient6 (OSSL_PKEY_PARAM_RSA_COEFFICIENT6) " -.ie n .IP """rsa\-coefficient7"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT7\s0\fR) " 4 -.el .IP "``rsa\-coefficient7'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT7\s0\fR) " 4 -.IX Item "rsa-coefficient7 (OSSL_PKEY_PARAM_RSA_COEFFICIENT7) " -.ie n .IP """rsa\-coefficient8"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT8\s0\fR) " 4 -.el .IP "``rsa\-coefficient8'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT8\s0\fR) " 4 -.IX Item "rsa-coefficient8 (OSSL_PKEY_PARAM_RSA_COEFFICIENT8) " -.ie n .IP """rsa\-coefficient9"" (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT9\s0\fR) " 4 -.el .IP "``rsa\-coefficient9'' (\fB\s-1OSSL_PKEY_PARAM_RSA_COEFFICIENT9\s0\fR) " 4 -.IX Item "rsa-coefficient9 (OSSL_PKEY_PARAM_RSA_COEFFICIENT9) " -.PD -\&\s-1RSA CRT\s0 (Chinese Remainder Theorem) coefficients. The coefficients are known as -\&\*(L"qInv\*(R" and \*(L"t_i\*(R". -Up to eight additional \*(L"t_i\*(R" exponents are supported. -.SS "\s-1RSA\s0 key generation parameters" -.IX Subsection "RSA key generation parameters" -When generating \s-1RSA\s0 keys, the following key generation parameters may be used. -.ie n .IP """bits"" (\fB\s-1OSSL_PKEY_PARAM_RSA_BITS\s0\fR) " 4 -.el .IP "``bits'' (\fB\s-1OSSL_PKEY_PARAM_RSA_BITS\s0\fR) " 4 -.IX Item "bits (OSSL_PKEY_PARAM_RSA_BITS) " -The value should be the cryptographic length for the \fB\s-1RSA\s0\fR cryptosystem, in -bits. -.ie n .IP """primes"" (\fB\s-1OSSL_PKEY_PARAM_RSA_PRIMES\s0\fR) " 4 -.el .IP "``primes'' (\fB\s-1OSSL_PKEY_PARAM_RSA_PRIMES\s0\fR) " 4 -.IX Item "primes (OSSL_PKEY_PARAM_RSA_PRIMES) " -The value should be the number of primes for the generated \fB\s-1RSA\s0\fR key. The -default is 2. It isn't permitted to specify a larger number of primes than -10. Additionally, the number of primes is limited by the length of the key -being generated so the maximum number could be less. -Some providers may only support a value of 2. -.ie n .IP """e"" (\fB\s-1OSSL_PKEY_PARAM_RSA_E\s0\fR) " 4 -.el .IP "``e'' (\fB\s-1OSSL_PKEY_PARAM_RSA_E\s0\fR) " 4 -.IX Item "e (OSSL_PKEY_PARAM_RSA_E) " -The \s-1RSA\s0 \*(L"e\*(R" value. The value may be any odd number greater than or equal to -65537. The default value is 65537. -For legacy reasons a value of 3 is currently accepted but is deprecated. -.ie n .IP """rsa-derive-from-pq"" (\fB\s-1OSSL_PKEY_PARAM_RSA_DERIVE_FROM_PQ\s0\fR) " 4 -.el .IP "``rsa-derive-from-pq'' (\fB\s-1OSSL_PKEY_PARAM_RSA_DERIVE_FROM_PQ\s0\fR) " 4 -.IX Item "rsa-derive-from-pq (OSSL_PKEY_PARAM_RSA_DERIVE_FROM_PQ) " -Indicate that missing parameters not passed in the parameter list should be -derived if not provided. Setting a nonzero value will cause all -needed exponents and coefficients to be derived if not available. Setting this -option requires at least \s-1OSSL_PARAM_RSA_FACTOR1, OSSL_PARAM_RSA_FACTOR2,\s0 -and \s-1OSSL_PARAM_RSA_N\s0 to be provided. This option is ignored if -\&\s-1OSSL_KEYMGMT_SELECT_PRIVATE_KEY\s0 is not set in the selection parameter. -.SS "\s-1RSA\s0 key generation parameters for \s-1FIPS\s0 module testing" -.IX Subsection "RSA key generation parameters for FIPS module testing" -When generating \s-1RSA\s0 keys, the following additional key generation parameters may -be used for algorithm testing purposes only. Do not use these to generate -\&\s-1RSA\s0 keys for a production environment. -.ie n .IP """xp"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XP\s0\fR) " 4 -.el .IP "``xp'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XP\s0\fR) " 4 -.IX Item "xp (OSSL_PKEY_PARAM_RSA_TEST_XP) " -.PD 0 -.ie n .IP """xq"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XQ\s0\fR) " 4 -.el .IP "``xq'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XQ\s0\fR) " 4 -.IX Item "xq (OSSL_PKEY_PARAM_RSA_TEST_XQ) " -.PD -These 2 fields are normally randomly generated and are used to generate \*(L"p\*(R" and -\&\*(L"q\*(R". -.ie n .IP """xp1"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XP1\s0\fR) " 4 -.el .IP "``xp1'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XP1\s0\fR) " 4 -.IX Item "xp1 (OSSL_PKEY_PARAM_RSA_TEST_XP1) " -.PD 0 -.ie n .IP """xp2"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XP2\s0\fR) " 4 -.el .IP "``xp2'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XP2\s0\fR) " 4 -.IX Item "xp2 (OSSL_PKEY_PARAM_RSA_TEST_XP2) " -.ie n .IP """xq1"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XQ1\s0\fR) " 4 -.el .IP "``xq1'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XQ1\s0\fR) " 4 -.IX Item "xq1 (OSSL_PKEY_PARAM_RSA_TEST_XQ1) " -.ie n .IP """xq2"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XQ2\s0\fR) " 4 -.el .IP "``xq2'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_XQ2\s0\fR) " 4 -.IX Item "xq2 (OSSL_PKEY_PARAM_RSA_TEST_XQ2) " -.PD -These 4 fields are normally randomly generated. The prime factors \*(L"p1\*(R", \*(L"p2\*(R", -\&\*(L"q1\*(R" and \*(L"q2\*(R" are determined from these values. -.SS "\s-1RSA\s0 key parameters for \s-1FIPS\s0 module testing" -.IX Subsection "RSA key parameters for FIPS module testing" -The following intermediate values can be retrieved only if the values -specified in \*(L"\s-1RSA\s0 key generation parameters for \s-1FIPS\s0 module testing\*(R" are set. -These should not be accessed in a production environment. -.ie n .IP """p1"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_P1\s0\fR) " 4 -.el .IP "``p1'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_P1\s0\fR) " 4 -.IX Item "p1 (OSSL_PKEY_PARAM_RSA_TEST_P1) " -.PD 0 -.ie n .IP """p2"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_P2\s0\fR) " 4 -.el .IP "``p2'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_P2\s0\fR) " 4 -.IX Item "p2 (OSSL_PKEY_PARAM_RSA_TEST_P2) " -.ie n .IP """q1"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_Q1\s0\fR) " 4 -.el .IP "``q1'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_Q1\s0\fR) " 4 -.IX Item "q1 (OSSL_PKEY_PARAM_RSA_TEST_Q1) " -.ie n .IP """q2"" (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_Q2\s0\fR) " 4 -.el .IP "``q2'' (\fB\s-1OSSL_PKEY_PARAM_RSA_TEST_Q2\s0\fR) " 4 -.IX Item "q2 (OSSL_PKEY_PARAM_RSA_TEST_Q2) " -.PD -The auxiliary probable primes. -.SS "\s-1RSA\s0 key validation" -.IX Subsection "RSA key validation" -For \s-1RSA\s0 keys, \fBEVP_PKEY_param_check\fR\|(3) and \fBEVP_PKEY_param_check_quick\fR\|(3) -both return 1 unconditionally. -.PP -For \s-1RSA\s0 keys, \fBEVP_PKEY_public_check\fR\|(3) conforms to the SP800\-56Br1 \fIpublic key -check\fR when the OpenSSL \s-1FIPS\s0 provider is used. The OpenSSL default provider -performs similar tests but relaxes the keysize restrictions for backwards -compatibility. -.PP -For \s-1RSA\s0 keys, \fBEVP_PKEY_public_check_quick\fR\|(3) is the same as -\&\fBEVP_PKEY_public_check\fR\|(3). -.PP -For \s-1RSA\s0 keys, \fBEVP_PKEY_private_check\fR\|(3) conforms to the SP800\-56Br1 -\&\fIprivate key test\fR. -.PP -For \s-1RSA\s0 keys, \fBEVP_PKEY_pairwise_check\fR\|(3) conforms to the -SP800\-56Br1 \fIKeyPair Validation check\fR for the OpenSSL \s-1FIPS\s0 provider. The -OpenSSL default provider allows testing of the validity of multi-primes. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -.IP "\s-1FIPS186\-4\s0" 4 -.IX Item "FIPS186-4" -Section B.3.6 Generation of Probable Primes with Conditions Based on -Auxiliary Probable Primes -.IP "\s-1RFC 8017,\s0 excluding RSA-PSS and RSA-OAEP" 4 -.IX Item "RFC 8017, excluding RSA-PSS and RSA-OAEP" -.SH "EXAMPLES" -.IX Header "EXAMPLES" -An \fB\s-1EVP_PKEY\s0\fR context can be obtained by calling: -.PP -.Vb 2 -\& EVP_PKEY_CTX *pctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL); -.Ve -.PP -An \fB\s-1RSA\s0\fR key can be generated simply like this: -.PP -.Vb 1 -\& pkey = EVP_RSA_gen(4096); -.Ve -.PP -or like this: -.PP -.Vb 3 -\& EVP_PKEY *pkey = NULL; -\& EVP_PKEY_CTX *pctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL); -\& -\& EVP_PKEY_keygen_init(pctx); -\& EVP_PKEY_generate(pctx, &pkey); -\& EVP_PKEY_CTX_free(pctx); -.Ve -.PP -An \fB\s-1RSA\s0\fR key can be generated with key generation parameters: -.PP -.Vb 5 -\& unsigned int primes = 3; -\& unsigned int bits = 4096; -\& OSSL_PARAM params[3]; -\& EVP_PKEY *pkey = NULL; -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL); -\& -\& EVP_PKEY_keygen_init(pctx); -\& -\& params[0] = OSSL_PARAM_construct_uint("bits", &bits); -\& params[1] = OSSL_PARAM_construct_uint("primes", &primes); -\& params[2] = OSSL_PARAM_construct_end(); -\& EVP_PKEY_CTX_set_params(pctx, params); -\& -\& EVP_PKEY_generate(pctx, &pkey); -\& EVP_PKEY_print_private(bio_out, pkey, 0, NULL); -\& EVP_PKEY_CTX_free(pctx); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_RSA_gen\fR\|(3), \s-1\fBEVP_KEYMGMT\s0\fR\|(3), \s-1\fBEVP_PKEY\s0\fR\|(3), \fBprovider\-keymgmt\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-SM2.7ossl b/openssl-install/share/man/man7/EVP_PKEY-SM2.7ossl deleted file mode 100644 index dd7bbcca..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-SM2.7ossl +++ /dev/null @@ -1,227 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-SM2 7ossl" -.TH EVP_PKEY-SM2 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-SM2, EVP_KEYMGMT\-SM2, SM2 -\&\- EVP_PKEY keytype support for the Chinese SM2 signature and encryption algorithms -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fB\s-1SM2\s0\fR algorithm was first defined by the Chinese national standard \s-1GM/T -0003\-2012\s0 and was later standardized by \s-1ISO\s0 as \s-1ISO/IEC 14888.\s0 \fB\s-1SM2\s0\fR is actually -an elliptic curve based algorithm. The current implementation in OpenSSL supports -both signature and encryption schemes via the \s-1EVP\s0 interface. -.PP -When doing the \fB\s-1SM2\s0\fR signature algorithm, it requires a distinguishing identifier -to form the message prefix which is hashed before the real message is hashed. -.SS "Common \s-1SM2\s0 parameters" -.IX Subsection "Common SM2 parameters" -\&\s-1SM2\s0 uses the parameters defined in \*(L"Common \s-1EC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7). -The following parameters are different: -.ie n .IP """cofactor"" (\fB\s-1OSSL_PKEY_PARAM_EC_COFACTOR\s0\fR) " 4 -.el .IP "``cofactor'' (\fB\s-1OSSL_PKEY_PARAM_EC_COFACTOR\s0\fR) " 4 -.IX Item "cofactor (OSSL_PKEY_PARAM_EC_COFACTOR) " -This parameter is ignored for \fB\s-1SM2\s0\fR. -.IP "(\fB\s-1OSSL_PKEY_PARAM_DEFAULT_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "(OSSL_PKEY_PARAM_DEFAULT_DIGEST) " -Getter that returns the default digest name. -(Currently returns \*(L"\s-1SM3\*(R"\s0 as of OpenSSL 3.0). -.SH "NOTES" -.IX Header "NOTES" -\&\fB\s-1SM2\s0\fR signatures can be generated by using the 'DigestSign' series of APIs, for -instance, \fBEVP_DigestSignInit()\fR, \fBEVP_DigestSignUpdate()\fR and \fBEVP_DigestSignFinal()\fR. -Ditto for the verification process by calling the 'DigestVerify' series of APIs. -Note that the \s-1SM2\s0 algorithm requires the presence of the public key for signatures, -as such the \fB\s-1OSSL_PKEY_PARAM_PUB_KEY\s0\fR option must be set on any key used in signature -generation. -.PP -Before computing an \fB\s-1SM2\s0\fR signature, an \fB\s-1EVP_PKEY_CTX\s0\fR needs to be created, -and an \fB\s-1SM2\s0\fR \s-1ID\s0 must be set for it, like this: -.PP -.Vb 1 -\& EVP_PKEY_CTX_set1_id(pctx, id, id_len); -.Ve -.PP -Before calling the \fBEVP_DigestSignInit()\fR or \fBEVP_DigestVerifyInit()\fR functions, -that \fB\s-1EVP_PKEY_CTX\s0\fR should be assigned to the \fB\s-1EVP_MD_CTX\s0\fR, like this: -.PP -.Vb 1 -\& EVP_MD_CTX_set_pkey_ctx(mctx, pctx); -.Ve -.PP -There is normally no need to pass a \fBpctx\fR parameter to \fBEVP_DigestSignInit()\fR -or \fBEVP_DigestVerifyInit()\fR in such a scenario. -.PP -\&\s-1SM2\s0 can be tested with the \fBopenssl\-speed\fR\|(1) application since version 3.0. -Currently, the only valid algorithm name is \fBsm2\fR. -.PP -Since version 3.0, \s-1SM2\s0 keys can be generated and loaded only when the domain -parameters specify the \s-1SM2\s0 elliptic curve. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example demonstrates the calling sequence for using an \fB\s-1EVP_PKEY\s0\fR to verify -a message with the \s-1SM2\s0 signature algorithm and the \s-1SM3\s0 hash algorithm: -.PP -.Vb 1 -\& #include -\& -\& /* obtain an EVP_PKEY using whatever methods... */ -\& mctx = EVP_MD_CTX_new(); -\& pctx = EVP_PKEY_CTX_new(pkey, NULL); -\& EVP_PKEY_CTX_set1_id(pctx, id, id_len); -\& EVP_MD_CTX_set_pkey_ctx(mctx, pctx); -\& EVP_DigestVerifyInit(mctx, NULL, EVP_sm3(), NULL, pkey); -\& EVP_DigestVerifyUpdate(mctx, msg, msg_len); -\& EVP_DigestVerifyFinal(mctx, sig, sig_len) -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_DigestSignInit\fR\|(3), -\&\fBEVP_DigestVerifyInit\fR\|(3), -\&\fBEVP_PKEY_CTX_set1_id\fR\|(3), -\&\fBEVP_MD_CTX_set_pkey_ctx\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-Siphash.7ossl b/openssl-install/share/man/man7/EVP_PKEY-Siphash.7ossl deleted file mode 120000 index e258700c..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-Siphash.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_PKEY-X25519.7ossl b/openssl-install/share/man/man7/EVP_PKEY-X25519.7ossl deleted file mode 100644 index feb27ea7..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-X25519.7ossl +++ /dev/null @@ -1,246 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_PKEY-X25519 7ossl" -.TH EVP_PKEY-X25519 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_PKEY\-X25519, EVP_PKEY\-X448, EVP_PKEY\-ED25519, EVP_PKEY\-ED448, -EVP_KEYMGMT\-X25519, EVP_KEYMGMT\-X448, EVP_KEYMGMT\-ED25519, EVP_KEYMGMT\-ED448 -\&\- EVP_PKEY X25519, X448, ED25519 and ED448 keytype and algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX25519\fR, \fBX448\fR, \fB\s-1ED25519\s0\fR and \fB\s-1ED448\s0\fR keytypes are -implemented in OpenSSL's default and \s-1FIPS\s0 providers. These implementations -support the associated key, containing the public key \fIpub\fR and the -private key \fIpriv\fR. -.SS "Keygen Parameters" -.IX Subsection "Keygen Parameters" -.ie n .IP """dhkem-ikm"" (\fB\s-1OSSL_PKEY_PARAM_DHKEM_IKM\s0\fR) " 4 -.el .IP "``dhkem-ikm'' (\fB\s-1OSSL_PKEY_PARAM_DHKEM_IKM\s0\fR) " 4 -.IX Item "dhkem-ikm (OSSL_PKEY_PARAM_DHKEM_IKM) " -\&\s-1DHKEM\s0 requires the generation of a keypair using an input key material (seed). -Use this to specify the key material used for generation of the private key. -This value should not be reused for other purposes. -It should have a length of at least 32 for X25519, and 56 for X448. -This is only supported by X25519 and X448. -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) " -This getter is only supported by X25519 and X448 for the \s-1FIPS\s0 provider. -Since X25519 and X448 are unapproved in \s-1FIPS 140\-3\s0 this getter return 0. -.Sp -See \*(L"Common Information Parameters\*(R" in \fBprovider\-keymgmt\fR\|(7) for further information. -.PP -Use \fBEVP_PKEY_CTX_set_params()\fR after calling \fBEVP_PKEY_keygen_init()\fR. -.SS "Common X25519, X448, \s-1ED25519\s0 and \s-1ED448\s0 parameters" -.IX Subsection "Common X25519, X448, ED25519 and ED448 parameters" -In addition to the common parameters that all keytypes should support (see -\&\*(L"Common parameters\*(R" in \fBprovider\-keymgmt\fR\|(7)), the implementation of these keytypes -support the following. -.ie n .IP """group"" (\fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``group'' (\fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "group (OSSL_PKEY_PARAM_GROUP_NAME) " -This is only supported by X25519 and X448. The group name must be \*(L"x25519\*(R" or -\&\*(L"x448\*(R" respectively for those algorithms. This is only present for consistency -with other key exchange algorithms and is typically not needed. -.ie n .IP """pub"" (\fB\s-1OSSL_PKEY_PARAM_PUB_KEY\s0\fR) " 4 -.el .IP "``pub'' (\fB\s-1OSSL_PKEY_PARAM_PUB_KEY\s0\fR) " 4 -.IX Item "pub (OSSL_PKEY_PARAM_PUB_KEY) " -The public key value. -.ie n .IP """priv"" (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.el .IP "``priv'' (\fB\s-1OSSL_PKEY_PARAM_PRIV_KEY\s0\fR) " 4 -.IX Item "priv (OSSL_PKEY_PARAM_PRIV_KEY) " -The private key value. -.ie n .IP """encoded-pub-key"" (\fB\s-1OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY\s0\fR) " 4 -.el .IP "``encoded-pub-key'' (\fB\s-1OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY\s0\fR) " 4 -.IX Item "encoded-pub-key (OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY) " -Used for getting and setting the encoding of a public key for the \fBX25519\fR and -\&\fBX448\fR key types. Public keys are expected be encoded in a format as defined by -\&\s-1RFC7748.\s0 -.SS "\s-1ED25519\s0 and \s-1ED448\s0 parameters" -.IX Subsection "ED25519 and ED448 parameters" -.ie n .IP """mandatory-digest"" (\fB\s-1OSSL_PKEY_PARAM_MANDATORY_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mandatory-digest'' (\fB\s-1OSSL_PKEY_PARAM_MANDATORY_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mandatory-digest (OSSL_PKEY_PARAM_MANDATORY_DIGEST) " -The empty string, signifying that no digest may be specified. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -.IP "\s-1RFC 8032\s0" 4 -.IX Item "RFC 8032" -.PD 0 -.IP "\s-1RFC 8410\s0" 4 -.IX Item "RFC 8410" -.PD -.SH "EXAMPLES" -.IX Header "EXAMPLES" -An \fB\s-1EVP_PKEY\s0\fR context can be obtained by calling: -.PP -.Vb 2 -\& EVP_PKEY_CTX *pctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "X25519", NULL); -\& -\& EVP_PKEY_CTX *pctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "X448", NULL); -\& -\& EVP_PKEY_CTX *pctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "ED25519", NULL); -\& -\& EVP_PKEY_CTX *pctx = -\& EVP_PKEY_CTX_new_from_name(NULL, "ED448", NULL); -.Ve -.PP -An \fBX25519\fR key can be generated like this: -.PP -.Vb 1 -\& pkey = EVP_PKEY_Q_keygen(NULL, NULL, "X25519"); -.Ve -.PP -An \fBX448\fR, \fB\s-1ED25519\s0\fR, or \fB\s-1ED448\s0\fR key can be generated likewise. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_KEYMGMT\s0\fR\|(3), \s-1\fBEVP_PKEY\s0\fR\|(3), \fBprovider\-keymgmt\fR\|(7), -\&\s-1\fBEVP_KEYEXCH\-X25519\s0\fR\|(7), \s-1\fBEVP_KEYEXCH\-X448\s0\fR\|(7), -\&\s-1\fBEVP_SIGNATURE\-ED25519\s0\fR\|(7), \s-1\fBEVP_SIGNATURE\-ED448\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_PKEY-X448.7ossl b/openssl-install/share/man/man7/EVP_PKEY-X448.7ossl deleted file mode 120000 index 564c378e..00000000 --- a/openssl-install/share/man/man7/EVP_PKEY-X448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_RAND-CRNG-TEST.7ossl b/openssl-install/share/man/man7/EVP_RAND-CRNG-TEST.7ossl deleted file mode 100644 index dfc5c626..00000000 --- a/openssl-install/share/man/man7/EVP_RAND-CRNG-TEST.7ossl +++ /dev/null @@ -1,202 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND-CRNG-TEST 7ossl" -.TH EVP_RAND-CRNG-TEST 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND\-CRNG\-TEST \- The FIPS health testing EVP_RAND filter -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This \fB\s-1EVP_RAND\s0\fR object acts as a filter between the entropy source -and its users. It performs \s-1CRNG\s0 health tests as defined in -\&\s-1SP 800\-90B\s0 Section 4 \*(L"Health -Tests\*(R". Most requests are forwarded to the entropy source, either via -its parent reference or via the provider entropy upcalls. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"CRNG-TEST\*(R" is the name for this implementation; it can be used with the -\&\fBEVP_RAND_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -If a parent \s-1EVP_RAND\s0 is specified on context creation, the parent's -parameters are supported because the request is forwarded to the parent -seed source for processing. -.PP -If no parent \s-1EVP_RAND\s0 is specified on context creation, the following parameters -are supported: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -.PD 0 -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -.ie n .IP """max_request"" (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.IX Item "max_request (OSSL_RAND_PARAM_MAX_REQUEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3). -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) " -This parameter works as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \fBprovider\-rand\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -This \s-1EVP_RAND\s0 is only implemented by the OpenSSL \s-1FIPS\s0 provider. -.PP -A context for a health test filter can be obtained by calling: -.PP -.Vb 3 -\& EVP_RAND *parent = ...; -\& EVP_RAND *rand = EVP_RAND_fetch(NULL, "CRNG\-TEST", NULL); -\& EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, parent); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_RAND-CTR-DRBG.7ossl b/openssl-install/share/man/man7/EVP_RAND-CTR-DRBG.7ossl deleted file mode 100644 index 39ab18ed..00000000 --- a/openssl-install/share/man/man7/EVP_RAND-CTR-DRBG.7ossl +++ /dev/null @@ -1,249 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND-CTR-DRBG 7ossl" -.TH EVP_RAND-CTR-DRBG 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND\-CTR\-DRBG \- The CTR DRBG EVP_RAND implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for the counter deterministic random bit generator through the -\&\fB\s-1EVP_RAND\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"CTR-DRBG\*(R" is the name for this implementation; it can be used with the -\&\fBEVP_RAND_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -.PD 0 -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -.ie n .IP """max_request"" (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.IX Item "max_request (OSSL_RAND_PARAM_MAX_REQUEST) " -.ie n .IP """reseed_requests"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``reseed_requests'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "reseed_requests (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -.ie n .IP """reseed_time_interval"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.el .IP "``reseed_time_interval'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.IX Item "reseed_time_interval (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) " -.ie n .IP """min_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.el .IP "``min_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.IX Item "min_entropylen (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) " -.ie n .IP """max_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.el .IP "``max_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.IX Item "max_entropylen (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) " -.ie n .IP """min_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.el .IP "``min_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.IX Item "min_noncelen (OSSL_DRBG_PARAM_MIN_NONCELEN) " -.ie n .IP """max_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.el .IP "``max_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.IX Item "max_noncelen (OSSL_DRBG_PARAM_MAX_NONCELEN) " -.ie n .IP """max_perslen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.el .IP "``max_perslen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.IX Item "max_perslen (OSSL_DRBG_PARAM_MAX_PERSLEN) " -.ie n .IP """max_adinlen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.el .IP "``max_adinlen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.IX Item "max_adinlen (OSSL_DRBG_PARAM_MAX_ADINLEN) " -.ie n .IP """reseed_counter"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.el .IP "``reseed_counter'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.IX Item "reseed_counter (OSSL_DRBG_PARAM_RESEED_COUNTER) " -.ie n .IP """properties"" (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_DRBG_PARAM_PROPERTIES) " -.ie n .IP """cipher"" (\fB\s-1OSSL_DRBG_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_DRBG_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_DRBG_PARAM_CIPHER) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3). -.ie n .IP """use_derivation_function"" (\fB\s-1OSSL_DRBG_PARAM_USE_DF\s0\fR) " 4 -.el .IP "``use_derivation_function'' (\fB\s-1OSSL_DRBG_PARAM_USE_DF\s0\fR) " 4 -.IX Item "use_derivation_function (OSSL_DRBG_PARAM_USE_DF) " -This Boolean indicates if a derivation function should be used or not. -A nonzero value (the default) uses the derivation function. A zero value -does not. -.SH "NOTES" -.IX Header "NOTES" -A context for \s-1CTR DRBG\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_RAND *rand = EVP_RAND_fetch(NULL, "CTR\-DRBG", NULL); -\& EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL); -.Ve -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 5 -\& EVP_RAND *rand; -\& EVP_RAND_CTX *rctx; -\& unsigned char bytes[100]; -\& OSSL_PARAM params[2], *p = params; -\& unsigned int strength = 128; -\& -\& rand = EVP_RAND_fetch(NULL, "CTR\-DRBG", NULL); -\& rctx = EVP_RAND_CTX_new(rand, NULL); -\& EVP_RAND_free(rand); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER, -\& SN_aes_256_ctr, 0); -\& *p = OSSL_PARAM_construct_end(); -\& EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params); -\& -\& EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0); -\& -\& EVP_RAND_CTX_free(rctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST SP 800\-90A\s0 and \s-1SP 800\-90B\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_RAND-HASH-DRBG.7ossl b/openssl-install/share/man/man7/EVP_RAND-HASH-DRBG.7ossl deleted file mode 100644 index dd749158..00000000 --- a/openssl-install/share/man/man7/EVP_RAND-HASH-DRBG.7ossl +++ /dev/null @@ -1,274 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND-HASH-DRBG 7ossl" -.TH EVP_RAND-HASH-DRBG 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND\-HASH\-DRBG \- The HASH DRBG EVP_RAND implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for the hash deterministic random bit generator through the -\&\fB\s-1EVP_RAND\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"HASH-DRBG\*(R" is the name for this implementation; it can be used with the -\&\fBEVP_RAND_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -.PD 0 -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -.ie n .IP """max_request"" (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.IX Item "max_request (OSSL_RAND_PARAM_MAX_REQUEST) " -.ie n .IP """reseed_requests"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``reseed_requests'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "reseed_requests (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -.ie n .IP """reseed_time_interval"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.el .IP "``reseed_time_interval'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.IX Item "reseed_time_interval (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) " -.ie n .IP """min_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.el .IP "``min_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.IX Item "min_entropylen (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) " -.ie n .IP """max_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.el .IP "``max_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.IX Item "max_entropylen (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) " -.ie n .IP """min_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.el .IP "``min_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.IX Item "min_noncelen (OSSL_DRBG_PARAM_MIN_NONCELEN) " -.ie n .IP """max_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.el .IP "``max_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.IX Item "max_noncelen (OSSL_DRBG_PARAM_MAX_NONCELEN) " -.ie n .IP """max_perslen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.el .IP "``max_perslen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.IX Item "max_perslen (OSSL_DRBG_PARAM_MAX_PERSLEN) " -.ie n .IP """max_adinlen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.el .IP "``max_adinlen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.IX Item "max_adinlen (OSSL_DRBG_PARAM_MAX_ADINLEN) " -.ie n .IP """reseed_counter"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.el .IP "``reseed_counter'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.IX Item "reseed_counter (OSSL_DRBG_PARAM_RESEED_COUNTER) " -.ie n .IP """properties"" (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_DRBG_PARAM_PROPERTIES) " -.ie n .IP """digest"" (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_DRBG_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3). -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) " -.PD 0 -.ie n .IP """digest-check"" (\fB\s-1OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \fBprovider\-rand\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -When the \s-1FIPS\s0 provider is installed using the \fB\-no_drbg_truncated_digests\fR -option to fipsinstall, only these digests are permitted (as per -\&\s-1FIPS 140\-3 IG D.R\s0 ): -.IP "\s-1SHA\-1\s0" 4 -.IX Item "SHA-1" -.PD 0 -.IP "\s-1SHA2\-256\s0" 4 -.IX Item "SHA2-256" -.IP "\s-1SHA2\-512\s0" 4 -.IX Item "SHA2-512" -.IP "\s-1SHA3\-256\s0" 4 -.IX Item "SHA3-256" -.IP "\s-1SHA3\-512\s0" 4 -.IX Item "SHA3-512" -.PD -.PP -A context for \s-1HASH DRBG\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_RAND *rand = EVP_RAND_fetch(NULL, "HASH\-DRBG", NULL); -\& EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL); -.Ve -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 5 -\& EVP_RAND *rand; -\& EVP_RAND_CTX *rctx; -\& unsigned char bytes[100]; -\& OSSL_PARAM params[2], *p = params; -\& unsigned int strength = 128; -\& -\& rand = EVP_RAND_fetch(NULL, "HASH\-DRBG", NULL); -\& rctx = EVP_RAND_CTX_new(rand, NULL); -\& EVP_RAND_free(rand); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_DIGEST, SN_sha512, 0); -\& *p = OSSL_PARAM_construct_end(); -\& EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params); -\& -\& EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0); -\& -\& EVP_RAND_CTX_free(rctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST SP 800\-90A\s0 and \s-1SP 800\-90B\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3), -\&\fBopenssl\-fipsinstall\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -OpenSSL 3.1.1 introduced the \fB\-no_drbg_truncated_digests\fR option to -fipsinstall which restricts the permitted digests when using the \s-1FIPS\s0 -provider in a complaint manner. For details refer to -\&\s-1FIPS 140\-3 IG D.R\s0 . -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_RAND-HMAC-DRBG.7ossl b/openssl-install/share/man/man7/EVP_RAND-HMAC-DRBG.7ossl deleted file mode 100644 index 348486fe..00000000 --- a/openssl-install/share/man/man7/EVP_RAND-HMAC-DRBG.7ossl +++ /dev/null @@ -1,277 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND-HMAC-DRBG 7ossl" -.TH EVP_RAND-HMAC-DRBG 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND\-HMAC\-DRBG \- The HMAC DRBG EVP_RAND implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for the \s-1HMAC\s0 deterministic random bit generator through the -\&\fB\s-1EVP_RAND\s0\fR \s-1API.\s0 -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"HMAC-DRBG\*(R" is the name for this implementation; it can be used with the -\&\fBEVP_RAND_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -.PD 0 -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -.ie n .IP """max_request"" (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.IX Item "max_request (OSSL_RAND_PARAM_MAX_REQUEST) " -.ie n .IP """reseed_requests"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``reseed_requests'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "reseed_requests (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -.ie n .IP """reseed_time_interval"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.el .IP "``reseed_time_interval'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.IX Item "reseed_time_interval (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) " -.ie n .IP """min_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.el .IP "``min_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.IX Item "min_entropylen (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) " -.ie n .IP """max_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.el .IP "``max_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.IX Item "max_entropylen (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) " -.ie n .IP """min_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.el .IP "``min_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.IX Item "min_noncelen (OSSL_DRBG_PARAM_MIN_NONCELEN) " -.ie n .IP """max_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.el .IP "``max_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.IX Item "max_noncelen (OSSL_DRBG_PARAM_MAX_NONCELEN) " -.ie n .IP """max_perslen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.el .IP "``max_perslen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.IX Item "max_perslen (OSSL_DRBG_PARAM_MAX_PERSLEN) " -.ie n .IP """max_adinlen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.el .IP "``max_adinlen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.IX Item "max_adinlen (OSSL_DRBG_PARAM_MAX_ADINLEN) " -.ie n .IP """reseed_counter"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.el .IP "``reseed_counter'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.IX Item "reseed_counter (OSSL_DRBG_PARAM_RESEED_COUNTER) " -.ie n .IP """properties"" (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_DRBG_PARAM_PROPERTIES) " -.ie n .IP """mac"" (\fB\s-1OSSL_DRBG_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mac'' (\fB\s-1OSSL_DRBG_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mac (OSSL_DRBG_PARAM_MAC) " -.ie n .IP """digest"" (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_DRBG_PARAM_DIGEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3). -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) " -.PD 0 -.ie n .IP """digest-check"" (\fB\s-1OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \fBprovider\-rand\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -When using the \s-1FIPS\s0 provider, only these digests are permitted (as per -\&\s-1FIPS 140\-3 IG D.R\s0 ): -.IP "\s-1SHA\-1\s0" 4 -.IX Item "SHA-1" -.PD 0 -.IP "\s-1SHA2\-256\s0" 4 -.IX Item "SHA2-256" -.IP "\s-1SHA2\-512\s0" 4 -.IX Item "SHA2-512" -.IP "\s-1SHA3\-256\s0" 4 -.IX Item "SHA3-256" -.IP "\s-1SHA3\-512\s0" 4 -.IX Item "SHA3-512" -.PD -.PP -A context for \s-1HMAC DRBG\s0 can be obtained by calling: -.PP -.Vb 2 -\& EVP_RAND *rand = EVP_RAND_fetch(NULL, "HMAC\-DRBG", NULL); -\& EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL); -.Ve -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 5 -\& EVP_RAND *rand; -\& EVP_RAND_CTX *rctx; -\& unsigned char bytes[100]; -\& OSSL_PARAM params[3], *p = params; -\& unsigned int strength = 128; -\& -\& rand = EVP_RAND_fetch(NULL, "HMAC\-DRBG", NULL); -\& rctx = EVP_RAND_CTX_new(rand, NULL); -\& EVP_RAND_free(rand); -\& -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_MAC, SN_hmac, 0); -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_DIGEST, SN_sha256, 0); -\& *p = OSSL_PARAM_construct_end(); -\& EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params); -\& -\& EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0); -\& -\& EVP_RAND_CTX_free(rctx); -.Ve -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1NIST SP 800\-90A\s0 and \s-1SP 800\-90B\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3), -\&\fBopenssl\-fipsinstall\fR\|(1) -.SH "HISTORY" -.IX Header "HISTORY" -OpenSSL 3.1.1 introduced the \fB\-no_drbg_truncated_digests\fR option to -fipsinstall which restricts the permitted digests when using the \s-1FIPS\s0 -provider in a complaint manner. For details refer to -\&\s-1FIPS 140\-3 IG D.R\s0 ). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_RAND-JITTER.7ossl b/openssl-install/share/man/man7/EVP_RAND-JITTER.7ossl deleted file mode 100644 index bb79545b..00000000 --- a/openssl-install/share/man/man7/EVP_RAND-JITTER.7ossl +++ /dev/null @@ -1,225 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND-JITTER 7ossl" -.TH EVP_RAND-JITTER 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND\-JITTER \- The randomness seed source EVP_RAND implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for deterministic random number generator seeding through the -\&\fB\s-1EVP_RAND\s0\fR \s-1API.\s0 -.PP -This software seed source produces randomness based on tiny \s-1CPU\s0 -\&\*(L"jitter\*(R" fluctuations. -.PP -It is available when OpenSSL is compiled with \fBenable-jitter\fR -option. When available it is listed in \fBopenssl list -\&\-random\-generators\fR and \fBopenssl info \-seeds\fR. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"\s-1JITTER\*(R"\s0 is the name for this implementation; it can be used with the -\&\fBEVP_RAND_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -.PD 0 -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -.ie n .IP """max_request"" (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.IX Item "max_request (OSSL_RAND_PARAM_MAX_REQUEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -A context for the seed source can be obtained by calling: -.PP -.Vb 2 -\& EVP_RAND *rand = EVP_RAND_fetch(NULL, "JITTER", NULL); -\& EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL); -.Ve -.PP -The \fBenable-jitter\fR configuration option was added in OpenSSL 3.4. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 5 -\& EVP_RAND *rand; -\& EVP_RAND_CTX *seed, *rctx; -\& unsigned char bytes[100]; -\& OSSL_PARAM params[2], *p = params; -\& unsigned int strength = 128; -\& -\& /* Create and instantiate a seed source */ -\& rand = EVP_RAND_fetch(NULL, "JITTER", NULL); -\& seed = EVP_RAND_CTX_new(rand, NULL); -\& EVP_RAND_instantiate(seed, strength, 0, NULL, 0, NULL); -\& EVP_RAND_free(rand); -\& -\& /* Feed this into a DRBG */ -\& rand = EVP_RAND_fetch(NULL, "CTR\-DRBG", NULL); -\& rctx = EVP_RAND_CTX_new(rand, seed); -\& EVP_RAND_free(rand); -\& -\& /* Configure the DRBG */ -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER, -\& SN_aes_256_ctr, 0); -\& *p = OSSL_PARAM_construct_end(); -\& EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params); -\& -\& EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0); -\& -\& EVP_RAND_CTX_free(rctx); -\& EVP_RAND_CTX_free(seed); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_RAND-SEED-SRC.7ossl b/openssl-install/share/man/man7/EVP_RAND-SEED-SRC.7ossl deleted file mode 100644 index aed7099d..00000000 --- a/openssl-install/share/man/man7/EVP_RAND-SEED-SRC.7ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND-SEED-SRC 7ossl" -.TH EVP_RAND-SEED-SRC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND\-SEED\-SRC \- The randomness seed source EVP_RAND implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for deterministic random number generator seeding through the -\&\fB\s-1EVP_RAND\s0\fR \s-1API.\s0 -.PP -The seed sources used are specified at the time OpenSSL is configured for -building using the \fB\-\-with\-rand\-seed=\fR option. By default, operating system -randomness sources are used. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"SEED-SRC\*(R" is the name for this implementation; it can be used with the -\&\fBEVP_RAND_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -.PD 0 -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -.ie n .IP """max_request"" (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_RAND_PARAM_MAX_REQUEST\s0\fR) " 4 -.IX Item "max_request (OSSL_RAND_PARAM_MAX_REQUEST) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3). -.SH "NOTES" -.IX Header "NOTES" -A context for the seed source can be obtained by calling: -.PP -.Vb 2 -\& EVP_RAND *rand = EVP_RAND_fetch(NULL, "SEED\-SRC", NULL); -\& EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL); -.Ve -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 5 -\& EVP_RAND *rand; -\& EVP_RAND_CTX *seed, *rctx; -\& unsigned char bytes[100]; -\& OSSL_PARAM params[2], *p = params; -\& unsigned int strength = 128; -\& -\& /* Create and instantiate a seed source */ -\& rand = EVP_RAND_fetch(NULL, "SEED\-SRC", NULL); -\& seed = EVP_RAND_CTX_new(rand, NULL); -\& EVP_RAND_instantiate(seed, strength, 0, NULL, 0, NULL); -\& EVP_RAND_free(rand); -\& -\& /* Feed this into a DRBG */ -\& rand = EVP_RAND_fetch(NULL, "CTR\-DRBG", NULL); -\& rctx = EVP_RAND_CTX_new(rand, seed); -\& EVP_RAND_free(rand); -\& -\& /* Configure the DRBG */ -\& *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER, -\& SN_aes_256_ctr, 0); -\& *p = OSSL_PARAM_construct_end(); -\& EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params); -\& -\& EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0); -\& -\& EVP_RAND_CTX_free(rctx); -\& EVP_RAND_CTX_free(seed); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_RAND-TEST-RAND.7ossl b/openssl-install/share/man/man7/EVP_RAND-TEST-RAND.7ossl deleted file mode 100644 index 1528e155..00000000 --- a/openssl-install/share/man/man7/EVP_RAND-TEST-RAND.7ossl +++ /dev/null @@ -1,267 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND-TEST-RAND 7ossl" -.TH EVP_RAND-TEST-RAND 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND\-TEST\-RAND \- The test EVP_RAND implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for a test generator through the \fB\s-1EVP_RAND\s0\fR \s-1API.\s0 This generator is -for test purposes only, it does not generate random numbers. -.SS "Identity" -.IX Subsection "Identity" -\&\*(L"TEST-RAND\*(R" is the name for this implementation; it can be used with the -\&\fBEVP_RAND_fetch()\fR function. -.SS "Supported parameters" -.IX Subsection "Supported parameters" -The supported parameters are: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -.PD 0 -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR) " -.PD -These parameter works as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3). -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -.PD 0 -.ie n .IP """reseed_requests"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``reseed_requests'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "reseed_requests (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -.ie n .IP """reseed_time_interval"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.el .IP "``reseed_time_interval'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.IX Item "reseed_time_interval (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) " -.ie n .IP """max_request"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "max_request (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -.ie n .IP """min_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.el .IP "``min_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.IX Item "min_entropylen (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) " -.ie n .IP """max_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.el .IP "``max_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.IX Item "max_entropylen (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) " -.ie n .IP """min_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.el .IP "``min_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.IX Item "min_noncelen (OSSL_DRBG_PARAM_MIN_NONCELEN) " -.ie n .IP """max_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.el .IP "``max_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.IX Item "max_noncelen (OSSL_DRBG_PARAM_MAX_NONCELEN) " -.ie n .IP """max_perslen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.el .IP "``max_perslen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.IX Item "max_perslen (OSSL_DRBG_PARAM_MAX_PERSLEN) " -.ie n .IP """max_adinlen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.el .IP "``max_adinlen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.IX Item "max_adinlen (OSSL_DRBG_PARAM_MAX_ADINLEN) " -.ie n .IP """reseed_counter"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.el .IP "``reseed_counter'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.IX Item "reseed_counter (OSSL_DRBG_PARAM_RESEED_COUNTER) " -.PD -These parameters work as described in \*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3), except that -they can all be set as well as read. -.ie n .IP """test_entropy"" (\fB\s-1OSSL_RAND_PARAM_TEST_ENTROPY\s0\fR) " 4 -.el .IP "``test_entropy'' (\fB\s-1OSSL_RAND_PARAM_TEST_ENTROPY\s0\fR) " 4 -.IX Item "test_entropy (OSSL_RAND_PARAM_TEST_ENTROPY) " -Sets the bytes returned when the test generator is sent an entropy request. -The current position is remembered across generate calls. -If there are insufficient data present to satisfy a call, an error is returned. -.ie n .IP """test_nonce"" (\fB\s-1OSSL_RAND_PARAM_TEST_NONCE\s0\fR) " 4 -.el .IP "``test_nonce'' (\fB\s-1OSSL_RAND_PARAM_TEST_NONCE\s0\fR) " 4 -.IX Item "test_nonce (OSSL_RAND_PARAM_TEST_NONCE) " -Sets the bytes returned when the test generator is sent a nonce request. -Each nonce request will return all of the bytes. -.ie n .IP """generate"" (\fB\s-1OSSL_RAND_PARAM_GENERATE\s0\fR) " 4 -.el .IP "``generate'' (\fB\s-1OSSL_RAND_PARAM_GENERATE\s0\fR) " 4 -.IX Item "generate (OSSL_RAND_PARAM_GENERATE) " -If this parameter is zero, it will only emit the nonce and entropy data -supplied via the aforementioned parameters. Otherwise, low quality -non-cryptographic pseudorandom output is produced. This parameter defaults -to zero. -.SH "NOTES" -.IX Header "NOTES" -A context for a test generator can be obtained by calling: -.PP -.Vb 2 -\& EVP_RAND *rand = EVP_RAND_fetch(NULL, "TEST\-RAND", NULL); -\& EVP_RAND_CTX *rctx = EVP_RAND_CTX_new(rand, NULL); -.Ve -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.Vb 7 -\& EVP_RAND *rand; -\& EVP_RAND_CTX *rctx; -\& unsigned char bytes[100]; -\& OSSL_PARAM params[4], *p = params; -\& unsigned char entropy[1000] = { ... }; -\& unsigned char nonce[20] = { ... }; -\& unsigned int strength = 48; -\& -\& rand = EVP_RAND_fetch(NULL, "TEST\-RAND", NULL); -\& rctx = EVP_RAND_CTX_new(rand, NULL); -\& EVP_RAND_free(rand); -\& -\& *p++ = OSSL_PARAM_construct_uint(OSSL_RAND_PARAM_STRENGTH, &strength); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY, -\& entropy, sizeof(entropy)); -\& *p++ = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_NONCE, -\& nonce, sizeof(nonce)); -\& *p = OSSL_PARAM_construct_end(); -\& EVP_RAND_instantiate(rctx, strength, 0, NULL, 0, params); -\& -\& EVP_RAND_generate(rctx, bytes, sizeof(bytes), strength, 0, NULL, 0); -\& -\& EVP_RAND_CTX_free(rctx); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \s-1\fBEVP_RAND\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_RAND.7ossl b/openssl-install/share/man/man7/EVP_RAND.7ossl deleted file mode 100644 index 90ff6194..00000000 --- a/openssl-install/share/man/man7/EVP_RAND.7ossl +++ /dev/null @@ -1,407 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_RAND 7ossl" -.TH EVP_RAND 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_RAND \- the random bit generator -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The default OpenSSL \s-1RAND\s0 method is based on the \s-1EVP_RAND\s0 classes to provide -non-deterministic inputs to other cryptographic algorithms. -.PP -While the \s-1RAND API\s0 is the 'frontend' which is intended to be used by -application developers for obtaining random bytes, the \s-1EVP_RAND API\s0 -serves as the 'backend', connecting the former with the operating -systems's entropy sources and providing access to deterministic random -bit generators (\s-1DRBG\s0) and their configuration parameters. -A \s-1DRBG\s0 is a certain type of cryptographically-secure pseudo-random -number generator (\s-1CSPRNG\s0), which is described in -[\s-1NIST SP 800\-90A\s0 Rev. 1]. -.SS "Disclaimer" -.IX Subsection "Disclaimer" -Unless you have very specific requirements for your random generator, -it is in general not necessary to utilize the \s-1EVP_RAND API\s0 directly. -The usual way to obtain random bytes is to use \fBRAND_bytes\fR\|(3) or -\&\fBRAND_priv_bytes\fR\|(3), see also \s-1\fBRAND\s0\fR\|(7). -.SS "Typical Use Cases" -.IX Subsection "Typical Use Cases" -Typical examples for such special use cases are the following: -.IP "\(bu" 2 -You want to use your own private \s-1DRBG\s0 instances. -Multiple \s-1DRBG\s0 instances which are accessed only by a single thread provide -additional security (because their internal states are independent) and -better scalability in multithreaded applications (because they don't need -to be locked). -.IP "\(bu" 2 -You need to integrate a previously unsupported entropy source. -Refer to \fBprovider\-rand\fR\|(7) for the implementation details to support adding -randomness sources to \s-1EVP_RAND.\s0 -.IP "\(bu" 2 -You need to change the default settings of the standard OpenSSL \s-1RAND\s0 -implementation to meet specific requirements. -.SH "EVP_RAND CHAINING" -.IX Header "EVP_RAND CHAINING" -An \s-1EVP_RAND\s0 instance can be used as the entropy source of another -\&\s-1EVP_RAND\s0 instance, provided it has itself access to a valid entropy source. -The \s-1EVP_RAND\s0 instance which acts as entropy source is called the \fIparent\fR, -the other instance the \fIchild\fR. Typically, the child will be a \s-1DRBG\s0 because -it does not make sense for the child to be an entropy source. -.PP -This is called chaining. A chained \s-1EVP_RAND\s0 instance is created by passing -a pointer to the parent \s-1EVP_RAND_CTX\s0 as argument to the \fBEVP_RAND_CTX_new()\fR call. -It is possible to create chains of more than two \s-1DRBG\s0 in a row. -It is also possible to use any \s-1EVP_RAND_CTX\s0 class as the parent, however, only -a live entropy source may ignore and not use its parent. -.SH "THE THREE SHARED DRBG INSTANCES" -.IX Header "THE THREE SHARED DRBG INSTANCES" -Currently, there are three shared \s-1DRBG\s0 instances, -the , , and \s-1DRBG.\s0 -While the \s-1DRBG\s0 is a single global instance, the and -\&\s-1DRBG\s0 are created per thread and accessed through thread-local storage. -.PP -By default, the functions \fBRAND_bytes\fR\|(3) and \fBRAND_priv_bytes\fR\|(3) use -the thread-local and \s-1DRBG\s0 instance, respectively. -.SS "The \s-1DRBG\s0 instance" -.IX Subsection "The DRBG instance" -The \s-1DRBG\s0 is not used directly by the application, only for reseeding -the two other two \s-1DRBG\s0 instances. It reseeds itself by obtaining randomness -either from os entropy sources or by consuming randomness which was added -previously by \fBRAND_add\fR\|(3). -.SS "The \s-1DRBG\s0 instance" -.IX Subsection "The DRBG instance" -This instance is used per default by \fBRAND_bytes\fR\|(3). -.SS "The \s-1DRBG\s0 instance" -.IX Subsection "The DRBG instance" -This instance is used per default by \fBRAND_priv_bytes\fR\|(3) -.SH "LOCKING" -.IX Header "LOCKING" -The \s-1DRBG\s0 is intended to be accessed concurrently for reseeding -by its child \s-1DRBG\s0 instances. The necessary locking is done internally. -It is \fInot\fR thread-safe to access the \s-1DRBG\s0 directly via the -\&\s-1EVP_RAND\s0 interface. -The and \s-1DRBG\s0 are thread-local, i.e. there is an -instance of each per thread. So they can safely be accessed without -locking via the \s-1EVP_RAND\s0 interface. -.PP -Pointers to these \s-1DRBG\s0 instances can be obtained using -\&\fBRAND_get0_primary()\fR, \fBRAND_get0_public()\fR and \fBRAND_get0_private()\fR, respectively. -Note that it is not allowed to store a pointer to one of the thread-local -\&\s-1DRBG\s0 instances in a variable or other memory location where it will be -accessed and used by multiple threads. -.PP -All other \s-1DRBG\s0 instances created by an application don't support locking, -because they are intended to be used by a single thread. -Instead of accessing a single \s-1DRBG\s0 instance concurrently from different -threads, it is recommended to instantiate a separate \s-1DRBG\s0 instance per -thread. Using the \s-1DRBG\s0 as entropy source for multiple \s-1DRBG\s0 -instances on different threads is thread-safe, because the \s-1DRBG\s0 instance -will lock the \s-1DRBG\s0 automatically for obtaining random input. -.SH "THE OVERALL PICTURE" -.IX Header "THE OVERALL PICTURE" -The following picture gives an overview over how the \s-1DRBG\s0 instances work -together and are being used. -.PP -.Vb 10 -\& +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -\& | os entropy sources | -\& +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -\& | -\& v +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -\& RAND_add() ==> <\-| shared DRBG (with locking) | -\& / \e +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -\& / \e +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -\& <\- | per\-thread DRBG instances | -\& | | +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -\& v v -\& RAND_bytes() RAND_priv_bytes() -\& | ^ -\& | | -\& +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -\& | general purpose | | used for secrets like session keys | -\& | random generator | | and private keys for certificates | -\& +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ +\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-\-+ -.Ve -.PP -The usual way to obtain random bytes is to call RAND_bytes(...) or -RAND_priv_bytes(...). These calls are roughly equivalent to calling -EVP_RAND_generate(, ...) and -EVP_RAND_generate(, ...), -respectively. -.SH "RESEEDING" -.IX Header "RESEEDING" -A \s-1DRBG\s0 instance seeds itself automatically, pulling random input from -its entropy source. The entropy source can be either a trusted operating -system entropy source, or another \s-1DRBG\s0 with access to such a source. -.PP -Automatic reseeding occurs after a predefined number of generate requests. -The selection of the trusted entropy sources is configured at build -time using the \-\-with\-rand\-seed option. The following sections explain -the reseeding process in more detail. -.SS "Automatic Reseeding" -.IX Subsection "Automatic Reseeding" -Before satisfying a generate request (\fBEVP_RAND_generate\fR\|(3)), the \s-1DRBG\s0 -reseeds itself automatically, if one of the following conditions holds: -.PP -\&\- the \s-1DRBG\s0 was not instantiated (=seeded) yet or has been uninstantiated. -.PP -\&\- the number of generate requests since the last reseeding exceeds a -certain threshold, the so called \fIreseed_interval\fR. -This behaviour can be disabled by setting the \fIreseed_interval\fR to 0. -.PP -\&\- the time elapsed since the last reseeding exceeds a certain time -interval, the so called \fIreseed_time_interval\fR. -This can be disabled by setting the \fIreseed_time_interval\fR to 0. -.PP -\&\- the \s-1DRBG\s0 is in an error state. -.PP -\&\fBNote\fR: An error state is entered if the entropy source fails while -the \s-1DRBG\s0 is seeding or reseeding. -The last case ensures that the \s-1DRBG\s0 automatically recovers -from the error as soon as the entropy source is available again. -.SS "Manual Reseeding" -.IX Subsection "Manual Reseeding" -In addition to automatic reseeding, the caller can request an immediate -reseeding of the \s-1DRBG\s0 with fresh entropy by setting the -\&\fIprediction resistance\fR parameter to 1 when calling -\&\fBEVP_RAND_generate\fR\|(3). -.PP -The document [\s-1NIST SP 800\-90C\s0] describes prediction resistance requests -in detail and imposes strict conditions on the entropy sources that are -approved for providing prediction resistance. -A request for prediction resistance can only be satisfied by pulling fresh -entropy from a live entropy source (section 5.5.2 of [\s-1NIST SP 800\-90C\s0]). -It is up to the user to ensure that a live entropy source is configured -and is being used. -.PP -For the three shared DRBGs (and only for these) there is another way to -reseed them manually: -If \fBRAND_add\fR\|(3) is called with a positive \fIrandomness\fR argument -(or \fBRAND_seed\fR\|(3)), then this will immediately reseed the \s-1DRBG.\s0 -The and \s-1DRBG\s0 will detect this on their next generate -call and reseed, pulling randomness from . -.PP -The last feature has been added to support the common practice used with -previous OpenSSL versions to call \fBRAND_add()\fR before calling \fBRAND_bytes()\fR. -.SS "Entropy Input and Additional Data" -.IX Subsection "Entropy Input and Additional Data" -The \s-1DRBG\s0 distinguishes two different types of random input: \fIentropy\fR, -which comes from a trusted source, and \fIadditional input\fR', -which can optionally be added by the user and is considered untrusted. -It is possible to add \fIadditional input\fR not only during reseeding, -but also for every generate request. -.SS "Configuring the Random Seed Source" -.IX Subsection "Configuring the Random Seed Source" -In most cases OpenSSL will automatically choose a suitable seed source -for automatically seeding and reseeding its \s-1DRBG.\s0 The -default seed source can be configured when OpenSSL is compiled by -setting \fB\-DOPENSSL_DEFAULT_SEED_SRC=SEED\-SRC\fR. If not set then -\&\*(L"SEED-SRC\*(R" is used. One can specify a third-party provider seed-source, -or \fB\-DOPENSSL_DEFAULT_SEED_SRC=JITTER\fR if available. -.PP -In some cases however, it will be necessary to explicitly specify a -seed source used by \*(L"SEED-SRC\*(R" during configuration, using the -\&\-\-with\-rand\-seed option. For more information, see the \s-1INSTALL\s0 -instructions. There are also operating systems where no seed source is -available and automatic reseeding is disabled by default. -.PP -The following two sections describe the reseeding process of the primary -\&\s-1DRBG,\s0 depending on whether automatic reseeding is available or not. -.SS "Reseeding the primary \s-1DRBG\s0 with automatic seeding enabled" -.IX Subsection "Reseeding the primary DRBG with automatic seeding enabled" -Calling \fBRAND_poll()\fR or \fBRAND_add()\fR is not necessary, because the \s-1DRBG\s0 -pulls the necessary entropy from its source automatically. -However, both calls are permitted, and do reseed the \s-1RNG.\s0 -.PP -\&\fBRAND_add()\fR can be used to add both kinds of random input, depending on the -value of the \fIrandomness\fR argument: -.IP "randomness == 0:" 4 -.IX Item "randomness == 0:" -The random bytes are mixed as additional input into the current state of -the \s-1DRBG.\s0 -Mixing in additional input is not considered a full reseeding, hence the -reseed counter is not reset. -.IP "randomness > 0:" 4 -.IX Item "randomness > 0:" -The random bytes are used as entropy input for a full reseeding -(resp. reinstantiation) if the \s-1DRBG\s0 is instantiated -(resp. uninstantiated or in an error state). -The number of random bits required for reseeding is determined by the -security strength of the \s-1DRBG.\s0 Currently it defaults to 256 bits (32 bytes). -It is possible to provide less randomness than required. -In this case the missing randomness will be obtained by pulling random input -from the trusted entropy sources. -.PP -\&\s-1NOTE:\s0 Manual reseeding is *not allowed* in \s-1FIPS\s0 mode, because -[\s-1NIST\s0 SP\-800\-90Ar1] mandates that entropy *shall not* be provided by -the consuming application for instantiation (Section 9.1) or -reseeding (Section 9.2). For that reason, the \fIrandomness\fR -argument is ignored and the random bytes provided by the \fBRAND_add\fR\|(3) and -\&\fBRAND_seed\fR\|(3) calls are treated as additional data. -.SS "Reseeding the primary \s-1DRBG\s0 with automatic seeding disabled" -.IX Subsection "Reseeding the primary DRBG with automatic seeding disabled" -Calling \fBRAND_poll()\fR will always fail. -.PP -\&\fBRAND_add()\fR needs to be called for initial seeding and periodic reseeding. -At least 48 bytes (384 bits) of randomness have to be provided, otherwise -the (re\-)seeding of the \s-1DRBG\s0 will fail. This corresponds to one and a half -times the security strength of the \s-1DRBG.\s0 The extra half is used for the -nonce during instantiation. -.PP -More precisely, the number of bytes needed for seeding depend on the -\&\fIsecurity strength\fR of the \s-1DRBG,\s0 which is set to 256 by default. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBRAND\s0\fR\|(7), \s-1\fBEVP_RAND\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-CMAC.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-CMAC.7ossl deleted file mode 120000 index ca22fd3e..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-CMAC.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-DSA.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-DSA.7ossl deleted file mode 100644 index e86eed0f..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-DSA.7ossl +++ /dev/null @@ -1,266 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SIGNATURE-DSA 7ossl" -.TH EVP_SIGNATURE-DSA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SIGNATURE\-DSA -\&\- The EVP_PKEY DSA signature implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1DSA\s0 signatures. The signature produced with -\&\fBEVP_PKEY_sign\fR\|(3) is \s-1DER\s0 encoded \s-1ASN.1\s0 in the form described in -\&\s-1RFC 3279,\s0 section 2.2.2. -See \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7) for information related to \s-1DSA\s0 keys. -.PP -As part of \s-1FIPS 140\-3 DSA\s0 is not longer \s-1FIPS\s0 approved for key generation and -signature validation, but is still allowed for signature verification. -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -In this list, names are grouped together to signify that they are the same -algorithm having multiple names. This also includes the \s-1OID\s0 in canonical -decimal form (which means that they are possible to fetch if the caller has a -mere \s-1OID\s0 which came out in this form after a call to \fBOBJ_obj2txt\fR\|(3)). -.ie n .IP """\s-1DSA"",\s0 ""dsaEncryption"", ""1.2.840.10040.4.1""" 4 -.el .IP "``\s-1DSA'',\s0 ``dsaEncryption'', ``1.2.840.10040.4.1''" 4 -.IX Item "DSA, dsaEncryption, 1.2.840.10040.4.1" -The base signature algorithm, supported explicitly fetched with -\&\fBEVP_PKEY_sign_init_ex2\fR\|(3), and implicitly fetched (through -\&\s-1EC\s0 keys) with \fBEVP_DigestSignInit\fR\|(3) and -\&\fBEVP_DigestVerifyInit\fR\|(3). -.Sp -It can't be used with \fBEVP_PKEY_sign_message_init\fR\|(3) -.ie n .IP """\s-1DSA\-SHA1"", ""DSA\-SHA\-1"",\s0 ""dsaWithSHA1"", ""1.2.840.10040.4.3""" 4 -.el .IP "``\s-1DSA\-SHA1'', ``DSA\-SHA\-1'',\s0 ``dsaWithSHA1'', ``1.2.840.10040.4.3''" 4 -.IX Item "DSA-SHA1, DSA-SHA-1, dsaWithSHA1, 1.2.840.10040.4.3" -.PD 0 -.ie n .IP """\s-1DSA\-SHA2\-224"", ""DSA\-SHA224"",\s0 ""dsa_with_SHA224"", ""2.16.840.1.101.3.4.3.1""" 4 -.el .IP "``\s-1DSA\-SHA2\-224'', ``DSA\-SHA224'',\s0 ``dsa_with_SHA224'', ``2.16.840.1.101.3.4.3.1''" 4 -.IX Item "DSA-SHA2-224, DSA-SHA224, dsa_with_SHA224, 2.16.840.1.101.3.4.3.1" -.ie n .IP """\s-1DSA\-SHA2\-256"", ""DSA\-SHA256"",\s0 ""dsa_with_SHA256"", ""2.16.840.1.101.3.4.3.2""" 4 -.el .IP "``\s-1DSA\-SHA2\-256'', ``DSA\-SHA256'',\s0 ``dsa_with_SHA256'', ``2.16.840.1.101.3.4.3.2''" 4 -.IX Item "DSA-SHA2-256, DSA-SHA256, dsa_with_SHA256, 2.16.840.1.101.3.4.3.2" -.ie n .IP """\s-1DSA\-SHA2\-384"", ""DSA\-SHA384"",\s0 ""dsa_with_SHA384"", ""id\-dsa\-with\-sha384"", ""1.2.840.1.101.3.4.3.3""" 4 -.el .IP "``\s-1DSA\-SHA2\-384'', ``DSA\-SHA384'',\s0 ``dsa_with_SHA384'', ``id\-dsa\-with\-sha384'', ``1.2.840.1.101.3.4.3.3''" 4 -.IX Item "DSA-SHA2-384, DSA-SHA384, dsa_with_SHA384, id-dsa-with-sha384, 1.2.840.1.101.3.4.3.3" -.ie n .IP """\s-1DSA\-SHA2\-512"", ""DSA\-SHA512"",\s0 ""dsa_with_SHA512"", ""id\-dsa\-with\-sha512"", ""1.2.840.1.101.3.4.3.4""" 4 -.el .IP "``\s-1DSA\-SHA2\-512'', ``DSA\-SHA512'',\s0 ``dsa_with_SHA512'', ``id\-dsa\-with\-sha512'', ``1.2.840.1.101.3.4.3.4''" 4 -.IX Item "DSA-SHA2-512, DSA-SHA512, dsa_with_SHA512, id-dsa-with-sha512, 1.2.840.1.101.3.4.3.4" -.ie n .IP """\s-1DSA\-SHA3\-224"",\s0 ""dsa_with_SHA3\-224"", ""id\-dsa\-with\-sha3\-224"", ""2.16.840.1.101.3.4.3.5""" 4 -.el .IP "``\s-1DSA\-SHA3\-224'',\s0 ``dsa_with_SHA3\-224'', ``id\-dsa\-with\-sha3\-224'', ``2.16.840.1.101.3.4.3.5''" 4 -.IX Item "DSA-SHA3-224, dsa_with_SHA3-224, id-dsa-with-sha3-224, 2.16.840.1.101.3.4.3.5" -.ie n .IP """\s-1DSA\-SHA3\-256"",\s0 ""dsa_with_SHA3\-256"", ""id\-dsa\-with\-sha3\-256"", ""2.16.840.1.101.3.4.3.6""" 4 -.el .IP "``\s-1DSA\-SHA3\-256'',\s0 ``dsa_with_SHA3\-256'', ``id\-dsa\-with\-sha3\-256'', ``2.16.840.1.101.3.4.3.6''" 4 -.IX Item "DSA-SHA3-256, dsa_with_SHA3-256, id-dsa-with-sha3-256, 2.16.840.1.101.3.4.3.6" -.ie n .IP """\s-1DSA\-SHA3\-384"",\s0 ""dsa_with_SHA3\-384"", ""id\-dsa\-with\-sha3\-384"", ""2.16.840.1.101.3.4.3.7""" 4 -.el .IP "``\s-1DSA\-SHA3\-384'',\s0 ``dsa_with_SHA3\-384'', ``id\-dsa\-with\-sha3\-384'', ``2.16.840.1.101.3.4.3.7''" 4 -.IX Item "DSA-SHA3-384, dsa_with_SHA3-384, id-dsa-with-sha3-384, 2.16.840.1.101.3.4.3.7" -.ie n .IP """\s-1DSA\-SHA3\-512"",\s0 ""dsa_with_SHA3\-512"", ""id\-dsa\-with\-sha3\-512"", ""2.16.840.1.101.3.4.3.8""" 4 -.el .IP "``\s-1DSA\-SHA3\-512'',\s0 ``dsa_with_SHA3\-512'', ``id\-dsa\-with\-sha3\-512'', ``2.16.840.1.101.3.4.3.8''" 4 -.IX Item "DSA-SHA3-512, dsa_with_SHA3-512, id-dsa-with-sha3-512, 2.16.840.1.101.3.4.3.8" -.PD -\&\s-1DSA\s0 signature schemes with diverse message digest algorithms. They are all -supported explicitly fetched with \fBEVP_PKEY_sign_init_ex2\fR\|(3) and -\&\fBEVP_PKEY_sign_message_init\fR\|(3). -.SS "Signature Parameters" -.IX Subsection "Signature Parameters" -The following signature parameters can be set using \fBEVP_PKEY_CTX_set_params()\fR. -This may be called after \fBEVP_PKEY_sign_init()\fR or \fBEVP_PKEY_verify_init()\fR, -and before calling \fBEVP_PKEY_sign()\fR or \fBEVP_PKEY_verify()\fR. They may also be set -using \fBEVP_PKEY_sign_init_ex()\fR or \fBEVP_PKEY_verify_init_ex()\fR. -.ie n .IP """digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_SIGNATURE_PARAM_DIGEST) " -.PD 0 -.ie n .IP """properties"" (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_SIGNATURE_PARAM_PROPERTIES) " -.PD -These two are not supported with the \s-1DSA\s0 signature schemes that already -include a message digest algorithm, See \*(L"Algorithm Names\*(R" above. -.ie n .IP """nonce-type"" (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.el .IP "``nonce-type'' (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.IX Item "nonce-type (OSSL_SIGNATURE_PARAM_NONCE_TYPE) " -.PD 0 -.ie n .IP """key-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) " -.ie n .IP """digest-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) " -.ie n .IP """sign-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK\s0\fR) " 4 -.el .IP "``sign-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK\s0\fR) " 4 -.IX Item "sign-check (OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK) " -.PD -The settable parameters are described in \fBprovider\-signature\fR\|(7). -.PP -The following signature parameters can be retrieved using -\&\fBEVP_PKEY_CTX_get_params()\fR. -.ie n .IP """algorithm-id"" (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.el .IP "``algorithm-id'' (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.IX Item "algorithm-id (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_SIGNATURE_PARAM_DIGEST) " -.ie n .IP """nonce-type"" (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.el .IP "``nonce-type'' (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.IX Item "nonce-type (OSSL_SIGNATURE_PARAM_NONCE_TYPE) " -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) " -.PD -The gettable parameters are described in \fBprovider\-signature\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_params\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBprovider\-signature\fR\|(7), -.SH "HISTORY" -.IX Header "HISTORY" -\&\s-1DSA\s0 Key generation and signature generation are no longer \s-1FIPS\s0 approved in -OpenSSL 3.4. See \*(L"\s-1FIPS\s0 indicators\*(R" in \fBfips_module\fR\|(7) for more information. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-ECDSA.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-ECDSA.7ossl deleted file mode 100644 index facd152d..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-ECDSA.7ossl +++ /dev/null @@ -1,255 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SIGNATURE-ECDSA 7ossl" -.TH EVP_SIGNATURE-ECDSA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SIGNATURE\-ECDSA \- The EVP_PKEY ECDSA signature implementation. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1ECDSA\s0 signatures. -See \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) for information related to \s-1EC\s0 keys. -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -In this list, names are grouped together to signify that they are the same -algorithm having multiple names. This also includes the \s-1OID\s0 in canonical -decimal form (which means that they are possible to fetch if the caller has a -mere \s-1OID\s0 which came out in this form after a call to \fBOBJ_obj2txt\fR\|(3)). -.ie n .IP """\s-1ECDSA""\s0" 4 -.el .IP "``\s-1ECDSA''\s0" 4 -.IX Item "ECDSA" -The base signature algorithm, supported explicitly fetched with -\&\fBEVP_PKEY_sign_init_ex2\fR\|(3), and implicitly fetched (through -\&\s-1EC\s0 keys) with \fBEVP_DigestSignInit\fR\|(3) and -\&\fBEVP_DigestVerifyInit\fR\|(3). -.Sp -It can't be used with \fBEVP_PKEY_sign_message_init\fR\|(3) -.ie n .IP """\s-1ECDSA\-SHA1"", ""ECDSA\-SHA\-1"",\s0 ""ecdsa\-with\-SHA1"", ""1.2.840.10045.4.1""" 4 -.el .IP "``\s-1ECDSA\-SHA1'', ``ECDSA\-SHA\-1'',\s0 ``ecdsa\-with\-SHA1'', ``1.2.840.10045.4.1''" 4 -.IX Item "ECDSA-SHA1, ECDSA-SHA-1, ecdsa-with-SHA1, 1.2.840.10045.4.1" -.PD 0 -.ie n .IP """\s-1ECDSA\-SHA2\-224"", ""ECDSA\-SHA224"",\s0 ""ecdsa\-with\-SHA224"", ""1.2.840.10045.4.3.1""" 4 -.el .IP "``\s-1ECDSA\-SHA2\-224'', ``ECDSA\-SHA224'',\s0 ``ecdsa\-with\-SHA224'', ``1.2.840.10045.4.3.1''" 4 -.IX Item "ECDSA-SHA2-224, ECDSA-SHA224, ecdsa-with-SHA224, 1.2.840.10045.4.3.1" -.ie n .IP """\s-1ECDSA\-SHA2\-256"", ""ECDSA\-SHA256"",\s0 ""ecdsa\-with\-SHA256"", ""1.2.840.10045.4.3.2""" 4 -.el .IP "``\s-1ECDSA\-SHA2\-256'', ``ECDSA\-SHA256'',\s0 ``ecdsa\-with\-SHA256'', ``1.2.840.10045.4.3.2''" 4 -.IX Item "ECDSA-SHA2-256, ECDSA-SHA256, ecdsa-with-SHA256, 1.2.840.10045.4.3.2" -.ie n .IP """\s-1ECDSA\-SHA2\-384"", ""ECDSA\-SHA384"",\s0 ""ecdsa\-with\-SHA384"", ""1.2.840.10045.4.3.3""" 4 -.el .IP "``\s-1ECDSA\-SHA2\-384'', ``ECDSA\-SHA384'',\s0 ``ecdsa\-with\-SHA384'', ``1.2.840.10045.4.3.3''" 4 -.IX Item "ECDSA-SHA2-384, ECDSA-SHA384, ecdsa-with-SHA384, 1.2.840.10045.4.3.3" -.ie n .IP """\s-1ECDSA\-SHA2\-512"", ""ECDSA\-SHA512"",\s0 ""ecdsa\-with\-SHA512"", ""1.2.840.10045.4.3.4""" 4 -.el .IP "``\s-1ECDSA\-SHA2\-512'', ``ECDSA\-SHA512'',\s0 ``ecdsa\-with\-SHA512'', ``1.2.840.10045.4.3.4''" 4 -.IX Item "ECDSA-SHA2-512, ECDSA-SHA512, ecdsa-with-SHA512, 1.2.840.10045.4.3.4" -.ie n .IP """\s-1ECDSA\-SHA3\-224"",\s0 ""ecdsa_with_SHA3\-224"", ""id\-ecdsa\-with\-sha3\-224"", ""2.16.840.1.101.3.4.3.9""" 4 -.el .IP "``\s-1ECDSA\-SHA3\-224'',\s0 ``ecdsa_with_SHA3\-224'', ``id\-ecdsa\-with\-sha3\-224'', ``2.16.840.1.101.3.4.3.9''" 4 -.IX Item "ECDSA-SHA3-224, ecdsa_with_SHA3-224, id-ecdsa-with-sha3-224, 2.16.840.1.101.3.4.3.9" -.ie n .IP """\s-1ECDSA\-SHA3\-256"",\s0 ""ecdsa_with_SHA3\-256"", ""id\-ecdsa\-with\-sha3\-256"", ""2.16.840.1.101.3.4.3.10""" 4 -.el .IP "``\s-1ECDSA\-SHA3\-256'',\s0 ``ecdsa_with_SHA3\-256'', ``id\-ecdsa\-with\-sha3\-256'', ``2.16.840.1.101.3.4.3.10''" 4 -.IX Item "ECDSA-SHA3-256, ecdsa_with_SHA3-256, id-ecdsa-with-sha3-256, 2.16.840.1.101.3.4.3.10" -.ie n .IP """\s-1ECDSA\-SHA3\-384"",\s0 ""ecdsa_with_SHA3\-384"", ""id\-ecdsa\-with\-sha3\-384"", ""2.16.840.1.101.3.4.3.11""" 4 -.el .IP "``\s-1ECDSA\-SHA3\-384'',\s0 ``ecdsa_with_SHA3\-384'', ``id\-ecdsa\-with\-sha3\-384'', ``2.16.840.1.101.3.4.3.11''" 4 -.IX Item "ECDSA-SHA3-384, ecdsa_with_SHA3-384, id-ecdsa-with-sha3-384, 2.16.840.1.101.3.4.3.11" -.ie n .IP """\s-1ECDSA\-SHA3\-512"",\s0 ""ecdsa_with_SHA3\-512"", ""id\-ecdsa\-with\-sha3\-512"", ""2.16.840.1.101.3.4.3.12""" 4 -.el .IP "``\s-1ECDSA\-SHA3\-512'',\s0 ``ecdsa_with_SHA3\-512'', ``id\-ecdsa\-with\-sha3\-512'', ``2.16.840.1.101.3.4.3.12''" 4 -.IX Item "ECDSA-SHA3-512, ecdsa_with_SHA3-512, id-ecdsa-with-sha3-512, 2.16.840.1.101.3.4.3.12" -.PD -\&\s-1ECDSA\s0 signature schemes with diverse message digest algorithms. They are all -supported explicitly fetched with \fBEVP_PKEY_sign_init_ex2\fR\|(3) and -\&\fBEVP_PKEY_sign_message_init\fR\|(3). -.SS "\s-1ECDSA\s0 Signature Parameters" -.IX Subsection "ECDSA Signature Parameters" -The following signature parameters can be set using \fBEVP_PKEY_CTX_set_params()\fR. -This may be called after \fBEVP_PKEY_sign_init()\fR or \fBEVP_PKEY_verify_init()\fR, -and before calling \fBEVP_PKEY_sign()\fR or \fBEVP_PKEY_verify()\fR. -.ie n .IP """digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_SIGNATURE_PARAM_DIGEST) " -.PD 0 -.ie n .IP """properties"" (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_SIGNATURE_PARAM_PROPERTIES) " -.PD -These two are not supported with the \s-1ECDSA\s0 signature schemes that already -include a message digest algorithm, See \*(L"Algorithm Names\*(R" above. -.ie n .IP """nonce-type"" (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.el .IP "``nonce-type'' (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.IX Item "nonce-type (OSSL_SIGNATURE_PARAM_NONCE_TYPE) " -.PD 0 -.ie n .IP """key-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) " -.ie n .IP """digest-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) " -.PD -These parameters are described in \fBprovider\-signature\fR\|(7). -.PP -The following signature parameters can be retrieved using -\&\fBEVP_PKEY_CTX_get_params()\fR. -.ie n .IP """algorithm-id"" (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.el .IP "``algorithm-id'' (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.IX Item "algorithm-id (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_SIGNATURE_PARAM_DIGEST) " -.ie n .IP """nonce-type"" (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.el .IP "``nonce-type'' (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.IX Item "nonce-type (OSSL_SIGNATURE_PARAM_NONCE_TYPE) " -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) " -.ie n .IP """verify-message"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE\s0\fR " 4 -.el .IP "``verify-message'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE\s0\fR " 4 -.IX Item "verify-message (OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE " -.PD -The parameters are described in \fBprovider\-signature\fR\|(7). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_params\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBprovider\-signature\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-ED25519.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-ED25519.7ossl deleted file mode 100644 index 18ee2dac..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-ED25519.7ossl +++ /dev/null @@ -1,304 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SIGNATURE-ED25519 7ossl" -.TH EVP_SIGNATURE-ED25519 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SIGNATURE\-ED25519, -EVP_SIGNATURE\-ED448, -Ed25519, -Ed448 -\&\- EVP_PKEY Ed25519 and Ed448 support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBEd25519\fR and \fBEd448\fR \s-1EVP_PKEY\s0 implementation supports key -generation, one-shot digest-sign and digest-verify using the EdDSA -signature schemes described in \s-1RFC 8032.\s0 It has associated private and -public key formats compatible with \s-1RFC 8410.\s0 -.SS "EdDSA Instances" -.IX Subsection "EdDSA Instances" -\&\s-1RFC 8032\s0 describes five EdDSA instances: Ed25519, Ed25519ctx, -Ed25519ph, Ed448, Ed448ph. -.PP -The instances Ed25519, Ed25519ctx, Ed448 are referred to as \fBPureEdDSA\fR -schemes. For these three instances, the sign and verify procedures -require access to the complete message (not a digest of the message). -.PP -The instances Ed25519ph, Ed448ph are referred to as \fBHashEdDSA\fR -schemes. For these two instances, the sign and verify procedures do -not require access to the complete message; they operate on a hash of -the message. For Ed25519ph, the hash function is \s-1SHA512.\s0 For -Ed448ph, the hash function is \s-1SHAKE256\s0 with an output length of 512 -bits. -.PP -The instances Ed25519ctx, Ed25519ph, Ed448, Ed448ph accept an optional -\&\fBcontext-string\fR as input to sign and verify operations (and for -Ed25519ctx, the context-string must be nonempty). For the Ed25519 -instance, a nonempty context-string is not permitted. -.PP -These instances can be specified as signature parameters when using -\&\fBEVP_DigestSignInit\fR\|(3) and \fBEVP_DigestVerifyInit\fR\|(3), see -\&\*(L"\s-1ED25519\s0 and \s-1ED448\s0 Signature Parameters\*(R" below. -.PP -These instances are also explicitly fetchable as algorithms using -\&\fBEVP_SIGNATURE_fetch\fR\|(3), which can be used with -\&\fBEVP_PKEY_sign_init_ex2\fR\|(3), \fBEVP_PKEY_verify_init_ex2\fR\|(3), -\&\fBEVP_PKEY_sign_message_init\fR\|(3) and \fBEVP_PKEY_verify_message_init\fR\|(3). -.SS "\s-1ED25519\s0 and \s-1ED448\s0 Signature Parameters" -.IX Subsection "ED25519 and ED448 Signature Parameters" -Two parameters can be set during signing or verification: the EdDSA -\&\fBinstance name\fR and the \fBcontext-string value\fR. They can be set by -passing an \s-1OSSL_PARAM\s0 array to \fBEVP_DigestSignInit_ex()\fR. -.IP "\(bu" 4 -\&\*(L"instance\*(R" (\fB\s-1OSSL_SIGNATURE_PARAM_INSTANCE\s0\fR) -.Sp -One of the five strings \*(L"Ed25519\*(R", \*(L"Ed25519ctx\*(R", \*(L"Ed25519ph\*(R", \*(L"Ed448\*(R", \*(L"Ed448ph\*(R". -.Sp -\&\*(L"Ed25519\*(R", \*(L"Ed25519ctx\*(R", \*(L"Ed25519ph\*(R" are valid only for an Ed25519 \s-1EVP_PKEY.\s0 -.Sp -\&\*(L"Ed448\*(R", \*(L"Ed448ph\*(R" are valid only for an Ed448 \s-1EVP_PKEY.\s0 -.IP "\(bu" 4 -\&\*(L"context-string\*(R" (\fB\s-1OSSL_SIGNATURE_PARAM_CONTEXT_STRING\s0\fR) -.Sp -A string of octets with length at most 255. -.PP -Both of these parameters are optional. -.PP -When using \fBEVP_DigestSignInit\fR\|(3) or \fBEVP_DigestVerifyInit\fR\|(3), the -signature algorithm is derived from the key type name. The key type name -(\*(L"Ed25519\*(R" or \*(L"Ed448\*(R") is also the default for the instance, but this can be -changed with the \*(L"instance\*(R" parameter. -.PP -Note that a message digest name must \fB\s-1NOT\s0\fR be specified when signing -or verifying. -.PP -When using \fBEVP_PKEY_sign_init_ex2\fR\|(3), \fBEVP_PKEY_verify_init_ex2\fR\|(3), -\&\fBEVP_PKEY_sign_message_init\fR\|(3) or \fBEVP_PKEY_verify_message_init\fR\|(3), the -instance is the explicit signature algorithm name, and may not be changed -(trying to give one with the \*(L"instance\*(R" parameter is therefore an error). -.PP -If a context-string is not specified, then an empty context-string is -used. -.PP -See \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7) for information related to \fBX25519\fR and \fBX448\fR keys. -.PP -The following signature parameters can be retrieved using -\&\fBEVP_PKEY_CTX_get_params()\fR. -.IP "\(bu" 4 -\&\*(L"algorithm-id\*(R" (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) -.IP "\(bu" 4 -\&\*(L"instance\*(R" (\fB\s-1OSSL_SIGNATURE_PARAM_INSTANCE\s0\fR) -.IP "\(bu" 4 -\&\*(L"context-string\*(R" (\fB\s-1OSSL_SIGNATURE_PARAM_CONTEXT_STRING\s0\fR) -.PP -The parameters are described in \fBprovider\-signature\fR\|(7). -.SH "NOTES" -.IX Header "NOTES" -The PureEdDSA instances do not support the streaming mechanism of -other signature algorithms using, for example, \fBEVP_DigestUpdate()\fR. -The message to sign or verify must be passed using the one-shot -\&\fBEVP_DigestSign()\fR and \fBEVP_DigestVerify()\fR functions. -.PP -The HashEdDSA instances do not yet support the streaming mechanisms -(so the one-shot functions must be used with HashEdDSA as well). -.PP -When calling \fBEVP_DigestSignInit()\fR or \fBEVP_DigestVerifyInit()\fR, the -digest \fItype\fR parameter \fB\s-1MUST\s0\fR be set to \s-1NULL.\s0 -.PP -Applications wishing to sign certificates (or other structures such as -CRLs or certificate requests) using Ed25519 or Ed448 can either use \fBX509_sign()\fR -or \fBX509_sign_ctx()\fR in the usual way. -.PP -Ed25519 or Ed448 private keys can be set directly using -\&\fBEVP_PKEY_new_raw_private_key\fR\|(3) or loaded from a PKCS#8 private key file -using \fBPEM_read_bio_PrivateKey\fR\|(3) (or similar function). Completely new keys -can also be generated (see the example below). Setting a private key also sets -the associated public key. -.PP -Ed25519 or Ed448 public keys can be set directly using -\&\fBEVP_PKEY_new_raw_public_key\fR\|(3) or loaded from a SubjectPublicKeyInfo -structure in a \s-1PEM\s0 file using \fBPEM_read_bio_PUBKEY\fR\|(3) (or similar function). -.PP -Ed25519 and Ed448 can be tested with the \fBopenssl\-speed\fR\|(1) application -since version 1.1.1. -Valid algorithm names are \fBed25519\fR, \fBed448\fR and \fBeddsa\fR. If \fBeddsa\fR is -specified, then both Ed25519 and Ed448 are benchmarked. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -To sign a message using an \s-1ED25519 EVP_PKEY\s0 structure: -.PP -.Vb 5 -\& void do_sign(EVP_PKEY *ed_key, unsigned char *msg, size_t msg_len) -\& { -\& size_t sig_len; -\& unsigned char *sig = NULL; -\& EVP_MD_CTX *md_ctx = EVP_MD_CTX_new(); -\& -\& const OSSL_PARAM params[] = { -\& OSSL_PARAM_utf8_string ("instance", "Ed25519ctx", 10), -\& OSSL_PARAM_octet_string("context\-string", (unsigned char *)"A protocol defined context string", 33), -\& OSSL_PARAM_END -\& }; -\& -\& /* The input "params" is not needed if default options are acceptable. -\& Use NULL in place of "params" in that case. */ -\& EVP_DigestSignInit_ex(md_ctx, NULL, NULL, NULL, NULL, ed_key, params); -\& /* Calculate the required size for the signature by passing a NULL buffer. */ -\& EVP_DigestSign(md_ctx, NULL, &sig_len, msg, msg_len); -\& sig = OPENSSL_zalloc(sig_len); -\& -\& EVP_DigestSign(md_ctx, sig, &sig_len, msg, msg_len); -\& ... -\& OPENSSL_free(sig); -\& EVP_MD_CTX_free(md_ctx); -\& } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBEVP_PKEY\-X25519\s0\fR\|(7) -\&\fBprovider\-signature\fR\|(7), -\&\fBEVP_DigestSignInit\fR\|(3), -\&\fBEVP_DigestVerifyInit\fR\|(3), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-ED448.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-ED448.7ossl deleted file mode 120000 index 6362477e..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-ED448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE-ED25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-HMAC.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-HMAC.7ossl deleted file mode 100644 index de2d0352..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-HMAC.7ossl +++ /dev/null @@ -1,183 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SIGNATURE-HMAC 7ossl" -.TH EVP_SIGNATURE-HMAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SIGNATURE\-HMAC, EVP_SIGNATURE\-Siphash, EVP_SIGNATURE\-Poly1305, -EVP_SIGNATURE\-CMAC -\&\- The legacy EVP_PKEY MAC signature implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The algorithms described here have legacy support for creating MACs using -\&\fBEVP_DigestSignInit\fR\|(3) and related functions. This is not the preferred way of -creating MACs. Instead you should use the newer \fBEVP_MAC_init\fR\|(3) functions. -This mechanism is provided for backwards compatibility with older versions of -OpenSSL. -.PP -The same signature parameters can be set using \fBEVP_PKEY_CTX_set_params()\fR as can -be set via \fBEVP_MAC_CTX_set_params()\fR for the underlying \s-1EVP_MAC.\s0 See -\&\s-1\fBEVP_MAC\-HMAC\s0\fR\|(7), \fBEVP_MAC\-Siphash\fR\|(7), \fBEVP_MAC\-Poly1305\fR\|(7) and -\&\s-1\fBEVP_MAC\-CMAC\s0\fR\|(7) for details. -.PP -.Vb 3 -\& See L, L, L or -\& L for details about parameters that are supported during the -\& creation of an EVP_PKEY. -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_MAC_init\fR\|(3), -\&\fBEVP_DigestSignInit\fR\|(3), -\&\s-1\fBEVP_PKEY\-HMAC\s0\fR\|(7), -\&\fBEVP_PKEY\-Siphash\fR\|(7), -\&\fBEVP_PKEY\-Poly1305\fR\|(7), -\&\s-1\fBEVP_PKEY\-CMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-HMAC\s0\fR\|(7), -\&\fBEVP_MAC\-Siphash\fR\|(7), -\&\fBEVP_MAC\-Poly1305\fR\|(7), -\&\s-1\fBEVP_MAC\-CMAC\s0\fR\|(7), -\&\fBprovider\-signature\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-Poly1305.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-Poly1305.7ossl deleted file mode 120000 index ca22fd3e..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-Poly1305.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-RSA.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-RSA.7ossl deleted file mode 100644 index 1ae710e3..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-RSA.7ossl +++ /dev/null @@ -1,352 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP_SIGNATURE-RSA 7ossl" -.TH EVP_SIGNATURE-RSA 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -EVP_SIGNATURE\-RSA -\&\- The EVP_PKEY RSA signature implementation -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for computing \s-1RSA\s0 signatures. -See \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7) for information related to \s-1RSA\s0 keys. -.SS "Algorithm Names" -.IX Subsection "Algorithm Names" -In this list, names are grouped together to signify that they are the same -algorithm having multiple names. This also includes the \s-1OID\s0 in canonical -decimal form (which means that they are possible to fetch if the caller has a -mere \s-1OID\s0 which came out in this form after a call to \fBOBJ_obj2txt\fR\|(3)). -.ie n .IP """\s-1RSA"",\s0 ""rsaEncryption"", ""1.2.840.113549.1.1.1""" 4 -.el .IP "``\s-1RSA'',\s0 ``rsaEncryption'', ``1.2.840.113549.1.1.1''" 4 -.IX Item "RSA, rsaEncryption, 1.2.840.113549.1.1.1" -The base signature algorithm, supported explicitly fetched with -\&\fBEVP_PKEY_sign_init_ex2\fR\|(3), and implicitly fetched (through -\&\s-1RSA\s0 keys) with \fBEVP_DigestSignInit\fR\|(3) and -\&\fBEVP_DigestVerifyInit\fR\|(3). -.Sp -It can't be used with \fBEVP_PKEY_sign_message_init\fR\|(3) -.ie n .IP """\s-1RSA\-RIPEMD160"",\s0 ""ripemd160WithRSA"", ""1.3.36.3.3.1.2""" 4 -.el .IP "``\s-1RSA\-RIPEMD160'',\s0 ``ripemd160WithRSA'', ``1.3.36.3.3.1.2''" 4 -.IX Item "RSA-RIPEMD160, ripemd160WithRSA, 1.3.36.3.3.1.2" -.PD 0 -.ie n .IP """\s-1RSA\-SHA2\-256"", ""RSA\-SHA256"",\s0 ""sha256WithRSAEncryption"", ""1.2.840.113549.1.1.11""" 4 -.el .IP "``\s-1RSA\-SHA2\-256'', ``RSA\-SHA256'',\s0 ``sha256WithRSAEncryption'', ``1.2.840.113549.1.1.11''" 4 -.IX Item "RSA-SHA2-256, RSA-SHA256, sha256WithRSAEncryption, 1.2.840.113549.1.1.11" -.ie n .IP """\s-1RSA\-SHA2\-384"", ""RSA\-SHA384"",\s0 ""sha384WithRSAEncryption"", ""1.2.840.113549.1.1.12""" 4 -.el .IP "``\s-1RSA\-SHA2\-384'', ``RSA\-SHA384'',\s0 ``sha384WithRSAEncryption'', ``1.2.840.113549.1.1.12''" 4 -.IX Item "RSA-SHA2-384, RSA-SHA384, sha384WithRSAEncryption, 1.2.840.113549.1.1.12" -.ie n .IP """\s-1RSA\-SHA2\-512"", ""RSA\-SHA512"",\s0 ""sha512WithRSAEncryption"", ""1.2.840.113549.1.1.13""" 4 -.el .IP "``\s-1RSA\-SHA2\-512'', ``RSA\-SHA512'',\s0 ``sha512WithRSAEncryption'', ``1.2.840.113549.1.1.13''" 4 -.IX Item "RSA-SHA2-512, RSA-SHA512, sha512WithRSAEncryption, 1.2.840.113549.1.1.13" -.ie n .IP """\s-1RSA\-SHA2\-224"", ""RSA\-SHA224"",\s0 ""sha224WithRSAEncryption"", ""1.2.840.113549.1.1.14""" 4 -.el .IP "``\s-1RSA\-SHA2\-224'', ``RSA\-SHA224'',\s0 ``sha224WithRSAEncryption'', ``1.2.840.113549.1.1.14''" 4 -.IX Item "RSA-SHA2-224, RSA-SHA224, sha224WithRSAEncryption, 1.2.840.113549.1.1.14" -.ie n .IP """\s-1RSA\-SHA2\-512/224"", ""RSA\-SHA512\-224"",\s0 ""sha512\-224WithRSAEncryption"", ""1.2.840.113549.1.1.15""" 4 -.el .IP "``\s-1RSA\-SHA2\-512/224'', ``RSA\-SHA512\-224'',\s0 ``sha512\-224WithRSAEncryption'', ``1.2.840.113549.1.1.15''" 4 -.IX Item "RSA-SHA2-512/224, RSA-SHA512-224, sha512-224WithRSAEncryption, 1.2.840.113549.1.1.15" -.ie n .IP """\s-1RSA\-SHA2\-512/256"", ""RSA\-SHA512\-256"",\s0 ""sha512\-256WithRSAEncryption"", ""1.2.840.113549.1.1.16""" 4 -.el .IP "``\s-1RSA\-SHA2\-512/256'', ``RSA\-SHA512\-256'',\s0 ``sha512\-256WithRSAEncryption'', ``1.2.840.113549.1.1.16''" 4 -.IX Item "RSA-SHA2-512/256, RSA-SHA512-256, sha512-256WithRSAEncryption, 1.2.840.113549.1.1.16" -.ie n .IP """\s-1RSA\-SHA3\-224"",\s0 ""id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-224"", ""2.16.840.1.101.3.4.3.13""" 4 -.el .IP "``\s-1RSA\-SHA3\-224'',\s0 ``id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-224'', ``2.16.840.1.101.3.4.3.13''" 4 -.IX Item "RSA-SHA3-224, id-rsassa-pkcs1-v1_5-with-sha3-224, 2.16.840.1.101.3.4.3.13" -.ie n .IP """\s-1RSA\-SHA3\-256"",\s0 ""id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-256"", ""2.16.840.1.101.3.4.3.14""" 4 -.el .IP "``\s-1RSA\-SHA3\-256'',\s0 ``id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-256'', ``2.16.840.1.101.3.4.3.14''" 4 -.IX Item "RSA-SHA3-256, id-rsassa-pkcs1-v1_5-with-sha3-256, 2.16.840.1.101.3.4.3.14" -.ie n .IP """\s-1RSA\-SHA3\-384"",\s0 ""id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-384"", ""2.16.840.1.101.3.4.3.15""" 4 -.el .IP "``\s-1RSA\-SHA3\-384'',\s0 ``id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-384'', ``2.16.840.1.101.3.4.3.15''" 4 -.IX Item "RSA-SHA3-384, id-rsassa-pkcs1-v1_5-with-sha3-384, 2.16.840.1.101.3.4.3.15" -.ie n .IP """\s-1RSA\-SHA3\-512"",\s0 ""id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-512"", ""2.16.840.1.101.3.4.3.16""" 4 -.el .IP "``\s-1RSA\-SHA3\-512'',\s0 ``id\-rsassa\-pkcs1\-v1_5\-with\-sha3\-512'', ``2.16.840.1.101.3.4.3.16''" 4 -.IX Item "RSA-SHA3-512, id-rsassa-pkcs1-v1_5-with-sha3-512, 2.16.840.1.101.3.4.3.16" -.ie n .IP """\s-1RSA\-SM3"",\s0 ""sm3WithRSAEncryption"", ""1.2.156.10197.1.504""" 4 -.el .IP "``\s-1RSA\-SM3'',\s0 ``sm3WithRSAEncryption'', ``1.2.156.10197.1.504''" 4 -.IX Item "RSA-SM3, sm3WithRSAEncryption, 1.2.156.10197.1.504" -.PD -PKCS#1 v1.5 \s-1RSA\s0 signature schemes with diverse message digest algorithms. They -are all supported explicitly fetched with \fBEVP_PKEY_sign_init_ex2\fR\|(3) and -\&\fBEVP_PKEY_sign_message_init\fR\|(3). -They are all pre-set to use the pad mode \*(L"pkcs1\*(R". This cannot be changed. -.SS "Signature Parameters" -.IX Subsection "Signature Parameters" -The following signature parameters can be set using \fBEVP_PKEY_CTX_set_params()\fR. -This may be called after \fBEVP_PKEY_sign_init()\fR or \fBEVP_PKEY_verify_init()\fR, -and before calling \fBEVP_PKEY_sign()\fR or \fBEVP_PKEY_verify()\fR. They may also be set -using \fBEVP_PKEY_sign_init_ex()\fR or \fBEVP_PKEY_verify_init_ex()\fR. -.ie n .IP """digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_SIGNATURE_PARAM_DIGEST) " -.PD 0 -.ie n .IP """properties"" (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_SIGNATURE_PARAM_PROPERTIES) " -.PD -These are not supported with the \s-1RSA\s0 signature schemes that already include a -message digest algorithm, See \*(L"Algorithm Names\*(R" above. -.Sp -These common parameters are described in \fBprovider\-signature\fR\|(7). -.ie n .IP """pad-mode"" (\fB\s-1OSSL_SIGNATURE_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``pad-mode'' (\fB\s-1OSSL_SIGNATURE_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "pad-mode (OSSL_SIGNATURE_PARAM_PAD_MODE) " -The type of padding to be used. Its value can be one of the following: -.RS 4 -.ie n .IP """none"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_NONE\s0\fR)" 4 -.el .IP "``none'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_NONE\s0\fR)" 4 -.IX Item "none (OSSL_PKEY_RSA_PAD_MODE_NONE)" -.PD 0 -.ie n .IP """pkcs1"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_PKCSV15\s0\fR)" 4 -.el .IP "``pkcs1'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_PKCSV15\s0\fR)" 4 -.IX Item "pkcs1 (OSSL_PKEY_RSA_PAD_MODE_PKCSV15)" -.ie n .IP """x931"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_X931\s0\fR)" 4 -.el .IP "``x931'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_X931\s0\fR)" 4 -.IX Item "x931 (OSSL_PKEY_RSA_PAD_MODE_X931)" -.PD -This padding mode is no longer supported by the \s-1FIPS\s0 provider for signature -generation, but may be used for signature verification for legacy use cases. -(This is a \s-1FIPS 140\-3\s0 requirement) -.ie n .IP """pss"" (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_PSS\s0\fR)" 4 -.el .IP "``pss'' (\fB\s-1OSSL_PKEY_RSA_PAD_MODE_PSS\s0\fR)" 4 -.IX Item "pss (OSSL_PKEY_RSA_PAD_MODE_PSS)" -.RE -.RS 4 -.RE -.PD 0 -.ie n .IP """mgf1\-digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mgf1\-digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mgf1-digest (OSSL_SIGNATURE_PARAM_MGF1_DIGEST) " -.PD -The digest algorithm name to use for the maskGenAlgorithm used by \*(L"pss\*(R" mode. -.ie n .IP """mgf1\-properties"" (\fB\s-1OSSL_SIGNATURE_PARAM_MGF1_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mgf1\-properties'' (\fB\s-1OSSL_SIGNATURE_PARAM_MGF1_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mgf1-properties (OSSL_SIGNATURE_PARAM_MGF1_PROPERTIES) " -Sets the name of the property query associated with the \*(L"mgf1\-digest\*(R" algorithm. -\&\s-1NULL\s0 is used if this optional value is not set. -.ie n .IP """saltlen"" (\fB\s-1OSSL_SIGNATURE_PARAM_PSS_SALTLEN\s0\fR) or <\s-1UTF8\s0 string>" 4 -.el .IP "``saltlen'' (\fB\s-1OSSL_SIGNATURE_PARAM_PSS_SALTLEN\s0\fR) or <\s-1UTF8\s0 string>" 4 -.IX Item "saltlen (OSSL_SIGNATURE_PARAM_PSS_SALTLEN) or " -The \*(L"pss\*(R" mode minimum salt length. The value can either be an integer, -a string value representing a number or one of the following string values: -.RS 4 -.ie n .IP """digest"" (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_DIGEST\s0\fR)" 4 -.el .IP "``digest'' (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_DIGEST\s0\fR)" 4 -.IX Item "digest (OSSL_PKEY_RSA_PSS_SALT_LEN_DIGEST)" -Use the same length as the digest size. -.ie n .IP """max"" (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_MAX\s0\fR)" 4 -.el .IP "``max'' (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_MAX\s0\fR)" 4 -.IX Item "max (OSSL_PKEY_RSA_PSS_SALT_LEN_MAX)" -Use the maximum salt length. -.ie n .IP """auto"" (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO\s0\fR)" 4 -.el .IP "``auto'' (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO\s0\fR)" 4 -.IX Item "auto (OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO)" -Auto detect the salt length. -.ie n .IP """auto-digestmax"" (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO_DIGEST_MAX\s0\fR)" 4 -.el .IP "``auto-digestmax'' (\fB\s-1OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO_DIGEST_MAX\s0\fR)" 4 -.IX Item "auto-digestmax (OSSL_PKEY_RSA_PSS_SALT_LEN_AUTO_DIGEST_MAX)" -Auto detect the salt length when verifying. Maximize the salt length up to the -digest size when signing to comply with \s-1FIPS 186\-4\s0 section 5.5. -.RE -.RS 4 -.RE -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """key-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) " -.PD 0 -.ie n .IP """digest-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) " -.ie n .IP """sign\-x931\-pad\-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK\s0\fR) " 4 -.el .IP "``sign\-x931\-pad\-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK\s0\fR) " 4 -.IX Item "sign-x931-pad-check (OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK) " -.PD -These parameters are described in \fBprovider\-signature\fR\|(7). -.ie n .IP """rsa-pss-saltlen-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_RSA_PSS_SALTLEN_CHECK\s0\fR) " 4 -.el .IP "``rsa-pss-saltlen-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_RSA_PSS_SALTLEN_CHECK\s0\fR) " 4 -.IX Item "rsa-pss-saltlen-check (OSSL_SIGNATURE_PARAM_FIPS_RSA_PSS_SALTLEN_CHECK) " -The default value of 1 causes an error during signature generation or -verification if salt length (\fB\s-1OSSL_SIGNATURE_PARAM_PSS_SALTLEN\s0\fR) is not between -zero and the output block size of the digest function (inclusive). -Setting this to zero will ignore the error and set the approved \*(L"fips-indicator\*(R" -to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.PP -The following signature parameters can be retrieved using -\&\fBEVP_PKEY_CTX_get_params()\fR. -.ie n .IP """algorithm-id"" (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.el .IP "``algorithm-id'' (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.IX Item "algorithm-id (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) " -.PD 0 -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) " -.ie n .IP """verify-message"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE\s0\fR " 4 -.el .IP "``verify-message'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE\s0\fR " 4 -.IX Item "verify-message (OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE " -.PD -These common parameter are described in \fBprovider\-signature\fR\|(7). -.ie n .IP """digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_SIGNATURE_PARAM_DIGEST) " -.PD 0 -.ie n .IP """pad-mode"" (\fB\s-1OSSL_SIGNATURE_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``pad-mode'' (\fB\s-1OSSL_SIGNATURE_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "pad-mode (OSSL_SIGNATURE_PARAM_PAD_MODE) " -.ie n .IP """mgf1\-digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mgf1\-digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mgf1-digest (OSSL_SIGNATURE_PARAM_MGF1_DIGEST) " -.ie n .IP """saltlen"" (\fB\s-1OSSL_SIGNATURE_PARAM_PSS_SALTLEN\s0\fR) or <\s-1UTF8\s0 string>" 4 -.el .IP "``saltlen'' (\fB\s-1OSSL_SIGNATURE_PARAM_PSS_SALTLEN\s0\fR) or <\s-1UTF8\s0 string>" 4 -.IX Item "saltlen (OSSL_SIGNATURE_PARAM_PSS_SALTLEN) or " -.PD -These parameters are as described above. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_params\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBprovider\-signature\fR\|(7), -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/EVP_SIGNATURE-Siphash.7ossl b/openssl-install/share/man/man7/EVP_SIGNATURE-Siphash.7ossl deleted file mode 120000 index ca22fd3e..00000000 --- a/openssl-install/share/man/man7/EVP_SIGNATURE-Siphash.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE-HMAC.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/Ed25519.7ossl b/openssl-install/share/man/man7/Ed25519.7ossl deleted file mode 120000 index 6362477e..00000000 --- a/openssl-install/share/man/man7/Ed25519.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE-ED25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/Ed448.7ossl b/openssl-install/share/man/man7/Ed448.7ossl deleted file mode 120000 index 6362477e..00000000 --- a/openssl-install/share/man/man7/Ed448.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_SIGNATURE-ED25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/OPENSSL_API_COMPAT.7ossl b/openssl-install/share/man/man7/OPENSSL_API_COMPAT.7ossl deleted file mode 120000 index 39eebebe..00000000 --- a/openssl-install/share/man/man7/OPENSSL_API_COMPAT.7ossl +++ /dev/null @@ -1 +0,0 @@ -openssl_user_macros.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/OPENSSL_NO_DEPRECATED.7ossl b/openssl-install/share/man/man7/OPENSSL_NO_DEPRECATED.7ossl deleted file mode 120000 index 39eebebe..00000000 --- a/openssl-install/share/man/man7/OPENSSL_NO_DEPRECATED.7ossl +++ /dev/null @@ -1 +0,0 @@ -openssl_user_macros.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/OSSL_PROVIDER-FIPS.7ossl b/openssl-install/share/man/man7/OSSL_PROVIDER-FIPS.7ossl deleted file mode 100644 index b2372ecf..00000000 --- a/openssl-install/share/man/man7/OSSL_PROVIDER-FIPS.7ossl +++ /dev/null @@ -1,665 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PROVIDER-FIPS 7ossl" -.TH OSSL_PROVIDER-FIPS 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PROVIDER\-FIPS \- OpenSSL FIPS provider -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The OpenSSL \s-1FIPS\s0 provider is a special provider that conforms to the Federal -Information Processing Standards (\s-1FIPS\s0) specified in \s-1FIPS 140\-3.\s0 This 'module' -contains an approved set of cryptographic algorithms that is validated by an -accredited testing laboratory. -.SS "Properties" -.IX Subsection "Properties" -The implementations in this provider specifically have these properties -defined: -.ie n .IP """provider=fips""" 4 -.el .IP "``provider=fips''" 4 -.IX Item "provider=fips" -.PD 0 -.ie n .IP """fips=yes""" 4 -.el .IP "``fips=yes''" 4 -.IX Item "fips=yes" -.PD -.PP -It may be used in a property query string with fetching functions such as -\&\fBEVP_MD_fetch\fR\|(3) or \fBEVP_CIPHER_fetch\fR\|(3), as well as with other -functions that take a property query string, such as -\&\fBEVP_PKEY_CTX_new_from_name\fR\|(3). -.PP -To be \s-1FIPS\s0 compliant, it is mandatory to include \f(CW\*(C`fips=yes\*(C'\fR as -part of all property queries. This ensures that only \s-1FIPS\s0 approved -implementations are used for cryptographic operations. The \f(CW\*(C`fips=yes\*(C'\fR -query may also include other non-crypto support operations that -are not in the \s-1FIPS\s0 provider, such as asymmetric key encoders, see -\&\*(L"Asymmetric Key Management\*(R" in \fBOSSL_PROVIDER\-default\fR\|(7). -.PP -It is not mandatory to include \f(CW\*(C`provider=fips\*(C'\fR as part of your property -query. Including \f(CW\*(C`provider=fips\*(C'\fR in your property query guarantees -that the OpenSSL \s-1FIPS\s0 provider is used for cryptographic operations -rather than other \s-1FIPS\s0 capable providers. -.SS "Provider parameters" -.IX Subsection "Provider parameters" -See \*(L"Provider parameters\*(R" in \fBprovider\-base\fR\|(7) for a list of base parameters. -Additionally the OpenSSL \s-1FIPS\s0 provider also supports the following gettable -parameters: -.ie n .IP """security-checks"" (\fB\s-1OSSL_OSSL_PROV_PARAM_SECURITY_CHECKS\s0\fR) " 4 -.el .IP "``security-checks'' (\fB\s-1OSSL_OSSL_PROV_PARAM_SECURITY_CHECKS\s0\fR) " 4 -.IX Item "security-checks (OSSL_OSSL_PROV_PARAM_SECURITY_CHECKS) " -For further information refer to the \fBopenssl\-fipsinstall\fR\|(1) option -\&\fB\-no_security_checks\fR. -.SH "OPERATIONS AND ALGORITHMS" -.IX Header "OPERATIONS AND ALGORITHMS" -The OpenSSL \s-1FIPS\s0 provider supports these operations and algorithms: -.SS "Hashing Algorithms / Message Digests" -.IX Subsection "Hashing Algorithms / Message Digests" -.IP "\s-1SHA1,\s0 see \s-1\fBEVP_MD\-SHA1\s0\fR\|(7)" 4 -.IX Item "SHA1, see EVP_MD-SHA1" -.PD 0 -.IP "\s-1SHA2,\s0 see \s-1\fBEVP_MD\-SHA2\s0\fR\|(7)" 4 -.IX Item "SHA2, see EVP_MD-SHA2" -.IP "\s-1SHA3,\s0 see \s-1\fBEVP_MD\-SHA3\s0\fR\|(7)" 4 -.IX Item "SHA3, see EVP_MD-SHA3" -.IP "KECCAK-KMAC, see \s-1\fBEVP_MD\-KECCAK\-KMAC\s0\fR\|(7)" 4 -.IX Item "KECCAK-KMAC, see EVP_MD-KECCAK-KMAC" -.IP "\s-1SHAKE,\s0 see \s-1\fBEVP_MD\-SHAKE\s0\fR\|(7)" 4 -.IX Item "SHAKE, see EVP_MD-SHAKE" -.PD -.SS "Symmetric Ciphers" -.IX Subsection "Symmetric Ciphers" -.IP "\s-1AES,\s0 see \s-1\fBEVP_CIPHER\-AES\s0\fR\|(7)" 4 -.IX Item "AES, see EVP_CIPHER-AES" -.PD 0 -.IP "3DES, see \s-1\fBEVP_CIPHER\-DES\s0\fR\|(7)" 4 -.IX Item "3DES, see EVP_CIPHER-DES" -.PD -This is an unapproved algorithm. -.SS "Message Authentication Code (\s-1MAC\s0)" -.IX Subsection "Message Authentication Code (MAC)" -.IP "\s-1CMAC,\s0 see \s-1\fBEVP_MAC\-CMAC\s0\fR\|(7)" 4 -.IX Item "CMAC, see EVP_MAC-CMAC" -.PD 0 -.IP "\s-1GMAC,\s0 see \s-1\fBEVP_MAC\-GMAC\s0\fR\|(7)" 4 -.IX Item "GMAC, see EVP_MAC-GMAC" -.IP "\s-1HMAC,\s0 see \s-1\fBEVP_MAC\-HMAC\s0\fR\|(7)" 4 -.IX Item "HMAC, see EVP_MAC-HMAC" -.IP "\s-1KMAC,\s0 see \s-1\fBEVP_MAC\-KMAC\s0\fR\|(7)" 4 -.IX Item "KMAC, see EVP_MAC-KMAC" -.PD -.SS "Key Derivation Function (\s-1KDF\s0)" -.IX Subsection "Key Derivation Function (KDF)" -.IP "\s-1HKDF,\s0 see \s-1\fBEVP_KDF\-HKDF\s0\fR\|(7)" 4 -.IX Item "HKDF, see EVP_KDF-HKDF" -.PD 0 -.IP "\s-1TLS13\-KDF,\s0 see \s-1\fBEVP_KDF\-TLS13_KDF\s0\fR\|(7)" 4 -.IX Item "TLS13-KDF, see EVP_KDF-TLS13_KDF" -.IP "\s-1SSKDF,\s0 see \s-1\fBEVP_KDF\-SS\s0\fR\|(7)" 4 -.IX Item "SSKDF, see EVP_KDF-SS" -.IP "\s-1PBKDF2,\s0 see \s-1\fBEVP_KDF\-PBKDF2\s0\fR\|(7)" 4 -.IX Item "PBKDF2, see EVP_KDF-PBKDF2" -.IP "\s-1SSHKDF,\s0 see \s-1\fBEVP_KDF\-SSHKDF\s0\fR\|(7)" 4 -.IX Item "SSHKDF, see EVP_KDF-SSHKDF" -.IP "\s-1TLS1\-PRF,\s0 see \s-1\fBEVP_KDF\-TLS1_PRF\s0\fR\|(7)" 4 -.IX Item "TLS1-PRF, see EVP_KDF-TLS1_PRF" -.IP "\s-1KBKDF,\s0 see \s-1\fBEVP_KDF\-KB\s0\fR\|(7)" 4 -.IX Item "KBKDF, see EVP_KDF-KB" -.IP "X942KDF\-ASN1, see \s-1\fBEVP_KDF\-X942\-ASN1\s0\fR\|(7)" 4 -.IX Item "X942KDF-ASN1, see EVP_KDF-X942-ASN1" -.IP "X942KDF\-CONCAT, see \s-1\fBEVP_KDF\-X942\-CONCAT\s0\fR\|(7)" 4 -.IX Item "X942KDF-CONCAT, see EVP_KDF-X942-CONCAT" -.IP "X963KDF, see \s-1\fBEVP_KDF\-X963\s0\fR\|(7)" 4 -.IX Item "X963KDF, see EVP_KDF-X963" -.PD -.SS "Key Exchange" -.IX Subsection "Key Exchange" -.IP "\s-1DH,\s0 see \s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7)" 4 -.IX Item "DH, see EVP_KEYEXCH-DH" -.PD 0 -.IP "\s-1ECDH,\s0 see \s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7)" 4 -.IX Item "ECDH, see EVP_KEYEXCH-ECDH" -.IP "X25519, see \s-1\fBEVP_KEYEXCH\-X25519\s0\fR\|(7)" 4 -.IX Item "X25519, see EVP_KEYEXCH-X25519" -.IP "X448, see \s-1\fBEVP_KEYEXCH\-X448\s0\fR\|(7)" 4 -.IX Item "X448, see EVP_KEYEXCH-X448" -.IP "\s-1TLS1\-PRF\s0" 4 -.IX Item "TLS1-PRF" -.IP "\s-1HKDF\s0" 4 -.IX Item "HKDF" -.PD -.SS "Asymmetric Signature" -.IX Subsection "Asymmetric Signature" -.IP "\s-1RSA,\s0 see \s-1\fBEVP_SIGNATURE\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_SIGNATURE-RSA" -The \fBX931\fR padding mode \*(L"\s-1OSSL_PKEY_RSA_PAD_MODE_X931\*(R"\s0 is no longer supported -for signature generation, but may be used for verification for legacy use cases. -(This is a \s-1FIPS 140\-3\s0 requirement) -.IP "\s-1DSA,\s0 see \s-1\fBEVP_SIGNATURE\-DSA\s0\fR\|(7)" 4 -.IX Item "DSA, see EVP_SIGNATURE-DSA" -.PD 0 -.IP "\s-1ED25519,\s0 see \s-1\fBEVP_SIGNATURE\-ED25519\s0\fR\|(7)" 4 -.IX Item "ED25519, see EVP_SIGNATURE-ED25519" -.IP "\s-1ED448,\s0 see \s-1\fBEVP_SIGNATURE\-ED448\s0\fR\|(7)" 4 -.IX Item "ED448, see EVP_SIGNATURE-ED448" -.IP "\s-1ECDSA,\s0 see \s-1\fBEVP_SIGNATURE\-ECDSA\s0\fR\|(7)" 4 -.IX Item "ECDSA, see EVP_SIGNATURE-ECDSA" -.IP "\s-1HMAC,\s0 see \s-1\fBEVP_SIGNATURE\-HMAC\s0\fR\|(7)" 4 -.IX Item "HMAC, see EVP_SIGNATURE-HMAC" -.IP "\s-1CMAC,\s0 see \s-1\fBEVP_SIGNATURE\-CMAC\s0\fR\|(7)" 4 -.IX Item "CMAC, see EVP_SIGNATURE-CMAC" -.PD -.SS "Asymmetric Cipher" -.IX Subsection "Asymmetric Cipher" -.IP "\s-1RSA,\s0 see \s-1\fBEVP_ASYM_CIPHER\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_ASYM_CIPHER-RSA" -.SS "Asymmetric Key Encapsulation" -.IX Subsection "Asymmetric Key Encapsulation" -.PD 0 -.IP "\s-1RSA,\s0 see \s-1\fBEVP_KEM\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_KEM-RSA" -.PD -.SS "Asymmetric Key Management" -.IX Subsection "Asymmetric Key Management" -.IP "\s-1DH,\s0 see \s-1\fBEVP_KEYMGMT\-DH\s0\fR\|(7)" 4 -.IX Item "DH, see EVP_KEYMGMT-DH" -.PD 0 -.IP "\s-1DHX,\s0 see \s-1\fBEVP_KEYMGMT\-DHX\s0\fR\|(7)" 4 -.IX Item "DHX, see EVP_KEYMGMT-DHX" -.IP "\s-1DSA,\s0 see \s-1\fBEVP_KEYMGMT\-DSA\s0\fR\|(7)" 4 -.IX Item "DSA, see EVP_KEYMGMT-DSA" -.IP "\s-1RSA,\s0 see \s-1\fBEVP_KEYMGMT\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_KEYMGMT-RSA" -.IP "RSA-PSS" 4 -.IX Item "RSA-PSS" -.IP "\s-1EC,\s0 see \s-1\fBEVP_KEYMGMT\-EC\s0\fR\|(7)" 4 -.IX Item "EC, see EVP_KEYMGMT-EC" -.IP "X25519, see \s-1\fBEVP_KEYMGMT\-X25519\s0\fR\|(7)" 4 -.IX Item "X25519, see EVP_KEYMGMT-X25519" -.PD -This is an unapproved algorithm. -.IP "X448, see \s-1\fBEVP_KEYMGMT\-X448\s0\fR\|(7)" 4 -.IX Item "X448, see EVP_KEYMGMT-X448" -This is an unapproved algorithm. -.IP "\s-1ED25519,\s0 see \s-1\fBEVP_KEYMGMT\-ED25519\s0\fR\|(7)" 4 -.IX Item "ED25519, see EVP_KEYMGMT-ED25519" -This is an unapproved algorithm. -.IP "\s-1ED448,\s0 see \s-1\fBEVP_KEYMGMT\-ED448\s0\fR\|(7)" 4 -.IX Item "ED448, see EVP_KEYMGMT-ED448" -This is an unapproved algorithm. -.IP "\s-1TLS1\-PRF\s0" 4 -.IX Item "TLS1-PRF" -.PD 0 -.IP "\s-1HKDF\s0" 4 -.IX Item "HKDF" -.IP "\s-1HMAC,\s0 see \s-1\fBEVP_KEYMGMT\-HMAC\s0\fR\|(7)" 4 -.IX Item "HMAC, see EVP_KEYMGMT-HMAC" -.IP "\s-1CMAC,\s0 see \s-1\fBEVP_KEYMGMT\-CMAC\s0\fR\|(7)" 4 -.IX Item "CMAC, see EVP_KEYMGMT-CMAC" -.PD -.SS "Random Number Generation" -.IX Subsection "Random Number Generation" -.IP "CRNG-TEST, see \s-1\fBEVP_RAND\-CRNG\-TEST\s0\fR\|(7)" 4 -.IX Item "CRNG-TEST, see EVP_RAND-CRNG-TEST" -.PD 0 -.IP "CTR-DRBG, see \s-1\fBEVP_RAND\-CTR\-DRBG\s0\fR\|(7)" 4 -.IX Item "CTR-DRBG, see EVP_RAND-CTR-DRBG" -.IP "HASH-DRBG, see \s-1\fBEVP_RAND\-HASH\-DRBG\s0\fR\|(7)" 4 -.IX Item "HASH-DRBG, see EVP_RAND-HASH-DRBG" -.IP "HMAC-DRBG, see \s-1\fBEVP_RAND\-HMAC\-DRBG\s0\fR\|(7)" 4 -.IX Item "HMAC-DRBG, see EVP_RAND-HMAC-DRBG" -.IP "TEST-RAND, see \s-1\fBEVP_RAND\-TEST\-RAND\s0\fR\|(7)" 4 -.IX Item "TEST-RAND, see EVP_RAND-TEST-RAND" -.PD -TEST-RAND is an unapproved algorithm. -.SH "SELF TESTING" -.IX Header "SELF TESTING" -One of the requirements for the \s-1FIPS\s0 module is self testing. An optional callback -mechanism is available to return information to the user using -\&\fBOSSL_SELF_TEST_set_callback\fR\|(3). -.PP -The parameters passed to the callback are described in \fBOSSL_SELF_TEST_new\fR\|(3) -.PP -The OpenSSL \s-1FIPS\s0 module uses the following mechanism to provide information -about the self tests as they run. -This is useful for debugging if a self test is failing. -The callback also allows forcing any self test to fail, in order to check that -it operates correctly on failure. -Note that all self tests run even if a self test failure occurs. -.PP -The \s-1FIPS\s0 module passes the following type(s) to \fBOSSL_SELF_TEST_onbegin()\fR. -.ie n .IP """Module_Integrity"" (\fB\s-1OSSL_SELF_TEST_TYPE_MODULE_INTEGRITY\s0\fR)" 4 -.el .IP "``Module_Integrity'' (\fB\s-1OSSL_SELF_TEST_TYPE_MODULE_INTEGRITY\s0\fR)" 4 -.IX Item "Module_Integrity (OSSL_SELF_TEST_TYPE_MODULE_INTEGRITY)" -Uses \s-1HMAC SHA256\s0 on the module file to validate that the module has not been -modified. The integrity value is compared to a value written to a configuration -file during installation. -.ie n .IP """Install_Integrity"" (\fB\s-1OSSL_SELF_TEST_TYPE_INSTALL_INTEGRITY\s0\fR)" 4 -.el .IP "``Install_Integrity'' (\fB\s-1OSSL_SELF_TEST_TYPE_INSTALL_INTEGRITY\s0\fR)" 4 -.IX Item "Install_Integrity (OSSL_SELF_TEST_TYPE_INSTALL_INTEGRITY)" -Uses \s-1HMAC SHA256\s0 on a fixed string to validate that the installation process -has already been performed and the self test \s-1KATS\s0 have already been tested, -The integrity value is compared to a value written to a configuration -file after successfully running the self tests during installation. -.ie n .IP """KAT_Cipher"" (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_CIPHER\s0\fR)" 4 -.el .IP "``KAT_Cipher'' (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_CIPHER\s0\fR)" 4 -.IX Item "KAT_Cipher (OSSL_SELF_TEST_TYPE_KAT_CIPHER)" -Known answer test for a symmetric cipher. -.ie n .IP """KAT_AsymmetricCipher"" (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_ASYM_CIPHER\s0\fR)" 4 -.el .IP "``KAT_AsymmetricCipher'' (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_ASYM_CIPHER\s0\fR)" 4 -.IX Item "KAT_AsymmetricCipher (OSSL_SELF_TEST_TYPE_KAT_ASYM_CIPHER)" -Known answer test for a asymmetric cipher. -.ie n .IP """KAT_Digest"" (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_DIGEST\s0\fR)" 4 -.el .IP "``KAT_Digest'' (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_DIGEST\s0\fR)" 4 -.IX Item "KAT_Digest (OSSL_SELF_TEST_TYPE_KAT_DIGEST)" -Known answer test for a digest. -.ie n .IP """KAT_Signature"" (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_SIGNATURE\s0\fR)" 4 -.el .IP "``KAT_Signature'' (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_SIGNATURE\s0\fR)" 4 -.IX Item "KAT_Signature (OSSL_SELF_TEST_TYPE_KAT_SIGNATURE)" -Known answer test for a signature. -.ie n .IP """PCT_Signature"" (\fB\s-1OSSL_SELF_TEST_TYPE_PCT_SIGNATURE\s0\fR)" 4 -.el .IP "``PCT_Signature'' (\fB\s-1OSSL_SELF_TEST_TYPE_PCT_SIGNATURE\s0\fR)" 4 -.IX Item "PCT_Signature (OSSL_SELF_TEST_TYPE_PCT_SIGNATURE)" -Pairwise Consistency check for a signature. -.ie n .IP """\s-1KAT_KDF""\s0 (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_KDF\s0\fR)" 4 -.el .IP "``\s-1KAT_KDF''\s0 (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_KDF\s0\fR)" 4 -.IX Item "KAT_KDF (OSSL_SELF_TEST_TYPE_KAT_KDF)" -Known answer test for a key derivation function. -.ie n .IP """\s-1KAT_KA""\s0 (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_KA\s0\fR)" 4 -.el .IP "``\s-1KAT_KA''\s0 (\fB\s-1OSSL_SELF_TEST_TYPE_KAT_KA\s0\fR)" 4 -.IX Item "KAT_KA (OSSL_SELF_TEST_TYPE_KAT_KA)" -Known answer test for key agreement. -.ie n .IP """\s-1DRBG""\s0 (\fB\s-1OSSL_SELF_TEST_TYPE_DRBG\s0\fR)" 4 -.el .IP "``\s-1DRBG''\s0 (\fB\s-1OSSL_SELF_TEST_TYPE_DRBG\s0\fR)" 4 -.IX Item "DRBG (OSSL_SELF_TEST_TYPE_DRBG)" -Known answer test for a Deterministic Random Bit Generator. -.ie n .IP """Conditional_PCT"" (\fB\s-1OSSL_SELF_TEST_TYPE_PCT\s0\fR)" 4 -.el .IP "``Conditional_PCT'' (\fB\s-1OSSL_SELF_TEST_TYPE_PCT\s0\fR)" 4 -.IX Item "Conditional_PCT (OSSL_SELF_TEST_TYPE_PCT)" -Conditional test that is run during the generation of key pairs. -.ie n .IP """Continuous_RNG_Test"" (\fB\s-1OSSL_SELF_TEST_TYPE_CRNG\s0\fR)" 4 -.el .IP "``Continuous_RNG_Test'' (\fB\s-1OSSL_SELF_TEST_TYPE_CRNG\s0\fR)" 4 -.IX Item "Continuous_RNG_Test (OSSL_SELF_TEST_TYPE_CRNG)" -Continuous random number generator test. -.PP -The \*(L"Module_Integrity\*(R" self test is always run at startup. -The \*(L"Install_Integrity\*(R" self test is used to check if the self tests have -already been run at installation time. If they have already run then the -self tests are not run on subsequent startups. -All other self test categories are run once at installation time, except for the -\&\*(L"Pairwise_Consistency_Test\*(R". -.PP -There is only one instance of the \*(L"Module_Integrity\*(R" and \*(L"Install_Integrity\*(R" -self tests. All other self tests may have multiple instances. -.PP -The \s-1FIPS\s0 module passes the following descriptions(s) to \fBOSSL_SELF_TEST_onbegin()\fR. -.ie n .IP """\s-1HMAC""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_INTEGRITY_HMAC\s0\fR)" 4 -.el .IP "``\s-1HMAC''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_INTEGRITY_HMAC\s0\fR)" 4 -.IX Item "HMAC (OSSL_SELF_TEST_DESC_INTEGRITY_HMAC)" -\&\*(L"Module_Integrity\*(R" and \*(L"Install_Integrity\*(R" use this. -.ie n .IP """\s-1RSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_RSA_PKCS1\s0\fR)" 4 -.el .IP "``\s-1RSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_RSA_PKCS1\s0\fR)" 4 -.IX Item "RSA (OSSL_SELF_TEST_DESC_PCT_RSA_PKCS1)" -.PD 0 -.ie n .IP """\s-1RSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_RSA\s0\fR)" 4 -.el .IP "``\s-1RSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_RSA\s0\fR)" 4 -.IX Item "RSA (OSSL_SELF_TEST_DESC_PCT_RSA)" -.ie n .IP """\s-1ECDSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_ECDSA\s0\fR)" 4 -.el .IP "``\s-1ECDSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_ECDSA\s0\fR)" 4 -.IX Item "ECDSA (OSSL_SELF_TEST_DESC_PCT_ECDSA)" -.ie n .IP """\s-1EDDSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_EDDSA\s0\fR)" 4 -.el .IP "``\s-1EDDSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_EDDSA\s0\fR)" 4 -.IX Item "EDDSA (OSSL_SELF_TEST_DESC_PCT_EDDSA)" -.ie n .IP """\s-1DSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_DSA\s0\fR)" 4 -.el .IP "``\s-1DSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_PCT_DSA\s0\fR)" 4 -.IX Item "DSA (OSSL_SELF_TEST_DESC_PCT_DSA)" -.PD -Key generation tests used with the \*(L"Pairwise_Consistency_Test\*(R" type. -.ie n .IP """RSA_Encrypt"" (\fB\s-1OSSL_SELF_TEST_DESC_ASYM_RSA_ENC\s0\fR)" 4 -.el .IP "``RSA_Encrypt'' (\fB\s-1OSSL_SELF_TEST_DESC_ASYM_RSA_ENC\s0\fR)" 4 -.IX Item "RSA_Encrypt (OSSL_SELF_TEST_DESC_ASYM_RSA_ENC)" -.PD 0 -.ie n .IP """RSA_Decrypt"" (\fB\s-1OSSL_SELF_TEST_DESC_ASYM_RSA_DEC\s0\fR)" 4 -.el .IP "``RSA_Decrypt'' (\fB\s-1OSSL_SELF_TEST_DESC_ASYM_RSA_DEC\s0\fR)" 4 -.IX Item "RSA_Decrypt (OSSL_SELF_TEST_DESC_ASYM_RSA_DEC)" -.PD -\&\*(L"KAT_AsymmetricCipher\*(R" uses this to indicate an encrypt or decrypt \s-1KAT.\s0 -.ie n .IP """\s-1AES_GCM""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_CIPHER_AES_GCM\s0\fR)" 4 -.el .IP "``\s-1AES_GCM''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_CIPHER_AES_GCM\s0\fR)" 4 -.IX Item "AES_GCM (OSSL_SELF_TEST_DESC_CIPHER_AES_GCM)" -.PD 0 -.ie n .IP """AES_ECB_Decrypt"" (\fB\s-1OSSL_SELF_TEST_DESC_CIPHER_AES_ECB\s0\fR)" 4 -.el .IP "``AES_ECB_Decrypt'' (\fB\s-1OSSL_SELF_TEST_DESC_CIPHER_AES_ECB\s0\fR)" 4 -.IX Item "AES_ECB_Decrypt (OSSL_SELF_TEST_DESC_CIPHER_AES_ECB)" -.ie n .IP """\s-1TDES""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_CIPHER_TDES\s0\fR)" 4 -.el .IP "``\s-1TDES''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_CIPHER_TDES\s0\fR)" 4 -.IX Item "TDES (OSSL_SELF_TEST_DESC_CIPHER_TDES)" -.PD -Symmetric cipher tests used with the \*(L"KAT_Cipher\*(R" type. -.ie n .IP """\s-1SHA1""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_MD_SHA1\s0\fR)" 4 -.el .IP "``\s-1SHA1''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_MD_SHA1\s0\fR)" 4 -.IX Item "SHA1 (OSSL_SELF_TEST_DESC_MD_SHA1)" -.PD 0 -.ie n .IP """\s-1SHA2""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_MD_SHA2\s0\fR)" 4 -.el .IP "``\s-1SHA2''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_MD_SHA2\s0\fR)" 4 -.IX Item "SHA2 (OSSL_SELF_TEST_DESC_MD_SHA2)" -.ie n .IP """\s-1SHA3""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_MD_SHA3\s0\fR)" 4 -.el .IP "``\s-1SHA3''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_MD_SHA3\s0\fR)" 4 -.IX Item "SHA3 (OSSL_SELF_TEST_DESC_MD_SHA3)" -.PD -Digest tests used with the \*(L"KAT_Digest\*(R" type. -.ie n .IP """\s-1DSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_DSA\s0\fR)" 4 -.el .IP "``\s-1DSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_DSA\s0\fR)" 4 -.IX Item "DSA (OSSL_SELF_TEST_DESC_SIGN_DSA)" -.PD 0 -.ie n .IP """\s-1RSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_RSA\s0\fR)" 4 -.el .IP "``\s-1RSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_RSA\s0\fR)" 4 -.IX Item "RSA (OSSL_SELF_TEST_DESC_SIGN_RSA)" -.ie n .IP """\s-1ECDSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_ECDSA\s0\fR)" 4 -.el .IP "``\s-1ECDSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_ECDSA\s0\fR)" 4 -.IX Item "ECDSA (OSSL_SELF_TEST_DESC_SIGN_ECDSA)" -.ie n .IP """\s-1EDDSA""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_EDDSA\s0\fR)" 4 -.el .IP "``\s-1EDDSA''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_SIGN_EDDSA\s0\fR)" 4 -.IX Item "EDDSA (OSSL_SELF_TEST_DESC_SIGN_EDDSA)" -.PD -Signature tests used with the \*(L"KAT_Signature\*(R" type. -.ie n .IP """\s-1ECDH""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KA_ECDH\s0\fR)" 4 -.el .IP "``\s-1ECDH''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KA_ECDH\s0\fR)" 4 -.IX Item "ECDH (OSSL_SELF_TEST_DESC_KA_ECDH)" -.PD 0 -.ie n .IP """\s-1DH""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KA_DH\s0\fR)" 4 -.el .IP "``\s-1DH''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KA_DH\s0\fR)" 4 -.IX Item "DH (OSSL_SELF_TEST_DESC_KA_DH)" -.PD -Key agreement tests used with the \*(L"\s-1KAT_KA\*(R"\s0 type. -.ie n .IP """\s-1HKDF""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_HKDF\s0\fR)" 4 -.el .IP "``\s-1HKDF''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_HKDF\s0\fR)" 4 -.IX Item "HKDF (OSSL_SELF_TEST_DESC_KDF_HKDF)" -.PD 0 -.ie n .IP """\s-1TLS13_KDF_EXTRACT""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_TLS13_EXTRACT\s0\fR)" 4 -.el .IP "``\s-1TLS13_KDF_EXTRACT''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_TLS13_EXTRACT\s0\fR)" 4 -.IX Item "TLS13_KDF_EXTRACT (OSSL_SELF_TEST_DESC_KDF_TLS13_EXTRACT)" -.ie n .IP """\s-1TLS13_KDF_EXPAND""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_TLS13_EXPAND\s0\fR)" 4 -.el .IP "``\s-1TLS13_KDF_EXPAND''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_TLS13_EXPAND\s0\fR)" 4 -.IX Item "TLS13_KDF_EXPAND (OSSL_SELF_TEST_DESC_KDF_TLS13_EXPAND)" -.ie n .IP """\s-1SSKDF""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_SSKDF\s0\fR)" 4 -.el .IP "``\s-1SSKDF''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_SSKDF\s0\fR)" 4 -.IX Item "SSKDF (OSSL_SELF_TEST_DESC_KDF_SSKDF)" -.ie n .IP """X963KDF"" (\fB\s-1OSSL_SELF_TEST_DESC_KDF_X963KDF\s0\fR)" 4 -.el .IP "``X963KDF'' (\fB\s-1OSSL_SELF_TEST_DESC_KDF_X963KDF\s0\fR)" 4 -.IX Item "X963KDF (OSSL_SELF_TEST_DESC_KDF_X963KDF)" -.ie n .IP """X942KDF"" (\fB\s-1OSSL_SELF_TEST_DESC_KDF_X942KDF\s0\fR)" 4 -.el .IP "``X942KDF'' (\fB\s-1OSSL_SELF_TEST_DESC_KDF_X942KDF\s0\fR)" 4 -.IX Item "X942KDF (OSSL_SELF_TEST_DESC_KDF_X942KDF)" -.ie n .IP """\s-1PBKDF2""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_PBKDF2\s0\fR)" 4 -.el .IP "``\s-1PBKDF2''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_PBKDF2\s0\fR)" 4 -.IX Item "PBKDF2 (OSSL_SELF_TEST_DESC_KDF_PBKDF2)" -.ie n .IP """\s-1SSHKDF""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_SSHKDF\s0\fR)" 4 -.el .IP "``\s-1SSHKDF''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_SSHKDF\s0\fR)" 4 -.IX Item "SSHKDF (OSSL_SELF_TEST_DESC_KDF_SSHKDF)" -.ie n .IP """\s-1TLS12_PRF""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_TLS12_PRF\s0\fR)" 4 -.el .IP "``\s-1TLS12_PRF''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_TLS12_PRF\s0\fR)" 4 -.IX Item "TLS12_PRF (OSSL_SELF_TEST_DESC_KDF_TLS12_PRF)" -.ie n .IP """\s-1KBKDF""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_KBKDF\s0\fR)" 4 -.el .IP "``\s-1KBKDF''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_KDF_KBKDF\s0\fR)" 4 -.IX Item "KBKDF (OSSL_SELF_TEST_DESC_KDF_KBKDF)" -.PD -Key Derivation Function tests used with the \*(L"\s-1KAT_KDF\*(R"\s0 type. -.ie n .IP """\s-1CTR""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_DRBG_CTR\s0\fR)" 4 -.el .IP "``\s-1CTR''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_DRBG_CTR\s0\fR)" 4 -.IX Item "CTR (OSSL_SELF_TEST_DESC_DRBG_CTR)" -.PD 0 -.ie n .IP """\s-1HASH""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_DRBG_HASH\s0\fR)" 4 -.el .IP "``\s-1HASH''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_DRBG_HASH\s0\fR)" 4 -.IX Item "HASH (OSSL_SELF_TEST_DESC_DRBG_HASH)" -.ie n .IP """\s-1HMAC""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_DRBG_HMAC\s0\fR)" 4 -.el .IP "``\s-1HMAC''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_DRBG_HMAC\s0\fR)" 4 -.IX Item "HMAC (OSSL_SELF_TEST_DESC_DRBG_HMAC)" -.PD -\&\s-1DRBG\s0 tests used with the \*(L"\s-1DRBG\*(R"\s0 type. -.ie n .IP """\s-1RNG""\s0 (\fB\s-1OSSL_SELF_TEST_DESC_RNG\s0\fR)" 4 -.el .IP "``\s-1RNG''\s0 (\fB\s-1OSSL_SELF_TEST_DESC_RNG\s0\fR)" 4 -.IX Item "RNG (OSSL_SELF_TEST_DESC_RNG)" -\&\*(L"Continuous_RNG_Test\*(R" uses this. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -A simple self test callback is shown below for illustrative purposes. -.PP -.Vb 1 -\& #include -\& -\& static OSSL_CALLBACK self_test_cb; -\& -\& static int self_test_cb(const OSSL_PARAM params[], void *arg) -\& { -\& int ret = 0; -\& const OSSL_PARAM *p = NULL; -\& const char *phase = NULL, *type = NULL, *desc = NULL; -\& -\& p = OSSL_PARAM_locate_const(params, OSSL_PROV_PARAM_SELF_TEST_PHASE); -\& if (p == NULL || p\->data_type != OSSL_PARAM_UTF8_STRING) -\& goto err; -\& phase = (const char *)p\->data; -\& -\& p = OSSL_PARAM_locate_const(params, OSSL_PROV_PARAM_SELF_TEST_DESC); -\& if (p == NULL || p\->data_type != OSSL_PARAM_UTF8_STRING) -\& goto err; -\& desc = (const char *)p\->data; -\& -\& p = OSSL_PARAM_locate_const(params, OSSL_PROV_PARAM_SELF_TEST_TYPE); -\& if (p == NULL || p\->data_type != OSSL_PARAM_UTF8_STRING) -\& goto err; -\& type = (const char *)p\->data; -\& -\& /* Do some logging */ -\& if (strcmp(phase, OSSL_SELF_TEST_PHASE_START) == 0) -\& BIO_printf(bio_out, "%s : (%s) : ", desc, type); -\& if (strcmp(phase, OSSL_SELF_TEST_PHASE_PASS) == 0 -\& || strcmp(phase, OSSL_SELF_TEST_PHASE_FAIL) == 0) -\& BIO_printf(bio_out, "%s\en", phase); -\& -\& /* Corrupt the SHA1 self test during the \*(Aqcorrupt\*(Aq phase by returning 0 */ -\& if (strcmp(phase, OSSL_SELF_TEST_PHASE_CORRUPT) == 0 -\& && strcmp(desc, OSSL_SELF_TEST_DESC_MD_SHA1) == 0) { -\& BIO_printf(bio_out, "%s %s", phase, desc); -\& return 0; -\& } -\& ret = 1; -\& err: -\& return ret; -\& } -.Ve -.SH "NOTES" -.IX Header "NOTES" -Some released versions of OpenSSL do not include a validated -\&\s-1FIPS\s0 provider. To determine which versions have undergone -the validation process, please refer to the -OpenSSL Downloads page . If you -require FIPS-approved functionality, it is essential to build your \s-1FIPS\s0 -provider using one of the validated versions listed there. Normally, -it is possible to utilize a \s-1FIPS\s0 provider constructed from one of the -validated versions alongside \fIlibcrypto\fR and \fIlibssl\fR compiled from any -release within the same major release series. This flexibility enables -you to address bug fixes and CVEs that fall outside the \s-1FIPS\s0 boundary. -.PP -The \s-1FIPS\s0 provider in OpenSSL 3.1 includes some non-FIPS validated algorithms, -consequently the property query \f(CW\*(C`fips=yes\*(C'\fR is mandatory for applications that -want to operate in a \s-1FIPS\s0 approved manner. The algorithms are: -.IP "Triple \s-1DES ECB\s0" 4 -.IX Item "Triple DES ECB" -.PD 0 -.IP "Triple \s-1DES CBC\s0" 4 -.IX Item "Triple DES CBC" -.IP "EdDSA" 4 -.IX Item "EdDSA" -.PD -.PP -You can load the \s-1FIPS\s0 provider into multiple library contexts as any other -provider. However the following restriction applies. The \s-1FIPS\s0 provider cannot -be used by multiple copies of OpenSSL libcrypto in a single process. -.PP -As the provider saves core callbacks to the libcrypto obtained in the -\&\fBOSSL_provider_init()\fR call to global data it will fail if subsequent -invocations of its \fBOSSL_provider_init()\fR function yield different addresses -of these callbacks than in the initial call. This happens when different -copies of libcrypto are present in the memory of the process and both try -to load the same \s-1FIPS\s0 provider. A workaround is to have a different copy -of the \s-1FIPS\s0 provider loaded for each of the libcrypto instances in the -process. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-fipsinstall\fR\|(1), -\&\fBfips_config\fR\|(5), -\&\fBOSSL_SELF_TEST_set_callback\fR\|(3), -\&\fBOSSL_SELF_TEST_new\fR\|(3), -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), -\&\fBopenssl\-core.h\fR\|(7), -\&\fBopenssl\-core_dispatch.h\fR\|(7), -\&\fBprovider\fR\|(7), - -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/OSSL_PROVIDER-base.7ossl b/openssl-install/share/man/man7/OSSL_PROVIDER-base.7ossl deleted file mode 100644 index d13bdb78..00000000 --- a/openssl-install/share/man/man7/OSSL_PROVIDER-base.7ossl +++ /dev/null @@ -1,290 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PROVIDER-BASE 7ossl" -.TH OSSL_PROVIDER-BASE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PROVIDER\-base \- OpenSSL base provider -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The OpenSSL base provider supplies the encoding for OpenSSL's -asymmetric cryptography. -.SS "Properties" -.IX Subsection "Properties" -The implementations in this provider specifically have this property -defined: -.ie n .IP """provider=base""" 4 -.el .IP "``provider=base''" 4 -.IX Item "provider=base" -.PP -It may be used in a property query string with fetching functions. -.PP -It isn't mandatory to query for this property, except to make sure to get -implementations of this provider and none other. -.ie n .IP """type=parameters""" 4 -.el .IP "``type=parameters''" 4 -.IX Item "type=parameters" -.PD 0 -.ie n .IP """type=private""" 4 -.el .IP "``type=private''" 4 -.IX Item "type=private" -.ie n .IP """type=public""" 4 -.el .IP "``type=public''" 4 -.IX Item "type=public" -.PD -.PP -These may be used in a property query string with fetching functions to select -which data are to be encoded. Either the private key material, the public -key material or the domain parameters can be selected. -.ie n .IP """format=der""" 4 -.el .IP "``format=der''" 4 -.IX Item "format=der" -.PD 0 -.ie n .IP """format=pem""" 4 -.el .IP "``format=pem''" 4 -.IX Item "format=pem" -.ie n .IP """format=text""" 4 -.el .IP "``format=text''" 4 -.IX Item "format=text" -.PD -.PP -These may be used in a property query string with fetching functions to select -the encoding output format. Either the \s-1DER, PEM\s0 and plaintext are -currently permitted. -.SH "OPERATIONS AND ALGORITHMS" -.IX Header "OPERATIONS AND ALGORITHMS" -The OpenSSL base provider supports these operations and algorithms: -.SS "Random Number Generation" -.IX Subsection "Random Number Generation" -.IP "SEED-SRC, see \s-1\fBEVP_RAND\-SEED\-SRC\s0\fR\|(7)" 4 -.IX Item "SEED-SRC, see EVP_RAND-SEED-SRC" -.PD 0 -.IP "\s-1JITTER,\s0 see \s-1\fBEVP_RAND\-JITTER\s0\fR\|(7)" 4 -.IX Item "JITTER, see EVP_RAND-JITTER" -.PD -.PP -In addition to this provider, the \*(L"SEED-SRC\*(R" and \*(L"\s-1JITTER\*(R"\s0 algorithms -are also available in the default provider. -.SS "Asymmetric Key Encoder" -.IX Subsection "Asymmetric Key Encoder" -.IP "\s-1RSA\s0" 4 -.IX Item "RSA" -.PD 0 -.IP "RSA-PSS" 4 -.IX Item "RSA-PSS" -.IP "\s-1DH\s0" 4 -.IX Item "DH" -.IP "\s-1DHX\s0" 4 -.IX Item "DHX" -.IP "\s-1DSA\s0" 4 -.IX Item "DSA" -.IP "\s-1EC\s0" 4 -.IX Item "EC" -.IP "\s-1ED25519\s0" 4 -.IX Item "ED25519" -.IP "\s-1ED448\s0" 4 -.IX Item "ED448" -.IP "X25519" 4 -.IX Item "X25519" -.IP "X448" 4 -.IX Item "X448" -.IP "\s-1SM2\s0" 4 -.IX Item "SM2" -.PD -.PP -In addition to this provider, all of these encoding algorithms are also -available in the default provider. Some of these algorithms may be used in -combination with the \s-1FIPS\s0 provider. -.SS "Asymmetric Key Decoder" -.IX Subsection "Asymmetric Key Decoder" -.IP "\s-1RSA\s0" 4 -.IX Item "RSA" -.PD 0 -.IP "RSA-PSS" 4 -.IX Item "RSA-PSS" -.IP "\s-1DH\s0" 4 -.IX Item "DH" -.IP "\s-1DHX\s0" 4 -.IX Item "DHX" -.IP "\s-1DSA\s0" 4 -.IX Item "DSA" -.IP "\s-1EC\s0" 4 -.IX Item "EC" -.IP "\s-1ED25519\s0" 4 -.IX Item "ED25519" -.IP "\s-1ED448\s0" 4 -.IX Item "ED448" -.IP "X25519" 4 -.IX Item "X25519" -.IP "X448" 4 -.IX Item "X448" -.IP "\s-1SM2\s0" 4 -.IX Item "SM2" -.IP "\s-1DER\s0" 4 -.IX Item "DER" -.PD -.PP -In addition to this provider, all of these decoding algorithms are also -available in the default provider. Some of these algorithms may be used in -combination with the \s-1FIPS\s0 provider. -.SS "Stores" -.IX Subsection "Stores" -.IP "file" 4 -.IX Item "file" -.PD 0 -.IP "org.openssl.winstore, see \fBOSSL_STORE\-winstore\fR\|(7)" 4 -.IX Item "org.openssl.winstore, see OSSL_STORE-winstore" -.PD -.PP -In addition to this provider, all of these store algorithms are also -available in the default provider. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_PROVIDER\-default\fR\|(7), \fBopenssl\-core.h\fR\|(7), -\&\fBopenssl\-core_dispatch.h\fR\|(7), \fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/OSSL_PROVIDER-default.7ossl b/openssl-install/share/man/man7/OSSL_PROVIDER-default.7ossl deleted file mode 100644 index 1ac17c8b..00000000 --- a/openssl-install/share/man/man7/OSSL_PROVIDER-default.7ossl +++ /dev/null @@ -1,490 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PROVIDER-DEFAULT 7ossl" -.TH OSSL_PROVIDER-DEFAULT 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PROVIDER\-default \- OpenSSL default provider -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The OpenSSL default provider supplies the majority of OpenSSL's diverse -algorithm implementations. If an application doesn't specify anything else -explicitly (e.g. in the application or via config), then this is the -provider that will be used as fallback: It is loaded automatically the -first time that an algorithm is fetched from a provider or a function -acting on providers is called and no other provider has been loaded yet. -.PP -If an attempt to load a provider has already been made (whether successful -or not) then the default provider won't be loaded automatically. Therefore -if the default provider is to be used in conjunction with other providers -then it must be loaded explicitly. Automatic loading of the default -provider only occurs a maximum of once; if the default provider is -explicitly unloaded then the default provider will not be automatically -loaded again. -.SS "Properties" -.IX Subsection "Properties" -The implementations in this provider specifically have this property -defined: -.ie n .IP """provider=default""" 4 -.el .IP "``provider=default''" 4 -.IX Item "provider=default" -.PP -It may be used in a property query string with fetching functions such as -\&\fBEVP_MD_fetch\fR\|(3) or \fBEVP_CIPHER_fetch\fR\|(3), as well as with other -functions that take a property query string, such as -\&\fBEVP_PKEY_CTX_new_from_name\fR\|(3). -.PP -It isn't mandatory to query for this property, except to make sure to get -implementations of this provider and none other. -.PP -Some implementations may define additional properties. Exact information is -listed below -.SH "OPERATIONS AND ALGORITHMS" -.IX Header "OPERATIONS AND ALGORITHMS" -The OpenSSL default provider supports these operations and algorithms: -.SS "Hashing Algorithms / Message Digests" -.IX Subsection "Hashing Algorithms / Message Digests" -.IP "\s-1SHA1,\s0 see \s-1\fBEVP_MD\-SHA1\s0\fR\|(7)" 4 -.IX Item "SHA1, see EVP_MD-SHA1" -.PD 0 -.IP "\s-1SHA2,\s0 see \s-1\fBEVP_MD\-SHA2\s0\fR\|(7)" 4 -.IX Item "SHA2, see EVP_MD-SHA2" -.IP "\s-1SHA3,\s0 see \s-1\fBEVP_MD\-SHA3\s0\fR\|(7)" 4 -.IX Item "SHA3, see EVP_MD-SHA3" -.IP "\s-1KECCAK,\s0 see \s-1\fBEVP_MD\-KECCAK\s0\fR\|(7)" 4 -.IX Item "KECCAK, see EVP_MD-KECCAK" -.IP "KECCAK-KMAC, see \s-1\fBEVP_MD\-KECCAK\-KMAC\s0\fR\|(7)" 4 -.IX Item "KECCAK-KMAC, see EVP_MD-KECCAK-KMAC" -.IP "\s-1SHAKE,\s0 see \s-1\fBEVP_MD\-SHAKE\s0\fR\|(7)" 4 -.IX Item "SHAKE, see EVP_MD-SHAKE" -.IP "\s-1BLAKE2,\s0 see \s-1\fBEVP_MD\-BLAKE2\s0\fR\|(7)" 4 -.IX Item "BLAKE2, see EVP_MD-BLAKE2" -.IP "\s-1SM3,\s0 see \s-1\fBEVP_MD\-SM3\s0\fR\|(7)" 4 -.IX Item "SM3, see EVP_MD-SM3" -.IP "\s-1MD5,\s0 see \s-1\fBEVP_MD\-MD5\s0\fR\|(7)" 4 -.IX Item "MD5, see EVP_MD-MD5" -.IP "\s-1MD5\-SHA1,\s0 see \s-1\fBEVP_MD\-MD5\-SHA1\s0\fR\|(7)" 4 -.IX Item "MD5-SHA1, see EVP_MD-MD5-SHA1" -.IP "\s-1RIPEMD160,\s0 see \s-1\fBEVP_MD\-RIPEMD160\s0\fR\|(7)" 4 -.IX Item "RIPEMD160, see EVP_MD-RIPEMD160" -.IP "\s-1NULL,\s0 see \s-1\fBEVP_MD\-NULL\s0\fR\|(7)" 4 -.IX Item "NULL, see EVP_MD-NULL" -.PD -.SS "Symmetric Ciphers" -.IX Subsection "Symmetric Ciphers" -.IP "\s-1AES,\s0 see \s-1\fBEVP_CIPHER\-AES\s0\fR\|(7)" 4 -.IX Item "AES, see EVP_CIPHER-AES" -.PD 0 -.IP "\s-1ARIA,\s0 see \s-1\fBEVP_CIPHER\-ARIA\s0\fR\|(7)" 4 -.IX Item "ARIA, see EVP_CIPHER-ARIA" -.IP "\s-1CAMELLIA,\s0 see \s-1\fBEVP_CIPHER\-CAMELLIA\s0\fR\|(7)" 4 -.IX Item "CAMELLIA, see EVP_CIPHER-CAMELLIA" -.IP "3DES, see \s-1\fBEVP_CIPHER\-DES\s0\fR\|(7)" 4 -.IX Item "3DES, see EVP_CIPHER-DES" -.IP "\s-1SM4,\s0 see \s-1\fBEVP_CIPHER\-SM4\s0\fR\|(7)" 4 -.IX Item "SM4, see EVP_CIPHER-SM4" -.IP "ChaCha20, see \s-1\fBEVP_CIPHER\-CHACHA\s0\fR\|(7)" 4 -.IX Item "ChaCha20, see EVP_CIPHER-CHACHA" -.IP "ChaCha20\-Poly1305, see \s-1\fBEVP_CIPHER\-CHACHA\s0\fR\|(7)" 4 -.IX Item "ChaCha20-Poly1305, see EVP_CIPHER-CHACHA" -.IP "\s-1NULL,\s0 see \s-1\fBEVP_CIPHER\-NULL\s0\fR\|(7)" 4 -.IX Item "NULL, see EVP_CIPHER-NULL" -.PD -.SS "Message Authentication Code (\s-1MAC\s0)" -.IX Subsection "Message Authentication Code (MAC)" -.IP "\s-1BLAKE2,\s0 see \s-1\fBEVP_MAC\-BLAKE2\s0\fR\|(7)" 4 -.IX Item "BLAKE2, see EVP_MAC-BLAKE2" -.PD 0 -.IP "\s-1CMAC,\s0 see \s-1\fBEVP_MAC\-CMAC\s0\fR\|(7)" 4 -.IX Item "CMAC, see EVP_MAC-CMAC" -.IP "\s-1GMAC,\s0 see \s-1\fBEVP_MAC\-GMAC\s0\fR\|(7)" 4 -.IX Item "GMAC, see EVP_MAC-GMAC" -.IP "\s-1HMAC,\s0 see \s-1\fBEVP_MAC\-HMAC\s0\fR\|(7)" 4 -.IX Item "HMAC, see EVP_MAC-HMAC" -.IP "\s-1KMAC,\s0 see \s-1\fBEVP_MAC\-KMAC\s0\fR\|(7)" 4 -.IX Item "KMAC, see EVP_MAC-KMAC" -.IP "\s-1SIPHASH,\s0 see \fBEVP_MAC\-Siphash\fR\|(7)" 4 -.IX Item "SIPHASH, see EVP_MAC-Siphash" -.IP "\s-1POLY1305,\s0 see \fBEVP_MAC\-Poly1305\fR\|(7)" 4 -.IX Item "POLY1305, see EVP_MAC-Poly1305" -.PD -.SS "Key Derivation Function (\s-1KDF\s0)" -.IX Subsection "Key Derivation Function (KDF)" -.IP "\s-1HKDF,\s0 see \s-1\fBEVP_KDF\-HKDF\s0\fR\|(7)" 4 -.IX Item "HKDF, see EVP_KDF-HKDF" -.PD 0 -.IP "\s-1TLS13\-KDF,\s0 see \s-1\fBEVP_KDF\-TLS13_KDF\s0\fR\|(7)" 4 -.IX Item "TLS13-KDF, see EVP_KDF-TLS13_KDF" -.IP "\s-1SSKDF,\s0 see \s-1\fBEVP_KDF\-SS\s0\fR\|(7)" 4 -.IX Item "SSKDF, see EVP_KDF-SS" -.IP "\s-1PBKDF2,\s0 see \s-1\fBEVP_KDF\-PBKDF2\s0\fR\|(7)" 4 -.IX Item "PBKDF2, see EVP_KDF-PBKDF2" -.IP "\s-1PKCS12KDF,\s0 see \s-1\fBEVP_KDF\-PKCS12KDF\s0\fR\|(7)" 4 -.IX Item "PKCS12KDF, see EVP_KDF-PKCS12KDF" -.IP "\s-1SSHKDF,\s0 see \s-1\fBEVP_KDF\-SSHKDF\s0\fR\|(7)" 4 -.IX Item "SSHKDF, see EVP_KDF-SSHKDF" -.IP "\s-1TLS1\-PRF,\s0 see \s-1\fBEVP_KDF\-TLS1_PRF\s0\fR\|(7)" 4 -.IX Item "TLS1-PRF, see EVP_KDF-TLS1_PRF" -.IP "\s-1KBKDF,\s0 see \s-1\fBEVP_KDF\-KB\s0\fR\|(7)" 4 -.IX Item "KBKDF, see EVP_KDF-KB" -.IP "X942KDF\-ASN1, see \s-1\fBEVP_KDF\-X942\-ASN1\s0\fR\|(7)" 4 -.IX Item "X942KDF-ASN1, see EVP_KDF-X942-ASN1" -.IP "X942KDF\-CONCAT, see \s-1\fBEVP_KDF\-X942\-CONCAT\s0\fR\|(7)" 4 -.IX Item "X942KDF-CONCAT, see EVP_KDF-X942-CONCAT" -.IP "X963KDF, see \s-1\fBEVP_KDF\-X963\s0\fR\|(7)" 4 -.IX Item "X963KDF, see EVP_KDF-X963" -.IP "\s-1SCRYPT,\s0 see \s-1\fBEVP_KDF\-SCRYPT\s0\fR\|(7)" 4 -.IX Item "SCRYPT, see EVP_KDF-SCRYPT" -.IP "\s-1KRB5KDF,\s0 see \s-1\fBEVP_KDF\-KRB5KDF\s0\fR\|(7)" 4 -.IX Item "KRB5KDF, see EVP_KDF-KRB5KDF" -.IP "HMAC-DRBG, see \s-1\fBEVP_KDF\-HMAC\-DRBG\s0\fR\|(7)" 4 -.IX Item "HMAC-DRBG, see EVP_KDF-HMAC-DRBG" -.IP "\s-1ARGON2,\s0 see \s-1\fBEVP_KDF\-ARGON2\s0\fR\|(7)" 4 -.IX Item "ARGON2, see EVP_KDF-ARGON2" -.PD -.SS "Key Exchange" -.IX Subsection "Key Exchange" -.IP "\s-1DH,\s0 see \s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7)" 4 -.IX Item "DH, see EVP_KEYEXCH-DH" -.PD 0 -.IP "\s-1ECDH,\s0 see \s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7)" 4 -.IX Item "ECDH, see EVP_KEYEXCH-ECDH" -.IP "X25519, see \s-1\fBEVP_KEYEXCH\-X25519\s0\fR\|(7)" 4 -.IX Item "X25519, see EVP_KEYEXCH-X25519" -.IP "X448, see \s-1\fBEVP_KEYEXCH\-X448\s0\fR\|(7)" 4 -.IX Item "X448, see EVP_KEYEXCH-X448" -.IP "\s-1TLS1\-PRF\s0" 4 -.IX Item "TLS1-PRF" -.IP "\s-1HKDF\s0" 4 -.IX Item "HKDF" -.IP "\s-1SCRYPT\s0" 4 -.IX Item "SCRYPT" -.PD -.SS "Asymmetric Signature" -.IX Subsection "Asymmetric Signature" -.IP "\s-1DSA,\s0 see \s-1\fBEVP_SIGNATURE\-DSA\s0\fR\|(7)" 4 -.IX Item "DSA, see EVP_SIGNATURE-DSA" -.PD 0 -.IP "\s-1RSA,\s0 see \s-1\fBEVP_SIGNATURE\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_SIGNATURE-RSA" -.IP "\s-1ED25519,\s0 see \s-1\fBEVP_SIGNATURE\-ED25519\s0\fR\|(7)" 4 -.IX Item "ED25519, see EVP_SIGNATURE-ED25519" -.IP "\s-1ED448,\s0 see \s-1\fBEVP_SIGNATURE\-ED448\s0\fR\|(7)" 4 -.IX Item "ED448, see EVP_SIGNATURE-ED448" -.IP "\s-1ECDSA,\s0 see \s-1\fBEVP_SIGNATURE\-ECDSA\s0\fR\|(7)" 4 -.IX Item "ECDSA, see EVP_SIGNATURE-ECDSA" -.IP "\s-1SM2\s0" 4 -.IX Item "SM2" -.IP "\s-1HMAC,\s0 see \s-1\fBEVP_SIGNATURE\-HMAC\s0\fR\|(7)" 4 -.IX Item "HMAC, see EVP_SIGNATURE-HMAC" -.IP "\s-1SIPHASH,\s0 see \fBEVP_SIGNATURE\-Siphash\fR\|(7)" 4 -.IX Item "SIPHASH, see EVP_SIGNATURE-Siphash" -.IP "\s-1POLY1305,\s0 see \fBEVP_SIGNATURE\-Poly1305\fR\|(7)" 4 -.IX Item "POLY1305, see EVP_SIGNATURE-Poly1305" -.IP "\s-1CMAC,\s0 see \s-1\fBEVP_SIGNATURE\-CMAC\s0\fR\|(7)" 4 -.IX Item "CMAC, see EVP_SIGNATURE-CMAC" -.PD -.SS "Asymmetric Cipher" -.IX Subsection "Asymmetric Cipher" -.IP "\s-1RSA,\s0 see \s-1\fBEVP_ASYM_CIPHER\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_ASYM_CIPHER-RSA" -.PD 0 -.IP "\s-1SM2,\s0 see \s-1\fBEVP_ASYM_CIPHER\-SM2\s0\fR\|(7)" 4 -.IX Item "SM2, see EVP_ASYM_CIPHER-SM2" -.PD -.SS "Asymmetric Key Encapsulation" -.IX Subsection "Asymmetric Key Encapsulation" -.IP "\s-1RSA,\s0 see \s-1\fBEVP_KEM\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_KEM-RSA" -.PD 0 -.IP "X25519, see \s-1\fBEVP_KEM\-X25519\s0\fR\|(7)" 4 -.IX Item "X25519, see EVP_KEM-X25519" -.IP "X448, see \s-1\fBEVP_KEM\-X448\s0\fR\|(7)" 4 -.IX Item "X448, see EVP_KEM-X448" -.IP "\s-1EC,\s0 see \s-1\fBEVP_KEM\-EC\s0\fR\|(7)" 4 -.IX Item "EC, see EVP_KEM-EC" -.PD -.SS "Asymmetric Key Management" -.IX Subsection "Asymmetric Key Management" -.IP "\s-1DH,\s0 see \s-1\fBEVP_KEYMGMT\-DH\s0\fR\|(7)" 4 -.IX Item "DH, see EVP_KEYMGMT-DH" -.PD 0 -.IP "\s-1DHX,\s0 see \s-1\fBEVP_KEYMGMT\-DHX\s0\fR\|(7)" 4 -.IX Item "DHX, see EVP_KEYMGMT-DHX" -.IP "\s-1DSA,\s0 see \s-1\fBEVP_KEYMGMT\-DSA\s0\fR\|(7)" 4 -.IX Item "DSA, see EVP_KEYMGMT-DSA" -.IP "\s-1RSA,\s0 see \s-1\fBEVP_KEYMGMT\-RSA\s0\fR\|(7)" 4 -.IX Item "RSA, see EVP_KEYMGMT-RSA" -.IP "RSA-PSS" 4 -.IX Item "RSA-PSS" -.IP "\s-1EC,\s0 see \s-1\fBEVP_KEYMGMT\-EC\s0\fR\|(7)" 4 -.IX Item "EC, see EVP_KEYMGMT-EC" -.IP "X25519, see \s-1\fBEVP_KEYMGMT\-X25519\s0\fR\|(7)" 4 -.IX Item "X25519, see EVP_KEYMGMT-X25519" -.IP "X448, see \s-1\fBEVP_KEYMGMT\-X448\s0\fR\|(7)" 4 -.IX Item "X448, see EVP_KEYMGMT-X448" -.IP "\s-1ED25519,\s0 see \s-1\fBEVP_KEYMGMT\-ED25519\s0\fR\|(7)" 4 -.IX Item "ED25519, see EVP_KEYMGMT-ED25519" -.IP "\s-1ED448,\s0 see \s-1\fBEVP_KEYMGMT\-ED448\s0\fR\|(7)" 4 -.IX Item "ED448, see EVP_KEYMGMT-ED448" -.IP "\s-1TLS1\-PRF\s0" 4 -.IX Item "TLS1-PRF" -.IP "\s-1HKDF\s0" 4 -.IX Item "HKDF" -.IP "\s-1SCRYPT\s0" 4 -.IX Item "SCRYPT" -.IP "\s-1HMAC,\s0 see \s-1\fBEVP_KEYMGMT\-HMAC\s0\fR\|(7)" 4 -.IX Item "HMAC, see EVP_KEYMGMT-HMAC" -.IP "\s-1SIPHASH,\s0 see \fBEVP_KEYMGMT\-Siphash\fR\|(7)" 4 -.IX Item "SIPHASH, see EVP_KEYMGMT-Siphash" -.IP "\s-1POLY1305,\s0 see \fBEVP_KEYMGMT\-Poly1305\fR\|(7)" 4 -.IX Item "POLY1305, see EVP_KEYMGMT-Poly1305" -.IP "\s-1CMAC,\s0 see \s-1\fBEVP_KEYMGMT\-CMAC\s0\fR\|(7)" 4 -.IX Item "CMAC, see EVP_KEYMGMT-CMAC" -.IP "\s-1SM2,\s0 see \s-1\fBEVP_KEYMGMT\-SM2\s0\fR\|(7)" 4 -.IX Item "SM2, see EVP_KEYMGMT-SM2" -.PD -.SS "Random Number Generation" -.IX Subsection "Random Number Generation" -.IP "CTR-DRBG, see \s-1\fBEVP_RAND\-CTR\-DRBG\s0\fR\|(7)" 4 -.IX Item "CTR-DRBG, see EVP_RAND-CTR-DRBG" -.PD 0 -.IP "HASH-DRBG, see \s-1\fBEVP_RAND\-HASH\-DRBG\s0\fR\|(7)" 4 -.IX Item "HASH-DRBG, see EVP_RAND-HASH-DRBG" -.IP "HMAC-DRBG, see \s-1\fBEVP_RAND\-HMAC\-DRBG\s0\fR\|(7)" 4 -.IX Item "HMAC-DRBG, see EVP_RAND-HMAC-DRBG" -.IP "SEED-SRC, see \s-1\fBEVP_RAND\-SEED\-SRC\s0\fR\|(7)" 4 -.IX Item "SEED-SRC, see EVP_RAND-SEED-SRC" -.IP "\s-1JITTER,\s0 see \s-1\fBEVP_RAND\-JITTER\s0\fR\|(7)" 4 -.IX Item "JITTER, see EVP_RAND-JITTER" -.IP "TEST-RAND, see \s-1\fBEVP_RAND\-TEST\-RAND\s0\fR\|(7)" 4 -.IX Item "TEST-RAND, see EVP_RAND-TEST-RAND" -.PD -.PP -In addition to this provider, the \*(L"SEED-SRC\*(R" and \*(L"\s-1JITTER\*(R"\s0 algorithms -are also available in the base provider. -.SS "Asymmetric Key Encoder" -.IX Subsection "Asymmetric Key Encoder" -.IP "\s-1RSA\s0" 4 -.IX Item "RSA" -.PD 0 -.IP "RSA-PSS" 4 -.IX Item "RSA-PSS" -.IP "\s-1DH\s0" 4 -.IX Item "DH" -.IP "\s-1DHX\s0" 4 -.IX Item "DHX" -.IP "\s-1DSA\s0" 4 -.IX Item "DSA" -.IP "\s-1EC\s0" 4 -.IX Item "EC" -.IP "\s-1ED25519\s0" 4 -.IX Item "ED25519" -.IP "\s-1ED448\s0" 4 -.IX Item "ED448" -.IP "X25519" 4 -.IX Item "X25519" -.IP "X448" 4 -.IX Item "X448" -.IP "\s-1SM2\s0" 4 -.IX Item "SM2" -.PD -.PP -In addition to this provider, all of these encoding algorithms are also -available in the base provider. Some of these algorithms may be used in -combination with the \s-1FIPS\s0 provider. -.SS "Asymmetric Key Decoder" -.IX Subsection "Asymmetric Key Decoder" -.IP "\s-1RSA\s0" 4 -.IX Item "RSA" -.PD 0 -.IP "RSA-PSS" 4 -.IX Item "RSA-PSS" -.IP "\s-1DH\s0" 4 -.IX Item "DH" -.IP "\s-1DHX\s0" 4 -.IX Item "DHX" -.IP "\s-1DSA\s0" 4 -.IX Item "DSA" -.IP "\s-1EC\s0" 4 -.IX Item "EC" -.IP "\s-1ED25519\s0" 4 -.IX Item "ED25519" -.IP "\s-1ED448\s0" 4 -.IX Item "ED448" -.IP "X25519" 4 -.IX Item "X25519" -.IP "X448" 4 -.IX Item "X448" -.IP "\s-1SM2\s0" 4 -.IX Item "SM2" -.IP "\s-1DER\s0" 4 -.IX Item "DER" -.PD -.PP -In addition to this provider, all of these decoding algorithms are also -available in the base provider. Some of these algorithms may be used in -combination with the \s-1FIPS\s0 provider. -.SS "Stores" -.IX Subsection "Stores" -.IP "file" 4 -.IX Item "file" -.PD 0 -.IP "org.openssl.winstore, see \fBOSSL_STORE\-winstore\fR\|(7)" 4 -.IX Item "org.openssl.winstore, see OSSL_STORE-winstore" -.PD -.PP -In addition to this provider, all of these store algorithms are also -available in the base provider. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core.h\fR\|(7), \fBopenssl\-core_dispatch.h\fR\|(7), \fBprovider\fR\|(7), -\&\fBOSSL_PROVIDER\-base\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1RIPEMD160\s0 digest was added to the default provider in OpenSSL 3.0.7. -.PP -All other functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/OSSL_PROVIDER-legacy.7ossl b/openssl-install/share/man/man7/OSSL_PROVIDER-legacy.7ossl deleted file mode 100644 index 9af55ebb..00000000 --- a/openssl-install/share/man/man7/OSSL_PROVIDER-legacy.7ossl +++ /dev/null @@ -1,234 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PROVIDER-LEGACY 7ossl" -.TH OSSL_PROVIDER-LEGACY 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PROVIDER\-legacy \- OpenSSL legacy provider -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The OpenSSL legacy provider supplies OpenSSL implementations of algorithms -that have been deemed legacy. Such algorithms have commonly fallen out of -use, have been deemed insecure by the cryptography community, or something -similar. -.PP -We can consider this the retirement home of cryptographic algorithms. -.SS "Properties" -.IX Subsection "Properties" -The implementations in this provider specifically has this property -defined: -.ie n .IP """provider=legacy""" 4 -.el .IP "``provider=legacy''" 4 -.IX Item "provider=legacy" -.PP -It may be used in a property query string with fetching functions such as -\&\fBEVP_MD_fetch\fR\|(3) or \fBEVP_CIPHER_fetch\fR\|(3), as well as with other -functions that take a property query string, such as -\&\fBEVP_PKEY_CTX_new_from_name\fR\|(3). -.PP -It isn't mandatory to query for any of these properties, except to -make sure to get implementations of this provider and none other. -.SH "OPERATIONS AND ALGORITHMS" -.IX Header "OPERATIONS AND ALGORITHMS" -The OpenSSL legacy provider supports these operations and algorithms: -.SS "Hashing Algorithms / Message Digests" -.IX Subsection "Hashing Algorithms / Message Digests" -.IP "\s-1MD2,\s0 see \s-1\fBEVP_MD\-MD2\s0\fR\|(7)" 4 -.IX Item "MD2, see EVP_MD-MD2" -Disabled by default. Use \fIenable\-md2\fR config option to enable. -.IP "\s-1MD4,\s0 see \s-1\fBEVP_MD\-MD4\s0\fR\|(7)" 4 -.IX Item "MD4, see EVP_MD-MD4" -.PD 0 -.IP "\s-1MDC2,\s0 see \s-1\fBEVP_MD\-MDC2\s0\fR\|(7)" 4 -.IX Item "MDC2, see EVP_MD-MDC2" -.IP "\s-1WHIRLPOOL,\s0 see \s-1\fBEVP_MD\-WHIRLPOOL\s0\fR\|(7)" 4 -.IX Item "WHIRLPOOL, see EVP_MD-WHIRLPOOL" -.IP "\s-1RIPEMD160,\s0 see \s-1\fBEVP_MD\-RIPEMD160\s0\fR\|(7)" 4 -.IX Item "RIPEMD160, see EVP_MD-RIPEMD160" -.PD -.SS "Symmetric Ciphers" -.IX Subsection "Symmetric Ciphers" -Not all of these symmetric cipher algorithms are enabled by default. -.IP "Blowfish, see \s-1\fBEVP_CIPHER\-BLOWFISH\s0\fR\|(7)" 4 -.IX Item "Blowfish, see EVP_CIPHER-BLOWFISH" -.PD 0 -.IP "\s-1CAST,\s0 see \s-1\fBEVP_CIPHER\-CAST\s0\fR\|(7)" 4 -.IX Item "CAST, see EVP_CIPHER-CAST" -.IP "\s-1DES,\s0 see \s-1\fBEVP_CIPHER\-DES\s0\fR\|(7)" 4 -.IX Item "DES, see EVP_CIPHER-DES" -.PD -The algorithm names are: \s-1DES_ECB, DES_CBC, DES_OFB, DES_CFB, DES_CFB1, DES_CFB8\s0 -and \s-1DESX_CBC.\s0 -.IP "\s-1IDEA,\s0 see \s-1\fBEVP_CIPHER\-IDEA\s0\fR\|(7)" 4 -.IX Item "IDEA, see EVP_CIPHER-IDEA" -.PD 0 -.IP "\s-1RC2,\s0 see \s-1\fBEVP_CIPHER\-RC2\s0\fR\|(7)" 4 -.IX Item "RC2, see EVP_CIPHER-RC2" -.IP "\s-1RC4,\s0 see \s-1\fBEVP_CIPHER\-RC4\s0\fR\|(7)" 4 -.IX Item "RC4, see EVP_CIPHER-RC4" -.IP "\s-1RC5,\s0 see \s-1\fBEVP_CIPHER\-RC5\s0\fR\|(7)" 4 -.IX Item "RC5, see EVP_CIPHER-RC5" -.PD -Disabled by default. Use \fIenable\-rc5\fR config option to enable. -.IP "\s-1SEED,\s0 see \s-1\fBEVP_CIPHER\-SEED\s0\fR\|(7)" 4 -.IX Item "SEED, see EVP_CIPHER-SEED" -.SS "Key Derivation Function (\s-1KDF\s0)" -.IX Subsection "Key Derivation Function (KDF)" -.PD 0 -.IP "\s-1PBKDF1\s0" 4 -.IX Item "PBKDF1" -.IP "\s-1PVKKDF\s0" 4 -.IX Item "PVKKDF" -.PD -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), -\&\fBopenssl\-core.h\fR\|(7), -\&\fBopenssl\-core_dispatch.h\fR\|(7), -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/OSSL_PROVIDER-null.7ossl b/openssl-install/share/man/man7/OSSL_PROVIDER-null.7ossl deleted file mode 100644 index 669c84f5..00000000 --- a/openssl-install/share/man/man7/OSSL_PROVIDER-null.7ossl +++ /dev/null @@ -1,168 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_PROVIDER-NULL 7ossl" -.TH OSSL_PROVIDER-NULL 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_PROVIDER\-null \- OpenSSL null provider -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The OpenSSL null provider supplies no algorithms. -.PP -It can used to guarantee that the default library context and a fallback -provider will not be accidentally accessed. -.SS "Properties" -.IX Subsection "Properties" -The null provider defines no properties. -.SH "OPERATIONS AND ALGORITHMS" -.IX Header "OPERATIONS AND ALGORITHMS" -The OpenSSL null provider supports no operations and algorithms. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/OSSL_STORE-winstore.7ossl b/openssl-install/share/man/man7/OSSL_STORE-winstore.7ossl deleted file mode 100644 index d022b87c..00000000 --- a/openssl-install/share/man/man7/OSSL_STORE-winstore.7ossl +++ /dev/null @@ -1,201 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE-WINSTORE 7ossl" -.TH OSSL_STORE-WINSTORE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -OSSL_STORE\-winstore \- OpenSSL built in OSSL_STORE for Windows -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1OSSL_STORE\s0 implementation for Windows provides access to Windows' system -\&\f(CW\*(C`ROOT\*(C'\fR certificate store through URIs, using the \s-1URI\s0 scheme -\&\f(CW\*(C`org.openssl.winstore\*(C'\fR. -.SS "Supported URIs" -.IX Subsection "Supported URIs" -There is only one supported \s-1URI:\s0 -.PP -.Vb 1 -\& org.openssl.winstore: -.Ve -.PP -No authority (host, etc), no path, no query, no fragment. -.SS "Supported \s-1OSSL_STORE_SEARCH\s0 operations" -.IX Subsection "Supported OSSL_STORE_SEARCH operations" -.IP "\fBOSSL_STORE_SEARCH_by_name\fR\|(3)" 4 -.IX Item "OSSL_STORE_SEARCH_by_name" -As a matter of fact, this must be used. It is not possible to enumerate all -available certificates in the store. -.SS "Windows certificate store features" -.IX Subsection "Windows certificate store features" -Apart from diverse constraints present in the certificates themselves, the -Windows certificate store also has the ability to associate additional -constraining properties alongside a certificate in the store. This includes -both documented and undocumented capabilities: -.IP "\(bu" 4 -The documented capability to override \s-1EKU\s0 -.IP "\(bu" 4 -The undocumented capability to add name constraints -.IP "\(bu" 4 -The undocumented capability to override the certificate expiry date -.PP -\&\fISuch constraints are not checked by this \s-1OSSL_STORE\s0 implementation, and -thereby not honoured\fR. -.PP -However, once extracted with \fBOSSL_STORE_load\fR\|(3), certificates that have -constraints in their X.509 extensions will go through the usual constraint -checks when used by OpenSSL, and are thereby honoured. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \fBOSSL_STORE_open_ex\fR\|(3), \s-1\fBOSSL_STORE_SEARCH\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The winstore (\f(CW\*(C`org.openssl.winstore\*(C'\fR) implementation was added in OpenSSL -3.2.0. -.SH "NOTES" -.IX Header "NOTES" -OpenSSL uses \s-1\fBOSSL_DECODER\s0\fR\|(3) implementations under the hood. -To influence what \s-1\fBOSSL_DECODER\s0\fR\|(3) implementations are used, it's advisable -to use \fBOSSL_STORE_open_ex\fR\|(3) and set the \fIpropq\fR argument. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/RAND.7ossl b/openssl-install/share/man/man7/RAND.7ossl deleted file mode 100644 index 46fc9655..00000000 --- a/openssl-install/share/man/man7/RAND.7ossl +++ /dev/null @@ -1,212 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RAND 7ossl" -.TH RAND 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RAND -\&\- the OpenSSL random generator -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Random numbers are a vital part of cryptography, they are needed to provide -unpredictability for tasks like key generation, creating salts, and many more. -Software-based generators must be seeded with external randomness before they -can be used as a cryptographically-secure pseudo-random number generator -(\s-1CSPRNG\s0). -The availability of common hardware with special instructions and -modern operating systems, which may use items such as interrupt jitter -and network packet timings, can be reasonable sources of seeding material. -.PP -OpenSSL comes with a default implementation of the \s-1RAND API\s0 which is based on -the deterministic random bit generator (\s-1DRBG\s0) model as described in -[\s-1NIST SP 800\-90A\s0 Rev. 1]. The default random generator will initialize -automatically on first use and will be fully functional without having -to be initialized ('seeded') explicitly. -It seeds and reseeds itself automatically using trusted random sources -provided by the operating system. -.PP -As a normal application developer, you do not have to worry about any details, -just use \fBRAND_bytes\fR\|(3) to obtain random data. -Having said that, there is one important rule to obey: Always check the error -return value of \fBRAND_bytes\fR\|(3) and do not take randomness for granted. -Although (re\-)seeding is automatic, it can fail because no trusted random source -is available or the trusted source(s) temporarily fail to provide sufficient -random seed material. -In this case the \s-1CSPRNG\s0 enters an error state and ceases to provide output, -until it is able to recover from the error by reseeding itself. -For more details on reseeding and error recovery, see \s-1\fBEVP_RAND\s0\fR\|(7). -.PP -For values that should remain secret, you can use \fBRAND_priv_bytes\fR\|(3) -instead. -This method does not provide 'better' randomness, it uses the same type of -\&\s-1CSPRNG.\s0 -The intention behind using a dedicated \s-1CSPRNG\s0 exclusively for private -values is that none of its output should be visible to an attacker (e.g., -used as salt value), in order to reveal as little information as -possible about its internal state, and that a compromise of the \*(L"public\*(R" -\&\s-1CSPRNG\s0 instance will not affect the secrecy of these private values. -.PP -In the rare case where the default implementation does not satisfy your special -requirements, the default \s-1RAND\s0 internals can be replaced by your own -\&\s-1\fBEVP_RAND\s0\fR\|(3) objects. -.PP -Changing the default random generator should be necessary -only in exceptional cases and is not recommended, unless you have a profound -knowledge of cryptographic principles and understand the implications of your -changes. -.SH "DEFAULT SETUP" -.IX Header "DEFAULT SETUP" -The default OpenSSL \s-1RAND\s0 method is based on the \s-1EVP_RAND\s0 deterministic random -bit generator (\s-1DRBG\s0) classes. -A \s-1DRBG\s0 is a certain type of cryptographically-secure pseudo-random -number generator (\s-1CSPRNG\s0), which is described in [\s-1NIST SP 800\-90A\s0 Rev. 1]. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBRAND_bytes\fR\|(3), -\&\fBRAND_priv_bytes\fR\|(3), -\&\s-1\fBEVP_RAND\s0\fR\|(3), -\&\fBRAND_get0_primary\fR\|(3), -\&\s-1\fBEVP_RAND\s0\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/RSA-PSS.7ossl b/openssl-install/share/man/man7/RSA-PSS.7ossl deleted file mode 100644 index 6058c0a3..00000000 --- a/openssl-install/share/man/man7/RSA-PSS.7ossl +++ /dev/null @@ -1,189 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "RSA-PSS 7ossl" -.TH RSA-PSS 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -RSA\-PSS \- EVP_PKEY RSA\-PSS algorithm support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBRSA-PSS\fR \s-1EVP_PKEY\s0 implementation is a restricted version of the \s-1RSA\s0 -algorithm which only supports signing, verification and key generation -using \s-1PSS\s0 padding modes with optional parameter restrictions. -.PP -It has associated private key and public key formats. -.PP -This algorithm shares several control operations with the \fB\s-1RSA\s0\fR algorithm -but with some restrictions described below. -.SS "Signing and Verification" -.IX Subsection "Signing and Verification" -Signing and verification is similar to the \fB\s-1RSA\s0\fR algorithm except the -padding mode is always \s-1PSS.\s0 If the key in use has parameter restrictions then -the corresponding signature parameters are set to the restrictions: -for example, if the key can only be used with digest \s-1SHA256, MGF1 SHA256\s0 -and minimum salt length 32 then the digest, \s-1MGF1\s0 digest and salt length -will be set to \s-1SHA256, SHA256\s0 and 32 respectively. -.SS "Key Generation" -.IX Subsection "Key Generation" -By default no parameter restrictions are placed on the generated key. -.SH "NOTES" -.IX Header "NOTES" -The public key format is documented in \s-1RFC4055.\s0 -.PP -The PKCS#8 private key format used for RSA-PSS keys is similar to the \s-1RSA\s0 -format except it uses the \fBid-RSASSA-PSS\fR \s-1OID\s0 and the parameters field, if -present, restricts the key parameters in the same way as the public key. -.SH "CONFORMING TO" -.IX Header "CONFORMING TO" -\&\s-1RFC 4055\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_md\fR\|(3), -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md\fR\|(3), -\&\fBEVP_PKEY_CTX_set_rsa_pss_keygen_saltlen\fR\|(3), -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_CTX_ctrl_str\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/RSA.7ossl b/openssl-install/share/man/man7/RSA.7ossl deleted file mode 120000 index 95ecf373..00000000 --- a/openssl-install/share/man/man7/RSA.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-RSA.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/SM2.7ossl b/openssl-install/share/man/man7/SM2.7ossl deleted file mode 120000 index a439e053..00000000 --- a/openssl-install/share/man/man7/SM2.7ossl +++ /dev/null @@ -1 +0,0 @@ -EVP_PKEY-SM2.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/X25519.7ossl b/openssl-install/share/man/man7/X25519.7ossl deleted file mode 100644 index 89c31756..00000000 --- a/openssl-install/share/man/man7/X25519.7ossl +++ /dev/null @@ -1,210 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X25519 7ossl" -.TH X25519 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -X25519, -X448 -\&\- EVP_PKEY X25519 and X448 support -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fBX25519\fR and \fBX448\fR \s-1EVP_PKEY\s0 implementation supports key generation and -key derivation using \fBX25519\fR and \fBX448\fR. It has associated private and public -key formats compatible with \s-1RFC 8410.\s0 -.PP -No additional parameters can be set during key generation. -.PP -The peer public key must be set using \fBEVP_PKEY_derive_set_peer()\fR when -performing key derivation. -.SH "NOTES" -.IX Header "NOTES" -A context for the \fBX25519\fR algorithm can be obtained by calling: -.PP -.Vb 1 -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X25519, NULL); -.Ve -.PP -For the \fBX448\fR algorithm a context can be obtained by calling: -.PP -.Vb 1 -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X448, NULL); -.Ve -.PP -X25519 or X448 private keys can be set directly using -\&\fBEVP_PKEY_new_raw_private_key\fR\|(3) or loaded from a PKCS#8 private key file -using \fBPEM_read_bio_PrivateKey\fR\|(3) (or similar function). Completely new keys -can also be generated (see the example below). Setting a private key also sets -the associated public key. -.PP -X25519 or X448 public keys can be set directly using -\&\fBEVP_PKEY_new_raw_public_key\fR\|(3) or loaded from a SubjectPublicKeyInfo -structure in a \s-1PEM\s0 file using \fBPEM_read_bio_PUBKEY\fR\|(3) (or similar function). -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This example generates an \fBX25519\fR private key and writes it to standard -output in \s-1PEM\s0 format: -.PP -.Vb 9 -\& #include -\& #include -\& ... -\& EVP_PKEY *pkey = NULL; -\& EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_X25519, NULL); -\& EVP_PKEY_keygen_init(pctx); -\& EVP_PKEY_keygen(pctx, &pkey); -\& EVP_PKEY_CTX_free(pctx); -\& PEM_write_PrivateKey(stdout, pkey, NULL, NULL, 0, NULL, NULL); -.Ve -.PP -The key derivation example in \fBEVP_PKEY_derive\fR\|(3) can be used with -\&\fBX25519\fR and \fBX448\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_CTX_new\fR\|(3), -\&\fBEVP_PKEY_keygen\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3), -\&\fBEVP_PKEY_derive_set_peer\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2017\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/X448.7ossl b/openssl-install/share/man/man7/X448.7ossl deleted file mode 120000 index 607b7d10..00000000 --- a/openssl-install/share/man/man7/X448.7ossl +++ /dev/null @@ -1 +0,0 @@ -X25519.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/bio.7ossl b/openssl-install/share/man/man7/bio.7ossl deleted file mode 100644 index 2f0ae283..00000000 --- a/openssl-install/share/man/man7/bio.7ossl +++ /dev/null @@ -1,241 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "BIO 7ossl" -.TH BIO 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -bio \- Basic I/O abstraction -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -A \s-1BIO\s0 is an I/O abstraction, it hides many of the underlying I/O -details from an application. If an application uses a \s-1BIO\s0 for its -I/O it can transparently handle \s-1SSL\s0 connections, unencrypted network -connections and file I/O. -.PP -There are two types of \s-1BIO,\s0 a source/sink \s-1BIO\s0 and a filter \s-1BIO.\s0 -.PP -As its name implies a source/sink \s-1BIO\s0 is a source and/or sink of data, -examples include a socket \s-1BIO\s0 and a file \s-1BIO.\s0 -.PP -A filter \s-1BIO\s0 takes data from one \s-1BIO\s0 and passes it through to -another, or the application. The data may be left unmodified (for -example a message digest \s-1BIO\s0) or translated (for example an -encryption \s-1BIO\s0). The effect of a filter \s-1BIO\s0 may change according -to the I/O operation it is performing: for example an encryption -\&\s-1BIO\s0 will encrypt data if it is being written to and decrypt data -if it is being read from. -.PP -BIOs can be joined together to form a chain (a single \s-1BIO\s0 is a chain -with one component). A chain normally consists of one source/sink -\&\s-1BIO\s0 and one or more filter BIOs. Data read from or written to the -first \s-1BIO\s0 then traverses the chain to the end (normally a source/sink -\&\s-1BIO\s0). -.PP -Some BIOs (such as memory BIOs) can be used immediately after calling -\&\fBBIO_new()\fR. Others (such as file BIOs) need some additional initialization, -and frequently a utility function exists to create and initialize such BIOs. -.PP -If \fBBIO_free()\fR is called on a \s-1BIO\s0 chain it will only free one \s-1BIO\s0 resulting -in a memory leak. -.PP -Calling \fBBIO_free_all()\fR on a single \s-1BIO\s0 has the same effect as calling -\&\fBBIO_free()\fR on it other than the discarded return value. -.PP -Normally the \fItype\fR argument is supplied by a function which returns a -pointer to a \s-1BIO_METHOD.\s0 There is a naming convention for such functions: -a source/sink \s-1BIO\s0 typically starts with \fIBIO_s_\fR and -a filter \s-1BIO\s0 with \fIBIO_f_\fR. -.SS "\s-1TCP\s0 Fast Open" -.IX Subsection "TCP Fast Open" -\&\s-1TCP\s0 Fast Open (\s-1RFC7413\s0), abbreviated \*(L"\s-1TFO\*(R",\s0 is supported by the \s-1BIO\s0 -interface since OpenSSL 3.2. \s-1TFO\s0 is supported in the following operating systems: -.IP "\(bu" 4 -Linux kernel 3.13 and later, where \s-1TFO\s0 is enabled by default. -.IP "\(bu" 4 -Linux kernel 4.11 and later, using \s-1TCP_FASTOPEN_CONNECT.\s0 -.IP "\(bu" 4 -FreeBSD 10.3 to 11.4, supports server \s-1TFO\s0 only. -.IP "\(bu" 4 -FreeBSD 12.0 and later, supports both client and server \s-1TFO.\s0 -.IP "\(bu" 4 -macOS 10.14 and later. -.PP -Each operating system has a slightly different \s-1API\s0 for \s-1TFO.\s0 Please -refer to the operating systems' \s-1API\s0 documentation when using -sockets directly. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -Create a memory \s-1BIO:\s0 -.PP -.Vb 1 -\& BIO *mem = BIO_new(BIO_s_mem()); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBIO_ctrl\fR\|(3), -\&\fBBIO_f_base64\fR\|(3), \fBBIO_f_buffer\fR\|(3), -\&\fBBIO_f_cipher\fR\|(3), \fBBIO_f_md\fR\|(3), -\&\fBBIO_f_null\fR\|(3), \fBBIO_f_ssl\fR\|(3), -\&\fBBIO_f_readbuffer\fR\|(3), -\&\fBBIO_find_type\fR\|(3), -\&\fBBIO_get_conn_mode\fR\|(3), -\&\fBBIO_new\fR\|(3), -\&\fBBIO_new_bio_pair\fR\|(3), -\&\fBBIO_push\fR\|(3), \fBBIO_read_ex\fR\|(3), -\&\fBBIO_s_accept\fR\|(3), \fBBIO_s_bio\fR\|(3), -\&\fBBIO_s_connect\fR\|(3), \fBBIO_s_fd\fR\|(3), -\&\fBBIO_s_file\fR\|(3), \fBBIO_s_mem\fR\|(3), -\&\fBBIO_s_null\fR\|(3), \fBBIO_s_socket\fR\|(3), -\&\fBBIO_set_callback\fR\|(3), -\&\fBBIO_set_conn_mode\fR\|(3), -\&\fBBIO_set_tfo\fR\|(3), -\&\fBBIO_set_tfo_accept\fR\|(3), -\&\fBBIO_should_retry\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/crypto.7ossl b/openssl-install/share/man/man7/crypto.7ossl deleted file mode 120000 index 92157744..00000000 --- a/openssl-install/share/man/man7/crypto.7ossl +++ /dev/null @@ -1 +0,0 @@ -ossl-guide-libcrypto-introduction.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/ct.7ossl b/openssl-install/share/man/man7/ct.7ossl deleted file mode 100644 index 5342a64b..00000000 --- a/openssl-install/share/man/man7/ct.7ossl +++ /dev/null @@ -1,185 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "CT 7ossl" -.TH CT 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ct \- Certificate Transparency -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This library implements Certificate Transparency (\s-1CT\s0) verification for \s-1TLS\s0 -clients, as defined in \s-1RFC 6962.\s0 This verification can provide some confidence -that a certificate has been publicly logged in a set of \s-1CT\s0 logs. -.PP -By default, these checks are disabled. They can be enabled using -\&\fBSSL_CTX_enable_ct\fR\|(3) or \fBSSL_enable_ct\fR\|(3). -.PP -This library can also be used to parse and examine \s-1CT\s0 data structures, such as -Signed Certificate Timestamps (SCTs), or to read a list of \s-1CT\s0 logs. There are -functions for: -\&\- decoding and encoding SCTs in \s-1DER\s0 and \s-1TLS\s0 wire format. -\&\- printing SCTs. -\&\- verifying the authenticity of SCTs. -\&\- loading a \s-1CT\s0 log list from a \s-1CONF\s0 file. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBd2i_SCT_LIST\fR\|(3), -\&\fBCTLOG_STORE_new\fR\|(3), -\&\fBCTLOG_STORE_get0_log_by_id\fR\|(3), -\&\fBSCT_new\fR\|(3), -\&\fBSCT_print\fR\|(3), -\&\fBSCT_validate\fR\|(3), -\&\fBSCT_validate\fR\|(3), -\&\fBCT_POLICY_EVAL_CTX_new\fR\|(3), -\&\fBSSL_CTX_set_ct_validation_callback\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The ct library was added in OpenSSL 1.1.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/des_modes.7ossl b/openssl-install/share/man/man7/des_modes.7ossl deleted file mode 100644 index 8fbc8168..00000000 --- a/openssl-install/share/man/man7/des_modes.7ossl +++ /dev/null @@ -1,295 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "DES_MODES 7ossl" -.TH DES_MODES 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -des_modes \- the variants of DES and other crypto algorithms of OpenSSL -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Several crypto algorithms for OpenSSL can be used in a number of modes. Those -are used for using block ciphers in a way similar to stream ciphers, among -other things. -.SH "OVERVIEW" -.IX Header "OVERVIEW" -.SS "Electronic Codebook Mode (\s-1ECB\s0)" -.IX Subsection "Electronic Codebook Mode (ECB)" -Normally, this is found as the function \fIalgorithm\fR\fB_ecb_encrypt()\fR. -.IP "\(bu" 2 -64 bits are enciphered at a time. -.IP "\(bu" 2 -The order of the blocks can be rearranged without detection. -.IP "\(bu" 2 -The same plaintext block always produces the same ciphertext block -(for the same key) making it vulnerable to a 'dictionary attack'. -.IP "\(bu" 2 -An error will only affect one ciphertext block. -.SS "Cipher Block Chaining Mode (\s-1CBC\s0)" -.IX Subsection "Cipher Block Chaining Mode (CBC)" -Normally, this is found as the function \fIalgorithm\fR\fB_cbc_encrypt()\fR. -Be aware that \fBdes_cbc_encrypt()\fR is not really \s-1DES CBC\s0 (it does -not update the \s-1IV\s0); use \fBdes_ncbc_encrypt()\fR instead. -.IP "\(bu" 2 -a multiple of 64 bits are enciphered at a time. -.IP "\(bu" 2 -The \s-1CBC\s0 mode produces the same ciphertext whenever the same -plaintext is encrypted using the same key and starting variable. -.IP "\(bu" 2 -The chaining operation makes the ciphertext blocks dependent on the -current and all preceding plaintext blocks and therefore blocks can not -be rearranged. -.IP "\(bu" 2 -The use of different starting variables prevents the same plaintext -enciphering to the same ciphertext. -.IP "\(bu" 2 -An error will affect the current and the following ciphertext blocks. -.SS "Cipher Feedback Mode (\s-1CFB\s0)" -.IX Subsection "Cipher Feedback Mode (CFB)" -Normally, this is found as the function \fIalgorithm\fR\fB_cfb_encrypt()\fR. -.IP "\(bu" 2 -a number of bits (j) <= 64 are enciphered at a time. -.IP "\(bu" 2 -The \s-1CFB\s0 mode produces the same ciphertext whenever the same -plaintext is encrypted using the same key and starting variable. -.IP "\(bu" 2 -The chaining operation makes the ciphertext variables dependent on the -current and all preceding variables and therefore j\-bit variables are -chained together and can not be rearranged. -.IP "\(bu" 2 -The use of different starting variables prevents the same plaintext -enciphering to the same ciphertext. -.IP "\(bu" 2 -The strength of the \s-1CFB\s0 mode depends on the size of k (maximal if -j == k). In my implementation this is always the case. -.IP "\(bu" 2 -Selection of a small value for j will require more cycles through -the encipherment algorithm per unit of plaintext and thus cause -greater processing overheads. -.IP "\(bu" 2 -Only multiples of j bits can be enciphered. -.IP "\(bu" 2 -An error will affect the current and the following ciphertext variables. -.SS "Output Feedback Mode (\s-1OFB\s0)" -.IX Subsection "Output Feedback Mode (OFB)" -Normally, this is found as the function \fIalgorithm\fR\fB_ofb_encrypt()\fR. -.IP "\(bu" 2 -a number of bits (j) <= 64 are enciphered at a time. -.IP "\(bu" 2 -The \s-1OFB\s0 mode produces the same ciphertext whenever the same -plaintext enciphered using the same key and starting variable. More -over, in the \s-1OFB\s0 mode the same key stream is produced when the same -key and start variable are used. Consequently, for security reasons -a specific start variable should be used only once for a given key. -.IP "\(bu" 2 -The absence of chaining makes the \s-1OFB\s0 more vulnerable to specific attacks. -.IP "\(bu" 2 -The use of different start variables values prevents the same -plaintext enciphering to the same ciphertext, by producing different -key streams. -.IP "\(bu" 2 -Selection of a small value for j will require more cycles through -the encipherment algorithm per unit of plaintext and thus cause -greater processing overheads. -.IP "\(bu" 2 -Only multiples of j bits can be enciphered. -.IP "\(bu" 2 -\&\s-1OFB\s0 mode of operation does not extend ciphertext errors in the -resultant plaintext output. Every bit error in the ciphertext causes -only one bit to be in error in the deciphered plaintext. -.IP "\(bu" 2 -\&\s-1OFB\s0 mode is not self-synchronizing. If the two operation of -encipherment and decipherment get out of synchronism, the system needs -to be re-initialized. -.IP "\(bu" 2 -Each re-initialization should use a value of the start variable -different from the start variable values used before with the same -key. The reason for this is that an identical bit stream would be -produced each time from the same parameters. This would be -susceptible to a 'known plaintext' attack. -.SS "Triple \s-1ECB\s0 Mode" -.IX Subsection "Triple ECB Mode" -Normally, this is found as the function \fIalgorithm\fR\fB_ecb3_encrypt()\fR. -.IP "\(bu" 2 -Encrypt with key1, decrypt with key2 and encrypt with key3 again. -.IP "\(bu" 2 -As for \s-1ECB\s0 encryption but increases the key length to 168 bits. -There are theoretic attacks that can be used that make the effective -key length 112 bits, but this attack also requires 2^56 blocks of -memory, not very likely, even for the \s-1NSA.\s0 -.IP "\(bu" 2 -If both keys are the same it is equivalent to encrypting once with -just one key. -.IP "\(bu" 2 -If the first and last key are the same, the key length is 112 bits. -There are attacks that could reduce the effective key strength -to only slightly more than 56 bits, but these require a lot of memory. -.IP "\(bu" 2 -If all 3 keys are the same, this is effectively the same as normal -ecb mode. -.SS "Triple \s-1CBC\s0 Mode" -.IX Subsection "Triple CBC Mode" -Normally, this is found as the function \fIalgorithm\fR\fB_ede3_cbc_encrypt()\fR. -.IP "\(bu" 2 -Encrypt with key1, decrypt with key2 and then encrypt with key3. -.IP "\(bu" 2 -As for \s-1CBC\s0 encryption but increases the key length to 168 bits with -the same restrictions as for triple ecb mode. -.SH "NOTES" -.IX Header "NOTES" -This text was been written in large parts by Eric Young in his original -documentation for SSLeay, the predecessor of OpenSSL. In turn, he attributed -it to: -.PP -.Vb 5 -\& AS 2805.5.2 -\& Australian Standard -\& Electronic funds transfer \- Requirements for interfaces, -\& Part 5.2: Modes of operation for an n\-bit block cipher algorithm -\& Appendix A -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBBF_encrypt\fR\|(3), \fBDES_crypt\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2017 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/evp.7ossl b/openssl-install/share/man/man7/evp.7ossl deleted file mode 100644 index 0789f8c8..00000000 --- a/openssl-install/share/man/man7/evp.7ossl +++ /dev/null @@ -1,238 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "EVP 7ossl" -.TH EVP 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -evp \- high\-level cryptographic functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1EVP\s0 library provides a high-level interface to cryptographic -functions. -.PP -The \fBEVP_Seal\fR\fI\s-1XXX\s0\fR and \fBEVP_Open\fR\fI\s-1XXX\s0\fR -functions provide public key encryption and decryption to implement digital \*(L"envelopes\*(R". -.PP -The \fBEVP_DigestSign\fR\fI\s-1XXX\s0\fR and -\&\fBEVP_DigestVerify\fR\fI\s-1XXX\s0\fR functions implement -digital signatures and Message Authentication Codes (MACs). Also see the older -\&\fBEVP_Sign\fR\fI\s-1XXX\s0\fR and \fBEVP_Verify\fR\fI\s-1XXX\s0\fR -functions. -.PP -Symmetric encryption is available with the \fBEVP_Encrypt\fR\fI\s-1XXX\s0\fR -functions. The \fBEVP_Digest\fR\fI\s-1XXX\s0\fR functions provide message digests. -.PP -The \fB\s-1EVP_PKEY\s0\fR\fI\s-1XXX\s0\fR functions provide a high-level interface to -asymmetric algorithms. To create a new \s-1EVP_PKEY\s0 see -\&\fBEVP_PKEY_new\fR\|(3). EVP_PKEYs can be associated -with a private key of a particular algorithm by using the functions -described on the \fBEVP_PKEY_fromdata\fR\|(3) page, or -new keys can be generated using \fBEVP_PKEY_keygen\fR\|(3). -EVP_PKEYs can be compared using \fBEVP_PKEY_eq\fR\|(3), or printed using -\&\fBEVP_PKEY_print_private\fR\|(3). \fBEVP_PKEY_todata\fR\|(3) can be used to convert a -key back into an \s-1\fBOSSL_PARAM\s0\fR\|(3) array. -.PP -The \s-1EVP_PKEY\s0 functions support the full range of asymmetric algorithm operations: -.IP "For key agreement see \fBEVP_PKEY_derive\fR\|(3)" 4 -.IX Item "For key agreement see EVP_PKEY_derive" -.PD 0 -.IP "For signing and verifying see \fBEVP_PKEY_sign\fR\|(3), \fBEVP_PKEY_verify\fR\|(3) and \fBEVP_PKEY_verify_recover\fR\|(3). However, note that these functions do not perform a digest of the data to be signed. Therefore, normally you would use the \fBEVP_DigestSignInit\fR\|(3) functions for this purpose." 4 -.IX Item "For signing and verifying see EVP_PKEY_sign, EVP_PKEY_verify and EVP_PKEY_verify_recover. However, note that these functions do not perform a digest of the data to be signed. Therefore, normally you would use the EVP_DigestSignInit functions for this purpose." -.ie n .IP "For encryption and decryption see \fBEVP_PKEY_encrypt\fR\|(3) and \fBEVP_PKEY_decrypt\fR\|(3) respectively. However, note that these functions perform encryption and decryption only. As public key encryption is an expensive operation, normally you would wrap an encrypted message in a ""digital envelope"" using the \fBEVP_SealInit\fR\|(3) and \fBEVP_OpenInit\fR\|(3) functions." 4 -.el .IP "For encryption and decryption see \fBEVP_PKEY_encrypt\fR\|(3) and \fBEVP_PKEY_decrypt\fR\|(3) respectively. However, note that these functions perform encryption and decryption only. As public key encryption is an expensive operation, normally you would wrap an encrypted message in a ``digital envelope'' using the \fBEVP_SealInit\fR\|(3) and \fBEVP_OpenInit\fR\|(3) functions." 4 -.IX Item "For encryption and decryption see EVP_PKEY_encrypt and EVP_PKEY_decrypt respectively. However, note that these functions perform encryption and decryption only. As public key encryption is an expensive operation, normally you would wrap an encrypted message in a digital envelope using the EVP_SealInit and EVP_OpenInit functions." -.PD -.PP -The \fBEVP_BytesToKey\fR\|(3) function provides some limited support for password -based encryption. Careful selection of the parameters will provide a PKCS#5 \s-1PBKDF1\s0 compatible -implementation. However, new applications should not typically use this (preferring, for example, -\&\s-1PBKDF2\s0 from PCKS#5). -.PP -The \fBEVP_Encode\fR\fI\s-1XXX\s0\fR and -\&\fBEVP_Decode\fR\fI\s-1XXX\s0\fR functions implement base64 encoding -and decoding. -.PP -All the symmetric algorithms (ciphers), digests and asymmetric algorithms -(public key algorithms) can be replaced by \s-1ENGINE\s0 modules providing alternative -implementations. If \s-1ENGINE\s0 implementations of ciphers or digests are registered -as defaults, then the various \s-1EVP\s0 functions will automatically use those -implementations automatically in preference to built in software -implementations. For more information, consult the \fBengine\fR\|(3) man page. -.PP -Although low-level algorithm specific functions exist for many algorithms -their use is discouraged. They cannot be used with an \s-1ENGINE\s0 and \s-1ENGINE\s0 -versions of new algorithms cannot be accessed using the low-level functions. -Also makes code harder to adapt to new algorithms and some options are not -cleanly supported at the low-level and some operations are more efficient -using the high-level interface. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestInit\fR\|(3), -\&\fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_OpenInit\fR\|(3), -\&\fBEVP_SealInit\fR\|(3), -\&\fBEVP_DigestSignInit\fR\|(3), -\&\fBEVP_SignInit\fR\|(3), -\&\fBEVP_VerifyInit\fR\|(3), -\&\fBEVP_EncodeInit\fR\|(3), -\&\fBEVP_PKEY_new\fR\|(3), -\&\fBEVP_PKEY_fromdata\fR\|(3), -\&\fBEVP_PKEY_todata\fR\|(3), -\&\fBEVP_PKEY_keygen\fR\|(3), -\&\fBEVP_PKEY_print_private\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), -\&\fBEVP_PKEY_verify\fR\|(3), -\&\fBEVP_PKEY_verify_recover\fR\|(3), -\&\fBEVP_PKEY_derive\fR\|(3), -\&\fBEVP_BytesToKey\fR\|(3), -\&\fBENGINE_by_id\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/fips_module.7ossl b/openssl-install/share/man/man7/fips_module.7ossl deleted file mode 100644 index 035ef43a..00000000 --- a/openssl-install/share/man/man7/fips_module.7ossl +++ /dev/null @@ -1,721 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "FIPS_MODULE 7ossl" -.TH FIPS_MODULE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -fips_module \- OpenSSL fips module guide -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -See the individual manual pages for details. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This guide details different ways that OpenSSL can be used in conjunction -with the \s-1FIPS\s0 module. Which is the correct approach to use will depend on your -own specific circumstances and what you are attempting to achieve. -.PP -For information related to installing the \s-1FIPS\s0 module see -. -.PP -Note that the old functions \fBFIPS_mode()\fR and \fBFIPS_mode_set()\fR are no longer -present so you must remove them from your application if you use them. -.PP -Applications written to use the OpenSSL 3.0 \s-1FIPS\s0 module should not use any -legacy APIs or features that avoid the \s-1FIPS\s0 module. Specifically this includes: -.IP "\(bu" 4 -Low level cryptographic APIs (use the high level APIs, such as \s-1EVP,\s0 instead) -.IP "\(bu" 4 -Engines -.IP "\(bu" 4 -Any functions that create or modify custom \*(L"\s-1METHODS\*(R"\s0 (for example -\&\fBEVP_MD_meth_new()\fR, \fBEVP_CIPHER_meth_new()\fR, \fBEVP_PKEY_meth_new()\fR, \fBRSA_meth_new()\fR, -\&\fBEC_KEY_METHOD_new()\fR, etc.) -.PP -All of the above APIs are deprecated in OpenSSL 3.0 \- so a simple rule is to -avoid using all deprecated functions. See \fBossl\-guide\-migration\fR\|(7) for a list of -deprecated functions. -.SS "Making all applications use the \s-1FIPS\s0 module by default" -.IX Subsection "Making all applications use the FIPS module by default" -One simple approach is to cause all applications that are using OpenSSL to only -use the \s-1FIPS\s0 module for cryptographic algorithms by default. -.PP -This approach can be done purely via configuration. As long as applications are -built and linked against OpenSSL 3.0 and do not override the loading of the -default config file or its settings then they can automatically start using the -\&\s-1FIPS\s0 module without the need for any further code changes. -.PP -To do this the default OpenSSL config file will have to be modified. The -location of this config file will depend on the platform, and any options that -were given during the build process. You can check the location of the config -file by running this command: -.PP -.Vb 2 -\& $ openssl version \-d -\& OPENSSLDIR: "/usr/local/ssl" -.Ve -.PP -Caution: Many Operating Systems install OpenSSL by default. It is a common error -to not have the correct version of OpenSSL in your \f(CW$PATH\fR. Check that you are -running an OpenSSL 3.0 version like this: -.PP -.Vb 2 -\& $ openssl version \-v -\& OpenSSL 3.0.0\-dev xx XXX xxxx (Library: OpenSSL 3.0.0\-dev xx XXX xxxx) -.Ve -.PP -The \fB\s-1OPENSSLDIR\s0\fR value above gives the directory name for where the default -config file is stored. So in this case the default config file will be called -\&\fI/usr/local/ssl/openssl.cnf\fR. -.PP -Edit the config file to add the following lines near the beginning: -.PP -.Vb 2 -\& config_diagnostics = 1 -\& openssl_conf = openssl_init -\& -\& .include /usr/local/ssl/fipsmodule.cnf -\& -\& [openssl_init] -\& providers = provider_sect -\& alg_section = algorithm_sect -\& -\& [provider_sect] -\& fips = fips_sect -\& base = base_sect -\& -\& [base_sect] -\& activate = 1 -\& -\& [algorithm_sect] -\& default_properties = fips=yes -.Ve -.PP -Obviously the include file location above should match the path and name of the -\&\s-1FIPS\s0 module config file that you installed earlier. -See . -.PP -For \s-1FIPS\s0 usage, it is recommended that the \fBconfig_diagnostics\fR option is -enabled to prevent accidental use of non-FIPS validated algorithms via broken -or mistaken configuration. See \fBconfig\fR\|(5). -.PP -Any applications that use OpenSSL 3.0 and are started after these changes are -made will start using only the \s-1FIPS\s0 module unless those applications take -explicit steps to avoid this default behaviour. Note that this configuration -also activates the \*(L"base\*(R" provider. The base provider does not include any -cryptographic algorithms (and therefore does not impact the validation status of -any cryptographic operations), but does include other supporting algorithms that -may be required. It is designed to be used in conjunction with the \s-1FIPS\s0 module. -.PP -This approach has the primary advantage that it is simple, and no code changes -are required in applications in order to benefit from the \s-1FIPS\s0 module. There are -some disadvantages to this approach: -.IP "\(bu" 4 -You may not want all applications to use the \s-1FIPS\s0 module. -.Sp -It may be the case that some applications should and some should not use the -\&\s-1FIPS\s0 module. -.IP "\(bu" 4 -If applications take explicit steps to not load the default config file or -set different settings. -.Sp -This method will not work for these cases. -.IP "\(bu" 4 -The algorithms available in the \s-1FIPS\s0 module are a subset of the algorithms -that are available in the default OpenSSL Provider. -.Sp -If any applications attempt to use any algorithms that are not present, -then they will fail. -.IP "\(bu" 4 -Usage of certain deprecated APIs avoids the use of the \s-1FIPS\s0 module. -.Sp -If any applications use those APIs then the \s-1FIPS\s0 module will not be used. -.SS "Selectively making applications use the \s-1FIPS\s0 module by default" -.IX Subsection "Selectively making applications use the FIPS module by default" -A variation on the above approach is to do the same thing on an individual -application basis. The default OpenSSL config file depends on the compiled in -value for \fB\s-1OPENSSLDIR\s0\fR as described in the section above. However it is also -possible to override the config file to be used via the \fB\s-1OPENSSL_CONF\s0\fR -environment variable. For example the following, on Unix, will cause the -application to be executed with a non-standard config file location: -.PP -.Vb 1 -\& $ OPENSSL_CONF=/my/nondefault/openssl.cnf myapplication -.Ve -.PP -Using this mechanism you can control which config file is loaded (and hence -whether the \s-1FIPS\s0 module is loaded) on an application by application basis. -.PP -This removes the disadvantage listed above that you may not want all -applications to use the \s-1FIPS\s0 module. All the other advantages and disadvantages -still apply. -.SS "Programmatically loading the \s-1FIPS\s0 module (default library context)" -.IX Subsection "Programmatically loading the FIPS module (default library context)" -Applications may choose to load the \s-1FIPS\s0 provider explicitly rather than relying -on config to do this. The config file is still necessary in order to hold the -\&\s-1FIPS\s0 module config data (such as its self test status and integrity data). But -in this case we do not automatically activate the \s-1FIPS\s0 provider via that config -file. -.PP -To do things this way configure as per -\&\*(L"Making all applications use the \s-1FIPS\s0 module by default\*(R" above, but edit the -\&\fIfipsmodule.cnf\fR file to remove or comment out the line which says -\&\f(CW\*(C`activate = 1\*(C'\fR (note that setting this value to 0 is \fInot\fR sufficient). -This means all the required config information will be available to load the -\&\s-1FIPS\s0 module, but it is not automatically loaded when the application starts. The -\&\s-1FIPS\s0 provider can then be loaded programmatically like this: -.PP -.Vb 1 -\& #include -\& -\& int main(void) -\& { -\& OSSL_PROVIDER *fips; -\& OSSL_PROVIDER *base; -\& -\& fips = OSSL_PROVIDER_load(NULL, "fips"); -\& if (fips == NULL) { -\& printf("Failed to load FIPS provider\en"); -\& exit(EXIT_FAILURE); -\& } -\& base = OSSL_PROVIDER_load(NULL, "base"); -\& if (base == NULL) { -\& OSSL_PROVIDER_unload(fips); -\& printf("Failed to load base provider\en"); -\& exit(EXIT_FAILURE); -\& } -\& -\& /* Rest of application */ -\& -\& OSSL_PROVIDER_unload(base); -\& OSSL_PROVIDER_unload(fips); -\& exit(EXIT_SUCCESS); -\& } -.Ve -.PP -Note that this should be one of the first things that you do in your -application. If any OpenSSL functions get called that require the use of -cryptographic functions before this occurs then, if no provider has yet been -loaded, then the default provider will be automatically loaded. If you then -later explicitly load the \s-1FIPS\s0 provider then you will have both the \s-1FIPS\s0 and the -default provider loaded at the same time. It is unspecified which implementation -of an algorithm will be used if multiple implementations are available and you -have not explicitly specified via a property query (see below) which one should -be used. -.PP -Also note that in this example we have additionally loaded the \*(L"base\*(R" provider. -This loads a sub-set of algorithms that are also available in the default -provider \- specifically non cryptographic ones which may be used in conjunction -with the \s-1FIPS\s0 provider. For example this contains algorithms for encoding and -decoding keys. If you decide not to load the default provider then you -will usually want to load the base provider instead. -.PP -In this example we are using the \*(L"default\*(R" library context. OpenSSL functions -operate within the scope of a library context. If no library context is -explicitly specified then the default library context is used. For further -details about library contexts see the \s-1\fBOSSL_LIB_CTX\s0\fR\|(3) man page. -.SS "Loading the \s-1FIPS\s0 module at the same time as other providers" -.IX Subsection "Loading the FIPS module at the same time as other providers" -It is possible to have the \s-1FIPS\s0 provider and other providers (such as the -default provider) all loaded at the same time into the same library context. You -can use a property query string during algorithm fetches to specify which -implementation you would like to use. -.PP -For example to fetch an implementation of \s-1SHA256\s0 which conforms to \s-1FIPS\s0 -standards you can specify the property query \f(CW\*(C`fips=yes\*(C'\fR like this: -.PP -.Vb 1 -\& EVP_MD *sha256; -\& -\& sha256 = EVP_MD_fetch(NULL, "SHA2\-256", "fips=yes"); -.Ve -.PP -If no property query is specified, or more than one implementation matches the -property query then it is unspecified which implementation of a particular -algorithm will be returned. -.PP -This example shows an explicit request for an implementation of \s-1SHA256\s0 from the -default provider: -.PP -.Vb 1 -\& EVP_MD *sha256; -\& -\& sha256 = EVP_MD_fetch(NULL, "SHA2\-256", "provider=default"); -.Ve -.PP -It is also possible to set a default property query string. The following -example sets the default property query of \f(CW\*(C`fips=yes\*(C'\fR for all fetches within -the default library context: -.PP -.Vb 1 -\& EVP_set_default_properties(NULL, "fips=yes"); -.Ve -.PP -If a fetch function has both an explicit property query specified, and a -default property query is defined then the two queries are merged together and -both apply. The local property query overrides the default properties if the -same property name is specified in both. -.PP -There are two important built-in properties that you should be aware of: -.PP -The \*(L"provider\*(R" property enables you to specify which provider you want an -implementation to be fetched from, e.g. \f(CW\*(C`provider=default\*(C'\fR or \f(CW\*(C`provider=fips\*(C'\fR. -All algorithms implemented in a provider have this property set on them. -.PP -There is also the \f(CW\*(C`fips\*(C'\fR property. All \s-1FIPS\s0 algorithms match against the -property query \f(CW\*(C`fips=yes\*(C'\fR. There are also some non-cryptographic algorithms -available in the default and base providers that also have the \f(CW\*(C`fips=yes\*(C'\fR -property defined for them. These are the encoder and decoder algorithms that -can (for example) be used to write out a key generated in the \s-1FIPS\s0 provider to a -file. The encoder and decoder algorithms are not in the \s-1FIPS\s0 module itself but -are allowed to be used in conjunction with the \s-1FIPS\s0 algorithms. -.PP -It is possible to specify default properties within a config file. For example -the following config file automatically loads the default and \s-1FIPS\s0 providers and -sets the default property value to be \f(CW\*(C`fips=yes\*(C'\fR. Note that this config file -does not load the \*(L"base\*(R" provider. All supporting algorithms that are in \*(L"base\*(R" -are also in \*(L"default\*(R", so it is unnecessary in this case: -.PP -.Vb 2 -\& config_diagnostics = 1 -\& openssl_conf = openssl_init -\& -\& .include /usr/local/ssl/fipsmodule.cnf -\& -\& [openssl_init] -\& providers = provider_sect -\& alg_section = algorithm_sect -\& -\& [provider_sect] -\& fips = fips_sect -\& default = default_sect -\& -\& [default_sect] -\& activate = 1 -\& -\& [algorithm_sect] -\& default_properties = fips=yes -.Ve -.SS "Programmatically loading the \s-1FIPS\s0 module (nondefault library context)" -.IX Subsection "Programmatically loading the FIPS module (nondefault library context)" -In addition to using properties to separate usage of the \s-1FIPS\s0 module from other -usages this can also be achieved using library contexts. In this example we -create two library contexts. In one we assume the existence of a config file -called \fIopenssl\-fips.cnf\fR that automatically loads and configures the \s-1FIPS\s0 and -base providers. The other library context will just use the default provider. -.PP -.Vb 4 -\& OSSL_LIB_CTX *fips_libctx, *nonfips_libctx; -\& OSSL_PROVIDER *defctxnull = NULL; -\& EVP_MD *fipssha256 = NULL, *nonfipssha256 = NULL; -\& int ret = 1; -\& -\& /* -\& * Create two nondefault library contexts. One for fips usage and -\& * one for non\-fips usage -\& */ -\& fips_libctx = OSSL_LIB_CTX_new(); -\& nonfips_libctx = OSSL_LIB_CTX_new(); -\& if (fips_libctx == NULL || nonfips_libctx == NULL) -\& goto err; -\& -\& /* Prevent anything from using the default library context */ -\& defctxnull = OSSL_PROVIDER_load(NULL, "null"); -\& -\& /* -\& * Load config file for the FIPS library context. We assume that -\& * this config file will automatically activate the FIPS and base -\& * providers so we don\*(Aqt need to explicitly load them here. -\& */ -\& if (!OSSL_LIB_CTX_load_config(fips_libctx, "openssl\-fips.cnf")) -\& goto err; -\& -\& /* -\& * Set the default property query on the FIPS library context to -\& * ensure that only FIPS algorithms can be used. There are a few non\-FIPS -\& * approved algorithms in the FIPS provider for backward compatibility reasons. -\& */ -\& if (!EVP_set_default_properties(fips_libctx, "fips=yes")) -\& goto err; -\& -\& /* -\& * We don\*(Aqt need to do anything special to load the default -\& * provider into nonfips_libctx. This happens automatically if no -\& * other providers are loaded. -\& * Because we don\*(Aqt call OSSL_LIB_CTX_load_config() explicitly for -\& * nonfips_libctx it will just use the default config file. -\& */ -\& -\& /* As an example get some digests */ -\& -\& /* Get a FIPS validated digest */ -\& fipssha256 = EVP_MD_fetch(fips_libctx, "SHA2\-256", NULL); -\& if (fipssha256 == NULL) -\& goto err; -\& -\& /* Get a non\-FIPS validated digest */ -\& nonfipssha256 = EVP_MD_fetch(nonfips_libctx, "SHA2\-256", NULL); -\& if (nonfipssha256 == NULL) -\& goto err; -\& -\& /* Use the digests */ -\& -\& printf("Success\en"); -\& ret = 0; -\& -\& err: -\& EVP_MD_free(fipssha256); -\& EVP_MD_free(nonfipssha256); -\& OSSL_LIB_CTX_free(fips_libctx); -\& OSSL_LIB_CTX_free(nonfips_libctx); -\& OSSL_PROVIDER_unload(defctxnull); -\& -\& return ret; -.Ve -.PP -Note that we have made use of the special \*(L"null\*(R" provider here which we load -into the default library context. We could have chosen to use the default -library context for \s-1FIPS\s0 usage, and just create one additional library context -for other usages \- or vice versa. However if code has not been converted to use -library contexts then the default library context will be automatically used. -This could be the case for your own existing applications as well as certain -parts of OpenSSL itself. Not all parts of OpenSSL are library context aware. If -this happens then you could \*(L"accidentally\*(R" use the wrong library context for a -particular operation. To be sure this doesn't happen you can load the \*(L"null\*(R" -provider into the default library context. Because a provider has been -explicitly loaded, the default provider will not automatically load. This means -code using the default context by accident will fail because no algorithms will -be available. -.PP -See \*(L"Library Context\*(R" in \fBossl\-guide\-migration\fR\|(7) for additional information about the -Library Context. -.SS "Using Encoders and Decoders with the \s-1FIPS\s0 module" -.IX Subsection "Using Encoders and Decoders with the FIPS module" -Encoders and decoders are used to read and write keys or parameters from or to -some external format (for example a \s-1PEM\s0 file). If your application generates -keys or parameters that then need to be written into \s-1PEM\s0 or \s-1DER\s0 format -then it is likely that you will need to use an encoder to do this. Similarly -you need a decoder to read previously saved keys and parameters. In most cases -this will be invisible to you if you are using APIs that existed in -OpenSSL 1.1.1 or earlier such as \fBi2d_PrivateKey\fR\|(3). However the appropriate -encoder/decoder will need to be available in the library context associated with -the key or parameter object. The built-in OpenSSL encoders and decoders are -implemented in both the default and base providers and are not in the \s-1FIPS\s0 -module boundary. However since they are not cryptographic algorithms themselves -it is still possible to use them in conjunction with the \s-1FIPS\s0 module, and -therefore these encoders/decoders have the \f(CW\*(C`fips=yes\*(C'\fR property against them. -You should ensure that either the default or base provider is loaded into the -library context in this case. -.SS "Using the \s-1FIPS\s0 module in \s-1SSL/TLS\s0" -.IX Subsection "Using the FIPS module in SSL/TLS" -Writing an application that uses libssl in conjunction with the \s-1FIPS\s0 module is -much the same as writing a normal libssl application. If you are using global -properties and the default library context to specify usage of \s-1FIPS\s0 validated -algorithms then this will happen automatically for all cryptographic algorithms -in libssl. If you are using a nondefault library context to load the \s-1FIPS\s0 -provider then you can supply this to libssl using the function -\&\fBSSL_CTX_new_ex\fR\|(3). This works as a drop in replacement for the function -\&\fBSSL_CTX_new\fR\|(3) except it provides you with the capability to specify the -library context to be used. You can also use the same function to specify -libssl specific properties to use. -.PP -In this first example we create two \s-1SSL_CTX\s0 objects using two different library -contexts. -.PP -.Vb 11 -\& /* -\& * We assume that a nondefault library context with the FIPS -\& * provider loaded has been created called fips_libctx. -\& */ -\& SSL_CTX *fips_ssl_ctx = SSL_CTX_new_ex(fips_libctx, "fips=yes", TLS_method()); -\& /* -\& * We assume that a nondefault library context with the default -\& * provider loaded has been created called non_fips_libctx. -\& */ -\& SSL_CTX *non_fips_ssl_ctx = SSL_CTX_new_ex(non_fips_libctx, NULL, -\& TLS_method()); -.Ve -.PP -In this second example we create two \s-1SSL_CTX\s0 objects using different properties -to specify \s-1FIPS\s0 usage: -.PP -.Vb 10 -\& /* -\& * The "fips=yes" property includes all FIPS approved algorithms -\& * as well as encoders from the default provider that are allowed -\& * to be used. The NULL below indicates that we are using the -\& * default library context. -\& */ -\& SSL_CTX *fips_ssl_ctx = SSL_CTX_new_ex(NULL, "fips=yes", TLS_method()); -\& /* -\& * The "provider!=fips" property allows algorithms from any -\& * provider except the FIPS provider -\& */ -\& SSL_CTX *non_fips_ssl_ctx = SSL_CTX_new_ex(NULL, "provider!=fips", -\& TLS_method()); -.Ve -.SS "Confirming that an algorithm is being provided by the \s-1FIPS\s0 module" -.IX Subsection "Confirming that an algorithm is being provided by the FIPS module" -A chain of links needs to be followed to go from an algorithm instance to the -provider that implements it. The process is similar for all algorithms. Here the -example of a digest is used. -.PP -To go from an \fB\s-1EVP_MD_CTX\s0\fR to an \fB\s-1EVP_MD\s0\fR, use \fBEVP_MD_CTX_md\fR\|(3) . -To go from the \fB\s-1EVP_MD\s0\fR to its \fB\s-1OSSL_PROVIDER\s0\fR, -use \fBEVP_MD_get0_provider\fR\|(3). -To extract the name from the \fB\s-1OSSL_PROVIDER\s0\fR, use -\&\fBOSSL_PROVIDER_get0_name\fR\|(3). -.SS "\s-1FIPS\s0 indicators" -.IX Subsection "FIPS indicators" -\&\s-1FIPS\s0 indicators have been added to the \s-1FIPS\s0 provider in OpenSSL 3.4. -\&\s-1FIPS 140\-3\s0 requires indicators to be used if the \s-1FIPS\s0 provider allows non -approved algorithms. An algorithm is approved if it passes all required checks -such as minimum key size. By default an error will occur if any check fails. -For backwards compatibility individual algorithms may override the checks by -using either an option in the \s-1FIPS\s0 configuration (See -\&\*(L"\s-1FIPS\s0 indicator options\*(R" in \fBfips_config\fR\|(5)) \s-1OR\s0 in code using an algorithm context -setter. Overriding the check means that the algorithm is not \s-1FIPS\s0 compliant. -\&\fBOSSL_INDICATOR_set_callback\fR\|(3) can be called to register a callback to log -unapproved algorithms. At the end of any algorithm operation the approved status -can be queried using an algorithm context getter to retrieve the indicator -(e.g. \*(L"fips-indicator\*(R"). -An example of an algorithm context setter is \*(L"key-check\*(R" -in \*(L"Supported parameters\*(R" in \s-1\fBEVP_KDF\-HKDF\s0\fR\|(7). -.PP -The following algorithms use \*(L"fips-indicator\*(R" to query if the algorithm -is approved: -.IP "\s-1DSA\s0 Key generation" 4 -.IX Item "DSA Key generation" -\&\s-1DSA\s0 Key generation is no longer approved. -See \*(L"\s-1DSA\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7) -.IP "\s-1DSA\s0 Signatures" 4 -.IX Item "DSA Signatures" -\&\s-1DSA\s0 Signature generation is no longer approved. -See \*(L"Signature Parameters\*(R" in \s-1\fBEVP_SIGNATURE\-DSA\s0\fR\|(7) -.IP "\s-1ECDSA\s0 Signatures" 4 -.IX Item "ECDSA Signatures" -See \*(L"\s-1ECDSA\s0 Signature Parameters\*(R" in \s-1\fBEVP_SIGNATURE\-ECDSA\s0\fR\|(7) -.IP "\s-1EC\s0 Key Generation" 4 -.IX Item "EC Key Generation" -See \*(L"Common \s-1EC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) -.IP "\s-1RSA\s0 Encryption" 4 -.IX Item "RSA Encryption" -\&\*(L"pkcs1\*(R" padding is no longer approved. -.Sp -See \*(L"\s-1RSA\s0 Asymmetric Cipher parameters\*(R" in \s-1\fBEVP_ASYM_CIPHER\-RSA\s0\fR\|(7) and -\&\*(L"\s-1RSA KEM\s0 parameters\*(R" in \s-1\fBEVP_KEM\-RSA\s0\fR\|(7) -.IP "\s-1RSA\s0 Signatures" 4 -.IX Item "RSA Signatures" -See \*(L"Signature Parameters\*(R" in \s-1\fBEVP_SIGNATURE\-RSA\s0\fR\|(7) -.IP "\s-1DRBGS\s0" 4 -.IX Item "DRBGS" -See \*(L"Supported parameters\*(R" in \s-1\fBEVP_RAND\-HASH\-DRBG\s0\fR\|(7) and -\&\s-1\fBEVP_RAND\-HMAC\-DRBG\s0\fR\|(7)/Supported parameters> -.IP "\s-1DES\s0" 4 -.IX Item "DES" -Triple-DES is not longer approved for encryption. -See \*(L"Parameters\*(R" in \s-1\fBEVP_CIPHER\-DES\s0\fR\|(7) -.IP "\s-1DH\s0" 4 -.IX Item "DH" -See \*(L"\s-1DH\s0 and \s-1DHX\s0 key exchange parameters\*(R" in \s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7) -.IP "\s-1ECDH\s0" 4 -.IX Item "ECDH" -See \*(L"\s-1ECDH\s0 Key Exchange parameters\*(R" in \s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7) -.IP "\s-1KDFS\s0" 4 -.IX Item "KDFS" -See relevant \s-1KDF\s0 documentation e.g. \*(L"Supported parameters\*(R" in \s-1\fBEVP_KDF\-HKDF\s0\fR\|(7) -.IP "\s-1CMAC\s0 and \s-1KMAC\s0" 4 -.IX Item "CMAC and KMAC" -See \*(L"Supported parameters\*(R" in \s-1\fBEVP_MAC\-CMAC\s0\fR\|(7) and -\&\*(L"Supported parameters\*(R" in \s-1\fBEVP_MAC\-KMAC\s0\fR\|(7) -.PP -The following \s-1FIPS\s0 algorithms are unapproved and use the \*(L"fips-indicator\*(R". -.IP "RAND-TEST-RAND" 4 -.IX Item "RAND-TEST-RAND" -See \*(L"Supported parameters\*(R" in \s-1\fBEVP_RAND\-TEST\-RAND\s0\fR\|(7) -The indicator callback is \s-1NOT\s0 triggered for this algorithm since it is used -internally for non security purposes. -.IP "X25519 and X448 Key Generation and Key Exchange" 4 -.IX Item "X25519 and X448 Key Generation and Key Exchange" -.PP -The unapproved (non \s-1FIPS\s0 validated) algorithms have a property query value of -\&\*(L"fips=no\*(R". -.PP -The following algorithms use a unique indicator and do not trigger the -indicator callback. -.ie n .IP "AES-GCM ciphers support the indicator ""iv-generated""" 4 -.el .IP "AES-GCM ciphers support the indicator ``iv-generated''" 4 -.IX Item "AES-GCM ciphers support the indicator iv-generated" -See \*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3) for further information. -.ie n .IP "\s-1ECDSA\s0 and \s-1RSA\s0 Signatures support the indicator ""verify-message""." 4 -.el .IP "\s-1ECDSA\s0 and \s-1RSA\s0 Signatures support the indicator ``verify-message''." 4 -.IX Item "ECDSA and RSA Signatures support the indicator verify-message." -See \*(L"\s-1ECDSA\s0 Signature Parameters\*(R" in \s-1\fBEVP_SIGNATURE\-ECDSA\s0\fR\|(7) and -\&\*(L"Signature Parameters\*(R" in \s-1\fBEVP_SIGNATURE\-RSA\s0\fR\|(7) /for further information. -.SH "NOTES" -.IX Header "NOTES" -Some released versions of OpenSSL do not include a validated -\&\s-1FIPS\s0 provider. To determine which versions have undergone -the validation process, please refer to the -OpenSSL Downloads page . If you -require FIPS-approved functionality, it is essential to build your \s-1FIPS\s0 -provider using one of the validated versions listed there. Normally, -it is possible to utilize a \s-1FIPS\s0 provider constructed from one of the -validated versions alongside \fIlibcrypto\fR and \fIlibssl\fR compiled from any -release within the same major release series. This flexibility enables -you to address bug fixes and CVEs that fall outside the \s-1FIPS\s0 boundary. -.PP -As the \s-1FIPS\s0 provider still supports non-FIPS validated algorithms, -The property query \f(CW\*(C`fips=yes\*(C'\fR is mandatory for applications that -want to operate in a \s-1FIPS\s0 approved manner. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-migration\fR\|(7), \fBcrypto\fR\|(7), \fBfips_config\fR\|(5), - -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1FIPS\s0 module guide was created for use with the new \s-1FIPS\s0 provider -in OpenSSL 3.0. -\&\s-1FIPS\s0 indicators were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/life_cycle-cipher.7ossl b/openssl-install/share/man/man7/life_cycle-cipher.7ossl deleted file mode 100644 index 04cd9bb0..00000000 --- a/openssl-install/share/man/man7/life_cycle-cipher.7ossl +++ /dev/null @@ -1,283 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "LIFE_CYCLE-CIPHER 7ossl" -.TH LIFE_CYCLE-CIPHER 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -life_cycle\-cipher \- The cipher algorithm life\-cycle -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All symmetric ciphers (CIPHERs) go through a number of stages in their -life-cycle: -.IP "start" 4 -.IX Item "start" -This state represents the \s-1CIPHER\s0 before it has been allocated. It is the -starting state for any life-cycle transitions. -.IP "newed" 4 -.IX Item "newed" -This state represents the \s-1CIPHER\s0 after it has been allocated. -.IP "initialised" 4 -.IX Item "initialised" -These states represent the \s-1CIPHER\s0 when it is set up and capable of processing -input. There are three possible initialised states: -.RS 4 -.IP "initialised using EVP_CipherInit" 4 -.IX Item "initialised using EVP_CipherInit" -.PD 0 -.IP "initialised for decryption using EVP_DecryptInit" 4 -.IX Item "initialised for decryption using EVP_DecryptInit" -.IP "initialised for encryption using EVP_EncryptInit" 4 -.IX Item "initialised for encryption using EVP_EncryptInit" -.RE -.RS 4 -.RE -.IP "updated" 4 -.IX Item "updated" -.PD -These states represent the \s-1CIPHER\s0 when it is set up and capable of processing -additional input or generating output. The three possible states directly -correspond to those for initialised above. The three different streams should -not be mixed. -.IP "finaled" 4 -.IX Item "finaled" -This state represents the \s-1CIPHER\s0 when it has generated output. -.IP "freed" 4 -.IX Item "freed" -This state is entered when the \s-1CIPHER\s0 is freed. It is the terminal state -for all life-cycle transitions. -.SS "State Transition Diagram" -.IX Subsection "State Transition Diagram" -The usual life-cycle of a \s-1CIPHER\s0 is illustrated: - +---------------------------+ - | | - | start | - | | - +---------------------------+ + - - - - - - - - - - - - - + - | ' any of the initialised ' - | EVP_CIPHER_CTX_new ' updated or finaled states ' - v ' ' - +---------------------------+ + - - - - - - - - - - - - - + - | | | - | newed | | EVP_CIPHER_CTX_reset - | | <----+ - +---------------------------+ - | | | - +---------+ | +---------+ - EVP_DecryptInit | | EVP_CipherInit | EVP_EncryptInit - v v v - +---------------------------+ +---------------------------+ +---------------------------+ - | | | | | | - | initialised | | initialised | | initialised | - | for decryption | | | | for encryption | - +---------------------------+ +---------------------------+ +---------------------------+ - | | | - | EVP_DecryptUpdate | EVP_CipherUpdate EVP_EncryptUpdate | - | v | - | +---------------------------+ | - | | |--------------------+ | - | | updated | EVP_CipherUpdate | | - | | | <------------------+ | - v +---------------------------+ v - +---------------------------+ | +---------------------------+ - | |---------------------+ | | | - | updated | EVP_DecryptUpdate | | | updated |------+ - | for decryption | <-------------------+ | | for encryption | | - +---------------------------+ | +---------------------------+ | - | EVP_CipherFinal | | ^ | - +-------+ | +--------+ | | - EVP_DecryptFinal | | | EVP_EncryptFinal +-------------------+ - v v v EVP_EncryptUpdate - +---------------------------+ - | |-----------------------------+ - | finaled | | - | | <---------------------------+ - +---------------------------+ EVP_CIPHER_CTX_get_params - | (AEAD encryption) - | EVP_CIPHER_CTX_free - v - +---------------------------+ - | | - | freed | - | | - +---------------------------+ -.SS "Formal State Transitions" -.IX Subsection "Formal State Transitions" -This section defines all of the legal state transitions. -This is the canonical list. - Function Call ---------------------------------------------- Current State ----------------------------------------------- - start newed initialised updated finaled initialised updated initialised updated freed - decryption decryption encryption encryption - EVP_CIPHER_CTX_new newed - EVP_CipherInit initialised initialised initialised initialised initialised initialised initialised initialised - EVP_DecryptInit initialised initialised initialised initialised initialised initialised initialised initialised - decryption decryption decryption decryption decryption decryption decryption decryption - EVP_EncryptInit initialised initialised initialised initialised initialised initialised initialised initialised - encryption encryption encryption encryption encryption encryption encryption encryption - EVP_CipherUpdate updated updated - EVP_DecryptUpdate updated updated - decryption decryption - EVP_EncryptUpdate updated updated - encryption encryption - EVP_CipherFinal finaled - EVP_DecryptFinal finaled - EVP_EncryptFinal finaled - EVP_CIPHER_CTX_free freed freed freed freed freed freed freed freed freed - EVP_CIPHER_CTX_reset newed newed newed newed newed newed newed newed - EVP_CIPHER_CTX_get_params newed initialised updated initialised updated initialised updated - decryption decryption encryption encryption - EVP_CIPHER_CTX_set_params newed initialised updated initialised updated initialised updated - decryption decryption encryption encryption - EVP_CIPHER_CTX_gettable_params newed initialised updated initialised updated initialised updated - decryption decryption encryption encryption - EVP_CIPHER_CTX_settable_params newed initialised updated initialised updated initialised updated - decryption decryption encryption encryption -.SH "NOTES" -.IX Header "NOTES" -At some point the \s-1EVP\s0 layer will begin enforcing the transitions described -herein. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-cipher\fR\|(7), \fBEVP_EncryptInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/life_cycle-digest.7ossl b/openssl-install/share/man/man7/life_cycle-digest.7ossl deleted file mode 100644 index e5a97df1..00000000 --- a/openssl-install/share/man/man7/life_cycle-digest.7ossl +++ /dev/null @@ -1,262 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "LIFE_CYCLE-DIGEST 7ossl" -.TH LIFE_CYCLE-DIGEST 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -life_cycle\-digest \- The digest algorithm life\-cycle -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All message digests (MDs) go through a number of stages in their life-cycle: -.IP "start" 4 -.IX Item "start" -This state represents the \s-1MD\s0 before it has been allocated. It is the -starting state for any life-cycle transitions. -.IP "newed" 4 -.IX Item "newed" -This state represents the \s-1MD\s0 after it has been allocated. -.IP "initialised" 4 -.IX Item "initialised" -This state represents the \s-1MD\s0 when it is set up and capable of processing -input. -.IP "updated" 4 -.IX Item "updated" -This state represents the \s-1MD\s0 when it is set up and capable of processing -additional input or generating output. -.IP "finaled" 4 -.IX Item "finaled" -This state represents the \s-1MD\s0 when it has generated output. -For an \s-1XOF\s0 digest, this state represents the \s-1MD\s0 when it has generated a -single-shot output. -.IP "squeezed" 4 -.IX Item "squeezed" -For an \s-1XOF\s0 digest, this state represents the \s-1MD\s0 when it has generated output. -It can be called multiple times to generate more output. The output length is -variable for each call. -.IP "freed" 4 -.IX Item "freed" -This state is entered when the \s-1MD\s0 is freed. It is the terminal state -for all life-cycle transitions. -.SS "State Transition Diagram" -.IX Subsection "State Transition Diagram" -The usual life-cycle of a \s-1MD\s0 is illustrated: - +--------------------+ - | start | - +--------------------+ - | EVP_MD_CTX_reset - | EVP_MD_CTX_new +-------------------------------------------------+ - v v | - EVP_MD_CTX_reset + - - - - - - - - - - - - - - - - - - - - - - + EVP_MD_CTX_reset | - +-------------------> ' newed ' <--------------------+ | - | + - - - - - - - - - - - - - - - - - - - - - - + | | - | | | | - | | EVP_DigestInit | | - | v | | - | EVP_DigestInit + - - - - - - - - - - - - - - - - - - - - - - + | | - +----+-------------------> ' initialised ' <+ EVP_DigestInit | | - | | + - - - - - - - - - - - - - - - - - - - - - - + | | | - | | | ^ | | | - | | | EVP_DigestUpdate | EVP_DigestInit | | | - | | v | | | | - | | +---------------------------------------------+ | | | - | +-------------------- | | | | | - | | | | | | - | EVP_DigestUpdate | | | | | - | +-------------------- | | | | | - | | | updated | | | | - | +-------------------> | | | | | - | | | | | | - | | | | | | - +----+------------------------- | | -+-------------------+----+ | - | | +---------------------------------------------+ | | | | - | | | | | | | - | | | EVP_DigestSqueeze +-------------------+ | | | - | | v | | | | - | | EVP_DigestSqueeze +---------------------------------------------+ | | | - | | +-------------------- | | | | | - | | | | squeezed | | | | - | | +-------------------> | | ---------------------+ | | - | | +---------------------------------------------+ | | - | | | | | - | | +---------------------------------------+ | | - | | | | | - | | +---------------------------------------------+ EVP_DigestFinalXOF | | | - | +------------------------- | finaled | <--------------------+----+ | - | +---------------------------------------------+ | | - | EVP_DigestFinal ^ | | | | - +---------------------------------+ | | EVP_MD_CTX_free | | - | v | | - | +------------------+ EVP_MD_CTX_free | | - | | freed | <--------------------+ | - | +------------------+ | - | | - +------------------------------------------------------+ -.SS "Formal State Transitions" -.IX Subsection "Formal State Transitions" -This section defines all of the legal state transitions. -This is the canonical list. - Function Call --------------------- Current State ----------------------------------- - start newed initialised updated finaled squeezed freed - EVP_MD_CTX_new newed - EVP_DigestInit initialised initialised initialised initialised initialised - EVP_DigestUpdate updated updated - EVP_DigestFinal finaled - EVP_DigestFinalXOF finaled - EVP_DigestSqueeze squeezed squeezed - EVP_MD_CTX_free freed freed freed freed freed - EVP_MD_CTX_reset newed newed newed newed - EVP_MD_CTX_get_params newed initialised updated - EVP_MD_CTX_set_params newed initialised updated - EVP_MD_CTX_gettable_params newed initialised updated - EVP_MD_CTX_settable_params newed initialised updated - EVP_MD_CTX_copy_ex newed initialised updated squeezed -.SH "NOTES" -.IX Header "NOTES" -At some point the \s-1EVP\s0 layer will begin enforcing the transitions described -herein. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-digest\fR\|(7), \fBEVP_DigestInit\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/life_cycle-kdf.7ossl b/openssl-install/share/man/man7/life_cycle-kdf.7ossl deleted file mode 100644 index cb39667b..00000000 --- a/openssl-install/share/man/man7/life_cycle-kdf.7ossl +++ /dev/null @@ -1,219 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "LIFE_CYCLE-KDF 7ossl" -.TH LIFE_CYCLE-KDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -life_cycle\-kdf \- The KDF algorithm life\-cycle -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All key derivation functions (KDFs) and pseudo random functions (PRFs) -go through a number of stages in their life-cycle: -.IP "start" 4 -.IX Item "start" -This state represents the \s-1KDF/PRF\s0 before it has been allocated. It is the -starting state for any life-cycle transitions. -.IP "newed" 4 -.IX Item "newed" -This state represents the \s-1KDF/PRF\s0 after it has been allocated. -.IP "deriving" 4 -.IX Item "deriving" -This state represents the \s-1KDF/PRF\s0 when it is set up and capable of generating -output. -.IP "freed" 4 -.IX Item "freed" -This state is entered when the \s-1KDF/PRF\s0 is freed. It is the terminal state -for all life-cycle transitions. -.SS "State Transition Diagram" -.IX Subsection "State Transition Diagram" -The usual life-cycle of a \s-1KDF/PRF\s0 is illustrated: - +-------------------+ - | start | - +-------------------+ - | - | EVP_KDF_CTX_new - v - +-------------------+ - | newed | <+ - +-------------------+ | - | | - | EVP_KDF_derive | - v | EVP_KDF_CTX_reset - EVP_KDF_derive +-------------------+ | - + - - - - - - - - | | | - ' | deriving | | - + - - - - - - - -> | | -+ - +-------------------+ - | - | EVP_KDF_CTX_free - v - +-------------------+ - | freed | - +-------------------+ -.SS "Formal State Transitions" -.IX Subsection "Formal State Transitions" -This section defines all of the legal state transitions. -This is the canonical list. - Function Call ------------- Current State ------------- - start newed deriving freed - EVP_KDF_CTX_new newed - EVP_KDF_derive deriving deriving - EVP_KDF_CTX_free freed freed freed - EVP_KDF_CTX_reset newed newed - EVP_KDF_CTX_get_params newed deriving - EVP_KDF_CTX_set_params newed deriving - EVP_KDF_CTX_gettable_params newed deriving - EVP_KDF_CTX_settable_params newed deriving -.SH "NOTES" -.IX Header "NOTES" -At some point the \s-1EVP\s0 layer will begin enforcing the transitions described -herein. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-kdf\fR\|(7), \s-1\fBEVP_KDF\s0\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1KDF\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/life_cycle-mac.7ossl b/openssl-install/share/man/man7/life_cycle-mac.7ossl deleted file mode 100644 index 4d0e396b..00000000 --- a/openssl-install/share/man/man7/life_cycle-mac.7ossl +++ /dev/null @@ -1,238 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "LIFE_CYCLE-MAC 7ossl" -.TH LIFE_CYCLE-MAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -life_cycle\-mac \- The MAC algorithm life\-cycle -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All message authentication codes (MACs) -go through a number of stages in their life-cycle: -.IP "start" 4 -.IX Item "start" -This state represents the \s-1MAC\s0 before it has been allocated. It is the -starting state for any life-cycle transitions. -.IP "newed" 4 -.IX Item "newed" -This state represents the \s-1MAC\s0 after it has been allocated. -.IP "initialised" 4 -.IX Item "initialised" -This state represents the \s-1MAC\s0 when it is set up and capable of processing -input. -.IP "updated" 4 -.IX Item "updated" -This state represents the \s-1MAC\s0 when it is set up and capable of processing -additional input or generating output. -.IP "finaled" 4 -.IX Item "finaled" -This state represents the \s-1MAC\s0 when it has generated output. -.IP "freed" 4 -.IX Item "freed" -This state is entered when the \s-1MAC\s0 is freed. It is the terminal state -for all life-cycle transitions. -.SS "State Transition Diagram" -.IX Subsection "State Transition Diagram" -The usual life-cycle of a \s-1MAC\s0 is illustrated: - +-------------------+ - | start | - +-------------------+ - | - | EVP_MAC_CTX_new - v - +-------------------+ - | newed | - +-------------------+ - | - | EVP_MAC_init - v - +-------------------+ - +> | initialised | <+ - | +-------------------+ | - | | | - | | EVP_MAC_update | EVP_MAC_init - | v | - EVP_MAC_init | +-------------------+ | - | | updated | -+ - | +-------------------+ - | | | - | | EVP_MAC_final | EVP_MAC_finalXOF - | v v - | +-------------------+ - +- | finaled | - +-------------------+ - | - | EVP_MAC_CTX_free - v - +-------------------+ - | freed | - +-------------------+ -.SS "Formal State Transitions" -.IX Subsection "Formal State Transitions" -This section defines all of the legal state transitions. -This is the canonical list. - Function Call --------------------- Current State ---------------------- - start newed initialised updated finaled freed - EVP_MAC_CTX_new newed - EVP_MAC_init initialised initialised initialised initialised - EVP_MAC_update updated updated - EVP_MAC_final finaled - EVP_MAC_finalXOF finaled - EVP_MAC_CTX_free freed freed freed freed freed - EVP_MAC_CTX_get_params newed initialised updated - EVP_MAC_CTX_set_params newed initialised updated - EVP_MAC_CTX_gettable_params newed initialised updated - EVP_MAC_CTX_settable_params newed initialised updated -.SH "NOTES" -.IX Header "NOTES" -At some point the \s-1EVP\s0 layer will begin enforcing the transitions described -herein. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-mac\fR\|(7), \s-1\fBEVP_MAC\s0\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1MAC\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/life_cycle-pkey.7ossl b/openssl-install/share/man/man7/life_cycle-pkey.7ossl deleted file mode 100644 index e0873e88..00000000 --- a/openssl-install/share/man/man7/life_cycle-pkey.7ossl +++ /dev/null @@ -1,322 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "LIFE_CYCLE-PKEY 7ossl" -.TH LIFE_CYCLE-PKEY 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -life_cycle\-pkey \- The PKEY algorithm life\-cycle -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All public keys (PKEYs) go through a number of stages in their life-cycle: -.IP "start" 4 -.IX Item "start" -This state represents the \s-1PKEY\s0 before it has been allocated. It is the -starting state for any life-cycle transitions. -.IP "newed" 4 -.IX Item "newed" -This state represents the \s-1PKEY\s0 after it has been allocated. -.IP "decapsulate" 4 -.IX Item "decapsulate" -This state represents the \s-1PKEY\s0 when it is ready to perform a private key decapsulation -operation. -.IP "decrypt" 4 -.IX Item "decrypt" -This state represents the \s-1PKEY\s0 when it is ready to decrypt some ciphertext. -.IP "derive" 4 -.IX Item "derive" -This state represents the \s-1PKEY\s0 when it is ready to derive a shared secret. -.IP "digest sign" 4 -.IX Item "digest sign" -This state represents the \s-1PKEY\s0 when it is ready to perform a private key signature -operation. -.IP "encapsulate" 4 -.IX Item "encapsulate" -This state represents the \s-1PKEY\s0 when it is ready to perform a public key encapsulation -operation. -.IP "encrypt" 4 -.IX Item "encrypt" -This state represents the \s-1PKEY\s0 when it is ready to encrypt some plaintext. -.IP "key generation" 4 -.IX Item "key generation" -This state represents the \s-1PKEY\s0 when it is ready to generate a new public/private key. -.IP "parameter generation" 4 -.IX Item "parameter generation" -This state represents the \s-1PKEY\s0 when it is ready to generate key parameters. -.IP "verify" 4 -.IX Item "verify" -This state represents the \s-1PKEY\s0 when it is ready to verify a public key signature. -.IP "verify recover" 4 -.IX Item "verify recover" -This state represents the \s-1PKEY\s0 when it is ready to recover a public key signature data. -.IP "freed" 4 -.IX Item "freed" -This state is entered when the \s-1PKEY\s0 is freed. It is the terminal state -for all life-cycle transitions. -.SS "State Transition Diagram" -.IX Subsection "State Transition Diagram" -The usual life-cycle of a \s-1PKEY\s0 object is illustrated: - +-------------+ - | | - | start | - | | - EVP_PKEY_derive +-------------+ - +-------------+ EVP_PKEY_derive_set_peer | +-------------+ - | |----------------------------+ | +----------------------------| | - | derive | | | | EVP_PKEY_verify | verify | - | |<---------------------------+ | +--------------------------->| | - +-------------+ | +-------------+ - ^ | ^ - | EVP_PKEY_derive_init | EVP_PKEY_verify_init | - +---------------------------------------+ | +---------------------------------------+ - | | | - +-------------+ | | | +-------------+ - | |----------------------------+ | | | +----------------------------| | - | digest sign | EVP_PKEY_sign | | | | | EVP_PKEY_verify_recover | verify | - | |<---------------------------+ | | | +--------------------------->| recover | - +-------------+ | | | +-------------+ - ^ | | | ^ - | EVP_PKEY_sign_init | | | EVP_PKEY_verify_recover_init | - +---------------------------------+ | | | +---------------------------------+ - | | | | | - +-------------+ | | | | | +-------------+ - | |----------------------------+ | | | | | +----------------------------| | - | decapsulate | EVP_PKEY_decapsulate | | | | | | | EVP_PKEY_decrypt | decrypt | - | |<---------------------------+ | | v | | +--------------------------->| | - +-------------+ | +-------------+ | +-------------+ - ^ +---| |---+ ^ - | EVP_PKEY_decapsulate_init | | EVP_PKEY_decrypt_init | - +-------------------------------------| newed |-------------------------------------+ - | | - +---| |---+ - +-------------+ | +-------------+ | +-------------+ - | |----------------------------+ | | | | +----------------------------| | - | encapsulate | EVP_PKEY_encapsulate | | | | | | EVP_PKEY_encrypt | encrypt | - | |<---------------------------+ | | | | +--------------------------->| | - +-------------+ | | | | +-------------+ - ^ | | | | ^ - | EVP_PKEY_encapsulate_init | | | | EVP_PKEY_encrypt_init | - +---------------------------------+ | | +---------------------------------+ - | | - +---------------------------------------+ +---------------------------------------+ - | EVP_PKEY_paramgen_init EVP_PKEY_keygen_init | - v v - +-------------+ +-------------+ - | |----------------------------+ +----------------------------| | - | parameter | | | | key | - | generation |<---------------------------+ +--------------------------->| generation | - +-------------+ EVP_PKEY_paramgen EVP_PKEY_keygen +-------------+ - EVP_PKEY_gen EVP_PKEY_gen - - - + - - - - - + +-----------+ - ' ' EVP_PKEY_CTX_free | | - ' any state '------------------->| freed | - ' ' | | - + - - - - - + +-----------+ -.SS "Formal State Transitions" -.IX Subsection "Formal State Transitions" -This section defines all of the legal state transitions. -This is the canonical list. - Function Call ---------------------------------------------------------------------- Current State ---------------------------------------------------------------------- - start newed digest verify verify encrypt decrypt derive encapsulate decapsulate parameter key freed - sign recover generation generation - EVP_PKEY_CTX_new newed - EVP_PKEY_CTX_new_id newed - EVP_PKEY_CTX_new_from_name newed - EVP_PKEY_CTX_new_from_pkey newed - EVP_PKEY_sign_init digest digest digest digest digest digest digest digest digest digest digest - sign sign sign sign sign sign sign sign sign sign sign - EVP_PKEY_sign digest - sign - EVP_PKEY_verify_init verify verify verify verify verify verify verify verify verify verify verify - EVP_PKEY_verify verify - EVP_PKEY_verify_recover_init verify verify verify verify verify verify verify verify verify verify verify - recover recover recover recover recover recover recover recover recover recover recover - EVP_PKEY_verify_recover verify - recover - EVP_PKEY_encrypt_init encrypt encrypt encrypt encrypt encrypt encrypt encrypt encrypt encrypt encrypt encrypt - EVP_PKEY_encrypt encrypt - EVP_PKEY_decrypt_init decrypt decrypt decrypt decrypt decrypt decrypt decrypt decrypt decrypt decrypt decrypt - EVP_PKEY_decrypt decrypt - EVP_PKEY_derive_init derive derive derive derive derive derive derive derive derive derive derive - EVP_PKEY_derive_set_peer derive - EVP_PKEY_derive derive - EVP_PKEY_encapsulate_init encapsulate encapsulate encapsulate encapsulate encapsulate encapsulate encapsulate encapsulate encapsulate encapsulate encapsulate - EVP_PKEY_encapsulate encapsulate - EVP_PKEY_decapsulate_init decapsulate decapsulate decapsulate decapsulate decapsulate decapsulate decapsulate decapsulate decapsulate decapsulate decapsulate - EVP_PKEY_decapsulate decapsulate - EVP_PKEY_paramgen_init parameter parameter parameter parameter parameter parameter parameter parameter parameter parameter parameter - generation generation generation generation generation generation generation generation generation generation generation - EVP_PKEY_paramgen parameter - generation - EVP_PKEY_keygen_init key key key key key key key key key key key - generation generation generation generation generation generation generation generation generation generation generation - EVP_PKEY_keygen key - generation - EVP_PKEY_gen parameter key - generation generation - EVP_PKEY_CTX_get_params newed digest verify verify encrypt decrypt derive encapsulate decapsulate parameter key - sign recover generation generation - EVP_PKEY_CTX_set_params newed digest verify verify encrypt decrypt derive encapsulate decapsulate parameter key - sign recover generation generation - EVP_PKEY_CTX_gettable_params newed digest verify verify encrypt decrypt derive encapsulate decapsulate parameter key - sign recover generation generation - EVP_PKEY_CTX_settable_params newed digest verify verify encrypt decrypt derive encapsulate decapsulate parameter key - sign recover generation generation - EVP_PKEY_CTX_free freed freed freed freed freed freed freed freed freed freed freed freed -.SH "NOTES" -.IX Header "NOTES" -At some point the \s-1EVP\s0 layer will begin enforcing the transitions described -herein. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_new\fR\|(3), -\&\fBEVP_PKEY_decapsulate\fR\|(3), \fBEVP_PKEY_decrypt\fR\|(3), \fBEVP_PKEY_encapsulate\fR\|(3), -\&\fBEVP_PKEY_encrypt\fR\|(3), \fBEVP_PKEY_derive\fR\|(3), \fBEVP_PKEY_keygen\fR\|(3), -\&\fBEVP_PKEY_sign\fR\|(3), \fBEVP_PKEY_verify\fR\|(3), \fBEVP_PKEY_verify_recover\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1PKEY\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/life_cycle-rand.7ossl b/openssl-install/share/man/man7/life_cycle-rand.7ossl deleted file mode 100644 index 2206b71d..00000000 --- a/openssl-install/share/man/man7/life_cycle-rand.7ossl +++ /dev/null @@ -1,231 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "LIFE_CYCLE-RAND 7ossl" -.TH LIFE_CYCLE-RAND 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -life_cycle\-rand \- The RAND algorithm life\-cycle -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All random number generator (RANDs) -go through a number of stages in their life-cycle: -.IP "start" 4 -.IX Item "start" -This state represents the \s-1RAND\s0 before it has been allocated. It is the -starting state for any life-cycle transitions. -.IP "newed" 4 -.IX Item "newed" -This state represents the \s-1RAND\s0 after it has been allocated but unable to -generate any output. -.IP "instantiated" 4 -.IX Item "instantiated" -This state represents the \s-1RAND\s0 when it is set up and capable of generating -output. -.IP "uninstantiated" 4 -.IX Item "uninstantiated" -This state represents the \s-1RAND\s0 when it has been shutdown and it is no longer -capable of generating output. -.IP "freed" 4 -.IX Item "freed" -This state is entered when the \s-1RAND\s0 is freed. It is the terminal state -for all life-cycle transitions. -.SS "State Transition Diagram" -.IX Subsection "State Transition Diagram" -The usual life-cycle of a \s-1RAND\s0 is illustrated: - +-------------------------+ - | start | - +-------------------------+ - | - | EVP_RAND_CTX_new - v - +-------------------------+ - | newed | - +-------------------------+ - | - | EVP_RAND_instantiate - v - EVP_RAND_generate +-------------------------+ - +-------------------- | | - | | instantiated | - +-------------------> | | <+ - +-------------------------+ ' - | ' - | EVP_RAND_uninstantiate ' EVP_RAND_instantiate - v ' - +-------------------------+ ' - | uninstantiated | -+ - +-------------------------+ - | - | EVP_RAND_CTX_free - v - +-------------------------+ - | freed | - +-------------------------+ -.SS "Formal State Transitions" -.IX Subsection "Formal State Transitions" -This section defines all of the legal state transitions. -This is the canonical list. - Function Call ------------------ Current State ------------------ - start newed instantiated uninstantiated freed - EVP_RAND_CTX_new newed - EVP_RAND_instantiate instantiated - EVP_RAND_generate instantiated - EVP_RAND_uninstantiate uninstantiated - EVP_RAND_CTX_free freed freed freed freed - EVP_RAND_CTX_get_params newed instantiated uninstantiated freed - EVP_RAND_CTX_set_params newed instantiated uninstantiated freed - EVP_RAND_CTX_gettable_params newed instantiated uninstantiated freed - EVP_RAND_CTX_settable_params newed instantiated uninstantiated freed -.SH "NOTES" -.IX Header "NOTES" -At some point the \s-1EVP\s0 layer will begin enforcing the transitions described -herein. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\-rand\fR\|(7), \s-1\fBEVP_RAND\s0\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1RAND\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/migration_guide.7ossl b/openssl-install/share/man/man7/migration_guide.7ossl deleted file mode 120000 index 44ea4935..00000000 --- a/openssl-install/share/man/man7/migration_guide.7ossl +++ /dev/null @@ -1 +0,0 @@ -ossl-guide-migration.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/openssl-core.h.7ossl b/openssl-install/share/man/man7/openssl-core.h.7ossl deleted file mode 100644 index 6324305d..00000000 --- a/openssl-install/share/man/man7/openssl-core.h.7ossl +++ /dev/null @@ -1,184 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CORE.H 7ossl" -.TH OPENSSL-CORE.H 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl/core.h \- OpenSSL Core types -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fI\fR header defines a number of public types that -are used to communicate between the OpenSSL libraries and -implementation providers. -These types are designed to minimise the need for intimate knowledge -of internal structures between the OpenSSL libraries and the providers. -.PP -The types are: -.IP "\s-1\fBOSSL_DISPATCH\s0\fR\|(3)" 4 -.IX Item "OSSL_DISPATCH" -.PD 0 -.IP "\s-1\fBOSSL_ITEM\s0\fR\|(3)" 4 -.IX Item "OSSL_ITEM" -.IP "\s-1\fBOSSL_ALGORITHM\s0\fR\|(3)" 4 -.IX Item "OSSL_ALGORITHM" -.IP "\s-1\fBOSSL_PARAM\s0\fR\|(3)" 4 -.IX Item "OSSL_PARAM" -.IP "\s-1\fBOSSL_CALLBACK\s0\fR\|(3)" 4 -.IX Item "OSSL_CALLBACK" -.IP "\s-1\fBOSSL_PASSPHRASE_CALLBACK\s0\fR\|(3)" 4 -.IX Item "OSSL_PASSPHRASE_CALLBACK" -.PD -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-core_dispatch.h\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The types described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl-core_dispatch.h.7ossl b/openssl-install/share/man/man7/openssl-core_dispatch.h.7ossl deleted file mode 100644 index fb613cf7..00000000 --- a/openssl-install/share/man/man7/openssl-core_dispatch.h.7ossl +++ /dev/null @@ -1,182 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CORE_DISPATCH.H 7ossl" -.TH OPENSSL-CORE_DISPATCH.H 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl/core_dispatch.h -\&\- OpenSSL provider dispatch numbers and function types -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fI\fR header defines all the operation -numbers, dispatch numbers and provider interface function types -currently available. -.PP -The operation and dispatch numbers are represented with macros, which -are named as follows: -.IP "operation numbers" 4 -.IX Item "operation numbers" -These macros have the form \f(CW\*(C`OSSL_OP_\f(CIopname\f(CW\*(C'\fR. -.IP "dipatch numbers" 4 -.IX Item "dipatch numbers" -These macros have the form \f(CW\*(C`OSSL_FUNC_\f(CIopname\f(CW_\f(CIfuncname\f(CW\*(C'\fR, where -\&\f(CW\*(C`\f(CIopname\f(CW\*(C'\fR is the same as in the macro for the operation this -function belongs to. -.PP -With every dispatch number, there is an associated function type. -.PP -For further information, please see the \fBprovider\fR\|(7) -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The types and macros described here were added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl-core_names.h.7ossl b/openssl-install/share/man/man7/openssl-core_names.h.7ossl deleted file mode 100644 index 6a27b9be..00000000 --- a/openssl-install/share/man/man7/openssl-core_names.h.7ossl +++ /dev/null @@ -1,180 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-CORE_NAMES.H 7ossl" -.TH OPENSSL-CORE_NAMES.H 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl/core_names.h \- OpenSSL provider parameter names -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \fI\fR header defines a multitude of macros -for \s-1\fBOSSL_PARAM\s0\fR\|(3) names, algorithm names and other known names used -with OpenSSL's providers, made available for practical purposes only. -.PP -Existing names are further described in the manuals for OpenSSL's -providers (see \*(L"\s-1SEE ALSO\*(R"\s0) and the manuals for each algorithm they -provide (listed in those provider manuals). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBOSSL_PROVIDER\-default\fR\|(7), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -\&\fBOSSL_PROVIDER\-legacy\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The macros described here were added in OpenSSL 3.0. -.SH "CAVEATS" -.IX Header "CAVEATS" -\&\fIThis header file does not constitute a general registry of names\fR. -Providers that implement new algorithms are to be responsible for -their own parameter names. -.PP -However, authors of provider that implement their own variants of -algorithms that OpenSSL providers support will want to pay attention -to the names provided in this header to work in a compatible manner. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl-env.7ossl b/openssl-install/share/man/man7/openssl-env.7ossl deleted file mode 100644 index ea6a0a5b..00000000 --- a/openssl-install/share/man/man7/openssl-env.7ossl +++ /dev/null @@ -1,297 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-ENV 7ossl" -.TH OPENSSL-ENV 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-env \- OpenSSL environment variables -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The OpenSSL libraries use environment variables to override the -compiled-in default paths for various data. -To avoid security risks, the environment is usually not consulted when -the executable is set-user-ID or set-group-ID. -.IP "\fB\s-1CTLOG_FILE\s0\fR" 4 -.IX Item "CTLOG_FILE" -Specifies the path to a certificate transparency log list. -See \fBCTLOG_STORE_new\fR\|(3). -.IP "\fB\s-1OPENSSL\s0\fR" 4 -.IX Item "OPENSSL" -Specifies the path to the \fBopenssl\fR executable. Used by -the \fBrehash\fR script (see \*(L"Script Configuration\*(R" in \fBopenssl\-rehash\fR\|(1)) -and by the \fB\s-1CA\s0.pl\fR script (see \*(L"\s-1NOTES\*(R"\s0 in \s-1\fBCA\s0.pl\fR\|(1) -.IP "\fB\s-1OPENSSL_CONF\s0\fR, \fB\s-1OPENSSL_CONF_INCLUDE\s0\fR" 4 -.IX Item "OPENSSL_CONF, OPENSSL_CONF_INCLUDE" -Specifies the path to a configuration file and the directory for -included files. -See \fBconfig\fR\|(5). -.IP "\fB\s-1OPENSSL_CONFIG\s0\fR" 4 -.IX Item "OPENSSL_CONFIG" -Specifies a configuration option and filename for the \fBreq\fR and \fBca\fR -commands invoked by the \fB\s-1CA\s0.pl\fR script. -See \s-1\fBCA\s0.pl\fR\|(1). -.IP "\fB\s-1OPENSSL_ENGINES\s0\fR" 4 -.IX Item "OPENSSL_ENGINES" -Specifies the directory from which dynamic engines are loaded. -See \fBopenssl\-engine\fR\|(1). -.IP "\fB\s-1OPENSSL_MALLOC_FD\s0\fR, \fB\s-1OPENSSL_MALLOC_FAILURES\s0\fR" 4 -.IX Item "OPENSSL_MALLOC_FD, OPENSSL_MALLOC_FAILURES" -If built with debugging, this allows memory allocation to fail. -See \fBOPENSSL_malloc\fR\|(3). -.IP "\fB\s-1OPENSSL_MODULES\s0\fR" 4 -.IX Item "OPENSSL_MODULES" -Specifies the directory from which cryptographic providers are loaded. -Equivalently, the generic \fB\-provider\-path\fR command-line option may be used. -.IP "\fB\s-1OPENSSL_TRACE\s0\fR" 4 -.IX Item "OPENSSL_TRACE" -By default the OpenSSL trace feature is disabled statically. -To enable it, OpenSSL must be built with tracing support, -which may be configured like this: \f(CW\*(C`./config enable\-trace\*(C'\fR -.Sp -Unless OpenSSL tracing support is generally disabled, -enable trace output of specific parts of OpenSSL libraries, by name. -This output usually makes sense only if you know OpenSSL internals well. -.Sp -The value of this environment varialble is a comma-separated list of names, -with the following available: -.RS 4 -.IP "\fB\s-1TRACE\s0\fR" 4 -.IX Item "TRACE" -Traces the OpenSSL trace \s-1API\s0 itself. -.IP "\fB\s-1INIT\s0\fR" 4 -.IX Item "INIT" -Traces OpenSSL library initialization and cleanup. -.IP "\fB\s-1TLS\s0\fR" 4 -.IX Item "TLS" -Traces the \s-1TLS/SSL\s0 protocol. -.IP "\fB\s-1TLS_CIPHER\s0\fR" 4 -.IX Item "TLS_CIPHER" -Traces the ciphers used by the \s-1TLS/SSL\s0 protocol. -.IP "\fB\s-1CONF\s0\fR" 4 -.IX Item "CONF" -Show details about provider and engine configuration. -.IP "\fB\s-1ENGINE_TABLE\s0\fR" 4 -.IX Item "ENGINE_TABLE" -The function that is used by \s-1RSA, DSA\s0 (etc) code to select registered -ENGINEs, cache defaults and functional references (etc), will generate -debugging summaries. -.IP "\fB\s-1ENGINE_REF_COUNT\s0\fR" 4 -.IX Item "ENGINE_REF_COUNT" -Reference counts in the \s-1ENGINE\s0 structure will be monitored with a line -of generated for each change. -.IP "\fB\s-1PKCS5V2\s0\fR" 4 -.IX Item "PKCS5V2" -Traces PKCS#5 v2 key generation. -.IP "\fB\s-1PKCS12_KEYGEN\s0\fR" 4 -.IX Item "PKCS12_KEYGEN" -Traces PKCS#12 key generation. -.IP "\fB\s-1PKCS12_DECRYPT\s0\fR" 4 -.IX Item "PKCS12_DECRYPT" -Traces PKCS#12 decryption. -.IP "\fBX509V3_POLICY\fR" 4 -.IX Item "X509V3_POLICY" -Generates the complete policy tree at various points during X.509 v3 -policy evaluation. -.IP "\fB\s-1BN_CTX\s0\fR" 4 -.IX Item "BN_CTX" -Traces \s-1BIGNUM\s0 context operations. -.IP "\fB\s-1CMP\s0\fR" 4 -.IX Item "CMP" -Traces \s-1CMP\s0 client and server activity. -.IP "\fB\s-1STORE\s0\fR" 4 -.IX Item "STORE" -Traces \s-1STORE\s0 operations. -.IP "\fB\s-1DECODER\s0\fR" 4 -.IX Item "DECODER" -Traces decoder operations. -.IP "\fB\s-1ENCODER\s0\fR" 4 -.IX Item "ENCODER" -Traces encoder operations. -.IP "\fB\s-1REF_COUNT\s0\fR" 4 -.IX Item "REF_COUNT" -Traces decrementing certain \s-1ASN.1\s0 structure references. -.IP "\fB\s-1HTTP\s0\fR" 4 -.IX Item "HTTP" -Traces the \s-1HTTP\s0 client and server, such as messages being sent and received. -.RE -.RS 4 -.RE -.IP "\fB\s-1OPENSSL_WIN32_UTF8\s0\fR" 4 -.IX Item "OPENSSL_WIN32_UTF8" -If set, then \fBUI_OpenSSL\fR\|(3) returns \s-1UTF\-8\s0 encoded strings, rather than -ones encoded in the current code page, and -the \fBopenssl\fR\|(1) program also transcodes the command-line parameters -from the current code page to \s-1UTF\-8.\s0 -This environment variable is only checked on Microsoft Windows platforms. -.IP "\fB\s-1RANDFILE\s0\fR" 4 -.IX Item "RANDFILE" -The state file for the random number generator. -This should not be needed in normal use. -See \fBRAND_load_file\fR\|(3). -.IP "\fB\s-1SSL_CERT_DIR\s0\fR, \fB\s-1SSL_CERT_FILE\s0\fR" 4 -.IX Item "SSL_CERT_DIR, SSL_CERT_FILE" -Specify the default directory or file containing \s-1CA\s0 certificates. -See \fBSSL_CTX_load_verify_locations\fR\|(3). -.IP "\fB\s-1TSGET\s0\fR" 4 -.IX Item "TSGET" -Additional arguments for the \fBtsget\fR\|(1) command. -.IP "\fBOPENSSL_ia32cap\fR, \fBOPENSSL_sparcv9cap\fR, \fBOPENSSL_ppccap\fR, \fBOPENSSL_armcap\fR, \fBOPENSSL_s390xcap\fR, \fBOPENSSL_riscvcap\fR" 4 -.IX Item "OPENSSL_ia32cap, OPENSSL_sparcv9cap, OPENSSL_ppccap, OPENSSL_armcap, OPENSSL_s390xcap, OPENSSL_riscvcap" -OpenSSL supports a number of different algorithm implementations for -various machines and, by default, it determines which to use based on the -processor capabilities and run time feature enquiry. These environment -variables can be used to exert more control over this selection process. -See \fBOPENSSL_ia32cap\fR\|(3), \fBOPENSSL_s390xcap\fR\|(3) and \fBOPENSSL_riscvcap\fR\|(3). -.IP "\fB\s-1NO_PROXY\s0\fR, \fB\s-1HTTPS_PROXY\s0\fR, \fB\s-1HTTP_PROXY\s0\fR" 4 -.IX Item "NO_PROXY, HTTPS_PROXY, HTTP_PROXY" -Specify a proxy hostname. -See \fBOSSL_HTTP_parse_url\fR\|(3). -.IP "\fB\s-1QLOGDIR\s0\fR" 4 -.IX Item "QLOGDIR" -Specifies a \s-1QUIC\s0 qlog output directory. See \fBopenssl\-qlog\fR\|(7). -.IP "\fB\s-1OSSL_QFILTER\s0\fR" 4 -.IX Item "OSSL_QFILTER" -Used to set a \s-1QUIC\s0 qlog filter specification. See \fBopenssl\-qlog\fR\|(7). -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl-glossary.7ossl b/openssl-install/share/man/man7/openssl-glossary.7ossl deleted file mode 100644 index f920eeb9..00000000 --- a/openssl-install/share/man/man7/openssl-glossary.7ossl +++ /dev/null @@ -1,339 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-GLOSSARY 7ossl" -.TH OPENSSL-GLOSSARY 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-glossary \- An OpenSSL Glossary -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -.IP "Algorithm" 4 -.IX Item "Algorithm" -Cryptographic primitives such as the \s-1SHA256\s0 digest, or \s-1AES\s0 encryption are -referred to in OpenSSL as \*(L"algorithms\*(R". There can be more than one -implementation for any given algorithm available for use. -.Sp -\&\fBcrypto\fR\|(7) -.IP "\s-1ASN.1, ASN1\s0" 4 -.IX Item "ASN.1, ASN1" -\&\s-1ASN.1\s0 (\*(L"Abstract Syntax Notation One\*(R") is a notation for describing abstract -types and values. It is defined in the ITU-T documents X.680 to X.683: -.Sp -, -, -, - -.IP "Base Provider" 4 -.IX Item "Base Provider" -An OpenSSL Provider that contains encoders and decoders for OpenSSL keys. All -the algorithm implementations in the Base Provider are also available in the -Default Provider. -.Sp -\&\fBOSSL_PROVIDER\-base\fR\|(7) -.IP "Decoder" 4 -.IX Item "Decoder" -A decoder is a type of algorithm used for decoding keys and parameters from some -external format such as \s-1PEM\s0 or \s-1DER.\s0 -.Sp -\&\fBOSSL_DECODER_CTX_new_for_pkey\fR\|(3) -.IP "Default Provider" 4 -.IX Item "Default Provider" -An OpenSSL Provider that contains the most common OpenSSL algorithm -implementations. It is loaded by default if no other provider is available. All -the algorithm implementations in the Base Provider are also available in the -Default Provider. -.Sp -\&\fBOSSL_PROVIDER\-default\fR\|(7) -.ie n .IP "\s-1DER\s0 (""Distinguished Encoding Rules"")" 4 -.el .IP "\s-1DER\s0 (``Distinguished Encoding Rules'')" 4 -.IX Item "DER (Distinguished Encoding Rules)" -\&\s-1DER\s0 is a binary encoding of data, structured according to an \s-1ASN.1\s0 -specification. This is a common encoding used for cryptographic objects -such as private and public keys, certificates, CRLs, ... -.Sp -It is defined in ITU-T document X.690: -.Sp - -.IP "Encoder" 4 -.IX Item "Encoder" -An encoder is a type of algorithm used for encoding keys and parameters to some -external format such as \s-1PEM\s0 or \s-1DER.\s0 -.Sp -\&\fBOSSL_ENCODER_CTX_new_for_pkey\fR\|(3) -.IP "Explicit Fetching" 4 -.IX Item "Explicit Fetching" -Explicit Fetching is a type of Fetching (see Fetching). Explicit Fetching is -where a function call is made to obtain an algorithm object representing an -implementation such as \fBEVP_MD_fetch\fR\|(3) or \fBEVP_CIPHER_fetch\fR\|(3) -.IP "Fetching" 4 -.IX Item "Fetching" -Fetching is the process of looking through the available algorithm -implementations, applying selection criteria (via a property query string), and -finally choosing the implementation that will be used. -.Sp -Also see Explicit Fetching and Implicit Fetching. -.Sp -\&\fBcrypto\fR\|(7) -.IP "\s-1FIPS\s0 Provider" 4 -.IX Item "FIPS Provider" -An OpenSSL Provider that contains OpenSSL algorithm implementations that have -been validated according to the \s-1FIPS 140\-2\s0 standard. -.Sp -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) -.IP "Implicit Fetching" 4 -.IX Item "Implicit Fetching" -Implicit Fetching is a type of Fetching (see Fetching). Implicit Fetching is -where an algorithm object with no associated implementation is used such as the -return value from \fBEVP_sha256\fR\|(3) or \fBEVP_aes_128_cbc\fR\|(3). With implicit -fetching an implementation is fetched automatically using default selection -criteria the first time the algorithm is used. -.IP "Legacy Provider" 4 -.IX Item "Legacy Provider" -An OpenSSL Provider that contains algorithm implementations that are considered -insecure or are no longer in common use. -.Sp -\&\fBOSSL_PROVIDER\-legacy\fR\|(7) -.IP "Library Context" 4 -.IX Item "Library Context" -A Library Context in OpenSSL is represented by the type \fB\s-1OSSL_LIB_CTX\s0\fR. It can -be thought of as a scope within which configuration options apply. If an -application does not explicitly create a library context then the \*(L"default\*(R" -one is used. Many OpenSSL functions can take a library context as an argument. -A \s-1NULL\s0 value can always be passed to indicate the default library context. -.Sp -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3) -.IP "\s-1MSBLOB\s0" 4 -.IX Item "MSBLOB" -\&\s-1MSBLOB\s0 is a Microsoft specific binary format for \s-1RSA\s0 and \s-1DSA\s0 keys, both -private and public. This form is never passphrase protected. -.IP "Null Provider" 4 -.IX Item "Null Provider" -An OpenSSL Provider that contains no algorithm implementations. This can be -useful to prevent the default provider from being automatically loaded in a -library context. -.Sp -\&\fBOSSL_PROVIDER\-null\fR\|(7) -.IP "Operation" 4 -.IX Item "Operation" -An operation is a group of OpenSSL functions with a common purpose such as -encryption, or digesting. -.Sp -\&\fBcrypto\fR\|(7) -.ie n .IP "\s-1PEM\s0 (""Privacy Enhanced Message"")" 4 -.el .IP "\s-1PEM\s0 (``Privacy Enhanced Message'')" 4 -.IX Item "PEM (Privacy Enhanced Message)" -\&\s-1PEM\s0 is a format used for encoding of binary content into a mail and \s-1ASCII\s0 -friendly form. The content is a series of base64\-encoded lines, surrounded -by begin/end markers each on their own line. For example: -.Sp -.Vb 4 -\& \-\-\-\-\-BEGIN PRIVATE KEY\-\-\-\-\- -\& MIICdg.... -\& ... bhTQ== -\& \-\-\-\-\-END PRIVATE KEY\-\-\-\-\- -.Ve -.Sp -Optional header line(s) may appear after the begin line, and their existence -depends on the type of object being written or read. -.Sp -For all OpenSSL uses, the binary content is expected to be a \s-1DER\s0 encoded -structure. -.Sp -This is defined in \s-1IETF RFC 1421:\s0 -.Sp - -.IP "PKCS#8" 4 -.IX Item "PKCS#8" -PKCS#8 is a specification of \s-1ASN.1\s0 structures that OpenSSL uses for storing -or transmitting any private key in a key type agnostic manner. -There are two structures worth noting for OpenSSL use, one that contains the -key data in unencrypted form (known as \*(L"PrivateKeyInfo\*(R") and an encrypted -wrapper structure (known as \*(L"EncryptedPrivateKeyInfo\*(R"). -.Sp -This is specified in \s-1RFC 5208:\s0 -.Sp - -.IP "Property" 4 -.IX Item "Property" -A property is a way of classifying and selecting algorithm implementations. -A property is a key/value pair expressed as a string. For example all algorithm -implementations in the default provider have the property \*(L"provider=default\*(R". -An algorithm implementation can have multiple properties defined against it. -.Sp -Also see Property Query String. -.Sp -\&\fBproperty\fR\|(7) -.IP "Property Query String" 4 -.IX Item "Property Query String" -A property query string is a string containing a sequence of properties that -can be used to select an algorithm implementation. For example the query string -\&\*(L"provider=example,foo=bar\*(R" will select algorithms from the \*(L"example\*(R" provider -that have a \*(L"foo\*(R" property defined for them with a value of \*(L"bar\*(R". -.Sp -Property Query Strings are used during fetching. See Fetching. -.Sp -\&\fBproperty\fR\|(7) -.IP "Provider" 4 -.IX Item "Provider" -A provider in OpenSSL is a component that groups together algorithm -implementations. Providers can come from OpenSSL itself or from third parties. -.Sp -\&\fBprovider\fR\|(7) -.IP "\s-1PVK\s0" 4 -.IX Item "PVK" -\&\s-1PVK\s0 is a Microsoft specific binary format for \s-1RSA\s0 and \s-1DSA\s0 private keys. -This form may be passphrase protected. -.IP "SubjectPublicKeyInfo" 4 -.IX Item "SubjectPublicKeyInfo" -SubjectPublicKeyInfo is an \s-1ASN.1\s0 structure that OpenSSL uses for storing and -transmitting any public key in a key type agnostic manner. -.Sp -This is specified as part of the specification for certificates, \s-1RFC 5280:\s0 -.Sp - -.SH "HISTORY" -.IX Header "HISTORY" -This glossary was added in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl-qlog.7ossl b/openssl-install/share/man/man7/openssl-qlog.7ossl deleted file mode 100644 index 1ee29bd0..00000000 --- a/openssl-install/share/man/man7/openssl-qlog.7ossl +++ /dev/null @@ -1,352 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-QLOG 7ossl" -.TH OPENSSL-QLOG 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-qlog \- OpenSSL qlog tracing functionality -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL has unstable support for generating logs in the qlog logging format, -which can be used to obtain diagnostic data for \s-1QUIC\s0 connections. The data -generated includes information on packets sent and received and the frames -contained within them, as well as loss detection and other events. -.PP -The qlog output generated by OpenSSL can be used to obtain diagnostic -visualisations of a given \s-1QUIC\s0 connection using tools such as \fBqvis\fR. -.PP -\&\fB\s-1WARNING:\s0\fR The output of OpenSSL's qlog functionality uses an unstable format -based on a draft specification. qlog output is not subject to any format -stability or compatibility guarantees at this time, and \fBwill\fR change in -incompatible ways in future versions of OpenSSL. See \fB\s-1FORMAT STABILITY\s0\fR below -for details. -.SH "USAGE" -.IX Header "USAGE" -When OpenSSL is built with qlog support, qlog is enabled at run time by setting -the standard \fB\s-1QLOGDIR\s0\fR environment variable to point to a directory where qlog -files should be written. Once set, any \s-1QUIC\s0 connection established by OpenSSL -will have a qlog file written automatically to the specified directory. -.PP -Log files are generated in the \fI.sqlog\fR format based on JSON-SEQ (\s-1RFC 7464\s0). -.PP -The filenames of generated log files under the specified \fB\s-1QLOGDIR\s0\fR use the -following structure: -.PP -.Vb 1 -\& {connection_odcid}_{vantage_point_type}.sqlog -.Ve -.PP -where \fB{connection_odcid}\fR is the lowercase hexadecimal encoding of a \s-1QUIC\s0 -connection's Original Destination Connection \s-1ID,\s0 which is the Destination -Connection \s-1ID\s0 used in the header of the first Initial packet sent as part of the -connection process, and \fB{vantage_point_type}\fR is either \f(CW\*(C`client\*(C'\fR or -\&\f(CW\*(C`server\*(C'\fR, reflecting the perspective of the endpoint producing the qlog output. -.PP -The qlog functionality can be disabled at OpenSSL build time using the -\&\fIno-unstable-qlog\fR configure flag. -.SH "SUPPORTED EVENT TYPES" -.IX Header "SUPPORTED EVENT TYPES" -The following event types are currently supported: -.IP "\fBconnectivity:connection_started\fR" 4 -.IX Item "connectivity:connection_started" -.PD 0 -.IP "\fBconnectivity:connection_state_updated\fR" 4 -.IX Item "connectivity:connection_state_updated" -.IP "\fBconnectivity:connection_closed\fR" 4 -.IX Item "connectivity:connection_closed" -.IP "\fBtransport:parameters_set\fR" 4 -.IX Item "transport:parameters_set" -.IP "\fBtransport:packet_sent\fR" 4 -.IX Item "transport:packet_sent" -.IP "\fBtransport:packet_received\fR" 4 -.IX Item "transport:packet_received" -.IP "\fBrecovery:packet_lost\fR" 4 -.IX Item "recovery:packet_lost" -.PD -.SH "FILTERS" -.IX Header "FILTERS" -By default, all supported event types are logged. The \fB\s-1OSSL_QFILTER\s0\fR -environment variable can be used to configure a filter specification which -determines which event types are to be logged. Each event type can be turned on -and off individually. The filter specification is a space-separated list of -terms listing event types to enable or disable. The terms are applied in order, -thus the effects of later terms override the effects of earlier terms. -.SS "Examples" -.IX Subsection "Examples" -Here are some example filter specifications: -.ie n .IP """*"" (or ""+*"")" 4 -.el .IP "\f(CW*\fR (or \f(CW+*\fR)" 4 -.IX Item "* (or +*)" -Enable all supported qlog event types. -.ie n .IP """\-*""" 4 -.el .IP "\f(CW\-*\fR" 4 -.IX Item "-*" -Disable all qlog event types. -.ie n .IP """* \-transport:packet_received""" 4 -.el .IP "\f(CW* \-transport:packet_received\fR" 4 -.IX Item "* -transport:packet_received" -Enable all qlog event types, but disable the \fBtransport:packet_received\fR event -type. -.ie n .IP """\-* transport:packet_sent""" 4 -.el .IP "\f(CW\-* transport:packet_sent\fR" 4 -.IX Item "-* transport:packet_sent" -Disable all qlog event types, except for the \fBtransport:packet_sent\fR event type. -.ie n .IP """\-* connectivity:* transport:parameters_set""" 4 -.el .IP "\f(CW\-* connectivity:* transport:parameters_set\fR" 4 -.IX Item "-* connectivity:* transport:parameters_set" -Disable all qlog event types, except for \fBtransport:parameters_set\fR and all -supported event types in the \fBconnectivity\fR category. -.SS "Filter Syntax Specification" -.IX Subsection "Filter Syntax Specification" -Formally, the format of the filter specification in \s-1ABNF\s0 is as follows: -.PP -.Vb 1 -\& filter = *filter\-term -\& -\& filter\-term = add\-sub\-term -\& -\& add\-sub\-term = ["\-" / "+"] specifier -\& -\& specifier = global\-specifier / qualified\-specifier -\& -\& global\-specifier = wildcard -\& -\& qualified\-specifier = component\-specifier ":" component\-specifier -\& -\& component\-specifier = name / wildcard -\& -\& wildcard = "*" -\& -\& name = 1*(ALPHA / DIGIT / "_" / "\-") -.Ve -.PP -Filter terms are interpreted as follows: -.ie n .IP """+*"" (or ""*"")" 4 -.el .IP "\f(CW+*\fR (or \f(CW*\fR)" 4 -.IX Item "+* (or *)" -Enables all event types. -.ie n .IP """\-*""" 4 -.el .IP "\f(CW\-*\fR" 4 -.IX Item "-*" -Disables all event types. -.ie n .IP """+foo:*"" (or ""foo:*"")" 4 -.el .IP "\f(CW+foo:*\fR (or \f(CWfoo:*\fR)" 4 -.IX Item "+foo:* (or foo:*)" -Enables all event types in the \fBfoo\fR category. -.ie n .IP """\-foo:*""" 4 -.el .IP "\f(CW\-foo:*\fR" 4 -.IX Item "-foo:*" -Disables all event types in the \fBfoo\fR category. -.ie n .IP """+foo:bar"" (or ""foo:bar"")" 4 -.el .IP "\f(CW+foo:bar\fR (or \f(CWfoo:bar\fR)" 4 -.IX Item "+foo:bar (or foo:bar)" -Enables a specific event type \fBfoo:bar\fR. -.ie n .IP """\-foo:bar""" 4 -.el .IP "\f(CW\-foo:bar\fR" 4 -.IX Item "-foo:bar" -Disables a specific event type \fBfoo:bar\fR. -.PP -Partial wildcard matches are not supported at this time. -.SS "Default Configuration" -.IX Subsection "Default Configuration" -If the \fB\s-1OSSL_QFILTER\s0\fR environment variable is not set or set to the empty -string, this is equivalent to enabling all event types (i.e., it is equivalent -to a filter of \f(CW\*(C`*\*(C'\fR). Note that the \fB\s-1QLOGDIR\s0\fR environment variable must also be -set to enable qlog. -.SH "FORMAT STABILITY" -.IX Header "FORMAT STABILITY" -The OpenSSL qlog functionality currently implements a draft version of the qlog -specification. Future revisions to the qlog specification in advance of formal -standardisation are expected to introduce incompatible and breaking changes to -the qlog format. The OpenSSL qlog functionality will transition to producing -output in this format in the future once standardisation is complete. -.PP -Because of this, the qlog output of OpenSSL \fBwill\fR change in incompatible and -breaking ways in the future, including in non-major releases of OpenSSL. The -qlog output of OpenSSL is considered unstable and not subject to any format -stability or compatibility guarantees at this time. -.PP -Users of the OpenSSL qlog functionality must be aware that the output may change -arbitrarily between releases and that the preservation of compatibility with any -given tool between releases is not guaranteed. -.SS "Aims" -.IX Subsection "Aims" -The OpenSSL draft qlog functionality is primarily intended for use in -conjunction with the qvis tool . In terms of -format compatibility, the output format of the OpenSSL qlog functionality is -expected to track what is supported by qvis. As such, future changes to the -output of the OpenSSL qlog functionality are expected to track changes in qvis -as they occur, and reflect the versions of qlog currently supported by qvis. -.PP -This means that prior to the finalisation of the qlog standard, in the event of -a disparity between the current draft and what qvis supports, the OpenSSL qlog -functionality will generally aim for qvis compatibility over compliance with the -latest draft. -.PP -As such, OpenSSL's qlog functionality currently implements qlog version 0.3 as -defined in \fBdraft\-ietf\-quic\-qlog\-main\-schema\-05\fR and -\&\fBdraft\-ietf\-quic\-qlog\-quic\-events\-04\fR. These revisions are intentionally used -instead of more recent revisions due to their qvis compatibility. -.SH "LIMITATIONS" -.IX Header "LIMITATIONS" -The OpenSSL implementation of qlog currently has the following limitations: -.IP "\(bu" 4 -Not all event types defined by the draft specification are implemented. -.IP "\(bu" 4 -Only the JSON-SEQ (\fB.sqlog\fR) output format is supported. -.IP "\(bu" 4 -Only the \fB\s-1QLOGDIR\s0\fR environment variable is supported for configuring the qlog -output directory. The standard \fB\s-1QLOGFILE\s0\fR environment variable is not -supported. -.IP "\(bu" 4 -There is no \s-1API\s0 for programmatically enabling or controlling the qlog -functionality. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\-quic\fR\|(7), \fBopenssl\-env\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -This functionality was added in OpenSSL 3.3. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl-quic.7ossl b/openssl-install/share/man/man7/openssl-quic.7ossl deleted file mode 100644 index 5eaa8513..00000000 --- a/openssl-install/share/man/man7/openssl-quic.7ossl +++ /dev/null @@ -1,791 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-QUIC 7ossl" -.TH OPENSSL-QUIC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-quic \- OpenSSL QUIC -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -OpenSSL 3.2 and later features support for the \s-1QUIC\s0 transport protocol. -Currently, only client connectivity is supported. This man page describes the -usage of \s-1QUIC\s0 client functionality for both existing and new applications. -.PP -\&\s-1QUIC\s0 functionality uses the standard \s-1SSL API. A QUIC\s0 connection is represented -by an \s-1SSL\s0 object in the same way that a \s-1TLS\s0 connection is. Only minimal changes -are needed to existing applications making use of the libssl APIs to make use of -\&\s-1QUIC\s0 client functionality. To make use of \s-1QUIC,\s0 use the \s-1SSL\s0 method -\&\fBOSSL_QUIC_client_method\fR\|(3) or \fBOSSL_QUIC_client_thread_method\fR\|(3) with -\&\fBSSL_CTX_new\fR\|(3). -.PP -When a \s-1QUIC\s0 connection is created, by default, it operates in default stream -mode, which is intended to provide compatibility with existing non-QUIC -application usage patterns. In this mode, the connection has a single -stream associated with it. Calls to \fBSSL_read\fR\|(3) and -\&\fBSSL_write\fR\|(3) on the \s-1QUIC\s0 connection \s-1SSL\s0 object read and write from that -stream. Whether the stream is client-initiated or server-initiated from a \s-1QUIC\s0 -perspective depends on whether \fBSSL_read\fR\|(3) or \fBSSL_write\fR\|(3) is called -first. See the \s-1MODES OF OPERATION\s0 section for more information. -.PP -The default stream mode is intended for compatibility with existing -applications. New applications using \s-1QUIC\s0 are recommended to disable default -stream mode and use the multi-stream \s-1API\s0; see the \s-1MODES OF OPERATION\s0 section and -the \s-1RECOMMENDATIONS FOR NEW APPLICATIONS\s0 section for more information. -.PP -The remainder of this man page discusses, in order: -.IP "\(bu" 4 -Default stream mode versus multi-stream mode; -.IP "\(bu" 4 -The changes to existing libssl APIs which are driven by QUIC-related implementation -requirements, which existing applications should bear in mind; -.IP "\(bu" 4 -Aspects which must be considered by existing applications when adopting \s-1QUIC,\s0 -including potential changes which may be needed. -.IP "\(bu" 4 -Recommended usage approaches for new applications. -.IP "\(bu" 4 -New, QUIC-specific APIs. -.SH "MODES OF OPERATION" -.IX Header "MODES OF OPERATION" -.SS "Default Stream Mode" -.IX Subsection "Default Stream Mode" -A \s-1QUIC\s0 client connection can be used in either default stream mode or -multi-stream mode. By default, a newly created \s-1QUIC\s0 connection \s-1SSL\s0 object uses -default stream mode. -.PP -In default stream mode, a stream is implicitly created and bound to the \s-1QUIC\s0 -connection \s-1SSL\s0 object; \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) calls to the \s-1QUIC\s0 -connection \s-1SSL\s0 object work by default and are mapped to that stream. -.PP -When default stream mode is used, any \s-1API\s0 function which can be called on a \s-1QUIC\s0 -stream \s-1SSL\s0 object can also be called on a \s-1QUIC\s0 connection \s-1SSL\s0 object, in which -case it affects the default stream bound to the connection. -.PP -The identity of a \s-1QUIC\s0 stream, including its stream \s-1ID,\s0 varies depending on -whether a stream is client-initiated or server-initiated. In default stream -mode, if a client application calls \fBSSL_read\fR\|(3) first before any call to -\&\fBSSL_write\fR\|(3) on the connection, it is assumed that the application protocol -is using a server-initiated stream, and the \fBSSL_read\fR\|(3) call will not -complete (either blocking, or failing appropriately if nonblocking mode is -configured) until the server initiates a stream. Conversely, if the client -application calls \fBSSL_write\fR\|(3) before any call to \fBSSL_read\fR\|(3) on the -connection, it is assumed that a client-initiated stream is to be used -and such a stream is created automatically. -.PP -Default stream mode is intended to aid compatibility with legacy applications. -New applications adopting \s-1QUIC\s0 should use multi-stream mode, described below, -and avoid use of the default stream functionality. -.PP -It is possible to use additional streams in default stream mode using -\&\fBSSL_new_stream\fR\|(3) and \fBSSL_accept_stream\fR\|(3); note that the default incoming -stream policy will need to be changed using \fBSSL_set_incoming_stream_policy\fR\|(3) -in order to use \fBSSL_accept_stream\fR\|(3) in this case. However, applications -using additional streams are strongly recommended to use multi-stream mode -instead. -.PP -Calling \fBSSL_new_stream\fR\|(3) or \fBSSL_accept_stream\fR\|(3) before a default stream -has been associated with the \s-1QUIC\s0 connection \s-1SSL\s0 object will inhibit future -creation of a default stream. -.SS "Multi-Stream Mode" -.IX Subsection "Multi-Stream Mode" -The recommended usage mode for new applications adopting \s-1QUIC\s0 is multi-stream -mode, in which no default stream is attached to the \s-1QUIC\s0 connection \s-1SSL\s0 object -and attempts to call \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) on the \s-1QUIC\s0 connection -\&\s-1SSL\s0 object fail. Instead, an application calls \fBSSL_new_stream\fR\|(3) or -\&\fBSSL_accept_stream\fR\|(3) to create individual stream \s-1SSL\s0 objects for sending and -receiving application data using \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3). -.PP -To use multi-stream mode, call \fBSSL_set_default_stream_mode\fR\|(3) with an -argument of \fB\s-1SSL_DEFAULT_STREAM_MODE_NONE\s0\fR; this function must be called prior -to initiating the connection. The default stream mode cannot be changed after -initiating a connection. -.PP -When multi-stream mode is used, meaning that no default stream is associated -with the connection, calls to \s-1API\s0 functions which are defined as operating on a -\&\s-1QUIC\s0 stream fail if called on the \s-1QUIC\s0 connection \s-1SSL\s0 object. For example, calls -such as \fBSSL_write\fR\|(3) or \fBSSL_get_stream_id\fR\|(3) will fail. -.SH "CHANGES TO EXISTING APIS" -.IX Header "CHANGES TO EXISTING APIS" -Most \s-1SSL\s0 APIs, such as \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3), function as they do -for \s-1TLS\s0 connections and do not have changed semantics, with some exceptions. The -changes to the semantics of existing APIs are as follows: -.IP "\(bu" 4 -Since \s-1QUIC\s0 uses \s-1UDP,\s0 \fBSSL_set_bio\fR\|(3), \fBSSL_set0_rbio\fR\|(3) and -\&\fBSSL_set0_wbio\fR\|(3) function as before, but must now receive a \s-1BIO\s0 with datagram -semantics. There are broadly four options for applications to use as a network -\&\s-1BIO:\s0 -.RS 4 -.IP "\(bu" 4 -\&\fBBIO_s_datagram\fR\|(3), recommended for most applications, replaces -\&\fBBIO_s_socket\fR\|(3) and provides a \s-1UDP\s0 socket. -.IP "\(bu" 4 -\&\fBBIO_s_dgram_pair\fR\|(3) provides \s-1BIO\s0 pair-like functionality but with datagram -semantics, and is recommended for existing applications which use a \s-1BIO\s0 pair or -memory \s-1BIO\s0 to manage libssl's communication with the network. -.IP "\(bu" 4 -\&\fBBIO_s_dgram_mem\fR\|(3) provides a simple memory BIO-like interface but with -datagram semantics. Unlike \fBBIO_s_dgram_pair\fR\|(3), it is unidirectional. -.IP "\(bu" 4 -An application may also choose to implement a custom \s-1BIO.\s0 The new -\&\fBBIO_sendmmsg\fR\|(3) and \fBBIO_recvmmsg\fR\|(3) APIs must be supported. -.RE -.RS 4 -.RE -.IP "\(bu" 4 -\&\fBSSL_set_fd\fR\|(3), \fBSSL_set_rfd\fR\|(3) and \fBSSL_set_wfd\fR\|(3) traditionally -instantiate a \fBBIO_s_socket\fR\|(3). For \s-1QUIC,\s0 these functions instead instantiate -a \fBBIO_s_datagram\fR\|(3). This is equivalent to instantiating a -\&\fBBIO_s_datagram\fR\|(3) and using \fBSSL_set0_rbio\fR\|(3) and \fBSSL_set0_wbio\fR\|(3). -.IP "\(bu" 4 -Traditionally, whether the application-level I/O APIs (such as \fBSSL_read\fR\|(3) -and \fBSSL_write\fR\|(3) operated in a blocking fashion was directly correlated with -whether the underlying network socket was configured in a blocking fashion. This -is no longer the case; applications must explicitly configure the desired -application-level blocking mode using \fBSSL_set_blocking_mode\fR\|(3). See -\&\fBSSL_set_blocking_mode\fR\|(3) for details. -.IP "\(bu" 4 -Network-level I/O must always be performed in a nonblocking manner. The -application can still enjoy blocking semantics for calls to application-level -I/O functions such as \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3), but the underlying -network \s-1BIO\s0 provided to \s-1QUIC\s0 (such as a \fBBIO_s_datagram\fR\|(3)) must be configured -in nonblocking mode. For application-level blocking functionality, see -\&\fBSSL_set_blocking_mode\fR\|(3). -.IP "\(bu" 4 -\&\fBBIO_new_ssl_connect\fR\|(3) has been changed to automatically use a -\&\fBBIO_s_datagram\fR\|(3) when used with \s-1QUIC,\s0 therefore applications which use this -do not need to change the \s-1BIO\s0 they use. -.IP "\(bu" 4 -\&\fBBIO_new_buffer_ssl_connect\fR\|(3) cannot be used with \s-1QUIC\s0 and applications must -change to use \fBBIO_new_ssl_connect\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBSSL_shutdown\fR\|(3) has significant changes in relation to how \s-1QUIC\s0 connections -must be shut down. In particular, applications should be advised that the full -RFC-conformant \s-1QUIC\s0 shutdown process may take an extended amount of time. This -may not be suitable for short-lived processes which should exit immediately -after their usage of a \s-1QUIC\s0 connection is completed. A rapid shutdown mode -is available for such applications. For details, see \fBSSL_shutdown\fR\|(3). -.IP "\(bu" 4 -\&\fBSSL_want\fR\|(3), \fBSSL_want_read\fR\|(3) and \fBSSL_want_write\fR\|(3) no longer reflect -the I/O state of the network \s-1BIO\s0 passed to the \s-1QUIC SSL\s0 object, but instead -reflect the flow control state of the \s-1QUIC\s0 stream associated with the \s-1SSL\s0 -object. -.Sp -When used in nonblocking mode, \fB\s-1SSL_ERROR_WANT_READ\s0\fR indicates that the -receive part of a \s-1QUIC\s0 stream does not currently have any more data available to -be read, and \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR indicates that the stream's internal buffer -is full. -.Sp -To determine if the \s-1QUIC\s0 implementation currently wishes to be informed of -incoming network datagrams, use the new function \fBSSL_net_read_desired\fR\|(3); -likewise, to determine if the \s-1QUIC\s0 implementation currently wishes to be -informed when it is possible to transmit network datagrams, use the new function -\&\fBSSL_net_write_desired\fR\|(3). Only applications which wish to manage their own event -loops need to use these functions; see \fBAPPLICATION-DRIVEN \s-1EVENT LOOPS\s0\fR for -further discussion. -.IP "\(bu" 4 -The use of \s-1ALPN\s0 is mandatory when using \s-1QUIC.\s0 Attempts to connect without -configuring \s-1ALPN\s0 will fail. For information on how to configure \s-1ALPN,\s0 see -\&\fBSSL_set_alpn_protos\fR\|(3). -.IP "\(bu" 4 -Whether \s-1QUIC\s0 operates in a client or server mode is determined by the -\&\fB\s-1SSL_METHOD\s0\fR used, rather than by calls to \fBSSL_set_connect_state\fR\|(3) or -\&\fBSSL_set_accept_state\fR\|(3). It is not necessary to call either of -\&\fBSSL_set_connect_state\fR\|(3) or \fBSSL_set_accept_state\fR\|(3) before connecting, but -if either of these are called, the function called must be congruent with the -\&\fB\s-1SSL_METHOD\s0\fR being used. Currently, only client mode is supported. -.IP "\(bu" 4 -The \fBSSL_set_min_proto_version\fR\|(3) and \fBSSL_set_max_proto_version\fR\|(3) APIs are -not used and the values passed to them are ignored, as OpenSSL \s-1QUIC\s0 currently -always uses \s-1TLS 1.3.\s0 -.IP "\(bu" 4 -The following libssl functionality is not available when used with \s-1QUIC.\s0 -.RS 4 -.IP "\(bu" 4 -Async functionality -.IP "\(bu" 4 -\&\fB\s-1SSL_MODE_AUTO_RETRY\s0\fR -.IP "\(bu" 4 -Record Padding and Fragmentation (\fBSSL_set_block_padding\fR\|(3), etc.) -.IP "\(bu" 4 -\&\fBSSL_stateless\fR\|(3) support -.IP "\(bu" 4 -\&\s-1SRTP\s0 functionality -.IP "\(bu" 4 -TLSv1.3 Early Data -.IP "\(bu" 4 -\&\s-1TLS\s0 Next Protocol Negotiation cannot be used and is superseded by \s-1ALPN,\s0 which -must be used instead. The use of \s-1ALPN\s0 is mandatory with \s-1QUIC.\s0 -.IP "\(bu" 4 -Post-Handshake Client Authentication is not available as \s-1QUIC\s0 prohibits its use. -.IP "\(bu" 4 -\&\s-1QUIC\s0 requires the use of TLSv1.3 or later, therefore functionality only relevant -to older \s-1TLS\s0 versions is not available. -.IP "\(bu" 4 -Some cipher suites which are generally available for TLSv1.3 are not available -for \s-1QUIC,\s0 such as \fB\s-1TLS_AES_128_CCM_8_SHA256\s0\fR. Your application may need to -adjust the list of acceptable cipher suites it passes to libssl. -.IP "\(bu" 4 -\&\s-1CCM\s0 mode is not currently supported. -.RE -.RS 4 -.Sp -The following libssl functionality is also not available when used with \s-1QUIC,\s0 -but calls to the relevant functions are treated as no-ops: -.IP "\(bu" 4 -Readahead (\fBSSL_set_read_ahead\fR\|(3), etc.) -.RE -.RS 4 -.RE -.SH "CONSIDERATIONS FOR EXISTING APPLICATIONS" -.IX Header "CONSIDERATIONS FOR EXISTING APPLICATIONS" -Existing applications seeking to adopt \s-1QUIC\s0 should apply the following list to -determine what changes they will need to make: -.IP "\(bu" 4 -An application wishing to use \s-1QUIC\s0 must use \fBOSSL_QUIC_client_method\fR\|(3) or -\&\fBOSSL_QUIC_client_thread_method\fR\|(3) as its \s-1SSL\s0 method. For more information -on the differences between these two methods, see \fB\s-1THREAD ASSISTED MODE\s0\fR. -.IP "\(bu" 4 -Determine how to provide \s-1QUIC\s0 with network access. Determine which of the below -apply for your application: -.RS 4 -.IP "\(bu" 4 -Your application uses \fBBIO_s_socket\fR\|(3) to construct a \s-1BIO\s0 which is passed to -the \s-1SSL\s0 object to provide it with network access. -.Sp -Changes needed: Change your application to use \fBBIO_s_datagram\fR\|(3) instead when -using \s-1QUIC.\s0 The socket must be configured in nonblocking mode. You may or may -not need to use \fBSSL_set1_initial_peer_addr\fR\|(3) to set the initial peer -address; see the \fBQUIC-SPECIFIC \s-1APIS\s0\fR section for details. -.IP "\(bu" 4 -Your application uses \fBBIO_new_ssl_connect\fR\|(3) to -construct a \s-1BIO\s0 which is passed to the \s-1SSL\s0 object to provide it with network -access. -.Sp -Changes needed: No changes needed. Use of \s-1QUIC\s0 is detected automatically and a -datagram socket is created instead of a normal \s-1TCP\s0 socket. -.IP "\(bu" 4 -Your application uses any other I/O strategy in this list but combines it with a -\&\fBBIO_f_buffer\fR\|(3), for example using \fBBIO_push\fR\|(3). -.Sp -Changes needed: Disable the usage of \fBBIO_f_buffer\fR\|(3) when using \s-1QUIC.\s0 Usage -of such a buffer is incompatible with \s-1QUIC\s0 as \s-1QUIC\s0 requires datagram semantics -in its interaction with the network. -.IP "\(bu" 4 -Your application uses a \s-1BIO\s0 pair to cause the \s-1SSL\s0 object to read and write -network traffic to a memory buffer. Your application manages the transmission -and reception of buffered data itself in a way unknown to libssl. -.Sp -Changes needed: Switch from using a conventional \s-1BIO\s0 pair to using -\&\fBBIO_s_dgram_pair\fR\|(3) instead, which has the necessary datagram semantics. You -will need to modify your application to transmit and receive using a \s-1UDP\s0 socket -and to use datagram semantics when interacting with the \fBBIO_s_dgram_pair\fR\|(3) -instance. -.IP "\(bu" 4 -Your application uses a custom \s-1BIO\s0 method to provide the \s-1SSL\s0 object with network -access. -.Sp -Changes needed: The custom \s-1BIO\s0 must be re-architected to have datagram -semantics. \fBBIO_sendmmsg\fR\|(3) and \fBBIO_recvmmsg\fR\|(3) must be implemented. These -calls must operate in a nonblocking fashion. Optionally, implement the -\&\fBBIO_get_rpoll_descriptor\fR\|(3) and \fBBIO_get_wpoll_descriptor\fR\|(3) methods if -desired. Implementing these methods is required if blocking semantics at the \s-1SSL -API\s0 level are desired. -.RE -.RS 4 -.RE -.IP "\(bu" 4 -An application must explicitly configure whether it wishes to use the \s-1SSL\s0 APIs -in blocking mode or not. Traditionally, an \s-1SSL\s0 object has automatically operated -in blocking or nonblocking mode based on whether the underlying network \s-1BIO\s0 -operates in blocking or nonblocking mode. \s-1QUIC\s0 requires the use of a -nonblocking network \s-1BIO,\s0 therefore the blocking mode at the application level -must be explicitly configured by the application using the new -\&\fBSSL_set_blocking_mode\fR\|(3) \s-1API.\s0 The default mode is blocking. If an application -wishes to use the \s-1SSL\s0 object APIs at application level in a nonblocking manner, -it must add a call to \fBSSL_set_blocking_mode\fR\|(3) to disable blocking mode. -.IP "\(bu" 4 -If your application does not choose to use thread assisted mode, it must ensure -that it calls an I/O function on the \s-1SSL\s0 object (for example, \fBSSL_read\fR\|(3) or -\&\fBSSL_write\fR\|(3)), or the new function \fBSSL_handle_events\fR\|(3), regularly. If the -\&\s-1SSL\s0 object is used in blocking mode, an ongoing blocking call to an I/O function -satisfies this requirement. This is required to ensure that timer events -required by \s-1QUIC\s0 are handled in a timely fashion. -.Sp -Most applications will service the \s-1SSL\s0 object by calling \fBSSL_read\fR\|(3) or -\&\fBSSL_write\fR\|(3) regularly. If an application does not do this, it should ensure -that \fBSSL_handle_events\fR\|(3) is called regularly. -.Sp -\&\fBSSL_get_event_timeout\fR\|(3) can be used to determine when -\&\fBSSL_handle_events\fR\|(3) must next be called. -.Sp -If the \s-1SSL\s0 object is being used with an underlying network \s-1BIO\s0 which is pollable -(such as \fBBIO_s_datagram\fR\|(3)), the application can use -\&\fBSSL_get_rpoll_descriptor\fR\|(3), \fBSSL_get_wpoll_descriptor\fR\|(3) to obtain -resources which can be used to determine when \fBSSL_handle_events\fR\|(3) should be -called due to network I/O. -.Sp -Applications which use thread assisted mode do not need to be concerned -with this requirement, as the \s-1QUIC\s0 implementation ensures timeout events -are handled in a timely manner. See \fB\s-1THREAD ASSISTED MODE\s0\fR for details. -.IP "\(bu" 4 -Ensure that your usage of \fBSSL_want\fR\|(3), \fBSSL_want_read\fR\|(3) and -\&\fBSSL_want_write\fR\|(3) reflects the \s-1API\s0 changes described in \fB\s-1CHANGES TO EXISTING -APIS\s0\fR. In particular, you should use these APIs to determine the ability of a -\&\s-1QUIC\s0 stream to receive or provide application data, not to to determine if -network I/O is required. -.IP "\(bu" 4 -Evaluate your application's use of \fBSSL_shutdown\fR\|(3) in light of the changes -discussed in \fB\s-1CHANGES TO EXISTING APIS\s0\fR. Depending on whether your application -wishes to prioritise \s-1RFC\s0 conformance or rapid shutdown, consider using the new -\&\fBSSL_shutdown_ex\fR\|(3) \s-1API\s0 instead. See \fBQUIC-SPECIFIC \s-1APIS\s0\fR for details. -.SH "RECOMMENDED USAGE IN NEW APPLICATIONS" -.IX Header "RECOMMENDED USAGE IN NEW APPLICATIONS" -The recommended usage in new applications varies depending on three independent -design decisions: -.IP "\(bu" 4 -Whether the application will use blocking or nonblocking I/O at the application -level (configured using \fBSSL_set_blocking_mode\fR\|(3)). -.Sp -If the application does nonblocking I/O at the application level it can choose -to manage its own polling and event loop; see \fBAPPLICATION-DRIVEN \s-1EVENT LOOPS\s0\fR. -.IP "\(bu" 4 -Whether the application intends to give the \s-1QUIC\s0 implementation direct access to -a network socket (e.g. via \fBBIO_s_datagram\fR\|(3)) or whether it intends to buffer -transmitted and received datagrams via a \fBBIO_s_dgram_pair\fR\|(3) or custom \s-1BIO.\s0 -.Sp -The former is preferred where possible as it reduces latency to the network, -which enables \s-1QUIC\s0 to achieve higher performance and more accurate connection -round trip time (\s-1RTT\s0) estimation. -.IP "\(bu" 4 -Whether thread assisted mode will be used (see \fB\s-1THREAD ASSISTED MODE\s0\fR). -.PP -Simple demos for \s-1QUIC\s0 usage under these various scenarios can be found at -. -.PP -Applications which wish to implement QUIC-specific protocols should be aware of -the APIs listed under \fBQUIC-SPECIFIC \s-1APIS\s0\fR which provide access to -QUIC-specific functionality. For example, \fBSSL_stream_conclude\fR\|(3) can be used -to indicate the end of the sending part of a stream, and \fBSSL_shutdown_ex\fR\|(3) -can be used to provide a \s-1QUIC\s0 application error code when closing a connection. -.PP -Regardless of the design decisions chosen above, it is recommended that new -applications avoid use of the default stream mode and use the multi-stream \s-1API\s0 -by calling \fBSSL_set_default_stream_mode\fR\|(3); see the \s-1MODES OF OPERATION\s0 section -for details. -.SH "QUIC-SPECIFIC APIS" -.IX Header "QUIC-SPECIFIC APIS" -This section details new APIs which are directly or indirectly related to \s-1QUIC.\s0 -For details on the operation of each \s-1API,\s0 see the referenced man pages. -.PP -The following \s-1SSL\s0 APIs are new but relevant to both \s-1QUIC\s0 and \s-1DTLS:\s0 -.IP "\fBSSL_get_event_timeout\fR\|(3)" 4 -.IX Item "SSL_get_event_timeout" -Determines when the \s-1QUIC\s0 implementation should next be woken up via a call to -\&\fBSSL_handle_events\fR\|(3) (or another I/O function such as \fBSSL_read\fR\|(3) or -\&\fBSSL_write\fR\|(3)), if ever. -.Sp -This can also be used with \s-1DTLS\s0 and supersedes \fBDTLSv1_get_timeout\fR\|(3) for new -usage. -.IP "\fBSSL_handle_events\fR\|(3)" 4 -.IX Item "SSL_handle_events" -This is a non-specific I/O operation which makes a best effort attempt to -perform any pending I/O or timeout processing. It can be used to advance the -\&\s-1QUIC\s0 state machine by processing incoming network traffic, generating outgoing -network traffic and handling any expired timeout events. Most other I/O -functions on an \s-1SSL\s0 object, such as \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) -implicitly perform event handling on the \s-1SSL\s0 object, so calling this function is -only needed if no other I/O function is to be called. -.Sp -This can also be used with \s-1DTLS\s0 and supersedes \fBDTLSv1_handle_timeout\fR\|(3) for -new usage. -.PP -The following \s-1SSL\s0 APIs are specific to \s-1QUIC:\s0 -.IP "\fBSSL_set_blocking_mode\fR\|(3), \fBSSL_get_blocking_mode\fR\|(3)" 4 -.IX Item "SSL_set_blocking_mode, SSL_get_blocking_mode" -Configures whether blocking semantics are used at the application level. This -determines whether calls to functions such as \fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) -will block. -.IP "\fBSSL_get_rpoll_descriptor\fR\|(3), \fBSSL_get_wpoll_descriptor\fR\|(3)" 4 -.IX Item "SSL_get_rpoll_descriptor, SSL_get_wpoll_descriptor" -These functions facilitate operation in nonblocking mode. -.Sp -When an \s-1SSL\s0 object is being used with an underlying network read \s-1BIO\s0 which -supports polling, \fBSSL_get_rpoll_descriptor\fR\|(3) outputs an \s-1OS\s0 resource which -can be used to synchronise on network readability events which should result in -a call to \fBSSL_handle_events\fR\|(3). \fBSSL_get_wpoll_descriptor\fR\|(3) works in an -analogous fashion for the underlying network write \s-1BIO.\s0 -.Sp -The poll descriptors provided by these functions need only be used when -\&\fBSSL_net_read_desired\fR\|(3) and \fBSSL_net_write_desired\fR\|(3) return 1, respectively. -.IP "\fBSSL_net_read_desired\fR\|(3), \fBSSL_net_write_desired\fR\|(3)" 4 -.IX Item "SSL_net_read_desired, SSL_net_write_desired" -These functions facilitate operation in nonblocking mode and are used in -conjunction with \fBSSL_get_rpoll_descriptor\fR\|(3) and -\&\fBSSL_get_wpoll_descriptor\fR\|(3) respectively. They determine whether the -respective poll descriptor is currently relevant for the purposes of polling. -.IP "\fBSSL_set1_initial_peer_addr\fR\|(3)" 4 -.IX Item "SSL_set1_initial_peer_addr" -This function can be used to set the initial peer address for an outgoing \s-1QUIC\s0 -connection. This function must be used in the general case when creating an -outgoing \s-1QUIC\s0 connection; however, the correct initial peer address can be -autodetected in some cases. See \fBSSL_set1_initial_peer_addr\fR\|(3) for details. -.IP "\fBSSL_shutdown_ex\fR\|(3)" 4 -.IX Item "SSL_shutdown_ex" -This augments \fBSSL_shutdown\fR\|(3) by allowing an application error code to be -specified. It also allows a client to decide how quickly it wants a shutdown to -be performed, potentially by trading off strict \s-1RFC\s0 compliance. -.IP "\fBSSL_stream_conclude\fR\|(3)" 4 -.IX Item "SSL_stream_conclude" -This allows an application to indicate the normal end of the sending part of a -\&\s-1QUIC\s0 stream. This corresponds to the \s-1FIN\s0 flag in the \s-1QUIC RFC.\s0 The receiving -part of a stream remains usable. -.IP "\fBSSL_stream_reset\fR\|(3)" 4 -.IX Item "SSL_stream_reset" -This allows an application to indicate the non-normal termination of the sending -part of a stream. This corresponds to the \s-1RESET_STREAM\s0 frame in the \s-1QUIC RFC.\s0 -.IP "\fBSSL_get_stream_write_state\fR\|(3) and \fBSSL_get_stream_read_state\fR\|(3)" 4 -.IX Item "SSL_get_stream_write_state and SSL_get_stream_read_state" -This allows an application to determine the current stream states for the -sending and receiving parts of a stream respectively. -.IP "\fBSSL_get_stream_write_error_code\fR\|(3) and \fBSSL_get_stream_read_error_code\fR\|(3)" 4 -.IX Item "SSL_get_stream_write_error_code and SSL_get_stream_read_error_code" -This allows an application to determine the application error code which was -signalled by a peer which has performed a non-normal stream termination of the -respective sending or receiving part of a stream, if any. -.IP "\fBSSL_get_conn_close_info\fR\|(3)" 4 -.IX Item "SSL_get_conn_close_info" -This allows an application to determine the error code which was signalled when -the local or remote endpoint terminated the \s-1QUIC\s0 connection. -.IP "\fBSSL_get0_connection\fR\|(3)" 4 -.IX Item "SSL_get0_connection" -Gets the \s-1QUIC\s0 connection \s-1SSL\s0 object from a \s-1QUIC\s0 stream \s-1SSL\s0 object. -.IP "\fBSSL_is_connection\fR\|(3)" 4 -.IX Item "SSL_is_connection" -Returns 1 if a \s-1SSL\s0 object is not a \s-1QUIC\s0 stream \s-1SSL\s0 object. -.IP "\fBSSL_get_stream_type\fR\|(3)" 4 -.IX Item "SSL_get_stream_type" -Provides information on the kind of \s-1QUIC\s0 stream which is attached -to the \s-1SSL\s0 object. -.IP "\fBSSL_get_stream_id\fR\|(3)" 4 -.IX Item "SSL_get_stream_id" -Returns the \s-1QUIC\s0 stream \s-1ID\s0 which the \s-1QUIC\s0 protocol has associated with a \s-1QUIC\s0 -stream. -.IP "\fBSSL_new_stream\fR\|(3)" 4 -.IX Item "SSL_new_stream" -Creates a new \s-1QUIC\s0 stream \s-1SSL\s0 object representing a new, locally-initiated \s-1QUIC\s0 -stream. -.IP "\fBSSL_accept_stream\fR\|(3)" 4 -.IX Item "SSL_accept_stream" -Potentially yields a new \s-1QUIC\s0 stream \s-1SSL\s0 object representing a new -remotely-initiated \s-1QUIC\s0 stream, blocking until one is available if the -connection is configured to do so. -.IP "\fBSSL_get_accept_stream_queue_len\fR\|(3)" 4 -.IX Item "SSL_get_accept_stream_queue_len" -Provides information on the number of pending remotely-initiated streams. -.IP "\fBSSL_set_incoming_stream_policy\fR\|(3)" 4 -.IX Item "SSL_set_incoming_stream_policy" -Configures how incoming, remotely-initiated streams are handled. The incoming -stream policy can be used to automatically reject streams created by the peer, -or allow them to be handled using \fBSSL_accept_stream\fR\|(3). -.IP "\fBSSL_set_default_stream_mode\fR\|(3)" 4 -.IX Item "SSL_set_default_stream_mode" -Used to configure or disable default stream mode; see the \s-1MODES OF OPERATION\s0 -section for details. -.PP -The following \s-1BIO\s0 APIs are not specific to \s-1QUIC\s0 but have been added to -facilitate QUIC-specific requirements and are closely associated with its use: -.IP "\fBBIO_s_dgram_pair\fR\|(3)" 4 -.IX Item "BIO_s_dgram_pair" -This is a new \s-1BIO\s0 method which is similar to a conventional \s-1BIO\s0 pair but -provides datagram semantics. -.IP "\fBBIO_get_rpoll_descriptor\fR\|(3), \fBBIO_get_wpoll_descriptor\fR\|(3)" 4 -.IX Item "BIO_get_rpoll_descriptor, BIO_get_wpoll_descriptor" -This is a new \s-1BIO API\s0 which allows a \s-1BIO\s0 to expose a poll descriptor. This \s-1API\s0 -is used to implement the corresponding \s-1SSL\s0 APIs \fBSSL_get_rpoll_descriptor\fR\|(3) -and \fBSSL_get_wpoll_descriptor\fR\|(3). -.IP "\fBBIO_sendmmsg\fR\|(3), \fBBIO_recvmmsg\fR\|(3)" 4 -.IX Item "BIO_sendmmsg, BIO_recvmmsg" -This is a new \s-1BIO API\s0 which can be implemented by BIOs which implement datagram -semantics. It is implemented by \fBBIO_s_datagram\fR\|(3) and \fBBIO_s_dgram_pair\fR\|(3). -It is used by the \s-1QUIC\s0 implementation to send and receive \s-1UDP\s0 datagrams. -.IP "\fBBIO_dgram_set_no_trunc\fR\|(3), \fBBIO_dgram_get_no_trunc\fR\|(3)" 4 -.IX Item "BIO_dgram_set_no_trunc, BIO_dgram_get_no_trunc" -By default, \fBBIO_s_dgram_pair\fR\|(3) has semantics comparable to those of Berkeley -sockets being used with datagram semantics. This allows an alternative mode -to be enabled in which datagrams will not be silently truncated if they are -too large. -.IP "\fBBIO_dgram_set_caps\fR\|(3), \fBBIO_dgram_get_caps\fR\|(3)" 4 -.IX Item "BIO_dgram_set_caps, BIO_dgram_get_caps" -These functions are used to allow the user of one end of a -\&\fBBIO_s_dgram_pair\fR\|(3) to indicate its capabilities to the other end of a -\&\fBBIO_s_dgram_pair\fR\|(3). In particular, this allows an application to inform the -\&\s-1QUIC\s0 implementation of whether it is prepared to handle local and/or peer -addresses in transmitted datagrams and to provide the applicable information in -received datagrams. -.IP "\fBBIO_dgram_get_local_addr_cap\fR\|(3), \fBBIO_dgram_set_local_addr_enable\fR\|(3), \fBBIO_dgram_get_local_addr_enable\fR\|(3)" 4 -.IX Item "BIO_dgram_get_local_addr_cap, BIO_dgram_set_local_addr_enable, BIO_dgram_get_local_addr_enable" -Local addressing support refers to the ability of a \s-1BIO\s0 with datagram semantics -to allow a source address to be specified on transmission and to report the -destination address on reception. These functions can be used to determine if a -\&\s-1BIO\s0 can support local addressing and to enable local addressing support if it -can. -.IP "\fBBIO_err_is_non_fatal\fR\|(3)" 4 -.IX Item "BIO_err_is_non_fatal" -This is used to determine if an error while calling \fBBIO_sendmmsg\fR\|(3) or -\&\fBBIO_recvmmsg\fR\|(3) is ephemeral in nature, such as \*(L"would block\*(R" errors. -.SH "THREAD ASSISTED MODE" -.IX Header "THREAD ASSISTED MODE" -The optional thread assisted mode can be used with -\&\fBOSSL_QUIC_client_thread_method\fR\|(3). In this mode, a background thread is -created automatically. The OpenSSL \s-1QUIC\s0 implementation then takes responsibility -for ensuring that timeout events are handled on a timely basis even if no \s-1SSL -I/O\s0 function such as \fBSSL_read\fR\|(3) or \fBSSL_write\fR\|(3) is called by the -application for a long time. -.PP -All necessary locking is handled automatically internally, but the thread safety -guarantees for the public \s-1SSL API\s0 are unchanged. Therefore, an application must -still do its own locking if it wishes to make concurrent use of the public \s-1SSL\s0 -APIs. -.PP -Because this method relies on threads, it is not available on platforms where -threading support is not available or not supported by OpenSSL. However, it -does provide the simplest mode of usage for an application. -.PP -The implementation may or may not use a common thread or thread pool to service -multiple \s-1SSL\s0 objects in the same \fB\s-1SSL_CTX\s0\fR. -.SH "APPLICATION-DRIVEN EVENT LOOPS" -.IX Header "APPLICATION-DRIVEN EVENT LOOPS" -OpenSSL's \s-1QUIC\s0 implementation is designed to facilitate applications which wish -to use the \s-1SSL\s0 APIs in a blocking fashion, but is also designed to facilitate -applications which wish to use the \s-1SSL\s0 APIs in a nonblocking fashion and manage -their own event loops and polling directly. This is useful when it is desirable -to host OpenSSL's \s-1QUIC\s0 implementation on top of an application's existing -nonblocking I/O infrastructure. -.PP -This is supported via the concept of poll descriptors; see -\&\fBBIO_get_rpoll_descriptor\fR\|(3) for details. Broadly, a \fB\s-1BIO_POLL_DESCRIPTOR\s0\fR is -a structure which expresses some kind of \s-1OS\s0 resource which can be used to -synchronise on I/O events. The \s-1QUIC\s0 implementation provides a -\&\fB\s-1BIO_POLL_DESCRIPTOR\s0\fR based on the poll descriptor provided by the underlying -network \s-1BIO.\s0 This is typically an \s-1OS\s0 socket handle, though custom BIOs could -choose to implement their own custom poll descriptor format. -.PP -Broadly, an application which wishes to manage its own event loop should -interact with the \s-1SSL\s0 object as follows: -.IP "\(bu" 4 -It should provide read and write BIOs with nonblocking datagram semantics to -the \s-1SSL\s0 object using \fBSSL_set0_rbio\fR\|(3) and \fBSSL_set0_wbio\fR\|(3). This could be -a \s-1BIO\s0 abstracting a network socket such as \fBBIO_s_datagram\fR\|(3), or a \s-1BIO\s0 -abstracting some kind of memory buffer such as \fBBIO_s_dgram_pair\fR\|(3). Use of a -custom \s-1BIO\s0 is also possible. -.IP "\(bu" 4 -It should configure the \s-1SSL\s0 object into nonblocking mode by calling -\&\fBSSL_set_blocking_mode\fR\|(3). -.IP "\(bu" 4 -It should configure the \s-1SSL\s0 object as desired, set an initial peer as needed -using \fBSSL_set1_initial_peer_addr\fR\|(3), and trigger the connection process by -calling \fBSSL_connect\fR\|(3). -.IP "\(bu" 4 -If the network read and write BIOs provided were pollable (for example, -a \fBBIO_s_datagram\fR\|(3), or a custom \s-1BIO\s0 which implements -\&\fBBIO_get_rpoll_descriptor\fR\|(3) and \fBBIO_get_wpoll_descriptor\fR\|(3)), it should -perform the following steps repeatedly: -.RS 4 -.IP "\(bu" 4 -The application should call \fBSSL_get_rpoll_descriptor\fR\|(3) and -\&\fBSSL_get_wpoll_descriptor\fR\|(3) to identify \s-1OS\s0 resources which can be used for -synchronisation. -.IP "\(bu" 4 -It should call \fBSSL_net_read_desired\fR\|(3) and \fBSSL_net_write_desired\fR\|(3) to determine -whether the \s-1QUIC\s0 implementation is currently interested in readability and -writability events on the underlying network \s-1BIO\s0 which was provided, and call -\&\fBSSL_get_event_timeout\fR\|(3) to determine if any timeout event will become -applicable in the future. -.IP "\(bu" 4 -It should wait until one of the following events occurs: -.RS 4 -.IP "\(bu" 4 -The poll descriptor returned by \fBSSL_get_rpoll_descriptor\fR\|(3) becomes readable -(if \fBSSL_net_read_desired\fR\|(3) returned 1); -.IP "\(bu" 4 -The poll descriptor returned by \fBSSL_get_wpoll_descriptor\fR\|(3) becomes writable -(if \fBSSL_net_write_desired\fR\|(3) returned 1); -.IP "\(bu" 4 -The timeout returned by \fBSSL_get_event_timeout\fR\|(3) (if any) expires. -.RE -.RS 4 -.Sp -Once any of these events occurs, \fBSSL_handle_events\fR\|(3) should be called. -.RE -.RE -.RS 4 -.RE -.IP "\(bu" 4 -If the network read and write BIOs provided were not pollable (for example, in -the case of \fBBIO_s_dgram_pair\fR\|(3)), the application is responsible for managing -and synchronising network I/O. It should call \fBSSL_handle_events\fR\|(3) after it -writes data to a \fBBIO_s_dgram_pair\fR\|(3) or otherwise takes action so that the -\&\s-1QUIC\s0 implementation can read new datagrams via a call to \fBBIO_recvmmsg\fR\|(3) on -the underlying network \s-1BIO.\s0 The \s-1QUIC\s0 implementation may output datagrams via a -call to \fBBIO_sendmmsg\fR\|(3) and the application is responsible for ensuring these -are transmitted. -.Sp -The application must call \fBSSL_get_event_timeout\fR\|(3) after every call to -\&\fBSSL_handle_events\fR\|(3) (or another I/O function on the \s-1SSL\s0 object), and ensure -that a call to \fBSSL_handle_events\fR\|(3) is performed after the specified timeout -(if any). -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBSSL_handle_events\fR\|(3), \fBSSL_get_event_timeout\fR\|(3), -\&\fBSSL_net_read_desired\fR\|(3), \fBSSL_net_write_desired\fR\|(3), -\&\fBSSL_get_rpoll_descriptor\fR\|(3), \fBSSL_get_wpoll_descriptor\fR\|(3), -\&\fBSSL_set_blocking_mode\fR\|(3), \fBSSL_shutdown_ex\fR\|(3), -\&\fBSSL_set1_initial_peer_addr\fR\|(3), \fBSSL_stream_conclude\fR\|(3), -\&\fBSSL_stream_reset\fR\|(3), \fBSSL_get_stream_read_state\fR\|(3), -\&\fBSSL_get_stream_read_error_code\fR\|(3), \fBSSL_get_conn_close_info\fR\|(3), -\&\fBSSL_get0_connection\fR\|(3), \fBSSL_get_stream_type\fR\|(3), \fBSSL_get_stream_id\fR\|(3), -\&\fBSSL_new_stream\fR\|(3), \fBSSL_accept_stream\fR\|(3), -\&\fBSSL_set_incoming_stream_policy\fR\|(3), \fBSSL_set_default_stream_mode\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2022\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl-threads.7ossl b/openssl-install/share/man/man7/openssl-threads.7ossl deleted file mode 100644 index 4b629b22..00000000 --- a/openssl-install/share/man/man7/openssl-threads.7ossl +++ /dev/null @@ -1,236 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL-THREADS 7ossl" -.TH OPENSSL-THREADS 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl\-threads \- Overview of thread safety in OpenSSL -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -In this man page, we use the term \fBthread-safe\fR to indicate that an -object or function can be used by multiple threads at the same time. -.PP -OpenSSL can be built with or without threads support. The most important -use of this support is so that OpenSSL itself can use a single consistent -\&\s-1API,\s0 as shown in \*(L"\s-1EXAMPLES\*(R"\s0 in \fBCRYPTO_THREAD_run_once\fR\|(3). -Multi-platform applications can also use this \s-1API.\s0 -.PP -In particular, being configured for threads support does not imply that -all OpenSSL objects are thread-safe. -To emphasize: \fImost objects are not safe for simultaneous use\fR. -Exceptions to this should be documented on the specific manual pages, and -some general high-level guidance is given here. -.PP -One major use of the OpenSSL thread \s-1API\s0 is to implement reference counting. -Many objects within OpenSSL are reference-counted, so resources are not -released, until the last reference is removed. -References are often increased automatically (such as when an \fBX509\fR -certificate object is added into an \fBX509_STORE\fR trust store). -There is often an \fB\f(BIobject\fB_up_ref\fR() function that can be used to increase -the reference count. -Failure to match \fB\f(BIobject\fB_up_ref\fR() calls with the right number of -\&\fB\f(BIobject\fB_free\fR() calls is a common source of memory leaks when a program -exits. -.PP -Many objects have set and get \s-1API\s0's to set attributes in the object. -A \f(CW\*(C`set0\*(C'\fR passes ownership from the caller to the object and a -\&\f(CW\*(C`get0\*(C'\fR returns a pointer but the attribute ownership -remains with the object and a reference to it is returned. -A \f(CW\*(C`set1\*(C'\fR or \f(CW\*(C`get1\*(C'\fR function does not change the ownership, but instead -updates the attribute's reference count so that the object is shared -between the caller and the object; the caller must free the returned -attribute when finished. -Functions that involve attributes that have reference counts themselves, -but are named with just \f(CW\*(C`set\*(C'\fR or \f(CW\*(C`get\*(C'\fR are historical; and the documentation -must state how the references are handled. -Get methods are often thread-safe as long as the ownership requirements are -met and shared objects are not modified. -Set methods, or modifying shared objects, are generally not thread-safe -as discussed below. -.PP -Objects are thread-safe -as long as the \s-1API\s0's being invoked don't modify the object; in this -case the parameter is usually marked in the \s-1API\s0 as \f(CW\*(C`const\*(C'\fR. -Not all parameters are marked this way. -Note that a \f(CW\*(C`const\*(C'\fR declaration does not mean immutable; for example -\&\fBX509_cmp\fR\|(3) takes pointers to \f(CW\*(C`const\*(C'\fR objects, but the implementation -uses a C cast to remove that so it can lock objects, generate and cache -a \s-1DER\s0 encoding, and so on. -.PP -Another instance of thread-safety is when updates to an object's -internal state, such as cached values, are done with locks. -One example of this is the reference counting \s-1API\s0's described above. -.PP -In all cases, however, it is generally not safe for one thread to -mutate an object, such as setting elements of a private or public key, -while another thread is using that object, such as verifying a signature. -.PP -The same \s-1API\s0's can usually be used simultaneously on different objects -without interference. -For example, two threads can calculate a signature using two different -\&\fB\s-1EVP_PKEY_CTX\s0\fR objects. -.PP -For implicit global state or singletons, thread-safety depends on the facility. -The \fBCRYPTO_secure_malloc\fR\|(3) and related \s-1API\s0's have their own lock, -while \fBCRYPTO_malloc\fR\|(3) assumes the underlying platform allocation -will do any necessary locking. -Some \s-1API\s0's, such as \fBNCONF_load\fR\|(3) and related do no locking at all; -this can be considered a bug. -.PP -A separate, although related, issue is modifying \*(L"factory\*(R" objects -when other objects have been created from that. -For example, an \fB\s-1SSL_CTX\s0\fR object created by \fBSSL_CTX_new\fR\|(3) is used -to create per-connection \fB\s-1SSL\s0\fR objects by calling \fBSSL_new\fR\|(3). -In this specific case, and probably for factory methods in general, it is -not safe to modify the factory object after it has been used to create -other objects. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBCRYPTO_THREAD_run_once\fR\|(3), -local system threads documentation. -.SH "BUGS" -.IX Header "BUGS" -This page is admittedly very incomplete. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/openssl_user_macros.7ossl b/openssl-install/share/man/man7/openssl_user_macros.7ossl deleted file mode 100644 index c5d4a6d4..00000000 --- a/openssl-install/share/man/man7/openssl_user_macros.7ossl +++ /dev/null @@ -1,233 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OPENSSL_USER_MACROS 7ossl" -.TH OPENSSL_USER_MACROS 7ossl "2025-08-14" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -openssl_user_macros, OPENSSL_API_COMPAT, OPENSSL_NO_DEPRECATED -\&\- User defined macros -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -User defined macros allow the programmer to control certain aspects of -what is exposed by the OpenSSL headers. -.PP -\&\fB\s-1NOTE:\s0\fR to be effective, a user defined macro \fImust be defined -before including any header file that depends on it\fR, either in the -compilation command (\f(CW\*(C`cc \-DMACRO=value\*(C'\fR) or by defining the macro in -source before including any headers. -.PP -Other manual pages may refer to this page when declarations depend on -user defined macros. -.SS "The macros" -.IX Subsection "The macros" -.IP "\fB\s-1OPENSSL_API_COMPAT\s0\fR" 4 -.IX Item "OPENSSL_API_COMPAT" -The value is a version number, given in one of the following two forms: -.RS 4 -.ie n .IP """0xMNNFF000L""" 4 -.el .IP "\f(CW0xMNNFF000L\fR" 4 -.IX Item "0xMNNFF000L" -This is the form supported for all versions up to 1.1.x, where \f(CW\*(C`M\*(C'\fR -represents the major number, \f(CW\*(C`NN\*(C'\fR represents the minor number, and -\&\f(CW\*(C`FF\*(C'\fR represents the fix number, as a hexadecimal number. For version -1.1.0, that's \f(CW\*(C`0x10100000L\*(C'\fR. -.Sp -Any version number may be given, but these numbers are -the current known major deprecation points, making them the most -meaningful: -.RS 4 -.ie n .IP """0x00908000L"" (version 0.9.8)" 4 -.el .IP "\f(CW0x00908000L\fR (version 0.9.8)" 4 -.IX Item "0x00908000L (version 0.9.8)" -.PD 0 -.ie n .IP """0x10000000L"" (version 1.0.0)" 4 -.el .IP "\f(CW0x10000000L\fR (version 1.0.0)" 4 -.IX Item "0x10000000L (version 1.0.0)" -.ie n .IP """0x10100000L"" (version 1.1.0)" 4 -.el .IP "\f(CW0x10100000L\fR (version 1.1.0)" 4 -.IX Item "0x10100000L (version 1.1.0)" -.RE -.RS 4 -.PD -.Sp -For convenience, higher numbers are accepted as well, as long as -feasible. For example, \f(CW\*(C`0x60000000L\*(C'\fR will work as expected. -However, it is recommended to start using the second form instead: -.RE -.ie n .IP """mmnnpp""" 4 -.el .IP "\f(CWmmnnpp\fR" 4 -.IX Item "mmnnpp" -This form is a simple decimal number calculated with this formula: -.Sp -\&\fImajor\fR * 10000 + \fIminor\fR * 100 + \fIpatch\fR -.Sp -where \fImajor\fR, \fIminor\fR and \fIpatch\fR are the desired major, -minor and patch components of the version number. For example: -.RS 4 -.IP "30000 corresponds to version 3.0.0" 4 -.IX Item "30000 corresponds to version 3.0.0" -.PD 0 -.IP "10002 corresponds to version 1.0.2" 4 -.IX Item "10002 corresponds to version 1.0.2" -.IP "420101 corresponds to version 42.1.1" 4 -.IX Item "420101 corresponds to version 42.1.1" -.RE -.RS 4 -.RE -.RE -.RS 4 -.PD -.Sp -If \fB\s-1OPENSSL_API_COMPAT\s0\fR is undefined, this default value is used in its -place: -\&\f(CW30400\fR -.RE -.IP "\fB\s-1OPENSSL_NO_DEPRECATED\s0\fR" 4 -.IX Item "OPENSSL_NO_DEPRECATED" -If this macro is defined, all deprecated public symbols in all OpenSSL -versions up to and including the version given by \fB\s-1OPENSSL_API_COMPAT\s0\fR -(or the default value given above, when \fB\s-1OPENSSL_API_COMPAT\s0\fR isn't defined) -will be hidden. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-introduction.7ossl b/openssl-install/share/man/man7/ossl-guide-introduction.7ossl deleted file mode 100644 index a6b6182d..00000000 --- a/openssl-install/share/man/man7/ossl-guide-introduction.7ossl +++ /dev/null @@ -1,234 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-INTRODUCTION 7ossl" -.TH OSSL-GUIDE-INTRODUCTION 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-introduction -\&\- OpenSSL Guide: An introduction to OpenSSL -.SH "WHAT IS OPENSSL?" -.IX Header "WHAT IS OPENSSL?" -OpenSSL is a robust, commercial-grade, full-featured toolkit for general-purpose -cryptography and secure communication. Its features are made available via a -command line application that enables users to perform various cryptography -related functions such as generating keys and certificates. Additionally it -supplies two libraries that application developers can use to implement -cryptography based capabilities and to securely communicate across a network. -Finally, it also has a set of providers that supply implementations of a broad -set of cryptographic algorithms. -.PP -OpenSSL is fully open source. Version 3.0 and above are distributed under the -Apache v2 license. -.SH "GETTING AND INSTALLING OPENSSL" -.IX Header "GETTING AND INSTALLING OPENSSL" -The OpenSSL Project develops and distributes the source code for OpenSSL. You -can obtain that source code via the OpenSSL website -(). -.PP -Many Operating Systems (notably Linux distributions) supply pre-built OpenSSL -binaries either pre-installed or available via the package management system in -use for that \s-1OS.\s0 It is worth checking whether this applies to you before -attempting to build OpenSSL from the source code. -.PP -Some third parties also supply OpenSSL binaries (e.g. for Windows and some other -platforms). The OpenSSL project maintains a list of these third parties at -. -.PP -If you build and install OpenSSL from the source code then you should download -the appropriate files for the version that you want to use from the link given -above. Extract the contents of the \fBtar.gz\fR archive file that you downloaded -into an appropriate directory. Inside that archive you will find a file named -\&\fB\s-1INSTALL\s0.md\fR which will supply detailed instructions on how to build and -install OpenSSL from source. Make sure you read the contents of that file -carefully in order to achieve a successful build. In the directory you will also -find a set of \fB\s-1NOTES\s0\fR files that provide further platform specific information. -Make sure you carefully read the file appropriate to your platform. As well as -the platform specific \fB\s-1NOTES\s0\fR files there is also a \fB\s-1NOTES\-PERL\s0.md\fR file that -provides information about setting up Perl for use by the OpenSSL build system -across multiple platforms. -.PP -Sometimes you may want to build and install OpenSSL from source on a system -which already has a pre-built version of OpenSSL installed on it via the -Operating System package management system (for example if you want to use a -newer version of OpenSSL than the one supplied by your Operating System). In -this case it is strongly recommended to install OpenSSL to a different location -than where the pre-built version is installed. You should \fBnever\fR replace the -pre-built version with a different version as this may break your system. -.SH "CONTENTS OF THE OPENSSL GUIDE" -.IX Header "CONTENTS OF THE OPENSSL GUIDE" -The OpenSSL Guide is a series of documentation pages (starting with this one) -that introduce some of the main concepts in OpenSSL. The guide can either be -read end-to-end in order, or alternatively you can simply skip to the parts most -applicable to your use case. Note however that later pages may depend on and -assume knowledge from earlier pages. -.PP -The pages in the guide are as follows: -.IP "\fBossl\-guide\-libraries\-introduction\fR\|(7): An introduction to the OpenSSL libraries" 4 -.IX Item "ossl-guide-libraries-introduction: An introduction to the OpenSSL libraries" -.PD 0 -.IP "\fBossl\-guide\-libcrypto\-introduction\fR\|(7): An introduction to libcrypto" 4 -.IX Item "ossl-guide-libcrypto-introduction: An introduction to libcrypto" -.IP "\fBossl\-guide\-libssl\-introduction\fR\|(7): An introduction to libssl" 4 -.IX Item "ossl-guide-libssl-introduction: An introduction to libssl" -.IP "\fBossl\-guide\-tls\-introduction\fR\|(7): An introduction to \s-1SSL/TLS\s0 in OpenSSL" 4 -.IX Item "ossl-guide-tls-introduction: An introduction to SSL/TLS in OpenSSL" -.IP "\fBossl\-guide\-tls\-client\-block\fR\|(7): Writing a simple blocking \s-1TLS\s0 client" 4 -.IX Item "ossl-guide-tls-client-block: Writing a simple blocking TLS client" -.IP "\fBossl\-guide\-tls\-client\-non\-block\fR\|(7): Writing a simple nonblocking \s-1TLS\s0 client" 4 -.IX Item "ossl-guide-tls-client-non-block: Writing a simple nonblocking TLS client" -.IP "\fBossl\-guide\-tls\-server\-block\fR\|(7): Writing a simple blocking \s-1TLS\s0 server" 4 -.IX Item "ossl-guide-tls-server-block: Writing a simple blocking TLS server" -.IP "\fBossl\-guide\-quic\-introduction\fR\|(7): An introduction to \s-1QUIC\s0 in OpenSSL" 4 -.IX Item "ossl-guide-quic-introduction: An introduction to QUIC in OpenSSL" -.IP "\fBossl\-guide\-quic\-client\-block\fR\|(7): Writing a simple blocking \s-1QUIC\s0 client" 4 -.IX Item "ossl-guide-quic-client-block: Writing a simple blocking QUIC client" -.IP "\fBossl\-guide\-quic\-multi\-stream\fR\|(7): Writing a simple multi-stream \s-1QUIC\s0 client" 4 -.IX Item "ossl-guide-quic-multi-stream: Writing a simple multi-stream QUIC client" -.IP "\fBossl\-guide\-quic\-client\-non\-block\fR\|(7): Writing a simple nonblocking \s-1QUIC\s0 client" 4 -.IX Item "ossl-guide-quic-client-non-block: Writing a simple nonblocking QUIC client" -.IP "\fBossl\-guide\-migration\fR\|(7): Migrating from older OpenSSL versions" 4 -.IX Item "ossl-guide-migration: Migrating from older OpenSSL versions" -.PD -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-libcrypto-introduction.7ossl b/openssl-install/share/man/man7/ossl-guide-libcrypto-introduction.7ossl deleted file mode 100644 index 44d7f24d..00000000 --- a/openssl-install/share/man/man7/ossl-guide-libcrypto-introduction.7ossl +++ /dev/null @@ -1,521 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-LIBCRYPTO-INTRODUCTION 7ossl" -.TH OSSL-GUIDE-LIBCRYPTO-INTRODUCTION 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-libcrypto\-introduction, crypto -\&\- OpenSSL Guide: An introduction to libcrypto -.SH "INTRODUCTION" -.IX Header "INTRODUCTION" -The OpenSSL cryptography library (\f(CW\*(C`libcrypto\*(C'\fR) enables access to a wide range -of cryptographic algorithms used in various Internet standards. The services -provided by this library are used by the OpenSSL implementations of \s-1TLS\s0 and -\&\s-1CMS,\s0 and they have also been used to implement many other third party products -and protocols. -.PP -The functionality includes symmetric encryption, public key cryptography, key -agreement, certificate handling, cryptographic hash functions, cryptographic -pseudo-random number generators, message authentication codes (MACs), key -derivation functions (KDFs), and various utilities. -.SS "Algorithms" -.IX Subsection "Algorithms" -Cryptographic primitives such as the \s-1SHA256\s0 digest, or \s-1AES\s0 encryption are -referred to in OpenSSL as \*(L"algorithms\*(R". Each algorithm may have multiple -implementations available for use. For example the \s-1RSA\s0 algorithm is available as -a \*(L"default\*(R" implementation suitable for general use, and a \*(L"fips\*(R" implementation -which has been validated to \s-1FIPS 140\s0 standards for situations where that is -important. It is also possible that a third party could add additional -implementations such as in a hardware security module (\s-1HSM\s0). -.PP -Algorithms are implemented in providers. See -\&\fBossl\-guide\-libraries\-introduction\fR\|(7) for information about providers. -.SS "Operations" -.IX Subsection "Operations" -Different algorithms can be grouped together by their purpose. For example there -are algorithms for encryption, and different algorithms for digesting data. -These different groups are known as \*(L"operations\*(R" in OpenSSL. Each operation -has a different set of functions associated with it. For example to perform an -encryption operation using \s-1AES\s0 (or any other encryption algorithm) you would use -the encryption functions detailed on the \fBEVP_EncryptInit\fR\|(3) page. Or to -perform a digest operation using \s-1SHA256\s0 then you would use the digesting -functions on the \fBEVP_DigestInit\fR\|(3) page. -.SH "ALGORITHM FETCHING" -.IX Header "ALGORITHM FETCHING" -In order to use an algorithm an implementation for it must first be \*(L"fetched\*(R". -Fetching is the process of looking through the available implementations, -applying selection criteria (via a property query string), and finally choosing -the implementation that will be used. -.PP -Two types of fetching are supported by OpenSSL \- \*(L"Explicit fetching\*(R" and -\&\*(L"Implicit fetching\*(R". -.SS "Explicit fetching" -.IX Subsection "Explicit fetching" -Explicit fetching involves directly calling a specific \s-1API\s0 to fetch an algorithm -implementation from a provider. This fetched object can then be passed to other -APIs. These explicit fetching functions usually have the name \f(CW\*(C`APINAME_fetch\*(C'\fR, -where \f(CW\*(C`APINAME\*(C'\fR is the name of the operation. For example \fBEVP_MD_fetch\fR\|(3) -can be used to explicitly fetch a digest algorithm implementation. The user is -responsible for freeing the object returned from the \f(CW\*(C`APINAME_fetch\*(C'\fR function -using \f(CW\*(C`APINAME_free\*(C'\fR when it is no longer needed. -.PP -These fetching functions follow a fairly common pattern, where three -arguments are passed: -.IP "The library context" 4 -.IX Item "The library context" -See \s-1\fBOSSL_LIB_CTX\s0\fR\|(3) for a more detailed description. -This may be \s-1NULL\s0 to signify the default (global) library context, or a -context created by the user. Only providers loaded in this library context (see -\&\fBOSSL_PROVIDER_load\fR\|(3)) will be considered by the fetching function. In case -no provider has been loaded in this library context then the default provider -will be loaded as a fallback (see \fBOSSL_PROVIDER\-default\fR\|(7)). -.IP "An identifier" 4 -.IX Item "An identifier" -For all currently implemented fetching functions this is the algorithm name. -Each provider supports a list of algorithm implementations. See the provider -specific documentation for information on the algorithm implementations -available in each provider: -\&\*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \fBOSSL_PROVIDER\-default\fR\|(7), -\&\*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -\&\*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \fBOSSL_PROVIDER\-legacy\fR\|(7) and -\&\*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \fBOSSL_PROVIDER\-base\fR\|(7). -.Sp -Note, while providers may register algorithms against a list of names using a -string with a colon separated list of names, fetching algorithms using that -format is currently unsupported. -.IP "A property query string" 4 -.IX Item "A property query string" -The property query string used to guide selection of the algorithm -implementation. See -\&\*(L"\s-1PROPERTY QUERY STRINGS\*(R"\s0 in \fBossl\-guide\-libraries\-introduction\fR\|(7). -.PP -The algorithm implementation that is fetched can then be used with other diverse -functions that use them. For example the \fBEVP_DigestInit_ex\fR\|(3) function takes -as a parameter an \fB\s-1EVP_MD\s0\fR object which may have been returned from an earlier -call to \fBEVP_MD_fetch\fR\|(3). -.SS "Implicit fetching" -.IX Subsection "Implicit fetching" -OpenSSL has a number of functions that return an algorithm object with no -associated implementation, such as \fBEVP_sha256\fR\|(3), \fBEVP_aes_128_cbc\fR\|(3), -\&\fBEVP_get_cipherbyname\fR\|(3) or \fBEVP_get_digestbyname\fR\|(3). These are present for -compatibility with OpenSSL before version 3.0 where explicit fetching was not -available. -.PP -When they are used with functions like \fBEVP_DigestInit_ex\fR\|(3) or -\&\fBEVP_CipherInit_ex\fR\|(3), the actual implementation to be used is -fetched implicitly using default search criteria (which uses \s-1NULL\s0 for the -library context and property query string). -.PP -In some cases implicit fetching can also occur when a \s-1NULL\s0 algorithm parameter -is supplied. In this case an algorithm implementation is implicitly fetched -using default search criteria and an algorithm name that is consistent with -the context in which it is being used. -.PP -Functions that use an \fB\s-1EVP_PKEY_CTX\s0\fR or an \s-1\fBEVP_PKEY\s0\fR\|(3), such as -\&\fBEVP_DigestSignInit\fR\|(3), all fetch the implementations implicitly. Usually the -algorithm to fetch is determined based on the type of key that is being used and -the function that has been called. -.SS "Performance" -.IX Subsection "Performance" -If you perform the same operation many times with the same algorithm then it is -recommended to use a single explicit fetch of the algorithm and then reuse the -explicitly fetched algorithm each subsequent time. This will typically be -faster than implicitly fetching the algorithm every time you use it. See an -example of Explicit fetching in \*(L"\s-1USING ALGORITHMS IN APPLICATIONS\*(R"\s0. -.PP -Prior to OpenSSL 3.0, functions such as \fBEVP_sha256()\fR which return a \*(L"const\*(R" -object were used directly to indicate the algorithm to use in various function -calls. If you pass the return value of one of these convenience functions to an -operation then you are using implicit fetching. If you are converting an -application that worked with an OpenSSL version prior to OpenSSL 3.0 then -consider changing instances of implicit fetching to explicit fetching instead. -.PP -If an explicitly fetched object is not passed to an operation, then any implicit -fetch will use an internally cached prefetched object, but it will -still be slower than passing the explicitly fetched object directly. -.PP -The following functions can be used for explicit fetching: -.IP "\fBEVP_MD_fetch\fR\|(3)" 4 -.IX Item "EVP_MD_fetch" -Fetch a message digest/hashing algorithm implementation. -.IP "\fBEVP_CIPHER_fetch\fR\|(3)" 4 -.IX Item "EVP_CIPHER_fetch" -Fetch a symmetric cipher algorithm implementation. -.IP "\fBEVP_KDF_fetch\fR\|(3)" 4 -.IX Item "EVP_KDF_fetch" -Fetch a Key Derivation Function (\s-1KDF\s0) algorithm implementation. -.IP "\fBEVP_MAC_fetch\fR\|(3)" 4 -.IX Item "EVP_MAC_fetch" -Fetch a Message Authentication Code (\s-1MAC\s0) algorithm implementation. -.IP "\fBEVP_KEM_fetch\fR\|(3)" 4 -.IX Item "EVP_KEM_fetch" -Fetch a Key Encapsulation Mechanism (\s-1KEM\s0) algorithm implementation -.IP "\fBOSSL_ENCODER_fetch\fR\|(3)" 4 -.IX Item "OSSL_ENCODER_fetch" -Fetch an encoder algorithm implementation (e.g. to encode keys to a specified -format). -.IP "\fBOSSL_DECODER_fetch\fR\|(3)" 4 -.IX Item "OSSL_DECODER_fetch" -Fetch a decoder algorithm implementation (e.g. to decode keys from a specified -format). -.IP "\fBEVP_RAND_fetch\fR\|(3)" 4 -.IX Item "EVP_RAND_fetch" -Fetch a Pseudo Random Number Generator (\s-1PRNG\s0) algorithm implementation. -.PP -See \*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \fBOSSL_PROVIDER\-default\fR\|(7), -\&\*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), -\&\*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \fBOSSL_PROVIDER\-legacy\fR\|(7) and -\&\*(L"\s-1OPERATIONS AND ALGORITHMS\*(R"\s0 in \fBOSSL_PROVIDER\-base\fR\|(7) for a list of algorithm names -that can be fetched. -.SH "FETCHING EXAMPLES" -.IX Header "FETCHING EXAMPLES" -The following section provides a series of examples of fetching algorithm -implementations. -.PP -Fetch any available implementation of \s-1SHA2\-256\s0 in the default context. Note -that some algorithms have aliases. So \*(L"\s-1SHA256\*(R"\s0 and \*(L"\s-1SHA2\-256\*(R"\s0 are synonymous: -.PP -.Vb 3 -\& EVP_MD *md = EVP_MD_fetch(NULL, "SHA2\-256", NULL); -\& ... -\& EVP_MD_free(md); -.Ve -.PP -Fetch any available implementation of \s-1AES\-128\-CBC\s0 in the default context: -.PP -.Vb 3 -\& EVP_CIPHER *cipher = EVP_CIPHER_fetch(NULL, "AES\-128\-CBC", NULL); -\& ... -\& EVP_CIPHER_free(cipher); -.Ve -.PP -Fetch an implementation of \s-1SHA2\-256\s0 from the default provider in the default -context: -.PP -.Vb 3 -\& EVP_MD *md = EVP_MD_fetch(NULL, "SHA2\-256", "provider=default"); -\& ... -\& EVP_MD_free(md); -.Ve -.PP -Fetch an implementation of \s-1SHA2\-256\s0 that is not from the default provider in the -default context: -.PP -.Vb 3 -\& EVP_MD *md = EVP_MD_fetch(NULL, "SHA2\-256", "provider!=default"); -\& ... -\& EVP_MD_free(md); -.Ve -.PP -Fetch an implementation of \s-1SHA2\-256\s0 that is preferably from the \s-1FIPS\s0 provider in -the default context: -.PP -.Vb 3 -\& EVP_MD *md = EVP_MD_fetch(NULL, "SHA2\-256", "provider=?fips"); -\& ... -\& EVP_MD_free(md); -.Ve -.PP -Fetch an implementation of \s-1SHA2\-256\s0 from the default provider in the specified -library context: -.PP -.Vb 3 -\& EVP_MD *md = EVP_MD_fetch(libctx, "SHA2\-256", "provider=default"); -\& ... -\& EVP_MD_free(md); -.Ve -.PP -Load the legacy provider into the default context and then fetch an -implementation of \s-1WHIRLPOOL\s0 from it: -.PP -.Vb 2 -\& /* This only needs to be done once \- usually at application start up */ -\& OSSL_PROVIDER *legacy = OSSL_PROVIDER_load(NULL, "legacy"); -\& -\& EVP_MD *md = EVP_MD_fetch(NULL, "WHIRLPOOL", "provider=legacy"); -\& ... -\& EVP_MD_free(md); -.Ve -.PP -Note that in the above example the property string \*(L"provider=legacy\*(R" is optional -since, assuming no other providers have been loaded, the only implementation of -the \*(L"whirlpool\*(R" algorithm is in the \*(L"legacy\*(R" provider. Also note that the -default provider should be explicitly loaded if it is required in addition to -other providers: -.PP -.Vb 3 -\& /* This only needs to be done once \- usually at application start up */ -\& OSSL_PROVIDER *legacy = OSSL_PROVIDER_load(NULL, "legacy"); -\& OSSL_PROVIDER *default = OSSL_PROVIDER_load(NULL, "default"); -\& -\& EVP_MD *md_whirlpool = EVP_MD_fetch(NULL, "whirlpool", NULL); -\& EVP_MD *md_sha256 = EVP_MD_fetch(NULL, "SHA2\-256", NULL); -\& ... -\& EVP_MD_free(md_whirlpool); -\& EVP_MD_free(md_sha256); -.Ve -.SH "USING ALGORITHMS IN APPLICATIONS" -.IX Header "USING ALGORITHMS IN APPLICATIONS" -Cryptographic algorithms are made available to applications through use of the -\&\*(L"\s-1EVP\*(R"\s0 APIs. Each of the various operations such as encryption, digesting, -message authentication codes, etc., have a set of \s-1EVP\s0 function calls that can -be invoked to use them. See the \fBevp\fR\|(7) page for further details. -.PP -Most of these follow a common pattern. A \*(L"context\*(R" object is first created. For -example for a digest operation you would use an \fB\s-1EVP_MD_CTX\s0\fR, and for an -encryption/decryption operation you would use an \fB\s-1EVP_CIPHER_CTX\s0\fR. The -operation is then initialised ready for use via an \*(L"init\*(R" function \- optionally -passing in a set of parameters (using the \s-1\fBOSSL_PARAM\s0\fR\|(3) type) to configure how -the operation should behave. Next data is fed into the operation in a series of -\&\*(L"update\*(R" calls. The operation is finalised using a \*(L"final\*(R" call which will -typically provide some kind of output. Finally the context is cleaned up and -freed. -.PP -The following shows a complete example for doing this process for digesting -data using \s-1SHA256.\s0 The process is similar for other operations such as -encryption/decryption, signatures, message authentication codes, etc. Additional -examples can be found in the OpenSSL demos (see -\&\*(L"\s-1DEMO APPLICATIONS\*(R"\s0 in \fBossl\-guide\-libraries\-introduction\fR\|(7)). -.PP -.Vb 4 -\& #include -\& #include -\& #include -\& #include -\& -\& int main(void) -\& { -\& EVP_MD_CTX *ctx = NULL; -\& EVP_MD *sha256 = NULL; -\& const unsigned char msg[] = { -\& 0x00, 0x01, 0x02, 0x03 -\& }; -\& unsigned int len = 0; -\& unsigned char *outdigest = NULL; -\& int ret = 1; -\& -\& /* Create a context for the digest operation */ -\& ctx = EVP_MD_CTX_new(); -\& if (ctx == NULL) -\& goto err; -\& -\& /* -\& * Fetch the SHA256 algorithm implementation for doing the digest. We\*(Aqre -\& * using the "default" library context here (first NULL parameter), and -\& * we\*(Aqre not supplying any particular search criteria for our SHA256 -\& * implementation (second NULL parameter). Any SHA256 implementation will -\& * do. -\& * In a larger application this fetch would just be done once, and could -\& * be used for multiple calls to other operations such as EVP_DigestInit_ex(). -\& */ -\& sha256 = EVP_MD_fetch(NULL, "SHA256", NULL); -\& if (sha256 == NULL) -\& goto err; -\& -\& /* Initialise the digest operation */ -\& if (!EVP_DigestInit_ex(ctx, sha256, NULL)) -\& goto err; -\& -\& /* -\& * Pass the message to be digested. This can be passed in over multiple -\& * EVP_DigestUpdate calls if necessary -\& */ -\& if (!EVP_DigestUpdate(ctx, msg, sizeof(msg))) -\& goto err; -\& -\& /* Allocate the output buffer */ -\& outdigest = OPENSSL_malloc(EVP_MD_get_size(sha256)); -\& if (outdigest == NULL) -\& goto err; -\& -\& /* Now calculate the digest itself */ -\& if (!EVP_DigestFinal_ex(ctx, outdigest, &len)) -\& goto err; -\& -\& /* Print out the digest result */ -\& BIO_dump_fp(stdout, outdigest, len); -\& -\& ret = 0; -\& -\& err: -\& /* Clean up all the resources we allocated */ -\& OPENSSL_free(outdigest); -\& EVP_MD_free(sha256); -\& EVP_MD_CTX_free(ctx); -\& if (ret != 0) -\& ERR_print_errors_fp(stderr); -\& return ret; -\& } -.Ve -.SH "ENCODING AND DECODING KEYS" -.IX Header "ENCODING AND DECODING KEYS" -Many algorithms require the use of a key. Keys can be generated dynamically -using the \s-1EVP\s0 APIs (for example see \fBEVP_PKEY_Q_keygen\fR\|(3)). However it is often -necessary to save or load keys (or their associated parameters) to or from some -external format such as \s-1PEM\s0 or \s-1DER\s0 (see \fBopenssl\-glossary\fR\|(7)). OpenSSL uses -encoders and decoders to perform this task. -.PP -Encoders and decoders are just algorithm implementations in the same way as -any other algorithm implementation in OpenSSL. They are implemented by -providers. The OpenSSL encoders and decoders are available in the default -provider. They are also duplicated in the base provider. -.PP -For information about encoders see \fBOSSL_ENCODER_CTX_new_for_pkey\fR\|(3). For -information about decoders see \fBOSSL_DECODER_CTX_new_for_pkey\fR\|(3). -.PP -As well as using encoders/decoders directly there are also some helper functions -that can be used for certain well known and commonly used formats. For example -see \fBPEM_read_PrivateKey\fR\|(3) and \fBPEM_write_PrivateKey\fR\|(3) for information -about reading and writing key data from \s-1PEM\s0 encoded files. -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-libssl\-introduction\fR\|(7) for an introduction to using \f(CW\*(C`libssl\*(C'\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), \fBssl\fR\|(7), \fBevp\fR\|(7), \s-1\fBOSSL_LIB_CTX\s0\fR\|(3), \fBopenssl\-threads\fR\|(7), -\&\fBproperty\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7), \fBOSSL_PROVIDER\-base\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7), \fBOSSL_PROVIDER\-null\fR\|(7), -\&\fBopenssl\-glossary\fR\|(7), \fBprovider\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-libraries-introduction.7ossl b/openssl-install/share/man/man7/ossl-guide-libraries-introduction.7ossl deleted file mode 100644 index 86a27509..00000000 --- a/openssl-install/share/man/man7/ossl-guide-libraries-introduction.7ossl +++ /dev/null @@ -1,450 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-LIBRARIES-INTRODUCTION 7ossl" -.TH OSSL-GUIDE-LIBRARIES-INTRODUCTION 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-libraries\-introduction -\&\- OpenSSL Guide: An introduction to the OpenSSL libraries -.SH "INTRODUCTION" -.IX Header "INTRODUCTION" -OpenSSL supplies two libraries that can be used by applications known as -\&\f(CW\*(C`libcrypto\*(C'\fR and \f(CW\*(C`libssl\*(C'\fR. -.PP -The \f(CW\*(C`libcrypto\*(C'\fR library provides APIs for general purpose cryptography such as -encryption, digital signatures, hash functions, etc. It additionally supplies -supporting APIs for cryptography related standards, e.g. for reading and writing -digital certificates (also known as X.509 certificates). Finally it also -supplies various additional supporting APIs that are not directly cryptography -related but are nonetheless useful and depended upon by other APIs. For -example the \*(L"\s-1BIO\*(R"\s0 functions provide capabilities for abstracting I/O, e.g. via a -file or over a network. -.PP -The \f(CW\*(C`libssl\*(C'\fR library provides functions to perform secure communication between -two peers across a network. Most significantly it implements support for the -\&\s-1SSL/TLS, DTLS\s0 and \s-1QUIC\s0 standards. -.PP -The \f(CW\*(C`libssl\*(C'\fR library depends on and uses many of the capabilities supplied by -\&\f(CW\*(C`libcrypto\*(C'\fR. Any application linked against \f(CW\*(C`libssl\*(C'\fR will also link against -\&\f(CW\*(C`libcrypto\*(C'\fR, and most applications that do this will directly use \s-1API\s0 functions -supplied by both libraries. -.PP -Applications may be written that only use \f(CW\*(C`libcrypto\*(C'\fR capabilities and do not -link against \f(CW\*(C`libssl\*(C'\fR at all. -.SH "PROVIDERS" -.IX Header "PROVIDERS" -As well as the two main libraries, OpenSSL also comes with a set of providers. -.PP -A provider in OpenSSL is a component that collects together algorithm -implementations (for example an implementation of the symmetric encryption -algorithm \s-1AES\s0). In order to use an algorithm you must have at least one -provider loaded that contains an implementation of it. OpenSSL comes with a -number of providers and they may also be obtained from third parties. -.PP -Providers may either be \*(L"built-in\*(R" or in the form of a separate loadable module -file (typically one ending in \*(L".so\*(R" or \*(L".dll\*(R" dependent on the platform). A -built-in provider is one that is either already present in \f(CW\*(C`libcrypto\*(C'\fR or one -that the application has supplied itself directly. Third parties can also supply -providers in the form of loadable modules. -.PP -If you don't load a provider explicitly (either in program code or via config) -then the OpenSSL built-in \*(L"default\*(R" provider will be automatically loaded. -.PP -See \*(L"\s-1OPENSSL PROVIDERS\*(R"\s0 below for a description of the providers that OpenSSL -itself supplies. -.PP -Loading and unloading providers is quite an expensive operation. It is normally -done once, early on in the application lifecycle and those providers are kept -loaded for the duration of the application execution. -.SH "LIBRARY CONTEXTS" -.IX Header "LIBRARY CONTEXTS" -Many OpenSSL \s-1API\s0 functions make use of a library context. A library context can -be thought of as a \*(L"scope\*(R" within which configuration options take effect. When -a provider is loaded, it is only loaded within the scope of a given library -context. In this way it is possible for different components of a complex -application to each use a different library context and have different providers -loaded with different configuration settings. -.PP -If an application does not explicitly create a library context then the -\&\*(L"default\*(R" library context will be used. -.PP -Library contexts are represented by the \fB\s-1OSSL_LIB_CTX\s0\fR type. Many OpenSSL \s-1API\s0 -functions take a library context as a parameter. Applications can always pass -\&\fB\s-1NULL\s0\fR for this parameter to just use the default library context. -.PP -The default library context is automatically created the first time it is -needed. This will automatically load any available configuration file and will -initialise OpenSSL for use. Unlike in earlier versions of OpenSSL (prior to -1.1.0) no explicit initialisation steps need to be taken. -.PP -Similarly when the application exits, the default library context is -automatically destroyed. No explicit de-initialisation steps need to be taken. -.PP -See \s-1\fBOSSL_LIB_CTX\s0\fR\|(3) for more information about library contexts. -See also \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBossl\-guide\-libcrypto\-introduction\fR\|(7). -.SH "PROPERTY QUERY STRINGS" -.IX Header "PROPERTY QUERY STRINGS" -In some cases the available providers may mean that more than one implementation -of any given algorithm might be available. For example the OpenSSL \s-1FIPS\s0 provider -supplies alternative implementations of many of the same algorithms that are -available in the OpenSSL default provider. -.PP -The process of selecting an algorithm implementation is known as \*(L"fetching\*(R". -When OpenSSL fetches an algorithm to use it is possible to specify a \*(L"property -query string\*(R" to guide the selection process. For example a property query -string of \*(L"provider=default\*(R" could be used to force the selection to only -consider algorithm implementations in the default provider. -.PP -Property query strings can be specified explicitly as an argument to a function. -It is also possible to specify a default property query string for the whole -library context using the \fBEVP_set_default_properties\fR\|(3) or -\&\fBEVP_default_properties_enable_fips\fR\|(3) functions. Where both -default properties and function specific properties are specified then they are -combined. Function specific properties will override default properties where -there is a conflict. -.PP -See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBossl\-guide\-libcrypto\-introduction\fR\|(7) for more -information about fetching. See \fBproperty\fR\|(7) for more information about -properties. -.SH "MULTI-THREADED APPLICATIONS" -.IX Header "MULTI-THREADED APPLICATIONS" -As long as OpenSSL has been built with support for threads (the default case -on most platforms) then most OpenSSL \fIfunctions\fR are thread-safe in the sense -that it is safe to call the same function from multiple threads at the same -time. However most OpenSSL \fIdata structures\fR are not thread-safe. For example -the \fBBIO_write\fR\|(3) and \fBBIO_read\fR\|(3) functions are thread safe. However it -would not be thread safe to call \fBBIO_write()\fR from one thread while calling -\&\fBBIO_read()\fR in another where both functions are passed the same \fB\s-1BIO\s0\fR object -since both of them may attempt to make changes to the same \fB\s-1BIO\s0\fR object. -.PP -There are exceptions to these rules. A small number of functions are not thread -safe at all. Where this is the case this restriction should be noted in the -documentation for the function. Similarly some data structures may be partially -or fully thread safe. For example it is always safe to use an \fB\s-1OSSL_LIB_CTX\s0\fR in -multiple threads. -.PP -See \fBopenssl\-threads\fR\|(7) for a more detailed discussion on OpenSSL threading -support. -.SH "ERROR HANDLING" -.IX Header "ERROR HANDLING" -Most OpenSSL functions will provide a return value indicating whether the -function has been successful or not. It is considered best practice to always -check the return value from OpenSSL functions (where one is available). -.PP -Most functions that return a pointer value will return \s-1NULL\s0 in the event of a -failure. -.PP -Most functions that return an integer value will return a positive integer for -success. Some of these functions will return 0 to indicate failure. Others may -return 0 or a negative value for failure. -.PP -Some functions cannot fail and have a \fBvoid\fR return type. There are also a -small number of functions that do not conform to the above conventions (e.g. -they may return 0 to indicate success). -.PP -Due to the above variations in behaviour it is important to check the -documentation for each function for information about how to interpret the -return value for it. -.PP -It is sometimes necessary to get further information about the cause of a -failure (e.g. for debugging or logging purposes). Many (but not all) functions -will add further information about a failure to the OpenSSL error stack. By -using the error stack you can find out information such as a reason code/string -for the error as well as the exact file and source line within OpenSSL that -emitted the error. -.PP -OpenSSL supplies a set of error handling functions to query the error stack. See -\&\fBERR_get_error\fR\|(3) for information about the functions available for querying -error data. Also see \fBERR_print_errors\fR\|(3) for information on some simple -helper functions for printing error data. Finally look at \fBERR_clear_error\fR\|(3) -for how to clear old errors from the error stack. -.SH "OPENSSL PROVIDERS" -.IX Header "OPENSSL PROVIDERS" -OpenSSL comes with a set of providers. -.PP -The algorithms available in each of these providers may vary due to build time -configuration options. The \fBopenssl\-list\fR\|(1) command can be used to list the -currently available algorithms. -.PP -The names of the algorithms shown from \fBopenssl\-list\fR\|(1) can be used as an -algorithm identifier to the appropriate fetching function. Also see the provider -specific manual pages linked below for further details about using the -algorithms available in each of the providers. -.PP -As well as the OpenSSL providers third parties can also implement providers. -For information on writing a provider see \fBprovider\fR\|(7). -.SS "Default provider" -.IX Subsection "Default provider" -The default provider is built-in as part of the \fIlibcrypto\fR library and -contains all of the most commonly used algorithm implementations. Should it be -needed (if other providers are loaded and offer implementations of the same -algorithms), the property query string \*(L"provider=default\*(R" can be used as a -search criterion for these implementations. The default provider includes all -of the functionality in the base provider below. -.PP -If you don't load any providers at all then the \*(L"default\*(R" provider will be -automatically loaded. If you explicitly load any provider then the \*(L"default\*(R" -provider would also need to be explicitly loaded if it is required. -.PP -See \fBOSSL_PROVIDER\-default\fR\|(7). -.SS "Base provider" -.IX Subsection "Base provider" -The base provider is built in as part of the \fIlibcrypto\fR library and contains -algorithm implementations for encoding and decoding of OpenSSL keys. -Should it be needed (if other providers are loaded and offer -implementations of the same algorithms), the property query string -\&\*(L"provider=base\*(R" can be used as a search criterion for these implementations. -Some encoding and decoding algorithm implementations are not \s-1FIPS\s0 algorithm -implementations in themselves but support algorithms from the \s-1FIPS\s0 provider and -are allowed for use in \*(L"\s-1FIPS\s0 mode\*(R". The property query string \*(L"fips=yes\*(R" can be -used to select such algorithms. -.PP -See \fBOSSL_PROVIDER\-base\fR\|(7). -.SS "\s-1FIPS\s0 provider" -.IX Subsection "FIPS provider" -The \s-1FIPS\s0 provider is a dynamically loadable module, and must therefore -be loaded explicitly, either in code or through OpenSSL configuration -(see \fBconfig\fR\|(5)). It contains algorithm implementations that have been -validated according to \s-1FIPS\s0 standards. Should it be needed (if other -providers are loaded and offer implementations of the same algorithms), the -property query string \*(L"provider=fips\*(R" can be used as a search criterion for -these implementations. All approved algorithm implementations in the \s-1FIPS\s0 -provider can also be selected with the property \*(L"fips=yes\*(R". The \s-1FIPS\s0 provider -may also contain non-approved algorithm implementations and these can be -selected with the property \*(L"fips=no\*(R". -.PP -Typically the \*(L"Base provider\*(R" will also need to be loaded because the \s-1FIPS\s0 -provider does not support the encoding or decoding of keys. -.PP -See \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) and \fBfips_module\fR\|(7). -.SS "Legacy provider" -.IX Subsection "Legacy provider" -The legacy provider is a dynamically loadable module, and must therefore -be loaded explicitly, either in code or through OpenSSL configuration -(see \fBconfig\fR\|(5)). It contains algorithm implementations that are considered -insecure, or are no longer in common use such as \s-1MD2\s0 or \s-1RC4.\s0 Should it be needed -(if other providers are loaded and offer implementations of the same algorithms), -the property \*(L"provider=legacy\*(R" can be used as a search criterion for these -implementations. -.PP -See \fBOSSL_PROVIDER\-legacy\fR\|(7). -.SS "Null provider" -.IX Subsection "Null provider" -The null provider is built in as part of the \fIlibcrypto\fR library. It contains -no algorithms in it at all. When fetching algorithms the default provider will -be automatically loaded if no other provider has been explicitly loaded. To -prevent that from happening you can explicitly load the null provider. -.PP -You can use this if you create your own library context and want to ensure that -all \s-1API\s0 calls have correctly passed the created library context and are not -accidentally using the default library context. Load the null provider into the -default library context so that the default library context has no algorithm -implementations available. -.PP -See \fBOSSL_PROVIDER\-null\fR\|(7). -.SH "CONFIGURATION" -.IX Header "CONFIGURATION" -By default OpenSSL will load a configuration file when it is first used. This -will set up various configuration settings within the default library context. -Applications that create their own library contexts may optionally configure -them with a config file using the \fBOSSL_LIB_CTX_load_config\fR\|(3) function. -.PP -The configuration file can be used to automatically load providers and set up -default property query strings. -.PP -For information on the OpenSSL configuration file format see \fBconfig\fR\|(5). -.SH "LIBRARY CONVENTIONS" -.IX Header "LIBRARY CONVENTIONS" -Many OpenSSL functions that \*(L"get\*(R" or \*(L"set\*(R" a value follow a naming convention -using the numbers \fB0\fR and \fB1\fR, i.e. \*(L"get0\*(R", \*(L"get1\*(R", \*(L"set0\*(R" and \*(L"set1\*(R". This -can also apply to some functions that \*(L"add\*(R" a value to an existing set, i.e. -\&\*(L"add0\*(R" and \*(L"add1\*(R". -.PP -For example the functions: -.PP -.Vb 2 -\& int X509_CRL_add0_revoked(X509_CRL *crl, X509_REVOKED *rev); -\& int X509_add1_trust_object(X509 *x, const ASN1_OBJECT *obj); -.Ve -.PP -In the \fB0\fR version the ownership of the object is passed to (for an add or set) -or retained by (for a get) the parent object. For example after calling the -\&\fBX509_CRL_add0_revoked()\fR function above, ownership of the \fIrev\fR object is passed -to the \fIcrl\fR object. Therefore, after calling this function \fIrev\fR should not -be freed directly. It will be freed implicitly when \fIcrl\fR is freed. -.PP -In the \fB1\fR version the ownership of the object is not passed to or retained by -the parent object. Instead a copy or \*(L"up ref\*(R" of the object is performed. So -after calling the \fBX509_add1_trust_object()\fR function above the application will -still be responsible for freeing the \fIobj\fR value where appropriate. -.PP -Many OpenSSL functions conform to a naming convention of the form -\&\fB\fBCLASSNAME_func_name()\fB\fR. In this naming convention the \fB\s-1CLASSNAME\s0\fR is the name -of an OpenSSL data structure (given in capital letters) that the function is -primarily operating on. The \fBfunc_name\fR portion of the name is usually in -lowercase letters and indicates the purpose of the function. -.SH "DEMO APPLICATIONS" -.IX Header "DEMO APPLICATIONS" -OpenSSL is distributed with a set of demo applications which provide some -examples of how to use the various \s-1API\s0 functions. To look at them download the -OpenSSL source code from the OpenSSL website -(). Extract the downloaded \fB.tar.gz\fR file for -the version of OpenSSL that you are using and look at the various files in the -\&\fBdemos\fR sub-directory. -.PP -The Makefiles in the subdirectories give instructions on how to build and run -the demo applications. -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-libcrypto\-introduction\fR\|(7) for a more detailed introduction to -using \f(CW\*(C`libcrypto\*(C'\fR and \fBossl\-guide\-libssl\-introduction\fR\|(7) for more information -on \f(CW\*(C`libssl\*(C'\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBopenssl\fR\|(1), \fBssl\fR\|(7), \fBevp\fR\|(7), \s-1\fBOSSL_LIB_CTX\s0\fR\|(3), \fBopenssl\-threads\fR\|(7), -\&\fBproperty\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7), \fBOSSL_PROVIDER\-base\fR\|(7), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-legacy\fR\|(7), \fBOSSL_PROVIDER\-null\fR\|(7), -\&\fBopenssl\-glossary\fR\|(7), \fBprovider\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-libssl-introduction.7ossl b/openssl-install/share/man/man7/ossl-guide-libssl-introduction.7ossl deleted file mode 100644 index 19c51507..00000000 --- a/openssl-install/share/man/man7/ossl-guide-libssl-introduction.7ossl +++ /dev/null @@ -1,238 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-LIBSSL-INTRODUCTION 7ossl" -.TH OSSL-GUIDE-LIBSSL-INTRODUCTION 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-libssl\-introduction, ssl -\&\- OpenSSL Guide: An introduction to libssl -.SH "INTRODUCTION" -.IX Header "INTRODUCTION" -The OpenSSL \f(CW\*(C`libssl\*(C'\fR library provides implementations of several secure network -communications protocols. Specifically it provides \s-1SSL/TLS\s0 (SSLv3, TLSv1, -TLSv1.1, TLSv1.2 and TLSv1.3), \s-1DTLS\s0 (DTLSv1 and DTLSv1.2) and \s-1QUIC\s0 (client side -only). The library depends on \f(CW\*(C`libcrypto\*(C'\fR for its underlying cryptographic -operations (see \fBossl\-guide\-libcrypto\-introduction\fR\|(7)). -.PP -The set of APIs supplied by \f(CW\*(C`libssl\*(C'\fR is common across all of these different -network protocols, so a developer familiar with writing applications using one -of these protocols should be able to transition to using another with relative -ease. -.PP -An application written to use \f(CW\*(C`libssl\*(C'\fR will include the \fI\fR -header file and will typically use two main data structures, i.e. \fB\s-1SSL\s0\fR and -\&\fB\s-1SSL_CTX\s0\fR. -.PP -An \fB\s-1SSL\s0\fR object is used to represent a connection to a remote peer. Once a -connection with a remote peer has been established data can be exchanged with -that peer. -.PP -When using \s-1DTLS\s0 any data that is exchanged uses \*(L"datagram\*(R" semantics, i.e. -the packets of data can be delivered in any order, and they are not guaranteed -to arrive at all. In this case the \fB\s-1SSL\s0\fR object used for the connection is also -used for exchanging data with the peer. -.PP -Both \s-1TLS\s0 and \s-1QUIC\s0 support the concept of a \*(L"stream\*(R" of data. Data sent via a -stream is guaranteed to be delivered in order without any data loss. A stream -can be uni\- or bi-directional. -.PP -\&\s-1SSL/TLS\s0 only supports one stream of data per connection and it is always -bi-directional. In this case the \fB\s-1SSL\s0\fR object used for the connection also -represents that stream. See \fBossl\-guide\-tls\-introduction\fR\|(7) for more -information. -.PP -The \s-1QUIC\s0 protocol can support multiple streams per connection and they can be -uni\- or bi-directional. In this case an \fB\s-1SSL\s0\fR object can represent the -underlying connection, or a stream, or both. Where multiple streams are in use -a separate \fB\s-1SSL\s0\fR object is used for each one. See -\&\fBossl\-guide\-quic\-introduction\fR\|(7) for more information. -.PP -An \fB\s-1SSL_CTX\s0\fR object is used to create the \fB\s-1SSL\s0\fR object for the underlying -connection. A single \fB\s-1SSL_CTX\s0\fR object can be used to create many connections -(each represented by a separate \fB\s-1SSL\s0\fR object). Many \s-1API\s0 functions in libssl -exist in two forms: one that takes an \fB\s-1SSL_CTX\s0\fR and one that takes an \fB\s-1SSL\s0\fR. -Typically settings that you apply to the \fB\s-1SSL_CTX\s0\fR will then be inherited by -any \fB\s-1SSL\s0\fR object that you create from it. Alternatively you can apply settings -directly to the \fB\s-1SSL\s0\fR object without affecting other \fB\s-1SSL\s0\fR objects. Note that -you should not normally make changes to an \fB\s-1SSL_CTX\s0\fR after the first \fB\s-1SSL\s0\fR -object has been created from it. -.SH "DATA STRUCTURES" -.IX Header "DATA STRUCTURES" -As well as \fB\s-1SSL_CTX\s0\fR and \fB\s-1SSL\s0\fR there are a number of other data structures -that an application may need to use. They are summarised below. -.IP "\fB\s-1SSL_METHOD\s0\fR (\s-1SSL\s0 Method)" 4 -.IX Item "SSL_METHOD (SSL Method)" -This structure is used to indicate the kind of connection you want to make, e.g. -whether it is to represent the client or the server, and whether it is to use -\&\s-1SSL/TLS, DTLS\s0 or \s-1QUIC\s0 (client only). It is passed as a parameter when creating -the \fB\s-1SSL_CTX\s0\fR. -.IP "\fB\s-1SSL_SESSION\s0\fR (\s-1SSL\s0 Session)" 4 -.IX Item "SSL_SESSION (SSL Session)" -After establishing a connection with a peer the agreed cryptographic material -can be reused to create future connections with the same peer more rapidly. The -set of data used for such a future connection establishment attempt is collected -together into an \fB\s-1SSL_SESSION\s0\fR object. A single successful connection with a -peer may generate zero or more such \fB\s-1SSL_SESSION\s0\fR objects for use in future -connection attempts. -.IP "\fB\s-1SSL_CIPHER\s0\fR (\s-1SSL\s0 Cipher)" 4 -.IX Item "SSL_CIPHER (SSL Cipher)" -During connection establishment the client and server agree upon cryptographic -algorithms they are going to use for encryption and other uses. A single set -of cryptographic algorithms that are to be used together is known as a -ciphersuite. Such a set is represented by an \fB\s-1SSL_CIPHER\s0\fR object. -.Sp -The set of available ciphersuites that can be used are configured in the -\&\fB\s-1SSL_CTX\s0\fR or \fB\s-1SSL\s0\fR. -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-tls\-introduction\fR\|(7) for an introduction to the \s-1SSL/TLS\s0 -protocol and \fBossl\-guide\-quic\-introduction\fR\|(7) for an introduction to \s-1QUIC.\s0 -.PP -See \fBossl\-guide\-libcrypto\-introduction\fR\|(7) for an introduction to \f(CW\*(C`libcrypto\*(C'\fR. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-libcrypto\-introduction\fR\|(7), \fBossl\-guide\-tls\-introduction\fR\|(7), -\&\fBossl\-guide\-quic\-introduction\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2000\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-migration.7ossl b/openssl-install/share/man/man7/ossl-guide-migration.7ossl deleted file mode 100644 index 3308d975..00000000 --- a/openssl-install/share/man/man7/ossl-guide-migration.7ossl +++ /dev/null @@ -1,2186 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-MIGRATION 7ossl" -.TH OSSL-GUIDE-MIGRATION 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-migration, migration_guide -\&\- OpenSSL Guide: Migrating from older OpenSSL versions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -See the individual manual pages for details. -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This guide details the changes required to migrate to new versions of OpenSSL. -Currently this covers OpenSSL 3.0 & 3.1. For earlier versions refer to -. -For an overview of some of the key concepts introduced in OpenSSL 3.0 see -\&\fBcrypto\fR\|(7). -.SH "OPENSSL 3.1" -.IX Header "OPENSSL 3.1" -.SS "Main Changes from OpenSSL 3.0" -.IX Subsection "Main Changes from OpenSSL 3.0" -The \s-1FIPS\s0 provider in OpenSSL 3.1 includes some non-FIPS validated algorithms, -consequently the property query \f(CW\*(C`fips=yes\*(C'\fR is mandatory for applications that -want to operate in a \s-1FIPS\s0 approved manner. The algorithms are: -.IP "Triple \s-1DES ECB\s0" 4 -.IX Item "Triple DES ECB" -.PD 0 -.IP "Triple \s-1DES CBC\s0" 4 -.IX Item "Triple DES CBC" -.IP "EdDSA" 4 -.IX Item "EdDSA" -.PD -.PP -There are no other changes requiring additional migration measures since OpenSSL 3.0. -.SH "OPENSSL 3.0" -.IX Header "OPENSSL 3.0" -.SS "Main Changes from OpenSSL 1.1.1" -.IX Subsection "Main Changes from OpenSSL 1.1.1" -\fIMajor Release\fR -.IX Subsection "Major Release" -.PP -OpenSSL 3.0 is a major release and consequently any application that currently -uses an older version of OpenSSL will at the very least need to be recompiled in -order to work with the new version. It is the intention that the large majority -of applications will work unchanged with OpenSSL 3.0 if those applications -previously worked with OpenSSL 1.1.1. However this is not guaranteed and some -changes may be required in some cases. Changes may also be required if -applications need to take advantage of some of the new features available in -OpenSSL 3.0 such as the availability of the \s-1FIPS\s0 module. -.PP -\fILicense Change\fR -.IX Subsection "License Change" -.PP -In previous versions, OpenSSL was licensed under the dual OpenSSL and SSLeay -licenses -(both licenses apply). From OpenSSL 3.0 this is replaced by the -Apache License v2 . -.PP -\fIProviders and \s-1FIPS\s0 support\fR -.IX Subsection "Providers and FIPS support" -.PP -One of the key changes from OpenSSL 1.1.1 is the introduction of the Provider -concept. Providers collect together and make available algorithm implementations. -With OpenSSL 3.0 it is possible to specify, either programmatically or via a -config file, which providers you want to use for any given application. -OpenSSL 3.0 comes with 5 different providers as standard. Over time third -parties may distribute additional providers that can be plugged into OpenSSL. -All algorithm implementations available via providers are accessed through the -\&\*(L"high level\*(R" APIs (for example those functions prefixed with \f(CW\*(C`EVP\*(C'\fR). They cannot -be accessed using the \*(L"Low Level APIs\*(R". -.PP -One of the standard providers available is the \s-1FIPS\s0 provider. This makes -available \s-1FIPS\s0 validated cryptographic algorithms. -The \s-1FIPS\s0 provider is disabled by default and needs to be enabled explicitly -at configuration time using the \f(CW\*(C`enable\-fips\*(C'\fR option. If it is enabled, -the \s-1FIPS\s0 provider gets built and installed in addition to the other standard -providers. No separate installation procedure is necessary. -There is however a dedicated \f(CW\*(C`install_fips\*(C'\fR make target, which serves the -special purpose of installing only the \s-1FIPS\s0 provider into an existing -OpenSSL installation. -.PP -Not all algorithms may be available for the application at a particular moment. -If the application code uses any digest or cipher algorithm via the \s-1EVP\s0 interface, -the application should verify the result of the \fBEVP_EncryptInit\fR\|(3), -\&\fBEVP_EncryptInit_ex\fR\|(3), and \fBEVP_DigestInit\fR\|(3) functions. In case when -the requested algorithm is not available, these functions will fail. -.PP -See also \*(L"Legacy Algorithms\*(R" for information on the legacy provider. -.PP -See also \*(L"Completing the installation of the \s-1FIPS\s0 Module\*(R" and -\&\*(L"Using the \s-1FIPS\s0 Module in applications\*(R". -.PP -\fILow Level APIs\fR -.IX Subsection "Low Level APIs" -.PP -OpenSSL has historically provided two sets of APIs for invoking cryptographic -algorithms: the \*(L"high level\*(R" APIs (such as the \f(CW\*(C`EVP\*(C'\fR APIs) and the \*(L"low level\*(R" -APIs. The high level APIs are typically designed to work across all algorithm -types. The \*(L"low level\*(R" APIs are targeted at a specific algorithm implementation. -For example, the \s-1EVP\s0 APIs provide the functions \fBEVP_EncryptInit_ex\fR\|(3), -\&\fBEVP_EncryptUpdate\fR\|(3) and \fBEVP_EncryptFinal\fR\|(3) to perform symmetric -encryption. Those functions can be used with the algorithms \s-1AES, CHACHA, 3DES\s0 etc. -On the other hand, to do \s-1AES\s0 encryption using the low level APIs you would have -to call \s-1AES\s0 specific functions such as \fBAES_set_encrypt_key\fR\|(3), -\&\fBAES_encrypt\fR\|(3), and so on. The functions for 3DES are different. -Use of the low level APIs has been informally discouraged by the OpenSSL -development team for a long time. However in OpenSSL 3.0 this is made more -formal. All such low level APIs have been deprecated. You may still use them in -your applications, but you may start to see deprecation warnings during -compilation (dependent on compiler support for this). Deprecated APIs may be -removed from future versions of OpenSSL so you are strongly encouraged to update -your code to use the high level APIs instead. -.PP -This is described in more detail in \*(L"Deprecation of Low Level Functions\*(R" -.PP -\fILegacy Algorithms\fR -.IX Subsection "Legacy Algorithms" -.PP -Some cryptographic algorithms such as \fB\s-1MD2\s0\fR and \fB\s-1DES\s0\fR that were available via -the \s-1EVP\s0 APIs are now considered legacy and their use is strongly discouraged. -These legacy \s-1EVP\s0 algorithms are still available in OpenSSL 3.0 but not by -default. If you want to use them then you must load the legacy provider. -This can be as simple as a config file change, or can be done programmatically. -See \fBOSSL_PROVIDER\-legacy\fR\|(7) for a complete list of algorithms. -Applications using the \s-1EVP\s0 APIs to access these algorithms should instead use -more modern algorithms. If that is not possible then these applications -should ensure that the legacy provider has been loaded. This can be achieved -either programmatically or via configuration. See \fBcrypto\fR\|(7) man page for -more information about providers. -.PP -\fIEngines and \*(L"\s-1METHOD\*(R"\s0 APIs\fR -.IX Subsection "Engines and METHOD APIs" -.PP -The refactoring to support Providers conflicts internally with the APIs used to -support engines, including the \s-1ENGINE API\s0 and any function that creates or -modifies custom \*(L"\s-1METHODS\*(R"\s0 (for example \fBEVP_MD_meth_new\fR\|(3), -\&\fBEVP_CIPHER_meth_new\fR\|(3), \fBEVP_PKEY_meth_new\fR\|(3), \fBRSA_meth_new\fR\|(3), -\&\fBEC_KEY_METHOD_new\fR\|(3), etc.). These functions are being deprecated in -OpenSSL 3.0, and users of these APIs should know that their use can likely -bypass provider selection and configuration, with unintended consequences. -This is particularly relevant for applications written to use the OpenSSL 3.0 -\&\s-1FIPS\s0 module, as detailed below. Authors and maintainers of external engines are -strongly encouraged to refactor their code transforming engines into providers -using the new Provider \s-1API\s0 and avoiding deprecated methods. -.PP -\fISupport of legacy engines\fR -.IX Subsection "Support of legacy engines" -.PP -If openssl is not built without engine support or deprecated \s-1API\s0 support, engines -will still work. However, their applicability will be limited. -.PP -New algorithms provided via engines will still work. -.PP -Engine-backed keys can be loaded via custom \fB\s-1OSSL_STORE\s0\fR implementation. -In this case the \fB\s-1EVP_PKEY\s0\fR objects created via \fBENGINE_load_private_key\fR\|(3) -will be considered legacy and will continue to work. -.PP -To ensure the future compatibility, the engines should be turned to providers. -To prefer the provider-based hardware offload, you can specify the default -properties to prefer your provider. -.PP -Setting engine-based or application-based default low-level crypto method such -as \fB\s-1RSA_METHOD\s0\fR or \fB\s-1EC_KEY_METHOD\s0\fR is still possible and keys inside the -default provider will use the engine-based implementation for the crypto -operations. However \fB\s-1EVP_PKEY\s0\fRs created by decoding by using \fB\s-1OSSL_DECODER\s0\fR, -\&\fB\s-1PEM_\s0\fR or \fBd2i_\fR APIs will be provider-based. To create a fully legacy -\&\fB\s-1EVP_PKEY\s0\fRs \fBEVP_PKEY_set1_RSA\fR\|(3), \fBEVP_PKEY_set1_EC_KEY\fR\|(3) or similar -functions must be used. -.PP -\fIVersioning Scheme\fR -.IX Subsection "Versioning Scheme" -.PP -The OpenSSL versioning scheme has changed with the OpenSSL 3.0 release. The new -versioning scheme has this format: -.PP -\&\s-1MAJOR.MINOR.PATCH\s0 -.PP -For OpenSSL 1.1.1 and below, different patch levels were indicated by a letter -at the end of the release version number. This will no longer be used and -instead the patch level is indicated by the final number in the version. A -change in the second (\s-1MINOR\s0) number indicates that new features may have been -added. OpenSSL versions with the same major number are \s-1API\s0 and \s-1ABI\s0 compatible. -If the major number changes then \s-1API\s0 and \s-1ABI\s0 compatibility is not guaranteed. -.PP -For more information, see \fBOpenSSL_version\fR\|(3). -.PP -\fIOther major new features\fR -.IX Subsection "Other major new features" -.PP -Certificate Management Protocol (\s-1CMP, RFC 4210\s0) -.IX Subsection "Certificate Management Protocol (CMP, RFC 4210)" -.PP -This also covers \s-1CRMF\s0 (\s-1RFC 4211\s0) and \s-1HTTP\s0 transfer (\s-1RFC 6712\s0) -See \fBopenssl\-cmp\fR\|(1) and \fBOSSL_CMP_exec_certreq\fR\|(3) as starting points. -.PP -\s-1HTTP\s0(S) client -.IX Subsection "HTTP(S) client" -.PP -A proper \s-1HTTP\s0(S) client that supports \s-1GET\s0 and \s-1POST,\s0 redirection, plain and -\&\s-1ASN\s0.1\-encoded contents, proxies, and timeouts. -.PP -Key Derivation Function \s-1API\s0 (\s-1EVP_KDF\s0) -.IX Subsection "Key Derivation Function API (EVP_KDF)" -.PP -This simplifies the process of adding new \s-1KDF\s0 and \s-1PRF\s0 implementations. -.PP -Previously \s-1KDF\s0 algorithms had been shoe-horned into using the \s-1EVP_PKEY\s0 object -which was not a logical mapping. -Existing applications that use \s-1KDF\s0 algorithms using \s-1EVP_PKEY\s0 -(scrypt, \s-1TLS1 PRF\s0 and \s-1HKDF\s0) may be slower as they use an \s-1EVP_KDF\s0 bridge -internally. -All new applications should use the new \s-1\fBEVP_KDF\s0\fR\|(3) interface. -See also \*(L"Key Derivation Function (\s-1KDF\s0)\*(R" in \fBOSSL_PROVIDER\-default\fR\|(7) and -\&\*(L"Key Derivation Function (\s-1KDF\s0)\*(R" in \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7). -.PP -Message Authentication Code \s-1API\s0 (\s-1EVP_MAC\s0) -.IX Subsection "Message Authentication Code API (EVP_MAC)" -.PP -This simplifies the process of adding \s-1MAC\s0 implementations. -.PP -This includes a generic \s-1EVP_PKEY\s0 to \s-1EVP_MAC\s0 bridge, to facilitate the continued -use of MACs through raw private keys in functionality such as -\&\fBEVP_DigestSign\fR\|(3) and \fBEVP_DigestVerify\fR\|(3). -.PP -All new applications should use the new \s-1\fBEVP_MAC\s0\fR\|(3) interface. -See also \*(L"Message Authentication Code (\s-1MAC\s0)\*(R" in \fBOSSL_PROVIDER\-default\fR\|(7) -and \*(L"Message Authentication Code (\s-1MAC\s0)\*(R" in \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7). -.PP -Algorithm Fetching -.IX Subsection "Algorithm Fetching" -.PP -Using calls to convenience functions such as \fBEVP_sha256()\fR and \fBEVP_aes_256_gcm()\fR may -incur a performance penalty when using providers. -Retrieving algorithms from providers involves searching for an algorithm by name. -This is much slower than directly accessing a method table. -It is recommended to prefetch algorithms if an algorithm is used many times. -See \*(L"Performance\*(R" in \fBcrypto\fR\|(7), \*(L"Explicit fetching\*(R" in \fBcrypto\fR\|(7) and \*(L"Implicit fetching\*(R" in \fBcrypto\fR\|(7). -.PP -Support for Linux Kernel \s-1TLS\s0 -.IX Subsection "Support for Linux Kernel TLS" -.PP -In order to use \s-1KTLS,\s0 support for it must be compiled in using the -\&\f(CW\*(C`enable\-ktls\*(C'\fR configuration option. It must also be enabled at run time using -the \fB\s-1SSL_OP_ENABLE_KTLS\s0\fR option. -.PP -New Algorithms -.IX Subsection "New Algorithms" -.IP "\(bu" 4 -\&\s-1KDF\s0 algorithms \*(L"\s-1SINGLE STEP\*(R"\s0 and \*(L"\s-1SSH\*(R"\s0 -.Sp -See \s-1\fBEVP_KDF\-SS\s0\fR\|(7) and \s-1\fBEVP_KDF\-SSHKDF\s0\fR\|(7) -.IP "\(bu" 4 -\&\s-1MAC\s0 Algorithms \*(L"\s-1GMAC\*(R"\s0 and \*(L"\s-1KMAC\*(R"\s0 -.Sp -See \s-1\fBEVP_MAC\-GMAC\s0\fR\|(7) and \s-1\fBEVP_MAC\-KMAC\s0\fR\|(7). -.IP "\(bu" 4 -\&\s-1KEM\s0 Algorithm \*(L"\s-1RSASVE\*(R"\s0 -.Sp -See \s-1\fBEVP_KEM\-RSA\s0\fR\|(7). -.IP "\(bu" 4 -Cipher Algorithm \*(L"AES-SIV\*(R" -.Sp -See \*(L"\s-1SIV\s0 Mode\*(R" in \fBEVP_EncryptInit\fR\|(3). -.IP "\(bu" 4 -\&\s-1AES\s0 Key Wrap inverse ciphers supported by \s-1EVP\s0 layer. -.Sp -The inverse ciphers use \s-1AES\s0 decryption for wrapping, and \s-1AES\s0 encryption for -unwrapping. The algorithms are: \*(L"\s-1AES\-128\-WRAP\-INV\*(R", \*(L"AES\-192\-WRAP\-INV\*(R", -\&\*(L"AES\-256\-WRAP\-INV\*(R", \*(L"AES\-128\-WRAP\-PAD\-INV\*(R", \*(L"AES\-192\-WRAP\-PAD\-INV\*(R"\s0 and -\&\*(L"\s-1AES\-256\-WRAP\-PAD\-INV\*(R".\s0 -.IP "\(bu" 4 -\&\s-1CTS\s0 ciphers added to \s-1EVP\s0 layer. -.Sp -The algorithms are \*(L"\s-1AES\-128\-CBC\-CTS\*(R", \*(L"AES\-192\-CBC\-CTS\*(R", \*(L"AES\-256\-CBC\-CTS\*(R", -\&\*(L"CAMELLIA\-128\-CBC\-CTS\*(R", \*(L"CAMELLIA\-192\-CBC\-CTS\*(R"\s0 and \*(L"\s-1CAMELLIA\-256\-CBC\-CTS\*(R". -CS1, CS2\s0 and \s-1CS3\s0 variants are supported. -.PP -\s-1CMS\s0 and PKCS#7 updates -.IX Subsection "CMS and PKCS#7 updates" -.IP "\(bu" 4 -Added CAdES-BES signature verification support. -.IP "\(bu" 4 -Added CAdES-BES signature scheme and attributes support (\s-1RFC 5126\s0) to \s-1CMS API.\s0 -.IP "\(bu" 4 -Added AuthEnvelopedData content type structure (\s-1RFC 5083\s0) using \s-1AES_GCM\s0 -.Sp -This uses the AES-GCM parameter (\s-1RFC 5084\s0) for the Cryptographic Message Syntax. -Its purpose is to support encryption and decryption of a digital envelope that -is both authenticated and encrypted using \s-1AES GCM\s0 mode. -.IP "\(bu" 4 -\&\fBPKCS7_get_octet_string\fR\|(3) and \fBPKCS7_type_is_other\fR\|(3) were made public. -.PP -PKCS#12 \s-1API\s0 updates -.IX Subsection "PKCS#12 API updates" -.PP -The default algorithms for pkcs12 creation with the \fBPKCS12_create()\fR function -were changed to more modern \s-1PBKDF2\s0 and \s-1AES\s0 based algorithms. The default -\&\s-1MAC\s0 iteration count was changed to \s-1PKCS12_DEFAULT_ITER\s0 to make it equal -with the password-based encryption iteration count. The default digest -algorithm for the \s-1MAC\s0 computation was changed to \s-1SHA\-256.\s0 The pkcs12 -application now supports \-legacy option that restores the previous -default algorithms to support interoperability with legacy systems. -.PP -Added enhanced PKCS#12 APIs which accept a library context \fB\s-1OSSL_LIB_CTX\s0\fR -and (where relevant) a property query. Other APIs which handle PKCS#7 and -PKCS#8 objects have also been enhanced where required. This includes: -.PP -\&\fBPKCS12_add_key_ex\fR\|(3), \fBPKCS12_add_safe_ex\fR\|(3), \fBPKCS12_add_safes_ex\fR\|(3), -\&\fBPKCS12_create_ex\fR\|(3), \fBPKCS12_decrypt_skey_ex\fR\|(3), \fBPKCS12_init_ex\fR\|(3), -\&\fBPKCS12_item_decrypt_d2i_ex\fR\|(3), \fBPKCS12_item_i2d_encrypt_ex\fR\|(3), -\&\fBPKCS12_key_gen_asc_ex\fR\|(3), \fBPKCS12_key_gen_uni_ex\fR\|(3), \fBPKCS12_key_gen_utf8_ex\fR\|(3), -\&\fBPKCS12_pack_p7encdata_ex\fR\|(3), \fBPKCS12_pbe_crypt_ex\fR\|(3), \fBPKCS12_PBE_keyivgen_ex\fR\|(3), -\&\fBPKCS12_SAFEBAG_create_pkcs8_encrypt_ex\fR\|(3), \fBPKCS5_pbe2_set_iv_ex\fR\|(3), -\&\fBPKCS5_pbe_set0_algor_ex\fR\|(3), \fBPKCS5_pbe_set_ex\fR\|(3), \fBPKCS5_pbkdf2_set_ex\fR\|(3), -\&\fBPKCS5_v2_PBE_keyivgen_ex\fR\|(3), \fBPKCS5_v2_scrypt_keyivgen_ex\fR\|(3), -\&\fBPKCS8_decrypt_ex\fR\|(3), \fBPKCS8_encrypt_ex\fR\|(3), \fBPKCS8_set0_pbe_ex\fR\|(3). -.PP -As part of this change the EVP_PBE_xxx APIs can also accept a library -context and property query and will call an extended version of the key/IV -derivation function which supports these parameters. This includes -\&\fBEVP_PBE_CipherInit_ex\fR\|(3), \fBEVP_PBE_find_ex\fR\|(3) and \fBEVP_PBE_scrypt_ex\fR\|(3). -.PP -PKCS#12 \s-1KDF\s0 versus \s-1FIPS\s0 -.IX Subsection "PKCS#12 KDF versus FIPS" -.PP -Unlike in 1.x.y, the \s-1PKCS12KDF\s0 algorithm used when a PKCS#12 structure -is created with a \s-1MAC\s0 that does not work with the \s-1FIPS\s0 provider as the \s-1PKCS12KDF\s0 -is not a \s-1FIPS\s0 approvable mechanism. -.PP -See \s-1\fBEVP_KDF\-PKCS12KDF\s0\fR\|(7), \fBPKCS12_create\fR\|(3), \fBopenssl\-pkcs12\fR\|(1), -\&\s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7). -.PP -Windows thread synchronization changes -.IX Subsection "Windows thread synchronization changes" -.PP -Windows thread synchronization uses read/write primitives (SRWLock) when -supported by the \s-1OS,\s0 otherwise CriticalSection continues to be used. -.PP -Trace \s-1API\s0 -.IX Subsection "Trace API" -.PP -A new generic trace \s-1API\s0 has been added which provides support for enabling -instrumentation through trace output. This feature is mainly intended as an aid -for developers and is disabled by default. To utilize it, OpenSSL needs to be -configured with the \f(CW\*(C`enable\-trace\*(C'\fR option. -.PP -If the tracing \s-1API\s0 is enabled, the application can activate trace output by -registering BIOs as trace channels for a number of tracing and debugging -categories. See \fBOSSL_trace_enabled\fR\|(3). -.PP -Key validation updates -.IX Subsection "Key validation updates" -.PP -\&\fBEVP_PKEY_public_check\fR\|(3) and \fBEVP_PKEY_param_check\fR\|(3) now work for -more key types. This includes \s-1RSA, DSA, ED25519, X25519, ED448\s0 and X448. -Previously (in 1.1.1) they would return \-2. For key types that do not have -parameters then \fBEVP_PKEY_param_check\fR\|(3) will always return 1. -.PP -\fIOther notable deprecations and changes\fR -.IX Subsection "Other notable deprecations and changes" -.PP -The function code part of an OpenSSL error code is no longer relevant -.IX Subsection "The function code part of an OpenSSL error code is no longer relevant" -.PP -This code is now always set to zero. Related functions are deprecated. -.PP -\s-1STACK\s0 and \s-1HASH\s0 macros have been cleaned up -.IX Subsection "STACK and HASH macros have been cleaned up" -.PP -The type-safe wrappers are declared everywhere and implemented once. -See \s-1\fBDEFINE_STACK_OF\s0\fR\|(3) and \s-1\fBDEFINE_LHASH_OF_EX\s0\fR\|(3). -.PP -The \s-1RAND_DRBG\s0 subsystem has been removed -.IX Subsection "The RAND_DRBG subsystem has been removed" -.PP -The new \s-1\fBEVP_RAND\s0\fR\|(3) is a partial replacement: the \s-1DRBG\s0 callback framework is -absent. The \s-1RAND_DRBG API\s0 did not fit well into the new provider concept as -implemented by \s-1EVP_RAND\s0 and \s-1EVP_RAND_CTX.\s0 -.PP -Removed \fBFIPS_mode()\fR and \fBFIPS_mode_set()\fR -.IX Subsection "Removed FIPS_mode() and FIPS_mode_set()" -.PP -These functions are legacy APIs that are not applicable to the new provider -model. Applications should instead use -\&\fBEVP_default_properties_is_fips_enabled\fR\|(3) and -\&\fBEVP_default_properties_enable_fips\fR\|(3). -.PP -Key generation is slower -.IX Subsection "Key generation is slower" -.PP -The Miller-Rabin test now uses 64 rounds, which is used for all prime generation, -including \s-1RSA\s0 key generation. This affects the time for larger keys sizes. -.PP -The default key generation method for the regular 2\-prime \s-1RSA\s0 keys was changed -to the \s-1FIPS186\-4 B.3.6\s0 method (Generation of Probable Primes with Conditions -Based on Auxiliary Probable Primes). This method is slower than the original -method. -.PP -Change \s-1PBKDF2\s0 to conform to \s-1SP800\-132\s0 instead of the older \s-1PKCS5 RFC2898\s0 -.IX Subsection "Change PBKDF2 to conform to SP800-132 instead of the older PKCS5 RFC2898" -.PP -This checks that the salt length is at least 128 bits, the derived key length is -at least 112 bits, and that the iteration count is at least 1000. -For backwards compatibility these checks are disabled by default in the -default provider, but are enabled by default in the \s-1FIPS\s0 provider. -.PP -To enable or disable the checks see \fB\s-1OSSL_KDF_PARAM_PKCS5\s0\fR in -\&\s-1\fBEVP_KDF\-PBKDF2\s0\fR\|(7). The parameter can be set using \fBEVP_KDF_derive\fR\|(3). -.PP -Enforce a minimum \s-1DH\s0 modulus size of 512 bits -.IX Subsection "Enforce a minimum DH modulus size of 512 bits" -.PP -Smaller sizes now result in an error. -.PP -\s-1SM2\s0 key changes -.IX Subsection "SM2 key changes" -.PP -\&\s-1EC\s0 EVP_PKEYs with the \s-1SM2\s0 curve have been reworked to automatically become -\&\s-1EVP_PKEY_SM2\s0 rather than \s-1EVP_PKEY_EC.\s0 -.PP -Unlike in previous OpenSSL versions, this means that applications cannot -call \f(CW\*(C`EVP_PKEY_set_alias_type(pkey, EVP_PKEY_SM2)\*(C'\fR to get \s-1SM2\s0 computations. -.PP -Parameter and key generation is also reworked to make it possible -to generate \s-1EVP_PKEY_SM2\s0 parameters and keys. Applications must now generate -\&\s-1SM2\s0 keys directly and must not create an \s-1EVP_PKEY_EC\s0 key first. It is no longer -possible to import an \s-1SM2\s0 key with domain parameters other than the \s-1SM2\s0 elliptic -curve ones. -.PP -Validation of \s-1SM2\s0 keys has been separated from the validation of regular \s-1EC\s0 -keys, allowing to improve the \s-1SM2\s0 validation process to reject loaded private -keys that are not conforming to the \s-1SM2 ISO\s0 standard. -In particular, a private scalar \fIk\fR outside the range \fI1 <= k < n\-1\fR is -now correctly rejected. -.PP -\fBEVP_PKEY_set_alias_type()\fR method has been removed -.IX Subsection "EVP_PKEY_set_alias_type() method has been removed" -.PP -This function made a \fB\s-1EVP_PKEY\s0\fR object mutable after it had been set up. In -OpenSSL 3.0 it was decided that a provided key should not be able to change its -type, so this function has been removed. -.PP -Functions that return an internal key should be treated as read only -.IX Subsection "Functions that return an internal key should be treated as read only" -.PP -Functions such as \fBEVP_PKEY_get0_RSA\fR\|(3) behave slightly differently in -OpenSSL 3.0. Previously they returned a pointer to the low-level key used -internally by libcrypto. From OpenSSL 3.0 this key may now be held in a -provider. Calling these functions will only return a handle on the internal key -where the \s-1EVP_PKEY\s0 was constructed using this key in the first place, for -example using a function or macro such as \fBEVP_PKEY_assign_RSA\fR\|(3), -\&\fBEVP_PKEY_set1_RSA\fR\|(3), etc. -Where the \s-1EVP_PKEY\s0 holds a provider managed key, then these functions now return -a cached copy of the key. Changes to the internal provider key that take place -after the first time the cached key is accessed will not be reflected back in -the cached copy. Similarly any changes made to the cached copy by application -code will not be reflected back in the internal provider key. -.PP -For the above reasons the keys returned from these functions should typically be -treated as read-only. To emphasise this the value returned from -\&\fBEVP_PKEY_get0_RSA\fR\|(3), \fBEVP_PKEY_get0_DSA\fR\|(3), \fBEVP_PKEY_get0_EC_KEY\fR\|(3) and -\&\fBEVP_PKEY_get0_DH\fR\|(3) have been made const. This may break some existing code. -Applications broken by this change should be modified. The preferred solution is -to refactor the code to avoid the use of these deprecated functions. Failing -this the code should be modified to use a const pointer instead. -The \fBEVP_PKEY_get1_RSA\fR\|(3), \fBEVP_PKEY_get1_DSA\fR\|(3), \fBEVP_PKEY_get1_EC_KEY\fR\|(3) -and \fBEVP_PKEY_get1_DH\fR\|(3) functions continue to return a non-const pointer to -enable them to be \*(L"freed\*(R". However they should also be treated as read-only. -.PP -The public key check has moved from \fBEVP_PKEY_derive()\fR to \fBEVP_PKEY_derive_set_peer()\fR -.IX Subsection "The public key check has moved from EVP_PKEY_derive() to EVP_PKEY_derive_set_peer()" -.PP -This may mean result in an error in \fBEVP_PKEY_derive_set_peer\fR\|(3) rather than -during \fBEVP_PKEY_derive\fR\|(3). -To disable this check use EVP_PKEY_derive_set_peer_ex(dh, peer, 0). -.PP -The print format has cosmetic changes for some functions -.IX Subsection "The print format has cosmetic changes for some functions" -.PP -The output from numerous \*(L"printing\*(R" functions such as \fBX509_signature_print\fR\|(3), -\&\fBX509_print_ex\fR\|(3), \fBX509_CRL_print_ex\fR\|(3), and other similar functions has been -amended such that there may be cosmetic differences between the output -observed in 1.1.1 and 3.0. This also applies to the \fB\-text\fR output from the -\&\fBopenssl x509\fR and \fBopenssl crl\fR applications. -.PP -Interactive mode from the \fBopenssl\fR program has been removed -.IX Subsection "Interactive mode from the openssl program has been removed" -.PP -From now on, running it without arguments is equivalent to \fBopenssl help\fR. -.PP -The error return values from some control calls (ctrl) have changed -.IX Subsection "The error return values from some control calls (ctrl) have changed" -.PP -One significant change is that controls which used to return \-2 for -invalid inputs, now return \-1 indicating a generic error condition instead. -.PP -\s-1DH\s0 and \s-1DHX\s0 key types have different settable parameters -.IX Subsection "DH and DHX key types have different settable parameters" -.PP -Previously (in 1.1.1) these conflicting parameters were allowed, but will now -result in errors. See \s-1\fBEVP_PKEY\-DH\s0\fR\|(7) for further details. This affects the -behaviour of \fBopenssl\-genpkey\fR\|(1) for \s-1DH\s0 parameter generation. -.PP -\fBEVP_CIPHER_CTX_set_flags()\fR ordering change -.IX Subsection "EVP_CIPHER_CTX_set_flags() ordering change" -.PP -If using a cipher from a provider the \fB\s-1EVP_CIPH_FLAG_LENGTH_BITS\s0\fR flag can only -be set \fBafter\fR the cipher has been assigned to the cipher context. -See \*(L"\s-1FLAGS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3) for more information. -.PP -Validation of operation context parameters -.IX Subsection "Validation of operation context parameters" -.PP -Due to move of the implementation of cryptographic operations to the -providers, validation of various operation parameters can be postponed until -the actual operation is executed where previously it happened immediately -when an operation parameter was set. -.PP -For example when setting an unsupported curve with -\&\fBEVP_PKEY_CTX_set_ec_paramgen_curve_nid()\fR this function call will not fail -but later keygen operations with the \s-1EVP_PKEY_CTX\s0 will fail. -.PP -Removal of function code from the error codes -.IX Subsection "Removal of function code from the error codes" -.PP -The function code part of the error code is now always set to 0. For that -reason the \s-1\fBERR_GET_FUNC\s0()\fR macro was removed. Applications must resolve -the error codes only using the library number and the reason code. -.PP -ChaCha20\-Poly1305 cipher does not allow a truncated \s-1IV\s0 length to be used -.IX Subsection "ChaCha20-Poly1305 cipher does not allow a truncated IV length to be used" -.PP -In OpenSSL 3.0 setting the \s-1IV\s0 length to any value other than 12 will result in an -error. -Prior to OpenSSL 3.0 the ivlen could be smaller that the required 12 byte length, -using EVP_CIPHER_CTX_ctrl(ctx, \s-1EVP_CRTL_AEAD_SET_IVLEN,\s0 ivlen, \s-1NULL\s0). This resulted -in an \s-1IV\s0 that had leading zero padding. -.SS "Installation and Compilation" -.IX Subsection "Installation and Compilation" -Please refer to the \s-1INSTALL\s0.md file in the top of the distribution for -instructions on how to build and install OpenSSL 3.0. Please also refer to the -various platform specific \s-1NOTES\s0 files for your specific platform. -.SS "Upgrading from OpenSSL 1.1.1" -.IX Subsection "Upgrading from OpenSSL 1.1.1" -Upgrading to OpenSSL 3.0 from OpenSSL 1.1.1 should be relatively straight -forward in most cases. The most likely area where you will encounter problems -is if you have used low level APIs in your code (as discussed above). In that -case you are likely to start seeing deprecation warnings when compiling your -application. If this happens you have 3 options: -.IP "1." 4 -Ignore the warnings. They are just warnings. The deprecated functions are still present and you may still use them. However be aware that they may be removed from a future version of OpenSSL. -.IP "2." 4 -Suppress the warnings. Refer to your compiler documentation on how to do this. -.IP "3." 4 -Remove your usage of the low level APIs. In this case you will need to rewrite your code to use the high level APIs instead -.PP -\fIError code changes\fR -.IX Subsection "Error code changes" -.PP -As OpenSSL 3.0 provides a brand new Encoder/Decoder mechanism for working with -widely used file formats, application code that checks for particular error -reason codes on key loading failures might need an update. -.PP -Password-protected keys may deserve special attention. If only some errors -are treated as an indicator that the user should be asked about the password again, -it's worth testing these scenarios and processing the newly relevant codes. -.PP -There may be more cases to treat specially, depending on the calling application code. -.SS "Upgrading from OpenSSL 1.0.2" -.IX Subsection "Upgrading from OpenSSL 1.0.2" -Upgrading to OpenSSL 3.0 from OpenSSL 1.0.2 is likely to be significantly more -difficult. In addition to the issues discussed above in the section about -\&\*(L"Upgrading from OpenSSL 1.1.1\*(R", the main things to be aware of are: -.IP "1." 4 -The build and installation procedure has changed significantly. -.Sp -Check the file \s-1INSTALL\s0.md in the top of the installation for instructions on how -to build and install OpenSSL for your platform. Also read the various \s-1NOTES\s0 -files in the same directory, as applicable for your platform. -.IP "2." 4 -Many structures have been made opaque in OpenSSL 3.0. -.Sp -The structure definitions have been removed from the public header files and -moved to internal header files. In practice this means that you can no longer -stack allocate some structures. Instead they must be heap allocated through some -function call (typically those function names have a \f(CW\*(C`_new\*(C'\fR suffix to them). -Additionally you must use \*(L"setter\*(R" or \*(L"getter\*(R" functions to access the fields -within those structures. -.Sp -For example code that previously looked like this: -.Sp -.Vb 1 -\& EVP_MD_CTX md_ctx; -\& -\& /* This line will now generate compiler errors */ -\& EVP_MD_CTX_init(&md_ctx); -.Ve -.Sp -The code needs to be amended to look like this: -.Sp -.Vb 1 -\& EVP_MD_CTX *md_ctx; -\& -\& md_ctx = EVP_MD_CTX_new(); -\& ... -\& ... -\& EVP_MD_CTX_free(md_ctx); -.Ve -.IP "3." 4 -Support for TLSv1.3 has been added. -.Sp -This has a number of implications for \s-1SSL/TLS\s0 applications. See the -\&\s-1TLS1.3\s0 page for further details. -.PP -More details about the breaking changes between OpenSSL versions 1.0.2 and 1.1.0 -can be found on the -OpenSSL 1.1.0 Changes page . -.PP -\fIUpgrading from the OpenSSL 2.0 \s-1FIPS\s0 Object Module\fR -.IX Subsection "Upgrading from the OpenSSL 2.0 FIPS Object Module" -.PP -The OpenSSL 2.0 \s-1FIPS\s0 Object Module was a separate download that had to be built -separately and then integrated into your main OpenSSL 1.0.2 build. -In OpenSSL 3.0 the \s-1FIPS\s0 support is fully integrated into the mainline version of -OpenSSL and is no longer a separate download. For further information see -\&\*(L"Completing the installation of the \s-1FIPS\s0 Module\*(R". -.PP -The function calls \fBFIPS_mode()\fR and \fBFIPS_mode_set()\fR have been removed -from OpenSSL 3.0. You should rewrite your application to not use them. -See \fBfips_module\fR\|(7) and \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) for details. -.SS "Completing the installation of the \s-1FIPS\s0 Module" -.IX Subsection "Completing the installation of the FIPS Module" -The \s-1FIPS\s0 Module will be built and installed automatically if \s-1FIPS\s0 support has -been configured. The current documentation can be found in the -README-FIPS file. -.SS "Programming" -.IX Subsection "Programming" -Applications written to work with OpenSSL 1.1.1 will mostly just work with -OpenSSL 3.0. However changes will be required if you want to take advantage of -some of the new features that OpenSSL 3.0 makes available. In order to do that -you need to understand some new concepts introduced in OpenSSL 3.0. -Read \*(L"Library contexts\*(R" in \fBcrypto\fR\|(7) for further information. -.PP -\fILibrary Context\fR -.IX Subsection "Library Context" -.PP -A library context allows different components of a complex application to each -use a different library context and have different providers loaded with -different configuration settings. -See \*(L"Library contexts\*(R" in \fBcrypto\fR\|(7) for further info. -.PP -If the user creates an \fB\s-1OSSL_LIB_CTX\s0\fR via \fBOSSL_LIB_CTX_new\fR\|(3) then many -functions may need to be changed to pass additional parameters to handle the -library context. -.PP -Using a Library Context \- Old functions that should be changed -.IX Subsection "Using a Library Context - Old functions that should be changed" -.PP -If a library context is needed then all EVP_* digest functions that return a -\&\fBconst \s-1EVP_MD\s0 *\fR such as \fBEVP_sha256()\fR should be replaced with a call to -\&\fBEVP_MD_fetch\fR\|(3). See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7). -.PP -If a library context is needed then all EVP_* cipher functions that return a -\&\fBconst \s-1EVP_CIPHER\s0 *\fR such as \fBEVP_aes_128_cbc()\fR should be replaced vith a call to -\&\fBEVP_CIPHER_fetch\fR\|(3). See \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7). -.PP -Some functions can be passed an object that has already been set up with a library -context such as \fBd2i_X509\fR\|(3), \fBd2i_X509_CRL\fR\|(3), \fBd2i_X509_REQ\fR\|(3) and -\&\fBd2i_X509_PUBKEY\fR\|(3). If \s-1NULL\s0 is passed instead then the created object will be -set up with the default library context. Use \fBX509_new_ex\fR\|(3), -\&\fBX509_CRL_new_ex\fR\|(3), \fBX509_REQ_new_ex\fR\|(3) and \fBX509_PUBKEY_new_ex\fR\|(3) if a -library context is required. -.PP -All functions listed below with a \fI\s-1NAME\s0\fR have a replacement function \fINAME_ex\fR -that takes \fB\s-1OSSL_LIB_CTX\s0\fR as an additional argument. Functions that have other -mappings are listed along with the respective name. -.IP "\(bu" 4 -\&\fBASN1_item_new\fR\|(3), \fBASN1_item_d2i\fR\|(3), \fBASN1_item_d2i_fp\fR\|(3), -\&\fBASN1_item_d2i_bio\fR\|(3), \fBASN1_item_sign\fR\|(3) and \fBASN1_item_verify\fR\|(3) -.IP "\(bu" 4 -\&\fBBIO_new\fR\|(3) -.IP "\(bu" 4 -\&\fBb2i_RSA_PVK_bio()\fR and \fBi2b_PVK_bio()\fR -.IP "\(bu" 4 -\&\fBBN_CTX_new\fR\|(3) and \fBBN_CTX_secure_new\fR\|(3) -.IP "\(bu" 4 -\&\fBCMS_AuthEnvelopedData_create\fR\|(3), \fBCMS_ContentInfo_new\fR\|(3), \fBCMS_data_create\fR\|(3), -\&\fBCMS_digest_create\fR\|(3), \fBCMS_EncryptedData_encrypt\fR\|(3), \fBCMS_encrypt\fR\|(3), -\&\fBCMS_EnvelopedData_create\fR\|(3), \fBCMS_ReceiptRequest_create0\fR\|(3) and \fBCMS_sign\fR\|(3) -.IP "\(bu" 4 -\&\fBCONF_modules_load_file\fR\|(3) -.IP "\(bu" 4 -\&\fBCTLOG_new\fR\|(3), \fBCTLOG_new_from_base64\fR\|(3) and \fBCTLOG_STORE_new\fR\|(3) -.IP "\(bu" 4 -\&\fBCT_POLICY_EVAL_CTX_new\fR\|(3) -.IP "\(bu" 4 -\&\fBd2i_AutoPrivateKey\fR\|(3), \fBd2i_PrivateKey\fR\|(3) and \fBd2i_PUBKEY\fR\|(3) -.IP "\(bu" 4 -\&\fBd2i_PrivateKey_bio\fR\|(3) and \fBd2i_PrivateKey_fp\fR\|(3) -.Sp -Use \fBd2i_PrivateKey_ex_bio\fR\|(3) and \fBd2i_PrivateKey_ex_fp\fR\|(3) -.IP "\(bu" 4 -\&\fBEC_GROUP_new\fR\|(3) -.Sp -Use \fBEC_GROUP_new_by_curve_name_ex\fR\|(3) or \fBEC_GROUP_new_from_params\fR\|(3). -.IP "\(bu" 4 -\&\fBEVP_DigestSignInit\fR\|(3) and \fBEVP_DigestVerifyInit\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_PBE_CipherInit\fR\|(3), \fBEVP_PBE_find\fR\|(3) and \fBEVP_PBE_scrypt\fR\|(3) -.IP "\(bu" 4 -\&\fBPKCS5_PBE_keyivgen\fR\|(3) -.IP "\(bu" 4 -\&\s-1\fBEVP_PKCS82PKEY\s0\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_PKEY_CTX_new_id\fR\|(3) -.Sp -Use \fBEVP_PKEY_CTX_new_from_name\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_PKEY_derive_set_peer\fR\|(3), \fBEVP_PKEY_new_raw_private_key\fR\|(3) -and \fBEVP_PKEY_new_raw_public_key\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_SignFinal\fR\|(3) and \fBEVP_VerifyFinal\fR\|(3) -.IP "\(bu" 4 -\&\fBNCONF_new\fR\|(3) -.IP "\(bu" 4 -\&\fBOCSP_RESPID_match\fR\|(3) and \fBOCSP_RESPID_set_by_key\fR\|(3) -.IP "\(bu" 4 -\&\fBOPENSSL_thread_stop\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_STORE_open\fR\|(3) -.IP "\(bu" 4 -\&\fBPEM_read_bio_Parameters\fR\|(3), \fBPEM_read_bio_PrivateKey\fR\|(3), \fBPEM_read_bio_PUBKEY\fR\|(3), -\&\fBPEM_read_PrivateKey\fR\|(3) and \fBPEM_read_PUBKEY\fR\|(3) -.IP "\(bu" 4 -\&\fBPEM_write_bio_PrivateKey\fR\|(3), \fBPEM_write_bio_PUBKEY\fR\|(3), \fBPEM_write_PrivateKey\fR\|(3) -and \fBPEM_write_PUBKEY\fR\|(3) -.IP "\(bu" 4 -\&\fBPEM_X509_INFO_read_bio\fR\|(3) and \fBPEM_X509_INFO_read\fR\|(3) -.IP "\(bu" 4 -\&\fBPKCS12_add_key\fR\|(3), \fBPKCS12_add_safe\fR\|(3), \fBPKCS12_add_safes\fR\|(3), -\&\fBPKCS12_create\fR\|(3), \fBPKCS12_decrypt_skey\fR\|(3), \fBPKCS12_init\fR\|(3), \fBPKCS12_item_decrypt_d2i\fR\|(3), -\&\fBPKCS12_item_i2d_encrypt\fR\|(3), \fBPKCS12_key_gen_asc\fR\|(3), \fBPKCS12_key_gen_uni\fR\|(3), -\&\fBPKCS12_key_gen_utf8\fR\|(3), \fBPKCS12_pack_p7encdata\fR\|(3), \fBPKCS12_pbe_crypt\fR\|(3), -\&\fBPKCS12_PBE_keyivgen\fR\|(3), \fBPKCS12_SAFEBAG_create_pkcs8_encrypt\fR\|(3) -.IP "\(bu" 4 -\&\fBPKCS5_pbe_set0_algor\fR\|(3), \fBPKCS5_pbe_set\fR\|(3), \fBPKCS5_pbe2_set_iv\fR\|(3), -\&\fBPKCS5_pbkdf2_set\fR\|(3) and \fBPKCS5_v2_scrypt_keyivgen\fR\|(3) -.IP "\(bu" 4 -\&\fBPKCS7_encrypt\fR\|(3), \fBPKCS7_new\fR\|(3) and \fBPKCS7_sign\fR\|(3) -.IP "\(bu" 4 -\&\fBPKCS8_decrypt\fR\|(3), \fBPKCS8_encrypt\fR\|(3) and \fBPKCS8_set0_pbe\fR\|(3) -.IP "\(bu" 4 -\&\fBRAND_bytes\fR\|(3) and \fBRAND_priv_bytes\fR\|(3) -.IP "\(bu" 4 -\&\fBSMIME_write_ASN1\fR\|(3) -.IP "\(bu" 4 -\&\fBSSL_load_client_CA_file\fR\|(3) -.IP "\(bu" 4 -\&\fBSSL_CTX_new\fR\|(3) -.IP "\(bu" 4 -\&\fBTS_RESP_CTX_new\fR\|(3) -.IP "\(bu" 4 -\&\fBX509_CRL_new\fR\|(3) -.IP "\(bu" 4 -\&\fBX509_load_cert_crl_file\fR\|(3) and \fBX509_load_cert_file\fR\|(3) -.IP "\(bu" 4 -\&\fBX509_LOOKUP_by_subject\fR\|(3) and \fBX509_LOOKUP_ctrl\fR\|(3) -.IP "\(bu" 4 -\&\fBX509_NAME_hash\fR\|(3) -.IP "\(bu" 4 -\&\fBX509_new\fR\|(3) -.IP "\(bu" 4 -\&\fBX509_REQ_new\fR\|(3) and \fBX509_REQ_verify\fR\|(3) -.IP "\(bu" 4 -\&\fBX509_STORE_CTX_new\fR\|(3), \fBX509_STORE_set_default_paths\fR\|(3), \fBX509_STORE_load_file\fR\|(3), -\&\fBX509_STORE_load_locations\fR\|(3) and \fBX509_STORE_load_store\fR\|(3) -.PP -New functions that use a Library context -.IX Subsection "New functions that use a Library context" -.PP -The following functions can be passed a library context if required. -Passing \s-1NULL\s0 will use the default library context. -.IP "\(bu" 4 -\&\fBBIO_new_from_core_bio\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_ASYM_CIPHER_fetch\fR\|(3) and \fBEVP_ASYM_CIPHER_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_CIPHER_fetch\fR\|(3) and \fBEVP_CIPHER_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_default_properties_enable_fips\fR\|(3) and -\&\fBEVP_default_properties_is_fips_enabled\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_KDF_fetch\fR\|(3) and \fBEVP_KDF_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_KEM_fetch\fR\|(3) and \fBEVP_KEM_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_KEYEXCH_fetch\fR\|(3) and \fBEVP_KEYEXCH_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_KEYMGMT_fetch\fR\|(3) and \fBEVP_KEYMGMT_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_MAC_fetch\fR\|(3) and \fBEVP_MAC_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_MD_fetch\fR\|(3) and \fBEVP_MD_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_PKEY_CTX_new_from_pkey\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_PKEY_Q_keygen\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_Q_mac\fR\|(3) and \fBEVP_Q_digest\fR\|(3) -.IP "\(bu" 4 -\&\s-1\fBEVP_RAND\s0\fR\|(3) and \fBEVP_RAND_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_set_default_properties\fR\|(3) -.IP "\(bu" 4 -\&\fBEVP_SIGNATURE_fetch\fR\|(3) and \fBEVP_SIGNATURE_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_CMP_CTX_new\fR\|(3) and \fBOSSL_CMP_SRV_CTX_new\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_CRMF_ENCRYPTEDVALUE_get1_encCert\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_CRMF_MSG_create_popo\fR\|(3) and \fBOSSL_CRMF_MSGS_verify_popo\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_CRMF_pbm_new\fR\|(3) and \fBOSSL_CRMF_pbmp_new\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_DECODER_CTX_add_extra\fR\|(3) and \fBOSSL_DECODER_CTX_new_for_pkey\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_DECODER_fetch\fR\|(3) and \fBOSSL_DECODER_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_ENCODER_CTX_add_extra\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_ENCODER_fetch\fR\|(3) and \fBOSSL_ENCODER_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_LIB_CTX_free\fR\|(3), \fBOSSL_LIB_CTX_load_config\fR\|(3) and \fBOSSL_LIB_CTX_set0_default\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_PROVIDER_add_builtin\fR\|(3), \fBOSSL_PROVIDER_available\fR\|(3), -\&\fBOSSL_PROVIDER_do_all\fR\|(3), \fBOSSL_PROVIDER_load\fR\|(3), -\&\fBOSSL_PROVIDER_set_default_search_path\fR\|(3) and \fBOSSL_PROVIDER_try_load\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_SELF_TEST_get_callback\fR\|(3) and \fBOSSL_SELF_TEST_set_callback\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_STORE_attach\fR\|(3) -.IP "\(bu" 4 -\&\fBOSSL_STORE_LOADER_fetch\fR\|(3) and \fBOSSL_STORE_LOADER_do_all_provided\fR\|(3) -.IP "\(bu" 4 -\&\fBRAND_get0_primary\fR\|(3), \fBRAND_get0_private\fR\|(3), \fBRAND_get0_public\fR\|(3), -\&\fBRAND_set_DRBG_type\fR\|(3) and \fBRAND_set_seed_source_type\fR\|(3) -.PP -\fIProviders\fR -.IX Subsection "Providers" -.PP -Providers are described in detail here \*(L"Providers\*(R" in \fBcrypto\fR\|(7). -See also \*(L"\s-1OPENSSL PROVIDERS\*(R"\s0 in \fBcrypto\fR\|(7). -.PP -\fIFetching algorithms and property queries\fR -.IX Subsection "Fetching algorithms and property queries" -.PP -Implicit and Explicit Fetching is described in detail here -\&\*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7). -.PP -\fIMapping \s-1EVP\s0 controls and flags to provider \s-1\f(BIOSSL_PARAM\s0\fI\|(3) parameters\fR -.IX Subsection "Mapping EVP controls and flags to provider OSSL_PARAM parameters" -.PP -The existing functions for controls (such as \fBEVP_CIPHER_CTX_ctrl\fR\|(3)) and -manipulating flags (such as \fBEVP_MD_CTX_set_flags\fR\|(3))internally use -\&\fB\s-1OSSL_PARAMS\s0\fR to pass information to/from provider objects. -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for additional information related to parameters. -.PP -For ciphers see \*(L"\s-1CONTROLS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3), \*(L"\s-1FLAGS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3) and -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -.PP -For digests see \*(L"\s-1CONTROLS\*(R"\s0 in \fBEVP_DigestInit\fR\|(3), \*(L"\s-1FLAGS\*(R"\s0 in \fBEVP_DigestInit\fR\|(3) and -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_DigestInit\fR\|(3). -.PP -\fIDeprecation of Low Level Functions\fR -.IX Subsection "Deprecation of Low Level Functions" -.PP -A significant number of APIs have been deprecated in OpenSSL 3.0. -This section describes some common categories of deprecations. -See \*(L"Deprecated function mappings\*(R" for the list of deprecated functions -that refer to these categories. -.PP -Providers are a replacement for engines and low-level method overrides -.IX Subsection "Providers are a replacement for engines and low-level method overrides" -.PP -Any accessor that uses an \s-1ENGINE\s0 is deprecated (such as \fBEVP_PKEY_set1_engine()\fR). -Applications using engines should instead use providers. -.PP -Before providers were added algorithms were overridden by changing the methods -used by algorithms. All these methods such as \fBRSA_new_method()\fR and \fBRSA_meth_new()\fR -are now deprecated and can be replaced by using providers instead. -.PP -Deprecated i2d and d2i functions for low-level key types -.IX Subsection "Deprecated i2d and d2i functions for low-level key types" -.PP -Any i2d and d2i functions such as \fBd2i_DHparams()\fR that take a low-level key type -have been deprecated. Applications should instead use the \s-1\fBOSSL_DECODER\s0\fR\|(3) and -\&\s-1\fBOSSL_ENCODER\s0\fR\|(3) APIs to read and write files. -See \*(L"Migration\*(R" in \fBd2i_RSAPrivateKey\fR\|(3) for further details. -.PP -Deprecated low-level key object getters and setters -.IX Subsection "Deprecated low-level key object getters and setters" -.PP -Applications that set or get low-level key objects (such as \fBEVP_PKEY_set1_DH()\fR -or \fBEVP_PKEY_get0()\fR) should instead use the \s-1OSSL_ENCODER\s0 -(See \fBOSSL_ENCODER_to_bio\fR\|(3)) or \s-1OSSL_DECODER\s0 (See \fBOSSL_DECODER_from_bio\fR\|(3)) -APIs, or alternatively use \fBEVP_PKEY_fromdata\fR\|(3) or \fBEVP_PKEY_todata\fR\|(3). -.PP -Deprecated low-level key parameter getters -.IX Subsection "Deprecated low-level key parameter getters" -.PP -Functions that access low-level objects directly such as \fBRSA_get0_n\fR\|(3) are now -deprecated. Applications should use one of \fBEVP_PKEY_get_bn_param\fR\|(3), -\&\fBEVP_PKEY_get_int_param\fR\|(3), l<\fBEVP_PKEY_get_size_t_param\fR\|(3)>, -\&\fBEVP_PKEY_get_utf8_string_param\fR\|(3), \fBEVP_PKEY_get_octet_string_param\fR\|(3) or -\&\fBEVP_PKEY_get_params\fR\|(3) to access fields from an \s-1EVP_PKEY.\s0 -Gettable parameters are listed in \*(L"Common \s-1RSA\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7), -\&\*(L"\s-1DH\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7), \*(L"\s-1DSA\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), -\&\*(L"\s-1FFC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-FFC\s0\fR\|(7), \*(L"Common \s-1EC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) and -\&\*(L"Common X25519, X448, \s-1ED25519\s0 and \s-1ED448\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7). -Applications may also use \fBEVP_PKEY_todata\fR\|(3) to return all fields. -.PP -Deprecated low-level key parameter setters -.IX Subsection "Deprecated low-level key parameter setters" -.PP -Functions that access low-level objects directly such as \fBRSA_set0_crt_params\fR\|(3) -are now deprecated. Applications should use \fBEVP_PKEY_fromdata\fR\|(3) to create -new keys from user provided key data. Keys should be immutable once they are -created, so if required the user may use \fBEVP_PKEY_todata\fR\|(3), \fBOSSL_PARAM_merge\fR\|(3), -and \fBEVP_PKEY_fromdata\fR\|(3) to create a modified key. -See \*(L"Examples\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7) for more information. -See \*(L"Deprecated low-level key generation functions\*(R" for information on -generating a key using parameters. -.PP -Deprecated low-level object creation -.IX Subsection "Deprecated low-level object creation" -.PP -Low-level objects were created using methods such as \fBRSA_new\fR\|(3), -\&\fBRSA_up_ref\fR\|(3) and \fBRSA_free\fR\|(3). Applications should instead use the -high-level \s-1EVP_PKEY\s0 APIs, e.g. \fBEVP_PKEY_new\fR\|(3), \fBEVP_PKEY_up_ref\fR\|(3) and -\&\fBEVP_PKEY_free\fR\|(3). -See also \fBEVP_PKEY_CTX_new_from_name\fR\|(3) and \fBEVP_PKEY_CTX_new_from_pkey\fR\|(3). -.PP -EVP_PKEYs may be created in a variety of ways: -See also \*(L"Deprecated low-level key generation functions\*(R", -\&\*(L"Deprecated low-level key reading and writing functions\*(R" and -\&\*(L"Deprecated low-level key parameter setters\*(R". -.PP -Deprecated low-level encryption functions -.IX Subsection "Deprecated low-level encryption functions" -.PP -Low-level encryption functions such as \fBAES_encrypt\fR\|(3) and \fBAES_decrypt\fR\|(3) -have been informally discouraged from use for a long time. Applications should -instead use the high level \s-1EVP\s0 APIs \fBEVP_EncryptInit_ex\fR\|(3), -\&\fBEVP_EncryptUpdate\fR\|(3), and \fBEVP_EncryptFinal_ex\fR\|(3) or -\&\fBEVP_DecryptInit_ex\fR\|(3), \fBEVP_DecryptUpdate\fR\|(3) and \fBEVP_DecryptFinal_ex\fR\|(3). -.PP -Deprecated low-level digest functions -.IX Subsection "Deprecated low-level digest functions" -.PP -Use of low-level digest functions such as \fBSHA1_Init\fR\|(3) have been -informally discouraged from use for a long time. Applications should instead -use the high level \s-1EVP\s0 APIs \fBEVP_DigestInit_ex\fR\|(3), \fBEVP_DigestUpdate\fR\|(3) -and \fBEVP_DigestFinal_ex\fR\|(3), or the quick one-shot \fBEVP_Q_digest\fR\|(3). -.PP -Note that the functions \s-1\fBSHA1\s0\fR\|(3), \s-1\fBSHA224\s0\fR\|(3), \s-1\fBSHA256\s0\fR\|(3), \s-1\fBSHA384\s0\fR\|(3) -and \s-1\fBSHA512\s0\fR\|(3) have changed to macros that use \fBEVP_Q_digest\fR\|(3). -.PP -Deprecated low-level signing functions -.IX Subsection "Deprecated low-level signing functions" -.PP -Use of low-level signing functions such as \fBDSA_sign\fR\|(3) have been -informally discouraged for a long time. Instead applications should use -\&\fBEVP_DigestSign\fR\|(3) and \fBEVP_DigestVerify\fR\|(3). -See also \s-1\fBEVP_SIGNATURE\-RSA\s0\fR\|(7), \s-1\fBEVP_SIGNATURE\-DSA\s0\fR\|(7), -\&\s-1\fBEVP_SIGNATURE\-ECDSA\s0\fR\|(7) and \s-1\fBEVP_SIGNATURE\-ED25519\s0\fR\|(7). -.PP -Deprecated low-level \s-1MAC\s0 functions -.IX Subsection "Deprecated low-level MAC functions" -.PP -Low-level mac functions such as \fBCMAC_Init\fR\|(3) are deprecated. -Applications should instead use the new \s-1\fBEVP_MAC\s0\fR\|(3) interface, using -\&\fBEVP_MAC_CTX_new\fR\|(3), \fBEVP_MAC_CTX_free\fR\|(3), \fBEVP_MAC_init\fR\|(3), -\&\fBEVP_MAC_update\fR\|(3) and \fBEVP_MAC_final\fR\|(3) or the single-shot \s-1MAC\s0 function -\&\fBEVP_Q_mac\fR\|(3). -See \s-1\fBEVP_MAC\s0\fR\|(3), \s-1\fBEVP_MAC\-HMAC\s0\fR\|(7), \s-1\fBEVP_MAC\-CMAC\s0\fR\|(7), \s-1\fBEVP_MAC\-GMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-KMAC\s0\fR\|(7), \s-1\fBEVP_MAC\-BLAKE2\s0\fR\|(7), \fBEVP_MAC\-Poly1305\fR\|(7) and -\&\fBEVP_MAC\-Siphash\fR\|(7) for additional information. -.PP -Note that the one-shot method \s-1\fBHMAC\s0()\fR is still available for compatibility purposes, -but this can also be replaced by using \s-1EVP_Q_MAC\s0 if a library context is required. -.PP -Deprecated low-level validation functions -.IX Subsection "Deprecated low-level validation functions" -.PP -Low-level validation functions such as \fBDH_check\fR\|(3) have been informally -discouraged from use for a long time. Applications should instead use the high-level -\&\s-1EVP_PKEY\s0 APIs such as \fBEVP_PKEY_check\fR\|(3), \fBEVP_PKEY_param_check\fR\|(3), -\&\fBEVP_PKEY_param_check_quick\fR\|(3), \fBEVP_PKEY_public_check\fR\|(3), -\&\fBEVP_PKEY_public_check_quick\fR\|(3), \fBEVP_PKEY_private_check\fR\|(3), -and \fBEVP_PKEY_pairwise_check\fR\|(3). -.PP -Deprecated low-level key exchange functions -.IX Subsection "Deprecated low-level key exchange functions" -.PP -Many low-level functions have been informally discouraged from use for a long -time. Applications should instead use \fBEVP_PKEY_derive\fR\|(3). -See \s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7), \s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7) and \s-1\fBEVP_KEYEXCH\-X25519\s0\fR\|(7). -.PP -Deprecated low-level key generation functions -.IX Subsection "Deprecated low-level key generation functions" -.PP -Many low-level functions have been informally discouraged from use for a long -time. Applications should instead use \fBEVP_PKEY_keygen_init\fR\|(3) and -\&\fBEVP_PKEY_generate\fR\|(3) as described in \s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), \s-1\fBEVP_PKEY\-DH\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-RSA\s0\fR\|(7), \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) and \s-1\fBEVP_PKEY\-X25519\s0\fR\|(7). -The 'quick' one-shot function \fBEVP_PKEY_Q_keygen\fR\|(3) and macros for the most -common cases: <\fBEVP_RSA_gen\fR\|(3)> and \fBEVP_EC_gen\fR\|(3) may also be used. -.PP -Deprecated low-level key reading and writing functions -.IX Subsection "Deprecated low-level key reading and writing functions" -.PP -Use of low-level objects (such as \s-1DSA\s0) has been informally discouraged from use -for a long time. Functions to read and write these low-level objects (such as -\&\fBPEM_read_DSA_PUBKEY()\fR) should be replaced. Applications should instead use -\&\fBOSSL_ENCODER_to_bio\fR\|(3) and \fBOSSL_DECODER_from_bio\fR\|(3). -.PP -Deprecated low-level key printing functions -.IX Subsection "Deprecated low-level key printing functions" -.PP -Use of low-level objects (such as \s-1DSA\s0) has been informally discouraged from use -for a long time. Functions to print these low-level objects such as -\&\fBDSA_print()\fR should be replaced with the equivalent \s-1EVP_PKEY\s0 functions. -Application should use one of \fBEVP_PKEY_print_public\fR\|(3), -\&\fBEVP_PKEY_print_private\fR\|(3), \fBEVP_PKEY_print_params\fR\|(3), -\&\fBEVP_PKEY_print_public_fp\fR\|(3), \fBEVP_PKEY_print_private_fp\fR\|(3) or -\&\fBEVP_PKEY_print_params_fp\fR\|(3). Note that internally these use -\&\fBOSSL_ENCODER_to_bio\fR\|(3) and \fBOSSL_DECODER_from_bio\fR\|(3). -.PP -\fIDeprecated function mappings\fR -.IX Subsection "Deprecated function mappings" -.PP -The following functions have been deprecated in 3.0. -.IP "\(bu" 4 -\&\fBAES_bi_ige_encrypt()\fR and \fBAES_ige_encrypt()\fR -.Sp -There is no replacement for the \s-1IGE\s0 functions. New code should not use these modes. -These undocumented functions were never integrated into the \s-1EVP\s0 layer. -They implemented the \s-1AES\s0 Infinite Garble Extension (\s-1IGE\s0) mode and \s-1AES\s0 -Bi-directional \s-1IGE\s0 mode. These modes were never formally standardised and -usage of these functions is believed to be very small. In particular -\&\fBAES_bi_ige_encrypt()\fR has a known bug. It accepts 2 \s-1AES\s0 keys, but only one -is ever used. The security implications are believed to be minimal, but -this issue was never fixed for backwards compatibility reasons. -.IP "\(bu" 4 -\&\fBAES_encrypt()\fR, \fBAES_decrypt()\fR, \fBAES_set_encrypt_key()\fR, \fBAES_set_decrypt_key()\fR, -\&\fBAES_cbc_encrypt()\fR, \fBAES_cfb128_encrypt()\fR, \fBAES_cfb1_encrypt()\fR, \fBAES_cfb8_encrypt()\fR, -\&\fBAES_ecb_encrypt()\fR, \fBAES_ofb128_encrypt()\fR -.IP "\(bu" 4 -\&\fBAES_unwrap_key()\fR, \fBAES_wrap_key()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R" -.IP "\(bu" 4 -\&\fBAES_options()\fR -.Sp -There is no replacement. It returned a string indicating if the \s-1AES\s0 code was unrolled. -.IP "\(bu" 4 -\&\fBASN1_digest()\fR, \fBASN1_sign()\fR, \fBASN1_verify()\fR -.Sp -There are no replacements. These old functions are not used, and could be -disabled with the macro \s-1NO_ASN1_OLD\s0 since OpenSSL 0.9.7. -.IP "\(bu" 4 -\&\fBASN1_STRING_length_set()\fR -.Sp -Use \fBASN1_STRING_set\fR\|(3) or \fBASN1_STRING_set0\fR\|(3) instead. -This was a potentially unsafe function that could change the bounds of a -previously passed in pointer. -.IP "\(bu" 4 -\&\fBBF_encrypt()\fR, \fBBF_decrypt()\fR, \fBBF_set_key()\fR, \fBBF_cbc_encrypt()\fR, \fBBF_cfb64_encrypt()\fR, -\&\fBBF_ecb_encrypt()\fR, \fBBF_ofb64_encrypt()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -The Blowfish algorithm has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBBF_options()\fR -.Sp -There is no replacement. This option returned a constant string. -.IP "\(bu" 4 -\&\fBBIO_get_callback()\fR, \fBBIO_set_callback()\fR, \fBBIO_debug_callback()\fR -.Sp -Use the respective non-deprecated \fB_ex()\fR functions. -.IP "\(bu" 4 -\&\fBBN_is_prime_ex()\fR, \fBBN_is_prime_fasttest_ex()\fR -.Sp -Use \fBBN_check_prime\fR\|(3) which avoids possible misuse and always uses at least -64 rounds of the Miller-Rabin primality test. -.IP "\(bu" 4 -\&\fBBN_pseudo_rand()\fR, \fBBN_pseudo_rand_range()\fR -.Sp -Use \fBBN_rand\fR\|(3) and \fBBN_rand_range\fR\|(3). -.IP "\(bu" 4 -\&\fBBN_X931_derive_prime_ex()\fR, \fBBN_X931_generate_prime_ex()\fR, \fBBN_X931_generate_Xpq()\fR -.Sp -There are no replacements for these low-level functions. They were used internally -by \fBRSA_X931_derive_ex()\fR and \fBRSA_X931_generate_key_ex()\fR which are also deprecated. -Use \fBEVP_PKEY_keygen\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBCamellia_encrypt()\fR, \fBCamellia_decrypt()\fR, \fBCamellia_set_key()\fR, -\&\fBCamellia_cbc_encrypt()\fR, \fBCamellia_cfb128_encrypt()\fR, \fBCamellia_cfb1_encrypt()\fR, -\&\fBCamellia_cfb8_encrypt()\fR, \fBCamellia_ctr128_encrypt()\fR, \fBCamellia_ecb_encrypt()\fR, -\&\fBCamellia_ofb128_encrypt()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -.IP "\(bu" 4 -\&\fBCAST_encrypt()\fR, \fBCAST_decrypt()\fR, \fBCAST_set_key()\fR, \fBCAST_cbc_encrypt()\fR, -\&\fBCAST_cfb64_encrypt()\fR, \fBCAST_ecb_encrypt()\fR, \fBCAST_ofb64_encrypt()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -The \s-1CAST\s0 algorithm has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBCMAC_CTX_new()\fR, \fBCMAC_CTX_cleanup()\fR, \fBCMAC_CTX_copy()\fR, \fBCMAC_CTX_free()\fR, -\&\fBCMAC_CTX_get0_cipher_ctx()\fR -.Sp -See \*(L"Deprecated low-level \s-1MAC\s0 functions\*(R". -.IP "\(bu" 4 -\&\fBCMAC_Init()\fR, \fBCMAC_Update()\fR, \fBCMAC_Final()\fR, \fBCMAC_resume()\fR -.Sp -See \*(L"Deprecated low-level \s-1MAC\s0 functions\*(R". -.IP "\(bu" 4 -\&\fBCRYPTO_mem_ctrl()\fR, \fBCRYPTO_mem_debug_free()\fR, \fBCRYPTO_mem_debug_malloc()\fR, -\&\fBCRYPTO_mem_debug_pop()\fR, \fBCRYPTO_mem_debug_push()\fR, \fBCRYPTO_mem_debug_realloc()\fR, -\&\fBCRYPTO_mem_leaks()\fR, \fBCRYPTO_mem_leaks_cb()\fR, \fBCRYPTO_mem_leaks_fp()\fR, -\&\fBCRYPTO_set_mem_debug()\fR -.Sp -Memory-leak checking has been deprecated in favor of more modern development -tools, such as compiler memory and leak sanitizers or Valgrind. -.IP "\(bu" 4 -\&\fBCRYPTO_cts128_encrypt_block()\fR, \fBCRYPTO_cts128_encrypt()\fR, -\&\fBCRYPTO_cts128_decrypt_block()\fR, \fBCRYPTO_cts128_decrypt()\fR, -\&\fBCRYPTO_nistcts128_encrypt_block()\fR, \fBCRYPTO_nistcts128_encrypt()\fR, -\&\fBCRYPTO_nistcts128_decrypt_block()\fR, \fBCRYPTO_nistcts128_decrypt()\fR -.Sp -Use the higher level functions \fBEVP_CipherInit_ex2()\fR, \fBEVP_CipherUpdate()\fR and -\&\fBEVP_CipherFinal_ex()\fR instead. -See the \*(L"cts_mode\*(R" parameter in -\&\*(L"Gettable and Settable \s-1EVP_CIPHER_CTX\s0 parameters\*(R" in \fBEVP_EncryptInit\fR\|(3). -See \*(L"\s-1EXAMPLES\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3) for a \s-1AES\-256\-CBC\-CTS\s0 example. -.IP "\(bu" 4 -\&\fBd2i_DHparams()\fR, \fBd2i_DHxparams()\fR, \fBd2i_DSAparams()\fR, \fBd2i_DSAPrivateKey()\fR, -\&\fBd2i_DSAPrivateKey_bio()\fR, \fBd2i_DSAPrivateKey_fp()\fR, \fBd2i_DSA_PUBKEY()\fR, -\&\fBd2i_DSA_PUBKEY_bio()\fR, \fBd2i_DSA_PUBKEY_fp()\fR, \fBd2i_DSAPublicKey()\fR, -\&\fBd2i_ECParameters()\fR, \fBd2i_ECPrivateKey()\fR, \fBd2i_ECPrivateKey_bio()\fR, -\&\fBd2i_ECPrivateKey_fp()\fR, \fBd2i_EC_PUBKEY()\fR, \fBd2i_EC_PUBKEY_bio()\fR, -\&\fBd2i_EC_PUBKEY_fp()\fR, \fBd2i_RSAPrivateKey()\fR, -\&\fBd2i_RSAPrivateKey_bio()\fR, \fBd2i_RSAPrivateKey_fp()\fR, \fBd2i_RSA_PUBKEY()\fR, -\&\fBd2i_RSA_PUBKEY_bio()\fR, \fBd2i_RSA_PUBKEY_fp()\fR, \fBd2i_RSAPublicKey()\fR, -\&\fBd2i_RSAPublicKey_bio()\fR, \fBd2i_RSAPublicKey_fp()\fR -.Sp -See \*(L"Deprecated i2d and d2i functions for low-level key types\*(R" -.IP "\(bu" 4 -\&\fBo2i_ECPublicKey()\fR -.Sp -Use \fBEVP_PKEY_set1_encoded_public_key\fR\|(3). -See \*(L"Deprecated low-level key parameter setters\*(R" -.IP "\(bu" 4 -\&\fBDES_crypt()\fR, \fBDES_fcrypt()\fR, \fBDES_encrypt1()\fR, \fBDES_encrypt2()\fR, \fBDES_encrypt3()\fR, -\&\fBDES_decrypt3()\fR, \fBDES_ede3_cbc_encrypt()\fR, \fBDES_ede3_cfb64_encrypt()\fR, -\&\fBDES_ede3_cfb_encrypt()\fR,\fBDES_ede3_ofb64_encrypt()\fR, -\&\fBDES_ecb_encrypt()\fR, \fBDES_ecb3_encrypt()\fR, \fBDES_ofb64_encrypt()\fR, \fBDES_ofb_encrypt()\fR, -DES_cfb64_encrypt \fBDES_cfb_encrypt()\fR, \fBDES_cbc_encrypt()\fR, \fBDES_ncbc_encrypt()\fR, -\&\fBDES_pcbc_encrypt()\fR, \fBDES_xcbc_encrypt()\fR, \fBDES_cbc_cksum()\fR, \fBDES_quad_cksum()\fR, -\&\fBDES_check_key_parity()\fR, \fBDES_is_weak_key()\fR, \fBDES_key_sched()\fR, \fBDES_options()\fR, -\&\fBDES_random_key()\fR, \fBDES_set_key()\fR, \fBDES_set_key_checked()\fR, \fBDES_set_key_unchecked()\fR, -\&\fBDES_set_odd_parity()\fR, \fBDES_string_to_2keys()\fR, \fBDES_string_to_key()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -Algorithms for \*(L"DESX-CBC\*(R", \*(L"DES-ECB\*(R", \*(L"DES-CBC\*(R", \*(L"DES-OFB\*(R", \*(L"DES-CFB\*(R", -\&\*(L"\s-1DES\-CFB1\*(R"\s0 and \*(L"\s-1DES\-CFB8\*(R"\s0 have been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBDH_bits()\fR, \fBDH_security_bits()\fR, \fBDH_size()\fR -.Sp -Use \fBEVP_PKEY_get_bits\fR\|(3), \fBEVP_PKEY_get_security_bits\fR\|(3) and -\&\fBEVP_PKEY_get_size\fR\|(3). -.IP "\(bu" 4 -\&\fBDH_check()\fR, \fBDH_check_ex()\fR, \fBDH_check_params()\fR, \fBDH_check_params_ex()\fR, -\&\fBDH_check_pub_key()\fR, \fBDH_check_pub_key_ex()\fR -.Sp -See \*(L"Deprecated low-level validation functions\*(R" -.IP "\(bu" 4 -\&\fBDH_clear_flags()\fR, \fBDH_test_flags()\fR, \fBDH_set_flags()\fR -.Sp -The \fB\s-1DH_FLAG_CACHE_MONT_P\s0\fR flag has been deprecated without replacement. -The \fB\s-1DH_FLAG_TYPE_DH\s0\fR and \fB\s-1DH_FLAG_TYPE_DHX\s0\fR have been deprecated. -Use \fBEVP_PKEY_is_a()\fR to determine the type of a key. -There is no replacement for setting these flags. -.IP "\(bu" 4 -\&\fBDH_compute_key()\fR \fBDH_compute_key_padded()\fR -.Sp -See \*(L"Deprecated low-level key exchange functions\*(R". -.IP "\(bu" 4 -\&\fBDH_new()\fR, \fBDH_new_by_nid()\fR, \fBDH_free()\fR, \fBDH_up_ref()\fR -.Sp -See \*(L"Deprecated low-level object creation\*(R" -.IP "\(bu" 4 -\&\fBDH_generate_key()\fR, \fBDH_generate_parameters_ex()\fR -.Sp -See \*(L"Deprecated low-level key generation functions\*(R". -.IP "\(bu" 4 -\&\fBDH_get0_pqg()\fR, \fBDH_get0_p()\fR, \fBDH_get0_q()\fR, \fBDH_get0_g()\fR, \fBDH_get0_key()\fR, -\&\fBDH_get0_priv_key()\fR, \fBDH_get0_pub_key()\fR, \fBDH_get_length()\fR, \fBDH_get_nid()\fR -.Sp -See \*(L"Deprecated low-level key parameter getters\*(R" -.IP "\(bu" 4 -\&\fBDH_get_1024_160()\fR, \fBDH_get_2048_224()\fR, \fBDH_get_2048_256()\fR -.Sp -Applications should instead set the \fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR as specified in -\&\*(L"\s-1DH\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-DH\s0\fR\|(7)) to one of \*(L"dh_1024_160\*(R", \*(L"dh_2048_224\*(R" or -\&\*(L"dh_2048_256\*(R" when generating a \s-1DH\s0 key. -.IP "\(bu" 4 -\&\s-1\fBDH_KDF_X9_42\s0()\fR -.Sp -Applications should use \fBEVP_PKEY_CTX_set_dh_kdf_type\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBDH_get_default_method()\fR, \fBDH_get0_engine()\fR, DH_meth_*(), \fBDH_new_method()\fR, -\&\fBDH_OpenSSL()\fR, \fBDH_get_ex_data()\fR, \fBDH_set_default_method()\fR, \fBDH_set_method()\fR, -\&\fBDH_set_ex_data()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R" -.IP "\(bu" 4 -\&\fBDHparams_print()\fR, \fBDHparams_print_fp()\fR -.Sp -See \*(L"Deprecated low-level key printing functions\*(R" -.IP "\(bu" 4 -\&\fBDH_set0_key()\fR, \fBDH_set0_pqg()\fR, \fBDH_set_length()\fR -.Sp -See \*(L"Deprecated low-level key parameter setters\*(R" -.IP "\(bu" 4 -\&\fBDSA_bits()\fR, \fBDSA_security_bits()\fR, \fBDSA_size()\fR -.Sp -Use \fBEVP_PKEY_get_bits\fR\|(3), \fBEVP_PKEY_get_security_bits\fR\|(3) and -\&\fBEVP_PKEY_get_size\fR\|(3). -.IP "\(bu" 4 -\&\fBDHparams_dup()\fR, \fBDSA_dup_DH()\fR -.Sp -There is no direct replacement. Applications may use \fBEVP_PKEY_copy_parameters\fR\|(3) -and \fBEVP_PKEY_dup\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBDSA_generate_key()\fR, \fBDSA_generate_parameters_ex()\fR -.Sp -See \*(L"Deprecated low-level key generation functions\*(R". -.IP "\(bu" 4 -\&\fBDSA_get0_engine()\fR, \fBDSA_get_default_method()\fR, \fBDSA_get_ex_data()\fR, -\&\fBDSA_get_method()\fR, DSA_meth_*(), \fBDSA_new_method()\fR, \fBDSA_OpenSSL()\fR, -\&\fBDSA_set_default_method()\fR, \fBDSA_set_ex_data()\fR, \fBDSA_set_method()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R". -.IP "\(bu" 4 -\&\fBDSA_get0_p()\fR, \fBDSA_get0_q()\fR, \fBDSA_get0_g()\fR, \fBDSA_get0_pqg()\fR, \fBDSA_get0_key()\fR, -\&\fBDSA_get0_priv_key()\fR, \fBDSA_get0_pub_key()\fR -.Sp -See \*(L"Deprecated low-level key parameter getters\*(R". -.IP "\(bu" 4 -\&\fBDSA_new()\fR, \fBDSA_free()\fR, \fBDSA_up_ref()\fR -.Sp -See \*(L"Deprecated low-level object creation\*(R" -.IP "\(bu" 4 -\&\fBDSAparams_dup()\fR -.Sp -There is no direct replacement. Applications may use \fBEVP_PKEY_copy_parameters\fR\|(3) -and \fBEVP_PKEY_dup\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBDSAparams_print()\fR, \fBDSAparams_print_fp()\fR, \fBDSA_print()\fR, \fBDSA_print_fp()\fR -.Sp -See \*(L"Deprecated low-level key printing functions\*(R" -.IP "\(bu" 4 -\&\fBDSA_set0_key()\fR, \fBDSA_set0_pqg()\fR -.Sp -See \*(L"Deprecated low-level key parameter setters\*(R" -.IP "\(bu" 4 -\&\fBDSA_set_flags()\fR, \fBDSA_clear_flags()\fR, \fBDSA_test_flags()\fR -.Sp -The \fB\s-1DSA_FLAG_CACHE_MONT_P\s0\fR flag has been deprecated without replacement. -.IP "\(bu" 4 -\&\fBDSA_sign()\fR, \fBDSA_do_sign()\fR, \fBDSA_sign_setup()\fR, \fBDSA_verify()\fR, \fBDSA_do_verify()\fR -.Sp -See \*(L"Deprecated low-level signing functions\*(R". -.IP "\(bu" 4 -\&\fBECDH_compute_key()\fR -.Sp -See \*(L"Deprecated low-level key exchange functions\*(R". -.IP "\(bu" 4 -\&\s-1\fBECDH_KDF_X9_62\s0()\fR -.Sp -Applications may either set this using the helper function -\&\fBEVP_PKEY_CTX_set_ecdh_kdf_type\fR\|(3) or by setting an \s-1\fBOSSL_PARAM\s0\fR\|(3) using the -\&\*(L"kdf-type\*(R" as shown in \*(L"\s-1EXAMPLES\*(R"\s0 in \s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7) -.IP "\(bu" 4 -\&\fBECDSA_sign()\fR, \fBECDSA_sign_ex()\fR, \fBECDSA_sign_setup()\fR, \fBECDSA_do_sign()\fR, -\&\fBECDSA_do_sign_ex()\fR, \fBECDSA_verify()\fR, \fBECDSA_do_verify()\fR -.Sp -See \*(L"Deprecated low-level signing functions\*(R". -.IP "\(bu" 4 -\&\fBECDSA_size()\fR -.Sp -Applications should use \fBEVP_PKEY_get_size\fR\|(3). -.IP "\(bu" 4 -\&\fBEC_GF2m_simple_method()\fR, \fBEC_GFp_mont_method()\fR, \fBEC_GFp_nist_method()\fR, -\&\fBEC_GFp_nistp224_method()\fR, \fBEC_GFp_nistp256_method()\fR, \fBEC_GFp_nistp521_method()\fR, -\&\fBEC_GFp_simple_method()\fR -.Sp -There are no replacements for these functions. Applications should rely on the -library automatically assigning a suitable method internally when an \s-1EC_GROUP\s0 -is constructed. -.IP "\(bu" 4 -\&\fBEC_GROUP_clear_free()\fR -.Sp -Use \fBEC_GROUP_free\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBEC_GROUP_get_curve_GF2m()\fR, \fBEC_GROUP_get_curve_GFp()\fR, \fBEC_GROUP_set_curve_GF2m()\fR, -\&\fBEC_GROUP_set_curve_GFp()\fR -.Sp -Applications should use \fBEC_GROUP_get_curve\fR\|(3) and \fBEC_GROUP_set_curve\fR\|(3). -.IP "\(bu" 4 -\&\fBEC_GROUP_have_precompute_mult()\fR, \fBEC_GROUP_precompute_mult()\fR, -\&\fBEC_KEY_precompute_mult()\fR -.Sp -These functions are not widely used. Applications should instead switch to -named curves which OpenSSL has hardcoded lookup tables for. -.IP "\(bu" 4 -\&\fBEC_GROUP_new()\fR, \fBEC_GROUP_method_of()\fR, \fBEC_POINT_method_of()\fR -.Sp -\&\s-1EC_METHOD\s0 is now an internal-only concept and a suitable \s-1EC_METHOD\s0 is assigned -internally without application intervention. -Users of \fBEC_GROUP_new()\fR should switch to a different suitable constructor. -.IP "\(bu" 4 -\&\fBEC_KEY_can_sign()\fR -.Sp -Applications should use \fBEVP_PKEY_can_sign\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBEC_KEY_check_key()\fR -.Sp -See \*(L"Deprecated low-level validation functions\*(R" -.IP "\(bu" 4 -\&\fBEC_KEY_set_flags()\fR, \fBEC_KEY_get_flags()\fR, \fBEC_KEY_clear_flags()\fR -.Sp -See \*(L"Common \s-1EC\s0 parameters\*(R" in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) which handles flags as separate -parameters for \fB\s-1OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT\s0\fR, -\&\fB\s-1OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE\s0\fR, \fB\s-1OSSL_PKEY_PARAM_EC_ENCODING\s0\fR, -\&\fB\s-1OSSL_PKEY_PARAM_USE_COFACTOR_ECDH\s0\fR and -\&\fB\s-1OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC\s0\fR. -See also \*(L"\s-1EXAMPLES\*(R"\s0 in \s-1\fBEVP_PKEY\-EC\s0\fR\|(7) -.IP "\(bu" 4 -\&\fBEC_KEY_dup()\fR, \fBEC_KEY_copy()\fR -.Sp -There is no direct replacement. Applications may use \fBEVP_PKEY_copy_parameters\fR\|(3) -and \fBEVP_PKEY_dup\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBEC_KEY_decoded_from_explicit_params()\fR -.Sp -There is no replacement. -.IP "\(bu" 4 -\&\fBEC_KEY_generate_key()\fR -.Sp -See \*(L"Deprecated low-level key generation functions\*(R". -.IP "\(bu" 4 -\&\fBEC_KEY_get0_group()\fR, \fBEC_KEY_get0_private_key()\fR, \fBEC_KEY_get0_public_key()\fR, -\&\fBEC_KEY_get_conv_form()\fR, \fBEC_KEY_get_enc_flags()\fR -.Sp -See \*(L"Deprecated low-level key parameter getters\*(R". -.IP "\(bu" 4 -\&\fBEC_KEY_get0_engine()\fR, \fBEC_KEY_get_default_method()\fR, \fBEC_KEY_get_method()\fR, -\&\fBEC_KEY_new_method()\fR, \fBEC_KEY_get_ex_data()\fR, \fBEC_KEY_OpenSSL()\fR, -\&\fBEC_KEY_set_ex_data()\fR, \fBEC_KEY_set_default_method()\fR, EC_KEY_METHOD_*(), -\&\fBEC_KEY_set_method()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R" -.IP "\(bu" 4 -\&\fBEC_METHOD_get_field_type()\fR -.Sp -Use \fBEC_GROUP_get_field_type\fR\|(3) instead. -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R" -.IP "\(bu" 4 -\&\fBEC_KEY_key2buf()\fR, \fBEC_KEY_oct2key()\fR, \fBEC_KEY_oct2priv()\fR, \fBEC_KEY_priv2buf()\fR, -\&\fBEC_KEY_priv2oct()\fR -.Sp -There are no replacements for these. -.IP "\(bu" 4 -\&\fBEC_KEY_new()\fR, \fBEC_KEY_new_by_curve_name()\fR, \fBEC_KEY_free()\fR, \fBEC_KEY_up_ref()\fR -.Sp -See \*(L"Deprecated low-level object creation\*(R" -.IP "\(bu" 4 -\&\fBEC_KEY_print()\fR, \fBEC_KEY_print_fp()\fR -.Sp -See \*(L"Deprecated low-level key printing functions\*(R" -.IP "\(bu" 4 -\&\fBEC_KEY_set_asn1_flag()\fR, \fBEC_KEY_set_conv_form()\fR, \fBEC_KEY_set_enc_flags()\fR -.Sp -See \*(L"Deprecated low-level key parameter setters\*(R". -.IP "\(bu" 4 -\&\fBEC_KEY_set_group()\fR, \fBEC_KEY_set_private_key()\fR, \fBEC_KEY_set_public_key()\fR, -\&\fBEC_KEY_set_public_key_affine_coordinates()\fR -.Sp -See \*(L"Deprecated low-level key parameter setters\*(R". -.IP "\(bu" 4 -\&\fBECParameters_print()\fR, \fBECParameters_print_fp()\fR, \fBECPKParameters_print()\fR, -\&\fBECPKParameters_print_fp()\fR -.Sp -See \*(L"Deprecated low-level key printing functions\*(R" -.IP "\(bu" 4 -\&\fBEC_POINT_bn2point()\fR, \fBEC_POINT_point2bn()\fR -.Sp -These functions were not particularly useful, since \s-1EC\s0 point serialization -formats are not individual big-endian integers. -.IP "\(bu" 4 -\&\fBEC_POINT_get_affine_coordinates_GF2m()\fR, \fBEC_POINT_get_affine_coordinates_GFp()\fR, -\&\fBEC_POINT_set_affine_coordinates_GF2m()\fR, \fBEC_POINT_set_affine_coordinates_GFp()\fR -.Sp -Applications should use \fBEC_POINT_get_affine_coordinates\fR\|(3) and -\&\fBEC_POINT_set_affine_coordinates\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBEC_POINT_get_Jprojective_coordinates_GFp()\fR, \fBEC_POINT_set_Jprojective_coordinates_GFp()\fR -.Sp -These functions are not widely used. Applications should instead use the -\&\fBEC_POINT_set_affine_coordinates\fR\|(3) and \fBEC_POINT_get_affine_coordinates\fR\|(3) -functions. -.IP "\(bu" 4 -\&\fBEC_POINT_make_affine()\fR, \fBEC_POINTs_make_affine()\fR -.Sp -There is no replacement. These functions were not widely used, and OpenSSL -automatically performs this conversion when needed. -.IP "\(bu" 4 -\&\fBEC_POINT_set_compressed_coordinates_GF2m()\fR, \fBEC_POINT_set_compressed_coordinates_GFp()\fR -.Sp -Applications should use \fBEC_POINT_set_compressed_coordinates\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBEC_POINTs_mul()\fR -.Sp -This function is not widely used. Applications should instead use the -\&\fBEC_POINT_mul\fR\|(3) function. -.IP "\(bu" 4 -\&\fBENGINE_*()\fR -.Sp -All engine functions are deprecated. An engine should be rewritten as a provider. -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R". -.IP "\(bu" 4 -\&\fBERR_load_*()\fR, \fBERR_func_error_string()\fR, \fBERR_get_error_line()\fR, -\&\fBERR_get_error_line_data()\fR, \fBERR_get_state()\fR -.Sp -OpenSSL now loads error strings automatically so these functions are not needed. -.IP "\(bu" 4 -\&\fBERR_peek_error_line_data()\fR, \fBERR_peek_last_error_line_data()\fR -.Sp -The new functions are \fBERR_peek_error_func\fR\|(3), \fBERR_peek_last_error_func\fR\|(3), -\&\fBERR_peek_error_data\fR\|(3), \fBERR_peek_last_error_data\fR\|(3), \fBERR_get_error_all\fR\|(3), -\&\fBERR_peek_error_all\fR\|(3) and \fBERR_peek_last_error_all\fR\|(3). -Applications should use \fBERR_get_error_all\fR\|(3), or pick information -with ERR_peek functions and finish off with getting the error code by using -\&\fBERR_get_error\fR\|(3). -.IP "\(bu" 4 -\&\fBEVP_CIPHER_CTX_iv()\fR, \fBEVP_CIPHER_CTX_iv_noconst()\fR, \fBEVP_CIPHER_CTX_original_iv()\fR -.Sp -Applications should instead use \fBEVP_CIPHER_CTX_get_updated_iv\fR\|(3), -\&\fBEVP_CIPHER_CTX_get_updated_iv\fR\|(3) and \fBEVP_CIPHER_CTX_get_original_iv\fR\|(3) -respectively. -See \fBEVP_CIPHER_CTX_get_original_iv\fR\|(3) for further information. -.IP "\(bu" 4 -\&\fBEVP_CIPHER_meth_*()\fR, \fBEVP_MD_CTX_set_update_fn()\fR, \fBEVP_MD_CTX_update_fn()\fR, -\&\fBEVP_MD_meth_*()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R". -.IP "\(bu" 4 -\&\s-1\fBEVP_PKEY_CTRL_PKCS7_ENCRYPT\s0()\fR, \s-1\fBEVP_PKEY_CTRL_PKCS7_DECRYPT\s0()\fR, -\&\s-1\fBEVP_PKEY_CTRL_PKCS7_SIGN\s0()\fR, \s-1\fBEVP_PKEY_CTRL_CMS_ENCRYPT\s0()\fR, -\&\s-1\fBEVP_PKEY_CTRL_CMS_DECRYPT\s0()\fR, and \s-1\fBEVP_PKEY_CTRL_CMS_SIGN\s0()\fR -.Sp -These control operations are not invoked by the OpenSSL library anymore and -are replaced by direct checks of the key operation against the key type -when the operation is initialized. -.IP "\(bu" 4 -\&\fBEVP_PKEY_CTX_get0_dh_kdf_ukm()\fR, \fBEVP_PKEY_CTX_get0_ecdh_kdf_ukm()\fR -.Sp -See the \*(L"kdf-ukm\*(R" item in \*(L"\s-1DH\s0 key exchange parameters\*(R" in \s-1\fBEVP_KEYEXCH\-DH\s0\fR\|(7) and -\&\*(L"\s-1ECDH\s0 Key Exchange parameters\*(R" in \s-1\fBEVP_KEYEXCH\-ECDH\s0\fR\|(7). -These functions are obsolete and should not be required. -.IP "\(bu" 4 -\&\fBEVP_PKEY_CTX_set_rsa_keygen_pubexp()\fR -.Sp -Applications should use \fBEVP_PKEY_CTX_set1_rsa_keygen_pubexp\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBEVP_PKEY_cmp()\fR, \fBEVP_PKEY_cmp_parameters()\fR -.Sp -Applications should use \fBEVP_PKEY_eq\fR\|(3) and \fBEVP_PKEY_parameters_eq\fR\|(3) instead. -See \fBEVP_PKEY_copy_parameters\fR\|(3) for further details. -.IP "\(bu" 4 -\&\fBEVP_PKEY_encrypt_old()\fR, \fBEVP_PKEY_decrypt_old()\fR, -.Sp -Applications should use \fBEVP_PKEY_encrypt_init\fR\|(3) and \fBEVP_PKEY_encrypt\fR\|(3) or -\&\fBEVP_PKEY_decrypt_init\fR\|(3) and \fBEVP_PKEY_decrypt\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBEVP_PKEY_get0()\fR -.Sp -This function returns \s-1NULL\s0 if the key comes from a provider. -.IP "\(bu" 4 -\&\fBEVP_PKEY_get0_DH()\fR, \fBEVP_PKEY_get0_DSA()\fR, \fBEVP_PKEY_get0_EC_KEY()\fR, \fBEVP_PKEY_get0_RSA()\fR, -\&\fBEVP_PKEY_get1_DH()\fR, \fBEVP_PKEY_get1_DSA()\fR, EVP_PKEY_get1_EC_KEY and \fBEVP_PKEY_get1_RSA()\fR, -\&\fBEVP_PKEY_get0_hmac()\fR, \fBEVP_PKEY_get0_poly1305()\fR, \fBEVP_PKEY_get0_siphash()\fR -.Sp -See \*(L"Functions that return an internal key should be treated as read only\*(R". -.IP "\(bu" 4 -\&\fBEVP_PKEY_meth_*()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R". -.IP "\(bu" 4 -\&\fBEVP_PKEY_new_CMAC_key()\fR -.Sp -See \*(L"Deprecated low-level \s-1MAC\s0 functions\*(R". -.IP "\(bu" 4 -\&\fBEVP_PKEY_assign()\fR, \fBEVP_PKEY_set1_DH()\fR, \fBEVP_PKEY_set1_DSA()\fR, -\&\fBEVP_PKEY_set1_EC_KEY()\fR, \fBEVP_PKEY_set1_RSA()\fR -.Sp -See \*(L"Deprecated low-level key object getters and setters\*(R" -.IP "\(bu" 4 -\&\fBEVP_PKEY_set1_tls_encodedpoint()\fR \fBEVP_PKEY_get1_tls_encodedpoint()\fR -.Sp -These functions were previously used by libssl to set or get an encoded public -key into/from an \s-1EVP_PKEY\s0 object. With OpenSSL 3.0 these are replaced by the more -generic functions \fBEVP_PKEY_set1_encoded_public_key\fR\|(3) and -\&\fBEVP_PKEY_get1_encoded_public_key\fR\|(3). -The old versions have been converted to deprecated macros that just call the -new functions. -.IP "\(bu" 4 -\&\fBEVP_PKEY_set1_engine()\fR, \fBEVP_PKEY_get0_engine()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R". -.IP "\(bu" 4 -\&\fBEVP_PKEY_set_alias_type()\fR -.Sp -This function has been removed. There is no replacement. -See \*(L"\fBEVP_PKEY_set_alias_type()\fR method has been removed\*(R" -.IP "\(bu" 4 -\&\fBHMAC_Init_ex()\fR, \fBHMAC_Update()\fR, \fBHMAC_Final()\fR, \fBHMAC_size()\fR -.Sp -See \*(L"Deprecated low-level \s-1MAC\s0 functions\*(R". -.IP "\(bu" 4 -\&\fBHMAC_CTX_new()\fR, \fBHMAC_CTX_free()\fR, \fBHMAC_CTX_copy()\fR, \fBHMAC_CTX_reset()\fR, -\&\fBHMAC_CTX_set_flags()\fR, \fBHMAC_CTX_get_md()\fR -.Sp -See \*(L"Deprecated low-level \s-1MAC\s0 functions\*(R". -.IP "\(bu" 4 -\&\fBi2d_DHparams()\fR, \fBi2d_DHxparams()\fR -.Sp -See \*(L"Deprecated low-level key reading and writing functions\*(R" -and \*(L"Migration\*(R" in \fBd2i_RSAPrivateKey\fR\|(3) -.IP "\(bu" 4 -\&\fBi2d_DSAparams()\fR, \fBi2d_DSAPrivateKey()\fR, \fBi2d_DSAPrivateKey_bio()\fR, -\&\fBi2d_DSAPrivateKey_fp()\fR, \fBi2d_DSA_PUBKEY()\fR, \fBi2d_DSA_PUBKEY_bio()\fR, -\&\fBi2d_DSA_PUBKEY_fp()\fR, \fBi2d_DSAPublicKey()\fR -.Sp -See \*(L"Deprecated low-level key reading and writing functions\*(R" -and \*(L"Migration\*(R" in \fBd2i_RSAPrivateKey\fR\|(3) -.IP "\(bu" 4 -\&\fBi2d_ECParameters()\fR, \fBi2d_ECPrivateKey()\fR, \fBi2d_ECPrivateKey_bio()\fR, -\&\fBi2d_ECPrivateKey_fp()\fR, \fBi2d_EC_PUBKEY()\fR, \fBi2d_EC_PUBKEY_bio()\fR, -\&\fBi2d_EC_PUBKEY_fp()\fR -.Sp -See \*(L"Deprecated low-level key reading and writing functions\*(R" -and \*(L"Migration\*(R" in \fBd2i_RSAPrivateKey\fR\|(3) -.IP "\(bu" 4 -\&\fBi2o_ECPublicKey()\fR -.Sp -Use \fBEVP_PKEY_get1_encoded_public_key\fR\|(3). -See \*(L"Deprecated low-level key parameter getters\*(R" -.IP "\(bu" 4 -\&\fBi2d_RSAPrivateKey()\fR, \fBi2d_RSAPrivateKey_bio()\fR, \fBi2d_RSAPrivateKey_fp()\fR, -\&\fBi2d_RSA_PUBKEY()\fR, \fBi2d_RSA_PUBKEY_bio()\fR, \fBi2d_RSA_PUBKEY_fp()\fR, -\&\fBi2d_RSAPublicKey()\fR, \fBi2d_RSAPublicKey_bio()\fR, \fBi2d_RSAPublicKey_fp()\fR -.Sp -See \*(L"Deprecated low-level key reading and writing functions\*(R" -and \*(L"Migration\*(R" in \fBd2i_RSAPrivateKey\fR\|(3) -.IP "\(bu" 4 -\&\fBIDEA_encrypt()\fR, \fBIDEA_set_decrypt_key()\fR, \fBIDEA_set_encrypt_key()\fR, -\&\fBIDEA_cbc_encrypt()\fR, \fBIDEA_cfb64_encrypt()\fR, \fBIDEA_ecb_encrypt()\fR, -\&\fBIDEA_ofb64_encrypt()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -\&\s-1IDEA\s0 has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBIDEA_options()\fR -.Sp -There is no replacement. This function returned a constant string. -.IP "\(bu" 4 -\&\s-1\fBMD2\s0()\fR, \fBMD2_Init()\fR, \fBMD2_Update()\fR, \fBMD2_Final()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -\&\s-1MD2\s0 has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBMD2_options()\fR -.Sp -There is no replacement. This function returned a constant string. -.IP "\(bu" 4 -\&\s-1\fBMD4\s0()\fR, \fBMD4_Init()\fR, \fBMD4_Update()\fR, \fBMD4_Final()\fR, \fBMD4_Transform()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -\&\s-1MD4\s0 has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\s-1\fBMDC2\s0()\fR, \fBMDC2_Init()\fR, \fBMDC2_Update()\fR, \fBMDC2_Final()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -\&\s-1MDC2\s0 has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\s-1\fBMD5\s0()\fR, \fBMD5_Init()\fR, \fBMD5_Update()\fR, \fBMD5_Final()\fR, \fBMD5_Transform()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -.IP "\(bu" 4 -\&\s-1\fBNCONF_WIN32\s0()\fR -.Sp -This undocumented function has no replacement. -See \*(L"\s-1HISTORY\*(R"\s0 in \fBconfig\fR\|(5) for more details. -.IP "\(bu" 4 -\&\fBOCSP_parse_url()\fR -.Sp -Use \fBOSSL_HTTP_parse_url\fR\|(3) instead. -.IP "\(bu" 4 -\&\fB\s-1OCSP_REQ_CTX\s0\fR type and \fBOCSP_REQ_CTX_*()\fR functions -.Sp -These methods were used to collect all necessary data to form a \s-1HTTP\s0 request, -and to perform the \s-1HTTP\s0 transfer with that request. With OpenSSL 3.0, the -type is \fB\s-1OSSL_HTTP_REQ_CTX\s0\fR, and the deprecated functions are replaced -with \fBOSSL_HTTP_REQ_CTX_*()\fR. See \s-1\fBOSSL_HTTP_REQ_CTX\s0\fR\|(3) for additional -details. -.IP "\(bu" 4 -\&\fBOPENSSL_fork_child()\fR, \fBOPENSSL_fork_parent()\fR, \fBOPENSSL_fork_prepare()\fR -.Sp -There is no replacement for these functions. These pthread fork support methods -were unused by OpenSSL. -.IP "\(bu" 4 -\&\fBOSSL_STORE_ctrl()\fR, \fBOSSL_STORE_do_all_loaders()\fR, \fBOSSL_STORE_LOADER_get0_engine()\fR, -\&\fBOSSL_STORE_LOADER_get0_scheme()\fR, \fBOSSL_STORE_LOADER_new()\fR, -\&\fBOSSL_STORE_LOADER_set_attach()\fR, \fBOSSL_STORE_LOADER_set_close()\fR, -\&\fBOSSL_STORE_LOADER_set_ctrl()\fR, \fBOSSL_STORE_LOADER_set_eof()\fR, -\&\fBOSSL_STORE_LOADER_set_error()\fR, \fBOSSL_STORE_LOADER_set_expect()\fR, -\&\fBOSSL_STORE_LOADER_set_find()\fR, \fBOSSL_STORE_LOADER_set_load()\fR, -\&\fBOSSL_STORE_LOADER_set_open()\fR, \fBOSSL_STORE_LOADER_set_open_ex()\fR, -\&\fBOSSL_STORE_register_loader()\fR, \fBOSSL_STORE_unregister_loader()\fR, -\&\fBOSSL_STORE_vctrl()\fR -.Sp -These functions helped applications and engines create loaders for -schemes they supported. These are all deprecated and discouraged in favour of -provider implementations, see \fBprovider\-storemgmt\fR\|(7). -.IP "\(bu" 4 -\&\fBPEM_read_DHparams()\fR, \fBPEM_read_bio_DHparams()\fR, -\&\fBPEM_read_DSAparams()\fR, \fBPEM_read_bio_DSAparams()\fR, -\&\fBPEM_read_DSAPrivateKey()\fR, \fBPEM_read_DSA_PUBKEY()\fR, -PEM_read_bio_DSAPrivateKey and \fBPEM_read_bio_DSA_PUBKEY()\fR, -\&\fBPEM_read_ECPKParameters()\fR, \fBPEM_read_ECPrivateKey()\fR, \fBPEM_read_EC_PUBKEY()\fR, -\&\fBPEM_read_bio_ECPKParameters()\fR, \fBPEM_read_bio_ECPrivateKey()\fR, \fBPEM_read_bio_EC_PUBKEY()\fR, -\&\fBPEM_read_RSAPrivateKey()\fR, \fBPEM_read_RSA_PUBKEY()\fR, \fBPEM_read_RSAPublicKey()\fR, -\&\fBPEM_read_bio_RSAPrivateKey()\fR, \fBPEM_read_bio_RSA_PUBKEY()\fR, \fBPEM_read_bio_RSAPublicKey()\fR, -\&\fBPEM_write_bio_DHparams()\fR, \fBPEM_write_bio_DHxparams()\fR, \fBPEM_write_DHparams()\fR, \fBPEM_write_DHxparams()\fR, -\&\fBPEM_write_DSAparams()\fR, \fBPEM_write_DSAPrivateKey()\fR, \fBPEM_write_DSA_PUBKEY()\fR, -\&\fBPEM_write_bio_DSAparams()\fR, \fBPEM_write_bio_DSAPrivateKey()\fR, \fBPEM_write_bio_DSA_PUBKEY()\fR, -\&\fBPEM_write_ECPKParameters()\fR, \fBPEM_write_ECPrivateKey()\fR, \fBPEM_write_EC_PUBKEY()\fR, -\&\fBPEM_write_bio_ECPKParameters()\fR, \fBPEM_write_bio_ECPrivateKey()\fR, \fBPEM_write_bio_EC_PUBKEY()\fR, -\&\fBPEM_write_RSAPrivateKey()\fR, \fBPEM_write_RSA_PUBKEY()\fR, \fBPEM_write_RSAPublicKey()\fR, -\&\fBPEM_write_bio_RSAPrivateKey()\fR, \fBPEM_write_bio_RSA_PUBKEY()\fR, -\&\fBPEM_write_bio_RSAPublicKey()\fR, -.Sp -See \*(L"Deprecated low-level key reading and writing functions\*(R" -.IP "\(bu" 4 -\&\s-1\fBPKCS1_MGF1\s0()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -.IP "\(bu" 4 -\&\fBRAND_get_rand_method()\fR, \fBRAND_set_rand_method()\fR, \fBRAND_OpenSSL()\fR, -\&\fBRAND_set_rand_engine()\fR -.Sp -Applications should instead use \fBRAND_set_DRBG_type\fR\|(3), -\&\s-1\fBEVP_RAND\s0\fR\|(3) and \s-1\fBEVP_RAND\s0\fR\|(7). -See \fBRAND_set_rand_method\fR\|(3) for more details. -.IP "\(bu" 4 -\&\fBRC2_encrypt()\fR, \fBRC2_decrypt()\fR, \fBRC2_set_key()\fR, \fBRC2_cbc_encrypt()\fR, \fBRC2_cfb64_encrypt()\fR, -\&\fBRC2_ecb_encrypt()\fR, \fBRC2_ofb64_encrypt()\fR, -\&\s-1\fBRC4\s0()\fR, \fBRC4_set_key()\fR, \fBRC4_options()\fR, -\&\fBRC5_32_encrypt()\fR, \fBRC5_32_set_key()\fR, \fBRC5_32_decrypt()\fR, \fBRC5_32_cbc_encrypt()\fR, -\&\fBRC5_32_cfb64_encrypt()\fR, \fBRC5_32_ecb_encrypt()\fR, \fBRC5_32_ofb64_encrypt()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -The Algorithms \*(L"\s-1RC2\*(R", \*(L"RC4\*(R"\s0 and \*(L"\s-1RC5\*(R"\s0 have been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\s-1\fBRIPEMD160\s0()\fR, \fBRIPEMD160_Init()\fR, \fBRIPEMD160_Update()\fR, \fBRIPEMD160_Final()\fR, -\&\fBRIPEMD160_Transform()\fR -.Sp -See \*(L"Deprecated low-level digest functions\*(R". -The \s-1RIPE\s0 algorithm has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBRSA_bits()\fR, \fBRSA_security_bits()\fR, \fBRSA_size()\fR -.Sp -Use \fBEVP_PKEY_get_bits\fR\|(3), \fBEVP_PKEY_get_security_bits\fR\|(3) and -\&\fBEVP_PKEY_get_size\fR\|(3). -.IP "\(bu" 4 -\&\fBRSA_check_key()\fR, \fBRSA_check_key_ex()\fR -.Sp -See \*(L"Deprecated low-level validation functions\*(R" -.IP "\(bu" 4 -\&\fBRSA_clear_flags()\fR, \fBRSA_flags()\fR, \fBRSA_set_flags()\fR, \fBRSA_test_flags()\fR, -\&\fBRSA_setup_blinding()\fR, \fBRSA_blinding_off()\fR, \fBRSA_blinding_on()\fR -.Sp -All of these \s-1RSA\s0 flags have been deprecated without replacement: -.Sp -\&\fB\s-1RSA_FLAG_BLINDING\s0\fR, \fB\s-1RSA_FLAG_CACHE_PRIVATE\s0\fR, \fB\s-1RSA_FLAG_CACHE_PUBLIC\s0\fR, -\&\fB\s-1RSA_FLAG_EXT_PKEY\s0\fR, \fB\s-1RSA_FLAG_NO_BLINDING\s0\fR, \fB\s-1RSA_FLAG_THREAD_SAFE\s0\fR -\&\fB\s-1RSA_METHOD_FLAG_NO_CHECK\s0\fR -.IP "\(bu" 4 -\&\fBRSA_generate_key_ex()\fR, \fBRSA_generate_multi_prime_key()\fR -.Sp -See \*(L"Deprecated low-level key generation functions\*(R". -.IP "\(bu" 4 -\&\fBRSA_get0_engine()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R" -.IP "\(bu" 4 -\&\fBRSA_get0_crt_params()\fR, \fBRSA_get0_d()\fR, \fBRSA_get0_dmp1()\fR, \fBRSA_get0_dmq1()\fR, -\&\fBRSA_get0_e()\fR, \fBRSA_get0_factors()\fR, \fBRSA_get0_iqmp()\fR, \fBRSA_get0_key()\fR, -\&\fBRSA_get0_multi_prime_crt_params()\fR, \fBRSA_get0_multi_prime_factors()\fR, \fBRSA_get0_n()\fR, -\&\fBRSA_get0_p()\fR, \fBRSA_get0_pss_params()\fR, \fBRSA_get0_q()\fR, -\&\fBRSA_get_multi_prime_extra_count()\fR -.Sp -See \*(L"Deprecated low-level key parameter getters\*(R" -.IP "\(bu" 4 -\&\fBRSA_new()\fR, \fBRSA_free()\fR, \fBRSA_up_ref()\fR -.Sp -See \*(L"Deprecated low-level object creation\*(R". -.IP "\(bu" 4 -\&\fBRSA_get_default_method()\fR, RSA_get_ex_data and \fBRSA_get_method()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R". -.IP "\(bu" 4 -\&\fBRSA_get_version()\fR -.Sp -There is no replacement. -.IP "\(bu" 4 -\&\fBRSA_meth_*()\fR, \fBRSA_new_method()\fR, RSA_null_method and \fBRSA_PKCS1_OpenSSL()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R". -.IP "\(bu" 4 -\&\fBRSA_padding_add_*()\fR, \fBRSA_padding_check_*()\fR -.Sp -See \*(L"Deprecated low-level signing functions\*(R" and -\&\*(L"Deprecated low-level encryption functions\*(R". -.IP "\(bu" 4 -\&\fBRSA_print()\fR, \fBRSA_print_fp()\fR -.Sp -See \*(L"Deprecated low-level key printing functions\*(R" -.IP "\(bu" 4 -\&\fBRSA_public_encrypt()\fR, \fBRSA_private_decrypt()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R" -.IP "\(bu" 4 -\&\fBRSA_private_encrypt()\fR, \fBRSA_public_decrypt()\fR -.Sp -This is equivalent to doing sign and verify recover operations (with a padding -mode of none). See \*(L"Deprecated low-level signing functions\*(R". -.IP "\(bu" 4 -\&\fBRSAPrivateKey_dup()\fR, \fBRSAPublicKey_dup()\fR -.Sp -There is no direct replacement. Applications may use \fBEVP_PKEY_dup\fR\|(3). -.IP "\(bu" 4 -\&\fBRSAPublicKey_it()\fR, \fBRSAPrivateKey_it()\fR -.Sp -See \*(L"Deprecated low-level key reading and writing functions\*(R" -.IP "\(bu" 4 -\&\fBRSA_set0_crt_params()\fR, \fBRSA_set0_factors()\fR, \fBRSA_set0_key()\fR, -\&\fBRSA_set0_multi_prime_params()\fR -.Sp -See \*(L"Deprecated low-level key parameter setters\*(R". -.IP "\(bu" 4 -\&\fBRSA_set_default_method()\fR, \fBRSA_set_method()\fR, \fBRSA_set_ex_data()\fR -.Sp -See \*(L"Providers are a replacement for engines and low-level method overrides\*(R" -.IP "\(bu" 4 -\&\fBRSA_sign()\fR, \fBRSA_sign_ASN1_OCTET_STRING()\fR, \fBRSA_verify()\fR, -\&\fBRSA_verify_ASN1_OCTET_STRING()\fR, \fBRSA_verify_PKCS1_PSS()\fR, -\&\fBRSA_verify_PKCS1_PSS_mgf1()\fR -.Sp -See \*(L"Deprecated low-level signing functions\*(R". -.IP "\(bu" 4 -\&\fBRSA_X931_derive_ex()\fR, \fBRSA_X931_generate_key_ex()\fR, \fBRSA_X931_hash_id()\fR -.Sp -There are no replacements for these functions. -X931 padding can be set using \*(L"Signature Parameters\*(R" in \s-1\fBEVP_SIGNATURE\-RSA\s0\fR\|(7). -See \fB\s-1OSSL_SIGNATURE_PARAM_PAD_MODE\s0\fR. -.IP "\(bu" 4 -\&\fBSEED_encrypt()\fR, \fBSEED_decrypt()\fR, \fBSEED_set_key()\fR, \fBSEED_cbc_encrypt()\fR, -\&\fBSEED_cfb128_encrypt()\fR, \fBSEED_ecb_encrypt()\fR, \fBSEED_ofb128_encrypt()\fR -.Sp -See \*(L"Deprecated low-level encryption functions\*(R". -The \s-1SEED\s0 algorithm has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBSHA1_Init()\fR, \fBSHA1_Update()\fR, \fBSHA1_Final()\fR, \fBSHA1_Transform()\fR, -\&\fBSHA224_Init()\fR, \fBSHA224_Update()\fR, \fBSHA224_Final()\fR, -\&\fBSHA256_Init()\fR, \fBSHA256_Update()\fR, \fBSHA256_Final()\fR, \fBSHA256_Transform()\fR, -\&\fBSHA384_Init()\fR, \fBSHA384_Update()\fR, \fBSHA384_Final()\fR, -\&\fBSHA512_Init()\fR, \fBSHA512_Update()\fR, \fBSHA512_Final()\fR, \fBSHA512_Transform()\fR -.Sp -See \*(L"Deprecated low-level digest functions\*(R". -.IP "\(bu" 4 -\&\fBSRP_Calc_A()\fR, \fBSRP_Calc_B()\fR, \fBSRP_Calc_client_key()\fR, \fBSRP_Calc_server_key()\fR, -\&\fBSRP_Calc_u()\fR, \fBSRP_Calc_x()\fR, \fBSRP_check_known_gN_param()\fR, \fBSRP_create_verifier()\fR, -\&\fBSRP_create_verifier_BN()\fR, \fBSRP_get_default_gN()\fR, \fBSRP_user_pwd_free()\fR, \fBSRP_user_pwd_new()\fR, -\&\fBSRP_user_pwd_set0_sv()\fR, \fBSRP_user_pwd_set1_ids()\fR, \fBSRP_user_pwd_set_gN()\fR, -\&\fBSRP_VBASE_add0_user()\fR, \fBSRP_VBASE_free()\fR, \fBSRP_VBASE_get1_by_user()\fR, \fBSRP_VBASE_init()\fR, -\&\fBSRP_VBASE_new()\fR, \fBSRP_Verify_A_mod_N()\fR, \fBSRP_Verify_B_mod_N()\fR -.Sp -There are no replacements for the \s-1SRP\s0 functions. -.IP "\(bu" 4 -\&\fBSSL_CTX_set_tmp_dh_callback()\fR, \fBSSL_set_tmp_dh_callback()\fR, -\&\fBSSL_CTX_set_tmp_dh()\fR, \fBSSL_set_tmp_dh()\fR -.Sp -These are used to set the Diffie-Hellman (\s-1DH\s0) parameters that are to be used by -servers requiring ephemeral \s-1DH\s0 keys. Instead applications should consider using -the built-in \s-1DH\s0 parameters that are available by calling \fBSSL_CTX_set_dh_auto\fR\|(3) -or \fBSSL_set_dh_auto\fR\|(3). If custom parameters are necessary then applications can -use the alternative functions \fBSSL_CTX_set0_tmp_dh_pkey\fR\|(3) and -\&\fBSSL_set0_tmp_dh_pkey\fR\|(3). There is no direct replacement for the \*(L"callback\*(R" -functions. The callback was originally useful in order to have different -parameters for export and non-export ciphersuites. Export ciphersuites are no -longer supported by OpenSSL. Use of the callback functions should be replaced -by one of the other methods described above. -.IP "\(bu" 4 -\&\fBSSL_CTX_set_tlsext_ticket_key_cb()\fR -.Sp -Use the new \fBSSL_CTX_set_tlsext_ticket_key_evp_cb\fR\|(3) function instead. -.IP "\(bu" 4 -\&\s-1\fBWHIRLPOOL\s0()\fR, \fBWHIRLPOOL_Init()\fR, \fBWHIRLPOOL_Update()\fR, \fBWHIRLPOOL_Final()\fR, -\&\fBWHIRLPOOL_BitUpdate()\fR -.Sp -See \*(L"Deprecated low-level digest functions\*(R". -The Whirlpool algorithm has been moved to the Legacy Provider. -.IP "\(bu" 4 -\&\fBX509_certificate_type()\fR -.Sp -This was an undocumented function. Applications can use \fBX509_get0_pubkey\fR\|(3) -and \fBX509_get0_signature\fR\|(3) instead. -.IP "\(bu" 4 -\&\fBX509_http_nbio()\fR, \fBX509_CRL_http_nbio()\fR -.Sp -Use \fBX509_load_http\fR\|(3) and \fBX509_CRL_load_http\fR\|(3) instead. -.PP -\fI\s-1NID\s0 handling for provided keys and algorithms\fR -.IX Subsection "NID handling for provided keys and algorithms" -.PP -The following functions for \s-1NID\s0 (numeric id) handling have changed semantics. -.IP "\(bu" 4 -\&\fBEVP_PKEY_id()\fR, \fBEVP_PKEY_get_id()\fR -.Sp -This function was previously used to reliably return the \s-1NID\s0 of -an \s-1EVP_PKEY\s0 object, e.g., to look up the name of the algorithm of -such \s-1EVP_PKEY\s0 by calling \fBOBJ_nid2sn\fR\|(3). With the introduction -of \fBprovider\fR\|(7)s \fBEVP_PKEY_id()\fR or its new equivalent -\&\fBEVP_PKEY_get_id\fR\|(3) might now also return the value \-1 -(\fB\s-1EVP_PKEY_KEYMGMT\s0\fR) indicating the use of a provider to -implement the \s-1EVP_PKEY\s0 object. Therefore, the use of -\&\fBEVP_PKEY_get0_type_name\fR\|(3) is recommended for retrieving -the name of the \s-1EVP_PKEY\s0 algorithm. -.SS "Using the \s-1FIPS\s0 Module in applications" -.IX Subsection "Using the FIPS Module in applications" -See \fBfips_module\fR\|(7) and \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7) for details. -.SS "OpenSSL command line application changes" -.IX Subsection "OpenSSL command line application changes" -\fINew applications\fR -.IX Subsection "New applications" -.PP -\&\fBopenssl kdf\fR uses the new \s-1\fBEVP_KDF\s0\fR\|(3) \s-1API.\s0 -\&\fBopenssl kdf\fR uses the new \s-1\fBEVP_MAC\s0\fR\|(3) \s-1API.\s0 -.PP -\fIAdded options\fR -.IX Subsection "Added options" -.PP -\&\fB\-provider_path\fR and \fB\-provider\fR are available to all apps and can be used -multiple times to load any providers, such as the 'legacy' provider or third -party providers. If used then the 'default' provider would also need to be -specified if required. The \fB\-provider_path\fR must be specified before the -\&\fB\-provider\fR option. -.PP -The \fBlist\fR app has many new options. See \fBopenssl\-list\fR\|(1) for more -information. -.PP -\&\fB\-crl_lastupdate\fR and \fB\-crl_nextupdate\fR used by \fBopenssl ca\fR allows -explicit setting of fields in the generated \s-1CRL.\s0 -.PP -\fIRemoved options\fR -.IX Subsection "Removed options" -.PP -Interactive mode is not longer available. -.PP -The \fB\-crypt\fR option used by \fBopenssl passwd\fR. -The \fB\-c\fR option used by \fBopenssl x509\fR, \fBopenssl dhparam\fR, -\&\fBopenssl dsaparam\fR, and \fBopenssl ecparam\fR. -.PP -\fIOther Changes\fR -.IX Subsection "Other Changes" -.PP -The output of Command line applications may have minor changes. -These are primarily changes in capitalisation and white space. However, in some -cases, there are additional differences. -For example, the \s-1DH\s0 parameters output from \fBopenssl dhparam\fR now lists 'P', -\&'Q', 'G' and 'pcounter' instead of 'prime', 'generator', 'subgroup order' and -\&'counter' respectively. -.PP -The \fBopenssl\fR commands that read keys, certificates, and CRLs now -automatically detect the \s-1PEM\s0 or \s-1DER\s0 format of the input files so it is not -necessary to explicitly specify the input format anymore. However if the -input format option is used the specified format will be required. -.PP -\&\fBopenssl speed\fR no longer uses low-level \s-1API\s0 calls. -This implies some of the performance numbers might not be comparable with the -previous releases due to higher overhead. This applies particularly to -measuring performance on smaller data chunks. -.PP -b, \fBopenssl dsa\fR, \fBopenssl gendsa\fR, \fBopenssl dsaparam\fR, -\&\fBopenssl genrsa\fR and \fBopenssl rsa\fR have been modified to use \s-1PKEY\s0 APIs. -\&\fBopenssl genrsa\fR and \fBopenssl rsa\fR now write \s-1PKCS\s0 #8 keys by default. -.PP -\fIDefault settings\fR -.IX Subsection "Default settings" -.PP -\&\*(L"\s-1SHA256\*(R"\s0 is now the default digest for \s-1TS\s0 query used by \fBopenssl ts\fR. -.PP -\fIDeprecated apps\fR -.IX Subsection "Deprecated apps" -.PP -\&\fBopenssl rsautl\fR is deprecated, use \fBopenssl pkeyutl\fR instead. -\&\fBopenssl dhparam\fR, \fBopenssl dsa\fR, \fBopenssl gendsa\fR, \fBopenssl dsaparam\fR, -\&\fBopenssl genrsa\fR, \fBopenssl rsa\fR, \fBopenssl genrsa\fR and \fBopenssl rsa\fR are -now in maintenance mode and no new features will be added to them. -.SS "\s-1TLS\s0 Changes" -.IX Subsection "TLS Changes" -.IP "\(bu" 4 -\&\s-1TLS 1.3 FFDHE\s0 key exchange support added -.Sp -This uses \s-1DH\s0 safe prime named groups. -.IP "\(bu" 4 -Support for fully \*(L"pluggable\*(R" TLSv1.3 groups. -.Sp -This means that providers may supply their own group implementations (using -either the \*(L"key exchange\*(R" or the \*(L"key encapsulation\*(R" methods) which will -automatically be detected and used by libssl. -.IP "\(bu" 4 -\&\s-1SSL\s0 and \s-1SSL_CTX\s0 options are now 64 bit instead of 32 bit. -.Sp -The signatures of the functions to get and set options on \s-1SSL\s0 and -\&\s-1SSL_CTX\s0 objects changed from \*(L"unsigned long\*(R" to \*(L"uint64_t\*(R" type. -.Sp -This may require source code changes. For example it is no longer possible -to use the \fB\s-1SSL_OP_\s0\fR macro values in preprocessor \f(CW\*(C`#if\*(C'\fR conditions. -However it is still possible to test whether these macros are defined or not. -.Sp -See \fBSSL_CTX_get_options\fR\|(3), \fBSSL_CTX_set_options\fR\|(3), -\&\fBSSL_get_options\fR\|(3) and \fBSSL_set_options\fR\|(3). -.IP "\(bu" 4 -\&\fBSSL_set1_host()\fR and \fBSSL_add1_host()\fR Changes -.Sp -These functions now take \s-1IP\s0 literal addresses as well as actual hostnames. -.IP "\(bu" 4 -Added \s-1SSL\s0 option \s-1SSL_OP_CLEANSE_PLAINTEXT\s0 -.Sp -If the option is set, openssl cleanses (zeroizes) plaintext bytes from -internal buffers after delivering them to the application. Note, -the application is still responsible for cleansing other copies -(e.g.: data received by \fBSSL_read\fR\|(3)). -.IP "\(bu" 4 -Client-initiated renegotiation is disabled by default. -.Sp -To allow it, use the \fB\-client_renegotiation\fR option, -the \fB\s-1SSL_OP_ALLOW_CLIENT_RENEGOTIATION\s0\fR flag, or the \f(CW\*(C`ClientRenegotiation\*(C'\fR -config parameter as appropriate. -.IP "\(bu" 4 -Secure renegotiation is now required by default for \s-1TLS\s0 connections -.Sp -Support for \s-1RFC 5746\s0 secure renegotiation is now required by default for -\&\s-1SSL\s0 or \s-1TLS\s0 connections to succeed. Applications that require the ability -to connect to legacy peers will need to explicitly set -\&\s-1SSL_OP_LEGACY_SERVER_CONNECT.\s0 Accordingly, \s-1SSL_OP_LEGACY_SERVER_CONNECT\s0 -is no longer set as part of \s-1SSL_OP_ALL.\s0 -.IP "\(bu" 4 -Combining the Configure options no-ec and no-dh no longer disables TLSv1.3 -.Sp -Typically if OpenSSL has no \s-1EC\s0 or \s-1DH\s0 algorithms then it cannot support -connections with TLSv1.3. However OpenSSL now supports \*(L"pluggable\*(R" groups -through providers. Therefore third party providers may supply group -implementations even where there are no built-in ones. Attempting to create -\&\s-1TLS\s0 connections in such a build without also disabling TLSv1.3 at run time or -using third party provider groups may result in handshake failures. TLSv1.3 -can be disabled at compile time using the \*(L"no\-tls1_3\*(R" Configure option. -.IP "\(bu" 4 -\&\fBSSL_CTX_set_ciphersuites()\fR and \fBSSL_set_ciphersuites()\fR changes. -.Sp -The methods now ignore unknown ciphers. -.IP "\(bu" 4 -Security callback change. -.Sp -The security callback, which can be customised by application code, supports -the security operation \s-1SSL_SECOP_TMP_DH.\s0 This is defined to take an \s-1EVP_PKEY\s0 -in the \*(L"other\*(R" parameter. In most places this is what is passed. All these -places occur server side. However there was one client side call of this -security operation and it passed a \s-1DH\s0 object instead. This is incorrect -according to the definition of \s-1SSL_SECOP_TMP_DH,\s0 and is inconsistent with all -of the other locations. Therefore this client side call has been changed to -pass an \s-1EVP_PKEY\s0 instead. -.IP "\(bu" 4 -New \s-1SSL\s0 option \s-1SSL_OP_IGNORE_UNEXPECTED_EOF\s0 -.Sp -The \s-1SSL\s0 option \s-1SSL_OP_IGNORE_UNEXPECTED_EOF\s0 is introduced. If that option -is set, an unexpected \s-1EOF\s0 is ignored, it pretends a close notify was received -instead and so the returned error becomes \s-1SSL_ERROR_ZERO_RETURN.\s0 -.IP "\(bu" 4 -The security strength of \s-1SHA1\s0 and \s-1MD5\s0 based signatures in \s-1TLS\s0 has been reduced. -.Sp -This results in \s-1SSL 3, TLS 1.0, TLS 1.1\s0 and \s-1DTLS 1.0\s0 no longer -working at the default security level of 1 and instead requires security -level 0. The security level can be changed either using the cipher string -with \f(CW@SECLEVEL\fR, or calling \fBSSL_CTX_set_security_level\fR\|(3). This also means -that where the signature algorithms extension is missing from a ClientHello -then the handshake will fail in \s-1TLS 1.2\s0 at security level 1. This is because, -although this extension is optional, failing to provide one means that -OpenSSL will fallback to a default set of signature algorithms. This default -set requires the availability of \s-1SHA1.\s0 -.IP "\(bu" 4 -X509 certificates signed using \s-1SHA1\s0 are no longer allowed at security level 1 and above. -.Sp -In \s-1TLS/SSL\s0 the default security level is 1. It can be set either using the cipher -string with \f(CW@SECLEVEL\fR, or calling \fBSSL_CTX_set_security_level\fR\|(3). If the -leaf certificate is signed with \s-1SHA\-1,\s0 a call to \fBSSL_CTX_use_certificate\fR\|(3) -will fail if the security level is not lowered first. -Outside \s-1TLS/SSL,\s0 the default security level is \-1 (effectively 0). It can -be set using \fBX509_VERIFY_PARAM_set_auth_level\fR\|(3) or using the \fB\-auth_level\fR -options of the commands. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBfips_module\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The migration guide was created for OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2021\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-quic-client-block.7ossl b/openssl-install/share/man/man7/ossl-guide-quic-client-block.7ossl deleted file mode 100644 index 50f1b2d4..00000000 --- a/openssl-install/share/man/man7/ossl-guide-quic-client-block.7ossl +++ /dev/null @@ -1,514 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-QUIC-CLIENT-BLOCK 7ossl" -.TH OSSL-GUIDE-QUIC-CLIENT-BLOCK 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-quic\-client\-block -\&\- OpenSSL Guide: Writing a simple blocking QUIC client -.SH "SIMPLE BLOCKING QUIC CLIENT EXAMPLE" -.IX Header "SIMPLE BLOCKING QUIC CLIENT EXAMPLE" -This page will present various source code samples demonstrating how to write -a simple blocking \s-1QUIC\s0 client application which connects to a server, sends an -\&\s-1HTTP/1.0\s0 request to it, and reads back the response. Note that \s-1HTTP/1.0\s0 over -\&\s-1QUIC\s0 is non-standard and will not be supported by real world servers. This is -for demonstration purposes only. -.PP -We assume that you already have OpenSSL installed on your system; that you -already have some fundamental understanding of OpenSSL concepts, \s-1TLS\s0 and \s-1QUIC\s0 -(see \fBossl\-guide\-libraries\-introduction\fR\|(7), \fBossl\-guide\-tls\-introduction\fR\|(7) -and \fBossl\-guide\-quic\-introduction\fR\|(7)); and that you know how to -write and build C code and link it against the libcrypto and libssl libraries -that are provided by OpenSSL. It also assumes that you have a basic -understanding of \s-1UDP/IP\s0 and sockets. The example code that we build in this -tutorial will amend the blocking \s-1TLS\s0 client example that is covered in -\&\fBossl\-guide\-tls\-client\-block\fR\|(7). Only the differences between that client and -this one will be discussed so we also assume that you have run through and -understand that tutorial. -.PP -For this tutorial our client will be using a single \s-1QUIC\s0 stream. A subsequent -tutorial will discuss how to write a multi-stream client (see -\&\fBossl\-guide\-quic\-multi\-stream\fR\|(7)). -.PP -The complete source code for this example blocking \s-1QUIC\s0 client is available in -the \f(CW\*(C`demos/guide\*(C'\fR directory of the OpenSSL source distribution in the file -\&\f(CW\*(C`quic\-client\-block.c\*(C'\fR. It is also available online at -. -.SS "Creating the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects" -.IX Subsection "Creating the SSL_CTX and SSL objects" -In the \s-1TLS\s0 tutorial (\fBossl\-guide\-tls\-client\-block\fR\|(7)) we created an \fB\s-1SSL_CTX\s0\fR -object for our client and used it to create an \fB\s-1SSL\s0\fR object to represent the -\&\s-1TLS\s0 connection. A \s-1QUIC\s0 connection works in exactly the same way. We first create -an \fB\s-1SSL_CTX\s0\fR object and then use it to create an \fB\s-1SSL\s0\fR object to represent the -\&\s-1QUIC\s0 connection. -.PP -As in the \s-1TLS\s0 example the first step is to create an \fB\s-1SSL_CTX\s0\fR object for our -client. This is done in the same way as before except that we use a different -\&\*(L"method\*(R". OpenSSL offers two different \s-1QUIC\s0 client methods, i.e. -\&\fBOSSL_QUIC_client_method\fR\|(3) and \fBOSSL_QUIC_client_thread_method\fR\|(3). -.PP -The first one is the equivalent of \fBTLS_client_method\fR\|(3) but for the \s-1QUIC\s0 -protocol. The second one is the same, but it will additionally create a -background thread for handling time based events (known as \*(L"thread assisted -mode\*(R", see \fBossl\-guide\-quic\-introduction\fR\|(7)). For this tutorial we will be -using \fBOSSL_QUIC_client_method\fR\|(3) because we will not be leaving the \s-1QUIC\s0 -connection idle in our application and so thread assisted mode is not needed. -.PP -.Vb 10 -\& /* -\& * Create an SSL_CTX which we can use to create SSL objects from. We -\& * want an SSL_CTX for creating clients so we use OSSL_QUIC_client_method() -\& * here. -\& */ -\& ctx = SSL_CTX_new(OSSL_QUIC_client_method()); -\& if (ctx == NULL) { -\& printf("Failed to create the SSL_CTX\en"); -\& goto end; -\& } -.Ve -.PP -The other setup steps that we applied to the \fB\s-1SSL_CTX\s0\fR for \s-1TLS\s0 also apply to -\&\s-1QUIC\s0 except for restricting the \s-1TLS\s0 versions that we are willing to accept. The -\&\s-1QUIC\s0 protocol implementation in OpenSSL currently only supports TLSv1.3. There -is no need to call \fBSSL_CTX_set_min_proto_version\fR\|(3) or -\&\fBSSL_CTX_set_max_proto_version\fR\|(3) in an OpenSSL \s-1QUIC\s0 application, and any such -call will be ignored. -.PP -Once the \fB\s-1SSL_CTX\s0\fR is created, the \fB\s-1SSL\s0\fR object is constructed in exactly the -same way as for the \s-1TLS\s0 application. -.SS "Creating the socket and \s-1BIO\s0" -.IX Subsection "Creating the socket and BIO" -A major difference between \s-1TLS\s0 and \s-1QUIC\s0 is the underlying transport protocol. -\&\s-1TLS\s0 uses \s-1TCP\s0 while \s-1QUIC\s0 uses \s-1UDP.\s0 The way that the \s-1QUIC\s0 socket is created in our -example code is much the same as for \s-1TLS.\s0 We use the \fBBIO_lookup_ex\fR\|(3) and -\&\fBBIO_socket\fR\|(3) helper functions as we did in the previous tutorial except that -we pass \fB\s-1SOCK_DGRAM\s0\fR as an argument to indicate \s-1UDP\s0 (instead of \fB\s-1SOCK_STREAM\s0\fR -for \s-1TCP\s0). -.PP -.Vb 6 -\& /* -\& * Lookup IP address info for the server. -\& */ -\& if (!BIO_lookup_ex(hostname, port, BIO_LOOKUP_CLIENT, family, SOCK_DGRAM, 0, -\& &res)) -\& return NULL; -\& -\& /* -\& * Loop through all the possible addresses for the server and find one -\& * we can connect to. -\& */ -\& for (ai = res; ai != NULL; ai = BIO_ADDRINFO_next(ai)) { -\& /* -\& * Create a TCP socket. We could equally use non\-OpenSSL calls such -\& * as "socket" here for this and the subsequent connect and close -\& * functions. But for portability reasons and also so that we get -\& * errors on the OpenSSL stack in the event of a failure we use -\& * OpenSSL\*(Aqs versions of these functions. -\& */ -\& sock = BIO_socket(BIO_ADDRINFO_family(ai), SOCK_DGRAM, 0, 0); -\& if (sock == \-1) -\& continue; -\& -\& /* Connect the socket to the server\*(Aqs address */ -\& if (!BIO_connect(sock, BIO_ADDRINFO_address(ai), 0)) { -\& BIO_closesocket(sock); -\& sock = \-1; -\& continue; -\& } -\& -\& /* Set to nonblocking mode */ -\& if (!BIO_socket_nbio(sock, 1)) { -\& BIO_closesocket(sock); -\& sock = \-1; -\& continue; -\& } -\& -\& break; -\& } -\& -\& if (sock != \-1) { -\& *peer_addr = BIO_ADDR_dup(BIO_ADDRINFO_address(ai)); -\& if (*peer_addr == NULL) { -\& BIO_closesocket(sock); -\& return NULL; -\& } -\& } -\& -\& /* Free the address information resources we allocated earlier */ -\& BIO_ADDRINFO_free(res); -.Ve -.PP -You may notice a couple of other differences between this code and the version -that we used for \s-1TLS.\s0 -.PP -Firstly, we set the socket into nonblocking mode. This must always be done for -an OpenSSL \s-1QUIC\s0 application. This may be surprising considering that we are -trying to write a blocking client. Despite this the \fB\s-1SSL\s0\fR object will still -have blocking behaviour. See \fBossl\-guide\-quic\-introduction\fR\|(7) for further -information on this. -.PP -Secondly, we take note of the \s-1IP\s0 address of the peer that we are connecting to. -We store that information away. We will need it later. -.PP -See \fBBIO_lookup_ex\fR\|(3), \fBBIO_socket\fR\|(3), \fBBIO_connect\fR\|(3), -\&\fBBIO_closesocket\fR\|(3), \fBBIO_ADDRINFO_next\fR\|(3), \fBBIO_ADDRINFO_address\fR\|(3), -\&\fBBIO_ADDRINFO_free\fR\|(3) and \fBBIO_ADDR_dup\fR\|(3) for further information on the -functions used here. In the above example code the \fBhostname\fR and \fBport\fR -variables are strings, e.g. \*(L"www.example.com\*(R" and \*(L"443\*(R". -.PP -As for our \s-1TLS\s0 client, once the socket has been created and connected we need to -associate it with a \s-1BIO\s0 object: -.PP -.Vb 1 -\& BIO *bio; -\& -\& /* Create a BIO to wrap the socket */ -\& bio = BIO_new(BIO_s_datagram()); -\& if (bio == NULL) { -\& BIO_closesocket(sock); -\& return NULL; -\& } -\& -\& /* -\& * Associate the newly created BIO with the underlying socket. By -\& * passing BIO_CLOSE here the socket will be automatically closed when -\& * the BIO is freed. Alternatively you can use BIO_NOCLOSE, in which -\& * case you must close the socket explicitly when it is no longer -\& * needed. -\& */ -\& BIO_set_fd(bio, sock, BIO_CLOSE); -.Ve -.PP -Note the use of \fBBIO_s_datagram\fR\|(3) here as opposed to \fBBIO_s_socket\fR\|(3) that -we used for our \s-1TLS\s0 client. This is again due to the fact that \s-1QUIC\s0 uses \s-1UDP\s0 -instead of \s-1TCP\s0 for its transport layer. See \fBBIO_new\fR\|(3), \fBBIO_s_datagram\fR\|(3) -and \fBBIO_set_fd\fR\|(3) for further information on these functions. -.SS "Setting the server's hostname" -.IX Subsection "Setting the server's hostname" -As in the \s-1TLS\s0 tutorial we need to set the server's hostname both for \s-1SNI\s0 (Server -Name Indication) and for certificate validation purposes. The steps for this are -identical to the \s-1TLS\s0 tutorial and won't be repeated here. -.SS "Setting the \s-1ALPN\s0" -.IX Subsection "Setting the ALPN" -\&\s-1ALPN\s0 (Application-Layer Protocol Negotiation) is a feature of \s-1TLS\s0 that enables -the application to negotiate which protocol will be used over the connection. -For example, if you intend to use \s-1HTTP/3\s0 over the connection then the \s-1ALPN\s0 value -for that is \*(L"h3\*(R" (see -). -OpenSSL provides the ability for a client to specify the \s-1ALPN\s0 to use via the -\&\fBSSL_set_alpn_protos\fR\|(3) function. This is optional for a \s-1TLS\s0 client and so our -simple client that we developed in \fBossl\-guide\-tls\-client\-block\fR\|(7) did not use -it. However \s-1QUIC\s0 mandates that the \s-1TLS\s0 handshake used in establishing a \s-1QUIC\s0 -connection must use \s-1ALPN.\s0 -.PP -.Vb 1 -\& unsigned char alpn[] = { 8, \*(Aqh\*(Aq, \*(Aqt\*(Aq, \*(Aqt\*(Aq, \*(Aqp\*(Aq, \*(Aq/\*(Aq, \*(Aq1\*(Aq, \*(Aq.\*(Aq, \*(Aq0\*(Aq }; -\& -\& /* SSL_set_alpn_protos returns 0 for success! */ -\& if (SSL_set_alpn_protos(ssl, alpn, sizeof(alpn)) != 0) { -\& printf("Failed to set the ALPN for the connection\en"); -\& goto end; -\& } -.Ve -.PP -The \s-1ALPN\s0 is specified using a length prefixed array of unsigned chars (it is not -a \s-1NUL\s0 terminated string). Our original \s-1TLS\s0 blocking client demo was using -\&\s-1HTTP/1.0.\s0 We will use the same for this example. Unlike most OpenSSL functions -\&\fBSSL_set_alpn_protos\fR\|(3) returns zero for success and nonzero for failure. -.SS "Setting the peer address" -.IX Subsection "Setting the peer address" -An OpenSSL \s-1QUIC\s0 application must specify the target address of the server that -is being connected to. In \*(L"Creating the socket and \s-1BIO\*(R"\s0 above we saved that -address away for future use. Now we need to use it via the -\&\fBSSL_set1_initial_peer_addr\fR\|(3) function. -.PP -.Vb 5 -\& /* Set the IP address of the remote peer */ -\& if (!SSL_set1_initial_peer_addr(ssl, peer_addr)) { -\& printf("Failed to set the initial peer address\en"); -\& goto end; -\& } -.Ve -.PP -Note that we will need to free the \fBpeer_addr\fR value that we allocated via -\&\fBBIO_ADDR_dup\fR\|(3) earlier: -.PP -.Vb 1 -\& BIO_ADDR_free(peer_addr); -.Ve -.SS "The handshake and application data transfer" -.IX Subsection "The handshake and application data transfer" -Once initial setup of the \fB\s-1SSL\s0\fR object is complete then we perform the -handshake via \fBSSL_connect\fR\|(3) in exactly the same way as we did for the \s-1TLS\s0 -client, so we won't repeat it here. -.PP -We can also perform data transfer using a default \s-1QUIC\s0 stream that is -automatically associated with the \fB\s-1SSL\s0\fR object for us. We can transmit data -using \fBSSL_write_ex\fR\|(3), and receive data using \fBSSL_read_ex\fR\|(3) in the same -way as for \s-1TLS.\s0 The main difference is that we have to account for failures -slightly differently. With \s-1QUIC\s0 the stream can be reset by the peer (which is -fatal for that stream), but the underlying connection itself may still be -healthy. -.PP -.Vb 10 -\& /* -\& * Get up to sizeof(buf) bytes of the response. We keep reading until the -\& * server closes the connection. -\& */ -\& while (SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) { -\& /* -\& * OpenSSL does not guarantee that the returned data is a string or -\& * that it is NUL terminated so we use fwrite() to write the exact -\& * number of bytes that we read. The data could be non\-printable or -\& * have NUL characters in the middle of it. For this simple example -\& * we\*(Aqre going to print it to stdout anyway. -\& */ -\& fwrite(buf, 1, readbytes, stdout); -\& } -\& /* In case the response didn\*(Aqt finish with a newline we add one now */ -\& printf("\en"); -\& -\& /* -\& * Check whether we finished the while loop above normally or as the -\& * result of an error. The 0 argument to SSL_get_error() is the return -\& * code we received from the SSL_read_ex() call. It must be 0 in order -\& * to get here. Normal completion is indicated by SSL_ERROR_ZERO_RETURN. In -\& * QUIC terms this means that the peer has sent FIN on the stream to -\& * indicate that no further data will be sent. -\& */ -\& switch (SSL_get_error(ssl, 0)) { -\& case SSL_ERROR_ZERO_RETURN: -\& /* Normal completion of the stream */ -\& break; -\& -\& case SSL_ERROR_SSL: -\& /* -\& * Some stream fatal error occurred. This could be because of a stream -\& * reset \- or some failure occurred on the underlying connection. -\& */ -\& switch (SSL_get_stream_read_state(ssl)) { -\& case SSL_STREAM_STATE_RESET_REMOTE: -\& printf("Stream reset occurred\en"); -\& /* The stream has been reset but the connection is still healthy. */ -\& break; -\& -\& case SSL_STREAM_STATE_CONN_CLOSED: -\& printf("Connection closed\en"); -\& /* Connection is already closed. Skip SSL_shutdown() */ -\& goto end; -\& -\& default: -\& printf("Unknown stream failure\en"); -\& break; -\& } -\& break; -\& -\& default: -\& /* Some other unexpected error occurred */ -\& printf ("Failed reading remaining data\en"); -\& break; -\& } -.Ve -.PP -In the above code example you can see that \fB\s-1SSL_ERROR_SSL\s0\fR indicates a stream -fatal error. We can use \fBSSL_get_stream_read_state\fR\|(3) to determine whether the -stream has been reset, or if some other fatal error has occurred. -.SS "Shutting down the connection" -.IX Subsection "Shutting down the connection" -In the \s-1TLS\s0 tutorial we knew that the server had finished sending data because -\&\fBSSL_read_ex\fR\|(3) returned 0, and \fBSSL_get_error\fR\|(3) returned -\&\fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR. The same is true with \s-1QUIC\s0 except that -\&\fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR should be interpreted slightly differently. With \s-1TLS\s0 -we knew that this meant that the server had sent a \*(L"close_notify\*(R" alert. No -more data will be sent from the server on that connection. -.PP -With \s-1QUIC\s0 it means that the server has indicated \*(L"\s-1FIN\*(R"\s0 on the stream, meaning -that it will no longer send any more data on that stream. However this only -gives us information about the stream itself and does not tell us anything about -the underlying connection. More data could still be sent from the server on some -other stream. Additionally, although the server will not send any more data to -the client, it does not prevent the client from sending more data to the server. -.PP -In this tutorial, once we have finished reading data from the server on the one -stream that we are using, we will close the connection down. As before we do -this via the \fBSSL_shutdown\fR\|(3) function. This example for \s-1QUIC\s0 is very similar -to the \s-1TLS\s0 version. However the \fBSSL_shutdown\fR\|(3) function will need to be -called more than once: -.PP -.Vb 11 -\& /* -\& * Repeatedly call SSL_shutdown() until the connection is fully -\& * closed. -\& */ -\& do { -\& ret = SSL_shutdown(ssl); -\& if (ret < 0) { -\& printf("Error shutting down: %d\en", ret); -\& goto end; -\& } -\& } while (ret != 1); -.Ve -.PP -The shutdown process is in two stages. In the first stage we wait until all the -data we have buffered for sending on any stream has been successfully sent and -acknowledged by the peer, and then we send a \s-1CONNECTION_CLOSE\s0 to the peer to -indicate that the connection is no longer usable. This immediately closes the -connection and no more data can be sent or received. \fBSSL_shutdown\fR\|(3) returns -0 once the first stage has been completed. -.PP -In the second stage the connection enters a \*(L"closing\*(R" state. Application data -cannot be sent or received in this state, but late arriving packets coming from -the peer will be handled appropriately. Once this stage has completed -successfully \fBSSL_shutdown\fR\|(3) will return 1 to indicate success. -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-quic\-multi\-stream\fR\|(7) to read a tutorial on how to modify the -client developed on this page to support multiple streams. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7), \fBossl\-guide\-tls\-introduction\fR\|(7), -\&\fBossl\-guide\-tls\-client\-block\fR\|(7), \fBossl\-guide\-quic\-introduction\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-quic-client-non-block.7ossl b/openssl-install/share/man/man7/ossl-guide-quic-client-non-block.7ossl deleted file mode 100644 index 321359e4..00000000 --- a/openssl-install/share/man/man7/ossl-guide-quic-client-non-block.7ossl +++ /dev/null @@ -1,599 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-QUIC-CLIENT-NON-BLOCK 7ossl" -.TH OSSL-GUIDE-QUIC-CLIENT-NON-BLOCK 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-quic\-client\-non\-block -\&\- OpenSSL Guide: Writing a simple nonblocking QUIC client -.SH "SIMPLE NONBLOCKING QUIC CLIENT EXAMPLE" -.IX Header "SIMPLE NONBLOCKING QUIC CLIENT EXAMPLE" -This page will build on the example developed on the -\&\fBossl\-guide\-quic\-client\-block\fR\|(7) page which demonstrates how to write a simple -blocking \s-1QUIC\s0 client. On this page we will amend that demo code so that it -supports nonblocking functionality. -.PP -The complete source code for this example nonblocking \s-1QUIC\s0 client is available -in the \fBdemos/guide\fR directory of the OpenSSL source distribution in the file -\&\fBquic\-client\-non\-block.c\fR. It is also available online at -. -.PP -As we saw in the previous example an OpenSSL \s-1QUIC\s0 application always uses a -nonblocking socket. However, despite this, the \fB\s-1SSL\s0\fR object still has blocking -behaviour. When the \fB\s-1SSL\s0\fR object has blocking behaviour then this means that -it waits (blocks) until data is available to read if you attempt to read from -it when there is no data yet. Similarly it waits when writing if the \fB\s-1SSL\s0\fR -object is currently unable to write at the moment. This can simplify the -development of code because you do not have to worry about what to do in these -cases. The execution of the code will simply stop until it is able to continue. -However in many cases you do not want this behaviour. Rather than stopping and -waiting your application may need to go and do other tasks whilst the \fB\s-1SSL\s0\fR -object is unable to read/write, for example updating a \s-1GUI\s0 or performing -operations on some other connection or stream. -.PP -We will see later in this tutorial how to change the \fB\s-1SSL\s0\fR object so that it -has nonblocking behaviour. With a nonblocking \fB\s-1SSL\s0\fR object, functions such as -\&\fBSSL_read_ex\fR\|(3) or \fBSSL_write_ex\fR\|(3) will return immediately with a non-fatal -error if they are currently unable to read or write respectively. -.PP -Since this page is building on the example developed on the -\&\fBossl\-guide\-quic\-client\-block\fR\|(7) page we assume that you are familiar with it -and we only explain how this example differs. -.SS "Performing work while waiting for the socket" -.IX Subsection "Performing work while waiting for the socket" -In a nonblocking application you will need work to perform in the event that -we want to read or write to the \fB\s-1SSL\s0\fR object but we are currently unable to. -In fact this is the whole point of using a nonblocking \fB\s-1SSL\s0\fR object, i.e. to -give the application the opportunity to do something else. Whatever it is that -the application has to do, it must also be prepared to come back and retry the -operation that it previously attempted periodically to see if it can now -complete. Ideally it would only do this in the event that something has changed -such that it might succeed on the retry attempt, but this does not have to be -the case. It can retry at any time. -.PP -Note that it is important that you retry exactly the same operation that you -tried last time. You cannot start something new. For example if you were -attempting to write the text \*(L"Hello World\*(R" and the operation failed because the -\&\fB\s-1SSL\s0\fR object is currently unable to write, then you cannot then attempt to -write some other text when you retry the operation. -.PP -In this demo application we will create a helper function which simulates doing -other work. In fact, for the sake of simplicity, it will do nothing except wait -for the state of the underlying socket to change or until a timeout expires -after which the state of the \fB\s-1SSL\s0\fR object might have changed. We will call our -function \f(CW\*(C`wait_for_activity()\*(C'\fR. -.PP -.Vb 6 -\& static void wait_for_activity(SSL *ssl) -\& { -\& fd_set wfds, rfds; -\& int width, sock, isinfinite; -\& struct timeval tv; -\& struct timeval *tvp = NULL; -\& -\& /* Get hold of the underlying file descriptor for the socket */ -\& sock = SSL_get_fd(ssl); -\& -\& FD_ZERO(&wfds); -\& FD_ZERO(&rfds); -\& -\& /* -\& * Find out if we would like to write to the socket, or read from it (or -\& * both) -\& */ -\& if (SSL_net_write_desired(ssl)) -\& FD_SET(sock, &wfds); -\& if (SSL_net_read_desired(ssl)) -\& FD_SET(sock, &rfds); -\& width = sock + 1; -\& -\& /* -\& * Find out when OpenSSL would next like to be called, regardless of -\& * whether the state of the underlying socket has changed or not. -\& */ -\& if (SSL_get_event_timeout(ssl, &tv, &isinfinite) && !isinfinite) -\& tvp = &tv; -\& -\& /* -\& * Wait until the socket is writeable or readable. We use select here -\& * for the sake of simplicity and portability, but you could equally use -\& * poll/epoll or similar functions -\& * -\& * NOTE: For the purposes of this demonstration code this effectively -\& * makes this demo block until it has something more useful to do. In a -\& * real application you probably want to go and do other work here (e.g. -\& * update a GUI, or service other connections). -\& * -\& * Let\*(Aqs say for example that you want to update the progress counter on -\& * a GUI every 100ms. One way to do that would be to use the timeout in -\& * the last parameter to "select" below. If the tvp value is greater -\& * than 100ms then use 100ms instead. Then, when select returns, you -\& * check if it did so because of activity on the file descriptors or -\& * because of the timeout. If the 100ms GUI timeout has expired but the -\& * tvp timeout has not then go and update the GUI and then restart the -\& * "select" (with updated timeouts). -\& */ -\& -\& select(width, &rfds, &wfds, NULL, tvp); -\&} -.Ve -.PP -If you are familiar with how to write nonblocking applications in OpenSSL for -\&\s-1TLS\s0 (see \fBossl\-guide\-tls\-client\-non\-block\fR\|(7)) then you should note that there -is an important difference here between the way a \s-1QUIC\s0 application and a \s-1TLS\s0 -application works. With a \s-1TLS\s0 application if we try to read or write something -to the \fB\s-1SSL\s0\fR object and we get a \*(L"retry\*(R" response (\fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR) then we can assume that is because OpenSSL attempted to -read or write to the underlying socket and the socket signalled the \*(L"retry\*(R". -With \s-1QUIC\s0 that is not the case. OpenSSL may signal retry as a result of an -\&\fBSSL_read_ex\fR\|(3) or \fBSSL_write_ex\fR\|(3) (or similar) call which indicates the -state of the stream. This is entirely independent of whether the underlying -socket needs to retry or not. -.PP -To determine whether OpenSSL currently wants to read or write to the underlying -socket for a \s-1QUIC\s0 application we must call the \fBSSL_net_read_desired\fR\|(3) and -\&\fBSSL_net_write_desired\fR\|(3) functions. -.PP -It is also important with \s-1QUIC\s0 that we periodically call an I/O function (or -otherwise call the \fBSSL_handle_events\fR\|(3) function) to ensure that the \s-1QUIC\s0 -connection remains healthy. This is particularly important with a nonblocking -application because you are likely to leave the \fB\s-1SSL\s0\fR object idle for a while -while the application goes off to do other work. The \fBSSL_get_event_timeout\fR\|(3) -function can be used to determine what the deadline is for the next time we need -to call an I/O function (or call \fBSSL_handle_events\fR\|(3)). -.PP -An alternative to using \fBSSL_get_event_timeout\fR\|(3) to find the next deadline -that OpenSSL must be called again by is to use \*(L"thread assisted\*(R" mode. In -\&\*(L"thread assisted\*(R" mode OpenSSL spawns an additional thread which will -periodically call \fBSSL_handle_events\fR\|(3) automatically, meaning that the -application can leave the connection idle safe in the knowledge that the -connection will still be maintained in a healthy state. See -\&\*(L"Creating the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects\*(R" below for further details about this. -.PP -In this example we are using the \f(CW\*(C`select\*(C'\fR function to check the -readability/writeability of the socket because it is very simple to use and is -available on most Operating Systems. However you could use any other similar -function to do the same thing. \f(CW\*(C`select\*(C'\fR waits for the state of the underlying -socket(s) to become readable/writeable or until the timeout has expired before -returning. -.SS "Handling errors from OpenSSL I/O functions" -.IX Subsection "Handling errors from OpenSSL I/O functions" -A \s-1QUIC\s0 application that has been configured for nonblocking behaviour will need -to be prepared to handle errors returned from OpenSSL I/O functions such as -\&\fBSSL_read_ex\fR\|(3) or \fBSSL_write_ex\fR\|(3). Errors may be fatal for the stream (for -example because the stream has been reset or because the underlying connection -has failed), or non-fatal (for example because we are trying to read from the -stream but no data has not yet arrived from the peer for that stream). -.PP -\&\fBSSL_read_ex\fR\|(3) and \fBSSL_write_ex\fR\|(3) will return 0 to indicate an error and -\&\fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) will return 0 or a negative value to indicate -an error. \fBSSL_shutdown\fR\|(3) will return a negative value to incidate an error. -.PP -In the event of an error an application should call \fBSSL_get_error\fR\|(3) to find -out what type of error has occurred. If the error is non-fatal and can be -retried then \fBSSL_get_error\fR\|(3) will return \fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR depending on whether OpenSSL wanted to read to or write -from the stream but was unable to. Note that a call to \fBSSL_read_ex\fR\|(3) or -\&\fBSSL_read\fR\|(3) can still generate \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR. Similarly calls to -\&\fBSSL_write_ex\fR\|(3) or \fBSSL_write\fR\|(3) might generate \fB\s-1SSL_ERROR_WANT_READ\s0\fR. -.PP -Another type of non-fatal error that may occur is \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR. This -indicates an \s-1EOF\s0 (End-Of-File) which can occur if you attempt to read data from -an \fB\s-1SSL\s0\fR object but the peer has indicated that it will not send any more data -on the stream. In this case you may still want to write data to the stream but -you will not receive any more data. -.PP -Fatal errors that may occur are \fB\s-1SSL_ERROR_SYSCALL\s0\fR and \fB\s-1SSL_ERROR_SSL\s0\fR. These -indicate that the stream is no longer usable. For example, this could be because -the stream has been reset by the peer, or because the underlying connection has -failed. You can consult the OpenSSL error stack for further details (for example -by calling \fBERR_print_errors\fR\|(3) to print out details of errors that have -occurred). You can also consult the return value of -\&\fBSSL_get_stream_read_state\fR\|(3) to determine whether the error is local to the -stream, or whether the underlying connection has also failed. A return value -of \fB\s-1SSL_STREAM_STATE_RESET_REMOTE\s0\fR tells you that the stream has been reset by -the peer and \fB\s-1SSL_STREAM_STATE_CONN_CLOSED\s0\fR tells you that the underlying -connection has closed. -.PP -In our demo application we will write a function to handle these errors from -OpenSSL I/O functions: -.PP -.Vb 8 -\& static int handle_io_failure(SSL *ssl, int res) -\& { -\& switch (SSL_get_error(ssl, res)) { -\& case SSL_ERROR_WANT_READ: -\& case SSL_ERROR_WANT_WRITE: -\& /* Temporary failure. Wait until we can read/write and try again */ -\& wait_for_activity(ssl); -\& return 1; -\& -\& case SSL_ERROR_ZERO_RETURN: -\& /* EOF */ -\& return 0; -\& -\& case SSL_ERROR_SYSCALL: -\& return \-1; -\& -\& case SSL_ERROR_SSL: -\& /* -\& * Some stream fatal error occurred. This could be because of a -\& * stream reset \- or some failure occurred on the underlying -\& * connection. -\& */ -\& switch (SSL_get_stream_read_state(ssl)) { -\& case SSL_STREAM_STATE_RESET_REMOTE: -\& printf("Stream reset occurred\en"); -\& /* -\& * The stream has been reset but the connection is still -\& * healthy. -\& */ -\& break; -\& -\& case SSL_STREAM_STATE_CONN_CLOSED: -\& printf("Connection closed\en"); -\& /* Connection is already closed. */ -\& break; -\& -\& default: -\& printf("Unknown stream failure\en"); -\& break; -\& } -\& /* -\& * If the failure is due to a verification error we can get more -\& * information about it from SSL_get_verify_result(). -\& */ -\& if (SSL_get_verify_result(ssl) != X509_V_OK) -\& printf("Verify error: %s\en", -\& X509_verify_cert_error_string(SSL_get_verify_result(ssl))); -\& return \-1; -\& -\& default: -\& return \-1; -\& } -\& } -.Ve -.PP -This function takes as arguments the \fB\s-1SSL\s0\fR object that represents the -connection, as well as the return code from the I/O function that failed. In -the event of a non-fatal failure, it waits until a retry of the I/O operation -might succeed (by using the \f(CW\*(C`wait_for_activity()\*(C'\fR function that we developed -in the previous section). It returns 1 in the event of a non-fatal error -(except \s-1EOF\s0), 0 in the event of \s-1EOF,\s0 or \-1 if a fatal error occurred. -.SS "Creating the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects" -.IX Subsection "Creating the SSL_CTX and SSL objects" -In order to connect to a server we must create \fB\s-1SSL_CTX\s0\fR and \fB\s-1SSL\s0\fR objects for -this. Most of the steps to do this are the same as for a blocking client and are -explained on the \fBossl\-guide\-quic\-client\-block\fR\|(7) page. We won't repeat that -information here. -.PP -One key difference is that we must put the \fB\s-1SSL\s0\fR object into nonblocking mode -(the default is blocking mode). To do that we use the -\&\fBSSL_set_blocking_mode\fR\|(3) function: -.PP -.Vb 9 -\& /* -\& * The underlying socket is always nonblocking with QUIC, but the default -\& * behaviour of the SSL object is still to block. We set it for nonblocking -\& * mode in this demo. -\& */ -\& if (!SSL_set_blocking_mode(ssl, 0)) { -\& printf("Failed to turn off blocking mode\en"); -\& goto end; -\& } -.Ve -.PP -Although the demo application that we are developing here does not use it, it is -possible to use \*(L"thread assisted mode\*(R" when developing \s-1QUIC\s0 applications. -Normally, when writing an OpenSSL \s-1QUIC\s0 application, it is important that -\&\fBSSL_handle_events\fR\|(3) (or alternatively any I/O function) is called on the -connection \fB\s-1SSL\s0\fR object periodically to maintain the connection in a healthy -state. See \*(L"Performing work while waiting for the socket\*(R" for more discussion -on this. This is particularly important to keep in mind when writing a -nonblocking \s-1QUIC\s0 application because it is common to leave the \fB\s-1SSL\s0\fR connection -object idle for some time when using nonblocking mode. By using \*(L"thread assisted -mode\*(R" a separate thread is created by OpenSSL to do this automatically which -means that the application developer does not need to handle this aspect. To do -this we must use \fBOSSL_QUIC_client_thread_method\fR\|(3) when we construct the -\&\fB\s-1SSL_CTX\s0\fR as shown below: -.PP -.Vb 5 -\& ctx = SSL_CTX_new(OSSL_QUIC_client_thread_method()); -\& if (ctx == NULL) { -\& printf("Failed to create the SSL_CTX\en"); -\& goto end; -\& } -.Ve -.SS "Performing the handshake" -.IX Subsection "Performing the handshake" -As in the demo for a blocking \s-1QUIC\s0 client we use the \fBSSL_connect\fR\|(3) function -to perform the handshake with the server. Since we are using a nonblocking -\&\fB\s-1SSL\s0\fR object it is very likely that calls to this function will fail with a -non-fatal error while we are waiting for the server to respond to our handshake -messages. In such a case we must retry the same \fBSSL_connect\fR\|(3) call at a -later time. In this demo we do this in a loop: -.PP -.Vb 7 -\& /* Do the handshake with the server */ -\& while ((ret = SSL_connect(ssl)) != 1) { -\& if (handle_io_failure(ssl, ret) == 1) -\& continue; /* Retry */ -\& printf("Failed to connect to server\en"); -\& goto end; /* Cannot retry: error */ -\& } -.Ve -.PP -We continually call \fBSSL_connect\fR\|(3) until it gives us a success response. -Otherwise we use the \f(CW\*(C`handle_io_failure()\*(C'\fR function that we created earlier to -work out what we should do next. Note that we do not expect an \s-1EOF\s0 to occur at -this stage, so such a response is treated in the same way as a fatal error. -.SS "Sending and receiving data" -.IX Subsection "Sending and receiving data" -As with the blocking \s-1QUIC\s0 client demo we use the \fBSSL_write_ex\fR\|(3) function to -send data to the server. As with \fBSSL_connect\fR\|(3) above, because we are using -a nonblocking \fB\s-1SSL\s0\fR object, this call could fail with a non-fatal error. In -that case we should retry exactly the same \fBSSL_write_ex\fR\|(3) call again. Note -that the parameters must be \fIexactly\fR the same, i.e. the same pointer to the -buffer to write with the same length. You must not attempt to send different -data on a retry. An optional mode does exist -(\fB\s-1SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER\s0\fR) which will configure OpenSSL to allow -the buffer being written to change from one retry to the next. However, in this -case, you must still retry exactly the same data \- even though the buffer that -contains that data may change location. See \fBSSL_CTX_set_mode\fR\|(3) for further -details. As in the \s-1TLS\s0 tutorials (\fBossl\-guide\-tls\-client\-block\fR\|(7)) we write -the request in three chunks. -.PP -.Vb 10 -\& /* Write an HTTP GET request to the peer */ -\& while (!SSL_write_ex(ssl, request_start, strlen(request_start), &written)) { -\& if (handle_io_failure(ssl, 0) == 1) -\& continue; /* Retry */ -\& printf("Failed to write start of HTTP request\en"); -\& goto end; /* Cannot retry: error */ -\& } -\& while (!SSL_write_ex(ssl, hostname, strlen(hostname), &written)) { -\& if (handle_io_failure(ssl, 0) == 1) -\& continue; /* Retry */ -\& printf("Failed to write hostname in HTTP request\en"); -\& goto end; /* Cannot retry: error */ -\& } -\& while (!SSL_write_ex(ssl, request_end, strlen(request_end), &written)) { -\& if (handle_io_failure(ssl, 0) == 1) -\& continue; /* Retry */ -\& printf("Failed to write end of HTTP request\en"); -\& goto end; /* Cannot retry: error */ -\& } -.Ve -.PP -On a write we do not expect to see an \s-1EOF\s0 response so we treat that case in the -same way as a fatal error. -.PP -Reading a response back from the server is similar: -.PP -.Vb 10 -\& do { -\& /* -\& * Get up to sizeof(buf) bytes of the response. We keep reading until -\& * the server closes the connection. -\& */ -\& while (!eof && !SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) { -\& switch (handle_io_failure(ssl, 0)) { -\& case 1: -\& continue; /* Retry */ -\& case 0: -\& eof = 1; -\& continue; -\& case \-1: -\& default: -\& printf("Failed reading remaining data\en"); -\& goto end; /* Cannot retry: error */ -\& } -\& } -\& /* -\& * OpenSSL does not guarantee that the returned data is a string or -\& * that it is NUL terminated so we use fwrite() to write the exact -\& * number of bytes that we read. The data could be non\-printable or -\& * have NUL characters in the middle of it. For this simple example -\& * we\*(Aqre going to print it to stdout anyway. -\& */ -\& if (!eof) -\& fwrite(buf, 1, readbytes, stdout); -\& } while (!eof); -\& /* In case the response didn\*(Aqt finish with a newline we add one now */ -\& printf("\en"); -.Ve -.PP -The main difference this time is that it is valid for us to receive an \s-1EOF\s0 -response when trying to read data from the server. This will occur when the -server closes down the connection after sending all the data in its response. -.PP -In this demo we just print out all the data we've received back in the response -from the server. We continue going around the loop until we either encounter a -fatal error, or we receive an \s-1EOF\s0 (indicating a graceful finish). -.SS "Shutting down the connection" -.IX Subsection "Shutting down the connection" -As in the \s-1QUIC\s0 blocking example we must shutdown the connection when we are -finished with it. -.PP -Even though we have received \s-1EOF\s0 on the stream that we were reading from above, -this tell us nothing about the state of the underlying connection. Our demo -application will initiate the connection shutdown process via -\&\fBSSL_shutdown\fR\|(3). -.PP -Since our application is initiating the shutdown then we might expect to see -\&\fBSSL_shutdown\fR\|(3) give a return value of 0, and then we should continue to call -it until we receive a return value of 1 (meaning we have successfully completed -the shutdown). Since we are using a nonblocking \fB\s-1SSL\s0\fR object we might expect to -have to retry this operation several times. If \fBSSL_shutdown\fR\|(3) returns a -negative result then we must call \fBSSL_get_error\fR\|(3) to work out what to do -next. We use our \fBhandle_io_failure()\fR function that we developed earlier for -this: -.PP -.Vb 8 -\& /* -\& * Repeatedly call SSL_shutdown() until the connection is fully -\& * closed. -\& */ -\& while ((ret = SSL_shutdown(ssl)) != 1) { -\& if (ret < 0 && handle_io_failure(ssl, ret) == 1) -\& continue; /* Retry */ -\& } -.Ve -.SS "Final clean up" -.IX Subsection "Final clean up" -As with the blocking \s-1QUIC\s0 client example, once our connection is finished with -we must free it. The steps to do this for this example are the same as for the -blocking example, so we won't repeat it here. -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-quic\-client\-block\fR\|(7) to read a tutorial on how to write a -blocking \s-1QUIC\s0 client. See \fBossl\-guide\-quic\-multi\-stream\fR\|(7) to see how to write -a multi-stream \s-1QUIC\s0 client. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7), \fBossl\-guide\-quic\-introduction\fR\|(7), -\&\fBossl\-guide\-quic\-client\-block\fR\|(7), \fBossl\-guide\-quic\-multi\-stream\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-quic-introduction.7ossl b/openssl-install/share/man/man7/ossl-guide-quic-introduction.7ossl deleted file mode 100644 index 9f7d202e..00000000 --- a/openssl-install/share/man/man7/ossl-guide-quic-introduction.7ossl +++ /dev/null @@ -1,304 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-QUIC-INTRODUCTION 7ossl" -.TH OSSL-GUIDE-QUIC-INTRODUCTION 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-quic\-introduction -\&\- OpenSSL Guide: An introduction to QUIC in OpenSSL -.SH "INTRODUCTION" -.IX Header "INTRODUCTION" -This page will provide an introduction to some basic \s-1QUIC\s0 concepts and -background and how it is used within OpenSSL. It assumes that you have a basic -understanding of \s-1UDP/IP\s0 and sockets. It also assumes that you are familiar with -some OpenSSL and \s-1TLS\s0 fundamentals (see \fBossl\-guide\-libraries\-introduction\fR\|(7) -and \fBossl\-guide\-tls\-introduction\fR\|(7)). -.SH "WHAT IS QUIC?" -.IX Header "WHAT IS QUIC?" -\&\s-1QUIC\s0 is a general purpose protocol for enabling applications to securely -communicate over a network. It is defined in \s-1RFC9000\s0 (see -). \s-1QUIC\s0 integrates parts of the -\&\s-1TLS\s0 protocol for connection establishment but independently protects packets. -It provides similar security guarantees to \s-1TLS\s0 such as confidentiality, -integrity and authentication (see \fBossl\-guide\-tls\-introduction\fR\|(7)). -.PP -\&\s-1QUIC\s0 delivers a number of advantages: -.IP "Multiple streams" 4 -.IX Item "Multiple streams" -It supports multiple streams of communication (see \*(L"\s-1QUIC STREAMS\*(R"\s0 below), -allowing application protocols built on \s-1QUIC\s0 to create arbitrarily many -bytestreams for communication between a client and server. This allows an -application protocol to avoid problems where one packet of data is held up -waiting on another packet being delivered (commonly referred to as -\&\*(L"head-of-line blocking\*(R"). It also enables an application to open additional -logical streams without requiring a round-trip exchange of packets between the -client and server as is required when opening an additional \s-1TLS/TCP\s0 -connection. -.IP "\s-1HTTP/3\s0" 4 -.IX Item "HTTP/3" -Since \s-1QUIC\s0 is the basis of \s-1HTTP/3,\s0 support for \s-1QUIC\s0 also enables applications -to use \s-1HTTP/3\s0 using a suitable third-party library. -.IP "Fast connection initiation" 4 -.IX Item "Fast connection initiation" -Future versions of OpenSSL will offer support for 0\-RTT connection initiation, -allowing a connection to be initiated to a server and application data to be -transmitted without any waiting time. This is similar to \s-1TLS 1.3\s0's 0\-RTT -functionality but also avoids the round trip needed to open a \s-1TCP\s0 socket; thus, -it is similar to a combination of \s-1TLS 1.3 0\-RTT\s0 and \s-1TCP\s0 Fast Open. -.IP "Connection migration" 4 -.IX Item "Connection migration" -Future versions of OpenSSL will offer support for connection migration, allowing -connections to seamlessly survive \s-1IP\s0 address changes. -.IP "Datagram based use cases" 4 -.IX Item "Datagram based use cases" -Future versions of OpenSSL will offer support for the \s-1QUIC\s0 datagram extension, -allowing support for both \s-1TLS\s0 and DTLS-style use cases on a single connection. -.IP "Implemented as application library" 4 -.IX Item "Implemented as application library" -Because most \s-1QUIC\s0 implementations, including OpenSSL's implementation, are -implemented as an application library rather than by an operating system, an -application can gain the benefit of \s-1QUIC\s0 without needing to wait for an \s-1OS\s0 -update to be deployed. Future evolutions and enhancements to the \s-1QUIC\s0 protocol -can be delivered as quickly as an application can be updated without dependency -on an \s-1OS\s0 update cadence. -.IP "Multiplexing over a single \s-1UDP\s0 socket" 4 -.IX Item "Multiplexing over a single UDP socket" -Because \s-1QUIC\s0 is UDP-based, it is possible to multiplex a \s-1QUIC\s0 connection on the -same \s-1UDP\s0 socket as some other UDP-based protocols, such as \s-1RTP.\s0 -.SH "QUIC TIME BASED EVENTS" -.IX Header "QUIC TIME BASED EVENTS" -A key difference between the \s-1TLS\s0 implementation and the \s-1QUIC\s0 implementation in -OpenSSL is how time is handled. The \s-1QUIC\s0 protocol requires various actions to be -performed on a regular basis regardless of whether application data is being -transmitted or received. -.PP -OpenSSL introduces a new function \fBSSL_handle_events\fR\|(3) that will -automatically process any outstanding time based events that must be handled. -Alternatively calling any I/O function such as \fBSSL_read_ex\fR\|(3) or -\&\fBSSL_write_ex\fR\|(3) will also process these events. There is also -\&\fBSSL_get_event_timeout\fR\|(3) which tells an application the amount of time that -remains until \fBSSL_handle_events\fR\|(3) (or any I/O function) must be called. -.PP -Fortunately a blocking application that does not leave the \s-1QUIC\s0 connection idle, -and is regularly calling I/O functions does not typically need to worry about -this. However if you are developing a nonblocking application or one that may -leave the \s-1QUIC\s0 connection idle for a period of time then you will need to -arrange to call these functions. -.PP -OpenSSL provides an optional \*(L"thread assisted mode\*(R" that will automatically -create a background thread and will regularly call \fBSSL_handle_events\fR\|(3) in a -thread safe manner. This provides a simple way for an application to satisfy the -\&\s-1QUIC\s0 requirements for time based events without having to implement special -logic to accomplish it. -.SH "QUIC AND TLS" -.IX Header "QUIC AND TLS" -\&\s-1QUIC\s0 reuses parts of the \s-1TLS\s0 protocol in its implementation. Specifically the -\&\s-1TLS\s0 handshake also exists in \s-1QUIC.\s0 The \s-1TLS\s0 handshake messages are wrapped up in -\&\s-1QUIC\s0 protocol messages in order to send them to the peer. Once the \s-1TLS\s0 handshake -is complete all application data is sent entirely using \s-1QUIC\s0 protocol messages -without using \s-1TLS\s0 \- although some \s-1TLS\s0 handshake messages may still be sent in -some circumstances. -.PP -This relationship between \s-1QUIC\s0 and \s-1TLS\s0 means that many of the \s-1API\s0 functions in -OpenSSL that apply to \s-1TLS\s0 connections also apply to \s-1QUIC\s0 connections and -applications can use them in exactly the same way. Some functions do not apply -to \s-1QUIC\s0 at all, and others have altered semantics. You should refer to the -documentation pages for each function for information on how it applies to \s-1QUIC.\s0 -Typically if \s-1QUIC\s0 is not mentioned in the manual pages then the functions apply -to both \s-1TLS\s0 and \s-1QUIC.\s0 -.SH "QUIC STREAMS" -.IX Header "QUIC STREAMS" -\&\s-1QUIC\s0 introduces the concept of \*(L"streams\*(R". A stream provides a reliable -mechanism for sending and receiving application data between the endpoints. The -bytes transmitted are guaranteed to be received in the same order they were sent -without any loss of data or reordering of the bytes. A \s-1TLS\s0 application -effectively has one bi-directional stream available to it per \s-1TLS\s0 connection. A -\&\s-1QUIC\s0 application can have multiple uni-directional or bi-directional streams -available to it for each connection. -.PP -In OpenSSL an \fB\s-1SSL\s0\fR object is used to represent both connections and streams. -A \s-1QUIC\s0 application creates an initial \fB\s-1SSL\s0\fR object to represent the connection -(known as the connection \fB\s-1SSL\s0\fR object). Once the connection is complete -additional \fB\s-1SSL\s0\fR objects can be created to represent streams (known as stream -\&\fB\s-1SSL\s0\fR objects). Unless configured otherwise, a \*(L"default\*(R" stream is also -associated with the connection \fB\s-1SSL\s0\fR object so you can still write data and -read data to/from it. Some OpenSSL \s-1API\s0 functions can only be used with -connection \fB\s-1SSL\s0\fR objects, and some can only be used with stream \fB\s-1SSL\s0\fR objects. -Check the documentation for each function to confirm what type of \fB\s-1SSL\s0\fR object -can be used in any particular context. A connection \fB\s-1SSL\s0\fR object that has a -default stream attached to it can be used in contexts that require a connection -\&\fB\s-1SSL\s0\fR object or in contexts that require a stream \fB\s-1SSL\s0\fR object. -.SH "SOCKETS AND BLOCKING" -.IX Header "SOCKETS AND BLOCKING" -\&\s-1TLS\s0 assumes \*(L"stream\*(R" type semantics for its underlying transport layer protocol -(usually achieved by using \s-1TCP\s0). However \s-1QUIC\s0 assumes \*(L"datagram\*(R" type semantics -by using \s-1UDP.\s0 An OpenSSL application using \s-1QUIC\s0 is responsible for creating a -\&\s-1BIO\s0 to represent the underlying transport layer. This \s-1BIO\s0 must support datagrams -and is typically \fBBIO_s_datagram\fR\|(3), but other \fB\s-1BIO\s0\fR choices are available. -See \fBbio\fR\|(7) for an introduction to OpenSSL's \fB\s-1BIO\s0\fR concept. -.PP -A significant difference between OpenSSL \s-1TLS\s0 applications and OpenSSL \s-1QUIC\s0 -applications is the way that blocking is implemented. In \s-1TLS\s0 if your application -expects blocking behaviour then you configure the underlying socket for -blocking. Conversely if your application wants nonblocking behaviour then the -underlying socket is configured to be nonblocking. -.PP -With an OpenSSL \s-1QUIC\s0 application the underlying socket must always be configured -to be nonblocking. Howevever the \fB\s-1SSL\s0\fR object will, by default, still operate -in blocking mode. So, from an application's perspective, calls to functions such -as \fBSSL_read_ex\fR\|(3), \fBSSL_write_ex\fR\|(3) and other I/O functions will still -block. OpenSSL itself provides that blocking capability for \s-1QUIC\s0 instead of the -socket. If nonblocking behaviour is desired then the application must call -\&\fBSSL_set_blocking_mode\fR\|(3). -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-quic\-client\-block\fR\|(7) to see an example of applying these -concepts in order to write a simple blocking \s-1QUIC\s0 client. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7), \fBossl\-guide\-tls\-introduction\fR\|(7), -\&\fBossl\-guide\-tls\-client\-block\fR\|(7), \fBossl\-guide\-quic\-client\-block\fR\|(7), \fBbio\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-quic-multi-stream.7ossl b/openssl-install/share/man/man7/ossl-guide-quic-multi-stream.7ossl deleted file mode 100644 index 359f5fc8..00000000 --- a/openssl-install/share/man/man7/ossl-guide-quic-multi-stream.7ossl +++ /dev/null @@ -1,531 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-QUIC-MULTI-STREAM 7ossl" -.TH OSSL-GUIDE-QUIC-MULTI-STREAM 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-quic\-multi\-stream -\&\- OpenSSL Guide: Writing a simple multi\-stream QUIC client -.SH "INTRODUCTION" -.IX Header "INTRODUCTION" -This page will introduce some important concepts required to write a simple -\&\s-1QUIC\s0 multi-stream application. It assumes a basic understanding of \s-1QUIC\s0 and how -it is used in OpenSSL. See \fBossl\-guide\-quic\-introduction\fR\|(7) and -\&\fBossl\-guide\-quic\-client\-block\fR\|(7). -.SH "QUIC STREAMS" -.IX Header "QUIC STREAMS" -In a \s-1QUIC\s0 multi-stream application we separate out the concepts of a \s-1QUIC\s0 -\&\*(L"connection\*(R" and a \s-1QUIC\s0 \*(L"stream\*(R". A connection object represents the overarching -details of the connection between a client and a server including all its -negotiated and configured parameters. We use the \fB\s-1SSL\s0\fR object for that in an -OpenSSL application (known as the connection \fB\s-1SSL\s0\fR object). It is created by an -application calling \fBSSL_new\fR\|(3). -.PP -Separately a connection can have zero or more streams associated with it -(although a connection with zero streams is probably not very useful, so -normally you would have at least one). A stream is used to send and receive -data between the two peers. Each stream is also represented by an \fB\s-1SSL\s0\fR -object. A stream is logically independent of all the other streams associated -with the same connection. Data sent on a stream is guaranteed to be delivered -in the order that it was sent within that stream. The same is not true across -streams, e.g. if an application sends data on stream 1 first and then sends some -more data on stream 2 second, then the remote peer may receive the data sent on -stream 2 before it receives the data sent on stream 1. -.PP -Once the connection \fB\s-1SSL\s0\fR object has completed its handshake (i.e. -\&\fBSSL_connect\fR\|(3) has returned 1), stream \fB\s-1SSL\s0\fR objects are created by the -application calling \fBSSL_new_stream\fR\|(3) or \fBSSL_accept_stream\fR\|(3) (see -\&\*(L"\s-1CREATING NEW STREAMS\*(R"\s0 below). -.PP -The same threading rules apply to \fB\s-1SSL\s0\fR objects as for most OpenSSL objects -(see \fBossl\-guide\-libraries\-introduction\fR\|(7)). In particular most OpenSSL -functions are thread safe, but the \fB\s-1SSL\s0\fR object is not. This means that you can -use an \fB\s-1SSL\s0\fR object representing one stream at the same time as another thread -is using a different \fB\s-1SSL\s0\fR object for a different stream on the same -connection. But you cannot use the same \fB\s-1SSL\s0\fR object on two different threads -at the same time (without additional application level locking). -.SH "THE DEFAULT STREAM" -.IX Header "THE DEFAULT STREAM" -A connection \fB\s-1SSL\s0\fR object may also (optionally) be associated with a stream. -This stream is known as the default stream. The default stream is automatically -created and associated with the \fB\s-1SSL\s0\fR object when the application calls -\&\fBSSL_read_ex\fR\|(3), \fBSSL_read\fR\|(3), \fBSSL_write_ex\fR\|(3) or \fBSSL_write\fR\|(3) and -passes the connection \fB\s-1SSL\s0\fR object as a parameter. -.PP -If a client application calls \fBSSL_write_ex\fR\|(3) or \fBSSL_write\fR\|(3) first then -(by default) the default stream will be a client-initiated bi-directional -stream. If a client application calls \fBSSL_read_ex\fR\|(3) or \fBSSL_read\fR\|(3) -first then the first stream initiated by the server will be used as the default -stream (whether it is bi-directional or uni-directional). -.PP -This behaviour can be controlled via the default stream mode. See -\&\fBSSL_set_default_stream_mode\fR\|(3) for further details. -.PP -It is recommended that new multi-stream applications should not use a default -stream at all and instead should use a separate stream \fB\s-1SSL\s0\fR object for each -stream that is used. This requires calling \fBSSL_set_default_stream_mode\fR\|(3) -and setting the mode to \fB\s-1SSL_DEFAULT_STREAM_MODE_NONE\s0\fR. -.SH "CREATING NEW STREAMS" -.IX Header "CREATING NEW STREAMS" -An endpoint can create a new stream by calling \fBSSL_new_stream\fR\|(3). This -creates a locally initiated stream. In order to do so you must pass the \s-1QUIC\s0 -connection \fB\s-1SSL\s0\fR object as a parameter. You can also specify whether you want a -bi-directional or a uni-directional stream. -.PP -The function returns a new \s-1QUIC\s0 stream \fB\s-1SSL\s0\fR object for sending and receiving -data on that stream. -.PP -The peer may also initiate streams. An application can use the function -\&\fBSSL_get_accept_stream_queue_len\fR\|(3) to determine the number of streams that -the peer has initiated that are waiting for the application to handle. An -application can call \fBSSL_accept_stream\fR\|(3) to create a new \fB\s-1SSL\s0\fR object for -a remotely initiated stream. If the peer has not initiated any then this call -will block until one is available if the connection object is in blocking mode -(see \fBSSL_set_blocking_mode\fR\|(3)). -.PP -When using a default stream OpenSSL will prevent new streams from being -accepted. To override this behaviour you must call -\&\fBSSL_set_incoming_stream_policy\fR\|(3) to set the policy to -\&\fB\s-1SSL_INCOMING_STREAM_POLICY_ACCEPT\s0\fR. See the man page for further details. This -is not relevant if the default stream has been disabled as described in -\&\*(L"\s-1THE DEFAULT STREAM\*(R"\s0 above. -.PP -Any stream may be bi-directional or uni-directional. If it is uni-directional -then the initiator can write to it but not read from it, and vice-versa for the -peer. You can determine what type of stream an \fB\s-1SSL\s0\fR object represents by -calling \fBSSL_get_stream_type\fR\|(3). See the man page for further details. -.SH "USING A STREAM TO SEND AND RECEIVE DATA" -.IX Header "USING A STREAM TO SEND AND RECEIVE DATA" -Once you have a stream \fB\s-1SSL\s0\fR object (which includes the connection \fB\s-1SSL\s0\fR -object if a default stream is in use) then you can send and receive data over it -using the \fBSSL_write_ex\fR\|(3), \fBSSL_write\fR\|(3), \fBSSL_read_ex\fR\|(3) or -\&\fBSSL_read\fR\|(3) functions. See the man pages for further details. -.PP -In the event of one of these functions not returning a success code then -you should call \fBSSL_get_error\fR\|(3) to find out further details about the error. -In blocking mode this will either be a fatal error (e.g. \fB\s-1SSL_ERROR_SYSCALL\s0\fR -or \fB\s-1SSL_ERROR_SSL\s0\fR), or it will be \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR which can occur -when attempting to read data from a stream and the peer has indicated that the -stream is concluded (i.e. \*(L"\s-1FIN\*(R"\s0 has been signalled on the stream). This means -that the peer will send no more data on that stream. Note that the -interpretation of \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR is slightly different for a \s-1QUIC\s0 -application compared to a \s-1TLS\s0 application. In \s-1TLS\s0 it occurs when the connection -has been shutdown by the peer. In \s-1QUIC\s0 this only tells you that the current -stream has been concluded by the peer. It tells you nothing about the underlying -connection. If the peer has concluded the stream then no more data will be -received on it, however an application can still send data to the peer until -the send side of the stream has also been concluded. This can happen by the -application calling \fBSSL_stream_conclude\fR\|(3). It is an error to attempt to -send more data on a stream after \fBSSL_stream_conclude\fR\|(3) has been called. -.PP -It is also possible to abandon a stream abnormally by calling -\&\fBSSL_stream_reset\fR\|(3). -.PP -Once a stream object is no longer needed it should be freed via a call to -\&\fBSSL_free\fR\|(3). An application should not call \fBSSL_shutdown\fR\|(3) on it since -this is only meaningful for connection level \fB\s-1SSL\s0\fR objects. Freeing the stream -will automatically signal \s-1STOP_SENDING\s0 to the peer. -.SH "STREAMS AND CONNECTIONS" -.IX Header "STREAMS AND CONNECTIONS" -Given a stream object it is possible to get the \fB\s-1SSL\s0\fR object corresponding to -the connection via a call to \fBSSL_get0_connection\fR\|(3). Multi-threaded -restrictions apply so care should be taken when using the returned connection -object. Specifically, if you are handling each of your stream objects in a -different thread and call \fBSSL_get0_connection\fR\|(3) from within that thread then -you must be careful to not to call any function that uses the connection object -at the same time as one of the other threads is also using that connection -object (with the exception of \fBSSL_accept_stream\fR\|(3) and -\&\fBSSL_get_accept_stream_queue_len\fR\|(3) which are thread-safe). -.PP -A stream object does not inherit all its settings and values from its parent -\&\fB\s-1SSL\s0\fR connection object. Therefore certain function calls that are relevant to -the connection as a whole will not work on a stream. For example the function -\&\fBSSL_get_certificate\fR\|(3) can be used to obtain a handle on the peer certificate -when called with a connection \fB\s-1SSL\s0\fR object. When called with a stream \fB\s-1SSL\s0\fR -object it will return \s-1NULL.\s0 -.SH "SIMPLE MULTI-STREAM QUIC CLIENT EXAMPLE" -.IX Header "SIMPLE MULTI-STREAM QUIC CLIENT EXAMPLE" -This section will present various source code samples demonstrating how to write -a simple multi-stream \s-1QUIC\s0 client application which connects to a server, send -some \s-1HTTP/1.0\s0 requests to it, and read back the responses. Note that \s-1HTTP/1.0\s0 -over \s-1QUIC\s0 is non-standard and will not be supported by real world servers. This -is for demonstration purposes only. -.PP -We will build on the example code for the simple blocking \s-1QUIC\s0 client that is -covered on the \fBossl\-guide\-quic\-client\-block\fR\|(7) page and we assume that you -are familiar with it. We will only describe the differences between the simple -blocking \s-1QUIC\s0 client and the multi-stream \s-1QUIC\s0 client. Although the example code -uses blocking \fB\s-1SSL\s0\fR objects, you can equally use nonblocking \fB\s-1SSL\s0\fR objects. -See \fBossl\-guide\-quic\-client\-non\-block\fR\|(7) for more information about writing a -nonblocking \s-1QUIC\s0 client. -.PP -The complete source code for this example multi-stream \s-1QUIC\s0 client is available -in the \f(CW\*(C`demos/guide\*(C'\fR directory of the OpenSSL source distribution in the file -\&\f(CW\*(C`quic\-multi\-stream.c\*(C'\fR. It is also available online at -. -.SS "Disabling the default stream" -.IX Subsection "Disabling the default stream" -As discussed above in \*(L"\s-1THE DEFAULT STREAM\*(R"\s0 we will follow the recommendation -to disable the default stream for our multi-stream client. To do this we call -the \fBSSL_set_default_stream_mode\fR\|(3) function and pass in our connection \fB\s-1SSL\s0\fR -object and the value \fB\s-1SSL_DEFAULT_STREAM_MODE_NONE\s0\fR. -.PP -.Vb 8 -\& /* -\& * We will use multiple streams so we will disable the default stream mode. -\& * This is not a requirement for using multiple streams but is recommended. -\& */ -\& if (!SSL_set_default_stream_mode(ssl, SSL_DEFAULT_STREAM_MODE_NONE)) { -\& printf("Failed to disable the default stream mode\en"); -\& goto end; -\& } -.Ve -.SS "Creating the request streams" -.IX Subsection "Creating the request streams" -For the purposes of this example we will create two different streams to send -two different \s-1HTTP\s0 requests to the server. For the purposes of demonstration the -first of these will be a bi-directional stream and the second one will be a -uni-directional one: -.PP -.Vb 10 -\& /* -\& * We create two new client initiated streams. The first will be -\& * bi\-directional, and the second will be uni\-directional. -\& */ -\& stream1 = SSL_new_stream(ssl, 0); -\& stream2 = SSL_new_stream(ssl, SSL_STREAM_FLAG_UNI); -\& if (stream1 == NULL || stream2 == NULL) { -\& printf("Failed to create streams\en"); -\& goto end; -\& } -.Ve -.SS "Writing data to the streams" -.IX Subsection "Writing data to the streams" -Once the streams are successfully created we can start writing data to them. In -this example we will be sending a different \s-1HTTP\s0 request on each stream. To -avoid repeating too much code we write a simple helper function to send an \s-1HTTP\s0 -request to a stream: -.PP -.Vb 5 -\& int write_a_request(SSL *stream, const char *request_start, -\& const char *hostname) -\& { -\& const char *request_end = "\er\en\er\en"; -\& size_t written; -\& -\& if (!SSL_write_ex(stream, request_start, strlen(request_start), &written)) -\& return 0; -\& if (!SSL_write_ex(stream, hostname, strlen(hostname), &written)) -\& return 0; -\& if (!SSL_write_ex(stream, request_end, strlen(request_end), &written)) -\& return 0; -\& -\& return 1; -\& } -.Ve -.PP -We assume the strings \fBrequest1_start\fR and \fBrequest2_start\fR hold the -appropriate \s-1HTTP\s0 requests. We can then call our helper function above to send -the requests on the two streams. For the sake of simplicity this example does -this sequentially, writing to \fBstream1\fR first and, when this is successful, -writing to \fBstream2\fR second. Remember that our client is blocking so these -calls will only return once they have been successfully completed. A real -application would not need to do these writes sequentially or in any particular -order. For example we could start two threads (one for each stream) and write -the requests to each stream simultaneously. -.PP -.Vb 5 -\& /* Write an HTTP GET request on each of our streams to the peer */ -\& if (!write_a_request(stream1, request1_start, hostname)) { -\& printf("Failed to write HTTP request on stream 1\en"); -\& goto end; -\& } -\& -\& if (!write_a_request(stream2, request2_start, hostname)) { -\& printf("Failed to write HTTP request on stream 2\en"); -\& goto end; -\& } -.Ve -.SS "Reading data from a stream" -.IX Subsection "Reading data from a stream" -In this example \fBstream1\fR is a bi-directional stream so, once we have sent the -request on it, we can attempt to read the response from the server back. Here -we just repeatedly call \fBSSL_read_ex\fR\|(3) until that function fails (indicating -either that there has been a problem, or that the peer has signalled the stream -as concluded). -.PP -.Vb 10 -\& printf("Stream 1 data:\en"); -\& /* -\& * Get up to sizeof(buf) bytes of the response from stream 1 (which is a -\& * bidirectional stream). We keep reading until the server closes the -\& * connection. -\& */ -\& while (SSL_read_ex(stream1, buf, sizeof(buf), &readbytes)) { -\& /* -\& * OpenSSL does not guarantee that the returned data is a string or -\& * that it is NUL terminated so we use fwrite() to write the exact -\& * number of bytes that we read. The data could be non\-printable or -\& * have NUL characters in the middle of it. For this simple example -\& * we\*(Aqre going to print it to stdout anyway. -\& */ -\& fwrite(buf, 1, readbytes, stdout); -\& } -\& /* In case the response didn\*(Aqt finish with a newline we add one now */ -\& printf("\en"); -.Ve -.PP -In a blocking application like this one calls to \fBSSL_read_ex\fR\|(3) will either -succeed immediately returning data that is already available, or they will block -waiting for more data to become available and return it when it is, or they will -fail with a 0 response code. -.PP -Once we exit the while loop above we know that the last call to -\&\fBSSL_read_ex\fR\|(3) gave a 0 response code so we call the \fBSSL_get_error\fR\|(3) -function to find out more details. Since this is a blocking application this -will either return \fB\s-1SSL_ERROR_SYSCALL\s0\fR or \fB\s-1SSL_ERROR_SSL\s0\fR indicating a -fundamental problem, or it will return \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR indicating that -the stream is concluded and there will be no more data available to read from -it. Care must be taken to distinguish between an error at the stream level (i.e. -a stream reset) and an error at the connection level (i.e. a connection closed). -The \fBSSL_get_stream_read_state\fR\|(3) function can be used to distinguish between -these different cases. -.PP -.Vb 12 -\& /* -\& * Check whether we finished the while loop above normally or as the -\& * result of an error. The 0 argument to SSL_get_error() is the return -\& * code we received from the SSL_read_ex() call. It must be 0 in order -\& * to get here. Normal completion is indicated by SSL_ERROR_ZERO_RETURN. In -\& * QUIC terms this means that the peer has sent FIN on the stream to -\& * indicate that no further data will be sent. -\& */ -\& switch (SSL_get_error(stream1, 0)) { -\& case SSL_ERROR_ZERO_RETURN: -\& /* Normal completion of the stream */ -\& break; -\& -\& case SSL_ERROR_SSL: -\& /* -\& * Some stream fatal error occurred. This could be because of a stream -\& * reset \- or some failure occurred on the underlying connection. -\& */ -\& switch (SSL_get_stream_read_state(stream1)) { -\& case SSL_STREAM_STATE_RESET_REMOTE: -\& printf("Stream reset occurred\en"); -\& /* The stream has been reset but the connection is still healthy. */ -\& break; -\& -\& case SSL_STREAM_STATE_CONN_CLOSED: -\& printf("Connection closed\en"); -\& /* Connection is already closed. Skip SSL_shutdown() */ -\& goto end; -\& -\& default: -\& printf("Unknown stream failure\en"); -\& break; -\& } -\& break; -\& -\& default: -\& /* Some other unexpected error occurred */ -\& printf ("Failed reading remaining data\en"); -\& break; -\& } -.Ve -.SS "Accepting an incoming stream" -.IX Subsection "Accepting an incoming stream" -Our \fBstream2\fR object that we created above was a uni-directional stream so it -cannot be used to receive data from the server. In this hypothetical example -we assume that the server initiates a new stream to send us back the data that -we requested. To do that we call \fBSSL_accept_stream\fR\|(3). Since this is a -blocking application this will wait indefinitely until the new stream has -arrived and is available for us to accept. In the event of an error it will -return \fB\s-1NULL\s0\fR. -.PP -.Vb 10 -\& /* -\& * In our hypothetical HTTP/1.0 over QUIC protocol that we are using we -\& * assume that the server will respond with a server initiated stream -\& * containing the data requested in our uni\-directional stream. This doesn\*(Aqt -\& * really make sense to do in a real protocol, but its just for -\& * demonstration purposes. -\& * -\& * We\*(Aqre using blocking mode so this will block until a stream becomes -\& * available. We could override this behaviour if we wanted to by setting -\& * the SSL_ACCEPT_STREAM_NO_BLOCK flag in the second argument below. -\& */ -\& stream3 = SSL_accept_stream(ssl, 0); -\& if (stream3 == NULL) { -\& printf("Failed to accept a new stream\en"); -\& goto end; -\& } -.Ve -.PP -We can now read data from the stream in the same way that we did for \fBstream1\fR -above. We won't repeat that here. -.SS "Cleaning up the streams" -.IX Subsection "Cleaning up the streams" -Once we have finished using our streams we can simply free them by calling -\&\fBSSL_free\fR\|(3). Optionally we could call \fBSSL_stream_conclude\fR\|(3) on them if -we want to indicate to the peer that we won't be sending them any more data, but -we don't do that in this example because we assume that the \s-1HTTP\s0 application -protocol supplies sufficient information for the peer to know when we have -finished sending request data. -.PP -We should not call \fBSSL_shutdown\fR\|(3) or \fBSSL_shutdown_ex\fR\|(3) on the stream -objects since those calls should not be used for streams. -.PP -.Vb 3 -\& SSL_free(stream1); -\& SSL_free(stream2); -\& SSL_free(stream3); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7) \fBossl\-guide\-quic\-introduction\fR\|(7), -\&\fBossl\-guide\-quic\-client\-block\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-tls-client-block.7ossl b/openssl-install/share/man/man7/ossl-guide-tls-client-block.7ossl deleted file mode 100644 index 162e4bff..00000000 --- a/openssl-install/share/man/man7/ossl-guide-tls-client-block.7ossl +++ /dev/null @@ -1,730 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-TLS-CLIENT-BLOCK 7ossl" -.TH OSSL-GUIDE-TLS-CLIENT-BLOCK 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-tls\-client\-block -\&\- OpenSSL Guide: Writing a simple blocking TLS client -.SH "SIMPLE BLOCKING TLS CLIENT EXAMPLE" -.IX Header "SIMPLE BLOCKING TLS CLIENT EXAMPLE" -This page will present various source code samples demonstrating how to write -a simple \s-1TLS\s0 client application which connects to a server, sends an \s-1HTTP/1.0\s0 -request to it, and reads back the response. -.PP -We use a blocking socket for the purposes of this example. This means that -attempting to read data from a socket that has no data available on it to read -will block (and the function will not return), until data becomes available. -For example, this can happen if we have sent our request, but we are still -waiting for the server's response. Similarly any attempts to write to a socket -that is not able to write at the moment will block until writing is possible. -.PP -This blocking behaviour simplifies the implementation of a client because you do -not have to worry about what happens if data is not yet available. The -application will simply wait until it is available. -.PP -The complete source code for this example blocking \s-1TLS\s0 client is available in -the \fBdemos/guide\fR directory of the OpenSSL source distribution in the file -\&\fBtls\-client\-block.c\fR. It is also available online at -. -.PP -We assume that you already have OpenSSL installed on your system; that you -already have some fundamental understanding of OpenSSL concepts and \s-1TLS\s0 (see -\&\fBossl\-guide\-libraries\-introduction\fR\|(7) and \fBossl\-guide\-tls\-introduction\fR\|(7)); -and that you know how to write and build C code and link it against the -libcrypto and libssl libraries that are provided by OpenSSL. It also assumes -that you have a basic understanding of \s-1TCP/IP\s0 and sockets. -.SS "Creating the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects" -.IX Subsection "Creating the SSL_CTX and SSL objects" -The first step is to create an \fB\s-1SSL_CTX\s0\fR object for our client. We use the -\&\fBSSL_CTX_new\fR\|(3) function for this purpose. We could alternatively use -\&\fBSSL_CTX_new_ex\fR\|(3) if we want to associate the \fB\s-1SSL_CTX\s0\fR with a particular -\&\fB\s-1OSSL_LIB_CTX\s0\fR (see \fBossl\-guide\-libraries\-introduction\fR\|(7) to learn about -\&\fB\s-1OSSL_LIB_CTX\s0\fR). We pass as an argument the return value of the function -\&\fBTLS_client_method\fR\|(3). You should use this method whenever you are writing a -\&\s-1TLS\s0 client. This method will automatically use \s-1TLS\s0 version negotiation to select -the highest version of the protocol that is mutually supported by both the -client and the server. -.PP -.Vb 10 -\& /* -\& * Create an SSL_CTX which we can use to create SSL objects from. We -\& * want an SSL_CTX for creating clients so we use TLS_client_method() -\& * here. -\& */ -\& ctx = SSL_CTX_new(TLS_client_method()); -\& if (ctx == NULL) { -\& printf("Failed to create the SSL_CTX\en"); -\& goto end; -\& } -.Ve -.PP -Since we are writing a client we must ensure that we verify the server's -certificate. We do this by calling the \fBSSL_CTX_set_verify\fR\|(3) function and -pass the \fB\s-1SSL_VERIFY_PEER\s0\fR value to it. The final argument to this function -is a callback that you can optionally supply to override the default handling -for certificate verification. Most applications do not need to do this so this -can safely be set to \s-1NULL\s0 to get the default handling. -.PP -.Vb 6 -\& /* -\& * Configure the client to abort the handshake if certificate -\& * verification fails. Virtually all clients should do this unless you -\& * really know what you are doing. -\& */ -\& SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL); -.Ve -.PP -In order for certificate verification to be successful you must have configured -where the trusted certificate store to be used is located (see -\&\fBossl\-guide\-tls\-introduction\fR\|(7)). In most cases you just want to use the -default store so we call \fBSSL_CTX_set_default_verify_paths\fR\|(3). -.PP -.Vb 5 -\& /* Use the default trusted certificate store */ -\& if (!SSL_CTX_set_default_verify_paths(ctx)) { -\& printf("Failed to set the default trusted certificate store\en"); -\& goto end; -\& } -.Ve -.PP -We would also like to restrict the \s-1TLS\s0 versions that we are willing to accept to -TLSv1.2 or above. \s-1TLS\s0 protocol versions earlier than that are generally to be -avoided where possible. We can do that using -\&\fBSSL_CTX_set_min_proto_version\fR\|(3): -.PP -.Vb 8 -\& /* -\& * TLSv1.1 or earlier are deprecated by IETF and are generally to be -\& * avoided if possible. We require a minimum TLS version of TLSv1.2. -\& */ -\& if (!SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION)) { -\& printf("Failed to set the minimum TLS protocol version\en"); -\& goto end; -\& } -.Ve -.PP -That is all the setup that we need to do for the \fB\s-1SSL_CTX\s0\fR, so next we need to -create an \fB\s-1SSL\s0\fR object to represent the \s-1TLS\s0 connection. In a real application -we might expect to be creating more than one \s-1TLS\s0 connection over time. In that -case we would expect to reuse the \fB\s-1SSL_CTX\s0\fR that we already created each time. -There is no need to repeat those steps. In fact it is best not to since certain -internal resources are cached in the \fB\s-1SSL_CTX\s0\fR. You will get better performance -by reusing an existing \fB\s-1SSL_CTX\s0\fR instead of creating a new one each time. -.PP -Creating the \fB\s-1SSL\s0\fR object is a simple matter of calling the \fB\fBSSL_new\fB\|(3)\fR -function and passing the \fB\s-1SSL_CTX\s0\fR we created as an argument. -.PP -.Vb 6 -\& /* Create an SSL object to represent the TLS connection */ -\& ssl = SSL_new(ctx); -\& if (ssl == NULL) { -\& printf("Failed to create the SSL object\en"); -\& goto end; -\& } -.Ve -.SS "Creating the socket and \s-1BIO\s0" -.IX Subsection "Creating the socket and BIO" -\&\s-1TLS\s0 data is transmitted over an underlying transport layer. Normally a \s-1TCP\s0 -socket. It is the application's responsibility for ensuring that the socket is -created and associated with an \s-1SSL\s0 object (via a \s-1BIO\s0). -.PP -Socket creation for use by a client is typically a 2 step process, i.e. -constructing the socket; and connecting the socket. -.PP -How to construct a socket is platform specific \- but most platforms (including -Windows) provide a \s-1POSIX\s0 compatible interface via the \fIsocket\fR function, e.g. -to create an IPv4 \s-1TCP\s0 socket: -.PP -.Vb 1 -\& int sock; -\& -\& sock = socket(AF_INET, SOCK_STREAM, 0); -\& if (sock == \-1) -\& return NULL; -.Ve -.PP -Once the socket is constructed it must be connected to the remote server. Again -the details are platform specific but most platforms (including Windows) -provide the \s-1POSIX\s0 compatible \fIconnect\fR function. For example: -.PP -.Vb 2 -\& struct sockaddr_in serveraddr; -\& struct hostent *server; -\& -\& server = gethostbyname("www.openssl.org"); -\& if (server == NULL) { -\& close(sock); -\& return NULL; -\& } -\& -\& memset(&serveraddr, 0, sizeof(serveraddr)); -\& serveraddr.sin_family = server\->h_addrtype; -\& serveraddr.sin_port = htons(443); -\& memcpy(&serveraddr.sin_addr.s_addr, server\->h_addr, server\->h_length); -\& -\& if (connect(sock, (struct sockaddr *)&serveraddr, -\& sizeof(serveraddr)) == \-1) { -\& close(sock); -\& return NULL; -\& } -.Ve -.PP -OpenSSL provides portable helper functions to do these tasks which also -integrate into the OpenSSL error system to log error data, e.g. -.PP -.Vb 3 -\& int sock = \-1; -\& BIO_ADDRINFO *res; -\& const BIO_ADDRINFO *ai = NULL; -\& -\& /* -\& * Lookup IP address info for the server. -\& */ -\& if (!BIO_lookup_ex(hostname, port, BIO_LOOKUP_CLIENT, family, SOCK_STREAM, 0, -\& &res)) -\& return NULL; -\& -\& /* -\& * Loop through all the possible addresses for the server and find one -\& * we can connect to. -\& */ -\& for (ai = res; ai != NULL; ai = BIO_ADDRINFO_next(ai)) { -\& /* -\& * Create a TCP socket. We could equally use non\-OpenSSL calls such -\& * as "socket" here for this and the subsequent connect and close -\& * functions. But for portability reasons and also so that we get -\& * errors on the OpenSSL stack in the event of a failure we use -\& * OpenSSL\*(Aqs versions of these functions. -\& */ -\& sock = BIO_socket(BIO_ADDRINFO_family(ai), SOCK_STREAM, 0, 0); -\& if (sock == \-1) -\& continue; -\& -\& /* Connect the socket to the server\*(Aqs address */ -\& if (!BIO_connect(sock, BIO_ADDRINFO_address(ai), BIO_SOCK_NODELAY)) { -\& BIO_closesocket(sock); -\& sock = \-1; -\& continue; -\& } -\& -\& /* We have a connected socket so break out of the loop */ -\& break; -\& } -\& -\& /* Free the address information resources we allocated earlier */ -\& BIO_ADDRINFO_free(res); -.Ve -.PP -See \fBBIO_lookup_ex\fR\|(3), \fBBIO_socket\fR\|(3), \fBBIO_connect\fR\|(3), -\&\fBBIO_closesocket\fR\|(3), \fBBIO_ADDRINFO_next\fR\|(3), \fBBIO_ADDRINFO_address\fR\|(3) and -\&\fBBIO_ADDRINFO_free\fR\|(3) for further information on the functions used here. In -the above example code the \fBhostname\fR and \fBport\fR variables are strings, e.g. -\&\*(L"www.example.com\*(R" and \*(L"443\*(R". Note also the use of the family variable, which -can take the values of \s-1AF_INET\s0 or \s-1AF_INET6\s0 based on the command line \-6 option, -to allow specific connections to an ipv4 or ipv6 enabled host. -.PP -Sockets created using the methods described above will automatically be blocking -sockets \- which is exactly what we want for this example. -.PP -Once the socket has been created and connected we need to associate it with a -\&\s-1BIO\s0 object: -.PP -.Vb 1 -\& BIO *bio; -\& -\& /* Create a BIO to wrap the socket */ -\& bio = BIO_new(BIO_s_socket()); -\& if (bio == NULL) { -\& BIO_closesocket(sock); -\& return NULL; -\& } -\& -\& /* -\& * Associate the newly created BIO with the underlying socket. By -\& * passing BIO_CLOSE here the socket will be automatically closed when -\& * the BIO is freed. Alternatively you can use BIO_NOCLOSE, in which -\& * case you must close the socket explicitly when it is no longer -\& * needed. -\& */ -\& BIO_set_fd(bio, sock, BIO_CLOSE); -.Ve -.PP -See \fBBIO_new\fR\|(3), \fBBIO_s_socket\fR\|(3) and \fBBIO_set_fd\fR\|(3) for further -information on these functions. -.PP -Finally we associate the \fB\s-1SSL\s0\fR object we created earlier with the \fB\s-1BIO\s0\fR using -the \fBSSL_set_bio\fR\|(3) function. Note that this passes ownership of the \fB\s-1BIO\s0\fR -object to the \fB\s-1SSL\s0\fR object. Once ownership is passed the \s-1SSL\s0 object is -responsible for its management and will free it automatically when the \fB\s-1SSL\s0\fR is -freed. So, once \fBSSL_set_bio\fR\|(3) has been been called, you should not call -\&\fBBIO_free\fR\|(3) on the \fB\s-1BIO\s0\fR. -.PP -.Vb 1 -\& SSL_set_bio(ssl, bio, bio); -.Ve -.SS "Setting the server's hostname" -.IX Subsection "Setting the server's hostname" -We have already connected our underlying socket to the server, but the client -still needs to know the server's hostname. It uses this information for 2 key -purposes and we need to set the hostname for each one. -.PP -Firstly, the server's hostname is included in the initial ClientHello message -sent by the client. This is known as the Server Name Indication (\s-1SNI\s0). This is -important because it is common for multiple hostnames to be fronted by a single -server that handles requests for all of them. In other words a single server may -have multiple hostnames associated with it and it is important to indicate which -one we want to connect to. Without this information we may get a handshake -failure, or we may get connected to the \*(L"default\*(R" server which may not be the -one we were expecting. -.PP -To set the \s-1SNI\s0 hostname data we call the \fBSSL_set_tlsext_host_name\fR\|(3) function -like this: -.PP -.Vb 8 -\& /* -\& * Tell the server during the handshake which hostname we are attempting -\& * to connect to in case the server supports multiple hosts. -\& */ -\& if (!SSL_set_tlsext_host_name(ssl, hostname)) { -\& printf("Failed to set the SNI hostname\en"); -\& goto end; -\& } -.Ve -.PP -Here the \f(CW\*(C`hostname\*(C'\fR argument is a string representing the hostname of the -server, e.g. \*(L"www.example.com\*(R". -.PP -Secondly, we need to tell OpenSSL what hostname we expect to see in the -certificate coming back from the server. This is almost always the same one that -we asked for in the original request. This is important because, without this, -we do not verify that the hostname in the certificate is what we expect it to be -and any certificate is acceptable unless your application explicitly checks this -itself. We do this via the \fBSSL_set1_host\fR\|(3) function: -.PP -.Vb 10 -\& /* -\& * Ensure we check during certificate verification that the server has -\& * supplied a certificate for the hostname that we were expecting. -\& * Virtually all clients should do this unless you really know what you -\& * are doing. -\& */ -\& if (!SSL_set1_host(ssl, hostname)) { -\& printf("Failed to set the certificate verification hostname"); -\& goto end; -\& } -.Ve -.PP -All of the above steps must happen before we attempt to perform the handshake -otherwise they will have no effect. -.SS "Performing the handshake" -.IX Subsection "Performing the handshake" -Before we can start sending or receiving application data over a \s-1TLS\s0 connection -the \s-1TLS\s0 handshake must be performed. We can do this explicitly via the -\&\fBSSL_connect\fR\|(3) function. -.PP -.Vb 12 -\& /* Do the handshake with the server */ -\& if (SSL_connect(ssl) < 1) { -\& printf("Failed to connect to the server\en"); -\& /* -\& * If the failure is due to a verification error we can get more -\& * information about it from SSL_get_verify_result(). -\& */ -\& if (SSL_get_verify_result(ssl) != X509_V_OK) -\& printf("Verify error: %s\en", -\& X509_verify_cert_error_string(SSL_get_verify_result(ssl))); -\& goto end; -\& } -.Ve -.PP -The \fBSSL_connect\fR\|(3) function can return 1, 0 or less than 0. Only a return -value of 1 is considered a success. For a simple blocking client we only need -to concern ourselves with whether the call was successful or not. Anything else -indicates that we have failed to connect to the server. -.PP -A common cause of failures at this stage is due to a problem verifying the -server's certificate. For example if the certificate has expired, or it is not -signed by a \s-1CA\s0 in our trusted certificate store. We can use the -\&\fBSSL_get_verify_result\fR\|(3) function to find out more information about the -verification failure. A return value of \fBX509_V_OK\fR indicates that the -verification was successful (so the connection error must be due to some other -cause). Otherwise we use the \fBX509_verify_cert_error_string\fR\|(3) function to get -a human readable error message. -.SS "Sending and receiving data" -.IX Subsection "Sending and receiving data" -Once the handshake is complete we are able to send and receive application data. -Exactly what data is sent and in what order is usually controlled by some -application level protocol. In this example we are using \s-1HTTP 1.0\s0 which is a -very simple request and response protocol. The client sends a request to the -server. The server sends the response data and then immediately closes down the -connection. -.PP -To send data to the server we use the \fBSSL_write_ex\fR\|(3) function and to receive -data from the server we use the \fBSSL_read_ex\fR\|(3) function. In \s-1HTTP 1.0\s0 the -client always writes data first. Our \s-1HTTP\s0 request will include the hostname that -we are connecting to. For simplicity, we write the \s-1HTTP\s0 request in three -chunks. First we write the start of the request. Secondly we write the hostname -we are sending the request to. Finally we send the end of the request. -.PP -.Vb 3 -\& size_t written; -\& const char *request_start = "GET / HTTP/1.0\er\enConnection: close\er\enHost: "; -\& const char *request_end = "\er\en\er\en"; -\& -\& /* Write an HTTP GET request to the peer */ -\& if (!SSL_write_ex(ssl, request_start, strlen(request_start), &written)) { -\& printf("Failed to write start of HTTP request\en"); -\& goto end; -\& } -\& if (!SSL_write_ex(ssl, hostname, strlen(hostname), &written)) { -\& printf("Failed to write hostname in HTTP request\en"); -\& goto end; -\& } -\& if (!SSL_write_ex(ssl, request_end, strlen(request_end), &written)) { -\& printf("Failed to write end of HTTP request\en"); -\& goto end; -\& } -.Ve -.PP -The \fBSSL_write_ex\fR\|(3) function returns 0 if it fails and 1 if it is successful. -If it is successful then we can proceed to waiting for a response from the -server. -.PP -.Vb 2 -\& size_t readbytes; -\& char buf[160]; -\& -\& /* -\& * Get up to sizeof(buf) bytes of the response. We keep reading until the -\& * server closes the connection. -\& */ -\& while (SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) { -\& /* -\& * OpenSSL does not guarantee that the returned data is a string or -\& * that it is NUL terminated so we use fwrite() to write the exact -\& * number of bytes that we read. The data could be non\-printable or -\& * have NUL characters in the middle of it. For this simple example -\& * we\*(Aqre going to print it to stdout anyway. -\& */ -\& fwrite(buf, 1, readbytes, stdout); -\& } -\& /* In case the response didn\*(Aqt finish with a newline we add one now */ -\& printf("\en"); -.Ve -.PP -We use the \fBSSL_read_ex\fR\|(3) function to read the response. We don't know -exactly how much data we are going to receive back so we enter a loop reading -blocks of data from the server and printing each block that we receive to the -screen. The loop ends as soon as \fBSSL_read_ex\fR\|(3) returns 0 \- meaning that it -failed to read any data. -.PP -A failure to read data could mean that there has been some error, or it could -simply mean that server has sent all the data that it wants to send and has -indicated that it has finished by sending a \*(L"close_notify\*(R" alert. This alert is -a \s-1TLS\s0 protocol level message indicating that the endpoint has finished sending -all of its data and it will not send any more. Both of these conditions result -in a 0 return value from \fBSSL_read_ex\fR\|(3) and we need to use the function -\&\fBSSL_get_error\fR\|(3) to determine the cause of the 0 return value. -.PP -.Vb 10 -\& /* -\& * Check whether we finished the while loop above normally or as the -\& * result of an error. The 0 argument to SSL_get_error() is the return -\& * code we received from the SSL_read_ex() call. It must be 0 in order -\& * to get here. Normal completion is indicated by SSL_ERROR_ZERO_RETURN. -\& */ -\& if (SSL_get_error(ssl, 0) != SSL_ERROR_ZERO_RETURN) { -\& /* -\& * Some error occurred other than a graceful close down by the -\& * peer -\& */ -\& printf ("Failed reading remaining data\en"); -\& goto end; -\& } -.Ve -.PP -If \fBSSL_get_error\fR\|(3) returns \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR then we know that the -server has finished sending its data. Otherwise an error has occurred. -.SS "Shutting down the connection" -.IX Subsection "Shutting down the connection" -Once we have finished reading data from the server then we are ready to close -the connection down. We do this via the \fBSSL_shutdown\fR\|(3) function which has -the effect of sending a \s-1TLS\s0 protocol level message (a \*(L"close_notify\*(R" alert) to -the server saying that we have finished writing data: -.PP -.Vb 10 -\& /* -\& * The peer already shutdown gracefully (we know this because of the -\& * SSL_ERROR_ZERO_RETURN above). We should do the same back. -\& */ -\& ret = SSL_shutdown(ssl); -\& if (ret < 1) { -\& /* -\& * ret < 0 indicates an error. ret == 0 would be unexpected here -\& * because that means "we\*(Aqve sent a close_notify and we\*(Aqre waiting -\& * for one back". But we already know we got one from the peer -\& * because of the SSL_ERROR_ZERO_RETURN above. -\& */ -\& printf("Error shutting down\en"); -\& goto end; -\& } -.Ve -.PP -The \fBSSL_shutdown\fR\|(3) function will either return 1, 0, or less than 0. A -return value of 1 is a success, and a return value less than 0 is an error. More -precisely a return value of 1 means that we have sent a \*(L"close_notify\*(R" alert to -the server, and that we have also received one back. A return value of 0 means -that we have sent a \*(L"close_notify\*(R" alert to the server, but we have not yet -received one back. Usually in this scenario you would call \fBSSL_shutdown\fR\|(3) -again which (with a blocking socket) would block until the \*(L"close_notify\*(R" is -received. However in this case we already know that the server has sent us a -\&\*(L"close_notify\*(R" because of the \s-1SSL_ERROR_ZERO_RETURN\s0 that we received from the -call to \fBSSL_read_ex\fR\|(3). So this scenario should never happen in practice. We -just treat it as an error in this example. -.SS "Final clean up" -.IX Subsection "Final clean up" -Before the application exits we have to clean up some memory that we allocated. -If we are exiting due to an error we might also want to display further -information about that error if it is available to the user: -.PP -.Vb 10 -\& /* Success! */ -\& res = EXIT_SUCCESS; -\& end: -\& /* -\& * If something bad happened then we will dump the contents of the -\& * OpenSSL error stack to stderr. There might be some useful diagnostic -\& * information there. -\& */ -\& if (res == EXIT_FAILURE) -\& ERR_print_errors_fp(stderr); -\& -\& /* -\& * Free the resources we allocated. We do not free the BIO object here -\& * because ownership of it was immediately transferred to the SSL object -\& * via SSL_set_bio(). The BIO will be freed when we free the SSL object. -\& */ -\& SSL_free(ssl); -\& SSL_CTX_free(ctx); -\& return res; -.Ve -.PP -To display errors we make use of the \fBERR_print_errors_fp\fR\|(3) function which -simply dumps out the contents of any errors on the OpenSSL error stack to the -specified location (in this case \fIstderr\fR). -.PP -We need to free up the \fB\s-1SSL\s0\fR object that we created for the connection via the -\&\fBSSL_free\fR\|(3) function. Also, since we are not going to be creating any more -\&\s-1TLS\s0 connections we must also free up the \fB\s-1SSL_CTX\s0\fR via a call to -\&\fBSSL_CTX_free\fR\|(3). -.SH "TROUBLESHOOTING" -.IX Header "TROUBLESHOOTING" -There are a number of things that might go wrong when running the demo -application. This section describes some common things you might encounter. -.SS "Failure to connect the underlying socket" -.IX Subsection "Failure to connect the underlying socket" -This could occur for numerous reasons. For example if there is a problem in the -network route between the client and the server; or a firewall is blocking the -communication; or the server is not in \s-1DNS.\s0 Check the network configuration. -.SS "Verification failure of the server certificate" -.IX Subsection "Verification failure of the server certificate" -A verification failure of the server certificate would result in a failure when -running the \fBSSL_connect\fR\|(3) function. \fBERR_print_errors_fp\fR\|(3) would display -an error which would look something like this: -.PP -.Vb 2 -\& Verify error: unable to get local issuer certificate -\& 40E74AF1F47F0000:error:0A000086:SSL routines:tls_post_process_server_certificate:certificate verify failed:ssl/statem/statem_clnt.c:2069: -.Ve -.PP -A server certificate verification failure could be caused for a number of -reasons. For example -.IP "Failure to correctly setup the trusted certificate store" 4 -.IX Item "Failure to correctly setup the trusted certificate store" -See the page \fBossl\-guide\-tls\-introduction\fR\|(7) and check that your trusted -certificate store is correctly configured -.IP "Unrecognised \s-1CA\s0" 4 -.IX Item "Unrecognised CA" -If the \s-1CA\s0 used by the server's certificate is not in the trusted certificate -store for the client then this will cause a verification failure during -connection. Often this can occur if the server is using a self-signed -certificate (i.e. a test certificate that has not been signed by a \s-1CA\s0 at all). -.IP "Missing intermediate CAs" 4 -.IX Item "Missing intermediate CAs" -This is a server misconfiguration where the client has the relevant root \s-1CA\s0 in -its trust store, but the server has not supplied all of the intermediate \s-1CA\s0 -certificates between that root \s-1CA\s0 and the server's own certificate. Therefore -a trust chain cannot be established. -.IP "Mismatched hostname" 4 -.IX Item "Mismatched hostname" -If for some reason the hostname of the server that the client is expecting does -not match the hostname in the certificate then this will cause verification to -fail. -.IP "Expired certificate" 4 -.IX Item "Expired certificate" -The date that the server's certificate is valid to has passed. -.PP -The \*(L"unable to get local issuer certificate\*(R" we saw in the example above means -that we have been unable to find the issuer of the server's certificate (or one -of its intermediate \s-1CA\s0 certificates) in our trusted certificate store (e.g. -because the trusted certificate store is misconfigured, or there are missing -intermediate CAs, or the issuer is simply unrecognised). -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-tls\-client\-non\-block\fR\|(7) to read a tutorial on how to modify -the client developed on this page to support a nonblocking socket. -.PP -See \fBossl\-guide\-tls\-server\-block\fR\|(7) for a tutorial on how to implement a -simple \s-1TLS\s0 server handling one client at a time over a blocking socket. -.PP -See \fBossl\-guide\-quic\-client\-block\fR\|(7) to read a tutorial on how to modify the -client developed on this page to support \s-1QUIC\s0 instead of \s-1TLS.\s0 -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7), \fBossl\-guide\-tls\-introduction\fR\|(7), -\&\fBossl\-guide\-tls\-client\-non\-block\fR\|(7), \fBossl\-guide\-quic\-client\-block\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-tls-client-non-block.7ossl b/openssl-install/share/man/man7/ossl-guide-tls-client-non-block.7ossl deleted file mode 100644 index d4cb47f9..00000000 --- a/openssl-install/share/man/man7/ossl-guide-tls-client-non-block.7ossl +++ /dev/null @@ -1,513 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-TLS-CLIENT-NON-BLOCK 7ossl" -.TH OSSL-GUIDE-TLS-CLIENT-NON-BLOCK 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-tls\-client\-non\-block -\&\- OpenSSL Guide: Writing a simple nonblocking TLS client -.SH "SIMPLE NONBLOCKING TLS CLIENT EXAMPLE" -.IX Header "SIMPLE NONBLOCKING TLS CLIENT EXAMPLE" -This page will build on the example developed on the -\&\fBossl\-guide\-tls\-client\-block\fR\|(7) page which demonstrates how to write a simple -blocking \s-1TLS\s0 client. On this page we will amend that demo code so that it -supports a nonblocking socket. -.PP -The complete source code for this example nonblocking \s-1TLS\s0 client is available -in the \fBdemos/guide\fR directory of the OpenSSL source distribution in the file -\&\fBtls\-client\-non\-block.c\fR. It is also available online at -. -.PP -As we saw in the previous example a blocking socket is one which waits (blocks) -until data is available to read if you attempt to read from it when there is no -data yet. Similarly it waits when writing if the socket is currently unable to -write at the moment. This can simplify the development of code because you do -not have to worry about what to do in these cases. The execution of the code -will simply stop until it is able to continue. However in many cases you do not -want this behaviour. Rather than stopping and waiting your application may need -to go and do other tasks whilst the socket is unable to read/write, for example -updating a \s-1GUI\s0 or performing operations on some other socket. -.PP -With a nonblocking socket attempting to read or write to a socket that is -currently unable to read or write will return immediately with a non-fatal -error. Although OpenSSL does the reading/writing to the socket this nonblocking -behaviour is propagated up to the application so that OpenSSL I/O functions such -as \fBSSL_read_ex\fR\|(3) or \fBSSL_write_ex\fR\|(3) will not block. -.PP -Since this page is building on the example developed on the -\&\fBossl\-guide\-tls\-client\-block\fR\|(7) page we assume that you are familiar with it -and we only explain how this example differs. -.SS "Setting the socket to be nonblocking" -.IX Subsection "Setting the socket to be nonblocking" -The first step in writing an application that supports nonblocking is to set -the socket into nonblocking mode. A socket will be default be blocking. The -exact details on how to do this can differ from one platform to another. -Fortunately OpenSSL offers a portable function that will do this for you: -.PP -.Vb 5 -\& /* Set to nonblocking mode */ -\& if (!BIO_socket_nbio(sock, 1)) { -\& sock = \-1; -\& continue; -\& } -.Ve -.PP -You do not have to use OpenSSL's function for this. You can of course directly -call whatever functions that your Operating System provides for this purpose on -your platform. -.SS "Performing work while waiting for the socket" -.IX Subsection "Performing work while waiting for the socket" -In a nonblocking application you will need work to perform in the event that -we want to read or write to the socket, but we are currently unable to. In fact -this is the whole point of using a nonblocking socket, i.e. to give the -application the opportunity to do something else. Whatever it is that the -application has to do, it must also be prepared to come back and retry the -operation that it previously attempted periodically to see if it can now -complete. Ideally it would only do this in the event that the state of the -underlying socket has actually changed (e.g. become readable where it wasn't -before), but this does not have to be the case. It can retry at any time. -.PP -Note that it is important that you retry exactly the same operation that you -tried last time. You cannot start something new. For example if you were -attempting to write the text \*(L"Hello World\*(R" and the operation failed because the -socket is currently unable to write, then you cannot then attempt to write -some other text when you retry the operation. -.PP -In this demo application we will create a helper function which simulates doing -other work. In fact, for the sake of simplicity, it will do nothing except wait -for the state of the socket to change. -.PP -We call our function \f(CW\*(C`wait_for_activity()\*(C'\fR because all it does is wait until -the underlying socket has become readable or writeable when it wasn't before. -.PP -.Vb 4 -\& static void wait_for_activity(SSL *ssl, int write) -\& { -\& fd_set fds; -\& int width, sock; -\& -\& /* Get hold of the underlying file descriptor for the socket */ -\& sock = SSL_get_fd(ssl); -\& -\& FD_ZERO(&fds); -\& FD_SET(sock, &fds); -\& width = sock + 1; -\& -\& /* -\& * Wait until the socket is writeable or readable. We use select here -\& * for the sake of simplicity and portability, but you could equally use -\& * poll/epoll or similar functions -\& * -\& * NOTE: For the purposes of this demonstration code this effectively -\& * makes this demo block until it has something more useful to do. In a -\& * real application you probably want to go and do other work here (e.g. -\& * update a GUI, or service other connections). -\& * -\& * Let\*(Aqs say for example that you want to update the progress counter on -\& * a GUI every 100ms. One way to do that would be to add a 100ms timeout -\& * in the last parameter to "select" below. Then, when select returns, -\& * you check if it did so because of activity on the file descriptors or -\& * because of the timeout. If it is due to the timeout then update the -\& * GUI and then restart the "select". -\& */ -\& if (write) -\& select(width, NULL, &fds, NULL, NULL); -\& else -\& select(width, &fds, NULL, NULL, NULL); -\& } -.Ve -.PP -In this example we are using the \f(CW\*(C`select\*(C'\fR function because it is very simple -to use and is available on most Operating Systems. However you could use any -other similar function to do the same thing. \f(CW\*(C`select\*(C'\fR waits for the state of -the underlying socket(s) to become readable/writeable before returning. It also -supports a \*(L"timeout\*(R" (as do most other similar functions) so in your own -applications you can make use of this to periodically wake up and perform work -while waiting for the socket state to change. But we don't use that timeout -capability in this example for the sake of simplicity. -.SS "Handling errors from OpenSSL I/O functions" -.IX Subsection "Handling errors from OpenSSL I/O functions" -An application that uses a nonblocking socket will need to be prepared to -handle errors returned from OpenSSL I/O functions such as \fBSSL_read_ex\fR\|(3) or -\&\fBSSL_write_ex\fR\|(3). Errors may be fatal (for example because the underlying -connection has failed), or non-fatal (for example because we are trying to read -from the underlying socket but the data has not yet arrived from the peer). -.PP -\&\fBSSL_read_ex\fR\|(3) and \fBSSL_write_ex\fR\|(3) will return 0 to indicate an error and -\&\fBSSL_read\fR\|(3) and \fBSSL_write\fR\|(3) will return 0 or a negative value to indicate -an error. \fBSSL_shutdown\fR\|(3) will return a negative value to incidate an error. -.PP -In the event of an error an application should call \fBSSL_get_error\fR\|(3) to find -out what type of error has occurred. If the error is non-fatal and can be -retried then \fBSSL_get_error\fR\|(3) will return \fB\s-1SSL_ERROR_WANT_READ\s0\fR or -\&\fB\s-1SSL_ERROR_WANT_WRITE\s0\fR depending on whether OpenSSL wanted to read to or write -from the socket but was unable to. Note that a call to \fBSSL_read_ex\fR\|(3) or -\&\fBSSL_read\fR\|(3) can still generate \fB\s-1SSL_ERROR_WANT_WRITE\s0\fR because OpenSSL -may need to write protocol messages (such as to update cryptographic keys) even -if the application is only trying to read data. Similarly calls to -\&\fBSSL_write_ex\fR\|(3) or \fBSSL_write\fR\|(3) might generate \fB\s-1SSL_ERROR_WANT_READ\s0\fR. -.PP -Another type of non-fatal error that may occur is \fB\s-1SSL_ERROR_ZERO_RETURN\s0\fR. This -indicates an \s-1EOF\s0 (End-Of-File) which can occur if you attempt to read data from -an \fB\s-1SSL\s0\fR object but the peer has indicated that it will not send any more data -on it. In this case you may still want to write data to the connection but you -will not receive any more data. -.PP -Fatal errors that may occur are \fB\s-1SSL_ERROR_SYSCALL\s0\fR and \fB\s-1SSL_ERROR_SSL\s0\fR. These -indicate that the underlying connection has failed. You should not attempt to -shut it down with \fBSSL_shutdown\fR\|(3). \fB\s-1SSL_ERROR_SYSCALL\s0\fR indicates that -OpenSSL attempted to make a syscall that failed. You can consult \fBerrno\fR for -further details. \fB\s-1SSL_ERROR_SSL\s0\fR indicates that some OpenSSL error occurred. You -can consult the OpenSSL error stack for further details (for example by calling -\&\fBERR_print_errors\fR\|(3) to print out details of errors that have occurred). -.PP -In our demo application we will write a function to handle these errors from -OpenSSL I/O functions: -.PP -.Vb 7 -\& static int handle_io_failure(SSL *ssl, int res) -\& { -\& switch (SSL_get_error(ssl, res)) { -\& case SSL_ERROR_WANT_READ: -\& /* Temporary failure. Wait until we can read and try again */ -\& wait_for_activity(ssl, 0); -\& return 1; -\& -\& case SSL_ERROR_WANT_WRITE: -\& /* Temporary failure. Wait until we can write and try again */ -\& wait_for_activity(ssl, 1); -\& return 1; -\& -\& case SSL_ERROR_ZERO_RETURN: -\& /* EOF */ -\& return 0; -\& -\& case SSL_ERROR_SYSCALL: -\& return \-1; -\& -\& case SSL_ERROR_SSL: -\& /* -\& * If the failure is due to a verification error we can get more -\& * information about it from SSL_get_verify_result(). -\& */ -\& if (SSL_get_verify_result(ssl) != X509_V_OK) -\& printf("Verify error: %s\en", -\& X509_verify_cert_error_string(SSL_get_verify_result(ssl))); -\& return \-1; -\& -\& default: -\& return \-1; -\& } -\& } -.Ve -.PP -This function takes as arguments the \fB\s-1SSL\s0\fR object that represents the -connection, as well as the return code from the I/O function that failed. In -the event of a non-fatal failure, it waits until a retry of the I/O operation -might succeed (by using the \f(CW\*(C`wait_for_activity()\*(C'\fR function that we developed -in the previous section). It returns 1 in the event of a non-fatal error -(except \s-1EOF\s0), 0 in the event of \s-1EOF,\s0 or \-1 if a fatal error occurred. -.SS "Creating the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects" -.IX Subsection "Creating the SSL_CTX and SSL objects" -In order to connect to a server we must create \fB\s-1SSL_CTX\s0\fR and \fB\s-1SSL\s0\fR objects for -this. The steps do this are the same as for a blocking client and are explained -on the \fBossl\-guide\-tls\-client\-block\fR\|(7) page. We won't repeat that information -here. -.SS "Performing the handshake" -.IX Subsection "Performing the handshake" -As in the demo for a blocking \s-1TLS\s0 client we use the \fBSSL_connect\fR\|(3) function -to perform the \s-1TLS\s0 handshake with the server. Since we are using a nonblocking -socket it is very likely that calls to this function will fail with a non-fatal -error while we are waiting for the server to respond to our handshake messages. -In such a case we must retry the same \fBSSL_connect\fR\|(3) call at a later time. -In this demo we this in a loop: -.PP -.Vb 7 -\& /* Do the handshake with the server */ -\& while ((ret = SSL_connect(ssl)) != 1) { -\& if (handle_io_failure(ssl, ret) == 1) -\& continue; /* Retry */ -\& printf("Failed to connect to server\en"); -\& goto end; /* Cannot retry: error */ -\& } -.Ve -.PP -We continually call \fBSSL_connect\fR\|(3) until it gives us a success response. -Otherwise we use the \f(CW\*(C`handle_io_failure()\*(C'\fR function that we created earlier to -work out what we should do next. Note that we do not expect an \s-1EOF\s0 to occur at -this stage, so such a response is treated in the same way as a fatal error. -.SS "Sending and receiving data" -.IX Subsection "Sending and receiving data" -As with the blocking \s-1TLS\s0 client demo we use the \fBSSL_write_ex\fR\|(3) function to -send data to the server. As with \fBSSL_connect\fR\|(3) above, because we are using -a nonblocking socket, this call could fail with a non-fatal error. In that case -we should retry exactly the same \fBSSL_write_ex\fR\|(3) call again. Note that the -parameters must be \fIexactly\fR the same, i.e. the same pointer to the buffer to -write with the same length. You must not attempt to send different data on a -retry. An optional mode does exist (\fB\s-1SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER\s0\fR) -which will configure OpenSSL to allow the buffer being written to change from -one retry to the next. However, in this case, you must still retry exactly the -same data \- even though the buffer that contains that data may change location. -See \fBSSL_CTX_set_mode\fR\|(3) for further details. As in the \s-1TLS\s0 client -blocking tutorial (\fBossl\-guide\-tls\-client\-block\fR\|(7)) we write the request -in three chunks. -.PP -.Vb 10 -\& /* Write an HTTP GET request to the peer */ -\& while (!SSL_write_ex(ssl, request_start, strlen(request_start), &written)) { -\& if (handle_io_failure(ssl, 0) == 1) -\& continue; /* Retry */ -\& printf("Failed to write start of HTTP request\en"); -\& goto end; /* Cannot retry: error */ -\& } -\& while (!SSL_write_ex(ssl, hostname, strlen(hostname), &written)) { -\& if (handle_io_failure(ssl, 0) == 1) -\& continue; /* Retry */ -\& printf("Failed to write hostname in HTTP request\en"); -\& goto end; /* Cannot retry: error */ -\& } -\& while (!SSL_write_ex(ssl, request_end, strlen(request_end), &written)) { -\& if (handle_io_failure(ssl, 0) == 1) -\& continue; /* Retry */ -\& printf("Failed to write end of HTTP request\en"); -\& goto end; /* Cannot retry: error */ -\& } -.Ve -.PP -On a write we do not expect to see an \s-1EOF\s0 response so we treat that case in the -same way as a fatal error. -.PP -Reading a response back from the server is similar: -.PP -.Vb 10 -\& do { -\& /* -\& * Get up to sizeof(buf) bytes of the response. We keep reading until -\& * the server closes the connection. -\& */ -\& while (!eof && !SSL_read_ex(ssl, buf, sizeof(buf), &readbytes)) { -\& switch (handle_io_failure(ssl, 0)) { -\& case 1: -\& continue; /* Retry */ -\& case 0: -\& eof = 1; -\& continue; -\& case \-1: -\& default: -\& printf("Failed reading remaining data\en"); -\& goto end; /* Cannot retry: error */ -\& } -\& } -\& /* -\& * OpenSSL does not guarantee that the returned data is a string or -\& * that it is NUL terminated so we use fwrite() to write the exact -\& * number of bytes that we read. The data could be non\-printable or -\& * have NUL characters in the middle of it. For this simple example -\& * we\*(Aqre going to print it to stdout anyway. -\& */ -\& if (!eof) -\& fwrite(buf, 1, readbytes, stdout); -\& } while (!eof); -\& /* In case the response didn\*(Aqt finish with a newline we add one now */ -\& printf("\en"); -.Ve -.PP -The main difference this time is that it is valid for us to receive an \s-1EOF\s0 -response when trying to read data from the server. This will occur when the -server closes down the connection after sending all the data in its response. -.PP -In this demo we just print out all the data we've received back in the response -from the server. We continue going around the loop until we either encounter a -fatal error, or we receive an \s-1EOF\s0 (indicating a graceful finish). -.SS "Shutting down the connection" -.IX Subsection "Shutting down the connection" -As in the \s-1TLS\s0 blocking example we must shutdown the connection when we are -finished with it. -.PP -If our application was initiating the shutdown then we would expect to see -\&\fBSSL_shutdown\fR\|(3) give a return value of 0, and then we would continue to call -it until we received a return value of 1 (meaning we have successfully completed -the shutdown). In this particular example we don't expect \fBSSL_shutdown()\fR to -return 0 because we have already received \s-1EOF\s0 from the server indicating that it -has shutdown already. So we just keep calling it until \fBSSL_shutdown()\fR returns 1. -Since we are using a nonblocking socket we might expect to have to retry this -operation several times. If \fBSSL_shutdown\fR\|(3) returns a negative result then we -must call \fBSSL_get_error\fR\|(3) to work out what to do next. We use our -\&\fBhandle_io_failure()\fR function that we developed earlier for this: -.PP -.Vb 10 -\& /* -\& * The peer already shutdown gracefully (we know this because of the -\& * SSL_ERROR_ZERO_RETURN (i.e. EOF) above). We should do the same back. -\& */ -\& while ((ret = SSL_shutdown(ssl)) != 1) { -\& if (ret < 0 && handle_io_failure(ssl, ret) == 1) -\& continue; /* Retry */ -\& /* -\& * ret == 0 is unexpected here because that means "we\*(Aqve sent a -\& * close_notify and we\*(Aqre waiting for one back". But we already know -\& * we got one from the peer because of the SSL_ERROR_ZERO_RETURN -\& * (i.e. EOF) above. -\& */ -\& printf("Error shutting down\en"); -\& goto end; /* Cannot retry: error */ -\& } -.Ve -.SS "Final clean up" -.IX Subsection "Final clean up" -As with the blocking \s-1TLS\s0 client example, once our connection is finished with we -must free it. The steps to do this for this example are the same as for the -blocking example, so we won't repeat it here. -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-tls\-client\-block\fR\|(7) to read a tutorial on how to write a -blocking \s-1TLS\s0 client. See \fBossl\-guide\-quic\-client\-block\fR\|(7) to see how to do the -same thing for a \s-1QUIC\s0 client. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7), \fBossl\-guide\-tls\-introduction\fR\|(7), -\&\fBossl\-guide\-tls\-client\-block\fR\|(7), \fBossl\-guide\-quic\-client\-block\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-tls-introduction.7ossl b/openssl-install/share/man/man7/ossl-guide-tls-introduction.7ossl deleted file mode 100644 index 551929b4..00000000 --- a/openssl-install/share/man/man7/ossl-guide-tls-introduction.7ossl +++ /dev/null @@ -1,454 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-TLS-INTRODUCTION 7ossl" -.TH OSSL-GUIDE-TLS-INTRODUCTION 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-tls\-introduction -\&\- OpenSSL Guide: An introduction to SSL/TLS in OpenSSL -.SH "INTRODUCTION" -.IX Header "INTRODUCTION" -This page will provide an introduction to some basic \s-1SSL/TLS\s0 concepts and -background and how it is used within OpenSSL. It assumes that you have a basic -understanding of \s-1TCP/IP\s0 and sockets. -.SH "WHAT IS TLS?" -.IX Header "WHAT IS TLS?" -\&\s-1TLS\s0 stands for Transport Layer Security. \s-1TLS\s0 allows applications to securely -communicate with each other across a network such that the confidentiality of -the information exchanged is protected (i.e. it prevents eavesdroppers from -listening in to the communication). Additionally it protects the integrity of -the information exchanged to prevent an attacker from changing it. Finally it -provides authentication so that one or both parties can be sure that they are -talking to who they think they are talking to and not some imposter. -.PP -Sometimes \s-1TLS\s0 is referred to by its predecessor's name \s-1SSL\s0 (Secure Sockets -Layer). OpenSSL dates from a time when the \s-1SSL\s0 name was still in common use and -hence many of the functions and names used by OpenSSL contain the \*(L"\s-1SSL\*(R"\s0 -abbreviation. Nonetheless OpenSSL contains a fully fledged \s-1TLS\s0 implementation. -.PP -\&\s-1TLS\s0 is based on a client/server model. The application that initiates a -communication is known as the client. The application that responds to a -remotely initiated communication is the server. The term \*(L"endpoint\*(R" refers to -either of the client or the server in a communication. The term \*(L"peer\*(R" refers to -the endpoint at the other side of the communication that we are currently -referring to. So if we are currently talking about the client then the peer -would be the server. -.PP -\&\s-1TLS\s0 is a standardised protocol and there are numerous different implementations -of it. Due to the standards an OpenSSL client or server is able to communicate -seamlessly with an application using some different implementation of \s-1TLS. TLS\s0 -(and its predecessor \s-1SSL\s0) have been around for a significant period of time and -the protocol has undergone various changes over the years. Consequently there -are different versions of the protocol available. \s-1TLS\s0 includes the ability to -perform version negotiation so that the highest protocol version that the client -and server share in common is used. -.PP -\&\s-1TLS\s0 acts as a security layer over some lower level transport protocol. Typically -the transport layer will be \s-1TCP.\s0 -.SH "SSL AND TLS VERSIONS" -.IX Header "SSL AND TLS VERSIONS" -\&\s-1SSL\s0 was initially developed by Netscape Communications and its first publicly -released version was SSLv2 in 1995. Note that SSLv1 was never publicly released. -SSLv3 came along quickly afterwards in 1996. Subsequently development of the -protocol moved to the \s-1IETF\s0 which released the first version of \s-1TLS\s0 (TLSv1.0) in -1999 as \s-1RFC2246.\s0 TLSv1.1 was released in 2006 as \s-1RFC4346\s0 and TLSv1.2 came along -in 2008 as \s-1RFC5246.\s0 The most recent version of the standard is TLSv1.3 which -was released in 2018 as \s-1RFC8446.\s0 -.PP -Today TLSv1.3 and TLSv1.2 are the most commonly deployed versions of the -protocol. The \s-1IETF\s0 have formally deprecated TLSv1.1 and TLSv1.0, so anything -below TLSv1.2 should be avoided since the older protocol versions are -susceptible to security problems. -.PP -OpenSSL does not support SSLv2 (it was removed in OpenSSL 1.1.0). Support for -SSLv3 is available as a compile time option \- but it is not built by default. -Support for TLSv1.0, TLSv1.1, TLSv1.2 and TLSv1.3 are all available by default -in a standard build of OpenSSL. However special run-time configuration is -required in order to make TLSv1.0 and TLSv1.1 work successfully. -.PP -OpenSSL will always try to negotiate the highest protocol version that it has -been configured to support. In most cases this will mean either TLSv1.3 or -TLSv1.2 is chosen. -.SH "CERTIFICATES" -.IX Header "CERTIFICATES" -In order for a client to establish a connection to a server it must authenticate -the identity of that server, i.e. it needs to confirm that the server is really -the server that it claims to be and not some imposter. In order to do this the -server will send to the client a digital certificate (also commonly referred to -as an X.509 certificate). The certificate contains various information about the -server including its full \s-1DNS\s0 hostname. Also within the certificate is the -server's public key. The server operator will have a private key which is -linked to the public key and must not be published. -.PP -Along with the certificate the server will also send to the client proof that it -knows the private key associated with the public key in the certificate. It does -this by digitally signing a message to the client using that private key. The -client can verify the signature using the public key from the certificate. If -the signature verifies successfully then the client knows that the server is in -possession of the correct private key. -.PP -The certificate that the server sends will also be signed by a Certificate -Authority. The Certificate Authority (commonly known as a \s-1CA\s0) is a third party -organisation that is responsible for verifying the information in the server's -certificate (including its \s-1DNS\s0 hostname). The \s-1CA\s0 should only sign the -certificate if it has been able to confirm that the server operator does indeed -have control of the server associated with its \s-1DNS\s0 hostname and that the server -operator has control of the private key. -.PP -In this way, if the client trusts the \s-1CA\s0 that has signed the server's -certificate and it can verify that the server has the right private key then it -can trust that the server truly does represent the \s-1DNS\s0 hostname given in the -certificate. The client must also verify that the hostname given in the -certificate matches the hostname that it originally sent the request to. -.PP -Once all of these checks have been done the client has successfully verified the -identify of the server. OpenSSL can perform all of these checks automatically -but it must be provided with certain information in order to do so, i.e. the set -of CAs that the client trusts as well as the \s-1DNS\s0 hostname for the server that -this client is trying to connect to. -.PP -Note that it is common for certificates to be built up into a chain. For example -a server's certificate may be signed by a key owned by a an intermediate \s-1CA.\s0 -That intermediate \s-1CA\s0 also has a certificate containing its public key which is -in turn signed by a key owned by a root \s-1CA.\s0 The client may only trust the root -\&\s-1CA,\s0 but if the server sends both its own certificate and the certificate for the -intermediate \s-1CA\s0 then the client can still successfully verify the identity of -the server. There is a chain of trust between the root \s-1CA\s0 and the server. -.PP -By default it is only the client that authenticates the server using this -method. However it is also possible to set things up such that the server -additionally authenticates the client. This is known as \*(L"client authentication\*(R". -In this approach the client will still authenticate the server in the same way, -but the server will request a certificate from the client. The client sends the -server its certificate and the server authenticates it in the same way that the -client does. -.SH "TRUSTED CERTIFICATE STORE" -.IX Header "TRUSTED CERTIFICATE STORE" -The system described above only works if a chain of trust can be built between -the set of CAs that the endpoint trusts and the certificate that the peer is -using. The endpoint must therefore have a set of certificates for CAs that it -trusts before any communication can take place. OpenSSL itself does not provide -such a set of certificates. Therefore you will need to make sure you have them -before you start if you are going to be verifying certificates (i.e. always if -the endpoint is a client, and only if client authentication is in use for a -server). -.PP -Fortunately other organisations do maintain such a set of certificates. If you -have obtained your copy of OpenSSL from an Operating System (\s-1OS\s0) vendor (e.g. a -Linux distribution) then normally the set of \s-1CA\s0 certificates will also be -distributed with that copy. -.PP -You can check this by running the OpenSSL command line application like this: -.PP -.Vb 1 -\& openssl version \-d -.Ve -.PP -This will display a value for \fB\s-1OPENSSLDIR\s0\fR. Look in the \fBcerts\fR sub directory -of \fB\s-1OPENSSLDIR\s0\fR and check its contents. For example if \fB\s-1OPENSSLDIR\s0\fR is -\&\*(L"/usr/local/ssl\*(R", then check the contents of the \*(L"/usr/local/ssl/certs\*(R" -directory. -.PP -You are expecting to see a list of files, typically with the suffix \*(L".pem\*(R" or -\&\*(L".0\*(R". If they exist then you already have a suitable trusted certificate store. -.PP -If you are running your version of OpenSSL on Windows then OpenSSL (from version -3.2 onwards) will use the default Windows set of trusted CAs. -.PP -If you have built your version of OpenSSL from source, or obtained it from some -other location and it does not have a set of trusted \s-1CA\s0 certificates then you -will have to obtain them yourself. One such source is the Curl project. See the -page where you can download trusted -certificates in a single file. Rename the file to \*(L"cert.pem\*(R" and store it -directly in \fB\s-1OPENSSLDIR\s0\fR. For example if \fB\s-1OPENSSLDIR\s0\fR is \*(L"/usr/local/ssl\*(R", -then save it as \*(L"/usr/local/ssl/cert.pem\*(R". -.PP -You can also use environment variables to override the default location that -OpenSSL will look for its trusted certificate store. Set the \fB\s-1SSL_CERT_PATH\s0\fR -environment variable to give the directory where OpenSSL should looks for its -certificates or the \fB\s-1SSL_CERT_FILE\s0\fR environment variable to give the name of -a single file containing all of the certificates. See \fBopenssl\-env\fR\|(7) for -further details about OpenSSL environment variables. For example you could use -this capability to have multiple versions of OpenSSL all installed on the same -system using different values for \fB\s-1OPENSSLDIR\s0\fR but all using the same -trusted certificate store. -.PP -You can test that your trusted certificate store is setup correctly by using it -via the OpenSSL command line. Use the following command to connect to a \s-1TLS\s0 -server: -.PP -.Vb 1 -\& openssl s_client www.openssl.org:443 -.Ve -.PP -Once the command has connected type the letter \*(L"Q\*(R" followed by \*(L"\*(R" to exit -the session. This will print a lot of information on the screen about the -connection. Look for a block of text like this: -.PP -.Vb 2 -\& SSL handshake has read 4584 bytes and written 403 bytes -\& Verification: OK -.Ve -.PP -Hopefully if everything has worked then the \*(L"Verification\*(R" line will say \*(L"\s-1OK\*(R".\s0 -If its not working as expected then you might see output like this instead: -.PP -.Vb 2 -\& SSL handshake has read 4584 bytes and written 403 bytes -\& Verification error: unable to get local issuer certificate -.Ve -.PP -The \*(L"unable to get local issuer certificate\*(R" error means that OpenSSL has been -unable to find a trusted \s-1CA\s0 for the chain of certificates provided by the server -in its trusted certificate store. Check your trusted certificate store -configuration again. -.PP -Note that s_client is a testing tool and will still allow you to connect to the -\&\s-1TLS\s0 server regardless of the verification error. Most applications should not do -this and should abort the connection in the event of a verification error. -.SH "IMPORTANT OBJECTS FOR AN OPENSSL TLS APPLICATION" -.IX Header "IMPORTANT OBJECTS FOR AN OPENSSL TLS APPLICATION" -A \s-1TLS\s0 connection is represented by the \fB\s-1SSL\s0\fR object in an OpenSSL based -application. Once a connection with a remote peer has been established an -endpoint can \*(L"write\*(R" data to the \fB\s-1SSL\s0\fR object to send data to the peer, or -\&\*(L"read\*(R" data from it to receive data from the server. -.PP -A new \fB\s-1SSL\s0\fR object is created from an \fB\s-1SSL_CTX\s0\fR object. Think of an \fB\s-1SSL_CTX\s0\fR -as a \*(L"factory\*(R" for creating \fB\s-1SSL\s0\fR objects. You can create a single \fB\s-1SSL_CTX\s0\fR -object and then create multiple connections (i.e. \fB\s-1SSL\s0\fR objects) from it. -Typically you can set up common configuration options on the \fB\s-1SSL_CTX\s0\fR so that -all the \fB\s-1SSL\s0\fR object created from it inherit the same configuration options. -.PP -Note that internally to OpenSSL various items that are shared between multiple -\&\fB\s-1SSL\s0\fR objects are cached in the \fB\s-1SSL_CTX\s0\fR for performance reasons. Therefore -it is considered best practice to create one \fB\s-1SSL_CTX\s0\fR for use by multiple -\&\fB\s-1SSL\s0\fR objects instead of having one \fB\s-1SSL_CTX\s0\fR for each \fB\s-1SSL\s0\fR object that you -create. -.PP -Each \fB\s-1SSL\s0\fR object is also associated with two \fB\s-1BIO\s0\fR objects. A \fB\s-1BIO\s0\fR object -is used for sending or receiving data from the underlying transport layer. For -example you might create a \fB\s-1BIO\s0\fR to represent a \s-1TCP\s0 socket. The \fB\s-1SSL\s0\fR object -uses one \fB\s-1BIO\s0\fR for reading data and one \fB\s-1BIO\s0\fR for writing data. In most cases -you would use the same \fB\s-1BIO\s0\fR for each direction but there could be some -circumstances where you want them to be different. -.PP -It is up to the application programmer to create the \fB\s-1BIO\s0\fR objects that are -needed and supply them to the \fB\s-1SSL\s0\fR object. See -\&\fBossl\-guide\-tls\-client\-block\fR\|(7) and \fBossl\-guide\-tls\-server\-block\fR\|(7) for -usage examples. -.PP -Finally, an endpoint can establish a \*(L"session\*(R" with its peer. The session holds -various \s-1TLS\s0 parameters about the connection between the client and the server. -The session details can then be reused in a subsequent connection attempt to -speed up the process of connecting. This is known as \*(L"resumption\*(R". Sessions are -represented in OpenSSL by the \fB\s-1SSL_SESSION\s0\fR object. In TLSv1.2 there is always -exactly one session per connection. In TLSv1.3 there can be any number per -connection including none. -.SH "PHASES OF A TLS CONNECTION" -.IX Header "PHASES OF A TLS CONNECTION" -A \s-1TLS\s0 connection starts with an initial \*(L"set up\*(R" phase. The endpoint creates the -\&\fB\s-1SSL_CTX\s0\fR (if one has not already been created) and configures it. -.PP -A client then creates an \fB\s-1SSL\s0\fR object to represent the new \s-1TLS\s0 connection. Any -connection specific configuration parameters are then applied and the underlying -socket is created and associated with the \fB\s-1SSL\s0\fR via \fB\s-1BIO\s0\fR objects. -.PP -A server will create a socket for listening for incoming connection attempts -from clients. Once a connection attempt is made the server will create an \fB\s-1SSL\s0\fR -object in the same way as for a client and associate it with a \fB\s-1BIO\s0\fR for the -newly created incoming socket. -.PP -After set up is complete the \s-1TLS\s0 \*(L"handshake\*(R" phase begins. A \s-1TLS\s0 handshake -consists of the client and server exchanging a series of \s-1TLS\s0 handshake messages -to establish the connection. The client starts by sending a \*(L"ClientHello\*(R" -handshake message and the server responds with a \*(L"ServerHello\*(R". The handshake is -complete once an endpoint has sent its last message (known as the \*(L"Finished\*(R" -message) and received a Finished message from its peer. Note that this might -occur at slightly different times for each peer. For example in TLSv1.3 the -server always sends its Finished message before the client. The client later -responds with its Finished message. At this point the client has completed the -handshake because it has both sent and received a Finished message. The server -has sent its Finished message but the Finished message from the client may still -be in-flight, so the server is still in the handshake phase. It is even possible -that the server will fail to complete the handshake (if it considers there is -some problem with the messages sent from the client), even though the client may -have already progressed to sending application data. In TLSv1.2 this can happen -the other way around, i.e. the server finishes first and the client finishes -second. -.PP -Once the handshake is complete the application data transfer phase begins. -Strictly speaking there are some situations where the client can start sending -application data even earlier (using the TLSv1.3 \*(L"early data\*(R" capability) \- but -we're going to skip over that for this basic introduction. -.PP -During application data transfer the client and server can read and write data -to the connection freely. The details of this are typically left to some higher -level application protocol (for example \s-1HTTP\s0). Not all information exchanged -during this phase is application data. Some protocol level messages may still -be exchanged \- so it is not necessarily the case that, just because the -underlying socket is \*(L"readable\*(R", that application data will be available to read. -.PP -When the connection is no longer required then it should be shutdown. A shutdown -may be initiated by either the client or the server via a message known as a -\&\*(L"close_notify\*(R" alert. The client or server that receives a close_notify may -respond with one and then the connection is fully closed and application data -can no longer be sent or received. -.PP -Once shutdown is complete a \s-1TLS\s0 application must clean up by freeing the \s-1SSL\s0 -object. -.SH "FURTHER READING" -.IX Header "FURTHER READING" -See \fBossl\-guide\-tls\-client\-block\fR\|(7) for an example of how to apply these -concepts in order to write a simple \s-1TLS\s0 client based on a blocking socket. -See \fBossl\-guide\-tls\-server\-block\fR\|(7) for an example of how to apply these -concepts in order to write a simple \s-1TLS\s0 server handling one client at a time -over a blocking socket. -See \fBossl\-guide\-quic\-introduction\fR\|(7) for an introduction to \s-1QUIC\s0 in OpenSSL. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7), \fBossl\-guide\-tls\-client\-block\fR\|(7), -\&\fBossl\-guide\-tls\-server\-block\fR\|(7), \fBossl\-guide\-quic\-introduction\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2023\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl-guide-tls-server-block.7ossl b/openssl-install/share/man/man7/ossl-guide-tls-server-block.7ossl deleted file mode 100644 index 9e568f80..00000000 --- a/openssl-install/share/man/man7/ossl-guide-tls-server-block.7ossl +++ /dev/null @@ -1,483 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL-GUIDE-TLS-SERVER-BLOCK 7ossl" -.TH OSSL-GUIDE-TLS-SERVER-BLOCK 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl\-guide\-tls\-server\-block -\&\- OpenSSL Guide: Writing a simple blocking TLS server -.SH "SIMPLE BLOCKING TLS SERVER EXAMPLE" -.IX Header "SIMPLE BLOCKING TLS SERVER EXAMPLE" -This page will present various source code samples demonstrating how to write a -simple, non-concurrent, \s-1TLS\s0 \*(L"echo\*(R" server application which accepts one client -connection at a time, echoing input from the client back to the same client. -Once the current client disconnects, the next client connection is accepted. -.PP -Both the acceptor socket and client connections are \*(L"blocking\*(R". A more typical -server might use nonblocking sockets with an event loop and callbacks for I/O -events. -.PP -The complete source code for this example blocking \s-1TLS\s0 server is available in -the \fBdemos/guide\fR directory of the OpenSSL source distribution in the file -\&\fBtls\-server\-block.c\fR. It is also available online at -. -.PP -We assume that you already have OpenSSL installed on your system; that you -already have some fundamental understanding of OpenSSL concepts and \s-1TLS\s0 (see -\&\fBossl\-guide\-libraries\-introduction\fR\|(7) and \fBossl\-guide\-tls\-introduction\fR\|(7)); -and that you know how to write and build C code and link it against the -libcrypto and libssl libraries that are provided by OpenSSL. It also assumes -that you have a basic understanding of \s-1TCP/IP\s0 and sockets. -.SS "Creating the \s-1SSL_CTX\s0 and \s-1SSL\s0 objects" -.IX Subsection "Creating the SSL_CTX and SSL objects" -The first step is to create an \fB\s-1SSL_CTX\s0\fR object for our server. We use the -\&\fBSSL_CTX_new\fR\|(3) function for this purpose. We could alternatively use -\&\fBSSL_CTX_new_ex\fR\|(3) if we want to associate the \fB\s-1SSL_CTX\s0\fR with a particular -\&\fB\s-1OSSL_LIB_CTX\s0\fR (see \fBossl\-guide\-libraries\-introduction\fR\|(7) to learn about -\&\fB\s-1OSSL_LIB_CTX\s0\fR). We pass as an argument the return value of the function -\&\fBTLS_server_method\fR\|(3). You should use this method whenever you are writing a -\&\s-1TLS\s0 server. This method will automatically use \s-1TLS\s0 version negotiation to select -the highest version of the protocol that is mutually supported by both the -server and the client. -.PP -.Vb 9 -\& /* -\& * An SSL_CTX holds shared configuration information for multiple -\& * subsequent per\-client SSL connections. -\& */ -\& ctx = SSL_CTX_new(TLS_server_method()); -\& if (ctx == NULL) { -\& ERR_print_errors_fp(stderr); -\& errx(res, "Failed to create server SSL_CTX"); -\& } -.Ve -.PP -We would also like to restrict the \s-1TLS\s0 versions that we are willing to accept to -TLSv1.2 or above. \s-1TLS\s0 protocol versions earlier than that are generally to be -avoided where possible. We can do that using -\&\fBSSL_CTX_set_min_proto_version\fR\|(3): -.PP -.Vb 9 -\& /* -\& * TLS versions older than TLS 1.2 are deprecated by IETF and SHOULD -\& * be avoided if possible. -\& */ -\& if (!SSL_CTX_set_min_proto_version(ctx, TLS1_2_VERSION)) { -\& SSL_CTX_free(ctx); -\& ERR_print_errors_fp(stderr); -\& errx(res, "Failed to set the minimum TLS protocol version"); -\& } -.Ve -.PP -Next we configure some option flags, see \fBSSL_CTX_set_options\fR\|(3) for details: -.PP -.Vb 6 -\& /* -\& * Tolerate clients hanging up without a TLS "shutdown". Appropriate in all -\& * application protocols which perform their own message "framing", and -\& * don\*(Aqt rely on TLS to defend against "truncation" attacks. -\& */ -\& opts = SSL_OP_IGNORE_UNEXPECTED_EOF; -\& -\& /* -\& * Block potential CPU\-exhaustion attacks by clients that request frequent -\& * renegotiation. This is of course only effective if there are existing -\& * limits on initial full TLS handshake or connection rates. -\& */ -\& opts |= SSL_OP_NO_RENEGOTIATION; -\& -\& /* -\& * Most servers elect to use their own cipher preference rather than that of -\& * the client. -\& */ -\& opts |= SSL_OP_CIPHER_SERVER_PREFERENCE; -\& -\& /* Apply the selection options */ -\& SSL_CTX_set_options(ctx, opts); -.Ve -.PP -Servers need a private key and certificate. Though anonymous ciphers (no -server certificate) are possible in \s-1TLS 1.2,\s0 they are rarely applicable, and -are not currently defined for \s-1TLS 1.3.\s0 Additional intermediate issuer \s-1CA\s0 -certificates are often also required, and both the server (end-entity or \s-1EE\s0) -certificate and the issuer (\*(L"chain\*(R") certificates are most easily configured in -a single \*(L"chain file\*(R". Below we load such a chain file (the \s-1EE\s0 certificate -must appear first), and then load the corresponding private key, checking that -it matches the server certificate. No checks are performed to check the -integrity of the chain (\s-1CA\s0 signatures or certificate expiration dates, for -example). -.PP -.Vb 10 -\& /* -\& * Load the server\*(Aqs certificate *chain* file (PEM format), which includes -\& * not only the leaf (end\-entity) server certificate, but also any -\& * intermediate issuer\-CA certificates. The leaf certificate must be the -\& * first certificate in the file. -\& * -\& * In advanced use\-cases this can be called multiple times, once per public -\& * key algorithm for which the server has a corresponding certificate. -\& * However, the corresponding private key (see below) must be loaded first, -\& * *before* moving on to the next chain file. -\& */ -\& if (SSL_CTX_use_certificate_chain_file(ctx, "chain.pem") <= 0) { -\& SSL_CTX_free(ctx); -\& ERR_print_errors_fp(stderr); -\& errx(res, "Failed to load the server certificate chain file"); -\& } -\& -\& /* -\& * Load the corresponding private key, this also checks that the private -\& * key matches the just loaded end\-entity certificate. It does not check -\& * whether the certificate chain is valid, the certificates could be -\& * expired, or may otherwise fail to form a chain that a client can validate. -\& */ -\& if (SSL_CTX_use_PrivateKey_file(ctx, "pkey.pem", SSL_FILETYPE_PEM) <= 0) { -\& SSL_CTX_free(ctx); -\& ERR_print_errors_fp(stderr); -\& errx(res, "Error loading the server private key file, " -\& "possible key/cert mismatch???"); -\& } -.Ve -.PP -Next we enable session caching, which makes it possible for clients to more -efficiently make additional \s-1TLS\s0 connections after completing an initial full -\&\s-1TLS\s0 handshake. With \s-1TLS 1.3,\s0 session resumption typically still performs a fresh -key agreement, but the certificate exchange is avoided. -.PP -.Vb 7 -\& /* -\& * Servers that want to enable session resumption must specify a cache id -\& * byte array, that identifies the server application, and reduces the -\& * chance of inappropriate cache sharing. -\& */ -\& SSL_CTX_set_session_id_context(ctx, (void *)cache_id, sizeof(cache_id)); -\& SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_SERVER); -\& -\& /* -\& * How many client TLS sessions to cache. The default is -\& * SSL_SESSION_CACHE_MAX_SIZE_DEFAULT (20k in recent OpenSSL versions), -\& * which may be too small or too large. -\& */ -\& SSL_CTX_sess_set_cache_size(ctx, 1024); -\& -\& /* -\& * Sessions older than this are considered a cache miss even if still in -\& * the cache. The default is two hours. Busy servers whose clients make -\& * many connections in a short burst may want a shorter timeout, on lightly -\& * loaded servers with sporadic connections from any given client, a longer -\& * time may be appropriate. -\& */ -\& SSL_CTX_set_timeout(ctx, 3600); -.Ve -.PP -Most servers, including this one, do not solicit client certificates. We -therefore do not need a \*(L"trust store\*(R" and allow the handshake to complete even -when the client does not present a certificate. Note: Even if a client did -present a trusted ceritificate, for it to be useful, the server application -would still need custom code to use the verified identity to grant nondefault -access to that particular client. Some servers grant access to all clients -with certificates from a private \s-1CA,\s0 this then requires processing of -certificate revocation lists to deauthorise a client. It is often simpler and -more secure to instead keep a list of authorised public keys. -.PP -Though this is the default setting, we explicitly call the -\&\fBSSL_CTX_set_verify\fR\|(3) function and pass the \fB\s-1SSL_VERIFY_NONE\s0\fR value to it. -The final argument to this function is a callback that you can optionally -supply to override the default handling for certificate verification. Most -applications do not need to do this so this can safely be set to \s-1NULL\s0 to get -the default handling. -.PP -.Vb 12 -\& /* -\& * Clients rarely employ certificate\-based authentication, and so we don\*(Aqt -\& * require "mutual" TLS authentication (indeed there\*(Aqs no way to know -\& * whether or how the client authenticated the server, so the term "mutual" -\& * is potentially misleading). -\& * -\& * Since we\*(Aqre not soliciting or processing client certificates, we don\*(Aqt -\& * need to configure a trusted\-certificate store, so no call to -\& * SSL_CTX_set_default_verify_paths() is needed. The server\*(Aqs own -\& * certificate chain is assumed valid. -\& */ -\& SSL_CTX_set_verify(ctx, SSL_VERIFY_NONE, NULL); -.Ve -.PP -That is all the setup that we need to do for the \fB\s-1SSL_CTX\s0\fR. Next we create an -acceptor \s-1BIO\s0 on which to accept client connections. This just records the -intended port (and optional \*(L"host:\*(R" prefix), without actually creating the -socket. This delayed processing allows the programmer to specify additional -behaviours before the listening socket is actually created. -.PP -.Vb 10 -\& /* -\& * Create a listener socket wrapped in a BIO. -\& * The first call to BIO_do_accept() initialises the socket -\& */ -\& acceptor_bio = BIO_new_accept(hostport); -\& if (acceptor_bio == NULL) { -\& SSL_CTX_free(ctx); -\& ERR_print_errors_fp(stderr); -\& errx(res, "Error creating acceptor bio"); -\& } -.Ve -.PP -Servers almost always want to use the \*(L"\s-1SO_REUSEADDR\*(R"\s0 option to avoid startup -failures if there are still lingering client connections, so we do that before -making the \fBfirst\fR call to \fBBIO_do_accept\fR\|(3) which creates the listening -socket, without accepting a client connection. Subsequent calls to the same -function will accept new connections. -.PP -.Vb 6 -\& BIO_set_bind_mode(acceptor_bio, BIO_BIND_REUSEADDR); -\& if (BIO_do_accept(acceptor_bio) <= 0) { -\& SSL_CTX_free(ctx); -\& ERR_print_errors_fp(stderr); -\& errx(res, "Error setting up acceptor socket"); -\& } -.Ve -.SS "Server loop" -.IX Subsection "Server loop" -The server now enters a \*(L"forever\*(R" loop handling one client connection at a -time. Before each connection we clear the OpenSSL error stack, so that any -error reports are related to just the new connection. -.PP -.Vb 2 -\& /* Pristine error stack for each new connection */ -\& ERR_clear_error(); -.Ve -.PP -At this point the server blocks to accept the next client: -.PP -.Vb 5 -\& /* Wait for the next client to connect */ -\& if (BIO_do_accept(acceptor_bio) <= 0) { -\& /* Client went away before we accepted the connection */ -\& continue; -\& } -.Ve -.PP -On success the accepted client connection has been wrapped in a fresh \s-1BIO\s0 and -pushed onto the end of the acceptor \s-1BIO\s0 chain. We pop it off returning the -acceptor \s-1BIO\s0 to its initial state. -.PP -.Vb 3 -\& /* Pop the client connection from the BIO chain */ -\& client_bio = BIO_pop(acceptor_bio); -\& fprintf(stderr, "New client connection accepted\en"); -.Ve -.PP -Next, we create an \fB\s-1SSL\s0\fR object by calling the \fB\fBSSL_new\fB\|(3)\fR function and -passing the \fB\s-1SSL_CTX\s0\fR we created as an argument. The client connection \s-1BIO\s0 is -configured as the I/O conduit for this \s-1SSL\s0 handle. SSL_set_bio transfers -ownership of the \s-1BIO\s0 or BIOs involved (our \fBclient_bio\fR) to the \s-1SSL\s0 handle. -.PP -.Vb 8 -\& /* Associate a new SSL handle with the new connection */ -\& if ((ssl = SSL_new(ctx)) == NULL) { -\& ERR_print_errors_fp(stderr); -\& warnx("Error creating SSL handle for new connection"); -\& BIO_free(client_bio); -\& continue; -\& } -\& SSL_set_bio(ssl, client_bio, client_bio); -.Ve -.PP -And now we're ready to attempt the \s-1SSL\s0 handshake. With a blocking socket -OpenSSL will perform all the read and write operations required to complete the -handshake (or detect and report a failure) before returning. -.PP -.Vb 7 -\& /* Attempt an SSL handshake with the client */ -\& if (SSL_accept(ssl) <= 0) { -\& ERR_print_errors_fp(stderr); -\& warnx("Error performing SSL handshake with client"); -\& SSL_free(ssl); -\& continue; -\& } -.Ve -.PP -With the handshake complete, the server loops echoing client input back to the -client: -.PP -.Vb 9 -\& while (SSL_read_ex(ssl, buf, sizeof(buf), &nread) > 0) { -\& if (SSL_write_ex(ssl, buf, nread, &nwritten) > 0 && -\& nwritten == nread) { -\& total += nwritten; -\& continue; -\& } -\& warnx("Error echoing client input"); -\& break; -\& } -.Ve -.PP -Once the client closes its connection, we report the number of bytes sent to -\&\fBstderr\fR and free the \s-1SSL\s0 handle, which also frees the \fBclient_bio\fR and -closes the underlying socket. -.PP -.Vb 2 -\& fprintf(stderr, "Client connection closed, %zu bytes sent\en", total); -\& SSL_free(ssl); -.Ve -.PP -The server is now ready to accept the next client connection. -.SS "Final clean up" -.IX Subsection "Final clean up" -If the server could somehow manage to break out of the infinite loop, and -be ready to exit, it would first deallocate the constructed \fB\s-1SSL_CTX\s0\fR. -.PP -.Vb 5 -\& /* -\& * Unreachable placeholder cleanup code, the above loop runs forever. -\& */ -\& SSL_CTX_free(ctx); -\& return EXIT_SUCCESS; -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl\-guide\-introduction\fR\|(7), \fBossl\-guide\-libraries\-introduction\fR\|(7), -\&\fBossl\-guide\-libssl\-introduction\fR\|(7), \fBossl\-guide\-tls\-introduction\fR\|(7), -\&\fBossl\-guide\-tls\-client\-non\-block\fR\|(7), \fBossl\-guide\-quic\-client\-block\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl_store-file.7ossl b/openssl-install/share/man/man7/ossl_store-file.7ossl deleted file mode 100644 index 1ae34894..00000000 --- a/openssl-install/share/man/man7/ossl_store-file.7ossl +++ /dev/null @@ -1,191 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE-FILE 7ossl" -.TH OSSL_STORE-FILE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl_store\-file \- The store 'file' scheme loader -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -#include -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Support for the 'file' scheme is built into \f(CW\*(C`libcrypto\*(C'\fR. -Since files come in all kinds of formats and content types, the 'file' -scheme has its own layer of functionality called \*(L"file handlers\*(R", -which are used to try to decode diverse types of file contents. -.PP -In case a file is formatted as \s-1PEM,\s0 each called file handler receives -the \s-1PEM\s0 name (everything following any '\f(CW\*(C`\-\-\-\-\-BEGIN \*(C'\fR') as well as -possible \s-1PEM\s0 headers, together with the decoded \s-1PEM\s0 body. Since \s-1PEM\s0 -formatted files can contain more than one object, the file handlers -are called upon for each such object. -.PP -If the file isn't determined to be formatted as \s-1PEM,\s0 the content is -loaded in raw form in its entirety and passed to the available file -handlers as is, with no \s-1PEM\s0 name or headers. -.PP -Each file handler is expected to handle \s-1PEM\s0 and non-PEM content as -appropriate. Some may refuse non-PEM content for the sake of -determinism (for example, there are keys out in the wild that are -represented as an \s-1ASN.1 OCTET STRING.\s0 In raw form, it's not easily -possible to distinguish those from any other data coming as an \s-1ASN.1 -OCTET STRING,\s0 so such keys would naturally be accepted as \s-1PEM\s0 files -only). -.SH "NOTES" -.IX Header "NOTES" -When needed, the 'file' scheme loader will require a pass phrase by -using the \fB\s-1UI_METHOD\s0\fR that was passed via \fBOSSL_STORE_open()\fR. -This pass phrase is expected to be \s-1UTF\-8\s0 encoded, anything else will -give an undefined result. -The files made accessible through this loader are expected to be -standard compliant with regards to pass phrase encoding. -Files that aren't should be re-generated with a correctly encoded pass -phrase. -See \fBpassphrase\-encoding\fR\|(7) for more information. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBossl_store\fR\|(7), \fBpassphrase\-encoding\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ossl_store.7ossl b/openssl-install/share/man/man7/ossl_store.7ossl deleted file mode 100644 index 21d5df39..00000000 --- a/openssl-install/share/man/man7/ossl_store.7ossl +++ /dev/null @@ -1,220 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "OSSL_STORE 7ossl" -.TH OSSL_STORE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -ossl_store \- Store retrieval functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -#include -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -.SS "General" -.IX Subsection "General" -A \s-1STORE\s0 is a layer of functionality to retrieve a number of supported -objects from a repository of any kind, addressable as a filename or -as a \s-1URI.\s0 -.PP -The functionality supports the pattern \*(L"open a channel to the -repository\*(R", \*(L"loop and retrieve one object at a time\*(R", and \*(L"finish up -by closing the channel\*(R". -.PP -The retrieved objects are returned as a wrapper type \fB\s-1OSSL_STORE_INFO\s0\fR, -from which an OpenSSL type can be retrieved. -.SS "\s-1URI\s0 schemes and loaders" -.IX Subsection "URI schemes and loaders" -Support for a \s-1URI\s0 scheme is called a \s-1STORE\s0 \*(L"loader\*(R", and can be added -dynamically from the calling application or from a loadable engine. -.PP -Support for the 'file' scheme is built into \f(CW\*(C`libcrypto\*(C'\fR. -See \fBossl_store\-file\fR\|(7) for more information. -.SS "\s-1UI_METHOD\s0 and pass phrases" -.IX Subsection "UI_METHOD and pass phrases" -The \fB\s-1OSS_STORE\s0\fR \s-1API\s0 does nothing to enforce any specific format or -encoding on the pass phrase that the \fB\s-1UI_METHOD\s0\fR provides. However, -the pass phrase is expected to be \s-1UTF\-8\s0 encoded. The result of any -other encoding is undefined. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -.SS "A generic call" -.IX Subsection "A generic call" -.Vb 2 -\& #include /* for UI_get_default_method */ -\& #include -\& -\& OSSL_STORE_CTX *ctx = OSSL_STORE_open("file:/foo/bar/data.pem", -\& UI_get_default_method(), NULL, NULL, NULL); -\& -\& /* -\& * OSSL_STORE_eof() simulates file semantics for any repository to signal -\& * that no more data can be expected -\& */ -\& while (!OSSL_STORE_eof(ctx)) { -\& OSSL_STORE_INFO *info = OSSL_STORE_load(ctx); -\& -\& /* -\& * Do whatever is necessary with the OSSL_STORE_INFO, -\& * here just one example -\& */ -\& switch (OSSL_STORE_INFO_get_type(info)) { -\& case OSSL_STORE_INFO_CERT: -\& /* Print the X.509 certificate text */ -\& X509_print_fp(stdout, OSSL_STORE_INFO_get0_CERT(info)); -\& /* Print the X.509 certificate PEM output */ -\& PEM_write_X509(stdout, OSSL_STORE_INFO_get0_CERT(info)); -\& break; -\& } -\& OSSL_STORE_INFO_free(info); -\& } -\& -\& OSSL_STORE_close(ctx); -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\s-1\fBOSSL_STORE_INFO\s0\fR\|(3), \s-1\fBOSSL_STORE_LOADER\s0\fR\|(3), -\&\fBOSSL_STORE_open\fR\|(3), \fBOSSL_STORE_expect\fR\|(3), -\&\s-1\fBOSSL_STORE_SEARCH\s0\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2016\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/passphrase-encoding.7ossl b/openssl-install/share/man/man7/passphrase-encoding.7ossl deleted file mode 100644 index ae20f32a..00000000 --- a/openssl-install/share/man/man7/passphrase-encoding.7ossl +++ /dev/null @@ -1,288 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PASSPHRASE-ENCODING 7ossl" -.TH PASSPHRASE-ENCODING 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -passphrase\-encoding -\&\- How diverse parts of OpenSSL treat pass phrases character encoding -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -In a modern world with all sorts of character encodings, the treatment of pass -phrases has become increasingly complex. -This manual page attempts to give an overview over how this problem is -currently addressed in different parts of the OpenSSL library. -.SS "The general case" -.IX Subsection "The general case" -The OpenSSL library doesn't treat pass phrases in any special way as a general -rule, and trusts the application or user to choose a suitable character set -and stick to that throughout the lifetime of affected objects. -This means that for an object that was encrypted using a pass phrase encoded in -\&\s-1ISO\-8859\-1,\s0 that object needs to be decrypted using a pass phrase encoded in -\&\s-1ISO\-8859\-1.\s0 -Using the wrong encoding is expected to cause a decryption failure. -.SS "PKCS#12" -.IX Subsection "PKCS#12" -PKCS#12 is a bit different regarding pass phrase encoding. -The standard stipulates that the pass phrase shall be encoded as an \s-1ASN.1\s0 -BMPString, which consists of the code points of the basic multilingual plane, -encoded in big endian (\s-1UCS\-2 BE\s0). -.PP -OpenSSL tries to adapt to this requirements in one of the following manners: -.IP "1." 4 -Treats the received pass phrase as \s-1UTF\-8\s0 encoded and tries to re-encode it to -\&\s-1UTF\-16\s0 (which is the same as \s-1UCS\-2\s0 for characters U+0000 to U+D7FF and U+E000 -to U+FFFF, but becomes an expansion for any other character), or failing that, -proceeds with step 2. -.IP "2." 4 -Assumes that the pass phrase is encoded in \s-1ASCII\s0 or \s-1ISO\-8859\-1\s0 and -opportunistically prepends each byte with a zero byte to obtain the \s-1UCS\-2\s0 -encoding of the characters, which it stores as a BMPString. -.Sp -Note that since there is no check of your locale, this may produce \s-1UCS\-2 / -UTF\-16\s0 characters that do not correspond to the original pass phrase characters -for other character sets, such as any \s-1ISO\-8859\-X\s0 encoding other than -\&\s-1ISO\-8859\-1\s0 (or for Windows, \s-1CP 1252\s0 with exception for the extra \*(L"graphical\*(R" -characters in the 0x80\-0x9F range). -.PP -OpenSSL versions older than 1.1.0 do variant 2 only, and that is the reason why -OpenSSL still does this, to be able to read files produced with older versions. -.PP -It should be noted that this approach isn't entirely fault free. -.PP -A pass phrase encoded in \s-1ISO\-8859\-2\s0 could very well have a sequence such as -0xC3 0xAF (which is the two characters \*(L"\s-1LATIN CAPITAL LETTER A WITH BREVE\*(R"\s0 -and \*(L"\s-1LATIN CAPITAL LETTER Z WITH DOT ABOVE\*(R"\s0 in \s-1ISO\-8859\-2\s0 encoding), but would -be misinterpreted as the perfectly valid \s-1UTF\-8\s0 encoded code point U+00EF (\s-1LATIN -SMALL LETTER I WITH DIAERESIS\s0) \fIif the pass phrase doesn't contain anything that -would be invalid \s-1UTF\-8\s0\fR. -A pass phrase that contains this kind of byte sequence will give a different -outcome in OpenSSL 1.1.0 and newer than in OpenSSL older than 1.1.0. -.PP -.Vb 2 -\& 0x00 0xC3 0x00 0xAF # OpenSSL older than 1.1.0 -\& 0x00 0xEF # OpenSSL 1.1.0 and newer -.Ve -.PP -On the same accord, anything encoded in \s-1UTF\-8\s0 that was given to OpenSSL older -than 1.1.0 was misinterpreted as \s-1ISO\-8859\-1\s0 sequences. -.SS "\s-1OSSL_STORE\s0" -.IX Subsection "OSSL_STORE" -\&\fBossl_store\fR\|(7) acts as a general interface to access all kinds of objects, -potentially protected with a pass phrase, a \s-1PIN\s0 or something else. -This \s-1API\s0 stipulates that pass phrases should be \s-1UTF\-8\s0 encoded, and that any -other pass phrase encoding may give undefined results. -This \s-1API\s0 relies on the application to ensure \s-1UTF\-8\s0 encoding, and doesn't check -that this is the case, so what it gets, it will also pass to the underlying -loader. -.SH "RECOMMENDATIONS" -.IX Header "RECOMMENDATIONS" -This section assumes that you know what pass phrase was used for encryption, -but that it may have been encoded in a different character encoding than the -one used by your current input method. -For example, the pass phrase may have been used at a time when your default -encoding was \s-1ISO\-8859\-1\s0 (i.e. \*(L"nai\*:ve\*(R" resulting in the byte sequence 0x6E 0x61 -0xEF 0x76 0x65), and you're now in an environment where your default encoding -is \s-1UTF\-8\s0 (i.e. \*(L"nai\*:ve\*(R" resulting in the byte sequence 0x6E 0x61 0xC3 0xAF 0x76 -0x65). -Whenever it's mentioned that you should use a certain character encoding, it -should be understood that you either change the input method to use the -mentioned encoding when you type in your pass phrase, or use some suitable tool -to convert your pass phrase from your default encoding to the target encoding. -.PP -Also note that the sub-sections below discuss human readable pass phrases. -This is particularly relevant for PKCS#12 objects, where human readable pass -phrases are assumed. -For other objects, it's as legitimate to use any byte sequence (such as a -sequence of bytes from \fI/dev/urandom\fR that's been saved away), which makes any -character encoding discussion irrelevant; in such cases, simply use the same -byte sequence as it is. -.SS "Creating new objects" -.IX Subsection "Creating new objects" -For creating new pass phrase protected objects, make sure the pass phrase is -encoded using \s-1UTF\-8.\s0 -This is default on most modern Unixes, but may involve an effort on other -platforms. -Specifically for Windows, setting the environment variable -\&\fB\s-1OPENSSL_WIN32_UTF8\s0\fR will have anything entered on [Windows] console prompt -converted to \s-1UTF\-8\s0 (command line and separately prompted pass phrases alike). -.SS "Opening existing objects" -.IX Subsection "Opening existing objects" -For opening pass phrase protected objects where you know what character -encoding was used for the encryption pass phrase, make sure to use the same -encoding again. -.PP -For opening pass phrase protected objects where the character encoding that was -used is unknown, or where the producing application is unknown, try one of the -following: -.IP "1." 4 -Try the pass phrase that you have as it is in the character encoding of your -environment. -It's possible that its byte sequence is exactly right. -.IP "2." 4 -Convert the pass phrase to \s-1UTF\-8\s0 and try with the result. -Specifically with PKCS#12, this should open up any object that was created -according to the specification. -.IP "3." 4 -Do a nai\*:ve (i.e. purely mathematical) \s-1ISO\-8859\-1\s0 to \s-1UTF\-8\s0 conversion and try -with the result. -This differs from the previous attempt because \s-1ISO\-8859\-1\s0 maps directly to -U+0000 to U+00FF, which other non\-UTF\-8 character sets do not. -.Sp -This also takes care of the case when a \s-1UTF\-8\s0 encoded string was used with -OpenSSL older than 1.1.0. -(for example, \f(CW\*(C`i\*:\*(C'\fR, which is 0xC3 0xAF when encoded in \s-1UTF\-8,\s0 would become 0xC3 -0x83 0xC2 0xAF when re-encoded in the nai\*:ve manner. -The conversion to BMPString would then yield 0x00 0xC3 0x00 0xA4 0x00 0x00, the -erroneous/non\-compliant encoding used by OpenSSL older than 1.1.0) -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBevp\fR\|(7), -\&\fBossl_store\fR\|(7), -\&\fBEVP_BytesToKey\fR\|(3), \fBEVP_DecryptInit\fR\|(3), -\&\fBPEM_do_header\fR\|(3), -\&\fBPKCS12_parse\fR\|(3), \fBPKCS12_newpass\fR\|(3), -\&\fBd2i_PKCS8PrivateKey_bio\fR\|(3) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2018\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/property.7ossl b/openssl-install/share/man/man7/property.7ossl deleted file mode 100644 index bac385c9..00000000 --- a/openssl-install/share/man/man7/property.7ossl +++ /dev/null @@ -1,289 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROPERTY 7ossl" -.TH PROPERTY 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -property \- Properties, a selection mechanism for algorithm implementations -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -As of OpenSSL 3.0, a new method has been introduced to decide which of -multiple implementations of an algorithm will be used. -The method is centered around the concept of properties. -Each implementation defines a number of properties and when an algorithm -is being selected, filters based on these properties can be used to -choose the most appropriate implementation of the algorithm. -.PP -Properties are like variables, they are referenced by name and have a value -assigned. -.SS "Property Names" -.IX Subsection "Property Names" -Property names fall into two categories: those reserved by the OpenSSL -project and user defined names. -A \fIreserved\fR property name consists of a single C\-style identifier -(except for leading underscores not being permitted), which begins -with a letter and can be followed by any number of letters, numbers -and underscores. -Property names are case-insensitive, but OpenSSL will only use lowercase -letters. -.PP -A \fIuser defined\fR property name is similar, but it \fBmust\fR consist of -two or more C\-style identifiers, separated by periods. -The last identifier in the name can be considered the 'true' property -name, which is prefixed by some sort of 'namespace'. -Providers for example could include their name in the prefix and use -property names like -.PP -.Vb 2 -\& . -\& .. -.Ve -.SS "Properties" -.IX Subsection "Properties" -A \fIproperty\fR is a \fIname=value\fR pair. -A \fIproperty definition\fR is a sequence of comma separated properties. -There can be any number of properties in a definition, however each name must -be unique. -For example: "\*(L" defines an empty property definition (i.e., no restriction); -\&\*(R"my.foo=bar" defines a property named \fImy.foo\fR which has a string value \fIbar\fR -and \*(L"iteration.count=3\*(R" defines a property named \fIiteration.count\fR which -has a numeric value of \fI3\fR. -The full syntax for property definitions appears below. -.SS "Implementations" -.IX Subsection "Implementations" -Each implementation of an algorithm can define any number of -properties. -For example, the default provider defines the property \fIprovider=default\fR -for all of its algorithms. -Likewise, OpenSSL's \s-1FIPS\s0 provider defines \fIprovider=fips\fR and the legacy -provider defines \fIprovider=legacy\fR for all of their algorithms. -.SS "Queries" -.IX Subsection "Queries" -A \fIproperty query clause\fR is a single conditional test. -For example, \*(L"fips=yes\*(R", \*(L"provider!=default\*(R" or \*(L"?iteration.count=3\*(R". -The first two represent mandatory clauses, such clauses \fBmust\fR match -for any algorithm to even be under consideration. -The third clause represents an optional clause. -Matching such clauses is not a requirement, but any additional optional -match counts in favor of the algorithm. -More details about that in the \fBLookups\fR section. -A \fIproperty query\fR is a sequence of comma separated property query clauses. -It is an error if a property name appears in more than one query clause. -The full syntax for property queries appears below, but the available syntactic -features are: -.IP "\(bu" 4 -\&\fB=\fR is an infix operator providing an equality test. -.IP "\(bu" 4 -\&\fB!=\fR is an infix operator providing an inequality test. -.IP "\(bu" 4 -\&\fB?\fR is a prefix operator that means that the following clause is optional -but preferred. -.IP "\(bu" 4 -\&\fB\-\fR is a prefix operator that means any global query clause involving the -following property name should be ignored. -.IP "\(bu" 4 -\&\fB\*(L"...\*(R"\fR is a quoted string. -The quotes are not included in the body of the string. -.IP "\(bu" 4 -\&\fB'...'\fR is a quoted string. -The quotes are not included in the body of the string. -.SS "Lookups" -.IX Subsection "Lookups" -When an algorithm is looked up, a property query is used to determine -the best matching algorithm. -All mandatory query clauses \fBmust\fR be present and the implementation -that additionally has the largest number of matching optional query -clauses will be used. -If there is more than one such optimal candidate, the result will be -chosen from amongst those in an indeterminate way. -Ordering of optional clauses is not significant. -.SS "Shortcut" -.IX Subsection "Shortcut" -In order to permit a more concise expression of boolean properties, there -is one short cut: a property name alone (e.g. \*(L"my.property\*(R") is -exactly equivalent to \*(L"my.property=yes\*(R" in both definitions and queries. -.SS "Global and Local" -.IX Subsection "Global and Local" -Two levels of property query are supported. -A context based property query that applies to all fetch operations and a local -property query. -Where both the context and local queries include a clause with the same name, -the local clause overrides the context clause. -.PP -It is possible for a local property query to remove a clause in the context -property query by preceding the property name with a '\-'. -For example, a context property query that contains \*(L"fips=yes\*(R" would normally -result in implementations that have \*(L"fips=yes\*(R". -.PP -However, if the setting of the \*(L"fips\*(R" property is irrelevant to the -operations being performed, the local property query can include the -clause \*(L"\-fips\*(R". -Note that the local property query could not use \*(L"fips=no\*(R" because that would -disallow any implementations with \*(L"fips=yes\*(R" rather than not caring about the -setting. -.SH "SYNTAX" -.IX Header "SYNTAX" -The lexical syntax in \s-1EBNF\s0 is given by: -.PP -.Vb 11 -\& Definition ::= PropertyName ( \*(Aq=\*(Aq Value )? -\& ( \*(Aq,\*(Aq PropertyName ( \*(Aq=\*(Aq Value )? )* -\& Query ::= PropertyQuery ( \*(Aq,\*(Aq PropertyQuery )* -\& PropertyQuery ::= \*(Aq\-\*(Aq PropertyName -\& | \*(Aq?\*(Aq? ( PropertyName (( \*(Aq=\*(Aq | \*(Aq!=\*(Aq ) Value)?) -\& Value ::= NumberLiteral | StringLiteral -\& StringLiteral ::= QuotedString | UnquotedString -\& QuotedString ::= \*(Aq"\*(Aq [^"]* \*(Aq"\*(Aq | "\*(Aq" [^\*(Aq]* "\*(Aq" -\& UnquotedString ::= [A\-Za\-z] [^{space},]+ -\& NumberLiteral ::= \*(Aq0\*(Aq ( [0\-7]* | \*(Aqx\*(Aq [0\-9A\-Fa\-f]+ ) | \*(Aq\-\*(Aq? [1\-9] [0\-9]+ -\& PropertyName ::= [A\-Za\-z] [A\-Za\-z0\-9_]* ( \*(Aq.\*(Aq [A\-Za\-z] [A\-Za\-z0\-9_]* )* -.Ve -.PP -The flavour of \s-1EBNF\s0 being used is defined by: -. -.SH "HISTORY" -.IX Header "HISTORY" -Properties were added in OpenSSL 3.0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-asym_cipher.7ossl b/openssl-install/share/man/man7/provider-asym_cipher.7ossl deleted file mode 100644 index 2794352f..00000000 --- a/openssl-install/share/man/man7/provider-asym_cipher.7ossl +++ /dev/null @@ -1,422 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-ASYM_CIPHER 7ossl" -.TH PROVIDER-ASYM_CIPHER 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-asym_cipher \- The asym_cipher library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_asym_cipher_newctx(void *provctx); -\& void OSSL_FUNC_asym_cipher_freectx(void *ctx); -\& void *OSSL_FUNC_asym_cipher_dupctx(void *ctx); -\& -\& /* Encryption */ -\& int OSSL_FUNC_asym_cipher_encrypt_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_asym_cipher_encrypt(void *ctx, unsigned char *out, size_t *outlen, -\& size_t outsize, const unsigned char *in, -\& size_t inlen); -\& -\& /* Decryption */ -\& int OSSL_FUNC_asym_cipher_decrypt_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_asym_cipher_decrypt(void *ctx, unsigned char *out, size_t *outlen, -\& size_t outsize, const unsigned char *in, -\& size_t inlen); -\& -\& /* Asymmetric Cipher parameters */ -\& int OSSL_FUNC_asym_cipher_get_ctx_params(void *ctx, OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_asym_cipher_gettable_ctx_params(void *provctx); -\& int OSSL_FUNC_asym_cipher_set_ctx_params(void *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_asym_cipher_settable_ctx_params(void *provctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The asymmetric cipher (\s-1OSSL_OP_ASYM_CIPHER\s0) operation enables providers to -implement asymmetric cipher algorithms and make them available to applications -via the \s-1API\s0 functions \fBEVP_PKEY_encrypt\fR\|(3), -\&\fBEVP_PKEY_decrypt\fR\|(3) and -other related functions). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_asym_cipher_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_asym_cipher_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_asym_cipher_newctx_fn -\& OSSL_FUNC_asym_cipher_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_asym_cipher_newctx OSSL_FUNC_ASYM_CIPHER_NEWCTX -\& OSSL_FUNC_asym_cipher_freectx OSSL_FUNC_ASYM_CIPHER_FREECTX -\& OSSL_FUNC_asym_cipher_dupctx OSSL_FUNC_ASYM_CIPHER_DUPCTX -\& -\& OSSL_FUNC_asym_cipher_encrypt_init OSSL_FUNC_ASYM_CIPHER_ENCRYPT_INIT -\& OSSL_FUNC_asym_cipher_encrypt OSSL_FUNC_ASYM_CIPHER_ENCRYPT -\& -\& OSSL_FUNC_asym_cipher_decrypt_init OSSL_FUNC_ASYM_CIPHER_DECRYPT_INIT -\& OSSL_FUNC_asym_cipher_decrypt OSSL_FUNC_ASYM_CIPHER_DECRYPT -\& -\& OSSL_FUNC_asym_cipher_get_ctx_params OSSL_FUNC_ASYM_CIPHER_GET_CTX_PARAMS -\& OSSL_FUNC_asym_cipher_gettable_ctx_params OSSL_FUNC_ASYM_CIPHER_GETTABLE_CTX_PARAMS -\& OSSL_FUNC_asym_cipher_set_ctx_params OSSL_FUNC_ASYM_CIPHER_SET_CTX_PARAMS -\& OSSL_FUNC_asym_cipher_settable_ctx_params OSSL_FUNC_ASYM_CIPHER_SETTABLE_CTX_PARAMS -.Ve -.PP -An asymmetric cipher algorithm implementation may not implement all of these -functions. -In order to be a consistent set of functions a provider must implement -OSSL_FUNC_asym_cipher_newctx and OSSL_FUNC_asym_cipher_freectx. -It must also implement both of OSSL_FUNC_asym_cipher_encrypt_init and -OSSL_FUNC_asym_cipher_encrypt, or both of OSSL_FUNC_asym_cipher_decrypt_init and -OSSL_FUNC_asym_cipher_decrypt. -OSSL_FUNC_asym_cipher_get_ctx_params is optional but if it is present then so must -OSSL_FUNC_asym_cipher_gettable_ctx_params. -Similarly, OSSL_FUNC_asym_cipher_set_ctx_params is optional but if it is present then -so must OSSL_FUNC_asym_cipher_settable_ctx_params. -.PP -An asymmetric cipher algorithm must also implement some mechanism for generating, -loading or importing keys via the key management (\s-1OSSL_OP_KEYMGMT\s0) operation. -See \fBprovider\-keymgmt\fR\|(7) for further details. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_asym_cipher_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during an asymmetric cipher operation. -A pointer to this context will be passed back in a number of the other -asymmetric cipher operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -.PP -\&\fBOSSL_FUNC_asym_cipher_freectx()\fR is passed a pointer to the provider side asymmetric -cipher context in the \fIctx\fR parameter. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_asym_cipher_dupctx()\fR should duplicate the provider side asymmetric cipher -context in the \fIctx\fR parameter and return the duplicate copy. -.SS "Encryption Functions" -.IX Subsection "Encryption Functions" -\&\fBOSSL_FUNC_asym_cipher_encrypt_init()\fR initialises a context for an asymmetric encryption -given a provider side asymmetric cipher context in the \fIctx\fR parameter, and a -pointer to a provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_asym_cipher_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see \fBprovider\-keymgmt\fR\|(7)). -\&\fBOSSL_FUNC_asym_cipher_encrypt()\fR performs the actual encryption itself. -A previously initialised asymmetric cipher context is passed in the \fIctx\fR -parameter. -The data to be encrypted is pointed to by the \fIin\fR parameter which is \fIinlen\fR -bytes long. -Unless \fIout\fR is \s-1NULL,\s0 the encrypted data should be written to the location -pointed to by the \fIout\fR parameter and it should not exceed \fIoutsize\fR bytes in -length. -The length of the encrypted data should be written to \fI*outlen\fR. -If \fIout\fR is \s-1NULL\s0 then the maximum length of the encrypted data should be -written to \fI*outlen\fR. -.SS "Decryption Functions" -.IX Subsection "Decryption Functions" -\&\fBOSSL_FUNC_asym_cipher_decrypt_init()\fR initialises a context for an asymmetric decryption -given a provider side asymmetric cipher context in the \fIctx\fR parameter, and a -pointer to a provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_asym_cipher_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)). -.PP -\&\fBOSSL_FUNC_asym_cipher_decrypt()\fR performs the actual decryption itself. -A previously initialised asymmetric cipher context is passed in the \fIctx\fR -parameter. -The data to be decrypted is pointed to by the \fIin\fR parameter which is \fIinlen\fR -bytes long. -Unless \fIout\fR is \s-1NULL,\s0 the decrypted data should be written to the location -pointed to by the \fIout\fR parameter and it should not exceed \fIoutsize\fR bytes in -length. -The length of the decrypted data should be written to \fI*outlen\fR. -If \fIout\fR is \s-1NULL\s0 then the maximum length of the decrypted data should be -written to \fI*outlen\fR. -.SS "Asymmetric Cipher Parameters" -.IX Subsection "Asymmetric Cipher Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -the \fBOSSL_FUNC_asym_cipher_get_ctx_params()\fR and \fBOSSL_FUNC_asym_cipher_set_ctx_params()\fR -functions. -.PP -\&\fBOSSL_FUNC_asym_cipher_get_ctx_params()\fR gets asymmetric cipher parameters associated -with the given provider side asymmetric cipher context \fIctx\fR and stores them in -\&\fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_asym_cipher_set_ctx_params()\fR sets the asymmetric cipher parameters associated -with the given provider side asymmetric cipher context \fIctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -Parameters currently recognised by built-in asymmetric cipher algorithms are as -follows. -Not all parameters are relevant to, or are understood by all asymmetric cipher -algorithms: -.ie n .IP """pad-mode"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string> \s-1OR\s0 " 4 -.el .IP "``pad-mode'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_PAD_MODE\s0\fR) <\s-1UTF8\s0 string> \s-1OR\s0 " 4 -.IX Item "pad-mode (OSSL_ASYM_CIPHER_PARAM_PAD_MODE) OR " -The type of padding to be used. The interpretation of this value will depend -on the algorithm in use. -.ie n .IP """digest"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST) " -Gets or sets the name of the \s-1OAEP\s0 digest algorithm used when \s-1OAEP\s0 padding is in -use. -.ie n .IP """digest"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_ASYM_CIPHER_PARAM_DIGEST) " -Gets or sets the name of the digest algorithm used by the algorithm (where -applicable). -.ie n .IP """digest-props"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest-props'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest-props (OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS) " -Gets or sets the properties to use when fetching the \s-1OAEP\s0 digest algorithm. -.ie n .IP """digest-props"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest-props'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest-props (OSSL_ASYM_CIPHER_PARAM_DIGEST_PROPS) " -Gets or sets the properties to use when fetching the cipher digest algorithm. -.ie n .IP """mgf1\-digest"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mgf1\-digest'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mgf1-digest (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST) " -Gets or sets the name of the \s-1MGF1\s0 digest algorithm used when \s-1OAEP\s0 or \s-1PSS\s0 padding -is in use. -.ie n .IP """mgf1\-digest\-props"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mgf1\-digest\-props'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mgf1-digest-props (OSSL_ASYM_CIPHER_PARAM_MGF1_DIGEST_PROPS) " -Gets or sets the properties to use when fetching the \s-1MGF1\s0 digest algorithm. -.ie n .IP """oaep-label"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL\s0\fR) " 4 -.el .IP "``oaep-label'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL\s0\fR) " 4 -.IX Item "oaep-label (OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL) " -Gets the \s-1OAEP\s0 label used when \s-1OAEP\s0 padding is in use. -.ie n .IP """oaep-label"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL\s0\fR) " 4 -.el .IP "``oaep-label'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL\s0\fR) " 4 -.IX Item "oaep-label (OSSL_ASYM_CIPHER_PARAM_OAEP_LABEL) " -Sets the \s-1OAEP\s0 label used when \s-1OAEP\s0 padding is in use. -.ie n .IP """tls-client-version"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.el .IP "``tls-client-version'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.IX Item "tls-client-version (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) " -The \s-1TLS\s0 protocol version first requested by the client. -.ie n .IP """tls-negotiated-version"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.el .IP "``tls-negotiated-version'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION\s0\fR) " 4 -.IX Item "tls-negotiated-version (OSSL_ASYM_CIPHER_PARAM_TLS_CLIENT_VERSION) " -The negotiated \s-1TLS\s0 protocol version. -.ie n .IP """implicit-rejection"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION\s0\fR) " 4 -.el .IP "``implicit-rejection'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION\s0\fR) " 4 -.IX Item "implicit-rejection (OSSL_ASYM_CIPHER_PARAM_IMPLICIT_REJECTION) " -Gets or sets the use of the implicit rejection mechanism for \s-1RSA\s0 PKCS#1 v1.5 -decryption. When set (non zero value), the decryption \s-1API\s0 will return -a deterministically random value if the PKCS#1 v1.5 padding check fails. -This makes exploitation of the Bleichenbacher significantly harder, even -if the code using the \s-1RSA\s0 decryption \s-1API\s0 is not implemented in side-channel -free manner. Set by default in OpenSSL providers. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling either \fBOSSL_FUNC_asym_cipher_encrypt()\fR or -\&\fBOSSL_FUNC_asym_cipher_decrypt()\fR. It may return 0 if \*(L"key-check\*(R" is set to 0. -.ie n .IP """key-check"" (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_ASYM_CIPHER_PARAM_FIPS_KEY_CHECK) " -If required this parameter should be set using either -\&\fBOSSL_FUNC_asym_cipher_encrypt_init()\fR or \fBOSSL_FUNC_asym_cipher_decrypt_init()\fR. -The default value of 1 causes an error during the init if the key is not \s-1FIPS\s0 -approved (e.g. The key has a security strength of less than 112 bits). Setting -this to 0 will ignore the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.PP -\&\fBOSSL_FUNC_asym_cipher_gettable_ctx_params()\fR and \fBOSSL_FUNC_asym_cipher_settable_ctx_params()\fR -get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the gettable and settable -parameters, i.e. parameters that can be used with \fBOSSL_FUNC_asym_cipherget_ctx_params()\fR -and \fBOSSL_FUNC_asym_cipher_set_ctx_params()\fR respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_asym_cipher_newctx()\fR and \fBOSSL_FUNC_asym_cipher_dupctx()\fR should return the newly -created provider side asymmetric cipher context, or \s-1NULL\s0 on failure. -.PP -All other functions should return 1 for success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1ASYM_CIPHER\s0 interface was introduced in OpenSSL 3.0. -The Asymmetric Cipher Parameters \*(L"fips-indicator\*(R" and \*(L"key-check\*(R" -were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-base.7ossl b/openssl-install/share/man/man7/provider-base.7ossl deleted file mode 100644 index 25515466..00000000 --- a/openssl-install/share/man/man7/provider-base.7ossl +++ /dev/null @@ -1,1104 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-BASE 7ossl" -.TH PROVIDER-BASE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-base -\&\- The basic OpenSSL library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Functions offered by libcrypto to the providers */ -\& const OSSL_ITEM *core_gettable_params(const OSSL_CORE_HANDLE *handle); -\& int core_get_params(const OSSL_CORE_HANDLE *handle, OSSL_PARAM params[]); -\& -\& typedef void (*OSSL_thread_stop_handler_fn)(void *arg); -\& int core_thread_start(const OSSL_CORE_HANDLE *handle, -\& OSSL_thread_stop_handler_fn handfn, -\& void *arg); -\& -\& OPENSSL_CORE_CTX *core_get_libctx(const OSSL_CORE_HANDLE *handle); -\& void core_new_error(const OSSL_CORE_HANDLE *handle); -\& void core_set_error_debug(const OSSL_CORE_HANDLE *handle, -\& const char *file, int line, const char *func); -\& void core_vset_error(const OSSL_CORE_HANDLE *handle, -\& uint32_t reason, const char *fmt, va_list args); -\& -\& int core_obj_add_sigid(const OSSL_CORE_HANDLE *prov, const char *sign_name, -\& const char *digest_name, const char *pkey_name); -\& int core_obj_create(const OSSL_CORE_HANDLE *handle, const char *oid, -\& const char *sn, const char *ln); -\& -\& /* -\& * Some OpenSSL functionality is directly offered to providers via -\& * dispatch -\& */ -\& void *CRYPTO_malloc(size_t num, const char *file, int line); -\& void *CRYPTO_zalloc(size_t num, const char *file, int line); -\& void CRYPTO_free(void *ptr, const char *file, int line); -\& void CRYPTO_clear_free(void *ptr, size_t num, -\& const char *file, int line); -\& void *CRYPTO_realloc(void *addr, size_t num, -\& const char *file, int line); -\& void *CRYPTO_clear_realloc(void *addr, size_t old_num, size_t num, -\& const char *file, int line); -\& void *CRYPTO_secure_malloc(size_t num, const char *file, int line); -\& void *CRYPTO_secure_zalloc(size_t num, const char *file, int line); -\& void CRYPTO_secure_free(void *ptr, const char *file, int line); -\& void CRYPTO_secure_clear_free(void *ptr, size_t num, -\& const char *file, int line); -\& int CRYPTO_secure_allocated(const void *ptr); -\& void OPENSSL_cleanse(void *ptr, size_t len); -\& -\& unsigned char *OPENSSL_hexstr2buf(const char *str, long *buflen); -\& -\& OSSL_CORE_BIO *BIO_new_file(const char *filename, const char *mode); -\& OSSL_CORE_BIO *BIO_new_membuf(const void *buf, int len); -\& int BIO_read_ex(OSSL_CORE_BIO *bio, void *data, size_t data_len, -\& size_t *bytes_read); -\& int BIO_write_ex(OSSL_CORE_BIO *bio, const void *data, size_t data_len, -\& size_t *written); -\& int BIO_up_ref(OSSL_CORE_BIO *bio); -\& int BIO_free(OSSL_CORE_BIO *bio); -\& int BIO_vprintf(OSSL_CORE_BIO *bio, const char *format, va_list args); -\& int BIO_vsnprintf(char *buf, size_t n, const char *fmt, va_list args); -\& -\& void OSSL_SELF_TEST_set_callback(OSSL_LIB_CTX *libctx, OSSL_CALLBACK *cb, -\& void *cbarg); -\& -\& size_t get_entropy(const OSSL_CORE_HANDLE *handle, -\& unsigned char **pout, int entropy, -\& size_t min_len, size_t max_len); -\& size_t get_user_entropy(const OSSL_CORE_HANDLE *handle, -\& unsigned char **pout, int entropy, -\& size_t min_len, size_t max_len); -\& void cleanup_entropy(const OSSL_CORE_HANDLE *handle, -\& unsigned char *buf, size_t len); -\& void cleanup_user_entropy(const OSSL_CORE_HANDLE *handle, -\& unsigned char *buf, size_t len); -\& size_t get_nonce(const OSSL_CORE_HANDLE *handle, -\& unsigned char **pout, size_t min_len, size_t max_len, -\& const void *salt, size_t salt_len); -\& size_t get_user_nonce(const OSSL_CORE_HANDLE *handle, -\& unsigned char **pout, size_t min_len, size_t max_len, -\& const void *salt, size_t salt_len); -\& void cleanup_nonce(const OSSL_CORE_HANDLE *handle, -\& unsigned char *buf, size_t len); -\& void cleanup_user_nonce(const OSSL_CORE_HANDLE *handle, -\& unsigned char *buf, size_t len); -\& -\& /* Functions for querying the providers in the application library context */ -\& int provider_register_child_cb(const OSSL_CORE_HANDLE *handle, -\& int (*create_cb)(const OSSL_CORE_HANDLE *provider, -\& void *cbdata), -\& int (*remove_cb)(const OSSL_CORE_HANDLE *provider, -\& void *cbdata), -\& int (*global_props_cb)(const char *props, void *cbdata), -\& void *cbdata); -\& void provider_deregister_child_cb(const OSSL_CORE_HANDLE *handle); -\& const char *provider_name(const OSSL_CORE_HANDLE *prov); -\& void *provider_get0_provider_ctx(const OSSL_CORE_HANDLE *prov); -\& const OSSL_DISPATCH *provider_get0_dispatch(const OSSL_CORE_HANDLE *prov); -\& int provider_up_ref(const OSSL_CORE_HANDLE *prov, int activate); -\& int provider_free(const OSSL_CORE_HANDLE *prov, int deactivate); -\& -\& /* Functions offered by the provider to libcrypto */ -\& void provider_teardown(void *provctx); -\& const OSSL_ITEM *provider_gettable_params(void *provctx); -\& int provider_get_params(void *provctx, OSSL_PARAM params[]); -\& const OSSL_ALGORITHM *provider_query_operation(void *provctx, -\& int operation_id, -\& const int *no_store); -\& void provider_unquery_operation(void *provctx, int operation_id, -\& const OSSL_ALGORITHM *algs); -\& const OSSL_ITEM *provider_get_reason_strings(void *provctx); -\& int provider_get_capabilities(void *provctx, const char *capability, -\& OSSL_CALLBACK *cb, void *arg); -\& int provider_self_test(void *provctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays, in the call -of the provider initialization function. See \*(L"Provider\*(R" in \fBprovider\fR\|(7) -for a description of the initialization function. They are known as \*(L"upcalls\*(R". -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from a \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBcore_gettable_params()\fR has these: -.PP -.Vb 4 -\& typedef OSSL_PARAM * -\& (OSSL_FUNC_core_gettable_params_fn)(const OSSL_CORE_HANDLE *handle); -\& static ossl_inline OSSL_NAME_core_gettable_params_fn -\& OSSL_FUNC_core_gettable_params(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -For \fIin\fR (the \s-1\fBOSSL_DISPATCH\s0\fR\|(3) array passed from \fIlibcrypto\fR to the -provider): -.PP -.Vb 10 -\& core_gettable_params OSSL_FUNC_CORE_GETTABLE_PARAMS -\& core_get_params OSSL_FUNC_CORE_GET_PARAMS -\& core_thread_start OSSL_FUNC_CORE_THREAD_START -\& core_get_libctx OSSL_FUNC_CORE_GET_LIBCTX -\& core_new_error OSSL_FUNC_CORE_NEW_ERROR -\& core_set_error_debug OSSL_FUNC_CORE_SET_ERROR_DEBUG -\& core_vset_error OSSL_FUNC_CORE_VSET_ERROR -\& core_obj_add_sigid OSSL_FUNC_CORE_OBJ_ADD_SIGID -\& core_obj_create OSSL_FUNC_CORE_OBJ_CREATE -\& CRYPTO_malloc OSSL_FUNC_CRYPTO_MALLOC -\& CRYPTO_zalloc OSSL_FUNC_CRYPTO_ZALLOC -\& CRYPTO_free OSSL_FUNC_CRYPTO_FREE -\& CRYPTO_clear_free OSSL_FUNC_CRYPTO_CLEAR_FREE -\& CRYPTO_realloc OSSL_FUNC_CRYPTO_REALLOC -\& CRYPTO_clear_realloc OSSL_FUNC_CRYPTO_CLEAR_REALLOC -\& CRYPTO_secure_malloc OSSL_FUNC_CRYPTO_SECURE_MALLOC -\& CRYPTO_secure_zalloc OSSL_FUNC_CRYPTO_SECURE_ZALLOC -\& CRYPTO_secure_free OSSL_FUNC_CRYPTO_SECURE_FREE -\& CRYPTO_secure_clear_free OSSL_FUNC_CRYPTO_SECURE_CLEAR_FREE -\& CRYPTO_secure_allocated OSSL_FUNC_CRYPTO_SECURE_ALLOCATED -\& BIO_new_file OSSL_FUNC_BIO_NEW_FILE -\& BIO_new_mem_buf OSSL_FUNC_BIO_NEW_MEMBUF -\& BIO_read_ex OSSL_FUNC_BIO_READ_EX -\& BIO_write_ex OSSL_FUNC_BIO_WRITE_EX -\& BIO_up_ref OSSL_FUNC_BIO_UP_REF -\& BIO_free OSSL_FUNC_BIO_FREE -\& BIO_vprintf OSSL_FUNC_BIO_VPRINTF -\& BIO_vsnprintf OSSL_FUNC_BIO_VSNPRINTF -\& BIO_puts OSSL_FUNC_BIO_PUTS -\& BIO_gets OSSL_FUNC_BIO_GETS -\& BIO_ctrl OSSL_FUNC_BIO_CTRL -\& OPENSSL_cleanse OSSL_FUNC_OPENSSL_CLEANSE -\& OSSL_SELF_TEST_set_callback OSSL_FUNC_SELF_TEST_CB -\& ossl_rand_get_entropy OSSL_FUNC_GET_ENTROPY -\& ossl_rand_get_user_entropy OSSL_FUNC_GET_USER_ENTROPY -\& ossl_rand_cleanup_entropy OSSL_FUNC_CLEANUP_ENTROPY -\& ossl_rand_cleanup_user_entropy OSSL_FUNC_CLEANUP_USER_ENTROPY -\& ossl_rand_get_nonce OSSL_FUNC_GET_NONCE -\& ossl_rand_get_user_nonce OSSL_FUNC_GET_USER_NONCE -\& ossl_rand_cleanup_nonce OSSL_FUNC_CLEANUP_NONCE -\& ossl_rand_cleanup_user_nonce OSSL_FUNC_CLEANUP_USER_NONCE -\& provider_register_child_cb OSSL_FUNC_PROVIDER_REGISTER_CHILD_CB -\& provider_deregister_child_cb OSSL_FUNC_PROVIDER_DEREGISTER_CHILD_CB -\& provider_name OSSL_FUNC_PROVIDER_NAME -\& provider_get0_provider_ctx OSSL_FUNC_PROVIDER_GET0_PROVIDER_CTX -\& provider_get0_dispatch OSSL_FUNC_PROVIDER_GET0_DISPATCH -\& provider_up_ref OSSL_FUNC_PROVIDER_UP_REF -\& provider_free OSSL_FUNC_PROVIDER_FREE -.Ve -.PP -For \fI*out\fR (the \s-1\fBOSSL_DISPATCH\s0\fR\|(3) array passed from the provider to -\&\fIlibcrypto\fR): -.PP -.Vb 8 -\& provider_teardown OSSL_FUNC_PROVIDER_TEARDOWN -\& provider_gettable_params OSSL_FUNC_PROVIDER_GETTABLE_PARAMS -\& provider_get_params OSSL_FUNC_PROVIDER_GET_PARAMS -\& provider_query_operation OSSL_FUNC_PROVIDER_QUERY_OPERATION -\& provider_unquery_operation OSSL_FUNC_PROVIDER_UNQUERY_OPERATION -\& provider_get_reason_strings OSSL_FUNC_PROVIDER_GET_REASON_STRINGS -\& provider_get_capabilities OSSL_FUNC_PROVIDER_GET_CAPABILITIES -\& provider_self_test OSSL_FUNC_PROVIDER_SELF_TEST -.Ve -.SS "Core functions" -.IX Subsection "Core functions" -\&\fBcore_gettable_params()\fR returns a constant array of descriptor -\&\s-1\fBOSSL_PARAM\s0\fR\|(3), for parameters that \fBcore_get_params()\fR can handle. -.PP -\&\fBcore_get_params()\fR retrieves parameters from the core for the given \fIhandle\fR. -See \*(L"Core parameters\*(R" below for a description of currently known -parameters. -.PP -The \fBcore_thread_start()\fR function informs the core that the provider has stated -an interest in the current thread. The core will inform the provider when the -thread eventually stops. It must be passed the \fIhandle\fR for this provider, as -well as a callback \fIhandfn\fR which will be called when the thread stops. The -callback will subsequently be called, with the supplied argument \fIarg\fR, from -the thread that is stopping and gets passed the provider context as an -argument. This may be useful to perform thread specific clean up such as -freeing thread local variables. -.PP -\&\fBcore_get_libctx()\fR retrieves the core context in which the library -object for the current provider is stored, accessible through the \fIhandle\fR. -This function is useful only for built-in providers such as the default -provider. Never cast this to \s-1OSSL_LIB_CTX\s0 in a provider that is not -built-in as the \s-1OSSL_LIB_CTX\s0 of the library loading the provider might be -a completely different structure than the \s-1OSSL_LIB_CTX\s0 of the library the -provider is linked to. Use \fBOSSL_LIB_CTX_new_child\fR\|(3) instead to obtain -a proper library context that is linked to the application library context. -.PP -\&\fBcore_new_error()\fR, \fBcore_set_error_debug()\fR and \fBcore_vset_error()\fR are -building blocks for reporting an error back to the core, with -reference to the \fIhandle\fR. -.IP "\fBcore_new_error()\fR" 4 -.IX Item "core_new_error()" -allocates a new thread specific error record. -.Sp -This corresponds to the OpenSSL function \fBERR_new\fR\|(3). -.IP "\fBcore_set_error_debug()\fR" 4 -.IX Item "core_set_error_debug()" -sets debugging information in the current thread specific error -record. -The debugging information includes the name of the file \fIfile\fR, the -line \fIline\fR and the function name \fIfunc\fR where the error occurred. -.Sp -This corresponds to the OpenSSL function \fBERR_set_debug\fR\|(3). -.IP "\fBcore_vset_error()\fR" 4 -.IX Item "core_vset_error()" -sets the \fIreason\fR for the error, along with any addition data. -The \fIreason\fR is a number defined by the provider and used to index -the reason strings table that's returned by -\&\fBprovider_get_reason_strings()\fR. -The additional data is given as a format string \fIfmt\fR and a set of -arguments \fIargs\fR, which are treated in the same manner as with -\&\fBBIO_vsnprintf()\fR. -\&\fIfile\fR and \fIline\fR may also be passed to indicate exactly where the -error occurred or was reported. -.Sp -This corresponds to the OpenSSL function \fBERR_vset_error\fR\|(3). -.PP -The \fBcore_obj_create()\fR function registers a new \s-1OID\s0 and associated short name -\&\fIsn\fR and long name \fIln\fR for the given \fIhandle\fR. It is similar to the OpenSSL -function \fBOBJ_create\fR\|(3) except that it returns 1 on success or 0 on failure. -It will treat as success the case where the \s-1OID\s0 already exists (even if the -short name \fIsn\fR or long name \fIln\fR provided as arguments differ from those -associated with the existing \s-1OID,\s0 in which case the new names are not -associated). -.PP -The \fBcore_obj_add_sigid()\fR function registers a new composite signature algorithm -(\fIsign_name\fR) consisting of an underlying signature algorithm (\fIpkey_name\fR) -and digest algorithm (\fIdigest_name\fR) for the given \fIhandle\fR. It assumes that -the OIDs for the composite signature algorithm as well as for the underlying -signature and digest algorithms are either already known to OpenSSL or have been -registered via a call to \fBcore_obj_create()\fR. It corresponds to the OpenSSL -function \fBOBJ_add_sigid\fR\|(3), except that the objects are identified by name -rather than a numeric \s-1NID.\s0 Any name (\s-1OID,\s0 short name or long name) can be used -to identify the object. It will treat as success the case where the composite -signature algorithm already exists (even if registered against a different -underlying signature or digest algorithm). For \fIdigest_name\fR, \s-1NULL\s0 or an -empty string is permissible for signature algorithms that do not need a digest -to operate correctly. The function returns 1 on success or 0 on failure. -.PP -\&\fBCRYPTO_malloc()\fR, \fBCRYPTO_zalloc()\fR, \fBCRYPTO_free()\fR, \fBCRYPTO_clear_free()\fR, -\&\fBCRYPTO_realloc()\fR, \fBCRYPTO_clear_realloc()\fR, \fBCRYPTO_secure_malloc()\fR, -\&\fBCRYPTO_secure_zalloc()\fR, \fBCRYPTO_secure_free()\fR, -\&\fBCRYPTO_secure_clear_free()\fR, \fBCRYPTO_secure_allocated()\fR, -\&\fBBIO_new_file()\fR, \fBBIO_new_mem_buf()\fR, \fBBIO_read_ex()\fR, \fBBIO_write_ex()\fR, \fBBIO_up_ref()\fR, -\&\fBBIO_free()\fR, \fBBIO_vprintf()\fR, \fBBIO_vsnprintf()\fR, \fBBIO_gets()\fR, \fBBIO_puts()\fR, -\&\fBBIO_ctrl()\fR, \fBOPENSSL_cleanse()\fR and -\&\fBOPENSSL_hexstr2buf()\fR correspond exactly to the public functions with -the same name. As a matter of fact, the pointers in the \s-1\fBOSSL_DISPATCH\s0\fR\|(3) -array are typically direct pointers to those public functions. Note that the \s-1BIO\s0 -functions take an \fB\s-1OSSL_CORE_BIO\s0\fR type rather than the standard \fB\s-1BIO\s0\fR -type. This is to ensure that a provider does not mix BIOs from the core -with BIOs used on the provider side (the two are not compatible). -\&\fBOSSL_SELF_TEST_set_callback()\fR is used to set an optional callback that can be -passed into a provider. This may be ignored by a provider. -.PP -\&\fBget_entropy()\fR retrieves seeding material from the operating system. -The seeding material will have at least \fIentropy\fR bytes of randomness and the -output will have at least \fImin_len\fR and at most \fImax_len\fR bytes. -The buffer address is stored in \fI*pout\fR and the buffer length is -returned to the caller. On error, zero is returned. -.PP -\&\fBget_user_entropy()\fR is the same as \fBget_entropy()\fR except that it will -attempt to gather seed material via the seed source specified by a call to -\&\fBRAND_set_seed_source_type\fR\|(3) or via \*(L"Random Configuration\*(R" in \fBconfig\fR\|(5). -.PP -\&\fBcleanup_entropy()\fR is used to clean up and free the buffer returned by -\&\fBget_entropy()\fR. The entropy pointer returned by \fBget_entropy()\fR -is passed in \fBbuf\fR and its length in \fBlen\fR. -.PP -\&\fBcleanup_user_entropy()\fR is used to clean up and free the buffer returned by -\&\fBget_user_entropy()\fR. The entropy pointer returned by \fBget_user_entropy()\fR -is passed in \fBbuf\fR and its length in \fBlen\fR. -.PP -\&\fBget_nonce()\fR retrieves a nonce using the passed \fIsalt\fR parameter -of length \fIsalt_len\fR and operating system specific information. -The \fIsalt\fR should contain uniquely identifying information and this is -included, in an unspecified manner, as part of the output. -The output is stored in a buffer which contains at least \fImin_len\fR and at -most \fImax_len\fR bytes. The buffer address is stored in \fI*pout\fR and the -buffer length returned to the caller. On error, zero is returned. -.PP -\&\fBget_user_nonce()\fR is the same as \fBget_nonce()\fR except that it will attempt -to gather seed material via the seed source specified by a call to -\&\fBRAND_set_seed_source_type\fR\|(3) or via \*(L"Random Configuration\*(R" in \fBconfig\fR\|(5). -.PP -\&\fBcleanup_nonce()\fR is used to clean up and free the buffer returned by -\&\fBget_nonce()\fR. The nonce pointer returned by \fBget_nonce()\fR -is passed in \fBbuf\fR and its length in \fBlen\fR. -.PP -\&\fBcleanup_user_nonce()\fR is used to clean up and free the buffer returned by -\&\fBget_user_nonce()\fR. The nonce pointer returned by \fBget_user_nonce()\fR -is passed in \fBbuf\fR and its length in \fBlen\fR. -.PP -\&\fBprovider_register_child_cb()\fR registers callbacks for being informed about the -loading and unloading of providers in the application's library context. -\&\fIhandle\fR is this provider's handle and \fIcbdata\fR is this provider's data -that will be passed back to the callbacks. It returns 1 on success or 0 -otherwise. These callbacks may be called while holding locks in libcrypto. In -order to avoid deadlocks the callback implementation must not be long running -and must not call other OpenSSL \s-1API\s0 functions or upcalls. -.PP -\&\fIcreate_cb\fR is a callback that will be called when a new provider is loaded -into the application's library context. It is also called for any providers that -are already loaded at the point that this callback is registered. The callback -is passed the handle being used for the new provider being loadded and this -provider's data in \fIcbdata\fR. It should return 1 on success or 0 on failure. -.PP -\&\fIremove_cb\fR is a callback that will be called when a new provider is unloaded -from the application's library context. It is passed the handle being used for -the provider being unloaded and this provider's data in \fIcbdata\fR. It should -return 1 on success or 0 on failure. -.PP -\&\fIglobal_props_cb\fR is a callback that will be called when the global properties -from the parent library context are changed. It should return 1 on success -or 0 on failure. -.PP -\&\fBprovider_deregister_child_cb()\fR unregisters callbacks previously registered via -\&\fBprovider_register_child_cb()\fR. If \fBprovider_register_child_cb()\fR has been called -then \fBprovider_deregister_child_cb()\fR should be called at or before the point that -this provider's teardown function is called. -.PP -\&\fBprovider_name()\fR returns a string giving the name of the provider identified by -\&\fIhandle\fR. -.PP -\&\fBprovider_get0_provider_ctx()\fR returns the provider context that is associated -with the provider identified by \fIprov\fR. -.PP -\&\fBprovider_get0_dispatch()\fR gets the dispatch table registered by the provider -identified by \fIprov\fR when it initialised. -.PP -\&\fBprovider_up_ref()\fR increments the reference count on the provider \fIprov\fR. If -\&\fIactivate\fR is nonzero then the provider is also loaded if it is not already -loaded. It returns 1 on success or 0 on failure. -.PP -\&\fBprovider_free()\fR decrements the reference count on the provider \fIprov\fR. If -\&\fIdeactivate\fR is nonzero then the provider is also unloaded if it is not -already loaded. It returns 1 on success or 0 on failure. -.SS "Provider functions" -.IX Subsection "Provider functions" -\&\fBprovider_teardown()\fR is called when a provider is shut down and removed -from the core's provider store. -It must free the passed \fIprovctx\fR. -.PP -\&\fBprovider_gettable_params()\fR should return a constant array of -descriptor \s-1\fBOSSL_PARAM\s0\fR\|(3), for parameters that \fBprovider_get_params()\fR -can handle. -.PP -\&\fBprovider_get_params()\fR should process the \s-1\fBOSSL_PARAM\s0\fR\|(3) array -\&\fIparams\fR, setting the values of the parameters it understands. -.PP -\&\fBprovider_query_operation()\fR should return a constant \s-1\fBOSSL_ALGORITHM\s0\fR\|(3) -that corresponds to the given \fIoperation_id\fR. -It should indicate if the core may store a reference to this array by -setting \fI*no_store\fR to 0 (core may store a reference) or 1 (core may -not store a reference). -.PP -\&\fBprovider_unquery_operation()\fR informs the provider that the result of a -\&\fBprovider_query_operation()\fR is no longer directly required and that the function -pointers have been copied. The \fIoperation_id\fR should match that passed to -\&\fBprovider_query_operation()\fR and \fIalgs\fR should be its return value. -.PP -\&\fBprovider_get_reason_strings()\fR should return a constant \s-1\fBOSSL_ITEM\s0\fR\|(3) -array that provides reason strings for reason codes the provider may -use when reporting errors using \fBcore_put_error()\fR. -.PP -The \fBprovider_get_capabilities()\fR function should call the callback \fIcb\fR passing -it a set of \s-1\fBOSSL_PARAM\s0\fR\|(3)s and the caller supplied argument \fIarg\fR. The -\&\s-1\fBOSSL_PARAM\s0\fR\|(3)s should provide details about the capability with the name given -in the \fIcapability\fR argument relevant for the provider context \fIprovctx\fR. If a -provider supports multiple capabilities with the given name then it may call the -callback multiple times (one for each capability). Capabilities can be useful for -describing the services that a provider can offer. For further details see the -\&\*(L"\s-1CAPABILITIES\*(R"\s0 section below. It should return 1 on success or 0 on error. -.PP -The \fBprovider_self_test()\fR function should perform known answer tests on a subset -of the algorithms that it uses, and may also verify the integrity of the -provider module. It should return 1 on success or 0 on error. It will return 1 -if this function is not used. -.PP -None of these functions are mandatory, but a provider is fairly -useless without at least \fBprovider_query_operation()\fR, and -\&\fBprovider_gettable_params()\fR is fairly useless if not accompanied by -\&\fBprovider_get_params()\fR. -.SS "Provider parameters" -.IX Subsection "Provider parameters" -\&\fBprovider_get_params()\fR can return the following provider parameters to the core: -.ie n .IP """name"" (\fB\s-1OSSL_PROV_PARAM_NAME\s0\fR) <\s-1UTF8\s0 ptr>" 4 -.el .IP "``name'' (\fB\s-1OSSL_PROV_PARAM_NAME\s0\fR) <\s-1UTF8\s0 ptr>" 4 -.IX Item "name (OSSL_PROV_PARAM_NAME) " -This points to a string that should give a unique name for the provider. -.ie n .IP """version"" (\fB\s-1OSSL_PROV_PARAM_VERSION\s0\fR) <\s-1UTF8\s0 ptr>" 4 -.el .IP "``version'' (\fB\s-1OSSL_PROV_PARAM_VERSION\s0\fR) <\s-1UTF8\s0 ptr>" 4 -.IX Item "version (OSSL_PROV_PARAM_VERSION) " -This points to a string that is a version number associated with this provider. -OpenSSL in-built providers use \s-1OPENSSL_VERSION_STR,\s0 but this may be different -for any third party provider. This string is for informational purposes only. -.ie n .IP """buildinfo"" (\fB\s-1OSSL_PROV_PARAM_BUILDINFO\s0\fR) <\s-1UTF8\s0 ptr>" 4 -.el .IP "``buildinfo'' (\fB\s-1OSSL_PROV_PARAM_BUILDINFO\s0\fR) <\s-1UTF8\s0 ptr>" 4 -.IX Item "buildinfo (OSSL_PROV_PARAM_BUILDINFO) " -This points to a string that is a build information associated with this provider. -OpenSSL in-built providers use \s-1OPENSSL_FULL_VERSION_STR,\s0 but this may be -different for any third party provider. -.ie n .IP """status"" (\fB\s-1OSSL_PROV_PARAM_STATUS\s0\fR) " 4 -.el .IP "``status'' (\fB\s-1OSSL_PROV_PARAM_STATUS\s0\fR) " 4 -.IX Item "status (OSSL_PROV_PARAM_STATUS) " -This returns 0 if the provider has entered an error state, otherwise it returns -1. -.PP -\&\fBprovider_gettable_params()\fR should return the above parameters. -.SS "Core parameters" -.IX Subsection "Core parameters" -\&\fBcore_get_params()\fR can retrieve the following core parameters for each provider: -.ie n .IP """openssl-version"" (\fB\s-1OSSL_PROV_PARAM_CORE_VERSION\s0\fR) <\s-1UTF8\s0 string ptr>" 4 -.el .IP "``openssl-version'' (\fB\s-1OSSL_PROV_PARAM_CORE_VERSION\s0\fR) <\s-1UTF8\s0 string ptr>" 4 -.IX Item "openssl-version (OSSL_PROV_PARAM_CORE_VERSION) " -This points to the OpenSSL libraries' full version string, i.e. the string -expanded from the macro \fB\s-1OPENSSL_VERSION_STR\s0\fR. -.ie n .IP """provider-name"" (\fB\s-1OSSL_PROV_PARAM_CORE_PROV_NAME\s0\fR) <\s-1UTF8\s0 string ptr>" 4 -.el .IP "``provider-name'' (\fB\s-1OSSL_PROV_PARAM_CORE_PROV_NAME\s0\fR) <\s-1UTF8\s0 string ptr>" 4 -.IX Item "provider-name (OSSL_PROV_PARAM_CORE_PROV_NAME) " -This points to the OpenSSL libraries' idea of what the calling provider is named. -.ie n .IP """module-filename"" (\fB\s-1OSSL_PROV_PARAM_CORE_MODULE_FILENAME\s0\fR) <\s-1UTF8\s0 string ptr>" 4 -.el .IP "``module-filename'' (\fB\s-1OSSL_PROV_PARAM_CORE_MODULE_FILENAME\s0\fR) <\s-1UTF8\s0 string ptr>" 4 -.IX Item "module-filename (OSSL_PROV_PARAM_CORE_MODULE_FILENAME) " -This points to a string containing the full filename of the providers -module file. -.PP -Additionally, provider specific configuration parameters from the -config file are available, in dotted name form. -The dotted name form is a concatenation of section names and final -config command name separated by periods. -.PP -For example, let's say we have the following config example: -.PP -.Vb 2 -\& config_diagnostics = 1 -\& openssl_conf = openssl_init -\& -\& [openssl_init] -\& providers = providers_sect -\& -\& [providers_sect] -\& foo = foo_sect -\& -\& [foo_sect] -\& activate = 1 -\& data1 = 2 -\& data2 = str -\& more = foo_more -\& -\& [foo_more] -\& data3 = foo,bar -.Ve -.PP -The provider will have these additional parameters available: -.ie n .IP """activate""" 4 -.el .IP "``activate''" 4 -.IX Item "activate" -pointing at the string \*(L"1\*(R" -.ie n .IP """data1""" 4 -.el .IP "``data1''" 4 -.IX Item "data1" -pointing at the string \*(L"2\*(R" -.ie n .IP """data2""" 4 -.el .IP "``data2''" 4 -.IX Item "data2" -pointing at the string \*(L"str\*(R" -.ie n .IP """more.data3""" 4 -.el .IP "``more.data3''" 4 -.IX Item "more.data3" -pointing at the string \*(L"foo,bar\*(R" -.PP -For more information on handling parameters, see \s-1\fBOSSL_PARAM\s0\fR\|(3) as -\&\fBOSSL_PARAM_int\fR\|(3). -.SH "CAPABILITIES" -.IX Header "CAPABILITIES" -Capabilities describe some of the services that a provider can offer. -Applications can query the capabilities to discover those services. -.PP -\fI\*(L"TLS-GROUP\*(R" Capability\fR -.IX Subsection "TLS-GROUP Capability" -.PP -The \*(L"TLS-GROUP\*(R" capability can be queried by libssl to discover the list of -\&\s-1TLS\s0 groups that a provider can support. Each group supported can be used for -\&\fIkey exchange\fR (\s-1KEX\s0) or \fIkey encapsulation method\fR (\s-1KEM\s0) during a \s-1TLS\s0 -handshake. -\&\s-1TLS\s0 clients can advertise the list of \s-1TLS\s0 groups they support in the -supported_groups extension, and \s-1TLS\s0 servers can select a group from the offered -list that they also support. In this way a provider can add to the list of -groups that libssl already supports with additional ones. -.PP -Each \s-1TLS\s0 group that a provider supports should be described via the callback -passed in through the provider_get_capabilities function. Each group should have -the following details supplied (all are mandatory, except -\&\fB\s-1OSSL_CAPABILITY_TLS_GROUP_IS_KEM\s0\fR): -.ie n .IP """tls-group-name"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``tls-group-name'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "tls-group-name (OSSL_CAPABILITY_TLS_GROUP_NAME) " -The name of the group as given in the \s-1IANA TLS\s0 Supported Groups registry -. -.ie n .IP """tls-group-name-internal"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_NAME_INTERNAL\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``tls-group-name-internal'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_NAME_INTERNAL\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "tls-group-name-internal (OSSL_CAPABILITY_TLS_GROUP_NAME_INTERNAL) " -The name of the group as known by the provider. This could be the same as the -\&\*(L"tls-group-name\*(R", but does not have to be. -.ie n .IP """tls-group-id"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_ID\s0\fR) " 4 -.el .IP "``tls-group-id'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_ID\s0\fR) " 4 -.IX Item "tls-group-id (OSSL_CAPABILITY_TLS_GROUP_ID) " -The \s-1TLS\s0 group id value as given in the \s-1IANA TLS\s0 Supported Groups registry. -.Sp -It is possible to register the same group id from within different -providers. Users should note that if no property query is specified, or -more than one implementation matches the property query then it is -unspecified which implementation for a particular group id will be used. -.ie n .IP """tls-group-alg"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_ALG\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``tls-group-alg'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_ALG\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "tls-group-alg (OSSL_CAPABILITY_TLS_GROUP_ALG) " -The name of a Key Management algorithm that the provider offers and that should -be used with this group. Keys created should be able to support \fIkey exchange\fR -or \fIkey encapsulation method\fR (\s-1KEM\s0), as implied by the optional -\&\fB\s-1OSSL_CAPABILITY_TLS_GROUP_IS_KEM\s0\fR flag. -The algorithm must support key and parameter generation as well as the -key/parameter generation parameter, \fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR. The group -name given via \*(L"tls-group-name-internal\*(R" above will be passed via -\&\fB\s-1OSSL_PKEY_PARAM_GROUP_NAME\s0\fR when libssl wishes to generate keys/parameters. -.ie n .IP """tls-group-sec-bits"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_SECURITY_BITS\s0\fR) " 4 -.el .IP "``tls-group-sec-bits'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_SECURITY_BITS\s0\fR) " 4 -.IX Item "tls-group-sec-bits (OSSL_CAPABILITY_TLS_GROUP_SECURITY_BITS) " -The number of bits of security offered by keys in this group. The number of bits -should be comparable with the ones given in table 2 and 3 of the \s-1NIST SP800\-57\s0 -document. -.ie n .IP """tls-group-is-kem"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_IS_KEM\s0\fR) " 4 -.el .IP "``tls-group-is-kem'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_IS_KEM\s0\fR) " 4 -.IX Item "tls-group-is-kem (OSSL_CAPABILITY_TLS_GROUP_IS_KEM) " -Boolean flag to describe if the group should be used in \fIkey exchange\fR (\s-1KEX\s0) -mode (0, default) or in \fIkey encapsulation method\fR (\s-1KEM\s0) mode (1). -.Sp -This parameter is optional: if not specified, \s-1KEX\s0 mode is assumed as the default -mode for the group. -.Sp -In \s-1KEX\s0 mode, in a typical Diffie-Hellman fashion, both sides execute \fIkeygen\fR -then \fIderive\fR against the peer public key. To operate in \s-1KEX\s0 mode, the group -implementation must support the provider functions as described in -\&\fBprovider\-keyexch\fR\|(7). -.Sp -In \s-1KEM\s0 mode, the client executes \fIkeygen\fR and sends its public key, the server -executes \fIencapsulate\fR using the client's public key and sends back the -resulting \fIciphertext\fR, finally the client executes \fIdecapsulate\fR to retrieve -the same \fIshared secret\fR generated by the server's \fIencapsulate\fR. To operate -in \s-1KEM\s0 mode, the group implementation must support the provider functions as -described in \fBprovider\-kem\fR\|(7). -.Sp -Both in \s-1KEX\s0 and \s-1KEM\s0 mode, the resulting \fIshared secret\fR is then used according -to the protocol specification. -.ie n .IP """tls-min-tls"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MIN_TLS\s0\fR) " 4 -.el .IP "``tls-min-tls'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MIN_TLS\s0\fR) " 4 -.IX Item "tls-min-tls (OSSL_CAPABILITY_TLS_GROUP_MIN_TLS) " -.PD 0 -.ie n .IP """tls-max-tls"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MAX_TLS\s0\fR) " 4 -.el .IP "``tls-max-tls'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MAX_TLS\s0\fR) " 4 -.IX Item "tls-max-tls (OSSL_CAPABILITY_TLS_GROUP_MAX_TLS) " -.ie n .IP """tls-min-dtls"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MIN_DTLS\s0\fR) " 4 -.el .IP "``tls-min-dtls'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MIN_DTLS\s0\fR) " 4 -.IX Item "tls-min-dtls (OSSL_CAPABILITY_TLS_GROUP_MIN_DTLS) " -.ie n .IP """tls-max-dtls"" (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MAX_DTLS\s0\fR) " 4 -.el .IP "``tls-max-dtls'' (\fB\s-1OSSL_CAPABILITY_TLS_GROUP_MAX_DTLS\s0\fR) " 4 -.IX Item "tls-max-dtls (OSSL_CAPABILITY_TLS_GROUP_MAX_DTLS) " -.PD -These parameters can be used to describe the minimum and maximum \s-1TLS\s0 and \s-1DTLS\s0 -versions supported by the group. The values equate to the on-the-wire encoding -of the various \s-1TLS\s0 versions. For example TLSv1.3 is 0x0304 (772 decimal), and -TLSv1.2 is 0x0303 (771 decimal). A 0 indicates that there is no defined minimum -or maximum. A \-1 indicates that the group should not be used in that protocol. -.PP -\fI\*(L"TLS-SIGALG\*(R" Capability\fR -.IX Subsection "TLS-SIGALG Capability" -.PP -The \*(L"TLS-SIGALG\*(R" capability can be queried by libssl to discover the list of -\&\s-1TLS\s0 signature algorithms that a provider can support. Each signature supported -can be used for client\- or server-authentication in addition to the built-in -signature algorithms. -\&\s-1TLS1.3\s0 clients can advertise the list of \s-1TLS\s0 signature algorithms they support -in the signature_algorithms extension, and \s-1TLS\s0 servers can select an algorithm -from the offered list that they also support. In this way a provider can add -to the list of signature algorithms that libssl already supports with -additional ones. -.PP -Each \s-1TLS\s0 signature algorithm that a provider supports should be described via -the callback passed in through the provider_get_capabilities function. Each -algorithm can have the following details supplied: -.ie n .IP """iana-name"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_IANA_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``iana-name'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_IANA_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "iana-name (OSSL_CAPABILITY_TLS_SIGALG_IANA_NAME) " -The name of the signature algorithm as given in the \s-1IANA TLS\s0 Signature Scheme -registry as \*(L"Description\*(R": -. -This value must be supplied. -.ie n .IP """iana-code-point"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_CODE_POINT\s0\fR) " 4 -.el .IP "``iana-code-point'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_CODE_POINT\s0\fR) " 4 -.IX Item "iana-code-point (OSSL_CAPABILITY_TLS_SIGALG_CODE_POINT) " -The \s-1TLS\s0 algorithm \s-1ID\s0 value as given in the \s-1IANA TLS\s0 SignatureScheme registry. -This value must be supplied. -.Sp -It is possible to register the same code point from within different -providers. Users should note that if no property query is specified, or -more than one implementation matches the property query then it is -unspecified which implementation for a particular code point will be used. -.ie n .IP """sigalg-name"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``sigalg-name'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "sigalg-name (OSSL_CAPABILITY_TLS_SIGALG_NAME) " -A name for the full (possibly composite hash-and-signature) signature -algorithm. -The provider may, but is not obligated to, provide a signature implementation -with this name; if it doesn't, this is assumed to be a composite of a pure -signature algorithm and a hash algorithm, which must be given with the -parameters \*(L"sig-name\*(R" and \*(L"hash-name\*(R". -This value must be supplied. -.ie n .IP """sigalg-oid"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``sigalg-oid'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "sigalg-oid (OSSL_CAPABILITY_TLS_SIGALG_OID) " -The \s-1OID\s0 of the \*(L"sigalg-name\*(R" algorithm in canonical numeric text form. If -this parameter is given, \fBOBJ_create()\fR will be used to create an \s-1OBJ\s0 and -a \s-1NID\s0 for this \s-1OID,\s0 using the \*(L"sigalg-name\*(R" parameter for its (short) name. -Otherwise, it's assumed to already exist in the object database, possibly -done by the provider with the \fBcore_obj_create()\fR upcall. -This value is optional. -.ie n .IP """sig-name"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_SIG_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``sig-name'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_SIG_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "sig-name (OSSL_CAPABILITY_TLS_SIGALG_SIG_NAME) " -The name of the pure signature algorithm that is part of a composite -\&\*(L"sigalg-name\*(R". If \*(L"sigalg-name\*(R" is implemented by the provider, this -parameter is redundant and must not be given. -This value is optional. -.ie n .IP """sig-oid"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_SIG_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``sig-oid'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_SIG_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "sig-oid (OSSL_CAPABILITY_TLS_SIGALG_SIG_OID) " -The \s-1OID\s0 of the \*(L"sig-name\*(R" algorithm in canonical numeric text form. If -this parameter is given, \fBOBJ_create()\fR will be used to create an \s-1OBJ\s0 and -a \s-1NID\s0 for this \s-1OID,\s0 using the \*(L"sig-name\*(R" parameter for its (short) name. -Otherwise, it is assumed to already exist in the object database. This -can be done by the provider using the \fBcore_obj_create()\fR upcall. -This value is optional. -.ie n .IP """hash-name"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_HASH_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``hash-name'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_HASH_NAME\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "hash-name (OSSL_CAPABILITY_TLS_SIGALG_HASH_NAME) " -The name of the hash algorithm that is part of a composite \*(L"sigalg-name\*(R". -If \*(L"sigalg-name\*(R" is implemented by the provider, this parameter is redundant -and must not be given. -This value is optional. -.ie n .IP """hash-oid"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_HASH_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``hash-oid'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_HASH_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "hash-oid (OSSL_CAPABILITY_TLS_SIGALG_HASH_OID) " -The \s-1OID\s0 of the \*(L"hash-name\*(R" algorithm in canonical numeric text form. If -this parameter is given, \fBOBJ_create()\fR will be used to create an \s-1OBJ\s0 and -a \s-1NID\s0 for this \s-1OID,\s0 using the \*(L"hash-name\*(R" parameter for its (short) name. -Otherwise, it's assumed to already exist in the object database, possibly -done by the provider with the \fBcore_obj_create()\fR upcall. -This value is optional. -.ie n .IP """key-type"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``key-type'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "key-type (OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE) " -The key type of the public key of applicable certificates. If this parameter -isn't present, it's assumed to be the same as \*(L"sig-name\*(R" if that's present, -otherwise \*(L"sigalg-name\*(R". -This value is optional. -.ie n .IP """key-type-oid"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``key-type-oid'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE_OID\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "key-type-oid (OSSL_CAPABILITY_TLS_SIGALG_KEYTYPE_OID) " -The \s-1OID\s0 of the \*(L"key-type\*(R" in canonical numeric text form. If -this parameter is given, \fBOBJ_create()\fR will be used to create an \s-1OBJ\s0 and -a \s-1NID\s0 for this \s-1OID,\s0 using the \*(L"key-type\*(R" parameter for its (short) name. -Otherwise, it's assumed to already exist in the object database, possibly -done by the provider with the \fBcore_obj_create()\fR upcall. -This value is optional. -.ie n .IP """sec-bits"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_SECURITY_BITS\s0\fR) " 4 -.el .IP "``sec-bits'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_SECURITY_BITS\s0\fR) " 4 -.IX Item "sec-bits (OSSL_CAPABILITY_TLS_SIGALG_SECURITY_BITS) " -The number of bits of security offered by keys of this algorithm. The number -of bits should be comparable with the ones given in table 2 and 3 of the \s-1NIST -SP800\-57\s0 document. This number is used to determine the security strength of -the algorithm if no digest algorithm has been registered that otherwise -defines the security strength. If the signature algorithm implements its own -digest internally, this value needs to be set to properly reflect the overall -security strength. -This value must be supplied. -.ie n .IP """tls-min-tls"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_MIN_TLS\s0\fR) " 4 -.el .IP "``tls-min-tls'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_MIN_TLS\s0\fR) " 4 -.IX Item "tls-min-tls (OSSL_CAPABILITY_TLS_SIGALG_MIN_TLS) " -.PD 0 -.ie n .IP """tls-max-tls"" (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_MAX_TLS\s0\fR) " 4 -.el .IP "``tls-max-tls'' (\fB\s-1OSSL_CAPABILITY_TLS_SIGALG_MAX_TLS\s0\fR) " 4 -.IX Item "tls-max-tls (OSSL_CAPABILITY_TLS_SIGALG_MAX_TLS) " -.PD -These parameters can be used to describe the minimum and maximum \s-1TLS\s0 -versions supported by the signature algorithm. The values equate to the -on-the-wire encoding of the various \s-1TLS\s0 versions. For example TLSv1.3 is -0x0304 (772 decimal), and TLSv1.2 is 0x0303 (771 decimal). A 0 indicates that -there is no defined minimum or maximum. A \-1 indicates that the signature -algorithm should not be used in that protocol. -Presently values representing anything other than \s-1TLS1.3\s0 mean that the -complete algorithm is ignored. -.SH "NOTES" -.IX Header "NOTES" -The \fBcore_obj_create()\fR and \fBcore_obj_add_sigid()\fR functions were not thread safe -in OpenSSL 3.0. -.SH "EXAMPLES" -.IX Header "EXAMPLES" -This is an example of a simple provider made available as a -dynamically loadable module. -It implements the fictitious algorithm \f(CW\*(C`FOO\*(C'\fR for the fictitious -operation \f(CW\*(C`BAR\*(C'\fR. -.PP -.Vb 3 -\& #include -\& #include -\& #include -\& -\& /* Errors used in this provider */ -\& #define E_MALLOC 1 -\& -\& static const OSSL_ITEM reasons[] = { -\& { E_MALLOC, "memory allocation failure" }. -\& OSSL_DISPATCH_END -\& }; -\& -\& /* -\& * To ensure we get the function signature right, forward declare -\& * them using function types provided by openssl/core_dispatch.h -\& */ -\& OSSL_FUNC_bar_newctx_fn foo_newctx; -\& OSSL_FUNC_bar_freectx_fn foo_freectx; -\& OSSL_FUNC_bar_init_fn foo_init; -\& OSSL_FUNC_bar_update_fn foo_update; -\& OSSL_FUNC_bar_final_fn foo_final; -\& -\& OSSL_FUNC_provider_query_operation_fn p_query; -\& OSSL_FUNC_provider_get_reason_strings_fn p_reasons; -\& OSSL_FUNC_provider_teardown_fn p_teardown; -\& -\& OSSL_provider_init_fn OSSL_provider_init; -\& -\& OSSL_FUNC_core_put_error *c_put_error = NULL; -\& -\& /* Provider context */ -\& struct prov_ctx_st { -\& OSSL_CORE_HANDLE *handle; -\& } -\& -\& /* operation context for the algorithm FOO */ -\& struct foo_ctx_st { -\& struct prov_ctx_st *provctx; -\& int b; -\& }; -\& -\& static void *foo_newctx(void *provctx) -\& { -\& struct foo_ctx_st *fooctx = malloc(sizeof(*fooctx)); -\& -\& if (fooctx != NULL) -\& fooctx\->provctx = provctx; -\& else -\& c_put_error(provctx\->handle, E_MALLOC, _\|_FILE_\|_, _\|_LINE_\|_); -\& return fooctx; -\& } -\& -\& static void foo_freectx(void *fooctx) -\& { -\& free(fooctx); -\& } -\& -\& static int foo_init(void *vfooctx) -\& { -\& struct foo_ctx_st *fooctx = vfooctx; -\& -\& fooctx\->b = 0x33; -\& } -\& -\& static int foo_update(void *vfooctx, unsigned char *in, size_t inl) -\& { -\& struct foo_ctx_st *fooctx = vfooctx; -\& -\& /* did you expect something serious? */ -\& if (inl == 0) -\& return 1; -\& for (; inl\-\- > 0; in++) -\& *in ^= fooctx\->b; -\& return 1; -\& } -\& -\& static int foo_final(void *vfooctx) -\& { -\& struct foo_ctx_st *fooctx = vfooctx; -\& -\& fooctx\->b = 0x66; -\& } -\& -\& static const OSSL_DISPATCH foo_fns[] = { -\& { OSSL_FUNC_BAR_NEWCTX, (void (*)(void))foo_newctx }, -\& { OSSL_FUNC_BAR_FREECTX, (void (*)(void))foo_freectx }, -\& { OSSL_FUNC_BAR_INIT, (void (*)(void))foo_init }, -\& { OSSL_FUNC_BAR_UPDATE, (void (*)(void))foo_update }, -\& { OSSL_FUNC_BAR_FINAL, (void (*)(void))foo_final }, -\& OSSL_DISPATCH_END -\& }; -\& -\& static const OSSL_ALGORITHM bars[] = { -\& { "FOO", "provider=chumbawamba", foo_fns }, -\& { NULL, NULL, NULL } -\& }; -\& -\& static const OSSL_ALGORITHM *p_query(void *provctx, int operation_id, -\& int *no_store) -\& { -\& switch (operation_id) { -\& case OSSL_OP_BAR: -\& return bars; -\& } -\& return NULL; -\& } -\& -\& static const OSSL_ITEM *p_reasons(void *provctx) -\& { -\& return reasons; -\& } -\& -\& static void p_teardown(void *provctx) -\& { -\& free(provctx); -\& } -\& -\& static const OSSL_DISPATCH prov_fns[] = { -\& { OSSL_FUNC_PROVIDER_TEARDOWN, (void (*)(void))p_teardown }, -\& { OSSL_FUNC_PROVIDER_QUERY_OPERATION, (void (*)(void))p_query }, -\& { OSSL_FUNC_PROVIDER_GET_REASON_STRINGS, (void (*)(void))p_reasons }, -\& OSSL_DISPATCH_END -\& }; -\& -\& int OSSL_provider_init(const OSSL_CORE_HANDLE *handle, -\& const OSSL_DISPATCH *in, -\& const OSSL_DISPATCH **out, -\& void **provctx) -\& { -\& struct prov_ctx_st *pctx = NULL; -\& -\& for (; in\->function_id != 0; in++) -\& switch (in\->function_id) { -\& case OSSL_FUNC_CORE_PUT_ERROR: -\& c_put_error = OSSL_FUNC_core_put_error(in); -\& break; -\& } -\& -\& *out = prov_fns; -\& -\& if ((pctx = malloc(sizeof(*pctx))) == NULL) { -\& /* -\& * ALEA IACTA EST, if the core retrieves the reason table -\& * regardless, that string will be displayed, otherwise not. -\& */ -\& c_put_error(handle, E_MALLOC, _\|_FILE_\|_, _\|_LINE_\|_); -\& return 0; -\& } -\& pctx\->handle = handle; -\& return 1; -\& } -.Ve -.PP -This relies on a few things existing in \fIopenssl/core_dispatch.h\fR: -.PP -.Vb 1 -\& #define OSSL_OP_BAR 4711 -\& -\& #define OSSL_FUNC_BAR_NEWCTX 1 -\& typedef void *(OSSL_FUNC_bar_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_bar_newctx(const OSSL_DISPATCH *opf) -\& { return (OSSL_FUNC_bar_newctx_fn *)opf\->function; } -\& -\& #define OSSL_FUNC_BAR_FREECTX 2 -\& typedef void (OSSL_FUNC_bar_freectx_fn)(void *ctx); -\& static ossl_inline OSSL_FUNC_bar_freectx(const OSSL_DISPATCH *opf) -\& { return (OSSL_FUNC_bar_freectx_fn *)opf\->function; } -\& -\& #define OSSL_FUNC_BAR_INIT 3 -\& typedef void *(OSSL_FUNC_bar_init_fn)(void *ctx); -\& static ossl_inline OSSL_FUNC_bar_init(const OSSL_DISPATCH *opf) -\& { return (OSSL_FUNC_bar_init_fn *)opf\->function; } -\& -\& #define OSSL_FUNC_BAR_UPDATE 4 -\& typedef void *(OSSL_FUNC_bar_update_fn)(void *ctx, -\& unsigned char *in, size_t inl); -\& static ossl_inline OSSL_FUNC_bar_update(const OSSL_DISPATCH *opf) -\& { return (OSSL_FUNC_bar_update_fn *)opf\->function; } -\& -\& #define OSSL_FUNC_BAR_FINAL 5 -\& typedef void *(OSSL_FUNC_bar_final_fn)(void *ctx); -\& static ossl_inline OSSL_FUNC_bar_final(const OSSL_DISPATCH *opf) -\& { return (OSSL_FUNC_bar_final_fn *)opf\->function; } -.Ve -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The concept of providers and everything surrounding them was -introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-cipher.7ossl b/openssl-install/share/man/man7/provider-cipher.7ossl deleted file mode 100644 index ef86d596..00000000 --- a/openssl-install/share/man/man7/provider-cipher.7ossl +++ /dev/null @@ -1,381 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-CIPHER 7ossl" -.TH PROVIDER-CIPHER 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-cipher \- The cipher library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_cipher_newctx(void *provctx); -\& void OSSL_FUNC_cipher_freectx(void *cctx); -\& void *OSSL_FUNC_cipher_dupctx(void *cctx); -\& -\& /* Encryption/decryption */ -\& int OSSL_FUNC_cipher_encrypt_init(void *cctx, const unsigned char *key, -\& size_t keylen, const unsigned char *iv, -\& size_t ivlen, const OSSL_PARAM params[]); -\& int OSSL_FUNC_cipher_decrypt_init(void *cctx, const unsigned char *key, -\& size_t keylen, const unsigned char *iv, -\& size_t ivlen, const OSSL_PARAM params[]); -\& int OSSL_FUNC_cipher_update(void *cctx, unsigned char *out, size_t *outl, -\& size_t outsize, const unsigned char *in, size_t inl); -\& int OSSL_FUNC_cipher_final(void *cctx, unsigned char *out, size_t *outl, -\& size_t outsize); -\& int OSSL_FUNC_cipher_cipher(void *cctx, unsigned char *out, size_t *outl, -\& size_t outsize, const unsigned char *in, size_t inl); -\& -\& /* Cipher parameter descriptors */ -\& const OSSL_PARAM *OSSL_FUNC_cipher_gettable_params(void *provctx); -\& -\& /* Cipher operation parameter descriptors */ -\& const OSSL_PARAM *OSSL_FUNC_cipher_gettable_ctx_params(void *cctx, -\& void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_cipher_settable_ctx_params(void *cctx, -\& void *provctx); -\& -\& /* Cipher parameters */ -\& int OSSL_FUNC_cipher_get_params(OSSL_PARAM params[]); -\& -\& /* Cipher operation parameters */ -\& int OSSL_FUNC_cipher_get_ctx_params(void *cctx, OSSL_PARAM params[]); -\& int OSSL_FUNC_cipher_set_ctx_params(void *cctx, const OSSL_PARAM params[]); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The \s-1CIPHER\s0 operation enables providers to implement cipher algorithms and make -them available to applications via the \s-1API\s0 functions \fBEVP_EncryptInit_ex\fR\|(3), -\&\fBEVP_EncryptUpdate\fR\|(3) and \fBEVP_EncryptFinal\fR\|(3) (as well as the decrypt -equivalents and other related functions). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_cipher_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_cipher_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_cipher_newctx_fn -\& OSSL_FUNC_cipher_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_cipher_newctx OSSL_FUNC_CIPHER_NEWCTX -\& OSSL_FUNC_cipher_freectx OSSL_FUNC_CIPHER_FREECTX -\& OSSL_FUNC_cipher_dupctx OSSL_FUNC_CIPHER_DUPCTX -\& -\& OSSL_FUNC_cipher_encrypt_init OSSL_FUNC_CIPHER_ENCRYPT_INIT -\& OSSL_FUNC_cipher_decrypt_init OSSL_FUNC_CIPHER_DECRYPT_INIT -\& OSSL_FUNC_cipher_update OSSL_FUNC_CIPHER_UPDATE -\& OSSL_FUNC_cipher_final OSSL_FUNC_CIPHER_FINAL -\& OSSL_FUNC_cipher_cipher OSSL_FUNC_CIPHER_CIPHER -\& -\& OSSL_FUNC_cipher_get_params OSSL_FUNC_CIPHER_GET_PARAMS -\& OSSL_FUNC_cipher_get_ctx_params OSSL_FUNC_CIPHER_GET_CTX_PARAMS -\& OSSL_FUNC_cipher_set_ctx_params OSSL_FUNC_CIPHER_SET_CTX_PARAMS -\& -\& OSSL_FUNC_cipher_gettable_params OSSL_FUNC_CIPHER_GETTABLE_PARAMS -\& OSSL_FUNC_cipher_gettable_ctx_params OSSL_FUNC_CIPHER_GETTABLE_CTX_PARAMS -\& OSSL_FUNC_cipher_settable_ctx_params OSSL_FUNC_CIPHER_SETTABLE_CTX_PARAMS -.Ve -.PP -A cipher algorithm implementation may not implement all of these functions. -In order to be a consistent set of functions there must at least be a complete -set of \*(L"encrypt\*(R" functions, or a complete set of \*(L"decrypt\*(R" functions, or a -single \*(L"cipher\*(R" function. -In all cases the OSSL_FUNC_cipher_get_params and both OSSL_FUNC_cipher_newctx -and OSSL_FUNC_cipher_freectx functions must be present. -All other functions are optional. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_cipher_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during a cipher operation. -A pointer to this context will be passed back in a number of the other cipher -operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -.PP -\&\fBOSSL_FUNC_cipher_freectx()\fR is passed a pointer to the provider side cipher context in -the \fIcctx\fR parameter. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_cipher_dupctx()\fR should duplicate the provider side cipher context in the -\&\fIcctx\fR parameter and return the duplicate copy. -.SS "Encryption/Decryption Functions" -.IX Subsection "Encryption/Decryption Functions" -\&\fBOSSL_FUNC_cipher_encrypt_init()\fR initialises a cipher operation for encryption given a -newly created provider side cipher context in the \fIcctx\fR parameter. -The key to be used is given in \fIkey\fR which is \fIkeylen\fR bytes long. -The \s-1IV\s0 to be used is given in \fIiv\fR which is \fIivlen\fR bytes long. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_cipher_set_ctx_params()\fR. -.PP -\&\fBOSSL_FUNC_cipher_decrypt_init()\fR is the same as \fBOSSL_FUNC_cipher_encrypt_init()\fR except that it -initialises the context for a decryption operation. -.PP -\&\fBOSSL_FUNC_cipher_update()\fR is called to supply data to be encrypted/decrypted as part of -a previously initialised cipher operation. -The \fIcctx\fR parameter contains a pointer to a previously initialised provider -side context. -\&\fBOSSL_FUNC_cipher_update()\fR should encrypt/decrypt \fIinl\fR bytes of data at the location -pointed to by \fIin\fR. -The encrypted data should be stored in \fIout\fR and the amount of data written to -\&\fI*outl\fR which should not exceed \fIoutsize\fR bytes. -\&\fBOSSL_FUNC_cipher_update()\fR may be called multiple times for a single cipher operation. -It is the responsibility of the cipher implementation to handle input lengths -that are not multiples of the block length. -In such cases a cipher implementation will typically cache partial blocks of -input data until a complete block is obtained. -The pointers \fIout\fR and \fIin\fR may point to the same location, in which -case the encryption must be done in-place. If \fIout\fR and \fIin\fR point to different -locations, the requirements of \fBEVP_EncryptUpdate\fR\|(3) and \fBEVP_DecryptUpdate\fR\|(3) -guarantee that the two buffers are disjoint. -Similarly, the requirements of \fBEVP_EncryptUpdate\fR\|(3) and \fBEVP_DecryptUpdate\fR\|(3) -ensure that the buffer pointed to by \fIout\fR contains sufficient room for the -operation being performed. -.PP -\&\fBOSSL_FUNC_cipher_final()\fR completes an encryption or decryption started through previous -\&\fBOSSL_FUNC_cipher_encrypt_init()\fR or \fBOSSL_FUNC_cipher_decrypt_init()\fR, and \fBOSSL_FUNC_cipher_update()\fR -calls. -The \fIcctx\fR parameter contains a pointer to the provider side context. -Any final encryption/decryption output should be written to \fIout\fR and the -amount of data written to \fI*outl\fR which should not exceed \fIoutsize\fR bytes. -The same expectations apply to \fIoutsize\fR as documented for -\&\fBEVP_EncryptFinal\fR\|(3) and \fBEVP_DecryptFinal\fR\|(3). -.PP -\&\fBOSSL_FUNC_cipher_cipher()\fR performs encryption/decryption using the provider side cipher -context in the \fIcctx\fR parameter that should have been previously initialised via -a call to \fBOSSL_FUNC_cipher_encrypt_init()\fR or \fBOSSL_FUNC_cipher_decrypt_init()\fR. -This should call the raw underlying cipher function without any padding. -This will be invoked in the provider as a result of the application calling -\&\fBEVP_Cipher\fR\|(3). -The application is responsible for ensuring that the input is a multiple of the -block length. -The data to be encrypted/decrypted will be in \fIin\fR, and it will be \fIinl\fR bytes -in length. -The output from the encryption/decryption should be stored in \fIout\fR and the -amount of data stored should be put in \fI*outl\fR which should be no more than -\&\fIoutsize\fR bytes. -.SS "Cipher Parameters" -.IX Subsection "Cipher Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -these functions. -.PP -\&\fBOSSL_FUNC_cipher_get_params()\fR gets details of the algorithm implementation -and stores them in \fIparams\fR. -.PP -\&\fBOSSL_FUNC_cipher_set_ctx_params()\fR sets cipher operation parameters for the -provider side cipher context \fIcctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_cipher_get_ctx_params()\fR gets cipher operation details details from -the given provider side cipher context \fIcctx\fR and stores them in \fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_cipher_gettable_params()\fR, \fBOSSL_FUNC_cipher_gettable_ctx_params()\fR, -and \fBOSSL_FUNC_cipher_settable_ctx_params()\fR all return constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -arrays as descriptors of the parameters that \fBOSSL_FUNC_cipher_get_params()\fR, -\&\fBOSSL_FUNC_cipher_get_ctx_params()\fR, and \fBOSSL_FUNC_cipher_set_ctx_params()\fR -can handle, respectively. \fBOSSL_FUNC_cipher_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_cipher_settable_ctx_params()\fR will return the parameters associated -with the provider side context \fIcctx\fR in its current state if it is -not \s-1NULL.\s0 Otherwise, they return the parameters associated with the -provider side algorithm \fIprovctx\fR. -.PP -Parameters currently recognised by built-in ciphers are listed in -\&\*(L"\s-1PARAMETERS\*(R"\s0 in \fBEVP_EncryptInit\fR\|(3). -Not all parameters are relevant to, or are understood by all ciphers. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_cipher_newctx()\fR and \fBOSSL_FUNC_cipher_dupctx()\fR should return the newly created -provider side cipher context, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_cipher_encrypt_init()\fR, \fBOSSL_FUNC_cipher_decrypt_init()\fR, \fBOSSL_FUNC_cipher_update()\fR, -\&\fBOSSL_FUNC_cipher_final()\fR, \fBOSSL_FUNC_cipher_cipher()\fR, \fBOSSL_FUNC_cipher_get_params()\fR, -\&\fBOSSL_FUNC_cipher_get_ctx_params()\fR and \fBOSSL_FUNC_cipher_set_ctx_params()\fR should return 1 for -success or 0 on error. -.PP -\&\fBOSSL_FUNC_cipher_gettable_params()\fR, \fBOSSL_FUNC_cipher_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_cipher_settable_ctx_params()\fR should return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -array, or \s-1NULL\s0 if none is offered. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7), -\&\fBOSSL_PROVIDER\-legacy\fR\|(7), -\&\s-1\fBEVP_CIPHER\-AES\s0\fR\|(7), \s-1\fBEVP_CIPHER\-ARIA\s0\fR\|(7), \s-1\fBEVP_CIPHER\-BLOWFISH\s0\fR\|(7), -\&\s-1\fBEVP_CIPHER\-CAMELLIA\s0\fR\|(7), \s-1\fBEVP_CIPHER\-CAST\s0\fR\|(7), \s-1\fBEVP_CIPHER\-CHACHA\s0\fR\|(7), -\&\s-1\fBEVP_CIPHER\-DES\s0\fR\|(7), \s-1\fBEVP_CIPHER\-IDEA\s0\fR\|(7), \s-1\fBEVP_CIPHER\-RC2\s0\fR\|(7), -\&\s-1\fBEVP_CIPHER\-RC4\s0\fR\|(7), \s-1\fBEVP_CIPHER\-RC5\s0\fR\|(7), \s-1\fBEVP_CIPHER\-SEED\s0\fR\|(7), -\&\s-1\fBEVP_CIPHER\-SM4\s0\fR\|(7), \s-1\fBEVP_CIPHER\-NULL\s0\fR\|(7), -\&\fBlife_cycle\-cipher\fR\|(7), \fBEVP_EncryptInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1CIPHER\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-decoder.7ossl b/openssl-install/share/man/man7/provider-decoder.7ossl deleted file mode 100644 index c234f870..00000000 --- a/openssl-install/share/man/man7/provider-decoder.7ossl +++ /dev/null @@ -1,423 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-DECODER 7ossl" -.TH PROVIDER-DECODER 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-decoder \- The OSSL_DECODER library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Decoder parameter accessor and descriptor */ -\& const OSSL_PARAM *OSSL_FUNC_decoder_gettable_params(void *provctx); -\& int OSSL_FUNC_decoder_get_params(OSSL_PARAM params[]); -\& -\& /* Functions to construct / destruct / manipulate the decoder context */ -\& void *OSSL_FUNC_decoder_newctx(void *provctx); -\& void OSSL_FUNC_decoder_freectx(void *ctx); -\& const OSSL_PARAM *OSSL_FUNC_decoder_settable_ctx_params(void *provctx); -\& int OSSL_FUNC_decoder_set_ctx_params(void *ctx, const OSSL_PARAM params[]); -\& -\& /* Functions to check selection support */ -\& int OSSL_FUNC_decoder_does_selection(void *provctx, int selection); -\& -\& /* Functions to decode object data */ -\& int OSSL_FUNC_decoder_decode(void *ctx, OSSL_CORE_BIO *in, -\& int selection, -\& OSSL_CALLBACK *data_cb, void *data_cbarg, -\& OSSL_PASSPHRASE_CALLBACK *cb, void *cbarg); -\& -\& /* Functions to export a decoded object */ -\& int OSSL_FUNC_decoder_export_object(void *ctx, -\& const void *objref, size_t objref_sz, -\& OSSL_CALLBACK *export_cb, -\& void *export_cbarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fIThe term \*(L"decode\*(R" is used throughout this manual. This includes but is -not limited to deserialization as individual decoders can also do -decoding into intermediate data formats.\fR -.PP -The \s-1DECODER\s0 operation is a generic method to create a provider-native -object reference or intermediate decoded data from an encoded form -read from the given \fB\s-1OSSL_CORE_BIO\s0\fR. If the caller wants to decode -data from memory, it should provide a \fBBIO_s_mem\fR\|(3) \fB\s-1BIO\s0\fR. The decoded -data or object reference is passed along with eventual metadata -to the \fImetadata_cb\fR as \s-1\fBOSSL_PARAM\s0\fR\|(3) parameters. -.PP -The decoder doesn't need to know more about the \fB\s-1OSSL_CORE_BIO\s0\fR -pointer than being able to pass it to the appropriate \s-1BIO\s0 upcalls (see -\&\*(L"Core functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -The \s-1DECODER\s0 implementation may be part of a chain, where data is -passed from one to the next. For example, there may be an -implementation to decode an object from \s-1PEM\s0 to \s-1DER,\s0 and another one -that decodes \s-1DER\s0 to a provider-native object. -.PP -The last decoding step in the decoding chain is usually supposed to create -a provider-native object referenced by an object reference. To import -that object into a different provider the \fBOSSL_FUNC_decoder_export_object()\fR -can be called as the final step of the decoding process. -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_decoder_decode()\fR has these: -.PP -.Vb 7 -\& typedef int -\& (OSSL_FUNC_decoder_decode_fn)(void *ctx, OSSL_CORE_BIO *in, -\& int selection, -\& OSSL_CALLBACK *data_cb, void *data_cbarg, -\& OSSL_PASSPHRASE_CALLBACK *cb, void *cbarg); -\& static ossl_inline OSSL_FUNC_decoder_decode_fn* -\& OSSL_FUNC_decoder_decode(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 2 -\& OSSL_FUNC_decoder_get_params OSSL_FUNC_DECODER_GET_PARAMS -\& OSSL_FUNC_decoder_gettable_params OSSL_FUNC_DECODER_GETTABLE_PARAMS -\& -\& OSSL_FUNC_decoder_newctx OSSL_FUNC_DECODER_NEWCTX -\& OSSL_FUNC_decoder_freectx OSSL_FUNC_DECODER_FREECTX -\& OSSL_FUNC_decoder_set_ctx_params OSSL_FUNC_DECODER_SET_CTX_PARAMS -\& OSSL_FUNC_decoder_settable_ctx_params OSSL_FUNC_DECODER_SETTABLE_CTX_PARAMS -\& -\& OSSL_FUNC_decoder_does_selection OSSL_FUNC_DECODER_DOES_SELECTION -\& -\& OSSL_FUNC_decoder_decode OSSL_FUNC_DECODER_DECODE -\& -\& OSSL_FUNC_decoder_export_object OSSL_FUNC_DECODER_EXPORT_OBJECT -.Ve -.SS "Names and properties" -.IX Subsection "Names and properties" -The name of an implementation should match the target type of object -it decodes. For example, an implementation that decodes an \s-1RSA\s0 key -should be named \*(L"\s-1RSA\*(R".\s0 Likewise, an implementation that decodes \s-1DER\s0 data -from \s-1PEM\s0 input should be named \*(L"\s-1DER\*(R".\s0 -.PP -Properties, as defined in the \s-1\fBOSSL_ALGORITHM\s0\fR\|(3) array element of each -decoder implementation, can be used to further specify details about an -implementation: -.IP "input" 4 -.IX Item "input" -This property is used to specify what format of input the implementation -can decode. -.Sp -This property is \fImandatory\fR. -.Sp -OpenSSL providers recognize the following input types: -.RS 4 -.IP "pem" 4 -.IX Item "pem" -An implementation with that input type decodes \s-1PEM\s0 formatted data. -.IP "der" 4 -.IX Item "der" -An implementation with that input type decodes \s-1DER\s0 formatted data. -.IP "msblob" 4 -.IX Item "msblob" -An implementation with that input type decodes \s-1MSBLOB\s0 formatted data. -.IP "pvk" 4 -.IX Item "pvk" -An implementation with that input type decodes \s-1PVK\s0 formatted data. -.RE -.RS 4 -.RE -.IP "structure" 4 -.IX Item "structure" -This property is used to specify the structure that the decoded data is -expected to have. -.Sp -This property is \fIoptional\fR. -.Sp -Structures currently recognised by built-in decoders: -.RS 4 -.ie n .IP """type-specific""" 4 -.el .IP "``type-specific''" 4 -.IX Item "type-specific" -Type specific structure. -.ie n .IP """pkcs8""" 4 -.el .IP "``pkcs8''" 4 -.IX Item "pkcs8" -Structure according to the PKCS#8 specification. -.ie n .IP """SubjectPublicKeyInfo""" 4 -.el .IP "``SubjectPublicKeyInfo''" 4 -.IX Item "SubjectPublicKeyInfo" -Encoding of public keys according to the Subject Public Key Info of \s-1RFC 5280.\s0 -.RE -.RS 4 -.RE -.PP -The possible values of both these properties is open ended. A provider may -very well specify input types and structures that libcrypto doesn't know -anything about. -.SS "Subset selections" -.IX Subsection "Subset selections" -Sometimes, an object has more than one subset of data that is interesting to -treat separately or together. It's possible to specify what subsets are to -be decoded, with a set of bits \fIselection\fR that are passed in an \fBint\fR. -.PP -This set of bits depend entirely on what kind of provider-side object is -to be decoded. For example, those bits are assumed to be the same as those -used with \fBprovider\-keymgmt\fR\|(7) (see \*(L"Key Objects\*(R" in \fBprovider\-keymgmt\fR\|(7)) when -the object is an asymmetric keypair \- e.g., \fB\s-1OSSL_KEYMGMT_SELECT_PRIVATE_KEY\s0\fR -if the object to be decoded is supposed to contain private key components. -.PP -\&\fBOSSL_FUNC_decoder_does_selection()\fR should tell if a particular implementation -supports any of the combinations given by \fIselection\fR. -.SS "Context functions" -.IX Subsection "Context functions" -\&\fBOSSL_FUNC_decoder_newctx()\fR returns a context to be used with the rest of -the functions. -.PP -\&\fBOSSL_FUNC_decoder_freectx()\fR frees the given \fIctx\fR as created by -\&\fBOSSL_FUNC_decoder_newctx()\fR. -.PP -\&\fBOSSL_FUNC_decoder_set_ctx_params()\fR sets context data according to parameters -from \fIparams\fR that it recognises. Unrecognised parameters should be -ignored. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_decoder_settable_ctx_params()\fR returns a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -array describing the parameters that \fBOSSL_FUNC_decoder_set_ctx_params()\fR -can handle. -.PP -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -\&\fBOSSL_FUNC_decoder_set_ctx_params()\fR and \fBOSSL_FUNC_decoder_settable_ctx_params()\fR. -.SS "Export function" -.IX Subsection "Export function" -When a provider-native object is created by a decoder it would be unsuitable -for direct use with a foreign provider. The export function allows for -exporting the object into that foreign provider if the foreign provider -supports the type of the object and provides an import function. -.PP -\&\fBOSSL_FUNC_decoder_export_object()\fR should export the object of size \fIobjref_sz\fR -referenced by \fIobjref\fR as an \s-1\fBOSSL_PARAM\s0\fR\|(3) array and pass that into the -\&\fIexport_cb\fR as well as the given \fIexport_cbarg\fR. -.SS "Decoding functions" -.IX Subsection "Decoding functions" -\&\fBOSSL_FUNC_decoder_decode()\fR should decode the data as read from -the \fB\s-1OSSL_CORE_BIO\s0\fR \fIin\fR to produce decoded data or an object to be -passed as reference in an \s-1\fBOSSL_PARAM\s0\fR\|(3) array along with possible other -metadata that was decoded from the input. This \s-1\fBOSSL_PARAM\s0\fR\|(3) array is -then passed to the \fIdata_cb\fR callback. The \fIselection\fR bits, -if relevant, should determine what the input data should contain. -The decoding functions also take an \s-1\fBOSSL_PASSPHRASE_CALLBACK\s0\fR\|(3) function -pointer along with a pointer to application data \fIcbarg\fR, which should be -used when a pass phrase prompt is needed. -.PP -It's important to understand that the return value from this function is -interpreted as follows: -.IP "True (1)" 4 -.IX Item "True (1)" -This means \*(L"carry on the decoding process\*(R", and is meaningful even though -this function couldn't decode the input into anything, because there may be -another decoder implementation that can decode it into something. -.Sp -The \fIdata_cb\fR callback should never be called when this function can't -decode the input into anything. -.IP "False (0)" 4 -.IX Item "False (0)" -This means \*(L"stop the decoding process\*(R", and is meaningful when the input -could be decoded into some sort of object that this function understands, -but further treatment of that object results into errors that won't be -possible for some other decoder implementation to get a different result. -.PP -The conditions to stop the decoding process are at the discretion of the -implementation. -.SS "Decoder operation parameters" -.IX Subsection "Decoder operation parameters" -There are currently no operation parameters currently recognised by the -built-in decoders. -.PP -Parameters currently recognised by the built-in pass phrase callback: -.ie n .IP """info"" (\fB\s-1OSSL_PASSPHRASE_PARAM_INFO\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``info'' (\fB\s-1OSSL_PASSPHRASE_PARAM_INFO\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "info (OSSL_PASSPHRASE_PARAM_INFO) " -A string of information that will become part of the pass phrase -prompt. This could be used to give the user information on what kind -of object it's being prompted for. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_decoder_newctx()\fR returns a pointer to a context, or \s-1NULL\s0 on -failure. -.PP -\&\fBOSSL_FUNC_decoder_set_ctx_params()\fR returns 1, unless a recognised -parameter was invalid or caused an error, for which 0 is returned. -.PP -\&\fBOSSL_FUNC_decoder_settable_ctx_params()\fR returns a pointer to an array of -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) elements. -.PP -\&\fBOSSL_FUNC_decoder_does_selection()\fR returns 1 if the decoder implementation -supports any of the \fIselection\fR bits, otherwise 0. -.PP -\&\fBOSSL_FUNC_decoder_decode()\fR returns 1 to signal that the decoding process -should continue, or 0 to signal that it should stop. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1DECODER\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-digest.7ossl b/openssl-install/share/man/man7/provider-digest.7ossl deleted file mode 100644 index 38f30fb3..00000000 --- a/openssl-install/share/man/man7/provider-digest.7ossl +++ /dev/null @@ -1,405 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-DIGEST 7ossl" -.TH PROVIDER-DIGEST 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-digest \- The digest library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * Digests support the following function signatures in OSSL_DISPATCH arrays. -\& * (The function signatures are not actual functions). -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_digest_newctx(void *provctx); -\& void OSSL_FUNC_digest_freectx(void *dctx); -\& void *OSSL_FUNC_digest_dupctx(void *dctx); -\& -\& /* Digest generation */ -\& int OSSL_FUNC_digest_init(void *dctx, const OSSL_PARAM params[]); -\& int OSSL_FUNC_digest_update(void *dctx, const unsigned char *in, size_t inl); -\& int OSSL_FUNC_digest_final(void *dctx, unsigned char *out, size_t *outl, -\& size_t outsz); -\& int OSSL_FUNC_digest_digest(void *provctx, const unsigned char *in, size_t inl, -\& unsigned char *out, size_t *outl, size_t outsz); -\& -\& /* Digest parameter descriptors */ -\& const OSSL_PARAM *OSSL_FUNC_digest_gettable_params(void *provctx); -\& -\& /* Digest operation parameter descriptors */ -\& const OSSL_PARAM *OSSL_FUNC_digest_gettable_ctx_params(void *dctx, -\& void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_digest_settable_ctx_params(void *dctx, -\& void *provctx); -\& -\& /* Digest parameters */ -\& int OSSL_FUNC_digest_get_params(OSSL_PARAM params[]); -\& -\& /* Digest operation parameters */ -\& int OSSL_FUNC_digest_set_ctx_params(void *dctx, const OSSL_PARAM params[]); -\& int OSSL_FUNC_digest_get_ctx_params(void *dctx, OSSL_PARAM params[]); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The \s-1DIGEST\s0 operation enables providers to implement digest algorithms and make -them available to applications via the \s-1API\s0 functions \fBEVP_DigestInit_ex\fR\|(3), -\&\fBEVP_DigestUpdate\fR\|(3) and \fBEVP_DigestFinal\fR\|(3) (and other related functions). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_digest_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_digest_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_digest_newctx_fn -\& OSSL_FUNC_digest_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_digest_newctx OSSL_FUNC_DIGEST_NEWCTX -\& OSSL_FUNC_digest_freectx OSSL_FUNC_DIGEST_FREECTX -\& OSSL_FUNC_digest_dupctx OSSL_FUNC_DIGEST_DUPCTX -\& -\& OSSL_FUNC_digest_init OSSL_FUNC_DIGEST_INIT -\& OSSL_FUNC_digest_update OSSL_FUNC_DIGEST_UPDATE -\& OSSL_FUNC_digest_final OSSL_FUNC_DIGEST_FINAL -\& OSSL_FUNC_digest_digest OSSL_FUNC_DIGEST_DIGEST -\& -\& OSSL_FUNC_digest_get_params OSSL_FUNC_DIGEST_GET_PARAMS -\& OSSL_FUNC_digest_get_ctx_params OSSL_FUNC_DIGEST_GET_CTX_PARAMS -\& OSSL_FUNC_digest_set_ctx_params OSSL_FUNC_DIGEST_SET_CTX_PARAMS -\& -\& OSSL_FUNC_digest_gettable_params OSSL_FUNC_DIGEST_GETTABLE_PARAMS -\& OSSL_FUNC_digest_gettable_ctx_params OSSL_FUNC_DIGEST_GETTABLE_CTX_PARAMS -\& OSSL_FUNC_digest_settable_ctx_params OSSL_FUNC_DIGEST_SETTABLE_CTX_PARAMS -.Ve -.PP -A digest algorithm implementation may not implement all of these functions. -In order to be usable all or none of OSSL_FUNC_digest_newctx, OSSL_FUNC_digest_freectx, -OSSL_FUNC_digest_init, OSSL_FUNC_digest_update and OSSL_FUNC_digest_final should be implemented. -All other functions are optional. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_digest_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during a digest operation. -A pointer to this context will be passed back in a number of the other digest -operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -.PP -\&\fBOSSL_FUNC_digest_freectx()\fR is passed a pointer to the provider side digest context in -the \fIdctx\fR parameter. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_digest_dupctx()\fR should duplicate the provider side digest context in the -\&\fIdctx\fR parameter and return the duplicate copy. -.SS "Digest Generation Functions" -.IX Subsection "Digest Generation Functions" -\&\fBOSSL_FUNC_digest_init()\fR initialises a digest operation given a newly created -provider side digest context in the \fIdctx\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_digest_set_ctx_params()\fR. -.PP -\&\fBOSSL_FUNC_digest_update()\fR is called to supply data to be digested as part of a -previously initialised digest operation. -The \fIdctx\fR parameter contains a pointer to a previously initialised provider -side context. -\&\fBOSSL_FUNC_digest_update()\fR should digest \fIinl\fR bytes of data at the location pointed to -by \fIin\fR. -\&\fBOSSL_FUNC_digest_update()\fR may be called multiple times for a single digest operation. -.PP -\&\fBOSSL_FUNC_digest_final()\fR generates a digest started through previous \fBOSSL_FUNC_digest_init()\fR -and \fBOSSL_FUNC_digest_update()\fR calls. -The \fIdctx\fR parameter contains a pointer to the provider side context. -The digest should be written to \fI*out\fR and the length of the digest to -\&\fI*outl\fR. -The digest should not exceed \fIoutsz\fR bytes. -.PP -\&\fBOSSL_FUNC_digest_digest()\fR is a \*(L"oneshot\*(R" digest function. -No provider side digest context is used. -Instead the provider context that was created during provider initialisation is -passed in the \fIprovctx\fR parameter (see \fBprovider\fR\|(7)). -\&\fIinl\fR bytes at \fIin\fR should be digested and the result should be stored at -\&\fIout\fR. The length of the digest should be stored in \fI*outl\fR which should not -exceed \fIoutsz\fR bytes. -.SS "Digest Parameters" -.IX Subsection "Digest Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -these functions. -.PP -\&\fBOSSL_FUNC_digest_get_params()\fR gets details of the algorithm implementation -and stores them in \fIparams\fR. -.PP -\&\fBOSSL_FUNC_digest_set_ctx_params()\fR sets digest operation parameters for the -provider side digest context \fIdctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_digest_get_ctx_params()\fR gets digest operation details details from -the given provider side digest context \fIdctx\fR and stores them in \fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_digest_gettable_params()\fR returns a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array -containing descriptors of the parameters that \fBOSSL_FUNC_digest_get_params()\fR -can handle. -.PP -\&\fBOSSL_FUNC_digest_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_digest_settable_ctx_params()\fR both return constant -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) arrays as descriptors of the parameters that -\&\fBOSSL_FUNC_digest_get_ctx_params()\fR and \fBOSSL_FUNC_digest_set_ctx_params()\fR -can handle, respectively. The array is based on the current state of -the provider side context if \fIdctx\fR is not \s-1NULL\s0 and on the provider -side algorithm \fIprovctx\fR otherwise. -.PP -Parameters currently recognised by built-in digests with this function -are as follows. Not all parameters are relevant to, or are understood -by all digests: -.ie n .IP """blocksize"" (\fB\s-1OSSL_DIGEST_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``blocksize'' (\fB\s-1OSSL_DIGEST_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "blocksize (OSSL_DIGEST_PARAM_BLOCK_SIZE) " -The digest block size. -The length of the \*(L"blocksize\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """size"" (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_DIGEST_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_DIGEST_PARAM_SIZE) " -The digest output size. -The length of the \*(L"size\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """flags"" (\fB\s-1OSSL_DIGEST_PARAM_FLAGS\s0\fR) " 4 -.el .IP "``flags'' (\fB\s-1OSSL_DIGEST_PARAM_FLAGS\s0\fR) " 4 -.IX Item "flags (OSSL_DIGEST_PARAM_FLAGS) " -Diverse flags that describe exceptional behaviour for the digest: -.RS 4 -.IP "\fB\s-1EVP_MD_FLAG_ONESHOT\s0\fR" 4 -.IX Item "EVP_MD_FLAG_ONESHOT" -This digest method can only handle one block of input. -.IP "\fB\s-1EVP_MD_FLAG_XOF\s0\fR" 4 -.IX Item "EVP_MD_FLAG_XOF" -This digest method is an extensible-output function (\s-1XOF\s0). -.IP "\fB\s-1EVP_MD_FLAG_DIGALGID_NULL\s0\fR" 4 -.IX Item "EVP_MD_FLAG_DIGALGID_NULL" -When setting up a DigestAlgorithmIdentifier, this flag will have the -parameter set to \s-1NULL\s0 by default. Use this for PKCS#1. \fINote: if -combined with \s-1EVP_MD_FLAG_DIGALGID_ABSENT,\s0 the latter will override.\fR -.IP "\fB\s-1EVP_MD_FLAG_DIGALGID_ABSENT\s0\fR" 4 -.IX Item "EVP_MD_FLAG_DIGALGID_ABSENT" -When setting up a DigestAlgorithmIdentifier, this flag will have the -parameter be left absent by default. \fINote: if combined with -\&\s-1EVP_MD_FLAG_DIGALGID_NULL,\s0 the latter will be overridden.\fR -.IP "\fB\s-1EVP_MD_FLAG_DIGALGID_CUSTOM\s0\fR" 4 -.IX Item "EVP_MD_FLAG_DIGALGID_CUSTOM" -Custom DigestAlgorithmIdentifier handling via ctrl, with -\&\fB\s-1EVP_MD_FLAG_DIGALGID_ABSENT\s0\fR as default. \fINote: if combined with -\&\s-1EVP_MD_FLAG_DIGALGID_NULL,\s0 the latter will be overridden.\fR -Currently unused. -.RE -.RS 4 -.Sp -The length of the \*(L"flags\*(R" parameter should equal that of an -\&\fBunsigned long int\fR. -.RE -.SS "Digest Context Parameters" -.IX Subsection "Digest Context Parameters" -\&\fBOSSL_FUNC_digest_set_ctx_params()\fR sets digest parameters associated with the -given provider side digest context \fIdctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure. -.PP -\&\fBOSSL_FUNC_digest_get_ctx_params()\fR gets details of currently set parameters -values associated with the give provider side digest context \fIdctx\fR -and stores them in \fIparams\fR. -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_digest_newctx()\fR and \fBOSSL_FUNC_digest_dupctx()\fR should return the newly created -provider side digest context, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_digest_init()\fR, \fBOSSL_FUNC_digest_update()\fR, \fBOSSL_FUNC_digest_final()\fR, \fBOSSL_FUNC_digest_digest()\fR, -\&\fBOSSL_FUNC_digest_set_params()\fR and \fBOSSL_FUNC_digest_get_params()\fR should return 1 for success or -0 on error. -.PP -\&\fBOSSL_FUNC_digest_size()\fR should return the digest size. -.PP -\&\fBOSSL_FUNC_digest_block_size()\fR should return the block size of the underlying digest -algorithm. -.SH "BUGS" -.IX Header "BUGS" -The \fBEVP_Q_digest()\fR, \fBEVP_Digest()\fR and \fBEVP_DigestFinal_ex()\fR \s-1API\s0 calls do not -expect the digest size to be larger than \s-1EVP_MAX_MD_SIZE.\s0 Any algorithm which -produces larger digests is unusable with those \s-1API\s0 calls. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_PROVIDER\-FIPS\s0\fR\|(7), \fBOSSL_PROVIDER\-default\fR\|(7), -\&\fBOSSL_PROVIDER\-legacy\fR\|(7), -\&\fBEVP_MD\-common\fR\|(7), \s-1\fBEVP_MD\-BLAKE2\s0\fR\|(7), \s-1\fBEVP_MD\-MD2\s0\fR\|(7), -\&\s-1\fBEVP_MD\-MD4\s0\fR\|(7), \s-1\fBEVP_MD\-MD5\s0\fR\|(7), \s-1\fBEVP_MD\-MD5\-SHA1\s0\fR\|(7), -\&\s-1\fBEVP_MD\-MDC2\s0\fR\|(7), \s-1\fBEVP_MD\-RIPEMD160\s0\fR\|(7), \s-1\fBEVP_MD\-SHA1\s0\fR\|(7), -\&\s-1\fBEVP_MD\-SHA2\s0\fR\|(7), \s-1\fBEVP_MD\-SHA3\s0\fR\|(7), \s-1\fBEVP_MD\-KECCAK\s0\fR\|(7) -\&\s-1\fBEVP_MD\-SHAKE\s0\fR\|(7), \s-1\fBEVP_MD\-SM3\s0\fR\|(7), \s-1\fBEVP_MD\-WHIRLPOOL\s0\fR\|(7), -\&\s-1\fBEVP_MD\-NULL\s0\fR\|(7), -\&\fBlife_cycle\-digest\fR\|(7), \fBEVP_DigestInit\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1DIGEST\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-encoder.7ossl b/openssl-install/share/man/man7/provider-encoder.7ossl deleted file mode 100644 index e87443d3..00000000 --- a/openssl-install/share/man/man7/provider-encoder.7ossl +++ /dev/null @@ -1,432 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-ENCODER 7ossl" -.TH PROVIDER-ENCODER 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-encoder \- The OSSL_ENCODER library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Encoder parameter accessor and descriptor */ -\& const OSSL_PARAM *OSSL_FUNC_encoder_gettable_params(void *provctx); -\& int OSSL_FUNC_encoder_get_params(OSSL_PARAM params[]); -\& -\& /* Functions to construct / destruct / manipulate the encoder context */ -\& void *OSSL_FUNC_encoder_newctx(void *provctx); -\& void OSSL_FUNC_encoder_freectx(void *ctx); -\& int OSSL_FUNC_encoder_set_ctx_params(void *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_encoder_settable_ctx_params(void *provctx); -\& -\& /* Functions to check selection support */ -\& int OSSL_FUNC_encoder_does_selection(void *provctx, int selection); -\& -\& /* Functions to encode object data */ -\& int OSSL_FUNC_encoder_encode(void *ctx, OSSL_CORE_BIO *out, -\& const void *obj_raw, -\& const OSSL_PARAM obj_abstract[], -\& int selection, -\& OSSL_PASSPHRASE_CALLBACK *cb, -\& void *cbarg); -\& -\& /* Functions to import and free a temporary object to be encoded */ -\& void *OSSL_FUNC_encoder_import_object(void *ctx, int selection, -\& const OSSL_PARAM params[]); -\& void OSSL_FUNC_encoder_free_object(void *obj); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -\&\fIWe use the wide term \*(L"encode\*(R" in this manual. This includes but is -not limited to serialization.\fR -.PP -The \s-1ENCODER\s0 operation is a generic method to encode a provider-native -object (\fIobj_raw\fR) or an object abstraction (\fIobject_abstract\fR, see -\&\fBprovider\-object\fR\|(7)) into an encoded form, and write the result to -the given \s-1OSSL_CORE_BIO.\s0 If the caller wants to get the encoded -stream to memory, it should provide a \fBBIO_s_mem\fR\|(3) \fB\s-1BIO\s0\fR. -.PP -The encoder doesn't need to know more about the \fB\s-1OSSL_CORE_BIO\s0\fR -pointer than being able to pass it to the appropriate \s-1BIO\s0 upcalls (see -\&\*(L"Core functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -The \s-1ENCODER\s0 implementation may be part of a chain, where data is -passed from one to the next. For example, there may be an -implementation to encode an object to \s-1DER\s0 (that object is assumed to -be provider-native and thereby passed via \fIobj_raw\fR), and another one -that encodes \s-1DER\s0 to \s-1PEM\s0 (that one would receive the \s-1DER\s0 encoding via -\&\fIobj_abstract\fR). -.PP -The encoding using the \s-1\fBOSSL_PARAM\s0\fR\|(3) array form allows a -encoder to be used for data that's been exported from another -provider, and thereby allow them to exist independently of each -other. -.PP -The encoding using a provider side object can only be safely used -with provider data coming from the same provider, for example keys -with the \s-1KEYMGMT\s0 provider. -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_encoder_encode()\fR has these: -.PP -.Vb 8 -\& typedef int -\& (OSSL_FUNC_encoder_encode_fn)(void *ctx, OSSL_CORE_BIO *out, -\& const void *obj_raw, -\& const OSSL_PARAM obj_abstract[], -\& int selection, -\& OSSL_PASSPHRASE_CALLBACK *cb, void *cbarg); -\& static ossl_inline OSSL_FUNC_encoder_encode_fn -\& OSSL_FUNC_encoder_encode(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 2 -\& OSSL_FUNC_encoder_get_params OSSL_FUNC_ENCODER_GET_PARAMS -\& OSSL_FUNC_encoder_gettable_params OSSL_FUNC_ENCODER_GETTABLE_PARAMS -\& -\& OSSL_FUNC_encoder_newctx OSSL_FUNC_ENCODER_NEWCTX -\& OSSL_FUNC_encoder_freectx OSSL_FUNC_ENCODER_FREECTX -\& OSSL_FUNC_encoder_set_ctx_params OSSL_FUNC_ENCODER_SET_CTX_PARAMS -\& OSSL_FUNC_encoder_settable_ctx_params OSSL_FUNC_ENCODER_SETTABLE_CTX_PARAMS -\& -\& OSSL_FUNC_encoder_does_selection OSSL_FUNC_ENCODER_DOES_SELECTION -\& -\& OSSL_FUNC_encoder_encode OSSL_FUNC_ENCODER_ENCODE -\& -\& OSSL_FUNC_encoder_import_object OSSL_FUNC_ENCODER_IMPORT_OBJECT -\& OSSL_FUNC_encoder_free_object OSSL_FUNC_ENCODER_FREE_OBJECT -.Ve -.SS "Names and properties" -.IX Subsection "Names and properties" -The name of an implementation should match the type of object it handles. -For example, an implementation that encodes an \s-1RSA\s0 key should be named \*(L"\s-1RSA\*(R".\s0 -Likewise, an implementation that further encodes \s-1DER\s0 should be named \*(L"\s-1DER\*(R".\s0 -.PP -Properties, as defined in the \s-1\fBOSSL_ALGORITHM\s0\fR\|(3) array element of each -decoder implementation, can be used to further specify details about an -implementation: -.IP "output" 4 -.IX Item "output" -This property is used to specify what type of output the implementation -produces. -.Sp -This property is \fImandatory\fR. -.Sp -OpenSSL providers recognize the following output types: -.RS 4 -.IP "text" 4 -.IX Item "text" -An implementation with that output type outputs human readable text, making -that implementation suitable for \f(CW\*(C`\-text\*(C'\fR output in diverse \fBopenssl\fR\|(1) -commands. -.IP "pem" 4 -.IX Item "pem" -An implementation with that output type outputs \s-1PEM\s0 formatted data. -.IP "der" 4 -.IX Item "der" -An implementation with that output type outputs \s-1DER\s0 formatted data. -.IP "msblob" 4 -.IX Item "msblob" -An implementation with that output type outputs \s-1MSBLOB\s0 formatted data. -.IP "pvk" 4 -.IX Item "pvk" -An implementation with that output type outputs \s-1PVK\s0 formatted data. -.RE -.RS 4 -.RE -.IP "structure" 4 -.IX Item "structure" -This property is used to specify the structure that is used for the encoded -object. An example could be \f(CW\*(C`pkcs8\*(C'\fR, to specify explicitly that an object -(presumably an asymmetric key pair, in this case) will be wrapped in a -PKCS#8 structure as part of the encoding. -.Sp -This property is \fIoptional\fR. -.PP -The possible values of both these properties is open ended. A provider may -very well specify output types and structures that libcrypto doesn't know -anything about. -.SS "Subset selections" -.IX Subsection "Subset selections" -Sometimes, an object has more than one subset of data that is interesting to -treat separately or together. It's possible to specify what subsets are to -be encoded, with a set of bits \fIselection\fR that are passed in an \fBint\fR. -.PP -This set of bits depend entirely on what kind of provider-side object is -passed. For example, those bits are assumed to be the same as those used -with \fBprovider\-keymgmt\fR\|(7) (see \*(L"Key Objects\*(R" in \fBprovider\-keymgmt\fR\|(7)) when -the object is an asymmetric keypair. -.PP -\&\s-1ENCODER\s0 implementations are free to regard the \fIselection\fR as a set of -hints, but must do so with care. In the end, the output must make sense, -and if there's a corresponding decoder, the resulting decoded object must -match the original object that was encoded. -.PP -\&\fBOSSL_FUNC_encoder_does_selection()\fR should tell if a particular implementation -supports any of the combinations given by \fIselection\fR. -.SS "Context functions" -.IX Subsection "Context functions" -\&\fBOSSL_FUNC_encoder_newctx()\fR returns a context to be used with the rest of -the functions. -.PP -\&\fBOSSL_FUNC_encoder_freectx()\fR frees the given \fIctx\fR, if it was created by -\&\fBOSSL_FUNC_encoder_newctx()\fR. -.PP -\&\fBOSSL_FUNC_encoder_set_ctx_params()\fR sets context data according to parameters -from \fIparams\fR that it recognises. Unrecognised parameters should be -ignored. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_encoder_settable_ctx_params()\fR returns a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -array describing the parameters that \fBOSSL_FUNC_encoder_set_ctx_params()\fR -can handle. -.PP -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -\&\fBOSSL_FUNC_encoder_set_ctx_params()\fR and \fBOSSL_FUNC_encoder_settable_ctx_params()\fR. -.SS "Import functions" -.IX Subsection "Import functions" -A provider-native object may be associated with a foreign provider, and may -therefore be unsuitable for direct use with a given \s-1ENCODER\s0 implementation. -Provided that the foreign provider's implementation to handle the object has -a function to export that object in \s-1\fBOSSL_PARAM\s0\fR\|(3) array form, the \s-1ENCODER\s0 -implementation should be able to import that array and create a suitable -object to be passed to \fBOSSL_FUNC_encoder_encode()\fR's \fIobj_raw\fR. -.PP -\&\fBOSSL_FUNC_encoder_import_object()\fR should import the subset of \fIparams\fR -given with \fIselection\fR to create a provider-native object that can be -passed as \fIobj_raw\fR to \fBOSSL_FUNC_encoder_encode()\fR. -.PP -\&\fBOSSL_FUNC_encoder_free_object()\fR should free the object that was created with -\&\fBOSSL_FUNC_encoder_import_object()\fR. -.SS "Encoding functions" -.IX Subsection "Encoding functions" -\&\fBOSSL_FUNC_encoder_encode()\fR should take a provider-native object (in -\&\fIobj_raw\fR) or an object abstraction (in \fIobj_abstract\fR), and should output -the object in encoded form to the \fB\s-1OSSL_CORE_BIO\s0\fR. The \fIselection\fR bits, -if relevant, should determine in greater detail what will be output. -The encoding functions also take an \s-1\fBOSSL_PASSPHRASE_CALLBACK\s0\fR\|(3) function -pointer along with a pointer to application data \fIcbarg\fR, which should be -used when a pass phrase prompt is needed. -.SS "Encoder operation parameters" -.IX Subsection "Encoder operation parameters" -Operation parameters currently recognised by built-in encoders are as -follows: -.ie n .IP """cipher"" (\fB\s-1OSSL_ENCODER_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_ENCODER_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_ENCODER_PARAM_CIPHER) " -The name of the encryption cipher to be used when generating encrypted -encoding. This is used when encoding private keys, as well as -other objects that need protection. -.Sp -If this name is invalid for the encoding implementation, the -implementation should refuse to perform the encoding, i.e. -\&\fBOSSL_FUNC_encoder_encode_data()\fR and \fBOSSL_FUNC_encoder_encode_object()\fR -should return an error. -.ie n .IP """properties"" (\fB\s-1OSSL_ENCODER_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_ENCODER_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_ENCODER_PARAM_PROPERTIES) " -The properties to be queried when trying to fetch the algorithm given -with the \*(L"cipher\*(R" parameter. -This must be given together with the \*(L"cipher\*(R" parameter to be -considered valid. -.Sp -The encoding implementation isn't obligated to use this value. -However, it is recommended that implementations that do not handle -property strings return an error on receiving this parameter unless -its value \s-1NULL\s0 or the empty string. -.ie n .IP """save-parameters"" (\fB\s-1OSSL_ENCODER_PARAM_SAVE_PARAMETERS\s0\fR) " 4 -.el .IP "``save-parameters'' (\fB\s-1OSSL_ENCODER_PARAM_SAVE_PARAMETERS\s0\fR) " 4 -.IX Item "save-parameters (OSSL_ENCODER_PARAM_SAVE_PARAMETERS) " -If set to 0 disables saving of key domain parameters. Default is 1. -It currently has an effect only on \s-1DSA\s0 keys. -.PP -Parameters currently recognised by the built-in pass phrase callback: -.ie n .IP """info"" (\fB\s-1OSSL_PASSPHRASE_PARAM_INFO\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``info'' (\fB\s-1OSSL_PASSPHRASE_PARAM_INFO\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "info (OSSL_PASSPHRASE_PARAM_INFO) " -A string of information that will become part of the pass phrase -prompt. This could be used to give the user information on what kind -of object it's being prompted for. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_encoder_newctx()\fR returns a pointer to a context, or \s-1NULL\s0 on -failure. -.PP -\&\fBOSSL_FUNC_encoder_set_ctx_params()\fR returns 1, unless a recognised -parameter was invalid or caused an error, for which 0 is returned. -.PP -\&\fBOSSL_FUNC_encoder_settable_ctx_params()\fR returns a pointer to an array of -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) elements. -.PP -\&\fBOSSL_FUNC_encoder_does_selection()\fR returns 1 if the encoder implementation -supports any of the \fIselection\fR bits, otherwise 0. -.PP -\&\fBOSSL_FUNC_encoder_encode()\fR returns 1 on success, or 0 on failure. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1ENCODER\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-kdf.7ossl b/openssl-install/share/man/man7/provider-kdf.7ossl deleted file mode 100644 index 91750fc1..00000000 --- a/openssl-install/share/man/man7/provider-kdf.7ossl +++ /dev/null @@ -1,482 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-KDF 7ossl" -.TH PROVIDER-KDF 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-kdf \- The KDF library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_kdf_newctx(void *provctx); -\& void OSSL_FUNC_kdf_freectx(void *kctx); -\& void *OSSL_FUNC_kdf_dupctx(void *src); -\& -\& /* Encryption/decryption */ -\& int OSSL_FUNC_kdf_reset(void *kctx); -\& int OSSL_FUNC_kdf_derive(void *kctx, unsigned char *key, size_t keylen, -\& const OSSL_PARAM params[]); -\& -\& /* KDF parameter descriptors */ -\& const OSSL_PARAM *OSSL_FUNC_kdf_gettable_params(void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_kdf_gettable_ctx_params(void *kcxt, void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_kdf_settable_ctx_params(void *kcxt, void *provctx); -\& -\& /* KDF parameters */ -\& int OSSL_FUNC_kdf_get_params(OSSL_PARAM params[]); -\& int OSSL_FUNC_kdf_get_ctx_params(void *kctx, OSSL_PARAM params[]); -\& int OSSL_FUNC_kdf_set_ctx_params(void *kctx, const OSSL_PARAM params[]); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The \s-1KDF\s0 operation enables providers to implement \s-1KDF\s0 algorithms and make -them available to applications via the \s-1API\s0 functions \fBEVP_KDF_CTX_reset\fR\|(3), -and \fBEVP_KDF_derive\fR\|(3). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_kdf_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_kdf_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_kdf_newctx_fn -\& OSSL_FUNC_kdf_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) array entries are identified by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_kdf_newctx OSSL_FUNC_KDF_NEWCTX -\& OSSL_FUNC_kdf_freectx OSSL_FUNC_KDF_FREECTX -\& OSSL_FUNC_kdf_dupctx OSSL_FUNC_KDF_DUPCTX -\& -\& OSSL_FUNC_kdf_reset OSSL_FUNC_KDF_RESET -\& OSSL_FUNC_kdf_derive OSSL_FUNC_KDF_DERIVE -\& -\& OSSL_FUNC_kdf_get_params OSSL_FUNC_KDF_GET_PARAMS -\& OSSL_FUNC_kdf_get_ctx_params OSSL_FUNC_KDF_GET_CTX_PARAMS -\& OSSL_FUNC_kdf_set_ctx_params OSSL_FUNC_KDF_SET_CTX_PARAMS -\& -\& OSSL_FUNC_kdf_gettable_params OSSL_FUNC_KDF_GETTABLE_PARAMS -\& OSSL_FUNC_kdf_gettable_ctx_params OSSL_FUNC_KDF_GETTABLE_CTX_PARAMS -\& OSSL_FUNC_kdf_settable_ctx_params OSSL_FUNC_KDF_SETTABLE_CTX_PARAMS -.Ve -.PP -A \s-1KDF\s0 algorithm implementation may not implement all of these functions. -In order to be a consistent set of functions, at least the following functions -must be implemented: \fBOSSL_FUNC_kdf_newctx()\fR, \fBOSSL_FUNC_kdf_freectx()\fR, -\&\fBOSSL_FUNC_kdf_set_ctx_params()\fR, \fBOSSL_FUNC_kdf_derive()\fR. -All other functions are optional. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_kdf_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during a \s-1KDF\s0 operation. -A pointer to this context will be passed back in a number of the other \s-1KDF\s0 -operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -.PP -\&\fBOSSL_FUNC_kdf_freectx()\fR is passed a pointer to the provider side \s-1KDF\s0 context in -the \fIkctx\fR parameter. -If it receives \s-1NULL\s0 as \fIkctx\fR value, it should not do anything other than -return. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_kdf_dupctx()\fR should duplicate the provider side \s-1KDF\s0 context in the -\&\fIkctx\fR parameter and return the duplicate copy. -.SS "Encryption/Decryption Functions" -.IX Subsection "Encryption/Decryption Functions" -\&\fBOSSL_FUNC_kdf_reset()\fR initialises a \s-1KDF\s0 operation given a provider -side \s-1KDF\s0 context in the \fIkctx\fR parameter. -.PP -\&\fBOSSL_FUNC_kdf_derive()\fR performs the \s-1KDF\s0 operation after processing the -\&\fIparams\fR as per \fBOSSL_FUNC_kdf_set_ctx_params()\fR. -The \fIkctx\fR parameter contains a pointer to the provider side context. -The resulting key of the desired \fIkeylen\fR should be written to \fIkey\fR. -If the algorithm does not support the requested \fIkeylen\fR the function must -return error. -.SS "\s-1KDF\s0 Parameters" -.IX Subsection "KDF Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -these functions. -.PP -\&\fBOSSL_FUNC_kdf_get_params()\fR gets details of parameter values associated with the -provider algorithm and stores them in \fIparams\fR. -.PP -\&\fBOSSL_FUNC_kdf_set_ctx_params()\fR sets \s-1KDF\s0 parameters associated with the given -provider side \s-1KDF\s0 context \fIkctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_kdf_get_ctx_params()\fR retrieves gettable parameter values associated -with the given provider side \s-1KDF\s0 context \fIkctx\fR and stores them in \fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_kdf_gettable_params()\fR, \fBOSSL_FUNC_kdf_gettable_ctx_params()\fR, -and \fBOSSL_FUNC_kdf_settable_ctx_params()\fR all return constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -arrays as descriptors of the parameters that \fBOSSL_FUNC_kdf_get_params()\fR, -\&\fBOSSL_FUNC_kdf_get_ctx_params()\fR, and \fBOSSL_FUNC_kdf_set_ctx_params()\fR -can handle, respectively. \fBOSSL_FUNC_kdf_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_kdf_settable_ctx_params()\fR will return the parameters associated -with the provider side context \fIkctx\fR in its current state if it is -not \s-1NULL.\s0 Otherwise, they return the parameters associated with the -provider side algorithm \fIprovctx\fR. -.PP -Parameters currently recognised by built-in KDFs are as follows. Not all -parameters are relevant to, or are understood by all KDFs: -.ie n .IP """size"" (\fB\s-1OSSL_KDF_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_KDF_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_KDF_PARAM_SIZE) " -Gets the output size from the associated \s-1KDF\s0 ctx. -If the algorithm produces a variable amount of output, \s-1SIZE_MAX\s0 should be -returned. -If the input parameters required to calculate the fixed output size have not yet -been supplied, 0 should be returned indicating an error. -.ie n .IP """key"" (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_KDF_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_KDF_PARAM_KEY) " -Sets the key in the associated \s-1KDF\s0 ctx. -.ie n .IP """secret"" (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.el .IP "``secret'' (\fB\s-1OSSL_KDF_PARAM_SECRET\s0\fR) " 4 -.IX Item "secret (OSSL_KDF_PARAM_SECRET) " -Sets the secret in the associated \s-1KDF\s0 ctx. -.ie n .IP """pass"" (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.el .IP "``pass'' (\fB\s-1OSSL_KDF_PARAM_PASSWORD\s0\fR) " 4 -.IX Item "pass (OSSL_KDF_PARAM_PASSWORD) " -Sets the password in the associated \s-1KDF\s0 ctx. -.ie n .IP """cipher"" (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_KDF_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_KDF_PARAM_CIPHER) " -.PD 0 -.ie n .IP """digest"" (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_KDF_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_KDF_PARAM_DIGEST) " -.ie n .IP """mac"" (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mac'' (\fB\s-1OSSL_KDF_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mac (OSSL_KDF_PARAM_MAC) " -.PD -Sets the name of the underlying cipher, digest or \s-1MAC\s0 to be used. -It must name a suitable algorithm for the \s-1KDF\s0 that's being used. -.ie n .IP """maclen"" (\fB\s-1OSSL_KDF_PARAM_MAC_SIZE\s0\fR) " 4 -.el .IP "``maclen'' (\fB\s-1OSSL_KDF_PARAM_MAC_SIZE\s0\fR) " 4 -.IX Item "maclen (OSSL_KDF_PARAM_MAC_SIZE) " -Sets the length of the \s-1MAC\s0 in the associated \s-1KDF\s0 ctx. -.ie n .IP """properties"" (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_KDF_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_KDF_PARAM_PROPERTIES) " -Sets the properties to be queried when trying to fetch the underlying algorithm. -This must be given together with the algorithm naming parameter to be -considered valid. -.ie n .IP """iter"" (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.el .IP "``iter'' (\fB\s-1OSSL_KDF_PARAM_ITER\s0\fR) " 4 -.IX Item "iter (OSSL_KDF_PARAM_ITER) " -Sets the number of iterations in the associated \s-1KDF\s0 ctx. -.ie n .IP """mode"" (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mode'' (\fB\s-1OSSL_KDF_PARAM_MODE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mode (OSSL_KDF_PARAM_MODE) " -Sets the mode in the associated \s-1KDF\s0 ctx. -.ie n .IP """pkcs5"" (\fB\s-1OSSL_KDF_PARAM_PKCS5\s0\fR) " 4 -.el .IP "``pkcs5'' (\fB\s-1OSSL_KDF_PARAM_PKCS5\s0\fR) " 4 -.IX Item "pkcs5 (OSSL_KDF_PARAM_PKCS5) " -Enables or disables the \s-1SP800\-132\s0 compliance checks. -A mode of 0 enables the compliance checks. -.Sp -The checks performed are: -.RS 4 -.IP "\- the iteration count is at least 1000." 4 -.IX Item "- the iteration count is at least 1000." -.PD 0 -.IP "\- the salt length is at least 128 bits." 4 -.IX Item "- the salt length is at least 128 bits." -.IP "\- the derived key length is at least 112 bits." 4 -.IX Item "- the derived key length is at least 112 bits." -.RE -.RS 4 -.RE -.ie n .IP """ukm"" (\fB\s-1OSSL_KDF_PARAM_UKM\s0\fR) " 4 -.el .IP "``ukm'' (\fB\s-1OSSL_KDF_PARAM_UKM\s0\fR) " 4 -.IX Item "ukm (OSSL_KDF_PARAM_UKM) " -.PD -Sets an optional random string that is provided by the sender called -\&\*(L"partyAInfo\*(R". In \s-1CMS\s0 this is the user keying material. -.ie n .IP """cekalg"" (\fB\s-1OSSL_KDF_PARAM_CEK_ALG\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cekalg'' (\fB\s-1OSSL_KDF_PARAM_CEK_ALG\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cekalg (OSSL_KDF_PARAM_CEK_ALG) " -Sets the \s-1CEK\s0 wrapping algorithm name in the associated \s-1KDF\s0 ctx. -.ie n .IP """n"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_N\s0\fR) " 4 -.el .IP "``n'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_N\s0\fR) " 4 -.IX Item "n (OSSL_KDF_PARAM_SCRYPT_N) " -Sets the scrypt work factor parameter N in the associated \s-1KDF\s0 ctx. -.ie n .IP """r"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_R\s0\fR) " 4 -.el .IP "``r'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_R\s0\fR) " 4 -.IX Item "r (OSSL_KDF_PARAM_SCRYPT_R) " -Sets the scrypt work factor parameter r in the associated \s-1KDF\s0 ctx. -.ie n .IP """p"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_P\s0\fR) " 4 -.el .IP "``p'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_P\s0\fR) " 4 -.IX Item "p (OSSL_KDF_PARAM_SCRYPT_P) " -Sets the scrypt work factor parameter p in the associated \s-1KDF\s0 ctx. -.ie n .IP """maxmem_bytes"" (\fB\s-1OSSL_KDF_PARAM_SCRYPT_MAXMEM\s0\fR) " 4 -.el .IP "``maxmem_bytes'' (\fB\s-1OSSL_KDF_PARAM_SCRYPT_MAXMEM\s0\fR) " 4 -.IX Item "maxmem_bytes (OSSL_KDF_PARAM_SCRYPT_MAXMEM) " -Sets the scrypt work factor parameter maxmem in the associated \s-1KDF\s0 ctx. -.ie n .IP """prefix"" (\fB\s-1OSSL_KDF_PARAM_PREFIX\s0\fR) " 4 -.el .IP "``prefix'' (\fB\s-1OSSL_KDF_PARAM_PREFIX\s0\fR) " 4 -.IX Item "prefix (OSSL_KDF_PARAM_PREFIX) " -Sets the prefix string using by the \s-1TLS 1.3\s0 version of \s-1HKDF\s0 in the -associated \s-1KDF\s0 ctx. -.ie n .IP """label"" (\fB\s-1OSSL_KDF_PARAM_LABEL\s0\fR) " 4 -.el .IP "``label'' (\fB\s-1OSSL_KDF_PARAM_LABEL\s0\fR) " 4 -.IX Item "label (OSSL_KDF_PARAM_LABEL) " -Sets the label string using by the \s-1TLS 1.3\s0 version of \s-1HKDF\s0 in the -associated \s-1KDF\s0 ctx. -.ie n .IP """data"" (\fB\s-1OSSL_KDF_PARAM_DATA\s0\fR) " 4 -.el .IP "``data'' (\fB\s-1OSSL_KDF_PARAM_DATA\s0\fR) " 4 -.IX Item "data (OSSL_KDF_PARAM_DATA) " -Sets the context string using by the \s-1TLS 1.3\s0 version of \s-1HKDF\s0 in the -associated \s-1KDF\s0 ctx. -.ie n .IP """info"" (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.el .IP "``info'' (\fB\s-1OSSL_KDF_PARAM_INFO\s0\fR) " 4 -.IX Item "info (OSSL_KDF_PARAM_INFO) " -Sets the optional shared info in the associated \s-1KDF\s0 ctx. -.ie n .IP """seed"" (\fB\s-1OSSL_KDF_PARAM_SEED\s0\fR) " 4 -.el .IP "``seed'' (\fB\s-1OSSL_KDF_PARAM_SEED\s0\fR) " 4 -.IX Item "seed (OSSL_KDF_PARAM_SEED) " -Sets the \s-1IV\s0 in the associated \s-1KDF\s0 ctx. -.ie n .IP """xcghash"" (\fB\s-1OSSL_KDF_PARAM_SSHKDF_XCGHASH\s0\fR) " 4 -.el .IP "``xcghash'' (\fB\s-1OSSL_KDF_PARAM_SSHKDF_XCGHASH\s0\fR) " 4 -.IX Item "xcghash (OSSL_KDF_PARAM_SSHKDF_XCGHASH) " -Sets the xcghash in the associated \s-1KDF\s0 ctx. -.ie n .IP """session_id"" (\fB\s-1OSSL_KDF_PARAM_SSHKDF_SESSION_ID\s0\fR) " 4 -.el .IP "``session_id'' (\fB\s-1OSSL_KDF_PARAM_SSHKDF_SESSION_ID\s0\fR) " 4 -.IX Item "session_id (OSSL_KDF_PARAM_SSHKDF_SESSION_ID) " -Sets the session \s-1ID\s0 in the associated \s-1KDF\s0 ctx. -.ie n .IP """type"" (\fB\s-1OSSL_KDF_PARAM_SSHKDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``type'' (\fB\s-1OSSL_KDF_PARAM_SSHKDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "type (OSSL_KDF_PARAM_SSHKDF_TYPE) " -Sets the \s-1SSH KDF\s0 type parameter in the associated \s-1KDF\s0 ctx. -There are six supported types: -.RS 4 -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV" -The Initial \s-1IV\s0 from client to server. -A single char of value 65 (\s-1ASCII\s0 char 'A'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INITIAL_IV_SRV_TO_CLI\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INITIAL_IV_SRV_TO_CLI" -The Initial \s-1IV\s0 from server to client -A single char of value 66 (\s-1ASCII\s0 char 'B'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_CLI_TO_SRV\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_CLI_TO_SRV" -The Encryption Key from client to server -A single char of value 67 (\s-1ASCII\s0 char 'C'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_SRV_TO_CLI\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_SRV_TO_CLI" -The Encryption Key from server to client -A single char of value 68 (\s-1ASCII\s0 char 'D'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_CLI_TO_SRV\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_CLI_TO_SRV" -The Integrity Key from client to server -A single char of value 69 (\s-1ASCII\s0 char 'E'). -.IP "\s-1EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_SRV_TO_CLI\s0" 4 -.IX Item "EVP_KDF_SSHKDF_TYPE_INTEGRITY_KEY_SRV_TO_CLI" -The Integrity Key from client to server -A single char of value 70 (\s-1ASCII\s0 char 'F'). -.RE -.RS 4 -.RE -.ie n .IP """constant"" (\fB\s-1OSSL_KDF_PARAM_CONSTANT\s0\fR) " 4 -.el .IP "``constant'' (\fB\s-1OSSL_KDF_PARAM_CONSTANT\s0\fR) " 4 -.IX Item "constant (OSSL_KDF_PARAM_CONSTANT) " -Sets the constant value in the associated \s-1KDF\s0 ctx. -.ie n .IP """id"" (\fB\s-1OSSL_KDF_PARAM_PKCS12_ID\s0\fR) " 4 -.el .IP "``id'' (\fB\s-1OSSL_KDF_PARAM_PKCS12_ID\s0\fR) " 4 -.IX Item "id (OSSL_KDF_PARAM_PKCS12_ID) " -Sets the intended usage of the output bits in the associated \s-1KDF\s0 ctx. -It is defined as per \s-1RFC 7292\s0 section B.3. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_kdf_newctx()\fR and \fBOSSL_FUNC_kdf_dupctx()\fR should return the newly created -provider side \s-1KDF\s0 context, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_kdf_derive()\fR, \fBOSSL_FUNC_kdf_get_params()\fR, -\&\fBOSSL_FUNC_kdf_get_ctx_params()\fR and \fBOSSL_FUNC_kdf_set_ctx_params()\fR should return 1 for -success or 0 on error. -.PP -\&\fBOSSL_FUNC_kdf_gettable_params()\fR, \fBOSSL_FUNC_kdf_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_kdf_settable_ctx_params()\fR should return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -array, or \s-1NULL\s0 if none is offered. -.SH "NOTES" -.IX Header "NOTES" -The \s-1KDF\s0 life-cycle is described in \fBlife_cycle\-kdf\fR\|(7). Providers should -ensure that the various transitions listed there are supported. At some point -the \s-1EVP\s0 layer will begin enforcing the listed transitions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \fBlife_cycle\-kdf\fR\|(7), \s-1\fBEVP_KDF\s0\fR\|(3). -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1KDF\s0 interface was introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-kem.7ossl b/openssl-install/share/man/man7/provider-kem.7ossl deleted file mode 100644 index 3d06aed4..00000000 --- a/openssl-install/share/man/man7/provider-kem.7ossl +++ /dev/null @@ -1,384 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-KEM 7ossl" -.TH PROVIDER-KEM 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-kem \- The kem library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_kem_newctx(void *provctx); -\& void OSSL_FUNC_kem_freectx(void *ctx); -\& void *OSSL_FUNC_kem_dupctx(void *ctx); -\& -\& /* Encapsulation */ -\& int OSSL_FUNC_kem_encapsulate_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_kem_auth_encapsulate_init(void *ctx, void *provkey, -\& void *provauthkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_kem_encapsulate(void *ctx, unsigned char *out, size_t *outlen, -\& unsigned char *secret, size_t *secretlen); -\& -\& /* Decapsulation */ -\& int OSSL_FUNC_kem_decapsulate_init(void *ctx, void *provkey); -\& int OSSL_FUNC_kem_auth_decapsulate_init(void *ctx, void *provkey, -\& void *provauthkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_kem_decapsulate(void *ctx, unsigned char *out, size_t *outlen, -\& const unsigned char *in, size_t inlen); -\& -\& /* KEM parameters */ -\& int OSSL_FUNC_kem_get_ctx_params(void *ctx, OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_kem_gettable_ctx_params(void *ctx, void *provctx); -\& int OSSL_FUNC_kem_set_ctx_params(void *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_kem_settable_ctx_params(void *ctx, void *provctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The asymmetric kem (\s-1OSSL_OP_KEM\s0) operation enables providers to -implement asymmetric kem algorithms and make them available to applications -via the \s-1API\s0 functions \fBEVP_PKEY_encapsulate\fR\|(3), -\&\fBEVP_PKEY_decapsulate\fR\|(3) and other related functions. -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_kem_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_kem_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_kem_newctx_fn -\& OSSL_FUNC_kem_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_kem_newctx OSSL_FUNC_KEM_NEWCTX -\& OSSL_FUNC_kem_freectx OSSL_FUNC_KEM_FREECTX -\& OSSL_FUNC_kem_dupctx OSSL_FUNC_KEM_DUPCTX -\& -\& OSSL_FUNC_kem_encapsulate_init OSSL_FUNC_KEM_ENCAPSULATE_INIT -\& OSSL_FUNC_kem_auth_encapsulate_init OSSL_FUNC_KEM_AUTH_ENCAPSULATE_INIT -\& OSSL_FUNC_kem_encapsulate OSSL_FUNC_KEM_ENCAPSULATE -\& -\& OSSL_FUNC_kem_decapsulate_init OSSL_FUNC_KEM_DECAPSULATE_INIT -\& OSSL_FUNC_kem_auth_decapsulate_init OSSL_FUNC_KEM_AUTH_DECAPSULATE_INIT -\& OSSL_FUNC_kem_decapsulate OSSL_FUNC_KEM_DECAPSULATE -\& -\& OSSL_FUNC_kem_get_ctx_params OSSL_FUNC_KEM_GET_CTX_PARAMS -\& OSSL_FUNC_kem_gettable_ctx_params OSSL_FUNC_KEM_GETTABLE_CTX_PARAMS -\& OSSL_FUNC_kem_set_ctx_params OSSL_FUNC_KEM_SET_CTX_PARAMS -\& OSSL_FUNC_kem_settable_ctx_params OSSL_FUNC_KEM_SETTABLE_CTX_PARAMS -.Ve -.PP -An asymmetric kem algorithm implementation may not implement all of these -functions. -In order to be a consistent set of functions a provider must implement -OSSL_FUNC_kem_newctx and OSSL_FUNC_kem_freectx. -It must also implement both of OSSL_FUNC_kem_encapsulate_init and -OSSL_FUNC_kem_encapsulate, or both of OSSL_FUNC_kem_decapsulate_init and -OSSL_FUNC_kem_decapsulate. -OSSL_FUNC_kem_auth_encapsulate_init is optional but if it is present then so -must OSSL_FUNC_kem_auth_decapsulate_init. -OSSL_FUNC_kem_get_ctx_params is optional but if it is present then so must -OSSL_FUNC_kem_gettable_ctx_params. -Similarly, OSSL_FUNC_kem_set_ctx_params is optional but if it is present then -OSSL_FUNC_kem_settable_ctx_params must also be present. -.PP -An asymmetric kem algorithm must also implement some mechanism for generating, -loading or importing keys via the key management (\s-1OSSL_OP_KEYMGMT\s0) operation. -See \fBprovider\-keymgmt\fR\|(7) for further details. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_kem_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during an asymmetric kem operation. -A pointer to this context will be passed back in a number of the other -asymmetric kem operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -.PP -\&\fBOSSL_FUNC_kem_freectx()\fR is passed a pointer to the provider side asymmetric -kem context in the \fIctx\fR parameter. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_kem_dupctx()\fR should duplicate the provider side asymmetric kem -context in the \fIctx\fR parameter and return the duplicate copy. -.SS "Asymmetric Key Encapsulation Functions" -.IX Subsection "Asymmetric Key Encapsulation Functions" -\&\fBOSSL_FUNC_kem_encapsulate_init()\fR initialises a context for an asymmetric -encapsulation given a provider side asymmetric kem context in the \fIctx\fR -parameter, a pointer to a provider key object in the \fIprovkey\fR parameter and -the \fIname\fR of the algorithm. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_kem_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)>. -.PP -\&\fBOSSL_FUNC_kem_auth_encapsulate_init()\fR is similar to -\&\fBOSSL_FUNC_kem_encapsulate_init()\fR, but also passes an additional authentication -key \fIprovauthkey\fR which cannot be \s-1NULL.\s0 -.PP -\&\fBOSSL_FUNC_kem_encapsulate()\fR performs the actual encapsulation itself. -A previously initialised asymmetric kem context is passed in the \fIctx\fR -parameter. -Unless \fIout\fR is \s-1NULL,\s0 the data to be encapsulated is internally generated, -and returned into the buffer pointed to by the \fIsecret\fR parameter and the -encapsulated data should also be written to the location pointed to by the -\&\fIout\fR parameter. The length of the encapsulated data should be written to -\&\fI*outlen\fR and the length of the generated secret should be written to -\&\fI*secretlen\fR. -.PP -If \fIout\fR is \s-1NULL\s0 then the maximum length of the encapsulated data should be -written to \fI*outlen\fR, and the maximum length of the generated secret should be -written to \fI*secretlen\fR. -.SS "Decapsulation Functions" -.IX Subsection "Decapsulation Functions" -\&\fBOSSL_FUNC_kem_decapsulate_init()\fR initialises a context for an asymmetric -decapsulation given a provider side asymmetric kem context in the \fIctx\fR -parameter, a pointer to a provider key object in the \fIprovkey\fR parameter, and -a \fIname\fR of the algorithm. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)>. -.PP -\&\fBOSSL_FUNC_kem_auth_decapsulate_init()\fR is similar to -\&\fBOSSL_FUNC_kem_decapsulate_init()\fR, but also passes an additional authentication -key \fIprovauthkey\fR which cannot be \s-1NULL.\s0 -.PP -\&\fBOSSL_FUNC_kem_decapsulate()\fR performs the actual decapsulation itself. -A previously initialised asymmetric kem context is passed in the \fIctx\fR -parameter. -The data to be decapsulated is pointed to by the \fIin\fR parameter which is \fIinlen\fR -bytes long. -Unless \fIout\fR is \s-1NULL,\s0 the decapsulated data should be written to the location -pointed to by the \fIout\fR parameter. -The length of the decapsulated data should be written to \fI*outlen\fR. -If \fIout\fR is \s-1NULL\s0 then the maximum length of the decapsulated data should be -written to \fI*outlen\fR. -.SS "Asymmetric Key Encapsulation Parameters" -.IX Subsection "Asymmetric Key Encapsulation Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -the \fBOSSL_FUNC_kem_get_ctx_params()\fR and \fBOSSL_FUNC_kem_set_ctx_params()\fR -functions. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_KEM_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling either \fBOSSL_FUNC_kem_encapsulate()\fR or -\&\fBOSSL_FUNC_kem_decapsulate()\fR. It may return 0 if the \*(L"key-check\*(R" is set to 0. -.ie n .IP """key-check"" (\fB\s-1OSSL_KEM_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_KEM_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_KEM_PARAM_FIPS_KEY_CHECK) " -If required this parameter should be set using \fBOSSL_FUNC_kem_encapsulate_init()\fR -or \fBOSSL_FUNC_kem_decapsulate_init()\fR. -The default value of 1 causes an error during the init if the key is not \s-1FIPS\s0 -approved (e.g. The key has a security strength of less than 112 bits). Setting -this to 0 will ignore the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SS "Asymmetric Key Encapsulation Parameter Functions" -.IX Subsection "Asymmetric Key Encapsulation Parameter Functions" -\&\fBOSSL_FUNC_kem_get_ctx_params()\fR gets asymmetric \s-1KEM\s0 parameters associated -with the given provider side asymmetric kem context \fIctx\fR and stores them in -\&\fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_kem_set_ctx_params()\fR sets the asymmetric \s-1KEM\s0 parameters associated -with the given provider side asymmetric kem context \fIctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -No parameters are currently recognised by built-in asymmetric kem algorithms. -.PP -\&\fBOSSL_FUNC_kem_gettable_ctx_params()\fR and \fBOSSL_FUNC_kem_settable_ctx_params()\fR -get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the gettable and settable -parameters, i.e. parameters that can be used with \fBOSSL_FUNC_kem_get_ctx_params()\fR -and \fBOSSL_FUNC_kem_set_ctx_params()\fR respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_kem_newctx()\fR and \fBOSSL_FUNC_kem_dupctx()\fR should return the newly -created provider side asymmetric kem context, or \s-1NULL\s0 on failure. -.PP -All other functions should return 1 for success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1KEM\s0 interface was introduced in OpenSSL 3.0. -.PP -\&\fBOSSL_FUNC_kem_auth_encapsulate_init()\fR and \fBOSSL_FUNC_kem_auth_decapsulate_init()\fR -were added in OpenSSL 3.2. -.PP -The Asymmetric Key Encapsulation Parameters \*(L"fips-indicator\*(R" and \*(L"key-check\*(R" -were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-keyexch.7ossl b/openssl-install/share/man/man7/provider-keyexch.7ossl deleted file mode 100644 index 0824dbea..00000000 --- a/openssl-install/share/man/man7/provider-keyexch.7ossl +++ /dev/null @@ -1,392 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-KEYEXCH 7ossl" -.TH PROVIDER-KEYEXCH 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-keyexch \- The keyexch library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_keyexch_newctx(void *provctx); -\& void OSSL_FUNC_keyexch_freectx(void *ctx); -\& void *OSSL_FUNC_keyexch_dupctx(void *ctx); -\& -\& /* Shared secret derivation */ -\& int OSSL_FUNC_keyexch_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_keyexch_set_peer(void *ctx, void *provkey); -\& int OSSL_FUNC_keyexch_derive(void *ctx, unsigned char *secret, size_t *secretlen, -\& size_t outlen); -\& -\& /* Key Exchange parameters */ -\& int OSSL_FUNC_keyexch_set_ctx_params(void *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_keyexch_settable_ctx_params(void *ctx, -\& void *provctx); -\& int OSSL_FUNC_keyexch_get_ctx_params(void *ctx, OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_keyexch_gettable_ctx_params(void *ctx, -\& void *provctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The key exchange (\s-1OSSL_OP_KEYEXCH\s0) operation enables providers to implement key -exchange algorithms and make them available to applications via -\&\fBEVP_PKEY_derive\fR\|(3) and -other related functions). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_keyexch_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_keyexch_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_keyexch_newctx_fn -\& OSSL_FUNC_keyexch_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_keyexch_newctx OSSL_FUNC_KEYEXCH_NEWCTX -\& OSSL_FUNC_keyexch_freectx OSSL_FUNC_KEYEXCH_FREECTX -\& OSSL_FUNC_keyexch_dupctx OSSL_FUNC_KEYEXCH_DUPCTX -\& -\& OSSL_FUNC_keyexch_init OSSL_FUNC_KEYEXCH_INIT -\& OSSL_FUNC_keyexch_set_peer OSSL_FUNC_KEYEXCH_SET_PEER -\& OSSL_FUNC_keyexch_derive OSSL_FUNC_KEYEXCH_DERIVE -\& -\& OSSL_FUNC_keyexch_set_ctx_params OSSL_FUNC_KEYEXCH_SET_CTX_PARAMS -\& OSSL_FUNC_keyexch_settable_ctx_params OSSL_FUNC_KEYEXCH_SETTABLE_CTX_PARAMS -\& OSSL_FUNC_keyexch_get_ctx_params OSSL_FUNC_KEYEXCH_GET_CTX_PARAMS -\& OSSL_FUNC_keyexch_gettable_ctx_params OSSL_FUNC_KEYEXCH_GETTABLE_CTX_PARAMS -.Ve -.PP -A key exchange algorithm implementation may not implement all of these functions. -In order to be a consistent set of functions a provider must implement -OSSL_FUNC_keyexch_newctx, OSSL_FUNC_keyexch_freectx, OSSL_FUNC_keyexch_init and OSSL_FUNC_keyexch_derive. -All other functions are optional. -.PP -A key exchange algorithm must also implement some mechanism for generating, -loading or importing keys via the key management (\s-1OSSL_OP_KEYMGMT\s0) operation. -See \fBprovider\-keymgmt\fR\|(7) for further details. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_keyexch_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during a key exchange operation. -A pointer to this context will be passed back in a number of the other key -exchange operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -.PP -\&\fBOSSL_FUNC_keyexch_freectx()\fR is passed a pointer to the provider side key exchange -context in the \fIctx\fR parameter. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_keyexch_dupctx()\fR should duplicate the provider side key exchange context in -the \fIctx\fR parameter and return the duplicate copy. -.SS "Shared Secret Derivation Functions" -.IX Subsection "Shared Secret Derivation Functions" -\&\fBOSSL_FUNC_keyexch_init()\fR initialises a key exchange operation given a provider side key -exchange context in the \fIctx\fR parameter, and a pointer to a provider key object -in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_keyexch_set_params()\fR. -The key object should have been previously -generated, loaded or imported into the provider using the key management -(\s-1OSSL_OP_KEYMGMT\s0) operation (see \fBprovider\-keymgmt\fR\|(7)>. -.PP -\&\fBOSSL_FUNC_keyexch_set_peer()\fR is called to supply the peer's public key (in the -\&\fIprovkey\fR parameter) to be used when deriving the shared secret. -It is also passed a previously initialised key exchange context in the \fIctx\fR -parameter. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)>. -.PP -\&\fBOSSL_FUNC_keyexch_derive()\fR performs the actual key exchange itself by deriving a shared -secret. -A previously initialised key exchange context is passed in the \fIctx\fR -parameter. -The derived secret should be written to the location \fIsecret\fR which should not -exceed \fIoutlen\fR bytes. -The length of the shared secret should be written to \fI*secretlen\fR. -If \fIsecret\fR is \s-1NULL\s0 then the maximum length of the shared secret should be -written to \fI*secretlen\fR. -.SS "Key Exchange Parameters Functions" -.IX Subsection "Key Exchange Parameters Functions" -\&\fBOSSL_FUNC_keyexch_set_ctx_params()\fR sets key exchange parameters associated with the -given provider side key exchange context \fIctx\fR to \fIparams\fR, -see \*(L"Common Key Exchange parameters\*(R". -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_keyexch_get_ctx_params()\fR gets key exchange parameters associated with the -given provider side key exchange context \fIctx\fR into \fIparams\fR, -see \*(L"Common Key Exchange parameters\*(R". -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_keyexch_settable_ctx_params()\fR yields a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that -describes the settable parameters, i.e. parameters that can be used with -\&\fBOP_signature_set_ctx_params()\fR. -If \fBOSSL_FUNC_keyexch_settable_ctx_params()\fR is present, \fBOSSL_FUNC_keyexch_set_ctx_params()\fR must -also be present, and vice versa. -Similarly, \fBOSSL_FUNC_keyexch_gettable_ctx_params()\fR yields a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -array that describes the gettable parameters, i.e. parameters that can be -handled by \fBOP_signature_get_ctx_params()\fR. -If \fBOSSL_FUNC_keyexch_gettable_ctx_params()\fR is present, \fBOSSL_FUNC_keyexch_get_ctx_params()\fR must -also be present, and vice versa. -.PP -Notice that not all settable parameters are also gettable, and vice versa. -.SS "Common Key Exchange parameters" -.IX Subsection "Common Key Exchange parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -the \fBOSSL_FUNC_keyexch_set_ctx_params()\fR and \fBOSSL_FUNC_keyexch_get_ctx_params()\fR functions. -.PP -Common parameters currently recognised by built-in key exchange algorithms are -as follows. -.ie n .IP """kdf-type"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-type'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-type (OSSL_EXCHANGE_PARAM_KDF_TYPE) " -Sets or gets the Key Derivation Function type to apply within the associated key -exchange ctx. -.ie n .IP """kdf-digest"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-digest'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-digest (OSSL_EXCHANGE_PARAM_KDF_DIGEST) " -Sets or gets the Digest algorithm to be used as part of the Key Derivation Function -associated with the given key exchange ctx. -.ie n .IP """kdf-digest-props"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``kdf-digest-props'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "kdf-digest-props (OSSL_EXCHANGE_PARAM_KDF_DIGEST_PROPS) " -Sets properties to be used upon look up of the implementation for the selected -Digest algorithm for the Key Derivation Function associated with the given key -exchange ctx. -.ie n .IP """kdf-outlen"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_OUTLEN\s0\fR) " 4 -.el .IP "``kdf-outlen'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_OUTLEN\s0\fR) " 4 -.IX Item "kdf-outlen (OSSL_EXCHANGE_PARAM_KDF_OUTLEN) " -Sets or gets the desired size for the output of the chosen Key Derivation Function -associated with the given key exchange ctx. -The length of the \*(L"kdf-outlen\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """kdf-ukm"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.el .IP "``kdf-ukm'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.IX Item "kdf-ukm (OSSL_EXCHANGE_PARAM_KDF_UKM) " -Sets the User Key Material to be used as part of the selected Key Derivation -Function associated with the given key exchange ctx. -.ie n .IP """kdf-ukm"" (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.el .IP "``kdf-ukm'' (\fB\s-1OSSL_EXCHANGE_PARAM_KDF_UKM\s0\fR) " 4 -.IX Item "kdf-ukm (OSSL_EXCHANGE_PARAM_KDF_UKM) " -Gets a pointer to the User Key Material to be used as part of the selected -Key Derivation Function associated with the given key exchange ctx. Providers -usually do not need to support this gettable parameter as its sole purpose -is to support functionality of the deprecated \fBEVP_PKEY_CTX_get0_ecdh_kdf_ukm()\fR -and \fBEVP_PKEY_CTX_get0_dh_kdf_ukm()\fR functions. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_EXCHANGE_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling \fBOSSL_FUNC_keyexch_derive()\fR. It may -return 0 if either the \*(L"digest-check\*(R" or the \*(L"key-check\*(R" are set to 0. -.ie n .IP """key-check"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_EXCHANGE_PARAM_FIPS_KEY_CHECK) " -If required this parameter should be set using \fBOSSL_FUNC_keyexch_init()\fR. -The default value of 1 causes an error during the init if the key is not \s-1FIPS\s0 -approved (e.g. The key has a security strength of less than 112 bits). Setting -this to 0 will ignore the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.ie n .IP """digest-check"" (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_EXCHANGE_PARAM_FIPS_DIGEST_CHECK) " -If required this parameter should be set before any optional digest is set. -The default value of 1 causes an error when the digest is set if the digest is -not \s-1FIPS\s0 approved. Setting this to 0 will ignore the error and set the -approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_keyexch_newctx()\fR and \fBOSSL_FUNC_keyexch_dupctx()\fR should return the newly created -provider side key exchange context, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_keyexch_init()\fR, \fBOSSL_FUNC_keyexch_set_peer()\fR, \fBOSSL_FUNC_keyexch_derive()\fR, -\&\fBOSSL_FUNC_keyexch_set_params()\fR, and \fBOSSL_FUNC_keyexch_get_params()\fR should return 1 for success -or 0 on error. -.PP -\&\fBOSSL_FUNC_keyexch_settable_ctx_params()\fR and \fBOSSL_FUNC_keyexch_gettable_ctx_params()\fR should -always return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1KEYEXCH\s0 interface was introduced in OpenSSL 3.0. -.PP -The Key Exchange Parameters \*(L"fips-indicator\*(R", \*(L"key-check\*(R" and \*(L"digest-check\*(R" -were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-keymgmt.7ossl b/openssl-install/share/man/man7/provider-keymgmt.7ossl deleted file mode 100644 index 524a0e92..00000000 --- a/openssl-install/share/man/man7/provider-keymgmt.7ossl +++ /dev/null @@ -1,628 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-KEYMGMT 7ossl" -.TH PROVIDER-KEYMGMT 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-keymgmt \- The KEYMGMT library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Key object (keydata) creation and destruction */ -\& void *OSSL_FUNC_keymgmt_new(void *provctx); -\& void OSSL_FUNC_keymgmt_free(void *keydata); -\& -\& /* Generation, a more complex constructor */ -\& void *OSSL_FUNC_keymgmt_gen_init(void *provctx, int selection, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_keymgmt_gen_set_template(void *genctx, void *template); -\& int OSSL_FUNC_keymgmt_gen_get_params(void *genctx, OSSL_PARAM params[]); -\& int OSSL_FUNC_keymgmt_gen_set_params(void *genctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_gen_gettable_params(void *genctx, -\& void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_gen_settable_params(void *genctx, -\& void *provctx); -\& void *OSSL_FUNC_keymgmt_gen(void *genctx, OSSL_CALLBACK *cb, void *cbarg); -\& void OSSL_FUNC_keymgmt_gen_cleanup(void *genctx); -\& -\& /* Key loading by object reference, also a constructor */ -\& void *OSSL_FUNC_keymgmt_load(const void *reference, size_t reference_sz); -\& -\& /* Key object information */ -\& int OSSL_FUNC_keymgmt_get_params(void *keydata, OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_gettable_params(void *provctx); -\& int OSSL_FUNC_keymgmt_set_params(void *keydata, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_settable_params(void *provctx); -\& -\& /* Key object content checks */ -\& int OSSL_FUNC_keymgmt_has(const void *keydata, int selection); -\& int OSSL_FUNC_keymgmt_match(const void *keydata1, const void *keydata2, -\& int selection); -\& -\& /* Discovery of supported operations */ -\& const char *OSSL_FUNC_keymgmt_query_operation_name(int operation_id); -\& -\& /* Key object import and export functions */ -\& int OSSL_FUNC_keymgmt_import(void *keydata, int selection, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_import_types(int selection); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_import_types_ex(void *provctx, int selection); -\& int OSSL_FUNC_keymgmt_export(void *keydata, int selection, -\& OSSL_CALLBACK *param_cb, void *cbarg); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_export_types(int selection); -\& const OSSL_PARAM *OSSL_FUNC_keymgmt_export_types_ex(void *provctx, int selection); -\& -\& /* Key object duplication, a constructor */ -\& void *OSSL_FUNC_keymgmt_dup(const void *keydata_from, int selection); -\& -\& /* Key object validation */ -\& int OSSL_FUNC_keymgmt_validate(const void *keydata, int selection, int checktype); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1KEYMGMT\s0 operation doesn't have much public visibility in OpenSSL -libraries, it's rather an internal operation that's designed to work -in tandem with operations that use private/public key pairs. -.PP -Because the \s-1KEYMGMT\s0 operation shares knowledge with the operations it -works with in tandem, they must belong to the same provider. -The OpenSSL libraries will ensure that they do. -.PP -The primary responsibility of the \s-1KEYMGMT\s0 operation is to hold the -provider side key data for the OpenSSL library \s-1EVP_PKEY\s0 structure. -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from a \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_keymgmt_new()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_keymgmt_new_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_keymgmt_new_fn -\& OSSL_FUNC_keymgmt_new(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 2 -\& OSSL_FUNC_keymgmt_new OSSL_FUNC_KEYMGMT_NEW -\& OSSL_FUNC_keymgmt_free OSSL_FUNC_KEYMGMT_FREE -\& -\& OSSL_FUNC_keymgmt_gen_init OSSL_FUNC_KEYMGMT_GEN_INIT -\& OSSL_FUNC_keymgmt_gen_set_template OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE -\& OSSL_FUNC_keymgmt_gen_get_params OSSL_FUNC_KEYMGMT_GEN_GET_PARAMS -\& OSSL_FUNC_keymgmt_gen_gettable_params OSSL_FUNC_KEYMGMT_GEN_GETTABLE_PARAMS -\& OSSL_FUNC_keymgmt_gen_set_params OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS -\& OSSL_FUNC_keymgmt_gen_settable_params OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS -\& OSSL_FUNC_keymgmt_gen OSSL_FUNC_KEYMGMT_GEN -\& OSSL_FUNC_keymgmt_gen_cleanup OSSL_FUNC_KEYMGMT_GEN_CLEANUP -\& -\& OSSL_FUNC_keymgmt_load OSSL_FUNC_KEYMGMT_LOAD -\& -\& OSSL_FUNC_keymgmt_get_params OSSL_FUNC_KEYMGMT_GET_PARAMS -\& OSSL_FUNC_keymgmt_gettable_params OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS -\& OSSL_FUNC_keymgmt_set_params OSSL_FUNC_KEYMGMT_SET_PARAMS -\& OSSL_FUNC_keymgmt_settable_params OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS -\& -\& OSSL_FUNC_keymgmt_query_operation_name OSSL_FUNC_KEYMGMT_QUERY_OPERATION_NAME -\& -\& OSSL_FUNC_keymgmt_has OSSL_FUNC_KEYMGMT_HAS -\& OSSL_FUNC_keymgmt_validate OSSL_FUNC_KEYMGMT_VALIDATE -\& OSSL_FUNC_keymgmt_match OSSL_FUNC_KEYMGMT_MATCH -\& -\& OSSL_FUNC_keymgmt_import OSSL_FUNC_KEYMGMT_IMPORT -\& OSSL_FUNC_keymgmt_import_types OSSL_FUNC_KEYMGMT_IMPORT_TYPES -\& OSSL_FUNC_keymgmt_import_types_ex OSSL_FUNC_KEYMGMT_IMPORT_TYPES_EX -\& OSSL_FUNC_keymgmt_export OSSL_FUNC_KEYMGMT_EXPORT -\& OSSL_FUNC_keymgmt_export_types OSSL_FUNC_KEYMGMT_EXPORT_TYPES -\& OSSL_FUNC_keymgmt_export_types_ex OSSL_FUNC_KEYMGMT_EXPORT_TYPES_EX -\& -\& OSSL_FUNC_keymgmt_dup OSSL_FUNC_KEYMGMT_DUP -.Ve -.SS "Key Objects" -.IX Subsection "Key Objects" -A key object is a collection of data for an asymmetric key, and is -represented as \fIkeydata\fR in this manual. -.PP -The exact contents of a key object are defined by the provider, and it -is assumed that different operations in one and the same provider use -the exact same structure to represent this collection of data, so that -for example, a key object that has been created using the \s-1KEYMGMT\s0 -interface that we document here can be passed as is to other provider -operations, such as \fBOP_signature_sign_init()\fR (see -\&\fBprovider\-signature\fR\|(7)). -.PP -With some of the \s-1KEYMGMT\s0 functions, it's possible to select a specific -subset of data to handle, governed by the bits in a \fIselection\fR -indicator. The bits are: -.IP "\fB\s-1OSSL_KEYMGMT_SELECT_PRIVATE_KEY\s0\fR" 4 -.IX Item "OSSL_KEYMGMT_SELECT_PRIVATE_KEY" -Indicating that the private key data in a key object should be -considered. -.IP "\fB\s-1OSSL_KEYMGMT_SELECT_PUBLIC_KEY\s0\fR" 4 -.IX Item "OSSL_KEYMGMT_SELECT_PUBLIC_KEY" -Indicating that the public key data in a key object should be -considered. -.IP "\fB\s-1OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS\s0\fR" 4 -.IX Item "OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS" -Indicating that the domain parameters in a key object should be -considered. -.IP "\fB\s-1OSSL_KEYMGMT_SELECT_OTHER_PARAMETERS\s0\fR" 4 -.IX Item "OSSL_KEYMGMT_SELECT_OTHER_PARAMETERS" -Indicating that other parameters in a key object should be -considered. -.Sp -Other parameters are key parameters that don't fit any other -classification. In other words, this particular selector bit works as -a last resort bit bucket selector. -.PP -Some selector bits have also been combined for easier use: -.IP "\fB\s-1OSSL_KEYMGMT_SELECT_ALL_PARAMETERS\s0\fR" 4 -.IX Item "OSSL_KEYMGMT_SELECT_ALL_PARAMETERS" -Indicating that all key object parameters should be considered, -regardless of their more granular classification. -.Sp -This is a combination of \fB\s-1OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS\s0\fR and -\&\fB\s-1OSSL_KEYMGMT_SELECT_OTHER_PARAMETERS\s0\fR. -.IP "\fB\s-1OSSL_KEYMGMT_SELECT_KEYPAIR\s0\fR" 4 -.IX Item "OSSL_KEYMGMT_SELECT_KEYPAIR" -Indicating that both the whole key pair in a key object should be -considered, i.e. the combination of public and private key. -.Sp -This is a combination of \fB\s-1OSSL_KEYMGMT_SELECT_PRIVATE_KEY\s0\fR and -\&\fB\s-1OSSL_KEYMGMT_SELECT_PUBLIC_KEY\s0\fR. -.IP "\fB\s-1OSSL_KEYMGMT_SELECT_ALL\s0\fR" 4 -.IX Item "OSSL_KEYMGMT_SELECT_ALL" -Indicating that everything in a key object should be considered. -.PP -The exact interpretation of those bits or how they combine is left to -each function where you can specify a selector. -.PP -It's left to the provider implementation to decide what is reasonable -to do with regards to received selector bits and how to do it. -Among others, an implementation of \fBOSSL_FUNC_keymgmt_match()\fR might opt -to not compare the private half if it has compared the public half, -since a match of one half implies a match of the other half. -.SS "Constructing and Destructing Functions" -.IX Subsection "Constructing and Destructing Functions" -\&\fBOSSL_FUNC_keymgmt_new()\fR should create a provider side key object. The -provider context \fIprovctx\fR is passed and may be incorporated in the -key object, but that is not mandatory. -.PP -\&\fBOSSL_FUNC_keymgmt_free()\fR should free the passed \fIkeydata\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_init()\fR, \fBOSSL_FUNC_keymgmt_gen_set_template()\fR, -\&\fBOSSL_FUNC_keymgmt_gen_get_params()\fR, \fBOSSL_FUNC_keymgmt_gen_gettable_params()\fR, -\&\fBOSSL_FUNC_keymgmt_gen_set_params()\fR, \fBOSSL_FUNC_keymgmt_gen_settable_params()\fR, -\&\fBOSSL_FUNC_keymgmt_gen()\fR and \fBOSSL_FUNC_keymgmt_gen_cleanup()\fR work together as a -more elaborate context based key object constructor. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_init()\fR should create the key object generation context -and initialize it with \fIselections\fR, which will determine what kind -of contents the key object to be generated should get. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_keymgmt_set_params()\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_set_template()\fR should add \fItemplate\fR to the context -\&\fIgenctx\fR. The \fItemplate\fR is assumed to be a key object constructed -with the same \s-1KEYMGMT,\s0 and from which content that the implementation -chooses can be used as a template for the key object to be generated. -Typically, the generation of a \s-1DSA\s0 or \s-1DH\s0 key would get the domain -parameters from this \fItemplate\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_get_params()\fR should retrieve parameters into -\&\fIparams\fR in the key object generation context \fIgenctx\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_gettable_params()\fR should return a constant array of -descriptor \s-1\fBOSSL_PARAM\s0\fR\|(3), for parameters that -\&\fBOSSL_FUNC_keymgmt_gen_get_params()\fR can handle. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_set_params()\fR should set additional parameters from -\&\fIparams\fR in the key object generation context \fIgenctx\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_settable_params()\fR should return a constant array of -descriptor \s-1\fBOSSL_PARAM\s0\fR\|(3), for parameters that \fBOSSL_FUNC_keymgmt_gen_set_params()\fR -can handle. -.PP -\&\fBOSSL_FUNC_keymgmt_gen()\fR should perform the key object generation itself, and -return the result. The callback \fIcb\fR should be called at regular -intervals with indications on how the key object generation -progresses. -.PP -\&\fBOSSL_FUNC_keymgmt_gen_cleanup()\fR should clean up and free the key object -generation context \fIgenctx\fR -.PP -\&\fBOSSL_FUNC_keymgmt_load()\fR creates a provider side key object based on a -\&\fIreference\fR object with a size of \fIreference_sz\fR bytes, that only the -provider knows how to interpret, but that may come from other operations. -Outside the provider, this reference is simply an array of bytes. -.PP -At least one of \fBOSSL_FUNC_keymgmt_new()\fR, \fBOSSL_FUNC_keymgmt_gen()\fR and -\&\fBOSSL_FUNC_keymgmt_load()\fR are mandatory, as well as \fBOSSL_FUNC_keymgmt_free()\fR and -\&\fBOSSL_FUNC_keymgmt_has()\fR. Additionally, if \fBOSSL_FUNC_keymgmt_gen()\fR is present, -\&\fBOSSL_FUNC_keymgmt_gen_init()\fR and \fBOSSL_FUNC_keymgmt_gen_cleanup()\fR must be -present as well. -.SS "Key Object Information Functions" -.IX Subsection "Key Object Information Functions" -\&\fBOSSL_FUNC_keymgmt_get_params()\fR should extract information data associated -with the given \fIkeydata\fR, see \*(L"Common Information Parameters\*(R". -.PP -\&\fBOSSL_FUNC_keymgmt_gettable_params()\fR should return a constant array of -descriptor \s-1\fBOSSL_PARAM\s0\fR\|(3), for parameters that \fBOSSL_FUNC_keymgmt_get_params()\fR -can handle. -.PP -If \fBOSSL_FUNC_keymgmt_gettable_params()\fR is present, \fBOSSL_FUNC_keymgmt_get_params()\fR -must also be present, and vice versa. -.PP -\&\fBOSSL_FUNC_keymgmt_set_params()\fR should update information data associated -with the given \fIkeydata\fR, see \*(L"Common Information Parameters\*(R". -.PP -\&\fBOSSL_FUNC_keymgmt_settable_params()\fR should return a constant array of -descriptor \s-1\fBOSSL_PARAM\s0\fR\|(3), for parameters that \fBOSSL_FUNC_keymgmt_set_params()\fR -can handle. -.PP -If \fBOSSL_FUNC_keymgmt_settable_params()\fR is present, \fBOSSL_FUNC_keymgmt_set_params()\fR -must also be present, and vice versa. -.SS "Key Object Checking Functions" -.IX Subsection "Key Object Checking Functions" -\&\fBOSSL_FUNC_keymgmt_query_operation_name()\fR should return the name of the -supported algorithm for the operation \fIoperation_id\fR. This is -similar to \fBprovider_query_operation()\fR (see \fBprovider\-base\fR\|(7)), -but only works as an advisory. If this function is not present, or -returns \s-1NULL,\s0 the caller is free to assume that there's an algorithm -from the same provider, of the same name as the one used to fetch the -keymgmt and try to use that. -.PP -\&\fBOSSL_FUNC_keymgmt_has()\fR should check whether the given \fIkeydata\fR contains the subsets -of data indicated by the \fIselector\fR. A combination of several -selector bits must consider all those subsets, not just one. An -implementation is, however, free to consider an empty subset of data -to still be a valid subset. For algorithms where some selection is -not meaningful such as \fB\s-1OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS\s0\fR for -\&\s-1RSA\s0 keys the function should just return 1 as the selected subset -is not really missing in the key. -.PP -\&\fBOSSL_FUNC_keymgmt_validate()\fR should check if the \fIkeydata\fR contains valid -data subsets indicated by \fIselection\fR. Some combined selections of -data subsets may cause validation of the combined data. -For example, the combination of \fB\s-1OSSL_KEYMGMT_SELECT_PRIVATE_KEY\s0\fR and -\&\fB\s-1OSSL_KEYMGMT_SELECT_PUBLIC_KEY\s0\fR (or \fB\s-1OSSL_KEYMGMT_SELECT_KEYPAIR\s0\fR -for short) is expected to check that the pairwise consistency of -\&\fIkeydata\fR is valid. The \fIchecktype\fR parameter controls what type of check is -performed on the subset of data. Two types of check are defined: -\&\fB\s-1OSSL_KEYMGMT_VALIDATE_FULL_CHECK\s0\fR and \fB\s-1OSSL_KEYMGMT_VALIDATE_QUICK_CHECK\s0\fR. -The interpretation of how much checking is performed in a full check versus a -quick check is key type specific. Some providers may have no distinction -between a full check and a quick check. For algorithms where some selection is -not meaningful such as \fB\s-1OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS\s0\fR for -\&\s-1RSA\s0 keys the function should just return 1 as there is nothing to validate for -that selection. -.PP -\&\fBOSSL_FUNC_keymgmt_match()\fR should check if the data subset indicated by -\&\fIselection\fR in \fIkeydata1\fR and \fIkeydata2\fR match. It is assumed that -the caller has ensured that \fIkeydata1\fR and \fIkeydata2\fR are both owned -by the implementation of this function. -.SS "Key Object Import, Export and Duplication Functions" -.IX Subsection "Key Object Import, Export and Duplication Functions" -\&\fBOSSL_FUNC_keymgmt_import()\fR should import data indicated by \fIselection\fR into -\&\fIkeydata\fR with values taken from the \s-1\fBOSSL_PARAM\s0\fR\|(3) array \fIparams\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_export()\fR should extract values indicated by \fIselection\fR -from \fIkeydata\fR, create an \s-1\fBOSSL_PARAM\s0\fR\|(3) array with them and call -\&\fIparam_cb\fR with that array as well as the given \fIcbarg\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_import_types()\fR and \fBOSSL_FUNC_keymgmt_import_types_ex()\fR -should return a constant array of descriptor -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) for data indicated by \fIselection\fR, for parameters that -\&\fBOSSL_FUNC_keymgmt_import()\fR can handle. -Either \fBOSSL_FUNC_keymgmt_import_types()\fR or \fBOSSL_FUNC_keymgmt_import_types_ex()\fR, -must be implemented, if \fBOSSL_FUNC_keymgmt_import_types_ex()\fR is implemented, then -it is preferred over \fBOSSL_FUNC_keymgmt_import_types()\fR. -Providers that are supposed to be backward compatible with OpenSSL 3.0 or 3.1 -must continue to implement \fBOSSL_FUNC_keymgmt_import_types()\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_export_types()\fR and \fBOSSL_FUNC_keymgmt_export_types_ex()\fR -should return a constant array of descriptor -\&\s-1\fBOSSL_PARAM\s0\fR\|(3) for data indicated by \fIselection\fR, that the -\&\fBOSSL_FUNC_keymgmt_export()\fR callback can expect to receive. -Either \fBOSSL_FUNC_keymgmt_export_types()\fR or \fBOSSL_FUNC_keymgmt_export_types_ex()\fR, -must be implemented, if \fBOSSL_FUNC_keymgmt_export_types_ex()\fR is implemented, then -it is preferred over \fBOSSL_FUNC_keymgmt_export_types()\fR. -Providers that are supposed to be backward compatible with OpenSSL 3.0 or 3.1 -must continue to implement \fBOSSL_FUNC_keymgmt_export_types()\fR. -.PP -\&\fBOSSL_FUNC_keymgmt_dup()\fR should duplicate data subsets indicated by -\&\fIselection\fR or the whole key data \fIkeydata_from\fR and create a new -provider side key object with the data. -.SS "Common Information Parameters" -.IX Subsection "Common Information Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure. -.PP -Common information parameters currently recognised by all built-in -keymgmt algorithms are as follows: -.ie n .IP """bits"" (\fB\s-1OSSL_PKEY_PARAM_BITS\s0\fR) " 4 -.el .IP "``bits'' (\fB\s-1OSSL_PKEY_PARAM_BITS\s0\fR) " 4 -.IX Item "bits (OSSL_PKEY_PARAM_BITS) " -The value should be the cryptographic length of the cryptosystem to -which the key belongs, in bits. The definition of cryptographic -length is specific to the key cryptosystem. -.ie n .IP """max-size"" (\fB\s-1OSSL_PKEY_PARAM_MAX_SIZE\s0\fR) " 4 -.el .IP "``max-size'' (\fB\s-1OSSL_PKEY_PARAM_MAX_SIZE\s0\fR) " 4 -.IX Item "max-size (OSSL_PKEY_PARAM_MAX_SIZE) " -The value should be the maximum size that a caller should allocate to -safely store a signature (called \fIsig\fR in \fBprovider\-signature\fR\|(7)), -the result of asymmetric encryption / decryption (\fIout\fR in -\&\fBprovider\-asym_cipher\fR\|(7), a derived secret (\fIsecret\fR in -\&\fBprovider\-keyexch\fR\|(7), and similar data). -.Sp -Providers need to implement this parameter -in order to properly support various use cases such as \s-1CMS\s0 signing. -.Sp -Because an \s-1EVP_KEYMGMT\s0 method is always tightly bound to another method -(signature, asymmetric cipher, key exchange, ...) and must be of the -same provider, this number only needs to be synchronised with the -dimensions handled in the rest of the same provider. -.ie n .IP """security-bits"" (\fB\s-1OSSL_PKEY_PARAM_SECURITY_BITS\s0\fR) " 4 -.el .IP "``security-bits'' (\fB\s-1OSSL_PKEY_PARAM_SECURITY_BITS\s0\fR) " 4 -.IX Item "security-bits (OSSL_PKEY_PARAM_SECURITY_BITS) " -The value should be the number of security bits of the given key. -Bits of security is defined in \s-1SP800\-57.\s0 -.ie n .IP """mandatory-digest"" (\fB\s-1OSSL_PKEY_PARAM_MANDATORY_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mandatory-digest'' (\fB\s-1OSSL_PKEY_PARAM_MANDATORY_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mandatory-digest (OSSL_PKEY_PARAM_MANDATORY_DIGEST) " -If there is a mandatory digest for performing a signature operation with -keys from this keymgmt, this parameter should get its name as value. -.Sp -When \fBEVP_PKEY_get_default_digest_name()\fR queries this parameter and it's -filled in by the implementation, its return value will be 2. -.Sp -If the keymgmt implementation fills in the value \f(CW""\fR or \f(CW"UNDEF"\fR, -\&\fBEVP_PKEY_get_default_digest_name\fR\|(3) will place the string \f(CW"UNDEF"\fR into -its argument \fImdname\fR. This signifies that no digest should be specified -with the corresponding signature operation. -.ie n .IP """default-digest"" (\fB\s-1OSSL_PKEY_PARAM_DEFAULT_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``default-digest'' (\fB\s-1OSSL_PKEY_PARAM_DEFAULT_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "default-digest (OSSL_PKEY_PARAM_DEFAULT_DIGEST) " -If there is a default digest for performing a signature operation with -keys from this keymgmt, this parameter should get its name as value. -.Sp -When \fBEVP_PKEY_get_default_digest_name\fR\|(3) queries this parameter and it's -filled in by the implementation, its return value will be 1. Note that if -\&\fB\s-1OSSL_PKEY_PARAM_MANDATORY_DIGEST\s0\fR is responded to as well, -\&\fBEVP_PKEY_get_default_digest_name\fR\|(3) ignores the response to this -parameter. -.Sp -If the keymgmt implementation fills in the value \f(CW""\fR or \f(CW"UNDEF"\fR, -\&\fBEVP_PKEY_get_default_digest_name\fR\|(3) will place the string \f(CW"UNDEF"\fR into -its argument \fImdname\fR. This signifies that no digest has to be specified -with the corresponding signature operation, but may be specified as an -option. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_PKEY_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling \fBOSSL_FUNC_keymgmt_gen()\fR function. It may -return 0 if either the \*(L"key-check\*(R", or \*(L"sign-check\*(R" are set to 0. -.ie n .IP """key-check"" (\fB\s-1OSSL_PKEY_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_PKEY_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_PKEY_PARAM_FIPS_KEY_CHECK) " -If required this parameter should be set using \fBOSSL_FUNC_keymgmt_gen_set_params()\fR -or \fBOSSL_FUNC_keymgmt_gen_init()\fR. -The default value of 1 causes an error during the init if the key is not \s-1FIPS\s0 -approved (e.g. The key has a security strength of less than 112 bits). Setting -this to 0 will ignore the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.ie n .IP """sign-check"" (\fB\s-1OSSL_PKEY_PARAM_FIPS_SIGN_CHECK\s0\fR) " 4 -.el .IP "``sign-check'' (\fB\s-1OSSL_PKEY_PARAM_FIPS_SIGN_CHECK\s0\fR) " 4 -.IX Item "sign-check (OSSL_PKEY_PARAM_FIPS_SIGN_CHECK) " -If required this parameter should be set before the \fBOSSL_FUNC_keymgmt_gen()\fR -function. This value is not supported by all keygen algorithms. -The default value of 1 will cause an error if the generated key is not -allowed to be used for signing. -Setting this to 0 will ignore the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_keymgmt_new()\fR and \fBOSSL_FUNC_keymgmt_dup()\fR should return a valid -reference to the newly created provider side key object, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_keymgmt_import()\fR, \fBOSSL_FUNC_keymgmt_export()\fR, \fBOSSL_FUNC_keymgmt_get_params()\fR and -\&\fBOSSL_FUNC_keymgmt_set_params()\fR should return 1 for success or 0 on error. -.PP -\&\fBOSSL_FUNC_keymgmt_validate()\fR should return 1 on successful validation, or 0 on -failure. -.PP -\&\fBOSSL_FUNC_keymgmt_has()\fR should return 1 if all the selected data subsets are contained -in the given \fIkeydata\fR or 0 otherwise. -.PP -\&\fBOSSL_FUNC_keymgmt_query_operation_name()\fR should return a pointer to a string matching -the requested operation, or \s-1NULL\s0 if the same name used to fetch the keymgmt -applies. -.PP -\&\fBOSSL_FUNC_keymgmt_gettable_params()\fR and \fBOSSL_FUNC_keymgmt_settable_params()\fR -\&\fBOSSL_FUNC_keymgmt_import_types()\fR, \fBOSSL_FUNC_keymgmt_import_types_ex()\fR, -\&\fBOSSL_FUNC_keymgmt_export_types()\fR, \fBOSSL_FUNC_keymgmt_export_types_ex()\fR -should -always return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_PKEY_get_size\fR\|(3), -\&\fBEVP_PKEY_get_bits\fR\|(3), -\&\fBEVP_PKEY_get_security_bits\fR\|(3), -\&\fBprovider\fR\|(7), -\&\s-1\fBEVP_PKEY\-X25519\s0\fR\|(7), \s-1\fBEVP_PKEY\-X448\s0\fR\|(7), \s-1\fBEVP_PKEY\-ED25519\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-ED448\s0\fR\|(7), \s-1\fBEVP_PKEY\-EC\s0\fR\|(7), \s-1\fBEVP_PKEY\-RSA\s0\fR\|(7), -\&\s-1\fBEVP_PKEY\-DSA\s0\fR\|(7), \s-1\fBEVP_PKEY\-DH\s0\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1KEYMGMT\s0 interface was introduced in OpenSSL 3.0. -.PP -Functions \fBOSSL_FUNC_keymgmt_import_types_ex()\fR, and \fBOSSL_FUNC_keymgmt_export_types_ex()\fR -were added with OpenSSL 3.2. -.PP -The functions \fBOSSL_FUNC_keymgmt_gen_get_params()\fR and -\&\fBOSSL_FUNC_keymgmt_gen_gettable_params()\fR were added in OpenSSL 3.4. -.PP -The parameters \*(L"sign-check\*(R" and \*(L"fips-indicator\*(R" were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-mac.7ossl b/openssl-install/share/man/man7/provider-mac.7ossl deleted file mode 100644 index 5b6c6710..00000000 --- a/openssl-install/share/man/man7/provider-mac.7ossl +++ /dev/null @@ -1,390 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-MAC 7ossl" -.TH PROVIDER-MAC 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-mac \- The mac library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_mac_newctx(void *provctx); -\& void OSSL_FUNC_mac_freectx(void *mctx); -\& void *OSSL_FUNC_mac_dupctx(void *src); -\& -\& /* Encryption/decryption */ -\& int OSSL_FUNC_mac_init(void *mctx, unsigned char *key, size_t keylen, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_mac_update(void *mctx, const unsigned char *in, size_t inl); -\& int OSSL_FUNC_mac_final(void *mctx, unsigned char *out, size_t *outl, size_t outsize); -\& -\& /* MAC parameter descriptors */ -\& const OSSL_PARAM *OSSL_FUNC_mac_gettable_params(void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_mac_gettable_ctx_params(void *mctx, void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_mac_settable_ctx_params(void *mctx, void *provctx); -\& -\& /* MAC parameters */ -\& int OSSL_FUNC_mac_get_params(OSSL_PARAM params[]); -\& int OSSL_FUNC_mac_get_ctx_params(void *mctx, OSSL_PARAM params[]); -\& int OSSL_FUNC_mac_set_ctx_params(void *mctx, const OSSL_PARAM params[]); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The \s-1MAC\s0 operation enables providers to implement mac algorithms and make -them available to applications via the \s-1API\s0 functions \fBEVP_MAC_init\fR\|(3), -\&\fBEVP_MAC_update\fR\|(3) and \fBEVP_MAC_final\fR\|(3). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_mac_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_mac_newctx_fn)(void *provctx); -\& static ossl_inline OSSL_FUNC_mac_newctx_fn -\& OSSL_FUNC_mac_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_mac_newctx OSSL_FUNC_MAC_NEWCTX -\& OSSL_FUNC_mac_freectx OSSL_FUNC_MAC_FREECTX -\& OSSL_FUNC_mac_dupctx OSSL_FUNC_MAC_DUPCTX -\& -\& OSSL_FUNC_mac_init OSSL_FUNC_MAC_INIT -\& OSSL_FUNC_mac_update OSSL_FUNC_MAC_UPDATE -\& OSSL_FUNC_mac_final OSSL_FUNC_MAC_FINAL -\& -\& OSSL_FUNC_mac_get_params OSSL_FUNC_MAC_GET_PARAMS -\& OSSL_FUNC_mac_get_ctx_params OSSL_FUNC_MAC_GET_CTX_PARAMS -\& OSSL_FUNC_mac_set_ctx_params OSSL_FUNC_MAC_SET_CTX_PARAMS -\& -\& OSSL_FUNC_mac_gettable_params OSSL_FUNC_MAC_GETTABLE_PARAMS -\& OSSL_FUNC_mac_gettable_ctx_params OSSL_FUNC_MAC_GETTABLE_CTX_PARAMS -\& OSSL_FUNC_mac_settable_ctx_params OSSL_FUNC_MAC_SETTABLE_CTX_PARAMS -.Ve -.PP -A mac algorithm implementation may not implement all of these functions. -In order to be a consistent set of functions, at least the following functions -must be implemented: \fBOSSL_FUNC_mac_newctx()\fR, \fBOSSL_FUNC_mac_freectx()\fR, \fBOSSL_FUNC_mac_init()\fR, -\&\fBOSSL_FUNC_mac_update()\fR, \fBOSSL_FUNC_mac_final()\fR. -All other functions are optional. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_mac_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during a mac operation. -A pointer to this context will be passed back in a number of the other mac -operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -.PP -\&\fBOSSL_FUNC_mac_freectx()\fR is passed a pointer to the provider side mac context in -the \fImctx\fR parameter. -If it receives \s-1NULL\s0 as \fImctx\fR value, it should not do anything other than -return. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_mac_dupctx()\fR should duplicate the provider side mac context in the -\&\fImctx\fR parameter and return the duplicate copy. -.SS "Encryption/Decryption Functions" -.IX Subsection "Encryption/Decryption Functions" -\&\fBOSSL_FUNC_mac_init()\fR initialises a mac operation given a newly created provider -side mac context in the \fImctx\fR parameter. The \fIparams\fR are set before setting -the \s-1MAC\s0 \fIkey\fR of \fIkeylen\fR bytes. -.PP -\&\fBOSSL_FUNC_mac_update()\fR is called to supply data for \s-1MAC\s0 computation of a previously -initialised mac operation. -The \fImctx\fR parameter contains a pointer to a previously initialised provider -side context. -\&\fBOSSL_FUNC_mac_update()\fR may be called multiple times for a single mac operation. -.PP -\&\fBOSSL_FUNC_mac_final()\fR completes the \s-1MAC\s0 computation started through previous -\&\fBOSSL_FUNC_mac_init()\fR and \fBOSSL_FUNC_mac_update()\fR calls. -The \fImctx\fR parameter contains a pointer to the provider side context. -The resulting \s-1MAC\s0 should be written to \fIout\fR and the amount of data written -to \fI*outl\fR, which should not exceed \fIoutsize\fR bytes. -The same expectations apply to \fIoutsize\fR as documented for -\&\fBEVP_MAC_final\fR\|(3). -.SS "Mac Parameters" -.IX Subsection "Mac Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -these functions. -.PP -\&\fBOSSL_FUNC_mac_get_params()\fR gets details of parameter values associated with the -provider algorithm and stores them in \fIparams\fR. -.PP -\&\fBOSSL_FUNC_mac_set_ctx_params()\fR sets mac parameters associated with the given -provider side mac context \fImctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_mac_get_ctx_params()\fR gets details of currently set parameter values -associated with the given provider side mac context \fImctx\fR and stores them -in \fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_mac_gettable_params()\fR, \fBOSSL_FUNC_mac_gettable_ctx_params()\fR, -and \fBOSSL_FUNC_mac_settable_ctx_params()\fR all return constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -arrays as descriptors of the parameters that \fBOSSL_FUNC_mac_get_params()\fR, -\&\fBOSSL_FUNC_mac_get_ctx_params()\fR, and \fBOSSL_FUNC_mac_set_ctx_params()\fR -can handle, respectively. \fBOSSL_FUNC_mac_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_mac_settable_ctx_params()\fR will return the parameters associated -with the provider side context \fImctx\fR in its current state if it is -not \s-1NULL.\s0 Otherwise, they return the parameters associated with the -provider side algorithm \fIprovctx\fR. -.PP -All \s-1MAC\s0 implementations are expected to handle the following parameters: -.IP "with \fBOSSL_FUNC_set_ctx_params()\fR:" 4 -.IX Item "with OSSL_FUNC_set_ctx_params():" -.RS 4 -.PD 0 -.ie n .IP """key"" (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.el .IP "``key'' (\fB\s-1OSSL_MAC_PARAM_KEY\s0\fR) " 4 -.IX Item "key (OSSL_MAC_PARAM_KEY) " -.PD -Sets the key in the associated \s-1MAC\s0 ctx. This is identical to passing a \fIkey\fR -argument to the \fBOSSL_FUNC_mac_init()\fR function. -.RE -.RS 4 -.RE -.IP "with \fBOSSL_FUNC_get_params()\fR:" 4 -.IX Item "with OSSL_FUNC_get_params():" -.RS 4 -.PD 0 -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_SIZE) " -.PD -Can be used to get the default \s-1MAC\s0 size (which might be the only allowable -\&\s-1MAC\s0 size for the implementation). -.Sp -Note that some implementations allow setting the size that the resulting \s-1MAC\s0 -should have as well, see the documentation of the implementation. -.RE -.RS 4 -.ie n .IP """size"" (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.el .IP "``size'' (\fB\s-1OSSL_MAC_PARAM_BLOCK_SIZE\s0\fR) " 4 -.IX Item "size (OSSL_MAC_PARAM_BLOCK_SIZE) " -Can be used to get the \s-1MAC\s0 block size (if supported by the algorithm). -.RE -.RS 4 -.RE -.PP -The OpenSSL \s-1FIPS\s0 provider may support the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_MAC_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling the final function. It may return 0 if -either \*(L"no-short-mac\*(R" or \*(L"key-check\*(R" are set to 0. -.ie n .IP """no-short-mac"" (\fB\s-1OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC\s0\fR) " 4 -.el .IP "``no-short-mac'' (\fB\s-1OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC\s0\fR) " 4 -.IX Item "no-short-mac (OSSL_MAC_PARAM_FIPS_NO_SHORT_MAC) " -If required this parameter should be set early via an init function. -The default value of 1 causes an error when too short \s-1MAC\s0 output is -asked for. Setting this to 0 will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.ie n .IP """key-check"" (\fB\s-1OSSL_MAC_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_MAC_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_MAC_PARAM_FIPS_KEY_CHECK) " -If required this parameter should be set before OSSL_FUNC_mac_init. -The default value of 1 causes an error when small key sizes are -asked for. Setting this to 0 will ignore the error and set the approved -\&\*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "NOTES" -.IX Header "NOTES" -The \s-1MAC\s0 life-cycle is described in \fBlife_cycle\-rand\fR\|(7). Providers should -ensure that the various transitions listed there are supported. At some point -the \s-1EVP\s0 layer will begin enforcing the listed transitions. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_mac_newctx()\fR and \fBOSSL_FUNC_mac_dupctx()\fR should return the newly created -provider side mac context, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_mac_init()\fR, \fBOSSL_FUNC_mac_update()\fR, \fBOSSL_FUNC_mac_final()\fR, \fBOSSL_FUNC_mac_get_params()\fR, -\&\fBOSSL_FUNC_mac_get_ctx_params()\fR and \fBOSSL_FUNC_mac_set_ctx_params()\fR should return 1 for -success or 0 on error. -.PP -\&\fBOSSL_FUNC_mac_gettable_params()\fR, \fBOSSL_FUNC_mac_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_mac_settable_ctx_params()\fR should return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -array, or \s-1NULL\s0 if none is offered. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), -\&\s-1\fBEVP_MAC\-BLAKE2\s0\fR\|(7), \s-1\fBEVP_MAC\-CMAC\s0\fR\|(7), \s-1\fBEVP_MAC\-GMAC\s0\fR\|(7), -\&\s-1\fBEVP_MAC\-HMAC\s0\fR\|(7), \s-1\fBEVP_MAC\-KMAC\s0\fR\|(7), \fBEVP_MAC\-Poly1305\fR\|(7), -\&\fBEVP_MAC\-Siphash\fR\|(7), -\&\fBlife_cycle\-mac\fR\|(7), \s-1\fBEVP_MAC\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1MAC\s0 interface was introduced in OpenSSL 3.0. -The parameters \*(L"no-short-mac\*(R" and \*(L"fips-indicator\*(R" were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-object.7ossl b/openssl-install/share/man/man7/provider-object.7ossl deleted file mode 100644 index df63f919..00000000 --- a/openssl-install/share/man/man7/provider-object.7ossl +++ /dev/null @@ -1,292 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-OBJECT 7ossl" -.TH PROVIDER-OBJECT 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-object \- A specification for a provider\-native object abstraction -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The provider-native object abstraction is a set of \s-1\fBOSSL_PARAM\s0\fR\|(3) keys and -values that can be used to pass provider-native objects to OpenSSL library -code or between different provider operation implementations with the help -of OpenSSL library code. -.PP -The intention is that certain provider-native operations can pass any sort -of object that belong with other operations, or with OpenSSL library code. -.PP -An object may be passed in the following manners: -.IP "1." 4 -\&\fIBy value\fR -.Sp -This means that the \fIobject data\fR is passed as an octet string or an \s-1UTF8\s0 -string, which can be handled in diverse ways by other provided implementations. -The encoding of the object depends on the context it's used in; for example, -\&\s-1\fBOSSL_DECODER\s0\fR\|(3) allows multiple encodings, depending on existing decoders. -If central OpenSSL library functionality is to handle the data directly, it -\&\fBmust\fR be encoded in \s-1DER\s0 for all object types except for \fB\s-1OSSL_OBJECT_NAME\s0\fR -(see \*(L"Parameter reference\*(R" below), where it's assumed to a plain \s-1UTF8\s0 string. -.IP "2." 4 -\&\fIBy reference\fR -.Sp -This means that the \fIobject data\fR isn't passed directly, an \fIobject -reference\fR is passed instead. It's an octet string that only the correct -provider understands correctly. -.PP -Objects \fIby value\fR can be used by anything that handles \s-1DER\s0 encoded -objects. -.PP -Objects \fIby reference\fR need a higher level of cooperation from the -implementation where the object originated (let's call it X) and its target -implementation (let's call it Y): -.IP "1." 4 -\&\fIAn object loading function in the target implementation\fR -.Sp -The target implementation (Y) may have a function that can take an \fIobject -reference\fR. This can only be used if the target implementation is from the -same provider as the one originating the object abstraction in question (X). -.Sp -The exact target implementation to use is determined from the \fIobject type\fR -and possibly the \fIobject data type\fR. -For example, when the OpenSSL library receives an object abstraction with the -\&\fIobject type\fR \fB\s-1OSSL_OBJECT_PKEY\s0\fR, it will fetch a \fBprovider\-keymgmt\fR\|(7) -using the \fIobject data type\fR as its key type (the second argument in -\&\fBEVP_KEYMGMT_fetch\fR\|(3)). -.IP "2." 4 -\&\fIAn object exporter in the originating implementation\fR -.Sp -The originating implementation (X) may have an exporter function. This -exporter function can be used to export the object in \s-1\fBOSSL_PARAM\s0\fR\|(3) form, -that can then be imported by the target implementation's imported function. -.Sp -This can be used when it's not possible to fetch the target implementation -(Y) from the same provider. -.SS "Parameter reference" -.IX Subsection "Parameter reference" -A provider-native object abstraction is an \s-1\fBOSSL_PARAM\s0\fR\|(3) with a selection -of the following parameters: -.ie n .IP """data"" (\fB\s-1OSSL_OBJECT_PARAM_DATA\s0\fR) or <\s-1UTF8\s0 string>" 4 -.el .IP "``data'' (\fB\s-1OSSL_OBJECT_PARAM_DATA\s0\fR) or <\s-1UTF8\s0 string>" 4 -.IX Item "data (OSSL_OBJECT_PARAM_DATA) or " -The object data \fIpassed by value\fR. -.ie n .IP """reference"" (\fB\s-1OSSL_OBJECT_PARAM_REFERENCE\s0\fR) " 4 -.el .IP "``reference'' (\fB\s-1OSSL_OBJECT_PARAM_REFERENCE\s0\fR) " 4 -.IX Item "reference (OSSL_OBJECT_PARAM_REFERENCE) " -The object data \fIpassed by reference\fR. -.ie n .IP """type"" (\fB\s-1OSSL_OBJECT_PARAM_TYPE\s0\fR) " 4 -.el .IP "``type'' (\fB\s-1OSSL_OBJECT_PARAM_TYPE\s0\fR) " 4 -.IX Item "type (OSSL_OBJECT_PARAM_TYPE) " -The \fIobject type\fR, a number that may have any of the following values (all -defined in \fI\fR): -.RS 4 -.IP "\fB\s-1OSSL_OBJECT_NAME\s0\fR" 4 -.IX Item "OSSL_OBJECT_NAME" -The object data may only be \fIpassed by value\fR, and should be a \s-1UTF8\s0 -string. -.Sp -This is useful for \fBprovider\-storemgmt\fR\|(7) when a \s-1URI\s0 load results in new -URIs. -.IP "\fB\s-1OSSL_OBJECT_PKEY\s0\fR" 4 -.IX Item "OSSL_OBJECT_PKEY" -The object data is suitable as provider-native \fB\s-1EVP_PKEY\s0\fR key data. The -object data may be \fIpassed by value\fR or \fIpassed by reference\fR. -.IP "\fB\s-1OSSL_OBJECT_CERT\s0\fR" 4 -.IX Item "OSSL_OBJECT_CERT" -The object data is suitable as \fBX509\fR data. The object data for this -object type can only be \fIpassed by value\fR, and should be an octet string. -.Sp -Since there's no provider-native X.509 object, OpenSSL libraries that -receive this object abstraction are expected to convert the data to a -\&\fBX509\fR object with \fBd2i_X509()\fR. -.IP "\fB\s-1OSSL_OBJECT_CRL\s0\fR" 4 -.IX Item "OSSL_OBJECT_CRL" -The object data is suitable as \fBX509_CRL\fR data. The object data can -only be \fIpassed by value\fR, and should be an octet string. -.Sp -Since there's no provider-native X.509 \s-1CRL\s0 object, OpenSSL libraries that -receive this object abstraction are expected to convert the data to a -\&\fBX509_CRL\fR object with \fBd2i_X509_CRL()\fR. -.RE -.RS 4 -.RE -.ie n .IP """data-type"" (\fB\s-1OSSL_OBJECT_PARAM_DATA_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``data-type'' (\fB\s-1OSSL_OBJECT_PARAM_DATA_TYPE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "data-type (OSSL_OBJECT_PARAM_DATA_TYPE) " -The specific type of the object content. Legitimate values depend on the -object type; if it is \fB\s-1OSSL_OBJECT_PKEY\s0\fR, the data type is expected to be a -key type suitable for fetching a \fBprovider\-keymgmt\fR\|(7) that can handle the -data. -.ie n .IP """data-structure"" (\fB\s-1OSSL_OBJECT_PARAM_DATA_STRUCTURE\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``data-structure'' (\fB\s-1OSSL_OBJECT_PARAM_DATA_STRUCTURE\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "data-structure (OSSL_OBJECT_PARAM_DATA_STRUCTURE) " -The outermost structure of the object content. Legitimate values depend on -the object type. -.ie n .IP """desc"" (\fB\s-1OSSL_OBJECT_PARAM_DESC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``desc'' (\fB\s-1OSSL_OBJECT_PARAM_DESC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "desc (OSSL_OBJECT_PARAM_DESC) " -A human readable text that describes extra details on the object. -.PP -When a provider-native object abstraction is used, it \fImust\fR contain object -data in at least one form (object data \fIpassed by value\fR, i.e. the \*(L"data\*(R" -item, or object data \fIpassed by reference\fR, i.e. the \*(L"reference\*(R" item). -Both may be present at once, in which case the OpenSSL library code that -receives this will use the most optimal variant. -.PP -For objects with the object type \fB\s-1OSSL_OBJECT_NAME\s0\fR, that object type -\&\fImust\fR be given. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), \s-1\fBOSSL_DECODER\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The concept of providers and everything surrounding them was -introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2022 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-rand.7ossl b/openssl-install/share/man/man7/provider-rand.7ossl deleted file mode 100644 index 9f78b49b..00000000 --- a/openssl-install/share/man/man7/provider-rand.7ossl +++ /dev/null @@ -1,454 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-RAND 7ossl" -.TH PROVIDER-RAND 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-rand \- The random number generation library <\-> provider -functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_rand_newctx(void *provctx, void *parent, -\& const OSSL_DISPATCH *parent_calls); -\& void OSSL_FUNC_rand_freectx(void *ctx); -\& -\& /* Random number generator functions: NIST */ -\& int OSSL_FUNC_rand_instantiate(void *ctx, unsigned int strength, -\& int prediction_resistance, -\& const unsigned char *pstr, size_t pstr_len, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_rand_uninstantiate(void *ctx); -\& int OSSL_FUNC_rand_generate(void *ctx, unsigned char *out, size_t outlen, -\& unsigned int strength, int prediction_resistance, -\& const unsigned char *addin, size_t addin_len); -\& int OSSL_FUNC_rand_reseed(void *ctx, int prediction_resistance, -\& const unsigned char *ent, size_t ent_len, -\& const unsigned char *addin, size_t addin_len); -\& -\& /* Random number generator functions: additional */ -\& size_t OSSL_FUNC_rand_nonce(void *ctx, unsigned char *out, size_t outlen, -\& int strength, size_t min_noncelen, -\& size_t max_noncelen); -\& size_t OSSL_FUNC_rand_get_seed(void *ctx, unsigned char **buffer, -\& int entropy, size_t min_len, size_t max_len, -\& int prediction_resistance, -\& const unsigned char *adin, size_t adin_len); -\& void OSSL_FUNC_rand_clear_seed(void *ctx, unsigned char *buffer, size_t b_len); -\& int OSSL_FUNC_rand_verify_zeroization(void *ctx); -\& -\& /* Context Locking */ -\& int OSSL_FUNC_rand_enable_locking(void *ctx); -\& int OSSL_FUNC_rand_lock(void *ctx); -\& void OSSL_FUNC_rand_unlock(void *ctx); -\& -\& /* RAND parameter descriptors */ -\& const OSSL_PARAM *OSSL_FUNC_rand_gettable_params(void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_rand_gettable_ctx_params(void *ctx, void *provctx); -\& const OSSL_PARAM *OSSL_FUNC_rand_settable_ctx_params(void *ctx, void *provctx); -\& -\& /* RAND parameters */ -\& int OSSL_FUNC_rand_get_params(OSSL_PARAM params[]); -\& int OSSL_FUNC_rand_get_ctx_params(void *ctx, OSSL_PARAM params[]); -\& int OSSL_FUNC_rand_set_ctx_params(void *ctx, const OSSL_PARAM params[]); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The \s-1RAND\s0 operation enables providers to implement random number generation -algorithms and random number sources and make -them available to applications via the \s-1API\s0 function \s-1\fBEVP_RAND\s0\fR\|(3). -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_rand_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during a rand operation. -A pointer to this context will be passed back in a number of the other rand -operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). -The parameter \fIparent\fR specifies another rand instance to be used for -seeding purposes. If \s-1NULL\s0 and the specific instance supports it, the -operating system will be used for seeding. -The parameter \fIparent_calls\fR points to the dispatch table for \fIparent\fR. -Thus, the parent need not be from the same provider as the new instance. -.PP -\&\fBOSSL_FUNC_rand_freectx()\fR is passed a pointer to the provider side rand context in -the \fImctx\fR parameter. -If it receives \s-1NULL\s0 as \fIctx\fR value, it should not do anything other than -return. -This function should free any resources associated with that context. -.SS "Random Number Generator Functions: \s-1NIST\s0" -.IX Subsection "Random Number Generator Functions: NIST" -These functions correspond to those defined in \s-1NIST SP 800\-90A\s0 and \s-1SP 800\-90C.\s0 -.PP -\&\fBOSSL_FUNC_rand_instantiate()\fR is used to instantiate the \s-1DRBG\s0 \fIctx\fR at a requested -security \fIstrength\fR. In addition, \fIprediction_resistance\fR can be requested. -Additional input \fIaddin\fR of length \fIaddin_len\fR bytes can optionally -be provided. The parameters specified in \fIparams\fR configure the \s-1DRBG\s0 and these -should be processed before instantiation. -.PP -\&\fBOSSL_FUNC_rand_uninstantiate()\fR is used to uninstantiate the \s-1DRBG\s0 \fIctx\fR. After being -uninstantiated, a \s-1DRBG\s0 is unable to produce output until it is instantiated -anew. -.PP -\&\fBOSSL_FUNC_rand_generate()\fR is used to generate random bytes from the \s-1DRBG\s0 \fIctx\fR. -It will generate \fIoutlen\fR bytes placing them into the buffer pointed to by -\&\fIout\fR. The generated bytes will meet the specified security \fIstrength\fR and, -if \fIprediction_resistance\fR is true, the bytes will be produced after reseeding -from a live entropy source. Additional input \fIaddin\fR of length \fIaddin_len\fR -bytes can optionally be provided. -.SS "Random Number Generator Functions: Additional" -.IX Subsection "Random Number Generator Functions: Additional" -\&\fBOSSL_FUNC_rand_nonce()\fR is used to generate a nonce of the given \fIstrength\fR with a -length from \fImin_noncelen\fR to \fImax_noncelen\fR. If the output buffer \fIout\fR is -\&\s-1NULL,\s0 the length of the nonce should be returned. -.PP -\&\fBOSSL_FUNC_rand_get_seed()\fR is used by deterministic generators to obtain their -seeding material from their parent. The seed bytes will meet the specified -security level of \fIentropy\fR bits and there will be between \fImin_len\fR -and \fImax_len\fR inclusive bytes in total. If \fIprediction_resistance\fR is -true, the bytes will be produced from a live entropy source. Additional -input \fIaddin\fR of length \fIaddin_len\fR bytes can optionally be provided. -A pointer to the seed material is returned in \fI*buffer\fR and this must be -freed by a later call to \fBOSSL_FUNC_rand_clear_seed()\fR. -.PP -\&\fBOSSL_FUNC_rand_clear_seed()\fR frees a seed \fIbuffer\fR of length \fIb_len\fR bytes -which was previously allocated by \fBOSSL_FUNC_rand_get_seed()\fR. -.PP -\&\fBOSSL_FUNC_rand_verify_zeroization()\fR is used to determine if the internal state of the -\&\s-1DRBG\s0 is zero. This capability is mandated by \s-1NIST\s0 as part of the self -tests, it is unlikely to be useful in other circumstances. -.SS "Context Locking" -.IX Subsection "Context Locking" -When DRBGs are used by multiple threads, there must be locking employed to -ensure their proper operation. Because locking introduces an overhead, it -is disabled by default. -.PP -\&\fBOSSL_FUNC_rand_enable_locking()\fR allows locking to be turned on for a \s-1DRBG\s0 and all of -its parent DRBGs. From this call onwards, the \s-1DRBG\s0 can be used in a thread -safe manner. -.PP -\&\fBOSSL_FUNC_rand_lock()\fR is used to lock a \s-1DRBG.\s0 Once locked, exclusive access -is guaranteed. -.PP -\&\fBOSSL_FUNC_rand_unlock()\fR is used to unlock a \s-1DRBG.\s0 -.SS "Rand Parameters" -.IX Subsection "Rand Parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -these functions. -.PP -\&\fBOSSL_FUNC_rand_get_params()\fR gets details of parameter values associated with the -provider algorithm and stores them in \fIparams\fR. -.PP -\&\fBOSSL_FUNC_rand_set_ctx_params()\fR sets rand parameters associated with the given -provider side rand context \fIctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_rand_get_ctx_params()\fR gets details of currently set parameter values -associated with the given provider side rand context \fIctx\fR and stores them -in \fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_rand_gettable_params()\fR, \fBOSSL_FUNC_rand_gettable_ctx_params()\fR, -and \fBOSSL_FUNC_rand_settable_ctx_params()\fR all return constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -arrays as descriptors of the parameters that \fBOSSL_FUNC_rand_get_params()\fR, -\&\fBOSSL_FUNC_rand_get_ctx_params()\fR, and \fBOSSL_FUNC_rand_set_ctx_params()\fR -can handle, respectively. \fBOSSL_FUNC_rand_gettable_ctx_params()\fR -and \fBOSSL_FUNC_rand_settable_ctx_params()\fR will return the parameters -associated with the provider side context \fIctx\fR in its current state -if it is not \s-1NULL.\s0 Otherwise, they return the parameters associated -with the provider side algorithm \fIprovctx\fR. -.PP -Parameters currently recognised by built-in rands are as follows. Not all -parameters are relevant to, or are understood by all rands: -.ie n .IP """state"" (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.el .IP "``state'' (\fB\s-1OSSL_RAND_PARAM_STATE\s0\fR) " 4 -.IX Item "state (OSSL_RAND_PARAM_STATE) " -Returns the state of the random number generator. -.ie n .IP """strength"" (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.el .IP "``strength'' (\fB\s-1OSSL_RAND_PARAM_STRENGTH\s0\fR) " 4 -.IX Item "strength (OSSL_RAND_PARAM_STRENGTH) " -Returns the bit strength of the random number generator. -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_RAND_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This option is used by the OpenSSL \s-1FIPS\s0 provider and is not supported -by all \s-1EVP_RAND\s0 sources. -.PP -For rands that are also deterministic random bit generators (DRBGs), these -additional parameters are recognised. Not all -parameters are relevant to, or are understood by all \s-1DRBG\s0 rands: -.ie n .IP """reseed_requests"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``reseed_requests'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "reseed_requests (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -Reads or set the number of generate requests before reseeding the -associated \s-1RAND\s0 ctx. -.ie n .IP """reseed_time_interval"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.el .IP "``reseed_time_interval'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL\s0\fR) " 4 -.IX Item "reseed_time_interval (OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL) " -Reads or set the number of elapsed seconds before reseeding the -associated \s-1RAND\s0 ctx. -.ie n .IP """max_request"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.el .IP "``max_request'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_REQUESTS\s0\fR) " 4 -.IX Item "max_request (OSSL_DRBG_PARAM_RESEED_REQUESTS) " -Specifies the maximum number of bytes that can be generated in a single -call to OSSL_FUNC_rand_generate. -.ie n .IP """min_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.el .IP "``min_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_ENTROPYLEN\s0\fR) " 4 -.IX Item "min_entropylen (OSSL_DRBG_PARAM_MIN_ENTROPYLEN) " -.PD 0 -.ie n .IP """max_entropylen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.el .IP "``max_entropylen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ENTROPYLEN\s0\fR) " 4 -.IX Item "max_entropylen (OSSL_DRBG_PARAM_MAX_ENTROPYLEN) " -.PD -Specify the minimum and maximum number of bytes of random material that -can be used to seed the \s-1DRBG.\s0 -.ie n .IP """min_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.el .IP "``min_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MIN_NONCELEN\s0\fR) " 4 -.IX Item "min_noncelen (OSSL_DRBG_PARAM_MIN_NONCELEN) " -.PD 0 -.ie n .IP """max_noncelen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.el .IP "``max_noncelen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_NONCELEN\s0\fR) " 4 -.IX Item "max_noncelen (OSSL_DRBG_PARAM_MAX_NONCELEN) " -.PD -Specify the minimum and maximum number of bytes of nonce that can be used to -instantiate the \s-1DRBG.\s0 -.ie n .IP """max_perslen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.el .IP "``max_perslen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_PERSLEN\s0\fR) " 4 -.IX Item "max_perslen (OSSL_DRBG_PARAM_MAX_PERSLEN) " -.PD 0 -.ie n .IP """max_adinlen"" (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.el .IP "``max_adinlen'' (\fB\s-1OSSL_DRBG_PARAM_MAX_ADINLEN\s0\fR) " 4 -.IX Item "max_adinlen (OSSL_DRBG_PARAM_MAX_ADINLEN) " -.PD -Specify the minimum and maximum number of bytes of personalisation string -that can be used with the \s-1DRBG.\s0 -.ie n .IP """reseed_counter"" (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.el .IP "``reseed_counter'' (\fB\s-1OSSL_DRBG_PARAM_RESEED_COUNTER\s0\fR) " 4 -.IX Item "reseed_counter (OSSL_DRBG_PARAM_RESEED_COUNTER) " -Specifies the number of times the \s-1DRBG\s0 has been seeded or reseeded. -.ie n .IP """digest"" (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_DRBG_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_DRBG_PARAM_DIGEST) " -.PD 0 -.ie n .IP """cipher"" (\fB\s-1OSSL_DRBG_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``cipher'' (\fB\s-1OSSL_DRBG_PARAM_CIPHER\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "cipher (OSSL_DRBG_PARAM_CIPHER) " -.ie n .IP """mac"" (\fB\s-1OSSL_DRBG_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``mac'' (\fB\s-1OSSL_DRBG_PARAM_MAC\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "mac (OSSL_DRBG_PARAM_MAC) " -.PD -Sets the name of the underlying cipher, digest or \s-1MAC\s0 to be used. -It must name a suitable algorithm for the \s-1DRBG\s0 that's being used. -.ie n .IP """properties"" (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_DRBG_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_DRBG_PARAM_PROPERTIES) " -Sets the properties to be queried when trying to fetch an underlying algorithm. -This must be given together with the algorithm naming parameter to be -considered valid. -.PP -The OpenSSL \s-1FIPS\s0 provider also supports the following parameters: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_DRBG_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling \fBOSSL_FUNC_rand_generate()\fR. It may -return 0 if the \*(L"digest-check\*(R" is set to 0. -.ie n .IP """digest-check"" (\fB\s-1OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_DRBG_PARAM_FIPS_DIGEST_CHECK) " -If required this parameter should be set before the digest is set. -The default value of 1 causes an error when the digest is set if the digest is -not \s-1FIPS\s0 approved (e.g. truncated digests). Setting this to 0 will ignore -the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_rand_newctx()\fR should return the newly created -provider side rand context, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_rand_gettable_params()\fR, \fBOSSL_FUNC_rand_gettable_ctx_params()\fR and -\&\fBOSSL_FUNC_rand_settable_ctx_params()\fR should return a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) -array, or \s-1NULL\s0 if none is offered. -.PP -\&\fBOSSL_FUNC_rand_nonce()\fR returns the size of the generated nonce, or 0 on error. -.PP -\&\fBOSSL_FUNC_rand_get_seed()\fR returns the size of the generated seed, or 0 on -error. -.PP -All of the remaining functions should return 1 for success or 0 on error. -.SH "NOTES" -.IX Header "NOTES" -The \s-1RAND\s0 life-cycle is described in \fBlife_cycle\-rand\fR\|(7). Providers should -ensure that the various transitions listed there are supported. At some point -the \s-1EVP\s0 layer will begin enforcing the listed transitions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), -\&\s-1\fBRAND\s0\fR\|(7), -\&\s-1\fBEVP_RAND\s0\fR\|(7), -\&\fBlife_cycle\-rand\fR\|(7), -\&\s-1\fBEVP_RAND\s0\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1RAND\s0 interface was introduced in OpenSSL 3.0. -The Rand Parameters \*(L"fips-indicator\*(R" and \*(L"digest-check\*(R" were added in -OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-signature.7ossl b/openssl-install/share/man/man7/provider-signature.7ossl deleted file mode 100644 index 4c02098a..00000000 --- a/openssl-install/share/man/man7/provider-signature.7ossl +++ /dev/null @@ -1,738 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-SIGNATURE 7ossl" -.TH PROVIDER-SIGNATURE 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-signature \- The signature library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 2 -\& #include -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& /* Context management */ -\& void *OSSL_FUNC_signature_newctx(void *provctx, const char *propq); -\& void OSSL_FUNC_signature_freectx(void *ctx); -\& void *OSSL_FUNC_signature_dupctx(void *ctx); -\& -\& /* Get the key types that a signature algorithm supports */ -\& const char **OSSL_FUNC_signature_query_key_types(void); -\& -\& /* Signing */ -\& int OSSL_FUNC_signature_sign_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_signature_sign(void *ctx, unsigned char *sig, size_t *siglen, -\& size_t sigsize, const unsigned char *tbs, size_t tbslen); -\& int OSSL_FUNC_signature_sign_message_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_signature_sign_message_update(void *ctx, const unsigned char *in, -\& size_t inlen); -\& int OSSL_FUNC_signature_sign_message_final(void *ctx, unsigned char *sig, -\& size_t *siglen, size_t sigsize); -\& -\& /* Verifying */ -\& int OSSL_FUNC_signature_verify_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_signature_verify(void *ctx, const unsigned char *sig, size_t siglen, -\& const unsigned char *tbs, size_t tbslen); -\& int OSSL_FUNC_signature_verify_message_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_signature_verify_message_update(void *ctx, const unsigned char *in, -\& size_t inlen); -\& /* -\& * OSSL_FUNC_signature_verify_message_final requires that the signature to be -\& * verified is specified via a "signature" OSSL_PARAM, which is given with a -\& * previous call of OSSL_FUNC_signature_set_ctx_params(). -\& */ -\& int OSSL_FUNC_signature_verify_message_final(void *ctx); -\& -\& /* Verify Recover */ -\& int OSSL_FUNC_signature_verify_recover_init(void *ctx, void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_signature_verify_recover(void *ctx, unsigned char *rout, -\& size_t *routlen, size_t routsize, -\& const unsigned char *sig, size_t siglen); -\& -\& /* Digest Sign */ -\& int OSSL_FUNC_signature_digest_sign_init(void *ctx, const char *mdname, -\& void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_signature_digest_sign_update(void *ctx, const unsigned char *data, -\& size_t datalen); -\& int OSSL_FUNC_signature_digest_sign_final(void *ctx, unsigned char *sig, -\& size_t *siglen, size_t sigsize); -\& int OSSL_FUNC_signature_digest_sign(void *ctx, -\& unsigned char *sig, size_t *siglen, -\& size_t sigsize, const unsigned char *tbs, -\& size_t tbslen); -\& -\& /* Digest Verify */ -\& int OSSL_FUNC_signature_digest_verify_init(void *ctx, const char *mdname, -\& void *provkey, -\& const OSSL_PARAM params[]); -\& int OSSL_FUNC_signature_digest_verify_update(void *ctx, -\& const unsigned char *data, -\& size_t datalen); -\& int OSSL_FUNC_signature_digest_verify_final(void *ctx, const unsigned char *sig, -\& size_t siglen); -\& int OSSL_FUNC_signature_digest_verify(void *ctx, const unsigned char *sig, -\& size_t siglen, const unsigned char *tbs, -\& size_t tbslen); -\& -\& /* Signature parameters */ -\& int OSSL_FUNC_signature_get_ctx_params(void *ctx, OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_signature_gettable_ctx_params(void *ctx, -\& void *provctx); -\& int OSSL_FUNC_signature_set_ctx_params(void *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM *OSSL_FUNC_signature_settable_ctx_params(void *ctx, -\& void *provctx); -\& /* MD parameters */ -\& int OSSL_FUNC_signature_get_ctx_md_params(void *ctx, OSSL_PARAM params[]); -\& const OSSL_PARAM * OSSL_FUNC_signature_gettable_ctx_md_params(void *ctx); -\& int OSSL_FUNC_signature_set_ctx_md_params(void *ctx, const OSSL_PARAM params[]); -\& const OSSL_PARAM * OSSL_FUNC_signature_settable_ctx_md_params(void *ctx); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -This documentation is primarily aimed at provider authors. See \fBprovider\fR\|(7) -for further information. -.PP -The signature (\s-1OSSL_OP_SIGNATURE\s0) operation enables providers to implement -signature algorithms and make them available to applications via the \s-1API\s0 -functions \fBEVP_PKEY_sign\fR\|(3), \fBEVP_PKEY_verify\fR\|(3), -and \fBEVP_PKEY_verify_recover\fR\|(3) (as well -as other related functions). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition -named \fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the -function pointer from an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named -\&\fBOSSL_FUNC_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_signature_newctx()\fR has these: -.PP -.Vb 3 -\& typedef void *(OSSL_FUNC_signature_newctx_fn)(void *provctx, const char *propq); -\& static ossl_inline OSSL_FUNC_signature_newctx_fn -\& OSSL_FUNC_signature_newctx(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as -macros in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 3 -\& OSSL_FUNC_signature_newctx OSSL_FUNC_SIGNATURE_NEWCTX -\& OSSL_FUNC_signature_freectx OSSL_FUNC_SIGNATURE_FREECTX -\& OSSL_FUNC_signature_dupctx OSSL_FUNC_SIGNATURE_DUPCTX -\& -\& OSSL_FUNC_signature_query_key_types OSSL_FUNC_SIGNATURE_QUERY_KEY_TYPES -\& -\& OSSL_FUNC_signature_sign_init OSSL_FUNC_SIGNATURE_SIGN_INIT -\& OSSL_FUNC_signature_sign OSSL_FUNC_SIGNATURE_SIGN -\& OSSL_FUNC_signature_sign_message_init OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_INIT -\& OSSL_FUNC_signature_sign_message_update OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_UPDATE -\& OSSL_FUNC_signature_sign_message_final OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_FINAL -\& -\& OSSL_FUNC_signature_verify_init OSSL_FUNC_SIGNATURE_VERIFY_INIT -\& OSSL_FUNC_signature_verify OSSL_FUNC_SIGNATURE_VERIFY -\& OSSL_FUNC_signature_verify_message_init OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_INIT -\& OSSL_FUNC_signature_verify_message_update OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_UPDATE -\& OSSL_FUNC_signature_verify_message_final OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_FINAL -\& -\& OSSL_FUNC_signature_verify_recover_init OSSL_FUNC_SIGNATURE_VERIFY_RECOVER_INIT -\& OSSL_FUNC_signature_verify_recover OSSL_FUNC_SIGNATURE_VERIFY_RECOVER -\& -\& OSSL_FUNC_signature_digest_sign_init OSSL_FUNC_SIGNATURE_DIGEST_SIGN_INIT -\& OSSL_FUNC_signature_digest_sign_update OSSL_FUNC_SIGNATURE_DIGEST_SIGN_UPDATE -\& OSSL_FUNC_signature_digest_sign_final OSSL_FUNC_SIGNATURE_DIGEST_SIGN_FINAL -\& OSSL_FUNC_signature_digest_sign OSSL_FUNC_SIGNATURE_DIGEST_SIGN -\& -\& OSSL_FUNC_signature_digest_verify_init OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_INIT -\& OSSL_FUNC_signature_digest_verify_update OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_UPDATE -\& OSSL_FUNC_signature_digest_verify_final OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_FINAL -\& OSSL_FUNC_signature_digest_verify OSSL_FUNC_SIGNATURE_DIGEST_VERIFY -\& -\& OSSL_FUNC_signature_get_ctx_params OSSL_FUNC_SIGNATURE_GET_CTX_PARAMS -\& OSSL_FUNC_signature_gettable_ctx_params OSSL_FUNC_SIGNATURE_GETTABLE_CTX_PARAMS -\& OSSL_FUNC_signature_set_ctx_params OSSL_FUNC_SIGNATURE_SET_CTX_PARAMS -\& OSSL_FUNC_signature_settable_ctx_params OSSL_FUNC_SIGNATURE_SETTABLE_CTX_PARAMS -\& -\& OSSL_FUNC_signature_get_ctx_md_params OSSL_FUNC_SIGNATURE_GET_CTX_MD_PARAMS -\& OSSL_FUNC_signature_gettable_ctx_md_params OSSL_FUNC_SIGNATURE_GETTABLE_CTX_MD_PARAMS -\& OSSL_FUNC_signature_set_ctx_md_params OSSL_FUNC_SIGNATURE_SET_CTX_MD_PARAMS -\& OSSL_FUNC_signature_settable_ctx_md_params OSSL_FUNC_SIGNATURE_SETTABLE_CTX_MD_PARAMS -.Ve -.PP -A signature algorithm implementation may not implement all of these functions. -In order to be a consistent set of functions we must have at least a set of -context functions (OSSL_FUNC_signature_newctx and OSSL_FUNC_signature_freectx) as well as a -set of \*(L"signature\*(R" functions, i.e. at least one of: -.IP "OSSL_FUNC_signature_sign_init and OSSL_FUNC_signature_sign" 4 -.IX Item "OSSL_FUNC_signature_sign_init and OSSL_FUNC_signature_sign" -.PD 0 -.IP "OSSL_FUNC_signature_sign_message_init and OSSL_FUNC_signature_sign" 4 -.IX Item "OSSL_FUNC_signature_sign_message_init and OSSL_FUNC_signature_sign" -.IP "OSSL_FUNC_signature_sign_message_init, OSSL_FUNC_signature_sign_message_update and OSSL_FUNC_signature_sign_message_final" 4 -.IX Item "OSSL_FUNC_signature_sign_message_init, OSSL_FUNC_signature_sign_message_update and OSSL_FUNC_signature_sign_message_final" -.IP "OSSL_FUNC_signature_verify_init and OSSL_FUNC_signature_verify" 4 -.IX Item "OSSL_FUNC_signature_verify_init and OSSL_FUNC_signature_verify" -.IP "OSSL_FUNC_signature_verify_message_init and OSSL_FUNC_signature_verify" 4 -.IX Item "OSSL_FUNC_signature_verify_message_init and OSSL_FUNC_signature_verify" -.IP "OSSL_FUNC_signature_verify_message_init, OSSL_FUNC_signature_verify_message_update and OSSL_FUNC_signature_verify_message_final" 4 -.IX Item "OSSL_FUNC_signature_verify_message_init, OSSL_FUNC_signature_verify_message_update and OSSL_FUNC_signature_verify_message_final" -.IP "OSSL_FUNC_signature_verify_recover_init and OSSL_FUNC_signature_verify_recover" 4 -.IX Item "OSSL_FUNC_signature_verify_recover_init and OSSL_FUNC_signature_verify_recover" -.IP "OSSL_FUNC_signature_digest_sign_init, OSSL_FUNC_signature_digest_sign_update and OSSL_FUNC_signature_digest_sign_final" 4 -.IX Item "OSSL_FUNC_signature_digest_sign_init, OSSL_FUNC_signature_digest_sign_update and OSSL_FUNC_signature_digest_sign_final" -.IP "OSSL_FUNC_signature_digest_verify_init, OSSL_FUNC_signature_digest_verify_update and OSSL_FUNC_signature_digest_verify_final" 4 -.IX Item "OSSL_FUNC_signature_digest_verify_init, OSSL_FUNC_signature_digest_verify_update and OSSL_FUNC_signature_digest_verify_final" -.IP "OSSL_FUNC_signature_digest_sign_init and OSSL_FUNC_signature_digest_sign" 4 -.IX Item "OSSL_FUNC_signature_digest_sign_init and OSSL_FUNC_signature_digest_sign" -.IP "OSSL_FUNC_signature_digest_verify_init and OSSL_FUNC_signature_digest_verify" 4 -.IX Item "OSSL_FUNC_signature_digest_verify_init and OSSL_FUNC_signature_digest_verify" -.PD -.PP -OSSL_FUNC_signature_set_ctx_params and OSSL_FUNC_signature_settable_ctx_params are optional, -but if one of them is present then the other one must also be present. The same -applies to OSSL_FUNC_signature_get_ctx_params and OSSL_FUNC_signature_gettable_ctx_params, as -well as the \*(L"md_params\*(R" functions. The OSSL_FUNC_signature_dupctx function is optional. -.PP -A signature algorithm must also implement some mechanism for generating, -loading or importing keys via the key management (\s-1OSSL_OP_KEYMGMT\s0) operation. -See \fBprovider\-keymgmt\fR\|(7) for further details. -.SS "Context Management Functions" -.IX Subsection "Context Management Functions" -\&\fBOSSL_FUNC_signature_newctx()\fR should create and return a pointer to a provider side -structure for holding context information during a signature operation. -A pointer to this context will be passed back in a number of the other signature -operation function calls. -The parameter \fIprovctx\fR is the provider context generated during provider -initialisation (see \fBprovider\fR\|(7)). The \fIpropq\fR parameter is a property query -string that may be (optionally) used by the provider during any \*(L"fetches\*(R" that -it may perform (if it performs any). -.PP -\&\fBOSSL_FUNC_signature_freectx()\fR is passed a pointer to the provider side signature -context in the \fIctx\fR parameter. -This function should free any resources associated with that context. -.PP -\&\fBOSSL_FUNC_signature_dupctx()\fR should duplicate the provider side signature context in -the \fIctx\fR parameter and return the duplicate copy. -.SS "Signing Functions" -.IX Subsection "Signing Functions" -\&\fBOSSL_FUNC_signature_sign_init()\fR initialises a context for signing given a provider side -signature context in the \fIctx\fR parameter, and a pointer to a provider key object -in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_signature_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)). -.PP -\&\fBOSSL_FUNC_signature_sign()\fR performs the actual signing itself. -A previously initialised signature context is passed in the \fIctx\fR -parameter. -The data to be signed is pointed to be the \fItbs\fR parameter which is \fItbslen\fR -bytes long. -Unless \fIsig\fR is \s-1NULL,\s0 the signature should be written to the location pointed -to by the \fIsig\fR parameter and it should not exceed \fIsigsize\fR bytes in length. -The length of the signature should be written to \fI*siglen\fR. -If \fIsig\fR is \s-1NULL\s0 then the maximum length of the signature should be written to -\&\fI*siglen\fR. -.SS "Message Signing Functions" -.IX Subsection "Message Signing Functions" -These functions are suitable for providers that implement algorithms that -accumulate a full message and sign the result of that accumulation, such as -\&\s-1RSA\-SHA256.\s0 -.PP -\&\fBOSSL_FUNC_signature_sign_message_init()\fR initialises a context for signing a -message given a provider side signature context in the \fIctx\fR parameter, and a -pointer to a provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_signature_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)). -.PP -\&\fBOSSL_FUNC_signature_sign_message_update()\fR gathers the data pointed at by -\&\fIin\fR, which is \fIinlen\fR bytes long. -.PP -\&\fBOSSL_FUNC_signature_sign_message_final()\fR performs the actual signing on the -data that was gathered with \fBOSSL_FUNC_signature_sign_message_update()\fR. -.PP -\&\fBOSSL_FUNC_signature_sign()\fR can be used for one-shot signature calls. In that -case, \fItbs\fR is expected to be the whole message to be signed, \fItbslen\fR bytes -long. -.PP -For both \fBOSSL_FUNC_signature_sign_message_final()\fR and \fBOSSL_FUNC_signature_sign()\fR, -if \fIsig\fR is not \s-1NULL,\s0 the signature should be written to the location pointed -to by \fIsig\fR, and it should not exceed \fIsigsize\fR bytes in length. -The length of the signature should be written to \fI*siglen\fR. -If \fIsig\fR is \s-1NULL\s0 then the maximum length of the signature should be written to -\&\fI*siglen\fR. -.SS "Verify Functions" -.IX Subsection "Verify Functions" -\&\fBOSSL_FUNC_signature_verify_init()\fR initialises a context for verifying a signature given -a provider side signature context in the \fIctx\fR parameter, and a pointer to a -provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_signature_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)). -.PP -\&\fBOSSL_FUNC_signature_verify()\fR performs the actual verification itself. -A previously initialised signature context is passed in the \fIctx\fR parameter. -The data that the signature covers is pointed to be the \fItbs\fR parameter which -is \fItbslen\fR bytes long. -The signature is pointed to by the \fIsig\fR parameter which is \fIsiglen\fR bytes -long. -.SS "Message Verify Functions" -.IX Subsection "Message Verify Functions" -These functions are suitable for providers that implement algorithms that -accumulate a full message and verify a signature on the result of that -accumulation, such as \s-1RSA\-SHA256.\s0 -.PP -\&\fBOSSL_FUNC_signature_verify_message_init()\fR initialises a context for verifying -a signature on a message given a provider side signature context in the \fIctx\fR -parameter, and a pointer to a provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_signature_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)). -.PP -\&\fBOSSL_FUNC_signature_verify_message_update()\fR gathers the data pointed at by -\&\fIin\fR, which is \fIinlen\fR bytes long. -.PP -\&\fBOSSL_FUNC_signature_verify_message_final()\fR performs the actual verification on -the data that was gathered with \fBOSSL_FUNC_signature_verify_message_update()\fR. -The signature itself must have been passed through the \*(L"signature\*(R" -(\fB\s-1OSSL_SIGNATURE_PARAM_SIGNATURE\s0\fR) Signature parameter -before this function is called. -.PP -\&\fBOSSL_FUNC_signature_verify()\fR can be used for one-shot verification calls. In -that case, \fItbs\fR is expected to be the whole message to be verified on, -\&\fItbslen\fR bytes long. -.SS "Verify Recover Functions" -.IX Subsection "Verify Recover Functions" -\&\fBOSSL_FUNC_signature_verify_recover_init()\fR initialises a context for recovering the -signed data given a provider side signature context in the \fIctx\fR parameter, and -a pointer to a provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_signature_set_ctx_params()\fR. -The key object should have been previously generated, loaded or imported into -the provider using the key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see -\&\fBprovider\-keymgmt\fR\|(7)). -.PP -\&\fBOSSL_FUNC_signature_verify_recover()\fR performs the actual verify recover itself. -A previously initialised signature context is passed in the \fIctx\fR parameter. -The signature is pointed to by the \fIsig\fR parameter which is \fIsiglen\fR bytes -long. -Unless \fIrout\fR is \s-1NULL,\s0 the recovered data should be written to the location -pointed to by \fIrout\fR which should not exceed \fIroutsize\fR bytes in length. -The length of the recovered data should be written to \fI*routlen\fR. -If \fIrout\fR is \s-1NULL\s0 then the maximum size of the output buffer is written to -the \fIroutlen\fR parameter. -.SS "Digest Sign Functions" -.IX Subsection "Digest Sign Functions" -\&\fBOSSL_FUNC_signature_digest_sign_init()\fR initialises a context for signing given a -provider side signature context in the \fIctx\fR parameter, and a pointer to a -provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -using \fBOSSL_FUNC_signature_set_ctx_params()\fR and -\&\fBOSSL_FUNC_signature_set_ctx_md_params()\fR. -The key object should have been -previously generated, loaded or imported into the provider using the -key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see \fBprovider\-keymgmt\fR\|(7)). -The name of the digest to be used will be in the \fImdname\fR parameter. -.PP -\&\fBOSSL_FUNC_signature_digest_sign_update()\fR provides data to be signed in the \fIdata\fR -parameter which should be of length \fIdatalen\fR. A previously initialised -signature context is passed in the \fIctx\fR parameter. This function may be called -multiple times to cumulatively add data to be signed. -.PP -\&\fBOSSL_FUNC_signature_digest_sign_final()\fR finalises a signature operation previously -started through \fBOSSL_FUNC_signature_digest_sign_init()\fR and -\&\fBOSSL_FUNC_signature_digest_sign_update()\fR calls. Once finalised no more data will be -added through \fBOSSL_FUNC_signature_digest_sign_update()\fR. A previously initialised -signature context is passed in the \fIctx\fR parameter. Unless \fIsig\fR is \s-1NULL,\s0 the -signature should be written to the location pointed to by the \fIsig\fR parameter -and it should not exceed \fIsigsize\fR bytes in length. The length of the signature -should be written to \fI*siglen\fR. If \fIsig\fR is \s-1NULL\s0 then the maximum length of -the signature should be written to \fI*siglen\fR. -.PP -\&\fBOSSL_FUNC_signature_digest_sign()\fR implements a \*(L"one shot\*(R" digest sign operation -previously started through \fBOSSL_FUNC_signature_digest_sign_init()\fR. A previously -initialised signature context is passed in the \fIctx\fR parameter. The data to be -signed is in \fItbs\fR which should be \fItbslen\fR bytes long. Unless \fIsig\fR is \s-1NULL,\s0 -the signature should be written to the location pointed to by the \fIsig\fR -parameter and it should not exceed \fIsigsize\fR bytes in length. The length of the -signature should be written to \fI*siglen\fR. If \fIsig\fR is \s-1NULL\s0 then the maximum -length of the signature should be written to \fI*siglen\fR. -.SS "Digest Verify Functions" -.IX Subsection "Digest Verify Functions" -\&\fBOSSL_FUNC_signature_digest_verify_init()\fR initialises a context for verifying given a -provider side verification context in the \fIctx\fR parameter, and a pointer to a -provider key object in the \fIprovkey\fR parameter. -The \fIparams\fR, if not \s-1NULL,\s0 should be set on the context in a manner similar to -\&\fBOSSL_FUNC_signature_set_ctx_params()\fR and -\&\fBOSSL_FUNC_signature_set_ctx_md_params()\fR. -The key object should have been -previously generated, loaded or imported into the provider using the -key management (\s-1OSSL_OP_KEYMGMT\s0) operation (see \fBprovider\-keymgmt\fR\|(7)). -The name of the digest to be used will be in the \fImdname\fR parameter. -.PP -\&\fBOSSL_FUNC_signature_digest_verify_update()\fR provides data to be verified in the \fIdata\fR -parameter which should be of length \fIdatalen\fR. A previously initialised -verification context is passed in the \fIctx\fR parameter. This function may be -called multiple times to cumulatively add data to be verified. -.PP -\&\fBOSSL_FUNC_signature_digest_verify_final()\fR finalises a verification operation previously -started through \fBOSSL_FUNC_signature_digest_verify_init()\fR and -\&\fBOSSL_FUNC_signature_digest_verify_update()\fR calls. Once finalised no more data will be -added through \fBOSSL_FUNC_signature_digest_verify_update()\fR. A previously initialised -verification context is passed in the \fIctx\fR parameter. The signature to be -verified is in \fIsig\fR which is \fIsiglen\fR bytes long. -.PP -\&\fBOSSL_FUNC_signature_digest_verify()\fR implements a \*(L"one shot\*(R" digest verify operation -previously started through \fBOSSL_FUNC_signature_digest_verify_init()\fR. A previously -initialised verification context is passed in the \fIctx\fR parameter. The data to be -verified is in \fItbs\fR which should be \fItbslen\fR bytes long. The signature to be -verified is in \fIsig\fR which is \fIsiglen\fR bytes long. -.SS "Signature parameters" -.IX Subsection "Signature parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -the \fBOSSL_FUNC_signature_get_ctx_params()\fR and \fBOSSL_FUNC_signature_set_ctx_params()\fR functions. -.PP -\&\fBOSSL_FUNC_signature_get_ctx_params()\fR gets signature parameters associated with the -given provider side signature context \fIctx\fR and stored them in \fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_signature_set_ctx_params()\fR sets the signature parameters associated with the -given provider side signature context \fIctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -Common parameters currently recognised by built-in signature algorithms are as -follows. -.ie n .IP """digest"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_SIGNATURE_PARAM_DIGEST) " -Get or sets the name of the digest algorithm used for the input to the -signature functions. It is required in order to calculate the \*(L"algorithm-id\*(R". -.ie n .IP """properties"" (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``properties'' (\fB\s-1OSSL_SIGNATURE_PARAM_PROPERTIES\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "properties (OSSL_SIGNATURE_PARAM_PROPERTIES) " -Sets the name of the property query associated with the \*(L"digest\*(R" algorithm. -\&\s-1NULL\s0 is used if this optional value is not set. -.PP -Note that when implementing a signature algorithm that gathers a full message, -like \s-1RSA\-SHA256,\s0 the \*(L"digest\*(R" and \*(L"properties\*(R" parameters should not be used. -For such implementations, it's acceptable to simply ignore them if they happen -to be passed in a call to \fBOSSL_FUNC_signature_set_ctx_params()\fR. For such -implementations, however, it is not acceptable to have them in the \fB\s-1OSSL_PARAM\s0\fR -array that's returned by \fBOSSL_FUNC_signature_settable_ctx_params()\fR. -.ie n .IP """signature"" (\fB\s-1OSSL_SIGNATURE_PARAM_SIGNATURE\s0\fR) " 4 -.el .IP "``signature'' (\fB\s-1OSSL_SIGNATURE_PARAM_SIGNATURE\s0\fR) " 4 -.IX Item "signature (OSSL_SIGNATURE_PARAM_SIGNATURE) " -Sets the signature to verify, specifically when -\&\fBOSSL_FUNC_signature_verify_message_final()\fR is used. -.ie n .IP """digest-size"" (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST_SIZE\s0\fR) " 4 -.el .IP "``digest-size'' (\fB\s-1OSSL_SIGNATURE_PARAM_DIGEST_SIZE\s0\fR) " 4 -.IX Item "digest-size (OSSL_SIGNATURE_PARAM_DIGEST_SIZE) " -Gets or sets the output size of the digest algorithm used for the input to the -signature functions. -The length of the \*(L"digest-size\*(R" parameter should not exceed that of a \fBsize_t\fR. -.ie n .IP """algorithm-id"" (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.el .IP "``algorithm-id'' (\fB\s-1OSSL_SIGNATURE_PARAM_ALGORITHM_ID\s0\fR) " 4 -.IX Item "algorithm-id (OSSL_SIGNATURE_PARAM_ALGORITHM_ID) " -Gets the DER-encoded AlgorithmIdentifier for the signature operation. -This typically corresponds to the combination of a digest algorithm -with a purely asymmetric signature algorithm, such as SHA256WithECDSA. -.Sp -The \fBASN1_item_sign_ctx\fR\|(3) relies on this operation and is used by -many other functions signing \s-1ASN.1\s0 structures such as X.509 certificates, -certificate requests, and CRLs, as well as \s-1OCSP, CMP,\s0 and \s-1CMS\s0 messages. -.ie n .IP """nonce-type"" (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.el .IP "``nonce-type'' (\fB\s-1OSSL_SIGNATURE_PARAM_NONCE_TYPE\s0\fR) " 4 -.IX Item "nonce-type (OSSL_SIGNATURE_PARAM_NONCE_TYPE) " -Set this to 1 to use deterministic digital signature generation with -\&\s-1ECDSA\s0 or \s-1DSA,\s0 as defined in \s-1RFC 6979\s0 (see Section 3.2 \*(L"Generation of -k\*(R"). In this case, the \*(L"digest\*(R" parameter must be explicitly set -(otherwise, deterministic nonce generation will fail). Before using -deterministic digital signature generation, please read \s-1RFC 6979\s0 -Section 4 \*(L"Security Considerations\*(R". The default value for -\&\*(L"nonce-type\*(R" is 0 and results in a random value being used for the -nonce \fBk\fR as defined in \s-1FIPS 186\-4\s0 Section 6.3 \*(L"Secret Number -Generation\*(R". -.Sp -The \s-1FIPS\s0 provider does not support deterministic digital signature generation. -.ie n .IP """kat"" (\fB\s-1OSSL_SIGNATURE_PARAM_KAT\s0\fR) " 4 -.el .IP "``kat'' (\fB\s-1OSSL_SIGNATURE_PARAM_KAT\s0\fR) " 4 -.IX Item "kat (OSSL_SIGNATURE_PARAM_KAT) " -Sets a flag to modify the sign operation to return an error if the initial -calculated signature is invalid. -In the normal mode of operation \- new random values are chosen until the -signature operation succeeds. -By default it retries until a signature is calculated. -Setting the value to 0 causes the sign operation to retry, -otherwise the sign operation is only tried once and returns whether or not it -was successful. -Known answer tests can be performed if the random generator is overridden to -supply known values that either pass or fail. -.PP -The following parameters are used by the OpenSSL \s-1FIPS\s0 provider: -.ie n .IP """fips-indicator"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.el .IP "``fips-indicator'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR\s0\fR) " 4 -.IX Item "fips-indicator (OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR) " -A getter that returns 1 if the operation is \s-1FIPS\s0 approved, or 0 otherwise. -This may be used after calling either the sign or verify final functions. It may -return 0 if either the \*(L"digest-check\*(R", \*(L"key-check\*(R", or \*(L"sign-check\*(R" are set to 0. -.ie n .IP """verify-message"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE\s0\fR " 4 -.el .IP "``verify-message'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE\s0\fR " 4 -.IX Item "verify-message (OSSL_SIGNATURE_PARAM_FIPS_VERIFY_MESSAGE " -A getter that returns 1 if a signature verification operation acted on -a raw message, or 0 if it verified a predigested message. A value of 0 -indicates likely non-approved usage of the \s-1FIPS\s0 provider. This flag is -set when any signature verification initialisation function is called. -It is also set to 1 when any signing operation is performed to signify -compliance. See \s-1FIPS 140\-3 IG 2.4.B\s0 for further information. -.ie n .IP """key-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.el .IP "``key-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK\s0\fR) " 4 -.IX Item "key-check (OSSL_SIGNATURE_PARAM_FIPS_KEY_CHECK) " -If required this parameter should be set early via an init function -(e.g. \fBOSSL_FUNC_signature_sign_init()\fR or \fBOSSL_FUNC_signature_verify_init()\fR). -The default value of 1 causes an error during the init if the key is not \s-1FIPS\s0 -approved (e.g. The key has a security strength of less than 112 bits). -Setting this to 0 will ignore the error and set the approved \*(L"indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.ie n .IP """digest-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.el .IP "``digest-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK\s0\fR) " 4 -.IX Item "digest-check (OSSL_SIGNATURE_PARAM_FIPS_DIGEST_CHECK) " -If required this parameter should be set before the signature digest is set. -The default value of 1 causes an error when the digest is set if the digest is -not \s-1FIPS\s0 approved (e.g. \s-1SHA1\s0 is used for signing). Setting this to 0 will ignore -the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.ie n .IP """sign-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK\s0\fR) " 4 -.el .IP "``sign-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK\s0\fR) " 4 -.IX Item "sign-check (OSSL_SIGNATURE_PARAM_FIPS_SIGN_CHECK) " -If required this parameter should be set early via an init function. -The default value of 1 causes an error when a signing algorithm is used. (This -is triggered by deprecated signing algorithms). -Setting this to 0 will ignore the error and set the approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" to -return 0. -.ie n .IP """sign\-x931\-pad\-check"" (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK\s0\fR) " 4 -.el .IP "``sign\-x931\-pad\-check'' (\fB\s-1OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK\s0\fR) " 4 -.IX Item "sign-x931-pad-check (OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK) " -If required this parameter should be set before the padding mode is set. -The default value of 1 causes an error if the padding mode is set to X9.31 padding -for a \s-1RSA\s0 signing operation. Setting this to 0 will ignore the error and set the -approved \*(L"fips-indicator\*(R" to 0. -This option breaks \s-1FIPS\s0 compliance if it causes the approved \*(L"fips-indicator\*(R" -to return 0. -.PP -\&\fBOSSL_FUNC_signature_gettable_ctx_params()\fR and \fBOSSL_FUNC_signature_settable_ctx_params()\fR get a -constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the gettable and settable parameters, -i.e. parameters that can be used with \fBOSSL_FUNC_signature_get_ctx_params()\fR and -\&\fBOSSL_FUNC_signature_set_ctx_params()\fR respectively. -.SS "\s-1MD\s0 parameters" -.IX Subsection "MD parameters" -See \s-1\fBOSSL_PARAM\s0\fR\|(3) for further details on the parameters structure used by -the \fBOSSL_FUNC_signature_get_md_ctx_params()\fR and \fBOSSL_FUNC_signature_set_md_ctx_params()\fR -functions. -.PP -\&\fBOSSL_FUNC_signature_get_md_ctx_params()\fR gets digest parameters associated with the -given provider side digest signature context \fIctx\fR and stores them in \fIparams\fR. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_signature_set_ms_ctx_params()\fR sets the digest parameters associated with the -given provider side digest signature context \fIctx\fR to \fIparams\fR. -Any parameter settings are additional to any that were previously set. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -Parameters currently recognised by built-in signature algorithms are the same -as those for built-in digest algorithms. See -\&\*(L"Digest Parameters\*(R" in \fBprovider\-digest\fR\|(7) for further information. -.PP -\&\fBOSSL_FUNC_signature_gettable_md_ctx_params()\fR and \fBOSSL_FUNC_signature_settable_md_ctx_params()\fR -get a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array that describes the gettable and settable -digest parameters, i.e. parameters that can be used with -\&\fBOSSL_FUNC_signature_get_md_ctx_params()\fR and \fBOSSL_FUNC_signature_set_md_ctx_params()\fR -respectively. -.SH "RETURN VALUES" -.IX Header "RETURN VALUES" -\&\fBOSSL_FUNC_signature_newctx()\fR and \fBOSSL_FUNC_signature_dupctx()\fR should return the newly created -provider side signature context, or \s-1NULL\s0 on failure. -.PP -\&\fBOSSL_FUNC_signature_gettable_ctx_params()\fR, \fBOSSL_FUNC_signature_settable_ctx_params()\fR, -\&\fBOSSL_FUNC_signature_gettable_md_ctx_params()\fR and \fBOSSL_FUNC_signature_settable_md_ctx_params()\fR, -return the gettable or settable parameters in a constant \s-1\fBOSSL_PARAM\s0\fR\|(3) array. -.PP -All other functions should return 1 for success or 0 on error. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7), -\&\fBASN1_item_sign_ctx\fR\|(3) -.SH "HISTORY" -.IX Header "HISTORY" -The provider \s-1SIGNATURE\s0 interface was introduced in OpenSSL 3.0. -The Signature Parameters \*(L"fips-indicator\*(R", \*(L"key-check\*(R" and \*(L"digest-check\*(R" -were added in OpenSSL 3.4. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2025 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider-storemgmt.7ossl b/openssl-install/share/man/man7/provider-storemgmt.7ossl deleted file mode 100644 index 4b08e856..00000000 --- a/openssl-install/share/man/man7/provider-storemgmt.7ossl +++ /dev/null @@ -1,356 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER-STOREMGMT 7ossl" -.TH PROVIDER-STOREMGMT 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider\-storemgmt \- The OSSL_STORE library <\-> provider functions -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -\& -\& /* -\& * None of these are actual functions, but are displayed like this for -\& * the function signatures for functions that are offered as function -\& * pointers in OSSL_DISPATCH arrays. -\& */ -\& -\& void *OSSL_FUNC_store_open(void *provctx, const char *uri); -\& void *OSSL_FUNC_store_attach(void *provctx, OSSL_CORE_BIO *bio); -\& const OSSL_PARAM *store_settable_ctx_params(void *provctx); -\& int OSSL_FUNC_store_set_ctx_params(void *loaderctx, const OSSL_PARAM[]); -\& int OSSL_FUNC_store_load(void *loaderctx, -\& OSSL_CALLBACK *object_cb, void *object_cbarg, -\& OSSL_PASSPHRASE_CALLBACK *pw_cb, void *pw_cbarg); -\& int OSSL_FUNC_store_eof(void *loaderctx); -\& int OSSL_FUNC_store_close(void *loaderctx); -\& -\& int OSSL_FUNC_store_export_object -\& (void *loaderctx, const void *objref, size_t objref_sz, -\& OSSL_CALLBACK *export_cb, void *export_cbarg); -\& void *OSSL_FUNC_store_open_ex(void *provctx, const char *uri, -\& const OSSL_PARAM params[], -\& OSSL_PASSPHRASE_CALLBACK *pw_cb, -\& void *pw_cbarg); -\& -\& int OSSL_FUNC_store_delete(void *provctx, const char *uri, -\& const OSSL_PARAM params[], -\& OSSL_PASSPHRASE_CALLBACK *pw_cb, void *pw_cbarg); -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -The \s-1STORE\s0 operation is the provider side of the \fBossl_store\fR\|(7) \s-1API.\s0 -.PP -The primary responsibility of the \s-1STORE\s0 operation is to load all sorts -of objects from a container indicated by \s-1URI.\s0 These objects are given -to the OpenSSL library in provider-native object abstraction form (see -\&\fBprovider\-object\fR\|(7)). The OpenSSL library is then responsible for -passing on that abstraction to suitable provided functions. -.PP -Examples of functions that the OpenSSL library can pass the abstraction to -include \fBOSSL_FUNC_keymgmt_load()\fR (\fBprovider\-keymgmt\fR\|(7)), -\&\fBOSSL_FUNC_store_export_object()\fR (which exports the object in parameterized -form). -.PP -All \*(L"functions\*(R" mentioned here are passed as function pointers between -\&\fIlibcrypto\fR and the provider in \s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays via -\&\s-1\fBOSSL_ALGORITHM\s0\fR\|(3) arrays that are returned by the provider's -\&\fBprovider_query_operation()\fR function -(see \*(L"Provider Functions\*(R" in \fBprovider\-base\fR\|(7)). -.PP -All these \*(L"functions\*(R" have a corresponding function type definition named -\&\fBOSSL_FUNC_{name}_fn\fR, and a helper function to retrieve the function pointer -from a \s-1\fBOSSL_DISPATCH\s0\fR\|(3) element named \fBOSSL_get_{name}\fR. -For example, the \*(L"function\*(R" \fBOSSL_FUNC_store_attach()\fR has these: -.PP -.Vb 4 -\& typedef void *(OSSL_FUNC_store_attach_fn)(void *provctx, -\& OSSL_CORE_BIO * bio); -\& static ossl_inline OSSL_FUNC_store_attach_fn -\& OSSL_FUNC_store_attach(const OSSL_DISPATCH *opf); -.Ve -.PP -\&\s-1\fBOSSL_DISPATCH\s0\fR\|(3) arrays are indexed by numbers that are provided as macros -in \fBopenssl\-core_dispatch.h\fR\|(7), as follows: -.PP -.Vb 10 -\& OSSL_FUNC_store_open OSSL_FUNC_STORE_OPEN -\& OSSL_FUNC_store_attach OSSL_FUNC_STORE_ATTACH -\& OSSL_FUNC_store_settable_ctx_params OSSL_FUNC_STORE_SETTABLE_CTX_PARAMS -\& OSSL_FUNC_store_set_ctx_params OSSL_FUNC_STORE_SET_CTX_PARAMS -\& OSSL_FUNC_store_load OSSL_FUNC_STORE_LOAD -\& OSSL_FUNC_store_eof OSSL_FUNC_STORE_EOF -\& OSSL_FUNC_store_close OSSL_FUNC_STORE_CLOSE -\& OSSL_FUNC_store_export_object OSSL_FUNC_STORE_EXPORT_OBJECT -\& OSSL_FUNC_store_delete OSSL_FUNC_STORE_DELETE -\& OSSL_FUNC_store_open_ex OSSL_FUNC_STORE_OPEN_EX -.Ve -.SS "Functions" -.IX Subsection "Functions" -\&\fBOSSL_FUNC_store_open()\fR should create a provider side context with data based -on the input \fIuri\fR. The implementation is entirely responsible for the -interpretation of the \s-1URI.\s0 -.PP -\&\fBOSSL_FUNC_store_attach()\fR should create a provider side context with the core -\&\fB\s-1BIO\s0\fR \fIbio\fR attached. This is an alternative to using a \s-1URI\s0 to find storage, -supporting \fBOSSL_STORE_attach\fR\|(3). -.PP -\&\fBOSSL_FUNC_store_settable_ctx_params()\fR should return a constant array of -descriptor \s-1\fBOSSL_PARAM\s0\fR\|(3), for parameters that \fBOSSL_FUNC_store_set_ctx_params()\fR -can handle. -.PP -\&\fBOSSL_FUNC_store_set_ctx_params()\fR should set additional parameters, such as what -kind of data to expect, search criteria, and so on. More on those below, in -\&\*(L"Load Parameters\*(R". Whether unrecognised parameters are an error or simply -ignored is at the implementation's discretion. -Passing \s-1NULL\s0 for \fIparams\fR should return true. -.PP -\&\fBOSSL_FUNC_store_load()\fR loads the next object from the \s-1URI\s0 opened by -\&\fBOSSL_FUNC_store_open()\fR, creates an object abstraction for it (see -\&\fBprovider\-object\fR\|(7)), and calls \fIobject_cb\fR with it as well as -\&\fIobject_cbarg\fR. \fIobject_cb\fR will then interpret the object abstraction -and do what it can to wrap it or decode it into an OpenSSL structure. In -case a passphrase needs to be prompted to unlock an object, \fIpw_cb\fR should -be called. -.PP -\&\fBOSSL_FUNC_store_eof()\fR indicates if the end of the set of objects from the -\&\s-1URI\s0 has been reached. When that happens, there's no point trying to do any -further loading. -.PP -\&\fBOSSL_FUNC_store_close()\fR frees the provider side context \fIctx\fR. -.PP -When a provider-native object is created by a store manager it would be unsuitable -for direct use with a foreign provider. The export function allows for -exporting the object to that foreign provider if the foreign provider -supports the type of the object and provides an import function. -.PP -\&\fBOSSL_FUNC_store_export_object()\fR should export the object of size \fIobjref_sz\fR -referenced by \fIobjref\fR as an \s-1\fBOSSL_PARAM\s0\fR\|(3) array and pass that to the -\&\fIexport_cb\fR as well as the given \fIexport_cbarg\fR. -.PP -\&\fBOSSL_FUNC_store_delete()\fR deletes the object identified by the \fIuri\fR. The -implementation is entirely responsible for the interpretation of the \s-1URI.\s0 In -case a passphrase needs to be prompted to remove an object, \fIpw_cb\fR should be -called. -.PP -\&\fBOSSL_FUNC_store_open_ex()\fR is an extended variant of \fBOSSL_FUNC_store_open()\fR. If -the provider does not implement this function the code internally falls back to -use the original \fBOSSL_FUNC_store_open()\fR. -This variant additionally accepts an \s-1\fBOSSL_PARAM\s0\fR\|(3) object and a \fIpw_cb\fR -callback that can be used to request a passphrase in cases where the whole -store needs to be unlocked before performing any load operation. -.SS "Load Parameters" -.IX Subsection "Load Parameters" -.ie n .IP """expect"" (\fB\s-1OSSL_STORE_PARAM_EXPECT\s0\fR) " 4 -.el .IP "``expect'' (\fB\s-1OSSL_STORE_PARAM_EXPECT\s0\fR) " 4 -.IX Item "expect (OSSL_STORE_PARAM_EXPECT) " -Is a hint of what type of data the OpenSSL library expects to get. -This is only useful for optimization, as the library will check that the -object types match the expectation too. -.Sp -The number that can be given through this parameter is found in -\&\fI\fR, with the macros having names starting with -\&\f(CW\*(C`OSSL_STORE_INFO_\*(C'\fR. These are further described in -\&\*(L"\s-1SUPPORTED OBJECTS\*(R"\s0 in \s-1\fBOSSL_STORE_INFO\s0\fR\|(3). -.ie n .IP """subject"" (\fB\s-1OSSL_STORE_PARAM_SUBJECT\s0\fR) " 4 -.el .IP "``subject'' (\fB\s-1OSSL_STORE_PARAM_SUBJECT\s0\fR) " 4 -.IX Item "subject (OSSL_STORE_PARAM_SUBJECT) " -Indicates that the caller wants to search for an object with the given -subject associated. This can be used to select specific certificates -by subject. -.Sp -The contents of the octet string is expected to be in \s-1DER\s0 form. -.ie n .IP """issuer"" (\fB\s-1OSSL_STORE_PARAM_ISSUER\s0\fR) " 4 -.el .IP "``issuer'' (\fB\s-1OSSL_STORE_PARAM_ISSUER\s0\fR) " 4 -.IX Item "issuer (OSSL_STORE_PARAM_ISSUER) " -Indicates that the caller wants to search for an object with the given -issuer associated. This can be used to select specific certificates -by issuer. -.Sp -The contents of the octet string is expected to be in \s-1DER\s0 form. -.ie n .IP """serial"" (\fB\s-1OSSL_STORE_PARAM_SERIAL\s0\fR) " 4 -.el .IP "``serial'' (\fB\s-1OSSL_STORE_PARAM_SERIAL\s0\fR) " 4 -.IX Item "serial (OSSL_STORE_PARAM_SERIAL) " -Indicates that the caller wants to search for an object with the given -serial number associated. -.ie n .IP """digest"" (\fB\s-1OSSL_STORE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``digest'' (\fB\s-1OSSL_STORE_PARAM_DIGEST\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "digest (OSSL_STORE_PARAM_DIGEST) " -.PD 0 -.ie n .IP """fingerprint"" (\fB\s-1OSSL_STORE_PARAM_FINGERPRINT\s0\fR) " 4 -.el .IP "``fingerprint'' (\fB\s-1OSSL_STORE_PARAM_FINGERPRINT\s0\fR) " 4 -.IX Item "fingerprint (OSSL_STORE_PARAM_FINGERPRINT) " -.PD -Indicates that the caller wants to search for an object with the given -fingerprint, computed with the given digest. -.ie n .IP """alias"" (\fB\s-1OSSL_STORE_PARAM_ALIAS\s0\fR) <\s-1UTF8\s0 string>" 4 -.el .IP "``alias'' (\fB\s-1OSSL_STORE_PARAM_ALIAS\s0\fR) <\s-1UTF8\s0 string>" 4 -.IX Item "alias (OSSL_STORE_PARAM_ALIAS) " -Indicates that the caller wants to search for an object with the given -alias (some call it a \*(L"friendly name\*(R"). -.ie n .IP """properties"" (\fB\s-1OSSL_STORE_PARAM_PROPERTIES\s0\fR) " 4 -.el .IP "``properties'' (\fB\s-1OSSL_STORE_PARAM_PROPERTIES\s0\fR) " 4 -.IX Item "properties (OSSL_STORE_PARAM_PROPERTIES) " -Property string to use when querying for algorithms such as the \fB\s-1OSSL_DECODER\s0\fR -decoder implementations. -.ie n .IP """input-type"" (\fB\s-1OSSL_STORE_PARAM_INPUT_TYPE\s0\fR) " 4 -.el .IP "``input-type'' (\fB\s-1OSSL_STORE_PARAM_INPUT_TYPE\s0\fR) " 4 -.IX Item "input-type (OSSL_STORE_PARAM_INPUT_TYPE) " -Type of the input format as a hint to use when decoding the objects in the -store. -.PP -Several of these search criteria may be combined. For example, to -search for a certificate by issuer+serial, both the \*(L"issuer\*(R" and the -\&\*(L"serial\*(R" parameters will be given. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBprovider\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The \s-1STORE\s0 interface was introduced in OpenSSL 3.0. -.PP -\&\fBOSSL_FUNC_store_delete()\fR callback was added in OpenSSL 3.2 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2020\-2023 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/provider.7ossl b/openssl-install/share/man/man7/provider.7ossl deleted file mode 100644 index f150420b..00000000 --- a/openssl-install/share/man/man7/provider.7ossl +++ /dev/null @@ -1,400 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROVIDER 7ossl" -.TH PROVIDER 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -provider \- OpenSSL operation implementation providers -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -#include -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -.SS "General" -.IX Subsection "General" -This page contains information useful to provider authors. -.PP -A \fIprovider\fR, in OpenSSL terms, is a unit of code that provides one -or more implementations for various operations for diverse algorithms -that one might want to perform. -.PP -An \fIoperation\fR is something one wants to do, such as encryption and -decryption, key derivation, \s-1MAC\s0 calculation, signing and verification, -etc. -.PP -An \fIalgorithm\fR is a named method to perform an operation. -Very often, the algorithms revolve around cryptographic operations, -but may also revolve around other types of operation, such as managing -certain types of objects. -.PP -See \fBcrypto\fR\|(7) for further details. -.SS "Provider" -.IX Subsection "Provider" -A \fIprovider\fR offers an initialization function, as a set of base -functions in the form of an \s-1\fBOSSL_DISPATCH\s0\fR\|(3) array, and by extension, -a set of \s-1\fBOSSL_ALGORITHM\s0\fR\|(3)s (see \fBopenssl\-core.h\fR\|(7)). -It may be a dynamically loadable module, or may be built-in, in -OpenSSL libraries or in the application. -If it's a dynamically loadable module, the initialization function -must be named \f(CW\*(C`OSSL_provider_init\*(C'\fR and must be exported. -If it's built-in, the initialization function may have any name. -.PP -The initialization function must have the following signature: -.PP -.Vb 3 -\& int NAME(const OSSL_CORE_HANDLE *handle, -\& const OSSL_DISPATCH *in, const OSSL_DISPATCH **out, -\& void **provctx); -.Ve -.PP -\&\fIhandle\fR is the OpenSSL library object for the provider, and works -as a handle for everything the OpenSSL libraries need to know about -the provider. -For the provider itself, it is passed to some of the functions given in the -dispatch array \fIin\fR. -.PP -\&\fIin\fR is a dispatch array of base functions offered by the OpenSSL -libraries, and the available functions are further described in -\&\fBprovider\-base\fR\|(7). -.PP -\&\fI*out\fR must be assigned a dispatch array of base functions that the -provider offers to the OpenSSL libraries. -The functions that may be offered are further described in -\&\fBprovider\-base\fR\|(7), and they are the central means of communication -between the OpenSSL libraries and the provider. -.PP -\&\fI*provctx\fR should be assigned a provider specific context to allow -the provider multiple simultaneous uses. -This pointer will be passed to various operation functions offered by -the provider. -.PP -Note that the provider will not be made available for applications to use until -the initialization function has completed and returned successfully. -.PP -One of the functions the provider offers to the OpenSSL libraries is -the central mechanism for the OpenSSL libraries to get access to -operation implementations for diverse algorithms. -Its referred to with the number \fB\s-1OSSL_FUNC_PROVIDER_QUERY_OPERATION\s0\fR -and has the following signature: -.PP -.Vb 3 -\& const OSSL_ALGORITHM *provider_query_operation(void *provctx, -\& int operation_id, -\& const int *no_store); -.Ve -.PP -\&\fIprovctx\fR is the provider specific context that was passed back by -the initialization function. -.PP -\&\fIoperation_id\fR is an operation identity (see \*(L"Operations\*(R" below). -.PP -\&\fIno_store\fR is a flag back to the OpenSSL libraries which, when -nonzero, signifies that the OpenSSL libraries will not store a -reference to the returned data in their internal store of -implementations. -.PP -The returned \s-1\fBOSSL_ALGORITHM\s0\fR\|(3) is the foundation of any OpenSSL -library \s-1API\s0 that uses providers for their implementation, most -commonly in the \fIfetching\fR type of functions -(see \*(L"\s-1ALGORITHM FETCHING\*(R"\s0 in \fBcrypto\fR\|(7)). -.SS "Operations" -.IX Subsection "Operations" -Operations are referred to with numbers, via macros with names -starting with \f(CW\*(C`OSSL_OP_\*(C'\fR. -.PP -With each operation comes a set of defined function types that a -provider may or may not offer, depending on its needs. -.PP -Currently available operations are: -.IP "Digests" 4 -.IX Item "Digests" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1EVP_MD\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_DIGEST\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-digest\fR\|(7). -.IP "Symmetric ciphers" 4 -.IX Item "Symmetric ciphers" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1EVP_CIPHER\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_CIPHER\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-cipher\fR\|(7). -.IP "Message Authentication Code (\s-1MAC\s0)" 4 -.IX Item "Message Authentication Code (MAC)" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1EVP_MAC\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_MAC\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-mac\fR\|(7). -.IP "Key Derivation Function (\s-1KDF\s0)" 4 -.IX Item "Key Derivation Function (KDF)" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1EVP_KDF\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_KDF\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-kdf\fR\|(7). -.IP "Key Exchange" 4 -.IX Item "Key Exchange" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1EVP_KEYEXCH\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_KEYEXCH\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-keyexch\fR\|(7). -.IP "Asymmetric Ciphers" 4 -.IX Item "Asymmetric Ciphers" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1EVP_ASYM_CIPHER\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_ASYM_CIPHER\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-asym_cipher\fR\|(7). -.IP "Asymmetric Key Encapsulation" 4 -.IX Item "Asymmetric Key Encapsulation" -In the OpenSSL libraries, the corresponding method object is \fB\s-1EVP_KEM\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_KEM\s0\fR. -The functions the provider can offer are described in \fBprovider\-kem\fR\|(7). -.IP "Encoding" 4 -.IX Item "Encoding" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1OSSL_ENCODER\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_ENCODER\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-encoder\fR\|(7). -.IP "Decoding" 4 -.IX Item "Decoding" -In the OpenSSL libraries, the corresponding method object is -\&\fB\s-1OSSL_DECODER\s0\fR. -The number for this operation is \fB\s-1OSSL_OP_DECODER\s0\fR. -The functions the provider can offer are described in -\&\fBprovider\-decoder\fR\|(7). -.IP "Random Number Generation" 4 -.IX Item "Random Number Generation" -The number for this operation is \fB\s-1OSSL_OP_RAND\s0\fR. -The functions the provider can offer for random number generation are described -in \fBprovider\-rand\fR\|(7). -.IP "Key Management" 4 -.IX Item "Key Management" -The number for this operation is \fB\s-1OSSL_OP_KEYMGMT\s0\fR. -The functions the provider can offer for key management are described in -\&\fBprovider\-keymgmt\fR\|(7). -.IP "Signing and Signature Verification" 4 -.IX Item "Signing and Signature Verification" -The number for this operation is \fB\s-1OSSL_OP_SIGNATURE\s0\fR. -The functions the provider can offer for digital signatures are described in -\&\fBprovider\-signature\fR\|(7). -.IP "Store Management" 4 -.IX Item "Store Management" -The number for this operation is \fB\s-1OSSL_OP_STORE\s0\fR. -The functions the provider can offer for store management are described in -\&\fBprovider\-storemgmt\fR\|(7). -.PP -\fIAlgorithm naming\fR -.IX Subsection "Algorithm naming" -.PP -Algorithm names are case insensitive. Any particular algorithm can have multiple -aliases associated with it. The canonical OpenSSL naming scheme follows this -format: -.PP -ALGNAME[\s-1VERSION\s0?][\-SUBNAME[\s-1VERSION\s0?]?][\-SIZE?][\-MODE?] -.PP -\&\s-1VERSION\s0 is only present if there are multiple versions of an algorithm (e.g. -\&\s-1MD2, MD4, MD5\s0). It may be omitted if there is only one version. -.PP -\&\s-1SUBNAME\s0 may be present where multiple algorithms are combined together, -e.g. \s-1MD5\-SHA1.\s0 -.PP -\&\s-1SIZE\s0 is only present if multiple versions of an algorithm exist with different -sizes (e.g. \s-1AES\-128\-CBC, AES\-256\-CBC\s0) -.PP -\&\s-1MODE\s0 is only present where applicable. -.PP -Other aliases may exist for example where standards bodies or common practice -use alternative names or names that OpenSSL has used historically. -.PP -\fIProvider dependencies\fR -.IX Subsection "Provider dependencies" -.PP -Providers may depend for their proper operation on the availability of -(functionality implemented in) other providers. As there is no mechanism to -express such dependencies towards the OpenSSL core, provider authors must -take care that such dependencies are either completely avoided or made visible -to users, e.g., by documentation and/or defensive programming, e.g., -outputting error messages if required external dependencies are not available, -e.g., when no provider implementing the required functionality has been -activated. In particular, provider initialization should not depend on other -providers already having been initialized. -.PP -\fINote on naming clashes\fR -.IX Subsection "Note on naming clashes" -.PP -It is possible to register the same algorithm name from within different -providers. Users should note that if no property query is specified, or -more than one implementation matches the property query then it is -unspecified which implementation of a particular algorithm will be returned. -Such naming clashes may also occur if algorithms only differ in -capitalization as \*(L"Algorithm naming\*(R" is case insensitive. -.SH "OPENSSL PROVIDERS" -.IX Header "OPENSSL PROVIDERS" -OpenSSL provides a number of its own providers. These are the default, base, -fips, legacy and null providers. See \fBcrypto\fR\|(7) for an overview of these -providers. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBEVP_DigestInit_ex\fR\|(3), \fBEVP_EncryptInit_ex\fR\|(3), -\&\s-1\fBOSSL_LIB_CTX\s0\fR\|(3), -\&\fBEVP_set_default_properties\fR\|(3), -\&\fBEVP_MD_fetch\fR\|(3), -\&\fBEVP_CIPHER_fetch\fR\|(3), -\&\fBEVP_KEYMGMT_fetch\fR\|(3), -\&\fBopenssl\-core.h\fR\|(7), -\&\fBprovider\-base\fR\|(7), -\&\fBprovider\-digest\fR\|(7), -\&\fBprovider\-cipher\fR\|(7), -\&\fBprovider\-keyexch\fR\|(7) -.SH "HISTORY" -.IX Header "HISTORY" -The concept of providers and everything surrounding them was -introduced in OpenSSL 3.0. -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2024 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/proxy-certificates.7ossl b/openssl-install/share/man/man7/proxy-certificates.7ossl deleted file mode 100644 index 2e8b5586..00000000 --- a/openssl-install/share/man/man7/proxy-certificates.7ossl +++ /dev/null @@ -1,476 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "PROXY-CERTIFICATES 7ossl" -.TH PROXY-CERTIFICATES 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -proxy\-certificates \- Proxy certificates in OpenSSL -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -Proxy certificates are defined in \s-1RFC 3820.\s0 They are used to -extend rights to some other entity (a computer process, typically, or -sometimes to the user itself). This allows the entity to perform -operations on behalf of the owner of the \s-1EE\s0 (End Entity) certificate. -.PP -The requirements for a valid proxy certificate are: -.IP "\(bu" 4 -They are issued by an End Entity, either a normal \s-1EE\s0 certificate, or -another proxy certificate. -.IP "\(bu" 4 -They must not have the \fBsubjectAltName\fR or \fBissuerAltName\fR -extensions. -.IP "\(bu" 4 -They must have the \fBproxyCertInfo\fR extension. -.IP "\(bu" 4 -They must have the subject of their issuer, with one \fBcommonName\fR -added. -.SS "Enabling proxy certificate verification" -.IX Subsection "Enabling proxy certificate verification" -OpenSSL expects applications that want to use proxy certificates to be -specially aware of them, and make that explicit. This is done by -setting an X509 verification flag: -.PP -.Vb 1 -\& X509_STORE_CTX_set_flags(ctx, X509_V_FLAG_ALLOW_PROXY_CERTS); -.Ve -.PP -or -.PP -.Vb 1 -\& X509_VERIFY_PARAM_set_flags(param, X509_V_FLAG_ALLOW_PROXY_CERTS); -.Ve -.PP -See \*(L"\s-1NOTES\*(R"\s0 for a discussion on this requirement. -.SS "Creating proxy certificates" -.IX Subsection "Creating proxy certificates" -Creating proxy certificates can be done using the \fBopenssl\-x509\fR\|(1) -command, with some extra extensions: -.PP -.Vb 7 -\& [ proxy ] -\& # A proxy certificate MUST NEVER be a CA certificate. -\& basicConstraints = CA:FALSE -\& # Usual authority key ID -\& authorityKeyIdentifier = keyid,issuer:always -\& # The extension which marks this certificate as a proxy -\& proxyCertInfo = critical,language:id\-ppl\-anyLanguage,pathlen:1,policy:text:AB -.Ve -.PP -It's also possible to specify the proxy extension in a separate section: -.PP -.Vb 1 -\& proxyCertInfo = critical,@proxy_ext -\& -\& [ proxy_ext ] -\& language = id\-ppl\-anyLanguage -\& pathlen = 0 -\& policy = text:BC -.Ve -.PP -The policy value has a specific syntax, \fIsyntag\fR:\fIstring\fR, where the -\&\fIsyntag\fR determines what will be done with the string. The following -\&\fIsyntag\fRs are recognised: -.IP "\fBtext\fR" 4 -.IX Item "text" -indicates that the string is a byte sequence, without any encoding: -.Sp -.Vb 1 -\& policy=text:ra\*:ksmo\*:rga\*os -.Ve -.IP "\fBhex\fR" 4 -.IX Item "hex" -indicates the string is encoded hexadecimal encoded binary data, with -colons between each byte (every second hex digit): -.Sp -.Vb 1 -\& policy=hex:72:E4:6B:73:6D:F6:72:67:E5:73 -.Ve -.IP "\fBfile\fR" 4 -.IX Item "file" -indicates that the text of the policy should be taken from a file. -The string is then a filename. This is useful for policies that are -more than a few lines, such as \s-1XML\s0 or other markup. -.PP -Note that the proxy policy value is what determines the rights granted -to the process during the proxy certificate, and it is up to the -application to interpret and combine these policies.> -.PP -With a proxy extension, creating a proxy certificate is a matter of -two commands: -.PP -.Vb 3 -\& openssl req \-new \-config proxy.cnf \e -\& \-out proxy.req \-keyout proxy.key \e -\& \-subj "/DC=org/DC=openssl/DC=users/CN=proxy" -\& -\& openssl x509 \-req \-CAcreateserial \-in proxy.req \-out proxy.crt \e -\& \-CA user.crt \-CAkey user.key \-days 7 \e -\& \-extfile proxy.cnf \-extensions proxy -.Ve -.PP -You can also create a proxy certificate using another proxy -certificate as issuer. Note that this example uses a different -configuration section for the proxy extensions: -.PP -.Vb 3 -\& openssl req \-new \-config proxy.cnf \e -\& \-out proxy2.req \-keyout proxy2.key \e -\& \-subj "/DC=org/DC=openssl/DC=users/CN=proxy/CN=proxy 2" -\& -\& openssl x509 \-req \-CAcreateserial \-in proxy2.req \-out proxy2.crt \e -\& \-CA proxy.crt \-CAkey proxy.key \-days 7 \e -\& \-extfile proxy.cnf \-extensions proxy_2 -.Ve -.SS "Using proxy certs in applications" -.IX Subsection "Using proxy certs in applications" -To interpret proxy policies, the application would normally start with -some default rights (perhaps none at all), then compute the resulting -rights by checking the rights against the chain of proxy certificates, -user certificate and \s-1CA\s0 certificates. -.PP -The complicated part is figuring out how to pass data between your -application and the certificate validation procedure. -.PP -The following ingredients are needed for such processing: -.IP "\(bu" 4 -a callback function that will be called for every certificate being -validated. The callback is called several times for each certificate, -so you must be careful to do the proxy policy interpretation at the -right time. You also need to fill in the defaults when the \s-1EE\s0 -certificate is checked. -.IP "\(bu" 4 -a data structure that is shared between your application code and the -callback. -.IP "\(bu" 4 -a wrapper function that sets it all up. -.IP "\(bu" 4 -an ex_data index function that creates an index into the generic -ex_data store that is attached to an X509 validation context. -.PP -The following skeleton code can be used as a starting point: -.PP -.Vb 4 -\& #include -\& #include -\& #include -\& #include -\& -\& #define total_rights 25 -\& -\& /* -\& * In this example, I will use a view of granted rights as a bit -\& * array, one bit for each possible right. -\& */ -\& typedef struct your_rights { -\& unsigned char rights[(total_rights + 7) / 8]; -\& } YOUR_RIGHTS; -\& -\& /* -\& * The following procedure will create an index for the ex_data -\& * store in the X509 validation context the first time it\*(Aqs -\& * called. Subsequent calls will return the same index. -\& */ -\& static int get_proxy_auth_ex_data_idx(X509_STORE_CTX *ctx) -\& { -\& static volatile int idx = \-1; -\& -\& if (idx < 0) { -\& X509_STORE_lock(X509_STORE_CTX_get0_store(ctx)); -\& if (idx < 0) { -\& idx = X509_STORE_CTX_get_ex_new_index(0, -\& "for verify callback", -\& NULL,NULL,NULL); -\& } -\& X509_STORE_unlock(X509_STORE_CTX_get0_store(ctx)); -\& } -\& return idx; -\& } -\& -\& /* Callback to be given to the X509 validation procedure. */ -\& static int verify_callback(int ok, X509_STORE_CTX *ctx) -\& { -\& if (ok == 1) { -\& /* -\& * It\*(Aqs REALLY important you keep the proxy policy check -\& * within this section. It\*(Aqs important to know that when -\& * ok is 1, the certificates are checked from top to -\& * bottom. You get the CA root first, followed by the -\& * possible chain of intermediate CAs, followed by the EE -\& * certificate, followed by the possible proxy -\& * certificates. -\& */ -\& X509 *xs = X509_STORE_CTX_get_current_cert(ctx); -\& -\& if (X509_get_extension_flags(xs) & EXFLAG_PROXY) { -\& YOUR_RIGHTS *rights = -\& (YOUR_RIGHTS *)X509_STORE_CTX_get_ex_data(ctx, -\& get_proxy_auth_ex_data_idx(ctx)); -\& PROXY_CERT_INFO_EXTENSION *pci = -\& X509_get_ext_d2i(xs, NID_proxyCertInfo, NULL, NULL); -\& -\& switch (OBJ_obj2nid(pci\->proxyPolicy\->policyLanguage)) { -\& case NID_Independent: -\& /* -\& * Do whatever you need to grant explicit rights -\& * to this particular proxy certificate, usually -\& * by pulling them from some database. If there -\& * are none to be found, clear all rights (making -\& * this and any subsequent proxy certificate void -\& * of any rights). -\& */ -\& memset(rights\->rights, 0, sizeof(rights\->rights)); -\& break; -\& case NID_id_ppl_inheritAll: -\& /* -\& * This is basically a NOP, we simply let the -\& * current rights stand as they are. -\& */ -\& break; -\& default: -\& /* -\& * This is usually the most complex section of -\& * code. You really do whatever you want as long -\& * as you follow RFC 3820. In the example we use -\& * here, the simplest thing to do is to build -\& * another, temporary bit array and fill it with -\& * the rights granted by the current proxy -\& * certificate, then use it as a mask on the -\& * accumulated rights bit array, and voila\*`, you -\& * now have a new accumulated rights bit array. -\& */ -\& { -\& int i; -\& YOUR_RIGHTS tmp_rights; -\& memset(tmp_rights.rights, 0, -\& sizeof(tmp_rights.rights)); -\& -\& /* -\& * process_rights() is supposed to be a -\& * procedure that takes a string and its -\& * length, interprets it and sets the bits -\& * in the YOUR_RIGHTS pointed at by the -\& * third argument. -\& */ -\& process_rights((char *) pci\->proxyPolicy\->policy\->data, -\& pci\->proxyPolicy\->policy\->length, -\& &tmp_rights); -\& -\& for(i = 0; i < total_rights / 8; i++) -\& rights\->rights[i] &= tmp_rights.rights[i]; -\& } -\& break; -\& } -\& PROXY_CERT_INFO_EXTENSION_free(pci); -\& } else if (!(X509_get_extension_flags(xs) & EXFLAG_CA)) { -\& /* We have an EE certificate, let\*(Aqs use it to set default! */ -\& YOUR_RIGHTS *rights = -\& (YOUR_RIGHTS *)X509_STORE_CTX_get_ex_data(ctx, -\& get_proxy_auth_ex_data_idx(ctx)); -\& -\& /* -\& * The following procedure finds out what rights the -\& * owner of the current certificate has, and sets them -\& * in the YOUR_RIGHTS structure pointed at by the -\& * second argument. -\& */ -\& set_default_rights(xs, rights); -\& } -\& } -\& return ok; -\& } -\& -\& static int my_X509_verify_cert(X509_STORE_CTX *ctx, -\& YOUR_RIGHTS *needed_rights) -\& { -\& int ok; -\& int (*save_verify_cb)(int ok,X509_STORE_CTX *ctx) = -\& X509_STORE_CTX_get_verify_cb(ctx); -\& YOUR_RIGHTS rights; -\& -\& X509_STORE_CTX_set_verify_cb(ctx, verify_callback); -\& X509_STORE_CTX_set_ex_data(ctx, get_proxy_auth_ex_data_idx(ctx), -\& &rights); -\& X509_STORE_CTX_set_flags(ctx, X509_V_FLAG_ALLOW_PROXY_CERTS); -\& ok = X509_verify_cert(ctx); -\& -\& if (ok == 1) { -\& ok = check_needed_rights(rights, needed_rights); -\& } -\& -\& X509_STORE_CTX_set_verify_cb(ctx, save_verify_cb); -\& -\& return ok; -\& } -.Ve -.PP -If you use \s-1SSL\s0 or \s-1TLS,\s0 you can easily set up a callback to have the -certificates checked properly, using the code above: -.PP -.Vb 2 -\& SSL_CTX_set_cert_verify_callback(s_ctx, my_X509_verify_cert, -\& &needed_rights); -.Ve -.SH "NOTES" -.IX Header "NOTES" -To this date, it seems that proxy certificates have only been used in -environments that are aware of them, and no one seems to have -investigated how they can be used or misused outside of such an -environment. -.PP -For that reason, OpenSSL requires that applications aware of proxy -certificates must also make that explicit. -.PP -\&\fBsubjectAltName\fR and \fBissuerAltName\fR are forbidden in proxy -certificates, and this is enforced in OpenSSL. The subject must be -the same as the issuer, with one commonName added on. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_STORE_CTX_set_flags\fR\|(3), -\&\fBX509_STORE_CTX_set_verify_cb\fR\|(3), -\&\fBX509_VERIFY_PARAM_set_flags\fR\|(3), -\&\fBSSL_CTX_set_cert_verify_callback\fR\|(3), -\&\fBopenssl\-req\fR\|(1), \fBopenssl\-x509\fR\|(1), -\&\s-1RFC 3820\s0 -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2019\-2020 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/share/man/man7/ssl.7ossl b/openssl-install/share/man/man7/ssl.7ossl deleted file mode 120000 index e9aac4b6..00000000 --- a/openssl-install/share/man/man7/ssl.7ossl +++ /dev/null @@ -1 +0,0 @@ -ossl-guide-libssl-introduction.7ossl \ No newline at end of file diff --git a/openssl-install/share/man/man7/x509.7ossl b/openssl-install/share/man/man7/x509.7ossl deleted file mode 100644 index d2fbab13..00000000 --- a/openssl-install/share/man/man7/x509.7ossl +++ /dev/null @@ -1,206 +0,0 @@ -.\" Automatically generated by Pod::Man 4.14 (Pod::Simple 3.42) -.\" -.\" Standard preamble: -.\" ======================================================================== -.de Sp \" Vertical space (when we can't use .PP) -.if t .sp .5v -.if n .sp -.. -.de Vb \" Begin verbatim text -.ft CW -.nf -.ne \\$1 -.. -.de Ve \" End verbatim text -.ft R -.fi -.. -.\" Set up some character translations and predefined strings. \*(-- will -.\" give an unbreakable dash, \*(PI will give pi, \*(L" will give a left -.\" double quote, and \*(R" will give a right double quote. \*(C+ will -.\" give a nicer C++. Capital omega is used to do unbreakable dashes and -.\" therefore won't be available. \*(C` and \*(C' expand to `' in nroff, -.\" nothing in troff, for use with C<>. -.tr \(*W- -.ds C+ C\v'-.1v'\h'-1p'\s-2+\h'-1p'+\s0\v'.1v'\h'-1p' -.ie n \{\ -. ds -- \(*W- -. ds PI pi -. if (\n(.H=4u)&(1m=24u) .ds -- \(*W\h'-12u'\(*W\h'-12u'-\" diablo 10 pitch -. if (\n(.H=4u)&(1m=20u) .ds -- \(*W\h'-12u'\(*W\h'-8u'-\" diablo 12 pitch -. ds L" "" -. ds R" "" -. ds C` "" -. ds C' "" -'br\} -.el\{\ -. ds -- \|\(em\| -. ds PI \(*p -. ds L" `` -. ds R" '' -. ds C` -. ds C' -'br\} -.\" -.\" Escape single quotes in literal strings from groff's Unicode transform. -.ie \n(.g .ds Aq \(aq -.el .ds Aq ' -.\" -.\" If the F register is >0, we'll generate index entries on stderr for -.\" titles (.TH), headers (.SH), subsections (.SS), items (.Ip), and index -.\" entries marked with X<> in POD. Of course, you'll have to process the -.\" output yourself in some meaningful fashion. -.\" -.\" Avoid warning from groff about undefined register 'F'. -.de IX -.. -.nr rF 0 -.if \n(.g .if rF .nr rF 1 -.if (\n(rF:(\n(.g==0)) \{\ -. if \nF \{\ -. de IX -. tm Index:\\$1\t\\n%\t"\\$2" -.. -. if !\nF==2 \{\ -. nr % 0 -. nr F 2 -. \} -. \} -.\} -.rr rF -.\" -.\" Accent mark definitions (@(#)ms.acc 1.5 88/02/08 SMI; from UCB 4.2). -.\" Fear. Run. Save yourself. No user-serviceable parts. -. \" fudge factors for nroff and troff -.if n \{\ -. ds #H 0 -. ds #V .8m -. ds #F .3m -. ds #[ \f1 -. ds #] \fP -.\} -.if t \{\ -. ds #H ((1u-(\\\\n(.fu%2u))*.13m) -. ds #V .6m -. ds #F 0 -. ds #[ \& -. ds #] \& -.\} -. \" simple accents for nroff and troff -.if n \{\ -. ds ' \& -. ds ` \& -. ds ^ \& -. ds , \& -. ds ~ ~ -. ds / -.\} -.if t \{\ -. ds ' \\k:\h'-(\\n(.wu*8/10-\*(#H)'\'\h"|\\n:u" -. ds ` \\k:\h'-(\\n(.wu*8/10-\*(#H)'\`\h'|\\n:u' -. ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'^\h'|\\n:u' -. ds , \\k:\h'-(\\n(.wu*8/10)',\h'|\\n:u' -. ds ~ \\k:\h'-(\\n(.wu-\*(#H-.1m)'~\h'|\\n:u' -. ds / \\k:\h'-(\\n(.wu*8/10-\*(#H)'\z\(sl\h'|\\n:u' -.\} -. \" troff and (daisy-wheel) nroff accents -.ds : \\k:\h'-(\\n(.wu*8/10-\*(#H+.1m+\*(#F)'\v'-\*(#V'\z.\h'.2m+\*(#F'.\h'|\\n:u'\v'\*(#V' -.ds 8 \h'\*(#H'\(*b\h'-\*(#H' -.ds o \\k:\h'-(\\n(.wu+\w'\(de'u-\*(#H)/2u'\v'-.3n'\*(#[\z\(de\v'.3n'\h'|\\n:u'\*(#] -.ds d- \h'\*(#H'\(pd\h'-\w'~'u'\v'-.25m'\f2\(hy\fP\v'.25m'\h'-\*(#H' -.ds D- D\\k:\h'-\w'D'u'\v'-.11m'\z\(hy\v'.11m'\h'|\\n:u' -.ds th \*(#[\v'.3m'\s+1I\s-1\v'-.3m'\h'-(\w'I'u*2/3)'\s-1o\s+1\*(#] -.ds Th \*(#[\s+2I\s-2\h'-\w'I'u*3/5'\v'-.3m'o\v'.3m'\*(#] -.ds ae a\h'-(\w'a'u*4/10)'e -.ds Ae A\h'-(\w'A'u*4/10)'E -. \" corrections for vroff -.if v .ds ~ \\k:\h'-(\\n(.wu*9/10-\*(#H)'\s-2\u~\d\s+2\h'|\\n:u' -.if v .ds ^ \\k:\h'-(\\n(.wu*10/11-\*(#H)'\v'-.4m'^\v'.4m'\h'|\\n:u' -. \" for low resolution devices (crt and lpr) -.if \n(.H>23 .if \n(.V>19 \ -\{\ -. ds : e -. ds 8 ss -. ds o a -. ds d- d\h'-1'\(ga -. ds D- D\h'-1'\(hy -. ds th \o'bp' -. ds Th \o'LP' -. ds ae ae -. ds Ae AE -.\} -.rm #[ #] #H #V #F C -.\" ======================================================================== -.\" -.IX Title "X509 7ossl" -.TH X509 7ossl "2025-07-01" "3.4.2" "OpenSSL" -.\" For nroff, turn off justification. Always turn off hyphenation; it makes -.\" way too many mistakes in technical documents. -.if n .ad l -.nh -.SH "NAME" -x509 \- X.509 certificate handling -.SH "SYNOPSIS" -.IX Header "SYNOPSIS" -.Vb 1 -\& #include -.Ve -.SH "DESCRIPTION" -.IX Header "DESCRIPTION" -An X.509 certificate is a structured grouping of information about -an individual, a device, or anything one can imagine. An X.509 \s-1CRL\s0 -(certificate revocation list) is a tool to help determine if a -certificate is still valid. The exact definition of those can be -found in the X.509 document from ITU-T, or in \s-1RFC3280\s0 from \s-1PKIX.\s0 -In OpenSSL, the type X509 is used to express such a certificate, and -the type X509_CRL is used to express a \s-1CRL.\s0 -.PP -A related structure is a certificate request, defined in PKCS#10 from -\&\s-1RSA\s0 Security, Inc, also reflected in \s-1RFC2896.\s0 In OpenSSL, the type -X509_REQ is used to express such a certificate request. -.PP -To handle some complex parts of a certificate, there are the types -X509_NAME (to express a certificate name), X509_ATTRIBUTE (to express -a certificate attribute), X509_EXTENSION (to express a certificate -extension) and a few more. -.PP -Finally, there's the supertype X509_INFO, which can contain a \s-1CRL,\s0 a -certificate and a corresponding private key. -.PP -\&\fBX509_\fR\fI\s-1XXX\s0\fR, \fBd2i_X509_\fR\fI\s-1XXX\s0\fR, and \fBi2d_X509_\fR\fI\s-1XXX\s0\fR functions -handle X.509 certificates, with some exceptions, shown below. -.PP -\&\fBX509_CRL_\fR\fI\s-1XXX\s0\fR, \fBd2i_X509_CRL_\fR\fI\s-1XXX\s0\fR, and \fBi2d_X509_CRL_\fR\fI\s-1XXX\s0\fR -functions handle X.509 CRLs. -.PP -\&\fBX509_REQ_\fR\fI\s-1XXX\s0\fR, \fBd2i_X509_REQ_\fR\fI\s-1XXX\s0\fR, and \fBi2d_X509_REQ_\fR\fI\s-1XXX\s0\fR -functions handle PKCS#10 certificate requests. -.PP -\&\fBX509_NAME_\fR\fI\s-1XXX\s0\fR functions handle certificate names. -.PP -\&\fBX509_ATTRIBUTE_\fR\fI\s-1XXX\s0\fR functions handle certificate attributes. -.PP -\&\fBX509_EXTENSION_\fR\fI\s-1XXX\s0\fR functions handle certificate extensions. -.SH "SEE ALSO" -.IX Header "SEE ALSO" -\&\fBX509_NAME_ENTRY_get_object\fR\|(3), -\&\fBX509_NAME_add_entry_by_txt\fR\|(3), -\&\fBX509_NAME_add_entry_by_NID\fR\|(3), -\&\fBX509_NAME_print_ex\fR\|(3), -\&\fBX509_NAME_new\fR\|(3), -\&\fBPEM_X509_INFO_read\fR\|(3), -\&\fBd2i_X509\fR\|(3), -\&\fBd2i_X509_ALGOR\fR\|(3), -\&\fBd2i_X509_CRL\fR\|(3), -\&\fBd2i_X509_NAME\fR\|(3), -\&\fBd2i_X509_REQ\fR\|(3), -\&\fBd2i_X509_SIG\fR\|(3), -\&\fBcrypto\fR\|(7) -.SH "COPYRIGHT" -.IX Header "COPYRIGHT" -Copyright 2003\-2021 The OpenSSL Project Authors. All Rights Reserved. -.PP -Licensed under the Apache License 2.0 (the \*(L"License\*(R"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file \s-1LICENSE\s0 in the source distribution or at -. diff --git a/openssl-install/ssl/ct_log_list.cnf b/openssl-install/ssl/ct_log_list.cnf deleted file mode 100644 index e643cfdb..00000000 --- a/openssl-install/ssl/ct_log_list.cnf +++ /dev/null @@ -1,9 +0,0 @@ -# This file specifies the Certificate Transparency logs -# that are to be trusted. - -# Google's list of logs can be found here: -# www.certificate-transparency.org/known-logs -# A Python program to convert the log list to OpenSSL's format can be -# found here: -# https://github.com/google/certificate-transparency/blob/master/python/utilities/log_list/print_log_list.py -# Use the "--openssl_output" flag. diff --git a/openssl-install/ssl/ct_log_list.cnf.dist b/openssl-install/ssl/ct_log_list.cnf.dist deleted file mode 100644 index e643cfdb..00000000 --- a/openssl-install/ssl/ct_log_list.cnf.dist +++ /dev/null @@ -1,9 +0,0 @@ -# This file specifies the Certificate Transparency logs -# that are to be trusted. - -# Google's list of logs can be found here: -# www.certificate-transparency.org/known-logs -# A Python program to convert the log list to OpenSSL's format can be -# found here: -# https://github.com/google/certificate-transparency/blob/master/python/utilities/log_list/print_log_list.py -# Use the "--openssl_output" flag. diff --git a/openssl-install/ssl/misc/CA.pl b/openssl-install/ssl/misc/CA.pl deleted file mode 100755 index 0861fd7a..00000000 --- a/openssl-install/ssl/misc/CA.pl +++ /dev/null @@ -1,383 +0,0 @@ -#!/usr/bin/env perl -# Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# -# Wrapper around the ca to make it easier to use -# -# WARNING: do not edit! -# Generated by Makefile from apps/CA.pl.in - -use strict; -use warnings; - -my $verbose = 1; -my @OPENSSL_CMDS = ("req", "ca", "pkcs12", "x509", "verify"); - -my $openssl = $ENV{'OPENSSL'} // "openssl"; -$ENV{'OPENSSL'} = $openssl; -my @openssl = split_val($openssl); - -my $OPENSSL_CONFIG = $ENV{"OPENSSL_CONFIG"} // ""; -my @OPENSSL_CONFIG = split_val($OPENSSL_CONFIG); - -# Command invocations. -my @REQ = (@openssl, "req", @OPENSSL_CONFIG); -my @CA = (@openssl, "ca", @OPENSSL_CONFIG); -my @VERIFY = (@openssl, "verify"); -my @X509 = (@openssl, "x509"); -my @PKCS12 = (@openssl, "pkcs12"); - -# Default values for various configuration settings. -my $CATOP = "./demoCA"; -my $CAKEY = "cakey.pem"; -my $CAREQ = "careq.pem"; -my $CACERT = "cacert.pem"; -my $CACRL = "crl.pem"; -my @DAYS = qw(-days 365); -my @CADAYS = qw(-days 1095); # 3 years -my @EXTENSIONS = qw(-extensions v3_ca); -my @POLICY = qw(-policy policy_anything); -my $NEWKEY = "newkey.pem"; -my $NEWREQ = "newreq.pem"; -my $NEWCERT = "newcert.pem"; -my $NEWP12 = "newcert.p12"; - -# Commandline parsing -my %EXTRA; -my $WHAT = shift @ARGV // ""; -@ARGV = parse_extra(@ARGV); -my $RET = 0; - -sub split_val { - return split_val_win32(@_) if ($^O eq 'MSWin32'); - my ($val) = @_; - my (@ret, @frag); - - # Skip leading whitespace - $val =~ m{\A[ \t]*}ogc; - - # Unix shell-compatible split - # - # Handles backslash escapes outside quotes and - # in double-quoted strings. Parameter and - # command-substitution is silently ignored. - # Bare newlines outside quotes and (trailing) backslashes are disallowed. - - while (1) { - last if (pos($val) == length($val)); - - # The first char is never a SPACE or TAB. Possible matches are: - # 1. Ordinary string fragment - # 2. Single-quoted string - # 3. Double-quoted string - # 4. Backslash escape - # 5. Bare backlash or newline (rejected) - # - if ($val =~ m{\G([^'" \t\n\\]+)}ogc) { - # Ordinary string - push @frag, $1; - } elsif ($val =~ m{\G'([^']*)'}ogc) { - # Single-quoted string - push @frag, $1; - } elsif ($val =~ m{\G"}ogc) { - # Double-quoted string - push @frag, ""; - while (1) { - last if ($val =~ m{\G"}ogc); - if ($val =~ m{\G([^"\\]+)}ogcs) { - # literals - push @frag, $1; - } elsif ($val =~ m{\G.(["\`\$\\])}ogc) { - # backslash-escaped special - push @frag, $1; - } elsif ($val =~ m{\G.(.)}ogcs) { - # backslashed non-special - push @frag, "\\$1" unless $1 eq "\n"; - } else { - die sprintf("Malformed quoted string: %s\n", $val); - } - } - } elsif ($val =~ m{\G\\(.)}ogc) { - # Backslash is unconditional escape outside quoted strings - push @frag, $1 unless $1 eq "\n"; - } else { - die sprintf("Bare backslash or newline in: '%s'\n", $val); - } - # Done if at SPACE, TAB or end, otherwise continue current fragment - # - next unless ($val =~ m{\G(?:[ \t]+|\z)}ogcs); - push @ret, join("", splice(@frag)) if (@frag > 0); - } - # Handle final fragment - push @ret, join("", splice(@frag)) if (@frag > 0); - return @ret; -} - -sub split_val_win32 { - my ($val) = @_; - my (@ret, @frag); - - # Skip leading whitespace - $val =~ m{\A[ \t]*}ogc; - - # Windows-compatible split - # See: "Parsing C++ command-line arguments" in: - # https://learn.microsoft.com/en-us/cpp/cpp/main-function-command-line-args?view=msvc-170 - # - # Backslashes are special only when followed by a double-quote - # Pairs of double-quotes make a single double-quote. - # Closing double-quotes may be omitted. - - while (1) { - last if (pos($val) == length($val)); - - # The first char is never a SPACE or TAB. - # 1. Ordinary string fragment - # 2. Double-quoted string - # 3. Backslashes preceding a double-quote - # 4. Literal backslashes - # 5. Bare newline (rejected) - # - if ($val =~ m{\G([^" \t\n\\]+)}ogc) { - # Ordinary string - push @frag, $1; - } elsif ($val =~ m{\G"}ogc) { - # Double-quoted string - push @frag, ""; - while (1) { - if ($val =~ m{\G("+)}ogc) { - # Two double-quotes make one literal double-quote - my $l = length($1); - push @frag, q{"} x int($l/2) if ($l > 1); - next if ($l % 2 == 0); - last; - } - if ($val =~ m{\G([^"\\]+)}ogc) { - push @frag, $1; - } elsif ($val =~ m{\G((?>[\\]+))(?=")}ogc) { - # Backslashes before a double-quote are escapes - my $l = length($1); - push @frag, q{\\} x int($l / 2); - if ($l % 2 == 1) { - ++pos($val); - push @frag, q{"}; - } - } elsif ($val =~ m{\G((?:(?>[\\]+)[^"\\]+)+)}ogc) { - # Backslashes not before a double-quote are not special - push @frag, $1; - } else { - # Tolerate missing closing double-quote - last; - } - } - } elsif ($val =~ m{\G((?>[\\]+))(?=")}ogc) { - my $l = length($1); - push @frag, q{\\} x int($l / 2); - if ($l % 2 == 1) { - ++pos($val); - push @frag, q{"}; - } - } elsif ($val =~ m{\G([\\]+)}ogc) { - # Backslashes not before a double-quote are not special - push @frag, $1; - } else { - die sprintf("Bare newline in: '%s'\n", $val); - } - # Done if at SPACE, TAB or end, otherwise continue current fragment - # - next unless ($val =~ m{\G(?:[ \t]+|\z)}ogcs); - push @ret, join("", splice(@frag)) if (@frag > 0); - } - # Handle final fragment - push @ret, join("", splice(@frag)) if (@frag); - return @ret; -} - -# Split out "-extra-CMD value", and return new |@ARGV|. Fill in -# |EXTRA{CMD}| with list of values. -sub parse_extra -{ - my @args; - foreach ( @OPENSSL_CMDS ) { - $EXTRA{$_} = []; - } - while (@_) { - my $arg = shift(@_); - if ( $arg !~ m{^-extra-(\w+)$} ) { - push @args, split_val($arg); - next; - } - $arg = $1; - die "Unknown \"-extra-${arg}\" option, exiting\n" - unless grep { $arg eq $_ } @OPENSSL_CMDS; - die "Missing \"-extra-${arg}\" option value, exiting\n" - unless (@_ > 0); - push @{$EXTRA{$arg}}, split_val(shift(@_)); - } - return @args; -} - - -# See if reason for a CRL entry is valid; exit if not. -sub crl_reason_ok -{ - my $r = shift; - - if ($r eq 'unspecified' || $r eq 'keyCompromise' - || $r eq 'CACompromise' || $r eq 'affiliationChanged' - || $r eq 'superseded' || $r eq 'cessationOfOperation' - || $r eq 'certificateHold' || $r eq 'removeFromCRL') { - return 1; - } - print STDERR "Invalid CRL reason; must be one of:\n"; - print STDERR " unspecified, keyCompromise, CACompromise,\n"; - print STDERR " affiliationChanged, superseded, cessationOfOperation\n"; - print STDERR " certificateHold, removeFromCRL"; - exit 1; -} - -# Copy a PEM-format file; return like exit status (zero means ok) -sub copy_pemfile -{ - my ($infile, $outfile, $bound) = @_; - my $found = 0; - - open IN, $infile || die "Cannot open $infile, $!"; - open OUT, ">$outfile" || die "Cannot write to $outfile, $!"; - while () { - $found = 1 if /^-----BEGIN.*$bound/; - print OUT $_ if $found; - $found = 2, last if /^-----END.*$bound/; - } - close IN; - close OUT; - return $found == 2 ? 0 : 1; -} - -# Wrapper around system; useful for debugging. Returns just the exit status -sub run -{ - my ($cmd, @args) = @_; - print "====\n$cmd @args\n" if $verbose; - my $status = system {$cmd} $cmd, @args; - print "==> $status\n====\n" if $verbose; - return $status >> 8; -} - - -if ( $WHAT =~ /^(-\?|-h|-help)$/ ) { - print STDERR <${CATOP}/index.txt"; - close OUT; - open OUT, ">${CATOP}/crlnumber"; - print OUT "01\n"; - close OUT; - # ask user for existing CA certificate - print "CA certificate filename (or enter to create)\n"; - my $FILE; - $FILE = "" unless defined($FILE = ); - $FILE =~ s{\R$}{}; - if ($FILE ne "") { - copy_pemfile($FILE,"${CATOP}/private/$CAKEY", "PRIVATE"); - copy_pemfile($FILE,"${CATOP}/$CACERT", "CERTIFICATE"); - } else { - print "Making CA certificate ...\n"; - $RET = run(@REQ, qw(-new -keyout), "${CATOP}/private/$CAKEY", - "-out", "${CATOP}/$CAREQ", @{$EXTRA{req}}); - $RET = run(@CA, qw(-create_serial -out), "${CATOP}/$CACERT", @CADAYS, - qw(-batch -keyfile), "${CATOP}/private/$CAKEY", "-selfsign", - @EXTENSIONS, "-infiles", "${CATOP}/$CAREQ", @{$EXTRA{ca}}) - if $RET == 0; - print "CA certificate is in ${CATOP}/$CACERT\n" if $RET == 0; - } -} elsif ($WHAT eq '-pkcs12' ) { - my $cname = $ARGV[0]; - $cname = "My Certificate" unless defined $cname; - $RET = run(@PKCS12, "-in", $NEWCERT, "-inkey", $NEWKEY, - "-certfile", "${CATOP}/$CACERT", "-out", $NEWP12, - qw(-export -name), $cname, @{$EXTRA{pkcs12}}); - print "PKCS#12 file is in $NEWP12\n" if $RET == 0; -} elsif ($WHAT eq '-xsign' ) { - $RET = run(@CA, @POLICY, "-infiles", $NEWREQ, @{$EXTRA{ca}}); -} elsif ($WHAT eq '-sign' ) { - $RET = run(@CA, @POLICY, "-out", $NEWCERT, - "-infiles", $NEWREQ, @{$EXTRA{ca}}); - print "Signed certificate is in $NEWCERT\n" if $RET == 0; -} elsif ($WHAT eq '-signCA' ) { - $RET = run(@CA, @POLICY, "-out", $NEWCERT, @EXTENSIONS, - "-infiles", $NEWREQ, @{$EXTRA{ca}}); - print "Signed CA certificate is in $NEWCERT\n" if $RET == 0; -} elsif ($WHAT eq '-signcert' ) { - $RET = run(@X509, qw(-x509toreq -in), $NEWREQ, "-signkey", $NEWREQ, - qw(-out tmp.pem), @{$EXTRA{x509}}); - $RET = run(@CA, @POLICY, "-out", $NEWCERT, - qw(-infiles tmp.pem), @{$EXTRA{ca}}) if $RET == 0; - print "Signed certificate is in $NEWCERT\n" if $RET == 0; -} elsif ($WHAT eq '-verify' ) { - my @files = @ARGV ? @ARGV : ( $NEWCERT ); - foreach my $file (@files) { - my $status = run(@VERIFY, "-CAfile", "${CATOP}/$CACERT", $file, @{$EXTRA{verify}}); - $RET = $status if $status != 0; - } -} elsif ($WHAT eq '-crl' ) { - $RET = run(@CA, qw(-gencrl -out), "${CATOP}/crl/$CACRL", @{$EXTRA{ca}}); - print "Generated CRL is in ${CATOP}/crl/$CACRL\n" if $RET == 0; -} elsif ($WHAT eq '-revoke' ) { - my $cname = $ARGV[0]; - if (!defined $cname) { - print "Certificate filename is required; reason optional.\n"; - exit 1; - } - my @reason; - @reason = ("-crl_reason", $ARGV[1]) - if defined $ARGV[1] && crl_reason_ok($ARGV[1]); - $RET = run(@CA, "-revoke", $cname, @reason, @{$EXTRA{ca}}); -} else { - print STDERR "Unknown arg \"$WHAT\"\n"; - print STDERR "Use -help for help.\n"; - exit 1; -} - -exit $RET; diff --git a/openssl-install/ssl/misc/tsget b/openssl-install/ssl/misc/tsget deleted file mode 120000 index fa4d7006..00000000 --- a/openssl-install/ssl/misc/tsget +++ /dev/null @@ -1 +0,0 @@ -tsget.pl \ No newline at end of file diff --git a/openssl-install/ssl/misc/tsget.pl b/openssl-install/ssl/misc/tsget.pl deleted file mode 100755 index bf40640c..00000000 --- a/openssl-install/ssl/misc/tsget.pl +++ /dev/null @@ -1,200 +0,0 @@ -#!/usr/bin/env perl -# Copyright 2002-2018 The OpenSSL Project Authors. All Rights Reserved. -# Copyright (c) 2002 The OpenTSA Project. All rights reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use IO::Handle; -use Getopt::Std; -use File::Basename; -use WWW::Curl::Easy; - -use vars qw(%options); - -# Callback for reading the body. -sub read_body { - my ($maxlength, $state) = @_; - my $return_data = ""; - my $data_len = length ${$state->{data}}; - if ($state->{bytes} < $data_len) { - $data_len = $data_len - $state->{bytes}; - $data_len = $maxlength if $data_len > $maxlength; - $return_data = substr ${$state->{data}}, $state->{bytes}, $data_len; - $state->{bytes} += $data_len; - } - return $return_data; -} - -# Callback for writing the body into a variable. -sub write_body { - my ($data, $pointer) = @_; - ${$pointer} .= $data; - return length($data); -} - -# Initialise a new Curl object. -sub create_curl { - my $url = shift; - - # Create Curl object. - my $curl = WWW::Curl::Easy::new(); - - # Error-handling related options. - $curl->setopt(CURLOPT_VERBOSE, 1) if $options{d}; - $curl->setopt(CURLOPT_FAILONERROR, 1); - $curl->setopt(CURLOPT_USERAGENT, - "OpenTSA tsget.pl/openssl-3.4.2"); - - # Options for POST method. - $curl->setopt(CURLOPT_UPLOAD, 1); - $curl->setopt(CURLOPT_CUSTOMREQUEST, "POST"); - $curl->setopt(CURLOPT_HTTPHEADER, - ["Content-Type: application/timestamp-query", - "Accept: application/timestamp-reply,application/timestamp-response"]); - $curl->setopt(CURLOPT_READFUNCTION, \&read_body); - $curl->setopt(CURLOPT_HEADERFUNCTION, sub { return length($_[0]); }); - - # Options for getting the result. - $curl->setopt(CURLOPT_WRITEFUNCTION, \&write_body); - - # SSL related options. - $curl->setopt(CURLOPT_SSLKEYTYPE, "PEM"); - $curl->setopt(CURLOPT_SSL_VERIFYPEER, 1); # Verify server's certificate. - $curl->setopt(CURLOPT_SSL_VERIFYHOST, 2); # Check server's CN. - $curl->setopt(CURLOPT_SSLKEY, $options{k}) if defined($options{k}); - $curl->setopt(CURLOPT_SSLKEYPASSWD, $options{p}) if defined($options{p}); - $curl->setopt(CURLOPT_SSLCERT, $options{c}) if defined($options{c}); - $curl->setopt(CURLOPT_CAINFO, $options{C}) if defined($options{C}); - $curl->setopt(CURLOPT_CAPATH, $options{P}) if defined($options{P}); - $curl->setopt(CURLOPT_RANDOM_FILE, $options{r}) if defined($options{r}); - $curl->setopt(CURLOPT_EGDSOCKET, $options{g}) if defined($options{g}); - - # Setting destination. - $curl->setopt(CURLOPT_URL, $url); - - return $curl; -} - -# Send a request and returns the body back. -sub get_timestamp { - my $curl = shift; - my $body = shift; - my $ts_body; - local $::error_buf; - - # Error-handling related options. - $curl->setopt(CURLOPT_ERRORBUFFER, "::error_buf"); - - # Options for POST method. - $curl->setopt(CURLOPT_INFILE, {data => $body, bytes => 0}); - $curl->setopt(CURLOPT_INFILESIZE, length(${$body})); - - # Options for getting the result. - $curl->setopt(CURLOPT_FILE, \$ts_body); - - # Send the request... - my $error_code = $curl->perform(); - my $error_string; - if ($error_code != 0) { - my $http_code = $curl->getinfo(CURLINFO_HTTP_CODE); - $error_string = "could not get timestamp"; - $error_string .= ", http code: $http_code" unless $http_code == 0; - $error_string .= ", curl code: $error_code"; - $error_string .= " ($::error_buf)" if defined($::error_buf); - } else { - my $ct = $curl->getinfo(CURLINFO_CONTENT_TYPE); - if (lc($ct) ne "application/timestamp-reply" - && lc($ct) ne "application/timestamp-response") { - $error_string = "unexpected content type returned: $ct"; - } - } - return ($ts_body, $error_string); - -} - -# Print usage information and exists. -sub usage { - - print STDERR "usage: $0 -h [-e ] [-o ] "; - print STDERR "[-v] [-d] [-k ] [-p ] "; - print STDERR "[-c ] [-C ] [-P ] "; - print STDERR "[-r ] [-g ] []...\n"; - exit 1; -} - -# ---------------------------------------------------------------------- -# Main program -# ---------------------------------------------------------------------- - -# Getting command-line options (default comes from TSGET environment variable). -my $getopt_arg = "h:e:o:vdk:p:c:C:P:r:g:"; -if (exists $ENV{TSGET}) { - my @old_argv = @ARGV; - @ARGV = split /\s+/, $ENV{TSGET}; - getopts($getopt_arg, \%options) or usage; - @ARGV = @old_argv; -} -getopts($getopt_arg, \%options) or usage; - -# Checking argument consistency. -if (!exists($options{h}) || (@ARGV == 0 && !exists($options{o})) - || (@ARGV > 1 && exists($options{o}))) { - print STDERR "Inconsistent command line options.\n"; - usage; -} -# Setting defaults. -@ARGV = ("-") unless @ARGV != 0; -$options{e} = ".tsr" unless defined($options{e}); - -# Processing requests. -my $curl = create_curl $options{h}; -undef $/; # For reading whole files. -REQUEST: foreach (@ARGV) { - my $input = $_; - my ($base, $path) = fileparse($input, '\.[^.]*'); - my $output_base = $base . $options{e}; - my $output = defined($options{o}) ? $options{o} : $path . $output_base; - - STDERR->printflush("$input: ") if $options{v}; - # Read request. - my $body; - if ($input eq "-") { - # Read the request from STDIN; - $body = ; - } else { - # Read the request from file. - open INPUT, "<" . $input - or warn("$input: could not open input file: $!\n"), next REQUEST; - $body = ; - close INPUT - or warn("$input: could not close input file: $!\n"), next REQUEST; - } - - # Send request. - STDERR->printflush("sending request") if $options{v}; - - my ($ts_body, $error) = get_timestamp $curl, \$body; - if (defined($error)) { - die "$input: fatal error: $error\n"; - } - STDERR->printflush(", reply received") if $options{v}; - - # Write response. - if ($output eq "-") { - # Write to STDOUT. - print $ts_body; - } else { - # Write to file. - open OUTPUT, ">", $output - or warn("$output: could not open output file: $!\n"), next REQUEST; - print OUTPUT $ts_body; - close OUTPUT - or warn("$output: could not close output file: $!\n"), next REQUEST; - } - STDERR->printflush(", $output written.\n") if $options{v}; -} -$curl->cleanup(); diff --git a/openssl-install/ssl/openssl.cnf b/openssl-install/ssl/openssl.cnf deleted file mode 100644 index abace0ea..00000000 --- a/openssl-install/ssl/openssl.cnf +++ /dev/null @@ -1,390 +0,0 @@ -# -# OpenSSL example configuration file. -# See doc/man5/config.pod for more info. -# -# This is mostly being used for generation of certificate requests, -# but may be used for auto loading of providers - -# Note that you can include other files from the main configuration -# file using the .include directive. -#.include filename - -# This definition stops the following lines choking if HOME isn't -# defined. -HOME = . - -# Use this in order to automatically load providers. -openssl_conf = openssl_init - -# Comment out the next line to ignore configuration errors -config_diagnostics = 1 - -# Extra OBJECT IDENTIFIER info: -# oid_file = $ENV::HOME/.oid -oid_section = new_oids - -# To use this configuration file with the "-extfile" option of the -# "openssl x509" utility, name here the section containing the -# X.509v3 extensions to use: -# extensions = -# (Alternatively, use a configuration file that has only -# X.509v3 extensions in its main [= default] section.) - -[ new_oids ] -# We can add new OIDs in here for use by 'ca', 'req' and 'ts'. -# Add a simple OID like this: -# testoid1=1.2.3.4 -# Or use config file substitution like this: -# testoid2=${testoid1}.5.6 - -# Policies used by the TSA examples. -tsa_policy1 = 1.2.3.4.1 -tsa_policy2 = 1.2.3.4.5.6 -tsa_policy3 = 1.2.3.4.5.7 - -# For FIPS -# Optionally include a file that is generated by the OpenSSL fipsinstall -# application. This file contains configuration data required by the OpenSSL -# fips provider. It contains a named section e.g. [fips_sect] which is -# referenced from the [provider_sect] below. -# Refer to the OpenSSL security policy for more information. -# .include fipsmodule.cnf - -[openssl_init] -providers = provider_sect - -# List of providers to load -[provider_sect] -default = default_sect -# The fips section name should match the section name inside the -# included fipsmodule.cnf. -# fips = fips_sect - -# If no providers are activated explicitly, the default one is activated implicitly. -# See man 7 OSSL_PROVIDER-default for more details. -# -# If you add a section explicitly activating any other provider(s), you most -# probably need to explicitly activate the default provider, otherwise it -# becomes unavailable in openssl. As a consequence applications depending on -# OpenSSL may not work correctly which could lead to significant system -# problems including inability to remotely access the system. -[default_sect] -# activate = 1 - - -#################################################################### -[ ca ] -default_ca = CA_default # The default ca section - -#################################################################### -[ CA_default ] - -dir = ./demoCA # Where everything is kept -certs = $dir/certs # Where the issued certs are kept -crl_dir = $dir/crl # Where the issued crl are kept -database = $dir/index.txt # database index file. -#unique_subject = no # Set to 'no' to allow creation of - # several certs with same subject. -new_certs_dir = $dir/newcerts # default place for new certs. - -certificate = $dir/cacert.pem # The CA certificate -serial = $dir/serial # The current serial number -crlnumber = $dir/crlnumber # the current crl number - # must be commented out to leave a V1 CRL -crl = $dir/crl.pem # The current CRL -private_key = $dir/private/cakey.pem # The private key - -x509_extensions = usr_cert # The extensions to add to the cert - -# Comment out the following two lines for the "traditional" -# (and highly broken) format. -name_opt = ca_default # Subject Name options -cert_opt = ca_default # Certificate field options - -# Extension copying option: use with caution. -# copy_extensions = copy - -# Extensions to add to a CRL. Note: Netscape communicator chokes on V2 CRLs -# so this is commented out by default to leave a V1 CRL. -# crlnumber must also be commented out to leave a V1 CRL. -# crl_extensions = crl_ext - -default_days = 365 # how long to certify for -default_crl_days= 30 # how long before next CRL -default_md = default # use public key default MD -preserve = no # keep passed DN ordering - -# A few difference way of specifying how similar the request should look -# For type CA, the listed attributes must be the same, and the optional -# and supplied fields are just that :-) -policy = policy_match - -# For the CA policy -[ policy_match ] -countryName = match -stateOrProvinceName = match -organizationName = match -organizationalUnitName = optional -commonName = supplied -emailAddress = optional - -# For the 'anything' policy -# At this point in time, you must list all acceptable 'object' -# types. -[ policy_anything ] -countryName = optional -stateOrProvinceName = optional -localityName = optional -organizationName = optional -organizationalUnitName = optional -commonName = supplied -emailAddress = optional - -#################################################################### -[ req ] -default_bits = 2048 -default_keyfile = privkey.pem -distinguished_name = req_distinguished_name -attributes = req_attributes -x509_extensions = v3_ca # The extensions to add to the self signed cert - -# Passwords for private keys if not present they will be prompted for -# input_password = secret -# output_password = secret - -# This sets a mask for permitted string types. There are several options. -# default: PrintableString, T61String, BMPString. -# pkix : PrintableString, BMPString (PKIX recommendation before 2004) -# utf8only: only UTF8Strings (PKIX recommendation after 2004). -# nombstr : PrintableString, T61String (no BMPStrings or UTF8Strings). -# MASK:XXXX a literal mask value. -# WARNING: ancient versions of Netscape crash on BMPStrings or UTF8Strings. -string_mask = utf8only - -# req_extensions = v3_req # The extensions to add to a certificate request - -[ req_distinguished_name ] -countryName = Country Name (2 letter code) -countryName_default = AU -countryName_min = 2 -countryName_max = 2 - -stateOrProvinceName = State or Province Name (full name) -stateOrProvinceName_default = Some-State - -localityName = Locality Name (eg, city) - -0.organizationName = Organization Name (eg, company) -0.organizationName_default = Internet Widgits Pty Ltd - -# we can do this but it is not needed normally :-) -#1.organizationName = Second Organization Name (eg, company) -#1.organizationName_default = World Wide Web Pty Ltd - -organizationalUnitName = Organizational Unit Name (eg, section) -#organizationalUnitName_default = - -commonName = Common Name (e.g. server FQDN or YOUR name) -commonName_max = 64 - -emailAddress = Email Address -emailAddress_max = 64 - -# SET-ex3 = SET extension number 3 - -[ req_attributes ] -challengePassword = A challenge password -challengePassword_min = 4 -challengePassword_max = 20 - -unstructuredName = An optional company name - -[ usr_cert ] - -# These extensions are added when 'ca' signs a request. - -# This goes against PKIX guidelines but some CAs do it and some software -# requires this to avoid interpreting an end user certificate as a CA. - -basicConstraints=CA:FALSE - -# This is typical in keyUsage for a client certificate. -# keyUsage = nonRepudiation, digitalSignature, keyEncipherment - -# PKIX recommendations harmless if included in all certificates. -subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid,issuer - -# This stuff is for subjectAltName and issuerAltname. -# Import the email address. -# subjectAltName=email:copy -# An alternative to produce certificates that aren't -# deprecated according to PKIX. -# subjectAltName=email:move - -# Copy subject details -# issuerAltName=issuer:copy - -# This is required for TSA certificates. -# extendedKeyUsage = critical,timeStamping - -[ v3_req ] - -# Extensions to add to a certificate request - -basicConstraints = CA:FALSE -keyUsage = nonRepudiation, digitalSignature, keyEncipherment - -[ v3_ca ] - - -# Extensions for a typical CA - - -# PKIX recommendation. - -subjectKeyIdentifier=hash - -authorityKeyIdentifier=keyid:always,issuer - -basicConstraints = critical,CA:true - -# Key usage: this is typical for a CA certificate. However since it will -# prevent it being used as an test self-signed certificate it is best -# left out by default. -# keyUsage = cRLSign, keyCertSign - -# Include email address in subject alt name: another PKIX recommendation -# subjectAltName=email:copy -# Copy issuer details -# issuerAltName=issuer:copy - -# DER hex encoding of an extension: beware experts only! -# obj=DER:02:03 -# Where 'obj' is a standard or added object -# You can even override a supported extension: -# basicConstraints= critical, DER:30:03:01:01:FF - -[ crl_ext ] - -# CRL extensions. -# Only issuerAltName and authorityKeyIdentifier make any sense in a CRL. - -# issuerAltName=issuer:copy -authorityKeyIdentifier=keyid:always - -[ proxy_cert_ext ] -# These extensions should be added when creating a proxy certificate - -# This goes against PKIX guidelines but some CAs do it and some software -# requires this to avoid interpreting an end user certificate as a CA. - -basicConstraints=CA:FALSE - -# This is typical in keyUsage for a client certificate. -# keyUsage = nonRepudiation, digitalSignature, keyEncipherment - -# PKIX recommendations harmless if included in all certificates. -subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid,issuer - -# This stuff is for subjectAltName and issuerAltname. -# Import the email address. -# subjectAltName=email:copy -# An alternative to produce certificates that aren't -# deprecated according to PKIX. -# subjectAltName=email:move - -# Copy subject details -# issuerAltName=issuer:copy - -# This really needs to be in place for it to be a proxy certificate. -proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:3,policy:foo - -#################################################################### -[ tsa ] - -default_tsa = tsa_config1 # the default TSA section - -[ tsa_config1 ] - -# These are used by the TSA reply generation only. -dir = ./demoCA # TSA root directory -serial = $dir/tsaserial # The current serial number (mandatory) -crypto_device = builtin # OpenSSL engine to use for signing -signer_cert = $dir/tsacert.pem # The TSA signing certificate - # (optional) -certs = $dir/cacert.pem # Certificate chain to include in reply - # (optional) -signer_key = $dir/private/tsakey.pem # The TSA private key (optional) -signer_digest = sha256 # Signing digest to use. (Optional) -default_policy = tsa_policy1 # Policy if request did not specify it - # (optional) -other_policies = tsa_policy2, tsa_policy3 # acceptable policies (optional) -digests = sha1, sha256, sha384, sha512 # Acceptable message digests (mandatory) -accuracy = secs:1, millisecs:500, microsecs:100 # (optional) -clock_precision_digits = 0 # number of digits after dot. (optional) -ordering = yes # Is ordering defined for timestamps? - # (optional, default: no) -tsa_name = yes # Must the TSA name be included in the reply? - # (optional, default: no) -ess_cert_id_chain = no # Must the ESS cert id chain be included? - # (optional, default: no) -ess_cert_id_alg = sha256 # algorithm to compute certificate - # identifier (optional, default: sha256) - -[insta] # CMP using Insta Demo CA -# Message transfer -server = pki.certificate.fi:8700 -# proxy = # set this as far as needed, e.g., http://192.168.1.1:8080 -# tls_use = 0 -path = pkix/ - -# Server authentication -recipient = "/C=FI/O=Insta Demo/CN=Insta Demo CA" # or set srvcert or issuer -ignore_keyusage = 1 # quirk needed to accept Insta CA cert not including digitalsignature -unprotected_errors = 1 # quirk needed to accept negative responses possibly not protected -extracertsout = insta.extracerts.pem - -# Client authentication -ref = 3078 # user identification -secret = pass:insta # can be used for both client and server side - -# Generic message options -cmd = ir # default operation, can be overridden on cmd line with, e.g., kur - -# Certificate enrollment -subject = "/CN=openssl-cmp-test" -newkey = insta.priv.pem -out_trusted = apps/insta.ca.crt # does not include keyUsage digitalSignature -certout = insta.cert.pem - -[pbm] # Password-based protection for Insta CA -# Server and client authentication -ref = $insta::ref # 3078 -secret = $insta::secret # pass:insta - -[signature] # Signature-based protection for Insta CA -# Server authentication -trusted = $insta::out_trusted # apps/insta.ca.crt - -# Client authentication -secret = # disable PBM -key = $insta::newkey # insta.priv.pem -cert = $insta::certout # insta.cert.pem - -[ir] -cmd = ir - -[cr] -cmd = cr - -[kur] -# Certificate update -cmd = kur -oldcert = $insta::certout # insta.cert.pem - -[rr] -# Certificate revocation -cmd = rr -oldcert = $insta::certout # insta.cert.pem diff --git a/openssl-install/ssl/openssl.cnf.dist b/openssl-install/ssl/openssl.cnf.dist deleted file mode 100644 index abace0ea..00000000 --- a/openssl-install/ssl/openssl.cnf.dist +++ /dev/null @@ -1,390 +0,0 @@ -# -# OpenSSL example configuration file. -# See doc/man5/config.pod for more info. -# -# This is mostly being used for generation of certificate requests, -# but may be used for auto loading of providers - -# Note that you can include other files from the main configuration -# file using the .include directive. -#.include filename - -# This definition stops the following lines choking if HOME isn't -# defined. -HOME = . - -# Use this in order to automatically load providers. -openssl_conf = openssl_init - -# Comment out the next line to ignore configuration errors -config_diagnostics = 1 - -# Extra OBJECT IDENTIFIER info: -# oid_file = $ENV::HOME/.oid -oid_section = new_oids - -# To use this configuration file with the "-extfile" option of the -# "openssl x509" utility, name here the section containing the -# X.509v3 extensions to use: -# extensions = -# (Alternatively, use a configuration file that has only -# X.509v3 extensions in its main [= default] section.) - -[ new_oids ] -# We can add new OIDs in here for use by 'ca', 'req' and 'ts'. -# Add a simple OID like this: -# testoid1=1.2.3.4 -# Or use config file substitution like this: -# testoid2=${testoid1}.5.6 - -# Policies used by the TSA examples. -tsa_policy1 = 1.2.3.4.1 -tsa_policy2 = 1.2.3.4.5.6 -tsa_policy3 = 1.2.3.4.5.7 - -# For FIPS -# Optionally include a file that is generated by the OpenSSL fipsinstall -# application. This file contains configuration data required by the OpenSSL -# fips provider. It contains a named section e.g. [fips_sect] which is -# referenced from the [provider_sect] below. -# Refer to the OpenSSL security policy for more information. -# .include fipsmodule.cnf - -[openssl_init] -providers = provider_sect - -# List of providers to load -[provider_sect] -default = default_sect -# The fips section name should match the section name inside the -# included fipsmodule.cnf. -# fips = fips_sect - -# If no providers are activated explicitly, the default one is activated implicitly. -# See man 7 OSSL_PROVIDER-default for more details. -# -# If you add a section explicitly activating any other provider(s), you most -# probably need to explicitly activate the default provider, otherwise it -# becomes unavailable in openssl. As a consequence applications depending on -# OpenSSL may not work correctly which could lead to significant system -# problems including inability to remotely access the system. -[default_sect] -# activate = 1 - - -#################################################################### -[ ca ] -default_ca = CA_default # The default ca section - -#################################################################### -[ CA_default ] - -dir = ./demoCA # Where everything is kept -certs = $dir/certs # Where the issued certs are kept -crl_dir = $dir/crl # Where the issued crl are kept -database = $dir/index.txt # database index file. -#unique_subject = no # Set to 'no' to allow creation of - # several certs with same subject. -new_certs_dir = $dir/newcerts # default place for new certs. - -certificate = $dir/cacert.pem # The CA certificate -serial = $dir/serial # The current serial number -crlnumber = $dir/crlnumber # the current crl number - # must be commented out to leave a V1 CRL -crl = $dir/crl.pem # The current CRL -private_key = $dir/private/cakey.pem # The private key - -x509_extensions = usr_cert # The extensions to add to the cert - -# Comment out the following two lines for the "traditional" -# (and highly broken) format. -name_opt = ca_default # Subject Name options -cert_opt = ca_default # Certificate field options - -# Extension copying option: use with caution. -# copy_extensions = copy - -# Extensions to add to a CRL. Note: Netscape communicator chokes on V2 CRLs -# so this is commented out by default to leave a V1 CRL. -# crlnumber must also be commented out to leave a V1 CRL. -# crl_extensions = crl_ext - -default_days = 365 # how long to certify for -default_crl_days= 30 # how long before next CRL -default_md = default # use public key default MD -preserve = no # keep passed DN ordering - -# A few difference way of specifying how similar the request should look -# For type CA, the listed attributes must be the same, and the optional -# and supplied fields are just that :-) -policy = policy_match - -# For the CA policy -[ policy_match ] -countryName = match -stateOrProvinceName = match -organizationName = match -organizationalUnitName = optional -commonName = supplied -emailAddress = optional - -# For the 'anything' policy -# At this point in time, you must list all acceptable 'object' -# types. -[ policy_anything ] -countryName = optional -stateOrProvinceName = optional -localityName = optional -organizationName = optional -organizationalUnitName = optional -commonName = supplied -emailAddress = optional - -#################################################################### -[ req ] -default_bits = 2048 -default_keyfile = privkey.pem -distinguished_name = req_distinguished_name -attributes = req_attributes -x509_extensions = v3_ca # The extensions to add to the self signed cert - -# Passwords for private keys if not present they will be prompted for -# input_password = secret -# output_password = secret - -# This sets a mask for permitted string types. There are several options. -# default: PrintableString, T61String, BMPString. -# pkix : PrintableString, BMPString (PKIX recommendation before 2004) -# utf8only: only UTF8Strings (PKIX recommendation after 2004). -# nombstr : PrintableString, T61String (no BMPStrings or UTF8Strings). -# MASK:XXXX a literal mask value. -# WARNING: ancient versions of Netscape crash on BMPStrings or UTF8Strings. -string_mask = utf8only - -# req_extensions = v3_req # The extensions to add to a certificate request - -[ req_distinguished_name ] -countryName = Country Name (2 letter code) -countryName_default = AU -countryName_min = 2 -countryName_max = 2 - -stateOrProvinceName = State or Province Name (full name) -stateOrProvinceName_default = Some-State - -localityName = Locality Name (eg, city) - -0.organizationName = Organization Name (eg, company) -0.organizationName_default = Internet Widgits Pty Ltd - -# we can do this but it is not needed normally :-) -#1.organizationName = Second Organization Name (eg, company) -#1.organizationName_default = World Wide Web Pty Ltd - -organizationalUnitName = Organizational Unit Name (eg, section) -#organizationalUnitName_default = - -commonName = Common Name (e.g. server FQDN or YOUR name) -commonName_max = 64 - -emailAddress = Email Address -emailAddress_max = 64 - -# SET-ex3 = SET extension number 3 - -[ req_attributes ] -challengePassword = A challenge password -challengePassword_min = 4 -challengePassword_max = 20 - -unstructuredName = An optional company name - -[ usr_cert ] - -# These extensions are added when 'ca' signs a request. - -# This goes against PKIX guidelines but some CAs do it and some software -# requires this to avoid interpreting an end user certificate as a CA. - -basicConstraints=CA:FALSE - -# This is typical in keyUsage for a client certificate. -# keyUsage = nonRepudiation, digitalSignature, keyEncipherment - -# PKIX recommendations harmless if included in all certificates. -subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid,issuer - -# This stuff is for subjectAltName and issuerAltname. -# Import the email address. -# subjectAltName=email:copy -# An alternative to produce certificates that aren't -# deprecated according to PKIX. -# subjectAltName=email:move - -# Copy subject details -# issuerAltName=issuer:copy - -# This is required for TSA certificates. -# extendedKeyUsage = critical,timeStamping - -[ v3_req ] - -# Extensions to add to a certificate request - -basicConstraints = CA:FALSE -keyUsage = nonRepudiation, digitalSignature, keyEncipherment - -[ v3_ca ] - - -# Extensions for a typical CA - - -# PKIX recommendation. - -subjectKeyIdentifier=hash - -authorityKeyIdentifier=keyid:always,issuer - -basicConstraints = critical,CA:true - -# Key usage: this is typical for a CA certificate. However since it will -# prevent it being used as an test self-signed certificate it is best -# left out by default. -# keyUsage = cRLSign, keyCertSign - -# Include email address in subject alt name: another PKIX recommendation -# subjectAltName=email:copy -# Copy issuer details -# issuerAltName=issuer:copy - -# DER hex encoding of an extension: beware experts only! -# obj=DER:02:03 -# Where 'obj' is a standard or added object -# You can even override a supported extension: -# basicConstraints= critical, DER:30:03:01:01:FF - -[ crl_ext ] - -# CRL extensions. -# Only issuerAltName and authorityKeyIdentifier make any sense in a CRL. - -# issuerAltName=issuer:copy -authorityKeyIdentifier=keyid:always - -[ proxy_cert_ext ] -# These extensions should be added when creating a proxy certificate - -# This goes against PKIX guidelines but some CAs do it and some software -# requires this to avoid interpreting an end user certificate as a CA. - -basicConstraints=CA:FALSE - -# This is typical in keyUsage for a client certificate. -# keyUsage = nonRepudiation, digitalSignature, keyEncipherment - -# PKIX recommendations harmless if included in all certificates. -subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid,issuer - -# This stuff is for subjectAltName and issuerAltname. -# Import the email address. -# subjectAltName=email:copy -# An alternative to produce certificates that aren't -# deprecated according to PKIX. -# subjectAltName=email:move - -# Copy subject details -# issuerAltName=issuer:copy - -# This really needs to be in place for it to be a proxy certificate. -proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:3,policy:foo - -#################################################################### -[ tsa ] - -default_tsa = tsa_config1 # the default TSA section - -[ tsa_config1 ] - -# These are used by the TSA reply generation only. -dir = ./demoCA # TSA root directory -serial = $dir/tsaserial # The current serial number (mandatory) -crypto_device = builtin # OpenSSL engine to use for signing -signer_cert = $dir/tsacert.pem # The TSA signing certificate - # (optional) -certs = $dir/cacert.pem # Certificate chain to include in reply - # (optional) -signer_key = $dir/private/tsakey.pem # The TSA private key (optional) -signer_digest = sha256 # Signing digest to use. (Optional) -default_policy = tsa_policy1 # Policy if request did not specify it - # (optional) -other_policies = tsa_policy2, tsa_policy3 # acceptable policies (optional) -digests = sha1, sha256, sha384, sha512 # Acceptable message digests (mandatory) -accuracy = secs:1, millisecs:500, microsecs:100 # (optional) -clock_precision_digits = 0 # number of digits after dot. (optional) -ordering = yes # Is ordering defined for timestamps? - # (optional, default: no) -tsa_name = yes # Must the TSA name be included in the reply? - # (optional, default: no) -ess_cert_id_chain = no # Must the ESS cert id chain be included? - # (optional, default: no) -ess_cert_id_alg = sha256 # algorithm to compute certificate - # identifier (optional, default: sha256) - -[insta] # CMP using Insta Demo CA -# Message transfer -server = pki.certificate.fi:8700 -# proxy = # set this as far as needed, e.g., http://192.168.1.1:8080 -# tls_use = 0 -path = pkix/ - -# Server authentication -recipient = "/C=FI/O=Insta Demo/CN=Insta Demo CA" # or set srvcert or issuer -ignore_keyusage = 1 # quirk needed to accept Insta CA cert not including digitalsignature -unprotected_errors = 1 # quirk needed to accept negative responses possibly not protected -extracertsout = insta.extracerts.pem - -# Client authentication -ref = 3078 # user identification -secret = pass:insta # can be used for both client and server side - -# Generic message options -cmd = ir # default operation, can be overridden on cmd line with, e.g., kur - -# Certificate enrollment -subject = "/CN=openssl-cmp-test" -newkey = insta.priv.pem -out_trusted = apps/insta.ca.crt # does not include keyUsage digitalSignature -certout = insta.cert.pem - -[pbm] # Password-based protection for Insta CA -# Server and client authentication -ref = $insta::ref # 3078 -secret = $insta::secret # pass:insta - -[signature] # Signature-based protection for Insta CA -# Server authentication -trusted = $insta::out_trusted # apps/insta.ca.crt - -# Client authentication -secret = # disable PBM -key = $insta::newkey # insta.priv.pem -cert = $insta::certout # insta.cert.pem - -[ir] -cmd = ir - -[cr] -cmd = cr - -[kur] -# Certificate update -cmd = kur -oldcert = $insta::certout # insta.cert.pem - -[rr] -# Certificate revocation -cmd = rr -oldcert = $insta::certout # insta.cert.pem